fix: resolve the issue store from the project, not the plugin

`issue.store_root` and `_gitea.PAYLOAD_ROOT` were anchored on `__file__`, on
the reasoning that where an installation keeps its files is a fact about the
installation. That holds for an installation and not for a store.

Installed, the plugin therefore resolved every project's issues inside its own
directory — and a plugin cache is versioned, so the store moved on each
update:

    ~/.claude/plugins/cache/tea/tea/2.0.0/tmp/issues   5 files, 2 origin: local
    ~/.claude/plugins/cache/tea/tea/2.1.0/tmp/issues   12 files
    ~/.claude/plugins/cache/claude-skills/tea/2.2.0/   empty, the current one

Issues written from one project were invisible from the next, and an `origin:
local` file — which IS the issue, the only copy — was stranded a version bump
at a time. Two of them were.

The store is a fact about the project, exactly as the login pin is. So the
anchor is now an explicit marker an operator creates, `.tea/`, searched for up
from $CLAUDE_PROJECT_DIR and then cwd — the pin's order, so the two cannot
disagree about which project this is. Inferred markers were tried and are worse
than useless here: `.git` is in every clone including this plugin's own, and
the agents-sync hook writes an AGENTS.md next to every AGENTS.md, so the plugin
root always carried one and cwd never got a turn.

With no marker anywhere, `store_root()` is None and every entry point reports
which directories it searched. A store in a plausible-looking directory is the
failure this replaces, so nothing falls back to one.

- `.tea/` holds the store and the transport's scratchpad: `.tea/issues`,
  `.tea/payload`. One marker, one walk, one gitignore line.
- `issue_init.py` creates it, moves an old `tmp/issues` store in rather than
  copying, adds `.tea/` to `.gitignore`, and refuses to pick a winner when both
  sides hold the same file name.
- A linked worktree has no marker — it is gitignored — and reaches the main
  checkout's store by the hop the pin already took.
- `parents`, `gitdir_of` and `main_worktree` move from `pin.py` into the domain
  and `pin.py` imports them. The domain depends on nothing, so it is the layer
  all three callers can borrow from, and the walk stays written once: the
  guard, the transport and the store cannot disagree about a directory.

The suite stopped copying the script layers into its fixtures. That is what hid
this: with the scripts inside the fixture, the installation and the project
were the same directory. They are now deliberately far apart, and a regression
test asserts the plugin tree gains no files when commands run against a project
somewhere else.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
naudachu
2026-08-11 13:38:39 +05:00
parent 27e4b6b1da
commit fb5445915f
30 changed files with 1193 additions and 430 deletions
+181 -48
View File
@@ -16,7 +16,7 @@ only on this machine are first-class, not drafts on their way somewhere.
Identity is a slug derived from the title, and it is the only identity the
domain has. The file name is the id:
tmp/issues/wire-sqlc-appclick.md
.tea/issues/wire-sqlc-appclick.md
---
id: wire-sqlc-appclick
@@ -42,8 +42,8 @@ issue and a synced one without the domain learning a second vocabulary.
Every metadata field is one line and lists are inline, so plain grep works
without a parser:
grep -l 'labels:.*type/bug' tmp/issues/*.md
grep -ln 'depends:.*migrate-schema' tmp/issues/*.md # who depends on it
grep -l 'labels:.*type/bug' .tea/issues/*.md
grep -ln 'depends:.*migrate-schema' .tea/issues/*.md # who depends on it
"""
import collections
import os
@@ -52,61 +52,182 @@ import re
# --------------------------------------------------------------------------
# where the store lives
# --------------------------------------------------------------------------
# `<repo root>/tmp/issues`, absolute, resolved once at import.
# `<project root>/.tea/issues`, absolute, resolved once at import — where the
# project root is the nearest directory up from the WORKING DIRECTORY that an
# operator has run `issue_init.py` in.
#
# It used to be the relative `tmp/issues`, which made "the store" whatever
# directory the shell happened to be standing in. One `cd` — and a `cd` outlives
# the command that ran it — was enough for readers to report an empty store on a
# full one and for writers to quietly build a second store beside the first.
# Two anchors have been wrong here, in this order. First the relative
# `tmp/issues`, which made "the store" whatever directory the shell happened to
# be standing in: one `cd` — and a `cd` outlives the command that ran it — and
# readers reported an empty store on a full one while writers built a second
# store beside the first. Then `__file__`, on the reasoning that a script's own
# location is a fact about the installation while cwd is a fact about the last
# `cd`. That reasoning holds for an installation; it does not hold for a STORE.
#
# The anchor is THIS FILE, not the working directory. A script's own location is
# a fact about the installation; cwd is a fact about the last `cd`. Walking up
# from __file__ therefore hands every script in both layers the same answer no
# matter where it is invoked from — including from inside tmp/issues itself.
# Anchored on `__file__`, an installed plugin resolves the store inside its own
# directory — and a plugin cache is versioned, so `~/.claude/plugins/cache/tea/
# tea/2.0.0/tmp/issues` stopped being found the moment the plugin became 2.1.0.
# Issues written from one project landed in the plugin and were invisible from
# the next. `origin: local` files — which ARE the issue, the only copy — were
# stranded a version bump at a time.
#
# So: the store is a fact about the PROJECT, exactly as the login pin is (see
# auth/scripts/pin.py, which has always resolved this way and says why). The
# anchor is an explicit marker an operator created, not a marker inferred from
# the tree: `.git` is present in every clone including this plugin's own, and
# AGENTS.md was worse still — the agents-sync hook writes one next to every
# AGENTS.md, so the plugin root always carried one and cwd never got a turn.
#
# Nothing is guessed when the marker is absent. `store_root()` returns None and
# the callers report which directories were searched; a wrong directory that
# looks like it worked is the failure this replaces.
#
# An explicit --out still wins over all of this, and is used exactly as typed: a
# relative --out stays relative to cwd, because that is what the operator asked
# for. There is no environment override; the store is where the repo is.
# for.
STORE_PARTS = ("tmp", "issues")
# `.git` is a directory in a normal clone and a FILE in a worktree — hence
# exists(), not isdir(). AGENTS.md is the fallback for a plugin copied out of
# git; the agents-sync hook only ever puts one at a repository root.
REPO_MARKERS = (".git", "AGENTS.md")
_HERE = os.path.dirname(os.path.abspath(__file__))
MARKER = ".tea"
STORE_PARTS = (MARKER, "issues")
def repo_root(start):
"""Nearest ancestor of `start` (inclusive) carrying a repo marker, or None.
def anchors(start=None):
"""The directories a root search starts from, in order, first hit wins.
Markers, not a fixed number of `..` hops: how deep this file sits below the
root is an implementation detail of the repo layout, and the layout is not
a promise."""
`start` overrides them and exists so the resolution can be exercised
against a scratch tree. Otherwise: the project Claude Code was opened on,
then the working directory. The same order as `pin.search_dirs`, for the
same reason — both answer "which project is this", and a project that
disagrees with itself about that has two identities."""
if start is not None:
return [os.path.abspath(start)]
out = []
for d in (os.environ.get("CLAUDE_PROJECT_DIR"), os.getcwd()):
if d and os.path.isdir(d):
d = os.path.abspath(d)
if d not in out:
out.append(d)
return out
# The walk itself — the parent chain and the hop out of a linked worktree —
# lives here rather than in the identity layer that first needed it, because
# the domain is the layer everything else may depend on and it depends on
# nothing. `pin.py` imports these three; one written copy of the walk means the
# guard, the transport and the store cannot disagree about a directory. They
# did once: in a worktree, `tea` worked and every script said "no login
# pinned".
def parents(start):
"""`start` and every ancestor of it, up to the filesystem root."""
d = os.path.abspath(start)
while True:
if any(os.path.exists(os.path.join(d, m)) for m in REPO_MARKERS):
return d
yield d
parent = os.path.dirname(d)
if parent == d:
return None
return
d = parent
def store_root(start=None):
"""Absolute path of the issue store.
def gitdir_of(d):
"""The private git directory `d/.git` points at, or None.
`start` overrides the anchor and exists so the resolution can be exercised
against a scratch tree. When these scripts are not inside a repository at
all, cwd gets a turn; failing that the historical cwd-relative location
stands, made absolute so an error message can name the directory it really
looked in."""
for anchor in ([start] if start is not None else [_HERE, os.getcwd()]):
root = repo_root(anchor)
if root:
return os.path.join(root, *STORE_PARTS)
return os.path.abspath(os.path.join(*STORE_PARTS))
Only a `.git` FILE is a pointer; in an ordinary clone `.git` is a
directory and there is nothing to follow."""
p = os.path.join(d, ".git")
if not os.path.isfile(p):
return None
try:
with open(p) as f:
head = f.read(4096)
except OSError:
return None
for line in head.splitlines():
line = line.strip()
if line.startswith("gitdir:"):
target = line[len("gitdir:"):].strip()
if not target:
return None
if not os.path.isabs(target):
target = os.path.join(d, target)
return os.path.abspath(target)
return None
def main_worktree(d):
"""If `d` is a linked worktree, the main working tree of its repository.
`<worktree>/.git` -> `<main>/.git/worktrees/<name>`, whose `commondir`
file holds a path to `<main>/.git`; the main working tree is its parent.
The `.git` basename check keeps this to worktrees: a submodule's `.git`
is a pointer too, but it points into `<super>/.git/modules/…`, and the
tree it belongs to is already on the parent chain."""
gitdir = gitdir_of(d)
if not gitdir or not os.path.isdir(gitdir):
return None
common = gitdir
marker = os.path.join(gitdir, "commondir")
if os.path.isfile(marker):
try:
with open(marker) as f:
rel = f.read().strip()
except OSError:
rel = ""
if rel:
common = os.path.abspath(os.path.join(gitdir, rel))
if os.path.basename(common) != ".git":
return None
root = os.path.dirname(common)
if root and os.path.isdir(root) and root != os.path.abspath(d):
return root
return None
def project_root(start=None):
"""Nearest ancestor of an anchor (inclusive) holding `.tea/`, or None.
A marker, not a fixed number of `..` hops: how deep a caller sits below the
root is an implementation detail of the project layout, and the layout is
not a promise. Walking up means every script sees one store from anywhere
inside the project — including from inside the store itself — while a `cd`
into a DIFFERENT project correctly answers with that project's store.
A linked worktree is the same project on another branch, and the marker is
gitignored, so it is only ever in the main checkout: the chain is searched
first and always wins, then the main working tree of any worktree met on
it. Initializing inside a worktree would give one project two stores, and
the directory holding the second one disappears with the branch."""
for anchor in anchors(start):
hops = []
for d in parents(anchor):
if os.path.isdir(os.path.join(d, MARKER)):
return d
main = main_worktree(d)
if main and main not in hops:
hops.append(main)
for root in hops:
# One level of indirection, never two: a main checkout is not
# itself a linked worktree, so this cannot chain and cannot cycle.
for d in parents(root):
if os.path.isdir(os.path.join(d, MARKER)):
return d
return None
def store_root(start=None):
"""Absolute path of the issue store, or None when no project was found."""
root = project_root(start)
return os.path.join(root, *STORE_PARTS) if root else None
def no_project_error(start=None):
"""Why no store could be resolved, naming every directory searched.
The searched directories are the anchors, not the whole chain above them:
an operator who sees the two places the search began knows immediately
whether it began where they meant it to."""
return ("no %s/ found — searched up from %s. Run issue_init.py in the "
"project you mean to track issues in."
% (MARKER, " and ".join(anchors(start)) or "nowhere"))
ISSUE_ROOT = store_root()
@@ -577,16 +698,20 @@ class StoreMissing(Exception):
def __init__(self, root):
self.root = root
Exception.__init__(self, "store %s does not exist" % root)
Exception.__init__(self, no_project_error() if root is None
else "store %s does not exist" % root)
def store_exists(root):
return os.path.isdir(root)
return root is not None and os.path.isdir(root)
def require_store(root):
"""Assert the store is there before reading or writing it."""
if not os.path.isdir(root):
"""Assert the store is there before reading or writing it.
`root` is None when no project was found at all — a different failure from
a project whose store has not been created yet, and StoreMissing says so."""
if not store_exists(root):
raise StoreMissing(root)
return root
@@ -597,7 +722,11 @@ def create_store(root):
Only the commands that legitimately bootstrap a store call this — issue_new
and pull — and both announce it. Nothing creates a store as a side effect of
a write any more: a missing directory is something to report, not something
to conjure."""
to conjure. An unresolved root is never conjured either: without a marker
there is no project to create a store IN, and guessing one is how a store
ended up inside the plugin."""
if root is None:
raise StoreMissing(None)
if os.path.isdir(root):
return False
os.makedirs(root)
@@ -607,7 +736,11 @@ def create_store(root):
def store_error(root):
"""Why `root` cannot be read as a store, or None when it holds issues.
The two messages are distinct on purpose — see StoreMissing."""
The three messages are distinct on purpose — no project at all, a project
with no store, and a store with nothing in it are three different things to
do next."""
if root is None:
return no_project_error()
if not os.path.isdir(root):
return ("store %s does not exist — nothing was created; pass --out to "
"point elsewhere" % root)
@@ -629,7 +762,7 @@ def all_ids(root):
Without that rule `wire-sqlc.comments` reads as an issue called
`wire-sqlc.comments`, and a bare `push.py` tries to file the comment thread
as a unit of work."""
if not os.path.isdir(root):
if not store_exists(root):
return []
return sorted(f[:-3] for f in os.listdir(root)
if f.endswith(".md") and not f.startswith((".", "INDEX", "tree-"))