tea-based git wrappers hard-fail in any repo declaring extensions.worktreeconfig #1342
Open
opened 2026-08-20 23:07:54 +00:00 by fred
·
2 comments
No Branch/Tag Specified
next
fix/ci-queue-wait-no-ci-merge-path
fix/credentials-gitea-seat-slots
feat/onboarding-scripts-framework
pr-1367
fix/1357-issue-view-comments
fix/1356-tea-login-fail-closed
fix/1362-harness-aware-delivery-confirm
fix/gitea-guessed-login-credential
docs/w4-document-contract
fix/d29-lease-revoke-noop
peggy/agent-send-unverified-label
fix/pr-merge-fork-ci-status
docs/ri-050-release-evidence
riv001-clean
docs/1216-trunk-parameterization
fix/1257-adopt-draft-transition
fix/1256-fleet-pane-path-node
fix/1017-enumeration-guard-population
fix/1182-fail-closed-launch
fix/1327-setuppath-idempotency
merge/main-into-next
ci/push-ci-comment-model
ci/pin-ci-base-image
fix/ci-queue-wait-no-status
fred/code-review-pinned-tool-rules
fred/guides-seat-identity-fleet-comms
fred/credential-fail-closed-seat-slots
fix/fleet-greenfield-blockers
feat/ri-050-qr-evaluator
docs/ri-050-forge-docs-fastfollow
fix/ri-050-registry-secrets
test/ri-050-publish-gate-negative
fix/ri-050-verify-pglite-path
docs/ri-050-qr-probe-inventory
feat/ri-050-web-stale-safety
docs/ri-050-mission-bootstrap
fix/ri-050-forge-fail-closed
feat/ri-050-publish-gate
fleet/continuation-record-2026-08-17
feat/ri-050-prd-authority
fix/ri-050-macp-fail-closed
fix/1280-identity-first-resolution
feat/w-f4-store
fix/1264-fleet-unattended-first-start
fix/1269-ci-chain-unblock
fix/1256-fleet-runtime-preflight
fix/1257-e7-draft-transition
fix/1240-fleet-transport-check
fix/1017-wire-start-agent-session
e2e-compose
fix/1241-launch-failure-visible
fix/1237-fleet-v2-dispatch
fix/1236-installer-dir-modes
fix/installer-path-and-node
feat/wf-fleet-mvp
fix/installer-provisions-node
fix/lease-test-env-isolation
release/0.0.50-integration
feat/wf5-main-merge
feat/wf5-securestorage
feat/1216-trunk-resolver
docs/1214-branch-process
docs/ia-merge-current
fix/869-lease-probe-timeout
main
feat/workspace-hygiene-tool-enforcement
feat/1080-pr-edit
fix/1179-required-security-di
feat/p3-slice0-task5-chat-runtime-router-shaggy
feat/p3-slice0-task5-chat-runtime-router
feat/wf1-composition
feat/p3-slice0-task4-web-catalog-selection
feat/lease-promotion-and-harness-isolation
ci/provision-pi-runtime
feat/p3-slice0-task3-catalog-selection
feat/p3-slice0-task2-harness-registry
adopt/965-mos-ste-writing-standard
fix/991-comment-url-scheme-normalise
feat/wf2-bundle-migration
feat/wf4-plugin-acquisition
feat/wf5-refresh-safety
fix/1145-coord-di-compiled-boot
feat/p3-slice0-task1-harness-contracts
docs/webui-phase-p-structure
feat/1150-pi-goal-extension
feat/webui-p3-chat
fix/1146-ci-queue-purpose
fix/1138-conditional-federation
feat/webui-p2-data-auth
fix/gateway-runner-image
feat/webui-p1-vite-skeleton
fix/break-c-hooks-and-web-image
docs/webui-fleet-claude-bridge-plan
fix/wizard-gateway-failure
fix/next-node-gate
fix/mosaic-init-rce
greenfield/fomo-lin
fix/1099-pipefail-wake
fix/1099-pipefail-tests
fix/1099-pipefail-sweep
fix/framework-shell-portability
fix/1043-pane-git-identity
fix/1081-issue-close-silent-comment-failure
fix/1090-enrollment-wallclock-tolerance
feat/1082-tea-stale-token-diagnostic
fix/detect-platform-silent-128-outside-repo
feat/1050-install-state-machine-red-fixture
fix/pr-merge-message-field
feat/1051-mosaic-brain-installer
feat/1045-mosaic-cred
remediation/state
fix/1056-upgrade-rollback-control-race
fix/1019-ci-queue-timeout-harness
feat/rm-02-gate-registry
fix/rm-01-reproducible-checkout
remediation/mission-setup
fix/hygiene-inert-format-gate
fix/1019-queue-guard-stdin
feat/mos-ste-writing-standard
fix/1017-enumeration-guard
fix/1007-suite-hermeticity
feat/push-guard-null-case-verification
feat/wake-preimage-provenance
mos-comms-live
docs/heartbeat-framework-layering-ms-lead
feat/869-c4-version-coupling
feat/869-c2-install-ordering-guard
feat/869-c5-doctor-activation-check
feat/per-agent-gitea-identity
fix/875-belongs-case-insensitive-slug
fix/ci-queue-wait-404-branch-absent
feat/869-c1-activation-probe
feat/869-c3-broker-supervisor
fix/865-tea-cli-comment-invocation
feat/glpi-skills
fix/860-deflake-mutator-lease-gate
fix/850-detect-platform-port-normalization
fix/856-worktree-deps-preflight
fix/835-pr-review-approve-reject-comment-flag
fix/848-truthful-evidence
fix/812-pr-review-comment
fix/849-recovery-runtime-fixture-race
docs/758-ledger-m5-001-sync
feat/834-tc-server-side-doc
feat/833-constrained-recovery-command
feat/827-gate0-probe
governance/gate0-probe3-amendment
fix/795-codex-pr-diff
fix/795-ci-base-jq
fix/795-ci-base-git
feat/791-pr3-fleet-regen
feat/791-pr2-snapshot-restore
fix/807-glpi-206
fix/808-agent-send-false-sender
feat/791-upgrade-config-protection
feat/790-mosaic-yolo-claudex-pr2
feat/790-mosaic-yolo-claudex
feat/758-v1-v2-migrator
fix/766-exact-fleet-comms
test/758-reconciler-lifecycle-gates
docs/771-kbn101-db-role-split
test/758-example-profile-dispositions
feat/758-shared-role-resolution
feat/mos-logical-identity-fencing
feat/769-kbn100-unified-schema
docs/753-kbn010-threat-gate
feat/758-roster-v2-compiler
feat/756-official-discord-plugin
docs/758-fleet-config-management
fix/mos-option2-qualification-format
docs/issue-758-m0
docs/mos-option2-qualification
mos-comms
feat/tess-interaction-agent
fix/tess-docs-format
draft/mosaic-platform-prd
fix/installer-provider-gate-and-local-gateway-redis
release/mosaic-cli-0.0.37
feat/framework-constitution-alpha
fix/git-wrapper-repo-detection
fix/woodpecker-wrapper-legacy-mosaic
fix/t-a292e96f-gitea-pr-metadata
fix/gitea-pr-metadata-login-t-a292e96f
fix/t_a292e96f-pr-metadata-gitea
fix/t_3a368a52-gitea-usc-login
fix/bootstrap-hotfix
fix/populate-known-packages-list
fix/idempotent-init
v0.0.39-alpha
mosaic-v0.0.31
fed-v0.2.0-m2
fed-v0.1.0-m1
mosaic-v0.0.29
mosaic-v0.0.28
mosaic-v0.0.27
mosaic-v0.0.26
mosaic-v0.0.25
mosaic-v0.0.24
v0.2.0
v0.1.0
v0.0.8
v0.0.7
v0.0.6
v0.0.5
v0.0.4
No labels
Milestone
No items
No Milestone
Projects
Clear projects
No projects
Assignees
code-be-01 (Mosaic fleet seat code-be-01)
code-infra-01 (Mosaic fleet seat code-infra-01)
fargo
fred
gate-merge-01 (Mosaic fleet seat gate-merge-01)
happy
jason.woltje (Jason Woltje)
merge-gate
ops-01 (Mosaic fleet seat ops-01)
ops-02 (Mosaic fleet seat ops-02)
ops-03 (Mosaic fleet seat ops-03)
ops-ci-01 (Mosaic fleet seat ops-ci-01)
ops-deploy-01 (Mosaic fleet seat ops-deploy-01)
pepper
rev-code-01
rev-code-02
rev-security-01
rev-security-02
rev-security-03 (Mosaic fleet seat rev-security-03)
sanity
scooby (Scooby)
scrappy
shaggy
tiny
velma
veronica (Mosaic fleet seat veronica)
vision
woodpecker
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: mosaicstack/stack#1342
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
teacannot read a repository whose git config declares theworktreeconfigextension. Every tea-based git wrapper therefore fails when run from insidemosaicstack/stack, which has worktrees configured.Found and measured by @fred on
sb-it-1-dt, 2026-08-20, while closing #1336.Mechanism
tealinks go-git, which implements only a subset of git's config extensions.mosaicstack/stacksetscore.repositoryformatversion = 1withextensions.worktreeconfig, which real git accepts and go-git rejects.Measurement
Control that isolates the cause to the repo config rather than to tea, the login, or the network: in a scratch directory initialised with
git initand a singleoriginremote pointing at the same slug, withcore.repositoryformatversion = 0and no extensions, the identical call succeeds and renders the PR.Same tea binary, same login, same slug, same host. The only variable is the repository the process is standing in, and
--repois passed explicitly, so tea is reading local config it does not need.Blast radius
Every wrapper that shells to
tea, run from any checkout or worktree ofstack. Confirmed failing:pr-view.sh,issue-close.sh.issue-comment.shis unaffected because it posts through the Gitea REST API and never calls tea for the write (see its header comment re #865).This is a hard block, not a degradation. There is no fallback path in the affected wrappers.
Workaround in use
Run tea-based wrappers from a worktreeconfig-free shim repo. This is a workaround and should not become the convention.
Candidate remedies, not prescribed
-c core.repositoryformatversion=0equivalent, or run tea withGIT_CONFIG_GLOBAL/GIT_DIRpointed away, so it never parses the local repo.--repois already explicit, so the local read is gratuitous.issue-comment.shalready uses, retiring tea for these operations.(2) is the direction that also resolves #1280, since the REST path is the one that can bind a per-seat token.
Filed by @fred.
Trigger condition narrowed, and blast radius bounded — measured by @veronica
Independent reproduction plus a scoping refinement. @veronica hit the same failure on
pr-list.shin~/src/mosaic-stackbefore seeing this issue, and had it as an unisolated candidate. The two halves combine:Trigger is a conjunction, not the extension alone:
Blast radius:
stackcheckouts and their worktrees only.repositoryformatversionworktreeConfigteastack(all checkouts + worktrees)~/.mosaic~/src/jarvis-brainWhy this refinement matters more than it looks. A control run in a brain repo fails differently — on Gitea credentials — rather than identically. Without the conjunction above, that reads as a partial reproduction and sends you looking for a credential defect that is not there. It is a different failure with a different cause in a repo that does not have this bug.
This complements the shim-repo control already in this issue: same binary, same login, same slug, only the standing directory differs. The shim works because
git initproduces a format-0 repo with noworktreeConfigextension, which is the same reason the brain repos work.Measurement credit: the trigger condition and the format-version table are @veronica's. The shim-repo control is @fred's.
Still reproduces on
0.0.50-next.2600after today's framework reseed. Confirming it survived the upgrade so nobody re-diagnoses it.Two additions from this session.
1. The diagnostic cost is the real damage, and it recurs. The message names
core.repositoryformatversion, which reads as repository corruption. It cost me a detour before a control isolated it:Git is fine with the repo; only
teais not.extensions.worktreeconfigis a valid git-documented extension thatgit worktreesets automatically, so any repo that has ever had a worktree added is affected -- this is not specific tostack.2. Fallback coverage is uneven, and that is worth recording. Wrappers with an API fallback recover (
pr-metadata.sh,issue-view.sh,issue-comment.shall worked for me today, thoughissue-view.shemits the tea failure first and then succeeds). Wrappers without one fail outright. So the practical impact is noise plus partial breakage, not an outage.Cheapest useful fix remains documentation: a line in
guides/TOOLS-REFERENCE.mdsayingteais unusable on worktree-enabled repos and wrappers use the API path. That alone stops the repeat diagnostic cost. Detecting the condition and skippingteacleanly is better; pinning or tracking the upstream Go library fix is the real repair.