Skip to content

Refuse unattended purge of a non-empty nested Workspace - #175

Merged
BrettKinny merged 3 commits into
mainfrom
fix/purge-workspace-guard
Oct 1, 2026
Merged

BrettKinny merged 3 commits into
mainfrom
fix/purge-workspace-guard

Conversation

@BrettKinny

Copy link
Copy Markdown
Collaborator

Problem

uninstall.sh --purge --yes / uninstall.ps1 -Purge -Yes silently deleted the default Workspace at $INSTALL_DIR/workspace (user project files). The "Recorded Workspace contains N item(s)" warning only ran in interactive mode, and the pre-confirmation summary never listed the Workspace.

Change (both adapters, aligned)

  • The Workspace is inspected once, before the summary; inspection failure aborts with nothing removed.
  • The summary lists a non-empty Workspace inside the install directory: - Workspace inside install directory (N item(s)): <path>.
  • --purge --yes (-Purge -Yes) with a non-empty nested Workspace now refuses (exit 1, clear message) before any destructive operation unless --delete-workspace (-DeleteWorkspace) is passed.
  • An empty Workspace, or an external Workspace (always preserved), needs no flag.
  • The interactive path keeps its existing second Continue? [y/N] prompt.
  • --delete-workspace without --purge is rejected (bash exit 64; PowerShell Abort).
  • Usage text, README uninstall section, and docs/releases/v1.3.0.md are updated.

The v1.3.0 release notes also say that existing Boxes get the new --pids-limit=4096 bound only once the Box is recreated (sqrbx-rebuild, re-running the installer, or docker compose up -d for Compose).

Tests

  • tests/test-lifecycle-ownership.sh: with a non-empty nested Workspace, unattended purge refuses (exit 1), lists the Workspace in the summary, and leaves the Workspace files, Install identity, shell adapter, and rc sentinel in place. The mock runtime records no rm, rmi, or volume rm call. The test also checks that --delete-workspace without --purge exits 64, that --delete-workspace purges, and that an empty nested Workspace needs no flag. I confirmed it fails against the old uninstall.sh.
  • tests/test-lifecycle-powershell.ps1: a static assertion plus a behavioral refusal check (summary text, files kept, no destructive runtime calls) and a successful -DeleteWorkspace purge, using the mock runtime harness. I ran it locally in mcr.microsoft.com/powershell via podman: it passes, and it fails against the old uninstall.ps1.
  • tests/test-lifecycle-static.sh: greps for the new flag and the new summary line in both adapters.
  • Full host suite: all 19 tests/test-*.sh pass.

🤖 Generated with Claude Code

BrettKinny and others added 3 commits October 1, 2026 12:15
`uninstall.sh --purge --yes` and `uninstall.ps1 -Purge -Yes` silently
deleted the default Workspace at <install dir>/workspace because the
Workspace warning was gated on interactive mode and the summary never
listed it.

Both adapters now count the Workspace once, list a non-empty nested
Workspace (with item count) in the pre-confirmation summary, and refuse
unattended purge before any destructive operation unless
--delete-workspace / -DeleteWorkspace is passed. Empty or external
Workspaces need no flag; the interactive prompt is unchanged. The new
flag requires --purge.

Also document in the v1.3.0 release notes that the --pids-limit=4096
bound only reaches an existing Box when it is recreated.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@BrettKinny
BrettKinny merged commit 93aa925 into main Oct 1, 2026
4 checks passed
@BrettKinny
BrettKinny deleted the fix/purge-workspace-guard branch October 1, 2026 04:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant