Files
kshitijk4poor da2b64304b fix(lsp): no automatic trust for scheduled work; lock-free trust lookups
Re-review of the trust-anchor follow-up:

- Cron runs and Kanban workers no longer anchor trust. The cronjob tool
  lets the model pick a job's workdir, which becomes the run's session
  cwd, and kanban_create lets it pick a task workspace, which becomes the
  worker's launch dir and TERMINAL_CWD. Either one let an agent-cloned
  repo become trusted. Both now rely on lsp.trusted_workspaces only.
- A repository at or above $HOME never anchors, not only one at $HOME
  exactly.
- Operator roots are recorded only where a tool thread enters
  (enabled_for) and when the service is created. _trusted() is now a pure
  read. Before, it took _state_lock while two of its callers already held
  it, so a change in the roots could deadlock the LSP loop.
- Client lookups go through _live_key(). A multi-root client that
  started while its root was untrusted is still found and released after
  the root becomes trusted, instead of being orphaned.
- `hermes lsp status` stops listing roots that have since become trusted.
  The lint gate reads the cwd the same way the linter subprocess does.
- The path-list parser returns None for a malformed value, and each key
  logs its own warning. The _node_modules_trees docstring no longer
  mentions Vue.
2026-09-29 03:28:46 +05:30
..