Skip to content

[checkpoints] Prevent data loss when restoring a missing checkpoint - #22

Merged
simurg79 merged 1 commit into
mainfrom
fix/checkpoint-restore-missing-commit
Sep 24, 2026
Merged

simurg79 merged 1 commit into
mainfrom
fix/checkpoint-restore-missing-commit

Conversation

@simurg79

Copy link
Copy Markdown
Owner

What is the problem?

Restoring a checkpoint deleted untracked workspace files before checking whether the saved commit existed. If the checkpoint repository was deleted, recreated, pruned, or damaged, cleanup succeeded but the reset failed, permanently losing uncommitted user work.

How does this PR solve the problem?

Checks that the target commit exists before any workspace-mutating command. A missing commit now raises an error explaining that the checkpoint no longer exists and that no files were changed. Existing logging, error events, and rethrow behavior are preserved. Valid restores retain their existing behavior.

The supplied audit found that restoreCheckpoint is the only path running destructive Git commands against commit hashes from saved task messages. Branch deletion already validates branch names with branchLocal() and leaves core.worktree unset. Diff/show paths are read-only. The core checkpoint restore wrapper and webview edit/delete-message flows delegate to restoreCheckpoint and are protected transitively.

Only the checkpoint service and its two new tests are included. No unrelated files or changeset are included; no mandatory changeset requirement was found in this fork.

How did you test the PR?

cd src && npx vitest run services/checkpoints

Implementation-session result supplied with this change: exit 0, 2 test files, 40/40 tests passed. Tests cover preserving untracked files and tracked edits when the commit is missing, and restoring a valid commit normally. Tests were not rerun during PR preparation. The commit hook passed all 10 lint tasks.

Agent notes

Base: 4bf5874 (simurg79/Roo-Code main).
Preflight uses git cat-file -e ^{commit} before git clean -f -d -f and git reset --hard.
The patch is submitted unchanged.

@simurg79
simurg79 merged commit 19cd7a8 into main Sep 24, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant