CodeWhale Bot a02571347d lane: require verified managed-worktree identity before TTL cleanup (#5824)
TTL cleanup passed the persisted worktree_path straight to recursive
deletion: worktree_details() was consulted for git cleanup, but when it
could not identify the path, cleanup still fell through to
fs::remove_dir_all. A stale or malformed LaneRecord pointing at an
existing unrelated directory could therefore be recursively deleted the
moment its TTL hit zero.

Cleanup now requires successful managed-worktree identity before any
removal (#5824):

- worktree_details() also records every worktree the owning repository
  lists, and is_managed_worktree() verifies that the candidate path
  canonicalizes to one of those entries (still resolves to the
  identified worktree) and that its .git file names registration data
  beneath the owning repository's .git/worktrees/ (a linked, managed
  worktree of that repo — not a repo root or an unrelated subdirectory).
- An unverified path short-circuits: no git worktree remove, no prune,
  no branch deletion, no recursive delete.
- The fs::remove_dir_all fallback re-verifies identity immediately
  before running, closing the window where the directory was swapped
  between identification and removal.

Missing paths, TTL evaluation, git worktree removal, pruning, and the
merged-branch deletion policy are unchanged; nothing was deleted by the
old code path that git verified, so no existing test changed.

Fixes #5824

Gates (all pass): cargo fmt --all -- --check; clippy -p codewhale-lane
--all-targets --all-features --locked -D warnings; nextest -p
codewhale-lane --lib --profile ci: 67 tests run: 67 passed, 0 failed.
2026-09-02 13:20:20 -07:00

Codewhale

Codewhale is an open source coding agent for your terminal, built in Rust and improved in public with the people who use it.

Codewhale

简体中文 · 日本語 · Tiếng Việt · Bahasa Indonesia · 한국어 · Español · Português · Русский · Українська · Français · Deutsch · 繁體中文 · हिन्दी · Türkçe · Italiano · Polski · العربية · Català

CI crates.io npm Discord

A Codewhale terminal session

Install

npm install -g codewhale
codewhale

The first run helps you connect a provider or stay offline. Codewhale also supports Cargo, Docker, Nix, Scoop, prebuilt archives, Android/Termux, and a CNB mirror. See the installation guide.

Tab completion is one command per shell — codewhale completion bash|zsh|fish|powershell|elvish. See shell completions.

Use

Talk to Codewhale the same way you would talk to a teammate:

Fix the failing tests and explain what changed.

Or run a task without opening the TUI:

codewhale exec "fix the failing tests and explain what changed"

Codewhale can read your repository, edit files, run commands, inspect results, and keep working toward a goal. You decide how much access it has.

Why Codewhale

  • Use the model you want. Connect hosted providers or local models through Ollama, vLLM, or SGLang. Switch provider and model with /model.
  • Stay in control. Plan is read-only. Ask, Auto-Review, and Full Access make approval behavior visible. /undo reverts the last turn and /restore returns the workspace to an earlier snapshot.
  • Keep long work organized. Save sessions, set a durable /goal, review workflows before they run, and coordinate agents without turning their internal instructions into your transcript.
  • Extend the agent you already have. Connect MCP servers and skills, configure hooks, and keep agent roles as readable files in your project or personal settings.

Run /help in the TUI for commands and keyboard shortcuts.

Safety

Codewhale runs on your machine with the access you grant it. Approval modes and repository rules limit what the agent may do; optional OS sandboxing adds a stronger execution boundary where supported. Unknown model prices stay unknown instead of being reported as free.

Read authorization order for the exact policy stack and configuration for local settings.

Documentation

Join the community

Codewhale gets better when people use it, report what feels wrong, and help fix it. If a provider is missing, a workflow is awkward, or the terminal UI gets in your way, open an issue. If you know how to improve it, open a pull request. First contributions are welcome, and contributors keep credit for the work that lands.

Join the Discord, or add Hunter on WeChat (hunterbown) and ask to join the Whale Brothers group.

Project history

Codewhale began as deepseek-tui and still preserves that configuration and session compatibility. It is now provider-neutral and independently maintained; it is not affiliated with any model provider.

Thanks to every contributor and to the open source communities that helped the project grow. See the contributor record.

License

MIT. Portions adapted from other open-source projects are recorded in third-party notices.

Description
面向 DeepSeek V4 的终端原生编程智能体:100 万 token 上下文、思考模式流式推理、前缀缓存感知。自包含 Rust 二进制发布——开箱即带 MCP 客户端、沙箱和持久化任务队列
Readme MIT 378 MiB
Languages
Rust 92.9%
TypeScript 3.2%
JavaScript 1.7%
Python 1%
Shell 0.7%
Other 0.3%