# CODE_REVIEW: add-blast-radius-scheduler Reviewed against SPEC.md R1-R8. ## R1-R8 checklist | Req | Status | Notes | |-----|--------|-------| | R1 _ensure_worktree | PASS | Dispatches on `blast_radius.use_worktree` (default True); creates via `git worktree add`; records in state | | R2 graceful degradation | PASS | Not-a-repo, git-missing, and worktree-add-fail all return project root with WARNING | | R3 cmd_tick integration | PASS | Step 4 replaced with `cwd = _ensure_worktree(...)` | | R4 branch already exists | PASS | Retries without `-b` when stderr contains "already exists" | | R5 state consistency | PASS | Stale path cleared; state written atomically | | R6 platform paths | PASS | pathlib.Path throughout; git handles OS normalization | | R7 doc updates | PASS | technical.md section 7 updated; CHANGELOG updated | | R8 tests | PASS | 15 tests, 6 classes + regression | ## Edge cases checked 1. **`use_worktree` missing from `blast_radius`** -- defaults to `True` via `blast.get("use_worktree", True)`. PASS 2. **`blast_radius` entirely missing** -- `cfg.get("blast_radius") or {}` returns empty dict; `use_worktree` defaults True. PASS 3. **Worktree path exists but is not a git worktree** -- `git worktree add` would fail; runner falls back to project root. PASS 4. **Branch exists but worktree was deleted** -- first `git worktree add -b` fails with "already exists"; retry without `-b` succeeds. PASS 5. **`git worktree add` times out** -- `_git_run` has `timeout=15`; `subprocess.TimeoutExpired` is a `SubprocessError`, caught by `_git_run`. PASS 6. **State written before step 10** -- intentional: the worktree exists on disk, so recording it is correct even if the tick crashes later. The drift gate will check it on the next tick. PASS 7. **Concurrent ticks both creating worktree** -- TOCTOU: both might pass `worktree_path is null`, both call `git worktree add`, second one fails because the path exists. The second tick falls back to project root. Not ideal but safe (no state corruption; atomic write). Same TOCTOU class as `add-status-brakes` A6. PASS for v1. ## Code-quality observations 1. **`_git_run` is a generic wrapper** -- could be reused for other git operations in the runner. Currently only used by `_ensure_worktree`. Fine for v1. 2. **Branch name `loop/`** -- matches technical.md. If the loop name contains slashes (e.g. `ci/triage`), the branch name would be `loop/ci/triage` which git treats as a hierarchical branch. But `_is_kebab_case` in status.py rejects slashes in loop names. PASS. 3. **No worktree removal on loop deletion** -- if the user deletes a loop dir, the worktree branch remains in the repo. Worktree GC is deferred to v1.1 (BACKLOG). Accepted. ## Verdict APPROVE. Ready for bug_find.