Problem
When config.json cannot be read (EACCES) or does not parse, the backend gives unclear results. The behavior is the same on main 0c5e35d816 and on the head of #5750, so that PR does not cause it. Remote UAT for #5750 found it.
workspace.getInfo returns HTTP 200 with a null body for a workspace that is still registered on disk. The renderer cannot tell "unreadable config" from "workspace removed".
- A rejected edit after an EACCES read says
the existing corrupt config has no confirmed backup yet. Fix the reported backup failure or move the corrupt file aside. The file is not corrupt. It is only unreadable, and the load log already says so.
- A second edit in the same window fails with
Workspace not found instead of the config-load reason.
When the file is readable again, the next edit succeeds without a restart. Recovery works; only the reported state is wrong.
Repro (synthetic fixture, non-root user)
- Generate a fixture:
bun scripts/perf/workspace-scale/generate-fixture.ts --root <new dir> --workspaces 4700 --projects 19 --archived 0.57 --profile realistic.
- Start
node dist/cli/index.js server --no-auth with XUM_ROOT=<new dir> and XUM_MOCK_AI=1.
chmod 000 <root>/config.json.
POST /api/workspace/updateTitle {"workspaceId": <id>, "title": "x"} returns {"success":false,"error":"...the existing corrupt config has no confirmed backup yet..."}.
POST /api/workspace/getInfo {"workspaceId": <id>} returns HTTP 200 with body null.
- A second
updateTitle returns {"success":false,"error":"Workspace not found"}.
Expected
getInfo reports a config-load error instead of null.
- The edit refusal names the real cause (unreadable file) and does not tell the user to move a corrupt file aside.
- Later edits in the window report the same config-load cause, not "Workspace not found".
Out of scope
An in-place edit that keeps inode, size and mtime stays invisible until the next save. That is the existing stat-key limit of the config snapshot, not this issue.
Refs #5750
Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: high
Problem
When
config.jsoncannot be read (EACCES) or does not parse, the backend gives unclear results. The behavior is the same on main0c5e35d816and on the head of #5750, so that PR does not cause it. Remote UAT for #5750 found it.workspace.getInforeturns HTTP 200 with anullbody for a workspace that is still registered on disk. The renderer cannot tell "unreadable config" from "workspace removed".the existing corrupt config has no confirmed backup yet. Fix the reported backup failure or move the corrupt file aside. The file is not corrupt. It is only unreadable, and the load log already says so.Workspace not foundinstead of the config-load reason.When the file is readable again, the next edit succeeds without a restart. Recovery works; only the reported state is wrong.
Repro (synthetic fixture, non-root user)
bun scripts/perf/workspace-scale/generate-fixture.ts --root <new dir> --workspaces 4700 --projects 19 --archived 0.57 --profile realistic.node dist/cli/index.js server --no-authwithXUM_ROOT=<new dir>andXUM_MOCK_AI=1.chmod 000 <root>/config.json.POST /api/workspace/updateTitle {"workspaceId": <id>, "title": "x"}returns{"success":false,"error":"...the existing corrupt config has no confirmed backup yet..."}.POST /api/workspace/getInfo {"workspaceId": <id>}returns HTTP 200 with bodynull.updateTitlereturns{"success":false,"error":"Workspace not found"}.Expected
getInforeports a config-load error instead ofnull.Out of scope
An in-place edit that keeps inode, size and mtime stays invisible until the next save. That is the existing stat-key limit of the config snapshot, not this issue.
Refs #5750
Generated with
xum• Model:anthropic:claude-opus-5-5• Thinking:high