github / github/spec-kit

[Bug]: create-new-feature.sh reserves feature numbers non-atomically — concurrent invocations can share/overwrite a spec directory

Open
#4,270 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
137k
Forks
12.3k
Avg merge
2d 12h
Merged PRs (30d)
159

Description

## Version

spec-kit v1.0.1 (`.specify/scripts/bash/create-new-feature.sh`; the flow is also described in `.claude/skills/speckit-specify/SKILL.md`, "Create the directory and spec file")

## Description

Sequential numbering scans existing `specs/` directories, picks max+1, checks for existence, then uses `mkdir -p` and writes `spec.md`. Nothing in that sequence is atomic: two concurrent invocations (parallel agents on worktrees sharing a specs dir, or two terminals) can both scan, both select the same number, both pass the existence check (`mkdir -p` succeeds either way), and both write `spec.md` into the same directory — the second silently overwrites the first's starting specification.

This matters more now that multi-agent setups routinely run more than one spec-kit session against the same repository.

## Expected behavior

Reserve the directory with plain `mkdir` (no `-p`) so creation is exclusive; on `EEXIST`, discard the selected number, rescan, and retry before writing `spec.md`. A lock file would also work.

## Related

Prior sequential-numbering issues (#935, #975, #1332) covered scan-logic bugs in single-invocation scenarios; this one is specifically about the missing atomicity under concurrency.

Contributor guide

Open the contributing guide

Research direction

Start with .specify/scripts/bash/create-new-feature.sh and trace how it scans specs/, selects a number, creates the directory, and writes spec.md. Compare the flow with the “Create the directory and spec file” section in .claude/skills/speckit-specify/SKILL.md. Done means concurrent invocations reserve different directories and neither overwrites another invocation’s spec.md.

Written by the indexing model from the issue text.

Assessment

Tech stack
bash
Domain
tooling
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Active
Clarity
Clearly specified
Newbie friendliness
72/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.