Skip to main content
nono can take filesystem snapshots before and after sandboxed execution, allowing you to review and reverse any changes an agent made. The rollback system uses content-addressable storage with SHA-256 deduplication and Merkle tree integrity verification. The idea is that if an agent makes unintended changes to your filesystem, you can easily see what changed and restore any modified or deleted files back to their original state. This provides a safety net when running powerful agents that have write access to your files.

How It Works

When you run a command with --rollback, nono:
  1. Takes a baseline snapshot of all files in tracked directories before the command starts
  2. Runs the command inside the sandbox
  3. Takes a final snapshot after the command exits
  4. Shows an interactive diff of all changes, offering to restore any modified or deleted files
--rollback automatically selects supervised execution because the parent process needs to remain unsandboxed to write snapshots to $XDG_STATE_HOME/nono/rollbacks/ (default ~/.local/state/nono/rollbacks/).

Snapshot Architecture

Content-Addressable Object Store

Files are stored by their SHA-256 hash, so identical content is never stored twice. On macOS with APFS, nono uses clonefile() for copy-on-write storage - snapshots consume minimal additional disk space when files haven’t changed.

Merkle Tree Integrity

Each snapshot builds a Merkle tree over all tracked files. The root hash provides a cryptographic commitment to the exact filesystem state at that point in time. This allows:
  • Verifying that no snapshot data has been tampered with
  • Detecting corruption in stored objects
  • Efficient comparison between snapshots (only recompute changed subtrees)

Session Structure

Sessions are stored in $XDG_STATE_HOME/nono/rollbacks/ (default ~/.local/state/nono/rollbacks/). Older installs may still have data under ~/.nono/rollbacks/; nono reads that path with a deprecation warning until v1.0.0. Layout:
Session IDs use the format YYYYMMDD-HHMMSS-PID (e.g., 20260214-143022-12345).

Exclusion Filters

Not every file needs tracking. The rollback system respects:
  • Profile-defined patterns: Common build artifacts like node_modules, .next, __pycache__, target
  • Profile-defined globs: Patterns like *.tmp.[0-9]*.[0-9]*
  • gitignore integration: Reads .gitignore patterns from the working directory
These exclusions keep snapshots fast and storage efficient.

Commands

nono rollback list

List past sessions grouped by project directory.
Example output:

nono rollback show

Inspect the changes made during a session.

nono rollback restore

Restore files from a past session to their pre-change state.
Restoration uses atomic rename per file to prevent partial restores.

nono rollback verify

Verify the integrity of a stored session by recomputing Merkle tree hashes and checking all objects in the store.
Reports any missing objects, hash mismatches, or corrupted metadata.

nono rollback cleanup

Remove old sessions to reclaim disk space.

Interactive Post-Exit Flow

When a --rollback command exits and file changes are detected, nono presents an interactive review:
  1. Shows a summary of all changes (created, modified, deleted files)
  2. Offers to show diffs for individual files
  3. Asks whether to restore some or all files
Use --no-rollback-prompt to suppress the interactive UI while still taking snapshots (useful for scripting).

Storage Management

Configure these in your nono config file or use nono rollback cleanup for manual management.

Profile Rollback Configuration

Profiles can customize rollback behavior:
These exclusions are combined with gitignore patterns from the working directory.