Skip to content

Run explicit !commands locally in the coding console - #251

Merged
AetherAI3 merged 1 commit into
mainfrom
fix/244-local-shell-console
Oct 1, 2026
Merged

AetherAI3 merged 1 commit into
mainfrom
fix/244-local-shell-console

Conversation

@AetherAI3

@AetherAI3 AetherAI3 commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

Why

Typing !pwd previously sent a model prompt. This change runs explicit user shell submissions locally and returns to ordinary chat without spending model UVT.

Closes #244.

What changed

  • Share one classifier between TTY and line-mode submit paths before history, queueing and prompt rewriting. Support leading whitespace, \! for literal chat, empty-command guidance and explicit multiline-paste behavior.
  • Stream terminal-safe user-command output with origin, checkout, state and exit code. Reuse tree-aware cancellation and preserve the TTY type-ahead draft.
  • Keep queued submissions typed and serialize shell execution after the model/tool or slash operation. Cancellation drops pending follow-ups. Model tool validation and approval remain unchanged.
  • Exclude shell submissions/output from chat history and automatic hosted prompts. Register /shell-result as an explicit, session-only sharing action with an 8 KiB result limit; preserve the original escaped input in saved chat history.
  • Remove eager catalog warming so a shell-only TTY session makes no model/catalog API calls. Update README and generated command docs.
  • Fix a local-suite blocker: PC doctor reports denied network-interface enumeration as an unavailable metric instead of crashing, with a regression test.

Verification

  • TTY and pipe integration fixtures verify zero API calls for shell input, normal chat afterward, busy queue ordering/no duplicate execution, nonzero exit, cancellation, preserved TTY draft and explicit result sharing without implicit leakage.
  • Shared execution tests verify the chosen checkout, quoting/pipelines and bounded sharing; classifier tests cover whitespace, literal escape, empty input and multiline refusal.
  • Focused console/manifest/PC/production checks passed (51 tests before the final history/paste review).
  • Typecheck, generated-doc check, ATS source inventory and Python launcher tests (29) passed.
  • Final npm test: 2,900 tests, 2,889 passed, 11 skipped, 0 failed (146.9 seconds). Includes packed-CLI install verification.
  • Final source review: shared routing, escaped-history recall, multiline refusal, typed queues, cancellation cleanup, explicit sharing and unchanged model authority checked against [feature] Console: run !commands locally and return cleanly to chat #244.
  • Hosted CI/CodeQL could not execute: every job was rejected before its first step because the GitHub account is locked due to a billing issue. No workflow or branch-protection bypass was introduced.

Hosted run evidence: CI and CodeQL. These are infrastructure failures, not passing test evidence; Windows-hosted verification remains unavailable.

The GitHub source tree is identical to the locally tested tree: d5b4e073bb5e3d5b843d1251ce2bbdba5a296800.

Scope and risk

Explicit user shell commands have the operator's local authority. They do not grant later model execution permission. Each command uses a fresh noninteractive /bin/sh (POSIX) or cmd.exe (Windows) in the selected checkout. Online managed-agent DMs are unchanged.

Persistent cwd/environment remains tracked by #245; interactive PTY handoff remains tracked by #246. Large captured-output tail/UTF-8 improvements remain tracked by #247. No new duplicate follow-up issues were opened. Cross-repository ATS execution parity requires a separate ATSv2 checkout and is outside this console change.

Route typed shell input before history, prompt rewriting and queueing. Preserve cancellation, typed queues and explicit bounded result sharing. Report unavailable PC interface metrics without crashing diagnostics.
@AetherAI3
AetherAI3 marked this pull request as ready for review October 1, 2026 12:19

@AetherAI3 AetherAI3 left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Implementation self-review against #244 completed at a15eed2 (not an independent approval).

Checked both submit surfaces, routing before history/rewrite, typed busy queue serialization, explicit user origin/cwd/status/output/exit, shell cancellation and draft restoration, escaped literal history recall, multiline refusal, absence of implicit shell-output sharing, bounded explicit /shell-result, history opt-out and unchanged model validation/permission gates. No blocking source finding remains from this review.

Final local npm test: 2,900 total; 2,889 passed; 11 skipped; zero failed. Typecheck, generated-doc validation, packed CLI install, ATS source inventory and 29 Python launcher tests also passed. GitHub tree d5b4e073bb5e3d5b843d1251ce2bbdba5a296800 matches the locally tested source exactly.

CI and CodeQL were rejected before their first step with: 'The job was not started because your account is locked due to a billing issue.' Hosted Windows and CodeQL proof is unavailable. This PR does not weaken workflow policy or branch protections.

#245 retains persistent cwd/environment; #246 retains interactive PTY work; #247 retains capture-tail/UTF-8 improvements. Those are separate work and should remain open.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[feature] Console: run !commands locally and return cleanly to chat

1 participant