Skip to content

Share console shell cwd and environment with approved host tools - #252

Merged
AetherAI3 merged 1 commit into
mainfrom
fix/245-shared-shell-session
Oct 1, 2026
Merged

AetherAI3 merged 1 commit into
mainfrom
fix/245-shared-shell-session

Conversation

@AetherAI3

@AetherAI3 AetherAI3 commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

Typing !cd subdir previously lost its cwd and environment before the next command. The Linux/macOS coding console now owns one Bash session shared with approved local-model shell tools. File tools remain relative to the separate workspace root.

Closes #245. Builds on merged #251 / #244. Interactive PTY ownership remains #246.

Implementation

  • Preserve cwd, exports, variables and functions in /bin/bash --noprofile --norc; keep the initial credential-free child environment and existing model approval gates.
  • Serialize user/model shell and file operations through a FIFO host slot. Tag shell operations with origin/session/command IDs; show real cwd in the prompt and approvals. Bind approvals to session/cwd/state revision and refuse stale approvals.
  • Keep root-relative file resolution and traversal/symlink guards. Refuse ordinary cd escapes; lose the session if a command ends outside the approved workspace. Arbitrary shell authority remains the operator's existing authority, not an OS sandbox.
  • Reset shell/ownership on checkout changes and create fresh sessions after worktree selection. Crash, exit, timeout and cancellation lose state visibly; /shell-reset starts fresh without command replay.
  • Fingerprint model/user mutations between operations. Automatic git commits exclude intervening user edits and mixed files. Nested-workspace staging uses repo-relative names and checks the whole index to avoid committing staged user work outside that subtree.
  • Extend [feature] Console: run !commands locally and return cleanly to chat #244's single classifier/controller, typed queues, bounded /shell-result sharing and streaming output. Multiline TTY shell paste is now one Bash command. Preserve fresh cmd.exe behavior on Windows.

Validation

  • npm test: 2,914 total; 2,903 passed, 11 skipped, 0 failed (166.5 seconds).
  • 65 focused shell/console/Git/approval/picker tests passed before the full-suite run. Includes real Bash processes, project/worktree switches, failed cd/symlink escape, crashes, cancellation/tree cleanup, simultaneous submissions, stale approvals, user edits and nested staged-index refusal.
  • npm run typecheck, npm run lint, npm run docs:check, npm run verify:production, npm run release:truth, npm pack --dry-run, and git diff --check passed. Production verification installed/launched the exact packed CLI; release truth passed 12/12.
  • npm run smoke was attempted: 2 passed, 4 skipped, 1 failed because restricted DNS cannot resolve example.com for the live web-fetch probe. That probe is not claimed as passing.
  • GitHub source tree matches the locally tested tree exactly: f100d382700c4d436492c0ae4d00952c7fdd664c.

Review limits

Linux Bash integration was exercised locally. macOS/Windows were not exercised live. Hosted CI for this exact PR head was attempted: CI run 36864228720 and CodeQL run 36864228795 failed before any job steps. All five required-job annotations say the account is locked due to a billing issue. The Aether Hosted Build & Test check is neutral because its approved executor image is unavailable (0 tests run). These checks are not claimed as passing. No workflow/ruleset changes are included.

No PTY/interactive stdin or Online/ATS authority was added. Attribution is conservative per file between serialized operations; it is not a filesystem lock against unrelated writers during a model command.

Preserve workspace-relative file tools, serialize local execution, bind approvals to session state, and exclude intervening user edits from automatic commits.

@AetherAI3 AetherAI3 left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Completion review of head 615c3a3 (author review, not an independent approval): rechecked #245 against the implementation, documentation and real-process integration tests. Persistent Bash cwd/exports/functions are shared through one serialized host executor; model approval remains required and is bound to the displayed session state. File tools retain the workspace root. Checkout/worktree changes discard session state, and crash/cancel/reset never replay commands. Conservative ownership excludes user and mixed edits, with whole-index protection for nested workspaces. All stated acceptance scenarios are covered. No remaining source blocker found for #245.

The exact uploaded tree f100d382700c4d436492c0ae4d00952c7fdd664c passed the full local suite: 2,903 passed, 11 skipped, zero failed; typecheck, lint, generated docs, production package install/launch, release truth (12/12), pack dry run and diff checks passed. The live web-fetch smoke probe failed because this environment cannot resolve example.com. macOS/Windows live execution remains unverified.

Hosted CI/CodeQL for this head did not execute: all five required job annotations explicitly report the account billing lock. The separate hosted check is neutral because the approved executor image is unavailable. No checks are represented as green, and no workflow or protection settings were changed. Proceeding with the user's authorized landing on the recorded local evidence if GitHub permits the merge. #244 is already completed by #251; #246 is incomplete and stays open.

@AetherAI3
AetherAI3 merged commit 892b27b into main Oct 1, 2026
2 of 7 checks passed
@AetherAI3
AetherAI3 deleted the fix/245-shared-shell-session branch October 1, 2026 12:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[feature] Shell: share session cwd and environment between user and agent commands

1 participant