Share console shell cwd and environment with approved host tools - #252
Conversation
Preserve workspace-relative file tools, serialize local execution, bind approvals to session state, and exclude intervening user edits from automatic commits.
AetherAI3
left a comment
There was a problem hiding this comment.
Completion review of head 615c3a3 (author review, not an independent approval): rechecked #245 against the implementation, documentation and real-process integration tests. Persistent Bash cwd/exports/functions are shared through one serialized host executor; model approval remains required and is bound to the displayed session state. File tools retain the workspace root. Checkout/worktree changes discard session state, and crash/cancel/reset never replay commands. Conservative ownership excludes user and mixed edits, with whole-index protection for nested workspaces. All stated acceptance scenarios are covered. No remaining source blocker found for #245.
The exact uploaded tree f100d382700c4d436492c0ae4d00952c7fdd664c passed the full local suite: 2,903 passed, 11 skipped, zero failed; typecheck, lint, generated docs, production package install/launch, release truth (12/12), pack dry run and diff checks passed. The live web-fetch smoke probe failed because this environment cannot resolve example.com. macOS/Windows live execution remains unverified.
Hosted CI/CodeQL for this head did not execute: all five required job annotations explicitly report the account billing lock. The separate hosted check is neutral because the approved executor image is unavailable. No checks are represented as green, and no workflow or protection settings were changed. Proceeding with the user's authorized landing on the recorded local evidence if GitHub permits the merge. #244 is already completed by #251; #246 is incomplete and stays open.
Typing
!cd subdirpreviously lost its cwd and environment before the next command. The Linux/macOS coding console now owns one Bash session shared with approved local-model shell tools. File tools remain relative to the separate workspace root.Closes #245. Builds on merged #251 / #244. Interactive PTY ownership remains #246.
Implementation
/bin/bash --noprofile --norc; keep the initial credential-free child environment and existing model approval gates./shell-resetstarts fresh without command replay./shell-resultsharing and streaming output. Multiline TTY shell paste is now one Bash command. Preserve fresh cmd.exe behavior on Windows.Validation
npm test: 2,914 total; 2,903 passed, 11 skipped, 0 failed (166.5 seconds).npm run typecheck,npm run lint,npm run docs:check,npm run verify:production,npm run release:truth,npm pack --dry-run, andgit diff --checkpassed. Production verification installed/launched the exact packed CLI; release truth passed 12/12.npm run smokewas attempted: 2 passed, 4 skipped, 1 failed because restricted DNS cannot resolve example.com for the live web-fetch probe. That probe is not claimed as passing.f100d382700c4d436492c0ae4d00952c7fdd664c.Review limits
Linux Bash integration was exercised locally. macOS/Windows were not exercised live. Hosted CI for this exact PR head was attempted: CI run 36864228720 and CodeQL run 36864228795 failed before any job steps. All five required-job annotations say the account is locked due to a billing issue. The Aether Hosted Build & Test check is neutral because its approved executor image is unavailable (0 tests run). These checks are not claimed as passing. No workflow/ruleset changes are included.
No PTY/interactive stdin or Online/ATS authority was added. Attribution is conservative per file between serialized operations; it is not a filesystem lock against unrelated writers during a model command.