Skip to content

[feature] Shell: share session cwd and environment between user and agent commands #245

Description

@AetherAI3

Gap

A user cannot navigate once and have the next local command use that directory. ToolExecutor.run starts a fresh /bin/sh for every call with cwd: this.root; the executor root is fixed at construction. Shell cd, export and shell functions disappear when that child exits.

Deliverable

  • Introduce an explicit console-owned shell session with a selected supported Linux shell, observable current directory and documented environment/state persistence. Share it with user ! submissions and model shell tools only through the local host and existing approval gates.
  • Serialize execution and tag each command with user/model origin, session ID and command ID. Keep the authoritative workspace boundary separate from the current shell directory; explicitly define relative file-tool resolution and reject unapproved workspace changes.
  • Reset/reconcile state when changing checkout or creating a coding worktree. Never reuse a previous project's cwd/environment accidentally. Show the real cwd in the prompt and approval screen.
  • Track user mutations separately from agent-owned edits so automatic commit ownership does not sweep in the user's intervening work.
  • Recover visibly from shell exit/crash; do not silently restart with supposedly preserved state. Never automatically replay a mutating command.

Acceptance

Within an allowed workspace, !cd subdir followed by !pwd and an approved model command use the same cwd. A harmless exported variable persists as documented. Test project/worktree switch, failed cd, shell crash, simultaneous user/model submissions, cancellation and user edits between agent turns. Commit ownership excludes unrelated user changes.

Priority: P1. Depends on the console shell routing issue. This is local session control, separate from Online/ATS authority.

Related: #244.

Activity

  1. AetherAI3 commented on Oct 1, 2026

    @AetherAI3
    OwnerAuthor

    Completion review — 2026-10-01

    Verdict: not complete on current main 64631218cb3f68c8f08e6e6532b27b2afe4e6b54; keep this issue open. #244/#251 delivered local command routing, not persistent shared shell state. No implementing PR or completion evidence for #245 was found in this review.

    Concrete evidence:

    • ConsoleShell stores a readonly cwd and constructs a new ToolExecutor for every user command.
    • ToolExecutor.run still spawns a fresh /bin/sh (cmd.exe on Windows), always with cwd set to the executor root. A command's cd/export/function state is lost on exit.
    • User ConsoleShell and model executors are separate objects. The typed console queue serializes submissions, but it does not supply a shared persistent shell, session/command identity or reconciliation of user mutations with agent commit ownership.
    • Current console tests cover routing and per-command execution; they do not prove persistent cd/export, shared model-command cwd, session recovery or intervening user-edit ownership.

    Remaining closure checklist:

    1. One console-owned shell session shared by explicit user commands and approved model commands, with visible authoritative cwd and documented state persistence.
    2. Serialized user/model execution tagged by origin, session and command; file-tool relative-path/workspace semantics explicitly defined.
    3. Visible reset/recovery on project/worktree change or shell crash, no automatic mutation replay, and cwd shown in prompt/approval.
    4. Commit ownership excludes unrelated user edits made between agent turns.
    5. Exact-head tests for !cd subdir → !pwd → approved model command, harmless export persistence, failed cd, cancellation, crash, simultaneous submissions and worktree switch; record local-suite results.

    This was a source/evidence review, not a fresh local test run. #251's passing suite is evidence for #244 and cannot close #245. PTY support remains separately scoped to #246.

  2. AetherAI3 commented on Oct 1, 2026

    @AetherAI3
    OwnerAuthor

    Implementation and acceptance review completed in ready-for-review PR #252, head 615c3a3. This supersedes the earlier assessment of main before this implementation existed.

    The PR supplies the console-owned Bash session, shared approved local-model execution, FIFO origin/session/command tagging, separate workspace/file root, visible cwd, stale-approval refusal, checkout/worktree reset, explicit recovery without replay, and conservative user-versus-model commit ownership. Real Bash integration tests cover the issue's acceptance scenarios, including intervening user edits and nested-workspace staged-index refusal.

    Full local suite: 2,903 passed, 11 skipped, zero failures. Typecheck/lint/docs/production package verification/release truth/pack dry run passed. The live web-fetch smoke probe is blocked by DNS. Hosted CI jobs for #252 were not started because the account is locked due to billing; platform CI is not claimed as passing. Full evidence and limits are recorded in the PR review/body.

    Landing the exact tested head under the user's authorization; this issue will close only after the merge is confirmed. #246 remains a separate unfinished PTY feature.

  3. AetherAI3 commented on Oct 1, 2026

    @AetherAI3
    OwnerAuthor

    Closed as completed after PR #252 merged into main at 892b27b. Verified the landed source tree is exactly f100d382700c4d436492c0ae4d00952c7fdd664c, the locally tested tree (2,903 passed, 11 skipped, 0 failed). Review and validation limits are recorded on the PR, including the hosted-CI billing lock and DNS-dependent smoke probe.

    Final related-issue disposition: #244 is already completed by #251; #245 is now completed by #252; #246 remains open because interactive PTY stdin, resize and terminal ownership have not been implemented. No claim that #246 is complete.

  4. AetherAI3 commented on Oct 1, 2026

    @AetherAI3
    OwnerAuthor

    Follow-up review and closure confirmation — 2026-10-01

    Verdict: #245 is now complete for its documented Linux shell-session scope. This supersedes my earlier incomplete verdict at main 6463121. PR #252 has already landed at main 892b27b405964b779b7a7d7215f3458278a3f038; the current tree is f100d382700c4d436492c0ae4d00952c7fdd664c, exactly the tree recorded as locally tested. The issue is closed with reason completed.

    Reviewed the landed ShellSession, ConsoleShell, ToolExecutor, WorkspaceOwnership, chat/code integration and acceptance tests. The previous gaps are addressed:

    • One console-owned Bash process retains cwd, exports and functions and is reused by approved local-model shell calls.
    • FIFO host slots serialize operations; command events identify origin/session/command. File tools remain rooted at the separate workspace boundary.
    • The prompt and approval flow use actual cwd; execution refuses stale session/cwd/revision approval context.
    • Checkout/worktree changes reset state; crashes/cancellation lose state visibly and /shell-reset recovers without replay.
    • Per-file mutation attribution excludes unrelated user changes and mixed files from automatic commits; the nested-index guard covers staged work outside the selected subtree.

    Real Bash acceptance-test source covers persistent cd/export/functions, failed cd, project/worktree changes, concurrent submissions, cancellation/crash, stale approval and intervening user edits. PR #252 records 2,903 passed, 11 skipped, zero failures, with typecheck/lint/docs/packed-production/release checks passing. I reviewed this exact merged source and recorded evidence; I did not rerun the entire suite in this follow-up and did not create a redundant replacement PR.

    No additional blocking finding emerged in this scoped review. Keep #245 closed. Qualification limits remain explicit: macOS/Windows were not exercised live; hosted CI/CodeQL did not start due to billing lock; the live web-fetch smoke probe failed on restricted DNS. Interactive PTY ownership/input/resize remains unfinished under #246, and attribution is not a filesystem lock against concurrent external writers.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions