Repository navigation
Conversation
There was a problem hiding this comment.
Copilot review overview
馃煛 Changes recommended
Alternate-home attachment and live token accounting still contain concrete lookup and confinement gaps.
Review effort: Balanced
Findings: 2
Open (4)
What changed in this PR
Adds trusted multi-home agent session support, carrying agent-home metadata through adoption, transcript processing, review, and attachment workflows.
Changes:
- Adds a bounded registry of known agent homes and per-agent home/layout providers.
- Introduces symlink-safe transcript, offset, subagent, and token-usage reads.
- Extends adoption and attach discovery with comprehensive regression coverage.
| File | Description |
|---|---|
docs/鈥媎evelopment/鈥媐ilesystem-safety.md |
Documents agent-home trust and confinement. |
cmd/鈥媏ntire/鈥媍li/鈥媡ranscript.go |
Searches active and recorded homes. |
cmd/鈥媏ntire/鈥媍li/鈥媠trategy/鈥媡ranscript_offset_pending_test.go |
Updates prompt helper calls. |
cmd/鈥媏ntire/鈥媍li/鈥媠trategy/鈥媝hase_postcommit_test.go |
Tests confined finalization reads. |
cmd/鈥媏ntire/鈥媍li/鈥媠trategy/鈥媘anual_commit_session.go |
Records and refreshes agent homes. |
cmd/鈥媏ntire/鈥媍li/鈥媠trategy/鈥媘anual_commit_hooks.go |
Confines hook transcript processing. |
cmd/鈥媏ntire/鈥媍li/鈥媠trategy/鈥媘anual_commit_condensation.go |
Propagates homes through condensation. |
cmd/鈥媏ntire/鈥媍li/鈥媠trategy/鈥媗ate_flush_prompt_test.go |
Tests confined late-flush prompts. |
cmd/鈥媏ntire/鈥媍li/鈥媠trategy/鈥媓ooks_test.go |
Tests main and subagent confinement. |
cmd/鈥媏ntire/鈥媍li/鈥媠trategy/鈥媍ondensation_prompts_test.go |
Updates home-aware prompt tests. |
cmd/鈥媏ntire/鈥媍li/鈥媠trategy/鈥媋gent_home_record_test.go |
Tests home recording and refresh. |
cmd/鈥媏ntire/鈥媍li/鈥媠ession/鈥媠tate.go |
Adds persisted AgentHome. |
cmd/鈥媏ntire/鈥媍li/鈥媠ession_adopt.go |
Authorizes and canonicalizes adopted paths. |
cmd/鈥媏ntire/鈥媍li/鈥媠ession_adopt_agent_home_test.go |
Covers adoption trust and symlinks. |
cmd/鈥媏ntire/鈥媍li/鈥媟eview/鈥媘anifest.go |
Confines review transcript reads. |
cmd/鈥媏ntire/鈥媍li/鈥媟eview/鈥媍md_test.go |
Isolates Codex home in tests. |
cmd/鈥媏ntire/鈥媍li/鈥媍heckpoint/鈥媝ersistent.go |
Documents remaining unconfined fallback. |
cmd/鈥媏ntire/鈥媍li/鈥媍heckpoint/鈥媏phemeral.go |
Documents task fallback constraints. |
cmd/鈥媏ntire/鈥媍li/鈥媋ttach.go |
Adds alternate-home transcript discovery. |
cmd/鈥媏ntire/鈥媍li/鈥媋ttach_test.go |
Updates transcript resolver tests. |
cmd/鈥媏ntire/鈥媍li/鈥媋ttach_altHome_test.go |
Tests alternate-home lookup behavior. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媢nconfined_transcript_read_guard_test.go |
Ledgers unconfined transcript reads. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媡ranscript_position_confinement_test.go |
Tests confined offset counting. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媡ranscript_file.go |
Adds rooted transcript readers. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媡ranscript_file_test.go |
Tests transcript read confinement. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媡oken_usage.go |
Adds confined token accounting API. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媠ession_store.go |
Adds no-follow file opening. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媟egistry.go |
Exposes containment checking. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媝i/鈥媡ranscript.go |
Adds byte-based Pi analysis. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媝i/鈥媠ession_home.go |
Defines Pi home layout. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媝i/鈥媠ession_home_test.go |
Tests Pi layout validation. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媝i/鈥媝i.go |
Documents Pi read constraints. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媐actoryaidroid/鈥媡ranscript.go |
Confines Droid subagent accounting. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媐actoryaidroid/鈥媠ession_home.go |
Defines Droid home layout. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媐actoryaidroid/鈥媠ession_home_test.go |
Tests Droid layout validation. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媐actoryaidroid/鈥媗ifecycle.go |
Adds confined Droid capabilities. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媍opilotcli/鈥媡ranscript.go |
Adds byte-based Copilot analysis. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媍opilotcli/鈥媠ession_home.go |
Defines Copilot home layout. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媍opilotcli/鈥媠ession_home_test.go |
Tests Copilot layout validation. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媍opilotcli/鈥媍opilotcli.go |
Centralizes Copilot home resolution. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媍odex/鈥媡ranscript.go |
Adds byte-based Codex analysis. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媍odex/鈥媠ession_home.go |
Defines Codex home layout. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媍odex/鈥媠ession_home_test.go |
Tests Codex layout validation. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媍laudecode/鈥媡ranscript.go |
Confines Claude subagent reads. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媍laudecode/鈥媠ession_home.go |
Defines Claude home layout. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媍laudecode/鈥媠ession_home_test.go |
Tests Claude layout validation. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媍laudecode/鈥媍laude.go |
Adds byte-based Claude analysis. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媍apabilities.go |
Exposes new built-in capabilities. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媋rchitecture_test.go |
Guards confinement-test registration. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媋gent.go |
Defines home and confinement interfaces. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媋gent_homes.go |
Implements the home registry. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媋gent_homes_test.go |
Tests registry behavior and limits. |
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媋gent_home_confinement_test.go |
Enforces confined capability coverage. |
馃挕 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Keep review dispatch tests independent of the developer鈥檚 CODEX_HOME override. Entire-Checkpoint: 01M40V85EQ932BCTJVMAFJN432
Track independently resolved agent homes in a bounded per-user registry and model built-in session layouts beneath those homes. Validate transcript candidates without following links below the trusted root. Provide confined streaming and byte-based transcript analysis, including subagent inventory and token usage. Reuse reader parsers and descriptor-size hints to avoid unnecessary transcript buffering. Entire-Checkpoint: 01M40VDN67EB6ABDX7ZPX7RYW6
Record canonical home and transcript coordinates at session initialization and turn start. Retain established boundaries across resumed turns, partial-session repair, home aliases, and unsafe transcript replacements. Confine checkpoint analysis, prompt extraction, token accounting, Codex inventory, review reads, and streamed session output to the recorded home. Add regressions and a ledger for remaining legacy transcript readers. Entire-Checkpoint: 01M40VK88S8Z479VV0163H0F22
Authorize recorded parent and task transcripts against active or previously observed agent homes, checking session identity, native layouts, and no-follow confinement. Preserve canonical transcript coordinates across repeated adoption and worktree moves. Search the active store before historical homes, skip unsafe candidates, and retain the selected home during attach. Document provenance and legacy-store contracts alongside adoption and discovery regressions. Entire-Checkpoint: 01M40VRSH5947F0D6R833CB4D2
57d1026 to
058247a
Compare
|
Superseded by the split: #2655, #2657, #2703, #2710 and #2716. The planned follow-up for regular-file, size-capped transcript reads is dropped: now that adopt validates transcript paths against the source worktree's session directory under a trusted home, no untrusted input reaches a transcript read. Closing. |


https://entire.io/gh/entireio/cli/trails/1462
An agent can use a custom storage path, and a user can run several instances with different paths鈥攆or example, separate
CLAUDE_CONFIG_DIRorCODEX_HOMEvalues. Entire currently resolves storage from the invoking process鈥檚 environment. When that environment differs from the source session鈥檚,session adoptcan reject a valid transcript andattachcan fail to find it.Record the agent home alongside each session and remember independently resolved homes in a bounded per-user registry. Adoption validates the recorded home against locally trusted roots;
attachsearches previously used homes after the active store misses. This lets users continue sessions across repositories and find transcripts from another agent instance without recreating its environment.Carry that root through capture, checkpoint finalization, review, token accounting, and subagent reads. Shared rooted readers enforce containment when opening files, including after adoption, so stored paths and later symlink changes cannot redirect reads outside the authorized home. Preserve compatibility with older sessions and explicit session-directory overrides.
Alternatives considered: