Skip to content

fix(session): validate adopted task transcript paths - #2655

Merged
hiddeco merged 1 commit into
mainfrom
hidde/adopt-task-paths
Oct 5, 2026
Merged

hiddeco merged 1 commit into
mainfrom
hidde/adopt-task-paths

Conversation

@hiddeco

@hiddeco hiddeco commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

https://entire.io/gh/entireio/cli/trails/1479

Splitting #2636 into smaller chunks.


Adoption checked the parent transcript against the session's agent store but copied declared task transcript paths unchecked, and condensation reads those paths whole into the checkpoint. Validate each declared task path: it must be absolute and lie in the session directory of the session's agent, and agents with a task layout must recognise it as that task's transcript through the new optional agent.TaskTranscriptMatcher. Claude Code accepts agent-.jsonl in the session's subagents directory or beside the parent, Droid also accepts a Worker's .jsonl, and Codex requires rollout-*-.jsonl.

A session recorded without an agent type takes it from the agent that owns its parent transcript; without either, task paths are cleared. Relative parent paths are rejected and transcript paths are stored in clean form. Subagent inventory paths get the same check, and their resolved paths are cleared so Codex's session-end finalizer cannot copy an unverified path back into a task record.

A rejected path is cleared, logged and counted in adopt's output. Task records and the inventory are deep-cloned so the source session keeps its own. The checks are lexical; links are still followed on read.

@hiddeco
hiddeco requested a review from a team as a code owner October 5, 2026 11:28
Copilot AI balanced review requested due to automatic review settings October 5, 2026 11:28

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

馃煛 Changes recommended

Relative whitespace-only paths remain accepted, and rejected inventory paths are omitted from reporting.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
What changed in this PR

Strengthens session adoption by validating subagent transcript paths before checkpoint condensation.

Changes:

  • Adds agent-specific task transcript matching for Claude Code, Codex, and Droid.
  • Cleans or clears adopted transcript paths and deep-clones task state.
  • Adds adoption tests and architecture documentation.
File Description
docs/鈥媋rchitecture/鈥媠essions-and-checkpoints.md Documents adoption validation.
cmd/鈥媏ntire/鈥媍li/鈥媠ession_adopt.go Implements path validation and reporting.
cmd/鈥媏ntire/鈥媍li/鈥媠ession_adopt_test.go Extends cloning tests.
cmd/鈥媏ntire/鈥媍li/鈥媠ession_adopt_task_test.go Tests transcript validation.
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媡ask_transcript.go Defines transcript-matching capability.
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媍laudecode/鈥媍laude.go Matches Claude task paths.
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媍laudecode/鈥媗ifecycle.go Asserts Claude capability.
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媍odex/鈥媍odex.go Matches Codex rollout paths.
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媍odex/鈥媗ifecycle.go Asserts Codex capability.
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媐actoryaidroid/鈥媐actoryaidroid.go Matches Droid task paths.
cmd/鈥媏ntire/鈥媍li/鈥媋gent/鈥媐actoryaidroid/鈥媗ifecycle.go Asserts Droid capability.

馃挕 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread cmd/entire/cli/session_adopt.go
Comment thread cmd/entire/cli/session_adopt.go Outdated
Adoption checked the parent transcript against the session's agent store
but copied declared task transcript paths unchecked, and condensation reads
those paths whole into the checkpoint. Validate each declared task path:
it must be absolute and lie in the session directory of the session's
agent, and agents with a task layout must recognise it as that task's
transcript through the new optional agent.TaskTranscriptMatcher. Claude
Code accepts agent-<id>.jsonl in the session's subagents directory or
beside the parent, Droid also accepts a Worker's <id>.jsonl, and Codex
requires rollout-*-<id>.jsonl.

A session recorded without an agent type takes it from the agent that
owns its parent transcript; without either, task paths are cleared.
Relative parent paths are rejected and transcript paths are stored in
clean form. Subagent inventory paths get the same check, and their
resolved paths are cleared so Codex's session-end finalizer cannot copy
an unverified path back into a task record.

A rejected path is cleared, logged and counted in adopt's output. Task
records and the inventory are deep-cloned so the source session keeps
its own. The checks are lexical; links are still followed on read.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Entire-Checkpoint: 01M44M7YC11TCH7YV755JW5DVF
@hiddeco
hiddeco force-pushed the hidde/adopt-task-paths branch from 41f28c5 to 548f94a Compare October 5, 2026 11:41
@hiddeco
hiddeco merged commit ba0a4a2 into main Oct 5, 2026
17 of 18 checks passed
@hiddeco
hiddeco deleted the hidde/adopt-task-paths branch October 5, 2026 21:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants