Skip to content

Preserve session-wide token totals during condensation - #6

Draft
entire[bot] wants to merge 4 commits into
mainfrom
fix-session-token-total-2368
Draft

entire[bot] wants to merge 4 commits into
mainfrom
fix-session-token-total-2368

Conversation

@entire

@entire entire Bot commented Sep 11, 2026

Copy link
Copy Markdown

https://entire.io/gh/MuskanPaliwal/cli/trails/5

This draft pull request was opened by Entire after CI was requested for the linked trail. Feel free to edit the title or body — the link above is what keeps the trail and PR connected.

MuskanPaliwal pushed a commit that referenced this pull request Sep 24, 2026
…ionFile

#5 external.go reimplemented SessionStore.Name's relative branch verbatim —
same IsAbs/VolumeName pairing, same ToSlash(Clean(FromSlash(…))) — without the
comment explaining why the pairing is needed, and it had to know that the store
checks a name only after Name has produced one, which is WriteFile's private
prologue. Name's relative branch is now a named primitive both callers share,
the store exposes ValidateExternalSessionRef (every rule needing no store, plus
whether the ref is filesystem-shaped) and ValidateExternalWriteRef (the
store-backed half), and ValidateWritePath is unexported.

#6 The preflight ran after marshalling and was gated as a whole on RepoPath !=
"". Both current callers set RepoPath, which is what makes that a check that
disappears silently for the next one; the lexical rules need no repo, so only
the store-backed half is conditional now. The remaining asymmetry — an opaque
relative ref is forwarded as given while an absolute one is resolved — is the
protocol's, not this function's, and is left alone deliberately.

#7 ErrOutsideSessionStore said "path is outside the agent's session directory"
for an ID that never resolved anywhere, which names the wrong problem.
Malformed names now report ErrUnsafeSessionName; a path that genuinely left the
store still reports ErrOutsideSessionStore. validateWriteName no longer claims
to "inspect" anything — it touches no filesystem.

#8 The volume-separator check existed in both validators, worded identically,
while the shared reason helper omitted it. It moves in. ValidateSessionID keeps
its separator check ahead of the helper so a Windows absolute path still reports
the separators rather than the colon.

The ResolveSessionFile contract this branch wrote into agent.go had two live
violations: copilotcli's resolveTranscriptRef and cursor's, both passing a raw
payload ID to a resolver that puts it in a directory position. Both now resolve
through SessionStore.SessionFile, and a GitGrepGuard fails the build on the
next one. Two guards in buildAgentStop go: isSubagentAgentStop already returns
false for an unsafe ID via SessionFile, and ExtractModelFromTranscript reads a
path and never touches the ID, so gating it only dropped model attribution.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Entire-Checkpoint: 01M2RM92E1D4CK1JJ6NDSMTMHC
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant