Repository navigation
use strings.Contains - #5
Merged
Merged
Conversation
Entire-Checkpoint: f5e7d3c25b68
khaong
added a commit
that referenced
this pull request
Jan 27, 2026
- Add ValidateAgentUUID to validation package using google/uuid - GetOrCreateEntireSessionID now validates UUID format - Invalid UUIDs generate a random safe UUID instead of using untrusted input - Log warning with original input and generated ID when fallback occurs - Add thread-safety documentation to GetOrCreateEntireSessionID - Update tests to use valid UUIDs - Add test for invalid UUID fallback behavior Addresses Copilot review comments #5 and #6. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> Entire-Checkpoint: 47672e4ef20f
khaong
added a commit
that referenced
this pull request
Jan 27, 2026
- Add ValidateAgentSessionID to validation package (path-safe check, not UUID) - GetOrCreateEntireSessionID validates input and logs warning if invalid - Add thread-safety documentation to GetOrCreateEntireSessionID - Rename parameter from agentSessionUUID to agentSessionID for clarity - Add tests for ValidateAgentSessionID Allows test IDs like "test-session-1" while preventing path traversal. Addresses Copilot review comments #5 and #6. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
alishakawaguchi
added a commit
that referenced
this pull request
May 20, 2026
CI lint: - escape U+200B literals (staticcheck ST1018) Real bugs (cursor[bot] + Copilot review): - loop: ctx-cancel mid-cmd.Run() now classifies as OutcomeCancelled instead of being counted as a turn failure and tripping OutcomePaused after two consecutive cancels (#1) - loop: save state before returning OutcomePaused so --continue resumes from a snapshot that includes the failing turn (#11) - investigate fix: wrap context.Canceled as SilentError so Ctrl+C during the fix session doesn't print a cobra usage banner (#2) - cmd: redact URL userinfo on the issue-link Source: line in both interactive and non-interactive paths (#5) - issuelink: redact URL userinfo across gh stderr (not just argv) so a token in --issue-link cannot leak via the error path (#10) - cmd: outcome-aware footer — "Investigation ended" + resume hint for paused/cancelled, "Investigation complete" + fix hint only for Quorum/Stalled (#6) - cmd: validate maxTurns/quorum bounds after settings/flag merge so a hand-edited negative max_turns or oversized quorum errors cleanly instead of silently stalling (#7) - issuelink: tolerate GitHub URL trailing segments (/pull/123/files, trailing slash) — the regex now anchors prefix and ignores tail (#13) - picker: don't print "Saved investigate config" before persistence; moved to the caller after SaveLocal succeeds (#14) - picker: guard pickerFormOverride with atomic.Pointer so parallel tests that swap the override don't race (#12) Docs: - settings/loop: fix stale "0 → 3" max_turns doc; default is 2 (#8/#9) Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> Entire-Checkpoint: b0135abeee0d
4 of 8 tasks
Soph
added a commit
that referenced
this pull request
May 20, 2026
…693 exchange Pins github.com/entireio/auth-go to its hardened OAuth client (PR #5 head), which validates Resource as an origin URL, refuses unsigned JWTs (alg:none), enforces HTTPS unless the host is loopback, validates the verification_uri returned by the AS, and centralises OAuth error parsing with sanitised descriptions. auth/client.go: now a thin shim over deviceflow.Client. Preserves the historical DeviceAuthStart/DeviceAuthPoll types as aliases / equivalent shapes so login.go's polling switch keeps working. Unknown OAuth error codes are surfaced through DeviceAuthPoll.Error/ErrorDescription so login.go can fail fast on terminal rejections instead of treating them as transient. auth/store.go: implements tokenstore.Store (SaveTokens/LoadTokens/ DeleteTokens) so it can be passed to tokenmanager.New. Adds a defensive JSON-shape check on read — pre-shim entries are opaque token strings, never JSON; a JSON blob in the keyring is corruption and must not be put on the wire as a bearer. auth/exchange.go: new package-level Manager wired from CurrentProvider, AuthBaseURL, and NewStore. Exposes TokenForResource(ctx, url) and Token (ctx, req); both go through the manager's same-host shortcut, JWT-aud shortcut, and STS exchange dispatch as appropriate. SetManagerForTest() takes a mutex so concurrent tests can swap without racing. Single-host deployments hit the same-host shortcut and never call STS; split-host deployments perform an RFC 8693 token exchange against the auth issuer's STS endpoint to mint a resource-scoped bearer. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> Entire-Checkpoint: 6d696fc55440
computermode
added a commit
that referenced
this pull request
May 20, 2026
Five small cleanups identified by post-merge review: 1. Extract checkpoint.PreserveV1HistoryAndLog so the 'preserve + WARN on failure' pattern at the three read entry points in committed.go (WriteCommitted, ReadCommitted, ListCommitted) is one line each instead of three. 2. Pull the 1.1 tracking-ref shape into paths constants: MetadataTrackingRefPrefix, MetadataTrackingRefSuffix, plus a BuildMetadataTrackingRef(remoteName) helper. The MetadataTrackingRefName constant is now expressed in terms of those constants, and MetadataTrackingRefForRemote uses BuildMetadataTrackingRef instead of inline string concatenation. 3. Name the recognized checkpoints_version literals (checkpointsVersion11FloatLit, checkpointsVersion11StringLit, etc.) so parseCheckpointsVersion and UsesCustomMetadataRef refer to the same source of truth instead of repeating 1.1 / "1.1" magic. 4. installMetadataRefspec uses gitremote.GetRemoteURL instead of a raw exec.CommandContext to detect origin's presence — one less place that knows the underlying git command. 5. Tighten the refspec-existence loop in installMetadataRefspec so an empty 'git config --get-all' output isn't compared as a single empty line against the refspec (TrimSpace per line, not the whole buffer). No behavior change beyond #5's edge-case tightening. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> Entire-Checkpoint: 4faf19afed2d
Soph
added a commit
that referenced
this pull request
May 21, 2026
…693 exchange Pins github.com/entireio/auth-go to its hardened OAuth client (PR #5 head), which validates Resource as an origin URL, refuses unsigned JWTs (alg:none), enforces HTTPS unless the host is loopback, validates the verification_uri returned by the AS, and centralises OAuth error parsing with sanitised descriptions. auth/client.go: now a thin shim over deviceflow.Client. Preserves the historical DeviceAuthStart/DeviceAuthPoll types as aliases / equivalent shapes so login.go's polling switch keeps working. Unknown OAuth error codes are surfaced through DeviceAuthPoll.Error/ErrorDescription so login.go can fail fast on terminal rejections instead of treating them as transient. auth/store.go: implements tokenstore.Store (SaveTokens/LoadTokens/ DeleteTokens) so it can be passed to tokenmanager.New. Adds a defensive JSON-shape check on read — pre-shim entries are opaque token strings, never JSON; a JSON blob in the keyring is corruption and must not be put on the wire as a bearer. auth/exchange.go: new package-level Manager wired from CurrentProvider, AuthBaseURL, and NewStore. Exposes TokenForResource(ctx, url) and Token (ctx, req); both go through the manager's same-host shortcut, JWT-aud shortcut, and STS exchange dispatch as appropriate. SetManagerForTest() takes a mutex so concurrent tests can swap without racing. Single-host deployments hit the same-host shortcut and never call STS; split-host deployments perform an RFC 8693 token exchange against the auth issuer's STS endpoint to mint a resource-scoped bearer. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> Entire-Checkpoint: 6d696fc55440
suhaanthayyil
added a commit
that referenced
this pull request
Jun 30, 2026
Resolves the review packet on the Codex subagent change: - #1 Codex task-checkpoint UUID: documented that CheckpointUUID is Claude-format-specific (tool_result/UUID) and resolves to "" for Codex — rewind to a Codex task checkpoint restores files via the shadow tree but does not truncate the transcript (graceful fall-through; restore truncation is also Claude-only). Codex-aware line-offset truncation is a deferred follow-up. Comment at the call site + AGENT.md. - #2 Resumed-subagent token under-count: documented deliberate trade-off (chosen over the worse cross-turn double-count) + observability — logResumedOutOfRangeChildren debug-logs when a resume_agent targets a child spawned in a prior range. - #3 Regression tests: CalculateTotalTokenUsage nil-main-with-subagent-tokens unit test (guards the nil-deref); new integration test TestCodexSubagentEnd_SourcesFilesFromChildNotParent (+ SimulateCodexSubagentStart/Stop harness helpers) guarding handleLifecycleSubagentEnd's child-not-parent resolver. - #4 Debug logging across the discover→resolve→read→parse chain (readSubagentRolloutsUncached, CalculateTotalTokenUsage, spawn-output drop) so Codex wire-format drift is visible instead of silently zeroing attribution. - #5 isCodexSubagentRollout: nested source.subagent fallback for rollouts without thread_source + backward-compat test (missing marker → treated as parent turn). - #6 + nits: t.Parallel() on the pure-logic codex tests; AGENT.md PostToolUse line corrected (it IS consumed); StepTranscriptStart aligned to the resolved transcriptOffset (removes the exec/no-preState divergence; field is currently unconsumed by the strategy). go build (incl. integration tag), vet, unit + codex integration tests, lint (0) all green. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
suhaanthayyil
added a commit
that referenced
this pull request
Jul 15, 2026
Resolves the review packet on the Codex subagent change: - #1 Codex task-checkpoint UUID: documented that CheckpointUUID is Claude-format-specific (tool_result/UUID) and resolves to "" for Codex — rewind to a Codex task checkpoint restores files via the shadow tree but does not truncate the transcript (graceful fall-through; restore truncation is also Claude-only). Codex-aware line-offset truncation is a deferred follow-up. Comment at the call site + AGENT.md. - #2 Resumed-subagent token under-count: documented deliberate trade-off (chosen over the worse cross-turn double-count) + observability — logResumedOutOfRangeChildren debug-logs when a resume_agent targets a child spawned in a prior range. - #3 Regression tests: CalculateTotalTokenUsage nil-main-with-subagent-tokens unit test (guards the nil-deref); new integration test TestCodexSubagentEnd_SourcesFilesFromChildNotParent (+ SimulateCodexSubagentStart/Stop harness helpers) guarding handleLifecycleSubagentEnd's child-not-parent resolver. - #4 Debug logging across the discover→resolve→read→parse chain (readSubagentRolloutsUncached, CalculateTotalTokenUsage, spawn-output drop) so Codex wire-format drift is visible instead of silently zeroing attribution. - #5 isCodexSubagentRollout: nested source.subagent fallback for rollouts without thread_source + backward-compat test (missing marker → treated as parent turn). - #6 + nits: t.Parallel() on the pure-logic codex tests; AGENT.md PostToolUse line corrected (it IS consumed); StepTranscriptStart aligned to the resolved transcriptOffset (removes the exec/no-preState divergence; field is currently unconsumed by the strategy). go build (incl. integration tag), vet, unit + codex integration tests, lint (0) all green. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Soph
added a commit
that referenced
this pull request
Sep 17, 2026
…ionFile #5 external.go reimplemented SessionStore.Name's relative branch verbatim — same IsAbs/VolumeName pairing, same ToSlash(Clean(FromSlash(…))) — without the comment explaining why the pairing is needed, and it had to know that the store checks a name only after Name has produced one, which is WriteFile's private prologue. Name's relative branch is now a named primitive both callers share, the store exposes ValidateExternalSessionRef (every rule needing no store, plus whether the ref is filesystem-shaped) and ValidateExternalWriteRef (the store-backed half), and ValidateWritePath is unexported. #6 The preflight ran after marshalling and was gated as a whole on RepoPath != "". Both current callers set RepoPath, which is what makes that a check that disappears silently for the next one; the lexical rules need no repo, so only the store-backed half is conditional now. The remaining asymmetry — an opaque relative ref is forwarded as given while an absolute one is resolved — is the protocol's, not this function's, and is left alone deliberately. #7 ErrOutsideSessionStore said "path is outside the agent's session directory" for an ID that never resolved anywhere, which names the wrong problem. Malformed names now report ErrUnsafeSessionName; a path that genuinely left the store still reports ErrOutsideSessionStore. validateWriteName no longer claims to "inspect" anything — it touches no filesystem. #8 The volume-separator check existed in both validators, worded identically, while the shared reason helper omitted it. It moves in. ValidateSessionID keeps its separator check ahead of the helper so a Windows absolute path still reports the separators rather than the colon. The ResolveSessionFile contract this branch wrote into agent.go had two live violations: copilotcli's resolveTranscriptRef and cursor's, both passing a raw payload ID to a resolver that puts it in a directory position. Both now resolve through SessionStore.SessionFile, and a GitGrepGuard fails the build on the next one. Two guards in buildAgentStop go: isSubagentAgentStop already returns false for an unsafe ID via SessionFile, and ExtractModelFromTranscript reads a path and never touches the ID, so gating it only dropped model attribution. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Entire-Checkpoint: 01M2RM92E1D4CK1JJ6NDSMTMHC
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.