Skip to content

Improved entire enable messaging - #6

Merged
Soph merged 8 commits into
mainfrom
soph/improve-enable
Jan 6, 2026
Merged

Soph merged 8 commits into
mainfrom
soph/improve-enable

Conversation

@Soph

@Soph Soph commented Jan 5, 2026 •

Copy link
Copy Markdown
Collaborator

Before (main branch)

  $ entire enable --strategy manual-commit

  ✓ Local settings saved (.entire/settings.local.json)

  ✓ Enabled (manual-commit)

After (this branch)

  $ entire enable --strategy manual-commit
  ✓ Claude Code hooks installed
  ✓ Local settings saved (.entire/settings.local.json)
  ✓ Git hooks installed

  ✓ manual-commit strategy enabled

When running again (everything already set up):

  $ entire enable --strategy manual-commit
  ✓ Claude Code hooks verified
  ✓ Local settings saved (.entire/settings.local.json)
  ✓ Git hooks verified
  ✓ Created orphan branch 'entire/sessions' for session metadata

  ✓ manual-commit strategy enabled

For auto-commit strategy:

  $ entire enable --strategy auto-commit
  ✓ Claude Code hooks installed
  ✓ Local settings saved (.entire/settings.local.json)
  ✓ Git hooks installed
  ✓ Created orphan branch 'entire/sessions' for session metadata

  ✓ auto-commit strategy enabled

Entire-Checkpoint: 3724a646375c
@Soph
Soph requested a review from dipree January 5, 2026 18:56
Soph added 7 commits January 6, 2026 12:35
Entire-Checkpoint: 2a29469db94c
Entire-Checkpoint: 35762f1bcfdb
Entire-Checkpoint: e140526ef3de
Entire-Checkpoint: 0382579310fc
… for both strategies

Entire-Checkpoint: 74af160f6f80
@Soph
Soph merged commit e5914c3 into main Jan 6, 2026
3 checks passed
@Soph
Soph deleted the soph/improve-enable branch January 7, 2026 16:19
khaong added a commit that referenced this pull request Jan 27, 2026
- Add ValidateAgentUUID to validation package using google/uuid
- GetOrCreateEntireSessionID now validates UUID format
- Invalid UUIDs generate a random safe UUID instead of using untrusted input
- Log warning with original input and generated ID when fallback occurs
- Add thread-safety documentation to GetOrCreateEntireSessionID
- Update tests to use valid UUIDs
- Add test for invalid UUID fallback behavior

Addresses Copilot review comments #5 and #6.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Entire-Checkpoint: 47672e4ef20f
khaong added a commit that referenced this pull request Jan 27, 2026
- Add ValidateAgentSessionID to validation package (path-safe check, not UUID)
- GetOrCreateEntireSessionID validates input and logs warning if invalid
- Add thread-safety documentation to GetOrCreateEntireSessionID
- Rename parameter from agentSessionUUID to agentSessionID for clarity
- Add tests for ValidateAgentSessionID

Allows test IDs like "test-session-1" while preventing path traversal.
Addresses Copilot review comments #5 and #6.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
alishakawaguchi added a commit that referenced this pull request May 20, 2026
CI lint:
- escape U+200B literals (staticcheck ST1018)

Real bugs (cursor[bot] + Copilot review):
- loop: ctx-cancel mid-cmd.Run() now classifies as OutcomeCancelled
  instead of being counted as a turn failure and tripping OutcomePaused
  after two consecutive cancels (#1)
- loop: save state before returning OutcomePaused so --continue resumes
  from a snapshot that includes the failing turn (#11)
- investigate fix: wrap context.Canceled as SilentError so Ctrl+C during
  the fix session doesn't print a cobra usage banner (#2)
- cmd: redact URL userinfo on the issue-link Source: line in both
  interactive and non-interactive paths (#5)
- issuelink: redact URL userinfo across gh stderr (not just argv) so a
  token in --issue-link cannot leak via the error path (#10)
- cmd: outcome-aware footer — "Investigation ended" + resume hint for
  paused/cancelled, "Investigation complete" + fix hint only for
  Quorum/Stalled (#6)
- cmd: validate maxTurns/quorum bounds after settings/flag merge so a
  hand-edited negative max_turns or oversized quorum errors cleanly
  instead of silently stalling (#7)
- issuelink: tolerate GitHub URL trailing segments (/pull/123/files,
  trailing slash) — the regex now anchors prefix and ignores tail (#13)
- picker: don't print "Saved investigate config" before persistence;
  moved to the caller after SaveLocal succeeds (#14)
- picker: guard pickerFormOverride with atomic.Pointer so parallel
  tests that swap the override don't race (#12)

Docs:
- settings/loop: fix stale "0 → 3" max_turns doc; default is 2 (#8/#9)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Entire-Checkpoint: b0135abeee0d
khaong added a commit that referenced this pull request May 24, 2026
Resolves conflict in go.mod: keeps the entireio/auth-go dependency
added by 49dca72 (Integrate auth-go library) while taking the newer
go-git/go-git/v6 and go-git/go-billy/v6 versions from main.

While here, advance the auth-go pin from the pre-release commit
v0.1.1-0.20260520123811-da94c52ef430 to the v0.3.3 release tag. The
intermediate v0.3.x versions deliver three fixes the entire CLI's
split-host (us.auth.entire.io issuer, entire.io data API) deployment
depends on:

  v0.3.1 (auth-go #6): HTTP Basic Auth for the token-exchange grant —
    zitadel-oidc reads client credentials only from Authorization:
    Basic on this grant, not the form body.
  v0.3.2 (auth-go #7): default SubjectTokenType to :access_token —
    zitadel-oidc's STS validator handles :access_token / :refresh_token
    / :id_token but NOT :jwt, so the prior URI was silently rejected
    as "subject_token is invalid".
  v0.3.3 (auth-go #8): default Audience to Resource on the wire —
    zitadel-OIDC-backed servers reject token-exchange requests without
    an explicit `audience` form field with "invalid_target: audience
    is required".

End-to-end verified against us.auth.entire.io: entire login, search,
activity all succeed.
suhaanthayyil added a commit that referenced this pull request Jun 30, 2026
Resolves the review packet on the Codex subagent change:

- #1 Codex task-checkpoint UUID: documented that CheckpointUUID is
  Claude-format-specific (tool_result/UUID) and resolves to "" for Codex —
  rewind to a Codex task checkpoint restores files via the shadow tree but does
  not truncate the transcript (graceful fall-through; restore truncation is also
  Claude-only). Codex-aware line-offset truncation is a deferred follow-up.
  Comment at the call site + AGENT.md.
- #2 Resumed-subagent token under-count: documented deliberate trade-off (chosen
  over the worse cross-turn double-count) + observability — logResumedOutOfRangeChildren
  debug-logs when a resume_agent targets a child spawned in a prior range.
- #3 Regression tests: CalculateTotalTokenUsage nil-main-with-subagent-tokens
  unit test (guards the nil-deref); new integration test
  TestCodexSubagentEnd_SourcesFilesFromChildNotParent (+ SimulateCodexSubagentStart/Stop
  harness helpers) guarding handleLifecycleSubagentEnd's child-not-parent resolver.
- #4 Debug logging across the discover→resolve→read→parse chain
  (readSubagentRolloutsUncached, CalculateTotalTokenUsage, spawn-output drop) so
  Codex wire-format drift is visible instead of silently zeroing attribution.
- #5 isCodexSubagentRollout: nested source.subagent fallback for rollouts without
  thread_source + backward-compat test (missing marker → treated as parent turn).
- #6 + nits: t.Parallel() on the pure-logic codex tests; AGENT.md PostToolUse line
  corrected (it IS consumed); StepTranscriptStart aligned to the resolved
  transcriptOffset (removes the exec/no-preState divergence; field is currently
  unconsumed by the strategy).

go build (incl. integration tag), vet, unit + codex integration tests, lint (0) all green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
suhaanthayyil added a commit that referenced this pull request Jul 15, 2026
Resolves the review packet on the Codex subagent change:

- #1 Codex task-checkpoint UUID: documented that CheckpointUUID is
  Claude-format-specific (tool_result/UUID) and resolves to "" for Codex —
  rewind to a Codex task checkpoint restores files via the shadow tree but does
  not truncate the transcript (graceful fall-through; restore truncation is also
  Claude-only). Codex-aware line-offset truncation is a deferred follow-up.
  Comment at the call site + AGENT.md.
- #2 Resumed-subagent token under-count: documented deliberate trade-off (chosen
  over the worse cross-turn double-count) + observability — logResumedOutOfRangeChildren
  debug-logs when a resume_agent targets a child spawned in a prior range.
- #3 Regression tests: CalculateTotalTokenUsage nil-main-with-subagent-tokens
  unit test (guards the nil-deref); new integration test
  TestCodexSubagentEnd_SourcesFilesFromChildNotParent (+ SimulateCodexSubagentStart/Stop
  harness helpers) guarding handleLifecycleSubagentEnd's child-not-parent resolver.
- #4 Debug logging across the discover→resolve→read→parse chain
  (readSubagentRolloutsUncached, CalculateTotalTokenUsage, spawn-output drop) so
  Codex wire-format drift is visible instead of silently zeroing attribution.
- #5 isCodexSubagentRollout: nested source.subagent fallback for rollouts without
  thread_source + backward-compat test (missing marker → treated as parent turn).
- #6 + nits: t.Parallel() on the pure-logic codex tests; AGENT.md PostToolUse line
  corrected (it IS consumed); StepTranscriptStart aligned to the resolved
  transcriptOffset (removes the exec/no-preState divergence; field is currently
  unconsumed by the strategy).

go build (incl. integration tag), vet, unit + codex integration tests, lint (0) all green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Soph added a commit that referenced this pull request Sep 17, 2026
…ionFile

#5 external.go reimplemented SessionStore.Name's relative branch verbatim —
same IsAbs/VolumeName pairing, same ToSlash(Clean(FromSlash(…))) — without the
comment explaining why the pairing is needed, and it had to know that the store
checks a name only after Name has produced one, which is WriteFile's private
prologue. Name's relative branch is now a named primitive both callers share,
the store exposes ValidateExternalSessionRef (every rule needing no store, plus
whether the ref is filesystem-shaped) and ValidateExternalWriteRef (the
store-backed half), and ValidateWritePath is unexported.

#6 The preflight ran after marshalling and was gated as a whole on RepoPath !=
"". Both current callers set RepoPath, which is what makes that a check that
disappears silently for the next one; the lexical rules need no repo, so only
the store-backed half is conditional now. The remaining asymmetry — an opaque
relative ref is forwarded as given while an absolute one is resolved — is the
protocol's, not this function's, and is left alone deliberately.

#7 ErrOutsideSessionStore said "path is outside the agent's session directory"
for an ID that never resolved anywhere, which names the wrong problem.
Malformed names now report ErrUnsafeSessionName; a path that genuinely left the
store still reports ErrOutsideSessionStore. validateWriteName no longer claims
to "inspect" anything — it touches no filesystem.

#8 The volume-separator check existed in both validators, worded identically,
while the shared reason helper omitted it. It moves in. ValidateSessionID keeps
its separator check ahead of the helper so a Windows absolute path still reports
the separators rather than the colon.

The ResolveSessionFile contract this branch wrote into agent.go had two live
violations: copilotcli's resolveTranscriptRef and cursor's, both passing a raw
payload ID to a resolver that puts it in a directory position. Both now resolve
through SessionStore.SessionFile, and a GitGrepGuard fails the build on the
next one. Two guards in buildAgentStop go: isSubagentAgentStop already returns
false for an unsafe ID via SessionFile, and ExtractModelFromTranscript reads a
path and never touches the ID, so gating it only dropped model attribution.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Entire-Checkpoint: 01M2RM92E1D4CK1JJ6NDSMTMHC
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants