-
Notifications
You must be signed in to change notification settings - Fork 0
path state isolation
Issue #149 / Issue #152 / PR #162 / PR #163 / Issue #153 / Issue #155
Record the completed Phase 3 implementation for Issue #152 and clarify the remaining boundaries. The authoritative design is Phase 3 of Codex App Server Update and Remote Connection, doc/path-state-isolation-design.md, and ADR-013.
The detailed follow-up plan for reconnect, history, quarantined drafts, and stored-attachment metadata is Connection, History, and Draft Recovery — Issue #153.
Delivered by PR #162 and follow-up PR #163; Issue #152 is closed:
- Separate
LocalPath/ServerPathdomains, component mapping for Windows drive/UNC and POSIX roots, and physical symlink/junction containment (LocalPathBoundary). - One mapper for working directory, IDE context, attachments,
localImage, and approval paths. Unmappable attachments are rejected beforeturn/start. - Remote skill paths stay opaque server identifiers with no host filesystem probing.
- Volatile owner partitions (connection kind, profile, endpoint, roots, credential digest, Worker instance, owner generation), contract v18 owner stamps, owner-scoped requests, and stale-result rejection in the Worker and the Extension.
- Owner replacement clears selected conversation, transcript, composer, attachments, skills, models, usage, and approvals. The disk skill cache is disabled while account continuity cannot be proven.
PR #163 completed the account-change lifecycle, all-or-nothing attachment validation, mapped thread working-directory display, retired-owner rate-limit filtering, automated coverage, and the available Experimental Instance acceptance. Current owner replacement still clears the active state listed above. Phase 4 (#153) will capture an eligible composer/settings snapshot in memory before that clear and quarantine it for explicit user review; it will not carry active transcript, approvals, input, caches, or events across owners.
| Item in the original issue | Owner |
|---|---|
| Changed-file links, typed file artifacts, image preview, local open/reveal | Issue #155, using the mapper and boundary from #152 |
| Stored attachments, recovered history, retained drafts | Issue #153 (rendering and operations: Issue #155), using the owner partition from #152 |
Issue #153 owns stored attachment metadata, recovered history, and the in-memory quarantined draft workflow. Issue #155 owns rendering and actions for typed artifacts and stored attachment payloads. These later features must use the mapper, physical boundary, and owner partition delivered here.
Remote mode remains Preview until Issue #153 is complete and the upstream WebSocket transport is no longer experimental.
- Debug and Release builds completed with zero warnings.
- Release Core tests: 331 passed, 5 skipped (symlink privilege unavailable). Release UI tests: 318 passed, 1 skipped.
- Pinned CLI 0.159.1 schema-cache and live
initializechecks, plusgit diff --check, passed. - Experimental Instance screenshots verified startup Ready while signed in and sign-out reaching a new Ready session with Sign in available. Remote profile switching, attachment rejection, and remote skill selection were covered by automated tests; no screenshot evidence is claimed for those cases.
Remote mode remains Preview until Issue #153 is complete and the upstream WebSocket transport is no longer experimental. Unavailable checks remain explicitly incomplete.