fix(session): validate adopted task transcript paths

main

Commit

hiddecoyesterday

Adoption checked the parent transcript against the session's agent store but copied declared task transcript paths unchecked, and condensation reads those paths whole into the checkpoint. Validate each declared task path: it must be absolute and lie in the session directory of the session's agent, and agents with a task layout must recognise it as that task's transcript through the new optional agent.TaskTranscriptMatcher. Claude Code accepts agent-<id>.jsonl in the session's subagents directory or beside the parent, Droid also accepts a Worker's <id>.jsonl, and Codex requires rollout-*-<id>.jsonl.

A session recorded without an agent type takes it from the agent that owns its parent transcript; without either, task paths are cleared. Relative parent paths are rejected and transcript paths are stored in clean form. Subagent inventory paths get the same check, and their resolved paths are cleared so Codex's session-end finalizer cannot copy an unverified path back into a task record.

A rejected path is cleared, logged and counted in adopt's output. Task records and the inventory are deep-cloned so the source session keeps its own. The checks are lexical; links are still followed on read.

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com Entire-Checkpoint: 01M44M7YC11TCH7YV755JW5DVF

Checkpoints

Fix Session Task Transcript Path Validation

Claude CodeOpus 5.5
View session
Checkpoint 1