Simplify Agent-Home Discovery and Confinement

Should we potentially dumb down on hidde/adopt-across-agent-homes (available in a worktree)? Please assess.
I’ll inspect the worktree and compare the branch with its base, focusing on whether the added complexity earns its keep and what could be simplified safely.
The branch combines three changes: adoption across homes, a registry for finding transcripts in previously used homes, and broader transcript-read confinement. I’m checking which parts adoption actually needs and which could be split out or deferred.
The focused adoption and home-lookup tests pass. I found two concerns in the code: turn-start refresh can clear an established home boundary when a transcript becomes unreadable through it, and alternate-home lookup appears to miss archived Codex rollouts. Both point toward simplifying the rules around transcript reads, while keeping the provenance checks.
Yes—I’d narrow the scope and simplify the rules, while keeping the safety checks. The branch adds 4,356 lines across 54 files. Much of that is tests, but it combines adoption across homes, automatic transcript discovery across historical homes, and transcript-read confinement.
My recommendation:
- Keep home provenance and confinement.
AgentHomecomes from repository metadata; accepting it directly would let adoption authorize arbitrary filesystem reads. The independent registry and confinement of later reads address real risks. - Split out automatic cross-home attach discovery. Adoption already has a source state and transcript path. Searching historical homes adds candidate ordering, fallback behavior, and notices to
attach; that can ship separately. - Simplify adoption validation. Canonicalize the trusted home, derive the transcript’s relative name, check the agent layout, and validate through the confined store. The current validator separately resolves transcript symlinks and handles missing files, creating another set of filesystem rules alongside the reader.
- Shorten the incident-history comments. Preserve the contracts and regression tests, but move the repeated “P2/P4” narratives and hypothetical future-call-site warnings into the relevant documentation.
Two concrete concerns strengthen the case for simpler rules:
-
An established boundary can silently disappear. refreshAgentHome clears
AgentHomewhen confinement fails. Since an empty home selects unrestricted legacy reads, replacing an unchanged transcript with a symlink can cause a turn-start refresh to remove its protection. Preserve the boundary and report the read failure; clearing it should require evidence that the transcript or agent legitimately changed. -
Historical-home lookup appears to miss archived Codex sessions. probeSessionDir opens a store rooted at
<home>/sessions. Codex’s resolver can return<home>/archived_sessions/..., whichSessionFilethen rejects as outside that store. This needs a regression test if discovery stays in scope.
I wouldn’t replace this with “trust the recorded path” or merely validate once at adoption: subsequent checkpoint reads happen in other processes and need their own boundary. The bytes/reader-based analyzer methods are useful for that.
I’d ship a smaller adoption change with one consistent confinement policy, and defer historical-home discovery. That reduces product scope without reopening the underlying safety problem.
Focused adoption, home-registry, confinement, and lookup tests passed. The two concerns above are from code inspection; I left the worktree unchanged.
I do want the historical-home discovery, it's the most important feature to make things work nicely from a UX perspective.
Then I’d keep historical-home discovery as the centerpiece. My earlier suggestion to defer it doesn’t fit that priority.
The simplification should be internal:
- Keep the per-user home registry, automatic discovery, active-home precedence, and alternate-home notice.
- Share one trusted-home resolver and confined reader between adoption and attach, reducing overlapping path-validation logic.
- Preserve an established boundary when a read fails; avoid clearing
AgentHomeand silently switching to legacy reads. - Fix archived Codex discovery and cover it with a regression test.
- Shorten the incident-history comments while retaining the safety contracts and tests.
So yes to simplifying the implementation, while preserving the seamless discovery UX. The registry and search are justified; the overlapping validation and fallback rules are where I’d focus.
I’ll keep historical-home discovery and simplify the shared validation, fix archived Codex lookup, and prevent turn-start refresh from dropping an established read boundary. I’ll add focused regression coverage and run the relevant checks.
Adoption and attach now share a validator that canonicalizes the trusted home and applies the same symlink policy as later reads. Historical Codex lookup also uses the whole home as its boundary, which includes archived rollouts. I’m adding tests for that lookup and for keeping the boundary when a transcript is replaced by a symlink.
The new regression tests pass, and Go lint reports no issues. Historical-home discovery remains automatic; the changes reduce the separate path rules and shorten comments while preserving the guard tests. The broader unit run has failures outside the focused tests, so I’m checking whether those come from the sandbox or need a fix.
The broad run caught one issue in my implementation: historical lookup called the agent resolver directly, which the repository’s source guard forbids. I routed it through SessionStore so ID validation and containment stay centralized, without adding an exception. The other failures were from sandbox-blocked loopback sockets; the unit suite is now rerunning outside that restriction.
The full unit suite passed: 12,950 tests, with 18 skipped. The new tests cover live and archived Codex transcripts in historical homes, linked-home canonicalization, and boundary preservation after symlink replacement. I’m waiting for the final lint task to finish, then I’ll leave the changes uncommitted in the worktree for review.
Implemented in the hidde/adopt-across-agent-homes worktree, preserving automatic historical-home discovery.
- Shared trusted-home validation between adoption and attach.
- Fixed archived Codex transcript discovery.
- Preserved established read boundaries after symlink replacement.
- Shortened incident-history comments and updated documentation.
- Added regression tests.
Formatting, lint, and the full unit suite passed: 12,950 tests, 18 skipped. Changes are uncommitted.
I’ll run the required pre-commit check, then commit the worktree changes.
Formatting and lint passed. The required check is now running unit and integration tests with race detection, followed by the deterministic E2E canary.
The race-enabled suite is still running; no failures have been reported. I’m waiting for it and the canary to finish before committing.
The unit and integration tests passed with race detection. The deterministic canary is running now; I’ll commit once it passes.
Committed as 140471f9ab — Simplify trusted agent-home discovery and confinement.
mise run check passed. Worktree is clean.
Also: double check the new safety guards against previous issues. I believe we had a few PRs recently that resolved symlink bugs, and I don't want to reintroduce those.
I’ll trace the recent symlink fixes and compare their protections with this branch, then test the relevant failure cases.
I found two gaps while replaying the earlier fixes’ failure cases. Turn-start refresh can drop a recorded boundary when a hook spells the home through a symlink, and reattaching an existing session can switch to an unrestricted read after its transcript is replaced by a symlink. Both reproduce in new regression tests. I’ll fix them before calling this audit clear.
The earlier fixes still hold: reads pin and check each path component, reject links within the root as well as escaping and dangling links, and refuse non-regular files before opening them. Trusted agent-home symlinks also remain supported.
The two new reproductions now pass. I also added coverage for symlinked home registries and tightened the agent guard so late-flush prompt extraction must use confined transcript bytes.
I’ll commit the audit fixes separately once the running pre-commit check finishes. Formatting and lint have passed; the race-enabled tests and canary are still pending.
The integration check caught a compatibility case: a session can record a provisional home before any transcript path is known, then use an explicit session-directory override. I’m adjusting the reattach check to protect established home/path pairs while preserving that workflow, and adding a regression test for it.
The integration regression now passes, along with both symlink reproductions and the historical-home tests. The full pre-commit check is rerunning on the final tree; I’ll commit once it’s green.
Formatting and lint are green again. The full race-enabled suite is still running with no reported failures; the canary will run afterward.
Committed as f373227a3c — Preserve transcript boundaries across symlinked agent homes.
The audit found and fixed two boundary downgrades: linked-home spelling during turn start and symlink replacement during reattach. Added regression tests and strengthened registry and prompt-extraction guards.
mise run check passed. Worktree is clean.
I’ll read the branch’s trail finding and address it if it points to a real issue.
The finding appears to misread the control flow: the return is inside the underHome check. If that check fails, execution reaches the final layout check. I’m verifying the helpers and existing regression tests before concluding whether a change is needed.
The medium-severity finding on trail #1462 is a false positive. In refreshAgentHome, return is inside the successful underHome check. When it fails, execution reaches the final layout check as requested.
The existing refresh regression tests pass. No code change or commit is needed; the finding remains open.
I’ll dismiss the finding with the control-flow explanation.
Dismissed with the control-flow explanation. Verified that trail #1462 has no open current findings.
I’ll review the Copilot findings, resolve those addressed by the commits, and dismiss any false positives with an explanation.
All four Copilot findings are addressed in the PR’s current commits: live token accounting uses the confined API, attach retains the home boundary, agent-type correction clears stale homes, and historical lookup supports Codex and Copilot CLI. I’ll mark all four resolved with references to those fixes.
Resolved all four Copilot findings on PR #2636, with explanations of the fixes. Relevant regression tests pass.
I’ll read the new Copilot finding and check it against the current code.
This finding is valid: transcript output still uses a bare file open and ignores AgentHome. I’ll route streaming through the existing rooted, no-follow policy while preserving its snapshot and cancellation behavior, and add regressions for symlink replacement.
The regression reproduced the leak through both leaf and directory symlinks. The fix blocks those reads and paths outside the recorded home, while still allowing a trusted symlinked home root. The transcript-output tests pass; the full repository check is running.
Lint passed with no issues. The full CI test suite is still running. Once it passes, I’ll commit the fix, update the PR, and resolve the Copilot thread.
The new cases cover links to files both inside and outside the home, a redirected directory, an outside path, and a legitimate linked home root. They pass. I’m waiting for the remaining CI checks before updating the PR.
The full mise run check passed, including race tests, integration tests, and the deterministic canary. Committed as 297810edae; I’ll push it to the PR and resolve the finding.
The finding was valid. Fixed and pushed as 297810edae: transcript output now enforces the recorded home boundary and refuses symlink redirects.
Regression tests and full mise run check passed. Copilot thread resolved; no open current trail findings.
I’ll check the new findings on the PR and trail, then address any real issues.
There are three new trail findings and no new open Copilot threads. All three look valid: provisional homes can incorrectly enforce confinement on linked transcript directories, pre-upgrade sessions aren’t added to historical-home discovery, and late-flush prompt recovery bypasses Antigravity’s reader. I’ll fix them while preserving fail-closed reads for sessions that already have an established boundary.
The new regressions reproduced all three issues and now pass. Turn start registers only an independently resolved active home; it won’t grant trust to a retained home from session metadata. A provisional home is re-evaluated when the first transcript path arrives, while established boundaries still reject symlink swaps. Antigravity prompt recovery now uses its own reader when no home is recorded.
Lint passed with no issues. The focused tests also confirm that established homes still reject transcript redirection and that turn start cannot add a metadata-only home to the trust registry. The full CI suite is still running.
Once addressed, perform a review pass to see if likewise bugs of the same category remain
I’ll review the surrounding code for the same categories: provisional homes becoming enforced boundaries, metadata entering the trust registry, and shared readers bypassing agent-specific behavior. I’ll fix and test any additional issues before finishing.
The three reported fixes passed the full check. The follow-up review found one related issue in Codex partial-session repair: it recalculates AgentHome from readability, so a symlink swap can erase an existing boundary. I’ll make that path preserve established confinement too and add a regression.
The review is complete. I confirmed the additional Codex repair bug with a failing regression and fixed it by sharing the transcript/home refresh policy with turn start. The remaining new byte and streaming dispatch paths preserve their intended boundaries. Final checks are running before I commit and resolve the findings.
Final lint passed. The changes include regressions for the three reported issues and the additional Codex repair issue. I’m waiting for the race and integration suite to finish before committing and pushing.
The full check passed. Committed as 78d943d17, covering the three reported findings and the additional Codex repair bug. I’ll push it, resolve the three trail findings with the commit reference, and check for remaining findings.
Fixed and pushed as 78d943d17: all three reported issues are addressed.
The follow-up review found and fixed another boundary downgrade in Codex partial-session repair, with a regression test.
Full mise run check passed. All three findings are resolved; no open trail findings remain. Worktree is clean.
I’ll trace where recorded boundaries can be cleared or bypassed, focusing on session repair, adoption, reattachment, and transcript relocation. I’ll add regressions and fix any confirmed downgrades.
I found an adoption fallback worth tightening: a rejected recorded home can still fall through to legacy reads when an explicit session-directory override puts the transcript outside the active home. I’m also checking partial repair for other agents and reattachment’s agent auto-detection, which can change the agent before checking whether a boundary was lost.
Three more downgrades are confirmed by failing tests: adoption can bypass a rejected home through a session-directory override, reattachment can auto-detect a home-less agent and erase the prior boundary, and non-Codex partial-session repair can discard AgentHome. The fixes are in place, and I’m checking them against existing adoption and override behavior.
A fourth regression reproduced a downgrade when the active home changes to a different symlinked root: an unsafe replacement transcript causes refresh to clear the old boundary. Refresh now retains an established same-agent boundary when it can’t safely accept the new path. I’m running the broader checks.
The focused regressions pass, including a positive case where the session moves to a readable transcript under a newly resolved home. Legacy session-directory overrides still work for sessions without an established boundary. The full check is running on the formatted tree.
I’m checking repeated turns as well as the first failed relocation. Retaining the old home beside a new path outside it leaves inconsistent coordinates that a later refresh could treat as provisional. I’ll reject unsafe relocations and keep the previous home/path pair intact.
The repeated-turn regression caught that second downgrade. Unsafe relocations now fail without changing the persisted home/path pair. Adoption also rejects a failed recorded-home check when agent identity is missing. The final check is running across all four fixes and their compatibility tests.
Lint passed with no issues. The full race and integration suite is still running. Once it passes, I’ll commit and push the four fixes, then recheck the trail findings.
Found and fixed four more downgrades, pushed as 57d1026a1:
- Adoption fallback through directory overrides or missing agent identity.
- Reattachment auto-detecting a home-less agent.
- Non-Codex partial repair discarding the boundary.
- Unsafe home/path relocation, including repeated turns.
Added regressions; full mise run check passed. No open trail findings remain, and the worktree is clean.