fix: keep named sessions visible in scoped inventory - #2164
Conversation
Size Report
npm unpacked components
Startup median (7 runs, lower is better):
Top changed chunks:
Top changed packed files
|
|
Reviewed exact head |
f40d382 to
c1ee1e2
Compare
|
Addressed in The inventory now resolves tenant ownership from the canonical Regression coverage uses one mixed inventory: the caller's implicit cwd session and a local explicitly named session remain visible; another cwd and a lease-less tenant session stay hidden. A second test proves tenant A cannot see tenant B or global local sessions. The mixed regression was observed failing before the production fix because Validation: |
|
Two actionable findings still block readiness at
The new tenant-prefix test fixes the prior direct case but does not cover either ambiguous ownership shape. No |
c1ee1e2 to
8394fd7
Compare
|
Addressed both findings at
Planted-red evidence: before the production change, the local inventory regression omitted local Exact-head validation: 39 focused tests pass across the six routing/inventory/open suites. |
|
Follow-up: all checks on |
|
Summary
Keep explicitly named sessions visible in
agent-device session listwhile preserving cwd and tenant isolation.Session creation now persists explicit provenance (
cwd,tenant,named-local, orglobal-default), and inventory filtering uses that stored fact instead of reconstructing ownership from the session address. This keeps a valid local name such astenant-a:qalocal, prevents tenant inventories from seeing it, and prevents a global unscopeddefaultfrom leaking into cwd-scoped inventory.This fixes the reported contradiction where
--session qa-cart-integrityremained bound to an Android recording session whilesession list --jsonreturned an empty list. Externally terminating the emulator still does not silently discard the recording session:record stopretains its recovery opportunity andcloseremains the explicit fallback.Also clarify selector conflicts by saying the session is bound to the device, rather than saying the command itself is bound to the session.
Validation
The regressions were observed red before the production change: local inventory omitted
tenant-a:qaand leaked globaldefault, while tenant A inventory also leaked the local colon-named session. Tests now cover both directions, cross-worktree filtering, and provenance stored through real tenant and cwd open routes.At exact head
8394fd7c1f, 39 focused routing, inventory, open, and session-runner tests pass.pnpm check:affected --runpassed format, lint, typecheck, layering, fallow, and build; its related-test lane passed 1,423 tests and hit two 5-second provider-scenario timeouts. The recording scenario passed in isolation, and the remaining scripted iOS Settings timeout reproduced unchanged at pre-review headc1ee1e2e33.Exact-head GitHub CI is green, including integration, coverage, repository guards, CodeQL, package checks, and Android/iOS/Linux/macOS smoke. The iOS workflow exercised its simulator smoke paths; its physical-device step was skipped by workflow policy.
No separate live device run was needed because the changed behavior is deterministic daemon inventory filtering and provenance; recording recovery mechanics are unchanged.
17 files changed, all within the session command family and mirrored tests; scope did not grow beyond that family.