CL-8980: make read_file continuation failures recoverable rather than terminal - #1172
Closed
TheGreatAxios wants to merge 4 commits into
Closed
TheGreatAxios wants to merge 4 commits into
TheGreatAxios wants to merge 4 commits into
Conversation
Red tests for CL-8980: verbatim handle-following must yield the next window across session resume, dead handles must name source plus offset instead of a bare missing blob, never-handles must stay missing-blob errors, compaction stubs must preserve the resume recipe, spent replays stay single-next-call errors, and guard denials stay isError results outside decline classification.
Truncated reads minted opaque one-shot handles that died with the plugin instance: after resume, prune, or compaction the URI was a bare missing blob with no source or offset. Handles are now self-describing (source, offset, window, nonce ride in the URI), so a verbatim follow serves the next window with no in-memory record; dead handles fail as isError naming source plus offset; never-handles still fail as missing blobs; spent replays stay single-use errors; notices carry a plain path plus offset fallback; compaction stubs preserve resume recipes.
A hand-crafted tool-output:///cursor handle naming an outside-root file passed the spill-URI exemption and was served without any containment check. The sandbox now resolves the embedded file source through the normal workspace check at authorize and execution time.
Collaborator
Author
|
Superseded by #1179 (single-way path+offset resume). Closing per release review. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Truncated reads minted opaque one-shot in-memory handles: after session resume, prune, or compaction the URI was a bare missing blob with no source or offset named, and the notice hid the original path, leaving no fallback.
What changed:
Verification:
Sibling note: CL-8979 works the same read_file area on a separate branch; this diff is recovery behavior only.
Fixes CL-8980