Skip to content

feat: preview and edit shell results before model sharing (#281) - #308

Merged
AetherAI3 merged 2 commits into
mainfrom
feat/issue-281
Oct 6, 2026
Merged

AetherAI3 merged 2 commits into
mainfrom
feat/issue-281

Conversation

@AetherAI3

Copy link
Copy Markdown
Owner

Closes #281.

What changed

  • /shell-result stages and prints the exact sanitized prompt attachment. Users can inspect numbered lines, drop or replace a line, mask a literal, apply the existing redaction aid, send, or cancel.
  • The staged text retains its source shell session and command ID even if a newer command finishes. The attachment records the captured command, directory, exit status, command-output omission count, later staging omissions, and user edits.
  • /shell-result send is the explicit one-step form for pipe/JSON sessions. Preview, edit, cancel, and empty selections do not call a model. Shared content retains untrusted-data framing and is excluded from console history, task continuation, and auth-repair drafts.
  • Help, generated command documentation, and the README show the workflow.

Evidence

  • npm run docs:check passed (build/typecheck and six generated documentation outputs).
  • Focused Windows tests: node --test dist/test/console_input.test.js dist/test/console_shell.test.js dist/test/bounded_output.test.js dist/test/shell_output_capture.test.js dist/test/shell_session.test.js — 27 passed, 0 failed; 18 platform-specific tests skipped on Windows.
  • Additional final console and bounded-output run: 20 passed, 0 failed.
  • Fixtures cover TTY and line-mode routing, zero calls on preview/cancel, exact preview-to-send equality, immutable source binding across a newer command, edits and masking, Unicode/ANSI sanitation, nonzero exits, large-log omission counts, and an empty selection that cannot send.
  • Support bundles include metadata-only redacted events and exclude prompts and tool output; the console flow does not persist raw shell captures to ordinary history.

Linux runner checks are expected to exercise persistent-shell cases skipped on Windows.

@AetherAI3

Copy link
Copy Markdown
Owner Author

Exact-head review for 1d8373d36f87cd9bed51432b857afc7272311d53:

  • Linux CI job: Build and test passed — 3,368 tests, 3,357 passed, 11 skipped, 0 failed. The new staging/editing, TTY, line-mode, cancellation, and shell history fixtures passed. Independent Python ATS and managed-host checks also passed.
  • Local Windows: focused console and bounded-output tests 20/20 passed; additional output-capture tests passed. npm run docs:check and git diff --check passed.
  • CodeQL job: Initialize and Analyze passed; the job's required evidence upload failed.

The remaining red/queued checks have separate causes: GitHub artifact storage quota rejects evidence uploads; the Linux job cannot fetch the pinned private ATSv2 repository (https://github.com/AetherAI3/ATSv2/ returned repository not found); release:truth reports 11/12 checks passed and requires a frozen-prerelease operator packet for already-published 0.4.0; the Windows self-hosted runner aether-aws-windows-agent-01 is offline, leaving that job queued. These are disclosed for the admin merge; they are not represented as passing checks.

Reviewed flow: preview and edits are local; send uses the exact staged attachment; a later command cannot replace it; cancelled and empty selections yield no chat turn. Shared text is excluded from console history and continuation/auth-repair drafts. Support bundles use metadata-only redacted events and exclude prompts and tool output.

@AetherAI3
AetherAI3 merged commit 881cd5c into main Oct 6, 2026
2 of 7 checks passed
@AetherAI3
AetherAI3 deleted the feat/issue-281 branch October 6, 2026 19:57

Copy link
Copy Markdown
Owner Author

Acceptance review for #281 at exact head 1d8373d36f87cd9bed51432b857afc7272311d53 found reproducible gaps using harmless synthetic fixtures in an isolated checkout:

  • Removing the editable command line does not remove the same command from the complete sent attachment: the envelope adds it back outside the editable body.
  • Replacing a line with 8,193 ASCII bytes is accepted and produces an 8,828-byte attachment, exceeding the bounded attachment contract.
  • Preview and direct share agree, but the actual runTurn request with AGENTS.md context changes tag-shaped text through escaping, so the complete preview is not the exact wire content.
  • A mocked custody receipt echoing attachment content is persisted to custody.jsonl.

These checks compiled and ran without changing this branch. PR #309 contains an independently tested implementation addressing these boundaries, plus TTY/pipe history, failure-recovery, immutable queued-send and local-backend coverage. There is overlapping work; neither implementation should be counted as closure evidence until the chosen combined change passes the acceptance tests on its landed revision. No claim of production exposure or live-service qualification is made.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[feature] Preview and edit a shell result before sharing it with the model

1 participant