Skip to content

use strings.Contains - #5

Merged
Soph merged 1 commit into
mainfrom
soph/use-go-string-contains
Jan 6, 2026
Merged

use strings.Contains#5
Soph merged 1 commit into
mainfrom
soph/use-go-string-contains

Conversation

@Soph

@Soph Soph commented Jan 5, 2026

Copy link
Copy Markdown
Collaborator

No description provided.

Entire-Checkpoint: f5e7d3c25b68
@Soph
Soph requested a review from dipree January 5, 2026 17:30

@dipree dipree left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@Soph
Soph merged commit 3635247 into main Jan 6, 2026
3 checks passed
@Soph
Soph deleted the soph/use-go-string-contains branch January 7, 2026 16:19
khaong added a commit that referenced this pull request Jan 27, 2026
- Add ValidateAgentUUID to validation package using google/uuid
- GetOrCreateEntireSessionID now validates UUID format
- Invalid UUIDs generate a random safe UUID instead of using untrusted input
- Log warning with original input and generated ID when fallback occurs
- Add thread-safety documentation to GetOrCreateEntireSessionID
- Update tests to use valid UUIDs
- Add test for invalid UUID fallback behavior

Addresses Copilot review comments #5 and #6.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Entire-Checkpoint: 47672e4ef20f
khaong added a commit that referenced this pull request Jan 27, 2026
- Add ValidateAgentSessionID to validation package (path-safe check, not UUID)
- GetOrCreateEntireSessionID validates input and logs warning if invalid
- Add thread-safety documentation to GetOrCreateEntireSessionID
- Rename parameter from agentSessionUUID to agentSessionID for clarity
- Add tests for ValidateAgentSessionID

Allows test IDs like "test-session-1" while preventing path traversal.
Addresses Copilot review comments #5 and #6.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
alishakawaguchi added a commit that referenced this pull request May 20, 2026
CI lint:
- escape U+200B literals (staticcheck ST1018)

Real bugs (cursor[bot] + Copilot review):
- loop: ctx-cancel mid-cmd.Run() now classifies as OutcomeCancelled
  instead of being counted as a turn failure and tripping OutcomePaused
  after two consecutive cancels (#1)
- loop: save state before returning OutcomePaused so --continue resumes
  from a snapshot that includes the failing turn (#11)
- investigate fix: wrap context.Canceled as SilentError so Ctrl+C during
  the fix session doesn't print a cobra usage banner (#2)
- cmd: redact URL userinfo on the issue-link Source: line in both
  interactive and non-interactive paths (#5)
- issuelink: redact URL userinfo across gh stderr (not just argv) so a
  token in --issue-link cannot leak via the error path (#10)
- cmd: outcome-aware footer — "Investigation ended" + resume hint for
  paused/cancelled, "Investigation complete" + fix hint only for
  Quorum/Stalled (#6)
- cmd: validate maxTurns/quorum bounds after settings/flag merge so a
  hand-edited negative max_turns or oversized quorum errors cleanly
  instead of silently stalling (#7)
- issuelink: tolerate GitHub URL trailing segments (/pull/123/files,
  trailing slash) — the regex now anchors prefix and ignores tail (#13)
- picker: don't print "Saved investigate config" before persistence;
  moved to the caller after SaveLocal succeeds (#14)
- picker: guard pickerFormOverride with atomic.Pointer so parallel
  tests that swap the override don't race (#12)

Docs:
- settings/loop: fix stale "0 → 3" max_turns doc; default is 2 (#8/#9)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Entire-Checkpoint: b0135abeee0d
Soph added a commit that referenced this pull request May 20, 2026
…693 exchange

Pins github.com/entireio/auth-go to its hardened OAuth client (PR #5
head), which validates Resource as an origin URL, refuses unsigned JWTs
(alg:none), enforces HTTPS unless the host is loopback, validates the
verification_uri returned by the AS, and centralises OAuth error
parsing with sanitised descriptions.

auth/client.go: now a thin shim over deviceflow.Client. Preserves the
historical DeviceAuthStart/DeviceAuthPoll types as aliases / equivalent
shapes so login.go's polling switch keeps working. Unknown OAuth error
codes are surfaced through DeviceAuthPoll.Error/ErrorDescription so
login.go can fail fast on terminal rejections instead of treating them
as transient.

auth/store.go: implements tokenstore.Store (SaveTokens/LoadTokens/
DeleteTokens) so it can be passed to tokenmanager.New. Adds a defensive
JSON-shape check on read — pre-shim entries are opaque token strings,
never JSON; a JSON blob in the keyring is corruption and must not be
put on the wire as a bearer.

auth/exchange.go: new package-level Manager wired from CurrentProvider,
AuthBaseURL, and NewStore. Exposes TokenForResource(ctx, url) and Token
(ctx, req); both go through the manager's same-host shortcut, JWT-aud
shortcut, and STS exchange dispatch as appropriate. SetManagerForTest()
takes a mutex so concurrent tests can swap without racing.

Single-host deployments hit the same-host shortcut and never call STS;
split-host deployments perform an RFC 8693 token exchange against the
auth issuer's STS endpoint to mint a resource-scoped bearer.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Entire-Checkpoint: 6d696fc55440
computermode added a commit that referenced this pull request May 20, 2026
Five small cleanups identified by post-merge review:

1. Extract checkpoint.PreserveV1HistoryAndLog so the 'preserve + WARN on
   failure' pattern at the three read entry points in committed.go
   (WriteCommitted, ReadCommitted, ListCommitted) is one line each
   instead of three.
2. Pull the 1.1 tracking-ref shape into paths constants:
   MetadataTrackingRefPrefix, MetadataTrackingRefSuffix, plus a
   BuildMetadataTrackingRef(remoteName) helper. The MetadataTrackingRefName
   constant is now expressed in terms of those constants, and
   MetadataTrackingRefForRemote uses BuildMetadataTrackingRef instead of
   inline string concatenation.
3. Name the recognized checkpoints_version literals
   (checkpointsVersion11FloatLit, checkpointsVersion11StringLit, etc.)
   so parseCheckpointsVersion and UsesCustomMetadataRef refer to the
   same source of truth instead of repeating 1.1 / "1.1" magic.
4. installMetadataRefspec uses gitremote.GetRemoteURL instead of a
   raw exec.CommandContext to detect origin's presence — one less
   place that knows the underlying git command.
5. Tighten the refspec-existence loop in installMetadataRefspec so an
   empty 'git config --get-all' output isn't compared as a single empty
   line against the refspec (TrimSpace per line, not the whole buffer).

No behavior change beyond #5's edge-case tightening.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Entire-Checkpoint: 4faf19afed2d
Soph added a commit that referenced this pull request May 21, 2026
…693 exchange

Pins github.com/entireio/auth-go to its hardened OAuth client (PR #5
head), which validates Resource as an origin URL, refuses unsigned JWTs
(alg:none), enforces HTTPS unless the host is loopback, validates the
verification_uri returned by the AS, and centralises OAuth error
parsing with sanitised descriptions.

auth/client.go: now a thin shim over deviceflow.Client. Preserves the
historical DeviceAuthStart/DeviceAuthPoll types as aliases / equivalent
shapes so login.go's polling switch keeps working. Unknown OAuth error
codes are surfaced through DeviceAuthPoll.Error/ErrorDescription so
login.go can fail fast on terminal rejections instead of treating them
as transient.

auth/store.go: implements tokenstore.Store (SaveTokens/LoadTokens/
DeleteTokens) so it can be passed to tokenmanager.New. Adds a defensive
JSON-shape check on read — pre-shim entries are opaque token strings,
never JSON; a JSON blob in the keyring is corruption and must not be
put on the wire as a bearer.

auth/exchange.go: new package-level Manager wired from CurrentProvider,
AuthBaseURL, and NewStore. Exposes TokenForResource(ctx, url) and Token
(ctx, req); both go through the manager's same-host shortcut, JWT-aud
shortcut, and STS exchange dispatch as appropriate. SetManagerForTest()
takes a mutex so concurrent tests can swap without racing.

Single-host deployments hit the same-host shortcut and never call STS;
split-host deployments perform an RFC 8693 token exchange against the
auth issuer's STS endpoint to mint a resource-scoped bearer.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Entire-Checkpoint: 6d696fc55440
suhaanthayyil added a commit that referenced this pull request Jun 30, 2026
Resolves the review packet on the Codex subagent change:

- #1 Codex task-checkpoint UUID: documented that CheckpointUUID is
  Claude-format-specific (tool_result/UUID) and resolves to "" for Codex —
  rewind to a Codex task checkpoint restores files via the shadow tree but does
  not truncate the transcript (graceful fall-through; restore truncation is also
  Claude-only). Codex-aware line-offset truncation is a deferred follow-up.
  Comment at the call site + AGENT.md.
- #2 Resumed-subagent token under-count: documented deliberate trade-off (chosen
  over the worse cross-turn double-count) + observability — logResumedOutOfRangeChildren
  debug-logs when a resume_agent targets a child spawned in a prior range.
- #3 Regression tests: CalculateTotalTokenUsage nil-main-with-subagent-tokens
  unit test (guards the nil-deref); new integration test
  TestCodexSubagentEnd_SourcesFilesFromChildNotParent (+ SimulateCodexSubagentStart/Stop
  harness helpers) guarding handleLifecycleSubagentEnd's child-not-parent resolver.
- #4 Debug logging across the discover→resolve→read→parse chain
  (readSubagentRolloutsUncached, CalculateTotalTokenUsage, spawn-output drop) so
  Codex wire-format drift is visible instead of silently zeroing attribution.
- #5 isCodexSubagentRollout: nested source.subagent fallback for rollouts without
  thread_source + backward-compat test (missing marker → treated as parent turn).
- #6 + nits: t.Parallel() on the pure-logic codex tests; AGENT.md PostToolUse line
  corrected (it IS consumed); StepTranscriptStart aligned to the resolved
  transcriptOffset (removes the exec/no-preState divergence; field is currently
  unconsumed by the strategy).

go build (incl. integration tag), vet, unit + codex integration tests, lint (0) all green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
suhaanthayyil added a commit that referenced this pull request Jul 15, 2026
Resolves the review packet on the Codex subagent change:

- #1 Codex task-checkpoint UUID: documented that CheckpointUUID is
  Claude-format-specific (tool_result/UUID) and resolves to "" for Codex —
  rewind to a Codex task checkpoint restores files via the shadow tree but does
  not truncate the transcript (graceful fall-through; restore truncation is also
  Claude-only). Codex-aware line-offset truncation is a deferred follow-up.
  Comment at the call site + AGENT.md.
- #2 Resumed-subagent token under-count: documented deliberate trade-off (chosen
  over the worse cross-turn double-count) + observability — logResumedOutOfRangeChildren
  debug-logs when a resume_agent targets a child spawned in a prior range.
- #3 Regression tests: CalculateTotalTokenUsage nil-main-with-subagent-tokens
  unit test (guards the nil-deref); new integration test
  TestCodexSubagentEnd_SourcesFilesFromChildNotParent (+ SimulateCodexSubagentStart/Stop
  harness helpers) guarding handleLifecycleSubagentEnd's child-not-parent resolver.
- #4 Debug logging across the discover→resolve→read→parse chain
  (readSubagentRolloutsUncached, CalculateTotalTokenUsage, spawn-output drop) so
  Codex wire-format drift is visible instead of silently zeroing attribution.
- #5 isCodexSubagentRollout: nested source.subagent fallback for rollouts without
  thread_source + backward-compat test (missing marker → treated as parent turn).
- #6 + nits: t.Parallel() on the pure-logic codex tests; AGENT.md PostToolUse line
  corrected (it IS consumed); StepTranscriptStart aligned to the resolved
  transcriptOffset (removes the exec/no-preState divergence; field is currently
  unconsumed by the strategy).

go build (incl. integration tag), vet, unit + codex integration tests, lint (0) all green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants