refactor(pi-permission-inner-cmd): narrow bash recovery uniqueness to one message

- walk entries in reverse and stop at the latest assistant message containing the id
- require the id to match exactly one block within that message rather than across the whole session
- resolve a cross-message id reuse to the latest call being authorized
- update ADR 0001 wording for the narrowed scope
- add a regression test for cross-message id reuse
This commit is contained in:
2026-08-11 21:53:46 +08:00
parent f21cf54ff1
commit 06b21a28a6
3 changed files with 58 additions and 33 deletions
@@ -3,10 +3,10 @@ import type { SessionEntry } from "@earendil-works/pi-coding-agent";
import { recoverNativeBashCommand } from "../src/recovery";
/** Build a minimal assistant message entry carrying the given content blocks. */
function assistantEntry(content: unknown[]): SessionEntry {
function assistantEntry(content: unknown[], id = "entry-1"): SessionEntry {
return {
type: "message",
id: "entry-1",
id,
parentId: null,
timestamp: "2026-08-08T00:00:00.000Z",
message: {
@@ -156,6 +156,25 @@ describe("recoverNativeBashCommand", () => {
expect(recoverNativeBashCommand(entries, "call_1")).toBeUndefined();
});
it("returns the latest command when the id recurs across messages", () => {
// A cross-message id reuse resolves to the latest block, which is the
// call currently being authorized; the earlier block is already-
// resolved history and must not fail-closed the recovery.
const entries = [
assistantEntry(
[bashToolCall("call_1", "timeout 30s rm -rf /")],
"entry-a",
),
assistantEntry(
[bashToolCall("call_1", "timeout 30s pnpm test")],
"entry-b",
),
];
expect(recoverNativeBashCommand(entries, "call_1")).toBe(
"timeout 30s pnpm test",
);
});
it("tolerates a malformed content block that is not a tool call", () => {
const entries = [
assistantEntry([