What happened?
step --continue can open and append to another project's session. The paths /tmp/case/project-a and /tmp/case/project/a both map to the same default session directory. list() shows both projects' sessions and --continue picks whichever file is newest, ignoring its header cwd. This mixes conversation history and can modify the wrong project's session file. Reproduced 5/5 times on cb5fc14 with extensions disabled.
Steps to reproduce
- Use an isolated
STEP_CODING_AGENT_DIR, with STEP_CODING_AGENT_SESSION_DIR unset.
- Create and persist a session in each of the two paths above. Make the
project/a session newer.
- From
project-a, list sessions and continue the latest one. Both sessions appear; continue opens the project/a file. A new message from project-a is appended to that file.
Expected behavior
Current-project listing and continue should match the session header's actual cwd; a colliding directory name must not select a foreign session. I can implement the fix.
Version
0.84.4
What happened?
step --continuecan open and append to another project's session. The paths/tmp/case/project-aand/tmp/case/project/aboth map to the same default session directory.list()shows both projects' sessions and--continuepicks whichever file is newest, ignoring its headercwd. This mixes conversation history and can modify the wrong project's session file. Reproduced 5/5 times oncb5fc14with extensions disabled.Steps to reproduce
STEP_CODING_AGENT_DIR, withSTEP_CODING_AGENT_SESSION_DIRunset.project/asession newer.project-a, list sessions and continue the latest one. Both sessions appear; continue opens theproject/afile. A new message fromproject-ais appended to that file.Expected behavior
Current-project listing and continue should match the session header's actual
cwd; a colliding directory name must not select a foreign session. I can implement the fix.Version
0.84.4