diff --git a/.ai/contexts/session-cache.md b/.ai/contexts/session-cache.md index 36189aa7..67d19593 100644 --- a/.ai/contexts/session-cache.md +++ b/.ai/contexts/session-cache.md @@ -758,6 +758,60 @@ created the `.jsonl`; a manual host refresh did not help. rel path, not its own, because `readSubagentMeta()` in the transcript's row is what actually needs re-deriving. +## Remote hosts — sending a prompt (issue #219) + +`remote-send.js` writes one prompt to a live, unattached remote session through +the CLI's own messaging socket. Send only: nothing is read back, the state comes +from the descriptor the refresh cycle already pulls. + +- **Protocol** (measured in the issue, CLI 2.1.263): NDJSON over a unix socket, + one line `{"type":"user","message":{"role":"user","content":...},"msgV":1,"session_id":...}` + terminated by ` +`, capped at 1 MiB, first line within 30 s. The connection is + one-way; the server never answers on it. No auth line on POSIX (the peer is + identified by `SO_PEERCRED`); on Windows the token lives in a `.key` file that + the descriptor fetch and the denylist exclude on purpose, so a `\.\pipe\` + path is refused, not worked around. +- **`session_id` is in the line** so a descriptor that outlived its process, whose + pid was reused, never has its prompt accepted by another session. +- **The text is stdin only.** `defaultRunRemoteCommand` takes an `input` option: + stdin becomes a pipe, `-n` (which points ssh's stdin at the null device) is + dropped, the line is written and stdin closed. Same spawn site as every other + remote ssh, so `remote-ssh-spawn-sites.test.js` is unchanged. The remote + command holds fixed text, the integer pid and the single-quoted path. + The script is passed as `sh -c '