Align Session initial-input and metadata update admission - #35
Merged
Merged
Conversation
SaladDay
force-pushed
the
codex/session-admission-alignment
branch
from
September 22, 2026 16:45
6e696d7 to
c4c8e51
Compare
SaladDay
marked this pull request as ready for review
September 22, 2026 16:45
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Conversation-only Session creation previously accepted missing input, and Session updates accepted an empty body. Owned official API probes reject both. Require input for
noneand streamed creation outsideself_hosted, reject empty metadata updates before resource lookup, and preserve explicit null/empty metadata clearing and valid local creation retries.Update Core Web and existing SDK fixtures together: no-input hosted creation uses JSON; an unchanged manual retry after a lost creation stream uses the same key/input with JSON to recover the Session. Keep observable initial history in tests. Record the 58-operation evidence inventory and remaining differences, including native harness/daemon behavior and whitespace-only input.
Validation: API/contract tests and full
make check-webpassed (287 client tests, 583 Web tests, 76 browser cases). Three real harness profiles completed six initial Turns with no replay, rejection-without-writes, metadata and tenant-isolation checks; hosted/self-hosted no-input paths were retained. Servermake -o check-web checkpassed with dedicated PostgreSQL; Web was run separately as above. Fixed Python SDK and Go-client service acceptance also passed. The live source was7ccc636; integrated test/fixture changes passed the server gate at01f9356. A subsequent tool-policy evidence-count assertion compiled, with its optional native run skipped because private per-run options were not supplied. No new E2B, OAuth or native capability combination is claimed. Fresh independent Astra high full-diff review found no grounded in-scope blockers and independently passed API/contract plus 39 Web tests. Rebase onto main6a3131epreserved all patches; combined API/execution/contract and PostgreSQL scheduling/creation regressions passed. The optional packaged MiniMax native-tools probe was skipped; this batch does not requalify all native features.