propagate native session identity to structured children

This commit is contained in:
Merge Sim
2026-09-08 16:13:57 -07:00
parent 429011f1e4
commit 9c23b61ada
4 changed files with 43 additions and 20 deletions
@@ -240,17 +240,21 @@ export function createClaudeStructuredLaunchResolver(
command,
// Only a dispatched structured worker gets the orchestration identity and the Orca CLI on
// PATH; an ordinary chat session's env passes through untouched.
structuredWorkerChildIdentityEnv(record.sessionId, {
...applyClaudeEnvPatch(
cloneDefinedEnv(process.env),
{},
{
stripAuthEnv: auth.stripAuthEnv,
platform: process.platform
}
),
...(overlay ? cloneDefinedEnv(overlay) : {})
}),
structuredWorkerChildIdentityEnv(
record.sessionId,
{
...applyClaudeEnvPatch(
cloneDefinedEnv(process.env),
{},
{
stripAuthEnv: auth.stripAuthEnv,
platform: process.platform
}
),
...(overlay ? cloneDefinedEnv(overlay) : {})
},
record.lease.runtimeFence
),
{ platform: process.platform }
)
return {
@@ -1,5 +1,5 @@
import { z } from 'zod'
import { OptionalFiniteNumber, OptionalString, requiredString } from '../../../schemas'
import { OptionalFiniteNumber, OptionalString } from '../../../schemas'
export const OptionalWorkerLaunchPreference = z
.string()
@@ -17,7 +17,9 @@ export const WorkerStartParams = z
parent: OptionalString,
on: OptionalString,
run: OptionalString,
from: requiredString('Missing --from'),
from: z.string().min(1).optional(),
agentSessionId: OptionalString,
runtimeFence: OptionalFiniteNumber,
worktree: OptionalString,
name: OptionalString,
repo: OptionalString,
@@ -6,7 +6,7 @@ import {
decideWorkerStartMode,
readWorkerStartModeSettings
} from '../../orchestration-worker-start-mode'
import { resolveOrchestrationCaller } from '../runs/run-scope'
import { resolveOrchestrationCaller, resolveRunScope } from '../runs/run-scope'
import { WorkerStartParams } from './worker-start-schema'
import {
isWorkerStartTimeoutWithinTimerLimit,
@@ -30,11 +30,23 @@ export const ORCHESTRATION_WORKER_START_METHODS: RpcMethod[] = [
}
const readinessTimeoutMs = resolveWorkerStartReadinessTimeoutMs(params.timeoutMs)
const db = runtime.getOrchestrationDb()
const coordinatorPane = resolveOrchestrationCaller(runtime, {
callerTerminalHandle: params.from,
callerEvidence: orchestrationCompatibilityEvidence
})
const run = coordinatorPane ? db.getCurrentRunForPane(coordinatorPane) : undefined
const native = Boolean(params.agentSessionId)
const coordinatorPane = native
? null
: resolveOrchestrationCaller(runtime, {
callerTerminalHandle: params.from!,
callerEvidence: orchestrationCompatibilityEvidence
})
const run = native
? resolveRunScope(runtime, {
runId: params.run,
callerAgentSessionId: params.agentSessionId,
callerRuntimeFence: params.runtimeFence,
requireCurrentConsumer: true
})
: coordinatorPane
? db.getCurrentRunForPane(coordinatorPane)
: undefined
if (!run || (params.run && params.run !== run.id)) {
throw new OrchestrationError(
'consumer_fenced',
@@ -42,7 +42,8 @@ import { structuredWorkerIdentities } from './structured-worker-identity'
export function structuredWorkerChildIdentityEnv(
sessionId: string,
childEnv: Record<string, string>
childEnv: Record<string, string>,
runtimeFence?: number
): Record<string, string> {
const identity = structuredWorkerIdentities.getBySessionId(sessionId)
if (!identity) {
@@ -51,6 +52,10 @@ export function structuredWorkerChildIdentityEnv(
const env: Record<string, string> = {
...childEnv,
ORCA_TERMINAL_HANDLE: identity.handle,
ORCA_AGENT_SESSION_ID: sessionId,
...(runtimeFence !== undefined
? { ORCA_AGENT_SESSION_RUNTIME_FENCE: String(runtimeFence) }
: {}),
ORCA_CLI_COMMAND: 'orca'
}
applyOrcaCliPath(env)