Move a session to another working directory

`POST /sessions/{id}/cwd`, behind a field in the session settings dialog. A
working directory is settled when the process is spawned -- the CLI is
launched with it as its cwd and there is no control request that changes one
-- so this records the new one and ends the process that is in the old one.
It does not start a replacement, and the field says so in a line beside it:
a session with no process starts on the next message or on Start, which is
this app's rule for that everywhere else, and "usually restarts" is a worse
control than "always stops".

The path is checked against the session's own machine and refused if it is
not there. The spawn path corrects instead of refusing, because it is
resuming a directory the *machine* recorded and that can be gone through
nobody's fault; a path somebody has just typed is different, and a mistyped
one accepted here would surface much later as a session that would not
start, with nothing pointing at the typo. The refusal names the machine and
the path, and is drawn under the field it is about.

Nothing of Claude Code's own is moved, and that is measured rather than
assumed: on CLI 2.1.237, `claude --resume <id>` finds a session from any
working directory -- an id that does not exist answers "No conversation
found with session ID", and a real one resumed from an unrelated directory
did not. So the conversation continues in the new place with nothing
relocated. Doing otherwise would mean reproducing a rule this app cannot
see the whole of; PLAN.md records what that rule is, for whoever tries.

Found while checking it: `SessionInfo.cwd` came from the snapshot a session
launched with, so a moved session went on reporting its *old* directory for
as long as its process lived -- a dialog showing a directory the next launch
would not use, with nothing saying so. It is read from the config where the
row is built now, the same way `setup_name` already was, and for the reason
already written above `setup_name`: only the manager holds the config, and
both of these change under a running session.

Checked end to end on the emulator against a session whose process really
does take a cwd: /proc said /tmp/cwd-a before and /tmp/cwd-b after, the
dialog showed the new path immediately rather than after a restart, and a
directory that is not there and a relative path were both refused with the
session left exactly as it was.
This commit is contained in:
iris committed 2026-08-31 23:16:34 -04:00
1 parent 6236f0d5bd
commit deb908034c
6 files changed
+305 -11

No files matched your search

+65
View File
@@ -24,6 +24,8 @@
//! POST /sessions/{id}/stop end the process; the session and transcript stay
//! POST /sessions/{id}/start run the process again, continuing the conversation
//! POST /sessions/{id}/title {title}
//! POST /sessions/{id}/cwd {cwd} -- move it; stops the process,
//! which starts again in the new one
//! POST /sessions/{id}/model {model}
//! POST /sessions/{id}/command {text} -- /compact, /clear, /rename x, or the dialect's own
//! (starts the process first if it has exited)
@@ -101,6 +103,7 @@ pub fn router(manager: Arc<SessionManager>) -> Router {
.route("/sessions/{id}/stop", post(stop))
.route("/sessions/{id}/start", post(start))
.route("/sessions/{id}/title", post(rename))
.route("/sessions/{id}/cwd", post(set_cwd))
.route("/sessions/{id}/model", post(set_model))
.route("/sessions/{id}/permission-mode", post(set_permission_mode))
.route("/sessions/{id}/notify", post(set_notify))
@@ -1054,6 +1057,68 @@ async fn rename(
Ok(StatusCode::NO_CONTENT)
}
#[derive(Deserialize)]
#[serde(rename_all = "camelCase")]
#[serde(deny_unknown_fields)]
struct CwdRequest {
cwd: PathBuf,
}
/// Moves a session to a different working directory.
///
/// The directory is checked here rather than in the manager because
/// checking it is an ssh round trip on a remote setup, and the manager is
/// not async -- the same division `POST /sessions` already makes for the
/// directory an import was recorded in.
///
/// Checked rather than trusted, and refused rather than corrected: a
/// mistyped path that was accepted would leave a session recorded somewhere
/// its process cannot start, and the failure would arrive later, as a
/// session that would not come back, with nothing pointing at the typo. The
/// spawn path corrects instead because it is resuming a directory the
/// *machine* recorded, which can be gone through nobody's fault; a path
/// somebody has just typed is different.
///
/// Note what this does not do: it does not start a replacement process.
/// See [`SessionManager::set_session_cwd`].
async fn set_cwd(
State(manager): State<Arc<SessionManager>>,
UrlPath(id): UrlPath<String>,
axum::Json(body): axum::Json<CwdRequest>,
) -> Result<StatusCode, ApiError> {
let session = manager
.sessions()
.into_iter()
.find(|session| session.id == id)
.ok_or_else(|| ApiError::NotFound(format!("no session {id}")))?;
let cwd = body.cwd.to_string_lossy().trim().to_string();
if cwd.is_empty() {
return Err(ApiError::BadRequest(
"a working directory is a path, and this one is empty".to_string(),
));
}
// Absolute, because the alternative is relative to whatever the CLI is
// launched from, which is not something the person typing it can see.
if !cwd.starts_with('/') && !cwd.starts_with('~') {
return Err(ApiError::BadRequest(format!(
"{cwd} is not an absolute path, so where it would be depends on where the \
session happens to start"
)));
}
let setup = setup_by_id(&manager, &session.setup)?;
let transport = crate::session::transport::Transport::for_setup(&setup);
if !crate::session::import::directory_exists(&transport, &cwd).await {
return Err(ApiError::BadRequest(format!(
"{} has no directory {cwd}",
setup.name
)));
}
manager
.set_session_cwd(&id, PathBuf::from(&cwd))
.map_err(bad_request)?;
Ok(StatusCode::NO_CONTENT)
}
#[derive(Deserialize)]
#[serde(deny_unknown_fields)]
struct ModelRequest {
+77 -5
View File
@@ -500,15 +500,31 @@ impl LiveSession {
Ok(name)
}
/// `setup_name` is passed in rather than stored: only the manager
/// holds the config, and the label can change under a running session.
/// `setup_name` and `cwd` are passed in rather than read from the
/// snapshot this session launched with: only the manager holds the
/// config, and both of them can change under a running session. The
/// label changes when a setup is renamed; the directory changes when
/// somebody moves the session, and reading the snapshot reported the
/// old one for as long as the process lived -- a screen showing a
/// directory the next launch will not use, with nothing saying so.
///
/// Passed rather than mirrored into `Shared`, which is where `title`
/// and `notify` live: a second copy is a second thing to keep level,
/// and this way there is one answer, read where the row is built.
///
/// `kind` rather than the facts derived from it: two of this row's
/// fields are answers about the provider's *kind*, and passing them
/// separately meant every caller deriving each one and a third arriving
/// as a third parameter. `None` where the provider has been edited away,
/// which is a session that cannot run -- so both answers are the
/// cautious one rather than a guess.
fn info(&self, setup_name: &str, imported: bool, kind: Option<DriverKind>) -> SessionInfo {
fn info(
&self,
setup_name: &str,
cwd: Option<&Path>,
imported: bool,
kind: Option<DriverKind>,
) -> SessionInfo {
SessionInfo {
id: self.meta.id.clone(),
provider: self.meta.provider.clone(),
@@ -522,7 +538,7 @@ impl LiveSession {
max_image_edge: kind.and_then(DriverKind::max_image_edge),
imported,
keeps_own_transcript: kind.is_some_and(DriverKind::keeps_own_transcript),
cwd: self.meta.cwd.clone(),
cwd: cwd.map(Path::to_path_buf),
status: *self.shared.status.lock().unwrap(),
last_activity: *self.shared.last_activity.lock().unwrap(),
created: self.meta.created,
@@ -962,6 +978,7 @@ impl SessionManager {
.map(|meta| match inner.live.get(&meta.id) {
Some(session) => session.info(
label_of(&inner.config, &meta.setup),
meta.cwd.as_deref(),
import::read_cursor(&self.data_dir.join(&meta.id)).is_some(),
kind_of(&inner.config, &meta.setup, &meta.provider),
),
@@ -1123,6 +1140,7 @@ impl SessionManager {
// listing asks of the directory a moment later.
let info = session.info(
&setup.name,
session.meta.cwd.as_deref(),
import::read_cursor(&self.data_dir.join(&id)).is_some(),
Some(provider.kind),
);
@@ -1285,6 +1303,60 @@ impl SessionManager {
/// for every provider that has a process at all -- so asking it here
/// stops a session whose driver is in no state to be asked, and adds no
/// method a new driver could implement wrongly.
/// Moves a session to a different working directory.
///
/// The directory is settled at spawn -- the CLI is launched with it as
/// its cwd and there is no control request that changes one -- so this
/// records the new one and ends the process that is in the old one. It
/// does **not** start a replacement: a session with no process starts
/// on the next thing said to it, or on Start, which is this app's one
/// rule for that everywhere else. Starting one here would have to wait
/// for the recorded status to catch up with a process that is already
/// gone, and "usually restarts" is a worse control than "always stops".
///
/// Nothing of Claude Code's own is moved, and that is a measurement
/// rather than an omission: `claude --resume <id>` finds a session from
/// any working directory (checked against 2.1.237 on 2026-08-31 -- an
/// id that does not exist says "No conversation found with session ID"
/// and a real one resumed from an unrelated directory did not), so the
/// conversation continues in the new place with nothing relocated. The
/// file stays under the project directory the CLI made for it, which is
/// where the CLI itself looks. Reimplementing that directory's name to
/// move it would mean reproducing a rule this app cannot see the whole
/// of -- the CLI truncates at 200 characters and appends a hash of its
/// own, and an override can replace the name entirely -- to relocate a
/// file the CLI is still writing.
///
/// Whether the directory exists is the caller's question, because
/// asking it is an ssh round trip on a remote setup; see the route.
pub fn set_session_cwd(&self, id: &str, cwd: PathBuf) -> Result<()> {
{
let mut inner = self.inner.write().unwrap();
if !inner.config.sessions.iter().any(|meta| meta.id == id) {
bail!("no session {id}");
}
let mut candidate = inner.config.clone();
for meta in candidate.sessions.iter_mut().filter(|meta| meta.id == id) {
meta.cwd = Some(cwd.clone());
}
candidate.save(&self.config_path)?;
inner.config = candidate;
}
// Saved first, so a process that cannot be stopped leaves a session
// that will start in the right place rather than one recorded in a
// directory nothing agrees with.
let dir = self.data_dir.join(id);
if let Some(record) = process::live(&dir) {
tracing::info!(
"moving session {id} to {} -- stopping pid {}",
cwd.display(),
record.pid
);
process::stop(&record, process::STOP_GRACE);
}
Ok(())
}
pub fn stop_session(&self, id: &str) -> Result<()> {
if !self
.inner
@@ -2497,7 +2569,7 @@ mod tests {
assert_eq!(first.session_id, info.id);
// The title travels with it, because the phone may have no screen
// open to look one up on.
assert_eq!(first.title, session.info("m", false, None).title);
assert_eq!(first.title, session.info("m", None, false, None).title);
manager.set_session_notify(&info.id, false).expect("off");
// Subscribed before the message, or the turn can finish in the gap