Lifts the RFC 010 § Deferred restriction that the server had to launch in the
workspace ("cwd must equal the launch directory"). An editor can now open any
project folder, and N concurrent sessions over one connection can each target a
different directory.
- packages/acp: drop the `cwd === process.cwd()` guard in validateWorkspaceParams
(keep "must be absolute" — the cwd becomes the session header / bash workdir),
and drop the persisted-cwd-vs-launch-dir check in session/load (a resumed
session keeps its original header.cwd, so its bash tools run in its workspace).
- packages/tool-bash: the missing link — default the bash workdir to the calling
agent's session cwd (`exec.agent.session.header.cwd`) via a new resolveWorkdir
helper. An explicit model `workdir` still wins; a relative one resolves against
the session cwd. This is the only correct spot for multi-session: N sessions
share one ctx.bash executor, so the workdir must come per-call from exec.agent,
not executor config. Falls back to the executor default when no session cwd is
available (preserves non-ACP behavior).
- Trust: the cwd originates from the ACP client (the user's editor) at
session/new — same trust level as the old launch dir; no new untrusted-input
path. `additionalDirectories` (scope widening / sandbox) stays rejected.
- Tests: bridge accepts any absolute cwd + records it on the header; session/load
honors the persisted cwd; bash defaults to / resolves relative against the
session cwd; two sessions with different cwds each run bash in their own dir;
non-absolute cwd still rejected. 100% per-file coverage maintained.
- Docs: RFC 010 status + § Deferred cwd bullet marked RESOLVED; acp README adds a
Per-session cwd section; tool-bash + example READMEs and e2e comments updated.
RFCs
Proposals for substantial future work — reviewed before implementation, unlike ADRs (which record decisions already made). Each RFC groups a related set of ideas from the quality/robustness proposal (2026-06-11); statuses move proposed → accepted → implemented (then usually graduate to an ADR).
| # | Title | Status |
|---|---|---|
| 001 | Property-based testing for protocol-shaped code | implemented |
| 002 | Mutation testing as the coverage counterweight | proposed |
| 003 | Deterministic tests + replay invariant fixture + race stress | proposed |
| 004 | Architectural rules: dependency-cruiser, adapter conformance kit | proposed |
| 005 | Runtime arg validation, structured error taxonomy, dev-mode invariants | implemented |
| 006 | Doc-sync enforcement and API extractor reports | implemented (pts 1-2; pt 3 deferred) |
| 007 | Supply chain checks and vendor drift verification | proposed |
| 008 | Deep-readonly public surfaces | implemented (revised) |
| 009 | Durable session persistence — abstract, append-only, event-based store | proposed |
| 010 | Agent Client Protocol (ACP) support for external editors | proposed |
| 011 | Multiplex concurrent ACP sessions over one connection | proposed |
| 012 | Optional Code Mode — model writes TypeScript against an SDK of all tools | proposed |
| 013 | Runtime schemas for the event vocabulary (Zod vs the merge-extensible-map pattern) | proposed |