16a173a8d6
The command wrapper prints the cwd marker after the command returns. A killed or timed-out command emits no marker, so ``env.cwd`` still holds the directory of the last command to FINISH. One local environment serves every session, because ``_resolve_container_task_id`` collapses cwd-only overrides to ``"default"``. That leftover directory is therefore routinely another session's. The post-command dual-write copied ``env.cwd`` into the interrupted session's durable record. Every later command in that session then ran in the foreign directory, and the cwd echo told the model it had moved there. A desktop chat silently re-homed into a worktree that another chat had opened. Report the observation instead of inferring it. The marker parse now sets ``result["cwd_observed"]``, and both the record write and the echo read that flag. The local override clears the flag when it rolls back a path that does not exist, because the restored value is also unobserved. When a command reports no cwd, the session keeps the directory it already had. This needs no second session to be wrong: a lone session that interrupts a command re-adopts a stale value too. A second session only makes the wrong directory belong to somebody else. The same class of write exists in the file-tools rescue for a reaped environment (#26211). That rescue copied the cached snapshot of the shared ``env.cwd`` into the session record. The rescue is now fill-only: it writes the snapshot when the session has no record, and it never overwrites a record that the session wrote for itself. The tests drive ``terminal_tool`` itself through an interrupt, not a copy of its gate. Review found that a revert of either call site passed the first version of the tests. Each gate now has a test that fails when the gate is removed (verified by mutation). Two exact-dict assertions in the Vercel sandbox tests now assert the two fields they care about, so a new result key does not fail them.