github / github/copilot-cli

Session recall in a fresh session returns another project's history (ordered by recency)

Open
#4,025 0 comments 0 reactions 0 assignees View on GitHub
area:context-memory area:sessions
Dominant language
Shell
Stars
11.2k
Forks
1.9k
Avg merge
14h 16m
Merged PRs (30d)
6

Description

## Describe the bug

A brand-new CLI session, asked to recall recent work (e.g. "what did we work on?"), can return session history from a *different project* on the same machine. All local sessions share one store (`~/.copilot/session-state.json`), and recall is ordered by global recency rather than the current project, so the most-recent session from an unrelated project is surfaced. When it happens, that content enters the current session's context and can influence the response.

## Affected version

1.0.68

## Steps to reproduce the behavior

1. In a terminal in Project A, run the CLI and have a short session.
2. In a separate terminal in Project B, run a separate session and make it the most recently active one.
3. Open a fresh terminal/session in Project A and ask: "what did we last work on?"
4. It can answer with Project B's work.

Reproduced in a plain terminal with no editor involved (i.e. not specific to any particular editor integration).

## Expected behavior

A fresh session's recall should be scoped to the current project (cwd/repo), or at minimum clearly indicate when it is surfacing another project's session.

## Additional context

**Actual behavior:** Recall resolves across all projects by recency and returns another project's content, with no indication that it crossed a project boundary.

**Notes / observations:**

- Retrieval is agent-mediated and therefore INTERMITTENT: with an identical setup, one fresh session self-scoped to the current project while another surfaced the globally-most-recent (cross-project) session.
- Recency appears to be driven by the latest turn timestamp, not by a session-level `updated_at` field (which can be stale).
- Project attribution can be unreliable: the stored repository value for a session does not always match the session's actual working directory.

**Impact:** Unrelated project context can enter the current session and steer subsequent responses. Because it is intermittent, a single "it stayed in-project" attempt does not prove the session is safe.

**Environment:**

- Operating system: Windows
- Copilot CLI version: 1.0.68

Contributor guide

Open the contributing guide

Research direction

Start by inspecting ~/.copilot/session-state.json and the CLI entry point that handles recall in a fresh session. Reproduce the two-project scenario, then trace how sessions are selected and attributed; done means recall stays scoped to the current project or clearly identifies cross-project history.

Written by the indexing model from the issue text.

Assessment

Tech stack
shell
Domain
cli
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.