dde53a8f18
Reviewer flagged that forwarding `LoadedCustomTool[]` from a parent session to a subagent reused tool instances whose factories had closed over the parent's `CustomToolAPI` — `cwd`, `exec`, `pushPendingAction`, and `ui` all pointed at the parent. In isolated tasks the tool would `exec` against the parent worktree and queue pending actions on the parent session. Forward only the path list; let each session rebuild tools through `loadCustomTools` so factories see the right `CustomToolAPI`. - `extensibility/custom-tools/loader.ts`: extract `discoverCustomToolPaths` (FS scan only) from `discoverAndLoadCustomTools`; export `ToolPathWithSource`. The combined helper is now `discoverCustomToolPaths` + `loadCustomTools`. - `sdk.ts`: replace `preloadedCustomTools` (`LoadedCustomTool[]`) with `preloadedCustomToolPaths` (`ToolPathWithSource[]`). The custom-tools block runs `loadCustomTools` unconditionally; only the path scan is skipped when the caller pre-discovered it. - `tools/index.ts`: `ToolSession.loadedCustomTools` → `ToolSession.customToolPaths` for the same reason. - `task/executor.ts` and `task/index.ts`: forward `customToolPaths`. Drop the forward for isolated subagents — the worktree shifts `cwd`, so the subagent re-discovers tools against its own working tree. - New `test/sdk-custom-tools-per-session-binding.test.ts` pins the contract: two `loadCustomTools` calls on the same path with different `cwd` and different `pushPendingAction` callbacks yield distinct tool instances whose factories see the per-call bindings. - Updated `executor-pass-through` and `sdk-preloaded-extensions-isolation` tests for the new option name and added a `ToolPathWithSource` fixture. Refs PR review on #2193