Skip to content

feat(session): journal immutable task-owner retirement attempts - #6314

Merged
Yeachan-Heo merged 3 commits into
devfrom
fix/task-stack-10-journal-independent-base0e761
Oct 4, 2026
Merged

Yeachan-Heo merged 3 commits into
devfrom
fix/task-stack-10-journal-independent-base0e761

Conversation

@snowykr

@snowykr snowykr commented Oct 4, 2026

Copy link
Copy Markdown
Collaborator

Scope

Split #6240: install complete managed task-artifact-owner retirement journal APIs on dev 0e761bcc27b39eaeb21e4fcecd48b7cc8e764a6c, after externally merged #6293. Automatic owner production and trusted post-move task admission remain OFF. No GC/SDK owner-effect activation, legacy guard removal, or broader MCP/LSP redesign.

Exact head: 6c971f9bbf3c20bc9cd740081c23630ffef47dc4.
Actual dev production review cost: 709 additions + deletions: Scope707 plus generated native descriptor2. Tests457 and two release fragments6 excluded. No oversized dependent stack is included.

The journal authenticates original prepared authority and consecutive attempts, preserves original evidence and actual native outcomes, rejects expansion/replaced context, and verifies physical completion rather than promoting retained namespaces to completed. APIs are independently callable; their DTOs/receipts do not confer deletion authority.

Exact local qualification

On a separate clean checkout at the exact head, clean before and after:

  • bun test packages/coding-agent/test/managed-gc-retirement-journal.test.ts packages/coding-agent/test/managed-gc-retirement-codec.test.ts packages/coding-agent/test/task-artifact-owner-transcript.test.ts packages/coding-agent/test/task-artifact-owner-retirement.test.ts packages/coding-agent/test/session-storage.test.ts packages/coding-agent/test/gc-disk-retention.test.ts: exit0, 195 passed, 8 existing platform skips, 0 failed, 1002 assertions.
  • bun --cwd=packages/coding-agent run check: exit0 on 6c971f9bbf3c20bc9cd740081c23630ffef47dc4. Full vendor/Biome/type gate, including tsc -p tsconfig.json --noEmit; baseline2 warnings/1 info retained.

Native provenance: upstream dev is now0.18.6; historical0.18.5 and released0.18.6 bytes were not attributed to current source. bun run build:native completed successfully on exact build source b1fbdafa94f0ad68825d2d46590ba4ad81e013e0, ci profile, 115 exports. Native crates tree is identical at qualification head. The committed descriptor is the actual build-generated output, not manual digest stamping. Native version0.18.6; addon SHA256 ecca056f0c63eca5139c674999a86ca8f4c32926cb18b4c9804efd0d00c32030; path-identity source SHA256 26555fb71debdd40e0cdb70811847765452facd4cbb4107b646df7cc1a25dcaf. No descriptor rewrite during exact qualification; strict version/digest/source checks remain enabled.

Darwin execution only; skipped platforms are not claimed executed. No cumulative TS/Rust/SDK/admission/final-cohort or repaired installed-binary claim.

Preservation and review

Original protected branch fix/session-move-minimal, HEAD 1a12e32f6bbcb5c4a469dd480b4b5dacb37dc95d, 44 staged files preserved. Protected reference #6240 HEAD 7e5f7ef2a745bc1c3d012362f00be9a441bdeb76, sourceHash sha256:0ef698e426d34102d9be3e0c250a880059221bfa77c0ace2351bea28c97528ab preserved; no wholesale transplant.

Fresh code-event CI and exact-current-head write-access approval are separately required. Prior approvals do not transfer. Leader does not merge. Release fragments supplied; shared CHANGELOG sections untouched.

Read from prepared authority and reject divergent or gapped histories.
Publish each disposition through fenced managed no-replace storage before
consumer effects and retain actual native pending state across reopen.

Lore-id: c901da38
Constraint: owner_retired requires live physical proof not parsed flags
Constraint: producer activation and GC driver remain separate
Confidence: high
Scope-risk: narrow
Reversibility: easy
Tested: 229 consumer and storage tests 1221 assertions 8 existing skips
Tested: vendor Biome TypeScript and diff checks
Not-tested: completed physical reclamation on Darwin retained namespace
Not-tested: final GC and SDK driver integration
Directive: pending receipt replay does not itself prove fresh payload scrub
The released 0.18.6 artifact predates the strict native source prerequisite now on dev. Record the descriptor generated by a successful genuine ci-profile source build rather than attributing historical or release bytes to this source.

Lore-id: f5b83219
Constraint: digest and version checks remain strict
Tested: bun run build:native exit0; 115 exports; source SHA26555fb71debdd40e0cdb70811847765452facd4cbb4107b646df7cc1a25dcaf
Not-tested: subsequent current-prefix runtime qualification
Confidence: high
Scope-risk: bounded
Reversibility: revert
Keep release history in per-change fragments without touching shared CHANGELOG sections.

Lore-id: c3608952
Constraint: owner production and admission remain disabled
Tested: preceding exact-prefix native tests and full package gate; source unchanged
Confidence: high
Scope-risk: bounded
Reversibility: revert

@probepark probepark left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review (head 6c971f9, gajae-reviewer on behalf of probepark)

CI: green — all planned checks pass at this head, including check:@gajae-code/coding-agent, check:@gajae-code/natives, test:…/managed-gc-retirement-journal.test.ts, RSS checkpoint compare, install-methods, and Virtual integration validation (run 37186340766). The approve gate returns ALLOW with no pending, failed, or need-local checks.
Scope: +1171 / -1, 5 files. Reviewable source is about 709 lines: packages/coding-agent/src/session/internal/managed-session-scope.ts +707 and packages/natives/native/diagnostic-artifact.json 2. The remaining lines are the test (457) and changelog fragments.
Conventions: changelog.d fragments are present for coding-agent and natives, and no shared CHANGELOG section is touched. No hand-edited generated files: the diagnostic-artifact descriptor is stated to be build output. No labels. No console.*, mock.module, or spyOn. The test cleans up its temp roots in afterEach.
Notable:

  • managed-session-scope.ts:2628 — readManagedGcSessionRetirementReceipt goes through withManagedGcRetirementJournal, which calls ensureDirectory for the receipts and locks dirs (:2592) and takes a lock. A read therefore creates .internal/receipts and .internal/locks on first call. This is harmless for an opt-in API, but worth a doc line if readers are expected to be side-effect free.
  • bindManagedGcSessionRetirementTarget (:2252), publish… (:2684), and read… (:2628) are exported but have no production caller yet. This matches the stated "consumers stay disabled" scope. Consider adding an integration test once the GC consumer is wired, instead of relying only on the unit fixture.
    Blocking: none. I read the full source diff: prepared-authority-first replay, the consecutive-attempt check (attempt !== index + 1), the continuationExtendsPrevious chain, no-replace publish with re-read durability check, lock release aggregated with the operation error, and the physical-retirement check before owner_retired.

PR body verdict line count=0, not updated.

Verdict: gajae.pr-review-verdict.v1 merge-approved sha256:32d6deef0722d68c1b066e68af59ee30c4401386535f9536262f76515838cbe5 reviewer:human reviewer-id:probepark evidence:ci-green;approve-gate-allow;full-source-diff-read;journal-order-and-authority-checked;no-generated-hand-edit

@Yeachan-Heo
Yeachan-Heo merged commit 6ea157e into dev Oct 4, 2026
31 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants