Repository navigation
feat(session): journal immutable task-owner retirement attempts - #6314
Conversation
Read from prepared authority and reject divergent or gapped histories. Publish each disposition through fenced managed no-replace storage before consumer effects and retain actual native pending state across reopen. Lore-id: c901da38 Constraint: owner_retired requires live physical proof not parsed flags Constraint: producer activation and GC driver remain separate Confidence: high Scope-risk: narrow Reversibility: easy Tested: 229 consumer and storage tests 1221 assertions 8 existing skips Tested: vendor Biome TypeScript and diff checks Not-tested: completed physical reclamation on Darwin retained namespace Not-tested: final GC and SDK driver integration Directive: pending receipt replay does not itself prove fresh payload scrub
The released 0.18.6 artifact predates the strict native source prerequisite now on dev. Record the descriptor generated by a successful genuine ci-profile source build rather than attributing historical or release bytes to this source. Lore-id: f5b83219 Constraint: digest and version checks remain strict Tested: bun run build:native exit0; 115 exports; source SHA26555fb71debdd40e0cdb70811847765452facd4cbb4107b646df7cc1a25dcaf Not-tested: subsequent current-prefix runtime qualification Confidence: high Scope-risk: bounded Reversibility: revert
Keep release history in per-change fragments without touching shared CHANGELOG sections. Lore-id: c3608952 Constraint: owner production and admission remain disabled Tested: preceding exact-prefix native tests and full package gate; source unchanged Confidence: high Scope-risk: bounded Reversibility: revert
probepark
left a comment
There was a problem hiding this comment.
Review (head 6c971f9, gajae-reviewer on behalf of probepark)
CI: green — all planned checks pass at this head, including check:@gajae-code/coding-agent, check:@gajae-code/natives, test:…/managed-gc-retirement-journal.test.ts, RSS checkpoint compare, install-methods, and Virtual integration validation (run 37186340766). The approve gate returns ALLOW with no pending, failed, or need-local checks.
Scope: +1171 / -1, 5 files. Reviewable source is about 709 lines: packages/coding-agent/src/session/internal/managed-session-scope.ts +707 and packages/natives/native/diagnostic-artifact.json 2. The remaining lines are the test (457) and changelog fragments.
Conventions: changelog.d fragments are present for coding-agent and natives, and no shared CHANGELOG section is touched. No hand-edited generated files: the diagnostic-artifact descriptor is stated to be build output. No labels. No console.*, mock.module, or spyOn. The test cleans up its temp roots in afterEach.
Notable:
managed-session-scope.ts:2628—readManagedGcSessionRetirementReceiptgoes throughwithManagedGcRetirementJournal, which callsensureDirectoryfor the receipts and locks dirs (:2592) and takes a lock. A read therefore creates.internal/receiptsand.internal/lockson first call. This is harmless for an opt-in API, but worth a doc line if readers are expected to be side-effect free.bindManagedGcSessionRetirementTarget(:2252),publish…(:2684), andread…(:2628) are exported but have no production caller yet. This matches the stated "consumers stay disabled" scope. Consider adding an integration test once the GC consumer is wired, instead of relying only on the unit fixture.
Blocking: none. I read the full source diff: prepared-authority-first replay, the consecutive-attempt check (attempt !== index + 1), thecontinuationExtendsPreviouschain, no-replace publish with re-read durability check, lock release aggregated with the operation error, and the physical-retirement check beforeowner_retired.
PR body verdict line count=0, not updated.
Verdict: gajae.pr-review-verdict.v1 merge-approved sha256:32d6deef0722d68c1b066e68af59ee30c4401386535f9536262f76515838cbe5 reviewer:human reviewer-id:probepark evidence:ci-green;approve-gate-allow;full-source-diff-read;journal-order-and-authority-checked;no-generated-hand-edit
Scope
Split #6240: install complete managed task-artifact-owner retirement journal APIs on dev
0e761bcc27b39eaeb21e4fcecd48b7cc8e764a6c, after externally merged #6293. Automatic owner production and trusted post-move task admission remain OFF. No GC/SDK owner-effect activation, legacy guard removal, or broader MCP/LSP redesign.Exact head:
6c971f9bbf3c20bc9cd740081c23630ffef47dc4.Actual dev production review cost: 709 additions + deletions: Scope707 plus generated native descriptor2. Tests457 and two release fragments6 excluded. No oversized dependent stack is included.
The journal authenticates original prepared authority and consecutive attempts, preserves original evidence and actual native outcomes, rejects expansion/replaced context, and verifies physical completion rather than promoting retained namespaces to completed. APIs are independently callable; their DTOs/receipts do not confer deletion authority.
Exact local qualification
On a separate clean checkout at the exact head, clean before and after:
bun test packages/coding-agent/test/managed-gc-retirement-journal.test.ts packages/coding-agent/test/managed-gc-retirement-codec.test.ts packages/coding-agent/test/task-artifact-owner-transcript.test.ts packages/coding-agent/test/task-artifact-owner-retirement.test.ts packages/coding-agent/test/session-storage.test.ts packages/coding-agent/test/gc-disk-retention.test.ts: exit0, 195 passed, 8 existing platform skips, 0 failed, 1002 assertions.bun --cwd=packages/coding-agent run check: exit0 on6c971f9bbf3c20bc9cd740081c23630ffef47dc4. Full vendor/Biome/type gate, includingtsc -p tsconfig.json --noEmit; baseline2 warnings/1 info retained.Native provenance: upstream dev is now0.18.6; historical0.18.5 and released0.18.6 bytes were not attributed to current source.
bun run build:nativecompleted successfully on exact build sourceb1fbdafa94f0ad68825d2d46590ba4ad81e013e0, ci profile, 115 exports. Native crates tree is identical at qualification head. The committed descriptor is the actual build-generated output, not manual digest stamping. Native version0.18.6; addon SHA256ecca056f0c63eca5139c674999a86ca8f4c32926cb18b4c9804efd0d00c32030; path-identity source SHA25626555fb71debdd40e0cdb70811847765452facd4cbb4107b646df7cc1a25dcaf. No descriptor rewrite during exact qualification; strict version/digest/source checks remain enabled.Darwin execution only; skipped platforms are not claimed executed. No cumulative TS/Rust/SDK/admission/final-cohort or repaired installed-binary claim.
Preservation and review
Original protected branch
fix/session-move-minimal, HEAD1a12e32f6bbcb5c4a469dd480b4b5dacb37dc95d, 44 staged files preserved. Protected reference #6240 HEAD7e5f7ef2a745bc1c3d012362f00be9a441bdeb76, sourceHashsha256:0ef698e426d34102d9be3e0c250a880059221bfa77c0ace2351bea28c97528abpreserved; no wholesale transplant.Fresh code-event CI and exact-current-head write-access approval are separately required. Prior approvals do not transfer. Leader does not merge. Release fragments supplied; shared CHANGELOG sections untouched.