Skip to content

refactor(sessions): make operation ownership and project membership authoritative #918

Description

@Juliusolsson05

Status (quality-loop audit, 2026-09-25)

Landed: B00/B01 (#933, #935), the first B02 slice (#945), and child fixes #920, #921, #925, #926, #928–#930, #943, #898; #922–#924 via #1108.

Remaining: B02 receipts and editor-vote revalidation (#919), all of B06–B15, #927, and opencode-headless #10–#13.

Acceptance: This is an umbrella. Close it when its child issues are closed.

Original report

Agent Code needs complete session operations whose logical identity, exact project membership, native binding, execution attempt, side effects, and recovery outcome remain explicit across main, renderer, and provider boundaries.

This tracking issue consolidates three user-supplied architecture reviews into an implementation program. Their remote/cached source findings are leads, not proof of current runtime behavior. Planning uses application revision 552914f5610518458f944fa1bdaf63f243685bd1 and its seven package gitlinks; the architecture reference describes an older revision. PR #914 is already merged and its explicit project-tab merge semantics must be preserved.

Intended outcome:

  • Repair concrete quit, resource-inventory/routing, OpenCode, LSP, and orchestration composition failures before broad migration.
  • Carry source capture, projection/draft fidelity, publication, binding activation, and uncertainty through one continuation operation.
  • Audit existing agentNameId before choosing logical identity; move exact project membership/typed relationships to main incrementally, retaining presentation in renderer and native custody safeguards.
  • Correlate work requests and observation/history lifetimes without inventing exactly-once native execution.
  • Add composed regression coverage, package artifact verification, measurement-led fleet work, and bounded editor crash recovery.

Acceptance criteria for the planning deliverable:

  • A thick committed plan covers all three reviews with evidence status, source owners, staged PR-sized work, contracts, failure/recovery semantics, migration/rollback gates, scenario oracles, and performance validation.
  • Existing issues are reused and verified new bug patterns get separate problem records. Proposed designs are not misrepresented as shipped behavior.
  • No runtime changes or full implementation are implied by the plan-only PR. Future feature/refactor issues precede their implementation; resolving PRs close bugs only when implemented and verified.

Existing work includes #898, #879, #894, #895, #886, #854, #827, #845, #896, #774, #775, #769, #766, #764, #763, #365, #786 and #833. The plan records their precise relationship and will link separately filed findings. This umbrella is not resolved merely by writing the plan.

Planning verification was bounded source inspection, not a full package audit, running-app reproduction, benchmark, or application test run. Implementation evidence is recorded in the loop below and its PRs. The external sandbox review bundles were not available in this workspace; their reported checks and scenario counts are not claimed as local results.

Planning deliverable

Plan-only PR #931 contains the completed program as its first and only committed file. Read the plan at its committed revision.

The document contains approximately 18,700 words, B00–B15 delivery families, 95 named scenario obligations, all seven package pins, ownership and recovery contracts, rollback gates, and explicit disposition of all 35 numbered sections of the supplied reviews. Local document/link/scenario validation and whitespace checks passed. The documentation PR passed both CI gates; runtime implementation progress is tracked below. This issue remains open for program execution.

Separately tracked source findings

The future implementation PRs must add composed runtime evidence; source-confirmed findings and the isolated Node timer probe are not substitutes for that.

Active implementation loop

Authorized on 2026-09-12. The persistent implementation goal is active; the whole program is not complete.

For each dependency-ready slice: revalidate current source and active work → create/reuse the issue → use a dedicated outcome-named worktree and branch → commit its focused plan first → implement with composed regressions and WHY comments → run relevant checks → review the diff and resolve valid feedback → open a complete linked PR → verify CI → record the handoff and continue.

Merges require explicit user authorization. A submitted or locally verified PR is not a merged result. Continue independent work while other PRs await review; dependent work must declare its base rather than silently assuming an unmerged change exists in main.

Slice Current state Evidence / next action
Program plan PR #931 open, both CI gates passed No runtime implementation in that PR; remains unmerged
B00/B01 tmux inventory, #898 PR #933 review-ready; both CI gates passed on d424520c 58 focused tests, typecheck, contract/pins and app build verification; unmerged
B01 unknown-owner routing, #920 PR #935 review-ready; both CI gates passed Head 15032845; 116 unit + 14 renderer cases across final runs, typecheck, contract/pins and app build passed; both CI gates passed; unmerged
B02 quit/service lifecycle, #919 First disposal slice implemented/pushed; full app build pending Source e9b88bf5, base 115e26fc, first plan 841d0949; 57 unit + 9 remote system + 1 renderer cases passed; typecheck/contract/pins passed; no quit PR yet
Remaining batches Pending Concrete quit/OpenCode/LSP/orchestration reliability fixes precede semantic ownership migration; follow dependency gates in #931

Worktrees: .worktrees/tmux-workspace-inventory / fix/tmux-workspace-inventory is clean with PR #933. .worktrees/session-window-routing / fix/session-window-routing is clean with PR #935; first plan commit ea355775, implementation 3b3b9c5d, verification record 15032845. Active next slice: .worktrees/quit-service-lifecycle / fix/quit-service-lifecycle, based on current origin/main 115e26fc, focused plan first commit 841d0949. Quit source e9b88bf57e3a45447b9f7a2adb2eba0b1980ee0c is committed and pushed; its worktree is clean. It adds one application disposal composition, startup ownership checkpoints, pending dictation joins, and remote disposal serialized with enable/disable. Verification: 57 unit + 9 remote system + 1 renderer cases passed, including a 19-case post-review subset; full typecheck, contract and pins passed. The full application build is still running in the renderer phase under high local load, followed by final-source incremental verification and PR creation. No quit PR yet. The next B02 frontier must cover control-executor admission and result receipts as well as revision-bound editor decisions; see the focused plan and #919. Native editor approval revision/participant revalidation remains explicit B02 work and must not be declared complete by the initial service-disposal repair.

Tmux limitation retained explicitly: startup preservation is based on that file snapshot. This slice does not add durable quarantine or repair provenance across subsequent saves of damaged workspace metadata; carry that requirement into the later storage/recovery work instead of claiming it was proved by startup tests. No live user tmux process was touched.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    class:C2-identityIdentity/ownership across reload, replace, restore, waketype:choreMaintenance, deps, tests, docs

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions