Proposal
Define an opt-in Feature Recovery and Reconciliation Protocol for the Connection
Coordinator. The current protocol requires convergence on missing features but
does not specify the recovery owner, foreground-to-background handoff, or safe
handling of ambiguous operations and immutable feature replacement.
The proposal covers explicit per-channel ownership, reconciliation before retry,
bounded foreground attempts with durable background work, existing requestId
idempotency, authoritative feature failure information, and coordinated cleanup.
It preserves existing three-of-four provisioning eligibility and the full
verification handshake. No production implementation is proposed.
Related public discussion: #51 covers retries, reconciliation, and identity.
This proposal extends that discussion with ownership, lifecycle, compatibility,
and unresolved cross-provider fencing requirements; it does not assume #51 is
accepted.
Decisions Needed
- Bilateral capability negotiation and generated-client enum compatibility.
- Distributed generation/ownership fencing and safe handoff before automated
replacement or cleanup can be enabled.
- Retry budgets, replay semantics, retention, failure codes, and escalation.
- Explicit approval of stronger safeguards for the existing seven-day cleanup
permission and resolution of deferConnection/deferProvisioning naming.
These are review gates, not claims that distributed recovery races are solved.
Proposal
Define an opt-in Feature Recovery and Reconciliation Protocol for the Connection
Coordinator. The current protocol requires convergence on missing features but
does not specify the recovery owner, foreground-to-background handoff, or safe
handling of ambiguous operations and immutable feature replacement.
The proposal covers explicit per-channel ownership, reconciliation before retry,
bounded foreground attempts with durable background work, existing requestId
idempotency, authoritative feature failure information, and coordinated cleanup.
It preserves existing three-of-four provisioning eligibility and the full
verification handshake. No production implementation is proposed.
Related public discussion: #51 covers retries, reconciliation, and identity.
This proposal extends that discussion with ownership, lifecycle, compatibility,
and unresolved cross-provider fencing requirements; it does not assume #51 is
accepted.
Decisions Needed
replacement or cleanup can be enabled.
permission and resolution of deferConnection/deferProvisioning naming.
These are review gates, not claims that distributed recovery races are solved.