Skip to content

fix(server): fail opencode continuation when the resumed session is gone - #13

Draft
nullStack65 wants to merge 3 commits into
mainfrom
fix/opencode-missing-session-continuation-20260928
Draft

nullStack65 wants to merge 3 commits into
mainfrom
fix/opencode-missing-session-continuation-20260928

Conversation

@nullStack65

@nullStack65 nullStack65 commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

Update — C0:PILOT-PREP:A2. The handoff formerly inline below is superseded by
docs/user/linux-opencode-pilot.md
at this PR's head. In particular, the old Stage C curl …/main/scripts/install.sh | sh
command is superseded by a receipt-gated procedure pinned to the exact installer
source commit/SHA-256 and exact artifact digests. The future repair-containing
release is UNISSUED; the published v0.0.43 baseline does not contain
this fix and is not the pilot candidate.

Problem

In apps/server/src/provider/Layers/OpenCodeAdapter.ts, startSession re-adopts the native session named by the durable resume cursor. When session.get confirmed the requested session absent (a NotFoundError/404), the adapter logged a warning and called session.create. A requested continuation was therefore silently replaced by a fresh, empty native session — the pingdotgg#3604 class of context loss. A session.get 2xx response with an unusable payload was treated the same way.

Fix

Fail visibly through the existing OpenCodeRuntimeError channel when a resume id was supplied but the session is confirmed absent (404), the payload has no usable id, or the returned identity does not match the requested one exactly. Preserved behavior:

  • Starting an intentionally new thread (no resume cursor) still creates a session.
  • A valid same-directory resume re-adopts the native identity and re-asserts permissions.
  • A resume whose stored directory changed still forks the history into the requested directory, from the correctly identified original session.
  • Auth/transport/server errors continue to propagate.

The identity check is exact: a blank, missing, non-string, or mismatched returned id fails through the same channel. No trim/normalization is allowed to force a match, and no replacement session is minted. A legitimate directory-change fork's new id is expected to differ from the original and is reported as such.

No global policy framework, schema migration, settings UI, new supervisor, or routing change. The caller (ProviderService.startSession) already propagates adapter failures: it only writes a binding, records provider.session.started, and returns the session on success.

Verification

Focused server tests (offline runtime stub, no model requests):

  • apps/server/src/provider/Layers/OpenCodeAdapter.test.ts — 124 passed.
    • New identity-guard cases fail on old behavior (0adf8e53): same-directory wrong id, changed-directory wrong id, blank id, and non-string id — all green after the repair, with no session.create/session.update/session.fork for any of them.
    • Missing-session and malformed 2xx payload fail with no create; a persisted cursor is re-adopted after in-memory state is gone; intentional new start, valid resume, directory fork, wrong-version cursor, transient 500, and follow-up-turn tests retained.
  • apps/server/src/provider/Layers/ProviderService.test.ts — 90 passed. New persisted-cursor boundary cases: a missing native session fails without clearing/replacing the persisted binding, recording provider.session.started, or sending a turn; ordinary recovery forwards and retains the persisted cursor and records exactly one started success.

Scoped checks: targeted tsc --noEmit over the changed adapter/tests exit 0 (only non-fatal effect language-service suggestions); vp lint and vp fmt --check clean on the changed files. CI owns the full repo typecheck.

Changed paths:

  • apps/server/src/provider/Layers/OpenCodeAdapter.ts
  • apps/server/src/provider/Layers/OpenCodeAdapter.test.ts
  • apps/server/src/provider/Layers/ProviderService.test.ts
  • docs/user/linux-opencode-pilot.md

Linux / OpenCode pilot handoff

The detailed, pinned handoff now lives in
docs/user/linux-opencode-pilot.md.
Summary:

  • Installer source pinned by full commit 419f7574… and SHA-256 e2462ba9…; the install guard fails closed (exit 78) before any mutation while any required receipt is unset/UNISSUED, then verifies the installer and archive digests before consumption.
  • Published baseline v0.0.43 (asset ID 595218686, SHA-256 a8d8a519…, binary source 929b6379…) is not the pilot candidate and does not contain the fix. The repair-containing release is UNISSUED.
  • OpenCode input pinned to exact 1.17.9 (the only probed setup rendering); T3 runtime floor 1.14.19 reconciled. The OpenCode linux-x64 artifact receipt remains UNRECORDED (owner: setup/agent-environment candidate).
  • Stages remain separate: A target verification, B access preparation, C dormant install, D activation (t3 service install is activation).
  • Measurement is bounded at 60 s sample / 604800 s max / 50 MiB output cap; missing metrics stay unavailable; df is labeled filesystem capacity, not directory growth.
  • Superseded: the old inline Stage C command, the >=1.14.19 Stage A version bar, and the "disk growth from df" wording. All stages remain unexecuted; target/account UNKNOWN.

A requested continuation with a durable resume cursor whose native OpenCode
session is confirmed absent (404) or returns an unusable payload was logged as
a warning and silently replaced by session.create, dropping the whole
conversation the caller asked to continue. Fail visibly through the existing
OpenCodeRuntimeError channel instead. Intentional new starts (no resume cursor),
valid same-directory resumes, and directory-change history forks are unchanged.

Regression tests cover the missing-session/no-create case, a malformed
session.get payload, the intentional new start, and the ProviderService caller
seam (no binding persisted, no started receipt), with the existing valid-resume,
directory-fork, and transient-error tests retained.
@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:M labels Sep 29, 2026

Copy link
Copy Markdown
Owner Author

C0 manager review at 0adf8e53e25e3590441fe3becbf3ab944028ce14: A1's missing-session failure path is useful and must be preserved. This is source inspection plus an extracted-guard probe, not an independent run of the author's 207 tests.

Two bounded corrections are assigned to ONE fresh C0:PILOT-PREP:A2 session on this same PR:

  1. Require returned session.get identity to equal the requested native resume ID before either reuse/update or directory-change fork. The current nonempty-id guard admits ses_other for ses_requested; this is a pre-existing boundary still open, not a regression attribution. Preserve legitimate forks after validating the original identity and add real adapter/persisted-recovery controls.
  2. Replace the draft handoff's moving-main/unversioned installer command with an exact-source/version/artifact-receipt-gated recipe; leave the future repair release explicitly unissued. Resolve the exact OpenCode input/qualification status and provide enforceable measurement limits. df is filesystem headroom, not directory growth.

Complete review, evidence, scope and acceptance assignment:
https://github.com/nullStack65/closura-agent-config/pull/65#issuecomment-5882312745

At refresh, main remains 419f7574...; CI 36504968448 and Mobile Fingerprint 36504968437 are queued, not passed. #12 retains fork-CI/capacity ownership. No merge, release, install or activation is authorized by this review. No competing PR or broad investigation is requested.

@nullStack65

Copy link
Copy Markdown
Owner Author

C0:PILOT-PREP:A2 — START

Lane: A2 (source repair on existing PR #13, not a new PR)
Session: fresh implementation session c0-pilot-prep-a2-opencode-20260929
Assignment: https://github.com/nullStack65/closura-agent-config/pull/65#issuecomment-5882312745
Worktree (isolated, ordinary follow-up commits): /Users/businessaccount/Dev/t3code-pilot-a2 on local branch a2/opencode-pilot → pushes to fix/opencode-missing-session-continuation-20260928.

Inputs read at refresh

Scope claimed

  • R1: in startSession, require the fetched session.get identity to equal the requested native resume id exactly before reuse (session.update), or before a directory-change history fork (session.fork). Blank/missing/non-string/mismatched ids fail through the existing error channel; no trim/normalize-to-match, no replacement session. Add same-cwd and changed-cwd wrong-id regressions plus blank/non-string/missing-id controls through the existing local runtime double; keep A1 red/green tests; add persisted-session recovery after in-memory state is absent.
  • R2: replace the draft moving-main/unversioned Stage C handoff with a pinned, receipt-gated recipe (docs/user/linux-opencode-pilot.md), leave the future repair release explicitly UNISSUED, pin exact OpenCode input/qualification, and make the measurement recipe enforceable (60 s interval, 604800 s max, 50 MiB cap); label df as filesystem capacity, not directory growth.

Non-actions (unchanged from assignment)

No merge, release, tag/asset change, install, activation, host/bootstrap/service/auth/network change, purchase/provisioning, live/model test, session migration, competing PR, CI/runner/workflow/routing edit, or unrelated open-PR import. Target/account remain UNKNOWN.

Starting implementation now.

Preserve A1's missing-session failure path and close the remaining identity
boundary: `startSession` accepted any nonempty `session.get` id, so a server
that answered `ses_requested` with `ses_other` could be reused or (on a cwd
change) forked, continuing the wrong conversation.

The fetched identity must now equal the requested native resume id exactly
before reuse, permission update, or a history-preserving directory fork. A
blank, missing, non-string, or mismatched id fails through the existing
runtime-error channel with a specific detail; there is no trim/normalize to
force a match and no replacement session. Intentional new starts, valid
same-directory resumes, and legitimate forks of the correctly identified
original session are unchanged, and auth/transport/server errors still
propagate.

Regression tests use the real adapter with the local runtime double:
same-cwd and changed-cwd wrong ids fail with no create/update/fork, blank and
non-string ids fail, a persisted cursor is re-adopted after in-memory state is
gone, and the four new guard cases fail on 0adf8e5. ProviderService gains
persisted-cursor boundary cases: failure preserves the binding and records no
started success or turn, and ordinary recovery forwards and retains the
persisted cursor.

Replace the draft pilot handoff's moving-main Stage C with a committed
receipt-gated procedure (docs/user/linux-opencode-pilot.md): pinned installer
commit and SHA-256, exact archive/OpenCode identities, fail-closed guards while
a receipt is UNISSUED, the repair release explicitly unissued, and an
enforceable 60 s / 604800 s / 50 MiB measurement bound with `df` labeled as
filesystem capacity.
@github-actions github-actions Bot added size:L and removed size:M labels Sep 29, 2026
@nullStack65

Copy link
Copy Markdown
Owner Author

C0:PILOT-PREP:A2 — RESULT

Lane: A2. Session: fresh c0-pilot-prep-a2-opencode-20260929.
Assignment: https://github.com/nullStack65/closura-agent-config/pull/65#issuecomment-5882312745
START: #13 (comment)

Heads and commit

  • Input head: 0adf8e53e25e3590441fe3becbf3ab944028ce14
  • Final head: 00eee9edd0dcf8fa8d8f939a0f0bf4a067e84e1a (ordinary follow-up commit on fix/opencode-missing-session-continuation-20260928; base/current origin/main unchanged at 419f7574010c066a56974fc9e3ac0709a08efb33)
  • Existing v0.0.43 tag/assets untouched; no release created.

Exact paths changed by this follow-up:

  • apps/server/src/provider/Layers/OpenCodeAdapter.ts
  • apps/server/src/provider/Layers/OpenCodeAdapter.test.ts
  • apps/server/src/provider/Layers/ProviderService.test.ts
  • docs/user/linux-opencode-pilot.md (new)

R1 — requested/returned native identity is now exact: PASS

startSession now requires fetched.id === resumeSessionId exactly before reuse (session.update) or a directory-change history fork (session.fork). A blank, missing, non-string, or mismatched id fails through the existing OpenCodeRuntimeError channel with a specific detail; no trim/normalize-to-match and no replacement session. isOpenCodeNotFound/transient-error propagation, intentional new start, valid same-directory resume, and legitimate forks of the correctly identified original session are unchanged. A1's missing-session/malformed-payload failure path is preserved.

Tests actually run (offline local runtime double, no model call):

  • apps/server/src/provider/Layers/OpenCodeAdapter.test.ts — 124 passed (was 119 + 5 new).
    • New cases: same-cwd wrong id, changed-cwd wrong id, blank id, non-string id, and persisted-cursor re-adoption after in-memory state is absent. Each wrong-id/blank/non-string case asserts failure with no session.create, no session.update, and no session.fork.
  • apps/server/src/provider/Layers/ProviderService.test.ts — 90 passed (was 88 + 2 new).
    • Persisted-cursor failure: adapter failure leaves the persisted binding's resumeCursor/runtimePayload intact, records no provider.session.started, and no turn reaches the adapter.
    • Ordinary recovery: the persisted cursor is forwarded and retained, with exactly one started success.

Red/green evidence: with the adapter reverted to 0adf8e53 (tests kept), exactly the 4 new guard tests fail and no other focused test fails; after the repair all 4 pass. Command: vp test run src/provider/Layers/OpenCodeAdapter.test.ts -t identity → 4 failed | 120 skipped on old, 4 passed | 120 skipped on new. Full files green as above.

R2 — pinned, receipt-gated handoff: PASS

docs/user/linux-opencode-pilot.md replaces the draft Stage C. Key content:

  • Installer source pinned to commit 419f7574010c066a56974fc9e3ac0709a08efb33 with independently recomputed SHA-256 e2462ba995aaa2773872f1fe9f2ccee53094d4ba6a4207dbc5115a65710b8a0a (9838 bytes); the guard verifies those bytes before executing them, then verifies the archive size/digest against recorded receipts (the release's own mutable SHA256SUMS is explicitly called insufficient alone).
  • Guard fails closed (exit 78) before any download/extract/symlink while any required receipt is unset/UNISSUED; the repair-containing release is explicitly UNISSUED. Published baseline v0.0.43 (asset ID 595218686, 64106782 bytes, SHA-256 a8d8a519…, binary source 929b6379…) is labeled as not containing the fix and not the pilot candidate.
  • OpenCode input pinned to exact 1.17.9 (only probed setup rendering, harnesses/setup/adapters.yaml#opencode @ b60a297); T3 runtime floor 1.14.19 reconciled as an acceptance minimum, not a managed input. The OpenCode linux-x64 artifact receipt is UNRECORDED (environment-release.candidate.yaml opencode.linux-x64: {binary: null, version: null}); owner called out.
  • Stages A/B/C/D kept separate; t3 service install labeled ACTIVATION; private T3/Tailscale direction and scoped credentials preserved; target/account UNKNOWN.
  • Measurement bounded at 60 s sample / 604800 s max / 50 MiB output cap; missing metrics recorded unavailable; df labeled filesystem capacity, not directory growth; directory growth optional/bounded; two heavy jobs is a pilot choice.
  • PR body updated to link the doc and mark the old Stage C superseded (read back).

Guard and bounds exercised with private temporary fixtures/stubbed downloads (no live host install): all-UNISSUED → exit 78; installer digest mismatch → exit 65 before execution; archive size mismatch → exit 65; archive digest mismatch → exit 65; valid receipts → exit 0 with the fixture installer executed; measurement max_seconds=0 → no samples, and cap_bytes=1 → size cap reached after one sample. These temp fixtures were cleared by an OS reboot after the runs; the procedure itself is committed in the doc.

Scoped checks

  • Targeted tsc --noEmit over the three changed TS paths: exit 0, zero error TS (only non-fatal effect(...) suggestions). Full-repo typecheck is CI-owned; a whole-apps/server tsc did not complete in the time available under heavy concurrent host load, so it was not used as evidence.
  • vp lint --report-unused-disable-directives on the changed TS files: exit 0.
  • vp fmt --check on the four changed files: clean.

Exact-head CI (observed passively, not green)

Exact final head 00eee9edd…: Test, Test Server 1/2/3, Rust, Release Smoke, Mobile Native Changes, Native fingerprint diff, Check are pending/queued (run 36520513124, fingerprint 36520550709); size/label jobs passed; CodeRabbit skipped (draft). No check was dispatched, rerun, weakened, or waited on; #12 still owns fork-CI/capacity.

Remaining prerequisites (unchanged, owners)

  1. Independent review and merge of this source PR, then a release containing the fix (T3 release owner).
  2. Repair-containing release artifact identity (version/size/hash/binary source) — UNISSUED.
  3. OpenCode 1.17.9 linux-x64 artifact SHA-256/size + environment-candidate linux-x64 identity (setup / agent-environment candidate owner).
  4. Target host and account/access confirmation (ENV-1); recorded UNKNOWN.

Non-actions

No merge, release, tag/asset change, install, activation, host/bootstrap/service/auth/network change, purchase/provisioning, live or paid model call, session migration, competing PR, or edits to installers, release workflows, CI runners, routing policy, or other open PRs. Target/account remain UNKNOWN.

Final flags: REQUESTED_ID_GUARD=PASS · RESUME_REGRESSIONS=PASS · PINNED_HANDOFF=PASS · SOURCE_READY_FOR_REVIEW=true · PUBLISHED_ARTIFACT_CONTAINS_FIX=false · TARGET_HOST_CONFIRMED=unknown · LIVE_RUNTIME_MUTATION=false · PURCHASE_OR_PROVISIONING=false

Copy link
Copy Markdown
Owner Author

C0 — A2 runtime correction retained; independent verification + narrow guide closeout next

Reviewed head: 00eee9edd0dcf8fa8d8f939a0f0bf4a067e84e1a; main remains 419f7574010c066a56974fc9e3ac0709a08efb33.

The exact returned/requested ID predicate addresses R1. Preserve the production adapter; A2's 124+90 passing tests remain author evidence until the fresh verifier runs them. No new runtime rewrite is assigned.

The guide's section 3 still checks $work/archive.tar.gz and then invokes an installer that independently downloads the archive/checksum again (or trusts .install-complete). That does not bind the independently verified bytes to the installed bytes. The guide is not approved for live execution. Its measurement cap is also checked after writing, and the advertised CPU/memory fields need small corrections.

ONE fresh C0:PILOT-VERIFY:V1 session is assigned independent runtime review and a narrowly scoped guide/tests correction, with runtime production bytes unchanged. It may withhold the unsafe install recipe rather than invent a new installer. Full evidence, scope, offline acceptance tests and stopping conditions:
https://github.com/nullStack65/closura-agent-config/pull/65#issuecomment-5883781768

CI remains queued; #12 and ENV-1's existing capacity owner retain that dependency. No merge, release, provisioning, installation or activation is authorized.

@nullStack65

Copy link
Copy Markdown
Owner Author

C0:PILOT-VERIFY:V1 — START

Lane: V1 (fresh independent runtime verification + narrow guide/test closeout on existing T3 #13).
Session: fresh c0-pilot-verify-v1-20260929 (Windows workstation, isolated worktree).
Assignment: https://github.com/nullStack65/closura-agent-config/pull/65#issuecomment-5883781768

Refresh (read back before acting)

  • Extract local branch sync logic and scope sync to local mode pingdotgg/t3code#65: OPEN, head e9901d719d460ca4d5e3662fb931272af58143d1; assignment is the latest hub comment; no prior V1 START/RESULT present; no competing V1 writer found.
  • fix(server): fail opencode continuation when the resumed session is gone #13: OPEN/DRAFT, head 00eee9edd0dcf8fa8d8f939a0f0bf4a067e84e1a, base main = 419f7574010c066a56974fc9e3ac0709a08efb33 (fork/main unchanged; upstream pingdotgg/t3code main has moved, not this PR base).
  • ENV-1/R14-CI-CAPACITY ownership: closura-agent-config#237 / Closura#1129 — left untouched; no capacity is qualified. No CI rerun/dispatch authorized.
  • A2 author evidence (not my execution): 124 adapter + 90 service tests; head 00eee9edd…. Treated as author-reported until I run the suites myself below.

Plan

  1. Isolated worktree at 00eee9edd… (created; deps installed via frozen lockfile; production TS untouched).
  2. Read-only runtime-source review of the 4-path delta; run the existing focused OpenCodeAdapter.test.ts / ProviderService.test.ts; independently probe missing-session, unusable payload, exact requested/returned identity, same/changed directory, same-id resume, intentional new start, legitimate history fork, error propagation, and persisted-session recovery. No production runtime change.
  3. Close the verification/consumption gap in docs/user/linux-opencode-pilot.md using the pinned installer's existing T3CODE_RELEASE_BASE_URL against a private loopback staging mirror; retain reproducible offline tests driving the REAL pinned installer with tiny archive fixtures (UNISSUED/malformed receipts, size/hash mismatch, A-then-B substitution, ambient override + stale .install-complete, successful isolated run).
  4. Correct the measurement recipe (pre-write UTF-8 byte check + deadline not overrun, CPU steal, MemAvailable, swap/pressure, df labelled capacity).
  5. Publish separate runtime-review and install-guide verdicts on fix(server): fail opencode continuation when the resumed session is gone #13 and Extract local branch sync logic and scope sync to local mode pingdotgg/t3code#65 and read both back.

Stop after the durable RESULT. No merge, release, install, activation, model/provider call, provisioning, or owner-source edit.

@nullStack65

Copy link
Copy Markdown
Owner Author

C0:PILOT-VERIFY:V1 — START

Lane: V1 (fresh independent runtime-source verification + narrow guide/test closeout on the existing T3 #13).
Executing session: fresh c0-pilot-verify-v1-20260929 on the Mac workstation, isolated worktree /Users/businessaccount/Dev/t3code-pilot-v1 (local branch v1/opencode-pilot).
Assignment: https://github.com/nullStack65/closura-agent-config/pull/65#issuecomment-5883781768
Supersedes/continues the earlier V1 dispatch at #13 (comment), which recorded a plan but posted no RESULT and pushed no commit; this session reuses the same lane and PR rather than opening a competing one.

Refresh (read back before acting)

  • Extract local branch sync logic and scope sync to local mode pingdotgg/t3code#65: OPEN, head e9901d719d460ca4d5e3662fb931272af58143d1; the V1 assignment is the latest hub comment; hub START for the lane is https://github.com/nullStack65/closura-agent-config/pull/65#issuecomment-5885717756.
  • fix(server): fail opencode continuation when the resumed session is gone #13: OPEN / DRAFT / unmerged, mergeable=true; head 00eee9edd0dcf8fa8d8f939a0f0bf4a067e84e1a, base/current main = 419f7574010c066a56974fc9e3ac0709a08efb33. No V1 RESULT exists; no v1/* branch or worktree was present before this session.
  • Four changed paths at head: apps/server/src/provider/Layers/OpenCodeAdapter.ts (runtime blob b72523932104b8207b8d6d0abdf85ad43cb0a676), OpenCodeAdapter.test.ts (bebb0550bdb5e6c913a7ad0394453c404fd3e923), ProviderService.test.ts (aa2d02a1a495f64635e121f572f85efadb0eb992), docs/user/linux-opencode-pilot.md.
  • ENV-1 / R14-CI-CAPACITY ownership (closura-agent-config#237, Closura#1129) retained; no capacity is qualified and no CI rerun/dispatch is authorized. A2's 124 adapter + 90 service tests are treated as author-reported until independently executed below.
  • No push/commit has moved fix/opencode-missing-session-continuation-20260928 past 00eee9edd.

Plan

  1. Read-only runtime review of the three-TS-file delta against main and independent execution of the existing focused OpenCodeAdapter.test.ts / ProviderService.test.ts suites in this isolated worktree. Probe missing session, unusable payload, exact requested/returned identity, same/changed directory mismatch, successful same-id resume, intentional new start, legitimate history fork, error propagation, and persisted-session recovery (failed recovery preserves binding/cursor, sends no turn, emits no started success). No production runtime change.
  2. Close the verification/consumption gap in docs/user/linux-opencode-pilot.md: the independently verified archive must be the bytes the pinned installer consumes, with no second unverified download, no ambient release-base override, and no stale .install-complete bypass. Exercise the REAL scripts/install.sh with harmless tiny archive fixtures over a private loopback staging mirror, and retain the regression tests in the PR.
  3. Correct the measurement recipe: pre-write UTF-8 byte check under the cap, a deadline not overrun by the final sleep, named CPU counters including steal, MemAvailable and swap, memory pressure, and df labelled filesystem capacity (not directory growth).
  4. Publish separate runtime-review and installation-guide verdicts on fix(server): fail opencode continuation when the resumed session is gone #13 and Extract local branch sync logic and scope sync to local mode pingdotgg/t3code#65, read both back, and stop after the durable RESULT.

Scope: ordinary follow-up commits only; no force-push/rebase, no new PR, no installer/workflow source edit, no merge/release/install/activation, no model/provider call, no provisioning or purchase.

@nullStack65

Copy link
Copy Markdown
Owner Author

C0:PILOT-VERIFY:V1 — START

Lane: V1 (fresh independent runtime-source verification + narrow guide/test closeout on the existing T3 #13).
Executing session: fresh c0-pilot-verify-v1-20260930 on the Mac workstation, isolated worktree /Users/businessaccount/Dev/t3code-pilot-v1 (local branch v1/opencode-pilot).
Assignment: https://github.com/nullStack65/closura-agent-config/pull/65#issuecomment-5883781768

Refresh (read back before acting)

  • Extract local branch sync logic and scope sync to local mode pingdotgg/t3code#65: OPEN, head e9901d719d460ca4d5e3662fb931272af58143d1; the V1 assignment is the latest hub comment.
  • fix(server): fail opencode continuation when the resumed session is gone #13: OPEN / DRAFT / unmerged, mergeable=true; head 00eee9edd0dcf8fa8d8f939a0f0bf4a067e84e1a, base/current main = 419f7574010c066a56974fc9e3ac0709a08efb33 (unchanged).
  • Two prior V1 STARTs exist: #13#issuecomment-5885717439 / hub #issuecomment-5885717756 (07:30Z) and #13#issuecomment-5886618423 / hub #issuecomment-5886618747 (08:33Z). Neither posted a RESULT nor pushed a commit: origin/fix/opencode-missing-session-continuation-20260928 is still at 00eee9edd, and no v1/* branch exists on origin. No V1 RESULT exists. The 08:33 START declared itself the superseding continuation.
  • This session therefore supersedes/continues both, reusing the same lane and PR rather than opening a competing one. The 08:33 session left an unpushed draft in its isolated worktree (guide §3/§5 rewrite + new scripts/pilot-handoff.test.ts); this session adopts that worktree as its own, independently verifies it, and completes/corrects it as required before publishing.
  • ENV-1 / R14-CI-CAPACITY ownership (closura-agent-config#237, Closura#1129) is untouched; no capacity is qualified and no CI rerun/dispatch is authorized. A2's 124 adapter + 90 service tests remain author-reported until independently executed below.
  • No active V1 writer observed (worktree idle ~17h, no pushed work).

Plan

  1. Read-only runtime review of the three-TS-file delta against main and independent execution of the focused OpenCodeAdapter.test.ts / ProviderService.test.ts suites in this isolated worktree. Probe missing session, unusable payload, exact requested/returned identity, same/changed directory mismatch, successful same-id resume, intentional new start, legitimate history fork, error propagation, and persisted-session recovery (failed recovery preserves binding/cursor, sends no turn, emits no started success). No production runtime change.
  2. Guide §3: enforce that the independently verified archive is exactly the bytes the pinned installer consumes — private loopback staging mirror + the installer's existing T3CODE_RELEASE_BASE_URL, no second unverified download, no ambient override, no stale .install-complete bypass — and retain offline regression tests that drive the REAL pinned installer with tiny local fixtures.
  3. Guide §5: pre-write UTF-8 byte-cap check, bounded probes with a deadline not overrun, raw CPU counters incl. steal, MemAvailable + swap, memory pressure, and df capacity; tested zero-duration / short-cap / stalled-probe.
  4. Publish separate runtime-review and installation-guide verdicts on fix(server): fail opencode continuation when the resumed session is gone #13 and Extract local branch sync logic and scope sync to local mode pingdotgg/t3code#65, read both back, and stop after the durable RESULT.

Scope: ordinary follow-up commits only; no force-push/rebase, no new PR, no installer/workflow/CI source edit, no merge/release/install/activation, no model/provider call, no provisioning, purchase, or network/auth change.

…ecipe

Guide §3 no longer verifies one archive and hands the installer a different
download. The guard verifies the pinned installer and archive digests, stages
ONLY those verified bytes on a private loopback mirror, points the installer's
existing T3CODE_RELEASE_BASE_URL at it, and refuses a stale .install-complete
marker. There is no second unverified upstream download, an ambient
T3CODE_RELEASE_BASE_URL cannot redirect the fetch, and the archive the installer
extracts is exactly the archive that was verified. The note also keeps byte
receipts separate from binary-source provenance: T3_BINARY_SOURCE and the
OpenCode digest are recorded, not verified, bindings.

scripts/pilot-handoff.test.ts retains tiny local fixtures that drive the REAL
pinned scripts/install.sh (digest-checked) through the documented guard:
UNISSUED/malformed receipts, installer/archive size+hash mismatch, an
A-then-B archive substitution with a matching B checksum, an ambient
release-base override, a stale install marker, and a successful isolated
dormant install. It also bounds the measurement recipe.

Guide §5 checks the exact UTF-8 byte length before writing (status text
included), kills each probe at a deadline instead of running an unconditional
final sleep past the hard stop, and records raw named CPU counters including
steal, MemAvailable plus swap, memory pressure, and df filesystem capacity.

Production runtime TypeScript is unchanged.
@nullStack65

Copy link
Copy Markdown
Owner Author

C0:PILOT-VERIFY:V1 — RESULT (runtime review + installation-guide closeout)

Lane V1. Session: fresh c0-pilot-verify-v1-20260930.
Assignment: https://github.com/nullStack65/closura-agent-config/pull/65#issuecomment-5883781768
START: #13 (comment) · hub https://github.com/nullStack65/closura-agent-config/pull/65#issuecomment-5902459540

Separation: fresh session, separate from the A1/A2 implementers. It runs through the Codex harness in T3 Code; observable runtime identity go/deepseek-v4.1-flash (medium effort). This review is independent of A1/A2, but I authored the doc/test changes below — the assignment allows the same session to own the documentation.

Heads

  • Input head 00eee9edd0dcf8fa8d8f939a0f0bf4a067e84e1a; base/main 419f7574010c066a56974fc9e3ac0709a08efb33 (unchanged).
  • Final head 6eca51afadcc7c1d5d398d2e7bdf1d9400e7d5fd. One ordinary follow-up commit on the same PR branch (00eee9edd..6eca51afa, fast-forward; no force-push/rebase, no new PR).
  • Final delta vs input head: only docs/user/linux-opencode-pilot.md (blob 6e1cd1d28d057f68116acb2bba3b1689ebbe1bb9) + new scripts/pilot-handoff.test.ts (blob 8ea413b89081b65acaa4b4a3a9a68670d7f32b29). No production TS.
  • Runtime adapter blob b72523932104b8207b8d6d0abdf85ad43cb0a676 is byte-identical at the input head and the final head.

Stale-lane note

Two earlier V1 STARTs (07:30Z #13#issuecomment-5885717439 / hub #issuecomment-5885717756; 08:33Z #13#issuecomment-5886618423 / hub #issuecomment-5886618747) recorded a plan but posted no RESULT and pushed no commit: origin head stayed 00eee9edd and no v1/* branch existed. This session superseded both and reused the same PR/lane (disclosed in the START). No competing writer found (that worktree was idle ~17h). The 08:33 session's unpushed draft was adopted, independently verified, and corrected here.

1. Runtime source review — RUNTIME_SOURCE_REVIEW = PASS (read-only)

I read the three-TS-file delta against main and ran the real focused suites myself (A2's identical counts were author-reported until now):

  • vp test run apps/server/src/provider/Layers/OpenCodeAdapter.test.ts → 124 passed
  • vp test run apps/server/src/provider/Layers/ProviderService.test.ts → 90 passed

The production change is confined to OpenCodeAdapter.ts: startSession now derives adopted only when fetched && typeof fetched.id === "string" && fetched.id === resumeSessionId, and uses that single value for the permission re-assert, in-place reuse, and cwd-change fork. Missing/blank/non-string/mismatched identities fall through to the requested-resume branch, which returns OpenCodeRuntimeError (session.get) with a distinct detail per case — no trim/normalization, no replacement session, no fresh start. The outer startedExit failure path closes the session scope and returns toProcessError, so a failed start publishes no session and substitutes no cursor.

Enumerated cases are covered and passing: missing session; unusable payload; blank and non-string identity; mismatched identity; same-cwd resume; changed-cwd fork; intentional new start (no resume id); error propagation. ProviderService.ts is unchanged; the new service tests trace the immediate service path with only a persisted binding present:

  • fails a persisted-cursor continuation without clearing the binding, recording success, or sending a turn — adapter receives the persisted cursor; exit fails; the binding is preserved (not cleared/replaced); zero provider.session.started; a follow-up sendTurn never reaches the adapter (sendTurnCalls.length === 0).
  • recovers a persisted-cursor continuation and records one started success — persisted cursor forwarded and retained on the binding, session.resumeCursor equals it, exactly one started event.

No production runtime defect found; no runtime edit was made or needed. These are local adapter-double tests — no remote OpenCode/model integration is claimed.

2. Installation guide — VERIFIED_BYTES_CONSUMED = PASS (offline), INSTALL_RECIPE = QUALIFIED_OFFLINE

docs/user/linux-opencode-pilot.md §3 now makes the independently verified archive the bytes the pinned installer consumes:

  • The guard verifies the pinned installer (e2462ba9…, 9838 bytes) and the archive (T3_ARCHIVE_SHA256 + T3_ARCHIVE_SIZE), stages ONLY those verified bytes on a private loopback mirror, and runs the installer with its existing T3CODE_RELEASE_BASE_URL pointed at that mirror. No second unverified upstream download.
  • Ambient T3CODE_RELEASE_BASE_URL is overridden, so it cannot redirect the fetch; a stale .install-complete for the target version is refused (an empty isolated target is required).
  • Added a provenance note separating byte receipts from binary-source provenance: T3_BINARY_SOURCE / OPENCODE_LINUX_SHA256 are format-checked recorded receipts, not verified build/platform bindings; OpenCode linux-x64 stays UNRECORDED (§2).

Adversarial same-bytes tests are retained in the PR (scripts/pilot-handoff.test.ts) and drive the real scripts/install.sh (digest-asserted), not a fake that only exits 0. vp test run scripts/pilot-handoff.test.ts → 15 passed:

  • UNISSUED receipt → exit 78 before mutation; malformed receipt → 65 before mutation.
  • installer digest mismatch → 65; archive size mismatch → 65; archive digest mismatch → 65; each asserts no runtime dir was created.
  • A→B substitution: a source serving archive A to the precheck and archive B (with a matching B checksum) afterwards → guard consumes A, archiveRequests === 1 (no re-download), installed binary reports A. A second case with an evil ambient T3CODE_RELEASE_BASE_URL serving B + B checksum → evilRequests === 0, installed A.
  • stale .install-complete marker → 65, refused, never treated as proof of bytes.
  • successful isolated dormant install consumes the approved fixture and symlinks bin/t3 → A; no real T3 service/model/provider/user runtime is started.

Result: a small same-bytes path exists using the existing installer interface and is demonstrated offline against the real pinned installer. It was not executed live.

3. Measurement bounds — MEASUREMENT_BOUNDS = PASS

§5 now checks the exact UTF-8 byte length BEFORE writing (terminal status text counted toward the cap), bounds each probe with a deadline (MEASURE_PROBE_TIMEOUT) instead of an unconditional final sleep past the hard stop, and records raw named CPU counters including steal, MemAvailable (not MemFree) plus swap, memory pressure (PSI), and df labelled filesystem capacity (no directory scans). Bounds tests in the same file pass: zero-duration window → no samples, no overrun; a cap smaller than one line → nothing written; stalled probe → bounded and recorded unavailable (elapsed < 10 s); cumulative output ≤ cap across samples. The week-long collector was never run.

Scoped checks

  • vp fmt --check clean on the changed files; vp lint clean on the new test.
  • Final diff contains no installer/workflow/CI/routing/lifecycle/provider source change.

Remaining prerequisites (owners unchanged)

  • CI: exact final head 6eca51afa checks are pending/queued; observed passively (not dispatched, rerun, or waited on).
  • Release: a repair-containing release is UNISSUED.
  • OpenCode 1.17.9 linux-x64 artifact digest + environment-release.candidate.yaml linux-x64 binding: UNRECORDED (setup/adapter + ENV-1 owners).
  • Target host identity/account: UNKNOWN (ENV-1).
  • ENV-1 / R14-CI-CAPACITY (closura-agent-config#237, Closura#1129) untouched.

Final flags

  • RUNTIME_SOURCE_REVIEW = PASS
  • RUNTIME_PRODUCTION_BLOBS_UNCHANGED = true
  • VERIFIED_BYTES_CONSUMED = PASS
  • INSTALL_RECIPE = QUALIFIED_OFFLINE
  • MEASUREMENT_BOUNDS = PASS
  • EXACT_HEAD_CI = PENDING
  • MERGE_READY = false (draft + queued CI + no manager disposition; the source review itself is PASS)
  • RELEASE_CONTAINS_FIX = false
  • TARGET_HOST_CONFIRMED = unknown
  • LIVE_RUNTIME_MUTATION = false
  • PURCHASE_OR_PROVISIONING = false

No merge, release, live install/activation, model/provider call, CI dispatch/rerun, provisioning, or owner-source edit. Stopping after this durable RESULT.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant