Skip to content

feat(server): port durable child threads to v2 - #181

Merged
lukemaj merged 15 commits into
fork/v2from
feat/168-child-threads-v2
Oct 8, 2026
Merged

lukemaj merged 15 commits into
fork/v2from
feat/168-child-threads-v2

Conversation

@lukemaj

@lukemaj lukemaj commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

What: Port cross-project native children, descendant request handling and durable subtree Stop onto upstream V2.
Why: Upstream already owns lineage, task delegation and once-per-task results, but lacks these fork behaviors and imported child ancestry repair.
So what: PR #181 is ready at af30a6297a912840b9e95dac7158a6272a57e79d against a97591eaca9ecb9979221a8f853dc69fff0126f2; composed proof, all CI, exact-head independent review and Observer publication pass. It remains unmerged.

Closes #168. Part of #166; advances the Objective that Drafters start in any project. Based on current fork/v2 at a97591eaca9ecb9979221a8f853dc69fff0126f2, including merged foundation #178, Issues port #179 and people port #180. The PR diff contains only #168 changes.

Retains upstream delegate_task / task_status / task_cancel, environment-wide tools with the runtime mode ceiling, once-per-task completion wake and native lineage UI/mobile filtering. Adds optional project/workspace selection to both delegation paths through existing workspace preparation and access checks. Direct RPC and MCP validate existing worktrees against the destination project before creating children, then schedule the same idempotent preparation. Descendant approval/question notices dedupe accepted deliveries, retry rejected attempts and reconcile live after ancestor resume and after restart; responses remain descendant-only and preserve the child's mode.

Stop/start admission checks commit with receipts and events through the approved typed fork plan seam. Root Stop cancels and drains native descendant effects, including real blocked provider starts; only explicit trusted human/parent messages acknowledge retirement. Delayed propagated Stops carry the original root token and become accepted receipt-only no-ops after resume or token replacement. Archived/deleted ancestry remains traversable without changing deletion or UI behavior. Imported sub.* ancestry repairs only existing, acyclic parent links through #167's shell-only registry, idempotently without modifying transcripts. The feature map applies reviewed D13-D ownership, preserving all unaffected landed entries and one primary owner per path. Landed #170 supplies native parent-owner inheritance with empty child coOwners; cross-project integration proves parent owner/sharing stay intact. Both typed backfill registry entries compose.

Previous reviews apply only to their exact heads. Current af30a629 review against a97591e has no supported blocking finding and review/independent success; prior b93/264 review and readiness are superseded by the #170 base move. Full unchanged findings. All current CI jobs pass or are conditionally workflow-skipped. Observer publication is current; estimated cost is unknown with incomplete usage coverage.

Current composed proof on af30/a975:

  • 312 focused feature, server, SQLite rollback/replay, Stop, delegation and fork-maintenance tests pass across 22 files, including all 72 unchanged runtime rollback tests. Four opt-in cases are omitted from the ordinary run; feature, owner and Issues actual-source cases are explicitly executed below, with unchanged foundation actual-registry proof reused.
  • MCP toolkit integration: 2 pass. Actual IssueLinks service proves imported grandchild rollup appears after repair and survives repeat/hydration.
  • Explicit actual-source Port child threads onto upstream lineage and delegation #168 lineage proof: 2 pass, zero skipped. Read-only VACUUM INTO snapshot: 762 threads; all 502 existing-parent sub.* links repaired; zero dangling links, cycles or root mismatches; transcript counts unchanged and repeat execution adds zero messages/events.
  • Explicit landed Port thread people and ownership #170 actual-source owner backfill: 5 pass, zero skipped.
  • Explicit Port the GitHub Issues features #171 actual-source stored-Issue carryover: 2 pass, zero skipped, preserving stored source rows.
  • Fresh server and contracts scoped typechecks pass; all changed TypeScript files pass scoped lint (six unchanged base warnings); whole-stack fork-check.sh --base 12069eefd707f78eafc27812027c994eea0613cf passes with fourteen feature owners; diff check passes.
  • Routine additive map/allowlist conflicts were composed after root retained issues-links primary ownership of the shared registration test. Production patches remain equal; all unaffected landed entries are identical; root explicitly transferred seven primary paths from thread-people to child-threads, with thread-people watching them as sharedFiles.

The introduced CI rollback regression came from retirement metadata overwriting the active provider pointer set by an earlier provider-thread event in the same command. The correction uses the existing canonical projector to preserve planned thread state before adding retirement fields. Base rollback tests passed 72/72, candidate failed three, and a strengthened Stop/resume pointer assertion failed before this repair. Correction and proof.

Current #170 composition, 312-test commands and all three serial actual-source results are retained in the current-base proof.

Full commands, red/green production lifecycle, listener and intake evidence, new-base rollup composition, migration counts and decisions are retained in the #168 proof record. The generic transaction contract and reviewed D28 decisions are in the interface record. Upstream #13343 was fully inspected as a candidate; this adapts its serialized cancellation pattern without a merge dependency. Root A-D/D13-A/D14/D15/D21/D28 decisions supersede assessment suggestions; there are no old aliases or spawn_thread/Prism/Spectrum/Wight/scheduler ports.

Limitations: no browser, mobile, dev-server or live-provider execution was authorized. Provider lifecycle tests use actual server start/worker services with an adapter boundary controlled by Deferreds. Unchanged upstream accepted-interrupt settlement (settleInterruptedRun) and Claude's ten-second query-close timeout retain an unconfirmed background-work survival risk; no supported real-provider survival was demonstrated, and this PR does not claim all provider closure paths verified. Extra missing-ancestor reads and rescans on subsequent acknowledged-thread metadata are unmeasured optional performance concerns. No app installation, deployment, merge, main push, version bump or live userdata write.

Requirements and who asked: User #168 acceptance and reviewed #166/root decisions require native cross-project children, descendant requests, durable explicit-only retirement and existing-parent lineage repair.
Deleted: Fork aliases and duplicate delegation/UI/filtering/resume implementations; Prism, Spectrum, Wight and scheduler behaviors remain with their owners.
Bottleneck: Required current-base proof, CI, exact-head review and Observer publication are complete; integration remains parent-owned.
Checked myself: Verified merged base/live branch and #168-only range-diff, all foundation inventory entries unchanged, actual-service failing-before/green lifecycle cases, focused outputs and sanitized real snapshot counts.

Implemented with GPT-6.1-Sol through Codex in T3 Code; independent review routed by Prism to GPT-6-Luna through Codex.

@lukemaj

lukemaj commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

What: Independent exact-head review found no blocking code issue in this #168 candidate.
Why: The prior wake and public-intake findings required corrections and rereview on the foundation-based head.
So what: The coordinator relays the read-only review unchanged below, records its exact-head status, and holds the final ready claim for Observer publication. Consumer integration remains owned by #169/#170.

Read-only independent reviewer verdict, relayed unchanged:

Verdict

No supported blocking code finding on exact head 25ea84f9181805ec4666f051ab558039380fe289 against base 6e1653b6719565db2cc5094670e19e6efd3fc1ce. The direct RPC path now checks the destination project and registered worktree before dispatch, then prepares from accepted child/run events; the accepted replay and blocked-setup Stop cases are covered in the supplied proof at delegatedIntake.ts and ThreadMessageIntake.ts.

I inspected the exact-head artifacts without rerunning checks: 208 tests passed across 16 files with 2 opt-in skips, MCP integration passed 2 tests, and actual-source lineage proof passed 2 tests with zero skips. Its aggregate reports 761 threads, all 501 existing-parent child links repaired, and no orphan, dangling, cycle, or root mismatch; server typecheck and lint passed, with six lint warnings verified in the base, and the nine-feature inventory and fork check passed.

The constructor audit found only retirementAdmission and propagatedStopAdmission: their plans capture input data, resolve services inside the transaction, and contain no direct I/O or nested dispatch. The accept_noop path short-circuits later plans and effects; the lineage backfill remains projection-read-only and event-based.

Limits and follow-up

A crash after dispatch commits but before prepareDelegatedRun schedules setup leaves a preparing run for startup recovery, which cancels it; delegated-task recovery then settles the parent task. This is the existing post-commit launch policy shared by the MCP and ordinary launch paths, so I do not count it as a new blocker or claim automatic preparation recovery. Unchanged provider-survival concerns remain unproven without live-provider evidence; repeated wake scans and missing-ancestor lookup cost remain unmeasured performance limits.

The linked Issue proof comment still says the exact-head source run is underway and identifies the earlier 07dda8d run. Update that record before PR publication. This source verdict does not clear the #169 or #170 native blockers or establish overall PR readiness. No files, Issues, PRs, or statuses were changed.

Coordinator disposition: the proof-record follow-up is complete in the updated exact-head record. The earlier underway report is superseded. No source changed after review.

Requirements and who asked: User required independent exact-head/current-base review of #168.
Deleted: No supported finding was dismissed or proof gate waived; both prior required findings were fixed and rereviewed.
Bottleneck: Observer publication before the ready claim and consumer-owned integration.
Checked myself: Exact review SHA/base, complete reviewer verdict, current proof and unchanged source.

@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL labels Oct 8, 2026
@lukemaj

lukemaj commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor Author

Agent work on this PR

Estimated cost unknown · 0 responses · 41 sessions · 5.3 h wall time

Model Responses Tokens Estimated cost

Flags: 3 human corrections · 65 large tool outputs · 47 repeated commands · 9 repeated failures · 65 repeated reads · 5 repeated skill loads · 40 sessions with usage bound to no task · 1 session without usage records

Details: snapshot, prices, coverage, counters
  • Task toolboxmd/chromeria#168: outcome unknown (recorded acceptance only; a finished process never implies it).
  • Proof: Port child threads onto upstream lineage and delegation #168
  • Snapshot 04d7c390cccda4e7962aa93370752724bbb36758da1eb592c217198aa0fe48c9, records up to 2026-10-08 18:56 UTC.
  • 41 sessions on claude, codex; AgentsMD 14.6.0.
  • Not counted: 3,631 responses (at least $57.49) in sessions shared with other PRs that worked in no single PR's checkout.
  • 3,035 responses in these sessions worked on other PRs and are counted there.
  • Totals reconcile with the measured sessions: yes. Evidence complete: no.
  • Prices: list-price estimate from T3 local rate table (path withheld) as of 2026-09-28, schedule 696aae45933d0a684a015d3f08cfb6f1aa2fef02e7d272b4689e3a692ea04fff. Unknown prices stay unknown, never zero.
    • T3 LiteLLM rate table when present; bundled schedule covers the rest.
  • Native session usage or worker ownership is unavailable.
  • Harness-reported cost: none reported.
  • Usage totals are not billing. Subscription spending is separate and is never posted as spend.
  • Crashed runs are counted separately: 0.

Token counters by model (native counter semantics; never added across semantics):

Selected rates (USD per million tokens). These rates value the report at the selected schedule date; they do not establish historical prices or subscription spending.

Model Input tier Input Cache read Cache write Other output Reasoning

Other output and reasoning are priced without double counting inclusive native output. Missing rates remain unknown.

Local measurement from native records; usage totals are not billing. Updated in place by agent-observer publish.

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ℹ️ No successful main baseline artifact is available yet. This run establishes the initial measurement.

Provider Metric Main baseline This PR Impact PR ceiling
Codex Total thread wire — 5.0 KiB — 6.8 KiB ✅
Codex Thread snapshot wire — 3.8 KiB — 4.9 KiB ✅
Codex Live turn WebSocket wire — 1.2 KiB — 2.0 KiB ✅
Codex Live turn WebSocket decoded — 20.9 KiB — 29.3 KiB ✅
Codex Live turn messages — 2 — 8 ✅
Claude Total thread wire — 5.0 KiB — 6.8 KiB ✅
Claude Thread snapshot wire — 3.8 KiB — 4.9 KiB ✅
Claude Live turn WebSocket wire — 1.2 KiB — 2.0 KiB ✅
Claude Live turn WebSocket decoded — 21.2 KiB — 29.3 KiB ✅
Claude Live turn messages — 2 — 8 ✅

Baseline: unavailable · PR result: af30a62 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 108.5 KiB
  • Claude decoded thread snapshot: 108.8 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@lukemaj

lukemaj commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

What Independent exact-head review found no supported blocking code finding on e4e54d6.
Why The reviewer inspected the rebased candidate against 2647478 and carried the production audit through the formatter-only final delta.
So what CI rollback failures still hold readiness; this review verdict does not waive failed checks or clear native blockers.

Reviewer findings follow unchanged:

Verdict: no supported blocking finding on e4e54d673f850353866d50fb65c15156b9bef352 against 2647478da553b442c6e5000b76c3b42042b01e69. The worktree is clean and PR #181 points to those exact SHAs. The 948c007 to e4e54d6 delta only wraps the sharedFiles array in fork-features.md; the formatter check passes. The 12 existing ownership entries are unchanged, with 13 features total.

The production review carries forward from 948c007: the cross-project RPC validates before dispatch and prepares from accepted events; D28 preserves same-transaction Stop admission and descendant draining through archived or deleted anchors; the constructor and EventSink audit found no captured services, direct I/O, or nested dispatch in commit plans. The shell-only lineage backfill remains idempotent and transcript-preserving. The added IssueLinks fixture checks the real consumer after repair. The proof record reports 230 focused passes, 2 MCP passes, both actual-source runs passing with zero skips, 762 source threads and 502 repaired links with no graph errors, clean typechecks, and a passing 13-feature inventory check. Full proof record

Adjacent behavior to track separately: IssueLinks.ts builds descendant traversal from rows where deleted_at IS NULL. If an intermediate thread is deleted while its grandchild remains active, the root’s Issue rollup can miss that grandchild’s Issue. This is unchanged #171-owned behavior, and I do not count it as a required #168 correction under the approved scope; track it with #171 if rollups should traverse deleted anchors.

At the latest CI check, Build, Lint, Typecheck, and several test jobs passed, while Test, Test Server 2, Test Server 3, and Test Server 6 were still pending. review/independent also remains pending; I made no GitHub status or PR writes. This verdict does not claim readiness, clear #169/#170 blockers, or establish live-provider closure. Accepted-interrupt settlement and provider teardown survival remain unverified; the post-commit preparation crash window also retains inherited recovery behavior and does not auto-resume preparation.

Requirements and who asked The #168 task requires independent review of the exact final head and current base.
Deleted No check waiver, adjacent #171 implementation, or live-provider claim.
Bottleneck Three CI runtime rollback failures require diagnosis and disposition before readiness.
Checked myself Verified reviewer thread, exact live PR head/base, current worktree and CI failure log.

@lukemaj

lukemaj commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

What PR #181 now fixes the introduced rollback regression at b93bd69 against 2647478.
Why The trailing retirement metadata event copied AppThread payloads but missed the preceding provider-thread.updated event's activeProviderThreadId update, replacing it with null.
So what Fresh CI and independent exact-head rereview are pending; readiness remains held and no failing check is waived.

Attribution and correction

CI Test Server 6 failed three unchanged runtimeLayer.test.ts rollback cases with No active provider thread exists for rollback. Failed job. The candidate e4e54d6 reproduced 69 passed / 3 failed locally. An equivalent source-base experiment in the exclusive #168 workspace, temporarily replacing every modified tracked file with its exact 2647478 bytes and then restoring all candidate bytes, passed 72/72. Branch, index, HEAD and other worktrees were untouched; final status was clean. Added fork files remained present but were unreferenced by the restored base implementation. This established an introduced #168 regression, not a base waiver.

ProjectionStore's provider-thread.updated handler also updates the app thread pointer. The #168 metadata wrapper now folds all planned self-thread events with the existing upstream applyToProjection reducer before adding retirement fields. It reads only thread records, using empty control arrays, and does not load history or change upstream rollback behavior. The existing rollback tests were not edited. The delayed ancestor Stop / explicit human child resume regression now asserts the resumed run's provider pointer alongside its retirement acknowledgment; before the fix it failed because that pointer was null.

Commands and outcomes

All commands used Node 24.13.1, unset ELECTRON_RUN_AS_NODE, TMPDIR=/private/tmp/, and pnpm_config_verify_deps_before_run=error, with Homebrew paths removed as in fork.md.

  • pnpm exec vp test run apps/server/src/orchestration-v2/runtimeLayer.test.ts: base-source 72 passed; original candidate 69 passed / 3 failed.
  • pnpm exec vp test run apps/server/src/orchestration-v2/ThreadStop.test.ts: strengthened regression failed before correction, 15 passed / 1 failed, decisive null pointer assertion.
  • Focused runtimeLayer + ThreadStop + requestWake + providerStop: 102 passed after correction.
  • Existing 18-file final suite plus runtimeLayer: 302 passed across 19 files, 3 opt-in skips. Full prior command and unaffected snapshot/inventory proof remain in the current-base record. Actual-source snapshot proof will be refreshed separately and serially on this head.
  • pnpm --filter t3 typecheck: exit 0.
  • pnpm exec vp lint apps/server/src/orchestration-v2/Orchestrator.ts apps/server/src/orchestration-v2/ThreadStop.test.ts: exit 0, one unchanged base layerUnavailable warning.
  • git diff --check: exit 0; pre-commit formatter passed; push and live PR exact head/base verified.

The first uncommitted reducer attempt lacked control arrays and failed locally; no such attempt was committed or pushed. Filling the full typed empty projection resolved it before the passing proof above.

Review and limits

The previous e4 independent review remains valid only for that head. Its full findings are relayed unchanged, including unchanged #171 deleted-anchor Issue rollup behavior as adjacent scope. New head rereview is required. No retirement/query/commit-plan API changed. Post-commit preparation retains inherited cancellation recovery; supported-provider survival after accepted interrupt remains unverified, and no live provider was invoked. Parent will refresh the same Observer comment after this push.

Requirements and who asked The user requires a ready #168 PR with passing focused proof, exact-head review, current base and no failed-check waiver; parent authorized this faithful in-scope repair.
Deleted No weakening of rollback tests, no adjacent #171 change, no live-provider invocation, and no second PR.
Bottleneck The newly introduced metadata overwrite caused CI rollback failures; corrected candidate now awaits rereview and CI.
Checked myself Read the CI failures, reproduced candidate and base, traced canonical projector pointer updates, observed failing-before resume assertion, and inspected passing proof, clean push and live SHA/base.

@lukemaj

lukemaj commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

What Corrected PR #181 head b93bd69 passes refreshed serial actual-source lineage and stored-Issue carryover proofs.
Why Current-head snapshot evidence is required independently of the passing generated fixtures and earlier-head records.
So what Fresh CI and independent rereview remain pending; this is proof publication, not a readiness claim.

Against unchanged base 2647478, the following commands ran sequentially with Node24.13.1 and fork.md host-neutral environment:

  1. CHROMERIA_V1_SNAPSHOT_SOURCE=/Users/lukaszmaj/.t3/userdata/state.sqlite CHROMERIA_V1_SNAPSHOT_REPORT=/tmp/168-port/metadata-real-lineage-counts.json pnpm exec vp test run apps/server/src/childThreads/lineageBackfill.test.ts: 2 passed, zero skipped, exit0. Source opened read-only, copied through VACUUM INTO only.
  2. After (1) completed, CHROMERIA_V1_SNAPSHOT_SOURCE=/Users/lukaszmaj/.t3/userdata/state.sqlite pnpm exec vp test run apps/server/src/issueLinks/IssueLinks.carryover.test.ts: 2 passed, zero skipped, exit0.

Sanitized aggregate: 762 source threads, 502 subthreads, all 502 existing-parent links repaired; zero orphan, dangling, cycle or root-mismatch counts. Legacy transcript rows stayed at 41397; native rows were 1490 before hydration and 19148 after import, with ledger coverage762. Repeated import/repair adds zero events/messages. No IDs or message content published.

node scripts/fork-features.mjs check passes (13 features); bash scripts/fork-check.sh --base 12069eefd707f78eafc27812027c994eea0613cf passes. An initial command used the nonexistent .ts script extension and failed before checking; the exact .mjs command above is the successful inventory proof. There is no check waiver.

The complete correction/red-green and 302-test command evidence is recorded here. Scoped server typecheck passes; full changed-TypeScript scoped lint passes with six unchanged base warnings. The retirement/query/plan contract and map are unchanged by this correction. No live provider, browser, install, merge or userdata write.

Requirements and who asked The user requires current-head actual-source VACUUM proof, focused checks, inventory and independent exact-head review.
Deleted No generated-fixture substitution for actual-source proof, no private content publication and no failed-check waiver.
Bottleneck Fresh CI and independent rereview on b93bd69 remain the delivery gate.
Checked myself Inspected both serial passing outputs, aggregate snapshot counts, live PR SHA/base, scoped lint and inventory/fork-check output.

@lukemaj

lukemaj commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

What Independent review found no supported blocking code finding on b93bd69 against 2647478.
Why The reviewer audited the actual CI regression correction, canonical event folding and supplied red/green and real-source evidence.
So what This records code review success only; final CI remains pending and readiness is held until live checks pass.

Full reviewer findings follow unchanged:

Exact review verdict

No supported blocking finding remains on b93bd69b2176bd6c88c4cdbbe00bc72141516e2c against 2647478da553b442c6e5000b76c3b42042b01e69. The worktree is clean, and PR #181 points to those exact SHAs. This verdict supports review/independent: success for that head; I made no GitHub writes.

Correction audited

The e4 regression was real: retirement metadata could overwrite a newly planned provider-thread pointer. The supplied red run reports 3 failures out of the 72 rollback cases, and the delayed Stop then human-resume assertion observed a null pointer. In b93, Orchestrator.ts reads only thread records, folds all planned self-thread events through applyToProjection, then appends retirement metadata from the resulting thread (changed block). The existing reducer applies provider-thread.updated to activeProviderThreadId. This avoids loading history and adds no API. Fork-plan construction, token admission, and EventSink transaction guards are unchanged, so the fix does not alter Stop token race semantics.

Proof inspected

The supplied artifacts report 302 passes across 19 focused files with 3 opt-in skips, followed by 102 passes across 4 files. Server typecheck reports zero errors; changed-file lint reports one unchanged base warning. Both serial actual-source runs pass 2/2 with zero skips. The snapshot has 762 threads and 502 existing parent links repaired, with zero orphans, dangling links, cycles, or root mismatches; legacy message count remains 41,397 through hydration. Inventory and fork check pass with 13 features. The proof record is here; I inspected the referenced logs and counts without rerunning tests.

Carried limitations and scope

  • Provider closure remains unverified against live providers. Adapter tests establish server-side cancellation and draining behavior, not survival of work in every native provider. I make no all-provider closure claim.
  • The post-dispatch preparation crash window retains inherited recovery behavior: recovery settles or cancels the pending preparation and does not auto-resume it.
  • The unchanged Port the GitHub Issues features #171 IssueLinks consumer filters deleted rows when building its descendant graph (IssueLinks.ts). An active grandchild behind a deleted intermediate can therefore be absent from a root Issue rollup. This remains an adjacent Port the GitHub Issues features #171-owned limitation, outside the approved Port child threads onto upstream lineage and delegation #168 correction scope.
  • Missing-ancestor reads and repeated wake rescans remain unmeasured optional performance concerns.

CI is still pending per the latest update, so this review does not claim overall PR readiness. It clears no #169/#170 native blockers. I made no source, test, PR, Issue, or status changes.

Requirements and who asked The #168 user requires independent exact-head/current-base review and no failed-check waiver.
Deleted No old-head review substitution, no adjacent #171 changes and no live-provider closure claim.
Bottleneck Final current-head CI remains pending.
Checked myself Read the full independent verdict, verified exact PR head/base and clean workspace, and verified the current-head Observer publication.

@lukemaj

lukemaj commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

What PR #181 is ready for review into fork/v2 at exact head b93bd69.
Why The approved native child-thread port, current-base integration and introduced rollback correction now pass focused proof, mandatory actual-source proof, independent review and all current-head CI jobs.
So what This is the single #168 delivery PR; no merge was performed. The parent owns final integration and any #169/#170 native blocker disposition.

Exact delivery state

  • PR: feat(server): port durable child threads to v2 #181, OPEN, non-draft, target fork/v2, linked to the T3 thread.
  • Head: b93bd69; base and live origin/fork/v2: 2647478, verified after CI completed.
  • Exclusive branch feat/168-child-threads-v2 and workspace 168-v2 are clean and remote head matches. No checkout/index/file changes in foundation or main workspaces.
  • Independent exact-head/current-base findings relayed in full unchanged, review/independent SUCCESS on b93bd69. No supported blocking code finding.
  • Current-head CI: Check, Build, Lint, Typecheck, Test, Test Web, all six Test Server shards, Rust and Release Smoke SUCCESS. Fork Stack Model and native fingerprints SUCCESS. Preview/conditional analysis jobs were workflow-skipped, not failed-check waivers. No pending, failed or cancelled current-head check remains.
  • No inline review or review-body bot finding is present at final inspection.
  • Observer publication refreshed by root for b93 and verified live. Report retains estimated cost unknown, incomplete usage coverage and attribution gaps; this is not zero cost or billing evidence.

Current proof

Host-neutral Node24.13.1 commands used unset ELECTRON_RUN_AS_NODE, TMPDIR=/private/tmp/, pnpm_config_verify_deps_before_run=error and excluded Homebrew paths. No dependency mutations accompanied final proof.

  • Focused suite across childThreads, runtimeLayer, FoundationPersistence, ThreadStop, ThreadLaunchService, ThreadMessageIntake, MCP service/activity/core/worktree, fork backfills, IssueLinks/carryover and fork-maintenance: 302 passed across19 files; three actual-source opt-ins omitted from ordinary run. Complete command/attribution is in the correction record.
  • MCP toolkit integration command: pnpm exec vp test run apps/server/src/mcp/OrchestratorMcpToolkit.integration.test.ts, 2 passed on b93.
  • Mandatory source commands: CHROMERIA_V1_SNAPSHOT_SOURCE with lineageBackfill.test.ts and IssueLinks.carryover.test.ts ran SERIAL, 2/2 each, zero skips. Exact-head snapshot proof: read-only VACUUM copies, 762 source threads and all502 existing-parent links repaired, no orphan/dangling/cycle/root mismatch, legacy41397 unchanged, repeat adds no events/messages. Foundation's unchanged actual-registry proof is explicitly reused as recorded in the current-base proof.
  • pnpm --filter t3 typecheck: exit0 current correction. Contracts scoped typecheck reused from current-base proof because contracts are unchanged by b93; current CI Typecheck also passed.
  • pnpm exec vp lint on every changed TypeScript file relative2647478: exit0, six previously verified unchanged base warnings. No warning waiver or cleanup beyond scope.
  • node scripts/fork-features.mjs check:13 features, exit0. bash scripts/fork-check.sh --base12069eefd707f78eafc27812027c994eea0613cf:exit0; git diff --check:exit0. All12 landed feature entries remain identical; child-threads is one additional primary owner, and issues-links remains primary for the shared worktree registration test.

The CI rollback failure on e4 was an introduced #168 regression, not accepted as inherited: equivalent base source passed72/72 while candidate failed3; a new Stop/resume pointer invariant failed before correction. Canonical planned-event projection now preserves the upstream activeProviderThreadId and other thread metadata before retirement fields are appended. Existing rollback tests were unchanged, and current CI confirms the failed shard now passes.

Decisions and limits

Reviewed root A-D/D13-A/D14/D15/D21/D28 approvals govern this implementation. In-process typed fork plans remain bounded/data-only, provider starts are drained on subtree Stop, propagation preserves the original token, and only trusted explicit messages resume. The landed #171 registration-test primary-owner decision was followed without changing its entry; #170 SubagentProjection ownership transfer waits for an actual merge. No old aliases, spawn_thread, Prism/Spectrum/Wight/scheduler ports or second PR.

Unchanged #171 deleted-anchor Issue rollup behavior remains adjacent, not a #168 blocking finding. Provider accepted-interrupt/native teardown survival remains unverified against live providers; no all-provider closure claim. Post-commit preparation keeps inherited cancellation recovery rather than automatic preparation resume. Missing-ancestor reads/repeated wake scans have unmeasured optional performance cost. No browser/mobile/live provider/dev server, merge, main push, install/deploy/version bump or live userdata write.

Requirements and who asked The user and reviewed #166/root decisions require one ready native child-thread PR with focused and real-source proof, current base, exact-head independence and Observer publication.
Deleted Duplicate delegation/UI/filtering, obsolete aliases, unrelated service ports, failed-check waivers and second PRs.
Bottleneck Introduced metadata overwrite was fixed at its #168 owner; required proof, CI and exact-head review are now complete. Human integration remains with the parent.
Checked myself Verified live exact head/base, clean remote branch, CI including formerly failing shard, full independent verdict, red/green proof, both serial real snapshots, inventory identity and published Observer report.

@lukemaj

lukemaj commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

What The prior b93/264 readiness record is superseded because #170 merged into fork/v2 at a97591e.
Why Final proof and review must bind to the current base and real landed native ownership implementation.
So what PR #181 remains the only delivery PR; current-base rebase, affected proof and exact-head rereview are underway, with readiness held.

The root explicitly authorized rebase and confirmed D13-D transfer: child-threads primary for SubagentProjection.ts and the six shared MCP/Orchestrator/launch/contract paths, thread-people sharedFiles. Other landed entries remain unchanged, including issues-links primary ownership of worktree registration.test.ts. The routine registry conflict preserves both the landed thread-people backfill and child-lineage backfill in the same typed foundation registry; source patches otherwise remain equal by range-diff. No unapproved policy or source choice was introduced.

The ownership integration proof now exercises a shared parent owned by a fixture person: same-project and cross-project native children inherit only the parent owner, clear coOwners, and leave the parent's owner/sharing intact. This uses #170's landed makeSubagentChildThread helper without a new owner API or source implementation.

Requirements and who asked Root requires same PR181 rebased after actual #170 merge, approved ownership transfer, current-base proof and rereview.
Deleted Old-base readiness reuse, duplicate primary owners, a competing owner helper and a second PR.
Bottleneck Current-base affected proof and exact-head review precede CI/readiness.
Checked myself Verified live a975 merge, exact diff, routine additive conflicts and equal source range-diff; 14-feature inventory passes after the explicit transfer.

@lukemaj
lukemaj force-pushed the feat/168-child-threads-v2 branch from b93bd69 to af30a62 Compare October 8, 2026 18:55
@lukemaj

lukemaj commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

What PR #181 is rebased at af30a62 onto #170 merge a97591e, with passing composed proof.
Why The actual landed native owner inheritance and thread-people backfill must compose with child creation, retirement and imported lineage before final review.
So what Exact-head/current-base review, fresh CI and current-head Observer publication still gate readiness; previous b93/264 readiness is superseded.

Composition and ownership

All fourteen #168 implementation commits remain equal by range-diff except the routine additive registry context and map context. The registry retains the landed thread-people entry with its typed payload-error mapping, followed by the child-lineage entry. No competing hook, source implementation or owner input was added.

Root explicitly confirmed D13-D: child-threads primary and thread-people sharedFiles for SubagentProjection.ts, OrchestratorMcpService.ts, OrchestratorMcpToolkit.integration.test.ts, toolkits/thread/handlers.ts, Orchestrator.ts, ThreadLaunchService.ts and contracts/orchestrationV2.ts. Every other landed entry is unchanged; worktree registration.test.ts remains issues-links primary. JSON comparison verifies all unaffected entries identical and exactly seven paths transferred; 14-feature inventory has no duplicate primary owners.

The existing cross-project integration case now uses real commands to create a Fixture Owner parent and share it with Fixture Collaborator. Both native destination and inherited-workspace children keep Fixture Owner and empty coOwners through #170's landed helper, while the parent's project/workspace, owner and sharing stay intact. This strengthens the actual launch seam, with no new mirrored test or ownership helper.

Commands and results

All commands use Node24.13.1, unset ELECTRON_RUN_AS_NODE, TMPDIR=/private/tmp/, pnpm_config_verify_deps_before_run=error and omit Homebrew paths per fork.md. The exclusive workspace is clean; no dependency mutation or other checkout write.

pnpm exec vp test run apps/server/src/childThreads apps/server/src/orchestration-v2/runtimeLayer.test.ts apps/server/src/orchestration-v2/FoundationPersistence.test.ts apps/server/src/orchestration-v2/ThreadStop.test.ts apps/server/src/orchestration-v2/ThreadLaunchService.test.ts apps/server/src/orchestration-v2/ThreadMessageIntake.test.ts apps/server/src/orchestration-v2/ThreadPeople.test.ts apps/server/src/mcp/OrchestratorMcpService.test.ts apps/server/src/mcp/OrchestratorMcpService.activity.test.ts apps/server/src/mcp/toolkits/core.test.ts apps/server/src/mcp/toolkits/worktree/registration.test.ts apps/server/src/mcp/toolkits/thread/handlers.test.ts apps/server/src/persistence/forkV1Backfills.test.ts apps/server/src/persistence/forkThreadPeopleBackfill.test.ts apps/server/src/issueLinks/IssueLinks.test.ts apps/server/src/issueLinks/IssueLinks.carryover.test.ts scripts/fork-maintenance.test.ts: 312 passed across22 files, four actual-source opt-in skips in this ordinary run. The actual-source cases below run explicitly; unchanged foundation actual-registry evidence remains reused as recorded previously.

  • pnpm exec vp test run apps/server/src/mcp/OrchestratorMcpToolkit.integration.test.ts: 2 passed.
  • pnpm --filter t3 typecheck: exit0; pnpm --filter @t3tools/contracts typecheck: exit0, advisory suggestions only.
  • pnpm exec vp lint on all changed TypeScript files relative a97591e, plus the strengthened crossProject test: exit0, six unchanged base warnings.
  • node scripts/fork-features.mjs check: exit0,14 features; bash scripts/fork-check.sh --base 12069eefd707f78eafc27812027c994eea0613cf: exit0; git diff --check: exit0. Formatter passed before commit.

Serial real-source proof

Each following command uses CHROMERIA_V1_SNAPSHOT_SOURCE=/Users/lukaszmaj/.t3/userdata/state.sqlite and runs only after the preceding command completes; snapshots read-only VACUUM INTO, no live-state writes:

  1. pnpm exec vp test run apps/server/src/childThreads/lineageBackfill.test.ts with CHROMERIA_V1_SNAPSHOT_REPORT=/tmp/168-port/peoplebase-real-lineage-counts.json: 2 passed, zero skips. 762 source threads,502 existing-parent child links repaired, no orphan/dangling/cycle/root mismatch; legacy41517 unchanged, native1491 before hydrate and19217 after,762-ledger coverage, repeat adds no events/messages.
  2. pnpm exec vp test run apps/server/src/persistence/forkThreadPeopleBackfill.test.ts: 5 passed, zero skips, including the real-source owner backfill case from landed Port thread people and ownership #170.
  3. pnpm exec vp test run apps/server/src/issueLinks/IssueLinks.carryover.test.ts: 2 passed, zero skips, preserving stored source Issue rows.

Only aggregate counts are retained publicly; no real thread IDs, owner names or message content.

Review and limits

Current exact-head review was dispatched read-only and review/independent is pending. Older b93 success applies only to b93/264. The provider metadata rollback correction is unchanged and included in all72 passing runtime tests. D28 original-token/no-op guards, deleted/archived traversal and fork-plan constructor restrictions remain unchanged.

No live provider/browser/mobile/server/merge/install/deploy/version bump. Live-provider teardown remains unverified; post-commit preparation retains inherited cancellation recovery. Adjacent #171 deleted-anchor rollup limitation is unchanged and separate. Missing-ancestor reads/repeated scans retain unmeasured optional performance cost. Consumer/native blocker disposition remains parent-owned.

Requirements and who asked Root requires same PR181 rebase onto actual #170, D13-D ownership transfer, parent-preserving child inheritance, composed registry proof and current-head independent review.
Deleted Duplicate primary owners, competing owner helpers, old-base readiness and repository-wide local checks.
Bottleneck Fresh current-head CI, full independent review and Observer refresh remain before ready handoff.
Checked myself Verified merge/diff/range-diff, exact push/base, real owner inheritance commands, both typed registry entries, all unaffected map entries, passing scoped tests/types/lint/inventory and serial snapshot outputs.

@lukemaj

lukemaj commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

What Independent review found no supported blocking finding on af30a62 against a97591e.
Why The reviewer audited #170 owner inheritance and typed registry composition while preserving the reviewed child-thread behavior.
So what Record exact-head review success; current-head CI and Observer publication are independently verified complete, and final handoff follows without merging.

Full reviewer findings follow unchanged:

Verdict

No supported blocking finding on PR #181 at exact head af30a6297a912840b9e95dac7158a6272a57e79d against base a97591eaca9ecb9979221a8f853dc69fff0126f2. I verified the clean worktree and matching PR head/base. Per your latest update, all af30 CI jobs are successful or skipped and Observer publication is verified. This review does not clear any separate native blockers or claim all-provider closure.

Source review

The rebased changes preserve the reviewed production behavior. The only production composition difference in the range-diff is the approved addition of child-lineage backfill to the landed thread-people registry; its typed error handling remains intact. The latest commit adds the #170 ownership test and map updates, with no production changes.

The ownership test verifies children inherit the parent’s owner, start without co-owners, and leave the parent’s sharing unchanged in crossProject.test.ts. The feature map gives child-thread creation paths primary ownership under child-threads, marks them shared with thread-people, preserves the Issues registration test’s primary ownership, and passes the 14-feature inventory.

The approved Stop behavior remains intact: descendant Stops check the original ancestor token and resumed state at the child commit boundary. A stale Stop records an accepted no-op receipt and short-circuits later plans, events, outbox work, and cancellations in EventSink.ts. The production ForkCommitPlan constructors resolve projection state inside the transaction and capture only immutable identifiers and tokens; I found no captured services, direct I/O, or nested dispatch. Archived and deleted intermediate traversal remains in ThreadManagementService.ts.

The direct RPC path validates the destination before dispatch, then prepares the committed delegated run through the normal launch service. The b93 provider-metadata reducer fix remains. Provider-idle updates require the interrupted run to own the current provider-thread ordinal, with no pending roster or surviving background work. Existing delegation tools and finalization remain; no alias or spawn_thread feature was added.

The shell-only lineage backfill repairs eligible missing links only when the parent exists, refuses cycles and dangling ancestry, and uses idempotent metadata events. Its registry composition and repair logic are in forkV1Backfills.ts and lineageBackfill.ts.

Proof inspected

The focused suite passed 312 tests across 22 files, with 4 ordinary-run skips. All three serial actual-source runs passed with zero skips: lineage 2/2, landed thread-people ownership 5/5, and Issues carryover 2/2. The lineage snapshot covered 762 threads, repaired all 502 existing child-parent links, and reported zero orphan, dangling, cyclic, or root-mismatched links. Legacy counts remained 41,517; native messages increased from 1,491 to 19,217 after hydration.

MCP integration passed 2/2; server and contracts typechecks passed; changed-scope lint passed; fork inventory/check passed; and git diff --check was clean. Six lint warnings remain in unchanged baseline code. I ran no tests and made no changes. The proof is recorded in the Issue comment.

Carried limitations

  • The controlled-adapter tests exercise the server and worker flow. They do not establish cancellation survival across live Codex, Claude, Cursor, or other provider processes.
  • A process crash between delegated-child commit and workspace-preparation scheduling leaves startup recovery to cancel the stale preparing run. It does not automatically resume; this is the existing launch recovery policy.
  • The inherited Port the GitHub Issues features #171 Issues rollup query excludes deleted thread shells in IssueLinks.ts. A live grandchild behind a deleted intermediate can be omitted from the root rollup. The carryover proof covers live imported ancestry; this separate behavior remains outside the approved Port child threads onto upstream lineage and delegation #168 corrections.
  • Repeated wake rescans from persisted resume metadata and missing-ancestor lookup cost remain unmeasured efficiency questions; I found no supported correctness defect there.

Requirements and who asked The user requires full independent exact-head/current-base findings and success status after each final rebase.
Deleted No old-head verdict substitution, native-blocker clearance, adjacent #171 fix or all-provider closure claim.
Bottleneck Required source proof and current-head checks are complete; final integration remains parent-owned.
Checked myself Read the full verdict, verified live PR head/base, all CI jobs, current Observer publication and clean linked workspace.

@lukemaj
lukemaj merged commit 6627c1a into fork/v2 Oct 8, 2026
28 checks passed
@lukemaj

lukemaj commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

What PR #181 is ready into fork/v2 at af30a62.
Why The native child-thread port now composes with landed foundation, Issues and people changes, and current-head proof, CI, independent review and cost publication are complete.
So what This is the one #168 delivery PR, left open and unmerged; the parent owns integration and separate native blocker disposition.

Exact head: af30a62. Exact reviewed base and live origin/fork/v2: a97591e. PR181 is OPEN, non-draft, merge state CLEAN, linked to this T3 thread; exclusive168-v2 workspace is clean and remote branch matches. Previous b93/264 readiness is superseded. No other checkout/index/files were altered.

Proof and review

  • Full current-base command/result record:312 passed across22 focused files, MCP integration2/2, fresh server and contracts scoped typechecks0, scoped lint0 with six unchanged base warnings, 14-feature inventory/fork-check0, diff/formatter0. No repository-wide local checks or dependency changes.
  • Three explicit real-source commands ran serially: lineage2/2, landed Port thread people and ownership #170 owner backfill5/5, Issues carryover2/2, zero skips in all. Read-only VACUUM copies;762 threads, all502 existing-parent links repaired, no orphan/dangling/cycle/root mismatch, legacy41517 unchanged, repeated repair/import adds no events/messages. No private IDs/owner names/content published.
  • Cross-project owner integration uses actual native delegation and sharing commands: children inherit the merged helper's parent owner, clear coOwners, and preserve parent sharing/project/workspace. Both typed backfill registry entries remain. Exactly seven approved primary paths transfer to child-threads/thread-people sharedFiles; all other landed entries remain unchanged and issues-links retains worktree registration-test primary ownership.
  • Independent full findings relayed unchanged; review/independent SUCCESS on exact af30 against a975, live verified. No supported blocking finding.
  • CI run: Check, Build, Lint, Typecheck, Test, Test Web, every Test Server shard1-6, Rust, Release Smoke and report transfer SUCCESS. Fork Stack Model/native fingerprints SUCCESS. Conditional preview/analysis jobs workflow-skipped. No pending/failed/cancelled current-head checks; no failed-check waiver.
  • No inline review or review-body bot findings at final inspection.
  • Observer report refreshed by root after af30 push and live verified (updated19:01UTC, cutoff18:56UTC). Estimated cost remains unknown and usage coverage incomplete; neither zero cost nor billing is inferred.

Decision trail and limits

Reviewed A-D/D13-A/D14/D15/D21/D28 govern this port; the published transaction/interface record and current-base proof carry their exact dispositions. Root explicitly reconfirmed D13-D seven-path ownership transfer after #170 landed. Routine source conflicts were additive; no competing hook or owner API. The introduced retirement-metadata rollback regression was fixed at the #168 owner, reproduced failing-before and re-reviewed, with unchanged72 rollback tests now passing locally and in CI. No old aliases or spawn_thread, Prism/Spectrum/Wight/scheduler ports, and no second PR.

Live-provider closure remains unverified; controlled adapters prove server lifecycle cancellation/draining, not every native provider process. Post-commit preparation retains inherited cancel/settle recovery without automatic preparation resume. Unchanged #171 deleted-anchor root Issue rollup behavior stays adjacent, outside #168; repeated wake scans/missing-ancestor lookup costs remain unmeasured. Separate native blockers stay parent-owned. No browser/mobile/dev server/live provider, merge/main push/install/deploy/version bump or live userdata write.

Requirements and who asked The user/root requires one ready native child-thread PR with current base, composed owner/migration behavior, focused and real-source proof, exact-head independence and Observer publication.
Deleted Duplicate primary owners, duplicate delegation/UI/filtering, competing ownership/migration hooks, obsolete aliases, unrelated service ports, failed-check waivers and extra PRs.
Bottleneck Introduced metadata overwrite and current-base integration were resolved; all required delivery checks are now complete, with integration left to the parent.
Checked myself Verified live exact SHA/base and clean linked workspace, composed registry/owner behavior and unaffected inventory identity, red/green proof and actual snapshots, full verdict/status, all CI checks and current cost publication.

@lukemaj
lukemaj deleted the feat/168-child-threads-v2 branch October 8, 2026 19:10
@lukemaj

lukemaj commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

What PR #181 was merged by the parent at 6627c1a, and all authorized #168 transient resources are retired.
Why The ready PR and closed Issue are terminal; the exclusive workspace and private snapshot copies have no continuing need.
So what #168 finalization is complete and work stops. Follow-up #182 and other port integration remain with their owners; no install or main cleanup occurred.

Live disposition: PR181 MERGED at 2026-10-08T19:05:19Z; Issue168 CLOSED at19:05:27Z. Reviewed head af30a62; merge6627c1afe97378cd0c2e4528dec20e8177acd133 has an identical tree (git diff --quiet exit0). Pre-removal worktree status clean and git rev-list HEAD --not origin/feat/168-child-threads-v2 counted0: no dirty or unpushed work. Prior open/unmerged handoff is superseded by this verified parent merge.

Exact resource enumeration and verification

  • Removed /Users/lukaszmaj/dev/toolboxmd/chromeria-worktrees/168-v2 with git worktree remove from the full clone; verified filesystem path and worktree registration absent. All seven other registered worktree paths remain.
  • Deleted local feat/168-child-threads-v2 and owned backup/168-b93-before-170; for-each-ref verifies both absent. Deleted origin feat/168-child-threads-v2; git ls-remote exact ref returns no row. No other branch was removed.
  • Actual-source harness paths were identified from the feature, foundation, owner and Issues tests: chromeria-real-lineage-/state.sqlite, chromeria-real-import-/chromeria-v2.sqlite, chromeria-people-/chromeria-v2.sqlite and chromeria-real-issue-links-/chromeria-v2.sqlite under the documented /private/tmp root. Their test finalizers had already removed them. Exact enumeration found zero remaining directories; no broad wildcard deletion was used.
  • /tmp/168-port and the removed worktree contained no SQLite/WAL/SHM snapshot residue. One exact retained directory /private/tmp/chromeria-lineage-0eNQ1m was positively identified as the Port child threads onto upstream lineage and delegation #168 generated five-thread fixture with one known sentinel message, not user data, then removed. Verified absent.
  • Deleted42 obsolete task body/script/JSON files by enumerated exact paths. Retained122 small proof logs/sanitized aggregate-count files only under /tmp/168-port, plus the small cleanup manifest /tmp/168-cleanup-manifest.json. Required durable proof, decisions and review remain on GitHub.
  • No process remained with the exclusive worktree as cwd at final check. Two prior lsof observations were already exited at ps verification; no process was killed. No server/browser/live provider was started for cleanup.

No write to live userdata or main checkout, no shared-temp deletion, no install/deploy/version bump. The canonical full clone was used only for Git worktree/ref metadata and remote branch retirement; its checkout/index/files were preserved.

Final current-base proof, full independent verdict, and Observer publication remain durable. Provider closure and adjacent #171 deleted-anchor rollup limitations remain as reviewed; cost estimate remains unknown with incomplete usage attribution.

Requirements and who asked Root explicitly authorized terminal cleanup after verified PR181 merge: exclusive workspace, all owned actual snapshots, local/remote branches, small proof logs retained and stop.
Deleted Exact owned worktree, merged task/backup refs, obsolete task files and one positively identified generated fixture; actual-source copies were already finalized by tests.
Bottleneck Terminal resource retirement is complete; no remaining #168 cleanup blocker.
Checked myself Verified live merge/closure, identical tree, clean/published head, exact path/ref absence, zero owned snapshot residue and preserved other worktrees.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant