Reconcile an interrupted create-once exchange by proving delivery absent account-wide #65

Merged
xicv merged 6 commits from fix/create-once-absence-reconcile into main 2026-09-23 10:33:29 +00:00
xicv commented 2026-09-23 04:44:32 +00:00 (Migrated from github.com)

Summary

Closes the reconcile gap for an unbound create-once exchange interrupted before Send confirmation (RTR-2026-0111, workflow dde6f3b3). Until now ego_reconcile_conversation returned workflow_not_reconcilable for such a run. abandon_workflow_recovery proves nothing. PeoplePlanner retires the paused dispatch and sends one successor only on a broker-proven delivery absence.

  • Eligibility (src/create-once-absence.mjs):
    • an ego_exchange stopped browser_operation_interrupted_before_send_confirmation in browser_owned, with no confirmed-Send evidence;
    • the binding is create-once and unbound, with no canonical URL, zero messages, all five head fields equal to the prior head, and the same revision;
    • it started from the plain new-chat page. A project start is refused as create_once_absence_unsupported.
  • Generation safety:
    • Verified live: a driver script keeps running inside Ego Lite after the adapter's timeout kills its client. Only a newer broker generation's lease fences its mutations.
    • The proof therefore runs only when the interruption came from an earlier broker generation. New interruptions record brokerEpoch. An older record qualifies when it was last written before this broker process started. Anything else is refused as reconcile_requires_new_broker_generation.
  • Account-wide proof (driver mode prove_create_once_absent, src/account-conversation-scan.mjs):
    • The driver recreates the binding's Space when it was wiped and opens the new-chat page.
    • Inside that page it reads every conversation created since ten minutes before the attempt, with no upper bound, in both the active and archived lists. ChatGPT's own API is used with the page session. The token never leaves the page, and results carry counts, reasons and, only when found, ids.
    • Fails closed on any HTTP error, a page cap, an unzoned or unparseable time, out-of-order or shifted listings (consecutive pages overlap and must match), duplicates, or any candidate without a readable user message.
    • Each page call stays under Ego Lite's 15 s evaluation limit.
    • Only after proving absence does it clear this workflow's exact own draft. A foreign draft is left alone.
  • Commit: the same workflow.cancelled / delivery_absent / result.deliveryState: "absent" transition as the existing path, with absenceProof. The broker commits only onto the exact records it scanned. It then re-records the recreated tab as the binding's location, so the successor can run. The binding stays unbound with its head, message count and URL untouched.
    • A found marker or a tab that became a conversation → create_once_delivery_found with ids, nothing changed.
    • An incomplete scan → create_once_absence_unproven, nothing changed.
    • A repeated call returns the committed result.
  • Reachable through ego_reconcile_conversation and ego-chat reconcile <binding> <workflow>. The reconcile timeouts are raised to fit the scan.
  • Residual gap: a conversation the user has since deleted cannot be seen.

Browser contract 28, runtime generation 2026-09-23.5.

Verification

  • npm test 1069 tests, 1068 pass, 1 skipped; lint clean; receipt suite 16/16; cargo test 33 + 1.
  • Read-only against the live account, using this branch's own scan functions:
    • all 11 conversations created since RTR-0111's run began were listed and inspected, 0 archived, and the marker was found in none;
    • a positive control detected a known marker;
    • timestamps are zoned ISO strings, and AbortSignal.timeout exists in the page.
  • RTR-0111 meets every eligibility field: all five head fields, revision, identity name equals task id, and the plain new-chat start.

Not yet done

Not merged, released or installed: held until the operator's go. After install, run ego-chat reconcile peopleplanner-rtr-2026-0111 dde6f3b3-c204-407e-bf6b-8ffd48abb039 once and check every PeoplePlanner field.

## Summary Closes the reconcile gap for an unbound create-once exchange interrupted before Send confirmation (RTR-2026-0111, workflow `dde6f3b3`). Until now `ego_reconcile_conversation` returned `workflow_not_reconcilable` for such a run. `abandon_workflow_recovery` proves nothing. PeoplePlanner retires the paused dispatch and sends one successor only on a broker-proven delivery absence. - **Eligibility** (`src/create-once-absence.mjs`): - an `ego_exchange` stopped `browser_operation_interrupted_before_send_confirmation` in `browser_owned`, with no confirmed-Send evidence; - the binding is create-once and unbound, with no canonical URL, zero messages, all five head fields equal to the prior head, and the same revision; - it started from the plain new-chat page. A project start is refused as `create_once_absence_unsupported`. - **Generation safety:** - Verified live: a driver script keeps running inside Ego Lite after the adapter's timeout kills its client. Only a newer broker generation's lease fences its mutations. - The proof therefore runs only when the interruption came from an earlier broker generation. New interruptions record `brokerEpoch`. An older record qualifies when it was last written before this broker process started. Anything else is refused as `reconcile_requires_new_broker_generation`. - **Account-wide proof** (driver mode `prove_create_once_absent`, `src/account-conversation-scan.mjs`): - The driver recreates the binding's Space when it was wiped and opens the new-chat page. - Inside that page it reads every conversation created since ten minutes before the attempt, with no upper bound, in both the active and archived lists. ChatGPT's own API is used with the page session. The token never leaves the page, and results carry counts, reasons and, only when found, ids. - Fails closed on any HTTP error, a page cap, an unzoned or unparseable time, out-of-order or shifted listings (consecutive pages overlap and must match), duplicates, or any candidate without a readable user message. - Each page call stays under Ego Lite's 15 s evaluation limit. - Only after proving absence does it clear this workflow's exact own draft. A foreign draft is left alone. - **Commit:** the same `workflow.cancelled` / `delivery_absent` / `result.deliveryState: "absent"` transition as the existing path, with `absenceProof`. The broker commits only onto the exact records it scanned. It then re-records the recreated tab as the binding's location, so the successor can run. The binding stays unbound with its head, message count and URL untouched. - A found marker or a tab that became a conversation → `create_once_delivery_found` with ids, nothing changed. - An incomplete scan → `create_once_absence_unproven`, nothing changed. - A repeated call returns the committed result. - Reachable through `ego_reconcile_conversation` and `ego-chat reconcile <binding> <workflow>`. The reconcile timeouts are raised to fit the scan. - **Residual gap:** a conversation the user has since deleted cannot be seen. Browser contract 28, runtime generation 2026-09-23.5. ## Verification - `npm test` 1069 tests, 1068 pass, 1 skipped; lint clean; receipt suite 16/16; `cargo test` 33 + 1. - Read-only against the live account, using this branch's own scan functions: - all 11 conversations created since RTR-0111's run began were listed and inspected, 0 archived, and the marker was found in none; - a positive control detected a known marker; - timestamps are zoned ISO strings, and `AbortSignal.timeout` exists in the page. - RTR-0111 meets every eligibility field: all five head fields, revision, identity name equals task id, and the plain new-chat start. ## Not yet done Not merged, released or installed: held until the operator's go. After install, run `ego-chat reconcile peopleplanner-rtr-2026-0111 dde6f3b3-c204-407e-bf6b-8ffd48abb039` once and check every PeoplePlanner field.
Sign in to join this conversation.
No description provided.