Skip to content

feat: support validated same-session conversation rewind - #610

Closed
Wolf-L wants to merge 6 commits into
agentclientprotocol:mainfrom
Wolf-L:refresh/20261011-codex-core
Closed

Wolf-L wants to merge 6 commits into
agentclientprotocol:mainfrom
Wolf-L:refresh/20261011-codex-core

Conversation

@Wolf-L

@Wolf-L Wolf-L commented Oct 10, 2026 •

Copy link
Copy Markdown

Behavior and integration

Adds negotiated same-session conversation rewind without creating another Codex thread. _session/rewind validates the user-message identity, fingerprint/occurrence and retained assistant boundary, then verifies the persisted same-ID prefix after native revert. Legacy rollback is used only for an explicitly legacy history mode. Ambiguous writes are not retried; successful load is required to reconcile an unknown history outcome. This does not restore files.

Replaces #596 after withdrawing the earlier submission. Refreshed on upstream main 202e66e63343ec4f5a5e35ab590251d813d129ca (2.2.2), retaining custom instructions, AIR sessionIndex, title selection and app-server recovery. The contract and original implementation credit Nikita Ashikhmin's #508; the refreshed history consolidates the old integration.

New regressions cover crash recovery before rewind, no replay after a lost native acknowledgement, index mutation admission, provider-update/close ordering, idle title invalidation and dispatched-title draining across load/resume/close. A retired title generator cannot restart work; unknown title acknowledgements remain fenced. The upstream bounded title wait during load is preserved.

The full companion #611 adds runtime/discovery/archive/attachments and previewed file reversal. It contains this core scope; review/merge core first and refresh the companion afterwards. The persistent queue proposal is independent.

Local validation

  • Ubuntu 24.04 / Node 24.14.0: typecheck/build passed; full suite 1546 passed, 36 skipped (single worker).
  • Windows targeted rewind/title/recovery regressions: 68 passed. The broader recovery/index run has the same five subscription-notification failures as untouched main; no all-green Windows full-suite claim.
  • Pinned native Codex 0.160.1 with isolated home/workspace and a scripted loopback provider: 13/13 on both Windows and Linux. Historical/latest/first/repeated-message rewind, cold reload, resend context, interruption and child shutdown are checked.
  • All six Bun release targets compile. Cross-compilation is not physical ARM/macOS runtime validation.
  • No real account/model calls, installed package changes or user sessions were used. Local results are distinct from hosted CI and maintainer approval. The loopback/deny-proxy environment is not an OS firewall.

中文

撤回旧 #596 后,按最新主线 202e66e(2.2.2)重新提交同 ID 持久对话回退。保留新上游自定义指令、sessionIndex、标题选择和 app-server 恢复;先验证身份与保留边界,再执行并核对原生历史,未知结果不自动重试。协议及原始实现注明 #508 作者归属。

补齐崩溃恢复、索引修改互斥、provider 更新与 close 的取消顺序,以及跨 load/resume/close 旧标题任务的失效/回执保护。回退不恢复文件;完整增强 companion 包含本核心,应先审核心;原生持久队列为独立提案。

本地 Linux 全量 1546 通过/36 跳过,类型检查和构建通过;Windows 定向回归通过;双平台隔离原生各 13/13,六个平台交叉编译通过。Windows 的五项上游基线失败如实保留,未声称全套全绿或真实账号/模型/ARM 实机验证。托管 CI 与维护者批准另行判断。

Extension-only review after the full companion is published: core → extensions.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant