Repository navigation
Conversation
Build on review/native-rewind-core-codex. Preserve the tested full implementation from eec34bd with the same tree, while separating the core rewind review from runtime and file/session extensions.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
One integrated proposal for same-session rewind, native session controls and persistent queues. There are no companion or feature-split PR dependencies. Replaces withdrawn #596, #597, #598 and the withdrawn split refreshes #610, #611, #612.
Refreshed on upstream main
202e66e63343ec4f5a5e35ab590251d813d129ca: adapter 2.2.2, locked Codex 0.160.1 and ACP SDK 1.5.0. Rewind protocol/original implementation credit: Nikita Ashikhmin's #508.Included behavior
Integration safeguards
Preserves upstream custom instructions, sessionIndex routing/subscriptions/deletion, title handling and supervised app-server recovery. Queue writes share admission with rewind and runtime mutations. Active/retained autonomous work must settle before history/provider changes; pending entries block rewind and provider-wide controls. Both AIR/index and legacy archive reject active/retained queue ownership without closing it. Ordinary close and rename behavior remains intact.
A lost rewind acknowledgement fences later queue writes. Lazy recovery does not silently dispatch persisted input; explicit load adopts ownership before resume. Provider/file-control deadlines include readiness, and late readiness cannot continue after invalidation. Title writes retained across replaced/closed states are drained before rewind. Compiled process helpers enter before application/config imports and accept no executable source.
Local premerge validation
Official Node 24.21.0; Ubuntu 24.04 and Windows:
npm ci, typecheck, defaultnpm test, build and all six Bun 1.3.11 release targets: 1737 tests passed, 37 skipped.5c5b605; finalf5fda96only corrects two documentation files, with all other tracked files identical. Clean-tree, whitespace and latest-main merge checks passed.No user session, installed ACP, real account/model or global configuration was used or modified. These are local results, not hosted CI or maintainer approval.
Limits
Windows full-suite green is not claimed: five recovery/index subscription failures reproduced on untouched main. The WSL distribution Node 24.19 deep-JSON failure also reproduces on untouched main; that isolated upstream test and this branch's full suite pass with official Node 24.21. Opt-in account/model tests remain skipped.
File reversal is not a whole-workspace checkpoint and excludes binary, shell and unrecorded subagent writes. Search can miss ancestor-rollout content. External writers and descendants leaving the owned process group remain outside adapter guarantees. Queue cancellation is not atomic whole-queue pause; exactly-once execution is not promised. Cross-compilation is not physical ARM/all-target runtime validation. Loopback fixtures and a denying proxy are not an OS firewall.
中文
本 PR 一次整合回退、会话增强和持久队列,不再拆分功能 PR,也无 companion 依赖。基于最新主线
202e66e,保留上游索引、自定义指令、标题及进程恢复,并注明原始回退设计归属。队列与回退/运行控制共享互斥;活跃及保留子任务未结束时不能归档或修改历史。AIR 索引与旧归档入口均受保护,普通 close/rename 行为保留。未知回退结果阻止后续队列写入;普通自动恢复不偷偷启动队列,显式 load 先接管所有权再恢复。
CI 对齐验证:Linux 1737 通过、37 跳过;Windows 定向 153 通过;双平台真实原生各 28/28;六发行目标及六项编译产物进程测试通过。最终提交仅补正文档,运行/测试/构建输入与已测版本相同。均为隔离本地验证,未声称托管 CI、真实账号/模型或 ARM 实机通过;Windows 和旧发行版 Node 的上游基线失败如实保留。
文件反向应用不是完整 checkpoint,外部写入及全队列原子暂停不在保证内。