Repository navigation
fix(native-chat): keep a Codex ask's questions in the order it asked them - #23502
Conversation
…them Codex journals every question of one ask in a single write, so the questions share a timestamp. The transcript list sorted rows by timestamp and broke ties by row id, and a question's id ends in the question id the model chose, so answered, cancelled and still-pending rows of one ask came out in the alphabetical order of those ids. The transcript projection now breaks timestamp ties by the order its source gave: the journal's order for structured sessions. The session assembler keeps its id tie-break, since the sources it merges share no order of their own.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (4)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 4 remain after this review. 📝 WalkthroughWalkthroughJournal items now retain their position within lifecycle batches, and reducers sort items by sequence and batch index. Structured transcript projections carry journal positions, which guide transcript and renderer ordering. Worker reads omit this metadata. Tests cover reducer ordering, recovered rows, outbox submissions, and Codex question order. Priority: ➖ Normal Merge Risk: ⚪ Minimal · up to The journal-ordering change is mergeable after normal checks; no actionable issue remains identified. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 2 systems. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 2📝 Generate docstrings 💡
⚔️ Resolve merge conflicts 💡
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Two shared comparators differed only in whether they break timestamp ties by id, under near-identical names; spell the id tie-break in the name.
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes
- Tie-preserving transcript projection —
projectNativeChatTranscriptMessagesnow defaults to the new time-onlycompareNativeChatMessageTimes, so rows that share a timestamp keep the order their source supplied instead of falling back to row id (src/shared/native-chat-transcript-projection.ts:12). - List uses the tie-preserving comparator — the message list projection passes
compareMessageTimes(rank, then time) rather than the id-breakingcompareMessages(native-chat-message-list-projection.ts:28). - Total order kept for unordered sources —
compareMessagesis rebuilt ascompareMessageTimes || compareNativeChatMessagesByTime, preserving the previous rank → time → id total order for the terminal-backed merge andorderNativeChatMessages(native-chat-session-assembler.ts:120). - Host-journal integration test — a real Codex three-question ask is driven through the host journal, answer and cancel paths, the client reducer and the list projection, reproducing all three live orderings (
src/main/codex/codex-structured-question-order.test.ts). - List-projection tie test and tsconfig include — a new equal-timestamp ordering case, plus the two renderer files the new main-side test imports added to the node tsconfig.
I re-ran the three touched test files, the adjacent grouping/question/outline suites, pnpm tc:node and oxlint on the changed files — all pass. Reverting the comparator changes makes the four new ordering assertions fail, so the tests genuinely pin the behavior. agent-session-conversation-outline.ts is the only default-comparator caller and passes journal order, and mobile doesn't consume either changed projection, so the shared default change is safe.
DeepSeek Flash (free via Pullfrog for OSS) | 𝕏
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes
- Rename only since the prior review —
cf8ecbcrenames the time-then-id total order fromcompareNativeChatMessagesByTimetocompareNativeChatMessagesByTimeThenId, so it no longer reads as if it compared time alone (src/shared/native-chat-transcript-projection.ts:19). - Call sites updated —
compareMessagesin the session assembler now callscompareNativeChatMessagesByTimeThenId; no references to the old name remain (native-chat-session-assembler.ts:121). - The functional fix from
c577f02(time-only default comparator, list usescompareMessageTimes, host-journal integration test, tsconfig includes) is unchanged.
Verified at the new head: no remaining references to the old symbol, pnpm tc:node passes, and the codex question-order, list-projection, message-grouping and rail-outline-parity suites all pass.
DeepSeek Flash (free via Pullfrog for OSS) | 𝕏
Review status: ready for reviewHead: What this fixes. When Codex asked several questions at once in a structured chat, the rows came out scrambled:
Codex writes all questions of one ask in a single journal write, so they share a timestamp. The chat list sorted by time and broke ties by message id. Those ids end in question ids the model makes up, so the rows came out in alphabetical id order. The list and the host's conversation outline now keep the journal's order on ties. Terminal-backed chats keep their id tie-break, because their sources have no shared order. Nothing persisted changes shape. Review loops. Converged in two loops.
Readiness checks. Start and end both passed; the end check found no issues. Tests. A new end-to-end test drives a real three-question Codex ask through:
On main it reproduces all three wrong orders. Every new test fails with the fix removed. Live QA against real Codex in a background dev build with an isolated profile. The Codex question tool was switched on for the run only. The question ids sorted differently from the asked order, so an id sort would have shown up. The rows read Q1, Q2, Q3:
Normal Codex and Claude chats showed no rows moving while replies streamed. Before and after screenshots are in the PR body. Known, not caused by this PR:
|
The desktop list and the host's conversation outline sorted structured rows by timestamp. The journal's contract is that the sequence orders the timeline and the timestamp is the provider's clock: a Codex ask writes all of its questions in one write (one sequence, one timestamp), and a row recovered after a crash carries an earlier clock at a later sequence. The host now records each item's place within the write that created it, keeps it across revisions like the sequence, and sends it as an optional field. Rows projected from the journal carry that position, and both the desktop list and the outline order journal rows by it. Rows outside the journal keep their rules: rank for the streaming and pending tail, outbox sends after every journal row, and terminal-backed chats keep time then id.
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes
- Reworked ordering onto an explicit journal position —
458f7f8drops the tie-preserving comparator fromcf8ecbcand instead gives every journal row ajournalPosition({ sequence, index }), so ordering no longer reads the provider clock at all (src/shared/agent-session-journal-position.ts). - Host records and preserves the place within a write — the reducer now iterates
row.mutations.entries()and passes the index intojournalRenderItem, which emitssequenceIndexonly when non-zero;upsertItempins the creating write'ssequence,sequenceIndexandobservedAtacross revisions, so an answer or cancel moves content but not the bubble (journal-reducer.ts,journal-render-item.ts). - One comparator for host and client —
renderJournalState,projectJournalBatch,replacePageandmergeItemsall sort bycompareAgentJournalItems;projectNativeChatTranscriptMessagesdefaults to the newcompareNativeChatTranscriptMessages, which ranks positioned rows by position and leaves outbox/streaming/terminal rows on the old time-then-id order (structured-agent-session-reducer.ts,agent-session-journal-batch.ts,native-chat-transcript-projection.ts). - Structured projections carry the position — both the message and pending-question projections build rows through
agentJournalItemRowOrigin(item), andNativeChatMessagegains the optionaljournalPositionfield (structured-agent-session-projection.ts,structured-agent-question-projection.ts,native-chat-types.ts). - Tests pin the new semantics — a crash-recovered row sorts by journal position despite an earlier clock, a shuffled single write sorts by place, and an outbox send sorts below every journal row (
structured-agent-session-transcript-order.test.ts,journal-reducer.test.ts,structured-agent-session-reducer.test.ts, rail-outline-parity).
I read the incremental range and the full diff, traced the host reducer → wire → client reducer → transcript projection path, and confirmed mobile renders the shared reducer's order without re-sorting. The five ordering suites pass (61 tests) and pnpm tc:node passes.
DeepSeek Flash (free via Pullfrog for OSS) | 𝕏
…list positions off worker reads A send the host journalled before the provider refused it is shown from the outbox, and it sorted after every journal row, so it dropped below whatever the agent wrote after it. It now takes the journal position of the submission the host recorded. Structured worker reads and their archives projected journal rows through the same projection, so they returned the list-only journal position on every message. The worker payload bound now drops it.
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes
- Refused sends keep their journal place —
projectStructuredAgentSessionMessagesnow collects rejected journal items into arefusedmap and hands a matching outbox entry that item's journal position, so a send the host journalled before the provider refused it no longer drops below everything the agent wrote after it (src/shared/structured-agent-session-message-projection.ts:24). - Worker reads and archives drop the list-only field —
boundMessagedestructuresjournalPositionout, soworker-read --source transcript, its remote variant, andboundStructuredJournalTailnever carry a field that only orders a live list;NativeChatMessage.journalPosition's doc says so (src/main/runtime/orchestration/worker-transcript-payload.ts:111). - Position helper extracted —
agentJournalItemPositionis pulled out ofagentJournalItemRowOriginso the refused-send path reuses the exact{ sequence, sequenceIndex ?? 0 }construction instead of re-spelling it (src/shared/agent-session-journal-position.ts:23). - Tests — a refused, still-in-the-outbox send is pinned to
['ask', refused, 'reply', next], and a structured worker's rows are asserted to lose the position (with an anti-vacuous check that the projection adds it) (structured-agent-session-transcript-order.test.ts,worker-transcript-payload.test.ts).
I traced the refused path end to end: the rejected item is excluded from visibleItems, so its key is absent from journalled, the outbox entry flows through optimistic, and reconcileStructuredAgentSessionOutbox keeps a rejected entry unless its reason is DISPATCH_REJECTED_CANCELLED; the worker bound is the single chokepoint for every worker read and archive. pnpm vitest run on the three touched suites passes (21 tests) and oxlint on the four prod files is clean.
DeepSeek Flash (free via Pullfrog for OSS) | 𝕏
Review status (reworked): ready for reviewHead: What changed since the last status. Rows were ordered by timestamp with a fix for ties. They are now ordered by the journal's own position: the sequence of the write, then the item's place within that write. The journal already defines this order, and it is the order the agent produced the items in.
Review. Treated as a fresh review because the mechanism changed.
Live QA used real Codex, in a background dev build with an isolated profile. Codex's question feature was switched on for that run only. In every ask, an id sort would have produced Q2, Q1, Q3.
Screenshots are in the PR body. Behaviour worth a decision, not a defect:
Other observations:
|
…hat-codex-question-order
…failed Since a message is accepted before its delivery starts the agent, a restart that fails is journalled after the message, and the refused message keeps that journal place in the chat. Both host paths now pin it through the chat's own projection: a start the host could not make, and a restarted child that exits before proving its start. Folds the journal reducer's batch item write onto fewer lines, which the merge of main pushed past the file's line limit.
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes
- Failed-restart ordering pinned through the chat projection — a new end-to-end test drives a start the host could not make and asserts the error row draws below both accepted messages (
[first, second, errorRow]), and a second host test asserts the same relative order when a restarted child exits before proving its start (structured-agent-session-accept-then-deliver.test.ts,structured-agent-session-send-restarts-failed-start.test.ts). - Shared test helper —
hostTestDrawnRowIdsbuilds the composer's outbox and runs it through the realprojectStructuredAgentSessionMessages→projectNativeChatTranscriptMessagespath, so the assertions read what a chat actually draws (structured-agent-session-host-test-data.ts). - Mechanical reducer fold — the batch-item write is collapsed onto locals (
{ revision, body },producer,item) to stay under the file's line limit after theorigin/mainmerge; semantics are unchanged (journal-reducer.ts). - Merge of current
main—040288ebrought main'sstructured-agent-session-*changes in; thesequenceIndexlogic andupsertItem's position-pinning survived intact.
I re-ran the two changed host suites, the journal and client reducer suites, pnpm tc:node, and oxlint on the four changed files — all pass. Ablating the refused-send journalPosition in structured-agent-session-message-projection.ts makes both new tests fail (the message drops below the error/cause row), so the tests are not vacuous.
DeepSeek Flash (free via Pullfrog for OSS) | 𝕏
…hat-codex-question-order # Conflicts: # src/main/native-chat/agent-session-wire/structured-agent-session-accept-then-deliver.test.ts # src/shared/structured-agent-session-projection.ts
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes
This run covers 8c94a44, a merge of origin/main (5219b8a) into the branch. The merge had two conflicts, both resolved without losing either side's work:
- Journal position and main's projection changes coexist — in
src/shared/structured-agent-session-projection.tsthe resolution keeps the PR'sagentJournalItemRowOrigin(item)import and the row-origin spread inprojectStructuredItemToNativeChat, while taking main's removal of the now-unusedreadAgentJournalTurnOutcomeimport. - Both new failed-start tests retained — in
structured-agent-session-accept-then-deliver.test.tsthe resolution keeps the PR'sdraws the messages it failed above the error row, since they were accepted firsttest and main'snotifies failed once for the queued messages one start failure refusedtest, merging the import list to addAgentSessionTurnCompletionEvent.
I confirmed git diff 5219b8a..8c94a44 over the PR's own files introduces only the PR's changes — no hunk reverts a line main added, so the merge genuinely preserved both sides rather than favoring one. I then re-ran the eight touched suites (136 tests, including both conflict files and main's structured-agent-session-projection.test.ts), pnpm tc:node, and oxlint on the conflict files — all pass.
DeepSeek Flash (free via Pullfrog for OSS) | 𝕏
|
Update: now on current main (head
|
…ree tests (#23560) #22835 made history() and journalSnapshot() async; tests from #23502 and #22944 still call them synchronously, so the typecheck job is red on every PR while main pushes do not run it. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb
…n the host and pane (#23602) * test(native-chat): await the async history and journal snapshot in three tests (#23560) #22835 made history() and journalSnapshot() async; tests from #23502 and #22944 still call them synchronously, so the typecheck job is red on every PR while main pushes do not run it. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * feat(usage): show ZCode Coding Plan quota on current main (#23520) Shows the ZCode Coding Plan quota in the status bar alongside the Claude and Codex usage readouts, reading the key from the user's own ZCode config. Credentials are scoped tightly: the host must be an exact match in the allowlist, HTTPS on port 443 only, `redirect: 'error'`, and the key is checked for CR/LF before it reaches a header. The key itself is never stored or logged — account identity is an HMAC. Both JSON inputs (a user-edited config file and the remote quota response) are narrowed at runtime rather than asserted, and the request cancels an unread response body on the error path so it cannot trip the undici parser crash (orca#8695). Co-authored-by: guanbear <guanbear@users.noreply.github.com> * fix(mobile): paired clients re-derive a kept terminal after a cold restore (#23109) * fix(mobile): paired clients re-derive a kept terminal after a cold restore A renderer frame published before a cold-restored terminal's PTY registered was fenced to an empty tab list and recorded as accepted, and the renderer never resends unchanged content. When registerPty binds a surface the accepted frame fenced out, re-merge that frame so the fence reads current state. * test(mobile): drive the live desktop window through the runtime's desktop seam * test(mobile): the re-derive path never flushes the store synchronously * test(mobile): a re-derived frame must not bring back a surface the host retired after accept * fix(mobile): a re-derived frame changes membership only for the registering surface The replay re-ran the whole accepted frame, so a surface the host retired after accept (a phone close whose remote PTY is still exiting, or a closed chat tab) came back. Every other surface now keeps the host's current decision; the removal repair is extracted from the terminal retirement helper so non-terminal tabs are removed the same way. * test(mobile): a re-derived frame must not drop or disown a phone-created terminal the desktop has not published * fix(mobile): a re-derived frame does not infer renderer retirements from its older frame * revert(mobile): drop the replay of a fenced renderer frame Reverts the production parts of a88e1eaa0a, f5b99d0003 and 5af1c6d97a: the kept renderer frame, rederiveFencedRendererSurface and its registerPty call, and the mergeRendererMobileSnapshot / removeMobileSessionSnapshotTabs extractions. The fence will instead read the host's saved membership record. The test file stays and is rewritten for that mechanism. * fix(mobile): the paired-list fence admits a terminal the saved session still lists After a cold restore the in-memory mobile snapshot and PTY table start empty, so in a repo with host-authoritative terminal membership the fence dropped a restored terminal whose renderer frame arrived before its PTY registered, and paired clients never listed it. The fence now also admits a surface the host's saved workspace session still lists (tab under the worktree, leaf in its layout), and registerPty pushes the listing so pending-handle turns ready at once. A restored pane whose PTY never returns is listed as pending-handle, as in repos that are not host-authoritative. * test(mobile): keep the desktop window stub's type assertion on its SAFETY line * fix(mobile): coalesce the registration push for a listed restored terminal registerPty pushed the paired list immediately on every registration that backs a listed surface. The desktop's graph sync after a spawn already publishes the same pending-handle to ready flip on the 50 ms coalescing window, so each restored pane cost two pushes, and a restore of N panes cost N immediate full-list pushes per client. The touch now rides the same coalescing window, which still covers a registration no graph change follows. The test's "unchanged" sync dropped the graph's tab, which is itself a change, and its no-extra-push assertion ran before any coalesced push could fire; both are fixed, and a restore of two panes is asserted to push once. The fence comment no longer claims the new clause keeps pending leaves out of the graph: once the surface is listed, its leaves pass the shared predicate through that listing, as any listed surface's do. * fix(mobile): read saved membership only from the worktree's own session partition For a runtime-host workspace, emptying the owning partition re-routes session reads to a single other partition that still lists the worktree. If that older copy lists a surface a retirement just removed, a lagging renderer frame could re-admit it. The saved-membership check now reads only the partition the worktree's host names, so it never trusts a fallback copy. * test(mobile): pin the own saved partition for every workspace host kind Also correct the immediate-emit comment: only an exit bypasses the window; a registration's ready flip coalesces. * Fix terminal focus when Cmd+J wakes a workspace (#23546) * fix: retain workspace terminal focus through wake restoration * test: reset CPU throttling after wake focus assertion * fix: require terminal textarea readiness before claiming focus * test: configure React act environment for dialog regression * fix(mobile): size a terminal's first subscribe from the document's reported cell box (#23080) * fix(mobile): size a terminal's first subscribe from the document's reported cell box #22960 sent phone dims on a terminal's first subscribe by opening a throwaway empty terminal (init 80x24 ""), awaiting its ready and measuring, behind a per-document first-subscribe mark whose lifetime was tied to web-ready. That cost a second xterm/WebGL instance and ~150 ms per open, plus lifecycle state. The document now measures the cell box without a terminal (xterm 6's CharSizeService strategy, rounded as the renderer rounds it) for every text-size preset and reports it with its viewport in web-ready; a table, because the text scale only reaches the document after that notify. Each init's ready reports the box xterm actually laid out, which replaces the probe's entry. The controller answers fitDimensions/measureFitDimensions from that table and the view's layout with no message; without a table it asks the document as before. The session seeds an unmeasured viewport synchronously in subscribeToTerminal, so the first subscribe carries dims by construction. Deleted: the empty init, its awaitReady gate, deferFirstSubscribeUntilViewportMeasured and the subscribedDocuments mark. The fit pass is unchanged and still covers a document that reports no cell box. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * refactor(mobile): read the reported cell box through in-narrowing, not Reflect.get Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * fix(mobile): correct the probe's cell-box guess from the box xterm lays out The web-ready probe is a guess: building the WebGL addon creates no context, so a context that fails on load lands on the DOM renderer, whose width is not snapped and depends on the column count. Before, a ready box that differed was only logged; the first subscribe had carried the wrong column count, the host echoed it, the fit pass saw the viewport equal to the host's dims, and the grid stayed slightly shrunk. The store also kept the WebGL width after a context loss. The document now reports the box xterm laid out whenever it changes (from onRender, which covers a renderer swap and a DPR change that onDimensionsChange does not fire for, and at ready). The store replaces the guess; when that changes the current text size's entry, the view calls onCellBoxChange with xterm's grid and the session re-fits, running the bounded fit pass if the dims moved (one resubscribe). Equal boxes do nothing. The RN layout box now survives a document reload; the document's own viewport only stands in until the view reports a layout (on the page, web-ready arrives first). The mismatch console.log is gone, and the probe's rounding names the xterm version it copies. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * fix(mobile): correct each cell-box guess at most once, so a DOM renderer cannot loop On the DOM renderer the cell width is the rounded canvas width divided by the column count, so every re-init at new cols reported a new box. Each one counted as a correction, a floor over floats could flip the fit between two sizes, and each flip landed converged, which reset the resubscribe budget: an unbounded series of full-snapshot resubscribes. Only the first laid-out box for a guessed text size may be a correction; later reports still update the store, so fits stay truthful, but never resubscribe on their own. The fit's floor gains a 1e-6 epsilon so floating-point error at an exact boundary cannot flip a column or row. New document tests pin the render report after a renderer swap and the report at ready for a paused renderer. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * refactor(mobile): make xterm the only terminal cell measurer The document builds its real terminal before web-ready, at the app's text scale, and reports the box xterm laid out; the first init reuses that terminal. The page-side prediction, the per-scale guess table and the once-per-document correction are gone. The app remembers the box per text scale for its lifetime, so a later open at a known scale subscribes with phone dims at once. A box that changes at the same grid (renderer swap, pixel ratio) refits the open terminal in place. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * fix(mobile): keep commands queued before the terminal WebView first loads A subscribe sized from the stored cell box can queue init before the native WebView reports its first load start, which cleared the queue and left the terminal blank. Only a reload now drops queued commands. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * fix(mobile): re-init a document that lacks the subscription's init, and fit one frame width - Web-ready now says whether the document holds the terminal's latest init (a reload before the first ready drops a queued one); the session resubscribes any initialized terminal whose document lacks it. - One grid fit, shared by the app and the document, fed the unrounded frame width React Native laid out; it keeps exact fits whole at fractional pixel ratios. The document's viewport-width fits are gone. - The page builds every document at the scale the view mounted with, as the native WebView does. - A new document's first cell box is compared against the grid the subscribe fitted from the stored box. - The terminal built before ready stays hidden until its first init. - The cell-box census matches glyph-measurement techniques, not names; the store's unused clear() is gone. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * fix(mobile): build the terminal before ready only for the view shown at mount A session mounts one terminal view per tab, and each built xterm and a WebGL context before ready: 20 tabs made 20 contexts at load, past the ~16 a page (or Android's shared WebView renderer) holds, and native logged 32 context losses. Only the view shown when it mounts builds early now; the rest build at their first init as before. Deferring the WebGL addon instead would change the reported box: the DOM renderer lays out 7.8x15 where WebGL lays out 7.667x15 at the same font. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * fix(mobile): write a WebView document's start values into its page, not an injected script Android ran the pre-content injected script after the document's own in 1 of 22 documents on the emulator; that document started with no text scale or shown flag and built a terminal it should not have. The values now sit in the page ahead of the document script, one source object per start pair so a render never reloads the WebView. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * test(mobile): the pre-ready terminal measures and reports while hidden Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * fix(mobile): measure only the laid-out frame, and refit on a new grid, not a new width - A measure needs both of the frame's dimensions from React Native; the document's viewport-height fallback is gone, and before the first layout the handle answers no fit without asking the document. - A frame width change that still fits the PTY's grid from the stored box is a no-op, so sub-pixel layout jitter no longer re-measures. The width ref is written in that effect rather than during render (react-doctor). - One "last grid" ref: the last reported grid, or the one a subscribe fitted from the stored box. - The page render rig measures through the frame it laid out, as the session does, and lets the replay's fit settle before its resize-refit witness. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * fix(mobile): let only the current terminal document's ready flush A reload kept the WebView and its onMessage, so the old document's late web-ready flushed the queue into the reloading view and the new document got a second init. Each document now gets its own view (keyed on a generation the controller owns), every notify carries the generation of the view that received it, and a web-ready from a replaced document flushes nothing and stamps nothing. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * fix(mobile): drop every notify from a replaced terminal document One rule at the receive boundary: a notify from any generation but the current one is dropped, whatever its type, not only web-ready. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * fix(mobile): make fitDimensions a pure question; name each generation counter - fitDimensions no longer records the grid. A width change to a new grid asked it first, so the DOM renderer's report of that grid's box read as "same grid, new box" and refit again. Only the first-subscribe seed (seedFitDimensions) records the grid the document's first report is checked against. - viewGeneration counts the views, readyGeneration counts web-readies. - replaceDocument no longer resets the load flag; the load-start reset stays as the guard for a view that reloads itself. - The name-based lifecycle census is replaced by a behavioural test. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * fix(mobile): typecheck the handle mocks, drop the unused cell-box get - The two handle mocks carry both fitDimensions and seedFitDimensions, and the fake-timer acts return nothing, so the three test files check under tsconfig.test.json again. - terminalCellBoxes.get had no product caller; the store's tests assert through fit. - The load-start comment says what the controller does now. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * fix(mobile): hold the grid the document has, ignore a replaced view's load start, dispose a failed pre-ready terminal - The document reports a new grid even with an unchanged box, so an in-place reflow on WebGL is held before a later renderer swap at that grid; the swap then refits. The app's apply paths do not hold the grid themselves: the DOM renderer's box follows cols, and a grid held on apply would read its own box as a renderer change and loop. One writer (holdGrid) holds the seeded or reported grid. - A load start from a view a replacement unmounted is ignored, as its notifies already are. - A terminal whose open throws before ready is disposed, not only unreferenced. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * fix(mobile): ignore every native event from a replaced terminal view One wrapper binds each WebView lifecycle event (load start, error, HTTP error, render process gone, content process terminated) to the view's generation, so a replaced view's late event cannot reset, replace or put an error over the current document. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * test(mobile): a DOM seed refits once on its first report, not on the refit's own Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * refactor(mobile): subscribe a terminal only after its document is ready The document still builds its terminal before ready and reports the cell box xterm laid out in web-ready; the app now subscribes after that ready and fits from that box, so nothing is sent to a document before it is ready. Everything that made a pre-ready subscribe safe goes: the app-lifetime box store, the seed fit, the per-document view generations and their event filtering, the init tracker and the hasInit resubscribe. The native view reloads in place again and web-ready keeps main's reload rule. Boxes are kept per view; the grid a document last reported still guards the in-place refit against the DOM renderer's cols-dependent box. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * refactor(mobile): hold one reported cell box and the grid the subscribe fitted The controller keeps only the box the current document last reported, not a per-text-size store: the document re-reports on a scale change. The subscribe after ready fits from that box and holds the grid it fitted, so the DOM renderer's first report at that grid (a new box) refits once in place and converges; refit and apply paths hold nothing. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * fix(mobile): fit only a ready box at the app's scale; forget a reloaded document's box and grid A reload keeps the document's mount scale, so a ready after a text-size change reports a box at the old scale; that box no longer sizes the first subscribe, which then takes the no-box path. A readiness reset drops the old document's box and held grid, so the new document's first DOM report at the same grid does not refit. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * fix(mobile): give the terminal document its frame at init, and fit text scale over it only A subscribe sized from the ready box sends no measure, so the document had no frame when the text size changed and reported the pre-refit row pitch. The app's init now carries the frame it laid out, in the fields a measure uses; the router takes it from either. The text-scale fit reads only that frame, with no viewport fallback. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * docs(mobile): say why a frameless text-scale change skips the resize Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * refactor(mobile): one cell box per terminal notify, not an array web-ready and cell-metrics carry `cellBox: {fontScale, cellWidth, cellHeight} | null`; the document's `laidOutCellBox` returns one or null and the parser validates one object. The text-scale match moves from web-ready into `handle.fitDimensions`, the one place a box is fitted. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * refactor(mobile): fit terminals in the app from the reported box; drop the measure round trip The app already holds the box the document reported, so the refit and the fit pass await the init's ready and call `handle.fitDimensions` instead of posting `measure` and waiting on `measure-result`. The document's measure, its retries, and the measure promise and timeout go. The document still resizes locally on a text-size change, so every grid the app sends (init, resize, reflow) carries the laid-out frame it was fitted to. `holdSubscribedGrid` replaces `subscribeFitDimensions`, so the only fits are `fitDimensionsFromCell` and `handle.fitDimensions`. The render rig reads its fit from the ready box. The recorder adapter mounts the new handle with the same recorded effects; the goldens it mounts move on their adapterSha256 header only. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * refactor(mobile): keep the terminal frame in one ref, and notify a new width imperatively The session held the frame in a height ref, a width ref, a width state and the refit's own width ref. It now holds one `terminalFrameRef` ({width, height} | null until the first layout; a hidden 0x0 layout keeps the last box). onLayout notifies a new width imperatively, as it does height, and the refit's notify skips a width whose fit is the grid the PTY has. `terminal-frame-width-refit.ts`, the width state and its effect go. The subscribe's layout gate reads "no frame yet" directly. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * refactor(mobile): subscribe a held-back terminal on the frame's first layout only `handleTerminalFrameLayout` ran on every onLayout; it now runs once, when the frame first has a size. Later layouts only notify a new width. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * refactor(mobile): size the first subscribe inline in subscribeToTerminal `sizeTerminalViewportFromCellBox` wrapped five lines in a 37-line module; the subscribe now fits the ready box against the frame, holds that grid and records the diagnostic itself. The helper's tests fold into the subscription tests, which move to the subscription's name. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * refactor(mobile): drop the unreachable font-size guard on the reported cell box xterm 6.1.0-beta.303 updates the render service's cell box in the same task that sets `options.fontSize`: CharSizeService.measure fires onCharSizeChange, and RenderService.handleCharSizeChanged runs the renderer's `_updateDimensions` (DomRenderer.ts:359, WebglRenderer.ts:229). `term.onRender` fires from RenderService._renderRows after the rows are drawn (RenderService.ts:213, CoreBrowserTerminal.ts:538), and the document writes its text scale and the font size in one task (text-scaling.ts applyTextScale, terminal-init.ts init). So no report can read a box between the font and the scale; the guard and its test go. A new test pins the real order: no report when the font is set, the new box at the new scale on the next render. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * refactor(mobile): one start seam, no source cache, the reported box as an object - `useState` already pins each view's WebView source at mount (a new test re-renders at another text scale and gets the same object), so the module-level `webViewSources` Map goes. - `initialTextScale` and `buildsTerminalBeforeReady` become one `start(): { textScale, shown }` seam. - `reportedCellBox` holds the last reported box and grid, not a string key. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * test(mobile): repin the RPC recordings to this branch and re-record The terminal refit now fits in the app from the reported box and reads one frame ref, so the recorder's terminal adapter mounts the new handle (`awaitReady` + `fitDimensions`) and options (`terminalFrameRef`), keeping its recorded effects. `baseline` is repinned to 21954dbd2f1, the last commit to touch a fenced path, and every golden is re-recorded. Proof by class against HEAD: 787 header-only, 0 body moved, 0 added, 0 deleted. Header keys moved: `baseline` on all 787, and `adapterSha256` on the 14 goldens `terminal-mount-adapters.ts` mounts (query-reply 3, accessory-raw-send 4, takeover-report 4, viewport-refit 3). No recorded traffic moved. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * refactor(mobile): hold the reported cell box and its grid in one ref The controller kept the box in `cellBoxRef`, the grid in a string `lastGridRef` and wrote it through `terminal-held-grid.ts`. One `heldRef` now holds `{ cellBox, grid }`, as the document's own `reportedCellBox` does: web-ready writes the box, every cell-metrics report writes both, `holdSubscribedGrid` writes the grid, and a readiness reset clears it. Same write points, so the one-refit bound holds; the DOM-loop and refit-once tests pass unchanged. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * test(mobile): repin the RPC recordings to the hold-rule commit and re-record H (f00bebba483) touched a fenced path after the last repin, so `baseline` moves to it and every golden is re-recorded. Against the corpus before this branch's refreshes (21954dbd2f1): 787 header-only, 0 body moved, 0 added, 0 deleted; `baseline` on all 787 and `adapterSha256` on the 14 goldens `terminal-mount-adapters.ts` mounts. Against the previous refresh: `baseline` only. No recorded traffic moved. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * test(mobile): repin the RPC recordings to the main merge and re-record The merge (b3b1b0def22) is the last commit to touch a fenced path, so `baseline` moves to it and every golden is re-recorded. Against 97b5bb2b9ac: 787 header-only, 0 body moved, 0 added, 0 deleted; `baseline` on all 787, and `adapterSha256` on the 14 session.diff-review-actions goldens whose adapter #22951 edited. Against origin/main: 787 header-only, 0 body moved/added/deleted; `baseline` on all 787 and `adapterSha256` on this branch's 14 terminal goldens. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * refactor(mobile): the terminal document holds the grid and decides each refit The document already kept the last reported box and grid; the app kept a mirror of both to decide the refit. Now the document decides: its `cell-box` notify carries `{ cellBox, refit }`, sent only when the box changes, with `refit` a box that changed at a kept grid. web-ready records the pre-ready terminal's box at its 80x24 grid, and the first init that reuses that terminal holds the init's grid, so the DOM renderer's first report refits once, as the subscribe's hold did. A re-init no longer clears the record, so a new renderer at the same grid still refits. The app keeps one `cellBoxRef` and `holdSubscribedGrid`, `heldRef` and the grid on the notify go. The one-refit, DOM-loop and renderer-swap tests move to the document with the same scenarios. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * refactor(mobile): one init options object, and a frame on every grid `init` takes `{ cols, rows, data, preserveScroll, oscLinks, frame }` instead of six positionals, and `init`, `resize` and `reflow` (handle and messages) require `frame: TerminalFrame | null`. The refit's reflow check reads `!dims` alone, and the controller's test file is named for the `cell-box` notify it now covers. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * refactor(mobile): one notifyTerminalFrame for the frame's layout The frame's onLayout made four calls and held the classification itself. It now calls `notifyTerminalFrame({ width, height })`, and the session's terminal-webview hook keeps the one frame ref, notifies the height, subscribes the document held back for the first layout, and notifies a later width change. `handleTerminalFrameLayout` is named for what it does: `subscribeIntendedActiveTerminal`. The layout tests move to that hook. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * test(mobile): repin the RPC recordings to the round-8 head and re-record 85d421963c6 is the last commit to touch a fenced path. Against a676c1b65a7: 787 header-only, 0 body moved/added/deleted, `baseline` only. Against origin/main: 787 header-only, 0 body moved/added/deleted; `baseline` on all 787 and `adapterSha256` on this branch's 14 terminal goldens. No recorded traffic moved. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * refactor(mobile): name the init option initialData, as the message does The init option `data` becomes `initialData`, the message field's name, so the controller passes it through unrenamed. The `preserveScroll` why stays on the message type only, and the document test's title names the three grids that carry the frame. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * test(mobile): repin the RPC recordings to the round-9 head and re-record 486566c82b4 is the last commit to touch a fenced path. Against 3371c397150: 787 header-only, 0 body moved/added/deleted, `baseline` only. Against origin/main: 787 header-only, 0 body moved/added/deleted; `baseline` on all 787 and `adapterSha256` on this branch's 14 terminal goldens. No recorded traffic moved. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * ci: rerun checks against main with #23560 landed Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * feat(ai-vault): show ZCode CLI session history (#23513) Surfaces ZCode CLI session history in AI Vault, so past ZCode sessions show up next to the other agents' instead of being invisible. ZCode stores sessions in the same SQLite shape OpenCode uses, so this reuses the existing OpenCode lister and parser rather than adding a second scanner — the worker only varies the agent it stamps on each row. Discovery covers the native home and any WSL homes. SQLite rows are narrowed at runtime rather than asserted: the statement API returns untyped column values, so the declared row shape is only a claim until something checks it, and a drifted schema or a database written by another tool reaches the same code. Co-authored-by: guanbear <guanbear@users.noreply.github.com> * test(mobile): repin the RPC recording corpus to main after #23080 (#23565) #23080 squash-merged a corpus pinned to its branch commit 486566c82b4, which the squash left unreachable from main. Repin baseline to main's tip and re-record; every golden moves only its baseline header. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * perf(ci): diff against the merge commit's first parent so PR checkouts can be shallow (#23562) Every changed-path gate asked git for `--merge-base "$BASE_SHA" "$HEAD_SHA"`, which needs the event payload's base SHA to be in the local graph. That is the only reason two jobs cloned all 8127 refs' history. On a pull_request checkout HEAD is already the merge commit, so its first parent is the base side and no merge base has to be computed. config/scripts/git-pull-request-diff-base.mjs resolved that for the two Node gates; the workflow's inline gates now use the same helper through a small CLI rather than open-coding it. code_paths gates all 22 jobs, so its checkout is charged to the start of every one of them: measured 20.7s to 1.6s, keeping blob:none because its sparse tree is ~7 files and leaves no blobs to refetch. Static analysis drops the filter instead, since populating all 30,226 files makes blob:none force a second promisor fetch: 23s to ~11s. Verified on a real merge ref. At depth 50 the old and new forms produce identical changed-file sets. At depth 2 the new form still works and the old one fails with `fatal: bad object`, which is the failure a stale base would have caused once the checkout stopped being complete. Also drops the dead resolveBase + merge-base prelude in the changed-code gate, whose result resolvePullRequestDiffBase already discarded on every PR. * feat(mobile): the keyboard covers the page like a native screen, and the shell says its height (#23110) The shell no longer shortens the WebView for the keyboard; it publishes the keyboard height like the safe-area insets, so native's keyboard lift, refit hold and dismiss key run on the page unchanged. Keyboard and inset arithmetic read the shell's OS through a host-os seam. One page-version floor (manifest pageVersion, shell floor 1) replaces per-feature accept negotiation; a page below the floor gets the existing update wall, a desktop with no bundle keeps native screens. iOS shell drops the form accessory bar and its own keyboard observers. Native session screens untouched. * fix(agent-session): wait for in-flight session-store writes before teardown returns (#23545) * fix(agent-session): stop lease renewal before the renewal's write lands Clearing the renewal interval only cancelled the next tick. A tick already past its guard still had a whole-file store transaction to commit, and the store's transaction lock re-creates the store directory before it writes, so that commit could land after host teardown had finished releasing everything it touches. `stop()` now resolves once the tick in flight has finished writing, and host teardown's stop-lease-renewal phase waits for it. The three test harnesses that model a host vanishing without a clean quit shared a copy of the same incomplete shutdown; they now share one helper that waits. The symptom was a CI flake: the refusal-oracle spec removes its temp directory in `afterEach`, and a renewal landing mid-removal put the store directory back, so the removal failed with ENOTEMPTY on the temp root. * fix(agent-session): wait for the delivery loop's restart when abandoning a host The abandon helper disposed the delivery loop and moved on. Disposing only stops the loop's NEXT step: a step already past that check keeps going, and the restart it runs for an accepted send reserves an owner, which is a store commit. The store re-creates its own directory before every commit, so that commit put the directory back under the temp-directory removal the test does next, and the removal failed with ENOTEMPTY. Quit already waits for exactly this work, in its drain-attaches phase — every attach is registered with the task queue from enqueue. The helper now runs the same drain, in quit's order, so it waits for both producers that reach the store after the last awaited call returns. Adds a regression test that holds the loop's restart inside its provider acquisition and asserts abandoning does not return until it lands. * chore: re-trigger PR checks The push to 2ecc9c6e emitted no pull_request event, so the matrix never ran. * fix(sidebar): clip worktree card content to its border (#23566) * fix(runtime): answer terminal.subscribe at once for a pane the desktop already has mounted (#23512) * fix(runtime): answer terminal.subscribe at once for a pane the desktop already has mounted A mobile subscribe to a PTY with no headless model asked the renderer to mount its tab and waited for a newer serializer settle. The renderer drops mount requests for tabs it already has mounted, so a reattached daemon PTY whose restored provider snapshot outranked the live renderer held the reply for the full 3 s deadline. A live renderer screen now proves attachment and is adopted directly; an unmounted pane still requests the mount and waits. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * fix(runtime): treat any renderer answer, even a blank screen, as an attached pane A fresh shell that has printed nothing has a registered serializer and an empty screen; requiring non-empty data sent it back through the dropped mount request and the 3 s wait. A blank screen skips the wait but does not replace the chosen snapshot, so a parked pane cannot erase provider history. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * fix(runtime): treat a mounted pane with unsettled output as attached The stable renderer snapshot returned null both when no renderer answered and when output advanced under every retry, so a desktop pane printing continuously still took the dropped mount request and the 3 s wait. It now returns a typed outcome (settled, moving, absent); moving skips the mount and publishes the chosen snapshot, and late recovery still requires settled. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * fix(runtime): adopt only a renderer-ordered screen when probing a mounted pane The attachment probe read the terminal before knowing it would adopt, which can reach the provider snapshot on the unmounted path; the read now follows the decision. A seq-less renderer screen would replay every buffered chunk on top of itself, so the probe keeps the chosen snapshot for it. The probe, adopt and mount wait move into their own module to stay under the line cap. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * fix(runtime): adopt a seq-less renderer screen when no output is pending The seq gate only prevents a double replay of buffered output, so a settled non-blank screen without a seq is safe when nothing is pending. That keeps the better screen for a pane right after a deferred cold restore, before it is renderer-ordered. The rule now applies after the mount wait as well. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * refactor(runtime): decide renderer attachment from the host's serializer flag The mounted-pane probe re-derived attachment by serializing the renderer up to six times, which cost ~7.5 s for a registered but unresponsive renderer on a busy PTY. The host already holds that fact in the serializer readiness flag. The flag is never cleared when a pane closes over a live PTY, so one null serializer answer falls back to the mount wait: worst case is the old 3 s plus one 750 ms serialize. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * refactor(runtime): let the serializer's answer alone prove renderer attachment serializeRendererTerminalBuffer already answers null when the host's serializer flag is unset, so the separate flag accessor was redundant. The numeric-seq adopt test now replays only the byte past the seam. Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb * Revert "perf(ci): shard the anti-slop audit across processes instead of one JS runtime (#23543)" (#23575) This reverts commit fae0ae7a464c2991bd25885e7e61689c7f471a0f. * perf(ci): cache pnpm verification records on Linux (#23568) * perf(ci): pilot pnpm verification record caching on Linux * test(ci): review pnpm verification record in mobile cache audit * fix(native-chat): the host writes chat failures for a person, with a typed fact beside them (#23116) * refactor(native-chat): remove the unused terminal handoff No client ever called agentSession.requestHandoff or mounted the handoff chrome. Delete the handoff coordinator, the terminal-owner runtime, the proof write path and the unmounted UI. Keep agentSession.handoffStatus, which released desktop clients read for worktree activation, and let records an older build left mid handoff reconcile through the ordinary restart and recovery paths. * fix(native-chat): never let the pre-stop snapshot hold a chat's stop Eviction now drains delivered events before quit's resume-offer snapshot. An unbounded wait there sits ahead of the provider stop, so a sink whose journal write stalls kept the child running until the step deadline aborted the eviction. The offer is advisory: bound the drain and stop the child regardless. Co-Authored-By: Claude <noreply@anthropic.com> * refactor(native-chat): drop helpers only the terminal handoff called `claudeAuthEnvCarriedForward`, `isPathWithinDirectory` and `queryWindowsProcessRowsFresh` lost their last caller with the handoff. The fresh-scan tests now go through `queryWindowsProcessDescendants({ fresh: true })`, the teardown path that still depends on that contract. Co-Authored-By: Claude <noreply@anthropic.com> * docs(native-chat): stop citing the removed handoff in lifecycle comments Six comments still named the handoff coordinator, a handoff suspend, or a terminal-owned session as live participants in the flows they describe. Co-Authored-By: Claude <noreply@anthropic.com> * test(native-chat): type the stalled snapshot drain without a cast Co-Authored-By: Claude <noreply@anthropic.com> * test(native-chat): pin that a start dead before proving owes no settlement The removed restart handoff test pinned this branch; nothing else did. Co-Authored-By: Claude <noreply@anthropic.com> * fix(native-chat): keep the owner-status read behind an in-flight attach The handoff removal dropped the per-session queue from `handoffStatus`, so a read landing mid-start reported the reservation (no owner) instead of the settled chat owner, and shipped desktop clients blocked worktree activation on it. The read is queued again, as it was before the removal. Co-Authored-By: Claude <noreply@anthropic.com> * refactor(terminal): remove the agent-session PTY write gate The gate only refused a write when a PTY had been bound to a chat session, and the only code that ever bound one was the terminal handoff this branch removes. With it gone, every admit/readmit returned "admitted" unconditionally, so the checks on the renderer write path, the runtime controller backstop, terminal.send, agent prompts, preview input and orchestration pointers, the refusal fields on terminal.send and worker-start receipts, the plugin and CLI refusal copy, and the adopted-pane orchestration routing could no longer run. Ordinary writes take the same path in the same order as before. Co-Authored-By: Claude <noreply@anthropic.com> * refactor(native-chat): drop the transcript helpers only the handoff called appendLegacyTranscriptMessages fed the terminal transcript catch-up and proveClaudeTranscriptBranch backed the terminal owner's exit proof. Both lost their last caller with the handoff. Their tests now go through the live entry points instead: the roster bounds through the legacy import, the pinned-read and growth tests through the ancestry replay the history window uses, and the marker rules through the string proof in their own file rather than the session-file resolver's. Co-Authored-By: Claude <noreply@anthropic.com> * fix(native-chat): stop calling a starting chat "mid-handoff" A send refused because the chat's owner is not settled showed "The session is mid-handoff (<stage>)." in the composer. With the handoff gone, the stages that reach it are a chat that is still starting, or one whose previous agent process has not yet been confirmed stopped. The message now says which of the two it is. The refusal code is unchanged. Co-Authored-By: Claude <noreply@anthropic.com> * test(native-chat): type the stand-in roster decoder without a cast Co-Authored-By: Claude <noreply@anthropic.com> * refactor(codex): name the pinned rollout lookup for what it does With the terminal handoff gone, the module named codex-tui-rollout-proof holds only the pinned rollout lookup that structured Codex launches use to resume a thread, so the name described code that no longer exists. Rename the module and its options type. Also drop a mobile allowlist assertion that pinned the removed agentSession.requestHandoff method, which no longer exists to allow. * refactor(native-chat): type the owner-status reply as the host sends it The handoffStatus reply type still listed the terminal handoff's fields and states (terminal placement, host label, proof retry, queued and waiting phases, the to-terminal direction). No host writes them any more and the only client reader parses the reply as unknown, so they described nothing. The reply on the wire is unchanged. * refactor(native-chat): normalize terminal-handoff lease values once at decode Nothing in this build writes a terminal owner (`runtimeKind: 'tui'`) or the handoff's `preparing` / `old-owner-stopped` stages, but the in-memory types still admitted them, so readers across the host kept branches for values no path produces and the compiler could not point at them. The store now validates the on-disk shape, which still accepts those values so an older record is not quarantined, and maps them once while parsing: - `preparing` and `old-owner-stopped` become `recovering` - a `tui` lease becomes `native`; when it records a process it also becomes `conflicted`, the claim every build probes but never stops. A plain native owner would be stopped by restart recovery, here and in older builds. Revisions are taken over the normalized state on both sides of every compare, and the mapped record reaches disk with the store's first transaction, the same way the tab-id backfill does. The in-memory types narrow to what this build writes, and the branches that existed only for the removed values go. Structured-worker identity keeps its verdict for a former terminal owner by refusing a conflicted claim rather than a non-native kind. * refactor(native-chat): stop threading the owner kind through a reservation A reservation only ever names a native owner now, so the request no longer carries a kind and the reserved lease records `native` directly. The attach params keep `runtimeKind`: agentSession.ensure and create accept it, and the operation fingerprint stored in the ledger covers it. * test(native-chat): pin the legacy-lease rewrite with a transaction that changes nothing else Hiding a tab also committed the visibility index, so the no-op transaction wrote the file even when its open-time revision was wrong. Committing the index first leaves the pending rewrite as the only reason to write. * fix(native-chat): name a chat write by its target, not the owner generation A write carried the fence of the last frame the pane read, and the host refused it unless that fence was still current. An idle release and the restart after it each move the fence, and the release publishes nothing, so a send after a release was refused "Expected runtime fence 1; the session is at 3", and a Stop queued behind a cold start was refused as stale. Every write already names what it acts on: a send its conversation, a cancel its turn, a prompt answer its item revision, a rewind its epoch; an option is last-writer-wins. So admission stops comparing the client's fence, and the rebase that papered over one restart (admitAtResumedFence, resumedFromFence) goes with it. The writer-lease check stays, and so does the attach's compare-and-swap. Frames now stamp the fence read when each frame is sent instead of a copy each subscriber kept, which went stale on the same release. * fix(native-chat): every journal append reaches the chats that are open A journal write and its delivery to open readers were two calls, and some writers made only the first. A failed start whose lease could not be handed back, a provider revision with no frame behind it, and eviction's settlement were all journaled without reaching an open chat. A journal handle now reports every durable change, and the host's session map binds that report to the session's readers when the handle is set. Writers no longer publish what they append; the per-writer publish calls are deleted. * test(native-chat): an epoch replacement reaches the open chat * test(native-chat): each row reaches an open chat once, and a live handle enters only through the map * test(native-chat): give the legacy-lease store test a tab id so the backfill cannot supply its rewrite The seeded record had no surface tab id, so the next open backfilled one and that rewrite alone made the no-op transaction write. The test passed with the legacy-lease rewrite signal removed. * test(worktree-activation): restore the OMP surfaced-agent resume test The handoff removal deleted it alongside the terminal-owner tests, but it covers the surfaced-PTY block that still guards resume, including an agent whose ownership is unknown. * perf(native-chat): a publish behind a delivered commit reads nothing Each commit now delivers itself, so the publish a provider frame still sends afterwards found every reader caught up but still read rows and rebuilt the timeline for each one. A caught-up reader now skips the read. * test(native-chat): state why the teardown test's fake journal is safe to cast * docs(native-chat): say mutation admission checks only the writer lease * docs(native-chat): drop the send rebase from comments that still described it * fix(native-chat): a message is accepted, then delivered A send to a chat with no running agent restarted the agent inside the send call, before the message was recorded, so the client waited for the whole start and a failed restart refused the message. Claude held prompts sent during startup, and those could settle as "unconfirmed". A send is now accepted inside the session's serialized queue: one ledger row and one submission row marked handoverRecorded, published, answered pending. A per-session delivery loop exists while a message is queued. It starts the agent through the same serialized attach a hold uses, waits outside the queue for a Claude child to prove its start, and hands the oldest queued message over as its own serialized step, writing dispatch{pending} before the adapter call. A start it needed and did not get writes one error-tone row and rejects every queued message with the same words; a start Stop cancelled writes none. Settlement follows from the rows. A queued message is provably unwritten, so a close, an eviction or an exit rejects it. A handed-over message stays in doubt. A queued row at or below the sequence a handle found when it opened was left by an earlier process and is rejected at open, with no latch. Stop withdraws queued messages with no writer lease and no fence. An attach failure keeps the conversation open, and the attach adopts its journal. Owed work counts the loop and queued rows. A compaction or rewind found prepared when a conversation opens was started under a child this process no longer has, so the open settles it rather than leaving it to refuse every send until a view attaches. The open cursor is scoped to its epoch, because sequences restart when an epoch is replaced. Deleted: restart-before-admission, recordFailedRestart, the fence rebase, Claude's startup gate, the attach's forget on failure and its own crash boundary. Clients without agent-session.accepted-send.v1 get their reply held until the handover; the desktop and paired desktop lists advertise it. * fix(native-chat): settle queued messages only for the child that ended A child that proved its start and then exited before its message was handed over left the message queued: the exit settlement returned early when nothing else was in flight. Delivery then started another child for it, and a child that died the same way started another, without end and without a row. A retried settlement for an earlier generation, run by the attach that delivery started, did the opposite: with that generation's turn unfinished it rejected the message queued for the child being attached. The settlement now takes the rejection for queued messages from its caller. The unexpected exit and the eviction pass one, and it applies even with no other work in flight; the retry for an earlier generation passes none. * fix(native-chat): an adoption that fails to import keeps the conversation open The attach now writes into the conversation's own open journal, but a failed transcript import still closed it as if it were the attach's provisional one. The conversation stayed indexed with a closed journal, so every later send answered "could not be recorded" and every attach failed again until the app restarted. The import now closes only a journal the attach opened for itself. * perf(native-chat): the recovering open reads the journal once Every conversation open now goes through the recovering open, including the read restore of every chat at startup, which used to replay its journal once. The recovering open replayed it twice: once to probe it and again inside the open. The probe is now handed to the open as its load. * fix(native-chat): an attach that fails after indexing its child leaves no child behind A failed attach now keeps the conversation open, but a failure after `onAttached` indexed the child (the rewind or compaction recovery, or the attach's own success record) left that entry claiming a child the failure path had already released. The next send found the phantom, skipped the start, and wrote at a fence the journal had moved past, so the message stayed queued for good. The entry now drops the released child and its event sink, and follows the record's fence, as a failure before indexing already did. * fix(native-chat): a withdrawn message shows no error, and a rejection outlasts the send's answer The error strip for a message the host accepted and then did not deliver matched the entry before the outbox reconciled, so a Stop's withdrawal, which the reconcile drops, showed "Orca could not send your message" with nothing to retry. It now reads the reconciled entry. A rejection the journal records before the send's own pending answer lands is final as well: that answer no longer puts the entry back to dispatching with no Retry. * fix(orchestration): a structured worker whose agent outlasts the preamble wait is left unknown, not torn down The preamble waits for its submission to be delivered while the worker's agent starts. When that wait ran out it threw operation_unknown, and the failed-start teardown then closed the session, which rejected the very preamble the host was about to deliver. It now reports a turn start nobody observed yet: the worker is start-unknown with its session kept, the host delivers the preamble when the agent starts, and the worker's report settles the dispatch as for any unobserved start. The receipt no longer suggests reading a screen a structured worker lacks. * fix(native-chat): a message rejected while its chat was closed reads as not sent A remount reads an entry it left dispatching as unconfirmed. When the journal had rejected it meanwhile, as a failed start or a quit now does, the reconcile left it unconfirmed: it blocked every later message behind a Retry and no reason, and the delivery probe, seeing the journal already answered, never ran. The reconcile now settles it as rejected like a dispatching one. * test(orchestration): name why the readiness settlement fakes are cast * fix(native-chat): keep each pane's own fence on frames so a failed restart is not resent * docs(native-chat): drop the fence from the admission the send effects run behind * docs(native-chat): give the fence move on release the reason that still holds * docs(native-chat): stop citing a write fence check in launch and mailbox comments Three places still gave the removed fence check as a reason: the launch replay said admission puts the ledger ahead of the fence, the launch surface said a send must name the lease it was admitted against, and the direct-mailbox path said the lease fence decides whether delivery is safe. Admission now checks only the writer lease. * refactor(native-chat): the provider child is its own record A conversation now outlives any number of provider children, so the child is one record on the conversation's entry instead of five loose fields beside its journal. It is written in one place: indexed only once an attach has fully succeeded, and ended through one function that an exit, a failed re-attach, a Stop and an eviction all share, matched on the child's generation and fence. - A failed attach writes no child, so there is nothing to unwind: the field unwind and the fence patch after it are gone. - Conversation writes read the record's fence, the way mutation admission already does; a child's own writes use its fence. The four stored-fence patches, and the settlement retry's overwrite of the conversation's fence, are gone. - The owed wind-down is its own tombstone, carrying the child it is owed for, and is no longer dropped when an attach replaced the whole entry. - Stop on a child still proving its start stops only the child: its lease goes back and the chat is told it is idle, but the journal, the holders and the readers stay. Close is that stop plus the conversation's close. - The settlement retry uses the conversation's own journal, opened through the host's one open. * fix(native-chat): the delivery loop alone settles a message its start or child failed A queued message was settled by whichever path happened to end the child first: the loop, the unexpected exit, eviction's work settlement, the open's leftover rule, and the startup branch that rejected every pending row. That gave two failure rows with different tones for one start, a loop that could hand over to a different child than the one it waited on, and a Claude start that died while starting reading unlike every other failed start. - The loop remembers the child it waited on. At handover, if that child is gone or replaced, it reads how it ended: a Stop continues; anything else writes one failure row and rejects every queued message with the same words, then stops. A child still starting whose start the adapter says did not land fails the same way. The exit, eviction and the settlement retry only settle the handed-over and legacy rows of the child that ended. - One failure row, always an error, keyed by the start. A start a view began that dies with nothing queued writes the same row through the same builder, so a second report revises it. - The open no longer rejects leftovers; the loop's first step does, and the open wakes it. - `awaitStarted` answers why a start did not land, so the row says it even when the loop sees the failure before the exit is processed. - Quit closes every conversation the way closing a chat does: what is still queued is rejected as closed, with or without a child, and a start the loop already has in flight is waited for so the child it produces is stopped rather than left behind. * refactor(native-chat): a stopped child ends on the one reading of its stop The eviction step reads a stop's result through `stopAgentSessionProviderRoot` and hands that verdict to the child's ending, so the host never forms a second view of whether the root is gone. Every ending carries it: a stop's comes from that reading, an exit's root is gone by definition, and a failed re-attach passes what its release saw. The end-of-child record can therefore also carry a stop whose root was not seen to go, which nothing ends on yet. * feat(native-chat): the host says it accepts a send before any agent has it The host now lists agent-session.accepted-send.v1 among its own runtime capabilities, the same string capable clients already send. A client can then tell a host that answers a send at acceptance, and admits a Stop with no writer before a turn starts, from an older one that still restarts the agent inside the send. Additive: an older client ignores a capability it does not know. * refactor(native-chat): an attach never opens a journal of its own The attach adopts the conversation's open journal, which outlives it, so it no longer opens one for a direct caller either. That leaves nothing for a failed adopted import to close, and the flag that told the two cases apart is gone. Tests that attach without a host open the conversation the way a host does. * fix(native-chat): a moved fence resends nothing on a host that accepts first The outbox treated any fence change as a new owner: it dropped the answer of a send in flight, queued that send to go out again under the same id, and unblocked a refused head. On an older host that is how a send the restart refused, unrecorded, gets another try. On a host that records every send before it starts an agent, a fence moves because that start ran, so the same rule resent into every failed start. With a fence stamped on every frame, that became a loop. The outbox now reacts to a fence change only when the host has not advertised that it accepts a send before any agent has it. On such a host, only a Retry or a new send goes out, and a failed start reaches the client as a rejected message it keeps with its Retry. Against an older host, or before one has answered, the outbox behaves as it did. Desktop and paired web share this hook. * refactor(native-chat): a child's end says whether the user or the host stopped it The end-of-child record's cause now tells a user's Stop from the host stopping the child for a cause of its own: `user-stop` and `host-stop` replace `stop`. The delivery loop goes on after a user's Stop, as before, and fails the start it was waiting on after a host stop, with the one error row and every queued message rejected, in the stop's reason when it gave one. The reason stays description only. Stop passes `user-stop`; nothing passes `host-stop` yet. * fix(native-chat): a chat whose only work is a queued message is not offered for resume A message accepted while the agent was starting counts as working in the chat, and quit rejects it as never sent. The teardown snapshot read the same working rule, so a relaunch offered to resume a chat whose agent never had the message. The snapshot now reads only what was handed over. * test(native-chat): type the queued-message fixtures in the resume-offer tests * fix(native-chat): a start that dies while a message waits on it is that message's failed start Opening a chat's tab starts an agent for the view, and a send accepted meanwhile waits on it. When that start died, its exit wrote the start's error row and left the message queued, so the delivery loop started a second agent into the same failure and wrote a second row. A child's end now records where the conversation's journal stood, and the loop settles a message accepted before a failed start ended with that start: one row, under its key, and no second start. A message sent after the failure still gets a fresh start. * docs(native-chat): say what an attach's open conversation and unconfirmed ids are now * test(native-chat): pin what a failed start settles, and what a resume offer names A view's child that dies while a sent message waits settles that message only when it died starting and no child has taken its place: a proven child's crash, or a second start since, gets the message delivered. The resume offer names the handed-over message, never a newer one still queued. * test(native-chat): the failed-start pins fail on what the message became, not on a timeout * test(orchestration): the preamble's host stub is typed, not cast The preamble send now takes only what it reads of the host, the send, the settlement wait and the record's fence, so its test builds that host with real types instead of `as never`. * feat(native-chat): a typed failure fact beside every failure sentence Adds the shared vocabulary the host writes a failure with: a closed failure kind, a provider diagnostic that says who it is for (a person, or a log), and a refusal cause beside the refusal code. Status rows gain an optional failure fact and rejected submissions an optional rejection fact; the dispatch row carries it, the reducer reads it field by field, and the projection forwards it. Older rows and older readers are untouched: every field is optional and the schemas stay open. * fix(native-chat): durable failure rows and rejection reasons are written for a person Every host writer that records a failure now writes a sentence for a person beside a typed fact, instead of embedding a refusal's message, an exception or a composed exit string. A provider's own words travel as a separate diagnostic from the places Orca composes them - the Claude and Codex exit stderr (a log), Codex's JSON-RPC message, Claude's compact_error and Codex's turn error (for a person) - and are never inferred from a string afterwards. Not signed in and oversized history are typed at the adapter that detects them. Covers start and restart failures, the delivery loop, dispatch rejections (content, queue-full, write failures, provider refusals), cancel and answer confirmation rows, compaction, the rewind fallback, and not_delivered, which released clients printed as it was. Two leaks close on the way: a settlement retry no longer writes Orca's probe evidence into the exit row, and an attach or journal-sink failure is recorded as Orca's fault rather than as the provider stopping. The legacy rejection markers and the reasons on sends in doubt stay byte-identical. * feat(native-chat): refusals name their cause, and a failed start is worded in one place A refusal now carries an optional cause beside its code: one closed enum of the situations a chat write can meet, set at every emitter a structured-chat write reaches. Returned refusals build it with refuse(code, cause, message). Store and host paths that raised a bare Error(code) now throw AgentSessionRefusalError, whose message is still the code and which has no code property; the RPC error mapper handles it before any other passthrough, keeps today's wire code and message byte-identical, and adds { refusal: { code, cause } } to the error's data. The hold throws it, and restart-resume files the cause beside the unchanged reason. The operation ledger stores the cause beside the code, so a replay names the same situation as the first answer. The sto…

ELI5
When Codex asks several questions at once, the chat showed them in a scrambled order. Now every structured chat row sits where the chat's own record put it, so the questions read in the order Codex asked them.
What Changed
Before: in a structured Codex chat, answering the first of three questions moved the "Awaiting user input: 2 questions" row above the answered first question. Once all three were answered they read newest first, and a cancelled ask came out in yet another order.
After: the answered, cancelled and still-waiting rows of one ask always read in the order Codex asked them, at the ask's place in the transcript.
Mechanism: a structured chat is backed by a journal on the host. Each journal write gets a sequence number, and the journal's contract is that the sequence orders the timeline; the timestamp is the provider's clock and can run backwards. The desktop list ignored that and sorted rows by timestamp, breaking ties by row id. Codex writes every question of one ask in a single write, so they shared a timestamp and were ordered alphabetically by the question ids the model made up (for example
scope,priority,deadline).Rows projected from the journal now carry their journal position: the sequence of the write that created the item, then the item's place within that write. The host records that place when it folds a batch, keeps it when a later write revises the item (as it already did for the sequence), and sends it with each item as a new optional field. The desktop list and the host's conversation outline sort journal rows by that position and nothing else.
Rows that are not in the journal keep their existing rules. The streaming preview and the pending/launch rows are still separated by rank. A send still waiting in the outbox sorts after every journal row, since it was made after everything the journal holds, and sends among themselves sort by time. A send the host journalled and then refused is still drawn from the outbox (it waits there for Retry), but it keeps the place the journal recorded for it, so it does not drop below what the agent wrote afterwards; its Retry bar stays next to the composer as before. That covers a send whose agent could not be started: the host records the message first and only then starts the agent, so the "could not restart" line is written after the message and is drawn below it. Terminal-backed chats have no journal, so they keep exactly the old time-then-id order.
Why
Ordering by time was the bug class, not only the tie-break. Besides same-write ties, a row the host journals while recovering from a crash carries the provider's earlier clock at a later sequence, so the time sort drew it above rows that were written before it. The host's own snapshot already orders by sequence and has a test for that case; only the client re-sorted by time. Ordering by position removes both cases for every row kind (questions, approvals, messages, tool rows) instead of patching the tie-break.
The place within a write is recorded explicitly rather than read from array order. Keeping the order the rows arrived in happens to give the right answer today, but only because every step between the journal and the list preserves array order; the client's reducer, paging and batch merge now sort by the same explicit position, so no step can reorder it.
An outbox send sorts after journal rows instead of by its local timestamp. It has not reached the journal, so when it is sent it will land after everything the journal holds; drawing it there now means it does not jump when it lands, and a composer clock that trails the host's (for example on an SSH host) can no longer draw an unsent message above the agent's newer rows. Comparing an unsent message to journal rows by time instead would mix two orders that can disagree, so the list would have no single consistent order. When a send needs Orca to restart the agent and the restart fails, the order is: the message, then the "could not restart" line, then the Retry bar by the composer. The host records the message before it tries the restart, so the failure is always written after the message.
The alternative was to show one row per Codex ask, listing its questions with their answers. That also fixes the order for questions, but only because one ask would no longer produce several rows, and it leaves time-based ordering in place for everything else. It is a presentation change worth considering on its own.
Not changed here: the "Awaiting user input" list still folds after each answer, because the waiting group is keyed by its first unanswered question, which changes when that question is answered.
Linked Issue
None. Found during live QA of #23451.
Visual Proof
Checked live against real Codex (0.157) in a background dev build on a Mac with an isolated profile. A default structured Codex chat cannot ask questions (Codex offers its question tool only in Plan mode), so each run started Codex with its own
default_mode_request_user_inputfeature on, through a wrapper for that run only. In both runs, Codex listed its three questions in an order that differs from the alphabetical order of their ids, so an id sort shows up.Before (main): answered questions came out newest first (Q3, Q2, Q1), and after answering Q1 the waiting row sat above it:

After: answering Q1 leaves it above the waiting row for Q2 and Q3:

After: all three answered read Q1, Q2, Q3, and stay that way after a reload:

After: a cancelled ask reads Q1, Q2, Q3 (checked twice, and after reloads):

A follow-up sent while Codex is still working appears once and never moves (sampled every 150 ms), both while pending and after Codex accepts it:

After screenshots are from head
2d676c7ce3.Testing
src/main/codex/codex-structured-question-order.test.tsdrives a real Codex three-question ask through the real host journal, the answer and cancel paths, the client session reducer and the transcript projection. It reproduces all three live orders on main (waiting group above the answered question; answered rows newest first; cancelled rows second, first, third) and passes with the fix.New
structured-agent-session-transcript-order.test.ts: a row recovered after a crash, with an earlier timestamp than the rows journalled before it, sorts by sequence in both the desktop list and the host outline; the three answered questions of one write sort by their place in it even when handed over shuffled and with ids that sort differently; an outbox send sorts after journal rows even when its timestamp is older; a send the provider refused stays at its journal place above the agent's later reply, while a newer unsent message still sorts last.Restart failure order, through the real host, journal and chat projection: a start the host could not make (
structured-agent-session-accept-then-deliver.test.ts, "draws the messages it failed above the error row, since they were accepted first") and a restarted agent that exits before it finishes starting (structured-agent-session-send-restarts-failed-start.test.ts) both draw the accepted message above the failure line. With the refused send's journal place removed, both fail with the failure line drawn above the message.Worker transcript bounds: a structured worker's journal rows come back from
worker-readand the saved worker archive without the list position.Host reducer: a batch's items record their place in the write, and a later revision keeps it. Client reducer: a history page and a live batch with one write's items shuffled come out in position order.
The outline parity test's recovered row now sits where it was journalled (it previously asserted the time order).
Ablation, one change reverted at a time with the tests kept: time-based list sort (end-to-end and new transcript tests fail), place-in-write not recorded or not kept on revision (host reducer test fails), client reducer sorting by sequence only (client reducer test fails), outbox rows sorted by time (outbox test fails), a refused send without its journal place (refused-send test fails), worker reads keeping the position (worker bound test fails). Keeping arrival order for rows that share a timestamp, this PR's earlier approach, still passes the end-to-end test but fails the recovered-row and shuffled-write tests. Each passes again when restored.
On the branch merged with current main: native-chat renderer,
src/shared, native-chat main (journal and agent-session wire), Codex and worker transcript suites pass, plus mobile session tests and mobile typecheck,pnpm tc,check:code-quality:changed,check:react-doctor:changedandoxlinton the touched files.config/tsconfig.node.jsonlists the two renderer question-projection files the main-side end-to-end test imports.I manually tested these changes locally
Automated tests added/updated, or explained why not below
AI Disclosure
Review
Agent skill upstream boundary
docs/reference/agent-skill-sharing-upstream-boundary.mdand copies or mechanically translates no upstream skill-installer source, tests, fixtures, registry entries, path tables, comments, or documentation.Notes
Wire: the host adds one optional field to each journal item (its place within the write, omitted when zero). Older clients ignore it and keep sorting by time. A newer client paired with an older host reads the field as absent, so rows of one write tie on position and keep the order the host sent them, which is journal order; it still fixes the crash-recovery case, since the sequence is already on the wire. The position on a transcript row is set by the structured projection. The desktop and mobile lists and the host outline use it; the structured worker read and the saved worker archive run the same projection, so the worker transcript bound drops it and neither returns nor stores it. Terminal-backed chat messages never carry it. Nothing persisted changes: the place in a write is re-derived from the stored batch on every replay.
The host's conversation outline (the message rail's list of older user messages) now orders by journal position too. An older client showing a newer host's outline gets the journal order for the not-yet-loaded part while its loaded rows still sort by time, so the two could disagree only for a crash-recovered user message; the loaded rows replace the outline entries as they load. Mobile draws journal items in the order the shared client reducer keeps them, which now uses the same position, and does not re-sort by time; it already drew one row per question in journal order, so it looks the same. No platform-specific code.
Checklist
N/Awith reasonpnpm lint,pnpm typecheck,pnpm test, andpnpm buildpass (or CI will cover; local preferred)