Repository navigation
fix(native-chat): show a message Orca accepted and then failed to deliver as "Not sent" in the chat - #24710
Conversation
…he desktop chat as not sent Draw it in place from the host's history, so a crash that loses the outbox no longer makes it vanish. A later copy of the same body supersedes it; the outbox row wins while it holds the message; the phone is unchanged.
…en rejected Once the host's journal records a send as rejected, the desktop outbox lets it go, as it already does for delivered and Stop-withdrawn sends: the host's row shows it as not sent, with the host's reason and no Retry. The outbox keeps only sends the host refused before recording them, which keep their Retry. A send whose own reply says it was rejected is drawn by its outbox entry, with no Retry, until the journal carries the row; a copy left by an earlier session is dropped when the chat opens. - the transcript no longer hides a host row behind an outbox entry with the same id or the same text; those rules and their cache are gone - a rejected message the queue holds (a draft's hand-off, or a live card under its id) is drawn as its card, not as a row - a later copy of the same text hides a rejected row only when it was sent once the rejection was known, so a deliberate repeat stays - delivery notices read the same visibility rule as the transcript; a chat whose only rejection a Stop withdrew no longer rebuilds them per batch - the body fingerprint helper goes back to the host, its only user
…-message-shows-in-chat
…age go - the outbox no longer drops a host-rejected message when a chat opens; the reconcile lets it go once the journal's submissions say it was rejected, and that drop is written to storage, so nothing reads as still owed - a message the host rejected while the chat watched waits for its journal row with no Retry; one read back from storage with no row loaded keeps its Retry under a new id, since the host may have lost it - the delivery notices keep the same map and notice objects across a batch that words every row the same, so a submission batch re-renders no row - a rejected command such as /compact stays hidden: its own reply reports it - the desktop transcript requires the queued card ids, with a controller-level test that a card holding a rejected message keeps its row hidden
A message accepted to hand over later and rejected before any handover now sits at its rejection, as a handover places one: what the agent did while it waited happened before it, and the newest history page holds it. One handed over, or dispatched as it was recorded, keeps its place. An older host does not move it, so it stays at its submission, still drawn. A failed start now rejects the queued messages and writes its row in ONE journal append, the messages first: no reader ever meets one without the other, and the messages still draw above the row that says why.
Not only a queued message: one handed over into a turn and then rejected, or sent directly and rejected, also sits at its rejection, in no turn. A message in doubt stays where it was, a plain bubble: it may have reached the agent.
…tored fact - a message the host recorded and then rejected has no Retry on any mount, however that mount learned of it, and a Dismiss that clears it from storage; a send refused before the host recorded it keeps its Retry - the rule that keeps a rejected command such as /compact out of the transcript moves into the one visibility function rows and notices share - the outbox state docs say what lets a recorded message go: the client holding its rejected submission, whose row the host places at the rejection
…ry queued message first
…-message-shows-in-chat
… loads An older host leaves a rejected message where it was sent, which may be older than the loaded window: the chat then holds the rejected submission but not the row that draws it. The outbox copy now stays until that row loads, marked as the host recorded it (Dismiss, no Retry, in the host's words), and leaves once the page holding the row is loaded. Derived from the loaded rows each time. Tests that label their projection as the phone's now pass the phone's own setting.
…in the outbox The outbox re-reads the journal on every batch since it waits for a rejected message's row to load. Its reconcile now returns each unchanged entry, and the list, as themselves (a message left in doubt included), so a batch that changes nothing writes nothing to storage. The reconcile moves to its own module. A copy the host recorded and rejected owes no delivery, so it no longer keeps a hidden pane reading the journal.
…-message-shows-in-chat
Review statusThe problem. In the desktop chat, a message you sent could vanish. Orca had accepted it, then failed to deliver it: Orca restarted, the chat closed, the agent failed to start, or a message sent into a running turn was never picked up. The chat only showed such a message while a copy saved in browser storage still had it, and a crash often loses that copy. So after a crash the message was simply gone. Without a crash it showed "Not sent" with a Retry button, so the same failure looked different depending on luck. What changes for you (desktop).
What the review changed (the PR now differs substantially from the first version):
Deferred (each is listed under "Differences from the common pattern" in the PR description):
Verified.
Not verified.
|
… on its own, with no Dismiss The outbox copy of a message the host recorded and then rejected draws it only while the host's row is not loaded, and leaves on the batch or page that loads that row. It owes no delivery and offers no control: sending it again is a new message. The Dismiss that let the user clear it is gone, from the outbox, the notices and the session controller.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 🧰 Additional context used📚 Code guidelines (1)No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (14)
🚧 Files skipped from review as they are similar to previous changes (2)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review. 📝 WalkthroughWalkthroughThe change records queued rejections in the same journal batch as failed-start rows. Rejected messages retain their journal rejection position and can render as unsent messages on desktop. Outbox reconciliation now uses loaded journal rows, while host-recorded rejections use Dismiss instead of Retry. Message projection and session hooks accept queue and journal-row state. Tests cover placement, reconciliation, notices, queue behavior, and mobile projection. Priority: ➖ Normal Merge Risk: ⚪ Minimal · up to The change shows rejected messages in place with the host's reason and no Retry. No concrete merge-blocking issue was found in the supplied material. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change improves recovery of failed messages while preserving the reviewed conversation and write controls. No introduced security issue was established. Risk remains low rather than minimal because complete verification of session switching and compatibility with earlier behavior was not available. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…-message-shows-in-chat
There was a problem hiding this comment.
ℹ️ No critical issues — one path where the new "Not sent" rule is bypassed.
Reviewed changes
- Host journal placement. A rejected dispatch row now moves its message item to the rejection sequence, in no turn (
placeRejectedMessage), covering queued, handed-over, and direct sends; a message in doubt does not move. The host owns the position, so a recent rejection always lands on the newest loaded page. - Atomic start-failure write.
JournalRowWriter.enqueueRowswrites the queued-message rejections and the lifecycle "did not start" row in one transaction, rejections first, driven by a newJournalLifecycleBatchInput.rejectsQueued. Nothing is written when a Stop withdrew every queued message first. - Outbox lets go, and Retry becomes Dismiss.
reconcileStructuredAgentSessionOutboxmoves to its own module and drops an entry once the rejected submission's own row is loaded;structuredAgentSessionEntryRejectedByHostmakes a host-recorded rejection offer Dismiss and no Retry, andowesDeliverystops counting such an entry. - One rule for what shows.
structuredAgentSessionRejectedShownInPlacedecides in-place drawing (withdrawn, queued-card-held, commands, and a copy superseded by a later same-fingerprint send are hidden); desktop delivery notices use the same rule and are held stable across unchanged batches. - Mobile passes
rejectedInPlace: falseand is otherwise unchanged.
deepseek-v4.1-flash (free via Pullfrog for OSS) | 𝕏
| ): NativeChatMessage[] { | ||
| const optimistic = reconcileStructuredAgentSessionOutboxWithQueue(outbox, submissions) | ||
| // Refused sends are ledger evidence, not conversation history; local drafts remain in the outbox. | ||
| const optimistic = reconcileStructuredAgentSessionOutboxWithQueue(outbox, submissions, items) |
There was a problem hiding this comment.
The outbox-drawn copy bypasses the new supersede rule. structuredAgentSessionRejectedShownInPlace hides the host item when a later submission with the same payloadFingerprint was submitted at/after its resolvedAt, but optimistic here is filtered only against journalled (visible items), and reconcileStructuredAgentSessionOutbox keeps a rejected entry whenever its own row is not in the loaded items. So when the superseded message's host row is outside the loaded/retained window (the client retains only the newest items but mergeSubmissions keeps up to 256 submissions), its outbox entry still draws — a delivered resent row plus a stale Not sent row for the earlier copy. I reproduced this: items = [seed, resent], submissions = [seed, old(rejected), resent], outbox = [old(rejectedByHost)] renders three user rows, with old as unsent.
Technical details
# Supersede rule not applied to the outbox-drawn copy
## Affected sites
- `src/shared/structured-agent-session-message-projection.ts:69-72` — the supersede rule that hides the host item.
- `src/shared/structured-agent-session-message-projection.ts:88` — `optimistic` starts from the reconcile, which keeps a rejected entry until its own item loads.
- `src/shared/structured-agent-session-message-projection.ts:134-135` — the optimistic rows are filtered only against `journalled` (visible items).
- `src/shared/structured-agent-session-outbox-reconcile.ts:30-42` — keeps a rejected entry when its row is not in `items`.
- `src/shared/structured-agent-session-reducer.ts:199-203` / `structured-agent-session-item-retention.ts:21-38` — submissions survive item trimming, so a rejected submission can outlive its item.
## Required outcome
- A rejected submission hidden by the supersede rule (or by a queued card, a command, or a withdrawal) must not draw from its outbox copy either; the transcript should show only `resent`.
- The documented fallback must still hold: a rejected message whose host row is not loaded but which is not hidden by the rule keeps drawing from its outbox copy.
## Suggested approach
- Give the outbox path the same hiding decision as the item path — pass `queuedMessageIds`/`commandItemIds` into the reconcile (or the projection's optimistic filter), or have `structuredAgentSessionRejectedShownInPlace` also return the hidden set so `structuredAgentSessionEntryRejectedByHost` entries can be dropped.
## Open questions for the human
- Is a lingering outbox copy acceptable until the outbox is removed, given the stale row carries a Dismiss?There was a problem hiding this comment.
ℹ️ No new issues in this delta — the prior finding still stands.
Reviewed changes (delta against the prior review at 831e8eb1)
- Dismiss removed.
804ca8c69ddrops the Dismiss action from host-recorded rejection notices and the outbox hook. A host-recorded rejected copy now renders as text with no control on every mount, and leaves only when its row loads. The notices no longer build theoutboxDrawsset, anddismissis gone fromuseStructuredAgentSessionOutboxand the session controller. - Tests updated.
use-structured-agent-session-outbox-admission.test.tsx,structured-agent-session-delivery-notices.test.ts, the recorded-copy/older-host projection tests, anduse-structured-agent-session-delivery-notices.test.tsxnow assert no control and self-retirement. All pass locally (38 tests across the five touched suites).
The prior review's finding is unaffected: the shared projection and reconcile are unchanged by this delta, so a superseded rejected message whose host row is outside the loaded window still draws its outbox copy.
deepseek-v4.1-flash (free via Pullfrog for OSS) | 𝕏
There was a problem hiding this comment.
ℹ️ No critical issues — minor suggestion inline. The head is unchanged since the prior pullfrog review at
50c957b783, so this re-confirms the one previously flagged path and finds nothing new.
Reviewed changes
- Host journal placement. A rejected dispatch row now moves its message item to the rejection sequence, in no turn (
placeRejectedMessage), covering queued, handed-over, and direct sends; a message in doubt does not move. - Atomic start-failure write.
JournalRowWriter.enqueueRowswrites the queued-message rejections and the lifecycle "did not start" row in one transaction, rejections first, driven by a newJournalLifecycleBatchInput.rejectsQueued. Nothing is written when a Stop withdrew every queued message first. - Outbox lets go.
reconcileStructuredAgentSessionOutboxmoves to its own module and drops an entry once the rejected submission's own row is loaded;structuredAgentSessionEntryRejectedByHostmakes a host-recorded rejection offer no Retry, andowesDeliverystops counting such an entry. - One rule for what shows.
structuredAgentSessionRejectedShownInPlacedecides in-place drawing (withdrawn, queued-card-held, commands, and a copy superseded by a later same-fingerprint send are hidden); desktop delivery notices use the same rule and are held stable across unchanged batches. - Mobile passes
rejectedInPlace: falseand is otherwise unchanged.
deepseek-v4.1-flash (free via Pullfrog for OSS) | 𝕏
| if (submission?.dispatchState === 'rejected') { | ||
| // Its row draws it once loaded; until then the entry does, as the host recorded it. An older | ||
| // host leaves that row where it was sent, which may be outside the loaded window. | ||
| loaded ??= new Set(items.map((item) => item.itemId)) | ||
| if (loaded.has(agentJournalSubmissionKey(entry.clientMessageId))) { | ||
| return [] | ||
| } | ||
| const lastFailure = structuredAgentSessionRejectedFailure(submission) | ||
| return [ | ||
| structuredAgentSessionEntryRejectedByHost(entry) | ||
| ? entry | ||
| : { ...entry, state: 'rejected' as const, lastFailure } | ||
| ] |
There was a problem hiding this comment.
A rejected submission hidden by the supersede rule still draws from its outbox entry here whenever its host row is outside the loaded window, so a stale "Not sent" can appear beside the delivered resend. The reconcile gates the outbox copy only on the row being loaded, not on structuredAgentSessionRejectedShownInPlace; the projection then draws that entry as unsent at structured-agent-session-message-projection.ts:88.
Technical details
# Superseded rejected copy still draws from the outbox
## Affected sites
- `src/shared/structured-agent-session-outbox-reconcile.ts:30` — the `rejected` branch returns the entry whenever the submission's row is not loaded, with no supersede check.
- `src/shared/structured-agent-session-message-projection.ts:88` — those entries then map to `unsent` rows, bypassing `structuredAgentSessionRejectedShownInPlace`.
## Why it is reachable
- An older host leaves a rejected message at its sent position, which can be outside the loaded page; the outbox copy is kept for exactly that case. If a later same-`payloadFingerprint` copy was sent at/after the rejection's `resolvedAt`, the in-place rule suppresses the journal row but not this retained copy. The new `recorded-copy` test covers "row outside the window" and the `rejected-in-place` test covers supersede, but not both at once.
## Required outcome
- A rejected submission the in-place rule suppresses must not reappear as a "Not sent" row from its retained outbox copy.
## Suggested approach
- Have the reconcile consult the same rule as the projection (or accept the `shown` set) so an entry whose submission is superseded is dropped/skipped, not only one whose row is loaded.# Conflicts: # src/renderer/src/components/native-chat/NativeChatStructuredSessionDelivery.test.tsx # src/shared/structured-agent-session-outbox.ts
…-history #24710's enqueueRows (a failed start's rejections and its row in one transaction) now goes through the same write as a single append: every row, then any send ledger receipt, then the fold and ONE chat status written from the fold that holds every row; a failed COMMIT puts the fold back and adopts no receipt. Pinned by journal-append-status-commit.test.ts. The stored-status plumbing (status writes, fold undo, backfill, projection) moves out of the store and its collaborators into journal-session-status-writer.ts; the store exposes it as `sessionStatus` (`at`, `backfill`), replacing `statusState` and `backfillSessionStatus`. #24710 places a rejected message where it was rejected, which changes the latest prompt and request the stored summary reads: JOURNAL_SESSION_STATUS_RULES 1 -> 2, with a corpus case that pins it and the new digest. Conflicts: journal-store-collaborators.ts (main hoisted the row writer; kept, with this PR's deps) and journal-pending-submission-recovery.ts (both imports).
Takes main's side for the files #24710 also changed; this branch's remaining changes are re-applied on top in focused commits.
…ected message Main's #24710 draws a message Orca recorded and then rejected where the host placed it, as "Not sent", from the host's own history. The host side (the rejection moves the message to its place; a failed start writes its rejections and its row in one transaction) is taken as written. On the client, C2's settlement stays the only place an outbox entry ends: - #24710's reconcile module is folded into C2's: an entry whose rejected row is not loaded yet stays, never sent again, and draws the message until that row loads (or the host's window for its id ends). Nothing new is stored; the held submission says it was rejected. A batch that settles nothing writes nothing. - One "not sent" surface: main's rule hides a rejected message a live card holds or a later copy of the same text superseded, in the rows and the notices alike, on the desktop and the phone. The notice stays C2's muted one, and notices are kept as the same objects across unchanged batches. - No Retry: a message refused before it was recorded still goes back to the conversation's draft with the reason, as before. - A rejected /compact stays in the chat (#24918's rule), since the command's own reply says nothing once the journal shows it. - The phone and the desktop both draw these rows; only the host's outline, which older clients read, leaves them out.
#24918 and C2 already agreed on everything this head adds over main except wording sources, so the resolution keeps C2's mechanism: - A rejected /compact is case 1, shown muted and said once. The command's reply stays silent only while the journal draws it: a withdrawn, card-held or superseded copy still speaks (structuredAgentSessionJournalShowsSubmission now reads the shown-in-place set). - The phone draws recorded rejections in place with its live card ids. - The row's words come from the host's reason and fact, through C2's send-failure words module (send-disposition stays deleted). - The not-sent line keeps C2's `muted` flag; #24918's `notSent` field is not taken, and its Retry-era outbox notice tests stay out. - The list test for a rejected /compact is taken, on C2's notice signature.
…ded in doubt #24710 now draws every message the host rejected where it was rejected, in the host's words, so the journal-drawn not-delivered row, its outbox exclusion and the Retry rotation record go. Tests state which rejected message has a Retry: only a failed start no agent took, on a host that retries in place.
A rejected send's own row now moves to its rejection (#24710), so the row that resolved a send is the item's own position and needs no second copy. Keep submittedSequence, the one journal-order record of where a send was sent.
…puts its row #24710 moves a rejected send's row, a Stop's take-back included, to the row that rejected it, in no turn. Draw it at that row, past the end of every turn opened before it, and keep the send-order rule. A send whose turn opened before the provider echoed it is claimed by that turn's record when it was sent before the record and taken back after it, by submittedSequence, and is drawn as the turn's opener. The steer branch goes: the host no longer says which turn a taken-back steer joined, so it is drawn after that turn with its own row. The older-host fallback (floor, clock compare, submittedAt order) is now gated on submittedSequence alone and marked Temporary. resolvedSequence is gone, as in #25073.
…ow, not hidden #24710's tests pinned a withdrawn send as hidden, the rule this PR replaces. Each keeps what it is about: a withdrawn copy does not hide a failed one, no delivery notice is raised, and a message the host failed to deliver stays hidden on the phone.
…n a stopped one was answered into (#25073) * feat(native-chat): publish each submission's journal positions A client never learned where in the journal a send was accepted or taken back, so drawing a stopped send had to guess from its own row and from clocks, and the guesses misfired after restarts. Each projected submission now carries `submittedSequence` (its submission row) and `resolvedSequence` (the dispatch row that resolved it; absent while pending): two optional fields, computed on every fold from rows already stored, never stored themselves. Older clients ignore them. The failure-fact schema moves to its own module to keep the journal schema file within its size limit. * test(native-chat): pin a submission's resolved position on the provider-echo accept path Also say which rows can resolve a submission, and that the submission schema, not the shared type, omits acceptedSequence. * refactor(native-chat): publish only where each submission was sent A rejected send's own row now moves to its rejection (#24710), so the row that resolved a send is the item's own position and needs no second copy. Keep submittedSequence, the one journal-order record of where a send was sent. * feat(native-chat): publish the turn a withdrawn Codex send was answered into A send Codex answered into a turn that then ended without taking it is rejected by that turn's end. The rejection row now names that turn's record, and the submission carries it as answeredInTurnItemId, so a client can tell which turn the send belonged to without guessing from journal order or clocks. Absent on every other send. * feat(native-chat): say how a withdrawn Codex send joined the turn it names The answered turn becomes { turnItemId, via }: 'start' when Codex answered the send's turn/start with that turn, 'steer' when Orca steered it into that running turn. A client can then tell the turn's opener from a send steered into it even when the opener is on an older page. * feat(native-chat): state on every rejection whether it names a turn A rejection a host writes now always carries answeredInTurn: the turn Codex answered the send into, or null for none. A reader can then tell 'answered into no turn' from a row written before the field existed, which keeps no answer and is placed by the older rules. * refactor(native-chat): give the answered-turn schema its own module Keeps the journal schema file within its line limit. * docs(native-chat): say an unreadable answered turn reads as none
…e stop row after it (#25051) * refactor(native-chat): derive the queue's pause from Stop and Resume journal rows Stop now appends one journal row where it takes effect, before the interrupt, whatever the queue holds; Resume appends its own. The pause is a pure function of the fold: the latest Stop with no later Resume and no later accepted turn a person asked for. A /clear's carried cards name their source, which is the replacement's 'cleared' pause. Host-origin turns never lift either. One predicate decides which cards a pause holds; by default every waiting card without a hold of its own, including one queued after the Stop. The drain's consume re-judges it inside its own transaction. The rows are tombstones of an id no item takes, carrying the mark: a released host reads an unknown row kind as corruption and truncates the journal there. Deletes the stored pause (recordPause, the retire hook on every appended row, the settle-before-record step, mayReturnToWaiting and its row overlay) and the tests that only proved it retires. The queued_message_pauses table stays in the schema, unread and unwritten, for downgrade safety. * fix(native-chat): a card queued after a Stop sends normally, never ahead of held ones A Stop's pause now holds only the cards queued before its row, plus a steer it withdrew, which returns to its own place. Each card records the journal position it was queued at, and the one hold rule compares that with the Stop row. A card queued after the Stop is a new instruction: it sends as usual, but the drain still stops at the first held card, so it never overtakes them. /clear's pause holds the cards it carried. Holding every card again is a one-line switch in that rule. * fix(native-chat): the queue's own send re-checks the no-overtake rule in its transaction The drain's pick and its consume now read one function, nextSendableQueuedCard, so a Stop row that lands between them holds a newer card behind an older held one exactly as the pick would. Notes why Stop and Resume ride a tombstone row. * fix(native-chat): stop creating the unused queue pause table The queue's pause is derived from journal rows, so nothing reads or writes queued_message_pauses. It was still created on every open "for downgrade safety", but an older build creates it itself when it opens the database, so the table only sat empty in every new database. The tests now pin that no pause table exists. * fix(native-chat): a Stop's pause never hides the restart pause A Stop holds only the cards queued before it. The pause derivation still returned the Stop alone whenever it was in force, so the restart pause was never considered: a card queued after the Stop, written by a host process that has since exited, sent by itself after Orca restarted, with no pause header and no Resume. A /clear pause that held nothing could hide it the same way. Every pause in force is now derived. A card is held if any of them holds it, and it names the first that does. The drain's pick, the consume transaction's re-check and the published header all read that one rule; the header names the pause holding the first card Resume would send. * test(native-chat): pin the Stop's no-resend, lift and held-card rules - The Claude and Codex Stop-withdraws-a-steer tests checked "not sent again" at one instant, before a queue ignoring the pause re-sends. They now wait for the stopped turn to end and re-check after a quiet window. - The deleted-card test read a card queued after the Stop, which sends whether or not a person's turn lifts it; it now reads the Stop's pause before and after that turn. - Unit cases pin that a Stop holds a card with no recorded position and one queued before a rewind. * refactor(native-chat): a Stop writes one Stop event with its reason, turn and caller The Stop row that paused the queue becomes the general Stop event { reason, turnId?, at, caller? }, whose reason is the host's existing stop cause. It still rides a tombstone of a host-only id (a released host deletes the journal from the first unknown row kind), and Resume keeps its own marker on its own id. Only a person's Stop (reason user-stop) pauses the queue. * test(native-chat): a rewind keeps a lifted /clear pause lifted and restates the same Stop event * test(native-chat): pin that Stop and Resume rows never reach apps or count as history * test(native-chat): only a person's Stop event pauses the queue * test(native-chat): pin that a Stop's event precedes the interrupt and the at-start stop Through the real host: the event names the turn and who asked and is in the journal when the interrupt reaches the agent; at an agent still starting it is there before the start is ended and holds a card queued before it; an idle Stop writes one only when it withdrew a send; and the queue's claim re-judges a pause that landed after its pick. * test(native-chat): a card held at a starting agent is checked before the Stop's timing Also says precisely what the claim's in-transaction pause check defends against: the Stop and the drain share one serialized lane. * test(native-chat): a released build keeps and folds a journal holding Stop events Replays this build's rows from the released build's own journal database: every row is kept, the history after the Stop still folds, and an older client is sent only removed ids no item uses. * style(native-chat): format the Stop event changes * test(native-chat): type the released build's exports through one checked helper * fix(native-chat): the Stop/Resume row guard narrows to those tombstones only * test(native-chat): run the Stop-event downgrade test in CI, and cover a writable downgrade The Stop-event downgrade test ran in no CI lane: unit shards exclude the cross-version folder, and the cross-version lane runs a fixed file list that did not name it. It is now on that list. Its only case replayed the rows into a release's own fresh database, because that release cannot open the current host database. A second case opens the journal this build wrote with a main build that shares the database: it opens writable, keeps every row, appends, and this build then reopens it with the person's Stop still pausing the queue. * fix(native-chat): a Stop that stops nothing new writes no Stop event A Stop reaching a running agent wrote a Stop event on every press. Two presses before the first interrupt landed wrote two events, so a card queued between them counted as before the latest Stop and was held, though a card queued after a Stop should send normally. A Stop naming a turn that had already ended, as a phone sends late, also wrote an event for a turn it never stopped. It now writes one only when it withdrew a queued send, or stops something no event records yet: not a turn the journal no longer runs, and not the live turn a Stop still in force already names, unless a card was handed over into it since, which this Stop's interrupt sends back and must hold. The interrupt and the "already finished" note are unchanged. A Stop at a starting agent still always writes. * test(native-chat): pin that a later host, eviction or close Stop never lifts a person's Stop * chore(native-chat): put each Stop-row doc on its own declaration, and say only user-stop is journaled * fix(native-chat): any later Stop event ends a person's Stop pause A person's Stop paused the queue until their next accepted turn or Resume, and a later Stop of another reason (the host stopping the agent, an eviction, a close) was ignored. Now the pause is the latest Stop event's: a later Stop of any reason ends a person's pause, and only a person's Stop pauses. The fold keeps the latest Stop event whatever its reason. An eviction of a resting chat writes no Stop event (a Stop that stops nothing writes nothing), so it cannot release held cards; a test pins that no event means no lift. * fix(native-chat): a second Stop press is a repeat even when the first came before the turn showed A Stop pressed before the agent's turn shows in the journal (before Claude's echo, or before Codex opens the turn) records no turn. A second press once the turn showed compared that missing turn with the live one, wrote a second Stop event, and held a card queued between the presses. A repeat is now judged by what was sent since the Stop in force: with nothing sent after it (a refused send aside), a Stop that named no turn, or named the live one, is repeated and writes nothing. Anything sent since and not refused, including a send whose fate is unknown, makes the new press write, since its interrupt may send that card back to waiting. Tests: the two-press case across the turn showing; a steer between the presses settled unknown; and a Stop naming a turn that ended while the next card is sent but shows no turn yet, which writes and holds that card. The fold test that claimed an eviction path is renamed. * fix(native-chat): the queue's pause ignores a Stop or Resume row holding a value no build writes A Stop or Resume row's value is read from disk with no shape check, and the pause fold stored whatever it found. A stored `stopEvent: null` would then throw on every pause check for that chat: the queue's pick, its send, and every queue update to clients. No build writes such a row, so this is hardening. The fold now reads a Stop only when it is an object with a string reason and a finite time, and a Resume only when it is `true`. Anything else is ignored: it pauses nothing and ends nothing. The row is still not treated as malformed, which could cut the history short. * fix(native-chat): a Stop still reads as yours after Orca restarts before the turn ends Every stop that ends work now writes the Stop's event before it ends the child: a person's close of the chat, an eviction (worktree teardown, orchestration stop, tab cleanup) and the idle sweep's stop of a start that never landed. A stop that ends nothing writes nothing, and quit writes none: its resume marker records why. The turn-end write reads the latest Stop event where every turn row is built, so the adapter's settle, the host's fallback and the relaunch's settle all agree: a turn a person's Stop or close named, ending with no verdict of its own after that Stop, ends as their cancellation. A relaunch's probe-bounded end is no earlier than a Stop that found the turn running. When the provider refuses the interrupt and the turn runs on, a refusal row answers the Stop, so a later crash still reads Failed; pressing Stop again after a refusal is a new Stop. * refactor(native-chat): a stop no longer carries its cause; the turn's end reads the Stop event The cause of a stop was threaded in memory from each entry through the host's stop step, the adapter router and each adapter's close onto the `ended` it settled with, and Claude kept a per-turn copy of a Stop it sent. All of that is gone: adapters settle a turn they cut as interrupted with no verdict, the host's fallback does the same, and the one rule where a turn row is built (`turnEndAfterStop`) reads the journal's latest Stop event to say whether it was a person's. - `closeSession` / `disposeSession` take no cause; `ended` has no `stopCause`. - Claude reads an error result after a person's Stop as their cancellation from the journal's Stop event (through the event sink), not from a per-turn slot, and a refused interrupt is the host's refusal row, not `withdrawTurnStop`. - An owed wind-down keeps no cause: its retry's fallback reads the Stop event. - The mutation context's Stop passes no cause: its step already wrote the event, and the delivery loop's child-end reason is read back from it. - A Stop pressed before its turn showed applies to the turn that opens under it, unless a send a person made since was accepted. * test(native-chat): a turn a later send opened is no Stop's that named no turn * test(native-chat): the restart test's death proof carries its detail * refactor(native-chat): a refused Stop leaves no record; a Stop only ever ends the turn it names The stop-refused mark is gone: its tombstone kind, its fold, the clock-keyed match that tied it to a Stop, and the exception that let a second press after a refusal write a new Stop. A Stop that stops nothing writes nothing. A Codex refusal names a turn that is no longer its active one, and the Stop names that turn, so the turn running instead never reads as the person's by its id alone. * fix(native-chat): a Stop pressed before any turn showed stops only the turn opened next A Stop that named no turn read as the person's cancellation for every later turn that opened after it, until a send a person made was accepted. The queue's drain, orchestration mail and a restart continuation send as the host, so a turn they opened long after, cut by a crash, read "Interrupted" as if the person had stopped it. The Stop now applies only to the first turn opened after it. * fix(native-chat): an older Claude's error end after a Stop pressed before its echo reads Interrupted Claude CLIs before 2.1.91 end an interrupted turn with an error result that names no reason. The translator judged whether a person's Stop explained it by its own copy of the Stop rule, which ignored a Stop that named no turn, so a Stop pressed before Claude echoed the send read "Failed". The translator now writes such an end as interrupted with no verdict and no error row whenever a person's Stop may name the turn, and the journal's one rule decides as it writes the end. * fix(native-chat): a person's Stop and /clear each name why they end the agent The host's mutation path ended the agent with one "recorded" ending for every caller, which read back the reason of whatever Stop event the journal held last, however old. /clear writes no Stop event, so its end took an unrelated earlier reason. Each caller now names its own: the chat's Stop `user-stop`, whose event its own step wrote, and /clear `user-close`, the user replacing this chat. * fix(native-chat): a host stop judges whether it ends work after the provider's rows land A close, eviction or host stop decided whether it ended a running turn from the journal as it stood, while the provider's own rows (the turn its echo opened) could still be in the session's event sink. A close landing in that gap wrote no Stop event, so the turn it cut read as news. It now reads after the sink drains, as a person's Stop does, through the same check; a drain that fails or takes over a second reads working. * fix(native-chat): a Claude Stop naming a turn that just ended still marks the follow-up it cuts A phone names the turn it last saw. When that turn had ended and a follow-up was still unechoed, Claude's Stop interrupted the follow-up and ended the child, but the Stop's event named the ended turn, so the follow-up's turn the child's end cut read "Failed" under "Cancellation requested.". A Stop that ends the provider's session ends whatever is in flight, so its event now names the live turn or none, and a Stop that names none binds the turn opened next. Codex keeps naming only the turn the Stop names. The Claude Stop turn-end tests move to their own file, since the session-ending Stop suite is at its line budget. * fix(native-chat): the idle sweep reads working by the same rule as a stop's event The sweep judged a chat resting while a send whose reply was lost was still unanswered, but the stop's event writer counts that send as work. So the sweep evicted it and wrote an evict event, which ends a person's Stop pause and let the cards behind it drain on their own. The sweep's owed work now reads the main agent working the way every session list and the event writer do. * test(native-chat): an aborted eviction's injected drain failure lands on the eviction's own drain A host stop now drains the session's sink once to judge whether it ends work, so the tests that fail the eviction's drain-published step skip that first drain. * fix(native-chat): the idle sweep's rest writes no Stop event; it evicts a send that never echoes The previous commit made the sweep count an unanswered send as owed work, which pins a chat whose admitted send Codex never echoes forever, and the sweep exists to retire exactly that. That rule returns. The sweep stops only an agent it judged resting, so its eviction now writes no Stop event, whatever send it retires: a person's Stop pause holds through it. * fix(native-chat): stopping a start that carries no send writes no Stop event A host stop, eviction or close of a starting child wrote a Stop event whatever the start carried. A start with a send already reads working, so the clause only mattered for a start with none, which ends no turn and no send: its event only lifted a person's Stop pause and bumped the idle clock, which is why the idle sweep had been changed to close the conversation in the same pass. The clause goes and the sweep is #24072's again. The child's end still reads host-stop, as before. * test(native-chat): a Stop's pause across a restart is tested with a restart that writes no event The rig's restart closes the chat with an eviction, which now writes a Stop event when work runs and so ends a person's Stop pause. "A Stop never hides a restart's pause" then passed with no Stop pause left to hide anything. Those tests, and the pause-lift test whose dropped assertion returns, restart as a process that dies with no close, which like a quit writes no Stop event, and assert that both the Stop's and the restart's pauses are in force first. * fix(native-chat): a host stop of a turn a person's Stop is still ending keeps that Stop's reason An eviction or host stop that landed while a person's Stop or close was already ending the same turn wrote a newer Stop event, and the turn's end reads only the latest, so the person's Stop of that turn read as news. A host reason now writes nothing while a person's Stop still decides what runs: the live turn it names or bound, or, with none, the turn a send opens next. The person's own close still writes. The E2 tests now open and end the stopped send's own turn, as Codex does, so the mail turn after it is not the turnless Stop's. * fix(native-chat): an older Claude's error on a later turn keeps its error text after a Stop The translator left an error result that names no reason to the journal's Stop rule whenever a person's Stop named the turn or none, but the rule binds a Stop naming no turn only to the turn opened next. So a real error on a later turn read "Failed" with its error text dropped. The translator now asks the journal's rule itself (`personStopDecidesTurn`, the one core `turnEndAfterStop` and a host stop's in-force check share), so the two cannot disagree. * fix(native-chat): a Stop of a start that never landed binds no later turn, whatever sent it A person's Stop pressed while the agent starts names no turn, and the send it stopped is cancelled before it opens one. The Stop then bound the next turn anything opened (orchestration mail, a restart continuation, the queue's drain, all of which send as the host), so a host eviction of that turn wrote nothing and its crash or close read as the person's cancellation. A Stop that named no turn now binds only a turn no send journaled after it opened: any send since, of any origin and not refused, opens its own. The E2 test's mail send is accepted as Codex accepts it, instead of opening the stopped send's own turn first. * test(native-chat): a rewind's restated turnless Stop binds no turn opened after the rewind A Codex rewind restates a person's Stop still in force after the turns it keeps, at a new sequence, so by sequence alone it would bind the next turn opened after the rewind. A send journaled after the restated row voids that binding (the previous commit), which this pins. * fix(native-chat): a relaunch settles a person's stopped turn with no "stopped while in progress" row After a restart, a turn a person's Stop ended reads "Interrupted after N" with the muted mark, but the relaunch still added the error row saying the provider stopped mid-response, which a live Stop never writes. The settle now skips that row when every turn it interrupts is the person's Stop's by the journal's one rule; a crash nobody stopped keeps it. * test(native-chat): the unexpected-exit settle's journal fake answers whether a person's Stop decides a turn * fix(native-chat): a host stop whose sink drain fails reads the journal as it stands A host stop drains the session's sink before judging whether it ends work, and a failed or slow drain read as working. So an eviction of an agent at rest wrote a Stop event that ended nothing, which lifts a person's Stop pause, and a close wrote a person's event naming no turn. The drain is now best effort: the stop goes ahead either way and only its record is at stake, so a failed or slow drain leaves the journal's read as it stands. A person's Stop keeps its own rule. * fix(native-chat): a Stop that named no turn applies only to a turn a send it stopped opened A person's Stop pressed before any turn showed names no turn. It bound the first turn opened after it, then (5ead1f6bccd) any turn opened by no later send, so a turn the host started for a card the Stop held, or for orchestration mail, read as the person's cancellation, and a host eviction of it wrote no Stop event when its send had been abandoned by the close first. The rule is now the concept itself: a Stop naming no turn applies to a turn opened by a send it stopped, one already handed to the agent at the Stop's position. Nothing new is stored. The turn's row names the send that opened it (Codex: the submission's key; Claude: the echo, which the journal aliases to the submission), and a handed-over send's item sits at its handover, so the target set is derived from the journal. A card the Stop held is handed over after it, so it is no target; a Stop of a start whose send never opens a turn binds nothing; a rewind keeps no submissions, so a restated Stop binds no turn opened after it. With no turn running, a host stop defers to the person's Stop only while every unanswered send is one it stopped. Claude's translator, which asks before its echo row lands, passes the send its echo acknowledged. * fix(native-chat): a host stop whose sink drain runs long reads the agent working; a failed one reads the journal A drain past its bound may still hold the turn's row, while the echo's acceptance has already landed, so the journal as it stands read nothing running: a person's close of that turn wrote no Stop event and the turn read as news. The two drain outcomes now differ: one that failed has nothing more to deliver, so the journal's read holds (as before); one still running reads working. * test(native-chat): a host stop with no turn running defers only while every unanswered send is the Stop's The branch had no test. An eviction with only the stopped send unanswered writes nothing; one with a send made after the Stop still unanswered writes its event. * fix(native-chat): a slow sink drain reads working only while an accepted send's turn row is due The previous commit read every drain past its bound as working, so a host eviction or stop of an agent at rest during a sink backlog wrote a Stop event that ended nothing and lifted a person's Stop pause. A slow drain now reads working only when the latest send the agent accepted has opened no turn the journal holds, the race it was for; otherwise the journal's read holds. * test(native-chat): the host-stop control keeps the stopped send unanswered beside the later one With both unanswered, the host writes only because not every unanswered send is the Stop's; a rule that deferred when any one was would pass the old control. * fix(native-chat): a steer is no send owed a turn when a slow drain judges a host stop A slow drain reads working when the latest accepted send has opened no turn yet. A Codex steer or a Claude fold is accepted into the running turn and never opens one, so a chat at rest whose last send was a steer still read working, and an eviction lifted a person's Stop pause. Sends delivered into a running turn, whose item carries that turn's scope, are skipped. * feat(native-chat): a chat reads Stopping from the person's Stop until the work it stopped ends The host derives it on each journal publish from the Stop's event, the live turn and the Stop's own answer, and publishes it as an optional field on the session status and the main agent's row. Clients present it: the chat's tail line and Stop control, the sidebar row, worktree ps and the phone's row. The chat and the phone also read their own Stop press until its request answers. * test(native-chat): pin Stopping on the phone and across mixed versions * test: give touched fake journals and mocks their SAFETY notes * test(native-chat): a turn waiting on the person reads attention, never Stopping * test(native-chat): the sidebar row follows Stopping when it is the only field that moved * test(mobile): the phone reads Stopping from its own Stop until the request answers * test(mobile): type the held Stop request instead of casting it * chore: keep the base lockfile (a local pnpm run rewrote it) * fix(native-chat): narrow the Stop note's optional failure; type the phone test's reply * test(native-chat): type the Stop test envelope's fields narrowly * fix(native-chat): a Stop the agent declined, or whose child end failed, says so while the turn runs on A Stop naming the turn that still runs, refused by the agent, now writes the Stop's refused fact instead of 'already finished'. A session-ending Stop whose child end fails while the work runs on revises its note to unconfirmed. * fix(native-chat): Stopping holds while any press of the Stop took A repeat press refused after an earlier press took no longer clears Stopping. Exit early when the Stop named a turn that is not the live one. * fix(native-chat): keep Stop enabled while the host says Stopping Only this client's own Stop request in flight disables Stop and Esc. A repeat Stop is how a stop the provider took but never answered escalates. * fix(sidebar): every agent row says Stopping in place of its tool line The dashboard row, which the sidebar's non-compact mode also draws, read the last tool line while a person's Stop ended the turn. It now shares the compact row's rule. * fix(mobile): the worktree list sees Stopping change on its own A snapshot whose only change was the host dropping Stopping compared equal and was thrown away, leaving the row on Stopping. * refactor(native-chat): fold the status feed in src/shared for both clients The snapshot merge and the contact-loss strip move out of the renderer feed so the phone folds the same stream the same way. * feat(mobile): let phones read the structured session status stream agentSession.subscribeStatus joins the mobile allowlist. The agent-session methods move to their own file, which the at-cap allowlist spreads in, and the allowlist test reads the Set instead of parsing the source. * feat(mobile): the phone chat reads Stopping from the host, like the desktop One status stream per client, opened on a host that advertises the status feed; a refusal to phones reads as no feed. The chat reads Stopping from the host or its own press, and holds Stop only while its own request is in flight. * test: give the new fakes checked types or a SAFETY reason * revert(native-chat): drop the refused-named-turn rewrite of a Stop's note Codex can send its refusal before the turn's end frames, so reading the turn as still live after a flush races; the Codex Stop that ends nothing is handled by ending the process instead. The base's 'already finished' note and its test expectation return. The Claude wind-down failure revise stays. * fix(mobile): release the status stream when the host ends it; refusals last one connection The feed now drops the handle of a stream the host ended or refused, so the logical client never replays it on a later session. A refusal to phones holds for one connection, so a host updated while the phone stays paired is asked again. * perf(native-chat): read the live turn's opener from its record when deriving Stopping After a Stop that named no turn, every later commit walked and copied the whole journal to find the live turn's record. The derivation now reads that record off the rendered snapshot's tail and decides with the same rule. * refactor(mobile): move the method-unavailable check into transport The status feed imported it from the Files tab's fallback. No behaviour change. * test(native-chat): a send after a Stop reads Working before its turn opens Pins the derivation's running-only read of the newest turn: the stopped turn, already ended, must not keep the next send on Stopping. * fix(sidebar): the compact row leads with Stopping so a narrow sidebar keeps it whole At the default width the row read 'Codex Chat - Stoppin…': the model and time keep their room and the line truncates from the end. Stopping now leads the line the way monitoring already does, so the chat name is what gets cut. Also pins that the turn bar keeps its running clock while the tail line says Stopping. * test(native-chat): the retry of a close whose exit was unproven writes no second Stop event The idle sweep finishes a stop left owed with that stop's own cause. It is the same stop, so its event stands alone and the child's end keeps the cause, for a person's close and an eviction. * fix(native-chat): read and write a Stop's answer by the turn its event records Stop notes are now one row per turn, keyed by the turn the Stop's event records. Performing a Stop and deriving Stopping share that key. A refused or unconfirmed answer never overwrites one that took at the same key; only a session-ending Stop's failed wind-down downgrades it, and that step now revises the note the Stop actually wrote, carried on the wind-down. Stopping reads the turn's note whenever it was first written, plus newer notes no other turn owns. Test fixtures gain the host logger and the phone's quietRepeatedStop. * refactor(native-chat): read a Stop's target once for its event and its note The chat's Stop now reads what it is aimed at (the named turn and whether the Stop ends the provider session) once, and both its event and its note's key derive their turn from that one value through the same rule. Adds the host test for a Stop naming an ended turn on a provider whose Stop ends the session. * fix(native-chat): the host never steers a message into a turn a Stop is ending A queued card's Send-now, or a send made while a person's Stop ends the turn, went to the agent as a steer into that turn. The delivery loop now holds any waiting message while the host's own Stopping reading holds, and sends it as its own turn once the turn ends. The Stopping reader also stops at the Stop's position and looks the turn's note up by key, instead of walking the whole journal. * feat(native-chat): while Stopping, the composer says a message runs after the stop Desktop and phone: the composer placeholder reads "Queue a message to run after the stop" while the chat reads Stopping, and a queued card's Steer (and the desktop's steer shortcut) is held. New key translated in all 6 catalogs. * refactor(native-chat): the chat pane's Stop controls live in their own module The pane went over its line limit once merged with main. Its Stopping reading, the press that holds Stop, and the steer and placeholder it hands the composer move to native-chat-structured-stop-controls.ts. * fix(native-chat): hold a send at its handover, reading the feed's own Stopping The hold was checked when the delivery step started, but the handover runs in a later step after waiting on the agent's start, so a Stop landing in between let a new send steer into the stopping turn. The check now runs at the handover. It reads the status feed's projection for the commit instead of rendering the journal again, so holding a send adds no journal read of its own. * refactor(native-chat): one display status decides Stopping on every surface agentStopDisplayStatus combines whether the agent works, the host's flag and this client's own press. The chat pane, sidebar and dashboard rows, and the phone's chat all read it, instead of each combining the flags. * fix(native-chat): Stopping holds until the stopped turn ends, whatever the Stop's answer A Stop the agent declined, or whose end went unconfirmed, used to drop the chat back to Working. It now stays on Stopping until the turn ends, and Stop stays enabled so a repeat press escalates. The Stop's answer is no longer read for Stopping, so its note goes back to the key the base gives it (the restore of queued-stop.ts and the removed key test landed in the previous commit). The note still keeps a press that took over a later refusal, and a failed process end still says the Stop went unconfirmed. * fix(native-chat): a Stop binds only the turn it actually stopped A Stop pressed before any turn showed used to claim, at end-write time, whatever turn the stopped send later opened, even when the Stop stopped nothing. A turn that then died on its own read as "Interrupted" (your cancellation) instead of "Failed". Now a person's Stop that named no turn binds, in memory only, every turn that ends while the Stop settles, and afterwards only the turn its interrupt took. The settle ends a still-running stopped turn once. A relaunch finds nothing in memory, so an unsettled turnless Stop binds no turn. A Codex Stop whose answered turn does not open within its wait, or whose send's answer was lost, now answers refused, so the host ends the child and the turn can never run. * fix(native-chat): keep the person's queue pause and close binding after a Stop settles A host stop or eviction with no turn running now defers to a person's Stop while its queue pause still holds with nothing sent since, read from rows, so a held card is not handed off on reopen after a Stop that did nothing or whose kill failed. A person's close that named no turn opens a settle around its child's end, so a turn that end cuts reads as theirs. A press opens its settle only when the latest Stop event is its own or the one in force it repeats: a late Stop, a card's interrupt or a lost event row reopens no earlier Stop. A Codex Stop that cannot reach a turn still able to open says the Stop is unconfirmed rather than that no turn ran, and a second Stop still reaches a turn an earlier wait left unopened. Also drops the unused openedBy plumbing and the unreachable "a written cancellation stays one" rule, and pins a relaunch after a named Stop. * fix(native-chat): keep a failed Stop's turn display-only, and settle edges off the commit path A Stop that failed marks the turn it could not stop for "Stopping…" only (JournalStopSettle.failedOn): no turn-end rule reads it, so that turn's own end with no verdict reads as a failure, not the person's. A settle edge writes no row, so it no longer goes through the journal's commit listener, which also delivers history, counts as activity for the idle sweep and schedules the queue drain. A narrow settle-edge hook republishes the status row and wakes the steer hold's handover, and nothing else. * fix(native-chat): a Codex Stop agrees on both presses when a turn is still owed, and pin the close's settle A Codex Stop that waited for a turn Codex answered a send into now answers "may still open" whenever that turn neither opened nor ended and its send is still owed, however the wait ended (it ran out, or the thread went idle). Before, a first press after an idle thread said no turn was running and kept Codex, while an identical second press ended it. Adds a test that a person's close the conversation outlives (as /clear does) closes its settle, so a later turn that ends on its own reads as a failure. * fix(native-chat): a Stop that failed before its turn showed still reads Stopping through that turn A Stop that failed with no turn open marked nothing, so the chat dropped to Working and the turn that then opened never read "Stopping…". The display-only mark now also covers that case: the first turn that opens after the Stop failed, provided no message was handed to the agent in between. No turn-end rule reads the mark, so that turn's own end with no verdict still reads as a failure. * test(native-chat): a Stop whose event row failed binds no turn to an earlier Stop With one ordered journal writer the Stop's event is in the fold when its write returns, so the press reads whether it owns the latest Stop from the fold instead of awaiting the write. Pins the case the read must refuse. * test(native-chat): name the settle, not a stream drain, in the Stop's own-end test * test(native-chat): a Codex Stop answered before Codex ends the turn reads interrupted throughout Codex answers an interrupt it took before it sends turn/completed (interrupted): on TurnAborted the app-server answers pending interrupts, then ends the turn, on one channel. The test fake did the reverse. It now answers first and ends the turn on a later read, and the tests that read the turn's end right after a Stop wait for it. New end-to-end test through the shipped host, journal and Codex adapter: with the real order, every end row of the stopped turn reads interrupted by the Stop (named, unnamed, and a Stop pressed while turn/start was in flight). Breaking the settle window turns the in-flight case red: the Stop's own end row then has no verdict, which reads as failed until Codex's end lands. * test(native-chat): Stopping ends with a Codex turn whose interrupt is answered before its end With Codex's real order (the interrupt's answer, then turn/completed interrupted), the status shows Stopping while the Stop settles, drops it once the turn ends, and never carries a verdict other than the person's cancellation. * fix(native-chat): a Codex Stop interrupts a turn Codex answered but has not opened at once A Stop that named no turn, made after Codex answered a send but before the turn opened, used to wait up to 5 s for the turn to open before interrupting, and ended the Codex process when it didn't. The stated reason, that Codex refuses an interrupt until it opens the turn, holds only part of the time: with no turn active, Codex takes an interrupt once its thread runs (turn_interrupt_inner), and refuses it with -32600 "no active turn to interrupt" before that or once the turn has ended. The Stop now sends the interrupt at once. Only on that refusal, while the turn has neither opened nor ended, does it wait for the turn to open (bounded at 5 s) and send it once more. A turn that ended meanwhile was nothing to stop. One that never opens, or that an earlier wait already gave up on, fails the Stop, and the host ends the child as before. Sends still wait for the turn to open before steering into it. The test fake models Codex taking an interrupt once the thread runs (run()). * fix(mobile): name how the phone's status stream is released in the subscription inventory Main made each inventory entry state its release; the status feed's stream is released from its subscribe params, as the session event stream is. * fix(native-chat): every Codex Stop waits for an answered turn to start, as the first did A Stop whose interrupt Codex refused as finding no active turn skipped the wait when an earlier wait, a Stop's or a send's, had already given up on that turn. Every press now waits its own bound and retries once if the turn starts, so a turn that opens during a later press is still stopped. Both presses still reach the same verdict when it never starts. * fix(codex): never steer a turn whose interrupt Codex answered Codex answers an interrupt as the turn aborts, before it sends that turn's turn/completed. In that gap the adapter still counted the turn as running, so a message handed over right after a Stop settled (the Stop's own end row already reads the turn ended) went out as turn/steer, which Codex refused with -32600 "no active turn to steer", and only then as turn/start. The adapter now marks a turn whose interrupt Codex answered as aborted until its turn/completed, never steers into it, and starts the message's own turn directly. Steering a turn that is genuinely running is unchanged. * fix(native-chat): a message sent while Stopping is queued as a card, whatever the setting While the chat reads Stopping (the host's flag or this client's own Stop in flight) there is no turn left to steer into, so the desktop asks the host to queue the send even with the queueing setting off, and it is never drawn as a bubble inside the turn being stopped. The phone already queued every send on a capable host; a test now pins that it does so while Stopping. * fix(native-chat): a message queued while Stopping is a card at once, not after the stop A person's Stop holds the session's lane until Codex answers its interrupt, and a send was admitted only behind it. By then the turn read ended, so a send that asked to be queued went out plain: no card for the whole of Stopping, then a bubble and a new turn. While the host reads that a person's Stop is ending the work, a text send that asks to be queued is admitted without waiting for the lane: the same ledger and lease admission, and a plan that only writes the card through the journal's ordered writer. The card runs when the stop lands; the Stop's pause holds only cards queued before it. Anything else, including a Stop that settled by the time the send runs, takes the lane as before. The Codex test fake now drops the active turn when it takes an interrupt, as Codex does before it answers, so a turn/start after the answer opens a new turn. * fix(native-chat): a Codex Stop that ends the child before any turn opened withdraws its send A Stop on a Codex turn that was answered but never opened ends the Codex process. That end settled the send as in doubt (unknown, recovered), and the client's outbox holds every later send behind a send in doubt until the person presses Retry, which re-sends the very message they stopped. The chat looked stuck. Codex records a prompt only once its turn has started, so a send whose turn never opened never ran. When the Stop's refusal says so (turnMayOpen), the child end now settles the unanswered sends as withdrawn, the verdict Codex's own interrupted-turn end already gives an unechoed send. The flag rides on the owed wind-down, so a retry after a failed child end withdraws them too. Claude's child end still leaves its unanswered send in doubt. * fix(native-chat): derive the withdrawal of a Codex send whose turn never opened Replaces the flag the Stop carried to the child's end, and its copy on the owed wind-down, with a reading of the journal at the settlement that lands. A Codex child's unanswered send is withdrawn when a person's Stop is in force since it was sent and no turn row ran, or was written, after it; any other end (a turn that opened, a host's close, a crash, Claude) still leaves it in doubt. A retried wind-down reads the same rows, so it withdraws the same sends. * fix(native-chat): a card queued while Stopping runs past the cards the Stop holds A card queued before a person's Stop waits under its pause until Resume. One queued after it, as a message sent while Stopping now is, was stuck behind them too, since the queue never reorders. Such a card was asked for after the Stop, so it runs when the stop lands, past the cards held only by that Stop's pause; a returned card and the restart and /clear pauses still hold everything behind them. Also: the host's own Stopping reading is gated on working, as the published flag is, so a failed Stop's mark never reads Stopping on an idle session; a send that falls back to the lane re-reads the conversation's journal there; and the end-to-end test asserts the queue's pause rather than a per-card field. * fix(native-chat): a paused queue labels only the cards it holds Since a card queued after a person's Stop runs past the cards the Stop holds, labelling every card "paused" while the queue's pause is published misreads that card. The host now marks each card its pause holds (heldByPause, a new optional field), and the desktop and phone label only those. An older host marks none, so a client keeps today's labels; an older client ignores the field. Adds a test of the desktop's own send through the real outbox: while the chat reads Stopping, the request asks the host to queue it and no bubble is drawn, on a host that advertises the queue. * revert(native-chat): defer the per-card queue pause label to the queue's rollout The heldByPause field and its labels are visible only where the host advertises the queued-messages capability, which shipped hosts do not yet do. Deferred to that rollout; the real-outbox send test stays. * fix(native-chat): while Stopping, say and show what a send does where the queue is dark Shipped hosts do not advertise the queued-messages capability, so a message sent while Stopping goes out plain: the host holds it until the stopped turn ends and then runs it as its own turn. The composer still said "Queue a message to run after the stop", and the message was drawn inside the turn being stopped. Now the placeholder reads "Send a message to run after the stop" where the host does not queue sends, and "Queue a message…" only where it does (desktop and phone, all six catalogs). A send this client made that the host has not recorded yet is drawn after the Stopping line while the chat reads Stopping, as a message held behind a running command already is; once the host hands it over it opens its own turn. Client presentation only. * fix(native-chat): keep a send in doubt when a turn was open for it The derived withdrawal read a turn as open for a send only if it still ran or was written after the send. A send steered into a running Codex turn whose interrupt failed met neither once the adapter's end settled that turn ahead of the host's settle, so it read withdrawn, though Codex drains a steer into the running turn and may hold it. A turn that ended after the send was handed over was open for it too: such a send stays in doubt, as before. Pins that case, and that a send made after the Stop, to a child that then dies before its turn opens, stays in doubt. * fix(native-chat): restore the per-card queue pause label Kept after all: a paused queue labels only the cards it holds (heldByPause), which is visible only where the host advertises the queued-messages capability. * fix(native-chat): draw only a send made while Stopping after the Stopping line Every send the host had not recorded yet was drawn after the Stopping line, including one made just before the Stop, which the host steers into the turn; it then jumped up into that turn once recorded. The outbox now marks a send made while the chat reads Stopping, and only those wait after the line. * fix(native-chat): withdraw a Codex send by whether it started its own turn, not by timing Whether a turn was open for a send was read from end times: a turn that ended after the send's handover counted. A send made while a Stop ended the turn is handed over once that turn reads ended, yet Codex's own end for it can arrive later, so such a send whose own turn never opened read in doubt again, and the chat's queue held behind it. The handover already records where the send went: its message joins the turn running then (a steer) or belongs to no turn (it starts its own). Only a send that started its own turn, with none opened since, is withdrawn; one that joined a running turn, or has no recorded place, stays in doubt. The Codex test fake takes an answered interrupt as Codex does, dropping the turn before its end arrives. * refactor(native-chat): move queue-while-stopping to its own follow-up The queued-messages capability is off on every shipped host (#21062), so the parts of this PR that act only when it is on move to a follow-up stacked on this one: admitting a queued card while a Stop holds the session's lane, a card queued after a Stop running past the cards it holds, the per-card pause mark, and asking the host to queue a send made while Stopping. This PR keeps the Stopping state, the host's steer hold, the rule that never steers a turn whose interrupt Codex answered, and what a send while Stopping looks like where the queue is off. * fix(native-chat): leave no Stop row when the Stop took back a send that never ran A Stop on a Codex send whose turn never opened ends the child, and the child's end takes the send back into the composer. The Stop still wrote "Cancellation requested." at the conversation level, so with the send gone it sat under the previous finished turn and read as if that turn had been stopped. A Stop that found no turn running and whose child end took back every send it found now writes no row; a Stop of a running turn, or one that leaves a send in doubt, still does. * feat(native-chat): keep a message a Stop took back on screen, with one stop row after it A Stop that took back a message before the agent started it used to remove the message from the transcript and paste its text back into the sender's composer. Other devices just lost it, and with the message gone there was nowhere for a stop row to sit, so it either landed under the previous finished turn or was left out. The message now stays where it was sent, on every client, followed by one row, "Stopped before the agent started" (one row after several taken back together). A message whose turn had opened stays in that turn, whose "Interrupted" header already says it was stopped. A queued card's hand-off is still held by the card. Nothing the host recorded refills the composer any more. Text this client's own Stop took before the host ever had it still comes back, and only into an empty composer. Derived from facts the journal already holds (the rejected submission's cancelled verdict and its user item); nothing new is stored or sent. * fix(native-chat): one stop row per stopped send, drawn where the Stop took it, and nothing lost - A message this window's Stop took before the host had it, which the composer cannot take (it holds text or images, or no composer shows the chat), now stays in the outbox as not sent, on its Retry, instead of vanishing. - A Codex send whose turn opened but was never echoed belongs to that turn: its interrupted end is the stop, so no second row is drawn. A send taken back after a later turn started still gets its own row. - A steer the Stop took back stays in the turn it joined, with no row of its own. - A queued send taken back before its hand-over is drawn after the turn it waited behind, not inside it. - The conversation outline the host serves still leaves out sends a Stop took back, and the rail gives them no tick, so what the host publishes is unchanged. - The row is drawn as the Stop's own status rows are, and never folds behind a settled turn on a host that states no turn scopes. * fix(native-chat): draw a stopped follow-up after the turn that opened while it waited A follow-up sent just before the agent opened its turn, then stopped, drew its "Stopped before the agent started" row above that turn's own "Cancellation requested." whenever the turn was expanded. A send a Stop took back is now drawn after the rest of every turn it waited on: the one it was accepted behind, and any that opened after it and before the Stop took it back. Also corrects the stoppedBeforeStart doc to what sets it. * fix(native-chat): place a stopped send by journal order, not by turn start time The turn a stopped send waited on was picked by comparing the turn's start time with when the Stop took the send back. A Codex resume rewrites every finished turn's start time to Codex's whole seconds, so after a restart (or a child respawn) a turn opened for a later send could read as started first, and the stopped send dropped below that whole later exchange. A turn is now waited on when something sent before the stopped send opened it, read from the journal's own order only. Covered end to end through a restart whose resume reports whole-second start times. * test(native-chat): pin a stopped send held behind the first send's answer A second send made while Codex still held the first send's turn/start answer, then a Stop: the first turn opens after the second was accepted and streams after the Stop. The stopped second send and its row are drawn after that turn's output, never between the turn's header and its output. Fails on the two earlier placement rules. The restart case moves into the same file. * docs(native-chat): say why the pre-echo anchor still compares times * docs(native-chat): mark the pre-echo anchor's time compare temporary (STA-9337) * docs(native-chat): say the placement rule reads journal position, not send time * fix(native-chat): keep sends a Stop took back in the order they were sent Two sends queued during /compact, the first handed over and the second not, then a Stop that took both back: the handed-over one sat at its handover row and the other at its acceptance, so the second drew above the first. Among sends a Stop took back, a later-sent one is now drawn no earlier than just after an earlier one. Sent order is submittedAt, the host's accept time and the order every client already keeps submissions in, because a client never sees a handed-over send's acceptance position (STA-9337). * fix(native-chat): draw a stopped send below everything sent before it A send a Stop took back that was never handed over could still draw above an earlier send's whole exchange when that earlier send was not itself taken back: three queued during /compact, the first ran and finished, the second was left in doubt, and the Stop took back only the third. A stopped send is now drawn no earlier than the latest loaded row of anything sent before it, and the turns it waited on are read from that point, so the earlier exchange stays above it. * fix(native-chat): count a turn opened by the floor row as one the stopped send waited on When the latest row sent before a stopped send was itself a turn's opener, that turn compared equal to the floor and was not counted, so the stopped send landed inside the earlier send's exchange: two queued during /compact, the first handed over and streaming, then a Stop took back the second. A turn whose opener sits at or before that point now counts, and the send draws after the whole exchange. * feat(native-chat): publish each submission's journal positions A client never learned where in the journal a send was accepted or taken back, so drawing a stopped send had to guess from its own row and from clocks, and the guesses misfired after restarts. Each projected submission now carries `submittedSequence` (its submission row) and `resolvedSequence` (the dispatch row that resolved it; absent while pending): two optional fields, computed on every fold from rows already stored, never stored themselves. Older clients ignore them. The failure-fact schema moves to its own module to keep the journal schema file within its size limit. * fix(native-chat): place a stopped send by the journal row that took it back Hosts now publish where each submission and its resolving row sit in the journal (cherry-picked from #25073). The projection places a send withdrawn before it started at that row, keeps stopped sends in their published submission order, and falls back to the send's own row on hosts that publish neither. * test(native-chat): pin a submission's resolved position on the provider-echo accept path Also say which rows can resolve a submission, and that the submission schema, not the shared type, omits acceptedSequence. (cherry picked from commit 58a1ade5048669b1aadbac65799a6913152a9981) * fix(native-chat): keep the previous placement rules for a host that publishes no positions On a host from before the published journal positions, a stopped send is again drawn after the latest row of anything sent before it, as before the switch, so it no longer draws above the earlier exchange. Temporary until a host version floor. Also pins the published row against tied accept times. * perf(native-chat): place stopped sends in one pass, and skip it in chats with none The message projection runs on every streaming commit. It now builds turn anchors, the item lookup and the older-host floor only when the chat has a send a Stop took back, and places each such send with a binary search over the turns' furthest rows instead of rescanning every item per send. Draws are unchanged. * fix(native-chat): count a send whose answer was lost when a Stop takes it back The no-row rule counted only pending sends, but the child's end also takes back a send this process left in doubt when Codex's turn/start answer was lost. That case still wrote "Cancellation requested." under the previous turn. Both now read one predicate, so they cannot drift apart. * test(native-chat): pin which sends a Stop's child end can take back A send an earlier process left in doubt is never withdrawn and never holds the row back, and a queued card's send is never counted. * fix(native-chat): read the host's Stopping beside main's startup phase Main now reads only the startup phase from the status feed and no longer publishes which child is starting. The chat reads the host's Stopping from its own hook beside it, and the Stopping bridge test mocks the execution-host lookup main's owner resolution now calls. * test(native-chat): phone draws the same from merged frames as from a fresh snapshot A long chat whose last send never opened and was taken back at the child's exit, right after a send made while a Stop was ending the turn before it. From every subscribe point, at every later frame and with frames that carry one to three rows, the phone's list built from merged frames must equal the list built from a fresh snapshot of the same journal. * test(native-chat): widen the merged-vs-snapshot guard to content, long chats and the phone hooks The guard compared row ids and turn bars only, never left the phone's first window, put each row's writer fence on every batch, and stopped at the fold. It now: - compares each row's content, so a phone that kept an earlier revision of an answer or a status fails it; - adds a chat longer than the phone first loads, compared from the fresh page's first user row on (a turn whose user row the page cut off is keyed differently there); - sends batches at the subscriber's fence and a fresh snapshot when the fence moves, as the host's attach does; - writes the send made while stopping while the turn still runs, adds the provider's echo of each send, and a status row the provider drops; - adds a hooks test: a phone that sent the never-opened message itself, holding its echo and reading the host's Stopping from the status feed, shows the same list after every frame as a phone that opened the chat fresh then. * test(native-chat): pin the stop row to every frame from the one that took the send back Both guards compared a merged phone with a fresh one, so a list bug they shared passed, including one that held the stop row back until the next send. Both now check, at every frame from the take-back on, that the list itself shows the stop row: the data test through the list's own turn disclosure, the hooks test on the live and the fresh phone. Also: - the send made while stopping is written after the stopped turn's end, as the QA journal shows, and while the turn still runs, as a second case; - the long chat revises and drops a status near its end, inside the window; - each phone reduces its own copy of every frame; - Stopping is checked on the never-opened send's own Stop; - the headers say what neither guard covers; - the mobile production typecheck leaves *.test-fixture.ts to the tests' program, as it does tests, since these fixtures import desktop host code. * test(native-chat): check the stop row in the chat view's FlatList, through the real overlay The hooks guard rebuilt the overlay and chat view by hand, so a memo in the real view that held its list back until the next send passed it. The guard now renders the real overlay and chat view from the phone's own hooks, and checks the stop row in the FlatList's data at every frame from the one that took the send back. It also subscribes once before the history's last dropped status, so removals run through the real hooks too. * test(native-chat): compare the live and fresh phone on the chat view's own FlatList The hooks guard compared a hand-built copy of the overlay and view, so a memo in the real ones keyed on list lengths kept stale rows past it. It now compares, after every frame, what the real chat view hands its FlatList: each row as its renderItem draws it, with its bar, and the footer. The hand-built copy is gone. It also checks that the FlatList's keys never collide and that a changed list never arrives in the same array, and the controller stub's SAFETY note now states what the stub really provides. * test(native-chat): read the outbox reconcile from where main moved it * test(native-chat): pass the projection's options and mock the phone row's new imports after main's rejected-in-place rows * refactor(native-chat): place a taken-back send by where the host now puts its row #24710 moves a rejected send's row, a Stop's take-back included, to the row that rejected it, in no turn. Draw it at that row, past the end of every turn opened before it, and keep the send-order rule. A send whose turn opened before the provider echoed it is claimed by that turn's record when it was sent before the record and taken back after it, by submittedSequence, and is drawn as the turn's opener. The steer branch goes: the host no longer says which turn a taken-back steer joined, so it is drawn after that turn with its own row. The older-host fallback (floor, clock compare, submittedAt order) is now gated on submittedSequence alone and marked Temporary. resolvedSequence is gone, as in #25073. * test(native-chat): a turn recorded before a send was made is not the turn it opened * test(native-chat): a message a Stop withdrew is drawn with its stop row, not hidden #24710's tests pinned a withdrawn send as hidden, the rule this PR replaces. Each keeps what it is about: a withdrawn copy does not hide a failed one, no delivery notice is raised, and a message the host failed to deliver stays hidden on the phone. * fix(native-chat): a retried message no longer waits behind a later Stop Retry dropped the Stop it had outlived but kept the mark that it was sent while a Stop was ending a turn, so a retried message waited behind whatever later, unrelated turn a Stop was ending. Retry is a new send: drop that mark too. * feat(native-chat): publish the turn a withdrawn Codex send was answered into Same change as #25073 at 93749070e48b, so this stack builds on it. * feat(native-chat): say how a withdrawn Codex send joined the turn it names Same change as #25073 at ab2826ee1854, so this stack builds on it. * fix(native-chat): open a turn for a stopped send only when the host says it started it A send a Stop took back after its turn opened but before Codex echoed it is drawn as that turn's opener when the host names the turn and says the send started it. A steer into that turn keeps its own row after the turn. The guess from journal order and times is kept only for hosts that publish neither field, and never hands a turn the provider resumed on its own to a send. A page that starts inside such a turn draws the send before the turn's first loaded row. * test(native-chat): an echoed opener keeps its turn from a send the host says started it * feat(native-chat): state on every rejection whether it names a turn Same change as #25073 at e02f98add56b, so this stack builds on it. * fix(native-chat): place a stopped send from older history by journal order A rejection written before the host named turns carries no answered turn, though a newer host still publishes where it was sent and has moved its row to the take-back. Such a send is matched to its turn by journal order again, as before the host named turns; a rejection that states no turn opens none. * docs(native-chat): say an unreadable answered turn reads as none Same change as #25073 at 4ab6cc431c01. * refactor(native-chat): order stopped sends without non-null assertions One helper sorts by the published send position when every entry has it, else by accept time, and both stopped-send sorts use it. The rule kept for rejections written before the host named turns is labelled as kept for good: it draws those rows exactly as before. * docs(native-chat): say which half of the older-history turn rule is kept for good * fix(native-chat): word a send after a Stop by whether this send will queue The 'queue a message to run after the stop' placeholder read the host's queue capability alone. A send queues only when the host queues and this send asks it to: the queue setting is on and no pending prompt blocks the queue. Desktop and phone now word the placeholder from that same decision their send uses. * test(native-chat): one test per case for the words of a send after a Stop * refactor(native-chat): the dictation hook owns the composer's dictation state Keeps…

ELI5
A message you sent in a desktop structured chat could vanish after Orca crashed. Orca had taken the message, then couldn't deliver it, and the only thing that would have shown it was a copy the app keeps in browser storage, which a crash often never saves. Now the chat always shows that message, marked "Not sent" with the reason, at the point where it failed. Orca reads it from its own chat history, so a crash can't erase it.
What Changed
The problem as you saw it.
Why it happened. The desktop chat hid every rejected message unless that browser-storage copy (the outbox) still held it. The outbox is saved lazily, so after a crash it is often missing. Orca's own history still had the message and the reason it failed; the chat just never drew it.
Before: after a crash, a message Orca accepted and then rejected disappears. Without a crash, it shows "Not sent" with a Retry, at the bottom of the chat.
After (desktop):
/compactstays hidden, as before. The command reports its own failure in the composer.Mechanism.
JournalRowWriter.enqueueRows), rejections first. No reader ever sees one without the other, and the messages read above the row. If a Stop withdrew every queued message first, nothing is written: the failed start failed no one.Why
Orca already keeps every message it accepts, with the reason it failed. Drawing the chat from that history makes the failure visible on every reopen, crash or not, instead of depending on a second copy a crash can lose. It also means one stored fact always looks the same. This is the common pattern: a message the server recorded and then rejected stays in the conversation with its error, and there is no per-message Retry; you send it again.
Alternatives considered:
Differences from the common pattern
keptAsQueuedMessageId). Whichever of the two PRs lands second switches this rule to that field, so editing or deleting a kept card never brings the row back for users.Linked Issue
None (maintainer). Follow-up to #24461.
Visual Proof
Live run on a separate Mac against a hidden dev build of this branch. The crash and failed-start shots are from the final head 50c957b; the in-doubt, Stop and upgrade shots are from 7f7636e (later commits change only how the outbox settles its copies).
Killed while the agent was still starting; after relaunch, one "Not sent" row with the reason and no controls:

The same, in a new chat where it is the only message (not hidden behind the empty "start a chat" view):

Killed one second after a message sent into a running turn: its delivery is in doubt, so it stays a plain message, once, never "Not sent":

The agent failed to start: "Your message was not sent." sits above the "did not start" row (same after relaunch):


Stop on a message waiting behind /compact: no row; its text is back in the composer:

Upgrade: before, on main, "Not sent" with Retry; after Retry delivered it, the same profile on this branch shows only the delivered copy, no stale "Not sent" copy:


Testing
Host: placement.
journal-rejected-message-placement.test.ts:Host: atomic start failure.
journal-queued-rejection-batch.test.ts: rejections first, then the row; a row that can't be written writes neither; a Stop that withdraws every queued message first means nothing is written.journal-row-writer.test.ts: rows written together roll back together.Desktop.
structured-agent-session-message-projection.rejected-in-place.test.ts: in-place drawing; host words with no Retry; the start-failure wording; the supersede rule either way; withdrawn; queued-card and hand-off hiding;/compact; an older host's position; the phone option.use-structured-agent-session-outbox-rejection-cause.test.tsx: the outbox lets go once the host's record is held, and storage is cleared; the same stored rejection has no Retry and no other control on a first and a second open; the copy goes away with no user action once its row loads (live batch, reopen, older page).structured-agent-session-delivery-notices.test.ts: refusals keep Retry; host-recorded messages carry no control.structured-agent-session-message-projection.recorded-copy.test.ts: a recorded copy goes away with no user action in every case (new host live, reopen, older host's older page), never carries a control, and is never sent again.use-structured-agent-session-delivery-notices.test.tsx: notices stay the same objects across unchanged batches.use-structured-agent-session.rejected-card.test.tsx: queued card ids flow from the session controller.Ablations. Each rule was removed in turn, and a test went red.
Totals. 429 test files covering the journal, the host session wire, and native chat pass (3992 tests). The changed-code quality gate, React Doctor, and oxlint on changed files pass.
I manually tested these changes locally
Automated tests added/updated, or explained why not below
Review
Agent skill upstream boundary
docs/reference/agent-skill-sharing-upstream-boundary.mdand copies or mechanically translates no upstream skill-installer source, tests, fixtures, registry entries, path tables, comments, or documentation.Notes
Mixed versions. The journal row format does not change, but what the host publishes does, in two ways:
Older desktops and the phone hide rejected messages, so they see no change. An older desktop whose outbox still holds the message draws that copy at the new position. An older host does not move anything, so this desktop shows the message at its original position. When that position is older than the loaded page, the outbox copy keeps showing it (in Orca's words, no controls) until that page loads, and then the host's row takes over. If a crash also lost the outbox copy, the message appears only once you scroll back to it.
Legacy chats. In a chat whose failed start was written by an older version (row first, then rejections), the failed messages read just below the "did not start" row instead of above it. This is cosmetic; new chats read above.
SSH and remote hosts. The placement is computed by whichever host owns the chat, from its own journal. Clients only read it. Loss of contact is never read as a rejection.
Folder workspaces. No dependence on workspace type.
Performance. Moving a message is one map update per rejection. The notices and the command set are recomputed only for chats with a "Not sent" message, and they are kept identical across unchanged batches.
Checklist
N/Awith reasonpnpm lint,pnpm typecheck,pnpm test, andpnpm buildpass (or CI will cover; local preferred)