Skip to content

fix(native-chat): show a message Orca accepted and then failed to deliver as "Not sent" in the chat - #24710

Merged
brennanb2025 merged 24 commits into
mainfrom
brennanb2025/rejected-message-shows-in-chat
Oct 4, 2026
Merged

brennanb2025 merged 24 commits into
mainfrom
brennanb2025/rejected-message-shows-in-chat

Conversation

@brennanb2025

@brennanb2025 brennanb2025 commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor
Files Added Deleted Net
Test 45 $\color{#1a7f37}{\Huge{\mathbf{+}}}$​2377 $\color{#cf222e}{\Huge{\mathbf{−}}}$​276 $\color{#1a7f37}{\Huge{\mathbf{+}}}$​2101
Prod 28 $\color{#1a7f37}{\Huge{\mathbf{+}}}$​577 $\color{#cf222e}{\Huge{\mathbf{−}}}$​209 $\color{#1a7f37}{\Huge{\mathbf{+}}}$​368

ELI5

A message you sent in a desktop structured chat could vanish after Orca crashed. Orca had taken the message, then couldn't deliver it, and the only thing that would have shown it was a copy the app keeps in browser storage, which a crash often never saves. Now the chat always shows that message, marked "Not sent" with the reason, at the point where it failed. Orca reads it from its own chat history, so a crash can't erase it.

What Changed

The problem as you saw it.

  • You send a message. Orca records it and answers "got it". Then, before the agent receives it, something goes wrong: Orca is killed, the app quits mid-turn, the agent fails to start, or a message sent into a running turn is never picked up.
  • Orca marks that message rejected in the chat's history. Reopen the chat, and the message isn't there at all. There's no error and no hint to send it again.
  • Even when the message did show, it looked different depending on luck. If the browser-storage copy had been saved, you saw "Not sent" with a Retry button. If it hadn't, you saw nothing.

Why it happened. The desktop chat hid every rejected message unless that browser-storage copy (the outbox) still held it. The outbox is saved lazily, so after a crash it is often missing. Orca's own history still had the message and the reason it failed; the chat just never drew it.

Before: after a crash, a message Orca accepted and then rejected disappears. Without a crash, it shows "Not sent" with a Retry, at the bottom of the chat.

After (desktop):

  • The message shows where it was rejected, marked "Not sent" with the reason in Orca's words. For example: "Orca restarted before this message was sent."
  • If the agent failed to start, the messages it failed read only "Your message was not sent." They sit directly above the "did not start" row, which says why.
  • A message Orca recorded has no Retry button. To send it again, you send it again; it is a new message. No "Not sent" message has any button. While Orca's row for it is not loaded yet, the saved outbox copy shows it instead, and goes away by itself once that row loads.
  • A message Orca refused before recording it, for example while the chat history couldn't be read, keeps its Retry. Only the outbox ever had it, so Retry is the only way to send it.
  • A message you took back with Stop stays hidden; its text already went back to your composer.
  • A rejected message that is held as a queued card above the composer shows as that card, not also as a row.
  • A rejected /compact stays hidden, as before. The command reports its own failure in the composer.

Mechanism.

  • The host owns the position. When the host records a rejection, its history reducer moves the message to the rejection's place in the journal, in no turn. This covers a message that waited behind a running turn, one delivered into a turn and then rejected, and one sent directly. It mirrors how the host already places a queued message where it is handed over. A message whose delivery is only in doubt never moves: it may have reached the agent, so it stays a plain message.
    • The new position travels in the same journal updates and history pages clients already read, so a recent rejection is always on the newest loaded page.
  • A failed start is written in one step. The queued messages' rejections and the "did not start" row now go into the journal in one transaction (a new JournalRowWriter.enqueueRows), rejections first. No reader ever sees one without the other, and the messages read above the row. If a Stop withdrew every queued message first, nothing is written: the failed start failed no one.
  • The outbox lets go once the host's record is held. When the chat holds the host's rejected record of a message, the outbox drops its copy and saves that drop, so the chat no longer reads as owing a delivery. The host's row is the message from then on.
    • Placing the message at its rejection had to come with this change: once the outbox lets go, a message drawn where it was sent was drawn nowhere when that point was older than the loaded page (reproduced in review). On main the outbox copy had covered that case.
    • This brings part of step 3 of the planned outbox removal forward. The outbox now lets go of every message Orca recorded and then rejected, and those messages lose their Retry. The rest of that step, and the outbox's removal itself, are unchanged and still to come.
  • Retry is decided from what is stored, the same way on every open. If the outbox entry says the host recorded the message, it has no Retry and no other control. If the host refused it without recording it, it keeps Retry.
  • One rule decides what the chat shows, and the per-message notices use the same rule:
    • withdrawn by Stop: hidden;
    • held by a queued card (a draft's hand-off, or a card under the same id): hidden;
    • a command: hidden;
    • superseded by a later copy of the same text, sent once the rejection was known: hidden.
  • The outbox writes only on change. Its reconcile returns the same entries and list when a journal batch settles nothing, so streaming writes nothing to storage. A copy Orca recorded and rejected owes no delivery, so it never keeps a hidden chat reading its history.
  • Stable notices. A new batch that leaves every "Not sent" message unchanged keeps the same notice objects, so no row re-renders.

Why

Orca already keeps every message it accepts, with the reason it failed. Drawing the chat from that history makes the failure visible on every reopen, crash or not, instead of depending on a second copy a crash can lose. It also means one stored fact always looks the same. This is the common pattern: a message the server recorded and then rejected stays in the conversation with its error, and there is no per-message Retry; you send it again.

Alternatives considered:

  • Make the outbox save synchronously. That narrows the crash window but keeps two sources of truth, which have disagreed before.
  • Leave the message at the point where it was sent. A message that waited behind a long turn would jump hundreds of rows up. If that point was older than the loaded page, the chat drew it nowhere at all; the review reproduced this.
  • Keep the old start-failure write order (row, then rejections) and move only the messages. The failed messages then read below "did not start". Swapping the order as two separate writes would open a moment with neither the queued message nor the row, where a second "did not start" row could be written. One atomic write avoids either problem.

Differences from the common pattern

  • Intended: a later copy of the same text hides an earlier rejected one, but only if the later copy was sent after the rejection was known. With this PR, Retry no longer resends a message Orca recorded under a new id, so it creates no new pairs. The rule now covers history already in existing chats, plus Orca's own messages that it re-delivers under a new id. Orca-observed failures without it:
    • Earlier versions' Retry resent a rejected message under a new id, so existing chats contain rejected-then-resent pairs that would all show a stale "Not sent" copy after the update.
    • Orca re-delivers its own messages (orchestration pointers) under new ids. A real journal held four rejected copies of one such message, and without this rule all four draw as "Not sent".
    • A deliberate repeat sent before the first one failed stays visible.
  • Intended: the message is drawn where it was rejected, not where it was sent. Drawn where it was sent, a message that waited behind a long turn jumped hundreds of rows up, and when that point was older than the loaded page it was drawn nowhere at all (reproduced in review). At the rejection it is always on the newest page.
  • Temporary: the phone still hides these messages and puts a rejected message's text back in its composer. Follow-up: the phone draws rejected messages in place, as the desktop now does, and stops restoring the text.
  • Temporary: the host's conversation outline does not list rejected messages. Their rail tick appears once their page is loaded. Follow-up: include them in the outline behind a client capability, because older desktops hide these rows.
  • Temporary: with no Retry on a message Orca recorded, its images can't be resent with one click. Text can be copied. Follow-up: composer recall derived from the chat's own messages, including attachments.
  • Temporary: a copy saved before a crash can stand in for Orca's row until that row's page loads. If the chat reopens and Orca's record of the rejection is older than the loaded page, the saved copy shows the message as "Not sent" with its reason and no controls, exactly once, at the end of the chat; it goes away by itself when that page loads. The follow-up that removes the desktop outbox entirely also removes these copies.
  • Temporary, landing order with fix(native-chat): keep a message accepted before a quit or crash as a held card #24660: a rejected message held as a queued card is hidden while that card exists. Kept cards exist only once fix(native-chat): keep a message accepted before a quit or crash as a held card #24660 lands, and fix(native-chat): keep a message accepted before a quit or crash as a held card #24660 records the fact durably on the rejected message (keptAsQueuedMessageId). Whichever of the two PRs lands second switches this rule to that field, so editing or deleting a kept card never brings the row back for users.

Linked Issue

None (maintainer). Follow-up to #24461.

Visual Proof

Live run on a separate Mac against a hidden dev build of this branch. The crash and failed-start shots are from the final head 50c957b; the in-doubt, Stop and upgrade shots are from 7f7636e (later commits change only how the outbox settles its copies).

Killed while the agent was still starting; after relaunch, one "Not sent" row with the reason and no controls:
queued then crash

The same, in a new chat where it is the only message (not hidden behind the empty "start a chat" view):
only message

Killed one second after a message sent into a running turn: its delivery is in doubt, so it stays a plain message, once, never "Not sent":
in-doubt steer

The agent failed to start: "Your message was not sent." sits above the "did not start" row (same after relaunch):
failed start
failed start after relaunch

Stop on a message waiting behind /compact: no row; its text is back in the composer:
stop withdraws

Upgrade: before, on main, "Not sent" with Retry; after Retry delivered it, the same profile on this branch shows only the delivered copy, no stale "Not sent" copy:
main before retry
upgraded

Testing

  • Host: placement. journal-rejected-message-placement.test.ts:

    • A queued message, a message delivered into a turn, and a direct send each move to their rejection, in no turn.
    • The moved message reaches subscribers and the newest page.
    • A message in doubt does not move and is not drawn "Not sent".
  • Host: atomic start failure.

    • journal-queued-rejection-batch.test.ts: rejections first, then the row; a row that can't be written writes neither; a Stop that withdraws every queued message first means nothing is written.
    • journal-row-writer.test.ts: rows written together roll back together.
    • Existing tests still pass: "draws the messages it failed above the error row" and the two view-start tests.
  • Desktop.

    • structured-agent-session-message-projection.rejected-in-place.test.ts: in-place drawing; host words with no Retry; the start-failure wording; the supersede rule either way; withdrawn; queued-card and hand-off hiding; /compact; an older host's position; the phone option.
    • use-structured-agent-session-outbox-rejection-cause.test.tsx: the outbox lets go once the host's record is held, and storage is cleared; the same stored rejection has no Retry and no other control on a first and a second open; the copy goes away with no user action once its row loads (live batch, reopen, older page).
    • structured-agent-session-delivery-notices.test.ts: refusals keep Retry; host-recorded messages carry no control.
    • structured-agent-session-message-projection.recorded-copy.test.ts: a recorded copy goes away with no user action in every case (new host live, reopen, older host's older page), never carries a control, and is never sent again.
    • use-structured-agent-session-delivery-notices.test.tsx: notices stay the same objects across unchanged batches.
    • use-structured-agent-session.rejected-card.test.tsx: queued card ids flow from the session controller.
  • Ablations. Each rule was removed in turn, and a test went red.

  • Totals. 429 test files covering the journal, the host session wire, and native chat pass (3992 tests). The changed-code quality gate, React Doctor, and oxlint on changed files pass.

  • I manually tested these changes locally

  • Automated tests added/updated, or explained why not below

Review

Agent skill upstream boundary

  • Not applicable, or this change follows docs/reference/agent-skill-sharing-upstream-boundary.md and copies or mechanically translates no upstream skill-installer source, tests, fixtures, registry entries, path tables, comments, or documentation.

Notes

  • Mixed versions. The journal row format does not change, but what the host publishes does, in two ways:

    • A rejected message now carries the position of its rejection.
    • A failed start's rows arrive as one group, rejections first.

    Older desktops and the phone hide rejected messages, so they see no change. An older desktop whose outbox still holds the message draws that copy at the new position. An older host does not move anything, so this desktop shows the message at its original position. When that position is older than the loaded page, the outbox copy keeps showing it (in Orca's words, no controls) until that page loads, and then the host's row takes over. If a crash also lost the outbox copy, the message appears only once you scroll back to it.

  • Legacy chats. In a chat whose failed start was written by an older version (row first, then rejections), the failed messages read just below the "did not start" row instead of above it. This is cosmetic; new chats read above.

  • SSH and remote hosts. The placement is computed by whichever host owns the chat, from its own journal. Clients only read it. Loss of contact is never read as a rejection.

  • Folder workspaces. No dependence on workspace type.

  • Performance. Moving a message is one map update per rejection. The notices and the command set are recomputed only for chats with a "Not sent" message, and they are kept identical across unchanged batches.

Checklist

  • This PR is small and focused (it is focused on one bug, but touches the host's journal writer to make the failed-start write atomic)
  • I explained what changed and why (ELI5, the user-facing before/after, the mechanism, and why over the alternatives)
  • Before/after screenshots or videos attached for UI changes, or N/A with reason
  • Self-reviewed for correctness, security, and performance
  • Cross-platform, SSH/remote, and path/shortcut impact considered (or N/A)
  • pnpm lint, pnpm typecheck, pnpm test, and pnpm build pass (or CI will cover; local preferred)

…he desktop chat as not sent

Draw it in place from the host's history, so a crash that loses the outbox no
longer makes it vanish. A later copy of the same body supersedes it; the outbox
row wins while it holds the message; the phone is unchanged.
…en rejected

Once the host's journal records a send as rejected, the desktop outbox lets it
go, as it already does for delivered and Stop-withdrawn sends: the host's row
shows it as not sent, with the host's reason and no Retry. The outbox keeps
only sends the host refused before recording them, which keep their Retry.
A send whose own reply says it was rejected is drawn by its outbox entry, with
no Retry, until the journal carries the row; a copy left by an earlier session
is dropped when the chat opens.

- the transcript no longer hides a host row behind an outbox entry with the
  same id or the same text; those rules and their cache are gone
- a rejected message the queue holds (a draft's hand-off, or a live card under
  its id) is drawn as its card, not as a row
- a later copy of the same text hides a rejected row only when it was sent
  once the rejection was known, so a deliberate repeat stays
- delivery notices read the same visibility rule as the transcript; a chat
  whose only rejection a Stop withdrew no longer rebuilds them per batch
- the body fingerprint helper goes back to the host, its only user
…age go

- the outbox no longer drops a host-rejected message when a chat opens; the
  reconcile lets it go once the journal's submissions say it was rejected, and
  that drop is written to storage, so nothing reads as still owed
- a message the host rejected while the chat watched waits for its journal row
  with no Retry; one read back from storage with no row loaded keeps its Retry
  under a new id, since the host may have lost it
- the delivery notices keep the same map and notice objects across a batch that
  words every row the same, so a submission batch re-renders no row
- a rejected command such as /compact stays hidden: its own reply reports it
- the desktop transcript requires the queued card ids, with a controller-level
  test that a card holding a rejected message keeps its row hidden
A message accepted to hand over later and rejected before any handover now sits
at its rejection, as a handover places one: what the agent did while it waited
happened before it, and the newest history page holds it. One handed over, or
dispatched as it was recorded, keeps its place. An older host does not move it,
so it stays at its submission, still drawn.

A failed start now rejects the queued messages and writes its row in ONE
journal append, the messages first: no reader ever meets one without the
other, and the messages still draw above the row that says why.
Not only a queued message: one handed over into a turn and then rejected, or
sent directly and rejected, also sits at its rejection, in no turn. A message
in doubt stays where it was, a plain bubble: it may have reached the agent.
…tored fact

- a message the host recorded and then rejected has no Retry on any mount,
  however that mount learned of it, and a Dismiss that clears it from storage;
  a send refused before the host recorded it keeps its Retry
- the rule that keeps a rejected command such as /compact out of the
  transcript moves into the one visibility function rows and notices share
- the outbox state docs say what lets a recorded message go: the client holding
  its rejected submission, whose row the host places at the rejection
… loads

An older host leaves a rejected message where it was sent, which may be older
than the loaded window: the chat then holds the rejected submission but not the
row that draws it. The outbox copy now stays until that row loads, marked as
the host recorded it (Dismiss, no Retry, in the host's words), and leaves once
the page holding the row is loaded. Derived from the loaded rows each time.

Tests that label their projection as the phone's now pass the phone's own
setting.
…in the outbox

The outbox re-reads the journal on every batch since it waits for a rejected
message's row to load. Its reconcile now returns each unchanged entry, and the
list, as themselves (a message left in doubt included), so a batch that changes
nothing writes nothing to storage. The reconcile moves to its own module.

A copy the host recorded and rejected owes no delivery, so it no longer keeps a
hidden pane reading the journal.
@brennanb2025

brennanb2025 commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor Author

Review status

The problem. In the desktop chat, a message you sent could vanish. Orca had accepted it, then failed to deliver it: Orca restarted, the chat closed, the agent failed to start, or a message sent into a running turn was never picked up. The chat only showed such a message while a copy saved in browser storage still had it, and a crash often loses that copy. So after a crash the message was simply gone. Without a crash it showed "Not sent" with a Retry button, so the same failure looked different depending on luck.

What changes for you (desktop).

  • A message Orca accepted and then failed to deliver always shows, marked "Not sent" with the reason, at the point where it failed. It is read from Orca's own chat history, so a crash can't erase it.
  • Those messages carry no button at all; you send the text again. A message Orca refused before ever recording it keeps its Retry.
  • When the agent fails to start, the failed messages read "Your message was not sent." just above the "did not start" row.
  • A message sent into a running turn whose delivery is only in doubt after a crash stays a normal message; it is never marked "Not sent", because it may have reached the agent.
  • A message taken back with Stop, a failed /compact, and a message held as a queued card stay hidden, as before.

What the review changed (the PR now differs substantially from the first version):

  • The host's history is now the only thing that shows such a message: the browser-storage copy lets go once the host's record is loaded, and those messages lose Retry. This brings part of the planned outbox removal forward.
  • The host places a rejected message where it was rejected, not where it was sent. Before, a message that waited behind a long turn jumped hundreds of rows up, or wasn't drawn at all when that point wasn't loaded.
  • A failed start now writes its rejections and its "did not start" row in one step, rejections first. If Stop already took back every waiting message, nothing is written.
  • A later copy of the same text hides an earlier rejected one only if it was sent after the rejection, so a deliberate repeat stays visible.
  • A rejected message held by a queued card no longer shows twice, as a card and as a row.
  • Whether Retry shows is decided from what is stored, the same on every reopen. A saved copy of a message Orca recorded never has a control: it goes away by itself once Orca's own row for it loads.
  • Newer desktop with an older host: the saved copy keeps showing the message until its place in the history loads, then goes away by itself.
  • The outbox writes to storage only when something changed, not on every streamed update.

Deferred (each is listed under "Differences from the common pattern" in the PR description):

  • If the chat reopens after a crash and Orca's record of the rejection is older than the loaded page, the saved copy shows "Not sent" with its reason and no controls until that page loads. Removing the desktop outbox (the planned follow-up) removes these copies.
  • The phone still hides these messages and puts the text back in its composer. Follow-up: the phone draws them in place.
  • The conversation outline doesn't list them; their rail tick appears once their page loads. Follow-up: list them behind a client capability.
  • Images in a rejected message can't be resent with one click; the text can be copied. Follow-up: composer recall built from the chat's own messages.
  • Landing order with fix(native-chat): keep a message accepted before a quit or crash as a held card #24660: kept cards exist only with fix(native-chat): keep a message accepted before a quit or crash as a held card #24660, which records keptAsQueuedMessageId; whichever PR lands second switches the hiding rule to that field, so editing or deleting a kept card never brings the row back for users.
  • Smaller items: chats written by an older version show failed-start messages below the "did not start" row; a moved message's hover time is its rejection time; a failed /compact rejected after the command stopped waiting is reported nowhere, as on main; with an older host, a kept copy can briefly ignore the same-text rule until its page loads.

Verified.

  • On the final head 50c957b: typecheck (node and web) passes, CI is green (PR Checks, Mobile Checks), and 433 related test files (4,002 tests) pass locally. Every new rule was removed in turn and a test went red.
  • Live, on a separate Mac against a hidden dev build of this branch, five scenarios passed (screenshots in the description):
    • crash while a message waited to be sent: one "Not sent" row with the reason, no Retry, also when it is the chat's only message;
    • crash right after a message sent into a running turn: a plain message, shown once;
    • agent fails to start: "Your message was not sent." above the "did not start" row;
    • Stop on a waiting message: no row, text back in the composer;
    • upgrade from main after a Retry: only the delivered copy, no stale "Not sent" copy.

Not verified.

  • Live: a message Orca refuses without recording it, which should keep Retry. The test setup couldn't trigger a refusal; unit tests cover it.
  • Live: newer desktop with an older host. Unit tests only.
  • The phone (unchanged by design), SSH and Windows were not run live.
  • The crash and failed-start scenarios were re-run and passed on the final head 50c957b (no control of any kind on the "Not sent" row). The in-doubt, Stop and upgrade scenarios were run on 7f7636e; later commits change only how the browser-storage copy is released, which is covered by unit tests.

@brennanb2025
brennanb2025 marked this pull request as ready for review October 2, 2026 16:44
@brennanb2025
brennanb2025 marked this pull request as draft October 2, 2026 16:45
… on its own, with no Dismiss

The outbox copy of a message the host recorded and then rejected draws it only
while the host's row is not loaded, and leaves on the batch or page that loads
that row. It owes no delivery and offers no control: sending it again is a new
message. The Dismiss that let the user clear it is gone, from the outbox, the
notices and the session controller.
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (1)
AGENTS.md — auto-discovered

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: c98573d1-5cfe-4564-9306-2e7b0340b211
📥 Commits

Reviewing files that changed from the base of the PR and between 50c957b and 7c7a4c6.

📒 Files selected for processing (14)
  • src/main/native-chat/agent-session-journal/journal-pending-submission-recovery.ts
  • src/main/native-chat/agent-session-journal/journal-row-writer.test.ts
  • src/main/native-chat/agent-session-journal/journal-row-writer.ts
  • src/main/native-chat/agent-session-journal/journal-store-collaborators.ts
  • src/renderer/src/components/native-chat/NativeChatStructuredSession.tsx
  • src/renderer/src/components/native-chat/NativeChatStructuredSessionDelivery.test.tsx
  • src/renderer/src/components/native-chat/structured-agent-session-outbox-retry.ts
  • src/renderer/src/components/native-chat/use-structured-agent-session-outbox-admission.test.tsx
  • src/renderer/src/components/native-chat/use-structured-agent-session-outbox-relaunch-hold.test.tsx
  • src/renderer/src/components/native-chat/use-structured-agent-session-outbox.test.tsx
  • src/renderer/src/components/native-chat/use-structured-agent-session-outbox.ts
  • src/shared/native-chat-types.ts
  • src/shared/structured-agent-session-outbox.ts
  • src/shared/structured-agent-session-send-disposition.ts
🚧 Files skipped from review as they are similar to previous changes (2)
  • src/shared/structured-agent-session-send-disposition.ts
  • src/shared/native-chat-types.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review.


📝 Walkthrough

Walkthrough

The change records queued rejections in the same journal batch as failed-start rows. Rejected messages retain their journal rejection position and can render as unsent messages on desktop. Outbox reconciliation now uses loaded journal rows, while host-recorded rejections use Dismiss instead of Retry. Message projection and session hooks accept queue and journal-row state. Tests cover placement, reconciliation, notices, queue behavior, and mobile projection.

Priority: ➖ Normal

Merge Risk: ⚪ Minimal · up to 7c7a4

The change shows rejected messages in place with the host's reason and no Retry. No concrete merge-blocking issue was found in the supplied material.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 7c7a4

The change improves recovery of failed messages while preserving the reviewed conversation and write controls. No introduced security issue was established. Risk remains low rather than minimal because complete verification of session switching and compatibility with earlier behavior was not available.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The inspected effects concern conversation-message persistence, local retry state, and display. The reviewed notice path adds no independent transport authority, and the writer retains session-bound insertion. These observations do not establish complete cross-conversation isolation for unverified read paths.

Trust Boundaries and Controls

  • observed — Retry looks up entries in the specified session's outbox and changes only the matching client-message identity. Storage reads use session-specific keys and parse entries against that session. Send-result handling discards results from superseded dispatch generations.

Resilience and Maintainability Implications

  • observed — Batch planning runs on the serialized write lane and consults current queued submissions and applied settlement identities. Database failure invokes rollback handling before row adoption. Re-reading unchanged reconciliation state preserves object identity and avoids additional writes.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 31.18% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 93 functions across 57 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly describes the main change: showing a host-recorded delivery failure as “Not sent” in chat. It is specific, though longer than ideal.
Description check ✅ Passed The description covers the required sections with detailed change rationale, visual proof, testing, compatibility notes, and checklist status. The manual-testing checkbox is unchecked despite reported…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ℹ️ No critical issues — one path where the new "Not sent" rule is bypassed.

Reviewed changes

  • Host journal placement. A rejected dispatch row now moves its message item to the rejection sequence, in no turn (placeRejectedMessage), covering queued, handed-over, and direct sends; a message in doubt does not move. The host owns the position, so a recent rejection always lands on the newest loaded page.
  • Atomic start-failure write. JournalRowWriter.enqueueRows writes the queued-message rejections and the lifecycle "did not start" row in one transaction, rejections first, driven by a new JournalLifecycleBatchInput.rejectsQueued. Nothing is written when a Stop withdrew every queued message first.
  • Outbox lets go, and Retry becomes Dismiss. reconcileStructuredAgentSessionOutbox moves to its own module and drops an entry once the rejected submission's own row is loaded; structuredAgentSessionEntryRejectedByHost makes a host-recorded rejection offer Dismiss and no Retry, and owesDelivery stops counting such an entry.
  • One rule for what shows. structuredAgentSessionRejectedShownInPlace decides in-place drawing (withdrawn, queued-card-held, commands, and a copy superseded by a later same-fingerprint send are hidden); desktop delivery notices use the same rule and are held stable across unchanged batches.
  • Mobile passes rejectedInPlace: false and is otherwise unchanged.

Pullfrog  | Fix all ➔ | Fix 👍s ➔ | View workflow run | Using deepseek-v4.1-flash (free via Pullfrog for OSS) | 𝕏

): NativeChatMessage[] {
const optimistic = reconcileStructuredAgentSessionOutboxWithQueue(outbox, submissions)
// Refused sends are ledger evidence, not conversation history; local drafts remain in the outbox.
const optimistic = reconcileStructuredAgentSessionOutboxWithQueue(outbox, submissions, items)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The outbox-drawn copy bypasses the new supersede rule. structuredAgentSessionRejectedShownInPlace hides the host item when a later submission with the same payloadFingerprint was submitted at/after its resolvedAt, but optimistic here is filtered only against journalled (visible items), and reconcileStructuredAgentSessionOutbox keeps a rejected entry whenever its own row is not in the loaded items. So when the superseded message's host row is outside the loaded/retained window (the client retains only the newest items but mergeSubmissions keeps up to 256 submissions), its outbox entry still draws — a delivered resent row plus a stale Not sent row for the earlier copy. I reproduced this: items = [seed, resent], submissions = [seed, old(rejected), resent], outbox = [old(rejectedByHost)] renders three user rows, with old as unsent.

Technical details
# Supersede rule not applied to the outbox-drawn copy

## Affected sites
- `src/shared/structured-agent-session-message-projection.ts:69-72` — the supersede rule that hides the host item.
- `src/shared/structured-agent-session-message-projection.ts:88` — `optimistic` starts from the reconcile, which keeps a rejected entry until its own item loads.
- `src/shared/structured-agent-session-message-projection.ts:134-135` — the optimistic rows are filtered only against `journalled` (visible items).
- `src/shared/structured-agent-session-outbox-reconcile.ts:30-42` — keeps a rejected entry when its row is not in `items`.
- `src/shared/structured-agent-session-reducer.ts:199-203` / `structured-agent-session-item-retention.ts:21-38` — submissions survive item trimming, so a rejected submission can outlive its item.

## Required outcome
- A rejected submission hidden by the supersede rule (or by a queued card, a command, or a withdrawal) must not draw from its outbox copy either; the transcript should show only `resent`.
- The documented fallback must still hold: a rejected message whose host row is not loaded but which is not hidden by the rule keeps drawing from its outbox copy.

## Suggested approach
- Give the outbox path the same hiding decision as the item path — pass `queuedMessageIds`/`commandItemIds` into the reconcile (or the projection's optimistic filter), or have `structuredAgentSessionRejectedShownInPlace` also return the hidden set so `structuredAgentSessionEntryRejectedByHost` entries can be dropped.

## Open questions for the human
- Is a lingering outbox copy acceptable until the outbox is removed, given the stale row carries a Dismiss?

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ℹ️ No new issues in this delta — the prior finding still stands.

Reviewed changes (delta against the prior review at 831e8eb1)

  • Dismiss removed. 804ca8c69d drops the Dismiss action from host-recorded rejection notices and the outbox hook. A host-recorded rejected copy now renders as text with no control on every mount, and leaves only when its row loads. The notices no longer build the outboxDraws set, and dismiss is gone from useStructuredAgentSessionOutbox and the session controller.
  • Tests updated. use-structured-agent-session-outbox-admission.test.tsx, structured-agent-session-delivery-notices.test.ts, the recorded-copy/older-host projection tests, and use-structured-agent-session-delivery-notices.test.tsx now assert no control and self-retirement. All pass locally (38 tests across the five touched suites).

The prior review's finding is unaffected: the shared projection and reconcile are unchanged by this delta, so a superseded rejected message whose host row is outside the loaded window still draws its outbox copy.

Pullfrog  | Fix it ➔ | View workflow run | Using deepseek-v4.1-flash (free via Pullfrog for OSS) | 𝕏

@brennanb2025
brennanb2025 marked this pull request as ready for review October 2, 2026 17:50

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ℹ️ No critical issues — minor suggestion inline. The head is unchanged since the prior pullfrog review at 50c957b783, so this re-confirms the one previously flagged path and finds nothing new.

Reviewed changes

  • Host journal placement. A rejected dispatch row now moves its message item to the rejection sequence, in no turn (placeRejectedMessage), covering queued, handed-over, and direct sends; a message in doubt does not move.
  • Atomic start-failure write. JournalRowWriter.enqueueRows writes the queued-message rejections and the lifecycle "did not start" row in one transaction, rejections first, driven by a new JournalLifecycleBatchInput.rejectsQueued. Nothing is written when a Stop withdrew every queued message first.
  • Outbox lets go. reconcileStructuredAgentSessionOutbox moves to its own module and drops an entry once the rejected submission's own row is loaded; structuredAgentSessionEntryRejectedByHost makes a host-recorded rejection offer no Retry, and owesDelivery stops counting such an entry.
  • One rule for what shows. structuredAgentSessionRejectedShownInPlace decides in-place drawing (withdrawn, queued-card-held, commands, and a copy superseded by a later same-fingerprint send are hidden); desktop delivery notices use the same rule and are held stable across unchanged batches.
  • Mobile passes rejectedInPlace: false and is otherwise unchanged.

Pullfrog  | Fix all ➔ | Fix 👍s ➔ | View workflow run | Using deepseek-v4.1-flash (free via Pullfrog for OSS) | 𝕏

Comment on lines +30 to +42
if (submission?.dispatchState === 'rejected') {
// Its row draws it once loaded; until then the entry does, as the host recorded it. An older
// host leaves that row where it was sent, which may be outside the loaded window.
loaded ??= new Set(items.map((item) => item.itemId))
if (loaded.has(agentJournalSubmissionKey(entry.clientMessageId))) {
return []
}
const lastFailure = structuredAgentSessionRejectedFailure(submission)
return [
structuredAgentSessionEntryRejectedByHost(entry)
? entry
: { ...entry, state: 'rejected' as const, lastFailure }
]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A rejected submission hidden by the supersede rule still draws from its outbox entry here whenever its host row is outside the loaded window, so a stale "Not sent" can appear beside the delivered resend. The reconcile gates the outbox copy only on the row being loaded, not on structuredAgentSessionRejectedShownInPlace; the projection then draws that entry as unsent at structured-agent-session-message-projection.ts:88.

Technical details
# Superseded rejected copy still draws from the outbox

## Affected sites
- `src/shared/structured-agent-session-outbox-reconcile.ts:30` — the `rejected` branch returns the entry whenever the submission's row is not loaded, with no supersede check.
- `src/shared/structured-agent-session-message-projection.ts:88` — those entries then map to `unsent` rows, bypassing `structuredAgentSessionRejectedShownInPlace`.

## Why it is reachable
- An older host leaves a rejected message at its sent position, which can be outside the loaded page; the outbox copy is kept for exactly that case. If a later same-`payloadFingerprint` copy was sent at/after the rejection's `resolvedAt`, the in-place rule suppresses the journal row but not this retained copy. The new `recorded-copy` test covers "row outside the window" and the `rejected-in-place` test covers supersede, but not both at once.

## Required outcome
- A rejected submission the in-place rule suppresses must not reappear as a "Not sent" row from its retained outbox copy.

## Suggested approach
- Have the reconcile consult the same rule as the projection (or accept the `shown` set) so an entry whose submission is superseded is dropped/skipped, not only one whose row is loaded.

# Conflicts:
#	src/renderer/src/components/native-chat/NativeChatStructuredSessionDelivery.test.tsx
#	src/shared/structured-agent-session-outbox.ts
@brennanb2025
brennanb2025 merged commit 97fa6ae into main Oct 4, 2026
33 checks passed
brennanb2025 added a commit that referenced this pull request Oct 4, 2026
…-history

#24710's enqueueRows (a failed start's rejections and its row in one transaction) now goes
through the same write as a single append: every row, then any send ledger receipt, then the
fold and ONE chat status written from the fold that holds every row; a failed COMMIT puts the
fold back and adopts no receipt. Pinned by journal-append-status-commit.test.ts.

The stored-status plumbing (status writes, fold undo, backfill, projection) moves out of the
store and its collaborators into journal-session-status-writer.ts; the store exposes it as
`sessionStatus` (`at`, `backfill`), replacing `statusState` and `backfillSessionStatus`.

#24710 places a rejected message where it was rejected, which changes the latest prompt and
request the stored summary reads: JOURNAL_SESSION_STATUS_RULES 1 -> 2, with a corpus case that
pins it and the new digest. Conflicts: journal-store-collaborators.ts (main hoisted the row
writer; kept, with this PR's deps) and journal-pending-submission-recovery.ts (both imports).
brennanb2025 added a commit that referenced this pull request Oct 4, 2026
Takes main's side for the files #24710 also changed; this branch's remaining
changes are re-applied on top in focused commits.
brennanb2025 added a commit that referenced this pull request Oct 5, 2026
…ected message

Main's #24710 draws a message Orca recorded and then rejected where the host
placed it, as "Not sent", from the host's own history. The host side (the
rejection moves the message to its place; a failed start writes its rejections
and its row in one transaction) is taken as written.

On the client, C2's settlement stays the only place an outbox entry ends:
- #24710's reconcile module is folded into C2's: an entry whose rejected row is
  not loaded yet stays, never sent again, and draws the message until that row
  loads (or the host's window for its id ends). Nothing new is stored; the held
  submission says it was rejected. A batch that settles nothing writes nothing.
- One "not sent" surface: main's rule hides a rejected message a live card
  holds or a later copy of the same text superseded, in the rows and the
  notices alike, on the desktop and the phone. The notice stays C2's muted one,
  and notices are kept as the same objects across unchanged batches.
- No Retry: a message refused before it was recorded still goes back to the
  conversation's draft with the reason, as before.
- A rejected /compact stays in the chat (#24918's rule), since the command's
  own reply says nothing once the journal shows it.
- The phone and the desktop both draw these rows; only the host's outline,
  which older clients read, leaves them out.
brennanb2025 added a commit that referenced this pull request Oct 5, 2026
#24918 and C2 already agreed on everything this head adds over main except
wording sources, so the resolution keeps C2's mechanism:
- A rejected /compact is case 1, shown muted and said once. The command's reply
  stays silent only while the journal draws it: a withdrawn, card-held or
  superseded copy still speaks (structuredAgentSessionJournalShowsSubmission
  now reads the shown-in-place set).
- The phone draws recorded rejections in place with its live card ids.
- The row's words come from the host's reason and fact, through C2's
  send-failure words module (send-disposition stays deleted).
- The not-sent line keeps C2's `muted` flag; #24918's `notSent` field is not
  taken, and its Retry-era outbox notice tests stay out.
- The list test for a rejected /compact is taken, on C2's notice signature.
brennanb2025 added a commit that referenced this pull request Oct 5, 2026
…ded in doubt

#24710 now draws every message the host rejected where it was rejected, in the host's words, so
the journal-drawn not-delivered row, its outbox exclusion and the Retry rotation record go. Tests
state which rejected message has a Retry: only a failed start no agent took, on a host that
retries in place.
brennanb2025 added a commit that referenced this pull request Oct 5, 2026
A rejected send's own row now moves to its rejection (#24710), so the row that
resolved a send is the item's own position and needs no second copy. Keep
submittedSequence, the one journal-order record of where a send was sent.
brennanb2025 added a commit that referenced this pull request Oct 5, 2026
…puts its row

#24710 moves a rejected send's row, a Stop's take-back included, to the row
that rejected it, in no turn. Draw it at that row, past the end of every turn
opened before it, and keep the send-order rule. A send whose turn opened before
the provider echoed it is claimed by that turn's record when it was sent before
the record and taken back after it, by submittedSequence, and is drawn as the
turn's opener. The steer branch goes: the host no longer says which turn a
taken-back steer joined, so it is drawn after that turn with its own row.
The older-host fallback (floor, clock compare, submittedAt order) is now gated
on submittedSequence alone and marked Temporary. resolvedSequence is gone, as
in #25073.
brennanb2025 added a commit that referenced this pull request Oct 5, 2026
…ow, not hidden

#24710's tests pinned a withdrawn send as hidden, the rule this PR replaces.
Each keeps what it is about: a withdrawn copy does not hide a failed one, no
delivery notice is raised, and a message the host failed to deliver stays
hidden on the phone.
brennanb2025 added a commit that referenced this pull request Oct 5, 2026
…n a stopped one was answered into (#25073)

* feat(native-chat): publish each submission's journal positions

A client never learned where in the journal a send was accepted or taken back,
so drawing a stopped send had to guess from its own row and from clocks, and the
guesses misfired after restarts. Each projected submission now carries
`submittedSequence` (its submission row) and `resolvedSequence` (the dispatch row
that resolved it; absent while pending): two optional fields, computed on every
fold from rows already stored, never stored themselves. Older clients ignore
them. The failure-fact schema moves to its own module to keep the journal schema
file within its size limit.

* test(native-chat): pin a submission's resolved position on the provider-echo accept path

Also say which rows can resolve a submission, and that the submission schema, not the shared type, omits acceptedSequence.

* refactor(native-chat): publish only where each submission was sent

A rejected send's own row now moves to its rejection (#24710), so the row that
resolved a send is the item's own position and needs no second copy. Keep
submittedSequence, the one journal-order record of where a send was sent.

* feat(native-chat): publish the turn a withdrawn Codex send was answered into

A send Codex answered into a turn that then ended without taking it is
rejected by that turn's end. The rejection row now names that turn's
record, and the submission carries it as answeredInTurnItemId, so a
client can tell which turn the send belonged to without guessing from
journal order or clocks. Absent on every other send.

* feat(native-chat): say how a withdrawn Codex send joined the turn it names

The answered turn becomes { turnItemId, via }: 'start' when Codex
answered the send's turn/start with that turn, 'steer' when Orca steered
it into that running turn. A client can then tell the turn's opener from
a send steered into it even when the opener is on an older page.

* feat(native-chat): state on every rejection whether it names a turn

A rejection a host writes now always carries answeredInTurn: the turn
Codex answered the send into, or null for none. A reader can then tell
'answered into no turn' from a row written before the field existed,
which keeps no answer and is placed by the older rules.

* refactor(native-chat): give the answered-turn schema its own module

Keeps the journal schema file within its line limit.

* docs(native-chat): say an unreadable answered turn reads as none
brennanb2025 added a commit that referenced this pull request Oct 6, 2026
…e stop row after it (#25051)

* refactor(native-chat): derive the queue's pause from Stop and Resume journal rows

Stop now appends one journal row where it takes effect, before the interrupt,
whatever the queue holds; Resume appends its own. The pause is a pure function
of the fold: the latest Stop with no later Resume and no later accepted turn a
person asked for. A /clear's carried cards name their source, which is the
replacement's 'cleared' pause. Host-origin turns never lift either.

One predicate decides which cards a pause holds; by default every waiting card
without a hold of its own, including one queued after the Stop. The drain's
consume re-judges it inside its own transaction.

The rows are tombstones of an id no item takes, carrying the mark: a released
host reads an unknown row kind as corruption and truncates the journal there.

Deletes the stored pause (recordPause, the retire hook on every appended row,
the settle-before-record step, mayReturnToWaiting and its row overlay) and the
tests that only proved it retires. The queued_message_pauses table stays in the
schema, unread and unwritten, for downgrade safety.

* fix(native-chat): a card queued after a Stop sends normally, never ahead of held ones

A Stop's pause now holds only the cards queued before its row, plus a steer it
withdrew, which returns to its own place. Each card records the journal
position it was queued at, and the one hold rule compares that with the Stop
row. A card queued after the Stop is a new instruction: it sends as usual, but
the drain still stops at the first held card, so it never overtakes them.
/clear's pause holds the cards it carried. Holding every card again is a
one-line switch in that rule.

* fix(native-chat): the queue's own send re-checks the no-overtake rule in its transaction

The drain's pick and its consume now read one function, nextSendableQueuedCard,
so a Stop row that lands between them holds a newer card behind an older held
one exactly as the pick would. Notes why Stop and Resume ride a tombstone row.

* fix(native-chat): stop creating the unused queue pause table

The queue's pause is derived from journal rows, so nothing reads or writes
queued_message_pauses. It was still created on every open "for downgrade
safety", but an older build creates it itself when it opens the database, so
the table only sat empty in every new database. The tests now pin that no
pause table exists.

* fix(native-chat): a Stop's pause never hides the restart pause

A Stop holds only the cards queued before it. The pause derivation still
returned the Stop alone whenever it was in force, so the restart pause was
never considered: a card queued after the Stop, written by a host process
that has since exited, sent by itself after Orca restarted, with no pause
header and no Resume. A /clear pause that held nothing could hide it the
same way.

Every pause in force is now derived. A card is held if any of them holds
it, and it names the first that does. The drain's pick, the consume
transaction's re-check and the published header all read that one rule;
the header names the pause holding the first card Resume would send.

* test(native-chat): pin the Stop's no-resend, lift and held-card rules

- The Claude and Codex Stop-withdraws-a-steer tests checked "not sent
  again" at one instant, before a queue ignoring the pause re-sends. They
  now wait for the stopped turn to end and re-check after a quiet window.
- The deleted-card test read a card queued after the Stop, which sends
  whether or not a person's turn lifts it; it now reads the Stop's pause
  before and after that turn.
- Unit cases pin that a Stop holds a card with no recorded position and one
  queued before a rewind.

* refactor(native-chat): a Stop writes one Stop event with its reason, turn and caller

The Stop row that paused the queue becomes the general Stop event
{ reason, turnId?, at, caller? }, whose reason is the host's existing stop
cause. It still rides a tombstone of a host-only id (a released host deletes
the journal from the first unknown row kind), and Resume keeps its own marker
on its own id. Only a person's Stop (reason user-stop) pauses the queue.

* test(native-chat): a rewind keeps a lifted /clear pause lifted and restates the same Stop event

* test(native-chat): pin that Stop and Resume rows never reach apps or count as history

* test(native-chat): only a person's Stop event pauses the queue

* test(native-chat): pin that a Stop's event precedes the interrupt and the at-start stop

Through the real host: the event names the turn and who asked and is in the
journal when the interrupt reaches the agent; at an agent still starting it is
there before the start is ended and holds a card queued before it; an idle Stop
writes one only when it withdrew a send; and the queue's claim re-judges a
pause that landed after its pick.

* test(native-chat): a card held at a starting agent is checked before the Stop's timing

Also says precisely what the claim's in-transaction pause check defends
against: the Stop and the drain share one serialized lane.

* test(native-chat): a released build keeps and folds a journal holding Stop events

Replays this build's rows from the released build's own journal database: every
row is kept, the history after the Stop still folds, and an older client is sent
only removed ids no item uses.

* style(native-chat): format the Stop event changes

* test(native-chat): type the released build's exports through one checked helper

* fix(native-chat): the Stop/Resume row guard narrows to those tombstones only

* test(native-chat): run the Stop-event downgrade test in CI, and cover a writable downgrade

The Stop-event downgrade test ran in no CI lane: unit shards exclude the
cross-version folder, and the cross-version lane runs a fixed file list that
did not name it. It is now on that list.

Its only case replayed the rows into a release's own fresh database, because
that release cannot open the current host database. A second case opens the
journal this build wrote with a main build that shares the database: it opens
writable, keeps every row, appends, and this build then reopens it with the
person's Stop still pausing the queue.

* fix(native-chat): a Stop that stops nothing new writes no Stop event

A Stop reaching a running agent wrote a Stop event on every press. Two
presses before the first interrupt landed wrote two events, so a card
queued between them counted as before the latest Stop and was held,
though a card queued after a Stop should send normally. A Stop naming a
turn that had already ended, as a phone sends late, also wrote an event
for a turn it never stopped.

It now writes one only when it withdrew a queued send, or stops something
no event records yet: not a turn the journal no longer runs, and not the
live turn a Stop still in force already names, unless a card was handed
over into it since, which this Stop's interrupt sends back and must hold.
The interrupt and the "already finished" note are unchanged. A Stop at a
starting agent still always writes.

* test(native-chat): pin that a later host, eviction or close Stop never lifts a person's Stop

* chore(native-chat): put each Stop-row doc on its own declaration, and say only user-stop is journaled

* fix(native-chat): any later Stop event ends a person's Stop pause

A person's Stop paused the queue until their next accepted turn or Resume,
and a later Stop of another reason (the host stopping the agent, an
eviction, a close) was ignored. Now the pause is the latest Stop event's:
a later Stop of any reason ends a person's pause, and only a person's Stop
pauses. The fold keeps the latest Stop event whatever its reason.

An eviction of a resting chat writes no Stop event (a Stop that stops
nothing writes nothing), so it cannot release held cards; a test pins that
no event means no lift.

* fix(native-chat): a second Stop press is a repeat even when the first came before the turn showed

A Stop pressed before the agent's turn shows in the journal (before
Claude's echo, or before Codex opens the turn) records no turn. A second
press once the turn showed compared that missing turn with the live one,
wrote a second Stop event, and held a card queued between the presses.

A repeat is now judged by what was sent since the Stop in force: with
nothing sent after it (a refused send aside), a Stop that named no turn,
or named the live one, is repeated and writes nothing. Anything sent since
and not refused, including a send whose fate is unknown, makes the new
press write, since its interrupt may send that card back to waiting.

Tests: the two-press case across the turn showing; a steer between the
presses settled unknown; and a Stop naming a turn that ended while the next
card is sent but shows no turn yet, which writes and holds that card. The
fold test that claimed an eviction path is renamed.

* fix(native-chat): the queue's pause ignores a Stop or Resume row holding a value no build writes

A Stop or Resume row's value is read from disk with no shape check, and
the pause fold stored whatever it found. A stored `stopEvent: null` would
then throw on every pause check for that chat: the queue's pick, its
send, and every queue update to clients. No build writes such a row, so
this is hardening.

The fold now reads a Stop only when it is an object with a string reason
and a finite time, and a Resume only when it is `true`. Anything else is
ignored: it pauses nothing and ends nothing. The row is still not treated
as malformed, which could cut the history short.

* fix(native-chat): a Stop still reads as yours after Orca restarts before the turn ends

Every stop that ends work now writes the Stop's event before it ends the child: a
person's close of the chat, an eviction (worktree teardown, orchestration stop, tab
cleanup) and the idle sweep's stop of a start that never landed. A stop that ends
nothing writes nothing, and quit writes none: its resume marker records why.

The turn-end write reads the latest Stop event where every turn row is built, so the
adapter's settle, the host's fallback and the relaunch's settle all agree: a turn a
person's Stop or close named, ending with no verdict of its own after that Stop, ends
as their cancellation. A relaunch's probe-bounded end is no earlier than a Stop that
found the turn running. When the provider refuses the interrupt and the turn runs on,
a refusal row answers the Stop, so a later crash still reads Failed; pressing Stop
again after a refusal is a new Stop.

* refactor(native-chat): a stop no longer carries its cause; the turn's end reads the Stop event

The cause of a stop was threaded in memory from each entry through the host's stop
step, the adapter router and each adapter's close onto the `ended` it settled with,
and Claude kept a per-turn copy of a Stop it sent. All of that is gone: adapters
settle a turn they cut as interrupted with no verdict, the host's fallback does the
same, and the one rule where a turn row is built (`turnEndAfterStop`) reads the
journal's latest Stop event to say whether it was a person's.

- `closeSession` / `disposeSession` take no cause; `ended` has no `stopCause`.
- Claude reads an error result after a person's Stop as their cancellation from the
  journal's Stop event (through the event sink), not from a per-turn slot, and a
  refused interrupt is the host's refusal row, not `withdrawTurnStop`.
- An owed wind-down keeps no cause: its retry's fallback reads the Stop event.
- The mutation context's Stop passes no cause: its step already wrote the event, and
  the delivery loop's child-end reason is read back from it.
- A Stop pressed before its turn showed applies to the turn that opens under it,
  unless a send a person made since was accepted.

* test(native-chat): a turn a later send opened is no Stop's that named no turn

* test(native-chat): the restart test's death proof carries its detail

* refactor(native-chat): a refused Stop leaves no record; a Stop only ever ends the turn it names

The stop-refused mark is gone: its tombstone kind, its fold, the clock-keyed match that tied it to
a Stop, and the exception that let a second press after a refusal write a new Stop. A Stop that
stops nothing writes nothing. A Codex refusal names a turn that is no longer its active one, and
the Stop names that turn, so the turn running instead never reads as the person's by its id alone.

* fix(native-chat): a Stop pressed before any turn showed stops only the turn opened next

A Stop that named no turn read as the person's cancellation for every later turn that opened
after it, until a send a person made was accepted. The queue's drain, orchestration mail and a
restart continuation send as the host, so a turn they opened long after, cut by a crash, read
"Interrupted" as if the person had stopped it. The Stop now applies only to the first turn
opened after it.

* fix(native-chat): an older Claude's error end after a Stop pressed before its echo reads Interrupted

Claude CLIs before 2.1.91 end an interrupted turn with an error result that names no reason. The
translator judged whether a person's Stop explained it by its own copy of the Stop rule, which
ignored a Stop that named no turn, so a Stop pressed before Claude echoed the send read "Failed".
The translator now writes such an end as interrupted with no verdict and no error row whenever a
person's Stop may name the turn, and the journal's one rule decides as it writes the end.

* fix(native-chat): a person's Stop and /clear each name why they end the agent

The host's mutation path ended the agent with one "recorded" ending for every caller, which read
back the reason of whatever Stop event the journal held last, however old. /clear writes no Stop
event, so its end took an unrelated earlier reason. Each caller now names its own: the chat's Stop
`user-stop`, whose event its own step wrote, and /clear `user-close`, the user replacing this chat.

* fix(native-chat): a host stop judges whether it ends work after the provider's rows land

A close, eviction or host stop decided whether it ended a running turn from the journal as it
stood, while the provider's own rows (the turn its echo opened) could still be in the session's
event sink. A close landing in that gap wrote no Stop event, so the turn it cut read as news. It
now reads after the sink drains, as a person's Stop does, through the same check; a drain that
fails or takes over a second reads working.

* fix(native-chat): a Claude Stop naming a turn that just ended still marks the follow-up it cuts

A phone names the turn it last saw. When that turn had ended and a follow-up was still unechoed,
Claude's Stop interrupted the follow-up and ended the child, but the Stop's event named the ended
turn, so the follow-up's turn the child's end cut read "Failed" under "Cancellation requested.".
A Stop that ends the provider's session ends whatever is in flight, so its event now names the
live turn or none, and a Stop that names none binds the turn opened next. Codex keeps naming only
the turn the Stop names.

The Claude Stop turn-end tests move to their own file, since the session-ending Stop suite is at
its line budget.

* fix(native-chat): the idle sweep reads working by the same rule as a stop's event

The sweep judged a chat resting while a send whose reply was lost was still unanswered, but the
stop's event writer counts that send as work. So the sweep evicted it and wrote an evict event,
which ends a person's Stop pause and let the cards behind it drain on their own. The sweep's owed
work now reads the main agent working the way every session list and the event writer do.

* test(native-chat): an aborted eviction's injected drain failure lands on the eviction's own drain

A host stop now drains the session's sink once to judge whether it ends work, so the tests that
fail the eviction's drain-published step skip that first drain.

* fix(native-chat): the idle sweep's rest writes no Stop event; it evicts a send that never echoes

The previous commit made the sweep count an unanswered send as owed work, which pins a chat whose
admitted send Codex never echoes forever, and the sweep exists to retire exactly that. That rule
returns. The sweep stops only an agent it judged resting, so its eviction now writes no Stop
event, whatever send it retires: a person's Stop pause holds through it.

* fix(native-chat): stopping a start that carries no send writes no Stop event

A host stop, eviction or close of a starting child wrote a Stop event whatever the start carried.
A start with a send already reads working, so the clause only mattered for a start with none,
which ends no turn and no send: its event only lifted a person's Stop pause and bumped the idle
clock, which is why the idle sweep had been changed to close the conversation in the same pass.
The clause goes and the sweep is #24072's again. The child's end still reads host-stop, as before.

* test(native-chat): a Stop's pause across a restart is tested with a restart that writes no event

The rig's restart closes the chat with an eviction, which now writes a Stop event when work runs
and so ends a person's Stop pause. "A Stop never hides a restart's pause" then passed with no Stop
pause left to hide anything. Those tests, and the pause-lift test whose dropped assertion returns,
restart as a process that dies with no close, which like a quit writes no Stop event, and assert
that both the Stop's and the restart's pauses are in force first.

* fix(native-chat): a host stop of a turn a person's Stop is still ending keeps that Stop's reason

An eviction or host stop that landed while a person's Stop or close was already ending the same
turn wrote a newer Stop event, and the turn's end reads only the latest, so the person's Stop of
that turn read as news. A host reason now writes nothing while a person's Stop still decides what
runs: the live turn it names or bound, or, with none, the turn a send opens next. The person's
own close still writes. The E2 tests now open and end the stopped send's own turn, as Codex does,
so the mail turn after it is not the turnless Stop's.

* fix(native-chat): an older Claude's error on a later turn keeps its error text after a Stop

The translator left an error result that names no reason to the journal's Stop rule whenever a
person's Stop named the turn or none, but the rule binds a Stop naming no turn only to the turn
opened next. So a real error on a later turn read "Failed" with its error text dropped. The
translator now asks the journal's rule itself (`personStopDecidesTurn`, the one core
`turnEndAfterStop` and a host stop's in-force check share), so the two cannot disagree.

* fix(native-chat): a Stop of a start that never landed binds no later turn, whatever sent it

A person's Stop pressed while the agent starts names no turn, and the send it stopped is
cancelled before it opens one. The Stop then bound the next turn anything opened (orchestration
mail, a restart continuation, the queue's drain, all of which send as the host), so a host
eviction of that turn wrote nothing and its crash or close read as the person's cancellation. A
Stop that named no turn now binds only a turn no send journaled after it opened: any send since,
of any origin and not refused, opens its own. The E2 test's mail send is accepted as Codex
accepts it, instead of opening the stopped send's own turn first.

* test(native-chat): a rewind's restated turnless Stop binds no turn opened after the rewind

A Codex rewind restates a person's Stop still in force after the turns it keeps, at a new
sequence, so by sequence alone it would bind the next turn opened after the rewind. A send
journaled after the restated row voids that binding (the previous commit), which this pins.

* fix(native-chat): a relaunch settles a person's stopped turn with no "stopped while in progress" row

After a restart, a turn a person's Stop ended reads "Interrupted after N" with the muted mark, but
the relaunch still added the error row saying the provider stopped mid-response, which a live Stop
never writes. The settle now skips that row when every turn it interrupts is the person's Stop's
by the journal's one rule; a crash nobody stopped keeps it.

* test(native-chat): the unexpected-exit settle's journal fake answers whether a person's Stop decides a turn

* fix(native-chat): a host stop whose sink drain fails reads the journal as it stands

A host stop drains the session's sink before judging whether it ends work, and a failed or slow
drain read as working. So an eviction of an agent at rest wrote a Stop event that ended nothing,
which lifts a person's Stop pause, and a close wrote a person's event naming no turn. The drain is
now best effort: the stop goes ahead either way and only its record is at stake, so a failed or
slow drain leaves the journal's read as it stands. A person's Stop keeps its own rule.

* fix(native-chat): a Stop that named no turn applies only to a turn a send it stopped opened

A person's Stop pressed before any turn showed names no turn. It bound the first turn opened
after it, then (5ead1f6bccd) any turn opened by no later send, so a turn the host started for
a card the Stop held, or for orchestration mail, read as the person's cancellation, and a host
eviction of it wrote no Stop event when its send had been abandoned by the close first.

The rule is now the concept itself: a Stop naming no turn applies to a turn opened by a send it
stopped, one already handed to the agent at the Stop's position. Nothing new is stored. The turn's
row names the send that opened it (Codex: the submission's key; Claude: the echo, which the journal
aliases to the submission), and a handed-over send's item sits at its handover, so the target set
is derived from the journal. A card the Stop held is handed over after it, so it is no target; a
Stop of a start whose send never opens a turn binds nothing; a rewind keeps no submissions, so a
restated Stop binds no turn opened after it. With no turn running, a host stop defers to the
person's Stop only while every unanswered send is one it stopped. Claude's translator, which asks
before its echo row lands, passes the send its echo acknowledged.

* fix(native-chat): a host stop whose sink drain runs long reads the agent working; a failed one reads the journal

A drain past its bound may still hold the turn's row, while the echo's acceptance has already
landed, so the journal as it stands read nothing running: a person's close of that turn wrote no
Stop event and the turn read as news. The two drain outcomes now differ: one that failed has
nothing more to deliver, so the journal's read holds (as before); one still running reads working.

* test(native-chat): a host stop with no turn running defers only while every unanswered send is the Stop's

The branch had no test. An eviction with only the stopped send unanswered writes nothing; one
with a send made after the Stop still unanswered writes its event.

* fix(native-chat): a slow sink drain reads working only while an accepted send's turn row is due

The previous commit read every drain past its bound as working, so a host eviction or stop of an
agent at rest during a sink backlog wrote a Stop event that ended nothing and lifted a person's
Stop pause. A slow drain now reads working only when the latest send the agent accepted has opened
no turn the journal holds, the race it was for; otherwise the journal's read holds.

* test(native-chat): the host-stop control keeps the stopped send unanswered beside the later one

With both unanswered, the host writes only because not every unanswered send is the Stop's; a rule
that deferred when any one was would pass the old control.

* fix(native-chat): a steer is no send owed a turn when a slow drain judges a host stop

A slow drain reads working when the latest accepted send has opened no turn yet. A Codex steer or
a Claude fold is accepted into the running turn and never opens one, so a chat at rest whose last
send was a steer still read working, and an eviction lifted a person's Stop pause. Sends delivered
into a running turn, whose item carries that turn's scope, are skipped.

* feat(native-chat): a chat reads Stopping from the person's Stop until the work it stopped ends

The host derives it on each journal publish from the Stop's event, the live turn and the Stop's
own answer, and publishes it as an optional field on the session status and the main agent's row.
Clients present it: the chat's tail line and Stop control, the sidebar row, worktree ps and the
phone's row. The chat and the phone also read their own Stop press until its request answers.

* test(native-chat): pin Stopping on the phone and across mixed versions

* test: give touched fake journals and mocks their SAFETY notes

* test(native-chat): a turn waiting on the person reads attention, never Stopping

* test(native-chat): the sidebar row follows Stopping when it is the only field that moved

* test(mobile): the phone reads Stopping from its own Stop until the request answers

* test(mobile): type the held Stop request instead of casting it

* chore: keep the base lockfile (a local pnpm run rewrote it)

* fix(native-chat): narrow the Stop note's optional failure; type the phone test's reply

* test(native-chat): type the Stop test envelope's fields narrowly

* fix(native-chat): a Stop the agent declined, or whose child end failed, says so while the turn runs on

A Stop naming the turn that still runs, refused by the agent, now writes the
Stop's refused fact instead of 'already finished'. A session-ending Stop whose
child end fails while the work runs on revises its note to unconfirmed.

* fix(native-chat): Stopping holds while any press of the Stop took

A repeat press refused after an earlier press took no longer clears Stopping.
Exit early when the Stop named a turn that is not the live one.

* fix(native-chat): keep Stop enabled while the host says Stopping

Only this client's own Stop request in flight disables Stop and Esc. A repeat
Stop is how a stop the provider took but never answered escalates.

* fix(sidebar): every agent row says Stopping in place of its tool line

The dashboard row, which the sidebar's non-compact mode also draws, read the
last tool line while a person's Stop ended the turn. It now shares the compact
row's rule.

* fix(mobile): the worktree list sees Stopping change on its own

A snapshot whose only change was the host dropping Stopping compared equal and
was thrown away, leaving the row on Stopping.

* refactor(native-chat): fold the status feed in src/shared for both clients

The snapshot merge and the contact-loss strip move out of the renderer feed so
the phone folds the same stream the same way.

* feat(mobile): let phones read the structured session status stream

agentSession.subscribeStatus joins the mobile allowlist. The agent-session
methods move to their own file, which the at-cap allowlist spreads in, and the
allowlist test reads the Set instead of parsing the source.

* feat(mobile): the phone chat reads Stopping from the host, like the desktop

One status stream per client, opened on a host that advertises the status feed;
a refusal to phones reads as no feed. The chat reads Stopping from the host or
its own press, and holds Stop only while its own request is in flight.

* test: give the new fakes checked types or a SAFETY reason

* revert(native-chat): drop the refused-named-turn rewrite of a Stop's note

Codex can send its refusal before the turn's end frames, so reading the turn as
still live after a flush races; the Codex Stop that ends nothing is handled by
ending the process instead. The base's 'already finished' note and its test
expectation return. The Claude wind-down failure revise stays.

* fix(mobile): release the status stream when the host ends it; refusals last one connection

The feed now drops the handle of a stream the host ended or refused, so the
logical client never replays it on a later session. A refusal to phones holds
for one connection, so a host updated while the phone stays paired is asked
again.

* perf(native-chat): read the live turn's opener from its record when deriving Stopping

After a Stop that named no turn, every later commit walked and copied the whole
journal to find the live turn's record. The derivation now reads that record
off the rendered snapshot's tail and decides with the same rule.

* refactor(mobile): move the method-unavailable check into transport

The status feed imported it from the Files tab's fallback. No behaviour change.

* test(native-chat): a send after a Stop reads Working before its turn opens

Pins the derivation's running-only read of the newest turn: the stopped turn,
already ended, must not keep the next send on Stopping.

* fix(sidebar): the compact row leads with Stopping so a narrow sidebar keeps it whole

At the default width the row read 'Codex Chat - Stoppin…': the model and time
keep their room and the line truncates from the end. Stopping now leads the line
the way monitoring already does, so the chat name is what gets cut. Also pins
that the turn bar keeps its running clock while the tail line says Stopping.

* test(native-chat): the retry of a close whose exit was unproven writes no second Stop event

The idle sweep finishes a stop left owed with that stop's own cause. It is the same stop, so its
event stands alone and the child's end keeps the cause, for a person's close and an eviction.

* fix(native-chat): read and write a Stop's answer by the turn its event records

Stop notes are now one row per turn, keyed by the turn the Stop's event
records. Performing a Stop and deriving Stopping share that key. A refused or
unconfirmed answer never overwrites one that took at the same key; only a
session-ending Stop's failed wind-down downgrades it, and that step now revises
the note the Stop actually wrote, carried on the wind-down. Stopping reads the
turn's note whenever it was first written, plus newer notes no other turn owns.
Test fixtures gain the host logger and the phone's quietRepeatedStop.

* refactor(native-chat): read a Stop's target once for its event and its note

The chat's Stop now reads what it is aimed at (the named turn and whether the
Stop ends the provider session) once, and both its event and its note's key
derive their turn from that one value through the same rule. Adds the host test
for a Stop naming an ended turn on a provider whose Stop ends the session.

* fix(native-chat): the host never steers a message into a turn a Stop is ending

A queued card's Send-now, or a send made while a person's Stop ends the turn,
went to the agent as a steer into that turn. The delivery loop now holds any
waiting message while the host's own Stopping reading holds, and sends it as
its own turn once the turn ends. The Stopping reader also stops at the Stop's
position and looks the turn's note up by key, instead of walking the whole
journal.

* feat(native-chat): while Stopping, the composer says a message runs after the stop

Desktop and phone: the composer placeholder reads "Queue a message to run
after the stop" while the chat reads Stopping, and a queued card's Steer (and
the desktop's steer shortcut) is held. New key translated in all 6 catalogs.

* refactor(native-chat): the chat pane's Stop controls live in their own module

The pane went over its line limit once merged with main. Its Stopping reading,
the press that holds Stop, and the steer and placeholder it hands the composer
move to native-chat-structured-stop-controls.ts.

* fix(native-chat): hold a send at its handover, reading the feed's own Stopping

The hold was checked when the delivery step started, but the handover runs in a
later step after waiting on the agent's start, so a Stop landing in between let
a new send steer into the stopping turn. The check now runs at the handover.
It reads the status feed's projection for the commit instead of rendering the
journal again, so holding a send adds no journal read of its own.

* refactor(native-chat): one display status decides Stopping on every surface

agentStopDisplayStatus combines whether the agent works, the host's flag and
this client's own press. The chat pane, sidebar and dashboard rows, and the
phone's chat all read it, instead of each combining the flags.

* fix(native-chat): Stopping holds until the stopped turn ends, whatever the Stop's answer

A Stop the agent declined, or whose end went unconfirmed, used to drop the chat
back to Working. It now stays on Stopping until the turn ends, and Stop stays
enabled so a repeat press escalates. The Stop's answer is no longer read for
Stopping, so its note goes back to the key the base gives it (the restore of
queued-stop.ts and the removed key test landed in the previous commit). The
note still keeps a press that took over a later refusal, and a failed process
end still says the Stop went unconfirmed.

* fix(native-chat): a Stop binds only the turn it actually stopped

A Stop pressed before any turn showed used to claim, at end-write time,
whatever turn the stopped send later opened, even when the Stop stopped
nothing. A turn that then died on its own read as "Interrupted" (your
cancellation) instead of "Failed".

Now a person's Stop that named no turn binds, in memory only, every turn
that ends while the Stop settles, and afterwards only the turn its
interrupt took. The settle ends a still-running stopped turn once. A
relaunch finds nothing in memory, so an unsettled turnless Stop binds no
turn. A Codex Stop whose answered turn does not open within its wait, or
whose send's answer was lost, now answers refused, so the host ends the
child and the turn can never run.

* fix(native-chat): keep the person's queue pause and close binding after a Stop settles

A host stop or eviction with no turn running now defers to a person's
Stop while its queue pause still holds with nothing sent since, read from
rows, so a held card is not handed off on reopen after a Stop that did
nothing or whose kill failed.

A person's close that named no turn opens a settle around its child's
end, so a turn that end cuts reads as theirs.

A press opens its settle only when the latest Stop event is its own or
the one in force it repeats: a late Stop, a card's interrupt or a lost
event row reopens no earlier Stop.

A Codex Stop that cannot reach a turn still able to open says the Stop is
unconfirmed rather than that no turn ran, and a second Stop still reaches
a turn an earlier wait left unopened.

Also drops the unused openedBy plumbing and the unreachable "a written
cancellation stays one" rule, and pins a relaunch after a named Stop.

* fix(native-chat): keep a failed Stop's turn display-only, and settle edges off the commit path

A Stop that failed marks the turn it could not stop for "Stopping…" only
(JournalStopSettle.failedOn): no turn-end rule reads it, so that turn's
own end with no verdict reads as a failure, not the person's.

A settle edge writes no row, so it no longer goes through the journal's
commit listener, which also delivers history, counts as activity for the
idle sweep and schedules the queue drain. A narrow settle-edge hook
republishes the status row and wakes the steer hold's handover, and
nothing else.

* fix(native-chat): a Codex Stop agrees on both presses when a turn is still owed, and pin the close's settle

A Codex Stop that waited for a turn Codex answered a send into now answers
"may still open" whenever that turn neither opened nor ended and its send
is still owed, however the wait ended (it ran out, or the thread went
idle). Before, a first press after an idle thread said no turn was
running and kept Codex, while an identical second press ended it.

Adds a test that a person's close the conversation outlives (as /clear
does) closes its settle, so a later turn that ends on its own reads as a
failure.

* fix(native-chat): a Stop that failed before its turn showed still reads Stopping through that turn

A Stop that failed with no turn open marked nothing, so the chat dropped
to Working and the turn that then opened never read "Stopping…". The
display-only mark now also covers that case: the first turn that opens
after the Stop failed, provided no message was handed to the agent in
between. No turn-end rule reads the mark, so that turn's own end with no
verdict still reads as a failure.

* test(native-chat): a Stop whose event row failed binds no turn to an earlier Stop

With one ordered journal writer the Stop's event is in the fold when its
write returns, so the press reads whether it owns the latest Stop from the
fold instead of awaiting the write. Pins the case the read must refuse.

* test(native-chat): name the settle, not a stream drain, in the Stop's own-end test

* test(native-chat): a Codex Stop answered before Codex ends the turn reads interrupted throughout

Codex answers an interrupt it took before it sends turn/completed (interrupted):
on TurnAborted the app-server answers pending interrupts, then ends the turn, on
one channel. The test fake did the reverse. It now answers first and ends the
turn on a later read, and the tests that read the turn's end right after a Stop
wait for it.

New end-to-end test through the shipped host, journal and Codex adapter: with
the real order, every end row of the stopped turn reads interrupted by the Stop
(named, unnamed, and a Stop pressed while turn/start was in flight). Breaking the
settle window turns the in-flight case red: the Stop's own end row then has no
verdict, which reads as failed until Codex's end lands.

* test(native-chat): Stopping ends with a Codex turn whose interrupt is answered before its end

With Codex's real order (the interrupt's answer, then turn/completed interrupted),
the status shows Stopping while the Stop settles, drops it once the turn ends, and
never carries a verdict other than the person's cancellation.

* fix(native-chat): a Codex Stop interrupts a turn Codex answered but has not opened at once

A Stop that named no turn, made after Codex answered a send but before the turn
opened, used to wait up to 5 s for the turn to open before interrupting, and
ended the Codex process when it didn't. The stated reason, that Codex refuses an
interrupt until it opens the turn, holds only part of the time: with no turn
active, Codex takes an interrupt once its thread runs (turn_interrupt_inner),
and refuses it with -32600 "no active turn to interrupt" before that or once
the turn has ended.

The Stop now sends the interrupt at once. Only on that refusal, while the turn
has neither opened nor ended, does it wait for the turn to open (bounded at
5 s) and send it once more. A turn that ended meanwhile was nothing to stop. One
that never opens, or that an earlier wait already gave up on, fails the Stop,
and the host ends the child as before. Sends still wait for the turn to open
before steering into it.

The test fake models Codex taking an interrupt once the thread runs (run()).

* fix(mobile): name how the phone's status stream is released in the subscription inventory

Main made each inventory entry state its release; the status feed's stream is
released from its subscribe params, as the session event stream is.

* fix(native-chat): every Codex Stop waits for an answered turn to start, as the first did

A Stop whose interrupt Codex refused as finding no active turn skipped the wait
when an earlier wait, a Stop's or a send's, had already given up on that turn.
Every press now waits its own bound and retries once if the turn starts, so a
turn that opens during a later press is still stopped. Both presses still reach
the same verdict when it never starts.

* fix(codex): never steer a turn whose interrupt Codex answered

Codex answers an interrupt as the turn aborts, before it sends that turn's
turn/completed. In that gap the adapter still counted the turn as running, so a
message handed over right after a Stop settled (the Stop's own end row already
reads the turn ended) went out as turn/steer, which Codex refused with -32600
"no active turn to steer", and only then as turn/start. The adapter now marks a
turn whose interrupt Codex answered as aborted until its turn/completed, never
steers into it, and starts the message's own turn directly. Steering a turn
that is genuinely running is unchanged.

* fix(native-chat): a message sent while Stopping is queued as a card, whatever the setting

While the chat reads Stopping (the host's flag or this client's own Stop in
flight) there is no turn left to steer into, so the desktop asks the host to
queue the send even with the queueing setting off, and it is never drawn as a
bubble inside the turn being stopped. The phone already queued every send on a
capable host; a test now pins that it does so while Stopping.

* fix(native-chat): a message queued while Stopping is a card at once, not after the stop

A person's Stop holds the session's lane until Codex answers its interrupt, and
a send was admitted only behind it. By then the turn read ended, so a send that
asked to be queued went out plain: no card for the whole of Stopping, then a
bubble and a new turn.

While the host reads that a person's Stop is ending the work, a text send that
asks to be queued is admitted without waiting for the lane: the same ledger and
lease admission, and a plan that only writes the card through the journal's
ordered writer. The card runs when the stop lands; the Stop's pause holds only
cards queued before it. Anything else, including a Stop that settled by the
time the send runs, takes the lane as before.

The Codex test fake now drops the active turn when it takes an interrupt, as
Codex does before it answers, so a turn/start after the answer opens a new turn.

* fix(native-chat): a Codex Stop that ends the child before any turn opened withdraws its send

A Stop on a Codex turn that was answered but never opened ends the Codex
process. That end settled the send as in doubt (unknown, recovered), and the
client's outbox holds every later send behind a send in doubt until the person
presses Retry, which re-sends the very message they stopped. The chat looked
stuck.

Codex records a prompt only once its turn has started, so a send whose turn
never opened never ran. When the Stop's refusal says so (turnMayOpen), the child
end now settles the unanswered sends as withdrawn, the verdict Codex's own
interrupted-turn end already gives an unechoed send. The flag rides on the owed
wind-down, so a retry after a failed child end withdraws them too. Claude's
child end still leaves its unanswered send in doubt.

* fix(native-chat): derive the withdrawal of a Codex send whose turn never opened

Replaces the flag the Stop carried to the child's end, and its copy on the owed
wind-down, with a reading of the journal at the settlement that lands. A Codex
child's unanswered send is withdrawn when a person's Stop is in force since it
was sent and no turn row ran, or was written, after it; any other end (a turn
that opened, a host's close, a crash, Claude) still leaves it in doubt. A
retried wind-down reads the same rows, so it withdraws the same sends.

* fix(native-chat): a card queued while Stopping runs past the cards the Stop holds

A card queued before a person's Stop waits under its pause until Resume. One
queued after it, as a message sent while Stopping now is, was stuck behind them
too, since the queue never reorders. Such a card was asked for after the Stop,
so it runs when the stop lands, past the cards held only by that Stop's pause;
a returned card and the restart and /clear pauses still hold everything behind
them.

Also: the host's own Stopping reading is gated on working, as the published
flag is, so a failed Stop's mark never reads Stopping on an idle session; a send
that falls back to the lane re-reads the conversation's journal there; and the
end-to-end test asserts the queue's pause rather than a per-card field.

* fix(native-chat): a paused queue labels only the cards it holds

Since a card queued after a person's Stop runs past the cards the Stop holds,
labelling every card "paused" while the queue's pause is published misreads that
card. The host now marks each card its pause holds (heldByPause, a new optional
field), and the desktop and phone label only those. An older host marks none,
so a client keeps today's labels; an older client ignores the field.

Adds a test of the desktop's own send through the real outbox: while the chat
reads Stopping, the request asks the host to queue it and no bubble is drawn,
on a host that advertises the queue.

* revert(native-chat): defer the per-card queue pause label to the queue's rollout

The heldByPause field and its labels are visible only where the host
advertises the queued-messages capability, which shipped hosts do not yet do.
Deferred to that rollout; the real-outbox send test stays.

* fix(native-chat): while Stopping, say and show what a send does where the queue is dark

Shipped hosts do not advertise the queued-messages capability, so a message
sent while Stopping goes out plain: the host holds it until the stopped turn
ends and then runs it as its own turn. The composer still said "Queue a message
to run after the stop", and the message was drawn inside the turn being
stopped.

Now the placeholder reads "Send a message to run after the stop" where the host
does not queue sends, and "Queue a message…" only where it does (desktop and
phone, all six catalogs). A send this client made that the host has not
recorded yet is drawn after the Stopping line while the chat reads Stopping, as
a message held behind a running command already is; once the host hands it
over it opens its own turn. Client presentation only.

* fix(native-chat): keep a send in doubt when a turn was open for it

The derived withdrawal read a turn as open for a send only if it still ran or
was written after the send. A send steered into a running Codex turn whose
interrupt failed met neither once the adapter's end settled that turn ahead of
the host's settle, so it read withdrawn, though Codex drains a steer into the
running turn and may hold it. A turn that ended after the send was handed over
was open for it too: such a send stays in doubt, as before.

Pins that case, and that a send made after the Stop, to a child that then dies
before its turn opens, stays in doubt.

* fix(native-chat): restore the per-card queue pause label

Kept after all: a paused queue labels only the cards it holds (heldByPause),
which is visible only where the host advertises the queued-messages capability.

* fix(native-chat): draw only a send made while Stopping after the Stopping line

Every send the host had not recorded yet was drawn after the Stopping line,
including one made just before the Stop, which the host steers into the turn;
it then jumped up into that turn once recorded. The outbox now marks a send
made while the chat reads Stopping, and only those wait after the line.

* fix(native-chat): withdraw a Codex send by whether it started its own turn, not by timing

Whether a turn was open for a send was read from end times: a turn that ended
after the send's handover counted. A send made while a Stop ended the turn is
handed over once that turn reads ended, yet Codex's own end for it can arrive
later, so such a send whose own turn never opened read in doubt again, and the
chat's queue held behind it.

The handover already records where the send went: its message joins the turn
running then (a steer) or belongs to no turn (it starts its own). Only a send
that started its own turn, with none opened since, is withdrawn; one that
joined a running turn, or has no recorded place, stays in doubt.

The Codex test fake takes an answered interrupt as Codex does, dropping the
turn before its end arrives.

* refactor(native-chat): move queue-while-stopping to its own follow-up

The queued-messages capability is off on every shipped host (#21062), so the
parts of this PR that act only when it is on move to a follow-up stacked on
this one: admitting a queued card while a Stop holds the session's lane, a card
queued after a Stop running past the cards it holds, the per-card pause mark,
and asking the host to queue a send made while Stopping. This PR keeps the
Stopping state, the host's steer hold, the rule that never steers a turn whose
interrupt Codex answered, and what a send while Stopping looks like where the
queue is off.

* fix(native-chat): leave no Stop row when the Stop took back a send that never ran

A Stop on a Codex send whose turn never opened ends the child, and the child's end
takes the send back into the composer. The Stop still wrote "Cancellation
requested." at the conversation level, so with the send gone it sat under the
previous finished turn and read as if that turn had been stopped. A Stop that found
no turn running and whose child end took back every send it found now writes no
row; a Stop of a running turn, or one that leaves a send in doubt, still does.

* feat(native-chat): keep a message a Stop took back on screen, with one stop row after it

A Stop that took back a message before the agent started it used to remove the
message from the transcript and paste its text back into the sender's composer.
Other devices just lost it, and with the message gone there was nowhere for a
stop row to sit, so it either landed under the previous finished turn or was
left out.

The message now stays where it was sent, on every client, followed by one row,
"Stopped before the agent started" (one row after several taken back together).
A message whose turn had opened stays in that turn, whose "Interrupted" header
already says it was stopped. A queued card's hand-off is still held by the card.
Nothing the host recorded refills the composer any more. Text this client's own
Stop took before the host ever had it still comes back, and only into an empty
composer.

Derived from facts the journal already holds (the rejected submission's
cancelled verdict and its user item); nothing new is stored or sent.

* fix(native-chat): one stop row per stopped send, drawn where the Stop took it, and nothing lost

- A message this window's Stop took before the host had it, which the composer
  cannot take (it holds text or images, or no composer shows the chat), now stays
  in the outbox as not sent, on its Retry, instead of vanishing.
- A Codex send whose turn opened but was never echoed belongs to that turn: its
  interrupted end is the stop, so no second row is drawn. A send taken back after
  a later turn started still gets its own row.
- A steer the Stop took back stays in the turn it joined, with no row of its own.
- A queued send taken back before its hand-over is drawn after the turn it waited
  behind, not inside it.
- The conversation outline the host serves still leaves out sends a Stop took
  back, and the rail gives them no tick, so what the host publishes is unchanged.
- The row is drawn as the Stop's own status rows are, and never folds behind a
  settled turn on a host that states no turn scopes.

* fix(native-chat): draw a stopped follow-up after the turn that opened while it waited

A follow-up sent just before the agent opened its turn, then stopped, drew its
"Stopped before the agent started" row above that turn's own "Cancellation
requested." whenever the turn was expanded. A send a Stop took back is now drawn
after the rest of every turn it waited on: the one it was accepted behind, and
any that opened after it and before the Stop took it back.

Also corrects the stoppedBeforeStart doc to what sets it.

* fix(native-chat): place a stopped send by journal order, not by turn start time

The turn a stopped send waited on was picked by comparing the turn's start time
with when the Stop took the send back. A Codex resume rewrites every finished
turn's start time to Codex's whole seconds, so after a restart (or a child
respawn) a turn opened for a later send could read as started first, and the
stopped send dropped below that whole later exchange. A turn is now waited on
when something sent before the stopped send opened it, read from the journal's
own order only. Covered end to end through a restart whose resume reports
whole-second start times.

* test(native-chat): pin a stopped send held behind the first send's answer

A second send made while Codex still held the first send's turn/start answer,
then a Stop: the first turn opens after the second was accepted and streams after
the Stop. The stopped second send and its row are drawn after that turn's output,
never between the turn's header and its output. Fails on the two earlier
placement rules. The restart case moves into the same file.

* docs(native-chat): say why the pre-echo anchor still compares times

* docs(native-chat): mark the pre-echo anchor's time compare temporary (STA-9337)

* docs(native-chat): say the placement rule reads journal position, not send time

* fix(native-chat): keep sends a Stop took back in the order they were sent

Two sends queued during /compact, the first handed over and the second not,
then a Stop that took both back: the handed-over one sat at its handover row and
the other at its acceptance, so the second drew above the first. Among sends a
Stop took back, a later-sent one is now drawn no earlier than just after an
earlier one. Sent order is submittedAt, the host's accept time and the order
every client already keeps submissions in, because a client never sees a
handed-over send's acceptance position (STA-9337).

* fix(native-chat): draw a stopped send below everything sent before it

A send a Stop took back that was never handed over could still draw above an
earlier send's whole exchange when that earlier send was not itself taken back:
three queued during /compact, the first ran and finished, the second was left in
doubt, and the Stop took back only the third. A stopped send is now drawn no
earlier than the latest loaded row of anything sent before it, and the turns it
waited on are read from that point, so the earlier exchange stays above it.

* fix(native-chat): count a turn opened by the floor row as one the stopped send waited on

When the latest row sent before a stopped send was itself a turn's opener, that
turn compared equal to the floor and was not counted, so the stopped send landed
inside the earlier send's exchange: two queued during /compact, the first handed
over and streaming, then a Stop took back the second. A turn whose opener sits at
or before that point now counts, and the send draws after the whole exchange.

* feat(native-chat): publish each submission's journal positions

A client never learned where in the journal a send was accepted or taken back,
so drawing a stopped send had to guess from its own row and from clocks, and the
guesses misfired after restarts. Each projected submission now carries
`submittedSequence` (its submission row) and `resolvedSequence` (the dispatch row
that resolved it; absent while pending): two optional fields, computed on every
fold from rows already stored, never stored themselves. Older clients ignore
them. The failure-fact schema moves to its own module to keep the journal schema
file within its size limit.

* fix(native-chat): place a stopped send by the journal row that took it back

Hosts now publish where each submission and its resolving row sit in the journal (cherry-picked from #25073). The projection places a send withdrawn before it started at that row, keeps stopped sends in their published submission order, and falls back to the send's own row on hosts that publish neither.

* test(native-chat): pin a submission's resolved position on the provider-echo accept path

Also say which rows can resolve a submission, and that the submission schema, not the shared type, omits acceptedSequence.

(cherry picked from commit 58a1ade5048669b1aadbac65799a6913152a9981)

* fix(native-chat): keep the previous placement rules for a host that publishes no positions

On a host from before the published journal positions, a stopped send is again drawn after the latest row of anything sent before it, as before the switch, so it no longer draws above the earlier exchange. Temporary until a host version floor. Also pins the published row against tied accept times.

* perf(native-chat): place stopped sends in one pass, and skip it in chats with none

The message projection runs on every streaming commit. It now builds turn anchors, the item lookup and the older-host floor only when the chat has a send a Stop took back, and places each such send with a binary search over the turns' furthest rows instead of rescanning every item per send. Draws are unchanged.

* fix(native-chat): count a send whose answer was lost when a Stop takes it back

The no-row rule counted only pending sends, but the child's end also takes back a send this process left in doubt when Codex's turn/start answer was lost. That case still wrote "Cancellation requested." under the previous turn. Both now read one predicate, so they cannot drift apart.

* test(native-chat): pin which sends a Stop's child end can take back

A send an earlier process left in doubt is never withdrawn and never holds the row back, and a queued card's send is never counted.

* fix(native-chat): read the host's Stopping beside main's startup phase

Main now reads only the startup phase from the status feed and no longer publishes which
child is starting. The chat reads the host's Stopping from its own hook beside it, and the
Stopping bridge test mocks the execution-host lookup main's owner resolution now calls.

* test(native-chat): phone draws the same from merged frames as from a fresh snapshot

A long chat whose last send never opened and was taken back at the child's
exit, right after a send made while a Stop was ending the turn before it.
From every subscribe point, at every later frame and with frames that carry
one to three rows, the phone's list built from merged frames must equal the
list built from a fresh snapshot of the same journal.

* test(native-chat): widen the merged-vs-snapshot guard to content, long chats and the phone hooks

The guard compared row ids and turn bars only, never left the phone's first
window, put each row's writer fence on every batch, and stopped at the fold.
It now:
- compares each row's content, so a phone that kept an earlier revision of an
  answer or a status fails it;
- adds a chat longer than the phone first loads, compared from the fresh
  page's first user row on (a turn whose user row the page cut off is keyed
  differently there);
- sends batches at the subscriber's fence and a fresh snapshot when the fence
  moves, as the host's attach does;
- writes the send made while stopping while the turn still runs, adds the
  provider's echo of each send, and a status row the provider drops;
- adds a hooks test: a phone that sent the never-opened message itself, holding
  its echo and reading the host's Stopping from the status feed, shows the same
  list after every frame as a phone that opened the chat fresh then.

* test(native-chat): pin the stop row to every frame from the one that took the send back

Both guards compared a merged phone with a fresh one, so a list bug they
shared passed, including one that held the stop row back until the next send.
Both now check, at every frame from the take-back on, that the list itself
shows the stop row: the data test through the list's own turn disclosure, the
hooks test on the live and the fresh phone.

Also:
- the send made while stopping is written after the stopped turn's end, as
  the QA journal shows, and while the turn still runs, as a second case;
- the long chat revises and drops a status near its end, inside the window;
- each phone reduces its own copy of every frame;
- Stopping is checked on the never-opened send's own Stop;
- the headers say what neither guard covers;
- the mobile production typecheck leaves *.test-fixture.ts to the tests'
  program, as it does tests, since these fixtures import desktop host code.

* test(native-chat): check the stop row in the chat view's FlatList, through the real overlay

The hooks guard rebuilt the overlay and chat view by hand, so a memo in the
real view that held its list back until the next send passed it. The guard
now renders the real overlay and chat view from the phone's own hooks, and
checks the stop row in the FlatList's data at every frame from the one that
took the send back. It also subscribes once before the history's last
dropped status, so removals run through the real hooks too.

* test(native-chat): compare the live and fresh phone on the chat view's own FlatList

The hooks guard compared a hand-built copy of the overlay and view, so a memo
in the real ones keyed on list lengths kept stale rows past it. It now
compares, after every frame, what the real chat view hands its FlatList:
each row as its renderItem draws it, with its bar, and the footer. The
hand-built copy is gone. It also checks that the FlatList's keys never
collide and that a changed list never arrives in the same array, and the
controller stub's SAFETY note now states what the stub really provides.

* test(native-chat): read the outbox reconcile from where main moved it

* test(native-chat): pass the projection's options and mock the phone row's new imports after main's rejected-in-place rows

* refactor(native-chat): place a taken-back send by where the host now puts its row

#24710 moves a rejected send's row, a Stop's take-back included, to the row
that rejected it, in no turn. Draw it at that row, past the end of every turn
opened before it, and keep the send-order rule. A send whose turn opened before
the provider echoed it is claimed by that turn's record when it was sent before
the record and taken back after it, by submittedSequence, and is drawn as the
turn's opener. The steer branch goes: the host no longer says which turn a
taken-back steer joined, so it is drawn after that turn with its own row.
The older-host fallback (floor, clock compare, submittedAt order) is now gated
on submittedSequence alone and marked Temporary. resolvedSequence is gone, as
in #25073.

* test(native-chat): a turn recorded before a send was made is not the turn it opened

* test(native-chat): a message a Stop withdrew is drawn with its stop row, not hidden

#24710's tests pinned a withdrawn send as hidden, the rule this PR replaces.
Each keeps what it is about: a withdrawn copy does not hide a failed one, no
delivery notice is raised, and a message the host failed to deliver stays
hidden on the phone.

* fix(native-chat): a retried message no longer waits behind a later Stop

Retry dropped the Stop it had outlived but kept the mark that it was sent while
a Stop was ending a turn, so a retried message waited behind whatever later,
unrelated turn a Stop was ending. Retry is a new send: drop that mark too.

* feat(native-chat): publish the turn a withdrawn Codex send was answered into

Same change as #25073 at 93749070e48b, so this stack builds on it.

* feat(native-chat): say how a withdrawn Codex send joined the turn it names

Same change as #25073 at ab2826ee1854, so this stack builds on it.

* fix(native-chat): open a turn for a stopped send only when the host says it started it

A send a Stop took back after its turn opened but before Codex echoed it
is drawn as that turn's opener when the host names the turn and says the
send started it. A steer into that turn keeps its own row after the turn.
The guess from journal order and times is kept only for hosts that
publish neither field, and never hands a turn the provider resumed on its
own to a send. A page that starts inside such a turn draws the send
before the turn's first loaded row.

* test(native-chat): an echoed opener keeps its turn from a send the host says started it

* feat(native-chat): state on every rejection whether it names a turn

Same change as #25073 at e02f98add56b, so this stack builds on it.

* fix(native-chat): place a stopped send from older history by journal order

A rejection written before the host named turns carries no answered turn,
though a newer host still publishes where it was sent and has moved its
row to the take-back. Such a send is matched to its turn by journal order
again, as before the host named turns; a rejection that states no turn
opens none.

* docs(native-chat): say an unreadable answered turn reads as none

Same change as #25073 at 4ab6cc431c01.

* refactor(native-chat): order stopped sends without non-null assertions

One helper sorts by the published send position when every entry has it,
else by accept time, and both stopped-send sorts use it. The rule kept for
rejections written before the host named turns is labelled as kept for
good: it draws those rows exactly as before.

* docs(native-chat): say which half of the older-history turn rule is kept for good

* fix(native-chat): word a send after a Stop by whether this send will queue

The 'queue a message to run after the stop' placeholder read the host's
queue capability alone. A send queues only when the host queues and this
send asks it to: the queue setting is on and no pending prompt blocks the
queue. Desktop and phone now word the placeholder from that same decision
their send uses.

* test(native-chat): one test per case for the words of a send after a Stop

* refactor(native-chat): the dictation hook owns the composer's dictation state

Keeps…
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant