Skip to content

feat(server): record renderer publications as canonical events - #1777

Merged
chuks-qua merged 14 commits into
mainfrom
feat/canonical-publication-events
Sep 29, 2026
Merged

chuks-qua merged 14 commits into
mainfrom
feat/canonical-publication-events

Conversation

@chuks-qua

@chuks-qua chuks-qua commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

What

Numbered livePublication intents are the enriched, sanitized events the agent.event broadcast sends today. This PR records each one as a canonical publication.recorded envelope inside the same operation transaction, so the canonical stream now carries the same renderer-facing payload and replay or gap recovery delivers identical effects.

  • packages/agent-model: new publication.recorded canonical event carrying the publication id and the opaque event payload. The reducer treats it as a passthrough: identity and dedup bookkeeping apply, no thread or item state mutates.
  • canonical-execution-semantic-writer: storeReceipt commits one canonical envelope per numbered publication via the in-transaction commit path, and stores the accepted sequences as publication chunks so publishStoredEvents replays them like every other canonical envelope.
  • Unbuffered operation paths (control, stage-terminal, assistant text, terminal batches) cannot use the semantic publication buffer, so their committed envelopes queue on the writer and flush after the outer transaction commits. Buffered paths keep the existing flush.
  • threadStore: canonical pushes and reconnect deltas route publication.recorded payloads into handleAgentEvent with publicationId stamped, so the existing stable publication cursor accepts whichever copy (canonical or agent.event) arrives first and drops the other.

Why

The agent.event broadcast is fire-and-forget. The canonical stream is durable, sequenced, and gap-checked, but it only carried the pre-enrichment provider events. Recording the numbered publication itself moves the renderer-facing event stream onto the transport that can prove delivery, which is the prerequisite for retiring agent.event without losing tool events, notices, or terminal state on a dropped socket.

UI Changes

None.

Config Changes

None.

Review Notes


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

A half-open socket answers nothing and never fires close, so every
recovery mechanism (reconnect, hydration, subscription replay) waited
forever while the UI showed stale streaming state. A 30s interval now
issues the existing app.version RPC with a 10s deadline; an unanswered
probe closes the socket locally and the established onclose ladder owns
recovery. agent.send gains a 20s timeout so a composer submit cannot
park forever on a dead socket.

The wedged-socket test now answers the liveness probe, since a socket
that ignores it is exactly what the watchdog closes.
The reducer now writes routing.executionId onto the stored turn so
clients can correlate a canonical turn to the local runtime without
threading the event envelope through state. A payload-supplied
executionId that disagrees with routing is rejected as a routing
conflict.
Composer, project tree, and running-thread indicators now follow the
canonical replica once a turn correlates by execution identity, so a
dropped legacy terminal event can no longer strand runningThreadIds.
The optimistic window before turnStarted and the finalizing phase stay
on the legacy path until a canonical turn proves correlation. The
narrative projection keeps its existing child-only lifecycle gate.
The relay opened one socket and never recovered: a dropped connection
silently degraded the renderer to WebSocket-only delivery for the rest
of the session. Reconnect in the main process with bounded exponential
backoff, reset on successful connect, and stop when the window dies or
the relay is torn down. The renderer re-suppresses push channels as
frames resume, so no reconnect handshake is needed.
No caller remains: consumers read runningThreadIds directly.
Parent narrative recovery wrote items directly into canonical_agent_items,
so subscribed replicas only learned about them through snapshots. Each
mutation now commits an item.recorded envelope inside the existing
elapsed-bounded batch writer, discards become narrativeRecoveryDiscarded
tombstones, and the semantic writer flushes the envelopes through its
buffered publication channel. The web store reruns recoverParentNarrative
when a canonical batch touches narrative items, letting parent tool calls
and segments reach the chat through the canonical stream.
Numbered livePublication intents are the enriched, sanitized events the
agent.event broadcast sends today. Recording each one as a canonical
publication.recorded envelope inside the same operation transaction makes
the canonical stream carry the same renderer-facing payload, so replay and
gap recovery deliver identical effects without the legacy channel.

The reducer treats the envelope as a passthrough: identity and dedup
bookkeeping apply, but no thread or item state mutates. On the client,
canonical pushes and reconnect deltas dispatch the embedded event through
handleAgentEvent with its publicationId, so the existing stable
publication cursor accepts whichever copy arrives first and drops the
other.

Envelopes committed by unbuffered operation paths (control,
stage-terminal, assistant text, terminal batches) queue on the writer and
flush after the outer transaction commits, matching the buffered flush
used by live operations.
Live publication intents embed provider events before the public
enrichment stage, so canonical copies would persist raw tool inputs that
the legacy wire path strips. Sanitize the embedded event the same way
AgentEventPublicationService does before recording publication.recorded.
…hase

The runtime reconcile stamps runtimePhase from a correlated canonical turn
but never correlated the record's execution identity, so a canonically owned
"running" phase made getCanonicalLifecycleTurn treat the provider-owned child
turn as a local execution and suppress its projection. A later terminal
canonical event could then no longer clear the stamped phase either.

reconcileCanonicalRuntime now stamps turnExecutionId from the claiming turn's
executionId on live claims, and the lifecycle gate only treats runtimePhase
as locally owned when the canonical runtime turn is not the latest turn.
# Conflicts:
#	apps/web/src/stores/threadStore.ts
assertActiveTurnRecoveryRetention measured the serialized canonical
envelope drafts, letting transport overhead trip the cap before the
retained narrative itself did. Measure the persisted item payloads and
discarded item ids again, matching the pre-envelope accounting.
The byte-size computation pushed prepareParentNarrativeRecovery over
the complexity cap. Hoisting it keeps the retention accounting intact.
The rollback test still encoded the silent-write behavior where
recovery produced zero canonical events. recordParentNarrativeRecovery
commits item.recorded envelopes independently, so they survive a
finalize rollback and remain in the append-only history after the
terminal commit retires the item rows.
@chuks-qua
chuks-qua deleted the branch main September 29, 2026 21:34
@chuks-qua chuks-qua closed this Sep 29, 2026
@chuks-qua chuks-qua reopened this Sep 29, 2026
@chuks-qua
chuks-qua changed the base branch from feat/canonical-narrative-items to main September 29, 2026 21:35
@chuks-qua
chuks-qua merged commit 17f4f2c into main Sep 29, 2026
6 checks passed
@chuks-qua
chuks-qua deleted the feat/canonical-publication-events branch September 29, 2026 21:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant