Skip to content

feat(chat-swarm): deterministic worker continuation epoch transfer (#51-A) #120

Description

@James3014

Parent / purpose

Child implementation slice of #51. This issue owns #51-A deterministic worker continuation/rebind semantics only. It is intentionally transport-neutral and may proceed in parallel with #117.

Current source fence at creation:

  • repository: James3014/devspace
  • main: ab22dc9d0360bd02d00892734a5c51cdd0873f39
  • existing Swarm truth already includes workerId, carrierConversationFingerprint, checkpoint, continuationEpoch, task/attempt identity and fail-closed reconciliation.

Authority boundary

Preserve:

logical worker / task / attempt / continuation truth = Chat Swarm durable state
carrier creation/navigation/wake = #117/#105

Do not add browser/session-launch logic here. Do not create a second queue, worker registry, task authority or retry authority.

Required deterministic contract

At a safe continuation boundary:

worker W / epoch N / current carrier A
-> authenticated target carrier B requests continuation
-> request binds exact swarm + worker + sourceEpoch + targetEpoch
   + source carrier + target carrier + checkpoint hash + expiry/version
-> exact Owner approval / CAS
-> one atomic binding transfer
-> worker W becomes epoch N+1 on B
-> A is fenced from `next` / `submit`
-> durable readback recovers committed result after lost acknowledgement

Minimum V1 may allow transfer only when the worker is AVAILABLE, has no current task, and has a bounded checkpoint. Active/unknown effects must fail closed; they must not be cleared, requeued or duplicated by rollover.

Required invariants / hostile controls

  • target identity comes only from authenticated request metadata, never caller-supplied fingerprint;
  • source carrier must still equal the worker's current bound carrier at commit;
  • targetEpoch == sourceEpoch + 1;
  • exact replay is idempotent; changed material under the same attempt key is REPLAY_CONFLICT;
  • wrong swarm / worker / source epoch / target carrier fails closed;
  • parallel target carriers for the same worker: at most one commit;
  • expired request cannot commit;
  • response loss after commit is recoverable by durable readback and never creates a second replacement;
  • old carrier remains current until commit, then immediately loses worker authority;
  • old carrier next / submit after commit is rejected by existing worker identity checks;
  • no worker slot is added or consumed by continuation;
  • malformed/corrupt persisted continuation state fails closed;
  • restart preserves pending/committed continuation truth;
  • bounded capsule/checkpoint identity is hash-bound; no full transcript, hidden reasoning, credentials or raw tool dump is persisted.

Source shape

Prefer the smallest additive slice over current Swarm SQLite:

  • additive migration for durable continuation request/receipt state;
  • contract types/hash helper;
  • store transaction(s) for request/readback/commit;
  • coordinator methods that bind authenticated target identity and exact owner approval;
  • focused chat-swarm-continuation tests;
  • MCP/public tool registration may be included only if it remains bounded and does not pull P0: implement macOS zero-touch ChatGPT worker runtime pool #117 carrier behavior into this slice.

Verification

Required source acceptance:

  • focused continuation tests covering all positive/negative/replay/restart cases;
  • existing peer admission, task ledger, lifecycle, store and coordinator regressions;
  • database upgrade/reopen witness;
  • typecheck;
  • build;
  • npm test on macOS policy where practical;
  • git diff --check;
  • independent exact-head review before merge.

Claim ceiling

Source/CI completion of this issue may establish:

DETERMINISTIC_WORKER_CONTINUATION_SOURCE_ACCEPTED

It does not establish real ChatGPT conversation rollover, Auto Compact, zero-touch carrier creation, #117 completion, #51 overall completion or #104 Ultra parity.

Live #51 acceptance must later use #117/#105 to create the replacement carrier automatically with manual replacement-worker creation = 0 and manual continuation-ticket transfer = 0.

Activity

  1. self-assigned this
    on Sep 13, 2026
  2. James3014 commented on Sep 13, 2026

    @James3014
    OwnerAuthor

    2026-09-13 #120 source Candidate ready

    Focused implementation PR #122 is now Ready for review at exact head 503c900c1d3413207e1db7a9b0a98981c94b0281, base main@c6e09967cb745407de3a7d09808c472d38f6e612.

    Controller disposition: DETERMINISTIC_WORKER_CONTINUATION_SOURCE_CANDIDATE_READY.

    Exact-head macOS evidence from CI run #201 (34744259965):

    • Smoke macOS: typecheck/test/build/Doctor PASS
    • continuation coordinator PASS
    • durable-store PASS
    • restart-fence PASS
    • retired-carrier PASS
    • terminal-replay PASS
    • corruption-fence PASS
    • aggregate/domain PASS
    • Local agent sessions macOS PASS
    • Ubuntu Smoke PASS

    Windows Smoke remains the same pre-existing Test failure reproduced on current main c6e09967...; current delivery scope is macOS-only and no branch/check bypass is claimed.

    Source contract now includes authenticated target identity, exact owner/swarm approval, atomic epoch transfer, checkpoint/source-carrier CAS, unresolved-effect second-replacement fence, concurrent-target SUPERSEDED losers, retired old-carrier fence, terminal exact replay, TTL/attempt/hash binding, corrupt-ledger fail-closed behavior, restart reconciliation and lifecycle drain/reconcile-only gating.

    No second ledger/table/migration, browser carrier, public continuation MCP tool, provider catalog, routing authority or #117 implementation was introduced.

    Remaining #120 gate: independent exact-head review, then normal governed merge. Do not close #120 yet. Parent #51 remains open after #120 because real zero-touch carrier replacement / Auto Compact requires #117/#105 native evidence.

  3. James3014 commented on Sep 13, 2026

    @James3014
    OwnerAuthor

    2026-09-13 exact-head source candidate update — supersedes prior #120 candidate note

    Current source candidate:

    The earlier 503c900c... candidate evidence is superseded by additional controller review and repairs covering durable terminal metadata, absolute expiry/hash binding, unresolved-continuation no-duplicate fencing, retired-carrier fencing, state-independent terminal replay, cross-swarm reconciliation binding, and corrupt-state fail-close behavior.

    Exact-head verification on GitHub CI run #206 / 34745371083:

    • PR git diff --check: PASS;
    • all seven focused Chat Swarm continuation macOS jobs: PASS;
    • Local Agent Sessions macOS: PASS;
    • macOS Smoke: Typecheck/Test/Build/Doctor PASS;
    • Ubuntu Smoke: Typecheck/Test/Build/Doctor PASS;
    • Windows Smoke: Typecheck PASS, Test FAIL only on the pre-existing carrier-binding baseline.

    Windows baseline was compared against current main@c6e09967... push run #150 / 34735356613: both main and PR fail the same first seven carrier-binding.test.ts cases with the same AUTHORITY_REQUIRED: Cutover approval exceeds exact local resource or validity error. Therefore that failure is not attributed to #120. Branch-protection/required-check policy could not be read through the GitHub App, so no merge bypass is claimed.

    Persistence/reopen is exercised by startup-recovery tests using the same stateDir from a second lifecycle instance. This slice introduces no schema/table/migration, so schema upgrade is N/A.

    Remaining gate is governance-only: independent exact-head review of a168bb39... before merge. Owner/controller review is complete but is not independent approval. #120 remains OPEN; parent #51 remains OPEN. Real zero-touch ChatGPT conversation creation/replacement stays under #117/#105.

  4. James3014 commented on Sep 13, 2026

    @James3014
    OwnerAuthor

    Owner amendment — independent reviewer waived (2026-09-13)

    Owner explicitly removes the independent exact-head reviewer requirement from #120. This supersedes the earlier review-gate wording for this child issue only.

    Acceptance for #120 is now:

    After a normal GitHub merge of the exact head, #120 may be closed as source accepted with claim ceiling DETERMINISTIC_WORKER_CONTINUATION_SOURCE_ACCEPTED. Parent #51 remains OPEN; real zero-touch carrier replacement / Auto Compact still depends on #117/#105 native work.

  5. added a commit that references this issue on Sep 13, 2026
  6. James3014 commented on Sep 13, 2026

    @James3014
    OwnerAuthor

    #120 source acceptance — merged

    Owner reviewer waiver is active for this child issue. PR #122 merged normally at exact head a168bb39ea55a868f40c15e85f91fb1a59c0d8ce into main as merge commit 5256c40f56bbfd5a7eff7737ecf54da4b0359c4d.

    Fresh post-merge ref readback confirms main=5256c40f56bbfd5a7eff7737ecf54da4b0359c4d.

    Accepted claim ceiling for this issue only: DETERMINISTIC_WORKER_CONTINUATION_SOURCE_ACCEPTED.

    This does not establish real ChatGPT conversation rollover, zero-touch replacement, Auto Compact, #51 overall completion, #117/#105 completion, deployment, or production runtime acceptance. Those remain separate downstream/native gates.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions