Repository navigation
feat(profiles): add session profile disk corroboration reader - #1922
noxsystems wants to merge 4 commits into
Conversation
Part of Gentleman-Programming#1064 (slice 3b-i, codec). Standalone decoder for the gentle-pi.session-profile/v1 custom entry: closed origin set, own-property checks, one invalid route invalidates the whole snapshot, unknown fields ignored, prototype keys kept as own data. No Pi API, disk access, Enter, startup or routing changes. Chain: main -> [this] decoder -> encoder + active-branch replay (next). Out of scope: encoder, replay, disk-reader corroboration, Enter wiring.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (6)
Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 1 remain after this review. 📝 WalkthroughWalkthroughAdds a v1 session-profile codec and branch replay helper. Adds a read-only disk reader that checks the selected profile entry against session JSONL records. Adds unit and integration tests and documents the payload, replay, and disk-reader contracts. ChangesSession Profile Persistence and Disk Reader
Priority: ⬇️ Low Estimated code review effort: 4 (Complex) | ~45 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant SessionProfileSource
participant readSessionProfileDisk
participant SessionJSONL
SessionProfileSource->>readSessionProfileDisk: Provide session ID, file path, and branch
readSessionProfileDisk->>SessionJSONL: Read session records
SessionJSONL-->>readSessionProfileDisk: Return JSONL contents
readSessionProfileDisk->>SessionProfileSource: Recheck captured source state
Merge Risk: ⚪ Minimal · up to This change adds a read-only session profile disk corroboration reader with no consumer wiring, so production behavior is unchanged. No merge-blocking risk was identified. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 22.73% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 22 functions across 5 files. (1 skipped: 1 unsupported.)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…dicate Export isSafeAgentName from model-routing-authority and use it in the session profile decoder instead of probing normalizeModelConfig. Assert constructor and prototype keys stay own data in the hostile-keys test. Addresses the two CodeRabbit comments on Gentleman-Programming#1918.
Part of Gentleman-Programming#1064 (slice 3b-i, codec). Adds createSessionProfileBind and createSessionProfileClear (explicit user selections only, typed undefined model/thinking omitted, effort stays strict) and replaySessionProfileBranch: the newest profile-family entry on a caller-supplied, already disk-corroborated active branch is terminal, including invalid and unsupported, and never revives an older binding. Still no disk access, Pi API, Enter or routing changes. Chain: main -> decoder (previous) -> [this] encoder + replay. Depends on: feat/1064-3b-i-1-codec-decoder. Out of scope: disk-reader corroboration, Enter wiring, guards.
Part of Gentleman-Programming#1064 (slice 3b-i, disk reader). readSessionProfileDisk reads the session's public active branch and JSONL file, selects the newest profile-family entry (excluding known failed append IDs) and admits it only when the record on disk is byte-identical; otherwise it returns one indeterminate reason without record contents. No writes, fallback, cache, ancestry repair or fsync; a missing file never restores a memory-only profile. Verified against a real SessionManager session file. Chain: main -> decoder (Gentleman-Programming#1918) -> encoder + replay (Gentleman-Programming#1919) -> [this]. Depends on: Gentleman-Programming#1919. Out of scope: append controller, authority publication, Enter wiring.
f08be2b to
4d56f74
Compare
Summary
Part of #1064, slice 3b-i (persistence). Supplies the corroboration that
replaySessionProfileBranch(#1919) requires but cannot establish: whether the selected record on the active branch is actually on disk.readSessionProfileDisk(source, options): stateless, synchronous. Takes the session id, session file path and public active branch; selects the newest profile-family entry on the branch, excluding caller-suppliedknownFailedEntryIds; parses the JSONL file; admits the entry only when the disk record is identical (isDeepStrictEqualover a JSON snapshot, so getters and mutable references cannot leak in).entryIndexandlineNumber, orindeterminatewith one closed reason (missing-source,invalid-candidate-metadata,unreadable-file,source-changed,invalid-json,invalid-record,session-header-mismatch,duplicate-id,missing-header,selected-record-missing,selected-record-mismatch,unserializable-source). Reasons never carry record contents or exception messages.source-changed.This is PR 3 of the chain.
Issue
Part of #1064
PR type
type:feature)Changes
4d56f74b5lib/session-profile-disk-reader.ts,tests/session-profile-disk-reader.test.ts,tests/session-profile-disk-reader-pi.test.ts, Disk corroboration section indocs/session-profile-format.md.Test plan
Verified on top of #1919,
main9782d26df, Node 25.2.1:tests/session-profile-disk-reader.test.ts: 29 pass, 0 fail (every indeterminate reason, failed-ID exclusion, source-changed detection, hostile getters, duplicate and header checks).tests/session-profile-disk-reader-pi.test.ts: 4 pass, 0 fail, against a realSessionManagerfrom@earendil-works/pi-coding-agentwriting to a temp directory.tests/session-profile-persistence.test.ts+agent-profiles+model-routing-authority: 77 pass.node scripts/check-types.mjs: 186 recorded diagnostics, no regressions.Review follow-ups (non-blocking)
replaySessionProfileBranch(feat(profiles): add session profile encoder and active-branch replay #1919), because it needs the raw branch index and the failed-ID exclusion before decoding. The "newest family entry is terminal" rule therefore lives in two places; happy to fold one into the other if you'd rather.Chain Context
main(fork PRs cannot stack bases; rebased as #1918/#1919 land)Summary by CodeRabbit