Repository navigation
Persist native human questions through timeout and explicit recovery - #1035
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Worker questions now remain durable when a display is skipped, expires or loses its connection. Explicit recovery reopens the same pending question with a fresh presentation and challenge; late replies cannot answer a replacement display. The portable service persists the hold before presentation and keeps answer-dependent work held.
Adds a source-only MCP presentation adapter with an injected protected admission port, cancellation-aware store commits, single-send answer delivery, and bounded reconciliation observations. Native cleanup and exact matching output are recorded as evidence while the hold remains active. A separate nonsigning diagnostic probe exercises desktop presentation and recovery.
Validation: affected memory/SQLite, transport, presentation, interruption and store tests pass. Exact-candidate lint, build, package-boundary and install-policy gates pass. Full branch independent review passed (370/370 affected tests); PR CI must pass before merge. Historical desktop recovery and installed-Codex output observations retain their original artifact/runtime scope.
This is a source-only foundation. Production human admission, protected source provenance/retention, worker consumption and action containment remain separate qualification work. No default controller, public answer route or production signer is enabled; passkey/OIDC remain optional host choices.
Independent review: PASS by
/root/native_probe_ux_review, full 23-file delta, candidate0713042ea7f43b8243d63a12af08d948f2e39155against currentmainbase523220b8b7a98424a01a58bde450f78e3dca2e13. Candidate-bound local gate evidence verified; source artifacts and qualification limits inspected. No blocking findings.