P2-1: Guard SessionId NPE with safe-call in SessionsReducer
P2-2: Remove 16 dead event classes + reducer branches; replace with live orchestration events in tests
P2-3: Standardize ChatInput divergences — guard CancelSession, single-arg ProtocolError
P2-4: Remove dead TuiToolRecord.diff and ToolDisplayStatus.REQUESTED
P2-5: Remove dead streamLive from SessionEventBridge
P2-6: Extract SessionsReducerContext data class for 6+ param method
P2-7: Replace StageId("none") sentinel with TypeId.NONE
P2-9: Add TypeId.random() factory on all type-alias IDs
P2-10: Add KDoc on schemaVersion documenting reserved-for-migration
P2-8: Verified RouterReducer string-template already correct (TypeId value class toString)
P1-1: Replace check-then-act with computeIfAbsent for activeSessionJobs to
prevent double-launch. Register pendingApprovals[requestId] BEFORE emitting
ApprovalRequestedEvent to close the approve-before-register window.
P1-2: ToolCompleted with a diff now appends msg.diff to routerMessages
instead of the static "--- diff from $toolName ---" marker.
P1-3: Change routerMessages from List<String> to Map<String, List<String>>
keyed by sessionId.value. RootReducer appends to the correct session's list;
RouterPanel renders only routerMessages[selectedId].
P1-4: On IDLE chat submit, SessionsReducer creates an optimistic
SessionSummary(status="STARTING") and sets selectedId.
processSessionStartedMessage removes any STARTING session and inserts the
real one on echo. RootReducer sets sessionEntered=true for the optimistic
session.
Tests: LaunchRegistrationRaceTest, ApprovalRegisterBeforeEmitTest,
RootReducerTest (diff/per-session/isolation/optimistic-submit),
SessionsReducerTest (optimistic/reconciliation). All P0/P1 tests pass.
./gradlew check green.
Event log integrity (sole source of truth):
- SqliteEventStore: serialize append/appendAll under a Mutex, enable WAL +
busy_timeout + synchronous=NORMAL, roll back on any Throwable. Replaces the
app-computed `SELECT MAX(seq)+1` read-modify-write that dropped events under
concurrent appends (race was invisible to CI: only the in-memory store and
single-threaded :memory: tests were ever exercised).
- Serialization: encodeDefaults + ignoreUnknownKeys, explicit @SerialName on all
46 EventPayload subclasses and event-referenced enum constants, @Serializable on
RiskLevel/RiskAction. Guards the append-only log against silent corruption from
future class renames, field removals, or default-value changes.
Approval/grant security (Invariant: approvals cannot widen authority):
- Tier authorization is now a ceiling (request.tier.level <= max granted) instead
of set membership; SESSION grants bind to a specific toolName instead of matching
everything; handleCreateGrant rejects empty/over-tier/scopeless grants.
Router chat wiring (Phase 0-2): ChatInput round-trip, StartChatSession from IDLE,
router-panel layout, workflows behind Ctrl+W.
Tests: SqliteEventStore concurrency, serialization round-trip + discriminator
stability + unknown-key tolerance, adversarial grant scope/tier; updated existing
approval and reducer tests for the new grant semantics and StartChatSession effect.
- Fix duplicate inference requests after approval resume by registering orchestrator
jobs in activeSessionJobs (ServerModule.launchSessionRun), so the guard in the
OrchestrationResumedEvent subscription prevents spurious duplicate resume.
- Replace blocking Files.readString in computeToolPreview with withContext(Dispatchers.IO)
by making the function suspend — no blocking I/O on the coroutine dispatcher.
- Guard orderedIds.add() in rebuildTools against duplicate invocation IDs on replayed
ToolInvocationRequestedEvent to prevent duplicate tool records in snapshots.
- Add unified-diff preview for file_write tools: computeToolPreview reads existing
file and generates ---/+++ diff before emitting ApprovalRequestedEvent.
- Render diff preview with color coding in ApprovalSurface (@@ yellow, +/- green/red).
- Include current-stage tool records in SessionSnapshot via rebuildTools event replay.
- Fix RouterContextBuilderTest: recursive buildPack helper and 2 tests using class-level
builder instead of their local builder instances (conversationKeepLast mismatch).
- Add suspend keyword to RouterFacadeTest mock, fix buildPack recursion.
- GlobalStreamHandler.handleCreateGrant validates scope (SESSION/STAGE)
and sends ProtocolError to client on validation failure instead of
silent log.warn + drop.
- Derive event stageId directly from GrantScope type, removing
redundant stageIdForEvent tuple.
- SessionOrchestrator integrates ApprovalEngine to check active grants
before requesting user approval for T2+ tool calls.
- ContextEntry gains EntryRole (SYSTEM/USER/ASSISTANT/TOOL) field for
proper chat message role mapping.
- RouterContextBuilder.build is now suspend; uses Tokenizer for
accurate token estimation with fallback to character-based estimate.
- LlamaCppInferenceProvider maps EntryRole to ChatMessage role instead
of heuristic layer-based inference.
Three coordinated changes:
1. DefaultOrchestrationReducer now handles TransitionExecutedEvent,
updating currentStageId so the projected state always reflects the
actual current stage rather than staying stuck at the start stage.
2. DefaultSessionOrchestrator.resume() re-enters the execution loop at
the current stage without re-emitting WorkflowStartedEvent. It reads
currentStageId from the projected state, creates an ExecutionContext
there, and calls enterStage → step exactly as run() does after its
first stage.
3. ServerModule.start() calls resumeAbandonedSessions(), which scans all
RUNNING/PAUSED sessions on startup and launches resume() for each one
whose orchestrator is no longer in memory. Sessions that have a live
deferred are unaffected; only sessions with no coroutine (e.g. the
server was restarted while a tool was executing or approval was pending)
are picked up and re-executed from their current stage.
When a TUI client connects at the exact moment between an
OrchestrationPausedEvent being stored and its corresponding
ApprovalRequestedEvent being stored, the approval projector sees empty
pendingApprovalRequests while orchState.pendingApproval=true. The
stuck-session fix would then append a spurious OrchestrationResumedEvent,
clearing the TUI's pendingApproval display and hiding the approval dialog.
Fix: count OrchestrationPausedEvents vs ApprovalRequestedEvents in the
event log. If there is an unpaired pause (more pauses than requests),
the session just entered the gate — skip the fix entirely.
Also remove spurious ToolExecutionCompleted/Failed emissions from the
kernel orchestrator; those events are emitted by SandboxedToolExecutor
in the infrastructure layer. Keep ToolExecutionRejectedEvent which the
orchestrator does own (rejection happens before executor.execute is
called).
Sessions that had an approval resolved (or never needed one) but never
received OrchestrationResumedEvent would show the last tool as RUNNING
forever with no subsequent events. Three coordinated fixes:
1. SessionOrchestrator now emits OrchestrationResumedEvent in both the
approved and rejected approval branches, so the paused flag clears
correctly going forward.
2. SessionEventBridge.replaySnapshot() detects the stuck pattern
(pendingApproval=true with no unresolved requests) and appends a
synthetic OrchestrationResumedEvent so historical sessions self-heal
on next TUI connect.
3. DomainEventMapper maps OrchestrationResumedEvent → SessionResumed;
TUI SessionsReducer/SnapshotPhaseReducer handle the new message,
clearing pendingApproval and setting status back to ACTIVE.
Also adds server-restart recovery path in DefaultSessionOrchestrator
(emit decision + resume events directly when no live deferred exists)
and pre-registers pending approvals in ServerModule.start() to close
the race between reconnect and ApprovalResponse routing.
Reordered handleStartSession so protocol messages are sent before the
orchestrator launches in module.moduleScope. If the WS is already closed,
session.send() throws and the orchestrator never launches — avoiding silent
data loss where the session runs but the client never learns it exists.
- Stop silently booting user from session view on completion
(SessionsReducer.processSessionCompletedMessage no longer deselects)
- Wrap StageToolManifest send in runCatching to survive WS disconnect
after orchestrator launch in module scope
- Fix navigateUp dead state: wrap to last workflow instead of -1
- Consolidate event store reads in SessionEventBridge (single read
for both recentEvents and approval state), removing
DefaultApprovalRepository dependency
- Add unified diff viewer for file_write/file_edit tools across all layers:
ToolReceipt.diff → DiffUtil (LCS-based) → SandboxedToolExecutor → ToolCompleted
→ TuiToolRecord.diff → DiffViewer widget (colored +/- lines)
- Add workflow selection panel: WorkflowList server message, WorkflowListPanel
widget, ↑↓ seamlessly extends into workflow picker from session list
- Add cursor/caret support: inputCursor in TuiState, CursorLeft/CursorRight
actions and key events, AppendChar inserts at cursor, Backspace deletes before
- Colorize event history strip (green/red/yellow/blue by type) and input bar
(blue/yellow prompt, cyan session name, blue keybindings)
- Show 5 recent events instead of 3; increase event strip height to 6
- Remove lastEventAt sort so display and navigation use consistent order
- Fix approval reconnect: register pending approvals with ApprovalCoordinator
during snapshot replay so lookupSession works after reconnect
- 167 tests pass (126 TUI + 41 server)
- Change EventHistoryStrip take(3) to takeLast(3) so it shows the 3 most
recent events instead of the 3 oldest (chronological order is oldest-first)
- Add bridge test confirming replaySnapshot populates recentEvents from the
event store (with 3 different event types mapped correctly)
- Add TUI SessionsReducer test confirming processSessionSnapshotMessage maps
EventEntryDto entries from the snapshot into TuiEventEntry on the summary
Three fixes:
1. Status bar now shows model/provider from ProviderStatusChanged:
- RootReducer sets currentModel and providerType when the message arrives
- providerType is LOCAL for llama/local providers, REMOTE otherwise
- Removes the stale '(no model) (local)' display
2. SessionSnapshot now carries recent event history:
- New EventEntryDto in the protocol with timestamp/type/detail
- SessionSnapshot.recentEvents populated by bridge from event store
- Bridge reads last 7 display-relevant events per session
- TUI processSessionSnapshotMessage maps them to TuiEventEntry
- Completed sessions finally show their event history
3. SessionStarted now switches selectedId to the new session:
- RootReducer cross-field weave updates selectedId alongside sessionEntered
- Previously kept the old selectedId, navigating user into the wrong session
- Works whether starting a session from the list or during replay
KeyResolver was swallowing Enter in IDLE state when input text was blank,
so SubmitInput never reached RootReducer to set sessionEntered=true.
Now Enter always dispatches SubmitInput in IDLE — RootReducer handles
blank text by entering the selected session, non-blank by starting a
new session (as before). IN_SESSION and FILTER mode unchanged (blank
Enter still returns null there).
Restructure the TUI around a DisplayState enum (IDLE, IN_SESSION, APPROVAL) replacing
the previous InputMode-based navigation (NAVIGATE, STEER removed). Key changes:
- **DisplayState model**: New `DisplayState` enum governs per-mode key resolution and UI
rendering. Removes `ROUTER`/`NAVIGATE`/`STEER`/`FILTER` InputMode complexity.
- **Input history navigation**: Up/Down arrows in IN_SESSION cycle through per-session
input history (ARCH-HISTORY-2/3). `savedInputBuffer` preserves in-flight text.
- **Input history filter**: `Tab` toggles between ROUTER and FILTER modes; history nav
disabled while filtering.
- **Ctrl-C → Cancel**: Rebind Ctrl-C from Quit to Cancel across all states.
- **Approval flow**: `ApproveActive`/`RejectActive` moved from SessionsReducer to
RootReducer via `pendingDecision`/`SubmitApprovalDecision`. Approval overlay
replaced by `ApprovalSurface` component.
- **Event history strip**: Replaces old overlay with a persistent `EventHistoryStrip`
component, toggled via Ctrl-E.
- **Background update badge**: New `backgroundUpdateCount` on SessionsState tracks
events arriving for non-selected sessions (ARCH-BADGE-1).
- **StageToolManifest**: New `ServerMessage.StageToolManifest` and `ToolManifestEntry`
model for pre-declared tool shapes per stage (RF-3).
- **Cleanup**: Removed `ActiveSession`, `ApprovalPanel`, `ToolsPanel` components.
Removed `InputMode.NAVIGATE`, `InputMode.STEER`, approval overlay state fields.
Various reducer simplifications (no more overlaid effects for approval responses).
Two follow-ups for the approval refactor:
- InputReducer STEER input mode hardcodes APPROVE; needs the future
approve/reject overlay UX to let the user pick.
- GlobalStreamHandler derives scopeSessionId from requestId as a
placeholder; needs a real requestId → sessionId lookup once exposed.
ApprovalCoordinator (added in epic-13) was never instantiated. Its four
capabilities — multi-client fan-out, single-resolver dedupe, request
timeout, and a unified domain mapper — were duplicated piecemeal across
GlobalStreamHandler and SessionStreamHandler, with a STEER-outcome
divergence between them (coordinator mapped STEER → APPROVED while
GlobalStreamHandler mapped STEER → REJECTED). This refactor wires the
coordinator and removes the duplication.
Protocol: drop ApprovalDecision.STEER. STEER is no longer a discriminator;
it's expressed as (APPROVE | REJECT) + non-null steeringNote, so the user
can steer alongside either choice. TUI's current single-keybind STEER
input flow now sends APPROVE + note (matching the original epic-13
intent); a future overlay UX will let the user pick APPROVE or REJECT
explicitly.
Mapper: ClientMessage.ApprovalResponse → DomainApprovalDecision lives in
a single shared `toDomain` helper (apps/server/approval/
ApprovalResponseMapper.kt). Both stream handlers and the coordinator
use it.
Config: delete the duplicate apps/server/approval/ApprovalConfig.kt;
ApprovalCoordinator now takes core.config.ApprovalConfig (already had
timeoutMs=300_000L). ConfigLoader already populates it.
Wiring:
- ServerModule owns a SupervisorJob-backed moduleScope, constructs
ApprovalCoordinator, and on start() subscribes eventStore.subscribeAll()
to route ApprovalRequestedEvent payloads to onApprovalRequested.
- GlobalStreamHandler delegates ApprovalResponse to
approvalCoordinator.handleResponse and registers/unregisters via the
new registerGlobalClient/unregisterGlobalClient (global sockets aren't
bound to one SessionId, so broadcasts union session and global sets).
- SessionStreamHandler delegates ApprovalResponse and registers per-session
via registerClient/unregisterClient.
- Timeout is on by default at 5 minutes via config.timeoutMs.
Tests: ApprovalCoordinatorWiringTest covers delegate path, dedupe
producing ProtocolError, and event-stream subscription routing.
The cleanup-04 spec's write side was missing: Action.ApproveActive and
Action.RejectActive were dispatched by KeyResolver but had no reducer
branch, making the approve/reject keybindings silent no-ops. STEER
SubmitInput emitted an ApprovalResponse effect without clearing
`pendingApproval` on the selected session, violating the spec invariant
that the effect emission and the clear happen in the same tick.
SessionsReducer now handles both actions via a private
respondToSelectedApproval(sessions, decision, note) helper that reads
state.selectedPendingApproval(), clears the field, and emits
Effect.SendWs(ApprovalResponse(...)). InputReducer's STEER SubmitInput
branch clears `pendingApproval` on the selected session in the same
returned TuiState as the response effect.
Adds four tests covering APPROVE, REJECT, no-pending no-op, and
STEER atomicity.
Complete the tui-02 spec acceptance criteria: delete the orphan
`connectSession`, `disconnectSession`, `sessionStreamJob`, and
`sessionWsSession` members from TuiWsClient, and remove the `send()`
fallback that previously routed ApprovalResponse over a per-session
socket. All ClientMessage types now travel the single global socket.
Server side: GlobalStreamHandler.handleClientMessage now actually
handles ApprovalResponse (was returning a protocol error), converting
to a domain ApprovalDecision and dispatching to the orchestrator —
mirrors SessionStreamHandler's prior logic.
Adds ApprovalResponseGlobalSocketRoundTripTest covering APPROVE and
STEER encode/decode through ProtocolSerializer.
Close the narrow race where `streamGlobal` launched the subscribeAll
collector and immediately read `lastGlobalSequence()` — events appended
in that window were dropped by the replay=0 SharedFlow before the
collector actually subscribed. Now use a CompletableDeferred barrier
signaled via `onSubscription` (SharedFlow) or `onStart` (cold fallback),
awaited before `bridge.replaySnapshot()`.
Closes the remaining gap on finding #1 from
docs/specs/2026-05-24-review-fixes.
Effect.Quit is appended at the tail of the effect list rather than
prepended, so all sub-reducer cleanup effects dispatch before runner
teardown. Combined with the sequential dispatch from effects-01, list
position is a runtime guarantee.
Closes finding #9.
Replace per-effect launch with a single launch that iterates effects
sequentially via dispatchAll, closing the ordering race (I-E1 invariant).
Add EffectDispatchOrderTest proving sequential preserves order while
fire-and-forget does not.
Remove the approvalAction/NoOp wrong-scope filter and the ApprovalReducer
call site from RootReducer. approvalJustArrived is now derived from the
selected session's pendingApproval delta. Delete ApprovalReducer.kt,
ApprovalState.kt, and ApprovalReducerTest.kt; approval truth is
structurally owned by SessionSummary.
SessionsReducer now handles ServerMessage.ApprovalRequired and populates
SessionSummary.pendingApproval directly on the matched session. The
SessionSnapshot handler also propagates approval fields to pendingApproval.
ApprovalReducer's ServerEventReceived branch is removed; approval truth is
now strictly scoped to a single SessionSummary.
Add pendingApproval: ApprovalInfo? = null to SessionSummary and remove
the global approval: ApprovalState slot from TuiState. All production
code derives active approval from the selected session; RootReducer
bridges ApprovalState in/out of the selected session for the duration
of the existing ApprovalReducer (removed in Cleanup 03).
SessionSnapshot is the correct trigger for connectSession() — the client
has enough state to stream live events at that point. SessionStarted fires
pre-snapshot and no longer needs to emit ConnectSession.
Migrate _connection from MutableSharedFlow + tryEmit to Channel(UNLIMITED) + send to ensure no connection events are dropped under high load. Removes unused MutableSharedFlow and asSharedFlow imports. Changes public connection property type from SharedFlow to Flow for consistency with messages field.
- Replace MutableSharedFlow with Channel(UNLIMITED) for _connection
- Convert all _connection.tryEmit() calls to _connection.send()
- Update public connection property to use receiveAsFlow()
- Add TuiWsClientConnectionChannelTest with 10k event no-drop verification
Replace MutableSharedFlow + tryEmit pattern in _messages field with Channel(UNLIMITED) + receiveAsFlow() to guarantee no message loss under high throughput. The extraBufferCapacity-based SharedFlow silently dropped messages when subscribers were slow; Channel(UNLIMITED) provides deterministic FIFO behavior with no drops.
Updated public messages property type from SharedFlow to Flow for compatibility.
Changed both message emission sites (connect() and connectSession()) from tryEmit() to send().
Added TuiWsClientChannelTest with 10k message no-drop verification.
Acceptance criteria:
- Channel(UNLIMITED) used for _messages instead of SharedFlow
- receiveAsFlow() converts channel to Flow
- send() replaces tryEmit() for message emission
- connectSession/disconnectSession/sessionStreamJob/sessionWsSession intact
- 10k message test verifies no-drop guarantee
Add three new fields to support the snapshot/live streaming protocol phase:
- snapshotPhase: Boolean (true during initial snapshot)
- pendingEvents: List<ServerMessage> (FIFO buffer during snapshot)
- cursors: Map<String, Long> (per-session high-water marks for deduplication)
All fields include KDoc documenting their invariants and purpose. Additive
change only; all existing tests continue to pass.
Establishes subscribeAll() before replaySnapshot() so no event can slip between the
projection read and live forwarding. Removes liveStreamJobs map and per-session forwarder
spawn from handleStartSession; all live forwarding flows through the single global
subscription. Closes findings #1 (race) and #5 (truth sources).
Tests cover happy path, race (x100), empty sessions, and shutdown/leak cases.
SessionOrchestratorIntegrationTest: wire approvalRepository into
OrchestratorRepositories constructor which gained the field in the kernel
refactor. TambouiKeyMapperTest: correct ctrl-h to alt-h — the mapper has
always placed ToggleApprovalOverlay under the Alt branch, not Ctrl.
SessionOrchestrator.emit: replace substring(0,7) with take(7) to avoid
StringIndexOutOfBoundsException when session IDs are shorter than 7 chars.
Capture lastGlobalSequence() before any projection read to anchor the
buffer-drain window; capture lastSequence(sessionId) before each session's
projection read. SessionSnapshot.lastSequence now carries the global cursor
shared across all sessions in the batch. pendingApprovals populated from
filtered approval state and sorted by (timestamp, requestId) for deterministic
ordering. SnapshotComplete emitted unconditionally including the zero-sessions
case. Four new tests: zero-sessions, SnapshotComplete-last ordering, global
cursor isolation, and per-session cursor value.
Adds a file-private SLF4J logger and replaces the silent else->null branch
with a debug log line that names the payload type, sessionId, and sequence.
Test extended with a log-capture case that verifies exactly one DEBUG event
is emitted containing the payload class name for unrecognised event types.
StoredEvent gains sessionSequence: Long (per-session monotonic); existing
sequence field becomes the global monotonic cursor across the entire store.
SqliteEventStore allocates both counters inside the same BEGIN IMMEDIATE
transaction and emits to a global MutableSharedFlow after commit.
InMemoryEventStore mirrors this with an AtomicLong global counter and a
suspend-on-overflow SharedFlow. EventStore interface gains subscribeAll()
and lastGlobalSequence(). Contract tests updated and extended to cover
global-sequence and cross-session subscribeAll invariants.
Every event-derived ServerMessage gains sequence (global) and sessionSequence
(per-session) cursor fields. SessionSnapshot adds lastSequence and
lastSessionSequence at projection-read time. SnapshotComplete data object
terminates the snapshot phase and is registered in the polymorphic module.
replaySnapshot() now emits SnapshotComplete after all SessionSnapshot messages.
SessionStarted audit deferred with TODO comment. DomainEventMapper propagates
both cursors to all mapped messages including InferenceCompleted.
- fixed the tool overlay in tui.
- fixed tool calling - added schemas.
- getting all sessionIds via event store.
- instead of sending all events on the replay - there's a new way for replaying.
- session snapshot is now a thing getting sent for previously created sessions.
- added logging to important parts.
- revert workflowId from WorkflowCompletedEvent.
fixed detekt issues where possible.
fixed disttar failing build because tools is added twice in the server module.
added workflowId where required.
fixed some tests not being recognized because of runBlocking without explicit return type.
formatting + imports.