Skip to content

Session resume and multi-surface ownership

Source: docs/decisions/session-restart-refuse-second-writer.md
Status: current

Session resume and multi-surface ownership

Section titled “Session resume and multi-surface ownership”

Resume image = CRDT / PEW. Product session meaning restores from the session plane (openWork, sealed Expectation results, authored fields). Chrome derives from the work forest (SessionRoot.findRunningTurn(), approvalQueue / needsHuman — ../runtime/approval.md). There is no parkedTool / hasOpenTurn() / hasRunning() chrome field. Process-local host logs are never resume input.

Plane dial is multi-peer. Replication does not implement dial-time writer leases (?role=writer / busy lease codes). Clients attach as CRDT peers and steer via session RPC (turn, compact, kv/set, kv/clear, connect/adopt, connect/drop) and PEW/Proposals (cancel / Question), and they write durable approval fields on open Work. They do not CRDT-mint PEW/Expectation bodies. PEW claim ownership is process-local to the one daemon process when a session is claimed — not a replication upgrade gate.

CLI resume is ledger session id + plane rehydrate (--resume [sessionId]). There is no product --fork steal path on the plane dial.

Storage lives under the harness install root (~/.harness/… per convention): plane ydocs, session pairing, leftover metadata.

Once obligation and sealed results live on the Expectation tree, replaying a second image (event log / fold) for “phase” or transcript truth is dual books. Derive chrome from openWork shape.

Dial-time exclusive writer was rejected for the current product: multi-surface CRDT peers are the normal attach story; exclusive execution is PEW claim, not a WebSocket upgrade role. Reintroducing steal/lease-steal on the dial would recreate dual-resume interleave without solving who executes work (the claim owner).