Session resume and multi-surface ownership
Source:
docs/decisions/session-restart-refuse-second-writer.md
Status: current
Session resume and multi-surface ownership
Section titled “Session resume and multi-surface ownership”Decision
Section titled “Decision”Resume image = CRDT / PEW. Product session meaning restores from the session plane
(openWork, sealed Expectation results, authored fields). Chrome derives from the work
forest (SessionRoot.findRunningTurn(), approvalQueue / needsHuman — ../runtime/approval.md).
There is no parkedTool / hasOpenTurn() / hasRunning() chrome field. Process-local
host logs are never resume input.
Plane dial is multi-peer. Replication does not implement dial-time writer leases
(?role=writer / busy lease codes). Clients attach as CRDT peers and steer via session RPC
(turn, compact, kv/set, kv/clear, connect/adopt, connect/drop) and PEW/Proposals
(cancel / Question), and they write durable approval fields on open Work. They do not CRDT-mint PEW/Expectation bodies. PEW claim ownership is process-local to the one daemon process
when a session is claimed — not a replication upgrade gate.
CLI resume is ledger session id + plane rehydrate (--resume [sessionId]). There is
no product --fork steal path on the plane dial.
Storage lives under the harness install root (~/.harness/… per convention): plane ydocs,
session pairing, leftover metadata.
Rationale
Section titled “Rationale”Once obligation and sealed results live on the Expectation tree, replaying a second image (event log / fold) for “phase” or transcript truth is dual books. Derive chrome from openWork shape.
Dial-time exclusive writer was rejected for the current product: multi-surface CRDT peers are the normal attach story; exclusive execution is PEW claim, not a WebSocket upgrade role. Reintroducing steal/lease-steal on the dial would recreate dual-resume interleave without solving who executes work (the claim owner).