What would you like to be added?
This issue collects the findings from the review of #12855 (H0c of #12827) that were still unhandled when the PR merged: the Suggestion-level pair from round 2 (R2-1, R2-2) and the twelve findings the round-3 review posted after the merge (R3-1 through R3-12, of which three are Critical). Every item was re-checked against main at d697f98553 on 2026-10-03 and still stands at the time of filing.
The fix lands as three follow-up PRs, grouped so that no two PRs touch the same file. Each thread gets an individual reply and is resolved once its fix merges.
PR 1 — the three Critical findings
- R3-1 — the Broker-record execution mapping ignores
dispatchGeneration (thread). executionOf maps a SETTLED/cancelled record whose own Broker ledger proves it was never claimed (dispatchGeneration == 0) to settled, producing the intent -> settled step the H0b record contract refuses and leaving a Monitor cancelled before dispatch with no committable settling revision. Fix: give the mapping the record's dispatchGeneration, map that case to not_started_proven in both languages through a shared brokerExecutionCases row, record the wire-reading divergence, and reconcile Decision 10 of the authority doc with the record-contract doc.
- R3-2 —
apply semantically validates only the one body-bearing line (thread). Every other event line, every unrecognised subtype, and every domain.committed line with an unregistered body is stored after no check beyond JSON well-formedness, while the authority's reopen reader validates all of them and refuses the Session — so one bad line bricks a Session at the next open with no error at commit time. Fix: run the event-level half of requireEnvelope for every event line, mirror the event-kind and subtype vocabularies, validate domain.committed domains whether or not a body is registered, mirror the reserved <domain>:<n> namespace, count Stage H lines instead of flagging, and put the per-kind byte caps in the shared limits contract.
- R3-3 —
task.updated lands in the message-projection sequence space (thread). The announcement rides the same public Session event sequence a turn's text deltas use, and both consumers decide "continues the previous Part" by reading the event at sequence - 1, so one announcement between two deltas splits an assistant message into two stored, durable Parts under a frozen projection version. Fix: carry task.updated on its own outbox written in the same transaction, drained by the slice that serves task events, keeping managed_agent_event to turn and lifecycle events.
PR 2 — cross-language contract pins and TypeScript semantics
- R2-1 — the
changes-after-it-ended reject case is decided by the fixed-key rule, not the terminal rule its id names (thread).
- R2-2 — the twelve shared reject cases pin only the error class, not the "refused before publishing" invariant (thread).
- R3-4 — the shared projection fixture has no meta-pins (contract version, list names/emptiness, key sets) in either language (thread).
- R3-5 —
commitExtensionRecord publishes the record body before validating the actor class and the caller-supplied input, so a refused commit leaves an orphan body per retry (thread).
- R3-7 — the projection hand-copies the terminal run-state list and its
runtimeState clause order and settled-time clamp are unwitnessed (thread).
- R3-8 — nothing observes the grant gate after a replacement, a renewal, a refusal, or a revocation that precedes its grant, and
revoke's revision ceiling disagrees with install's (thread).
- R3-12 —
rebuildExtensionRecords decides whether a committed body is a Stage H record from the live body registry alone, and the reopen path re-validates already-parsed operands with serial resource reads (thread).
PR 3 — Java test efficacy, design docs, OpenAPI surface
- R3-6 — a family of new Java assertions cannot fail (unfalsifiable
journal_tx legs and MySQL re-read projection, re-typed EXPLAIN, driftable anchors, compile-time-constant pins) (thread).
- R3-9 — the H0c design doc names error codes the store never answers, pins its survey to a stale commit, and over-claims guarantees (thread).
- R3-10 — the H0a task-contract and H0b record-contract docs still state as present truth what H0c falsified (planned flags, future-tense H0c, unanswered open questions, superseded acceptance criteria) (thread).
- R3-11 — the four task routes flipped to
partial keep three false promises (five-source merge description, impossible 400 unsupported_feature, missing capabilities in WebShellSession.required, undeclared 403s) (thread).
What would you like to be added?
This issue collects the findings from the review of #12855 (H0c of #12827) that were still unhandled when the PR merged: the Suggestion-level pair from round 2 (R2-1, R2-2) and the twelve findings the round-3 review posted after the merge (R3-1 through R3-12, of which three are Critical). Every item was re-checked against
mainatd697f98553on 2026-10-03 and still stands at the time of filing.The fix lands as three follow-up PRs, grouped so that no two PRs touch the same file. Each thread gets an individual reply and is resolved once its fix merges.
PR 1 — the three Critical findings
dispatchGeneration(thread).executionOfmaps a SETTLED/cancelled record whose own Broker ledger proves it was never claimed (dispatchGeneration == 0) tosettled, producing theintent -> settledstep the H0b record contract refuses and leaving a Monitor cancelled before dispatch with no committable settling revision. Fix: give the mapping the record'sdispatchGeneration, map that case tonot_started_provenin both languages through a sharedbrokerExecutionCasesrow, record the wire-reading divergence, and reconcile Decision 10 of the authority doc with the record-contract doc.applysemantically validates only the one body-bearing line (thread). Every other event line, every unrecognisedsubtype, and everydomain.committedline with an unregistered body is stored after no check beyond JSON well-formedness, while the authority's reopen reader validates all of them and refuses the Session — so one bad line bricks a Session at the next open with no error at commit time. Fix: run the event-level half ofrequireEnvelopefor every event line, mirror the event-kind and subtype vocabularies, validatedomain.committeddomains whether or not a body is registered, mirror the reserved<domain>:<n>namespace, count Stage H lines instead of flagging, and put the per-kind byte caps in the sharedlimitscontract.task.updatedlands in the message-projection sequence space (thread). The announcement rides the same public Session event sequence a turn's text deltas use, and both consumers decide "continues the previous Part" by reading the event atsequence - 1, so one announcement between two deltas splits an assistant message into two stored, durable Parts under a frozen projection version. Fix: carrytask.updatedon its own outbox written in the same transaction, drained by the slice that serves task events, keepingmanaged_agent_eventto turn and lifecycle events.PR 2 — cross-language contract pins and TypeScript semantics
changes-after-it-endedreject case is decided by the fixed-key rule, not the terminal rule its id names (thread).commitExtensionRecordpublishes the record body before validating the actor class and the caller-supplied input, so a refused commit leaves an orphan body per retry (thread).runtimeStateclause order and settled-time clamp are unwitnessed (thread).revoke's revision ceiling disagrees withinstall's (thread).rebuildExtensionRecordsdecides whether a committed body is a Stage H record from the live body registry alone, and the reopen path re-validates already-parsed operands with serial resource reads (thread).PR 3 — Java test efficacy, design docs, OpenAPI surface
journal_txlegs and MySQL re-read projection, re-typedEXPLAIN, driftable anchors, compile-time-constant pins) (thread).partialkeep three false promises (five-source merge description, impossible400 unsupported_feature, missingcapabilitiesinWebShellSession.required, undeclared 403s) (thread).