Observed behavior: handleSessionStart in src/hooks/restore.ts checks publication admission, releases it, then awaits daemon startup and dynamic imports before pruning the local outbox. The pruneProcessed, pruneUnprocessed, and pruneErrorLog calls do not retain or reacquire the same publication authority. A nonterminal publication can begin between the initial check and the destructive operation.
Expected behavior: Serialize destructive outbox actions with canonical publication consumer authority so a maintenance/publication fence preserves pending or acknowledged input. Preserve the explicit local hook-append exception.
Root cause: A short admission precheck is used as permission for mutations after asynchronous work. Source ordering verified at a824d63d31876fc1fcca960f32a621b4392cf615; runtime race reproduction is still pending, so this report does not claim observed production data loss.
How to reproduce: In an isolated hook test, pause ensureDaemon after the initial admission. Prepare a nonterminal BackendPublicationCoordinator journal, resume SessionStart with connected=true and an old acknowledged/remote-pruned fixture row, and assert pruning refuses or preserves the row while the journal is nonterminal.
Evidence and scope: Discovered during #622 immutable snapshot/maintenance planning under #92. Relevant source is src/hooks/restore.ts around the initial publication check and subsequent prune calls. Track outside Epic #92's frozen inventory and native hierarchy. Minimal integration may be required for #622's retention acceptance; no implementation PR exists yet.
Environment:
- Agent: Codex / GPT-6 Astra
- Connector: CLI
- OS: Fedora Linux
- Source:
a824d63d31876fc1fcca960f32a621b4392cf615
Observed behavior:
handleSessionStartinsrc/hooks/restore.tschecks publication admission, releases it, then awaits daemon startup and dynamic imports before pruning the local outbox. ThepruneProcessed,pruneUnprocessed, andpruneErrorLogcalls do not retain or reacquire the same publication authority. A nonterminal publication can begin between the initial check and the destructive operation.Expected behavior: Serialize destructive outbox actions with canonical publication consumer authority so a maintenance/publication fence preserves pending or acknowledged input. Preserve the explicit local hook-append exception.
Root cause: A short admission precheck is used as permission for mutations after asynchronous work. Source ordering verified at
a824d63d31876fc1fcca960f32a621b4392cf615; runtime race reproduction is still pending, so this report does not claim observed production data loss.How to reproduce: In an isolated hook test, pause
ensureDaemonafter the initial admission. Prepare a nonterminalBackendPublicationCoordinatorjournal, resume SessionStart withconnected=trueand an old acknowledged/remote-pruned fixture row, and assert pruning refuses or preserves the row while the journal is nonterminal.Evidence and scope: Discovered during #622 immutable snapshot/maintenance planning under #92. Relevant source is
src/hooks/restore.tsaround the initial publication check and subsequent prune calls. Track outside Epic #92's frozen inventory and native hierarchy. Minimal integration may be required for #622's retention acceptance; no implementation PR exists yet.Environment:
a824d63d31876fc1fcca960f32a621b4392cf615