Skip to content

fix(proxy): recover tool-complete sessions from unavailable owners - #30

Merged
maisi merged 7 commits into
mainfrom
fix/27-continuity-owner-recovery
Sep 9, 2026
Merged

maisi merged 7 commits into
mainfrom
fix/27-continuity-owner-recovery

Conversation

@maisi

@maisi maisi commented Sep 9, 2026 •

Copy link
Copy Markdown
Owner

Summary

Fixes #27.

A rate/usage-limited owner currently strands a session when its full resend includes a complete tool-call/result batch followed by a new user instruction. The durable manifest proves the batch is complete, but the replay helper rejects the trailing user input and returns previous_response_owner_unavailable.

This permits that proven full replay on an eligible replacement, retains the complete calls/results/new input, and removes the old upstream anchor through the existing recovery path. Subsequent anchored requests remain on the replacement. Unsafe requests keep their continuity error code and now explain how to resend complete account-neutral history or start a new session.

Upstream integration PRs #29 and #31 are merged. This focused fix targets current main and is verified with beta6.

Safety and scope

  • Preserve exact durable-prefix and tool-manifest proof, call order/types, complete results, collision checks and bounded developer interleave.
  • Validate trailing input with the canonical ownership and allowed-fields classifier; unknown fields and owner metadata remain rejected.
  • Preserve account scope, file pins, pre-dispatch gates and durable ownership fencing. Opaque compaction remains account-bound.
  • Explicit anchors may be removed only with the existing full-context proof. Missing results, file pins and unknown fields do not dispatch to a replacement or open a retry-circuit cooldown.

No settings, migrations, dashboard changes or new defaults. Reuses the existing recovery path rather than introducing a second session mechanism.

OpenSpec: openspec/changes/archive/2026-09-09-recover-unavailable-continuity-owner/.
Related upstream work: Soju06#1707 and Soju06#2121. Public regression scenarios are adapted from Soju06#2121 and extended for rate limits, explicit anchors and repeated unsafe requests; the stricter trailing-input validation addresses its review concern.

Validation

  • Before the fix, the new rate-limited-owner reproduction failed on both /v1/responses and /backend-api/codex/responses with 502.
  • Focused proof and recovery cases pass; 16 rate/quota/endpoint/explicit-anchor cases pass.
  • 377 ownership and continuity tests, all 32 repeated-rejection/recovery scenarios, and 552 replay/HTTP/WebSocket tests pass.
  • All 1,660 replay-safety, HTTP bridge and direct WebSocket tests pass after integration with beta6.
  • Ruff, type checking and strict change-spec validation pass.

OpenSpec is verified, synchronized and archived. Final GitHub checks must pass before merge.

Preserve canonical replay ownership checks and make unreplayable continuity errors actionable.

Regression scenarios adapted from Soju06#2121 and extended for temporary rate limits, explicit anchors, unknown fields and repeated rejection.
@maisi
maisi changed the base branch from chore/sync-upstream-beta5-fix-27 to chore/sync-upstream-beta6 September 9, 2026 21:15
@maisi
maisi marked this pull request as ready for review September 9, 2026 21:19
@maisi
maisi changed the base branch from chore/sync-upstream-beta6 to main September 9, 2026 21:27
@maisi
maisi merged commit e5911e2 into main Sep 9, 2026
34 of 36 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug(proxy): rate-limited continuity owner strands existing Codex session despite another available account

1 participant