Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion TOOLING.md
Original file line number Diff line number Diff line change
Expand Up @@ -222,7 +222,8 @@ Two status-parameter mutants test the rule that only bare `$?` can preserve
reusable candidates. The focused test rejects other unknown output data.
The new target took 49 seconds after package restore.

The local run on 2026-09-18 took about 22 minutes. CI allows 30 minutes for
The script groups targets by source project. Stryker analyzes each source project once.
The local run on 2026-09-24 took under four minutes. CI allows 30 minutes for
hosted-runner variance and report upload. The report directory is
`artifacts/stryker/shell-command-analysis`.

Expand Down
13 changes: 11 additions & 2 deletions docs/spec/SPEC-011-daemon-architecture.md
Original file line number Diff line number Diff line change
Expand Up @@ -234,6 +234,15 @@ The pipeline reports cancellation through its canceled task state. The daemon
keeps the existing approval prompt. Button and text responses can resume the
recovered turn. A channel UI can temporarily lag the session state after restart.

During any graceful stop, the actor gives an active model call a two-second
completion grace. It then cancels an eligible call and waits for its task.
The actor returns a standard `current_session` reminder for durable pending
input. The reminder expires ten minutes after the interruption. Startup
registers each fresh reminder through the reminder manager. The session
restores the pending input under its recorded authority when the reminder
arrives. A completed turn, partial text, or possible tool effect produces no
restart reminder.

`netclaw daemon status` checks the PID file and verifies the process is alive.
Reports: running/stopped, PID, uptime, port, number of active sessions.

Expand Down Expand Up @@ -360,8 +369,8 @@ not execute tools.
4. **Valid config**: close daemon-managed ingress, enumerate live session actors,
ask them to drain, persist a restart manifest, and request coordinated
daemon restart
5. **After restart**: warm the sessions that were active when restart began and
inject a continuity notice for the next turn
5. **After restart**: register fresh restart reminders. The normal reminder
route activates each target session.
6. **Invalid config**: log warning with validation errors, preserve previous config

### What Changes Take Effect After Restart
Expand Down
13 changes: 9 additions & 4 deletions feeds/skills/.system/files/netclaw-operations/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ name: netclaw-operations
description: "REQUIRED when the user asks about scheduling, reminders, cron jobs, timers, background jobs, diagnostics, troubleshooting, MCP tools, daemon health, identity updates, or Netclaw capabilities and self-maintenance."
metadata:
author: netclaw
version: "2.75.1"
version: "2.75.2"
---

# Netclaw Operations
Expand Down Expand Up @@ -461,11 +461,16 @@ stale button, ask them to re-issue the request.

During a graceful stop, the session can stop a tool task that waits only for
journaled approval prompts. The session waits for that task to stop before it
acknowledges drain. The daemon keeps the existing approval prompt. The original requester can
still approve through its button or a text response after restart. The UI
acknowledges drain. The daemon keeps the existing approval prompt. The original
requester can approve it after restart. They can use its button or a text response. The UI
can temporarily lag the session state. Shutdown cancellation does not mean
the approval expired.
An active tool or accepted buffered input keeps the current bounded drain path.
An active tool with a possible external effect keeps the bounded drain path.

An interrupted model call can create a short-lived restart reminder. The
session restores accepted input and its original authority from the journal.
The reminder expires ten minutes after the interruption. A completed turn,
partial reply, or possible tool effect does not create this reminder.

**Why you may not see a prompt at all.** If the user invokes a read-only verb
(say `grep`) with a path argument under a tree the operator has previously
Expand Down
13 changes: 7 additions & 6 deletions openspec/changes/resume-interrupted-sessions/design.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,15 +38,15 @@ The actor creates a standard one shot `ReminderDefinition` only when these condi
- no tool batch started;
- no partial text reached a subscriber;
- the stored turn context is valid;
- the existing reminder path supports the session channel.
- the stored turn has a channel type for current-session delivery.

The reminder expires ten minutes after the interruption. The restart manifest stores the definition with the active session list.
The reminder expires ten minutes after the interruption. The restart manifest stores only restart reminder definitions.

### D3. The reminder manager owns wakeup and delivery

Startup registers each fresh definition through `SaveReminderCommand`. The reminder uses `DeliveryKind.CurrentSession` and the existing gateway path.

The daemon adds no route binder, channel state, retry loop, or resume candidate protocol. The reminder manager owns persistence, delivery retries, and deduplication.
The daemon adds no route binder, channel state, retry loop, or resume candidate protocol. The reminder manager owns route resolution, persistence, delivery retries, and deduplication.

### D4. The reminder is a trigger

Expand All @@ -67,8 +67,8 @@ journal -> session: stored
session -> source: CommandAck
stop -> session: PrepareForDaemonRestart
session -> model: cancel and await stop
session -> stop: ReminderDefinition or no reminder
stop -> manifest: active sessions and reminders
session -> stop: DaemonRestartPrepared with a reminder or no reminder
stop -> manifest: restart reminders
start -> reminder manager: SaveReminderCommand
reminder manager -> existing gateway: current_session reminder
gateway -> session: SendUserMessage
Expand All @@ -82,4 +82,5 @@ session -> model: resume prior work
- A tool can have an uncertain effect. `ToolBatchStarted` closes its input before execution and blocks this path.
- A partial reply can repeat text. The actor records transient text emission and does not create a reminder.
- A reminder can register twice after a process failure. Its stored ID makes `CreateOnly` registration idempotent.
- A channel can lack `current_session` support. The actor creates no reminder for that session.
- A stored turn can lack a channel type. The actor then creates no reminder.
- The reminder system owns gateway resolution for a stored channel type.
Original file line number Diff line number Diff line change
Expand Up @@ -78,9 +78,9 @@ The reminder manager SHALL deliver a fresh restart reminder through its existing
- **THEN** it does not register or deliver that reminder
- **AND** it logs one warning

#### Scenario: A channel lacks current session delivery
#### Scenario: Stored authority has no channel type

- **GIVEN** an interrupted session uses a channel that the reminder manager cannot address
- **GIVEN** an interrupted session has no stored channel type
- **WHEN** graceful drain classifies the session
- **THEN** the actor creates no restart reminder
- **AND** no channel adapter is added by this change
- **AND** the actor does not contain a channel-specific route list
18 changes: 9 additions & 9 deletions openspec/changes/resume-interrupted-sessions/tasks.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,18 +7,18 @@

## 2. Graceful drain

- [ ] 2.1 Retain and cancel the active model task after a short grace.
- [ ] 2.2 Return one standard reminder definition for eligible pending input.
- [ ] 2.3 Exclude approvals, tool work, partial replies, and unsupported channels.
- [x] 2.1 Retain and cancel the active model task after a short grace.
- [x] 2.2 Return one standard reminder definition for eligible pending input.
- [x] 2.3 Exclude approvals, tool work, partial replies, and input without a channel type.

## 3. Existing reminder path

- [ ] 3.1 Store reminder definitions in the restart manifest.
- [ ] 3.2 Register fresh reminders through the reminder manager after startup.
- [ ] 3.3 Restore pending input under its original context when the reminder arrives.
- [ ] 3.4 Verify expiration, duplicate registration, and a cold session wakeup.
- [x] 3.1 Store reminder definitions in the restart manifest.
- [x] 3.2 Register fresh reminders through the reminder manager after startup.
- [x] 3.3 Restore pending input under its original context when the reminder arrives.
- [x] 3.4 Verify expiration, duplicate registration, and a cold session wakeup.

## 4. Verification

- [ ] 4.1 Update SPEC-011 and the operations skill.
- [ ] 4.2 Run actor and daemon tests, evals, Slopwatch, headers, and OpenSpec validation.
- [x] 4.1 Update SPEC-011 and the operations skill.
- [x] 4.2 Run actor and daemon tests, evals, Slopwatch, headers, and OpenSpec validation.
Loading
Loading