Files
stack/docs/plans/reviews/2026-09-08_publication-trial-recovery-summary.md

3.2 KiB

Planned-restart trial — privacy-safe recovery summary

Task PUB-REC-ROCKO-1, trial #1497. Author of worker evidence: Rocko. Coordinator: Darkwing. Status: worker action complete; independent recovery review and Jason's overall trial acceptance pending.

Evidence chain

  1. Before restart, Rocko declared an unexecuted next action: node --test scripts/test-rocko-launch.mjs, inspected as an isolated fixture with fake Claude and temporary state, no real model call. Coordinator independently read the test without running the reserved action.
  2. Coordinator verified checkpoint and inventory hashes, unchanged test/launcher bytes, baseline HEAD and absent recovery artifact before telling Jason the planned restart was ready.
  3. Jason reported done, then continue issued. Coordinator supplied no reconstructed task prompt after restart and did not read private sessions/panes.
  4. Rocko reports retained task context, re-reading declared shared records, no private-state reads after restart and one reserved test invocation. Launcher resume stdout was unavailable inside his process; exact resume mode is inferred from retained context, not independently observed from that output. Harness compaction occurred and was not treated as the sole task record.
  5. Worker output reports one test, one pass, zero failures, exit 0, empty stderr. No tracked files changed; two additional untracked task records appeared, including the worker recovery file and an unrelated coordinator review disposition. This is not a literally unchanged worktree claim.
  6. The coordinator verified test and launcher hashes still match the pre-restart inventory. The announced recovery hash matches exactly the byte prefix before its appended transport receipt; the full post-send record has a different, recorded identity.

Exact identities

  • Baseline HEAD: 3b7fd19d08.
  • Checkpoint SHA-256: 30c4e1906b22220a29868c1ef4253676d2e2324d46a1f281543e50347af7fdd8.
  • Inventory SHA-256: 51536b1d4a8fee30caa711527295ed7b860d46ae9b81e5530af6631a53030b5f.
  • Recovery announced pre-send SHA-256: 52778f1a681277335f5d86a1e1fe2b96e9df07303b81c1d833ed674cf44811f7.
  • Recovery full post-send SHA-256: df77133d49d66be72f12f6d742d1f220529a82098efac79117c13d256048abca.
  • Test SHA-256: 13c32cad02587aad85da2f1a2bca8e61d77d9285ffc9e21dc91b7bafa7d0e05d.
  • Launcher SHA-256: b65566e19fa0fb83409552954a645b8cdc4d2bdb1002df55d27088add6acf65d.

Raw worker records remain local pending privacy handling; they contain runtime identifiers and are not publication candidates. This derivative deliberately omits those identifiers and hosted conversation links. Hashes identify evidence without publishing private session state.

Limits

A planned operator restart with neutral continuation and checkpoint recovery is supported by the owner report and worker execution evidence. No crash-recovery guarantee, authenticated process-incarnation proof, production orchestration, repeated reliability rate or unobserved exactly-once guarantee is claimed. One execution is the worker's recorded run count, not a separate runtime-enforced invariant. Independent review must evaluate the evidence and these limits before publication. C1 remains held. Candidate review, publication and overall user acceptance are separate gates.