Decision Desk resetting deliberately
Eli now has a conversational fork. Before changing it, write down the intended boundary:
- Keep the conversation, refresh local provider-facing state: fresh.
- Drop the live/model conversation but keep this journal identity: clear.
- Start another conversation identity: new.
These operations are not escalating levels of secure deletion.
A before-and-after reset ledger
The table describes successful native operations. “Identity” means persistent journal identity.
| State | /fresh | /clear | /new |
|---|---|---|---|
| Live conversation | Retained | Cleared | Cleared |
| Existing journal history | Unchanged by the operation | Retained; reset boundary appended | Retained in the previous journal |
| Persistent ID and path | Retained | Retained | New ID and allocated path |
| Title | Retained | Retained | Ordinary new session starts without the prior title |
| Model and settings | Retained | Retained | Not a factory reset; current model/settings remain applicable |
| Provider-facing state | Local handles closed; fresh transient ID | Local handles closed; fresh transient ID | Local handles closed; normal identity selection resynchronized |
| Ordinary queues | Retained | Cleared | Cleared |
| Cwd and workspace | Unchanged | Unchanged | Current project remains |
| Prior artifacts and exports | Retained | Retained | Prior artifacts retained, not copied as a fork |
| Active plan reference | Retained | Path retained and reference re-armed | Ordinary new-session reference resets to its default |
Normally the provider-facing ID after /new follows the new journal ID. An explicit provider-session override is a separate input; do not turn that normal case into a universal identity rule.
Milestone: Refresh the provider boundary without losing the conversation
Need. Eli wants to discard local provider transport/session state while retaining the conversation.
Obstacle. “Fresh session” sounds like an empty conversation, but this command is deliberately narrower.
In the idle fictional fork:
Human OMP slash command:
/fresh
Expected observation. The visible conversation remains. The status reports how many local provider states were pruned. Zero can be normal.
The implementation closes cached provider-state entries, clears the local map, mints a fresh provider-facing ID, rekeys associated session-memory identity, and invalidates append-only context for rebuilding.
It does not append a reset boundary, change the journal header ID, or clear ordinary steering/follow-up queues. The next model-context build uses the retained conversation—not every old entry that might remain elsewhere in the journal.
Recorded check. One inert provider handle received close(). The provider-facing ID changed; persistent journal ID, file, bytes, messages, and ordinary queues remained unchanged.
That is local state-transition evidence. It does not prove that a real provider outage, authentication failure, remote conversation problem, or retention concern was fixed.
Failure and recovery. If a response is still streaming, wait or abort through OMP’s normal control, then retry. A pruning count is not a remote deletion receipt. Even local close errors can be logged while the handle map is cleared.
Self-check. Does a changed AgentSession.sessionId after /fresh prove that a new durable conversation was created?
Answer: No. That getter is provider-facing. Compare the persistent header ID and file.
Milestone: Clear live context while keeping the journal
Need. Eli wants the next conversation to stop depending on the current turns, but wants to continue this persistent session.
Obstacle. A blank live transcript could be mistaken for erased history.
In the idle fictional fork:
Human OMP slash command:
/clear
Expected observation. The live transcript clears and OMP reports a context reset while the session continues.
The source-backed reset drops:
- Live messages.
- Steering, follow-up, and pending next-turn messages.
- Pending tool calls and error state.
- Deferred session-scoped tool decisions and internal per-turn state.
- This agent’s scheduled continuation work and owned asynchronous jobs.
It also rotates provider-facing state and refreshes applicable base/project context. Clearing conversation messages does not disable project instructions or erase a separate memory backend.
The persistent ID, path, title, cwd, model, settings, and active plan path remain. A reset_boundary is appended to the journal.
Subsequent model-context and collapsed-live rebuilds honor that boundary. Full-history paths still retain earlier entries. This distinction survives reopening; it is not merely a temporary screen clear.
Recorded check. The real reset retained identity, path, title, model, and cwd; cleared messages, ordinary queues, and a synthetic pending tool marker; and appended one reset boundary. Reopening rebuilt an empty context after the boundary while full-history reconstruction retained the earlier fictional messages.
The test also appended one fictional post-clear message and observed only that message in rebuilt model context. It did not send a next provider request.
Failure and recovery. /clear refuses while streaming or while foreground bash/Python work is running. Its controller first aborts active compaction and waits for it to stop. The warning text does not enumerate every predicate.
If reset throws after beginning, do not assume nothing changed. Inspect the journal boundary and active state before retrying; this reset is not presented as an all-stage transaction.
Self-check. Can a later full HTML export still include the conversation from before /clear?
Answer: Yes. Clear is a context boundary, not an export scrubber.
Milestone: Start a different identity without deleting the old one
Need. Eli wants another conversation rather than continuing the fork’s identity.
Obstacle. An empty new journal may not yet exist as a physical file.
Human OMP slash command:
/new
Expected observation. OMP starts an empty conversation under a new persistent identity and allocated path.
Ordinary /new:
- Preserves the prior journal and workspace.
- Does not create a fork parent link.
- Clears messages and queues.
- Aborts current work after the veto point rather than using the same streaming refusal as
/fresh. - Refreshes base/project prompt context.
- Does not reset the whole installation’s settings.
A new session can contain initial metadata without having a materialized transcript file. Therefore, an absent third JSONL file is not evidence that the identity failed to change.
Recorded check. The real new-session transition allocated another identity and path, emptied messages and ordinary queues, and retained the previous journal and workspace. Its immediate identity was measured directly in the SDK ledger, not inferred from file count.
Failure and recovery. A before-switch hook can veto /new. Transient UI may already have been cleared by the controller, so a changed status area is not proof of a new identity. Other failures need inspection; there is no universal rollback promise for this path.
Self-check. Does ordinary /new delete the fork you just left?
Answer: No.
Inspect the saved outcome
Exit without sending a model prompt.
Human OMP slash command:
/exit
Then inspect only the lab’s files.
Terminal shell — read-only comparison, in the same shell holding the receipt variables:
jq -s 'map(select(.type == "session") | {id,parentSession,cwd,title})' "$SESSIONS"/*.jsonl
shasum -a 256 "$SOURCE"
jq -s 'map(select(.type == "reset_boundary") | {type,id,parentId})' "$SESSIONS"/*.jsonl
jq -s 'map(select(.type == "message") | .message.content)' "$SESSIONS"/*.jsonl
cat "$PROJECT/today.txt"
Look for retained parent history, a child header linked to the original identity, a reset boundary in the cleared child, and retained fictional messages.
These queries aggregate saved journals. They do not measure a now-closed process’s live context. Correlate the child header with its recorded parent and the child file path you noted. Inspect that individual file when you need per-file evidence.
The original hash is useful evidence, but do not demand universal byte equality across native startup and shutdown. Lifecycle records can be added outside the narrower fork call. The recorded parent-byte assertion was scoped to that call.
Milestone: Fork from the original at startup
Need. Eli wants another identity from a saved conversation without first opening it interactively.
Obstacle. Startup has a launch cwd and no parent process’s ordinary message queues to clone.
Print the supplied startup fork command:
Terminal shell — print the generated native startup fork command:
jq -r '.commands.forkExplicitPath' "$RECEIPT"
Run the entire printed command. Stop on setup; do not prompt. If startup succeeds, inspect session information and directories, then exit normally.
This recipe supplies the copied project as launch cwd. It therefore does not visually demonstrate two different project directories. The separate parser/manager check did use a different launch cwd and confirmed the rule.
Expected observation. A new child identity retains source history and records the original persistent ID as parent. The source remains available. Session artifacts are copied best-effort by default; workspace files are not copied.
Recorded checks. The parser/manager test confirmed launch-cwd behavior and rejection of --fork with --no-session. The separate source-CLI startup fork returned a new identity, two retained fictional messages, and unchanged workspace bytes.
Source-ID fork lookup is implemented but was not the exercised startup-fork target form; the recorded startup examples used explicit paths.
Failure and recovery. Unknown source IDs fail. --fork with --no-session is invalid. After a write or artifact error, inspect the child journal and artifact availability before calling the result a complete copy.
Self-check. Does startup fork inherit queued follow-up messages from an old OMP process?
Answer: No. It rebuilds from saved history, not another process’s queues.
Source anchors: packages/coding-agent/src/session/agent-session.ts — freshSession, resetSessionContext, newSession, sessionId; packages/agent/src/agent.ts — reset; packages/coding-agent/src/modes/controllers/command-controller.ts — handleFreshCommand, handleResetContextCommand, handleClearCommand, #runNewSessionFlow; packages/coding-agent/src/session/session-context.ts — buildSessionContext.
Sessions, resets, and reviewable history · Source chapter: continuity/decision-desk-resetting-deliberately. Original evidence remains scoped to its recorded snapshot.