Evidence and limitations
This edition is grounded in supplied implementation bodies, public fictional fixtures, completed isolated reports, and a completed browser report. No new commands or live checks were run to author this manuscript.
The evidence supports specific behavior in a particular source snapshot. It does not establish compatibility with every installed release.
Supplied implementation inspection
The main source responsibilities are:
| Concern | Supplied paths and symbols |
|---|---|
| Persistent identity, journal operations, lazy files, artifacts, continuation | packages/coding-agent/src/session/session-manager.ts — SessionManager.open, fork, forkFrom, newSession, moveTo, continueRecent, copySessionArtifacts |
| Identifier resolution and listing | packages/coding-agent/src/session/session-listing.ts — resolveResumableSession, sessionMatchesResumeArg, findMostRecentSession |
| Breadcrumbs and terminal identity | packages/coding-agent/src/session/session-paths.ts; packages/tui/src/ttyid.ts — getTerminalId |
| Startup routing | packages/coding-agent/src/main.ts — createSessionManager, runRootCommand, missing-cwd and project-switch helpers; packages/coding-agent/src/cli/args.ts; packages/coding-agent/src/cli/flag-tables.ts |
| Runtime reset and transition behavior | packages/coding-agent/src/session/agent-session.ts — freshSession, resetSessionContext, newSession, fork, switchSession |
| Context versus retained history | packages/coding-agent/src/session/session-context.ts — buildSessionContext; packages/coding-agent/src/session/session-entries.ts — ResetBoundaryEntry |
| Human command routing and UI caveats | packages/coding-agent/src/slash-commands/builtin-lifecycle.ts, builtin-session.ts, builtin-collaboration.ts; packages/coding-agent/src/modes/controllers/command-controller.ts, selector-controller.ts |
| Dumps and exports | packages/coding-agent/src/session/session-dump-format.ts; packages/coding-agent/src/export/html/args.ts, index.ts, template.html, template.js |
| Sharing, conditional redaction, handlers, cancellation | packages/coding-agent/src/export/share.ts, custom-share.ts; packages/coding-agent/src/config/settings-schema.ts; packages/coding-agent/src/secrets/obfuscator.ts; packages/tui/src/components/cancellable-loader.ts |
| Startup/provider boundaries | packages/coding-agent/src/sdk.ts; packages/coding-agent/src/config/model-registry.ts, model-provider-discovery.ts |
Implementation bodies and recorded outcomes take precedence over stale descriptions. In particular, this workbook does not adopt the older implications that:
/forkopens a previous-message picker.- GitHub gist is the default share route.
- Embedded HTML data guarantees an offline viewer.
- A dump necessarily contains all retained journal history.
- Every explicit missing path is a guaranteed not-found failure.
- Every “session ID” is the persistent journal ID.
Completed recorded checks
The supplied coverage summary reports 38 passing checks across three suites:
| Suite | Recorded coverage | Important qualification |
|---|---|---|
| Return Desk — 11 checks | Identity/history/cwd retention, local/global lookup, unknown IDs, no-session manager precedence, breadcrumb priority and fallback, missing-cwd decisions, selector behavior, public helper, and source-CLI resume/continue/fork | Most checks use manager/component/controller seams. Native startup used RPC read-only inspection and private disabled-provider policy, not a physical TUI. |
| Decision Desk — 11 checks | Real SDK/registry/controller fork, fresh, clear, new, queue retention/removal, synthetic guards, in-memory fork refusal, real extension veto, injected switch rollback, artifact success/failure, command inventory | Provider handles were inert; busy predicates were synthetic; artifact coverage was narrow. Drop was not executed. |
| Review Packet — 16 checks | Live versus file snapshots, nested history, path parsing, source-CLI export, sidecars and failure, in-memory limits, intercepted encrypted sharing, conditional redaction, trimming, gist fallback, server error, custom handlers, and late completion after Escape | No real upload or clipboard operation. Share transport was intercepted, and gh was a deliberately unauthenticated fake. |
All three final launch reports recorded successful exit without timeout.
The native continuity check ran the real source CLI with only state/message inspection and stdin EOF shutdown. Resume and continue returned the intended fictional identity; fork returned another identity; each retained two fictional messages and unchanged workspace bytes. Its network-attempt records were empty under the private restrictions.
The supplied coverage summary also reports a passing public bun check and no remaining blockers in the preceding review. That summary is not a new verification of this manuscript, a website build, or an installed distribution.
Publication review also independently checked the complete manuscript with no remaining blockers and executed its added receipt-capture, JSON inspection, checksum and embedded-payload decoder commands on owned fictional copies. The reset-inspection queries were syntax-checked against initial copied journals; the actual reset behavior is established by the separate SDK checks above, not by those queries.
Completed browser evidence
The separate headless Chromium report reviewed a generated fictional Harbor Notes packet, including its decoded parent, Scout, Checklist, and explicitly fictional current prompt/tool metadata.
It recorded:
- Blocked CDN scripts: visible controls, no rendered transcript.
- Allowed CDN scripts: visible pre-clear history, keyboard navigation into Scout and Checklist, and Escape returning to Scout.
This establishes the tested viewer behavior. It does not establish a self-contained offline viewer, a physical desktop-open result, or clipboard behavior.
The generated proof exports remain private artifacts; this workbook links only the supplied public fixtures and recipes.
What remains unverified
Material limitations remain explicit:
- Physical TUI behavior: full installed interactive startup, terminal rendering, picker exit presentation, and platform-specific input behavior were not physically tested.
- Real providers: no inference, authentication recovery, transport repair, remote deletion, or provider-cache outcome was established.
- Concurrency: real streaming cancellation, hidden-turn scheduling, async-job races, and compaction timing were not exercised by the synthetic guard checks.
- Universal rollback: the switch-failure injection covered the guarded target-load block, not every preflight, post-commit, external, or filesystem effect.
- Filesystem breadth: one successful artifact file and one blocked destination do not establish symlink, huge-tree, cross-device, permission, or power-loss guarantees.
- Missing export inputs: the reports checked valid input journals, not every empty/missing-path behavior delegated through the loader.
- Clipboard and OS opening: controller open requests were intercepted; TUI dump clipboard delivery and real desktop opening were not performed.
- Live sharing: no actual share server or GitHub publication, viewer decryption service, revocation, expiry, or retention policy was verified.
- Redaction completeness: configured synthetic cases do not prove that arbitrary real secrets, personal information, image content, or extension metadata will be removed.
- Implementation identity: the supplied inventory fingerprints source files, but no exact release/commit mapping establishes what a reader’s installed OMP contains. Session format version 3 is not itself a product-release promise.
- Delegated code: some loader/storage/provider helpers and the generated tool-view bundle were not included as implementation bodies. Named repository tests were not supplied as executed test logs.
- Reader state: no workbook page, checklist, or fixture inspection establishes what is active in a reader’s actual OMP process.
When installed behavior differs, preserve that difference as an observation and stop the affected exercise. Do not turn an expectation into a passed check.
The durable habit is the same across all three stories: choose conversations by identity, choose resets by state boundary, and choose disclosure by inspected content—not by the appearance of the screen.
Sessions, resets, and reviewable history · Source chapter: continuity/evidence-and-limitations. Original evidence remains scoped to its recorded snapshot.