## Evidence and limitations

This edition is grounded in supplied implementation bodies\,&#32;public fictional fixtures\,&#32;completed isolated reports\,&#32;and a completed browser report\.&#32;No new commands or live checks were run to author this manuscript\.

The evidence supports specific behavior in a particular source snapshot\.&#32;It does not establish compatibility with every installed release\.

### Supplied implementation inspection

The main source responsibilities are\:

| Concern | Supplied paths and symbols |
| --- | --- |
| Persistent identity\,&#32;journal operations\,&#32;lazy files\,&#32;artifacts\,&#32;continuation | `packages/coding-agent/src/session/session-manager.ts`&#32;—&#32;`SessionManager.open`\,&#32;`fork`\,&#32;`forkFrom`\,&#32;`newSession`\,&#32;`moveTo`\,&#32;`continueRecent`\,&#32;`copySessionArtifacts` |
| Identifier resolution and listing | `packages/coding-agent/src/session/session-listing.ts`&#32;—&#32;`resolveResumableSession`\,&#32;`sessionMatchesResumeArg`\,&#32;`findMostRecentSession` |
| Breadcrumbs and terminal identity | `packages/coding-agent/src/session/session-paths.ts`\;&#32;`packages/tui/src/ttyid.ts`&#32;—&#32;`getTerminalId` |
| Startup routing | `packages/coding-agent/src/main.ts`&#32;—&#32;`createSessionManager`\,&#32;`runRootCommand`\,&#32;missing\-cwd and project\-switch helpers\;&#32;`packages/coding-agent/src/cli/args.ts`\;&#32;`packages/coding-agent/src/cli/flag-tables.ts` |
| Runtime reset and transition behavior | `packages/coding-agent/src/session/agent-session.ts`&#32;—&#32;`freshSession`\,&#32;`resetSessionContext`\,&#32;`newSession`\,&#32;`fork`\,&#32;`switchSession` |
| Context versus retained history | `packages/coding-agent/src/session/session-context.ts`&#32;—&#32;`buildSessionContext`\;&#32;`packages/coding-agent/src/session/session-entries.ts`&#32;—&#32;`ResetBoundaryEntry` |
| Human command routing and UI caveats | `packages/coding-agent/src/slash-commands/builtin-lifecycle.ts`\,&#32;`builtin-session.ts`\,&#32;`builtin-collaboration.ts`\;&#32;`packages/coding-agent/src/modes/controllers/command-controller.ts`\,&#32;`selector-controller.ts` |
| Dumps and exports | `packages/coding-agent/src/session/session-dump-format.ts`\;&#32;`packages/coding-agent/src/export/html/args.ts`\,&#32;`index.ts`\,&#32;`template.html`\,&#32;`template.js` |
| Sharing\,&#32;conditional redaction\,&#32;handlers\,&#32;cancellation | `packages/coding-agent/src/export/share.ts`\,&#32;`custom-share.ts`\;&#32;`packages/coding-agent/src/config/settings-schema.ts`\;&#32;`packages/coding-agent/src/secrets/obfuscator.ts`\;&#32;`packages/tui/src/components/cancellable-loader.ts` |
| Startup\/provider boundaries | `packages/coding-agent/src/sdk.ts`\;&#32;`packages/coding-agent/src/config/model-registry.ts`\,&#32;`model-provider-discovery.ts` |

Implementation bodies and recorded outcomes take precedence over stale descriptions\.&#32;In particular\,&#32;this workbook does not adopt the older implications that\:

- `/fork`&#32;opens a previous\-message picker\.
- GitHub gist is the default share route\.
- Embedded HTML data guarantees an offline viewer\.
- A dump necessarily contains all retained journal history\.
- Every explicit missing path is a guaranteed not\-found failure\.
- Every “session ID” is the persistent journal ID\.

### Completed recorded checks

The supplied coverage summary reports&#32;**38 passing checks**&#32;across three suites\:

| Suite | Recorded coverage | Important qualification |
| --- | --- | --- |
| Return Desk — 11 checks | Identity\/history\/cwd retention\,&#32;local\/global lookup\,&#32;unknown IDs\,&#32;no\-session manager precedence\,&#32;breadcrumb priority and fallback\,&#32;missing\-cwd decisions\,&#32;selector behavior\,&#32;public helper\,&#32;and source\-CLI resume\/continue\/fork | Most checks use manager\/component\/controller seams\.&#32;Native startup used RPC read\-only inspection and private disabled\-provider policy\,&#32;not a physical TUI\. |
| Decision Desk — 11 checks | Real SDK\/registry\/controller fork\,&#32;fresh\,&#32;clear\,&#32;new\,&#32;queue retention\/removal\,&#32;synthetic guards\,&#32;in\-memory fork refusal\,&#32;real extension veto\,&#32;injected switch rollback\,&#32;artifact success\/failure\,&#32;command inventory | Provider handles were inert\;&#32;busy predicates were synthetic\;&#32;artifact coverage was narrow\.&#32;Drop was not executed\. |
| Review Packet — 16 checks | Live versus file snapshots\,&#32;nested history\,&#32;path parsing\,&#32;source\-CLI export\,&#32;sidecars and failure\,&#32;in\-memory limits\,&#32;intercepted encrypted sharing\,&#32;conditional redaction\,&#32;trimming\,&#32;gist fallback\,&#32;server error\,&#32;custom handlers\,&#32;and late completion after Escape | No real upload or clipboard operation\.&#32;Share transport was intercepted\,&#32;and&#32;`gh`&#32;was a deliberately unauthenticated fake\. |

All three final launch reports recorded successful exit without timeout\.

The native continuity check ran the real source CLI with only state\/message inspection and stdin EOF shutdown\.&#32;Resume and continue returned the intended fictional identity\;&#32;fork returned another identity\;&#32;each retained two fictional messages and unchanged workspace bytes\.&#32;Its network\-attempt records were empty under the private restrictions\.

The supplied coverage summary also reports a passing public&#32;`bun check`&#32;and no remaining blockers in the preceding review\.&#32;That summary is not a new verification of this manuscript\,&#32;a website build\,&#32;or an installed distribution\.

Publication review also independently checked the complete manuscript with no remaining blockers and executed its added receipt\-capture\,&#32;JSON inspection\,&#32;checksum and embedded\-payload decoder commands on owned fictional copies\.&#32;The reset\-inspection queries were syntax\-checked against initial copied journals\;&#32;the actual reset behavior is established by the separate SDK checks above\,&#32;not by those queries\.

### Completed browser evidence

The separate headless Chromium report reviewed a generated fictional Harbor Notes packet\,&#32;including its decoded parent\,&#32;Scout\,&#32;Checklist\,&#32;and explicitly fictional current prompt\/tool metadata\.

It recorded\:

- **Blocked CDN scripts\:**&#32;visible controls\,&#32;no rendered transcript\.
- **Allowed CDN scripts\:**&#32;visible pre\-clear history\,&#32;keyboard navigation into Scout and Checklist\,&#32;and Escape returning to Scout\.

This establishes the tested viewer behavior\.&#32;It does not establish a self\-contained offline viewer\,&#32;a physical desktop\-open result\,&#32;or clipboard behavior\.

The generated proof exports remain private artifacts\;&#32;this workbook links only the supplied public fixtures and recipes\.

### What remains unverified

Material limitations remain explicit\:

- **Physical TUI behavior\:**&#32;full installed interactive startup\,&#32;terminal rendering\,&#32;picker exit presentation\,&#32;and platform\-specific input behavior were not physically tested\.
- **Real providers\:**&#32;no inference\,&#32;authentication recovery\,&#32;transport repair\,&#32;remote deletion\,&#32;or provider\-cache outcome was established\.
- **Concurrency\:**&#32;real streaming cancellation\,&#32;hidden\-turn scheduling\,&#32;async\-job races\,&#32;and compaction timing were not exercised by the synthetic guard checks\.
- **Universal rollback\:**&#32;the switch\-failure injection covered the guarded target\-load block\,&#32;not every preflight\,&#32;post\-commit\,&#32;external\,&#32;or filesystem effect\.
- **Filesystem breadth\:**&#32;one successful artifact file and one blocked destination do not establish symlink\,&#32;huge\-tree\,&#32;cross\-device\,&#32;permission\,&#32;or power\-loss guarantees\.
- **Missing export inputs\:**&#32;the reports checked valid input journals\,&#32;not every empty\/missing\-path behavior delegated through the loader\.
- **Clipboard and OS opening\:**&#32;controller open requests were intercepted\;&#32;TUI dump clipboard delivery and real desktop opening were not performed\.
- **Live sharing\:**&#32;no actual share server or GitHub publication\,&#32;viewer decryption service\,&#32;revocation\,&#32;expiry\,&#32;or retention policy was verified\.
- **Redaction completeness\:**&#32;configured synthetic cases do not prove that arbitrary real secrets\,&#32;personal information\,&#32;image content\,&#32;or extension metadata will be removed\.
- **Implementation identity\:**&#32;the supplied inventory fingerprints source files\,&#32;but no exact release\/commit mapping establishes what a reader’s installed OMP contains\.&#32;Session format version 3 is not itself a product\-release promise\.
- **Delegated code\:**&#32;some loader\/storage\/provider helpers and the generated tool\-view bundle were not included as implementation bodies\.&#32;Named repository tests were not supplied as executed test logs\.
- **Reader state\:**&#32;no workbook page\,&#32;checklist\,&#32;or fixture inspection establishes what is active in a reader’s actual OMP process\.

When installed behavior differs\,&#32;preserve that difference as an observation and stop the affected exercise\.&#32;Do not turn an expectation into a passed check\.

The durable habit is the same across all three stories\:&#32;**choose conversations by identity\,&#32;choose resets by state boundary\,&#32;and choose disclosure by inspected content—not by the appearance of the screen\.**
