OMP Workbook

Read the source. Follow the evidence.

10. Protect context and recover

A tangent is not a privacy boundary

A tan can inherit conversation content that has nothing to do with its narrow assignment:

  • Prior user and assistant messages.
  • Tool results and file contents.
  • Previously attached images.
  • Instructions or memory-derived content already present in the inherited context.

It can also access the shared workspace through its available tools.

Before launching, consider whether the inherited content is appropriate for the model/provider and tool access involved. A narrow task prompt does not remove unrelated inherited information.

Do not assume that Main’s extension-based safeguards or interactive approval prompts are reproduced identically. Verify protections that matter before unattended work.

This public workbook never needs your real transcripts, credentials, or private instructions.

Cost: concurrent does not mean free

A tan can add model requests, tool work, retries, and auxiliary model activity while Main is also active.

The initial controller copies Main’s effective prompt-cache routing key while giving the child a separate provider request lineage. That creates eligibility for provider cache reuse, not a cache-hit or savings guarantee.

The supplied mock-provider proof reported zero usage by design. Those zeros are not pricing evidence.

Also be careful with transcript-derived totals: a fork includes historical messages and their usage records. Such totals are not necessarily the tan’s incremental new spend.

Shared scratch space and artifact boundaries

During its initial run, the tan uses a captured mapping to Main’s local:// scratch root. A file such as local://lantern-label-audit.md can therefore be shared with Main.

The Tan transcript is nested in the parent session’s artifact tree, and the launch does not recursively copy that tree.

But sharing local:// does not mean every artifact allocator is identical. The initial controller does not adopt Main’s ArtifactManager; tools can create child-session artifacts. The cold reviver, in contrast, adopts the current Main artifact manager.

Use paths and links actually returned by the tools. Do not construct guessed artifact IDs or assume that all resources keep the same mapping after Main moves or a tan is cold-revived.

Compaction preserves intent only within its actual wiring

During the initial background run, the Tan controller reasserts the fork boundary after successful reported compaction.

That is a useful guard, not a guarantee that every later revived conversation carries the same live reminder machinery. After compaction or revival, a concise restatement of scope and ownership is a sensible operating practice.

Recovery guide

SymptomCheckRecovery
“I cannot find it in /jobs.”Did the job expire? Is it owned by another agent? Is this a revived, jobless prompt?Check the live and parked roster and history://; do not guess a new job ID.
“Hub list says no actionable peers.”Are there parked peers? Is the list truncated?Request the parked filter and inspect counts; use the runtime Hub for further inspection.
“The row says running, but nothing seems active.”Is startup still wiring up? Does live session activity corroborate the status?Inspect current state and history before treating it as a stale registration.
“My correction did not affect the answer.”Was the right Tan focused? Was it queued, processed, or submitted after auto-return?Locate the message in the correct transcript before resending.
“I got returned to Main unexpectedly.”Did the focused tan park, become aborted, or disappear?Recheck both state tracks and the draft recipient.
“The command was refused in tan chat.”Did the draft begin with slash, shell, or Python command syntax?Preserve it if needed, return to Main, and perform only the intended Main action there.
“An image was missing.”Was it staged beside /tan, or sent later as an actual focused attachment? Was image input allowed?Attach explicitly to the verified tan, or provide an authorized accessible file.
“The report disappeared from later job snapshots.”Was it already auto-delivered or recovered?Read the earlier result, actual artifact link, or transcript.
“Revival failed.”Transcript, saved contract, workspace, runtime factory, model/auth, and tool dependenciesRepair the actual dependency; otherwise use retained history to prepare a new tangent.
“I cancelled it, but a parked row appeared later.”Was this job cancellation or plain release rather than explicit tombstoned kill?Reconcile the transcript and lifecycle. Use explicit kill if terminal intent is still required.
“Stopping it did not stop a server.”Was the server a separately supervised or external process?Discover and control that process separately; verify ownership first.
“A test failed during concurrent edits.”Did another worker change the tested files or dependencies?Establish a stable input point and one writer, then rerun the relevant check.

Restart and retention are not the same as live control

Source supports discovering retained child transcripts under a session’s artifact tree and rebuilding eligible parked agents. It does not mean a running Tan keeps executing through an OMP process exit.

Discovery also has boundaries:

  • It is tied to reachable session roots, not an unlimited search of every file on the computer.
  • Saved-agent scans and metadata hydration can fail or be incomplete.
  • A long inherited transcript can place Tan-specific initialization beyond the small prefix used for roster metadata.
  • A row’s preview may therefore be missing or insufficient to identify its assignment.
  • File existence alone does not prove a live, controllable agent.

The supplied runtime proof exercised cold revival without proving restart rediscovery.

Transcripts remained on disk at the proof’s observation points. That is not permanent retention. Session deletion, artifact cleanup, archive/GC policy, storage errors, and loss of image/blob dependencies can change later availability. The supplied evidence does not establish a guaranteed retention period.

Completed journal entries and in-flight streaming text also have different durability. Do not assume an abrupt exit preserves every partial token.

Optional detail: do not borrow ordinary-task recovery settings blindly

The initial Tan controller does not run through the ordinary task executor’s full driver.

In particular, do not present these as established controls for the initial Tan:

  • task.maxRuntimeMs as its automatic wall-clock stop.
  • task.softRequestBudget as its run budget.
  • task.agentIdleTtlMs as a way to prevent its immediate completion parking.
  • task.isolation.* as automatic /tan isolation.
  • Agent-definition model overrides as a live Tan model selector.

Those settings have uses elsewhere. Their existence does not establish the same behavior in TanCommandController.start().


Tangent work and live control · Source chapter: tan/10-protect-context-and-recover. Original evidence remains scoped to its recorded snapshot.

Read this chapter as Markdown

Your lesson ticks

A self-reported reading checklist, not proof of real OMP behavior. Only these ticks are saved in this browser. Reading a milestone does not resume, fork, reset or export a session.

Chapters I have worked through
Start here 1
Sessions, resets, and reviewable history 19
Memory and reusable knowledge 14
Tangent work and live control 17
Tool permissions and approvals 15
Extensions inside those boundaries 23
Connections and next steps 8
0 of 97 checked

Checklist saving needs JavaScript and available browser storage.