Skip to content

[6] Recover accepted work links after restart - #1351

Open
tautvydasLiekis wants to merge 17 commits into
feat/verify-pr-cost-accuracyfrom
feat/recover-work-continuations
Open

tautvydasLiekis wants to merge 17 commits into
feat/verify-pr-cost-accuracyfrom
feat/recover-work-continuations

Conversation

@tautvydasLiekis

@tautvydasLiekis tautvydasLiekis commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

When you continue a saved plan, its planning requests now join the implementation work even if the evidence was missing at that moment or Kimchi restarted. Before this, those planning costs could stay unassigned and drop out of the PR total.

Linked issue

Depends on #1350. No public issue is linked.

What does this PR do?

Kimchi saves each accepted continuation with a hash of the accepted plan bytes, the account, repository and accepting input, and the producing request when it is known. It retries the link at startup and during background reconciliation, and links only when:

  • the plan matches the accepted version, or a native artifact matches its saved edit;
  • the original producer, input, account and repository agree;
  • you have not already corrected or revoked that link (your choice wins).

Missing or competing evidence stays unresolved. Only the planning input is confirmed; other inputs stay separate.

flowchart TD
    A[Saved continuation] --> B{History readable and valid?}
    B -->|No| W[Wait for repaired evidence]
    B -->|Yes| C{Accepted version and one scoped producer?}
    C -->|No| W
    C -->|Yes| D{User correction already exists?}
    D -->|Yes| K[Keep the correction]
    D -->|No| L[Confirm the planning input]
Loading

It also hardens the journal that recovery reads:

  • A crash mid-write no longer blocks later records. The next append starts a new line, and readers skip the cut-off record, including journals written by released versions.
  • Other damage still blocks confirmation, and the warning names the journal and its first damaged line. The continued work is still adopted and remembered for work matching.
  • A record of an unknown type, for example from a newer Kimchi, blocks only the works and requests it names.
  • When a background pass has examined every remaining receipt without confirming one, later passes skip reading history until a journal changes. Once no receipt can still be confirmed, later passes read only the journals changed since.

The choice is saved under continuations in ~/.config/kimchi/harness/work/<workId>/work.json; a successful link appears under workLinks. Recovery makes no model or authentication calls and keeps request IDs and prices.

Evidence

On 92822475b, after the final review fixes:

  • CI: build, pr-checks, master-checks, TUI e2e in 4 shards, ACP e2e and MCP e2e pass on this head. A duplicate tui-e2e entry from a superseded workflow run shows as cancelled.
  • The stack top 95614e7c6 (#1389) contains this PR. On it, pnpm check passes and the full unit suite passes except 5 tests that need tools this machine lacks: a DAP js-debug adapter, a built validate-skill.mjs and a binary rebuilt for the smoke test.
  • New tests: an input naming an ADR owned from another worktree stays unresolved without reading every journal; a full pass over confirmed receipts reads each journal once and no retained plan; receipts that can never link drop out, so passes over more than 25 of them settle; a deleted plan keeps its owner.
  • Lab on a binary built from 95614e7c6 (scripted model; local GitHub, billing and report fixtures): 73/73 default scenarios pass.
  • On an earlier head, an idle background pass on a generated history with every plan already confirmed took about 90–140 ms for the first pass and 4 ms for later ones at 15,000 requests (38 MiB of journals); 340–380 ms, then 7–10 ms, at 60,000 requests (154 MiB).

Model replies are scripted.

Limits

  • Plan choices saved by older versions without a content hash stay unresolved.
  • While journals keep changing, each 30-second pass still reads every journal synchronously: about 90 ms at 15,000 requests and 340–380 ms at 60,000. Journals are never pruned, so heavy users will eventually need an incremental reader.
  • A retained plan file restored by hand is checked only after the next journal write.
  • No e2e test restarts Kimchi and waits for the background repair; unit and integration tests cover the repair and its scheduling.

Checklist

  • I have read CONTRIBUTING.md and agree to the CLA
  • This PR links to an open issue above
  • Tests pass locally (pnpm run test)
  • Lint passes (pnpm run check)
  • Documentation updated if behavior changed

🤖 Generated with Claude Code

@tautvydasLiekis tautvydasLiekis added the new feature Introduces a new feature label Oct 5, 2026
@kimchi-review

kimchi-review Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Kimchi Code Review

Property Value
Commit 73d174d
Author @tautvydasLiekis
Files changed 14
Review status Completed
Comments 0
Duration 21s

Summary

🚫 Merge request too large to review

📏 Size: 14 file(s) changed, +1029 / −60 lines

🧠 Cognitive load: 4/5 (1 = trivial, 5 = extremely demanding)

One feature but many interlocking invariants: content-hash identity of accepted bytes, producer pinning, and bounded background repair with lease, budget and rotation rules, all forbidden from overriding corrections. Large failure-mode/concurrency test additions dominate the diff and must be verified against those invariants.

✂️ Suggested split

  1. Hash accepted plan bytes into continuation evidence — Captures content hashes at match time so later edits cannot rewrite accepted evidence.
    • src/extensions/work-attribution/continuation.ts
    • src/extensions/work-attribution/continuation.test.ts
  2. Add budget-checked, validity-reporting ledger scans — Lets record readers bound scan time and surface malformed history rows.
    • src/extensions/work-attribution/summary.ts
    • src/extensions/work-attribution/summary.test.ts
  3. Pin producers and build the continuation repair engine — Core link construction, producer pinning, and bounded repair over saved receipts.
    • src/extensions/work-attribution/links.ts
    • src/extensions/work-attribution/links.test.ts
  4. Record continuation receipts when accepting saved work — Extension persists accepted evidence with scope and pins producers at input time.
    • src/extensions/work-attribution.ts
    • src/extensions/work-attribution.test.ts
    • src/extensions/work-attribution/continuation.integration.test.ts
  5. Run continuation repair in the reconciliation supervisor — Schedules repair after PR and billing passes under the shared lease and budget.
    • src/extensions/work-attribution/reconcile-supervisor.ts
    • src/extensions/work-attribution/reconcile-supervisor.test.ts
  6. Cover continuation recovery in e2e tests and docs — End-to-end receipt assertions and documentation of retention and repair behavior.
    • tests/e2e/acp/work-continuation.test.ts
    • tests/e2e/tui/work-attribution.test.ts
    • docs/work-attribution.md

👉 Please split this merge request into the smaller merge requests suggested above — the AI review will run automatically on each of them.

⚠️ Full review skipped — this merge request exceeds the reviewable size limit. See the split proposal above.

What to expect

Kimchi will analyze the changes in this pull request and post:

  • A summary of the overall changes
  • Inline comments on specific lines with findings categorized by issue type

The review typically completes within a few minutes. This comment will be updated once the review is ready.

Interact with Kimchi
  • @getkimchi review — re-trigger a full review on the latest commit
  • @getkimchi summary — regenerate the PR summary
  • @getkimchi ignore — skip this PR (no review will be posted)
  • Reply to any inline comment to ask follow-up questions or request clarification
Configuration

Reviews are configured by your organization admin.
Review instructions, excluded directories, and severity thresholds can be adjusted per repository in the Kimchi dashboard.


Powered by Kimchi — AI-powered code review by CAST AI

@kimchi-review kimchi-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 Merge request too large to review

📏 Size: 14 file(s) changed, +1029 / −60 lines

🧠 Cognitive load: 4/5 (1 = trivial, 5 = extremely demanding)

One feature but many interlocking invariants: content-hash identity of accepted bytes, producer pinning, and bounded background repair with lease, budget and rotation rules, all forbidden from overriding corrections. Large failure-mode/concurrency test additions dominate the diff and must be verified against those invariants.

✂️ Suggested split

  1. Hash accepted plan bytes into continuation evidence — Captures content hashes at match time so later edits cannot rewrite accepted evidence.
    • src/extensions/work-attribution/continuation.ts
    • src/extensions/work-attribution/continuation.test.ts
  2. Add budget-checked, validity-reporting ledger scans — Lets record readers bound scan time and surface malformed history rows.
    • src/extensions/work-attribution/summary.ts
    • src/extensions/work-attribution/summary.test.ts
  3. Pin producers and build the continuation repair engine — Core link construction, producer pinning, and bounded repair over saved receipts.
    • src/extensions/work-attribution/links.ts
    • src/extensions/work-attribution/links.test.ts
  4. Record continuation receipts when accepting saved work — Extension persists accepted evidence with scope and pins producers at input time.
    • src/extensions/work-attribution.ts
    • src/extensions/work-attribution.test.ts
    • src/extensions/work-attribution/continuation.integration.test.ts
  5. Run continuation repair in the reconciliation supervisor — Schedules repair after PR and billing passes under the shared lease and budget.
    • src/extensions/work-attribution/reconcile-supervisor.ts
    • src/extensions/work-attribution/reconcile-supervisor.test.ts
  6. Cover continuation recovery in e2e tests and docs — End-to-end receipt assertions and documentation of retention and repair behavior.
    • tests/e2e/acp/work-continuation.test.ts
    • tests/e2e/tui/work-attribution.test.ts
    • docs/work-attribution.md

👉 Please split this merge request into the smaller merge requests suggested above — the AI review will run automatically on each of them.

⚠️ Full review skipped — this merge request exceeds the reviewable size limit. See the split proposal above.

@tautvydasLiekis
tautvydasLiekis force-pushed the feat/verify-pr-cost-accuracy branch from 4349d37 to a76bbb2 Compare October 6, 2026 10:39
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/recover-work-continuations branch from 73d174d to 3aec50c Compare October 6, 2026 11:02
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/verify-pr-cost-accuracy branch from a76bbb2 to 711e09e Compare October 6, 2026 11:33
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/recover-work-continuations branch 2 times, most recently from d28b459 to c2a41b9 Compare October 6, 2026 12:01
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/verify-pr-cost-accuracy branch from 711e09e to 13cb56f Compare October 6, 2026 12:01
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/recover-work-continuations branch 2 times, most recently from 6969473 to dc4fe8b Compare October 6, 2026 16:48
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/verify-pr-cost-accuracy branch 2 times, most recently from cd8b287 to fbb4685 Compare October 6, 2026 17:20
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/recover-work-continuations branch from dc4fe8b to c07737f Compare October 6, 2026 17:20
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/verify-pr-cost-accuracy branch from fbb4685 to 8a8d570 Compare October 6, 2026 18:28
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/recover-work-continuations branch 2 times, most recently from 3b72231 to 5f61465 Compare October 6, 2026 20:47
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/verify-pr-cost-accuracy branch 2 times, most recently from 07e8f4d to eb6f010 Compare October 7, 2026 08:30
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/recover-work-continuations branch 2 times, most recently from ddd1ee6 to fc128db Compare October 7, 2026 15:40
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/verify-pr-cost-accuracy branch 2 times, most recently from 698a241 to e715a29 Compare October 7, 2026 17:51
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/recover-work-continuations branch from fc128db to 00cb976 Compare October 7, 2026 17:51
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/verify-pr-cost-accuracy branch from e715a29 to a3b50a2 Compare October 7, 2026 20:53
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/recover-work-continuations branch from 00cb976 to 06268ba Compare October 7, 2026 20:53
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/verify-pr-cost-accuracy branch from a3b50a2 to d9d7a5a Compare October 7, 2026 21:20
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/recover-work-continuations branch from 06268ba to 48f82a4 Compare October 7, 2026 21:20
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/verify-pr-cost-accuracy branch from d9d7a5a to 8663368 Compare October 8, 2026 04:24
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/verify-pr-cost-accuracy branch from ac03776 to 29a3e1a Compare October 9, 2026 11:37
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/recover-work-continuations branch from f6b6b74 to 3fb2129 Compare October 9, 2026 11:37
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/verify-pr-cost-accuracy branch from 29a3e1a to 9af7f14 Compare October 9, 2026 12:54
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/recover-work-continuations branch from 3fb2129 to 82387b5 Compare October 9, 2026 12:54
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/verify-pr-cost-accuracy branch from 9af7f14 to c296c34 Compare October 9, 2026 12:59
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/recover-work-continuations branch from 82387b5 to a92f821 Compare October 9, 2026 13:00
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/verify-pr-cost-accuracy branch from c296c34 to 2d3ff9b Compare October 9, 2026 14:38
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/recover-work-continuations branch from a92f821 to 90c3011 Compare October 9, 2026 14:38
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/verify-pr-cost-accuracy branch from 2d3ff9b to ec3fd92 Compare October 9, 2026 21:49
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/recover-work-continuations branch from 90c3011 to de9c8d4 Compare October 9, 2026 21:49
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/recover-work-continuations branch from de9c8d4 to 9282247 Compare October 10, 2026 09:09
@tautvydasLiekis
tautvydasLiekis force-pushed the feat/verify-pr-cost-accuracy branch from ec3fd92 to 69cee61 Compare October 10, 2026 09:09
…ntinuations

# Conflicts:
#	src/extensions/work-attribution.ts
#	src/extensions/work-attribution/continuation.owned-reference.test.ts
#	src/extensions/work-attribution/continuation.ts
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

new feature Introduces a new feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant