V2 assistant attempts have no V0 semantic dispatch case: validate their exact V2 members and positive step coordinates locally while preserving the embedded stream. Explicitly classify agent-message relay attribution and file attachment metadata; both preserve foreign identities and non-Session byte counts, and reject unknown members.
Native V3 request headers retain current extension fields while rejecting retired header.system, independently of the closed V2 migration inventory. Add direct and multihop attempt regressions, exact source/file negative cases, and native header roundtrip coverage. All 41 focused tests and host tsc pass; scoped lint and bilingual pairing pass.
The structural V2-to-V3 edge reuses the frozen V0 payload and relationship helpers through their public package exports. Record the explicit workspace dependency so clean installs resolve the same validation code without editing a released migration package.
Stream an empty protected head after the first step and replace it before changed or cleared request headers, without moving source events. Remap only audited local sequence references, derive inherited cuts after upstream cardinality changes, and preserve generation-qualified captures and message identities.
Refuse pre-step surfaces and out-of-step prompt changes rather than invent lifecycle events. Reject unclassified migration payloads and detect deterministic generated-ID collisions in either source order. Native V3 accepts empty and in-history system messages, protects only the head, and reuses frozen relationships through a private nonescaping projection; historical repair IDs remain opaque.
Keep released codecs untouched and distinguish migration admission from native extension admission. V3 structural payload preflight cannot disappear behind recoverable row corruption. Validation: 35 focused tests, host TypeScript build, focused Oxlint, documentation quick gates and paired README recording. Parent owns installed-core/catalog/persistence integration and lockfile propagation.
Record order-preserving structural conversion and strict refusal instead of an identity edge; distinguish native writer layout and local references from historical delivery facts. Keep released generations frozen and one evolving unreleased V3 target, with canonical envelopes composing afterward.
Restore all 147 historical canonical fixtures changed by the lower branch to exact shared base 220ff708e3628a9be46d9747d09af6d8cd742f0d bytes (145 V2 and two V0). All 180 committed V0/V1/V2 canonical files now have zero diff against that base, including unchanged Python, test-support and preview sources.
Preserve corrected lower writer bodies in 146 V3 successors across 119 owner directories: replace 135 unreleased V3 counterparts and add 11 siblings. Change only each copied Session header version; preserve all body bytes, raw model streams, inline images, IDs, references and historical delivery generation markers. Remove two unshipped V2 additions after creating their V3 sibling: record-suite/rec-pin and empty-response-retry-current.
Keep six explicitly historical snapshot owners pinned with no V3 sibling. Restore the two pre-step V0 record child sources without synthesizing current output. Fix seven embedded Session header versions in exactly five test-support behavior owners whose output filenames already select V3. Leave protocol expectations, shared references, sidecars, consumer scripts and production migration/normalization code untouched.
Validation: purpose-built temporary Python inventory and verifier checked 337 canonical headers, 3714 successor JSON rows, message roles, contiguous child roles, exact successor bodies, all 180 historical base bytes and zero git diff, noncanonical JSONL immutability, six retained owners and six unchanged preview fixtures. git diff --cached --check passed. Temporary generators removed. Strict migration, native refresh and replay remain pending parent integration; unsupported pre-step sources are reported separately.
Use a typed expected failure object and the current toThrow matcher in the new leading-system-image regression. This preserves the rejection test while avoiding deprecated matcher and unsafe-any diagnostics from the full type-aware lint gate.
Address ds-review-bot thread 3921300994 (PRRT_kwDOS3Pfcs6eyLsu). contextBreakdown now folds system/message instead of request/header.system, so version-2 checkpoints have different semantics even though their numeric fields still pass the current schema. Bump the lower projection to stateVersion 3 so cache-only reads omit old values and restore replays the full log; derived caches are not covered by the Session-log persistence compatibility waiver. No migration or fallback is added.
Regression seeds a schema-valid v2 row at the current watermark with stale system/message prices. Before the bump, cache views returned it, restoreFloor selected seq 2 rather than 0, and restore retained system=0/message=17 instead of system=8/message=9. After the bump, the 13-test owning suite passes and exact src/breakdown-projection.ts coverage is 100% statements, branches, functions, and lines; refreshed rows equal a fresh fold at version 3. Existing token-meter README prose documents the current system/message fold without a version literal, so it needs no edit.
Propagation requirement: the upper layer already uses version 3 for a different compact cache representation. Advance that layer to version 4 when propagating this fix to avoid assigning one version to two schemas.
Address ds-review-bot thread 3921300999 (PRRT_kwDOS3Pfcs6eyLsz). The synchronous conversion removed a leading system message before its image check, silently discarding image-only, mixed, and nested image content. Reuse assertSupportedImageRoles on the unsplit history, matching the image-aware path without changing text prompt precedence or user-image storage requirements.
Regression: all three leading-system image cases failed against 8082f4a950 (expected rejection, received a context). The focused context suite now passes 20 tests, including both conversion paths, no attachment reads on rejection, empty/text leading prompts, later systems, and explicit options.system precedence. Exact src/context.ts coverage is 100% statements, branches, functions, and lines. Updated the paired README limitation and synchronous JSDoc.
These two current fixtures already contain system/message, so searching
only for stale request/header.system misses their persisted replay drift.
Both omit the shipped standard agentPreset. Plan exit must replace the
first system message (sequence 10), not append a second system prompt.
The Goal fixture's first get_goal result must reference its own tool call
at sequence 18 rather than the preceding bash call at sequence 16.
Refresh both owning browser scenarios. Retain the writer's canonical
embedded Assistant stream packing and refreshed timing where repacking
requires it. Expanded stream chunks, all 44 user/model/tool messages and
calls, and the deliberate shuf command failure remain unchanged. The
plan title remains before request/header on this lower branch. No UI,
runtime, normalizer, test-driver, or frozen v0/v1 files change.
Evidence at lower d29574fed9, reusing the dedicated tree's own prior build
(the intervening subagent spacing edits do not affect these owners):
- DSH_SNAPSHOT=replay pnpm exec vitest run --config vitest.web.config.ts apps/web/tests/{plan-review,goal-multi-turn-actions}.e2e.ts: before refresh, both owners failed persisted-session comparisons.
- DSH_SNAPSHOT=refresh pnpm exec vitest run --config vitest.web.config.ts apps/web/tests/{plan-review,goal-multi-turn-actions}.e2e.ts: 2 files passed, 4 tests passed, 1 record-only test skipped (10.24s).
- DSH_SNAPSHOT=replay pnpm exec vitest run --config vitest.web.config.ts apps/web/tests/{plan-review,goal-multi-turn-actions}.e2e.ts: 2 files passed, 4 tests passed, 1 record-only test skipped (10.24s).
- JSON payload comparison: all 44 messages/calls and expanded chunk content
across all 14 Assistant streams preserved; stream timing is excluded.
- git diff --check passed; only the two current session.v2.jsonl files changed.
Require exactly two System prompt controls for the unchanged-header resume fixture, and pin the repeated prompt in both collapsed and expanded subagent history. Keep all branch eligibility, disabled action, cancellation, disclosure, and inventory assertions intact.
Refresh stale July 25 clocks only where canonical fixture createdAt=0 already selects the seedSession near-now anchor. Preserve nonzero historical timestamps and the existing normalizer: do not conceal calendar differences globally. Update navigation read paths to the recorded workspace subdirectory and omit decode throughput for the zero-duration Bash cancellation stream.
Evidence: own frozen install and full build; baseline eight-file replay 10 failed, 37 passed, 3 record skips plus stale question teardown; six-file ARIA refresh 36 passed, 2 record skips; final read-only eight-file replay 47 passed, 3 record skips after separately authored Web fixture prerequisite eaa5277d82. Baseline exact count rejected 2 versus 1 and old date/prompt goldens rejected actual output. No Session generation, helper, runtime, or normalization edits in this commit. Live/question source mismatch is repaired solely by the prerequisite; their passing ARIA and skill goldens stay unchanged.
Fourteen current Web v2 fixtures still store the system prompt in
request/header.system and omit system/message. The built Cordis owner
passes its five behavior assertions but fails persisted-session replay.
Refresh thirteen owning recorded scenarios and update the authored pwsh
seed input to carry the same system text as a message event.
Keep the lower branch's title-before-header order. Preserve all 90
user/model/tool messages and all 35 recorded Assistant streams, including
timing. Only the system event, header field removal, message identifiers,
and their sequence references differ. Frozen v0/v1, UI goldens, runtime,
and normalizers remain unchanged.
Evidence on macOS, base 8d66f7c917:
- pnpm install --frozen-lockfile && pnpm run build: passed.
- DSH_SNAPSHOT=replay pnpm exec vitest run --config vitest.web.config.ts apps/web/tests/cordis-tool-round.e2e.ts: before repair, persisted replay failed after 5 behavior tests passed.
- DSH_SNAPSHOT=refresh pnpm exec vitest run --config vitest.web.config.ts apps/web/tests/{approval-composer,cordis-tool-round,feedback-command,file-upload-round,replay-round-trip,lifecycle-chrome,live-interactions,permission-policy-context,ptc-round,question-composer,steering,turn-tail-actions,web-search-round}.e2e.ts: 13 files passed; 71 tests passed, 2 record-only tests skipped.
- PATH="/tmp/pwsh:$PATH" DSH_SNAPSHOT=refresh pnpm exec vitest run --config vitest.web.config.ts apps/web/tests/pwsh-terminal.e2e.ts: 2 tests passed with existing PowerShell 7.4.6.
- PATH="/tmp/pwsh:$PATH" DSH_SNAPSHOT=replay pnpm exec vitest run --config vitest.web.config.ts apps/web/tests/{approval-composer,cordis-tool-round,feedback-command,file-upload-round,replay-round-trip,lifecycle-chrome,live-interactions,permission-policy-context,ptc-round,pwsh-terminal,question-composer,steering,turn-tail-actions,web-search-round}.e2e.ts: 14 files passed; 73 tests passed, 2 record-only tests skipped (102.62s).
- Exact base/current JSON comparison: all 14 files equal base plus the system event, header.system removal and deterministic ID/sequence remapping.
- No current Web v2 request/header.system remains; git diff --check passed.
Give JSON.parse results in the unexpected-header regression their actual record type before searching by event tag. Preserve the forbidden-field oracle while satisfying the full type-aware lint rules; do not weaken lint or production parsing.
Validation: exact-head Linux artifact CI reported unsafe-return and unsafe-member-access in this regression. The owning replay suite passes after the local typed result correction.
Replace the replay's fixed temporary-root find command with the existing fromRequest capture of the preceding session_event_read result. Quote the exact returned file and use portable grep -Fq/printf checks; emit SPILL_CANONICAL_OK only after request/header and session_event_search are present. Preserve the owning layer's seq11 request/header target.
Before cleanup or fixture refresh, require both successful tool results and the exact verification marker, read the returned spill file independently, and compare its complete JSON to the live request/header event. This prevents accepting a failed verification transcript or an unrelated/incomplete spill after event ordering changes. No runtime or error-text normalization changes.
Evidence: nonexistent recorded-root negative control fails at the marker assertion (bash exit 2 still carries isError:false). Focused keyless refresh, read-only source replay, built-profile replay, corpus ownership guard, and focused driver lint pass. Host/client library builds pass. Portable POSIX command reviewed; Linux CI remains the platform confirmation.
A resume header starts a visible request series even when the system node text is unchanged. Include resume in the request-prompt visibility predicate so full history and an older-page prepend retain the restart card. Keep startsSeries handling and existing regression assertions unchanged; align the local JSDoc and README pair.
Carry the newly merged current-writer spill recording through the representation change on its owning PR. Add the system surface message and remove header.system, while retaining the representation layer title-before-request order and every captured spill/source fact. The dependent admission PR separately records its changed title scheduling.
Validation: JSON records parse; the same recorded scenario was refreshed through the built integrated loop. Only layer-specific title order differs, and both variants are replayed before publication.
The source fixture now contains the system surface node, so a literal sequence13 no longer names its captured tail. Record the source watermark before saveText mutates the session and assert that exact independent observation. This continues proving the spill uses the pre-mutation capture without coupling the test to unrelated fixture event counts.
Validation: the newly merged upstream regression failed with expected13 versus actual14; the session-reference suite passes with the captured watermark assertion.
The historical-comparison negative control replaces title.messageSeqs with [0], which cites a non-human event. The current Session validator correctly rejects this before normalization; comparing the malformed result for inequality made the otherwise passing built snapshot lane fail.
Assert the specific earlier-human-message validation error for that malformed control. Keep the valid prompt and model difference comparisons, every citation field, and all production restoration and normalization logic unchanged.
Validation: full DSH_EXAMPLE_MODE=lib DSH_SNAPSHOT=replay pnpm exec vitest run --config vitest.snapshot.config.ts reproduced the lone negative-control failure, then passed all 6 files and 126 tests after repair (2 existing PowerShell availability skips). PATH used the existing uv Python 3.14.5 bin; no software installed.
The committed current rec-pin fixture held only request/header, so the corpus restore gate rejected it outside an open turn. Its owning scripted behavior already emits turn/start, step/start and the system surface message.
Regenerate the selected current fixture with ACP_SNAPSHOT_SPEC_BOOTSTRAP=1 and the focused rec-pin record test. Keep all retired parent and child generations unchanged. No parser, normalizer or production behavior changes.
Validation: the corpus restore test reproduced the missing-turn failure; documented owner bootstrap passed; pnpm exec vitest run packages/test-support/llm-replay/tests/session-format-corpus.spec.ts packages/test-support/session-snapshot/tests/suite.spec.ts passed (141 tests, one intentional skip).
The current Session relationship validator correctly rejects a second step/start while the previous step remains open. Both replay and refresh of the synthetic pin-turn scenario failed after the stricter master validation landed.
Add the missing step/end to the owning scripted behavior and resequence its later events. Regenerate only the current pin-turn fixture through defineAcpSnapshotSuite refresh mode. Preserve both system messages, replacement provenance, and all three request headers; do not relax migration validation or normalization.
Validation: reproduced both pin-turn failures with the focused suite filter; owning refresh passed; pnpm exec vitest run packages/test-support/session-snapshot/tests/suite.spec.ts passed (140 tests, one intentional record skip). Full build and doc-sync also passed before this fixture-only repair.
Retain installLlmReplay, Config validation and apply when resolving the streaming migration API change. The representation layer requires no replay plugin source changes, so restore its complete current-master implementation rather than a truncated conflict fragment. Capability additions remain exclusively in the dependent feature layer.
Validation: the restored source is byte-identical to origin/master and the replay unit suite passes. The initial normal commit hook failed because this detached worktree had no dependency links; pnpm install --frozen-lockfile installs them before retrying the unchanged hook, without bypass.
The default and retry header pins were retained pre-system-node logs, so preserving their historical header.system correctly exposed stale expectations across headless and shared SDK compositions. Move the default pin to tool-call-turn and add a current retry companion; retain every committed predecessor and keep readable sidecar ownership on text-turn.
Replace the historical blanket body-comparison skip with a headless-only semantic projection: current system nodes contribute historical header.system and event citations follow retained positions. Full normalized logs still compare, current-writer logs stay unadapted, and independent prompt/header checks remain strict. Negative controls preserve prompt, model and citation differences. Refresh only pi-ai metadata and Web minimal-preset current artifacts; no SDK outputs, Python fixtures or package oracles changed.
Validation: 18 focused headless/SDK/corpus tests; three pin, sidecar and historical mutation controls; Web minimal-preset persisted replay; focused oxlint; typecheck and client/Web builds. doc-sync:31 passed,2 failed on pre-existing token-meter/Cordis and config catalog freshness; no broad catalog rewrite. Full suite, browser interaction and platform matrix not rerun.
Regenerate source-owned catalogs after the oracle simplification and usage-anchor correction. The configuration catalog retains the same declared options while its source location follows removed compatibility stripping; the token-meter service docs now state that the usage anchor includes all admitted request inputs. Keep bilingual generated declarations aligned instead of retaining stale copied contracts.
Validation: pnpm run doc-sync identified only cordis catalog and config catalog freshness failures (31 other gates passed); pnpm run gen-cordis-catalog and pnpm run gen-config-catalog regenerated their owners, and the config pair was updated and recorded. Full layer documentation validation follows integration.
Cause: SystemPromptProjection skipped the first empty rendered prompt. The initial admitted user then occupied surface node zero, so a later nonempty prompt appended behind user history. Routes without in-history system support lost the leading system role; pi-ai demotes a non-leading system message to user content.
Fix: append the initial system node even when its content is empty. The existing loop commit order reserves node zero before admitted user messages; later prompt text replaces that node. Empty content still derives to no wire message. Keep retained-node replacement, clearing, multi-system handling, and pi-ai conversion unchanged; this addresses only the reviewed PR3476 initial-empty finding, not PR3483.
Tests: added initial-empty projection and two-turn loop regressions for empty wire output, reserved surface head, later leading system role, replacement intent, and series header. Negative control failed before the source fix. Focused projection/runtime-context/loop/request-reconstruction/session-surface/pi-ai-context suites passed 176 tests; exact runtime-context.ts coverage is 100% statements, branches, functions, and lines. test:docs passed all 15 gates. Updated README EN/ZH, architecture map and owning architecture note; recorded all three translation pairs. Broad doc-sync/lint stopped at parent request for combined-layer validation. No normalize.ts conflict-comment edit.
The representation PR left child and restart recordings in the old header-system representation while the packaged writer emits system/message before entered user messages. Restart result expectations also retained standalone assistant/chunk notifications after the writer moved stream records into assistant/message. These are stale expected artifacts, not fields to erase in normalization.
Regenerate the owning advanced and restart scenarios through the native macOS ARM64 packaged dsh runtime. Retain messages, tool effects, typed feedback and packed streams; update only the missing system nodes and their sequence references, and remove obsolete standalone chunk notifications. The advanced parent result and parent session already match the writer after the rebase, so this commit changes only two child logs and the restart result/logs.
Validation: pnpm run build; pnpm exec tsx scripts/build-exe-for-python-sdk.ts --skip-build --targets=node24-macos-arm64; uv run --project python/sdk python scripts/smoke-python-runtime.py --scenario sdk-snapshot --exe dist-exe/deepseek-harness-sdk-runtime-macos-arm64 and the equivalent sdk-restart command each reproduced the mismatch, then passed with --update-snapshots and again without it. Both read-only reruns pass. Other native targets remain covered by exact-head CI.
The rec-child fake-agent behavior used an 11-digit UUID tail for both copies of its shared system message. Supply the missing digit in both places without changing their identity relationship. This semantic correction is separate from the preceding five-file formatting-only change.
Add a focused owner-fixture assertion requiring two matching complete v4 UUIDs. It fails on the original short tail and passes after repair. Evidence: pnpm exec vitest run packages/test-support/session-snapshot/tests/suite.spec.ts: 140 passing, one intentional record-mode skip, including replay/record/refresh and UUID validation. No expected-output refresh or normalization change is needed.
Compact each logged event onto one line in exactly five owner-local fake-agent behavior fixtures: record-suite rec-child/rec-pin and suite pin-turn/plain-turn/shared-pin. Keep wrapper structure readable so event sequencing and payload changes remain reviewable without hundreds of formatting-only lines.
Evidence: node deepStrictEqual compares parsed working-tree JSON against HEAD for all five changed files, with exactly five paths asserted; all semantic values and ordering are identical. git diff --check passes. The malformed rec-child UUID is deliberately retained here for a separate semantic repair commit. The unchanged fixture behavior passed the preceding suite.spec.ts run (139 passing, one intentional skip). No snapshot refresh was run.
Delete the leftover diff3 parent marker and both copies of the obsolete request-header prompt JSDoc. Keep only the current system/message tokenization contract. This is a local comment-only finding; neither oracle behavior nor fixture content changes.
Evidence: git diff --check is clean; focused normalize.spec.ts scrubSystemPrompts test passes (1 selected, 64 skipped). The earlier header-preservation commit intentionally retained this marker so the findings stay independent.
sessionFixtures already selects the highest generation independently for each parent or child role. Filtering its output to files[0] silently exempted every child from prompt and schema fixed points and prompt-before-request ordering. Merge those assertions into the per-role loop and expose the actual checker for focused negative controls without mocking Vitest registration.
The three selected-child controls reject missing system/message, raw prompt text, and raw tool schemas; each resolved incorrectly with the parent-only filter. A positive mixed-generation case proves retained predecessors remain unselected. Correct the two versionless record-suite child fixtures that the restored enforcement exposes, including the retired-child copy used by recording tests. No released historical generation or broad recording is rewritten.
Evidence: pnpm exec vitest run packages/test-support/session-snapshot/tests/storage-policy.spec.ts packages/test-support/session-snapshot/tests/suite.spec.ts --coverage --coverage.include=packages/test-support/session-snapshot/src/suite.ts: 143 pass, one intentional record-mode skip, suite.ts 100% statements/branches/functions/lines. Update and re-record the session-snapshot README EN/ZH pair.
The loop appends step/start before system/message and the entered user
messages. Capturing nodes at step/start therefore omits inputs already
included in the provider's successful usage, then adds those inputs back
as a positive surface delta. Prompt replacement can also incorrectly add
or subtract the difference from the prior prompt on a completed call.
Snapshot the current priced surface immediately before assistant/message
commits. Keep provider output separate from the durable assistant node so
listener rewrites retain their signed delta. The invariant is zero delta
immediately after an unchanged successful output: provider usage already
includes every admitted prompt input. Later appends/replacements still
produce signed deltas, and low or absent usage keeps heuristic fallback.
Delete stepStart.nodes rather than adding prompt-specific corrections or
another request snapshot: the existing transactional surface fold already
contains the successful request inputs, including replacements made during
same-step retry recovery. Keep turn/step state and all overlap, mismatch,
and late-assistant lifecycle validation. Retry attempts are log-only and
request middleware changes configuration; injected messages remain queued
until admission. No loop, event format, projection, or retry policy changes.
Exercise the real loop with reported usage and initial, growing, shrinking,
and empty prompts; same-step failed attempt plus retry prompt replacement;
request middleware; eager observation and fresh seeded replay. The two
regressions fail before the fix with spurious deltas of +48 and +18 tokens.
Retain existing durable-output rewrite, route repricing, missing/low usage,
transactional failure, and lifecycle tests. Update README EN/ZH and the
existing system-prompt surface-node Agent Note, including pairing records.
Validation (dedicated worktree, no full unit suite):
- pnpm exec vitest run packages/llm/token-meter/tests packages/compaction/compaction-basic/tests/compaction-loop-repro.spec.ts --coverage --coverage.include='packages/llm/token-meter/src/index.ts'
118 passed; exact changed runtime file 100% statements/branches/functions/lines.
- pnpm exec vitest run packages/core/agent-loop/tests/request-reconstruction.spec.ts packages/compaction/compaction-basic/tests/compaction-basic.spec.ts packages/compaction/compaction-basic/tests/loader-composition.spec.ts
118 passed, including retry reconstruction and real Loader composition.
- pnpm run doc-sync: 33 gates passed.
- pnpm run test:docs: 15 gates passed.
- pnpm run lint: passed, 0 warnings/errors.
- git diff --cached --check: passed.
Baseline normalize.ts comment conflict marker is intentionally untouched.
The session already derives the protected system head as a Message, and both adapters accept leading system history. Passing it through a separate SummarizationInput.system string unnecessarily flattens that value and rebuilds the same wire message in the adapter. Prepend the derived head to messages and remove textContent, the separate field, and GenerateOptions.system plumbing from the summarizer.
Keep range selection, shadowed seq accounting, session head protection, routed tools, image references, target policy, and the model-visible compaction instruction unchanged. Empty-content heads still derive to null and contribute no request message, but their surface node remains protected. Update subclass consumers/tests, EN/ZH package and subsystem prose, and the existing system-prompt surface owning note with refreshed pairing records.
Evidence: pnpm exec vitest run packages/compaction/compaction-basic/tests packages/llm/llm-deepseek/tests/serialize.spec.ts packages/llm/llm-pi-ai/tests/context.spec.ts --coverage --coverage.include='packages/compaction/compaction-basic/src/region.ts' --coverage.include='packages/compaction/compaction-basic/src/summarizer.ts' passed 203 tests in 6 files; both changed sources have 100% statements, branches, functions, and lines. Region-to-default-summarizer cases pin exact prefix and tools for nonempty Unicode/multiline, empty, and absent heads. DeepSeek JSON byte equality and pi-ai context equality pin leading-message vs separate-system equivalence on text and image-capable conversion paths.
pnpm run doc-sync passed all 33 gates including doc-typecheck, documentation build, translation pairing and model-experience checks. git diff --check passed. Own dependencies installed with pnpm install --frozen-lockfile. An initial test iteration used a nonexistent ctx.dispose teardown on the in-memory fixture; corrected to its existing fixture lifecycle and reran successfully. No runtime/model behavior, normalizer marker, main worktree, push, or rebase changes.
Remove both unconditional header.system erasures from log normalization and replay comparison encoding, including the unrelated Session-header deletion. The catalog owns released-format migration; comparison must not turn an unexpected field into equality or supply a compatibility shim.
Add direct log/snapshot and catalog-restoration controls that retain unexpected request/header.system and differ from the field-absent fixture. Preserve malformed provenance data as well, closing the owned normalizer coverage gap. Update the two package README pairs with this oracle obligation.
Evidence: pnpm exec vitest run packages/test-support/session-snapshot/tests/normalize.spec.ts packages/test-support/llm-replay/tests/llm-replay.spec.ts --coverage --coverage.include=packages/test-support/session-snapshot/src/normalize.ts --coverage.include=packages/test-support/llm-replay/src/index.ts: 205 tests pass, both files 100% statements/branches/functions/lines. Direct normalizer negative control fails before the fix. Baseline diff3 comment remains untouched for the separate cleanup finding.
Consolidate the representation-change PR and its rebase reconciliations into one baseline. Preserve the exact tree and keep the in-history feature in the dependent PR. Follow-up fixes remain separate.
The failover runbook's Windows switch scope returns to the native Windows jobs:
remove the Python runtime eligibility sentences, the pool Python prerequisite,
and the proposal links. The #3629 self-hosted Python runtime proposal is
retired (deleted as obsolete after its unmeasured-throughput run), and a new
implemented note records that the Windows x64 runtime lane stays on
GitHub-hosted Windows with the evidence and alternatives. Bilingual sidecars
re-recorded.
The failover runbook's Windows switch scope returns to the native Windows jobs:
remove the Python runtime eligibility sentences, the pool Python prerequisite,
and the links to the proposal. The self-hosted Python runtime proposal is
moved to rejected with its unmeasured-throughput verdict, and a new
implemented note records that the Windows x64 runtime lane stays on
GitHub-hosted Windows with the reasons. Bilingual sidecars re-recorded.
Windows x64 runtime builds resolve their hosted matrix.runner unconditionally
again (windows-2025 for pull-request CI). Remove the DSH_CI_FAILOVER_WINDOWS
selector, job-private Python toolchain, self-hosted dependency install and
post-step cleanup, the private setup script, and the routing spec introduced
in #3629. The Windows failover switch again covers only the native Windows
jobs in ci.yml.