返回 DeepSeek-Reasonix
history-startup-loading.md
根目录 / docs / history-startup-loading.md
1 # History discovery, reading preparation, and execution recovery
2
3 Ordinary startup does not migrate transcript formats. Existing JSONL, DAG, and directory sessions keep their native storage; newly created sessions use the current directory format. Catalogs and history locators are disposable projections, not authoritative transcripts.
4
5 ## Readiness has three meanings
6
7 - **Catalog available:** the database is open and existing metadata can be queried. Discovery may still be incomplete.
8 - **History readable:** a validated display window is available for the selected session. Preparation runs independently of its execution controller and can be canceled.
9 - **Execution ready:** the complete execution context and write authority have been restored. Reading history does not authorize sending. Draft editing and navigation remain available during recovery.
10
11 Execution failures, including an external writer's lease, do not settle history preparation as a read error. Passive metadata refreshes join an existing cold read for the same navigation and source; they do not replace it with a controller-dependent Follow request. Rebuild notifications also respect the unavailable runtime. An actual cold-read failure produces local retry state; a later ready runtime can replace that cut through the existing live handoff.
12
13 Discovery reads file identity, attributes, and bounded metadata sidecars. Unknown fields remain unknown; an unknown turn count is not zero. A failed or interrupted scan cannot declare the unvisited remainder missing. A parseable prefix of damaged authoritative content is not published as a complete history.
14
15 ## Maintenance boundaries implemented
16
17 Ordinary startup no longer repairs display indexes across the history library. The catalog instance is published before discovery, watchers register before scanning, and the active session restores from its saved identity. Pending creates and durable operations remain owned by their existing recovery lifecycle.
18
19 Filesystem watching now begins while saved identities are still restoring. Startup admission does not wait for project/topic metadata synchronization or restored-path indexing. Restored paths enter the existing exact-path queue. Initial, periodic, and user-triggered metadata refreshes share one cancellable worker with one coalesced pending request; the watcher continues receiving events while that worker waits for the database. Shutdown joins the worker.
20
21 Reservation recovery now publishes a registry-only refresh after restored-shell admission. The watcher alone schedules initial legacy discovery; the recovery notification no longer races it to queue another full scan. Genuine source changes during discovery still retain their follow-up scan. Advisory registry projection uses the shared background scheduler and releases the database writer after each bounded slice. It compares the current project/topic rows, including older writers' changes, and publishes only changed metadata. Retirement uses keyset pages over registry-owned rows and begins only after all input additions finish; cancellation or a failed slice cannot retire unvisited input. Source-derived topic cleanup remains with source removal/reconciliation. Each writer slice retains a 30-second cancellation deadline; the whole registry observation can continue across slices instead of restarting at that deadline. Other catalog modes keep their atomic refresh contract. The optional partial index's first creation is still a background full-table operation, and loading/parsing registry JSON is not yet incremental.
22
23 Discovery preserves directory iterators within the process and rotates roots. Each background slice admits at most 128 entries, 4 MiB, or 50 ms, with a minimum 100 ms yield and a shared 8 MiB/s input budget. Foreground preparation and background scanning each have concurrency 1. The visible project's metadata has priority; other roots pause during foreground preparation. Controlled reads check cancellation in blocks of at most 64 KiB. These are scheduling parameters, not hard real-time or measured end-to-end guarantees.
24
25 Queued metadata discovery retains at most eight iterators. Background roots occupy at most seven slots, leaving one for the visible workspace. Waiting roots enter when a retained scan finishes; admitted scans keep their exact iterator and progress. Repeated workspace switches do not bypass the cap or evict unfinished scans. If all slots are occupied, a newly visible root waits for a slot; small exact-path updates remain independent of admission. This bound covers queued discovery, not explicit synchronous management scans.
26
27 Invalidations received while a root is waiting for dispatch merge into its first scan, including the latest scope and durable journal sequence. Changes after dispatch still require a follow-up before the shared completion signal settles. Tests hold a scan at a controlled checkpoint to distinguish these cases.
28
29 Renderer locale synchronization refreshes presentation only. It runs on every mount and must not schedule source discovery, even if the initial scan has already started. Its regression checks both repeated startup synchronization and an actual language change.
30
31 Catalog monitoring uses the existing platform directory watcher: FSEvents on macOS, ReadDirectoryChangesW on Windows, and the existing notification adapter elsewhere. macOS registration no longer enumerates every child or allocates one descriptor per historical file. Canonical watch paths route exact events back to registered access paths. Failed watch registration retries separately from discovery: the five-minute rotating audit covers an unavailable watch, while successful recovery schedules reconciliation of its unobserved interval. A 30-second metadata refresh no longer invalidates every unwatched root.
32
33 Exact save events update the affected path. Dirty-root coordination records survive restart. Ordinary failures back off for 1, 5, and 30 seconds; inaccessible roots keep a failure state without hiding their history in bulk.
34
35 Filesystem notification consumers use nonblocking exact-path admission. When that queue is full, the watcher retains one dirty entry per root and journals it in its existing batch; rejected journal admission stays pending. It no longer performs a synchronous root-journal write for every overflowing file event. Authoritative save observers retain their existing durable overflow path. Pre-discovery notices merge into initial discovery; changes after dispatch still require reconciliation and are not discarded as noise.
36
37 A root invalidation supersedes an active metadata iterator at its next slice boundary. The incomplete generation cannot confirm missing records or clear the pending journal. Notifications coalesce for 100 ms, with a one-second ceiling for each admission delay, before the replacement starts. Ordinary budget yields retain the iterator. An unchanged metadata row is rechecked inside the commit transaction and updates only its scan-presence generation; it does not rewrite topic aggregates or emit a redundant list revision. Discovery progress is reported independently.
38
39 An optional legacy root that has never contained cataloged history may be absent on a fresh installation. Its discovery completes empty without creating the directory. An absent root with retained catalog rows remains unavailable; it cannot confirm those rows as missing. Creating the optional directory later schedules ordinary discovery again.
40
41 Per-workspace completeness uses that discovery result. It does not silently omit an unavailable root because a later filesystem stat reports it absent; retained rows remain visible while the failed-directory count reports incomplete discovery.
42
43 The automatically sorted legacy all-sessions view reads bounded pages from an immutable catalog database view instead of collecting every page first, including when the workspace contains groups. Time filters run in the page query with a cutoff frozen for the snapshot. Automatically sorted pinned workspace shells use the same adapter and read only pinned current-format member headers. Sessions sharing a topic are paged individually. Releasing a cursor closes its dedicated read-only database connection. Activity updates appear after refreshing the snapshot.
44
45 Automatically sorted group and ungrouped views use the same bounded result pages. Membership is fixed by the captured organization and matches physical source keys, so sharing a topic does not put two sessions in the same group. Current-format group/pin admission happens before reading member headers. Empty groups stay empty; missing groups report an error. Membership edits appear only in a new snapshot. Sparse group predicates may still scan database metadata keys; this is not a constant-time lookup guarantee or completion of incremental organization import. Source-key comparison uses the existing hash contract without resolving each candidate file or adding a persisted schema/index function.
46
47 Text filtering in automatically sorted single-head views also keeps a fixed catalog snapshot and reads metadata in bounded batches. It preserves Go Unicode case matching over the displayed title, preview, and physical source key, including localized automatic titles. Source keys come from captured catalog identities without resolving each candidate file. Only matching result pages remain resident. Sparse or absent matches can still scan all metadata; this is bounded memory, not indexed full-text search or a constant-latency guarantee. Cancellation is checked between candidates and database batches.
48
49 Creating, renaming, or deleting a group no longer forces legacy page enumeration when no old source-dependent preferences need importing. Assigning or unassigning a session admits only the explicit source in the organization transaction. Path-only and source selectors use the same physical membership key. Explicit ungrouping retains an import fence, so later discovery cannot restore an old topic-wide assignment. Adoption and canonical lifecycle changes are rechecked inside the transaction; a stale revision or ownership conflict cannot admit a source. Manual reordering and old group/order preference import still require their existing full-source path.
50
51 Legacy JSONL checkpoints, trusted `.display-index.json` files, and DAGs can build SQLite locator projections in the cache. Bodies are still read through their native format. DAG projection applies the selected branch and overlays and does not create a current-format manifest. Bound readers and compatibility paging share one preparation owner for each source, branch, and observed generation. Replacing a source cancels the old generation's reads; releasing one reader does not cancel its peers. Retiring owners remain discoverable until their database is closed, so immediate reopen and canceled successor tasks cannot bypass the cache-close barrier. Shutdown also cancels preparations borrowed without a persistent read handle. Native directory sessions can be read before a controller is created.
52
53 Native bound readers advertise `history-native-search-v1` for on-demand full-text search. An explicit search prepares a disposable SQLite text index from the validated checkpoint or selected event/DAG view, one provider message at a time. Search returns `preparing` with no hits until a complete generation is published; opening or paging alone never starts that work. Readers share the preparation and cancellation owner; the last release and shutdown join search before closing its databases. Search cursors bind the query and source/branch generation, results resolve through the existing message locator, and a matching completed cache is reused on reopen. This adds bound search APIs and a negotiated frontend adapter, not a new search dialog.
54
55 Historical root services share a 256 MiB idle-runtime budget and the existing 60-second idle TTL. Executing, approval-waiting, and bound runtimes are not idle eviction candidates. This is not a total application memory limit.
56
57 Bound JSONL/checkpoint and DAG readers also provide paged authored-turn outlines and direct turn/message anchors without creating an execution controller. Outline positions use a partial SQLite index; previews decode only the requested user records, one at a time, and retain bounded text. The optional answer preview is omitted on this cold path. Primary display-message identities resolve directly to fixed-cut cursors; derived subrows are not advertised as independent locator identities. Outline and anchor requests validate the same source, branch and rewrite generation as window reads. Older services without `history-native-navigation-v1` keep their existing navigation protocol. Read cancellation or source replacement cannot publish a partial outline into another navigation.
58
59 Schema-1 native event logs without a trusted display sidecar use the same reader. Replace/append records are folded into disk-backed message locations; even a replacement containing the entire conversation is decoded one message at a time. Broken append chains, future schemas, and torn tails cannot publish a valid prefix as complete history. JSON field ordering is preserved as a compatibility property. A validated cached generation avoids rescanning even a header placed after a large message array. Only derived SQLite files change; checkpoints, event logs, and compatibility display sidecars remain untouched.
60
61 Large-field refs returned by bound native windows retain their read handle. Content chunks use the same pager, source cut and cancellation lifetime; releasing or replacing the handle cannot redirect an old ref into a new reader or a management target. Reading a field no longer invokes the compatibility checkpoint-repair path for these refs.
62
63 Unbound compatibility field reads for formats accepted by the native pager also borrow that preparation owner, including explicit management targets. They validate the native source before and after reading and do not publish a compatibility display sidecar or repair a stale checkpoint. Canceling one borrowed read does not cancel a bound peer. Unsupported preparation paths and ancient event-row refs still use their existing compatibility reader; this does not give those protocols the lifetime of a persistent read handle.
64
65 Cold compatibility readers resolve the captured historical path against known source directories. A global tab's current workspace directory does not replace the original global history directory. Paging, field reads, and older preview RPCs share that resolution; unknown roots and symlinks escaping known roots remain rejected.
66
67 Only explicit unsupported-format results permit the compatibility reader. Cache, I/O and parse failures in an admitted native source remain read failures, instead of silently starting full replay. Ancient kind/type event envelopes are explicitly classified at the first record; a foreign row after valid checkpoint messages is damage, not an unsupported format. Removed or renamed catalog roots explicitly release their native watch before registering a replacement at the same path.
68
69 Maintenance diagnostics contain counters and resource usage, not transcript bodies. `historyMaintenance.instrumentedReadBytes` counts actual controlled-reader bytes, not stat sizes presented as I/O measurements.
70
71 ## Registry reads and ownership resolution
72
73 Each successful registry verification publishes an immutable snapshot with session ownership, lifecycle, shared-topic, and source-branch lookup indexes. Navigation, execution ownership checks, and legacy adoption lookups use explicit identities. A single-session lookup does not copy workspace membership or operation journals. A successful durable mutation immediately publishes an independently owned snapshot; retained earlier snapshots do not change.
74
75 Source and session invalidation tokens are built once from that same publication, including source proofs, lifecycle generations, and unknown persisted fields. Workspace membership and source fences share one byte verification per page validation and query the related identities instead of cloning the registry and rescanning every mapping for each row. Title/pin edits and unrelated session changes do not revoke a retained read. Display copies borrow the exact publication's immutable token index; equal numeric generations alone cannot establish that relationship.
76
77 Display readers may retain a published snapshot, but it does not authorize execution. Execution and management admission still verify actual registry bytes, including older writers that preserve timestamps or generation. Overlapping verifications share a read, and canceling one caller does not cancel the others. Corrupt files, future formats, and ownership conflicts neither replace the last display snapshot nor authorize overwriting the authoritative file with cached state.
78
79 Stable snapshot lookup is O(1). Initial reads, external validation, and JSON registry writes remain O(B), where B is the registry byte count. Lookup benchmarks covering 100, 10,000, and 100,000 sessions distributed over 1, 100, and 1000 projects measure only snapshot queries, not startup acceptance.
80
81 Mainline formal session creation and input recovery remain intact. Durable operation receipts establish successful creation; a later history or sidebar projection failure cannot authorize creating another session. Runtime updates retain the existing epoch/revision owner, and bodies retain their negotiated read binding.
82
83 ## Remaining acceptance boundaries
84
85 The history.29 package (`741ce6a81`) carries the event/DAG restart preparation, protected-window budget correction, and eviction-time release of historical read bindings. Its native smoke passed checkpoint and schema-1 event cold reads, bounded pages, outlines, anchors, search, Unicode large fields, writer conflicts, group cursors and normal shell/service exit. The same package completed the [cache soak evidence](validation/history-cache-history29.json) over four rounds and eight checkpoint/event sessions with bidirectional paging and A→B→A navigation: 195 observations, resident windows capped at 3, body bytes at 130,080, parsed Markdown at 987,280, 20 history evictions, two reclaimed pages, and 466 SVG URL creations with 464 revocations. Settled samples had no pending Markdown worker work. Source hashes stayed unchanged and both processes exited normally.
86
87 The history.28 package (`66f838fdf`) remains the latest valid scale-measurement package. Its [90 warm-catalog samples](validation/history-startup-history28.json) passed the unchanged threshold on macOS arm64 / Apple M1 Max: at 100/10,000/100,000 sessions, interactive-button p95 was 1,411/1,468/1,485 ms, first-page 1,354/1,422/1,358 ms, trusted-window 1,446/1,491/1,528 ms and send-ready 1,476/1,514/1,550 ms. Initial discovery took 1.2/22.4/249.3 seconds, recorded separately. The history.29 scale run was not accepted because its altered measurement harness did not produce qualified evidence.
88
89 These cache fixtures exercise eviction and page reclamation; they do not saturate byte budgets or qualify total process memory, cross-root idle runtimes, every list mode, non-active body reads or other platforms. The native package evidence also does not establish that every historical format avoids whole-record decode for a single oversized message.
90
91 The history.26 production package (`bc8cdb9fd`) includes the incremental registry projection, checkpoint restart preparation and streamed display-index import. It passed native JSONL/event paging, outline, search, content reads, writer conflicts, group snapshot cursors and normal shell/service exit. All 90 warm-catalog measurements passed on macOS arm64 / Apple M1 Max with the original thresholds: for 100/10,000/100,000 sessions, interactive-button p95 was 1,430/1,345/1,350 ms, catalog first-page 1,304/1,295/1,309 ms, trusted-window 1,464/1,366/1,360 ms, and send-ready 1,483/1,376/1,382 ms. Initial background discovery took 1.2/21.5/241.1 seconds, separately from startup. [All samples and package identity](validation/history-startup-history26.json) are retained. These results do not qualify subsequent product edits or the outstanding memory, body-read-count, list-mode and cross-platform gates.
92
93 The history.24 production package (`bcef753a5`) completed all 90 measurements on macOS arm64 / Apple M1 Max and passed the unchanged warm-catalog scale threshold. At 100/10,000/100,000 sessions, visible-button p95 was 1,299/1,368/1,350 ms; catalog first-page p95 was 1,277/1,351/1,319 ms; trusted-window p95 was 1,380/1,408/1,349 ms; send-ready p95 was 1,340/1,388/1,371 ms. Initial background discovery took approximately 1.1/21.4/238.3 seconds and is separate from startup samples. Native JSONL/events paging, navigation, search, writer conflicts, unchanged source bytes, group cursors and normal shell/service exit also passed. These measurements precede the incremental registry projection change; they do not qualify every list mode, format, memory budget or platform.
94
95 The history.23 package (`39733a7cd`) passed native checks and eliminated the per-file synchronous journal flood. The 100/10,000 cohorts each completed 30 launches: first-page p95 was 1,272/1,284 ms, visible-button 1,310/1,354 ms, trusted-window 1,345/1,414 ms and send-ready 1,359/1,388 ms. At 100,000 sessions it still restarted discovery after approximately 239 seconds and exceeded the unchanged 300-second warmup limit without startup samples. The subsequent slice-boundary replacement and unchanged-metadata optimizations have deterministic/race coverage; their combined production-scale result is recorded above for history.24/history.26, without attributing that improvement to one isolated change.
96
97 Discovery progress updates use the same process-local SQLite writer boundary as metadata refresh, row publication, and scan completion. An outdated scan generation cannot update a successor's progress. Cancellation leaves discovery incomplete. This removes a concurrent writer admission gap; it does not suppress external database contention or change the retry limits.
98
99 The native measurement harness is `node desktop/packaging/history-startup-scale.mjs /path/Reasonix.app`. Its default is 30 launches at each of 100, 10,000 and 100,000 inactive legacy sessions with one fixed active session. It records package identity, machine, individual samples and p95 separately for a visible action button, the first 50 catalog rows, the trusted transcript window, and sending readiness with a nonempty unsent draft. Button visibility is a proxy, not a comprehensive responsiveness measurement. The harness verifies active identity, no additional model calls and clean shell/service exit. Failed runs retain the fixture and report incomplete cohorts; smoke runs cannot qualify the 30-run gate.
100
101 The September 22, 2026 history.12 run completed 30 samples for 100 and 10,000 sessions: first-page p95 increased from 1,296 ms to 2,374 ms; visible-button p95 was 1,337 ms and 1,330 ms. The 100,000-session discovery warmup timed out before measurement and retained a database with a busy-write failure. This is failed/incomplete acceptance evidence, not a passing performance result. Later packages include the writer-boundary repair; the combined passing measurements are recorded above.
102
103 The history.13 package (`d3522a790`) completed 30 samples each for 100 and 10,000 sessions: first-page p95 was 1,227/1,302 ms, visible-button 1,330/1,330 ms, trusted-window 1,344/1,385 ms, and send-ready 1,357/1,371 ms. At 100,000 sessions discovery reached its first EOF around 245 seconds, then restarted and exceeded the unchanged 300-second warmup limit. No 100,000-session startup sample was collected. The retained fixture and progress trace distinguish this incomplete result from passing acceptance. The later combined result includes the duplicate-recovery-notification and registry-refresh repairs; this older package remains a failed measurement.
104
105 The history.14 package (`8bf67d4a4`) also completed only the two smaller 30-run cohorts: first-page p95 was 1,256/1,424 ms and visible-button 1,340/1,437 ms. Its 100,000-session discovery restarted after roughly 242 seconds and timed out before sampling. Removing the recovery notification was therefore insufficient. The subsequent platform watcher and dispatch-coalescing changes passed focused race tests, including native macOS registration for 512 files under a 256-descriptor process limit; later combined production-scale evidence is recorded above, rather than treating those tests as native qualification.
106
107 The history.15 package (`29e62fc10`) passed native navigation but failed the external-writer fixture when switching to schema-1 event history. The selected session was lease-blocked and passive refresh replaced its pending cold read with a rejected live Follow. A deterministic lifecycle test reproduces that ordering and now passes with the reader/runtime separation above. This is repair evidence, not a passing result for the original package or the outstanding scale cohort.
108
109 The history.16 package (`5d2f9a5c6`) passed native cold reads, external-writer conflicts and rapid navigation. Its 100/10,000 cohorts completed 30 runs each: first-page p95 was 1,265/1,366 ms, visible-button 1,353/1,387 ms, trusted-window 1,366/1,375 ms and send-ready 1,381/1,408 ms. The 100,000 cohort again restarted discovery after its first EOF and exceeded the unchanged 300-second warmup limit, collecting no startup samples. Startup now admits the first watched-root batch before releasing interrupted journal jobs; query admission remains independent of journal writes, and rejected root requests remain pending for retry. This addresses an additional duplicate-dispatch ordering; the later combined package measurement is recorded above.
110
111 The history.17 package (`1833a5fac`) passed the same native checks but still restarted 100,000-session discovery and timed out before sampling. The 100/10,000 cohorts each had 30 runs; first-page p95 was 1,340/1,312 ms and visible-button 1,352/1,322 ms. A further deterministic reproduction identified `SetTrayLocale`: the renderer's mount effect invoked the all-root refresh path. Four locale synchronizations produced four scan requests before repair. Presentation-only notification removes that trigger; its individual performance effect was not isolated; later combined package measurements are recorded above.
112
113 The history.19, history.20 and history.21 100,000-session probes also timed out before collecting startup samples. Filtering root write notifications was not a demonstrated repair and was removed. The history.22 package (`7f6695004`) passed native JSONL/events navigation, search, group paging, writer conflicts and clean exit. It completed 30 launches at 100/10,000 sessions: first-page p95 was 1,319/1,368 ms, visible-button p95 1,328/1,399 ms. At 100,000 sessions it restarted discovery after approximately 247 seconds and exceeded the unchanged 300-second warmup limit. Flushing native notifications once before discovery was therefore insufficient. Diagnostics identified continued per-file queue overflow; later combined package measurements include the watcher admission repair, without proving its independent effect.
114
115 The implementation must not yet be described as complete performance governance. Custom ordering and multi-head sidebars still use the original full snapshot adapter. Importing old source-dependent organization preferences can still enumerate legacy pages. The ordinary all-sessions view still reads all current-format member headers; historical directory discovery still needs integration into the persistent incremental projection. A shell still collects all explicitly pinned rows. These remaining paths prevent a claim that every startup/list configuration is independent of library size.
116
117 Desktop's advisory metadata catalog opens without waiting for a full database integrity scan. The full `integrity_check`, including index consistency, is admitted through background maintenance after restoration admission. Corruption discovered by that audit or a metadata query revokes the generation, cancels its work, and closes every dedicated read lease before the lifecycle owner reopens through normal validation/quarantine. Replacement revisions remain above the revoked generation. Transient I/O, lock contention and cancellation do not authorize quarantine. Other projections, including body locators, retain their existing synchronous validation.
118
119 The background integrity audit is a cancellable SQLite statement; its internal I/O is not yet divided into 64 KiB/50 ms application slices. Schema upgrades and metadata refresh can still perform whole-projection work. Removing the synchronous integrity scan therefore does not prove that every opening path or background task is independent of catalog size.
120
121 Checkpoint JSONL preparation retains committed progress across cancellation and reopening. One disposable staging database stores message locations, source offset, turn state and the semantic digest state in the same transaction. The existing cross-process rebuild lock serializes staging owners. The resume key includes native source identity and change metadata; the open file and current path are checked before and after preparation, and an available authoritative content digest must match before publication. A replaced source, missing source fence, or damaged progress restarts preparation; an ordinary build failure discards staging. Only a fully validated database replaces the readable generation. These are disposable cache additions that older readers can ignore; no manifest or transcript is rewritten. Deterministic tests cover interrupted batches, a child process exiting immediately after a committed batch without closing its database, same-size rewrites with restored modification time, replacement during preparation and newly authoritative event logs. Resumption measures actual controlled-reader bytes to confirm that the completed prefix is not decoded again. This does not establish equivalent source-version behavior on every filesystem.
122
123 Importing an existing display-index JSON also persists committed entry batches and the consumed JSON offset. Resumption reconstructs array framing without rereading the completed prefix and preserves header fields appearing before or after entries. The offset comes from parser consumption, not buffered read-ahead. Source changes and damaged checkpoints restart the disposable import. Repeated cancellation and cancellation at the final entry preserve cancellation semantics; malformed separators and incomplete tails remain errors. The original display index is never rewritten.
124
125 Schema-1 event preparation also saves the consumed parser offset, completed records and partial message arrays with their staged locations. The separate selected-view projection phase checkpoints its message position, turn counts and digest state. Reopening validates the source generation and resumes both phases; fields after arrays, repeated messages fields, replace/append ordering and invalid JSON tails keep their original semantics. Tests cover cancellation, a process exiting without cleanup, damaged/missing progress, source replacement and same-size rewrites. This is cache-only data; previous readers can discard it. Source-kind detection for unusual legacy field ordering can still reread the identifying record before resuming preparation.
126
127 DAG preparation also persists its graph scan, parent-chain traversal and selected-view projection as separate resumable phases. Consumed offsets, branch selection, chain positions, turn counts and digest state commit atomically with derived rows. Each batch updates only changed heads instead of rewriting every branch. Tests compare resumed views with native replay across cancellation and abrupt process exit in each phase, repeated cancellation, missing/damaged progress, source replacement, same-size rewrites, explicit branch changes and cancellation before publication. Restored head state still uses memory proportional to branch count; this does not address oversized individual records.
128
129 The production cache soak additionally exposed a passive-ready refresh replacing an independently readable lease-blocked window with the newest page. Passive metadata now retains an existing certified window for the same identity and generation when no changed content proof is supplied. Explicit retries, missing proof, changed revisions and changed generations still require reading. The history.27 native reader, search, anchors and normal shutdown passed, but sustained navigation exposed another defect: resident accounting excluded protected windows. The budget now counts all resident windows while evicting only unprotected candidates. Live owners are preserved if they alone exceed capacity, and unpinning immediately rechecks the budget. The real-package soak must pass on a package containing these fixes before claiming native cache qualification.
130
131 Oversized individual messages and append-stable cursors also require further implementation and validation. Checkpoint preparation currently bounds a single decoded record at 16 MiB; it does not yet spool larger records. Event arrays are streamed, but individual provider messages are still decoded as values. Native full-text preparation also retains one decoded provider message and its search text; one- or two-character queries may scan that selected session's search index. Unsupported ancient formats still require their compatibility path. No parseable prefix is certified as a complete replacement for unsupported or damaged history.
132
133 Formats or remote protocols without the new read binding retain their negotiated reader. A read failure does not authorize changing the storage source. Explicit import, archive, recovery, copy, move, and complete export keep their management semantics.
134
135 Acceptance records interactive startup, catalog first page, first trusted window, and execution readiness separately. Thirty fixed-environment measurements at each of 100, 10,000, and 100,000 sessions, actual packaged startup and exit, and memory convergence during sustained navigation require independent evidence. Browser mock tests do not replace those gates.
136
136 lines MARKDOWN