Files
Michał Pierzchała 8c06965d28 fix(daemon): cap events.ndjson with cursor-safe rotation (#1867)
* fix(daemon): cap events.ndjson with cursor-safe rotation

Rotate events.ndjson to events.ndjson.1 once it reaches
AGENT_DEVICE_EVENT_LOG_MAX_BYTES (default 5 MB), keeping one rotated
generation. Cursors stay absolute across rotation through a sidecar
window offset, so a persisted nextCursor still names the same event; a
cursor older than the retained window fails with COMMAND_FAILED and
details.reason EVENT_LOG_CURSOR_EXPIRED instead of returning a wrong
page.

Closes #1788

* fix(daemon): verify the events.ndjson window against the files on disk

Rotation recorded only a dropped-line offset, written after the rename,
so a reader landing in that window mapped every absolute cursor a whole
generation too far (reproduced: 5 of 58 reads returned event 17 for
cursor 9), and a missing rotated file or stale sidecar shifted cursors
permanently and silently.

The sidecar now records each retained generation's first absolute line
index, line count, and first-line digest, and is written before the
rename it describes. The reader identifies each file on disk by digest,
derives its start from the matching record, and checks the recorded line
count and generation contiguity; anything unverifiable raises a typed
EVENT_LOG_WINDOW_UNVERIFIED instead of a guessed offset. A torn snapshot
(rotation landing mid-read from the threadpool) is retried, not
interpreted. A corrupt sidecar fails reads typed and never blocks
appends, and rotation no longer does synchronous whole-file I/O.

* refactor(daemon): split event-log window placement and share one line splitter
2026-08-19 12:53:51 +02:00
..

ADR index — read this when…

ADR Read when you touch…
0001 Provider-First Integration Scenarios integration testing strategy, provider transcripts, the scenario harness
0002 Persistent Platform Helper Sessions helper process lifecycle, keep-alive semantics
0003 Daemon Command Registry daemon routing, request-policy traits
0004 iOS Snapshot Backend Strategy snapshot capture plans, backend fallbacks, quality verdicts
0005 iOS Runner Interaction Lifecycle XCTest runner sessions, leases, adoption, idle-stop
0006 Daemon RPC Protocol Version remote daemon HTTP/JSON-RPC compatibility
0007 Remote Device Leases leases, tenancy, provider-owned devices
0008 Command Descriptor Registry adding/changing a command, any surface projection (CLI/MCP/client/batch), timeout policy
0009 Apple Platform Consolidation Apple platform family, apple/appleOs axes, the apple-leak guard
0010 Error system conventions error codes, hints, normalizeError, typed error signals
0011 Interaction Guarantee Contract interaction dispatch paths, fast paths, guards, the guarantee matrix, parity tables
0012 Interactive Replay replay healing/--update, diagnostic resolution disclosure, bounded .ad target-binding evidence, bounded divergence wire/error handling, plan-bound replay-only --from semantics, and agent-supervised re-record repair ("heal-by-doing")
0013 Unified Gesture Plans gesture API/routing, contact topology, multi-touch geometry, native pointer injection, two-finger pan
0014 Session Ref-Frame Lifetime ref authorization epochs, complete/partial issuance, pre-side-effect expiration, replay/batch compatibility, and cross-platform stale-mutation policy
0015 Direct Maestro Compatibility Engine Maestro YAML parsing/execution, compatibility observation policy, conformance, performance gates, gesture integration
0016 Active-Session Script Publication publishing an armed open-to-destination .ad script without closing its live session
0017 Parameterized Recorded Inputs safely authoring sensitive fill inputs as ${VAR} placeholders across recording, replay, and repair
0018 Unified Request Event Journal (Proposed) event/diagnostic vocabulary, journal scopes and sinks, progress-channel separation, observability-only state
0019 Request-Bound Platform Runtime platform-package boundaries/composition, device discovery, runtime facts/facets, request binding, provider ownership, platform-shaped session resources, durable reattachment, daemon-handler migration

ADRs record why; the registries and gates they describe are the living source of truth — when prose and a registry disagree, the registry wins and the ADR needs a follow-up.

Shape conventions, so consulting an ADR stays cheap:

  • Normative rules first, terse. Status, then a "Rules at a glance" summary a reader can stop after; full contracts and rationale below it.
  • Rationale and refuted alternatives stay in the ADR — they are what stops re-litigating settled ideas — but below the fold.
  • Process history is deleted once complete, not archived in-file. Migration plans, per-step landing tables, and point-in-time status change-logs go to git history; the Status section keeps one line saying so plus any accepted, still-relevant waiver or evidence gap.
  • Once a rule is gate-enforced, the ADR keeps the why and points at the gate rather than restating the rule's details.