Skip to content

test(sessions): verify host identity across model changes and lifecycle transitions #1534

Description

@dnlrsls

🔍 Problem Description

#1270 now has real HTTP/SQLite evidence for concurrent host-owned writes on Pi native and Codex, plus a local Claude candidate pending exact-candidate review. Those tests do not run an operator's model switch, compaction, or resume in the host and then prove the same two authoritative session owners still receive their own writes. Simulated callbacks and seeded rows must not be described as that proof. Without an explicit runtime journey, a later host update could lose the binding while adapter unit tests stay green.

💡 Proposed Solution

Add bounded host/runtime conformance journeys for supported integrations, using isolated configuration and a temporary Engram server/database, without touching the operator's Engram data or agent configuration:

  • Register two host sessions with the same project and directory; persist distinguishable writes before and after a real host model change and available compaction/resume event.
  • Verify the stored rows preserve each original host ID and never cross-attribute; failed or ended ownership must refuse an attributed write rather than retry without an ID as if it were a manual MCP save.
  • Clearly label which steps ran through an actual host/client and which use synthetic callbacks, intercepted HTTP, or a simulated external MCP dispatcher. If an operator event cannot be invoked deterministically offline, document the missing executable test route instead of replacing it with a green imitation.
  • Keep tests and code in reviewable ≤400-changed-line work units. Preserve independent direct/manual MCP semantics and existing session rows/leases; no new identity registry.

📦 Affected Area

MCP Server (tools, transport)

🔄 Alternatives Considered

A seeded-session unit test that changes a fake model field is useful for adapter regression, but does not prove real operator model-switch continuity. Broadening #1270 indefinitely makes the accepted host-owned binding work impossible to close honestly.

📎 Additional Context

Follow-up to #1270's formally narrowed acceptance. OpenCode V2 adapter/runtime support is tracked by #1220; its restart with an ended root is a distinct reproduced bug in #1522, so do not duplicate that fix here. Pi legacy adapter configuration is addressed separately from native Pi host binding (related #1507). Claude's local conformance commit fab6aa5c is not yet review-approved or published. Pi 0.1.17 npm publication and the Go installer version pin are separate release decisions.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions