reattach a refreshed browser to a running turn
Refreshing mid-turn appeared to kill the agent's output. It never did: the session survives a dropped socket, the agent keeps generating into it and keeps committing durable events, and `close` only detaches the socket and arms an hour-long idle timer. What broke was purely delivery — and the reconnect path that would have fixed it could not fire, because the browser came back having forgotten officer's session key. It lived in page state. The only id left was Claude's transcript uuid in the URL, and nothing accepted that. So accept it. `attach` carries the uuid, and the agent's on-disk session map — the single record relating the two — turns it back into the key everything else is written in terms of. The uuid now also goes out at `system.init` rather than only at `result`, which is what makes the first turn recoverable at all: until now a chat had no address until it had finished, and a long first turn is exactly the one worth reconnecting to. `sync:live` deliberately carries no messages. The harness writes its transcript as it goes, so the HTTP load on landing already supplies the past; sending the server's record of the same messages on top of it would duplicate them, and there is no shared id to reconcile the two by. Attach hands over the rest of the turn, the half-written paragraph the transcript cannot hold, and the session's cursor head — that last one so a *later* drop replays from the head instead of re-delivering the whole conversation from zero. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -85,6 +85,15 @@ export type ClientMessage =
|
||||
// the current turn. Frees the session so its transcript can be resumed elsewhere.
|
||||
type: 'disconnect';
|
||||
}
|
||||
| {
|
||||
// Sent on (re)connect when the client knows only Claude's transcript uuid — which, after a page
|
||||
// refresh, is the ONLY id it has: officer's `sessionId` lived in React state and died with the
|
||||
// page, while the uuid is in the URL. Officer reverse-maps it through the agent sidecar's
|
||||
// on-disk session map and re-binds this socket to the live session, so a turn that kept running
|
||||
// while the browser was away resumes delivering instead of stranding the user on a dead page.
|
||||
type: 'attach';
|
||||
claudeSessionId: string;
|
||||
}
|
||||
| {
|
||||
// Sent on (re)connect: re-bind this socket to the session and replay every durable event queued
|
||||
// since `cursor` (the last seq the client saw). Powers transparent reconnect without losing
|
||||
@@ -120,6 +129,15 @@ export type ServerMessage =
|
||||
context?: string;
|
||||
contextId?: string;
|
||||
}
|
||||
| {
|
||||
// Claude's transcript uuid, forwarded the moment the harness reports it (its `system.init`) rather
|
||||
// than at the end of the turn with `result`. The client writes it straight into the address bar, so
|
||||
// the chat is addressable — and therefore recoverable after a refresh — from the first second of the
|
||||
// first turn instead of only once the turn has finished. Live-only: anyone replaying the durable log
|
||||
// reached it by this id already.
|
||||
type: 'session:claude';
|
||||
claudeSessionId: string;
|
||||
}
|
||||
| ({
|
||||
type: 'assistant:text';
|
||||
text: string;
|
||||
@@ -158,6 +176,26 @@ export type ServerMessage =
|
||||
isGenerating: boolean;
|
||||
streamingText: string;
|
||||
}
|
||||
| {
|
||||
// Answer to a client `attach`: this socket is now bound to the live session. Deliberately carries
|
||||
// no messages. The client has just loaded the transcript over HTTP and the harness writes that file
|
||||
// as it goes, so the past is already on screen; what it cannot have is the part of the turn still
|
||||
// being written. Sending both records of the same messages is the one thing guaranteed to produce
|
||||
// duplicates — there is no shared id to reconcile them by — so attach hands over the *future* of
|
||||
// the turn plus the half-written paragraph, and nothing else.
|
||||
type: 'sync:live';
|
||||
sessionId: string;
|
||||
isGenerating: boolean;
|
||||
streamingText: string;
|
||||
/**
|
||||
* The session's newest durable cursor, so the client starts from the head rather than from zero.
|
||||
* Not an optimisation: this socket now holds officer's session key, so the *next* drop goes down
|
||||
* the `resume-cursor` path — and a cursor of 0 there would replay the entire session on top of the
|
||||
* transcript the client already loaded over HTTP, turning one reconnect into a duplicated
|
||||
* conversation.
|
||||
*/
|
||||
cursor: number;
|
||||
}
|
||||
| {
|
||||
type: 'error';
|
||||
message: string;
|
||||
@@ -194,6 +232,7 @@ export type ServerMessage =
|
||||
// cursor of the previous durable message in the same session — which lets a reconnecting client tell a
|
||||
// contiguous replay from one with a hole in it. Absent when the writer cannot vouch for it.
|
||||
export type TurnMessageType =
|
||||
| 'session:claude'
|
||||
| 'assistant:delta'
|
||||
| 'assistant:text'
|
||||
| 'tool:start'
|
||||
@@ -209,6 +248,7 @@ export type TurnMessageType =
|
||||
export type TurnMessage = Extract<ServerMessage, { type: TurnMessageType }> & { prevSeq?: number };
|
||||
|
||||
export type ChatEvent =
|
||||
| { type: 'session'; claudeSessionId: string }
|
||||
| ({ type: 'text'; text: string } & Parented)
|
||||
| ({ type: 'delta'; text: string } & Parented)
|
||||
| ({
|
||||
|
||||
@@ -8,7 +8,7 @@ import { ensureGeneralChatSessionsCwd } from './claude-sessions';
|
||||
import * as sidecar from '@@/sidecar-registry';
|
||||
import { join } from 'path';
|
||||
import { getOwnerHomeDir, getEmailAccountsDir } from '../../../servers/data-path';
|
||||
import { getUserSettings, getEmailAccounts, getChatEventsSince, appendChatEvent } from 'officerdb';
|
||||
import { getUserSettings, getEmailAccounts, getChatEventsSince, getLastChatEventSeq, appendChatEvent } from 'officerdb';
|
||||
import { mkdirSync } from 'node:fs';
|
||||
import { logger } from './logger';
|
||||
|
||||
@@ -130,6 +130,8 @@ export function message(ws: ServerWebSocket<WSData>, raw: string | Buffer): void
|
||||
await handleDisconnect(ws);
|
||||
} else if (clientMsg.type === 'resume-cursor') {
|
||||
await handleResumeCursor(ws, clientMsg);
|
||||
} else if (clientMsg.type === 'attach') {
|
||||
await handleAttach(ws, clientMsg);
|
||||
}
|
||||
} catch (err) {
|
||||
logger.error('Error handling WebSocket message', { email: ws.data.email, error: String(err) });
|
||||
@@ -603,6 +605,78 @@ async function handleResumeCursor(
|
||||
if (msg.generating) await endTurnIfAgentIsGone(ws, sessionId, model);
|
||||
}
|
||||
|
||||
/**
|
||||
* Re-bind a socket that knows only Claude's transcript uuid.
|
||||
*
|
||||
* This is the refresh case, and until now it was the hole in an otherwise complete reconnect path. Every
|
||||
* piece of the machinery already existed — the session survives a dropped socket, the agent keeps
|
||||
* generating into it, `close` only detaches and arms an hour-long idle timer — but the browser came back
|
||||
* having forgotten officer's session id, so `resume-cursor` could never fire and the output simply stopped
|
||||
* arriving. The uuid in the URL is the one identifier a refresh cannot destroy; the agent's on-disk map
|
||||
* turns it back into the key everything else here is written in terms of.
|
||||
*
|
||||
* Deliberately hands over only the live turn, never the transcript — see `sync:live`.
|
||||
*/
|
||||
async function handleAttach(ws: ServerWebSocket<WSData>, msg: { claudeSessionId: string }): Promise<void> {
|
||||
const { claudeSessionId } = msg;
|
||||
if (!claudeSessionId) return;
|
||||
|
||||
const sessionId = await sidecar.findClaudeSessionKey(claudeSessionId);
|
||||
if (!sessionId) {
|
||||
// No agent, or a transcript it has never run. Nothing is wrong: an ordinary finished conversation
|
||||
// opened from history lands here every time. Stay silent and leave the socket as it was — the next
|
||||
// `chat` mints a session in the usual way.
|
||||
logger.info('Attach found no live session for transcript', { claudeSessionId });
|
||||
return;
|
||||
}
|
||||
|
||||
// An officer restart takes the in-memory session with it while the agent carries on, so the key can
|
||||
// resolve to a session this process has never heard of. Adopting re-subscribes it to the sidecar's bus,
|
||||
// which is what makes the rest of the turn arrive.
|
||||
const existing = sessionManager.getSession(sessionId);
|
||||
const session = existing ?? adoptOrphanedSession(ws, sessionId, DEFAULT_MODEL, '');
|
||||
|
||||
sessionManager.attachWs(sessionId, ws);
|
||||
wsToSessionMap.set(ws as any, sessionId);
|
||||
|
||||
// The client learns officer's key here, so any *later* drop of this socket goes down the existing
|
||||
// cursor-replay path instead of coming back through attach.
|
||||
sendToClient(ws, {
|
||||
type: 'session:init',
|
||||
sessionId,
|
||||
model: session.model,
|
||||
cwd: session.cwd,
|
||||
context: session.meta.context,
|
||||
contextId: session.meta.contextId,
|
||||
});
|
||||
|
||||
// `isGenerating` is officer's own belief and is only as good as this process's memory of the turn. For
|
||||
// an adopted session it is a fresh record's default, so ask the agent — the same question, and for the
|
||||
// same reason, as `endTurnIfAgentIsGone`.
|
||||
const isGenerating = existing ? session.isGenerating : await sidecar.isClaudeGenerating(sessionId);
|
||||
session.isGenerating = isGenerating;
|
||||
|
||||
let cursor = 0;
|
||||
try {
|
||||
cursor = (await getLastChatEventSeq(sessionId)) ?? 0;
|
||||
} catch (err) {
|
||||
logger.error('Failed to read chat event head on attach', { sessionId, error: String(err) });
|
||||
}
|
||||
|
||||
sendToClient(ws, {
|
||||
type: 'sync:live',
|
||||
sessionId,
|
||||
isGenerating,
|
||||
cursor,
|
||||
// Whatever the agent had typed but not yet finished as a message. The transcript on disk cannot
|
||||
// supply it — the harness writes an assistant message only once it is complete — so this is the one
|
||||
// piece of the turn a refresh would otherwise genuinely lose.
|
||||
streamingText: session.streamBuffer,
|
||||
});
|
||||
|
||||
logger.info('Attached socket to live session by transcript id', { sessionId, claudeSessionId, isGenerating });
|
||||
}
|
||||
|
||||
/**
|
||||
* The client came back still believing a turn is running. Check whether it is, and if it isn't, say so.
|
||||
*
|
||||
|
||||
@@ -318,6 +318,27 @@ export async function isClaudeGenerating(sessionKey: string): Promise<boolean> {
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Officer's session key for a Claude transcript uuid, or null if the agent has never seen it.
|
||||
*
|
||||
* The browser only ever has the uuid after a refresh — it is what the URL carries — and officer's own
|
||||
* key is not derivable from it. The agent's on-disk map is the single record that relates them, so this
|
||||
* is the hinge the whole reattach path turns on.
|
||||
*
|
||||
* Fails toward null: no agent, no answer, or a timeout all mean "cannot re-bind", and the caller falls
|
||||
* back to today's behaviour of leaving the socket unattached rather than binding it to a guess.
|
||||
*/
|
||||
export async function findClaudeSessionKey(claudeSessionId: string): Promise<string | null> {
|
||||
const sc = findSidecarByCapability('claude');
|
||||
if (!sc) return null;
|
||||
try {
|
||||
const res = await sendCommandToSidecar(sc, { type: 'claude:find-session', id: nextId(), claudeSessionId });
|
||||
return res.type === 'claude:session-key' ? res.sessionKey : null;
|
||||
} catch {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
export function clearClaudeSession(sessionKey: string): void {
|
||||
sendFire('claude', { type: 'claude:clear-session', id: nextId(), sessionKey });
|
||||
}
|
||||
|
||||
@@ -105,6 +105,28 @@ export function getClaudeSession(sessionKey: string): string | undefined {
|
||||
return currentState.claudeSessions[sessionKey];
|
||||
}
|
||||
|
||||
/**
|
||||
* The same map read backwards: Claude's transcript uuid → the key officer made up for the session.
|
||||
*
|
||||
* A browser that has refreshed holds only the uuid, because that is what is in the URL; officer's own
|
||||
* key lived in page state and is gone. This is the only record anywhere that relates the two, which is
|
||||
* why re-binding a socket to a running turn has to come through the sidecar rather than being answerable
|
||||
* on the platform side.
|
||||
*
|
||||
* A linear scan over a handful of live sessions. If that ever stops being true, add the inverse map —
|
||||
* but a second copy of a mapping is a second thing to keep honest, and this one is written on every turn.
|
||||
* Newest wins: a transcript resumed under a fresh key leaves the old entry in place, and the caller wants
|
||||
* the session generating now, not the one that produced the same file yesterday.
|
||||
*/
|
||||
export function findSessionKeyByClaudeSession(claudeSessionId: string): string | undefined {
|
||||
const keys = Object.keys(currentState.claudeSessions);
|
||||
for (let i = keys.length - 1; i >= 0; i--) {
|
||||
const key = keys[i]!;
|
||||
if (currentState.claudeSessions[key] === claudeSessionId) return key;
|
||||
}
|
||||
return undefined;
|
||||
}
|
||||
|
||||
function scheduleSave() {
|
||||
if (saveTimer) return;
|
||||
saveTimer = setTimeout(async () => {
|
||||
|
||||
@@ -338,7 +338,10 @@ describe('parseStream', () => {
|
||||
|
||||
expect(state.gotResult).toBe(true);
|
||||
expect(sessionIds).toEqual(['sess_1', 'sess_1']);
|
||||
expect(events.map((e) => e.type)).toEqual(['delta', 'text', 'result']);
|
||||
// `session` leads: the transcript id goes out at `system.init` so the URL is a permalink from the
|
||||
// start of the turn, which is what makes a mid-turn refresh reattachable.
|
||||
expect(events.map((e) => e.type)).toEqual(['session', 'delta', 'text', 'result']);
|
||||
expect(events[0]).toEqual({ type: 'session', claudeSessionId: 'sess_1' });
|
||||
});
|
||||
|
||||
test('handles chunked delivery (split mid-line)', async () => {
|
||||
|
||||
@@ -148,7 +148,13 @@ function handleSystem(msg: Record<string, unknown>, callbacks: StreamParserCallb
|
||||
const subtype = msg.subtype as string | undefined;
|
||||
if (subtype === 'init') {
|
||||
const sessionId = msg.session_id as string | undefined;
|
||||
if (sessionId) callbacks.onSessionId(sessionId);
|
||||
if (sessionId) {
|
||||
callbacks.onSessionId(sessionId);
|
||||
// Also out to the browser, and at the *start* of the turn. The same id used to travel only on
|
||||
// `result`, so a chat had no address until its first turn had finished — refresh before that and
|
||||
// there was nothing to reconnect by, which is exactly when a long turn is worth reconnecting to.
|
||||
callbacks.onEvent({ type: 'session', claudeSessionId: sessionId });
|
||||
}
|
||||
} else if (subtype === 'task_started') {
|
||||
callbacks.onEvent({
|
||||
type: 'task:started',
|
||||
|
||||
@@ -28,6 +28,27 @@ describe('createTurnStream', () => {
|
||||
expect(durable).toHaveLength(0);
|
||||
});
|
||||
|
||||
test('the transcript id goes out live but is never persisted', () => {
|
||||
// Durable would put a second copy of the answer inside the question: the only way to replay this log
|
||||
// is to ask for it by the very id the event carries.
|
||||
const { all, durable, types } = run([{ type: 'session', claudeSessionId: 'claude-uuid-1' }]);
|
||||
expect(types).toEqual(['session:claude']);
|
||||
expect(all[0]!.msg).toEqual({ type: 'session:claude', claudeSessionId: 'claude-uuid-1' });
|
||||
expect(durable).toHaveLength(0);
|
||||
});
|
||||
|
||||
test('the transcript id does not disturb an open delta buffer', () => {
|
||||
// It arrives at `system.init`, but a resumed turn can re-announce it mid-flight, and flushing there
|
||||
// would split one paragraph into two messages.
|
||||
const { durable } = run([
|
||||
{ type: 'delta', text: 'half ' },
|
||||
{ type: 'session', claudeSessionId: 'claude-uuid-1' },
|
||||
{ type: 'delta', text: 'a sentence' },
|
||||
{ type: 'result', cost: COST },
|
||||
]);
|
||||
expect(durable[0]).toEqual({ type: 'assistant:text', text: 'half a sentence' });
|
||||
});
|
||||
|
||||
test('an explicit text event wins over the deltas that produced it', () => {
|
||||
const { durable } = run([
|
||||
{ type: 'delta', text: 'par' },
|
||||
|
||||
@@ -46,6 +46,12 @@ export function createTurnStream(sessionId: string): TurnStream {
|
||||
const parent = ('parentToolUseId' in event ? event.parentToolUseId : undefined) ?? '';
|
||||
|
||||
switch (event.type) {
|
||||
case 'session':
|
||||
// Not durable: the id names the log rather than belonging in it, and a client replaying the log
|
||||
// had to know the id to ask for it. Persisting it would put a second copy of the answer inside
|
||||
// the question.
|
||||
return [{ msg: { type: 'session:claude', claudeSessionId: event.claudeSessionId }, durable: false }];
|
||||
|
||||
case 'delta':
|
||||
buffers.set(parent, (buffers.get(parent) ?? '') + event.text);
|
||||
return [{ msg: { type: 'assistant:delta', text: event.text, ...parented(parent) }, durable: false }];
|
||||
|
||||
@@ -2,7 +2,15 @@ import { existsSync, mkdirSync, readFileSync, writeFileSync } from 'node:fs';
|
||||
import { join, resolve } from 'node:path';
|
||||
import { homedir } from 'node:os';
|
||||
import type { SidecarCommand, SidecarEvent } from '../protocol';
|
||||
import { initPaths, loadState, flushAndSave, acquireLock, releaseLock, readProxySecretFromDisk } from './state';
|
||||
import {
|
||||
initPaths,
|
||||
loadState,
|
||||
flushAndSave,
|
||||
acquireLock,
|
||||
releaseLock,
|
||||
readProxySecretFromDisk,
|
||||
findSessionKeyByClaudeSession,
|
||||
} from './state';
|
||||
import { createSessionLogStore } from './session-log';
|
||||
import { setMcpConfigPath } from './claude-manager';
|
||||
import * as claudeManager from './claude-manager';
|
||||
@@ -194,6 +202,14 @@ async function handleCommand(cmd: SidecarCommand, reply: ReplyFn) {
|
||||
reply({ type: 'claude:generating', id: cmd.id, generating: claudeManager.isSessionGenerating(cmd.sessionKey) });
|
||||
break;
|
||||
|
||||
case 'claude:find-session':
|
||||
reply({
|
||||
type: 'claude:session-key',
|
||||
id: cmd.id,
|
||||
sessionKey: findSessionKeyByClaudeSession(cmd.claudeSessionId) ?? null,
|
||||
});
|
||||
break;
|
||||
|
||||
case 'claude:clear-session':
|
||||
claudeManager.clearSession(cmd.sessionKey);
|
||||
sessionLog.drop(cmd.sessionKey);
|
||||
|
||||
@@ -20,6 +20,9 @@ export type SidecarCommand =
|
||||
// Is a turn still running for this session? Only the process that owns the session can say, which is
|
||||
// exactly why it is asked over the wire — see `isClaudeGenerating` in sidecar-registry.
|
||||
| { type: 'claude:is-generating'; id: string; sessionKey: string }
|
||||
// Which session key owns this transcript? The map lives on the agent's disk, so only it can answer —
|
||||
// see `findClaudeSessionKey` in sidecar-registry, and `attach` in the chat socket for why it is asked.
|
||||
| { type: 'claude:find-session'; id: string; claudeSessionId: string }
|
||||
// OpenCode — drive a turn via `opencode run … --format json` (tools re-anchored to cwd via --dir)
|
||||
| { type: 'opencode:run-streaming'; id: string; params: OpenCodeRunParams }
|
||||
| { type: 'opencode:kill'; id: string; sessionKey: string }
|
||||
@@ -47,6 +50,7 @@ export type SidecarEvent =
|
||||
| { type: 'claude:interrupted'; id: string }
|
||||
| { type: 'claude:session-cleared'; id: string }
|
||||
| { type: 'claude:generating'; id: string; generating: boolean }
|
||||
| { type: 'claude:session-key'; id: string; sessionKey: string | null }
|
||||
// VNC
|
||||
| { type: 'vnc:started'; id: string; port: number; display: number }
|
||||
| { type: 'vnc:password'; id: string; password: string }
|
||||
|
||||
Reference in New Issue
Block a user