Add the durable session-persistence capability seam (ADR 0016): an
abstract SessionPersistence service (dsh-session-persistence,
ctx.sessionPersistence) defining create/append/load/list/has/delete/
update over the existing SessionEvent — no parallel persisted type — and
a first implementation (dsh-session-persistence-jsonl): an append-only
JSONL log per session with crash-safe atomic writes, truncation-repair
of a never-committed crash tail, and a read/replay path. SessionMeta
(format version, cwd, lineage) travels out-of-log via session.header.
A shared runPersistenceContract suite holds every backend to the same
append-only / contiguous-seq / lazy-materialization / serializability
semantics.
Config-driven create() now uses a per-run ${id}-session-<uuid> session
id so a fixed name no longer collides with an on-disk log once a durable
backend is loaded; each run is a new session (a demo simplification). The
examples drop their hand-rolled session-jsonl.ts and load the JSONL
backend via cordis.yml; CI smoke-loads it too.
The agent-facing create/resume factory that consumes load() is a
separate seam, deferred to a follow-up; this change stops at the load
primitive and does not reach into the loop.
Architecture Decision Records
Short, immutable records of the why behind decisions that shape this codebase. Code and docs say what the system does; ADRs say why it does it that way and what we gave up.
Format: one file per decision, numbered, with Status / Context / Decision / Consequences. An ADR is never edited into a different decision — supersede it with a new one and cross-link.
When to write an ADR
Write one when a decision is all three of: durable (it shapes the codebase beyond a single function or package), contested (there was a real alternative you rejected, and a reasonable engineer might have chosen it), and surprising (a future reader would otherwise ask "why on earth is it done this way?"). The ADR captures the why and what we gave up — the parts code and docs can't.
Do NOT write an ADR for: a mechanical or local choice (a variable name, a one-file refactor); anything already enforced and explained by a gate or a convention in AGENTS.md; or a still-provisional decision tagged TODO(...) in the code — record those as TODOs and promote to an ADR only once they settle. When in doubt, the test is the "why on earth" question: if the code alone would mislead a careful reader about intent, write the ADR.
| # | Title | Status |
|---|---|---|
| 0001 | Vendor Cordis as source, not npm dependencies | accepted |
| 0002 | Microkernel: extension via Cordis event taxonomy, one concrete loop | accepted |
| 0003 | Event-sourced sessions with derived message history | accepted |
| 0004 | Provider-neutral content-block vocabulary owned by dsh-llm | accepted |
| 0005 | Custom typed tool-schema DSL instead of schemastery | accepted |
| 0006 | Tool schemas are part of the system-prompt assembly | accepted |
| 0007 | Mechanical quality gates over prose guidelines | accepted |
| 0008 | tsdown for JS bundling instead of dumble | accepted |
| 0009 | Capability seams — interface / implementation / consumer split | accepted |
| 0010 | Two LLM adapters as a design-verification twin | accepted |
| 0011 | Runtime arg validation at the model boundary | accepted |
| 0012 | Dev-mode invariants over compile-time deep-readonly | accepted |
| 0013 | Property-based testing for protocol-shaped code | accepted |
| 0014 | Doc-sync enforcement (doc code blocks + event taxonomy) | accepted |
| 0015 | Structured error taxonomy (HarnessError base) | accepted |
| 0016 | Session persistence as an abstract service over SessionEvent |
accepted |
| 0017 | Every session event is enclosed in a turn | accepted |