source.kind: plugin says a plugin supplied the message; it does not prove Agent Loop authored it. Search the exact plugin, summary, text, and installed bytes.One type contract, one runtime gap.
createUserMessage()Adds a UUID, role: user, and freezes the message before delivery.
Can cross JavaScript or patched-package boundaries without a runtime identity.
rc.2 live append snapshots JSON and validates the surface, but cold restore additionally runs assertMessageEventShape(). An id-less notice can therefore appear healthy until restart. The durable fix is producer construction plus receiver-side fail-fast validation—not lenient replay.
Do not collapse two failures.
One Session fails full load at a later event sequence.
Header-only listing fails when the first Zstandard frame contains more than one line.
Generic whole-file recompression can turn the first failure into the second.
The exact producer package and bytes outrank the generic source kind.
Preserve the correlation set.
- 01Stop every writer and copy the complete Session directory.
- 02Hash the original; work only on an isolated copy.
- 03Capture the id-less event and its earlier
agent/inbox/splicedinsertion. - 04Find the producer from
source.plugin, exact text, package version, and installed bytes. - 05Use one consistent identity across correlated events; never patch only the final load error.
- 06Preserve the one-line header frame, checksums, sequence, surface, and cold-load behavior.
Quarantine the affected Session and continue in a new one unless a version-pinned tool validates every logical and physical invariant on a copy.
Primary evidence.
- Id-less notice report #4819
- identified message constructors
- live append and cold-load validator
- durable Inbox splice
- header-only Zstandard listing
Keep the complete Session corruption router.
The canonical runbook separates framing, sequence, projection identity, message construction, quarantine, repair, and regression ownership.
Read and star on GitHub