Not selected does not mean not ownedA background Session, another Host, SDK process, or shared profile can still own the only safe writer.
Choose the operation by intent.
Serialized domain update. The event log and workspace slot remain durable.
Stop every writer, snapshot all coordinated roots, then publish one no-overwrite trash generation.
Know which store owns truth.
JSONL log
→authorityprojection
→derivedworkspace
domain stateDo not reverse a lossy path.
The normalized project directory cannot reconstruct the original cwd.
Never overwrite an older trash entry for the same Session ID.
Restore fails when the destination ID exists. Never merge event histories.
Six proof gates.
- 01Every process sharing the Session and storage roots is quiescent.
- 02A tested whole-root snapshot predates mutation.
- 03The immutable header matches ID, cwd, and artifact path.
- 04Trash publication cannot overwrite an earlier generation.
- 05Remaining Sessions list and replay after restart.
- 06Restore proves the exact digest before retention expires.
Primary evidence.
Preserve recovery before reclaiming bytes.
The canonical guide specifies storage authority, single-writer quiescence, whole-root snapshots, crash-safe trash generations, collision-free restore, purge gates, and eighteen manager acceptance checks.
Read the complete guide