import type { FastifyInstance } from "fastify"; import type { PiProcessManager } from "../pi/pi-process-manager.js"; import type { ThtRunner } from "../tht/tht-runner.js"; import type { SseHub } from "../sse/sse-hub.js"; import type { Settings } from "../settings/settings-store.js"; import { getUser } from "../auth/auth.js"; import type { ReadinessManager } from "../runtime/readiness-manager.js"; const BOOTSTRAP_FAILURE_MESSAGE = "Session startup failed. Check configuration and connectivity, then Resume the session."; const READINESS_FAILURE_MESSAGE = "Session services are not ready. Check configuration and connectivity, then try again."; const RESUME_FAILURE_MESSAGE = "Session could not be resumed. Check configuration and connectivity, then try again."; function eventCursor(...values: unknown[]): number { let cursor = 0; for (const value of values.flatMap((item) => Array.isArray(item) ? item : [item])) { if (typeof value !== "string" || !/^\d+$/.test(value)) continue; const parsed = Number(value); if (Number.isSafeInteger(parsed)) cursor = Math.max(cursor, parsed); } return cursor; } export function sessionRoutes( app: FastifyInstance, d: { mgr: PiProcessManager; tht: ThtRunner; hub: SseHub; getSettings: () => Settings; readiness: ReadinessManager }, ) { const lifecycleTails = new Map>(); const boundRuntimes = new Map< string, ReturnType >(); const failurePersistenceClaimed = new WeakSet< ReturnType >(); const withSessionLifecycle = async (id: string, work: () => Promise): Promise => { const previous = lifecycleTails.get(id) ?? Promise.resolve(); let release!: () => void; const gate = new Promise((resolve) => { release = resolve; }); const tail = previous.then(() => gate); lifecycleTails.set(id, tail); await previous; try { return await work(); } finally { release(); if (lifecycleTails.get(id) === tail) lifecycleTails.delete(id); } }; const info = (id: string, text: string, level = "info") => d.hub.publish(id, "info", { type: "info", level, text }); const bindRuntime = (id: string, rt: ReturnType) => { const previous = boundRuntimes.get(id); boundRuntimes.set(id, rt); try { rt.bridge.onClientEvent((e) => { // Child termination is asynchronous. Ignore queued events from a runtime once a newer // identity is bound or the session is explicitly closed/deleted. The active identity // remains bound after an unexpected exit so its public failure events still reach SSE. if (boundRuntimes.get(id) !== rt) return; if (e.type === "system_event" && e.event === "session_failed") { if (!failurePersistenceClaimed.has(rt)) { failurePersistenceClaimed.add(rt); void withSessionLifecycle(id, async () => { // agent_end can release the old binding before this queued work acquires the lock. // Undefined means no replacement; a different identity means Resume won and the // old failure must not touch its manifest. const bound = boundRuntimes.get(id); if (bound !== undefined && bound !== rt) return; await d.tht.failSession(id, d.getSettings().workspace).catch(() => undefined); }).catch(() => undefined); } } d.hub.publish(id, e.type, e); if ( e.type === "system_event" && e.event === "agent_end" && d.mgr.get(id) !== rt && boundRuntimes.get(id) === rt ) { boundRuntimes.delete(id); } }); } catch (error) { if (previous) boundRuntimes.set(id, previous); else if (boundRuntimes.get(id) === rt) boundRuntimes.delete(id); throw error; } }; const bootstrap = ( id: string, rt: ReturnType, configure: Promise, retrieval: Promise | null, start: () => void, ) => { void (async () => { try { if (retrieval) info(id, "Preparing retrieval context"); await Promise.all([configure, retrieval]); if (d.mgr.get(id) !== rt) return; info(id, "Starting model"); if (d.mgr.get(id) !== rt) return; start(); } catch { void withSessionLifecycle(id, async () => { // A bootstrap continuation can settle after Close/Delete or after a replacement was // installed. Claim only the runtime identity that actually failed; holding the same // lifecycle lock through persistence prevents a Resume from becoming that failure's // accidental target. if (d.mgr.get(id) !== rt || !d.mgr.teardownIfCurrent(id, rt)) return; if (!failurePersistenceClaimed.has(rt)) { failurePersistenceClaimed.add(rt); await d.tht.failSession(id, d.getSettings().workspace).catch(() => undefined); } rt.bridge.emitClientEvent({ type: "info", level: "error", text: BOOTSTRAP_FAILURE_MESSAGE }); rt.bridge.emitClientEvent({ type: "system_event", event: "session_failed" }); rt.bridge.emitClientEvent({ type: "system_event", event: "agent_end" }); }); } })(); }; app.post("/runtime/prewarm", async (_req, reply) => { const workspace = d.getSettings().workspace ?? ""; void d.readiness.ensure(workspace).catch(() => undefined); return reply.code(202).send({ status: "warming" }); }); app.post("/sessions", async (req, reply) => { const b = req.body as { question: string; name?: string }; const s = d.getSettings(); const ensure = await d.readiness.ensure(s.workspace ?? ""); if (!ensure.ok) return reply.code(503).send({ error: READINESS_FAILURE_MESSAGE }); // Settings (global) supply workspace/provider/model/thinking. The new-question // form sends only the question text. `workspace` selects the tht `-c `. const { id } = await d.tht.sessionNew({ question: b.question, name: b.name, workspace: s.workspace, provider: s.provider, model: s.model, thinking: s.thinking, }); const options = { provider: s.provider, model: s.model, thinking: s.thinking, author: getUser(req).id, question: b.question, }; const rt = d.mgr.createFor(id, options); bindRuntime(id, rt); info(id, "Session created"); bootstrap( id, rt, d.mgr.configure(rt, options), d.tht.searchPack(b.question, id, s.workspace), () => d.mgr.start(id, rt, options), ); return { id }; }); app.get("/sessions", async () => d.tht.sessionList(d.getSettings().workspace)); app.get("/sessions/:id", async (req) => d.tht.sessionShow((req.params as any).id, d.getSettings().workspace)); app.post("/sessions/:id/response", async (req, reply) => { const id = (req.params as any).id; const rt = d.mgr.get(id); if (!rt) return reply.code(404).send({ error: "sessione non attiva" }); rt.bridge.respond((req.body as any).ui_response); return reply.code(204).send(); }); app.post("/sessions/:id/steer", async (req, reply) => { const rt = d.mgr.get((req.params as any).id); if (!rt) return reply.code(404).send({ error: "sessione non attiva" }); rt.bridge.steer((req.body as any).text); return reply.code(204).send(); }); app.post("/sessions/:id/resume", async (req, reply) => { const id = (req.params as any).id; return withSessionLifecycle(id, async () => { // This check belongs inside the per-session lock: a preceding cold Resume may have // installed a running runtime while this request was waiting. const existing = d.mgr.get(id); if (existing) { const state = existing.bridge.turnState(); if (state === "running" || state === "waiting") { return reply.code(200).send({ id, alreadyActive: true }); } } const manifest = (await d.tht.sessionShow(id, d.getSettings().workspace)) as { status?: string; archived?: boolean } | null; if (manifest?.status === "finalized" || manifest?.archived) { return reply.code(409).send({ error: "sessione in sola lettura (finalizzata o archiviata)" }); } const settings = d.getSettings(); const ensure = await d.readiness.ensure(settings.workspace ?? ""); if (!ensure.ok) return reply.code(503).send({ error: READINESS_FAILURE_MESSAGE }); const saved = manifest as { provider?: string; model?: string; thinking?: string } | null; const options = { provider: saved?.provider, model: saved?.model, thinking: saved?.thinking ?? settings.thinking, author: getUser(req).id, mode: "resume" as const, }; // Reopening is validation, not the transport commit point. Keep the old hub intact if // persistence cannot be reopened. try { await d.tht.reopenSession(id, settings.workspace); } catch { return reply.code(503).send({ error: RESUME_FAILURE_MESSAGE }); } // Re-check immediately before the replacement commit. A lifecycle operation that ran // before this request acquired the lock may have changed or removed the runtime. const current = d.mgr.get(id); if (current) { const state = current.bridge.turnState(); if (state === "running" || state === "waiting") { return reply.code(200).send({ id, alreadyActive: true }); } } let rt: ReturnType | undefined; try { if (current) { if (boundRuntimes.get(id) === current) boundRuntimes.delete(id); d.mgr.teardownIfCurrent(id, current); } rt = d.mgr.createFor(id, options); bindRuntime(id, rt); } catch { // A created-but-unbound runtime is not usable. The old hub remains attached because // clear() has not happened yet. if (rt) { if (boundRuntimes.get(id) === rt) boundRuntimes.delete(id); d.mgr.teardownIfCurrent(id, rt); } return reply.code(503).send({ error: RESUME_FAILURE_MESSAGE }); } // Commit the replacement only after reopen + runtime creation/binding succeeded, and // immediately before the first event produced by the new Resume. d.hub.clear(id); info(id, "Resuming session"); bootstrap(id, rt, d.mgr.configure(rt, options), null, () => d.mgr.start(id, rt, options)); return reply.code(200).send({ id, alreadyActive: false }); }); }); app.post("/sessions/:id/close", async (req) => { const id = (req.params as { id: string }).id; return withSessionLifecycle(id, async () => { // Invalidate the live generation before persistence can yield. Otherwise its deferred // bootstrap may start Pi while Close is already in progress. const current = d.mgr.get(id); boundRuntimes.delete(id); if (current) d.mgr.teardownIfCurrent(id, current); try { await d.tht.closeSession(id, d.getSettings().workspace); } finally { d.hub.clear(id); } return { closed: true }; }); }); app.get("/sessions/:id/events", (req, reply) => { const id = (req.params as any).id; const rt = d.mgr.get(id); const afterId = eventCursor( req.headers["last-event-id"], (req.query as { lastEventId?: unknown }).lastEventId, ); // Add CORS headers manually: reply.raw.writeHead bypasses Fastify's onSend hooks // (where @fastify/cors injects headers), so we must set them explicitly here. const origin = (req.headers.origin as string | undefined) ?? "*"; reply.raw.writeHead(200, { "Content-Type": "text/event-stream", "Cache-Control": "no-cache", "X-Accel-Buffering": "no", Connection: "keep-alive", "Access-Control-Allow-Origin": origin, "Access-Control-Allow-Credentials": "true", }); // Send the handshake immediately. Without this, Node waits for the first event body and // proxies/clients cannot establish an idle SSE subscription or inspect its headers. reply.raw.flushHeaders(); const send = (event: string, data: object, eventId: number) => reply.raw.write(`id: ${eventId}\nevent: ${event}\ndata: ${JSON.stringify(data)}\n\n`); const off = d.hub.subscribe(id, send, { afterId, pending: rt?.bridge.pendingWidget() ?? null, // clear()/forget() end every old transport so native EventSource reconnects with its // Last-Event-ID instead of remaining attached to a subscriber callback that no longer exists. close: () => { if (!reply.raw.writableEnded) reply.raw.end(); }, }); req.raw.on("close", off); }); app.post("/sessions/:id/rename", async (req, reply) => { await d.tht.setName((req.params as any).id, (req.body as any).name); return reply.code(204).send(); }); app.post("/sessions/:id/group", async (req, reply) => { await d.tht.setGroup((req.params as any).id, (req.body as any).group); return reply.code(204).send(); }); app.post("/sessions/:id/archive", async (req, reply) => { await d.tht.archive((req.params as any).id); return reply.code(204).send(); }); app.post("/sessions/:id/unarchive", async (req, reply) => { await d.tht.unarchive((req.params as any).id); return reply.code(204).send(); }); app.delete("/sessions/:id", async (req, reply) => { const id = (req.params as any).id; return withSessionLifecycle(id, async () => { const current = d.mgr.get(id); boundRuntimes.delete(id); if (current) d.mgr.teardownIfCurrent(id, current); await d.tht.deleteSession(id, d.getSettings().workspace); d.hub.forget(id); return reply.code(204).send(); }); }); app.get("/sessions/:id/documents", async (req) => d.tht.documents((req.params as any).id)); }