docs(gateway): document scheduler ownership and timer census (#160477)

## What Problem This Solves

The Gateway architecture and cron documentation need to explain timer ownership, wake-after-sleep behavior, and shutdown joining after the scheduler cutovers.

## User Impact

Operators can distinguish a late wake in a running Gateway from cron's separate startup catch-up policy, and understand which work shutdown joins. This docs-only PR changes no runtime behavior or operator configuration.

## Why This Change Was Made

Document the kernel-owned `GatewayScheduler`, its single host timer, default replacement and `mode: "earliest"`, coalescing after sleep, and the `beginClose()` / `stop()` lifecycle. Durable deadlines and execution authority remain with their owners. Request/stream/process timers remain local, and SQLite WAL checkpoints remain storage-owned.

This PR also records the bounded timer census and the closeout's merge/proof evidence. The census is a baseline inventory, not a claim that all background plugin timers have moved to the kernel scheduler.

## Evidence

- Docs head: `4c23620461cd4d7a25f5df8b3856ab9265ec3a5c`, base `8b3f9bd1d6`. Cherry-picked only reviewed docs commit `522cf46835be9919a14c1b93f4a734c4b64ac720`; stable patch identity matches, exactly two docs pages. **Production +0/-0/net 0; tests +0/-0/net 0; docs +22/-0/net +22.**
- Independent exact-commit Codex autoreview: **scoped-clean through P2**, no accepted/actionable findings; reviewed the docs against the scheduler implementation.
- Exact-head docs sanity passed on Blacksmith Testbox lease `tbx_01m3m10xyr1gsv0bpgymeytt5f` ([lease run](https://github.com/openclaw/openclaw/actions/runs/36424356939)), using a clean detached checkout materialized from the Git bundle. `pnpm docs:list`: 0.11s; `node scripts/check-docs-mdx.mjs docs/automation/cron-jobs/how-it-works.md docs/concepts/architecture.md`: 0.24s, both pages passed; `pnpm docs:check-i18n-glossary --base 8b3f9bd1d6 --head 4c23620461cd4d7a25f5df8b3856ab9265ec3a5c`: 0.14s; `git diff --check`: passed. No tests added or changed; test cost is zero.
- Required `node scripts/check-changed.mjs --base 8b3f9bd1d6 -- docs/automation/cron-jobs/how-it-works.md docs/concepts/architecture.md`: **passed, 16.63s**. Dependency install took 6.22s.
- The broader `pnpm docs:check-links:anchors` reports **54 pre-existing broken links**: identical failure lines on this head (9.55s) and clean base `8b3f9bd1d6` (11.33s), with zero failures in the two changed pages and zero introduced failures. The new scheduler link and anchor are covered by that audit. Missing external ClawHub sources leave their unrelated fragments unverified.
- Merged-main live proof: **not yet run**. The intended proof is an isolated command cron job due in about 20 seconds, SIGSTOP past its due time then SIGCONT, followed by SIGTERM during a second job and a restart duplicate check. Replace this paragraph with observed evidence or link the final proof comment after the merged-main run.

### Closeout landings and accounting

Thirteen code/test PRs are merged with main ancestry verified. Four PRs remain parked with auto-merge disabled after bounded CI investigation; each PR body records its failure evidence and remaining uncertainty. Parked commits are excluded from merged LOC. Persistence-cache cleanup landed independently of activity summaries.

| Slice | PR | Merge SHA / parked head | Production +added/-deleted/net | Tests +added/-deleted/net |
|---|---|---|---:|---:|
| Node-presence dead handles | #160068 | `fa7c9bec6f` | +1/-9/-8 | +0/-1/-1 |
| Approval bootstrap | #160315 | `3903ccc777` | +29/-35/-6 | +133/-38/+95 |
| Skills refresh | #160318 | `df785c0971` | +18/-36/-18 | +102/-40/+62 |
| MCP dead timer options | #160326 | `a68299da6a` | +8/-23/-15 | +83/-107/-24 |
| Question deadlines/retention | #160334 | `b9f86cfbf3` | +89/-97/-8 | +211/-107/+104 |
| Restart sentinel | #160335 | `7f9528cbdb` | +72/-72/0 | +190/-116/+74 |
| Activity summaries | #160340 | PARKED; head `c32f2e9b9b` | Excluded | Excluded |
| Cron stream watchers | #160341 | `2aaf6d41a7` | +40/-37/+3 | +86/-0/+86 |
| Presence publication | #160369 | PARKED; head `8ee671f969a3140b9ad6ea6ac2be5b3eb89204d0` | Excluded | Excluded |
| Device-scope retention | #160370 | `ab2b206e20` | +27/-26/+1 | +46/-1/+45 |
| Companion dead options | #160371 | `31199f528f` | +2/-6/-4 | +0/-0/0 |
| Install-policy test clocks | #160372 | `fc168b2f6c` | +0/-0/0 | +10/-3/+7 |
| Node connection notices | #160374 | `7df73d3313` | +37/-55/-18 | +89/-45/+44 |
| Config reload/restart | #160375 | PARKED; head `238fa8cc96a000abafe82c86d49eb8aa496fcab7` | Excluded | Excluded |
| Cron exit watchers | #160381 | `ec1b2b4602` | +32/-26/+6 | +100/-37/+63 |
| Persistence cache | #160391 | `013a04798b` | +19/-15/+4 | +57/-35/+22 |
| TLS renewal | #160395 | PARKED; head `43edf9c8c6288730835d8b2e9cced5946d9f3637` | Excluded | Excluded |

LOC is cumulative first-parent merge-commit churn (`git diff-tree --numstat --no-renames`), not a moving-main snapshot. Production means `src/**` and `extensions/**` excluding basenames `*.test.ts`, `*.test-support.ts`, `test-helpers*`, and `*.test-utils.ts`. Tests and docs are separate; no production code is moved to tests or scripts to reduce the metric.

| Scope | Production +added/-deleted/net | Tests +added/-deleted/net | Docs +added/-deleted/net |
|---|---:|---:|---:|
| Prior scheduler stack (37 scheduler PRs, four requested repairs, four direct repairs) | +2562/-1495/+1067 | +7841/-3284/+4557 | +8/-0/+8 |
| This closeout: 13 merged code/test PRs | +374/-437/-63 | +1107/-530/+577 | +0/-0/0 |
| This closeout including this docs PR (docs merge pending) | +374/-437/-63 | +1107/-530/+577 | +22/-0/+22 |
| Grand scheduler stack, merged commits only | +2936/-1932/+1004 | +8948/-3814/+5134 | +8/-0/+8 |
| Grand scheduler stack including this docs PR (docs merge pending) | +2936/-1932/+1004 | +8948/-3814/+5134 | +30/-0/+30 |

The prior total excludes unrelated task-retirement PR #159179 and unrelated PR #159574. The closeout has **production net -63**, using actual merge SHAs. This unmerged docs PR adds exactly 22 docs lines and no production or test lines; the two labeled rows show that known addition separately. No parked candidate is counted.

### Merged-main live proof

**PENDING; no live result claimed.** Record the exact merged-main SHA, resolved provider, lease ID, commands, due/stop/resume/run/exit timestamps, receipt IDs and counts before/after restart, measured graceful shutdown wait, and process/socket cleanup. Include the observed build result and lease cleanup. Any missing part remains a stated gap.

### Follow-ups

The remaining census is 72 physical d sites: 67 structural follow-ups plus five timer sites in the four parked PRs (activity summaries, presence publication, TLS renewal, and two config reload/restart sites). Of the structural follow-ups, 49 plugin/channel sites need a supported service scheduling contract; 15 agent/cron sites need explicit ownership across Gateway, standalone, worker, or durable-repair lifetimes; three infra sites need host binding across Gateway/CLI/node-host uses. All four dead-plumbing groups have been removed in merged PRs. Reasons and baseline paths are recorded row by row below. No public scheduler SDK, schema, or durable write-custody contract is invented by this closeout.

## Timer census

Baseline: [`fb2487a903ab`](fb2487a903). All locations below refer to that baseline, not to shifted post-cutover lines. `G/` = `src/gateway/`, `I/` = `src/infra/`, `A/` = `src/agents/`, `C/` = `src/cron/`, `H/` = `src/channels/`, `P/` = `src/plugins/`, `X/` = `extensions/`.

**Baseline physical-site accounting:** a = 42 already migrated scheduler/owner registrations; b = 718 legitimately local operation/resource timers; c = 1 storage-owned WAL exception; d = 84 background-lifetime candidates. Total 845. The closeout migrated 12 of the 17 prepared baseline d sites (10 Gateway, approval bootstrap, question delivery retention). Four migrations remain parked, covering five Gateway sites: activity summaries, presence publication, TLS renewal, and config reload/restart. The remaining count is 72: 67 structural follow-ups (15 agents/cron, 49 extensions/channels, 3 infra) plus those five parked sites. This is not a count of final scheduler registrations: question expiry/retention combine, the device-result helper mixes local and retained work, and registrations can serve multiple logical jobs. Class e counts four dead-plumbing groups, not timer arms. All four groups were removed in merged PRs: node-presence handles, question-duration seams, MCP clock seams, and companion timer options. Merge evidence is in the landing table.

Counts are lexical arm/registration sites, not live timer instances. Native aliases, timer promises and event-loop yields are included. A clock adapter and its invocation count once. Shared timer helpers are counted at their implementation, not every caller. The infra audit conservatively also retains worker-owned timers, generated successor-helper timers and socket probe deadlines as b; these are expressly not Gateway maintenance. Test/bench/support fixtures, type declarations, imports, clears, non-timer `unref`, and `AbortSignal.timeout` are outside the primary denominator. CLI-only/generated-browser/generated-remote extension sites and Gateway socket-timeout settings are excluded here; their locations are recorded in the supplemental census. No new public scheduler SDK is introduced: plugin services currently have durable CronService operations, not `GatewayScheduler.schedule`.

| Class | Baseline sites (`file:lines`) | Reason / decision |
|---|---|---|
| a (1) | `G/auth-rate-limit.ts:171` | Authentication attempt pruning |
| a (1) | `G/channel-health-monitor.ts:315` | Channel health cadence |
| a (2) | `G/control-ui-session-pr-subscriptions.ts:321,507` | Subscription refresh delay and periodic PR polling |
| a (1) | `G/exec-approval-expiry.ts:48` | Approval expiry/retry deadlines |
| a (1) | `G/exec-approval-lifecycle.ts:510` | Terminal approval retention |
| a (2) | `G/github-oauth-lifecycle.ts:612,618` | System and personal OAuth maintenance |
| a (1) | `G/mention-inbox.ts:406` | Durable mention expiry/retry |
| a (1) | `G/server-cron.ts:1485` | System cron-job reconciliation retry |
| a (1) | `G/server-idle-task.ts:48` | Idle maintenance/prewarm retries, including startup handler prewarm |
| a (2) | `G/server-lifetime-sidecars.ts:78,99` | Secret expiry and GitHub publication maintenance |
| a (3) | `G/server-maintenance.ts:141,208,304` | Generic periodic maintenance, telemetry, and media maintenance registration sites; each helper creates multiple logical jobs |
| a (3) | `G/server-runtime-services.ts:110,298,346` | Post-ready maintenance and outbound/session delivery recovery |
| a (1) | `G/server-start.ts:108` | Post-ready work release deadline |
| a (1) | `G/server-startup-sidecar-scheduler.ts:73` | Generation deadline owner used by restart sentinel and startup sidecars |
| a (2) | `G/server-worker-placement-startup.ts:671,677` | Worker placement reconciliation and disk-space cadence |
| a (1) | `G/server/event-loop-health.ts:374` | Event-loop health sampling cadence |
| a (1) | `G/session-cold-storage-maintenance.ts:123` | Cold storage maintenance cadence |
| a (1) | `G/session-companion.ts:63` | Companion sweep cadence |
| a (1) | `G/session-incognito-lifetime.ts:61` | Incognito expiry deadline/retry |
| a (2) | `G/update-run-watcher.ts:50,126` | Schema-publication durable grace and detached update-run poll |
| a (1) | `G/worker-environments/service.ts:451` | Worker environment reconciliation cadence |
| a (1) | `I/gateway-scheduler.ts:34` | Canonical single host timer behind injected GatewayScheduler clock |
| a (2) | `I/session-delivery-queue-runtime.ts:53,86` | Migrated durable delivery scan/retry deadlines; required scheduler, earliest per-entry mode, joins admitted work on stop |
| a (1) | `I/update-campaign.ts:294` | Migrated campaign deadline via required GatewayScheduler; no raw timer remains |
| a (1) | `I/update-check-lifecycle.ts:58` | Migrated update/catalog check arming via required scheduler and lifecycle-owned joins |
| a (2) | `I/update-startup.ts:739,747` | Delegates periodic update/catalog checks to migrated UpdateCheckLifecycle schedule wrapper |
| a (1) | `A/agent-bundle-mcp-manager-lifecycle.ts:346` | MCP idle runtime sweep; required injected scheduler with stopped-lifecycle selection |
| a (1) | `C/maintenance-scheduler.ts:49` | Cron periodic maintenance; scheduler run returns admitted sweep completion and shutdown joins it |
| a (1) | `C/service/timer-scheduler.ts:119` | Cron due/recheck scheduling; cron owns durable job state and execution |
| a (1) | `C/service/foreign-receipt-monitor.ts:32` | Foreign receipt recovery polling; cron service owns cancellation and store reconciliation |
| a (1) | `P/plugin-source-capture-directory.ts:575` | Explicit Gateway metadata-owner maintenance; one scheduler job, recurring grace sweep; migrated in c6d17f6dfe (#158959) |
| d (1) | `G/config-reload.ts:357` | Config-source reload coalescing/lease retry; parked in #160375 at repaired head `238fa8cc96a0` after bounded CI investigation; auto-merge disabled, details in that PR body. |
| d (1) | `G/cron-exit-watchers.ts:211` | Durable exit-watcher retry; Migrated in #160381. |
| d (2) | `G/cron-stream-job-owner.ts:419,602` | Durable source restart and stable-run reset; Migrated in #160341. |
| d (1) | `G/device-scope-upgrade.ts:34` | Detached result retention; shared baseline helper also served awaited reconciliation; Migrated in #160370. |
| d (1) | `G/node-connection-notifications.ts:215` | First-connection alert routing; Migrated in #160374. |
| d (2) | `G/question-manager.ts:164,527` | Question expiry and terminal retention; Migrated in #160334. |
| d (1) | `G/server-reload-restart.ts:329` | Detached restart-emission retry; parked in #160375 at repaired head `238fa8cc96a0` after bounded CI investigation; auto-merge disabled, details in that PR body. |
| d (1) | `G/server-restart-sentinel.ts:435` | Pending control-plane update retry; Migrated in #160335. |
| d (1) | `G/server-startup-early.ts:135` | Skills-change coalescing/remote-bin refresh; Migrated in #160318. |
| d (1) | `G/server-tls-renewal.ts:40` | Accepted-certificate refresh debounce; parked in #160395. The original UI shard passed on clean baseline (80 files, 359 tests), leaving the old failure unclassified; details and source/UI proof gap are recorded in that PR body. |
| d (1) | `G/server/presence-events.ts:21` | Presence publication windows; parked in #160369 after bounded CI/baseline investigation; auto-merge disabled, details in that PR body. |
| d (1) | `G/session-activity-summaries.ts:556` | Background recap queue cooldown; parked in #160340 after bounded CI/baseline investigation; auto-merge disabled, details in that PR body. |
| d (1) | `G/session-lifecycle-persistence-owner.ts:133` | Retained terminal-write cache grace; Migrated in #160391. |
| d (1) | `I/approval-handler-bootstrap.ts:133` | Handler bootstrap retry; Migrated in #160315. |
| d (1) | `I/net/pinned-dispatcher-pool.ts:135` | Deferred: Idle eviction; shared Gateway/CLI singleton needs explicit host binding. |
| d (1) | `I/question-channel-runtime-internal.ts:139` | Terminal delivery retention; Migrated in #160334. |
| d (1) | `I/session-event-wake.ts:478` | Deferred: Cross-call wake/retry queue; embedded/SDK handler-generation binding and monotonic ordering need one owner. |
| d (1) | `I/terminal-file-upload.ts:122` | Deferred: Retained upload expiry/retry; both Gateway and node-host lifecycles must supply ownership. |
| d (1) | `A/bash-process-registry.ts:518` | Deferred: Finished-exec retention; global Gateway/standalone cache lacks host ownership and takeover/retirement. |
| d (1) | `A/code-mode-node.ts:141` | Deferred: Warm worker retirement; standalone/headless executor lacks host scheduler/stop owner. |
| d (1) | `A/code-mode-state.ts:276` | Deferred: Parked-cell expiry; required host binding must cover Gateway and standalone/headless callers. |
| d (1) | `A/main-session-recovery/main-session-recovery-lifecycle.ts:50` | Deferred: Durable repair can outlive its Gateway generation; define transfer/join for Gateway and standalone write custody. |
| d (1) | `A/mcp-ui-resource.ts:308` | Deferred: MCP view TTL retains a lease across calls; public preview/runtime has no scheduler capability or internal host owner. |
| d (1) | `A/provider-local-service.ts:482` | Deferred: Provider idle retirement; shared CLI/Gateway shutdown owner must receive host scheduler. |
| d (7) | `A/subagents/registry/subagent-registry-completion-runtime.ts:82`; `A/subagents/registry/subagent-registry-lifecycle-cleanup.ts:68`; `A/subagents/registry/subagent-registry-lifecycle-wake.ts:377`; `A/subagents/registry/subagent-registry-restore.ts:130`; `A/subagents/registry/subagent-registry-run-wait.ts:244`; `A/subagents/registry/subagent-registry-sweeper.ts:117`; `A/subagents/registry/subagent-registry.ts:201` | Deferred: global subagent registry retries/sweep; startup hydration precedes instance activation, standalone uses remain, and detached callbacks lack stop/join. Define host binding, row takeover and returning callbacks together. |
| d (1) | `A/subagents/swarm/swarm-scheduler.ts:172` | Deferred: Queued-launch retry; restored registry activation lacks lifecycle binding. Preserve FIFO reservations and existing joins. |
| d (1) | `C/store/run-receipt-settlement.ts:158` | Deferred: Durable receipt retry must retain write custody after cron stop; define settlement/close order for standalone/workers too. |
| d (1) | `X/beam/src/mirror.ts:612` | Deferred: Beam service catalog polling; service SDK lifecycle binding required. |
| d (1) | `X/beam/src/store.ts:114` | Deferred: Beam service cross-process SQLite inventory reconciliation; service SDK lifecycle binding required. |
| d (2) | `X/browser/src/browser-proxy-upload.ts:292,351` | Deferred: Browser service retained-upload cleanup and recovery retry beyond the originating request; service SDK lifecycle binding required. |
| d (1) | `X/browser/src/browser/session-tab-cleanup.ts:56` | Deferred: Browser service recurring tracked-tab retention sweep; service SDK lifecycle binding required. |
| d (1) | `X/buzz/src/buzz-bus.ts:148` | Deferred: Buzz account presence publication heartbeat; service SDK lifecycle binding required. |
| d (1) | `X/clickclack/src/discussions/reconcile-scheduler.ts:66` | Deferred: Discussion service event coalescing and retry queue, joined by its service owner; service SDK lifecycle binding required. |
| d (1) | `X/clickclack/src/discussions/service.ts:649` | Deferred: Discussion service durable ambiguous-create reconciliation; service SDK lifecycle binding required. |
| d (1) | `X/codex/src/app-server/desktop-generation.ts:213` | Deferred: Plugin desktop-generation filesystem watcher recovery; service SDK lifecycle binding required. |
| d (3) | `X/codex/src/session-catalog-currency.ts:65,125,166` | Deferred: Plugin catalog owner background hydration and native/file reconciliation; service SDK lifecycle binding required. |
| d (1) | `X/device-pair/notify.ts:479` | Deferred: Device-pair service background approval notification polling; service SDK lifecycle binding required. |
| d (1) | `X/discord/src/monitor/auto-presence.ts:231` | Deferred: Discord account service recurring presence evaluation; service SDK lifecycle binding required. |
| d (1) | `X/discord/src/monitor/thread-bindings.manager.ts:621` | Deferred: Discord account binding expiry sweep; service SDK lifecycle binding required. |
| d (1) | `X/discord/src/voice/voice-following.ts:305` | Deferred: Discord account voice-following service reconciliation; service SDK lifecycle binding required. |
| d (2) | `X/facetime/src/helper-supervisor.ts:199,209` | Deferred: FaceTime service helper injection and stale-process reconciliation; service SDK lifecycle binding required. |
| d (1) | `X/imap/src/watcher.ts:169` | Deferred: IMAP account message sweep and durable rejected-admission reconciliation; service SDK lifecycle binding required. |
| d (2) | `X/imessage/src/monitor/monitor-provider.ts:1611,1614` | Deferred: iMessage account approval-reaction polling and discovery; service SDK lifecycle binding required. |
| d (3) | `X/logbook/src/service.ts:123,127,131` | Deferred: Logbook service capture, analysis, and retention polling; service SDK lifecycle binding required. |
| d (1) | `X/matrix/src/matrix/client/file-sync-store.ts:209` | Deferred: Matrix account sync-cache persistence debounce outlives a receive call; service SDK lifecycle binding required. |
| d (1) | `X/matrix/src/matrix/sdk/client-base.ts:701` | Deferred: Matrix account periodic IndexedDB crypto snapshot persistence (not a WAL checkpoint); service SDK lifecycle binding required. |
| d (2) | `X/matrix/src/matrix/thread-bindings.ts:392,650` | Deferred: Matrix account binding delayed persistence and expiry sweep; service SDK lifecycle binding required. |
| d (2) | `X/memory-core/src/dreaming.ts:453,521` | Deferred: Memory service cron reconciliation and deferred interrupted-run cleanup; service SDK lifecycle binding required. |
| d (1) | `X/memory-core/src/memory/manager-session-sync-ops.ts:299` | Deferred: Memory manager background session-update batching; service SDK lifecycle binding required. |
| d (1) | `X/memory-core/src/memory/manager-watch-ops.ts:122` | Deferred: Memory manager periodic background index sync; service SDK lifecycle binding required. |
| d (2) | `X/memory-core/src/memory/manager-watch-resources.ts:90,262` | Deferred: Memory watcher startup diagnostics and file-change settling; service SDK lifecycle binding required. |
| d (1) | `X/nostr/src/nostr-cursor.ts:143` | Deferred: Nostr account durable cursor persistence debounce across receive calls; service SDK lifecycle binding required. |
| d (1) | `X/reef/src/owner-notice.ts:57` | Deferred: Reef service durable rejection-notice delivery retries; service SDK lifecycle binding required. |
| d (1) | `X/slack/src/monitor/presence-monitor.ts:437` | Deferred: Slack account presence polling service; service SDK lifecycle binding required. |
| d (1) | `X/team-reports/src/scheduler.ts:194` | Deferred: Team Reports service recurring report/catch-up scheduling; service SDK lifecycle binding required. |
| d (1) | `X/telegram/src/thread-bindings.ts:517` | Deferred: Telegram account binding expiry sweep; service SDK lifecycle binding required. |
| d (1) | `X/tlon/src/monitor/index.ts:1361` | Deferred: Tlon account channel discovery and polling service; service SDK lifecycle binding required. |
| d (1) | `X/visitor-access/index.ts:99` | Deferred: Visitor-access service retention sweep; service SDK lifecycle binding required. |
| d (1) | `X/visitor-access/src/visitors.ts:215` | Deferred: Visitor-access service grant expiry queue and revocation; service SDK lifecycle binding required. |
| d (1) | `X/voice-call/src/webhook/stale-call-reaper.ts:31` | Deferred: Voice Call service stale-call sweep; service SDK lifecycle binding required. |
| d (1) | `X/whatsapp/src/auto-reply/monitor.ts:510` | Deferred: WhatsApp account pending-delivery reconciliation polling; service SDK lifecycle binding required. |
| d (1) | `X/whatsapp/src/directory-config.ts:170` | Deferred: Account cleanup custody retries after originating call; service SDK lifecycle binding required. |
| d (1) | `X/workboard/src/automation-nudge.ts:111` | Deferred: Workboard service pending-nudge expiry queue; service SDK lifecycle binding required. |
| d (1) | `X/workboard/src/change-events.ts:44` | Deferred: Workboard service cross-process store-change polling; service SDK lifecycle binding required. |
| d (1) | `X/workboard/src/lifecycle-sync.ts:553` | Deferred: Workboard service recurring lifecycle recovery; service SDK lifecycle binding required. |
| d (1) | `H/message/ingress-monitor.ts:725` | Deferred: Shared SDK-exposed ingress monitor periodic drain/retry/retention trigger; service SDK lifecycle binding required. |
| c (1) | `I/sqlite-wal.ts:617` | Explicit storage-owner exception: handle-owned WAL checkpoint/identity admission timer |
| b (138) | `X/a2a/src/task-store.ts:123`; `X/codex/src/app-server/computer-use-health.ts:49`; `X/discord/src/internal/rest-scheduler.ts:380`; `X/facetime/src/runtime.ts:203,547`; `X/line/src/inbound-image-set.ts:202,231,247`; `X/matrix/src/matrix/sdk/client-base.ts:407`; `X/msteams/src/pending-uploads.ts:54`; `X/team-reports/src/scheduler.ts:176,298`; `X/telegram/src/bot-handlers.inbound-media.ts:503,517`; `X/telegram/src/bot/delivery.resolve-media.ts:120`; `X/telegram/src/client-fetch.ts:127`; `X/telegram/src/polling-lease.ts:77`; `X/telegram/src/telegram-ingress-worker.runtime.ts:130`; `X/telegram/src/telegram-ingress-worker.ts:89`; `X/telegram/src/webhook.ts:84`; `A/agent-bundle-mcp-runtime.ts:564`; `A/auth-profiles/oauth-refresh-fence.ts:378`; `A/bash-tools.exec-run.ts:683`; `A/cli-runner/execute-plugin.ts:402`; `A/code-mode-bridge.ts:435`; `A/code-mode-deadline.ts:21`; `A/code-mode-execution.ts:220`; `A/code-mode-headless.ts:66`; `A/code-mode-node.ts:234,320`; `A/command/maintenance-budget.ts:28`; `A/embedded-agent-runner/openrouter-model-capabilities.ts:149`; `A/embedded-agent-runner/run/attempt-queue-message.ts:219`; `A/embedded-agent-runner/run/attempt-timeout-prepare.ts:64,91`; `A/exec-auto-reviewer.ts:374`; `A/harness/attempt-deadlines.ts:37`; `A/harness/native-hook-relay-bridge.ts:260`; `A/harness/native-hook-relay.ts:133`; `A/main-session-recovery/main-session-restart-dispatch-start.ts:99`; `A/mcp-connection-resolver.ts:75`; `A/mcp-pagination.ts:79`; `A/models-config.providers.implicit.ts:366`; `A/prepared-model-catalog-worker.ts:551`; `A/prepared-model-runtime.catalog-access.ts:669`; `A/prepared-model-runtime.startup.ts:60`; `A/run-cleanup-timeout.ts:180`; `A/runtime/proxy.ts:164,218`; `A/subagents/announce/subagent-announce-capture.ts:32`; `A/subagents/announce/subagent-announce-completion-delivery.ts:74`; `A/subagents/completion/session-followup-completion.ts:275`; `A/subagents/registry/subagent-registry-lifecycle-announce-cleanup.ts:624`; `A/subagents/registry/subagent-registry-pending-lifecycle.ts:49`; `A/tools/subagents-tool.ts:209`; `C/active-jobs.ts:494`; `C/service/agent-watchdog.ts:87,103,122,162,233`; `G/agent-turn/agent-handler-helpers.ts:197`; `G/auth-rate-limit.ts:304`; `G/call.ts:895`; `G/channel-health-monitor.ts:291`; `G/cron-stream-job-owner.ts:111,346`; `G/desktop/managed-linux-audio.ts:110,162`; `G/desktop/rfb-preauth.ts:408`; `G/desktop/rfb-probe.ts:191`; `G/github-oauth-lifecycle.ts:655`; `G/local-http-probe.ts:110`; `G/mcp-http.loopback-runtime.ts:291`; `G/model-account-connect.ts:292`; `G/net.ts:349`; `G/node-registry.ts:961`; `G/openresponses-http.ts:753`; `G/provider-browser-auth.ts:112`; `G/server-discovery-runtime.ts:236`; `G/server-in-process-dispatch.ts:109`; `G/server-methods/channels.ts:129`; `G/server-methods/session-catalog-list-operations.ts:181`; `G/server-methods/session-discussion.ts:70`; `G/server-methods/tools-effective.ts:217`; `G/server-runtime-services.ts:316`; `G/server/connection-transport-close.ts:28`; `G/server/connection.ts:240`; `G/server/hooks-request-handler-response.ts:29`; `G/server/hooks.ts:489`; `G/server/ws-connection/node-lifecycle-dispatch.ts:44`; `G/server/ws-connection/worker-connection.ts:233`; `G/session-activity-summaries.ts:357`; `G/session-companion-ask.ts:517`; `G/session-observer-completion.ts:47`; `G/session-reset-acp.ts:25`; `G/system-ca-warmup.ts:138`; `G/terminal/open-deadline.ts:43`; `G/worker-environments/artifact-transfer-service.ts:111`; `G/worker-environments/node-launch-adapter.ts:232,323`; `G/worker-environments/worker-turn-launcher.ts:481`; `G/worker-environments/workspace-sync-helpers.ts:64`; `I/acquire-with-wait.ts:26`; `I/approval-native-route-coordinator.ts:180,229`; `I/diagnostic-events.ts:1243,1295`; `I/embedded-plugin-approval-broker.ts:64`; `I/http-request-lifecycle.ts:200`; `I/http-response-body-timeout.ts:53`; `I/jsonl-socket.ts:54`; `I/net/ssrf.ts:748`; `I/oauth-loopback-callback.ts:316`; `I/ports-probe.ts:90`; `I/provider-usage.shared.ts:93`; `I/push-apns-http2.ts:143,282`; `I/push-apns.ts:216`; `I/shell-env.ts:176`; `I/sqlite-backup.ts:10`; `I/sqlite-readonly-worker.ts:464`; `I/sqlite-wal-write-admission.ts:89`; `I/sqlite-worker-broker.ts:578`; `I/update-candidate-canary-process.ts:148`; `I/update-repair-agent.runtime.ts:342`; `I/update-repair-agent.ts:108,157`; `I/update-repair-inference.ts:38`; `I/worker-task-pool-core.ts:532`; `P/conversation-binding-pending.ts:47`; `P/hook-timeout.ts:13`; `P/host-hook-runtime.ts:119`; `P/plugin-instance.ts:564,625,722`; `P/runtime/runtime-llm-isolated.ts:144`; `P/services.ts:230` | Retain: one request, run, transfer or registration deadline/wait; released at settlement/disposal. |
| b (23) | `X/active-memory/recall-state.ts:79`; `X/crabbox/src/crabbox-worker-heartbeat.ts:46`; `X/reef/protocol/pipeline.ts:175`; `A/embedded-agent-runner/run/lane-controller.ts:171`; `A/harness/native-session/binding-leases.ts:202,372`; `A/worktrees/run-lease.ts:195`; `H/message/ingress-drain.ts:209,283`; `G/agent-turn/agent-handler-helpers.ts:203`; `G/desktop/session-registry.ts:201,423`; `G/server-chat-live-text.ts:178`; `G/sessions-history-http.ts:503`; `G/talk/relay/session-create.ts:642`; `G/worker-environments/placement-turn-claims.ts:442`; `I/clawhub-client.ts:233`; `I/outbound/delivery-queue-lease.ts:51,79`; `I/outbound/delivery-queue-migration.ts:191`; `I/outbound/delivery-queue-preparation.ts:76`; `I/session-cost-usage-reporting.ts:139`; `I/state-migrations.transcript-directives-archives.ts:410` | Retain: one claim, lease, request or operation owns renewal/deadline and settlement. |
| b (130) | `X/active-memory/transcript-watch.ts:142`; `X/agentsapi/agentsapi-client.ts:505`; `X/agentsapi/agentsapi-session.ts:249,547,579`; `X/discord/src/activities/interaction.ts:74`; `X/discord/src/activities/shell.ts:71`; `X/discord/src/api.ts:171`; `X/discord/src/internal/event-queue.ts:172`; `X/discord/src/internal/gateway-identify-limiter.ts:37`; `X/discord/src/internal/rest.ts:250`; `X/discord/src/monitor/message-media.ts:275`; `X/discord/src/monitor/native-command-model-picker-apply.ts:78`; `X/discord/src/monitor/provider.lifecycle.ts:107,126,202,204,314`; `X/discord/src/monitor/timeouts.ts:76,105,126`; `X/feishu/src/setup-surface.ts:314`; `X/github-copilot/login.ts:264`; `X/imap/src/watcher.ts:219`; `X/imessage/src/monitor/monitor-provider.ts:315`; `X/irc/src/monitor.ts:141`; `X/matrix/src/matrix/actions/verification.ts:150,187`; `X/matrix/src/matrix/client/shared.ts:350`; `X/matrix/src/matrix/monitor/verification-events.ts:268`; `X/matrix/src/matrix/sdk/client-support.ts:93`; `X/matrix/src/matrix/sdk/client-sync-quiesce.ts:95`; `X/matrix/src/matrix/sdk/client-sync-ready.ts:91`; `X/matrix/src/matrix/sdk/crypto-bootstrap.ts:192`; `X/matrix/src/matrix/sdk/decrypt-bridge.ts:231,359`; `X/matrix/src/matrix/sdk/verification-manager.ts:463`; `X/mattermost/src/mattermost/client.ts:552`; `X/mattermost/src/mattermost/monitor-thread-backfill.ts:256`; `X/mattermost/src/mattermost/monitor-websocket.ts:202,227,237,329`; `X/mattermost/src/mattermost/reconnect.ts:97`; `X/mattermost/src/mattermost/slash-http.ts:158`; `X/minimax/oauth.ts:349,361`; `X/ollama/src/setup-pull.ts:35,60`; `X/openai/openai-chatgpt-device-code.ts:443,448`; `X/openai/openai-chatgpt-oauth-flow.runtime.ts:45`; `X/openai/openai-chatgpt-oauth.runtime.ts:59`; `X/openai/realtime-session-retirement.ts:107,144`; `X/signal/src/client-container.ts:87,223,497`; `X/signal/src/client-unix.ts:51`; `X/signal/src/client.ts:142,197,296`; `X/signal/src/daemon.ts:292`; `X/signal/src/monitor/event-handler.ts:720`; `X/signal/src/socket-path.ts:112`; `X/team-reports/src/sources/discord/client.ts:28`; `X/telegram/src/draft-stream.ts:809`; `X/tlon/src/monitor/approval-runtime.ts:258`; `X/whatsapp/src/connection-owner.ts:57,96`; `X/whatsapp/src/creds-persistence.ts:80`; `X/whatsapp/src/inbound/message-delivery.ts:633`; `X/whatsapp/src/login-qr.ts:272,356,572`; `X/whatsapp/src/login.ts:57`; `X/whatsapp/src/session.ts:469`; `X/whatsapp/src/socket-close.ts:11`; `X/whatsapp/src/socket-timing.ts:110`; `X/xai/xai-oauth.ts:499,508`; `A/bash-tools.exec-approval-followup.ts:284`; `A/bash-tools.process.ts:258`; `A/cli-runner.ts:102`; `A/cli-runner/cli-run-settlement.ts:46`; `A/embedded-agent-runner/run/abortable.ts:63`; `A/embedded-agent-runner/run/auth-controller.ts:343,353`; `A/embedded-agent-runner/run/compaction-retry-aggregate-timeout.ts:39`; `A/harness/native-hook-relay-client.ts:220`; `A/mcp-http-transport.ts:291,350`; `A/run-wait.ts:271,317`; `A/sandbox/browser.ts:92,113`; `A/subagents/announce/subagent-announce-delivery-retry.ts:206,214`; `A/subagents/announce/subagent-announce-output.ts:450`; `A/subagents/spawn/subagent-spawn-cleanup.ts:156`; `A/subagents/spawn/subagent-spawn-gateway.ts:232`; `A/tools/ask-user-tool.ts:202,245,332`; `A/tools/sessions-tool.ts:658`; `A/workspace.ts:623`; `A/worktrees/checkout-apfs.ts:143,172`; `H/plugins/binding-routing.ts:303`; `G/agent-turn/agent-job.ts:301,723`; `G/desktop/observe-bridge.ts:301`; `G/probe.ts:411`; `G/server-methods/nodes.wake.ts:70`; `G/server-reload-active-work.ts:99`; `G/server-restart-sentinel-notice.ts:266`; `G/server-restart-sentinel.ts:133`; `G/server-startup-post-attach.ts:124,316,851`; `G/worker-environments/node-enrollment.ts:318`; `I/embedded-state-lock.ts:23`; `I/package-lifecycle.ts:256`; `I/session-cost-usage-cache-runtime.ts:290`; `I/sqlite-transaction.ts:528`; `I/ssh-tunnel.ts:218`; `I/state-migrations.audit-backup.ts:236`; `I/tailscale-backend-ready.ts:85`; `I/update-candidate-canary-readiness.ts:216`; `I/update-failure-report-precreate.ts:35` | Retain: retry/readiness/delay belongs to one operation, request or transport lifecycle. |
| b (169) | `X/active-memory/recall-run.ts:78`; `X/active-memory/recall.ts:289`; `X/active-memory/transcript-result.ts:144`; `X/active-memory/transcript.ts:170`; `X/anthropic/cli-process.ts:135`; `X/anthropic/cli-transport.ts:61,88`; `X/browser/src/browser/pw-session-cdp-transport.ts:75,133,167`; `X/buzz/src/directory-relay.ts:183`; `X/buzz/src/relay-auth.ts:153,202`; `X/buzz/src/relay-subscription.ts:125`; `X/buzz/src/room-membership-tracker.ts:48,375`; `X/clickclack/src/http-client.ts:173`; `X/codex/src/app-server/attempt-steering.ts:370`; `X/codex/src/app-server/attempt-timeouts.ts:70`; `X/codex/src/app-server/bounded-turn.ts:235`; `X/codex/src/app-server/client.ts:614`; `X/codex/src/app-server/compact-lifecycle.ts:117,136`; `X/codex/src/app-server/computer-use.ts:946`; `X/codex/src/app-server/connection-health.ts:194`; `X/codex/src/app-server/desktop-generation-owner.ts:83`; `X/codex/src/app-server/dynamic-tool-execution.ts:303`; `X/codex/src/app-server/ephemeral-turn.ts:125`; `X/codex/src/app-server/event-projector-tool-transcript.ts:481`; `X/codex/src/app-server/inference-proxy.ts:461,558`; `X/codex/src/app-server/native-config-fence.ts:82`; `X/codex/src/app-server/native-hook-relay.ts:128`; `X/codex/src/app-server/request-attempt.ts:175`; `X/codex/src/app-server/request.ts:276`; `X/codex/src/app-server/run-attempt-lifecycle-controller.ts:82`; `X/codex/src/app-server/run-attempt-settlement.ts:30`; `X/codex/src/app-server/sandbox-exec-server/sandbox-child.ts:163,278`; `X/codex/src/app-server/server-requests.ts:86`; `X/codex/src/app-server/transport-process-containment.ts:68,166`; `X/codex/src/app-server/transport-process-snapshot.ts:143,228`; `X/codex/src/app-server/transport-websocket.ts:80,107`; `X/codex/src/app-server/transport.ts:110,207`; `X/codex/src/app-server/turn-router.ts:272`; `X/codex/src/conversation-turn-collector.ts:130`; `X/codex/src/migration/session-binding-orphans.ts:136`; `X/codex/src/session-catalog-homes.ts:136,145,167,255`; `X/codex/src/session-catalog-index-state.ts:264`; `X/codex/src/session-catalog-index.ts:535`; `X/codex/src/session-catalog-list-operation.ts:85`; `X/codex/src/session-catalog-native-page.ts:63`; `X/codex/src/session-catalog-rollouts.ts:302`; `X/codex/src/session-rollout-snapshot.ts:99`; `X/comfy/workflow-runtime.ts:497`; `X/crabbox/src/crabbox-worker-provider.ts:105`; `X/fal/video-generation-provider.ts:527`; `X/feishu/src/async.ts:34,103`; `X/feishu/src/media-chunk-idle.ts:37`; `X/feishu/src/sequential-queue.ts:44`; `X/github-copilot/models.ts:317`; `X/google-meet/src/voice-call-gateway.ts:34`; `X/google/transport-stream.ts:715`; `X/google/video-generation-provider.ts:319`; `X/imessage/src/approval-handler.runtime.ts:253`; `X/imessage/src/client.ts:275,346`; `X/line/src/download.ts:113,169`; `X/line/src/webhook-spool.ts:103`; `X/lobster/src/lobster-runner.ts:206`; `X/memory-core/src/dreaming-state.ts:150,157,193`; `X/memory-core/src/memory-corpus.ts:131`; `X/memory-core/src/memory/manager-database-context.ts:347`; `X/memory-core/src/memory/manager-embedding-ops.ts:210,381`; `X/memory-core/src/memory/manager-search-knn-subprocess.ts:344,405`; `X/memory-core/src/memory/manager-search-vector.ts:153`; `X/memory-core/src/memory/manager-source-sync-ops.ts:51`; `X/memory-core/src/memory/search-deadline.ts:56`; `X/memory-lancedb/embeddings.ts:372,435`; `X/memory-lancedb/lancedb-store.ts:96`; `X/memory-wiki/src/compile.ts:402`; `X/minimax/tts.ts:68`; `X/msteams/src/msteams-ingress.ts:250`; `X/nostr/src/nostr-profile-import.ts:112`; `X/nostr/src/nostr-profile.ts:44`; `X/nostr/src/nostr-relay-subscription.ts:52`; `X/ollama/src/stream.runtime.ts:115`; `X/opencode-go/stream-termination.ts:175`; `X/openrouter/music-generation-provider.ts:225`; `X/reef/protocol/guard.ts:117`; `X/reef/src/audit-state.ts:175`; `X/slack/src/client.ts:74`; `X/slack/src/monitor/media.ts:167`; `X/slack/src/monitor/provider-support.ts:103`; `X/synology-chat/src/client.ts:288,465`; `X/synology-chat/src/outbound-media.ts:126`; `X/team-reports/src/sources/github/client.ts:90`; `X/team-reports/src/sources/http.ts:35`; `X/tlon/src/urbit/sse-client.ts:210`; `X/twitch/src/probe.ts:82`; `X/twitch/src/twitch-client.ts:287`; `X/vault/vault-secret-ref-resolver.js:195`; `X/xai/tts.ts:242,260`; `X/xiaomi/speech-provider.ts:228`; `X/zai/detect.ts:83`; `X/zalo/src/api.ts:154`; `X/zalo/src/monitor.ts:249`; `X/zalouser/src/zalo-js.ts:1428,1432`; `A/code-mode-node.worker.ts:380`; `A/context-cache-projection.ts:156`; `A/embedded-agent-runner/run/attempt-preparation.ts:25`; `A/embedded-agent-runner/runs.ts:1273,1380`; `A/harness/gateway-question.ts:488,658`; `A/prepared-model-runtime.build.ts:229,293,330,363,425`; `A/prepared-model-runtime.facts.ts:261,378,415,606`; `A/queued-file-writer.ts:75`; `A/tools/agents-wait-tool.ts:259,271,277`; `A/worktrees/filesystem-backend.ts:37`; `C/heartbeat-monitor.ts:177`; `G/cli-session-history.claude-snapshot.ts:188,231,266`; `G/server-channel-startup.ts:7`; `G/server-channels.ts:1444`; `G/server-cron-skill-review-jobs.ts:38,55,76`; `G/server-kernel.ts:228`; `G/server-methods/sessions-files.ts:238`; `G/server-methods/sessions-read.ts:337`; `G/server-methods/tts.ts:42`; `G/server-startup-observers.ts:39`; `G/server-startup-sidecar-scheduler.ts:31`; `G/server-startup-update-check.ts:99,152`; `G/server/ws-connection/request-start.ts:49`; `G/session-event-prepared-row.ts:36,55`; `G/session-projection-work.ts:10`; `I/session-cost-usage-worker-runtime.ts:428`; `I/state-migrations.transcript-directives.ts:331` | Retain: operation-scoped deadlines/backoff or cooperative event-loop dispatch; no maintenance cadence. |
| b (98) | `X/clickclack/src/activity.ts:209`; `X/clickclack/src/progress.ts:205,220`; `X/deepgram/audio-flux.ts:327`; `X/deepgram/realtime-transcription-provider-factory.ts:320`; `X/discord/src/internal/gateway-rate-limit.ts:110`; `X/discord/src/voice/audio-transport.ts:234`; `X/discord/src/voice/audio-worker.ts:400,517`; `X/discord/src/voice/audio.ts:197`; `X/discord/src/voice/capture-state.ts:96`; `X/discord/src/voice/realtime-output.runtime.ts:127,399,466`; `X/discord/src/voice/realtime-session.runtime.ts:76`; `X/discord/src/voice/transcripts-source.ts:344`; `X/facetime/src/audio-pump.ts:187,200,322,330,464`; `X/facetime/src/helper-rpc.ts:237,623`; `X/facetime/src/runtime-call-control.ts:260,294,324`; `X/facetime/src/runtime-helper-results.ts:193`; `X/facetime/src/talk-driver.ts:402`; `X/facetime/src/talk-initial-greeting.ts:33`; `X/feishu/src/streaming-card.ts:470`; `X/google/realtime-voice-provider.ts:1218`; `X/openai/realtime-live-delegation-queue.ts:36`; `X/openai/realtime-quicksilver-audio-buffer.ts:87`; `X/openai/realtime-quicksilver-bridge.ts:233`; `X/openai/realtime-quicksilver-gateway-bridge.ts:543`; `X/openai/realtime-quicksilver-media.runtime.ts:401`; `X/openai/realtime-quicksilver-peer.runtime.ts:180`; `X/openai/realtime-quicksilver-protocol.ts:95`; `X/openai/realtime-quicksilver-session.ts:254`; `X/openai/realtime-quicksilver-sideband.ts:96`; `X/openai/realtime-quicksilver-socket.ts:171`; `X/openai/realtime-quicksilver-socket.worker.ts:43`; `X/voice-call/src/gateway-continue-operation.ts:63`; `X/voice-call/src/manager/outbound.ts:466`; `X/voice-call/src/manager/timers.ts:53,136`; `X/voice-call/src/media-stream.ts:554,681`; `X/voice-call/src/providers/twilio.ts:667,681`; `X/voice-call/src/tunnel.ts:48,49,137`; `X/voice-call/src/webhook/realtime-audio-pacer.ts:325`; `X/voice-call/src/webhook/realtime-handler.ts:704,1526,1530,1652,1834,1974`; `X/voice-call/src/webhook/stream-disconnect-grace.ts:38`; `X/xai/realtime-voice-events.ts:380`; `A/command/attempt-execution.helpers.ts:157`; `A/embedded-agent-runner/run/attempt-transcript-lifecycle.ts:153`; `A/embedded-agent-runner/run/attempt.model-diagnostic-events.ts:41`; `A/embedded-agent-runner/wait-for-idle-before-flush.ts:42`; `A/mcp-transport.ts:77`; `A/tools/common.ts:445`; `H/draft-stream-loop.ts:125`; `H/progress-draft-compositor.ts:290`; `H/status-reactions.ts:245,271,275,343`; `H/streaming.ts:661`; `H/typing.ts:79`; `G/cron-stream-output.ts:85,477,659`; `G/node-registry.invoke-stream.ts:336`; `G/server-methods/session-change-event.ts:471,496`; `G/server-methods/session-typing-state.ts:117,152`; `G/session-observer-preamble.ts:113`; `G/session-observer.ts:293,446`; `G/session-row-projection-transcript.ts:24`; `G/talk/relay/cancellation-deadline.ts:17,32`; `G/talk/relay/voice.ts:66`; `G/talk/voice-selection.ts:309`; `G/terminal/output-coalescer.ts:76`; `G/terminal/output-flow-control.ts:135`; `G/worker-environments/workspace-sync-helpers.ts:435`; `I/diagnostics-timeline.ts:151`; `I/http-body.ts:176,343` | Retain: one work item/stream/session update, pacing or settlement window; canceled with that work. |
| b (85) | `X/acpx/src/harness-attempt.ts:101`; `X/acpx/src/process-reaper.ts:294`; `X/acpx/src/service.ts:173`; `X/browser/src/browser/cdp-page-session.ts:134`; `X/browser/src/browser/cdp-websocket.ts:191`; `X/browser/src/browser/cdp.helpers.ts:489`; `X/browser/src/browser/chrome-mcp-connect.ts:38,159`; `X/browser/src/browser/chrome-mcp-process.ts:279,295,318`; `X/browser/src/browser/chrome-mcp-routing.ts:98`; `X/browser/src/browser/chrome.diagnostics.ts:182`; `X/browser/src/browser/chrome.ts:471,517,953`; `X/browser/src/browser/client-fetch.ts:356,456`; `X/browser/src/browser/extension-install.ts:220`; `X/browser/src/browser/extension-relay-daemon-spawn.ts:18`; `X/browser/src/browser/extension-relay/auth-v2-websocket.ts:42,45`; `X/browser/src/browser/extension-relay/owner-client.ts:130`; `X/browser/src/browser/extension-relay/owner-server.ts:140,196`; `X/browser/src/browser/extension-relay/relay-auth.ts:158`; `X/browser/src/browser/extension-relay/relay-fetch.ts:203`; `X/browser/src/browser/extension-relay/relay-server.ts:197,262`; `X/browser/src/browser/extension-relay/relay-session-owner.ts:366`; `X/browser/src/browser/pw-download-capture.ts:164`; `X/browser/src/browser/pw-session-actions.ts:502`; `X/browser/src/browser/pw-session-connection.ts:227,544`; `X/browser/src/browser/pw-session-downloads.ts:61`; `X/browser/src/browser/pw-session-page-target.ts:44`; `X/browser/src/browser/pw-session-state.ts:386`; `X/browser/src/browser/pw-tools-core.downloads.ts:133`; `X/browser/src/browser/pw-tools-core.interactions.navigation.ts:310,383,607`; `X/browser/src/browser/pw-tools-core.responses.ts:65`; `X/browser/src/browser/routes/agent.act.existing-session.ts:31,96,128,204,295`; `X/browser/src/browser/routes/tabs.ts:102`; `X/browser/src/browser/screencast/session.ts:255`; `X/browser/src/browser/server-context.availability.ts:357`; `X/browser/src/sdk-node-runtime.ts:18`; `X/codex/src/app-server/native-subagent-completion-delivery.ts:284`; `X/codex/src/app-server/native-subagent-recovery-coordinator.ts:128`; `X/codex/src/app-server/native-subagent-submission-owner.ts:509`; `X/codex/src/app-server/sandbox-exec-server/processes.ts:58,429`; `X/copilot/src/attempt-active-run.ts:177`; `X/copilot/src/attempt-cleanup.ts:107,145`; `X/copilot/src/isolated-completion.ts:93`; `A/cli-runner/execute-node-claude.ts:181`; `A/provider-local-service.ts:326,665`; `A/sessions/exec.ts:120`; `A/sessions/tools/bash-local-exec.ts:76`; `A/shell-snapshot.ts:482,492`; `A/subagents/spawn/acp-spawn-parent-stream.ts:278,405,487,503`; `G/desktop/computer-process.ts:99,164`; `G/desktop/managed-linux.ts:486`; `G/server-methods/open-path.ts:76`; `G/worker-environments/tunnel-ssh-runner.ts:149,163`; `G/worker-environments/workspace-sync-inventory.ts:144,196`; `I/github-issue.ts:364`; `I/sqlite-readonly-worker-session.ts:272,334`; `I/tailscale.ts:207,253`; `I/update-runner-command.ts:31` | Retain: one process/run startup, output wait, stop or kill grace; process owner settles it. |
| b (12) | `X/anthropic/cli.runtime.ts:234`; `X/codex/src/app-server/client-runtime.ts:298`; `X/copilot/src/runtime.ts:136`; `X/diffs/src/browser.runtime.ts:452`; `G/desktop/computer-service.ts:170`; `G/question-manager.ts:310`; `G/server-chat.ts:755`; `G/talk/transcription-relay.ts:315,430`; `G/terminal/session-manager.ts:651`; `G/watch-node-http.ts:382,1082` | Retain: bounded session/client/resource idle retention; its resource owner cancels or retires it. |
| b (29) | `X/browser/src/browser/extension-relay/relay-bridge.ts:128,342,380`; `X/discord/src/internal/gateway-lifecycle.ts:13,34,69`; `X/line/src/monitor.ts:99`; `X/reef/src/transport.ts:424,733`; `X/telegram/src/polling-session.ts:50,505,518`; `X/whatsapp/src/connection-controller.ts:231,1018,1026`; `A/cli-runner/execute-plugin-watchdog.ts:17`; `A/embedded-agent-runner/run/llm-idle-timeout.ts:330,404`; `A/embedded-agent-runner/run/tool-activity-heartbeat.ts:20`; `A/sessions/tools/bash.ts:239,345`; `A/tools/media-generate-background-shared.ts:159,371`; `H/run-state-machine.ts:52`; `H/transport/stall-watchdog.ts:130`; `H/typing-lifecycle.ts:36`; `G/mcp-http.ts:63`; `G/websocket-keepalive.ts:63`; `I/backup-create-stream.ts:116` | Retain: active operation/transport liveness or watchdog; ends with that operation/resource. |
| b (8) | `C/service/active-run-cancellation.ts:31,160`; `G/server-run-shutdown.ts:93`; `G/server-shutdown.ts:10`; `I/gateway-active-work.ts:235`; `I/gateway-suspend-coordinator.ts:125`; `I/restart.ts:113,819` | Retain: bounded suspend/restart/drain control must work while scheduler admission is closed. |
| b (15) | `X/codex/src/app-server/client-catalog-worker.ts:153`; `A/auth-profiles/sqlite-read-pool.ts:79`; `I/sqlite-integrity-worker.ts:77,400`; `I/sqlite-readonly-location.worker.ts:101`; `I/tailscale-route-owner.worker.ts:97`; `I/triage-continuation.ts:90,215,368,438,556`; `I/update-repair-turn-worker.ts:31,120`; `I/worker-idle-gc.ts:22`; `I/worker-task-pool-retirement.ts:145` | Retain: worker/storage resource custody and reclamation, independent of Gateway maintenance. |
| b (8) | `I/update-managed-service-handoff-control.ts:263,267,282`; `I/update-managed-service-handoff.ts:194,988,1102,1175,2141` | Retain: successor-helper authority/parent-exit control or its IPC deadline; independent of Gateway exit. |
| b (3) | `X/buzz/src/room-access-wait.ts:45,172`; `X/cua-computer/src/commands.ts:473` | Retain: subscription-scoped polling; its disposer cancels the timer. |

Dead plumbing (zero physical arms; separate from the 845-site denominator):

| Class | Baseline locations | Deletion |
|---|---|---|
| e | `G/server-node-session-runtime.ts:85,170`; `G/server-lifecycle.ts:137,565`; `G/server-close.ts:241,503,504,505,506`; `G/server-close.test-support.ts:76` | Deleted in #160068: unused `nodePresenceTimers` map, threading and close hook; no production writer remained. |
| e | `A/agent-bundle-mcp-manager-lifecycle.ts:48,51,59,60,61,102,103,106,338,339` | Deleted in #160326: unused interval option and test-only enable/clock overrides after required scheduler injection. Independent inherited-CI evidence is retained in that PR body. |
| e | `I/question-channel-runtime-internal.ts:78,92` | Deleted in #160334: test-only retention-duration option; scheduler fake clock tests the actual retention policy. |
| e | `G/session-companion-ask.ts:82,83,364,365` (uses `:517,644`) | Deleted in #160371: uncalled timer override options and fallback locals. Independent inherited-CI evidence is retained in that PR body. Native per-ask deadline remains b; policy `now` remains. |

## Supplemental census references and exclusions

Baseline `fb2487a903`. Path abbreviations match the primary census.

| Classification | Baseline locations | Reason |
|---|---|---|
| external-timer-helper | `G/active-sessions-shutdown-drain.ts:55`; `G/channel-stop-timeout.ts:12`; `G/chat-abort-lifecycle-internal.ts:105`; `G/dashboard-session-title.ts:271`; `G/desktop/managed-linux.ts:191`; `G/node-invoke-readiness.ts:50`; `G/server-channels.ts:1085`; `G/server-close.ts:99,126,169,542,555`; `G/server-cron-notifications.ts:245,423`; `G/server-media-cleanup-lifecycle.ts:34`; `G/server-methods/claws-monitors.ts:163`; `G/server-methods/sessions-lifecycle-drain.ts:298,301,321`; `G/server-reload-utils.ts:89`; `G/server-restart-sentinel-notice.ts:122`; `G/server-worker-placement-reclaim.ts:108`; `G/server/http-listen.ts:59`; `G/session-reset-incognito.ts:32`; `G/worker-environments/desktop-tunnel.ts:335`; `G/worker-environments/environment-access.ts:392`; `G/worker-environments/node-launch-adapter.ts:405`; `G/worker-environments/node-worker-tunnel.ts:261,275`; `G/worker-environments/service.ts:134,148`; `G/worker-environments/workspace-sync.ts:107` | b: bounded awaited timeout/backoff/drain; shared implementation owns the arm. |
| native-abort | `G/control-ui-link-preview.ts:186`; `G/control-ui-session-pr-check-details.ts:110`; `G/github-user-identity.ts:96`; `G/server-instance-runtime.ts:263`; `G/server-methods/web-search.ts:179`; `G/server-plugin-subagent-runtime.ts:275`; `G/user-profiles-http.ts:197,399`; `G/worker-environments/node-worker-tunnel.ts:210,440`; `G/worker-environments/node-worker-workspace-drain.ts:25`; `G/worker-environments/node-workspace-transfer-http.ts:132`; `G/worker-environments/node-workspace-transfer-service.ts:403,604`; `G/worker-environments/node-workspace-transfer-snapshot.ts:55`; `G/worker-environments/worker-turn-admission.ts:165`; `G/worker-environments/workspace-sync-preflight.ts:25` | b: one request/transfer/model abort deadline; outside named timer API count. |
| generated-browser | `G/mcp-app-standalone-host.ts:365` | Excluded: generated browser resource-load abort deadline. |
| helper/abort references | `I/backup-tar-retry.ts:41`; `I/clawhub-retry.ts:52`; `I/delivery-recovery.shared.ts:261`; `I/git-network-retry.ts:94`; `I/net/proxy/proxy-validation.ts:313`; `I/outbound/message-action-execution.ts:123`; `I/provider-usage.admin.ts:118`; `I/provider-usage.fetch.shared.ts:15`; `I/push-apns.relay.ts:258`; `I/restart-stale-pids.ts:93,102`; `I/retry-policy.ts:76,116`; `I/ssh-tunnel.ts:107`; `I/system-disks.ts:265`; `I/tailscale.ts:472`; `I/telemetry.ts:384`; `I/transport-ready.ts:60`; `I/update-candidate-canary-readiness.ts:107,114`; `I/update-candidate-io.ts:111,154,157`; `I/update-candidate-rehearsal.ts:227`; `I/update-managed-service-handoff-control.ts:424`; `I/update-managed-service-handoff-parent-source.ts:29`; `I/update-managed-service-handoff.ts:802,817,901,914,938,948,1096,1243` | b: operation retry/deadline or independent successor-helper wait; 34 references, no additional physical arm. |
| excluded | `G/mcp-app-standalone-host.ts:289` | Generated browser iframe teardown code; does not execute inside Gateway. |
| excluded | `G/server/plugin-legacy-listeners.ts:64,94` | HTTP server socket timeout configuration; no JS timer arm. |
| excluded | `G/server.e2e-ws-harness.ts:68` | Test harness, not production. |
| excluded | `G/websocket-keepalive.ts:34,87` | Socket timeout settings; the actual ping/pong keepalive interval at :63 is already counted as class b. |
| excluded | `G/worker-environments/project-setup-script.ts:127` | Generated remote child script setup command deadline; not Gateway execution. |
| excluded | `G/worker-environments/workspace-quiescence-scripts.ts:407,420,465` | Generated remote watchdog timers deliberately independent of Gateway process. |
| excluded | `X/acpx/src/codex-auth-bridge.ts:504,524` | Generated child-wrapper program: parent watchdog and child kill grace run in ACP wrapper process |
| excluded | `X/browser/src/browser/pw-tools-core.interactions.actions.ts:389` | JavaScript evaluate timeout executes in inspected web page |
| excluded | `X/browser/src/browser/relay-daemon.ts:99` | Standalone browser relay daemon owns its independent process idle exit |
| excluded | `X/browser/src/browser/routes/agent.act.ts:558` | Highlight cleanup executes in inspected web page |
| excluded | `X/crabbox/src/crabbox-worker-node-enrollment.ts:230` | Generated remote node enrollment program |
| excluded | `X/crabbox/src/crabbox-worker-node-process.ts:173,193,227` | Generated remote node process script |
| excluded | `X/crabbox/src/crabbox-worker-warm-image-scrub.ts:14` | Generated warm-image shell/Node cleanup script |
| excluded | `X/google-meet/src/transports/google-meet-caption-observer-source.ts:110`; `X/google-meet/src/transports/google-meet-page-scripts.ts:80` | JavaScript injected into the meeting web page |
| excluded | `X/matrix/src/cli-shared.ts:32` | CLI exit helper |
| excluded | `X/memory-core/src/cli-index-search.runtime.ts:132` | CLI-only index/search deadline |
| excluded | `X/mxc/src/mxc-spawn-launcher.mjs:39` | Child process launcher parent-disconnect kill grace |
| excluded | `X/policy/src/cli.ts:129` | CLI-only policy command delay |
| excluded | `X/signal/src/client.ts:148` | request.setTimeout(0) disables an existing socket timeout; it does not arm a timer |

<details>
<summary>Measured hosted CI run wall times</summary>

### Hosted CI run wall times

GitHub updated_at minus run_started_at, in seconds, for each completed workflow run. This is whole-run elapsed wall time, not per-file test duration, runner CPU time, billable time, or summed parallel job time. Cancelled runs remain labelled cancelled. Prior heads are separate evidence.

| PR | Slice / revision | Run | Head | Conclusion | RUN WALL (seconds) |
| --- | --- | --- | --- | --- | ---: |
| #160315 | approval-bootstrap / published | [36401825740](https://github.com/openclaw/openclaw/actions/runs/36401825740) | `c5b3c4ae01` | failure | 1448 |
| #160318 | skills-refresh / published | [36402003337](https://github.com/openclaw/openclaw/actions/runs/36402003337) | `4fafc2add7` | failure | 1492 |
| #160326 | mcp / published | [36402978963](https://github.com/openclaw/openclaw/actions/runs/36402978963) | `1fceb8f4e7` | failure | 1525 |
| #160334 | questions / prior head | [36403551682](https://github.com/openclaw/openclaw/actions/runs/36403551682) | `9485d33201` | failure | 1629 |
| #160334 | questions / repaired head | [36407409443](https://github.com/openclaw/openclaw/actions/runs/36407409443) | `f2ca3af6feeb` | failure | 1700 |
| #160335 | restart-sentinel / published | [36403569235](https://github.com/openclaw/openclaw/actions/runs/36403569235) | `62cb7cd6ff` | failure | 1505 |
| #160340 | activity-summary / published | [36404157978](https://github.com/openclaw/openclaw/actions/runs/36404157978) | `c32f2e9b9b` | failure | 1925 |
| #160341 | cron-stream / published | [36404170083](https://github.com/openclaw/openclaw/actions/runs/36404170083) | `42975a258c` | failure | 1355 |
| #160369 | presence / published | [36410007950](https://github.com/openclaw/openclaw/actions/runs/36410007950) | `8ee671f969a3` | failure | 1414 |
| #160370 | device-scope / published | [36410030329](https://github.com/openclaw/openclaw/actions/runs/36410030329) | `cb777346a282` | failure | 1578 |
| #160371 | companion / published | [36410052666](https://github.com/openclaw/openclaw/actions/runs/36410052666) | `75c4c209949e` | failure | 1773 |
| #160375 | config-reload / prior head | [36410694894](https://github.com/openclaw/openclaw/actions/runs/36410694894) | `843ca77b7306` | failure | 1750 |
| #160375 | config-reload / repaired head | [36421206233](https://github.com/openclaw/openclaw/actions/runs/36421206233) | `238fa8cc96a0` | failure | 1892 |
| #160381 | cron-exit / published | [36411857535](https://github.com/openclaw/openclaw/actions/runs/36411857535) | `66d57e0dfa26` | failure | 1892 |
| #160391 | persistence-cache / published | [36415298483](https://github.com/openclaw/openclaw/actions/runs/36415298483) | `932dd2a523fa` | failure | 1688 |
| #160395 | tls-renewal / published | [36416138126](https://github.com/openclaw/openclaw/actions/runs/36416138126) | `43edf9c8c628` | cancelled | 802 |

Skipped unknown CI run IDs: #160068, #160372, #160374. No additional run discovery, logs, or tests were requested for this timing collection.

</details>
This commit is contained in:
Peter Steinberger 2026-09-28 07:25:31 -07:00 • committed by GitHub
parent 670415932e
commit 738c844e40
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 22 additions and 0 deletions

View file

@ -19,6 +19,7 @@ How the Gateway scheduler runs a job, what it keeps between runs, and how a repe
- One-shot jobs (`--at`) auto-delete after successful completion: delivery is confirmed, not requested, intentionally suppressed, or explicitly best-effort. Failed or unknown required delivery retains the job disabled for inspection without replaying the payload. Pass `--keep-after-run` to keep successful jobs too.
- Per-run wall-clock budget: `--timeout-seconds` when set. Otherwise, isolated/detached agent-turn jobs are bounded by the scheduler's own 60-minute watchdog before the underlying agent-turn timeout (`agents.defaults.timeoutSeconds`, default 48 hours) would ever apply; command jobs default to 10 minutes, and script payloads default to 5 minutes.
- On Gateway startup, overdue agent-turn jobs and jobs that await a heartbeat are rescheduled instead of replayed immediately, keeping model/tool execution out of scheduler startup. This includes heartbeat monitors, migrated heartbeat tasks, and main-session system events with immediate wake. Startup catch-up delays survive label or payload-content reconciliation and another restart; changing the schedule starts a new scheduling decision.
- When a running Gateway wakes after a deadline, the scheduler coalesces missed timer ticks. Cron rechecks eligible jobs using its stored deadlines and run receipts. The shared [Gateway scheduler](/concepts/architecture#timed-work-and-shutdown) owns timer arming and shutdown joining; cron owns execution, catch-up policy, and durable results.
- If you drive `openclaw agent` from system cron or another external scheduler, wrap it with a hard-kill escalation even though the CLI already handles `SIGTERM`/`SIGINT`. Gateway-backed runs ask the Gateway to abort accepted runs; `--local` runs get the same abort signal. For GNU `timeout`, prefer `timeout -k 60 600 openclaw agent ...` over plain `timeout 600 ...` — the `-k` value is the backstop if the process cannot drain in time. For systemd units, use a `SIGTERM` stop signal with a grace window (`TimeoutStopSec`) before the final kill. Reusing a `--run-id` while the original Gateway run is still active reports the duplicate as in-flight instead of starting a second run.
<AccordionGroup>

View file

@ -141,6 +141,27 @@ Details: [Gateway protocol](/gateway/protocol), [Pairing](/channels/pairing),
- Health: `health` over WS (also included in `hello-ok`).
- Supervision: launchd/systemd for auto-restart.
### Timed work and shutdown
The Gateway kernel owns one `GatewayScheduler` for registered maintenance and cron
wakeups. Owners receive that instance and register jobs; one host timer drives the
next wake. For durable work, stores retain deadlines and their owners reconstruct
schedules at startup rather than persisting a second scheduler state.
After sleep, a late wake dispatches each runnable, due registration once for that
wake. A periodic registration waits for its callback and tracked work to finish
before starting its next interval; missed ticks are coalesced. Wall time catches
sleep, while elapsed time keeps relative delays and cadences moving through a
backward clock correction. Rescheduling replaces a waiting job by default;
`mode: "earliest"` preserves earlier wall and elapsed deadlines for the same job ID
so a stale read cannot postpone an already promised wake.
`beginClose()` closes scheduling admission, cancels pending wakes, and signals
shutdown. `stop()` joins callbacks already running and work tracked by their async
scope; the Gateway lifecycle owns the outer shutdown budget and resource teardown.
Request deadlines, stream-local timers, and child-process cleanup stay with their
operation owners. SQLite WAL checkpoint timers stay with the storage owner.
## Invariants
- Exactly one Gateway controls a single Baileys session per host.