Nothing large enough to matter can go missing
A paged session spine, an interview the server can attest from both sides, and the schema fix that made every submission fail.
The spine deleted the agent’s half
get_spine was the one tool with no result ceiling — up to 600 KB, thirty times what every other tool respects. When a session went past that, the fallback dropped every assistant turn to fit.
That is the worst thing to lose: roughly two thirds of the prose in a session is the agent’s, and 17 of 23 recorded trials came from its side. The spine is now paged like the diff, so a long session costs more calls and no material.
The server only heard one side
record_interview_round took both the question and the answer from the reviewer, so a fabricated interview was indistinguishable from a real one.
Questions are now recorded first and come back with a q_id; the author answers by that id through answer_questions. meta.interview gained author_attested, so an unattested interview shows up in the document. The interview also went from four rounds to two.
The schema fix
summarizeRun grew two fields; meta.interview is additionalProperties: false over three. submit_document stamps that summary into every document — so every submission failed validation. The tool could not file its own output.
124 unit tests passed with the bug in place, because no test stamped a real summary into a real document. A reviewer agent reading the diff cold found it, which is what the two-role split is for.
Commits for this release: v0.3.1…v1.0.0