From b19d420b11af77e991b4bf14ef5a312c70cbfa3e Mon Sep 17 00:00:00 2001 From: Craig Jennings Date: Fri, 24 Jul 2026 17:42:54 -0500 Subject: chore(inbox): park lint-org and telegram fixes from home and .emacs.d --- .../lint-org-example-block/report-from-home.org | 21 ++ .../note-from-emacsd.txt | 27 ++ .../note-superseded-1723.txt | 22 ++ working/triage-telegram-down-launch/proposed.diff | 57 ++++ .../triage-intake.telegram.org.proposed | 290 +++++++++++++++++++++ .../triage-intake.telegram.org.superseded-1723 | 273 +++++++++++++++++++ 6 files changed, 690 insertions(+) create mode 100644 working/lint-org-example-block/report-from-home.org create mode 100644 working/triage-telegram-down-launch/note-from-emacsd.txt create mode 100644 working/triage-telegram-down-launch/note-superseded-1723.txt create mode 100644 working/triage-telegram-down-launch/proposed.diff create mode 100644 working/triage-telegram-down-launch/triage-intake.telegram.org.proposed create mode 100644 working/triage-telegram-down-launch/triage-intake.telegram.org.superseded-1723 (limited to 'working') diff --git a/working/lint-org-example-block/report-from-home.org b/working/lint-org-example-block/report-from-home.org new file mode 100644 index 0000000..0b9f4d3 --- /dev/null +++ b/working/lint-org-example-block/report-from-home.org @@ -0,0 +1,21 @@ +#+TITLE: lint-org.el bug: invalid-block false positive on an example +#+SOURCE: from home +#+DATE: 2026-07-24 12:48:05 -0500 + +lint-org.el bug: invalid-block false positive on an example block containing a heading line. + +Repro: an org file with + + #+begin_example + ** Feature Name or Topic + #+end_example + +reports BOTH delimiters as judgment findings — 'Possible incomplete block "#+begin_example"' on the begin line and 'Possible incomplete block "#+end_example"' on the end line — even though the block is correctly paired. The trigger is the literal '** ' heading line inside the block body; the checker appears to treat it as a structural break rather than block content, so it loses track of the open block. + +Seen in home's .ai/notes.org (the PENDING DECISIONS section documents its own task format inside an example block, which is a legitimate and common shape for a docs file). These are the only 2 findings left in that file after I cleaned up the real defects, so they're pure noise now and they'll recur on any org file that documents org syntax inside an example block. + +Suggested fix: while inside a begin_example/begin_src block, skip structural parsing of the body entirely until the matching #+end_ line. Example and src blocks are verbatim by definition, so nothing inside them should be read as a heading, a timestamp, or a block delimiter. + +Worth noting the same class of bug would hit a src block containing '#+end_example' or similar as literal text. + +Context on what surfaced it: home's notes.org had 17 lint findings that had been dismissed as false positives across several sessions. 15 were real — the file used markdown '**bold**' where org wants single asterisks, so it rendered as literal asterisks and looked heading-shaped to the checker. Fixing the markup cleared those. That left these 2, which are the genuine checker bug. The lesson for the checker's credibility: a persistent block of 'known false positives' hid 15 real defects, because nobody re-examined the pile once it got labeled. diff --git a/working/triage-telegram-down-launch/note-from-emacsd.txt b/working/triage-telegram-down-launch/note-from-emacsd.txt new file mode 100644 index 0000000..209aa24 --- /dev/null +++ b/working/triage-telegram-down-launch/note-from-emacsd.txt @@ -0,0 +1,27 @@ +FOLLOW-UP / CORRECTION to my earlier triage-intake.telegram.org fix (inbox 2026-07-24-1723). Both affected projects (work + home) replied with reproductions, and the root cause is NOT the missing setq — it's a behavioral bug the plugin's wording allowed. Attaching the re-edited workflow file; please take this version, not the setq-only one. The setq fix is still included and correct; this adds the real fix on top. + +WHAT ACTUALLY BIT WORK AND HOME (both independently, same failure) + +The telegram source, on finding telega down/unloaded — its NORMAL entry state — reported "SCAN FAILED: telegram — not loaded" (work) or a silent SKIP / blind scan (home), INSTEAD OF running Step 1 to start it. Neither hit the segfault path. Verbatim from work's digest: + + ⚠ SCAN FAILED: telegram — telega isn't loaded in the running Emacs daemon, so this sweep is blind on Telegram. + +Work then ran the numbered Step 1 verbatim as a reproduction: down → (telega t) → server live (run open listen connect stop) → telega--loadChats → 18 chats. So the recovery IS Step 1; (telega t) both loads the package and starts the docker server. The sessions simply didn't run it — they treated "down" as "failed/skip." + +WHY THE WORDING ALLOWED IT + +The Quick Reference said "never skips because the server is down" (good), but the closing paragraph said "If any lifecycle step fails (docker image missing, server crash, daemon unreachable), the sweep reports it as SCAN FAILED." An agent conflates "server is down" with "a lifecycle step failed" → SCAN FAILED → blind sweep, without ever attempting the launch. Two agents made exactly this read. + +THE FIX (in the attached file) + +1. Added a prominent directive right after the Quick Reference intro: DOWN / not-loaded is the TRIGGER to launch, never a reason to skip or fail. (telega t) loads AND starts. SCAN FAILED is reserved for a launch that was ATTEMPTED and did not reach Ready. The :ENABLED: guard tests whether telega is INSTALLED (fboundp), not whether the server is up; a down server never disables the source. +2. Reworded the closing SCAN FAILED paragraph to say the failure rule applies only AFTER the launch was attempted — a pre-launch down state means "run Step 1," not "SCAN FAILED" — and noted a blind sweep is worse than a clean failure because it hides real unread behind a false all-clear. +3. Kept the setq fix in Step 1 (latent segfault guard; both projects confirmed it's real but was NOT the cause since the daemon reads telega-use-docker t). + +SECONDARY FINDING — ENGINE, not this plugin (your call) + +Work reported: "The marker still advanced, which is its own smell — a SCAN FAILED source shouldn't silently advance the sentinel." That's engine behavior in triage-intake.org (the per-source last-run/anchor advance), not the telegram plugin — telegram is :ANCHOR: none, yet something advanced. Worth a look: a source that reports SCAN FAILED advancing its cursor means the next sweep thinks it already covered that window, compounding the blind-sweep hole. I did not touch the engine; flagging for your judgment. + +STILL UNRESOLVED, for the record: home carries an older data point (its telega bug task, 2026-07-16) where a launch WITH the setq present returned 'started but server-live-p stayed nil and no container appeared — a launch failure not explained by any of the above. If that's since fixed by the current v1.2.0 image reaching Ready, it's moot; noting it in case the crashing recurs. + +No reply needed unless you disagree. diff --git a/working/triage-telegram-down-launch/note-superseded-1723.txt b/working/triage-telegram-down-launch/note-superseded-1723.txt new file mode 100644 index 0000000..7c54ede --- /dev/null +++ b/working/triage-telegram-down-launch/note-superseded-1723.txt @@ -0,0 +1,22 @@ +Fix for a defect in triage-intake.telegram.org: the numbered Step 1 was missing the mandatory `(setq telega-use-docker t)` that the plugin's own Quick Reference and SEGFAULT gotcha both require. Attached is the edited workflow file (.ai/workflows/triage-intake.telegram.org) — please take it into the canonical at claude-templates/.ai/workflows/. + +THE DEFECT + +The plugin contradicts itself across three places: +- Quick Reference (line 35): `emacsclient -e "(progn (setq telega-use-docker t) (telega t) 'started)"` — has the setq. +- SEGFAULT gotcha (line ~170): "docker mode stays mandatory (telega-use-docker = t; the setq before (telega t) is still the right defense)". +- Numbered Step 1 (lines 91-93): `(progn (unless (...live-p) (telega t)) 'started)` — NO setq. + +telega-use-docker defaults to nil. In native (non-docker) mode the dockerized-vs-native tdlib difference is exactly the SEGFAULT the gotcha documents (exit 139). A session following the numbered Step 1 literally, on a daemon where nothing had already forced telega-use-docker to t, starts telega native and crashes the server — which the engine reports as SCAN FAILED at the top of the summary. Both of Craig's personal projects that use the telegram source (work and home) reported triage-intake failing. + +THE FIX + +Added `(setq telega-use-docker t)` as the first form in Step 1's progn, before the `(unless ... (telega t))`, with a comment pointing at the gotcha. Now Step 1 matches the Quick Reference. Minimal, wording/robustness only; no behavior change on a daemon that already had docker mode on. + +IMPORTANT CAVEAT — this is a real defect but NOT a confirmed root cause. I could not reproduce the original failure: Craig doesn't remember the symptom ("it was much earlier"), and his .emacs.d daemon currently reads telega-use-docker t (via .emacs.d's telega-config `:custom`), so on his machine right now the missing setq may have been moot. The fix removes one genuine failure mode that matches the reported symptom; whether it was THE cause is unconfirmed. I've asked work and home for their actual error via their inboxes; if they come back with something else (e.g. the recent :TRIAGE_SOURCES: gating change 4d87f35, or a different source), I'll send a follow-up. + +Two things worth your judgment on the canonical: +1. The stale note at line 37 ("Craig's daemon currently has telega-use-docker nil") is now false on .emacs.d — telega-config sets it t. Consider softening it to "the daemon's default is nil unless an Emacs-config :custom forces it," since the workflow syncs to machines/daemons without that config. +2. If the daemon reliably has docker mode on everywhere telega runs, this whole class is belt-and-braces — but Step 1 contradicting the Quick Reference is a defect regardless, and the belt is cheap. + +No reply needed unless you disagree with the fix. diff --git a/working/triage-telegram-down-launch/proposed.diff b/working/triage-telegram-down-launch/proposed.diff new file mode 100644 index 0000000..72b9cd4 --- /dev/null +++ b/working/triage-telegram-down-launch/proposed.diff @@ -0,0 +1,57 @@ +--- claude-templates/.ai/workflows/triage-intake.telegram.org 2026-07-09 13:57:29.819324933 -0500 ++++ working/triage-telegram-down-launch/triage-intake.telegram.org.proposed 2026-07-24 17:26:36.349127827 -0500 +@@ -30,6 +30,20 @@ + unless Craig has Telegram open in Emacs. The scan therefore runs the full + lifecycle every time, never skips because the server is down: + ++⚠ *DOWN / not-loaded is the TRIGGER to launch, never a reason to skip or fail.* ++This is the exact mistake two projects (work + home, 2026-07-24) made: they ++probed telega, saw =(telega-server-live-p)= nil or telega not =featurep=, and ++reported =SCAN FAILED: telegram — not loaded= or a silent SKIP — a *blind* ++sweep — instead of running Step 1 to start it. A down or unloaded telega is the ++normal entry state; =(telega t)= both LOADS the package and STARTS the docker ++server (work confirmed: down → =(telega t)= → Ready, 18 chats). So the plugin ++MUST run Step 1's launch whenever telega is down/unloaded, wait for Ready, then ++scan. =SCAN FAILED= is reserved for a launch that was actually ATTEMPTED and did ++not reach Ready (image missing, server crash on start, daemon unreachable) — ++never for the pre-launch down state itself. The =:ENABLED:= guard above tests ++whether telega is INSTALLED (=fboundp=), not whether the server is up; a down ++server never disables the source. ++ + 1. Record prior state: TELEGA_WAS_RUNNING via (telega-server-live-p). + 2. Launch (only if not running): + emacsclient -e "(progn (setq telega-use-docker t) (telega t) 'started)" +@@ -48,10 +62,13 @@ + Verify: telega-server-live-p → nil, no zevlg/telega-server container in + docker ps. If Craig had it running, leave it untouched. + +-If any lifecycle step fails (docker image missing, server crash, daemon +-unreachable), the sweep reports it as SCAN FAILED at the top of the summary +-per the engine's failure rule — never as a silent skip. Craig gets real +-traffic here. ++If any lifecycle step fails *after the launch was attempted* (docker image ++missing, server crash on start, daemon unreachable, Ready never reached), the ++sweep reports it as SCAN FAILED at the top of the summary per the engine's ++failure rule — never as a silent skip. This does NOT cover the ordinary ++pre-launch down state: a down server means "run Step 1," not "SCAN FAILED." ++Craig gets real traffic here, so a blind sweep that skipped the launch is worse ++than a clean failure — it hides real unread messages behind a false all-clear. + + ** Scan + +@@ -88,7 +105,15 @@ + # `(telega t)` starts without popping the root buffer. Docker mode (the stable + # path — see the SEGFAULT gotcha) reconnects the persisted ~/.telega session in + # ~2s. Then load the main chat list so telega--chats populates. ++# ++# The `(setq telega-use-docker t)` is mandatory and must come BEFORE `(telega t)`: ++# tdlib segfaults in native mode (SEGFAULT gotcha below), and the daemon's default ++# is nil unless something (e.g. an Emacs-config :custom) has already forced it. It ++# was missing here while the Quick Reference and the gotcha both require it — ++# a session that started telega without it on a native-mode daemon would crash the ++# server, surfacing as a triage SCAN FAILED. Match the Quick Reference exactly. + emacsclient -e "(progn ++ (setq telega-use-docker t) + (unless (and (fboundp 'telega-server-live-p) (telega-server-live-p)) (telega t)) + 'started)" + # Poll until Ready with chats synced, or a crash/timeout. Background this with an diff --git a/working/triage-telegram-down-launch/triage-intake.telegram.org.proposed b/working/triage-telegram-down-launch/triage-intake.telegram.org.proposed new file mode 100644 index 0000000..42d46fe --- /dev/null +++ b/working/triage-telegram-down-launch/triage-intake.telegram.org.proposed @@ -0,0 +1,290 @@ +#+TITLE: Triage Intake — Telegram Source +#+AUTHOR: Craig Jennings +#+DATE: 2026-06-09 + +# Source plugin for the triage-intake engine. See triage-intake.org for the +# contract and the Phase A-D orchestration. This file declares ONE source. +# +# General (personal) source: Telegram via the Emacs telega.el package (tdlib +# backend). It lives in .ai/workflows/ and is template-synced, sitting with the +# other general personal sources (personal-gmail, cmail, personal-calendar, +# signal, github-prs) — not the project plugins. Telegram is personal +# messaging, not project-specific. +# +# Unlike signal-cli (a standalone CLI), Telegram has no headless CLI here. The +# client is telega.el running inside Craig's long-lived `emacs --daemon`, so the +# plugin drives it over `emacsclient -e`. tdlib keeps a persisted session in +# ~/.telega (td.binlog), so a started telega reconnects without re-auth. + +* Source: telegram +:PROPERTIES: +:ORDER: 24 +:ENABLED: command -v emacsclient && emacsclient -e "(or (featurep 'telega) (fboundp 'telega))" | grep -q t +:ANCHOR: none +:SUBAGENT_OVER: 40 +:END: + +** Quick reference — full lifecycle + +Telega does not autostart with the Emacs daemon. "Down" is its normal state +unless Craig has Telegram open in Emacs. The scan therefore runs the full +lifecycle every time, never skips because the server is down: + +⚠ *DOWN / not-loaded is the TRIGGER to launch, never a reason to skip or fail.* +This is the exact mistake two projects (work + home, 2026-07-24) made: they +probed telega, saw =(telega-server-live-p)= nil or telega not =featurep=, and +reported =SCAN FAILED: telegram — not loaded= or a silent SKIP — a *blind* +sweep — instead of running Step 1 to start it. A down or unloaded telega is the +normal entry state; =(telega t)= both LOADS the package and STARTS the docker +server (work confirmed: down → =(telega t)= → Ready, 18 chats). So the plugin +MUST run Step 1's launch whenever telega is down/unloaded, wait for Ready, then +scan. =SCAN FAILED= is reserved for a launch that was actually ATTEMPTED and did +not reach Ready (image missing, server crash on start, daemon unreachable) — +never for the pre-launch down state itself. The =:ENABLED:= guard above tests +whether telega is INSTALLED (=fboundp=), not whether the server is up; a down +server never disables the source. + +1. Record prior state: TELEGA_WAS_RUNNING via (telega-server-live-p). +2. Launch (only if not running): + emacsclient -e "(progn (setq telega-use-docker t) (telega t) 'started)" + The setq is mandatory defense: tdlib segfaults outside docker mode + (2026-06-09), and Craig's daemon currently has telega-use-docker nil. + Wait ~2s for Ready, then (telega--loadChats 'main) until telega--chats + is populated. +3. Check messages: the maphash unread scan in ** Scan Step 2 (filters the + messageContactRegistered join-notice noise). +4. Send (needs the server live; /voice personal first — Telegram + occasionally carries WORK communication to Kostya and Vrezh, so treat + sends with the same care as Slack): + emacsclient -e "(telega-chat-send-msg (telega-chat-get ) \"\")" +5. Shutdown (ONLY if step 1 recorded not-running): + emacsclient -e "(progn (telega-server-kill) (ignore-errors (telega-kill t)) 'stopped)" + Verify: telega-server-live-p → nil, no zevlg/telega-server container in + docker ps. If Craig had it running, leave it untouched. + +If any lifecycle step fails *after the launch was attempted* (docker image +missing, server crash on start, daemon unreachable, Ready never reached), the +sweep reports it as SCAN FAILED at the top of the summary per the engine's +failure rule — never as a silent skip. This does NOT cover the ordinary +pre-launch down state: a down server means "run Step 1," not "SCAN FAILED." +Craig gets real traffic here, so a blind sweep that skipped the launch is worse +than a clean failure — it hides real unread messages behind a false all-clear. + +** Scan + +Telegram direct messages and groups via telega.el in the running Emacs daemon. +=ANCHOR: none= because telega reports live unread *state* (each chat's +=:unread_count=), not a since-window — the engine substitutes no cutoff. Phase B +uses each message's timestamp only to order and label recency. + +The scan reads the =telega--chats= hash table (chat-id → chat plist), which +telega populates as chats sync. *This is robust to the tdlib server crashing +mid-session* (see the SEGFAULT gotcha below): the hash retains the last-synced +unread counts and =:last_message= even after the server dies, so a scan reading +the hash still returns the most recent known state. + +*** Leave-no-trace lifecycle (start only if needed, shut down only if we started it) + +telega is a long-lived client inside Craig's daemon. If he already has it +running, the scan must leave it running. If it's *not* running, the scan starts +it for the read and shuts it down cleanly afterward, restoring the daemon to its +prior state. The discipline: *record the prior liveness, branch on it at the +end.* + +*** Step 0 — record prior state + +#+begin_src bash +# t if telega's tdlib server was ALREADY live before this scan, nil otherwise. +# Hold this value; Step 3 reads it to decide whether to shut telega down. +TELEGA_WAS_RUNNING=$(emacsclient -e "(and (fboundp 'telega-server-live-p) (telega-server-live-p) t)" 2>/dev/null) +#+end_src + +*** Step 1 — start (docker mode) if not already running, wait for Ready + +#+begin_src bash +# `(telega t)` starts without popping the root buffer. Docker mode (the stable +# path — see the SEGFAULT gotcha) reconnects the persisted ~/.telega session in +# ~2s. Then load the main chat list so telega--chats populates. +# +# The `(setq telega-use-docker t)` is mandatory and must come BEFORE `(telega t)`: +# tdlib segfaults in native mode (SEGFAULT gotcha below), and the daemon's default +# is nil unless something (e.g. an Emacs-config :custom) has already forced it. It +# was missing here while the Quick Reference and the gotcha both require it — +# a session that started telega without it on a native-mode daemon would crash the +# server, surfacing as a triage SCAN FAILED. Match the Quick Reference exactly. +emacsclient -e "(progn + (setq telega-use-docker t) + (unless (and (fboundp 'telega-server-live-p) (telega-server-live-p)) (telega t)) + 'started)" +# Poll until Ready with chats synced, or a crash/timeout. Background this with an +# until-loop so the wait doesn't block; exit on Ready-with-chats OR an abnormal +# server exit. Then force a chat-list load if the hash is thin: +emacsclient -e "(progn (ignore-errors (telega--loadChats 'main)) (ignore-errors (telega--loadChats 'main)) 'loaded)" +#+end_src + +On a persisted session telega reaches status "Ready" within ~2s; the chat list +loads over a few more. If =(hash-table-count telega--chats)= is 0 or thin, +re-issue =telega--loadChats= and poll until it stabilizes. + +*** Step 2 — read unread, classified by last-message type + +The single most important filter: =messageContactRegistered=. Telegram counts a +" joined Telegram" service notice as one unread message, so every contact +from Craig's old address book who ever joined shows as a 1-unread "DM" *that +person never actually sent*. On the 2026-06-09 first scan this was 30 of ~50 +unread chats. Drop them entirely (tally only). + +#+begin_src bash +emacsclient -e "(let (real svc other) + (when (boundp 'telega--chats) + (maphash (lambda (id chat) + (let* ((uc (or (plist-get chat :unread_count) 0)) + (lm (plist-get chat :last_message)) + (ctype (when lm (plist-get (plist-get lm :content) :@type))) + (title (or (ignore-errors (substring-no-properties (telega-chat-title chat))) \"?\"))) + (when (> uc 0) + (cond + ((equal ctype \"messageContactRegistered\") (push title svc)) + ((member ctype '(\"messageText\" \"messagePhoto\" \"messageVideo\" \"messageDocument\" \"messageVoiceNote\" \"messageSticker\" \"messageAnimation\")) + (push (list title uc ctype) real)) + (t (push (list title uc (or ctype \"nil\")) other)))))) + telega--chats)) + (list (cons 'real (nreverse real)) + (cons 'joined-telegram-count (length svc)) + (cons 'other (nreverse other))))" +#+end_src + +For a chat that survives as Action-worthy, pull the last message's text to +classify and summarize: + +#+begin_src bash +# from the maphash key (the scan can also return ids alongside titles) +emacsclient -e "(let ((c (gethash telega--chats))) + (substring-no-properties + (or (telega--tl-get c :last_message :content :text :text) \"\")))" +#+end_src + +*** Step 3 — restore prior state (shut down only if we started it) + +#+begin_src bash +# If telega was NOT running before this scan, shut it down cleanly to leave the +# daemon as we found it. If Craig already had it running, leave it alone. +if [ "$TELEGA_WAS_RUNNING" != "t" ]; then + emacsclient -e "(progn (ignore-errors (telega-server-kill)) (ignore-errors (telega-kill t)) 'killed)" +fi +#+end_src + +⚠ *In docker mode, =telega-kill= alone is not enough.* =telega-kill= buries the +telega buffers but leaves the dockerized tdlib server running (=telega-server-live-p= +stays non-nil). =telega-server-kill= is what actually stops the server. Call +*both* — server-kill then kill — for a clean teardown. Verified clean afterward: +=telega-server-live-p= → nil, root buffer gone, no =zevlg/telega-server= container +left in =docker ps=. Skipping this whole branch when =TELEGA_WAS_RUNNING= is t is +the point of Step 0: never tear down a session Craig is actively using. + +⚠ *SEGFAULT GOTCHA — crashes are spontaneous; treat server death as routine.* +The dockerized =telega-server= (=zevlg/telega-server:latest=, image built +2026-06-04, tdlib 1.8.64) SIGSEGVs (exit 139) *on its own*, minutes-to-hours +into a session — 11 host coredumps between 2026-06-09 and 2026-06-11, several at +times when no triage verb was running. The 2026-06-11 investigation reproduced +the crash-free verbs and the spontaneous deaths side by side: coredump +backtraces show a corrupted stack (memory corruption in the musl build), and +no newer image exists upstream. Earlier theories — "native mode is the trigger", +"toggle-read is the trigger" — were timing coincidences; the verbs are sound. + +Operationally: docker mode stays mandatory (=telega-use-docker= = t; the setq +before =(telega t)= is still the right defense), and *every action batch checks +the server first* — =(process-live-p (telega-server--proc))= — restarting via +=(telega t)= when dead and re-checking Ready before firing verbs. A mid-sweep +death is recoverable, not an abort: restart, confirm Ready, resume. Durable-fix +candidates if the crashing gets worse: pin a pre-2026-06 image digest, build +=telega-server= natively against tdlib, or report upstream to zevlg with the +coredumps (=coredumpctl list /usr/bin/telega-server=). + +Defense in depth: even if the server does die, the scan still works because it +reads the cached =telega--chats= hash, not a live query. A dead server is +*scan-only* — you can still report unread state, but cannot read new bodies, mark +read, or reply until it restarts. Treat that as "scan-only, no actions this run" +and say so. + +** Classify + +Bias: Craig's personal Telegram is *spam-dominated* with a thin layer of real +signal. The opposite of Signal (high signal/low volume) — here the volume is +high and almost all noise. Filter aggressively; surface only the few real +threads. Kostya and Vrezh occasionally reach Craig here, so a real DM from a +work contact is Action, full stop. + +- *Noise-trash (tally only, never itemized):* + - =messageContactRegistered= "joined Telegram" notices — always noise, no + matter whose name is on them. The real contacts Craig knows live here; a + join notice is not a message from them. + - Romance/crypto spam DMs — the signature is an emoji-laden handle or a + two-word "RealName + FantasyWord" suffix (=Gayle ⚾🤎RoyalVineyard=, + =Cherie🌷🏰 InfiniteRhapsody=, =Jane 🍒🔥=, =Luna Skye=). One unread, + unsolicited, no prior thread. + - =Deleted Account-NNNN= threads, blank-title chats, bot channels + (=Z-Library Official=), Telegram's own =✔️Telegram= service notices. +- *Noise-keep (never reported):* unread in dev-community groups Craig follows — + =GNU Emacs=, =zed=, =Kitty=, and similar. Skipped in sweep reports entirely — + not even a name + count line — unless Craig specifically asks about them + (Craig's ruling, 2026-06-11, via the work project's handoff). Leave them + unread; they're reading material, not signal. +- *Action:* a real text/voice/media message from a *known personal contact* in + an existing one-to-one thread — an explicit ask, a question, a reply owed. On + a spam-heavy account these are rare; when one appears, surface it prominently + with the sender + gist, because it's the needle in the haystack. + +The 2026-06-09 calibration run: 30 join-notices + ~10 spam/deleted/bot + 3 dev +groups + 0 real personal DMs. Expect most sweeps to look like this — a clean +"nothing real" is the common, correct result. + +** Render + +#+begin_example +**Telegram — N unread chats (M real after filtering).** +- Action: +- Noise: K joined-Telegram notices, J spam/bot/deleted (tally only) +#+end_example + +Dev-community group traffic never appears here — no FYI line, no name + count — +unless Craig asks for it in that sweep (2026-06-11 ruling). Real DMs from known +contacts still surface as Action. + +Omit the block entirely when there's nothing but group traffic, join-notices, +and spam — under the engine's deltas-only rule that's a no-change source. Render +the block only when there's an Action item or a Noise tally worth a state-change +suggestion (e.g. a trash batch). + +** Actions + +Actions need the tdlib server *live* (see the SEGFAULT gotcha — a dead server is +scan-only). All run through telega in the daemon: + +- reply :: =emacsclient -e "(telega-chat-send-msg (telega-chat-get ) \"\")"= — public-facing (goes out under Craig's name), so run =/voice personal= before sending. Prefer a body file for multi-line. +- mark-read :: verified 2026-06-11 (the previously documented =telega-chat--mark-read= never existed in telega). The idempotent per-chat verb: + + #+begin_example + emacsclient -e "(let ((chat (telega-chat-get ))) + (telega--viewMessages chat (list (plist-get chat :last_message)) + :source '(:@type \"messageSourceChatList\") :force t) + (telega--readAllChatMentions chat) + (telega--readAllChatReactions chat))" + #+end_example + + =telega-chat-toggle-read= also works but *toggles*: on a chat with zero unread it marks the chat UNREAD, so scripting must guard on =(> (plist-get chat :unread_count) 0)=. Never mark the whole account read blindly; a real DM is handled deliberately, not swept. +- delete-join-notice :: standing policy (Craig, 2026-06-11): a chat whose *newest* message is a =messageContactRegistered= "joined Telegram" notice is a chat Craig never responded to and doesn't want to keep — *delete it* rather than mark it read. The bulk sweep (returns the count deleted): + + #+begin_example + emacsclient -e "(let ((n 0)) + (maphash (lambda (_id chat) + (when (equal (plist-get (plist-get (plist-get chat :last_message) :content) :@type) + \"messageContactRegistered\") + (telega--deleteChatHistory chat t nil) + (setq n (1+ n)))) + telega--chats) + n)" + #+end_example + + =telega--deleteChatHistory chat t nil= removes the chat from the list on Craig's side only (no revoke). First run 2026-06-11 deleted 41 such chats and cut the unread-chat count from 48 to 16. +- open :: =emacsclient -e "(telega-chat-with (telega-chat-get ))"= — pop the chat buffer for Craig to read/handle by hand (useful when a real DM needs a considered reply). diff --git a/working/triage-telegram-down-launch/triage-intake.telegram.org.superseded-1723 b/working/triage-telegram-down-launch/triage-intake.telegram.org.superseded-1723 new file mode 100644 index 0000000..497f74b --- /dev/null +++ b/working/triage-telegram-down-launch/triage-intake.telegram.org.superseded-1723 @@ -0,0 +1,273 @@ +#+TITLE: Triage Intake — Telegram Source +#+AUTHOR: Craig Jennings +#+DATE: 2026-06-09 + +# Source plugin for the triage-intake engine. See triage-intake.org for the +# contract and the Phase A-D orchestration. This file declares ONE source. +# +# General (personal) source: Telegram via the Emacs telega.el package (tdlib +# backend). It lives in .ai/workflows/ and is template-synced, sitting with the +# other general personal sources (personal-gmail, cmail, personal-calendar, +# signal, github-prs) — not the project plugins. Telegram is personal +# messaging, not project-specific. +# +# Unlike signal-cli (a standalone CLI), Telegram has no headless CLI here. The +# client is telega.el running inside Craig's long-lived `emacs --daemon`, so the +# plugin drives it over `emacsclient -e`. tdlib keeps a persisted session in +# ~/.telega (td.binlog), so a started telega reconnects without re-auth. + +* Source: telegram +:PROPERTIES: +:ORDER: 24 +:ENABLED: command -v emacsclient && emacsclient -e "(or (featurep 'telega) (fboundp 'telega))" | grep -q t +:ANCHOR: none +:SUBAGENT_OVER: 40 +:END: + +** Quick reference — full lifecycle + +Telega does not autostart with the Emacs daemon. "Down" is its normal state +unless Craig has Telegram open in Emacs. The scan therefore runs the full +lifecycle every time, never skips because the server is down: + +1. Record prior state: TELEGA_WAS_RUNNING via (telega-server-live-p). +2. Launch (only if not running): + emacsclient -e "(progn (setq telega-use-docker t) (telega t) 'started)" + The setq is mandatory defense: tdlib segfaults outside docker mode + (2026-06-09), and Craig's daemon currently has telega-use-docker nil. + Wait ~2s for Ready, then (telega--loadChats 'main) until telega--chats + is populated. +3. Check messages: the maphash unread scan in ** Scan Step 2 (filters the + messageContactRegistered join-notice noise). +4. Send (needs the server live; /voice personal first — Telegram + occasionally carries WORK communication to Kostya and Vrezh, so treat + sends with the same care as Slack): + emacsclient -e "(telega-chat-send-msg (telega-chat-get ) \"\")" +5. Shutdown (ONLY if step 1 recorded not-running): + emacsclient -e "(progn (telega-server-kill) (ignore-errors (telega-kill t)) 'stopped)" + Verify: telega-server-live-p → nil, no zevlg/telega-server container in + docker ps. If Craig had it running, leave it untouched. + +If any lifecycle step fails (docker image missing, server crash, daemon +unreachable), the sweep reports it as SCAN FAILED at the top of the summary +per the engine's failure rule — never as a silent skip. Craig gets real +traffic here. + +** Scan + +Telegram direct messages and groups via telega.el in the running Emacs daemon. +=ANCHOR: none= because telega reports live unread *state* (each chat's +=:unread_count=), not a since-window — the engine substitutes no cutoff. Phase B +uses each message's timestamp only to order and label recency. + +The scan reads the =telega--chats= hash table (chat-id → chat plist), which +telega populates as chats sync. *This is robust to the tdlib server crashing +mid-session* (see the SEGFAULT gotcha below): the hash retains the last-synced +unread counts and =:last_message= even after the server dies, so a scan reading +the hash still returns the most recent known state. + +*** Leave-no-trace lifecycle (start only if needed, shut down only if we started it) + +telega is a long-lived client inside Craig's daemon. If he already has it +running, the scan must leave it running. If it's *not* running, the scan starts +it for the read and shuts it down cleanly afterward, restoring the daemon to its +prior state. The discipline: *record the prior liveness, branch on it at the +end.* + +*** Step 0 — record prior state + +#+begin_src bash +# t if telega's tdlib server was ALREADY live before this scan, nil otherwise. +# Hold this value; Step 3 reads it to decide whether to shut telega down. +TELEGA_WAS_RUNNING=$(emacsclient -e "(and (fboundp 'telega-server-live-p) (telega-server-live-p) t)" 2>/dev/null) +#+end_src + +*** Step 1 — start (docker mode) if not already running, wait for Ready + +#+begin_src bash +# `(telega t)` starts without popping the root buffer. Docker mode (the stable +# path — see the SEGFAULT gotcha) reconnects the persisted ~/.telega session in +# ~2s. Then load the main chat list so telega--chats populates. +# +# The `(setq telega-use-docker t)` is mandatory and must come BEFORE `(telega t)`: +# tdlib segfaults in native mode (SEGFAULT gotcha below), and the daemon's default +# is nil unless something (e.g. an Emacs-config :custom) has already forced it. It +# was missing here while the Quick Reference and the gotcha both require it — +# a session that started telega without it on a native-mode daemon would crash the +# server, surfacing as a triage SCAN FAILED. Match the Quick Reference exactly. +emacsclient -e "(progn + (setq telega-use-docker t) + (unless (and (fboundp 'telega-server-live-p) (telega-server-live-p)) (telega t)) + 'started)" +# Poll until Ready with chats synced, or a crash/timeout. Background this with an +# until-loop so the wait doesn't block; exit on Ready-with-chats OR an abnormal +# server exit. Then force a chat-list load if the hash is thin: +emacsclient -e "(progn (ignore-errors (telega--loadChats 'main)) (ignore-errors (telega--loadChats 'main)) 'loaded)" +#+end_src + +On a persisted session telega reaches status "Ready" within ~2s; the chat list +loads over a few more. If =(hash-table-count telega--chats)= is 0 or thin, +re-issue =telega--loadChats= and poll until it stabilizes. + +*** Step 2 — read unread, classified by last-message type + +The single most important filter: =messageContactRegistered=. Telegram counts a +" joined Telegram" service notice as one unread message, so every contact +from Craig's old address book who ever joined shows as a 1-unread "DM" *that +person never actually sent*. On the 2026-06-09 first scan this was 30 of ~50 +unread chats. Drop them entirely (tally only). + +#+begin_src bash +emacsclient -e "(let (real svc other) + (when (boundp 'telega--chats) + (maphash (lambda (id chat) + (let* ((uc (or (plist-get chat :unread_count) 0)) + (lm (plist-get chat :last_message)) + (ctype (when lm (plist-get (plist-get lm :content) :@type))) + (title (or (ignore-errors (substring-no-properties (telega-chat-title chat))) \"?\"))) + (when (> uc 0) + (cond + ((equal ctype \"messageContactRegistered\") (push title svc)) + ((member ctype '(\"messageText\" \"messagePhoto\" \"messageVideo\" \"messageDocument\" \"messageVoiceNote\" \"messageSticker\" \"messageAnimation\")) + (push (list title uc ctype) real)) + (t (push (list title uc (or ctype \"nil\")) other)))))) + telega--chats)) + (list (cons 'real (nreverse real)) + (cons 'joined-telegram-count (length svc)) + (cons 'other (nreverse other))))" +#+end_src + +For a chat that survives as Action-worthy, pull the last message's text to +classify and summarize: + +#+begin_src bash +# from the maphash key (the scan can also return ids alongside titles) +emacsclient -e "(let ((c (gethash telega--chats))) + (substring-no-properties + (or (telega--tl-get c :last_message :content :text :text) \"\")))" +#+end_src + +*** Step 3 — restore prior state (shut down only if we started it) + +#+begin_src bash +# If telega was NOT running before this scan, shut it down cleanly to leave the +# daemon as we found it. If Craig already had it running, leave it alone. +if [ "$TELEGA_WAS_RUNNING" != "t" ]; then + emacsclient -e "(progn (ignore-errors (telega-server-kill)) (ignore-errors (telega-kill t)) 'killed)" +fi +#+end_src + +⚠ *In docker mode, =telega-kill= alone is not enough.* =telega-kill= buries the +telega buffers but leaves the dockerized tdlib server running (=telega-server-live-p= +stays non-nil). =telega-server-kill= is what actually stops the server. Call +*both* — server-kill then kill — for a clean teardown. Verified clean afterward: +=telega-server-live-p= → nil, root buffer gone, no =zevlg/telega-server= container +left in =docker ps=. Skipping this whole branch when =TELEGA_WAS_RUNNING= is t is +the point of Step 0: never tear down a session Craig is actively using. + +⚠ *SEGFAULT GOTCHA — crashes are spontaneous; treat server death as routine.* +The dockerized =telega-server= (=zevlg/telega-server:latest=, image built +2026-06-04, tdlib 1.8.64) SIGSEGVs (exit 139) *on its own*, minutes-to-hours +into a session — 11 host coredumps between 2026-06-09 and 2026-06-11, several at +times when no triage verb was running. The 2026-06-11 investigation reproduced +the crash-free verbs and the spontaneous deaths side by side: coredump +backtraces show a corrupted stack (memory corruption in the musl build), and +no newer image exists upstream. Earlier theories — "native mode is the trigger", +"toggle-read is the trigger" — were timing coincidences; the verbs are sound. + +Operationally: docker mode stays mandatory (=telega-use-docker= = t; the setq +before =(telega t)= is still the right defense), and *every action batch checks +the server first* — =(process-live-p (telega-server--proc))= — restarting via +=(telega t)= when dead and re-checking Ready before firing verbs. A mid-sweep +death is recoverable, not an abort: restart, confirm Ready, resume. Durable-fix +candidates if the crashing gets worse: pin a pre-2026-06 image digest, build +=telega-server= natively against tdlib, or report upstream to zevlg with the +coredumps (=coredumpctl list /usr/bin/telega-server=). + +Defense in depth: even if the server does die, the scan still works because it +reads the cached =telega--chats= hash, not a live query. A dead server is +*scan-only* — you can still report unread state, but cannot read new bodies, mark +read, or reply until it restarts. Treat that as "scan-only, no actions this run" +and say so. + +** Classify + +Bias: Craig's personal Telegram is *spam-dominated* with a thin layer of real +signal. The opposite of Signal (high signal/low volume) — here the volume is +high and almost all noise. Filter aggressively; surface only the few real +threads. Kostya and Vrezh occasionally reach Craig here, so a real DM from a +work contact is Action, full stop. + +- *Noise-trash (tally only, never itemized):* + - =messageContactRegistered= "joined Telegram" notices — always noise, no + matter whose name is on them. The real contacts Craig knows live here; a + join notice is not a message from them. + - Romance/crypto spam DMs — the signature is an emoji-laden handle or a + two-word "RealName + FantasyWord" suffix (=Gayle ⚾🤎RoyalVineyard=, + =Cherie🌷🏰 InfiniteRhapsody=, =Jane 🍒🔥=, =Luna Skye=). One unread, + unsolicited, no prior thread. + - =Deleted Account-NNNN= threads, blank-title chats, bot channels + (=Z-Library Official=), Telegram's own =✔️Telegram= service notices. +- *Noise-keep (never reported):* unread in dev-community groups Craig follows — + =GNU Emacs=, =zed=, =Kitty=, and similar. Skipped in sweep reports entirely — + not even a name + count line — unless Craig specifically asks about them + (Craig's ruling, 2026-06-11, via the work project's handoff). Leave them + unread; they're reading material, not signal. +- *Action:* a real text/voice/media message from a *known personal contact* in + an existing one-to-one thread — an explicit ask, a question, a reply owed. On + a spam-heavy account these are rare; when one appears, surface it prominently + with the sender + gist, because it's the needle in the haystack. + +The 2026-06-09 calibration run: 30 join-notices + ~10 spam/deleted/bot + 3 dev +groups + 0 real personal DMs. Expect most sweeps to look like this — a clean +"nothing real" is the common, correct result. + +** Render + +#+begin_example +**Telegram — N unread chats (M real after filtering).** +- Action: +- Noise: K joined-Telegram notices, J spam/bot/deleted (tally only) +#+end_example + +Dev-community group traffic never appears here — no FYI line, no name + count — +unless Craig asks for it in that sweep (2026-06-11 ruling). Real DMs from known +contacts still surface as Action. + +Omit the block entirely when there's nothing but group traffic, join-notices, +and spam — under the engine's deltas-only rule that's a no-change source. Render +the block only when there's an Action item or a Noise tally worth a state-change +suggestion (e.g. a trash batch). + +** Actions + +Actions need the tdlib server *live* (see the SEGFAULT gotcha — a dead server is +scan-only). All run through telega in the daemon: + +- reply :: =emacsclient -e "(telega-chat-send-msg (telega-chat-get ) \"\")"= — public-facing (goes out under Craig's name), so run =/voice personal= before sending. Prefer a body file for multi-line. +- mark-read :: verified 2026-06-11 (the previously documented =telega-chat--mark-read= never existed in telega). The idempotent per-chat verb: + + #+begin_example + emacsclient -e "(let ((chat (telega-chat-get ))) + (telega--viewMessages chat (list (plist-get chat :last_message)) + :source '(:@type \"messageSourceChatList\") :force t) + (telega--readAllChatMentions chat) + (telega--readAllChatReactions chat))" + #+end_example + + =telega-chat-toggle-read= also works but *toggles*: on a chat with zero unread it marks the chat UNREAD, so scripting must guard on =(> (plist-get chat :unread_count) 0)=. Never mark the whole account read blindly; a real DM is handled deliberately, not swept. +- delete-join-notice :: standing policy (Craig, 2026-06-11): a chat whose *newest* message is a =messageContactRegistered= "joined Telegram" notice is a chat Craig never responded to and doesn't want to keep — *delete it* rather than mark it read. The bulk sweep (returns the count deleted): + + #+begin_example + emacsclient -e "(let ((n 0)) + (maphash (lambda (_id chat) + (when (equal (plist-get (plist-get (plist-get chat :last_message) :content) :@type) + \"messageContactRegistered\") + (telega--deleteChatHistory chat t nil) + (setq n (1+ n)))) + telega--chats) + n)" + #+end_example + + =telega--deleteChatHistory chat t nil= removes the chat from the list on Craig's side only (no revoke). First run 2026-06-11 deleted 41 such chats and cut the unread-chat count from 48 to 16. +- open :: =emacsclient -e "(telega-chat-with (telega-chat-get ))"= — pop the chat buffer for Craig to read/handle by hand (useful when a real DM needs a considered reply). -- cgit v1.2.3