Confirmed durability invariant violation
Reviewed master at 886c36d8ebe861aa987059a1744d45b78797baae (v4.7.0). Suggested priority: P1.
The outer tool-timeout path catches exceptions from after_tool_interrupted, logs them, and returns a normal timeout tool result. The model loop can continue and complete while the durable operation remains RUNNING, although its external outcome could be unknown.
Source: swallowed settlement error, durability contract and settlement.
Isolated integration reproduction
Use the existing fake-bot/write-invariant test factory with temporary databases. A scripted provider calls a mocked run_command; its fake executor begins and blocks. A short outer timeout cancels it. Inject a transient exception on the first interrupted ledger settlement, then allow subsequent storage operations. The scripted provider's next response says continued.
tool_started=True
ledger_failures=1
provider_generations=2
reply='continued'
turn=TERMINAL_COMPLETED
operation=RUNNING
Independently reproduced by two reviewers. No real command or provider request ran. The injected fault models a failed SQLite/fenced write; it does not prove an external effect occurred in the fixture. The dangerous fact is continuation without settled uncertainty after dispatch began.
Expected behavior / acceptance criteria
- Failure to durably settle an interrupted tool must stop the durable turn through the existing failure/escape path.
- Do not issue another model generation or present a completed turn while this ledger settlement remains unresolved.
- Preserve uncertainty and recovery evidence; do not re-execute the tool to discover what happened.
- Add fault injection specifically on the outer-timeout settlement branch and assert no next generation.
- Keep ordinary timeout handling unchanged when settlement succeeds.
Behavior change: turns with this rare storage failure halt rather than continue. This restores the advertised fail-closed behavior, rather than adding a new approval policy. No source changes were made.
Confirmed durability invariant violation
Reviewed
masterat886c36d8ebe861aa987059a1744d45b78797baae(v4.7.0). Suggested priority: P1.The outer tool-timeout path catches exceptions from
after_tool_interrupted, logs them, and returns a normal timeout tool result. The model loop can continue and complete while the durable operation remainsRUNNING, although its external outcome could be unknown.Source: swallowed settlement error, durability contract and settlement.
Isolated integration reproduction
Use the existing fake-bot/write-invariant test factory with temporary databases. A scripted provider calls a mocked
run_command; its fake executor begins and blocks. A short outer timeout cancels it. Inject a transient exception on the first interrupted ledger settlement, then allow subsequent storage operations. The scripted provider's next response sayscontinued.Independently reproduced by two reviewers. No real command or provider request ran. The injected fault models a failed SQLite/fenced write; it does not prove an external effect occurred in the fixture. The dangerous fact is continuation without settled uncertainty after dispatch began.
Expected behavior / acceptance criteria
Behavior change: turns with this rare storage failure halt rather than continue. This restores the advertised fail-closed behavior, rather than adding a new approval policy. No source changes were made.