Repository navigation
Conversation
… the control plane The autonomous scheduler called participant_runtime.initialize with the apply's live working snapshot and adopted the returned snapshot unchecked, so an initialize could write runtime-owned metadata or drop accepted resource entries while the apply reported success. The control plane already invokes the same backend method through _call_backend_apply with participant_effect_authority. _ensure_participant_episode now calls it through _call_backend_apply with the same participant effect authority, so the arguments are detached and the result may change only participant-owned state for the named participant. Unlike the control plane call, it passes no information-state context resolver. ASR-532 now traces the scheduler module and the new regression test.
doublewhy
force-pushed
the
1439-participant-initialize-gate
branch
from
October 9, 2026 13:26
8e966c6 to
a173304
Compare
doublewhy
marked this pull request as ready for review
October 9, 2026 15:31
9 of 11 tasks
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The autonomous participant scheduler initialized participant episodes by calling
participant_runtime.initialize(request, snapshot)directly fromparticipant_scheduler_initialization._ensure_participant_episode. It passed the apply's live working snapshot and adopted whatever snapshot came back. Ondevat 3512210, using the DSL-437 autonomous fixture:initializethat wrotesnapshot.metadatahad that write committed;initializethat returned a snapshot without the accepted entries left 9 of the 25 entries the honest run commits.Both applies reported success. The control plane already gates the same backend method:
initialize_participant_episodereaches it through_call_backend_applywithparticipant_effect_authority(request, snapshot).The scheduler now invokes
initializethrough_call_backend_applywith the same participant effect authority. The arguments are detached, and the result may change only participant-owned state for the named participant. Ondevan exception raised byinitializepropagated out ofRuntimeManager.apply(); it now fails the apply with a diagnostic. Unlike the control plane's call, it passes no information-state context resolver. The stub, libvirt and reference participant runtimes inheritBaseParticipantRuntime.initialize, which writes only participant episode results and history.Requirement UIDs
ASR-532(Runtime Backend Result Integrity). Its normative contract,specs/formal/runtime-contracts/backend-result-admission.md, applies to "direct-manager and authenticated control-plane backend invocation", requires "an isolated immediate predecessor", and says a backend "MUST NOT ... change unrelated resources, or mutate runtime-owned metadata or provenance". This PR adds the scheduler module and the new regression test to the ASR-532 record's Traceability.Related Issues
Closes #1439
ADR Impact
specs/formal/runtime-contracts/backend-result-admission.mdas a normative contract; this change follows it and changes no ADR text.Changes
implementations/python/packages/raes_runtime/participant_scheduler_initialization.py:_ensure_participant_episodebuilds theParticipantEpisodeInitializeRequestonce and callsparticipant_runtime.initializethrough_call_backend_apply, withrealization=participant_effect_authority(request, snapshot)and the addressruntime.participant-scheduler.<participant>.initialize. A refused result fails the participant execution phase withruntime.backend-contract-invalidand keeps the predecessor. An exception frominitializenow also fails the phase and keeps the predecessor, instead of propagating out ofRuntimeManager.apply():TypeErrorandValueErrorgiveruntime.backend-contract-invalid, and any otherExceptiongivesruntime.backend-call-failed. The call passes no_BackendCallContext, so it has no information-state context resolver, and the code comment says so.implementations/python/tests/test_issue_1439_participant_initialize_gate.py(new), on the DSL-437 autonomous fixture (_scenario_yaml,_autonomous_manifest,_NativeParticipantRuntime):initializethat writes its snapshot argument, and one that returns a snapshot without the accepted entries. Each makes the apply fail withruntime.backend-contract-invalid. The forged metadata is not committed, no episode result is committed, and the provisioned entries equal the honest run's.docs/requirements/ASR-532/requirement.md: two Traceability lines,IMPLEMENTS → CODE_FILEfor the scheduler module andTESTS → TESTfor the new test module, andupdated_atset to 2026-10-09.tools/research_evidence.pyimplementation_digest()hashes every package.py:execution-snapshot-v69.json,analysis-v69.json, issue-1439 bundle) replays the retained matrix against this branch's source.execution-snapshot-v70.json,analysis-v70.json,retest-v70.json) replays the retained formal cases with baseline 69.0.0. None of the 27 replayed cases changed digest or outcome, and no deviation is recorded.tools/check_specification_coverage.py,tools/formal_semantic_validation/, and the three evidence test modules. Both research indexes record the new releases.Test Plan
uv run --project implementations/python --frozen --all-extras python -m pytest implementations/python/tests/test_issue_1439_participant_initialize_gate.py -q -p no:cacheproviderpassed (3 passed). With-m integrationit selects nothing (3 deselected), because all three tests use the default markers. Withdev'sparticipant_scheduler_initialization.pyswapped in, the same command failed both parametrized cases withassert True is False(the apply succeeded) and passed the honest case (2 failed, 1 passed). Every case runs the changed call, so the new lines are covered. The new module has no case whereinitializeraises, so a probe on the same fixture checked that path.RuntimeErrorgaveruntime.backend-call-failed, andValueErrorandTypeErrorgaveruntime.backend-contract-invalid. Each apply failed with the 16 provisioned entries kept and no episode result committed. Withdev's module swapped in, all three exceptions escapedRuntimeManager.apply().The 36 test modules that build autonomous policies, pass a participant runtime, use the participant scheduler or reuse the native participant runtime fixture passed: 962 passed. This command selects and runs them from the repository root:
uv run --project implementations/python --frozen --all-extras python -m pytest -q -p no:cacheprovider \ $(grep -lE 'autonomous_execution|_autonomous_manifest|ParticipantScheduler|participant_scheduler|participant_runtime=|_NativeParticipantRuntime' implementations/python/tests/test_*.py)They include the
test_dsl_437_*,test_act_614_*,test_issue_898_*andtest_issue_899_*modules,test_participant_concurrent_batch_reservations.pyandtest_issue_1204_targeted_effects.py. None of their tests is integration-marked: adding-m "integration and not docker"deselects all 962.tools/check_requirement_governance.py --base-rev origin/dev --requirement-uid ASR-532exited 1 before the record change, withtraceability-missing-implementsfor the scheduler module andtraceability-missing-testsfor the new test. With the two new lines it exits 0, also with--require-governance.After the republish,
tools/check_specification_coverage.pyandtools/check_formal_semantic_validation.pypassed underuv run --project implementations/python --frozen --all-extras. The three evidence test modules passed: 209 passed and 19 deselected with default markers, and 19 passed with-m integration.RAES_REQUIREMENT_UID=ASR-532 nox -s verify-fast-feedback -- --base-rev origin/devpassed every stage, including requirement governance; YAML syntax was skipped because no YAML file changed. It ran the four directly changed test modules (212 passed, 19 deselected).nox -s lintpassed.CI resolves no requirement UID from this branch name, and the branch has no requirement scope file, so CI skips the requirement governance stage.
Ground Control Checks
RAES_REQUIREMENT_UID=ASR-532 make policypassed every stage, including requirement governance for ASR-532. No pre-push Codex or test-quality review was run for this lane.Traceability
raes_runtime/backend_realization_authority.py) to the backend call gate. feat(realization): admit prepared completions and validate delivered state #1251 addedparticipant_effect_authorityand applied it to the control plane's participant actions incontrol_plane_execution.py. Re-checking that backend-authority work against currentdevfound this scheduler call outside the gate.Checklist
CHANGELOG.mdfrom it)