verdict integrity: rejected outputs fail the instance, no hollow cache rows #9
Loading…
Reference in a new issue
No description provided.
Delete branch "lu/verdict-integrity"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What
Items 1, 2, 3 and 5 of docs/live-upgrades.md §7 ("Bugs found"), without protocol changes.
kb-control-plane/src/ws.rs). AnOutputsevent that cannot be applied — an expansion that does not parse/validate/materialize, a declared output that was not reported, or any storage error — marks the instancefailedwith exit classexpansion-invalid/outputs-invalidand writes the reason to the instance log, instead of rolling back and only logging. TheState{succeeded}that follows lands on a terminal instance and is ignored. Before this, an Expand in that position "succeeded" with no children: a false green the merge queue would land.record_result_if_donewrites aresultsrow only when the recorded outputs cover the def (every declared output; for anExpand, its expansion). A def that promises nothing is still cached with[].kb-agent/src/outbound.rs); log chunks remain the only droppable kind.ExitInfoclass list (comment only, no wire ordef_hashchange), TODO (lease self-abort shipped in0dd2e89; remaining lost-Outputsgap recorded — closed later by the atomicFinishedevent).Tests
tests/outputs_integrity.rs(new, end to end with the fake agent): unparseable expansion → expanderfailed/expansion-invalid, graphfailed, nothing materialized or cached; missing declared output →failed/outputs-invalid; success without promised outputs not cached, while a def promising nothing is still substituted.ws.rsunit test for the coverage rule;outbound.rsoverflow tests.tests/artifacts.rsnow declares thereportoutput it reports;tests/replay.rsseeds its legacy[]row by hand.🤖 Generated with Claude Code
An agent's report can no longer turn into a green verdict or a cache entry it does not back: - kb-control-plane: an `Outputs` event the control plane cannot apply (expansion that does not parse/validate/materialize, a declared output missing, any error storing it) fails the instance durably with class `expansion-invalid` / `outputs-invalid` and writes the reason to the instance log, so the `State{succeeded}` behind it is ignored as already terminal. Previously the transaction rolled back, an error was logged, and an Expand then "succeeded" with no children. - `record_result_if_done` writes a `results` row only when the recorded outputs cover the def: every declared output, or for an `Expand` its expansion. `[]` stays for a def that promises nothing. - kb-agent: the outbound queue never drops a non-log message when full with no log left to evict; it grows past the bound instead, and an incoming log is the one refused. - SPEC §5/§7.1/§9 state the new behaviour; TODO drops the shipped lease self-abort item and records the remaining lost-`Outputs` gap. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>@krisbuild r+
Merged as
cca3f8755c.