Conversation
XuPeng-SH
force-pushed
the
refactor/runtime-responsibility-cleanup
branch
from
October 4, 2026 16:14
abdba93 to
164f0b4
Compare
8 of 10 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Retire three protocols that no longer own production execution: local recovery retry/replay bookkeeping, the unwired RuntimeEnvironment/FakeRuntime execution API, and test-only host judgment overrides. Recovery now uses the existing owned checkpoint validator; Work and skill judgment tests exercise the actual provider response boundary. Live harness follow-up also keeps command budgets out of model arguments and reconciles tool evidence by its owning run.
Related issue
Responsibility cleanup of existing runtime contracts; no new subsystem or database schema.
Change type
User and compatibility impact
Crash recovery offers continuation after acknowledging unknown effects, or abort. It no longer claims it will replay or skip tools: the retired choices did not execute tools. Owner-scoped checkpoints, canonical journal recovery and policy/capability checks remain authoritative. Removed unwired execution APIs have no in-repository production callers. No compatibility layer or migration is added.
Bash callback requests carry a required
command_timeout_cap_msseparate from the delivery deadline. CLI execution preserves original model arguments for approval and journal evidence. Missing or invalid command authority fails closed. Server terminal tool summaries remain authoritative when CLI records cover only local executions.Architecture and complexity delta
d5cf67352: implementation/helpers −1,378; tests −1,612; docs +12; manifests/lockfile −2. Total −2,980. File moves are not counted as reduction.Verification
make checkpassed; strict workspace nextest: 21,204 passed, 800 skipped; workspace doctests and CLI/Server/harness production builds passed. Both child transcript journeys, the terminal-storage admission barrier and executable identity regression passed.164f0b413; the live Server health check confirmed that same SHA with database and Memoria connected.read_only_source_review_compliance,session_tool_result_artifact_recovery,skill_discovery_uses_skill_tool, andwork_auto_decomposition_journey. Execution model:deepseek-flash. All 60 deterministic criteria passed.qwen3.8-maxwas configured as the judge model, but these cases contain no LLM-judge criterion.bashandintrospect; Skill invocation is counted once.Final checklist