pub fn check_turn_loop_pairing(journal: &Journal) -> CheckResultExpand description
turn-loop-pairing — the tool loop’s contract: every call the model
requested is resolved exactly once before the next prompt is assembled,
nothing is executed that the model never requested (phantom execution),
and no result arrives for a call that was never made or was already
resolved.
The crash carve-outs are deliberate: unresolved calls before a resume
were orphaned by the crash (expected — the replay of their side effects
is effect-exactly-once’s territory), and a journal that simply stops
mid-turn records a crash, not a defect. Only a session that claims
completed with dangling calls fails here.