1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
//! Settling a tool window nothing will finish (§2.9 stop, §6 crash).
//!
//! A tool window that ends without answers — the §2.9 stop cascade
//! felled it, or its executor died outright — leaves the step's
//! model-output entry committed (§2.5 — the assistant entry lands
//! before any tool runs) while some of its `tool_use` blocks have no
//! committed `tool_result`. Left that way the branch tip is unpaired:
//! `litany advance` declines it loudly (`Error::UnpairedToolUse`), so
//! no deposit could ever revive the agent — a stop would retire the
//! branch instead of ending the work it had in flight (contradicting
//! §2.9 "a stop is not a locked door … a message into the stopped
//! agent's inbox starts a driver and resumes the same branch"), and a
//! crash would strand it until a human forks from history.
//!
//! So the window is **settled**: one in-band `is_error` `tool_result`
//! per unanswered `tool_use` id — the same shape a grant decline and a
//! control refusal already commit ([`super::refusal`],
//! [`super::seam::refusal_text`]) — saying why there is no output. The
//! tail is then settled, the warrant is `ModelCallDue`, an ordinary
//! deposit revives the agent, and the model reads *in band* what
//! happened, which is both the truthful record and the useful one. Two
//! settlements, two sentences: [`interrupted`] is the stopped exit
//! settling its own window on the way out (§2.9, bl-b98d);
//! [`crashed`] is the next drive settling a window whose executor died
//! without one (§6, bl-4187 — reached from
//! [`crate::prompt::dispatch::advance`], before delivery, so the
//! settlement lands ahead of any mail and composes wire-legal under
//! §2.3's positional pairing).
//!
//! Deleting the tail — what the dispatch commit does at a **fork**
//! ([`super::super::step_commit::unsettled`], §2.3 step 2) — is the
//! wrong repair in either case: that tail belongs to the agent's *own*
//! branch, where discarding it would throw away the assistant's
//! reasoning and leave the model with no evidence it was ever cut off.
//!
//! A **hold** is deliberately not settled (§3.3 *Tool control*): a
//! parked branch's unpaired tail is its state, and its mark asserts
//! nothing at or past the held block ran. Both entries here run only
//! where no live mark governs the window: the stopped exit makes any
//! mark stale by §3.3's own rule, and the drive boundary adjudicates
//! the mark before it ever reaches the crash settlement.
use transcript;
use ToolWindow;
use crate;
use Content;
use Path;
/// Commit an interrupted `tool_result` for every `tool_use` in
/// `assistant_content` still unanswered, and report the window stopped
/// (§2.9, bl-b98d).
pub
/// Commit a died-executor `tool_result` for every `tool_use` in
/// `assistant_content` still unanswered (§6, bl-4187): the drive
/// boundary found a markless unpaired window — its executor's lease
/// was kernel-released mid-window, the one way such a window exists.
pub
/// The shared settlement: one in-band `is_error` `tool_result` per
/// unanswered `tool_use` id, worded by `text`.
///
/// Idempotent by construction: the answered ids are read from the
/// transcript (the record, never a stored cursor — PRINCIPLES single
/// source of truth), so results committed before the window ended —
/// and settlements a prior entry already committed — keep the one
/// entry they already have.
/// The in-band text an unanswered invocation carries as its `is_error`
/// `tool_result` — why there is no output, in the terms §2.9 gives it.
/// No result envelope and no exit code: nothing returned, so none is
/// invented (§3.3, the [`super::seam::refusal_text`] discipline).
/// The crash settlement's sentence (§6): unlike a stop, a died executor
/// recorded nothing, so whether the invocation ran at all is unknown —
/// said plainly, and the re-issue judgement left to the reader, the
/// only party with context to make it.