fix(runtime): restrict running effects to launch results and index history

Only the native detached launch (bg_job_id) or a bridge's explicit detachment
marks an operation's own work as RUNNING. A listing that reports some other
download/model/job as running settled normally; treating it as running left
the claim pending forever and could block required artifacts.

EffectHistory now indexes outcomes per effect once, removing a cubic scan in
assessment over long run lineages.

Adds adversarial coverage: browser page operations stay fail-closed through
the real dispatcher with effects enabled (no claim, never dispatched),
scheduler task triggers stay unverified admission, and assessment scales.
This commit is contained in:
Alexandre Teixeira
2026-10-02 20:13:24 +01:00
parent 3953ea2444
commit 75243fe0b0
4 changed files with 64 additions and 6 deletions
+15 -1
View File
@@ -33,7 +33,7 @@ def run(ws, tmp_path):
journal = ActionJournal(workspace=str(ws), observed_artifacts=("a.txt",))
journal.effects = EffectLog(journal.run_id, directory=tmp_path / "fx")
authority = RequestAuthority("request", "alice", "thread", str(ws), tuple(
OperationGrant(tool) for tool in ("write_file", "read_file", "edit_file", "apply_patch", "ls")))
OperationGrant(tool) for tool in ("write_file", "read_file", "edit_file", "apply_patch", "ls", "private_browser")))
async def call(tool, args):
content = args if isinstance(args, str) else json.dumps(args)
@@ -218,6 +218,20 @@ def test_listing_is_partial_and_does_not_verify_content(run):
assert verdicts(run.journal) == [fx.EffectVerdict.UNVERIFIED]
@pytest.mark.parametrize("args", [
{"action": "click", "page": "t1", "selector": "#buy"},
{"action": "open", "url": "https://example.com"},
{"action": "snapshot", "page": "t1"},
{"action": "evaluate", "page": "t1", "script": "1"},
])
def test_browser_page_operations_stay_fail_closed_with_effects(run, args):
description, result = run("private_browser", args)
assert "UNSUPPORTED" in description
assert result["failure_kind"] == "browser_page_authority_unavailable" and result["executed"] is False
assert run.journal.effects.history().claims == ()
assert run.journal.actions[0].execution_id is None
def test_ordinary_read_only_turn_completes_normally(run, ws):
(ws / "a.txt").write_text("existing\n")
run("read_file", {"path": "a.txt"})