Repository navigation
fix(agent-loop): recover disabled capability calls - #6840
Conversation
|
Caution The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased. |
📝 WalkthroughWalkthroughDisabled-capability model calls now produce a model-visible ChangesCapability rejection recovery
Estimated code review effort: 3 (Moderate) | ~20 minutes Sequence Diagram(s)sequenceDiagram
participant Model
participant Gateway
participant DefaultRecoveryStrategy
Model->>Gateway: invoke disabled builtin.spawn_subagent
Gateway->>DefaultRecoveryStrategy: outside_capability_surface invalid output
DefaultRecoveryStrategy-->>Model: model-visible error observation
Model->>Gateway: repaired follow-up response
Possibly related issues
Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
🔎 Review · PR #6840
GitHub request failed IronLoop could not complete a required GitHub request. Automatic · PR opened · attempt 1 of 3 · failed after 2m 9s Failure details
|
Coverage ratchetReborn integration-tier coverageLine coverage (Reborn crates): 85.73% — 313881 / 366127 lines Per-crate breakdown (60 crates, lowest-covered first)
This table itself is informational and never gates the PR on its own — not the percentage, not the per-crate holes, not the 0-coverage callout. A separate coverage ratchet (dry-run until enforce=true; see tests/integration/coverage-floor.toml) can fail the build on specific configured floors. Exemptions (3 entry/entries excluded from the accounting above)
|
|
🚅 Deployed to the ironclaw-pr-6840 environment in ironclaw-ci-preview
|
* fix(agent-loop): recover disabled capability calls * test(agent-loop): address recovery review
Summary
outside_capability_surfacemodel-output failures an immediate typed recovery observation instead of spending generic blind retries first.spawn_subagentintegration pin so the run completes after a corrective model turn while proving zero dispatch and zero successful capability results.Change Type
Linked Issue
Closes #5583
Related #6284
Validation
cargo fmt --all -- --checkcargo clippy --all --benches --tests --examples --all-features -- -D warnings— Not run: targeted clippy was selected for the changed crate and integration binary.cargo build— Not run separately: both test suites compiled the affected production and integration paths.ironclaw_agent_loopandreborn_integration_tool_callcargo test --features integrationif database-backed or integration behavior changed — Not applicable: no database or feature-gated backend behavior changed.review-prorpr-shepherd --fixwas run before requesting review — Equivalent multi-agent review completed across eight lenses; both findings were fixed and revalidated.Test Strategy
User behavior: A hallucinated call to a disabled capability receives a precise model-visible observation, gets one corrective model turn, and completes without reporting or executing the rejected call.
Risk areas:
Tests added or updated:
OutsideCapabilitySurfaceobserves immediately and aborts if repeated.tool_call.rsscenario through the real product, runner, loop, gateway, and capability-surface chain.What the tests prove:
reason=outside_capability_surface.Commands run:
Security Impact
Capability-surface enforcement is unchanged and still rejects the disabled call before registration or dispatch. This changes only the model recovery policy after that rejection, using a typed host-authored observation with no provider-supplied detail.
Reborn Trust-Boundary Checklist
ModelErrorRecoveryObservationcontrol message.rg -n "OutsideCapabilitySurface|outside_capability_surface" crates tests/integration.serde(default)fields fail closed or have migration tests: Not applicable; no serialized fields changed.InvalidOutput(OutsideCapabilitySurface)remains unchanged.Database Impact
None.
Blast Radius
Limited to agent-loop recovery for the already typed
OutsideCapabilitySurfaceinvalid-output reason and its existing whole-turn integration scenario. Gateway filtering, capability registration, dispatch, result persistence, and other invalid-output recovery classes are unchanged.Rollback Plan
Revert this PR (commits
8ad550fcband1a91968a2). This restores the prior generic invalid-output retry policy and the old terminal integration pin without schema or compatibility work.Review Follow-Through
Reviewer judgment requested on the deliberate one-attempt policy: a repeated outside-surface violation remains terminal after the model has received the precise correction once. No known follow-up is required in this scope.
Review track: C (runtime error-recovery behavior)