Repository navigation
Fail the Session when its hosted Environment fails to provision - #81
Merged
Merged
Conversation
The shared Runtime initializer now adds exit_code to its failed receipt when a setup command or package manager run through bwrap exits nonzero. It never serializes the exception, command, input or child output; Runtime-internal helpers, signals and other errors keep the generic receipt.
A hosted initialization failure now records, in the allocation's cleanup transaction, the failed Environment with a safe reason and failure time (additive nullable migration 000061), agent.session.environment.failed with the observed environment_error/environment_connection_failed payload, an error event (environment_error/sandbox_error, param null) and one agent.session.failed snapshot. Session retrieve, list and events derive status failed, the reason and last_active_at from that record; GET and creation streams end after the failed event; new input returns the observed 409 conflict_error. Pending-input settlement, expiry, self_hosted and none are unchanged. The reason names only a fixed step label and the Runtime-reported exit status of a confirmed failed step; unknown effects, timeouts and receipts without an exit status use a generic reason. Command, package-manager and file output is never copied.
Error events other than Core's stream_interrupted now reach onEvent as AgentSessionErrorEvent before the failed snapshot instead of raising, and stream errors accept the pinned nullable param.
Record rows H1-H8 with the HI-01..04 evidence, the initialization failure lifecycle and reasons, the failure event sequence and stream end, the HF evidence register code and the updated Session operation rows.
The fixture's failed managed Environment now carries the step and exit status reason that Core reports for a hosted provisioning failure.
Main added 000061_project_api_keys.sql; the Environment failure columns move to 000062 unchanged.
The 000062 Down now locks environments and raises when any failure reason is recorded, following the repository's rollback guards. A migration test covers the additive upgrade, the column checks and both rollback outcomes.
Released clients validate exactly code, type and message on stream errors and would report the interruption as an invalid stream. Core's own interruption frame keeps that shape; the official-shaped hosted failure error event keeps param null. Both shapes are tested.
The contracts README and CONTRIBUTING said GET streams never end on their own; they now name the terminal hosted failure and Session deletion as the only server-side ends.
The docs called the failed receipt strict. The decoder deliberately ignores other fields so older images keep working; the only value taken from it is an integer exit_code from 1 to 255, and output fields are never read.
runRuntimeSetup and installInitialFile tests cover stderr, other process statuses, exit_code 0, 256, negative, null and mistyped, ignored and duplicate fields, raw output and a Plugin step. The store tests add the Skill label end to end, and the fake Provider now returns canary output in receipt fields; the HTTP test also scans captured logs for it.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
When an
openai_hostedEnvironment fails to provision, clients now see the failure the way the official service reports it. Core used to leave the Sessionidlewith no error and keep the stream open. Command, package-manager and file output is never exposed. The pinned baseline is unchanged (SDK 3.13.0 / d7c41ef /agents=v1).Behavior
agent.session.environment.failed,errorandagent.session.failed.failed,errorset to the safe reason,required_actions: []andlast_active_at.environment.failedcarries{type: environment_error, code: environment_connection_failed, message: "The environment failed to connect."}.errorevent carries{type: environment_error, code: sandbox_error, message: <reason>, param: null}.Failed to provision environment: script "setup_commands[0]" failed with exit code 3, orscript "Python package installation" failed with exit code 1.initialization did not complete.agent.session.failed.events.createon that Session returns 409conflict_error/conflict_error, "the hosted environment failed to provision". Expired Environments keep their previous response.000062adds nullableenvironments.failure_reasonandfailed_at.status = failedand at most 256 characters.stream_interruptedframes keep their{code,type,message}shape for released clients.errorevents toonEvent.Evidence
openai_hostedSessions without Turns, both deleted; raw frames recorded).environment-templates.md,history-events-usage.md,official-semantics-alignment.md,operation-evidence.md(register HF) and the READMEs.Validation
Live acceptance on Core-managed Docker
openai_hostedwith Codex. Images, including each tree's initializer, were built from each tree and hash-checked. There was a fresh database per phase and no model Turns.exit 3: retrieve/listidle, no errorfailed, step and exit-code reason,last_active_atexit 3: streamenvironment.failed(generic), stayed openenvironment.failed,error,session.failed, then closedexit 3: inputenvironment_unavailableconflict_errorofficial messagefailedwith the Python label and exit code 1; same stream and 409All events and reads pass the pinned SDK's strict parse. Cleanup and secret scans passed.
Tests:
Server gate on this head: all
make checktargets, plus Web typecheck, core-doctor, unit tests and build, pass. The Playwright browser cases were not run on the server (no Google Chrome; the user approved the skip).make openapiandmake sqlc-generateare byte-identical.Independent blind review by a fresh Claude Code subagent (the user-approved replacement for GPT-6 Astra). It found no leak path, race or behavior blocker. Its follow-ups are fixed in the last commits:
stream_interruptedcompatibility;They were verified by focused tests and the gate without a new review, per the user's rule. The optional official
turn_id: nullon Environment events is deferred, because released clients accept only four fields there.Deferred decisions: HI-05 (delete during provisioning) and HI-06 (long setup steps). No full protocol compatibility is claimed.
Need help on this PR? Tag
@codesmithwith what you need. Autofix is disabled.