Approval and restart clinic¶
Change the decision, enforcement, persistence, and crash point. The clinic separates a reported approval request from actual dispatch control, then uses an independent effect count to verify what happened across restart.
Read the result as three separate contracts¶
- Authorization: a pause must gate the actual dispatch. An advisory callback can report a request after work has already happened.
- Durability: pending operation, decision, and resume state must cross a process boundary as serializable data. Keeping a live runner in memory is not restart recovery.
- Effect safety: a crash after commit but before checkpoint creates an unknown outcome. Stable operation identity prevents replay from becoming a second effect.
The trusted caller supplies the decision in this fixture. A production approval must also bind approver identity, exact operation and arguments, expiry, and policy revision.
Produce the same run locally¶
python -m examples.harness.approval_lab --decision approve --crash after_effect --gated --durable --stable-operation
python -m examples.harness.approval_lab --decision deny --crash none --no-gated
pytest tests/test_approval_lab.py tests/test_learning_reliability.py -q
Then run the repository's framework-neutral behavior checks:
python -m pytest tests/test_suspend_resume.py tests/test_durable_state.py -q
The human_in_the_loop arena measures pause-before-effect and approved/denied outcomes. The durable_state arena discards the runner, JSON round-trips resume state, builds a fresh runner, and fails correct answers that repeated earlier tool work.
Read human approval evidence, durable-state evidence, and the restart problem note.
Next: Reliability and restart ยท Developer labs