From 42ac29eacc4d743ed2df7db0f886b99111d9e68b Mon Sep 17 00:00:00 2001 From: kshitijk4poor <82637225+kshitijk4poor@users.noreply.github.com> Date: Thu, 27 Aug 2026 20:19:54 +0530 Subject: [PATCH] =?UTF-8?q?docs(cron):=20comment=20accuracy=20=E2=80=94=20?= =?UTF-8?q?booking=20is=20fail-open=20on=20probe=20errors;=20cross-ref=20s?= =?UTF-8?q?tatus=20vocabulary?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Review follow-up on the #93829 salvage: the block header said 'fail-closed' while probe-error behavior deliberately keeps cron_complete (fail-open); and the pathological-status tuple now cross-references the classifier's vocabulary in hermes_state so drift is caught at the source. --- cron/scheduler.py | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/cron/scheduler.py b/cron/scheduler.py index 331ddfb0d6..a96b4175ae 100644 --- a/cron/scheduler.py +++ b/cron/scheduler.py @@ -6821,7 +6821,7 @@ def run_job( break except (Exception, KeyboardInterrupt): continue - # Fail-closed completion booking (#93820): the run may only be + # Verified completion booking (#93820): the run may only be # recorded as cron_complete when the session's LAST message row is # a real assistant reply — a plain answer or the [SILENT] sentinel # (both are assistant-text rows, so both classify as 'complete'). @@ -6830,9 +6830,12 @@ def run_job( # call / user prompt and must not surface as a healthy run. # session_lifecycle_statuses is the existing cost-bounded # classifier for exactly this shape. Only a POSITIVELY recognized - # pathological status downgrades the booking: an unknown value - # (newer classifier shape, test doubles) keeps the historical - # reason, and so does a failed probe — classification is + # pathological status (see the status vocabulary in + # hermes_state's session_lifecycle_statuses docstring — keep the + # tuple below in sync when it grows) downgrades the booking: an + # unknown value (newer classifier shape, test doubles) keeps the + # historical reason, and so does a failed probe — the booking + # itself is FAIL-OPEN on probe errors, because classification is # best-effort metadata and must not mislabel a healthy run. _end_reason = "cron_complete" try: