Run 终止哲学

wesgine 的 Run 终止策略:无限制,有韧性(INV-TERM-01 / INV-TERM-04)。


核心原则

引擎不因 counter 阈值主动终止正常运行的任务。

Run 的终止只有以下合法来源:

来源说明
end_turn模型主动结束
用户中断POST /sessions/{sid}/interrupt
CycleDetector 自愈失败真循环,HITL 超时
ErrorStreak HITL 超时伪进展检测
BudgetCheckFn 返回 Exhausted外部商业限制
Cell Stop生命周期

INV-TERM-01

引擎不因 counter 阈值(轮次 / token / 时间)主动终止。

这些指标是观测值,不是终止条件。


INV-TERM-04:终端事件完整性

runLoop 的每个 return 路径必须在返回前发出终端事件:

事件含义
EventDone正常完成
EventError错误终止
EventInterrupted用户中断

context 取消场景

callLLM 和 execute 返回 phaseReturn 时,若 ctx.Err() != nil:

缺失终端事件的后果

terminal guard 合成虚假 EventError(missing_terminal_event):


终止路径清单

Run 可通过 11 种非 end_turn 路径终止:

  1. budget_exhausted
  2. cycle_detected
  3. quality_revision_limit
  4. context_cancelled
  5. cognitive_error
  6. execute_error
  7. panic_stop
  8. error_streak
  9. interrupted
  10. guardrail_blocked
  11. content_filter_blocked

每种终止路径都必须执行 CognitiveSettlement(唯一例外:panic_stop)。


错误重试分类

类别行为示例
可重试显示重试按钮Provider 503/429、cognitive_internal
不可重试柔和提示,无按钮guardrail_blocked、budget_exhausted
静默不渲染thinking_only_retrying、empty_response_recovered
用户中断压制context_cancelled、interrupted

分类由 engine-errors.ts 的 severity 字段控制。


一次性宽限调用

_budget_grace_call 机制:


RunEnd 摘要

Run 终止时引擎写入 role=system 摘要消息到 wes_messages: