Skip to content

Upward agent transfer HITL resume can skip a subsequent confirmation gate #7303

Description

@ITSMERNB

Summary

In the pre-fix workflow path, an upward agent transfer that interrupts for HITL input can leave the calling parent recorded as completed without the expected checkpoint. On resume, this can cause a later confirmation-gated step to execute without presenting the second confirmation.

This appears to be fixed by commit 198139ef31f8c51b723b58a7a74d8eb2eb15dc31; I am filing this primarily for tracking/backport awareness for affected releases.

Reproduction

A deterministic test used this flow:

parent A -> child B -> upward transfer to A -> HITL interrupt -> resume -> privileged successor

Two consecutive FunctionTool(require_confirmation=True) gates are used.

Control path:

  • turn 2 presents the second confirmation
  • privileged successor does not run before approval

Affected upward-transfer path:

  • turn 2 confirmation count: 0
  • privileged successor executed: ['PRIVILEGED_ACTION']
  • bypass result: True

Observed differential:

CONTROL TURN2_CONFIRMATION_COUNT 1
UPWARD TURN2_CONFIRMATION_COUNT 0
UPWARD TURN2_EXECUTED ['PRIVILEGED_ACTION']
UPWARD_BYPASS_CONFIRMED True

Revisions

  • Pre-fix revision tested: 8f1323ae6daf5cc6a8dfa33703cb4a682990af47
  • Fix/candidate: 198139ef31f8c51b723b58a7a74d8eb2eb15dc31

The fixing commit notes the same underlying state problem: after an upward transfer that interrupts, the caller could previously be recorded COMPLETED while execution was actually waiting for user input, with no checkpoint emitted.

Expected behavior

An interrupted transfer must remain resumable from the correct execution context, and every later confirmation-required tool/action must still present its confirmation gate before execution.

Actual behavior on the affected revision

The upward-transfer resume path can lose the expected checkpoint/state relationship and proceed past the next confirmation gate.

Impact

This is primarily a workflow/HITL correctness issue. In applications that depend on sequential confirmation gates, the affected state transition can cause a later state-changing action to run without the expected second approval.

No destructive action was used in the reproduction; the privileged action was a benign test marker.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions