feat(turn): name the operator-reachable exits in a managed executor refusal - #4477
Conversation
…efusal Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Validation before merge (self-review; author-owned PR, GitHub blocks formal self-approval)Changed surfaces (6 files, +165/−2): Risk profile: additive readback on the governed Turn control path. No selection, Checks run
Failures / skips / manual holds: none. Not covered: no provider call is made, Why the coverage is enough: the change is a readback field set with no control English: additive, non-selecting readback on the managed Turn refusal path; canary |
What changes
A managed Turn that cannot launch already fails closed with one typed
unavailable_reason. That names the missing fact but not the way out, so anoperator on a fresh machine has to guess that
DEEPSEEK_API_KEYor--host codex-cliis the exit. This change makes the same refusal actionablewithout changing anything it selects.
managed_executor_bindinggainsunavailable_remediation: typed codes namingthe operator-reachable exits (
configure_operator_credential,configure_dsh_runtime,correct_execution_profile,select_individual_host).It is
[]for every launchable or non-managed executor, so the field is readthe same way in both states.
remediationand adds the concreteremediation_host(codex-cli) andremediation_env_vars(
DEEPSEEK_API_KEY), so no caller re-derives them from the reason string.managed_executor_remediation_projectionprojects that entry, and contributesnothing when no exit was named, so a launchable payload stays byte-identical.
nothing — acting on it is still an explicit credential, profile, or
--hostchange.
This is deliberately not the closed PR #4454: the shipped Turn host default
stays environment-independent and an uncredentialed machine keeps failing
closed. Only the readback becomes actionable.
Boundaries
available,unavailable_reason, and the fail-closedpath are unchanged; the new field is additive and empty on every happy path.
operator_credential.pyisuntouched; the new codes quote facts the binding already reports.
remediation_env_varsreports names only, never values.