What would you like to be added?
Give the immediate POST /executions route the same payload separation the deferred reserve/start path and the managed-runtime-provider/1 protocol already have: accept the tool payload separately from the stored reference, so callers never persist tool arguments in reference_json.
Today the deferred path reserves a four-field reference and takes the exact payloadJson only at start, and provider reservations use a seven-field reference with no payload. The immediate route still reads toolName/input from the stored reference map (HttpRuntimeTransport.execute), so a caller of that route must write full tool arguments — for write_file/edit, complete file contents — into the Broker's durable reference_json, which the tool contract's §4.1 forbids for durable state.
The fix must keep the deferred raw reference shape pinned by FaultGateControlTest (exactly sessionId, promptId, callId, argsDigest, dispatchMode) and add a RuntimeBrokerHttpServerTest case that posts /executions with a four-field reference plus a separate payload and asserts the persisted record's reference carries no toolName/input.
Why is this needed?
#12765 closed this gap for the provider and deferred routes; the immediate route is the documented remainder (see the Open boundaries section of docs/design/2026-09-27-broker-provider-control.md).
Additional context
Split out from the review of #12868.
中文说明
希望增加什么?
让 immediate POST /executions 路由获得与 deferred reserve/start 路径和 managed-runtime-provider/1 协议相同的负载分离:在已保存的 reference 之外单独接收工具负载,使调用方不再把工具参数持久化进 reference_json。
目前 deferred 路径预留四字段 reference、仅在 start 时提供精确的 payloadJson;provider 预留使用七字段 reference 且不携带负载。而 immediate 路由仍从已保存的 reference 中读取 toolName/input(HttpRuntimeTransport.execute),因此该路由的调用方必须把完整的工具参数(对 write_file/edit 即完整文件内容)写入 Broker 持久化的 reference_json——这正是工具契约 §4.1 禁止写入持久状态的形态。
修复必须保持 FaultGateControlTest 钉住的 deferred 原始 reference 形状(恰好 sessionId、promptId、callId、argsDigest、dispatchMode),并在 RuntimeBrokerHttpServerTest 新增用例:以四字段 reference 加单独负载 POST /executions,断言持久化记录的 reference 不含 toolName/input。
为什么需要?
#12765 已在 provider 与 deferred 路由上关闭了该缺口;immediate 路由是记录在案的剩余部分(见 docs/design/2026-09-27-broker-provider-control.zh-CN.md 的“开放边界”一节)。
其他上下文
拆自 #12868 的评审。
What would you like to be added?
Give the immediate
POST /executionsroute the same payload separation the deferred reserve/start path and themanaged-runtime-provider/1protocol already have: accept the tool payload separately from the stored reference, so callers never persist tool arguments inreference_json.Today the deferred path reserves a four-field reference and takes the exact
payloadJsononly at start, and provider reservations use a seven-field reference with no payload. The immediate route still readstoolName/inputfrom the stored reference map (HttpRuntimeTransport.execute), so a caller of that route must write full tool arguments — forwrite_file/edit, complete file contents — into the Broker's durablereference_json, which the tool contract's §4.1 forbids for durable state.The fix must keep the deferred raw reference shape pinned by
FaultGateControlTest(exactlysessionId,promptId,callId,argsDigest,dispatchMode) and add aRuntimeBrokerHttpServerTestcase that posts/executionswith a four-field reference plus a separate payload and asserts the persisted record's reference carries notoolName/input.Why is this needed?
#12765 closed this gap for the provider and deferred routes; the immediate route is the documented remainder (see the Open boundaries section of
docs/design/2026-09-27-broker-provider-control.md).Additional context
Split out from the review of #12868.
中文说明
希望增加什么?
让 immediate
POST /executions路由获得与 deferred reserve/start 路径和managed-runtime-provider/1协议相同的负载分离:在已保存的 reference 之外单独接收工具负载,使调用方不再把工具参数持久化进reference_json。目前 deferred 路径预留四字段 reference、仅在 start 时提供精确的
payloadJson;provider 预留使用七字段 reference 且不携带负载。而 immediate 路由仍从已保存的 reference 中读取toolName/input(HttpRuntimeTransport.execute),因此该路由的调用方必须把完整的工具参数(对write_file/edit即完整文件内容)写入 Broker 持久化的reference_json——这正是工具契约 §4.1 禁止写入持久状态的形态。修复必须保持
FaultGateControlTest钉住的 deferred 原始 reference 形状(恰好sessionId、promptId、callId、argsDigest、dispatchMode),并在RuntimeBrokerHttpServerTest新增用例:以四字段 reference 加单独负载 POST/executions,断言持久化记录的 reference 不含toolName/input。为什么需要?
#12765 已在 provider 与 deferred 路由上关闭了该缺口;immediate 路由是记录在案的剩余部分(见
docs/design/2026-09-27-broker-provider-control.zh-CN.md的“开放边界”一节)。其他上下文
拆自 #12868 的评审。