fix(verifier): stop the run on a sampler the model cannot draw, and offer disabled targets

Candidates returns an error now. The refusal is thrown at the draw and wrapped
with the source of the leaf that made it, since generate() cannot know which
leaf it is inside. Only that marked refusal is fatal: this walk calls every
leaf on every step, so promoting the rest would kill model runs the seeded arm
survives.

Authored actions on a disabled target are no longer dropped from the model's
candidate list. The seeded picker executes whatever the leaf authored, and a
control the application forgot to re-enable is exactly where boundary defects
live, so a policy that cannot attempt it cannot find them.

Claude-Session: https://claude.ai/code/session_01A5KmftdEJ49A9z5mF5ESrX
This commit is contained in:
pj committed 2026-08-13 00:44:00 +05:30
1 parent c76ba4b497
commit 0094a7fc64
4 files changed
+269 -84

No files matched your search

+13
View File
@@ -45,6 +45,13 @@ type Verifier struct {
// over the picker's action space rather than one of its own.
enumerateBuiltinFn goja.Callable
// setEnumeratingCandidatesFn is the bundle-installed
// __sanderlingSetEnumeratingCandidates__, which brackets the model policy's
// authored-leaf calls. Those run outside the picker's rng scope, where a
// sampler would quietly hand back its first item, so the bundle refuses to
// sample while it is set.
setEnumeratingCandidatesFn goja.Callable
evaluators map[string]*ltl.Evaluator
priorVerdicts map[string]ltl.Verdict
@@ -192,6 +199,12 @@ func (v *Verifier) Load(source string) error {
}
}
if fn := v.runtime.GlobalObject().Get("__sanderlingSetEnumeratingCandidates__"); fn != nil {
if callable, ok := goja.AssertFunction(fn); ok {
v.setEnumeratingCandidatesFn = callable
}
}
return nil
}