Add GatewayFailure: the provider not answering is not a tool failing
terminationFor sent every gateway error that was not Refused or Timeout to ToolFailure, because the enum had nowhere else to put it. On 2026-09-22 that was 131 of 318 production runs, and not one of them was a tool failing: 56 were retired model ids, 25 an exhausted Anthropic balance, 45 Groq's free-tier rate limit -- the only one still happening. An operator reading the termination column saw "a tool is broken" for two weeks while the actual answer was "we are not paying for capacity". GatewayFailure is the seventh termination. Rate limited, request rejected, credential refused and unreachable land there; Refused and Deadline keep their own reasons; a non-gateway error is still the tool layer's. A delegation whose subagent died at the gateway now carries that reason up to the parent instead of reading as a tool call that failed. Migration 000016 widens the CHECK that 000006 chose precisely so this would be a migration rather than an ALTER TYPE. Its down folds any GatewayFailure rows back to ToolFailure BEFORE narrowing the constraint, which is the order that works; verified up, down and up again on a scratch database. Existing rows are left as they are -- the trajectory entries still carry the gateway.* code for anyone reclassifying history. The surface wording is the one termination where "try again" is honest advice, since the dominant cause clears within a minute. Full suite run against a real database, including the tests that skip without one. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PJvibeSc1JYXjatankqM1g
This commit is contained in:
@@ -22,13 +22,26 @@ const (
|
||||
TerminationConfirmationPending Termination = "ConfirmationPending"
|
||||
TerminationToolFailure Termination = "ToolFailure"
|
||||
TerminationRefused Termination = "Refused"
|
||||
|
||||
// GatewayFailure is the model provider failing to answer at all: rate
|
||||
// limited, rejected the request, refused the credential, or unreachable.
|
||||
// Added 2026-09-22 because until then every one of those was recorded as
|
||||
// ToolFailure, and 131 of 318 production runs read as "a tool is broken"
|
||||
// when no tool had failed — 45 of them were Groq's free-tier rate limit,
|
||||
// which is a capacity decision, not a bug. The two are different questions
|
||||
// to an operator ("what did we break" versus "what are we not paying
|
||||
// for"), and an enum that could not tell them apart hid the answer for
|
||||
// two weeks. Refused and Deadline keep their own reasons; this is the
|
||||
// rest of the gateway's vocabulary.
|
||||
TerminationGatewayFailure Termination = "GatewayFailure"
|
||||
)
|
||||
|
||||
// Valid reports whether t is one of the six.
|
||||
// Valid reports whether t is one of the seven.
|
||||
func (t Termination) Valid() bool {
|
||||
switch t {
|
||||
case TerminationCompleted, TerminationBudgetExceeded, TerminationDeadline,
|
||||
TerminationConfirmationPending, TerminationToolFailure, TerminationRefused:
|
||||
TerminationConfirmationPending, TerminationToolFailure, TerminationRefused,
|
||||
TerminationGatewayFailure:
|
||||
return true
|
||||
}
|
||||
return false
|
||||
|
||||
Reference in New Issue
Block a user