@@ -83,17 +83,18 @@ finalization retains its existing publication behavior.
8383
8484Reports contain only bounded diagnostic categories, redacted backend identifiers,
8585coverage and requirement results. They never retain call data, handles,
86- credentials, source, selectors, Stores, or reservations. Valid incomplete static
87- coverage is reported; ` run ` and ` submit ` emit ` DispatchCoverageWarning ` , while
88- ` explain ` does not warn .
86+ credentials, source, selectors, Stores, or reservations. Incomplete static
87+ coverage remains in ` explain ` diagnostics even when a normal unresolved call
88+ does not warn. ` explain ` never emits ` DispatchCoverageWarning ` .
8989
9090## Probing And Static Coverage
9191
9292` ProbeOptions ` is an immutable, inert policy with defaults
9393` placement="auto" ` , ` execution_timeout=30.0 ` , ` max_targets=256 ` , and
94- ` max_depth=32 ` . ` placement="auto" ` uses an explicit probe backend when supplied;
95- otherwise it probes inline only with compatible current-process evidence and uses
96- an owned local subprocess when isolation is required. ` placement="execute" `
94+ ` max_depth=32 ` , and ` coverage_policy="default" ` . ` placement="auto" ` uses an
95+ explicit probe backend when supplied; otherwise it probes inline only with
96+ compatible current-process evidence and uses an owned local subprocess when
97+ isolation is required. ` placement="execute" `
9798uses the supplied backend or that local subprocess default. ` placement="in_process" `
9899requires compatible current-process evidence and rejects a contradictory backend.
99100Probe placement is independent of the selected workload route. It never falls
@@ -117,8 +118,14 @@ at 4 MiB. They retain at most 64 diagnostic entries with 512 characters per
117118field. Capture separately limits individual source reads to 1 MiB, aggregate
118119source reads to 8 MiB, candidate targets to 4,096, binding/call facts to 16,384,
119120and raw annotation occurrences to 4,096. These ceilings do not make static
120- analysis a full call-graph proof. A valid incomplete result warns and can proceed
121- when known requirements pass; malformed projections/results, conflicts, crashes,
121+ analysis a full call-graph proof. By default, accepted incomplete coverage only
122+ warns when a traversal limit or other diagnostic accompanies ` static.unresolved ` ;
123+ an unresolved-only call (common for notebook-defined functions and callbacks)
124+ proceeds quietly with ` coverage="incomplete" ` and its diagnostics retained in
125+ ` explain ` . ` ProbeOptions(coverage_policy="warn") ` restores warnings for every
126+ accepted incomplete probe. ` ProbeOptions(coverage_policy="strict") ` instead
127+ returns an ineligible report and rejects ` run ` /` submit ` before workload acceptance
128+ for any incomplete probe. Malformed projections/results, conflicts, crashes,
122129timeouts, or cleanup failures stop submission rather than becoming empty results.
123130
124131An ` EnvironmentSpec ` pin selects an existing interpreter, venv executable, or
@@ -140,7 +147,15 @@ result recovery, and cleanup retain the core Execute contracts.
140147result, and reconciles its owned cleanup. If both the workload result and
141148cleanup fail, the workload failure remains primary and the cleanup failure is
142149its cause. Dispatch does not retry work, adapt results, or choose another
143- backend after an unavailable or rejected selected backend.
150+ backend after an unavailable or rejected selected backend. A ` KeyboardInterrupt `
151+ while the future is still pending first attempts confirmed pre-GO cancellation,
152+ then requests best-effort running cancellation if GO has won. It propagates the
153+ interrupt without prematurely cleaning up running work; core's one-off
154+ completion owns eventual cleanup. Blocking ` run ` occupies a notebook shell until
155+ it completes or is interrupted. In an async notebook cell, use ` submit ` and
156+ ` await future ` to avoid blocking the shell task; the caller remains responsible
157+ for observing and cleaning up the returned future. Captured live asyncio tasks,
158+ futures, and event loops cannot be transported into workers.
144159
145160The selected worker environment and world requirements are the combined
146161configured and discovered requirements. A resolved worker Python selector is
0 commit comments