Skip to content

OrbitalProof · AI agents · for a technical reader

Crash recovery for AI assistants’ multi-step changes: the lab’s exact wording

The lab’s own sentences and figures for this result, word for word, in its working terms, with its limits in full. The plain account is on the result’s page; it says the same things in plain words.

The lab’s plain-English sentence

When an AI assistant carries out a multi-step change to files and one database table, the lab's transaction layer is meant to either complete all of it or undo all of it — but only for plans it admits in advance

  • which may contain at most one action that cannot be undone (such as sending a message), placed last and carrying a replay key, other plans being refused or left for a human operator
  • killed at 29 moments the authors chose, the program each time recovered a clean all-or-nothing state from its on-disk log in a fresh process, while a deliberately broken version did not
  • but killed 2,893 more times at random moments it recovered 31 times to a state that was neither, some of them undoing work already committed

At the moments the lab chose, in its words

atomic recovery recorded at every one of those 29 points

The limit to read first, in the lab’s words

The 2,893 random kills are process kills, not power cuts, so the fsync ordering the journal relies on is still untested

Kills at random moments

2,893 further kills at seeded random moments found 31 recoveries that were not atomic

Recorded in the lab’s claim; the run record is not published.

At the moments the authors chose

atomic recovery recorded at every one of those 29 points and a negative control that is genuinely non-atomic

The lab’s prior-art search concludes

So this is INCREMENTAL, a real test of one more system, done to less than the published standard

Claim

Twenty-nine real processes killed with `os._exit(9)` at declared interruption points, each recovered in a fresh interpreter from the on-disk journal, with atomic recovery recorded at every one of those 29 points and a negative control that is genuinely non-atomic; 2,893 further kills at seeded random moments found 31 recoveries that were not atomic, some undoing committed work.

Limits

The 2,893 random kills are process kills, not power cuts, so the fsync ordering the journal relies on is still untested; they sample the interleaving space (85 distinct crash states) rather than exhaust it; and the three windows they found are recorded, not fixed.

All resultsFormal statements

How we show numbers

Every number on this site links to the file it comes from. How each result is checked

  • We never show a number before its file has loaded.
  • A question we have not checked yet is marked as unchecked.
  • A check that found nothing says so.
  • A file with no value for a question says so.
  • A number whose file is missing or has changed is not shown.
  • Two files that disagree about what a number describes are both flagged.
  • A number from too few samples shows its sample size.
  • Two files that give different values are both shown.
  • A file we cannot publish is listed by its fingerprint only.
  • A measurement more than a week old shows its age.
  • A question that does not apply to a page is left off it.
  • A measurement whose program failed is shown as failed.