fix(task): fail closed on stale revived kernel capabilities
Retain the per-child requested-name/descriptor binding in the parent engine's runtime capability map through SAME-host idle parking, so a cold revive in the same live parent reaches the same closures and re-checks the original generation/revision on every call. A host restart, a new parent kernel, a deliberate destruction, a record expunge or parent shutdown leaves no binding: the revived child then gets a typed tools_unavailable error stub restored ONLY from the kernel-tool names its own transcript already recorded, and that stub never invokes a closure. A kernel reset or a same-name redefinition yields kernel_tool_stale on the CHILD channel and never runs a replacement closure for an old descriptor, while a new explicit spawn resolves the new descriptor and succeeds. Pool workers re-resolve at each new spawn and a stale tool error produces one keyed error plus one aggregate, with no automatic retry; process/team children stay typed unavailable. The task tool's argument normalization now carries tools through to execute, and a refused grant reports a typed public message instead of a generic runner failure.
Y
YeonGyu-Kim committed
e2426cf960fdb251feb8a2b978fa8462a121fc0e
Parent: bf84eff