Agent Architecture · Principal
The agent rolled back a failed branch. Why does the next model call remember it?
The question
Interview question
An investigation agent tries a speculative branch, sees an untrusted note, and then aborts that branch. The application transcript is restored to the last approved checkpoint. The next model request contains only the approved messages. Still, the model sometimes acts on the discarded note. If the request tokens are clean, what state could be dirty?
Take a few minutes to form your approach. Then open a worked answer and compare the decisions.
Reveal a worked answer
In a stateful serving session, the model may reuse KV computed while the aborted branch was in context. Clearing a database transcript does not clear attention state held by the inference runtime. Research on rollback consistency for language agents demonstrates this class of mismatch under retained KV. The failure requires a reuse path that can attend to cache state from the abandoned branch. A stateless API that recomputes from the supplied tokens and isolates caches by exact prefix will not exhibit this particular mechanism just because the app rolled back a transcript.
I would compare two next calls with identical token IDs, model revision and decoding setup. In one, reuse the session cache after the abort. In the other, rebuild KV from the committed transcript. If the outputs or logits diverge, inspect cache handles, valid-token counts, branch IDs and the boundary at which speculative KV became reusable. A prompt log alone cannot prove what the model attended to when the serving runtime keeps state outside the logged prompt.
Treat application history and inference state as one logical transaction. A branch may have an isolated cache handle or snapshot. Commit promotes that handle only after the branch is accepted. Abort discards its cache or restores the committed checkpoint. If that is not supported, recompute from the committed tokens. Never rely on an instruction saying “ignore the previous note” to erase the computation. The ownership contract also matters across worker migration and prefix-cache publication. A cancelled branch's blocks should not be published under a cache identity representing committed history.
What if recompute is expensive for a long agent run? Keep immutable committed prefix blocks and branch-local tail blocks, so rollback drops only the tail. Measure memory cost and prove that the next attention path can read only committed blocks. Test abort after several tool calls, nested branches, worker preemption and a block-boundary crossing. Include a same-token, different-cache test in CI. The user changes their mind while the agent's tool call is in flight. What stops? covers stopping a tool call when the user changes their mind. Here the external side effect may never have happened. The model's own hidden serving state survived a logical rollback and influenced the next decision.
Continue reading
Related questions
Read beyond the question
Explore more agent architecture
Follow another question in this area, or search the complete Question Library.
Browse this area →Browse Question Library →