The barrier in driveSessionToYield was unreachable for terminal yields:
the yield tool's shouldTerminate fired requestAbort("terminate"), so
abortSignal was always aborted before the barrier's loop condition ran,
and a run with pending owner jobs completed immediately with whatever
the pre-async yield said (Codex review on #6119).
- Split "stop the free-running turn after yield" from "terminate the
run": a terminal yield with pending owner async work now parks the
run with a recoverable session abort (budget-stop precedent) via
requestYieldTurnStop; only a quiescent yield terminates.
- An async-result follow-up injected after a recorded yield un-latches
it (transcript-ordered, in the run monitor) and re-runs the reminder
ladder, so the run only completes on a yield that postdates every
delivered result — including results injected during the notice turn.
- A run that never refreshes a superseded yield fails (exit 1) with an
explicit reason; the stale payload ships only as failed-run salvage
through the existing failed-after-yield finalize path.
- Rewrote subagent-async-pending.md: the "your current yield stands"
option contradicted the enforced contract.
- Regression tests: parked yield -> injected result -> fresh yield wins;
refusal -> stale payload fails; no-async fast path unchanged.