ce4f5b8615
The advisor system prompt told the watcher model "at most one advise per update" and "NEVER send the same advice twice", but nothing enforced either rule. Issue #3520 captured a session where the advisor emitted 309 advise() calls covering 92 unique notes - 114x "Stop.", 52x "No issue; continue.", 41x "Done." - landing 309 <advisory severity="blocker"> injections in the primary transcript and destabilizing the watched agent after the task was already complete. New AdvisorEmissionGuard sits on AgentSession#enqueueAdvice and: - Normalizes notes (lowercase, NFKC, punctuation->space, trim) so every "Stop.", "*Stop*", "STOP!" variant keys to the same canonical form. - Drops a small allowlist of content-free self-talk filler (stop, done, complete, no issue continue, lgtm, nothing to add, no further input, carry on, ...) - silence is the correct expression of "no concerns". - Dedupes by exact normalized text across the session, FIFO-bounded at 4096 entries. - Rate-limits to one accepted advise per advisor model prompt cycle. The runtime calls host.beginAdvisorUpdate?.() before each agent.prompt(), so the new batch starts with a fresh budget. Suppressed calls don't consume the budget - a noise call never displaces a real concern. Reset on advisor reset (compaction, session switch, /new) so a re-primed reviewer can re-raise old concerns against the rewritten transcript. Suppression is invisible to the advisor model: AdviseTool still returns "Recorded." for a dropped call. Surfacing "suppressed" risks the model rephrasing the same useless note ("Stop." -> "Halt." -> "Cease.") to bypass the dedupe. Fixes #3520