dd8b50649a
`finalizeSubprocessOutput` always spliced collected `report_finding` entries onto a top-level `findings` array regardless of the active output schema. A caller-supplied schema with `additionalProperties: false` and no `findings` property would accept the raw payload in-tool (via the `yield` validator, which only sees the pre-injection data) but then fail post-mortem validation — emitting `schema_violation: findings: must not be present` and propagating as a fatal `RuntimeError` through `agent-bridge.ts` and the eval Python/JS preludes, collapsing the entire workflow cell along with any prior successful subagent work. `normalizeCompleteData` now takes the resolved validator and only performs the injection when the augmented candidate validates. When the schema rejects it, the raw payload is returned instead — which the in- tool yield validator already accepted, so the lockstep guarantee documented at the top of `output-schema-validator.ts` is honored. Findings remain visible via the agent progress stream and JSONL artifact, so no information is dropped when injection is suppressed. Both finalize call paths (yield-success and no-yield fallback) now share the single validator build instead of constructing it twice, and the yield-path schema_violation branch is now reached only via the explicit malformed-schema check, never via spurious findings rejection. Fixes #2070