The Commitment Decision Is Undecidable; the Commit Action Is Not
Ran Tao (Octoryn Research)
Abstract
The commitment decision at an irreversibility boundary splits in two. The COMMIT ACTION is decidable: a terminating local recompute of currently-held belief, gated fail-closed. The FINALITY / safe-to-commit predicate is UNDECIDABLE: a claim about the unobserved future of a third-party-owned stream, isomorphic to Two Generals common-knowledge impossibility over a channel that acknowledges reversals but never finality. FLP and CAP are corroborating shadows; reopening makes finality non-monotone. The defensible deliverable is a conservative bound plus a tamper-evident audit, never a safety proof.
The Commitment Decision Is Undecidable; The Commit Action Is Not
Track: Runtime Systems Type: architecture-paper Evidence: hypothesis Lineage: sharpens prior results on forward-undecidability, stale-certainty, and non-monotone re-opening.
1. Verdict: BOUNDED-APPROXIMABLE (with a hard UNDECIDABLE core)
Split the predicate; the split is load-bearing.
- (a) The COMMIT ACTION — DECIDABLE. "Recompute risk at the commit site from currently-held belief, then emit or withhold the irreversible operation" is a local, terminating function of runtime-observable state. It halts and is computable in bounded resources.
- (b) The FINALITY / SAFE-TO-COMMIT predicate — UNDECIDABLE. "This irreversible action is now final / safe-forever" is not a fixed point of the runtime's update map. It is a claim about the unobserved future suffix of an exogenous, third-party-owned input stream: the reversibility window lives in another administrative domain and arrives with unbounded delay.
Load-bearing reason. The update map is not a self-map on a runtime-observable metric space. The finality variable is governed by a window owned off-box, sampled only across network lag. Contraction-style convergence cannot apply to the finality coordinate; only a worst-case-clamped, exogenously-revisable, bounded-horizon risk estimate converges.
Binding isomorphism — Two Generals / coordinated-attack. Finality is common knowledge between the runtime and the reversal rail that no further reversal will ever arrive. Real rails (ACH/NACHA, card networks, SWIFT) emit acknowledgments for reversals but emit no finality acknowledgment, no "I promise never to reverse" message. Over an unbounded-delay, loss-possible channel with that structurally-missing acknowledgment, common knowledge is provably unattainable. Finality-as-knowledge is therefore impossible, not merely hard.
Corroborating shadows. FLP: internal agreement that "the commit is decided" under asynchrony plus one crash inherits non-termination — the pending reversal-observation is exactly the delayed message that keeps the configuration bivalent (reversible-vs-final undetermined) forever. CAP: on a reversal-rail partition the commit site must trade availability (refuse) against consistency-with-true-world (commit on stale information). Rice: the task-completion half of the stopping question is an undecidable semantic property of the goal predicate.
Quantified residual. The attainable freshness floor is the round-trip time to the authoritative rail: sub-millisecond on a local network, tens-to-hundreds of milliseconds cross-institution, and effectively unbounded (forward-undecidable) for consent-gated rails. Zero staleness is physically unattainable: best attainable staleness is at least one-way observation lag. The probability of a wrong confident commit per action is at least the revocation rate multiplied by round-trip time, for memoryless revocation. This residual is irreducible by local computation — shrinkable only by smaller round-trip time, short-lived leases (an authority pre-commits not to revoke for a bounded interval, converting an unknowable present into a bounded promise), or refusing the undecidable consent-rail class entirely.
Concrete non-monotonicity. Finality at time t is non-monotone and time-varying: a payout settles (final), then an unauthorized-return rule reopens it weeks later, then a chargeback on the funding leg fires on a different rail and clock, then arbitration reverses, then a regulatory or appeal clawback reopens again. Fraud and regulatory clawbacks have statute-of-limitations horizons, not protocol acknowledgments, and frequently no finite upper bound. "Committed-and-final" is not a fixed point; it is an oscillator driven by an adversarial exogenous input the runtime cannot sample synchronously.
2. Honest design consequence: BOUND + AUDIT + reconcile + forced-commit — never "prove safe"
A sovereign execution runtime at an irreversibility boundary cannot decide truth, only a safe lower bound on it. The only defensible commit predicate is fail-closed, and conjoins four conditions, all of which must hold:
- the action falls in a statically-known forced-commit class (a constant-time taxonomy lookup);
- the escape hatch is statically grounded — its compensator chain is proven to bottom out in local state;
- the remaining lease time-to-live exceeds the commit latency (a short-lived, signed, fail-closed lease); and
- the conservative lower bound on the reversibility window is strictly positive.
The regress "deciding reversibility is itself an action of unknown reversibility" does terminate, but only by redefining the target from the exact window to a conservative lower bound, and only at a static base case: a forced-commit taxonomy (instant-payment send, physical actuation, message-already-emitted = irreversible) plus trivially-committed local actions whose own reversibility needs no external rail. A hatch is admissible only if its compensator chain is statically proven to terminate at such a local action. Any hatch whose validity depends on a third party's future consent (for example a recall request that the counterparty may refuse) must be classified as a non-hatch. This rule is sound but incomplete: it refuses some objectively-safe commits in order to guarantee zero false-confident ones.
This is exactly the auditable-runtime, zero-false-confident-for-actions thesis. The runtime never asserts a "now final, stop watching" bit — that bit asserts common knowledge it provably cannot have, so any design that emits it is broken. Instead it exposes a bounded-horizon, continuously-revisable, worst-case-clamped risk estimate, keeps a compensating-action reserve (a saga or clawback reserve), and persists an audit record of the bound it acted on and the freshness it had. The defensible artifact is the audit plus the conservative bound, not a safety guarantee. You cannot prove the world safe; you can prove what you knew, when, how stale it was, and what you reserved to undo it.
3. Do the commitment boundary and the outcome-runtime terminal line unify? NO — they are joined by disjunction, not identity
They are two independently-undecidable predicates with different undecidability budgets:
- Task-completion is a property of the goal predicate over world-state — Rice-undecidable, but an internal predicate approximable from the agent's own observations.
- Crosses-irreversibility is a property of the action's reversibility window — shared, third-party-owned, time-varying, and undecidable for a stronger, distributed-epistemic reason (Two Generals: no common knowledge that the window is open; FLP: no crash-vs-slow detection of the authority). It is not approximable to certainty.
They coincide only in the degenerate case where the task's terminal step is the irreversible commit (send the payment). In general they diverge: an agent can be far from complete yet one step from an early irreversible side-effect, or complete with every step reversible. Forcing them into one "stopping line" is a category error that hides the harder, distributed-epistemic term.
The single honest object is a STOPPING PREDICATE — a disjunction, not an identity:
halt = completion(goal_state) OR crosses_irreversibility(reversibility_window)
We name it the Stopping Disjunction (the dual-budget halt predicate). The left disjunct is approximable-from-self (Rice budget); the right disjunct is bounded by Two-Generals/FLP and is not approximable to certainty (distributed-epistemic budget). And note: forced-commit relocates, it does not contain, irreversibility — the compensating action is itself a second commit against a possibly-irreversible substrate (a recall is a discretionary, window-bounded, refusable third-party request, not a guaranteed inverse), so "compensate the compensation" inherits the same forward-undecidability core at every level. A true no-compensating-action point-of-no-return exists.
4. Final defensible theory (one paragraph) + irreducible cores
Theory. At an irreversibility boundary a sovereign runtime can compute the commit action — a terminating local recompute of currently-held belief gated by the fail-closed predicate above — but it cannot compute finality: "is this action now final/safe?" is undecidable, isomorphic to the Two Generals coordinated-attack common-knowledge impossibility over an acknowledgment-less third-party channel, with FLP non-termination and CAP partition as corroborating shadows, and made non-monotone by exogenous reopening windows (returns, chargebacks, clawbacks) with no protocol-acknowledged finite horizon. The entangled fixed point over (window, memory, authorization) has no stable fixed point in the finality coordinate; it oscillates under adversarial exogenous input. The theory survives only if it never emits a "committed-and-final" bit and instead exposes a bounded-horizon, continuously-revisable, worst-case-clamped risk estimate plus an explicit non-finality / compensating-action posture (saga, clawback reserve), and persists the audit of what it knew, how stale, and what it reserved. The deliverable is not a safety proof but a defensible bound plus a tamper-evident record; the halt question is the Stopping Disjunction (completion OR crosses-irreversibility), two undecidables with different budgets, coincident only in the degenerate terminal-step case.
Irreducible cores no engineering removes:
- Forward-undecidability: the future suffix of a third-party-owned input stream cannot be read in the present; a consent-gated reversal has no readable present value.
- Stale-certainty: freshness is floored at round-trip time to the authoritative rail; zero staleness is physically unattainable; residual equals revocation rate times round-trip time per action.
- Non-monotone re-opening: finality at time t reopens after closing, on independent rail clocks with statute horizons rather than protocol acknowledgments — no fixed point, only an oscillator.
- Finality-is-not-a-fixed-point (this paper, sharpening the above): finality across an acknowledgment-less channel equals coordinated-attack common knowledge and is provably unattainable; never emit a "stop watching" bit.
Honest-evidence flags: This is a stronger result than a false "it computes." The commitment decision is not decidable; treating forced-commit as risk-containing (rather than risk-relocating) is wrong, and unifying the commitment boundary with the completion line as one object is a category error. Bound, audit, reconcile, forced-commit — never "prove safe."
Claim boundary
The author's explicit scope — what this work does and does not establish — carried over from the Octoryn Research publishing model.
Proves
- The commit ACTION is decidable: a terminating local recompute of currently-held belief gated by a fail-closed predicate.
- The FINALITY / safe-to-commit predicate is undecidable, isomorphic to Two Generals coordinated-attack common-knowledge impossibility over a reversal channel that never emits a finality acknowledgment.
- The commitment boundary and the task-completion line do not unify by identity; they form a stopping disjunction (completion OR crosses-irreversibility) of two undecidables with different budgets.
- Zero staleness is physically unattainable; freshness is floored at round-trip latency to the authoritative rail, leaving an irreducible per-action residual no local computation removes.
Does not prove
- Does not prove any runtime can ever prove an irreversible action safe-forever; it proves the opposite.
- Does not prove forced-commit contains irreversibility; it only relocates it onto a possibly-irreversible compensating action.
- Does not prove the conservative lower bound equals the true reversibility window; the gap is the irreducible core.
- Does not prove the residual reaches zero; only that it shrinks via smaller round-trip latency, short-lived leases, or refusing the undecidable consent-rail class.
Applies when
- An irreversible action's reversibility window is owned by a third party or external rail reachable only across network lag.
- The reversal channel emits acknowledgments for reversals but no finality acknowledgment (ACH/NACHA, card networks, SWIFT, FedNow).
- Finality is non-monotone: windows can reopen after closing on independent rail clocks via returns, chargebacks, or clawbacks.
- A runtime must decide commit at the boundary and persist an audit of what it knew and how stale that knowledge was.
Does not apply when
- The action and its compensator both bottom out at trivially-committed local state the runtime fully owns, with no external rail.
- The reversal rail does emit a binding never-reverse finality acknowledgment, making common knowledge attainable.
- Reversibility is statically guaranteed for the full action class, so no present-state observation is needed.
- The task's terminal step is itself the irreversible commit, the degenerate case where the two predicates coincide.
Authors
- Ran Tao — Investigation, Writing
Cite this
Citation
Tao, R., Octoryn Research. (2026). The Commitment Decision Is Undecidable; the Commit Action Is Not (AP-2026-0008). Octopus Research Institute.
BibTeX
@techreport{oriap20260008,
title = {The Commitment Decision Is Undecidable; the Commit Action Is Not},
author = {Tao, Ran and {Octoryn Research}},
institution = {Octopus Research Institute},
year = {2026},
note = {Permanent ID AP-2026-0008. Not peer reviewed.}
}Disclosures
- Funding
- Hardware and infrastructure provided by Octoryn / Octopus Core Pty Ltd.
- Conflicts of interest
- Octoryn ships commercial inference and governance tooling; findings are reported independently.
