Conversation
Co-Authored-By: JeikCode <code@jeikcode.top>
Co-Authored-By: JeikCode <code@jeikcode.top>
xuan2261
marked this pull request as ready for review
October 6, 2026 06:39
Co-Authored-By: JeikCode <code@jeikcode.top>
xuan2261
marked this pull request as draft
October 6, 2026 07:33
Co-Authored-By: JeikCode <code@jeikcode.top>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
变更类型
基于的分支与版本号
beta5fa1f27e78988140fafeff2a21b8a124d39cbee73b3a4258e6f8b605c3fe1eb9e349ea302f6acd0d184192626f88682221029926ac1071ee2400a0d77.1.53-beta.11当前问题、对用户使用体验会产生什么问题或影响
Interactive approvals could race across
/chat, native/live, clients, and desktop notifications:/chat/permissioncould report success before the runtime had actually consumed the decision;request_timeoutto becomeNone, so/chatpermission/user-input waits could become unbounded;call_id, which can be reused;User-visible impact includes stale approval cards, a reported successful approval that the runtime did not accept, a late decision being applied to the wrong request/policy boundary, or an interactive
/chatrequest that never times out.解决方案
/chatapprovals by exact(session_id, approval_id)and keep per-turnExpiredtombstones for timeout/cancel/duplicate rejection.approval_idfrom the persisted pending-permission checkpoint so reused provider call ids across checkpoints remain distinct./chat/permissiononly after the runtime driver accepts the exact response; dropped/rejected runtime responses fail closed.(session_id, generation, request_id)and reject stale runtime generations before a reused request id can be consumed./chatapproval URIs; notification actions post only to/chat/permission.提交清单(组内独立、可单独回退)
0e9fc26afix(daemon): harden approval response correlation3b3a4258fix(daemon): preserve interactive request timeout每项提交引起的变化和影响面
0e9fc26achanges the Rust approval trust boundary plus the WebUI, VS Code, JetBrains and OS-notification consumers that must carry the same exact identity.3b3a4258is deliberately narrow:live_api.rspreserves the configured driver timeout before interactive mode disables the kernel timeout, andlive_hub.rsadds a generation-correlation regression test. No CI/release/installer/documentation changes are mixed into this PR.Rollback: revert the relevant commit(s); no persistent schema migration or history rewrite is required.
自检(与 CI 相同的命令)
cargo fmt --all -- --checkcargo clippy --workspace --all-targets— not run as a new local repo-wide gate; currentAGENTS.mdrequires targeted Rust checks and delegates broad validation to GitHub Actions.cargo check --locked --lib -p jeikcode-daemoncd webui && npm run build(涉及前端变动时)Fresh exact-head verification on Windows (
3b3a4258e6f8b605c3fe1eb9e349ea302f6acd0d), with isolatedJEIKCODE_HOME:cargo test --locked -p jeikcode-daemon permission_bridge::tests::— 7/7 PASScargo test --locked -p jeikcode-daemon chat_permission_— 5/5 PASScargo test --locked -p jeikcode-daemon chat_user_input_wait_— 2/2 PASScargo test --locked -p jeikcode-daemon confirmed_response_rejects_stale_generation_before_reused_request_id— PASScargo check --locked --lib -p jeikcode-daemon— PASScargo fmt --all -- --check— PASSgit diff --check origin/beta...HEAD— PASSEarlier validation of unchanged approval surfaces from
0e9fc26aalso passed: live-permission/runtime-generation Rust tests, notify feature tests, WebUI targeted tests + build, VS Code compile and lane-specific permission regressions. JetBrains local execution remains environment-blocked as noted below.Live GitHub CI on actual PR merge-ref
184192626f88682221029926ac1071ee2400a0d7(run37416734681):Rust and WebUI checkout logs explicitly fetch and checkout
refs/pull/8/mergeand report:HEAD is now at 184192626 Merge 3b3a4258e6f8b605c3fe1eb9e349ea302f6acd0d into 5fa1f27e78988140fafeff2a21b8a124d39cbee7This is merge-result validation, not source-branch-only validation.
Independent review:
NOT YET VERIFIED:
SseParserTestlocally: this Windows host has no Java/JBR/JDK inPATHor common install locations. No new toolchain was installed outside this PR scope.Known unrelated/pre-existing
origin/betaissues were not changed merely to make this suite green:rendering-regression.test.tscontains an LF-only source extractor that fails against a CRLF Windows checkout.provider-queue-regression.test.tscalls_watchJeikCodeAuth, whileorigin/betaprovider.tsdoes not define that method./chat/user-inputcurrently correlates by raw(session_id, request_id)and the kernel interactive request counter is per newly builtRequestCtx; this correlation shape already exists onorigin/betaand is not an approval/policy authorization boundary. It is being tracked as a separate Phase-3 hardening follow-up rather than expanding this focused approval PR.This PR remains Draft until the pending broad independent liveness review is available/inspected. No merge is requested.
署名
xuan2261 / JeikCode