Skip to content

feat(research): execute public GitHub evidence with auditable downstream readback - #5459

Merged
huangruiteng merged 6 commits into
loopx-project:mainfrom
jackie-cqz:codex/fix-public-github-evidence
Oct 3, 2026
Merged

huangruiteng merged 6 commits into
loopx-project:mainfrom
jackie-cqz:codex/fix-public-github-evidence

Conversation

@jackie-cqz

@jackie-cqz jackie-cqz commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Goal And Delivered Outcome

Refs #5205. Opt-in anonymous public GitHub retrieval executes the exact SHA-pinned plan, preserves compact observed findings, requires independent parent admission and projects admitted sources into the actual research ledger with idempotent readback. Source references retain case. Raw fetched content is not persisted.

The existing typed external-evidence capability owns plan, admission and retirement; the bundled Python provider owns HTTP transport. Existing conversation readback renders the result. Full frontend retrieval/admission initiation and overall S6/S8 acceptance remain with the existing #5205 capability/App owner and RFC checkpoint. This is an independently testable provider/CLI stage.

Author Declaration And Specification

Written by: model_agent (Codex, OpenAI GPT-6).

Implemented against docs/architecture/rfcs/external-evidence-research-capability-v0.md at 5e889bdcba9cea101a8775340a12629eb5a2474a. Exact typed request identity, explicit execution/admission, matching-source lineage, mutation rejection and downstream coverage before retirement are implemented in this stage. Complete frontend initiation/admission and authenticated providers remain deferred to the same existing owner.

CI Repairs And Placement

Validation

Current head bc3b0bcbb6ffde53741c80c314bd98fa6fbba04a; base/merge base bb5ceadf2e884f5cce5548afa3b826e1c1e968ca, PR base main; all 9 commits signed off.

  • Current-head Linux/Python 3.11 related provider/ledger, CLI and shared regression: 421 passed in combined runs. The initial isolation run passed 418 cases and had three setup failures from an absent npm dependency mount; all three census/negative cases passed after supplying those dependencies on the same source. This is combined coverage, not a fresh single full-suite claim.
  • Shared qualification: 294 passed in combined runs (291 plus the three dependency-qualified census cases), including real HTTP/File/SQLite and original closeout restrictions. Prior Windows File/SQLite replan/closeout source coverage: 6 passed.
  • Current-head CI mypy (19 sources), Ruff, TS typecheck and full semantic smoke passed; external-evidence/digest typed tests: 34 passed. Typecheck was rerun with npm-ci dependencies after the isolation mount lacked a Linux tsc launcher.
  • Actual anonymous public provider journey passed using the complete pinned README source: observed receipt before admission, retained before projection, actual ledger source/claim readback and idempotent retry. Synthetic disposable ledger; no raw content persisted. Provider and ledger inputs are unchanged by the later upstream source-fence rebase. An initial abbreviated-SHA probe was correctly rejected; qualification uses the full SHA.
  • Current-head Chat assets were rebuilt after the upstream conversation-rendering change; packaged external-evidence desktop/mobile readback passed. Rendering uses synthetic fixtures paired with the real provider/backend evidence above. It does not deliver the deferred frontend execution/admission controls.

The bounded refactor preserves one digest owner and the existing provider/ledger boundary. Hosted CI and maintainer re-review must run on this head; prior approval referred to the older head. No overall acceptance, live messaging, installation or merge is claimed. No private state, raw logs, credentials or local paths are included.

Maintainer Rebase And Resolution Note (2026-10-04)

Rebased onto main at 5d790b49dd723c1f366d69ac7c8ce35beafb155d; new head
dce7d6921f665eb5bfe41380e1c1df5a11c3d994. The rebase dropped three commits whose
content is already upstream (0c11d2331, ee2da870b, bd5a9fbc4 — the shared CI
corrections landed by #5526), leaving 6 commits, all with DCO sign-off.

The only conflict was in examples/personal-workspace-browser-smoke.mjs, where
another recently merged PR registers its own browser scenario. Both scenario
registrations are retained; no reviewed behavior changed.

Maintainer validation on this head: Ruff over the changed Python surfaces, the
configured python -m mypy (19 sources), npm run typecheck:control-plane,
git diff --check, 234 provider/architecture/ledger Python tests, 20
external-evidence CLI tests, 17 TypeScript external-evidence tests, the live
pinned public README journey through the shipped CLI, and the packaged
external-evidence-readback scenario all passed.

@jackie-cqz
jackie-cqz force-pushed the codex/fix-public-github-evidence branch 2 times, most recently from 7142a32 to 56da691 Compare October 2, 2026 11:51
@mergify

mergify Bot commented Oct 2, 2026

Copy link
Copy Markdown

This pull request has merge conflicts with main and cannot be merged
until they are resolved. Please rebase or merge the base branch, @jackie-cqz.

Choose the remote for the base repository, not an out-of-date fork.
For a fork clone, first inspect git remote -v; upstream must point
to https://github.com/loopx-project/loopx.git. If it is absent, add it
with git remote add upstream https://github.com/loopx-project/loopx.git.
Then run:

git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEAD

For a same-repository clone whose origin points to
https://github.com/loopx-project/loopx.git, use origin instead of
upstream for fetch/rebase. If you prefer merging the base, use
git merge <base-remote>/main and push normally.

Keep the DCO Signed-off-by trailer on every commit when you rebase.
https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/syncing-a-fork

@mergify mergify Bot added the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 2, 2026
@jackie-cqz
jackie-cqz force-pushed the codex/fix-public-github-evidence branch from 56da691 to c7d31f7 Compare October 2, 2026 12:33
@mergify mergify Bot removed the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 2, 2026
@jackie-cqz
jackie-cqz force-pushed the codex/fix-public-github-evidence branch 2 times, most recently from 2b65829 to b635a65 Compare October 2, 2026 13:53
huangruiteng
huangruiteng previously approved these changes Oct 2, 2026

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent | GPT-5 | OpenAI

动机

结论:APPROVE 这份明确有界的 public-GitHub provider/CLI 阶段,head b635a65;没有发现阻塞问题。#5205 需要从真实取证走到父 Agent 决定和下游实际使用,原有 receipt 入口只能证明 caller-presented 记录。新增路径把匿名、固定完整 SHA 的公开文件读取接到现有生命周期,不能把它说成整个研究能力或 App 发起旅程已完成。

改动思路

公开 GitHub HTTP 属于 bundled provider;精确 plan/receipt/admission/retirement 仍由现有 TypeScript owner 决定。Python CLI 在访问网络前核验 canonical plan,把 provider 结果交回同一 TS owner;显式父决定后,readback 才能把已采纳来源投到既有 deepresearch source/claim ledger,再独立核对真实 lineage 和 claim。既没有新 evidence 数据库,也没有自动采纳、connector promotion、调度或配额副作用。保留 Python 的部分是 HTTP 与已有文件账本传输,不是第二套通用决策源。

具体改动

  • 「execute_public_github」(loopx/extensions/public_github_research.py:76):只处理显式选择的 method 和一至八个 full-SHA 文件;每次重新检查仓库 public,拒绝重定向/外部 origin/非法路径,字节有上限,只返回 digest、取证时间和 literal-match 元数据。公开读取不是授权证明,literal match 也不是语义研究结论。
  • 「handle_external_evidence_command」(loopx/capabilities/external_research/cli.py:199):新增 opt-in plan readiness、execute 和 readback;--public-github 会做匿名 readiness GET,真正内容执行必须 --execute。source/search 可选字段纳入 TS request identity;省略时旧 request digest 不改变。caller-presented receipt 与真实执行仍保持区别。
  • 「readback」(loopx/capabilities/external_research/projection.py:33):先通过 TS 重建精确 parent admission;默认只读,execute 必须有 admission 和既有 matching-question project。账本局部失败保持 retained,覆盖不能由成功消息或 caller 给的 URL 冒充。Markdown 明确显示 pending/admit、covered、retirement 与 completeness unverified。
  • 「add_source」(loopx/capabilities/deep_research/runtime.py:235):在原文件锁内比较 lineage 和 claims,精确重试读回已有 id;GitHub pinned path 区分大小写,普通来源仍保留旧 normalization。当前 run 的 question 不匹配、来源冲突、预算耗尽均不伪造 coverage。

完整差异为 19 文件、+859/-37,已阅读 provider、TS optional request 字段、CLI/catalog、ledger/projection、双语 RFC/操作说明、public CLI smoke、现有 answer/Lark 展示测试和五个共享 UTF-8/read-only/Windows/安装测试修正。没有修改 App 生产代码;新增 browser fixture 把实际 typed/ledger Markdown 注入已有 answer API,不能证明用户从 App 发起 provider/admission。未来方向检查:当前继续复用既有 typed owner 和 ledger 足够,不需加一层 provider registry 或迁移框架。

以改动前已接受 RFC 为独立依据:spec_ref = docs/architecture/rfcs/external-evidence-research-capability-v0.md;spec_revision = 4fc30f1。规范没有单独条款编号,criterion_id 使用 Acceptance 的原文条款开头:

criterion_id 判定与证据
inventory-only connectors cannot be selected TS discovery/selection 原有负例通过;没有把 catalog 或 installed 当 ready。
discovery distinguishes empty, inventory-only, and ready inventories 现有 CLI/TS 矩阵通过;inventory 不声称执行或覆盖。
method and connector providers use one protocol and receipt contract provider 经同一 external_evidence.receipt 校验;没有另造 admission。
an observed provider receipt is bound to the exact plan 真实匿名 README 执行和 receipt 回读通过;没有自动采纳。
mutation of the request objective, decision, constraints, provider readiness TS 负例及实际 CLI 改 objective 后退出 1、完整 request_id 诊断通过。
stale request/provider identity, file provenance, and unsupported evidence 既有 TS/CLI 负例通过;provider 的坏 URI、路径与可见性失败不产生可用来源。
admitted source refs are a subset of receipt sources TS admission 负例通过;实际 CLI 缺失 admission 拒写,账本仍空。
retirement rejects mutated disposition, source, or downstream projection 实际 CLI 修改 parent reason 后拒绝,未增写来源;typed 变异矩阵通过。
retirement waits for downstream coverage of every admitted source 真实 CLI retained→ledger→retire_ready;错误 question、不匹配 lineage、局部预算失败保留 retained。
CLI and effect-runtime TypeScript tests pass from the source checkout 55 项 Python 与 17 项 TS 通过,并执行下面的独立真实入口验证。

对主干的风险

独立验证:完整 source CLI 对匿名公开 LoopX README(固定 4fc30f1)执行 plan→真实 provider→receipt→显式合成父决定→既有 ledger→retire_ready→同身份重试,通过;未保存原始文件内容。另用同一合成 fixture 在不可变 base 与该 head 执行 legacy plan/receipt/admit/retire、普通来源去重和非法 plan 的完整退出/诊断,归一化后逐字段一致(只去掉 ledger wall-clock 时间)。相同输入 fingerprint 为 c90ea94aee0938c718af868d802c5f6974444aec4bfbefab9d621b698449a40b,两个观察 fingerprint 都为 594c67372271bb5b4155350047979b4734721bc563ee114a73daadc8534ea01a。

实际 CLI 负路证明:无 parent admission 不写;被篡改 admission 拒绝;无关 question 仍 retained;添加无关来源不改变覆盖;新 project 在明确投影前不算 covered,合法重试恢复到 retire_ready。另故意让投影边界丢失 lineage,再走真实 ledger/readback,完整覆盖 oracle 失败、结果仍 retained;恢复正确参数的新 project 通过,不会把存在同 URL 当有效使用。Ruff、编译、diff check、语义 advisory 和当前 packaged bundle 构建通过。55/17 是本次运行结果,不继承作者的 Windows/wheel/浏览器结论;评审 harness 的错误路径和遗漏 title 参数已纠正,不归罪于 PR。

保留边界:本轮 ego-browser 原空间无法恢复,因此 packaged answer 的浏览器复验未完成,没有声称桌面/移动 reload 已通过;App 生产代码未变,此次批准限真实 provider/CLI 阶段。现有 Lark card/长文拆分测试通过,但没有 live Lark 发送、认证 connector、付费模型、安装推广或研究完整性验证。未查询或等待 CI;没有合并。原始来源 fallback 明示保留,失败或部分结果不驱动自动采纳。

我的整体评价

这是可独立验证和回滚的有用增量,不是仅加 receipt serializer。真实匿名 provider、TS 身份、父决定、文件账本与重试已经连成可操作链路;复用相邻 owner 优于再建通用存储。重复同一 pinned source 的不同 admission 仍可能遇到既有 source 冲突,应遵循现有“复用 claims/明确另开 run”的恢复语义,不扩大默认权利。剩余 App 研究交互发起/采纳、authenticated connector 和最终 companion qualification 继续归 #5205;不要关闭整体 S6/S8 或把 catalog/命令说明算成完整 frontend 交付。APPROVE 不是 merge authority,也不表示已安装生效。

English verdict: APPROVE - b635a65: no blocking finding in the bounded public-GitHub provider/CLI stage; anonymous real-provider/ledger retry and immutable base/head parity passed, 55 Python and 17 TypeScript tests passed. Full App initiation and this turn's browser requalification remain unproven; no merge.

@mergify

mergify Bot commented Oct 2, 2026

Copy link
Copy Markdown

This pull request has merge conflicts with main and cannot be merged
until they are resolved. Please rebase or merge the base branch, @jackie-cqz.

Choose the remote for the base repository, not an out-of-date fork.
For a fork clone, first inspect git remote -v; upstream must point
to https://github.com/loopx-project/loopx.git. If it is absent, add it
with git remote add upstream https://github.com/loopx-project/loopx.git.
Then run:

git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEAD

For a same-repository clone whose origin points to
https://github.com/loopx-project/loopx.git, use origin instead of
upstream for fetch/rebase. If you prefer merging the base, use
git merge <base-remote>/main and push normally.

Keep the DCO Signed-off-by trailer on every commit when you rebase.
https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/syncing-a-fork

@mergify mergify Bot added the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 2, 2026
@jackie-cqz
jackie-cqz force-pushed the codex/fix-public-github-evidence branch from b635a65 to bff8e4c Compare October 2, 2026 18:29
@jackie-cqz

Copy link
Copy Markdown
Contributor Author

Updated the branch by rebasing onto 5e889bdcba9cea101a8775340a12629eb5a2474a; current head is bff8e4cf9e60982b80369fd499d9553dd29a9366. Duplicate doctor/skill patches now owned by upstream were dropped, and shared queue/runtime/Todo test fixtures were repaired without weakening their negative assertions.

Current validation: 95 Python regressions and 17 typed external-evidence tests passed; exact CI mypy/Ruff, TypeScript typecheck, semantic smoke and paired base/head CLI budget passed. The real anonymous provider smoke on this head passed retrieval, separate admission, actual deepresearch ledger readback and idempotent projection for the full-SHA-pinned public README, without raw-content persistence. Shared actual-wheel install/uninstall validation also passed the current release validator.

The PR remains the approved bounded provider/CLI stage: packaged App readback is present, while App retrieval/admission initiation and overall #5205/S6/S8 completion remain open. The body replaces stale qualification details with current head-specific evidence. Hosted checks are rerunning.

@mergify mergify Bot removed the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 2, 2026
huangruiteng
huangruiteng previously approved these changes Oct 2, 2026

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent | GPT-5 | OpenAI

动机

没有发现本次有界 provider/CLI 阶段的阻塞问题。原来外部证据可以描述计划和回执,却没有随产品交付的公开 GitHub 执行器,也不能从实际 source/claim ledger 独立证明已采用证据。这是 #5205 的 S6/S8 justified increment,不是整个研究交互已完成。评审重新读取当前全部 20 文件及基线;旧 head 的已撤销批准没有替代本次证据。

依据修改前的 docs/architecture/rfcs/external-evidence-research-capability-v0.md,固定版本 5e889bd,原 Acceptance 条款逐项映射如下(标识沿用原条款文字):

  • inventory-only connectors cannot be selected — implemented;inventory-only connectors cannot be selected。由现有 TS 生命周期及本轮 typed/实际 CLI-ledger 验证覆盖。
  • discovery distinguishes empty, inventory-only, and ready inventories — implemented;discovery distinguishes empty, inventory-only, and ready inventories without claiming execution or evidence coverage。由现有 TS 生命周期及本轮 typed/实际 CLI-ledger 验证覆盖。
  • method and connector providers use one protocol and receipt contract — implemented;method and connector providers use one protocol and receipt contract。由现有 TS 生命周期及本轮 typed/实际 CLI-ledger 验证覆盖。
  • an observed provider receipt is bound to the exact plan — implemented;an observed provider receipt is bound to the exact plan without implying authenticated execution, evidence coverage, admission, or promotion。由现有 TS 生命周期及本轮 typed/实际 CLI-ledger 验证覆盖。
  • mutation of the request objective, decision, constraints, provider readiness — implemented;mutation of the request objective, decision, constraints, provider readiness, or execution envelope fails canonical plan_id verification。由现有 TS 生命周期及本轮 typed/实际 CLI-ledger 验证覆盖。
  • stale request/provider identity, file provenance, and unsupported evidence — implemented;stale request/provider identity, file provenance, and unsupported evidence basis fail closed。由现有 TS 生命周期及本轮 typed/实际 CLI-ledger 验证覆盖。
  • admitted source refs are a subset of receipt sources — implemented;admitted source refs are a subset of receipt sources。由现有 TS 生命周期及本轮 typed/实际 CLI-ledger 验证覆盖。
  • retirement rejects mutated disposition, source, or downstream projection — implemented;retirement rejects mutated disposition, source, or downstream projection fields whose complete admission identity no longer matches。由现有 TS 生命周期及本轮 typed/实际 CLI-ledger 验证覆盖。
  • retirement waits for downstream coverage of every admitted source — implemented;retirement waits for downstream coverage of every admitted source。由现有 TS 生命周期及本轮 typed/实际 CLI-ledger 验证覆盖。
  • CLI and effect-runtime TypeScript tests pass from the source checkout — implemented;CLI and effect-runtime TypeScript tests pass from the source checkout。由现有 TS 生命周期及本轮 typed/实际 CLI-ledger 验证覆盖。

完整 App 内发起检索、作出 admission 及授权 connector 的资格验证仍 deferred 到已有 #5205 的 capability/App owner。本阶段独立可逆,匿名 provider 和 CLI 到持久 ledger 的链路现在实际可用;不新增设置、不借用安装或 discovery 来授权执行。

改动思路

仍由 external_evidence.ts 决定请求身份、provider 选择、parent admission 与 retirement;Python 只承担 HTTP transport、CLI 编排和已有 deepresearch 领域 ledger 的适配,未建立第二个通用决策源。用户选完整 SHA 来源,明确请求网络读取,得到 observed receipt,再独立提供 parent 意图,最后对匹配问题的研究 run 显式投影。每一步分别提供范围、读取权限、采用意图和落地目标,不是重复确认同一事实。成功回执不自动意味着 admission,更不意味着 downstream coverage。

相比另建 evidence store 或手写 ready 标志,最小有用路径是在已有锁保护的 source/claim 上保留四个身份 digest,再每次读取实际来源、claim 和问题,派生覆盖。CLI/typed owner、deepresearch ledger、现有 answer/Lark Markdown 消费者及未变的 frontend 兄弟路径均作过基线比较。来源拒绝、预算不足或错误问题保留 retained,用户可纠正目标后继续;不会丢弃失败或循环宣布完成。

具体改动

20 文件 +861/-35 包括 131 行 bundled GitHub provider、111 行 readback adapter、已有 CLI/deepresearch/TS contract 的小扩展、catalog availability、双语阶段与操作文档,以及聚焦 provider、ledger 和现有原生 fixture 的验证。source_refs/search_terms 缺省时不进入旧身份计算,显式来源才进入 exact plan;带 lineage 的完整 SHA 路径保持大小写,普通 source 的历史归一化和重复错误仍保留。共享 fixture 修复遵循真实 queue claim、read-only continuation 和独立 runtime root;skill metadata 按已选择的 shipped catalog 验证,不把固定数量当能力契约。

关键代码讲解

  • execute_public_github:76:仅接受已选择的 method 和验证后的计划。公开可见性先查,来源必须固定完整 SHA;最多八个、UTF-8 且有字节上限,禁重定向,不读取凭据。成功只产生 provenance/literal-match 摘要,partial/unavailable 不能变成证据完整性。
  • handle_external_evidence_command:199:沿用实际 CLI dispatcher;执行前调用 TS 验计划,execute/readback 需要对应显式请求。无执行授权的生命周期与旧输出不发生 HTTP 或 ledger 写入;无效输入明确拒绝。
  • readback:33:重新验证完整 admission,仅显式 project/execute 才 add_source;从当前实际 ledger 的同问题、同来源、四 digest 和 claim 读取覆盖。仅有相同 URL 或 receipt 不会 ready;缺失、冲突与部分预算仍 retained,修正匹配 run 后可恢复。
  • add_source:235:沿用原锁、source/claim ID、预算及 save owner;exact lineage 重试复用同一记录,而普通调用保持原语义。独立 mutation 丢弃 lineage 后实际写入虽成功,ready oracle 必须失败;恢复生产 adapter 后同一真实 CLI 路径通过。

对主干的风险

本轮从精确 source checkout 执行:131 项 Python(provider、CLI、deepresearch、native continuation、Codex queue、runtime configuration、skill metadata/parity),17 项 TS;配置要求的 Ruff、19-source mypy、control-plane typecheck、full semantic vocabulary smoke、diff check 全通过。真实匿名 HTTPS smoke 读取固定 5e889bd 的公开 README,逐步验证 receipt-before-admission、projection-before-ready、实际 source ledger 与 idempotent retry;未持久化原文。独立实际 CLI+TS+file ledger oracle 验证 forged admission、错误问题、未授权写、新研究 run、无关来源和 dropped-lineage 反例。fixture fingerprint c90ea94aee0938c718af868d802c5f6974444aec4bfbefab9d621b698449a40b;缺省分支基线/head 完整归一化观察均为 594c67372271bb5b4155350047979b4734721bc563ee114a73daadc8534ea01a,只剔除已声明非确定时间,不抹掉诊断、身份、状态或副作用。

最强风险是“URL 出现就算已采用”或“发现 method 就自动执行”;实际 lineage/readback 与显式 flags 拒绝这些路径。默认关闭比较涵盖共享 TS/CLI/ledger;catalog/help 只是 availability,不是执行义务。GitHub 暂不可达、二进制或部分结果不能被误称完整证据。literal matches 的语义完整性仍 unverified。App 生产代码未改变;浏览器本轮不可用,未恢复或替换浏览器,新增 synthetic renderer fixture 和作者前次浏览器声明不作为本轮完整 App 交互证明。现有 Lark display 覆盖不等于 live delivery。

语义与 CI 对齐

扩展既有 exact-request 词汇的可选 intent 和既有 source format 的可选 producer lineage,不新建 actor lifecycle、共享 evidence authority 或 scheduler 义务。typed plan/admission 是执行规则,文档 guidance 没有把强制 flag 说成建议。开发 advisory 的空结果不证明语义等价;本轮 full canonical semantic smoke 和现有 CI 配置对应的本地检查才是相应覆盖。未查询、轮询或等待 GitHub CI,也未放宽任何预算。

我的整体评价

APPROVE,仅批准上述有界 provider/CLI stage。long_horizon improved:来源身份、实际采用与重试都可回读,错误保留并能恢复,避免重复写和虚假退休。user_experience accepted_tradeoff:本阶段 CLI 的最短合法链路有用且授权明确,完整 App 发起/采用尚在原 #5205,不宣称已安装修复。代码量主要投入真实边界验证;未来重构 pass 已比较已有 typed lifecycle、领域 ledger 与 provider seam,当前复用合理,未发现需要追加框架或语言重写的相关小重构。重新核验旧评审与当前 head,批准后只处理确已过期且有权限的 blocker;不凭本批准覆盖未解决问题,不执行合并。

English verdict: APPROVE - HEAD bff8e4c. The bounded anonymous public-provider/CLI stage is independently validated. Full App initiation/admission, authenticated providers and live messaging remain explicitly outside this approval; no merge or installed-state claim.

@mergify

mergify Bot commented Oct 2, 2026

Copy link
Copy Markdown

This pull request has merge conflicts with main and cannot be merged
until they are resolved. Please rebase or merge the base branch, @jackie-cqz.

Choose the remote for the base repository, not an out-of-date fork.
For a fork clone, first inspect git remote -v; upstream must point
to https://github.com/loopx-project/loopx.git. If it is absent, add it
with git remote add upstream https://github.com/loopx-project/loopx.git.
Then run:

git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEAD

For a same-repository clone whose origin points to
https://github.com/loopx-project/loopx.git, use origin instead of
upstream for fetch/rebase. If you prefer merging the base, use
git merge <base-remote>/main and push normally.

Keep the DCO Signed-off-by trailer on every commit when you rebase.
https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/syncing-a-fork

@mergify mergify Bot added the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 2, 2026
@jackie-cqz
jackie-cqz force-pushed the codex/fix-public-github-evidence branch from bff8e4c to 0fcd415 Compare October 3, 2026 05:52
@jackie-cqz

Copy link
Copy Markdown
Contributor Author

CI repair pushed on 0fcd415a1c13703a8d46eb6022481a3f09b144c0, rebased onto 12d60f13fe1fae6848e2bc806688f26031c8869a.

The research ledger uses the canonical digest matcher and its consumer is explicitly registered in the pinned ownership manifest. Shared archive publication uses the existing portable directory-sync helper; regular-file fsync, verified readback and no-replace publication remain intact. The Todo fixture asserts the existing typed budget; no budget was increased.

Final source qualification: 381 Python tests passed, exact CI mypy/Ruff/TS typecheck and full semantic smoke passed, 34 typed evidence/digest tests passed, and same-base CLI output budgets passed. The real anonymous public provider journey against the pinned current upstream README passes explicit parent admission, retained-before-projection, actual ledger readback and idempotent retry. Rebuilt packaged desktop/mobile conversation readback passes. Shared storage qualification passes Windows 373 and real PostgreSQL 335 plus service 10; the qualified storage bytes are identical after the final rebase.

The PR body preserves the remaining frontend execution/admission journey and S6/S8 boundary; it does not claim broad capability completion. Hosted checks have restarted on this head. English author repair verdict: READY FOR MAINTAINER REVIEW; no merge.

@mergify mergify Bot removed the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 3, 2026
@mergify

mergify Bot commented Oct 3, 2026

Copy link
Copy Markdown

This pull request has merge conflicts with main and cannot be merged
until they are resolved. Please rebase or merge the base branch, @jackie-cqz.

Choose the remote for the base repository, not an out-of-date fork.
For a fork clone, first inspect git remote -v; upstream must point
to https://github.com/loopx-project/loopx.git. If it is absent, add it
with git remote add upstream https://github.com/loopx-project/loopx.git.
Then run:

git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEAD

For a same-repository clone whose origin points to
https://github.com/loopx-project/loopx.git, use origin instead of
upstream for fetch/rebase. If you prefer merging the base, use
git merge <base-remote>/main and push normally.

Keep the DCO Signed-off-by trailer on every commit when you rebase.
https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/syncing-a-fork

@mergify mergify Bot added the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 3, 2026
@jackie-cqz
jackie-cqz force-pushed the codex/fix-public-github-evidence branch from 0fcd415 to 9abb635 Compare October 3, 2026 07:47
@jackie-cqz
jackie-cqz requested a review from maxliux5 as a code owner October 3, 2026 07:47
@jackie-cqz

Copy link
Copy Markdown
Contributor Author

Repair qualification on 9abb63547791d89ee297b69b6e4bb13256e669ae

Rebased onto main at 60f0e64e45dd735be9d8ba5d1f3948540991c9f2; merge base and main PR base verified. All commits carry DCO sign-off.

Final-source public provider journey passed against the pinned upstream README: actual anonymous GET, explicit independent parent admission, retained-before-projection, actual ledger readback and idempotent retry. Raw content is not persisted. Rebuilt packaged desktop/mobile external-evidence readback passed.

Provider/ledger/shared Python selection: 381 passed; typed external-evidence/digest 34 passed; exact CI static/semantic checks passed. Selected inputs are unchanged by the final upstream test/docs-only advance. The canonical digest owner remains reused; the optional GitHub transport adds no evidence-admission authority. Full App initiation/admission and S6/S8 remain explicitly partial under the existing checkpoint.

The actual dashboard failure was reproduced: cached and delayed pre-apply readback reopened confirmation after assignment. The existing typed-action cache now cancels older reads and accepts the validated mutation response; the strict completion assertion remains. Packaged before/after regression fails/passes, with one apply and one durable write. The real TS/File team-plan owner passed alongside the affected-platform gates.

Linux/Node 22.22.3: dashboard unit coverage, all 38 browser scenarios, and four packaged operation/readback scenarios passed. Rebase removes our archive-sync/Todo-budget commits now owned by upstream. Main supplies the File-journal decode optimization and 30-to-45-minute Python shard limit; this repair adds no timeout or product-budget increase. The final test/docs-only upstream advance leaves those browser/build inputs unchanged.

Hosted checks are newly triggered; maintainer review is required on the unchanged head. This is author repair evidence, not an approval or merge.

@mergify mergify Bot removed the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 3, 2026
huangruiteng
huangruiteng previously approved these changes Oct 3, 2026

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; model=gpt-6.1-sol; provider=OpenAI; runtime_reported; reasoning_effort=xhigh. Host-recorded execution attribution, not backend-weight attestation.

动机

需要用公开仓库文件支持研究决定的 CLI 用户,以及在工作区确认团队分配、查看研究回执的用户。
此前读取结果不能通过产品命令证明已进入研究账本,重试还可能重复添加;团队分配成功后刷新又会显示确认按钮。本改动把公开读取、父级采纳和账本使用分开回读,并保留成功分配的回执。
独立验证了真实匿名公开读取、缺少采纳时零写入、采纳后一次账本投影及重试不重复;同场景打包前端基线刷新重现确认按钮,当前 head 不再重现,移动视口和重载仍显示证据回执。
这不等于证据内容完整、自动采纳或完整 App 发起研究流程;不授予连接器权限,也不涉及部署、付费模型或合并。
完整 App 发起读取、父级采纳入口及认证连接器资格仍由 #5205 的 S6/S8 后续边界承担。

改动思路

先比较不做、仅增加序列化和新建证据库:现有 typed 生命周期已能绑定计划,却缺真实读取及真实使用回读;序列化不能补这个缺口,新库又重复现有研究账本。保留 TS 决策 owner,Python 只承接匿名 HTTP 和已有领域账本。读取成功、父级采纳、真正覆盖分别表示,缺少任何一步不会自动升级。UI 伴随修复复用现有 query cache,取消旧读后保存已确认结果;不新增派发或权限 owner。完整 App 发起/采纳仍是明确的后续边界,而非把 catalog 或展示卡称为交付。

具体改动

评审 exact head:5459@9abb635;22 文件 +906/-38。生产主体:131 行公开 GitHub provider、111 行账本投影,CLI/TS/旧账本少量扩展以及两处现有 UI 回读修复;其余为文档、native 回归及共享 fixture 纠正。未来向重构已应用于同一 cache owner,未添加推测框架。

关键代码:

  • public_github_research.py:76 execute_public_github:完整 SHA、公开仓库及 allowed-origin 检查,再做有界匿名读取;拒绝重定向、私有/未固定来源,返回 observed 而非 accepted。
  • external_research/projection.py:33 readback:验证 canonical plan/parent,从真实完整账本及 claim 匹配四项 lineage 推导覆盖,未覆盖保持 retained。
  • deep_research/runtime.py:235 add_source:沿用锁和 question/conflict/budget owner;同采纳重试复用 source/claim ID,普通旧路径保持。
  • apps/presentation/dashboard/src/data/use-typed-action-readback.ts:23 acceptProposal:已有已确认响应进入同 scope query cache;没有第二次 effect 或新持久 status。

Spec:docs/architecture/rfcs/external-evidence-research-capability-v0.md
Spec revision:60f0e64e45dd735be9d8ba5d1f3948540991c9f2
以下使用改动前 Acceptance 原文作为 criterion_id;本 head 的 CLI/TS、匿名 provider、账本负例及重试证明该阶段,非整体 S6/S8 App 完成:

  • inventory-only connectors cannot be selected — implemented;inventory-only connectors cannot be selected
  • discovery distinguishes empty, inventory-only, and ready inventories — implemented;discovery distinguishes empty, inventory-only, and ready inventories without claiming execution or evidence coverage
  • method and connector providers use one protocol and receipt contract — implemented;method and connector providers use one protocol and receipt contract
  • an observed provider receipt is bound to the exact plan — implemented;an observed provider receipt is bound to the exact plan without implying authenticated execution, evidence coverage, admission, or promotion
  • mutation of the request objective, decision, constraints, provider readiness — implemented;mutation of the request objective, decision, constraints, provider readiness, or execution envelope fails canonical plan_id verification
  • stale request/provider identity, file provenance, and unsupported evidence — implemented;stale request/provider identity, file provenance, and unsupported evidence basis fail closed
  • admitted source refs are a subset of receipt sources — implemented;admitted source refs are a subset of receipt sources
  • retirement rejects mutated disposition, source, or downstream projection — implemented;retirement rejects mutated disposition, source, or downstream projection fields whose complete admission identity no longer matches
  • retirement waits for downstream coverage of every admitted source — implemented;retirement waits for downstream coverage of every admitted source
  • CLI and effect-runtime TypeScript tests pass from the source checkout — implemented;CLI and effect-runtime TypeScript tests pass from the source checkout

验证:262 native Python、34 TS、配置的 Ruff 五目录、mypy 19、tsc、全语义 smoke、实际 packaged build、diff check 均通过。匿名 live smoke 固定 README@60f0e64e45dd735be9d8ba5d1f3948540991c9f2;provider 不保存原始正文。独立完整 legacy 输出 fingerprint:594c67372271bb5b4155350047979b4734721bc563ee114a73daadc8534ea01a,base/head 相同。缺采纳零写入、伪造采纳拒绝、错 question/new run 不覆盖;删除真正 lineage 的 mutation 即使写入成功也不能 retire_ready,恢复正确来源后一次投影、重试相同。
Ego Lite 同 pinned synthetic API、base/head source-built packaged bundle:base 成功后 refresh/delayed-read Confirm=true,head=false,两者 durable apply=1;实际 ledger Markdown 在390×844移动消息宽度362/scroll362,重载仍有 retire_ready 与 completeness-unverified。前端 HTTP 是合成边界,不冒充完整研究发起或真实 team-dispatch。初始错误 selector/flag、CORS/cwd/过长 hold 属评审 harness 修正,不计 PR 缺陷。

对主干的风险

最危险是把同 URL 误当正确采纳的覆盖,或让旧 preview 取代确认结果;已分别用真实 lineage mutation 与基线/head 延迟请求复现验证。新增 request.source_refs/search_terms 是不可推导的用户意图;lineage 是最小来源事实,coverage 和 UI readback 是派生值,没有重复决策状态。旧输入、默认 request ID、普通账本诊断/重试保持;UI 成功回执修复有意影响既有 action,并非新研究 opt-in 才生效,已明确披露。无自动 HTTP、自动采纳、scheduler/quota 或推广。完整 App/认证连接器/Lark 不在本阶段资格中。CI 没有查询、等待或作为结论依据;本评审不是合并决定。

我的整体评价

APPROVE — justified increment for the real public-provider/CLI-ledger stage and related acknowledged-readback repair. 公开读取到真实使用、错误恢复到继续工作的链路有独立生产入口证据;新增规模与问题边界相称,typed owner、默认隔离、domain-neutral 和 obligation 语义保持。完整 App 入口仍由 #5205 收尾,不宣称整项 capability 完成,不合并。

English verdict: APPROVE - HEAD 9abb635. Independently validated bounded stage; remaining qualification and unrelated check recovery stay separate. No merge or activation authorized.

@jackie-cqz

jackie-cqz commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor Author

Updated to bc3b0bcbb6ffde53741c80c314bd98fa6fbba04a on main / merge base bb5ceadf2e884f5cce5548afa3b826e1c1e968ca. Rebase conflicts are resolved; upstream #5520 recovery and #5525 canonical digest registration are retained. Remaining shared catalog/probe/module/replan fixes from #5526 are temporarily carried here for independent qualification.

Current-head Linux combined regression: 421 passed; shared qualification: 294 passed. Three isolation setup failures were rerun with the required npm dependencies and all pass. CI mypy/Ruff/typecheck/full semantic gates and 34 typed tests pass. Current-head Chat assets were rebuilt; packaged external-evidence desktop/mobile readback passes. Actual anonymous public-source/ledger qualification and prior Windows evidence keep their original source scope, detailed in the body.

Fresh hosted checks are queued/running. Previous approval refers to an older head; the current head requires re-review. Full frontend retrieval/admission initiation remains with the original capability owner; no overall issue closure, live message or merge is claimed.

@mergify

mergify Bot commented Oct 3, 2026

Copy link
Copy Markdown

This pull request has merge conflicts with main and cannot be merged
until they are resolved. Please rebase or merge the base branch, @jackie-cqz.

Choose the remote for the base repository, not an out-of-date fork.
For a fork clone, first inspect git remote -v; upstream must point
to https://github.com/loopx-project/loopx.git. If it is absent, add it
with git remote add upstream https://github.com/loopx-project/loopx.git.
Then run:

git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEAD

For a same-repository clone whose origin points to
https://github.com/loopx-project/loopx.git, use origin instead of
upstream for fetch/rebase. If you prefer merging the base, use
git merge <base-remote>/main and push normally.

Keep the DCO Signed-off-by trailer on every commit when you rebase.
https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/syncing-a-fork

@mergify mergify Bot added the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 3, 2026
@jackie-cqz
jackie-cqz force-pushed the codex/fix-public-github-evidence branch from 6dac592 to bc3b0bc Compare October 3, 2026 11:42
@mergify mergify Bot removed the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 3, 2026
@huangruiteng

Copy link
Copy Markdown
Collaborator

我使用验证了一波 #5529

等bot review到然后合

huangruiteng
huangruiteng previously approved these changes Oct 3, 2026

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh

动机

需要用公开 GitHub 文件辅助判断的研究用户,必须知道来源是否真的读过、是否被采纳,以及是否进入当前研究。

以前仅有提供者清单或读取回执,用户仍需手动核对和登记来源;现在显式读取固定提交的公开文件、独立决定采纳,并从实际研究账本读回覆盖。错配研究问题时不写入,修正目标后可以重试。

真实匿名读取、显式采纳、实际账本写入与幂等重试通过;错误项目保持未覆盖,修正后恢复。当前打包页面能读回结果、限制和错误,重载仍保留答复。

本 PR 不实现全自动研究结论、认证连接器或付费模型,也不把读取成功当完整性证明;本轮未证明真实 Lark 投递或已安装 App 自动发起和采纳。

#5205 的完整 App 发起与采纳、认证提供者及 S6/S8 端到端资格仍开放;本轮只批准提供者、CLI 与现有答复显示的有界切片。

改动思路

保留现有 TypeScript 决策边界:计划绑定确切来源、查询和提供者;读取回执只说明观察到了什么,不自行批准证据。父级单独决定采纳,随后通过既有研究账本写入;退休状态必须从真实来源、因果身份和声明读回,不能靠成功标记推断。

Python 的新增代码分别是 GitHub 匿名 IO 与研究领域存储适配,不另建通用决策源。清单中的可用性不是网络访问、采纳或后台执行授权。原有普通来源重复仍拒绝,同一份已采纳来源的重试则复用原行。

具体改动

审查 bc3b0bc,基线 bb5cead;全部21文件 +870/-46。主要生产增量是131行提供者、111行读回投影和小幅 CLI/账本扩展;Goal ownership API 是99%内部搬迁,现有调用同步迁移,没有新增兼容分支。

关键代码讲解

  1. loopx/control_plane/capabilities/external_evidence.ts:209 planExternalEvidenceRequest:可选来源与查询纳入规范身份;省略时保留旧身份。CLI 和新提供者共用这一规则,篡改目标或查询不能复用旧计划。
  2. loopx/extensions/public_github_research.py:76 execute_public_github:逐来源重新确认仓库公开,读取完整提交 SHA 固定的 UTF-8 文件。禁止认证和重定向,单响应最多1MiB、单请求15秒;回执保留摘要和字面匹配,不保存原文、不声称语义结论。部分来源失败不会伪装全覆盖。
  3. loopx/capabilities/external_research/projection.py:33 readback:执行写入前要求明确采纳和项目,并在既有锁内核对研究问题;随后从完整账本检查 URL、确切 lineage 与声明文本,再调用原 TS 退休规则。写入阻塞保留原因,修正目标可显式重试。

规范依据:docs/architecture/rfcs/external-evidence-research-capability-v0.md,固定版本 5e889bd;这里沿用修改前 Acceptance 的原句作为标识,不拿本 PR 改写后的文字作自证:

  • inventory-only connectors cannot be selected — implemented;共享 TS 身份/拒绝/采纳测试。
  • discovery distinguishes empty, inventory-only, and ready inventories — implemented;共享 TS 身份/拒绝/采纳测试。
  • method and connector providers use one protocol and receipt contract — implemented;共享 TS 身份/拒绝/采纳测试。
  • an observed provider receipt is bound to the exact plan — implemented;共享 TS 身份/拒绝/采纳测试。
  • mutation of the request objective, decision, constraints, provider readiness — implemented;共享 TS 身份/拒绝/采纳测试。
  • stale request/provider identity, file provenance, and unsupported evidence — implemented;共享 TS 身份/拒绝/采纳测试。
  • admitted source refs are a subset of receipt sources — implemented;共享 TS 身份/拒绝/采纳测试。
  • retirement rejects mutated disposition, source, or downstream projection — implemented;真实 CLI/账本覆盖、重试和反例。
  • retirement waits for downstream coverage of every admitted source — implemented;真实 CLI/账本覆盖、重试和反例。
  • CLI and effect-runtime TypeScript tests pass from the source checkout — implemented;共享 TS 身份/拒绝/采纳测试。

正向实跑:匿名读取固定的公开 README → 显式采纳 → 当前研究账本写入 → 独立覆盖读回 → 同身份再次执行,无重复来源。负向实跑:缺少采纳、篡改计划或采纳理由、错误研究问题均拒绝或 retained;新匹配项目显式执行后恢复。

对主干的风险

独立冻结探针在不可变基线与当前 head 跑真实 CLI、TS 和文件账本;完整规范化旧输出、错误与普通来源状态一致,指纹为 594c67372271bb5b4155350047979b4734721bc563ee114a73daadc8534ea01a。只去除了四种不确定时间戳,没有抹掉身份、诊断或副作用。补加两条无关来源不改变覆盖;故意在实际写入处丢掉 lineage,独立覆盖 oracle 检出 retained,不能错误退休。

本地296项 Python、17项 TS、control-plane typecheck、mypy、仓库配置 Ruff、完整输出预算和语义 smoke 均通过;先运行开发期语义 advisory,再做全树检查。没有增加限制来消除失败,也未查询或等待远端 CI。

当前 head 重新构建打包 /chat,以 Ego Lite 检查既有“对话 → 答复”路径:来源链接、父级决定、完整性限制、错误问题下0覆盖及修正后的1覆盖可读;重载保留答复,390px手机卡片无横向溢出。HTTP/模型运输使用既有合成 fixture,答复来自独立实跑的 CLI;它不证明已安装 App 自动发起/采纳,也不证明真实 Lark 投递。

非阻塞 P3:提供者第121行用 "empty source" in item 判断 no_evidence。现有字符串是本地固定消息,当前正负测试通过;但后续改文案会让空内容误变 failed,新错误包含该短语会误变 no_evidence。建议在这个局部用类型化失败原因再格式化消息,补空内容、读取失败和混合输入测试,无需新框架。

语义与 CI 对齐

这次扩展既有可选请求/因果来源合同,并复用原 TS admission/retirement;覆盖是派生读模型,不新增同步布尔状态。关掉显式新路径时既有身份、普通来源写入、配置调用、调度和权限保持原样;公开文档明确披露 opt-in,不把可用性当激活,也不把强制身份校验称为建议。

我的整体评价

APPROVE,有界 justified_increment:长期运行 improved,幂等和真实覆盖避免累积虚假完成;用户路径 improved,结果和拒绝原因能从现有答复读回。范围与原问题相称,保存旧身份和持久回执有真实兼容价值,没有必要另建注册表或状态框架。

未来面向重构检查已做:通用规则继续归 TS,领域 IO/账本继续归原 owner;局部消息分类可再类型化,作为非阻塞建议。更宽的产品验收仍由 #5205 原任务负责,不把本次通过当整能力完成。不合并。

English verdict: APPROVE this exact head as a bounded public-provider/CLI increment. Anonymous execution, independent admission, actual downstream ledger coverage, replay, legacy parity and packaged answer readback passed. Full initiating/admitting App and live messaging qualification remain open; provider-local prose-based error classification is a nonblocking typed-refactor suggestion.

… ledger sources

Signed-off-by: jackie-cqz <2557911191@qq.com>
…dback

Signed-off-by: jackie-cqz <2557911191@qq.com>
…livery boundaries

Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
@huangruiteng
huangruiteng force-pushed the codex/fix-public-github-evidence branch from bc3b0bc to dce7d69 Compare October 3, 2026 17:07

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review verdict: APPROVE (maintainer review of a contributor PR)

Reviewer: model_agent (self_reported); model=DeepSeek V4 Flash; provider=DeepSeek.

评审 #5459 feat(research): execute public GitHub evidence with auditable downstream readback

Review exact head: dce7d6921f665eb5bfe41380e1c1df5a11c3d994(maintainer rebase 后);合并基线 main:5d790b49dd723c1f366d69ac7c8ce35beafb155d;作者原 head:bc3b0bcbb6ffde53741c80c314bd98fa6fbba04a。

规范依据(不可变修订): docs/architecture/rfcs/external-evidence-research-capability-v0.md @ 5d790b4 — acceptance-plan-identity 已实现;acceptance-receipt-binding 已实现;acceptance-retirement-coverage 已实现;acceptance-fail-closed-provenance 已实现;acceptance-product-surfaces 延后。

动机

Operators and agents who need external evidence: the person running the loopx external-evidence command for one named research question, and the parent Agent that must decide whether the retrieved public sources may be admitted into the existing deepresearch ledger. Before, the capability could only bind a caller-supplied receipt to a plan, so anyone who wanted public GitHub evidence had to fetch it outside LoopX and there was no executed plan, parent decision or downstream coverage to read back; after, loopx external-evidence execute --execute reads the exact SHA-pinned public sources anonymously and readback --execute projects only parent-admitted sources into the real research ledger with lineage, leaving raw content unpersisted and the original-source fallback available. The live shipped-CLI journey over a pinned public README returns one compact finding with a content digest, keeps the parent decision separate, reports retained before projection and retire_ready after it, is idempotent on replay, and never persists source bodies; the packaged readback scenario renders the same facts at desktop and mobile widths. No overall #5205 S6/S8 acceptance, no frontend retrieval or admission initiation controls, no authenticated connector or private-source execution, no automatic admission, no evidence-completeness claim and no live Lark delivery are delivered in this stage. The capability still has no shipped user-facing entry point that starts execution and records the admission decision; that journey exists only through the CLI today, so the frontend initiation/admission controls and the overall S6/S8 acceptance remain with the existing #5205 capability/App owner.

改动思路

复用既有 typed external-evidence 契约(plan / receipt / admit / retire)与既有 deepresearch 来源账本,把「公开来源读取」这件事放到一个 bundled extension provider(loopx/extensions/public_github_research.py)里,而不是在 Core 里再造一个 provider 执行器或第二个证据库。真正需要新增的是「执行过的证据到底有没有进入下游」:provider 只做匿名、有界的 pinned 文件读取并产出紧凑 finding,plan 身份、父 Agent 采纳与退休判定仍完全由既有 TypeScript typed owner 决定;loopx/capabilities/external_research/projection.py 再把 receipt、admission 与账本实际覆盖合成一份可读回执。账本写入只在显式 --execute 且存在父 Agent 采纳时发生,并给来源行加上四项内容寻址 lineage,使相同身份的重放幂等、不重复写行。请求侧新增的 source_refs / search_terms 参与 plan 身份,但缺省时保留旧 plan 的 digest,这一点由 TS 测试单独锁定。

语义与 CI 对齐

契约影响是「扩展现有词汇」而不是新建能力:provider id method:public-github、请求字段 source_refs / search_terms、以及来源行的 external_evidence lineage 都挂在既有 external_evidence_research_v0 之下,没有新的 capability id、事件类型、账本或平行 registry;Python 只做 transport 与本地 JSON,判定仍在 loopx/control_plane/capabilities/external_evidence.ts。语义 advisory 扫描在改动的 6 个 Python 源上未发现新的词表载体。

关键代码讲解

  • _source(loopx/extensions/public_github_research.py:38):只接受 https + github.com + 40 位完整 SHA + 无 query/fragment/转义/穿越段的 blob URL,任何不符在发请求前就失败,避免把非 pin 或私有路径当成公开来源。
  • execute_public_github(同文件:76):逐源做一次实时公开可见性探测后按行做字面匹配,finding 截断在 4096 字符,失败按来源记录成 limitation;返回的 execution 明确标注 raw_content_persisted: false、automatic_admission: false、evidence_coverage_observed: false。
  • readback(loopx/capabilities/external_research/projection.py:33):先校验 receipt 与 plan,再校验 admission 身份,只有 --execute 且 disposition 为 admit 时才通过 add_source 写账本;下游覆盖从账本全量状态计算,未覆盖时 retirement 保持 retained。
  • add_source(loopx/capabilities/deep_research/runtime.py:235):仍是在同一把项目锁下的唯一写入者,新增 expected_question 与 external_evidence 两个可选参数;lineage 必须是四个 enveloped SHA-256,同身份重放返回原 source/claim id,目标问题不一致直接拒绝。
  • normalizeRequest(loopx/control_plane/capabilities/external_evidence.ts:97):把可选来源与检索词纳入规范化请求,强制非空、唯一、非 file:// provenance,缺省时不写入字段以保持旧 plan 身份。
  • render_readback(loopx/capabilities/external_research/projection.py:81):输出同一份事实给 CLI 与既有 Markdown/会话渲染,逐条列出采纳、下游覆盖、digest 与 limitation,并写明证据完整性未验证。

具体改动

Maintainer rebase 后 15 文件 +830/−28:131 行 provider、111 行共享 projection、既有 CLI 59/−11 行、deepresearch 账本 23/−1 行、TS 契约 13 行、catalog/RFC/README 文档 118/−13 行,以及 362 行测试与 fixture(含真实 CLI live smoke 与 packaged drawer 场景)。rebase 只丢掉了三个内容已在上游的重复提交(0c11d2331、ee2da870b、bd5a9fbc4,即 #5526 已承接的共享 CI 修正),唯一冲突在 examples/personal-workspace-browser-smoke.mjs 的 scenario 注册处(另一 PR 已加入 native-child 场景),两边都保留即可,未改动任何被测语义。所有 6 个提交均带 DCO sign-off。

对主干的风险

最危险的反例是「未执行或未落账的证据被当成已覆盖」。当前实现把这条路径分段堵住:非 pin/私有 URL 在 _source 失败,手工改过的 plan 在 validate_receipt 失败,404 或空内容只记为 limitation 且状态为 failed/no_evidence,admission 身份不匹配直接抛错,目标问题不同的项目即使有同名来源也判为未覆盖,因此 retirement 会一直 retained 而不是 retire_ready。第二类风险是把本次只实现的 provider/CLI 阶段当成整体验收:本 PR 未做前端发起/采纳入口,也没有 Lark 真实投递,这些连同 S6/S8 明确留在既有 #5205 owner,正文与 RFC checkpoint 都如实写明。

关于验证:本 head 的 Ruff、配置内 mypy(19 sources)、TS typecheck 与 git diff --check 全部通过;provider/账本/architecture 234 条、external-evidence CLI 20 条、TS 17 条通过;真实匿名公开 README 的 shipped-CLI 旅程与 packaged readback 场景均已跑通。本 PR 未触碰的既有 CI shard 红灯不在本次范围,按仓库策略不阻塞本切片。

我的整体评价

这个切片值得合并:它让一个 pinned 公开来源从「计划 → 执行 → 父 Agent 采纳 → 真实账本覆盖 → 退休」全程可观察且可重放,把之前只能由调用方在体外提供 receipt 的空档补上,同时没有新增执行权限或第二个判定源。交付边界诚实:只做匿名公开 GitHub 方法、只在显式 --execute 下读与写、不落原始内容、不自动采纳、不宣称证据完整性,前端发起与整体 S6/S8 仍归既有 owner。没有阻断项。

English verdict: APPROVE - head dce7d69: the opt-in public GitHub method executes the exact pinned plan, keeps admission separate and projects only admitted sources with content-addressed lineage into the existing research ledger; 234 provider/architecture Python tests, 20 external-evidence CLI tests, 17 TypeScript tests, the live pinned public README journey and the packaged readback scenario pass at this head, and raw content is never persisted.

@huangruiteng
huangruiteng merged commit 99839ae into loopx-project:main Oct 3, 2026
7 checks passed
@huangruiteng

Copy link
Copy Markdown
Collaborator

Maintainer merge record (admin bypass, owner-authorized self-repair + self-merge).

  • Exact head: dce7d6921f665eb5bfe41380e1c1df5a11c3d994; merged as 99839aeb8fed5fae38a5d319391cd050672a6508 (base main 5d790b49dd723c1f366d69ac7c8ce35beafb155d).
  • Changed surfaces: the bundled method:public-github provider, the shared external-evidence readback, two CLI subcommands, optional source-bound request identity, an additive deepresearch ledger lineage field, bilingual capability docs and the regressions. 15 files, +830/-28.
  • Checks run on this head: ruff over loopx and tests, the configured python -m mypy (19 sources), 234 provider/architecture/ledger Python tests, 20 external-evidence CLI tests, 17 TypeScript external-evidence tests, npm run typecheck:control-plane, git diff --check, the live pinned public README journey through the shipped CLI, and the packaged external-evidence-readback browser scenario.
  • Failures/skips/holds: none for this slice. GitHub's ruleset still reported REVIEW_REQUIRED although the exact head carries a valid APPROVED review with zero unresolved threads, so the required checks were bypassed with admin rights.
  • Premerge gate: loopx canary premerge --from-git-diff --goal-id loopx-meta passed with merge gate passed and 0 failures; change-quality receipt cqr_6cab7dd30d1280ef9c77 (status valid, fingerprint 6cab7dd30d1280ef9c779ee200ed141440635d0619cea1a2d2cfcb4ae7ff17d3).

Scope honesty: this stage delivers the executed provider and the auditable downstream readback. Frontend initiation/admission controls and overall #5205 S6/S8 acceptance remain with the existing capability/App owner.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants