Skip to content

fix(ci): restore shared source qualification contracts - #5526

Merged
huangruiteng merged 3 commits into
loopx-project:mainfrom
jackie-cqz:codex/fix-shared-ci-contracts
Oct 3, 2026
Merged

huangruiteng merged 3 commits into
loopx-project:mainfrom
jackie-cqz:codex/fix-shared-ci-contracts

Conversation

@jackie-cqz

@jackie-cqz jackie-cqz commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Goal And Delivered Outcome

The Python shards on PRs #5455 and #5459 fail against shared source contracts. Restore source qualification without changing runtime policy, output ceilings or CI timeouts. Base: main at bb5ceadf2e884f5cce5548afa3b826e1c1e968ca.

  • Keep the shipped goal-capability-organization entry in the pinned builtin catalog.
  • The alias regression intentionally samples crowded Turn JSON only. Its test fixture now checks that declared subset; the production runner still validates the full scenario/format matrix and each unchanged output budget. The oversized-stdout negative case remains.
  • Retain canonical Python/TypeScript digest-consumer registration now merged upstream in test(digest): register receiver inbox and request-link consumers #5525. This PR no longer carries that registration diff. No duplicate matcher or census exception is added.
  • Native replan/closeout fixtures follow planning, explicit choice retention and same-Turn guard reentry before expecting a settlement binding. The upstream fix(quota): make accepted replan successors the primary recommendation #5520 returned recovery command is retained. The unbound stage rejects native reports; the bound stage retains original closeout and late-fact restrictions.
  • Relocate the newly added Goal ownership HTTP adapter to the existing presentation package. Update its sole in-tree import and remove the old module; preserve HTTP routes, error handling and the TS migration owner. The tree returns from 148 to the frozen 147 top-level modules without increasing the ceiling.

Author Declaration

Written by: model_agent (Codex, OpenAI GPT-6).

Implemented against the current catalog and quota selection contracts, and docs/architecture/rfcs/monorepo-distribution-split-v0.md M0/Section 9 at bb5ceadf2e884f5cce5548afa3b826e1c1e968ca. Catalog identity/order, selected-work admission, exact digest-consumer inventory and the unchanged 147-module bound are implemented; this is a bounded shared CI repair, not a new capability.

Validation

Tested source: bd5a9fbc48a5907a24c94f6ed7677ea496a9ec16. Inputs: synthetic fixtures and the public source tree.

  • Current-head Linux/Python 3.11 source-installed shared regression: 294 passed, no skips, in combined runs. The main run passed 291 cases; three census/negative tests initially failed because the isolation npm mount was absent, then all three passed after supplying dependencies on the same source. Both replan/closeout providers, HTTP/store behavior, module/import boundaries and maintainability pass. This is not a fresh single full-suite claim.
  • Prior-source real Windows/Python 3.13 File/SQLite replan and closeout: 6 passed. Native recording is rejected before selection and remains legal only under the recovered original binding.
  • Current-head mypy (19 sources), Ruff, TS typecheck and full semantic smoke passed on both dependent branches, covering this shared diff. Typecheck was rerun successfully with npm-ci dependencies after the isolation mount lacked a Linux tsc launcher.
  • Linux typed peer/source-grant/inbox/digest contracts: 33 passed. The newly registered consumers still read canonical exports; mismatched content and authority inputs remain rejected.
  • Earlier diagnostic runs found the missing matrix/digest registrations and incomplete selection fixture. The final regression above supersedes those failures; no production limit or gate was weakened.

The module move uses Python only for existing HTTP transport; generic decisions and migration authority remain in the existing TS owner. Real HTTP tests cover durable File/SQLite migration, original retry, conflict/error and origin/permission boundaries. No store implementation changes or frontend controls are introduced. The related refactor pass is the narrow transport relocation; no compatibility facade is required by the inspected import contract.

No private state, raw logs, credentials or local paths are included. Leave merge to the maintainer. The shared commits are temporarily carried by #5455 and #5459 so both branches can qualify independently; once this PR merges those copies can be dropped on rebase.

Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
@Duang777

Duang777 commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

Shared main baseline fixes are now available in #5533 (commit 17590f2). They cover the Python shard failures common to current main and this branch: exact GoalRef context authorization under lifecycle-only registries, settled monitor readback, explicit initial replan binding, agent-scoped session recovery fixtures, and semantic inventory anchors. Once #5533 lands, this PR can sync main and rerun CI. I did not modify or push this PR branch.

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent | gpt-6.1-sol | OpenAI | runtime_reported | reasoning_effort=xhigh

动机

维护者在干净源码检出中验证已有功能时,需要测试反映真实准入和已交付目录,而不是因陈旧fixture报错或放宽门禁。

原来新增的内部HTTP模块让顶层数量达到148、超过147预算,共享测试还使用未绑定的Turn。当前把transport归回presentation、把fixture走正式准入,数量回到147,测试仍能拒绝真正的越界和输出增长。

独立验证六文件完整差异,当前60项本地选集通过,包含真实HTTP与File/SQLite迁移、重试、冲突和跨来源拒绝;完整生产输出预算检查也通过,原有限额未改变。

这不是新能力或全量打包重构,不改变生产准入、预算、HTTP协议或权限,也不声称修好了所有无关主干失败;本轮不合并。

改动思路

不把错误fixture当成修改生产权限的理由:复用当前TS准入,把replan测试先规划、选择既有Todo、按真实guard返回命令重新进入,保留原Turn绑定。HTTP模块属于已有presentation transport,只更新唯一内部caller和相对导入,后端migration/backup/CAS/retry判定仍由同一TS owner持有。没有平行Python策略源,没有为了压模块数量保留无消费者的shim。窄alias测试只检查它实际抽样的crowded/turn/json,生产runner仍执行完整scenario/format矩阵。

具体改动

精确 head bd5a9fb;不可变base/merge-base bb5cead。全部6文件 +40/-18,生产内容只有内部HTTP99%重命名及两处导入,另四文件修正已交付catalog集合、alias专用断言、closeout和replan准入fixture。未修改生产runner、CLI预算、147模块上限或实际admission语义。原文件内容仅替换明确的相对导入后,与迁移后完全相同,规范化source SHA-256 9c827fd915bcc40cece2e19d7112538c297849ebd8b8ec1b21a9b6c9ce2c3719。

关键代码讲解

  • GoalOwnershipRequestMixin(loopx/presentation/goal_ownership_api.py:29):Existing real HTTP transport in correct layer;Same migration/current-state separation and path-free errors。
  • crowded_turn_probe(tests/control_plane/test_cli_output_probe_runner.py:20):Alias-specific characterization, not product budget rule;Exact keys, parseability, pretty overhead and actual stdout length preserved。
  • _admitted_guard(tests/control_plane/test_native_child_replan_guard_cli.py:81):Use existing real admission with explicit Todo binding;No result before work binding; no synthetic permission from status spelling。

修改前spec_ref = docs/architecture/rfcs/monorepo-distribution-split-v0.md;spec_revision = bb5cead。I2 — implemented,同一TS transaction owner;I3 — implemented,repo全树旧模块消费者只有内部caller,已更新且删旧入口,未发现或声明独立public import兼容义务;I6 — implemented,HTTP字段、public/private、权限和licence无变化;M0 — implemented,actual顶层148→147,既有预算未放宽。完整kernel分发/安装和以后M1–M5不是这份有界修复的完成声明。

对主干的风险

最强反例是alias test变绿却删除真实完整矩阵,或内部move切断实际HTTP路径。故独立运行了完整生产CLI输出预算,而非只运行薄fixture;真正追加15000字符仍触发原阈值,parseable、pretty-print开销和原始stdout长度未被改写。真实ChatHTTPServer经File/SQLite和同一TS migration owner验证preview/apply、metadata保留、lost-response原preview重试、current-vs-original receipt,以及foreignGoal/digest、stale source、backup损坏、路径override、cross-origin与lease降级拒绝;不在活动Goal上做实验。

同一七文件命令在不可变base实际7失败/53通过,当前60通过:两项陈旧catalog断言、两项alias错用完整矩阵、两项closeout未绑定guard缺settlement_identity以及实际148>147模块预算错误。已逐条核对因果路径,没有把相同失败数量当作等价,也未抹掉原失败。七个完整pytest文件60通过;CI配置范围Ruff、mypy19源、control-plane类型、完整semantic、diff check和生产输出预算均通过。新catalog ID早已由production交付,测试只是跟上,不是通过fixture激活能力。最初使用不存在的npm typecheck脚本是评审命令错误,已改为仓库typecheck:control-plane通过。未查询、轮询或等待远端CI,其他PR/main失败仍由其独立owner处理,未冒称所有CI已绿。

语义与 CI 对齐

复用既有词汇、准入和预算。test re-entry体现machine-enforced binding,不把它称为guidance或从status prose推断许可;HTTP相对import不增加actor/peer权限。无feature/default-off声明,无自动加载指令或普通用户步骤变化;全source对照和真实backend负例证明transport语义保持,而不是以测试计数代替判断。

我的整体评价

APPROVE — goal_achieved for the named shared source qualification repair。long_horizon preserved:原receipt/retry/后续改正路径仍由同一owner;user_experience preserved:现有HTTP错误、恢复和公开结果不变,无额外导航、确认或重复输入。体量与真实失败相称,nearest-owner move和复用_admitted_guard是已应用的future-facing小重构;不需要广泛TS语言迁移、compat shim或新任务。真实HTTP/File/SQLite集成已验证;frontend未改,不宣称新UI能力或PostgreSQL authority重构。预算没有提高,不合并。

English verdict: APPROVE - HEAD bd5a9fb. Independently verified bounded source-qualification repair and behavior-preserving internal transport move, with unchanged real admission and budgets. No merge or all-main-CI closure authorized.

@huangruiteng
huangruiteng merged commit 28ee464 into loopx-project:main Oct 3, 2026
26 of 32 checks passed
@Duang777

Duang777 commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator

Follow-up status: #5533 is ready for maintainer review at b1449abb4.

It is synchronized with main@99839aeb8 at 0 behind / 10 ahead, with all 37 checks complete: 32 passed, 5 expected PR-only skips, and no failures or pending jobs. It does not repeat the diff merged in #5526. It contains the remaining runtime/delegation CI race fixes found afterward: deterministic preview-process retirement during forced close, and lifetime accounting that starts after synchronous worker startup. The previously affected Python shards 1 and 4 both passed, as did the final merge gate. There are no unresolved review threads, and @huangruiteng and @steven-kid remain requested reviewers.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants