Skip to content

refactor(state): derive Next Action from Todo-bound recommendation receipts - #5531

Merged
huangruiteng merged 13 commits into
mainfrom
codex/next-action-writeback
Oct 4, 2026
Merged

huangruiteng merged 13 commits into
mainfrom
codex/next-action-writeback

Conversation

@huangruiteng

@huangruiteng huangruiteng commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

Task-local next steps were stored in shared Next Action prose, so concurrent Agents could overwrite each other's continuation. Bind explicit step edits to the selected Todo through the existing typed recommendation receipt, derive CLI/status/quota/Lark readback from that owner, and reject stale edits before effects.

Native Turn host continuation guidance is kept intact in the durable host journal. It no longer implicitly edits the current task step; explicit refresh-state step editing still requires a registered Agent and an eligible task. This retires the old shared-prose/free-text selection default. The full packaged frontend editor and canonical-intent amendment remain an explicit staged gap in the existing RFC.

Validation: actual disposable SQLite and File paths; Agent/peer isolation, stale-basis refusal/fresh recovery, completion, replay and one settlement; 14 authority-derived identities across six Goal shapes, four domain-specific steps each. Native Turn/Codex/step-focused suite passes, CLI base/head differential and absolute output budget smoke pass, and the latest-main premerge canary passes all 19 selected checks. The suites overlap and are not summed as independent coverage.

Output cost is disclosed: ordinary quota adds about 100 pretty / 94 compact JSON characters. Redundant source context/top-level basis is removed from default status, while the selected task and explicit peer readbacks retain the fence. The differential allowance is limited to the first valid 0-to-1..4 JSON read-fence migration; absolute caps and subsequent same-shape growth guards remain unchanged.

The native managed review contract does not wait for remote CI. Required local validation, published exact-head review, thread closeout and native ready=true determine merge readiness; remote CI is not claimed green. No paid-model, multi-day autonomous effect, account execution or complete frontend-editor qualification is claimed.

Integrated merged PR #5536 and the current main review qualification contract. Both budget assertion groups are retained; the affected task-step/history production paths match the independently qualified combined candidate. Budget/probe regression rerun: 117 passed; real CLI comparison is repeated against the current main.

Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
@mergify

mergify Bot commented Oct 3, 2026

Copy link
Copy Markdown

This pull request has merge conflicts with main and cannot be merged
until they are resolved. Please rebase or merge the base branch, @huangruiteng.

Choose the remote for the base repository, not an out-of-date fork.
For a fork clone, first inspect git remote -v; upstream must point
to https://github.com/loopx-project/loopx.git. If it is absent, add it
with git remote add upstream https://github.com/loopx-project/loopx.git.
Then run:

git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEAD

For a same-repository clone whose origin points to
https://github.com/loopx-project/loopx.git, use origin instead of
upstream for fetch/rebase. If you prefer merging the base, use
git merge <base-remote>/main and push normally.

Keep the DCO Signed-off-by trailer on every commit when you rebase.
https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/syncing-a-fork

@mergify mergify Bot added the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 3, 2026
…owner

Signed-off-by: huangruiteng <huangrt01@163.com>
…xpectations

Signed-off-by: huangruiteng <huangrt01@163.com>
…ndaries

Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
@huangruiteng huangruiteng changed the title fix(state): allow sole-peer Next Action writes and guard shared updates refactor(state): derive Next Action from Todo-bound recommendation receipts Oct 3, 2026
@mergify mergify Bot removed the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 3, 2026
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; model=gpt-6.1-sol; provider=OpenAI; runtime_reported; reasoning_effort=xhigh

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Exact head: a18587bcedc93245f80259aa46a3287d1dd8dc61. APPROVE 的结论只针对这一版本及以下明确的增量边界。

动机

同一项目中并行执行不同任务的 Agent,以及需要在重启后继续任务的操作者,会遇到共享下一步互相覆盖的问题。 一个 Agent 正在核验恢复路径,另一个正在修控制面;原先共享 Next Action 正文可能把两人的步骤混在一起,现在步骤随注册 Agent 和选中 Todo 的回执保存。

真实 CLI 与隔离 SQLite 中,14 个身份按不同领域各续接四轮,自己的步骤可读回、同伴步骤和原任务保持;陈旧读栅栏拒绝后重新读取可以恢复。

本增量不授予任务 claim、lease、Goal amendment 或外部执行权限;完整 packaged frontend 步骤编辑和长期模型决策收益仍属于后续验收。 已交付 CLI 编辑与共享读投影;完整 frontend 编辑旅程和 canonical-intent amendment 继续由既有 RFC 阶段承担。

改动思路

复用既有 recommended_action_resolution 回执及 typed Todo selector,把任务内步骤从共享 Markdown 中移出。读栅栏 next_action_basis 是所选任务和既有源事实的摘要:用来检测陈旧编辑,不成为第二份任务 authority。Python 做源重读、锁内核验与 IO,TypeScript 保持选中任务及步骤规则的单一 owner。

复审发现 native Turn 的 host guidance 与显式 CLI 步骤编辑含义不同。现已修复真实 caller:host 的 recommended_action 和 next_action 均保存到 durable host_result;generic next_action 不再隐式改写当前任务步骤。显式 refresh-state --next-action 继续要求注册身份和合格任务,两个显式编辑参数若含义冲突仍拒绝。这是明确的默认行为变化。

具体改动

关键代码讲解

  1. loopx/control_plane/work_items/refresh_recommendation.py:129 的 resolve_refresh_recommendation 重读真实 source 和 selection,再调用 TS;stale basis 与无合格任务均在写入前拒绝。
  2. loopx/control_plane/work_items/refresh_recommendation.ts:263 的 resolveRefreshRecommendation 绑定步骤到选中 Todo,不从任意正文出现 Todo id 推断选中。
  3. loopx/control_plane/runtime/run_context_retention.py:166 保留每个 Agent 的最新步骤回执;neutral history 不挤掉它,任务完成/切换后不会继承旧步骤。
  4. loopx/cli_commands/turn_run_once.py:283 保留两个合法不同的 host 文本到 journal,移除对当前任务步骤的隐式编辑;恢复、终止和 crash/replay 继续由既有 Turn journal 负责。
  5. loopx/control_plane/testing/cli_output_differential.py:654 的私有 _task_step_read_fence_migration 只识别首次 0→1..4 合法 basis 的 JSON 迁移成本;复用 digest owner,绝对上限、后续同形状增长和非 JSON guard 不变。

独立规格:docs/architecture/rfcs/shared-goal-alignment-and-governed-amendment-v0.md,spec_revision fd65e71f467fb76cf847f2ca904c4d463fcf65f8。§9 的 compatibility prose/read projection 边界已验证,Next Action 不授予 claim、lease、amendment 或 settlement。§3 的 canonical intent/per-Agent frontier 分离由任务回执推进;完整 canonical-intent amendment、接收方采纳和 frontend 编辑属于既有后续阶段,不在此宣告完成。

对主干的风险

原 head 的合法 distinct host fields 曾阻断 17 个基线通过的 native Turn 场景。修复保留这些不同文案,断言 journal 同时保存两字段、共享 Markdown 不被隐式覆盖、回放只结算一次;没有把 fixture 改成同文绕过问题。原生 Turn/Codex/步骤隔离及 CLI 差分等七个文件 304 passed;预算/digest/步骤相关 345 passed;最终 helper 提取相关 112 passed。这些集合有重叠,不相加为独立覆盖数。CLI 输出预算 smoke、typecheck、投影 smoke 和原 premerge canary 19 项均通过;接入 #5536 后当前 head 的 canary 结果按原生报告另行核验。

按完整 authority 的只读资料,逐个检验 14 个身份、6 个 Goal 形状;领域步骤共 56 轮,覆盖工程评审、控制面、产品、运营、决策、知识/系统学习、工具、交接、金融研究/复核/展示及双会话消息恢复。四轮模拟保持原任务和同伴 readback;stale basis 被拒,fresh readback 后恢复。领域观察是合成的,不是金融账户执行、真实消息发送或模型质量测试。源无合格任务的拒绝、旧模板未知身份、wrong-agent、终止/重试由独立反例核验。

默认 status 移除内部 source context 和顶层重复 basis,选中任务与 explicit peer rows 保留可用读栅栏。实测普通 quota 增量约 100 pretty / 94 compact JSON 字符,peer detail 压缩后增量 457 / 346;这是防陈旧写入的成本。首次迁移 allowance 范围、digest 形状、非法类型、过大计数和 N→N 情况都有负例,不能持续放宽预算。绝对 hard caps 保持。

原 checkpoint-only 及 canonical periodic successor 的 File/SQLite 三项,在 immutable 当前 main 9cdc8c9780f8dc80fcc20b0de7d50a9b49ce35ab 和本 exact head 再次于相同原 Turn binding guard 失败,失败 test id 与细节一致;与这次已修的 17 个 native Turn 回归分开归因,未把红项改成通过。接入已合并的 #5536 后,本 PR 影响的步骤、恢复和投影生产代码与此前独立组合核验一致,保留两组预算断言;测试间补两空行。最新主干额外接入现有 PR review 资格合同并单独验证(224 passed;37 个显式 opt-in 的付费模型 live qualification 未运行),不引入步骤/历史规则变化。既有组合 332 项和 14 个身份领域模拟证据仍适用;当前 head 重跑预算/探针 117 项及真实 base/head CLI(当前 main 的 96 对 96 项,0 candidate-only,7 项首次读栅栏有意差分);风险 canary 19 项通过,其生产路径与当前 head 一致。当前 Goal 的原生评审/合并契约明确 wait_for_ci=false,已停止轮询;本次批准依据当前 head 的本地入口、反例、差分与 canary 验证。接入最新 main 前曾观察到 DCO 和真实 PostgreSQL 检查成功;这些远端记录不冒充本次新 head 全绿。新 head 的远端 CI 不轮询、不以其替代本地验证;发布/部署和非要求版本路径的 skip 不当通过。用户已明确授权两 PR 自合并,仍须公开 exact-head review、无未解决 review thread 和原生 ready=true。

语义与 CI 对齐

状态规则复用 typed selector 与现有 receipt,错误保持 Goal-neutral;显式步骤编辑的 identity/task/basis 拒绝是机器义务,host continuation 文本是 guidance,二者不可混用。不存在 default-off 声明或开关;共享 CLI/status/quota/Lark 读投影及 host adapter 的默认变化均在 quota 文档、Todo 合同与测试名称中披露。旧整段 prose writer/free-text binding 已移除,历史 receipt reader 保留。语义全树、manifest 和公共边界检查通过;零 advisory carrier 不能单独证明语义安全。

我的整体评价

该完整增量与实际并行步骤污染、恢复成本相称。Future-facing pass 保持单一 typed owner,压缩重复读投影并将预算迁移判断放回现有模块的小助手;没有新步骤表或通用框架。长期效果预计正向:更少互相覆盖、更可靠恢复。每次 quota 略增输出成本,不能声称已测出端到端加速。完整 frontend 编辑旅程仍是 staged gap。

English verdict: APPROVE — exact head a18587b provides Todo-bound step isolation, restores valid distinct native Turn guidance and durable replay, and preserves authority boundaries. The measured first-read-fence output cost is bounded and disclosed. This is a validated CLI/projection increment, not frontend-editor or multi-day model-effect completion.

@huangruiteng
huangruiteng merged commit 558d214 into main Oct 4, 2026
8 checks passed
@huangruiteng
huangruiteng deleted the codex/next-action-writeback branch October 4, 2026 08:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant