Conversation
Preserve receipt-bound monitor readback without reopening execution, authorize exact GoalRef context delivery without enumerating lifecycle registries, and align replan/session fixtures with the merged contracts. Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
|
This pull request has merge conflicts with Choose the remote for the base repository, not an out-of-date fork. git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEADFor a same-repository clone whose Keep the DCO |
Wait for a retiring Effect runtime locator before the safe retry and unblock a stopped delegation supervisor during forced cleanup. Align the fingerprint and replan fixtures with their current runtime contracts. Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…ontracts-20261003 Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com> # Conflicts: # loopx/chat_configuration_api.py # loopx/chat_goal_ownership_api.py # loopx/presentation/chat_goal_ownership_api.py # loopx/presentation/goal_ownership_api.py # tests/control_plane/test_cli_output_probe_runner.py # tests/control_plane/test_native_child_closeout_cli.py
…ontracts-20261003 Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
|
CI update for
Ready for maintainer review. I will not self-merge. |
…ontracts-20261003 Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…ontracts-20261003 Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
|
This pull request has merge conflicts with Choose the remote for the base repository, not an out-of-date fork. git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEADFor a same-repository clone whose Keep the DCO |
…ontracts-20261003 Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com> # Conflicts: # loopx/control_plane/collaboration/delegation_preview_bridge.ts
huangruiteng
left a comment
There was a problem hiding this comment.
Reviewer: model_agent — gpt-6.1-sol (OpenAI); runtime_reported; reasoning_effort=xhigh
Exact reviewed head: e5f1f9e
动机
反复核验委托和监控结果的操作者,需要在重启、超时和结算重放后继续同一个任务,且不留下重复 worker。
此前精确 Goal 实例会被通用目录限制挡住;现在精确目标可通过原实例与注册校验继续回传。另一方面,新的强制清理会忘掉仍存活的 worker,下一次核验又启动一个。
实测精确目标回传恢复,selected、blocked_targets 和取消 sender 的真实撤权均不发送;真实 supervisor 卡死后,两次超时核验留下两个仍存活的 worker,完整恢复尚未达标。
本轮限定精确目标授权、只读预检进程、runtime locator 和结算投影;不证明整个团队已接续、真实外部账户交付或模型质量提升。
改动思路
精确 GoalRef 已经提供 scope、Agent 注册和实例寿命证明,因此无需把 source-session registry 当成通用 runtime catalog 再枚举;源 sender/channel/policy 仍通过同一个 TS owner。预检复用只用于长驻 MCP,只读 worker 的 process group 仍应由原 Host supervisor 收尾。可恢复的等待和已结算 monitor 的历史观察都不能变成第二次执行权限;任何 lifecycle 优化须保留这个失败边界。
具体改动
独立规范索引:docs/reference/local-delegation.md; docs/reference/protocols/manager-evidence-and-continuity-v0.md; docs/reference/protocols/quota-monitor-observation-receipt-v0.md,固定版本 558d214。逐项映射 Use an existing Agent conversation through its shell:当前未满足 single-worker、process-group cleanup 和 uncertain-cleanup 禁止重试;Ownership and defaults:精确目标通过原 Goal 实例、注册与源授权,真实撤权拒绝通过;Contract:settled 重放继续 should_run=false、must_attempt_work=false、next_turn_required,没有第二次结算权限。没有用修改后的输出或作者“兼容性”标签代替原合同。
关键代码讲解
source_context_target_authority 复用 _source_context_grant 和 TS collaboration.source.recipients,参数来自先验证的 exact Goal scope;通用目录路径仍拒绝 source_session_v1,因此修复定点回传并未开放整个目录。_close 在真正 cleanup 之前清空 process、partition、sequence 并 detach finalizer;_close_bridge 超时后只 kill Node supervisor。这两段结合,旧 detached worker 尚在运行也会允许下一次 replacement。_wait_for_runtime_locator_turnover 在发送前失败后有界等待旧 locator 换代,未删除 live locator;这个 250ms 等待只是恢复适配,不证明长期 runtime 关闭所有故障。apply_settled_monitor_precedence 恢复历史 selected_todo/next_action,执行权限仍由 settled_replay_fields 置为 skip。
Diff 是 21 文件 +360/-72。7 个生产文件涉及四个适配边界,12 个测试主要修正已有 guard/binding 与输入预期,两个 inventory 更新通过 semantic census。未来重构检查认可 source grant 抽取成一个 policy observation;进程恢复应继续复用 Host group owner,不能因 kill 成功再建一套 Python child 生命周期判断。当前没有新增 capability、公共选项或新的 persisted phase。
对主干的风险
[P1] supervisor 退出不能代替 worker group 停止。 delegation_preview_transport.py:112–121 在 cleanup 前清空 owner,65–96 的强制 kill 仅针对 Node 进程。真实 public preview 探针启动 detached Python worker,让 worker 收到请求后写出 PID 并 sleep;Node preload 在看到该 PID 后用 Atomics.wait 阻塞事件循环,使 EOF/SIGTERM handler 不再处理。保持生产 5 秒 cleanup timeout 和 1 秒请求 timeout:首次约 6.013 秒返回 TimeoutExpired,旧 worker 仍活着;同一 transport 再调用,约 6.016 秒后共有两个 live workers。所有 probe 都是 disposable fixture,finally 清理了这两个 group。原基线在 close 阻塞并保留 _process,探针通过明确的外部救援终止;没有把这个救援冒充原实现正常 cleanup。当前测试只给 supervisor 自身设置忽略 SIGTERM,没有 child,故无法发现此反例。最小修复:保留未知清理状态的 owner/partition,只有原 Host owner 已证明旧 process group 停止时才允许 replacement;supervisor 被杀不能充当 group cleanup fence。复用现有 Host 边界,避免新增平行 Python 生命周期规则。
[P2] 实际撤权集成用例仍失败。 source suite 72 passed / 1 failed,其中 revoke=True 只把 targets 置空;当前 TS owner 默认 all_registered,因此这不是撤权。独立探针确认:清空默认 targets 仍可发送,但 selected 模式清空目标、blocked_targets 或取消 sender 各为零发送。这不是权限绕过,不能靠改默认语义“修绿”;应修 fixture 并保留真实 no-send 与恢复断言。完整扩展套件另有 412 passed / 1 failed:read_only_settlement_omits_non_causal_delivery_workspace 的 hook intent_count=0,单独 head 跑通过、base 单独跑失败;在这组有界结果下不能宣布间歇性问题已解决,也尚未判定因果。保留这项未决验证,不挑选绿色重跑替代完整结果。
语义与 CI 对齐
两份 semantic inventory 和既有 typed vocabulary 被复用;development advisory 未发现新 closed set,full-tree semantic/ratchet 与全部选择的 canary 技术检查通过,未读取或等待远端 CI。generic CLI 一次性 inspection 与普通 chat 不启用 resident preview,现有 entrypoint isolation 用例通过。selected_todo 在 settled 结果中现在重新出现,应把旧文档的历史身份说明补充为明确的只读观察,并强调 must_attempt_work=false;不能当新任务或第二次 spend。主要违反的既有合同是 local-delegation.md 的“uncertain cleanup never grants retry permission”,不是未来 stop RFC 的建议要求。
我的整体评价
REQUEST_CHANGES。精确源实例的定点回传和共享 source grant 抽取有正向价值,降低无意义的目录阻塞,user_experience=improved;真实 selected/blocked/sender 拒绝未被绕过。long_horizon=regression:强制退出变快了,但未知清理状态被丢弃,重复核验积累 worker,效率与资源安全反而下降。修复应围绕已有 Host 证明和原 owner 保留,不需要扩大成新框架。历史选中项仅作观察时可接受,但必须明确只读语义;集成中的陈旧撤权 fixture 和未决 hook 结果也应保留真实的 failed/untested 区分。
English verdict: REQUEST_CHANGES — exact-target authorization usefully reuses the existing typed source policy after GoalRef/membership validation; actual selected, blocked-target and sender revocation all prevent sending. The forced preview cleanup is unsafe: it clears transport ownership and kills only the Node supervisor, while the detached Python worker may remain alive. With the production five-second cleanup wait and a blocked Node event loop, two one-second public preview calls each return after about six seconds and leave two live workers. Keep an uncertain-cleanup owner/partition and refuse replacement until the original Host proves group retirement. Add a real descendant test; the current supervisor-only SIGTERM test misses this. Also fix the stale source-session revoke fixture: clearing targets under all_registered is not revocation. The expanded suite has an unresolved intermittent hook-count failure; isolated success does not erase it. Selected canary technical checks passed, CI was not queried, and no merge was attempted. Long-horizon resource behavior currently regresses despite the useful exact-target UX repair.
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…ontracts-20261003 Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent — gpt-6.1-sol (OpenAI); runtime_reported; reasoning_effort=xhigh
Exact reviewed head: 8039296
动机
反复核验委托和监控结果的操作者,需要在重启、超时和结算重放后继续同一个任务,且不留下重复 worker。
此前精确 Goal 实例会被通用目录限制挡住;现在精确目标可通过原实例与注册校验继续回传。另一方面,新的强制清理会忘掉仍存活的 worker,下一次核验又启动一个。
实测精确目标回传恢复,selected、blocked_targets 和取消 sender 的真实撤权均不发送;真实 supervisor 卡死后,两次超时核验留下两个仍存活的 worker,完整恢复尚未达标。
本轮限定精确目标授权、只读预检进程、runtime locator 和结算投影;不证明整个团队已接续、真实外部账户交付或模型质量提升。
改动思路
精确 GoalRef 已提供原实例和 Agent 注册证明,目标回传应复用这个 scope 与原 source grant,不再通过不兼容的通用目录枚举。只读 preview 仍由 TS Host 管进程组;结算后的 monitor 只能展示原身份,不能获得第二次执行或扣费。配置备份的新增移动应保持 CLI、HTTP 和完整备份调用一致。
具体改动
逐项读完本 head 的 29 文件(+418/-107):manager_context 的目标授权与回传注册检查;source grant 共用 helper;Python preview 强制清理与 TS lifetime 起点;runtime locator 的最多 250ms 退场等待;settlement 历史身份恢复;两处内部 configuration backup 模块移动及全部 importer;两个 typed inventory/census;canonical planning、replan binding、fingerprint、Lark 结构化上下文、monitor 与 host recovery 夹具。配置移动没有新增 API 或权限,既有真实 CLI/HTTP 备份、摘要拒绝、occupied target 和 state-backup 测试通过。
关键代码讲解
source_context_target_authority(loopx/control_plane/collaboration/source_grant_observation.py:109):接收已经验证的精确 target,继续调用同一 TS recipient owner,grant 仍只允许 context delivery。_exact_return_scope(loopx/capabilities/manager_context/roundtrip.py:379):把原 Agent 加入 scope 注册检查;原会话和实例不可被别名替换。_close(loopx/control_plane/collaboration/delegation_preview_transport.py:112):清掉 process、partition、sequence 和 finalizer 后才清理进程;当前 P1 就在这个顺序及 parent-only kill。apply_settled_monitor_precedence(loopx/control_plane/quota/settlement_precedence.py:121):恢复 receipt-bound 历史选择,同时保留 should_run=false、must_attempt_work=false 和 settled phase。历史身份不是执行授权。
独立验收依据为 docs/reference/local-delegation.md; docs/reference/protocols/manager-evidence-and-continuity-v0.md; docs/reference/protocols/quota-monitor-observation-receipt-v0.md,固定版本 e15af3968f8ae20d117795a5d427624f2b85cc28。Use an existing Agent conversation through its shell not_met:不确定 process-group 清理不能允许 replacement。Ownership and defaults implemented:exact source 回传恢复,selected、blocked_targets、sender 撤权均不发送。Contract implemented:monitor CLI 重放保持已结算、不重复执行。
对主干的风险
[P1] supervisor 被强杀后仍允许启动第二个 worker。 在真实公开 preview 入口让 Node event loop 无法处理 SIGTERM,保留实际 detached Python worker,使用生产 5 秒 cleanup:第一次 6.006 秒超时后有 1 个活 worker,第二次 6.011 秒后有 2 个;两次 transport 都已 reset。临时进程已由探针 finally 清理。这与普通 SIGSTOP 可恢复或仅检查 supervisor.poll 不同。保留未知清理状态的 owner/partition,只有原 Host owner 已证明旧 process group 停止时才允许 replacement;supervisor 被杀不能充当 group cleanup fence。复用现有 Host 边界,避免新增平行 Python 生命周期规则。 回归必须同时观察父进程、worker group 和第二次 admission。
[P2] 原 revoke=True 夹具仍把清空 targets 当撤权。 tests/test_collaboration_goal_instance.py:1044 未设置 selected scope,默认 all_registered 仍授权已注册 target;本 head 实际 sends=1。应让夹具明确 selected-empty、blocked_targets 或撤销 sender。不要改变默认授权范围去迎合断言;三个真正撤权场景均已实测零发送。
当前扩展测试 546 passed / 1 failed(上述夹具),另有一条 pydantic-settings forward-reference warning。premerge 18 项选择检查及直接 diff/compile/ratchet 通过;semantic advisory 零受支持新 vocabulary carrier,不把空报告当语义证明。未读取、轮询或等待 CI。上一 head 的 hook-count 间歇失败保留在历史证据,当前整套覆盖相同断言通过,未宣称已查清其历史原因。没有外部账户、付费模型或完整 packaged frontend 验收声明。
我的整体评价
REQUEST_CHANGES。long_horizon=regression:反复 timeout 增长 worker,当前清理优化对长期资源和恢复效率是负向。user_experience=improved 的有限部分是 exact 目标不再被目录限制挡住,monitor 历史身份可读;这不能抵消 P1。没有新 actor lifecycle、claim/lease 或默认 opt-in;原 TS source/settlement owner 和闭合集合复用,新增 Python 仅做 IO/生命周期适配。future-facing pass 已检查 backup placement 和共用 grant helper,后续应修原 Host cleanup proof。此 head 不批准、不合并,两个旧 blocker 均保留。
English verdict: REQUEST_CHANGES - 8039296; repeated timeout leaves live detached workers while the transport resets, and the revoke fixture is still invalid under all_registered. 546 tests passed, one fixture failed; 18 local premerge checks passed.
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…ontracts-20261003 Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
The timeout path cleared transport ownership after SIGKILLing only the Node supervisor, so another preview could start while its detached worker remained alive. Keep the original owner and partition unless normal Host completion or a retirement fence proves process-group cleanup. Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
|
This pull request has merge conflicts with Choose the remote for the base repository, not an out-of-date fork. git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEADFor a same-repository clone whose Keep the DCO |
…ontracts-20261003 Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com> # Conflicts: # tests/extensions/test_lark_goal_topic_connections.py
The local Goal delivery guard added on main correctly rejects the old out-of-root success fixtures. Run successful host and validation paths from the registered Goal workspace while retaining dedicated rejection coverage for unqualified workspaces. Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Reuse the reviewed shared source-grant and settled-readback fixes from PR loopx-project#5533 by Duang777. Keep recipient policy in the TypeScript owner and expose only receipt-bound historical identity after settlement. Signed-off-by: song <liusongstep@gmail.com>
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent | gpt-6.1-sol | OpenAI | runtime_reported | reasoning_effort=xhigh
动机
通过复用的命令服务委托工作的调用者,在请求超时后可能遇到后台仍在执行、重试又启动一个 worker 的情况。
此前 supervisor 无法确认清理时,第二次请求仍可再开 worker;当前版本保留清理责任并立即拒绝第二次请求,避免重复执行。
独立进程反例证实不确定清理后的第二次请求被拒绝;生产代码未变的前一版本整组两次均615通过,最新版本新增的Turn测试90通过,source grant的拒绝、恢复与重复回读已验证。
本次不验收真实 Bot 切换、完整长期协作或所有运行时迁移,也不以远端 CI 状态决定结论。
真实已安装 host、Bot 切换和更广的长期协作未验收;main 继承的模块体积债务另行保留,旧版本 hook 失败根因未宣称修复。
改动思路
修复复用已有 TypeScript source grant、进程组清理及 quota receipt owner。Python 适配传输、文件和读回:无法确认 worker 清理时保留责任;已有 committed result 按当前原始 sender/target 授权返回。配置备份和 API 归入现有 capability/presentation owner,内部旧导入已更新,没有新增平行授权或长期 Agent 生命周期。
具体改动
评审绑定 5533@10e699a7634c70d167f7430706487848a43508ad,精确 base 为 1af7dbd43a1629b0356ecd5ee28a426ad45d1d7a;完整 diff31文件 +485/-133,未沿用旧批准。发布前发现旧 e18d 被更新,因此其未发布结论留作历史,并在新版本重新执行必要验证。三个规范与旧已读内容逐字相同,版本基准仍更新为当前 immutable base。
关键代码讲解
loopx/control_plane/collaboration/delegation_preview_transport.py:121,ReusableDelegationPreviewTransport._close:Retain live cleanup responsibility。Unknown cleanup cannot permit another process。调用 _close_bridge terminates/waits; bridge retirement confirms group cleanup 后交给 Next preview call sees retained owner;失败由 Transport owns retry refusal; no automatic respawn 处理。loopx/control_plane/collaboration/source_grant_observation.py:109,source_context_target_authority:Validate exact authorized target for source return。Fresh registry/source grant and current sender identity still required。调用 _source_context_grant -> TS source.recipients 后交给 Manager result return;失败由 Missing/revoked source/target rejects; not a generic catalog bypass 处理。loopx/capabilities/manager_context/roundtrip.py:379,_exact_return_scope:Original result return scope。No invented alternate Agent/instance。调用 source_context_target_authority 后交给 Committed return/readback;失败由 Fail closed on unavailable original actor/grant 处理。loopx/control_plane/quota/settlement_precedence.py:121,apply_settled_monitor_precedence:Historical monitor readback。should_run=false/must_attempt=false; no new execution。调用 Existing receipt projection 后交给 heartbeat recommendation and status;失败由 Same Turn skips; cannot reopen completed monitoring 处理。
规范:docs/reference/local-delegation.md @ 1af7dbd43a1629b0356ecd5ee28a426ad45d1d7a 的 Use an existing Agent conversation through its shell 已满足 timeout/unknown-cleanup fail-closed。docs/reference/protocols/manager-evidence-and-continuity-v0.md 同版本的 Ownership and defaults 已验证原 sender 与 registered target;docs/reference/protocols/quota-monitor-observation-receipt-v0.md 同版本的 Contract 保留 settled 历史回读并禁止新义务/refresh/spend。
当前独立 source probe:selected builder 可接收原结果;同一 Goal 的 reviewer 不在 scope 时拒绝;注册新 observer 后仍不自动获授权;未注册 target 拒绝。撤回真实原 sender 后 return0,恢复原 sender 后 return1且 source/session/Turn 不变,再次 drain0。这既检查拒绝,也检查恢复到有用结果。
对主干的风险
没有剩余阻塞 finding。旧两份 review 的 worker 清理与 sender-grant 负例已逐项复核:真实 blocked Node supervisor、原生产5秒 cleanup timeout 下,历史8039296的两次请求产生两个 worker;当前7109第一次超时后保留 owner,第二次快速拒绝,只有一个 worker。fixture 最后清除全部进程。revocation fixture 采用明确 selected-empty;当前 source恢复 probe 验证授权与拒绝两方向,不以 targets空且all_registered当作撤权。
验证:运行时相同的7109 head 同一完整 changed/adjacent suite 两次615 passed,Pydantic forward-reference warning保留;当前精确 base554 passed/59失败,主要是本 PR 修复的 source/instance/fixture契约不兼容。191架构/语义检查、TS typecheck、scoped Ruff和diff check通过;risk canary直接检查及19项选择通过,包含下述继承 advisory。fresh CLI与复用 MCP 在相同 validator drift、unsafe/recovery和workspace分区上比较完整JSON,并验证无host启动/Turn/authority副作用,base和head相关用例通过。
历史失败未删除:旧e18d整组两次出现 terminal hook 0 != 1,当时孤立base/head均通过,根因仍未知。这没有被称为已修复;7109两次完整原工作负载、相同终态断言和独立scope/恢复证据,加上10e699新增测试资格共同支持本次资格,结论只覆盖当前版本。
独立无关债务:maintainability ratchet在真实Git base/head都失败,唯一unreviewed项是未改动的 loopx/extensions/lark/goal_topic_runtime.py,同为1649lines/56Any;scanner/metric baseline/该模块均一致。初次archive测量被Git扫描范围影响而false-green,已作废并换成native Git baseline。这项债务由原Lark owner处理,不放宽预算,不宣称全树完全绿色;approval与merge hold分别记录。
可重复完整命令:
uv run --extra test python -m pytest -q tests/test_delegation_preview_reuse.py tests/test_collaboration_goal_instance.py tests/test_manager_context_roundtrip.py tests/test_manager_context_handoff.py tests/test_configuration_backup.py tests/test_state_backup.py tests/control_plane/test_canonical_planning_consumers.py tests/control_plane/test_effect_runtime_integration.py tests/control_plane/test_goal_amendment_proposal_lifecycle.py tests/control_plane/test_long_chain_projected_closeout.py tests/control_plane/test_monitor_followthrough_contract.py tests/control_plane/test_quota_plan_observation_payload.py tests/control_plane/test_quota_settlement_cli.py tests/control_plane/test_refresh_checkpoint_recovery.py tests/control_plane/test_replan_successor_durable_ack.py tests/control_plane/test_runtime_source_read_batching.py tests/control_plane/test_settled_monitor_user_gate.py tests/extensions/test_lark_goal_topic_connections.py tests/test_loopx_turn_executor.py最新10e699增量仅修改 tests/test_loopx_turn_driver.py 的8处workspace fixture,从未获准的空目录改为真实Goal producer root;所有生产/typed/frontend/规范源码与7109逐字一致。实际最新head补跑整组Turn driver为90 passed;精确base为78 passed/12 failed,均暴露旧不合格workspace输入。unowned terminal recovery仍有负例,不把移除权限断言当修绿。复用615×2和故障/恢复证据经过完整差异失效检查,明确不是声称615用例在10e699重新执行。
语义与 CI 对齐
policy revision18的 typed state、authority、default-off、行为披露、domain neutrality和guidance/obligation lenses均按实际路径执行。保留的monitor Todo是phase=settled历史证据,不能被显示存在误当作可执行;改动没有通过substring/prose扩大授权。语义advisory空结果不代替动态规则证明。未查询、轮询或等待远端 CI;继承本地债务按同命令、同signature、未变因果路径归因。
我的整体评价
这个有界修复改善重复调用的安全与原始结果返回,真实失败后也能按原grant恢复进展。当前本地必要证据支持批准;真实installed host、Bot与更广长期接受条件仍未声称完成。Future-facing pass已在PR应用:共用source-grant规则、退役旧backup模块位置,并保持一个TS进程组 authority;无需为本次修复再建新runtime框架。
English verdict: APPROVE. Current exact-head cleanup, scoped result return and settlement compatibility are qualified by two complete615-case runs and independent real fault/recovery evidence. Preserve unknown old-head hook history and independently matched baseline module debt; this approval does not grant runtime merge authority.
All findings reverified at 10e699a; exact-head approval review5406199196 is preserved. P1: production5s cleanup with a blocked Node event loop now retains owner/partition, refuses request2 promptly and keeps one real worker; old8039296 counterexample creates two. P2: revocation fixture now explicitly selects empty recipients; native selected-scope probe rejects uncovered/new/unregistered targets, blocks revoked sender, then restores the original source/session/Turn once with replay0. Earlier hook0!=1 history remains unknown, not claimed fixed: identical-runtime7109 full workload615 passed twice; latest test-only10e699 Turn suite90 passed, with complete shipped-source equality checked. Settled monitor remains read-only and cannot rearm work/spend. Unchanged base/head Lark module metric debt remains separate. Findings are resolved/independently qualified; discussion retained. 已逐项核验当前版本,撤回旧阻塞状态,保留讨论和历史失败证据。
…ontracts-20261003 Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…ontracts-20261003 Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…ontracts-20261003 Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent — gpt-6.1-sol (OpenAI); runtime_reported; reasoning_effort=xhigh
精确 head:63cd618d9575f6f959b471493c45e30ab023b9b1;全 PR 基线:8ce73724b9d590bb48a05c46abfdcec63d1c2b7b。独立复审整个新 diff 后,未发现仍阻塞本 PR 的问题。
动机
通过 manager 委托已注册 worker、等待原会话收到结论,以及长驻 MCP 中反复检查 worker 的调用者会遇到这些兼容问题。
旧版本把严格 Goal 实例的定点回传误判为目录不可用;上一轮修复还会在清理未知时丢掉旧进程所有权,使第二次检查再启动一个 worker。
新 head 的定点回传及重启重放成功;真实清理故障下第二次检查被拒绝,worker 数保持 1,撤权的三个负例均为零发送。
本 PR 修复既有合同兼容和内部模块归属,不新增执行权限、配置开关或 UI 旅程;未知清理后的自动恢复、Windows 清理和长期吞吐不在这次实测结论内。
本次先对照既有规范,再重做完整 PR 判断。主要规范是 docs/reference/local-delegation.md,固定版本 8ce73724b9d590bb48a05c46abfdcec63d1c2b7b;验收项为 uncertain-cleanup-no-retry、verified-retirement-only、one-shot-isolation,三项均有实际通过证据。另核验同版本 docs/reference/protocols/manager-evidence-and-continuity-v0.md 的原会话回传/实时授权,以及 docs/reference/protocols/quota-monitor-observation-receipt-v0.md 的 settled Turn 不再执行或消费配额。
改动思路
定点 deliver/return 先由既有 GoalRef scope 校验实例和 agent 注册,再交给共享 source grant owner 核验该 target 的来源、sender 和目标范围。避免让精确定点操作依赖不适用于严格实例的全目录枚举;没有跳过 membership 或撤权。
预检仍由 TypeScript Host 管进程组。Python 适配器保留未知清理状态:Node supervisor 被强杀不代表 detached worker 已停止;没有可信 retirement proof 就拒绝 replacement。读写、退役、超时继续共用原 deadline 和单次安全重试合同。一次性 CLI/Chat、leased execution 不承担 resident preview 行为。
其余修复复用既有 owners:RPC 在发送前连接失败时有界等待 locator 换代;settled monitor 保留历史身份观察,但执行、refresh/spend 权限仍为 false;acceptance 的 work digest 排除已有 completion receipt 元数据;配置备份归入 capability 与 presentation。
具体改动
全 diff 为 33 文件 +489/−135,包含两个内部模块移动,未新增公共开关或 persisted phase。
DelegationPreviewTransport._close(loopx/control_plane/collaboration/delegation_preview_transport.py,121 行):确认清理后才释放 owner;preview在未知状态拒绝第二次启动。TS bridge 的 lifetime timer 在 Host spawn 后初始化。旧 P1 的实际 detached-worker 场景已复现修复。source_context_target_authority(loopx/control_plane/collaboration/source_grant_observation.py,109 行):复用_source_context_grant,供经过精确 scope 的 deliver 与_exact_return_context使用;定点 return 显式传入唯一 agent。_wait_for_runtime_locator_turnover(loopx/control_plane/effect_runtime.py,465 行):仅发送前失败后等待最多 min(原 timeout, 250ms),不删除新 locator,不增加无限重试。apply_settled_monitor_precedence(loopx/control_plane/quota/settlement_precedence.py,121 行):恢复 receipt-bound 历史观察,仍保留 skip、must_attempt_work=false 和所有 delivery/spend 拒绝。acceptance_contract.ts将已有completion_receipt_id归为非 work 字段,避免普通完成凭据误使绑定过期。configuration_backup.py移到 capabilities、HTTP mixin 移到 presentation;CLI/Chat/state backup 的活跃 imports 同步更新,原内部文件移除,没有 speculative compatibility wrapper。I/O census 和 Goal instance binding inventory 同步;mutation harness 改为当前真实 CAS 锚点,现有 replan/Turn/host fixtures 绑定当前合同。
对主干的风险
强反例实测:Node event loop 不响应 SIGTERM,而 worker 仍运行。上一轮 head 的两次检查各约 6 秒、留下两个 worker;当前 head 首次约 6.02 秒,第二次 0.012 秒直接拒绝,只有一个 worker,transport 不重置。探针最后显式清理自己的测试进程;没有把这个清理冒充产品自动恢复。正常 timeout、source invalidation、合法退役及非法 fence 的恢复/拒绝另由真实进程测试覆盖。
授权反例:selected 下 targets=[]、blocked_targets、sender_ids=[] 各零发送。默认 all_registered 下清空 targets 仍能发给当前已注册成员,符合原 typed policy;旧 P2 已改为真实 selected 撤权,不能以修改默认授权“修绿”。定点回传的 base/head 对照使用隔离磁盘状态、真实 typed admission;外部发送回调是模拟 provider,并非真实飞书发送。legacy transcript 同 ID 不同文本的历史行为两边相同,属于已有 delivery adapter 问题,本 PR 未修改其因果路径。
本 head:395 项 Python 功能/兼容用例、287 项架构/I/O/边界检查、238 项 host/runtime 用例均通过;control-plane typecheck 通过;选定 TS 套件 137 passed、15 skipped、0 failed。15 项是未提供隔离 PostgreSQL 连接的 provider 扩展;本 PR 没有改 PostgreSQL store/迁移,已通过 File/SQLite 的实际 CLI/备份/settlement 路径,不能宣称 PostgreSQL 已测。development semantic advisory 先于 full-tree suite。早先不存在测试路径的命令属于评审准备错误,已纠正;历史红灯不冒充当前结果。
不查询 CI。未执行真实外部消息、Windows 故障注入或长期 soak。unknown cleanup 仍要求 owner 清理/恢复,属于原规范明确的 fail-closed 边界;它消除了重复 worker 的放大,未承诺无人工介入的万能恢复。
我的整体评价
APPROVE。这次重置了上一轮的判断,既核验 P1/P2 修复,也覆盖当前完整 33 文件。效果上的正向证据是严格实例的合法回传恢复、sender/目标撤权仍生效、settled 回放没有重新执行;效率上的正向证据是重复失败不再增加 worker,也不需要为合法定点操作绕过或改写授权目录。未测长期吞吐和模型任务收益,不能把通过数量当成这些结论。
未来重构检查已应用:source grant 共用一个 owner;两个配置备份模块删除旧内部入口、保留实际 caller 与现有 persisted backup 格式。进一步进程自动恢复需继续由 Host 的可信 group proof 驱动,本次不新增第二套 Python 进程生命周期。
English verdict: APPROVE — 63cd618. Exact-instance return now succeeds while selected/blocked-target/sender revocation still prevents sending. The production-timeout detached-worker fault retains one poisoned owner and rejects a second preview instead of accumulating workers. Current checks: 395 functional, 287 architecture and 238 host/runtime tests pass; TS has 137 passes and 15 optional PostgreSQL skips; typecheck passes. Unknown cleanup remains fail-closed, no live external send or Windows/long-soak qualification is claimed, and no merge was attempted.
…ontracts-20261003 Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…ontracts-20261003 Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Goal And Delivered Outcome
main; related to fix(ci): restore shared source qualification contracts #5526.main.Author Declaration
Implemented against
main@e55489c77and the request in this PR are the basis.source_context_target_authorityapply_settled_monitor_precedencetests/test_loopx_turn_executor.pyScope And Continuation
Validation
17590f29bunitpassedstaticpassedgit diff --checkintegrationpassedregression_paritypassedstaticpassedFrontend / Visual Evidence
Type of Change
LoopX Area
Technical Direction
Shared-authority RFC fixture impact
Boundary Checklist
.loopx/,.codex/goals/, and liveACTIVE_GOAL_STATE.md).none.Signed-off-bytrailer (git commit -s).