Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
34 commits
Select commit Hold shift + click to select a range
3bf6160
docs(rfc): specify the lease-fenced delegation stop contract
songoow Oct 3, 2026
29a0695
fix(review): judge historical failures by current invariant evidence
huangruiteng Oct 3, 2026
28ee464
fix(ci): restore shared source qualification contracts (#5526)
jackie-cqz Oct 3, 2026
dbefcf7
fix(subagents): observe native Codex child events on owned Turns
jackie-cqz Oct 2, 2026
49c2c32
docs(subagents): explain native host provenance and protocol limits
jackie-cqz Oct 2, 2026
50b6b8c
test(subagents): cover native receipt replay and product readback
jackie-cqz Oct 2, 2026
4d58655
fix(subagents): preserve receipt correlation across host resumes
jackie-cqz Oct 2, 2026
326322d
refactor(codex): place native child receipts at the provider seam
jackie-cqz Oct 3, 2026
bf6753d
test(codex): reproduce resumed followup result ownership
jackie-cqz Oct 3, 2026
29668f8
fix(codex): recover the latest native followup result binding
jackie-cqz Oct 3, 2026
c15b9ba
docs(codex): describe durable followup result recovery
jackie-cqz Oct 3, 2026
cdfa279
fix(codex): bind terminal snapshots to their own decision
jackie-cqz Oct 3, 2026
ddac460
docs(native-child): clarify terminal replay ownership
jackie-cqz Oct 3, 2026
f241c56
fix(codex): retain consumed wait result ownership across replay
jackie-cqz Oct 3, 2026
c2ea347
chore(codex): drop the lineage import the session refactor moved
huangruiteng Oct 3, 2026
5d790b4
Merge pull request #5455 from jackie-cqz/codex/fix-native-child-host-…
huangruiteng Oct 3, 2026
06a789f
feat(research): execute public GitHub evidence and read back admitted…
jackie-cqz Oct 2, 2026
b94d024
test(research): qualify provider failures and actual conversation rea…
jackie-cqz Oct 2, 2026
e0f5417
docs(research): record public provider qualification and remaining de…
jackie-cqz Oct 2, 2026
45e9847
fix(research): preserve case-sensitive pinned source lineage
jackie-cqz Oct 2, 2026
7c0000a
fix(research): reuse the canonical content digest matcher
jackie-cqz Oct 3, 2026
dce7d69
test(research): register the canonical digest consumer
jackie-cqz Oct 3, 2026
99839ae
Merge pull request #5459 from jackie-cqz/codex/fix-public-github-evid…
huangruiteng Oct 3, 2026
a91b3d1
docs(rfc): bound stop drain by the proven expiry, not a fixed interval
songoow Oct 3, 2026
dbdeb98
docs(rfc): distinguish stop proposal from current review contract
songoow Oct 3, 2026
8c1663f
Merge branch 'main' into codex/delegation-stop-contract
songoow Oct 4, 2026
bd37a9c
docs(delegation): require host evidence before claiming drain
songoow Oct 4, 2026
9f2b710
fix(collaboration): default trusted sources to registered local recip…
huangruiteng Oct 4, 2026
359a0a8
Merge pull request #5534 from songoow/codex/delegation-stop-contract
huangruiteng Oct 4, 2026
78595db
fix(collaboration): preserve revocation intent under disabled Goal
huangruiteng Oct 4, 2026
a04fc20
test(collaboration): restore recipient before metadata-only parity check
huangruiteng Oct 4, 2026
6a172f6
Merge pull request #5558 from loopx-project/codex/owner-local-deliver…
huangruiteng Oct 4, 2026
c453bbe
Merge existing review evidence repair into current validation worktree
loopx-agent Oct 4, 2026
851e915
fix(review): separate code approval from CI completion
loopx-agent Oct 4, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions apps/presentation/dashboard/src/data/status.ts
Original file line number Diff line number Diff line change
Expand Up @@ -363,8 +363,8 @@ export const projectAssetTodoProjectionGapSchema = z.object({

export const nativeChildActivitySchema = z.object({
schema_version: z.literal("native_subagent_activity_v0"),
observation: z.enum(["unknown", "coordinator_reported"]),
host_attested: z.literal(false),
observation: z.enum(["unknown", "coordinator_reported", "host_observed", "mixed"]),
host_attested: z.boolean(),
configured_limit: z.number().int().nonnegative(),
launched_count: z.number().int().nonnegative(),
skipped_count: z.number().int().nonnegative(),
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -801,10 +801,12 @@ export function ContextDrawer({ agents, attentionHistory = [], onSelectAttention
<button className="personal-secondary-action" onClick={() => callbacks.onRequestScheduleConfig?.("heartbeat", selection.item.goalId)} type="button"><Radio size={16} />{t("drawer.setupHeartbeat")}</button>
<button className="personal-secondary-action" onClick={() => callbacks.onRequestScheduleConfig?.("monitor", selection.item.goalId)} type="button"><CalendarClock size={16} />{t("drawer.scheduleAdd")}</button>
</div> : null}
{selection.item.nativeChildActivity?.observation === "coordinator_reported" ? (
{selection.item.nativeChildActivity && selection.item.nativeChildActivity.observation !== "unknown" ? (
<section className="personal-detail-card personal-native-child-activity">
<h3>{t("drawer.subagentReportTitle")}</h3>
<p>{t("drawer.subagentReportedActivity", {
<p>{t(selection.item.nativeChildActivity.observation === "host_observed"
? "drawer.subagentHostActivity" : selection.item.nativeChildActivity.observation === "mixed"
? "drawer.subagentMixedActivity" : "drawer.subagentReportedActivity", {
started: selection.item.nativeChildActivity.launched_count,
skipped: selection.item.nativeChildActivity.skipped_count,
rejected: selection.item.nativeChildActivity.capacity_rejected_count,
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -296,6 +296,8 @@ const en = {
"drawer.subagentCurrentBoundary": "Current task-domain restriction",
"drawer.subagentDescription": "Allows the runtime to create temporary child agents for independent tasks only after Todo, quota, capability, and write-scope gates pass. It does not force parallel work or grant durable authority.",
"drawer.subagentReportTitle": "Child activity",
"drawer.subagentHostActivity": "Host-observed activity: {started} starts, {rejected} capacity rejections, {failed} host failures, {accepted} parent-accepted results.",
"drawer.subagentMixedActivity": "Host observations and coordinator reports: {started} starts, {skipped} skips, {rejected} capacity rejections, {failed} host failures, {accepted} parent-accepted results. Some decisions are unverified.",
"drawer.subagentReportedActivity": "Latest coordinator report: {started} starts, {skipped} skips, {rejected} capacity rejections, {failed} host failures, {accepted} parent-accepted results. Host verification is unavailable.",
"drawer.subagentDisable": "Preview turning off sub-agent execution",
"drawer.subagentDisableSummary": "New child-agent execution will be disabled for this Goal. Existing Todo ownership and execution records stay unchanged.",
Expand Down Expand Up @@ -1574,6 +1576,8 @@ const zhCN: Record<WorkspaceMessageKey, string> = {
"drawer.subagentCurrentBoundary": "当前任务领域限制",
"drawer.subagentDescription": "仅在 Todo、配额、能力和写入范围门禁全部通过后,允许运行时为相互独立的任务临时创建子代理;不会强制并行,也不会授予持久权限。",
"drawer.subagentReportTitle": "子代理活动",
"drawer.subagentHostActivity": "宿主已观察:启动 {started} 次、容量拒绝 {rejected} 次、宿主失败 {failed} 次、主 Agent 验收 {accepted} 项。",
"drawer.subagentMixedActivity": "宿主观察与主 Agent 回报:启动 {started} 次、跳过 {skipped} 次、容量拒绝 {rejected} 次、宿主失败 {failed} 次、主 Agent 验收 {accepted} 项;部分决策未经宿主核验。",
"drawer.subagentReportedActivity": "最近一轮主 Agent 回报:启动 {started} 次、跳过 {skipped} 次、容量拒绝 {rejected} 次、宿主失败 {failed} 次、主 Agent 验收 {accepted} 项;目前没有宿主核验。",
"drawer.subagentDisable": "预览关闭子代理执行",
"drawer.subagentDisableSummary": "这个 Goal 将不再创建新的子代理;现有 Todo 归属和执行记录不受影响。",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -159,8 +159,8 @@ export type WorkspaceGoal = {
subagentExecution?: WorkspaceGoalSubagentConfiguration;
nativeChildActivity?: {
turn_instance_id: string;
observation: "unknown" | "coordinator_reported";
host_attested: false;
observation: "unknown" | "coordinator_reported" | "host_observed" | "mixed";
host_attested: boolean;
launched_count: number;
skipped_count: number;
capacity_rejected_count: number;
Expand Down
4 changes: 2 additions & 2 deletions apps/presentation/dashboard/src/views/dashboard-page.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -468,8 +468,8 @@ type PersonalGoalItem = {
hasRunObservation: boolean;
nativeChildActivity?: {
turn_instance_id: string;
observation: "unknown" | "coordinator_reported";
host_attested: false;
observation: "unknown" | "coordinator_reported" | "host_observed" | "mixed";
host_attested: boolean;
launched_count: number;
skipped_count: number;
capacity_rejected_count: number;
Expand Down
2 changes: 1 addition & 1 deletion docs/architecture/rfcs/STATUS.md
Original file line number Diff line number Diff line change
Expand Up @@ -61,7 +61,7 @@ appendix may keep dated history, but no dated log heading may precede it.
| [RFC: Research Exploration Control Plane v0](research-exploration-control-plane-v0.md) | Accepted | none | — |
| [RFC: Semantic Vocabulary Convergence and Commit-Time Drift Checks (v0)](semantic-vocabulary-convergence-v0.md) | Accepted | none | [5 entries](ledger/semantic-vocabulary-convergence-v0/) |
| [RFC: Shared Goal Alignment and Governed Amendment Protocol (v0)](shared-goal-alignment-and-governed-amendment-v0.md) | Accepted | none | [2 entries](ledger/shared-goal-alignment-and-governed-amendment-v0/) |
| [RFC: LoopX Shared Control-Plane Authority and Pluggable State Providers (v0)](shared-goal-authority-state-provider-v0.md) | Accepted | none | [23 entries](ledger/shared-goal-authority-state-provider-v0/) |
| [RFC: LoopX Shared Control-Plane Authority and Pluggable State Providers (v0)](shared-goal-authority-state-provider-v0.md) | Accepted | none | [24 entries](ledger/shared-goal-authority-state-provider-v0/) |
| [RFC: Single-Owner Local Daemon (v0)](single-owner-local-daemon-v0.md) | Accepted | none | — |
| [RFC: TypeScript Control-Plane Migration Direction v0](typescript-control-plane-migration-v0.md) | Accepted | none | [14 entries](ledger/typescript-control-plane-migration-v0/) |

Expand Down
2 changes: 1 addition & 1 deletion docs/architecture/rfcs/STATUS.zh-CN.md
Original file line number Diff line number Diff line change
Expand Up @@ -58,7 +58,7 @@
| [RFC:研究型探索控制面 v0](research-exploration-control-plane-v0.zh-CN.md) | 已接受 | 无 | — |
| [RFC:语义词表收敛与提交期漂移检查(v0)](semantic-vocabulary-convergence-v0.zh-CN.md) | 已接受 | 无 | [5 条](ledger/semantic-vocabulary-convergence-v0/) |
| [RFC:共享 Goal 对齐与受治理 Amendment 协议(v0)](shared-goal-alignment-and-governed-amendment-v0.zh-CN.md) | 已接受 | 无 | [2 条](ledger/shared-goal-alignment-and-governed-amendment-v0/) |
| [RFC:LoopX 共享控制面权威与可插拔状态 Provider(v0)](shared-goal-authority-state-provider-v0.zh-CN.md) | 已接受 | 无 | [23 条](ledger/shared-goal-authority-state-provider-v0/) |
| [RFC:LoopX 共享控制面权威与可插拔状态 Provider(v0)](shared-goal-authority-state-provider-v0.zh-CN.md) | 已接受 | 无 | [24 条](ledger/shared-goal-authority-state-provider-v0/) |
| [RFC: Single-Owner Local Daemon (v0)](single-owner-local-daemon-v0.md) | 已接受 | none | — |
| [RFC:LoopX 控制面 TypeScript 渐进迁移方向 v0](typescript-control-plane-migration-v0.zh-CN.md) | 已接受 | 无 | [14 条](ledger/typescript-control-plane-migration-v0/) |

Expand Down
28 changes: 17 additions & 11 deletions docs/architecture/rfcs/capable-manager-semantic-handoff-v0.md
Original file line number Diff line number Diff line change
Expand Up @@ -219,17 +219,23 @@ grant for linked Core details. The shipped managed-Goal context grant below is
a bounded step; full planning/effect inheritance still needs its typed grant
chain, installed receiver adoption and original-route acceptance.

Use managed Goal scope for an authenticated owner's context-delegation grant:
all current and future registered Agents within those Goals inherit it. Avoid
requiring separate enrollment every time a worker joins. Retain exact-recipient
grants for restricted sources, and explicit recipient revocations that override
the Goal grant. New Goals, evidence-read scope and execution permissions are
separate authority; registration or a quoted request cannot expand them.
The shared `collaboration/source_grants.ts` owner resolves the same current
policy for the catalog, direct handoff and peer forwarding. The existing local
operator command can configure a Goal target by omitting `--agent-id`, with
preview, locked apply and readback. This bounded configuration slice does not
qualify settings-UI editing, native receiver adoption or the full M1–M3 journey.
**Local context-delivery default.** An operator-configured source with a verified authorized
sender defaults to all active registered recipients on its selected local registry,
across Goals and later registrations. `local_delivery_scope=selected` deliberately
retains an enrollment boundary; an old enrollment list alone no longer restricts
the default. Explicit Agent and Goal exclusions survive broad restoration and
apply at direct delivery, replay and each parent-forwarding hop. Missing or
malformed source provenance cannot activate the default. Context delivery grants
no evidence-read expansion, remote delivery, execution, claim/lease or protected
operation. Shared TypeScript `collaboration/source_grants.ts` owns the decision;
Python observes registration/provenance and persists operator changes. Qualify
cross-Goal delivery, future registration, revoked replay and original-route return
through the existing App/Lark conversation, without claiming worker adoption from
catalog access. The existing local operator commands preview, apply and read back exceptions.
Restoring a Goal retains its individually revoked Agents; selected scope can
enroll a whole Goal by omitting `--agent-id`. Editing source policy in packaged
settings remains an unqualified configuration journey. Native receiver adoption
and full M1–M3 execution are separate acceptance gates.

LoopX state mutations always use the existing typed command boundary, even if initiated through shell. The manager does not edit registry/authority files behind the control plane. Repository modifications use the project's normal worktree/review practice. Scoped merge/deploy authorization may be reused; unrelated payment or trading authority cannot be inferred from it.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -78,11 +78,11 @@ inventory-only row for the same provider id.

## Product surfaces

- CLI: `external-evidence discover|plan|receipt|admit|retire`.
- Managed Turn: the same five effect-runtime methods.
- Frontend/Lark: not changed in this Core slice. A companion slice should render
the same typed plan/admission projection and readback; it must not invent a
second registry or lifecycle.
- CLI: `external-evidence discover|plan|execute|receipt|admit|readback|retire`.
- Managed Turn: the same five typed effect-runtime methods; explicit provider
execution and ledger projection use the capability's CLI owner.
- Frontend/Lark: existing conversation answer/report and Markdown transports
render the shared validated readback. No independent registry or lifecycle.

## Acceptance

Expand All @@ -102,6 +102,29 @@ inventory-only row for the same provider id.
- retirement waits for downstream coverage of every admitted source;
- CLI and effect-runtime TypeScript tests pass from the source checkout.

## Delivery checkpoint (2026-10-02)

The public GitHub method now completes a bounded real journey: anonymous pinned
file reads, exact-plan receipt validation, a separate parent decision, projection
into the existing deepresearch source ledger, actual lineage readback and retirement.
Optional source refs and literal search terms are bound into the request/plan digest;
legacy requests retain their existing identity. The provider is bundled in extensions
under `method:public-github`; capability and ledger owners remain unchanged.

Passed: real public-provider/source CLI journey; negative cases for private or stale
readiness, malformed/unpinned sources, plan/admission mutation, partial/empty/failed
reads, independent admission and coverage, wrong-question projection, budget failure
and idempotent replay; packaged desktop/mobile conversation readback and reload;
existing Lark Markdown presentation. Source bodies are not persisted. The shared
Markdown readback uses existing answer/report and Lark transports; no frontend
configuration or parallel evidence authority is needed.

Commands are in the [versioned capability guide](../../../loopx/capabilities/external_research/README.md#public-github-method--公开-github-方法).
Live Lark delivery, authenticated connector execution and broader semantic research
quality remain untested; this checkpoint does not promote those providers or close
S6/S8. Failed or partial results preserve original-source fallback, and neither a
successful read nor a parent admission certifies evidence completeness.

## Non-goals

- a universal browser/search engine;
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -60,10 +60,11 @@ Connector registry 继续只拥有库存与遥测。`supported` 绝不映射为

## 产品入口

- CLI:`external-evidence discover|plan|receipt|admit|retire`;
- Managed Turn:复用同五个 effect-runtime 方法;
- Frontend/Lark:本 Core 切片不修改。后续 companion slice 只渲染同源 plan/admission
投影与读回,不建立第二个 registry 或生命周期。
- CLI:`external-evidence discover|plan|execute|receipt|admit|readback|retire`;
- Managed Turn:复用五个 typed effect-runtime 方法;显式 provider 执行与账本投影
使用能力的 CLI owner;
- Frontend/Lark:现有会话答复/报告和 Markdown 运输渲染同源校验回读,
不建立独立 registry 或生命周期。

## 验收

Expand All @@ -80,6 +81,24 @@ Connector registry 继续只拥有库存与遥测。`supported` 绝不映射为
- 全部被采纳来源完成下游覆盖前不得退休;
- CLI 与 effect-runtime TypeScript 测试在源码 checkout 中通过。

## 交付检查点(2026-10-02)

公开 GitHub method 已完成有界真实链路:匿名读取固定提交文件、精确 plan 回执校验、
独立父 Agent 决定、投影到现有 deepresearch 来源账本、实际 lineage 回读与退休。
可选 source refs 和字面检索词进入 request/plan digest;旧请求身份保持兼容。
provider 以 `method:public-github` 内置在 extensions,能力和账本 owner 不变。

通过:真实公开 provider/源码 CLI 链路;私有或过期 readiness、无效/未固定来源、
plan/admission 篡改、部分/空/失败读取、独立采纳与覆盖、问题不匹配、预算耗尽及
幂等重放等负向用例;打包桌面/移动会话回读与重载;现有 Lark Markdown 展示。
不持久化来源正文。同源 Markdown 沿用现有答复/报告和 Lark 运输路径,
无需新增前端配置或并行证据权威。

命令参见[版本化能力指南](../../../loopx/capabilities/external_research/README.md#public-github-method--公开-github-方法)。
真实 Lark 送达、带凭据 connector 执行和更广泛语义研究质量尚未验证;
该检查点不晋升这些 provider,也不关闭 S6/S8。失败或部分结果保留原始来源退路;
读取成功和父 Agent 采纳均不证明证据完整性。

## 非目标

- 通用浏览器或搜索引擎;
Expand Down
Loading
Loading