fix(service): qualify owned wheels and retain macOS workspace selection - #5543
huangruiteng wants to merge 2 commits into
Conversation
…tion Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
|
This pull request has merge conflicts with Choose the remote for the base repository, not an out-of-date fork. git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEADFor a same-repository clone whose Keep the DCO |
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent · gpt-6.1-sol · OpenAI · runtime_reported · xhigh
[P1] 普通 pip 安装仍被新运行时指纹校验拒绝。
动机
用普通 pip 安装后管理本机后台服务的用户,需要确认服务运行的是当前安装包,并保留已选工作区。
以前后台服务校验只接受带发布清单的快照,普通包管理器安装会被拒绝;本改动拟接受属于当前安装的实际包文件,并保留已有工作区选择。
已验证禁用字节码编译的同一 wheel 能获得指纹;但普通 pip 安装仍没有指纹,后台服务的合法安装入口尚未修好。
本轮不验收真实 launchctl 常驻升级、用户已有服务迁移、跨主机或发布,也不把包指纹当发布者认证。
改动思路
复用 release_runtime_identity 为无发布清单的包管理器安装添加实际字节摘要;不能仅凭版本相同认定服务是当前安装。ChatHTTPServer 与 StatusHTTPServer 构造时保存启动身份,之后 HTTP 不随磁盘升级改写旧进程。doctor 提供实际 Python 解释器,macOS helper 使用所选 console 的解释器解析并保存既有 registry、Codex home、工作区列表。既有 snapshot 和 package manager 各自保留原 ownership。
规范依据:docs/guides/installing-loopx.md,不可变版本 99839aeb8fed5fae38a5d319391cd050672a6508。逐项判断:
-
Installation owner and package: not_met — Real default pip wheel install records1212 pyc and returns no fingerprint; no-compile same wheel returns a digest..
-
Managed Effect runtime: implemented — pr5543-144225 native and owner counterexample/control evidence.
-
Rollback: deferred — Mocked helper reinstall/restart/context retention verified; no actual user launchctl rollback performed..
具体改动
全量13文件396+/34-。release_manifest.py:348 的 _distribution_runtime_fingerprint 核验非editable、精确版本、真正导入模块、完整文件集合和symlink,哈希真实字节;doctor/installation-only doctor 读同一身份和解释器。两个HTTP server冻结构造身份;现有dashboard readiness复用该身份。
macOS helper 优先询问选定console的解释器,解析已有plist环境与旧shlex参数;registry必须绝对路径,roots是最多32项的现存绝对目录JSON,去重并逐项quote。显式registry同时传给Chat/status,移除会覆盖自定义registry的global选项;先验证身份/参数再bootstrap。IO manifest只是行号变化。focused distribution/server/dashboard/doctor测试、mocked helper smoke及双语安装说明覆盖同一改动。
缺陷在 release_manifest.py:360–377:安装清单集合保留所有loopx/条目,磁盘集合却排除__pycache__/pyc/pyo;真实pip默认安装会在RECORD记录生成的pyc。独立构建当前head的完整wheel,在隔离Python3.12环境用真实pip正常安装,读到2800项loopx文件,其中1212项pyc。实际安装console的doctor installation-only成功,但service_runtime_identity没有package_fingerprint,且无release_id;helper期望身份因而仍拒绝合法安装。同一wheel用pip --no-compile安装产生指纹。没有修改RECORD或把mock返回当包归属证明。最小修复是在清单与磁盘两侧对称排除生成字节码,保留源码完整性、版本/import-root/editable/symlink所有拒绝条件;加入真实default pip的回归。
对主干的风险
当前190项focused原生测试、162项架构/语义IO检查、source Chat bundle/frontend tsc构建、LaunchAgent mocked smoke、diff/DCO通过;2项Windows-only在macOS跳过,未冒充跨平台验收。不可变base同集合中的既有非dashboard/native检查134项通过(同2项平台skip)。对照重点是实际默认pip安装与同wheel no-compile;不是用通过的synthetic distribution fixture否定真实失败。初次缺少source bundle导致的4项dashboard准备失败,构建后同42项全部通过,随后完整集合复跑也通过。root npm缺失和错误测试路径的准备失败单独保留,补依赖后同162项均通过。安装身份正例/负例和冻结HTTP测试不代表真实launchctl升级、rollback或常驻服务验收。
没有查询、轮询或等待CI。author描述的历史CI不当作本轮根因、修复或豁免证据。没有PostgreSQL authority refactor或真实用户Goal/lease状态故障注入。当前head必须保持不变;integration/release与merge另由维护者验收。
我的整体评价
REQUEST_CHANGES,精确head 8a4c5e0e7d60a3799c32615d42f4487ad81a7a9e。Apply the same generated-bytecode exclusion to both distribution RECORD entries and the on-disk file set; retain owned import-root, complete-source, version, editable and symlink rejection. Add a real default pip wheel install versus --no-compile regression.
未来重构检查:建议同域窄修生成文件判定的共同owner,避免两侧集合语义继续分叉;其范围可在当前PR局部验证和回滚。正常路径及其它边界的测试已通过,不能抵消上述实际入口反例。全量合同不要求新增发布者认证;摘要与来源证明继续分开。
English verdict: REQUEST_CHANGES - 8a4c5e0. P1: real default pip records1212 generated pyc entries, but the new identity filters only the disk side, so a valid owned wheel still lacks package_fingerprint. The same wheel installed with --no-compile qualifies. Native190, architecture162 and mocked helper pass; preserve ownership/source negatives and add a real compiled-wheel regression.
| files = { | ||
| item.as_posix(): Path(item.locate()) | ||
| for item in installed.files or () | ||
| if item.as_posix().startswith("loopx/") |
There was a problem hiding this comment.
A real default pip install of this exact wheel records 1,212 generated .pyc entries under loopx/. This comprehension includes them, but actual below excludes __pycache__, .pyc and .pyo, so set equality returns None for an otherwise valid owned installation. The actual installed console doctor has neither release_id nor package_fingerprint and the service helper still refuses it; the same wheel with --no-compile gets a fingerprint. Exclude generated bytecode symmetrically in both sets while retaining import-root/version/complete-source/editable/symlink checks, and cover a real default pip installation.
The macOS service helper currently requires a snapshot release manifest, so a valid uv/pipx-owned wheel cannot pass its runtime fence. Reinstall also loses explicit workspace selection and can replace a custom registry with the runtime-root global path. This change makes the existing helper retain those choices and qualify the running artifact without adding a service or execution authority.
release_runtime_identitykeeps snapshot identities intact and adds a package fingerprint for a complete, non-editable, RECORD-owned wheel. The digest reads actual Python/TypeScript/frontend bytes; it is a local reuse fence, not release or source attestation. Both HTTP services freeze identity before startup. Installation-only doctor exposes the canonical identity and selected interpreter; the helper validates before replacing plists or stopping services, retains the registry/Codex home/workspace array, passes selected roots to both services, and bounds readiness HTTP requests.This PR independently targets latest main
99839aeb8fed5fae38a5d319391cd050672a6508. It contains none of #5538 or the private-conversation stack #5540–#5542. This belongs to the roadmap S4/S12 clean-install/upgrade boundary and the existing installation owner; it does not qualify the wider App/provider journey.Validation:
8a4c5e0e7d60a3799c32615d42f4487ad81a7a9ewas built as an isolated wheel and exercised through actual macOS launchctl: startup, restart with preserved context, same-version replacement while the old process retains its startup identity, and refusal of an unowned package file without replacing the live service. The synthetic registry remained empty; both canary services/plists were removed.CI at this exact head is complete: 22 checks passed, 6 skipped and 6 failed (four Python shards, pytest aggregate and merge gate). The failed Python log contains 71 unique test names, the same names observed at #5542; this comparison does not attribute or waive every failure. Related package/service tests above pass locally, but overall CI qualification is still unmet. Maintainer review remains required. Actual login-after-reboot, real provider inbound/mobile, and a normal release upgrade are untested. The existing installed tool was not replaced. No self-merge: this changes runtime/product behavior. Keep future installer changes on the canonical identity and existing helper, without another daemon or private configuration in the repository.