Skip to content

fix(service): qualify owned wheels and retain macOS workspace selection - #5543

Open
huangruiteng wants to merge 2 commits into
mainfrom
codex/native-workspace-service-20261004
Open

huangruiteng wants to merge 2 commits into
mainfrom
codex/native-workspace-service-20261004

Conversation

@huangruiteng

@huangruiteng huangruiteng commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

The macOS service helper currently requires a snapshot release manifest, so a valid uv/pipx-owned wheel cannot pass its runtime fence. Reinstall also loses explicit workspace selection and can replace a custom registry with the runtime-root global path. This change makes the existing helper retain those choices and qualify the running artifact without adding a service or execution authority.

release_runtime_identity keeps snapshot identities intact and adds a package fingerprint for a complete, non-editable, RECORD-owned wheel. The digest reads actual Python/TypeScript/frontend bytes; it is a local reuse fence, not release or source attestation. Both HTTP services freeze identity before startup. Installation-only doctor exposes the canonical identity and selected interpreter; the helper validates before replacing plists or stopping services, retains the registry/Codex home/workspace array, passes selected roots to both services, and bounds readiness HTTP requests.

This PR independently targets latest main 99839aeb8fed5fae38a5d319391cd050672a6508. It contains none of #5538 or the private-conversation stack #5540–#5542. This belongs to the roadmap S4/S12 clean-install/upgrade boundary and the existing installation owner; it does not qualify the wider App/provider journey.

Validation:

  • Final exact-head package/service/doctor regressions: 148 passed (94.86s), including same-version byte replacement, editable/foreign/incomplete/broken-symlink refusal, frozen HTTP identity and stale-service rejection. Fingerprint cases: 12 passed; census/maintainability companion: 22 passed.
  • LaunchAgent smoke passed: explicit paths with shell metacharacters, reinstall/restart preservation, custom registry, malformed selection and unqualified package refusal. Ruff, configured Mypy and semantic drift passed; registry I/O manifest changes only refresh ten line anchors, with no new sites or classifications.
  • Risk-selected premerge passed five direct and nineteen selected checks. The tested index tree equals the two DCO commits’ final tree; no architecture budgets were raised.
  • Exact head 8a4c5e0e7d60a3799c32615d42f4487ad81a7a9e was built as an isolated wheel and exercised through actual macOS launchctl: startup, restart with preserved context, same-version replacement while the old process retains its startup identity, and refusal of an unowned package file without replacing the live service. The synthetic registry remained empty; both canary services/plists were removed.

CI at this exact head is complete: 22 checks passed, 6 skipped and 6 failed (four Python shards, pytest aggregate and merge gate). The failed Python log contains 71 unique test names, the same names observed at #5542; this comparison does not attribute or waive every failure. Related package/service tests above pass locally, but overall CI qualification is still unmet. Maintainer review remains required. Actual login-after-reboot, real provider inbound/mobile, and a normal release upgrade are untested. The existing installed tool was not replaced. No self-merge: this changes runtime/product behavior. Keep future installer changes on the canonical identity and existing helper, without another daemon or private configuration in the repository.

…tion

Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
@mergify

mergify Bot commented Oct 4, 2026

Copy link
Copy Markdown

This pull request has merge conflicts with main and cannot be merged
until they are resolved. Please rebase or merge the base branch, @huangruiteng.

Choose the remote for the base repository, not an out-of-date fork.
For a fork clone, first inspect git remote -v; upstream must point
to https://github.com/loopx-project/loopx.git. If it is absent, add it
with git remote add upstream https://github.com/loopx-project/loopx.git.
Then run:

git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEAD

For a same-repository clone whose origin points to
https://github.com/loopx-project/loopx.git, use origin instead of
upstream for fetch/rebase. If you prefer merging the base, use
git merge <base-remote>/main and push normally.

Keep the DCO Signed-off-by trailer on every commit when you rebase.
https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/syncing-a-fork

@mergify mergify Bot added the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 4, 2026

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent · gpt-6.1-sol · OpenAI · runtime_reported · xhigh

[P1] 普通 pip 安装仍被新运行时指纹校验拒绝。

动机

用普通 pip 安装后管理本机后台服务的用户,需要确认服务运行的是当前安装包,并保留已选工作区。

以前后台服务校验只接受带发布清单的快照,普通包管理器安装会被拒绝;本改动拟接受属于当前安装的实际包文件,并保留已有工作区选择。

已验证禁用字节码编译的同一 wheel 能获得指纹;但普通 pip 安装仍没有指纹,后台服务的合法安装入口尚未修好。

本轮不验收真实 launchctl 常驻升级、用户已有服务迁移、跨主机或发布,也不把包指纹当发布者认证。

改动思路

复用 release_runtime_identity 为无发布清单的包管理器安装添加实际字节摘要;不能仅凭版本相同认定服务是当前安装。ChatHTTPServer 与 StatusHTTPServer 构造时保存启动身份,之后 HTTP 不随磁盘升级改写旧进程。doctor 提供实际 Python 解释器,macOS helper 使用所选 console 的解释器解析并保存既有 registry、Codex home、工作区列表。既有 snapshot 和 package manager 各自保留原 ownership。

规范依据:docs/guides/installing-loopx.md,不可变版本 99839aeb8fed5fae38a5d319391cd050672a6508。逐项判断:

  • Installation owner and package: not_met — Real default pip wheel install records1212 pyc and returns no fingerprint; no-compile same wheel returns a digest..

  • Managed Effect runtime: implemented — pr5543-144225 native and owner counterexample/control evidence.

  • Rollback: deferred — Mocked helper reinstall/restart/context retention verified; no actual user launchctl rollback performed..

具体改动

全量13文件396+/34-。release_manifest.py:348 的 _distribution_runtime_fingerprint 核验非editable、精确版本、真正导入模块、完整文件集合和symlink,哈希真实字节;doctor/installation-only doctor 读同一身份和解释器。两个HTTP server冻结构造身份;现有dashboard readiness复用该身份。

macOS helper 优先询问选定console的解释器,解析已有plist环境与旧shlex参数;registry必须绝对路径,roots是最多32项的现存绝对目录JSON,去重并逐项quote。显式registry同时传给Chat/status,移除会覆盖自定义registry的global选项;先验证身份/参数再bootstrap。IO manifest只是行号变化。focused distribution/server/dashboard/doctor测试、mocked helper smoke及双语安装说明覆盖同一改动。

缺陷在 release_manifest.py:360–377:安装清单集合保留所有loopx/条目,磁盘集合却排除__pycache__/pyc/pyo;真实pip默认安装会在RECORD记录生成的pyc。独立构建当前head的完整wheel,在隔离Python3.12环境用真实pip正常安装,读到2800项loopx文件,其中1212项pyc。实际安装console的doctor installation-only成功,但service_runtime_identity没有package_fingerprint,且无release_id;helper期望身份因而仍拒绝合法安装。同一wheel用pip --no-compile安装产生指纹。没有修改RECORD或把mock返回当包归属证明。最小修复是在清单与磁盘两侧对称排除生成字节码,保留源码完整性、版本/import-root/editable/symlink所有拒绝条件;加入真实default pip的回归。

对主干的风险

当前190项focused原生测试、162项架构/语义IO检查、source Chat bundle/frontend tsc构建、LaunchAgent mocked smoke、diff/DCO通过;2项Windows-only在macOS跳过,未冒充跨平台验收。不可变base同集合中的既有非dashboard/native检查134项通过(同2项平台skip)。对照重点是实际默认pip安装与同wheel no-compile;不是用通过的synthetic distribution fixture否定真实失败。初次缺少source bundle导致的4项dashboard准备失败,构建后同42项全部通过,随后完整集合复跑也通过。root npm缺失和错误测试路径的准备失败单独保留,补依赖后同162项均通过。安装身份正例/负例和冻结HTTP测试不代表真实launchctl升级、rollback或常驻服务验收。

没有查询、轮询或等待CI。author描述的历史CI不当作本轮根因、修复或豁免证据。没有PostgreSQL authority refactor或真实用户Goal/lease状态故障注入。当前head必须保持不变;integration/release与merge另由维护者验收。

我的整体评价

REQUEST_CHANGES,精确head 8a4c5e0e7d60a3799c32615d42f4487ad81a7a9e。Apply the same generated-bytecode exclusion to both distribution RECORD entries and the on-disk file set; retain owned import-root, complete-source, version, editable and symlink rejection. Add a real default pip wheel install versus --no-compile regression.

未来重构检查:建议同域窄修生成文件判定的共同owner,避免两侧集合语义继续分叉;其范围可在当前PR局部验证和回滚。正常路径及其它边界的测试已通过,不能抵消上述实际入口反例。全量合同不要求新增发布者认证;摘要与来源证明继续分开。

English verdict: REQUEST_CHANGES - 8a4c5e0. P1: real default pip records1212 generated pyc entries, but the new identity filters only the disk side, so a valid owned wheel still lacks package_fingerprint. The same wheel installed with --no-compile qualifies. Native190, architecture162 and mocked helper pass; preserve ownership/source negatives and add a real compiled-wheel regression.

Comment thread loopx/release_manifest.py
files = {
item.as_posix(): Path(item.locate())
for item in installed.files or ()
if item.as_posix().startswith("loopx/")

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A real default pip install of this exact wheel records 1,212 generated .pyc entries under loopx/. This comprehension includes them, but actual below excludes __pycache__, .pyc and .pyo, so set equality returns None for an otherwise valid owned installation. The actual installed console doctor has neither release_id nor package_fingerprint and the service helper still refuses it; the same wheel with --no-compile gets a fingerprint. Exclude generated bytecode symmetrically in both sets while retaining import-root/version/complete-source/editable/symlink checks, and cover a real default pip installation.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-rebase Mergify: the pull request has merge conflicts with its base branch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants