Skip to content

fix(packaging): ship project-scoped skill sources in wheels - #5560

Open
huangruiteng wants to merge 3 commits into
mainfrom
codex/packaged-project-skills-20261004
Open

huangruiteng wants to merge 3 commits into
mainfrom
codex/packaged-project-skills-20261004

Conversation

@huangruiteng

Copy link
Copy Markdown
Collaborator

Wheel-installed LoopX could not install loopx-material or loopx-change-quality into a connected project: both canonical source trees were omitted from the distribution. Bundle their skill text, project scope markers and host display metadata so preview, install, readback and uninstall work through the existing release-owned project skill delivery path.

The packaging regression tests now use the existing scope classifier to cover both declared release scopes. Default global discovery, capability activation and domain authority retain their existing contracts. No runtime owner or material store is introduced.

Validation on head 5d5c60693aefd830167397618bd1e6ddbc3b9f96 against main 6a172f699653a11c5a4dad578e244fe535013c4c:

  • The new checks reproduced four missing-source/metadata failures before the packaging fix. The fixed focused set passed 93 tests; Ruff and diff checks passed.
  • Built the Chat assets and actual wheel, then installed the wheel into an isolated Python environment outside the checkout. Both project source trees matched the checkout bytes. Seventeen actual CLI operations passed: three host surfaces, preview/install/readback/uninstall, missing-connection and unmanaged/modified/symlink protection, and global install/readback/uninstall with the global catalog unchanged. Synthetic project registries stayed unchanged.
  • Exact three-path canary premerge passed four direct checks and fifteen selected checks. An earlier clean-scope attempt lacked the TypeScript dependency after temporary build links were removed; installing repository dev dependencies resolved that environment failure. Change-quality policy was disabled; no qualification receipt is claimed.

Full repository tests and live material intake/ranking were not run for this packaging slice. The isolated wheel retains distribution version 1.2.4; it is a source candidate, not a published release or an in-place upgrade. Maintainer review/merge remains required for this installation behavior change.

Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh

Exact head: 5560@5d5c60693aefd830167397618bd1e6ddbc3b9f96. Base: 6a172f699653a11c5a4dad578e244fe535013c4c.

动机

通过 Python wheel 安装 LoopX、需要项目级材料或变更质量技能的用户。 旧 wheel 没有这两个技能的 canonical source,项目安装预览报缺少 scope marker;新 wheel 包含完整的技能文本、范围标记和 host 元数据,可以执行已有项目安装流程。 隔离 wheel 的真实 CLI 已在四种 host 目录安装、逐字节回读、重复执行并卸载两个技能;全局安装继续排除它们,临时项目的 registry 未变化。 本次修复发行包内容,不启用材料或质量能力、不注册 Goal、不增加权限,不声明公开发布、现有机器升级或新的前端配置旅程完成。

改动思路

沿既有源、安装和原生权限 owner 完成这一有界修复。数据文件补入原 manifest,通过同一个 resolver 和 copy/digest guard 使用,不创建新的全局发现或配置源。 不以作者测试数或元数据代替真实入口证据。规范依据为 loopx/capabilities/project_skill_delivery/README.md @ 6a172f699653a11c5a4dad578e244fe535013c4c。

具体改动

关键代码讲解

完整三文件 +38/-11。pyproject.toml:79 的 data-files 增加两个项目级技能的三类文件(文本、project scope marker、agents 元数据),没有修改全局允许集合。RELEASE_SKILL_IDS:10 复用原 classifier,把 global 与 project 两类 release 源一起纳入测试;test_release_scoped_skills_ship_source_and_scope_markers:33 与 metadata 测试逐项检查声明。README 增加 wheel/source 同一 canonical source、可发现性不等于 activation 的说明。原验收 release source retention、managed lifecycle、fail-closed and authority 三项均实现。

源码的67项 packaging/workflow/project/material delivery 与23项 material/default-off 契约检查通过。重新构建相同版本的基线/精确 head wheel,分别安装到隔离 Python 环境,从 checkout 外执行真实 CLI,并确认 provenance 为 python_distribution。基线两个 preview 都 rc2、缺 scope marker;head 在 codex、claude-code、opencode、pi 上预览不写文件、执行后 current/managed、24个文件逐字节相同、重复 changed=false、预览卸载不删文件、执行卸载后 missing。已有最短合法流程 preview→execute→status 没有新增确认或输入;显式 execute 供应写文件的授权。

负例也执行实际 wheel 入口:拒绝 unmanaged、locally_modified、unconnected、symlink escape 与无标记 merge skill;保留原文件和外部目录,恢复 locally_modified 文件后卸载成功。全局 install/status/repeat/uninstall 在两版都排除项目技能及 repo-only merge skill。全局安装之后新建项目,仍需独立显式项目安装,registry保持原字节。缺源码曾遮蔽基线后续目标检查,所以记录的错误优先级变化是恢复源码后的有意行为,未把基线 missing-source 当作目标保护通过。

对主干的风险

完整影响范围是发行源可用性及原安装路径。已审查源解析、scope marker、全局/项目分离、digest 回读、显式请求和 native admission 边界。安装/可发现性没有赋予 Goal、claim/lease、runner、private-store 或外部权限。临时文件系统和合成 registry 验证了实际安装 owner,未使用 mock 提供被测结果。

初次 wheel 构建在基线/head 都因复用的旧前端 assets 不新鲜被拒绝;分别 npm run build:chat 后再构建、安装和验证通过,保留初次失败归因。 私有验证脚本最初使用不支持的模块入口和错误的 inspect 字段,修正为真实 entrypoint/before 读回后两版重跑通过;这些脚本错误不归给 PR。Ruff、diff/public boundary scan、advisory→全树 semantic smoke 均通过。advisory未检测到支持语法的新 vocabulary不等于完整语义证明;全树检查保留原动态和未验证范围。未查询、轮询或等待 CI。

语义与 CI 对齐

复用既有 source scope、managed digest 与 native authority 契约,不新增共享 vocab、权限或并行决定源;以上三个规范条目均 implemented。Distribution availability changes intentionally;global discovery and capability defaults do not. README and renamed parameterized source/metadata tests disclose it. 测试验证说明/发行源与真实安装相符,未把 guidance 当作 machine enforcement 或全局安装当 capability activation。

No live material store, ranking/intake operation, capability activation, full repository suite, independent Windows/Linux, public release or in-place upgrade was exercised. Rebuilt frontend assets were a wheel prerequisite;no changed UI journey is claimed. Base refusal precedence changes intentionally from missing-source to the existing target/connection checks once sources exist.

我的整体评价

APPROVE,已独立证明所需发行源与现有项目安装旅程;user_experience 在 wheel 路径改善,long_horizon 的原事务与继续执行契约保持。无新增状态机或 domain activation,使用原 scope vocabulary。未来重构 pass 认为复用 classifier 并扩大原测试覆盖已足够,无须另建 resolver。 无当前阻塞 finding,结论只适用于完整精确 head。这是不同作者 PR,可发布 GitHub 正式 APPROVED;合并与发布仍需独立授权和仓库门槛。 源码或说明回退无需状态迁移,维护者合并和活跃 host 采用保持独立。

English verdict: APPROVE - 5560@5d5c60693aefd830167397618bd1e6ddbc3b9f96;Project-scoped sources now ship in the actual wheel;four-host managed lifecycle,source bytes,global exclusion and protection/recovery verified. 90 focused tests pass. No CI consulted;merge/adoption remain separate.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants