Skip to content

feat(lark): accept private images through native conversation turns - #5581

Merged
loopx-agent merged 5 commits into
mainfrom
codex/native-private-images-20261004
Oct 5, 2026
Merged

loopx-agent merged 5 commits into
mainfrom
codex/native-private-images-20261004

Conversation

@loopx-agent

@loopx-agent loopx-agent commented Oct 4, 2026 •

Copy link
Copy Markdown
Collaborator

Private image and image/text posts now reach the existing native Session/Turn and Codex image input by default, under the independently verified receiving App. Captions, stable source/request identity and bounded queue input survive duplicate delivery and restart. Failed downloads, unsupported mixed media, control-command images and attached-host images receive an explicit non-execution notice. Existing four-image/5MiB-each/12MiB-total limits remain.

This head incorporates latest main through a normal merge, preserving shared reactions/Markdown, compact status, all-registered steward scope, canonical coordination and original result-return/timeout behavior. It removes the old runtime budget edit and duplicated workspace documentation. The provider remains a bounded Lark IO leaf; Core retains input, routing, Session and recovery ownership. No media runner, new queue, permission uplift or extra model thread.

A real provider-entry regression found that image placeholders hid exact control captions such as /stop and /new. Five counterexamples failed before the repair; caption-only control parsing now reuses the same canonical resource matcher and refuses the whole message without native work.

Validation at bc1829a3bff86a046ec7c165f5173f8078ef6915:

  • 110 related File/Core/synthetic-host tests pass; after help-only copy,27 image/status cases and14 typed binding cases pass.
  • Identical immutable main/head public-entry harnesses preserve full ordinary text observations; supported images change from refused to actual native image wire, while image-controls and files start no Session. Duplicate/restart/download-time revocation cases pass.
  • Ruff/diff/public boundary and DCO checks pass; new image leaf focused types pass. Two pre-existing opaque-import no-any-return diagnostics in the external conversation module reproduce at the same expressions on immutable main; full types are not claimed green.
  • Final native premerge:5 direct+13 selected all pass,0 failures/advisories; change-quality is disabled for the managed Goal. Chat build and44 packaged disposable workspace browser scenarios pass; the existing steward journey's4 gaps remain explicit. CI was not queried, polled or waited for.

External Lark download/model vision, final installed two-App qualification, other media, sustained latency and login recovery remain separate acceptance. Local fixtures are not a claim that the running service has upgraded.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
…rkspace UI

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
@loopx-agent
loopx-agent requested a review from maxliux5 as a code owner October 4, 2026 16:00
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Base automatically changed from codex/native-private-reaction-feedback-20261004 to main October 5, 2026 17:31
…closeout-20261006

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

# Conflicts:
#	docs/architecture/rfcs/app-conversation-and-async-inbox-v0.zh-CN.md
#	loopx/canary/module_metric_baseline.json
#	loopx/extensions/lark/private_conversations.py
#	tests/control_plane_ts/conversation_binding.test.ts

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; GPT-6; OpenAI; self_reported

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Exact head: 5581@bc1829a3bff86a046ec7c165f5173f8078ef6915; baseline: 6e2c1c03b0dd9e042ee6300689f02d8ad17eb18e.

动机

用户在已授权的项目或管家私聊中发送图片,希望助手理解图像并保留对话上下文。 以前发送截图会被拒绝或不能进入模型;现在普通图片和配文进入原会话,携图控制命令明确拒绝,下载失败不会只执行文字部分。 生产文件存储与合成 Codex 协议进程验证图片像素输入、同一会话、重复事件一次执行和持久重启恢复。 本 PR 不新增模型 runner、素材流程或授权目录,也不宣称支持文件、音视频或原宿主 Agent 的图片。 已安装服务的最终两 App 图片旅程与真实模型理解须在候选升级后另行验收。

改动思路

复用既有原生图片输入、Session(会话)和持久 Turn(一次执行)队列;稳定 Lark provider 只核验、下载该 App 的原消息资源。类型化 Core 仍决定路由,既有 native store/host 决定准入和恢复,原 provider journal 决定回复读回。没有第二个图片队列、素材 runner、额外模型线程或默认关闭开关。

重审整个主干到本 head 的12路径,而非继承旧审核。本次普通 merge 保留 main 的 Markdown/reaction 反馈、简明状态、all_registered 管家范围、canonical 交办/回传与 timeout;删除旧预算调整和重复工作区说明。未来重构检查采用最邻近的资源 matcher 解析控制配文,不加通用命令框架。

依据基线 App conversation contract:native-images 对应复用原生附件/会话;current-app-authority 对应 exact receiving App/source 与撤权;truthful-user-entry 对应既有设置/help的实际支持范围。本次只落实此有界图片入口,未关闭完整素材或长期委托验收。

具体改动

  • private_images.py 的87行 IO leaf:只从 canonical message 取资源,在接收 App 身份下下载;临时目录、真实格式与共享4张/5MiB/12MiB上限验证,全部成功才交执行。共享 caption helper 保留模型图片占位符、识别不含资源的控制配文。
  • private_conversations.admit:下载后的 current binding/source 重新核验;稳定 message/source 捕获与重复事件复用原图片。携图控制命令和附在原宿主 Agent 的图片明确拒绝;不执行混合消息的文字部分。help/Settings 如实显示支持范围。
  • external_conversations.admit/_route:规范化 input 进入既有 source fence/请求和原 Turn;给类型化路由的只有 attachment count,图片字节不进入该观测。
  • ChatSessionStore.create_queued_turn 与 ChatRuntimeController.enqueue_turn/resume_session_queue:保存/replay 校验并原线程恢复图片,旧无附件 text request 不增加必需字段。planBoundConversationRequest 在既有 owner 拒绝控制/attached-host 图片。
  • 聚焦回归覆盖 native pixel wire、配文、原 Session、download一次、changed replay 拒绝、持久 store/host 重启、下载中撤权、尺寸/格式/混合媒体及真实控制-caption。双语 RFC 和唯一设置说明不承诺文件/音视频或原宿主支持。

关键符号

  • loopx/extensions/lark/private_images.py:29 — private_message_images:Download exact own-App message resources within current limits; resource matcher also supplies control caption.
  • loopx/extensions/lark/private_conversations.py:134 — admit:Current source and App verification, capture image input once, classify caption controls before native route.
  • loopx/capabilities/native_chat/external_conversations.py:27 — admit:Persist normalized image input under stable source/request fence; routing sees count only.
  • loopx/chat_store.py:1050 — create_queued_turn:Native queued input/replay includes attachments; worker drains original Session/thread.

对主干的风险

实际 File/Core/TS bridge 与合成 Codex 协议子进程的110项组合通过,final help-only修正后27项 image/status通过;14项 TS binding通过。复跑相同独立 public-entry harness:immutable main 与当前 source 普通文字的完整语义观测相等;图片从明确拒绝变为原会话实际 image wire,携图控制/文件两侧均不建 Session。生产 Lark 下载与真实模型理解使用合成边界,不能将这些测试说成安装/live验收。

原图片 head 的单测只向 typed planner 人工提供 command,实际配文图片占位符遮蔽 /stop、/new 等控制。真实 provider 入口5条反例全部失败,本 head修复并保持图文配文。保留初始 wrong test filename 与 harness按目录末项等待旧 Turn 的失败;修正到确切输入后才做最终 base/head比较,没有通过放宽断言隐藏产品问题。

Ruff/diff/public边界及 DCO检查通过。新图片 leaf focused Mypy通过;external module两项 no-any-return在同一 immutable main相同表达式独立复现,未宣称全树类型绿色。最终 bc1829a native 风险门5 direct+13 selected全部通过,0 failures/advisories;Goal change-quality关闭,不虚构资格回执。Chat包构建及44个隔离的 packaged workspace浏览器场景通过,保留既有 steward-journey 的4个未闭环 gap。浏览器以合成状态/API/宿主为边界,不是已安装真实Bot验收。原 uv.lock只作本地检查,不进入12路径公开 diff。没有查询、轮询或等待 CI。

我的整体评价

APPROVE;没有剩余阻塞 finding。默认图片有实际价值,修复复用现有 Core输入与恢复 owner,范围符合用户发送图片并持续对话的需求。尚未证明已安装 final两App、真实模型视觉质量、其它媒体、登录恢复或持续时延,仍由候选 promotion/原消息验收接续。不会将模型或素材 authority扩大到 provider。

English verdict: APPROVE - 5581@bc1829a3bff86a046ec7c165f5173f8078ef6915; verified private images/captions enter the existing durable native Session/Turn and original Codex image input. Real provider-path control-caption counterexamples are fixed; duplicate/restart and revocation preserve existing authority. 110 composition,27 image/status and14 typed cases pass; full text base/head observations match. Actual external provider/model and installed two-App promotion remain separate, no CI queried.

@loopx-agent
loopx-agent merged commit 60e94dd into main Oct 5, 2026
14 of 15 checks passed
@loopx-agent
loopx-agent deleted the codex/native-private-images-20261004 branch October 5, 2026 18:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant