fix: qualify local peer delivery without Git worktree - #5566
Conversation
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent — gpt-6.1-sol (OpenAI); runtime_reported; reasoning_effort=xhigh
Request changes conclusion (author-owned PR; GitHub blocks formal self-review)
结论:REQUEST_CHANGES,审查精确 head e4b1fbdb216bac6f6eaa33418a83272aa5a8b8b8。本地多 Agent 续跑有实测正向价值,但仓库校验遗漏现存旧格式路径,且一项当前必需验证尚未归因。
动机
在非 Git 项目中协作研究、整理材料的 Agent,以及需要回读它们进度的操作者。同一研究任务以前通过准入和独立验收后,仍被 Git worktree 要求卡在回写;本次 File/SQLite 实测能以本地 Goal 工作区结算,并在下一 Turn 继续原任务。合格本地工作可以保持交付身份写回;重放只记账一次,进行中的 Todo 保持 open,未通过独立验证的结果不能完成。本 PR 不完成 App/Bot 终端体验、真实模型效果评估、远端账户授权或正式 Goal 验收。旧 Markdown Todo 的仓库匹配仍遗漏,且当前 hook 测试失败尚未完成归因;这些缺口阻止本 head 获得批准。
真正的长期收益是让已经合法完成的工作进入可续跑、可回读、只扣一次的账本,减少重复恢复和错误重分类。这个收益在隔离的真实 CLI/File/SQLite 路径上成立;不能据此推算模型质量、真实 Bot 或 App 总体效率。
改动思路
复用原有 TypeScript 工作区 owner,把“有多个 Agent”与“必须隔离 Git 写入”分开。Python 只观察项目根、Git origin/worktree 和原 Todo,再把事实送给 typed owner;沿用既有 local/Git receipt、claim/lease、独立验收和同 Turn 结算。正式 Goal result 的准入提前到 validator 之前,让 --result-file 的误用能无副作用纠正为 --evidence。
最强反对理由是错误放宽仓库边界。无条件撤掉 worktree 要求或把研究改成 non-delivery 都不合适;当前结构足够小,也不需要新框架,但输入源必须完整。
具体改动
读完全部 12 文件(+342/-21):6 个运行代码文件,3 个测试文件,2 份协议/额度文档和 1 个生成行号 census。包括 final commit 的释放执行 lease 后续跑用例。
独立依据:docs/reference/protocols/peer-agent-runtime-v1.md,以及 docs/quota-allocation.md 的既有记账合同,均固定在变更前 69ad89c7fe214e3fb67d1fe894b65b17e6040461。逐项核验:Work Ownership 的认领/lease 保留;Completion And Review 的独立验收未变成 profile 授权;Post-turn accounting protocol 的一次记账、原 Turn 和后续续跑通过;Workspace Isolation 的原 task_repository 匹配在 legacy 路径尚未满足。对这些文档的修改是本次行为扩展的披露,不能替代变更前的规范。
关键代码讲解
refresh_state_run(loopx/state_refresh.py:693)组织真实宿主观察和原 Turn 写回。新隔离调用之前,仅从todo_fields找原 Todo;旧 Markdown 的 planning source 此值为 None,这是下面遗漏的输入点。evaluateDeliveryWorkspace(loopx/control_plane/agents/delivery_workspace.ts:249)新增isolation操作,使用既有 local/Git 类型与精确仓库身份;显式 owner 要求或声明的 Git 任务不能以 local receipt 满足。executeCoordinationTodoTerminalLifecycle(loopx/control_plane/coordination/todo_terminal_lifecycle.ts:1023)在无绑定 Goal acceptance 时提前拒绝 completion_result,再沿用原有 validator/事务;本地证据指针与正式验收不同。_build_interaction_cli_channel(loopx/control_plane/work_items/interaction_contract.py:1298)给既有交付包添加本地工作区提示;这是提示,真正拒绝边界仍在 owner 中。
[P1] 把旧格式原 Todo 的仓库身份传给同一个隔离 owner。 loopx/state_refresh.py:1169–1176 在 todo_fields=None 时选择空对象。真实 CLI 对照中,原 Todo 明确指定 git:github.com/example/right;一个 origin 为 example/wrong 的实际 linked worktree,在本 head 的 legacy Markdown 路径得到 appended=true,后续原生 spend 成功,账本扣一次。相同 File 输入在 append 前拒绝。基线两条路径都接受错误 origin,因此这是本次新 gate 未补齐的既有遗漏,不能称作本 PR 新引入的权限绕过。复用完整 planning source;legacy 按现有 parser 的 item_limit=None 解析原绑定 Todo,再交同一 TS owner。新增 legacy/File/SQLite wrong-origin 拒绝、零 receipt/零 debit 和 matching-origin 恢复回归,不要增加第二套 Python 隔离决策。
[P2] 归因当前 terminal hook 验证失败。 test_read_only_settlement_omits_non_causal_delivery_workspace 在此 head 的完整运行和单独运行均失败,终结后的 periodic-report intent_count 期待 1,实际 0;同命令在不可变基线单独运行通过。尚无独立因果证据说明这是 PR 回归或无关历史问题。保留断言,定位差异或建立有效的无关归因;不能用旧 head 上的偶发历史、一次 green 或提高容差冲掉本次风险。
对主干的风险
实测正向链路:File 7 peers、SQLite 15 peers 的合法非 Git 工作,基线卡在 worktree gate,本 head 能 refresh→spend→同 Turn replay;只一次 debit,原 Todo 保持 open,下一 Turn 仍能选它。单 Agent 原合法路径保留。真正错误的 artifact 完成失败且仍 open,修正内容后由原 validator 验收并 done;unsupported result-file 从基线的“先跑 validator 再拒绝”变为“先拒绝且给 evidence 修复途径”。显式 owner 隔离、本地/Git 不匹配和外部根目录拒绝;回到注册根可继续。typed blocked/no-spend、释放执行 lease 的续跑也通过新原生回归。
验证:主要 Python 范围 163 passed / 1 failed,另有 Goal acceptance CLI/runtime 33 passed;TS 工作区/settlement/terminal 127 passed,typecheck 通过;开发期 advisory 未发现支持的新增词汇载体,完整语义/census/hot-path 与 19 项 premerge 检查及直接检查通过。没有查询/等待 CI。失败、基线结果与遗漏没有被这些 green 覆盖。所有探针使用隔离临时项目、真实存储和真实 Git,未改 active Goal、账户或 live Bot;没有真实模型/远端 provider 或 packaged App 端到端证明。
我的整体评价
设计和规模相称:既有 typed owner 承担规则,原 receipt/validator/lease 复用,没有新 schema、配置开关、调度器或必须重复输入的信息。前瞻整理已体现在归属收敛;下一步最有价值的是复用完整 Todo 来源,补齐 legacy 输入,而非扩展抽象。此 PR 的局部效果和操作效率已显示正向,整个现存边界仍需上述两项证据修复,当前不批准、不合并;App/Bot 和长期模型效果保持未测。
English verdict: REQUEST_CHANGES - e4b1fbd. Real File/SQLite non-Git peer continuation and one-debit replay improve, but legacy Markdown drops the bound task repository and accepts/charges a foreign linked checkout. A current terminal-hook check also fails twice while the immutable baseline isolated check passes; attribution is unresolved. 163+33 Python tests, 127 TS tests, typecheck and 19 premerge checks passed alongside the retained failure. Complete the original-source gate and qualify that failure before approval.
…24-5566 Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent — gpt-6.1-sol (OpenAI); runtime_reported; reasoning_effort=xhigh
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
结论:APPROVE,精确 head b43f38e24ce96964358d776ce65c8330eea34f81。没有阻塞发现。此前 REQUEST_CHANGES 的仓库来源遗漏已修复;hook 失败经独立同输入对照证实是既有问题,保留风险而不称作本 PR 已修复。自审不能替代 GitHub 合并资格,仍须另验原生 merge-readiness。
动机
在非 Git 项目中协作研究、整理材料的 Agent,以及需要回读它们进度的操作者。同一研究任务以前通过准入和独立验收后,仍被 Git worktree 要求卡在回写;本次实测能用注册的本地工作区结算,并在下一 Turn 继续原任务。合格本地工作可以保留交付身份写回;重放只记账一次,进行中的 Todo 保持 open,未通过独立验证的结果不能完成。本 PR 不证明真实模型效果、App/Bot 全链路收益,也不授权远端账户或代替正式 Goal 验收。CLI 交付工作区与结算边界已满足本次修复;同秒 hook 身份碰撞仍属既有独立问题,真实 App/Bot 和模型长程效果保持未测。
体验收益有真实边界证据:减少无意义 Git 初始化、重复恢复和误用 result-file 时的 validator 副作用;长期收益是原 Todo、Turn 和验收承诺能延续到可回读且只记账一次的结果。未测的模型质量或总体吞吐不能从这些测试推算。
改动思路
复用既有 TypeScript 工作区 owner,以实际 local/Git 类型、owner 要求和原任务仓库决定隔离;Python 只观察宿主和解析支持的 Todo 来源。既有认领、lease、独立 validator、验收和额度 owner 保留。强反对理由是错误放宽仓库边界,本次对照同时证明合法本地工作不会被误拦、错误 origin 不能逃逸;失败后回到正确 origin 可在原 Turn 前进。
正式 Goal result 没有绑定验收标准时,在 validator 前拒绝,并给 --evidence 修复途径;不把一个独立 validator 当作 Goal 验收授权。
具体改动
完整重审当前 main 30efccd6c7d4e2300c2ac87ddc6ddb1dfb855a40 到 head 的 12 文件(+401/-21):6 个生产文件、3 个测试、2 份文档、1 处生成行号 census。上次审查至当前 head 只增加完整 legacy 来源适配和三 provider 回归(2 文件 +60/-1),并先整合当前 main,未继承旧结论。
独立规范:docs/reference/protocols/peer-agent-runtime-v1.md 固定在变更前 69ad89c7fe214e3fb67d1fe894b65b17e6040461,以及原 quota Post-turn accounting protocol。逐项:Work Ownership 保留原 claim/lease;Workspace Isolation 用完整原 Todo 的 task_repository 核对真实 origin;Completion And Review 保留独立验收而不从 profile 推导授权;Post-turn accounting protocol 保留原 Turn、一次扣额、blocked 零扣额和后续续跑。修改后的文档是默认行为变化的披露,不能代替这些原规范。
关键代码:
refresh_state_run(loopx/state_refresh.py:693,输入适配在 1169)先取得完整 canonical 来源;legacy 使用既有parse_active_state_todos(..., item_limit=None),再按原 todo_id 精确选 task_repository,避免显示 cap 或 None 冒充“没有仓库”。实际规则交给同一个 typed owner。evaluateDeliveryWorkspace(loopx/control_plane/agents/delivery_workspace.ts:249)使用既有 local/Git schema 的 isolation 分支:注册本地根可记录本地交付,显式 owner 隔离或原 Git 任务仍需匹配 Git worktree;未验证根或 origin 不产 receipt。executeCoordinationTodoTerminalLifecycle(loopx/control_plane/coordination/todo_terminal_lifecycle.ts:1023)在不具备 Goal acceptance 绑定时提前拒绝 result,再沿用原 validator/终结事务。实际 CLI 中 unbound result 不产生 validator 标记,错误 artifact 留 open,修正后独立验证完成。_build_interaction_cli_channel(loopx/control_plane/work_items/interaction_contract.py:1298)提供本地工作区提示;提示是 advisory,真正拒绝在 owner 中执行。
P1 闭环:原 regression 在生产修复前运行,legacy 失败、File/SQLite 通过;修复后3种来源错误真实 linked origin 均在 append 前拒绝且零 debit,matching origin 在同原 Turn 写回、spend、replay 后仅扣1次。原任务放在35条无关任务之后,确实核验完整来源。
对主干的风险
File 7 peers、SQLite 15 peers 和单 Agent 实际 CLI 对照:多 peer local 基线拒绝,当前 head 完成 refresh→spend→replay,仅1次 debit,同 Turn skip,下一 Turn仍选 open 原 Todo。File/SQLite 在旧任务已准入之后新增任务、登记第二 peer,再为新任务建立自己的 Turn/claim/lease;当前 head 可结算且新 Todo open,基线仍卡 local worktree。其他 owner/exclusion/capability 拒绝保留,外部根拒绝后注册根恢复,显式 Git task 不被 local receipt 满足。typed blocked 零扣額和释放执行 lease 后的合法延续通过。
当前生产源码验证:200 Python passed、127 TS passed、typecheck passed、19 项原生 premerge 与直接检查 passed,advisory 在全树语义检查前运行。没有查询、轮询或等待 CI;没有削弱断言或增加等待来获得 green。真实隔离 File/SQLite/legacy、Git和validator验证不修改活动 Goal,不证明真实 Bot、账户、模型或 packaged App端到端收益。没有 PostgreSQL 存储重构或 provider promotion。
P2 归因闭环,仍有未修风险:原 head 全套 163 passed/1 failed 和单项失败、旧基线单项通过均保留。自然当前全套200通过不能消除间歇性。冻结仅旧 Todo commit timestamp为同一秒,实际 CLI 的其他 owner 不改:当前不可变 main 30efccd6c7d4e2300c2ac87ddc6ddb1dfb855a40 与精确 head 都得到相同 AssertionError,终结 hook 将普通零-intent receipt 当作 replay,intent_count=0;旧69ad也同样失败。Todo CLI、post-writeback CLI、hook Python/TS owner和原断言文件在当前base/head字节相同。故这是 pre_existing_unrelated 的同秒身份碰撞,尚未修复,归现有 hook owner;本 PR 不引入或改变该身份规则。合并资格与该风险明确分开记录,不将一次 green、相等数量或旧评论作为归因证据。
我的整体评价
此有界 CLI 修复对长程延续和操作效率为正向:让合法产物进入一次记账和后续执行,减少重复恢复且保留必要授权。没有新增 schema、capability、配置开关、调度器或必须重复提供的参数。前瞻整理已应用为“复用同 typed owner、补齐同来源适配”,现有 parser/receipt 足够,无需新框架。没有阻塞发现;最强缺失验证仍是真实 App/Bot/model 长程结果,当前不声称这些已经完成。既有同秒 hook 风险如上保留。
English verdict: APPROVE - b43f38e. No blocking findings. The legacy task-repository omission is fixed through the existing complete parser and same typed workspace owner; three real-provider wrong-origin/recovery regressions now pass. Actual CLI local peers, fresh task after admission, one-debit replay and later continuation improve without new required inputs or authority. 200 Python tests, 127 TS tests, typecheck and 19 native premerge checks pass. The deterministic same-second terminal-hook diagnostic still fails identically on immutable current main and this head; byte-identical causal files establish a pre-existing unrelated identity collision, not a repaired failure. Live App/Bot/model outcomes remain unmeasured; merge readiness is a separate native gate.
Qualified non-Git peer work could pass admission and independent validation, then fail progress writeback because peer count alone demanded a Git worktree. This change lets the existing typed workspace owner qualify a registered local Goal workspace while preserving explicit owner isolation, the original task repository, claim/lease ownership and once-only settlement.
The original Todo is selected from the complete canonical or supported legacy source before workspace qualification. Foreign linked Git origins refuse before append/spend, and matching-origin recovery preserves the original Turn. Unbound
--result-filealso fails before running a validator, with actionable--evidenceguidance; a standalone validator does not authorize Goal acceptance. No new schema, capability, setting or required CLI argument is introduced.Validation at
b43f38e24ce96964358d776ce65c8330eea34f81against current main30efccd6c7d4e2300c2ac87ddc6ddb1dfb855a40:Retained unrelated failure: the original terminal periodic-report test failed at the old head, while an isolated baseline run passed. A deterministic same-second probe now fixes only the legacy Todo commit timestamp and runs the actual CLI: immutable current main and final head fail with identical hook replay/zero-intent detail. The hook/CLI causal files and original assertion are byte-identical. The final natural full suite passes, but that does not repair the existing hook identity collision; it remains with the existing post-writeback owner. No assertion or hard limit was weakened, and this PR does not alter hook identity.
The future-facing pass reuses the existing TypeScript isolation owner, receipt formats and complete Todo parser. It adds the bounded source adapter rather than another authority or speculative framework. Full exact-head public self-review and native merge readiness are required before the explicitly authorized merge.