Skip to content

fix: qualify local peer delivery without Git worktree - #5566

Merged
loopx-agent merged 4 commits into
mainfrom
codex/local-delivery-contract-20261004
Oct 4, 2026
Merged

loopx-agent merged 4 commits into
mainfrom
codex/local-delivery-contract-20261004

Conversation

@loopx-agent

@loopx-agent loopx-agent commented Oct 4, 2026 •

Copy link
Copy Markdown
Collaborator

Qualified non-Git peer work could pass admission and independent validation, then fail progress writeback because peer count alone demanded a Git worktree. This change lets the existing typed workspace owner qualify a registered local Goal workspace while preserving explicit owner isolation, the original task repository, claim/lease ownership and once-only settlement.

The original Todo is selected from the complete canonical or supported legacy source before workspace qualification. Foreign linked Git origins refuse before append/spend, and matching-origin recovery preserves the original Turn. Unbound --result-file also fails before running a validator, with actionable --evidence guidance; a standalone validator does not authorize Goal acceptance. No new schema, capability, setting or required CLI argument is introduced.

Validation at b43f38e24ce96964358d776ce65c8330eea34f81 against current main 30efccd6c7d4e2300c2ac87ddc6ddb1dfb855a40:

  • 200 affected Python tests and 127 workspace/settlement/terminal TypeScript tests pass; typecheck and 19 native premerge checks plus direct checks pass.
  • Actual isolated CLI/File/SQLite/legacy journeys cover local peers, completion validation, partial progress, released execution lease, typed blocked zero-spend, wrong/matching Git origin, replay and later continuation. The three-provider repository regression was added before the complete-source repair and first failed the legacy path.
  • Same independent fixtures compare baseline/head with 1/7/15 registered agents; local progress no longer requires fabricated Git setup. Real fresh Todo creation after prior admission is also checked with its own binding/claim/lease.
  • No CI fetch/wait, live Bot/provider/model claim or active Goal mutation in validation. The changed surface is the existing CLI settlement journey; packaged App/Bot and long-running model outcomes remain unmeasured.

Retained unrelated failure: the original terminal periodic-report test failed at the old head, while an isolated baseline run passed. A deterministic same-second probe now fixes only the legacy Todo commit timestamp and runs the actual CLI: immutable current main and final head fail with identical hook replay/zero-intent detail. The hook/CLI causal files and original assertion are byte-identical. The final natural full suite passes, but that does not repair the existing hook identity collision; it remains with the existing post-writeback owner. No assertion or hard limit was weakened, and this PR does not alter hook identity.

The future-facing pass reuses the existing TypeScript isolation owner, receipt formats and complete Todo parser. It adds the bounded source adapter rather than another authority or speculative framework. Full exact-head public self-review and native merge readiness are required before the explicitly authorized merge.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent — gpt-6.1-sol (OpenAI); runtime_reported; reasoning_effort=xhigh

Request changes conclusion (author-owned PR; GitHub blocks formal self-review)

结论:REQUEST_CHANGES,审查精确 head e4b1fbdb216bac6f6eaa33418a83272aa5a8b8b8。本地多 Agent 续跑有实测正向价值,但仓库校验遗漏现存旧格式路径,且一项当前必需验证尚未归因。

动机

在非 Git 项目中协作研究、整理材料的 Agent,以及需要回读它们进度的操作者。同一研究任务以前通过准入和独立验收后,仍被 Git worktree 要求卡在回写;本次 File/SQLite 实测能以本地 Goal 工作区结算,并在下一 Turn 继续原任务。合格本地工作可以保持交付身份写回;重放只记账一次,进行中的 Todo 保持 open,未通过独立验证的结果不能完成。本 PR 不完成 App/Bot 终端体验、真实模型效果评估、远端账户授权或正式 Goal 验收。旧 Markdown Todo 的仓库匹配仍遗漏,且当前 hook 测试失败尚未完成归因;这些缺口阻止本 head 获得批准。

真正的长期收益是让已经合法完成的工作进入可续跑、可回读、只扣一次的账本,减少重复恢复和错误重分类。这个收益在隔离的真实 CLI/File/SQLite 路径上成立;不能据此推算模型质量、真实 Bot 或 App 总体效率。

改动思路

复用原有 TypeScript 工作区 owner,把“有多个 Agent”与“必须隔离 Git 写入”分开。Python 只观察项目根、Git origin/worktree 和原 Todo,再把事实送给 typed owner;沿用既有 local/Git receipt、claim/lease、独立验收和同 Turn 结算。正式 Goal result 的准入提前到 validator 之前,让 --result-file 的误用能无副作用纠正为 --evidence。

最强反对理由是错误放宽仓库边界。无条件撤掉 worktree 要求或把研究改成 non-delivery 都不合适;当前结构足够小,也不需要新框架,但输入源必须完整。

具体改动

读完全部 12 文件(+342/-21):6 个运行代码文件,3 个测试文件,2 份协议/额度文档和 1 个生成行号 census。包括 final commit 的释放执行 lease 后续跑用例。

独立依据:docs/reference/protocols/peer-agent-runtime-v1.md,以及 docs/quota-allocation.md 的既有记账合同,均固定在变更前 69ad89c7fe214e3fb67d1fe894b65b17e6040461。逐项核验:Work Ownership 的认领/lease 保留;Completion And Review 的独立验收未变成 profile 授权;Post-turn accounting protocol 的一次记账、原 Turn 和后续续跑通过;Workspace Isolation 的原 task_repository 匹配在 legacy 路径尚未满足。对这些文档的修改是本次行为扩展的披露,不能替代变更前的规范。

关键代码讲解

  • refresh_state_run(loopx/state_refresh.py:693)组织真实宿主观察和原 Turn 写回。新隔离调用之前,仅从 todo_fields 找原 Todo;旧 Markdown 的 planning source 此值为 None,这是下面遗漏的输入点。
  • evaluateDeliveryWorkspace(loopx/control_plane/agents/delivery_workspace.ts:249)新增 isolation 操作,使用既有 local/Git 类型与精确仓库身份;显式 owner 要求或声明的 Git 任务不能以 local receipt 满足。
  • executeCoordinationTodoTerminalLifecycle(loopx/control_plane/coordination/todo_terminal_lifecycle.ts:1023)在无绑定 Goal acceptance 时提前拒绝 completion_result,再沿用原有 validator/事务;本地证据指针与正式验收不同。
  • _build_interaction_cli_channel(loopx/control_plane/work_items/interaction_contract.py:1298)给既有交付包添加本地工作区提示;这是提示,真正拒绝边界仍在 owner 中。

[P1] 把旧格式原 Todo 的仓库身份传给同一个隔离 owner。 loopx/state_refresh.py:1169–1176 在 todo_fields=None 时选择空对象。真实 CLI 对照中,原 Todo 明确指定 git:github.com/example/right;一个 origin 为 example/wrong 的实际 linked worktree,在本 head 的 legacy Markdown 路径得到 appended=true,后续原生 spend 成功,账本扣一次。相同 File 输入在 append 前拒绝。基线两条路径都接受错误 origin,因此这是本次新 gate 未补齐的既有遗漏,不能称作本 PR 新引入的权限绕过。复用完整 planning source;legacy 按现有 parser 的 item_limit=None 解析原绑定 Todo,再交同一 TS owner。新增 legacy/File/SQLite wrong-origin 拒绝、零 receipt/零 debit 和 matching-origin 恢复回归,不要增加第二套 Python 隔离决策。

[P2] 归因当前 terminal hook 验证失败。 test_read_only_settlement_omits_non_causal_delivery_workspace 在此 head 的完整运行和单独运行均失败,终结后的 periodic-report intent_count 期待 1,实际 0;同命令在不可变基线单独运行通过。尚无独立因果证据说明这是 PR 回归或无关历史问题。保留断言,定位差异或建立有效的无关归因;不能用旧 head 上的偶发历史、一次 green 或提高容差冲掉本次风险。

对主干的风险

实测正向链路:File 7 peers、SQLite 15 peers 的合法非 Git 工作,基线卡在 worktree gate,本 head 能 refresh→spend→同 Turn replay;只一次 debit,原 Todo 保持 open,下一 Turn 仍能选它。单 Agent 原合法路径保留。真正错误的 artifact 完成失败且仍 open,修正内容后由原 validator 验收并 done;unsupported result-file 从基线的“先跑 validator 再拒绝”变为“先拒绝且给 evidence 修复途径”。显式 owner 隔离、本地/Git 不匹配和外部根目录拒绝;回到注册根可继续。typed blocked/no-spend、释放执行 lease 的续跑也通过新原生回归。

验证:主要 Python 范围 163 passed / 1 failed,另有 Goal acceptance CLI/runtime 33 passed;TS 工作区/settlement/terminal 127 passed,typecheck 通过;开发期 advisory 未发现支持的新增词汇载体,完整语义/census/hot-path 与 19 项 premerge 检查及直接检查通过。没有查询/等待 CI。失败、基线结果与遗漏没有被这些 green 覆盖。所有探针使用隔离临时项目、真实存储和真实 Git,未改 active Goal、账户或 live Bot;没有真实模型/远端 provider 或 packaged App 端到端证明。

我的整体评价

设计和规模相称:既有 typed owner 承担规则,原 receipt/validator/lease 复用,没有新 schema、配置开关、调度器或必须重复输入的信息。前瞻整理已体现在归属收敛;下一步最有价值的是复用完整 Todo 来源,补齐 legacy 输入,而非扩展抽象。此 PR 的局部效果和操作效率已显示正向,整个现存边界仍需上述两项证据修复,当前不批准、不合并;App/Bot 和长期模型效果保持未测。

English verdict: REQUEST_CHANGES - e4b1fbd. Real File/SQLite non-Git peer continuation and one-debit replay improve, but legacy Markdown drops the bound task repository and accepts/charges a foreign linked checkout. A current terminal-hook check also fails twice while the immutable baseline isolated check passes; attribution is unresolved. 163+33 Python tests, 127 TS tests, typecheck and 19 premerge checks passed alongside the retained failure. Complete the original-source gate and qualify that failure before approval.

…24-5566

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent — gpt-6.1-sol (OpenAI); runtime_reported; reasoning_effort=xhigh

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

结论:APPROVE,精确 head b43f38e24ce96964358d776ce65c8330eea34f81。没有阻塞发现。此前 REQUEST_CHANGES 的仓库来源遗漏已修复;hook 失败经独立同输入对照证实是既有问题,保留风险而不称作本 PR 已修复。自审不能替代 GitHub 合并资格,仍须另验原生 merge-readiness。

动机

在非 Git 项目中协作研究、整理材料的 Agent,以及需要回读它们进度的操作者。同一研究任务以前通过准入和独立验收后,仍被 Git worktree 要求卡在回写;本次实测能用注册的本地工作区结算,并在下一 Turn 继续原任务。合格本地工作可以保留交付身份写回;重放只记账一次,进行中的 Todo 保持 open,未通过独立验证的结果不能完成。本 PR 不证明真实模型效果、App/Bot 全链路收益,也不授权远端账户或代替正式 Goal 验收。CLI 交付工作区与结算边界已满足本次修复;同秒 hook 身份碰撞仍属既有独立问题,真实 App/Bot 和模型长程效果保持未测。

体验收益有真实边界证据:减少无意义 Git 初始化、重复恢复和误用 result-file 时的 validator 副作用;长期收益是原 Todo、Turn 和验收承诺能延续到可回读且只记账一次的结果。未测的模型质量或总体吞吐不能从这些测试推算。

改动思路

复用既有 TypeScript 工作区 owner,以实际 local/Git 类型、owner 要求和原任务仓库决定隔离;Python 只观察宿主和解析支持的 Todo 来源。既有认领、lease、独立 validator、验收和额度 owner 保留。强反对理由是错误放宽仓库边界,本次对照同时证明合法本地工作不会被误拦、错误 origin 不能逃逸;失败后回到正确 origin 可在原 Turn 前进。

正式 Goal result 没有绑定验收标准时,在 validator 前拒绝,并给 --evidence 修复途径;不把一个独立 validator 当作 Goal 验收授权。

具体改动

完整重审当前 main 30efccd6c7d4e2300c2ac87ddc6ddb1dfb855a40 到 head 的 12 文件(+401/-21):6 个生产文件、3 个测试、2 份文档、1 处生成行号 census。上次审查至当前 head 只增加完整 legacy 来源适配和三 provider 回归(2 文件 +60/-1),并先整合当前 main,未继承旧结论。

独立规范:docs/reference/protocols/peer-agent-runtime-v1.md 固定在变更前 69ad89c7fe214e3fb67d1fe894b65b17e6040461,以及原 quota Post-turn accounting protocol。逐项:Work Ownership 保留原 claim/lease;Workspace Isolation 用完整原 Todo 的 task_repository 核对真实 origin;Completion And Review 保留独立验收而不从 profile 推导授权;Post-turn accounting protocol 保留原 Turn、一次扣额、blocked 零扣额和后续续跑。修改后的文档是默认行为变化的披露,不能代替这些原规范。

关键代码:

  • refresh_state_run(loopx/state_refresh.py:693,输入适配在 1169)先取得完整 canonical 来源;legacy 使用既有 parse_active_state_todos(..., item_limit=None),再按原 todo_id 精确选 task_repository,避免显示 cap 或 None 冒充“没有仓库”。实际规则交给同一个 typed owner。
  • evaluateDeliveryWorkspace(loopx/control_plane/agents/delivery_workspace.ts:249)使用既有 local/Git schema 的 isolation 分支:注册本地根可记录本地交付,显式 owner 隔离或原 Git 任务仍需匹配 Git worktree;未验证根或 origin 不产 receipt。
  • executeCoordinationTodoTerminalLifecycle(loopx/control_plane/coordination/todo_terminal_lifecycle.ts:1023)在不具备 Goal acceptance 绑定时提前拒绝 result,再沿用原 validator/终结事务。实际 CLI 中 unbound result 不产生 validator 标记,错误 artifact 留 open,修正后独立验证完成。
  • _build_interaction_cli_channel(loopx/control_plane/work_items/interaction_contract.py:1298)提供本地工作区提示;提示是 advisory,真正拒绝在 owner 中执行。

P1 闭环:原 regression 在生产修复前运行,legacy 失败、File/SQLite 通过;修复后3种来源错误真实 linked origin 均在 append 前拒绝且零 debit,matching origin 在同原 Turn 写回、spend、replay 后仅扣1次。原任务放在35条无关任务之后,确实核验完整来源。

对主干的风险

File 7 peers、SQLite 15 peers 和单 Agent 实际 CLI 对照:多 peer local 基线拒绝,当前 head 完成 refresh→spend→replay,仅1次 debit,同 Turn skip,下一 Turn仍选 open 原 Todo。File/SQLite 在旧任务已准入之后新增任务、登记第二 peer,再为新任务建立自己的 Turn/claim/lease;当前 head 可结算且新 Todo open,基线仍卡 local worktree。其他 owner/exclusion/capability 拒绝保留,外部根拒绝后注册根恢复,显式 Git task 不被 local receipt 满足。typed blocked 零扣額和释放执行 lease 后的合法延续通过。

当前生产源码验证:200 Python passed、127 TS passed、typecheck passed、19 项原生 premerge 与直接检查 passed,advisory 在全树语义检查前运行。没有查询、轮询或等待 CI;没有削弱断言或增加等待来获得 green。真实隔离 File/SQLite/legacy、Git和validator验证不修改活动 Goal,不证明真实 Bot、账户、模型或 packaged App端到端收益。没有 PostgreSQL 存储重构或 provider promotion。

P2 归因闭环,仍有未修风险:原 head 全套 163 passed/1 failed 和单项失败、旧基线单项通过均保留。自然当前全套200通过不能消除间歇性。冻结仅旧 Todo commit timestamp为同一秒,实际 CLI 的其他 owner 不改:当前不可变 main 30efccd6c7d4e2300c2ac87ddc6ddb1dfb855a40 与精确 head 都得到相同 AssertionError,终结 hook 将普通零-intent receipt 当作 replay,intent_count=0;旧69ad也同样失败。Todo CLI、post-writeback CLI、hook Python/TS owner和原断言文件在当前base/head字节相同。故这是 pre_existing_unrelated 的同秒身份碰撞,尚未修复,归现有 hook owner;本 PR 不引入或改变该身份规则。合并资格与该风险明确分开记录,不将一次 green、相等数量或旧评论作为归因证据。

我的整体评价

此有界 CLI 修复对长程延续和操作效率为正向:让合法产物进入一次记账和后续执行,减少重复恢复且保留必要授权。没有新增 schema、capability、配置开关、调度器或必须重复提供的参数。前瞻整理已应用为“复用同 typed owner、补齐同来源适配”,现有 parser/receipt 足够,无需新框架。没有阻塞发现;最强缺失验证仍是真实 App/Bot/model 长程结果,当前不声称这些已经完成。既有同秒 hook 风险如上保留。

English verdict: APPROVE - b43f38e. No blocking findings. The legacy task-repository omission is fixed through the existing complete parser and same typed workspace owner; three real-provider wrong-origin/recovery regressions now pass. Actual CLI local peers, fresh task after admission, one-debit replay and later continuation improve without new required inputs or authority. 200 Python tests, 127 TS tests, typecheck and 19 native premerge checks pass. The deterministic same-second terminal-hook diagnostic still fails identically on immutable current main and this head; byte-identical causal files establish a pre-existing unrelated identity collision, not a repaired failure. Live App/Bot/model outcomes remain unmeasured; merge readiness is a separate native gate.

@loopx-agent
loopx-agent merged commit 1af7dbd into main Oct 4, 2026
23 of 28 checks passed
@loopx-agent
loopx-agent deleted the codex/local-delivery-contract-20261004 branch October 4, 2026 12:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant