Skip to content

fix(chat): preserve Todo authority and independent metadata - #5605

Merged
huangruiteng merged 4 commits into
mainfrom
codex/todo-preview-recovery
Oct 4, 2026
Merged

huangruiteng merged 4 commits into
mainfrom
codex/todo-preview-recovery

Conversation

@loopx-agent

@loopx-agent loopx-agent commented Oct 4, 2026 •

Copy link
Copy Markdown
Collaborator

Canonical Todo preview refusals previously escaped as generic errors; unclaimed tasks borrowed the Goal's default executor as an owner, and confirmed updates left the workspace stale. The Chat adapter now preserves the canonical refusal code without granting actor/lease authority. Active cards, completed history and inspectors show only recorded claims. Confirmed Todo updates reuse the existing Goal-scoped status loader; action-driven read failures retain the verified write receipt and show recovery guidance.

The same shared Todo mapper now preserves notes independently from evidence. Note-only records appear as Notes, and records containing both fields retain both. The existing inspector exposes complete notes through a keyboard-accessible disclosure in English and Chinese. This fixes presentation only: no persisted schema, configuration default, permission or canonical writer changes.

Validation: 54 HTTP checks including actual File/SQLite refusal with no proposal/effect and redacted source; actual React consumer smoke covering claim absence/presence and independent metadata across both languages/open and completed states; workspace contracts; packaged TypeScript build/source verification; standard risk-based premerge including semantic and public-boundary checks. Real packaged File/SQLite walkthroughs verified long-note/evidence readback, normal confirmation, complete source/opaque metadata/history preservation, failure/draft recovery and no duplicate writes. A 390px keyboard-accessible viewport was also inspected.

Existing evidence/title presentation budgets and freshness of an already open inspector after external metadata updates remain separate consumer gaps. Complete metadata coverage and installed adoption are not certified here. Full scripted browser suite, Lark/PostgreSQL/Windows and real host execution were not exercised. The existing unrelated maintainability advisory and bundle chunk warning remain. The stale structural review_priority assertion was aligned with the shipped review_order field.

Future-facing pass: reuse the existing typed read model, native disclosure and status owner; remove the notes-as-evidence inference without introducing a parallel Python decision owner. This product/control-plane PR requires maintainer review and merge.

中文:保留 canonical 拒绝原因、真实领取归属和确认后的自动读回;备注与证据分别展示,长备注可用键盘展开。真实 File/SQLite 的普通确认、完整原文/未知字段/历史保持及失败恢复已验证。完整 metadata 覆盖、打开中详情的外部更新刷新和安装采用仍有未完成边界;交由维护者评审合并。

@loopx-agent loopx-agent changed the title fix(chat): show canonical Todo preview failures in context fix(workspace): preserve canonical Todo errors and claim identity Oct 4, 2026
@loopx-agent
loopx-agent force-pushed the codex/todo-preview-recovery branch from 1ee649d to c7a19bc Compare October 4, 2026 18:38
@loopx-agent loopx-agent changed the title fix(workspace): preserve canonical Todo errors and claim identity fix(chat): preserve Todo authority and refresh confirmed updates Oct 4, 2026
@loopx-agent

Copy link
Copy Markdown
Collaborator Author

Validation update for head c7a19bca7a99e287428b8f00af6a44fa671c34b2: confirmed Todo updates now invalidate their Goal through the existing background loader. Action-driven read failures reach existing refresh guidance without invalidating the successful receipt; passive reads retain their behavior. This also makes lifecycle/decision reconciliation failures observable through the same owner.

Passed: TypeScript/package build/source verification, actual React ownership consumers, progressive-loader (37 checks), action-review parity/negative cases, workspace contracts, standard premerge and public-boundary checks. Real packaged File/SQLite A/B walkthroughs verified automatic priority visibility, retained claim absence, complete records/metadata/history, canonical refusal with retained draft and zero effects, and blocked-read recovery without duplicate writes. No affected consumer/server source changed during rebase.

Failures/skips: an old structural contract assertion initially expected only lifecycle/decision reconciliation and was updated for the explicit Todo behavior. Existing unrelated Lark maintainability advisory and chunk-size warning remain. Full scripted browser suite, Lark/PostgreSQL and installed application adoption were not exercised. The full metadata journey is not claimed complete.

Future-facing refactor reused the existing status owner; no parallel Python decisions or persisted vocabulary. This control-plane/product PR remains for maintainer review and merge.

该 head 的自动更新可见性及读取失败恢复已在真实 File/SQLite 打包页面验证;完整源与历史保持,每次确认只写一次。仍保留完整 metadata 呈现、安装采用及上述未测边界,不以通过测试替代业务验收或合并授权。

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
@loopx-agent
loopx-agent force-pushed the codex/todo-preview-recovery branch from c7a19bc to ca1a047 Compare October 4, 2026 19:20
@loopx-agent loopx-agent changed the title fix(chat): preserve Todo authority and refresh confirmed updates fix(chat): preserve Todo authority and independent metadata Oct 4, 2026
@loopx-agent

Copy link
Copy Markdown
Collaborator Author

Validation for exact head ca1a04724c587e39794721c1901a501d1fd873af (base bd607db9c563b263111abdbc37167620e919feb7): the shared Todo consumer now preserves source notes separately from evidence. Note-only records are Notes; dual-field records retain both. Complete notes use the existing bilingual inspector with native disclosure and visible keyboard focus. No writer, actor/lease authority, provider schema or machine defaults changed.

Passed: actual React claim/metadata consumers, final workspace contracts, canonical packaged TypeScript build and source verification, 54 HTTP checks, and standard premerge including semantic and public-boundary checks. Actual packaged File/SQLite walkthroughs read back the complete long note and independent evidence after one ordinary confirmation each. All other records, opaque metadata and the full original history were preserved; each confirmation added exactly one transaction. The unprivileged claimed-task preview was refused with retained draft and unchanged state. English/Chinese desktop and 390px keyboard/disclosure presentation were inspected. The affected consumer/server/store sources are unchanged by the final rebase.

The exact-scope change-quality receipt passes and retains two nonblocking consumer warnings: existing active text/evidence display budgets and snapshot freshness of an already open Todo inspector after an external update. These are real remaining gaps; reopening reads current values. Complete metadata coverage and installed application adoption remain unqualified. The runtime receipt also includes the local untracked lockfile, which is excluded from the 15-file public PR.

Failures/skips: a pre-existing stale structural assertion expected review_priority; one bounded safe-fix pass updated it to the shipped review_order field and reran the check. Source verification initially lacked the canonical bundle manifest; the repository's canonical build and verify then passed. Existing unrelated Lark maintainability advisory and chunk warning remain; no budgets were relaxed. The full scripted browser suite, Lark/PostgreSQL/Windows and real host execution were not exercised. PostgreSQL authority storage is unchanged.

Future-facing review reused the existing typed Todo mapper, action receipt, status owner and native disclosure. No additional abstraction or Python decision source is needed for this slice. This author validation does not replace maintainer review or authorize merge.

中文:本 head 的备注/证据独立语义及普通确认后的完整原文读回已在真实 File/SQLite 打包页面验证;所有原记录、未知 metadata 和历史保持,每次确认只有一个 effect。键盘和窄屏可用。现有显示预算与外部更新时打开中详情的刷新仍有缺口,完整 metadata 与安装采用未验收;质量回执保留这些 warning,PR 继续交维护者评审合并。

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; model=gpt-6.1-sol; provider=OpenAI; declaration_source=runtime_reported; reasoning_effort=xhigh

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

审查 head:ca1a04724c587e39794721c1901a501d1fd873af;基线:bd607db9c563b263111abdbc37167620e919feb7。未发现阻塞问题;有一项非阻塞文案建议。

动机

在工作区查看和修改 Todo 的用户,需要看到真实领取者、独立的备注与证据,以及确认后的最新任务状态。
此前未领取任务借用 Goal 默认执行者作为 Owner,备注被当作证据或被独立证据遮住;确认修改后还需手动刷新,权限拒绝也只能看到泛化错误。
本次预期改进是只展示已有 claim,分别呈现完整备注和证据,确认后自动读回,并保留权限拒绝的原因及草稿;真实 File/SQLite 打包页面已验证这些语义及失败恢复。
本次不验收完整 metadata 覆盖、安装采用、Lark/Windows/真实模型,也不补造 actor、lease 或 canonical 写权限。
剩余边界是原有标题/证据展示预算和打开中的 inspector 对外部更新仍需重新选择;本次不把它们算作已修复。

先读取基线 docs/development/frontend-delivery.md,spec_revision 为 bd607db9c563b263111abdbc37167620e919feb7;按 Task-first delivery / 从用户任务开始 核验普通操作、必要的一次确认、真实 packaged 页面、owning backend、失败恢复与 readback。配套 docs/project-agent-todo-contract.md 的 Reviewed canonical edits and recovery 明确要求 Chat 自己获取基线、preview 调用真正 dry-run,caller context 不提供权限;本次保留这个边界。

改动思路

扩展既有 typed Todo mapper、drawer 和 Goal-scoped status loader,比增加第二份 Todo 状态、权限豁免或新的刷新机制更小。Python 只适配 canonical exception 的公开诊断;实际写入、CAS、历史回执和 actor/lease 判断仍是原 owner。用户选择优先级后检查一次提案并确认,确认提供实际写入授权;备注 disclosure 只是可选阅读,不增加必填表单。

具体改动

  • ChatRequestHandler._action_preview 捕获 LocalCoordinationAuthorityUnavailable,保留原 error_code、脱敏路径并说明重试;没有生成 proposal 或替用户取得 lease。
  • ContextDrawer.previewAction 捕获可回读错误,按 Goal+Todo identity 和 attempt fence 隔离结果,保留草稿;切换任务清除旧错误。
  • GoalTasksView、CompletedTaskLane 和 inspector 只从 recorded claim 展示 Owner;workspaceAgentTodoFromItem 将 note/evidence 分开,active 和 retained history 复用该 mapper。notes 使用原生 details/summary,完整呈现,英文/中文 label 和可见键盘 focus 同时补齐。
  • PersonalWorkspacePage.applyProposal 将 todo.update 纳入现有成功后 reconciliation;DashboardPage.loadFromUrl 只让 action-driven read 抛出失败,成功写入回执保留,passive refresh 语义不变。
  • package 增加真实 React consumer smoke;既有 browser 场景补拒绝草稿、错误隔离和一次确认后读回,HTTP 测试补 File/SQLite 真实 canonical 拒绝与零效果。registry I/O manifest 仅更新源行号;旧 review_priority 结构断言对齐已经发布的 review_order,没有新增行为开关。

共 15 文件 +213/-23,围绕同一 Todo 读写体验,没有新 capability、schema 或平行 Python 规则。未来维护继续在 shared mapper/status owner;已删除 note→evidence 推断,本次无需额外抽象。

对主干的风险

主要风险是把显示错误当成写失败而重复写入,或把默认执行者误当成权限事实。独立验证包括 54 HTTP tests、真实 React ownership/metadata consumer、37 项 progressive-loader 检查、workspace contract、canonical packaged build/source verify、CSS token 检查、正式 semantic drift 和 whitespace 检查,全部通过;未读取 CI。

不可变 base/head mapper 对照覆盖 16 个相同合法输入(字段组合×open/done×claim):旧版 note-only 冒充证据、dual-field 丢失备注;新版二者独立,claim 和不涉及备注的语义保持。另有实际 React 双语、缺失/null/空/单字段/双字段以及完成历史覆盖。

独立 reviewer 启动此 head 的真实 serve_chat 和重新构建的 packaged UI,使用隔离合成 File/SQLite stores;不修改活跃 Goal。两者都精确读回 18,233 字原备注和单独证据。File 中文页一次确认 P0 后自动刷新;全部原历史、其它记录、备注/证据保留,仅 priority/text/updated_at 改变,新增一筆事务。已领取任务的 preview 被拒绝,P2 草稿保留、完整 head/history 不变,切换另一 Todo 无旧错误。390px 页面无横向溢出,summary 44px,Enter 可展开且 focus 可见;桌面两语言 viewport 已查看。

SQLite 英文页在确认前仅阻断客户端 status.json 读取,确认仍产生可验证的成功回执,同时显示 Refresh 恢复提示;解除阻断并使用原 Refresh 后 P0、Owner、完整备注及证据正确。完整历史前缀和其它 Todo 保留,最终仍只有一筆写入。这证明读取失败不会要求再次执行写入。模型/执行器被禁用,这不证明 installed App 或真实模型采用。全 scripted browser suite 和 PostgreSQL 未跑;本次没有 PostgreSQL authority refactor。

非阻塞 P2:i18n.tsx::feedback.goalRefreshFailed 现有文案 “The Goal opened...” 也被 Todo 修改后的状态读取失败复用。实际场景是写入已经完成,应改为说明“操作成功,但最新状态暂时无法读取;请刷新”,避免让用户误以为只是打开页面;中文应一致。回执与恢复已正确,因此不阻塞这次修复。

我的整体评价

APPROVE,作为有明确剩余边界的体验改进。正向价值来自更可信的归属和资料、减少确认后的人工刷新,以及读失败时保留成功回执并避免重复写入;不是来自测试数量。完整 metadata、外部更新的打开中 inspector 和安装采用继续由既有 consumer 后续工作验收。保留必要的一次写确认和 canonical 权限,持续工作不会因这次改动获得更宽权限。评审不授予合并权限。

English verdict: APPROVE - head ca1a047. Recorded ownership and independent notes/evidence are preserved; confirmed updates reconcile without duplicate effects. 54 HTTP tests, real React consumers, packaged File/SQLite reviewer journeys, blocked-read recovery, 16 immutable base/head mapper cases, build/source, CSS and semantic checks passed. P2: make refresh-failure wording identify the successful action. Full metadata coverage and installed adoption remain unqualified; CI was not consulted.

@huangruiteng
huangruiteng merged commit 8f34c2c into main Oct 4, 2026
5 of 7 checks passed
@huangruiteng
huangruiteng deleted the codex/todo-preview-recovery branch October 4, 2026 20:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants