Skip to content

feat(control-plane): protect caller-authored first delivery on CLI/MCP - #5677

Open
xyx2002OvO wants to merge 18 commits into
loopx-project:mainfrom
xyx2002OvO:codex/first-delivery-freshness
Open

xyx2002OvO wants to merge 18 commits into
loopx-project:mainfrom
xyx2002OvO:codex/first-delivery-freshness

Conversation

@xyx2002OvO

@xyx2002OvO xyx2002OvO commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Problem and delivered stage

Execution can finish against an outdated task or direction basis. This PR binds explicit local File/SQLite CLI and MCP completion to the actual read identity, checks relevant facts at the owning commit, and recovers the original Turn without repeating a committed result or quota debit.

This is PR1: a CLI/MCP protocol and backend prerequisite. The caller validates the candidate, commits the ordinary result, reads the resulting direction basis, authors its Vision/unchanged decision, and resumes the original settlement. Managed execution retains main's ordinary implementation and session behavior. Default owning-Agent continuation and its packaged product journey belong to the next stage; an optional independent reviewer needs a separately registered input/result/recovery contract.

Scope and contracts

  • Preserve receipt-first recovery, provider CAS/source fences, indexed checkpoint replay, and uncertainty when an append cannot be established.
  • Remove the automatic independent direction Host, its session/profile branch and attempt-budget machinery from this stage. Python captures/transports IO; existing TypeScript owners retain decision and commit authority.
  • Reject protected no-followup before a new native commit; MCP rejects that intent before preparing effects. Existing ordinary closeout, exact historical receipt recovery, and refresh → spend → terminal ordering remain unchanged. The later protected terminal stage must close its changed-frontier recovery before being admitted.
  • Preserve ordinary completion with malformed optional history when an exact receipt or verified ordinary original writeback proves the existing path. Unknown enrollment is not inferred absent.
  • Keep Post-Writeback optional-hook isolation and its primary settlement boundary unchanged. No additional primary settlement step, model invocation, new reviewer capability, budget-grant API, or Goal completion certificate is introduced.

Validation

Validation details and remaining limitations are recorded in the update comment on the exact pushed head. Focused checks cover real File/SQLite CLI/MCP commits, stale basis rejection/reread, response/crash recovery, ordinary receipt replay, and zero new effects for unsupported protected closeout. Type checking, generated contracts, registry I/O inventory and semantic vocabulary checks are included. PostgreSQL uses an isolated disposable server for shared authority compatibility; this does not add PostgreSQL first-delivery support.

CLI and MCP are the changed entrypoints. Status/quota use the existing shared readback consumed by frontend/Lark; this does not claim the default managed or packaged frontend recovery journey is delivered. Existing source-session, compound repair/replan, distributed atomicity and model-outcome acceptance remain outside this stage.

The future-facing pass narrows the existing Todo/checkpoint boundaries and removes unused managed/terminal-specific structure. Local study reports, frozen evaluation inputs, raw logs and private planning remain excluded.

@xyx2002OvO xyx2002OvO left a comment •

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Author validation correction — previous APPROVE conclusion withdrawn

此前由改动作者发布的 APPROVE 结论撤回。作者自检不能替代独立评审;基线复现只能说明失败来源,不代表当前 PR 的红色检查已经处理完成。

当前交付仍有两项未完成:处理 CI 失败并验证修复;获得独立评审。此前列出的本地通过项仍是验证证据,但不构成批准、完成交付或合并授权。PR 保持未合并。

This comment replaces the author's earlier approval conclusion. It records author validation only, not an independent review or approval. CI failures still need remediation and verification, and independent review remains outstanding. No merge is authorized by this comment.

Original reviewed head: a87ee49. The earlier validation record remains in the PR description; its baseline-failure attribution must not be read as resolution.

@xyx2002OvO
xyx2002OvO force-pushed the codex/first-delivery-freshness branch from a87ee49 to 1e47484 Compare October 5, 2026 12:55
@xyx2002OvO
xyx2002OvO requested a review from maxliux5 as a code owner October 5, 2026 12:55
@xyx2002OvO
xyx2002OvO requested a review from steven-kid as a code owner October 5, 2026 13:20

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh

动机

长程执行中先完成结果、再决定下一步的 Agent 和读取进展的操作者。 以前执行期间新增要求可能没有进入原方向判断;现在结果先保留,再读当前要求重判,新增任务会拒绝旧方向而不重复已完成工作。 两个隔离 Goal、工程和研究四类注册 Agent 的实际 File/SQLite 调用保留了结果及同伴证据;新增任务使旧方向失效,拒绝时没有追加或扣额。 本轮不验收完整 Goal、长期模型收益、已安装 App、源机会话或新权限。 新功能的完整界面操作、真实模型效果和持续效率仍未验收;本次两个回归先由本 PR 修复。

“当前方向”是读完结果后的下一步判断,不是新的实施工作。本次独立验证支持这个有界收益,但关闭态读回出现回归,不能据此批准整个精确 head。

改动思路

入口是显式 --first-delivery 或 MCP first_delivery=true。实现前读结果依据,普通结果由现有 Todo CAS 提交;之后重新读方向依据并调用一次独立 Host,只能返回方向字段。TypeScript 比较真实 authority、依赖、lease、Goal/Agent/Turn 及相关 frontier,Python 负责 IO 和已有 journal 的恢复。模型推理在 provider/source 锁外;方向变旧时重判,成功结果及原扣额回执保留。需要终结的路径还检查提交后的全 Goal 方向,新增任务不能被旧的 no-followup 吞掉。

这比把旧 Vision 换上一个新 read ID 更可靠,也比重做实施节省重复工作。新的 read ID、用户选择与 Vision 判断属于不可推断的意图;进展显示从已有 Todo、run、spend 回执推导,不能另存一个成功布尔值。共用 checkpointProviderFacts、原 CAS/receipt 和 settlement owner 是合适的边界。MCP v0/v1 和旧 supplement 有真实持久消费者,需要保留,但共享 observer 必须隔离坏文件。

具体改动

完整 merge-base 6bfa358d3bced7f8b1effa4468adfbea0bce8dec → 772f442fcc0a17f9176695431a9e11526d626996,57 文件 +1932/-183;包括 CLI、MCP、managed executor、shared status/quota、File/SQLite fence、文档及验证。远端 base tip 已向前移动,不能把两 tip 的无关差异算成本 PR。本次看完整提交和 diff,不继承作者的自评或大测试数字。

独立规范是 docs/reference/protocols/goal-vision-replan-contract-v0.md,spec_revision 6bfa358d3bced7f8b1effa4468adfbea0bce8dec。Vision Checkpoint:本轮结果/新工作边界已实现;Read basis for checkpoint-only recovery:原身份和 real fence 路径通过,普通关闭态规则因下面 P2 不满足;Semantic History Continuity:成功重放、方向失效和 unknown 不能自证 Goal 完成,已核验。新文档的 first-delivery 承诺没有反过来充当自己的验收标准,整体 roadmap 与真实模型运营验收保持 open。

关键代码讲解

  • checkpointBasisSnapshot(checkpoint_read_context.ts:44):明确区分 result 与 direction,方向重新计算完整相关 frontier,其他 Agent 的独立工作不会进入自己的 lane;共享要求和相关依赖仍进入依据。
  • terminalDeliveryBasisCheck(todo_delivery_context.ts:45):在最终 canonical head 上核对结果 token,重放先读原回执,必要的 terminal 还核对 indexed direction 与当前 frontier;CAS 重试保留同伴更新。
  • prepare_first_delivery(direction_review.py:21):普通结果先提交再推理;异常保留原 Turn 和成功结果。方向最多两次推理,持续变化进入明确恢复,不能无限空转。Codex 路径新建临时 read-only 调用并去掉本次注入的 LoopX MCP;通用 Host 仍是受信任执行边界,未实测额外全局工具隔离。
  • pending_first_delivery_progress(checkpoint_context_io.py:120):新 observer 扫描所有历史 JSON,先解析后按目的/Agent 过滤,异常直接泄漏到普通 status,形成下面的关闭态回归。

对主干的风险

[P2,阻塞] 把历史 receipt 损坏限制在观察范围。 在没有 first-delivery enrollment 的隔离 Goal,给 checkpoint-contexts 放一个正确摘要命名、内容损坏为 { 的历史 receipt。实际 File 和 SQLite status --goal-id … --agent-id …,base 两次 exit0/ok=true,head 两次 exit1/ok=false,完整错误为 Expecting property name enclosed in double quotes: line 1 column 2 (char 1);健康和旧 supplement 三组配对均通过。原因是 checkpoint_context_io.py:123–127 在 purpose/agent 判断前无保护地 json.loads,共享 collector、quota 和 bootstrap 都新增调用。一个与本次功能无关的旧文件现在可让普通进展读回失败;损坏不可被解释为“没有待恢复工作”,也不应该让其他 lane 失去状态。最小修复是在既有 observation owner 校验/隔离不完整读回,以 scoped unavailable/unknown 保留错误,同时让无关关闭态工作仍可读取;实际已 enrolled 的不确定提交继续 fail closed。补上 File/SQLite、其他 Agent、未启用和已启用 crash 的反向测试,不能只把全局异常吞掉。

[P2,阻塞] 恢复跨换行的生成一致性。 turn_contract_generated.py:3 和 .ts:3 把 SHA 改成 252c7ea…,但 canonical JSON 没改。独立复算 LF source 为 18404665…,把同一字节内容改成 CRLF 恰好得到 252c7ea…。相同 uv run --extra test python scripts/generate_turn_contract.py --check 在固定 base 通过、head 拒绝两份 stale artifacts;原生 semantic smoke 也因此失败。生成器按 raw bytes 算摘要,使 Windows 生成头无法在 LF checkout 满足当前检查。请固定 canonical newline/内容摘要并重新生成,或明确强制源的 LF 边界;同时在 LF/CRLF 输入上验证语义相同的生成结果。只保留 Windows 的绿色记录不解决这个 portable gate。重新跑 generator --check 以及 uv run --extra test loopx canary smoke-suite --script semantic-vocabulary-drift-smoke.py。

独立实际验证:head 181 Python pass,含 File/SQLite 进程写锁和 before-artifacts/after-json/after-markdown/after-index 崩溃、managed 单次实施/方向重判/失败恢复、MCP 结果→方向→一次扣额与新增任务 terminal 拒绝。固定 base 139 pass/7 fail:6个 MCP fixture 缺 connected-delivery 在 guard 被拒绝,另1个无 Vision replan 原 oracle 错误;head 修改对应 fixture/区分 missing-Vision obligation 后通过,未放宽产品 gate,新增未连接负例保留。它们是基线验证差异,不是本轮 7 个新回归。

TS focused 84 pass/15 PostgreSQL skipped;随后在一次性真实 PostgreSQL 16.2 跑 authority store/archive、lease、acceptance、delegation,共 441 pass/0 skip,补齐 shared terminal CAS 的实际 PostgreSQL 兼容检查。新 first-delivery 本身仍只支持 File/SQLite。TS typecheck、changed Ruff、diff check 和三个 UI contract 用例通过。语义 advisory 先执行(没有受支持的 carrier 候选,并不等于无新语义),完整 semantic smoke 的生成失败保留,未扩大预算。

独立另外走实际 CLI 的工程/研究两个 Goal、四个注册角色:peer update→自己的 result CAS 保留 peer evidence,方向读到 selected done,自己的 lane 排除 peer;后加入新的自己任务,旧 direction 返回 stale/frontier,无新 run/扣额,已提交结果仍 done、新任务仍 open。这些是 isolated authority/确定性 Host 验证,不是活动 Goal 改写或真实模型效果研究。最初 probe 给 agent todo add 带了不支持的 --agent-id,合法拒绝;改成已有 --claimed-by 后才采用结果,没有修改生产 parser。

界面改动只增加既有投影的 contract 检查;本轮没有重跑 packaged viewport/native App、Lark 外部写入或完整交互,也没有实测 Codex 模型或长期吞吐。CLI/MCP 新能力的完整可发现/可操作前端仍由现有展示 owner 验收,不能用这三个静态测试替代。历史 context 全量扫描和逐身份 settlement 读取有累积成本,尚未测量规模曲线;建议本次 observer 修复复用完整当前状态的一次读取,避免再加平行状态或静默截断 pending 工作。

语义与 CI 对齐

结果/方向 purpose、阶段和 v2 request 是已有 checkpoint/host owner 的本地显式扩展;没有创建新的 actor 生命周期或授权。receipt/schema/decision 必须由机器核对;direction-only 的操作禁令对通用 Host 仍是指令,不能叫作工具权限隔离。关闭态 observer 回归和 generated owner 不一致违反当前隔离/生成契约。按本 Goal wait_for_ci=false,未查询、轮询或等待远端 CI;本地通过、失败和未测分别保留。

我的整体评价

REQUEST_CHANGES。long_horizon=regression,user_experience=regression。 成功结果保留和原 Turn 恢复的有界收益成立:减少丢回复后的重复实施,新增任务能纠正旧方向。代价是正常路径多一次方向推理,发生 stale 时最多再一次;这是实际调用数量,不是净 token 或吞吐收益。关闭态 status 被旧文件击穿、跨平台 generation 失败修复前,整个 head 对持续运行和可用读回仍有负向影响,不能给批准。

future-facing pass 已核对共用 provider facts、CAS/receipt 与 typed decision owner;最小相关修复是 observer 的错误/枚举边界及 canonical generation。历史扫描规模优化可随同边界验证后收敛,不能只截断数据或增加一个人工同步成功字段。保留实际前端、真实模型收益和持续效率证据缺口,不新建平行路线图,不合并、dismiss 或升级本机。

English verdict: REQUEST_CHANGES — exact head 772f442. Two blocking P2 findings: malformed historical contexts break ordinary feature-off status on both real File/SQLite, and CRLF-derived generated hashes fail the LF native generator/semantic gate. Core staged recovery is supported by181 Python tests,441 isolated real PostgreSQL compatibility checks,84 focused TS passes and independent two-Goal/four-role authority walks. Extra direction inference and accumulated observation costs prevent a net long-run efficiency claim; packaged UI, live models and installed behavior remain unqualified.

"""Bounded to this Agent's enrolled local Turns; readback, never admission."""
identities = {}
for path in (root / "goals" / goal_id / "checkpoint-contexts").glob("*.json"):
receipt = json.loads(path.read_text(encoding="utf-8"))

@loopx-agent loopx-agent Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] Keep malformed historical observations from breaking ordinary status

With first_delivery disabled, one malformed digest-named historical context makes the real status CLI exit 1 on both File and SQLite. The same fixed fixture exits 0 at the merge base. This JSON parse runs before purpose and Agent filtering, and the shared collector invokes it unconditionally.

Validate and contain this readback in the existing observation owner. Report scoped unavailable or unknown evidence while keeping unrelated disabled lanes usable. Preserve fail-closed handling for actual enrolled uncertain appends. Add both-provider disabled/other-Agent negatives alongside the enrolled crash/replay positives.

"""Generated by scripts/generate_turn_contract.py; do not edit.
Source: loopx/control_plane/turn_loop_controller_contract_v0.json
SHA256: 184046656dada524b5412be128424b840dc1d490eef5bf8a0c9e9e5bb786492a"""
SHA256: 252c7ea204f59809779aa2fed4a7998d5b0579d46bb141bd95f3711553b750c4"""

@loopx-agent loopx-agent Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] Keep the generated Turn digest independent of checkout newlines

The unchanged canonical JSON hashes to 18404665… in LF form. Replacing its newlines with CRLF produces exactly the committed 252c7ea… header. Consequently generate_turn_contract.py --check passes at the fixed base but rejects both generated files at this head; the native semantic smoke fails too.

Use canonical newline/content hashing or enforce the source LF boundary, regenerate both artifacts, and validate equivalent LF/CRLF source content. Rerun the native generator and semantic smoke; a Windows-only passing receipt does not satisfy this portable check.

@mergify

mergify Bot commented Oct 5, 2026

Copy link
Copy Markdown

This pull request has merge conflicts with main and cannot be merged
until they are resolved. Please rebase or merge the base branch, @xyx2002OvO.

Choose the remote for the base repository, not an out-of-date fork.
For a fork clone, first inspect git remote -v; upstream must point
to https://github.com/loopx-project/loopx.git. If it is absent, add it
with git remote add upstream https://github.com/loopx-project/loopx.git.
Then run:

git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEAD

For a same-repository clone whose origin points to
https://github.com/loopx-project/loopx.git, use origin instead of
upstream for fetch/rebase. If you prefer merging the base, use
git merge <base-remote>/main and push normally.

Keep the DCO Signed-off-by trailer on every commit when you rebase.
https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/syncing-a-fork

@mergify mergify Bot added the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 5, 2026
@xyx2002OvO
xyx2002OvO force-pushed the codex/first-delivery-freshness branch from 772f442 to cd8a5a7 Compare October 6, 2026 03:19
@mergify mergify Bot removed the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 6, 2026

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent — gpt-6.1-sol (OpenAI); runtime_reported; reasoning_effort=xhigh

Exact reviewed head: cd8a5a7; immutable baseline: 9e78309

动机

先完成工作、再判断下一步的长程 Agent,以及查看当前进展和恢复失败的操作者。

执行后要求变化时,旧判断可能继续沿过期方向;这个提交先保存已验证结果,再读取当前要求,拒绝过期方向时保留结果,不重复实施。

实际 File/SQLite 两个工程与研究 Goal、四类角色保留同伴证据;新增任务使方向失效,拒绝时没有追加或扣额。临时 Codex 方向调用的三类失败却删除原实施会话绑定,后续 resume 失败。

本轮不验收完整 Goal、已安装 App、外部 Lark、真实模型效果或长期吞吐。

这项分段机制有实际用途:要求变化不应抹掉已经完成的结果,也不应逼迫 Agent 重做实施。当前提交修复了上轮历史坏 JSON 导致未参与角色 status 失败、生成文件 CRLF 校验误报两项问题。但新的临时方向调用仍能破坏原实施会话,暂不能交付为可靠的长程恢复能力。

改动思路

复用现有 Todo、checkpoint 和 Turn journal,而不是另建目标或 worker。实施前读取当前要求、完整相关任务和 provider fence,终态结果以带读取依据的 CAS 写入原 Todo;随后一次新方向调用只提出后续判断,refresh 再核对当前来源,最后由原 settlement 扣额。结果、方向、checkpoint 和 spend 是不同阶段;某阶段拒绝不等于前面的产物丢失,也不等于整个 Goal 已完成。

读取身份和 result/direction purpose 是无法从其它记录猜出的调用意图;任务版本、frontier、当前进展则从 canonical 状态生成。commit-attempt journal 是崩溃后辨认既有副作用的事实,不是第二份手动维护的 Goal 真相。Python 负责 host/filesystem IO,TS 的既有 checkpoint/Todo owner 负责依据、范围和终态规则。旧 persisted supplement 与独立 MCP v0/v1 消费者仍有读取用途,不能为了减代码直接删掉。

正向路径已沿真实隔离 authority 走到结果保存、同伴更新、新任务加入和拒绝过期 refresh;结果和同伴证据都保留。Codex 方向调用用新 session、read-only sandbox,并去掉本次注入的 MCP server;这不证明任意 provider 或全局工具配置的隔离。当前缺陷是它的错误清理仍指向原 Todo 的持久实施 session。

具体改动

完整 base-to-head 为 58 文件 +2106/-181:38 运行时、16 测试、2 文档、2 构建/生成配置;读取了全部 diff、涉及的生产文件和未改动调用方。本轮没有只继承旧评审结论。历史坏 receipt 现在产生 observation_unavailable 警告,未参与角色的合法下一步保持;已参与但来源不全的原 append 仍拒绝。生成器对读取、hash 与解析统一换行,LF/CRLF 都可用,真正内容改变仍会被发现。

依据既有 docs/reference/protocols/goal-vision-replan-contract-v0.md,spec_revision 9e78309,没有用本 PR 新写的规范替代独立验收:

  • Vision Checkpoint:implemented,结果与目标结论分开,refresh 要求当前 Vision 或 unchanged reason;实际拒绝与恢复套件覆盖。此 PR 不关闭整个产品/接收方采用验收。
  • Read basis for checkpoint-only recovery:implemented,原 Turn 身份、相关完整来源与有 fence 的 append 保留;File/SQLite 多角色实测显示同伴无关更新不改变自身任务范围、新相关工作能使方向失效。
  • Semantic History Continuity:implemented,status 报告阶段及来源不足,旧 receipt 的存在不冒充 Goal 完成;历史坏数据不截断全部 status。完整 frontend、source-session enrollment、其它 provider 和实时模型采用仍按已声明阶段边界保留缺口。

关键代码讲解

  1. checkpointBasisSnapshot(loopx/control_plane/goals/checkpoint_read_context.ts)从 canonical 要求、相关 Todo/frontier、provider fence 构成读取依据;不是靠列表显示前几项证明没有工作。
  2. terminalDeliveryBasisCheck(loopx/control_plane/coordination/todo_delivery_context.ts)在现有终态写入 owner 核对依据;result 写已验证产物,direction 不能绕过终态检查。
  3. prepare_first_delivery(loopx/control_plane/turn_driver/direction_review.py:21)给真实 run-once 入口准备分段调用,保留原 Turn 的 journal/恢复身份;不是只有 serializer 可达。
  4. pending_first_delivery_progress(loopx/control_plane/goals/checkpoint_context_io.py:137)隔离历史读取失败并保留严格恢复边界;坏 JSON 变来源警告,不能伪造结果已提交。
  5. run_codex_cli_host(loopx/control_plane/turn_driver/codex_cli.py:684)令 direction 使用临时新 session,并在 store_session 的第 734 行避免保存到主绑定;但 discard_session 和第 865 行失败分支仍会删除同一原 lineage 的持久绑定,产生下面的阻塞问题。

对主干的风险

[P2] 临时方向调用失败会删除原实施 session,破坏后续 resume。 已有正常实施在默认 Todo scope 下保存主 session 绑定后,执行 direction_review。进程返回 model_requires_newer_codex、session_missing 或 output_schema_rejected 任一错误,原来用于实施调用的失败清理仍执行 discard_session();它用原 lineage 删除持久绑定,尽管这个方向调用根本没使用或创建该绑定。随后原计划的 resume 在第三个进程启动前报 Codex CLI resume binding disappeared after planning。

独立复现调用真实 production adapter、真实 OS 子进程、真实 session 文件,再调用 production resume。子进程是受控 Codex 事件 fixture,不是付费实时模型;绑定的保存、删除及后续恢复由生产代码实际执行。成功方向调用保留文件并可 resume,三类失败均删除文件并阻止 resume。结果、Todo 与已有 quota 收据不因此被删除,不能把这个问题扩大成重扣额或已证实重复实施。

最小修复:在现有 session owner 同时隔离临时 direction 的保存和删除,保留普通实施失败原有失效规则。私下只在内存给失败清理增加 not direction_only 条件,同一个四场景 harness 全部保留主绑定并可 resume;这只是修复可行性证据,公开 head 仍有缺陷。增加三类错误的真实文件与冷 resume 回归,重跑 uv run --extra test python -m pytest -q tests/test_loopx_turn_codex_cli.py tests/control_plane/test_first_delivery_managed.py,并对普通实施失败验证原失效规则。

现有检查全部通过仍未覆盖该分支:相关 Python checkpoint/fence/fault/managed/MCP/status suites 162 passed(1 个 Pydantic unresolved annotation 警告);既有 Codex/Turn 164 passed;TS checkpoint/terminal/content digest 43 passed;独立 PostgreSQL 16.2 的六组实际 store/lease/acceptance/delegation/archive suites 443 passed,0 skip,隔离临时 server 已关闭。Ruff、TS typecheck、生成器 check、diff check、canary 10 catalog +8 risk +1 public boundary、全树 semantic/census 均通过。未查询或等待远程 CI。

同一真实 status harness 在固定 base/head、File/SQLite ×无记录/旧 supplement/其它角色坏记录六场景都正常返回、原状态不改,下一步相同。head 对坏记录额外提供来源警告;这是真实完整响应差异,不把所有输出都说成逐字相等。尚未完成所有共享 schema、prompt、accepted-input 和 persistence 表面的完整 feature-off 配对证明,因此 default_off_isolation=not_yet_proven;未发现一个新的已复现默认路径故障,也不因对象不存在就认证隔离。新能力目前是明确的 CLI/backend 阶段,未验证 packaged frontend 的可发现、操作、失败和持久读回旅程。

语义与 CI 对齐

扩展既有 checkpoint/Todo/Turn vocabulary,而非新增 actor 或授权来源;purpose、basis、stage 与响应使用现有 typed owner,通用规则不含领域专用词或 substring denylist。开发 advisory 37 source/0 supported carrier 仅是有限探针,另有全树 semantic、registry census 和生成器检查通过。默认未启用 first-delivery opt-in;参与后依据拒绝是机器义务,方向判断是建议,不能把强制 CAS 称为可忽略 guidance。临时 host 的实际权限与现有 session 生命周期仍必须分别证明,名称没有自动授权效果。

我的整体评价

REQUEST_CHANGES。long_horizon=regression、user_experience=regression:结果保存和过期方向拒绝在上述范围有正向价值,但临时方向的常见失败会毁掉独立主 session 的续接路径,令后续工作失去既有上下文、需要修复会话后再继续。这是当前 head 的具体错误,不是仅凭规模、模型身份或未来设想拒绝。

58 文件形成一个可独立回退的 opt-in 阶段,现有 owner 下实现分段结果与崩溃重放有必要,纯 status 文案无法保护先发生的写入。完整 frontend/真实模型效率的缺口已明确保留,不能把该阶段视为全能力完成。额外方向判断通常增加一次调用、最多两次尝试;能否用少返工抵消模型成本尚未测量,没有长程吞吐或节省比例。未来改动已检查:最高价值的 bounded pass 是在同一 Codex session owner 收敛 store/discard 的临时调用规则,不需要新框架;旧持久 receipt/独立 MCP 消费者兼容保留,未要求无依据的全面迁移。

两个历史阻塞点已在本 head 核验修复;上述新 session 缺陷仍阻塞。重新评审需公开修复 head、三类错误保留主绑定且恢复、普通实施失效规则保持,并补足声明所需的 feature-off 证据。结果与 Goal 验收分开,当前 runtime/control-plane 变更继续交由维护者合并。

English verdict: REQUEST_CHANGES — cd8a5a7. The historical malformed-receipt and CRLF defects are resolved, but an ephemeral direction-only Codex failure still discards the persistent implementation-session binding. Real production adapter/process/file/resume probes reproduce this for all three invalidating error categories; a successful direction call preserves it. Guard temporary-session failure cleanup, preserve ordinary implementation invalidation, and test cold resume. Result and quota receipts survive. Local suites and canary pass; full disabled-path parity, packaged frontend and sustained real-model efficiency remain unqualified. No remote CI was consulted.

exact_goal_ref = dict(goal_ref) if isinstance(goal_ref, Mapping) else None

def store_session(observed_session_id: str) -> None:
if direction_only:

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] Preserve the persistent implementation-session binding on temporary direction failures. This added guard prevents storing the fresh direction session, but discard_session() and the invalidating-error branch below still use the original Todo lineage. After a main binding exists, model_requires_newer_codex, session_missing or output_schema_rejected from the ephemeral direction subprocess unlinks it; the subsequent planned resume raises before launch. Reproduced with the production adapter, an OS event fixture, actual session files and a subsequent production resume. Guard temporary-session cleanup as well, and retain ordinary implementation invalidation.

@xyx2002OvO
xyx2002OvO force-pushed the codex/first-delivery-freshness branch from cd8a5a7 to daf8744 Compare October 6, 2026 05:00

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent | gpt-6.1-sol | OpenAI | runtime_reported | xhigh

Exact reviewed head: daf87448be08450237b59fd7b4e9d57180e0f462; immutable pre-change merge base: 77d23b7c09d6c1ee816d0c380c9935fbc67149f2. Full-PR re-review; earlier findings are independently rechecked below.

动机

先完成工作、再判断下一步的长程 Agent,以及关闭或恢复普通 Todo 的操作者。 工作做完后要求变化,旧判断可能继续沿过期方向;这个提交先保存已验证结果,再读取当前要求,拒绝过期方向时保留结果,减少重复实施。 结果与同伴证据保留、过期方向拒绝和临时方向会话隔离得到实测支持;但未启用功能的普通完成及成功后的同身份重试,在损坏 checkpoint 下从成功变为失败。 本轮不验收完整 Goal、已安装 App、外部 Lark、真实模型效果或长期吞吐。 普通关闭态完成与回执恢复尚有回归;完整关闭态跨入口对照、该能力的打包前端旅程、真实模型采用及长期净收益仍未验收。

改动思路

这次把“已有工作结果”和“接下来往哪走”拆成同一个原始 Turn 的两个阶段。Turn 是一次有身份的执行与记账周期;结果先经过原生 Todo 存储的比较后写入,方向再读取当前相关事实并重新判断,最后 refresh/spend 使用同一身份。结果保存并不代表目标验收完成,也不授予新的写入权限。

状态判断复用 TypeScript 的 checkpoint、Todo terminal、first-delivery 状态机和 provider fence;Python 负责实际文件锁、来源采集及 Codex 进程。purpose/read_context_id 是调用者所判断的读操作身份,不能从“安装了能力”或同伴状态推断;frontier/version/status 从现有 authority 派生,commit-attempt/receipt 是已尝试效果的崩溃恢复见证。CLI/guard/MCP 和 managed 请求有真实生产调用链,没有新建平行 Goal 真相。

正向路径是在结果提交后再读取方向;相关任务新增使旧方向失效时,结果、依赖和同伴证据保留,拒绝过期追加且不重复扣额。此前实测的工程/研究两个 Goal、四类角色场景,只在逐文件确认相关 owner 字节未变后复用;本轮重跑当前头的 provider/managed/真实进程及恢复测试。新增的方向进程现在同时跳过主实施会话的保存和清理,成功与三类失败均保留原绑定,后续冷启动 resume 可以继续。

具体改动

完整差异为 62 文件、+2212/-190:38 个生产路径,20 个测试及浏览器 fixture,2 个文档,2 个生成/配置路径。包括 CLI 注册和 Todo/refresh/quota/status/run-once,typed checkpoint/terminal/recovery,Python host/IO、MCP/KunlunCode/Lark adapter,run-history 投影与 turn-contract 生成;三个浏览器文件修正 fixture 的 authority/readback 表达,不构成该能力已打包前端交互的证明。与上次审查的 cd8a 逐文件对照:当前 PR 的 57/62 路径字节相同,5 个变化集中于 Codex 清理、其测试和浏览器 fixture;仍重读完整差异及实际调用者,没有继承旧 verdict。

关键代码讲解

  1. checkpointBasisSnapshot(checkpoint_read_context.ts:44)从完整相关 canonical Todo、依赖、owner acceptance、Goal/agent vision 和来源身份生成读基准。无关全局更新时间不能替代相关输入;purpose 区分结果与方向,缺失或过期的覆盖内输入拒绝追加。
  2. terminalDeliveryBasisCheck(todo_delivery_context.ts:45)把新结果检查放进既有原生 terminal/CAS 边界;历史已提交回执应先返回,新的覆盖内提交再受读基准与 provider fence 约束。
  3. prepare_first_delivery(direction_review.py:21)由实际 run-once/managed producer 建立同一 Turn 的分阶段请求和 fresh direction,并沿既有 journal 恢复,避免另建执行/记账身份。
  4. delivery_result_context_input(checkpoint_context_io.py:201)为 terminal owner 捕获可选 enrollment 与来源;第 211 行在 capture 的 try 之外读取 enrollment,第 75 行解析损坏 JSON 时,普通未启用任务也会在原生历史回执查询前失败,这是当前 F1。
  5. run_codex_cli_host(codex_cli.py:668)的 store_session/discard_session 现在对 direction-only 都直接返回。相同真实进程/文件/随后 resume 脚本:旧 cd8a 三类错误删除主绑定,当前 daf 四个结果均保留并能继续;普通实施进程的错误失效规则仍由当前测试覆盖。

判断依据为已接受的 checkpoint 合同(固定基线),没有把本 PR 新增文字当独立验收标准:Vision Checkpoint 的结果/方向与 Goal 证明边界已实现;Read basis for checkpoint-only recovery 中普通首写保持原规则、同身份已提交效果可恢复的要求 not_met(F1);Semantic History Continuity 的按 agent 保留历史与坏来源显式 unknown 得到当前 status/observation 测试支持。roadmap 仍是局部阶段,不宣称闭合整个 R1。

对主干的风险

[P2] F1:可选 enrollment 读取提前阻断普通完成与历史回执恢复。 触发步骤:未启用 first-delivery、不提供 read token 的普通已准入 Turn;对应 effect-id 的旧 checkpoint supplement 文件损坏为 {;执行同身份 todo complete。CLI 仍传 settlement identity,Python provider wrapper 先调用 delivery_result_context_input → first_delivery_context_enrolled → JSON 解析,尚未到达既有原生 terminal 的回执优先恢复。File 和 SQLite 均 exit 1,错误是 Expecting property name enclosed in double quotes: line 1 column 2 (char 1)。首次完成时 Todo 仍 open;先健康完成再损坏文件重试时 Todo 已 done,但 CLI 同样失败。

相同独立公共 CLI 脚本,在固定 B 与 H 的真实一次性 File/SQLite authority 上各跑 none、有效旧 supplement、损坏匹配 receipt、健康提交后损坏再重试:基线 8/8 成功,当前 4/8 失败,另外 4 个正常/兼容场景成功。损坏场景 authority/run index 没有额外变化;这不是“结果被删除”或“双重扣费”的证据,问题是合法操作和已提交结果恢复被新读路径挡住,造成错误提示和人工介入。与此前无关 agent 的损坏文件 status 失败不是同一未修复分支:当前六个配对 status 场景全部成功,正常 action 保持,坏来源警告保留。

最小修复:在既有 terminal owner 中保留普通历史回执优先恢复,再处理可选 enrollment 的不可读来源;捕获错误必须有作用域,并保持真正已启用/状态不确定的追加 fail-closed。不能简单吞掉所有损坏 JSON 当“未启用”,也不能只搬 try 而破坏原请求/回执匹配。补 File/SQLite 关闭态首次完成及同身份 replay,保留已启用 unknown/stale/missing token 拒绝与无效果断言。

验证与失败归因

当前独立执行:133 项 checkpoint/provider/fault/MCP/observation/generator/host Python 测试通过;92 项 Codex/managed 测试通过,包含实际文件及独立解释器冷 resume;Python 保留 1 个 Pydantic lifespan unresolved-forward-reference 警告,未把它当失败或静默删除;30 项 TS 测试通过;独立实际 PostgreSQL 16.2 临时 server 的六套集成测试 450 项通过、0 skip,已停止 server。PG 结果只覆盖共享 authority 兼容性,不证明新的 PostgreSQL first-delivery enrollment。TS typecheck、turn-contract generator、changed Python Ruff、diff check、语义 advisory 后 full semantic、public/private scan 均通过。

原生 canary aggregate 仍红:5 个 direct checks 通过,19 个 selected checks 中 18 个通过;唯一失败是以较新 origin/main 9f6a87f 对照的小 status 输出预算:chars/UTF-8 +146、允许 145,compact +106、允许 104。另用相同 native 96 场景/oracle 固定本 PR 的 B/H,全部通过、小 status 尺寸 delta=0;再用固定 9f 对照 immutable B,复现同一个失败身份及细节,B/H 的该输出只差等长生成时间。归为 pre_existing_unrelated 的对照基线问题,保留原失败作为 merge diagnostic;没有放宽上限、缩 fixture 或把 aggregate 改成绿。它不掩盖 F1 的四个实际回归。

语义与 CI 对齐

复用并扩展已有 typed checkpoint/Todo/Turn 词汇,名称没有授予独立 peer 权限;没有引入领域子串分类器或产品/benchmark 专属强制语句。方向建议是 guidance,freshness/CAS 与 settlement 是机器约束。关闭态对照明确判为 not_isolated:完整 schema/prompt/input/迁移矩阵仍未全部证明,普通 terminal 已有具体反例。按当前 Goal capability 的 wait_for_ci=false 未查询、轮询或等待任何 GitHub CI;作者 CI 声明不算本轮独立验证。

我的整体评价

当前头 REQUEST_CHANGES。交付判断是 justified_increment:先保存结果再重判方向是有实际 caller、可回滚的局部机制;当前关闭态可靠性缺陷仍阻止交付。长程效果与用户体验的判断均为 regression:原本能完成及恢复的普通任务如今会在损坏可选文件上卡住,即便结果已保存也要求额外排查;旧 Codex 会话丢失已经独立修复,不继续当成当前 blocker。

机制范围基本成比例,沿既有 typed owner 扩展,新增状态有 producer 和持久恢复用途。兼容性的保留由原始 Turn/terminal/supplement 回执和独立 MCP 消费者支撑,不能只为减行数删除。相关未来改造应收敛到原生回执与 Python capture 的同一恢复边界;无需新建抽象或平行 authority。当前 full-shared-surface 关闭态证据、该能力打包前端操作、真实模型采用与长期净效率仍未 qualified。额外 fresh inference 可能减少返工,也增加调用与等待成本,不能从测试数或保存了 receipt 推断净收益。修复 F1 后需要重跑完整相关正负路径和既有回执恢复,重新核验当前 exact head。

English verdict: REQUEST_CHANGES - daf8744. Malformed optional checkpoint enrollment blocks feature-off ordinary completion and committed receipt replay on both File and SQLite (base8/8 succeeds; head4/8 fails). Previous Codex session loss is fixed; current native/provider tests pass, with the original canary budget failure preserved and independently attributed. No CI or merge authority claimed.

@mergify

mergify Bot commented Oct 6, 2026

Copy link
Copy Markdown

This pull request has merge conflicts with main and cannot be merged
until they are resolved. Please rebase or merge the base branch, @xyx2002OvO.

Choose the remote for the base repository, not an out-of-date fork.
For a fork clone, first inspect git remote -v; upstream must point
to https://github.com/loopx-project/loopx.git. If it is absent, add it
with git remote add upstream https://github.com/loopx-project/loopx.git.
Then run:

git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEAD

For a same-repository clone whose origin points to
https://github.com/loopx-project/loopx.git, use origin instead of
upstream for fetch/rebase. If you prefer merging the base, use
git merge <base-remote>/main and push normally.

Keep the DCO Signed-off-by trailer on every commit when you rebase.
https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/syncing-a-fork

@mergify mergify Bot added the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 6, 2026
@xyx2002OvO
xyx2002OvO force-pushed the codex/first-delivery-freshness branch from daf8744 to 8ad8dc9 Compare October 6, 2026 07:11
@mergify mergify Bot removed the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 6, 2026

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent | gpt-6-astra | OpenAI | runtime_reported | xhigh

Exact reviewed head: 8ad8dc9a564d57c0e877a33f2998f4f351629034; immutable PR merge base: 715c8774074871fa4b96c7efb6306436fc4b30be (下文 B);本轮检查的 main:42e55a809eb94f13443d303d76118735d4112182 (下文 M)。

REQUEST_CHANGES,主要依据本轮维护者明确的架构与产品交付要求。 发布前作者将 head 更新到 8ad8dc9;我重新核对了 rebase 与增量,旧 F1 的普通历史恢复修复已进入该 head,不把旧失败直接算到新代码。后续交付方向是:基础 freshness、结果保留和恢复进入默认产品路径;额外独立 Host 的方向复核作为可选 capability,经一个由 kernel 管理生命周期的 typed hook 接入。 后者是本轮明确的设计调整,不把先前声明为 opt-in 的实现追溯成“隐瞒默认行为”。以下给出具体契约、迁移边界和分阶段 PR 建议;它们是待实现设计,不是当前 head 已提供的能力。

动机

受影响的是执行长程任务的 Agent,以及从 CLI、App 或 Lark 查看和恢复交付的操作者。Agent 按旧验收完成工作后,用户或同伴更新要求;继续使用旧方向可能遗漏新工作,而把整个 Turn 重跑又会重复已完成的实施。目标是提交时核对结果依据、保留合法完成的结果,再根据当前事实判断方向,并能在中断后从原 Turn 继续。当前 PR 已有结果与方向分阶段的实际调用链,最新 head 也修复了已证明普通历史的可选 receipt 恢复;默认保护与独立复核仍捆绑在 opt-in 流程中。完整默认产品接入、可选 reviewer 的配置/恢复旅程和真实模型净收益尚未验收。本轮不要求完成整个 Goal、跨主机协作、PostgreSQL 新协议 enrollment 或完整共享意图治理。

保留这个问题的解决方向。完全不做,无法解决执行期间依据变化及结果提交后的方向失效;只改提示词,无法关闭检查与提交之间的并发窗口。但“依据未过期”和“语义判断足够好”必须分开:前者是确定性提交条件,后者需要 Agent 判断;独立 reviewer 只是其中一种增强实现。hash/token 不能证明模型真正理解了目标,增加一次模型调用也不能自动证明更少返工。

改动思路

A. 收敛为默认 kernel 保证、可选 capability 策略、Host 实现三个边界

机制 目标归属及默认性 必须保留的约束
结果绑定读取依据,最终写入时校验相关事实 现有 Todo terminal / Goal typed owner;在完成适配的产品路径默认生效 依据来自实际交付给执行者的读取;禁止在提交时给旧结果补造新 token
方向判断绑定当前依据 现有 checkpoint owner;遵守已有 checkpoint 触发规则 不增加“每次 heartbeat 都复核”的隐式义务;保留合法 in-flight exemption
成功结果保留、exact replay、原 Turn 恢复 现有 receipt / Turn journal / settlement owner 不因 reviewer 失败撤销结果、重做实施或创建新 Turn 绕过未决效果
额外独立 Host 审视当前方向 可选的、面向“交付方向复核”结果的 capability 默认关闭增强复核;配置选择它以后,其必要性和失败行为必须明确
临时会话、只读工具面、进程超时和清理 已有 Host/provider adapter 不存入或删除主实施 session;不能用 prompt 禁令冒充真实工具隔离
已保存/待判断/待结算/提交未知及可执行恢复动作 原有共享 projection 和产品交互 owner 从持久事实派生;不能维护第二套“成功/完成”真相

基础方向判断仍由当前 owning Agent 基于新依据作出。可复用它的会话/续接能力,但这不等于模型零调用,也不能复用执行前旧 Vision。增强 capability 改变的是方向判断的实现方式,不替代 freshness、receipt、quota 或 terminal owner。

三种流程的实际差别:

路径 实施后如何判断方向 侵入与增补
PR 前的既有流程 沿原有 Todo / checkpoint / settlement 规则提交;没有本次新增的结果与方向两次读绑定 原有回执/结算已存在,不能把此前描述为完全没有恢复或一致性保证
当前 PR 关闭开关 主执行路径仍走原逻辑,但共享 CLI、schema、读取与恢复代码有改动 false 证明没选择增强执行,不自动证明所有共享表面与基线相同
当前 PR 开启开关 结果依据校验 → 保留结果 → 新方向读取 → 独立 Host → checkpoint/结算 确定性保护和额外推理捆绑,新增等待、尝试预算和失败恢复分支
建议目标 默认路径具有依据校验/保留/恢复,当前 Agent 提交新判断;配置可把判断实现切换为独立 reviewer 默认强约束属于 owner;增强策略只接入一处 typed 判断端口

普通完成路径的目标结构:

flowchart TD
    A[读取并绑定结果依据] --> B[当前 Agent 实施与验证]
    B --> C[Kernel 在原生提交边界复核依据]
    C --> D[提交并保留结果回执]
    D --> E[读取当前方向依据]
    E --> F{已解析并绑定的判断方式}
    F -->|默认| G[当前 Agent 作出新方向判断]
    F -->|显式选择增强 capability| H[受限 Host 独立复核]
    G --> I[方向提案绑定本次读取身份]
    H --> I
    I --> J[Kernel 再校验依据并提交 checkpoint]
    J --> K[原 Turn 按已有规则结算或恢复]
Loading

图不覆盖特殊顺序:no_followup 仍保留原来的 refresh → spend → terminal;必要时延后 Todo terminal 写入。terminal_ready 只是提案,最终仍须当前全 Goal frontier、验收与权限检查。不得为了统一图形而把最后一个 Todo 提前关闭。

B. Capability placement:先比较已有 owner,不再发明一套“复核系统”

仓库已有三个相关但不同的边界:

  1. progress-review-sentinel:异步读取已捕获工作变化的 drift receipt,shadow 展示,assist 通过连续信号触发现有 replan obligation;它明确没有 Turn settlement/Goal acceptance 权限。
  2. todo_replan_cadence / #5699:已合并的完成 Todo / settled work Turn 复核节奏,决定何时提出既有方向复核义务。新能力不能再加一个独立计数器,或把同一交付计算两次。
  3. Goal Vision/checkpoint:当前 Agent 的方向判断、依据校验和提交归属。

本次独立 reviewer 的直接 caller outcome 是“为这一次交付 checkpoint 提供基于当前依据的方向判断”。建议先按独立的 direction-review capability 设计,复用既有配置、provider admission 和 Host 端口;这个名字是设计建议,注册前仍应做 catalog 冲突/所有权核对。它和 progress-review 的时点、失败语义、返回对象不同,不能直接把原有 assist 升级为阻塞 settlement。若作者选择扩展已有 capability,必须提供明确的新 operation/version,并证明旧 shadow/assist 契约完全保持。

核心协议/注册信息可以随 LoopX 分发,运行时增强行为仍默认关闭;已有 Codex/generic Host adapter 提供实现。独立安装/版本管理的 reviewer provider 才进入 packages/<provider> 或独立 distribution。不要把模型 prompt、provider-specific session 分支放进 typed kernel,也不要为了可安装而再造一层 capability。按照 extensions 的既有职责表,capability 提出策略结果,kernel 接受/拒绝并持有持久状态权威。

C. 新 hook 的定位:checkpoint decision,而非旁路 post-writeback

建议将窄端口称为 checkpoint_decision phase / Goal direction decision hook。名称暂定,最终复用或扩展已有语义登记;不要建立通用 before_every_write hook、任意命令回调、hook DAG 或新的 workflow engine。v0 只有一个实际调用点:既有交付流程需要当前方向判断、即将提交该 checkpoint 的边界。

对比 现有 post_writeback 本次建议的 checkpoint_decision
目的 已提交后提出后续 intent 为既有必要 checkpoint 提供判断提案
来源 已提交主回执的有限投影 当前 decision basis + 原 Turn 身份 + 结果引用
是否属于主流程必要条件 否;failure_policy=isolate 必要性由既有 checkpoint 规则及显式选定策略决定
失败 不改变主回执和匹配 quota spend 资格 该必要判断保持 pending;沿原 Turn 恢复
返回 typed follow-up intent typed direction proposal / typed evaluation failure
持久提交者 后续另行准入的 executor 原 checkpoint/Todo/settlement owner

现有 Post-Writeback RFC §5 明确禁止 optional hook 成为第五个 primary settlement step;hook 失败不得阻止对应 quota 结算。不能改它的 isolate 定义来承接本 PR。新增 phase 必须单独登记注册/输入/结果/恢复语义,复用现有 admission/typed validation 结构;共享机制不代表共享失败策略。

“可选”是选择增强判断方式时的属性;一旦本次 checkpoint 已明确选择它作为必要判断实现,provider 失败不能被静默降级成成功。反过来,provider 也不能通过输出 required=true 给自己创设新义务。必要性始终来自 kernel 已有规则与 caller 的有效配置。

D. 建议的最小 typed 契约

以下是语义草图,不要求照抄新的字段或重复保存现有 identity;实现时优先引用已有类型和 journal 字段。

type DirectionDecisionInput = {
  // Existing Goal/instance, Agent, Todo-or-obligation, Turn/effect identity.
  identity: ExistingSettlementIdentity;
  invocation: ExistingJournalInvocationRef;
  // Captured from the admitted effective configuration, not provider output.
  strategyBinding: {
    capabilityId: string;
    providerId: string;
    policyRevision: string;
  };
  readContext: ExistingCheckpointReadContext;
  result: CommittedResultRef | ValidatedPendingTerminalResultRef;
};

type DirectionDecisionOutput =
  | {
      kind: "proposal";
      readContextId: string;
      // Reuse registered direction decisions and existing Vision validation.
      proposal: ExistingDirectionProposal;
    }
  | {
      kind: "unavailable" | "failed";
      reason: RegisteredBoundedReason;
    };

这里的 Existing* 是已有 owning contract 的引用占位符,不是建议新增同名类型。v0 只允许一个已选定 provider、一个当前有效 invocation。不要顺手实现多 reviewer 投票、动态选择 DAG 或任意 veto chain。

  • 输入完整性:basis 由 kernel 从权威源组装,覆盖选中 Todo、依赖闭包、验收、共享要求、当前 Agent Vision、source/store identity、必要 lease,以及判断 scope 对应的完整 frontier。provider 不能自己提交“我认为相关”的缩水 Todo 列表。agent_lane 与 goal 使用已有 typed 选择规则;no-followup 用全 Goal scope。
  • 私密边界:供模型判断的 basis 可能包含私有 Goal 内容,不能直接套用 post-writeback 的 public-safe 投影并宣称信息齐全。只能向已授权 provider 交付声明范围内的数据;公开状态/日志只保留必要摘要、opaque identity 和错误码。缺乏必要读取权限应报告 unavailable,不得用残缺视图证明“没有剩余工作”。
  • 输出校验:精确匹配身份和 read_context_id,拒绝额外写入指令及非法字段。复用当前 continue / revalidate_result / terminal_ready 含义和 Vision/unchanged-reason 的互斥校验;最终合法性仍由既有 owner 判定。无需为了 hook 再复制一套 Todo/Goal 状态机。
  • 作者与执行者身份:独立 Host 是原 owning Agent 已准入 checkpoint 请求的计算实现,不自动成为新 peer/manager,也没有替原 Agent 取得权限。journal 记录 caller 与 evaluator 来源;提交仍走原 Agent 的授权请求。若未来是真正另一个 Agent 给意见,应走现有 request/adoption 契约,不能把该回复直接冒充 owning Agent 的 Vision。
  • 权限:proposal 不写 Todo、不修改 acceptance、不延长 lease、不扣 quota、不改变调度、不确认 Goal complete。kernel 在提交点重新检查当前权限和来源。已授权配置也不能覆盖后来的 stop/revocation。

E. 生命周期、并发与恢复要求

时点/事件 owner 应执行的规则
选择策略 从既有机器默认/Goal override resolver 获取有效策略,在当前 Turn/checkpoint journal 中绑定;安装、doctor-ready、schema 存在都不等于启用
首次调用前 验证 scope、provider readiness、权限、成本/尝试预算;持久记录本次 invocation,再发出 Host 请求
运行模型 在 provider/source 写锁之外;使用已批准的读取/工具面。保留原实施 session
收到提案 校验 schema、绑定、当前 invocation 和响应 digest;旧 attempt 的迟到回复不能覆盖新 attempt
提交 checkpoint 前 在既有真实 source/provider fence 内重读当前依据并校验,然后提交;不能靠 hook 开始时的检查消除 TOCTOU
依据变更 旧提案失效;读取新的依据并重新判断。保留原结果,不给旧判断换 token;本 Turn 自身结果写入通过独立 post-result 读取体现
回包丢失/进程重启 先读原 invocation、checkpoint 和 settlement 回执;已提交效果返回历史结果,未决效果先查明,不能盲目新建 Turn
provider 失败/超时/非法输出 保留已提交结果,给出带恢复 owner 的 typed pending/failure;不自动宣称审核通过,也不凭一条错误文本制造用户审批 gate
revalidate_result 保留既有结果证据,交给现有 repair/replan/验收路径处理差异;不直接重开 Todo、不删除结果、不把拒绝当作恢复已经完成
terminal_ready 仍执行现有全局 frontier、验收、授权、refresh→spend→terminal 检查;新任务或变化的验收可以拒绝终结
策略中途关闭/升级 新 checkpoint 使用新配置;进行中的已绑定调用不因重读配置自动换 provider 或消失。授权撤销立即阻止新调用/提交;取消或改用基础路径必须有显式、留痕的恢复转换和新的判断

必须区分两种 replay:已提交效果的历史恢复优先于当前 freshness 检查;尚未提交的新决定必须检查当前依据。旧 receipt 不等于当前工作仍有权限,权限已撤销时不能发起新效果,但已经发生的历史事实仍应可读回。

必要的持久数据只是不可重新推导的绑定、已交付的读身份、调用尝试和已观察结果。result_committed / direction_pending / settled 等展示从已有回执派生。不要再加一份手工同步的 stage DB、第二套 quota 或新队列作为主事实。

重试总数和超时应沿原 Turn 持久计数,重启不能重置。可以以 PR 当前“最多两次方向尝试”为首个有界值,但应放在明确的 owning policy/已有预算边界,而非 scattered constants。模型请求的实际 usage 单独记录;Turn settlement 只扣一次不代表额外推理免费,也无法保证远端模型在回包丢失时只计费一次。预算耗尽的出口应明确到“恢复哪个步骤、由谁处理、如何继续”,不是无限循环 recommended_action。

F. 产品入口必须和默认化一起交付

普通用户不应复制两个 token 或手工区分 result/direction phase。CLI/MCP 可以保留专家级显式操作,managed host 和产品入口应沿已绑定 Turn 自动传递 identity,并在确实需要新判断时将完整依据交付给 Agent。

复用既有 Capability Center 的机器/Goal 配置 resolver 和编辑器;不要再做 first_delivery 与 reviewer-enabled 两个含义重叠的开关。增强能力需要显示用途、有效配置来源、额外成本/预算、provider 不可用、启用/关闭和持久读回。核心 freshness 不应成为一个默认不勾选的“更安全”选项。

交付读回至少区分“结果已保存,待方向判断”“方向已确认,待结算”“提交结果未知,正在/需要核对”。恢复动作由现有 typed action/host owner 执行,只恢复剩余阶段。App 必须验证实际点击后的持久结果及 reload;Lark 复用对应 audience 的 action/projection,若这一阶段没有可操作入口就明确保留未验收范围。静态目录行、复制命令按钮和共用 next_action 文本不构成完整旅程。

不支持的 source-session、provider、operation-tools 或 compound repair/replan 组合,必须在适当的准入点清楚说明范围。不能到结果提交后才发现方向 adapter 根本不可用,也不能静默降级后继续显示“已保护”。旧持久记录可按旧契约恢复,但不能追认它们已经通过新 freshness 校验。

具体改动

新 head 已 rebase 到 B;range-diff 显示前 12 个 PR commit 等价,浏览器 fixture 随 main 调整,新增 terminal 恢复与文档两个 commit。当前 B→H 完整差异为 62 文件、+2354/-187。生产路径覆盖 CLI Todo/refresh/run-once/status/quota、typed checkpoint/terminal/provider fence、managed executor/Host、MCP/KunlunCode guard、Lark/共享 readback;其余是聚焦测试、两个浏览器 fixture、两份文档和生成/语义登记。浏览器 fixture 修复不等于新增 capability 已有前端交互。

关键代码讲解

  1. checkpointBasisSnapshot:purpose 区分结果和方向,方向使用完整相关 frontier;未知 Todo 字段默认进入依据,只有明确展示字段排除。这部分应收敛到默认读取/提交 owner。不要为了降低 stale 数量改为文本关键词“相关性”判断。
  2. terminalDeliveryBasisCheck:现有 terminal/CAS 检查当前来源与 provider head,no-followup 额外验证 indexed direction 及 terminal versions。这是 kernel 责任,不能移到锁外 hook 后直接信任结果。
  3. prepare_first_delivery / review_first_delivery:目前把提交结果、额外 Host、最多两次尝试、方向提案及 terminal 条件编排在同一路径。建议拆职责而不是复制流程:kernel/既有 TS owner 决定阶段与合法转换,capability 决定复核策略,Python 保留 Host IO。
  4. delivery_result_context_input:新 head 将可选 enrollment 的读取错误传入 native owner,保留普通请求指纹,先恢复已提交 receipt;未提交操作再验证原 ordinary writeback 是否足以证明损坏来源可忽略。这是 F1 修复的关键边界。
  5. evaluateFirstDelivery:已有纯校验/投影 seam,可用于收口提案契约;“响应合法”只能证明结构、身份与字段约束,不等于认可目标完成。run_codex_cli_host 已同时隔离临时调用的 store/discard,搬迁时保留其回归覆盖。

其他接入也不能在重构时漏掉:MCP v2 分段 complete/vision 调用及 v0/v1 消费者;CLI 参数互斥;managed 原 plan 的恢复;status/quota 的来源不足和 pause 优先级;File/SQLite 的真实 fence;旧 supplement 与 commit-attempt 崩溃见证;generator 的 LF/CRLF 一致性。这些都有独立的兼容含义,不能把所有 purpose 合并成一个不带语义的字符串来减少行数。

独立规范基线为 docs/reference/protocols/goal-vision-replan-contract-v0.md,spec_revision=715c8774074871fa4b96c7efb6306436fc4b30be。没有用 PR 自己新增的 first-delivery 文档作为独立正确性 oracle。

原规范 criterion 当前 head 判断 后续要求
Vision Checkpoint 分阶段实现可见,当前 suite 覆盖正向/拒绝路径;默认产品 adoption 尚未交付 保留 material closeout 与 in-flight 的现有区分,不靠新增 reviewer 无条件扩大触发频率
Read basis for checkpoint-only recovery F1 的已提交 receipt/已证明普通 writeback 恢复已修复;完整关闭态矩阵仍待补齐 保持 receipt-first;新操作依然校验依据,unknown 不能当 absent
Semantic History Continuity 有派生进展与坏来源观察覆盖;长期规模成本未验证 保留按 Agent/原 Turn 的语义读回,不把 bounded display 的缺席当 canonical absence

新 phase 还需对齐 Post-Writeback RFC 的隔离边界及 TypeScript migration RFC 的单一 decision owner。契约增量与实际调用点放进同一阶段;不要求先造一份无调用者的通用 hook 框架。

Roadmap 的对应关系:R1 是提交/失败/恢复的局部增量;R5 是相关 typed transaction 与持久权威边界;R4 的共享依据治理只得到部分支持,basis digest 不是完整意图修订协议。capability/provider 生命周期属于 S8。此工作不自动完成 R2 多 Agent 协作、R3 接收/返回或真实模型收益验收。

对主干的风险

F1 历史问题与本次修复:不再把旧失败当成新 head 的缺陷

旧 daf87448 的普通 todo complete 会在 Python enrollment JSON 解析处失败,尚未到 native terminal 的历史 receipt 恢复。本轮先独立复现:File/SQLite × 无 receipt、可解析旧 supplement、损坏匹配 receipt、健康提交后损坏再重放;旧 head 4 passed / 4 failed,旧不可变基线 8/8 通过。已有结果没有被删除,这不是重复扣额证据。原 finding

新 8ad8dc9 保留普通请求指纹,让已提交 terminal receipt 优先返回;对于尚未提交的操作,只在既有 ordinary writeback 及 indexed artifacts 证明普通历史、且没有 result enrollment receipt 时忽略损坏的共享 supplement。没有足够历史、已有结果 enrollment、损坏/不一致 writeback 仍返回 checkpoint_commit_unknown。

这个区别应保留:我们测试脚本知道“没启用”,不等于持久状态足以证明“没启用”。对不可证明的 enrollment fail closed,不能仅因旧版接受就称为新 bug;它应有明确的受影响 scope、可操作恢复和兼容说明。本轮另外用真实 ordinary writeback 作为独立前置事实,重跑 File/SQLite 的首次完成与冷 replay,并运行作者新增的反向保护测试;结果列在下面。请保留这些修复,不简单吞掉所有 malformed JSON,也不要为了拆 capability 再把 provider 读取放回历史 receipt 之前。

D1 — 当前维护者要求的架构调整:解除基础保护与独立推理的捆绑

这是一项交付方向要求,不是声称现有独立推理必然判断错误。当前 first_delivery_freshness 一路携带到 executor、Host、MCP、refresh、Todo 和 readback,选择基础保护同时选择额外 Host 与恢复分支。直接默认打开会把新的等待、provider 可用性和额外失败源推给普通任务;继续永久全量 opt-in 又不能交付已确定的默认保护目标。

请按 A–F 收口:确定性保护留在 owner,方向判断提供一个窄接口,默认 owning Agent、可选 capability provider。保留身份/fence/receipt 的必要复杂度;削减的是重复决策源、让调用者手工协调的协议分支和没有证据支撑的无条件额外推理。是否可合并以实际交付与验证判断,不以 62 文件或行数作为拒绝依据。

验收矩阵:区分当前证据与重构后必须新增的证据

场景 重构后的预期,不能只检查 happy path
增强 capability 未配置/禁用/未安装 基础保护和既有正常流程成立;零 reviewer 调用;已证明未 enrollment 的普通完成不因坏的可选 receipt 受阻,不能把不确定历史当成已证明关闭
已安装但未启用,或只启用同 Goal 的另一 lane 不自动扩大 scope;自己的 request/schema、prompt、读回、quota 与错误优先级按声明保持
新建 Todo/新 Turn 按有效配置明确决定是否覆盖;不从旧 receipt 或“目录存在”推断 enrollment
当前 Agent 基础路径 确实收到当前依据并作出新决定;没有自动给旧 Vision 刷新 token
增强能力启用且成功 原 Host 实施一次、受限 reviewer 一次、原 owner 提交;正确回执和 usage 读回
选中 Todo/依赖/验收/共享要求变化 原决定拒绝;相关当前事实完整;拒绝后能重新判断并推进
独立 peer 更新、展示排序/分页/超出显示上限的工作 合法独立工作不被误阻断,完整相关 frontier 不被遗漏;不是只比较 decision code
reviewer 返回前又发生变化 提交点仍拒绝 stale;证明 final fence 有效
旧 token、跨 Agent/Turn token、迟到响应、重复/冲突响应 错误请求拒绝,不能替换当前 attempt;同身份相同效果按历史回执恢复
reviewer 超时、非零退出、非法 schema、读权限不足 保留结果和实施 session,准确 failure/pending,预算有界,原 Turn 可恢复
在结果提交/方向提交/quota/terminal 间崩溃 原 receipt 决定恢复位置;不重复实施、不重复效果、不通过新 Turn 绕过 unknown
no-followup 后新增工作 最终 terminal 拒绝;保留合法结果,不把 terminal_ready 当 Goal 完成证明
provider 卸载、配置升级/撤销、owner stop 进行中状态可解释;立即尊重撤销,迟到结果不能获得新写权;无静默 fallback
App 操作后 reload / 配置 CAS 冲突 / provider unavailable 有真实 backend 持久读回和授权的恢复动作;无第二份 UI 状态源
原 MCP v0/v1、旧 supplement、旧 Turn receipt、无关 provider 有明确迁移和兼容测试;不追认旧记录已经通过新协议
真实模型对照 基础 Agent 与增强 reviewer 在相同任务/预算下比较返工、错误阻塞、人工介入、调用数、延迟、成本;不以 receipt/test 数量宣称收益

本轮验证记录

以下均为本轮独立执行,除单独标记的远端观察外,针对新 head 8ad8dc9:

检查 结果与范围
Python 聚焦套件 173 passed,281.69 s;checkpoint read context / provider fence / first-delivery faults / managed / MCP / observation / terminal / Codex CLI,共 8 个文件,pytest -n 4
独立 ordinary-completion 反例 File/SQLite × 无额外 receipt、旧 supplement、损坏匹配 receipt、提交后损坏并冷 replay;均先通过真实 CLI 写入 ordinary writeback,head 8/8 passed。不可变基线比较结果见下;未修改生产代码
TypeScript checkpoint_read_context.test.ts + content_digest_single_owner.test.ts,29 passed / 0 skipped
静态/生成检查 npm run typecheck:control-plane、uv run --extra test python scripts/generate_turn_contract.py --check、B→H git diff --check 均通过
语义 advisory uv run --extra test python scripts/generate_semantic_inventory.py --changed-from 715c8774074871fa4b96c7efb6306436fc4b30be,37 changed sources / 0 supported candidates;这不是无新语义证明
完整语义检查 uv run --extra test loopx canary smoke-suite --script semantic-vocabulary-drift-smoke.py,通过,57.847 s;不是全仓库 full-public canary
当前 head 的远端 CI 观察 观察时 Summary 成功,build、adapter-contract、real PostgreSQL、DCO 等 7 个 job 仍 queued。pending 本身不是本 review 的 REQUEST_CHANGES 依据;merge readiness 单独保留

Python 复现命令:

uv run --extra test python -m pytest -q -n 4 \
  tests/control_plane/test_checkpoint_read_context.py \
  tests/control_plane/test_checkpoint_provider_fence.py \
  tests/control_plane/test_first_delivery_faults.py \
  tests/control_plane/test_first_delivery_managed.py \
  tests/control_plane/test_first_delivery_mcp.py \
  tests/control_plane/test_first_delivery_observation.py \
  tests/control_plane/test_first_delivery_terminal.py \
  tests/test_loopx_turn_codex_cli.py
node --no-warnings --experimental-sqlite --experimental-strip-types --test \
  tests/control_plane_ts/checkpoint_read_context.test.ts \
  tests/control_plane_ts/content_digest_single_owner.test.ts

全部运行使用隔离的合成 Goal/runtime;未对活跃 Goal 做故障注入。旧 head 的 149 项通过及独立 4/8 失败属于历史证据,不累加到新 head 的通过数。最初独立测试的 fixture 导入路径、旧 TS 检查缺少新 worktree 依赖,以及一次 TS 测试目录输入错误均已修正;这些是本轮测试准备问题,不归因于 PR。新 head 的成功运行没有放宽断言或语义预算。

同一个带 ordinary writeback 前置事实的独立 8 用例,在当前 PR 不可变 merge base 715c8774074871fa4b96c7efb6306436fc4b30be 上也 8/8 passed(35.73 s),head 为 8/8 passed(43.67 s);使用各自源树加载 CLI/模块,fixture 语义相同。更早的 77d23b7 基线也通过,但不代替本次 B→H 比较。这只证明这 8 个普通路径场景,不证明全部 feature-off 隔离。

作者另报 343 项 Linux 测试、真实 PostgreSQL 检查及部分 packaged-browser 验证;它们属于作者证据,本轮没有独立重跑。作者也保留了 packaged aggregate 的 team-evidence-return-smoke 超时并报告固定基线同样失败;本轮不把这一未独立归因的历史/环境问题当成本 PR 已证实引入的 bug,也不声称整个 packaged suite 已通过。

新 hook/capability 尚未实现,因此上表不是通过清单;尤其默认 App/Lark 恢复、真实工具权限隔离、长期模型效果和全共享表面的关闭态矩阵仍是未验证。需要 PostgreSQL 兼容覆盖的共享 authority 变更必须保持其实际服务器检查;本轮不把 remote green 或旧 review 的测试数冒充本地独立执行,也不据此宣布新增 provider 被支持。

语义与 CI 对齐

现 head 扩展既有 checkpoint/Todo/Turn 的 purpose、stage 和响应词汇;不是新 actor 生命周期。新 phase 属于需要显式登记的共享协议增量;提案决策尽量复用现有枚举,capability 配置只表达调用者意图,不能成为第二套 Goal 状态。开发 advisory 与 full semantic 检查需要针对最终 diff 执行;仅有字符串扫描不能证明完整语义覆盖。

kernel 的 freshness、required checkpoint、scope、budget 和提交条件是机器义务,不能叫作可忽略 guidance。reviewer 的语义意见是 proposal;但当它被选为必要 checkpoint 的实现,未取得有效提案会阻止该阶段推进,不能把整个路径宣称为旁路建议。域中立要求适用于所有 Goal,避免把“代码交付/benchmark 分数”写进通用错误与判断枚举。F1 的已证明普通历史恢复已经修复;关闭态整体仍为 not_yet_proven,没有完成的 schema/prompt/accepted-input/persistence 配对证据保持 unverified,不能从几个通过的反例推广为完整隔离。

我的整体评价

当前实现包含值得保留的 justified_increment:真实 caller 已能绑定结果/方向依据并恢复原 Turn。当前 long_horizon=not_yet_proven、user_experience=not_yet_proven:F1 修复排除了已确认的普通历史恢复故障,但完整隔离和默认产品可操作恢复尚未 qualification;新的 capability/hook 分层也还没有实现。独立 reviewer 的净收益为 not yet proven,不能用多一层审视预设结果一定更好。

本轮 future-facing pass 的结论是:收口既有 terminal/checkpoint/Turn owner 与策略接口,保留真实历史消费者所需的兼容;不做全库 TS 重写,不造通用 workflow 框架。Python 继续承担必要 IO,相关语义编排回到既有 TS owner。原 MCP 版本、旧持久 receipt 的兼容应按独立升级边界保留;内部 co-deployed helper 的重叠分支则应能合并就合并。

建议分成三个有实际结果的 PR 阶段

建议把 #5677 调整为第一阶段,后两阶段引用它的具体交付;也可以用清晰标明 supersedes 的 successor 替换,但不要让两个分支并行维护相同 authority。以下是交付边界,不是要求机械按文件拆,也不要求一次性建立三个空 PR。

阶段 独立交付结果 必要范围 验收与剩余边界
PR 1:结果/方向依据与原 Turn 恢复收敛 现有受支持 File/SQLite 路径能保护结果、拒绝 stale,并可靠恢复;保留 F1 修复 既有 typed result/checkpoint owner、receipt-first、相关 fence/unknown、必要 CLI/MCP 适配及精简文档;从核心编排拆出独立 Host 选择,但不单独发布空插件框架 真实首次提交、相关/无关并发、旧回执、崩溃、关闭态反例。若尚未接默认 host,明确这是协议/后端前置阶段,不能称默认产品能力完成;默认接入 owner 在 PR 2
PR 2:基础保护进入默认产品路径 用户从已有入口正常交付,不需要 first-delivery 开关或手动搬 token;当前 Agent 基于新依据判断并能恢复 实际 managed/MCP/CLI 消费者、必要当前 Agent 续接、原配置/typed action/readback,以及 packaged frontend 的失败/恢复旅程;Lark 对应适用入口或明确未资格范围 无增强 reviewer 时走真实默认全过程,状态变化时重新判断,重启只恢复剩余阶段;验证配置/调用兼容、stop、no-followup;披露新默认和支持组合,更新旧默认测试与文档
PR 3:可选方向复核 capability + checkpoint decision hook 用户能在现有能力设置里选择独立 reviewer、看见有效范围/成本/不可用状态、关闭并恢复未完成判断 窄 phase 的 typed 注册/结果/生命周期 + 一个真实 Host provider + 现有配置编辑器/操作入口 + 端到端恢复,作为同一完整纵向包 默认关闭且与 PR 2 基础路径配对;成功/超时/非法输出/迟到/撤销/工具权限/主 session 保留;实际原 Turn readback;不以测试 provider 冒充 live-model 效果

PR 2 依赖 PR 1;PR 3 依赖基础判断/提交边界和实际产品接入。默认产品保护不应等待独立 reviewer 的模型效果研究,增强 capability 也不能只留下 CLI flag,把操作/恢复推到一个无限期 frontend follow-up。

每阶段至少有一个实际 caller 和失败后继续推进的证据。不要单独拆“只有 schema”“只有 serializer”“只有 hook registry”三个小 PR,反而让 reviewer 重建完整逻辑。若 PR 1 与 PR 2 的必要改动很紧密,应合并为一个可审查的完整基础交付包,而不是为了数量强拆。

只有出现真实第二个 provider、独立分发需求或已有实验结果需要代码变化时,才安排后续 provider/效果改进 PR。受控对照可以更新原 capability 的 qualification/checkpoint;不必为了“阶段 4”再造任务或外部插件 SDK。作者当前 PR 描述明确报告模型研究未通过 irrelevant-update gate;本轮没有独立重跑该研究,也不建议修改门槛来证明默认化。

回滚也按边界处理:PR 3 的增强策略关闭不应删除未决调用、历史 evidence 或基础 freshness;PR 2 回滚要检查旧二进制能否理解进行中的新 Turn;PR 1 已写入的新 receipt 格式需要兼容读回/迁移计划。任何回滚都不能偷偷消除尚未确定的提交,也不能重扣 quota。

下一轮请同时给出:最终 owner/capability/provider placement、调用链与失败语义、真实默认/增强两条旅程、F1 修复的反向保护及完整关闭态证据、兼容矩阵和阶段边界。先将可用的基础交付闭合,再用可选 capability 验证独立复核的价值。当前 head 保持 REQUEST_CHANGES,不涉及合并或忽略其他 review。

English verdict: REQUEST_CHANGES - 8ad8dc9. The updated head repairs receipt-first recovery for proven ordinary history; that old defect is not retained as a current finding. Changes are still requested for the maintainer-selected architecture/product boundary and incomplete full-surface isolation evidence. Separate default kernel freshness/recovery from an optional direction-review capability. Introduce only a narrowly scoped, kernel-supervised checkpoint-decision hook; preserve the existing non-blocking post-writeback contract, authority boundaries, original-Turn recovery and product readback. Deliver the core contract, default product adoption, and optional reviewer as cohesive stages with explicit compatibility and validation. The new architecture is a requested design direction, not a claim of shipped behavior or measured model benefit.

@huangruiteng

Copy link
Copy Markdown
Collaborator

我 review 了一下,给了上面的建议

@huangruiteng

Copy link
Copy Markdown
Collaborator

其中【现有 Post-Writeback RFC §5 明确禁止 optional hook 成为第五个 primary settlement step;hook 失败不得阻止对应 quota 结算。不能改它的 isolate 定义来承接本 PR。新增 phase 必须单独登记注册/输入/结果/恢复语义,复用现有 admission/typed validation 结构;共享机制不代表共享失败策略。】 这段酌情可参考或者不参考,maybe 复用和拓展 post writeback 也是一种选择,需要你评估一下

@mergify

mergify Bot commented Oct 6, 2026

Copy link
Copy Markdown

This pull request has merge conflicts with main and cannot be merged
until they are resolved. Please rebase or merge the base branch, @xyx2002OvO.

Choose the remote for the base repository, not an out-of-date fork.
For a fork clone, first inspect git remote -v; upstream must point
to https://github.com/loopx-project/loopx.git. If it is absent, add it
with git remote add upstream https://github.com/loopx-project/loopx.git.
Then run:

git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEAD

For a same-repository clone whose origin points to
https://github.com/loopx-project/loopx.git, use origin instead of
upstream for fetch/rebase. If you prefer merging the base, use
git merge <base-remote>/main and push normally.

Keep the DCO Signed-off-by trailer on every commit when you rebase.
https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/syncing-a-fork

@mergify mergify Bot added the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 6, 2026
Signed-off-by: Tartar <xiaoyx67@mail2.sysu.edu.cn>
Signed-off-by: Tartar <xiaoyx67@mail2.sysu.edu.cn>
Signed-off-by: Tartar <xiaoyx67@mail2.sysu.edu.cn>
Signed-off-by: Tartar <xiaoyx67@mail2.sysu.edu.cn>
Signed-off-by: Tartar <xiaoyx67@mail2.sysu.edu.cn>
Signed-off-by: Tartar <xiaoyx67@mail2.sysu.edu.cn>
Signed-off-by: Tartar <xiaoyx67@mail2.sysu.edu.cn>
Signed-off-by: Tartar <xiaoyx67@mail2.sysu.edu.cn>
Signed-off-by: Tartar <xiaoyx67@mail2.sysu.edu.cn>
Signed-off-by: Tartar <xiaoyx67@mail2.sysu.edu.cn>
Signed-off-by: Tartar <xiaoyx67@mail2.sysu.edu.cn>
Signed-off-by: Tartar <xiaoyx67@mail2.sysu.edu.cn>
Signed-off-by: Tartar <xiaoyx67@mail2.sysu.edu.cn>
…rors

Signed-off-by: Tartar <xiaoyx67@mail2.sysu.edu.cn>
Signed-off-by: Tartar <xiaoyx67@mail2.sysu.edu.cn>
Signed-off-by: Tartar <xiaoyx67@mail2.sysu.edu.cn>
Signed-off-by: Tartar <xiaoyx67@mail2.sysu.edu.cn>
Signed-off-by: Tartar <xiaoyx67@mail2.sysu.edu.cn>
@xyx2002OvO
xyx2002OvO force-pushed the codex/first-delivery-freshness branch from 8ad8dc9 to 8979f57 Compare October 6, 2026 10:21
@xyx2002OvO xyx2002OvO changed the title feat(control-plane): protect staged first delivery against stale decisions feat(control-plane): protect caller-authored first delivery on CLI/MCP Oct 6, 2026
@xyx2002OvO

Copy link
Copy Markdown
Contributor Author

PR1 scope adjustment is pushed at 8979f570df27a6bf03bfb3e044fdcbcb4f143483, rebased onto main 8251ec80e0c327d28d13a1fd64e3f343a2aa3c0e.

This is the permitted CLI/MCP protocol/backend prerequisite. Automatic independent direction Host execution, managed first-delivery enrollment, its attempt budget and terminal-only fields are removed from the final diff. Ordinary managed implementation, session behavior and its tests match main. Default owning-Agent continuation/product recovery remain the next stage; independent reviewer registration/input/result/recovery remain a separate stage. Post-Writeback §5 isolation and primary settlement steps are unchanged.

Caller-authored direction now recovers stale post-result context by explicit reread and a new decision on the original Turn, retaining one result and one spend. The observer uses the existing checkpoint's explicit not_required exemption, and does not claim a retained result before result commit. Protected no-followup is outside PR1: MCP rejects before effects, native admission rejects before a new commit after receipt recovery; the ordinary CLI settlement prerequisite and historical ordinary closeout remain intact. No post-spend terminal trap is advertised as supported.

Validation:

  • Isolated Python run: 107 passed / 57 failed / 2 skipped. All protocol/checkpoint/provider/MCP tests passed. The 57 remaining failures are confined to unchanged test_loopx_turn_codex_cli.py; a representative mixed-structured-code failure reproduces on frozen main 43cdce787. These failures are not claimed passed.
  • Final head: 6 passed for real File/SQLite MCP stale-direction recovery and unsupported protected terminal zero-effect cases; 33 passed for focused TypeScript checkpoint/Host/projection checks. SQLite concurrency fence rerun: 4 passed.
  • Digest single-owner checks: 17 passed, after a Windows file-URL fixture fix. Semantic/contract Python checks: 154 passed. Typecheck, generated bindings/Turn contract, registry I/O inventory, semantic advisory and diff whitespace checks passed.
  • Real PostgreSQL compatibility: isolated disposable server/database, 330 passed / 4 runtime-permission failures / 1 skipped initially; targeted rerun 5 passed, including the original four failures. The temporary container was removed. This does not add PostgreSQL first-delivery support.
  • Broad Windows TypeScript suite was 3972 passed / 93 failed / 52 skipped. Six representative failures reproduced on frozen main; other families include temporary-runtime permissions, Windows process signals and a source-changing-during-measurement failure. The seven digest path failures were subsequently fixed and independently tested. This is not an all-green suite or a blanket attribution of every failure to the environment; remote CI still needs readback.

Local study artifacts/raw logs/private planning stay excluded. This author update requests maintainer re-review of the narrower stage; it is not self-approval or a merge claim.

中文:本批收口为显式 CLI/MCP 基础保护与原 Turn 恢复。默认 Agent 续接、已提交结果修复和 protected terminal 改向由后续阶段闭合;独立 reviewer 另行登记完整契约。真实 File/SQLite 核心路径、并发 fence 与零写入拒绝已验证;普通 managed 代码与 main 一致,但其 Windows Codex fixture 剩余失败及广泛套件限制如上保留,请按新 head 复审。

@mergify mergify Bot removed the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 6, 2026

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh

Reviewed exact head: 8979f570df27a6bf03bfb3e044fdcbcb4f143483. 重新核验当前完整 PR:51 files, +1886/-159。与上次已评审 head 比较时分开各自的 merge base;rebase 带入的上游改动没有被算作本 PR 新功能。

动机

在任务提交前后需要判断结果和下一步的人,可能读完旧状态后才提交:这期间另一个 Agent 已修改验收、依赖或工作集合,旧判断便不再适用。原有 checkpoint 恢复主要解决已写回 Turn 缺少方向记录的问题,不能据此证明首次提交也用了当前依据。这个 PR1 为显式选择保护的 CLI/MCP 调用方补齐有界路径:结果提交前核对所读依据,提交后另读方向,发生相关变化时只重做尚未成立的判断。可观察改善是保留成功结果和原 Turn,恢复方向时不重复任务或记账。本阶段交付后端前置路径;默认 Agent 自动续接、已提交结果修复、protected terminal 出口和完整产品旅程仍待后续阶段,不能据此宣布 Goal 完成或模型效果提高。

改动思路

沿用 Todo、checkpoint、Turn 和 provider CAS(比较当前版本后提交)的现有 owner,把结果依据与方向依据分开。关键规则由 TypeScript 判断,Python 捕获文件、提供 CLI/MCP 适配,模型判断和任务验证留在短锁之外。没有新增独立 reviewer 身份、模型调用、方向尝试预算或通用回滚权。

这次按上一轮 maintainer 接受的 PR1/PR2/PR3 分期重新审查,而不是要求 PR1 承担已明确后移的默认 Agent/UI 旅程。此前 managed enrollment、自动独立方向 Host、attempt-budget 及 terminal-specific 路径已从当前 PR 删除;原 Codex executor、普通 managed host 和其测试与当前 base 的 blob 相同,旧新增 reviewer 模块也在 base/head 均不存在。移除的是实际执行路径,并非仅改文案。

具体改动

spec_ref: docs/reference/protocols/goal-vision-replan-contract-v0.md; spec_revision: 8251ec80e0c327d28d13a1fd64e3f343a2aa3c0e(修改前规范)。独立分期依据是上轮 review #5425122971。逐项映射:Ownership Boundary 保留 Agent 自己判断方向及原有提交权限;Vision Checkpoint 保留 required/satisfied/not_required 区分,首轮 opt-in 要有当前方向决定;Read basis for checkpoint-only recovery 继续按原身份、当前依据和原回执恢复,既有 supplement 路径不被新 opt-in 替代;Acceptance 保留 agent-scoped checkpoint、status/quota 消费投影及无私有材料的验证。本次新增协议段是显式 first-delivery 扩展,不能反过来当作修改前规范的独立证明。PR1 的 CLI/MCP 前置阶段已交付,PR2 默认 owning-Agent 续接/产品采用、PR3 独立 reviewer 契约继续 deferred。

关键代码讲解

生产链路是 read_checkpoint_context → terminalDeliveryBasisCheck/原 Todo owner → resolveCheckpointReadContext → commitCheckpoint → 原 refresh/spend。结果提交在原回执恢复后检查相关事实、源文件及真实 provider head;无关 revision 重试不产生新判断,相关变化要求重新核验候选。方向提交验证完整 frontier 成员、用户义务、依赖、验收和 source identity。JSON/Markdown 有内容而索引未成立时保持 unknown;同 Agent 新 Todo/Turn 不能绕过未协调的原提交。MCP v2 三次调用分别读取结果、提交结果并读取方向、提交方向并结算;每一步提供新的正确性依据,原有 v0/v1 调用没有额外必填参数。

负向路径已独立运行:相关方向变化拒绝原 token,再读依据后恢复,同一原结果保留且只 spend 一次;protected no-follow-up 在新副作用前拒绝,普通旧 closeout 仍可用。历史观察损坏只给作用域内诊断,不能让其他 Agent 的 next-action 被覆盖;受保护原操作未知仍拒绝恢复写入。普通精确完成回执/可证明普通 writeback 可先恢复,不能把“JSON 读坏”猜作未开启保护。这也覆盖此前 F1 已修复的普通路径,未重新提出上一轮已撤回的无效损坏-fixture推断。

另以真实 CLI 和两个本地 provider 读取 1004 个 canonical Todos:agent_lane 精确保留 3 个本 Agent 项,goal scope 保留全部 1004 个,包括显示上限之外的最后一项;peer 工作没有被误算为本 Agent 义务。

本地验证:Python 176 passed(1 条既有 Pydantic 注解 warning);TS 聚焦 88 passed、15 个需 PG 的分支跳过,随后在隔离真实 PostgreSQL 16.2 上相关六套集成 450 passed、0 skipped。后者证明共享 owner 没有回归,不把新保护扩展为 PG 支持。不可变 base/head 上独立实际 CLI/MCP File/SQLite ordinary 调用、successor、cold replay、单次 spend 和未创建 protected history 的归一化观测完全相同。类型检查、Turn 生成一致性、286-site registry I/O manifest、全树语义 smoke、diff/public-boundary 检查均通过。没有查或等待 CI;没有改 active Goal/账本做故障测试;没有真实模型、付费调用或 packaged 默认 UI 验收。

对主干的风险

最强反例是已提交结果后 frontier 改变或方向写回中断:如果只看成功的 Todo,下一轮会错过当前义务或重复提交。本轮实际相关依据变化、torn append、丢失响应及精确 replay 均保留原身份和成功 artifacts,未增加第二次 spend;普通损坏 supplement 的可证明恢复与保护历史未知的拒绝分别测试。真实 File/SQLite 默认关闭对照相同,PG 只验证既有共享 owner,不声称新保护支持 PG。此阶段更多读取的历史成本尚未做规模测量,后续默认采用不能把该限制隐去。

语义与 CI 对齐

新 purpose、scope 和观察 stage 属于已有 Todo/checkpoint/Turn typed owner;read/status 是证据,实际拒绝是机器义务,不能说成建议。完整语义与生成检查已运行;CI 未查询或等待,APPROVE 不从 CI 颜色或作者声明推导。

我的整体评价

APPROVE,结论限于 justified_increment 的 PR1。长期正确性与恢复体验在这个边界内是正向:相关状态变化不再沿用旧判断,成功提交不会因方向重试再次执行或 debit;默认旧路径的额外操作为零。选保护时增加显式读取和决定步骤,这是正确性成本,不能将它宣传成已测得整体更快。历史 receipt 仍需完整扫描,尚未量化多 Goal、大量历史的持续读取成本;完整 Agent/App/Lark 体验和模型净效率继续未验收。此前宽泛多 Host 设计已经收缩到一个可独立验证、撤回的本地前置路径;继续沿原 owner 做后续产品采用,避免另建 reviewer 或结算决策源。未来整理已应用于同一恢复/依据 owner,当前没有必须再拆出的 speculative abstraction。该 approval 不自动解除旧 head 的 CHANGES_REQUESTED,也不授权合并或关闭业务 Goal。

English verdict: APPROVE this exact head as a justified, explicit local File/SQLite CLI/MCP prerequisite. Freshness, original-result recovery and single settlement are verified; default Agent adoption, protected terminal redirection, frontend journey, live-model utility and long-run cost remain outside this delivered stage.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants