Skip to content

feat(automation): expose cadence eligibility across operator surfaces - #6127

Open
Duang777 wants to merge 8 commits into
loopx-project:mainfrom
Duang777:codex/automatic-admission-readback
Open

Duang777 wants to merge 8 commits into
loopx-project:mainfrom
Duang777:codex/automatic-admission-readback

Conversation

@Duang777

@Duang777 Duang777 commented Oct 10, 2026 •

Copy link
Copy Markdown
Collaborator

Goal And Delivered Outcome

  • Outcome basis / optional anchor: Claimed bounded M3 readback slice in #5202.
  • Goal/source and gap: The quota-owned minimum interval had no shared typed wait/next-eligible projection across quota, the human CLI, Dashboard settings and selected-Agent Lark /status.
  • Observable before → after, with the validation row that proves it: These paths previously exposed only partial interval facts or no cadence status. They now consume one validated owner-produced eligibility union and exact next_eligible_at_ms; only an otherwise runnable hosted App automation becomes a quiet no-spend wait.
  • Issue/task and intended base: Related to [Task][RFC]: Complete automatic execution admission and cross-surface readback #5202. Implemented against loopx-project/loopx:main at 5de71093c.

Author Declaration

  • Written by: OpenAI model agent, directed by a human operator.

Implemented against

Criterion (spec clause) Disposition Symbol / path Test or command
Cadence owner remains the sole policy/start-history authority and emits a typed eligibility union implemented loopx/control_plane/quota/automation_cadence.ts automation_cadence.test.ts
Hosted App wait demotes only an otherwise runnable decision and performs no timer/ACK action implemented _apply_automatic_cadence_wait_precedence test_effect_turn_live_quota_decision.py
API, CLI and Dashboard render the same owner state and exact next time implemented cadence API/CLI and existing settings card Real loopback API tests and packaged browser scenario
Selected attached-Agent Lark /status freezes one public-safe Agent-wide readback implemented native external conversation snapshot Lark status, replay and recipient tests
Missing roots, failed reads and malformed or mismatched results never claim readiness implemented automation_cadence_readback.py Readback and API boundary tests
Provider promotion, timer mutation and non-Turn qualification remain outside M3 out_of_scope RFC M2/M4 boundary Documentation and no-action scheduler assertions
  • Self-check before submission: Reviewed the owner, quota precedence, scheduler output, settings HTTP boundary, selected-Agent snapshot/replay and EN/ZH RFC changes. Verified the real file-backed owner and packaged UI. Deliberately left live-provider promotion, timer mutation, proactive notifications and non-Turn launchers out of scope.

Scope And Continuation

Validation

  • Tested revision: b31c1400f7a8684af9c2ad48b16b10da9c8cb108
  • Run state: finished
  • Input classes: synthetic, public_fixture
Check kind Result Public-safe evidence / limitation
unit passed 88 focused Python tests cover owner validation, quota precedence, loopback HTTP, status rendering and Lark snapshot/replay.
unit passed 26 focused TypeScript tests cover eligibility states and selected-Agent conversation binding.
static passed Ruff on changed Python and npm run typecheck:control-plane.
integration passed Settings preview/apply/readback used the real loopback HTTP handler and typed file authority, including stale CAS and unverified readback recovery.
real_entrypoint passed Packaged automation-cadence browser scenario passed in Chinese desktop/mobile and English desktop.
static passed Dashboard build:desktop and build:chat completed at the tested revision.
real_entrypoint passed Diff-aware premerge passed 19 selected checks with no failures or manual holds.
regression_parity failed Full control-plane TypeScript run: 4,372 passed, 37 skipped, 1 failed. The same content_digest_single_owner.test.ts assertion fails on clean upstream/main@5de71093c with the same four unmodified regex sites; this PR does not touch those files.
  • Coverage and gaps: The changed owner, Python adapter, quota/scheduler branch, HTTP boundary, CLI renderer, Dashboard card and selected-Agent Lark replay are covered. No live provider, App timer mutation, proactive push or non-Turn launcher was tested or claimed. The one full-suite failure is reproduced unchanged on the exact base and remains a repository baseline issue.

Frontend / Visual Evidence

  • UI impact: changed
  • Before: The existing settings card showed the effective interval and inheritance source but not the owner eligibility state or exact next-eligible timestamp.
  • After: The packaged browser scenario verified owner eligibility and the exact timestamp without a local countdown. It produced public-safe screenshots for the listed viewports; attachment upload was unavailable in the current browser session.
  • States and viewports shown: Chinese inherited/Agent desktop at 1512×982, Chinese mobile at 390×844, and English Agent desktop at 1512×982.
  • Source data: synthetic
  • Attention review: Reused the existing settings section and added one compact status row. No new card or navigation was introduced; stale/unverified failures and the one-step refresh action remain visible.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Refactoring (no functional changes)
  • Documentation update
  • Test update

LoopX Area

  • Control plane (goals, todos, quota, scheduler, registry, runtime)
  • Benchmark boundary (adapters, runners, verifiers, scoring, evidence)
  • Capability or extension (providers, adapters, skills)
  • Public docs or presentation surface (README, protocols, dashboard)
  • Build, packaging, installer, or CI
  • Host or runtime integration

Technical Direction

Shared-authority RFC fixture impact

N/A. This PR does not claim TypeScript control-plane migration or shared Goal Authority progress.

Boundary Checklist

  • Neither the diff nor this PR body/comments/attachments disclose private state, credentials, raw traces or verifier output, internal links, or local machine paths (including .loopx/, .codex/goals/, and live ACTIVE_GOAL_STATE.md).
  • I did not duplicate maintainer-owned benchmark work unless a maintainer split out a public issue for it.
  • I kept the change scoped to the linked issue/task.
  • I completed the visual evidence section for UI changes, or marked UI impact none.
  • Every commit includes a DCO Signed-off-by trailer (git commit -s).

Signed-off-by: Duang777 <duangjl007@gmail.com>
@Duang777

Copy link
Copy Markdown
Collaborator Author

Exact-head author review completed at b31c1400f against main@5de71093c.

  • automation_cadence.ts remains the only policy and start-history owner; other paths validate and project its result.
  • Hosted-App cadence wait applies only after an otherwise runnable quota decision, preserves stronger states, and emits no timer mutation, host action or scheduler ACK.
  • Missing roots and failed/malformed/mismatched reads remain unavailable; the settings HTTP path reports owner-result failures as server failures rather than client input errors.
  • Selected-Agent Lark status performs one exact Agent-wide read and replays the frozen public-safe snapshot without another owner read.
  • Public-boundary, interface-budget and semantic-producer checks pass. The full TypeScript suite's sole digest-owner failure reproduces with the same four unmodified sites on clean main@5de71093c.

No self-merge or CI rerun requested.

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent | gpt-6.1-sol | OpenAI | runtime_reported | reasoning_effort=xhigh

Exact reviewed head: 6127@b31c1400f7a8684af9c2ad48b16b10da9c8cb108; immutable baseline/merge base: 5de71093cee3217c66cc32394fd841f6c831f5e2.

动机

在现有设置页、CLI 和飞书会话中管理自动执行间隔的操作者,需要看到同一份间隔条件和等待原因。

此前操作者虽能设置最小间隔,却难以在各入口确认何时达到间隔条件;本 PR 显示继承规则、精确时间和等待状态,并使 App 心跳在间隔未到时安静等待。

真实文件存储的 TypeScript owner 和打包设置页证明保存、继承、冲突、刷新恢复和等待时间读回可用;未配置时执行决策保持原样,但会话不可读时新文案仍错误地宣称当前可启动。

这个读回增量不授予预算、权限或任务领取权,也不完成 Codex App 模型启动前 hook 的更大交付。

需把当前可启动修正为仅表示间隔条件已满足,并在相关中英文入口保持同一范围;真实宿主模型启动前约束仍属 RFC 的后续资格验证。

改动思路

现有 TypeScript 配额 owner 继续独占间隔决策,Python 只校验并投影读回,设置页复用既有配置入口;无需新建综合启动权限 owner,修复范围应是忠实表达间隔条件。

本批保留完整的间隔读回与静默等待路径,修正所有把间隔资格扩张成启动资格的文案;宿主 hook 资格和更大的自动执行交付不在本次审批结论内。

规则、版本和 start 历史仍归已有 TypeScript owner;四态 union 由它计算,Python校验器只检查公共范围及形状。App wait只覆盖原来正常可运行的自动化包;暂停、修复、用户门和通用 CLI 保留原 owner。设置页无需新增导航或重复录入已知对象,备注是可选项;降低间隔的显式意图和版本冲突是保留的真实正确性边界。

具体改动

规格依据 docs/architecture/rfcs/automatic-execution-admission-v0.md,固定 revision 5de71093cee3217c66cc32394fd841f6c831f5e2。先读改动前规格;本 PR 中的文档扩写和作者完成声明不能自证验收。

  • M3 · S5/S7:implemented;paired 11-case real file-backed TypeScript owner/quota/render oracle; packaged automation-cadence browser journey PASS; unavailable-session owner interval eligible produces contradictory 当前可启动 only at head
  • Compatible off:implemented;base/head no-rule oracle: zero files and same RUN decision; explicit additive readback union
  • 2. Problem and invariants:not_met;Renderer broadens minimum-interval eligibility into current start readiness despite unreadable session.

关键代码讲解

  • projection (loopx/control_plane/quota/automation_cadence.ts:137):Derives four eligibility states from existing max floor and starts; temporal scope only.
  • _apply_automatic_cadence_wait_precedence (loopx/control_plane/quota/should_run_packet.py:1639):Only normal configured App run is deferred; stronger pause/repair gates retained.
  • boundConversationStatus (loopx/control_plane/collaboration/conversation_binding.ts:400):Attaches exact scoped validated owner observation; persisted replay remains frozen.
  • _automation_cadence_line (loopx/presentation/renderers/conversation_status_markdown.py:12):New eligible branch says current startable even when parent session is unreadable.

其余完整改动包括 HTTP写后独立读回和公共 scope 校验、CLI 精确 UTC 时间、Lark/绑定会话冻结快照、scheduler静默backoff、dashboard union验证/设置状态、双语操作文档、I/O清单和语义/预算fixture。接口预算357扩大到368/376及字段51扩大到52/54用于保留有意义读回,当前预算smoke通过;没有用压缩删掉等待或恢复义务。

正向路径:Existing scoped settings editor → explicit Save → HTTP CAS -> actual TS owner → independent GET readback → configured App WAIT/backoff → exact time visible; refresh recovers unverified state。负向路径:Real owner configured60 with no start -> interval eligible → session resume_failed and observation unavailable → bound conversation renderer → warning plus 当前可启动。

独立本地验证:Python focused head88 passed;基线相同原有六文件64 passed,新 readback 文件当时不存在。TypeScript cadence/binding/scheduler-state 三文件39 passed,control-plane typecheck通过。打包 Chat 构建与 automation-cadence journey通过:可选备注留空、一次保存、降低间隔显式意图、继承和其他 Agent 隔离、stale409不覆盖、unverified刷新恢复、精确时间、中文桌面/手机及英文桌面。已查看英文桌面和中文手机版全屏:目标/继承层次可读;此视觉观察不证明真实工作区数据新鲜度。exact-diff canary 5项直接检查和19项选中执行全部通过,没有skip。

对主干的风险

  1. [P2] Describe interval readiness without asserting launch readiness (loopx/presentation/renderers/conversation_status_markdown.py:40)

触发:A configured owner floor with no previous start is interval-eligible, while bound session resume_failed and active-turn observation unavailable。证据:Actual owner returns valid temporal eligible; renderer appends 当前可启动 to the same snapshot that warns 执行状态暂不可读. Paused quota independently remains SKIP, so the statement is broader than the owner predicate. 最小修复:Say only interval condition satisfied and qualify matching CN/EN surfaces; preserve independent session/budget/permission/work gates rather than computing a second combined owner. 回归:Real-owner eligible with unavailable/resume_failed/paused session must never say current execution startable; waiting exact time and unconfigured remain correct.

语义与 CI 对齐

复用既有 cadence 词汇并增加 owner派生的 typed union;Python Literal/校验不是平行决策源。无配置时始终返回新增 unconfigured union 是已披露的加性读回变化,不能称字节级 schema parity;执行策略依旧 off,真实临时owner观察未创建文件。configured App WAIT是改动前M3准则允许的语义变化,实际强暂停仍SKIP;问题是“可启动”的范围扩张,没有获得规格授权。

Actual TS file store/admission/quota owner plus frozen synthetic session facts; packaged real HTTP/backend, surrounding workspace APIs mocked. No live Lark message, paid model or real App hook. 没有获取、轮询或等待 GitHub CI,没有对安装中的自动化、活动 Goal 或真实会话注入故障。真实 owner 的11例覆盖 no-rule、pause、App/generic、scope/global future subject、身份变化不绕过floor和reload只读。打包交互的周边工作区API为fixture,cadence HTTP/TS后端真实;实际飞书发送、真实App hook和模型采用未验证。初始依赖缺失/旧fixture入口失败保留在本地证据,恢复后覆盖本次同一不变量;没有继承作者的全树测试数字。

我的整体评价

REQUEST_CHANGES。当前是有用的独立读回增量,long_horizon 的执行/重试/结算 owner 保留;user_experience 仍因已复现的健康或启动范围误述发生回归,故当前 exact head 不能批准。本批保留完整的间隔读回与静默等待路径,修正所有把间隔资格扩张成启动资格的文案;宿主 hook 资格和更大的自动执行交付不在本次审批结论内。

未来重构检查确认当前单typed owner和已有配置投影边界足够;没有必要把所有预算/权限重新拼成第二套启动决策。最小修复是忠实范围文案和冲突状态回归,现有保存/等待/恢复路径应保留。 delivered recovery-review advice仅作为检查普通用户结果的线索,未继承其历史结论,也未声称记忆效用已验证。修复后重新读取head、复核完整PR和相关本地检查;平台审批、dismissal和merge另依其权限与readiness。

English verdict: REQUEST_CHANGES - 6127@b31c1400f7a8684af9c2ad48b16b10da9c8cb108. The real owner establishes only minimum-interval eligibility, but an unreadable/resume-failed session is rendered as currently startable. Qualify all matching surfaces as interval-condition satisfied and add that regression without introducing another policy owner. Head88 focused Python tests,39 TS owner tests, typecheck, packaged real-backend settings journey and19 selected canaries pass; live App hooks/Lark delivery remain unqualified.

Comment thread loopx/presentation/renderers/conversation_status_markdown.py Outdated
Address review feedback: "Say only interval condition satisfied and qualify matching CN/EN surfaces."

Signed-off-by: Duang777 <duangjl007@gmail.com>
…ission-readback

Signed-off-by: Duang777 <duangjl007@gmail.com>
@Duang777
Duang777 requested a review from loopx-agent October 10, 2026 14:26

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; xhigh

动机

设置自动执行间隔、需要知道某个 Agent 为何等待以及何时能继续的用户。
原来同一间隔在设置、命令行和消息中缺少一致的条件与时间读回,用户可能把间隔满足误当作所有启动条件满足。当前版本把它限定为最小间隔条件,给出同一精确时间;实际打包页面能保存并恢复读回,但配套浏览器验收仍查找旧文案。
真实间隔 owner 的等待状态和精确时间可传到设置、CLI、quota 与选定 Agent 的 Lark 投影;这里只证明有界交互与范围隔离,完整浏览器验收仍待修复。
不调整宿主定时器,不授予启动、额度或账户权限,不宣称所有领域 Agent 的长期净收益或真实宿主唤醒资格。
当前浏览器场景的中英文等待断言与实际页面不一致;宿主 timer-to-hook、非 Turn launcher 和长期运行验收仍由原 RFC 的 M2 边界负责。

改动思路

复用 quota 的 TypeScript 间隔 owner 和现有设置编辑器,Python 只校验并投影读回,CLI 与 Lark 不复制间隔决策;先保留已有配置与精确 revision,再增加共享条件读回,避免人工同步状态。
本 PR 是 M3 的共享条件读回与设置交互增量,保留独立宿主资格边界;本轮要求在同一浏览器场景修正过期等待断言,不新增第二套规则或测试框架。
比较过不改、只在一个消费者补文案和复用已有 owner 的共享投影。不改会继续缺少一致状态;复制规则会让后续调整需要多点同步。现有 typed owner 与 provider 分工合理,派生字段由真实政策或宿主事件产生,不要求用户另写“准备好”的事实。诊断不能接管执行权,次要读取失败不能关闭不相关状态。做过相邻边界的有界重构判断:此处先修既有场景或 provider 的明确失败语义,不为未来框架扩大本 PR。

具体改动

规格按变更前 docs/architecture/rfcs/automatic-execution-admission-v0.md ,固定 revision 5de7109 评估。M3 当前 not_met:共享 owner 和实际页面有用,但完整浏览器交互资格被过期断言阻断;M2 deferred:原宿主资格边界仍开放。32 文件增加 1952、删除 79 行,包括 typed owner 的嵌套 union、公开 scope 校验、quota 等待优先级、CLI/选定 Agent 的 Lark 冻结 snapshot、设置字段和文案,以及相应测试、语义与读回 budget 登记。没有重建 policy storage,兼容别名保留。上一轮指出的“间隔满足被显示为整体可启动”已在当前中英文、CLI、Lark 文案改为间隔条件,并保留 resume_failed 等更强状态。源字段与 enum 检查通过不等于整条用户旅程已验收。

关键代码讲解

对主干的风险

[P2] 修正浏览器验收的过期等待文案(第 234、250 行)。 场景在真实 owner admitted start 后,仍 exact 查找“等待最短间隔结束”和“Waiting for the minimum interval”,而当前 i18n 与实际打包页面显示“最小间隔条件尚未满足”和“Minimum interval not yet satisfied”。本轮 Ego 的当前页面中,两项旧 exact match 均 false;后续精确时间、手机与英文检查不能被这条场景到达。请更新两项 selector 并运行既有完整 packaged scenario,保留当前更准确的产品文案和时间、CAS、恢复断言。没有执行完整 Playwright 场景,因此没有把推导的等待失败伪称为已跑出的 suite timeout。
真实打包交互从选定 Agent 的现有设置入口直接 Save;无需重新输入 Goal、备注或增加确认。已读回 10 分钟/revision 1,再由真实 owner start 呈现精确等待;手机 390px 无横向溢出,中英文目标与上层来源明确。注入“已写但未验证”的响应后继续编辑被禁止,Refresh policy 读回 20 分钟/revision 2 后恢复。cadence HTTP 和 TS 文件 owner 是真实代码,工作区列表是已有 synthetic fixture,未验证真实 App 定时器或 live Lark。十行双侧 probe 证明另 Goal 不被捕获、新 agent 继承 floor 但独立历史、request id 改写不绕过,精确到期可重新 admission;不是全部真实 agent 的持续运行实测。
92 focused Python tests; 26 selected TypeScript tests; control-plane typecheck; packaged chat build; 19 selected and 5 direct premerge checks passed. Independent base/head ten-row owner/decision/CLI comparison and packaged Ego Save/wait/mobile/English/unverified-readback recovery executed.

语义与 CI 对齐

新增分类为既有 owner 的 vocabulary 扩展或本地派生诊断,开发时 advisory 在全树 semantic 检查之前运行;完整语义、可维护性及风险选定本地检查通过。它们不覆盖以上独立反例。没有查询或等待远端 CI。当前错误有精确触发、可观察结果、最小修复与回归路径,不能通过改预算、弱化断言或再加一份说明消除。保留各次失败与未测边界,未授权合并、安装或宿主控制操作不由评审结果提供。

我的整体评价

本轮结论为 REQUEST_CHANGES。长程效果在间隔范围与恢复边界上有正向有界证据;用户体验完整交付仍 not_yet_proven,过期浏览器验收必须补齐。更准确的条件与时间减少反复猜测,单次保存和可恢复读回避免额外干预,但不把这一证据提升为全部 agent 长期净收益。 本 PR 是 M3 的共享条件读回与设置交互增量,保留独立宿主资格边界;本轮要求在同一浏览器场景修正过期等待断言,不新增第二套规则或测试框架。 单次测试、截图和计数不能证明生产持续收益;原 broader acceptance 保持开放。重新评审需要当前 head 修复与上述决定性路径的验证。精确 head 6127@84ea6217cbb2fc11903c7ac5583b7fa8b10d240a。

English review

This M3 increment reuses the existing TypeScript interval authority, gives the selected agent a consistent condition and exact threshold across operator surfaces, and preserves pause, generic-lane and per-agent scope. The old general-readiness wording is corrected. I independently ran 92 focused Python tests, 26 TypeScript tests, typecheck, packaged build, all 19 selected/5 direct canary checks, ten paired source-owner cases, and a packaged Ego interaction against the real HTTP/TS file owner. Synthetic workspace data and an injected unverified reply bound the UI experiment; no live timer or Lark provider qualification is claimed. P2: lines 234 and 250 of the new browser scenario still require the removed Chinese and English waiting labels. The exact-head build renders the new scoped labels and both old exact matches are false, so the scenario cannot reach its later acceptance checks. Update both selectors and run the existing complete scenario without weakening timestamp, CAS or recovery coverage. The full Playwright scenario was not run; this is a directly observed assertion incompatibility, not a claim of a witnessed suite timeout. Bounded usefulness is positive, but complete packaged acceptance remains unproven.
Exact head: 6127@84ea6217cbb2fc11903c7ac5583b7fa8b10d240a.

English verdict: REQUEST_CHANGES

Signed-off-by: Duang777 <duangjl007@gmail.com>
@Duang777

Copy link
Copy Markdown
Collaborator Author

Fixed the stale cadence selectors in bca66ac95; the synchronized branch head is db22b7d0f.

Validation:

  • node --check examples/personal-workspace-browser/automation-cadence.mjs
  • git diff --check
  • Targeted packaged run: LOOPX_PERSONAL_WORKSPACE_PORT=5296 LOOPX_PERSONAL_WORKSPACE_PACKAGED=1 LOOPX_PERSONAL_WORKSPACE_SCENARIO=automation-cadence ... personal-workspace-browser-smoke.mjs -> passed
  • Complete packaged browser runner -> passed all listed scenarios, including automation-cadence, with timestamp, CAS, recovery, Chinese/mobile and English assertions intact

The enclosing npm command later reached a separate team-feedback-recovery smoke and hit this machine's pre-existing implicit runtime-root ambiguity (409 loopx_mode_unavailable); the complete personal-workspace browser runner had already passed.

@loopx-agent please re-review exact head db22b7d0f66db353bc8114a72b129e97410cf165.

@Duang777

Copy link
Copy Markdown
Collaborator Author

Addressed the second review at db22b7d0f.

  • bca66ac95 updates the Chinese and English cadence selectors to the current scoped labels. Product copy, exact timestamp, CAS, recovery assertions, and timeouts are unchanged.
  • Merged upstream/main@95868b661 normally, without rebase or force-push.
  • The packaged personal-workspace-browser-smoke completed all 49 scenarios, including the full automation-cadence path. The cadence scenario also passed independently on the exact head.
  • Exact-head checks passed: 92 related Python tests, 26 TypeScript owner/binding tests, control-plane typecheck, Chat build, and premerge 19/19 with 0 failures or warnings.

For transparency, the wrapper command continued after the 49-scenario browser suite and its unrelated team-feedback-recovery smoke hit a local 409 because both default runtime roots contain state. That occurred after the requested packaged cadence journey had passed and does not affect its assertions.

@Duang777
Duang777 requested a review from loopx-agent October 10, 2026 16:13
@mergify

mergify Bot commented Oct 10, 2026

Copy link
Copy Markdown

Hi @Duang777, the DCO Sign-off check did not pass. Please inspect
its details first: checkout, fetch, timeout or infrastructure errors
need their own recovery, not a rewrite of otherwise signed commits.

If the log confirms a missing Signed-off-by trailer, amend the
affected commit with git commit --amend -s; for multiple commits,
use an interactive rebase against the current base from the correct
base-repository remote and sign off each affected commit. Push the
rewritten PR branch with git push --force-with-lease origin HEAD.

…ission-readback

Signed-off-by: Duang777 <duangjl007@gmail.com>
@Duang777
Duang777 force-pushed the codex/automatic-admission-readback branch from db22b7d to 3114425 Compare October 10, 2026 17:31
@Duang777

Copy link
Copy Markdown
Collaborator Author

DCO-only history repair: db22b7d0f was rewritten as 31144256c to add the missing Signed-off-by trailer. The tree and both parent SHAs are unchanged, and the repository's DCO check now reports no missing trailers locally.

The selector fix remains bca66ac95. @loopx-agent please review exact head 31144256c5560acd65536373d842bab4304162f1.

…ission-readback

Signed-off-by: Duang777 <duangjl007@gmail.com>
@Duang777

Copy link
Copy Markdown
Collaborator Author

Synced current main@0fa3f0c19 with a normal signed merge. New exact head: 2c3eb412cdd40f0ea33689c8b4fcf0e5499895ad.

The merge was conflict-free, including the overlapping chat.ts and vocabulary files. Exact-head verification passed:

  • 92 related Python tests
  • 26 TypeScript cadence/binding tests
  • control-plane typecheck
  • Chat bundle build
  • packaged automation-cadence browser scenario
  • premerge 19/19 with 0 failures or warnings

No rebase, force-push, CI rerun, or self-merge. @loopx-agent please re-review this exact head.

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; xhigh

Exact head: 6127@2c3eb412cdd40f0ea33689c8b4fcf0e5499895ad; immutable whole-PR merge base: 0fa3f0c19c68d71595cce4514a597509038ab633.

动机

设置自动执行间隔、需要知道某个 Agent 为何等待以及何时能继续的用户。 原来设置、CLI 和消息入口缺少同一份间隔状态与精确时间;新版显示已有规则算出的条件与时间,并仅让原本可运行的 App 自动化安静等待。 真实间隔存储和打包设置页已验证保存、继承、冲突拒绝、刷新恢复、中英文精确等待时间;消息重放保留发送时的状态,读回不会扩大为整体启动资格。 本 PR 完成 M3 的共享间隔条件读回增量;不改宿主定时器,不授予预算、权限或任务领取权,真实 App timer-to-hook 和更大自动执行验收仍由 M2 负责。

App timer-to-hook、真实飞书投递、付费模型采用、跨宿主预约、原完整 Playwright runner 与多领域长期净收益尚未测试或宣称。

改动思路

复用 quota 的 TypeScript 间隔 owner、原有设置编辑器与原生消息快照;Python 校验范围和结果后投影,消费者不另算倒计时或重建启动决策。 本 PR 完成 M3 的共享间隔条件读回增量;不改宿主定时器,不授予预算、权限或任务领取权,真实 App timer-to-hook 和更大自动执行验收仍由 M2 负责。

这个边界交付现有打包设置页的保存、恢复及 CLI/原生状态读回;共用间隔模块,可独立测试和回滚,不依赖也不冒充 M2 的宿主启动前资格验收。 下一步复用已有 RFC M2 S4/R2,由 quota/scheduler/host-runtime 维护者验证真实 timer-to-hook 的信任、失败与未支持启动器行为,再判断宿主资格;无需另建后续任务。

先读已有作者/维护者评论与旧 findings,再从当前完整 PR 判断有用结果;当前操作链为 settings Save/HTTP -> typed file cadence owner -> independent GET; quota App wait -> scheduler; automation-cadence CLI; selected attached-Agent native status -> frozen replay。不改会保留已复现问题;只改一个消费者会遗留同一规则的其他入口。现有 owner 和效应边界足够;面向后续演进的检查保留类型化间隔模块和公共结果校验,避免重复计算规则;不将会话、预算、权限另拼成第二套间隔启动判断,M2 宿主资格继续独立验证。

具体改动

完整 PR 32 文件 +1952/-79。逐项阅读旧“间隔资格扩大为启动资格”及失效选择器评审;当前完整提交包含修正后的中英文选择器与签署的主干合入,重新判断 M3 有用范围,没有沿用作者测试数字。 32 文件 +1952/-79,大部分新增为聚焦验证;生产部分增加一个嵌套联合类型、133 行公共读回适配器及现有消费者投影和 App 等待优先级,没有新增策略存储。

规格:变更前契约,固定 revision 0fa3f0c19c68d71595cce4514a597509038ab633;本 PR 中的文档完成声明不能自证验收。

  • M3 · S5/S7:implemented;现有编辑器与 quota/CLI/前端/飞书统一等待反馈,打包读回一致且不新增决策源;本轮证据为 pr-6127-base-tests.log; pr-6127-head-tests.log; pr-6127-ts.log; pr-6127-typecheck.log; pr-6127-build.log; pr-6127-base-independent.json; pr-6127-head-independent.json; pr-6127-parity-assessment.json; ui-stage1.json; ui-stage2.json; real-lark-replay.json; pr-6127-canary-corrected.json。
  • Compatible off:implemented;无规则观察不创建间隔状态,原执行决定保持不变;本轮证据为 pr-6127-base-tests.log; pr-6127-head-tests.log; pr-6127-ts.log; pr-6127-typecheck.log; pr-6127-build.log; pr-6127-base-independent.json; pr-6127-head-independent.json; pr-6127-parity-assessment.json; ui-stage1.json; ui-stage2.json; real-lark-replay.json; pr-6127-canary-corrected.json。
  • 2. Problem and invariants:implemented;满足时间条件不授予预算、权限、领取权或整体启动资格;本轮证据为 pr-6127-base-tests.log; pr-6127-head-tests.log; pr-6127-ts.log; pr-6127-typecheck.log; pr-6127-build.log; pr-6127-base-independent.json; pr-6127-head-independent.json; pr-6127-parity-assessment.json; ui-stage1.json; ui-stage2.json; real-lark-replay.json; pr-6127-canary-corrected.json。

关键代码讲解

  • projection:由已有规则和启动历史推导间隔条件;使用带范围的嵌套联合类型并保留旧别名。
  • _apply_automatic_cadence_wait_precedence:只将原本可运行的受管理 App 工作转为等待;清除交付/领取投影,更强状态继续保留。
  • automation_cadence_readback:校验精确公共范围与状态;允许列表排除所有者备注,未知结果不能变为可运行。
  • AutomationCadenceSettings:提供现有一次保存及条件读回交互;展示原始精确时间、冲突/恢复与中英文间隔文案。

正向:existing Goal settings entry → choose existing Agent → single Save without mandatory note → revision-locked preview/apply → actual TypeScript file owner → independent GET → exact condition/time readback。负向:concurrent policy change or committed but unverified reply → reject stale CAS / lock further writes → Refresh policy → separate owner readback → resume legal editing。为真实存在的 scheduler/Turn 消费者保留结果、存储版本与旧别名;本次配套 UI 使用新增联合类型。已持久化的状态快照保留当时读回,v1/v2 存储迁移仍归原间隔模块。

对主干的风险

本轮独立执行92项相关 Python、26项原生 TypeScript、control-plane typecheck、Chat bundle build,均通过;基线原有六文件64项通过。十行配对真实 file owner/quota/CLI 探针覆盖 off、App/generic、pause、peer/new domain、其他 Goal、请求身份变化和精确到期。六条未改变分支的完整 execution_obligation 一致,off read 创建零文件。exact-base premerge 5 direct +19 selected 全过,无 warning/failure/hold。真实 owner 与 native status/transport 额外一项通过:捕获60分钟 waiting 快照后改为120,重新投递仍保留旧快照且不重复发送。

独立 Ego 浏览器走了现有 Goal 设置 → 间隔 → 选择对象 → 一次保存:空备注、双提交只写一次、降低下限、继承/peer隔离、草稿切换清除、stale CAS、已写未核实→刷新、keyboard Save、automation目标与备注持久化均通过;真实 admitted start 后,修正后的中英文 exact 标签和同一 UTC 时间可见。中文1512×982/390×844、英文1512×982截图已视觉检查,手机无横向溢出。cadence HTTP/TS owner真实,周边workspace目录为synthetic fixture。原完整Playwright runner未运行;本轮以Ego独立执行同一cadence场景的相关路径,不继承作者49场景通过的数字。

首次 canary 调用使用了不存在的 --base-ref;读取当前 help 后按 --git-diff-base 重跑,原失败记录保留。 Ego 自动滚动经过聚焦数字输入时改动了草稿,导致 below-viewport click 未提交;新 snapshot 定位后用原生 Enter 保存相同意图并独立读回。这个 reviewer harness 失败保留,不归因于 PR。bundle 有原有 large-chunk 建议;构建/校验成功。 没有获取、轮询或等待远端 CI;本轮所有结论来自当前 head 的本地证据。没有将旧失效 head 的失败简单抹掉,也没有用作者测试数字代替本轮验证。

语义与 CI 对齐

新增 union 是既有 typed owner 的派生词汇;Python/Zod 是输入/结果校验,未复制 interval 决策。新增 always-present readback 是披露的加性 schema 变化,执行 off parity 不等于逐字schema parity。configured App wait是 M3授权的变化,must_attempt_work=false是机器义务而不是建议;强暂停/修复/用户门与generic不被覆盖。接口budget保留有用scope/revision/union字段,未删语义条款压缩,full semantics 和budget检查通过。 新增联合类型与版本读回总是可用;已配置间隔且原本可运行的 App 现在等待,不记账或修改 timer/ACK。普通入口与更强的停止决定保留,UI/CLI/Lark 文案明确仅描述间隔条件。 App timer-to-hook、真实飞书投递、付费模型采用、跨宿主预约、原完整 Playwright runner 与多领域长期净收益尚未测试或宣称。

我的整体评价

APPROVE。 long_horizon:同一持久化间隔和启动历史支撑各入口,等待不记账、不改 timer/ACK,peer 和新 Agent 的历史独立;重放不因后来策略变化改写旧事实。尚无所有领域 Agent 的长期净收益实测。 user_experience:从原设置入口选择对象后一次保存即可,无必填备注或重复确认;等待给出精确时间,冲突和未核实写入要求刷新,不虚报已可启动。中英文与手机交互已实际验证。 当前结论仅覆盖这里的有界结果:本 PR 完成 M3 的共享间隔条件读回增量;不改宿主定时器,不授予预算、权限或任务领取权,真实 App timer-to-hook 和更大自动执行验收仍由 M2 负责。

面向后续演进的检查保留类型化间隔模块和公共结果校验,避免重复计算规则;不将会话、预算、权限另拼成第二套间隔启动判断,M2 宿主资格继续独立验证。 复用 quota 的 TypeScript 间隔 owner、原有设置编辑器与原生消息快照;Python 校验范围和结果后投影,消费者不另算倒计时或重建启动决策。 原有 roadmap/宿主/业务 acceptance 保持自己的边界。回忆中的恢复/真实用户路径经验仅用作选择验证线索,没有继承过去 verdict 或声称已证明记忆因果效用。审核批准不等于 merge readiness、平台 dismissal、安装升级或新的宿主权限;旧 blocking review 的平台状态仍应按 native exact-head closeout 读回。

English review

Motivation

Operators need to know why a selected agent is waiting and the exact interval threshold across settings, CLI and messaging. This M3 increment exposes one owner-produced interval condition and makes only otherwise-runnable hosted App work wait quietly.

Approach

The existing TypeScript cadence owner remains the sole policy/start-history authority. Python validates scoped public observations; settings and native conversation snapshots project them without another countdown or combined launch-readiness owner.

Changes

The entire current diff is 32 files, +1952/-79: one nested eligibility union, existing quota/API/CLI/settings/native-status projections and focused tests. Both prior wording and stale CN/EN selector findings are addressed. Store/result versions and legacy aliases remain for existing readers; frozen status replay retains its observation.
Specification docs/architecture/rfcs/automatic-execution-admission-v0.md at immutable 0fa3f0c19c68d71595cce4514a597509038ab633: M3 · S5/S7 implemented within this slice, Compatible off implemented within this slice, 2. Problem and invariants implemented within this slice.

Risks and validation

Independently ran 92 focused Python and 26 TypeScript tests, typecheck, packaged build and all 5 direct/19 selected canaries. Base has 64 original Python cases passing. Ten paired real-file owner/quota/CLI cases cover no-rule, hosted/generic, pause, peer/future domains, another goal, identity escape and exact due recovery; six unaffected full execution obligations match and off creates zero files. A real-owner native status replay test preserves its 60-minute snapshot after a 120-minute edit without another send. The Ego packaged journey exercises Save, optional notes, duplicate submission, inherited/automation scope, CAS and unverified recovery, keyboard, exact corrected CN/EN waiting labels and the same timestamp, desktop/mobile and stored audit notes.
Workspace-directory data and transport are synthetic; cadence HTTP/TS authority and native file replay are real. No original full Playwright runner, live Lark message, App hook, paid model or cross-host promotion is claimed. Initial reviewer setup failures are retained separately from resolved current checks; no CI was consulted, limits relaxed or active authority mutated.

Overall judgment

The bounded M3 readback and recovery journey improve without more mandatory input or repeated confirmation. Interval satisfaction is explicitly separate from health, budget, permission and launch authority. M2 host qualification and multi-domain long-term net utility remain open; positive local evidence does not certify them. Approval is not merge permission or installed behavior.

English verdict: APPROVE - 6127@2c3eb412cdd40f0ea33689c8b4fcf0e5499895ad.

…ission-readback

Signed-off-by: Duang777 <duangjl007@gmail.com>
…ission-readback

Signed-off-by: Duang777 <duangjl007@gmail.com>
@Duang777

Copy link
Copy Markdown
Collaborator Author

Synced current main@f1a0290bb with normal signed merges. New exact head: 4cac35b94b3ce2d5b728f66b3e61d0cc2db5f9ed.

Exact-head verification after the first sync passed:

  • 92 related Python tests
  • 26 TypeScript cadence/binding tests
  • control-plane typecheck
  • Chat bundle build
  • personal-workspace contract smoke
  • committed-diff premerge 19/19 with 0 failures or warnings; the untracked root uv.lock was explicitly excluded

main then advanced by one non-overlapping commit that changed only three docs and tests/control_plane/test_cold_source_import_cli.py; its 14 tests passed after the second signed merge. The cadence production, UI, and browser-scenario blobs did not change, so the packaged cadence journey was not rerun.

No rebase, force-push, CI rerun, or self-merge. @loopx-agent please re-review exact head 4cac35b94b3ce2d5b728f66b3e61d0cc2db5f9ed.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants