Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
17 commits
Select commit Hold shift + click to select a range
f8f4952
feat(explore): enforce scoped composition lineage and lifecycle evidence
LIHUA919 Sep 29, 2026
1a5f6f4
test(explore): qualify composition write gates across real entrypoints
LIHUA919 Sep 29, 2026
21a2d9d
docs(explore): document scoped lineage and no-spend retirement
LIHUA919 Sep 29, 2026
3bf0dbe
fix(explore): register completion evidence registry read
LIHUA919 Sep 29, 2026
758a141
Merge remote-tracking branch 'origin/main' into codex/explore-composi…
LIHUA919 Sep 29, 2026
14650fd
chore(validation): refresh integrated registry census coordinates
LIHUA919 Sep 29, 2026
85c7958
fix(explore): qualify execution against current live lineage
LIHUA919 Sep 29, 2026
8a16deb
test(explore): cover diagnostic history before bound execution
LIHUA919 Sep 29, 2026
1636697
docs(explore): reconcile implemented composition boundary
LIHUA919 Sep 29, 2026
20ce37d
Merge remote-tracking branch 'origin/main' into codex/explore-composi…
LIHUA919 Sep 29, 2026
862d31c
Merge latest main and refresh registry I/O census
LIHUA919 Sep 29, 2026
fed89c2
test: preserve admitted required-read commands in interaction smoke
LIHUA919 Sep 29, 2026
fdc2b80
test: track generated twins and turn-start hook projection
LIHUA919 Sep 30, 2026
4e3d77f
Merge latest main with release-book qualification
LIHUA919 Sep 30, 2026
3adb543
Merge latest main into M3 Explore PR
LIHUA919 Sep 30, 2026
6395df7
test(runtime): align source-read and disclosure fixtures
LIHUA919 Sep 30, 2026
5f9705d
test(coverage): exclude disposable probe checkout from shards
LIHUA919 Sep 30, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ import { useId, type ReactNode } from "react";
import type { CapabilityConfigurationEditor } from "../../data/chat";
import { PeriodicReportScheduleField } from "./periodic-report-schedule-field";

type FieldCopy = Record<string, { description?: string; label?: string }>;
type FieldCopy = Record<string, { description?: string; label?: string; optionLabels?: Record<string, string> }>;
type ConfigurationField = CapabilityConfigurationEditor["fields"][number];
type FieldValue = boolean | number | string | string[] | Record<string, unknown> | null;
type FieldChange = (key: string, value: FieldValue) => void;
Expand Down Expand Up @@ -40,7 +40,7 @@ function ConfigurationFieldControl({ copy, field, id, onChange, value, timezone
<span>{label}</span>
<select id={id} onChange={onChange ? (event) => onChange(field.key, event.target.value) : undefined} value={typeof value === "string" ? value : ""}>
<option value="" />
{(field.options ?? []).map((option) => <option key={option} value={option}>{option}</option>)}
{(field.options ?? []).map((option) => <option key={option} value={option}>{copy[field.key]?.optionLabels?.[option] ?? option}</option>)}
</select>
</label>
);
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ type LocalizedCopy = Readonly<{
readOnlyReason?: string;
}>;

type FieldCopy = Record<string, Readonly<{ description?: string; label: string }>>;
type FieldCopy = Record<string, Readonly<{ description?: string; label: string; optionLabels?: Record<string, string> }>>;

const capabilityCopy: Record<WorkspaceLocale, Record<string, LocalizedCopy>> = {
en: {
Expand Down Expand Up @@ -36,7 +36,7 @@ const capabilityCopy: Record<WorkspaceLocale, Record<string, LocalizedCopy>> = {
},
explore_harness: {
displayName: "Explore Harness",
description: "Selects a capability-owned planning and research harness profile for bounded multi-step exploration.",
description: "Plans bounded exploration. Explicit composition replans require a bound experiment or typed result; task completion and execution permissions remain separate.",
},
lark_event_inbox: {
displayName: "Lark event inbox",
Expand Down Expand Up @@ -102,7 +102,7 @@ const capabilityCopy: Record<WorkspaceLocale, Record<string, LocalizedCopy>> = {
},
explore_harness: {
displayName: "探索 Harness",
description: "为有界的多步探索选择由能力负责的规划与研究 Harness profile。",
description: "规划有界探索。显式组合的重新规划需绑定实验或类型化结果;任务完成和执行权限单独判断。",
},
lark_event_inbox: {
displayName: "飞书事件收件箱",
Expand Down Expand Up @@ -162,6 +162,8 @@ const fieldCopy: Record<WorkspaceLocale, FieldCopy> = {
reasoning_effort: { label: "Child reasoning effort", description: "For example max; the host must support this model and effort." },
max_children: { label: "Maximum children", description: "Hard upper bound for concurrently delegated child work." },
profile: { label: "Planner profile", description: "Select one registered Explore Harness profile." },
composition_mode: { label: "Composition policy", description: "Replan requires an exact experiment successor or typed result; it grants no execution authority.", optionLabels: {disabled: "Off", explicit_only: "Explicit candidates"} },
composition_scope_id: { label: "Research coverage scope", description: "An opaque scope id required by the explicit-only composition policy." },
profile_preset: { label: "Report profile", description: "Capability-owned report profile, such as weekly-progress." },
wait_for_ci: { label: "Wait for CI", description: "Disable to use local validation without querying or waiting for CI. Merge authority is unchanged." },
review_priority: { label: "Review priority", description: "Choose whether other developers' PRs or the authenticated reviewer's own PRs are ranked first." },
Expand Down Expand Up @@ -189,6 +191,8 @@ const fieldCopy: Record<WorkspaceLocale, FieldCopy> = {
reasoning_effort: { label: "子 Agent 推理档位", description: "例如 max;宿主须支持所选模型与档位。" },
max_children: { label: "最大子 Agent 数", description: "可同时委派的子任务硬上限。" },
profile: { label: "规划 Profile", description: "选择一个已注册的 Explore Harness profile。" },
composition_mode: { label: "组合策略", description: "重新规划需要精确的实验后继或类型化结果;它不授予执行权限。", optionLabels: {disabled: "关闭", explicit_only: "仅显式候选"} },
composition_scope_id: { label: "研究覆盖范围", description: "显式组合策略要求填写不含私有内容的范围标识。" },
profile_preset: { label: "报告 Profile", description: "由该能力管理的报告 profile,例如 weekly-progress。" },
wait_for_ci: { label: "等待 CI", description: "关闭后使用本地验证,不查询或等待 CI;不改变合并权限。" },
review_priority: { label: "审阅优先级", description: "选择先排其他开发者的 PR,还是先排当前已认证审阅者自己的 PR。" },
Expand Down
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
import { useEffect, useMemo, useState } from "react";
import { useEffect, useLayoutEffect, useMemo, useState } from "react";
import { AlertTriangle, Code2, LoaderCircle, RefreshCw } from "lucide-react";

import {
Expand Down Expand Up @@ -54,7 +54,9 @@ function useCapabilityMutation({ goalId, onApplied, selected, t }: Readonly<{
? parseEditableCapabilityJson(selected.configuration_editor, jsonDraft) : null, [selected, jsonDraft]);
const jsonValid = editorMode === "guided" || parsedJson !== null;

useEffect(() => {
// Initialize the new capability's draft before it can receive input. A
// post-paint reset can otherwise erase the first toggle after selection.
useLayoutEffect(() => {
setEditorMode("guided");
setJsonDraft("");
setMutation({
Expand Down
40 changes: 33 additions & 7 deletions docs/architecture/rfcs/research-exploration-control-plane-v0.md
Original file line number Diff line number Diff line change
Expand Up @@ -150,10 +150,8 @@ milestone status.

| Gap | Consequence |
|---|---|
| No shared research write-time gate | The cold evidence codec cannot discharge or enforce a live composition obligation. |
| No exact obligation/Todo/result lineage | A research receipt is not proof of an authorized Todo transition or accepted Goal closure. |
| Cold shadow not adopted by hot status/frontier | The existing #3173 projection remains behavior-compatible; canonical research obligations still need M3 integration. |
| No dismissal or deferral contract | Evidence invalidation is visible, but typed candidate retirement and resumption remain unimplemented. |
| Integrated M3 qualification remains | Typed dismissal, blocker waits and exact invalidated-duty retirement are implemented locally; final premerge and maintainer-reviewed integration remain distinct from implementation and live research qualification. |
| Execution attribution is not effect authority | The live replan gate joins exact Todo/experiment/input facts; its receipt is not task-lease/effect authorization or accepted Goal closure. |
| Live qualification incomplete | Deterministic and real CLI/file-log tests establish state semantics, not model selection quality or scientific truth; no live Lark sync is qualified by projection tests. |
| No promotion evidence for inferred combinations | Shared constraints are not known to be precise enough to trigger obligations. |

Expand Down Expand Up @@ -232,8 +230,9 @@ execution, and result into one ambiguous relation. This RFC rejects that shape.

The research envelope and closure basis have an active CLI caller and the
[versioned evidence protocol](../../reference/protocols/research-observation-v0.md).
The action signature, shared write gate and model selection below remain design
targets. The cold shadow does not promote them into current behavior.
The opt-in M3 development path implements exact execution lineage and shared
write gates and bounded retirement transitions. Model selection below
remain design targets; the cold shadow does not activate enforcement.

### 7.1 Compose; do not mutate v0 silently

Expand Down Expand Up @@ -804,7 +803,7 @@ control-plane failures.
| M0 | RFC, current-state inventory, and explicit ownership decision | Maintainer review; no runtime behavior | Accepted design |
| M1 | Characterization fixtures plus typed research observation and closure contract in Explore | Deterministic normalization, privacy, compatibility, and negative tests | Implemented evidence/CLI slice; live research qualification remains separate |
| M2 | Explicit-only composition candidate, canonical gap projection, and read-only status shadow | No pairwise inference; bounded packet; projection parity | Partial: #3173 legacy quota/successor; canonical binary cold shadow in CLI/Lark projection; hot status adoption and live Lark qualification remain |
| M3 | Goal-frontier obligation, exact Todo/experiment lineage, and shared write-time gate | State/replay matrix and premerge canary pass | Not started |
| M3 | Goal-frontier obligation, exact Todo/experiment lineage, and shared write-time gate | State/replay matrix and premerge canary pass | Local state/replay and standard premerge qualified; maintainer-reviewed integration pending. Scoped policy/editor, shared gates, archive lineage, consumers, dismissal, waits and exact no-spend duty retirement are implemented |
| M4 | Bounded multi-candidate cards, `composition_selection_v0`, real model-tool behavior qualification, and repeated live shadow | Model autonomously selects a legal semantic action from the delivered candidate set; selection quality is no worse than the declared fallback; compact receipts only | Not started |
| M5 | Shared-constraint candidate ranking in shadow mode | Precision and cost evidence; no automatic trigger | Not started |
| M6 | Optional inferred trigger | Explicit maintainer decision and measured promotion thresholds | Deferred |
Expand Down Expand Up @@ -835,6 +834,33 @@ M3 is the first behavior-changing slice. It should be a separate PR so the
obligation and write gate can be reviewed and reverted independently from the
evidence schema.

The M3 development boundary joins current same-agent Todo, experiment and input
facts in the typed Explore owner. Goal policy is explicitly scoped and disabled
by default; the existing capability editor and CLI share its configuration
owner. Quota and refresh reuse one live frontier, with the original duty pinned
through scalar rollout fields and both receipt adapters. Real CLI tests reject
unrelated/deferred successors and invalidated writeback, then settle the original
Turn through its exact successor. File/SQLite tests distinguish canonical Todos
from stale display rows; packaged UI checks exercise policy preview, activation,
disable, readback and narrow screens. Native actor/lease and CAS admission remain in force; a fixed IO host
locks the graph while the typed owner qualifies and persists completion evidence.
Real File/SQLite and legacy tests cover missing evidence, direct IPC self-approval,
terminal-verb bypass, retained archive lineage and immutable completion replay.
Agent-scoped status, Explore and existing Lark Summary fields use the same live
facts. Typed candidate dismissal permits scoped terminal retirement; a fresh
canonical blocker and common Todo resume condition defer the gap without closing
it. Real CLI validates exact observed/dismissed/blocked progress source through
the original Turn, with independent File/SQLite lease-safe wait/resume evidence.
Invalidated input/scope/activation produces source-qualified retirement for the
original duty. Common readback retains its guard and historical debit, closes
that Turn without spend, and keeps the current frontier and runnable/paused work
visible. IO assembly stays in existing CLI/refresh composition roots; the shared
gate consumes supplied capability facts and the typed owner remains singular.
The local state/replay matrix and 19 standard risk-selected premerge checks pass.
Two existing scheduler ACK tests fail identically on the unchanged base under the
same local runtime; this is retained as a baseline limitation, not called green.
Maintainer-reviewed integration and independent live qualification remain.

## 17. Rejected Alternatives

### 17.1 Automatically pair nodes with a shared closure stage
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -131,10 +131,8 @@ hypothesis”或“新 probe family”。它无法持久表达:A 和 B 都已

| 缺口 | 后果 |
|---|---|
| 没有 shared research write-time gate | Cold evidence codec 不能解除或强制 live composition obligation。 |
| 没有精确 obligation/Todo/result lineage | Research receipt 不证明已授权 Todo transition 或已接受 Goal closure。 |
| Cold shadow 未接入 hot status/frontier | 既有 #3173 投影保持行为兼容;canonical research obligation 仍需 M3 集成。 |
| 没有 dismissal/deferral contract | Evidence invalidation 可见,但类型化 candidate retirement/resumption 尚未实现。 |
| M3 集成资格仍未完成 | Typed dismissal、blocker wait 和精确 invalidated-duty retirement 已在本地实现;最终 premerge 与 maintainer review 集成仍独立于实现和真实研究 qualification。 |
| 执行 attribution 不是 effect 权限 | Live replan 门禁连接精确 Todo/experiment/input 事实;receipt 不证明 task-lease/effect 授权或已接受 Goal closure。 |
| Live qualification 不完整 | Deterministic 与真实 CLI/file-log 测试证明状态语义,不证明 model selection 质量或科学结论;projection 测试不构成 live Lark sync 资格。 |
| inferred combination 没有 promotion evidence | 共享 constraint 的精度还不足以直接触发 obligation。 |

Expand Down Expand Up @@ -209,8 +207,8 @@ A、B 之间的 `joint_probe` 直连边会把 candidate、execution 和 result

Research envelope 与 closure basis 已有真实 CLI caller 和
[版本化证据协议](../../reference/protocols/research-observation-v0.zh-CN.md)。
下文 action signature、shared write gate 和 model selection 仍为设计目标;
cold shadow 不会将其 promotion 为当前行为。
Opt-in M3 开发路径已实现精确 execution lineage 和共享 write gate。下文 model
selection 仍为设计目标;有界 retirement 已实现,cold shadow 不会激活门禁。

### 7.1 组合,而不是静默修改 v0

Expand Down Expand Up @@ -742,7 +740,7 @@ rule,以及 model variance 与 control-plane failure 的分离。
| M0 | RFC、current-state inventory 与显式 ownership decision | Maintainer review;无 runtime behavior | 已接受的设计 |
| M1 | Characterization fixture,以及 Explore 中的 typed research observation 与 closure contract | Deterministic normalization、privacy、compatibility 与 negative test | Evidence/CLI 切片已实现;真实研究 qualification 独立保留 |
| M2 | Explicit-only composition candidate、canonical gap projection 与 read-only status shadow | 不做 pairwise inference;packet 有界;projection parity | 部分实现:#3173 legacy quota/successor;CLI/Lark projection 的 canonical binary cold shadow;hot status adoption 与 live Lark qualification 仍未完成 |
| M3 | Goal-frontier obligation、精确 Todo/experiment lineage 与共享 write-time gate | State/replay matrix 与 premerge canary 通过 | 未开始 |
| M3 | Goal-frontier obligation、精确 Todo/experiment lineage 与共享 write-time gate | State/replay matrix 与 premerge canary 通过 | 本地 state/replay 与 standard premerge 已验证,maintainer review 集成待完成。Scoped policy/editor、共享门禁、archive lineage、消费者、dismissal、wait 与精确无支出 duty retirement 已实现 |
| M4 | 有界 multi-candidate card、`composition_selection_v0`、真实 model-tool behavior qualification 与重复 live shadow | 模型从交付 candidate set 中自主选择合法 semantic action;选择质量不劣于 declared fallback;只保留 compact receipt | 未开始 |
| M5 | Shared-constraint candidate 在 shadow mode 中排序 | 有 precision/cost evidence;不自动触发 | 未开始 |
| M6 | 可选 inferred trigger | 显式 maintainer decision 与量化 promotion threshold | 延后 |
Expand Down Expand Up @@ -771,6 +769,27 @@ Projection 测试不证明 live remote effect 或模型自主研究行为。交
M3 是第一个 behavior-changing slice。它应单独成 PR,使 obligation 与 write gate
能够独立于 evidence schema 评审和回滚。

M3 开发边界在 typed Explore owner 中连接当前同一 Agent 的 Todo、experiment
和 input 事实。Goal policy 显式限定范围且默认关闭;既有能力编辑器与 CLI 共享
配置 owner。Quota 与 refresh 复用同一 live frontier,原 duty 通过 rollout 标量
字段和两端 receipt adapter 固定。真实 CLI 测试拒绝无关/延期 successor 与失效
writeback,再通过精确 successor 结算原 Turn。File/SQLite 测试区分 canonical
Todo 与陈旧显示行;打包 UI 验证策略预览、启用、关闭、读回和窄屏。Native actor/lease 与 CAS admission
仍强制执行;固定 IO host 锁定图,typed owner 校验并持久化 completion evidence。
真实 File/SQLite 与 legacy 测试覆盖缺少证据、direct IPC 自报 approval、terminal
verb 绕过、保留 archive lineage 和不可变 completion 回放。Agent 范围的 status、
Explore 与既有 Lark Summary 字段使用同一 live fact。Typed candidate dismissal
允许 scoped terminal retirement;新 canonical blocker 与通用 Todo resume condition
使 gap 暂缓,但不关闭。真实 CLI 通过原 Turn 校验 observed/dismissed/blocked 的
精确 progress source;File/SQLite 独立验证 lease-safe wait/resume。
输入/scope/activation 失效时,为原 duty 生成 source-qualified retirement。
通用 readback 保留原 guard 与历史 debit,无支出关闭该 Turn,同时保持当前
frontier 与 runnable/paused work 可见。IO 装配保留在既有 CLI/refresh composition
root;共享门禁消费传入的 capability fact,typed owner 始终只有一个。
本地 state/replay matrix 与 19 项 standard 风险验证通过。两个既有 scheduler ACK
测试在相同本地 runtime、未修改 base 上也以相同方式失败;保留为 baseline 限制,
不称为 green。Maintainer review 集成与独立 live qualification 仍未完成。

## 17. 被拒绝的替代方案

### 17.1 自动组合拥有共享 closure stage 的 node
Expand Down
16 changes: 16 additions & 0 deletions docs/reference/handoff-mode.md
Original file line number Diff line number Diff line change
Expand Up @@ -207,6 +207,22 @@ permission. The original rejection code and all fences remain unchanged:
| `soft_claim`, non-open Todo, acceptance hold or conflicting write scopes | Resolve the reported acquisition blocker. No acquire action is offered. |
| Edit changes retained leased work requirements or status | Use the owning lifecycle transition; acquiring another lease cannot authorize the metadata edit. |

The existing `open -> blocked -> open` lifecycle also accepts a typed
prerequisite wait: use `todo update --status blocked --resume-when
todo_done:<dependency-todo> --reason '<bounded cause>'` after the active holder
releases its execution lease. This explicit wait form is newly supported for
native hard-lease Todos; the prior clear-wait pause form is unchanged. A live
lease or bundled execution proof still rejects the transition. Resume with
`--status open --clear-resume-when --reason '<resume basis>'`; neither transition
grants execution authority, and the next execution requires a fresh lease.

既有 `open -> blocked -> open` lifecycle 也支持 typed 前置任务等待:active
holder 先释放执行 lease,再用 `todo update --status blocked --resume-when
todo_done:<dependency-todo> --reason '<bounded cause>'` 暂停。此显式 wait 形式
新增支持 native hard-lease Todo;原 clear-wait pause 形式保持不变。有效 lease
或附带执行 proof 仍被拒绝。用 `--status open --clear-resume-when --reason
'<resume basis>'` 恢复;两次转换都不授予执行权限,下一次执行仍需新 lease。

The recovery descriptor uses the standalone `loopx task-lease acquire` command.
Combined `todo claim --task-lease-idempotency-key` is restricted to `hard_lease`
and is not the recovery route for `legacy`. Acquire uses `--owner`, a **fresh**
Expand Down
Loading
Loading