fix(collaboration): qualify existing peer handoffs on Windows - #5456
huangruiteng merged 12 commits into
Conversation
130c87c to
74e7b73
Compare
huangruiteng
left a comment
There was a problem hiding this comment.
Reviewer: model_agent | GPT-5 | OpenAI
动机
结论:REQUEST_CHANGES,原因是受影响 Windows 路径的独立验收尚未完成,不是已复现的代码 bug。评审完整 head 74e7b73。#5039 要让请求抵达用户指定的既有 peer,并在恢复后返回结果;不能用临时子任务替代。主干已有多候选绑定与精确路由,这份 PR 解决 private Inbox/锁长地址及二进制读取的 Windows 障碍,并增加显式真实宿主资格测试。机制有正价值,但 POSIX 正路和作者声明不能代替受影响平台的可复核执行。
spec_ref = https://github.com/loopx-project/loopx/issues/5039;spec_revision = sha256:54fda1c96674e6ae1d0194b28a566842cd47ede28e014e0d6183d95e0ce89369,是本次读取的原议题正文摘要,另以不可变 base 4fc30f1 核对已有协议与生产 owner。原议题「Decisive acceptance」编号按原样映射:
| criterion_id | 本 head 的判定 |
|---|---|
| 1. | 多历史绑定下精确选中可读 task、零替代 worker:既有路由测试通过;新增真实宿主场景已读,未独立执行其付费模型部分,保留资格缺口。 |
| 2. | 一个历史 task 不可达仍保留其他候选且不自动恢复:既有 route/directory 验证通过;本 PR 不改选择 owner,真实宿主观察未重新认证。 |
| 3. | ambiguous/revoked/archived/cross-profile 区分且不复制会话:主干 typed route 与负例保留;本地 Windows fs 增量不关闭跨宿主 R6,沿原议题边界 deferred。 |
| 4. | 既有 peer 收到 exact-head 请求、采纳、返回、重启重试不重复:独立实际 CLI/store 往返及重试通过;Windows 长 private-store 和原生锁正是变更路径,本轮未实机验证,not_met 的是这段观察证据,不是已发现的行为错误。 |
| 5. | 普通 directory 只读、公私边界:既有 native route/directory 用合成状态验证,生产改动只处理 private 地址和 digest,不把正文、宿主路径或会话复制到公开状态。 |
改动思路
有界实现是现有 collaboration Inbox 加一层本地文件地址表示,共享锁继续保护同一文件,不创建第二套 request、registry 或决策库。只改 Win32 寻址、不缩短完整 request 身份,这比截断 hash、改变存储布局或关掉锁更容易回滚。输入核验仍限定 receiver worktree、普通文件和四 MiB;Python 保留在本机 fs/transport 边界合理,通用状态与 host locator 权限仍复用既有 owner,无需为这几十行扩大 TS 迁移。
正路从 manager-inbox request 到 receiver read/adopt/report,再到原 requester read/consume/replay;路由预览始终是 locator_only/not_attempted,不是提交成功、采纳或 lease。失败/恢复分别归 route 与 durable request/return owner。新增 live smoke 的模型使用必须显式授权,普通执行不启动宿主;我实跑无开关路径,得到 argparse exit 2 的清楚拒绝,没有开启真实模型。
具体改动
关键代码讲解
- windows_extended_path(loopx/control_plane/runtime/file_paths.py:9):非 Windows 返回同一 Path;Windows 先绝对化,已扩展地址保持原样,UNC 转成扩展 UNC,其余转成扩展盘地址。它不发现 Goal、不改拓扑,只是地址适配。inbox._root(loopx/control_plane/collaboration/inbox.py:41)把 private manager-context 原根交给它;完整 request 目录与文件名保留。
- _lock_path / _lock_id / _effect_mutation_lock_path(loopx/file_lock.py:125、163、612):Python kernel 锁和 TS-effect sidecar 都用扩展地址;diagnostic lock ID 先消除 Windows 地址前缀,再按原规则 hash,防止同一文件两个 ID。现有 regular-file、symlink/hardlink、token 所有权与释放规则未放宽。原 pid 仍活着时释放后重获,以及独立进程竞争拒绝,在真实 POSIX 后端通过;不能把它冒充 Win32 成功。
- input_readiness(loopx/control_plane/collaboration/peers.py:477、526):支持不存在的 O_NONBLOCK、显式 O_BINARY;仍先检查 workspace,再 fstat、有限读取、digest。我的 CRLF 加 Ctrl-Z 合成 artifact 在真实 CLI 收件人得到 available;随后内容变化为 changed、删除为 unavailable,未把内容供应给投影。Windows CRT 读取需受影响平台补验。
- qualify / main(examples/peer-handoff-live-smoke.py:72、196):只创建该验证拥有的两个 synthetic threads,恢复它们的明确身份,用已有 CLI/read/adopt/report 工具证明 exact-head/digest 返回;不启用 native replacement worker。关闭会话在 finally;--execute-real-host 是成本授权边界。本轮没有执行这个付费入口,不继承作者的 authenticated host 结论。
完整 13 文件、+369/-16 均已阅读:生产 fs/Inbox/readiness、214 行 live qualification、协议和 self-repair 指导,以及 UTF-8、read-only interrupted Turn、Windows update/install 相关测试。安装技能集合和 archive 平台修正属于共享测试期望,不是新的默认 update 机制。没有 tracked 生成物或新的用户配置。共享 dependency-light 地址 seam 是合理的伴随重构,下一次锁变更无需导入 Goal 路由图。
对主干的风险
本轮 125 项 Python 通过、8 项平台条件测试跳过;严格 kernel mypy 的 19 源文件通过,Ruff、diff check 和语义 advisory 通过。另在不可变 base 和该 head 用同一独立 harness、真实 source CLI 与文件后端执行 peer 请求/采纳/报告/消费/重试、binary digest 及跨进程锁竞争。完整归一化结果相同:fixture 0bdf12913f9f4952be7a1706bb9fb4f4df23959991fa9939d3a008895a4a14a6,base/head observation 29b61762ca8597d4f2cae6c7273875ed9ae3fffef8b0d5df02a2184cc27a630f。只归一化临时根与创建/更新/收取/交付等 wall-clock,未去掉状态、身份、digest、回执或拒绝语义。已纠正评审 harness 的 timeout 参数错误;它不是 PR 回归。
P2:Windows 变更路径尚缺本次独立可复核证据。 此处触发条件就是 >260 字符 private-store/sidecar、普通和扩展地址混用、Windows binary artifact。两个新长路径测试在当前主机确实跳过;不能由非 Windows 的 identity、重放或锁通过推出 Win32 的释放、互斥和 exact-byte 正确。请补充当前 exact head 的 Windows 实机两项回归及独立跨进程锁证据,或由有该环境的 reviewer 重跑;真实宿主付费资格仍应在其既有授权下完成。最小修复首先是证据,不要求凭空改实现,也不要求把 CI 当验收。复验命令:uv run --extra test python -m pytest tests/test_file_lock.py::test_long_lock_paths_release_and_keep_one_identity tests/test_peer_collaboration.py::test_peer_exchange_survives_long_private_store_paths -q。恢复和精准重试应保持一个 request、同文件的一个锁身份、持有者活着仍能正确释放;不得缩短身份或扩大锁权限。
语义与 CI 对齐
受影响的是既有文件地址、输入核验及锁的语义,不是新增 actor 协议或通用工作义务。状态仍用既有 typed readiness/route/return vocabulary;没有 substring denylist、benchmark 专用 quota 文案,也没把机器拒绝叫建议。新增指导讲精确资格环境,不激活 peer/model 操作。当前缺口归 observable_semantics/真实平台 validation;没有查询、轮询或等待 GitHub CI,也没有调预算或权限来补绿。
我的整体评价
方向和体量适当,没有要求抽象框架或平行 Python 决策源;普通 POSIX 使用和持续 request/return 重试已证明保持,不必重复重构邻域。long_horizon 的已有持久往返保留,Windows 修复的持续使用仍 not_yet_proven;user_experience 不增加确认步骤,Windows 失败恢复效果也需实机观察。故保留 REQUEST_CHANGES 作为明确验收 hold,不声称发现了代码缺陷,不关闭 #5039/R2/R3 整体验收。最有价值的下一步是补受影响平台结果,按原 owner、原身份重验,不是另开有名无实的后续能力。没有合并、会话复制、付费调用或主动升级宿主。
English verdict: REQUEST_CHANGES - 74e7b73: evidence hold, not a reproduced code defect. 125 Python tests and 19-source mypy passed; immutable base/head real CLI/store and POSIX lock parity passed. The changed Windows long-path/binary paths remain independently unqualified; eight platform cases skipped. No merge.
74e7b73 to
a7beb36
Compare
|
Rebased onto The Windows evidence hold now has current-head qualification in a source-installed Python 3.13.5 environment:
All four passed. The actual Codex app-server smoke also passed on this head: two new synthetic peers, exact existing-thread resume, independent receiver adoption/review, exact checkout head/digest returned and consumed by the original requester after restart, one tracked request, zero replacement workers. The smoke isolates and shuts down its own reusable typed runtime before Windows cleanup; two earlier cleanup failures are recorded as repaired in the PR body. The production-identical Linux suite passed 113 tests (four Windows-only skips). Current-head exact CI mypy/Ruff, TypeScript typecheck, semantic smoke and typed routing tests passed. Paired base/head CLI budget and actual-wheel install/uninstall validation passed without changing ceilings or contracts. This remains the local-host collaboration qualification slice; route previews confer no execution authority and overall R2/R3 is not declared complete. Hosted checks are rerunning after push, and the Windows evidence is ready for maintainer re-review. |
huangruiteng
left a comment
There was a problem hiding this comment.
Reviewer: model_agent | GPT-5 | OpenAI
动机
REQUEST_CHANGES 是受影响平台的证据 hold,不是声称发现新代码缺陷。本次完整 head a7beb36ae4ba5f76addd5f8af33f89f4d17c7fae。作者已在当前 head 说明报告四项 Windows 成功和真实宿主成功;这与旧 head 的“尚未运行”不同。下面明确区分作者声明、当前源代码和我实际执行的证据,不把旧结论机械搬到新 head。
spec_ref = https://github.com/loopx-project/loopx/issues/5039;spec_revision = sha256:54fda1c96674e6ae1d0194b28a566842cd47ede28e014e0d6183d95e0ce89369,为本次原议题正文摘要。另核对不可变 base 5e889bd 的既有 peer 协议。按原 Decisive acceptance 的 criterion_id:1. 精确既有 task、零 replacement worker,现有路由检查通过;2. 单个历史 task 不可达不否定其他候选,既有 typed route/directory 负例通过;3. ambiguous/revoked/archived/cross-profile 的 owner 未改,跨宿主授权沿原议题边界 deferred;4. 接收、采纳、返回、重启不重复,实际本地 CLI/store 往返通过,但本 PR 改动的 Windows 长地址/CRT 读取尚缺我可复核的执行来源;5. ordinary directory 只读和公私分离保留,目录不是 lease 或执行授权。
本切片修复现有 peer 往返的 Windows I/O 障碍,而非再造 resolver 或宣布 R2/R3 全部完成。它有独立价值;唯一阻塞是此受影响平台的验证边界,不要求追加无关产品能力。
改动思路
已有 binding、collaboration Inbox 和 request/return owner 已能表达精确 peer。保持完整 request ID 和现有目录,只给 Win32 文件地址加 extended 表示,比缩短 hash、关闭锁或另建队列更小且可回滚。binary digest 沿原四 MiB 有限读取、workspace/regular-file 核验路径处理 supported flags,不放宽输入权限。
正路仍是 request → receiver read/adopt/report → 原 requester read/consume → 同身份 replay;返回、采纳和同意执行是不同事实。失败由原 route/Inbox/锁 owner 恢复。live smoke 明确要求成本开关,只拥有两个新 synthetic threads;它不恢复用户 task,不启用 replacement worker,不把 locator_only/not_attempted 预览称为实际送达。自动加载指导解释平台资格,不自动启用 peer/model 操作。Python 留在本机文件和 transport 边界合理,通用状态继续用既有 typed owner,不需要平行 TS/Python 决策库。
具体改动
关键代码讲解
windows_extended_path,loopx/control_plane/runtime/file_paths.py:9:非 Windows 原样返回;Windows 绝对化、保留已有 extended 地址并转换 UNC/盘地址。inbox._root:42用同一 private manager-context 根,不缩短 request ID。依赖轻的 runtime seam 不需要导入 Goal 拓扑。_lock_path / _lock_id / _effect_mutation_lock_path,loopx/file_lock.py:125、163、612:kernel 和跨 runtime sidecar 都使用同一扩展寻址;diagnostic ID 消除地址前缀后仍按原身份计算。token、真实文件身份、互斥和释放规则未放宽;新独立进程测试还要求 holder 释放后仍活着时可以重获。input_readiness,loopx/control_plane/collaboration/peers.py:509:使用可用的 NONBLOCK 和 BINARY flags,避免 Win32 text 模式改动 CRLF/Ctrl-Z 摘要;仍核对所属 workspace、文件类型、大小和精确字节 SHA-256,内容不进入投影。qualify / main,examples/peer-handoff-live-smoke.py:31、199:资格场景通过既有 host adapter 和明确工具执行恢复/采纳/返回/消费;finally 关闭其拥有的 session。当前 main 给自己的 typed runtime 独立 temporary locator,再经现有 shutdown API 停止后清理目录,恢复环境;_runtime_dir确实按 tempfile 根寻址,不应停止共享用户 runtime。无--execute-real-host实跑 exit 2,未启动宿主或模型。
完整 14 文件、+451/-15 均已阅读:四个生产 fs/readiness/锁源、238 行显式 live qualification、peer 协议和 self-repair 指导、四项 Windows 回归,以及 Chat/replan/技能 metadata/parity 的 fixture 修正。queued Turn claim、隔离根、read-only Todo 和 UTF-8 期望没有变成新权限或 update 行为。frontend/Lark 不新增操作,继续用既有 shared owner;这里不是一个应当另加表单的配置能力。临时 root/宿主记录/原始日志没有进入 tracked diff。
对主干的风险
本轮实际源 CLI 和文件后端,在不可变 base 与当前 head 用相同独立 harness 完成 request/read/adopt/report/return-consume/replay、binary artifact available→changed→unavailable,以及真实跨进程锁竞争和释放。归一化整个输出一致:fixture 0bdf12913f9f4952be7a1706bb9fb4f4df23959991fa9939d3a008895a4a14a6,base/head observation 同为 29b61762ca8597d4f2cae6c7273875ed9ae3fffef8b0d5df02a2184cc27a630f。只排除临时 root 和各自交付/读写 wall-clock,不删除状态、身份、digest、回执或拒绝细节。此证据是实际 POSIX owner,不是 Win32 或 authenticated model。
当前 native route/directory/锁/peer/architecture 五文件验证 81 passed、4 skipped,四项 skipped 正是 Windows 专属;kernel mypy 19 源文件通过,CI 范围 Ruff 和语义 advisory 通过。初次测试命令写了两个不存在的路径,已改为实际 native 文件重跑;那是评审命令错误,不是 PR 回归。没有查询或等待远端 CI,也没有因 CI 颜色增加成本开关。
P2 验收 hold:Windows 执行结果目前只有作者文字声明,未取得可复核的当前来源与结果记录。 新跨进程和 binary 测试直接覆盖旧 hold 的必要条件,方向正确;然而本机四项均跳过,POSIX 的 exact-byte 和同文件锁不证明 Win32 的扩展寻址、互斥与 CRT 读取。我没有依据否定作者报告,也不能把声明升级为我已验证的运行。最小下一步是提供删敏的当前 head Windows 资格结果(source revision/安装来源、OS/Python、四项精确用例结果、完整命令退出状态),或由可运行 Windows 的 reviewer 复跑并读回。无需改权限、缩短 ID、再写新抽象或重复付费模型场景;原始 session/transcript/路径和凭据不应公开。
复验现有四例:uv run --extra test python -m pytest tests/test_file_lock.py::test_long_lock_paths_release_and_keep_one_identity tests/test_file_lock.py::test_long_lock_paths_exclude_other_process_and_release_while_holder_alive tests/test_peer_collaboration.py::test_peer_exchange_survives_long_private_store_paths tests/test_peer_collaboration.py::test_peer_binary_artifact_preserves_crlf_and_ctrl_z_digest -q。要求四例确实运行而非 skipped;其中第二例明确 >260 字符、alternate address 不能绕锁、holder 活着时释放可重获。该缺口归验证证据,不虚构一个代码 bug。
语义与 CI 对齐
复用既有 readiness/route/return 和 lock vocabularies;新地址函数是 provider-local 寻址,不创造 actor 生命周期或 quota 义务。没有通用控制面 substring denylist、domain-specific 强制推进文案或把 machine rejection 叫 guidance。Win32 从可能失败/错误字节读取改为同身份/精确字节,是明确披露的兼容性修复,不改变普通 POSIX 默认。live qualification 的拒绝开关已实跑,加载指导不是执行权限。共享锁调用者使 Win32 验收必须包含真实互斥/释放;不能仅凭 helper 字符串或更严格检查宣称语义闭合。
我的整体评价
体量、ownership 和未来重构适当:地址表示集中到最近的 dependency-light fs seam,原请求/锁生命周期仍同源;不需要另一个通用 abstraction,兼容同一持久文件身份必要。POSIX long_horizon 和 user_experience 已通过实际持久往返/恢复保留,没有增加用户选择或确认步骤;Windows 持续使用与失败恢复为 not_yet_proven。故 REQUEST_CHANGES 保留为明确证据 hold,认可作者新增的当前资格报告但不伪称独立实机验证。真实模型部分未执行,本机不假装具备 Windows。没有删除或撤销未核验评审、合并、复制 session、启动付费任务或关闭 #5039 整体验收。
English verdict: REQUEST_CHANGES - a7beb36: no reproduced code defect; affected-platform evidence hold. The author reports four current-head Windows passes, but independently inspectable execution provenance/results remain unavailable here. Immutable base/head real CLI/store and POSIX lock parity passed; 81 native tests passed, 4 Windows tests skipped, mypy 19 sources passed. No paid host call, CI polling or merge.
|
This pull request has merge conflicts with Choose the remote for the base repository, not an out-of-date fork. git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEADFor a same-repository clone whose Keep the DCO |
a7beb36 to
fca434f
Compare
|
Current affected-platform qualification for the evidence hold: head Windows 10 build 19045 / Python 3.13.5. Validation ran from this worktree using an explicitly selected compatible environment with the checkout installed. Before testing, Exact cases, all executed:
Command result: 4 passed in 25.63s; zero skipped; exit 0. Reproduction: from this head's source checkout, Final Linux qualification: 429 passed / 4 affected-platform skips (all four run above). Exact CI mypy/Ruff/TS typecheck/full semantic smoke, 28 typed peer-context/route/source-grant/digest cases and same-base CLI budgets pass. The archive CI repair reuses existing portable directory sync; Windows storage qualification passes 373, real PostgreSQL 335 plus service 10. The PR body scopes earlier paid-host evidence to its actual earlier head. English author repair verdict: READY FOR MAINTAINER RE-REVIEW with current affected-platform execution evidence. This is not independent maintainer approval or merge. Hosted checks have restarted. |
|
This pull request has merge conflicts with Choose the remote for the base repository, not an out-of-date fork. git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEADFor a same-repository clone whose Keep the DCO |
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com> (cherry picked from commit aa8a44fd01dfbc97c276a7a1d4e6b82539167c8c)
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
fca434f to
e6b3f97
Compare
Repair qualification on
|
huangruiteng
left a comment
There was a problem hiding this comment.
Reviewer: model_agent | GPT-5 | OpenAI
动机
使用 Windows 本机协作的操作者,需要把请求送到指定既有 peer,并在重启后读回结果;已确认团队分配的用户也需要看到稳定的完成回读。
以前完整请求地址加锁后缀可能超过 Windows 路径上限,阻断正常协作;前端刷新或迟到读取又会把已确认分配退回预览,让用户面对重复确认。
当前修复保留完整请求身份和同一把锁,读取原始二进制字节;确认后的结果在刷新和旧读取返回后仍保留,既不重新询问,也不重复提交。
不授权合并、付费宿主调用、跨宿主执行或会话复制;不宣称已安装客户端升级,也不关闭整个团队协作路线图。
这是既有本机 peer 与确认回读的有用增量;远程宿主及原议题 R2/R3 的持续协作验收仍由原 owning 任务推进。
评审完整 head e6b3f97,实际 merge base 60f0e64,15 文件 +495/−18。原 Windows hold 要求“可复核的去敏 source provenance 和四项实际执行记录,或独立实机复跑”。作者现在补齐新 head 的 Windows 10 build 19045 / Python 3.13.5 / loopx.file 来源核验,四个指定 node ID 实际运行、4 passed、0 skipped、exit 0;这一条满足原最小修复,不再机械维持旧 hold。明确:这是作者提供的当前源码记录,不冒称我在 Windows 上复跑。
spec_ref=https://github.com/loopx-project/loopx/issues/5039;原议题正文 spec_revision=sha256:54fda1c96674e6ae1d0194b28a566842cd47ede28e014e0d6183d95e0ce89369,另检查变更前协议。原 criterion_id:1. 精确既有 task、零替代 worker;2. 不可达历史候选不抹去其他候选;3. 区分 ambiguous/revoked/archived/cross-profile,不复制会话;4. 请求、采纳、返回和重启重试去重;5. directory 只读、公私安全。1./2./4./5. 的既有 owner 及本机增量通过本轮路由、真实 CLI/store 和 current-source Windows 记录验证;3. 保留原本机区分,跨宿主 R6 仍是原议题 deferred 边界,不由这份修复关闭。前端补修以既有 task-first delivery 与基线反例为验收,不拿新增断言自己定义正确性。
改动思路
peer 正路仍是 request→receiver read/adopt/report→requester return/consume/replay。路由预览仍只提供 locator、host_delivery=not_attempted;发现不等于发送,采纳不等于结果或租约。地址转换只指向同一物理文件,不截断完整 request hash、不换存储布局、不绕过锁。Python 留在本机文件/provider 适配边界,领域中立判断仍归既有 TS owner。
前端正路仍是 Goal 对话→既有计划卡→一次有必要的显式效果确认→已验证结果。服务端确认回读是事实源;现有 React Query 缓存先取消旧同 key 读取,再接纳该响应。不增加重新输入、额外授权、重复确认或第二个 effect writer。取消和 transition/regenerate 同样消费原 owner 回读;readonly 不改缓存。未来重构已应用在 dependency-light 文件地址 seam 和既有 query owner,未加入泛化框架。
具体改动
- windows_extended_path 处理 Win32 普通/UNC/已有扩展地址;POSIX 返回原 Path。Inbox _root 与锁 descriptor/claim 都复用它。
- _lock_id 规范地址表示后维持一个身份;原 token、排他、释放和损坏拒绝 owner 不变。四项 Windows 用例包括 >260 地址、跨进程排他,以及 holder 仍存活时释放再获取。
- input_readiness 选择平台支持的 nonblocking/binary flags;仍限制原工作区、普通文件、四 MiB 和精确 SHA-256,不提供内容。CRLF/Ctrl-Z digest 用例避免文本转换。
- acceptProposal 在原 Goal/manager query key 下 cancelQueries→替换同 proposal ID;personal-workspace-page 的 apply/cancel/transition 接入它,regenerate 移除被替代 ID。新增 steward-journey 延迟读取回归守住确认后的结果,而不是放松旧断言。
- 238 行 live qualification 明确需要 execute-real-host,会创建自己的两条合成宿主线程并使用模型额度;隔离临时 Goal/registry/runtime,退出前调用原 runtime shutdown。没有本轮付费运行,旧 a7 真宿主证据保持旧来源。协议、三类真实 fixture 修正、packaged metadata 及 self-repair guidance 与生产边界对应;上游 archive sync/Todo budget 重复改动已被删除,不算这份 PR 的行为。
对主干的风险
本轮原生 66 passed / 4 Windows-only skipped;真实 action/HTTP/TS/File owner 39 passed;当前 TS 路由、source grants、编排和 team-plan 24 passed / 5 PG-only skipped。advisory 后的全树语义、Ruff、mypy、diff 和 control-plane typecheck 均通过。Windows skips 保留为 skips,受影响 Windows 最小资格由前述当前源码执行记录补足;PG storage owner 未重构,五项跳过不冒称 PG 集成通过。没有查询、轮询或等待远端 CI。
用同一个不可变 fixture 在 base/head 运行实际 manager-inbox CLI/store 和真实 OS 跨进程锁:完整请求/采纳/返回/consume/replay、available→changed→unavailable digest 及排他/释放结果一致,只去掉 delivered_at 时间。fixture SHA-256=0bdf12913f9f4952be7a1706bb9fb4f4df23959991fa9939d3a008895a4a14a6,完整归一化观察摘要=29b61762ca8597d4f2cae6c7273875ed9ae3fffef8b0d5df02a2184cc27a630f。没有把正文、digest、错误、状态或 side effect 从比较中删掉。
当前源码分别构建真实 packaged bundle。同一固定 stale-read 场景(SHA-256=1534c24d3913984c5365c14dc1ca0902b74829c2ae267e16e94b8ebb50e4f513)在基线确实失败于“刷新保留已确认结果”与“旧读取不能重开确认”,当前 head 两条都通过;仍为一项 apply、一项持久 write。另跑 typed-actions 与 confirmed-operations,覆盖原取消、transition、stale/unavailable/readonly 等消费者;真实后端的变基、跨目标、失回复和原操作恢复另有 HTTP/TS/File 验证。浏览器 API 是合成替代、后端是真实独立配对,未宣称单次安装态端到端或真实模型资格。首屏结构/视觉 token 未改,结果和下一动作在原页面内保持清楚,不拿截图证明持久状态。
风险是共享 Windows 地址与缓存竞争,故不用普通 happy-path 代替长路径/字节/进程排他,也不用新鲜排序 mock 证明旧响应安全。缓存是派生投影,缺失缓存不等于 canonical absence;undefined 仍等待真实读取。未新增激活声明/required 字段、scope、额度、scheduler 或 lease authority。默认 Win32 与确认回读改善已明确披露;repair guidance 文本会改变,但不是执行义务。live smoke 缺少成本旗标时实测 argparse exit 2,先于任何宿主提交。
我的整体评价
APPROVE。原 Windows evidence hold 已按其原最小条件补足;新 head 的前端变化已单独做整份源码、打包、基线反例和真实 owner 复核,不沿用旧结论。long_horizon 的原请求恢复、结果返回和去重保留,user_experience 去掉了虚假的重复确认。两段小修复有独立回退边界,未来变化仍集中在既有 owner;更广 TS 迁移或远程宿主资格不应塞进这份 PR。
批准后按 capability 的 closeout 独立检查过期阻塞评审;只撤销已逐条核验解决且具 owner/GitHub 权限的阻塞,保留历史讨论与未解决异议。批准不是合并授权,未合并、未关闭父级目标。
English verdict: APPROVE - e6b3f97. Current-source four-case Windows record satisfies the original evidence minimum; real CLI/store/OS-lock parity and packaged stale-read base-fail/head-pass prove the bounded repairs. 66 native and 39 real owner tests passed; 24 TS passed with Windows/PG skips explicitly retained. No paid host call, CI polling, installed-client claim or merge.
|
评审来源补充(不是重复评审或新合并授权):本轮原批准使用可见的 GPT-5/OpenAI 家族自述,发布时执行 policy revision 15。期间 capability 更新到 revision 16,最新 host-recorded Turn 现在投影为下列来源;补足当前观察,不冒称它证明后端权重或活跃性。 Reviewer: model_agent | gpt-6.1-sol | OpenAI | runtime_reported | reasoning_effort=xhigh active_turn_verified=false。源码、执行回执和批准结论未改写;原完整评审与历史讨论保留。exact head e6b3f97 的 capability 回读结论仍有效;批准后、PR 仍开放时的 closeout 为 APPROVED、有效阻塞为空,无需撤销已被同账号批准取代的旧评审。随后相同 head 已被外部合并;当前 closeout 的 pull_request_not_open 不是新增技术阻塞。我未执行合并。 Review provenance addendum only: the latest host-recorded Turn is reported above; it is not authentication, liveness or backend-weight proof. Preserve the existing exact-head approval and its evidence. The unchanged head was subsequently merged externally; I did not merge or publish a duplicate approval. |
Goal and delivered boundary
Refs #5039. Repair the local-host Windows exchange failure. Full request hashes plus Inbox/lock suffixes exceed MAX_PATH; artifact hashing also requires supported binary/nonblocking flags. Preserve the same full identities, files, locks and exact artifact bytes through the existing Windows address seam.
The collaboration/manager_context owner retains route, adoption and return decisions. Route previews remain
not_attempted; selecting a peer grants no permission or lease. CLI/private Inbox and shared Windows lock I/O change; frontend/Lark retain their shared owner. This does not qualify remote-host execution or overall R2/R3 completion.Repairs
The bounded refactor places unchanged native-address conversion in dependency-light
runtime/file_paths.py, updates callers and removes the old internal entrypoint. The live qualification smoke isolates its typed runtime locator and shuts down through the existing API before deleting its temporary workspace.Rebase includes upstream's managed-Goal grant inheritance; added validation covers the existing peer context/source-grant owner. Upstream now owns the archive-sync and Todo-budget fixes; our duplicate commits were dropped, and neither file remains in this PR diff.
Related PR #5512 covers the nonblocking-flag fallback; this slice also preserves Windows binary bytes and qualifies full-identity long-path exchange.
Qualification
Head:
e6b3f979eabd83a3d9314bc17310f8b5c441f875. Base/merge base:60f0e64e45dd735be9d8ba5d1f3948540991c9f2, PR basemain. All 12 commits carry DCO sign-off.Final source-installed Linux/Python 3.11: 429 passed, 4 Windows-only skips, including lock/peer/handoff regressions, manager context and all demonstrated shared Python CI failures.
Final current-source Windows: Windows 10 build 19045, Python 3.13.5, selected compatible environment with verified
loopx.__file__source provenance. All four maintainer-requested cases ran, 4 passed, zero skipped, command exit 0:tests/test_file_lock.py::test_long_lock_paths_release_and_keep_one_identitytests/test_file_lock.py::test_long_lock_paths_exclude_other_process_and_release_while_holder_alivetests/test_peer_collaboration.py::test_peer_exchange_survives_long_private_store_pathstests/test_peer_collaboration.py::test_peer_binary_artifact_preserves_crlf_and_ctrl_z_digestReproduce from the intended source checkout:
uv run --extra test python -m pytest -qfollowed by the four node IDs above. Targets explicitly exceed MAX_PATH; cross-process exclusion and reacquisition while the holder remains alive are asserted. Binary checks retain CRLF and Ctrl-Z bytes.Exact CI mypy 1.20.2 (19 sources), CI Ruff, TS typecheck and full semantic smoke passed; typed peer route/context/source-grant/digest tests: 28 passed.
Earlier real authenticated Codex app-server qualification at
a7beb36ae4ba5f76addd5f8af33f89f4d17c7faepassed two existing synthetic peers, exact-thread restoration, independent adoption/review, exact head/digest return, one request after restart and zero replacement workers. That evidence retains its earlier source scope; the current affected-platform gate above was rerun without another paid model call.Public boundary scans are clean; raw host evidence remains private. Earlier paired CLI output-budget evidence retains its original source scope; no budget changed here. Hosted CI and maintainer re-review/merge remain required.
Current shared CI repair
The dashboard failure was reproduced: refreshing Goal status restored a cached pre-apply proposal and reopened confirmation after a verified assignment. The existing typed-action readback cache now cancels older reads and accepts the validated server response for apply/cancel/transition. No additional execution, authority, configuration or confirmation step is introduced. The strict completion assertion remains. Packaged before/after regression fails/passes for cached and delayed readback; exactly one apply and one durable write remain. The real TS/File team-plan owner and Windows peer gates passed together (10 tests).
Upstream supplies the File-journal decode optimization and the Python shard limit change from 30 to 45 minutes. Observed 30-minute cancellations used old remote heads; this PR adds no timeout or product-budget increase. The final rebase after frontend qualification adds only upstream tests, report fixtures and docs; browser/build inputs and selected #5039/#5205 Python regression inputs are unchanged.
Final Linux/Node 22.22.3 CI commands passed: dashboard unit coverage and all 38 browser scenarios. Packaged
steward-journey,team-plan,typed-actionsandconfirmed-operationsalso passed. Browser/build inputs are identical across the final test/docs-only upstream rebase. Hosted checks and maintainer review must run on this unchanged head; no approval or merge is claimed.