Conversation
Preserve receipt-bound monitor readback without reopening execution, authorize exact GoalRef context delivery without enumerating lifecycle registries, and align replan/session fixtures with the merged contracts. Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
|
This pull request has merge conflicts with Choose the remote for the base repository, not an out-of-date fork. git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEADFor a same-repository clone whose Keep the DCO |
Wait for a retiring Effect runtime locator before the safe retry and unblock a stopped delegation supervisor during forced cleanup. Align the fingerprint and replan fixtures with their current runtime contracts. Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…ontracts-20261003 Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com> # Conflicts: # loopx/chat_configuration_api.py # loopx/chat_goal_ownership_api.py # loopx/presentation/chat_goal_ownership_api.py # loopx/presentation/goal_ownership_api.py # tests/control_plane/test_cli_output_probe_runner.py # tests/control_plane/test_native_child_closeout_cli.py
…ontracts-20261003 Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
|
CI update for
Ready for maintainer review. I will not self-merge. |
…ontracts-20261003 Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…ontracts-20261003 Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
|
This pull request has merge conflicts with Choose the remote for the base repository, not an out-of-date fork. git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEADFor a same-repository clone whose Keep the DCO |
…ontracts-20261003 Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com> # Conflicts: # loopx/control_plane/collaboration/delegation_preview_bridge.ts
huangruiteng
left a comment
There was a problem hiding this comment.
Reviewer: model_agent — gpt-6.1-sol (OpenAI); runtime_reported; reasoning_effort=xhigh
Exact reviewed head: e5f1f9e
动机
反复核验委托和监控结果的操作者,需要在重启、超时和结算重放后继续同一个任务,且不留下重复 worker。
此前精确 Goal 实例会被通用目录限制挡住;现在精确目标可通过原实例与注册校验继续回传。另一方面,新的强制清理会忘掉仍存活的 worker,下一次核验又启动一个。
实测精确目标回传恢复,selected、blocked_targets 和取消 sender 的真实撤权均不发送;真实 supervisor 卡死后,两次超时核验留下两个仍存活的 worker,完整恢复尚未达标。
本轮限定精确目标授权、只读预检进程、runtime locator 和结算投影;不证明整个团队已接续、真实外部账户交付或模型质量提升。
改动思路
精确 GoalRef 已经提供 scope、Agent 注册和实例寿命证明,因此无需把 source-session registry 当成通用 runtime catalog 再枚举;源 sender/channel/policy 仍通过同一个 TS owner。预检复用只用于长驻 MCP,只读 worker 的 process group 仍应由原 Host supervisor 收尾。可恢复的等待和已结算 monitor 的历史观察都不能变成第二次执行权限;任何 lifecycle 优化须保留这个失败边界。
具体改动
独立规范索引:docs/reference/local-delegation.md; docs/reference/protocols/manager-evidence-and-continuity-v0.md; docs/reference/protocols/quota-monitor-observation-receipt-v0.md,固定版本 558d214。逐项映射 Use an existing Agent conversation through its shell:当前未满足 single-worker、process-group cleanup 和 uncertain-cleanup 禁止重试;Ownership and defaults:精确目标通过原 Goal 实例、注册与源授权,真实撤权拒绝通过;Contract:settled 重放继续 should_run=false、must_attempt_work=false、next_turn_required,没有第二次结算权限。没有用修改后的输出或作者“兼容性”标签代替原合同。
关键代码讲解
source_context_target_authority 复用 _source_context_grant 和 TS collaboration.source.recipients,参数来自先验证的 exact Goal scope;通用目录路径仍拒绝 source_session_v1,因此修复定点回传并未开放整个目录。_close 在真正 cleanup 之前清空 process、partition、sequence 并 detach finalizer;_close_bridge 超时后只 kill Node supervisor。这两段结合,旧 detached worker 尚在运行也会允许下一次 replacement。_wait_for_runtime_locator_turnover 在发送前失败后有界等待旧 locator 换代,未删除 live locator;这个 250ms 等待只是恢复适配,不证明长期 runtime 关闭所有故障。apply_settled_monitor_precedence 恢复历史 selected_todo/next_action,执行权限仍由 settled_replay_fields 置为 skip。
Diff 是 21 文件 +360/-72。7 个生产文件涉及四个适配边界,12 个测试主要修正已有 guard/binding 与输入预期,两个 inventory 更新通过 semantic census。未来重构检查认可 source grant 抽取成一个 policy observation;进程恢复应继续复用 Host group owner,不能因 kill 成功再建一套 Python child 生命周期判断。当前没有新增 capability、公共选项或新的 persisted phase。
对主干的风险
[P1] supervisor 退出不能代替 worker group 停止。 delegation_preview_transport.py:112–121 在 cleanup 前清空 owner,65–96 的强制 kill 仅针对 Node 进程。真实 public preview 探针启动 detached Python worker,让 worker 收到请求后写出 PID 并 sleep;Node preload 在看到该 PID 后用 Atomics.wait 阻塞事件循环,使 EOF/SIGTERM handler 不再处理。保持生产 5 秒 cleanup timeout 和 1 秒请求 timeout:首次约 6.013 秒返回 TimeoutExpired,旧 worker 仍活着;同一 transport 再调用,约 6.016 秒后共有两个 live workers。所有 probe 都是 disposable fixture,finally 清理了这两个 group。原基线在 close 阻塞并保留 _process,探针通过明确的外部救援终止;没有把这个救援冒充原实现正常 cleanup。当前测试只给 supervisor 自身设置忽略 SIGTERM,没有 child,故无法发现此反例。最小修复:保留未知清理状态的 owner/partition,只有原 Host owner 已证明旧 process group 停止时才允许 replacement;supervisor 被杀不能充当 group cleanup fence。复用现有 Host 边界,避免新增平行 Python 生命周期规则。
[P2] 实际撤权集成用例仍失败。 source suite 72 passed / 1 failed,其中 revoke=True 只把 targets 置空;当前 TS owner 默认 all_registered,因此这不是撤权。独立探针确认:清空默认 targets 仍可发送,但 selected 模式清空目标、blocked_targets 或取消 sender 各为零发送。这不是权限绕过,不能靠改默认语义“修绿”;应修 fixture 并保留真实 no-send 与恢复断言。完整扩展套件另有 412 passed / 1 failed:read_only_settlement_omits_non_causal_delivery_workspace 的 hook intent_count=0,单独 head 跑通过、base 单独跑失败;在这组有界结果下不能宣布间歇性问题已解决,也尚未判定因果。保留这项未决验证,不挑选绿色重跑替代完整结果。
语义与 CI 对齐
两份 semantic inventory 和既有 typed vocabulary 被复用;development advisory 未发现新 closed set,full-tree semantic/ratchet 与全部选择的 canary 技术检查通过,未读取或等待远端 CI。generic CLI 一次性 inspection 与普通 chat 不启用 resident preview,现有 entrypoint isolation 用例通过。selected_todo 在 settled 结果中现在重新出现,应把旧文档的历史身份说明补充为明确的只读观察,并强调 must_attempt_work=false;不能当新任务或第二次 spend。主要违反的既有合同是 local-delegation.md 的“uncertain cleanup never grants retry permission”,不是未来 stop RFC 的建议要求。
我的整体评价
REQUEST_CHANGES。精确源实例的定点回传和共享 source grant 抽取有正向价值,降低无意义的目录阻塞,user_experience=improved;真实 selected/blocked/sender 拒绝未被绕过。long_horizon=regression:强制退出变快了,但未知清理状态被丢弃,重复核验积累 worker,效率与资源安全反而下降。修复应围绕已有 Host 证明和原 owner 保留,不需要扩大成新框架。历史选中项仅作观察时可接受,但必须明确只读语义;集成中的陈旧撤权 fixture 和未决 hook 结果也应保留真实的 failed/untested 区分。
English verdict: REQUEST_CHANGES — exact-target authorization usefully reuses the existing typed source policy after GoalRef/membership validation; actual selected, blocked-target and sender revocation all prevent sending. The forced preview cleanup is unsafe: it clears transport ownership and kills only the Node supervisor, while the detached Python worker may remain alive. With the production five-second cleanup wait and a blocked Node event loop, two one-second public preview calls each return after about six seconds and leave two live workers. Keep an uncertain-cleanup owner/partition and refuse replacement until the original Host proves group retirement. Add a real descendant test; the current supervisor-only SIGTERM test misses this. Also fix the stale source-session revoke fixture: clearing targets under all_registered is not revocation. The expanded suite has an unresolved intermittent hook-count failure; isolated success does not erase it. Selected canary technical checks passed, CI was not queried, and no merge was attempted. Long-horizon resource behavior currently regresses despite the useful exact-target UX repair.
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…ontracts-20261003 Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent — gpt-6.1-sol (OpenAI); runtime_reported; reasoning_effort=xhigh
Exact reviewed head: 8039296
动机
反复核验委托和监控结果的操作者,需要在重启、超时和结算重放后继续同一个任务,且不留下重复 worker。
此前精确 Goal 实例会被通用目录限制挡住;现在精确目标可通过原实例与注册校验继续回传。另一方面,新的强制清理会忘掉仍存活的 worker,下一次核验又启动一个。
实测精确目标回传恢复,selected、blocked_targets 和取消 sender 的真实撤权均不发送;真实 supervisor 卡死后,两次超时核验留下两个仍存活的 worker,完整恢复尚未达标。
本轮限定精确目标授权、只读预检进程、runtime locator 和结算投影;不证明整个团队已接续、真实外部账户交付或模型质量提升。
改动思路
精确 GoalRef 已提供原实例和 Agent 注册证明,目标回传应复用这个 scope 与原 source grant,不再通过不兼容的通用目录枚举。只读 preview 仍由 TS Host 管进程组;结算后的 monitor 只能展示原身份,不能获得第二次执行或扣费。配置备份的新增移动应保持 CLI、HTTP 和完整备份调用一致。
具体改动
逐项读完本 head 的 29 文件(+418/-107):manager_context 的目标授权与回传注册检查;source grant 共用 helper;Python preview 强制清理与 TS lifetime 起点;runtime locator 的最多 250ms 退场等待;settlement 历史身份恢复;两处内部 configuration backup 模块移动及全部 importer;两个 typed inventory/census;canonical planning、replan binding、fingerprint、Lark 结构化上下文、monitor 与 host recovery 夹具。配置移动没有新增 API 或权限,既有真实 CLI/HTTP 备份、摘要拒绝、occupied target 和 state-backup 测试通过。
关键代码讲解
source_context_target_authority(loopx/control_plane/collaboration/source_grant_observation.py:109):接收已经验证的精确 target,继续调用同一 TS recipient owner,grant 仍只允许 context delivery。_exact_return_scope(loopx/capabilities/manager_context/roundtrip.py:379):把原 Agent 加入 scope 注册检查;原会话和实例不可被别名替换。_close(loopx/control_plane/collaboration/delegation_preview_transport.py:112):清掉 process、partition、sequence 和 finalizer 后才清理进程;当前 P1 就在这个顺序及 parent-only kill。apply_settled_monitor_precedence(loopx/control_plane/quota/settlement_precedence.py:121):恢复 receipt-bound 历史选择,同时保留 should_run=false、must_attempt_work=false 和 settled phase。历史身份不是执行授权。
独立验收依据为 docs/reference/local-delegation.md; docs/reference/protocols/manager-evidence-and-continuity-v0.md; docs/reference/protocols/quota-monitor-observation-receipt-v0.md,固定版本 e15af3968f8ae20d117795a5d427624f2b85cc28。Use an existing Agent conversation through its shell not_met:不确定 process-group 清理不能允许 replacement。Ownership and defaults implemented:exact source 回传恢复,selected、blocked_targets、sender 撤权均不发送。Contract implemented:monitor CLI 重放保持已结算、不重复执行。
对主干的风险
[P1] supervisor 被强杀后仍允许启动第二个 worker。 在真实公开 preview 入口让 Node event loop 无法处理 SIGTERM,保留实际 detached Python worker,使用生产 5 秒 cleanup:第一次 6.006 秒超时后有 1 个活 worker,第二次 6.011 秒后有 2 个;两次 transport 都已 reset。临时进程已由探针 finally 清理。这与普通 SIGSTOP 可恢复或仅检查 supervisor.poll 不同。保留未知清理状态的 owner/partition,只有原 Host owner 已证明旧 process group 停止时才允许 replacement;supervisor 被杀不能充当 group cleanup fence。复用现有 Host 边界,避免新增平行 Python 生命周期规则。 回归必须同时观察父进程、worker group 和第二次 admission。
[P2] 原 revoke=True 夹具仍把清空 targets 当撤权。 tests/test_collaboration_goal_instance.py:1044 未设置 selected scope,默认 all_registered 仍授权已注册 target;本 head 实际 sends=1。应让夹具明确 selected-empty、blocked_targets 或撤销 sender。不要改变默认授权范围去迎合断言;三个真正撤权场景均已实测零发送。
当前扩展测试 546 passed / 1 failed(上述夹具),另有一条 pydantic-settings forward-reference warning。premerge 18 项选择检查及直接 diff/compile/ratchet 通过;semantic advisory 零受支持新 vocabulary carrier,不把空报告当语义证明。未读取、轮询或等待 CI。上一 head 的 hook-count 间歇失败保留在历史证据,当前整套覆盖相同断言通过,未宣称已查清其历史原因。没有外部账户、付费模型或完整 packaged frontend 验收声明。
我的整体评价
REQUEST_CHANGES。long_horizon=regression:反复 timeout 增长 worker,当前清理优化对长期资源和恢复效率是负向。user_experience=improved 的有限部分是 exact 目标不再被目录限制挡住,monitor 历史身份可读;这不能抵消 P1。没有新 actor lifecycle、claim/lease 或默认 opt-in;原 TS source/settlement owner 和闭合集合复用,新增 Python 仅做 IO/生命周期适配。future-facing pass 已检查 backup placement 和共用 grant helper,后续应修原 Host cleanup proof。此 head 不批准、不合并,两个旧 blocker 均保留。
English verdict: REQUEST_CHANGES - 8039296; repeated timeout leaves live detached workers while the transport resets, and the revoke fixture is still invalid under all_registered. 546 tests passed, one fixture failed; 18 local premerge checks passed.
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…ontracts-20261003 Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
The timeout path cleared transport ownership after SIGKILLing only the Node supervisor, so another preview could start while its detached worker remained alive. Keep the original owner and partition unless normal Host completion or a retirement fence proves process-group cleanup. Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
|
This pull request has merge conflicts with Choose the remote for the base repository, not an out-of-date fork. git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEADFor a same-repository clone whose Keep the DCO |
…ontracts-20261003 Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com> # Conflicts: # tests/extensions/test_lark_goal_topic_connections.py
The local Goal delivery guard added on main correctly rejects the old out-of-root success fixtures. Run successful host and validation paths from the registered Goal workspace while retaining dedicated rejection coverage for unqualified workspaces. Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Goal And Delivered Outcome
main; related to fix(ci): restore shared source qualification contracts #5526.main.Author Declaration
Implemented against
main@e55489c77and the request in this PR are the basis.source_context_target_authorityapply_settled_monitor_precedencetests/test_loopx_turn_executor.pyScope And Continuation
Validation
17590f29bunitpassedstaticpassedgit diff --checkintegrationpassedregression_paritypassedstaticpassedFrontend / Visual Evidence
Type of Change
LoopX Area
Technical Direction
Shared-authority RFC fixture impact
Boundary Checklist
.loopx/,.codex/goals/, and liveACTIVE_GOAL_STATE.md).none.Signed-off-bytrailer (git commit -s).