Skip to content

fix(leases): normalize observed worktree repository identities - #5584

Merged
huangruiteng merged 2 commits into
loopx-project:mainfrom
catwithtudou:codex/fix-worktree-lease-repository-identity
Oct 5, 2026
Merged

huangruiteng merged 2 commits into
loopx-project:mainfrom
catwithtudou:codex/fix-worktree-lease-repository-identity

Conversation

@catwithtudou

@catwithtudou catwithtudou commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Goal And Delivered Outcome

Fix a reproduced rejection of valid independent-worktree code-edit leases. A Todo for git:github.com/example/project matches ssh://git@github.com:22/example/project.git, but the worktree observer retained :22 and acquisition rejected it as lease_workspace_repository_mismatch. The supported git:// transport was also rejected.

The observer now uses the existing Todo repository codec after its origin transport check. Default ports and safe repeated path separators normalize consistently; nondefault ports stay distinct, and unsafe raw paths/password-bearing origins fail closed.

actual Git origin → transport admission → existing Todo identity codec → lease matching
  • Basis: self-contained reproduced defect in the shipped task-lease acquire --write-worktree command; base main at 1af7dbd43a1629b0356ecd5ee28a426ad45d1d7a.
  • Existing TypeScript work-item owner; no new capability, provider, dependency or Python decision owner.

Author Declaration

  • Written by: model_agent · GPT-6 · OpenAI (self-reported).

Implemented against

Specification: docs/reference/canonical-lease-renew.md, “Repository-relative scope identity” and “Independent worktree code edits,” plus normalizeTodoRepository in loopx/control_plane/todos/work_requirements.ts, at base 1af7dbd43.

Criterion Disposition Implementation / evidence
Origin matches the Todo's canonical repository implemented Shared raw-remote identity codec; independent Git origin vectors and real File/SQLite CLI acquisition
Different repositories/ports and unsafe workspaces remain excluded implemented Nondefault-port mismatch, same-worktree conflict, redirected paths, invalid-origin tests
Replay and lifecycle preserve frozen workspace identity implemented Public CLI replay, renew, inspect and release on both providers

Self-check: traced the sole observer caller and canonical acquisition decision; checked related current PRs; verified default/nondefault ports, credentials, raw path semantics and ambiguous canonical-looking origins. Independent Standards and Spec reviews report zero findings at the tested head.

Scope And Continuation

Complete within this bounded repair. The related simplification replaces duplicate identity-generation knowledge with the existing typed owner; transport admission and physical worktree checks retain their own responsibilities. Historical leases are not migrated, backfilled or widened. Code rollback is reversible; ordinary lease lifecycle remains available. Broader frontend/Lark collaboration and cross-host qualification are outside this fix, with no claim that those programs are complete.

Validation

  • Tested revision: bc5a73aa1fefb5a9809a9180e1f5134053b24547.
  • Run state: finished.
  • Input classes: synthetic, public_fixture.
  • Environment: Python 3.12.10, Node 22.22.3; real temporary Git worktrees and isolated File/SQLite authority.
Check kind Result Public-safe evidence / limitation
regression_parity passed The same public CLI cases on unchanged product base give 4 failed / 4 passed; final head gives 8 passed. Default SSH/Git ports fail before and work after.
real_entrypoint passed tests/test_task_lease_worktree.py: acquisition, mismatched port, sibling overlap advisory, same-worktree exclusion, redirected paths, retries, renew, inspect, release, and path-free persisted identity on both File/SQLite.
unit passed task_lease_workspace.test.ts: 17 passed / 1 PostgreSQL skip; five new origin subcases fail on base. Independent review exercised an additional accepted/rejected origin matrix.
static passed TypeScript typecheck, configured Ruff and mypy, diff-scoped semantic advisory, full semantic smoke, git diff --check; isolated public-boundary scan: 3,484 files, zero errors/warnings.
real_entrypoint failed Premerge: 13 of 15 selected checks pass, plus all four direct/compile checks. Maintainability ratchet references removed loopx/status.py (inherited advisory); refresh-state smoke lacks required registered agent identity. Both failures reproduce on unchanged base. Task-lease runtime and all eight selected risk-profile smokes pass.
real_entrypoint passed CLI output budget comparison pinned to immutable base 1af7dbd43.
unit passed Complete TypeScript suite: 4,005 passed / 31 conditional skips / zero failures on the unchanged tested revision.
unit failed Complete Python suite on final head: 16,113 passed / 102 failed / 83 skipped. All eight worktree CLI cases pass in this run. Re-running the 102 failures on unchanged base gives 101 failed / 1 passed; the remaining case also passes when rerun on final head.
real_backend passed (CI); not_run (local) The PostgreSQL Integration real-server job passed for this PR. The original local PostgreSQL test was skipped without a disposable server; File/SQLite CLI evidence remains separate.
manual not_run Native Windows worktree identity remains unsupported by the existing command; live hosts/cross-host operation were not exercised.

The full Python failure that did not reproduce in isolation is test_missing_cursor_cannot_reuse_a_sequence_when_the_next_writer_arrives_first; its full-run cause remains unresolved. The other 101 cases also fail on unchanged base across existing control-plane, collaboration, inventory, runtime and qualification checks. Neither the full Python suite nor premerge is claimed green. Later main f35978e3a does not touch the four files in this PR; all comparisons remain pinned to the stated base.

Coverage and gaps: no checks were disabled or budgets relaxed. Broader failed checks remain failures, separate from the demonstrated corrected lease journey.

CI follow-up (2026-10-05)

The Python Tests run is failed, not merge-ready. Its checkout is merge commit a5fef283fe4346b843c13f1b914fdddcd7f62b83, combining this unchanged head with main f35978e3a1289a146687346467b848bfca8fa2b0.

  • Acceptance regression attributed to main: node --no-warnings --experimental-sqlite --experimental-strip-types --test tests/control_plane_ts/goal_acceptance_runtime.test.ts, with Node 22.22.3, gives 15 passed on PR head, 13 passed / 2 failed on both the CI merge and its unchanged main parent, and 15 passed on fix(control-plane): restore merged contract compatibility #5533 at 647a5e8d381867418b2d0a309d12aabed0d1fc8a. Both failures are the same stale versus ready assertions reported by CI. fix(control-plane): restore merged contract compatibility #5533 adds the newly introduced completion_receipt_id to NON_WORK_FIELDS, so lifecycle receipt metadata does not change the work digest. That upstream repair is not copied into this lease PR.
  • Stage2C locator failure attributed to main: both this PR and fix(reliability): preserve diagnostic event chronology #5572 stop at obsolete remove_refresh_cas. The focused case reproduces mutation locator drift on unchanged main f35978e3a. Independently running test(stage2c): align refresh mutation with no-write contract #5613 at 994b9ea6e8f268254bdc1b4864f1dfb5c91f24e4 with --case public_refresh_writes_owned_paragraph gives control exit 0, mutant exit 1, killed by assertion. Only this focused mutation was rerun here; the entire mutation suite was not requalified.
  • Lease entrypoint on the CI merge: uv run --extra test python -m pytest -q tests/test_task_lease_worktree.py gives 8 passed on a5fef283f, using Python 3.12.10 and qualified Node 22.22.3 for the real File/SQLite CLI cases.
  • Remaining CI failures: the four Python shards report 145 failures. They have not all been reproduced or attributed in this follow-up. The historical 102-failure local comparison above is not treated as an explanation of this different CI run. No tests or gates were relaxed, and the identified upstream repairs are not claimed to make the full suite green.

Frontend / Visual Evidence

  • UI impact: none; this repairs an existing CLI filesystem-observation path. No frontend caller of write_worktree is changed or added.
  • Before/after: rejected matching origin → acquired scoped lease, asserted by the real CLI tests.
  • States/viewports, source images and attention review: not applicable; no visual surface changes.

Type of Change

  • Bug fix
  • Documentation update
  • Test update

LoopX Area

  • Control plane (goals, todos, quota, scheduler, registry, runtime)

Technical Direction

Shared coordination: correct repository identity at the existing independent-worktree lease boundary.

Shared-authority RFC fixture impact

No fixture schema, provider transaction, promotion, routing or compatibility projection change. File/SQLite CLI arms run as above. The GitHub PostgreSQL Integration real-server job passed; local PostgreSQL and the broader three-arm RFC rehearsal were not run. No broader RFC completion claim.

Boundary Checklist

  • No private state, credentials, raw traces, internal links or local machine paths in the diff or PR. Invalid credential cases use explicit synthetic fixture values.
  • No duplicated maintainer-owned benchmark work.
  • Scope is limited to the reproduced defect and existing contract.
  • UI impact marked none.
  • Both commits include DCO sign-offs using the contributor's GitHub noreply address.

Signed-off-by: catwithtudou <42607255+catwithtudou@users.noreply.github.com>
Signed-off-by: catwithtudou <42607255+catwithtudou@users.noreply.github.com>

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent · gpt-6.1-sol · OpenAI · runtime_reported · reasoning_effort=xhigh

Exact head: bc5a73aa1fefb5a9809a9180e1f5134053b24547
Immutable base: 1af7dbd43a1629b0356ecd5ee28a426ad45d1d7a

动机

使用独立 Git worktree 领取代码编辑租约的执行者会遇到这个问题。

例如 Todo 指向普通 GitHub 仓库,而 origin 显式写 SSH 默认端口 22:旧版把同仓库当成不同仓库而拒绝领取,新版归一化后可领取;Git 默认端口 9418 的 URL 也能通过已有身份规则。

本轮同一真实 CLI 用例在固定 base 是四失败四通过,在精确 head 是八通过,确认有效 worktree 不再因默认端口误拒绝。

本 PR 只修复已有 CLI 的仓库观察,不授权共享运行数据、Git 管理、远端写入或合并,不迁移旧租约,也不宣称跨主机或完整多 Agent 前端旅程已完成。

改动思路

真实 Git origin 先通过 transport admission,然后复用已有 Todo raw-remote codec,再由 canonical acquire decision 比较 Todo 的仓库。物理 worktree、机器/目录身份、非空代码 scope 和 provider CAS 仍各自负责原边界,没有第二份仓库解析规则或新的授权字段。合法 origin 归一化后领取、重放、续租、inspect、release;错误端口、同 worktree 和 ignored symlink 仍先拒绝或报告排他冲突。

具体改动

Specification: docs/reference/canonical-lease-renew.md at 1af7dbd43a1629b0356ecd5ee28a426ad45d1d7a。按变更前文本判断 head 对规格的编辑;没有用修改后的文字证明自己。

  • Repository-relative scope identity — implemented:Freeze the canonical Todo repository; no caller repository override. 由上述现有 owner 与本轮真实路径验证覆盖。
  • Independent worktree code edits — implemented:Verify worktree/origin and retain repository mismatch, physical isolation and ordinary exclusion. 由上述现有 owner 与本轮真实路径验证覆盖。
  • Acquire retries must use the same worktree — implemented:Retain frozen workspace/repository across replay, renewal, inspection and release. 由上述现有 owner 与本轮真实路径验证覆盖。

关键代码讲解

  • loopx/control_plane/work_items/task_lease_workspace.ts:49 / observeLeaseWorktree:验证物理 worktree/transport,再复用 Todo 的 raw-origin codec;不保存本地路径。输入来自 canonical Todo 与真实 Git origin,失败继续交给既有 typed owner,消费者仍读原回执。
  • loopx/control_plane/todos/work_requirements.ts:17 / normalizeTodoRepository:忽略显式默认端口、保留非默认端口;检查原始路径与密码。输入来自 canonical Todo 与真实 Git origin,失败继续交给既有 typed owner,消费者仍读原回执。
  • loopx/control_plane/work_items/task_lease_acquire_decision.ts:324 / evaluateTaskLeaseAcquireDecision:比较 authoritative Todo 与观察仓库,只有已验证 sibling isolation 将冲突变成 advisory。输入来自 canonical Todo 与真实 Git origin,失败继续交给既有 typed owner,消费者仍读原回执。

四文件 +76/-5:生产代码 +4/-2、测试 +63/-3、文档 +9。扩展现有 CLI 参数化验证,并用 bilingual 文档披露默认端口和危险路径的变化;未加模块、CLI flag、provider 或 migration。

对主干的风险

最危险的回归是把真正不同的仓库或非默认端口当成相同,从而错误放松 scope 排他;另一个方向是 WHATWG URL 先消除 dot segment 导致危险 raw path 被接受。

真实 File/SQLite CLI 8 passed;额外 raw origin 与无副作用拒绝案例 2 passed;TS 76 passed / 1 conditional PostgreSQL skip;typecheck、Ruff、advisory 和全树 semantic smoke 通过。本轮仅在 disposable synthetic state 运行,未修改活动 Goal 来做验证;没有查询、轮询或等待 CI。

同一 head regression harness(SHA-256 86428ecfaab922e2ae149d219019d1543683c4487ad27b4408864f96c68e6612)在 base 是 4 failed / 4 passed,在 head 是 8 passed。失败具体是显式 SSH :22 的仓库 mismatch 与 git :9418 的 transport refusal。额外 public CLI 验证 password、dot segment、percent path、query、file/canonical-looking raw origin 拒绝,且 inspect 没有留下 lease;恢复合法 repeated separator origin 后完成原 lifecycle。新建 canonical Todo 的同 worktree 写入仍 conflict,普通未请求 worktree 的 Todo 也保持冲突。PG 的一项旧持久化用例因无 disposable server 跳过;本改动不重构 PG provider。

语义与 CI 对齐

复用已有 typed repository vocabulary;显式默认端口和安全重复分隔符的接受变化及危险 raw path 拒绝已披露。ordinary lease 不进入 observer,无自动 promotion 或授权扩张。Generic errors 仍领域中立,排他/receipt 校验属于 machine enforcement,不称为普通 guidance。semantic advisory 和完整 smoke 通过不代表自动证明等价;CI 按当前 policy 不咨询,merge gate/冲突与代码 review 结论分开。

我的整体评价

APPROVE:本有界目标 goal_achieved。long_horizon preserved:Lease replay/renew/release and scoped isolation retain durable continuation. user_experience improved:本轮同一真实 CLI 用例在固定 base 是四失败四通过,在精确 head 是八通过,确认有效 worktree 不再因默认端口误拒绝。

Persisted lease/workspace/receipt schema is unchanged. Existing leases remain conservative; no backfill. Raw origin observation deliberately changes only new acquisition/replay admission. 未来改动的 bounded refactor pass 已落实为复用现有 owner;没有必要加额外框架或复制 policy。改动与实际 caller 成本相称,未找到当前 blocking finding。Windows/跨主机、生产持续负载与模型实际采用保持未测;没有宣称整个 Goal 或上层 RFC 完成。本结论仅绑定上述 head;更新或集成冲突解决后需重新核验。此处发布代码批准,未据此获得社区 PR 的 merge 权限。

English verdict: APPROVE - bc5a73a. Shared repository codec fixes default-port worktree acquisition; independent real File/SQLite base/head regression, negatives and lifecycle pass. PG/other hosts untested; no merge authorization implied.

@huangruiteng
huangruiteng merged commit cf545a1 into loopx-project:main Oct 5, 2026
25 of 35 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants