Skip to content

Qualify explicit registry routing in Turn output budgets - #5374

Merged
huangruiteng merged 5 commits into
mainfrom
codex/registry-command-budget
Sep 30, 2026
Merged

huangruiteng merged 5 commits into
mainfrom
codex/registry-command-budget

Conversation

@huangruiteng

@huangruiteng huangruiteng commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

After #5363 made writeback commands carry their explicit registry, the crowded Turn fixture grew from 14,482 to 14,557 characters against a 14,500 regression ceiling. The 75 added characters route the command to the right registry; removing them would weaken the authority binding. The differential oracle also recognized runtime-root routing costs but missed registry routing, causing five comparative failures.

Reuse the bounded command-route allowance for both bindings, parse decoded JSON/Markdown command argv once for both option orders, and retain review signals for newly added routes. Missing, malformed, negative or unchanged counts grant no extra allowance. Empty/missing option values, broken quoting, incomplete prefixes, empty/whitespace-only subcommands and invalid formats do not count as valid routes; duplicate bindings count only once per command. Reconcile the crowded absolute ceiling to 14,600 (43 characters of margin), preserving line/per-Todo growth limits. Actual CLI assertions protect complete registry/runtime arguments; both the vision-authoring and oversized-stdout rejection tests now share the single budget definition. No runtime state, permissions, or UI behavior changes.

Validation: final integration passes 139 tests (133 output cases plus six real File/SQLite settlement and lease cases). The 133 CLI output/differential/probe-runner tests pass; original base 04bf6b6c1c1d37d3b19194c91efe5b4c4d9daa7d and candidate were re-probed with the same 102-row fixture and pass comparison, retaining 16 registry-routing review signals. Original failing #5363 receipts remain evidence. Focused Mypy (two modules, follow-imports=silent), Ruff and diff/private-boundary checks pass. Final premerge passes all selected checks and the public/private scan; exact-scope quality receipt cqr_5cadb30cb7a1219c7883 is valid.

After synchronizing the already-reviewed #5372, the PR diff remains byte-identical to the independently approved pre-integration diff; final integration premerge also passes. The new commit requires its own exact-head review.

This is an evidence-backed regression-budget reconciliation, not a transport/quota limit increase. Python placement follows the existing repository-native validation owner; no second production decision owner is introduced.

Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Reviewed exact head: dcafdf8e09867af8db6ce33d68d1f9b0bc02c178; immutable merge base: 3156771e47268433c4b4b233bd37bdd3f2b37726; original pre-routing comparison: 04bf6b6c1c1d37d3b19194c91efe5b4c4d9daa7d. 本文执行当前 pull_request_review_execution_contract_v2(policy revision12),重新审阅全部7文件,不继承作者CQA/测试结论。无剩余阻塞发现。

动机

#5363 的正确registry绑定使同一crowded Turn观察从14,482增到14,557字符:原14,500回归预算失败,旧differential又只识别runtime-root,造成5条比较失败。这里保护的是agent看到的输出成本,不是硬quota、benchmark评分或冻结promotion门槛。75字符提供实际命令目标,不能为了预算删掉。保留原失败、确认同负载和消费者价值后,才判断预算应如何协调。

改动思路

复用最近的输出预算和route allowance owner:只把crowded JSON ceiling调到14,600,剩43字符;400行与60字符/Todo增长约束未放宽。已有160字符/UTF8字节/compact allowance适用于新观察到的必要registry/runtime-root绑定,使用max而非叠加普通或migration预算,额外行预算为0。缺失、bool/string、负值、相同或减少count不能赚额度;下一次count已成为baseline后恢复普通增长检查。没有新增能力、参数或第二个生产状态决策源。

具体改动

  1. 现有probe在一处派生两个route count;JSON先解码再shlex解析,不把空registry、option当值、坏quote、缺命令、空/纯空白命令或无效format作为新route。重复同一binding只计一次。未知未来global option保守不授额,而不是复制整个CLI命令目录。
  2. differential复用既有有限metric规则,为两种binding各保留可见review signal;102条实际观察没有缩窄或改写stdout。vision authoring与oversized stdout test改为读取同一个共享ceiling,避免旧14500文字使正确negative测试本身失败。
  3. crowded实际CLI assertion仍要求返回的next_cli_actions保留精确registry和runtime-root;不是仅测试field存在,也不以compaction隐藏目标。没有frontend/Lark companion需要:完整diff只改变repository qualification observer/预算/tests,CLI producer、settings编辑器、公共操作步骤和installed prompt都未改。

关键代码讲解

  • cli_output_semantics.py:203 command_route_counts:遍历实际渲染的JSON/string或Markdown code;shlex建立argv,按合法完整option prefix检查,只有非空subcommand才能形成diagnostic count。它不验证provider readiness或执行权限。
  • cli_output_differential.py:312 _command_route_growth_allowances:只认exact int与0 <= before < after,按新增binding数计算160有限成本;_compare_row仍保留普通增长/semantic检查及提示,没有全局waiver。
  • cli-output-probe-runner.py:44 _receipt_row:同一observer调用生成两个派生字段,继续保留真实stdout metric、signature、schema/shape等已有证据,供版本化comparison消费者读取。
  • cli_output_budget.py:73 CLI_OUTPUT_BUDGET_SPECS:单一绝对预算定义解释14,482→14,557及43margin;不另造vision/probe平行ceiling。future-facing pass已落实为共享observer、退役旧helper与去掉测试重复知识,未扩张CLIcatalog框架。

对主干的风险

最强反例不是远端红CI,而是observer把非法命令算成新route后误放行输出增长。ffe7最初的empty-registry漏项、probe固定14500断言均已被修正;b10d虽通过127项测试,仍将loopx --registry /tmp/review-empty-subcommand-registry ""计为registry1。真实CLI exit2;实际_receipt_row+compare_cli_output_receipts把同形JSON的41→141字符(+100)错误判passed,160allowance;不授route则按64拒绝。同一独立oracle在immutable315基线通过、b10d失败,当前exact head通过,原失败回执保留。修复只拒绝空/纯空白subcommand,并覆盖raw/JSON/Markdown;没有继承“上一问题已修”就自动批准。

我自己重跑:133 passed in 38.17s、7个changed-file Ruff、2个source focused Mypy(follow-imports=silent)、changed-diff semantic advisory,以及最终全部selected risk/catalog/boundary premerge。实际CLI原不可变04bf与候选使用相同观察器/完整102行fixture;候选没有measurement-only逃逸,absolute通过;比较102/102通过,16条registry signal仍可见。crowded实际值14,557/393行;重放结果没有删除identity、改raw输出或缩小population。独立empty-registry和empty-subcommand realCLI/productionbuilder负例通过;missing/类型/负值/unchanged/321越界及actual oversized stdout仍拒绝。

语义与CI对齐

这是公开可复用的Python测试观察边界,不是新增通用control-plane生产决策owner;已有typed TS permission/state rules、持久化和真实PostgreSQL入口没有改动,故不伪称运行PostgreSQL集成或部署资格。派生receipt count不是额外authoritative state;missing旧receipt字段不授新额。没有opt-in/default-off claim或更宽actor协议。budget失败是机器执行条件,review signal只是提示,两者不混称guidance。wait_for_ci=false:不获取、等待或因无关远端红CIrequest changes;旧head的已证明新缺陷归因与修复证据单列。本次reviewer误加--execute的命令解析失败也保留,按真实help纠正后重跑,未修改产品或减掉检查。CQA由本轮对exact final scope记录与verify,不继承作者receipt。

我的整体评价

APPROVE。原始预算缺口已作为完整、有界、可逆的qualification修复闭合:目标binding保留,独立negative oracle抓住并验证两轮误授额修复,全部真实fixture和普通增长限制仍在。43字符margin是明示取舍,不允许未来无证增长。任意完整shell/CLI命令权限、长soak、部署和父级roadmap验收不在本次证据范围。评审不是merge授权或Goal终结,本轮无自合并/admin bypass/host升级。

English verdict: APPROVE - exact head dcafdf8. Necessary explicit registry routing is preserved under an evidence-backed bounded regression budget; all102 real CLI observations qualify, registry review signals remain visible, and independently reproduced malformed-route false grants are now rejected. No runtime permission, deployed-provider acceptance, or merge authorization is implied.

…d-budget

Signed-off-by: huangruiteng <huangrt01@163.com>

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Reviewed exact head: 70bfb0e4c0272f1c2afe012493505dce8b1b7398; immutable merge base: 9c9b90d8eb9972c6d2a308750db5fc22a53c5df3. 执行当前 LoopX pull_request_review_execution_contract_v2(policy revision12)。本轮重新审阅完整7文件差异、集成影响和实际入口;无剩余阻塞发现。作者CQA或上一head批准没有替代本轮验证。

动机

#5363 增加必要registry目标后,同一crowded Turn输出从14,482变为14,557字符。14,500回归预算和只认识runtime-root的比较器因此误阻断正确输出。这里保护agent阅读成本,不是硬quota、benchmark评分或冻结promotion阈值。目标参数不能删;先保留原失败、确认相同负载和消费者价值,才允许协调局部预算。

改动思路

复用既有absolute budget、route observer和differential owner,不新增能力或生产状态机。crowded ceiling仅调到14,600,43字符margin;400行及60字符/Todo限制保留。原160字符/字节/compact route成本扩展到新registry/runtime-root绑定,与普通或migration预算取max,不能叠加;不增加行数额度。只有exact int、非负且真正增加count才授额,旧receipt缺字段、bool/string、负值、相同或减少count都不授额。下一次count成为baseline后,普通增长检查恢复。

具体改动

同一probe一次派生两个count,先解JSON再shlex看完整option prefix及非空subcommand;空registry、option当值、坏quote、缺命令、空/纯空白subcommand或无效format不能获授额,重复binding只计一次。观察器不是执行权限或完整CLI目录。differential保留每个binding的review signal;fixture不缩窄,不改写stdout。vision authoring和真实oversized-output断言读取共享ceiling,消除旧14500测试知识。

关键代码讲解

  • loopx/control_plane/testing/cli_output_semantics.py:203 command_route_counts:Decode emitted JSON and shell argv once; derive both route observations;Nonempty complete recognized option prefix, valid format and nonempty subcommand; malformed text gets0; duplicate option gets1. Not a runtime permission validator.
  • loopx/control_plane/testing/cli_output_differential.py:312 _command_route_growth_allowances:Reuse160-char/byte/compact route cost with zero extra lines;Exact int only and0<=before<after; max versus ordinary/migration allowance, not sum; same count cannot repeatedly earn allowance.
  • examples/control_plane/cli-output-probe-runner.py:44 _receipt_row:Build public-safe measurement from actual unrewritten stdout;Both route counts emitted in one owner invocation, rest of semantic keys/action-signature evidence retained.
  • loopx/control_plane/testing/cli_output_budget.py:73 CLI_OUTPUT_BUDGET_SPECS:Single owner of absolute presentation ceiling;14500->14600 solely accounts for75 necessary routing chars; line400 and perTodo60 stay unchanged; registry/runtime args must still be exact.

完整集成差异与上次读过的修复patch逐字节一致(摘要7b025cdc…100fead);集成main仅另带已审#5372的ignored lease参数移除及manifest行号同步。为检查组合影响,本轮仍从70bfb实际源码跑135个测试(3个输出模块+canonical lease lifecycle),以及20项真实CLI的File/SQLite acquire、renew、transfer、replay、错误CAS/owner拒绝、release和独立readback。没有让另一个session替我验证。

对主干的风险

最强风险是非法命令被算成route后误放行真实增长。早期ffe7的empty-registry和b10d的empty-subcommand原失败已保留:b10d虽通过127测试,实际CLI拒绝空命令,但production _receipt_row+compare_cli_output_receipts仍曾把同形JSON的41→141字符(+100)按160额度判passed;不授额应按普通64拒绝。同一独立oracle在immutable315通过、缺陷b10d失败、当前head通过。此次再次运行empty-registry和empty-subcommand实际CLI/production比较器负例,不继承“上次已修”结论。raw/JSON/Markdown、缺失/类型/负数/unchanged和超过上限仍受测试约束。

原不可变pre-routing04bf与当前70bfb使用相同观察器、完整102行真实CLI fixture:候选normal absolute mode通过(无measurement-only豁免),比较102/102通过,16条registry signal保留;crowded14,557/393行。135测试、全部7changed-file Ruff、2-source focused Mypy(follow-imports=silent)、changed-diff semantic advisory和所有本次risk/catalog/boundary premerge均通过。CQA本轮自己record并verify,scope 5cadb30cb7a1219c788349225a6f1a898c9b86ed63bff9a15cd38f7a4798f24a、receipt cqr_5cadb30cb7a1219c7883 有效;未做safe-fix。错误选择测试文件及premerge参数导致的命令解析失败已保留并纠正重跑,不是产品检查被删掉。

语义与CI对齐

派生count不新增authoritative state;旧receipt字段缺失fail-closed。没有opt-in/default-off、actor生命周期或authority拓宽。budget failure是机器执行条件,review signal仅提示,不能都叫guidance。Python代码属于已有专业qualification边界,TS permission/state决策与PostgreSQL入口未变;不伪称PG/部署/installed验证。完整diff不改CLI producer、settings编辑器、前端/Lark步骤或prompt,所以没有遗漏对应companion。wait_for_ci=false:未获取、轮询或等待远端CI,更不会把无关红CI当作request changes理由。

我的整体评价

APPROVE。完整、有界、可逆的qualification修复已经闭合:必要目标参数保留,真实fixture完整,独立反例验证误授额已拒绝,普通增长限制仍在。future-facing pass已落实到共享observer、退役旧helper和统一ceiling,无必要追加CLIcatalog框架。43字符margin是明示取舍,不允许未来无证增长。任意shell/完整CLI权限、长soak、部署和父级roadmap不在证据范围。结论不是merge授权或Goal终结;本轮无自合并/bypass/本机升级。

English verdict: APPROVE - exact head 70bfb0e. Necessary command identity is preserved under a measured bounded output budget. All102 actual CLI comparison rows,135 combined tests,20 real lease CLI observations, malformed-route negatives and exact-scope quality/premerge checks pass. No runtime authority or merge authorization is implied.

@huangruiteng
huangruiteng merged commit f49b4a0 into main Sep 30, 2026
24 of 27 checks passed
@huangruiteng
huangruiteng deleted the codex/registry-command-budget branch September 30, 2026 22:06
@huangruiteng

Copy link
Copy Markdown
Collaborator Author

Merged with explicit maintainer authorization after independent exact-head review of 70bfb0e4c0272f1c2afe012493505dce8b1b7398 and a matching managed ready=true merge-readiness result. Merge commit: f49b4a00870604d39fa4318da24d6dd35e72bb6e. Remote CI was not consulted under the configured policy.

Final author integration: 139 tests and all selected premerge checks pass. The independent review also revalidated real CLI observations and malformed-route counterexamples. The installed snapshot now identifies this exact merged source; activation qualification and doctor pass. Six additional regression cases used the actual installed executable with disposable File/SQLite stores and passed, followed by a healthy live Goal status readback. Previous failed observations are preserved; this does not claim broader provider-default admission.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant