Skip to content

feat(operations): request operator-granted exact-session continuation after confirmation - #5383

Open
huangruiteng wants to merge 11 commits into
mainfrom
codex/operation-auto-start-20261001
Open

huangruiteng wants to merge 11 commits into
mainfrom
codex/operation-auto-start-20261001

Conversation

@huangruiteng

@huangruiteng huangruiteng commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Delivered scope / 交付范围

Authenticated confirmation can request a default-off, separately operator-granted continuation through the existing delegation worker and ordinary managed Turn into the exact original native session. The canonical operation records its first accepted native start. Start is not permission consumption, task completion or a financial result.

认证确认回调可在独立、默认关闭的 operator grant 下,经既有 delegation worker 与普通受管 Turn 恢复精确的原生会话,并在 canonical operation 保存首次原生启动接受回执。启动不等于消费许可、完成任务或产生金融结果。

  • The existing TS operation owner decides exact Goal/Agent/Todo/session/profile/lifetime admission and immutable first-start evidence. Python supplies configuration, locked storage and delegation/CLI/native IO; no parallel approval queue, scheduler, session directory or Python decision owner.
  • Confirmation never supplies launch configuration. Collector operation_callbacks.managed_turn_wake selects one existing requester/binding. The ordinary delegation owner retains its operator grant, quota, lease and pinned validation; callback code does not invoke the native Host or domain executor directly.
  • Canonical operation identity yields a stable delegation key. Concurrent replay, uncertain spawn ACK and journal readback cannot spawn again. Removing the collector grant is read at the next callback boundary without restarting the collector.
  • Immediately before native resume, the operation owner rechecks the original Goal lifetime, exact original session and complete effective profile. Missing/expired/consumed operations, stopped Goals, fresh/replacement sessions and changed Todo/model/profile cannot start a process. The internal operation-id argument is a locator/fence, not authentication or an execution permit.
  • Dynamic pending discovery filters exact executor scope before bounded pagination. Another Todo cannot crowd out matching operations or reuse their cursor. First-start evidence cannot be overwritten by a later Turn. Receipt failure aborts before tool dispatch; one-shot consumption, unknown-result reconciliation and effect/outcome disclosure remain authoritative.

中文:准入和不可变首次启动仍由原 TS owner 决定,Python 仅适配配置与 IO。确认单不能代替 operator 配置;稳定 journal 使重放及丢 ACK 不重复启动,下一回调读回撤销配置。普通 Turn 的 quota、lease、验证不绕过;动态 pending 在分页前按原主体过滤。消费一次、未知结果对账及副作用披露仍走原权威。

User entry points and incomplete delivery / 用户入口与未完成事项

CLI / managed Turn: collector-plan/status read back whether the optional wake grant is configured without leaking private paths; the bilingual operator path documents activation/removal. Actual detached worker → CLI → normal Turn is exercised with File and SQLite synthetic fixtures.

Lark: the authenticated callback uses the existing confirmation/claim lock and requests only the configured delegation. Its diagnostic receipt reports requested/existing delegation with native_start_verified=false and execution_allowed=false, never a native accepted-start or domain result. Default-off managed and attached flows retain pending authorization. No real card/user approval was used in qualification.

Frontend: shared TS review frame and packaged Chat row/drawer distinguish “Native continuation accepted; authorization not consumed” from Applying. No separate UI authority or extra confirmation button. The new grant has no frontend settings editor yet; that configuration journey remains partial. Historical packaged state-label evidence below does not prove grant editing.

中文:CLI 读回可选配置;Lark 只返回 delegation 请求/已有 journal,不冒充启动或结果。既有前端行/抽屉复用同一 TS frame 显示“原生续接已接受,许可尚未消费”;新 grant 的前端编辑器尚未交付。后端/API 测试不等于该配置入口或完整端到端验收。

Authenticated outcome return to the original native source audience, genuine human-approved domain submission/readback and the investment minimum loop are not established. Group-card readback is not proof that the original conversation received a result. Live paid-model and real Lark probes were not run; no consumption, order, signature, transfer or financial effect. Homepage redesign is not a prerequisite for this existing-entry-point route.

经认证的原生来源受众回传、真实批准后的领域提交/读回及投研最小闭环仍未证明;群卡片不能冒充原线程收到结果。未跑在线付费模型/真实 Lark,未消费许可或执行交易。首屏重设计不是既有路径闭环的前置门禁。

Remaining scope is recorded bilingually in RFC §13 and the operator path.

Exact-head validation / 精确版本验证

Historical head 7db4e03, based on main e240730 (these results are not relabeled as final-head validation):

  • Python 161 passed / 2 opt-in live-model skipped: operation host, Lark callback/collector, real local delegation, canonical action-store and CLI suites.
  • Actual detached File/SQLite worker/CLI/normal Turn reaches the original native session and records matching accepted-start/Turn-key evidence. Human confirmation/native transport are synthetic. The fixture waits and is rejected as Todo completion, proving startup is not acceptance; no consume/outcome/effect.
  • Replay/lost ACK, spawn failure, missing grant, Todo/model/fresh drift, stopped Goal, running-collector revocation and default-off behavior are covered. Negative control bypassing final native admission fails on a forbidden start spy; restoring it passes all seven fence cases.
  • Focused handoff/review-frame and digest-owner TS 41 passed; control-plane typecheck, touched production Ruff, repository-configured Mypy (19 files) and local new-adapter typing passed. Changed-vocabulary advisory found no supported carriers; unsupported/dynamic syntax is a limitation. Semantic smoke passed before this main sync, not fresh post-sync proof.
  • Full unchanged-budget TS: 3606 total / 3574 passed / 1 failed / 31 conditional PostgreSQL skipped. leader_exit counter 20 → 21 after return at host_process.test.ts:71 is preserved. Frozen clean main comparison completed: 3602 total / 3566 passed / 5 failed / 31 conditional PostgreSQL skipped, including abort counter 4 → 5, locator publication, File CLI prepare, NoKV open timeout and SQLite rehearsal timeout. The abort failure does not match the head's leader_exit identity; this is not exact attribution. No passing retry waives the original failure.
  • Exploratory unscoped Ruff and dependency-expanded Mypy failed outside repository-configured scopes; these failures remain disclosed.

中文:7db4 的 Python 161 通过、2 live 跳过,focused TS 41 通过。真实本地 worker/CLI/Turn 使用合成确认及 native transport,只证明启动关联、不证明真实批准/消费/结果。全量 TS 3574 通过、1 失败、31 PostgreSQL 条件跳过;counter 20→21 的失败保留。冻结 main 的全量结果为 3566 通过、5 失败、31 跳过,其中 abort 4→5 不匹配 leader_exit 20→21,不能宣称旧失败已归因。未改阈值、预算或 allowlist。

Merged repair dependency / 已合入修复依赖

The duplicate whole-value digest matcher now reuses ENVELOPED_SHA256_PATTERN; #5377 is already in the preceding base. #5382 merged at c4c2320 repairs signal-dispatch-versus-termination in the existing TS Host owner, with a deterministic delayed-KILL counterfactual. This is causal repair evidence, not retrospective attribution. Updated main b3879f9 was normally merged as 4db1ec6. Integration exposed a duplicate BARE_SHA256_PATTERN import in the lease owner; 8ef3929 removes only that duplicate. No history rewrite or self-merge of another PR.

Final-head control-plane typecheck passed. Lease/digest-focused TS: 142 total / 139 passed / 0 failed / 3 conditional PostgreSQL skipped. Fresh native-operation Python: 18 passed / 2 opt-in live skipped. Fresh six-related-suite qualification: 121 passed / 2 opt-in live skipped in 156.96s, using test_codex_operation_host.py, test_lark_goal_channel_operation.py, test_lark_event_collector_runtime.py, test_local_delegation.py, test_chat_operation_actions.py and test_todo_operation_receipt_cli.py. This is the stated selected workload, not the historical 161-test workload. The earlier mixed-source six-suite run (started with the duplicate import, finished after removal) failed 46 / passed 115 / skipped 2 and is diagnostic, not exact-head qualification. The 4db focused handoff/frame/Host/group run passed 55, but its typecheck failed; that failure is not hidden. Independent final-head full TS and review/readiness belong to the authorized maintainer; this author makes no all-green or merge-ready claim.

中文:重复 matcher 复用原 owner;#5377 已在旧基线。#5382 已合入,修复“信号已发出 ≠ 后代已停止”,不倒推旧失败归因。正常 merge main 后发现重复 import,8ef 仅移除重复;最终头 typecheck、139 个 lease/digest 测试及 18 个 native Python 测试通过,分别有 3 PostgreSQL/2 live 条件跳过。新六套所列相关 Python 测试 121 通过/2 live 跳过,耗时 156.96 秒;不把它改称历史 161 个测试的相同工作量。混合源码旧轮 46 失败/115 通过/2 跳过保留。独立全量 TS、评审及就绪判断由有授权的维护者完成,不宣称合并就绪。

Historical packaged UI qualification / 先前打包前端验证

The earlier UI slice built packaged Chat and exercised API plus canonical-store synthetic first-start evidence: EN/ZH × 1512/390px, keyboard drawer, truthful labels, no horizontal overflow or apply/reject/regenerate controls, zero durable writes. Desktop Chinese/mobile English screenshots were inspected. build:chat, smoke:action-review-plan and source bundle verification passed at that slice; the existing size warning remained. This is historical fixture/layout evidence, not updated-head grant editing, genuine approval or investment acceptance.

中文:前期打包 UI 的中英文/桌面移动端、键盘抽屉、真实状态文案和零写入通过并查看截图;该历史证据不冒充新 grant 编辑器、真人批准或投研验收,原体积 warning 保留。

Increment judgment, adoption and rollback / 增量判断、采用与回滚

Justified increment / 有依据的增量: eliminates the evidenced confirmation-to-governed-start gap at shipped callers without another discovery tick, preserves ordinary effect boundaries and is independently reversible. User still needs the original launch grant, not another approval. Frontend grant editing/original-source outcome remain partial.

Remove the optional collector grant and read back the next callback/configuration boundary to disable wake requests; source revert remains available. Old operations without host_start retain previous behavior; a receipt grants no authority. This author has not globally installed or established genuine consumer adoption. Independent exact-head review and the authorized maintainer's final readiness/merge decision are separate. Private state, credentials, screenshots, probe scripts and generated artifacts are excluded.

中文:移除可选 grant 并读回下一配置/回调边界可撤销启动请求,必要时回滚源码。旧操作兼容,回执不授新权。本作者未全局安装或完成真实采用;独立 exact-head 评审及有授权维护者的最终 readiness/合并决定单独执行。私人状态、凭据、截图、探针及生成物均不提交。

Final main integration / 最终主干集成

Main integration head cb23112 includes main 6a8a042 (#5378). The integration preserves both the explicit registered source audience for proposal preparation and the internal confirmed-operation continuation fence. The native prompt permits authorized preparation before consumption while retaining one-time consumption before any external effect. Both independent test groups are retained.

Fresh selected integration validation: Python 104 passed / 2 opt-in live skipped (native host, canonical operations, Lark operations) in 52.99s; TS handoff/review-frame 26 passed; control-plane typecheck, touched-production Ruff, Python compilation, CLI flag/help readback and diff hygiene passed. Earlier whole-TS qualification at 8ef3929 was 3583 passed / 0 failed / 31 conditional PostgreSQL skipped; it is historical evidence, not a fresh whole-tree run on this integration. The first CLI invocation used an unsupported package main entry, failed before execution, and was corrected to the original entrypoint for the successful flag check. No live card confirmation, domain consumption, order or original-source outcome is claimed.

中文:最终头同时保留原受众 prepare 与精确原 operation 续跑 fence,合并两组测试;fresh Python 104 通过/2 live 跳过,TS 26 通过,typecheck/Ruff/compile/原 CLI 入口读回及 diff 检查通过。8ef 全量 TS 3583 通过/31 条件跳过为历史资格,不改称本头全量。首次误用不存在的 package main 失败已保留,随后用原入口通过。本次不冒充真实群批准、消费或成交。

Original standalone profile coverage

Final head 72f53d8 documents and qualifies the existing operator option --codex-mcp-server-json null for an original standalone operation Session created without delegation MCP. No new configuration field, global Codex change, replacement Session or relaxed profile fence is introduced. Actual CLI parsing retains the final operator null; default MCP profiles retain their server. The original standalone profile is prepared without injected MCP rather than initialized with the later injected profile to hide drift. The operator instructions are bilingual.

Fresh complete tests/test_local_delegation.py: 22 passed in 86.71s, including default MCP, explicit null and missing-null rejection on File/SQLite through the real detached worker -> CLI -> ordinary Turn. Positive cases retain the original session/profile, record native acceptance and ignore repeated callback; missing-null refuses before a second native process starts while retaining the original confirmation. All synthetic typed waits remain rejected work results: no consumption, financial effect or automatic source return is claimed. Two exploratory runs used incorrect new assertion names/error-body expectations; they failed, were corrected against the existing public contract, and are not qualification. Final test/docs bytes were independently hash-checked before committing; production/TS/UI code is unchanged from cb23112.

Latest main integration: af10994eb94de131ec7177b2d89d6ab2de7193c8. Main added only three test fixture/process files via #5365. Production, documentation, and package dependencies are byte-identical to the approved 72f53d80b53248a3ed4e446d7caadb97ef2871be; targeted host-process and Codex CLI integration tests: 48 passed. No CI wait. Final exact-head review is refreshed for this integration commit.

Signed-off-by: huangruiteng <huangrt01@163.com>

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Exact head: 66ecdd3. APPROVE for this bounded increment, no blocking finding. Core merge/install and investment-loop acceptance are not implied.

动机

已确认请求需要进入当前已准入的执行者,并真实区分宿主接受启动、授权消费和领域结果。旧版本要求 Agent 再发现请求,待消费页面还显示 Applying。这个改动完成的是可独立验收的启动观测增量,不宣称自动唤醒或投研闭环完成;原受众结果返回仍由原工作项负责。

改动思路

复用规范操作存储、既有受管 session 和 Inbox,而不是新建批准队列或调度器。TS 原 owner 决定绑定、首次观测和一次性消费,Python 只连接存储锁与 native transport。批准和 session 存在不能推出原生启动已接受,因此首次启动是独立的观测事实;由 turn/start 响应触发,不需要用户填写新配置,也不授予执行许可。

具体改动

17 文件共 +359/-18:生产 +134/-10,测试/烟测 +197/-1,中英 RFC +28/-7,没有生成物或私有材料。

关键代码讲解

  • run_codex_operation_host(codex_operation_host.py:211)查询当前绑定的规范请求,在既有提示中附加有界 locator。原生 RPC 接受后才观察首次启动;写回失败走现有 Host error,不派发自定义 operation tool。
  • planAgentOperationHandoff(operation_agent_handoff.ts:123)核对精确路线、模型、深度与确认期限。首次记录关联原事件和 claim;后续回合保留第一次回执,不把新的 native Turn 冒充第一次启动,消费规则没有放松。
  • record_agent_operation_host_start(chat_action_store.py:1071)在原存储锁内执行 TS 决定并原子落盘,回执由独立读回确认,不只是成功响应字段。
  • projectAgentOperationInbox(operation_agent_handoff.ts:259)先过滤精确执行路线,再按原排序和分页投影,避免其他 Todo 挤掉匹配项;原 Inbox 保留历史和溢出信息。
  • compileOperationReviewFrame(action_review_plan.ts:290)从同一事实生成只读 pending 状态,消费状态优先。Dashboard 行/抽屉和 Lark formatter 分开启动接受与实际结果,不新增批准或执行按钮。

对主干的风险

最危险的反例是夹具直接提供已接受输入,或进程启动/后续重试被标成真实执行。此次沿实际 native send callback、文件存储和 TS bridge 验证;对端协议仍是 synthetic,不证明真人批准。没有原生接受时不写回执,存储失败时没有 operation tool 派发,后续两个已准入回合保持第一次记录。同 Goal/Agent 的25条其他 Todo 请求既未进入提示,也未写启动记录。

基线 f49b4a0 与该 exact head 使用同一夹具走普通 host、公开 turn run-once 和真实文件后端:普通 CLI 均无 operation 字段,opt-in dryrun 不创建 session,执行不降级 plain CLI、不扣 quota。基线 locator/start 独立断言失败,新头通过;两侧均未消费授权或写领域结果。

语义与 CI 对齐

扩展原 operation receipt 和共享 pending 词汇,没有新审批/调度权威。旧 envelope 可缺少 optional receipt;共享 Applying 文案修正已披露,并非隐藏默认开关。按当前 policy 不查询或等待远端 CI。本地69 Python、23 TS、控制面 typecheck、打包 Chat、共享 view smoke、bundle 校验及边界检查通过。8项 live 测试未运行;保留既有 bundle/Goal-projection 警告,不宣称全量全绿。

我的整体评价

长程推进和用户路径都获得可验证改善:减少再次发现请求,保留首次 causal identity,已有页面说真话,不增加用户输入或批准步骤。四组打包页面的中英桌面/移动浏览器检查通过,抽屉可键盘打开、零写入且无执行控件;API夹具和 Lark formatter 不冒充线上渠道验收。

最强剩余缺口是 callback 即时准入唤醒、原卡自动更新/原受众结果返回,以及合入后的固定配置采用和真人领域验收。原 TS owner 继续唯一决策,无平行 Python 源或新兼容协议分支;代码量与该有界问题相称。对此 exact head 结论为 APPROVE(增量),Core 合并和安装仍留给维护者。

English verdict: APPROVE - exact head 66ecdd3, bounded first-start evidence; local and paired validations pass, genuine wake/effect/outcome remains open.

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Request changes conclusion (author-owned PR; GitHub blocks formal self-review)

Reviewed exact head 66ecdd34380bb20f31ba2df1d8533aaa4016ccdd, against base f49b4a00870604d39fa4318da24d6dd35e72bb6e.

动机

这份 PR 有可验证的独立价值:在已经准入、显式启用 operation transport 的回合中,自动携带当前精确绑定的确认操作,并把首次 native turn/start 接受与原确认事件、claim 和 LoopX Turn 关联起来。原来执行者需要自行发现 locator,界面也无法区分“等待绑定回合”和“原生续接已接受”。这对应 human-confirmed-domain-operations-v0 第 13 节 的工程交付边界。

我认可这个有界增量,不把它算作即时 callback 唤醒、真实批准/提交、原卡自动更新或来源受众结果回传的完成。这些仍属于既有 operation/admission、Lark delivery 和 domain provider 边界;本 PR 的接受回执不能替代那些验收。

改动思路

现有 CLI opt-in → run_codex_operation_host → 当前 Goal/Agent/Todo/session/profile 的 canonical inbox → native turn/start response → agent_operation_action → 原 TS decision owner → 锁内 ChatActionStore 写首次观察 → Dashboard/Lark 共用 review frame。先按 executor route 筛选再分页,避免别的 Todo 占满本回合的 20 项窗口。后续回合保留首条回执;消费授权、unknown-result reconciliation 和外部效果仍由原合同负责。

比新建启动队列、第二份 inbox 或由模型报告“已经启动”,复用现有 owner 更合适。原 native host result 没有保存本次 prompt 中的精确 operation/claim 关联,所以这份首次观察不能仅从旧结果投影出来。未来维护所需的有界简化是复用已有 digest 格式 owner,见下面的阻塞项;没有理由新增 helper 或扩大 TS 迁移。

具体改动

  • codex_operation_host.py 的 run_codex_operation_host 在发送前读取精确 locator;chat_agent.py 原有 send 只在收到 native response 后发出 turn.started。新 callback 在 operation tool dispatch 前记录观察,写入失败就中止。
  • operation_handoff.py 的 pending_operation_handoffs 传递 route;agent_operation_action 为观察复用 active-Goal、原绑定和 registry/store 边界。chat_action_store.py 的 record_agent_operation_host_start 复用原锁和 TS plan,只写 write_host_start 的首次结果。
  • operation_agent_handoff.ts 的 planAgentOperationHandoff 检查确认、claim、精确 actor、profile/model/effort、到期与尚未消费的状态;projectAgentOperationInbox 在 20 项分页之前筛选 route。新增回执明确 execution_allowed=false、external_write_performed=false。
  • action_review_plan.ts 派生 managed_turn_started,消费后的状态优先。Dashboard 的 timeline、drawer、page 和中英 i18n,以及 Lark renderer,显示“原生续接已接受,授权尚未消费”,并去掉待确认操作的泛化 Applying 标题。未新增执行按钮或配置 owner。既有 operation inspect 响应新增 nullable host_start 元数据;未启动记录仍为 authorized_pending/not_attempted,旧 frame 仍是 managed_turn_pending。
  • 两份中英 RFC 更新当前 slice 和剩余边界;TS handoff/frame、Python host/Lark tests 与 frontend smoke 覆盖同一语义。完整 diff 为 17 文件、+359/-18,没有生成 bundle、截图或私有 probe 入库。

正向独立回放使用真实 File action store 和公开 Python Host 入口,只有 native 协议 subprocess 是模拟的。同一 harness 在 base 不携带 locator、没有首次回执,在 head 自动携带精确 proposal/claim 并可单独读回确认事件和 native Turn;独立正向 oracle 在 base 失败、head 通过。重复接受保持首条回执,始终未消费或产生 outcome。关闭 operation transport 的普通 CLI 结果和 argv、同 Goal 中新建的其他 Todo、未获 native acceptance 的超时路径均完成 base/head 对比。

反向回放实际造了 26 条 canonical 操作:25 条别的 Todo 未隐藏目标,也未获得回执;重排底层记录不覆盖首次观察。存储失败保持操作状态不变,恢复原 writer 后同一绑定继续并写回真实观察;篡改 actor Todo 被拒绝;stopped Goal 拒绝观察,在授权恢复这个隔离 fixture 后下一正常回合可推进。原一次性消费、过期/绑定漂移及 unknown reconciliation 的 native tests 同样执行。

对主干的风险

阻塞项 [P2]:复用已有 enveloped SHA-256 matcher。 operation_agent_handoff.ts:183 新写了 /^sha256:[a-f0-9]{64}$/,但同一模块已从 content_digest.ts 导入 bare matcher,那里也已有 ENVELOPED_SHA256_PATTERN。它建立了第二份格式决策,并实际新增 required single-owner census 的 offender。base 只有原来的 task_lease_workspace.ts:26;head 多出本 PR 的 operation_agent_handoff.ts:183。全量本地 suite 和仓库锁定 Node 22.22.3 下的独立 census 都复现这一差异,不能把整个失败归为旧基线。最小修复是从同一 owner 导入并使用 ENVELOPED_SHA256_PATTERN,保留格式检查与负例,不放宽 census 或登记例外。重跑 handoff/frame、typecheck 和 census,确认新增 offender 消失;原有 task-lease offender 的归属另行处理。

另外,全量本地 TS 在 head 有 leader_exit: descendants cannot keep working after managed execution returns 的计数继续变化断言失败;base 失败的是不同的 timeout case。虽然底层 supervision 文件未改,失败 identity/detail 不匹配,当前仍按 unresolved 保留,不能用 unchanged source 或绿色 focused retry 宣称已归因。这是批准前的验证缺口,不是我已证明本 PR 引入了进程清理缺陷,也不要求本 PR 顺便修复另一条主线。

实际验证:Python focused 69 passed / 8 deselected(显式 not live);TS focused 23 passed;typecheck、repository-scoped Ruff、Mypy、Dashboard build/chat-bundle source verify 和 action-review smoke通过;premerge 5 direct + 19 selected 全通过,semantic advisory未识别受支持新 vocabulary carrier,full semantic smoke通过。全量 TS:head 3598 total / 3565 passed / 2 failed / 31 skipped;base 3595 / 3562 / 2 / 31。31 项是未配置独立 PostgreSQL 的条件测试,本 slice 改的是 File action store 和 Host adapter,没有 PostgreSQL authority-store refactor;不把它们说成已执行。全量失败并未被较窄的绿色 canary覆盖。

独立构建的 packaged Chat 在 Ego 浏览器中检查了中文桌面和英文 390px 手机整屏、键盘打开 drawer、返回与 reload,并从 canonical store 生成的 accepted/未启动状态读回:文案区分首条接受证据与正在运行,详情无 apply/reject/regenerate 控件,无横向溢出,fixture durable writes为零。UI API 是隔离 HTTP fixture;这不证明真实 Lark 原卡已经更新、生产 freshness/sorting 或 paid-model/domain acceptance。没有调用远程 CI、真实通道、真实账户或付费模型。

我的整体评价

REQUEST_CHANGES。 首次 native-start 证据、原 owner 复用、明确的无授权增量和可读回的 UI 是合理且已实测的增量。当前需要修复新引入的 digest owner 重复,并完成剩余 required native failure 的严格归因或恢复验证,才能批准。本评审覆盖整个 exact-head PR;不继承 #5378/#5382 的结论,不安装、不晋级、不合并,合并留给 maintainer。

English verdict: REQUEST_CHANGES - head 66ecdd3 introduces a duplicate SHA-256 matcher that worsens the required single-owner census; reuse ENVELOPED_SHA256_PATTERN. Native-start, immutable readback, scoped filtering, failure recovery and packaged UI were independently exercised; 69 Python and 23 focused TS tests pass. Full local TS also retains an unattributed process-lifecycle failure. No remote CI or real domain acceptance claimed; maintainer merge remains separate.

Comment thread loopx/control_plane/work_items/operation_agent_handoff.ts Outdated
Signed-off-by: huangruiteng <huangrt01@163.com>
@huangruiteng

Copy link
Copy Markdown
Collaborator Author

Follow-up at exact head 8d543946b962dbb79c2123eeb2785ba77507ff41 / 本次增量。

The native startup inbox already passed its exact execution route to the TS owner, but dynamic loopx_operation pending omitted it. The new canonical-store test reproduced 25 other-task approvals contaminating the same Agent's page (pending_count=26 rather than 1). The callsite now passes its existing Goal/Agent/Todo/session/profile route; the matching task remains visible and cross-subject cursor reuse is rejected. No new decision owner, protocol, storage, configuration or authority is introduced.

旧动态 pending 漏传精确执行范围,同 Agent 另一任务的批准会污染分页。本次复用已有 TS 过滤判定并补齐调用参数;回归同时验证匹配任务不被挤占,以及跨执行主体游标拒绝。最新相关 Python 回归 76 通过、2 项真实模型测试未启用;TS 23 项、类型检查和全树语义检查通过。旧调用缺参数的负对照明确失败。

This remains partial delivery: no immediate callback-triggered wake or actual original-native-source return is claimed. Existing group-card recovery is not native source delivery. No real approval, financial effect, Core merge or installation was performed. This progress note is not an exact-head approval or merge-readiness verdict.

…legation

Signed-off-by: huangruiteng <huangrt01@163.com>
…start-20261001

Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
…in sync

Signed-off-by: huangruiteng <huangrt01@163.com>
@huangruiteng huangruiteng changed the title Record canonical native-start evidence for managed operations feat(operations): request operator-granted exact-session continuation after confirmation Oct 1, 2026

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Reviewed head: 8ef39295affb29bd71132a3b23a7c5c09aafad52
Packet base: b3879f96f0b89e6a417ed19ba16c945085e0081d
Independent current-main counterfactual: 638d0e39cff09948df1816a4a5c5ccce70262c57

未发现这个完整 PR 引入的阻塞问题。结论是 APPROVE,针对有依据、可回滚的运行时增量;grant 设置入口与原生来源结果回传仍是 partial。此评审不执行合并。

动机

原路径已经能确认精确操作,但确认后的执行方还要等下一次 discovery 才发现它;即便原生 Turn 已接受启动,也没有把这件事与原确认、claim 和 LoopX Turn 写成可核验的首次回执。同一 Agent 下其他 Todo 的操作还可能占满 pending 第一页。实际要解决的是“精确确认 → 获准恢复原会话 → 读回原生接受启动”,保留消费许可和真实结果的独立边界。回调 ACK、拉起进程、模型成功文字都不能代替这三件事。

改动思路

更小的 pending 查询修复只能解决发现问题,定时重试也无法兑现确认后的受管续接;把 native resume 放进回调则会越过既有 Turn 的 quota、lease、验证与恢复。因此本次扩展既有 TypeScript operation owner,由它判断精确主体、配置和生命周期,Python 负责配置、锁、journal 与 Host IO。独立 operator grant 选择原有 delegation binding;确认单不携带启动配置,也不授予另一个会话身份。首次原生接受回执是追加的事实,消费一次及未知结果对账仍由原 owner 负责。

具体改动

关键代码讲解

planAgentOperationHandoff(operation_agent_handoff.ts:123)先验证 canonical terms/digests,再区分 wake、observe、consume 和 report。wake 只给启动准入,始终返回 execution_allowed=false;observe 绑定原 Goal/Agent/Todo/session/profile、native Turn 和 LoopX Turn key,已经有首次回执时不覆盖。原先重复的 enveloped SHA-256 matcher 已复用 ENVELOPED_SHA256_PATTERN。消费与 reconciliation 分支没有被这个启动回执替代。

dispatch_confirmed_operation_wake(operation_wake.py:31)复用已有 Delegations。canonical operation id 派生稳定 journal key,已有 journal 只读回,不重复 spawn,也不在回调中跑 artifact validator。run_codex_operation_host(codex_operation_host.py:218)在 native resume 前再次核对原 Goal lifetime、会话、完整有效 profile 和确认状态;turn.started 只在 native turn/start 接受后写首次回执,记录失败会在动态工具分发前中止。真实 detached worker → CLI → 普通 Turn 的 File/SQLite 测试把这些层连起来,合成 native transport 只用于进程边界;启动后 fixture 仍因未满足 Todo 验收而 rejected,证明启动不是任务完成。

projectAgentOperationInbox(operation_agent_handoff.ts:278)在排序和 20 项分页前按完整 executor route 过滤,跨主体 cursor 被拒绝。独立同一 harness 在当前主干和本 head 对照:25 个其他 Todo 操作后创建一个自己的操作,主干返回 pending_count=26,head 只返回自己的 1 个;随后增加自己的操作并验证另一主体不能复用 cursor。另一个公共 Host harness 在两版验证默认关闭的 argv/result/无写入相同、后来创建的未覆盖 Todo 没有原操作 locators/回执;本 head 的匹配主体才得到真实 canonical 首次接受回执,后续 Turn 重放保持它不变。

本 head 独立全量 TS 实测:3614 total / 3583 passed / 0 failed / 31 conditional PostgreSQL skipped,使用符合仓库 SQLite qualification 要求的 Node 22,预算、阈值和扫描范围未变。六个相关 Python 套件的完整选择实测 121 passed / 2 opt-in live-host skipped;另有独立 scope/grant 恢复 3 项通过。control-plane typecheck、CI 配置范围的 Ruff、项目配置的 Mypy(19 files)、changed-vocabulary advisory、全树 semantic smoke 与 diff check 通过。这里的 Python 结论是所列相关套件,不是整个 Python 仓库。

CLI、Lark 和前端都有对应入口:CLI 的 internal operation-id 是 locator/fence;collector 下次回调重读可选 grant,撤销不必重启 collector;Lark 只返回 delegation 请求/已有 journal,不能声称 native start 或领域结果。打包 Chat 重新 build、verify、shared-frame smoke 通过;以本 head 的 canonical-store 合成状态跑了 EN/ZH × 桌面/手机 × 5 个状态,共 20 个行/抽屉场景,包括键盘打开、关闭、reload 与再次读回,零 durable write、零执行按钮、无横向溢出。查看了桌面中文与手机英文整屏。该证据来自重新构建的 packaged surface 与 fixture API,不代表全局安装、真实群确认或真实领域采用。

对主干的风险

语义与 CI 对齐

host_start 是原 canonical operation 的不可变外部观察;confirmed_operation_id 是原 delegation journal 的因果关系;managed_turn_started 是既有共享 frame 的派生显示。没有新增审批队列、scheduler、session directory 或 Python 决策 owner。旧操作缺少回执仍按原状态读回;Python/Node 请求同版部署,持久化的旧 operation/delegation 继续可读。零 advisory 候选不等于没有语义变化,这些 producer、reader 与 persistence 已另行核对。

默认关闭验证没有只看 feature-on:普通 Host 的 argv、结果及 canonical 无写入保持相同,8 个普通/历史 frame 和 unscoped Inbox 整体投影逐字相同。managed/attached callback 在没有 grant 时保持所有原字段、原 pending canonical 状态、无新 delegation journal 和重放结果;新增的是显式 not_configured 的可选诊断,三个 authority/effect 标志均为 false,现有 listener 只消费原有 ok,该诊断不进入启动或持久化授权。collector-plan/status 的配置可用性也不是 activation。启用后仍必须逐 operation/Todo/session 检查;scope、fresh/replacement、profile、停止/缺失和撤销的负路径均受原 owner 拒绝,恢复 grant 后同一 canonical callback 能产生一次新的受管工作请求。

packet base 与较新的 main 之间只有 #5391 的单行重复 import 修复,本 head 已包含等价修复;对照运行使用不可变、可运行的最新 main,而没有把旧 broken base 的错误说成成功。#5382 的 Host cleanup 修复也已经在 base 中。历史 7db 的 reviewer NoKV open timeout、作者 leader_exit 20→21,以及旧主干 abort 4→5 是不同的原始观察,继续保留,不能互相归因,也不能把 focused 重试当成旧全量绿色。这里记录的是整合后新冻结 head 的新全量运行;没有回写历史结果或调高预算。review harness 的错误路径/环境调用已修正并保留诊断,所报通过来自正确源码与命令。

31 个 PostgreSQL 条件跳过属于未配置的独立 PostgreSQL 环境;本 PR 未改 PostgreSQL authority provider,File/SQLite 的真实受影响路径已验证,不声称 PostgreSQL 运行通过。两个 live-host case 未 opt in,不跑付费模型或真实 Lark。没有查询、轮询或等待远端 CI。新 grant 的 frontend settings editor、authenticated original-source outcome return,以及真实批准后的领域提交/读回仍未交付或未证明;群卡片读回不能替代原生来源收到结果。

我的整体评价

APPROVE,作为 RFC §13 所描述的有界增量。长期推进改善来自 canonical pending 的精确发现、一次 journal 启动与原生接受后的稳定回执,避免重复启动、分页饥饿或将未知结果重发。用户路径减少一次发现等待,同时保留必要、范围明确的 operator launch grant;没有新增第二次领域批准。配置 UI 与原来源结果闭环继续标成 partial,不借启动成功关闭其验收。原有 typed owner、分页 seam 和 delegation journal 已复用,相关未来维护改进——共享 digest owner——已经落实;当前不需要再建通用框架。移除可选 collector grant 并读回下一事件即可停止新 wake 请求,既有已启动工作仍走普通停止/对账路径,必要时可回滚源码。合并留给维护者。

English verdict: APPROVE - The complete exact-head increment preserves scoped authority and one-shot effects, verifies governed original-session continuation and immutable native-start readback, and explicitly retains partial grant-editor and original-source outcome delivery. Merge is left to the maintainer.

…start-20261001

Signed-off-by: huangruiteng <huangrt01@163.com>
@mergify

mergify Bot commented Oct 1, 2026

Copy link
Copy Markdown

This pull request has merge conflicts with main and cannot be merged
until they are resolved. Please rebase or merge the base branch, @huangruiteng.

Choose the remote for the base repository, not an out-of-date fork.
For a fork clone, first inspect git remote -v; upstream must point
to https://github.com/loopx-project/loopx.git. If it is absent, add it
with git remote add upstream https://github.com/loopx-project/loopx.git.
Then run:

git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEAD

For a same-repository clone whose origin points to
https://github.com/loopx-project/loopx.git, use origin instead of
upstream for fetch/rebase. If you prefer merging the base, use
git merge <base-remote>/main and push normally.

Keep the DCO Signed-off-by trailer on every commit when you rebase.
https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/syncing-a-fork

@mergify mergify Bot added the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 1, 2026
…start-20261001

Signed-off-by: huangruiteng <huangrt01@163.com>

# Conflicts:
#	loopx/cli_commands/turn.py
#	loopx/cli_commands/turn_registration.py
#	loopx/control_plane/turn_driver/codex_operation_host.py
#	tests/test_codex_operation_host.py
@mergify mergify Bot removed the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 1, 2026
Signed-off-by: huangruiteng <huangrt01@163.com>

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

评审精确 head:72f53d80b53248a3ed4e446d7caadb97ef2871be,base:6a8a042ab868a0694e8c19a1ba29c534c575864a。没有阻塞项。以下按完整 PR 判断;旧 8ef 的批准没有继承。

动机

确认完成后,原受管操作仍可能等待下一次发现;启动 ACK 也不能证明原生会话已接收。这个 PR 把确认接到既有受管 Turn,并保存首次原生接收证据;同时修复同 Agent 其他 Todo 在分页前挤掉匹配操作的问题。这是有用、可撤销的续接增量,尚未完成真实用户批准后的领域执行与原受众返回。

改动思路

启动配置与批准操作条款是两种独立权限。默认关闭的 collector 配置选择原 requester/binding,回调只传规范操作定位信息;既有 delegation journal、普通 Turn 的 quota、租约和固定验收继续负责执行。TS 原 owner 判断身份、生命周期和状态,Python 适配配置、锁及原生 IO。来源受众只是返回路由;主干 #5378 的 prepare/source-route 与本次 confirmed-operation fence 均保留。

具体改动

  • dispatch_confirmed_operation_wake 复用既有 worker 和稳定 journal。重放及丢失 ACK 读原记录,不再次 spawn;撤销配置在下一回调生效。
  • Delegations._execution_arguments 附带原 operation 定位信息;run_codex_operation_host 在启动前核对原 Goal/Agent/Todo/session 和完整有效 profile。原生接受 Turn 后才写首次 host_start,写入失败在工具调用前中止;启动不授予消费许可。
  • projectAgentOperationInbox 在分页前按完整执行主体过滤;compileActionReviewPlan 为既有 Chat 行、抽屉和 Lark 共享“原生续接已接收、尚未消费许可”的状态。没有新增 UI 决策权或确认按钮。CLI/collector 的 plan/status 读回配置,双语文档说明启用、撤销和未完成边界。

原独立 Session 的 mcp_server=null 是此次重点反证:默认 delegation 注入 MCP 会改变 profile,原 fence 正确拒绝。独立 File/SQLite 实路验证确认,原 binding 使用既有 --codex-mcp-server-json null 即可保持原 profile;真实 parser 采用后项,不能取 argv 第一次出现来判断。最终两个文件仅补双语说明及持久回归,没有新增生产分支、替换 Session 或放宽 fence。原 profile 使用 delegation MCP 时则保留该 server。

对主干的风险

完整差异为 26 文件、1106 增行/28 删行。主要风险是把回调请求、进程创建或启动回执误当消费/完成,恢复错误 Session,或用来源路由冒充执行身份。精确主体、首次回执不可覆盖、一次消费和未知结果对账仍由原权威约束。默认关闭路径保留原行为;新增 inactive callback diagnostic 是非授权的附加读回字段。

独立验证:最终 tests/test_local_delegation.py 22 通过,103.76 秒;覆盖 default MCP、explicit null、遗漏 null 三场景 × File/SQLite,经真实 detached worker → CLI → 普通 Turn。正例原生进程计数 1→2、重放不增加,原 session/profile 不变;反例停在第二次原生启动之前,原确认保留。合成等待仍被拒绝为工作完成,没有消费或结果。

集成头 cb23112 的 fresh Python 104 通过/2 live 跳过、TS 26 通过、typecheck 和语义检查可复用到最终头:两头生产/TS/UI 源码相同。最终配置范围 Ruff、Mypy(19 文件)、diff/DCO/公开边界检查通过。更早 8ef 的全量 TS 3583 通过/31 条件 PostgreSQL 跳过及 20 个打包 UI 夹具场景保持历史标记;已核对未变消费者、文件和依赖,不把它们改称本头全量运行。旧不同头的失败及审阅探针纠正保留,不倒推归因;本次按 Goal 契约未查询或等待 CI。

我的整体评价

批准这个有界增量。最强反证暴露的 null-MCP 配置缺口已用现有接口补齐并由实际原会话路径验证;继续增加 profile 策略或另一个启动 owner 没有必要。未来改动便利性检查确认沿用现有 typed owner、分页和 journal,比新增框架更合适。

非阻塞 P2 文档建议:RFC §13「自动续接与原受众返回」仍无条件写“不会启动原宿主”,并把确认续接整体列为后续交付。建议双语明确区分默认未配置路径、已经交付的 operator-granted 请求,以及仍未验收的真实消费者/60 秒延迟/原受众结果返回,避免维护者重复实现。

新 grant 的前端编辑器、安装后的真实原消费者批准/消费/领域证据、原来源受众的认证结果送达仍属部分交付;群卡读回和合成 native 接收不能替代这些验收。这份评审不代表合并、安装或投研闭环完成。

English verdict: APPROVE - 72f53d8. No blocking findings. Original null-MCP continuation uses the existing operator override without weakening the profile fence; independent final delegation tests passed 22, with cb production-equivalent integration evidence and explicitly revision-bound historical coverage. Optional governed startup is distinct from consumption, genuine domain execution and original-audience return. Non-blocking RFC wording clarification suggested.

…start-20261001

Signed-off-by: huangruiteng <huangrt01@163.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant