Skip to content

fix(quota): fence settlement by exact GoalRef - #5389

Merged
huangruiteng merged 21 commits into
loopx-project:mainfrom
Duang777:codex/quota-goalref-owner-fence-clean
Oct 2, 2026
Merged

huangruiteng merged 21 commits into
loopx-project:mainfrom
Duang777:codex/quota-goalref-owner-fence-clean

Conversation

@Duang777

@Duang777 Duang777 commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Problem and result

Quota settlement previously relied on a Goal alias where a source-bound caller needs the exact Goal instance. This can let stale results or replay cross a delete/recreate boundary. The change threads the existing GoalRef through admitted spend/void, checkpoint, monitor, host/Turn, native-child and readback paths; transactions and history consumers enforce the same owner before selection or effects. Inactive legacy callers retain their existing behavior.

The TypeScript quota owner reuses first-party currentness and ordered lock witnesses; Python transports identity and IO. This PR qualifies quota_settlement only, retaining the source-session activation hold and all remaining owner/old-writer/drain gates. It is the DCO-clean successor to #5340 and advances #5206 without closing the full RFC.

Product integration plan

The bilingual Goal-instance RFC and overall roadmap, plus steward golden queries, now connect the quota foundation to existing delivery owners:

  • P0: GQ01/02 Goal creation and Agent creation/reuse; GQ05/11/12 small-team dependency artifacts, peer handoff and independent review; GQ08/09 correction and recovery.
  • P1: GQ15 shared budgets/mixed teams and R5/M4 governed orphan recovery.
  • P2: GQ16 cross-host continuation under its existing authority gates.

First qualify the ordinary supported-profile 2–3-worker journey. Only after the selected M2/M3 owner, compatibility and drain gates pass, exercise an isolated M5 old A/new B/late A scenario, independent acceptance and unrelated-Goal progress. Goal lifetime, registered Agent, session/execution generation and work request/attempt remain distinct. Packaged App/CLI and Lark acceptance is tracked separately; documentation is not a live qualification claim.

Validation

At final head a5118d08f51809762c7983e6363d4d3c92a3548f, integrated with main at 9b0486dc1b891bc5254ea85d1ba06da089d22853:

  • 231 focused Python and 279 TypeScript tests passed; 37 final-main refresh/Lark/census integration tests passed.
  • Independent identical-fixture base/head public CLI guard → refresh → spend → replay preserved refusal, persisted result and one debit. Native spend/void/replay complete responses plus seven persisted files were byte-equal without normalization. Missing source admission is rejected at head.
  • Control-plane typecheck, configured Mypy, Ruff, docs governance, RFC index, semantic advisory/drift and registry census passed. Current base/head module budgets passed; all 21 PR-only commits carry DCO sign-off.
  • Risk-based premerge passed: 10 catalog canaries, 8 risk-profile smokes, public-boundary scan and diff/compile checks; no failures, skips or manual holds. Exact-scope change-quality receipt valid.
  • Per review policy, remote CI was not polled. No live paid-agent run, active-state mutation, PostgreSQL service qualification, profile activation or packaged M5 acceptance is claimed.

@Duang777
Duang777 requested a review from huangruiteng as a code owner October 1, 2026 03:16
@Duang777
Duang777 requested a review from cocolord October 1, 2026 03:16
@Duang777

Duang777 commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator Author

CI attribution for exact head f2b154547671d0cb9230cb371ab99b49846a30eb after run 36809727068 completed:

No #5389-owned failure was found. A detached integration of exact heads #5377, #5379, #5375, and #5367 on the same base passed the focused Python suite (35 tests) and digest-owner TypeScript suite (17 tests). After those baseline fixes reach main, #5389 can be synced normally and rerun. No merge action was taken.

@Duang777

Duang777 commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator Author

Exact-head update for f5f04c30a43c5917f554910b3db427ec451421c4:

Fresh CI is running on this exact head. @cocolord @huangruiteng please re-review when available. No merge action was taken.

@Duang777

Duang777 commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator Author

Exact-head update for a931649233afe6c9d976ad87d0dbc22913492675:

Exact-head CI run 36825859844 completed with 21 successful jobs, 2 optional skips, and 2 related failures. Every direct Python and TypeScript test job passed. The pytest coverage aggregate failed because test_cli_inspects_disjoint_index_and_worktree_values left a temporary /tmp/.../loopx/a.py source path in coverage data after pytest removed the synthetic checkout; merge-gate then failed only as the aggregate result.

#5375 removes the inherited pytest-cov environment from that synthetic subprocess, and its exact-head CI run 36825867638 passed all 24 jobs with no failures. No #5389-owned fix is needed. After #5375 lands, this branch should sync current main and rerun CI. No merge action was taken.

@Duang777

Duang777 commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator Author

Exact-head update for c91767874b4fd91ea4af5cfe0d59a8489de1187e on main@7674ae9d3a98eb3673b3012876e5a3fd26c9acf7:

Fresh exact-head CI is queued. @huangruiteng please re-review when available. No merge action was taken.

Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
@Duang777
Duang777 force-pushed the codex/quota-goalref-owner-fence-clean branch from 516a703 to 57e0d9c Compare October 1, 2026 10:55
…wner-fence-clean

Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…wner-fence-clean

Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…wner-fence-clean

Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…wner-fence-clean

Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…wner-fence-clean

Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…wner-fence-clean

Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…wner-fence-clean

Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…wner-fence-clean

Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…wner-fence-clean

Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…wner-fence-clean

Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…wner-fence-clean

Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…wner-fence-clean

Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
@mergify

mergify Bot commented Oct 2, 2026

Copy link
Copy Markdown

This pull request has merge conflicts with main and cannot be merged
until they are resolved. Please rebase or merge the base branch, @Duang777.

Choose the remote for the base repository, not an out-of-date fork.
For a fork clone, first inspect git remote -v; upstream must point
to https://github.com/loopx-project/loopx.git. If it is absent, add it
with git remote add upstream https://github.com/loopx-project/loopx.git.
Then run:

git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEAD

For a same-repository clone whose origin points to
https://github.com/loopx-project/loopx.git, use origin instead of
upstream for fetch/rebase. If you prefer merging the base, use
git merge <base-remote>/main and push normally.

Keep the DCO Signed-off-by trailer on every commit when you rebase.
https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/syncing-a-fork

@mergify mergify Bot added the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 2, 2026
huangruiteng
huangruiteng previously approved these changes Oct 2, 2026

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent · GPT-5 · OpenAI(self-reported;不是身份认证或独立模型溯源)

动机

评审 exact head:9baac7c6cfc15e4daf5f010658725fa6a2141d43,基线 3c50e59c0c3da96ac00b1715e7978440030c13a9。依据 #5206 和 Goal-instance RFC 的 M3 quota_settlement:同名 Goal 重建后,旧实例迟到的 debit、replay、repair、读回不能污染继任实例。这里只资格化完整 accounting 切片,不宣称整个 RFC 或 provider 激活完成。

规范对照以改动前 docs/architecture/rfcs/goal-instance-identity-and-orphan-recovery-v0.md、revision 3c50e59c0c3da96ac00b1715e7978440030c13a9 为准,不用新增 checkpoint 反证实现正确:5.5 的短事务 exact fence、旧历史不授权继任结算,在完整 accounting owner/消费者及 native race/replay/readback 验证;7 的未激活兼容以同夹具完整输出/产物对照验证。M3 只完成 quota_settlement owner,其他 owner/drain/旧 binary 仍 deferred 于 #5206;M5 完整迁移、packaged/Lark 多 worker 验收不在这个 M3 accounting 切片内。不把任一阶段写成整个 RFC 完成。

改动思路

复用既有 TypeScript accounting transaction 和 decideFirstPartyHostRuntime(require_current)。Python 捕获/传递 GoalRef 与真实 lock witness,run-index 先于 source lifetime guard;typed owner 校验目标、角色、pid/token 和 currentness 后才进入效果。单阶段接管锁到完成;多阶段 auxiliary monitor 只借用 admission,外层 Python 持锁贯穿 preflight、provider writeback、commit/replay。覆盖生产和消费两端,避免仅添加字段,迟到效果或兼容 Turn inference 仍按 alias 操作;不新增平行 Python 决策规则。

具体改动

检查完整 78 paths,+4249/-392:大部分新增覆盖是 TS native 负例和 Python 集成;薄层传播包括 quota/refresh/todo/turn/native-child CLI、MCP/effect plans、accounting/read models、checkpoint fence,以及双语 checkpoint/inventory/census。这是一条实际效果路径,不是78份独立政策。

关键代码:

  • parseQuotaAccountingOwner / withQuotaAccountingOwner:明确 alias/exact_source;GoalRef/admission 一起提供,两份有序 witness 必须匹配,复用既有 currentness owner。
  • quota_accounting_admission:在真实 index/source locks 内生成 snapshot/witness;Python 不重建 stale/current 业务决策,也不意外释放借用的外层锁。
  • commitQuotaAccountingArtifactTransaction:record、event、index、payload、receipt owner 一致;cross-instance replay/prepared repair/effect identity 冲突拒绝,保留既有 CAS 和可恢复事务。
  • readQuotaSettlement:先按 exact/alias ownership 过滤再进行 Turn inference;void、rolling-window、checkpoint、native-child 消费同一约束,迟到 A 不替换当前 B。
  • evaluateQuotaMonitorPollCommit:multi-phase settlement 借用同一 admission,internal readback 不误接管/释放外层锁;source provider 路径仍保留 activation hold。

当前 Python 11文件矩阵 128 passed、1 failed,失败为下述既有 architecture budget,不隐藏。实际 File/SQLite checkpoint/provider fence、kernel/file locks、落盘产物参与。六文件 TypeScript 218 passed、0 failed,覆盖 current/stale/malformed、spend/replay/repair/void、exact readback 及 monitor preflight/exception/commit/replay;typecheck通过。

额外生产 Python→TypeScript effect 对照:两个 immutable revisions 使用相同绝对临时夹具路径和固定 generated_at,legacy 首次/replay 的完整响应、JSON/JSONL/Markdown/receipt 完全一致,未删字段或哈希。独立 negative:GoalRef 有但缺 admission,base 实际写4份 artifact,head 拒绝、写入0;合法 witnessed scope planned A/current B 在 head 返回 stale_goal_instance,无 Goal artifact 或剩余 effect lock。base旧 native owner无法接管 held scope而超时,不误说它在持锁时成功写 stale A;合法 Python race/current-source 调用由原生测试另外覆盖。

分支范围16个提交均有 sign-off,替代 #5340 的旧 DCO-only 阻塞独立核验消除;不跨 PR 撤销 #5340 历史评审。

对主干的风险

共享 control-plane 边界主要风险是只 fence 写入却漏掉消费、或借锁误释放。本版 callers、readback/rolling/native-child consumers 和异常重试均进入同一 owner,没有发现当前可复现阻塞。currentness 是机器规则,不称“指导”;generic Goal/instance/accounting errors 不混入产品/benchmark policy 或 substring 分类。

非 source 默认无新 required fields/prompt/form/自动激活,完整 legacy 响应与持久化对照一致。隐藏 instance 参数是捕获后的 transport,不增加人工反复填写;provider discovery/CLI存在不是 activation。没有新的 frontend setting/config schema,已有 status消费者继续读回,故无需平行新页面;未激活的 provider journey不能描述为用户已可用。

语义与 CI 对齐

advisory 未检出新受支持 vocabulary carrier,不据此证明无语义影响;已检查 discriminated owner、ordered lock roles、既有 ExactGoalRef parser/currentness decision。完整 semantic/boundary检查随 canary执行,5 direct及19 selected全部通过。

保留 Python test_top_level_module_count_stays_at_the_pinned_budget 失败:base/head 均147预算对148模块,offender同为 workflow_skill_install.py,完整断言堆栈一致。PR不增加 top-level module,预算文件和 offender不变;accounting 不变量独立通过。不把 canary通过扩大成所有测试绿,也不提高预算覆盖失败。

未查询、轮询或等待 GitHub CI。没有改造或验证 PostgreSQL quota store,File/SQLite证据不替代 PostgreSQL采用资格。execution_authority:false、整体 activation hold、不支持/常驻 binary、downstream external-effect drain、其他 M3 owner均保留,见双语 RFC。

我的整体评价

APPROVE:不是仅做 serializer/happy-path stamp;已有 typed owner覆盖实际 commit、replay/repair、消费及 monitor外层 scope。同夹具完整 legacy对照和 missing/stale authority negative补足兼容/恢复证据。相邻重构集中 exact/alias admission与 witness parser,Python保持运输/存储适配归属,不扩成全量迁移。仅更新既有 quota_settlement checkpoint,其他接受度保持开放;由维护者决定合并,本评审未自合并 control-plane改变。

English verdict: APPROVE — 9baac7c. Exact ownership covers accounting effects, replay/repair, readback and borrowed monitor scopes. Native same-root legacy outputs/artifacts match; missing/stale authority rejects without writes. 218 TypeScript tests and risk canary pass. One unchanged budget failure is baseline-attributed; provider activation and other M3 acceptance remain held. No merge performed.

…wner-fence-clean

Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>

# Conflicts:
#	loopx/cli_commands/turn.py
…wner-fence-clean

Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
@Duang777
Duang777 requested a review from huangruiteng October 2, 2026 14:26
@huangruiteng

Copy link
Copy Markdown
Collaborator

@Duang777 我正在接手当前 head 的维护者复核,并在本 PR 补齐与 roadmap R1–R3 / G1 和 Goal-instance RFC M5 的落地关系:Goal 创建、Agent 创建/复用、小团队产物交接、中断恢复与同名重建的迟到结果隔离。会更新现有双语 RFC/roadmap 和 golden-query 验收场景,保留仅 quota_settlement 完成及整体 activation hold 的边界。

接下来会向当前分支追加文档提交并做最终验证;请暂缓同步该分支,避免审核期间 head 继续变化。完成后会在这里回报合并与后续验收路径。

…ecycle-journeys

Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
…5389-goal-lifecycle-journeys

Signed-off-by: huangruiteng <huangrt01@163.com>

# Conflicts:
#	loopx/semantics/project_registry_io_manifest_v1.json

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent · GPT-6 · OpenAI

English verdict: APPROVE — a5118d0

动机

本 PR 解决同名 Goal 重建后,旧实例的额度效果、历史结果或重放被新实例错误消费的问题。它交付完整的 quota_settlement 归属切片,并将后续产品验收接到现有创建、协作和恢复旅程。长期推进可靠性改善,既有默认用户旅程保持;尚未完成的整体实例激活和小团队验收仍明确保留。

规范依据:docs/architecture/rfcs/goal-instance-identity-and-orphan-recovery-v0.md,采用修改前不可变版本 62ca35f280b51fd4a474b4380a9664570d5aa802。本次映射:5.5 的 quota binding/commit fence 和 7 的未激活兼容边界已实现并验证;M3 的其他 owner、旧/warm writer 和 drain、M4 的孤儿恢复、M5 的 packaged 产品组合验收仍由 #5206 持有。本次文档编辑没有用实现倒推或降低这些准入标准。

改动思路

复用既有 GoalRef、first-party host 的当前实例判定与 mutation-lock,TypeScript 持有准入及效果规则,Python 捕获并传递真实锁见证、执行 IO。持久 receipt 保存写入时的实例事实,不能事后从当前 alias 推导。legacy 和 exact_source 是同一额度边界中的显式分支;未激活模式保持原有参数、扣费、拒绝和重放行为。

只给一个 receipt 增加字段不能覆盖旧结果推断、checkpoint、monitor 及 fallback,因此这些已有消费者必须一起收口。有限重构保留共用准入边界,将轻量 GoalRef 校验移出 registry 导入链;没有引入新的 Agent 工厂、调度器或第二个 Python 决策源。

具体改动

全量检查相对于 9b0486dc1b891bc5254ea85d1ba06da089d22853 的 82 个文件,并核对已撤销旧审查之后的 Turn 参数迁移及主干集成。当前 head 同时保留最新 refresh-state 的 blocked notice 处理;唯一手工冲突是生成清单的两个源码行号,已按实际源文件校正并验证。

五处文档更新覆盖双语 RFC、双语 roadmap 和 golden queries:P0 先做 GQ01/02 的 Goal 创建及 Agent 创建/复用,再做 GQ05/11/12 的依赖产物、peer handoff、独立验收及 GQ08/09 的纠偏恢复;P1 接共享预算和孤儿恢复;P2 接跨主机恢复。普通受支持 profile 先验小团队,再在完整 owner/兼容/drain 门槛满足后做隔离的 A 退役、B 同名重建、A 迟到返回场景。Goal lifetime、registered Agent、session/execution generation、work request/attempt 四类身份明确分开。

关键代码讲解

  1. loopx/control_plane/quota/source_admission.ts:268 的 withQuotaAccountingOwner 接管实际 source/run-index 锁见证后调用既有当前实例判定,再执行效果;路径、角色、PID/token 或 GoalRef 不一致不能获得写权限。
  2. 同文件 :349 的 withBorrowedQuotaAccountingOwner 在多阶段 monitor 调用间只释放临时 claim,保留 Python 外层锁,保证 preflight、provider、commit/replay 的归属一致。
  3. loopx/control_plane/quota/settlement_readback.ts:1210 的 readQuotaSettlementForAdmittedOwnerFromSnapshot 使用已解析 owner,并在推断 Turn 前过滤规范历史,避免把其他实例更新的结果选为当前结算。
  4. loopx/control_plane/quota/slot_accounting.py:384 的 _latest_unspent_turn_settlement_run 在 classification 与提前返回前完成 owner 过滤,保证 Python fallback 不能绕过 native 边界。

对主干的风险

重点反例是旧 A/外来历史污染 B,或 monitor 提前释放锁后继续写入。当前真实临时文件、SQLite/provider 和 Python→TypeScript 路径验证了 stale/foreign、过期或伪造见证、父进程丢失、部分事务恢复、重复 spend/void 和 native-child 归属。组件结果为 231 项 Python、279 项 TS 通过;最后一次主干集成后的 refresh/Lark/census 37 项通过。类型检查、Mypy、Ruff、文档治理及 RFC 索引检查通过。21 个 PR-only 提交均有 DCO sign-off。

独立不可变 base/head 对照重新执行了相同 public CLI fixture:先拒绝无交付凭据扣费,再持久化并独立回读结果,随后一次扣费及幂等重放。观测 hash 为 8c07ce6028d8f3075112ca0c48d843ed9d20eb2fd351dc4e7f4d3eaf84127cdf。另一路真实 native spend/void/replay 比较完整返回和七份落盘文件,零归一化且逐字节相同,观测 hash 为 0075e2b438282e1f7f19dec3e85e43f70f5262a344a67d8d6b177b83c1213441。独立敏感性探针只提供 GoalRef 而不提供 admission:base 接受,head 在效果前以 quota_source_admission_invalid 拒绝,符合规范。

语义与 CI 对齐

复用既有 GoalRef vocabulary;alias/exact_source 保持 quota 本地判别,不宣称更广泛 actor 生命周期。规则以 typed 状态与精确相等判定,不依赖 substring denylist;错误和义务保持领域中立,机器强制 fence 没有称作建议。开发期语义 advisory 与全树 drift/census 检查均执行;advisory 未检出候选不代表无语义影响。

最终 canary premerge --from-git-diff passed:10 个 catalog canary、8 个 risk-profile smoke、公开边界扫描,以及 diff/compile 检查全部通过,失败与跳过均为零,manual holds 为空。质量 receipt 与最终 base/head/diff 一致。历史审查里的模块预算失败未复用;本次同一预算命令在当前 base/head 均通过。按当前 review policy wait_for_ci=false 使用本地证据,没有轮询远端 CI。

我的整体评价

APPROVE,未发现当前 head 的阻塞项。该切片改善跨轮次归属与恢复,兼容旧用户流程;机制成本与完整 write/read/replay 边界相符,不能仅以字段补丁替代。文档给出了真实产品落地顺序,也保留 App、CLI、Lark 各入口独立验收的要求。

本次没有运行真实付费多 Agent 团队、激活 source_session_v1、资格化 PostgreSQL service 或宣称外部子进程 drain 已完成;没有新增前端设置或修改首屏。#5206 与 roadmap 组合里程碑继续开放,后续依照 M3/M4/M5 证据推进。最终合并判断绑定上述完整 head,不继承旧 head 的批准。

@mergify mergify Bot removed the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 2, 2026
@huangruiteng

Copy link
Copy Markdown
Collaborator

Maintainer merge record for a5118d08f51809762c7983e6363d4d3c92a3548f:

The repository owner explicitly requested handling this PR, adding the roadmap/RFC integration plan, and maintainer self-merge. The exact-head review is published and read back; approval closeout is clear with no blocking reviews or unresolved threads. Local risk-based premerge and exact-scope quality qualification passed.

The automatic readiness result remains false: GitHub reports REVIEW_REQUIRED under its last-push-approval rule, and BEHIND. The same authenticated comparison reports behind_by: 0, merge base 9b0486dc1b891bc5254ea85d1ba06da089d22853, and the PR reports mergeable: true. The approval is by the maintainer who appended the documentation/integration commits; it is not an independent last-push approval.

Proceeding as the owner's explicitly requested administrative self-merge exception, without changing repository rules, fabricating a passing readiness receipt, dismissing another review, or treating pending remote CI as local validation. No source-profile activation or M3/M4/M5 completion is implied.

@huangruiteng
huangruiteng merged commit 3cecb0d into loopx-project:main Oct 2, 2026
8 checks passed
@huangruiteng

Copy link
Copy Markdown
Collaborator

@Duang777 已完成最终复核、文档补充和合并:3cecb0d7cbf3d247cfd996267d7fc64627bd6e49。这次 quota 实例归属隔离已接入实际产品路线:

最终审查与验证包含 231 Python、279 TS、37 主干集成测试,独立 base/head CLI/落盘行为对比及全通过的风险 canary。本次仍只资格化 quota_settlement,没有宣称多 Agent 产品旅程或整个 profile 已完成。维护者追加提交后的管理员合并例外已单独记录。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants