Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
21 commits
Select commit Hold shift + click to select a range
57e0d9c
fix(quota): fence settlement by exact GoalRef
Duang777 Oct 1, 2026
8f73386
Merge remote-tracking branch 'origin/main' into codex/quota-goalref-o…
Duang777 Oct 1, 2026
d7e40a5
Merge remote-tracking branch 'origin/main' into codex/quota-goalref-o…
Duang777 Oct 1, 2026
5f1c15e
Merge remote-tracking branch 'origin/main' into codex/quota-goalref-o…
Duang777 Oct 1, 2026
b716a72
Merge remote-tracking branch 'origin/main' into codex/quota-goalref-o…
Duang777 Oct 1, 2026
665a783
Merge remote-tracking branch 'origin/main' into codex/quota-goalref-o…
Duang777 Oct 2, 2026
49c3735
Merge remote-tracking branch 'origin/main' into codex/quota-goalref-o…
Duang777 Oct 2, 2026
6a9bd67
Merge remote-tracking branch 'origin/main' into codex/quota-goalref-o…
Duang777 Oct 2, 2026
cd91976
Merge remote-tracking branch 'origin/main' into codex/quota-goalref-o…
Duang777 Oct 2, 2026
6069047
Merge remote-tracking branch 'origin/main' into codex/quota-goalref-o…
Duang777 Oct 2, 2026
aa58cd5
Merge remote-tracking branch 'origin/main' into codex/quota-goalref-o…
Duang777 Oct 2, 2026
15e49ae
Merge remote-tracking branch 'origin/main' into codex/quota-goalref-o…
Duang777 Oct 2, 2026
b7633c8
Merge remote-tracking branch 'origin/main' into codex/quota-goalref-o…
Duang777 Oct 2, 2026
9872aee
Merge origin/main into codex/quota-goalref-owner-fence-clean
Duang777 Oct 2, 2026
1ea609b
Merge origin/main into codex/quota-goalref-owner-fence-clean
Duang777 Oct 2, 2026
9baac7c
Merge origin/main into codex/quota-goalref-owner-fence-clean
Duang777 Oct 2, 2026
0eb351e
Merge remote-tracking branch 'origin/main' into codex/quota-goalref-o…
Duang777 Oct 2, 2026
c917678
Merge remote-tracking branch 'origin/main' into codex/quota-goalref-o…
Duang777 Oct 2, 2026
a4b4608
Merge remote-tracking branch 'origin/main' into codex/pr5389-goal-lif…
huangruiteng Oct 2, 2026
225e950
docs: connect Goal lifetime fences to small-team journeys
huangruiteng Oct 2, 2026
a5118d0
Merge commit '9b0486dc1b891bc5254ea85d1ba06da089d22853' into codex/pr…
huangruiteng Oct 2, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@

- **RFC status:** Accepted
- **Supersedes / closes:** none
- **Delivery maturity:** Identity/recovery proposal; codec prerequisite shipped in #4917
- **Delivery maturity:** Partial source-session lifetime and binding-owner implementation; quota settlement qualified in #5389; activation, orphan recovery and product acceptance remain held
- **Authors / owners:** LoopX contributors
- **Created:** 2026-09-23
- **Last normative revision:** 2026-09-23
- **Last normative revision:** 2026-10-02
- **Implementation baseline:** `23edcb19c70394480e3a9ebe8a960f5a320c5342`
- **Related contracts:** [Issue #4801](https://github.com/loopx-project/loopx/issues/4801), [orphan fence slice #4808](https://github.com/loopx-project/loopx/pull/4808)
- **Language mirror:** [Chinese semantic mirror](goal-instance-identity-and-orphan-recovery-v0.zh-CN.md)
Expand Down Expand Up @@ -718,13 +718,50 @@ already prevents execution.
| M4: orphan recovery | Reuse fence/diagnosis/path/backup owners; journaled file-state resolution with exact legacy cleanup | Preview, destructive/retry/rollback negatives and original-entry readback. Archive/delete can ship earlier without identity creation; native-provider adoption stays blocked. |
| M5: migration and product acceptance | M2–M4 plus multi-Goal quiescence/reconnection; packaged frontend and qualified Lark | 2–3 workers, dependency artifact, interrupted A, recreated B and late A return; unrelated Goal progresses; B accepted independently. No duplicate protected effect. |

M0 is a prerequisite checkpoint, not the next unstarted task. The next slice
owns M1 compatibility/consumer characterization and the M2 local lifecycle seam;
do not ship a field-only milestone as the ABA outcome. M2 and M3 describe
M0 is shipped; retain the implemented source-session lifetime transaction and
qualified binding owners. Continue from the remaining owner/compatibility gaps
in the binding inventory and the M4 recovery path tracked by #5206; do not
restart the codec or count fields as the ABA outcome. M2 and M3 describe
implementation order, not permission to activate a partially fenced system.
R2/R3 consume the completed local slice; R6 service adoption and D1–D3 provider
promotion retain their own acceptance. No new paid cohort or soak is authorized.

### Product integration through existing roadmap journeys

Use [#5206](https://github.com/loopx-project/loopx/issues/5206) for lifetime and
recovery delivery and the existing R1–R3/G1 owners under
[#4574](https://github.com/loopx-project/loopx/issues/4574) for product adoption.
The [golden-query lifecycle variant](../../product/use-cases/steward/golden-queries.md#goal-lifetime-creation-collaboration-and-recovery)
is the common scenario specification. These are planned integration exits, not
claims that the source profile is activated or that G1/M5 has passed.

| Priority / existing journey | Lifetime contribution and companion owner | Decisive observable result |
| --- | --- | --- |
| P0 · GQ01/02, R1/R2: create a Goal and create/reuse an Agent | Source lifecycle publishes the exact GoalRef; registry/onboarding and session owners reconcile creation retries and bind authorized work | Lost responses and repeated clicks create no duplicate Goal, Agent or executor; an old same-alias attachment cannot attach itself to the new Goal |
| P0 · GQ05/11/12, R2/R3/G1: dependent artifacts and independent review | Collaboration carries instance identity through request, adoption, result and original-conversation return; Todo/lease and quota retain their own acceptance/effect checks | Two real cycles use exact artifact versions; late A work cannot complete, debit or enter B's accepted synthesis; B and unrelated work still progress |
| P0 · GQ08/09, R2/R3: stop, correct and resume | Session/execution generation and claim/lease fence stale execution within one Goal; this RFC fences a retired Goal lifetime | Ordinary correction/reconnect/resume retains the GoalRef; explicit retirement/recreation changes it; both paths preserve the owed result without duplicate effects |
| P1 · GQ15, S7/R2/R3: mixed team within an agreed budget | #5389 isolates quota spend/replay/repair/void/readback by instance; existing quota and scheduler owners enforce team allocation | Replay does not double-charge or charge a successor; the team allowance is not copied to each worker. Instance accounting alone does not qualify shared-budget allocation |
| P1 · R5/M4/M5: recover orphaned work at create/connect entry | Existing diagnosis and lifecycle resolution drive preview, backup, apply/resume and explicit reconnection | The packaged App and CLI show the selected disposition and recovery result; no guessed candidate or silent adoption of old authority |
| P2 · GQ16, R6/G3: local/cloud work and reconnect | Authenticated service, remote binding, revocation and lease owners consume exact identity after their own qualification | A returning remote executor cannot commit or debit a successor; local-file evidence does not qualify a remote provider |

Keep Goal lifetime, registered Agent identity, host session/execution generation
and work request/attempt identity distinct. Reusing an Agent grants no new Goal
authority; changing its model, reconnecting or opening a Turn does not mint a
Goal instance. Intent corrections and artifact revisions retain their existing
R4/work-graph owners. Identity matching neither transfers a lease nor accepts an
artifact. No new Agent factory, scheduler or parallel task ledger is needed.

First qualify creation/reuse, two collaboration cycles and same-lifetime
interruption on an already supported profile. In an isolated qualification
environment, add the M5 retirement/recreation variant only after the selected
source profile's M2/M3 owner, old-writer and effect-drain gates are satisfied;
include M4 if orphan resolution is exercised. Component fixtures may run before
that gate but cannot certify the live journey. Use the packaged App with
independent CLI/source readback; Lark retains separate transport/audience
qualification. Record entry/retry, receiver adoption, artifact acceptance,
instance-scoped settlement and original-route return separately. #5389 qualifies
only `quota_settlement`; missing companion owners remain open in #5206.

## 12. Open decisions and holds

1. **Supported package/profile matrix:** release and host owners pin all supported
Expand Down Expand Up @@ -840,6 +877,33 @@ promotion retain their own acceptance. No new paid cohort or soak is authorized.
drain, unsupported/warm binary coverage, or any other M3 row.
`execution_authority: false` and the overall activation hold remain.

### 2026-09-30: M3 quota settlement owner candidate

- **Baseline:** `3ec049e13`.
- **Proposed:** Bind source-profile quota spend, replay, receipt repair, void,
settlement readback, and rolling-window accounting to the caller-captured
exact GoalRef. Python hands the ordered run-index and Goal-lifecycle lock
witnesses to the TypeScript accounting owner. TypeScript validates both
witnesses and reuses `decideFirstPartyHostRuntime(require_current)`.
Single-phase accounting adopts the witnesses through artifact commit;
multi-phase monitor accounting borrows them while Python retains the
enclosing lock scope across preflight, provider writeback, and commit.
- **Evidence:** TypeScript and Python integration tests publish same-alias Goal
B after Goal A capture and prove that stale A writes nothing. They also cover
B-only spend and void, cross-instance replay and prepared-receipt repair
rejection, exact settlement readback, per-instance rolling-window accounting,
mixed alias/exact fallback history, and exact auxiliary monitor preflight,
exception, commit, and replay under one admission.
- **Compatibility:** Non-source spend, replay, void, and readback requests omit
GoalRef and source admission. Their persisted records, receipts, response
payloads, and lock behavior retain the legacy shape.
- **Remaining hold:** This qualifies only the `quota_settlement` inventory row.
The source-profile provider journey remains behind its existing activation
gate; the native monitor evidence does not claim that route is activated.
Unsupported and warm binaries, downstream external-effect drain, and every
other unqualified M3 owner remain blocked. `execution_authority: false` and
the overall activation hold remain unchanged.

## Appendix B: Decision log

| Date | Decision | Owner / approval | Alternatives | Normative sections changed |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@

- **RFC 状态:** 已接受
- **替代 / 关闭:** 无
- **交付成熟度:** Identity/recovery 提案;codec 前置已由 #4917 交付
- **交付成熟度:** source-session 生命周期与 binding owner 部分实现;#5389 资格化 quota settlement;activation、孤儿恢复与产品验收仍受限
- **作者/Owner:** LoopX contributors
- **创建日期:** 2026-09-23
- **最后规范修订:** 2026-09-23
- **最后规范修订:** 2026-10-02
- **实现基线:** `23edcb19c70394480e3a9ebe8a960f5a320c5342`
- **相关契约:** [Issue #4801](https://github.com/loopx-project/loopx/issues/4801)、[orphan fence 切片 #4808](https://github.com/loopx-project/loopx/pull/4808)
- **语言镜像:** [英文语义镜像](goal-instance-identity-and-orphan-recovery-v0.md)
Expand Down Expand Up @@ -652,11 +652,40 @@ retry 必须幂等。External manual cleanup 只作提示,因为 logical revoc
| M4:orphan recovery | 复用 fence/diagnosis/path/backup owner;journaled file-state resolution 与精确 legacy cleanup | Preview、destructive/retry/rollback negative、原入口 readback;archive/delete 可提前交付但不创建身份,native-provider adoption 仍阻塞。 |
| M5:迁移与产品验收 | M2–M4、多 Goal quiescence/reconnection、packaged frontend、已资格化 Lark | 2–3 worker、一条产物依赖、中断 A、重建 B、迟到 A return;无关 Goal 继续,B 独立验收;无重复 protected effect。 |

M0 是前置 checkpoint,不是下一个尚未开始的任务。下一切片承担 M1 compatibility/
consumer 刻画及 M2 本地 lifecycle seam,不能把加字段当作 ABA outcome。M2/M3
M0 已交付;保留已实现的 source-session lifetime transaction 和已资格化 binding
owner。继续处理 binding inventory 的剩余 owner/compatibility 缺口以及 #5206
跟踪的 M4 恢复路径;不重建 codec,也不把加字段当作 ABA outcome。M2/M3
描述实现顺序,不授权激活部分有 fence 的系统。R2/R3 消费完成的本地切片;R6
service adoption、D1–D3 provider promotion 保留各自验收。不授权付费 cohort/soak。

### 通过既有 roadmap 旅程接入产品

生命周期与恢复交付继续归 [#5206](https://github.com/loopx-project/loopx/issues/5206),
产品采用归 [#4574](https://github.com/loopx-project/loopx/issues/4574) 下既有 R1–R3/G1
owner。[golden-query 生命周期变体](../../product/use-cases/steward/golden-queries.md#goal-lifetime-creation-collaboration-and-recovery)
是共用场景规范。以下是计划中的集成出口,不表示 source profile 已激活或 G1/M5 已通过。

| 优先级 / 既有旅程 | 生命周期贡献与配套 owner | 决定性的可观察结果 |
| --- | --- | --- |
| P0 · GQ01/02、R1/R2:创建 Goal,创建或复用 Agent | Source lifecycle 发布精确 GoalRef;registry/onboarding 与 session owner 核对创建重试并绑定获授权工作 | 响应丢失、重复点击不产生重复 Goal、Agent 或 executor;同名旧 attachment 不能自行接入新 Goal |
| P0 · GQ05/11/12、R2/R3/G1:依赖产物与独立复核 | Collaboration 在请求、采用、结果与原会话返回中携带实例身份;Todo/lease 与 quota 保留各自验收和效果检查 | 两轮真实协作使用精确产物版本;迟到 A 工作不能完成 B、扣 B 的额度或进入 B 已验收汇总;B 和无关工作继续推进 |
| P0 · GQ08/09、R2/R3:停止、纠偏、恢复 | Session/执行代次和 claim/lease 隔离同一 Goal 内过期执行;本 RFC 隔离已退役 Goal 的生命周期 | 普通纠偏、重连、恢复保留 GoalRef;明确退役后重建才改变它;两条路径都保留结果返回义务且不重复执行效果 |
| P1 · GQ15、S7/R2/R3:既定预算内的混合小队 | #5389 按实例隔离 quota spend/replay/repair/void/readback;团队分配仍由既有 quota/scheduler owner 强制执行 | 重放不重复扣账,也不扣继任实例;团队额度不会复制给每个 worker。实例记账本身不资格化共享预算分配 |
| P1 · R5/M4/M5:从创建/接入入口恢复孤儿工作 | 既有诊断与生命周期 resolution 驱动 preview、backup、apply/resume 和明确重连 | Packaged App 与 CLI 显示选定处置和恢复结果;不猜测 candidate,不静默继承旧 authority |
| P2 · GQ16、R6/G3:本地/云端协作与重连 | 认证服务、远端 binding、撤销和 lease owner 在独立资格化后消费精确身份 | 返回的远端 executor 不能向继任实例提交或扣账;本地文件证据不资格化远端 provider |

区分 Goal 生命周期、注册 Agent 身份、host session/执行代次和工作请求/尝试身份。
复用 Agent 不授予新 Goal 权限;换模型、重连或新开 Turn 不生成 Goal 实例。
意图纠偏和产物修订继续归既有 R4/work-graph owner。身份匹配不转移 lease,也不验收
产物。不新增 Agent factory、scheduler 或平行任务账本。

先在已支持 profile 上验收创建/复用、两轮协作和同生命周期中断。隔离资格化环境中的
M5 退役/重建变体,须等待所选 source profile 的 M2/M3 owner、旧 writer 排除与
effect-drain 门槛全部满足;涉及孤儿 resolution 时还需 M4。组件夹具可提前运行,
但不能证明真实旅程完成。以 packaged App 和独立 CLI/source 回读验收;Lark 保留
独立 transport/受众资格。分别记录入口/重试、接收方采用、产物验收、实例内结算和
原路返回。#5389 仅资格化 `quota_settlement`;缺失配套 owner 继续在 #5206 跟踪。

## 12. 未决事项与 hold

1. **受支持 package/profile matrix:** release/host owner 在 M2 activation 前固定
Expand Down Expand Up @@ -761,6 +790,30 @@ service adoption、D1–D3 provider promotion 保留各自验收。不授权付
binary 或其他 M3 行已完成。`execution_authority: false` 和总 activation hold
保持不变。

### 2026-09-30:M3 quota settlement owner 候选

- **基线:** `3ec049e13`。
- **候选实现:** Source profile 的 quota spend、replay、receipt repair、void、
settlement readback 与 rolling-window accounting 均绑定调用方预先捕获的精确
GoalRef。Python 按顺序把 run-index 与 Goal lifecycle lock witness 交接给
TypeScript accounting owner。TypeScript 校验两个 witness,并复用
`decideFirstPartyHostRuntime(require_current)`。单阶段 accounting 会接管
witness 直至 artifact commit;多阶段 monitor accounting 只借用 witness,
由 Python 在 preflight、provider writeback 与 commit 的完整外层范围内持锁。
- **证据:** TypeScript 与 Python 集成测试在 Goal A 捕获后发布同名 Goal B,
证明迟到的 A 不产生任何写入。测试还覆盖 B 独立 spend/void、跨实例 replay
和 prepared receipt repair 拒绝、精确 settlement readback,以及按实例隔离的
rolling-window accounting、alias/exact 混合 fallback 历史,以及在同一
admission 下的 exact auxiliary monitor preflight、异常、commit 与 replay。
- **兼容性:** 非 source 的 spend、replay、void 与 readback 请求不携带 GoalRef
或 source admission;其持久化 record、receipt、响应 payload 和锁行为保持
legacy 形态。
- **剩余 hold:** 本切片只资格化 `quota_settlement` inventory 行。Source
profile provider journey 仍受既有 activation gate 限制,native monitor
证据不表示该路径已启用。不支持及常驻
binary、downstream external-effect drain 和其他未资格化 M3 owner 继续受阻。
`execution_authority: false` 和总 activation hold 保持不变。

## 附录 B:决策日志

| 日期 | 决策 | Owner/批准 | 替代方案 | 变更的规范章节 |
Expand Down
Loading
Loading