Skip to content

[Task][RFC]: Deliver the Agent IM / LoopX / OpenViking collaboration contract #5198

Description

@huangruiteng

Outcome / 目标

交付 IM、LoopX 与 OpenViking 三方协作契约。One task tracks this RFC's delivery; keep implementation PRs and milestone evidence here instead of creating a parallel task tree.

Canonical design: RFC. Roadmap: S3/S6/S9, under #4574. Design acceptance is distinct from implementation, live qualification and promotion.

Current boundary

Source audit: main at ce3862e33 (2026-09-28). This is source/PR inspection, not a new test or live-qualification claim.

IM delivery, canonical work/claim authority and memory providers already exist separately. The RFC index does not claim the integrated three-owner journey. Memory retrieval must not become claim or execution authority.

Work remaining

  • Compose the RFC’s first real room projection and revision-guarded claim interaction through existing Goal Channel and Todo owners; return the canonical receipt beside the interaction.
  • Keep scoped OpenViking retrieval read-only; carry authorized artifact references and recheck authority after reconnect.

Ownership and ongoing work

Reuse #4339 for semantic handoff, #3245 for shared authority and #3964 for bot provisioning. This task owns their composition, not a replacement transport, scheduler or memory store.

Contribution route: available for a bounded proposal/PR within this RFC. Name the intended milestone and exact files in a claim comment so simultaneous contributors do not duplicate work.

Acceptance

  • Two competing hosts yield one accepted claim; same-key retries do not create another transition.
  • Stale cards, revoked scope, unavailable authority and reconnect cannot create authority or disclose private content.
  • Show the room interaction, direct CLI readback and recovery on an authorized non-production setup; synthetic evidence stays labelled.
  • Reconcile the RFC's current delivery checkpoint and this issue with the integrated revision, commands, passed/failed/untested evidence and remaining gates. Close the accepted scope only; no claim that a merged PR alone completes the RFC.

Starting points and delivery boundary

Base: latest main. Reuse the existing typed owner and provider boundaries. Include affected CLI/frontend/Lark companions; verify real entrypoints and backend where changed. Preserve existing first-screen review and maintainer merge gates. Public artifacts contain only synthetic/public-safe evidence, no private operational state. This task does not authorize provider promotion, benchmark launches, release/deployment or unrelated protected effects.

Activity

  1. LIHUA919 commented on Sep 28, 2026

    @LIHUA919
    Contributor

    Scoped contribution: local claims, callbacks and private reconnect context

    Draft #5248, proposed head 87ac09725, based on main at 738115bde87e.

    The proposal composes existing Goal Channel, canonical Todo and scoped Turn Recall owners. project|claim returns room orientation and historical receipt/current ownership; offer|revoke and the default-off authenticated collector provide one fixed claim interaction. work resume returns private read-only context and explicitly requested scoped references after current authority/quota readback. It never accepts/renews work or sends private context into the room.

    Qualified locally: 110 room/claim/callback/restore regressions passed on disposable File/SQLite stores with synthetic Lark/provider transport. Competition now uses independent source CLI processes with separate TS runtimes, a new client/runtime for exact-key retry, and separate direct CLI ownership readback. One transition/result card; stale or revoked scope cannot act or disclose private content. Two proposal CI regressions (UTF-8 offer reading and a stale recall-loader mock) were repaired; 58 related checks and all 19 standard premerge checks passed. This proves local registered-client behavior, not independently authenticated remote hosts.

    CI: six failures on prior head 9036ba8c7 also occur on exact pinned main (main run, prior-head run). They concern canonical User Todo fixtures and scheduler ACK. Exact-head 87ac09725 CI completed with those same six pinned-main failures (run); no additional proposal failure was observed. DCO, dependency review, builds, typed core and real PostgreSQL integration passed. Full-CI and maintainer acceptance remain unqualified.

    Remaining: authorized non-production native rendering/listener, independently authenticated hosts, live daemon reconnect and scoped OV retrieval; arbitrary external artifact target access remains unqualified. Exact GoalRef support requires the existing shared-authority/Goal-instance owners to bind heads, operation receipts, retirement and old writers consistently. Source-session effects stay closed; existing wires reject unqualified GoalRef intent. That later profile does not make a parallel authority migration a prerequisite for this legacy-profile local stage.

    The RFC checkpoint and usage guide preserve those boundaries. Reuse #3245, #4339 and #3964 for authority, handoff and provisioning. No active Goal promotion, live room write, deployment or self-merge occurred. Keep draft/maintainer review gates and all full issue acceptance boxes open.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions