You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[Task][RFC]: Qualify DSH/Pi observation and managed-runtime selection #5208
验收 DSH/Pi 观测与托管运行时选择。One task tracks this RFC's delivery; keep implementation PRs and milestone evidence here instead of creating a parallel task tree.
Canonical design: RFC. Roadmap: S4/S10/S11, under #4574. Design acceptance is distinct from implementation, live qualification and promotion.
Current boundary
Comparative source audit: main at ce3862e33 (2026-09-28); that audit does not establish live observer qualification.
The bounded DSH install/compatibility repair #5589 is merged at 4e820bb0ced6c0f8dff2acd641a6c19dbc986935 (reviewed head 4c08ea3d293a66c24a65fabcfbfaa35420248cb4, integrated main baseline bfe3c434). It qualifies the existing provider on 0.2.0-rc.2 while retaining supported legacy lifecycle behavior and requires the already released Windows-safe LoopX 1.2.4 CLI. The final risk-based validation passed frozen install, types, peer ranges, 206 tests, exact registry bundles and four rows, wrong-tag/discovery/integrity rejection, removal, packed artifact/profile, real 0.2 web runtime/shared carrier, full semantic validation and the 22-path public boundary scan. Earlier real 0.1.7/frozen 0.1.5 and isolated PyPI bootstrap/native skill/reopen evidence remains explicitly bounded; fresh floating 0.1.5 upstream startup fails on both baseline and candidate. The patched fflate development dependency was requalified. Earlier broad canary/CI failures are recorded, not labeled green; Windows distribution CI passed on the earlier 5b4a885 head. Current existing managed review policy does not consult remote CI. The complete exact-head review was published/read back and merge readiness returned ready before the explicitly authorized merge.
Beta.6 is now published from merged commit 5eee730c201a374d57e6695139bdbe0ea8eac782. Downloaded GitHub bytes match the tagged build (SHA-256 5c36776ded02ea330f560fa5395ed8deef144b59690ac15353df1c7263474a90). The illustrated upgrade guide belongs to the verified personal user account; final text and all three real DSH screenshot bytes were read back. #5680 updates the approved install entry, and #5687 reconciles this evidence in the RFC. Optional npm publishing remains unconfigured; GitHub package distribution does not require an npm account.
Published-byte qualification passed native DSH 0.2 URL installation, beta.5-on-compatible-0.1.5 to beta.6-on-0.2 upgrade/removal, offline plugin tgz install/removal, packed real SDK/HTTP runtime and VM Client lifecycle, and a clean Linux container with the released LoopX 1.2.4 wheel for PEP 668 private installation, skills, launch authentication and GoalBar readback. The original source-wheel Docker script failed for an unbuilt Chat bundle; the independent release-wheel harness passed using artifact copying. In a real macOS DSH 0.2 browser, a synthetic Goal and preconfigured unique binding passed Start/Pause through the published CLI (active/stopped read back); an unactivated Session added no model turn. This does not qualify model-driven continuation, observer fidelity or Windows desktop.
As of 2026-10-10, awesome-directory #6633 is merged and its deployed directory selects beta.6. The actual Hub 1.6.4 English/Chinese feeds (api.dsh-plugin.org/plugins.en.json and plugins.zh.json) and website still select beta.5. Those feeds are separate consumers; upstream #146 tracks their correction. Upgrading Hub or merging the awesome-directory update does not establish Hub adoption. Native direct installation of the published beta.6 URL was requalified on isolated macOS DSH 0.2.0-rc.2 with pnpm 11.25.0 and Hub 1.6.4, including package versions, four rows and actual Web loading.
Hub #98 shipped in 1.5.0. Hub #102 merged on 2026-10-07, and current Hub 1.6.4 ships the checksum-policy diagnostic, bilingual recovery guidance and actual-command reporting. Earlier packed-candidate failure-dialog/notification and backup-preserving recovery evidence remains bounded to macOS. Shipping the guidance does not repair existing lockfiles or establish why reported Windows lockfiles lost integrity.
The 24 open generated install reports separate into four evidence classes: 11 outer-wrapper-only failures, four exact missing-tarball-integrity failures, eight repository-root Git/preflight failures, and one Windows desktop-host bootstrap-module failure. Actionable current replies are published/read back on #6053, #5852 and #5688. The existing report classification is not proof that every wrapper has the same underlying error. Keep unresolved platform readback open; do not close them from merged PR counts.
Native browser hot uninstall remains failed in published beta.6: fresh Hub 1.6.4 removal deletes the dependency but withdrawing loopxBootstrap stops the shared Web rows and disconnects the browser. A no-effect plugin control preserved the same host, narrowing the fault to LoopX's shared dependency patch. A proposed repair in #6102 removes that dependency while keeping native Loader readiness and LoopX-owned Host/Driver gating. Its packed real 0.2.0-rc.2 and 0.1.5-rc.2 regressions passed delayed initialization before readiness, live-disable/route retirement and disabled-package cold boot. Real macOS DSH 0.2 + Hub 1.6.4 browser Uninstall → Complete → refresh passed: backend task done/exit 0, no restart required, package dependency removed, Hub present and LoopX absent. This candidate is not a new published package and is independent of the install-report recovery.
Failed or unverified: For released beta.6, close DSH before native CLI removal and restart afterwards. #5671 remains a missing Windows desktop-host CLI module before plugin loading; do not label it a missing LoopX entry or claim it fixed by beta.6. Windows desktop full market install/init/control/upgrade/remove, unknown inner wrapper errors, lockfile-origin diagnosis and external-network recovery remain unverified. Offline tgz recovery needs compatible host/CLI dependencies or caches. C0/C1, overhead, retention/deletion and runtime-selection acceptance remain open.
DSH is the first L1 event source, not an automatically preferred production runtime. Combined diagnostic status/receipt readback exists; mode/session support and manager transport have separate partial evidence.
Work remaining
Complete the remaining existing provider delivery: correct/read back actual Hub feeds under upstream Document benchmark seam self-merge policy #146; review/merge and separately release/qualify the native hot-uninstall repair in #6102; obtain inner pnpm evidence for wrapper-only reports and establish reported Windows lockfile origin; repair/read back Windows desktop-host [dsh-plugin.org | dsh-plugin-hub] plugin install failed: loopx-project/loopx #5671 and the full Windows/0.2 market journey. These are independent gaps. Public beta.6 and the personal guide are delivered; npm remains optional.
Complete the RFC’s C0/C1, overhead and retention/deletion decision record before claiming an observer-qualified profile.
Separately qualify managed lifecycle behavior and make runtime selection follow explicit user intent and current readiness; retain Pi as a candidate, not a predetermined migration.
Ownership and ongoing work
This task owns comparative runtime/observer evidence. Session-mode RFC owns admission, and reliability-diagnostics RFC owns diagnostic product/retention. Reuse existing providers and #3243; no live model spend or retention deletion is granted by issue publication.
Contribution route: implementation/integration overlaps active work. Start from the linked current owners/PRs and identify an unowned acceptance gap in a claim comment; do not begin a competing rewrite.
Acceptance
Freeze treatments and thresholds before authorized experiments; preserve failed runs, uncertainty and no-uplift outcomes.
Exact session/run identity and observation age prevent a stale goal ledger being shown as current health.
Start/resume/interrupt/close, crash and duplicate completion preserve one executor; observation cannot influence prompts or scheduler decisions.
Reconcile the RFC's current delivery checkpoint and this issue with the integrated revision, commands, passed/failed/untested evidence and remaining gates. Close the accepted scope only; no claim that a merged PR alone completes the RFC.
Base: latest main. Reuse the existing typed owner and provider boundaries. Include affected CLI/frontend/Lark companions; verify real entrypoints and backend where changed. Preserve existing first-screen review and maintainer merge gates. Public artifacts contain only synthetic/public-safe evidence, no private operational state. This task does not authorize provider promotion, benchmark launches, release/deployment or unrelated protected effects.
I'd like to take the bounded exact-session/run diagnostic read contract slice of the second Acceptance row, separate from #5589's install/compatibility work and the Hub release route.
The RFC's Implemented Readback Increment explicitly requires a future consumer to refuse to label a stale or multi-run goal ledger as current session health. Today, build_diagnostic_projection() folds every ordered envelope in the goal ledger into one stage; the CLI binds only goal_id and an evaluation timestamp. The receipt exposes treatment/run identities, but a caller cannot pin the session/observer/treatment it expects before consuming that stage. Existing replay/age tests cover explicit timestamps and read-only behavior, so simply adding another fixture would not close this consumer gap.
I plan an opt-in manual status read that carries the caller's expected provider/observer/session identity plus the existing typed treatment identity, an explicit evaluation time, and a caller-declared maximum observation age. It will return typed ineligibility for mismatched or ambiguous identities, stale/future observations, and non-valid integrity instead of presenting an aggregate stage as that binding's current health. The existing unbound historical response remains compatible. Positive and independent negative tests will exercise the real CLI/readback seam and assert that neither ledger nor canonical work state is changed.
This is a reusable read contract prerequisite, not C0/C1 live qualification, a Mode B panel, automatic polling, runtime promotion, overhead measurement, or retention/deletion work. No provider calls or maintainer-owned benchmark runs are included. I'll keep the delivered checkpoint and remaining live qualification gates distinct. Please flag any existing owner of this exact read-contract slice so I can avoid overlapping their work.
Outcome / 目标
验收 DSH/Pi 观测与托管运行时选择。One task tracks this RFC's delivery; keep implementation PRs and milestone evidence here instead of creating a parallel task tree.
Canonical design: RFC. Roadmap: S4/S10/S11, under #4574. Design acceptance is distinct from implementation, live qualification and promotion.
Current boundary
Comparative source audit:
mainatce3862e33(2026-09-28); that audit does not establish live observer qualification.The bounded DSH install/compatibility repair #5589 is merged at
4e820bb0ced6c0f8dff2acd641a6c19dbc986935(reviewed head4c08ea3d293a66c24a65fabcfbfaa35420248cb4, integrated main baselinebfe3c434). It qualifies the existing provider on 0.2.0-rc.2 while retaining supported legacy lifecycle behavior and requires the already released Windows-safe LoopX 1.2.4 CLI. The final risk-based validation passed frozen install, types, peer ranges, 206 tests, exact registry bundles and four rows, wrong-tag/discovery/integrity rejection, removal, packed artifact/profile, real 0.2 web runtime/shared carrier, full semantic validation and the 22-path public boundary scan. Earlier real 0.1.7/frozen 0.1.5 and isolated PyPI bootstrap/native skill/reopen evidence remains explicitly bounded; fresh floating 0.1.5 upstream startup fails on both baseline and candidate. The patched fflate development dependency was requalified. Earlier broad canary/CI failures are recorded, not labeled green; Windows distribution CI passed on the earlier5b4a885head. Current existing managed review policy does not consult remote CI. The complete exact-head review was published/read back and merge readiness returned ready before the explicitly authorized merge.Beta.6 is now published from merged commit
5eee730c201a374d57e6695139bdbe0ea8eac782. Downloaded GitHub bytes match the tagged build (SHA-2565c36776ded02ea330f560fa5395ed8deef144b59690ac15353df1c7263474a90). The illustrated upgrade guide belongs to the verified personal user account; final text and all three real DSH screenshot bytes were read back. #5680 updates the approved install entry, and #5687 reconciles this evidence in the RFC. Optional npm publishing remains unconfigured; GitHub package distribution does not require an npm account.Published-byte qualification passed native DSH 0.2 URL installation, beta.5-on-compatible-0.1.5 to beta.6-on-0.2 upgrade/removal, offline plugin tgz install/removal, packed real SDK/HTTP runtime and VM Client lifecycle, and a clean Linux container with the released LoopX 1.2.4 wheel for PEP 668 private installation, skills, launch authentication and GoalBar readback. The original source-wheel Docker script failed for an unbuilt Chat bundle; the independent release-wheel harness passed using artifact copying. In a real macOS DSH 0.2 browser, a synthetic Goal and preconfigured unique binding passed Start/Pause through the published CLI (
active/stoppedread back); an unactivated Session added no model turn. This does not qualify model-driven continuation, observer fidelity or Windows desktop.As of 2026-10-10, awesome-directory #6633 is merged and its deployed directory selects beta.6. The actual Hub 1.6.4 English/Chinese feeds (
api.dsh-plugin.org/plugins.en.jsonandplugins.zh.json) and website still select beta.5. Those feeds are separate consumers; upstream #146 tracks their correction. Upgrading Hub or merging the awesome-directory update does not establish Hub adoption. Native direct installation of the published beta.6 URL was requalified on isolated macOS DSH 0.2.0-rc.2 with pnpm 11.25.0 and Hub 1.6.4, including package versions, four rows and actual Web loading.Hub #98 shipped in 1.5.0. Hub #102 merged on 2026-10-07, and current Hub 1.6.4 ships the checksum-policy diagnostic, bilingual recovery guidance and actual-command reporting. Earlier packed-candidate failure-dialog/notification and backup-preserving recovery evidence remains bounded to macOS. Shipping the guidance does not repair existing lockfiles or establish why reported Windows lockfiles lost integrity.
The 24 open generated install reports separate into four evidence classes: 11 outer-wrapper-only failures, four exact missing-tarball-integrity failures, eight repository-root Git/preflight failures, and one Windows desktop-host bootstrap-module failure. Actionable current replies are published/read back on #6053, #5852 and #5688. The existing report classification is not proof that every wrapper has the same underlying error. Keep unresolved platform readback open; do not close them from merged PR counts.
Native browser hot uninstall remains failed in published beta.6: fresh Hub 1.6.4 removal deletes the dependency but withdrawing
loopxBootstrapstops the shared Web rows and disconnects the browser. A no-effect plugin control preserved the same host, narrowing the fault to LoopX's shared dependency patch. A proposed repair in #6102 removes that dependency while keeping native Loader readiness and LoopX-owned Host/Driver gating. Its packed real 0.2.0-rc.2 and 0.1.5-rc.2 regressions passed delayed initialization before readiness, live-disable/route retirement and disabled-package cold boot. Real macOS DSH 0.2 + Hub 1.6.4 browser Uninstall → Complete → refresh passed: backend task done/exit 0, no restart required, package dependency removed, Hub present and LoopX absent. This candidate is not a new published package and is independent of the install-report recovery.Failed or unverified: For released beta.6, close DSH before native CLI removal and restart afterwards. #5671 remains a missing Windows desktop-host CLI module before plugin loading; do not label it a missing LoopX entry or claim it fixed by beta.6. Windows desktop full market install/init/control/upgrade/remove, unknown inner wrapper errors, lockfile-origin diagnosis and external-network recovery remain unverified. Offline tgz recovery needs compatible host/CLI dependencies or caches. C0/C1, overhead, retention/deletion and runtime-selection acceptance remain open.
DSH is the first L1 event source, not an automatically preferred production runtime. Combined diagnostic status/receipt readback exists; mode/session support and manager transport have separate partial evidence.
Work remaining
Ownership and ongoing work
This task owns comparative runtime/observer evidence. Session-mode RFC owns admission, and reliability-diagnostics RFC owns diagnostic product/retention. Reuse existing providers and #3243; no live model spend or retention deletion is granted by issue publication.
Contribution route: implementation/integration overlaps active work. Start from the linked current owners/PRs and identify an unowned acceptance gap in a claim comment; do not begin a competing rewrite.
Acceptance
Starting points and delivery boundary
Base: latest
main. Reuse the existing typed owner and provider boundaries. Include affected CLI/frontend/Lark companions; verify real entrypoints and backend where changed. Preserve existing first-screen review and maintainer merge gates. Public artifacts contain only synthetic/public-safe evidence, no private operational state. This task does not authorize provider promotion, benchmark launches, release/deployment or unrelated protected effects.