fix(quota): preserve and sign TurnEnvelope settlement plans - #5636
Conversation
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Exact head: 5636@6ffbb44070996fadbf0d96056f465df6226055a6; immutable base f512891.
未发现阻塞。APPROVE限定于结算契约投影完整性修复;不代表短上下文推广或模型效率已验收。
动机
选择 TurnEnvelope 短包、准备写回成果并结算原 Turn 的 CLI 或宿主使用者。 使用短包推进已有任务时,旧版本能报告行动签名一致,却省略结算身份、条件步骤和宿主交接;较长命令还会被裁到420字符,需要重新读取完整结果或重建步骤。新版本直接携带原计划和完整命令,仍由原准入和回执规则执行。 同一输入base/head确认旧包无计划、新包完整保留;真实隔离CLI拒绝提前spend,写回后原Turn只结算一次并可幂等重放。六种计划修改均被真实host verifier拒绝。 本评审不证明实际模型收益、默认短包推广、同Turn缓存详情、全量跨host或正式安装采用。 现有短上下文/R5 owner继续同Turn缓存详情、normal/replan上下文选择、模型受控对照及默认view推广;复杂真实包仍超8KiB。
改动思路
原effect identity、步骤条件、期望回执和host handoff已在共享结算owner生成,最小修复是在现有TS短包投影直接保留,禁止从命令预览重新拼计划。hash相等只能证明覆盖维度一致,不能证明授权或真实执行。无计划输入继续使用旧coverage,默认完整CLI、MCP complete_task和原结算规则保留。
独立规范是修复前 docs/reference/protocols/turn-envelope-v0.md,固定于f51289168e402111e535a7ecb0d26333eb24c588:TurnEnvelope v0的投影/默认边界implemented;Budget warnings and allocation的权限、完整命令与未放宽预算implemented;Multi-State Parity Evidence的default推广条件deferred,现有短上下文owner继续。另读同base的docs/architecture/rfcs/agent-loop-effect-interpreter-v0.md,M7.2原身份/条件/回执及R5投影约束、Core-Path Adoption Matrix中scheduler outside settlement不变。作者修改的checkpoint不能充当验收oracle。
具体改动
完整8路径 +196/-4:TS projection/coverage、Python兼容常量、delivery differential迁移;2测试路径与3协议/RFC文档。125行新回归覆盖真实CLI和计划突变。没有新store、builder、executor、capability开关或增长预算。
关键代码讲解
- actionProjection读取原cli_channel.settlement_plan,只有实际非空计划才拷入writeback;normal next_cli_actions保留原完整字符串。旧无计划/replan选择分支继续运行,来源对象不变。
- signatureCoverage在plan-bearing输入选择v5;已有签名document已经覆盖wholewriteback,因此identity、ordered_steps、conditional、expected_receipt和host_handoff全部参与完整性核验,无需第二签名owner。
- _action_signature_migration仅接受原v0–v4到v5的显式迁移并要求review;不加size allowance,逆迁移、未知v999和同v5不同hash仍拒绝。
- test_real_cli_envelope_settles_original_turn_once实际使用隔离CLI生成并消费计划,提前spend无记录,原Turn写回后spend一次,重放幂等。额外直接调用真实extract_turn_authority,六种身份/顺序/条件/回执/host/removal突变全部拒绝。
对主干的风险
本轮369 Python(176.62s)、19 TS、typecheck、Ruff、diff、advisory→full semantic通过。真实CLI不是mock receipt;TempFile/runtime与synthetic Goal隔离,没有改活跃authority。初次错误pytest文件名未收集,改用实际路径完整通过;初次私有观察把matrix patch当payload,改为相同独立fixture+patch后通过。保留失败,未改产品断言。无PostgreSQL store/provider重构,因此未运行PG服务;没有paid model、实际App安装采用或CI查询/等待。
独立同输入base/head15场景:本机只读捕获的bound normal从14265→16922bytes(+2657),两个原命令长度420/371→470/371;697字符长命令旧包420、新包697。标准delivery加现有plan从5127→7735bytes,仍小于8192。原plan-free、MCP executor-owned、historical receipt与9个旧matrix场景完整envelope逐字节相同;action、boundary、scheduler等授权投影未漂移。生产capture只用于本地只读验证,公共评审只提供泛化尺寸。
复杂capture在base已超8KiB,新head加重,当前warning清晰保留,标准fixture和原delivery growth gates未放松。这是必要完整性成本,不可拿它宣传更省token;后续应在现有context owner压缩重复观察/使用已有cold-path,不能截断执行契约、提高预算掩盖增长。15场景不等于所有真实Goal/Agent及模型连续运行资格。
语义与 CI 对齐
v5是既有shared action-signature vocabulary扩展;Python常量只是兼容投影与delivery校验,没有平行决策源。advisory不识别scalar版本常量,0finding不能证明语义没有变化;全树仍44未证明producer,保留限制。optional view只由原explicit --turn-envelope选择,默认fullCLI、无计划/MCP与原历史读路径隔离。签名一致性不认证执行来源,准入和receipt仍在原owner。
我的整体评价
APPROVE。长程正向证据是原结算身份/义务不丢失、提前spend拒绝、原Turn重放不重复扣款;体验正向是已有信息与长命令能直接带到下一步,不用重建已知契约。新包较大是实测代价;模型耗时/token/完成率净收益尚未测,默认推广仍deferred。
Future-facing pass:现有writeback已参与签名,复用它及canonical plan,避免新builder/signer;保留一个typed projection owner。更大的cached-detail/context选择工作留给既有R5短上下文owner,无新增形式性任务。此运行时/控制面PR按当前仓库规则交维护者合并;本轮没有自合并或本机升级。
English verdict: APPROVE - 5636@6ffbb44070996fadbf0d96056f465df6226055a6; canonical settlement identity, conditional steps and host handoff survive the opt-in envelope, long commands remain intact, and six real host mutations reject. 369 Python/19 TS and focused checks pass; real isolated CLI rejects premature spend and settles/replays once. Larger packets are measured; model efficiency/default promotion remain unqualified.
|
Pre-merge qualification for 5636@6ffbb44070996fadbf0d96056f465df6226055a6. The existing full exact-head approval review is preserved; no duplicate review was posted. Changed surfaces are the opt-in TS TurnEnvelope projection, Python compatibility coverage constant, delivery-differential migration, their regressions and protocol/RFC documentation. Independent merge validation: 274 Python settlement/envelope/output tests, 19 native TS envelope tests, control-plane typecheck, 69 semantic inventory/exception checks, focused Ruff and diff hygiene pass. The real isolated CLI rejects premature spend, preserves the original identity, then writes back/spends once and replays idempotently. Same-input base/head projection preserves a plan-free envelope exactly, retains the canonical plan, and keeps a 642-character command that the base truncated at 420. A complex bound capture grows from 17,550 to 20,116 UTF-8 bytes; both exceed the unchanged 8 KiB target. This is a measured integrity cost, not evidence of token savings, model benefit or default promotion. The strict quality receipt cqr_0f2099064b31d326e9ef passed and was verified BEFORE merge against live main 796cb29 and this unchanged eight-file diff. Future-facing pass reuses the existing plan and writeback signer; no second builder, decision or execution authority was added. Failures retained: an initial TS invocation used an unavailable tsx loader; the repository's native Node TS runner passed. An initial semantic test path did not exist; both actual architecture inventory modules passed. No product assertions or budgets were relaxed. CI was not queried, polled or awaited. PostgreSQL is unaffected; paid model/default-promotion/installed-host qualification remains untested. Closeout is clear. GitHub's aggregate remains REVIEW_REQUIRED because the same GitHub author account cannot formally self-approve; COMMENTED is the exact-head approval conclusion, not a platform APPROVED claim. Merge is separately maintainer-authorized, requires a fresh native readiness readback, and uses an exact-head guard for admin bypass. |
TurnEnvelope could report matching action signatures while omitting the CLI settlement plan. A compact-view consumer consequently lost the original effect identity, conditional completion/closeout steps and host handoff; long normal settlement command previews could also lose their trailing binding or execute arguments.
Preserve the existing plan intact in
writeback.settlement_planand keep its next commands untruncated. Coverage v5 signs the added contract; historical plan-free packets retain their previous coverage. Default full quota output, admission, receipt ownership and execution rules stay unchanged. The differential recognizes the declared signature migration without a new size allowance.Validation: 216 focused Python tests and 19 TypeScript tests pass; an additional focused CLI settlement/selection run passes. The real isolated CLI test consumes the projected commands, rejects spend before writeback, then writes and spends the original Turn exactly once with idempotent replay. Negative cases mutate identity, order, conditions, receipt and host ownership or remove the plan. Ruff, diff check and semantic advisory/full inventory pass; the advisory does not detect scalar coverage-version constants.
Placement: existing TypeScript quota projection transports the shared settlement owner contract; Python only exposes its compatibility constant and delivery-time migration check. No new capability, authority or Python decision source. CLI JSON is the affected entrypoint; there is no new frontend/Lark operation. Related refactor pass retained the existing owner rather than adding another plan builder.
This is a bounded prerequisite for short-context delivery. The 8 KiB performance target and growth checks remain unchanged; source replay can still report oversize warnings. Same-Turn cached detail delivery, runner opt-in, controlled model validation and default-view promotion remain open in the existing RFC/Todo. No active benchmark process or installed runtime is changed.