fix(quota): reuse local Goal defaults and scope matching - #5676
Conversation
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh
Request changes conclusion (author-owned PR; GitHub blocks formal self-review)
Reviewed complete head: 5676@9eed030ceb7f12640541208d681f22aaf3d1db63; immutable merge base b88f98949c46ba7474485a3b0f75c9943698f0fc. Two P2 workspace/admission defects remain. This COMMENTED review is the canonical blocking conclusion for the shared author account.
动机
在本地非 Git 项目内核验资料并写报告的 agent,需要执行已获 Goal 授权的相对路径任务,而无需创建无关代码仓库。
旧版本把合法本地资料写入当成仓库编辑并阻断;本版本在正确项目内解除这个误阻断,但单 agent 或关闭独立 worktree 要求时,在项目外也会放行,并且正常拒绝路径给出错误的 worktree 恢复指令。
真实 File/SQLite 本地写回和单次结算通过;项目外的范围约束及可执行恢复指令仍需修复。
不扩大 Goal 写授权,不免除 claim/lease、因果工作区或单次记账,不资格化 App/Lark 采用或整个 Goal 完成。
改动思路
复用现有 Todo work-requirement TypeScript owner,把绝对 Goal grants 投影成相对 Todo scopes;Python 仅观察本地文件系统和调用 typed owner。明确非 code、无 task repository、same-agent continuation 及完整 scopes 才能进入本地路径。没有新增配置开关、持久授权、Python 决策副本或专用资料框架。
doing-nothing 会保留合法资料任务的 worktree/absolute-scope 误阻断;已有 scope 与 causal-workspace owner 足够承载有界修复,删除 scopes 或宽泛绕过 workspace gate 都不合适。目前投影观察的是注册根,实际 cwd 的约束却只放在 peer-isolation guard,形成漏口。
具体改动
8文件 +508/-10:约160行 owning code/bridge、336行聚焦验证及12行文档说明,无生成或机械搬迁代码。已审全 diff、quota/guard/projection/settlement 调用链及相关开放 PR;完整队列中只有本 PR 的 key files 涉及这些 owner。规格 docs/quota-allocation.md,revision b88f98949c46ba7474485a3b0f75c9943698f0fc。映射 local_goal 的注册根身份与项目外限制 not_met;independent_git_worktree 的明确代码/隔离策略保留 implemented;Post-turn accounting protocol 的 File/SQLite refresh→spend→replay 单次结算 implemented。既有文档是边界依据,新增 admission 说明不是自身正确性的证明。
关键代码讲解
projectGoalLocalWriteScopes(work_requirements.ts)验证相对 scopes、绝对 grant 根前缀、dot segments 与简单 recursive containment;已有 declarations 是 owner intent,admission 只是投影,不能再授予权限。observe_goal_local_write_scopes识别注册的 local_goal 物理根,再将 scopes 交给 TS;quota.should-run向 workspace guard 和 boundary repair 传同一结果。build_agent_workspace_guard的新增分支本应要求当前 cwd 仍属于该 local_goal;但workspace_guard.py:404–405在单 agent 时提前返回,而425–429在 explicit false时豁免了项目根检查。它们与后续 scope 投影的放行没有共享这一约束。build_boundary_projection_repair_hint合入投影的 relative scopes,从而对上述项目外路径撤去原 boundary hold。move_to_goal_workspace新 action 则仍被既有 generic repair 的 primary action、execution obligation 和 CLI步骤投影为创建独立 Git worktree。- settlement 仍通过既有 path-free local_goal snapshot、Todo/Turn 绑定和一次 debit owner;本 PR 没改该记账决策。
对主干的风险
[P2] 在应用根绑定 scope 投影前,始终核验实际工作区。 四组独立真实 CLI 合成 authorities 对照:正确项目内的两-agent任务在 base 被错误阻断,head正常准入;项目外的两-agent默认路径在head拒绝。但同一仅获 PROJECT/materials/** 的任务,注册一个 agent,或两 agent且 peer_independent_worktree_required=false,从 PROJECT 的父目录运行,base均 normal_delivery_allowed=false / boundary_projection_repair,head却 normal_delivery_allowed=true / normal_run,没有任何 workspace/boundary hold。关闭独立 worktree 的要求不授权把相对写任务改绑到另一个项目。最小修复是把当前 local_goal 身份检查置于 peer数量/独立worktree policy 之外,只对正确根提供该投影;项目外仍返回可执行的回根诊断。不要新增授权开关或改变代码任务规则。补单/多agent、explicit false、foreign cwd及返回正确根的真实 CLI 对照。
[P2] 新 local workspace action 没有贯穿必做恢复契约。 默认两-agent项目外路径虽正确拒绝,workspace_guard.required_workspace=local_goal_workspace / action=move_to_goal_workspace,其 interaction_contract.agent_channel.primary_action 却要求“create or switch to an independent worktree/branch”;同一 mode 的 execution obligation 和 CLI步骤也固定要求 Git worktree。这个 Goal 本来没有 Git,按照 packet 的必做路径仍无法恢复。最小修复是在已有 typed repair action/投影 owner 中让目标工作区贯穿这些消费者,保留真实 Git peer repair。验证完整packet明确要求回 Goal 根,并同 Turn 重跑进入本地 delivery,不仅断言 workspace_guard 的一项字段。
独立验证:新 admission 与现有 settlement 两模块共101项通过、1项失败;失败的 todoless-autonomous-replan fresh-Turn skip 断言在固定base同样失败,属未改的 replan边界,未当成本 PR新增缺陷。45项 TS通过、1项显式跳过;typecheck、Ruff、compile、diff、advisory与全树 semantic smoke通过。File/SQLite 正确根的 refresh→spend→idempotent replay 测试使用隔离真实 authorities;没有写活跃项目状态。premerge的5项direct通过,selected中peer-runtime aggregate受旧 migration heartbeat措辞断言阻断;已在固定base复现,报告原始失败,未改断言或抬阈值。canary ratchet 的既有3项 advisory仍披露,未声称全绿。CI未查询或等待。
语义与 CI 对齐
goal_local_write_scopes 扩展既有 effect-runtime operation closed set;move_to_goal_workspace 是新的 workspace repair action,未产生权限。typed scope owner已复用,但相邻 primary-action/obligation/CLI read model 没有采用新 action,是本次具体语义缺口。advisory空结果不证明无新增语义;full-tree smoke 的44个未证明producer仍保留。资料准入由机器执行,mandatory repair不是guidance。公开文档披露了原误阻断与新本地准入,没有把权限扩张当修复。
我的整体评价
REQUEST_CHANGES,delivery judgment: not_yet_proven。本地资料准入是合理而完整的有界目标,但 long_horizon 在项目外准入缺乏正确工作区绑定,user_experience 在普通拒绝路径给出无法执行的 Git恢复要求,均 regression。先修复根绑定与同一恢复action投影,再按新完整head复核;App/Lark adoption仍是明确未验收的消费者边界。
未来演进检查已应用:现有 TypeScript work owner及因果结算复用正确;最有价值的有界整理是让 local identity与scope projection共享一次真实观察,并让既有repair consumers读取同一action,避免添加平行权限/工作区框架。旧receipt和独立Git caller要保留,未要求无关语言重写或全产品交付。本评审不合并;控制面修改由维护者决定。
English verdict: REQUEST_CHANGES - 5676@9eed030ceb7f12640541208d681f22aaf3d1db63. Actual paired CLI reproduces introduced outside-root admission for single-agent and explicit-no-isolation Goals; the correctly denied peer path still mandates an unrelated Git worktree. Repair physical-root binding before relative scope admission and propagate the local recovery action through the full packet.101 Python and45 TS pass; one Python failure and the premerge migration hold reproduce at base, one TS case skips. No CI wait, App/Lark adoption or merge claim.
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
|
The revised delivery frame for this PR is to extend the existing registered local-Goal behavior from #3574 and #5614, rather than introduce another material-specific admission policy. Registered Goal-relative scopes keep the existing boundary matcher's relative and glob semantics; absolute grants under the registered project are another spelling of those target scopes. Caller cwd neither rebases the targets nor grants writes outside them. An accountable refresh from another cwd can name the actual registered delivery target with the existing Under this frame, requiring every local-task caller to relocate cwd would add an unnecessary restriction. The repair removes that proposed restriction and the extra local admission classifier, reuses the existing workspace identity and boundary guard, and validates broader default local work against |
…rkspace-repair Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
动机
结论:APPROVE,当前完整 PR 没有阻塞发现。评审 head 为 ababc82a487e4d6c7f339f8c4c61cf6865cdf3f2。
运行已注册本地项目任务的 CLI 用户和 peer worker 会遇到这个问题,尤其是已经声明输出路径的普通任务。
例如任务要在项目内生成 reports/result.md,Goal 已授权 reports/*.md 或对应的绝对路径;main 却可能要求本地 peer 建立 Git worktree,或因为绝对授权与相对任务路径不匹配而进入修复回合。新提交让这些已授权任务直接运行,随后仍在实际交付目标记账。
已验证的改善是:原先通过的相对 scope 单 worker 场景继续通过,绝对 scope 和本地 peer 的误拦截消失;从另一个 cwd 执行 refresh、spend 和重放也能完成一次交付、只扣一次额度。
本 PR 修复现有 CLI/backend 本地任务路径;不新增权限、lease、持久化 schema 或 CLI 参数,也不声称完成 App/Lark 新交互、默认安装替换或长期运行认证。
改动思路
这次沿用 #3574 / #5614 已有的本地交付身份,把它接回任务准入,默认通用化地解决问题。当前评审框架明确了调用 cwd 与实际交付目标的区别:cwd 既不授予权限,也不应要求本地任务额外建 Git worktree。之前评审要求绑定调用 cwd 的结论已被这个明确方向取代;实际目标的因果交付检查仍然保留。
独立规范基准是 docs/quota-allocation.md,固定在提交 23935d5057cb5624609ab83fae5e697162642c44(先读改动前的契约,修改后的文档不是自己的正确性证明):
required_write_scopes:正常交付前由既有 boundary guard 检查覆盖;不覆盖的任务仍进入 boundary repair。真实 CLI 反例验证同项目未授权目标、其他根授权和 scope 逃逸都拒绝,owner 修正授权后能完成产物与结算。local_goal:已注册非 Git 或 canonical originless 项目可以记录无路径的本地交付身份;真实 File/SQLite refresh→spend→重放验证一次扣费、身份持久化与后续回合复用。independent_git_worktree:Git peer、显式 task repository 和 owner isolation 仍遵循既有隔离规则;Git 事实检查与真实 CLI 反例覆盖,没有增加本地 fallback。--delivery-workspace-path:从另一调用目录 refresh 可以显式标明实际交付目标,路径本地验证后不写入历史;已有 CLI 参数和记账 owner 足够,无需新开关。
结构上,Python 仅观察实际文件系统/Git 与已注册根,现有 TypeScript owner 投影 scope 拼写,既有 write_scope_allowed 继续独占覆盖判断。没有增加 task domain、continuation marker、独立 admission 分类器或持久化状态。
具体改动
workspace_guard.py:350 observe_goal_local_workspace 在选定 Todo 后捕获已注册根的现有身份。没有 Todo、显式 task repository 或未证明为 local_goal 时继续走原有 guard。peer guard 先服从显式 owner policy,再对 local_goal 默认免除“有写入就必须 Git”的推断。
work_requirements.ts:13 projectGoalWriteScopes 只把已注册根下的绝对授权转为相对视图,保留原有相对路径和 glob。外部根不能按尾部相似路径匹配。settlement_workspace_causality.py/.ts 通过现有 effect bridge 调用这个类型化投影,没有第二套覆盖算法。
should_run.py:66 _apply_selected_todo_guards 复用一次 local observation,传给 workspace guard,并把投影与原授权一并交给原 boundary guard。没有扩大原 grants。interaction_contract.py:1298 _build_interaction_cli_channel 说明实际目标 refresh 和使用已记录身份的 spend;显式 Git 分支不变。
正向旅程是:本地 peer 选中已授权 Todo → 从其他 cwd 得到 normal_run → 在 Goal 目标写产物 → 用已有参数 refresh 实际目标 → spend → 同 Turn 重放仍只扣一次。负向旅程是:任务需要未授权后缀或其他目录 → boundary repair、零扣费 → owner 修正授权 → 产物、refresh 和 spend 成功。显式隔离或 task repository 则仍进入 workspace repair。
两份测试覆盖这些生产路径;文档补充默认行为,原要求调用目录搬迁的 hint 断言已改名并更新。未来改动的局部整理已应用:删除重复 admission/containment 分类、local_write_scopes 特殊参数和 cwd relocation action;复用既有身份、codec、matcher 与 receipt owner。最终 diff 是 9 文件、+368/-13,其中生产 +111/-10、测试 +244/-2、文档 +13/-1;没有生成 bundle、lock、日志或私有状态。
对主干的风险
最大反例是本地身份被误当作对其他目标或 Git 工作的授权。真实 CLI 验证目标覆盖、foreign-root、scope 逃逸、新 Todo、显式 policy/repository 及 owner 修正后的恢复,证明更宽松的默认仍受既有边界约束。注册根的 symlink 授权保持其明确拼写,Git 读取失败/空 origin/foreign repository 不会变成本地 fallback。
固定 main 对照提交 7d46d6414bcfe9aeb98f48ba1b00c072fc53841f 与规范基准之间,所触及 owner 路径没有改动。相同合成输入的 8 次真实 CLI 对照中,main 的两个既有放行情形保持放行,6 个本地误拦截在 head 放行;没有用更严格拒绝替代兼容性证据。新代码不改 Todo 选择、显示分页、claim/lease 或 receipt schema,不需要另一个人工同步的事实。
验证与限制:
- 当前 head 的本地/Git 事实/交互专项套件 32 passed,含 16 个 File/SQLite × 单/peer × 默认/显式关闭 × 绝对/相对 glob 的真实 CLI 交付、结算与重放。
- 8 个真实 CLI scope/隔离反例通过;拒绝时零扣费,授权修正后实际产物和一次结算完成。
- 新构建的非 editable wheel 校验 source hash 与 site-packages 来源,4 个 File/SQLite × scope 实际旅程通过;没有替换用户默认安装。较早 stale chat/wheel 的失败由重新构建、哈希和真实安装运行验证取代,没有把旧 wheel 当作通过证据。
- TypeScript checking 通过,相关 owner 测试 49 passed / 1 existing platform skip;语义 advisory/full-tree smoke、Ruff、diff/public boundary 与当前 head 的风险 premerge gate 通过(5 direct、19 selected,零阻塞失败)。其中全树 maintainability ratchet 有一项 inherited advisory:三个未改路径的既有体积 debt,固定 main 独立复现,changed-module ceiling 通过;没有修改预算来隐藏它。语义扫描的已有 producer/跨 runtime 分析边界仍存在,不把零 advisory 当作等价证明。
- 更广回归有 143 项通过,另一个旧 hint 精确文本断言因已披露的变化失败;更新后的四例模块及最新32例专项通过。独立的
test_todoless_autonomous_replan_settles_quota_refresh_spend_chain在固定 main 和当前 head 都于相同断言失败(期望 skip,实际 autonomous_replan_required);该 Todo-less replan 规则没有被本 PR 修改,相关修正由 #5691 独立处理。本 PR 没有改阈值或绕过相关规则,不能宣称全套无失败。
review policy 为 wait_for_ci=false,未查询或等待 CI;结论基于当前本地必需证据。无手工 delivery hold。没有承诺未验证的平台运行、App/Lark 新旅程或长期 soak;这些不是本次已有 CLI 默认修复的前置条件。
我的整体评价
这次已经闭合原动机:本地工作默认使用已经存在的本地身份,scope 沿用 main matcher,绝对与相对视图接通,调用 cwd 不增加 worktree 或搬迁要求。它同时删掉了早期提案的多余参数和独立分类,保留授权与因果记账的现有 owner。做 nothing 会留下可复现误拦截,只改其中一处会残留另一个 blocker,全面 bypass 则会丢授权边界;当前组合是可局部回滚的完整修复。
没有阻塞发现。剩余风险与未验证范围如上,回滚无需 receipt 数据迁移。按当前会话明确授权,在发布并读回本 exact-head 自评、closeout 和 merge-readiness 返回 ready 后自行合并。
English verdict: APPROVE - 5676@ababc82a487e4d6c7f339f8c4c61cf6865cdf3f2; default local Goal identity and baseline scope matching reused, false Git/scope repair gates removed, explicit authority and causal replay preserved. Exact-head real CLI, negative/recovery, candidate-wheel, typed-owner and risk validation passed; unchanged fresh-Turn baseline failure and one platform skip disclosed.
Registered local Goals could settle through the existing
local_goalidentity, but declaring write scopes still made peer tasks demand a Git worktree, and absolute Goal grants failed to match relative Todo targets. Reuse the identity from #3574/#5614 for local tasks by default, without requiring a task-domain or continuation marker. Preserve the existing scope matcher's relative/glob semantics and project rooted absolute grants into the same view. Caller cwd does not rebase the targets; refresh can name the actual delivery target with the existing--delivery-workspace-path.This removes the proposed local admission classifier, duplicate containment rules,
local_write_scopesboundary argument and cwd relocation action. Explicit task repositories and owner isolation keep their guards; grants, claim/lease, persisted workspace schemas and single-debit settlement stay with their existing owners. Python observes filesystem facts and bridges the TypeScript projection. The current review frame is recorded here.Validation: paired real CLI runs against immutable main show no stricter local admission; 21 focused local tests cover relative/absolute/glob scopes, single/peer and default/explicit-off policies, plus File/SQLite refresh→spend→replay. A non-editable candidate wheel passes four real File/SQLite journeys from another cwd with one debit each. TypeScript checking and 49 TS tests pass (one platform skip); semantic advisory/full-tree smoke, Ruff, diff/public-boundary checks and risk premerge pass (5 direct +19 selected). The broader regression run had 143 passes and one obsolete wording assertion; the disclosed hint change updates that test and its four-case module passes. One unrelated fresh-Turn replan expectation was deselected after the same failure reproduced on immutable main; no threshold or unrelated rule was changed. No CI polling under the configured review policy.
This qualifies the existing CLI/backend local-work path. App/Lark adoption and sustained operation remain outside this bounded change; no default installation was replaced.