fix(steward): default owner discovery to the registered portfolio - #5683
Conversation
… root Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh
Request changes conclusion (author-owned PR; GitHub blocks formal self-review)
Exact head: 5683@aced6731526a1b53d50c6c18cc6bbae67e6dfa16; immutable base 4e820bb.
动机
连接本人私聊管家、希望管理已注册工作的用户。新管家原先只看创建后的任务,独立 Chat 目录还可能读另一套协作状态;本次让它发现当前和未来注册,但升级写入中断时仍会显示错误范围。
独立目录的真实原生 admission 能读取 150 个 Goal,再加入第 151 个后保持原会话;正常键盘升级和刷新通过,写入中断及旧调用兼容两项失败仍未修复。
不认证正式安装、手机、付费模型自主选择、接收方采用、worker 执行或完整 R3 结果返回。
改动思路
沿用已有 App/本人身份校验和 TypeScript 会话、来源权限 owner,Python 只观察注册表和落盘;协作目录取注册表的 common runtime root,Chat 会话与 App 存储仍留在各自目录。新管家使用全部已注册范围,旧配置没有范围字段时保留 selected,只有用户明确点击升级才扩大。发现、上下文投递、worker 执行和发布仍是分别授权的操作。
具体改动
规范依据为 docs/architecture/rfcs/app-conversation-and-async-inbox-v0.md 及明确修正的当前/未来注册发现要求。RFC-scope:implemented,已验证本人范围和旧绑定;RFC-R3:implemented,已验证独立目录及分页当前/未来发现;RFC-recovery:not_met,故障后范围读回不真实;RFC-full-loop:deferred,完整接收采用、执行与原会话返回由既有 R3 owner 继续,不用本次入口修复宣称闭环。
关键代码讲解
ChatConversationBindings.configure 保留旧绑定身份和范围,预检既有 channel,然后先写 binding、再逐个更新 policy;后者故障暴露下面的阻塞。resolveBoundConversation 只对 all_registered 读取当前注册表,150 个 Goal 和未来第151个可由同一 Session 发现。coordination_runtime_root 让 context/inbox/return 跟随注册表,实际 admission 在独立目录已验证。configureSourceScope 复用已有 selected/all_registered 规则并保留 blocked_targets。handle_manager_inbox 增加新 CLI 编辑操作,但开头直接访问新增可选属性破坏既有调用。
其余全 diff 包括 Settings 一键授权和范围计数、HTTP 请求/响应、源码范围校验、Effect-runtime 注册、英文/中文 RFC、三张合成截图、浏览器场景、registry IO manifest、TS/Python 回归以及 chat_runtime 两行初始化带来的2006→2008结构预算调整。没有增加另一套注册表、worker、调度器或权限来源。去掉128条选定范围上限是为了读取真实注册目录,仍用12条分页,而非一次投递300个Agent明细。结构预算仅覆盖现有构造器重用共同目录,不是扩大行为预算。未来重构检查:继续复用现有 typed owner;与入口修复集成后可以共用 exact-channel helper,无需另造通用事务框架。
对主干的风险
[P2] 保留旧 manager-inbox 调用兼容(manager_inbox.py:81)。 已有 test_delivery_read_decision_are_separate_and_restart_safe 传入原来的 Namespace,基线通过;此 head 在读取 local_delivery_scope 时抛 AttributeError,未到达原 read 分支。新增两个可选参数应有兼容默认值,并保留新 action 的参数约束。复跑上述现有测试即可确认修复。
[P2] 升级策略写入失败后出现持久范围漂移(conversation_bindings.py:93)。 对已有 selected binding/channel,在真实文件写边界注入一次 OSError:binding 已发布 all_registered,来源 policy 仍 selected;恢复写能力后下一次原生 admission 仍保留 selected。Settings 又只看 binding 隐藏升级按钮,让用户失去直接恢复入口。这不是要求跨文件事务:需要在已有 configure owner 内让显式升级可重试、收敛并真实读回,覆盖首个/中间 policy 以及 binding 写失败;普通消息不应顺手覆盖用户手工范围或撤权。
验证:相关 Python 182通过/1新增回归失败;22项 typed 测试、TypeScript typecheck、全树语义 smoke、打包构建和键盘升级/刷新/390宽屏浏览器场景通过。另跑真实 native admission,独立common root、150→151同一Session、撤权拒绝及重新显式授权后恢复通过,IO故障断言失败。普通项目私聊在base/head没有portfolio或policy副作用,模型输入规范化摘要一致。浏览器 API 和模型使用合成 fixture,实际 binding/TS/文件 backend 独立配对验证,未冒充手机或安装验收。premerge五项direct通过,19项selected有既有ratchet失败;base/head同样三项(goal_topic_runtime模块、quota和goal_boundary函数),零magnitude regression,和本次两个阻塞分开。没有查询或等待 CI。
语义与 CI 对齐
沿用并扩展现有 TypeScript scope vocabulary,Schema/manifest/文档同步;语义扫描仍有44个未证明producer站点,未声称全系统证明。当前明确违背的是范围发布后的真实读回与恢复契约,应修同一配置路径并保留负例,不用更改结构预算、权限或删失败断言处理。
我的整体评价
REQUEST_CHANGES。long_horizon=regression:升级中断后普通重试不能恢复承诺范围;user_experience=regression:界面显示已完成却隐藏必要升级操作。所选目录发现和配套Settings是有用且合理的同域改动,但当前受两个可复现阻塞影响,problem_context=not_yet_proven。完成最小兼容修复及显式升级恢复后,对新完整head重新评审;完整R3、正式安装和真实模型验收继续保持未验收。运行时/权限/控制面仍交维护者合并。
English verdict: REQUEST_CHANGES - aced673; fix the introduced legacy handler crash and recover scope publication after policy-write failure; actual common-root admission and packaged happy paths pass, but recovery readback remains inconsistent.
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
loopx-agent
left a comment
There was a problem hiding this comment.
动机
使用个人管家私聊的用户,需要在同一会话查看全部已注册工作,并在新增工作后继续使用,而不用重复输入已知的项目列表。
旧版本最多展示一部分注册工作,且私聊存储与协作存储分离时会找错收件箱;新版本按当前注册表分页发现全部工作,并把协作请求指向既有公共运行根。旧连接仍保持原范围,用户可以在设置里明确升级。
真实原生入口在同一会话发现 150→151 项工作;撤销后拒绝请求、重新明确授权后恢复。范围升级写入失败时,界面和绑定仍显示旧范围,键盘重试成功后读回新范围。
本 PR 不接管工作 agent,不扩大执行、发布、额度或外部账户权限,也不把打包界面与合成后端验证当作真实安装环境或完整产品验收。
完整的工作 agent 采用、执行及原私聊结果回传仍属于既有 R3/R5 交付检查点。
改动思路
固定验收来源 docs/architecture/rfcs/app-conversation-and-async-inbox-v0.md,不可变基线 7d46d6414bcfe9aeb98f48ba1b00c072fc53841f。RFC-scope / RFC-R3 / RFC-recovery 在本范围内已实现;RFC-full-loop 保留为既有 R3/R5 检查点,由 #5615/#5622/#5634 等对应交付继续证明。注册表是当前工作名单的唯一来源,范围字段表达用户明确意图,二者不能替代 sender、audience 和 recipient 授权。
具体改动
关键符号
ChatConversationBindings.configure(loopx/capabilities/native_chat/conversation_bindings.py:44):先校验候选绑定并预检/写入/回读 source policy,最后发布绑定。第一次、中途 policy 写入以及最终 binding 写入失败,均保留旧的可见范围;已授权的部分 policy 写入明确允许,重试收敛,没有声称跨文件原子事务。coordination_runtime_root(loopx/capabilities/native_chat/project_context.py:115):复用注册表公共协作根;Chat 会话及凭据存储仍归原 owner。configure_delivery_scope(loopx/capabilities/manager_context/__init__.py:408):复用已有类型化 source-grant effect;普通 admission 只补缺失 scope,保留独立手工限制与撤销。handle_manager_inbox(loopx/cli_commands/manager_inbox.py:79):旧 Namespace 未传新字段仍能读取;新 configure action 的参数边界保持验证。
语义与实际入口
新验证过的 steward 默认覆盖当前与未来已注册工作;旧连接缺 goal_scope 仍是 selected,升级由单个明确按钮提供缺失的同意。普通项目私聊不会创建隐藏 Goal 或协作 policy。不可变 base/head 的真实普通私聊输入 SHA256 均为 795e04252a5d07ad6e12e2d771bf8b686e7595b1b7bb451ef7a71afd6755e6b1,仅规范化临时根路径。当前 head 的独立 admission 探针验证同会话 150→151、分离存储、撤销拒绝与重新授权后恢复;现有测试也覆盖 301 个 agent 与分页、伪造 audience、独立 recipient block。
此前 review 5415210428 的两项 finding 已逐项重验:scope 写失败后的误发布已由真实首/中途 policy 与 binding 故障及重试覆盖;旧 manager-inbox Namespace 崩溃已由原入口测试覆盖。最终 head 172 Python + 3 独立原生探针、22 TS 通过;TS typecheck、规范 mypy 19 文件、Ruff、diff、语义 advisory/全树 smoke、Chat build 通过。packaged UI 的合成 API 场景验证 500 失败→保留旧范围与错误→键盘重试→清除错误→刷新读回,并实际检查 390px 窄屏。界面场景的 synthetic API 与原生 policy/state 验证分别注明,不推导真实外部账户采用。
作者合并 main 后的增量已经复核:main 的 Chat store/roundtrip 相关消费路径包含在上述 172 项测试;一行过时源码断言改为现有 localizedCapabilityFieldCopy(locale, localizedSelected.capability_id),源码契约 fixture 当前 3 tests passed。
对主干的风险
本次完整 diff 为 28 路径、+539/-38。未来相关重构检查已做:现有 typed owner、注册表派生和直接有序发布已足够,无需第二份名单、权限 owner 或事务框架;兼容旧 selected 范围与旧调用者具有实际消费者。仅对 chat_runtime 两行公共根初始化作同 diff 的 +2 ceiling 对照,没有放宽其他债务。
最终风险型 premerge 5 direct passed;19 selected,18 passed、1 failed。失败仍是 maintainability ratchet 的三项:goal_topic_runtime.py module metric、handle_quota_command 及 goal_boundary oversized function。同一不可变 base 用相同命令复现完全相同 identity/detail,相关路径字节不变、magnitude regression=0,改动不在它们的因果路径;变更自身的不变量有独立通过证据。判为 pre-existing unrelated,不改变本 PR 的批准结论,但保留独立合并 gate,未放宽限制。旧源码契约失败已被当前准确断言及通过结果取代。未读取或等待 GitHub CI。
我的整体评价
APPROVE — 5683@6ab378bfb9a742563eca4a93a8720ef8211f2eac。两项旧 finding 已解决;这是有实际可读回结果的范围/协作根增量,完整产品验收和继承的合并 hold 明确保留。
Reviewer: model_agent | model=gpt-6.1-sol | provider=OpenAI | reasoning_effort=xhigh | declaration_source=runtime_reported | observation=29d152fe416f37b0ce384b020f7d76935f4d426a7c3e5a1eb2c7579e98018b0a
Approval conclusion (author-owned PR; GitHub blocks formal self-approval): APPROVE.
English verdict: APPROVE on 5683@6ab378bfb9a742563eca4a93a8720ef8211f2eac. Both previous findings are resolved at the actual owning entrypoints. Current/future registry scope, canonical coordination roots, independent recipient revocation, legacy callers and recoverable explicit upgrades pass independent native and packaged checks. The unchanged maintainability ratchet failure remains a separate merge hold; full installed worker adoption and original-conversation return are not certified by this prerequisite.
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
loopx-agent
left a comment
There was a problem hiding this comment.
动机
使用个人管家私聊的用户,需要在同一会话查看全部已注册工作,并在新增工作后继续使用,而不用重复输入已知的项目列表。
旧版本最多展示一部分注册工作,且私聊存储与协作存储分离时会找错收件箱;新版本按当前注册表分页发现全部工作,并把协作请求指向既有公共运行根。旧连接仍保持原范围,用户可以在设置里明确升级。
真实原生入口在同一会话发现 150→151 项工作;撤销后拒绝请求、重新明确授权后恢复。范围升级写入失败时,界面和绑定仍显示旧范围,键盘重试成功后读回新范围。
本 PR 不接管工作 agent,不扩大执行、发布、额度或外部账户权限,也不把打包界面与合成后端验证当作真实安装环境或完整产品验收。
完整的工作 agent 采用、执行及原私聊结果回传仍属于既有 R3/R5 交付检查点。
改动思路
注册表仍是当前工作的唯一名单;用户明确授予的范围由既有类型化 binding/source-grant owner 决定。设置写入按预检、policy 写入与回读、最后 binding 发布的顺序,失败时保留旧可见范围,重试收敛。Chat 会话和凭据仍归原存储,协作请求使用注册表公共运行根。普通项目与旧 selected 连接保持各自边界;阅读范围、发送者身份和 recipient 权限分别校验。
具体改动
验收来源 docs/architecture/rfcs/app-conversation-and-async-inbox-v0.md,不可变 revision 23935d5057cb5624609ab83fae5e697162642c44。RFC-scope、RFC-R3、RFC-recovery 在本范围 implemented;RFC-full-loop deferred,保留现有 R3/R5 owner。不是用作者声明或测试数量替代验收。
关键代码讲解
ChatConversationBindings.configure(loopx/capabilities/native_chat/conversation_bindings.py:44):源 policy 完成读回后才发布 binding;故障下不谎报已升级。coordination_runtime_root(loopx/capabilities/native_chat/project_context.py:115):从当前 registry 解析公共协作根,不移动私聊身份或会话。configure_delivery_scope(loopx/capabilities/manager_context/__init__.py:413):复用类型化授权,普通 admission 仅补缺失配置,不覆盖已明确限制或撤销。ChatExternalConversations._record_steward_ingress(loopx/capabilities/native_chat/external_conversations.py:195,来自 main):enqueue 前登记确切 sender/source 与原消息摘要,replay 使用同一原始身份;分离运行根仍写到真实 owner。
本次 head 是合入 main 后的新版本。此前 28 个变更路径中 25 个 blob 相同;其余 manager-context、native external-conversation 和语义 manifest 的消费者已重新检查,不能机械继承旧批准。对当前 base 的 author delta 是 ingress 测试四行:验证过的 owner 默认有 registered recipient;后续显式 selected 空范围下,evidence-only 和 grant preview 仍无发送权限,执行授权才恢复,伪造内容、错误 origin、跨 App 和撤权仍拒绝。
当前 158 native Python(77 + 81)+ 3 独立 admission 探针、22 TS 通过。实际原生探针覆盖分离协作根、同会话 current→future 注册、撤权→重授权与写失败重试。不可变 base/head 普通私聊模型输入仅规范化临时路径,SHA256 都是 795e04252a5d07ad6e12e2d771bf8b686e7595b1b7bb451ef7a71afd6755e6b1,无隐藏 Goal 或 policy。当前 Chat 已重建,packaged scope 场景的合成 API 500、旧范围保留、键盘重试、刷新读回与窄屏交互通过;此界面验证与原生存储验证分别限定,没有认证真实外部账户。
对主干的风险
完整当前 diff 29 路径 +542/-39。之前两项 finding(失败升级误发布、旧 Namespace 调用崩溃)在当前原入口与 companion suite 重验;没有新的具体功能阻塞。未来相关重构检查:复用现有 scope 与 typed source-grant owner 已足够,当前增量不需要第二份名单、权限决策源或事务框架;保留旧 selected 调用者有实际兼容价值。
语义与 CI 对齐
复用既有 typed vocabulary;新 steward 默认 all_registered 的行为变化在双语 RFC 和明确升级 UI 披露,旧 binding 缺省仍 selected。精确 native audience regex 是 identity 边界,通配/部分 identity 被拒绝;不是靠子串推断权限。机器执行 grant/readback 校验,文案不称为可忽略 guidance。
当前风险型 premerge 5 direct passed;19 selected,18 passed、1 failed。仍是 goal_topic_runtime.py module metric、handle_quota_command 和 goal_boundary oversized function 三项 maintainability ratchet。相同命令在不可变 23935d5057cb5624609ab83fae5e697162642c44 复现相同 identity/detail,三条因果源码 blob 与 head 完全相同,magnitude regression=0,变更不在其因果路径,变更不变量另有通过证据。因此为 pre-existing unrelated,保留独立 merge hold,没有放宽预算。规范 mypy 19 文件、TS typecheck、advisory/全树语义、diff 与 Chat build 通过。未查询或等待 GitHub CI。
我的整体评价
APPROVE — 5683@273ded8ac079b40b7cd13af663e166d348911f8d。这个范围/协作根增量改善长期注册工作的可发现性与用户重试恢复,原先两项缺陷已解决,当前 main 组合的入口也有独立证据。完整 installed worker adoption、原消息回传及 R3/R5 产品验收仍需各自 owner 证明,继承的 merge hold 保留。
Reviewer: model_agent | model=gpt-6.1-sol | provider=OpenAI | reasoning_effort=xhigh | declaration_source=runtime_reported | observation=e7199a54b34ba89687f50e7622b74d9d0d961890c8a9f3bcfe6c22852beaaefa
Approval conclusion (author-owned PR; GitHub blocks formal self-approval): APPROVE.
English verdict: APPROVE on 5683@273ded8ac079b40b7cd13af663e166d348911f8d. The current-main native ingress producer, registered scope, explicit recipient denial/revocation, interruption replay and packaged failure/retry pass independent checks. Prior evidence was reused only after blob/caller invalidation. The unchanged maintainability failure remains a separate merge hold; installed adoption and the complete original-conversation worker return are not certified.
A verified personal steward kept a creation-only Goal list, and a separate Chat storage root could route coordination to another inbox. This change uses the configured registry and its declared common runtime root for discovery and source policy. New verified steward bindings include current and future registrations; existing bindings retain their scope until the owner upgrades them in Settings → Lark.
The upgrade retains the binding, Session, audience and individual recipient revocations. It now applies and verifies known sender-bound source policies before publishing the broader binding. A failed write leaves the old advertised scope and a usable retry; explicit retry converges any earlier authorized source writes. Ordinary admission preserves manually narrowed policies. This is ordered recovery, not a cross-file transaction. Legacy manager-inbox callers without the newly optional fields also retain their existing behavior.
Ordinary project assistants retain their workspace grant and create no hidden Goal. Existing typed binding/source-policy owners carry authority; Python remains the store/provider bridge. Native private ingress and actual worker activation/return remain separate integration work (#5615/#5634). Discovery grants neither execution nor publishing authority.
Validation at 273ded8, after normally merging main 23935d5 without rewriting branch history:
The current full head is undergoing a bounded re-review of the main composition and corrected fixture; the previous full-head approval is not being inherited. This delivery Goal uses the supported local-evidence merge policy, while retaining exact-head approval/closeout and native merge-readiness checks. Remote CI is not consulted under that policy; the disclosed inherited maintainability failure is not relabeled as passing. Not qualified: formal installation, mobile acceptance, autonomous model routing, worker task adoption/execution or full original-route return. This PR fixes scope discovery and explicit configuration recovery through existing owners, without adding another registry, scheduler or runner.