Skip to content

fix(collaboration): preserve checked returns during peer progress - #5692

Open
loopx-agent wants to merge 4 commits into
mainfrom
codex/team-validation-readback-20261005
Open

loopx-agent wants to merge 4 commits into
mainfrom
codex/team-validation-readback-20261005

Conversation

@loopx-agent

@loopx-agent loopx-agent commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

A delegated return could publish output that changed after its checks. Stable checks could also be rejected when an unrelated peer advanced the shared Goal. This prevents a requester from reliably reading the current report while other workers progress.

Read declared outputs before and after the real configured checks and return only matching versions. The existing TypeScript validation plan now binds current task work and claim/lifecycle alongside its selected rules, pins and verified workspace, reusing the acceptance owner's work digest. Unrelated Todo commits and observation-only metadata updates no longer invalidate identical checks; changed work (including unknown future fields), claim/lifecycle, validators, pins or outputs still reject. Provider revision CAS for mutations is unchanged.

The existing Team evidence disclosure shows host check time and exact matching output versions through the same Chat/CLI reader. Older runtimes and mismatched records explicitly lack those observations. Failed reads clear the report and check records; restoring the original output and rechecking recovers them without executing another task. This adds no verifier identity, semantic verdict or configuration/authority switch.

User journey and evidence

Open Team execution → Evidence → Current validation basis, inspect the readable report, and recheck in place. Concurrent progress on another task requires no recovery or repeated input. Actual output loss clears evidence; restore and explicitly recheck on the same operation. First viewport, navigation and execution controls are unchanged.

These are public-safe packaged synthetic views. A separate production SQLite/HTTP/CLI fixture exercised a real canonical peer commit during checks, retained the current report, then withdrew and restored an actual output. Only the unrelated open task's note/actor/time changed; four fixture host invocation counters remained at one. No active Goal or paid/live model was used.

Validation and limits

  • The output race and first-return/recovery regressions failed before the repair and pass with it. Four real File/SQLite scoped-check cases reproduced rejection on an unrelated task commit before the continuity fix; the final validation suite passes all 24 cases, including current work/claim refusal, cross-repository pins and owner-rule enforcement.
  • 77 additional production delegation and Chat/CLI cases passed; 25 TS rules and control-plane typecheck passed. Intermediate fixture errors (unregistered test actor and attempted metadata update to a completed task) were rejected by native authority; corrected fixtures use the assigned actor and an open unrelated task.
  • Official bundle build/source verification and full packaged reader smoke passed: legacy/current/mismatched records, error/recheck, linked-source/downstream loss and restoration, pagination, desktop/390px, keyboard/reduced motion and no task/message execution.
  • Actual packaged SQLite/HTTP/CLI state and failure/recovery passed. Semantic advisory, full vocabulary smoke, diff and private-boundary scans passed. No generated bundle, raw evidence, local state, lockfile or private paths are included.

Snapshots cannot detect changed-then-restored bytes between observations or prove semantic completeness. Independent verifier identity/exact-version semantic acceptance, a real objection and two adopted live collaboration cycles remain open. This candidate is proposed, not installed; PostgreSQL, the full repository quality suite, native screen-reader/200% zoom/soak and signed updater recovery were not qualified here. CI and maintainer review must assess the current exact head; this runtime/product change is not self-merged.

Placement/future-facing pass: keep policy in the existing collaboration TS owner and reuse the Goal acceptance work classification; Python remains host IO. Extracting the existing bounded artifact reader removes duplicate authority from the long MCP adapter. The task-basis digest is internal plan data, not a persisted success or new public receipt. Update the existing Live Team Workspace L1 checkpoint without claiming its live acceptance closed.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
@loopx-agent loopx-agent changed the title fix(collaboration): return stable checked output versions fix(collaboration): preserve checked returns during peer progress Oct 5, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant