Skip to content

feat(zcode): add host diagnostics and managed native Goal control - #5752

Open
jackie-cqz wants to merge 38 commits into
loopx-project:mainfrom
jackie-cqz:feat/zcode-host-diagnostics
Open

jackie-cqz wants to merge 38 commits into
loopx-project:mainfrom
jackie-cqz:feat/zcode-host-diagnostics

Conversation

@jackie-cqz

@jackie-cqz jackie-cqz commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Goal And Delivered Outcome

ZCode previously entered through the LoopX Skill facade without machine-backed native Goal control. This adds an explicit managed CLI session bound to an existing LoopX Goal and registered Agent, with model selection, start/pause/resume/stop, status readback and Core quota admission/revocation.

  • Outcome basis: the bounded host integration request; main is the intended base. No issue or RFC milestone is closed.
  • Before → after: the existing Goal detail drawer and CLI can operate and read back one owned native session. Quota withdrawal pauses that target and denies resume until admission returns and the caller explicitly resumes.
  • The drawer consumes the binding owner's host eligibility: explicit other-host Agents are excluded, mixed Goals select a compatible Agent, and undeclared advisory hosts retain explicit binding compatibility. Closed controls make no native status probes; removal discards pending receipts.
  • Separate diagnostics observe CLI, Desktop/bundled CLI and source checkout versions/help, and installer-owned Skill delivery. They do not execute models or certify authentication.

Author Declaration

  • Written by: model_agent — OpenAI Codex (GPT-6 family), under human operator direction.
  • Implemented against the request and scope above, the operating guide in loopx/zcode_goal_mode/README.md, existing Goal/registered actor/quota contracts, docs/development/frontend-delivery.md, docs/development/design.md and S4/S5/S7/S8/S12 in the overall roadmap.
  • Current main (4d254fb6f) is included. The provider's TypeScript runtime owns native lifecycle; Python adapts existing canonical authority, and the frontend consumes its readback. No parallel quota or Goal decision owner is added.
Criterion Disposition Owning boundary Decisive evidence
Existing Goal and registered actor, no implicit registration implemented bridge.py, existing registry and routing owners Exact-instance/creation-witness, replacement, registration and foreign-host refusal before native effects
Explicit same-session lifecycle and recovery implemented runtime.ts, app-server.ts, guard.ts Native persistence, lost-start receipt, CAS, permission and owned-process cases; isolated real CLI cold recovery
Core quota admission/revocation implemented cli.ts, runtime.ts Actual synthetic Core withdrawal → pause → denied resume → restored admission → explicit same-target resume → stop
CLI and packaged frontend operation/readback implemented existing Goal drawer, provider API/CLI Host filtering, unavailable recovery, model/quotas, stale Agent and removed-Agent responses; actual Chat HTTP and owning binding parity
Host diagnostics and safe Skill repair implemented diagnostics.py, doctor/installer owners Isolated bounded probes, ownership/conflict and mixed-installation repair precedence

Scope And Continuation

Managed CLI scope only; the existing ZCode Skill facade remains available and native execution remains explicit opt-in. Desktop conversation attachment, MCP/Hooks/plugins, Automations, live provider billing, per-model-call hard budgets and fleet efficiency remain outside this slice. Native usage is unknown; native completion does not settle a LoopX Goal or debit credits. Exact instance identifiers and existing creation witnesses are fenced; legacy aliases without either cannot distinguish identical deletion/recreation.

The bounded CI repairs retain real authority: obsolete parser fixtures use the CLI parser, installed acceptance explicitly selects its temporary pre-promotion File source, routed command oracles retain complete registry/runtime targets, and owned POSIX cleanup confirms descendant shutdown. Current main confines preference instructions to the capability-owned participating hook; untouched runtimes and other Goal/Agent scopes remain silent, and the generic Skill does not carry a preference recipe. The presentation ceilings already qualified at 77dde0d4a, execution quota, per-Todo/fixed growth and duplication checks are unchanged. The existing 8 KiB envelope performance diagnostic and warning boundary remains unchanged; passing presentation checks is not a performance-SLO declaration.

The future-facing pass moves provider-only frontend validation/requests out of generic Chat data, preserving one provider vocabulary and the existing request transport. The source observation seam reuses existing bounded/cached canonical reads; eligibility adds zero source reads or native probes. Broader host composition is deferred until a real caller needs it.

Validation

Latest synchronized source: 27c179606f7370dbd8369dd5d63bc986dc441b99, including main at 4d254fb6f. Published head: 27c179606f7370dbd8369dd5d63bc986dc441b99. New exact-head CI and independent review remain required. Qualification uses disposable synthetic fixtures; no paid provider or native Goal was started during these main-sync repairs.

Check Result and practical limit
Current participating preference and Skill owners 79 tests passed across both complete Python files on Linux, without skips. Real legacy/File/SQLite journeys preserve inactive and cross-scope silence, explicit-use participation, current corrections/retirements, one owner snapshot, fresh external-action instructions and unchanged work authority. Both journal and namespace permission denial/recovery ran as a non-root user. This source-checkout run used Python 3.12.3, Node 24.21.0, Git/origin metadata and declared dependencies; it is not installed-wheel proof.
Current typed owners 47 preference/interaction/frontier/summary tests passed without skips, including scoped hook guidance, full-source identity before display caps and rejection of inconsistent batched facts.
Current Windows boundaries 76 ZCode and registry-census tests passed.
Current budget/probe/differential All 151 tests passed independently on Linux and Windows. The enforced 96-row Linux matrix and original regression smoke against true 4d254fb6f main passed. No overlay or ceiling edits were needed: the ceilings already qualified at 77dde0d4a remain intact. These results qualify presentation, consumer clauses, complete routes, growth and duplication contracts; they do not measure fleet efficiency or close the unchanged 8 KiB performance target.
Static Current changed-diff semantic advisory found no supported new carriers. Full-tree semantic smoke, full CI Ruff inputs plus changed provider/installer files, control-plane typecheck and Linux-target kernel mypy (19 files) passed on the current source. Frontend typecheck/build and packaged acceptance remain earlier qualification; the frontend assets and native provider sources are unchanged since f04c5a46d.

At 80368be6, six complete Python owner files passed 147 cases and a separate changed canonical read-adoption run passed 28 cases, both without skips. The preference/Skill portions are superseded by the current 79-case run. The earlier qualification retains its unchanged delete/update fencing, summary/frontier, succession, registry/cutover, claim/lease lifecycle, causal/bound-turn recovery, archived dependency, routing and exact-detail --thin rejection scope; it is not relabeled as a fresh 27c179606 run.

Prior feature qualification remains separate: 39 native provider TypeScript tests and 267 Linux host/status/API/registry tests passed, including actual Chat HTTP and binding-owner parity. The packaged frontend passed all 49 personal-workspace scenes on Linux, including real temporary HTTP feedback recovery, team proposal/recovery, acceptance retry, upgrade and asset provenance; the final ZCode scene also passed on Windows. These earlier feature runs are not new 27c179606 runs.

Earlier installed Linux wheel acceptance passed all five stages. A source-matched wheel with real ZCode CLI 0.16.9 completed bind → stop → immediate disconnected status → cold bind of the same session without starting a native Goal or calling a model. An earlier capped local synthetic model exercised actual Core quota withdrawal, paused/denied resume, restored admission, explicit same-target resume and stop (2 of 5 permitted calls, no paid provider). At f04c5a46d, 343 tests passed in the PostgreSQL-backed store/service qualification suites, including service unit tests; that is prior owning-scope evidence, not a new 27c179606 PostgreSQL rerun. None of these results certifies live billing or fleet performance.

Failed runs stay failed. Old-head CI exposed stale fixtures and process/budget defects. Interim 80368be6 exceeded old presentation caps in 10 Linux / 18 Windows rows; its Windows test run returned 7 failed / 144 passed. An interim Windows true-main comparison passed its 96 rows but failed temporary cleanup. Those runs are separate from the current passing 27c179606 qualification. Earlier Windows broader host tests had 12 POSIX shell/path failures; the main model-behavior helper had 16 Windows synthetic bound-path privacy failures while all 175 cases passed on Linux. Privacy checks were not relaxed. Earlier Windows writer/census qualification returned 18 passed, one POSIX interleaving skip and two pipe-select failures; all 14 writer cases passed on Linux. The prior archive-checkout run returned 257 passed / one failure; after restoring snapshot Git/origin metadata, that case and its 10-case workspace subset passed separately, not as a single 258-pass run. Environment setup failures are excluded from pass claims. Earlier envelope-overflow observations are not current-head measurements; the 8 KiB diagnostic boundary remains unchanged.

Frontend / Visual Evidence

  • UI impact: secondary control disclosure in the existing Goal detail drawer; existing opening navigation is retained.
  • Before: N/A for the new native control surface.
  • States: desktop quota-held pause with start/resume disabled and stop available; mobile native error/disconnection with unknown observations. Updated packaged acceptance also covers absent controls for foreign hosts and Agent removal/reappearance.
  • Attention review: operation and readback remain in the Goal context; native/model details are collapsed. Synthetic illustrations below demonstrate UI states, not billing or live execution receipts.

Synthetic desktop quota-held controls

Synthetic mobile native execution error

Type of Change

  • New feature and focused bug fixes
  • Public documentation and focused validation

LoopX Area

  • Host/runtime integration and existing Goal/quota authority
  • Frontend, CLI/API, doctor, installer and packaging

Boundary Checklist

  • Public/private scan excludes credentials, local paths, private state and raw logs from code, fixtures, body and images.
  • No new benchmark jobs, duplicated maintainer work, implicit authority or execution admission.
  • Intentional vocabulary reuse and provider placement reviewed; no new generic capability or parallel state owner.
  • DCO sign-off on branch commits; control-plane change left for maintainer review/merge.

Separate CLI, Desktop, bundled agent and source metadata. Use isolated bounded help/version probes and report observed interfaces without claiming native execution readiness.

Read the installer-owned ZCode facade set from its own skills root. Reuse one renderer, preserve custom CLI invocations and installation repair precedence, and leave other host diagnostics unchanged.

Signed-off-by: jackie-cqz <2557911191@qq.com>
Cover host identity, independent versions, relative paths, probe deadlines and output limits, facade conflicts and freshness, and Windows source-entry fixtures.

Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
…ostics

Signed-off-by: jackie-cqz <2557911191@qq.com>
Bind an explicitly selected CLI session to existing Goal and registered Agent authority. Add model selection, native lifecycle operations, durable recovery, quota admission and revocation, and owned process cleanup through the CLI and Goal drawer.

Keep the Skill facade as default. Native completion and unknown usage do not settle Core Goals or debit credits; Desktop attachment remains a separate stage.

Signed-off-by: jackie-cqz <2557911191@qq.com>
Cover stale identity fences, quota denial and revocation, protocol and permission failures, lost receipts, durable empty-session binding and process ownership. Exercise the packaged Goal controls and contract-aware frontend freshness.

Signed-off-by: jackie-cqz <2557911191@qq.com>
Document CLI and frontend activation, model selection, quota coordination, stop and recovery, legacy identity limits, and the bounded roadmap checkpoint.

Signed-off-by: jackie-cqz <2557911191@qq.com>
…ostics

Signed-off-by: jackie-cqz <2557911191@qq.com>

# Conflicts:
#	loopx/chat_server.py
Keep legacy Skill activation available without advertising native operations for unregistered actors. Prove ordinary Chat project context cannot be injected into Goal control requests. Refresh registry I/O source locations after synchronizing main.

Signed-off-by: jackie-cqz <2557911191@qq.com>
Add public synthetic desktop and mobile illustrations to the managed provider guide and include them in the package. The figures illustrate UI states and do not claim live execution or billing evidence.

Signed-off-by: jackie-cqz <2557911191@qq.com>

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh

Reviewed exact head: dc32655a7c81026157dc565b4c7ce38b07f6e82f; immutable base 42e55a809eb94f13443d303d76118735d4112182. 完整范围:45 个文件、+4405/-61,包含 provider、诊断/安装、CLI/HTTP、打包与界面、验证和文档。

动机

在已有 LoopX Goal 下使用 ZCode 的人,需要能明确绑定一个受托管的 CLI 会话,再启动、暂停、恢复、停止并核对它的状态。之前只有 skill 入口,用户无法从 Goal 详情控制这个独立会话;发生暂停或连接丢失后,也缺少一致的读回路径。本 PR 提议保留 skill 默认入口,增加显式绑定和同一目标的控制,让界面读回与 CLI 使用同一 provider。已验证的改善是打包界面可以完成模型选择与控制/异常恢复,协议层拒绝旧身份和越界响应;发现的缺陷是安装版本不匹配同时缺失 skill 时,恢复指引只修 skill,丢失真正的版本修复。原生模型调用费用、逐次调用硬预算、Desktop 附着和多 Agent 长程效益均未因此成立。真实已安装 ZCode 的恢复与长程净效率仍待独立核验,混合安装故障的恢复分支需要修复。

改动思路

spec_ref: docs/architecture/rfcs/loopx-overall-roadmap-v0.md; spec_revision: 42e55a809eb94f13443d303d76118735d4112182,按修改前的 S4、S5、S7、S8、S12 要求评估,有效 provider 是有界增量,不能用 PR 新写的 checkpoint 给自己认证。

S4:现有 Goal/注册 Agent、实例/创建凭据校验;独立 native session/target、串行操作、失去 broker 时终止自有进程树,unit/子进程负例通过,但本审查尚未独立复现作者所述真实已安装 ZCode 的恢复证据。S5:CLI 与 Goal 详情抽屉共用读回;打包浏览器覆盖绑定、模型/推理级别、quota 拒绝、旧 Goal 凭据、错误回执恢复和 Agent 切换,所替代的是 HTTP/provider fixture,不能证明真实提供方行为。S7:启动/恢复复用 Core quota;撤销后暂停、不把 native completion 当 LoopX 验收/扣费,未知 token 保持未知;逐调用预算/fleet 成本仍是剩余边界。S8:明确 opt-in、版本/权限、停止/卸载/恢复,provider 不增加一个平行 Core 决策 owner;真实入口/隔离证据仍须与声明对齐。S12:构建、打包来源与正常 skill 行为已核对,恢复顺序的混合失败反例未满足。

具体改动

Python zcode_goal_operation 校验权威身份,生成当前 heartbeat 任务并经同一解释器桥接 TypeScript;NativeGoalController 管理不可推导的绑定意图、目标、丢失开始回执和恢复,不重新定义 Core quota。ZCodeAppServer 对接 NDJSON 协议,验证 session/target/revision,拒绝交互权限,暂停后确认停止;guardian 把失去 broker 的取消传到自有进程树。ZCodeGoalControl 的操作集合由 provider 读回,修改 CLI 路径不隐藏暂停/停止,旧身份或未知操作结果要求先读回再操作。doctor 分开观察 CLI、Desktop、源码版本,仅 version/help;skill 检查复用 installer 的渲染,保护用户文件;构建指纹包含共享 provider 契约。

正向路径:打开 Goal 详情→已有注册 Agent→绑定 CLI(不启动模型)→必要时选已有模型/推理级别→显式启动→暂停/恢复同一目标→停止并读回断开。每个必需步骤提供身份、定位、模型选择或效果授权;无需另建 Goal/Agent。负向路径:同名 Goal 的创建凭据改变,旧面板 POST 被拒绝,零模型启动,刷新后才能继续;quota 撤销保持目标并暂停,不能仅凭 paused 绕过当前准入。

对主干的风险

阻断发现 [P2]:混合安装失败时丢失版本修复指引。 loopx/doctor.py:885–891 仅凭 repair_recommended 与坏 skill 覆盖 upgrade_command,1252–1257 又以 facade_problem 覆盖 fix。触发:release manifest 版本与运行包不一致(manifest_package_version_matches_runtime=false),同时 ZCode facades 缺失/过期。用相同合成事实在基线与 head 调用生产 collect_doctor(agent_type="zcode"):基线保留 install/upgrade 指引;head 仍报告 requires_upgrade=true,却只返回 slash-commands --install --surface zcode。该命令只修文本,不能修复包/manifest 不匹配,用户会多跑一轮甚至重复停在同一错误。最小修复:只有已确认“仅 skill 不新鲜”时使用 skill-only 修复;包/版本/运行时故障保留其 owner 的安装恢复,再追加 skill 修复。不要依赖总 status 或某个先出现的 reason 判断唯一原因。回归:在现有 test_zcode_doctor_skill_delivery.py 增加“版本不匹配 × 缺失/过期 facade”的组合,验证完整恢复和修复后读回。该反例无需模型/网络调用;基础设施用合成替身,生产诊断/恢复决策未替换。

另外,新增 test_probe_uses_disposable_storage_and_preserves_parent_environment 在 macOS 的 /var→/private/var 别名下失败。真实目录隔离并未因此失效;应规范化两侧路径/比较目录身份并保留原有隔离、环境不被修改、临时目录清理断言,勿直接删测试或放宽为任意目录。

本地验证:39 项 TS 协议/控制/guardian 测试通过;Python 新功能与 bundle 检查为 126 passed / 1 failed(上述路径断言);182 项既有 doctor/activation/installer 测试通过;TS 类型检查、chat 构建/校验、打包 zcode-goal 浏览器场景、全树语义 smoke 通过;独立混合恢复反例失败并在同一 base/head 比较定位到新覆盖分支。7 份默认 ZCode skill 内容在 base/head 字节相同,Codex activation 完全相同;ZCode activation 仅新增可用 provider 信息和明确默认仍是 skill 的说明,没有因此启动执行。新增词表属于 provider 状态/本地诊断,Core 资格/结算 owner 未替换。无 CI 拉取或等待。未独立完成真实已安装 ZCode 的完整恢复、live billing 或多 Goal 并发测量;作者声明不代替这些证据。

我的整体评价

REQUEST_CHANGES。交互和隔离方向有正向价值,但“可控且可恢复”需要同时覆盖普通路径和安装组合故障,当前遗漏会给后续升级/重试增加成本。长程净效率还不能判为已改善:每个活跃托管会话约每 2 秒启动权威/quota 子进程,一小时截止,缺少规模成本和真实有效产出测量。保留这个明确有界的 provider,先修具体恢复分支和 macOS 验证;无需顺便承诺 per-call 预算、Desktop 或 fleet。最近相关复用已检查:Core quota/身份保持原 owner,provider transport/state 需要自己的宿主边界;更小的纯 skill 文档改动无法交付这些控制。未来整理宜继续聚焦同一恢复 owner,避免另增一套“诊断成功”判断或新配置协议。修复后重新在变更 head 核验,不从此次 passing 项推导上层验收或合并授权。

English verdict: REQUEST_CHANGES — exact head dc32655; mixed package-version/skill failures replace required installation recovery with skill-only guidance. Protocol, packaged UI and legacy checks passed; one new macOS path assertion failed and real installed-host recovery/net-efficiency remain unverified.

@mergify

mergify Bot commented Oct 6, 2026

Copy link
Copy Markdown

This pull request has merge conflicts with main and cannot be merged
until they are resolved. Please rebase or merge the base branch, @jackie-cqz.

Choose the remote for the base repository, not an out-of-date fork.
For a fork clone, first inspect git remote -v; upstream must point
to https://github.com/loopx-project/loopx.git. If it is absent, add it
with git remote add upstream https://github.com/loopx-project/loopx.git.
Then run:

git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEAD

For a same-repository clone whose origin points to
https://github.com/loopx-project/loopx.git, use origin instead of
upstream for fetch/rebase. If you prefer merging the base, use
git merge <base-remote>/main and push normally.

Keep the DCO Signed-off-by trailer on every commit when you rebase.
https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/syncing-a-fork

@mergify mergify Bot added the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 6, 2026
…ostics

Signed-off-by: jackie-cqz <2557911191@qq.com>

# Conflicts:
#	apps/presentation/dashboard/src/data/chat.ts
#	loopx/semantics/project_registry_io_manifest_v1.json
Reuse the installation freshness owner without Skill admission to retain required package/runtime repair before ZCode facade repair. Cover mixed missing/stale Skill faults through real installer repair and complete readback, canonicalize macOS temporary paths, and qualify the added bridge tests with CI lint.

Signed-off-by: jackie-cqz <2557911191@qq.com>
Replace the two provider matcher copies with the existing content digest owner and register the actual consumers. Use fileURLToPath in the unchanged static ownership check so Windows runs all original assertions, with no exceptions or relaxed matching.

Signed-off-by: jackie-cqz <2557911191@qq.com>
Bind the HTTP acceptance fixture to its disposable runtime root and count persisted Turns by the existing schema owner instead of incidental JSON filenames. Retain exactly-one acceptance and dispatch assertions, and remove the unused import left by the upstream Todo module split.

Signed-off-by: jackie-cqz <2557911191@qq.com>
@jackie-cqz

Copy link
Copy Markdown
Contributor Author

修复已推送到 9588ccc345c4444427fe6acb1341d923771d81db,已同步真实上游 main(da45cfe771e96d20b9c5129a021a8c971ee03324),合并冲突已消除。

  • Review P2:混合安装/Skill 故障。 复用同一 build_install_freshness owner,以相同事实和时间另做 installation-only projection;仅在确认无其他安装故障时使用 Skill-only 修复。包版本不匹配/旧快照与缺失/过期 facade 共 4 组回归,保留安装恢复命令,再追加 Skill 修复;实际修复 Skill 后仍要求安装恢复,两者修好后重新读回正常。非 ZCode 分支保持原 owner。
  • macOS 路径反例。 规范化 cwd 与 storage 的路径后比较,保留环境不被修改、临时目录隔离和清理断言;macOS CI 仍待本轮运行。
  • 真实 CI 阻塞。 修正 6 处新增测试 lint 错误;两处 ZCode 64hex matcher 改用现有 BARE_SHA256_PATTERN,注册真实消费者。静态 owner 测试改用 fileURLToPath,全部 17 个原断言通过,未添加 exception 或放宽检查。另清理上游拆分遗留的 unused import,并修复 HTTP acceptance fixture 的临时 runtime 绑定和 typed Turn 计数,保留 exactly-one retry/dispatch 断言。
  • 原 CI 的其他失败。 已吸收上游 Todo、status redaction、Windows locator 和 team-evidence-return 修复;原失败的可本地运行用例与团队证据打包流程通过。Linux pipe barrier 与 Windows/POSIX 差异保留为未通过/待 CI 的证据,未用它们宣称全绿。

本轮验证:Python focused 55 + 75 + 82 项通过;ZCode TS 39、digest owner 17 项通过;完整类型检查、lint、Linux 目标 kernel mypy、semantic smoke、打包来源检查通过。浏览器 49 个场景中 48 通过(含 ZCode);1 个主干原样的 Windows 子进程 cleanup 断言失败。新 wheel 中 1,643 个 LoopX 文件与源码一致;真实已安装 CLI bind → stop → immediate status → cold bind 恢复同一 session,0 次模型调用。

PR 描述已将新 head 验证、旧 head quota/本地模型证据、平台失败和未测范围分开。仍然只交付有界 managed CLI provider;不新增 per-call hard budget、Desktop attachment、live billing 或 fleet/net-efficiency 完成声明。本轮 GitHub CI 已排队/运行,尚未确认全绿,请在此精确 head 重新 review;这不是合并批准。

Known review findings addressed; pending exact-head re-review and GitHub CI.

@mergify mergify Bot removed the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 7, 2026
loopx-agent
loopx-agent previously approved these changes Oct 7, 2026

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh

Reviewed exact head: 9588ccc345c4444427fe6acb1341d923771d81db; immutable base da45cfe771e96d20b9c5129a021a8c971ee03324. Whole PR: 48 files, +4512/-71. This is a fresh full-scope re-review, not a reuse of the old approval state.

动机

在已有 LoopX Goal 下使用 ZCode 的人,需要明确绑定一个受托管的 CLI 会话,再启动、暂停、恢复、停止并核对状态。 之前只有 skill 入口,用户无法从 Goal 详情控制这个独立会话;连接丢失后,也缺少保留同一会话的读回与恢复路径。 现在增加显式控制:打包界面通过模型选择与异常恢复检查,真实 CLI 和生产 HTTP 入口都在停止后恢复同一个空闲会话,旧 Goal 凭据与外部网页请求被拒绝。 这次验证没有运行付费模型;逐调用硬预算、Desktop 附着、live billing 和多 Agent 长程净收益仍未成立。 活跃模型的真实取消/恢复、规模化监测成本与持续有效产出仍待限定场景实测;当前交付是可停止、可冷恢复的单会话可选 provider。

改动思路

spec_ref: docs/architecture/rfcs/loopx-overall-roadmap-v0.md; spec_revision: da45cfe771e96d20b9c5129a021a8c971ee03324。用修改前 S4/S5/S7/S8/S12 的宿主监督、共享投影、准入/消耗区分、provider 生命周期与安装恢复来判断有界增量,不用 PR 自己新增的 checkpoint 认证自己。

Core 身份与 quota 保留唯一 owner,TypeScript 管理宿主状态/效果,Python 只桥接现有权威;同一会话的真实冷恢复证明了这层 provider 边界有用,纯 skill 文档无法交付这些控制。 当前 PR 保留一个明确 opt-in、可停止的单会话 provider 和既有 Goal 抽屉入口;不新增通用能力、默认执行或账户配置,活跃模型与 fleet 成本继续由现有 S4/S7/S8 验收持有。

最强反对理由是约 4.5k 行引入 broker、journal、guardian 与轮询成本,若只是给 skill 加说明会过大。但纯文档无法控制 native session,取消、恢复和旧身份拒绝必须跨真实 provider。这里复用 Core,新增状态只保存不能从注册关系推导的 session/target/已授权启动意图;没有额外通用配置框架。S4 中真实运行模型的取消/恢复,以及 S7/S8 的 live 成本和规模验收仍未完成,不能从空闲会话恢复推导它们。

具体改动

CLI/生产 HTTP 都经 Python bridge 读取现有 Goal、已注册 Agent、实例或创建凭据,然后进入同一 TypeScript controller。controller 串行管理模型选择、明确启动、暂停、停止和 durable intent;app-server 校验 session/target/revision,拒绝交互权限;guardian 在 broker 丢失时关掉自有进程树。Goal 抽屉共用契约和可用动作,未知结果先清空旧 snapshot,重新读回后再操作;不同 Agent 的迟到读回不污染当前选择。doctor 分开观察 CLI/Desktop/源码版本,用 installer 渲染判断 skill,不把版本/help 成功当完整运行资格。

相关 refactor 已在现有 owner 内完成:复用 canonical digest 正则,使用 fileURLToPath 保留跨平台路径身份,移除一个未使用导入;HTTP acceptance fixture 用 typed Turn schema 计数并指向自己的临时 runtime,未改变产品 Turn 规则。没有必要增加另一套状态分类或 freshness owner。

正向体验:打开已有 Goal→选已注册 Agent→绑定实际 CLI(不运行模型)→需要时选择已有模型/推理级别→明确启动→读回/暂停/恢复/停止。Agent 提供作用对象、CLI 路径提供宿主选择、启动提供效果授权,刷新为旧或未知结果提供当前权威;这些步骤没有重复创建 Goal/Agent。现有默认模型保留,模型修改是可选操作。

负向及恢复:生产 HTTP 的外部 Origin 返回 403,旧 Goal 实例凭据返回 409,均在 native launch 前;新鲜读回可继续绑定。实际 CLI 和 HTTP 分别完成 bind→stop→status→cold bind→stop,冷绑定恢复各自同一 session、无 target、保持 idle,模型目录为空时启动不可用,自有 owner 锁释放,registry 字节未改变。

对主干的风险

原审查 5426602303 的两项问题已逐项核验:组合故障恢复现在先保留包/manifest 版本修复,再追加 ZCode facade 修复。相同合成事实调用基线/head 的生产 doctor,当前 head 不再把 requires_upgrade=true 的包故障替换成 skill-only 指令;四个 missing/stale × version-mismatch 用例验证“只修 facade 仍不就绪、完整修复后就绪”。macOS 临时路径改为目录身份规范化,保留隔离、父环境未修改和临时目录清理断言,当前全部通过。原来的阻断不再适用于这个 head。

当前 exact-head 本地检查:131 个 touched Python 检查、182 个既有安装/doctor/activation 检查、56 个 TS 检查(含实际 owned-process 清理与共享 digest owner)通过;类型、构建/安装/来源校验、全树 semantic smoke、diff 检查通过。打包 desktop/mobile 场景通过:折叠时零探测、模型/推理级别、quota 拒绝、旧创建凭据、未知操作恢复、Agent 切换及 viewport 布局。它使用 stateful HTTP/provider fixture;另有生产 ChatHTTPServer+Core+真实官方 CLI 的独立 8 请求资格,不能混称为真实模型端到端。既有真实 HTTP acceptance retry 两个故障场景也通过。

真实宿主取自官方 ZCode macOS release,CLI 自报 0.16.9。全新隔离环境中直接调用 Desktop JS bundle 最初因其找不到 bundled provider config 而退出;同一 CLI 直接协议探测复现了这个 upstream 启动问题。显式提供该发布包已有的 provider config 后,CLI 与生产 HTTP 的空闲冷恢复通过。没有安装或修改用户账户、没有模型请求;这个边界应与通常已配置 CLI 的可运行环境区分。doctor 的 version/help 观察也不代表 app-server 一定可运行。

默认关闭核验:同一基线/head 的 7 份 managed facade 字节一致,Codex activation 一致;ZCode 只增加明确可选 provider 的信息与默认仍为 skill 的说明,collapsed panel 没有请求。没有默认启动、Automations、quota 结算或 native completion 转 Goal 验收。CI 按 capability 未拉取/等待;live billing、逐调用硬预算、Desktop 附着与多 Goal 长程净效率没有实测。

我的整体评价

APPROVE,限定为本次可选单会话 provider。恢复阻断已修复,真实宿主的会话留存/冷恢复和当前权限边界已独立验证;用户从“靠外部会话手动猜状态”进入“同一 Goal 内明确控制与读回”,升级组合错误也避免无效重试,局部体验和恢复效果是正向的。

效率采用明确有界取舍:每个活跃会话约两秒一次串行权威/quota 子进程、十秒检查超时、一小时执行安全截止、五分钟空闲退出;该成本仅在显式启用 provider 后产生,失败暂停、恢复不自动续跑。因此当前证据支持可控恢复的正向增量,不能支持 fleet 长程净效率已经提高。未来测量应沿现有 S4/S7/S8 做真实活跃模型与成本/有效产出资格,不增加推测性框架。已考虑同域 refactor 并复用 digest/诊断 owner;暂不扩大为 per-call budget 或 Desktop 控制。合并与通用无人值守验收是独立责任。

English verdict: APPROVE — exact head 9588ccc. The prior mixed-install recovery and macOS path blockers are resolved. Current protocol/process, packaged UI, legacy installation and real official idle CLI/production HTTP cold-session recovery pass. This approves the bounded opt-in provider, not active-model/fleet efficiency, live billing, Desktop attachment or autonomous merge authority.

…ostics

Signed-off-by: jackie-cqz <2557911191@qq.com>
…ostics

Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
…ostics

Signed-off-by: jackie-cqz <2557911191@qq.com>
@jackie-cqz

Copy link
Copy Markdown
Contributor Author

Updated head: a5b97fcca67ba2e3b461cd52f038dfc02c1b0a1f; base main includes 49af193c4. GitHub now reports BLOCKED / REVIEW_REQUIRED, rather than BEHIND. Required CI has restarted on this head.

Separate signed commits address the old-head failures: preserve complete routed commands with measured presentation budgets; use real producing-workspace and newer-receipt fixture inputs; persist confirmation gates through reload; replay demo completions through hard leases; explicitly select the temporary legacy File source for installed shadow/promotion/rollback acceptance; keep Skill activation in the existing host boundary; constrain registry metadata exceptions to exact read-only functions; confirm owned POSIX descendants stop before returning.

The process repair closes a demonstrated asynchronous KILL race. Absence/all-zombie state proves stop; unknown/failed observation remains an error. Execution deadlines, force-only zero-grace, quota, per-Todo growth, authority and stale-write constraints are retained. No quiet-period assertion was weakened.

Local qualification: full settlement 92 passed; process/operation-host/ZCode doctor 106 passed, 2 existing opt-in skips; metadata/lifecycle 11 passed; synchronized host/architecture 208 passed, manager/operation 84 passed, budget/probe/demo 150 passed. Full CLI budget smoke passed against actual 31510ea75 main, with matched 96-row Linux/Windows evidence. Linux installed acceptance passed all five stages.

At the published head, lint, control-plane typecheck, the 288-site registry census, full semantic smoke, packaged ZCode/typed-action journeys and source-matched wheel readback pass. Actual ZCode CLI 0.16.9 preserves the same session across bind/stop/cold reconnect, with zero model calls. Larger suite counts refer to synchronized repair checkpoints, not a claim that GitHub CI is finished.

The bounded result remains managed CLI Goal control. Desktop attachment, live billing and per-call hard budgets stay outside scope. Existing typed Goal/quota/receipt owners retain authority; PS states and architecture classifications stay local. The adjacent refactor reuses host/process boundaries. Confirmed shutdown and durable UI gates improve recovery; native usage remains unknown and completion grants no Goal acceptance or credit settlement.

The previous approval covered 9588ccc; this new head requires maintainer re-review after required checks finish. No merge performed.

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh

Reviewed exact head: a5b97fcca67ba2e3b461cd52f038dfc02c1b0a1f; base: 49af193c465409f488705b4dadfbc73fad13e8f5.

动机

使用已有 Goal 的 ZCode 用户需要在同一位置绑定、启动、暂停、恢复和停止独立 CLI 会话。此前只能通过 Skill 入口进入,缺少原生会话的直接控制和状态回读。本 PR 增加可选的托管 CLI provider,同时提供诊断和安装恢复。当前缺陷是纯非 ZCode Goal 也获得 ZCode 入口,混合 host 的 Goal 又把无法使用此 provider 的 Agent 放入候选列表,用户展开后进入必然被拒绝的状态。本文要求修复这个资格投影,不要求新增 Desktop 附着、Automations、逐模型调用硬预算或 live billing。其他 host 应保持原有 Goal 详情体验,混合 Goal 应保留符合资格的 ZCode 操作。

改动思路

CLI 和本地 HTTP 经同一 bridge 读取 Core 的 Goal、注册 Agent、实例和创建凭据;TypeScript controller 管理 native session、显式启动意图及恢复,Core 保留准入和 quota 决策。诊断使用隔离的 version/help 探测,Skill freshness 复用 installer 渲染。这个 provider 与纯 Skill 说明有不同职责,新增会话状态有真实生命周期消费者,不宜把 Core quota 或身份规则复制到 frontend。

本轮最小修复边界是共享 host/provider 资格的投影与展示:入口和候选 Agent 使用与后端一致的资格来源;不能仅按当前整个 App 的 host 隐藏,因为一个 Goal 可同时含 Codex 和 ZCode Agent。明确声明其他 host 的 Agent 必须排除;未声明 host 的 Agent 应遵循后端现有显式 provider 选择规则,不能根据 Agent 名称猜 host,或顺便破坏该兼容路径。正常绑定和模型执行仍保持显式操作。

具体改动

spec_ref: docs/development/frontend-delivery.md; spec_revision: 49af193c465409f488705b4dadfbc73fad13e8f5。该文“Choose the owner and composition”要求不展示不能作用于所选对象的控制,并复用既有状态/效果 owner。关联视觉依据为同版本 docs/development/design.md 的 Earn The User's Attention。criteria FD-target-applicability 在此 head 为 not_met:可选 provider 的 UI 未投影注册 Agent 的 host 资格。最小修复是用共同 owner 的资格 read model 过滤入口和候选集合,不放宽 backend 拒绝。

关键代码讲解

  1. ContextDrawer(context-drawer.tsx:807)无条件挂载 ZCodeGoalControl。buildPersonalHomeModel 只把 coordination.registered_agents 传入 WorkspaceGoal.registeredAgentIds,没有传递 provider 资格,因此非 ZCode Goal 同样显示该折叠入口。
  2. ZCodeGoalControl(zcode-goal-control.tsx:12–27)默认选第一个注册 Agent,并把整个集合映射成下拉选项。展开本地可写且有 Agent 的面板后,ZCodeAgentControl 的 effect 调用 fetchZCodeGoal;失败清空 snapshot,再让用户读状态重试。当前缺少资格,不是 snapshot 错误恢复能解决的问题。
  3. validate_zcode_binding(bridge.py:73–80)读取注册 profile,并对明确声明为其他 host 的 Agent 拒绝;这发生在 Node/provider discovery 前。未声明 host 则允许显式选择 provider。身份、quota、会话动作不应为了让错误候选可用而放宽。
  4. NativeGoalController、app-server 和 guardian 管理同一 session/target、CAS、权限拒绝、冷恢复暂停及 owned process 清理;doctor 和 facade 检查负责独立宿主观察与安装恢复。共享 HTTP/CLI 和包装指纹使用同一 provider vocabulary,界面文案/CSS及 browser smoke 交付操作和回读。
  5. 当前完整范围是 63 文件、+5037/-219;还包含 POSIX process-group 停止确认、CLI 展示预算调整、demo hard-lease/decision-scope 适配,以及 HTTP retry、installed-authority 和 heartbeat fixture 修正。这些范围已纳入阅读和风险清单;本轮没有把它们的历史验证重新标成当前独立通过。

对主干的风险

[P2, blocking] 按注册 Agent 的 provider 资格过滤入口和候选列表。 触发:Goal 仅有显式 codex-cli Agent,或注册列表以该 Agent 开头且后面有 ZCode Agent。纯非 ZCode用户仍看到“ZCode 原生 Goal”;混合用户展开时默认选中 Codex Agent并请求 status。生产 bridge 对该身份返回 400 / The registered Agent explicitly declares a different host.,绑定、启动也被拒绝。刷新不能改变这个注册事实,用户需要自己猜测哪个 Agent 能用。

独立证据:对当前组件的真实 React SSR,non-ZCode、mixed 和 ZCode 三类输入均渲染同一个 ZCode summary;这是组件源码验证,不是 packaged viewport 或 installed App 验收。源码 registeredIds.map 证明其他 host 未被排除;对隔离合成 registry 调用生产 zcode_goal_operation,Codex 的 status/bind/start 均在 provider discovery 前拒绝,registry 字节不变、provider discovery 调用为零。

修复后请在现有 zcode-goal packaged browser 场景覆盖:纯其他 host 不出现无关入口、不请求 ZCode status;混合 host 只列符合 backend 规则的候选,并选择合适默认值;符合资格但 CLI 缺失时保留可理解的 unavailable/恢复状态;未声明 host 的现有显式绑定兼容路径保持;切换/移除 Agent 后旧响应不能污染新选择。用真实 owning backend 核对资格规则,不能让 HTTP fixture 直接伪造全部 Agent 都可用。

本轮当前 head:uv run --extra test python -m pytest -q tests/test_zcode_goal_bridge.py tests/test_zcode_host_surface.py 为 69 passed;三个 zcode_* TS suites 为 39 passed;生产不同 host 反例和 SSR 观察如上。现有 browser smoke 仅放入两个 ZCode Agent,不能覆盖这项缺口。当前 CI 观察为 1 success、9 queued,pending 本身不是本次阻断原因;未等待或宣称全绿。没有运行付费模型、当前 head 的 packaged 全视口、real native active-model/fleet、完整展示预算对比或完整平台测试。

我的整体评价

REQUEST_CHANGES,阻断依据是已确认的前端对象资格不一致。provider 的会话控制增量有价值;本轮 69+39 项检查没有显示这些局部契约失败,但不能代替非 ZCode 的用户路径。user_experience 是 regression:用户多一个不能使用的入口,并可能因默认错误对象反复刷新;long_horizon 的 native active-model/fleet 效益本轮未重测,不从此前 approval 或空闲恢复推导它已成立。

同域 future-facing pass 应将 host 资格一次投影给 frontend,使下一次 provider 扩展无需再复制一套分类;不需要新增开关、放宽权限或扩大为整套 host 架构重写。provider 动作/状态词表是本地 contract,Goal/Agent/quota 继续复用已有 owner。修复并提交新 head 后,重跑现有 packaged 场景及不同 host 负例,再独立复审;本意见不撤销旧讨论、不批准合并。

English verdict: REQUEST_CHANGES — exact head a5b97fc. The Goal drawer exposes ZCode controls and all registered Agent candidates even when backend host eligibility rejects them. Filter both entry visibility and candidates through the shared eligibility owner, preserving mixed-host and undeclared-host compatibility. Current focused checks pass (69 Python, 39 TS); production bridge rejection and component SSR confirm the gap. Packaged non-ZCode/mixed-host regression coverage is required.

export function ZCodeGoalControl({goal, readOnly}: {goal: WorkspaceGoal; readOnly: boolean}) {
const {t} = useWorkspaceI18n();
const [opened, setOpened] = useState(false);
const registeredIds = goal.registeredAgentIds ?? [];

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] 让入口与 Agent 候选共用后端的 host/provider 资格

这里直接使用全部 registeredAgentIds,并默认选第一个;ContextDrawer 也无条件挂载本面板。仅有显式 codex-cli Agent 的 Goal 仍显示 ZCode 入口;混合 Goal 若 Codex 排在前面,展开就会请求这个身份的 status,而 validate_zcode_binding 在 provider discovery 前返回 different-host 400。刷新不能修复不适用的对象。

请由共享 owner 投影资格,同时过滤入口与候选/默认值;不要仅按整个 App 当前 host 隐藏,以免误伤混合 Goal,也不要按 Agent 名称猜 host。未声明 host 的现有显式 provider 选择路径应按 backend 契约保留。补充 packaged 非 ZCode-only/mixed-host 场景,证明无错误对象探测、正确候选和默认值,并与真实资格 backend 对齐。

@mergify

mergify Bot commented Oct 7, 2026

Copy link
Copy Markdown

This pull request has merge conflicts with main and cannot be merged
until they are resolved. Please rebase or merge the base branch, @jackie-cqz.

Choose the remote for the base repository, not an out-of-date fork.
For a fork clone, first inspect git remote -v; upstream must point
to https://github.com/loopx-project/loopx.git. If it is absent, add it
with git remote add upstream https://github.com/loopx-project/loopx.git.
Then run:

git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEAD

For a same-repository clone whose origin points to
https://github.com/loopx-project/loopx.git, use origin instead of
upstream for fetch/rebase. If you prefer merging the base, use
git merge <base-remote>/main and push normally.

Keep the DCO Signed-off-by trailer on every commit when you rebase.
https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/syncing-a-fork

@mergify mergify Bot added the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 7, 2026
…ostics

Signed-off-by: jackie-cqz <2557911191@qq.com>

# Conflicts:
#	examples/shared-goal-authority-e2e/installed.py
#	loopx/control_plane/testing/cli_output_budget.py
#	loopx/semantics/project_registry_io_manifest_v1.json
#	tests/control_plane/test_cli_output_budget.py
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
…ostics

Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
@jackie-cqz

Copy link
Copy Markdown
Contributor Author

CI and review repairs are pushed at 77dde0d4ae1de8c86375ba0a14a9af8bcf31f8d7, including main at 0475fce1a.

  • Python shards: all 13 failures had the same obsolete refresh-state Namespace, before the intended strict-JSON/hook checks. True main and the original PR each reproduced 13 failed / 2 passed. The fixture now uses the real CLI parser; all 15 tests pass with existing assertions and negative cases retained.
  • Three frontend/package jobs: build and wheel/sdist installation passed; they shared the stale team-plan retry expectation. The accepted main test(chat): cover authoritative Team Plan recovery #5849 recovery fixture is included. Packaged readback proves one authoritative applied write, read-only recovery after unavailable action-list status, and explicit safe retry returning the original receipt without a second write. The final Linux packaged suite passes 49/49 scenes plus related real temporary HTTP feedback, proposal/recovery, upgrade and asset checks.
  • Review [P2], host/provider eligibility: the existing binding guard supplies the Chat read model and frontend candidates/default/visibility. Explicit other-host Goals have no controls and zero native probes; mixed Goals filter candidates; undeclared advisory hosts retain explicit compatibility. Removing eligibility unmounts pending requests, and stale receipts cannot authorize the new panel. Actual Chat HTTP follows canonical shared sources, fails closed on unreadable metadata and adds zero canonical source reads. Provider-only frontend requests now live outside generic Chat data so existing narrow smoke compiler flags continue to work.
  • Main sync exposed unchanged presentation-budget failures. Matched main/head caller clauses, complete commands and growth/duplication rules are retained. Only measured presentation allowances and obsolete route/JSON test oracles changed; production quota and the 8 KiB performance diagnostic did not. Some crowded/multi-Agent envelopes still report their existing overflow warnings. See the updated budget evidence and limits.

Validation: 151 budget/probe/differential tests on Linux and Windows; enforced 96-row candidate budgets; 267 Linux host/status/API/census tests; 175 latest-main qualification tests on Linux; 39 native-provider TypeScript tests; final packaged ZCode on Windows; full CI Ruff, frontend build/typecheck, control-plane typecheck, kernel mypy, semantic advisory/full-tree check and the 289-site registry census. Broader Windows POSIX host tests and latest-main bound-path privacy qualification failures are recorded separately in the PR body; no privacy guard was relaxed. No paid model or native Goal was started during these repairs.

New exact-head CI and independent review are pending. This comment reports the repair and evidence; it does not approve or merge the PR.

@mergify mergify Bot removed the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 7, 2026
…ostics

Signed-off-by: jackie-cqz <2557911191@qq.com>
@jackie-cqz

Copy link
Copy Markdown
Contributor Author

Final main sync is pushed at eb67ce65466fab6cdd77e2a97938b30f0ee88b68, including main 718753e78 (#5848/#5858). This follows the CI/review repairs; the final merge adds no further ZCode lifecycle or frontend changes.

The previous Python Tests run at 77dde0d4a was cancelled by GitHub concurrency: its annotation reports a higher-priority waiting request for the same PR merge ref. That snapshot has cancelled jobs, not a failed test conclusion. The triggering event was not established.

Final merged-source verification passed: 27 TypeScript quota/gate tests; 43 Python deadline/clock/compact/resume tests; all 14 Linux writer/interleaving tests with no skips; the existing enforced 96-row budget matrix and 30 focused budget/probe tests; CI Ruff, control-plane typecheck, 19-file Linux-target mypy, semantic advisory/full-tree check and the current 289-site registry census. Budget limits and ZCode contracts were not changed during this sync.

Windows writer/census qualification reports 18 passed, one POSIX interleaving skip and two upstream pipe-select platform failures. Both affected tests execute and pass in the complete Linux writer file. The PR body distinguishes this final merge evidence from the earlier 49-scene packaged frontend, 151 budget and 267 host/API qualification.

The branch includes the fetched main head, has DCO sign-offs and a clean worktree. New exact-head CI and independent review remain required; this does not approve or merge the PR.

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; model=gpt-6.1-sol; provider=OpenAI; runtime_reported; reasoning_effort=xhigh.

Exact head: eb67ce65466fab6cdd77e2a97938b30f0ee88b68; base: 718753e78e64c1943ea029e193282aceedce078a. 这是重新核验当前完整 70 个路径后的结论。

动机

使用已注册 ZCode Agent、希望从 CLI 或工作区管理原生 Goal 的用户。 之前用户需要在宿主手动检查 CLI、选择会话并控制原生 Goal;现在可显式绑定、选模型、启动、暂停、恢复和回读,并在缺失 CLI 或额度受限时看到可操作状态。 当前代码与打包界面已验证显式绑定、模型选择、旧身份拒绝和额度阻止;退出成功却遗留原生进程的反例仍阻止完整交付。 不证明 Desktop 接入、Windows 进程树、真实模型成本、长期多轮或 fleet 资格。 完整停机与异常退出仍会遗留原生进程;真实宿主和长期净效率未独立验证。

原生 Goal 是宿主内部任务状态,不等于 LoopX Goal 验收。判断依据为本 PR 之前的 整体路线图:S4 停止/重启必须隔离旧执行者,S5 需要完整界面与恢复路径,S7 区分额度准入和真实消耗,S8 要有明确启用/停用及隔离边界,S12 保留包与源码验证。

改动思路

沿用 Core 的 Goal/Agent 身份、创建见证和额度,在 provider 内用 TypeScript 管理原生意图、NDJSON 会话与 CLI broker;Python 只做注册源、CLI/API 适配和只读诊断。前端复用 Goal 抽屉,先选实际可用 Agent,再显式绑定 CLI 和模型;缺失 CLI、身份变化、配额拒绝都能回读,绑定不会自动选模型或启动。

本次也独立确认了此前混合安装/Skill 诊断和任意注册 Agent 出现 ZCode 控件的问题已修复。旧 review 的结论不作为当前退出路径已安全的证明。

具体改动

关键符号:

  • ZCodeAppServer / terminateOwnedProcess:协议边界、超时、权限拒绝和进程退出。
  • guard:broker 管道丢失时撤销受管 CLI。
  • runtime / expected_binding:原生意图恢复及精确身份/创建见证的前后核验。
  • ZCodeGoalControl:Agent 过滤、显式模型确认、操作回读与迟到响应丢弃。
  • SkillFacadeReadbackStatus:共享 Skill 诊断、已有宿主 facade 与混合安装修复。

其余改动也已纳入审查:通用 process helper、source-goal 观察缓存和 status/Chat 投影;doctor/Skill 安装与包构建输入;英中翻译、CSS、两张示意截图;浏览器/CLI/原生协议回归;示例的 lease 完成释放与安装态显式 File 选择;输出预算与 registry I/O 清单。它们没有把原生完成兑换为 Core Todo/Goal 完成。动态诊断和 provider 状态属于其现有 typed owner,语义 advisory 有六项提示;全文语义门未独立跑完,保持未测。

[P1] 成功退出仍可能遗留原生进程(app-server.ts:257–266, guard.ts:8,28–29)。 app-server 把 guardian 放到独立进程组,guardian 又把 CLI 放到另一个独立组;close() 直接 SIGKILL guardian 的组,只确认 guardian 退出。guardian 来不及清理,CLI 的组不在被杀的组内。此外 native leader 先退出时,guardian 直接退出,而 helper 对已退出 leader 提前 return,活着的后代也被跳过。

我用隔离的真实子进程、无模型协议 fixture 调用生产代码,分别复现:① initialize → close 正常返回,但 native leader 与 descendant 都仍存活;② native leader 退出 0,guardian 退出 0,descendant 仍存活;③已回收 leader 后调用 helper,成功返回但 descendant 仍存活。探针结束时清理了自己创建的模拟进程,没有操作真实 Goal。最小修复是在现有 TS guardian/helper 边界先协作关闭、再有界兜底,保留 leader 退出后的组身份,并确认整个受管执行树停止;确认不了就返回失败。补上上述三条真实进程回归,而不是只断言 leader exit。

对主干的风险

这是 S4/S8 的停机后置条件缺口:界面或 broker 可报告断开,实际工作仍运行;后续恢复可能与旧执行重叠。Core 准入不等于逐次模型硬上限,所以不能用一次额度检查消除此风险。没有实测真实模型费用或频率,不把进程存活推断成已经收费。

独立当前头验证:274 个 Python host/bridge/doctor/Chat/process 测试、39 个 TS 原生协议/guardian/runtime 测试、124 个预算/探针/结算/demo 测试通过;build:chat、控制面 typecheck 和 diff check 通过。打包 zcode-goal 浏览器场景通过,覆盖纯其他宿主无控件、混合 Agent、缺失 CLI、模型显式选择、旧见证拒绝、配额拒绝、迟到结果与移动端;它使用有状态 HTTP fixture,不能替代真实 native transport。三条生产进程反例失败,而且现有绿色 TS 测试没覆盖这些情况。

未独立验证:完整同负载 base/head 输出预算差分、Windows 清理、安装态真实 ZCode/模型及长期多轮。作者证据与未抓取的 CI 不充当这些验证。现有 TS provider 清理只有 leader 退出确认,并拥有两个独立进程组;必须修复整个受管执行树的停机后置条件。 在本 PR 的 guardian/app-server 边界完成退出修复与真实进程回归,不新增通用生命周期框架。

我的整体评价

现有 TS provider 清理只有 leader 退出确认,并拥有两个独立进程组;必须修复整个受管执行树的停机后置条件。 在本 PR 的 guardian/app-server 边界完成退出修复与真实进程回归,不新增通用生命周期框架。

显式启用、身份拒绝和恢复界面的方向有价值,能降低用户反复手工配置的负担;目前不能说长程效果与净效率已正向。成功停机却留下旧执行会抵消恢复收益,并增加重复工作风险。保留已验证的改进,修复进程退出后置条件后再重新核验;当前请求修改,未合并或升级运行中的任何宿主。

English verdict: REQUEST_CHANGES - eb67ce6: production close and native-parent exit can leave owned native processes alive while reporting success. Three real isolated process counterexamples reproduce the defect despite 274+39+124 passing tests and the packaged fixture journey passing; repair guardian/group ownership and whole-tree confirmation before approval.

…ostics

Signed-off-by: jackie-cqz <2557911191@qq.com>
…ostics

Signed-off-by: jackie-cqz <2557911191@qq.com>
@jackie-cqz

Copy link
Copy Markdown
Contributor Author

Main is synchronized at f04c5a46d7c62c9bf7ab2c8a496f2174e1ad79c2, including main aa87cc019e1062455e79c934764b5e85688663cd. Both signed merge commits are conflict-free; there are no additional feature or budget edits. GitHub readback reports MERGEABLE / BLOCKED, with the branch no longer behind the fetched base.

The incoming changes cover legal same-Turn recovery, artifact-only Todo guidance, the optional HTTPS reader, atomic Monitor writeback/recovery and idle Lark handler-failure retry. Existing ZCode quota queries and pause behavior remain unchanged.

Latest merged-source qualification passed: 90 TypeScript Monitor/Todo/quota tests; 53 Linux public crash-recovery/shadow/external-wait/Lark tests; 76 Windows ZCode binding/registry-census tests; the existing enforced 96-row output budget matrix; and 343 tests in the PostgreSQL-backed store/service qualification suites (including service unit tests) on an owned disposable PostgreSQL 16.15 instance with synthetic databases. The server was stopped and removed afterward. No active Goal, registry or provider was used.

Static validation also passed: CI Ruff, control-plane typecheck, 19-file Linux-target mypy, changed-diff semantic advisory and full-tree semantic smoke. Sampled budget character/line costs match the preceding 3e083a709 receipt; no limits or assertions changed.

Earlier receipt-sync evidence remains separate: 162 TS tests passed; the four-file Python run initially had 257 passes and one missing-checkout-context failure, then the corrected case and related 10-case workspace subset passed after private Git/origin metadata restoration. The same case passed in the actual Windows worktree. Raw failures and setup evidence were retained locally; no product or test oracle was relaxed.

All PR-unique commits have DCO sign-offs and the worktree is clean. Exact-head CI and independent review are still required; this comment does not approve or merge the PR.

…ostics

Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
…ostics

Signed-off-by: jackie-cqz <2557911191@qq.com>
This reverts commit b53caa5.

Signed-off-by: jackie-cqz <2557911191@qq.com>
@jackie-cqz

Copy link
Copy Markdown
Contributor Author

Updated this PR to exact head 27c179606f7370dbd8369dd5d63bc986dc441b99, including current main at 4d254fb6f5cca703c31a18d87488bf489ca486ef.

The incoming changes retain canonical Todo lifecycle assertions through exact detail reads, compose the existing frontier index inside its typed summary owner, fence Goal deletion against canonical writers, and scope preference guidance to the participating capability hook. No new ZCode runtime or frontend edits are included in this sync. The intervening presentation-budget proposal was reverted after the upstream scope correction; the existing ceilings, per-Todo/fixed growth, duplication guards, execution quota and 8 KiB performance diagnostic are unchanged.

Validation at this head:

  • 151 budget/probe/differential tests passed separately on Linux and Windows. The enforced 96-row Linux matrix and original regression smoke against true 4d254fb6f passed without changing the ceilings or fixture populations.
  • 79 tests across the two complete preference/Skill Python files and 47 typed preference/interaction/frontier/summary tests passed on Linux without skips. Actual File/SQLite journeys and non-root permission denial/recovery ran; inactive and cross-scope silence, fresh action-specific readback and authority boundaries remain covered.
  • 76 Windows ZCode binding/registry-census tests passed. Full CI Ruff inputs, control-plane typecheck, Linux-target mypy (19 files), changed-diff semantic advisory and full-tree semantic smoke passed.
  • The earlier 80368be6 147-owner and 28-read-adoption runs retain their unchanged deletion/frontier/cutover/lifecycle scope. Prior installed-wheel, packaged frontend and f04c5a46d PostgreSQL qualification are identified separately in the updated body; they are not relabeled as new-head runs. The new summary batch is a pure typed projection rather than a PostgreSQL authority-store refactor.

Original failures remain failures: the interim 80368be6 budget run returned 7 failed / 144 passed on Windows, and its 96-row Windows comparison completed before temporary cleanup failed. The current passing runs above use the final scope correction and existing ceilings. Presentation passes do not certify the 8 KiB performance target, billing or fleet behavior. No live native Goal, paid model or active shared state was used during this sync.

The bounded future-facing pass reuses the existing preference and summary owners; broader host composition is deferred. All PR-only commits carry DCO trailers. GitHub now reports MERGEABLE and BLOCKED, not BEHIND; new-head checks are queued, so this is a validation record rather than merge approval. The PR remains open for maintainer review and merge.

@mergify

mergify Bot commented Oct 7, 2026

Copy link
Copy Markdown

This pull request has merge conflicts with main and cannot be merged
until they are resolved. Please rebase or merge the base branch, @jackie-cqz.

Choose the remote for the base repository, not an out-of-date fork.
For a fork clone, first inspect git remote -v; upstream must point
to https://github.com/loopx-project/loopx.git. If it is absent, add it
with git remote add upstream https://github.com/loopx-project/loopx.git.
Then run:

git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEAD

For a same-repository clone whose origin points to
https://github.com/loopx-project/loopx.git, use origin instead of
upstream for fetch/rebase. If you prefer merging the base, use
git merge <base-remote>/main and push normally.

Keep the DCO Signed-off-by trailer on every commit when you rebase.
https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/syncing-a-fork

@mergify mergify Bot added the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 7, 2026

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; model=gpt-6.1-sol; provider=OpenAI; runtime_reported; reasoning_effort=xhigh.

REQUEST_CHANGES — current exact head 27c179606f7370dbd8369dd5d63bc986dc441b99 still leaves owned native execution alive after successful shutdown. The earlier P1 is not resolved by this main sync. Entire PR: 70 paths, +5359/-310; immutable merge base 4d254fb6f5cca703c31a18d87488bf489ca486ef.

动机

使用已注册 ZCode Agent、希望从 CLI 或工作区管理原生 Goal 的用户。 之前用户需要在宿主手动检查 CLI、选择会话并控制原生 Goal;现在可显式绑定、选模型、启动、暂停、恢复和回读,并在缺失 CLI 或额度受限时看到可操作状态。 重复配置和不透明恢复会增加干预;受管进程残留又会使后续恢复与旧执行重叠。频率、真实模型费用和净效率没有测量。 已复验显式绑定、身份拒绝、诊断与恢复分支;当前真实子进程三条反例仍报告成功却留下受管执行,阻止安全恢复。 不证明 Desktop 接入、Windows 进程树、真实模型成本、长期多轮或 fleet 资格。 成功停机与 leader 退出后的受管执行仍未停止;真实模型采用和长程净成本不在本次验证范围。

实际收益是把“在宿主手工寻找并控制会话”变成已有 Goal 下可读回的显式操作,缺失 CLI、额度拒绝和旧身份可以定位与恢复。当前反例使“已断开后能安全继续”不成立,不能仅以同步 main 或此前修复数判断长程收益。

改动思路

spec_ref: docs/architecture/rfcs/loopx-overall-roadmap-v0.md; spec_revision: 4d254fb6f5cca703c31a18d87488bf489ca486ef。按修改前已接受的相关条目核验,本 PR 新增的路线图 checkpoint 不是独立验收依据。

  • S4:停止/重启要保留工作并隔离旧执行者。本次三条真实进程反例未满足,需在同一 guardian/helper 边界修复。
  • S5:本批是已有 Goal 抽屉的原生 CLI 控制与异常读回增量。完整共享会话、协作返回、所有前端/Lark 路线仍属父路线图;未宣称完成。
  • S7:Core 的准入、消耗和估计分开;native token/cost 保持未知,native complete 不变成 Core Todo/Goal 完成或扣费。当前 bridge 与 native 回归覆盖此边界。
  • S8:能力发现与启动分开;已注册且适用的 Agent 才显示控制,绑定/模型/执行都明确选择。关闭的停机后置条件仍未满足,其余安装/只读诊断/off-state 回归通过。
  • S12:本次 source、临时安装/更新和语义检查通过;此前相同 provider/UI 的打包场景按 blob 对照复用。真实安装态模型、Windows 停机及所有系统升级资格仍未完成。

Core 负责身份和额度,TypeScript provider 负责原生会话意图、协议与效果,Python 适配已有权威源,前端投影同一个 owner。原生 session/目标/模型意图不能从 Core Goal 自动推导,保留独立 provider 有理由;诊断与 Skill freshness 复用 installer 渲染,source 观察复用已有缓存。最近相关的未来整理应落在现有 typed process/group 边界:已有 host_process_group.ts 会在 leader 退出后确认组内是否仍有可执行成员;provider 不能继续使用更弱的成功定义。

现有 TS provider 清理只有 leader 退出确认,并拥有两个独立进程组;必须修复整个受管执行树的停机后置条件。 在本 PR 的 guardian/app-server 边界完成退出修复与真实进程回归,不新增通用生命周期框架。 这是当前必须修复的 invariant,不是可选择的观测策略。无需引入通用生命周期框架或另建 Core 额度/身份 owner。

具体改动

全 PR 覆盖了:CLI/API/Chat/status 与注册源投影,native bridge/runtime/cli/app-server/guard,doctor 的 CLI/Desktop/源码和 Skill 诊断,installer 的共享 facade 提取与混合修复,构建指纹/包清单,Goal 抽屉的模型和生命周期控件、英中翻译/CSS/两张状态示意图,以及相关 Python/TS/浏览器回归、demo lease 释放、安装态 File 选择、预算规则与 registry I/O 清单。未把 provider 完成换成 Core 业务验收。

关键路径:validate_zcode_binding 拒绝未注册、外部宿主和旧实例/创建见证;NativeGoalController 保留显式 native 意图并支持冷读回,cli.ts 在启动/恢复前查 Core quota;ZCodeAppServer 验 NDJSON session/target/revision、拒绝未获准交互;ZCodeGoalControl 使用后端资格过滤候选、丢弃已移除 Agent 的迟到回执;inspect_skill_facades 用当前 installer 内容判断 freshness,保护用户文件。普通使用路径是打开 Goal→选择可用已注册 Agent→显式绑定→必要时选模型→启动→暂停/明确恢复→停止/读回。每次执行选择提供真实目标或效果授权,没有要求再建 Goal/Agent;模型目录或 CLI 存在本身不会启动。

[P1] 成功退出仍遗留受管执行:app-server.ts:257–266, guard.ts:8,28–29。 app-server 把 guardian 放入独立组,guardian 又把 native CLI 放入另一个独立组。close() 直接 SIGKILL guardian 的组,等待 guardian 退出,CLI 的组未停止。native leader 先退出时,guardian 直接退出;helper 也对已 reaped 的 leader 提前 return,活着的后代因此被跳过。

本次在当前 exact head 的 Darwin 真实子进程上重新复现:① production initialize→close 成功返回,native leader 与 descendant 都存活;② native leader 退出0、guardian退出0,descendant仍存活;③ leader已回收后调用 production helper,成功返回而 descendant仍存活。判断依据是实际 PID/PGID 和非 zombie 状态;NDJSON 只有模型无关的协议回答,零模型调用、零真实 Goal 变更,探针最终清理了自己创建的进程。最小修复:先允许 guardian 协作关闭,再有界兜底;保留 leader 退出后的 owned-group 身份,确认整个受管执行停止,确认不了就返回失败。三条真实路径都要有回归,不能只断言 leader exit。

对主干的风险

本次复核了所有 70 条变更路径与此前已完整审查的 eb67ce65466fab6cdd77e2a97938b30f0ee88b68:67 个 head blob 相同;另三个为共享 facade、结算 fixture 和生成 census,base/head 都有上游变化,已重新读差异。native provider、前端、状态示意资产没有变化,所以此前真实打包浏览器的其他宿主无控件、混合 Agent、CLI 不可用恢复、显式模型、旧见证、quota-held、迟到回执及移动端证据可有界复用;没有将其改写成新的打包/OS/model 运行。旧混合安装修复和 host 资格 findings 由当前完整 Python suites 继续覆盖。P1 teardown 当前仍失败。

当前独立验证:293 Python host/bridge/doctor/Skill/Chat/process 用例,39 TS native 协议/guardian/runtime 用例,124 预算/探针/结算/demo 用例通过;控制面 typecheck 通过;精确基线 premerge 的19 selected和5 direct均通过,包含全树语义、安装/更新、公共边界和预算。另以不可变 4d254fb6f5cca703c31a18d87488bf489ca486ef 明确运行同负载 CLI 差分:base96/candidate96,candidate_only0、review_required0;这说明本轮测得预算与结构/条款 guards 满足,不代表模型理解、运行提速或未变的8KiB性能目标已达成。advisory的六项属于 provider词表、本地诊断和既有 bundle来源 owner,动态词表不在该探针覆盖内。

绿色测试未覆盖上述三种实际停止条件。风险是断开成功后仍工作、随后恢复产生重叠,频率和真实收费未测;不把进程存活推断成已经收费。真实安装 ZCode/model、Windows 清理、长期采用/净费用和 fleet 未独立验证;不抓取或等待 CI。关闭能力不应靠用户额外清进程来恢复。

我的整体评价

现有 TS provider 清理只有 leader 退出确认,并拥有两个独立进程组;必须修复整个受管执行树的停机后置条件。 在本 PR 的 guardian/app-server 边界完成退出修复与真实进程回归,不新增通用生命周期框架。

原生控制与可操作诊断对单人体验有正向潜力,当前已验证减少手工找会话和不透明重试;停机保证却直接影响后续能否安全继续,当前长程效果及净效率不能判为正向。保留有用增量,修复具体 owned-tree 后置条件后再按新 exact head 复验。没有新增控制面的验收捷径;没有合并、安装升级、模型费用资格或父 Goal 完成声明。

English verdict: REQUEST_CHANGES - 27c1796: production close, native-parent exit and reaped-leader cleanup still leave owned executable processes alive. Three current real-process counterexamples fail despite 293 Python,39 native TS,124 budget/settlement tests,19+5 premerge checks and the pinned96/96 CLI differential passing. Repair cooperative guardian shutdown and whole-owned-group confirmation before approval.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-rebase Mergify: the pull request has merge conflicts with its base branch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants