Skip to content

fix(heartbeat): retain selected registry through host execution - #5818

Merged
loopx-agent merged 3 commits into
mainfrom
codex/heartbeat-registry-route-20261007
Oct 6, 2026
Merged

loopx-agent merged 3 commits into
mainfrom
codex/heartbeat-registry-route-20261007

Conversation

@loopx-agent

@loopx-agent loopx-agent commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

A heartbeat can read its Goal and Agent from an explicitly selected registry, then generate a quota guard that silently selects the working directory's registry instead. This produces a collection/admission failure despite valid registration. Its action-selection, recovery and settlement guidance can lose the same route.

Pass the resolved registry through the existing heartbeat command renderers and interaction projections. Preserve shell quoting, runtime root, exact Turn identity and current admission/receipt owners. An invalid selected registry still fails; it does not fall back to a valid local roster. The presentation budget normalizes this host path like existing Goal/state inputs, while actual body size remains reported. Refresh the moved registry-read coordinate and record the bounded qualification in the roadmap.

Validation:

  • Seven route/budget regressions pass, including a real CLI generated-command journey in a conflicting working directory, rejected selection, spaces in paths and an invalid selected roster. A review-found long path containing a single quote and the Goal name now normalizes correctly without changing the executed command; the focused route/prompt suites pass 61 tests.
  • Broader affected suite: 201 passed, one existing scheduler-ACK assertion failed identically on clean base be9232700cbe1fa2e6e904fc7417f722f4c7e734. The failure expects an unbound later guard to supersede an older scheduler ACK; this PR does not change that owner.
  • Native standard premerge passes all 19 selected checks and five direct checks; Ruff, configured mypy (19 files), semantic/I/O inventory and public-boundary checks pass.
  • Generated thin CLI input was checked against a real registered Goal. No production guard/settlement was replayed for this validation.

This repair does not qualify model/host latency, distributed authority or fleet scale. Binary rollout follows exact-head review and merge readiness.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

没有剩余阻塞发现。已在当前 exact head 核对完整 diff、实际入口、负例及固定 base 对照;这是同账号的独立角色评审,GitHub 记录为 COMMENTED,不声称平台正式自批准。

动机

使用已注册角色执行原生 heartbeat 的 CLI 与自动化宿主。

操作者从另一个工作目录运行已指定 registry 的 heartbeat 时,旧版生成的命令重新选择当前目录的 registry,导致已注册角色仍被拒绝;本版沿原命令保存选定 registry,恢复、写回和扣槽可在同一 Turn 内继续。

真实 File/SQLite 对照中,base 的生成 guard 因冲突目录注册表失败;head 能选择原 Todo、执行拒绝后的恢复、写回和扣槽,并幂等重放且只扣一槽。

本批只修复已选 registry 的命令路由,不证明安装后的双 Bot 持续运行、模型采用、宿主时延或整个舰队验收。

改动思路

复用既有 renderer 和 typed settlement owner,以参数传播修复真实执行入口;无需新 capability、provider、状态标志或决策副本。

当前边界是现有 heartbeat 和 work-item 命令投影的路由修复;不增加准入、账务、Todo 或调度决策 owner。

准入/执行资格由既有 work-lane/selection owner 决定,结算和幂等性由既有 TypeScript quota settlement owner 决定;Python 仍只承担 CLI 路由与文本投影。 Route 本身不授予 claim、lease、费用、外部 sink 或 merge 权限,也不因 profile 或账户存在而开启能力。

依据是在 diff 之前读取的 receipt-backed settlement progress:selected-route-and-turn 要求生成命令保留原 Goal/Agent/Todo/Turn 与 registry/runtime;scope-refusal-and-recovery 要求选定注册表无效时 fail closed,并经授权的原生恢复继续。两项在真实临时 File/SQLite 中核验。

具体改动

  • support_control.py:成功与错误路径都传已解析的 agent_registry_path.resolve();全局查找及注册规则不改。
  • heartbeat/builder.py:把路由传入 guard、spend、refresh、pre-quota、再生成及可见 Goal 命令;原 Turn placeholder 和宿主选择保留。
  • action_selection_contract.py 与 interaction_contract.py:复用现有 prefix renderer,将同一 registry 传给合法选择、拒绝后的 reentry 和 typed settlement command templates。
  • project_prompt.py:原 renderer 接受可选 registry;显式路径优先,省略参数保留旧 global fallback。默认六个命令与默认 prompt/error 对象在 B/H 完全一致。
  • heartbeat/budget.py:在原展示预算 owner 排除宿主路径长度,保留真实 char_count 和原阈值;shell 转义及 Goal 子串边界在本轮增量修复,独立测量保留旧失败。
  • registry I/O manifest:更新现有 build_new_project_prompt codec-read 的行坐标,不新增删除读写身份或放宽分类。
  • 新 route 回归测试:四种 prompt 模式及真实冲突 cwd/错误选定 roster;同一新增 route 模块补一项预算转义回归。roadmap 只记录有界路由修复,未声称 fleet/latency 资格。

真实正例:从带空格、单引号的选定 registry 生成 guard,在另一 roster 的 cwd 执行;保持原 Turn,选择原 Todo,拒绝错误选择后执行返回的恢复命令,实际 refresh、spend、重复 refresh/spend,并读回同一 identity、无新增 admission、只有一槽费用。反例:使选定 roster 无效而 cwd roster 有效,入口仍错误返回、不生成 guard、不追加费用。base 的两 provider 在生成 guard 即错误拒绝;没有由测试补齐缺失 route 来声称其通过。另有单独显式路由控制组用于区分原 owner 的重放行为。

对主干的风险

不可变 base/初始 head 的相同三个既有文件各71通过;当前 head 的 route+heartbeat-support 两文件45通过(7个新增route/budget、38个既有);其余33个既有测试经全增量仅两路径的失效检查复用;真实 File/SQLite 全链及错误选定 registry 拒绝;Ruff、配置mypy19、TS typecheck、diff advisory、全树semantic和标准premerge19选择项及5直接检查。

可重跑重点:uv run --extra test python -m pytest -q tests/control_plane/test_heartbeat_registry_route.py tests/control_plane/test_heartbeat_prompt_support.py tests/control_plane/test_interaction_contract_workspace_causality.py tests/control_plane/test_quota_authority_settlement_journey.py;npm run typecheck:control-plane;uv run --extra test loopx canary premerge --from-git-diff --git-diff-base be9232700cbe1fa2e6e904fc7417f722f4c7e734。未查询、轮询或等待 CI。

保留基线红:test_standard_codex_app_settlement_is_receipted_and_idempotent 在不可变 B=be9232700cbe1fa2e6e904fc7417f722f4c7e734 与本 H 的 line2423 同样期望 ack_rc==1、实际 0,即旧 scheduler ACK 被接受。测试及其 settlement/selection 因果 owner 在两个版本字节一致,路由不变量另有真实通过证据,所以归为既有无关问题;没有删断言、放宽检查或宣称它已修复,原 scheduler owner/主线程需保留独立限制。

预算不是 transport 或授权 quota。相同生成输入保留 actual 字符数,只比较去宿主路径后的 authored guidance;原 full fixture 的预算溢出也如实保留,不能因修复 registry 就称所有模式均不超限。未声明 vision baseline 的临时 open Todo 重放仍可显示 normal_run,两版显式路由控制组一致;本批证明 receipt 身份与无重复 effect,不虚报所有场景都是 settled-skip。

我的整体评价

当前 exact head ee26083,实际 immutable merge base be92327。复用既有 renderer 和 typed settlement owner,以参数传播修复真实执行入口;无需新 capability、provider、状态标志或决策副本。 当前边界是现有 heartbeat 和 work-item 命令投影的路由修复;不增加准入、账务、Todo 或调度决策 owner。 这是一项可逆且能在真实入口继续工作的修复。future-facing pass 已复用既有 selection renderer,在原 budget helper 收口转义顺序;两个既有 prefix 的实际兼容调用保留,未增加第三个 renderer 或 Python 决策源。剩余 ACK 基线问题和安装后持续运行资格保留给其原 owner。

English verdict: APPROVE - ee26083; selected registry is retained through real File/SQLite guard, selection, recovery and receipt-backed settlement; default API parity and native validation passed, with the unchanged baseline scheduler-ACK failure explicitly retained. No merge or installed-host qualification is asserted.

@loopx-agent
loopx-agent merged commit a6f5ceb into main Oct 6, 2026
6 checks passed
@loopx-agent
loopx-agent deleted the codex/heartbeat-registry-route-20261007 branch October 6, 2026 21:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant