Repository navigation
fix(context): scope preference guidance to its participating hook - #5874
Conversation
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
loopx-agent
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Reviewer: model_agent / OpenAI gpt-6.1-sol / reasoning_effort=xhigh (runtime_reported)
Exact head: 9623e12740b4f3d8126c61e18fd1016177a0fa13; baseline: 06b6caa07b3a7e420584f36c23320e173cddd1b8. Full 9-file review, +95/-97.
No blocking finding found. The reviewed README inconsistency was repaired in a signed doc-only commit on this PR: Fresh-turn adoption now points to the participating hook and current.instructions, matching the actual installed Skill and delivered view. All runtime/test owner paths are byte-identical to the previously validated head; the new head has fresh distribution/doc readback and risk validation.
动机
使用普通 quota 或原生 Turn 的 Agent,在从未保存本地偏好时也会收到偏好读写的操作指引。
主干即使没有偏好 journal,也调用一次偏好 provider,并把偏好操作说明放进通用 Skill;本 PR 让未参与的作用域保持安静,仅在明确保存过偏好的 Goal/Agent 中通过 hook 交付操作规则。
主干与 PR 的真实 CLI 对照确认:未触及的 runtime 从一次偏好 provider 调用降为零,生成的通用 Skill 从 6129 字节降到 4909 字节;参与后仍一次快照交付当前偏好。
本次只修复已有 CLI/host 的指令与参与边界,不新增开关、权限、记忆服务或前端编辑器;不证明模型自然采用、长期任务得分或整个 Turn 的费用降低。
改动思路
已有 journal 是保存显式指令的私有事务记录,足以说明准确作用域是否参与;没有必要再加配置开关或缓存。真实入口是普通 quota 和原生 Turn。桥接层在整个 namespace 不存在时直接返回;namespace 已存在时让原来的 TypeScript owner 读取一次,只有准确 Goal/Agent 的 journal 才交付正文。read 和 preview 不创建 journal,其他 Agent 的记录不会激活本 Agent。读取失败走已有 unavailable 策略:暂停依赖该上下文的动作,独立工作保留原授权。
架构判断:已有 journal 和 TS current 足以决定准确作用域并提供规则,移除通用入口中的重复领域指令;不增加开关、缓存或平行权威。本次只修复本地偏好的参与与指令归属,保留既有生命周期、失败和后续动作新鲜性;模型自然采用、外部服务、整轮费用不在此次已验证范围。相关的有界简化已经应用:指令集中到 current owner;额外模块抽取或新状态 owner 没有当前需要。
具体改动
关键代码讲解
extend_turn_start_dispatch(loopx/capabilities/semantic_preference/agent_preferences.py:34):无 namespace 时不调用 provider;已存在时由原 typed store 判断准确 scope。permission denial 不被误当作关闭,retired/expired 记录继续保留参与关系。current(loopx/control_plane/capabilities/agent_preferences.ts:79):把读、纠正、退役、来源、稳定操作身份及 preview/execute/readback 规则放进当前正文。已经履行的 pre-work read 不重复;每次依赖偏好的后续外部动作前,仍必须用新 guard 或显式 agent read 获得新鲜视图,包括此前为空或已有正文的情况。偏好始终是建议,不能授予权限。projectInteractionWorkContext(loopx/control_plane/work_items/interaction_contract.ts):撤回通用 empty-observation 投影,保留能力中立的 source freshness、剩余 required_reads 和 unavailable 依赖动作暂停规则。缺少 hook 表示未观察,不是已确认为空。_command_prompt_specs(loopx/slash_command_install.py):通用 Skill 删除可选能力的操作段落;真实 wheel materializer 的结果为 4909 字节,重复 materialize 为 unchanged。参与 scope 的 current 正文含迁移后的各条规则。
规范基线是 Explicit Agent preferences / Read, remember, correct and retire / Fresh-turn adoption。逐项映射:exact-scope implemented,真实两个 Goal、八个领域 Agent 无跨 scope 继承;advisory-current implemented,纠正/退役/真实到期/重放和 conditional authority 仍归原 owner;late-action-freshness implemented,真实晚到纠正和发出的指令均要求后来动作前新鲜读取。通用空观察与通用 recipe 的移除是明确默认行为变化,README 新章节和重命名的测试已披露,保留原生命周期并不等于保留旧的普遍可选能力提示。
对主干的风险
独立验证包括 107 个 Python 测试、19 个 TypeScript 测试、TS typecheck、Ruff、语义 diff advisory 后的全树 vocabulary 检查与 288-site registry IO census;native premerge 的 19 个选中检查和 5 个 direct checks 全部通过。CI 策略是 not_consulted / wait_for_ci=false,没有等待远端 CI。四个实际 wheel owner 文件与 exact-head 源码 hash 一致;源码、不可变主干和隔离 wheel 均运行同一真实 CLI harness,每个 41 次调用。
独立负例覆盖:旧 snapshot 返回后真实纠正,随后显式 read/new guard 看见新值;retirement 和真实时钟 expiry 保留失效标记;非 root 的 journal/namespace 实际权限拒绝后恢复并重新获得可用正文;复制其他 scope 的真实 journal 被拒绝后恢复;完整 64 个 subject 在 quota/read/signed Turn 都保留,第 65 个被拒绝且不驱逐旧约束;篡改 signed current 指令被拒绝。没有用空结果或阻塞 receipt 冒充恢复。偏好写入未改 Goal/Todo authority。初始验证命令有路径/参数误用,未产生产品测试结果;随后使用正确仓库入口完成以上检查,没有删断言或放宽限制。最后的文档修正只改3行、删2行,八个其他路径和全部运行 owner 文件逐字不变,因此复用前述行为证据,同时重建新 wheel 读回 README 并在新 head 重跑 native premerge。
主要边界:已有 foreign namespace 的未参与 scope 仍可能做一次存在性/source 检查,但不交付 recipe;参与者的规则正文增长是保留正确性的成本。外部 recall enabled 和显式本地 journal 生命周期是不同边界,外部服务没有被启用或作为实时环境测试。generic empty projection 的移除经过完整来源/失败投影检查,不能把缺失观察解释成空。原先残留的文档句子已修正,并在新 wheel 中逐字读回;没有剩余文档或代码 blocker。
我的整体评价
APPROVE。这次完成的是已有本地 hook 参与与指令归属的有界修复,原始长期 Goal/领域模型验收仍不由此完成。
长程效果判断为 preserved:反复 guard、实际纠正/退役/到期、准确 scope、容量拒绝和权限恢复保持正确,不新增负缓存、额外状态或授权。体验判断为 improved:未使用偏好的 Agent 少了无关指引和 optional provider 调用,显式用户继续沿原 preview/execute/readback 路径进入参与,不增加参数或确认步骤。
效率证据是 mechanism-level:未触及 runtime 的偏好调用 1→0,已参与 1→1,通用 Skill 6129→4909 bytes(减少1220);本次 fixture 的 inactive work_context 减少552字节。五次 warm command 样本在并行验证下波动,不能推出 wall time、模型 token/费用或整轮吞吐的因果改善。长期净收益取决于模型是否少做无关 discovery;本次没有付费模型、长程得分或 live memory-service 结论。该证据支持本 slice 的体验和边界方向,同时保留必要的新鲜性成本。本次补丁和自合并已有 owner 明确授权;仍在当前不变 head 通过原生合并资格检查后执行,精确 head 自 review 记录与 merge readback 分别保留。
English verdict: APPROVE - The existing explicit-use boundary and participating-hook guidance are independently verified across the immutable baseline, exact-head CLI, real journal and isolated wheel. No blocking defect found; the remaining stale README sentence is now fixed and shipped in the rebuilt wheel. Whole-Turn latency, cost and model adoption are unqualified.
Agents that never used local preferences could still discover and reread an empty journal because the generic
/loopxskill taught a preference-specific read/correction workflow. Move those instructions to the TypeScript-owned current preference view, delivered by the participating turn-start hook. Ordinary quota and native Turn receive the same scoped behavior without requiring TurnEnvelope.Local participation retains the existing explicit-use boundary: the first
semantic-preference agent remember --executecommits this Goal/Agent's journal. Read/preview and another scope's journal do not opt the caller in; the separate external-recallenabledsetting is unchanged. An untouched runtime skips the preference provider and adds no preference hook, recipe or read obligation. This follow-up to #5870 removes the generic skill's prior default instructions and the always-empty observation projection.For participating scopes, one fresh snapshot supplies discovery and the current body. Corrections, retirement/expiry markers, exact-scope isolation and later-action freshness remain intact. Permission denial and other failures produce unavailable context with a dependent-action hold; independent work keeps its existing authority. Shared context prose stays capability-neutral; preference operating rules live in the existing capability owner. No new switch, provider registry or lifecycle vocabulary is introduced.
Validation: 127 focused Python tests, 63 TypeScript tests, TypeScript typecheck, Ruff, semantic advisory and registry-I/O census passed. Standard premerge passed all 19 selected checks plus 5 direct checks; no failed/skipped checks or manual validation holds. A newly built wheel was installed into an isolated target and exercised through its real CLI: generated skill, default-off quota/signed Turn, preview versus commit, correction after an earlier snapshot, retirement, permission denial and recovery. Goal paths cover legacy/File/SQLite; preference persistence covers real File/SQLite. Public/private diff scan is clean. Existing running experiments were not updated, and no natural whole-Turn efficiency or score benefit is claimed.
Future-facing pass: remove the unused generic empty-observation carrier and consolidate preference prose in the existing typed capability view. CLI/host prompt surfaces changed; no new frontend/Lark configuration surface or capability operation is added. Maintainer merge is required after exact-head review.
通用
/loopxskill 不再向未使用偏好的 Agent 注入读取、纠正和保存偏好的操作指引;这些规则由参与的 semantic-preference hook 随当前视图提供。保留既有本地显式使用边界:首次remember --execute写入当前 Goal/Agent 的 journal 后参与,read/preview、别的 scope 的记录不会开启本 scope。外部 recall 开关仍独立。启用后的单次快照、纠正/退役、后续偏好依赖动作前重新读取和失败恢复仍保留。默认关闭路径、真实 CLI、签名 Turn、生成 skill 和独立安装包均已验证;不热更新现有实验,不将功能验证当作效率或分数收益。交原 reviewer 审查新精确头,由维护者合并。