Skip to content

fix(chat): keep manager return delivery on the original host - #6047

Merged
loopx-agent merged 1 commit into
mainfrom
codex/manager-return-original-host
Oct 9, 2026
Merged

loopx-agent merged 1 commit into
mainfrom
codex/manager-return-original-host

Conversation

@loopx-agent

@loopx-agent loopx-agent commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

When several Chat hosts share a coordination runtime, a host without the original conversation can consume its manager return and write retry_pending. The resulting backoff delays the host that can actually deliver it.

Both return paths now check the existing host-frozen source-store provenance before acquiring delivery locks, admitting a return, or changing its receipt. Legacy routes keep their coordination-root default and the existing startup recovery for separate Chat stores. Source grants, lifetime admission, provider verification and idempotent transcript delivery remain with their existing owners.

Validation: reproduced three failing cases before the fix; 73 roundtrip/source-store tests and 198 related collaboration tests pass (3 existing skips). The regressions cover a separate source store, a foreign host leaving the receipt untouched, immediate delivery on the source host, restart deduplication, and skipping exact admission on a foreign host. Ruff and diff checks pass. The generated registry I/O census changes only the existing call's line number; the semantic check passes after regeneration. Native premerge passes after regeneration, with no failures or manual holds; the original failed census check is retained in local evidence. An existing live return later recovered on the old installation and was read back once with a verified delivery receipt. That does not establish the deployed fix; post-review validation must distinguish recovery from deployment and must not resend that result.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: actor_kind=model_agent; model=gpt-6.1-sol; provider=OpenAI; declaration_source=runtime_reported; reasoning_effort=xhigh.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

评审对象:#6047,精确 head 8e5d4c90374d3e93deab75b76ae6024ebf313b46,基线 1d5284077b97ad77a0c173761c11690a7d039ea4。独立核验后未发现阻塞问题,结论 APPROVE。同账号是作者,本记录使用 COMMENTED 自评批准结论,不能称为 GitHub 正式自批准。

动机

在原 Chat 会话等待委托结果、同时运行多个 Chat 宿主的用户。 此前共用协调队列的错误宿主会把本不属于它的回传写成重试,原宿主同一时刻无法送达;现在错误宿主先跳过,原宿主立即处理原会话的结果。 独立基线对照重现了延迟及重试后恢复;当前版本在 File、SQLite 与 source-session 的真实存储上保持外来宿主无写入、原会话立即送达和重启去重。 本次修复宿主分流,不扩大来源授权、Goal 生命周期或 provider 权限;不部署服务,也不宣称生产管家/Lark 回传和全部协作验收完成。 实际安装、线上管家/Lark provider 与包装前端自动刷新未独立验证;此次不把本地存储往返当生产送达。

基线反例还明确证明:旧代码并非永久阻断,原宿主在重试窗口后能送达。因此当前修复的是错误宿主引入的延迟和错误观察,不把已经送达的旧实例算作新版本的恢复产物,也不重发任何已验证结果。

改动思路

宿主归属由已有冻结来源存储位置推导,复用现有来源观察 owner,并在两条 pump 的锁、准入与回执写入前筛选;授权和生命周期继续由原 typed owner 决定。 当前 PR 交付可独立复现的来源宿主分流和原会话继续送达;实际安装后的现场回传资格仍由部署者验证。 增大超时保留错误状态写入,换 consumer 或账号改变用户目标,新宿主登记系统增加重复知识。复用冻结来源位置并在两条 pump 的所有效果之前过滤,正好解决可复现的原因。Path 相等仅选择负责处理的宿主;实际来源授权、GoalRef 生命周期、外部发送许可和 unknown-attempt 验证仍在原 typed owner,不能由这次筛选推导权限。

具体改动

全量四文件 +93/-9:返回模块增加来源宿主过滤;现有来源观察模块提取共同路径解析;registry I/O manifest 只调整既有读点行号;测试新增三个回归并扩展真实来源存储 fixture。没有新 CLI、UI、持久状态、可选能力或默认关闭的权限承诺。

修改前 docs/reference/project-coordination.md,固定版本 1d5284077b97ad77a0c173761c11690a7d039ea4 的 Current local product path 是独立验收依据:结果返回原会话,分离来源存储由可信宿主冻结,恢复依赖精确提交的来源证据,重启去重,并保留来源授权和生命周期。当前验证满足这次有界增量;未据此宣称整个后续恢复 RFC、安装现场或全部产品旅程完成。

关键代码讲解

  • loopx/control_plane/collaboration/source_chat_observation.py:14 的 _source_chat_root 保留绝对、非空 locator 验证和旧数据的协调根默认值,供观察器及 is_source_chat_host 共用。比较 actual store root 是文件系统来源观察,Python 归属合理;没有复写 TS 状态机或 grant 决策。
  • loopx/capabilities/manager_context/roundtrip.py:668 的 _belongs_to_chat_host 读取对应原 roundtrip 路由,排除 peer 路由并比较原 Chat 根。原 inbox JSON reader 已限定 dict 和大小;无效地址/读取错误被捕获后跳过,不产生错误宿主回执。
  • loopx/capabilities/manager_context/roundtrip.py:684 的 _drain_exact 以及后面的 legacy drain 均在锁、准入、发送与回执写入前调用过滤。仍由既有 startup 恢复旧分离存储的精确来源;授权撤回、closed source、Goal 重建、terminal 和外部发送不确定性继续走原校验。不能把路由地址当成发送授权,也不能重定向已冻结地址。

未来维护检查已应用小幅相关整理:把来源根解析留在一个现有 owner,两条 pump 复用同一过滤。两条 pump 的既有版本化准入/锁语义仍各自保留,避免为了这次修复引入广泛迁移或新的宿主状态。

对主干的风险

使用精确 head 的原生 checkout 环境独立验证,未继承作者测试数或之前的 verdict:

  • roundtrip/source-store 原生测试当前 73 passed,同基线原有选集 70 passed;把新三个回归测试放入基线原生代码均失败,当前版本三个均通过。
  • 五组相关协作原生测试 107 passed / 3 skipped;三个 skip 为现有 Win32 专用场景,本机 POSIX 未认证 Windows。覆盖 revoked/closed source、channel/receipt、Goal 重建、旧 route 缺失、private File/SQLite startup 恢复和 unknown provider attempt 不重发等负例。
  • 独立实际 File、SQLite、source-session 权威存储及 ChatSessionStore 往返:普通 handoff 冻结来源,真实 acknowledge/report,错误宿主零处理且状态字节不变,原宿主立即处理一次,重开 Chat store 后零重复。外部 transport 及 host scope fixture 是合成边界,不能据此认证真实 provider。
  • 独立同一 logical clock 的基线/当前反例:基线错误宿主写 retry_pending,原宿主同一时刻为零,越过重试窗口后送达一次;当前错误宿主无写入、原宿主立即送达一次、后续不重复。使用测试时间,不对现场结果等待或重发。
  • scoped Ruff、diff check、开发期 semantic advisory、全树 semantic vocabulary drift smoke、maintainability ratchet 全部通过。advisory 无新增支持语法的分类载体,不把空结果当完整语义证明;manifest 只更新既有位置。

语义与 CI 对齐

来源位置与 typed source/lifetime/send 语义复用既有 owner(reuse_existing),manifest 没有新增 contract;没有新闭合集或需要注册的新词汇。完整树语义 smoke 与 changed advisory 均已按源码执行,保留 advisory 的语法覆盖局限。当前能力配置 wait_for_ci=false,因此 CI 状态不作为此次批准的前置条件,也未查询 CI。

canary premerge --no-execute 仅用于风险清单预览,未把 preview 当执行成功;上述源码环境的原生检查、对照和真实存储路径组成这次评审的风险验证集。没有查询、轮询或等待 CI。实际部署、线上管家/Lark provider 和包装前端自动刷新保留未测;此次属于既有内部回传入口修复,不新增 caller-facing capability 或要求重复配置。回滚可撤销有界过滤,需保留既有回执与未知发送尝试;错误宿主重试延迟可能随之恢复。

我的整体评价

APPROVE,仅针对上述 head。long_horizon 改善来自消除外来宿主的重试累积及保留原会话去重;user_experience 改善来自原会话及时收到结果,无额外询问、账号切换或回传重放。完整 changed-path、失败路径、类型规则、domain neutrality、行为默认变化、guidance/obligation 与授权语义已检查,没有 substring denylist、新协议或额外授权。尚未验证的安装现场保持为部署者责任,不据此关闭更大的业务验收。本记录不执行合并或部署。

English verdict: APPROVE - head 8e5d4c9, base 1d52840. The original host is selected before either pump can lock, admit or mutate delivery state, using the existing frozen source-provenance owner. All three introduced regressions independently fail on the base and pass on this head; real File/SQLite/source-session handoff/return/restart paths pass. A separate clock-controlled counterfactual confirms the base eventually delivers after backoff, while the head immediately returns once with no foreign writes. Native focused tests: 73 passed; related collaboration: 107 passed and 3 existing Windows-only skips. Ruff, whitespace, full semantic inventory and maintainability ratchet pass. Existing source grants, GoalRef lifetime, legacy private-store recovery and unknown-provider no-resend remain. Production provider/deployment and packaged frontend refresh are unverified; CI was not consulted. No blocking finding, new authority or claim of formal GitHub self-approval.

@loopx-agent
loopx-agent merged commit dcecad9 into main Oct 9, 2026
7 of 9 checks passed
@loopx-agent
loopx-agent deleted the codex/manager-return-original-host branch October 9, 2026 19:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant