Repository navigation
fix(chat): keep manager return delivery on the original host - #6047
Conversation
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: actor_kind=model_agent; model=gpt-6.1-sol; provider=OpenAI; declaration_source=runtime_reported; reasoning_effort=xhigh.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
评审对象:#6047,精确 head 8e5d4c90374d3e93deab75b76ae6024ebf313b46,基线 1d5284077b97ad77a0c173761c11690a7d039ea4。独立核验后未发现阻塞问题,结论 APPROVE。同账号是作者,本记录使用 COMMENTED 自评批准结论,不能称为 GitHub 正式自批准。
动机
在原 Chat 会话等待委托结果、同时运行多个 Chat 宿主的用户。 此前共用协调队列的错误宿主会把本不属于它的回传写成重试,原宿主同一时刻无法送达;现在错误宿主先跳过,原宿主立即处理原会话的结果。 独立基线对照重现了延迟及重试后恢复;当前版本在 File、SQLite 与 source-session 的真实存储上保持外来宿主无写入、原会话立即送达和重启去重。 本次修复宿主分流,不扩大来源授权、Goal 生命周期或 provider 权限;不部署服务,也不宣称生产管家/Lark 回传和全部协作验收完成。 实际安装、线上管家/Lark provider 与包装前端自动刷新未独立验证;此次不把本地存储往返当生产送达。
基线反例还明确证明:旧代码并非永久阻断,原宿主在重试窗口后能送达。因此当前修复的是错误宿主引入的延迟和错误观察,不把已经送达的旧实例算作新版本的恢复产物,也不重发任何已验证结果。
改动思路
宿主归属由已有冻结来源存储位置推导,复用现有来源观察 owner,并在两条 pump 的锁、准入与回执写入前筛选;授权和生命周期继续由原 typed owner 决定。 当前 PR 交付可独立复现的来源宿主分流和原会话继续送达;实际安装后的现场回传资格仍由部署者验证。 增大超时保留错误状态写入,换 consumer 或账号改变用户目标,新宿主登记系统增加重复知识。复用冻结来源位置并在两条 pump 的所有效果之前过滤,正好解决可复现的原因。Path 相等仅选择负责处理的宿主;实际来源授权、GoalRef 生命周期、外部发送许可和 unknown-attempt 验证仍在原 typed owner,不能由这次筛选推导权限。
具体改动
全量四文件 +93/-9:返回模块增加来源宿主过滤;现有来源观察模块提取共同路径解析;registry I/O manifest 只调整既有读点行号;测试新增三个回归并扩展真实来源存储 fixture。没有新 CLI、UI、持久状态、可选能力或默认关闭的权限承诺。
修改前 docs/reference/project-coordination.md,固定版本 1d5284077b97ad77a0c173761c11690a7d039ea4 的 Current local product path 是独立验收依据:结果返回原会话,分离来源存储由可信宿主冻结,恢复依赖精确提交的来源证据,重启去重,并保留来源授权和生命周期。当前验证满足这次有界增量;未据此宣称整个后续恢复 RFC、安装现场或全部产品旅程完成。
关键代码讲解
loopx/control_plane/collaboration/source_chat_observation.py:14的_source_chat_root保留绝对、非空 locator 验证和旧数据的协调根默认值,供观察器及is_source_chat_host共用。比较 actual store root 是文件系统来源观察,Python 归属合理;没有复写 TS 状态机或 grant 决策。loopx/capabilities/manager_context/roundtrip.py:668的_belongs_to_chat_host读取对应原 roundtrip 路由,排除 peer 路由并比较原 Chat 根。原 inbox JSON reader 已限定 dict 和大小;无效地址/读取错误被捕获后跳过,不产生错误宿主回执。loopx/capabilities/manager_context/roundtrip.py:684的_drain_exact以及后面的 legacydrain均在锁、准入、发送与回执写入前调用过滤。仍由既有 startup 恢复旧分离存储的精确来源;授权撤回、closed source、Goal 重建、terminal 和外部发送不确定性继续走原校验。不能把路由地址当成发送授权,也不能重定向已冻结地址。
未来维护检查已应用小幅相关整理:把来源根解析留在一个现有 owner,两条 pump 复用同一过滤。两条 pump 的既有版本化准入/锁语义仍各自保留,避免为了这次修复引入广泛迁移或新的宿主状态。
对主干的风险
使用精确 head 的原生 checkout 环境独立验证,未继承作者测试数或之前的 verdict:
- roundtrip/source-store 原生测试当前 73 passed,同基线原有选集 70 passed;把新三个回归测试放入基线原生代码均失败,当前版本三个均通过。
- 五组相关协作原生测试 107 passed / 3 skipped;三个 skip 为现有 Win32 专用场景,本机 POSIX 未认证 Windows。覆盖 revoked/closed source、channel/receipt、Goal 重建、旧 route 缺失、private File/SQLite startup 恢复和 unknown provider attempt 不重发等负例。
- 独立实际 File、SQLite、source-session 权威存储及 ChatSessionStore 往返:普通 handoff 冻结来源,真实 acknowledge/report,错误宿主零处理且状态字节不变,原宿主立即处理一次,重开 Chat store 后零重复。外部 transport 及 host scope fixture 是合成边界,不能据此认证真实 provider。
- 独立同一 logical clock 的基线/当前反例:基线错误宿主写 retry_pending,原宿主同一时刻为零,越过重试窗口后送达一次;当前错误宿主无写入、原宿主立即送达一次、后续不重复。使用测试时间,不对现场结果等待或重发。
- scoped Ruff、diff check、开发期 semantic advisory、全树 semantic vocabulary drift smoke、maintainability ratchet 全部通过。advisory 无新增支持语法的分类载体,不把空结果当完整语义证明;manifest 只更新既有位置。
语义与 CI 对齐
来源位置与 typed source/lifetime/send 语义复用既有 owner(reuse_existing),manifest 没有新增 contract;没有新闭合集或需要注册的新词汇。完整树语义 smoke 与 changed advisory 均已按源码执行,保留 advisory 的语法覆盖局限。当前能力配置 wait_for_ci=false,因此 CI 状态不作为此次批准的前置条件,也未查询 CI。
canary premerge --no-execute 仅用于风险清单预览,未把 preview 当执行成功;上述源码环境的原生检查、对照和真实存储路径组成这次评审的风险验证集。没有查询、轮询或等待 CI。实际部署、线上管家/Lark provider 和包装前端自动刷新保留未测;此次属于既有内部回传入口修复,不新增 caller-facing capability 或要求重复配置。回滚可撤销有界过滤,需保留既有回执与未知发送尝试;错误宿主重试延迟可能随之恢复。
我的整体评价
APPROVE,仅针对上述 head。long_horizon 改善来自消除外来宿主的重试累积及保留原会话去重;user_experience 改善来自原会话及时收到结果,无额外询问、账号切换或回传重放。完整 changed-path、失败路径、类型规则、domain neutrality、行为默认变化、guidance/obligation 与授权语义已检查,没有 substring denylist、新协议或额外授权。尚未验证的安装现场保持为部署者责任,不据此关闭更大的业务验收。本记录不执行合并或部署。
English verdict: APPROVE - head 8e5d4c9, base 1d52840. The original host is selected before either pump can lock, admit or mutate delivery state, using the existing frozen source-provenance owner. All three introduced regressions independently fail on the base and pass on this head; real File/SQLite/source-session handoff/return/restart paths pass. A separate clock-controlled counterfactual confirms the base eventually delivers after backoff, while the head immediately returns once with no foreign writes. Native focused tests: 73 passed; related collaboration: 107 passed and 3 existing Windows-only skips. Ruff, whitespace, full semantic inventory and maintainability ratchet pass. Existing source grants, GoalRef lifetime, legacy private-store recovery and unknown-provider no-resend remain. Production provider/deployment and packaged frontend refresh are unverified; CI was not consulted. No blocking finding, new authority or claim of formal GitHub self-approval.
When several Chat hosts share a coordination runtime, a host without the original conversation can consume its manager return and write
retry_pending. The resulting backoff delays the host that can actually deliver it.Both return paths now check the existing host-frozen source-store provenance before acquiring delivery locks, admitting a return, or changing its receipt. Legacy routes keep their coordination-root default and the existing startup recovery for separate Chat stores. Source grants, lifetime admission, provider verification and idempotent transcript delivery remain with their existing owners.
Validation: reproduced three failing cases before the fix; 73 roundtrip/source-store tests and 198 related collaboration tests pass (3 existing skips). The regressions cover a separate source store, a foreign host leaving the receipt untouched, immediate delivery on the source host, restart deduplication, and skipping exact admission on a foreign host. Ruff and diff checks pass. The generated registry I/O census changes only the existing call's line number; the semantic check passes after regeneration. Native premerge passes after regeneration, with no failures or manual holds; the original failed census check is retained in local evidence. An existing live return later recovered on the old installation and was read back once with a verified delivery receipt. That does not establish the deployed fix; post-review validation must distinguish recovery from deployment and must not resend that result.