Skip to content

Commit 78f7ebc

Browse files
committed
docs(chat): state the one-executor rule where the channel contract lives
The manager evidence contract and both harness-selection mirrors now say that "exactly one segment per turn" is held (typed refusal on a second start, a discarded interrupted answer), and the M2-M3 row splits what has shipped from what has not. Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
1 parent 6b198d8 commit 78f7ebc

3 files changed

Lines changed: 8 additions & 3 deletions

File tree

‎docs/architecture/rfcs/harness-selection-dsh-pi-v0.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -401,7 +401,7 @@ operator-local path is recorded here.
401401
| Manager M2 — semantic continuation | Receiver resolution across registered running lanes; typed per-source coverage and freshness; a goal-level milestone the report can lead with instead of coverage disclaimers | Not implemented. Delegation resolves against the supplied delegation catalog, so a request whose owning lane is absent from that catalog is refused or routed to an unrelated lane; a provider read failure surfaces as raw error text instead of a typed source row; the manager context exposes deliveries and coverage but no goal-level milestone field to synthesize from |
402402
| Manager M3 — automatic complete exchange | A persisted answer that exceeds or violates the channel's outbound text contract is split and re-sent under a stable answer identity; an ambiguous or failed send is reconciled instead of replaced by a local notice; the return path survives a transport restart; rich markdown renders as structured text | Partially mitigated. `loopx/extensions/lark/outbound.py` fails closed on an over-limit or malformed payload, and the channel reports that local failure without re-delivering the persisted answer; one answer carries no idempotency identity, so a retry can duplicate it; structured rendering is not guaranteed |
403403
| Host modes M0-M1 | The channel's executor selection and its bounded one-segment execution | Selection is covered by PR #4446 and the Turn-side selection by PR #4443; bounded one-segment execution is covered by the Mode B acceptance above. The channel itself now reaches the managed host through the segment transport, so the managed host's own one-segment execution is reachable from the channel; what remains open is that the segment is not a session, so cross-turn host continuity is still not offered |
404-
| Host modes M2-M3 | Attached-host parity, typed unavailability, and mode-aware projection with no mode inference and no second executor | Not implemented for the channel; an external audience still degrades to `restricted`, and the channel projects neither its mode nor its session status |
404+
| Host modes M2-M3 | Attached-host parity, typed unavailability, and mode-aware projection with no mode inference and no second executor | Partly shipped: the channel's managed segment transport holds one executor per binding, refuses a second start with the typed `managed_host_chat_segment_in_flight`, and discards an interrupted segment's answer instead of letting it enter visible history. Still not implemented: attached-host parity, and an external audience still degrades to `restricted`, while the channel projects neither its mode nor its session status |
405405

406406
Two boundaries stay fixed across all five rows. The channel remains an entry point
407407
and projection of one manager Session: it owns no profile, no permission state, no

‎docs/architecture/rfcs/harness-selection-dsh-pi-v0.zh-CN.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -324,7 +324,7 @@ operator 凭据上,且管家通道自身不存在任何默认指向个人订
324324
| 管家 M2 — 语义续接 | 跨所有已注册运行中 lane 的接收者解析;按来源的 typed 覆盖与新鲜度;报告可以先用目标级里程碑开头,而不是先给覆盖免责声明 | 未实现。委托只按传入的委托目录解析,因此拥有该事项的 lane 不在目录中时会被拒绝或投给无关 lane;provider 读取失败以原始错误文本出现在回答里,而不是 typed 来源行;管家上下文只提供交付与覆盖,没有可综合的目标级里程碑字段 |
325325
| 管家 M3 — 自动完成一次交流 | 超出或违反通道出站文本契约的已保存回答,按稳定答案身份分片重发;含糊或失败的发送要协调而不是用本地提示替代;回传路径要能跨传输重启存活;富文本要渲染成结构化文本 | 部分缓解。`loopx/extensions/lark/outbound.py` 在超限或载荷不合法时 fail closed,通道只回报这个本地失败、不重新投递已保存的回答;一条回答没有幂等身份,重试可能重复发送;结构化渲染没有保证 |
326326
| 宿主模式 M0-M1 | 通道的执行器选型与其有界单段执行 | 选型由 PR #4446 覆盖,Turn 侧选型由 PR #4443 覆盖;有界单段执行由上面的 Mode B 验收覆盖。通道本身现在经单段传输抵达托管宿主,因此托管宿主自己的单段执行已可从通道抵达;仍未提供的是跨 turn 宿主连续性——片段不是会话 |
327-
| 宿主模式 M2-M3 | attached-host 对齐、typed 不可用,以及不做模式推断、不引入第二执行器的模式感知投影 | 通道尚未实现;外部受众仍降级为 `restricted`,通道既不投影模式也不投影会话状态 |
327+
| 宿主模式 M2-M3 | attached-host 对齐、typed 不可用,以及不做模式推断、不引入第二执行器的模式感知投影 | 部分已实现:通道的托管段传输为每个绑定只保留一个执行器,第二次启动以 typed `managed_host_chat_segment_in_flight` 拒绝,被中断段的回答会被丢弃而不会进入可见历史。仍未实现:attached-host 对齐;外部受众仍降级为 `restricted`,通道既不投影模式也不投影会话状态 |
328328

329329
五行的两条边界固定不变:通道始终是同一个 manager Session 的入口与投影,不拥有
330330
profile、权限状态、第二执行器或工作权威,因此更丰富的回答契约不得扩大通道可读或

‎docs/reference/protocols/manager-evidence-and-continuity-v0.md‎

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -121,7 +121,12 @@ execution profile, with the channel's bounded visible history as input. That
121121
transport deliberately claims no partial streaming, no cross-turn host session
122122
and no tool authority: LoopX pins `DSH_PERMISSION_MODE=read-only` for those
123123
segments, so dsh refuses a write or shell action itself instead of trusting the
124-
channel prompt. A segment that cannot run (missing credential or missing runtime)
124+
channel prompt. "Exactly one" is held, not assumed: a segment is the binding's
125+
single executor until its thread exits, so a start while one is still running is
126+
refused with the typed `managed_host_chat_segment_in_flight` instead of quietly
127+
running a second executor, and an answer that arrives for an interrupted turn is
128+
discarded rather than folded into the visible history the next segment reads. A
129+
segment that cannot run (missing credential or missing runtime)
125130
makes the endpoint unavailable in `channel_binding` with the typed reason the
126131
governed Turn surface already publishes, and a session request for that endpoint
127132
fails as a typed host-tool gate with the next step instead of an unknown-endpoint

0 commit comments

Comments
 (0)