Skip to content

Commit ce1252b

Browse files
authored
docs: establish the LoopX overall product and delivery roadmap (#4570)
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com> Co-authored-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
1 parent 0aa6179 commit ce1252b

22 files changed

Lines changed: 877 additions & 408 deletions

‎docs/architecture/rfcs/README.md‎

Lines changed: 26 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -46,6 +46,18 @@ This index was last audited against `main` on **2026-09-04**. Update an entry
4646
whenever its RFC status, promoted behavior, or meaningful delivery boundary
4747
changes.
4848

49+
## Overall Product and Delivery Roadmap
50+
51+
- [LoopX Overall Roadmap v0](loopx-overall-roadmap-v0.md)
52+
([中文版](loopx-overall-roadmap-v0.zh-CN.md))
53+
- **RFC status:** Draft portfolio roadmap.
54+
- **Delivery on `main`:** Planning and audit evidence, not runtime promotion.
55+
- **Current boundary:** Maps all 30 pre-existing primary RFCs and important
56+
non-RFC domains into 13 streams, G0–G5 product milestones and R1–R7 core
57+
execution cards. Covers product, multi-LoopX-Agent collaboration/handoff,
58+
kernel, hosts, memory, cost, security, operations, research, releases,
59+
community and adoption. Domain contracts retain their authority gates.
60+
4961
## Control-Plane Kernel, State, And Migration
5062

5163
- [Human-confirmed domain operations v0](human-confirmed-domain-operations-v0.md)
@@ -95,8 +107,10 @@ changes.
95107
default-off local shadow/cutover foundations are on `main`
96108
([#3529](https://github.com/huangruiteng/loopx/pull/3529),
97109
[#3669](https://github.com/huangruiteng/loopx/pull/3669),
98-
[#3798](https://github.com/huangruiteng/loopx/pull/3798)). No provider-first
99-
runtime promotion or remote shared-authority service has shipped.
110+
[#3798](https://github.com/huangruiteng/loopx/pull/3798)). In-process PostgreSQL
111+
service admission and identity rotation also exist;
112+
deployed authenticated remote service and provider promotion remain distinct
113+
qualification gates.
100114
- [Shared Goal Alignment and Governed Amendment Protocol v0](shared-goal-alignment-and-governed-amendment-v0.md)
101115
([中文版](shared-goal-alignment-and-governed-amendment-v0.zh-CN.md))
102116
- **RFC status:** Draft, under maintainer review.
@@ -173,15 +187,17 @@ changes.
173187
- [Capable Agent Manager and Semantic Work Handoff v0](capable-manager-semantic-handoff-v0.md)
174188
([中文版](capable-manager-semantic-handoff-v0.zh-CN.md))
175189
- **RFC status:** Draft, under maintainer review.
176-
- **Delivery on `main`:** Proposal; existing manager/inbox foundations are reused.
190+
- **Delivery on `main`:** Partial; private runtime profile, executor settings,
191+
team-plan confirmation and initial Todo materialization shipped.
177192
- **Current boundary:** Proposes ordinary host-tool autonomy, persistent scoped
178193
conversations, long-horizon semantic continuation and automatic result delivery.
179194
Includes an official Grok Bot study distinguishing availability from goal
180195
continuation; M0–M4 and A1–A20 define delivery and acceptance, with explicit
181196
alignment, shared-authority and TS migration dependencies.
182197
Cross-session restoration, execution takeover and automatic return are specified
183198
separately, reusing #4094 with optional Obelisk gap recall under its own scope.
184-
Runtime-profile promotion and generic handoff migration have not shipped.
199+
Full runtime-profile qualification and generic handoff migration remain open.
200+
185201

186202
- [Explicit Todo Continuation — Stage A](cross-session-memory-substrate-v0.md)
187203
([中文版](cross-session-memory-substrate-v0.zh-CN.md))
@@ -296,10 +312,12 @@ changes.
296312
- [Long-Running Agent Reliability Diagnostics and Governed Delivery v0](long-running-agent-reliability-diagnostics-governed-delivery-v0.md)
297313
([中文版](long-running-agent-reliability-diagnostics-governed-delivery-v0.zh-CN.md))
298314
- **RFC status:** Draft, product direction and delivery contract.
299-
- **Delivery on `main`:** Direction only.
300-
- **Current boundary:** The observer-first adoption path, matched benchmark
301-
qualification, and governed delivery package are proposed; no unified
302-
product contract has been promoted.
315+
- **Delivery on `main`:** Default-off L1 diagnostic prototype and first DSH
316+
event-source adapter implemented.
317+
- **Current boundary:** The capability-owned README records the prototype;
318+
C0 adapter fidelity, C1 non-interference and measured overhead remain
319+
required before P0 exit. Broader governed delivery and commercial adoption
320+
remain proposals.
303321

304322
RFCs must not contain internal conversations, private links, local filesystem
305323
paths, credentials, raw transcripts, or non-public organizational context.

‎docs/architecture/rfcs/agent-session-execution-modes-v0.md‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -454,6 +454,12 @@ at least one real-host row: a live process, a real bind, and a real restart.
454454
- **Recovery.** An interrupted executor turn is reconciled before retry. A
455455
validated result is journaled before lifecycle writeback.
456456

457+
### Long-horizon managed route (2026-09-16)
458+
459+
[Roadmap](loopx-overall-roadmap-v0.md) R2 first qualifies a steward and 2–3 actual managed workers across Turns; R6 qualifies local/cloud execution on one authority, then R7 expands active scale. M1–M4 here retain host admission ownership. Team-plan `ready` cannot replace binding, qualification, claim/lease or actual process readback.
460+
461+
DSH steward Chat is currently single-segment, read-only and without cross-turn host sessions; `turn run-once` is a separate bounded execution path. The next slice proves successor wake, cancellation/stop, crash recovery and returning stale-executor fences with packaged frontend/CLI/Lark readback. An executor name, one segment or multiple registrations cannot establish continuous managed execution. Disconnection never switches attached hosts to managed, and unqualified hosts retain their existing boundary.
462+
457463
## 12. Normative delivery plan
458464

459465
| Milestone | Shipped behavior | Entry gate | Exit evidence | Rollback |

‎docs/architecture/rfcs/agent-session-execution-modes-v0.zh-CN.md‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -364,6 +364,12 @@ claim 与完成回执,以及"只有经过验证的回写才推进工作"这一
364364
- **恢复。** 被中断的执行器 turn 在重试前先被协调。经过验证的结果在生命周期回写之前
365365
先被记录。
366366

367+
### 长程 managed 执行路线(2026-09-16)
368+
369+
[统一路线](loopx-overall-roadmap-v0.zh-CN.md) R2 先验一个管家与 2–3 个真实 managed worker 的跨 Turn 闭环;R6 再验本地/云端同 authority,R7 才扩大活跃规模。本 RFC M1–M4 继续拥有宿主接入,不用团队计划的 `ready` 取代 binding、资格、claim/lease 或实际进程读回。
370+
371+
目前 DSH 管家 Chat 是单段、只读、无跨 turn 宿主会话;`turn run-once` 是另一条有界执行路径。下一切片要证明 successor wake、取消/停止、崩溃恢复及旧执行器返回 fence,经 packaged frontend/CLI/Lark 回读真实状态。不能仅增加一个 executor 名称、启动一个片段或绑定若干 Agent 就声称持续 managed 模式完成。attached host 不因掉线而改为 managed,未验收宿主保持原资格边界。
372+
367373
## 12. 规范性交付计划
368374

369375
| 里程碑 | 交付行为 | 进入门槛 | 退出证据 | 回滚 |

‎docs/architecture/rfcs/capable-manager-semantic-handoff-v0.md‎

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
# RFC: Capable Agent Manager and Semantic Work Handoff (v0)
22

33
- **RFC status:** Draft, under maintainer review
4-
- **Delivery maturity:** Proposal; existing foundations are identified in Section 4
4+
- **Delivery maturity:** Partial; private runtime profile, team-plan confirmation and Todo materialization shipped; complete M1–M4 remain unqualified.
55
- **Authors / owners:** LoopX maintainers; manager engineering owner
66
- **Created / last normative revision:** 2026-09-13 / 2026-09-15
77
- **Implementation baseline:** `7eb4b7bb1661bd5eff63a8725a33169792d5964b`
@@ -61,6 +61,12 @@ Include global manager conversations, host-native investigation, ordinary author
6161

6262
Do not build a replacement agent runtime, a second scheduler, an external-agent marketplace, a new repository API, a universal workflow DSL or a duplicate task database. A substantial refactor of the current manager, collaboration and adapter boundaries is explicitly in scope; conserving current code volume or module names is not an acceptance goal. Do not require OpenViking, a shared online database or A2A to make local handoffs correct. Do not copy private reasoning traces or complete historical transcripts into every request. Complex financial and other domain effects remain owned by their capabilities and execution adapters.
6363

64+
### Current cross-RFC route (2026-09-16)
65+
66+
At `43d362532`, the private `manager_runtime` profile, steward executor configuration and team preview→frontend confirmation→initial Todo materialization have implementations. #4547/#4548/#4552 supply confirmation UI, bundle and browser fixture; they do not prove worker execution. DSH Chat remains a bounded read-only segment without cross-turn host sessions and cannot borrow Codex `trusted_owner` qualification.
67+
68+
The [overall roadmap](loopx-overall-roadmap-v0.md) records verified F1–F7 and R1–R7. Repair R1 commitment preservation, stale basis and recovery first, then qualify R2 small teams; M2/M3 converge through R3, and M4 requires real user journeys. Section 4 retains its older baseline as migration input, not an override of this checkpoint. Partial merges do not complete M1–M4. Parallel joins, pipeline dependencies, peer help/review, execution responsibility continuation and cross-host collaboration between long-running LoopX Agents follow the roadmap Section 5 matrix. R2 requires real inter-Agent handoff; M2/M3 cannot reduce to steward broadcasts or one-turn forwarding.
69+
6470
## 4. Current-system contract: audited facts
6571

6672
The baseline already has substantial reusable machinery:
@@ -501,7 +507,7 @@ If this program changes a provider, retention or authority-source profile, its a
501507

502508
### 11.2 Execution order and integration receipts
503509

504-
1. **Start M1; finish baseline reconciliation in that PR.** Record the exact source head and actual runtime/entrypoint call sites. Fix the owner-private profile and existing readback/feedback. Run A1–A3/A12. Do not deliver a standalone inventory framework.
510+
1. **Complete and qualify M1 through R1/R2 without rebuilding shipped profiles/entrypoints.** Record the exact source head and actual runtime/entrypoint call sites. Fix the owner-private profile and existing readback/feedback. Run A1–A3/A12. Do not deliver a standalone inventory framework.
505511
2. **Replace one complete M2 request transaction, then attach receivers.** Begin from `manager_context` request/tracking/return producers and both real consumers, including the shipped #4094 CLI continuation adapter (§5.13). Publish the before/after ownership map, migration mapping and the migration economics review artifact (§5.12). Preserve accepted work state through existing commands; qualify crash-between-commits and legacy/promoted sources before widening producer rollout. Use existing alignment source-basis reads, not a copied classifier.
506512
3. **Close M3 automatic return and user visibility.** Independent reply recovery can ship in parallel with steps 1–2. Integrate the generic producer only after its receipt contract is stable; exercise A8–A10, A13–A16 and A17/A20 across the actual entrance/receiver/return paths. With the source session gone, verify the same committed result/outbox identity, reconnect recovery and audience isolation through packaged frontend, Lark and CLI readback.
507513
4. **Promote a named M4 cohort and remove the replaced paths.** Keep provider default, Goal-intent authority and capability qualifications explicit. Shared-amendment commit integration follows its upstream readiness; until then the UI says proposal/admission or unsupported commit, never “Goal changed.” Provider source migration follows the shared-authority program rather than this release.

‎docs/architecture/rfcs/capable-manager-semantic-handoff-v0.zh-CN.md‎

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
# RFC:强能力 Agent 管家与语义工作交接(v0)
22

33
- **RFC 状态:** Draft,待维护者审阅
4-
- **交付成熟度:** 提案;已有基础见第 4 节
4+
- **交付成熟度:** Partial;私人运行 profile、团队计划确认与 Todo 物化已交付,完整 M1–M4 未验收。
55
- **作者 / 责任人:** LoopX 维护者、管家工程负责人
66
- **创建 / 最近规范修订:** 2026-09-13 / 2026-09-15
77
- **实现基线:** `7eb4b7bb1661bd5eff63a8725a33169792d5964b`
@@ -61,6 +61,12 @@
6161

6262
不重造 Agent runtime、第二套调度器、外部 Agent 市场、新仓库 API、通用工作流 DSL 或任务数据库。明确允许对现有管家、协作和 adapter 边界大幅重构;保住现有代码体积或模块名字不是验收目标。本地交接正确性不依赖 OpenViking、在线共享数据库或 A2A。每个请求不携带私人推理轨迹和完整历史。复杂金融等垂域效果继续归各 capability 和执行 adapter。
6363

64+
### 跨 RFC 当前路线(2026-09-16)
65+
66+
在 `43d362532`,本 RFC 的私人 `manager_runtime` profile、管家执行器配置,以及团队计划预览→前端确认→首批 Todo 物化已有实现。#4547/#4548/#4552 提供确认 UI、打包产物及 browser fixture;它们不证明 worker 已运行。DSH Chat 仍是只读有界片段,无跨 turn 宿主会话,不能借用 Codex `trusted_owner` 的资格。
67+
68+
[整体路线总纲](loopx-overall-roadmap-v0.zh-CN.md) 记录已复核 F1–F7 与 R1–R7 执行卡。优先修 R1 承诺保留、stale basis 和恢复,再验 R2 小团队;M2/M3 按 R3 收敛,M4 需真实用户旅程。第 4 节的旧基线保留为迁移输入,不能覆盖本检查点;不因局部切片合并将 M1–M4 标为完成。 多个长程 LoopX Agent 的并行汇合、流水线依赖、peer 求助/复核、执行责任接续和跨 host 协作,统一按路线第 5 节协作矩阵验收;R2 必须包含真实 Agent 间 handoff,M2/M3 不能退化为管家广播或单轮转发。
69+
6470
## 4. 当前系统:已核对的基线事实
6571

6672
已有大量基础应该复用:
@@ -501,7 +507,7 @@ M1 不必等通用 handoff 重构。M3 独立的格式/投递修复可先用已
501507

502508
### 11.2 执行顺序与衔接回执
503509

504-
1. **启动 M1,在该 PR 内完成基线对齐。** 记录精确 source head、真实 runtime/入口 caller;修主人私人 profile 和已有读回/反馈;验 A1–A3/A12。不单独交付盘点框架。
510+
1. **按 R1/R2 补齐并验收 M1,不重建已交付 profile/入口。** 记录精确 source head、真实 runtime/入口 caller;修主人私人 profile 和已有读回/反馈;验 A1–A3/A12。不单独交付盘点框架。
505511
2. **替换一个完整 M2 请求事务,再接接收方。** 从 `manager_context` request/tracking/return producer 和两种真实消费者开始,提交前后 owner 图、迁移映射、migration economics 审阅工件(§5.12)。工作状态继续走已有命令;扩大 producer 上线前验提交间崩溃和 legacy/promoted source。复用 alignment source-basis 读取,不复制分类器。 显式纳入已交付 #4094 CLI 接续 adapter(§5.13)。
506512
3. **收口 M3 自动回传和用户可见性。** 独立正文恢复可与前两步并行;通用 producer 待回执契约稳定再接。沿真实入口/接收方/返回路径验 A8–A10、A13–A16、A17/A20;在来源 session 已消失时,通过 packaged frontend、飞书、CLI 读回核实同一已提交结果/outbox 身份、重连恢复和受众隔离。
507513
4. **晋级指定 M4 cohort,并删除被替换路径。** 明确 provider 默认、Goal-intent authority、capability 资格。共享 amendment commit 待上游就绪;此前 UI 只能说提案/准入或不支持提交,不能说“Goal 已修改”。provider source 迁移按 shared-authority 计划,不夹进本次发布。

‎docs/architecture/rfcs/desktop-execution-frontends-v0.md‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -768,6 +768,12 @@ trust binding fails closed.
768768
- Use synthetic provider fixtures for committed tests and make live provider
769769
tests explicit and opt-in.
770770

771+
### Team coordination product loop (2026-09-16)
772+
773+
#4547/#4548/#4552 delivered team-preview confirmation UI, packaged resources and a browser fixture; the confirmation entry is no longer unimplemented. Follow [roadmap](loopx-overall-roadmap-v0.md) R1 for semantically accurate partial/gap/stale readback, R2 for actual worker execution and R3 for automatic return/restart recovery. The confirmation fixture does not prove the complete Lark loop.
774+
775+
Frontend/Lark consume the same proposal, receipt and audience projection; confirmed plans cannot imply execution. Every implementation includes real packaged-frontend interaction and applicable Lark qualification, or explicitly names the untested surface. First-viewport/primary-CTA implementation changes still require concrete preview approval. This revision edits RFCs only, not UI.
776+
771777
## Delivery slices
772778

773779
### Slice A: Agent-scoped Lark connection

‎docs/architecture/rfcs/desktop-execution-frontends-v0.zh-CN.md‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -638,6 +638,12 @@ executor 精确版本、完成情况、延迟、动作数、人工介入、禁
638638
- 不把私有部署或协作上下文复制到公共 fixtures、截图、示例或文档中。
639639
- 已提交测试使用合成 provider fixtures,并把真实 provider 测试设为显式可选。
640640

641+
### 团队协调的产品闭环(2026-09-16)
642+
643+
#4547/#4548/#4552 已交付团队预览确认 UI、打包资源及 browser fixture,不再把确认入口列为未实现。按[统一路线](loopx-overall-roadmap-v0.zh-CN.md) R1 补语义一致的 partial/gap/stale 回读,R2 验 worker 实际执行,R3 验自动回报和重启恢复。现有确认 fixture 不能证明 Lark 端完整闭环。
644+
645+
前端/Lark 消费同一 proposal、receipt 和 audience projection;运行状态不能由计划已确认推断。每个实现批次含 packaged frontend 的实际交互和 Lark 适用路径验收,或明确说明未验收。涉及首屏/主 CTA 的实现继续先展示具体预览并获批准;本次仅更新 RFC,不修改 UI。
646+
641647
## 交付切片
642648

643649
### 切片 A:Agent 级 Lark 连接

0 commit comments

Comments
 (0)