Skip to content

[Task][RFC]: Qualify the effective manager runtime profile across sessions #5212

Description

@huangruiteng

Outcome / 目标

验收管家有效运行配置与会话一致性。One task tracks this RFC's delivery; keep implementation PRs and milestone evidence here instead of creating a parallel task tree.

Canonical design: RFC. Roadmap: S1/S4/S9 · manager M1, under #4574. Design acceptance is distinct from implementation, live qualification and promotion.

Current boundary

Source audit: main at ce3862e33 (2026-09-28). This is source/PR inspection, not a new test or live-qualification claim.

The machine-level restricted/trusted_owner configuration, controller integration and focused tests are already recorded as shipped. The RFC explicitly separates that implementation from deployment and full M1 qualification.

Work remaining

  • Verify the effective config, sandbox, prompt, workspace instructions and active upstream Session agree on the real supported endpoint.
  • Finish restart/profile-change/downgrade recovery and existing settings readback without adding a second configuration source.

Ownership and ongoing work

Reuse #4339 and current manager/App work; coordinate with #5187 settings consolidation. This RFC owns profile consistency, not general handoff, outbox or a new permission system.

Contribution route: implementation/integration overlaps active work. Start from the linked current owners/PRs and identify an unowned acceptance gap in a claim comment; do not begin a competing rewrite.

Acceptance

  • Default/invalid config remains restricted with actionable repair; unsupported endpoints do not pretend to enforce trusted_owner.
  • A material profile change rotates the upstream thread while preserving visible history; unrelated settings do not rotate it.
  • External audiences remain restricted absent the existing scoped grant; protected operations retain their own authorization. CLI and actual frontend expose the effective Session profile.
  • Reconcile the RFC's current delivery checkpoint and this issue with the integrated revision, commands, passed/failed/untested evidence and remaining gates. Close the accepted scope only; no claim that a merged PR alone completes the RFC.

Starting points and delivery boundary

Base: latest main. Reuse the existing typed owner and provider boundaries. Include affected CLI/frontend/Lark companions; verify real entrypoints and backend where changed. Preserve existing first-screen review and maintainer merge gates. Public artifacts contain only synthetic/public-safe evidence, no private operational state. This task does not authorize provider promotion, benchmark launches, release/deployment or unrelated protected effects.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions