From e8a0e4fb67be96890c7564b1d4f1115263d44899 Mon Sep 17 00:00:00 2001 From: huangruiteng <14976749+huangruiteng@users.noreply.github.com> Date: Wed, 16 Sep 2026 20:55:57 +0800 Subject: [PATCH] docs(rfc): record the live remote-source coverage acceptance The steward-readiness table recorded that a provider read failure surfaced as raw error text instead of a typed source row. That changed with the typed remote failure causes, and this records the behaviour as accepted from a live manager-channel read on 2026-09-16 at release `20260916T123949Z` (serving revision `55ebbc6b7`, executor `dsh`, profile `deepseek-v4-flash@high`): - the answer named the one declared remote source it read and kept that read's freshness visible; - it stated its evidence window and the bounds it applied; - it listed the remote rows it included; - it said that hosts it did not read are outside coverage instead of presenting them as having made no progress. The recorded half is the typed per-source coverage and freshness the table asked for; receiver resolution across registered running lanes and a goal-level milestone stay open, and the failure half still needs an unreadable source to exercise, which is why this is a documented live procedure rather than a CI job. English and Chinese stay in step, and no transcript, audience identity, dated incident or operator-local path is recorded. Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com> --- .../rfcs/harness-selection-dsh-pi-v0.md | 26 +++++++++++++++++++ .../rfcs/harness-selection-dsh-pi-v0.zh-CN.md | 18 +++++++++++++ 2 files changed, 44 insertions(+) diff --git a/docs/architecture/rfcs/harness-selection-dsh-pi-v0.md b/docs/architecture/rfcs/harness-selection-dsh-pi-v0.md index 19caa1d29b..ef5ee95768 100644 --- a/docs/architecture/rfcs/harness-selection-dsh-pi-v0.md +++ b/docs/architecture/rfcs/harness-selection-dsh-pi-v0.md @@ -663,6 +663,32 @@ operator-local path is recorded here. | Host modes M0-M1 | The channel's executor selection and its bounded one-segment execution | Selection is covered by PR #4446 and the Turn-side selection by PR #4443; bounded one-segment execution is covered by the Mode B acceptance above. The channel itself now reaches the managed host through the segment transport, so the managed host's own one-segment execution is reachable from the channel; what remains open is that the segment is not a session, so cross-turn host continuity is still not offered | | Host modes M2-M3 | Attached-host parity, typed unavailability, and mode-aware projection with no mode inference and no second executor | Partly shipped: the channel's managed segment transport holds one executor per binding, refuses a second start with the typed `managed_host_chat_segment_in_flight`, and discards an interrupted segment's answer instead of letting it enter visible history. The channel readback also carries the mode-aware projection: it quotes the Session's own `session_mode` and `status`, reads a channel with no Session as `unbound`, and names a mode outside the closed set as `unrecognized` instead of deriving a mode from the executor it resolved. Still not implemented: attached-host parity, and an external audience still degrades to `restricted` | +### Remote-source coverage acceptance (2026-09-16) + +The M2 row above recorded that "a provider read failure surfaces as raw error +text instead of a typed source row". Two shipped changes moved that, and the +behaviour is now accepted from a live channel read rather than inferred from the +code: + +- a declared remote source that cannot be read reports a typed cause together + with the repair that clears it (an authorization that lapsed, a remote client + that is missing, a remote protocol that is unavailable, a host that cannot be + reached) instead of an untyped unavailability; +- a live manager-channel question that required its declared remote source was + accepted on 2026-09-16 at release `20260916T123949Z` (serving revision + `55ebbc6b7`, executor `dsh`, profile `deepseek-v4-flash@high`). The answer + named the one declared source it read and kept that read's freshness visible, + stated its evidence window and the bounds it applied, listed the remote rows it + included, and said that hosts it did not read are outside coverage instead of + presenting them as having made no progress. + +That is the typed per-source coverage and freshness property the M2 row asked +for. The other two halves of M2 - receiver resolution across registered running +lanes, and a goal-level milestone the report can lead with - stay open. The +acceptance is a live channel read: it needs a running channel, a real credential +and a declared source, so it is a recorded procedure rather than a CI job, and +the failure half needs an unreadable source to exercise. + Two boundaries stay fixed across all five rows. The channel remains an entry point and projection of one manager Session: it owns no profile, no permission state, no second executor and no work authority, so a richer answer contract must not widen diff --git a/docs/architecture/rfcs/harness-selection-dsh-pi-v0.zh-CN.md b/docs/architecture/rfcs/harness-selection-dsh-pi-v0.zh-CN.md index fc25da0855..36ebdd25d4 100644 --- a/docs/architecture/rfcs/harness-selection-dsh-pi-v0.zh-CN.md +++ b/docs/architecture/rfcs/harness-selection-dsh-pi-v0.zh-CN.md @@ -509,6 +509,24 @@ Todo 创建、quota 或 goal policy——复用预览点名的身份,不得扩 | 宿主模式 M0-M1 | 通道的执行器选型与其有界单段执行 | 选型由 PR #4446 覆盖,Turn 侧选型由 PR #4443 覆盖;有界单段执行由上面的 Mode B 验收覆盖。通道本身现在经单段传输抵达托管宿主,因此托管宿主自己的单段执行已可从通道抵达;仍未提供的是跨 turn 宿主连续性——片段不是会话 | | 宿主模式 M2-M3 | attached-host 对齐、typed 不可用,以及不做模式推断、不引入第二执行器的模式感知投影 | 部分已实现:通道的托管段传输为每个绑定只保留一个执行器,第二次启动以 typed `managed_host_chat_segment_in_flight` 拒绝,被中断段的回答会被丢弃而不会进入可见历史。通道读回也带上了模式感知投影:引用 Session 自己的 `session_mode` 与 `status`,没有 Session 的通道读作 `unbound`,闭集之外的模式命名为 `unrecognized`,而不是从已解析的执行器反推模式。仍未实现:attached-host 对齐;外部受众仍降级为 `restricted` | +### 远程来源覆盖的现场验收(2026-09-16) + +上面 M2 行记录过"provider 读取失败以原始错误文本出现在回答里,而不是 typed 来源行"。 +两项已交付改动改变了这一点,而且现在是从**一次真实通道读取**中验收,而不是从代码推断: + +- 声明了却读不到的远端来源,会回报 typed 原因与清除该原因的修复动作(授权过期、 + 远端客户端缺失、远端协议不可用、主机不可达),而不是一句没有类型的不可用; +- 2026-09-16 在一次真实管家通道提问上完成验收:该问题需要其已声明的远端来源。 + 发布版本 `20260916T123949Z`(服务中的修订 `55ebbc6b7`,执行器 `dsh`, + profile `deepseek-v4-flash@high`)。回答点名了它实际读到的那一个已声明来源并保留 + 该次读取的新鲜度,说明了自己的证据窗口与所施加的上限,列出纳入的远端行,并明确 + 表示没有读到的主机属于覆盖之外,而不是把它们呈现成"没有进展"。 + +这正是 M2 行要求的"按来源的 typed 覆盖与新鲜度"。M2 的另外两半——跨已注册运行中 +lane 的接收者解析、报告可先用的目标级里程碑——仍然开放。这次验收是一次真实通道读取: +它需要运行中的通道、真实凭据与已声明的来源,因此作为**记录下来的流程**而不是 CI 任务; +失败那一半还需要一个真正读不到的来源才能复现。 + 五行的两条边界固定不变:通道始终是同一个 manager Session 的入口与投影,不拥有 profile、权限状态、第二执行器或工作权威,因此更丰富的回答契约不得扩大通道可读或 可改的范围;本文也不提升任何一行的状态——M1-M4 接入里程碑与跨前端投影行仍归