Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
26 changes: 26 additions & 0 deletions docs/architecture/rfcs/harness-selection-dsh-pi-v0.md
Original file line number Diff line number Diff line change
Expand Up @@ -663,6 +663,32 @@ operator-local path is recorded here.
| Host modes M0-M1 | The channel's executor selection and its bounded one-segment execution | Selection is covered by PR #4446 and the Turn-side selection by PR #4443; bounded one-segment execution is covered by the Mode B acceptance above. The channel itself now reaches the managed host through the segment transport, so the managed host's own one-segment execution is reachable from the channel; what remains open is that the segment is not a session, so cross-turn host continuity is still not offered |
| Host modes M2-M3 | Attached-host parity, typed unavailability, and mode-aware projection with no mode inference and no second executor | Partly shipped: the channel's managed segment transport holds one executor per binding, refuses a second start with the typed `managed_host_chat_segment_in_flight`, and discards an interrupted segment's answer instead of letting it enter visible history. The channel readback also carries the mode-aware projection: it quotes the Session's own `session_mode` and `status`, reads a channel with no Session as `unbound`, and names a mode outside the closed set as `unrecognized` instead of deriving a mode from the executor it resolved. Still not implemented: attached-host parity, and an external audience still degrades to `restricted` |

### Remote-source coverage acceptance (2026-09-16)

The M2 row above recorded that "a provider read failure surfaces as raw error
text instead of a typed source row". Two shipped changes moved that, and the
behaviour is now accepted from a live channel read rather than inferred from the
code:

- a declared remote source that cannot be read reports a typed cause together
with the repair that clears it (an authorization that lapsed, a remote client
that is missing, a remote protocol that is unavailable, a host that cannot be
reached) instead of an untyped unavailability;
- a live manager-channel question that required its declared remote source was
accepted on 2026-09-16 at release `20260916T123949Z` (serving revision
`55ebbc6b7`, executor `dsh`, profile `deepseek-v4-flash@high`). The answer
named the one declared source it read and kept that read's freshness visible,
stated its evidence window and the bounds it applied, listed the remote rows it
included, and said that hosts it did not read are outside coverage instead of
presenting them as having made no progress.

That is the typed per-source coverage and freshness property the M2 row asked
for. The other two halves of M2 - receiver resolution across registered running
lanes, and a goal-level milestone the report can lead with - stay open. The
acceptance is a live channel read: it needs a running channel, a real credential
and a declared source, so it is a recorded procedure rather than a CI job, and
the failure half needs an unreadable source to exercise.

Two boundaries stay fixed across all five rows. The channel remains an entry point
and projection of one manager Session: it owns no profile, no permission state, no
second executor and no work authority, so a richer answer contract must not widen
Expand Down
18 changes: 18 additions & 0 deletions docs/architecture/rfcs/harness-selection-dsh-pi-v0.zh-CN.md
Original file line number Diff line number Diff line change
Expand Up @@ -509,6 +509,24 @@ Todo 创建、quota 或 goal policy——复用预览点名的身份,不得扩
| 宿主模式 M0-M1 | 通道的执行器选型与其有界单段执行 | 选型由 PR #4446 覆盖,Turn 侧选型由 PR #4443 覆盖;有界单段执行由上面的 Mode B 验收覆盖。通道本身现在经单段传输抵达托管宿主,因此托管宿主自己的单段执行已可从通道抵达;仍未提供的是跨 turn 宿主连续性——片段不是会话 |
| 宿主模式 M2-M3 | attached-host 对齐、typed 不可用,以及不做模式推断、不引入第二执行器的模式感知投影 | 部分已实现:通道的托管段传输为每个绑定只保留一个执行器,第二次启动以 typed `managed_host_chat_segment_in_flight` 拒绝,被中断段的回答会被丢弃而不会进入可见历史。通道读回也带上了模式感知投影:引用 Session 自己的 `session_mode` 与 `status`,没有 Session 的通道读作 `unbound`,闭集之外的模式命名为 `unrecognized`,而不是从已解析的执行器反推模式。仍未实现:attached-host 对齐;外部受众仍降级为 `restricted` |

### 远程来源覆盖的现场验收(2026-09-16)

上面 M2 行记录过"provider 读取失败以原始错误文本出现在回答里,而不是 typed 来源行"。
两项已交付改动改变了这一点,而且现在是从**一次真实通道读取**中验收,而不是从代码推断:

- 声明了却读不到的远端来源,会回报 typed 原因与清除该原因的修复动作(授权过期、
远端客户端缺失、远端协议不可用、主机不可达),而不是一句没有类型的不可用;
- 2026-09-16 在一次真实管家通道提问上完成验收:该问题需要其已声明的远端来源。
发布版本 `20260916T123949Z`(服务中的修订 `55ebbc6b7`,执行器 `dsh`,
profile `deepseek-v4-flash@high`)。回答点名了它实际读到的那一个已声明来源并保留
该次读取的新鲜度,说明了自己的证据窗口与所施加的上限,列出纳入的远端行,并明确
表示没有读到的主机属于覆盖之外,而不是把它们呈现成"没有进展"。

这正是 M2 行要求的"按来源的 typed 覆盖与新鲜度"。M2 的另外两半——跨已注册运行中
lane 的接收者解析、报告可先用的目标级里程碑——仍然开放。这次验收是一次真实通道读取:
它需要运行中的通道、真实凭据与已声明的来源,因此作为**记录下来的流程**而不是 CI 任务;
失败那一半还需要一个真正读不到的来源才能复现。

五行的两条边界固定不变:通道始终是同一个 manager Session 的入口与投影,不拥有
profile、权限状态、第二执行器或工作权威,因此更丰富的回答契约不得扩大通道可读或
可改的范围;本文也不提升任何一行的状态——M1-M4 接入里程碑与跨前端投影行仍归
Expand Down