Skip to content

fix(steward): commit team assignments atomically and simplify result recovery - #4633

Merged
huangruiteng merged 9 commits into
mainfrom
codex/steward-team-transaction-20260917
Sep 17, 2026
Merged

huangruiteng merged 9 commits into
mainfrom
codex/steward-team-transaction-20260917

Conversation

@huangruiteng

@huangruiteng huangruiteng commented Sep 17, 2026 •

Copy link
Copy Markdown
Collaborator

Goal And Delivered Outcome

R1 team confirmation currently writes each lane independently. Equal-text lanes can collapse into one Todo, and a lost response or later write failure strands the card after partial effects.

This change moves admission and whole-batch planning into the typed work-items owner. Each proposal/lane has a stable identity; all admitted tasks and their operation receipt commit together. Retrying the same operation recovers its historical result without recreating work that a receiver changed, completed or deleted. Chat preserves projection failures as recoverable failures. The packaged result card leads with assigned tasks and pending reasons, collapses the original plan, and removes the completed confirmation button. A failed or uncertain apply retries the original proposal instead of creating another one.

Base: main. Consolidates the useful behavior from #4592, #4598 and #4600; replaces #4602's per-lane recovery and #4604's unqualified readiness ladder. #4605's cross-host lease remains outside this transaction.

Scope And Continuation

The delivered slice is local assignment, commit recovery and product readback. Existing Todo admission, AuthorityStore CAS/receipts, legacy writer fences and projection outbox remain the owners; no new capability, provider or scheduler is introduced. Ordinary Todo create retains role/text deduplication.

Behavior changes: owner confirmation assigns registered peers without impersonating receivers as authors; an Agent-originated settlement cannot assign another peer. Quota/stop declarations remain advisory and explicit enforcement claims are rejected. Historical recovery uses team_plan_commit_recovered; old already-present receipts remain readable. Already-applied cards remain historical records. Older pre-transaction partial cards must be replanned against their existing tasks; this does not migrate their effects automatically.

Assignment does not establish receiver adoption, a lease, execution, dependency consumption or independent acceptance. R1–R4 retain those obligations, shared-intent acceptance and executor qualification. Ordinary already-authorized work does not acquire a universal second confirmation. Lark currently has a presentation-frame seam but no team-plan delivery/callback route; this PR does not claim that journey. These boundaries keep the storage repair independently verifiable and reversible.

Future-facing refactor applied: removed the Python preview/per-lane writer, reused the existing typed create planner and command receipt, and preserved the previous shipped bundle instead of intermediate local builds.

Validation

  • Tested revision: a4c69218937a99413d0d7bdc41fec82ff03b5666: 50 related Python tests and the real File/PostgreSQL team-plan suite (11/11). The complete packaged Personal Workspace suite (7 scenarios) and unchanged-bundle rebuild ran at 6680abcc; assets remain unchanged. Full backend suites ran at 4f177272; focused File/PostgreSQL tests ran at fd4ea85a. The typed control-plane implementation is unchanged; the final Chat correction reports historical recovery even when the original plan retains staffing gaps.
  • Run state: finished.
  • Input classes: synthetic, public_fixture.
Check kind Result Evidence / limitation
static passed TypeScript typecheck, changed Python ruff, configured mypy (22 files), diff hygiene and public-boundary scan.
unit / integration passed Full TypeScript suite on qualified Node 22.22.3: 1775 passed, 0 failed; optional external service case below. Earlier default-Node SQLite qualification failures were resolved by using the required runtime; capacity rehearsal contention passed on bounded-concurrency rerun.
real_entrypoint passed 50 final-head team-plan Python tests (plus the earlier broader 67-test pass), including actual Chat apply and fenced FileAuthorityStore projection failure/recovery, changed canonical state and equal-text lanes.
real_backend passed PostgreSQL 16 on an isolated disposable server: 105 store integration checks. Final team_plan.test.ts: 11 passed, no skips; real File/PostgreSQL concurrency, invalid final lane, failed commit, lost response, receiver edits/completion/deletion and declared capability/audience gaps.
real_entrypoint passed build:chat, smoke:team-plan-proposal, and complete smoke:personal-workspace-packaged (all 7 scenarios). Final-head browser covers compact results, original-plan expansion, completed-card action, injected post-write response loss and same-proposal retry without another durable write. The fixture retains the stored plan after apply.
regression_parity passed Baseline 9060ddc with the same browser fixture fails the new acceptance/gap readback expectations; candidate passes. The old per-lane implementation also fails the independent equal-text identity counterexample.
integration not_run External PostgreSQL service endpoint test (1 optional suite skip); unchanged network service transport is outside this slice. No live Lark or cross-host worker execution claimed.

Frontend / Visual Evidence

UI impact: changed confirmation/result card. Source data: synthetic. Before is the actual verbose card at 4f177272 immediately before this UI refinement; after is the validated compact card. Desktop result state shown; result and original plan are separated without changing surrounding navigation. The public task/assignee display is derived from the admitted preview and committed receipt.

Before After
Before After

Type / Area

Bug fix and refactor with disclosed behavior changes; control plane and dashboard. Final exact-diff qualification is valid (35 files; 0 blockers, 0 warnings, 1 advisory about remaining collaboration acceptance). Premerge passed all 19 selected checks with 0 failures on final head a4c692189. Exact-head self-review and the capability-owned merge-readiness gate govern the maintainer-authorized merge; configured review policy does not wait for remote CI.

Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
…ution

Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
…nt readback

Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
…tion

Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
@huangruiteng

Copy link
Copy Markdown
Collaborator Author

已核对最终提交 fd4ea85afd971f5a6b527ead1c1b07b05b90dd09。这次交付修复的是可恢复的任务分配事务,并提供完整的本地 Chat → 写入 → 产品读回路径。

  • 状态与效果:准入、整批计划、任务身份和历史恢复归 typed work-items 所有;复用现有 AuthorityStore CAS/command receipt。Python 负责 IO 适配,没有另一套逐条补写状态机。
  • 产品表达:结果先列出已分配任务与待安排原因,原计划折叠,完成后按钮变为查看结果。失败重试保持同一 proposal;打包浏览器模拟写入后响应丢失,确认重试不产生额外写入。
  • 权限与默认行为:仅 team.plan 使用 operation/lane 身份,普通 Todo create 继续 role/text 去重;普通动作的失败路径保持不变。owner 分配不冒充接收方作者;Agent 自身提交不能给其他 Agent 分派。quota/stop 明确是参考,未实现的 enforcement 声明被拒绝。
  • 验证:完整未变后端 1775 个 TS 用例通过、67 个 Python 用例通过;隔离 PostgreSQL 105 个集成用例通过;最终 team-plan 用例 11 个通过、0 跳过;前端构建、类型检查、打包交互和 canary 19/19 通过。可选外部 PostgreSQL service endpoint 用例未运行,未将其计为通过;远端 CI 尚排队。
  • 后续边界:R1–R4 的共享意图、接收方采纳、依赖消费、独立验收和结果返回尚未完成。本次分配不宣称 lease、执行或团队协作成立。相关重构已删除 Python 逐条 writer,未新增无调用方的 readiness 协议。

English: the local assignment/recovery slice is implemented and validated on this head. It remains subject to maintainer review/merge and remote CI; full receiver collaboration and cross-host execution are not claimed.

@huangruiteng
huangruiteng marked this pull request as ready for review September 17, 2026 07:58
…mparison

Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
@huangruiteng

Copy link
Copy Markdown
Collaborator Author

已修正 before 对照图:现在使用 4f177272 中精简前的实际卡片,不再使用更早的 main 截图。after 保持打包浏览器验证过的简洁卡片。两张图均固定引用最终提交 52c44017461ff7a4f825f8af2ec696ac10c4ddd4,已回读 GitHub 文件并确认内容一致。

该提交只更换 before PNG;最终质量凭证已重新核验,canary 19/19 通过、0 失败。前文代码检查证据仍适用于未改变的实现;远端 CI 尚排队,继续留待维护者合并。

English: corrected the before-image provenance and pinned both images to the final commit. Image readback and final premerge validation passed; no runtime changes in this commit.

Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
@huangruiteng

Copy link
Copy Markdown
Collaborator Author

已在 6680abcc142d311d1ba3e5b3c5c4dbd36c513366 修复 frontstage CI。

失败点是 Verify packaged Personal Workspace is current 中的 steward-journey:它仍等待旧团队计划标题、旧确认按钮和通用成功句,而产品已经改成精简的分配结果。

本次只更新现有浏览器验收:按动作类型和 Goal 定位提案,确认后检查已分配任务、待安排任务及原因,验证完成后确认按钮消失,并删除过期的“缺少结果展示”判定。未修改生产代码、超时或跳过条件。

验证:build:chat 后打包资产无变化;smoke:personal-workspace-packaged 全部 7 个场景通过;最终 canary 19/19 通过,0 失败。精确差异质量凭证有效。新的 frontstage CI 已触发,当前排队中。

English: repaired stale steward-journey expectations. The complete packaged workspace suite and final premerge checks pass locally; the new remote frontstage run is queued.

Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Reviewed head: a4c69218937a99413d0d7bdc41fec82ff03b5666; base: 9060ddc915100ac882d42ad91dbfc6b639bd8848.
按当前 pull-request-review 能力的 policy_revision=6 执行完整审查。结论:没有剩余阻断项;自审中发现的部分分配恢复回执问题已在最终提交修复。

动机

这次改动对应 overall roadmap R1:确认后的任务身份、失败恢复和原入口读回必须可信。

用同一组公开合成输入调用真实 Chat 和 Todo 读回,主干的 legacy 路径把 alpha/beta 两条同文 lane 合成一条,最终只剩 beta 的任务;FileAuthorityStore 路径则留下 alpha 的一条任务和失败卡片。最终提交在两条路径均保留两个独立任务。普通 Todo create 仍按原规则去重。

交付判断是有价值的完整增量:本地分配、提交恢复和产品读回已闭合;并不宣称 R1–R4 整体完成。接收方采纳、真实执行、依赖产物消费、独立验收和结果返回,仍按原 RFC 的 R2/R3/R4 验收。任务分配本身不能证明团队协作成立。

改动思路

准入和整批计划归 typed work-items,复用现有 Todo planner。legacy 将任务和回执放进一次原子写;canonical 将它们放进一次 AuthorityStore CAS,复用 CoordinationCommandReceipt 和 projection outbox。Python 保留存储适配,不再逐条决定和补写任务。

历史回执有独立价值:接收方修改、完成或删除任务后,不能从当前 Todo 反推当初操作是否提交。相同 proposal/lane 的回执先于新准入检查恢复,避免重新造任务。canonical 仍通过既有 writer fence,不能降级成 legacy 写入。

只修改去重规则不能解决部分效果和响应丢失;另建调度器又超出问题。当前批次复用既有 authority,是更小且完整的修复。相关重构已删除重复的 Python 准入/逐条 writer,并提取共享结果组件;未引入无生产调用方的 worker 生命周期。

具体改动

  • Runtime:typed preview/transaction、两种存储适配、effect dispatch、Chat fingerprint/恢复和 governed settlement;只有团队事务使用 operation/lane 身份,普通 create 保持原默认值。
  • 产品:workspace model/mapper、drawer、结果组件、中英文文案和样式。先显示已分配任务和待安排原因,原计划折叠;完成后移除确认按钮,失败重试使用原 proposal。打包 JS/CSS/HTML 与源码一致,并保留前一已发布 bundle。
  • 指引和文档:manager skill 明确新分配确认的范围、owner/receiver 权限以及 advisory quota/stop;两份双语 RFC checkpoint 保留后续协作门槛。before 图片使用精简前实际卡片,after 为验证后的精简结果。
  • 验证:扩展现有真实 Chat、File/PostgreSQL 和浏览器场景,替换旧的逐条部分写入断言。frontstage 的 steward journey 已按实际分配结果验收,不再等待过期标题或通用成功句。

关键代码讲解

  1. planTeamTransaction:接收确认计划和当前事实;先恢复已有回执,否则校验全部 lane,再输出整批 Todos 和回执。相同文本不会把两个 lane 合并,末条非法也不会留下前缀写入。
  2. commitTeamPlan:从 AuthorityStore 读取历史操作或完整 head,检查 provider revision,通过既有 CAS 同时提交任务与回执;响应不确定由 command receipt 恢复。
  3. apply_team_plan:Chat/governed 的实际适配入口;legacy 写入使用既有 fence 和原子 writer,canonical 使用原有投影交付。投影未完成仍返回可恢复失败。
  4. ChatActionService._apply_team_plan:owner 分配不冒充接收方作者;无可安排任务仍失败,未提交计划过期仍拒绝。最终修复让 reused 优先于原有 gap_count,因此恢复和缺口可以同时准确表达。
  5. TeamPlanResult:只从回执成员关系展示已分配项,用已准入预览补充任务标签;缺口原因保留,当前执行进度通过 Goal 查看,历史结果不冒充当前执行状态。

对主干的风险

主要风险是重试覆盖接收方进展,以及共享 Todo planner 意外改变普通任务语义。已通过以下反例验证:并发确认、最后一条非法、跨 Agent 未授权提交、canonical 已变而 Markdown 未刷新、提交响应丢失、投影失败,以及提交后任务被修改/完成/删除。恢复读取历史结果,不重建被删除的任务,也不新增 lease。

本次自审确实发现了浏览器 fixture 与后端的差异:fixture 对带缺口的重试报告 recovered,而 Chat 先按 gap_count 返回 partially_applied。此前真实测试只覆盖满编计划。新增同一真实测试的带缺口分支后,旧代码失败;修正分支顺序后通过,且回执保留原缺口、接收方修改后的文件逐字节不变。

验证 结果与适用范围
同一真实入口的主干/最终提交对照 14 类输入 × legacy/File 两后端,覆盖合法、缺失/空输入、重叠非法条件、完整错误信息、优先级、归属、普通去重、stale 和 replay。主干违反独立 lane 身份断言,最终提交通过。
最终提交 Python 50 个 team-plan/Chat/准入/真实 canonical 投影用例通过。
真实 File/PostgreSQL 16 本次重跑 11/11 通过、0 跳过,覆盖并发、原子性、失败、历史恢复及显式缺口。首次本地重跑因临时数据库端口未恢复而连接失败;修正启动参数后全部通过。
未改变的 TS/backend 范围 4f177272 的完整 TS 1775 个通过;隔离 PostgreSQL store 105 个通过。已核对该版本到最终提交的 control-plane 实现没有变化。
未改变的打包前端 6680abcc 的 build、完整 packaged suite 7/7 通过;最终提交仅改 Python 回执分支和回归测试,资产无变化。浏览器 fixture 证明交互,后端原子性由真实存储测试证明。
最终静态与合并前检查 ruff、配置内 mypy 22 文件、diff/public-boundary 检查通过;canary 19/19、0 失败;精确差异质量凭证有效。

非 manager 的 _session_objective 在主干/最终提交逐字节一致,manager 指引变化是明确披露的范围修正;普通 Todo 的双后端读回一致。PR 没有新增默认关闭功能,安装或注册不触发任务执行。

语义与 CI 对齐

复用现有 Todo/claim/CAS/command-receipt 词汇,仅扩展团队批次历史回执;intent_basis 仍是原 source-facts digest,没有冒充强版本化意图。quota/stop 是计划参考,显式要求未实现的 enforcement 会在效果前拒绝。错误和规则保持 Goal 通用,不引入业务场景专用内核义务。

按当前能力配置 wait_for_ci=false,本次审查不查询、轮询或等待远端 CI。仓库要求的本地验证已完成。可选外部 authority-service endpoint 用例未运行;这不替代已完成的真实 PostgreSQL store 验证,也不声称 Lark/cross-host 执行已验收。

我的整体评价

APPROVE。完整差异的必要性成立:它修复真实的数据/恢复缺陷,同时让发起入口正确读回结果。没有剩余阻断项。代码成本主要是一个共享 typed planner、必要的两种存储适配和结果呈现,没有把“创建任务”包装成更广的协作协议。

剩余兼容边界:旧的已应用卡片和旧结果仍可读;事务改造前已留下部分效果的卡片需基于现有任务显式重规划,不自动迁移。回滚应停止新计划生产并保留现有任务/回执。R2/R3 下一步仍须真实 receiver adoption、依赖产物、独立验收和自动返回,而不是再添加 readiness 字段。

Maintainer-authorized self-merge is eligible only after the unchanged exact head passes the capability-owned merge-readiness check; admin bypass does not replace that gate.

English verdict: APPROVE - a4c6921. Atomic assignment and historical recovery are validated; self-review fixed partial-plan recovery labeling without rewriting receiver work. Final Python 50/50, real File/PostgreSQL 11/11, unchanged packaged UI 7/7 and premerge 19/19 passed. Adoption, execution and cross-host collaboration remain outside this slice.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant