Skip to content

fix(quota): retain auxiliary monitors after primary completion - #5159

Merged
huangruiteng merged 1 commit into
mainfrom
codex/auxiliary-monitor-completed-advancement-20260927
Sep 27, 2026
Merged

huangruiteng merged 1 commit into
mainfrom
codex/auxiliary-monitor-completed-advancement-20260927

Conversation

@huangruiteng

Copy link
Copy Markdown
Collaborator

Summary / 摘要

Fix the managed CLI path where an advancement Todo has completed but its original Turn still needs writeback/spend, and a separately leased, due monitor must record an auxiliary observation.

根因:Python 入口把“当前开放任务选择”当作原 Turn 身份权威。主任务完成后会离开开放列表,合法辅助观察因此被误拒。修复不改原绑定、不重开任务、不自动扣额。

  • Read the exact original Todo's canonical lifecycle, including completed history; move auxiliary admission into the existing TS monitor commit owner, reusing the existing TS settlement readback.
  • Require the original committed, unsettled advancement identity, matching actor/ownership, the monitor's own due-work admission and existing provider/lease fencing. Wrong identities, foreign ownership, closed ordinary gates and fresh effects after settlement fail closed.
  • Preserve exact pending-effect recovery and durable replay across later projection/settlement changes, without authorizing a new mutation or another spend.
  • Return a compact settlement_resume: original identity, shared progress reference, and only the currently required next step. Suppress a newly selected Todo's misleading closeout commands. Conflicts retain both Todo identifiers.

Placement / 归属与边界

TS owns admission, settlement state and existing journal/CAS recovery. Python remains the canonical-source transport and CLI command-rendering adapter; it reuses the existing typed settlement plan renderer and does not introduce a parallel decision owner or a new service.

沿用 TS 重构 RFC 的单一 owner 边界;顺带删除旧 Python 开放列表准入判定。未改 File/SQLite/PostgreSQL store 实现,也未引入金融规则。

Affected entry points: managed/CLI JSON and its executable projected commands. There is no new setting or capability schema. The dashboard has no monitor-poll/auxiliary-settlement consumer, and existing monitor lifecycle/receipt fields remain unchanged, so no frontend/Lark controls or second projection owner are added. This is not a claim of new UI, Lark, automatic-hook, or live-provider qualification.

Validation / 验证

  • Counterfactual on unchanged baseline production: the same completed-primary regression fails with heartbeat_receipt_identity_conflict; this is an intended behavior correction, not a claim of byte-for-byte equivalence to that defect.
  • Public CLI regression: open primary; completed primary before/after writeback; real File and SQLite authority with the monitor's own lease; provider readback; exact replay after lease release and original settlement; actual projected writeback/spend commands; repeated spend yields exactly one debit. The new resume envelope is bounded below 2,000 characters for these fixtures.
  • Native TS tests: exact identity/actor/ownership, ordinary due-work gates, no unauthorized journal effects, pending recovery after original settlement, durable replay, rejection of a fresh auxiliary effect after settlement; existing CAS/concurrency, fencing and settlement suites retained.
uv run --no-sync pytest -q tests/control_plane/test_monitor_observation_admission.py
uv run --no-sync pytest -q tests/control_plane/test_leased_monitor_poll.py tests/control_plane/test_quota_monitor_poll_runtime.py tests/control_plane/test_monitor_poll_cli_projection.py tests/control_plane/test_auxiliary_monitor_poll_availability.py
node --no-warnings --experimental-sqlite --experimental-strip-types --test tests/control_plane_ts/auxiliary_monitor_settlement.test.ts tests/control_plane_ts/quota_monitor_poll_commit.test.ts tests/control_plane_ts/quota_settlement_readback.test.ts
npm run typecheck:control-plane
uv run --no-sync ruff check loopx/quota.py loopx/control_plane/quota/monitor_poll.py loopx/control_plane/quota/cli_projection.py tests/control_plane/test_monitor_observation_admission.py
uv run --no-sync loopx --format json canary premerge --from-git-diff

Final result counts are recorded in the exact-head self-review. All new fixtures are synthetic. No credentials, account data, research captures, active Goal state, or local validation artifacts are committed. The first premerge attempt was intentionally stopped after this author changed a tracked file during validation; the final frozen-tree run is the acceptance evidence.

Remaining / 剩余

Maintainer review/merge and a merged-release install precede owner-authorized live managed qualification. This PR is not installed into the active runtime and does not claim the original live blocker resolved. PostgreSQL storage is unchanged and this batch does not claim a PostgreSQL/live-account qualification. No self-merge.

Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

精确 head:cbf8d1ff54ef991ca35d39fea1788e09b078c1a1。未发现阻塞项;结论仅覆盖本 PR 的通用 managed/CLI 修复,不代表已合入、已安装或真实业务 Goal 已恢复。

动机

本 PR 修的是一个真实入口的生命周期错配:主任务已经完成、原 Turn 尚待结算时,辅助 monitor 的独立租约和到期条件都合法,但 Python 仍要求原主任务出现在开放任务选择里。结果是观察无法登记,后续原 Turn 结算也容易跟随另一个被选中的 Todo。以同一冻结回归分别调用基线 420782f0 和本 head,基线在 monitor-poll 处报身份冲突,本 head 完成观察、重复重试与唯一一次原身份扣额。

判断为有实际价值的有界增量,而非整项长期目标已完成。它消除合法监控饥饿和手动重开主任务的压力;后续仍由维护者合入,再从合入版本安装并验证实际 managed 调用。没有要求用户放松验收合同、复制旧租约或重写 Goal。

改动思路

判断框架是既有 辅助观察契约 和 TS 重构 RFC 的 T2 边界。开放任务选择是发现投影,不是不可变 Turn 身份。Python 精确读回原 Todo,包括完成历史;既有 TS monitor transaction 根据该事实、原 settlement readback 和普通 due-work 条件决定是否准入。Monitor 的业务写入继续走既有 provider/CAS/租约 owner。

最小的 Python 条件放宽虽然能绕过当前报错,却保留第二份准入规则,也不能阻止响应把另一个 Todo 的结算命令交给调用者。因此这里删除旧 Python 判定,复用 TS owner;没有新服务、配置开关或平行状态机。新增事实字段由真实 CLI 每次读取权威源后产生,不要求 Agent 手动维护。续接仅引用原身份和共享进度,并渲染当前一步,不返回重复的完整计划。

具体改动

关键代码讲解

  1. record_quota_monitor_poll:删除依赖开放列表的 Python gate,按原绑定 Todo 精确读取 lifecycle。成功后使用既有 TS settlement readback 和命令渲染器形成 settlement_resume;若后续发现选中另一条 Todo,移除其误导性的结算命令并关闭该投影的 spend 标志,不能借观察替换原身份。
  2. record_quota_monitor_poll_for_decision:只把原 Todo 的五项 lifecycle/ownership 事实加入现有请求;观察仍携带 monitor 自己的执行 fence。没有获取、续租或跨 Todo 借用租约。
  3. auxiliaryMonitorAllowed:区分辅助观察和普通同身份 monitor;校验 actor、原 advancement 的身份/状态/归属、未结算回执及 monitor 自己的到期条件,保留普通准入门禁。错误消息保留 settlement/observation 两个 Todo ID。
  4. evaluateQuotaMonitorPollCommit:精确 durable replay 仍先于新准入;已冻结的 pending 仅恢复原 effect。另用真正的旧源码生成不含新增 lifecycle 字段的 pending v1,验证新 head 在原主任务结算后仍能 written/replayed;没有通过手改旧回执制造“历史准入”。
  5. compact_quota_monitor_poll_cli_payload:默认 JSON 保留续接引用,避免精简响应丢失当前可执行路径。续接段实测从约 4,106 字符降为 1,386 字符,settled 后无下一步。

两个测试文件分别覆盖实际 CLI/provider 写回与 TS 拒绝/恢复边界。CLI 测试执行的是投影出来的命令,不是只检查字符串:主任务完成前后、写回前后、File/SQLite 自有监控租约、provider 独立读回、释放租约后的重试、原身份两次 spend 只扣一次。另加 150 条反序排列的无关完成历史,真实 File 入口仍成功,不把精简列表之外的原引用当成不存在。

对主干的风险

最大风险是为了恢复合法观察而放宽成任意跨 Todo 执行。负向验证覆盖错误 Turn/绑定、缺失原 lifecycle、其他 owner、排除 actor、无到期目标、普通门禁关闭和需要用户动作;这些拒绝不写 journal/index。原 Turn 已结算后,新辅助 effect 被拒绝,精确 pending/已提交 replay 则保持可恢复。普通同身份 monitor 不经过新增分支,原租约与 provider 事务未改;34 项邻近回归覆盖 lease 失效、响应丢失、CAS、业务提交后恢复等路径。

语义与 CI 对齐

有意变化是“完成的 advancement 不再等同失去原 Turn 身份”,以及拒绝把已结算 Turn 当作新辅助执行授权;已有原身份、观察身份、no-spend、pending、精确重放语义被复用。PR 明确披露变化,未新增金融词汇或另一个 Python 决策 owner。此处没有 default-off/能力启用主张,也没有修改模型提示或配置入口。

本地证据:CLI 主回归 5/5,邻近回归 34/34,原生 TS 81/81,typecheck、Ruff、diff 检查通过;冻结树 premerge 18/18,无失败、警告或跳过。另有相同 harness 的开放主任务基线/head 对照、完成主任务的历史缺陷对照,以及旧源码 pending 恢复。按 Goal 的 wait_for_ci=false 未查询远端 CI。首次 canary 因作者在检查期间改动 tracked 文件而中止,不把它当作产品失败,也不作为通过证据。

当前用户路径是 managed/CLI JSON,没有新设置;检索 dashboard 未发现辅助 monitor-poll 消费者,现有 Monitor lifecycle/receipt 字段保持不变,所以不新增前端/Lark 控件或第二权威投影。这里只验收实际投影命令和真实 File/SQLite 存储,不宣称新的页面体验、Lark 自动 hook、PostgreSQL store 重构或真实账户执行资格。

我的整体评价

long_horizon 和 user_experience 均改善:原承诺可以继续结算,监控能独立留痕,重试不复制业务或扣额,也不要求用户改变任务身份。整体机制与问题相称:生产部分删除旧 gate,增加既有 owner 的有界判定和一份派生续接响应;主要新增量是耐久回归,没有包装成通用新框架。历史 pending 的兼容分支有真实旧生产者和升级边界,不是无依据的版本堆叠;完成全量 pending 迁移前不应删除。

结论 APPROVE,未发现阻塞性代码问题。尚缺合入版本在实际 managed 会话上的安装态复验,这是维护者合入后的部署步骤,不用未合入分支冒充修复已生效;整项能力组合/记忆路线也没有被本 PR 宣告完成。控制面改动保持维护者评审,不自合并。

English verdict: APPROVE - cbf8d1f. Fixes completed-primary auxiliary monitor admission and exact original-Turn closeout without new delivery authority or duplicate spend. CLI 5, adjacent 34, native TS 81 and premerge 18 passed; baseline/head and old-source pending recovery verified. Merge/install/live qualification remain separate.

@huangruiteng
huangruiteng merged commit fdec859 into main Sep 27, 2026
28 of 32 checks passed
@huangruiteng
huangruiteng deleted the codex/auxiliary-monitor-completed-advancement-20260927 branch September 27, 2026 03:08
@huangruiteng

Copy link
Copy Markdown
Collaborator Author

Post-merge audit: auxiliary monitor continuation

Reviewed exact head cbf8d1ff54ef991ca35d39fea1788e09b078c1a1 against 420782f03725bf9b7603be481f2b0525beff5807. The PR merged during this independent review as fdec859. This comment records a new actionable P2 finding: explicitly narrow the Optional runtime_root and settlement progress in quota.py:1213/1246/1255. Native runtime invariants pass; the expanded checker and this audit quality receipt are non-passing. The code verdict below applies to the exact merged diff and grants no merge or deployment authority.

动机

主任务完成后,开放任务发现会移除它,但已承诺的原 Turn 仍可能欠写回和一次扣账。此时到期 monitor 应能用自己的租约留下一次辅助观察,并继续原承诺。相同冻结 CLI 回归在基线上报 heartbeat_receipt_identity_conflict;本 head 能完成观察、执行投影出来的写回/扣账命令,并在重试后保持唯一一次效果。这个有界修复能恢复持续推进和实际调用体验;合入、安装与真实 managed 会话复验仍由既有部署流程完成。

改动思路

判断依据是 辅助观察契约 与 TS 重构 RFC 的既有 quota owner。仅放宽 Python 的开放列表条件会保留第二份准入判定,也不能解决响应借用了新选中 Todo 的结算命令。这里删除旧判定,在现有 TS owner 中核对原身份、完成历史和 monitor 自己的准入;Python 读取权威事实并复用现有命令渲染器。

新增事实与续接都是从现有权威源派生,普通调用者无需手动维护字段。没有新增配置、服务或存储 owner。当前变化落在 managed/CLI JSON;检索相关 dashboard/Lark 入口没有辅助 monitor-poll 消费者或对应设置,现有 monitor lifecycle 字段未改,故本批无需新控件,也未宣称新的 UI/Lark 执行资格。

具体改动

关键代码讲解

  1. record_quota_monitor_poll 按原绑定 ID 精确读取 canonical Todo,包括完成历史。成功观察后由原 settlement readback 构造当前一步的 settlement_resume;后续选择了其他 Todo 时,移除其误导性结算命令,保留原身份与共享进度。
  2. record_quota_monitor_poll_for_decision 只传递原 Todo 的五项 lifecycle/ownership 事实。monitor 自己的 lease、provider mutation、CAS 与恢复路径继续归既有 owner。
  3. auxiliaryMonitorAllowed 核对精确未结算 advancement、actor/归属和普通 due-work 门禁。新 effect 不能利用已结算原 Turn;已有 admitted pending 与 durable replay 仍可恢复。用真正基线生产者生成不含新增字段的 pending-v1,当前 head 在原 Turn 结算后仍能 written/replayed,兼容分支有实际升级对象。
  4. compact_quota_monitor_poll_cli_payload 保留续接引用,精简响应仍能找到原身份当前一步;不授予新 delivery 或自动 spend。

生产部分新增 169、删除 80 行;361 行新增测试覆盖真实 CLI/provider 和 typed admission/recovery。相关整理已应用:删除 Python 重复准入,复用现有 TS owner 与 renderer。继续提取新框架没有当前独立消费者。

对主干的风险

最主要的风险是恢复合法跨 Todo 观察时扩大权限。原生负向用例验证错误 Turn/绑定、缺失或 blocked lifecycle、其他 owner/actor、非到期 monitor、普通门禁关闭与需要用户操作均拒绝,且不写未授权 journal/index。完成后的新辅助 effect 被拒绝,已冻结 pending 和精确 replay 可继续。完整 CLI 回归执行投影命令、独立读回真实 File/SQLite provider、释放 monitor lease 后重试,以及重复 spend 的唯一扣账。

语义与 CI 对齐

本次独立本地验证:head 39/39、immutable base 35/35;原生 TS 81/81;14 组普通 owner 输入的完整返回/错误在 base/head 精确相等,无归一化。补充真实 File CLI fixture 放入 150 条无关完成记录,原绑定仍能观察、结算与重放。仓库指定的 20-file strict mypy、control-plane typecheck、Ruff、diff/DCO 与公开边界检查通过。按 wait_for_ci=false 未查询远端 CI。本次未运行完整 premerge、PostgreSQL 或 live/install 资格验证,也不借用作者的通过声明。

P2:显式收窄续接适配器的 Optional 值。 扩大检查三个 Python 模块后,504 文件检查在 base/head 分别报 4,168/4,166 个错误。逐条对照发现新增三处:quota.py:1213 的 Path | None、:1246 和 :1255 的 progress | None。因此不能将净减少两条错误解释成没有新诊断。现有 recorder 已先验证 runtime root,TS found readback 始终提供 progress,真实入口验证没有复现运行时缺陷;建议在此适配器中显式校验/收窄两者,使预条件在类型边界可验证,并保留完成-primary回归。

扩大检查不属于当前 pyproject.toml 的必检范围,该建议不阻塞代码评审。但失败已如实写入 quality receipt,严格 qualification 因该失败未通过;该审计回执不能作为严格质量资格通过的证据;PR 已在本审计发布前合并。后续应解决新增诊断并由质量检查 owner 重新完成资格判断,保留遗留诊断的归因记录。

我的整体评价

结论 APPROVE,这是对已合并精确 diff 的代码结论;新增 P2 是本审计的可操作意见,审计质量资格另处于 hold。整个修复保持原 commitment、monitor 自有权限和唯一结算,改善 long_horizon 与 user_experience。有意改变的“完成任务仍保留原 Turn 身份”、已结算 Turn 的新 effect 拒绝及原身份 current-step JSON 已在 PR 正文和耐久回归中披露;没有 prose/substr 分类、特定业务用语或新增 default-off 宣称。存储实现未改,本批实际验证覆盖真实 File/SQLite;PG、部署安装与 live managed 仍明确未验证。本任务未执行合并,代码结论不等于严格质量资格通过或部署完成。

English verdict: APPROVE — cbf8d1f. Native CLI head 39/base 35, TS 81, exact ordinary-owner parity, baseline-produced pending recovery and dense completed-history journey verified. One non-blocking Optional-narrowing suggestion; expanded mypy failed and the strict quality receipt is non-passing. Merge readiness and deployment remain separate.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant