Skip to content

fix(delegation): preserve scoped runtime diagnosis without inflating planning - #5176

Merged
huangruiteng merged 2 commits into
mainfrom
codex/delegation-runtime-recovery-20260927T0500
Sep 27, 2026
Merged

huangruiteng merged 2 commits into
mainfrom
codex/delegation-runtime-recovery-20260927T0500

Conversation

@huangruiteng

Copy link
Copy Markdown
Collaborator

Summary / 摘要

Preserve the existing Turn host's public runtime diagnosis through authorized
delegation preflight. A missing module in the probing interpreter is not a
machine-wide runtime outage, and an unprobed generic adapter is not ready.

委派预检此前丢弃已有 host owner 的探测范围和修复代码,容易把单个解释器缺模块
误判为整机不可用。此修复保留同一事实源,不修改 requester grant、任务验收、
执行器选择或运行环境,也不启动/恢复 worker。

Implementation / 实现

  • One TS delegationRuntimeFacts decoder validates bounded public metadata;
    preflight retains the full probe and remediation codes. Legacy omitted
    metadata remains compatible; explicit null remains unprobed.
  • The existing Python adapter only transports facts from its existing host
    probe. Module/import probing stays with that host adapter; no parallel
    Python policy or extra runtime RPC is introduced.
  • Planning progressively discloses only probe_scope; full facts are read
    by inspecting the same binding. The 900-byte route and 2048-byte contribution
    budgets are unchanged, including the two-route crowded fixture.
  • 原有准入状态优先级和只读 effects 不变。凭据失败仍不能被成功的模块探测覆盖;
    未授权请求者、retarget/execute 参数继续被拒绝。公开文档同步中英文。

Validation / 验证

  • TS delegation/context tests: 25 passed.
  • Python context, host binding and actual delegation CLI tests: 60 passed,
    including real File/SQLite authority fixtures.
  • npm run typecheck:control-plane: passed.
  • Ruff on the touched Python/test files: passed.
  • Source premerge: 11 selected checks and 5 direct checks passed; its local
    validation gate passed, while self-merge authority remains absent.
  • Matched pre-fix regressions: 3 TS cases, 3 context cases and 4 actual CLI
    File/SQLite cases failed because diagnosis fields were missing; the repaired
    checks pass. Original failed logs are retained privately.
  • A read-only configured-binding inspection returns the original interpreter
    probe/remedy; planning retains both the blocked managed route and unknown
    generic route without raising the budget. No provider request, request/Turn
    creation, quota spend or worker launch is performed by inspection.

Entry points and remaining work / 入口与剩余工作

Affected entry points: CLI/MCP/Goal Chat delegation inspection and managed
planning capability context. Original configuration and its editors are
unchanged. Shared service output is verified through actual CLI and typed
context paths.

This is a bounded diagnostic foundation, not complete product recovery.
The current Dashboard status component does not render the new diagnosis;
frontend status/feedback and Lark user-facing presentation are companion work.
Default installation dependency repair, current task acceptance, actual fresh/
resume execution and requester adoption remain separate acceptance requirements.

本 PR 不宣称运行环境已修复、异构执行已完成或投研闭环已达成;控制面变更留给
维护者评审合入,不自合并。私有配置、现场绑定身份、路径、日志和凭据均不提交。

@mergify

mergify Bot commented Sep 27, 2026

Copy link
Copy Markdown

Hi @huangruiteng, the DCO Sign-off check did not pass. Please inspect
its details first: checkout, fetch, timeout or infrastructure errors
need their own recovery, not a rewrite of otherwise signed commits.

If the log confirms a missing Signed-off-by trailer, amend the
affected commit with git commit --amend -s; for multiple commits,
use an interactive rebase against the current base from the correct
base-repository remote and sign off each affected commit. Push the
rewritten PR branch with git push --force-with-lease origin HEAD.

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Exact head: 4327fda; base: 1cef055.

动机

本 PR 修复的是运行时诊断在两条现有消费路径中被裁剪掉的问题,而不是重新定义委派权限。原 host binding 已经区分“探测当前解释器中的模块”和“探测显式 runner”,也提供结构化修复代码,但 delegation inspect 和规划上下文没有完整传递这个范围。使用者容易把当前进程的依赖缺失误判为整台机器不能运行,或把尚未探测的 generic runner 当成故障。这个差异会导致反复查错环境、错误重派和重复预检。保留原事实是有价值的独立增量,不能据此宣布 worker 已能启动或整个委派闭环完成。

改动思路

沿用 host binding 作为探测事实来源,TS delegationPreflight 作为任务准入的唯一判断源;Python 只搬运已有公开观察,不新增探测、安装、授权或另一个准入规则。详细 inspect 传递经过结构校验的 runtime_probe 和符号化 unavailable_remediation;规划热路径只保留 probe_scope,其他内容通过同一 binding 的 inspect 渐进披露。这比把所有诊断塞入每次规划更合适:实测完整内联会挤掉第二条路线,当前方案保留原 900-byte 路线块和 2048-byte contribution 限制,受测的两路线场景从 861/1953 bytes 变成 897/1989 bytes,仍同时保留两条路线。

实现没有新配置入口、持久状态、版本分支或调度动作。旧 producer 不提供两个可选字段仍可读取,generic 的 null 仍是“未探测”,不是 false。修复建议只是建议代码,既不授予安装权限,也不跳过原 Goal authority、Turn、任务验收和租约。文档同步解释范围与恢复所有者。

具体改动

关键代码讲解

  1. loopx/control_plane/collaboration/delegation.ts:65 delegationRuntimeFacts:输入来自原 executor 观察,仅接受 managed_runtime_probe_v0、probing_interpreter/configured_runner、布尔 available 及有界模块名;返回清洁的公开 probe 和有界符号化 remedies。未知私有键不透传,错误 scope(包括字符串数组)拒绝,缺失字段保持兼容。它不从模块存在推导凭证可用或任务可执行。

  2. loopx/control_plane/collaboration/delegation.ts:92 delegationPreflight:调用新共享解码器填充 executor,但保持原判断顺序——先匹配 requester/binding,再检查 promoted authority、只读 Turn preview、task acceptance,最后才解释 runtime availability。实际 DSH 预检仍返回 acceptance_unavailable,同时附带解释器模块不可用事实;所有 host_invoked/state_written/quota_spent/scheduler_acknowledged 均为 false。探测 true 加上 credential failure 的反例仍不能变成 launchable。

  3. loopx/control_plane/collaboration/delegation_context.py:44 _route:已有 managed_executor_binding_from_host_args 产生观察后,只转运 runtime_probe/unavailable_remediation 两个公开字段。没有读取秘密值、枚举新的 operation journal,也没有第二次探测或额外 RPC。before_plan 的开启规则和原配置路径约束保持不变。

  4. loopx/control_plane/subagent_context.ts:102 boundedDelegationContext:复用同一 TS 解码器,紧凑路线仅加入 probe_scope;blocked 保持 blocked,generic 保持 unknown,不能提升为任务 ready。原截断和计数逻辑继续有界,不能把未出现在紧凑视图中的 binding 当成不存在。before_plan/before_delegate 都通过两路线测试,私有路径和完整 remediation 不进入规划包。

四个测试文件分别覆盖 TS 结构拒绝/授权边界、共享规划预算、Python 事实转运,以及 File/SQLite 实际 CLI 的未知与 DSH 预检。原 Codex exact-object 断言按新增可选字段更新,最终完整重跑通过,不把初次断言失败包装为原有故障。两份公共文档覆盖用户路径、范围解释和按需 inspect;没有把文档当作执行授权。

正反路径与入口

正向:已授权 binding → 既有 host facts → TS preflight → 详细 executor 诊断;或同一目录 → Python 转运 → TS 紧凑规划 → 按需 inspect。负向:未授权 requester 在原 binding 边界被拒;authority 不可用不进入 executor;模块探测成功但凭证失败仍不可运行;generic 未探测为 null;畸形 scope/remedy 拒绝且不执行 host。实际 CLI 验证 registry 未变、没有 host-started、没有新增 delegation/Turn 记录。

现有 Dashboard preflight 组件仍消费 host/reason/state,不会自动展示新详情;其配置/呈现 companion 仍是后续产品工作。Lark 继续走原共享 delegation/preflight owner,本 PR 不声称已完成新 Lark 卡片或聊天验收。CLI 的诊断改进已被验证,UI 行为保持原样,这是局部交付而非 API 测试冒充端到端恢复。

语义与CI对齐

对照既有 managed_runtime_probe_v0、host_binding 事实、TS 准入优先级及上下文预算,没有新增平行规则。相关既有 runtime qualification/credential owner 与 settlement recovery 改动不被本 PR 覆盖。按当前 Goal 评审契约 wait_for_ci=false,未获取或等待 GitHub CI;使用本地仓库验证。TS 25 项、Python/实际 CLI 60 项、control-plane typecheck、触及的 Ruff、精确 head premerge(11 个选中检查,其中 5 个 direct checks)均通过。对照修复前实现,同一新字段/紧凑上下文断言确实失败,修复后通过;原始失败保留,未调高预算。其他 PR 的 crowded JSON 输出预算问题不在本 PR 修复范围内。

对主干的风险

最大实质风险是诊断内容增加后挤掉另一条授权路线,或错误把局部 module probe 当成全局 launchability;第二个风险是透传路径、凭证配置等私有信息。这些风险分别由真实规划边界的两路线预算测试、Credential-false/probe-true 反例、TS 白名单解码和实际 CLI 无写入测试约束。极长路线仍可能按现有预算截断,读者必须遵循 routes_truncated 和按需 inspect,不承诺全部路线永远内联。

没有修改 Core/File/SQLite 的写入、调度或结算,因此不产生新的重复效果或恢复分支;重跑 inspect 仍是当次只读观察。可回滚这三个生产文件和对应文档/测试,不需要迁移持久数据。真实远端 runner、新任务 fresh/resume、安装后资格复核及结果采用仍需原所有者另行验证,未用 mock 证明它们完成。当前代码只证明信息传递正确,绝不证明可用依赖已经安装。

我的整体评价

APPROVE 这个诊断修复增量:价值清楚、TS 共享语义且 host 适配边界合理,主动压缩规划投影避免挤掉有效候选,没有放宽权限或校验。整个委派恢复任务仍保持开放;下一步由原安装/资格所有者处理实际执行器依赖,并按原任务契约完成资格、fresh/resume 和调用方结果采用,现有产品 companion 补前端/Lark 诊断。没有新的阻塞性代码发现,不代表允许自合并、已升级本机或投研闭环已验收。该 PR 涉及委派/控制面,保留维护者评审与合并。

English verdict: APPROVE - exact head 4327fda; scoped runtime facts remain diagnostic, admission and budgets stay unchanged; 25 TS tests, 60 Python/real-CLI tests, typecheck, Ruff and exact-head premerge passed. Runtime installation, qualification and product companions remain outside this partial delivery.

@huangruiteng
huangruiteng merged commit ef693b4 into main Sep 27, 2026
31 of 36 checks passed
@huangruiteng
huangruiteng deleted the codex/delegation-runtime-recovery-20260927T0500 branch September 27, 2026 07:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant