Skip to content

fix(delegation): reuse canonical independent-task validation and member continuation - #5185

Merged
huangruiteng merged 3 commits into
mainfrom
codex/delegation-independent-validation-20260927
Sep 27, 2026
Merged

huangruiteng merged 3 commits into
mainfrom
codex/delegation-independent-validation-20260927

Conversation

@huangruiteng

@huangruiteng huangruiteng commented Sep 27, 2026 •

Copy link
Copy Markdown
Collaborator

动机 / Motivation

Independent delegated work can already be admitted outside owner-selected Goal acceptance, but delegation preflight and artifact readback still required a Goal acceptance binding. Legacy non-hard-lease member completion also asserted terminal no_followup before its original Turn had settled, creating an ordering cycle with controller completion validation.

独立任务已可按规范 Todo 准入,但委派仍强制读取 Goal 验收关联;旧 soft-claim 路径还在结算前声明 terminal no-follow-up,形成完成与结算的先后循环。本 PR 修复两处协议不一致,不放松 owner 所选验收。

Changes / 改动

  • Reuse the exact canonical Todo and acceptance scope in one TypeScript validation plan. Out-of-scope/disabled Goal acceptance requires an explicit canonical Todo validator; covered unbound/stale work remains rejected. Applicable Todo and Goal checks are cumulative.
  • Keep Python as private declaration/file IO and authorized validation execution only. Declaration digests, pinned Goal validator files, canonical revisions, completion, returned-artifact hashes and requester adoption retain their separate gates.
  • Reuse the same plan for inspection, pre-launch checks, Turn validation and artifact readback. Preserve specific canonical unbound/stale errors rather than inventing an authority promotion failure.
  • Complete bounded member Todos with the ordinary active-Goal continuation, then resume only the original Turn settlement without rerunning its host. Explicit terminal settlement gates remain unchanged.
  • 更新中英文委派边界与 roadmap;不激活 provider、不创建 binding、不改 owner 验收。

Validation / 验证

  • Final exact head 4764f169: 16 real CLI/HTTP checks passed in 164.31s (12 File/SQLite independent CLI + local-host regressions and 4 existing frontend HTTP cases). Cases cover soft/hard lease, canonical completion/original-Turn continuation, artifact tampering, missing explicit validator, cumulative failing owner criteria and selected-unbound work without fallback.
  • 64 existing CLI/MCP/delegation/acceptance regression checks passed at source head 7d9bab58; the only subsequent source change removes an unused Python import. Callers, base and dependencies were checked for invalidation.
  • 68 TypeScript delegation/acceptance tests, including isolated PostgreSQL, with zero skips; another 28 TypeScript acceptance-runtime/terminal tests passed.
  • Four existing frontend HTTP inspect cases passed for both Goal-bound and independent tasks, without creating a Turn or launching a host.
  • Final TypeScript source check, Ruff and premerge passed (14/14 selected checks); Python compile and whole-branch whitespace checks passed. No remote CI fetched or polled under the resolved review policy.
  • Immutable base 6399b8db: same new independent-preflight fixture failed as expected for File/SQLite (2 oracle failures); 4 unchanged Goal-bound preflight/reconnect cases passed. Restoring the old Goal-only gate and soft-claim --no-follow-up branch produced 2 + 2 expected real-path failures. All deliberate mutations were restored and are not committed.
  • An intermediate repeat failed during local disk exhaustion, independently accompanied by baseline temp-directory creation failure. This failed attempt is retained, not counted as a pass; after removing only the task-owned reconstructible baseline export, the identical final-head command passed all 16 cases. Low disk headroom still separately holds local merged-main installation.

Product / 产品边界

CLI/managed Turn and the existing frontend HTTP preflight consume the same owner projection. No public response schema or settings field changes, so the current ready/blocked/unknown UI needs no companion configuration control or second source of truth. Real-model financial research, requester synthesis, and Lark parity remain unqualified; this does not claim the research minimum loop is complete.

No automatic migration, new grant, model switch, provider activation, owner-acceptance modification, or trading authority is introduced. Maintainer review and merge are required for these runtime/control-plane changes.

…thority

Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

评审范围:5185@4764f169a9784cd85708f53d219cad25dbbe23e7,完整基线为 6399b8db9e06b9f74b09e78cba7441935a0d4cfb。未发现阻塞性代码问题;这是独立任务委派的有界修复,不是整个真实投研闭环的验收。此自评不能替代指定独立评审或 maintainer 合并。

动机

普通 Todo 的准入已经区分 owner 选定验收范围和范围外独立工作,但委派预检及产物读回仍要求 Goal 验收关联。旧 soft-claim 完成路径还提前传入 terminal --no-follow-up;对需要 controller 完成校验的 Todo,原 Turn 未结算会阻止完成,而完成又是结算的前置条件。这两处协议不一致会让合法工作不能启动或停在返回阶段。

最强的反对方案是只给任务补 owner binding,或直接去掉验收检查。前者把本来独立的工作重新纳入不相关的 owner 契约,后者让 covered 工作绕过门禁。正确边界是复用现有规范 Todo、scope 和 completion declaration,同时保留完成、结算及接收方采用各自的证据。

改动思路

先从同一规范 head 读取精确 Todo 和 owner scope;TS 生成唯一的校验 effects,Python 只负责私有声明、文件 IO 与既有 runner 执行。scope 为 null 表示既有 owner 判定的范围外/关闭,不是 unbound 或 stale 的兜底。范围内 owner criteria 与普通 Todo validator 累加,任一不通过均拒绝。

成员完成采用原有 active-Goal continuation,再恢复原 Turn 的结算,不重新运行 host。显式 terminal 结算门禁仍保留;没有修改 owner 验收、provider、模型配置、binding 或 caller grant。

具体改动

涉及 15 文件:8 个生产文件 +159/-48,4 个测试文件 +193/-3,3 个双语文档文件 +52/-2。生产改动包括共享 TS 计划、规范私有读回、既有 effect 注册、Python IO 适配和 member continuation;终结 owner 中的 effects 构造移入既有 acceptance contract,未增加第二套规则。

关键代码讲解

  • delegationValidationPlan(loopx/control_plane/collaboration/delegation.ts:20):检查 Todo 身份、provider revision、owner completion requirements;独立工作必须有匹配规范 SHA 的显式声明。validator 成功与 canonical done 分开,不把模型返回当完成。
  • capture / validate(loopx/control_plane/collaboration/delegation_validation.py:19,46):复用已有私有声明 resolver,禁止持久化副作用;执行前后重读同一依据和已声明文件 pins。漂移、缺失及失败均拒绝,没有 Python 策略 owner。
  • acceptanceValidationEffects(loopx/control_plane/goals/acceptance_contract.ts:74):从原 terminal owner 迁出同一构造,terminal completion 和 delegation 共用它。
  • _complete_delegated_todo(loopx/collaboration_mcp.py:823):删除旧 soft-claim terminal 标记;原 lease 与 continuation 合同继续由原 CLI owner 决定,恢复路径只结算原 Turn。

新增 File/SQLite 真实 CLI + 本地 fixture-host 正反例覆盖显式独立 validator、soft/hard lease、原 Turn 恢复、篡改结果、缺失声明、累积 owner 校验失败及 selected-unbound 无兜底。HTTP 测试复用现有团队读回,断言没有新 Turn、host 或扣额副作用。

对主干的风险

完整 diff 检查了 preflight、prepared launch、Turn validation、done readback、原 Turn resume 及 requester adoption;现有产物路径/大小/hash、撤权和无 adoption 不接受等边界未变。Done 不等于 Goal accepted。独立 validator 摘要固定命令,而不固定未声明脚本依赖;文档明确这一原有权限边界,不能把它包装成不可变脚本认证。

真实 immutable base 对照:同一新 fixture 在 File、SQLite 旧版本均得到 acceptance_unavailable(2 个预期失败),现有 Goal-bound preflight/reconnect 4 例在 base 通过。恢复旧 Goal-only TS 判定也产生 2 个预期失败;恢复旧 --no-follow-up 产生 2 个 turn_returned 失败,具体诊断为缺少原结算身份的 accountable refresh-state 回执。仅归一化临时路径、随机 ID、时间及耗时,不归一化状态、诊断、effects 或 host 次数。

已有 source-head 7d9bab58 验证:12 个新增真实 CLI、本地 host 回归;64 个现有 CLI/MCP/acceptance 回归;96 个 TS 检查(含隔离 PostgreSQL,无跳过);4 个现有 HTTP 检查。最终 head 仅删除未使用的 Python import,Ruff、TS source check 和 premerge 14/14 已通过。最终 head 的 16 个真实 CLI/HTTP 检查已全部通过(164.31s,26 项按明确筛选未运行),覆盖上述 12 个独立任务用例及 4 个 HTTP 读回。曾遇磁盘耗尽的失败不计为通过:当时同时出现规范 SQLite 读回失败与独立基线无法创建临时目录;仅清理本任务可重建基线后,原命令重跑通过。磁盘余量仍低,本机 merged-main 升级另行保留,不把它当作本 PR 的代码缺陷。

语义与 CI 对齐

遵循 TS 重构的单一决策/effect owner,保留既有私有持久声明和历史回执,没有平行 Python 决策源。只修正两项已说明的行为;covered、unbound、stale 和显式 terminal 的门禁不降低。当前 Goal 的 review policy 为不等待 CI,因此以本地 repository-native 验证判定,没有拉取或轮询远端 CI。

现有前端 DelegationPreflight 字段和 ready/blocked/unknown 组件仍消费相同 HTTP 投影,没有新增设置或配置字段,故无需新增 UI owner。检查了现有团队入口并运行其后端 roundtrip;此 PR 不声称完成新的 UI 操作流程或 Lark、真实模型投研验收。真实 managed worker → requester 综合/采用仍是合并升级后由委派请求方与工程 owner 共同执行的下一步,保留具体 grant、产物和 source-budget 约束。

我的整体评价

这是必要且可回滚的协议修复,而非新增委派框架。owner gate、普通校验、canonical completion、原 Turn 结算及 requester adoption 各守原边界,修复后合法独立任务能够取得产物并无重复 host 地恢复;最强缺口仍是真实模型与请求方采用的产品验收,不能从 synthetic host 通过推断。

English verdict: APPROVE - exact head 4764f16; canonical independent validation and original-Turn continuation are aligned without weakening owner gates. Local regression/premerge evidence is recorded; real-model research and Lark are not claimed, and maintainer merge remains required.

@huangruiteng
huangruiteng merged commit d23f1c8 into main Sep 27, 2026
31 of 33 checks passed
@huangruiteng
huangruiteng deleted the codex/delegation-independent-validation-20260927 branch September 27, 2026 11:03

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent post-merge audit of 5185@4764f169a9784cd85708f53d219cad25dbbe23e7, against immutable base 6399b8db9e06b9f74b09e78cba7441935a0d4cfb.

未发现阻塞性代码问题。评审进行中,maintainer 于 11:03:10Z 合并了该 head;以下是独立事后代码审阅,不代表合并前已完成独立批准,也未继承作者自评或把合并当作验收证据。

动机

规范 Todo 已允许 owner 选定验收范围之外的独立工作,委派适配层却仍要求 Goal 验收绑定;合法任务因此无法取得产物。soft-claim 成员完成又提前使用 terminal no_followup,与原 Turn 的完成/结算顺序不一致。

在 File、SQLite 上用同一公开安全 fixture 对照:base 的独立任务得到 acceptance_unavailable;base 的已完成 covered 成员记录 no_followup。这两项共 4 个预期失败,在最终 head 均通过,后者记录 active_goal,恢复后的 host 次数仍为 1。

改动思路

复用既有 canonical Todo、owner scope、私有 validator 摘要和 TS completion owner。范围外任务使用显式普通校验;范围内普通校验与 owner criteria 累加。selected-unbound、stale、缺失或损坏声明均拒绝,不能被普通校验成功抹掉。

成员先按既有 active-Goal continuation 完成 canonical Todo,再结算原 Turn;复用原 operation/turn key、lease 和 receiver adoption。模型返回、validator 通过、canonical done、原 Turn 结算及产物接受仍是不同条件。

具体改动

15 个文件,生产代码 +159/-48、测试 +193/-3、文档 +52/-2。全量 diff 和周边 CLI/MCP/HTTP、Goal/Todo owner、私有声明 resolver、恢复及结果消费者已审阅。

  • delegationValidationPlan(loopx/control_plane/collaboration/delegation.ts:20)从同一 canonical head 的精确 Todo、provider revision、scope requirements 和声明 SHA 派生 effects。null requirements 来自既有 owner 的关闭/范围外判断,不是错误兜底。
  • capture / validate(loopx/control_plane/collaboration/delegation_validation.py:19,46)只负责私有声明与文件 IO、已有 runner 执行和前后 snapshot 比较。独立反例确认:成功校验后 canonical Todo 改变仍拒绝,损坏的选中声明也不能靠 projection 重建绕过。
  • acceptanceValidationEffects(loopx/control_plane/goals/acceptance_contract.ts:74)从原 terminal owner 移出同一 effects 构造,普通完成和委派共用,避免 Python 再造 scope/criteria 决策。
  • _complete_delegated_todo / _execute(loopx/collaboration_mcp.py:823,860)保留原 CLI 的 claim/lease/continuation authority,删除提前 terminal 标记,并用原 Turn 恢复结算。实际读回、resume、产物篡改、撤权及 adoption 缺失路径由现有回归覆盖。

独立验证全部绑定最终 head:

  • tests/test_independent_delegation_validation.py:12 passed,File/SQLite 真实 CLI 和本地 fixture host,含 soft/hard lease、缺失 validator、累积 owner 失败、selected-unbound、恢复及产物篡改。
  • 现有 local delegation、CLI、preflight、MCP、inventory、result-use 六个测试文件:63 passed,包含 4 个现有前端 HTTP 读回用例。
  • TS delegation、Goal acceptance authority/runtime、Todo completion transaction:99 passed、0 skipped;使用隔离真实 PostgreSQL 16.15,另覆盖 File/SQLite。
  • 额外独立反例:10 passed;同一正向用例在 immutable base 产生上述 4 个预期失败。覆盖 stale owner、私有声明损坏和成功校验后的 canonical 变化。
  • 关闭 execution config 时,base/head 实际 stdio MCP 的 5 个工具 schema 与完整 read_context 响应一致;只归一化 JSON key 顺序,没有删字段。
  • Ruff、仓库 TS source typecheck、配置的 mypy 19 文件、DCO/diff/public boundary、exact-scope quality receipt 均通过。完整 risk-based premerge 最终 14/14、5 项 direct checks 通过。

首次 premerge 为 13/14,失败保留:catalog E2E 的“非 Git 临时目录”fixture 被放在 Git checkout 内,误继承祖先仓库并寻找不存在的 smoke。同一命令在 base/head 复现相同 assertion/缺失文件;PR 未改 canary runner、catalog 或该 fixture。仅将测试临时根置于仓库外后,未改源码、未降 gate、未缩 workload,完整 premerge 重跑通过。作者此前磁盘耗尽导致的未完成检查也不计作本次通过证据。

对主干的风险

最强风险是独立 validator 成为 owner gate 的绕过,或前后 canonical 变化仍接受缓存结果。已分别沿真实入口和共享 TS authority 验证相反方向:合法独立工作能够推进;covered-unbound/stale、owner criterion 失败、声明损坏、validation race 均保留拒绝。普通 absent-acceptance completion、既有公开 projection、原 Turn 与 private receipt 兼容路径由共享 native tests 覆盖。

协议及错误文本保持 task/criterion/declaration 的领域中立语义,没有子串 denylist 或第二套 Python 状态决策。校验、done、文件 freshness 和 adoption 是机器义务,文档未将它们包装成“建议”。有意变化在 local-delegation 参考和双语 roadmap 中披露;没有新的默认 prompt、自动加载 skill、持久化 schema、CLI flag、provider activation 或 requester grant。

现有 frontend 消费相同 preflight 字段,HTTP roundtrip 已测,因此这个修复无需另建 UI 配置 owner。相关未来重构已通过共享 effect builder、收拢 IO snapshot 和删除重复读取完成;没有再添加框架或兼容 wrapper。

我的整体评价

这是一个可独立验证和回滚的有效阶段:合法独立任务可返回规范完成、已校验且可恢复的产物,同时保留 owner authority。完整投研闭环仍未验收;最强未验证项是真实 DSH/GHO worker、requester 的综合/采用,以及 packaged frontend/Lark 实际交互。这些继续由现有交付 owner 与请求方负责,不能从 fixture host 或此次合并推断。

English verdict: APPROVE — independent post-merge audit of exact head 4764f16 found no blocking code issue. Canonical owner gates, cumulative validation and original-Turn continuation are preserved. This audit does not retroactively establish independent pre-merge approval or qualify real-model research/Lark delivery.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant