fix(delegation): reuse canonical independent-task validation and member continuation - #5185
Conversation
…thority Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
评审范围:5185@4764f169a9784cd85708f53d219cad25dbbe23e7,完整基线为 6399b8db9e06b9f74b09e78cba7441935a0d4cfb。未发现阻塞性代码问题;这是独立任务委派的有界修复,不是整个真实投研闭环的验收。此自评不能替代指定独立评审或 maintainer 合并。
动机
普通 Todo 的准入已经区分 owner 选定验收范围和范围外独立工作,但委派预检及产物读回仍要求 Goal 验收关联。旧 soft-claim 完成路径还提前传入 terminal --no-follow-up;对需要 controller 完成校验的 Todo,原 Turn 未结算会阻止完成,而完成又是结算的前置条件。这两处协议不一致会让合法工作不能启动或停在返回阶段。
最强的反对方案是只给任务补 owner binding,或直接去掉验收检查。前者把本来独立的工作重新纳入不相关的 owner 契约,后者让 covered 工作绕过门禁。正确边界是复用现有规范 Todo、scope 和 completion declaration,同时保留完成、结算及接收方采用各自的证据。
改动思路
先从同一规范 head 读取精确 Todo 和 owner scope;TS 生成唯一的校验 effects,Python 只负责私有声明、文件 IO 与既有 runner 执行。scope 为 null 表示既有 owner 判定的范围外/关闭,不是 unbound 或 stale 的兜底。范围内 owner criteria 与普通 Todo validator 累加,任一不通过均拒绝。
成员完成采用原有 active-Goal continuation,再恢复原 Turn 的结算,不重新运行 host。显式 terminal 结算门禁仍保留;没有修改 owner 验收、provider、模型配置、binding 或 caller grant。
具体改动
涉及 15 文件:8 个生产文件 +159/-48,4 个测试文件 +193/-3,3 个双语文档文件 +52/-2。生产改动包括共享 TS 计划、规范私有读回、既有 effect 注册、Python IO 适配和 member continuation;终结 owner 中的 effects 构造移入既有 acceptance contract,未增加第二套规则。
关键代码讲解
delegationValidationPlan(loopx/control_plane/collaboration/delegation.ts:20):检查 Todo 身份、provider revision、owner completion requirements;独立工作必须有匹配规范 SHA 的显式声明。validator 成功与 canonical done 分开,不把模型返回当完成。capture/validate(loopx/control_plane/collaboration/delegation_validation.py:19,46):复用已有私有声明 resolver,禁止持久化副作用;执行前后重读同一依据和已声明文件 pins。漂移、缺失及失败均拒绝,没有 Python 策略 owner。acceptanceValidationEffects(loopx/control_plane/goals/acceptance_contract.ts:74):从原 terminal owner 迁出同一构造,terminal completion 和 delegation 共用它。_complete_delegated_todo(loopx/collaboration_mcp.py:823):删除旧 soft-claim terminal 标记;原 lease 与 continuation 合同继续由原 CLI owner 决定,恢复路径只结算原 Turn。
新增 File/SQLite 真实 CLI + 本地 fixture-host 正反例覆盖显式独立 validator、soft/hard lease、原 Turn 恢复、篡改结果、缺失声明、累积 owner 校验失败及 selected-unbound 无兜底。HTTP 测试复用现有团队读回,断言没有新 Turn、host 或扣额副作用。
对主干的风险
完整 diff 检查了 preflight、prepared launch、Turn validation、done readback、原 Turn resume 及 requester adoption;现有产物路径/大小/hash、撤权和无 adoption 不接受等边界未变。Done 不等于 Goal accepted。独立 validator 摘要固定命令,而不固定未声明脚本依赖;文档明确这一原有权限边界,不能把它包装成不可变脚本认证。
真实 immutable base 对照:同一新 fixture 在 File、SQLite 旧版本均得到 acceptance_unavailable(2 个预期失败),现有 Goal-bound preflight/reconnect 4 例在 base 通过。恢复旧 Goal-only TS 判定也产生 2 个预期失败;恢复旧 --no-follow-up 产生 2 个 turn_returned 失败,具体诊断为缺少原结算身份的 accountable refresh-state 回执。仅归一化临时路径、随机 ID、时间及耗时,不归一化状态、诊断、effects 或 host 次数。
已有 source-head 7d9bab58 验证:12 个新增真实 CLI、本地 host 回归;64 个现有 CLI/MCP/acceptance 回归;96 个 TS 检查(含隔离 PostgreSQL,无跳过);4 个现有 HTTP 检查。最终 head 仅删除未使用的 Python import,Ruff、TS source check 和 premerge 14/14 已通过。最终 head 的 16 个真实 CLI/HTTP 检查已全部通过(164.31s,26 项按明确筛选未运行),覆盖上述 12 个独立任务用例及 4 个 HTTP 读回。曾遇磁盘耗尽的失败不计为通过:当时同时出现规范 SQLite 读回失败与独立基线无法创建临时目录;仅清理本任务可重建基线后,原命令重跑通过。磁盘余量仍低,本机 merged-main 升级另行保留,不把它当作本 PR 的代码缺陷。
语义与 CI 对齐
遵循 TS 重构的单一决策/effect owner,保留既有私有持久声明和历史回执,没有平行 Python 决策源。只修正两项已说明的行为;covered、unbound、stale 和显式 terminal 的门禁不降低。当前 Goal 的 review policy 为不等待 CI,因此以本地 repository-native 验证判定,没有拉取或轮询远端 CI。
现有前端 DelegationPreflight 字段和 ready/blocked/unknown 组件仍消费相同 HTTP 投影,没有新增设置或配置字段,故无需新增 UI owner。检查了现有团队入口并运行其后端 roundtrip;此 PR 不声称完成新的 UI 操作流程或 Lark、真实模型投研验收。真实 managed worker → requester 综合/采用仍是合并升级后由委派请求方与工程 owner 共同执行的下一步,保留具体 grant、产物和 source-budget 约束。
我的整体评价
这是必要且可回滚的协议修复,而非新增委派框架。owner gate、普通校验、canonical completion、原 Turn 结算及 requester adoption 各守原边界,修复后合法独立任务能够取得产物并无重复 host 地恢复;最强缺口仍是真实模型与请求方采用的产品验收,不能从 synthetic host 通过推断。
English verdict: APPROVE - exact head 4764f16; canonical independent validation and original-Turn continuation are aligned without weakening owner gates. Local regression/premerge evidence is recorded; real-model research and Lark are not claimed, and maintainer merge remains required.
huangruiteng
left a comment
There was a problem hiding this comment.
Independent post-merge audit of 5185@4764f169a9784cd85708f53d219cad25dbbe23e7, against immutable base 6399b8db9e06b9f74b09e78cba7441935a0d4cfb.
未发现阻塞性代码问题。评审进行中,maintainer 于 11:03:10Z 合并了该 head;以下是独立事后代码审阅,不代表合并前已完成独立批准,也未继承作者自评或把合并当作验收证据。
动机
规范 Todo 已允许 owner 选定验收范围之外的独立工作,委派适配层却仍要求 Goal 验收绑定;合法任务因此无法取得产物。soft-claim 成员完成又提前使用 terminal no_followup,与原 Turn 的完成/结算顺序不一致。
在 File、SQLite 上用同一公开安全 fixture 对照:base 的独立任务得到 acceptance_unavailable;base 的已完成 covered 成员记录 no_followup。这两项共 4 个预期失败,在最终 head 均通过,后者记录 active_goal,恢复后的 host 次数仍为 1。
改动思路
复用既有 canonical Todo、owner scope、私有 validator 摘要和 TS completion owner。范围外任务使用显式普通校验;范围内普通校验与 owner criteria 累加。selected-unbound、stale、缺失或损坏声明均拒绝,不能被普通校验成功抹掉。
成员先按既有 active-Goal continuation 完成 canonical Todo,再结算原 Turn;复用原 operation/turn key、lease 和 receiver adoption。模型返回、validator 通过、canonical done、原 Turn 结算及产物接受仍是不同条件。
具体改动
15 个文件,生产代码 +159/-48、测试 +193/-3、文档 +52/-2。全量 diff 和周边 CLI/MCP/HTTP、Goal/Todo owner、私有声明 resolver、恢复及结果消费者已审阅。
delegationValidationPlan(loopx/control_plane/collaboration/delegation.ts:20)从同一 canonical head 的精确 Todo、provider revision、scope requirements 和声明 SHA 派生 effects。null requirements 来自既有 owner 的关闭/范围外判断,不是错误兜底。capture / validate(loopx/control_plane/collaboration/delegation_validation.py:19,46)只负责私有声明与文件 IO、已有 runner 执行和前后 snapshot 比较。独立反例确认:成功校验后 canonical Todo 改变仍拒绝,损坏的选中声明也不能靠 projection 重建绕过。acceptanceValidationEffects(loopx/control_plane/goals/acceptance_contract.ts:74)从原 terminal owner 移出同一 effects 构造,普通完成和委派共用,避免 Python 再造 scope/criteria 决策。_complete_delegated_todo / _execute(loopx/collaboration_mcp.py:823,860)保留原 CLI 的 claim/lease/continuation authority,删除提前 terminal 标记,并用原 Turn 恢复结算。实际读回、resume、产物篡改、撤权及 adoption 缺失路径由现有回归覆盖。
独立验证全部绑定最终 head:
tests/test_independent_delegation_validation.py:12 passed,File/SQLite 真实 CLI 和本地 fixture host,含 soft/hard lease、缺失 validator、累积 owner 失败、selected-unbound、恢复及产物篡改。- 现有 local delegation、CLI、preflight、MCP、inventory、result-use 六个测试文件:63 passed,包含 4 个现有前端 HTTP 读回用例。
- TS delegation、Goal acceptance authority/runtime、Todo completion transaction:99 passed、0 skipped;使用隔离真实 PostgreSQL 16.15,另覆盖 File/SQLite。
- 额外独立反例:10 passed;同一正向用例在 immutable base 产生上述 4 个预期失败。覆盖 stale owner、私有声明损坏和成功校验后的 canonical 变化。
- 关闭 execution config 时,base/head 实际 stdio MCP 的 5 个工具 schema 与完整
read_context响应一致;只归一化 JSON key 顺序,没有删字段。 - Ruff、仓库 TS source typecheck、配置的 mypy 19 文件、DCO/diff/public boundary、exact-scope quality receipt 均通过。完整 risk-based premerge 最终 14/14、5 项 direct checks 通过。
首次 premerge 为 13/14,失败保留:catalog E2E 的“非 Git 临时目录”fixture 被放在 Git checkout 内,误继承祖先仓库并寻找不存在的 smoke。同一命令在 base/head 复现相同 assertion/缺失文件;PR 未改 canary runner、catalog 或该 fixture。仅将测试临时根置于仓库外后,未改源码、未降 gate、未缩 workload,完整 premerge 重跑通过。作者此前磁盘耗尽导致的未完成检查也不计作本次通过证据。
对主干的风险
最强风险是独立 validator 成为 owner gate 的绕过,或前后 canonical 变化仍接受缓存结果。已分别沿真实入口和共享 TS authority 验证相反方向:合法独立工作能够推进;covered-unbound/stale、owner criterion 失败、声明损坏、validation race 均保留拒绝。普通 absent-acceptance completion、既有公开 projection、原 Turn 与 private receipt 兼容路径由共享 native tests 覆盖。
协议及错误文本保持 task/criterion/declaration 的领域中立语义,没有子串 denylist 或第二套 Python 状态决策。校验、done、文件 freshness 和 adoption 是机器义务,文档未将它们包装成“建议”。有意变化在 local-delegation 参考和双语 roadmap 中披露;没有新的默认 prompt、自动加载 skill、持久化 schema、CLI flag、provider activation 或 requester grant。
现有 frontend 消费相同 preflight 字段,HTTP roundtrip 已测,因此这个修复无需另建 UI 配置 owner。相关未来重构已通过共享 effect builder、收拢 IO snapshot 和删除重复读取完成;没有再添加框架或兼容 wrapper。
我的整体评价
这是一个可独立验证和回滚的有效阶段:合法独立任务可返回规范完成、已校验且可恢复的产物,同时保留 owner authority。完整投研闭环仍未验收;最强未验证项是真实 DSH/GHO worker、requester 的综合/采用,以及 packaged frontend/Lark 实际交互。这些继续由现有交付 owner 与请求方负责,不能从 fixture host 或此次合并推断。
English verdict: APPROVE — independent post-merge audit of exact head 4764f16 found no blocking code issue. Canonical owner gates, cumulative validation and original-Turn continuation are preserved. This audit does not retroactively establish independent pre-merge approval or qualify real-model research/Lark delivery.
动机 / Motivation
Independent delegated work can already be admitted outside owner-selected Goal acceptance, but delegation preflight and artifact readback still required a Goal acceptance binding. Legacy non-hard-lease member completion also asserted terminal
no_followupbefore its original Turn had settled, creating an ordering cycle with controller completion validation.独立任务已可按规范 Todo 准入,但委派仍强制读取 Goal 验收关联;旧 soft-claim 路径还在结算前声明 terminal no-follow-up,形成完成与结算的先后循环。本 PR 修复两处协议不一致,不放松 owner 所选验收。
Changes / 改动
Validation / 验证
4764f169: 16 real CLI/HTTP checks passed in 164.31s (12 File/SQLite independent CLI + local-host regressions and 4 existing frontend HTTP cases). Cases cover soft/hard lease, canonical completion/original-Turn continuation, artifact tampering, missing explicit validator, cumulative failing owner criteria and selected-unbound work without fallback.7d9bab58; the only subsequent source change removes an unused Python import. Callers, base and dependencies were checked for invalidation.6399b8db: same new independent-preflight fixture failed as expected for File/SQLite (2 oracle failures); 4 unchanged Goal-bound preflight/reconnect cases passed. Restoring the old Goal-only gate and soft-claim--no-follow-upbranch produced 2 + 2 expected real-path failures. All deliberate mutations were restored and are not committed.Product / 产品边界
CLI/managed Turn and the existing frontend HTTP preflight consume the same owner projection. No public response schema or settings field changes, so the current ready/blocked/unknown UI needs no companion configuration control or second source of truth. Real-model financial research, requester synthesis, and Lark parity remain unqualified; this does not claim the research minimum loop is complete.
No automatic migration, new grant, model switch, provider activation, owner-acceptance modification, or trading authority is introduced. Maintainer review and merge are required for these runtime/control-plane changes.