fix(scheduler): preserve authority scope through Codex compatibility - #5219
Conversation
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Exact head: f571573
未发现阻塞性问题。本评审只认可 scheduler 状态 scope 修复,不把代码验收冒充安装成功、实际 Agent 恢复或 Effect 延迟根治。
动机
App proposal 从 common state 读到合法下一档,却在 Codex 兼容投影里被改成旧键。两种状态并存时,TS 因错误 scope 中新 identity 的非零初始档位而拒绝,CAS 摘要相等也不能消除这个错误。修复让宿主原样执行当前 hint,让随后调度读到真实持久回执,避免不断重试归属错误的 ACK。
改动思路
最小方案是贯穿既有链路保留实际读键,不是延长超时、放宽初始档位或新增迁移服务。只删除兼容覆盖还不够:旧状态独存的非零 continuation 与手工 CLI/Python 默认键也须跟随实际 packet。状态加载、reset、CAS、原子写入、失败缓存与 Turn 新鲜度仍属于同一 TS owner。既有 Python 代码只传输字段,符合 TS-first RFC 的适配器边界,没有新增平行决策源。
具体改动
关键代码讲解
build_codex_app_compatibility_projection不再固定改成旧键;backoff、host facts、ACK/failure 命令共享 App packet 的实际键。宿主 schema/surface 可以转换,状态权威不可以。_SchedulerHintBuilder采用已验证状态的实际键,common 优先,旧键独存时保留旧 scope。不能把已有非零档位当作空 common state 的首次 ACK。load_app_automation_scheduler_state只纠正注释,不新增迁移。_followup_state_key和record_quota_scheduler_ack保留未传参语义并从当前 packet 取键;显式键不静默重定向。validate_quota_command_context_request不再提前给 Codex 注入旧键,Trae 的 common-only 校验不变。- 新测试贯穿真实 should-run、同一 Turn、TS state store、生成 launcher 命令和独立读回,覆盖三种存储布局、ACK/failure、原生/API/手工 CLI,并断言旧 sibling 未改写。双语文档披露默认变化、无隐式迁移及状态归属。
对主干的风险
主要兼容风险是外部脚本硬编码旧 namespace 而不消费 packet 的 state_key;此变化已明确披露。仓库内可达入口均已覆盖,已有 Codex schema 与持久旧状态保留。错误显式键仍拒绝,旧状态独存仍能合法推进,没有靠全面禁用旧路径变绿。新身份非零首次档位、跨档、过期 Turn、CAS 与 replay 保护均未放松。
语义与 CI 对齐
复用已有 vocabulary 与 TS owner,不新增权限或 work admission 规则。同一回归源 SHA 在不可变基线 8636bbd 上有18项失败、1项通过,coexisting 原生命令复现初始档位冲突及相等 CAS 摘要。候选入口/当前宿主28项、其余 Python48项、原生 TS51项通过。标准 premerge 的5项直接检查与19项 canary 全部执行通过、零跳过;首次缺少 npm 开发依赖已安装并原样重跑,没有豁免失败。当前评审契约不查询或等待远端 CI。
我的整体评价
APPROVE:长期推进与用户路径均有实测改善,既有合法旧状态得以保留,重复执行和错误写入仍由统一 TS 事务把关。生产规模适当,参数矩阵集中覆盖回归,没有增加配置、状态日记或第二 writer。无新前端配置字段,受影响的是现有 host/CLI/API 路径,不能声称真人宿主已验收。剩余是 maintainer 合并、安装后以新鲜 hint 核对真实 Agent;这份 core 控制面 PR 不自合并,Effect 延迟仍为独立事项。
English verdict: APPROVE - exact head f571573. Preserves the TS-validated scheduler read scope across generated Codex hints and omitted-key callers, including legacy-only continuation, without weakening reset/CAS/receipt guards. Identical baseline:18 failures/1 pass; head entry/current-host:28 passes; other Python:48; native TS:51; standard premerge:5 direct +19 canaries pass. Maintainer merge and actual adoption remain separate.
问题 / Problem
app_automationreads the current common scheduler state, but the Codex compatibility projection rewrote itsstate_keyto the obsolete Codex namespace. With both states retained, a legitimate stage-1 ACK/failure could therefore fail withinitial_progression_index_conflictdespite equal CAS digests. The generated host command was scoped to the wrong state, not a racing writer.仅有旧状态时同样不能把其非零档位直接写入空 common state;那会把 continuation 误当首次 ACK。
修复 / Repair
语言边界:改动位于既有 Python compatibility transport,传递 TS 已验证的状态 scope;scheduler transition、决策校验和 durable write 仍由既有 TS owner 完成,没有新增 Python 决策源。
验收 / Validation
8636bbd8c: real generated native ACK with coexisting state reproduced the original initial-stage conflict and equal CAS digests before the fix.git diff --checkpass. Standard premerge at exact headf571573f48c778436b50ee50257e8a7e8fec2474: 5 direct checks + 19 selected/executed canaries, zero failures/skips. The initial missing npm dev dependency was repaired withnpm ci --ignore-scriptsand the complete gate rerun; no gate was waived. Validation passing is not self-merge authority.用户路径与边界 / Product boundary
Changed entry points are managed host-generated follow-up CLI, manual Codex CLI and in-process compatibility APIs. The regression runs the emitted receipt-bound command through
scripts/loopxwith Python deliberately unavailable, then reads real durable state; it is not a mocked projection-only test.No frontend settings or capability-editor field changes are needed: there is no new user configuration. Existing host consumers receive the same typed packet with the corrected scope. No frontend build or live automation update is claimed. Merge, installation and real-agent recovery remain separate adoption steps; this core control-plane change is left for maintainer review/merge.