Skip to content

chore(release): prepare v1.2.2 - #5221

Merged
huangruiteng merged 2 commits into
mainfrom
codex/release-v1.2.2
Sep 27, 2026
Merged

huangruiteng merged 2 commits into
mainfrom
codex/release-v1.2.2

Conversation

@huangruiteng

@huangruiteng huangruiteng commented Sep 27, 2026 •

Copy link
Copy Markdown
Collaborator

LoopX 1.2.2 improves App conversation recovery, delegation result continuity and local authority replay. It also makes configuration targets explicit and keeps rollout boundaries visible.

Release Decision

Who should upgrade: Users of App Chat, local delegation, File/SQLite authority or Codex App heartbeats on 1.2.1.

What this release solves: Interrupted accepted Chat requests can recover their missing durable writes; late delegated results stay in the original conversation; identical local commits recover their original proof instead of failing. Settings identify the exact device, Goal and Agent target. #5139 #5170 #5169 #5215 #5186 #5187

Breaking changes: No new CLI signatures or automatic provider migration. Intentional changes: CLI/App usage statistics activate after visible first disclosure (explicit disable persists); the interval editor starts in per-Agent scope; identical File/SQLite retry may report applied/applied while persisting one transaction. See the activation/privacy entries below. #5190 #5186 #5169

How to verify: Install the named version using your current installation owner, check the version and doctor, then inspect the desired workflow’s status.

python3 -m pip install --upgrade 'loopx==1.2.2'
loopx --version
loopx doctor --deep
loopx update check

Contributors: @Duang777, @LIHUA919, @gcl-coder, and first-time contributors @hhe48203-ctrl and @karenchuu; concrete contributions and links are below.

State Kernel & Control Plane

  • Exact File/SQLite operation retries validate the complete original intent and retained proof, return the historical cursor/revision and leave later head state intact. The integrated SQLite streaming-verifier repair preserves changed-intent and corruption refusal. PostgreSQL/NoKV retain their direct-commit conflict/readReceipt behavior. #5169 #5215

  • Reviewed provider transitions retain the current handoff mode or explicitly review hard-lease migration, and bounded source outbox drain has one typed batch owner with complete lineage/source witnesses. These are explicit operator workflows, not automatic cutover. #5173 #5175

  • Canonical first completion retains its pinned validator; an accountable in-flight Turn may settle without declaring its Todo complete; scheduler compatibility carries the authoritative state key through ACK/failure. #5192 #5184 #5219

  • Goal-scoped quota status/plan retain the selected Goal and cache identity, expose observation coverage/freshness, reject unknown Goals and keep shared/global health failures visible. Omitting the selector preserves the global view; no latency or execution-admission claim is made. #5220

Capabilities & Workflows

  • Managed App Chat repairs interrupted acceptance with the original request identity, exact durable-prefix proof and dispatch deduplication. App transport recovery retries transient failures once; delayed delegation returns survive session replacement without another model turn. #5139 #5170
  • Independent delegation requires canonical validation. Preflight preserves the exact Todo’s quota refusal and explains a turn_blocked result; existing-peer requests resolve the exact host route. Reading or returning a result still does not establish adoption. #5185 #5188 #5183
  • Capabilities settings share one navigation entry with explicit Device/Goal ownership; interval settings show every available Agent and discard stale previews on target changes. Usage statistics now disclose once through the visible CLI/App entry before subsequent measurement. #5187 #5186 #5190

Quality & Testing

  • The existing Codex runtime-profile regression now checks the selected canonical state key and matching ACK authority, while retaining legacy-only coverage and old schema labels. #5225

  • Equal-source native qualification profiles now have separate HOME-scoped temporary files and runtime locators during installation and later calls; a real two-profile test proves that stopping one leaves the other running. #5226

  • The existing Widesearch app-server privacy regression now requires those profile-scoped temporary variables even when external temporary settings are inherited, while retaining exact credential exclusion. #5231

  • Formal native-profile qualification stops its own managed runtime before temporary directory removal, preserving provider/privacy and app-server assertions. The retained Goal continuity design record now follows the canonical bilingual lifecycle/index contract while deferred delivery remains explicit. #5224

  • Issue-Fix metrics supplements and status carriers reuse their canonical vocabulary owners; raw remote-location detection has one safety owner while surface-specific local-path policies remain separate. #5168 #5195 #5196

  • Module-count regression coverage and the registry access census guard current architecture. Release preparation reconciles the measured compatibility-import cost without new public names: 119 is accepted, 120 still fails, and the source-module ceiling stays at 50. #5191 #5193 #5221

Benchmarks & Integrations

  • An explicitly opted-in steward group may respond to verified new human messages without @. Existing addressed-only connections, historical backfill, bot exclusion and worker-Topic priority retain their boundaries. #5189
  • Lark post-writeback diagnostics retain the send/readback/persistence failure stage and delivery uncertainty while preserving the business settlement identity and debit count. This does not qualify live group delivery or change sink retry authority. #5194

Documentation & Compatibility

  • The canonical CLI catalog/manual include the shipped exact peer route read; generated manual and bilingual Developer Book baselines agree with 1.2.2. Existing completeness checks remain enforced. #5223

  • SQLite/archive replay reuses already-owned state while retaining verification; measured read-path improvements do not close all many-field latency targets, sustained-memory or elapsed-soak qualification. SQLite remains opt-in; File stays the fallback. #4931

  • Authority retirement checkpoints distinguish merged cutover/drain work, remaining Goal consumer closure, profile qualification and default-entry adoption. Remaining writers retire with their last callers, not a PR-count target. #5197

  • Recent completion previews select the newest completed work across loaded active Goals by completion time, with invalid/deferred/monitor rows excluded. It does not retrieve stopped or unloaded Goals. #5218

Community Contributors

  • @Duang777 — Recoverable App request acceptance and identical File/SQLite operation replay. #5139 #5169
  • @LIHUA919 — External community contributor. Reuse already-owned state during SQLite and archive replay while keeping proof checks. #4931
  • @gcl-coder — External community contributor. Single-source the Issue-Fix metrics supplement vocabulary. #5168
  • @hhe48203-ctrl — External community contributor. First contributions to LoopX. Resolve the exact host route for requests to existing peers. #5183
  • @karenchuu — External community contributor. First contributions to LoopX. Guard the top-level module budget, consolidate status carriers and centralize raw-location safety classification. #5191 #5195 #5196

Compatibility & Upgrade

Package 1.2.2, tag v1.2.2, source ee9dad81b14c6d15d32b95851b5d38fcc485e732. Python 3.11+ and Node 22.22.3+ remain required. Use loopx update check, then loopx update plan and the reported owner’s loopx update apply; source checkouts remain development installations. Package installation, host material delivery and running service activation are separate readbacks. See versioned installation guidance.

No benchmark uplift or production long-horizon completion is claimed, so the matched outcome-baseline experiment is not required. Full managed/attached multi-cycle team adoption, SQLite default activation/10-day soak and PostgreSQL deployed-tenant switching remain separate qualification. Preserve live writer fences, canonical history and private configuration during update or rollback.

Validation

Exact clean source ee9dad81b14c6d15d32b95851b5d38fcc485e732 passes all eight release qualifications. Final-source official CI JUnit test cases: 12,885 passed, 0 failed, 65 skipped; all 514 public smokes pass through the final-source official CI under their original budgets; all 19 selected premerge checks pass, and the conservative benchmark-fixture path review is explicitly completed. Ruff, mypy, public-boundary scan, actual install/1.2.1 upgrade/sdist rebuild/Host material and packaged Chat HTTP pass. The actual doubao-seed-2-1-pro-260628 qualification passes 21 scenarios twice, 6 contrasts and 42 actor calls, with no failures or skips. The installed package passes 21 browser scenarios and five Python 3.11 checks. The optional native Codex Goal live probe is skipped because an isolated API profile is unavailable, as permitted by the testing guide; no live pass is claimed for it. These source qualifications do not claim benchmark improvement or production long-horizon completion. Post-publication verification passes: wheel/sdist and all four Mac/Windows desktop artifacts have matching checksums and GitHub build attestations for this tagged source; PyPI distributions match the attested GitHub bytes, and a fresh Python 3.11 PyPI install passes deep doctor, packaged Chat HTTP and Host material install/uninstall. The macOS updater signature verifies with the shipped public key, its feed matches desktop-stable, stable points at the tagged source, and the deployed homepage, installer and bilingual docs read back successfully. All seven qualifying CI/publication runs pass on the tagged source. The first full-public attempt failed during disposable native-profile cleanup; the unchanged-source full five-shard rerun passes under the same budgets. The initial failure is retained at the original workflow; this rerun does not establish elimination of that intermittent validation-fixture race. Published wheel/sdist checksums and GitHub attestations match this source; PyPI and GitHub bytes agree. Four desktop artifacts pass checksums and attestations. The shipped updater key verifies the signature, and the stable feed matches. A fresh Python 3.11 PyPI install passes version, doctor, Chat HTTP and workflow-skill install/uninstall. The same-source official PostgreSQL Integration workflow passes against a real isolated PostgreSQL 16.15 server, including store conformance and service admission; this is not a deployed tenant or live Goal cutover.

Optional Capability Activation & Use

Use the actual GOAL_ID and registered AGENT_ID from your own configuration in commands below. Preview and readback do not grant mutation authority.

Usage Statistics

Activation: CLI and App now share visible first disclosure → automatic activation → later measurement. The first disclosure sends nothing. Open App Settings → Basic usage statistics, or read status and explicitly enable after reviewing the notice. Previously disabled installations remain off.

Validation: Read recipient, policy and bounded payload previews:

loopx usage-ping status
  # Explicit opt-in after reading the notice:
loopx usage-ping enable

Disable / rollback: loopx usage-ping disable clears the local ID and pending counts for all channels. LOOPX_USAGE_PING=0 or DO_NOT_TRACK=1 suppresses collection in that process; the stored disable remains persistent.

Authority boundary: The channels use bounded installation, feature and Goal-duration buckets. They do not send message text, prompts, file contents, commands, paths or Goal identifiers. App clicks are outside collection scope; disclosure is not authority to grant tools or change a Goal.

Docs: Read the versioned policy and recipient before enabling. Versioned docs.

Scoped App Settings

Activation: Run the dashboard and open Settings → Capabilities. Explicitly choose Device or the intended Goal before editing. Automatic interval settings now start at per-Agent scope: select the Agent from the complete list, preview and apply to that target; Goal-wide scope remains available.

Validation: Reopen the same target and check its effective source and values. Use the existing read-only CLI projections:

loopx dashboard --no-open
  # In a second terminal, with your actual Goal:
loopx capability list --goal-id "$GOAL_ID"
loopx quota status --goal-id "$GOAL_ID"

Disable / rollback: Discard an unapplied draft without applying its preview. For a saved setting, restore its previously recorded value through the same scope editor and preview/apply/readback; use that capability’s existing disable control. Switching scope does not write configuration.

Authority boundary: Device defaults and Goal overrides retain separate owners. Unsupported or read-only scopes stay non-editable. Interval changes retain quota/CAS/reduction gates and do not directly update an existing Codex App timer.

Docs: The RFC documents supported scopes and the existing editor journey. Versioned docs.

App Conversation Recovery

Activation: Use an already configured local managed Agent conversation in loopx dashboard. There is no new persistent switch. Managed acceptance retries transport/5xx/transient adapter failures once using the original client_turn_id; late delegation returns remain visible after session replacement.

Validation: Open the original conversation and inspect the saved request/result. Basic local readback:

loopx dashboard --no-open
  # In a second terminal after startup:
curl -fsS http://127.0.0.1:8767/chat/ >/dev/null
curl -fsS http://127.0.0.1:8767/status.json

Disable / rollback: Stop the local dashboard process to stop this UI. Preserve conversation storage. Do not create a new request identity to recover an uncertain prior acceptance; for a package rollback follow the reported installation-owner plan and preserve data.

Authority boundary: Recovery repairs the exact durable prefix and deduplicates dispatch; it is not another model execution, delegated acceptance or recipient adoption. Attached routing, external permissions and full multi-cycle team qualification retain their existing boundaries.

Docs: The conversation RFC records continuity and incomplete journey gates. Versioned docs.

Local Delegation

Activation: Keep an operator-owned binding outside member workspaces with exact requester, worker, Todo, host and output refs. Covered tasks need current owner acceptance; independent tasks outside that scope need a canonical Todo validator declared via todo add --validation-command-json. Register the existing ignored Goal-relative execution-config pointer only after preview.

Validation: Set GOAL_ID, AGENT_ID and DELEGATION_CONFIG to your existing authorized configuration. Inspection launches no host:

loopx delegation inspect --goal-id "$GOAL_ID" --agent-id "$AGENT_ID" \
  --execution-config "$DELEGATION_CONFIG" --binding-id independent-review
loopx agent-context --goal-id "$GOAL_ID" --agent-id "$AGENT_ID" --phase before_plan

After a deliberate start, read the same operation; accepted results and hashes still need receiver adoption.

Disable / rollback: Remove the exact binding from the operator file to revoke execution/accepted-return admission. loopx configure-goal --goal-id "$GOAL_ID" --clear-subagent-execution-config --execute removes only the planning pointer, not the grant or retained operation history.

Authority boundary: Registration/readiness/peer messages do not grant execution. Quota refusal remains turn_blocked on the exact Todo; do not retarget work or bypass the scan. Canonical completion, pinned validators, unchanged artifacts and adoption remain distinct.

Docs: Use the reference for start/read/wait, canonical validators and adoption. Versioned docs.

Reviewed Local Authority and Replay

Activation: File remains the selected local-provider fallback; no existing Goal is automatically migrated. On an explicitly enabled, bootstrapped and qualified disposable shadow, promotion remains a per-command owner operation. Choose preserve/hard-lease migration in the preview and keep that saved plan unchanged.

Validation: Read-only preview/readback; use a real qualified Goal and review the saved result before any --execute:

loopx coordination-shadow inspect --goal-id "$GOAL_ID"
loopx coordination-shadow promote --goal-id "$GOAL_ID" \
  --minimum-operations 3 --require-event-kind todo_update --format json > reviewed-promotion.json
loopx coordination-shadow promote --goal-id "$GOAL_ID" --reviewed-plan reviewed-promotion.json

Disable / rollback: Before execution, abandon the unused saved plan and omit --execute; no cutover occurs. After a committed/fenced transition, do not delete a fence or restore old Markdown. Use coordination-shadow recover-promotion --goal-id "$GOAL_ID" --reviewed-plan reviewed-promotion.json to preview original-transaction recovery; post-cutover rollback is not automatically provided.

Authority boundary: File/SQLite identical retries return the original receipt/cursor after complete-intent and retained-proof checks, without rewinding the live head or reauthorizing effects. PostgreSQL/NoKV keep their direct conflict/readReceipt contract. SQLite’s default rollout/soak and PostgreSQL tenant authority remain separate gates.

Docs: The versioned guide covers qualification, bounded drain, source drift and forward recovery. Versioned docs.

Authority Archives

Activation: Explicit per-command export/verify/restore; no persistent switch. Use the existing source Goal registry/runtime; export refuses to overwrite a file. Restore only into a new isolated destination after reviewing the Goal and verified archive digest.

Validation: Use your source Goal and a writable private destination directory:

loopx authority-archive export --goal-id "$GOAL_ID" --archive ./authority.ndjson
loopx authority-archive verify --archive ./authority.ndjson

The reported archive_sha256 is the verified record chain/seal, not raw file SHA-256.

Disable / rollback: Do not invoke export/restore to keep this workflow inactive. Omit --execute on restore for preview only. Abandon an unused preview or isolated copy under your retention policy; never adopt it or replace the live selector as an automatic rollback.

Authority boundary: The archive is private canonical history, not registry/quota/host/external artifact backup. Verification/replay grants no execution lease, promotion or provider switch; restored revisions belong to the new store incarnation.

Docs: The reference defines export pins, interrupted restore and corruption refusal. Versioned docs.

Lark Steward Groups

Activation: Requires the explicitly activated bundled loopx-lark provider and Lark app permission to receive all group messages. In App Settings → Lark → steward connection → When to respond, choose Respond to group members without @ and save for that one connection.

Validation: Reopen the connection and read back routing.turn_trigger=human_messages. From the running local dashboard:

curl -fsS http://127.0.0.1:8767/api/chat/lark/connections

Check the actual provider/listener health before relying on live delivery; synthetic CI is not evidence of messages sent in your group.

Disable / rollback: Select Only when mentioned or replied to and save/read back routing.turn_trigger=addressed. To disable the provider, use loopx extension disable loopx-lark --execute; stop its separately configured collector service as documented.

Authority boundary: Existing connections remain addressed-only. Verified new human senders may trigger in the opted-in group; historical backfill, bots and unknown unaddressed senders do not. Worker Topics keep priority. Capture does not grant tool, delegation, other-group or recipient permissions.

Docs: The reference includes provider activation, listener setup and exact no-mention scope. Versioned docs.

Codex App Scheduler Compatibility

Activation: Use the existing explicitly approved Codex App heartbeat bootstrap for your registered Goal/Agent. This fix adds no switch: generated ACK/failure commands preserve the typed scheduler’s actual authoritative state key; legacy-only state retains its own scope.

Validation: Read the current packet and follow its exact emitted command instead of reconstructing a receipt:

loopx quota should-run --goal-id "$GOAL_ID" --agent-id "$AGENT_ID" \
  --runtime-profile codex_app_heartbeat
loopx quota status --goal-id "$GOAL_ID"

Disable / rollback: Pause the Goal through loopx goal-lifecycle --goal-id "$GOAL_ID" --operation stop --actor-kind owner --execute; read quota again and let the host honor the resulting pause/delete directive. This does not forcibly kill a tool already running.

Authority boundary: The fix preserves TS transition ownership, CAS/freshness/identity/reset checks and spend rules. A compatibility alias does not create scheduler authority, change a timer or grant automatic execution; no pre-model host qualification is inferred.

Docs: The guide covers approved bootstrap, readback and stopping the heartbeat. Versioned docs.

Scoped Quota Observation

Activation: Opt in per read with --goal-id; no configuration write or new capability activation is needed.

Validation: Use your registered Goal and inspect the scope/freshness envelope:

loopx quota status --goal-id "$GOAL_ID" --format json
loopx quota plan --goal-id "$GOAL_ID" --format json

Disable / rollback: Omit --goal-id to return to the existing global observation. No state or envelope needs removal; use the installation-owner rollback plan if rolling back the package.

Authority boundary: The selector scopes a read-only observation and its cache; it does not grant a lease, spend, schedule, promotion or mutation. Global/shared health failures remain visible; an unknown Goal is an actionable error, not an empty success. Scoped rankings are not a global next-turn decision.

Docs: The quota contract describes scoped observations and their coverage boundary. Versioned docs.

Isolated Codex Qualification Profiles

Activation: Opt in per invocation on a clean source checkout with Codex available. This creates a disposable formal installation; it does not enable a model worker or benchmark job.

Validation: Run the existing installed-profile qualification and inspect its provider/privacy, skills and Goal readback:

uv run --extra test python examples/benchmark-native-goal-installed-profile-smoke.py --require-app-server

The installer and subsequent profile CLI/app-server calls use native_codex_profile_environment, including HOME-scoped TMPDIR/TMP/TEMP. Equal-source profiles keep separate runtime locators.

Disable / rollback: Omit the command to leave the workflow inactive. The smoke stops its owned runtime before automatic temporary-directory cleanup. For a retained profile, quiesce all its callers, invoke its installed CLI doctor --installation-only --restart-runtime with native_codex_profile_environment(profile), require stopped or not_running, then remove only that profile. Incomplete shutdown remains a failure.

Authority boundary: The temporary namespace grants no production Goal mutation, shared-runtime shutdown, upstream credentials, model spend, benchmark launch or OS/network sandbox. Actual model workers still require the documented provider gateway and OS isolation; environment isolation alone does not grant those boundaries.

Docs: Use the versioned provider reference for formal installation, environment ownership and teardown. Versioned docs.

中文摘要

LoopX 1.2.2 改善 App 会话中断恢复、委派结果连续性与本地权威重放;设置明确设备、Goal 和 Agent 范围,并保留 rollout 门禁。

升级决策

谁需要升级: 使用 1.2.1 的 App Chat、本地委派、File/SQLite 权威或 Codex App heartbeat 用户。

解决了什么: 已接受请求可修补中断的持久写入,迟到的委派结果回到原会话,同意图本地提交恢复原证明;配置目标更明确。#5139 #5170 #5169 #5215 #5186 #5187

是否有破坏性变更: 无新增 CLI 签名或自动 provider 迁移。有意改变:CLI/App 使用统计在可见首次告知后启用(已有明确停用保持);间隔编辑器默认逐 Agent;File/SQLite 同意图并发重试可均报告 applied,实际只写一次。下方说明启用、停用与隐私边界。#5190 #5186 #5169

如何验证: 按当前安装 owner 安装指定版本,读回版本、doctor,再检查所需工作流状态。

python3 -m pip install --upgrade 'loopx==1.2.2'
loopx --version
loopx doctor --deep
loopx update check

贡献者: @Duang777、@LIHUA919、@gcl-coder,以及首次贡献的 @hhe48203-ctrl 和 @karenchuu;下方列出具体贡献与 PR。

状态内核与控制面

  • File/SQLite 精确重试校验完整意图与留存证明,返回历史 cursor/revision,不倒退当前 head;SQLite streaming verifier 集成修复保留漂移与损坏拒绝。PostgreSQL/NoKV 普通重复提交仍用冲突/readReceipt。#5169 #5215

  • reviewed transition 保留当前 handoff mode 或明确审阅 hard-lease 迁移;outbox drain 复用单一 typed batch owner 和完整来源/事务证明,不自动切换。#5173 #5175

  • 首次规范完成绑定原校验;有可核对进展的 in-flight Turn 可结算而不完成 Todo;scheduler 兼容 ACK/failure 保留实际权威 state key。#5192 #5184 #5219

  • quota status/plan 保留指定 Goal 与缓存身份,公开查询覆盖/新鲜度、拒绝未知 Goal,并继续呈现共享/全局健康失败;省略选择器保持全局读取。不宣称延迟改善或新增执行准入。#5220

能力与工作流

  • managed App Chat 用原请求标识、精确持久前缀证明和 dispatch 去重恢复验收;暂态传输失败重试一次,替换会话后仍显示迟到委派结果,不再次调用模型。#5139 #5170
  • 独立委派须规范校验;预检保留精确 Todo 的 quota 拒绝并解释 turn_blocked,既有 peer 请求解析精确宿主路由。读回和返回仍不代表采纳。#5185 #5188 #5183
  • 能力设置统一入口并明确设备/Goal owner;间隔编辑器显示全部 Agent,换目标撤销旧预览;统计先在可见 CLI/App 告知,再采集后续使用。#5187 #5186 #5190

质量与测试

  • Codex runtime-profile 既有回归改为检查选中的 canonical 状态键和 ACK 相同权威,保留 legacy-only 覆盖及旧 schema label。#5225

  • 相同源码的 native 资格 profile 在安装及后续调用中采用各自 HOME 范围的临时目录与 runtime locator;真实双 profile 验证停止其中一个后另一个仍运行。#5226

  • Widesearch 现有 app-server 隐私回归现要求这些 profile 范围的临时变量,即使继承了外部临时目录设置,也继续严格排除上游凭证。#5231

  • 正式 native profile 验证在删除临时目录前停止自己创建的 runtime,保留 provider/隐私和 app-server 断言;Goal 连续性设计记录补齐双语生命周期/目录合同,仍明确尚未交付的边界。#5224

  • Issue-Fix 与 status 常量复用规范词汇 owner;原始远程地址检测统一 owner,各表面的本地路径策略仍分开。#5168 #5195 #5196

  • 模块数量与 registry census 约束当前架构;发布准备按实测兼容导入成本调整到 119,没有新公开名称或余量,120 仍拒绝,来源模块上限保持 50。#5191 #5193 #5221

基准与集成

  • 显式启用的管家群可响应经验证的新 human 消息而无需 @;既有寻址模式、历史补采、bot 排除和 worker Topic 优先级保留。#5189
  • Lark 写回后诊断保留发送/读回/持久化失败阶段与送达不确定性,不改变业务结算标识或扣额次数;不宣称真实群送达或改变 sink 重试权限。#5194

文档与兼容性

  • 既有 CLI 目录/手册补齐精确 peer 路由读取;生成手册与双语 Developer Book 基线一致为 1.2.2,原有完整性检查保持执行。#5223

  • SQLite/归档重放复用已有状态并保留校验;实测改善不关闭所有 many-field 延迟、持续内存或 elapsed soak 资格。SQLite 仍 opt-in,File 仍为 fallback。#4931

  • 权威退役 checkpoint 区分已合入切换/drain、Goal 消费者闭合、profile 资格与默认入口;writer 随最后调用方退出,不按 PR 数量宣布完成。#5197

  • 最近完成预览按完成时间跨已加载 active Goal 排序,排除无效/deferred/monitor 项;不获取已停止或未加载 Goal。#5218

社区贡献者

  • @Duang777:App 请求验收恢复与 File/SQLite 同意图操作重放。 #5139 #5169
  • @LIHUA919:外部社区贡献者。 SQLite 和归档重放复用已有状态,同时保留证明校验。 #4931
  • @gcl-coder:外部社区贡献者。 统一 Issue-Fix metrics supplement 词汇来源。 #5168
  • @hhe48203-ctrl:外部社区贡献者。 首次向 LoopX 贡献。 为既有 peer 请求解析精确宿主路由。 #5183
  • @karenchuu:外部社区贡献者。 首次向 LoopX 贡献。 守护顶层模块预算、合并 status 常量来源并统一原始地址的安全分类。 #5191 #5195 #5196

兼容性与升级

包 1.2.2、标签 v1.2.2,源码 ee9dad81b14c6d15d32b95851b5d38fcc485e732;继续要求 Python 3.11+、Node 22.22.3+。先 loopx update check、loopx update plan,再遵从当前安装 owner 执行 loopx update apply;包安装、host 材料与运行服务须分别读回。版本化安装指南。

不宣称 benchmark 提分或生产长时程完成,因此无需昂贵的 matched outcome baseline。完整 managed/attached 多轮团队采纳、SQLite 默认启用/十天 soak 与 PostgreSQL 部署租户切换保留独立资格;更新或回退时保留 live fence、规范历史与私有配置。

验证

同一干净提交 ee9dad81b14c6d15d32b95851b5d38fcc485e732 通过全部八项发布资格。最终提交官方 CI JUnit 测试用例:12,885 通过、0 失败、65 跳过;514 项公共 smoke 在官方 CI 原预算下通过,全部 19 项 premerge 检查通过,benchmark fixture 路径的保守人工评审门禁已明确完成。Ruff、mypy、公开边界扫描、实际安装/1.2.1 升级/sdist 重建/Host 材料及打包 Chat HTTP 通过。真实 doubao-seed-2-1-pro-260628 验证 21 个场景各两次、6 个对照、42 次 actor 调用,零失败、零跳过。同源已安装包通过 21 项浏览器场景与 5 项 Python 3.11 检查。可选的 native Codex Goal live probe 因独立 API profile 不可用而按测试指南跳过,不宣称其真实执行通过;这些资格不等于 benchmark 提分或生产长时程完成。发行后独立读回通过:wheel/sdist 与全部四个 Mac/Windows 工件的校验和及 GitHub 构建证明绑定同一 tag 源码;PyPI 分发包与 GitHub 已证明的文件一致,全新 Python 3.11 PyPI 安装通过 deep doctor、打包 Chat HTTP 与 Host 材料安装/卸载。macOS updater 用随包公钥验签通过,feed 与 desktop-stable 一致,stable 指向该 tag 提交;线上首页、安装脚本及中英文文档读回通过,七个同源 CI/发布资格运行通过。 全量公共 smoke 首次运行在可丢弃 native profile 的清理阶段失败;同一源码、相同预算的完整五 shard 重跑通过。原始 workflow 的失败保留,重跑通过不表示已彻底消除该验证 fixture 的偶发竞态。 发行后的 wheel/sdist 校验和及 GitHub attestation 匹配该源码,PyPI 与 GitHub 工件字节一致;四个桌面工件的校验和与 attestation 通过,发布的 updater 公钥验证签名,stable feed 一致。全新 Python 3.11 PyPI 安装通过版本、doctor、Chat HTTP 与 workflow skill 安装/卸载。 同源官方 PostgreSQL Integration 在真实隔离的 PostgreSQL 16.15 服务通过 store conformance 与 service admission;这不代表部署租户或生产 Goal 切换。

可选能力启用与使用

命令中的 GOAL_ID 与已注册 AGENT_ID 使用你自己的实际配置;预览和读回不授予写入权限。

Usage Statistics

启用: CLI 与 App 共用“先可见告知→自动启用→后续测量”。首次告知不发送数据;在 App 设置的基础使用统计中读取说明,或先读 status 后显式 enable。之前明确停用的安装保持停用。

验证: 读取接收方、策略和有界载荷预览:

loopx usage-ping status
  # 阅读告知后显式启用:
loopx usage-ping enable

停用 / 回退: loopx usage-ping disable 删除所有通道的本机 ID 和待发计数;LOOPX_USAGE_PING=0 或 DO_NOT_TRACK=1 抑制当前进程采集,保存的停用决定持续有效。

权限边界: 仅包含有界安装、功能及 Goal 时长分桶,不发送消息正文、prompt、文件正文、命令、路径或 Goal 标识;不采集 App 点击。告知不授予工具或 Goal 修改权。

文档: 启用前阅读版本化策略与接收方。 版本文档。

Scoped App Settings

启用: 启动 dashboard,在设置→能力中明确选择设备或目标 Goal 再编辑。自动间隔默认进入逐 Agent 范围:从完整列表选 Agent,预览后应用;仍可切换整个 Goal 范围。

验证: 重新打开同一对象读回有效来源和值;CLI 只读投影:

loopx dashboard --no-open
  # 另一终端中使用实际 Goal:
loopx capability list --goal-id "$GOAL_ID"
loopx quota status --goal-id "$GOAL_ID"

停用 / 回退: 未应用的草稿可直接放弃;已保存设置通过相同范围编辑器恢复此前记录的值,预览、应用并读回。使用该能力既有停用开关;切换范围本身不写配置。

权限边界: 设备默认值和 Goal 覆盖仍由不同 owner 管理;不支持或只读范围不可编辑。间隔保留 quota/CAS/减少间隔门禁,不直接修改既有 Codex App timer。

文档: RFC 记录支持范围与既有编辑路径。 版本文档。

App Conversation Recovery

启用: 在 loopx dashboard 中使用已经配置的本地 managed Agent 会话,无新增持久开关。managed 验收遇到传输、5xx 或暂态 adapter 故障时沿用原 client_turn_id 重试一次;替换会话后仍显示迟到的委派结果。

验证: 打开原会话检查保存的请求与结果,基本本机读回:

loopx dashboard --no-open
  # 启动后在另一终端执行:
curl -fsS http://127.0.0.1:8767/chat/ >/dev/null
curl -fsS http://127.0.0.1:8767/status.json

停用 / 回退: 停止本机 dashboard 进程即可停用界面,保留会话存储。恢复不确定的旧验收时不要创建新请求标识;包回退遵从安装 owner 的计划并保留数据。

权限边界: 恢复修补精确的持久前缀并去重 dispatch,不是再次执行模型、委派验收或接收方采纳。attached 路由、外部权限及多轮团队资格保持原边界。

文档: 会话 RFC 记录连续性与尚未关闭的产品门禁。 版本文档。

Local Delegation

启用: operator binding 位于成员 workspace 之外,固定 requester、worker、Todo、host 和输出引用。范围内任务保留当前 owner 验收;范围外独立任务通过 todo add --validation-command-json 声明规范 Todo 校验。既有已忽略的 Goal 相对配置指针先预览再保存。

验证: 将 GOAL_ID、AGENT_ID、DELEGATION_CONFIG 设为已有授权配置;预检不启动 host:

loopx delegation inspect --goal-id "$GOAL_ID" --agent-id "$AGENT_ID" \
  --execution-config "$DELEGATION_CONFIG" --binding-id independent-review
loopx agent-context --goal-id "$GOAL_ID" --agent-id "$AGENT_ID" --phase before_plan

显式启动后读回原 operation;接受结果与哈希仍须接收方采纳。

停用 / 回退: 从 operator 文件移除精确 binding 撤销执行与接受结果返回准入。loopx configure-goal --goal-id "$GOAL_ID" --clear-subagent-execution-config --execute 只删除规划指针,不撤销 grant 或历史。

权限边界: 注册、ready 或 peer 消息不授予执行权;精确 Todo 的 quota 拒绝保持 turn_blocked,不可换任务或绕过扫描。规范完成、固定校验、产物未变和采纳保持不同状态。

文档: 参考文档给出 start/read/wait、规范校验与采纳。 版本文档。

Reviewed Local Authority and Replay

启用: 未选择本地 provider 时仍采用 File,不自动迁移既有 Goal。在显式开启、bootstrap 且已合格的可丢弃 shadow 中,promotion 仍是逐命令的 owner 操作;在预览选择 preserve/hard-lease 并保留原计划。

验证: 使用实际合格的 Goal 进行只读预览;任何 --execute 前审阅保存的结果:

loopx coordination-shadow inspect --goal-id "$GOAL_ID"
loopx coordination-shadow promote --goal-id "$GOAL_ID" \
  --minimum-operations 3 --require-event-kind todo_update --format json > reviewed-promotion.json
loopx coordination-shadow promote --goal-id "$GOAL_ID" --reviewed-plan reviewed-promotion.json

停用 / 回退: 执行前放弃未使用的保存计划、不加 --execute 即不发生切换。已提交或保留 fence 后不可删 fence 或恢复旧 Markdown;使用 coordination-shadow recover-promotion --goal-id "$GOAL_ID" --reviewed-plan reviewed-promotion.json 预览原事务恢复,不提供自动切换后回退。

权限边界: File/SQLite 同意图重试先校验完整意图和留存证明,再返回原回执/cursor,不倒退当前 head 或再次授权 effect。PostgreSQL/NoKV 保留冲突/readReceipt 合同;SQLite 默认 rollout/soak 与 PostgreSQL 租户授权仍有独立门禁。

文档: 版本化指南涵盖资格、有界 drain、来源漂移及前向恢复。 版本文档。

Authority Archives

启用: export/verify/restore 显式逐命令使用,没有持久开关。使用原 Goal registry/runtime,export 不覆盖文件;审阅 Goal 和已验证归档摘要后,仅恢复到新建的隔离目录。

验证: 使用来源 Goal 和可写的私有目标目录:

loopx authority-archive export --goal-id "$GOAL_ID" --archive ./authority.ndjson
loopx authority-archive verify --archive ./authority.ndjson

返回的 archive_sha256 是已验证记录链/seal,不是文件字节 SHA-256。

停用 / 回退: 不调用 export/restore 即不启用此工作流;restore 不加 --execute 只预览。按留存策略放弃未使用预览或隔离副本,不把它自动采纳或替换 live selector 作为回退。

权限边界: 归档是私有规范历史,不是 registry/quota/host/外部产物备份;验证或重放不授予执行 lease、promotion 或 provider 切换权,恢复后的 revision 属于新 store incarnation。

文档: 文档定义导出固定点、中断恢复与损坏拒绝。 版本文档。

Lark Steward Groups

启用: 需要显式启用 bundled loopx-lark provider,且 Lark App 已获接收全部群消息权限。在 App 设置→Lark→管家连接→何时回复中选择“群成员发言无需 @”并保存,只作用于该连接。

验证: 重新打开连接读回 routing.turn_trigger=human_messages;在已运行的本机 dashboard 上执行:

curl -fsS http://127.0.0.1:8767/api/chat/lark/connections

依赖真实送达前检查 provider/listener 健康;合成 CI 不代表向你的群发送过消息。

停用 / 回退: 选择“仅 @ 或回复时”并保存,读回 routing.turn_trigger=addressed。停用 provider 使用 loopx extension disable loopx-lark --execute;另按文档停止独立配置的 collector service。

权限边界: 既有连接仍只响应明确寻址;启用群中经验证的新 human sender 可触发,历史补采、bot、未知未寻址 sender 不触发。worker Topic 保留优先级;采集不授予工具、委派、其他群或接收方权限。

文档: 文档包含 provider 启用、listener 设置及无 @ 的精确范围。 版本文档。

Codex App Scheduler Compatibility

启用: 使用既有已明确批准且绑定已注册 Goal/Agent 的 Codex App heartbeat bootstrap。本修复无新增开关:生成的 ACK/failure 命令保留 typed scheduler 实际权威 state key;legacy-only 仍保留自身范围。

验证: 读当前 packet,执行其精确生成命令,不自行拼接回执:

loopx quota should-run --goal-id "$GOAL_ID" --agent-id "$AGENT_ID" \
  --runtime-profile codex_app_heartbeat
loopx quota status --goal-id "$GOAL_ID"

停用 / 回退: loopx goal-lifecycle --goal-id "$GOAL_ID" --operation stop --actor-kind owner --execute 暂停 Goal,再读 quota,让宿主遵从 pause/delete 指令;不强杀已运行的工具。

权限边界: 保留 TS transition owner、CAS/freshness/identity/reset 检查及扣额规则;兼容别名不产生调度权、不改 timer、不授予自动执行,也不推断 pre-model 宿主资格。

文档: 指南包含明确批准的 bootstrap、读回及停止 heartbeat。 版本文档。

Scoped Quota Observation

启用: 每次读取通过 --goal-id 选择范围,无配置写入,也无需激活新能力。

验证: 使用已注册 Goal,读回 scope/freshness envelope:

loopx quota status --goal-id "$GOAL_ID" --format json
loopx quota plan --goal-id "$GOAL_ID" --format json

停用 / 回退: 省略 --goal-id 即恢复既有全局查询,不需要删除状态或 envelope;回退软件包时遵从实际安装 owner 的计划。

权限边界: 选择器仅约束只读投影及其缓存,不授予 lease、扣额、调度、promotion 或修改权。共享/全局健康失败仍可见;未知 Goal 返回可处理错误,不伪装为空成功。局部排序不代表全局下一 Turn 决策。

文档: quota 合同说明局部查询及其覆盖边界。 版本文档。

Isolated Codex Qualification Profiles

启用: 在干净源码 checkout 且 Codex 可用时,逐次命令显式启用;创建一次性正式安装,不开启 model worker 或 benchmark 作业。

验证: 运行既有安装 profile 验证,读回 provider/隐私、技能与 Goal:

uv run --extra test python examples/benchmark-native-goal-installed-profile-smoke.py --require-app-server

安装及后续 profile CLI/app-server 调用均使用 native_codex_profile_environment,包含 HOME 范围的 TMPDIR/TMP/TEMP;相同源码 profile 保持各自 runtime locator。

停用 / 回退: 不执行该命令即不启用此流程。smoke 在临时目录自动清理前停止自己拥有的 runtime;保留的 profile 应先停止全部调用方,再以 native_codex_profile_environment(profile) 调用其已安装 CLI doctor --installation-only --restart-runtime,仅接受 stopped 或 not_running 后删除这个 profile,未完成停止仍报失败。

权限边界: 临时 namespace 不授予生产 Goal 修改、共享 runtime 停止、上游凭证、模型扣费、benchmark 启动或 OS/网络沙箱。实际模型 worker 仍须文档要求的 provider gateway 与 OS isolation;环境隔离本身不授予这些边界。

文档: 版本化 provider 文档给出正式安装、环境 owner 与收尾要求。 版本文档。

Full comparison

Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Reviewed exact head 5221@8444845bcf6c35622a7ff07f110d8ad267524155.

动机

维护者要求发布 LoopX 1.2.2。主干仍使用 1.2.1 的包身份,历史时间线遗漏已发布的 1.2.1。发布前检查另发现 #5195 合入后的兼容导入计数为 119,超过旧例外上限 117。这项准备同步命名版本、补记真实历史,并修复已证明的发布检查失败。

改动思路

保留运行时与 PyPI 的既有版本来源。维护性指标统计从包导入的公开名称;#5195 将十五个既有常量改为导入唯一 owner,原来本地定义的公开名称并没有因此新增。上一标签计数为 105,当前 base 和 head 同样为 119,来源模块为 50。删除这些兼容名称会破坏已有导入,恢复本地定义会重新制造重复权威。按现有预算决策指南,将该例外收敛到实测 119,模块上限仍为 50,不预留增长空间;新增到 120 仍被拒绝。

具体改动

完整差异为四个文件、11 行增加和4行删除:两个版本字段同步为 1.2.2,公开时间线补充实际发布的 1.2.1,既有兼容例外记录 owner 导入的原因与实测上限。实际 CLI、版本/manifest/更新契约 smoke、仓库卫生和公开边界检查通过;32 个发布/更新/归档测试及21个导出身份/维护性测试通过,一个原有 Windows 专属测试在 macOS 跳过。原始维护性失败保留,修复后的原 smoke 与 119/120 反例通过。风险预合入和精确差异质量回执通过。已有产品执行、状态、配额、能力默认值保持;本 PR 不把准备阶段称为已发布或已安装生效。剩余工作是在最终合入的干净提交验证完整 CI、真实默认模型、安装升级和远程产物。

对主干的风险

版本值必须与包元数据和标签一致,既有负向测试覆盖不匹配拒绝。维护性上限调整是检查政策的明确变更,不能代替对导出价值的判断:已读十五个 owner 与兼容身份测试,既有来源模块上限没有增加,下一项未解释增长继续失败。原始失败与修改后的结果分开保存,不重标历史资格。没有新前端交互或首屏变更;打包前端仍由最终发布构建和安装验证负责。按照仓库规定,涉及 loopx 检查政策的合并需维护者授权,当前评审本身不授予该权限。

我的整体评价

没有阻塞性的代码问题。这个准备阶段覆盖命名版本与已证实的发布检查缺口,范围可审查、可回退。相邻边界的未来改动检查认为,现有单 owner 与兼容身份机制应保留,无需新增抽象或语言迁移。可批准当前 head;合并权限和最终发行资格分别由维护者与本次发布操作负责。全量最终提交资格和下载产物读回尚未执行,不能据局部测试作交付完成声明。

English verdict: APPROVE

@huangruiteng
huangruiteng merged commit fe5c589 into main Sep 27, 2026
7 of 8 checks passed
@huangruiteng
huangruiteng deleted the codex/release-v1.2.2 branch September 27, 2026 19:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant