fix(collaboration): allow exact source-session context grants - #5595
huangruiteng merged 4 commits into
Conversation
Signed-off-by: mika <211269698+mikamikasuki@users.noreply.github.com>
ed2e90e to
44706b2
Compare
|
For the record: this fix corresponds to our root-cause diagnosis in #5592 (bisect-localized to d0fb611/#5522, parent commit 63/63 green, tip 46 red, suggested narrow fix keeping the lifecycle gate and allowing observation for instantiated Goals). We independently verified the same 46-case failure population and the same file (source_grant_observation.py). If useful, our live tests for the narrowing predicate (test-source-grant-narrowing.py, 4 boundary cases) are available — happy to contribute them to this PR's coverage. |
|
This pull request has merge conflicts with Choose the remote for the base repository, not an out-of-date fork. git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEADFor a same-repository clone whose Keep the DCO |
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent; model=gpt-6.1-sol; provider=OpenAI; declaration_source=runtime_reported; reasoning_effort=xhigh
Exact head: f4d124a582554c1ab226efb040c3bd49257b6461; immutable base: 96164637c21db7ccd2f741cb7da6ef630fa413e6.
[P2] 当前合并提交缺少 DCO Signed-off-by。实现修复已经通过独立功能核验,但每个 PR 分支提交都须签署;之前44706b2的签署不覆盖当前f4d124a合并提交。请签署该提交或重写分支保留完整签署,再 review 新 head。
动机
使用本人聊天把上下文交给已注册 Agent 的用户,需要让任务送到当前 Goal 实例并能读回结果,同时保留原有接收者授权。
原来发送给具有合法实例身份的 Agent 也被统一拒绝;候选改动后消息写入对应实例的收件记录,重复发送复用同一记录,撤销的授权和其它实例仍不能借此执行。
独立实测旧版合法发送失败,候选版本可以送达并幂等重放;外部来源无接收授权时不增加记录,恢复精确授权后同一请求写入记录,原注册表未变。
本次完成5592的有界发送准入修复,不认证完整 Goal 激活、孤儿恢复、真实飞书网络或长期多 Agent 效率;当前合并提交缺少 DCO 签署,仍需修正后审核新 head。
改动思路
修复所属观察适配器:原 runtime compatibility用于执行准入,会统一拒绝 source-session;上下文观察则先检查既有 exact GoalRef(Goal别名加不可复用实例身份),只留下有效已实例化 Goal,再交给原注册成员、会话边界、来源授权和提交时实例判断。身份有效不意味着可以执行、读取其它域证据或选择任意接收者;没有新状态表、CLI参数、配置开关或确认步骤。
按固定 base的 accepted Goal instance contract,revision 96164637c21db7ccd2f741cb7da6ef630fa413e6:5.2 的已有精确身份/无隐式激活由实例过滤和 lifecycle-only拒绝落实;5.5 的同实例读/check/commit锁仍由既有 goal_instance_scope 与 TS decision保持,并在 stale/recreated/concurrent原路径实测;7 的legacy/default-off由原非source分支和完整输出/v1记录兼容覆盖。M5 的真实host激活、孤儿恢复与产品验收属于规范仍 held 的独立范围,这个5592发送修复不能代替它,也不需要假称完成它才能判断本次有界修复。
具体改动
source_grant_observation.py:37从同一权威注册表读 profile;source模式要求列表,过滤缺失/错误的 Goal/实例字符串,用既有 exact_goal_ref原始校验器,不另写权限政策。非source仍走原 runtime compatibility。- 然后原 registered_context_recipients按 canonical activation_state、registered_agents过滤;会话所属域和外部 channel/消息digest/sender grant继续验证,TS
collaboration.source.recipients选择 allowed,再与实际 available相交并排序,输出仅 context_only。有效实例但 stopped/错误activation/selected空列表会得到空目标的context_only诊断;生命周期-only和非法GoalRef仍 unavailable,这个诊断差异没有任何执行许可。 - 现有
manager_context.deliver:89在 Goal lifetime锁内创建同一 exact request,复查当前来源/接收者权限,再将 exact v2记录写入所属收件目录并读回。真实 head发送与重放得到相同 request_id/GoalRef,一次记录;priority_changed、todo_created、execution_interrupted均false,注册表字节未变。 - 修改撤销测试为
local_delivery_scope="selected",targets=[]正确表达撤销。既有 TS owner默认 all_registered,不显式selected时空targets本来就不能表示撤销;这是校准测试意图,不是删除权限断言。独立实际外部流程先selected[]拒绝、记录总数不变,再恢复精确builder授权,同一请求增加一条有效记录。 - 阻塞点是当前 commit qualification:
git log 96164637c21db7ccd2f741cb7da6ef630fa413e6..f4d124a582554c1ab226efb040c3bd49257b6461 --format=%B与当前git show -s --format=full独立证实44706b2含Signed-off-by,而当前merge commitf4d124a582554c1ab226efb040c3bd49257b6461仅有merge标题,无任何trailer。仓库每个PR分支commit必须DCO签署;PR说明“commit includes a sign-off”不覆盖merge commit。请签署/重写这个提交、保留原签署与修复,再对新head审核。此 finding不要求增加运行时框架或无关测试。
对主干的风险
新鲜精确 head的 Goal instance、manager handoff和source-session denial architecture 96 passed;相同 immutable base的核心两套 46 failed / 48 passed,不是沿用作者旧基线。独立同一19场景 harness直接观察base合法发送/恢复授权仍失败、收件0条;head合法发送、重放和精确外部授权恢复可写入,拒绝阶段不写。六个 legacy/lifecycle-only/非法实例/非法别名/撤销sender/消息mismatch完整输出与base一致;stopped和非法activation始终无目标。混合容器内非法/停止项排除;Goal chat添加合法new-domain仍只delivery,75其它Goal与逆序相同完整catalog;外部selected只builder,不会包含同Goal其它Agent或其它Goal。这里只规范地模拟外部已验证来源,没有调用真实Lark账户网络。
现有 focused套件还沿真实CLI/loopbackHTTP、原来源结果返回、pending/replay、timeout/失败、recreated实例与并发写路径执行;legacy v1路径/ID/JSON字节测试覆盖旧记录。公开边界2路径、whitespace与semantic advisory通过;既有TS三类决策未变,Python只适配已有身份原语,没有第二套授权状态机。未查询或等待CI,未运行真实模型/外部宿主、多日吞吐或完整packaged App视觉操作;既有未变的UI/API入口已沿源码和原HTTP实测追踪。DCO失败仍保留,不能用96绿替代。
我的整体评价
REQUEST_CHANGES,当前唯一已验证阻塞是缺少merge commit DCO签署;未发现本修复引入的功能/越权阻塞。5592有界行为目标 goal_achieved,long_horizon和user_experience均 improved:合法上下文能进入持续工作与返回/恢复路径,重复输入幂等、拒绝后可通过精确授权恢复,不增加参数或重复确认。长期效率正向预期由解除确定性全拒绝和保留幂等/隔离支持,尚无多日收益量化。未来维护检查认为复用现有精确身份与TS授权owner已经足够,不把一次IO适配修复扩大成语言迁移或新capability。新head、主干冲突处理和真正运行采用分别需要独立读回。
English verdict: REQUEST_CHANGES - f4d124a, solely for the missing DCO Signed-off-by on this PR's merge commit; the earlier signed implementation commit does not cover it. The bounded issue5592 repair has positive behavioral value: real exact-instance delivery, replay and scoped grant recovery now reach durable records, without execution authority or implicit activation. Independent base core suites reproduce46 failures;96 focused exact-head tests and19 real local authority/store counterfactuals pass, with full legacy/malformed/source-denial parity and documented empty-catalog diagnostics. Sign the branch merge commit and review the new head; full activation/orphan/live-Lark/model and quantitative sustained-efficiency acceptance remain separate.
|
Quick note on the DCO sign-off: [local-harness-v124 cac5c3c25] 司法组四席终裁落地: 五标第6条重写(用户'有机一体'纠偏——删排序改场景权衡+留痕+独立席复核+升C8条件)/第7条补齐(同类定义+台账锚+独立席清点)/元准则⑧补出边(→PRINCIPLES§二→用户终审)/deslopify人话对照表入档 If you wish to set tracking information for this branch you can do so with: |
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
|
DCO finding correction / DCO finding 更正 独立核验后,先前对 This corrects the sole DCO finding, not an approval of a changed head. 新 head The prior DCO finding was incorrect under the accepted verified-GitHub-merge exemption and is withdrawn. The revised head still requires independent review; no merge or approval is claimed here. |
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent; model=GPT-6; provider=OpenAI; declaration_source=self_reported
Exact head: a085ca8180be0512391ccf90c30304262a27779f; immutable current-main base: bfe3c4344813aa5832ed51d70a119c2f8a877c83.
动机
把上下文交给已有 Agent 的聊天调用者,会先读取当前可交办的成员目录。
当前主干已能向指定的有效 Goal 实例交办,但同一会话的交办目录仍返回不可用;候选版本会显示当前有效实例中已授权的成员。
模型获得可交办目标的真实列表,项目会话仍只显示本项目成员,撤权和停止状态继续拒绝交办。
本次不激活新的 Goal、不增加执行权限,也不认证完整 source-session Chat、宿主激活或真实飞书网络。
生命周期专用注册表的通用成员读取工具在两个版本都仍返回不可用;完整激活与孤儿恢复继续属于规范 M5 的 held 范围。
改动思路
这次复核以新主干为基线:主干已有单目标 target_authority,所以不能再沿用旧评审“所有合法发送仍失败”的结论。本补丁只恢复交办目录的正确观察。使用现有 registry codec、精确 Goal 身份校验和已注册成员,之后仍由同一类型化会话与来源授权 owner 筛选;不添加模型线程、调度器、配置表或新参数。
正常路径是当前 source registry → 已有精确实例 → 活跃成员 → 会话/来源 grant → 可交办目录;发送仍在现有实例锁内重新核验。来源撤权会清空受理权限,恢复原有授权后可继续发送并幂等重放。这是对目录观察的有界修复,不替代完整宿主激活和通用 source-session Chat 资格。
具体改动
规范依据为 docs/architecture/rfcs/goal-instance-identity-and-orphan-recovery-v0.md,spec_revision bfe3c4344813aa5832ed51d70a119c2f8a877c83。5.2 implemented:复用现有精确身份,不按别名猜实例、不隐式激活。5.5 implemented:现有发送/回传的精确 Goal scope、当前权限与提交锁保持,由新增12目录用例及现有实例/并发/回传测试验证。7 implemented:非source原分支和通用read-to-effect拒绝保持,观察不声称完整ABA保护。M5 deferred:既有规范的宿主激活、孤儿恢复和产品资格仍held,不以本次目录修复宣称完成。
关键代码讲解
source_context_authority读取同一权威源。在source profile中,只保留合法字符串和既有exact_goal_ref认可的Goal/实例;无合法实例则仍unavailable。随后原registered_context_recipients排除停止/异常激活成员,再走原授予范围。对非source仍用原runtime兼容门禁。_source_context_grant保留新主干实现:项目会话按本Goal筛选;外部来源复核channel、消息digest和当前sender policy,由既有TS source.recipients决定,再与真实available相交。catalog和单目标source_context_target_authority共用它,避免冲突修复恢复旧的重复权限实现。- 新增12个现有suite参数用例,用真实object/strict codec检查有效邻居、未实例化、非法实例、非法别名、stopped和非法activation,以及项目隔离/无registry写入。主干更完整的 sender/selected/blocked-target 撤权测试原样保留。生成census仅现有读点行号126→128,没有新读者或分类。
最终diff为3文件:生产+29/-3、回归测试+42、生成metadata+1/-1。正常signed merge解决冲突,保留作者贡献及新主干路径,未force重写历史。
对主干的风险
未发现阻塞性功能/越权问题。主要反例是同一容器中的未实例化、非法或停止Goal被误列为可交办,以及来源撤权后继续发送。实际对照中,候选排除这些项;项目会话在75个额外Goal下仍只授予本Goal;全局owner目录包含未来注册,反序登记不改变完整结果;外部selected仅一个目标,移除sender后两次发送均拒绝,恢复sender后恢复目录/原幂等路径。注册表字节未变。
本head 108 focused + 2 architecture passed;同一新增12用例在固定main 12 failed、候选 12 passed。独立10场景通过真实codec、authority、manager-read与File inbox执行:有效source目录由unavailable恢复,而当前main和候选的精确发送/重放结果相同。通用source registry的manager-read在两侧仍为agent_inventory_unavailable,按规范M5保留缺口,没有当成读成功或悄悄绕过兼容门禁。这里模拟可信source/本人受众,没有调用真实Lark网络、模型或宿主激活。
语义与 CI 对齐
复用既有GoalRef、profile、activation和TS来源授权词汇。Ruff、canonical mypy 19 source files、census 281 / 0 unclassified、语义advisory及最终premerge 5 direct / 17 selected / 0 blocking failures完成。维护性提示在固定main与head逐字一致:goal_topic_runtime的module debt、handle_quota_command和goal_boundary的function debt;没有提高预算。初次census过期与验证期间metadata变更触发side-effect guard均已保留失败记录,提交生成metadata后完整premerge重跑通过;非canonical单文件mypy把未选的旧图全加载所产生错误不算canonical验证通过,正式配置19文件检查另行通过。
先前f4d缺DCO的finding不成立:当前严格DCO workflow豁免可验证GitHub自动双父提交;API证明该提交committer为GitHub/web-flow、签名verified/valid且父项吻合;原贡献有Signed-off,新手工merge和metadata提交也均Signed-off。未降低DCO要求。当前远端CI仍排队,保留为合并门禁,不能用本地绿替代实际ready。
我的整体评价
APPROVE 这个有界、可回退的目录修复;delivery judgment为 justified_increment,long_horizon improved、user_experience improved:既有持续交办/返回路径获得真实可交办目录,不新增表单、手动角色信息或确认步骤。完整source-session激活/通用发现和真实Bot旅程未关闭,不能扩写成父Goal已完成。
未来维护检查选择保留新主干共享权限函数和精确单目标路径;29行已有观察owner修复比全局拆门禁或新框架更合适。保留实际legacy/persisted契约,不增加版本分支。head已核对;审批不等于合并,原review对账、当前CI与native exact-head readiness仍分别检查。
English verdict: APPROVE - a085ca8; restores exact-instance context catalog observation while retaining current-main direct-target grants, revocation, replay and lifecycle denial. 108 focused and 2 architecture tests pass; 12 catalog regressions fail on immutable main and pass on head; 10 real codec/authority/inspection/inbox comparisons validate intentional catalog deltas and preserved delivery. Canonical typing/census and final risk premerge pass with one independently identical baseline advisory. Verified GitHub-generated merge DCO exemption applies. Full source-session activation/discovery and live Lark/model acceptance remain outside this bounded increment; pending CI holds merge readiness.
Goal And Delivered Outcome
source_context_authorityrejected everysource_session_v1registry before observing recipients, including valid instance-bound Goals used by exact collaboration handoffs.2f68e3b835c3bfc0e3718373cdb6c72eea99291e.Author Declaration
Implemented against
docs/architecture/rfcs/goal-instance-identity-and-orphan-recovery-v0.mdat2f68e3b835c3bfc0e3718373cdb6c72eea99291e; issue source_context_authority rejects source_session_v1 profile after #5522 — 46 exact-path tests red on main #5592.source_context_authoritytests/test_collaboration_goal_instance.pysource_context_authoritytests/test_manager_context_handoff.pyba443e2b9d096f5e6ec3c710ef68143ffff73448reproduced 46 failures among 66 exact-instance cases. Rebased onto current main and reran the focused tests; lifecycle-only denial and exact GoalRef admission remain covered.Scope And Continuation
Validation
44706b2c92f59143c8a42a339117f3783adc47a9.ba443e2b9d096f5e6ec3c710ef68143ffff73448: exact-instance suite had 46 failures and 20 passes. On rebased head44706b2c92f59143c8a42a339117f3783adc47a9against main2f68e3b835c3bfc0e3718373cdb6c72eea99291e, focused suites passed: 96 tests.git diff --checkpassed.Frontend / Visual Evidence
Type of Change
LoopX Area
Technical Direction
Shared-authority RFC fixture impact
Boundary Checklist