Skip to content

fix(collaboration): qualify long Windows workspace inputs - #5603

Merged
huangruiteng merged 1 commit into
loopx-project:mainfrom
jackie-cqz:codex/fix-peer-input-paths
Oct 5, 2026
Merged

huangruiteng merged 1 commit into
loopx-project:mainfrom
jackie-cqz:codex/fix-peer-input-paths

Conversation

@jackie-cqz

@jackie-cqz jackie-cqz commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Goal And Delivered Outcome

  • Outcome basis: reproduced Windows collaboration-input defect; direct bug-fix PR.
  • Gap: a real workspace file beyond MAX_PATH, with the expected SHA-256, is reported unavailable by manager-inbox read.
  • Result: resolve both the selected workspace and its inputs through the existing native-path adapter before confinement and file opening. Legal long inputs are readable; deep junctions outside the workspace remain outside_workspace without exposing their digest or content.
  • Intended base: main at 796cb29610336bcde0924ffd551102c2457aece2.

Author Declaration

  • Written by: model_agent (Codex, OpenAI GPT-6).
  • Specification: existing input-readiness contract in loopx/control_plane/collaboration/peers.py, the brief validator in loopx/control_plane/collaboration/semantic_request.ts, and workspace boundary in docs/reference/protocols/peer-agent-runtime-v1.md, at the base revision.
Criterion Disposition Evidence
Read a real legal input and preserve byte-exact SHA-256 implemented Real native Windows CLI request/read of a >260-character binary path, including CRLF and Ctrl-Z
Preserve changed/missing/outside classifications implemented Wrong digest, absent file, relative escape and deep external junction cases
Receiver read supplies readiness without content or additional authority implemented Existing brief/receiver contract unchanged; outside digest remains absent

Scope And Continuation

Complete for the demonstrated receiver input IO defect. Placement: existing Python native-filesystem adapter; reuse windows_extended_path, with no parallel decision owner or new capability/vocabulary. The related refactor makes workspace and input canonicalization share one boundary. The existing registry IO manifest changes only the import-shifted call-site line number.

Original Validation

  • Windows Python 3.13.5 / Node 24.15.0: affected module 32 passed, 2 skipped; the real long-path CLI regression also passed after rebase and independent read-only review. Skips: privileged Windows symlink fixture and POSIX FIFO fixture. The long-path junction negative case runs on Windows.
  • Isolated Linux Python 3.11 / Node 24: 102 passed, 3 Windows-only tests skipped across peer collaboration, host routing, local delivery journey and manager-context roundtrip. Unix FIFO/symlink behavior is retained.
  • Original validated revision 7b0afe6f3397273ecaca9362d92a1923ca1e7c86: Ruff, mypy, TS typecheck, full semantic smoke and 7 registry-IO architecture tests pass. Earlier broad/Windows runs used identical runtime behavior before the metadata-only manifest refresh. Diff advisory and git diff --check pass.
  • Baseline comparison: the new real CLI regression failed before repair with existing long files reported unavailable; it succeeds after repair. Input classes: synthetic. Run state: finished.
  • Separate baseline limitation: the maintainability ratchet reports the same pre-existing Lark goal-topic module budget on unchanged main; this patch does not increase its metric.

CI Follow-up (2026-10-05)

  • Rebased head: 05e596dd860b31c8c4d107eedb494e47c54bbe67; main base: 796cb29610336bcde0924ffd551102c2457aece2. One signed repair commit remains above that base.
  • Fresh native Windows qualification: the long-workspace-input regression and byte-exact binary regression pass; two unrelated selected fixtures skip (privileged symlink and POSIX FIFO). Fresh Linux qualification: 115 related Python tests pass, with 3 Windows-only skips, including registry-IO architecture checks.
  • Fresh Ruff, mypy, control-plane TypeScript typecheck, full semantic smoke, actual-diff semantic advisory and diff whitespace checks pass.
  • The Optional Ark job had 27 failures in the workspace/acceptance/dependency families. The main Python shards report the same errors; the peer input changes do not touch these paths.

The shared failure comparison uses upstream main run 37247859756, not an assumption from unrelated test names.

  • TypeScript core shard 1: the same two File Goal completion tests return stale instead of ready. Both failures also reproduce on main at the new base. The completion-receipt digest repair is proposed in #5587, which is still open.
  • Python: recipient authorization, workspace validation, legacy replan fixtures and repository budgets fail on main as well. #5533, #5567 and #5619 cover parts of this work and remain open. The reproduced unsupported replan_context schema_version failure is not covered by those candidate file lists; they must not be treated as a complete CI repair.
  • Stage2c mutants: the unchanged refresh mutation locator no longer matches its source. #5613 proposes aligning it with the current no-write contract and remains open.

The PR remains scoped to its original repair. Rebase removes obsolete baseline/fixture drift but does not establish a green merge gate. Shared repairs require their own review and qualification; no checks were weakened or suppressed.

Frontend / Visual Evidence

UI impact: none. Existing CLI request/read and receiver readiness projection are exercised; no schema, UI, claim, lease or action-authority changes. Static path checks do not claim protection against arbitrary concurrent filesystem replacement.

Boundary Checklist

  • Public-safe source and synthetic fixtures; no private state, credentials, raw logs or machine paths.
  • Scoped bug fix; no benchmark work.
  • DCO sign-off on every commit.

Signed-off-by: jackie-cqz <2557911191@qq.com>
@jackie-cqz
jackie-cqz force-pushed the codex/fix-peer-input-paths branch from 7b0afe6 to 05e596d Compare October 5, 2026 03:09
@jackie-cqz

Copy link
Copy Markdown
Contributor Author

CI Follow-up (2026-10-05)

  • Rebased head: 05e596dd860b31c8c4d107eedb494e47c54bbe67; main base: 796cb29610336bcde0924ffd551102c2457aece2. One signed repair commit remains above that base.
  • Fresh native Windows qualification: the long-workspace-input regression and byte-exact binary regression pass; two unrelated selected fixtures skip (privileged symlink and POSIX FIFO). Fresh Linux qualification: 115 related Python tests pass, with 3 Windows-only skips, including registry-IO architecture checks.
  • Fresh Ruff, mypy, control-plane TypeScript typecheck, full semantic smoke, actual-diff semantic advisory and diff whitespace checks pass.
  • The Optional Ark job had 27 failures in the workspace/acceptance/dependency families. The main Python shards report the same errors; the peer input changes do not touch these paths.

The shared failure comparison uses upstream main run 37247859756, not an assumption from unrelated test names.

  • TypeScript core shard 1: the same two File Goal completion tests return stale instead of ready. Both failures also reproduce on main at the new base. The completion-receipt digest repair is proposed in #5587, which is still open.
  • Python: recipient authorization, workspace validation, legacy replan fixtures and repository budgets fail on main as well. #5533, #5567 and #5619 cover parts of this work and remain open. The reproduced unsupported replan_context schema_version failure is not covered by those candidate file lists; they must not be treated as a complete CI repair.
  • Stage2c mutants: the unchanged refresh mutation locator no longer matches its source. #5613 proposes aligning it with the current no-write contract and remains open.

The PR remains scoped to its original repair. Rebase removes obsolete baseline/fixture drift but does not establish a green merge gate. Shared repairs require their own review and qualification; no checks were weakened or suppressed.

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; model=gpt-6.1-sol; provider=OpenAI; declaration_source=runtime_reported; reasoning_effort=xhigh

Exact head: 05e596dd860b31c8c4d107eedb494e47c54bbe67; immutable base: 796cb29610336bcde0924ffd551102c2457aece2.

[P2] 当前缺少独立的真实Windows受影响路径核验。作者报告已经跑过native Windows;我的host为macOS,新增Windows专用测试实际被跳过。这里是验收证据缺口,没有把它说成已发现Windows代码失败;不能用本机115通过或改os.name的模拟替代Win32长路径/junction的独立readback。

动机

Windows上的接收Agent在持续协作中读取层级较深的工作资料,需要看到真实版本与缺失原因,并保持工作区之外的资料不可读取。
预期是接收方不必搬短文件路径,就能识别深层二进制资料的正确版本,并拒绝跳出工作区的junction;本次在macOS实测前后完整结果一致,Windows上这项改善仍未由我独立跑通。
本次独立实测确认原CLI发送、读取、拒绝、资料恢复、重放与结果返回保持原行为;当前host跳过Windows专用用例,不能把115个本机通过判作Windows修复已验收。
本次评价已有接收资料检查的地址修复,不认证真实Windows尚未执行的路径、不扩大执行权限、不防任意并发文件替换,也不宣称完整跨host资料采用、Lark或多日效率验收。

改动思路

复用现有 windows_extended_path(Windows本机文件地址前缀转换),在接收资料的IO适配边界先规范化选定工作区,再解析输入并检查是否仍位于该根下。原TypeScript brief owner继续限制相对路径、SHA256与输入数量;原Goal/来源授权、别名/配置工作区和请求返回规则不变。Python负责现有平台文件IO,没有增加平行的通用授权规则、capability、参数或持久状态。

具体改动

peers.py:514 的 _input_readiness_for_goal先沿原规则选择Goal根、关联worktree或显式configured companion根;537行改用existing helper再resolve,以让深层native地址和junction在confinement前得到解析。548行将原 O_RDONLY/O_NONBLOCK/O_BINARY表达式命名为flags,保留二进制读取、fstat regular-file检查及4MiB上限;只输出版本/hash/status,不供应内容,也不把可用资料当执行许可。read_inbox:602仍沿真实CLI/MCP的request读取和独立结果返回消费这个观察。

manifest只随新增import将 _goal codec读站点52改53,所有281站点仍通过既有census。测试新增一个Win32专用用例:>260地址,CRLF/Ctrl-Z/NUL/ff原字节、正确与错误SHA、缺失文件、跳出工作区的deep junction,要求 available/changed/unavailable/outside_workspace及no-content,并带范围检查后的临时目录清理。完整3文件+65/-5,主要是58行聚焦测试,未新建模块或抽象。

按改动前 accepted semantic handoff contract,revision 796cb29610336bcde0924ffd551102c2457aece2:5.4 要区分资料定位、当前版本、实际读状态与记录的声称,Windows这一受影响项仍 not_met,最小补齐是对固定base与head执行同一个真实Windows CLI fixture、记录旧缺陷与修复后正常读/拒绝/恢复;5.5 的发现、资料读权限、上下文与执行准备分离由原typed/Goal owner保持,本机真实无执行效果及返回链已核验;A14 属于规范另外要求的跨host资料获取、提取与接收采用,不在本次本地地址修复范围,也不能声称完成它。

对主干的风险

独立精确head五套测试115 passed/3 skipped;相同immutable base五套115 passed/2 skipped,新增skip就是Windows长input测试,其它两项也是Win32专用。另用同一隔离真实文件/CLI脚本跑前后13个完整观测:深层二进制SHA、changed、missing、outside symlink、too_large、目录/FIFO,以及修复资料后reread、request重放、adopt/report、原sender读取/消费返回、路径遍历拒绝、未授权与configured工作区。仅归一化时间与临时根地址,完整字段/诊断/ID/hash保持,输出一致;fixture SHA256 5f0e9d66bb29dbc0be662a2a58fdc1561c586ac308bbb15f7f36a7072d6e081a,结果 SHA256 d57b46a41f8abfa3069b13f4258d8a8e21de514099c0f60d64ebea587a135584。重放只一条请求,注册表不变,Todo/priority/interruption均false,outside无内容/hash泄漏。

三路径公开边界、whitespace、manifest和semantic advisory通过;完整semantic vocabulary smoke通过。没有查询、等待CI,也没有用作者native报告冒充我的独立运行。现有CLI/MCP入口与原字段消费者已追踪,本PR没有新用户capability或配置;我未测试真实Windows packaged App、Lark、模型采用和多日吞吐。已有静态confinement不承诺防任意并发目录替换,这属于原边界,不能暗加更宽承诺。

我的整体评价

REQUEST_CHANGES,最小所需是独立native Windows基线/head生产路径证据,不要求新能力或无关重构。修复意图及代码规模 proportionate;long_horizon与user_experience仍 not_yet_proven:POSIX体验已证实保持、Windows免搬短路径的改善有正向预期,但真实受影响环境尚无我的通过回执。未来维护检查认为复用现有平台helper、保留一个typed brief owner和原return边界已经足够,无需再加抽象。请在同一版本固定的fixture中验证legal长binary、mismatch、missing、deep outside junction和合法资料恢复,保留完整byte/hash/no-content/no越界读结果;取得这些证据后复审同head或修复后的新head。可用性不等于接收采用,单次成功不等于长期效率验收。

English verdict: REQUEST_CHANGES - 05e596d, for missing independently executed native Windows affected-backend qualification, not a discovered Windows code failure or pending CI. Independent macOS base/head five-suite runs each pass115 tests; Windows-only skips are2/3. An identical real local CLI/filesystem fixture preserves13 complete observations, exact binary hashes, confinement/no-content, material recovery, replay and result return. Qualify pinned native Windows long-path/binary/deep-junction base/head behavior and recovery before approval; no new permission, capability or broad refactor is requested.

@huangruiteng
huangruiteng merged commit e5a08d6 into loopx-project:main Oct 5, 2026
20 of 35 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants