Skip to content

fix(quota): honor explicit Todo selection for host-owned turns - #5624

Merged
huangruiteng merged 1 commit into
mainfrom
codex/generic-cli-todo-selection
Oct 5, 2026
Merged

huangruiteng merged 1 commit into
mainfrom
codex/generic-cli-todo-selection

Conversation

@loopx-agent

Copy link
Copy Markdown
Collaborator

External CLI workers with a host-owned Turn could execute the projected --todo-id command yet remain in selection_required, because CLI transport forwarded explicit selection only for guided App profiles. A receipt could therefore name a Todo while delivery remained refused.

Forward explicit selections whenever the caller supplies a Turn identity to the existing typed admission owner. Preserve legacy calls without an identity, guided-start eligibility, controller-owned settlement, current capability checks and same-Turn conflict rejection. This is an existing CLI/runtime correction; frontend and Lark entrypoints are unchanged. No new capability or decision owner is introduced, and the adjacent-boundary review found no useful additional abstraction.

Validation: latest-main reproductions fail for generic CLI, outer-controller and native CLI profiles before the fix. Real CLI regression coverage executes returned selection commands, re-entry, conflicting selection, writeback and idempotent spend; negative cases cover missing/ineligible Todos and unavailable capabilities. 90 real CLI tests and 124 contract tests pass, as do Ruff, semantic vocabulary smoke and diff checks. The first semantic smoke lacked npm development dependencies; after installing them, the full semantic smoke passed. No full repository test sweep was run. Live workers have not been patched by this PR.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Exact head: 5624@ced5d763dc6c00138b64593267e1e3bc5713c010. Base: 2f68e3b835c3bfc0e3718373cdb6c72eea99291e.

动机

使用外部 CLI、并由宿主提供本轮标识的执行者。 旧版执行返回的 Todo 选择命令后,回执已写入该 Todo,响应却仍要求选择、禁止交付;当前版本先把选择交给既有资格判定,当次就返回一致的可交付状态。 三种外部 CLI profile 对推荐列表之外的合法 Todo 当次完成绑定,重复进入保持同一身份;换绑、缺失 Todo 和缺少权限的 Todo 被拒绝,获准回写后的重复扣额只产生一次记录。 本次修正已有 CLI 选择传输,不新增 Turn 创建权限、inner-agent 结算权限或配置,不声明活跃 worker 热修、packaged GUI 验收或长期协作达标。

改动思路

把宿主明确提供的 Turn 标识和选择传给既有 admission,再生成一致的回执和响应,不新增决定源。 规范依据为 docs/quota-allocation.md @ 2f68e3b835c3bfc0e3718373cdb6c72eea99291e,按 Explicit action selection, Receipt identity, Host settlement ownership 逐项核验。既有 R1/S4 连续执行边界指导这一小修复,未推导整条路线完成。

具体改动

完整三文件 +85/-9:已有 CLI helper +4/-1,原 settlement CLI 测试 +75/-8,quota 文档 +6。_requested_quota_action_todo_id:67 只增加 supplied turn_instance_id 的传输条件;load_requested_quota_action_selection:83 保留已绑定/保留选择逻辑;reconcile_requested_quota_action_selection:235 仍沿现有 preflight 处理拒绝与恢复。资格决定仍由未改的 TypeScript qualifyActionSelection:359 检查当前 candidate、能力和高优先级抢占,Python 没有重新定义状态机。

对主干的风险

用同一份冻结基线 fixture、真实 CLI 和第四个合法 Todo(超出前三条建议)对照:generic_cli、outer_controller、codex_cli 的 base 都出现回执已绑定但 selection_required=true/delivery_allowed=false;head 当次绑定后立即可交付。base 额外无选择重入可以恢复,所以证据支持“多一次重入/响应矛盾”,不宣称永远无法恢复。head 重入保持同一身份,换绑拒绝且回执仍只有两次记录。更强的首调用负例中,base 对不存在和缺权限 Todo 写入错误绑定回执;head 两项均 quota_action_selection_rejected/not_committed,回执数为0。未提供 Turn identity 的旧调用行为保持相同。

generic/native head 实际 refresh→spend→重复 spend 只记一次扣额。outer_controller 当次可交付但没有 inner-agent settlement_plan,控制者结算权没有外扩。90项真实 CLI、87项 portfolio/conflict/workspace/envelope 契约及31项原生检查通过;Ruff、advisory→全树 semantic smoke、whitespace 通过。新增 profile 条件的默认行为变更已写进 quota 文档;begin-turn 资格保留。未来重构检查认为原 transport helper 和单一 TS admission 足够,没有有价值的额外抽象。#5623 workspace 文案仍是相关但独立修复;本 PR 保留其旧基线提示,未把它算作已修。

同一 Turn 首次返回后再新建合法 Todo 的真实 CLI 对照也已执行:guided profile 在两版均正确;generic_cli 的当前 head 当次正确绑定,基线仍要求选择。新建项目项仍须当前资格检查,不由 Goal 激活自动授予权限。

当前权限、claim/lease、typed gate、真实 source/receipt 与本轮 profile 分开处理。没有以 profile、peer 请求或建议列表授予权限;没有用 mock 提供被测后置条件。公开新增行的 private/credential/local-path 扫描未发现泄漏。未查询、轮询或等待 CI。

No packaged GUI/Lark, installed-wheel upgrade, independent Windows/Linux, full-repository suite or sustained live-worker qualification. No active worker or experiment was modified. #5623 independently fixes workspace prompt wording; this transport-only PR retains that baseline hint.

我的整体评价

APPROVE,无当前阻塞 finding。该有界修复使原 CLI 指令及继续执行更一致,不增加操作者输入或新的同步状态。通过结论覆盖本精确 head 的完整三文件;真实安装及持续运行保持未测。它修改控制面/运行时,交由维护者合并。当前账号也是 PR 作者,因此这是 COMMENTED 的通过结论,不能称为 GitHub 正式 APPROVED。

English verdict: APPROVE - 5624@ced5d763dc6c00138b64593267e1e3bc5713c010;Host-owned explicit selections qualify before binding and return consistent delivery;invalid input rejects without receipts,controller ownership and once-only spend retained;90+87 Python and31 native tests pass. No CI consulted;maintainer merge and live adoption remain separate.

@huangruiteng
huangruiteng merged commit 04b0a04 into main Oct 5, 2026
20 of 34 checks passed
@huangruiteng
huangruiteng deleted the codex/generic-cli-todo-selection branch October 5, 2026 04:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants