Skip to content

fix(service): qualify owned wheels and retain macOS workspace selection - #5543

Open
huangruiteng wants to merge 5 commits into
mainfrom
codex/native-workspace-service-20261004
Open

huangruiteng wants to merge 5 commits into
mainfrom
codex/native-workspace-service-20261004

Conversation

@huangruiteng

@huangruiteng huangruiteng commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

Ordinary pip/uv/pipx wheel installations must qualify for the existing macOS service helper, and reinstall must retain the selected registry, Codex home and workspaces. This change fingerprints the actual imported, RECORD-owned non-editable package and freezes each service's startup identity, while preserving snapshot identities and the existing service owner.

The default-pip review defect is fixed at d2987cc575f9c1717d83b29c1c364c1a1415f43e: one package-local artifact predicate excludes generated __pycache__, .pyc and .pyo entries on both the installed RECORD and disk sides. Imported-root/version/editable/complete-source/symlink refusal remains intact; changed owned bytes still change the fingerprint. The helper retains bounded, validated workspace selection and custom registry parameters. This is a local reuse fence, not publisher or source attestation.

The branch now integrates main 4537095659eeee499b869f6f1869703583f77aef through signed append-only merges, resolving the stale registry IO anchors. The PR remains 13 paths; no generated uv.lock is submitted. Placement stays in the existing release identity and macOS service helper; the shared filter removes duplicated artifact-set semantics without adding another installer, service or authority.

Validation at this head:

  • 141 related package/service/doctor/dashboard tests passed, including the real pip regression; final identity set: 13 passed. The new real-pip regression fails against the pre-fix source with a missing fingerprint.
  • Independently built complete baseline/candidate wheels and installed them with real pip in isolated Python 3.12 environments. Default pip recorded 1229 generated bytecode entries: baseline lacks a fingerprint, while candidate default/no-compile identities match. Both candidate installation-only console doctors pass. Same-version byte changes alter the digest; an extra unowned source denies identity; restoration reads back the original identity.
  • Packaged Chat build, mocked macOS LaunchAgent preservation/rejection smoke, 7 registry IO census tests (281 sites, zero unclassified), Ruff, focused Mypy and diff/DCO checks pass. The semantic advisory finds no supported new vocabulary, which is not a semantic proof.
  • Goal-linked native premerge returns a passing gate with five direct and nineteen selected checks, plus one inherited advisory maintainability failure in unchanged goal_topic_runtime.py. Current main independently reproduces that same debt; no budget was raised. Change-quality policy is disabled for this Goal, so no quality receipt is claimed.

Historical real launchctl startup/restart evidence in the earlier PR remains historical. This repair does not repeat actual login-after-reboot, real provider inbound or a normal release upgrade, and does not replace the installed tool or running Bot service. Full remote CI at this new head is not yet qualified. Runtime/product changes remain for exact-head maintainer review and merge; this task does not self-merge or bypass that gate.

…tion

Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
@mergify

mergify Bot commented Oct 4, 2026

Copy link
Copy Markdown

This pull request has merge conflicts with main and cannot be merged
until they are resolved. Please rebase or merge the base branch, @huangruiteng.

Choose the remote for the base repository, not an out-of-date fork.
For a fork clone, first inspect git remote -v; upstream must point
to https://github.com/loopx-project/loopx.git. If it is absent, add it
with git remote add upstream https://github.com/loopx-project/loopx.git.
Then run:

git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEAD

For a same-repository clone whose origin points to
https://github.com/loopx-project/loopx.git, use origin instead of
upstream for fetch/rebase. If you prefer merging the base, use
git merge <base-remote>/main and push normally.

Keep the DCO Signed-off-by trailer on every commit when you rebase.
https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/syncing-a-fork

@mergify mergify Bot added the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 4, 2026

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent · gpt-6.1-sol · OpenAI · runtime_reported · xhigh

[P1] 普通 pip 安装仍被新运行时指纹校验拒绝。

动机

用普通 pip 安装后管理本机后台服务的用户,需要确认服务运行的是当前安装包,并保留已选工作区。

以前后台服务校验只接受带发布清单的快照,普通包管理器安装会被拒绝;本改动拟接受属于当前安装的实际包文件,并保留已有工作区选择。

已验证禁用字节码编译的同一 wheel 能获得指纹;但普通 pip 安装仍没有指纹,后台服务的合法安装入口尚未修好。

本轮不验收真实 launchctl 常驻升级、用户已有服务迁移、跨主机或发布,也不把包指纹当发布者认证。

改动思路

复用 release_runtime_identity 为无发布清单的包管理器安装添加实际字节摘要;不能仅凭版本相同认定服务是当前安装。ChatHTTPServer 与 StatusHTTPServer 构造时保存启动身份,之后 HTTP 不随磁盘升级改写旧进程。doctor 提供实际 Python 解释器,macOS helper 使用所选 console 的解释器解析并保存既有 registry、Codex home、工作区列表。既有 snapshot 和 package manager 各自保留原 ownership。

规范依据:docs/guides/installing-loopx.md,不可变版本 99839aeb8fed5fae38a5d319391cd050672a6508。逐项判断:

  • Installation owner and package: not_met — Real default pip wheel install records1212 pyc and returns no fingerprint; no-compile same wheel returns a digest..

  • Managed Effect runtime: implemented — pr5543-144225 native and owner counterexample/control evidence.

  • Rollback: deferred — Mocked helper reinstall/restart/context retention verified; no actual user launchctl rollback performed..

具体改动

全量13文件396+/34-。release_manifest.py:348 的 _distribution_runtime_fingerprint 核验非editable、精确版本、真正导入模块、完整文件集合和symlink,哈希真实字节;doctor/installation-only doctor 读同一身份和解释器。两个HTTP server冻结构造身份;现有dashboard readiness复用该身份。

macOS helper 优先询问选定console的解释器,解析已有plist环境与旧shlex参数;registry必须绝对路径,roots是最多32项的现存绝对目录JSON,去重并逐项quote。显式registry同时传给Chat/status,移除会覆盖自定义registry的global选项;先验证身份/参数再bootstrap。IO manifest只是行号变化。focused distribution/server/dashboard/doctor测试、mocked helper smoke及双语安装说明覆盖同一改动。

缺陷在 release_manifest.py:360–377:安装清单集合保留所有loopx/条目,磁盘集合却排除__pycache__/pyc/pyo;真实pip默认安装会在RECORD记录生成的pyc。独立构建当前head的完整wheel,在隔离Python3.12环境用真实pip正常安装,读到2800项loopx文件,其中1212项pyc。实际安装console的doctor installation-only成功,但service_runtime_identity没有package_fingerprint,且无release_id;helper期望身份因而仍拒绝合法安装。同一wheel用pip --no-compile安装产生指纹。没有修改RECORD或把mock返回当包归属证明。最小修复是在清单与磁盘两侧对称排除生成字节码,保留源码完整性、版本/import-root/editable/symlink所有拒绝条件;加入真实default pip的回归。

对主干的风险

当前190项focused原生测试、162项架构/语义IO检查、source Chat bundle/frontend tsc构建、LaunchAgent mocked smoke、diff/DCO通过;2项Windows-only在macOS跳过,未冒充跨平台验收。不可变base同集合中的既有非dashboard/native检查134项通过(同2项平台skip)。对照重点是实际默认pip安装与同wheel no-compile;不是用通过的synthetic distribution fixture否定真实失败。初次缺少source bundle导致的4项dashboard准备失败,构建后同42项全部通过,随后完整集合复跑也通过。root npm缺失和错误测试路径的准备失败单独保留,补依赖后同162项均通过。安装身份正例/负例和冻结HTTP测试不代表真实launchctl升级、rollback或常驻服务验收。

没有查询、轮询或等待CI。author描述的历史CI不当作本轮根因、修复或豁免证据。没有PostgreSQL authority refactor或真实用户Goal/lease状态故障注入。当前head必须保持不变;integration/release与merge另由维护者验收。

我的整体评价

REQUEST_CHANGES,精确head 8a4c5e0e7d60a3799c32615d42f4487ad81a7a9e。Apply the same generated-bytecode exclusion to both distribution RECORD entries and the on-disk file set; retain owned import-root, complete-source, version, editable and symlink rejection. Add a real default pip wheel install versus --no-compile regression.

未来重构检查:建议同域窄修生成文件判定的共同owner,避免两侧集合语义继续分叉;其范围可在当前PR局部验证和回滚。正常路径及其它边界的测试已通过,不能抵消上述实际入口反例。全量合同不要求新增发布者认证;摘要与来源证明继续分开。

English verdict: REQUEST_CHANGES - 8a4c5e0. P1: real default pip records1212 generated pyc entries, but the new identity filters only the disk side, so a valid owned wheel still lacks package_fingerprint. The same wheel installed with --no-compile qualifies. Native190, architecture162 and mocked helper pass; preserve ownership/source negatives and add a real compiled-wheel regression.

Comment thread loopx/release_manifest.py
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
@mergify mergify Bot removed the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 4, 2026

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent · gpt-6.1-sol · OpenAI · runtime_reported · xhigh

未发现阻塞项。 上次默认 pip 的 P1 已在完整当前 PR 与实际安装入口独立复验;以下批准只适用于这个精确 head。

动机

用普通 pip 安装并管理本机后台服务的用户。

用户升级同版本安装包并重装后台服务时,原先合法的普通 wheel 会被拒绝,已有工作区选择也可能丢失;现在 helper 能识别实际安装包并保留所选目录与 registry。

当前完整 wheel 的默认 pip 与 no-compile 指纹一致,实际安装 console doctor 通过;已启动 HTTP 服务保持原身份,重装配置的保留与非法路径拒绝通过隔离 smoke。

本轮不替换运行中的 Bot/服务,不验收真实 launchctl 常驻、重启登录后恢复或 provider 消息,也不把指纹当发布者认证。

实际用户服务升级、登录后恢复及 provider acceptance 仍由既有安装/发布 owner 单独资格化。

改动思路

复用 release_runtime_identity、现有 doctor、Chat/Status server 及 macOS helper。snapshot 保留 release/source 身份;非 editable wheel 从真正导入包与 RECORD 所属字节生成 additive fingerprint。同版本字节不同便不再被当成相同服务。服务器构造时保存身份,后续 HTTP 不因为磁盘替换而改称运行了新包。

helper 从选定 console 的 installation-only doctor 获取解释器,避免 checkout 环境接管其它 pip/uv/pipx 安装;读旧 plist 的 registry、Codex home 和目录数组,在替换或 bootstrap 前验证。选定路径只是发现范围,不授 conversation/host 权限,没有新增安装器、runner、scheduler 或 authority。

具体改动

全量13文件 +441/-34 已读。相较上次 8a4c5e0e7d60a3799c32615d42f4487ad81a7a9e,新增共享字节码过滤和真实 pip 回归,并以签名追加 merge 同步当前 main;审批同时覆盖当前整个 diff,不只过滤函数。

关键代码讲解

  • _distribution_artifact_file(release_manifest.py:348)为 RECORD 与磁盘集合使用相同的 __pycache__/pyc/pyo 排除规则,修复默认 pip 的生成记录不对称。_distribution_runtime_fingerprint(:352)仍核验实际导入根、版本、完整文件集合、editable 和 symlink,hash 真实字节而非相信 RECORD hash。
  • resolve_global_registry 保留显式/旧 plist/default route,并在 checkout 外使用选定解释器解析;resolve_chat_scan_paths 验证最多32个现存绝对目录,去重和逐项 quote,shell 元字符保持字面值。移除会覆盖明确 registry 的 --global-registry,Chat 与 status 都收到同一选择。
  • Chat/Status 构造保存 runtime_identity,capabilities/readiness 消费该 snapshot;full/installation-only doctor 提供同一身份及 Python 可执行路径。helper 在替换 plist 和停止旧服务之前拒绝不合格身份/路径,并限定本机 HTTP 探测时间。

其它路径:5份测试/隔离 helper smoke 覆盖同版本字节、默认 pip、冻结 HTTP、选择保留与拒绝;安装说明披露运行/禁用/rollback 和指纹边界;registry IO manifest 仅随实际代码调整行锚,没有另一个 registry writer。

规范 docs/guides/installing-loopx.md,不可变版本 4537095659eeee499b869f6f1869703583f77aef,新安装说明用于披露而非自证:Installation owner and package — implemented(实际 selected wheel/console);Managed Effect runtime — implemented(实际 HTTP startup identity 与 native runtime tests);Rollback — deferred(同安装 owner 的步骤及隔离 helper 恢复已检查,真实用户 launchctl rollback 尚未执行)。

对主干的风险

独立构建当前完整 wheel,在隔离 Python3.12 环境用实际 pip 安装:默认记录1231个 pyc,no-compile记录0个,两者 fingerprint 相同,两份实际 console 的 installation-only doctor 均 ok。上次8a完整 wheel 默认安装记录1215个 pyc,仍无 fingerprint,反例确实区分修复。当前真实安装的 Chat HTTP 启动后改 owned README 字节,新读取身份变化,已启动 HTTP 仍返回原 fingerprint;加未归属源码拒绝,恢复后原摘要读回一致。没有修改 RECORD 伪造通过。

当前174项相关 native 测试通过;不可变当前 base 的同7份既有测试158项通过。13项 identity 保留 editable/import-root/extra/missing/symlink/broken-symlink/version 负例。Chat bundle 与完整 wheel构建、隔离 helper smoke、7项 IO census(已含174)、Ruff、diff、完整 semantic smoke 都通过。开始时 checkout 的旧 bundle 导致4项准备失败,重建后同完整174项重跑通过;错误测试路径、tsx 准备和独立 HTTP fixture 缺 close 清理方法的失败均保留、修正,没有改产品代码/断言/预算,也没有把这些失败当成通过。真实 wheel HTTP 的最终 probe 含完成清理的独立回读。

语义与 CI 对齐

扩展既有 loopx_runtime_identity_v1 的可选 package_fingerprint;它只用于本机 service reuse,不是 publisher/source 认证。语义/IO检查通过;advisory 没有支持的新 vocabulary 不是完整等价证明。control-plane write API 的显式 opt-in 仍保持默认关闭,helper smoke 验证了该分支。没有查询、轮询或等待 CI。

我的整体评价

APPROVE,精确 head d2987cc575f9c1717d83b29c1c364c1a1415f43e。long_horizon 和 user_experience 均 improved:正常安装能继续已有选择,同版本升级可以区分新字节与旧进程,不需要新的授权/运行队列。结果是有用且可独立回滚的安装修复切片,实际登录后常驻、真实 provider 和当前用户服务升级仍由原 owner 另验。

未来重构检查已应用:同域共享 artifact predicate 消除了两个文件集合的知识重复;不需要新 wheel authority 或更大的 installer 框架。真实部署 compatibility 保留 snapshot/旧 helper fallback 和持久 plist 选择,新的字段 additive。上次全部 review/inline 已重读,P1 根因由当前 real default-pip 反例/控制证明解决;批准后另读 native closeout 和 raw GitHub decision。runtime/product 仍留维护者合并,不自合并。

English verdict: APPROVE - d2987cc. Real full-wheel default pip and no-compile identities now match; both installed console doctors pass. Actual installed Chat HTTP retains startup identity after owned bytes change, source ownership rejects unowned additions and recovery restores the digest. Native174/base158, helper/build/IO/semantic checks pass. No CI queried; live launchctl/provider/upgrade acceptance remains separate.

@mergify

mergify Bot commented Oct 4, 2026

Copy link
Copy Markdown

This pull request has merge conflicts with main and cannot be merged
until they are resolved. Please rebase or merge the base branch, @huangruiteng.

Choose the remote for the base repository, not an out-of-date fork.
For a fork clone, first inspect git remote -v; upstream must point
to https://github.com/loopx-project/loopx.git. If it is absent, add it
with git remote add upstream https://github.com/loopx-project/loopx.git.
Then run:

git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEAD

For a same-repository clone whose origin points to
https://github.com/loopx-project/loopx.git, use origin instead of
upstream for fetch/rebase. If you prefer merging the base, use
git merge <base-remote>/main and push normally.

Keep the DCO Signed-off-by trailer on every commit when you rebase.
https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/syncing-a-fork

@mergify mergify Bot added the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 4, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-rebase Mergify: the pull request has merge conflicts with its base branch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants