fix(service): qualify owned wheels and retain macOS workspace selection - #5543
huangruiteng wants to merge 5 commits into
Conversation
…tion Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
|
This pull request has merge conflicts with Choose the remote for the base repository, not an out-of-date fork. git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEADFor a same-repository clone whose Keep the DCO |
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent · gpt-6.1-sol · OpenAI · runtime_reported · xhigh
[P1] 普通 pip 安装仍被新运行时指纹校验拒绝。
动机
用普通 pip 安装后管理本机后台服务的用户,需要确认服务运行的是当前安装包,并保留已选工作区。
以前后台服务校验只接受带发布清单的快照,普通包管理器安装会被拒绝;本改动拟接受属于当前安装的实际包文件,并保留已有工作区选择。
已验证禁用字节码编译的同一 wheel 能获得指纹;但普通 pip 安装仍没有指纹,后台服务的合法安装入口尚未修好。
本轮不验收真实 launchctl 常驻升级、用户已有服务迁移、跨主机或发布,也不把包指纹当发布者认证。
改动思路
复用 release_runtime_identity 为无发布清单的包管理器安装添加实际字节摘要;不能仅凭版本相同认定服务是当前安装。ChatHTTPServer 与 StatusHTTPServer 构造时保存启动身份,之后 HTTP 不随磁盘升级改写旧进程。doctor 提供实际 Python 解释器,macOS helper 使用所选 console 的解释器解析并保存既有 registry、Codex home、工作区列表。既有 snapshot 和 package manager 各自保留原 ownership。
规范依据:docs/guides/installing-loopx.md,不可变版本 99839aeb8fed5fae38a5d319391cd050672a6508。逐项判断:
-
Installation owner and package: not_met — Real default pip wheel install records1212 pyc and returns no fingerprint; no-compile same wheel returns a digest..
-
Managed Effect runtime: implemented — pr5543-144225 native and owner counterexample/control evidence.
-
Rollback: deferred — Mocked helper reinstall/restart/context retention verified; no actual user launchctl rollback performed..
具体改动
全量13文件396+/34-。release_manifest.py:348 的 _distribution_runtime_fingerprint 核验非editable、精确版本、真正导入模块、完整文件集合和symlink,哈希真实字节;doctor/installation-only doctor 读同一身份和解释器。两个HTTP server冻结构造身份;现有dashboard readiness复用该身份。
macOS helper 优先询问选定console的解释器,解析已有plist环境与旧shlex参数;registry必须绝对路径,roots是最多32项的现存绝对目录JSON,去重并逐项quote。显式registry同时传给Chat/status,移除会覆盖自定义registry的global选项;先验证身份/参数再bootstrap。IO manifest只是行号变化。focused distribution/server/dashboard/doctor测试、mocked helper smoke及双语安装说明覆盖同一改动。
缺陷在 release_manifest.py:360–377:安装清单集合保留所有loopx/条目,磁盘集合却排除__pycache__/pyc/pyo;真实pip默认安装会在RECORD记录生成的pyc。独立构建当前head的完整wheel,在隔离Python3.12环境用真实pip正常安装,读到2800项loopx文件,其中1212项pyc。实际安装console的doctor installation-only成功,但service_runtime_identity没有package_fingerprint,且无release_id;helper期望身份因而仍拒绝合法安装。同一wheel用pip --no-compile安装产生指纹。没有修改RECORD或把mock返回当包归属证明。最小修复是在清单与磁盘两侧对称排除生成字节码,保留源码完整性、版本/import-root/editable/symlink所有拒绝条件;加入真实default pip的回归。
对主干的风险
当前190项focused原生测试、162项架构/语义IO检查、source Chat bundle/frontend tsc构建、LaunchAgent mocked smoke、diff/DCO通过;2项Windows-only在macOS跳过,未冒充跨平台验收。不可变base同集合中的既有非dashboard/native检查134项通过(同2项平台skip)。对照重点是实际默认pip安装与同wheel no-compile;不是用通过的synthetic distribution fixture否定真实失败。初次缺少source bundle导致的4项dashboard准备失败,构建后同42项全部通过,随后完整集合复跑也通过。root npm缺失和错误测试路径的准备失败单独保留,补依赖后同162项均通过。安装身份正例/负例和冻结HTTP测试不代表真实launchctl升级、rollback或常驻服务验收。
没有查询、轮询或等待CI。author描述的历史CI不当作本轮根因、修复或豁免证据。没有PostgreSQL authority refactor或真实用户Goal/lease状态故障注入。当前head必须保持不变;integration/release与merge另由维护者验收。
我的整体评价
REQUEST_CHANGES,精确head 8a4c5e0e7d60a3799c32615d42f4487ad81a7a9e。Apply the same generated-bytecode exclusion to both distribution RECORD entries and the on-disk file set; retain owned import-root, complete-source, version, editable and symlink rejection. Add a real default pip wheel install versus --no-compile regression.
未来重构检查:建议同域窄修生成文件判定的共同owner,避免两侧集合语义继续分叉;其范围可在当前PR局部验证和回滚。正常路径及其它边界的测试已通过,不能抵消上述实际入口反例。全量合同不要求新增发布者认证;摘要与来源证明继续分开。
English verdict: REQUEST_CHANGES - 8a4c5e0. P1: real default pip records1212 generated pyc entries, but the new identity filters only the disk side, so a valid owned wheel still lacks package_fingerprint. The same wheel installed with --no-compile qualifies. Native190, architecture162 and mocked helper pass; preserve ownership/source negatives and add a real compiled-wheel regression.
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent · gpt-6.1-sol · OpenAI · runtime_reported · xhigh
未发现阻塞项。 上次默认 pip 的 P1 已在完整当前 PR 与实际安装入口独立复验;以下批准只适用于这个精确 head。
动机
用普通 pip 安装并管理本机后台服务的用户。
用户升级同版本安装包并重装后台服务时,原先合法的普通 wheel 会被拒绝,已有工作区选择也可能丢失;现在 helper 能识别实际安装包并保留所选目录与 registry。
当前完整 wheel 的默认 pip 与 no-compile 指纹一致,实际安装 console doctor 通过;已启动 HTTP 服务保持原身份,重装配置的保留与非法路径拒绝通过隔离 smoke。
本轮不替换运行中的 Bot/服务,不验收真实 launchctl 常驻、重启登录后恢复或 provider 消息,也不把指纹当发布者认证。
实际用户服务升级、登录后恢复及 provider acceptance 仍由既有安装/发布 owner 单独资格化。
改动思路
复用 release_runtime_identity、现有 doctor、Chat/Status server 及 macOS helper。snapshot 保留 release/source 身份;非 editable wheel 从真正导入包与 RECORD 所属字节生成 additive fingerprint。同版本字节不同便不再被当成相同服务。服务器构造时保存身份,后续 HTTP 不因为磁盘替换而改称运行了新包。
helper 从选定 console 的 installation-only doctor 获取解释器,避免 checkout 环境接管其它 pip/uv/pipx 安装;读旧 plist 的 registry、Codex home 和目录数组,在替换或 bootstrap 前验证。选定路径只是发现范围,不授 conversation/host 权限,没有新增安装器、runner、scheduler 或 authority。
具体改动
全量13文件 +441/-34 已读。相较上次 8a4c5e0e7d60a3799c32615d42f4487ad81a7a9e,新增共享字节码过滤和真实 pip 回归,并以签名追加 merge 同步当前 main;审批同时覆盖当前整个 diff,不只过滤函数。
关键代码讲解
_distribution_artifact_file(release_manifest.py:348)为 RECORD 与磁盘集合使用相同的__pycache__/pyc/pyo 排除规则,修复默认 pip 的生成记录不对称。_distribution_runtime_fingerprint(:352)仍核验实际导入根、版本、完整文件集合、editable 和 symlink,hash 真实字节而非相信 RECORD hash。resolve_global_registry保留显式/旧 plist/default route,并在 checkout 外使用选定解释器解析;resolve_chat_scan_paths验证最多32个现存绝对目录,去重和逐项 quote,shell 元字符保持字面值。移除会覆盖明确 registry 的--global-registry,Chat 与 status 都收到同一选择。- Chat/Status 构造保存
runtime_identity,capabilities/readiness 消费该 snapshot;full/installation-only doctor 提供同一身份及 Python 可执行路径。helper 在替换 plist 和停止旧服务之前拒绝不合格身份/路径,并限定本机 HTTP 探测时间。
其它路径:5份测试/隔离 helper smoke 覆盖同版本字节、默认 pip、冻结 HTTP、选择保留与拒绝;安装说明披露运行/禁用/rollback 和指纹边界;registry IO manifest 仅随实际代码调整行锚,没有另一个 registry writer。
规范 docs/guides/installing-loopx.md,不可变版本 4537095659eeee499b869f6f1869703583f77aef,新安装说明用于披露而非自证:Installation owner and package — implemented(实际 selected wheel/console);Managed Effect runtime — implemented(实际 HTTP startup identity 与 native runtime tests);Rollback — deferred(同安装 owner 的步骤及隔离 helper 恢复已检查,真实用户 launchctl rollback 尚未执行)。
对主干的风险
独立构建当前完整 wheel,在隔离 Python3.12 环境用实际 pip 安装:默认记录1231个 pyc,no-compile记录0个,两者 fingerprint 相同,两份实际 console 的 installation-only doctor 均 ok。上次8a完整 wheel 默认安装记录1215个 pyc,仍无 fingerprint,反例确实区分修复。当前真实安装的 Chat HTTP 启动后改 owned README 字节,新读取身份变化,已启动 HTTP 仍返回原 fingerprint;加未归属源码拒绝,恢复后原摘要读回一致。没有修改 RECORD 伪造通过。
当前174项相关 native 测试通过;不可变当前 base 的同7份既有测试158项通过。13项 identity 保留 editable/import-root/extra/missing/symlink/broken-symlink/version 负例。Chat bundle 与完整 wheel构建、隔离 helper smoke、7项 IO census(已含174)、Ruff、diff、完整 semantic smoke 都通过。开始时 checkout 的旧 bundle 导致4项准备失败,重建后同完整174项重跑通过;错误测试路径、tsx 准备和独立 HTTP fixture 缺 close 清理方法的失败均保留、修正,没有改产品代码/断言/预算,也没有把这些失败当成通过。真实 wheel HTTP 的最终 probe 含完成清理的独立回读。
语义与 CI 对齐
扩展既有 loopx_runtime_identity_v1 的可选 package_fingerprint;它只用于本机 service reuse,不是 publisher/source 认证。语义/IO检查通过;advisory 没有支持的新 vocabulary 不是完整等价证明。control-plane write API 的显式 opt-in 仍保持默认关闭,helper smoke 验证了该分支。没有查询、轮询或等待 CI。
我的整体评价
APPROVE,精确 head d2987cc575f9c1717d83b29c1c364c1a1415f43e。long_horizon 和 user_experience 均 improved:正常安装能继续已有选择,同版本升级可以区分新字节与旧进程,不需要新的授权/运行队列。结果是有用且可独立回滚的安装修复切片,实际登录后常驻、真实 provider 和当前用户服务升级仍由原 owner 另验。
未来重构检查已应用:同域共享 artifact predicate 消除了两个文件集合的知识重复;不需要新 wheel authority 或更大的 installer 框架。真实部署 compatibility 保留 snapshot/旧 helper fallback 和持久 plist 选择,新的字段 additive。上次全部 review/inline 已重读,P1 根因由当前 real default-pip 反例/控制证明解决;批准后另读 native closeout 和 raw GitHub decision。runtime/product 仍留维护者合并,不自合并。
English verdict: APPROVE - d2987cc. Real full-wheel default pip and no-compile identities now match; both installed console doctors pass. Actual installed Chat HTTP retains startup identity after owned bytes change, source ownership rejects unowned additions and recovery restores the digest. Native174/base158, helper/build/IO/semantic checks pass. No CI queried; live launchctl/provider/upgrade acceptance remains separate.
|
This pull request has merge conflicts with Choose the remote for the base repository, not an out-of-date fork. git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEADFor a same-repository clone whose Keep the DCO |
Ordinary pip/uv/pipx wheel installations must qualify for the existing macOS service helper, and reinstall must retain the selected registry, Codex home and workspaces. This change fingerprints the actual imported, RECORD-owned non-editable package and freezes each service's startup identity, while preserving snapshot identities and the existing service owner.
The default-pip review defect is fixed at
d2987cc575f9c1717d83b29c1c364c1a1415f43e: one package-local artifact predicate excludes generated__pycache__,.pycand.pyoentries on both the installed RECORD and disk sides. Imported-root/version/editable/complete-source/symlink refusal remains intact; changed owned bytes still change the fingerprint. The helper retains bounded, validated workspace selection and custom registry parameters. This is a local reuse fence, not publisher or source attestation.The branch now integrates main
4537095659eeee499b869f6f1869703583f77aefthrough signed append-only merges, resolving the stale registry IO anchors. The PR remains 13 paths; no generated uv.lock is submitted. Placement stays in the existing release identity and macOS service helper; the shared filter removes duplicated artifact-set semantics without adding another installer, service or authority.Validation at this head:
goal_topic_runtime.py. Current main independently reproduces that same debt; no budget was raised. Change-quality policy is disabled for this Goal, so no quality receipt is claimed.Historical real launchctl startup/restart evidence in the earlier PR remains historical. This repair does not repeat actual login-after-reboot, real provider inbound or a normal release upgrade, and does not replace the installed tool or running Bot service. Full remote CI at this new head is not yet qualified. Runtime/product changes remain for exact-head maintainer review and merge; this task does not self-merge or bypass that gate.