test(goal-direction): check in the F2 revision-drift fixture (GH-C89b) - #5549
Conversation
Implements Appendix D F2 of goal-direction-baseline-v0 as a public-safe smoke ahead of M1: a fixture-local synthetic pure builder proves that a revision change after the selected Agent's receipt reports re_evaluation_required / material_revision_changed with the changed item stale, while inputs stay byte-identical and no Vision patch, Todo, wake, lease, Goal amendment, or path delta is emitted. The mutation arm proves that relaxed revision matching and cross-Agent receipt trust fail the same contract, so the check cannot pass vacuously. No runtime code changes: the RFC's M1 builder is not authorized, so the builder lives in the example and the projection carries only allowlisted public-safe keys (opaque ids, revisions, digests, typed tokens). Records the delivery in the bilingual RFC ledger (Appendix A entry, E4 evidence row) and documents in Section 11 and Appendix D why M1 remains closed. Closes loopx-project#5547 Signed-off-by: BigDataDZ <76271875+BigDataDZ@users.noreply.github.com>
23f6acb to
d083d81
Compare
huangruiteng
left a comment
There was a problem hiding this comment.
Reviewer: model_agent — gpt-6.1-sol (OpenAI); runtime_reported; reasoning_effort=xhigh
Exact reviewed head: d083d81
动机
方向材料更新后,维护者需要能复现“旧阅读记录不能证明新版本已读”的检查,避免未来 builder 把过期依据继续显示成 current。
此前 RFC 的 F2 修订漂移行只有文字,没有可执行反例。现在用两个虚构材料和同一 Agent 的阅读记录,先验证 current,再把一个材料的要求版本从 rev-6 改为 rev-7,验证它变成 stale 并提示重新评估。
该合成检查实测输出 re_evaluation_required/material_revision_changed,输入保持字节一致且 effects 为空;放宽 revision 和跨 Agent 复用新阅读记录的两个变体均被拒绝。
本 PR 交付 pre-M1 合成 fixture 与双语记录,不交付生产 builder、consumer、真实材料读取或 Vision/Todo/lease 写入;M1 入口决策和其余 F1/F3–F8 未完成。
改动思路
规范采用 docs/architecture/rfcs/goal-direction-baseline-v0.md,固定版本 99839ae,并先读 #5547 GH-C89b 的 fixture-only 边界。逐项映射:F2:同 Agent 的旧 revision 不能证明新版本已读;Appendix D:故意放宽 revision/Agent 匹配必须让同一个 F2 oracle 失败;§11:合并 M0 或合成 fixture 不授权 M1;§7:不复制源文、不产生写入权限或变更。这些标准来自改动前 RFC;新增 ledger 不用作自证标准。
具体改动
invented_authority/invented_receipts 提供两个虚构材料,build_projection 是 fixture 内的纯 builder。assert_f2_contract 独立检查聚合状态、原因、stale 行、新旧 revision、2/1/1/0 计数、零 effects、输入字节一致、truth flags 和公开字段边界。expect_f2_failure 复用同一 oracle,两条 arm 分别放宽版本和 Agent 匹配;digest 还检查 authority 更新后变化、不同 Agent 共用同一 authority 时不变化。两份 RFC 只加 pre-M1 限定、镜像 ledger 与 fixture 链接,E4 仍标 pending;没有改规范要求。
对主干的风险
独立运行脚本通过 F2 正例及两个匹配变异。额外注入 todo_write effect 和修改 authority 输入均被 oracle 拒绝;把正确 projection 传给 expect_f2_failure 会报“mutation passed”,证明它不是靠无关前置错误伪造 mutation 成功。
首次 premerge 因缺失本机 TypeScript 检查依赖失败;npm ci --ignore-scripts 后同命令的技术检查全部通过,但 overall gate=quality_receipt_missing,diff/compile、semantic、风险检查、公开边界通过,无 manual hold。本地 Goal 严格质量 receipt 缺失,overall premerge 仍为 false;检查 scope 还包含不属于 PR 的未跟踪 uv.lock。此项保留为合并门槛,本次只评审、未合并。未读取/等待远端 CI。字段 denylist 只是本合成输出的辅助公开性检查,核心 drift 状态依赖显式 revision/Agent 比较;不应作为未来生产分类或隐私完备性证明。
主要局限是没有生产 builder/consumer:这条测试不能发现将来生产实现独自退化,也没有证明真实 Goal store、receipt 排序、frontend 展示或长程业务效果。F1、F3–F8 和 M1 决策仍保留原交付边界;此处不因未来缺口否定明确要求的 F2 prerequisite。
我的整体评价
APPROVE,结论限于 #5547 的 F2 fixture 交付。long_horizon=preserved:本 PR 不接入运行中的 Agent,不改 wake、quota、lease 或 Vision/Todo;旧依据和跨 Agent 复用受到可执行契约压力。user_experience=improved:维护者由只能读表格变为可执行一条命令、看到真实失败反例;生产用户体验收益仍待 M1/M2 证明。未来重构检查建议在 M1 接入 typed owner 时复用独立 oracle、替换 fixture-local builder,不添加第二生产权威。现有覆盖和同作者近期批次没有同形 F2 重复。341 行有维护成本,但含独立 oracle、公开边界及有意义 mutation,未引入闲置生产框架,符合明确的 pre-M1 请求。
English verdict: APPROVE - d083d81; the accepted pre-M1 F2 boundary is now executable and mutation-sensitive; F2, independent effect/input/non-vacuity probes and canary technical checks passed; strict local quality-receipt merge hold retained. This does not qualify a production builder or consumer.
Goal And Delivered Outcome
Outcome basis / optional anchor: GH-C89b (contributor task board, Lane C) — goal-direction-baseline-v0 §7 synthetic case F2 / Appendix D. Claim issue: [Task]: check in synthetic case F2 for goal-direction-baseline-v0 (GH-C89b) #5547.
Goal/source and gap: the RFC's M0 delivery (docs: define a provider-neutral goal direction baseline #4172) leaves its §9 F2 row as prose — nothing on
mainexecutes "revision changes expose drift without mutation", and Appendix D requires the fixture table to become a checked-in public-safe fixture with a mutation test before M1.Observable before → after, with the validation row that proves it: before,
re_evaluation_required/material_revision_changedexist only in docs; after,python3 examples/goal-direction-baseline-f2-smoke.pypasses on current main and proves that a revision change after the selected Agent's receipt reportsre_evaluation_required/material_revision_changedwith the changed itemstale, while inputs stay byte-identical and no Vision patch, Todo, wake, lease, Goal amendment, or path delta is emitted — and its mutation arm fails under relaxed revision matching or cross-Agent receipt trust (rows below).Issue/task and intended base: Closes [Task]: check in synthetic case F2 for goal-direction-baseline-v0 (GH-C89b) #5547; base
main.Author Declaration
Implemented against
docs/architecture/rfcs/goal-direction-baseline-v0.md@ upstream99839ae(M0, landed in docs: define a provider-neutral goal direction baseline #4172)re_evaluation_required;material_revision_changed; changed item stalebuild_projection+assert_f2_contractinexamples/goal-direction-baseline-f2-smoke.pypython3 examples/goal-direction-baseline-f2-smoke.pyeffectslist +MUTATION_EFFECT_KINDStop-level key checkassert_public_boundary+ key-set checks (raw_source_body_recordedis the RFC's own negation flag)expect_f2_failure(relaxed revision, cross-Agent trust)ruff checkon the new file (clean), andloopx check --scan-path docs/architecture/rfcs(public-boundary scan clean, 176 files). No runtime behavior assumed: the fixture is synthetic, adds no runtime code, and runtime modules are deliberately untouched.Scope And Continuation
Validation
manualpassedpython3 examples/goal-direction-baseline-f2-smoke.py— F2 contract passes; both mutation arms fail the contract as requiredstaticpassedruff check examples/goal-direction-baseline-f2-smoke.py— cleanstaticpassedloopx check --scan-path docs/architecture/rfcs— public-boundary scan clean (176 files); expected registry-absent warnings onlyunitnot_runSee validation disclosure guidance.
Frontend / Visual Evidence
Type of Change
LoopX Area
Technical Direction
Shared-authority RFC fixture impact
N/A — this PR does not touch the TypeScript control-plane migration or the shared Goal Authority RFC fixtures.
Boundary Checklist
.loopx/,.codex/goals/, and liveACTIVE_GOAL_STATE.md).none.Signed-off-bytrailer (git commit -s).