Skip to content

fix(workspace): isolate edits and preserve complete current evidence - #5587

Merged
huangruiteng merged 18 commits into
mainfrom
codex/l1-evidence-return-20261004
Oct 5, 2026
Merged

huangruiteng merged 18 commits into
mainfrom
codex/l1-evidence-return-20261004

Conversation

@loopx-agent

@loopx-agent loopx-agent commented Oct 4, 2026 •

Copy link
Copy Markdown
Collaborator

Separate verified Git worktrees can edit overlapping repository files without a cross-checkout file mutex. Explicit --write-worktree treats those overlaps as integration advisories, including a retained grant whose workspace is unknown. Known same-checkout collisions, ordinary exclusive acquisition, shared-state authority, Todo ownership, TTL/CAS and original receipts remain fenced. No other grant is rewritten.

The existing workspace now reads a Task’s complete current request on demand through the same Todo authority, keeps summary/thin packets bounded, and exposes loading, source failure and retry. Linked team evidence has a stepwise return path, fresh current-list readback and restored keyboard focus. Lost downstream adoption remains distinct from current core evidence. The validation basis is a path-free current definition observation, not an independent-verifier receipt.

The owning boundaries are the existing typed lease, Goal acceptance and delegation validation owners, existing Todo source reader, and existing Task/evidence presentation. No new capability/provider, configuration switch, task store or polling loop. Frontend and exact CLI reads change; Lark entrypoints remain unchanged.

Current-head repair at b7763c1321da5b93f940bee633b884bc75db0ca1 integrates immutable main 896cdf1278ab2358260f4b5c59b211baa3a525ac. Origin URL/default-port safety and both-provider tests are retained alongside the old-grant/collision cases; the I/O manifest is regenerated. GitHub’s stale base projection was refreshed to that same main. Local and remote comparisons both contain 40 files, +907/-115. All 18 branch commits carry DCO sign-off, and the push preserves the original head history.

Validation at this head:

  • 71 focused Python cases plus 20 long-history/pagination/retained-reader cases pass. Real File/SQLite Git-worktree CLI, exact active/retained HTTP/CLI, and production delegation/Turn are covered with disposable synthetic state/model hosts.
  • Full TypeScript suite: 4042 pass, 31 optional PostgreSQL/service skips. Separately, disposable real PostgreSQL 16.2 store/workspace/acceptance/delegation: 430 pass, 0 skip; the isolated instance was removed.
  • Exact-source Chat production build, TypeScript typecheck, all 43 packaged workspace browser scenarios and the dedicated evidence-return scenario pass. Real SQLite/HTTP/CLI plus the actual packaged page returns all 988 source characters and the final acceptance condition; a real unavailable-source 503 shows only the 500-character summary, then retry restores the full body. Escape/Enter return to the original task. Canonical Todos and provider revision are unchanged after observation.
  • Changed-diff semantic advisory precedes the full-tree semantic check; typed local unions and existing shared owners are manually traced. Public boundary scan, DCO and risk-based canary pass. Canary: 5 direct checks, 19 selected checks (18 passed, one inherited advisory), zero blocking failures/manual holds, strict exact-scope quality receipt passes. CI was not consulted under the resolved review policy.

The routine npm packaged entry stops at a pre-existing locale source-text assertion. The same immutable-main test and producer blobs fail identically; the actual 43 browser scenarios were run separately without removing assertions or scenarios. The raw maintainability report retains three identical baseline/head findings and metrics; no budget or scan scope was changed. The first canary’s not-yet-recorded quality receipt failure is retained; unchanged-scope requalification passes after recording the completed result.

Live Team Workspace/L3 checkpoints remain bounded: independent exact-version verifier evidence, real semantic objection and two real correction/requester-adoption cycles remain open. Synthetic browser/model fixtures do not qualify those outcomes. Installed Native behavior, complete screen-reader/200% zoom, broad live-team scale/stream/comprehension and formal signed release are not claimed here. The prior Native startup issue is addressed by already-merged #5582 in the current base.

Future-facing review reuses the physical-checkout predicate and current typed validation plan, keeps reference-only navigation and per-open reads, and avoids another authority/protocol/store. The first viewport, hero, opening navigation and primary CTA are unchanged. Existing public screenshots are synthetic evidence-reader states.

中文:本轮保留主干 origin/端口安全校验与旧 grant 围栏,解决3处冲突并刷新 GitHub 主干基线。真实打包页面已读回988字要求、503退回摘要及恢复重试,证据返回与焦点恢复、真实 File/SQLite/PostgreSQL 边界均已重新验证。已有 locale 源码断言和 maintainability 基线失败保留并独立归因;不查询 CI,不把合成数据或本次合并当成独立语义验收/真实团队持续协作/已安装 App 验收。原记录和验收 owner 保留,无新权限、能力、配置或任务仓库。

@loopx-agent
loopx-agent marked this pull request as draft October 4, 2026 14:18
@loopx-agent loopx-agent changed the title fix(chat): retain current acceptance and return through linked evidence fix(chat): keep current evidence and execution-list state on return Oct 4, 2026
@loopx-agent loopx-agent changed the title fix(chat): keep current evidence and execution-list state on return fix(chat): keep current evidence through navigation and recovery Oct 4, 2026
@loopx-agent loopx-agent changed the title fix(chat): keep current evidence through navigation and recovery fix(chat): keep evidence navigation and current validation readable Oct 4, 2026
@loopx-agent loopx-agent changed the title fix(chat): keep evidence navigation and current validation readable fix(collaboration): allow isolated edits and preserve current evidence Oct 4, 2026
@loopx-agent
loopx-agent marked this pull request as ready for review October 4, 2026 21:29

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

APPROVE。完整 head 5587@1fecd0f2bf5bf4103a53f0c246087ad7d36e3f18 未发现阻塞问题;下述 P2 是测试入口的非阻塞改进建议。COMMENTED 自评不是 GitHub 正式批准或合并授权。

动机

在同一 Goal 内独立编辑代码、随后阅读团队纠偏证据的操作者。

以前独立工作目录仍可能被旧文件租约拦住;阅读关联证据后又要重新找回原执行,采用失联还会抹掉仍然有效的纠偏路径。现在独立目录可继续编辑并收到集成提示,关联证据能逐级返回,采用失联单独标明。

实测旧租约保持不变,普通独占和同目录冲突仍拒绝;核心产物变化会清除正文并撤回列表验收,恢复后显式重读可重新显示。

本次只验收协作代码编辑与按需证据读回,不验收整个团队的真实模型纠偏、持续运行或合并权限。

最新提交还补了点击任务的阅读连续性:以往 macOS 点击按钮不一定取得焦点,关闭详情可能回到前一个导航控件;现在 Escape/关闭回到原任务或动作按钮,Enter 可打开同一任务。当前打包版本桌面和390px均通过,未触发模型或 Todo 写入;已安装 native App 尚未重验此补丁。

独立验收者的准确版本回执、两轮真实模型协作及完整 L1 用户验收仍未完成;界面对此明确显示缺口。

改动思路

租约仍由既有 TypeScript owner 根据 canonical Todo、owner、当前租约和实际目录身份判断。新增行为只允许已验证调用者把跨 checkout 文件重叠当集成提示;同物理目录冲突优先于仓库 metadata,原持有者无需改动。普通独占仍用原有边界。CLI/MCP/HTTP 的接受读回仍运行原 validator 和输出版本检查,规则摘要来自同一 typed plan,Python 只执行原 effects 和文件 IO。

界面保留的是执行引用,返回时重新读;不把旧正文或验收缓存当当前事实。原产物、回应、修订先独立核验,后续采用再核验准确的 operation/request/Agent/Todo、输入和输出。下游缺失只撤掉采用,核心失效清除纠偏路径。规则摘要和“独立验收证据未提供”分开展示,避免把 successful validator 当独立复核。

任务入口在打开详情前显式聚焦自己的按钮,再复用原抽屉的 active-element 捕获与关闭恢复;不新增焦点状态源,也不从 Goal 或执行推断未指派 Todo 的 owner。

具体改动

完整 base 2f68e3b835c3bfc0e3718373cdb6c72eea99291e → head,共 29 文件 +566/-109:六处 runtime、六处 UI、八处验证、九处文档/合成截图。租约 admission、完成后接受绑定、读回摘要和前端返回构成同一个实际协作路径;不是只审最显眼的 UI 改动。

独立规范是不可变 docs/architecture/rfcs/live-team-workspace-v0.md 和 docs/reference/canonical-lease-renew.md,按改动前文本判断。V1 Truth:当前接受、缺失采用和未知 verifier 的区别有生产读回证据;V6 Rollback:普通关闭态、旧 runtime、源丢失与显式恢复有对应检查。V3 Experience:本次桌面、390px、键盘/reduced motion 通过,完整 screen-reader/200% 矩阵仍 deferred 到原展示 owner。First live outcome: one understandable correction:真实异议与独立准确版本验收仍 deferred 到现有 L1 owner,不以作者更新后的 checkpoint 自证完成。

关键代码讲解

  • decideTaskLeaseAcquire(task_lease_acquire_decision.ts:382):保留 owner/CAS/同 Todo 校验;正向目录碰撞进入 conflict,其余已验证调用者重叠进入 advisory。sameLeaseCheckout 只比实际 host/worktree 身份,旧 sibling-only helper 删除。
  • acceptanceDigestMatches(acceptance_contract.ts:199):完成回执属于观察,不能让原工作绑定变 stale;对确曾含回执的旧 digest 保留精确兼容。修改 text、capability 或 write scope 仍使绑定失效。实际相同 SQLite 完成任务在 base 读回 goal_acceptance_stale,head 接受同一产物。
  • delegationValidationPlan(delegation.ts:22):从当前要求/effects 派生 source、摘要和检查/固定项数,不持久化 success,不输出命令或路径。_accepted 先完成原规则和文件核对,才返回正文与本次 basis。
  • GoalTasksView.selectFromButton(goal-tasks-view.tsx:136):先 focus({preventScroll:true}) 再选择,复用 ContextDrawer 的现有返回机制;任务、提醒、执行、菜单和定时入口都走同一局部 helper。负责人只做 span 包裹,仍显示 canonical Todo 的 owner。
  • GoalTeamWork.returnToList(goal-team-work.tsx:98):引用栈实现逐级返回;退出单次重读原 cursor,失败清旧行并让刷新恢复可用,恢复键盘焦点。

文档明确 worktree 行为改变、普通独占回退和当前证据的边界,中英文镜像一致;截图展示合成数据。refresh smoke 改成真正 history-only preview,核对状态/registry/runtime 不被写入,未放宽生产规则。

对主干的风险

最强反例是用编辑便利绕过别人 Todo、同物理目录或当前验收。九个相同基线/head 输入中,八个完整 decision 结果逐字一致;只有 legacy-workspace overlap 从 conflict 变 apply/advisory。真实 File/SQLite CLI 验证 retained legacy grant、目录别名、普通独占、忽略的 symlink 重定向、重放/续租/释放。当前 full control-plane 使用一次性真实 PostgreSQL 16.2,包含现有 receipt/reload conformance;没有活动 Goal 的测试改写。

真实 SQLite/HTTP/CLI 的当前 head 重跑与打包 UI 检查配对:四份已接受合成执行,basis source/check/file-pin 为 goal_acceptance/1/3;下游文件缺失时修订仍200、采用 unavailable,原产物/回应入口保留;核心变化返回409,正文清空,列表验收4→3。恢复原字节后显式重查回到4。规则文件变化也撤回正文/basis;四个 fixture host 调用数始终各1。前一版本的真实 HTTP 界面已查看桌面与390px viewport,dialog 宽度与 scrollWidth 都356、关联证据键盘返回正确;此次26个原有文件的 Git blob逐一相同。当前 head 重新构建后,既有 packaged team-evidence、return smoke 和新 task-inspector-return 全部通过,覆盖分页、失败 inventory、旧 runtime、reduced motion与任务精准返回;当前 Task 桌面/390px截图也已查看。独立去掉任务 opener 的显式 focus 后,Escape 确实回到 Tasks 导航而丢失原任务上下文;正常当前版本返回原按钮。

独立检查:63 个 Python CLI/MCP/delegation 用例通过;当前 head TS 完整隔离重跑4385通过、1个可选 service endpoint 跳过;TS 类型检查、Dashboard 与 Chat 生产构建/安装到 source checkout及 source verify、Ruff、语义 advisory→完整 smoke、refresh write smoke、diff check 通过。初次完整 suite 是4384通过/1失败/1跳过,失败是 NoKV Python consumer90秒超时;同一 native/legacy 用例在不可变 base/head 分别2项通过,完整 private-temp PG重跑通过。首次超时保留,不能声称根因已修复。当前 head 启动 PG 工具时缺少可选 pgserver,补齐隔离工具依赖后运行;并行构建曾遇到正在准备的 TypeScript library,依赖准备完成后顺序重跑生产 build 通过,源代码没有变更。构建原有 chunk-size warning 保留。早期探针的错误入口、来源目录、浏览器 locator 和过宽的 focus mutation 尝试不计作通过,最终使用当前 source、原生 CLI和只作用于任务按钮的反例。

[P2,非阻塞] 接入常规测试入口。 新的 team-evidence-return-smoke.mjs 已直接执行通过;在现有 packaged browser入口/package scripts/workflows 中未找到引用。建议把它接入既有入口,或将这些稳定断言收进已有 team-evidence scenario,避免以后只跑常规 suite 时漏掉返回/采用失联的回归;无需另建大型测试框架。

语义与 CI 对齐

复用原 lease/acceptance vocabulary,新增 validation 是当前规则定义观察,不是更宽的 actor 或 verifier receipt。advisory 的0候选不覆盖 inline object 语义,已人工核对其生产者、typed consumer与失效路径。普通独占未默认放宽,worktree opt-in 的改变有明确披露。集成 advisory 是建议;owner、同 checkout 和当前规则是机器强制。按 Goal 的 wait_for_ci=false,未查询、轮询或等待 CI;上述本地检查与未测项分别保留。

我的整体评价

本次为 justified_increment:long_horizon=improved,user_experience=improved。相同 authority 数据证实减少旧租约造成的无效阻塞;逐级返回减少重新查找,单次重新读避免把旧成功带回列表;后续失联不再要求重建当前仍有效的纠偏证据。多一次列表读是必要的当前事实核验,既有 validator 仍执行,没有新增轮询或第二验收器。精准恢复任务焦点还减少键盘重新定位成本;关闭/读取没有新增模型调用或权限写入。没有测量总 token、吞吐分布或长期时间收益,因此不外推整个团队效果。

范围与成本相称。未来演进检查已应用:复用同一 typed owner,删旧 sibling predicate,摘要复用既有 validation plan,兼容旧 binding 有真实持久消费者,返回栈只存引用,Task opener复用既有抽屉恢复。保留现有 L1/展示 owner 的独立 verifier、真实双循环和剩余可访问性验收;不新建平行计划。App/CLI/MCP/HTTP 的受影响 reading/admission 边界有证据,Lark/已安装 native App没有本次实测,不称源机职责切换或发布完成。批准精确 head,合并由维护者按仓库规则执行。

English verdict: APPROVE - 5587@1fecd0f2bf5bf4103a53f0c246087ad7d36e3f18; current-head4385 TS/63 Python passed with disposable PostgreSQL,1optional service skip; real SQLite/HTTP/CLI recovery and packaged task/evidence returns verified; opener-focus mutation detects regression; prior NoKV timeout retained; P2 evidence-smoke entry suggestion; installed native focus, real-model L1 and sustained throughput unqualified.

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh

Request changes conclusion (author-owned PR; GitHub blocks formal self-review)

REQUEST_CHANGES。精确 head 5587@d2ff7eeecc4116952dffa32da56c2954b9a8cd69 有一个 P2 阻塞:真实原生 Task 的长要求仍会在 status 投影中截断,当前详情无法读回完整原文。此前 evidence-return 测试未接入常规入口的 P2 建议已由最新 manifest 修复,不再作为待办。COMMENTED 结论不是 GitHub 正式自审或合并授权。

动机

在同一 Goal 内独立编辑代码、随后阅读团队纠偏证据和长任务要求的操作者。

以前独立目录可能被旧文件租约拦住,阅读关联证据后要重新找回原执行,任务详情还可能沿用卡片短预览。现在跨目录重叠可作为集成提示,证据和任务返回更顺畅,详情也能保留收到的较长文本。

实际隔离 SQLite/HTTP 与打包界面显示:988 字符的原生任务在桌面和390px详情中只剩500字符,末尾验收要求仍不可读;焦点返回正常且没有模型或权限写入。

本次评判协作编辑、当前证据阅读与所声明的任务原文读回,不要求整个团队的真实模型纠偏或持续运行已经完成。

这不是说本 PR 删除了 canonical 原文:上游500字符投影限制已有,但新增“原始要求”详情仍直接消费它。测试只提供较短的合成 API 数据,无法证明普通原生长任务旅程完成。更好的焦点和500字符详情有局部价值,不能替代完整要求或明确的摘要/不可用提示。

改动思路

既有 TypeScript lease owner 仍负责 Todo/owner/CAS/真实目录判断;已验证 --write-worktree 才把跨目录文件重叠当 advisory,同物理目录冲突和普通独占仍拒绝,旧持有者不变。接受读回仍执行原 validator 和文件版本检查,Python 执行 effects/IO,没有第二决策源。

证据返回栈只保留引用;每次返回重新读,核心失效清正文和纠偏路径,下游采用失联只撤采用。当前规则摘要与“独立准确版本验收未提供”分开,避免把成功 validator 当独立复核。任务入口复用现有抽屉焦点捕获/关闭返回,未指派 owner 仍来自 canonical Todo。

最新本地 requestText 字段保留 mapper 收到的 Todo.text,卡片继续截短,抽屉选择原文或兼容旧 compact-only 数据。但是生产 status 在 mapper 前已将原文截为500字符,因此该字段并不是完整 canonical request。

具体改动

完整 base 2f68e3b835c3bfc0e3718373cdb6c72eea99291e → 当前 head,共32路径 +581/-111,包括 runtime/typed规则、前端、验证、文档和合成截图。完整 diff 已核验。上一轮 1fecd0f2 后变动是三个详情/场景文件以及本次常规测试 manifest;1ee0462 → 当前只改变 manifest,其余31个路径 Git blob相同。

独立规范采用改动前 Live Team Workspace RFC 与 canonical lease contract,不以作者更新的 checkpoint 自证。V1 Truth/V6 Rollback 的 admission、来源失效与恢复有真实 authority 证据;V3 Experience 的 desktop/390px、键盘、reduced motion 已验证,但原生长任务读回当前失败。完整 screen-reader/200%以及 First live outcome: one understandable correction 的独立 verifier、真实异议/修订/采用两轮,仍归既有 L1/展示 owner。

关键代码:

  • decideTaskLeaseAcquire 与 sameLeaseCheckout:真实 checkout 碰撞优先于仓库 metadata;跨 checkout advisory 不转移 Todo 或旧 grant。
  • acceptanceDigestMatches:完成 receipt 是观察;旧 digest 只作准确兼容,工作 text/capability/write-scope 变化仍失效。
  • delegationValidationPlan 与 _accepted:复用当前 typed validation plan,检查通过后才返回正文/basis,不持久化新的 success/独立 verifier。
  • GoalTeamWork.returnToList:引用栈逐级返回并重新读列表,失败清旧行,分页/恢复保留现有 owner。
  • GoalTasksView.selectFromButton:打开前 focus,再调用 existing drawer;任务、动作、提醒等入口复用局部 helper,关闭不触发模型或 claim。
  • workspaceAgentTodoFromItem(personal-workspace-model.ts:71)→ ContextDrawer(context-drawer.tsx:657):新增字段保存收到的 text,抽屉显示它。生产 normalize_todo_item/normalize_todo_text 默认500字符,所以目前缺少完整读回边界。
  • smoke:personal-workspace-packaged:现已接入既有 team-evidence-return-smoke.mjs;在当前 head 重建后,常规 npm 入口以 Task selector运行并自动执行该独立 evidence smoke,通过,不再保留旧未接入建议。

文档中英文披露了 worktree admission 改变、普通独占回退与 verifier 边界;4张合成图沿用此前来源。history-only refresh smoke验证无状态/registry/runtime写入,没有放宽生产 NextAction gate。

对主干的风险

[P2,阻塞] Task详情还不能恢复真实长要求。 最小复现:在隔离真实 SQLite Goal 通过原生 CLI新增988字符任务,把必要验收条件放在最后;普通 Tasks卡片→详情,在1512/390px均只显示500字符,并以省略号结尾。canonical add回执保留988字符,真实 HTTP status和详情都丢失末尾。卡片122字符(含状态),Escape仍返回原按钮,0模型/authority写入。源码真实 mapper/React抽屉的相同输入对照显示,在 full input 时旧版8种语言/状态组合丢尾、head全部保留;compact-only 8种组合保持fallback。这恰好解释为什么合成测试通过却生产旅程仍不完整。

最小修复:保留热队列与卡片预算,复用既有原生 Todo detail/read owner,在详情按已授权 Todo id读取完整当前请求并展示 loading/error/retry;或者明确标注“摘要/来源已截断”并提供现有可用的完整读取入口,收窄“完整原始要求”的声明。不要把所有长文塞进每次热 status,也不要用丢失后的文本猜补原文。增加超过500字符、末尾独立验收条件的真实 SQLite→HTTP→packaged UI案例;覆盖失效/不可用与历史读取适用路径。

其他边界没有新阻塞:本轮当前源码真实 SQLite/HTTP/CLI正向、下游loss、core/pin失效和显式恢复均通过,4个 fixture host始终各调用1次。43个 packaged场景在 1ee0462 全通过;当前仅manifest变化,重建后的常规 selector+集成 evidence-return 也通过。Dashboard/Chat生产构建与来源校验通过;语义 advisory→full smoke、diff检查通过。第一次manifest后入口正确拒绝旧构建,重建后恢复;原bundle-size warning保留。

既有 File/SQLite 63项与真实一次性 PostgreSQL16.2的4385 TS通过/1可选endpoint跳过,是先前 1fecd0f2 的 qualification,未冒充本轮新跑。相关 backend源码/输入未变,Git blob已逐个核对;旧9个paired lease输入为8个完整相同结果、1个有意legacy advisory变化。先前 NoKV 90秒timeout、独立base/head2项通过和后续隔离full通过都保留,未声称修复首次超时根因。作者的已安装native App截图/读回不替代本轮独立证据,本次未升级已安装App。未查询、轮询或等待CI。

Typed/default-off/authority评审:普通独占与feature-off规则没有默认放宽;worktree opt-in改变公开披露。validation是规则观察,requestText是局部presentation carrier,无新增共享协议或独立验收权限。跨目录 advisory 是建议,同目录/owner/CAS/当前版本是机器义务。核心合同保持领域中性。

我的整体评价

长程方向有正向证据:减少重复租约阻塞和重新找证据,返回重读防止陈旧成功,精准焦点减少键盘重新定位,均保留权限和版本边界。500字符以内的源要求,新增carrier可以消除卡片预览造成的二次截短。没有测量整体token、吞吐或长期耗时,不能据此量化总效率。

当前“打开长Task读完整要求”的体验尚未成立;988→500的原生反例可能导致操作者漏看末尾条件。属于同一阅读旅程未完成,而非要求本 PR承担整个 L1路线。修复上述P2后再核验精确head。

未来演进检查:已复用typed owner、删除旧sibling predicate、复用validation plan与drawer返回状态,并接入常规smoke。剩余修复宜复用现有Todo冷读边界;没有理由新增平行reader/全局长文缓存或扩大热packet。CLI/MCP/HTTP与packaged UI证据分别记录;Lark、installed native App、完整可访问性、真实模型双循环和持续效率仍未测。合并按维护者权限执行。

English verdict: REQUEST_CHANGES - 5587@d2ff7eeecc4116952dffa32da56c2954b9a8cd69; blocking P2: real SQLite/HTTP Task request is988chars but packaged desktop/390px details retain only500, losing final acceptance conditions.43 prior-equivalent packaged scenarios, current rebuilt routine selector/evidence-return, paired React and real authority recovery passed; prior backend qualification reused by unchanged blobs; no CI queried; full native Task readback remains incomplete.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
…nces

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
@loopx-agent
loopx-agent force-pushed the codex/l1-evidence-return-20261004 branch from d2ff7ee to 05ba74e Compare October 5, 2026 00:50
@loopx-agent loopx-agent changed the title fix(collaboration): allow isolated edits and preserve current evidence fix(workspace): isolate edits and preserve complete current evidence Oct 5, 2026

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Exact head: 5587@05ba74e42eb9b4171f6fcf42e9be3b548a3bb457; immutable base 01c6651366476820f329314983255ea5bc688ad5.

动机

在同一 Goal 内独立编辑代码、并阅读原任务与团队纠偏证据的操作者。 旧文件租约可能拦住独立 worktree;查看关联证据后需要重新寻找原执行,来源失效可能保留旧验收;988 字任务经摘要进入详情后只有500字。新路径保留独立编辑和按需阅读,同时保留原有实例与来源校验。 当前真实 File/SQLite CLI/HTTP和打包界面显示完整988字及尾部要求;失败明确保留摘要并可重试恢复,产物改写后清除旧正文且验收数4→3,恢复原版本后显式重查回到4。 本次不验收真实模型异议、独立语义验收者、已安装 Native App或长期吞吐。 L1 的独立验收者及准确版本回执、两轮真实纠偏与请求方采用,仍由既有 acceptance/Live Team Workspace owner接续。

此前阻塞点是原任务尾部要求在真实阅读路径中丢失。本次重新审完整40路径,按新 head独立执行,不继承旧批准。原500字正文问题在本轮有界源码与打包路径上已解决;这不代表本机正式发布或长期协作验收。

改动思路

复用已有 TS lease/acceptance决策、Python IO与 Todo authority、React证据面板。经验证的独立 worktree将文件重叠返回为集成提示;已知同一物理目录、同一 Todo执行与普通独占仍受原规则约束。未知旧grant不被重写,也不被宣称已隔离。明确 opt-in改变代码文件协调,未赋予共享运行状态或合并权限。

先读修复前 docs/architecture/rfcs/live-team-workspace-v0.md(Live Team Workspace RFC)与lease contract,以及design/frontend delivery规定。RFC V1 的当前来源/未知、V3 的原始要求和可恢复阅读、V6 的失效撤回,分别由准确读取、键盘返回、失败清除与版本恢复验证;L1仍deferred。新增checkpoint明确为展示/读取切片,不用作者的新文案替代旧验收。

具体改动

全 diff40路径 +907/-115:TS工作目录与acquire规则、当前验收摘要兼容和validation定义;Python delegation读取及新增46行HTTP原文适配;38行TaskRequest与原 mapper/drawer/多语言、团队证据返回/采用恢复;版本化docs与4张公共合成图;native/TS/browser回归和既有refresh dry-run检查修正。manifest只更新对应I/O位置。四图逐张查看,明确缺失独立验收、失效计数及采用不可用;未改变公开首屏/hero/导航。

关键代码讲解

  • _todo_detail(loopx/chat_todo_detail.py):入口仅本机loopback、同源、单一Goal/Task;复用准确 Todo读回,404/409/503明确区分。读取不返回路径或权限配置。
  • list_goal_todos:保留typed选择与状态投影,只在准确ID、非thin单条结果里从原authority恢复完整正文。普通列表和thin预算不扩张;active/retained、缺display文件均验证。
  • acceptanceDigestMatches 与 delegationValidationPlan:完成回执是观察而非工作定义;保留精确legacy digest,真正要求/规则/固定文件改变仍失效。当前validation仅返回来源、digest、check/pin数量,不是独立verifier或持久成功凭据。
  • TaskRequest 与原团队阅读器:每次打开独立读取,身份变化/关闭abort,失败丢弃旧全文并提供retry。关联证据只保留引用、返回重新读;列表保留cursor并读一次。采用失联保留本次仍有效的纠偏,核心版本丢失则清除路径;身份、输入和输出一致才恢复采用。

对主干的风险

独立current head68项Python通过,4388项TS通过;TS使用隔离真实PostgreSQL16.2及synthetic fixtures,1项另需POSTGRES_SERVICE_URL的service-wrapper未配置,原生PostgreSQL affected store路径已实测。43个打包场景以及integrated team-return通过;build、TS typecheck、Ruff、diff、advisory→full-tree semantic、refresh-write检查通过。先跑advisory无支持语法新carrier;全树仍有44项未证明producer限制,不宣称覆盖全部动态语义。

另用隔离生产SQLite、真实HTTP及打包页面手动读取988字,desktop/390px完整尾部可读、无横向overflow;来源临时不可用返回503,界面仅摘要并明确retry,恢复后同一按钮读回988字。原生File/SQLite测试覆盖保留任务、错误Goal/ID、跨origin拒绝及authority revision/rows不变。真实纠偏页显示当前validation与缺失verifier,打开原产物后按引用返回;实际改写修订产物清除旧正文,返回当前列表4→3,恢复原字节重查回到4。Ego本轮拥有空间38已完成清理。所有worker为合成host,无真实模型执行或付费调用。browser fixtures的身份不匹配/晚响应、downstream loss/restore、分页、focus和reduced-motion负例仍明确是合成边界。

保留设置失败:一次错误npm script名称改用实际入口;并行browser检查端口冲突后使用不同隔离端口,正式43场景及integrated入口最终通过;不存在产品失败被忽略或放宽断言。一次手动原产物读取观察过早,随后等待准确operation及正文核验实际原始raw_fcf90和修订返回。未查询/轮询/等待CI。没有跨账户、Bot、生产Goal或其它role测试。

我的整体评价

APPROVE这个有界协调/读取阶段,原988→500阻塞在当前head已独立验证解决。长程效果的正向证据是原始要求不再在阅读时丢失、失效证据不会继续支撑决定;效率的正向机制是关联阅读能原路返回、恢复沿原选择重试,列表只重读一次,不追加周期轮询。未测吞吐、token或持续完成率,不能把测试数量当收益量化。

未来重构检查:复用现有Todo和typed acceptance定义,局部UI状态不另建存储;保留persisted digest和独立旧runtime的unknown兼容有实际消费边界,当前无必要再抽象。完整L1仍需独立verifier版本回执与两轮真实纠偏采用。该PR改变控制面/运行时,交维护者合并,不据本次批准自动合并或升级本机。

English verdict: APPROVE - 5587@05ba74e42eb9b4171f6fcf42e9be3b548a3bb457; the full988-character Task source and503 recovery are verified through real SQLite/HTTP and packaged desktop/mobile. Stale output withdraws content and accepted counts, then restores on explicit recheck.68Python,4388TS with disposable realPostgreSQL,43packaged scenarios and team-return pass;1optional service-wrapper skip. NoCI observation. Independent verifier/live correction adoption, installed Native and sustained performance remain unqualified.

@mergify

mergify Bot commented Oct 5, 2026

Copy link
Copy Markdown

This pull request has merge conflicts with main and cannot be merged
until they are resolved. Please rebase or merge the base branch, @loopx-agent.

Choose the remote for the base repository, not an out-of-date fork.
For a fork clone, first inspect git remote -v; upstream must point
to https://github.com/loopx-project/loopx.git. If it is absent, add it
with git remote add upstream https://github.com/loopx-project/loopx.git.
Then run:

git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEAD

For a same-repository clone whose origin points to
https://github.com/loopx-project/loopx.git, use origin instead of
upstream for fetch/rebase. If you prefer merging the base, use
git merge <base-remote>/main and push normally.

Keep the DCO Signed-off-by trailer on every commit when you rebase.
https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/syncing-a-fork

@mergify mergify Bot added the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 5, 2026
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
@mergify mergify Bot removed the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 5, 2026

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

APPROVE — #5587b7763c1。整合前 head 05ba74e42eb9b4171f6fcf42e9be3b548a3bb457 的结论未直接继承;当前整份 PR 以 immutable main 896cdf1278ab2358260f4b5c59b211baa3a525ac 为基线重新审查。CI 按配置未查询、轮询或等待。

动机

用户在任务抽屉读取长要求,或在团队执行中追查修订与后续结果时,需要看到完整的当前证据并回到原工作。

旧列表把 988 字要求截成 500 字,抽屉也只能看到摘要,最后的验收条件丢失;查看关联证据后又需重新找原执行,旧成功计数还可能掩盖失效产物。新抽屉按需读取完整原文,来源失联显示摘要与重试;证据可逐级返回,并重新核对当前验收。

当前打包页面连接真实 SQLite/HTTP/CLI,已读回全部 988 字与末尾条件;真实来源不可用时退回 500 字摘要,恢复后重试成功,Escape/Enter 返回原任务,canonical Todo 与 revision 保持不变。

本 PR 交付只读证据旅程及独立 worktree 的协作代码编辑协调,不改变评分、provider、共享运行状态权限、Todo 实例归属或合并权限,也不宣称完整实时团队协作已验收。

独立验收者与准确版本回执、真实语义异议以及两轮真实纠偏和请求方采用,仍由既有 Live Team Workspace/acceptance owner 的 L1 验收推进;安装后的 Native、完整屏幕阅读器和 200% 缩放未在本轮重新资格化。

改动思路

复用既有 Todo、typed lease admission、Goal acceptance 与 delegation validation owner。Python 只承担当前源码读取和本机 HTTP transport,TS 决定租约与验收语义,既有 Task/证据面板消费同一事实。没有新 capability、provider、设置、任务仓库或轮询器。普通打开 Task 只增加一次必要的权威读取,点击、返回、重试都不要求重填已知要求或额外确认,也不启动模型。

worktree 模式明确选择协作代码编辑:经验证的调用者在独立 checkout 编辑,文件重叠成为集成提示;不把对方缺失的旧 workspace 身份伪造为已隔离。已知同 checkout、同 Todo、普通独占模式、TTL/CAS 和原执行 receipt 仍受保护。最强反对意见是把所有文件冲突降为提示会削弱共享状态保护;本实现只在显式 verified code-edit 请求中改变文件协调,保留普通模式和实例围栏,并在公开协议说明变化及退出方式。

具体改动

整份40文件 +907/-115:11个 dashboard 配置/组件/smoke 路径,9个公开 RFC/参考文档/合成截图,10个验证路径,9个运行时路径和1个 I/O 生成清单。任务卡仍提供有界预览,sourceTodoId 与显示用 id 分离;TaskRequest 每次打开读取原文,取消旧请求,拒绝错 Goal/Todo 回复。GoalTeamWork 保留证据引用栈,返回时读一次原执行页、保留 cursor 与焦点;GoalTeamEpisode 将核心修订和后续采用的有效性分别处理,不能把后续失联伪装为整体成功或抹去仍有效的核心证据。

本轮解决三处主干冲突:保留 origin 默认端口、非默认端口及不安全 URL 校验;把四类 origin/双 provider 测试与旧 grant 提示/同 checkout 拒绝同时保留;按整合后源码重新生成281个 I/O sites(0 unclassified)。原17个 signed commits 被保留,新增 signed integration commit,正常 FF push。GitHub 原 base 缓存一度把已合入 main 的历史算进 PR;重新指定同一个 main 后,本地与远端 base/merge-base/40文件差异一致。

规范依据为改动前 Accepted docs/architecture/rfcs/live-team-workspace-v0.md,spec_revision 896cdf1278ab2358260f4b5c59b211baa3a525ac:V1 Truth 的事实分离、失效撤回与显式缺口 implemented;V3 Experience 的 packaged desktop/390px、键盘、reduced motion 和返回路径 implemented,完整屏幕阅读器/200% 缩放 deferred;V6 Rollback 的源失联、默认路径与无额外执行 implemented。First live outcome: one understandable correction、V4 Research loop 的独立语义验收/准确版本 verifier receipt/两轮真实采用 deferred,仍在同一 RFC,不用合成场景关闭 L1。V2 Stream、V5 Scale、V7 Comprehension out_of_scope:本切片没有 stream、renderer 或规模/观察者实验。docs/reference/canonical-lease-renew.md 在 896cdf1278ab2358260f4b5c59b211baa3a525ac 定义的 ordinary exclusion、Todo owner、TTL/CAS 与历史 replay 保持;其双 sibling worktree 条件是本 PR 有意更改的协调语义,不能称为等价重构。

关键代码讲解

  • decideTaskLeaseAcquire:验证当前 caller workspace 后,以 sameLeaseCheckout 判定物理碰撞;已知同 checkout 优先于不同仓库 metadata,未知旧 workspace 只产生 advisory。真实 File/SQLite Git worktree CLI 与真实 PostgreSQL reopen/replay 均覆盖,旧 grant 不改写。
  • list_goal_todos:仅 exact、non-thin、唯一匹配恢复 source 原文;普通列表、thin、歧义和身份/role/archive 匹配继续由原 owner 决定,长正文不进入常规 status 预算。
  • TodoDetailRequestMixin._todo_detail:只允许 loopback、同源、注册 Goal 和一个准确 Todo;无效400、缺失404、歧义409、来源不可用503,返回正文及最小身份,不泄露路径、权限声明或完整 authority 包。真实 HTTP 403/400/404/503 及恢复均验证。
  • delegationValidationPlan:从当前 requirements/effects 派生 path-free 定义 digest、规则来源和检查/文件 pin 计数;host 原校验通过后 _accepted 才曝光 observation。completion_receipt_id 归为完成观察,旧绑定保留精确历史 digest 兼容;改变 text/capability/scope 仍 stale。
  • GoalTeamEpisode:每次显式核验重读 original/response/revision,并核对 operation/request/Todo/actor 与准确 artifact ref/hash;采用记录从该次 owner observation 获取,再核对 downstream。核心失效清空路径,采用失联单独标为 unavailable,独立 verifier 缺口始终可见。

对主干的风险

原评审5408762404 的全文 blocker 在当前 head 独立验证:同一988字 workload,真实 canonical 与末尾条件、常规500字摘要、exact CLI 与打包 HTTP drawer 相互核对;真实来源失联不复用旧全文,原地重试恢复。指针打开、Escape、关闭与 Enter 返回原 opener;390px、错身份、晚响应与 legacy display-only id 由 packaged 43场景验证。实际普通旅程从 Goal → Tasks → 原任务,返回原点;没有新的配置或确认步骤。整份证据阅读/失效/采用丢失/撤回/恢复/分页专项通过,数据为公开合成 fixture,不证明真实模型语义异议。

当前本地验证:71项 Python+20项长历史/分页/retained读取通过;全量 TS4042通过、31项可选 PostgreSQL/service 跳过;另外一次性真实 PostgreSQL16.2 的 store/worktree/acceptance/delegation430通过、0跳过,实例已删除。确切源码 Chat build、TS typecheck、43 packaged browser 场景、team-evidence-return、差异 semantic advisory→全树 semantic smoke、公开边界与18 commits DCO 均通过。关闭本轮真实服务后 canonical Todos 与 provider revision 和读取前一致。#5582 已在本基线合并,历史 Native 启动缺口不再作为本 PR 未解决 blocker;本轮没有改写系统安装或宣称安装后的 App 已更新。

保留两类基线问题:routine npm 入口在已有 locale 源码字符串断言停止,immutable main 与 head 同断言同失败,测试与 producer blob 完全相同;实际43 packaged 场景单独执行通过,没有修改断言、删场景或放宽限值。raw maintainability 的完整三项 finding/metric/exception 在固定 base/head 相同,仅 root不同:Lark any56/49、quota statements96/90、goal_boundary decisions63/60,没有加预算。第一次 canary 的质量 receipt 未就绪而失败也保留;填完确切 scope receipt 后重跑,5项直接检查、19项选中检查中18通过/1 inherited advisory,blocking failures0、manual holds0,strict quality与canary通过。未查 CI。

语义与 CI 对齐

复用既有 goal_acceptance/todo_validation vocabulary、lease facts 和 receipt owner;RequestRead 是局部 UI discriminated union,不是新 shared lifecycle。默认行为披露于 canonical-lease-renew、local-delegation、双语 Live Team RFC/L3 checkpoint及重命名 lease smoke:只有显式 verified --write-worktree 的文件范围变为集成提示;ordinary exclusive、owner、TTL、CAS、replay 和未知仓库保守规则保持。typed base/head probe 的完整普通/同 checkout/不同仓库/owner/scope结果一致;有意变化为未知旧 workspace 的 advisory、同物理 checkout 仓库 metadata 不能逃逸,以及完成观察不再使 work binding stale。

advisory 只是协调信息;实例归属、同 checkout 拒绝、输入身份、权限与当前验收是机器强制条件,不称为 guidance。空 semantic advisory 不覆盖动态或局部 union,已人工追到当前 typed owner;不使用 substring denylist 或 prose-only classifier,也不把 domain-specific wording加入通用 quota/work-lane 义务。旧 grant、旧 digest 和旧 runtime 不提供 validation observation 的兼容有真实 persisted/independent consumer 依据,不能为减行数删除。

我的整体评价

APPROVE,justified_increment。long_horizon=improved:当前源丢失会撤回旧成功,恢复后能回到原执行与有用工作,旧实例/receipt不被改写;user_experience=improved:完整要求、可理解的来源失败与原地重试、逐级证据返回和键盘焦点都在既有界面直接完成。剩余独立验收/真实持续协作仍如开头所述,不以计数或合并关闭父验收。

future-facing pass 已在同一 owning boundary 应用:统一物理碰撞 predicate,当前规则观察从既有 plan 派生,navigation只存引用,全文读取留在现有 source owner;没有必要新增协议版本、泛型 sink、Task store 或更大重构。40路径的生产/文档/验证是一个可回滚的协调和阅读切片;新增代码主要为小型 transport/reader 与真实边界验证。首屏、hero、导航与主 CTA 未改变,四张文档图是合成证据阅读状态。用户明确授权本 PR 自修复自合并;需先读回此评审、完成 closeout,再以 unchanged head readiness=true执行合并。

English verdict: APPROVE - 5587@b7763c1321da5b93f940bee633b884bc75db0ca1; current-main conflicts and stale PR base metadata repaired. Real File/SQLite CLI/HTTP and packaged 988-character read/error/retry/focus, lease authority/replay and disposable PostgreSQL430 cases independently verified. Current evidence navigation/adoption gaps stay truthful; inherited source-layout and maintainability failures, optional service skips and live-team/native/accessibility limits remain explicit. CI was not consulted.

@loopx-agent

Copy link
Copy Markdown
Collaborator Author

Post-review base freshness: main advanced to 61e37f089a63aaf6e2bcdf77444e0be410b79a6b while qualification completed. The complete intervening diff changes only the existing explore finding-title projection and its focused tests. It touches none of this PR’s Todo reader, lease admission, acceptance, delegation, evidence UI or required source-layout assertion, and does not alter their input/authority contracts. The reviewed head remains b7763c1321da5b93f940bee633b884bc75db0ca1; its merge base and review/quality evidence retain immutable 896cdf1278ab2358260f4b5c59b211baa3a525ac. CI remains unconsulted.

中文:评审期间 main 新增 explore 标题投影的局部修复;已检查完整差异,不触及本 PR 的任务正文、租约、验收、委派或证据页面及其输入/权限合同。评审 head 未改变,基线证据仍固定于已记录的不可变提交。

@huangruiteng
huangruiteng merged commit b9df6d1 into main Oct 5, 2026
10 of 28 checks passed
@huangruiteng
huangruiteng deleted the codex/l1-evidence-return-20261004 branch October 5, 2026 08:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants