From cf19c0b5e4b37eafb24c1ff8f0dee802d2d60ed3 Mon Sep 17 00:00:00 2001 From: hyk <4408344+hhyykk@users.noreply.github.com> Date: Mon, 5 Oct 2026 11:51:33 +0800 Subject: [PATCH 1/2] fix(work-items): fence reviewed sources through team-plan commit Signed-off-by: hyk <4408344+hhyykk@users.noreply.github.com> --- .../work_items/team_plan_adapter.py | 82 ++++++-- .../work_items/team_plan_authority.ts | 71 ++++++- .../project_registry_io_manifest_v1.json | 14 +- .../control_plane/test_team_plan_authority.py | 191 +++++++++++++++++- tests/control_plane_ts/team_plan.test.ts | 13 ++ .../team_plan_commit_probe.ts | 22 ++ tests/test_steward_team_plan_apply.py | 24 +++ 7 files changed, 381 insertions(+), 36 deletions(-) create mode 100644 tests/control_plane_ts/team_plan_commit_probe.ts diff --git a/loopx/control_plane/work_items/team_plan_adapter.py b/loopx/control_plane/work_items/team_plan_adapter.py index 0b13b3fba1..d580b165d2 100644 --- a/loopx/control_plane/work_items/team_plan_adapter.py +++ b/loopx/control_plane/work_items/team_plan_adapter.py @@ -11,18 +11,25 @@ import json import re from collections.abc import Callable, Mapping +from contextlib import ExitStack from pathlib import Path from typing import Any from ...agent_registry import registered_agent_ids_for_goal from ...history import load_registry +from ...file_lock import ( + LockAcquireTimeoutError, cross_runtime_lock_witness, exclusive_cross_runtime_file_lock, +) from ...registry import find_registry_goal from ...state_refresh import now_local from ..effect_runtime import EffectRuntimeRejected, effect_runtime_result from ..runtime.public_safety import validate_public_safe_value from ..coordination.local_authority import read_canonical_todos_if_promoted from ..coordination.local_authority_shadow_adapter import effective_runtime_root -from ..coordination.legacy_writer_fence import legacy_todo_write_transaction +from ..coordination.legacy_writer_fence import ( + legacy_coordination_todo_lock_path, legacy_todo_write_transaction, +) +from ..coordination.shadow_management import shadow_maintenance_lock_target from ..coordination.runtime_shadow_writer_adapter import ( begin_todo_runtime_shadow_capture, write_captured_todo_state, settle_todo_runtime_shadow_capture, @@ -136,20 +143,34 @@ def apply_team_plan( validate_public_safe_value(dict(proposal), path="team_plan") registry_path = Path(registry_path).expanduser() runtime = effective_runtime_root(registry_path, None) - goal = find_registry_goal(load_registry(registry_path), goal_id) - if goal is None: + if find_registry_goal(load_registry(registry_path), goal_id) is None: raise ValueError("steward team plan proposal names an unknown Goal") project, state = resolve_todo_state_path(registry_path=registry_path, goal_id=goal_id) request = { "goal_id": goal_id, "plan": dict(proposal), "actor_agent_id": agent_id, - "registered_agents": registered_agent_ids_for_goal(goal), "supported_action_kinds": sorted(TODO_ACTION_KIND_ADVANCEMENT_VALUES), "observed_at": now_local(), "expected_state_fingerprint": expected_state_fingerprint, - "intent_basis": steward_team_plan_intent_basis( - goal_id=goal_id, goal=goal, registry_path=registry_path, plan=proposal), } + + def read_source_request() -> None: + # Called under the registry and state locks, including on the legacy + # path. A registry rebind while acquiring the guards must not redirect + # the operation to an unguarded source or provider. + goal = find_registry_goal(load_registry(registry_path), goal_id) + if goal is None: + raise ValueError("steward team plan proposal names an unknown Goal") + _, current_state = resolve_todo_state_path(registry_path=registry_path, goal_id=goal_id) + if (effective_runtime_root(registry_path, None).resolve() != runtime.resolve() + or current_state.resolve() != state.resolve()): + raise TeamPlanCommitError("team_plan_preview_stale", "team plan source binding changed after preview") + request.update( + registered_agents=registered_agent_ids_for_goal(goal), + intent_basis=steward_team_plan_intent_basis( + goal_id=goal_id, goal=goal, registry_path=registry_path, plan=proposal), + ) + identity = effect_runtime_result("work_items.team_plan.identity", request) marker = f"