Repository navigation
feat(zcode): add host diagnostics and managed native Goal control - #5752
jackie-cqz wants to merge 69 commits into
Conversation
Separate CLI, Desktop, bundled agent and source metadata. Use isolated bounded help/version probes and report observed interfaces without claiming native execution readiness. Read the installer-owned ZCode facade set from its own skills root. Reuse one renderer, preserve custom CLI invocations and installation repair precedence, and leave other host diagnostics unchanged. Signed-off-by: jackie-cqz <2557911191@qq.com>
Cover host identity, independent versions, relative paths, probe deadlines and output limits, facade conflicts and freshness, and Windows source-entry fixtures. Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
…ostics Signed-off-by: jackie-cqz <2557911191@qq.com>
Bind an explicitly selected CLI session to existing Goal and registered Agent authority. Add model selection, native lifecycle operations, durable recovery, quota admission and revocation, and owned process cleanup through the CLI and Goal drawer. Keep the Skill facade as default. Native completion and unknown usage do not settle Core Goals or debit credits; Desktop attachment remains a separate stage. Signed-off-by: jackie-cqz <2557911191@qq.com>
Cover stale identity fences, quota denial and revocation, protocol and permission failures, lost receipts, durable empty-session binding and process ownership. Exercise the packaged Goal controls and contract-aware frontend freshness. Signed-off-by: jackie-cqz <2557911191@qq.com>
Document CLI and frontend activation, model selection, quota coordination, stop and recovery, legacy identity limits, and the bounded roadmap checkpoint. Signed-off-by: jackie-cqz <2557911191@qq.com>
…ostics Signed-off-by: jackie-cqz <2557911191@qq.com> # Conflicts: # loopx/chat_server.py
Keep legacy Skill activation available without advertising native operations for unregistered actors. Prove ordinary Chat project context cannot be injected into Goal control requests. Refresh registry I/O source locations after synchronizing main. Signed-off-by: jackie-cqz <2557911191@qq.com>
Add public synthetic desktop and mobile illustrations to the managed provider guide and include them in the package. The figures illustrate UI states and do not claim live execution or billing evidence. Signed-off-by: jackie-cqz <2557911191@qq.com>
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh
Reviewed exact head: dc32655a7c81026157dc565b4c7ce38b07f6e82f; immutable base 42e55a809eb94f13443d303d76118735d4112182. 完整范围:45 个文件、+4405/-61,包含 provider、诊断/安装、CLI/HTTP、打包与界面、验证和文档。
动机
在已有 LoopX Goal 下使用 ZCode 的人,需要能明确绑定一个受托管的 CLI 会话,再启动、暂停、恢复、停止并核对它的状态。之前只有 skill 入口,用户无法从 Goal 详情控制这个独立会话;发生暂停或连接丢失后,也缺少一致的读回路径。本 PR 提议保留 skill 默认入口,增加显式绑定和同一目标的控制,让界面读回与 CLI 使用同一 provider。已验证的改善是打包界面可以完成模型选择与控制/异常恢复,协议层拒绝旧身份和越界响应;发现的缺陷是安装版本不匹配同时缺失 skill 时,恢复指引只修 skill,丢失真正的版本修复。原生模型调用费用、逐次调用硬预算、Desktop 附着和多 Agent 长程效益均未因此成立。真实已安装 ZCode 的恢复与长程净效率仍待独立核验,混合安装故障的恢复分支需要修复。
改动思路
spec_ref: docs/architecture/rfcs/loopx-overall-roadmap-v0.md; spec_revision: 42e55a809eb94f13443d303d76118735d4112182,按修改前的 S4、S5、S7、S8、S12 要求评估,有效 provider 是有界增量,不能用 PR 新写的 checkpoint 给自己认证。
S4:现有 Goal/注册 Agent、实例/创建凭据校验;独立 native session/target、串行操作、失去 broker 时终止自有进程树,unit/子进程负例通过,但本审查尚未独立复现作者所述真实已安装 ZCode 的恢复证据。S5:CLI 与 Goal 详情抽屉共用读回;打包浏览器覆盖绑定、模型/推理级别、quota 拒绝、旧 Goal 凭据、错误回执恢复和 Agent 切换,所替代的是 HTTP/provider fixture,不能证明真实提供方行为。S7:启动/恢复复用 Core quota;撤销后暂停、不把 native completion 当 LoopX 验收/扣费,未知 token 保持未知;逐调用预算/fleet 成本仍是剩余边界。S8:明确 opt-in、版本/权限、停止/卸载/恢复,provider 不增加一个平行 Core 决策 owner;真实入口/隔离证据仍须与声明对齐。S12:构建、打包来源与正常 skill 行为已核对,恢复顺序的混合失败反例未满足。
具体改动
Python zcode_goal_operation 校验权威身份,生成当前 heartbeat 任务并经同一解释器桥接 TypeScript;NativeGoalController 管理不可推导的绑定意图、目标、丢失开始回执和恢复,不重新定义 Core quota。ZCodeAppServer 对接 NDJSON 协议,验证 session/target/revision,拒绝交互权限,暂停后确认停止;guardian 把失去 broker 的取消传到自有进程树。ZCodeGoalControl 的操作集合由 provider 读回,修改 CLI 路径不隐藏暂停/停止,旧身份或未知操作结果要求先读回再操作。doctor 分开观察 CLI、Desktop、源码版本,仅 version/help;skill 检查复用 installer 的渲染,保护用户文件;构建指纹包含共享 provider 契约。
正向路径:打开 Goal 详情→已有注册 Agent→绑定 CLI(不启动模型)→必要时选已有模型/推理级别→显式启动→暂停/恢复同一目标→停止并读回断开。每个必需步骤提供身份、定位、模型选择或效果授权;无需另建 Goal/Agent。负向路径:同名 Goal 的创建凭据改变,旧面板 POST 被拒绝,零模型启动,刷新后才能继续;quota 撤销保持目标并暂停,不能仅凭 paused 绕过当前准入。
对主干的风险
阻断发现 [P2]:混合安装失败时丢失版本修复指引。 loopx/doctor.py:885–891 仅凭 repair_recommended 与坏 skill 覆盖 upgrade_command,1252–1257 又以 facade_problem 覆盖 fix。触发:release manifest 版本与运行包不一致(manifest_package_version_matches_runtime=false),同时 ZCode facades 缺失/过期。用相同合成事实在基线与 head 调用生产 collect_doctor(agent_type="zcode"):基线保留 install/upgrade 指引;head 仍报告 requires_upgrade=true,却只返回 slash-commands --install --surface zcode。该命令只修文本,不能修复包/manifest 不匹配,用户会多跑一轮甚至重复停在同一错误。最小修复:只有已确认“仅 skill 不新鲜”时使用 skill-only 修复;包/版本/运行时故障保留其 owner 的安装恢复,再追加 skill 修复。不要依赖总 status 或某个先出现的 reason 判断唯一原因。回归:在现有 test_zcode_doctor_skill_delivery.py 增加“版本不匹配 × 缺失/过期 facade”的组合,验证完整恢复和修复后读回。该反例无需模型/网络调用;基础设施用合成替身,生产诊断/恢复决策未替换。
另外,新增 test_probe_uses_disposable_storage_and_preserves_parent_environment 在 macOS 的 /var→/private/var 别名下失败。真实目录隔离并未因此失效;应规范化两侧路径/比较目录身份并保留原有隔离、环境不被修改、临时目录清理断言,勿直接删测试或放宽为任意目录。
本地验证:39 项 TS 协议/控制/guardian 测试通过;Python 新功能与 bundle 检查为 126 passed / 1 failed(上述路径断言);182 项既有 doctor/activation/installer 测试通过;TS 类型检查、chat 构建/校验、打包 zcode-goal 浏览器场景、全树语义 smoke 通过;独立混合恢复反例失败并在同一 base/head 比较定位到新覆盖分支。7 份默认 ZCode skill 内容在 base/head 字节相同,Codex activation 完全相同;ZCode activation 仅新增可用 provider 信息和明确默认仍是 skill 的说明,没有因此启动执行。新增词表属于 provider 状态/本地诊断,Core 资格/结算 owner 未替换。无 CI 拉取或等待。未独立完成真实已安装 ZCode 的完整恢复、live billing 或多 Goal 并发测量;作者声明不代替这些证据。
我的整体评价
REQUEST_CHANGES。交互和隔离方向有正向价值,但“可控且可恢复”需要同时覆盖普通路径和安装组合故障,当前遗漏会给后续升级/重试增加成本。长程净效率还不能判为已改善:每个活跃托管会话约每 2 秒启动权威/quota 子进程,一小时截止,缺少规模成本和真实有效产出测量。保留这个明确有界的 provider,先修具体恢复分支和 macOS 验证;无需顺便承诺 per-call 预算、Desktop 或 fleet。最近相关复用已检查:Core quota/身份保持原 owner,provider transport/state 需要自己的宿主边界;更小的纯 skill 文档改动无法交付这些控制。未来整理宜继续聚焦同一恢复 owner,避免另增一套“诊断成功”判断或新配置协议。修复后重新在变更 head 核验,不从此次 passing 项推导上层验收或合并授权。
English verdict: REQUEST_CHANGES — exact head dc32655; mixed package-version/skill failures replace required installation recovery with skill-only guidance. Protocol, packaged UI and legacy checks passed; one new macOS path assertion failed and real installed-host recovery/net-efficiency remain unverified.
|
This pull request has merge conflicts with Choose the remote for the base repository, not an out-of-date fork. git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEADFor a same-repository clone whose Keep the DCO |
…ostics Signed-off-by: jackie-cqz <2557911191@qq.com> # Conflicts: # apps/presentation/dashboard/src/data/chat.ts # loopx/semantics/project_registry_io_manifest_v1.json
Reuse the installation freshness owner without Skill admission to retain required package/runtime repair before ZCode facade repair. Cover mixed missing/stale Skill faults through real installer repair and complete readback, canonicalize macOS temporary paths, and qualify the added bridge tests with CI lint. Signed-off-by: jackie-cqz <2557911191@qq.com>
Replace the two provider matcher copies with the existing content digest owner and register the actual consumers. Use fileURLToPath in the unchanged static ownership check so Windows runs all original assertions, with no exceptions or relaxed matching. Signed-off-by: jackie-cqz <2557911191@qq.com>
Bind the HTTP acceptance fixture to its disposable runtime root and count persisted Turns by the existing schema owner instead of incidental JSON filenames. Retain exactly-one acceptance and dispatch assertions, and remove the unused import left by the upstream Todo module split. Signed-off-by: jackie-cqz <2557911191@qq.com>
|
修复已推送到
本轮验证:Python focused 55 + 75 + 82 项通过;ZCode TS 39、digest owner 17 项通过;完整类型检查、lint、Linux 目标 kernel mypy、semantic smoke、打包来源检查通过。浏览器 49 个场景中 48 通过(含 ZCode);1 个主干原样的 Windows 子进程 cleanup 断言失败。新 wheel 中 1,643 个 LoopX 文件与源码一致;真实已安装 CLI bind → stop → immediate status → cold bind 恢复同一 session,0 次模型调用。 PR 描述已将新 head 验证、旧 head quota/本地模型证据、平台失败和未测范围分开。仍然只交付有界 managed CLI provider;不新增 per-call hard budget、Desktop attachment、live billing 或 fleet/net-efficiency 完成声明。本轮 GitHub CI 已排队/运行,尚未确认全绿,请在此精确 head 重新 review;这不是合并批准。 Known review findings addressed; pending exact-head re-review and GitHub CI. |
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh
Reviewed exact head: 9588ccc345c4444427fe6acb1341d923771d81db; immutable base da45cfe771e96d20b9c5129a021a8c971ee03324. Whole PR: 48 files, +4512/-71. This is a fresh full-scope re-review, not a reuse of the old approval state.
动机
在已有 LoopX Goal 下使用 ZCode 的人,需要明确绑定一个受托管的 CLI 会话,再启动、暂停、恢复、停止并核对状态。 之前只有 skill 入口,用户无法从 Goal 详情控制这个独立会话;连接丢失后,也缺少保留同一会话的读回与恢复路径。 现在增加显式控制:打包界面通过模型选择与异常恢复检查,真实 CLI 和生产 HTTP 入口都在停止后恢复同一个空闲会话,旧 Goal 凭据与外部网页请求被拒绝。 这次验证没有运行付费模型;逐调用硬预算、Desktop 附着、live billing 和多 Agent 长程净收益仍未成立。 活跃模型的真实取消/恢复、规模化监测成本与持续有效产出仍待限定场景实测;当前交付是可停止、可冷恢复的单会话可选 provider。
改动思路
spec_ref: docs/architecture/rfcs/loopx-overall-roadmap-v0.md; spec_revision: da45cfe771e96d20b9c5129a021a8c971ee03324。用修改前 S4/S5/S7/S8/S12 的宿主监督、共享投影、准入/消耗区分、provider 生命周期与安装恢复来判断有界增量,不用 PR 自己新增的 checkpoint 认证自己。
Core 身份与 quota 保留唯一 owner,TypeScript 管理宿主状态/效果,Python 只桥接现有权威;同一会话的真实冷恢复证明了这层 provider 边界有用,纯 skill 文档无法交付这些控制。 当前 PR 保留一个明确 opt-in、可停止的单会话 provider 和既有 Goal 抽屉入口;不新增通用能力、默认执行或账户配置,活跃模型与 fleet 成本继续由现有 S4/S7/S8 验收持有。
最强反对理由是约 4.5k 行引入 broker、journal、guardian 与轮询成本,若只是给 skill 加说明会过大。但纯文档无法控制 native session,取消、恢复和旧身份拒绝必须跨真实 provider。这里复用 Core,新增状态只保存不能从注册关系推导的 session/target/已授权启动意图;没有额外通用配置框架。S4 中真实运行模型的取消/恢复,以及 S7/S8 的 live 成本和规模验收仍未完成,不能从空闲会话恢复推导它们。
具体改动
CLI/生产 HTTP 都经 Python bridge 读取现有 Goal、已注册 Agent、实例或创建凭据,然后进入同一 TypeScript controller。controller 串行管理模型选择、明确启动、暂停、停止和 durable intent;app-server 校验 session/target/revision,拒绝交互权限;guardian 在 broker 丢失时关掉自有进程树。Goal 抽屉共用契约和可用动作,未知结果先清空旧 snapshot,重新读回后再操作;不同 Agent 的迟到读回不污染当前选择。doctor 分开观察 CLI/Desktop/源码版本,用 installer 渲染判断 skill,不把版本/help 成功当完整运行资格。
相关 refactor 已在现有 owner 内完成:复用 canonical digest 正则,使用 fileURLToPath 保留跨平台路径身份,移除一个未使用导入;HTTP acceptance fixture 用 typed Turn schema 计数并指向自己的临时 runtime,未改变产品 Turn 规则。没有必要增加另一套状态分类或 freshness owner。
正向体验:打开已有 Goal→选已注册 Agent→绑定实际 CLI(不运行模型)→需要时选择已有模型/推理级别→明确启动→读回/暂停/恢复/停止。Agent 提供作用对象、CLI 路径提供宿主选择、启动提供效果授权,刷新为旧或未知结果提供当前权威;这些步骤没有重复创建 Goal/Agent。现有默认模型保留,模型修改是可选操作。
负向及恢复:生产 HTTP 的外部 Origin 返回 403,旧 Goal 实例凭据返回 409,均在 native launch 前;新鲜读回可继续绑定。实际 CLI 和 HTTP 分别完成 bind→stop→status→cold bind→stop,冷绑定恢复各自同一 session、无 target、保持 idle,模型目录为空时启动不可用,自有 owner 锁释放,registry 字节未改变。
对主干的风险
原审查 5426602303 的两项问题已逐项核验:组合故障恢复现在先保留包/manifest 版本修复,再追加 ZCode facade 修复。相同合成事实调用基线/head 的生产 doctor,当前 head 不再把 requires_upgrade=true 的包故障替换成 skill-only 指令;四个 missing/stale × version-mismatch 用例验证“只修 facade 仍不就绪、完整修复后就绪”。macOS 临时路径改为目录身份规范化,保留隔离、父环境未修改和临时目录清理断言,当前全部通过。原来的阻断不再适用于这个 head。
当前 exact-head 本地检查:131 个 touched Python 检查、182 个既有安装/doctor/activation 检查、56 个 TS 检查(含实际 owned-process 清理与共享 digest owner)通过;类型、构建/安装/来源校验、全树 semantic smoke、diff 检查通过。打包 desktop/mobile 场景通过:折叠时零探测、模型/推理级别、quota 拒绝、旧创建凭据、未知操作恢复、Agent 切换及 viewport 布局。它使用 stateful HTTP/provider fixture;另有生产 ChatHTTPServer+Core+真实官方 CLI 的独立 8 请求资格,不能混称为真实模型端到端。既有真实 HTTP acceptance retry 两个故障场景也通过。
真实宿主取自官方 ZCode macOS release,CLI 自报 0.16.9。全新隔离环境中直接调用 Desktop JS bundle 最初因其找不到 bundled provider config 而退出;同一 CLI 直接协议探测复现了这个 upstream 启动问题。显式提供该发布包已有的 provider config 后,CLI 与生产 HTTP 的空闲冷恢复通过。没有安装或修改用户账户、没有模型请求;这个边界应与通常已配置 CLI 的可运行环境区分。doctor 的 version/help 观察也不代表 app-server 一定可运行。
默认关闭核验:同一基线/head 的 7 份 managed facade 字节一致,Codex activation 一致;ZCode 只增加明确可选 provider 的信息与默认仍为 skill 的说明,collapsed panel 没有请求。没有默认启动、Automations、quota 结算或 native completion 转 Goal 验收。CI 按 capability 未拉取/等待;live billing、逐调用硬预算、Desktop 附着与多 Goal 长程净效率没有实测。
我的整体评价
APPROVE,限定为本次可选单会话 provider。恢复阻断已修复,真实宿主的会话留存/冷恢复和当前权限边界已独立验证;用户从“靠外部会话手动猜状态”进入“同一 Goal 内明确控制与读回”,升级组合错误也避免无效重试,局部体验和恢复效果是正向的。
效率采用明确有界取舍:每个活跃会话约两秒一次串行权威/quota 子进程、十秒检查超时、一小时执行安全截止、五分钟空闲退出;该成本仅在显式启用 provider 后产生,失败暂停、恢复不自动续跑。因此当前证据支持可控恢复的正向增量,不能支持 fleet 长程净效率已经提高。未来测量应沿现有 S4/S7/S8 做真实活跃模型与成本/有效产出资格,不增加推测性框架。已考虑同域 refactor 并复用 digest/诊断 owner;暂不扩大为 per-call budget 或 Desktop 控制。合并与通用无人值守验收是独立责任。
English verdict: APPROVE — exact head 9588ccc. The prior mixed-install recovery and macOS path blockers are resolved. Current protocol/process, packaged UI, legacy installation and real official idle CLI/production HTTP cold-session recovery pass. This approves the bounded opt-in provider, not active-model/fleet efficiency, live billing, Desktop attachment or autonomous merge authority.
…ostics Signed-off-by: jackie-cqz <2557911191@qq.com>
…ostics Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
|
Conflict resolution published on Main independently landed the same workspace-digest fixture fix. The conflict was formatting-only; main's multiline form preserves the required synthetic digest and production recovery validation. Exact-head validation: 94 native Windows runtime/permission tests, 140 typed settlement/review-plan tests, frontend build and complete packaged typed-actions Chromium journey passed. Typecheck, semantic advisory/full smoke and diff checks passed. Existing shared owners are reused; no new authority or abstraction was authored. Remote comparison confirms |
Signed-off-by: jackie-cqz <2557911191@qq.com>
Signed-off-by: jackie-cqz <2557911191@qq.com>
|
Latest base sync published on Final head: 118 Lark progress/conversation/manager-return tests passed, zero skips; semantic advisory/full smoke and diff checks passed. The preceding merge passed 118 review experience/Lark/configuration tests, with 137 optional benchmark cases skipped because sforge/harbor are unavailable. Those skips are not passes; no benchmark/model job was launched. Remote comparison confirms |
Signed-off-by: jackie-cqz <2557911191@qq.com>
|
CI repair published on The site build failed The smoke now checks resolved clickable anchor destinations. Windows and Linux Node 24.21 both pass for all six bilingual article pairs. Embedded negative cases still reject wrong articles, external hosts, malformed URLs, metadata-only links and data-href-only anchors. Diff/advisory checks pass. No page/UI or runtime behavior changed, and no new shared contract is introduced. New CI must qualify the pushed head; no all-green claim is made. The PR remains for maintainer review/merge. |
Signed-off-by: jackie-cqz <2557911191@qq.com>
|
Latest main sync published on All five source-session registry-denial tests, Node 24.21 bilingual Blog smoke (six paired articles), semantic advisory/full smoke and diff checks passed. The existing blog CI fix is retained. No runtime/permission change or new abstraction was authored; the upstream qualification notes preserve their stated SQLite evidence gap. Remote comparison confirms |
Signed-off-by: jackie-cqz <2557911191@qq.com>
|
Latest main sync published on All 133 affected Python tests and 15 typed work-requirement tests passed, zero skips. This covers durable Explore links/writeback/readback and relative filename versus private path boundaries. Typecheck, semantic advisory/full smoke and diff checks passed. Existing owners are retained; no new abstraction or ZCode authority was authored. Remote comparison confirms |
|
This pull request has merge conflicts with Choose the remote for the base repository, not an out-of-date fork. git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEADFor a same-repository clone whose Keep the DCO |
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent | gpt-6.1-sol | OpenAI | runtime_reported | reasoning_effort=xhigh
English verdict: REQUEST_CHANGES — exact head fb87c2123b6a773e879324f21b496d0571257c69. All three independently repeated Darwin shutdown cases leave executable owned processes alive despite successful close/exit. Current156provider Python,79architecture/effect tests,39native TS and typecheck pass. Source invalidation covers85unchanged PR blobs and6fresh paths; old broad passes retain original revisions. Full current packaged/off-state/Windows/PostgreSQL/paidmodel and long-run net-efficiency remain unqualified. No CI queried or waited; no merge/install.
动机
在已有 LoopX Goal 中显式启动 ZCode native 会话的用户和 Agent。
原先用户只能从 Skill 入口使用 ZCode;本 PR 增加已有 Goal 的显式启动、暂停、恢复、停止与读回。
当前fb87的三个真实Darwin停止反例仍留下可执行子进程:close成功后native与child仍存活、native和guardian退出后child仍存活、leader已回收后helper成功返回但child仍存活。
本切片不验收 Desktop 对话绑定、真实模型费用、全平台安装或整个父路线图。
受管执行树的停止后置条件仍未满足;当前whole packaged/off-state、Windows整树停止、PG、真实模型及跨Goal领域Agent长期净收益未验收。
显式模型、额度暂停、同一会话恢复有实际价值,但用户看见停止成功后仍后台执行,会增加下一次恢复的重叠风险及无效资源占用。未测发生频率、模型费用或净效率,不把可用按钮与绿色测试当作长期收益。
改动思路
既有Goal抽屉/CLI→注册Agent与实例见证→Core当前额度准入→native模型/目标意图→durable journal读回;quota撤销先pause,恢复准入后仍显式resume。Core拥有Goal/Todo/结算,provider TS拥有native协议与意图,Python适配已有权威;诊断与Skill可用性仅观察,不授予执行。
关闭实际形成两个独立进程组。外层硬杀guardian、等待leader退出,无法证明其detached native组退出。应在既有TS guardian/app-server边界协作撤销与有界全组确认,不另建通用生命周期或平行Core owner。这是方向合理的增量,其自己的停止后置条件仍必须满足。
应在既有 TS guardian/app-server 边界协作撤销与有界全组确认,不另建通用生命周期或平行 Core owner。
这是方向合理的 native-provider 增量;它自己的停止后置条件仍必须满足,完整跨入口安装与模型旅程另验。
具体改动
完整91文件+5633/-328逐域重评;对15d527前次完整评审,85个PR路径blob相同,6个变化逐项重读,当前重新运行156项相关Python、79项架构与effect集成、39项native typed及三条真实停止反例。旧762+13Python/39+15typed与旧digest16通过1失败保留原b6ea/7ec来源,不称当前整套重跑。
完整91文件包含provider contract/runtime/CLI/bridge/API/diagnosis、shared host facade/installer/status、已有Goal抽屉十个展示面、bundle/packaging、CI六Python/三browser分片及coverage/receipt汇合、demo、文档与IO census。85相同不等于继承旧批准;六项fresh分别为总纲main同步、blog实际链接判定、typed-actions格式、package experience数据、registry denial的新增reader和effect transient PermissionError恢复测试。新baseline依赖另以79项真实source架构/effect检查核验,未推定whole packaged旅程。
采用 变更前总纲,spec_ref docs/architecture/rfcs/loopx-overall-roadmap-v0.md、spec_revision 271a3d98c601d86363159711b5672cdd6be2171d;PR自加checkpoint不自证接受。S4 not_met:停止须隔离旧执行;S8 not_met:关闭须确认拥有的执行退出;S7 implemented:admission/consumption/unknown区分,native完成不授Core credit;S5 deferred、S12 deferred:完整跨入口/安装/多平台/模型旅程仍独立验收。
关键代码讲解
terminateOwnedProcess(app-server.ts:256)在leader已exit/reap时直接返回;正常路径硬杀外层group后只确认leader,不确认另一个nativegroup。guard(guard.ts:8、28–29)detached启动native;nativeleader退出后guardian直接退出,留下同组child。validate_zcode_binding复用注册宿主、实例与creation witness;CLI/API拒foreign与过期目标,不能用provider会话代替Core权限。NativeGoalController保留显式native模型/目标意图,冷恢复到同一会话paused,不自动执行;ZCodeGoalControl复用Goal抽屉,丢弃过期响应,但停止读回必须建立于真实backend后置条件。
对主干的风险
[P1] app-server.ts:257–276 / guard.ts:8、28–29:清理成功仍保留受管执行。 当前fb87真实Darwin上,①actual initialize→close成功但nativeleader与child均非zombie存活;②nativeleader及guardian退出0但child存活;③leader回收后helper成功返回,child仍存活。系统PID/PGID/state为独立观察,探针exit0表示结果采集完成,产品后置条件三条均失败。
最小修复:guardian协作撤销它拥有的native组,再有界硬停止兜底;leader退出后保留合法组身份,确认全部受管执行停止,否则明确process_cleanup_unconfirmed。只检查leader或回执成功不覆盖三个反例。夹具仅NDJSON、0模型调用、0活动Goal故障写入;finalizer只清本探针owned组,最后所有PID不存在。
[P2] demo/workspace/README.md:28仍称各checkpoint获取hard lease,与同文后段及现行soft_claim replay相矛盾。 source blob与前次相同,删旧句即可,不改变权限;原本真实replay测试已断言lease None,当前未把它称作新运行。
当前156相关Python、79架构/effect、39nativeTS、typecheck及blog实际caller6paired通过。开发advisory先于full semantic,六候选分别复用bundle/installer owner或保持provider本地身份/状态/diagnosis词表;不是新增泛化Core权威。当前source premerge:5direct/19selected;gate=failed;failures=1,5direct及18selected通过,install-local-smoke.py:458唯一失败。该项在不可变b2f基线复跑也是相同 never infer verified from metadata or CI 固定文案断言;测试与Skill源blob未改,现行Skill仍要求missing evidence不升级为verified,措辞/标点不同。将此归为pre_existing_unrelated且保留raw失败的合并门,未删除断言或宣称安装整体通过,不把它混成三个PR自身停止缺陷。
旧762+13Python/39+15typed/premerge5+19保留b6ea来源,85blob一致及6fresh审查支持复用其未失效规则,不能称全部current重新跑。旧digest16pass/1fail仍保留immutable7ec/b6ea配对,未改变断言消除失败,也未伪造当前base/head同测。全current packaged viewport/off-state、Windows whole-tree、真实PG/paidmodel和跨领域长期净收益未测;作者声明不充当本角色实测。
语义与 CI 对齐
Core准入与机器义务域中立,诊断只观察;provider-native status/identity不扩大为Core生命周期或结算。默认不隐式执行,但当前whole packaged off-state未重验。语义扫描与正向源测试不能抵消owned-stop实际失败,PR新增checkpoint不能改写pre-change S4/S8的停止承诺。
我的整体评价
REQUEST_CHANGES;交付方向 justified_increment保留,long_horizon及user_experience均有具体 regression。后续恢复可能与“已停止”的旧执行重叠,这是可观察的管理失效,未宣称实际重复业务效果或已发生模型损失。更多main同步和绿色检查没有修复此不变量。
bounded future-facing pass应在现有typed guardian/owned-group边界完成协作清理及整树确认,保留Core准入和必要native意图;不扩展framework。其他产品/模型资格保留在原owner验收,不创建仪式化任务,不把未测性能当批准理由。
Signed-off-by: jackie-cqz <2557911191@qq.com>
|
Conflict resolution published on The exact-Todo mock conflict adopts main's equivalent singular/plural shape. Registry manifest conflicts were regenerated from merged code, then checked: 291 current sites, zero unclassified direct sites. All 80 affected Python and 34 typed tests passed. Frontend build and complete packaged typed-actions Chromium journey, typecheck, semantic advisory/full smoke and diff checks passed. Initial wrong-path validation ran no tests; the corrected invocation produced the 80 passes. No benchmark/model jobs were launched and no broad upstream benchmark qualification is claimed. Existing CI fixes and typed/generator owners are retained. Remote comparison confirms |
|
This pull request has merge conflicts with Choose the remote for the base repository, not an out-of-date fork. git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEADFor a same-repository clone whose Keep the DCO |
Signed-off-by: jackie-cqz <2557911191@qq.com>
|
Conflict resolution published on Registry manifest conflict was regenerated from actual merged source: 291 current sites, zero unclassified direct sites, manifest check passed. Existing ZCode/CI fixes remain intact. All 76 affected Python and 34 typed tests passed, zero skips, covering Bot-group/private conversation authorization, transport composition, binding and registry census. Typecheck, semantic advisory/full smoke and diff checks passed. Existing binding/generator owners are retained; no new abstraction or authority change was authored by resolution. Remote comparison confirms |
|
This pull request has merge conflicts with Choose the remote for the base repository, not an out-of-date fork. git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEADFor a same-repository clone whose Keep the DCO |
…coverage Signed-off-by: jackie-cqz <2557911191@qq.com>
…erge Signed-off-by: jackie-cqz <2557911191@qq.com>
|
Conflict resolution published on Preserved browser shards/coverage merging plus main's timeout budget; unified the paired-URL smoke on main's parser with retained negative cases; adopted current selection/exact-Todo fixtures while retaining repeated/wrong-scope Explore refusal checks. Registry metadata regenerated and checked (291 current sites, zero unclassified). Initial run had 618 passes/four failures: three missing-helper failures repaired by restoring the helper needed by retained tests, and one isolated PATH setup failure. All 23 replan tests then passed; the fresh final-head run passed all 622 selected tests, zero skips. Blog smoke, typecheck, semantic advisory/full smoke and diff checks passed. No production authority change or speculative abstraction was authored. Full desktop/backup/benchmark qualification remains for owning CI; no benchmark/model job was launched. Remote comparison confirms |
Goal And Delivered Outcome
ZCode previously entered through the LoopX Skill facade without machine-backed native Goal control. This adds an explicit managed CLI session bound to an existing LoopX Goal and registered Agent, with model selection, start/pause/resume/stop, status readback and Core quota admission/revocation.
mainis the intended base. No issue or RFC milestone is closed.Author Declaration
loopx/zcode_goal_mode/README.md, existing Goal/registered actor/quota contracts,docs/development/frontend-delivery.md,docs/development/design.mdand S4/S5/S7/S8/S12 in the overall roadmap.main(647e216ba) is included. The provider's TypeScript runtime owns native lifecycle; Python adapts existing canonical authority, and the frontend consumes its readback. No parallel quota or Goal decision owner is added.bridge.py, existing registry and routing ownersruntime.ts,app-server.ts,guard.tscli.ts,runtime.tsdiagnostics.py, doctor/installer ownersScope And Continuation
Managed CLI scope only; the existing ZCode Skill facade remains available and native execution remains explicit opt-in. Desktop conversation attachment, MCP/Hooks/plugins, Automations, live provider billing, per-model-call hard budgets and fleet efficiency remain outside this slice. Native usage is unknown; native completion does not settle a LoopX Goal or debit credits. Exact instance identifiers and existing creation witnesses are fenced; legacy aliases without either cannot distinguish identical deletion/recreation.
The CI repair follows the current canonical contracts. Synthetic histories explicitly opt into the existing completed-Todo cadence instead of relying on the new effective-Turn default. Causal waiting acquires a lease before installing a pending dependency, applies successor planning with that proof, and uses the narrow owner-deferral transition to atomically retire the lease. Exact Todo reads preserve full requirements and reject
--thin. History reduction remains tolerant while authoritative status fails closed on malformed settlement evidence. Explore's scoped hook body is already delivered by the typed context owner; source commands are provenance, and redundant or retargeted tool execution remains rejected. Windows lock-holder metadata is distinguished from committed journal/run records. No product permissions, quota limits or admission rules are weakened by these fixture corrections.The future-facing pass moves provider-only frontend validation/requests out of generic Chat data, preserving one provider vocabulary and the existing request transport. The source observation seam reuses existing bounded/cached canonical reads; eligibility adds zero source reads or native probes. Broader host composition is deferred until a real caller needs it.
Validation
Current candidate:
9a046fe10d2c2ec339083951cf1473a7ac7fc2f5, including main647e216bacc0a69368dccc18fcb52dcba6002553.Resolved five conflicts with current contract ownership: retained three browser shards/coverage merge and main's 25-minute acceptance budget; adopted main's stronger paired-URL anchor parsing while retaining wrong-target/non-anchor tests; adopted current selection/Todo fixtures; preserved repeated/wrong-scope Explore refusal tests alongside main's inline work-context checks. Regenerated registry metadata from merged code (291 current sites, zero unclassified sites).
Initial selected run: 618 passed, four failed. Three failures exposed a retained negative-test helper omitted during merge; it is restored without changing product behavior. The fourth was isolated validation setup (
command_available=false), corrected by putting the selected environment's command directory on PATH. All 23 replan semantic tests passed after the helper repair. A fresh exact-final-head run then passed all 622 selected tests, zero skips, covering replan/selection/Todo, workflow partition/coverage, Node probing and doctor installation scope. Node 24.21 bilingual Blog smoke (six pairs), typecheck, advisory, full semantic drift and diff checks passed.Remote comparison confirms
behind_by=0. The bounded future-facing pass preserves shared owners, one URL parser and durable negative coverage; no production authority or new abstraction was authored. Upstream desktop/backup/benchmark changes were adopted; their complete platform/build/benchmark suites were not locally requalified and no benchmark/model job was launched. New exact-head CI and maintainer review remain required; initial failed evidence is retained.Prior CI-repair qualification
Prior CI-repair candidate:
1f308bbdf974ca652eba2e7d22c3b9c5b37cea32, including main89505091fe52d318112aaaefb85f97e61cf11b33.The last published head
3bce41ae0had six obsolete-contract Python failures, two Windows runtime-retirement deadline failures, a Dashboard 15-minute timeout, and two Python 45-minute timeouts. Python shard 2 actually passed 4,725 tests before its artifact upload was cancelled. These are distinct failure causes; cancelled jobs are not passes.checks,dashboard-acceptance,pytestand the final coverage artifact names remain stable.Remote CI is running for the current exact head. The owning acceptance is reliable complete qualification (S2/S10 validation boundary); no roadmap checkpoint is closed from local passes alone. The related refactor consolidates browser coverage merging and canonical relative paths; no product lifecycle, quota, admission or permission owner changes.
Retained prior qualification
Candidate head:
3bce41ae082d06a2a0f093aed22e5d545da72250, including main44931b6d22a50b949d43354e6ea498fb6b68d231.The previous exact head
082a097c1executed Python shards 1 and 2 and failed obsolete fixture assumptions; shards 3 and 4 were cancelled. TypeScript, real PostgreSQL, packaged browser, static, dashboard and Windows jobs passed on that earlier head. Those results are retained as prior evidence, not a green result for this candidate.Prior feature qualification remains available: the packaged frontend's 49 scenes plus real HTTP storage/recovery, native CLI cold recovery, quota withdrawal/pause/denied-resume/restored-admission/explicit-resume, and the original matched 96-workload presentation checks. Live billing, Desktop conversation attachment and per-model-call hard budgets remain unqualified and out of scope. No benchmark/model job or external notification was launched by this CI repair.
Remote CI and independent review must qualify the published head. This control-plane/provider PR remains for maintainer review and merge.