Skip to content

fix(control-plane): isolate host completion by Goal instance - #5967

Open
Duang777 wants to merge 8 commits into
loopx-project:mainfrom
Duang777:codex/fix-host-completion-goal-instance
Open

Duang777 wants to merge 8 commits into
loopx-project:mainfrom
Duang777:codex/fix-host-completion-goal-instance

Conversation

@Duang777

@Duang777 Duang777 commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator

Goal And Delivered Outcome

  • Outcome basis / optional anchor: Reproduced control-plane settlement identity collision.
  • Goal/source and gap: host_todo_completion.ts preserved an exact GoalRef in commands but derived turn_instance_id from only goal_id, agent_id, and todo_id.
  • Observable before → after, with the validation row that proves it: Two Goal instances with one alias produced the same settlement identity, so the successor could be blocked by the predecessor quota receipt. Exact Goal references now use a domain-separated digest that includes goal_instance_id; alias-only requests retain their existing bytes.
  • Issue/task and intended base: Self-contained bug fix against loopx-project/loopx:main.

Author Declaration

  • Written by: OpenAI model agent, directed by a human operator.

Implemented against

  • Specification and revision: No written specification; the request in this PR is the basis.
  • Criteria:
Criterion (spec clause) Disposition Symbol / path Test or command
Exact retries keep one settlement identity implemented turnInstanceId host_todo_completion.test.ts
Different Goal instances cannot share a settlement identity implemented turnInstanceId host_todo_completion.test.ts
Alias-only callers keep the legacy identity encoding implemented turnInstanceId Existing host completion and Python adapter tests
  • Self-check before submission: Reviewed the host completion, effect ID, and quota receipt call chain. Ran the focused TypeScript and Python suites, TypeScript typecheck, and diff-driven premerge. This PR does not change quota settlement schemas or Goal acceptance state.

Scope And Continuation

  • Completed scope and remaining work: Complete within host Todo completion identity derivation. Goal acceptance lifetime fencing is a separate change.
  • Slice boundary / successor: N/A for this defect; the fix is independently testable and preserves the alias-only contract.

Validation

  • Tested revision: d06fe964a07c6e04c915c4a914888765677cacf2
  • Run state: finished
  • Input classes: synthetic
Check kind Result Public-safe evidence / limitation
unit passed node --no-warnings --experimental-sqlite --experimental-strip-types --test tests/control_plane_ts/host_todo_completion.test.ts: 15 passed.
integration passed python -m pytest -q tests/test_goal_mode_mcp_settlement.py: 8 passed.
static passed npm run -s typecheck:control-plane.
real_entrypoint passed loopx canary premerge --from-git-diff --git-diff-base upstream/main: 13 selected checks passed with no manual hold.
real_backend not_applicable The changed identity reducer is deterministic and does not access a provider.
  • Coverage and gaps: Tests cover retry stability, cross-instance separation, downstream effect separation, and mismatched finalization. Existing adapter tests cover the alias-only path. No backend-specific path changed.

Frontend / Visual Evidence

  • UI impact: none
  • Before: N/A
  • After: N/A
  • States and viewports shown: N/A
  • Source data: none
  • Attention review: N/A

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Refactoring (no functional changes)
  • Documentation update
  • Test update

LoopX Area

  • Control plane (goals, todos, quota, scheduler, registry, runtime)
  • Benchmark boundary (adapters, runners, verifiers, scoring, evidence)
  • Capability or extension (providers, adapters, skills)
  • Public docs or presentation surface (README, protocols, dashboard)
  • Build, packaging, installer, or CI
  • Host or runtime integration

Technical Direction

  • Direction / acceptance reference, when applicable: Core control-plane hardening.

Shared-authority RFC fixture impact

N/A. This PR changes local identity derivation, not provider routing or shared-authority schemas.

Boundary Checklist

  • Neither the diff nor this PR body/comments/attachments disclose private state, credentials, raw traces or verifier output, internal links, or local machine paths (including .loopx/, .codex/goals/, and live ACTIVE_GOAL_STATE.md).
  • I did not duplicate maintainer-owned benchmark work unless a maintainer split out a public issue for it.
  • I kept the change scoped to the linked issue/task.
  • I completed the visual evidence section for UI changes, or marked UI impact none.
  • Every commit includes a DCO Signed-off-by trailer (git commit -s).

Signed-off-by: Duang777 <duangjl007@gmail.com>
Signed-off-by: Duang777 <duangjl007@gmail.com>
Signed-off-by: Duang777 <duangjl007@gmail.com>
Signed-off-by: Duang777 <duangjl007@gmail.com>
Signed-off-by: Duang777 <duangjl007@gmail.com>
Signed-off-by: Duang777 <duangjl007@gmail.com>
Signed-off-by: Duang777 <duangjl007@gmail.com>
Signed-off-by: Duang777 <duangjl007@gmail.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant