Skip to content

test(collaboration): qualify split-source recovery on SQLite - #6056

Merged
loopx-agent merged 1 commit into
mainfrom
codex/native-source-roundtrip-qualification
Oct 9, 2026
Merged

loopx-agent merged 1 commit into
mainfrom
codex/native-source-roundtrip-qualification

Conversation

@loopx-agent

@loopx-agent loopx-agent commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Split Chat/coordination source-recovery refusals and lost-answer recovery were exercised with the default File fixture, while SQLite had only the positive forwarding/return journey. Exercise the same existing source, grant and recovery invariants against both real canonical providers. A rejected legacy source must also leave all request, peer-operation and return-route records unchanged.

Validation: 46 source tests and the same 46 tests against an independently installed wheel passed, including the production manager-inbox CLI request/read/adopt/report/consume path and original-conversation return. Removing the closed-source check in the disposable installed package caused both File and SQLite refusal cases to fail as expected; the package was restored. Ruff, diff checks, semantic advisory and native premerge checks passed (four direct checks, no selected catalog checks).

This is provider qualification coverage. Fixtures use isolated synthetic Goals and a synthetic verified sender; they do not establish live peer adoption, real external delivery or release-default SQLite qualification. Reuses the existing fixture and typed source/grant/recovery owners; there are no runtime or frontend changes.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; xhigh.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

动机

维护跨 Chat 存储与协作存储的转交链路时,维护者需要知道原会话关闭或来源授权撤销后,SQLite 会拒绝恢复和继续转交。 此前同一组错误来源和丢失答案的用例只使用 File;未来 SQLite 回归可能在既有正例仍通过时漏检。本 PR 将这些既有用例同时运行在 File 和真实 SQLite,并检查拒绝操作没有改变协作记录。 已验证两种 provider 拒绝非法来源并保持原记录,已提交的请求在答案丢失后仍可恢复;在独立安装包中移除关闭检查,两种 provider 的负例都会失败。

本 PR 仅改变验收测试,不改变运行时、默认 provider、App/Lark 界面或权限,不建立真实 peer 采用和真实外部消息交付的证明。 真实 peer 独立接收、采用、评审、请求方消费及原会话实际交付仍由现有协作验收任务继续核验;SQLite 发布默认资格也保持独立。

改动思路

精确 head:49901c0be4259cf303da7fdebdfb1b9766895956,基线:81865ed9512fa0afc36b8e11b561788104a47247。依据已接受的 loopx/capabilities/manager_context/README.md,spec_revision:81865ed9512fa0afc36b8e11b561788104a47247。保持原始来源、当前 grant、请求身份与返回路由的既有 owner;Python 这里只选择测试 provider,没有新增决策源。

逐项对照该文档的验收内容(以原章节和要求命名,没有额外创造契约):

  • Original source provenance:原始 Chat Session/Turn 与固定来源须精确匹配;关闭、缺失、错误/含糊 locator 的负例在两种 provider 上通过。
  • Current source grants:每次转交重新检查当前来源授权;撤销、第三跳无授权的用例通过。
  • Peer result consumption:既有真实 CLI request/read/adopt/report/acknowledge-return 正例仍通过。
  • Original conversation return:原始会话、去重与恢复由现有 ReturnService/drain 正例验证;外部 sender 为合成验证适配器。
  • Live peer adoption:本次未验证真实 Agent 或外部服务,保留为现有协作验收的剩余工作。

具体改动

唯一修改 tests/control_plane/test_peer_source_store.py(+20/-10)。五个已有测试组复用 source_request(provider=...),包括旧来源拒绝、固定来源不可重指向、Host 不可替换已有来源、丢失 Chat 答案恢复、精确原会话可用性。旧来源拒绝还比较 entries、peer-operations、roundtrips 的完整记录快照,验证没有新增或改写记录。

生产路径仍是 Chat 来源 → 原始路由与 ingress 观测 → 既有 TypeScript 来源授权/Goal 身份规则 → peer 请求/结果记录 → 原始会话返回。读取不会创建另一份 Chat 存储;只有真实原 Host 的恢复流程可补齐旧来源。复用原 fixture,避免新矩阵文件或并行兼容层;本次未来重构检查已落实为扩展原用例,未发现需要移动运行时 owner 的相关改动。

对主干的风险

测试改动不会改变持续执行、重试、调度和用户操作步骤。最强回归场景是 SQLite 在原会话关闭后仍许可转交,但正例仍为绿;独立安装包中删除关闭拒绝检查产生预期的两项失败(File/SQLite),随后恢复原文件。覆盖增加了测试执行时间,不增加产品运行时成本。

验证:基线 26 项通过,最终源码 46 项通过;独立 wheel、隔离目录、真实 File/SQLite 后端和生产 CLI 再次 46 项通过。Ruff、diff hygiene、semantic advisory 通过;原生 premerge 四项直接检查通过,catalog 选中/执行均为 0。首次 wheel 构建因已有前端 assets 与 lock 不匹配被拒绝,按现有构建流程重建未修改的前端后成功;没有绕过构建边界或改变资产源码。关闭检查反事实的两项失败是刻意注入的缺陷,不是当前 head 的失败。按 Goal 配置未查询 CI,没有额外人工 hold。

隔离 fixture 使用真实 canonical 存储与 typed grant owner,但 Host authorization scope 为 mock、sender 为合成适配器。验证的是恢复/拒绝契约,不能据此声称真实 peer 已执行或真实 Lark 已发送。旧格式、历史回执和真实调用方均未删除;回滚只需撤销此测试提交。

同作者公开未合并批次扫描没有另一个等价的来源拒绝矩阵;相邻 PR #6055 是实际边界修复,#6052 是 settlement 可发现性,#6050 是 App producer 退役,均不是同形测试拆分。已有覆盖扫描确认负例原先默认 File;本次整合进既有测试,具有具体回归保护价值。

我的整体评价

APPROVE,属于 justified_increment:补齐真实 SQLite 的来源拒绝和恢复验收缺口,完整、可独立审查和撤销。没有阻断项;现有协作任务保留真实 peer 与原会话交付验收。本 PR 只触及测试,符合小型测试 PR 自评审后的合并范围;最终合并仍需原生精确 head merge-readiness,运行时 PR 保持维护者合并边界。

English verdict: APPROVE - 49901c0. Reuses the existing real File/SQLite fixtures to qualify source refusals and lost-answer recovery; 46 source and 46 isolated installed-wheel tests passed, and removing the closed-source check produced the expected two failures. Live peer adoption and external delivery remain separate acceptance work.

@loopx-agent

Copy link
Copy Markdown
Collaborator Author

Exact-scope change-quality qualification passed for 49901c0be4259cf303da7fdebdfb1b9766895956 against 81865ed9512fa0afc36b8e11b561788104a47247 (receipt cqr_6559c380b76e475ef9f0). The existing fixture and five test groups are reused; no runtime, UI, authority or persisted-contract change. Source and independently installed wheel each passed 46 tests; the closed-source counterfactual produced the expected two failures and was restored. Native premerge passed four direct checks; catalog selected/executed zero. No current failures or manual holds; CI is not consulted under the resolved review policy.

The exact-head self-review is published and read back. This test-only PR fits the repository's narrow self-merge policy under the owner's authorization to advance reviewed PR merges. Original live peer/transport acceptance remains open; runtime PRs retain the maintainer merge boundary. Run the native exact-head merge-readiness gate again immediately before merging.

@loopx-agent
loopx-agent merged commit ef999b6 into main Oct 9, 2026
4 checks passed
@loopx-agent
loopx-agent deleted the codex/native-source-roundtrip-qualification branch October 9, 2026 23:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant