Skip to content

test(architecture): register source session loader owner - #5927

Merged
huangruiteng merged 1 commit into
loopx-project:mainfrom
mikamikasuki:codex/loopx-source-session-denial-manifest
Oct 8, 2026
Merged

huangruiteng merged 1 commit into
loopx-project:mainfrom
mikamikasuki:codex/loopx-source-session-denial-manifest

Conversation

@mikamikasuki

@mikamikasuki mikamikasuki commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Goal And Delivered Outcome

  • Outcome basis: Reproduced the current-main failure in the direct project-registry loader ownership inventory.
  • Goal/source and gap: The architecture contract requires every direct loader to be listed and assigned to its guarded-reader or source-session lifecycle boundary. At canonical main 9ba6148fccf335f2e38d800812dbb398008229c6, loopx/control_plane/goals/source_session_recreation.py directly loads the project registry but is missing from both ownership sets.
  • Observable before → after: On exact main 9ba6148, tests/architecture/test_source_session_registry_denial.py fails 1 test and passes 1; the failure identifies source_session_recreation.py as the extra direct loader. This patch adds that path to the direct-loader allowlist and source-session owner set. On PR head 5c2ff67488d9540798584b52b213d2c9be9922f7, the same module passes 2/2.
  • Issue/task and intended base: Self-contained architecture-test correction; no separate issue is required under CONTRIBUTING.md#find-work. Base: canonical main at 9ba6148fccf335f2e38d800812dbb398008229c6.

Author Declaration

  • Written by: model_agent — OpenAI GPT-6 Luna.

Implemented against

  • Specification and revision: The direct-loader ownership invariant in tests/architecture/test_source_session_registry_denial.py and the lifecycle boundary in docs/architecture/rfcs/goal-instance-identity-and-orphan-recovery-v0.md, both at 9ba6148fccf335f2e38d800812dbb398008229c6.
  • Acceptance criterion: Every direct project-registry loader is inventoried at its correct owner boundary.
  • Scope: Test-only ownership inventory update; no product behavior change.
  • Self-check: Compared exact current-main and PR-head results after rebasing, reviewed the two-line diff, and reran focused, static, and repository validation.

Scope And Continuation

  • Completed scope and remaining work: Add the missing lifecycle-owned module to both architecture-test sets.
  • Slice boundary / successor: Complete within this scope; no production change is required.

Validation

  • Tested revision: 5c2ff67488d9540798584b52b213d2c9be9922f7 (base 9ba6148fccf335f2e38d800812dbb398008229c6).
  • Run state: Local validation finished; required GitHub checks are running.
  • Input classes: synthetic.
Check kind Result Public-safe evidence / limitation
regression_parity passed On exact main, the target module is 1 failed / 1 passed because the direct-loader owner is missing; on this PR head it is 2 passed.
unit passed python -m pytest -q tests/architecture/test_source_session_registry_denial.py: 2 passed.
static passed Ruff, Python compilation, and git diff --check origin/main...HEAD passed.
repository validation passed loopx canary premerge --from-git-diff: 2 selected, 2 passed, zero failures or manual holds.
required GitHub checks running Summary passed; changes, DCO, and Dependency Review are queued; merge-gate is expected. Code-owner review remains requested.
  • Coverage and gaps: The change updates only the static ownership inventory. It does not claim a runtime behavior change.

Frontend / Visual Evidence

  • UI impact: none.
  • Before/after screenshots: N/A.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Refactoring (no functional changes)
  • Documentation update
  • Test update

LoopX Area

  • Control plane (goals, todos, quota, scheduler, registry, runtime)
  • Benchmark boundary (adapters, runners, verifiers, scoring, evidence)
  • Capability or extension (providers, adapters, skills)
  • Public docs or presentation surface (README, protocols, dashboard)
  • Build, packaging, installer, or CI
  • Host or runtime integration

Technical Direction

  • Direction / acceptance reference: N/A; this is a focused architecture-test ownership inventory repair.

Shared-authority RFC fixture impact

  • Production-scale fixture schema: N/A.
  • Semantic dimensions changed: None; no authority schema or runtime semantics changed.
  • Provider conformance arms: N/A.
  • Read-only legacy/file/PostgreSQL rehearsal: N/A.

Boundary Checklist

  • No private state, credentials, raw traces, verifier output, internal links, or local machine paths are included.
  • This does not duplicate maintainer-owned benchmark work.
  • The change is scoped to the reproduced loader-inventory failure.
  • UI impact is none.
  • The commit includes a DCO Signed-off-by trailer.

@mikamikasuki
mikamikasuki force-pushed the codex/loopx-source-session-denial-manifest branch from 701549e to e5025ed Compare October 8, 2026 02:46
@mikamikasuki

Copy link
Copy Markdown
Contributor Author

Windows run 37719525911 fails test_successive_same_effect_checkpoints_receive_distinct_operation_ids when _read_info receives PermissionError opening the temporary runtime locator JSON and raises EffectRuntimeHostPermissionError. This PR changes the source-session loader ownership manifest/test and does not modify the runtime reader. The shared transient locator-read failure is addressed in #5936; both affected integration cases pass on that PR's head 8137922 (2 passed). After #5936 is merged, this Windows check should be rerun against the updated base.

@mikamikasuki
mikamikasuki force-pushed the codex/loopx-source-session-denial-manifest branch from e5025ed to a62e9fc Compare October 8, 2026 05:15
@mikamikasuki

Copy link
Copy Markdown
Contributor Author

CI attribution update: I reran six representative shard-3 failing selectors in a detached worktree at the exact PR base 82d1b83; all six also fail there (6 failed in 6.97s). They are outside this PR’s sole changed architecture-test file. On PR head a62e9fc, that focused file passes (2 passed). This confirms those selected failures predate this manifest-only change. The current run still has shard 3 and Windows PowerShell failures, with other jobs pending; the Windows locator PermissionError is separate from this diff and #5936 remains open. I’ll keep this PR scoped and reassess after the remaining checks/base update.

@mikamikasuki
mikamikasuki force-pushed the codex/loopx-source-session-denial-manifest branch 2 times, most recently from b2eff6a to abb55f3 Compare October 8, 2026 12:56

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent | gpt-6.1-sol | OpenAI | runtime_reported | xhigh

动机

运行架构检查的贡献者和维护者会遇到此问题。现有 Goal 重建模块已直接读取项目注册表,但清单未记录它,主干检查因此失败;补入既有清单与生命周期 owner 集合后,正常检查通过,新添未知读取者仍被拒绝。本次复现 base 一失败一通过,精确 head 两项通过,并验证未知 loader 与删除通用 decoder 拒绝调用的两个反例仍会失败。此 PR 只修复架构检查清单,不改变 Goal 生命周期权限,也不验收实例隔离全链路。

评审 head:abb55f39d643d0f29375780b16c6afc091a1fdfb;base:aa0c2ea6a6bad1f105e8c2f66464cf4d8c4de2b1。独立依据是 docs/architecture/rfcs/goal-instance-identity-and-orphan-recovery-v0.md,spec_revision aa0c2ea6a6bad1f105e8c2f66464cf4d8c4de2b1;M0 要复用既有 codec/transaction/I/O 清单,本次在此 owner 内修复缺项。M3 的完整 owner 资格与 activation hold 保持,属于范围外;此两行改动不证明全链路已满足。

改动思路

先验证模块的归属再补清单。source_session_recreation._canonical_writer_guard_path 读取注册表以解析 canonical writer 锁,实际调用者是 recreate_goal_instance 的生命周期流程,沿用 source-session transaction 与 typed Effect 决策,而不是普通 runtime reader。最小修复就是同时登记两处现有集合;删掉扫描、删断言或加第二套 owner 都不合适。机制留在既有测试及生命周期 owner,当前 PR 交付边界是清单修复。未来相关重构检查已做:这一处无需增加 helper 或重写未改动的生产代码。

具体改动

只有 tests/architecture/test_source_session_registry_denial.py 两处:DIRECT_LOADER_ALLOWLIST 登记实际 AST 发现的读取者;source_session_owners 登记它既有的专属生命周期归属。全目录 AST 扫描、集合精确相等、其余 runtime reader 的拒绝检查、精确函数级 metadata-reader 例外及 decoder 拒绝调用断言全部保留。生产源码树完全相同。

独立验证:同命令 base 1 failed/1 passed,失败只指出此缺项;head 2 passed。完整源代码 fixture 中加入未登记 loader、移除通用 decoder 拒绝调用,各自被原断言拒绝。另跑生产 lifecycle 套件 24 passed;执行 checkout 与本 PR 的生产树、套件 blob 完全一致,未用 mock 供应生命周期后置条件。聚焦 Ruff、diff/compile 和原生 premerge 的 2 个 semantic/architecture 检查及 4 个直接检查均通过;本角色的 exact-scope CQR 也已有效读回。

对主干的风险

未发现阻塞项。风险是清单豁免被错误扩大,本次反例仍失败,并没有缩小扫描或去掉拒绝检查。读取者登记不授予新权限。静态清单和这些合成生命周期测试不等于真实已激活 profile 的所有 effect 资格。阅读了历史 locator/Windows 讨论,但不继承旧测试结论,不查询或等待 CI。检索现有覆盖和同作者 47 项 PR 后,当前改动复用既有测试,邻近 digest-owner 修复与该 owner 不重复。

我的整体评价

APPROVE。这是复现出的主干架构清单维护问题,当前 head 修复它且保留异常探测能力,符合 M0 复用边界;不以测试变绿冒充 M3 完成。无需扩成 runtime 重构或新增 smoke。代码批准和合并授权仍分别处理。

English verdict: APPROVE - abb55f3; repairs the existing source-session loader inventory without changing runtime authority. Exact base fails only on the missing owner, head passes 2 tests, two deliberate guard/census mutations are rejected, and 24 identical-source lifecycle tests plus focused/native validation pass. CI was not consulted.

Signed-off-by: mika <211269698+mikamikasuki@users.noreply.github.com>
@mikamikasuki
mikamikasuki force-pushed the codex/loopx-source-session-denial-manifest branch from abb55f3 to 5c2ff67 Compare October 8, 2026 15:51
@huangruiteng
huangruiteng merged commit 9d7680a into loopx-project:main Oct 8, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants