Skip to content

fix(periodic-report): recognize native accepted Vision successors - #5935

Merged
huangruiteng merged 5 commits into
loopx-project:mainfrom
hhyykk:codex/periodic-report-native-successor-stage-20261008
Oct 8, 2026
Merged

huangruiteng merged 5 commits into
loopx-project:mainfrom
hhyykk:codex/periodic-report-native-successor-stage-20261008

Conversation

@hhyykk

@hhyykk hhyykk commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Problem and result

A real accepted Vision-successor writeback carries semantic_delta.obligation_id without a monitor's optional frontier_identity. The existing enabled refresh-state hook omitted its completed-stage milestone. The first repair recognized that typed acceptance, but composed Turn negative cases revealed a second attribution error: a later ordinary refresh could first report an older accepted boundary.

The capability read model now binds a successor milestone to the exact durable source refresh carrying its accepted ACK and selected Vision. Successor retry uses that source's run-index append prefix, including equal-clock writes, so a later unacknowledged Vision cannot borrow or displace the original acceptance. Terminal settlement remains based on current history: later Todo completion can settle a still-current CLOSED Vision, while a newer ACTIVE Vision prevents an older CLOSED stage from being declared terminal.

The existing TypeScript replan acceptance owner, explicit frontier receipt identities, stage identity and report queue are reused. This adds no generic decision owner, capability, configuration, new persisted schema, generation authority or external-delivery authority.

Validation and remaining boundary

Current base is 21707b7fb64123df02e730bf7959192010f85a1b; current head is 1a34dcc36eebe2f6aa23b06398996e8affb24724. All five branch commits carry DCO sign-offs.

  • On latest main, the same public native fixture genuinely fails the enabled intent assertion (0 instead of1); feature-off passes. The final source branch passes 94 stage/native CLI/hook checks. The worker's earlier focused set passed108 and independent final edge review passed6; those are separate bounded observations.
  • Fresh standalone wheel and sdist each pass all five real native CLI cases, including enabled/off, ordinary later refresh rejection, and original-source retry after same/next-second unacknowledged Vision edits. Installed provenance and seven production-source hashes match this exact source; no checkout fallback.
  • Latest-main local composition with fix(periodic-report): recover hooks from original canonical writebacks #5939 passes122 source checks, including the preserved ordinary Turn negative cases that previously failed3, and eight direct accepted-successor Turn/recovery cases. Fresh composed wheel and sdist each pass26 real native/terminal/Turn cases with13 production-source hashes verified. The durable caller coverage is proposed separately in draft test(periodic-report): preserve Turn milestones through retry recovery #5951; this branch does not carry copied Turn production code.
  • Ruff, diff checks, semantic advisory and full semantic premerge pass. Risk-based premerge passes5 direct checks,5/6 catalog checks,8/8 risk-profile checks and the public boundary scan.
  • The sole premerge failure remains the unchanged dashboard JSON budget. Identical standalone base/head work measures22,560 against22,500; the canary startup context separately measures22,728. The failure is retained with no budget increase or instruction compression; CI/merge readiness is not claimed.

The related future-facing pass removes a second historical ACK search as an authority source and binds successor replay to the already persisted run. Legacy unpromoted Todo state still has no historical frontier readback: replay after later Todo mutation remains dependent on current frontier facts. #5939 owns canonical historical-source recovery. The stronger current-Vision terminal guard, including newer nonmaterial CLOSED cases, also belongs to #5939 and is not claimed complete on this standalone successor branch. The existing64-run source-history bound, full PostgreSQL Turn, frontend/Lark and live provider/model adoption remain unqualified; this PR does not complete the parent migration or report lifecycle.

All fixtures are isolated synthetic state; no active Goal, benchmark/model job or external send is used. Generated lock files and raw evidence are excluded. Runtime/control-plane change: maintainer merge only. The earlier exact-head blocker review remains part of the discussion; the final repair receives a new whole-PR review on its unchanged head.

Maintainer Rebase And Resolution Note (2026-10-08)

Rebased onto main at 62acd670fc5c231f323176ebf28f228aee5bd334 (after #5939 landed the
canonical historical-source recovery); new head
8a05a79fbea4365aac98a0c60abea29bc2d50271 over base
62acd670fc5c231f323176ebf28f228aee5bd334. All five commits keep their original
author and carry DCO sign-offs.

The rebase replayed onto #5939's newer read model: the committed-refresh
source_runs injection, read_report_source_history, and the stronger
current_vision terminal guard are all retained from main. The resolution
keeps this PR's intent for the successor path: a history-wide search for a
settleable ACK is removed, so a successor milestone is only claimed from the
exact durable refresh that wrote the selected accepted Vision and its ACK.
Field conflicts were limited to post_writeback_hook.py,
stage_completion.py and test_periodic_report_stage_completion.py; both the
upstream terminal-guard tests and this branch's successor tests are kept.

Maintainer validation on this head: the CI-scope Ruff command plus the changed
periodic-report surface, the configured python -m mypy (19 sources),
git diff --check, six affected period-report/post-writeback suites (148
passed), and the sibling periodic-report suites (143 + 160 passed).

@hhyykk hhyykk left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=ultra

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Exact head: fdb1c0a

动机

启用周期报告、通过公开 CLI 写回阶段结果的使用者会遇到这个问题。
一个阶段已完成,系统接受了后继计划,但报告队列没有里程碑;修复后同一写回产生一个可发现的待处理意图。
已验证原生写回、重复调用和待处理队列读回,无需新增手工输入。
这项变更不授权生成或外部发布,也不完成整个 TypeScript 迁移。
直接 Turn 钩子接入、旧前沿恢复和完整前端报告流程仍待交付。

改动思路

验收仍由现有 TypeScript 重规划规则决定,Python 只修正周期报告的派生读模型。
现有原生凭据已经给出接受的义务 ID,要求它另带监控专用前沿 ID 会丢掉合法结果。
复用已有凭据和归一化函数比新增声明、状态或 RPC 更直接。
既有显式前沿身份继续用于旧收据去重;原生路径须匹配完整接受增量、Agent 和后继 Vision 修订。
该改动只修复已有 refresh-state 报告生产者,没有新增能力、配置、状态生命周期或通用决策源。

具体改动

关键代码讲解

  1. build_periodic_report_post_writeback_projection 在既有已记录 ACK 中投影 semantic_delta.obligation_id,仍从现有 Todo 来源和历史读取状态。没有重写接受规则或增加执行权限。
  2. derive_periodic_report_stage_completion 在无显式前沿时使用规范化义务身份;拒绝义务不匹配、未接受增量、错误 Agent、非后继结果或不成立的自有前沿。显式前沿收据保持原有身份。
  3. derive_periodic_report_stage_completion_from_runs 要求所选后继 Vision 与接受该增量的写回一致。独立审查发现仅比较 ID 可以借用另一增量;现在同时检查接受增量及来源 Agent,原反例被拒绝。

两个测试文件分别覆盖身份、错误增量和跨 Agent 反例,以及真实公开 CLI 的关闭/启用、原生接受、精确重放、侧车数量和待处理队列读回。协议文档解释原生身份与既有前沿兼容;迁移 RFC 的现有 T3 检查点明确已交付与剩余边界。

规格依据为 docs/reference/protocols/periodic-report-v0.md,固定修订 89505091fe52d318112aaaefb85f97e61cf11b33,不是本 PR 改写后的文本。其已有术语 bounded_segment_milestone 要求有证据的阶段闭合和持久化继续路径,本次已实现原生生产者;vision_successor_required 要求匹配的接受增量和后继 Vision,本次已实现。通用钩子权限边界沿用 docs/architecture/rfcs/provider-neutral-post-writeback-capability-hooks-v0.md。直接 Turn 接入和原始前沿恢复仍属于该 RFC 的后续边界。

对主干的风险

主要风险是把另一写回的接受凭据误认作本阶段完成。现在错误义务、不同接受增量、其他 Agent 和后来的未确认 Vision 都被拒绝;已有显式前沿测试继续通过。关闭功能仍走原有主写回路径,不产生意图或侧车;安装、凭据可读和 CLI 可用本身不会启用报告。生成与外部发布授权始终为 false,普通 Todo 完成仍不能直接证明阶段闭合。

89 项阶段/钩子/原生 CLI 检查与 72 项消费/运行时/触发检查通过,后者包含真实 File/SQLite 编辑请求路径。wheel 与 sdist 各通过 2 项公开 CLI 检查,安装源码哈希一致;Ruff、diff 和完整语义词表检查通过。初始安装测试因未显式绑定测试工作区失败,补齐工作区参数后真实安装路径通过,没有放宽产品校验。未验证真实发布、Lark、完整前端报告流程或真实 host/model;本次没有这些入口改动。

语义与 CI 对齐

复用既有接受义务词汇和 owner,没有新共享词表。最终 premerge 的 5 项直接检查、5/6 项目录检查和 8/8 项风险检查通过;剩余失败是 Dashboard 输出预算。同一 canary 在固定 main 与本 head 均报 22,728 字符,超过未改动的 22,500 上限,失败身份和数值相同;本 PR 没有改变该因果路径。未提高预算或隐藏失败。远程 CI 在初次读取时仍排队,合并就绪须另行判断。

现有 Goal 全局 64 条历史窗口可能在大量其他运行后丢失闭合 Vision;这在改动前已经存在,不宣称本次修复了繁忙 Goal 的完整历史连续性。直接 Turn 绕过和后续 Todo 变更后的旧前沿重建同样保留为现有交付缺口。

我的整体评价

这是 justified_increment:已有公开写回和待处理队列获得可用结果,原生场景在 main 上为一项通过、一项失败,在修复与两种安装包上均通过。long_horizon 在已验证的重复/重放边界 improved;user_experience 在已有 CLI 队列发现路径 improved,没有新增确认或输入步骤。
生产改动是两个现有模块约 39 行净增,没有新框架。相关收紧已经应用到凭据与 Vision 关联处,显式身份兼容有真实旧收据契约支持。独立审查反例已修复,没有本 PR 的阻塞项;整体结论 APPROVE,现有预算失败和尚未完成的远程 CI 保持独立合并限制,运行时变更由维护者合并。

English verdict: APPROVE fdb1c0a. Native accepted successors now produce one discoverable bounded report intent; mismatched deltas/agents and stale Vision borrowing are rejected. 89 focused and 72 consumer checks passed, plus wheel/sdist CLI checks. The unchanged main/head Dashboard budget failure remains a separate merge-readiness hold; direct Turn adoption and historical frontier recovery remain open.

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent | gpt-6.1-sol | OpenAI | runtime_reported | reasoning_effort=xhigh

English verdict: REQUEST_CHANGES — exact head fdb1c0a9df21d71941fe353294aeee70a2b0f3f6 improves the native successor path, but the same-writeback guard aliases distinct Vision writes within one second. No CI was queried or awaited.

动机

启用周期报告、完成当前阶段后继续下一段工作的操作者会遇到这个问题。原生续任写回只带已接受的 obligation_id,旧 reducer 因缺少可选 frontier_identity 而漏掉阶段里程碑;本改动让现有待处理报告队列收到该里程碑。正常原生续任现在能产生一个有界 intent,但同秒内另一次未获 ACK 的 Vision 仍可借用旧 ACK,被错误标记为已验证。本 PR 不授权生成或外部发布报告,也不改变 claim、lease、quota 或重规划决策。当前有界生产者修复仍需消除同秒关联漏洞;既有 64-run 历史窗口、直接 Turn hook 采用和完整 frontend/Lark 报告旅程继续由原 RFC 边界验收。

改动思路

修复应留在 periodic_report 的派生读模型,复用已有 TS 接受决策和共享 obligation normalizer;不需要新的 Stage 生命周期或第二套权限。当前 PR 交付 enabled post-writeback 到 pending intent 的生产者修复;同秒关联必须在本 PR 修复,历史窗口和后续报告交互保持现有 RFC 后续边界。 不修复会继续漏掉已完成阶段;直接信任最新 ACK 会把它借给另一个 successor。当前方案增加规范化 obligation fallback,并尝试证明 ACK 和 Vision 同属一次写回,这个方向合理;缺口在身份关联,而不是接受决策。

具体改动

完整 base 89505091fe52d318112aaaefb85f97e61cf11b33 → head 为 6 文件、+278/-3:两个生产模块、两个测试文件及两份文档。规范先于实现读取:docs/reference/protocols/periodic-report-v0.md,固定到 89505091fe52d318112aaaefb85f97e61cf11b33。原文 Trigger Decision 的 native successor 识别部分 implemented,但 accepted successor 关联未满足;Post-Writeback Capability Hook Boundary 的 enabled-only、有界 intent、分开授权与 replay implemented;Ownership And Provider Boundary 保持既有 owner。64-run/直接 Turn hook/产品交互是原 RFC 明示的 deferred 边界,不能把本 PR 当作整个报告流程已完成。

关键代码讲解

  • build_periodic_report_post_writeback_projection(post_writeback_hook.py:181)从当前私有 Todo 和最多 64 条历史选择本 agent 的 settled ACK,在 :265 传递其 obligation_id。它只派生报告证据,不接管 quota 或外部 sink。
  • derive_periodic_report_stage_completion(stage_completion.py:91)复用 normalize_todo_replan_obligation_id,保留显式 frontier 身份,检查 accepted delta、触发类型和可归属 successor frontier。
  • derive_periodic_report_stage_completion_from_runs(:202)试图在 :249–273 找到同一个写回;但 :270 使用 _vision_identity,该 helper 的返回值只有 (agent_id, generated_at)。

[P2] 同秒的未获 ACK 的 Vision 可以借用旧 ACK

loopx/control_plane/runtime/time.py:110 的生产时钟会移除微秒;历史支持同秒多条独立 run(独立记录和顺序)。因此 agent 与秒级时刻不是写回身份。控制秒级时钟后,实际隔离 CLI 连续持久化两份不同 Vision;后一次没有 autonomous_replan_ack。生产 build_periodic_report_post_writeback_projection 却返回 successor_frontier_settled、acceptance=validated;把后一次时刻移到下一秒,projection 才变为空。

这是实际 CLI 和持久化文件的反例,只控制时钟,不手改历史、ACK 或权限。按现有 test_periodic_report_native_successor._native_successor 创建已接受 successor,保持 state_refresh.now_local 同秒,再用普通 refresh-state --agent-vision-json 写入不同 acceptance_summary(不带 --autonomous-replan-recorded),读原生历史并调用生产 projection,即可复现。独立 oracle 是:最新未获 ACK 的不同 Vision 不得获得 acceptance=validated。显式 frontier 的原有兼容分支不是这项新漏洞的归因。

最小修复:把选中 successor 与承载 accepted ACK 的同一持久化 run 绑定,或使用能区分同秒不同 Vision 的既有稳定写回/修订身份;不要仅比较 agent_id 与 generated_at。保留现有 accepted semantic delta owner。 回归应同时覆盖同秒不同内容(拒绝)、同一次写回/完整同秒历史(接受)、下一秒未获 ACK 的编辑(拒绝)、foreign agent/delta 和 exact replay。

对主干的风险

198 项阶段、原生 CLI、post-writeback/retry、pending/runtime/trigger 相关测试通过。原生 enabled 路径仅产生一个 bounded intent,重放不重复,feature-off 无 intent/sidecar;真实 CLI/history 的下一秒反例被拒绝。 标准 premerge 5 个 direct 和 15 个 selected/executed 检查中,仅 Dashboard 预算 smoke 失败:canary 启动环境测得 22,728/22,500。另以完全相同的 standalone 命令在 base/head 分别运行,两者均为 22,560/22,500;这是已有 Dashboard 预算问题,未改阈值,也不把两种启动环境混作同一个测量。其余检查通过。该无关预算失败需由 Dashboard owner 处理,不能覆盖本 PR 的同秒关联缺陷。

语义与CI对齐

本变更复用现有协议词汇和 TS 接受 owner;Python 只做已有 capability 的读模型。feature-off 的原生回放无 sidecar/intent,启用后 requested_write_scope 仍为空,generation_authorized/external_delivery_authorized 仍 false;安装/发现/ACK 不授予外部动作。未测完整 packaged frontend/Lark、实际账户发布、模型采纳、真实多进程同秒调度及窗口以外的历史。时钟受控 fixture 证明可表达的同秒历史漏洞,不声称完成真实长期运行验收。

我的整体评价

有用且比例适当的生产者修复,尚不能批准。伴随未来改动的收敛应把关联固定到既有 durable writeback identity,并保留当前 typed 接受 owner;不增加并行 Stage 管理框架。修复应留在 periodic_report 的派生读模型,复用已有 TS 接受决策和共享 obligation normalizer;不需要新的 Stage 生命周期或第二套权限。当前 PR 交付 enabled post-writeback 到 pending intent 的生产者修复;同秒关联必须在本 PR 修复,历史窗口和后续报告交互保持现有 RFC 后续边界。

@hhyykk hhyykk left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=ultra

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Exact head: 5601496

动机

启用周期报告、通过公开 CLI 写回阶段结果的使用者会遇到这个问题。
一个阶段已完成,系统接受了后继计划,但报告队列没有里程碑;修复后同一写回产生一个可发现的待处理意图。
已验证原生写回、重复调用和待处理队列读回,无需新增手工输入。
这项变更不授权生成或外部发布,也不完成整个 TypeScript 迁移。
直接 Turn 钩子接入、旧前沿恢复和完整前端报告流程仍待交付。

改动思路

验收仍由现有 TypeScript 重规划规则决定,Python 只修正周期报告的派生读模型。
现有原生凭据已经给出接受的义务 ID,要求它另带监控专用前沿 ID 会丢掉合法结果。
复用已有凭据和归一化函数比新增声明、状态或 RPC 更直接。
既有显式前沿身份继续用于旧收据去重;原生路径须匹配完整接受增量、Agent 和后继 Vision 修订。
该改动只修复已有 refresh-state 报告生产者,没有新增能力、配置、状态生命周期或通用决策源。

具体改动

关键代码讲解

  1. build_periodic_report_post_writeback_projection 在既有已记录 ACK 中投影 semantic_delta.obligation_id,仍从现有 Todo 来源和历史读取状态。没有重写接受规则或增加执行权限。
  2. derive_periodic_report_stage_completion 在无显式前沿时使用规范化义务身份;拒绝义务不匹配、未接受增量、错误 Agent、非后继结果或不成立的自有前沿。显式前沿收据保持原有身份。
  3. derive_periodic_report_stage_completion_from_runs 保留所选后继 Vision 的持久化 run,并要求原生接受 ACK 就在该 run 上,完整增量和来源 Agent 同时匹配。维护者发现旧检查只用 Agent 与秒级时间,会把同秒的另一 Vision 写入认作原写回;现在不再搜索时间相同的历史 ACK。真实 CLI 同秒三次写入具有不同持久化文件,未确认的编辑被拒绝,同一次接受及精确重放保留。

两个测试文件覆盖身份、错误增量、跨 Agent、同秒与下一秒未确认编辑,以及真实公开 CLI 的关闭/启用、原生接受、精确重放、侧车数量和待处理队列读回。协议文档解释原生身份与既有前沿兼容;迁移 RFC 的现有 T3 检查点明确已交付与剩余边界。

规格依据为 docs/reference/protocols/periodic-report-v0.md,固定修订 89505091fe52d318112aaaefb85f97e61cf11b33,不是本 PR 改写后的文本。其已有术语 bounded_segment_milestone 要求有证据的阶段闭合和持久化继续路径,本次已实现原生生产者;vision_successor_required 要求匹配的接受增量和后继 Vision,本次已实现。通用钩子权限边界沿用 docs/architecture/rfcs/provider-neutral-post-writeback-capability-hooks-v0.md。直接 Turn 接入和原始前沿恢复仍属于该 RFC 的后续边界。

对主干的风险

主要风险是把另一写回的接受凭据误认作本阶段完成。现在错误义务、不同接受增量、其他 Agent 和后来的未确认 Vision 都被拒绝;已有显式前沿测试继续通过。关闭功能仍走原有主写回路径,不产生意图或侧车;安装、凭据可读和 CLI 可用本身不会启用报告。生成与外部发布授权始终为 false,普通 Todo 完成仍不能直接证明阶段闭合。

当前精确 head 的 164 项阶段、钩子、原生 CLI、待处理消费、运行时生产者与触发检查通过。独立审查重跑 30 项阶段和原生 CLI 检查;wheel 与 sdist 各通过 4 项公开 CLI 检查,安装源码哈希一致。相同 CLI fixture 在旧 head 为 3 通过、1 失败,失败正是同秒未确认 Vision 获得 validated 阶段;修复 head 四项通过。此前 File/SQLite 消费边界验收保持原有证据,不把它当成本次新增历史来源资格;Ruff、diff 和完整语义词表检查通过。初始安装测试因未显式绑定测试工作区失败,补齐工作区参数后真实安装路径通过,没有放宽产品校验。未验证真实发布、Lark、完整前端报告流程或真实 host/model;本次没有这些入口改动。

语义与 CI 对齐

复用既有接受义务词汇和 owner,没有新共享词表。最终 premerge 的 5 项直接检查、5/6 项目录检查和 8/8 项风险检查通过;剩余失败是 Dashboard 输出预算。同一 canary 在固定 main 与本 head 均报 22,728 字符,超过未改动的 22,500 上限,失败身份和数值相同;本 PR 没有改变该因果路径。未提高预算或隐藏失败。旧 head 的 Windows 运行时 locator 在请求派发前报 PermissionError,与本 PR 文件边界不同;最新 main 有相关 metadata 修复,本 PR 未混入它,也没有声称 Windows 已合格。新 head 远程 CI 与维护者重新评审仍待完成,合并就绪须另行判断。

现有 Goal 全局 64 条历史窗口可能在大量其他运行后丢失闭合 Vision;这在改动前已经存在,不宣称本次修复了繁忙 Goal 的完整历史连续性。直接 Turn 绕过和后续 Todo 变更后的旧前沿重建同样保留为现有交付缺口。

我的整体评价

这是 justified_increment:已有公开写回和待处理队列获得可用结果,原生场景在 main 上为一项通过、一项失败,在修复与两种安装包上均通过。long_horizon 在已验证的重复/重放边界 improved;user_experience 在已有 CLI 队列发现路径 improved,没有新增确认或输入步骤。
生产改动留在两个现有模块,没有新框架。相关收紧已经应用到凭据与 Vision 关联处,显式身份兼容有真实旧收据契约支持。维护者的同秒反例与独立审查反例均已修复,没有本次证据审查的阻塞项;作者的整体结论 APPROVE 不代替维护者撤销其修改请求,现有预算失败和尚未完成的远程 CI 保持独立合并限制,运行时变更由维护者合并。

English verdict: APPROVE 5601496. Native successor ACKs now occupy the selected Vision's durable run; separate same-second edits cannot borrow acceptance. The identical prior-head fixture fails this counterexample (3 passed/1 failed); this head passes 164 regressions, an independent 30-case recheck, and four CLI cases each in wheel/sdist. Unchanged Dashboard budget and old-head Windows locator failure remain disclosed; new CI and maintainer re-review are pending. Direct Turn/source/frontend qualification remains outside this producer slice.

@hhyykk hhyykk left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=ultra

Request changes conclusion (author-owned PR; GitHub blocks formal self-review)

Exact head: 5601496

P1 — 后来的普通写回会取得旧后继阶段的首个报告意图。复现组合为本 head 与 #5939 的 713b7fe,基于 main 5cb9e4b;这是组合证据,不声称本 PR 单独的原生正例失败。

动机

本 PR 修复已接受原生后继 Vision 未进入周期报告队列的问题。已有 TypeScript 接受凭据提供义务身份,不应再要求监控专用前沿字段。本次复核发现另一个来源缺口:关闭报告时接受后继,稍后启用报告并完成普通 Todo,会给较早阶段产生新的里程碑意图。报告应属于建立该后继的写回,后来的普通进展不应首次补造它。

已验证本次接受后继写回可产生一个有界待处理意图;当前来源归属仍有阻塞缺陷。这项变更不授权生成或外部发布,也不完成整个 TypeScript 迁移。

改动思路

原实现复用接受增量、阶段收据和现有报告钩子,新增的同 run 检查能拒绝同秒未确认 Vision 借用 ACK。然而它只证明所选历史 Vision 和 ACK 相互一致,没有证明这个 run 就是当前钩子的来源。需要在既有报告投影与阶段归约边界绑定确切持久化来源,保留原始来源重放;不新增通用决策 owner、状态或权限。

具体改动

build_periodic_report_post_writeback_projection 投影原生义务 ID,但会扫描保留历史找到较早的接受 ACK。derive_periodic_report_stage_completion 复用规范化义务身份,保留显式前沿收据兼容,并检查 Agent、接受结果与自有前沿。derive_periodic_report_stage_completion_from_runs 把所选后继 Vision 和 ACK 绑定到同一个历史 run,却跳过没有 Vision 的当前普通写回。因此旧阶段仍能归属当前来源。这是 P1 的具体路径。

两个测试文件覆盖既有阶段归约、错误身份/Agent/增量、同秒未确认编辑及真实 CLI 启用、重放和队列读回;协议和 RFC 文档说明原生身份及 T3 边界。它们的现有正例仍有价值。组合后另跑 test_periodic_report_native_successor.py 与 test_periodic_report_turn_writeback.py,结果 14 通过、3 失败:File/SQLite 的普通完成 Turn 刷新应为零意图却得到一条;终端派发前中断场景已存在待处理意图,来源同样是此前刷新,并非终端钩子。

正向完整调用仍通过:公开 generic-cli Turn 返回合法 material_replan、持久化 ACTIVE Vision 与接受 ACK,本次来源产生一个 bounded_segment_milestone;后续 Todo/未确认 Vision 变化后精确重试仍保留一个 host、刷新和 spend。新的八场景在组合源码、wheel、sdist 各通过八项,包括侧车提交后丢失响应。这些正例没有覆盖旧阶段被另一普通写回取得的负例,不能抵消三个失败。

规格依据仍为固定修订 89505091fe52d318112aaaefb85f97e61cf11b33 的 docs/reference/protocols/periodic-report-v0.md:bounded_segment_milestone 与 vision_successor_required 约束有证据的阶段闭合和接受继续路径,不能用本 PR 更新后的说明替代原规格。

对主干的风险

错误意图仍没有生成或外部发布权限,主交易也没有重复执行;风险是报告阶段和证据归属错误。必须保持原有零意图断言,不能因新生产者上线就改成一条。修复只约束后继阶段来源:当前仍为 CLOSED Vision 的合法终端关闭可以由后续 Todo 完成建立,不能被误拦。显式旧收据身份兼容、关闭功能无可选副作用、后来未确认 Vision 拒绝及原始来源恢复都须保留。

当前 head 原有 164 项源码回归、独立 30 项、wheel/sdist 各四项原生 CLI 检查的证据仍有效,限定在原有测试范围;新增组合检查明确为 3 失败/14 通过。新八项回归已独立复核并验证两种真实安装包,但尚未提交。既有 Dashboard 预算失败及远程 CI/维护者评审仍是单独合并限制。没有验证真实模型工作、完整 PostgreSQL Turn、前端/Lark 报告旅程或外部发布。

我的整体评价

REQUEST_CHANGES。原生里程碑修复有可观察收益,但来源归属仍有阻塞缺陷。最小修复是让后继阶段所选的持久化 Vision/ACK run 与当前钩子来源精确一致,使用身份或追加位置而非秒级时间;原始来源重放仍可读取该 run。保持三个负例,并覆盖启用后继自身写回、后来普通同秒写回、原始来源失败后恢复和合法 CLOSED 终端路径。修复在现有 #5935 内推进,组合回归提案暂缓。运行时合并由维护者决定。

English verdict: REQUEST_CHANGES 5601496. P1: composing this head with #5939713b7fe on main@5cb9e4 exposes an older accepted successor being minted as a milestone of a later ordinary Turn refresh. The selected Vision and ACK share a historical run, but it is not bound to the current hook source. Neighboring real File/SQLite tests are 14 passed/3 failed; keep their negative assertions. Bind successor-stage derivation to its exact source refresh, preserving original-source replay and current-CLOSED terminal closeout. Eight positive Turn cases pass in source/wheel/sdist, but do not close this negative-path gap. Existing runtime CI and maintainer merge holds remain.

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent | gpt-6.1-sol | OpenAI | runtime_reported | reasoning_effort=xhigh

English verdict: REQUEST_CHANGES — exact head 5601496f097f7e5cb5db41ef6b858d88e183adb6 fixes same-second ACK borrowing, but a later ordinary refresh can first mint a milestone from an old accepted successor. Independently reproduced on this head alone, without #5939. No CI was queried or awaited.

动机

启用周期报告、验收阶段后继续工作的操作者。
原生续任原先漏掉阶段报告;本 PR 补上正常续任,但后来启用报告后的普通进展会借用旧阶段验收。
正常续任与同秒未验收编辑拒绝已通过;合法新 Turn 的普通进展却生成一个来自旧阶段的新 intent。
本 PR 不授权报告生成、外部发送、Todo/Goal 完成或额外 quota;真实模型和完整 frontend/Lark 采用未验。
当前来源关联需在本 PR 修复;历史 64-run 窗口、直接 Turn hook 采用及完整报告交互仍留在原 RFC。

阶段完成报告应该帮助用户判断最近取得了什么结果。补上真实续任的漏报有正向价值;把早先完成的阶段归到无关的新进展,会让长期报告与当前行动不符,并给后续消费队列增加错误工作。这里只实测有界意图与持久化来源,没有将它等同于发送、收费或长期模型净收益。

改动思路

修复留在 periodic_report 派生读模型,复用 typed accepted replan 与 obligation normalizer;不新增 Stage 权威或调度器。当前有界生产者的来源关联必须修好,原 RFC 的完整采用边界不由本 PR 关闭。
CLI 的 refresh-state 先提交原生写回,optional hook 再从私有历史派生阶段证据;Core 继续校验 hook 的来源和 sidecar,后续受管执行才拥有报告生成与外部效果权限。普通完成与阶段验收不能互相替代。

当前新增的 obligation fallback 复用已有接受决定,解决可选 frontier_identity 缺失;同一个持久化 run 的匹配也比秒级时间匹配正确。但“Vision 与 ACK 同属一个旧 run”仍不等于“它们属于现在这次 hook 的来源”。只检查更精确的旧记录,无法阻止新普通写回借用它。未来收敛应在现有来源边界完成稳定身份匹配,保留原来源的失败恢复,避免再建生命周期框架。

具体改动

完整 base 89505091fe52d318112aaaefb85f97e61cf11b33 → head 为 6 文件、+323/-3:两个生产模块、两个阶段/真实 CLI 测试及两份协议/RFC 文档。spec_ref: docs/reference/protocols/periodic-report-v0.md;spec_revision: 89505091fe52d318112aaaefb85f97e61cf11b33,在读 diff 前读取其已接受条款,未用本 PR 修改后的文档自证。

  • Trigger decision:正常 accepted successor implemented;来源关联 not_met。既有条款说 ordinary Todo completion 等普通进展不能证明阶段完成;合法新 Turn 的普通 refresh 却首次产生旧阶段 intent,需要当前来源匹配。
  • Post-writeback hook boundary:primary commit、enabled-only、独立 sidecar 和外部权限隔离 implemented;本次 source 与旧历史 stage 的归属仍 not_met。来源修复必须允许旧来源 exact replay 恢复失败 hook。
  • Ownership boundary:implemented,已有 Core lifecycle、capability proposal 和后续 effect owner 保持分离;未引入另一套 Stage/Goal 接受权威。

关键代码讲解

  • build_periodic_report_post_writeback_projection(post_writeback_hook.py:181)读取当前 Todo/frontier 与最多 64 条历史,:232–280 寻找历史 settled ACK,并把规范化 obligation_id 传入 reducer。它没有将选中历史 run 的身份与当前 payload 的持久化来源匹配。
  • derive_periodic_report_stage_completion_from_runs(stage_completion.py:202)从历史寻找 successor/closed Vision。:249–267 验证 ACK 和 Vision 同 run,修好同秒不同编辑的漏洞;没有 Vision 的新普通 run 被跳过,旧 accepted successor 仍可返回 validated receipt。
  • periodic_report_post_writeback_hook(post_writeback_hook.py:313)把阶段证据放进 bounded intent,并使用当前 hook event 的 source_receipt_id;于是旧阶段的证明可以第一次挂到新的普通来源上。

对主干的风险

[P2] 普通新写回首次生成旧阶段的里程碑

独立反例只使用当前 head 的真实 CLI 与隔离 File runtime:报告关闭时闭合阶段并 accepted successor;按原 Turn 合法 spend 结算;开启报告;再为新 Turn guard/bind 原 Todo,执行不带 Vision、不带 autonomous_replan_recorded 的普通 refresh。当前写回确实没有 agent_vision/ACK,hook 没有失败,却产生一个 validated successor_frontier_settled intent,source_receipt_id 指向本次普通写回。持续关闭的同一反例没有 sidecar/intent。

把选中的 successor Vision/ACK 持久化 run 绑定到本次 hook 的稳定来源身份;保留原来源重放与合法 terminal 路径。 不要以秒级时间或“当前历史里存在 accepted ACK”代替来源证明;也不要阻断 closed Vision 在后来真实 terminal Todo 完成时才满足的合法终结分支。

133 项仓库阶段、原生 CLI、pending 与 post-writeback/retry 测试通过;当前独立来源反例 1 通过 / 1 失败。相同外部 harness 在不可变 base 上来源两例均通过,在初始 PR head fdb1c0a 上同一晚启用反例失败;当前修复没有消除这个 PR 新增的问题。正常原生四例的 base 为 1 通过 / 3 失败,初始 head 为 3 通过 / 同秒拒绝 1 失败,当前四例全过,明确区分已修和仍失败的分支。

标准 premerge:5 个 direct 与 15 个 selected/executed 中仅 Dashboard 输出预算失败,其余通过。通过原 canary runner 对不可变 base 重测,同样 22,728/22,500;没有改阈值或把基线失败算成通过。初次测试命令指向两个不存在的文件,没有执行测试;纠正后取得上述仓库结果。初版普通反例缺少完整 source,hook 拒绝了投影,不能据空队列证明正确;最终反例使用完整新 Turn/Todo 来源,仍失败。

语义与 CI 对齐

复用既有 replan obligation 与阶段词汇,Python 只是现有 capability 读模型;没有 substring 分类或新 generic 义务。feature-off 通过真实 CLI 的无 sidecar/intent 路径;启用的 intent 仍 requested_write_scope=[],generation_authorized 与 external_delivery_authorized=false。代码、文档和断言没有降低外部效果门槛。Ruff、语义 advisory 与完整 canary 语义检查通过;模型采纳、真实 PostgreSQL/多进程长期调度、窗口外历史、完整 packaged frontend/Lark 与真实发送未测。没有 fetch/poll/wait CI。

我的整体评价

有用且比例适当的生产者增量,当前 REQUEST_CHANGES。长程效果和用户体验均存在具体 regression:新进展错误归属旧阶段,报告队列可能增加没有新验收结果的工作。修好的同秒分支是正向,不能覆盖来源反例。必要的 bounded future-facing pass 是在现有 source/read-model seam 统一稳定来源匹配,保留显式 frontier 兼容、原来源 replay、foreign-agent/delta 拒绝与 terminal 分支;未建议大范围迁移。完整报告采用和长期净效率不从这次测试或 PR 数量推断。

@hhyykk
hhyykk force-pushed the codex/periodic-report-native-successor-stage-20261008 branch from 5601496 to 1a34dcc Compare October 8, 2026 07:23

@hhyykk hhyykk left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=ultra

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Reviewed exact head: 1a34dcc36eebe2f6aa23b06398996e8affb24724.

动机

已启用周期报告的 Agent 在接受下一阶段 Vision 后,报告队列可能没有该里程碑。 Vision 是 Agent 当前阶段的目标;这里的里程碑要求有实际接受证据,并且下一阶段或结束状态已可靠写入。原生接受写入过去漏报,而较晚的普通刷新又可能补报旧阶段;本次让里程碑只属于原始接受写入,并能在随后编辑 Vision 后重试。 因此收益是使已完成阶段准确进入现有报告队列,避免用户遗漏进展或把后来的普通操作误当成阶段完成。

真实 refresh-state 和安装包能产生一个有界待处理意图;普通后来刷新不会借用旧 ACK,原始来源重试保持同一阶段。 本 PR 不授权生成或外部发布,也不完成整个报告或 TypeScript 迁移。 未提升的 legacy Todo 历史来源、完整当前 Vision terminal 校验及直接 Turn/canonical 来源恢复仍由 #5939 等既有边界承接。 这是对既有真实调用方的有界 producer 修复,不以待处理意图本身证明完整报告已生成或交付。

规范依据是变更前已接受的 docs/reference/protocols/periodic-report-v0.md,spec_revision 为 21707b7fb64123df02e730bf7959192010f85a1b。vision_successor_required 要求匹配接受的 semantic delta、持久化 successor Vision 和归属 frontier;原生 successor 分支在本 head 已实现。更广的 bounded_segment_milestone 包含完整当前 Vision、canonical 历史及 terminal 保证,仍按分阶段边界承接,不能因为本 PR 改写了说明而宣称全部关闭。

改动思路

复用已有持久化 run、ACK 和阶段归约器即可恢复调用方结果,不需要新的状态机、权限或通用决策源。 本批交付原生 successor producer 的准确来源与 Vision 历史重试;canonical Todo 历史、严格 terminal-current-Vision 和直接 Turn 恢复由 #5939 承接。 obligation-only fallback 虽然解决漏报,却不能防止另一次刷新借用旧 ACK。仅增加 source path 判断也不能恢复被后来的 Vision 编辑遮住的原始来源。两者共享同一阶段报告读取原因,合在既有两个模块中才形成可用、可审阅且可回滚的 producer 修复。

通用 replan 的接受决策仍属于既有 TypeScript owner。Python 的 periodic-report reader 使用该 owner 已接受的事实,生成能力内部的阶段投影;没有新状态机、persisted schema、CLI、provider、capability 或通用 Python 决策源。显式 monitor frontier 与已有原生 obligation_id 有不同来源,但都通过既有 normalizer 和完整 delta 校验,没有借名称扩大 actor 生命周期或权限。

历史顺序采用 index 的真实 append position,不能用秒级时间相等代替同一次写入。source prefix 只用于 successor;terminal 先读取当前 history,允许关闭阶段之后的 Todo 完成继续走既有关闭路径。完整 canonical Todo 历史与更严格的 current-Vision terminal 校验属于 #5939;本批不另造历史 snapshot 基础设施,也不把 legacy 当前 Todo reader 冒充历史事实。

具体改动

post_writeback_hook.py 的 build_periodic_report_post_writeback_projection 先尝试 current-history terminal;需要 successor 时,从现有 load_index_snapshot 读取 index,并要求 payload 的 json_path 恰好匹配一个来源。缺失、错误或重复匹配返回无 stage。通过匹配后,以该 append 行为上界构造至多 64 条 successor history,读取该行的 ACK、完整 delta 和 actor,交给既有 reducer。后来的普通 refresh 既没有自己的 accepted ACK,也不能靠复制 payload 中的旧 ACK 来获得旧 stage。

stage_completion.py 的 derive_periodic_report_stage_completion 为原生 ACK 使用已有 obligation_id,保留显式 frontier 的原持久化去重身份。derive_periodic_report_stage_completion_from_runs 保留 selected successor_run,比较完整 accepted delta 和 actor,再以 source_run_path 约束该 Vision 确实属于当前来源;不以 timestamp 重新搜索。新增 ACTIVE-over-CLOSED guard 防止当前仍在推进时结算旧 CLOSED。更广的较新非 material CLOSED/current-Vision 条件在 #5939 的强 guard 中验证,不声明为本 standalone 分支已全部完成。

test_periodic_report_native_successor.py 是五个真实 CLI 场景:enabled/off、较晚同秒普通 refresh、同秒与次秒未接受 Vision 编辑。测试先实际写入 CLOSED checkpoint、合法原生接受 ACK 和 ACTIVE Vision,再读取现有 pending consumer;检查意图只有一个、scope 为空、generation/external authority 均为 false。Vision-edit retry 在没有原始 sidecar 的情况下恢复原来源,避免把已有副作用当作证明。

test_periodic_report_stage_completion.py 覆盖 obligation/delta/actor 失配、selected-run 关联、显式身份兼容和 ACTIVE terminal 负向。test_post_writeback_capability_hooks.py 将临时 payload 改为真实 index/run artifact,并独立覆盖缺失、错误、歧义来源与当前 CLOSED 后的 Todo completion。protocol 明确 exact-source、append-prefix retry 和 legacy current Todo 限制;migration RFC 的既有 checkpoint 明确这一 producer 分阶段结果。七个文件 +532/-50,生产代码两个既有模块净增加 52 行,其他为必要的薄验证和协议说明,没有新的框架、模块或私有证据。

正向路径从真实 accepted refresh 写入开始,typed acceptance 保留,精确来源选择成功,stage reducer 返回稳定身份,现有 pending queue 发现一个有界 intent;后来 Vision 编辑后原来源仍可重试。负向路径在关闭报告时接受 successor,再开启报告并普通刷新;即使同一秒、甚至给临时 payload 填入旧 ACK,该来源也不能报告旧阶段。真正的 generation 和 delivery 仍须各自授权,observer 不回滚或重复 primary writeback。

对主干的风险

此前 source-attribution 阻塞评审针对 5601496f097f7e5cb5db41ef6b858d88e183adb6,组合 neighbor 检查是 14 pass / 3 fail:普通 Turn 的 refresh intent_count 实际为 1,预期 0。旧发现保留在公开讨论中。本次没有把三个预期改成 1,而是修复来源归属,最新主分支组合下 122 项 source 检查通过。此前原来源在后来的 Vision 编辑后不可重放,是旧实现已存在的 gap;本次 successor prefix 改善它,不能误称前一轮新引入的回归。

最终 standalone source 的 stage/native/hooks 合计 94 项通过。相同原生 CLI fixture 在最新 main 的 enabled 情况真实失败于 0!=1,off 情况通过;当前独立 wheel 和 sdist 各通过全部五个真实 CLI 场景,七个生产源码 hash 相同,加载 site-packages,未回退到源码 checkout。最新组合 wheel 和 sdist 各通过 26 项 native/terminal/direct Turn 场景,13 个生产源码 hash 匹配;其中八项直接 Turn 及中断、response-loss 恢复的持久覆盖在 draft #5951,依赖 #5935/#5939,不在本 branch 复制 runtime 改动。六项独立 edge review 通过;worker 更早的 108 项结果与新基线 94 项分别记录,不合并计数冒充一次运行。

Ruff、diff、advisory 和 full semantic 检查通过。premerge 五项 direct、catalog 5/6、risk 8/8 和公开边界通过;唯一失败仍是已有 Dashboard 字数预算。当前不可变 main 与 exact head 的同一独立工作负载均为 22,560,超过未变的 22,500,失败身份和差值相同;canary startup 上下文的 22,728 分开保留。没有调大预算或压缩义务,远程 CI 与该预算作为独立合并门槛保留。

默认仍关闭,package 存在、ACK 可读或 CLI 可用都不启用报告。actual enabled/off 配对证明关闭时没有报告 sidecar 或 intent,没有新增必填字段、scheduler/spend 或授权效果。协议的 accepted/recorded 和阶段检查是机器约束,报告则是可选 observer;不能把接受条件写成建议,也不能让 observer 决定 primary 是否结算。

剩余限制是 legacy Todo 没有历史 frontier、64-run source history 边界、完整严格 current-Vision terminal、全 PostgreSQL Turn、frontend/Lark 和 live provider/model adoption。canonical 历史与完整 current-Vision 检查已经有 #5939 owner,不新建平行任务;完整包装旅程不由这个原生 producer PR 冒充。全部测试使用隔离合成状态,没有活跃 Goal fault probe、benchmark/model 工作或外部发送;uv.lock、临时日志与私有材料均未进入提交。

我的整体评价

APPROVE 当前有界 producer 修复,没有本 head 新引入的阻塞发现。 原始漏报与后来来源冒用都有真实 caller 证据,修复局限在既有 accepted facts 的报告读取边界;原来源 retry、反方向拒绝、feature-off 和安装包均已验证。保留既有显式 frontier 的持久化去重身份;原生 ACK 复用已有 obligation_id,不添加版本解码器。

复用已有持久化 run、ACK 和阶段归约器即可恢复调用方结果,不需要新的状态机、权限或通用决策源。 本批交付原生 successor producer 的准确来源与 Vision 历史重试;canonical Todo 历史、严格 terminal-current-Vision 和直接 Turn 恢复由 #5939 承接。 对相邻边界的 future-facing pass 已落实为替换第二次历史 ACK 搜索和绑定 append source,未增加猜测性 framework。更广里程碑 acceptance 按上面具名 owner 继续承接,不宣称整个报告或迁移完成。公开的旧 head REQUEST_CHANGES 不被删除;当前新 head 的 earned approval、既有预算/CI 和 maintainer merge authority 分别记录,不自合并控制面。

English verdict: APPROVE the bounded native producer repair at 1a34dcc36eebe2f6aa23b06398996e8affb24724. Exact persisted-source binding prevents later refresh/ACK borrowing and an append prefix preserves original successor replay. Latest standalone source passes 94 checks; own wheel/sdist pass five real CLI cases each. Composed latest-main source passes 122 and packages pass 26 each. Legacy historical/current-terminal completeness stays with #5939; unchanged dashboard budget and remote CI remain merge holds. Maintainer merge only.

@hhyykk

hhyykk commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

Resolution mapping for prior review #5935 (review):

The whole-PR review at 1a34dcc36eebe2f6aa23b06398996e8affb24724 is published and read back: #5935 (review). The old-head source-attribution finding is repaired in the existing projection/reducer: a unique persisted source row must match the current payload; its own accepted ACK and selected Vision are required. An ordinary later source cannot select an older ACK. Successor history is bounded to that original source's append prefix, retaining original retry after later Vision edits; terminal still reads current history first.

Current standalone native source checks94 and fresh own wheel/sdist5 each pass. Latest-main composition with #5939 passes122, including the preserved3 ordinary/superseded-stage negative assertions; composed packages pass26 each. No assertions or authority gates were relaxed. The standalone later-ordinary CLI negative and same/next-clock original-source replay are durable tests in this head; canonical File/SQLite direct Turn recovery coverage is in dependent draft #5951.

The prior review remains retained and effective in GitHub until maintainer reconciliation; no dismissal or merge was performed. Legacy Todo history and stronger current-Vision terminal guarantees remain with #5939, with full PG Turn/frontend/Lark/live adoption unqualified. Unchanged dashboard budget and CI are separate merge holds.

@mergify

mergify Bot commented Oct 8, 2026

Copy link
Copy Markdown

This pull request has merge conflicts with main and cannot be merged
until they are resolved. Please rebase or merge the base branch, @hhyykk.

Choose the remote for the base repository, not an out-of-date fork.
For a fork clone, first inspect git remote -v; upstream must point
to https://github.com/loopx-project/loopx.git. If it is absent, add it
with git remote add upstream https://github.com/loopx-project/loopx.git.
Then run:

git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEAD

For a same-repository clone whose origin points to
https://github.com/loopx-project/loopx.git, use origin instead of
upstream for fetch/rebase. If you prefer merging the base, use
git merge <base-remote>/main and push normally.

Keep the DCO Signed-off-by trailer on every commit when you rebase.
https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/syncing-a-fork

@mergify mergify Bot added the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 8, 2026
loopx-agent
loopx-agent previously approved these changes Oct 8, 2026

@loopx-agent loopx-agent left a comment •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent | gpt-6.1-sol | OpenAI | runtime_reported | reasoning_effort=xhigh

English verdict: APPROVE — exact head 1a34dcc36eebe2f6aa23b06398996e8affb24724. No blocking finding in the bounded native report producer. The prior source-provenance counterexample now passes unchanged. Premerge is not all green: the dashboard budget fails identically at the immutable baseline. Native approval closeout is clear; current branch conflicts and the budget failure remain separate merge holds. No CI queried or awaited.

动机

启用周期报告、验收阶段后继续工作的操作者。
启用报告后,原生验收阶段并创建后继工作,旧版漏掉一次阶段报告意图;当前版产生一次有来源的意图,后来的普通进展不会首次借用旧验收。
同一次阶段验收应留下可追溯的报告意图,普通后续工作应继续推进而不制造一个没有新验收结果的旧阶段报告。这个问题在真实原生输入上存在,修复不是单纯补字段。
同一基线的原生续任正向场景漏掉意图;当前 178 项仓库检查和 2 项独立来源检查通过,后来普通写回不会借用旧阶段。
本 PR 不授权报告生成或外部发送,不完成 Todo/Goal,不新增 quota 或调度规则;真实模型和完整产品采用尚未核验。
完整报告生成、完整 packaged frontend/Lark 采用、长期历史窗口与真实模型净收益仍在原 RFC 边界;预合并 dashboard 大小预算在同一基线也失败,合并资格单独保留。

改动思路

复用 periodic_report 派生读模型、既有 obligation normalizer、持久化 run index 和 typed post-writeback supervisor;不新增 Stage 权威或改变核心验收规则。
入口是原生 refresh-state 的已提交写回。核心 TypeScript 已接受的重规划 ACK 仍决定验收,Python 报告读模型只识别来源和派生意图;订阅默认关闭,optional hook 失败不改主写回。正常路径从关闭的有效 checkpoint 走到同一 run 中的后继 Vision 和 ACK。负向路径把旧 Turn 结算后再开启报告并执行普通 refresh,当前来源没有自己的 ACK,读模型返回空。不能以时间戳相同或 payload 复制了旧 ACK 为来源证明。

具体改动

全量七文件 +532/-50:两个现有报告运行模块、三个 focused 测试和两份协议/RFC;没有新增核心 Stage 写权威。规范采用改动前 merge base 的 periodic-report-v0:Trigger decision、Post-writeback hook boundary、Ownership boundary 在本 producer 范围均 implemented。报告生成、投递和完整用户交互继续留在既有 RFC,不能把这个 producer 当完整交付。

关键代码讲解

  • build_periodic_report_post_writeback_projection(post_writeback_hook.py:181)先保留已有 terminal 路径,再对后继阶段要求 payload.json_path 对应恰好一条持久化 index 行;缺失、错误、歧义来源均不产生阶段。按 index 的追加位置截取来源可见历史,等时钟写入和原来源重放不再借用后来编辑。
  • derive_periodic_report_stage_completion_from_runs(stage_completion.py:202)保存选中的 successor run,并校验来源路径和同 run 中的完整 accepted delta/actor。既有显式 frontier 保持兼容,原生 obligation 使用已有 normalizer;它不自行宣布重规划被接受。
  • terminal 与后继来源的前置条件不同:合法 Todo 收尾仍可在现有关闭 Vision 下派生终态,不能为了来源修复强迫 terminal 也带 successor ACK。当前 focused terminal 和重放检查已通过。

对主干的风险

独立 source 检查180项通过(178仓库+2独立 oracle)。相同当前 native 夹具放到不可变基线运行:1失败3通过,失败是 enabled 正向路径漏掉意图;相同独立合法 Turn 的 later-enable/still-off 普通来源在当前均通过,上轮的 enabled 反例已消失。另有 missing/wrong/ambiguous 来源、外国 actor/delta、同秒和下一秒未验收编辑、原来源 retry、terminal 与 feature-off 回归。
Ruff、开发时 advisory 和 full semantic 检查通过;premerge 5 direct 通过、15 selected 中14通过。失败的 dashboard_status_json 大小在同一不可变基线/当前均22728>22500,保留失败及独立归因,未豁免预算也不宣称 ready。首次无效 module 调用在检查前失败,已改为正确 selected source CLI;不计入产品检查。完整 packaged frontend/Lark、真实 PG、模型及长期历史窗口未验;本次使用隔离 File fixtures,没有修改活跃 Goal。

我的整体评价

交付判断 justified_increment;当前 bounded producer 无 blocking finding,APPROVE。有界来源改善已实测:补上原生续任的漏报,并拒绝普通新来源借用旧阶段;没有执行模型或测量长期成本,不能据此承诺整体净收益。
长程效果和体验的正向证据是来源正确、漏报被补上、后续普通工作没有无谓旧阶段意图;整体净效率仍未测。bounded future-facing pass 已在原 index/source seam 实施,保留 explicit frontier 与 terminal 的不同语义,没有增加新框架。此 approval 不自动消除历史 REQUEST_CHANGES,也不授予 dismissal/merge 权限;完整报告采用和预合并失败仍分别处理。

hhyykk added 5 commits October 8, 2026 17:37
Signed-off-by: hyk <4408344+hhyykk@users.noreply.github.com>
Signed-off-by: hyk <4408344+hhyykk@users.noreply.github.com>
Signed-off-by: hyk <4408344+hhyykk@users.noreply.github.com>
Signed-off-by: hyk <4408344+hhyykk@users.noreply.github.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: hyk <4408344+hhyykk@users.noreply.github.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
@mergify mergify Bot removed the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 8, 2026
@huangruiteng
huangruiteng force-pushed the codex/periodic-report-native-successor-stage-20261008 branch from 990c697 to 8a05a79 Compare October 8, 2026 09:39

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review verdict: APPROVE (maintainer review of a contributor PR)

Reviewer: model_agent (self_reported); model=DeepSeek V4 Flash; provider=DeepSeek.

评审 #5935 fix(periodic-report): recognize native accepted Vision successors

Review exact head: 8a05a79fbea4365aac98a0c60abea29bc2d50271(maintainer rebase 后);合并基线 main:62acd670fc5c231f323176ebf28f228aee5bd334;作者原 head:1a34dcc36eebe2f6aa23b06398996e8affb24724。

规范依据(不可变修订): docs/reference/protocols/periodic-report-v0.md @ 62acd67 — bounded-segment-settlement 已实现;producer-dedup-identity 已实现;no-todo-trigger 已实现;goal-terminal-continuation 保留;legacy-historical-frontier 延后。

动机

Operators and Maintainers who read periodic reports: the goal owner who expects one milestone update when an accepted Vision successor becomes durable, and the agent that runs the enabled refresh-state post-writeback hook for that Goal. Before, a real accepted Vision-successor writeback that carries only semantic_delta.obligation_id without a monitor's optional frontier_identity produced no stage milestone at all, and a later ordinary refresh could instead report an older accepted boundary; after, the hook binds the successor milestone to the exact durable refresh that wrote the selected accepted Vision and its ACK, so the accepted boundary is reported once, from its own writeback, and a later equal-timestamp Vision edit cannot borrow it. The enabled hook emits successor_frontier_settled for a native accepted successor whose ACK carries only the obligation id, keeps the terminal path and the existing explicit frontier receipts working, refuses a copied or unacknowledged ACK even at the same timestamp, and deduplicates by the closed-vision revision plus the settled continuation identity. No new capability, decision owner, persisted schema, generation or external-delivery authority; no parent migration completion, no frontend/Lark adoption and no canonical historical frontier recovery are claimed here. Legacy unpromoted Todo state still has no historical frontier readback, so a retry after later Todo mutation remains dependent on current frontier facts, and the stronger current-Vision terminal guard for newer non-material CLOSED cases plus the durable Turn caller coverage stay with the separate owners (#5939 and the drafted #5951).

改动思路

复用既有 typed replan 事件与既有 periodic_report 阶段派生 owner,把「什么算作一次被接受的 Vision successor」从「必须有 monitor 的 frontier identity」放宽为「被接受的 obligation 身份」,同时把「哪一次 refresh 有权报告这个里程碑」收紧为「写下该 successor Vision 与其 ACK 的那个持久 run」。具体做法分两层:在阶段派生层(loopx/capabilities/periodic_report/stage_completion.py)用既有 normalize_todo_replan_obligation_id 归一化 obligation id,使 claim 侧与 ack 侧都以同一身份对齐,并新增 source_run_path 与 successor_run,要求被选中的 successor Vision 必须来自该 run,且当 ACK 没有显式 frontier 时其 semantic delta 必须与该 run 自己记录的 ACK 完全一致;在 hook 层(loopx/capabilities/periodic_report/post_writeback_hook.py)先按当前历史做终态派生,失败后再按 payload 的 json_path 定位 run-index 的追加前缀,只用那个前缀里该 run 自己的 ACK 去派生。这样终端完成仍然可以晚于 Todo 完成地结算,而 successor 里程碑必须在它自己的那次写回里被报告,后来的普通刷新或同秒 Vision 编辑都无法冒用。没有新增第二个判定源,也没有改动 frontier/终端语义。

语义与 CI 对齐

契约影响是既有 periodic-report 协议的一次收紧,不是新词汇:successor_frontier_settled、vision_successor_required、stage_identity 与 bounded_segment_milestone 都沿用既有取值,新增的只是「settled continuation identity 可以是 obligation id」这一条已写进协议的判定。Python 只做历史读取与派生,仍然没有平行的第二个决策 owner;语义 advisory 在改动的 2 个 Python 源上未发现新的词表载体。

关键代码讲解

  • derive_periodic_report_stage_completion(loopx/capabilities/periodic_report/stage_completion.py:91):obligation_id 与 ack_obligation_id 都经 normalize_todo_replan_obligation_id 归一;frontier_identity 现在可以回退到 obligation id,且当 obligation 带 id 时 ACK 的 id 必须相同,重复的跨 agent 或改写 ACK 继续失败关闭。
  • derive_periodic_report_stage_completion_from_runs(同文件:202):新增 successor_run 与 source_run_path 参数;终端分支保留 main 上更强的 current-Vision 守卫,successor 分支要求 successor_run.json_path == source_run_path,并在 ACK 无 frontier 时校验该 run 自己持久化的 ACK 与 semantic delta 一致。
  • build_periodic_report_post_writeback_projection(loopx/capabilities/periodic_report/post_writeback_hook.py:186):先用当前历史(或 committed source_runs)做一次无 ACK 的派生,覆盖终端结算;只有在它返回 None 时才按 payload json_path 唯一匹配 run-index,取该 refresh 的追加前缀与它自己的 ACK 再派生一次。
  • 同文件的 exact-source 分支(约 :277–:333):json_path 缺失、重复(同秒重复行)、agent 归属不符、ACK 未 recorded 或缺 vision_successor_required 时一律返回 {},不写 intent。

具体改动

Maintainer rebase 后 7 文件 +536/−54:post_writeback_hook.py 54/−33、stage_completion.py 33/−2、协议文档 16/−1、TS 迁移 RFC 6 行,以及 428 行测试(native successor 249、stage completion 102、post-writeback hooks 77/−18)。rebase 到最新 main(62acd670fc)无冲突重放;唯一需要人工判断的地方是 #5939 已经上线的 current_vision 终端守卫与 source_runs 注入路径:本 head 保留 #5939 的更强守卫和 committed-refresh 前缀语义,并按本 PR 的意图把「按历史扫描出一个可结算 ACK」去掉,改成必须绑定到写下该 Vision 的那次 refresh,因此同一个 successor 不会被后来的普通刷新抢先报告。所有 5 个提交带 DCO sign-off,作者身份保持不变。

对主干的风险

最危险的反例是「旧的成功边界被后来的写回冒用」或者「一次本该结算的 successor 因为缺 frontier identity 永远不结算」。当前实现两头都有正向与负向证据:正向覆盖原生 accepted successor(ACK 只带 obligation id)、显式 frontier receipt 兼容、终端在后续 Todo 完成后仍可结算;负向覆盖同秒后续刷新复制 ACK、未确认的 Vision 编辑借光、重复 index 行、跨 agent ACK 与他人 claim 的 frontier,全部失败关闭并且不产生 intent。第二类风险是 rebase 语义:main 的 #5939 与本地解法不同(前者会在历史里搜索一个可结算 ACK),如果保留它,payload 未指向具体 run 的旧路径仍会报告 successor;本 head 明确去掉了这条搜索,只用 exact-source 绑定,这既是本 PR 声明的边界,也是被 101 条相关用例固定下来的行为。协议文档同时更新了 dedup 身份与 exact-source retry 的说明,没有改写既有验收条目。

关于验证:本 head 的 Ruff(CI 口径 tests loopx/canary loopx/control_plane loopx/domain_packs loopx/presentation 与改动的 periodic_report 目录)、配置内 python -m mypy(19 sources)、git diff --check 全部通过;受影响的 6 个 periodic-report/post-writeback 套件 148 passed;其余 periodic-report 族 143 + 160 passed。仓库级 ruff check 在未改动的 loopx/capabilities/content_ops/cli.py:532(E731)上有一条与 main 完全相同的既有告警,且不在 CI 的 lint 口径内。

我的整体评价

这个切片值得合并:它把一个真实的产品缺口(原生 accepted Vision successor 缺 frontier identity 时不出里程碑)和一个真实的归属错误(后来的普通刷新抢先报告旧边界)同时修掉,做法是复用既有 typed obligation 身份并把报告权绑定到写下它的那次 refresh,没有新增 capability、schema 或第二个判定源。交付边界写得很清楚:历史 frontier 回读、更强的非 material CLOSED 守卫、Turn 侧调用覆盖与前端/Lark 采纳都留给既有 owner(#5939、#5951),本 PR 不宣称完成父迁移或报告生命周期。没有阻断项。

English verdict: APPROVE - head 8a05a79: a native accepted Vision successor is recognized through its obligation identity, its milestone is bound to the exact durable refresh that wrote the selected Vision and ACK, and later ordinary or same-second refreshes cannot borrow or displace it; 148 affected period-report/post-writeback tests plus 303 sibling period-report cases, the CI-scope Ruff check, the configured mypy run and the diff check pass at this head.

@huangruiteng
huangruiteng merged commit 271a3d9 into loopx-project:main Oct 8, 2026
4 of 5 checks passed
@huangruiteng

Copy link
Copy Markdown
Collaborator

Maintainer merge record (admin bypass, owner-authorized self-rebase + self-merge).

  • Exact head: 8a05a79fbea4365aac98a0c60abea29bc2d50271; merged as 271a3d98c601d86363159711b5672cdd6be2171d (base main 62acd670fc5c231f323176ebf28f228aee5bd334).
  • Changed surfaces: the periodic-report stage derivation and post-writeback hook (native obligation identity plus exact-source refresh binding), the protocol document, the migration RFC status note and the regressions. 7 files, +536/-54.
  • Rebase resolution: main's fix(periodic-report): recover hooks from original canonical writebacks #5939 read model (committed source_runs, read_report_source_history, the stronger current_vision terminal guard) is retained; the recent-history ACK search is removed so a successor milestone is only claimed by the exact refresh that wrote the selected Vision and ACK. Upstream terminal-guard tests and this branch's successor tests are both kept.
  • Checks run on this head: CI-scope ruff plus the changed periodic_report surface, the configured python -m mypy (19 sources), git diff --check, six affected period-report/post-writeback suites (148 passed), and sibling periodic-report suites (143 + 160 passed). loopx canary premerge --from-git-diff --goal-id loopx-meta passed with 0 failures after the root npm dev dependencies were linked into the worktree; change-quality receipt cqr_31f130d1195769f1db17 (status valid).
  • Failures/skips/holds: none for this slice. GitHub's ruleset still reported REVIEW_REQUIRED although the exact head carries a valid APPROVED review with zero unresolved threads, so the required checks were bypassed with admin rights.

Remaining boundary unchanged: canonical historical frontier recovery, the stronger non-material CLOSED guard, durable Turn caller coverage and frontend/Lark adoption stay with their separate owners.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants