Skip to content

fix(runtime): retry transient locator read denials - #5936

Merged
huangruiteng merged 2 commits into
loopx-project:mainfrom
mikamikasuki:codex/loopx-effect-runtime-windows-locator-retry
Oct 8, 2026
Merged

huangruiteng merged 2 commits into
loopx-project:mainfrom
mikamikasuki:codex/loopx-effect-runtime-windows-locator-retry

Conversation

@mikamikasuki

@mikamikasuki mikamikasuki commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Goal And Delivered Outcome

  • Outcome basis: Windows CI runs for the runtime lifecycle in #5927 and #5930 reported PermissionError while reading runtime locator files in _read_info. On the unpatched fix(status): skip settlement reads without matching run receipts #5952 base 060f023, Windows run 37753529459 failed this exact selector with PermissionError in _read_info while opening the runtime locator. An earlier Windows run on fix(runtime): retry transient locator read denials #5936 head 9f9ad34 passed the full integration module (183 passed, 6 skipped). This cross-run pattern is consistent with the retry addressing the transient denial, but it is not a controlled comparison and does not isolate the Windows trigger.
  • Goal/source and gap: _read_info treats the first access denial for a regular locator file as permanent. A brief denial can abort a runtime request even when the locator becomes readable moments later.
  • Observable before → after: On original baseline 8950509, a synthetic first-read denial raises EffectRuntimeHostPermissionError. The reader now retries up to three times at the existing 25 ms polling interval and succeeds when a later read works. Persistent denial still raises the typed host-permission error; a directory occupying the locator still follows managed startup diagnostic handling.
  • Issue/task and intended base: Self-contained fix; CONTRIBUTING.md#find-work permits a direct PR for a reproduced defect. Rebased and tested against canonical main at 271a3d9. Related boundaries: #5735 covers a directory occupying the locator; #5871 addresses a post-publication chmod failure. Neither covers a transient read denial.

Author Declaration

  • Written by: model_agent — OpenAI GPT-6 Luna.

Implemented against

  • Specification and revision: No separate issue or RFC is required for this self-contained runtime reliability fix. It preserves the locator behavior in loopx/control_plane/effect_runtime.py.
  • Criteria:
Criterion Disposition Symbol / path Test or command
A brief denial does not abort a read when the locator becomes readable within the bounded retry window implemented _read_info test_read_info_retries_transient_runtime_locator_permission_error
Persistent unreadable metadata retains the typed host-permission error; an occupied directory retains startup diagnostic handling implemented _read_info and runtime request path test_read_info_distinguishes_directory_from_unreadable_runtime_metadata; test_real_locator_denial_never_launches_or_dispatches_and_recovers
  • Self-check: Reviewed the locator reader and both error paths; the diff only changes bounded retry handling and focused regression coverage. The exact Windows OS trigger has not been isolated.

Scope And Continuation

  • Completed scope and remaining work: Bounded read-side recovery for transient runtime locator access denials; persistent denial and occupied-directory behavior remain intact.
  • Slice boundary / successor: Complete within this scope.

Validation

  • Tested revision: 11c6948 (base 271a3d9); original denial reproduction on 8950509.
  • Run state: focused validation is complete locally. DCO, dependency review, and Summary passed; PostgreSQL Integration is still in progress; Release Artifacts build failed in the packaged browser smoke while waiting for the synthetic Storage recovery proposal row. The failure's attribution is unconfirmed; fix(runtime): retry transient locator read denials #5936 changes only the runtime locator and its tests. The required merge-gate has not reported, and code-owner review is still required.
  • Input classes: synthetic.
Check kind Result Public-safe evidence / limitation
regression_parity passed A synthetic first-read denial reproduces the typed error before the fix; the retry regression passes on 11c6948.
unit passed tests/control_plane/test_effect_runtime_host_permission.py and tests/control_plane/test_effect_runtime_integration.py: 93 passed on 11c6948.
static passed Python compilation, Ruff on the three changed files, and git diff --check pass on 11c6948.
integration pending Fresh checks on 11c6948 remain in progress. On the previous head, Windows PowerShell run 37740790595 passed tests/control_plane/test_effect_runtime_integration.py (183 passed, 6 skipped).
CI failure attribution partly established On main revision 271a3d9, five of six selectors from an earlier Python shard failure reproduced as failing and one passed. Four failures in untouched cases also reproduced on 271a3d; the SQLite history case is addressed separately by #5952. The Linux TypeScript host_process_group failure from the earlier CI run passed once on macOS at main revision 271a3d; this cross-OS check does not isolate the Linux failure.
  • Coverage and gaps: Synthetic regression covers one transient denial. Existing tests cover persistent denial, directory handling, and avoiding process launch or dispatch after persistent denial. Windows CI has shown the transient symptom, but has not identified the OS-level trigger. Full fresh CI and code-owner review remain outstanding.

Frontend / Visual Evidence

  • UI impact: none
  • Before: N/A
  • After: N/A
  • States and viewports shown: N/A
  • Source data: none
  • Attention review: N/A

Type Of Change

  • Bug fix
  • New feature
  • Breaking change
  • Refactoring (no functional changes)
  • Documentation update
  • Test update

LoopX Area

  • Control plane (goals, todos, quota, scheduler, registry, runtime)
  • Benchmark boundary (adapters, runners, verifiers, scoring, evidence)
  • Capability or extension (providers, adapters, skills)
  • Public docs or presentation surface (README, protocols, dashboard)
  • Build, packaging, installer, or CI
  • Host or runtime integration

Technical Direction

  • Direction / acceptance reference, when applicable: N/A; this preserves the existing runtime locator contract.

Shared-authority RFC fixture impact

  • Production-scale fixture schema: N/A.
  • Semantic dimensions changed, or reviewed no-impact rationale: N/A; no authority schema or vocabulary changes.
  • Provider conformance arms run: N/A.
  • Read-only legacy/file/PostgreSQL three-arm rehearsal: N/A.

Boundary Checklist

  • No private state, credentials, raw traces, internal links, or local machine paths are included.
  • No maintainer-owned benchmark work was duplicated.
  • The change is scoped to runtime locator reads.
  • The visual evidence section is complete; UI impact is none.
  • Every commit includes a DCO Signed-off-by trailer.

@mikamikasuki

Copy link
Copy Markdown
Contributor Author

CI attribution update for run 37728072115: shards 1 and 2 failed. I reran 14 representative failing selectors on the exact PR base 82d1b83; all 14 also fail there, including the source-session loader allowlist, native-child settlement assertions, stopped-Goal assertions, exact Todo export, history artifact read, and opaque-reference message check. These failures are therefore pre-existing relative to this PR diff. The separate transient-locator regression and 118 focused runtime tests pass on the PR head. The overall run is not green: the dashboard job timed out/cancelled at 15m and other shards were cancelled after failures.

@mikamikasuki
mikamikasuki force-pushed the codex/loopx-effect-runtime-windows-locator-retry branch from d4a990c to 9f9ad34 Compare October 8, 2026 07:00
Signed-off-by: mika <211269698+mikamikasuki@users.noreply.github.com>
@mikamikasuki
mikamikasuki force-pushed the codex/loopx-effect-runtime-windows-locator-retry branch from 9f9ad34 to 11c6948 Compare October 8, 2026 10:15
@mikamikasuki

Copy link
Copy Markdown
Contributor Author

CI update for head 11c6948: DCO, dependency review, PostgreSQL Integration, and Summary passed. Release Artifacts build failed in the packaged browser smoke while waiting for the synthetic Storage recovery proposal row; attribution remains unconfirmed because this PR changes only the runtime locator and its tests. The Python Tests changes job is queued and the required merge-gate has not reported. A Windows PowerShell run on #5952 base 060f023 also failed the same _read_info locator-read selector (1 failed, 181 passed, 6 skipped), while an earlier Windows run on #5936 head 9f9ad34 passed the full module (183 passed, 6 skipped). These are cross-run corroboration, not a controlled comparison; the OS-level trigger remains unidentified. Code-owner review is still pending.

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent · gpt-6.1-sol · OpenAI · runtime_reported · reasoning_effort=xhigh

English verdict: APPROVE — 11c6948e137e7c745f16cb245b163724acdea6f1. No blocking finding. A bounded pre-dispatch file-read retry repairs a demonstrated discovery failure while preserving permanent-denial, locator identity and effect-replay boundaries. Independent real TCP fault replay and 93 focused tests pass. Windows OS locking was simulated on macOS; CI was not queried. This review grants no merge authorization.

动机

在本机调用 LoopX CLI 或 Python API、需要连接既有运行服务的用户。
读取连接信息文件时若第一次被操作系统短暂拒绝,旧代码立即报权限错误;新代码在最多三次、每次25毫秒的等待内重新读取,恢复后连接原服务,持续拒绝仍明确失败。
隔离的真实TCP服务验证了短暂拒绝后成功连接且只发送一次请求;持续拒绝与目录软链接仍被阻止,未启动替代服务或发送请求。
本PR不放宽权限、不改变写操作重试规则,也不承诺解决所有Windows文件锁或启动失败。

这消除了服务已就绪却因一次短暂文件锁而中断调用的具体故障。它完成的是连接恢复这一有界用户结果;不能由一次ping推出多日稳定性或所有平台问题已关闭。没有找到这项重读预算的独立已接受规范或关联issue,因此spec basis是no_spec;依据是已发布读入口的永久失败边界和独立重现的旧故障,不编造RFC验收编号。

改动思路

权限拒绝的有界重读属于现有宿主文件IO;效应和状态决策继续由既有TypeScript服务承担,不增加通用重试框架。
当前交付是连接信息读取恢复及原永久失败边界,CLI/API入口可用;没有新的开关、状态或评分/调度策略。

调用仍沿effect_runtime_request → _read_info → _request_with_info → 真实TCP TypeScript运行服务。重试只发生在读取连接文件、尚未发送请求时;把它移到RPC层会碰到写操作重复执行和模糊响应,不能直接复用那种重试。正常读取、文件不存在、JSON非法、身份不匹配、普通目录等路径沿用原语义。这个修复不需要新的设置、表单、说明书命令或用户重填已知信息。

具体改动

完整三文件diff为+55/-12,主生产变更21增/10删。审阅head 11c6948e137e7c745f16cb245b163724acdea6f1,不可变比较基线 271a3d98c601d86363159711b5672cdd6be2171d。检索了同一locator的全部startup/request/readiness调用和retry_safe分支,原reader是正确的唯一文件IO owner;没有第二套状态或效应决策。

  • loopx/control_plane/effect_runtime.py:465:只对PermissionError循环,最多4次读、3次25ms等待。真实非软链接目录仍返回None;目录软链接或重试耗尽仍抛EffectRuntimeHostPermissionError。成功读到内容后仍逐项验证schema、fingerprint、127.0.0.1、token、port与PID。
  • loopx/control_plane/effect_runtime.py:1012与:667:原RPC retry_safe和发送前/后错误归属保持。连接文件读失败不构成启动替代服务或重放写入的授权;非PermissionError的缺失/无效内容仍按既有发现路径处理。
  • tests/control_plane/test_effect_runtime_integration.py:94补第一读拒绝、第二读真实payload的回归;tests/control_plane/test_effect_runtime_host_permission.py:164把持续拒绝计数更新为4,并保留真实locator、零启动/零dispatch及恢复检查。已有发送后不确定、非retry-safe写和readiness错误测试继续通过。

对主干的风险

最大反例是把真权限失败误当“文件不存在”,导致另起服务或发送请求;另一个是把文件重读扩大为写请求重放。独立隔离probe使用真实托管TypeScript服务和TCP,只有Path.read_text注入失败,未mock响应或成功后置条件。同一服务下替换为基线的原reader,第一次拒绝得到1次读、typed denial、0 dispatch;当前reader第一次/第三次拒绝后分别2/4次读,返回与初始ping相同的ready=true、PID、fingerprint且各只dispatch一次。四次持续拒绝为typed denial、0 dispatch;目录软链接同样拒绝。这里仅重放了不可变历史reader,不声称跑过整个基线测试树。

独立本地验证:uv run --extra test python -m pytest -q tests/control_plane/test_effect_runtime_host_permission.py tests/control_plane/test_effect_runtime_integration.py为93 passed;Ruff、diff检查、公开边界smoke与changed-base语义advisory通过。uv run --extra test loopx --format json canary premerge --from-git-diff --git-diff-base 271a3d98c601d86363159711b5672cdd6be2171d通过5项直接检查和原生选中的维护性/全树语义及控制面smoke。没有查询、轮询或等待CI,也没有放宽测试预算、运行权限或失败条件。当前必需检查无未解决失败/skip;本机真实Windows共享锁触发未测,仍属验证局限。

先前reviewer probe错误地比较包含随机request_id的完整响应,v1失败被保留;最终probe改为检查真实ok/result及ready身份,并清理自己隔离的服务。原错用canary选项也保留为调用错误,采用实际支持的--git-diff-base完成检查。这些不是PR回归,也没有被算作通过。若持续拒绝,仍由现有宿主权限诊断及原修复路径恢复;该PR额外成本最多75ms,不形成无界重试或新持久状态。

关闭/权限语义:本改动没有optional或default-off声明,它明确改变现有默认读失败路径;没有skill/prompt安装、activation、quota/lease/Todo规则、新协议名或模型义务。通用错误保持领域中性,文件重读也不授予RPC效应权限。

我的整体评价

**APPROVE,goal_achieved / proportionate。**没有当前阻塞发现。long_horizon的改善在调用连续性:短暂读失败可以继续真实工作,永久失败及时有界停止;user_experience的改善是同一CLI/API不再为可恢复文件锁要求人工重入,失败诊断仍真实。证明范围是隔离入口和已有回归,未宣称多日实测或所有Windows锁已修复。

未来改动成本检查已做:考虑抽取通用重试helper,当前只有一个共享文件读取边界,单独抽象会淡化pre-dispatch权限含义而增加维护面,故无需追加框架。保持既有reader和typed异常是更小且可回滚的选择。生产变更通过精确head审阅后仍由维护者决定合并;本轮没有merge或dismiss旧review。

@huangruiteng
huangruiteng merged commit aa0c2ea into loopx-project:main Oct 8, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants