Repository navigation
fix(quota): return directly executable JSON settlement commands - #5667
Conversation
Signed-off-by: LoopX Agent <[email protected]>
Signed-off-by: LoopX Agent <[email protected]>
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent | gpt-6.1-sol | OpenAI | runtime_reported | xhigh
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
动机
执行已获准工作的 CLI、App heartbeat 和 visible Goal 调用方需要按返回的计划写回并结算。以前直接执行返回命令会收到人类文本,调用方为读取结果而在 spend-slot 后追加 JSON 参数又被拒绝;现在填好计划占位项即可得到可解析的 JSON。同一独立真实 CLI 驱动在三个宿主的不可变 base 上观察到非 JSON 输出,在本 head 上完成拒绝、写回、恢复及重放,三条路径各只扣费一次。本次只修复生成命令的格式位置,不改变直接 CLI 默认输出、历史回执、准入权限或 TypeScript 结算规则;模型效率及 worker 长程采用不在本次验收内。R5 的模型 token/IO 成本、决策质量及长期采用仍由现有实验 owner 验收。
无阻塞 finding;存在独立归因的原有验证失败及其合并 hold。
改动思路
复用原来的 TypeScript decision/settlement owner,Python 只处理既有命令、文件和领域 provider 传输。先比较不做、在原 owner 内修复、另建 dispatcher 三种方案;可复现的消费者问题支持在原边界修复,不能由测试数量或新 protocol 对象推导价值。Frontend/Lark 没有新操作;本次明确是可回滚的有界 correction 或研究 prerequisite,安装态用户旅程与整体模型效果尚未验收。
具体改动
精确 head 656cd168c9c8f6b9b843553b550e8725e1c88052,真实 merge base 3bb268d7c4ca35c972fb1bcaf19837ba3ffeacaa。5files +48/-16: production1(+3/-1),tests2(+23/-15),docs2(+22/-0); no generated/moved/private artifact.
规格依据 docs/reference/protocols/turn-envelope-v0.md,spec_revision 3bb268d7c4ca35c972fb1bcaf19837ba3ffeacaa,并按修改前 Accepted docs/architecture/rfcs/agent-loop-effect-interpreter-v0.md 的 R5/M7.4 归属核验;当前文档修改只用于披露,不反向证明原始要求。
- settlement-plan-preservation:implemented。3host full/envelope equality;129TS tests and24realCLI receipts
- same-turn-authority:implemented。Premature spend and invalid writeback rejected; owed recovery followed by original-command replay gives one debit per host
- default-view-and-budget:implemented。Identical fixture base/head command execution; hot-path budget unchanged/pass
- R5-bounded-adoption:deferred。Existing R5 research owner retains model economics and long-run worker adoption. No new experimental acceptance is claimed.
effect_program.py:128::build_turn_scoped_cli_settlement_plan 只在共享 prefix 后加入全局 --format json,位置仍在子命令之前;registry/runtime 路径及 actor/GoalRef/Turn 引用继续按原逻辑引用。Todo completion、refresh、quota spend、conditional terminal closeout 都使用同一个 prefix,不增加第二套决策源。
settlement.py:170::attach_settlement_progress 未修改;它仍从 typed receipt progress 派生当前 owed step,再调用同一个 renderer。真实 refresh 返回的 settlement_owed.command 也经过修复,调用方不用另补参数。无有效原始身份或未到 quota_spend 时不会凭空生成可花费命令。
两个测试文件更新旧前缀预期,并用 App/generic/visible Goal 三条真实路径直接执行命令,包括带空格的路由、无效写回、过早 spend、owed recovery 和原命令重放。两份文档明确说明这是生成命令的默认格式变更,同时保留直接调用/历史回执和 R5 研究边界。
对主干的风险
独立实际 CLI 对照有24份执行观察(9base+15head),没有调用方 JSON 参数修补。三个宿主均保留完整/短包同一 settlement plan;head 过早 spend、invalid writeback 被拒绝,正确写回后的恢复与重放各保持一个扣费。
84项 focused Python、129项 TS、Ruff、diff check、advisory 后全树 semantic smoke 和 hot-path budget 通过,预算未放宽。扩展 Python 为174通过、1失败,失败在 test_todoless_autonomous_replan_settles_quota_refresh_spend_chain:5282:新 Turn 的 decision 是 autonomous_replan_required,预期 skip。不可变 base 和head 单独再跑均8.8秒稳定复现相同末尾断言;检查到原测试、checkpoint/replan projection、receipt validation及readback的blob一致,而且测试本身每次调用明确设置全局JSON。失败发生于已成功结算和scheduler ACK重放后的新轮资格,不经过变更的命令文本消费。故归因为 unchanged pre-existing failure,不能称为本PR修复、间歇已消除或所有检查绿。
当前 strict change-quality 已保存 exact scope receipt cqr_a84072ea87b43abb380b,但 required red 检查使 receipt invalid,合并应继续hold。APPROVE与这个合并阻塞分别记录,不绕过CQ。未执行全仓库测试、真实模型或长期实验;这些不作为当前命令修复的通过证据。CI按配置没有查询、轮询或等待。
typed vocabulary 复用原 owner,没有 substring denylist、并行 Python 状态决策或新核心领域化义务。projection/缓存不授予权限,scheduler ACK 仍是 host 边界。兼容窗口保留现有 direct/full/historical readers;公开命令和 private capture 的差异分别判断,不用更严拒绝或相同 reason code 替代真实恢复证据。
我的整体评价
APPROVE。问题贡献为 justified_increment;原身份重放和有效恢复保持 sustained-work 路径,CLI transport 减少手工修补。observable_semantics=intentional_change_validated,default_off_isolation=not_applicable。没有当前PR阻塞;既有required red检查的strict CQ合并hold未清除,不以批准掩盖。
有界 future-facing pass 已执行:保留共享 renderer/capture/selection owner,拒绝另加通用 executor。这一小修无需更多抽象。 本角色未做 tracked 源码变更。COMMENTED 结论是共享作者账户的 GitHub fallback,不是 formal APPROVED 或合并授权;合并另由精确版本、当前原生 gates 和真实维护者授权决定。
English verdict: APPROVE - exact head 656cd16; shared settlement commands now execute as JSON without caller format surgery, with three-host real CLI recovery/replay and84focusedPython/129TS evidence. An independently unchanged fresh-replan red check still holds strict merge qualification.
Generated settlement commands previously omitted the global JSON output option. A caller executing the returned command received human-readable output; adding
--format jsonafterquota spend-slotwas rejected. The existing shared renderer now places the global option before every settlement subcommand, including the writeback recovery command.The observable contract is that callers can fill the declared placeholders and execute the returned command without format surgery. This applies to App heartbeat, generic CLI, visible Goal, full decisions and TurnEnvelope. Direct CLI output defaults, stored receipts, identity checks and one-spend semantics remain unchanged. Python owns command rendering only; the existing typed settlement owner retains decision authority. No new capability, vocabulary, frontend operation or Lark operation is introduced.
Validation:
This closes a command-rendering defect within the effect-interpreter R5 boundary. It does not establish model-efficiency gains or qualify worker adoption; live experiments and installed runtimes are unchanged. Existing authoring help improvements are tracked separately in #5653.
Future-facing pass: reuse the common renderer across all callers rather than add caller-specific repairs. No further abstraction is needed for this bounded correction. Public/private scan is clean. Maintainer review and merge remain required for this control-plane change.