Skip to content

fix(status): preserve canonical peer work facts over audit rows - #5668

Merged
loopx-agent merged 2 commits into
mainfrom
codex/peer-directory-canonical-status
Oct 6, 2026
Merged

loopx-agent merged 2 commits into
mainfrom
codex/peer-directory-canonical-status

Conversation

@loopx-agent

@loopx-agent loopx-agent commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Goal And Delivered Outcome

After a canonical Todo is blocked, deferred, completed or has its claim cleared, peer status could still show stale runnable work or restore an old claimant. Historical audit events overwrote current state, and short titles/ordinals let stale aliases survive deduplication.

Current source facts now win. The existing read adapters reconcile Goal/Todo identity before claimant assignment, preserve explicit status over a compatibility checkbox, and retain historical events as audit metadata. Management and execution-facts consumers share the same reconciliation. No dispatcher, writable state, protocol, capability or provider is added.

Author Declaration

  • Written by: model_agent — OpenAI GPT-6 / Codex.
  • Original implementation reference: docs/reference/protocols/agent-management-projection-v0.md and docs/reference/protocols/peer-agent-directory-and-observation-v0.md at 3bb268d7c4ca35c972fb1bcaf19837ba3ffeacaa.
  • Current review also checked those accepted contracts at base 7b12259f29aa87cbeb3e31e82d4185aa9b5a50fd.
Criterion Disposition Owning path Current evidence
Current state outranks historical audit implemented loopx/control_plane/todos/todo_index.py Historical-event regressions and actual File/SQLite CLI
Stable Goal/Todo identity before claimant assignment implemented loopx/control_plane/agents/management_projection.py Stale aliases, cleared claim, explicit deferred/done
Read-only directory preserves claim and lease authority implemented Existing canonical owners unchanged Independent Todo/provider revision readback; active/released lease
Missing source does not revive historical work implemented Existing unavailable-source owner plus projection filter Actual provider loss, truthful refusal and restored readback

Scope And Continuation

This is a bounded repair to the shipped Python status adapters. Canonical TypeScript lifecycle, admission and provider transactions are untouched. Four files: 230 additions/24 deletions; production 51 additions/24 deletions, tests 179 additions in existing suites.

Installed Bot/runtime upgrades, live GUI/Host adoption and the broader collaboration roadmap are separate acceptance work. No PostgreSQL transaction, paid-model or long-running qualification is claimed.

Validation

  • Current tested head: ed2ccf8e79c2c7a548a2a8b9af2538f21e702686
  • Immutable comparison base: 7b12259f29aa87cbeb3e31e82d4185aa9b5a50fd
  • Run state: finished; inputs: synthetic, public fixtures.
Check Current result Evidence and limitations
Focused regression / real backend passed 34 cases in test_peer_agent_directory.py and test_retired_todo_event_source.py; actual File/SQLite CLI creation, block/defer/complete, active/released leases, source unavailable/restored, unchanged read-only provider revision and Todo contents
Regression sensitivity passed Identical head test files on base: 11 expected failures and 23 passes, including nine state/identity negatives and both real File/SQLite blocked-state regressions
Adjacent regression passed 100 tests across agent lifecycle, canonical lease lifecycle, task lease and native lease CLI
Independent real CLI parity passed Six inputs at base/head: ordinary and short-title rows, 245 unrelated rows beyond the 240-item index cap, reversed order, terminal done, missing/restored source; status --limit 1/999; other-Goal caller refused; future peer refused before registration and visible without claim after explicit registration
Static / public boundary passed Ruff, diff hygiene, changed Python compilation and four-file public-boundary scan
Semantic alignment passed Full vocabulary smoke on base and head after installing declared npm dependencies; existing analyzer limitations retained
Native premerge passed Complete exact-head rerun: 5 direct checks and all 18 selected checks pass; zero failures, warnings or manual holds
DCO policy passed Contribution has sign-off. Exact two-parent integration commit satisfies the repository's verified GitHub-generated merge exception: SHA, parents, web-flow, GitHub committer and valid signature checked
Change-quality receipt not required by current review Goal Current native gate reports policy disabled; no new receipt is claimed, and the author's old failed receipt is retained as historical evidence
Remote CI not consulted Managed review policy is wait_for_ci=false; no fetch, polling or waiting
Installed package / live Bot / UI / Host / PostgreSQL / soak not run Outside this source read-model repair; no adoption claim

The author's earlier efe31aa premerge failed the old peer-migration prose assertion and held its quality receipt. Those historical results are not relabeled. The current main-integrated head passes the complete native gate. This review's first premerge failed because the clean worktree lacked the declared TypeScript npm dependency; the same failure was reproduced on base. npm ci --ignore-scripts repaired the environment, then both semantic scans and the complete head premerge passed without changing production code, assertions or limits.

Frontend / Visual Evidence

Existing dashboard and CLI consumers receive the corrected state fields. No layout, interaction, configuration editor or viewport implementation changed. Live GUI adoption was not tested in this review.

Type of Change

  • Bug fix
  • Test update

LoopX Area

  • Control plane (goals, todos, quota, scheduler, registry, runtime)

Technical Direction

R1 correctness, S2 shared source and S5 management visibility. This independently verifiable repair does not close the full roadmap or Bot Goal.

@huangruiteng
huangruiteng marked this pull request as ready for review October 6, 2026 04:36
@huangruiteng
huangruiteng self-requested a review as a code owner October 6, 2026 04:36

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; effort=xhigh

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

动机

查看同一 Goal 内协作任务的操作者与 peer Agent。 任务已阻塞、延后或完成后,旧审计记录及短标题别名可能仍显示它可执行,甚至恢复已清除的归属;新版本以当前权威任务状态和身份显示同一项工作。 已验证状态、归属、真实租约和源丢失恢复的读回保持一致,历史操作仍可作为审计信息查看。 本 PR 不派发或重新分配任务,不修改租约权限,也不宣称真实宿主执行或生产 UI 采用已经验收。 真实安装与 UI/Host 采用、整个协作路线的业务验收,以及旧质量回执的重新资格化仍未完成。

改动思路

当前权威任务是 Todo 存储中的状态和归属;审计记录只说明过去发生过什么。修复复用原有状态采集和目录投影,让当前完整任务行先于短标题、序号和 Next Action 别名参与同一身份的合并。它同时服务管理界面和 execution-facts 读取,避免两处各自推断。仅阻止一项审计字段覆盖仍会留下延后状态和别名问题;新增调度器或另一套状态存储没有必要。TypeScript 生命周期与事务 owner 未修改,Python 留在现有读模型适配边界。

具体改动

Head: ed2ccf8e79c2c7a548a2a8b9af2538f21e702686;base: 7b12259f29aa87cbeb3e31e82d4185aa9b5a50fd。完整四文件 230 增/24 删,其中生产 51 增/24 删,其余 179 行是现有测试文件的反例与真实生命周期检查。

关键代码讲解

  • management_projection.py:83 的 _is_done 复用明确状态,仅在缺少状态时保留旧 checkbox 推断;延后任务的已勾选展示不再被误认为完成。
  • management_projection.py:318 的 _iter_status_todos 收集当前候选与提示,按 Goal/Todo 身份先去重再归属;源不可用时排除该 Goal。selected_by 只作为提示补充,不恢复旧 claimant。projected_agent_goals 与管理投影共享它,后者删掉重复去重。
  • management_projection.py:392 的 _todo_identity 对已有 Todo ID 忽略展示文本和序号;只有缺少 ID 的兼容行保留旧键。
  • todo_index.py:148 的 build_todo_index 保留事件计数、时间、摘要与事件状态,仅 event-only 审计行接受事件推导状态/actor;当前源行的状态和归属不被改写。

规范 docs/reference/protocols/agent-management-projection-v0.md,接受基线 7b12259f29aa87cbeb3e31e82d4185aa9b5a50fd;同时读取同版本 docs/reference/protocols/peer-agent-directory-and-observation-v0.md。Sources Of Truth:当前事实优先,真实状态变化后重新读回,implemented。Todo Row:Goal 内 Todo ID 唯一与显式状态优先,implemented。Acceptance Checks:只读、不派发、不接管租约及来源缺失不复活旧工作,implemented。更大的真实协作与生产采用不属于这项读模型修复的已完成验收。

对主干的风险

没有发现阻塞代码项。最强反例是旧 open 别名在当前任务已经延后、完成或清除归属后恢复可执行工作;另一方向是正常延后工作被过严规则隐藏。34 项聚焦测试通过,包含真实 File/SQLite CLI 的 open、blocked、deferred、done、active/released lease、权威源失效与恢复,以及读取前后相同 provider revision/任务内容。相同九个新增反例在不可变基线生产模块上全部失败。独立八项输入在新版本全通过,基线七失败一通过,覆盖无附加标记、展示顺序、270 项无关工作、终态别名、源缺失/恢复和 event-only 历史行。真实 CLI 基线对照也保存了失败结果,不以 helper 测试替代 backend。

33 项相邻回归、Ruff、diff-check、管理契约、peer 迁移和 dashboard 状态解析/合并契约 smoke 通过。私有探针最初用了不合法的 Todo ID,五项失败;只修正 fixture 身份后八项通过,没有改变产品规则。语义脚本最初误用 pytest,没有收集测试;正确直接运行已通过。作者旧 head 的 premerge/quality 失败没有改写为通过,本次没有重跑整个 native premerge 或签发新质量回执。CI 未查询、轮询或等待;未测新的安装包、live GUI/Host、Windows、PostgreSQL 和长期运行。

语义与 CI 对齐

复用已有 Todo 状态和投影词汇,没有增加协议或平行生命周期 owner。开发期 advisory 未发现支持范围内新载体;这不覆盖动态与无名值。随后完整语义 vocabulary smoke 通过,并保留其未证明领域的限制。此处是明确披露的默认读回修正,没有 opt-in/default-off 机制或新增 machine obligation。

合并条件单独保留:当前 merge commit ed2ccf8e79c2c7a548a2a8b9af2538f21e702686 缺少 DCO sign-off trailer,需由维护者按仓库要求补齐;若因此改变 head,必须重新绑定该版本。旧质量 hold 与 live adoption 也没有自动关闭。以上代码 APPROVE 不代表平台总状态 APPROVED 或拥有 merge/bypass 授权。

我的整体评价

APPROVE;delivery judgment 为 justified_increment,long_horizon improved,user_experience improved。重复状态读取不再恢复历史工作,操作者无需额外确认或重填已知信息。完整 diff 是同一个可验证、可回滚的读模型修复;本次未来改动检查认为共享身份去重已经完成必要简化,保留缺少 ID/状态的旧读取兼容有真实消费者,不需要另建通用框架或展开语言迁移。没有修改持久状态,回滚仅恢复原适配逻辑。保留生产采用与质量门禁的边界,控制面 PR 交维护者合并。

English verdict: APPROVE - ed2ccf8; current authoritative Todo state and identity outrank stale audit/hints. Full-diff review, real File/SQLite lifecycle and source recovery, independent negatives and immutable-base counterfactuals passed at this head. DCO sign-off, old quality closeout and live adoption remain separate merge/delivery holds; CI was not consulted.

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; GPT-6; OpenAI; self_reported

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

动机

查看协作任务状态的管家、peer Agent 和操作者。 任务已经阻塞、延后、完成或撤销领取后,旧审计事件和短标题别名仍可能把它显示成可执行,迫使操作者重复核对;修复后同一任务以当前状态和领取记录显示。 真实 File/SQLite CLI 验证了当前状态、领取和租约读回,权威数据源丢失时不会复活旧工作,恢复后可继续读取;历史事件仍可查看。 本 PR 只修正现有读模型,不派发任务、不修改领取或租约权限,不宣称本机 Bot、生产 UI 或真实宿主执行已升级验收。

本轮判定为 goal_achieved,关闭的是“当前协作工作状态读回修复”这个独立切口。长期 Bot 项目仍要另行验收实际部署及消息执行,不能用本 PR 的测试数代替。

改动思路

当前任务状态与领取来自权威 Todo 存储,审计事件只说明过去发生过什么,Next Action 是下一步提示。修复直接延伸既有两个适配器:索引合并时保护当前行;管理投影先收集完整当前行,再按 Goal/Todo 身份归并短标题、序号和提示,最后计算归属。管理视图与 execution-facts 读取共享同一迭代器,删除第二处重复去重。

只阻止审计覆盖会留下别名和 deferred checkbox 问题,另建调度器或第二份状态又会增加维护成本。此处是现有 Python 读模型的有界修复;TypeScript 生命周期、准入、领取、租约和 provider 事务 owner 保持原边界。没有新增配置或要求用户重复授权。

具体改动

完整评审 head:ed2ccf8e79c2c7a548a2a8b9af2538f21e702686;不可变基线:7b12259f29aa87cbeb3e31e82d4185aa9b5a50fd。四个文件共 230 增/24 删,其中生产代码 51 增/24 删,179 行新增测试集中在既有两个测试文件。

关键代码讲解

  • loopx/control_plane/todos/todo_index.py:148 的 build_todo_index:相同 Goal/Todo 上继续累积事件计数、时间、摘要和 latest_event_status。只有来源为 rollout_event_log 的纯审计行才由事件推导状态/actor;已有当前行的 status、done 和归属不再被历史事件覆盖。真实调用来自 status runtime summaries。
  • loopx/control_plane/agents/management_projection.py:318 的 _iter_status_todos:当前 items 先于短摘要和 Next Action;在判断领取者前去重,数据源不可用的 Goal 不回退到旧提示。只补充 advisory selected_by,不复制提示中的旧领取者。projected_agent_goals 和管理视图都走这个入口,execution-facts 不再读到另一份工作身份。
  • 同文件 :392 的 _todo_identity:有 Todo ID 时使用 Goal+Todo,不再把标题截断、序号和领取者当身份。没有 ID 的旧展示记录仍保留兼容键;这不会创建新的持久身份或恢复已清除的领取。
  • 同文件 :83 的 _is_done:通过既有 _todo_status 让明确状态优先,缺状态才读旧 checkbox。deferred 即使勾选也不是完成,目录显示 waiting;明确 done 的任务不再作为当前工作。

接受规范为 docs/reference/protocols/agent-management-projection-v0.md,读取版本 7b12259f29aa87cbeb3e31e82d4185aa9b5a50fd;同时核对同版本 docs/reference/protocols/peer-agent-directory-and-observation-v0.md。逐项对齐 Sources Of Truth(当前事实优先,implemented)、Todo Row(Goal 内稳定 ID 与显式状态,implemented)、Acceptance Checks(只读、保留真实租约、不在来源缺失时复活旧工作,implemented)。本次没有为匹配代码而改写规范。

对主干的风险

未发现阻塞代码问题。最强反例是当前任务已撤销领取、延后或完成,但旧事件和短别名重新显示可执行工作;反向风险是过严终态判断把正常 deferred 隐藏。相同 34 项聚焦测试在 head 全通过,在基线有 11 项失败、23 项通过。失败包含九项状态/身份反例,以及 File/SQLite 两种真实 CLI 中 blocked 被索引成 open 的错误,因此回归并非只重复新 helper 的逻辑。

独立的六组实际 CLI 对照在 base/head 均通过:无附加选择标记、短标题、245 条无关任务超过 240 条索引窗口、反转显示顺序、done、权威源失效并恢复。status --limit 1/999 的同一目标身份和状态一致;他 Goal 的 Agent 不能读取本 Goal,新 Agent 注册前拒绝、明确注册后可读目录但没有领取。每组都单独读回 Todo 和 provider revision,观察没有修改它们。更大的工作区、群授权、真实宿主执行不在这些 fixture 的证明范围内。

验证结果:34 项聚焦、100 项相邻 lifecycle/lease 回归、Ruff、四文件公开边界扫描通过;完整 native premerge 的 5 项直接检查及 18 项选中检查全部通过,零失败、零 manual hold。第一轮缺 TypeScript npm 依赖导致语义扫描失败;在 base 同样复现,按仓库 npm ci --ignore-scripts 补齐后,两个版本的语义扫描以及完整 head premerge 重跑通过。私有探针初期的字段/schema 假设修正仅限 fixture,未改产品规则或放宽断言。

语义与 CI 对齐

复用现有 Todo 状态、身份和 projection vocabulary;完整语义检查通过,但其动态生产者等未证明领域仍保留限制。无 opt-in/default-off 承诺、新协议或强制工作义务。遵循本轮 managed review 的 wait_for_ci=false,没有查询、轮询或等待 CI;没有宣称运行新安装包、live GUI/Bot/Host、PostgreSQL 或长期 soak。

此前评审提到的 merge commit DCO 问题已独立核实:按照 .github/workflows/dco.yml,head 的 SHA、两个 parents、web-flow 身份和 valid GitHub 签名均满足 GitHub 生成合并的明确豁免,底层 contribution 有 sign-off。没有重写历史或豁免未签名贡献。作者旧 head 的 peer 迁移/premerge 失败及旧质量回执作为历史保留;当前 head 的完整 native gate 已通过。本轮 Goal 的 change-quality policy 为 disabled,未签发或伪称已有新质量回执。

我的整体评价

APPROVE。当前源优先、稳定身份和显式状态是同一项读回修复,范围与实际问题相称,共享迭代器已完成必要简化。重复状态读取和 source 恢复后不再复活历史工作,long_horizon 与 user_experience 均 improved;普通用户没有新增确认、配置或重复提供已知信息的步骤。保留旧缺字段快照的兼容有实际消费者,不需要扩成 provider、模型或语言迁移。

同一 head 上已有 APPROVE;本轮补充独立当前 native premerge 证据,并纠正此前 DCO hold 的归因。代码结论与 GitHub 平台审批状态、合并授权分开。本次用户已明确授权自评审、自合并,仍须在合并前通过 exact-head readiness,并核对远端 head 未变化;生产采用与长期 Bot 目标没有因此自动关闭。

English verdict: APPROVE - ed2ccf8; current canonical Todo state, identity and claim outrank stale audit/hints. 34 focused tests, 100 adjacent tests, paired real CLI scope/cap/recovery cases, full native premerge (5 direct + 18 selected) and verified repository DCO policy passed. CI was not consulted; installed Bot/UI/Host adoption remains untested.

@loopx-agent

Copy link
Copy Markdown
Collaborator Author

Supplemental merge validation at unchanged PR head ed2ccf8e79c2c7a548a2a8b9af2538f21e702686:

  • Tested the source candidate consisting of current main 1e85a1e69c38d45b8085217b320988b2abeb5e77 plus this PR's four files. Both production modules and both test files exactly match the reviewed head bytes; the candidate imported its own source.
  • All 134 focused and adjacent regression tests passed (181.14s), including real File/SQLite state, claim/lease and source-recovery journeys. This checks interaction with the newly merged Todo recovery and lifecycle changes.
  • The exact PR head's complete native premerge already passed 5 direct and 18 selected checks. No head rewrite, product assertion change, CI query or installed/live Bot adoption is claimed.

The current exact-head approval and public review remain valid. Owner authorization for self-merge is explicit; merge still requires a fresh native readiness readback immediately before the operation.

@loopx-agent
loopx-agent merged commit cdfe146 into main Oct 6, 2026
9 of 27 checks passed
@loopx-agent
loopx-agent deleted the codex/peer-directory-canonical-status branch October 6, 2026 05:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants