fix(runtime): preserve Windows locator diagnostics - #5734
huangruiteng merged 1 commit into
Conversation
3de618d to
14ce63b
Compare
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent — gpt-6.1-sol (OpenAI); runtime_reported; reasoning_effort=xhigh
Exact reviewed head: 14ce63b; immutable baseline: cf1f686
动机
在 Windows 启动本地控制面运行时的 CLI、App 使用者和维护者。 locator 路径被目录占据时,旧版在读取阶段误报宿主权限拒绝;新版让已有运行时返回目录发布失败的安全诊断,移除自己确认的占用后沿同一入口恢复。 真实进程对照中,模拟 Windows 目录打开异常从零启动的权限拒绝变为一次失败启动的文件系统诊断;不可读文件、符号链接和活锁保持原拒绝或锁诊断,八类场景移除自建故障后都能实际 ping 和关停。 本次不修复全部启动故障、不删除未知占用、不改变重试授权;本机没有原生 Windows 结果,也不证明已安装 App、Lark、真实模型或多领域长期净收益。 原生 Windows 与安装版体验尚未核验;关停响应后立即用 retry_safe=False 重连的既有时序问题在不可变 base/head 各六次同签名复现,属于未改路径。此修复是有独立价值的 justified_increment,不将局部诊断修复当作完整运行时验收。
改动思路
复用现有 TS 文件系统错误 owner 和启动 envelope:Python 只把“PermissionError 且真实目录且非 symlink”当作未发现有效 locator,让现有 server 尝试发布并给出安全错误。真正权限拒绝仍 fail closed。没有第二份 Python OS 错误码表、fallback runner、超时扩大、权限授予或新状态开关。正常读取路径不增加判断;只有拒绝路径新增两次文件类型检查。这里的 Python 是 pathlib/host IO 适配,既有 TypeScript 控制面和副作用权威没有移动。
具体改动
完整 2 文件 +59/-3。effect_runtime.py 增 6 行(2 行判断/返回,4 行解释);test_effect_runtime_integration.py +53/-3,增加目录/不可读普通文件的读取对照,并在既有真实发布故障 fixture 上增加 Windows denied-open 信号变体,保留原目录和活锁 fixture。未新增模块、CLI 参数、provider、catalog 或持久化契约。
规范依据 https://github.com/loopx-project/loopx/issues/5735,固定正文版本 issue-5735-body-sha256:3f8c33d59a92009db928f54e99926a3093d14f7206054b34594c75889bd95e4d。原有标题 Expected behavior:Windows 占用目录进入 server 的既有启动 envelope;Problem:真正不可读的普通 metadata 保持 runtime_host_permission_denied。两项在本 head 的适配/实际后端路径已实现。另先读不可变基线 cf1f686cc517e844a164ac0f45fda7132d9c82b2 的 docs/guides/installing-loopx.md:45–57 和 #5551 frame;指南已经要求安全目录/锁诊断、保留占用,不另造 RFC 门槛。
关键代码讲解
_read_info(effect_runtime.py:462)在 PermissionError 分支区分真实目录和符号链接;其余 fingerprint、loopback、port/token、PID 校验原样保留。_start_runtime(:876)沿原启动锁创建真实 Node 进程、等待 readiness 或解码 startup error,并 finally 清理自己的启动锁。server.listen callback(effect_runtime_server.ts:291)仍经 atomicWriteJson/withFileMutationLock 发布,失败通过 effectRuntimeErrorPayload → failStartup 输出固定安全 envelope;并未让 Python 硬编码 Windows 的 io_permission_denied。effect_runtime_request(effect_runtime.py:999)保留权限失败不重试、retry_safe 有界启动和真实 socket 请求规则。
对主干的风险
独立同一脚本在不可变 base/head 运行八类真实进程/文件后端场景:普通目录冲突;模拟 Windows 目录 read_text PermissionError;真实目录符号链接/悬空链接的 denied-open;真实 chmod000 普通 metadata;普通文件 denied-open;当前活 PID 的 mutation lock;正常启动。只有 Windows 目录信号改变:base 是 runtime_host_permission_denied、0 次 server 启动;head 是真实 macOS server 的 io_is_directory、1 次失败启动。这里仅输入异常受控,server、原子发布、锁、socket、诊断 envelope 和恢复都是真实的;没有把 macOS 输出冒充原生 Windows io_permission_denied。未改 TS EACCES/EPERM 分类表提供 source 依据,原生 Windows 仍是独立安装/发布资格。
不可读普通文件和链接在两边仍权限拒绝/0 启动;目录和活锁不被删除或覆盖,自己的 start lock 清理,stderr 不含 fixture 路径、token 或 Node stack。移除仅自行创建的故障后,八场景两边均 actual ping ready、shutdown、locator 退役。没有额外用户导航、重新输入已知信息、确认或配置;普通入口和 truthful failure 读回保持。
语义与 CI 对齐
136 项 runtime integration/host permission/restart/publication-ready/request-scope/compile-cache 测试通过;Ruff、diff/compile 和 canary 5 direct +2 catalog +8 risk 通过,含 full-tree semantic/maintainability,tracked side-effect guard 干净。development advisory 在 full-tree 检查前运行、没有支持的新 vocabulary carrier;空 advisory 不是语义证明。无 optional/default-off 承诺,普通启动/真正拒绝的 base/head 对照保持,未增加 caller 字段、指导语或调度义务。未查询、轮询或等待 CI(当前 wait_for_ci=false);作者 Windows CI 链接不当独立通过证据。无 PostgreSQL 权威重构、新 frontend 设置或 UI 展示,未声称安装版 App/Lark/model 验收。
失败记录保留:首版私有 harness 误用 pong 字段,实际既有 runtime.ping 契约为 ready;核对原 handler 后只修正 harness。第二版在 shutdown 应答后马上 retry_safe=False ping 遇到 ConnectionRefusedError。没有靠一次绿色重跑消掉它:独立相同脚本在 base/head 各六次重现相同 runtime_request_failed/ConnectionRefusedError,旧 locator 尚在、0 PermissionError,request owner source hash 相同;未改的 server 是先停止接新请求再异步退役 locator。这是已存在的无重试关停时序,PR 未修复。当前 recovery fixture 等实际 locator 退役后验证新请求,沿既有关停握手,没有修改生产代码、放宽权限断言或重试来粉饰这条失败。该问题与本次目录错误分支的通过证据分别记录。
我的整体评价
APPROVE。效果局部正向:占用目录不再误导为宿主访问拒绝,仍保留真实权限、安全诊断和恢复边界。效率的收益是减少错误排查和反复尝试,不宣称吞吐百分比;目录故障会从零启动变为一次失败启动,这是获得既有权威诊断所需的有界成本,正常路径不多做工作。长程恢复通过多类失败→纠正→实际继续运行验证,未把原生 Windows、模型领域收益或全部启动故障打包认证。
future-facing pass:现有 reader 和 TS error owner 已是最小合适边界,增加 helper 或复制 Windows 分类只会增成本;无需伴随重构。既有关停时序保留独立失败归因,不能以此拒绝无关目录修复,也不能称它已解决。runtime 变更仍由维护者合并。
English verdict: APPROVE — 14ce63b. The concrete nonsymlink-directory guard restores the existing safe startup-diagnostic path without bypassing unreadable-file or symlink permission denial. Same immutable-base/head eight-case real Node/filesystem/socket probes preserve occupants, locks and recovery;136 runtime tests and selected canaries pass. Windows' directory-open input signal is controlled on macOS, not native Windows qualification. The separate immediate-shutdown/no-retry race reproduces with identical signatures six times on each revision and is not fixed or waived by this patch.
14ce63b to
43ea173
Compare
Signed-off-by: mika <[email protected]>
43ea173 to
4b463a2
Compare
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent; model=gpt-6.1-sol; provider=OpenAI; declaration_source=runtime_reported; reasoning_effort=xhigh
Exact reviewed head: 4b463a25f2eecc6bd1db5eb2abfde23dddc2d56c; immutable merge-base: a4cd008484de7fbba1c44bb1638bf8cdb62bd40c.
动机
在 Windows 启动本地控制面运行时并遇到 locator 目录占用的 CLI、App 用户和维护者。
目录占用会被旧读取器误报为宿主权限拒绝;当前版本仅把真实且非符号链接的目录交给既有 server 发布诊断,移除自行确认的占用后沿原入口恢复。
macOS 上受控 Windows 目录打开异常由零 server 启动的权限拒绝变为一次失败启动的安全目录诊断;不可读文件、目录链接、悬空链接和活锁保持原拒绝,八类场景都能纠正后实际 ping、shutdown 和退役 locator。
本 PR 不删除未知占用、不放宽真正权限拒绝、不增加重试或新权限;macOS 输入模拟不能认证原生 Windows 或已安装 App。
原生 Windows 和安装版体验仍未在本次执行;源路径多类恢复已验证,发布资格由既有运行时 owner 负责。
改动思路
复用 Python locator reader 和现有 TypeScript startup envelope。只有 PermissionError、真实目录、非符号链接三个条件同时成立才返回未发现 locator,交由原 server 尝试发布并给出安全诊断;真正宿主拒绝仍 fail closed。正常读取不加文件类型判断,不复制 Windows 错误码表,不增加超时、重试、provider 或第二决策源。CLI/App仍用原启动入口和既有诊断,无新增配置/确认。
完整两文件 +59/-3;生产仅增六行,余下是现有 integration case 的目录、普通文件和受控 Windows 信号回归。此前正文14ce63b3不覆盖当前基线中的live startup-lock年龄保护;该改动属于新base而非本PR六行,但137项当前测试已包含它。
具体改动
关键代码讲解
- _read_info:PermissionError directory discrimination; genuinely unreadable files and links remain host-denied.
- _start_runtime:Existing lock/process/readiness/startup-envelope handling, with no foreign deletion.
- server.listen callback:Actual atomicWriteJson/withFileMutationLock publication uses shared safe error payload and fails startup.
spec_ref: https://github.com/loopx-project/loopx/issues/5735;spec_revision: issue-5735-body-sha256:3f8c33d59a92009db928f54e99926a3093d14f7206054b34594c75889bd95e4d。先读固定版本的相关已接受要求,未通过修改规范让实现自行合格;标准对应如下:
Expected behavior:implemented;上述真实入口、拒绝/恢复和当前本地测试对应此规范项。Problem:implemented;上述真实入口、拒绝/恢复和当前本地测试对应此规范项。
对主干的风险
八类相同输入分别在 immutable base/head 使用真实 Node server、文件/锁、原子发布、startup envelope 与 socket。唯一预期差异是受控 Windows 目录打开异常:base 为 runtime_host_permission_denied且server0,head为本机实际io_is_directory且server1,另有一次node版本探针,不把两个Popen都叫server。原生macOS目录、目录/悬空链接拒绝、真实chmod000普通文件、普通文件受控拒绝、活PID mutation lock、正常启动的错误类型/代码/消息和进程类别保持相同。
占用和活锁未删除,自己的start lock清理,stderr不带fixture路径/token/stack。仅移除自行创建故障后八类都实际ping ready、shutdown并等待locator退役后恢复。137项当前runtime suite通过;原base的目录分类回归一项预期失败,普通文件控制一项通过。本轮没有复现或认证历史即时shutdown/no-retry竞态已修复;正常恢复沿既有退役边界,历史失败仍是独立未改路径记录。
语义与 CI 对齐
复用现有 vocabulary 与 typed owner,不新增 shared Enum、schema 或并行状态机。修改期 advisory先于全树检查、没有支持的新载体,但空结果不证明动态语义安全;当前 canonical semantic-vocabulary smoke、完整maintainability ratchet、修改文件Ruff和diff检查均通过。初次semantic命令用了不存在的子目录,未执行检查;更正为仓库实际路径后通过,原错误保留。当前 wait_for_ci=false,未查询、轮询或等待CI。没有PostgreSQL权威存储重构、可见UI布局或新caller capability,未推断live/installed/frontend结果。
我的整体评价
long_horizon preserved、user_experience improved,限于当前源码证据:目录故障从零server变成一次有界失败启动以取得权威诊断,真实拒绝、锁和恢复不放宽;正常路径保持。没有新增手动同步、持久化格式或权限。future-facing pass认为现有reader与TS错误owner已经是最小边界,提取新helper或复制分类表会增加成本。APPROVE;原生Windows和安装态是剩余发布资格,不把macOS模拟冒充其通过,也不把局部修复当完整运行时验收。由维护者合并。
完整本轮结论绑定当前 4b463a25f2eecc6bd1db5eb2abfde23dddc2d56c,替代正文仍写旧revision的过期证明;发布前重读head、结论库存,发布后读回正文/state/head,再执行原生closeout/readiness。批准与合并权限分开。
English verdict: APPROVE - 4b463a2. Only the controlled denied-open real directory reaches existing server publication; seven other error/launch classes preserve prior behavior. 137 current runtime tests passed; eight paired immutable-base/head real Node/filesystem/socket cases, with process-kind attribution separated from node --version; intended directory signal changes, seven other normalized error/launch classes remain identical. One expected base directory regression fails; unreadable-file control passes. Ratchet, Ruff, diff and canonical semantic check passed. Source qualification only; 原生 Windows 和安装版体验仍未在本次执行;源路径多类恢复已验证,发布资格由既有运行时 owner 负责。
Goal And Delivered Outcome
Author Declaration
Validation
Scope
This fixes the occupied-directory diagnostic while preserving permission-denial handling for unreadable metadata and symlinks. No UI or shared-authority RFC fixture changed.
Type of Change
LoopX Area
Boundary Checklist