chore(release): prepare v0.5.4 - #3864
Merged
Merged
Conversation
Signed-off-by: huangruiteng <huangrt01@163.com>
Collaborator
Author
|
No blocking findings in the exact release diff. Product / architecture judgment
Exact-head validation (
Merge decision: hold only for required GitHub CI. After merge, the eventual merge commit will be requalified from scratch before tagging, moving |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
LoopX v0.5.4
At a Glance
Typed control-plane transactions, governed workflow completion, and safer host integrations for long-running Agent work.
Upgrade
Existing installs upgrade explicitly; fresh installs use the package-native path in
## Install / Updatebelow.loopx update check loopx update apply loopx --version && loopx doctorHighlights
loopx todo list --thinprovides a bounded projection without changing default list behavior, selection, ordering, quota, or lifecycle semantics. (#3679)Replan Fixes
Contributors
This release includes work from @AetherX-Technologies, @Alicecooo, @BouwenZhou, @bubble66, @cocolord, @Danceiny, @Duang777, @hhyykk, @Jarad-z, @LIHUA919, @MohammedThowfiq, @NIU-123370, @now-ing, @ObVious55, @songoow, @steven-kid, @wchwawa, @xiaods, @yuefengw, and @zyaiire. Concrete attribution and first-time contributor highlights appear in
## Community Contributors.Release Decision
Who should upgrade: Operators running long-lived Goals, periodic reports, Personal Workspace over Remote SSH, DSH, Lark collectors, or Benchmark Toolkit workflows should upgrade; users unaffected by those paths can remain on v0.5.3 until their normal maintenance window.
What this release solves: It removes split ownership from more control-plane transactions, closes replan and scheduler settlement gaps, completes governed report delivery, and makes optional host and research workflows easier to activate and verify safely.
Breaking changes: No. Existing local Goal, Todo, registry, and event state remain compatible; the dashboard's default status source is restored to same-origin, while shared-authority providers and every external-write workflow remain staged or opt-in rather than becoming a new default.
How to verify: After upgrading, package identity must report
0.5.4, doctor must complete for the active install owner, and the focused command for any enabled optional surface must return its documented typed readback.Contributors: Maintainer @huangruiteng prepared the release with the 20 community contributors named in
## Community Contributors.State Kernel & Control Plane
The transaction-payoff phase moves complete behavior slices behind typed TypeScript owners instead of adding parallel helpers. Native task-lease acquire and lifecycle, host Todo settlement, Vision refresh, monitor-poll and void quota commits, scheduler follow-up, capability lifecycle validation, and settlement readback now share typed decisions, fenced effects, and replay receipts. (#3702, #3704, #3706, #3714, #3715, #3720, #3723, #3724, #3832)
Shared Control-Plane Authority gains a provider-neutral store contract and staged file, PostgreSQL, and NoKV candidates with CAS, lease fencing, idempotent settlement, ambiguous-commit recovery, tenant isolation, and conformance coverage. These providers are not the default runtime authority in v0.5.4; local Markdown/file projections remain authoritative until the RFC's separately reviewed promotion stages. (#3669, #3798, #3806, #3807, #3802, #3819, #3833, #3839)
Capabilities & Workflows
Periodic Report now turns committed completion facts into an intent-only post-writeback hook, consumes that intent through the governed generation/review path, reopens rejected drafts, records the actual work interval, publishes approved incremental progress through the enabled Goal Channel Bot, and verifies normalized delivery readback. It does not infer sink authority from a profile or report intent. (#3691, #3748, #3749, #3750, #3751, #3754, #3755, #3757, #3857)
Personal Workspace preserves startup error context, uses
/status.jsonthrough the same-origin Vite proxy by default, projects completed Todo progress, makes Goal stop feedback immediate, and self-heals owned stale listeners across legacy and current launchers. Chat avoids closing sessions with pending turns and restores ready state after a healthy resume. (#3561, #3732, #3745, #3772, #3773, #3814, #3855, #3858)Quality & Testing
The release pipeline now treats PyPI publication as a verified outcome: it builds wheel and sdist, publishes through Trusted Publishing, then installs the exact version from PyPI in a clean environment and checks
loopx --version. Frontstage CI and public smoke boundaries are isolated more precisely, installed-runtime doctor checks vary by install kind, and release qualification can use the explicitly allowlisteddoubao-seed-evolvingrolling model alias while binding its receipt to the exact commit and observation time. (#3728, #3736, #3740, #3797)Benchmarks & Integrations
The DSH plugin now bootstraps its private LoopX runtime and skills before readiness, then activates continuation only from typed evidence in the exact Session. Lark adds bounded new-message catch-up, safe collector-route reconciliation, structured mentions, and fresh-versus-recovery inbox reads. Codex provider routing adds Luna, Standard/Fast selector contracts, bounded account traversal, and a public-safe heartbeat transport diagnostic. (#3725, #3733, #3737, #3741, #3816, #3817, #3822, #3845, #3848, #3853)
Benchmark Toolkit adds reproducible study metadata, public-safe transport envelopes, a no-network local provider simulation, dashboard projections, TraeX evidence reduction, and bounded continuation decisions. The SWE-Marathon report and harness publish one reproducible 75-trial comparison in which LoopX Turn materially outperformed Codex
/goal; the other treatment-arm differences are presented as study observations, not generalized product uplift. No release command launches a benchmark or uploads a result by default. (#3776, #3779, #3812, #3838, #3841, #3846, #3849, #3850)Documentation & Compatibility
The release adds planner-worker guidance, hosted-doc navigation and locale parity, atomic-promotion failure guidance, reward-memory and governance walkthroughs, an Obelisk bounded-Replan-history RFC, and a shared-goal-alignment RFC. Default Todo listing remains unchanged unless
--thinis supplied; same-origin Dashboard status fixes both local and Remote SSH use; optional extensions do not grant provider credentials or external-write authority; and no persisted-state migration is required. (#3630, #3632, #3633, #3657, #3659, #3679, #3793, #3810, #3837)Community Contributors
Optional Capability Activation & Use
DSH Native LoopX Plugin
Activation: Install the versioned plugin in the DSH web profile and start DSH; one exact Session activates continuation only after a typed
loopxskill invocation.Validation: Resolve the live DSH Session and require one exact
status=boundGoal/Agent pair.Disable / rollback: Remove
dsh-loopx-pluginfrom the web profile and restart DSH.Authority boundary: Installation grants no model-provider credential, Goal binding, Todo, quota, or external-write authority; the plugin's HTTP carrier remains loopback-only.
Docs: https://github.com/huangruiteng/loopx/blob/v0.5.4/packages/dsh-loopx-plugin/README.md
Periodic Report Governed Lifecycle
Activation: An explicit request to generate the current project report activates one provider-free run; unattended reports additionally require an enabled project profile and a matching host Automation.
Validation: Inspect the built-in weekly profile and require
active=true,generation_allowed=true, and no external-write grant.Disable / rollback: Stop requesting one-shot reports; for scheduled runs, pause the host Automation and set the project profile's
enabledfield tofalse.Authority boundary: A trigger or generated artifact grants no archive, Lark delivery, provider credential, or publication authority; every sink remains independently enabled, approved, and read back.
Docs: https://github.com/huangruiteng/loopx/blob/v0.5.4/loopx/capabilities/periodic_report/README.md
Benchmark Toolkit Study and TraeX Contracts
Activation: Invoke the explicit
loopx benchmarksubcommand for a public-safe manifest, envelope, local simulation, TraeX observation, or bounded continuation decision; preview is the default.Validation: Validate the study manifest, preview the local transport, and read back only after an explicit
--executeto a caller-selected simulation store.Disable / rollback: Omit
--execute; there is no resident service or global enablement. A caller that executed against a simulation store owns retaining or replacing that local test artifact.Authority boundary: These commands grant no runner, model, task-source, credential, network, score, upload, submission, or publication authority, and raw tasks or trajectories have no upload schema slot.
Docs: https://github.com/huangruiteng/loopx/blob/v0.5.4/loopx/capabilities/benchmark_toolkit/README.md
Lark Dynamic Collector Routes
Activation: Install and doctor the bundled Lark extension, preview one additive collector route, then repeat with
--executeafter reviewing the exact inputs.Validation: Repeat the same request and require the typed
already_appliedzero-write result; restart or reinstall the collector separately and verify runtime readback before treating the route as live.Disable / rollback: Disable or roll back the
loopx-larkextension; route removal is a separate owner-authorized lifecycle operation.Authority boundary: Route reconciliation grants no chat membership, Bot scopes, credentials, runtime reload, message send, route removal, or rebind authority.
Docs: https://github.com/huangruiteng/loopx/blob/v0.5.4/loopx/extensions/lark/README.md
Codex Provider Routing Qualification
Activation: Install the co-located extension package, register its manifest explicitly, and run only content-free catalog, selector, runtime, or heartbeat qualification inputs.
Validation: Doctor the enabled extension and run the versioned public example through its managed lifecycle.
Disable / rollback: Disable or roll back
loopx-codex-provider-routing; restore the operator-owned CPA/App configuration independently.Authority boundary: The extension reads no credentials or prompts and grants no CPA installation, account access, routing mutation, App restart, config write, or model-provider authority.
Docs: https://github.com/huangruiteng/loopx/blob/v0.5.4/packages/loopx-codex-provider-routing/README.md
Install / Update
New PyPI users and existing PyPI users use the same package-native path:
All existing installs use explicit update intent; the command preserves the active pip, pipx, or archive owner:
中文摘要
LoopX v0.5.4 将更多长程 Agent 控制面事务收敛到 typed TypeScript owner,补齐受治理工作流,并强化可验证、可回退的 Host 集成。
/status.json,同时加强 Chat、Lark collector 与 listener 自愈;loopx todo list --thin是显式有界投影,不改变默认 list 行为。Replan 方面,Agent lane 会优先使用 selected Todo,typed blocker 与只读 autonomous replan 可闭环 settlement,delayed scheduler ACK 与 semantic replan 均绑定精确 Turn guard。
本版本包含 @AetherX-Technologies、@Alicecooo、@BouwenZhou、@bubble66、@cocolord、@Danceiny、@Duang777、@hhyykk、@Jarad-z、@LIHUA919、@MohammedThowfiq、@NIU-123370、@now-ing、@ObVious55、@songoow、@steven-kid、@wchwawa、@xiaods、@yuefengw 与 @zyaiire 的贡献;具体归因见下方“社区贡献者”。
升级决策
**谁需要升级:**运行长程 Goal、Periodic Report、Remote SSH Personal Workspace、DSH、Lark collector 或 Benchmark Toolkit 工作流的 operator 建议升级;未涉及这些路径的用户可按正常维护窗口从 v0.5.3 升级。
**解决了什么:**本版本继续消除控制面事务的双重语义 owner,修复 replan 与 scheduler settlement 缺口,补齐受治理报告投递,并让可选 Host 和研究工作流更容易安全启用、验证与回退。
**是否有破坏性变更:**无。已有本地 Goal、Todo、registry 与 event 状态保持兼容;Dashboard 默认状态源恢复为同源路径,shared-authority providers 与所有外部写入工作流仍是 staged 或 opt-in,不会成为新默认。
**如何验证:**升级后 package identity 应为
0.5.4,doctor应针对当前安装 owner 完成;启用任一可选 surface 时,再运行其下方 focused readback 命令。**贡献者:**Maintainer @huangruiteng 与“社区贡献者”一节列出的 20 位贡献者共同完成本版本。
状态内核与控制面
Native task-lease acquire/lifecycle、host Todo settlement、Vision refresh、monitor-poll 与 void quota commit、scheduler follow-up、capability lifecycle validation 和 settlement readback 进一步迁入 typed TypeScript transaction owner。Shared Control-Plane Authority 同时形成 provider-neutral contract、staged file/PostgreSQL/NoKV candidates,并补上 PostgreSQL tenant isolation;但 v0.5.4 不切换默认权威源,仍须经过 RFC 规定的独立 promotion 阶段。
能力与工作流
Periodic Report 已从 durable post-writeback facts 连到 generation/review/approval/delivery/readback,且 sink authority 不能从 profile 或 intent 隐式继承。Personal Workspace 修复 Remote SSH 同源 status、进度投影、Goal stop 即时反馈和 owned listener 自愈;Chat 的 pending-turn close 与 healthy resume 也得到修复。
质量与测试
Release workflow 会构建 wheel/sdist、通过 Trusted Publishing 发布 PyPI,再在干净环境从 PyPI 安装精确版本并验证
loopx --version。本版本还改进 Frontstage/public smoke 隔离、按 install kind 的 doctor deep checks,并允许 exact-commit model-behaviour qualification 显式选择doubao-seed-evolving;该 receipt 只证明运行时刻观察到的 rolling alias,不声称 immutable model revision。基准与集成
DSH、Lark 与 Codex provider-routing 获得更完整的 activation/readback/failure contracts。Benchmark Toolkit 提供 public-safe study/transport/dashboard/TraeX/continuation contracts;SWE-Marathon 75-trial 研究中 LoopX Turn 显著优于 Codex
/goal,其余 treatment arm 差异作为该研究的观察保留,不泛化成稳定产品 uplift。默认不启动或上传 benchmark。文档与兼容性
新增 planner-worker、hosted-doc parity、atomic promotion、reward-memory、governance、Obelisk bounded Replan history 与 shared Goal alignment 资料。默认 Todo list 不变;Dashboard 同源状态源覆盖本机与 Remote SSH;可选 extension 不继承 provider credential 或外部写入权限;无需迁移持久状态。
社区贡献者
可选能力启用与使用
DSH Native LoopX Plugin
**启用:**把版本化插件安装进 DSH web profile 并启动 DSH;只有精确 Session 出现 typed
loopxskill invocation 后才激活自动续跑。**验证:**解析当前 DSH Session,要求唯一
status=boundGoal/Agent pair。**停用 / 回退:**从 web profile 移除
dsh-loopx-plugin并重启 DSH。**权限边界:**安装不会授予模型凭证、Goal binding、Todo、quota 或外部写入权限;HTTP carrier 仅限 loopback。
**文档:**https://github.com/huangruiteng/loopx/blob/v0.5.4/packages/dsh-loopx-plugin/README.md
Periodic Report Governed Lifecycle
**启用:**显式要求生成当前项目报告可激活一次 provider-free run;无人值守报告还需 enabled project profile 与匹配的 host Automation。
**验证:**检查内置 weekly profile,要求
active=true、generation_allowed=true,且没有 external-write grant。**停用 / 回退:**停止发起一次性报告;定时路径需暂停 host Automation,并把项目 profile 的
enabled设为false。**权限边界:**trigger 或 artifact 不授予 archive、Lark delivery、provider credential 或 publication 权限;每个 sink 必须独立启用、批准并读回。
**文档:**https://github.com/huangruiteng/loopx/blob/v0.5.4/loopx/capabilities/periodic_report/README.md
Benchmark Toolkit Study and TraeX Contracts
**启用:**对 public-safe manifest、envelope、本地 simulation、TraeX observation 或 bounded continuation 显式调用对应
loopx benchmark子命令;默认只 preview。**验证:**先验证 study manifest,再 preview 本地 transport;只有对 caller-selected simulation store 显式
--execute后才执行 readback。**停用 / 回退:**不传
--execute即保持只读;不存在 resident service 或全局开关,已执行的 simulation artifact 由 caller 管理。**权限边界:**不授予 runner、model、task source、credential、network、score、upload、submission 或 publication 权限;raw task/trajectory 不在 upload schema 中。
**文档:**https://github.com/huangruiteng/loopx/blob/v0.5.4/loopx/capabilities/benchmark_toolkit/README.md
Lark Dynamic Collector Routes
**启用:**安装并 doctor bundled Lark extension,先 preview additive collector route,再在核对输入后以
--execute应用。**验证:**重复同一请求并要求 typed
already_appliedzero-write 结果;另行重启或重装 collector 并验证 runtime readback 后,才能视为 live。**停用 / 回退:**disable 或 rollback
loopx-larkextension;route removal 是独立的 owner-authorized lifecycle operation。**权限边界:**route reconcile 不授予群成员身份、Bot scope、credential、runtime reload、消息发送、route 删除或 rebind 权限。
**文档:**https://github.com/huangruiteng/loopx/blob/v0.5.4/loopx/extensions/lark/README.md
Codex Provider Routing Qualification
**启用:**安装 co-located extension package,显式注册 manifest,并只提交 content-free catalog、selector、runtime 或 heartbeat qualification input。
**验证:**doctor enabled extension,并通过 managed lifecycle 运行版本化 public example。
**停用 / 回退:**disable 或 rollback
loopx-codex-provider-routing;CPA/App 配置由 operator 独立恢复。**权限边界:**extension 不读取 credential 或 prompt,也不授予 CPA 安装、账号访问、routing mutation、App restart、config write 或模型 Provider 权限。
**文档:**https://github.com/huangruiteng/loopx/blob/v0.5.4/packages/loopx-codex-provider-routing/README.md
发布验证
0.5.4/v0.5.4.TARGET_COMMIT_SHA.loopx==0.5.4from PyPI and reads backloopx --versionplusloopx doctor.Compare: v0.5.3...v0.5.4