Skip to content

release: prepare LoopX 1.0.0 Workspace milestone - #3995

Merged
huangruiteng merged 13 commits into
mainfrom
codex/release-1.0.0-20260906
Sep 6, 2026
Merged

huangruiteng merged 13 commits into
mainfrom
codex/release-1.0.0-20260906

Conversation

@huangruiteng

@huangruiteng huangruiteng commented Sep 6, 2026 •

Copy link
Copy Markdown
Collaborator

LoopX 1.0 — a workspace for long-running agents

At a Glance

See what agents are doing, what is waiting on you, and what has actually been delivered—in one persistent Workspace.

Upgrade

loopx update check
loopx update plan
loopx update apply
loopx --version
loopx doctor

Highlights

  • A richer Workspace: all agent lanes, completed work, capability settings and verified reports.
  • IM as an operating surface: reconnect Goal Topics and choose live steering, session queuing or async inbox.
  • Signed desktop maintenance: paired App/runtime updates with stable/main, repair and rollback.
  • Real frontend project stories, and a stronger Doubao evolving behavior gate.

Contributors

Release Decision

Who should upgrade: Workspace, Lark/IM and desktop users, plus operators needing the recent Todo and host-recovery fixes; stable CLI-only deployments can review the affected optional surfaces before upgrading.

What this release solves: More work state becomes visible and actionable, completed delivery is easier to verify, and desktop maintenance has a signed, recoverable App/runtime path.

Breaking changes: No. The 1.0 label marks a Workspace milestone, not blanket promotion of staged authority backends. Older desktop shells need one manual bootstrap replacement; optional delivery routes and host capabilities keep their explicit activation boundaries.

How to verify: Expect package version 1.0.0, inspect doctor output, then read back your Goal and the App/runtime identity for the installed source.

Contributors: @Duang777, @now-ing, @steven-kid, @yuefengw, @songoow. Milestone foundations also include @maxliux5; see the contribution details below.

loopx --version
loopx doctor
loopx machine-config inspect

Workspace milestone

1.0 marks the Personal Workspace milestone: a durable control surface for work that continues across sessions. The Workspace already existed before v0.5.4; this release brings its state and operation paths together.

  • Open the Workspace before slow Goal histories finish: a lightweight directory appears first, Goals load independently, and transient failures recover automatically, and stopped histories load on selection (#4007, #4009).
  • See all work-agent lanes, act from the workspace, and reliably read completed tasks (#3888, #3894, #3961).
  • Configure Goal capabilities and typed machine policy; inspect verified reports with bounded indexing (#3860, #3861, #3865, #3951).
  • Explore reusable, complex project stories through the real frontend and state APIs (#3990).

State kernel and integrations

  • Native Todo create/update, request-bound idempotency and attached-completion recovery improve real delivery; promoted claim retries now expose their exact identity, with cross-provider lease-race qualification (#3973, #3974, #3977, #3980, #3981, #3987, #3986).
  • Stage2C authority work remains staged. Kernel routing and legacy writer fences are foundations, not a declaration that every existing tenant has been promoted (#3882, #3895).
  • Reconnect existing Lark Goal Topics, reuse session history, and apply scoped outbound guidance before authorized messages (#3983, #3868, #3968, #3998, #3999, #3992).
  • Codex provider routing improves Fast/dualAuto and quota recovery; host recovery and heartbeat compatibility are hardened (#3984, #3892, #3880, #3913, #3890).
  • Read benchmark-native study views and bounded terminal insights without changing experiment authority or scoring (#3896, #3898, #3878, #3881).

Desktop and qualification

Signed App updates pair the shell with its runtime. Stable is independent of unrelated plugin releases; service startup failures leave recovery usable; channel selection survives polling (#3994, #3996). Native maintenance now matches the actual IPC origin; unavailable feeds and local status failures have distinct recovery messages. The behavior gate removes extra answer hints and adds adversarial diagnostic contrasts and mutation checks (#3997). Release checks now use bounded scheduler clocks, typed followthrough obligations and stable historical version anchors; CLI command owners and help/manpage coverage are aligned without raising budgets (#4002, #4003). No benchmark uplift or long-horizon outcome improvement is claimed.

Community Contributors

Special milestone thanks to @maxliux5 for the Workspace, tasks-first navigation, Manager/Lark integration and session/streaming foundations (#3149, #3167, #3274, #3385, #3292, #3285, #3073). These contributions predate the v0.5.4 comparison range; they are credited as foundations of 1.0.

Optional Capability Activation & Use

Set the shell variables in the commands below to your own existing Goal, Agent, reviewed configuration and input files. Configuration writes require the named explicit execution step.

Workspace and machine configuration

Activation: Run loopx dashboard; configure a Goal through its Capability settings. For typed machine policy, inspect namespaces, preview a JSON envelope, then apply that exact returned plan revision with --execute.

Validation: Use machine-config inspect to read effective policy and its revision; use configure-goal --goal-id "$GOAL_ID" for Goal readback.

Disable / rollback: Close the local dashboard with Ctrl-C. Preview machine-config remove --namespace "$NAMESPACE", then repeat with its --expected-plan-revision and --execute; rollback similarly uses a recorded --transaction-id, a fresh preview revision and explicit execution.

Authority boundary: Local machine configuration and Goal capability selection do not grant external writes, override user gates or promote staged authority-store tenants. Remote/SSH read models remain read-only.

Docs: https://github.com/huangruiteng/loopx/blob/v1.0.0/docs/guides/personal-workspace-user-guide.md

loopx machine-config describe
loopx machine-config inspect
loopx configure-goal --goal-id "$GOAL_ID"

Periodic reports

Activation: Ask the active agent to generate this week’s project report for a one-session Markdown/HTML report. Recurrence requires an explicit custom profile and host Automation; machine/Goal subscriptions require periodic_report.enabled: true and an explicit route_ref.

Validation: Inspect the weekly preset: active and generation_allowed should both be true. Read the generated artifacts and bounded source receipts.

Disable / rollback: One-session generation creates no recurring job. Pause its Automation or set a custom profile to enabled: false; disable the machine/Goal subscription to stop subscribed delivery.

Authority boundary: The weekly preset has no sink and does not send. An enabled subscription with an explicit route is standing delivery authority, still subject to provider, identity and readback gates.

Docs: https://github.com/huangruiteng/loopx/blob/v1.0.0/loopx/capabilities/periodic_report/README.md

loopx periodic-report inspect-profile --preset weekly --format json

Lark Goal Channels

Activation: In notification settings → Lark → Connections, choose the Goal, registered target Agent, chat, capture scope and ingress mode, then save. Reconnect an existing topic without creating a duplicate.

Validation: Read back the connection/session binding. Send a new @ message yourself; for Async inbox, drain the exact Goal/Agent to inspect the event.

Disable / rollback: Choose Disconnect on that Goal connection. This removes its topic route and preserves Goal data, sessions, history and other connections.

Authority boundary: Steering targets an exact live turn; Queuing targets the same exact session; Async inbox waits for drain. Capture scope does not enlarge agent authority or authorize cross-topic replies.

Docs: https://github.com/huangruiteng/loopx/blob/v1.0.0/docs/guides/personal-workspace-user-guide.md

loopx lark-inbox drain --goal-id "$GOAL_ID" --agent-id "$AGENT_ID"

Workspace stories

Activation: From a source checkout with Python 3.11+ and Node 22.6+, run the module below and open its printed loopback URL.

Validation: Inspect three projects, each with four work roles, 18 delivery tasks, two owner decisions and two scheduled watches; inspect their calculated budgets and sensitivity tables.

Disable / rollback: Stop with Ctrl-C. For a persistent replay, use prepare --root /tmp/workspace-stories, then serve --root /tmp/workspace-stories; choose a new empty directory to start over.

Authority boundary: These are authored scenario replays through real LoopX APIs, not customer outcomes or live-agent completion claims. State is isolated; no scheduler, agent, external message, purchase or deployment is started.

Docs: https://github.com/huangruiteng/loopx/blob/v1.0.0/demo/workspace/README.md

python -m demo.workspace serve

Outbound guidance recall

Activation: In the existing agent-scoped Reward Memory experiment, add outbound_message.before_send with scoped_feedback, the exact peer_ref: agent:…, and automation.automatic_recall: true; apply the reviewed config below.

Validation: Read experiment-status. Use lark-inbox send with --provider-preflight and without --execute to validate a configured route without sending.

Disable / rollback: Set automation.automatic_recall: false or remove this surface and reapply the experiment configuration.

Authority boundary: Advisory preferences do not authorize sending. This integration covers Goal/Agent-bound lark-inbox send and reply, not arbitrary messaging tools or Goal Topic auto-replies. No raw outgoing message enters the recall query.

Docs: https://github.com/huangruiteng/loopx/blob/v1.0.0/loopx/capabilities/reward_memory/OUTBOUND.md

loopx configure-goal --goal-id "$GOAL_ID" --reward-memory-config "$REWARD_CONFIG" --reward-memory-agent "$AGENT_ID" --execute
loopx reward-memory experiment-status --goal-id "$GOAL_ID" --agent-id "$AGENT_ID"

Codex provider routing

Activation: From the source checkout and the same activated Python environment, install this optional package and its managed manifest.

Validation: Run extension doctor and the packaged content-free request. This validates routing/host observations, not live account ownership.

Disable / rollback: Run loopx extension disable loopx-codex-provider-routing --execute. A separately deployed CPA operator is stopped/unloaded independently; disabling this read-only extension does not stop that service.

Authority boundary: The extension is a read-only contract compiler/qualifier, not a proxy or credential authority. CPA and the operator retain their own routing, installation and credential responsibilities.

Docs: https://github.com/huangruiteng/loopx/blob/v1.0.0/packages/loopx-codex-provider-routing/README.md

python3 -m pip install packages/loopx-codex-provider-routing
loopx extension install --manifest packages/loopx-codex-provider-routing/extension.toml --execute
loopx extension doctor loopx-codex-provider-routing --execute
loopx extension run loopx-codex-provider-routing --input-json packages/loopx-codex-provider-routing/examples/request.json --execute

Benchmark study readback

Activation: Pass an existing compact study manifest and public-safe local record store to study-dashboard; the command itself is the opt-in.

Validation: Inspect campaign/arm/case/run projections, declared denominators and provisional coverage. Add --four-arm-contract-json only for a qualified matching four-arm design.

Disable / rollback: Stop invoking the read-only projection. Disable any separately activated upload provider through its own extension lifecycle.

Authority boundary: This read model does not launch experiments, change scoring, create Todo authority or authorize uploading raw tasks, trajectories, logs or hidden evaluator data.

Docs: https://github.com/huangruiteng/loopx/blob/v1.0.0/loopx/capabilities/benchmark_toolkit/README.md

loopx benchmark study-dashboard --manifest-json "$STUDY_MANIFEST" --store "$STUDY_STORE" --format json

Signed desktop updates

Activation: Install the new macOS App once to bootstrap older shells. In Recovery & Updates, explicitly check stable or main, install, then restart to pair the App with its bundled runtime.

Validation: Read App version and the Workspace runtime identity; use loopx --version and loopx doctor. Stable reads the dedicated desktop-stable feed; main reads complete signed main builds.

Disable / rollback: Use Repair for the current App’s runtime or Restore previous version when a verified backup exists, then restart. Keep an external installation backup; runtime rollback does not promise reversal of incompatible future Goal schemas.

Authority boundary: Only explicit native actions install. Feeds cannot supply arbitrary browser commands or runtime URLs. macOS uses ad-hoc code signing plus updater signatures, not notarization; Python 3.11+ is required. Windows artifacts use manual updates.

Docs: https://github.com/huangruiteng/loopx/blob/v1.0.0/apps/desktop/loopx-control-plane/README.md

loopx --version
loopx doctor

Install / Update

Python 3.11+ and Node 22.6+ are required for the packaged control plane. Existing installs preserve their pip, pipx or archive owner through loopx update; inspect its plan first. PyPI users can also pin the milestone directly:

python3 -m pip install --upgrade loopx==1.0.0
loopx workflow-skills --install
loopx slash-commands --install
loopx doctor

Keep your previous installation and private Goal data backup. App rollback restores an installation, not arbitrary state-schema migrations. No blanket persisted-state migration is requested by this milestone.

中文摘要

让长程 Agent 的工作有一个持续可用的控制面:正在做什么、卡在哪里、等谁决策、实际交付了什么,都能在同一个 Workspace 里检查和操作。

本次聚焦完整工作状态、Capability 配置、报告、飞书协作及 App/运行时配套更新;它是工作区的 1.0 里程碑,而非首次出现前端。升级与最小验证命令见上方。

升级决策

谁需要升级: 工作区、飞书/IM 和桌面用户,以及需要近期 Todo、宿主恢复修复的 operator;稳定 CLI-only 部署可先核对受影响能力。

解决了什么: 更多工作状态可见可操作,完成结果可验证,桌面获得签名、可恢复的 App 与运行时配套维护路径。

是否有破坏性变更: 无。1.0 是工作区里程碑,不代表分阶段 authority 后端全部提升;旧桌面壳需一次手动替换,可选投递与宿主能力仍按明确授权启用。

如何验证: package version 应为 1.0.0,检查 doctor,再读回 Goal 配置与 App/runtime 的源码身份。

贡献者: @Duang777, @now-ing, @steven-kid, @yuefengw, @songoow;另感谢工作区基础贡献者 @maxliux5,范围区分见下文。

loopx --version
loopx doctor
loopx machine-config inspect

工作区里程碑

1.0 是 Personal Workspace 的里程碑:让跨会话持续推进的工作有可检查、可操作的长程控制面。工作区在 v0.5.4 之前已经存在,本次将更丰富的状态与操作路径汇合起来。

  • 先进入工作区,再逐个补齐 Goal 状态:轻量目录先展示,慢 Goal 不阻塞其他项目,短暂失败自动重试,已停止 Goal 的详情按需加载(#4007, #4009)。
  • 汇总各工作 Agent、即时操作并可靠读回已完成任务(#3888, #3894, #3961)。
  • 配置 Goal capability 与机器策略,检查经过验证的报告和有界索引(#3860, #3861, #3865, #3951)。
  • 用真实前端与状态 API 重放复杂项目,场景能力沉淀进仓库(#3990)。

状态内核与集成

  • 原生 Todo 创建/更新、请求级幂等与完成恢复改进真实交付;已提升路径的 claim retry 提供精确身份,并补充跨 provider 的 lease 竞争验证(#3973, #3974, #3977, #3980, #3981, #3987, #3986)。
  • Stage2C 仍分阶段推进,内核路由和旧 writer fence 不代表全部既有 tenant 已提升(#3882, #3895)。
  • 重连已有飞书 Goal Topic、复用会话历史,在已授权发送前召回范围内偏好(#3983, #3868, #3968, #3998, #3999, #3992)。
  • Codex 路由补齐 Fast/dualAuto、quota 恢复及宿主/心跳兼容(#3984, #3892, #3880, #3913, #3890)。
  • 只读研究视图与终态 insight 保留 benchmark 原生指标、权限与评分口径(#3896, #3898, #3878, #3881)。

桌面与资格验证

签名更新将 App 与运行时配套升级;stable 不受插件 Latest 干扰,服务启动失败后仍能恢复,通道选择不会被轮询覆盖(#3994, #3996)。原生更新接口修正 IPC origin 匹配,更新源不可用与本机状态读取失败分别给出恢复提示。行为测试移除额外答案提示,增加诊断诱导反例及判分器 mutation checks(#3997)。发布检查改用有界时钟、typed followthrough 义务与稳定历史版本锚点;CLI 模块职责、帮助和手册同步且不提高预算(#4002, #4003)。不据此宣称 benchmark 或长程结果提升。

社区贡献者

特别感谢 @maxliux5 为工作区、任务优先导航、Manager/飞书集成及会话/流式体验打下基础(#3149, #3167, #3274, #3385, #3292, #3285, #3073)。这些工作早于 v0.5.4,本次作为 1.0 基础贡献致谢,不计作本次 tag range 新增贡献。

可选能力启用与使用

下方变量应替换为你已有的 Goal、Agent、已审阅配置和输入文件;配置写入需显式执行。

Workspace and machine configuration

启用: 运行 loopx dashboard,在 Goal 的 Capability 设置中配置能力。机器策略先发现 namespace、预览 JSON,再用返回的精确 plan revision 和 --execute 应用。

验证: 用 machine-config inspect 读回生效策略与 revision;用 configure-goal --goal-id "$GOAL_ID" 读回 Goal 配置。

停用 / 回退: Ctrl-C 关闭本地 dashboard。先 machine-config remove --namespace "$NAMESPACE" 预览,再带返回的 --expected-plan-revision 与 --execute 删除;rollback 用已记录的 transaction ID、最新预览 revision 与显式执行。

权限边界: 配置不授予外发权限、不跳过审批,也不自动提升处于分阶段迁移中的 authority-store tenant;远端/SSH 读模型保持只读。

文档: https://github.com/huangruiteng/loopx/blob/v1.0.0/docs/guides/personal-workspace-user-guide.md

loopx machine-config describe
loopx machine-config inspect
loopx configure-goal --goal-id "$GOAL_ID"

Periodic reports

启用: 向当前 Agent 明确请求“生成本周项目报告”,即可在当前会话生成 Markdown/HTML。定时报告需自定义 profile 与 Automation;机器/Goal 订阅需显式 enabled: true 和 route_ref。

验证: 检查 weekly preset 的 active、generation_allowed 均为 true,并读回报告产物与有界来源凭据。

停用 / 回退: 单次生成不会留下定时任务;暂停 Automation 或设置 profile 的 enabled: false 可停止定时路径;关闭机器/Goal 订阅可停止订阅投递。

权限边界: weekly preset 不含 sink、不发送;启用且指定 route 的订阅构成持续投递授权,仍受 provider、身份和读回检查约束。

文档: https://github.com/huangruiteng/loopx/blob/v1.0.0/loopx/capabilities/periodic_report/README.md

loopx periodic-report inspect-profile --preset weekly --format json

Lark Goal Channels

启用: 在通知设置 → 飞书 → Connections 选择 Goal、已注册 Agent、群聊、捕获范围及 ingress 模式并保存;可以重连既有话题而不重复建话题。

验证: 读回连接与 Session 绑定;自己发一条新的 @ 消息,Async inbox 可用精确 Goal/Agent 的 drain 查看事件。

停用 / 回退: 在该 Goal 连接中选择 Disconnect,只删除话题路由,保留 Goal、会话、历史和其他连接。

权限边界: Steering 指向精确活跃 turn,Queuing 指向同一精确 Session,Async inbox 等待 drain;捕获范围不扩大 Agent 权限或跨话题回复授权。

文档: https://github.com/huangruiteng/loopx/blob/v1.0.0/docs/guides/personal-workspace-user-guide.md

loopx lark-inbox drain --goal-id "$GOAL_ID" --agent-id "$AGENT_ID"

Workspace stories

启用: 在 Python 3.11+、Node 22.6+ 的源码 checkout 中运行下面命令,打开打印的 loopback URL。

验证: 检查三个项目:每个有四个工作角色、18 项交付任务、两个 owner 决策及两个定时观察;可查看计算生成的预算和敏感性表。

停用 / 回退: Ctrl-C 停止。固定重放用 prepare --root /tmp/workspace-stories 后再 serve --root /tmp/workspace-stories;重开进度选择新的空目录。

权限边界: 场景通过真实 API 重放,来源为编写的场景,不冒充客户结果或实时 Agent 完成记录;状态隔离,不启动调度、Agent、外发、购买或部署。

文档: https://github.com/huangruiteng/loopx/blob/v1.0.0/demo/workspace/README.md

python -m demo.workspace serve

Outbound guidance recall

启用: 在已有 Agent 范围的 Reward Memory 实验中配置 outbound_message.before_send、scoped_feedback、精确 peer_ref: agent:… 和 automation.automatic_recall: true,再应用审阅后的配置。

验证: 读回 experiment-status;对已配置路由使用 lark-inbox send --provider-preflight 且不带 --execute,可以检查但不发送。

停用 / 回退: 设置 automation.automatic_recall: false 或移除此 surface,再应用配置。

权限边界: 偏好建议不授予发送权限;仅覆盖 Goal/Agent 绑定的 send/reply,不拦截任意消息工具或 Goal Topic 自动回复;召回查询不包含原始待发消息。

文档: https://github.com/huangruiteng/loopx/blob/v1.0.0/loopx/capabilities/reward_memory/OUTBOUND.md

loopx configure-goal --goal-id "$GOAL_ID" --reward-memory-config "$REWARD_CONFIG" --reward-memory-agent "$AGENT_ID" --execute
loopx reward-memory experiment-status --goal-id "$GOAL_ID" --agent-id "$AGENT_ID"

Codex provider routing

启用: 在源码 checkout 的同一 Python 环境安装可选 package 及 managed manifest。

验证: 运行 extension doctor 及随包的无内容请求,验证路由/宿主观察合同,不代表验证实际账号归属。

停用 / 回退: 执行 loopx extension disable loopx-codex-provider-routing --execute;独立部署的 CPA operator 需单独停止/卸载服务,禁用此只读扩展不会停止它。

权限边界: 扩展是只读合同编译/资格检查器,不是代理或凭证 authority;CPA 与 operator 分别拥有自己的路由、安装和凭证职责。

文档: https://github.com/huangruiteng/loopx/blob/v1.0.0/packages/loopx-codex-provider-routing/README.md

python3 -m pip install packages/loopx-codex-provider-routing
loopx extension install --manifest packages/loopx-codex-provider-routing/extension.toml --execute
loopx extension doctor loopx-codex-provider-routing --execute
loopx extension run loopx-codex-provider-routing --input-json packages/loopx-codex-provider-routing/examples/request.json --execute

Benchmark study readback

启用: 向 study-dashboard 提供已有的精简 manifest 和公开安全的本地记录 store;按次调用即为 opt-in。

验证: 查看 campaign/arm/case/run 投影、分母及 provisional 覆盖;只有匹配且合格的四臂设计才提供 four-arm contract。

停用 / 回退: 停止调用只读投影即可;若另行启用了上传 provider,通过该扩展自己的生命周期停用。

权限边界: 读模型不启动实验、不改评分、不创建 Todo authority,也不授权上传原始任务、轨迹、日志或隐藏评测数据。

文档: https://github.com/huangruiteng/loopx/blob/v1.0.0/loopx/capabilities/benchmark_toolkit/README.md

loopx benchmark study-dashboard --manifest-json "$STUDY_MANIFEST" --store "$STUDY_STORE" --format json

Signed desktop updates

启用: 旧壳先手动安装新版 macOS App。在恢复与更新中显式检查 stable/main、安装并重启,使 App 与内置运行时配套。

验证: 读回 App 版本和工作区 runtime identity,并运行 version/doctor。stable 使用独立 desktop-stable feed,main 使用完整签名构建。

停用 / 回退: Repair 重装当前 App 的运行时;存在已验证备份时可恢复上版并重启。保留外部安装备份;运行时回滚不承诺逆转未来不兼容的 Goal schema。

权限边界: 仅显式原生动作执行安装,不接受浏览器任意命令/运行时 URL。macOS 为 ad-hoc code signing 加 updater 签名、尚未 notarize,需 Python 3.11+;Windows 手动更新。

文档: https://github.com/huangruiteng/loopx/blob/v1.0.0/apps/desktop/loopx-control-plane/README.md

loopx --version
loopx doctor

发布验证

Validation and provenance (English). Qualification is source-specific. Doubao evolving completed 21 scenarios, 42 actor attempts and 6 contrasts (66 live API calls), with no failed or skipped cases, on candidate 749f9004. That candidate also passed the TypeScript suite (625 passed, one optional skip), real isolated PostgreSQL integration (26 passed) and isolated native tests (25 passed). These are qualification results, not claims of benchmark uplift.

The initial full pytest run had 6,151 passes, two stale CLI-test assertions and 25 skips. After repairing the assertions for the extracted CLI owners, both hosted pytest shards and the aggregate gate passed on 7e94febe. The owner requested no further full-kernel rerun for the final frontend/desktop fixes. Final coverage combines this kernel baseline with scoped delta validation; it is not a new full-suite receipt for the tag.

On 40aaddb6, active-first loading and recovery passed Chromium/WebKit checks, the Lark binding-isolation regression passed, and the installer recovery smoke passed. On final candidate 14c5f877, native maintenance tests passed (24 passed, two environment-dependent cases not rerun in that unit invocation), release Clippy and dashboard TypeScript/build passed, five desktop packaging/feed tests passed, and the packaged browser smoke passed desktop/mobile update, IPC failure/readback recovery, feed failure, confirmation, redaction and startup recovery checks. The exact signed App was installed locally; runtime identity matched the final source and doctor passed required checks. Actual archive signature verification passed and tampering was rejected. Native GUI clickthrough was unavailable; browser and native contract checks are reported separately.

The earlier full-public fleet was not fully green: 512 checks ran with four failures involving the optional native Codex benchmark profile, nested canary installation, disk exhaustion during help/manpage generation and a promotion-concurrency installer timeout. The focused installer retry later passed. Remaining fleet gaps are retained as limitations; this release does not claim every optional benchmark/host profile passed. Doctor also reports non-blocking local skill-route and projection warnings, separate from its passing required checks.

验证与源码对应(中文)。 Doubao evolving 在候选 749f9004 上完成 21 个场景、42 次 actor 尝试和 6 组对照,共 66 次真实 API 调用,无失败或跳过;同一基线还通过 TypeScript(625 通过、1 个可选跳过)、真实隔离 PostgreSQL(26 通过)及隔离原生测试(25 通过)。这些是资格验证结果,不用于宣称 benchmark 提升。

最初全量 pytest 为 6,151 通过、2 个旧 CLI 断言失败、25 跳过。修正模块职责抽取后的旧断言后,7e94febe 的 GitHub 两个 pytest 分片及汇总门禁均通过。遵照维护者要求,最后的前端/桌面修复不再重跑完整内核;发布证据明确区分已有内核基线与最终增量验证。

40aaddb6 通过 active-first 渐进加载、Chromium/WebKit 恢复验证、飞书绑定隔离回归及安装恢复 smoke。最终候选 14c5f877 通过原生维护测试(24 通过;该次单测未重跑两个依赖隔离环境的用例)、release Clippy、前端类型检查和构建、5 项桌面打包/更新源测试,以及覆盖桌面/窄屏、IPC 状态读取恢复、更新源故障、安装确认、脱敏和启动恢复的浏览器回归。本机已安装这份签名 App,运行时身份匹配最终源码,doctor 必需检查通过;真实签名校验通过且能拒绝篡改。原生 GUI 点击验收不可用,未将浏览器验证冒称为原生 GUI 验收。

此前 full-public 的 512 项检查有 4 项失败,分别涉及可选原生 Codex benchmark profile、嵌套 canary 安装、帮助/手册检查时磁盘耗尽及 promotion 并发安装超时;后续安装恢复专项重试已通过。其余 fleet 缺口仍明确保留,不宣称所有可选 benchmark/宿主 profile 均通过。doctor 的本机 skill 路由及 projection 非阻断提示也与必需检查结果分开记录。

Compare: v0.5.4...v1.0.0

Signed-off-by: huangruiteng <huangrt01@163.com>

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Request changes conclusion (author-owned PR; GitHub blocks formal self-review)

Exact head:c3fffa0739da7ca12a7109201f39270bdd27eb0f。结论:Request changes。版本准备方向正确,但当前 CI 有可复现阻塞;没有合并或发布。

动机

为 Personal Workspace 里程碑把 LoopX 包版本从 0.5.4 升为 1.0.0。用户可见结果是安装包和运行时版本标识改变,不是这个 PR 新增 Workspace 功能或完成全部发布资格。README/首屏、最终 release 文案与 contributor attribution 留在各自审批和发布环节,边界清楚。

改动思路

同步两个既有 canonical 字段:构建侧 pyproject.toml:[project].version 和运行时 loopx/__init__.py:__version__。复用既有 release version/manifest/update readback 链路,没有加新版本 resolver 或分支判断。

正向验证:release-version-contract-smoke.py 从 runtime version 推导 tag,并核对 pyproject、manifest、freshness/update readback;本 head 通过。原有负向 fixture 的 manifest/runtime 不匹配检测也在同一 smoke 内通过。release-artifacts-smoke.py 同样通过,但不能据此声称真实公开包或最终 tag 已验证。

具体改动

仅 2 文件、+2/-2,无新增模块、schema 或依赖。

  • loopx/__init__.py:5:运行时导出的 __version__ 从 0.5.4 改为 1.0.0;release tag、manifest 与 freshness 消费这一版本事实。
  • pyproject.toml:7:Python 构建元数据同步到 1.0.0,避免安装包与 runtime 分裂。

两处已有字段同步是适当范围,不需要在版本 PR 中引入架构迁移;但必须处理仍把旧版本写死的活跃测试消费者。

对主干的风险

[P1] 同步版本消费者,修复必现的 required Python CI 失败

tests/test_license_metadata.py:34–35 仍断言根版本为 0.5.4,以及源码包含 __version__ = "0.5.4"。本 PR 更新两个版本字段后,test_python_distributions_declare_apache_2 第一条断言必然失败,下一条也已过时。

远端 Python run 34023584593 的 shard 2 和 pytest aggregate 已失败,日志明确为 assert '1.0.0' == '0.5.4'。独立在 exact head 运行该测试文件得到 1 failed、3 passed,不是 runner 慢或偶发网络问题。

最小修复:保留 Apache-2.0、license-files 和历史许可边界的断言;把当前版本硬编码从许可证测试移除,版本一致性复用现有 release-version-contract 验证,或改为动态核对两个 canonical 字段。不要简单屏蔽整个许可证测试,也不宜仅把常量改为 1.0.0 让下次发布继续踩坑。修复后重跑该文件、两个 release smokes 和 required CI。

其他边界:两行版本改动不更改可选能力 activation、Agent authority、租约或 scheduler obligation;默认关闭隔离/typed 状态分类没有新增行为需验证。1.0.0 标签不等于 staged provider 自动可用,PR body 已说明。最终 clean commit 资格、双语操作说明、tag-range 社区贡献者归属和公开安装包 readback 仍未在本次完成,不能以此 PR 的范围较小豁免发布门禁。

独立验证:两个 release smokes 成功,diff whitespace 检查成功;许可证测试文件 1 failed/3 passed。远端 build、checks、shard 1、Windows、DCO、dependency 成功,shard 2/aggregate 失败,Sonar 与正式发布任务跳过。本次未发布任何包或 tag。

我的整体评价

比例合适,版本源复用正确;阻塞是明确且小的测试维护遗漏,不需要扩大到产品重构。未来改动简化检查建议把许可证测试与“当前发布版本”的重复知识解耦,直接复用既有版本合同,这比每次发布改一轮无关测试常量更稳。

修复该失败后可重新审阅为发布准备候选;当前不批准,不建议绕过 required CI,也不把准备版本与完成 v1.0 发布混为一谈。

English verdict: REQUEST_CHANGES at c3fffa0. The two canonical version fields correctly move to 1.0.0, but the active license test still requires 0.5.4, reproducibly failing required Python CI. Independent validation: both release smokes and diff checks pass; license tests report one failure and three passes. Remove stale version coupling while retaining license assertions and reuse the existing version contract. No package/tag publication or merge performed.

Signed-off-by: huangruiteng <huangrt01@163.com>
…cal state

Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Exact head:a428235f449adf81219ad18c3b86b3fb8bc052ef。结论:Approve。此前阻塞 required Python CI 的旧版本硬编码已经按正确边界解除,当前 diff 没有发现新的 blocker;本次只做评审,没有合并、打 tag 或发布包。

动机

把 LoopX 的 canonical 包版本从 0.5.4 提升到 1.0.0,作为 Personal Workspace 里程碑的发布准备。这个 PR 的用户可见含义是后续构建包、运行时 --version、release manifest 与更新检查共同识别为 1.0.0;它本身不声称新增 Workspace 功能,也不等于已经完成 GitHub/PyPI 发布。

改动思路

版本事实仍由现有两处 canonical 字段共同表达:loopx.__version__ 服务运行时与 release/update 链路,pyproject.toml [project].version 服务 Python 构建元数据。现有 release-version-contract-smoke.py 负责两者一致性及 manifest/freshness/update readback,不引入第二套 resolver。

随后的测试修复也按所属边界处理:

  • 许可证测试只验证 Apache-2.0、许可文件与历史 NOTICE,不再重复记忆“当前版本必须是 0.5.4”;版本一致性继续由专门的 release contract 覆盖,并保留 manifest/runtime 不一致的负向用例。
  • installed-mode dashboard 测试显式把已有 Chat 探测固定为 unavailable,隔离开发机或 runner 上 8791 端口的环境状态;这只修复测试夹具的确定性,不改变 _probe_existing_chat 或 dashboard 的生产行为。

具体改动

Exact base f88e0d8ef4175350af36deda797264297c4ee69a 到 head 共 4 文件、+6/-4:

  • loopx/__init__.py:__version__ 更新为 1.0.0。
  • pyproject.toml:项目版本同步为 1.0.0。
  • tests/test_license_metadata.py:删除与许可证职责无关、每次发版都会过期的两条版本常量断言;所有许可证断言保留。
  • tests/test_dashboard_command.py:为 installed-mode bundle 测试固定端口探测结果,避免复用本机已运行服务导致 serve_chat 未被调用。

独立验证通过:release-version-contract-smoke.py、release-artifacts-smoke.py、许可证测试与目标 dashboard 测试(5 passed)、Ruff、git diff --check。远端 DCO、dependency review、build、checks、两组 Python shard、coverage aggregate pytest 与 Windows 均已通过;评审时仅非阻塞 Sonar 分析仍在运行。

对主干的风险

未发现阻塞项。

删除许可证测试里的版本常量不会形成覆盖空洞:专门的 release version smoke 会动态核对 pyproject/runtime 两个 canonical 字段,并验证 release tag、manifest、install freshness、update plan 和错误版本 manifest 的拒绝路径。dashboard monkeypatch 不触及运行时代码,也没有静默改变默认行为。

这次改动不涉及 typed state、调度/配额义务、default-off 隔离、权限或 provider activation;domain-neutrality、guidance-vs-obligation 与 authority lenses 均无新增风险。版本号合并后,现有文档中 v0.5.4 作为“最近已发布 tag”的历史锚点仍然成立,直至正式发布材料更新;不应把准备版本误读为发布完成。

正式发布仍需单独满足 final clean commit qualification、双语 capability 使用/回滚说明、tag-range 社区贡献者归因、GitHub release 与 PyPI/安装后 readback。PR body 已明确这些边界,因此它们是发布动作的 gate,而不是这个窄版本准备 PR 的代码 blocker。

我的整体评价

这是正向且比例合适的改动:复用既有版本权威,修复了真实 CI 耦合,并让 dashboard 测试从机器局部状态中隔离出来。未来改动简化检查未发现需要在本 PR 顺带加入的重构;版本一致性的专门 owner 已存在,继续保持许可证与版本测试各管各的,比新增共享抽象更清晰、可回滚。

English verdict: APPROVE at a428235f449adf81219ad18c3b86b3fb8bc052ef. The two canonical version fields consistently move to 1.0.0; stale version assertions were removed from the license test without weakening license coverage, and the dashboard fixture is now isolated from local listener state. Independent release smokes, focused tests, Ruff, and diff checks pass; required remote Python, Windows, build, DCO, and dependency checks are green. Final release qualification, bilingual operating guidance, contributor attribution, and package readback remain publication gates. No merge, tag, or package publication was performed.

Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Request changes conclusion (author-owned PR; GitHub blocks formal self-review)

Exact head:749f9004d4ec4336dd573184ab893568995488a6。结论:Request changes。版本与文档同步本身合理、focused/release 验证通过,但当前 exact head 的 required Python CI 明确失败,而且发布说明仍保留“资格验证进行中”的占位文本;在这两个发布门禁关闭前不应合并、打 tag 或发布包。

动机

这个 PR 把 LoopX 的 canonical 包版本从 0.5.4 提升为 1.0.0,并把用户可见的 manpage 与中英文开发者手册发布锚点同步到 1.0,作为 Personal Workspace 里程碑的最终发布准备。旧行为是运行时、构建元数据和公开阅读基线仍指向 0.5.4;合并后的预期结果是 loopx --version、release manifest、doctor/update readback、manpage 和当前文档锚点共同识别 1.0.0。

最小版本修复原本只需同步 loopx.__version__ 与 pyproject.toml,但公开手册和 manpage 也是本次发布声明的活跃消费者,因此随版本一起更新是合理的;许可证测试去掉无关的版本常量、dashboard 测试隔离本机 listener 状态,也分别消除了上次审查发现的测试耦合,没有引入新的产品机制。

改动思路

权威版本仍沿用既有链路:loopx.__version__ 是 runtime/release manifest 的版本源,pyproject.toml [project].version 是构建元数据镜像;现有 release contract 动态验证两者一致。man/loopx.1 和四个中英文 book 入口只同步展示层锚点,不新增 resolver、schema、迁移或权限分支。

正向路径是:构建读取 1.0.0 → runtime 导出同一版本 → CLI/doctor/release manifest/update plan 消费该值 → manpage 与 book 入口展示同一当前发布锚点。负向路径仍由 release-version contract 覆盖:manifest/runtime 不一致会被拒绝;许可证检查继续验证 Apache-2.0 与许可文件,但不再重复记忆当前版本。default-off、typed state、Agent authority、调度/配额和 provider activation 均未被这个 diff 改动;这些 lenses 在本 PR 上验证为不适用,而不是被版本号隐式放宽。

具体改动

Exact base 8f72c21944b9d5ce9a130a7e962939e80c93c43e 到 head 共 9 文件、+12/-10:production 1 文件 +1/-1,构建配置 1 文件 +1/-1,文档/manpage 5 文件 +6/-6,测试 2 文件 +4/-2;没有 generated 文件或机械搬移。

关键代码讲解

  • loopx/__init__.py:5 的 __version__ 从 0.5.4 改为 1.0.0。活跃消费者包括 CLI --version、doctor、state backup、release manifest 和 update freshness,因此这是运行时版本事实源,而不是展示常量。
  • pyproject.toml:7 同步 Python distribution 版本。release-version-contract-smoke.py 动态核对它与 loopx.__version__,并走 manifest、freshness、update plan 的正向和错误版本拒绝路径。
  • man/loopx.1:1 与中英文 book 的 reading guide/index 把当前发布锚点更新为 v1.0.0;同一章节中保留的 v0.5.4 内容仍明确是历史迁移基线,dev-book-publication-smoke.py 对这一区分通过。
  • tests/test_license_metadata.py 删除两条 0.5.4 硬编码,只保留许可证职责;tests/test_dashboard_command.py 将 installed-mode Chat 探测固定为 unavailable,使测试不再受 runner 或开发机 8791 listener 影响,未修改 production launcher。

独立验证通过:release version contract、release artifacts、release readiness docs、developer book publication、CLI help/manpage、exact release commit qualification、许可证与目标 dashboard tests(5 passed)、Ruff、git diff --check。

对主干的风险

[P1] 当前 exact head 的 required Python CI 仍然失败,不能作为发布合并点

远端 test-shard (1)、test-shard (2) 与 aggregate pytest 均失败。两个实际失败分别是:todo --help 的 lazy-owner module 断言不再成立,以及 inspect-journal 测试仍 monkeypatch 已不存在的 complete_goal_todo。我在本 head 上稳定复现 2 个失败,并在 exact base 8f72c21944b9d5ce9a130a7e962939e80c93c43e 上也复现同样 2 个失败,证明它们不是这 9 文件 diff 引入的回归,而是当前 main 基线已有的 release blocker。

最小修复不是在版本 PR 里屏蔽测试:先在 main 上修复对应 CLI owner/fixture contract,验证 required shards 变绿,再把 release branch 更新到该 main 并重跑全部 required checks。只要这个 exact head 仍是红 CI,就不能用 focused smokes 替代合并门禁。

[P1] 发布说明仍明确声明最终资格尚未完成

PR body 的“发布验证”仍写着 Final exact-source qualification is in progress. This local draft is not ready for publication until the completed evidence replaces this paragraph.。这会让 1.0 release notes 自己声明尚不可发布,也缺少最终 exact-source 证据。请在最终 clean commit qualification 完成后,用实际 commit/tag、required checks、artifact/package 安装后 readback 和已知限制替换该占位段;不要在验证完成前改成笼统的“全部通过”。

版本、文档与测试隔离的改动比例是合理的,没有发现 default-off、authority semantics、typed-state 或行为披露方面的新 blocker;风险集中在发布门禁,而不是 1.0.0 两个 canonical 字段的设计。

我的整体评价

改动方向正向,代码量与问题规模匹配,也正确复用了既有版本权威和验证链;新增的文档/manpage 同步让 1.0 对用户更一致。当前请求修改不是要求扩大实现,而是要求关闭两个事实性的发布 gate:恢复 required Python CI,并把占位资格声明替换为可读回的最终证据。

完成后重新触发 exact-head 审查即可;在此之前不建议合并,不应绕过 checks,也不应把“版本字段已改为 1.0.0”误当成 GitHub release、PyPI 包与安装后 runtime 已经发布。

English verdict: REQUEST_CHANGES at 749f9004d4ec4336dd573184ab893568995488a6. The 1.0.0 version, manpage, book-anchor, and test-isolation changes are proportionate and pass focused release, documentation, exact-commit, Ruff, and diff validation. However, both required Python shards still fail on this head (the same failures reproduce on base main), and the PR body still says final exact-source qualification is in progress. Fix main, update/re-run this release head to green, and replace the placeholder with verified commit/tag/artifact/package readback before merge or publication.

Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
…lures

Signed-off-by: huangruiteng <huangrt01@163.com>
@huangruiteng

Copy link
Copy Markdown
Collaborator Author

No remaining blocking findings in the final diff at 14c5f877.

The final updater repair addresses a concrete transport mismatch: custom-protocol IPC uses the HTTP Origin header, while the capability previously matched /chat/. The capability now uses the exact App origin and retains its two-command, main-window restriction. Regression coverage proves both transport URL forms match and other ports, hosts and schemes remain denied. Plugin errors become bounded public categories; unknown/private diagnostics stay out of the UI. Native status-read failures and an unavailable feed no longer share a misleading network diagnosis.

Product/architecture: 1.0 combines the reviewed long-horizon control plane with the approved Workspace/README milestone. Startup progressively renders the directory and active Goals, retries transient failures, and loads stopped Goal details on demand. The updater keeps App/runtime pairing, signature verification and explicit installation confirmation. The related simplification pass reuses Tauri's origin/pattern contract rather than adding another URL matcher or a second updater. Main risk is the desktop IPC/installed-user boundary; focused native, packaging, browser, real installation and signature checks cover that delta.

Validation: exact-scope quality receipt cqr_bc69ef3cf08bf265e067 verified; premerge passed 16 selected checks with zero failures, alongside direct diff/Python hygiene and public-boundary checks. Native maintenance: 24 passed, two environment-dependent cases not run in that invocation; actual final App installation, runtime identity, required doctor checks and signed-archive/tampering validation passed separately. Release Clippy, dashboard TypeScript/build, five desktop Python tests and packaged desktop/mobile recovery browser smoke passed. Chromium/WebKit loading recovery and focused installer recovery passed on the immediate predecessor; the final installed Workspace also loads in WebKit without page errors.

Kernel provenance: full hosted pytest passed on 7e94febe; the owner waived repeating the complete kernel for the final UI/desktop delta. Doubao evolving's 66 live calls passed on 749f9004. The earlier full-public fleet had four failures; the complete bilingual release body preserves their scope and the subsequent installer recovery instead of claiming a green fleet. Native GUI clickthrough is unavailable and is not claimed. Current hosted desktop/full-pytest jobs may still be running; local scoped qualification is complete.

Merge decision: owner-authorized release merge, preserving the exact qualified candidate for the v1.0.0 tag. Signed stable feed publication and remote asset verification follow publication; social posts remain for separate owner confirmation.

中文复核:最终 diff 无剩余阻断项。修复原生 IPC 的 origin/path 权限匹配,保留精确端口、窗口及两个命令的权限范围;本机状态读取、更新源、网络及签名错误采用脱敏分类。渐进加载、失败重试、历史 Goal 按需加载与已批准 README 均已纳入。精确质量回执有效,premerge 16 项通过;原生、前端、实际安装、运行时身份和签名反例验证通过。完整内核沿用既有通过基线,不冒称最终源码重跑了全量;full-public 缺口和原生 GUI 验收限制在发布说明中明确保留。按维护者授权合并发布,群消息及 X 仍需另行确认。

@huangruiteng
huangruiteng merged commit d6e8387 into main Sep 6, 2026
17 checks passed
@huangruiteng
huangruiteng deleted the codex/release-1.0.0-20260906 branch September 6, 2026 12:52

This branch was previously deployed

1 inactive deployment
pypi — 14c5f877 Deployed Sep 6, 2026 by huangruiteng via publish-pypi #1747
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant