From bc1b8638a534d6adc8662bf6cee6072191ec56a1 Mon Sep 17 00:00:00 2001 From: huangruiteng <14976749+huangruiteng@users.noreply.github.com> Date: Wed, 16 Sep 2026 18:24:04 +0800 Subject: [PATCH] fix(peer): stop the hard-cut guard flagging ordinary runtime prose The peer-agent hard-cut boundary guard keeps legacy hierarchy vocabulary out of the repository, and its denylist contains the phrase `controller owns` because that phrase described the retired controller-over-sub-agent model. Two docstrings and one comment use the same words for a different subject -- the runtime controller holding the runtime root and its machine-configuration store -- so the guard reports them as escaped hierarchy and the peer-agent canary fails on `main`. That red blocks the pre-merge gate for any diff that selects the canary, which is why it is worth fixing rather than working around. The prose is reworded to say the same thing without the flagged phrase: the controller *holds* the runtime root, the credential scope is the runtime root *this controller resolves*, and the steward channel reads *this controller's* machine configuration. No code, no behavior and no contract changes, and the guard keeps its full strictness rather than being narrowed. Verified: examples/control_plane/peer-agent-hard-cut-boundary-smoke.py ok, examples/control_plane/peer-agent-runtime-v1-smoke.py ok (it also runs the continuation-state-machine, task-orchestration and quota-spend-workspace smokes), tests/test_chat_manager_context.py and tests/capabilities/test_steward_executor_machine_defaults.py 25 passed. Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com> --- loopx/chat_manager.py | 6 +++--- loopx/chat_runtime.py | 4 ++-- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/loopx/chat_manager.py b/loopx/chat_manager.py index 64a15931b6..a70af92a87 100644 --- a/loopx/chat_manager.py +++ b/loopx/chat_manager.py @@ -187,7 +187,7 @@ def is_manager_channel(value: Any) -> bool: def steward_machine_defaults(controller: Any) -> Mapping[str, Any] | None: """Return the machine-configured steward defaults this channel reads. - The runtime controller owns the runtime root and therefore the + The runtime controller holds the runtime root and therefore the machine-configuration store, so the resolution below never re-derives which document is authoritative. A caller that has no such owner -- a transport that does not serve the Dashboard, or a test double -- resolves through its @@ -213,8 +213,8 @@ def controller_runtime_root(controller: Any) -> Path | None: def operator_credential_resolution(controller: Any) -> dict[str, Any]: """Return the credential-resolved environment and source for one owner. - A key stored from a product surface lives under the runtime root the - controller owns, so the same owner that resolves the machine's steward + A key stored from a product surface lives under the runtime root this + controller resolves, so the same owner that resolves the machine's steward defaults resolves where the credential came from and what it resolved to. A controller without that owner -- a transport outside the Dashboard, or a test double -- resolves to an unread environment, which lets the channel diff --git a/loopx/chat_runtime.py b/loopx/chat_runtime.py index dffd226590..ba4f4924f3 100644 --- a/loopx/chat_runtime.py +++ b/loopx/chat_runtime.py @@ -394,8 +394,8 @@ def _start_adapter( if manager_profile is not None else None ), - # The steward channel's executor, model and effort come from the - # machine configuration this controller owns. + # The steward channel's executor, model and effort come from this + # controller's machine configuration. **( manager_model_config( machine_defaults=self.steward_executor_defaults()