Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
34 changes: 26 additions & 8 deletions docs/architecture/rfcs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,18 @@ This index was last audited against `main` on **2026-09-04**. Update an entry
whenever its RFC status, promoted behavior, or meaningful delivery boundary
changes.

## Overall Product and Delivery Roadmap

- [LoopX Overall Roadmap v0](loopx-overall-roadmap-v0.md)
([中文版](loopx-overall-roadmap-v0.zh-CN.md))
- **RFC status:** Draft portfolio roadmap.
- **Delivery on `main`:** Planning and audit evidence, not runtime promotion.
- **Current boundary:** Maps all 30 pre-existing primary RFCs and important
non-RFC domains into 13 streams, G0–G5 product milestones and R1–R7 core
execution cards. Covers product, multi-LoopX-Agent collaboration/handoff,
kernel, hosts, memory, cost, security, operations, research, releases,
community and adoption. Domain contracts retain their authority gates.

## Control-Plane Kernel, State, And Migration

- [Human-confirmed domain operations v0](human-confirmed-domain-operations-v0.md)
Expand Down Expand Up @@ -95,8 +107,10 @@ changes.
default-off local shadow/cutover foundations are on `main`
([#3529](https://github.com/huangruiteng/loopx/pull/3529),
[#3669](https://github.com/huangruiteng/loopx/pull/3669),
[#3798](https://github.com/huangruiteng/loopx/pull/3798)). No provider-first
runtime promotion or remote shared-authority service has shipped.
[#3798](https://github.com/huangruiteng/loopx/pull/3798)). In-process PostgreSQL
service admission and identity rotation also exist;
deployed authenticated remote service and provider promotion remain distinct
qualification gates.
- [Shared Goal Alignment and Governed Amendment Protocol v0](shared-goal-alignment-and-governed-amendment-v0.md)
([中文版](shared-goal-alignment-and-governed-amendment-v0.zh-CN.md))
- **RFC status:** Draft, under maintainer review.
Expand Down Expand Up @@ -173,15 +187,17 @@ changes.
- [Capable Agent Manager and Semantic Work Handoff v0](capable-manager-semantic-handoff-v0.md)
([中文版](capable-manager-semantic-handoff-v0.zh-CN.md))
- **RFC status:** Draft, under maintainer review.
- **Delivery on `main`:** Proposal; existing manager/inbox foundations are reused.
- **Delivery on `main`:** Partial; private runtime profile, executor settings,
team-plan confirmation and initial Todo materialization shipped.
- **Current boundary:** Proposes ordinary host-tool autonomy, persistent scoped
conversations, long-horizon semantic continuation and automatic result delivery.
Includes an official Grok Bot study distinguishing availability from goal
continuation; M0–M4 and A1–A20 define delivery and acceptance, with explicit
alignment, shared-authority and TS migration dependencies.
Cross-session restoration, execution takeover and automatic return are specified
separately, reusing #4094 with optional Obelisk gap recall under its own scope.
Runtime-profile promotion and generic handoff migration have not shipped.
Full runtime-profile qualification and generic handoff migration remain open.


- [Explicit Todo Continuation — Stage A](cross-session-memory-substrate-v0.md)
([中文版](cross-session-memory-substrate-v0.zh-CN.md))
Expand Down Expand Up @@ -296,10 +312,12 @@ changes.
- [Long-Running Agent Reliability Diagnostics and Governed Delivery v0](long-running-agent-reliability-diagnostics-governed-delivery-v0.md)
([中文版](long-running-agent-reliability-diagnostics-governed-delivery-v0.zh-CN.md))
- **RFC status:** Draft, product direction and delivery contract.
- **Delivery on `main`:** Direction only.
- **Current boundary:** The observer-first adoption path, matched benchmark
qualification, and governed delivery package are proposed; no unified
product contract has been promoted.
- **Delivery on `main`:** Default-off L1 diagnostic prototype and first DSH
event-source adapter implemented.
- **Current boundary:** The capability-owned README records the prototype;
C0 adapter fidelity, C1 non-interference and measured overhead remain
required before P0 exit. Broader governed delivery and commercial adoption
remain proposals.

RFCs must not contain internal conversations, private links, local filesystem
paths, credentials, raw transcripts, or non-public organizational context.
6 changes: 6 additions & 0 deletions docs/architecture/rfcs/agent-session-execution-modes-v0.md
Original file line number Diff line number Diff line change
Expand Up @@ -454,6 +454,12 @@ at least one real-host row: a live process, a real bind, and a real restart.
- **Recovery.** An interrupted executor turn is reconciled before retry. A
validated result is journaled before lifecycle writeback.

### Long-horizon managed route (2026-09-16)

[Roadmap](loopx-overall-roadmap-v0.md) R2 first qualifies a steward and 2–3 actual managed workers across Turns; R6 qualifies local/cloud execution on one authority, then R7 expands active scale. M1–M4 here retain host admission ownership. Team-plan `ready` cannot replace binding, qualification, claim/lease or actual process readback.

DSH steward Chat is currently single-segment, read-only and without cross-turn host sessions; `turn run-once` is a separate bounded execution path. The next slice proves successor wake, cancellation/stop, crash recovery and returning stale-executor fences with packaged frontend/CLI/Lark readback. An executor name, one segment or multiple registrations cannot establish continuous managed execution. Disconnection never switches attached hosts to managed, and unqualified hosts retain their existing boundary.

## 12. Normative delivery plan

| Milestone | Shipped behavior | Entry gate | Exit evidence | Rollback |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -364,6 +364,12 @@ claim 与完成回执,以及"只有经过验证的回写才推进工作"这一
- **恢复。** 被中断的执行器 turn 在重试前先被协调。经过验证的结果在生命周期回写之前
先被记录。

### 长程 managed 执行路线(2026-09-16)

[统一路线](loopx-overall-roadmap-v0.zh-CN.md) R2 先验一个管家与 2–3 个真实 managed worker 的跨 Turn 闭环;R6 再验本地/云端同 authority,R7 才扩大活跃规模。本 RFC M1–M4 继续拥有宿主接入,不用团队计划的 `ready` 取代 binding、资格、claim/lease 或实际进程读回。

目前 DSH 管家 Chat 是单段、只读、无跨 turn 宿主会话;`turn run-once` 是另一条有界执行路径。下一切片要证明 successor wake、取消/停止、崩溃恢复及旧执行器返回 fence,经 packaged frontend/CLI/Lark 回读真实状态。不能仅增加一个 executor 名称、启动一个片段或绑定若干 Agent 就声称持续 managed 模式完成。attached host 不因掉线而改为 managed,未验收宿主保持原资格边界。

## 12. 规范性交付计划

| 里程碑 | 交付行为 | 进入门槛 | 退出证据 | 回滚 |
Expand Down
10 changes: 8 additions & 2 deletions docs/architecture/rfcs/capable-manager-semantic-handoff-v0.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# RFC: Capable Agent Manager and Semantic Work Handoff (v0)

- **RFC status:** Draft, under maintainer review
- **Delivery maturity:** Proposal; existing foundations are identified in Section 4
- **Delivery maturity:** Partial; private runtime profile, team-plan confirmation and Todo materialization shipped; complete M1–M4 remain unqualified.
- **Authors / owners:** LoopX maintainers; manager engineering owner
- **Created / last normative revision:** 2026-09-13 / 2026-09-15
- **Implementation baseline:** `7eb4b7bb1661bd5eff63a8725a33169792d5964b`
Expand Down Expand Up @@ -61,6 +61,12 @@ Include global manager conversations, host-native investigation, ordinary author

Do not build a replacement agent runtime, a second scheduler, an external-agent marketplace, a new repository API, a universal workflow DSL or a duplicate task database. A substantial refactor of the current manager, collaboration and adapter boundaries is explicitly in scope; conserving current code volume or module names is not an acceptance goal. Do not require OpenViking, a shared online database or A2A to make local handoffs correct. Do not copy private reasoning traces or complete historical transcripts into every request. Complex financial and other domain effects remain owned by their capabilities and execution adapters.

### Current cross-RFC route (2026-09-16)

At `43d362532`, the private `manager_runtime` profile, steward executor configuration and team preview→frontend confirmation→initial Todo materialization have implementations. #4547/#4548/#4552 supply confirmation UI, bundle and browser fixture; they do not prove worker execution. DSH Chat remains a bounded read-only segment without cross-turn host sessions and cannot borrow Codex `trusted_owner` qualification.

The [overall roadmap](loopx-overall-roadmap-v0.md) records verified F1–F7 and R1–R7. Repair R1 commitment preservation, stale basis and recovery first, then qualify R2 small teams; M2/M3 converge through R3, and M4 requires real user journeys. Section 4 retains its older baseline as migration input, not an override of this checkpoint. Partial merges do not complete M1–M4. Parallel joins, pipeline dependencies, peer help/review, execution responsibility continuation and cross-host collaboration between long-running LoopX Agents follow the roadmap Section 5 matrix. R2 requires real inter-Agent handoff; M2/M3 cannot reduce to steward broadcasts or one-turn forwarding.

## 4. Current-system contract: audited facts

The baseline already has substantial reusable machinery:
Expand Down Expand Up @@ -501,7 +507,7 @@ If this program changes a provider, retention or authority-source profile, its a

### 11.2 Execution order and integration receipts

1. **Start M1; finish baseline reconciliation in that PR.** Record the exact source head and actual runtime/entrypoint call sites. Fix the owner-private profile and existing readback/feedback. Run A1–A3/A12. Do not deliver a standalone inventory framework.
1. **Complete and qualify M1 through R1/R2 without rebuilding shipped profiles/entrypoints.** Record the exact source head and actual runtime/entrypoint call sites. Fix the owner-private profile and existing readback/feedback. Run A1–A3/A12. Do not deliver a standalone inventory framework.
2. **Replace one complete M2 request transaction, then attach receivers.** Begin from `manager_context` request/tracking/return producers and both real consumers, including the shipped #4094 CLI continuation adapter (§5.13). Publish the before/after ownership map, migration mapping and the migration economics review artifact (§5.12). Preserve accepted work state through existing commands; qualify crash-between-commits and legacy/promoted sources before widening producer rollout. Use existing alignment source-basis reads, not a copied classifier.
3. **Close M3 automatic return and user visibility.** Independent reply recovery can ship in parallel with steps 1–2. Integrate the generic producer only after its receipt contract is stable; exercise A8–A10, A13–A16 and A17/A20 across the actual entrance/receiver/return paths. With the source session gone, verify the same committed result/outbox identity, reconnect recovery and audience isolation through packaged frontend, Lark and CLI readback.
4. **Promote a named M4 cohort and remove the replaced paths.** Keep provider default, Goal-intent authority and capability qualifications explicit. Shared-amendment commit integration follows its upstream readiness; until then the UI says proposal/admission or unsupported commit, never “Goal changed.” Provider source migration follows the shared-authority program rather than this release.
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# RFC:强能力 Agent 管家与语义工作交接(v0)

- **RFC 状态:** Draft,待维护者审阅
- **交付成熟度:** 提案;已有基础见第 4 节
- **交付成熟度:** Partial;私人运行 profile、团队计划确认与 Todo 物化已交付,完整 M1–M4 未验收。
- **作者 / 责任人:** LoopX 维护者、管家工程负责人
- **创建 / 最近规范修订:** 2026-09-13 / 2026-09-15
- **实现基线:** `7eb4b7bb1661bd5eff63a8725a33169792d5964b`
Expand Down Expand Up @@ -61,6 +61,12 @@

不重造 Agent runtime、第二套调度器、外部 Agent 市场、新仓库 API、通用工作流 DSL 或任务数据库。明确允许对现有管家、协作和 adapter 边界大幅重构;保住现有代码体积或模块名字不是验收目标。本地交接正确性不依赖 OpenViking、在线共享数据库或 A2A。每个请求不携带私人推理轨迹和完整历史。复杂金融等垂域效果继续归各 capability 和执行 adapter。

### 跨 RFC 当前路线(2026-09-16)

在 `43d362532`,本 RFC 的私人 `manager_runtime` profile、管家执行器配置,以及团队计划预览→前端确认→首批 Todo 物化已有实现。#4547/#4548/#4552 提供确认 UI、打包产物及 browser fixture;它们不证明 worker 已运行。DSH Chat 仍是只读有界片段,无跨 turn 宿主会话,不能借用 Codex `trusted_owner` 的资格。

[整体路线总纲](loopx-overall-roadmap-v0.zh-CN.md) 记录已复核 F1–F7 与 R1–R7 执行卡。优先修 R1 承诺保留、stale basis 和恢复,再验 R2 小团队;M2/M3 按 R3 收敛,M4 需真实用户旅程。第 4 节的旧基线保留为迁移输入,不能覆盖本检查点;不因局部切片合并将 M1–M4 标为完成。 多个长程 LoopX Agent 的并行汇合、流水线依赖、peer 求助/复核、执行责任接续和跨 host 协作,统一按路线第 5 节协作矩阵验收;R2 必须包含真实 Agent 间 handoff,M2/M3 不能退化为管家广播或单轮转发。

## 4. 当前系统:已核对的基线事实

已有大量基础应该复用:
Expand Down Expand Up @@ -501,7 +507,7 @@ M1 不必等通用 handoff 重构。M3 独立的格式/投递修复可先用已

### 11.2 执行顺序与衔接回执

1. **启动 M1,在该 PR 内完成基线对齐。** 记录精确 source head、真实 runtime/入口 caller;修主人私人 profile 和已有读回/反馈;验 A1–A3/A12。不单独交付盘点框架。
1. **按 R1/R2 补齐并验收 M1,不重建已交付 profile/入口。** 记录精确 source head、真实 runtime/入口 caller;修主人私人 profile 和已有读回/反馈;验 A1–A3/A12。不单独交付盘点框架。
2. **替换一个完整 M2 请求事务,再接接收方。** 从 `manager_context` request/tracking/return producer 和两种真实消费者开始,提交前后 owner 图、迁移映射、migration economics 审阅工件(§5.12)。工作状态继续走已有命令;扩大 producer 上线前验提交间崩溃和 legacy/promoted source。复用 alignment source-basis 读取,不复制分类器。 显式纳入已交付 #4094 CLI 接续 adapter(§5.13)。
3. **收口 M3 自动回传和用户可见性。** 独立正文恢复可与前两步并行;通用 producer 待回执契约稳定再接。沿真实入口/接收方/返回路径验 A8–A10、A13–A16、A17/A20;在来源 session 已消失时,通过 packaged frontend、飞书、CLI 读回核实同一已提交结果/outbox 身份、重连恢复和受众隔离。
4. **晋级指定 M4 cohort,并删除被替换路径。** 明确 provider 默认、Goal-intent authority、capability 资格。共享 amendment commit 待上游就绪;此前 UI 只能说提案/准入或不支持提交,不能说“Goal 已修改”。provider source 迁移按 shared-authority 计划,不夹进本次发布。
Expand Down
6 changes: 6 additions & 0 deletions docs/architecture/rfcs/desktop-execution-frontends-v0.md
Original file line number Diff line number Diff line change
Expand Up @@ -768,6 +768,12 @@ trust binding fails closed.
- Use synthetic provider fixtures for committed tests and make live provider
tests explicit and opt-in.

### Team coordination product loop (2026-09-16)

#4547/#4548/#4552 delivered team-preview confirmation UI, packaged resources and a browser fixture; the confirmation entry is no longer unimplemented. Follow [roadmap](loopx-overall-roadmap-v0.md) R1 for semantically accurate partial/gap/stale readback, R2 for actual worker execution and R3 for automatic return/restart recovery. The confirmation fixture does not prove the complete Lark loop.

Frontend/Lark consume the same proposal, receipt and audience projection; confirmed plans cannot imply execution. Every implementation includes real packaged-frontend interaction and applicable Lark qualification, or explicitly names the untested surface. First-viewport/primary-CTA implementation changes still require concrete preview approval. This revision edits RFCs only, not UI.

## Delivery slices

### Slice A: Agent-scoped Lark connection
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -638,6 +638,12 @@ executor 精确版本、完成情况、延迟、动作数、人工介入、禁
- 不把私有部署或协作上下文复制到公共 fixtures、截图、示例或文档中。
- 已提交测试使用合成 provider fixtures,并把真实 provider 测试设为显式可选。

### 团队协调的产品闭环(2026-09-16)

#4547/#4548/#4552 已交付团队预览确认 UI、打包资源及 browser fixture,不再把确认入口列为未实现。按[统一路线](loopx-overall-roadmap-v0.zh-CN.md) R1 补语义一致的 partial/gap/stale 回读,R2 验 worker 实际执行,R3 验自动回报和重启恢复。现有确认 fixture 不能证明 Lark 端完整闭环。

前端/Lark 消费同一 proposal、receipt 和 audience projection;运行状态不能由计划已确认推断。每个实现批次含 packaged frontend 的实际交互和 Lark 适用路径验收,或明确说明未验收。涉及首屏/主 CTA 的实现继续先展示具体预览并获批准;本次仅更新 RFC,不修改 UI。

## 交付切片

### 切片 A:Agent 级 Lark 连接
Expand Down
Loading