fix(steward): commit team assignments atomically and simplify result recovery - #4633
Conversation
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
…ution Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
…nt readback Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
…tion Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
|
已核对最终提交
English: the local assignment/recovery slice is implemented and validated on this head. It remains subject to maintainer review/merge and remote CI; full receiver collaboration and cross-host execution are not claimed. |
…mparison Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
|
已修正 before 对照图:现在使用 该提交只更换 before PNG;最终质量凭证已重新核验,canary 19/19 通过、0 失败。前文代码检查证据仍适用于未改变的实现;远端 CI 尚排队,继续留待维护者合并。 English: corrected the before-image provenance and pinned both images to the final commit. Image readback and final premerge validation passed; no runtime changes in this commit. |
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
|
已在 失败点是 本次只更新现有浏览器验收:按动作类型和 Goal 定位提案,确认后检查已分配任务、待安排任务及原因,验证完成后确认按钮消失,并删除过期的“缺少结果展示”判定。未修改生产代码、超时或跳过条件。 验证: English: repaired stale steward-journey expectations. The complete packaged workspace suite and final premerge checks pass locally; the new remote frontstage run is queued. |
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Reviewed head: a4c69218937a99413d0d7bdc41fec82ff03b5666; base: 9060ddc915100ac882d42ad91dbfc6b639bd8848.
按当前 pull-request-review 能力的 policy_revision=6 执行完整审查。结论:没有剩余阻断项;自审中发现的部分分配恢复回执问题已在最终提交修复。
动机
这次改动对应 overall roadmap R1:确认后的任务身份、失败恢复和原入口读回必须可信。
用同一组公开合成输入调用真实 Chat 和 Todo 读回,主干的 legacy 路径把 alpha/beta 两条同文 lane 合成一条,最终只剩 beta 的任务;FileAuthorityStore 路径则留下 alpha 的一条任务和失败卡片。最终提交在两条路径均保留两个独立任务。普通 Todo create 仍按原规则去重。
交付判断是有价值的完整增量:本地分配、提交恢复和产品读回已闭合;并不宣称 R1–R4 整体完成。接收方采纳、真实执行、依赖产物消费、独立验收和结果返回,仍按原 RFC 的 R2/R3/R4 验收。任务分配本身不能证明团队协作成立。
改动思路
准入和整批计划归 typed work-items,复用现有 Todo planner。legacy 将任务和回执放进一次原子写;canonical 将它们放进一次 AuthorityStore CAS,复用 CoordinationCommandReceipt 和 projection outbox。Python 保留存储适配,不再逐条决定和补写任务。
历史回执有独立价值:接收方修改、完成或删除任务后,不能从当前 Todo 反推当初操作是否提交。相同 proposal/lane 的回执先于新准入检查恢复,避免重新造任务。canonical 仍通过既有 writer fence,不能降级成 legacy 写入。
只修改去重规则不能解决部分效果和响应丢失;另建调度器又超出问题。当前批次复用既有 authority,是更小且完整的修复。相关重构已删除重复的 Python 准入/逐条 writer,并提取共享结果组件;未引入无生产调用方的 worker 生命周期。
具体改动
- Runtime:typed preview/transaction、两种存储适配、effect dispatch、Chat fingerprint/恢复和 governed settlement;只有团队事务使用 operation/lane 身份,普通 create 保持原默认值。
- 产品:workspace model/mapper、drawer、结果组件、中英文文案和样式。先显示已分配任务和待安排原因,原计划折叠;完成后移除确认按钮,失败重试使用原 proposal。打包 JS/CSS/HTML 与源码一致,并保留前一已发布 bundle。
- 指引和文档:manager skill 明确新分配确认的范围、owner/receiver 权限以及 advisory quota/stop;两份双语 RFC checkpoint 保留后续协作门槛。before 图片使用精简前实际卡片,after 为验证后的精简结果。
- 验证:扩展现有真实 Chat、File/PostgreSQL 和浏览器场景,替换旧的逐条部分写入断言。frontstage 的 steward journey 已按实际分配结果验收,不再等待过期标题或通用成功句。
关键代码讲解
planTeamTransaction:接收确认计划和当前事实;先恢复已有回执,否则校验全部 lane,再输出整批 Todos 和回执。相同文本不会把两个 lane 合并,末条非法也不会留下前缀写入。commitTeamPlan:从 AuthorityStore 读取历史操作或完整 head,检查 provider revision,通过既有 CAS 同时提交任务与回执;响应不确定由 command receipt 恢复。apply_team_plan:Chat/governed 的实际适配入口;legacy 写入使用既有 fence 和原子 writer,canonical 使用原有投影交付。投影未完成仍返回可恢复失败。ChatActionService._apply_team_plan:owner 分配不冒充接收方作者;无可安排任务仍失败,未提交计划过期仍拒绝。最终修复让reused优先于原有gap_count,因此恢复和缺口可以同时准确表达。TeamPlanResult:只从回执成员关系展示已分配项,用已准入预览补充任务标签;缺口原因保留,当前执行进度通过 Goal 查看,历史结果不冒充当前执行状态。
对主干的风险
主要风险是重试覆盖接收方进展,以及共享 Todo planner 意外改变普通任务语义。已通过以下反例验证:并发确认、最后一条非法、跨 Agent 未授权提交、canonical 已变而 Markdown 未刷新、提交响应丢失、投影失败,以及提交后任务被修改/完成/删除。恢复读取历史结果,不重建被删除的任务,也不新增 lease。
本次自审确实发现了浏览器 fixture 与后端的差异:fixture 对带缺口的重试报告 recovered,而 Chat 先按 gap_count 返回 partially_applied。此前真实测试只覆盖满编计划。新增同一真实测试的带缺口分支后,旧代码失败;修正分支顺序后通过,且回执保留原缺口、接收方修改后的文件逐字节不变。
| 验证 | 结果与适用范围 |
|---|---|
| 同一真实入口的主干/最终提交对照 | 14 类输入 × legacy/File 两后端,覆盖合法、缺失/空输入、重叠非法条件、完整错误信息、优先级、归属、普通去重、stale 和 replay。主干违反独立 lane 身份断言,最终提交通过。 |
| 最终提交 Python | 50 个 team-plan/Chat/准入/真实 canonical 投影用例通过。 |
| 真实 File/PostgreSQL 16 | 本次重跑 11/11 通过、0 跳过,覆盖并发、原子性、失败、历史恢复及显式缺口。首次本地重跑因临时数据库端口未恢复而连接失败;修正启动参数后全部通过。 |
| 未改变的 TS/backend 范围 | 4f177272 的完整 TS 1775 个通过;隔离 PostgreSQL store 105 个通过。已核对该版本到最终提交的 control-plane 实现没有变化。 |
| 未改变的打包前端 | 6680abcc 的 build、完整 packaged suite 7/7 通过;最终提交仅改 Python 回执分支和回归测试,资产无变化。浏览器 fixture 证明交互,后端原子性由真实存储测试证明。 |
| 最终静态与合并前检查 | ruff、配置内 mypy 22 文件、diff/public-boundary 检查通过;canary 19/19、0 失败;精确差异质量凭证有效。 |
非 manager 的 _session_objective 在主干/最终提交逐字节一致,manager 指引变化是明确披露的范围修正;普通 Todo 的双后端读回一致。PR 没有新增默认关闭功能,安装或注册不触发任务执行。
语义与 CI 对齐
复用现有 Todo/claim/CAS/command-receipt 词汇,仅扩展团队批次历史回执;intent_basis 仍是原 source-facts digest,没有冒充强版本化意图。quota/stop 是计划参考,显式要求未实现的 enforcement 会在效果前拒绝。错误和规则保持 Goal 通用,不引入业务场景专用内核义务。
按当前能力配置 wait_for_ci=false,本次审查不查询、轮询或等待远端 CI。仓库要求的本地验证已完成。可选外部 authority-service endpoint 用例未运行;这不替代已完成的真实 PostgreSQL store 验证,也不声称 Lark/cross-host 执行已验收。
我的整体评价
APPROVE。完整差异的必要性成立:它修复真实的数据/恢复缺陷,同时让发起入口正确读回结果。没有剩余阻断项。代码成本主要是一个共享 typed planner、必要的两种存储适配和结果呈现,没有把“创建任务”包装成更广的协作协议。
剩余兼容边界:旧的已应用卡片和旧结果仍可读;事务改造前已留下部分效果的卡片需基于现有任务显式重规划,不自动迁移。回滚应停止新计划生产并保留现有任务/回执。R2/R3 下一步仍须真实 receiver adoption、依赖产物、独立验收和自动返回,而不是再添加 readiness 字段。
Maintainer-authorized self-merge is eligible only after the unchanged exact head passes the capability-owned merge-readiness check; admin bypass does not replace that gate.
English verdict: APPROVE - a4c6921. Atomic assignment and historical recovery are validated; self-review fixed partial-plan recovery labeling without rewriting receiver work. Final Python 50/50, real File/PostgreSQL 11/11, unchanged packaged UI 7/7 and premerge 19/19 passed. Adoption, execution and cross-host collaboration remain outside this slice.
Goal And Delivered Outcome
R1 team confirmation currently writes each lane independently. Equal-text lanes can collapse into one Todo, and a lost response or later write failure strands the card after partial effects.
This change moves admission and whole-batch planning into the typed work-items owner. Each proposal/lane has a stable identity; all admitted tasks and their operation receipt commit together. Retrying the same operation recovers its historical result without recreating work that a receiver changed, completed or deleted. Chat preserves projection failures as recoverable failures. The packaged result card leads with assigned tasks and pending reasons, collapses the original plan, and removes the completed confirmation button. A failed or uncertain apply retries the original proposal instead of creating another one.
Base:
main. Consolidates the useful behavior from #4592, #4598 and #4600; replaces #4602's per-lane recovery and #4604's unqualified readiness ladder. #4605's cross-host lease remains outside this transaction.Scope And Continuation
The delivered slice is local assignment, commit recovery and product readback. Existing Todo admission, AuthorityStore CAS/receipts, legacy writer fences and projection outbox remain the owners; no new capability, provider or scheduler is introduced. Ordinary Todo create retains role/text deduplication.
Behavior changes: owner confirmation assigns registered peers without impersonating receivers as authors; an Agent-originated settlement cannot assign another peer. Quota/stop declarations remain advisory and explicit enforcement claims are rejected. Historical recovery uses
team_plan_commit_recovered; old already-present receipts remain readable. Already-applied cards remain historical records. Older pre-transaction partial cards must be replanned against their existing tasks; this does not migrate their effects automatically.Assignment does not establish receiver adoption, a lease, execution, dependency consumption or independent acceptance. R1–R4 retain those obligations, shared-intent acceptance and executor qualification. Ordinary already-authorized work does not acquire a universal second confirmation. Lark currently has a presentation-frame seam but no team-plan delivery/callback route; this PR does not claim that journey. These boundaries keep the storage repair independently verifiable and reversible.
Future-facing refactor applied: removed the Python preview/per-lane writer, reused the existing typed create planner and command receipt, and preserved the previous shipped bundle instead of intermediate local builds.
Validation
a4c69218937a99413d0d7bdc41fec82ff03b5666: 50 related Python tests and the real File/PostgreSQL team-plan suite (11/11). The complete packaged Personal Workspace suite (7 scenarios) and unchanged-bundle rebuild ran at6680abcc; assets remain unchanged. Full backend suites ran at4f177272; focused File/PostgreSQL tests ran atfd4ea85a. The typed control-plane implementation is unchanged; the final Chat correction reports historical recovery even when the original plan retains staffing gaps.team_plan.test.ts: 11 passed, no skips; real File/PostgreSQL concurrency, invalid final lane, failed commit, lost response, receiver edits/completion/deletion and declared capability/audience gaps.build:chat,smoke:team-plan-proposal, and completesmoke:personal-workspace-packaged(all 7 scenarios). Final-head browser covers compact results, original-plan expansion, completed-card action, injected post-write response loss and same-proposal retry without another durable write. The fixture retains the stored plan after apply.9060ddcwith the same browser fixture fails the new acceptance/gap readback expectations; candidate passes. The old per-lane implementation also fails the independent equal-text identity counterexample.Frontend / Visual Evidence
UI impact: changed confirmation/result card. Source data: synthetic. Before is the actual verbose card at
4f177272immediately before this UI refinement; after is the validated compact card. Desktop result state shown; result and original plan are separated without changing surrounding navigation. The public task/assignee display is derived from the admitted preview and committed receipt.Type / Area
Bug fix and refactor with disclosed behavior changes; control plane and dashboard. Final exact-diff qualification is valid (35 files; 0 blockers, 0 warnings, 1 advisory about remaining collaboration acceptance). Premerge passed all 19 selected checks with 0 failures on final head
a4c692189. Exact-head self-review and the capability-owned merge-readiness gate govern the maintainer-authorized merge; configured review policy does not wait for remote CI.