Skip to content

fix(goal_frontier): carry the agent-owned frontier identity into writeback ACK checkpoints - #4645

Closed
huangruiteng wants to merge 1 commit into
mainfrom
codex/long-chain-writeback-ack-owned-identity
Closed

huangruiteng wants to merge 1 commit into
mainfrom
codex/long-chain-writeback-ack-owned-identity

Conversation

@huangruiteng

@huangruiteng huangruiteng commented Sep 17, 2026 •

Copy link
Copy Markdown
Collaborator

A semantic writeback ACK drops the agent-owned frontier identity between long-chain observation and persisted checkpoint. A peer claiming shared unclaimed work can therefore rearm an already acknowledged chain even though the agent-owned material basis is unchanged.

The two-field propagation fix is being superseded by a cohesive typed checkpoint refactor: one TypeScript owner for observation, source and writeback checkpoint construction; Python retains legacy source encoding and IO adaptation. The replacement will qualify both ACK paths through synthetic real-entrypoint tests before this PR is retired.

Compatibility must preserve revision-only historical ACKs and rearm on changes to owned material work. Maintenance timestamps alone do not alter material identity. The initial patch does not qualify end-to-end recovery or complete the wider collaboration roadmap. Maintainer review and merge remain separate.

…k ACKs

The long-chain ACK fence already matches on the identity over the rows this
agent owns (`frontier_owned_identity`, added in #4610), but the typed-delta
writeback path never carried that identity:

- `LongTodoChainObservation.to_trigger()` omitted it, so the recorded
  obligation trigger only exposed `frontier_revision`;
- `replan_obligation_trigger_checkpoints()` rebuilds the ACK checkpoints from
  those triggers, so writeback ACKs recorded a revision-only checkpoint.

The revision covers the whole selectable set, which also contains rows nobody
has claimed yet. Any peer lane claiming or editing such a row moves the
revision, so a writeback ACK re-armed the pending `long_todo_chain` replan
obligation on the next wake even though this agent's own work basis had not
changed. Observed live: the 15:24 ACK for `replan-132c272361cab7f1` recorded
`trigger_checkpoints: [{kind, frontier_revision}]` only, and the next guard
reported `rearmed_after_obligation_id: replan-132c272361cab7f1`.

The prompt-path ACK (`replan_successor_transition_ack`) was unaffected because
it composes `long_todo_chain_source_checkpoint`, which already carries the
identity; this change makes both ACK paths record the same fence.

Validation: `tests/control_plane/test_goal_frontier_replan_rules.py::test_writeback_ack_owned_identity_absorbs_a_peer_claim`
reproduces the peer-claim re-arm and fails on either dropped hop (verified by
reverting each half independently); 151 focused control-plane tests pass.

Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>

@huangruiteng huangruiteng left a comment •

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This exact-head review is superseded by the current owner-requested implementation assessment. Head: 32082e9.

The patch repairs two dropped-field hops, but checkpoint construction still has separate Python paths and the successor path repeats frontier reads. A replacement is being developed with a single TypeScript checkpoint owner and real writeback/readback validation. The previous review also overstated timestamp semantics: maintenance timestamps do not change the material revision; owned material fields do.

Historical validation reported 151 focused tests for this patch. That evidence does not qualify the forthcoming replacement head, live deployment, or the complete collaboration journey. No merge readiness is asserted here.

English verdict: Superseded assessment; hold this PR for the typed checkpoint replacement and its exact-head validation.

@huangruiteng

Copy link
Copy Markdown
Collaborator Author

Superseded by #4655. The replacement retains the owned-frontier ACK fix, unifies checkpoint construction in the existing TypeScript owner, and covers successor causality through real CLI and canonical File-provider readback. Wrong origins, stale/ambiguous successors and incomplete sources remain rejected.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant