feat(collaboration): recover delegated team work after context loss - #4731
Conversation
…ecords Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
…readback Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Reviewed head: 733b67de09e81d2c4622f3c5e47e7af865639836; baseline: 3d5fc5b462f8af1b357b32a227d200d15a338a47.
动机
未发现阻塞项。此前 coordinator 丢失对话上下文后,即使委派仍在持久日志中,也需要记住每个 operation ID 才能继续读取。这个 PR 让主力和承担协调的成员各自找回原请求,避免靠重新派工来恢复上下文。它是总体路线图 R2/R3 的一个可独立使用、验证和回滚的增量;不代表完整团队 readiness、通用 Agent 创建或无人值守唤醒已完成。
改动思路
CLI、显式启用的 MCP、新挂载工具的 Goal Chat 共用 Delegations.operations,读取已有 requester journal。没有第二套团队注册表或完成状态。Python 负责有界枚举和 IO,TS 负责查询约束及读回分类;每个返回项仍通过既有 Delegations.read 检查当前绑定与执行,accepted 还要重跑 pinned 验证、读 canonical Todo 完成状态并比较准确产物。
最小替代方案是让调用方记录 ID,但无法解决 ID 已丢失的情形;再建 fleet store 会增加同步权威。这里复用既有执行 owner,并把枚举放进邻近的小读模型,符合该边界下一步演进的需要。没有增加投研或云厂商特定的控制面规则。
具体改动
17 个文件涵盖 6 个运行时文件、5 个测试文件与 6 个说明/RFC 文件。实际入口为 delegation operations、list_delegations 与新工具 schema 中的 action=operations。文档同步说明 live paging、accepted 的当前核验、恢复与启动的区别,以及后续 readiness、身份/profile 创建、原请求返回的顺序。
关键代码讲解
read_delegation_inventory:先验证 requester,再从其哈希目录选取最多limit + 1个地址。记录身份必须与地址一致;逐条调用原 reader。单条损坏或撤销变成unavailable,不吞掉健康兄弟项;目录本身不可读则整体报错。读取不调用 start/resume。delegationInventoryItem:复用既有 observation 状态集合。accepted 必须带当前产物引用与 SHA-256;返回页省略正文。读回缺失不能变成 accepted,恢复资格也保持未知。has_more与page_readback_complete分开表达,不能据一页判断整个 Goal 完成。handle_delegation:新增分页入口,拒绝不相容的单项选择和执行参数。MCP 与 Chat 调用同一方法;Chat 继续要求当前执行 turn 和原 sender/config,并保留 pause fence。
Codex 恢复已有原生线程时不会更新动态工具 schema。因此新操作说明只位于新 TOOL.description,共享 GUIDANCE 保持原样;不为了安装新工具替换未完成的线程。有 shell 能力的原会话可独立使用 CLI。这里不改变 frontend 设置或组件,Goal Chat 复用已有工具调用和回包展示;现有成员 chips 仍仅是对话观测,不宣称完整清单。Lark 对等入口尚未交付。
对主干的风险
最强风险是把历史 accepted 当成当前有效结果。已通过实际 CLI 做语义变异:临时绕过 _accepted,产物篡改断言立即失败;恢复代码后通过。当前代码下,撤销绑定、损坏记录或改变产物都不会留下虚假的 accepted,调用方应沿原 ID 核对而非自动重派。
- 41 个共享 Python 用例通过,覆盖 File/SQLite、真实 CLI/stdio 子进程、断连恢复、独立验收、范围隔离和损坏分支。模型执行使用明确的 fixture host。
- 最终 44 个 Chat/native 用例通过;7 个 TS 用例、完整 TS typecheck、Ruff 和公开内容扫描通过。
- 同一合成状态在 baseline/head 上执行 5 组旧 CLI 路径,完整 stdout、stderr 与退出码一致,注册表/配置/日志未变。关闭执行时的 5 个 MCP 工具完整 schema、原已启用工具 schema、共享 Chat guidance 也一致。
- 另外通过真实 CLI 在两种隔离 provider 上验证分页大小、添加兄弟记录、移除诊断文字、单条损坏、撤销绑定和不可读目录。展示变化不改变已有工作事实;不完整来源不会变成空清单。
- 新 CLI 从此前真实 DSH/Ark 合成团队中找回 3 个主力请求及 1 个嵌套请求,4 份产物重新通过验收,零 Agent 启动,Goal 保持 active。这是既有真实执行的恢复验证,不是新一轮四 Agent 执行。
语义与 CI 对齐
沿用既有 delegation/验收词汇与 TS 权威;新增的是派生读模型,不是状态迁移或调度义务。按 review policy revision 7,wait_for_ci=false,未查询、轮询或等待远端 CI;本地必要检查仍全部执行。风险选择的 premerge 验证覆盖 5 个直接检查和 14 个选定检查。首次 catalog e2e 的嵌套检查触及超时,原限制未修改,单独重跑与完整重跑通过。最后一次 schema 修改使旧质量凭据失效,已针对最终 diff 重新审核和记录有效凭据。无验证豁免或人工 hold。
我的整体评价
APPROVE,限于上述准确提交和范围。这个增量让持久协作真正具备“重新接上旧工作”的入口,且保留既有验收权威。相邻的结构优化已应用:共用读模型与原 reader,避免 host dispatcher 增长成第二个状态 owner。
剩余限制是 live paging 不提供快照隔离,accepted 重验可能耗时,调用方应选择较小页;已有原生会话工具 schema 不热升级。完整 readiness、经授权的身份/profile provisioning、闲置主力唤醒和跨宿主完整 inbox/queue/steer 仍须后续单独验收。本 PR 涉及运行时,保留给维护者合并。
English verdict: APPROVE - 733b67de09e81d2c4622f3c5e47e7af865639836. Requester-scoped recovery reuses current canonical acceptance without launching Agents. Real CLI/MCP tests, baseline parity, semantic mutation, mixed-team readback, type/lint checks and risk-selected local premerge validation passed. Existing native tool schemas remain unchanged; live paging, provisioning and idle-host wake limitations are explicit.
A coordinator that loses conversation context can now recover its delegated work without remembering every operation ID.
loopx delegation operations, enabled MCPlist_delegations, and newly tool-equipped Goal Chataction=operationsread the same existing requester-scoped journal. They return original request/task identities, current execution observations and compact accepted artifact references.This advances roadmap R2/R3's recovery path for both leads and coordinating members. It adds no Agent registry or scheduler. The TS collaboration owner validates paging and readback states; the existing
Delegations.readstill checks current grants, canonical completion, pinned validation and exact artifacts. A corrupt record, revoked binding or stale artifact becomes an individualunavailableitem rather than hiding healthy work or claiming acceptance. Journal access failure remains an error. Listing never starts or resumes an Agent.The operating guide and bilingual roadmap/session RFCs now distinguish durable work recovery, actual readiness, approved identity/profile provisioning and original-request continuation. Paging is live rather than snapshot-isolated, and accepted-item validators can be expensive; callers choose a bounded page. No frontend settings or polling changes are needed: Goal Chat uses its existing explicitly enabled collaboration tool and reply surface, retaining sender/config pins and pause fencing. Already enrolled native threads retain their old tool schema on resume; the new recovery guidance is confined to the new tool description and never forces thread replacement. Its recent member chips remain conversation observations.
Validation:
Generic Agent creation, automatic wake of an idle attached lead, complete fleet readiness and Lark parity remain outside this slice. Private state, credentials, local paths and raw experiment evidence are excluded. This runtime PR is left for maintainer merge.