Skip to content

fix(cli): reuse canonical bootstrap for source invocations - #5244

Merged
huangruiteng merged 1 commit into
mainfrom
codex/completion-validation-batch-20260928
Sep 28, 2026
Merged

huangruiteng merged 1 commit into
mainfrom
codex/completion-validation-batch-20260928

Conversation

@huangruiteng

@huangruiteng huangruiteng commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

What this delivers / 本次交付

Source callers (python -m loopx.cli) now reuse the existing console bootstrap instead of importing every command owner before dispatch. The imported loopx.cli.main / build_parser API remains the full-parser compatibility surface.

源 CLI 复用现有 console bootstrap,消除先加载全部命令 owner 的入口漂移;库方式调用保留完整 parser。这是 Python 宿主适配器修复,复用现有 TS/command owners,不增加 Python 策略源、命令目录或 provider。

The bound scheduler route also preserves the existing outer-controller write guard: an outer-controlled invocation cannot process-replace the dispatcher before that guard runs. Missing Node on a normally bound TS route still fails closed; manual/unbound compatibility remains.

已绑定 scheduler 路线保留外层控制器写保护,不能在 guard 执行前 process-replace;正常 TS 路线缺少 Node 时仍关闭失败,手工/无绑定调用继续兼容。

Changed surfaces / 变更范围

  • loopx/cli.py: route only module execution through loopx.entrypoint.main; retain imported full-parser APIs and canonical fallback diagnostics.
  • loopx/entrypoint.py: keep outer-controlled calls in the dispatcher that already owns Goal matching and write denial.
  • tests/control_plane/test_source_cli_entrypoint.py: 32 fresh-process cases covering owner loading, parser fallback, TS routing, no-Node failure, guard ordering, usage disclosure/opt-out, real File/SQLite reads, independent-Goal scope and actual scheduler-write recovery.
  • docs/reference/source-cli-entrypoint.md: bilingual ownership, compatibility, user journey, qualification and honest timing boundaries.

Validation and limits / 验收与局限

  • At exact head 440cefcfca376c03190384d8546658e912b5fc8e, based on main 6643f367064b9921c864db75a042979fddc4b8c3 (includes separately merged perf(contract): overlap bounded full-tree file reads #5239), the full source/CLI/usage/completion/scheduler/native-controller/public-reader matrix passed: 168 passed, 1 existing warning, 165.59 s, with no skips. This includes all 32 source-entry cases. The two supplementary source/console scope-and-recovery cases also passed independently before the final matrix.
  • Ruff, compile checks and configured mypy (19 source files) passed; whole diff whitespace checks passed.
  • Independent counterfactual consumers rejected the old eager source entry, deliberately reintroduced unrelated-owner loading and removal of the outer-controller route guard. Mutations were restored before committing.
  • Real File/SQLite reads retained exact canonical provider revisions with Markdown display removed, with no authority mutation or recovery from that display.
  • Real receipt-bound scheduler tests reject the protected Goal even if the actor changes, allow both existing and newly registered independent Goals, and commit/read back the original Goal's scheduler state after its controller releases the guard. Ordinary health-failure reads are distinguished from guard rejection; this does not claim that an unrelated Goal's business task or health is repaired.
  • The normal packaged-frontend build and bundle verification passed, followed by a wheel build and an isolated wheel installation outside the source tree. Installed source/console version, help, canonical parser rejection, pure JSON and protected-write/no-state checks passed (12 invocations). The wheel contains the packaged chat assets and TS follow-up owner; installed bootstrap files exactly match this head. The initial wheel attempt correctly refused a missing prebuilt chat bundle; the normal build supplied it without bypassing the packaging gate. No frontend source changed and the live installed runtime was not replaced.
  • One earlier pre-rebase large run had 151 passed / 1 unchanged usage timing assertion failed (foreground 2.817 s vs baseline 1.650 s + 1 s). The assertion was not changed. Four independent alternating base/candidate reruns of that case passed (3.45, 3.80, 3.08, 2.95 s pytest duration); the latest full matrix also passed. Shared active-host load is a limitation, not proven failure attribution.

中文:完整回归、独立入口/权限反例和真实 File/SQLite 读回均已执行。保留此前耗时断言失败及复验结果,没有放宽断言、删除验收或把 host load 推断当作根因证明。

This does not close the whole-batch deadline task. Pre-rebase ABBA runs of the same unchanged 28-case scheduler matrix all passed but took base 129.28/123.24 s and candidate 120.63/191.03 s. The adverse candidate sample does not establish a stable whole-batch improvement; the original 20-second budget remains unmet and unchanged. The separately merged #5239 is not retroactively included in those measurements.

不宣称整批期限已达成。 28 项原断言全部保留,但候选有变慢样本,完整负载仍远超 20 秒。继续保留任务与验收缺口,不把启动改进算作 terminal 完成,也不扩大 validator deadline。

An alternating fresh-process startup probe on the shared active host measured --version medians 0.759 → 0.040 s and quota --help 0.805 → 0.072 s. These are tiny/help startup measurements only, not business operation latency, isolated cold-machine cost or p95.

Product path and compatibility / 产品路径与兼容性

Affected: source CLI and managed/canary callers invoking that module. Source now intentionally shares console help and existing usage policy: first eligible use may disclose on stderr; JSON stdout stays pure; help/version do not observe; existing opt-outs and machine settings are preserved. This is not byte parity with the old source entry's absence of disclosure.

受影响入口为源 CLI 及调用它的 managed/canary;首条使用告知和机器设置统一到现有 owner。前端/Lark 不新增控件或配置/schema,继续消费相同投影与回执;既有 usage-settings HTTP roundtrip 已验收。本次没有前端源码或布局变化;为验证完整 wheel,已按既有流程生成并校验打包资源,不冒充新前端/Lark transport E2E 验收。

The installation above is an isolated artifact check only, not live deployment or provider promotion. The TS migration RFC's single-owner boundary remains; core merge stays with maintainers.

没有宣称已安装、provider 晋级或 TS 全量切换;LoopX core 合并仍交维护者。

Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
@huangruiteng
huangruiteng force-pushed the codex/completion-validation-batch-20260928 branch from e0a66fe to 440cefc Compare September 28, 2026 05:48

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Exact head: 440cefc; base: 6643f36.

动机

没有阻塞性发现;本结论只批准可独立验收的入口修复,不批准整批期限任务完成。真实 managed/canary caller 会执行源模块,旧源入口先导入所有命令,偏离 console 的轻量启动路径;console 的已绑定 scheduler follow-up 还可能在外层控制器 guard 前替换进程。本次把入口收敛回现有 owner,减少无关加载并恢复该权限边界。原多命令验收的 20 秒预算仍未达成,后续成本优化继续由原任务承担。

改动思路

源模块执行先进入既有 entrypoint,普通常用命令交给 selected dispatcher,拒绝参数及其他命令回到完整 parser,库方式导入的完整 API 保留。已绑定 follow-up 正常复用现有 TS executable;outer-controller 标记存在时不提前替换进程,让既有 guard 解析实际 Goal 并判断写权限。标记只选择宿主路线,不新增权限事实,也不复制 Goal 匹配规则。缺少 Node 的正常绑定路线仍关闭失败。此边界符合 TS 重构 RFC 的单一 owner 原则:Python 只做宿主适配,TS 与原控制面继续负责调度、状态、回执和结算。

具体改动

全量 diff 为四个文件,508 行增加、4 行删除;生产部分只有14行增加、4行删除,其余为337行回归和157行双语说明。测试不是只比较两个新 helper:新解释器实际执行源模块,与 console 比较加载、完整诊断及输出;真实 File/SQLite 读回在移除 Markdown 展示后仍保留原 provider revision,且不改权威状态。追加的两个范围测试覆盖读取、现有及后注册的独立 Goal、改变 actor 不能绕过保护,以及 controller 解除保护后的真实 ACK 提交与单独读回。fixture 无业务 Todo 时允许普通 health-failure 读取,不把它包装成业务恢复。

关键代码讲解

  1. loopx/cli.py:7 的 module-execution 分支在 command imports 前调用现有 bootstrap;按名字再次导入完整 parser 时不会重入此分支,避免递归并保留库 API。
  2. loopx/entrypoint.py:20 的 _native_scheduler_followup_argv 在外层控制器标记为精确值1时停止提前 native dispatch。它不做 Goal 权限判断,实际规则仍在既有 guard,正常绑定及缺 Node 分支保留。
  3. loopx/cli_runtime.py:344 的既有 _dispatch_selected 先执行 guard,再解析 registry、进入 handler;新源入口复用它,拒绝发生在 provider effect 前。
  4. loopx/cli_runtime.py:360 的既有 _run_full_cli 按名字导入完整 API,selected parser 拒绝的参数恢复原诊断,未新增第二套 grammar。

对主干的风险

最强反例是“禁止绕过但误拦所有 Goal”或“返回 blocker 却无法恢复”。真实 module/console 反例均通过:受保护 Goal 即使 actor 改变仍拒绝且无 scheduler state;同一 registry 的独立 Goal 及启用后新 Goal 可实际写回;原 controller 解除保护后原 Goal 也能提交并读回。这证明调度写入恢复,不证明整段金融工作已交付。独立 base/head probe 还能识别旧 eager 加载和提前 exec;exec 截获本身不是实际 TS 写入证明,真实回执/state 测试补足该限制。

源入口现在有意采用既有 console help 和 usage-policy:首条合资格命令可能在 stderr 告知,JSON stdout 不受污染,现有 opt-out 和 machine choice 保留。不能称与旧入口“没有告知”的默认逐字等价。前端/Lark 无新 schema、配置 owner 或控件,原 usage-settings HTTP roundtrip 已验证;完整 wheel 的原前端资源构建、校验和隔离安装也通过,但不冒充新 transport E2E 或现用 runtime 升级。

语义与 CI 对齐

原声明、source/lease fence、quota 扣额及状态 owner 不变;这是 S2 单一权威与 S10 恢复成本的增量,不是 TS cutover 或预算晋级。按当前 Goal 的 review policy,未查询或等待 GitHub CI。本 head 的十文件完整回归168项通过,无跳过;Ruff、编译、配置内 mypy19文件与 diff 检查通过。保留此前一轮未改动 usage timing 断言失败:2.817秒超过1.650+1秒;四次独立 base/candidate 重跑和之后两轮完整矩阵通过,未放宽断言。宿主负载不是已证明的失败归因。旧28项 ABBA有候选变慢样本,不能推断整批稳定提速;没有扩大20秒预算。回滚只需撤回此 bootstrap delta,不涉及状态格式迁移。

我的整体评价

APPROVE 的范围是上述完整、可逆的入口切片。长程状态与后续调用契约保持,权限拒绝与恢复通过真实路径验证;用户入口减少无关加载、保留诊断,并明确披露默认告知变化。与在旧入口底部加 wrapper 或新建 parser/权限 owner 相比,当前方案是更小的有效修复。剩余风险是共享宿主的延迟波动及尚未达成的整批20秒验收;这两者没有被文件数、启动中位数或测试通过数量冒充关闭。合并仍由维护者决定,现用安装与 provider 晋级尚未发生。

English verdict: APPROVE - exact head 440cefc; reuse the existing source/console bootstrap and Goal-scoped guard, preserving independent Goals and real scheduler recovery. 168 local tests, static checks and isolated packaged-wheel smoke passed; the frozen whole-batch20s acceptance remains open, and no live deployment is claimed.

@huangruiteng
huangruiteng merged commit 4277682 into main Sep 28, 2026
26 of 33 checks passed
@huangruiteng
huangruiteng deleted the codex/completion-validation-batch-20260928 branch September 28, 2026 12:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant