Repository navigation
fix(cli): reuse canonical bootstrap for source invocations - #5244
Conversation
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
e0a66fe to
440cefc
Compare
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Exact head: 440cefc; base: 6643f36.
动机
没有阻塞性发现;本结论只批准可独立验收的入口修复,不批准整批期限任务完成。真实 managed/canary caller 会执行源模块,旧源入口先导入所有命令,偏离 console 的轻量启动路径;console 的已绑定 scheduler follow-up 还可能在外层控制器 guard 前替换进程。本次把入口收敛回现有 owner,减少无关加载并恢复该权限边界。原多命令验收的 20 秒预算仍未达成,后续成本优化继续由原任务承担。
改动思路
源模块执行先进入既有 entrypoint,普通常用命令交给 selected dispatcher,拒绝参数及其他命令回到完整 parser,库方式导入的完整 API 保留。已绑定 follow-up 正常复用现有 TS executable;outer-controller 标记存在时不提前替换进程,让既有 guard 解析实际 Goal 并判断写权限。标记只选择宿主路线,不新增权限事实,也不复制 Goal 匹配规则。缺少 Node 的正常绑定路线仍关闭失败。此边界符合 TS 重构 RFC 的单一 owner 原则:Python 只做宿主适配,TS 与原控制面继续负责调度、状态、回执和结算。
具体改动
全量 diff 为四个文件,508 行增加、4 行删除;生产部分只有14行增加、4行删除,其余为337行回归和157行双语说明。测试不是只比较两个新 helper:新解释器实际执行源模块,与 console 比较加载、完整诊断及输出;真实 File/SQLite 读回在移除 Markdown 展示后仍保留原 provider revision,且不改权威状态。追加的两个范围测试覆盖读取、现有及后注册的独立 Goal、改变 actor 不能绕过保护,以及 controller 解除保护后的真实 ACK 提交与单独读回。fixture 无业务 Todo 时允许普通 health-failure 读取,不把它包装成业务恢复。
关键代码讲解
loopx/cli.py:7的 module-execution 分支在 command imports 前调用现有 bootstrap;按名字再次导入完整 parser 时不会重入此分支,避免递归并保留库 API。loopx/entrypoint.py:20的_native_scheduler_followup_argv在外层控制器标记为精确值1时停止提前 native dispatch。它不做 Goal 权限判断,实际规则仍在既有 guard,正常绑定及缺 Node 分支保留。loopx/cli_runtime.py:344的既有_dispatch_selected先执行 guard,再解析 registry、进入 handler;新源入口复用它,拒绝发生在 provider effect 前。loopx/cli_runtime.py:360的既有_run_full_cli按名字导入完整 API,selected parser 拒绝的参数恢复原诊断,未新增第二套 grammar。
对主干的风险
最强反例是“禁止绕过但误拦所有 Goal”或“返回 blocker 却无法恢复”。真实 module/console 反例均通过:受保护 Goal 即使 actor 改变仍拒绝且无 scheduler state;同一 registry 的独立 Goal 及启用后新 Goal 可实际写回;原 controller 解除保护后原 Goal 也能提交并读回。这证明调度写入恢复,不证明整段金融工作已交付。独立 base/head probe 还能识别旧 eager 加载和提前 exec;exec 截获本身不是实际 TS 写入证明,真实回执/state 测试补足该限制。
源入口现在有意采用既有 console help 和 usage-policy:首条合资格命令可能在 stderr 告知,JSON stdout 不受污染,现有 opt-out 和 machine choice 保留。不能称与旧入口“没有告知”的默认逐字等价。前端/Lark 无新 schema、配置 owner 或控件,原 usage-settings HTTP roundtrip 已验证;完整 wheel 的原前端资源构建、校验和隔离安装也通过,但不冒充新 transport E2E 或现用 runtime 升级。
语义与 CI 对齐
原声明、source/lease fence、quota 扣额及状态 owner 不变;这是 S2 单一权威与 S10 恢复成本的增量,不是 TS cutover 或预算晋级。按当前 Goal 的 review policy,未查询或等待 GitHub CI。本 head 的十文件完整回归168项通过,无跳过;Ruff、编译、配置内 mypy19文件与 diff 检查通过。保留此前一轮未改动 usage timing 断言失败:2.817秒超过1.650+1秒;四次独立 base/candidate 重跑和之后两轮完整矩阵通过,未放宽断言。宿主负载不是已证明的失败归因。旧28项 ABBA有候选变慢样本,不能推断整批稳定提速;没有扩大20秒预算。回滚只需撤回此 bootstrap delta,不涉及状态格式迁移。
我的整体评价
APPROVE 的范围是上述完整、可逆的入口切片。长程状态与后续调用契约保持,权限拒绝与恢复通过真实路径验证;用户入口减少无关加载、保留诊断,并明确披露默认告知变化。与在旧入口底部加 wrapper 或新建 parser/权限 owner 相比,当前方案是更小的有效修复。剩余风险是共享宿主的延迟波动及尚未达成的整批20秒验收;这两者没有被文件数、启动中位数或测试通过数量冒充关闭。合并仍由维护者决定,现用安装与 provider 晋级尚未发生。
English verdict: APPROVE - exact head 440cefc; reuse the existing source/console bootstrap and Goal-scoped guard, preserving independent Goals and real scheduler recovery. 168 local tests, static checks and isolated packaged-wheel smoke passed; the frozen whole-batch20s acceptance remains open, and no live deployment is claimed.
What this delivers / 本次交付
Source callers (
python -m loopx.cli) now reuse the existing console bootstrap instead of importing every command owner before dispatch. The importedloopx.cli.main/build_parserAPI remains the full-parser compatibility surface.源 CLI 复用现有 console bootstrap,消除先加载全部命令 owner 的入口漂移;库方式调用保留完整 parser。这是 Python 宿主适配器修复,复用现有 TS/command owners,不增加 Python 策略源、命令目录或 provider。
The bound scheduler route also preserves the existing outer-controller write guard: an outer-controlled invocation cannot process-replace the dispatcher before that guard runs. Missing Node on a normally bound TS route still fails closed; manual/unbound compatibility remains.
已绑定 scheduler 路线保留外层控制器写保护,不能在 guard 执行前 process-replace;正常 TS 路线缺少 Node 时仍关闭失败,手工/无绑定调用继续兼容。
Changed surfaces / 变更范围
loopx/cli.py: route only module execution throughloopx.entrypoint.main; retain imported full-parser APIs and canonical fallback diagnostics.loopx/entrypoint.py: keep outer-controlled calls in the dispatcher that already owns Goal matching and write denial.tests/control_plane/test_source_cli_entrypoint.py: 32 fresh-process cases covering owner loading, parser fallback, TS routing, no-Node failure, guard ordering, usage disclosure/opt-out, real File/SQLite reads, independent-Goal scope and actual scheduler-write recovery.docs/reference/source-cli-entrypoint.md: bilingual ownership, compatibility, user journey, qualification and honest timing boundaries.Validation and limits / 验收与局限
440cefcfca376c03190384d8546658e912b5fc8e, based on main6643f367064b9921c864db75a042979fddc4b8c3(includes separately merged perf(contract): overlap bounded full-tree file reads #5239), the full source/CLI/usage/completion/scheduler/native-controller/public-reader matrix passed: 168 passed, 1 existing warning, 165.59 s, with no skips. This includes all 32 source-entry cases. The two supplementary source/console scope-and-recovery cases also passed independently before the final matrix.中文:完整回归、独立入口/权限反例和真实 File/SQLite 读回均已执行。保留此前耗时断言失败及复验结果,没有放宽断言、删除验收或把 host load 推断当作根因证明。
This does not close the whole-batch deadline task. Pre-rebase ABBA runs of the same unchanged 28-case scheduler matrix all passed but took base 129.28/123.24 s and candidate 120.63/191.03 s. The adverse candidate sample does not establish a stable whole-batch improvement; the original 20-second budget remains unmet and unchanged. The separately merged #5239 is not retroactively included in those measurements.
不宣称整批期限已达成。 28 项原断言全部保留,但候选有变慢样本,完整负载仍远超 20 秒。继续保留任务与验收缺口,不把启动改进算作 terminal 完成,也不扩大 validator deadline。
An alternating fresh-process startup probe on the shared active host measured
--versionmedians 0.759 → 0.040 s andquota --help0.805 → 0.072 s. These are tiny/help startup measurements only, not business operation latency, isolated cold-machine cost or p95.Product path and compatibility / 产品路径与兼容性
Affected: source CLI and managed/canary callers invoking that module. Source now intentionally shares console help and existing usage policy: first eligible use may disclose on stderr; JSON stdout stays pure; help/version do not observe; existing opt-outs and machine settings are preserved. This is not byte parity with the old source entry's absence of disclosure.
受影响入口为源 CLI 及调用它的 managed/canary;首条使用告知和机器设置统一到现有 owner。前端/Lark 不新增控件或配置/schema,继续消费相同投影与回执;既有 usage-settings HTTP roundtrip 已验收。本次没有前端源码或布局变化;为验证完整 wheel,已按既有流程生成并校验打包资源,不冒充新前端/Lark transport E2E 验收。
The installation above is an isolated artifact check only, not live deployment or provider promotion. The TS migration RFC's single-owner boundary remains; core merge stays with maintainers.
没有宣称已安装、provider 晋级或 TS 全量切换;LoopX core 合并仍交维护者。