Conversation
Signed-off-by: Lihua <1017343802@qq.com>
Signed-off-by: Lihua <1017343802@qq.com>
Signed-off-by: Lihua <1017343802@qq.com>
Signed-off-by: Lihua <1017343802@qq.com>
Signed-off-by: Lihua <1017343802@qq.com>
Signed-off-by: Lihua <1017343802@qq.com>
Signed-off-by: Lihua <1017343802@qq.com>
Signed-off-by: Lihua <1017343802@qq.com>
Signed-off-by: Lihua <1017343802@qq.com>
Signed-off-by: Lihua <1017343802@qq.com>
|
This pull request has merge conflicts with Choose the remote for the base repository, not an out-of-date fork. git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEADFor a same-repository clone whose Keep the DCO |
…dback Signed-off-by: Lihua <1017343802@qq.com>
Signed-off-by: Lihua <1017343802@qq.com>
…alification Signed-off-by: Lihua <1017343802@qq.com>
Signed-off-by: Lihua <1017343802@qq.com>
Signed-off-by: Lihua <1017343802@qq.com>
Signed-off-by: Lihua <1017343802@qq.com>
Signed-off-by: Lihua <1017343802@qq.com>
Signed-off-by: Lihua <1017343802@qq.com>
Signed-off-by: Lihua <1017343802@qq.com>
Signed-off-by: Lihua <1017343802@qq.com>
|
This pull request has merge conflicts with Choose the remote for the base repository, not an out-of-date fork. git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEADFor a same-repository clone whose Keep the DCO |
Result and scope
Related to #5198 (S3/S6/S9). Integrated head:
21008301deb5e78d8fa3224295932cfc8e872788; base:mainat7e60e69999d9dd00c6d19a93221982a2f1f736b1. The latest main was merged append-only with a signed merge commit; the PR still changes the same 28 proposal files relative to current main. This proposal joins existing Goal Channel delivery, canonical Todo claims and private read-only Turn Recall. It delivers the local legacy-profile stage; the full live collaboration acceptance remains open.goal-channel work project|claimpublishes content-minimal orientation and historical claim receipts with current ownership.offer|revokegrants one revision-bound native claim interaction to explicit principals; the existing default-off collector verifies provider membership, originating card, source route, registered Agent, binding and expiry. Exact retries recover the canonical receipt; transport recovery only repairs the result card.work resumereads current channel identity, canonical work and an admitted Turn, retrieves scoped context anew, then rereads authority and quota. Changes discard earlier observations, context and references. Only explicitly requested scoped artifact pointers covered by current verified recall receipts are carried. The private packet sends no room message, accepts no claim, renews no lease, spends no quota and skips memory-ingest reconciliation.Ownership and compatibility
Reuse the existing typed Todo, Goal Channel, collector and recall owners. No new store, provider, scheduler or configuration editor. Existing Agent connection and Reward Memory editors remain sufficient for this explicit CLI path. No authored frontend or public first-screen change; native card screenshots remain unqualified.
Promoted direct claims deliberately reject foreign
bound_agent. Both existing claim wire versions and the domain owner reject explicit unqualifiedgoal_refbefore provider or historical-receipt access. Source-session business effects remain closed: lifetime-bound head/receipts, retirement serialization and old-writer fencing must first qualify under the existing shared-authority/Goal-instance owners. That later profile boundary is not a prerequisite for the supported legacy-profile local stage.Future-facing pass: reuse shared typed admission/readback and the public quota loader; keep private offers outside Todo lifecycle authority. Collector feature-off behavior and ordinary recall defaults remain unchanged.
Validation
Synthetic Lark/provider transport and disposable real File/SQLite stores; no active Goal was promoted or used for testing.
21008301deb5e78d8fa3224295932cfc8e872788, the focused room/claim/reconnect, recall and outbound Python suites passed 179/179; the four focused TypeScript files passed 9/9; control-plane TypeScript typecheck and staged diff checks passed. This is source-level qualification on the append-only merge, not live Lark/OpenViking acceptance.738115bde87e. Its exact head87ac09725had six CI failures also present on that pinned main (main run, old-head run).21008301dhas completed with failures. Python shard 2/3 failure IDs match exact-base main; Frontstage, Dashboard and chat-bundle failures share the base'sExecution chip ... 28px tallsignature, also seen in the PR Release Artifacts build. Aggregate checks/pytest/merge-gate are red downstream. One additionaltypescript-core (1/3)failure is theclosed_pipesHost-process timing test; its focused local rerun passed 9/9, so attribution remains unresolved. No remote green-CI or merge readiness is claimed.Negative coverage includes stale/duplicate claims, revoked principals/Agent/binding, Bot/message/card mismatch, expiry, authority loss, retrieval-time scope/quota/selection/revision changes, expired/foreign memory and read-only ingest isolation. No PostgreSQL provider changed; local evidence does not qualify shared-service operation.
Remaining gates
Keep draft status and maintainer merge ownership. Untested: authorized native non-production rendering/listener, independently authenticated hosts, live daemon reconnect, scoped OpenViking retrieval and arbitrary external artifact target access. Reuse #3245, #4339 and #3964 for their existing authority, handoff and provisioning boundaries. A merged PR alone does not close #5198 or the RFC.