fix(quota): fence settlement by exact GoalRef - #5389
huangruiteng merged 21 commits into
Conversation
|
CI attribution for exact head
No #5389-owned failure was found. A detached integration of exact heads #5377, #5379, #5375, and #5367 on the same base passed the focused Python suite (35 tests) and digest-owner TypeScript suite (17 tests). After those baseline fixes reach |
|
Exact-head update for
Fresh CI is running on this exact head. @cocolord @huangruiteng please re-review when available. No merge action was taken. |
|
Exact-head update for
Exact-head CI run #5375 removes the inherited pytest-cov environment from that synthetic subprocess, and its exact-head CI run |
|
Exact-head update for
Fresh exact-head CI is queued. @huangruiteng please re-review when available. No merge action was taken. |
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
516a703 to
57e0d9c
Compare
…wner-fence-clean Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…wner-fence-clean Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…wner-fence-clean Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…wner-fence-clean Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…wner-fence-clean Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…wner-fence-clean Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…wner-fence-clean Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…wner-fence-clean Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…wner-fence-clean Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…wner-fence-clean Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…wner-fence-clean Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
…wner-fence-clean Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
|
This pull request has merge conflicts with Choose the remote for the base repository, not an out-of-date fork. git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEADFor a same-repository clone whose Keep the DCO |
huangruiteng
left a comment
There was a problem hiding this comment.
Reviewer: model_agent · GPT-5 · OpenAI(self-reported;不是身份认证或独立模型溯源)
动机
评审 exact head:9baac7c6cfc15e4daf5f010658725fa6a2141d43,基线 3c50e59c0c3da96ac00b1715e7978440030c13a9。依据 #5206 和 Goal-instance RFC 的 M3 quota_settlement:同名 Goal 重建后,旧实例迟到的 debit、replay、repair、读回不能污染继任实例。这里只资格化完整 accounting 切片,不宣称整个 RFC 或 provider 激活完成。
规范对照以改动前 docs/architecture/rfcs/goal-instance-identity-and-orphan-recovery-v0.md、revision 3c50e59c0c3da96ac00b1715e7978440030c13a9 为准,不用新增 checkpoint 反证实现正确:5.5 的短事务 exact fence、旧历史不授权继任结算,在完整 accounting owner/消费者及 native race/replay/readback 验证;7 的未激活兼容以同夹具完整输出/产物对照验证。M3 只完成 quota_settlement owner,其他 owner/drain/旧 binary 仍 deferred 于 #5206;M5 完整迁移、packaged/Lark 多 worker 验收不在这个 M3 accounting 切片内。不把任一阶段写成整个 RFC 完成。
改动思路
复用既有 TypeScript accounting transaction 和 decideFirstPartyHostRuntime(require_current)。Python 捕获/传递 GoalRef 与真实 lock witness,run-index 先于 source lifetime guard;typed owner 校验目标、角色、pid/token 和 currentness 后才进入效果。单阶段接管锁到完成;多阶段 auxiliary monitor 只借用 admission,外层 Python 持锁贯穿 preflight、provider writeback、commit/replay。覆盖生产和消费两端,避免仅添加字段,迟到效果或兼容 Turn inference 仍按 alias 操作;不新增平行 Python 决策规则。
具体改动
检查完整 78 paths,+4249/-392:大部分新增覆盖是 TS native 负例和 Python 集成;薄层传播包括 quota/refresh/todo/turn/native-child CLI、MCP/effect plans、accounting/read models、checkpoint fence,以及双语 checkpoint/inventory/census。这是一条实际效果路径,不是78份独立政策。
关键代码:
parseQuotaAccountingOwner/withQuotaAccountingOwner:明确 alias/exact_source;GoalRef/admission 一起提供,两份有序 witness 必须匹配,复用既有 currentness owner。quota_accounting_admission:在真实 index/source locks 内生成 snapshot/witness;Python 不重建 stale/current 业务决策,也不意外释放借用的外层锁。commitQuotaAccountingArtifactTransaction:record、event、index、payload、receipt owner 一致;cross-instance replay/prepared repair/effect identity 冲突拒绝,保留既有 CAS 和可恢复事务。readQuotaSettlement:先按 exact/alias ownership 过滤再进行 Turn inference;void、rolling-window、checkpoint、native-child 消费同一约束,迟到 A 不替换当前 B。evaluateQuotaMonitorPollCommit:multi-phase settlement 借用同一 admission,internal readback 不误接管/释放外层锁;source provider 路径仍保留 activation hold。
当前 Python 11文件矩阵 128 passed、1 failed,失败为下述既有 architecture budget,不隐藏。实际 File/SQLite checkpoint/provider fence、kernel/file locks、落盘产物参与。六文件 TypeScript 218 passed、0 failed,覆盖 current/stale/malformed、spend/replay/repair/void、exact readback 及 monitor preflight/exception/commit/replay;typecheck通过。
额外生产 Python→TypeScript effect 对照:两个 immutable revisions 使用相同绝对临时夹具路径和固定 generated_at,legacy 首次/replay 的完整响应、JSON/JSONL/Markdown/receipt 完全一致,未删字段或哈希。独立 negative:GoalRef 有但缺 admission,base 实际写4份 artifact,head 拒绝、写入0;合法 witnessed scope planned A/current B 在 head 返回 stale_goal_instance,无 Goal artifact 或剩余 effect lock。base旧 native owner无法接管 held scope而超时,不误说它在持锁时成功写 stale A;合法 Python race/current-source 调用由原生测试另外覆盖。
分支范围16个提交均有 sign-off,替代 #5340 的旧 DCO-only 阻塞独立核验消除;不跨 PR 撤销 #5340 历史评审。
对主干的风险
共享 control-plane 边界主要风险是只 fence 写入却漏掉消费、或借锁误释放。本版 callers、readback/rolling/native-child consumers 和异常重试均进入同一 owner,没有发现当前可复现阻塞。currentness 是机器规则,不称“指导”;generic Goal/instance/accounting errors 不混入产品/benchmark policy 或 substring 分类。
非 source 默认无新 required fields/prompt/form/自动激活,完整 legacy 响应与持久化对照一致。隐藏 instance 参数是捕获后的 transport,不增加人工反复填写;provider discovery/CLI存在不是 activation。没有新的 frontend setting/config schema,已有 status消费者继续读回,故无需平行新页面;未激活的 provider journey不能描述为用户已可用。
语义与 CI 对齐
advisory 未检出新受支持 vocabulary carrier,不据此证明无语义影响;已检查 discriminated owner、ordered lock roles、既有 ExactGoalRef parser/currentness decision。完整 semantic/boundary检查随 canary执行,5 direct及19 selected全部通过。
保留 Python test_top_level_module_count_stays_at_the_pinned_budget 失败:base/head 均147预算对148模块,offender同为 workflow_skill_install.py,完整断言堆栈一致。PR不增加 top-level module,预算文件和 offender不变;accounting 不变量独立通过。不把 canary通过扩大成所有测试绿,也不提高预算覆盖失败。
未查询、轮询或等待 GitHub CI。没有改造或验证 PostgreSQL quota store,File/SQLite证据不替代 PostgreSQL采用资格。execution_authority:false、整体 activation hold、不支持/常驻 binary、downstream external-effect drain、其他 M3 owner均保留,见双语 RFC。
我的整体评价
APPROVE:不是仅做 serializer/happy-path stamp;已有 typed owner覆盖实际 commit、replay/repair、消费及 monitor外层 scope。同夹具完整 legacy对照和 missing/stale authority negative补足兼容/恢复证据。相邻重构集中 exact/alias admission与 witness parser,Python保持运输/存储适配归属,不扩成全量迁移。仅更新既有 quota_settlement checkpoint,其他接受度保持开放;由维护者决定合并,本评审未自合并 control-plane改变。
English verdict: APPROVE — 9baac7c. Exact ownership covers accounting effects, replay/repair, readback and borrowed monitor scopes. Native same-root legacy outputs/artifacts match; missing/stale authority rejects without writes. 218 TypeScript tests and risk canary pass. One unchanged budget failure is baseline-attributed; provider activation and other M3 acceptance remain held. No merge performed.
…wner-fence-clean Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com> # Conflicts: # loopx/cli_commands/turn.py
…wner-fence-clean Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
|
@Duang777 我正在接手当前 head 的维护者复核,并在本 PR 补齐与 roadmap R1–R3 / G1 和 Goal-instance RFC M5 的落地关系:Goal 创建、Agent 创建/复用、小团队产物交接、中断恢复与同名重建的迟到结果隔离。会更新现有双语 RFC/roadmap 和 golden-query 验收场景,保留仅 quota_settlement 完成及整体 activation hold 的边界。 接下来会向当前分支追加文档提交并做最终验证;请暂缓同步该分支,避免审核期间 head 继续变化。完成后会在这里回报合并与后续验收路径。 |
…ecycle-journeys Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
…5389-goal-lifecycle-journeys Signed-off-by: huangruiteng <huangrt01@163.com> # Conflicts: # loopx/semantics/project_registry_io_manifest_v1.json
huangruiteng
left a comment
There was a problem hiding this comment.
Reviewer: model_agent · GPT-6 · OpenAI
English verdict: APPROVE — a5118d0
动机
本 PR 解决同名 Goal 重建后,旧实例的额度效果、历史结果或重放被新实例错误消费的问题。它交付完整的 quota_settlement 归属切片,并将后续产品验收接到现有创建、协作和恢复旅程。长期推进可靠性改善,既有默认用户旅程保持;尚未完成的整体实例激活和小团队验收仍明确保留。
规范依据:docs/architecture/rfcs/goal-instance-identity-and-orphan-recovery-v0.md,采用修改前不可变版本 62ca35f280b51fd4a474b4380a9664570d5aa802。本次映射:5.5 的 quota binding/commit fence 和 7 的未激活兼容边界已实现并验证;M3 的其他 owner、旧/warm writer 和 drain、M4 的孤儿恢复、M5 的 packaged 产品组合验收仍由 #5206 持有。本次文档编辑没有用实现倒推或降低这些准入标准。
改动思路
复用既有 GoalRef、first-party host 的当前实例判定与 mutation-lock,TypeScript 持有准入及效果规则,Python 捕获并传递真实锁见证、执行 IO。持久 receipt 保存写入时的实例事实,不能事后从当前 alias 推导。legacy 和 exact_source 是同一额度边界中的显式分支;未激活模式保持原有参数、扣费、拒绝和重放行为。
只给一个 receipt 增加字段不能覆盖旧结果推断、checkpoint、monitor 及 fallback,因此这些已有消费者必须一起收口。有限重构保留共用准入边界,将轻量 GoalRef 校验移出 registry 导入链;没有引入新的 Agent 工厂、调度器或第二个 Python 决策源。
具体改动
全量检查相对于 9b0486dc1b891bc5254ea85d1ba06da089d22853 的 82 个文件,并核对已撤销旧审查之后的 Turn 参数迁移及主干集成。当前 head 同时保留最新 refresh-state 的 blocked notice 处理;唯一手工冲突是生成清单的两个源码行号,已按实际源文件校正并验证。
五处文档更新覆盖双语 RFC、双语 roadmap 和 golden queries:P0 先做 GQ01/02 的 Goal 创建及 Agent 创建/复用,再做 GQ05/11/12 的依赖产物、peer handoff、独立验收及 GQ08/09 的纠偏恢复;P1 接共享预算和孤儿恢复;P2 接跨主机恢复。普通受支持 profile 先验小团队,再在完整 owner/兼容/drain 门槛满足后做隔离的 A 退役、B 同名重建、A 迟到返回场景。Goal lifetime、registered Agent、session/execution generation、work request/attempt 四类身份明确分开。
关键代码讲解
loopx/control_plane/quota/source_admission.ts:268的withQuotaAccountingOwner接管实际 source/run-index 锁见证后调用既有当前实例判定,再执行效果;路径、角色、PID/token 或 GoalRef 不一致不能获得写权限。- 同文件
:349的withBorrowedQuotaAccountingOwner在多阶段 monitor 调用间只释放临时 claim,保留 Python 外层锁,保证 preflight、provider、commit/replay 的归属一致。 loopx/control_plane/quota/settlement_readback.ts:1210的readQuotaSettlementForAdmittedOwnerFromSnapshot使用已解析 owner,并在推断 Turn 前过滤规范历史,避免把其他实例更新的结果选为当前结算。loopx/control_plane/quota/slot_accounting.py:384的_latest_unspent_turn_settlement_run在 classification 与提前返回前完成 owner 过滤,保证 Python fallback 不能绕过 native 边界。
对主干的风险
重点反例是旧 A/外来历史污染 B,或 monitor 提前释放锁后继续写入。当前真实临时文件、SQLite/provider 和 Python→TypeScript 路径验证了 stale/foreign、过期或伪造见证、父进程丢失、部分事务恢复、重复 spend/void 和 native-child 归属。组件结果为 231 项 Python、279 项 TS 通过;最后一次主干集成后的 refresh/Lark/census 37 项通过。类型检查、Mypy、Ruff、文档治理及 RFC 索引检查通过。21 个 PR-only 提交均有 DCO sign-off。
独立不可变 base/head 对照重新执行了相同 public CLI fixture:先拒绝无交付凭据扣费,再持久化并独立回读结果,随后一次扣费及幂等重放。观测 hash 为 8c07ce6028d8f3075112ca0c48d843ed9d20eb2fd351dc4e7f4d3eaf84127cdf。另一路真实 native spend/void/replay 比较完整返回和七份落盘文件,零归一化且逐字节相同,观测 hash 为 0075e2b438282e1f7f19dec3e85e43f70f5262a344a67d8d6b177b83c1213441。独立敏感性探针只提供 GoalRef 而不提供 admission:base 接受,head 在效果前以 quota_source_admission_invalid 拒绝,符合规范。
语义与 CI 对齐
复用既有 GoalRef vocabulary;alias/exact_source 保持 quota 本地判别,不宣称更广泛 actor 生命周期。规则以 typed 状态与精确相等判定,不依赖 substring denylist;错误和义务保持领域中立,机器强制 fence 没有称作建议。开发期语义 advisory 与全树 drift/census 检查均执行;advisory 未检出候选不代表无语义影响。
最终 canary premerge --from-git-diff passed:10 个 catalog canary、8 个 risk-profile smoke、公开边界扫描,以及 diff/compile 检查全部通过,失败与跳过均为零,manual holds 为空。质量 receipt 与最终 base/head/diff 一致。历史审查里的模块预算失败未复用;本次同一预算命令在当前 base/head 均通过。按当前 review policy wait_for_ci=false 使用本地证据,没有轮询远端 CI。
我的整体评价
APPROVE,未发现当前 head 的阻塞项。该切片改善跨轮次归属与恢复,兼容旧用户流程;机制成本与完整 write/read/replay 边界相符,不能仅以字段补丁替代。文档给出了真实产品落地顺序,也保留 App、CLI、Lark 各入口独立验收的要求。
本次没有运行真实付费多 Agent 团队、激活 source_session_v1、资格化 PostgreSQL service 或宣称外部子进程 drain 已完成;没有新增前端设置或修改首屏。#5206 与 roadmap 组合里程碑继续开放,后续依照 M3/M4/M5 证据推进。最终合并判断绑定上述完整 head,不继承旧 head 的批准。
|
Maintainer merge record for The repository owner explicitly requested handling this PR, adding the roadmap/RFC integration plan, and maintainer self-merge. The exact-head review is published and read back; approval closeout is clear with no blocking reviews or unresolved threads. Local risk-based premerge and exact-scope quality qualification passed. The automatic readiness result remains false: GitHub reports Proceeding as the owner's explicitly requested administrative self-merge exception, without changing repository rules, fabricating a passing readiness receipt, dismissing another review, or treating pending remote CI as local validation. No source-profile activation or M3/M4/M5 completion is implied. |
|
@Duang777 已完成最终复核、文档补充和合并:
最终审查与验证包含 231 Python、279 TS、37 主干集成测试,独立 base/head CLI/落盘行为对比及全通过的风险 canary。本次仍只资格化 |
Problem and result
Quota settlement previously relied on a Goal alias where a source-bound caller needs the exact Goal instance. This can let stale results or replay cross a delete/recreate boundary. The change threads the existing GoalRef through admitted spend/void, checkpoint, monitor, host/Turn, native-child and readback paths; transactions and history consumers enforce the same owner before selection or effects. Inactive legacy callers retain their existing behavior.
The TypeScript quota owner reuses first-party currentness and ordered lock witnesses; Python transports identity and IO. This PR qualifies quota_settlement only, retaining the source-session activation hold and all remaining owner/old-writer/drain gates. It is the DCO-clean successor to #5340 and advances #5206 without closing the full RFC.
Product integration plan
The bilingual Goal-instance RFC and overall roadmap, plus steward golden queries, now connect the quota foundation to existing delivery owners:
First qualify the ordinary supported-profile 2–3-worker journey. Only after the selected M2/M3 owner, compatibility and drain gates pass, exercise an isolated M5 old A/new B/late A scenario, independent acceptance and unrelated-Goal progress. Goal lifetime, registered Agent, session/execution generation and work request/attempt remain distinct. Packaged App/CLI and Lark acceptance is tracked separately; documentation is not a live qualification claim.
Validation
At final head
a5118d08f51809762c7983e6363d4d3c92a3548f, integrated withmainat9b0486dc1b891bc5254ea85d1ba06da089d22853: