fix(collaboration): resolve named peers past archived host bindings - #5396
Conversation
Signed-off-by: huangruiteng <huangrt01@163.com>
…cceptance Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
评审对象:#5396,完整 head 01e0b0439c32e639d61f780427e881945ef6d0dd,base 6a8a042ab868a0694e8c19a1ba29c534c575864a。没有阻塞性问题。本次结论覆盖全部 11 个文件,不继承作者的验证结论。
动机
原来只要同一 Agent 保留多个宿主绑定,解析器就要求主人找一个精确任务链接;即使四个已经归档、第五个明确可读,也会拒绝记录请求。历史 session 越积越多,普通的按名字找同伴就越依赖主人重复查链接。这次修复完成了一个有用的本地 CLI 切片:观察完整候选集,排除有明确归档事实的历史,固定唯一可读任务并持久化原有请求。依据是peer route 契约以及管家 RFC 的发现检查点;它没有完成 A24 的原生投递、接收采用和结果回传。
改动思路
做更少的显示过滤,或直接挑最新绑定,都无法证明其他候选已经失效;删除历史绑定又会改变权威状态。这里复用已有绑定 owner、只读宿主 observer 和协作请求 owner:Python 负责范围、可见性和平台读取,TypeScript 的纯选择器负责“仅明确归档才排除”的规则。最多观察 32 个完整候选,发布的三行上限不参与选择。宿主读取之后再次核验注册、候选身份集合及选中地址的跨 Goal 唯一性;仅重排不改变结果,新增备选或撤销身份则停止解析。
普通路径是按 Goal/Agent 解析 → 只读观察 → 唯一选择 → 原有 manager-inbox request --require-host-route 记录 → 独立读回与重试。未知、缺失、不支持、失败、被隐藏或多个可读备选都保留缺口。显式链接保持原来的精确含义,选中归档任务时不会换成另一个任务。resolved 仍然只是一条 locator,宿主发送权限、任务执行与接收方决策各有自己的边界。
具体改动
三个运行时代码文件包含批量观察、选择器以及 effect handler 注册;两份测试覆盖真实隔离宿主库、实际 CLI、负例和读取期间的来源变化。四份说明材料包括英中文 RFC、协议及能力 README,明确写出了旧默认到新默认的变化和剩余 App 验收。另有一份自动加载的管家 skill 更新可信宿主的操作建议,一份注册表 I/O 清单登记第二次规范读取;后者不是新的持久业务状态。完整 diff 为 379 行新增、52 行删除,没有附带公共诊断脚本或新增授权配置。
关键代码讲解
selectObservedPeerHostRoute,第 20 行:严格解码 1–32 个观察,只移除archived;多个剩余候选仍 ambiguous,唯一 unavailable 仍不可用。它返回索引和理由,不执行宿主效果。_observe_bindings,第 51 行:按宿主合并读取完整允许集合;被隐藏、未找到或读取失败都产生固定的不确定事实,私有异常文本不会进入结果。resolve_peer_host_route,第 94 行:把候选范围、显示和选择分开,选择后重读注册与身份集合,再调用既有全项目精确绑定 resolver。返回始终保留authority: locator_only和host_delivery: not_attempted。- 现有请求入口,第 115 行:未开启 route 要求时继续原请求路径;开启时解析失败就在写入前拒绝。成功后复用原有请求锁、operation identity 和 inbox,接收方仍独立采用、延后或拒绝。
对主干的风险
最需要反证的是:显示上限或未知备选会不会被当作“没有别的任务”,以及宿主 I/O 期间的注册变化会不会固定错误身份。本次独立运行 118 项 Python 测试、7 项 TS 测试,并执行 38 次实际源码 CLI 子进程观察,覆盖同一隔离 Codex SQLite/JSONL 与规范注册表上的 base/head 对照。第五个可读任务、重排、缺失、远端不支持、隐藏、33 个候选、跨 Goal 同址、显式归档/外部链接均有实际观察;来源竞争由当前 Python 负例补充。
在同一五候选输入上,base 路由 ambiguous,请求退出 1 且明确“没有记录”;head 选择 current,单独读回一条含原始语义 brief 和固定 route 的请求,重试保持同一个 id。新增第二个可读候选再次拒绝;将该宿主明确归档后可以重试原请求,不产生第二条。未传 --require-host-route 的 base/head 请求结果完全一致,单独读回没有 host_route。预览不创建 runtime,注册表和宿主数据保持只读;测试中用于改变归档状态的写入仅作用于隔离合成库。
Ruff、配置的 Mypy(19 个源文件)、TS typecheck、diff/DCO 和公共边界检查通过。改动期语义 advisory 为零个受支持候选,但匿名字面量不在其扫描范围,已经人工核对 Host 枚举与 TS bridge;完整语义及注册表 I/O smoke 通过。最新 main 3ad3269 相对 base 仅有三个宿主清理测试文件变化,没有修改本次协作、观察、请求或依赖边界。没有查询或等待 CI,也没有把作者的全套 TS/canary 数量当成本次执行。
语义与 CI 对齐
该修改复用既有 Host 状态、route 状态和请求格式;新增的是内部纯选择入口,没有新增持久生命周期词表。公开协议、测试名称与已加载 skill 都披露多绑定默认变化。选择规则在 TS,Python 保留读取和身份适配;不存在第二份归档决策 owner。现有请求的默认路径实际对照保持一致,但 resolver 本身是明确披露的默认行为修复,不能称为完全没有行为变化。
我的整体评价
APPROVE。长期运行方面,历史绑定不再使普通同伴请求永久依赖主人查链接;未知与未来候选仍保持安全拒绝。使用体验方面,只有真正没有选择余地时省去重复输入,真实的身份/权限决定仍保留。现有 owner 内的有界修复比自动解绑、另建路由存储或挑最新记录更合适;本 PR 已应用同范围的未来维护改进,统一匹配过滤并分开平台观察与 TS 选择,没有必要再加框架。
剩余风险是宿主“可读”不证明在线、新鲜、容量或发送权限。验证使用真实读取实现和隔离合成数据,不证明已安装 App、远端可用性、实际宿主提交、接收采用或原群回传;双语 RFC 已保留这些验收缺口。当前结论只批准上述本地解析与请求固定切片,合并仍由维护者处理。
English verdict: APPROVE - exact head 01e0b04. No blocking finding across the full 11-file diff. Independent validation: 118 Python tests, 7 TS tests, 38 source-CLI receipts on disposable real local stores, lint/types and full semantic/I/O smoke passed. Installed App/remote submission, adoption and result return remain unqualified; locator resolution grants no execution authority.
A named peer with one readable host task and several archived bindings previously required the user to find an exact task link. This change resolves that existing task after positively observing every archived alternative, so trusted local callers can record the same peer request without another lookup.
The selection rule belongs to the shared TypeScript collaboration owner. Python reuses the binding authority and read-only host observer, batches reads once per host, and rechecks registration, the scoped candidate set and the selected identity after host I/O. Unknown, missing, unsupported, failed or withheld alternatives remain unresolved; two readable tasks still need an explicit choice. Observation is bounded to 32 candidates independently of the three-row display cap. An explicit task link retains its exact meaning.
The existing
resolve-peer-routeandmanager-inbox request --require-host-routeentry points consume the rule. No new frontend form or configuration is needed for this CLI slice. The managed steward guidance and bilingual handoff RFC now describe the changed default and the remaining App-first acceptance. This proposal does not qualify installed App routing, host submission, recipient adoption or result return; no permission, resume, message-send or execution authority is granted by a locator.Validation on
01e0b0439c32e639d61f780427e881945ef6d0dd, based on6a8a042ab868a0694e8c19a1ba29c534c575864a:not_attempted.cqr_2382c24690309cdb9e21verified valid. The refinement reused one candidate filter, closed the source-race gap, and separated the batch host-observation adapter from the narrowly named TypeScript selector. The registry I/O census records the second canonical read; no architecture budget was raised, no archive-selection rule remains in Python, and no compatibility wrapper was added.Risk-based
canary premerge --from-git-diffpassed: 19 selected checks (10 catalog, 8 risk-profile, 1 public-boundary), 5 direct checks, zero failures or warnings, and no manual holds. It covers shared control-plane behavior, docs and Python adapters; the changed 11 public files scan clean. The full native suite's 31 optional environment skips remain unqualified environment coverage, not evidence for remote or PostgreSQL deployment.This changes the previous blanket refusal for multiple bindings only when all alternatives are positively archived. Missing observations remain uncertainty, not proof of retirement. PostgreSQL deployment, remote host availability and full collaboration cycles remain separate acceptance. Runtime changes remain for maintainer review and merge.