fix: restore managed operation effort parity and structured continuation - #5369
Conversation
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
结论:当前完整差异没有阻塞性发现,这是可独立验收的 transport 修复增量,不是投研端到端闭环已经完成。评审版本:bba9b5ca4476eb50d3924793a2c1346dbc813d06;不可变基线:67930ab6af78491f10ca3de4ff74ef7a39954a51。
动机
已有 managed operation 入口接受 CLI 的 effort vocabulary,但 TS 预检漏掉 none/max/ultra,导致合法配置在启动前被拒绝。真实 Luna/max 新建 context 成功后,同会话续接又因为 commentary 与最终 JSON 拼接而失败。这两个问题都会令持续工作的 Agent 卡在传输层;修复应复用现有宿主,不应新增认证捷径或让用户反复重新绑定。基线/候选同输入对照和真实新建、续接均支持本次增量价值。
改动思路
沿用 RFC 第 13 节:来源会话提供上下文与返回路由,执行身份由受管宿主产生。TS 继续拥有配置预检、绑定与消费判断;Python 只修现有 app-server IO 适配器。配置有效不等于模型已验证,更不等于人工授权。结构化输出采用 completed final answer;不是去掉 JSON 校验、解析任意 prose 或添加新的审批状态。
具体改动
关键代码讲解
projectManagedOperationTransport位于operation_agent_handoff.ts:35:effort 从旧五值扩展到既有 CLI 八值,并显式要求字符串,拒绝数组强制转换。合法配置仍返回runtime_qualified:false,人工确认与首次消费要求不变。CodexChatAgentSession.send位于chat_agent.py:935,新增 completed structured response,在当前 thread/Turn 的item/completed收到 final_answer 或兼容旧无 phase 消息时取完整正文;commentary-only JSON 与未知非最终阶段拒绝。最终仍严格解析为 JSON object,交给原 Turn result validator,最终 prose 不是 operation receipt。- 四个既有测试文件承载回归,而非新增平行测试框架:TS 检查八种 effort、两种 sandbox 和畸形输入;真实 Python→TS binding 测试消费原 CLI 常量;chat 测试覆盖 commentary、部分 delta、旧 phase 和非最终拒绝;显式 opt-in live host 测试增加 Luna/max,并保留同会话续接及 native Turn 不同的断言。总差异六文件、99 行新增/8 行删除,其中生产代码仅 20 行新增/2 行删除。
对主干的风险
普通非结构化聊天路径未改变。相同输入经过不可变基线与候选的真实 send/host-binding→TS 边界,普通聊天、delta-only、final-only、外来/历史事件过滤、畸形最终结果拒绝及关闭 operation/xhigh/缺失配置/错误宿主优先级保持相同观察。固定 oracle 在基线分别发现合法最终答案被拒、commentary 被误当最终结果、max 配置被拒,候选全部修复。事件流是合成输入,不冒充模型执行;另有真实 Sol/xhigh 和 Luna/max 新建与续接两组通过。
聚焦 Python 165 passed、2 个 opt-in skipped;两组 opt-in live 单独执行通过;TS 聚焦 10 passed;typecheck、Ruff、17 项风险选择 smoke 和 5 项直接检查通过。全量 TS 不是绿色:候选有 unchanged host_process 的 leader_exit 失败;基线全量复现同一失败(返回后计数增加一,19/18 对 18/17),另有 abort 失败,两边单独进程测试都通过。相关生产及测试文件没有差异。这是独立的既有进程清理风险,保留失败记录与独立合并就绪检查,不要求本修复改变测试上限来掩盖它。
语义与 CI 对齐
复用既有 reasoning vocabulary 与 app-server completed item 协议,不创设金融或认证语义。当前 Goal 要求本地验收、无需等待 CI;本地语义 smoke 通过。不存在新增持久字段、技能自动加载、配置 owner、UI 确认入口或 Lark 回调。App 自动发现与状态刷新、真正 prepare/群卡/真人确认/一次性消费/原渠道返回,仍属于尚未完成的整体旅程;接口成功和 context 测试不能证明这些能力。
我的整体评价
长程持续推进与用户传输入口均有所改善:合法 profile 不再提前误拒,同会话续接不再因 commentary 污染结构化结果;原有拒绝与授权边界保留。最小修复位于原 TS owner 和原 IO adapter,无新状态、CLI 或依赖,两个生产修复共同解决已观察的 host gate,而非堆叠认证机制。旧 phase/delta-only 兼容对应已有 app-server 测试消费者,保留并受对照测试保护。已检查完整差异、实际调用方及相关 RFC;仍需原 Agent 执行独立非金融真实验收,core 需 owner 评审合并,未全局安装。既有全量进程失败另行影响合并就绪,不被本评审抹去。
English verdict: APPROVE - bba9b5c. No blocking finding in this bounded transport increment: canonical effort parity and authoritative structured final-answer parsing are validated. Focused Python 165 passed, TS 10 passed, 17 smokes/5 direct checks, and both Sol/xhigh and Luna/max fresh/resumed native-host probes passed. The unchanged full-suite process failure reproduces on the immutable base; neither full run is green. Genuine prepare/approval/consumption/UI return and merge/install remain separate.
Summary / 改动说明
修复 managed
--codex-operation-tools两个真实阻塞:TypeScript profile 预检与现有 CLI reasoning vocabulary 不一致;structured Turn 在 commentary 与最终答案同时出现时错误拼接 JSON。补齐none/max/ultra,拒绝非字符串 effort,并从 authoritative completed final answer 解析结构化结果。不改变绑定、审批、一次性消费或模型支持判定。Align the owned operation transport's TypeScript profile preflight with the existing CLI effort vocabulary, and parse structured results from the authoritative completed final answer rather than concatenated commentary/deltas. Configuration validity remains distinct from runtime/model qualification and execution authorization. Commentary-only JSON and unknown/nonfinal phases fail closed; ordinary nonstructured chat and legacy delta-only transport remain compatible.
通用 profile 判定继续由 TS 单一权威负责;Python 改动只位于现有 app-server subprocess/stdio 适配器,不新增通用决策源。The Python change stays in the existing subprocess/stdio adapter; provider-neutral control-plane authority remains TypeScript-owned.
Validation / 验证
none,max,ultrabefore the fix.bba9b5ca4476eb50d3924793a2c1346dbc813d06: focused chat/operation/host/binding/Lark suites: 165 passed, 2 skipped (explicit live-host cases).maxpreflight acceptance and commentary/final separation; no state or effect is produced by these checks.host_process.test.ts(leader_exitdescendant counter). The immutable base full run reproduces the sameleader_exitfailure (counter grows by one after return: base 19/18, candidate 18/17), plus anabortfailure: 3539 passed, 30 skipped, 2 failed. Both revisions pass all 9 process tests separately. The TS execution is from the first commit; the second commit changes only Python IO/tests, and all TS inputs are unchanged. Do not label either full run green or hide the process-cleanup risk; merge readiness remains separate.contextplus same-session resume both passed (2 passed, 7 deselected). The original Luna/max resume failure was traced to structured-output parsing, not authentication or approval; its oracle was not weakened. This PR does not claim completed live prepare/group/App/human-confirmation/consumption or global release qualification.Product and authority boundary / 产品与权限边界
CLI/managed Turn is the affected entry point. This corrects rejection of an already-exposed argument and parsing in the existing owned app-server adapter; it introduces no setting, card field, UI state, Lark callback or second configuration owner. Existing shared projections, session/profile digest, Goal/Agent/Todo binding and approval/first-consumption requirements are unchanged. No new frontend control is necessary for these transport fixes; the broader group/App/live-executor journey is explicitly partial, including real card discovery and status refresh that still require live acceptance.
现有生产规模 coordination fixture 不受影响:没有新增 Todo、租约、存储或 provider 语义;profile parity 由公开 CLI vocabulary 与真实 TS bridge 的聚焦回归保护。No production-scale coordination fixture dimensions change; no schema/store/provider/lease behavior is introduced.
Private workspaces, configuration, native request data and diagnosis logs are excluded. No live account effect, group delivery, global installation or shared-history rewrite was performed. Owner review is required; this LoopX core PR is not covered by finance-repository self-merge authority.