Skip to content

fix(quota): project scoped override actions from final admission - #5370

Open
cocolord wants to merge 2 commits into
mainfrom
codex/quota-action-projection-1001
Open

cocolord wants to merge 2 commits into
mainfrom
codex/quota-action-projection-1001

Conversation

@cocolord

Copy link
Copy Markdown
Collaborator

Goal And Delivered Outcome

A peer-scoped User gate could leave agent_scoped_*_override.selected_action pointing to a P0 Todo requiring network even after quota selected a shell-only P1 Todo. Settled and selection-required packets could also retain that executable-looking text.

The final packet now derives this optional field from the final selected Todo through a typed quota projection, only when the final interaction permits delivery. Gate admission diagnostics and receipt binding remain intact. This implements the bounded correction under the existing TypeScript control-plane migration RFC and supersedes #5349. Base: main.

Scope And Continuation

Complete within this scope: both scoped User gate/action overrides, capability filtering, explicit selection, rejected selection and settled readback. The existing quota owner is sufficient; no capability, provider or wire schema is added. This deliberately changes the diagnostic field on non-delivery packets: consumers must tolerate its absence.

The future-facing pass removes the override's independent final action authority while keeping early gate admission intact. Remaining Python route/primary-action builders and recommendation reservation remain outside this correction; the existing migration RFC retains those broader boundaries.

Validation

  • Tested revision: runtime commit 8295cde84; final head adds only the bilingual RFC checkpoint.
  • Run state: finished.
  • Input classes: synthetic, public_fixture.
Check kind Result Evidence / limitation
regression_parity passed New real quota-builder cases: seven failed before the fix; all nine pass after it, including bound receipt identity and no-delivery cases.
integration passed 75 Python tests covering scoped fallback, selected Todo metadata/tool behavior, settlement replay, unadmitted selection, boundary selection and selection conflicts. Existing quota-agent-scoped-user-gate-smoke.py passes.
unit passed Four TS interaction-contract tests include projection immutability, missing identity rejection and absence of a selected Todo.
static passed npm run typecheck:control-plane, semantic inventory advisory, maintainability ratchet and git diff --check.
static passed Source loopx check: public-boundary scan clean; zero errors. Two unrelated pre-existing local-state warnings are outside this diff.

Coverage targets the actual quota builder and its TS Effect runtime transport. The premerge selector was previewed; the risk-based checks above were executed directly. No storage mutation changes, so provider integration is not applicable. No frontend/Lark consumer independently reads this override action; existing interaction authority remains the execution contract. Maintainer review/merge remains required.

Frontend / Visual Evidence

UI impact: none. This changes CLI diagnostic JSON and RFC body text, with no first-screen or visual change.

Shared-authority RFC fixture impact

The existing synthetic quota/Todo shapes are retained. Changed dimension: final admitted action versus early peer-gate diagnostic candidate. Receipt identity and selected-Todo fields are preserved. Provider promotion and three-arm rehearsal are not applicable to this readback correction.

Boundary Checklist

  • Public-safe code, docs and synthetic tests only; no private state, raw logs, credentials or local paths.
  • Focused control-plane bug fix with regression tests and bilingual RFC checkpoint.
  • Every commit includes DCO sign-off.

cocolord and others added 2 commits October 1, 2026 03:40
Signed-off-by: lusendong.6789 <lusendong.6789@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>
Signed-off-by: lusendong.6789 <lusendong.6789@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>
@cocolord

Copy link
Copy Markdown
Collaborator Author

Self-review of head 2d21f98c19f6d9422cee022f999845614d546c3f: no blocking issue found within the submitted scope; maintainer review and merge are still required.

  • Changed surfaces: final quota diagnostic projection and its TS Effect registration. Early gate admission, selected-Todo identity and settlement authority remain owned by their existing contracts.
  • Typed-state/domain-neutrality lenses: uses the existing decoded interaction contract and selected Todo; no prose classification, denylist, new state vocabulary or domain-specific obligation.
  • Behavior disclosure: selected_action is corrected for the final Todo and omitted when delivery is not admitted. Portfolio recommendations remain non-binding, and diagnostic to_state does not grant execution.
  • Coverage: 75 Python tests, four TS tests, the existing scoped-gate smoke, TS typecheck, maintainability ratchet, semantic advisory and public-boundary check passed. Seven new regression cases failed before the fix. Full premerge was previewed, not executed; this focused validation set exercises selection, capability, receipt, notification-adjacent interaction and the actual TS transport. No storage changes require backend qualification.
  • Failures/skips: no unresolved failure in the executed set; two existing unrelated local-state check warnings. Manual hold: maintainer review/merge. Future-facing pass: final diagnostics reuse admitted selection; broader primary-action migration stays in the existing RFC.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant