Skip to content

fix(todo): close bound user actions without execution authority - #5402

Merged
huangruiteng merged 3 commits into
mainfrom
codex/user-action-lifecycle-20261001
Oct 1, 2026
Merged

huangruiteng merged 3 commits into
mainfrom
codex/user-action-lifecycle-20261001

Conversation

@huangruiteng

@huangruiteng huangruiteng commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Motivation / 动机

Ordinary bound user_action Todos cannot claim execution leases, but canonical hard-lease completion required one. This stranded withdrawn or fulfilled reminders. Explicit cancellation was also gate-only; allowing it to fall through ordinary completion would incorrectly resume linked work.

普通绑定用户事项不能领取执行租约,canonical hard-lease 完成却要求租约,导致已撤回或已处理的提醒无法关闭。取消也只对 gate 开放;取消不能被解释成普通完成后的下游恢复。

Implementation / 实现

  • Reuse the canonical TS terminal lifecycle owner: only the exact registered, non-excluded bound actor can administratively close a user_action without a lease. Active holders, explicit lease CAS, claims and actor fences remain authoritative. No execution lease or claim is minted; supersede is unchanged.
  • Share outcome validation in existing todo.user_completion.plan; the Python legacy adapter transports source facts and typed errors, rather than adding a second decision owner. Ordinary actions accept explicit cancel, not approve/reject.
  • Preserve native Gate completion without an outcome as closure only. It does not approve, consume requirements or resume linked work; the legacy explicit adapter retains its own pre-existing outcome requirement without imposing it on native callers.
  • Cancel closes the source only, preserves its linked target and scopes, and records decision_cancelled for a linked reminder. No dependent resume, gate conversion, financial effect or automatic expiry handling.
  • Add reusable File/SQLite/PostgreSQL conformance and actual CLI regressions for actor/outcome rejection, preview, CAS conflict, response loss, replay and changed-intent fencing. Expand existing CLI help and bilingual lifecycle documentation.

复用既有 TS 终结权威,只为精确绑定且已注册的普通事项关闭提供行政路径,不产生执行认领或租约,不绕过活跃持有者或显式 CAS。Python 保留旧路径适配和错误传输。取消保留关联任务与决策要求,不产生批准、恢复、交易或自动到期处置。

User entry points / 用户入口与边界

CLI/managed CLI is the delivered explicit-cancellation entry point. Existing Chat completion and packaged HTTP proposal/readback/retry reuse the terminal owner. Existing frontend/Lark readers consume canonical completed state; no new layout, setting or cancellation control is claimed. Direct frontend/Lark cancellation controls are outside this bounded slice. The legacy Markdown adapter shares cancellation outcome/effect semantics, but its separate hard-lease terminal fence is unchanged. No provider/default change, runtime installation or real request mutation is included.

本次交付取消的 CLI/managed CLI 入口;既有 Chat 完成、打包 HTTP、失败投影和原操作重试仍共用权威。未新增前端/Lark 取消控件;不改变旧 Markdown 的独立 hard-lease 门禁、不安装运行时、不处理真实用户事项。

Validation / 验证

  • Current-head TS lifecycle/outcome tests: 26 passed.
  • Current-head File/SQLite/real PostgreSQL lifecycle followthrough: 36 passed, no skips, including Gate closure without a decision, real CAS conflict, lost response and replay.
  • Current-head public completion, gate compatibility and packaged Chat HTTP/recovery: 55 passed in 114.11s; focused legacy/File/SQLite Gate complete/update CLI cases: 6 passed. Test duration is not a service-latency claim.
  • Current-head immutable-base comparison: 20 cases × 2 providers × 2 revisions = 80 real CLI observations, plus two historical Gate-null receipt upgrade replays. Both base and head accept native Gate closure without a decision and preserve the dependent exactly.
  • Prior production qualification at 74417f0a: File/SQLite/real PostgreSQL followthrough 30 passed, full public CLI 24 passed. A representative File completion + SQLite cancel CLI validator passed in 8.45s inside the unchanged 29s completion budget. Earlier full authority qualification: File 313, SQLite 329, real disposable PostgreSQL 313, no skips; these are prior-source results, not full-suite reruns at the current head.
  • Additional existing completion/fence/transaction/policy/update-recovery tests: 38 passed. Four initial Chat failures were missing packaged assets (HTTP 404); source packaging and the affected rerun passed. Gate-error transport regression was caught, fixed and rerun.
  • Immutable base 3ad3269af4d2cfae2085693823dcfcda522f9a2b versus candidate through the same isolated real CLI harness: File/SQLite ordinary completion and cancel fail on the original lease defect, then pass with persisted source/target/claim/scope readback on the fix.
  • npm run typecheck:control-plane, diff checks, Python compilation, diff semantic advisory and full-tree semantic vocabulary canary passed. Packaged frontend built from source.

Replayable affected checks:

node --experimental-strip-types --test tests/control_plane_ts/user_completion.test.ts tests/control_plane_ts/todo_terminal_decision.test.ts
node --no-warnings --experimental-sqlite --experimental-strip-types --test tests/control_plane_ts/authority_store.test.ts tests/control_plane_ts/sqlite_authority_store.test.ts
npm run test:postgresql-authority-store # set LOOPX_TEST_POSTGRES_URL to an isolated disposable server
uv run python scripts/chat_bundle.py build --install
uv run --extra test python -m pytest -q tests/control_plane/test_user_completion_provider_followthrough.py tests/control_plane/test_todo_decision_scope_lifecycle.py tests/control_plane/test_native_user_completion_update.py

All test data is synthetic and process/data isolated. Private harness files, runtime state, logs and credentials are excluded. Runtime adoption and real expired-request closure still require reviewed deployment and the original authorized actor. Core maintainer review is required; this PR will not be self-merged.

所有数据均为隔离合成数据;私有 harness、运行态、日志与凭据未提交。真实采用和到期请求关闭仍须评审部署与原授权主体完成。本 PR 保持 Core maintainer review,不自合并。

Exact-head review refinement / 精确 Head 评审补充

At 7d125b2666c8ecf3980489e6640cd793c8624bb7, the earlier native Gate input tightening is removed. Native todo complete without --decision-outcome continues to close the Gate without recording a decision, consuming requirements or changing the blocked dependent. todo update --status done remains closure-only too. Explicit approve|reject|cancel still supplies a decision; the legacy Markdown adapter keeps its pre-existing outcome requirement. The prior e7 review does not qualify this new head.

The isolated public CLI harness reran all 80 observations against immutable current base db3672f3c6646a75878158d66c79a1a5a32ceb32 and the new head. It covers legal completion/cancel, actor/binding/exclusion/claim/CAS rejection, invalid outcomes, deferred source, retired target, remaining requirements, 260 reordered unrelated rows, post-promotion subjects, and Gate decisions/closure. Fixture hashes match per pair; persisted rows and diagnostics are independently inspected. Success fingerprints identify executions, not byte-identical generated IDs/render hashes. Historical successful Gate-null receipts replay with no additional effects.

One initial PostgreSQL rerun used the OS/default database roles against an older disposable fixture, whose declared role differed; all twelve PG cases failed before reaching product logic. A newly isolated fixture with an explicit test role passed all 36 provider cases. Earlier harness/fixture failures remain recorded, not counted as passing checks.

已撤掉上一轮引入的原生 Gate 收紧,保留“不带决定只关闭”的旧行为,不补造批准、消解要求或恢复目标;旧 Markdown 原有必填规则不扩到原生入口。新 Head 重新跑过 80 条 base/head CLI 对照、36 项三存储事务/响应丢失/重放、55 项入口/兼容/Chat 和 26 项 TS 回归。历史成功回执仍可重放。初始 PG 夹具角色错误已归因并用明确角色的隔离夹具重验,不豁免产品失败。仍待 Core maintainer review/部署,不自合并、不安装、不处理真实请求。

Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

English verdict: APPROVE - head e7b9057

结论:当前完整 PR 未发现阻塞问题。评审中发现原生 Gate 无决策完成的收紧缺少充分披露,已在新 Head 补上真实 CLI 回归及中英文说明。此评论是作者自评结论,不代替 Core maintainer review,也不表示已合并或采用。

动机

普通绑定提醒不能领取执行租约,原生 hard-lease 完成却要求租约,造成已处理或已撤回事项无法合法关闭。当前 immutable base 的真实 CLI 复现了这项失败。本切片修复提醒的持久生命周期,减少后续轮次被过期承诺误导;它没有完成整个上层目标,也不授予执行、批准或外部操作权限。

改动思路

最小修复应留在现有终结权威和用户完成联动计划,而不是新增取消命令、伪造执行租约或直接覆盖 Markdown。权威仍从完整 canonical 快照读取 actor、绑定、排除、认领及租约。只有精确绑定的已注册主体能走行政关闭;取消只关闭源事项。旧 Markdown adapter 调用同一 TS 结果规则,删除原 Python 校验副本;旧路径独立 hard-lease 门禁仍保留并明确标注限制。

正常完成经过既有守护规则恢复关联工作;取消不恢复、不消解范围。拒绝或响应丢失后由原主体/原操作回执恢复,不新造授权。晋升后新建事项和同 Goal 未覆盖主体亦按逐 Todo 绑定处理,Goal 激活不是全局豁免。

具体改动

完整差异为十个文件,生产代码五个文件新增七十一行、删除三十二行;其余是耐久回归和说明。当前评审补丁仅增加四十一行 CLI 回归、十四行双语说明,生产逻辑与此前资格验证源完全一致。未增加 schema、provider、调度器、安装操作或新的 UI 权威。

关键代码讲解

  • terminalFence(todo_lifecycle_decision.ts:423):先沿用 actor/claim/排除边界,再让普通绑定事项在没有活跃持有者、显式租约证明或 delegation override 时用 provider CAS 关闭。不会生成执行认领/租约;过期 lineage 退休时不伪造代次。
  • requireCompletionDecisionOutcome(user_completion.ts:38):普通事项仅允许显式取消,拒绝 approve/reject;Gate 显式完成必须有决定。错误走既有 typed transport,Python 恢复为公开 ValueError,而不是意外 handler 错误。
  • planUserCompletion(user_completion.ts:53):普通取消在读取并修改关联目标前返回空 updates 和 decision_cancelled;关联目标、认领、要求和结果原样保留。普通无结果完成仍走既有 guarded resume。
  • executeCoordinationTodoTerminalLifecycle(todo_terminal_lifecycle.ts:1023):新显式完成在任何副作用前校验结果;状态 update 只记录关闭,原回执重放不被重新解释。源事项、实际需要的目标联动及回执仍按同一事务提交。

CLI/managed CLI 是交付的显式取消入口。现有 Chat User 完成使用 reviewed update basis,前端快捷完成也走同一 proposal/update/readback;并未新增前端或 Lark 取消按钮。打包 HTTP/失败投影/重试覆盖保持通过,不把后端取消等同完整新 UI 旅程。

对主干的风险

最危险的错误是把取消解释为恢复或批准,或者把行政例外扩大成异主体执行授权。对照实际检查了 target/claim/scopes 和无副作用,而不是只看成功码:当前 base 与生产源的十八类场景、两种存储、两个修订共七十二条观察,另有当前 Head 的重绑定逃逸和错误主体加 approve 八条观察。包括二百六十条无关事项反序、晋升后新建、延期源和已完成目标。错误主体优先级、拒绝详情和独立持久读回保留。

明确的兼容变化:此前 canonical 显式 Gate 完成允许遗漏 decision-outcome,现在在写入前拒绝,与旧路径契约对齐;todo update --status done 仍能无批准地记录关闭。File/SQLite 已验证历史无决定成功回执升级后可重放,所有持久行不变。生成操作身份和渲染摘要未被当成字节等价证据。

发布前主干又前进到 #5394 合并提交 060e4698,而 PR 的 baseRefOid 仍读回 db3672。已检查共享 handler、展示计划和 Lark 路径:改的是只读内容/确认到期/operation 取消展示,未改变 Todo 完成 RPC 或终结准入。上述对照仍明确标记旧快照来源,不冒充新主干集成;集成与部署留给 maintainer/原服务 owner。

语义与 CI 对齐

复用既有 typed role/task_class/outcome/receipt 词汇,行政关闭不等于执行权,取消提醒不等于撤单或外发撤回。本次不是 default-off 功能,没有安装指导或隐藏激活机制。按 capability policy 未查询、轮询或等待 GitHub CI;以仓库本地验收作评审依据。

当前工作树入口/兼容/Chat 批次五十二项通过;新 Head 聚焦 CLI 五项、TS 二十五项、类型和 diff 检查通过。此前生产源最终 File/SQLite/真实隔离 PostgreSQL followthrough 三十项无跳过;较早完整 authority suite 为三百一十三/三百二十九/三百一十三项,保留其来源而不冒充全套新 Head 重跑。初始 Gate 差异、夹具参数/临时目录/注释错误均保留后修正,没有放宽硬门禁。共享 Git 后台 GC 锁告警未影响签名提交和推送,未清除他人锁。

我的整体评价

长程连续性和 CLI 用户体验均改善;现有 TS owner 扩展与 Python 副本删除使机制规模相称。常规 Gate 三结果、状态关闭、历史重放等兼容已核对,当前 Head 对上次生产源只有回归/说明增量,未沿用旧 approval。没有阻塞发现;APPROVE 仅表示本切片评审通过。

最强剩余验证是通过原安装/服务 owner 部署并由原绑定主体真实关闭已撤回请求,本轮故意不执行。Core maintainer review 和最新主干集成仍必须完成;不自合并、不安装,不把 CLI 版本变化当作服务已采用。直接前端/Lark 取消控件和旧 Markdown hard-lease 行政豁免仍属明确的非交付范围。

Signed-off-by: huangruiteng <huangrt01@163.com>

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

English verdict: APPROVE - head 7d125b2; native Gate closure without a decision remains compatible. 55 caller/Chat tests, 26 TS tests, 36 real-provider transaction cases and 80 paired CLI observations passed.

结论:当前完整 PR 未发现阻塞问题。上一轮引入的原生 Gate 决定必填规则已撤掉,现保留旧版“不带决定只关闭”的行为。此新 Head 已独立复审,旧 e7 结论不用于新 Head;作者自评不代替 Core maintainer review,也不表示已合并或采用。

动机

普通绑定提醒不能领取执行租约,canonical hard-lease 完成却要求租约,造成已处理或撤回事项无法关闭。取消还必须与正常完成区分,否则会误恢复下游工作。本切片修复持久生命周期,但不授予执行或批准权限,也不完成上层目标。另一个明确要求是原生 Gate 不带决定的旧入口继续可用;把旧适配器的严格规则强加给它会增加无必要的确认负担。

改动思路

最小修复位于既有终结权威和 User 完成计划,不新增取消命令、状态同步或租约伪造。完整 canonical 快照决定主体、绑定、排除、认领和租约;普通绑定事项只获得行政关闭。取消只关闭源事项,正常完成仍走受保护恢复。

输入规则在同一个 TS owner 中维护,但尊重两个入口已有的存在性契约:原生 Gate 允许遗漏决定并生成空下游计划;旧 Markdown 显式完成桥要求决定,内部调用明确指定原有规则。该区别不是新增用户配置或另一份 Python 策略,也不能由请求载荷关闭校验。明确的批准、拒绝和取消继续走原来的范围规则。

具体改动

完整 PR 十个文件新增三百八十九行、删除三十七行;生产代码五个文件新增七十五行、删除三十二行,其余为耐久回归和中英文说明。本轮相对 e7 在五个文件内修改六十四行新增、三十二行删除,撤掉无依据的输入收紧并扩大已有测试,而不是只换披露文字。

关键代码讲解

  • terminalFence(todo_lifecycle_decision.ts:423)保留主体、认领和排除边界,仅在精确绑定、无活跃租约持有者、无显式租约证明、无 delegation override 时允许普通事项用 provider CAS 关闭;不生成执行认领或租约代次。
  • requireCompletionDecisionOutcome(user_completion.ts:39)仍拒绝普通事项 approve/reject,允许显式 cancel。原生 Gate 的 null 直接保留;旧桥内部要求决定。明确结果的物化检查与 typed error 传输不变。
  • planUserCompletion(user_completion.ts:57)对 Gate 无决定返回空计划;普通取消在目标查找前返回空 updates 和 decision_cancelled。因此二者不会消解范围或修改关联任务;普通正常完成保留既有 guarded resume。
  • executeCoordinationTodoTerminalLifecycle(todo_terminal_lifecycle.ts:1023)仍在新显式完成副作用前校验结果,沿用原事务提交源、必要联动、租约和回执。更新关闭与历史重放不被解释为新决定。

CLI/managed CLI 是显式取消的交付入口。现有 Chat User 完成使用 reviewed update basis;打包 HTTP proposal、失败投影、读回及原操作重试仍共用终结权威。没有新布局、设置或前端/Lark 取消按钮,因此不把后端修复说成完整新 UI 旅程。文档双语说明原生与旧桥的边界,CLI help 区分提醒取消和 Gate 批准。

对主干的风险

最危险的错误仍是取消被当作恢复或批准,或者行政例外扩成异主体执行权。新 Head 与 immutable base db3672 的二十类场景、两种存储、两个修订共八十条实际 CLI 观察,检查了完整持久行、claim、范围和诊断,而不只是退出码。覆盖异主体、无绑定、排除、外部认领、错误证明、重绑定关闭逃逸、延期源、已完成目标、剩余要求、二百六十条反序无关事项及晋升后新建。

Gate 无决定在 base 和当前 Head 都成功关闭,目标逐字段不变;历史成功回执升级后仍可重放。三种真实存储的三十六项事务检查含新 Gate 无决定路径、CAS 竞争、响应丢失、重放与改变意图拒绝,全部通过且无跳过。Python 入口/兼容/Chat 五十五项、TS 二十六项、类型与 diff 检查通过。成功指纹保留生成操作身份,并非宣称生成 ID 或渲染摘要字节相同。

初始 PostgreSQL 重跑连接到旧隔离夹具时使用了不存在的默认角色,十二项在产品逻辑前失败;没有通过修改业务规则或跳过 PG 掩盖。新建声明明确角色、仅本地 socket 的隔离夹具后,三十六项全部通过,服务器已停。早期完整 authority 313/329/313 等结果保留原修订来源,不冒充本次全套重跑。

发布前主干已读回 98acf52,而 PR 的 baseRefOid 仍为 db3672。已核对共享 handler 的增量仅增加 reply-context/peer-route handlers,Todo 终结和 User completion owner 未改变;此前 #5394 的只读展示/到期内容变化也已检查。本次对照不冒充最新主干集成或服务采用,集成和部署仍由 maintainer/原安装服务 owner 完成。

语义与 CI 对齐

复用既有 role、task_class、outcome 和 receipt 词汇;关闭不等于批准,取消提醒不等于撤单或外发撤回。没有新 schema、provider、默认关闭开关或自动激活。按 capability policy 未查询、轮询或等待 GitHub CI;本地 owning-path 验收是评审依据。边界扫描无错误,另外两项注册 Goal 的旧投影告警与本 PR 公共文件无关。

我的整体评价

长程连续性与 CLI 用户体验改善,原生 Gate 的既有输入兼容保留;源码体量与生命周期故障相称。Python 仅保留旧格式锁内适配,决定规则由 TS 单一 owner 承担。新 Head 的真实跨存储、入口、范围与回放证据均满足本切片,没有沿用旧 approval。

最强剩余验收是原安装 owner 部署、服务实际 source 读回及原绑定主体真实关闭请求,本轮不执行。Core maintainer review 和最新主干集成仍待完成;不自合并、不安装、不触碰真实请求。直接前端/Lark 取消控件、旧 Markdown hard-lease 行政豁免和真实金融操作均不属于本切片。

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Reviewed head: 7d125b2666c8ecf3980489e6640cd793c8624bb7。评审范围是原始 base 3ad3269af4d2cfae2085693823dcfcda522f9a2b 到当前 head 的全部十个文件,并单独检查了 e7b9057 → 7d125b2 的兼容性修正。没有沿用旧 head 的批准结论。已读当前作者自评及其明确留下的独立评审、主干集成边界;以下补充本次独立执行的完整 provider、CLI 和主干集成证据。

动机

没有发现阻塞问题。这个修复解决了可复现的权限矛盾:晋升后的 hard_lease Goal 要求终结事项持有执行租约,但普通 user_action 无法领取这种租约,导致精确绑定的合法主体也不能关闭提醒。取消提醒还需要区别于正常完成,避免被误解释成批准关联工作。

判断依据是现有 canonical Todo completion/update 契约。真实 CLI 的相同合成输入在原始 base 上有 21 个合法关闭/取消场景失败;当前 head 全部通过。直接编辑 Markdown 或制造执行租约都会绕过或混淆既有权威边界,因此在现有终结 owner 内修复是合理的。

改动思路

仍由 TypeScript 负责权限判定、结果校验和联动计划,由现有 provider CAS 原子提交源事项、关联效果和回执。行政关闭只适用于精确绑定、已注册且未被排除的主体;认领冲突、活跃租约、显式错误租约证明和 delegated override 不获得豁免。

普通 cancel 只关闭源提醒。无 outcome 的普通完成保留受保护的恢复行为,明确的 Gate 决定保留范围语义。本次修正还保留了 native Gate 无 outcome 的原有“仅关闭”合同;legacy Markdown 显式完成入口仍要求决定。gateOutcomeRequired 表达这两个实际调用方原有的输入差异,没有新增持久化权限状态,也没有形成第二套 Python 决策规则。

具体改动

完整改动为 389 行新增、37 行删除:五个运行时文件 75+/32-,四个测试文件 248+/5-,双语契约文档 66+/0-。涉及 CLI 帮助、终结权限、终结事务、共享完成计划和 Python 适配器,没有新增模块、存储、配置或 CLI 命令。

关键代码讲解

  1. terminalFence:从原始主体、绑定、认领与租约事实推导 complete-only 行政关闭例外;不铸造认领或租约代次,既有过期租约仅保持原 lineage 后释放。
  2. requireCompletionDecisionOutcome:普通事项仅接受显式 cancel,拒绝 approve/reject;native Gate 可省略决定,legacy bridge 明确启用原有必填要求,未 materialize 的明确 Gate 决定仍拒绝。
  3. planUserCompletion:普通取消提前返回空 updates 和 decision_cancelled/changed=false;native Gate 无决定返回空计划,保留关联任务、要求、范围结果与认领。
  4. executeCoordinationTodoTerminalLifecycle:在新显式 complete 的效果发生前调用共享校验;历史回执先于新 admission 读取,CAS 和回执恢复继续负责并发、响应丢失与重放。
  5. require_completion_decision_outcome:删除 Python 原有 Gate-only 判断,传递锁内源事实到现有 typed bridge,并把已知协议拒绝转换成公共输入错误。

正向路径是 CLI 显式取消 → 原始绑定 admission → 行政终结判定 → 空关联更新 → CAS/回执 → 独立 canonical 读回及重试。负向路径包括异主体关闭、同时修改绑定后完成、活跃/错误租约、普通事项伪造批准,以及不完整 authority source;全部在效果发生前拒绝。拒绝后由真正绑定的主体关闭新事项,或由 fixture owner 恢复完整源后再次执行,能够恢复合法进展。

对主干的风险

主要风险是把取消当成批准,或将单事项绑定扩大成全 Goal 权限。独立运行同一 CLI harness 的 61 组 base/head 输入,完整比较公共返回、错误和持久化行:34 组保持一致,27 组为预期的合法行政关闭/取消及错误诊断变化,没有未解释差异。只规范化路径、时钟和生成的操作身份;主体、租约 lineage、范围、认领、字段存在性和完整错误保留。native Gate 无 outcome 在两版均成功且关联状态不变,legacy 的拒绝也保持一致。

当前 head 本地验证:672 个 TypeScript 用例(含 File/SQLite 事务与共享决策),隔离真实 PostgreSQL 16.15 的 315 个用例、零跳过;66 个公共 CLI/Chat/provider 用例及 149 个 authority/快照/交接兼容用例。另通过新事项绑定隔离与恢复、历史 Gate 回执跨版本重放、不完整源拒绝及恢复探针。测试没有访问活动 Goal 或真实业务状态。

将完整 PR patch 应用到主干 f2517a83f43249281103ec3964771043ed9a6446 后,79 个 Python 和 26 个 TypeScript 用例通过;源码构建的 packaged Chat HTTP 实际执行 preview/apply、成功与失败读回。相关主干新增 RPC/展示分支没有修改 Todo outcome owner。类型检查、配置内 Mypy、Ruff、diff/DCO 和风险选择的 19 项 premerge canary 均通过。语义 advisory 未发现支持语法内的新词汇载体;该结果不替代上述行为比较。

合并就绪检查另有明确 hold:当前远端分支为 BEHIND,ready=false 的原因是 merge_state_requires_update。这是分支更新条件,未发现源码阻塞;更新产生新 head 后应重新验证该 head 及合并门禁。

语义与 CI 对齐

复用现有 role、task_class、outcome、scope 与 receipt 词汇;关闭不授予执行权,提醒取消不授予 Gate 决定权。没有新增协议或默认关闭能力,机器门禁和调用方输入要求均明确。按当前 capability policy,未查询、轮询或等待 GitHub CI;批准依据为上述本地 owning-path 验证。

我的整体评价

当前完整 head 可以批准。长程连续性与 CLI 用户体验均改善:合法提醒能够持久关闭和重放,取消不会解锁后续工作,原有 native Gate 入口保持可用。这是现有 owner 内可独立验证、回滚的有效切片:修复合法关闭、分离取消效果、删除重复 Python 规则,并保留 native Gate 兼容性。未来重构检查已落实在共享校验 owner;进一步迁移 legacy hard-lease 终结适配器会扩大本次边界,当前没有必要加入。

交付的取消入口是 CLI/managed CLI;既有 Chat 完成入口及 canonical 完成读回已验证,不声明新增前端/Lark 取消控件。最强的未验证维度是实际安装版本对真实请求的采用与服务端读回;源码和合成 fixture 不能证明部署采用。legacy 独立 hard-lease 门禁、外部撤单/消息动作、自动到期与新 UI 入口仍在声明范围之外。控制面 PR 等待维护者合并。

English verdict: APPROVE - Exact head 7d125b2666c8ecf3980489e6640cd793c8624bb7; no blocking finding. Bound administrative closure and source-only cancellation preserve actor/lease/scope fences and native no-decision Gate compatibility. Independently validated 61 base/head CLI pairs, 672 TS tests, 315 isolated real PostgreSQL tests, scoped Python and packaged-HTTP/current-main integration; deployment adoption remains outside this source review. Maintainer merge required.

@huangruiteng
huangruiteng merged commit cef2311 into main Oct 1, 2026
24 of 29 checks passed
@huangruiteng
huangruiteng deleted the codex/user-action-lifecycle-20261001 branch October 1, 2026 10:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant