Skip to content

chore(release): prepare LoopX v1.2.1 - #5146

Merged
huangruiteng merged 1 commit into
mainfrom
codex/release-v1.2.1
Sep 26, 2026
Merged

huangruiteng merged 1 commit into
mainfrom
codex/release-v1.2.1

Conversation

@huangruiteng

@huangruiteng huangruiteng commented Sep 26, 2026 •

Copy link
Copy Markdown
Collaborator

LoopX v1.2.1 — recoverable work, clearer Chat and inspectable usage

This release includes 131 merged PRs since v1.2.0 and contributions from 12 community developers. It improves recovery and current-state readback, packages a more reliable App/Chat workflow, and makes basic usage statistics visible and controllable.

State Kernel & Recovery

Atomic Todo completion, lost-response reconciliation and typed backoff retain the original committed operation and receipt. Blocked Turns do not spend quota; selected leases, shared write waits and monitor fairness retain their owning rules. File history uses exact deltas/checkpoints with verified format backup and upgrade; original receipts and provider identity remain intact. Unexpected Turn failures preserve execution uncertainty and allowlisted original-journal recovery. (#5003, #5005, #5012, #5013, #5014, #5027, #5030, #5050, #5102, #5142, #5152, #5156, #5159, #5171)

The obsolete experimental Todo event replay, overlay, dual writer and automatic backfill paths are retired. A nonempty unpromoted legacy event source is refused unchanged, with actionable preservation/export guidance; independent Goals remain usable. Supervisor proposals and host receipts use a separate explicit local-private log. (#5054, #5105)

First-party Host journals and results gain partial exact-Goal instance fencing for the fresh source-session profile. This does not open the remaining M3 activation or external-effect drain hold. Archive restore/audit compares logical transactions and original receipts without selecting active authority or claiming whole-Goal rollback. (#5141, #5140)

App, Chat & Host Workflows

Chat shows actual current activity, accepts steering/interruption and saves long answers as reports. Pending drafts, canonical Todos, failed queued requests, saved-answer hydration and complete continuation context share existing owners. App loopback startup, Mac installation entry and Windows browser discovery are more reliable. (#4999, #5028, #5029, #5036, #5041, #5059, #5062, #5064, #5074, #5081, #5128, #5145, #5166)

Pi supports one user-scope extension installation while project bindings stay local. Delivery target preview/grant/revoke and read-only capability inspection expose their existing authority boundaries. Concurrent installation serializes shared Chat preparation before activation and preserves canary/rollback checks. (#4369, #5046, #5110, #5151)

Generic CLI and Codex CLI execution share the typed process supervisor: timeout, owner EOF and output-consumer failure clean bounded managed work; POSIX process-group cleanup includes leftover descendants after leader exit. This does not expand execution authority, provider fencing or attached App cancellation. (#5144)

Enabled native-child reporting records Turn-bound coordinator reports, results and evidence-backed parent review. It does not launch children or certify host attestation. (#5052)

Scoped runtime diagnosis remains available through existing delegation entrypoints while planning stays concise; it does not broaden execution authority. (#5176)

Usage & Reward Memory

Basic statistics use one CLI/App switch and outgoing preview. Visible first-use disclosure precedes the new default-on policy; prior explicit opt-outs persist. Heartbeat, CLI counts and independent Goal duration histograms describe separate populations and cannot be added together or treated as completion/billing. UTF-8 settings and daily heartbeat send ownership are repaired without changing consent, payload limits, disable fencing or no-retry behavior. (#5083, #5121, #5133, #5137, #5151, #5160)

Query-ready Reward Memory distinguishes qualified recall, private context delivery and attributed semantic assessment. Delivery/language views reflect verified caller results. Surface-scoped checkpoints share the existing typed owner; invalid freshness/read-authority input exposes allowlisted diagnostics while preserving fail-open behavior. Exact retained replay does not query again; no universal frontend/Lark adoption, cross-session persistence or benchmark uplift is claimed. (#5138, #5158, #5154)

Decision Context now reports per-source last successful read, freshness windows and failures, including unscanned sources. Capture host silence alerts through doctor; a healthy process never establishes source freshness. (#5075)

Contributors, Docs & Quality

Merged RFCs are accepted and claimable; contributor work comes from roadmap/RFC/reproduced defects, and ordinary bounded repairs need no ceremonial issue. Current docs remove retired prototype citations and record the accepted monorepo distribution design. (#5078, #5080, #5079, #5131, #5073, #5161, #5174)

DCO exempts only precisely verified GitHub-generated two-parent merge commits while checking underlying contributor commits. LF-framed Git/review/JSONL handling, credential-key shape and non-string rejection retain their public-safety semantics. Canonical registry IO ownership is current. (#5143, #5100, #5108, #5118, #5119, #5109, #5135, #5167, #5164, #5165, #5177, #5178, #5179, #5180, #5181)

Community Contributors

  • @JunZ-Leo (external, first contribution): registered binding and peer-route candidates; case-stable credential keys. (#5066, #5068, #5070, #5135)
  • @fengyin-solo (external, first contribution): complete handoff context with independent receiver acceptance. (#4444)
  • @jackie-cqz (external, first contribution): reject non-string fields at the public-safety boundary. (#5109)
  • @kokokoXUY (external, first contribution): LF-framed Git/review/JSONL records and accurate task-board/module references, indexed delivery envelopes, Windows browser discovery and UTF-8 usage state. (#5100, #5108, #5113, #5114, #5115, #5116, #5119, #5118, #5124, #5128, #5131, #5161, #5160)
  • @Duang777: recoverable Goal deletion, lock/history ordering, host output and queue reliability, packaged receipts, Windows upgrade isolation and partial exact-Goal Host fencing. (#5016, #5055, #5088, #5089, #5090, #5091, #5095, #5096, #5104, #5107, #5141)
  • @NIU-123370: current settings semantics, pre-read writer refusal, LF envelopes and typed diagnosis fallback. (#5043, #5044, #5053, #5058, #5061)
  • @hhyykk: faster public-boundary scanning while retaining the authoritative regex and Unicode behavior. (#3718)
  • @huashuai: heartbeat language follows the user language. (#4125)
  • @luw2007: discoverable Pi user-global extension installation and readback. (#4369)
  • @songoow: receipt-bound settlement and scheduler ACK attribution. (#5097)
  • @gcl-coder (external, first contribution): single-source the connected-adapter and periodic-report status vocabularies without changing classification. (#5164, #5165)
  • @yuedai-pbc: distinguish lost responses from absent committed operations in recovery coverage. (#5027)

Compatibility & Upgrade

Python 3.11+ and Node.js 22.22.3+ requirements are unchanged. There are explicit compatibility changes: current File physical format is required, recognized stores are backed up/upgraded before activation, and nonempty retired experimental Todo event sources need preservation/export with a compatible older release before migration. The supervisor experimental schema is separate; unknown old schemas refuse unchanged. No default provider promotion occurs.

Basic usage becomes default-on only after visible disclosure; previous explicit opt-out stays off. Inspect or disable it through the commands below or App Settings → Capability Center. Package acquisition, host material delivery, runtime activation and extension readiness are separate readbacks.

loopx update check
loopx update plan
loopx update apply
loopx --version
loopx doctor --deep
loopx --format json authority-archive upgrade --all-known --require-current
loopx usage-ping status

Restart the host after refreshing installed materials. For source/external package updates, preview authority-archive upgrade, then explicitly run --all-known --execute before the current-format readback. Do not overwrite later writes with a raw old backup. Native providers retain their own selection, lease and writer-fence boundaries.

Release Decision

Who should upgrade: Users of Goal Chat, Todo/quota recovery, File/SQLite history, Pi installation, Windows updates or contributor task discovery.
What this release solves: Lost-response ambiguity, incomplete Chat continuation/readback, duplicate retired Todo authority and insufficiently visible usage policy.
Breaking changes: Yes. Current File physical format and explicit legacy Todo-event recovery are required; basic usage becomes default-on after disclosure while prior opt-out persists. Provider selection is unchanged; partial instance enforcement does not open M3 execution authority.
How to verify: Confirm the installed version, deep doctor, current-format readback and actual local usage switch with the commands below.
Contributors: Twelve community developers are credited above, including external first-time contributors @JunZ-Leo, @fengyin-solo, @jackie-cqz, @kokokoXUY and @gcl-coder; each contribution is linked to its PRs.

loopx --version
loopx doctor --deep
loopx --format json authority-archive upgrade --all-known --require-current
loopx usage-ping status

Validation

Exact clean source fce1a4bac83ac9bdc9b8a6fc16a7849e06569ec9 passes all eight release qualifications. Final-source official CI JUnit test cases: 12,695 passed, 0 failed, 65 skipped; all 514 public smokes pass through the final-source official CI under their original budgets; all 19 selected premerge checks pass. Ruff, mypy, public-boundary scan, actual install/1.2.0 upgrade/sdist rebuild/Host material and packaged Chat HTTP pass. The actual doubao-seed-2-1-pro-260628 qualification passes 21 scenarios twice, 6 contrasts and 42 actor calls, with no failures or skips. The installed package passes 18 browser scenarios and five Python 3.11 checks. The optional native Codex Goal live probe is skipped because an isolated API profile is unavailable, as permitted by the testing guide; no live pass is claimed for it. These source qualifications do not claim benchmark improvement or production long-horizon completion. Post-publication verification passes: wheel/sdist and all four Mac/Windows desktop artifacts have matching checksums and GitHub build attestations for this tagged source; PyPI distributions match the attested GitHub bytes, and a fresh Python 3.11 PyPI install passes deep doctor, packaged Chat HTTP and Host material install/uninstall. The macOS updater signature verifies with the shipped public key, its feed matches desktop-stable, stable points at the tagged source, and the deployed homepage, installer and bilingual docs read back successfully. All six final-source CI/publication workflows pass.

Tag/version: v1.2.1 / 1.2.1; qualified source: fce1a4bac83ac9bdc9b8a6fc16a7849e06569ec9. macOS distribution uses ad-hoc signing and is not Apple-notarized; Windows artifacts are not publisher-signed. Platform build/attestation readbacks do not substitute for every end-user environment.

Optional Capability Activation & Use

Basic usage statistics

Activation: Enabled by default only after visible first-use disclosure. Previous explicit opt-out persists; loopx usage-ping enable explicitly allows all channels. The packaged App Settings → Capability Center uses the same switch and outgoing preview.

Validation: loopx usage-ping status shows policy, recipient and outgoing previews. Heartbeat, CLI counts and independent Goal duration histograms have separate populations; they are estimates, not unique Goals, completion, CPU time or billing.

Disable / rollback: loopx usage-ping disable stops every channel and clears the local random ID, pending counts and timing cursors. LOOPX_USAGE_PING=0 or DO_NOT_TRACK=1 also suppresses sending; distribution owners can require consent with LOOPX_USAGE_POLICY=consent_required.

Authority boundary: Heartbeat contains a random installation ID and platform/version fields; aggregates contain no identity or join key. No transcripts, paths, Goal/Agent IDs, raw prompts or credentials are sent. Cloudflare handles network metadata. Timing reads are bounded and local; no Goal write, scheduler or execution authority is granted.

Docs: Versioned usage guide

loopx usage-ping status
loopx usage-ping enable
loopx usage-ping status
loopx usage-ping disable

Pi user-global extension

Activation: loopx slash-commands --install --surface pi --pi-scope user installs discoverable extension code once at user scope; project-local bindings stay local and project scope remains the default.

Validation: loopx slash-commands --inspect --surface pi reads both scopes, including stale/partial/user-owned files and duplicate-load warnings.

Disable / rollback: loopx slash-commands --uninstall --surface pi --pi-scope user removes managed user-scope files while preserving user-owned edits.

Authority boundary: Installation is host material delivery. It neither moves project bindings nor grants repository, credential, network, merge or Goal execution authority.

Docs: Versioned usage guide

loopx slash-commands --install --surface pi --pi-scope user
loopx slash-commands --inspect --surface pi
loopx slash-commands --uninstall --surface pi --pi-scope user

External delivery targets

Activation: For an existing sender-bound channel and registered recipient, preview grant-delivery-target; add --execute only to grant the exact pair. Set CHANNEL_ID, GOAL_ID and AGENT_ID to actual registered identities and use the connection's registry/runtime.

Validation: Run the same grant command without --execute to read the target/count preview; this is policy readback, not proof that a worker adopted or executed a request.

Disable / rollback: loopx manager-inbox revoke-delivery-target --channel-id "$CHANNEL_ID" --goal-id "$GOAL_ID" --agent-id "$AGENT_ID" --execute revokes future delivery and replay to that target.

Authority boundary: No sender identity is created; no worker is launched. Delivery permission grants no protected operation, merge or unrelated Goal access.

Docs: Versioned usage guide

loopx manager-inbox grant-delivery-target --channel-id "$CHANNEL_ID" --goal-id "$GOAL_ID" --agent-id "$AGENT_ID"
loopx manager-inbox grant-delivery-target --channel-id "$CHANNEL_ID" --goal-id "$GOAL_ID" --agent-id "$AGENT_ID" --execute
loopx manager-inbox revoke-delivery-target --channel-id "$CHANNEL_ID" --goal-id "$GOAL_ID" --agent-id "$AGENT_ID" --execute

Capability inspection

Activation: loopx capability inspect --goal-id "$GOAL_ID" --format json is explicit and read-only. Adding both --agent-id "$AGENT_ID" --phase before_plan requests the existing bounded TS context projection.

Validation: Read effective config/source/revision and not_requested or no_contribution; use capability list/show for native provider readiness. An empty contribution does not mean all capabilities are disabled.

Disable / rollback: Stop invoking the inspection command. It creates no activation envelope or persistent switch to remove.

Authority boundary: Inspection writes no state, spends no quota, enables no feature, starts no worker and recalls no private memory. Configuration and context are independent reads, not a joint execution snapshot.

Docs: Versioned usage guide

loopx capability inspect --goal-id "$GOAL_ID" --format json
loopx capability inspect --goal-id "$GOAL_ID" --agent-id "$AGENT_ID" --phase before_plan --format json

Authority format upgrade

Activation: The normal installer/update path backs up and upgrades recognized File/SQLite stores before activation. Source checkouts or external package updates explicitly preview authority-archive upgrade, then use --all-known --execute.

Validation: loopx --format json authority-archive upgrade --all-known --require-current checks format compatibility; authority-archive inspect --source "$STORE_PATH" recognizes one actual store/backup. This is physical format qualification, not a provider cutover.

Disable / rollback: Do not overwrite newer writes with an old raw backup. Before binary rollback, the target runtime must pass --require-current; restore backup only to an isolated directory, then upgrade/export it through the documented fenced recovery path. There is no disable switch for required format compatibility.

Authority boundary: Upgrade preserves provider identity, revisions and original receipts, and does not change selectors, registries, leases or writer fences. Unknown/corrupt histories and failed backups stop activation; already-completed per-store upgrades remain explicit.

Docs: Versioned usage guide

loopx --format json authority-archive upgrade
loopx --format json authority-archive upgrade --all-known --execute
loopx --format json authority-archive upgrade --all-known --require-current

Goal Chat workflow

Activation: Run loopx chat and open the displayed local URL; existing owner/provider configuration remains authoritative. Chat shows in-flight activity, accepts steering/interruption and can save a long response as a report.

Validation: Open a Goal, inspect its current activity and saved report, and use loopx --format json status --goal-id "$GOAL_ID" for native state readback. Registration or attached claims do not by themselves prove execution.

Disable / rollback: Cancel the selected request through its existing Chat control; stop the local server with Ctrl-C. Stopping the server does not stop independently managed Goals or revoke their authority.

Authority boundary: The workflow uses existing Goal/Host ownership and protected-action gates; it grants no new repository, network, merge or external-recipient authority.

Docs: Versioned usage guide

loopx chat
loopx --format json status --goal-id "$GOAL_ID"

Query-ready Reward Memory consumption

Activation: Enable Reward Memory through its existing Goal configuration and qualified Agent/corpus/surface binding, then explicitly call the exported run_reward_memory_decision API with query_ready=True, an actual frozen question/artifact, mode=preview/recall_only/execute and the documented application strategy. There is no new global switch or automatic query.

Validation: loopx reward-memory evaluate --format json runs the shipped bounded contract suite; the caller must separately read context_delivery_verified and actual attributed applied/ignored/refuted semantic assessment. API import/configuration is not a live provider or utility result.

Disable / rollback: Return the caller to run_reward_memory_automatic_recall_hook; retain its unchanged optional callback semantics. Set automatic_recall=false through the existing configuration owner, or preview then execute configure-goal --clear-reward-memory-config to disable the experiment.

Authority boundary: Private queries, memories, current artifact and rationale remain caller-private. TS owns admission/completion and receives only compact projection. Exact caller-retained replay does not query again; no cross-session persistence, universal frontend/Lark consumption, memory write, merge or action authority is granted.

Docs: Versioned usage guide

python3 -c "from loopx.capabilities.reward_memory import run_reward_memory_decision, assess_reward_memory_decision"
loopx reward-memory evaluate --format json
loopx configure-goal --goal-id "$GOAL_ID" --clear-reward-memory-config
loopx configure-goal --goal-id "$GOAL_ID" --clear-reward-memory-config --execute

Archive recovery audit

Activation: Run the existing administration command authority-archive audit with an actual reviewed archive, its SHA-256, registered Goal identity and isolated destination. There is no new persistent enable switch; default exact mode checks all commits and original receipts.

Validation: Run authority-archive verify for the source digest, then audit the actual restored provider. Explicit --allow-newer-head checks only the retained archive prefix; later writes are outside that result.

Disable / rollback: Stop invoking audit; it changes no store or configuration. Restore is a separate preview/--execute operation into an isolated destination. Never roll back over later acknowledged writes.

Authority boundary: Audit is read-only. It grants no active provider selection, execution safety, writer-fence removal, lease transfer or rollback authority. Private archive copies need archive-sized temporary disk space; abrupt process death may leave private temporary files.

Docs: Versioned usage guide

loopx --format json authority-archive verify --archive "$ARCHIVE_PATH"
loopx --format json authority-archive audit --goal-id "$GOAL_ID" --archive "$ARCHIVE_PATH" --archive-sha256 "$ARCHIVE_SHA256" --destination "$RESTORED_PATH"
loopx --format json authority-archive audit --goal-id "$GOAL_ID" --archive "$ARCHIVE_PATH" --archive-sha256 "$ARCHIVE_SHA256" --allow-newer-head

Experimental supervisor log

Activation: For an existing registered Goal and peers, explicitly configure the supervisor and selected peers with configure-goal. This does not create sessions or supply a host adapter. With no configuration the workflow stays off.

Validation: supervisor-observe and supervisor-event list read the actual scoped proposal/receipt history. Preview a proposal before explicit --execute publication; a recorded proposal is not executed work.

Disable / rollback: configure-goal --clear-supervisor --execute removes activation. Preserve an old incompatible experimental supervisor log before starting fresh: unknown schemas are refused unchanged; no automatic conversion occurs.

Authority boundary: supervisor_log_event_v0 is local-private and independent of Todo state. TS owns identity/sequence admission; the existing Host owns capabilities, authority and external execution. The log grants no Todo mutation, scheduler, merge or exactly-once external action authority.

Docs: Versioned usage guide

loopx configure-goal --goal-id "$GOAL_ID" --supervisor-agent "$SUPERVISOR_AGENT_ID" --supervised-agent "$PEER_AGENT_ID" --execute
loopx supervisor-observe --goal-id "$GOAL_ID" --agent-id "$SUPERVISOR_AGENT_ID"
loopx supervisor-event list --goal-id "$GOAL_ID" --agent-id "$SUPERVISOR_AGENT_ID"
loopx configure-goal --goal-id "$GOAL_ID" --clear-supervisor --execute

Partial first-party Goal instance enforcement

Activation: Only a fresh isolated local project may explicitly select --goal-instance-profile source_session_v1 when project register creates its first Goal. Existing projects are not automatically migrated; installation and codec support do not activate this profile.

Validation: project resolve reads the exact registered GoalRef when both --goal-id and --goal-instance-id from registration are supplied. Bind/resolve/unbind require the returned goal_instance_id. Supported Turn, Codex, DSH and Kunlun state paths reject stale instance results; execution_authority remains false while the remaining M3 owners and external-effect drain are held.

Disable / rollback: Remove an exact session binding with project unbind-session. Before an incompatible cutover, abandon the isolated rehearsal; after publication use the documented forward-repair journal. Do not delete the envelope or run an older binary to bypass lifetime checks. There is no supported live-project downgrade switch.

Authority boundary: This is partial local-profile enforcement, not full M3 activation, global routing, provider promotion or execution permission. Legacy projects retain their prior behavior. No user session, credential or private Host content is exported by instance readback.

Docs: Versioned usage guide

loopx --registry "$ISOLATED_REGISTRY" project register --project-id instance-rehearsal --project-kind personal --knowledge-root "$ISOLATED_KNOWLEDGE_ROOT" --goal-id instance-rehearsal --objective "Inspect exact local Goal identity" --acceptance "Resolve the registered instance" --next-effect "Read project resolve" --stop-condition "Stop after identity readback" --goal-instance-profile source_session_v1 --operation-id register-rehearsal --format json > "$ISOLATED_REGISTRATION_JSON"
GOAL_INSTANCE_ID="$(node -p 'JSON.parse(require("fs").readFileSync(process.argv[1], "utf8")).goal.goal_instance_id' "$ISOLATED_REGISTRATION_JSON")"
loopx --registry "$ISOLATED_REGISTRY" project resolve --project-id instance-rehearsal --goal-id instance-rehearsal --goal-instance-id "$GOAL_INSTANCE_ID"
loopx --registry "$ISOLATED_REGISTRY" project unbind-session --session-id "$SESSION_ID" --goal-id instance-rehearsal --goal-instance-id "$GOAL_INSTANCE_ID" --operation-id unbind-rehearsal

Decision Context source freshness

Activation: Keep this experimental route default off unless an ignored private decision_context_profile_v0 explicitly has enabled=true, includes the exact Agent in enabled_agents and declares enabled sources with freshness_seconds. For scheduled reference capture, explicitly set automation.automatic_capture=true, source_ids to enabled incremental/exact-readable sources, interval_seconds and max_pending_batches; run capture --execute from your own bounded host scheduler.

Validation: capture-status with the same profile/spool/cursor arguments reads last successful read, staleness, failure streak and alerts. prepare-evidence/prepare-review also project source_freshness. doctor reads registered capture-host health; a healthy process, last attempt or enabled profile never proves fresh source content.

Disable / rollback: Stop the host scheduler, set automation.automatic_capture=false to stop capture, or enabled=false/remove the private profile to disable the route. Retain the private spool and receipts. Remove the exact retired host health record under the configured runtime-root/decision-context/capture-hosts after deliberately retiring its host; older binaries do not honor recovery holds.

Authority boundary: Reference capture stores bounded receipts/private replay cursors, no source bodies. Provider reads use existing source authority. Freshness does not grant external execution, memory writes, automatic semantic review, Goal promotion or a new heartbeat. Unscanned/failed sources remain visible and conclusions must disclose incomplete coverage.

Docs: Versioned usage guide

loopx decision-context inspect-profile --goal-id "$GOAL_ID" --agent-id "$AGENT_ID" --profile "$PRIVATE_PROFILE" --format json
loopx decision-context capture --goal-id "$GOAL_ID" --agent-id "$AGENT_ID" --profile "$PRIVATE_PROFILE" --spool "$PRIVATE_SPOOL" --cursor-state "$REVIEWED_CURSORS" --execute --format json
loopx decision-context capture-status --goal-id "$GOAL_ID" --agent-id "$AGENT_ID" --profile "$PRIVATE_PROFILE" --spool "$PRIVATE_SPOOL" --cursor-state "$REVIEWED_CURSORS" --format json
loopx doctor --deep

Host-native child reports

Activation: For an existing registered Goal/coordinator, explicitly configure --multi-subagent-feature enabled --max-children 2. Within an already admitted Turn carrying a settlement binding, use native-child record --execute with stable operation_id and an opaque existing host entrypoint. Host tools create the actual child; this command does not launch one.

Validation: native-child read returns that exact Turn report; status and agent-context after_delegate_result project it. Read decision/result/review separately: only completed results can be accepted, with public-safe evidence-ref and validation-ref. The report is coordinator_reported, host_attested=false; missing reports remain unknown.

Disable / rollback: configure-goal --multi-subagent-feature off --execute stops the configured child-worker route. Stop producing reports through the host integration and retain existing records for audit. If the local configuration UI was enabled, restart Dashboard without --enable-goal-subagent-configuration to remove that editor.

Authority boundary: A report grants no child launch, scheduling, quota spend, authority write or repository/credential/merge permission. max_children is only the Goal bound, not observed host capacity. Do not store raw prompts, errors, transcripts, paths or credentials; reporting does not replace LoopX delegation receipts or actual parent validation.

Docs: Versioned usage guide

loopx --registry "$REGISTRY" configure-goal --goal-id "$GOAL_ID" --multi-subagent-feature enabled --max-children 2 --execute
loopx --registry "$REGISTRY" native-child read --goal-id "$GOAL_ID" --agent-id "$COORDINATOR" --turn-instance-id "$TURN" --format json
loopx --registry "$REGISTRY" configure-goal --goal-id "$GOAL_ID" --multi-subagent-feature off --execute

Managed CLI Host process lifetime

Activation: Existing generic-cli and codex-cli turn run-once commands automatically use the shared process supervisor; no new opt-in switch. Explicit --host selects the existing adapter, and only --execute authorizes the admitted Turn. For an actual existing Goal, start with turn plan and the versioned quickstart, then supply an independent validator before execution.

Validation: The shipped loopx-turn-codex-cli-e2e-smoke.py runs a disposable model-free integration with independent validation and idempotent replay. Actual execution must read the typed Turn result/validation/spend receipt; process exit zero or closed pipes alone do not prove completion. Real Codex live calls remain a separate explicit --real-codex-cli opt-in.

Disable / rollback: Stop invoking the command or stop its owning host scheduler; timeout/owner EOF cleans managed work. POSIX cleanup uses the dedicated process group, including leftover descendants after leader exit. Do not use that group for intended persistent services. There is no unsafe per-command switch to bypass supervision; package rollback must separately satisfy current authority-format compatibility.

Authority boundary: This is process supervision, not a sandbox or execution permission. It adds no provider lease renewal, remote-effect cancellation, attached App-session cancellation or in-process DSH supervision. Windows tree cleanup is best effort; escaped descendants and killing the supervisor itself with SIGKILL remain outside the boundary. Raw output stays transient.

Docs: Versioned usage guide

loopx turn plan --goal-id "$GOAL_ID" --agent-id "$AGENT_ID" --host codex-cli --execution-mode isolated-headless
uv run --extra test python examples/loopx-turn-codex-cli-e2e-smoke.py

中文摘要

本版本包含 v1.2.0 以来合入的 131 个 PR 与 12 位社区开发者的贡献,改进恢复与当前状态读回,完善 App/Chat 流程,并让基础使用统计可见、可检查、可关闭。

状态内核与恢复

Todo 原子完成、响应丢失恢复及 typed backoff 保留原操作与回执;被阻塞 Turn 不扣额。Lease、共享写等待与 monitor 公平性继续使用既有 owner。File 用精确 delta/checkpoint 保存历史,格式升级先验证备份,保留原回执和 provider 身份。异常 Turn 保留执行不确定性与 allowlist 原 journal 恢复观察。(#5003, #5005, #5012, #5013, #5014, #5027, #5030, #5050, #5102, #5142, #5152, #5156, #5159, #5171)

退休旧实验 Todo event replay、overlay、双写与自动回填;非空且未 promoted 的旧源原样拒绝,并显示保存/导出指引,其他 Goal 继续可用。Supervisor proposal/host receipt 使用独立、显式启用的私有日志。(#5054, #5105)

新 source-session profile 的第一方 Host journal/结果加入局部 exact-Goal instance fencing;剩余 M3 activation 与 external-effect drain hold 没有解除。Archive restore/audit 对比逻辑事务和原回执,不选择活动 authority,也不宣称 whole-Goal rollback。(#5141, #5140)

App、Chat 与 Host 流程

Chat 展示真实当前活动,接收 steering/中断,保存长回答为报告。Pending draft、canonical Todo、失败队列请求、已保存回答 hydration 和完整 continuation 使用原 owner。App loopback 启动、Mac 安装入口和 Windows 浏览器发现更可靠。(#4999, #5028, #5029, #5036, #5041, #5059, #5062, #5064, #5074, #5081, #5128, #5145, #5166)

Pi 支持用户级一次安装,项目绑定仍留在项目;delivery target 的 preview/grant/revoke 和只读 capability inspect 呈现原权限边界。并发安装在激活前串行准备共享 Chat,保留 canary/回退检查。(#4369, #5046, #5110, #5151)

Generic CLI 与 Codex CLI 执行共享 typed process supervisor;timeout、owner EOF 与 output-consumer failure 清理受管工作,POSIX process group 包含 leader 退出后的遗留 descendants。不扩大执行权限、provider fencing 或 attached App cancellation。(#5144)

显式启用的 native-child reporting 记录 Turn-bound coordinator report、结果与带证据的 parent review,不启动 child,不证明 Host attestation。(#5052)

既有 delegation 入口保留 scoped runtime diagnosis,同时保持规划上下文简洁,不扩大执行权限。(#5176)

统计与 Reward Memory

基础统计共享 CLI/App 开关与待发送预览;可见首次披露先于新 default-on policy,既有显式 opt-out 保持关闭。Heartbeat、CLI 计数、独立 Goal 时长直方图有不同总体,不能相加或当成完成/账单。UTF-8 设置与每日 heartbeat 发送归属修复,consent、payload 上限、disable fencing 和失败不重试保持。(#5083, #5121, #5133, #5137, #5151, #5160)

Query-ready Reward Memory 区分合格召回、私有上下文交付和真实归因判断;delivery/language 视图依据已验证 caller 结果。Surface checkpoint 复用既有 typed owner,非法 freshness/read-authority 输入仅显示白名单诊断并保留 fail-open;准确保留的 replay 不重复查询,不宣称所有 frontend/Lark 采纳、跨 session 持久化或 benchmark 提分。(#5138, #5158, #5154)

Decision Context 按源报告最近成功读取、freshness window、连续失败及未扫描状态;capture host 静默由 doctor 告警,进程健康不证明源新鲜。(#5075)

贡献者任务、文档与质量

合入的 RFC 视为接受并可认领;贡献任务来源于 roadmap/RFC/已复现缺陷,普通有界修复无需仪式性 issue。文档清理退休 prototype 引用,并记录已接受的 monorepo distribution 设计。(#5078, #5080, #5079, #5131, #5073, #5161, #5174)

DCO 只豁免精确验证的 GitHub 双父自动合并提交,底层贡献提交仍逐一检查。Git/review/JSONL 的 LF 分帧、credential-key shape 与非字符串拒绝保留公开安全语义,canonical registry IO owner 已更新。(#5143, #5100, #5108, #5118, #5119, #5109, #5135, #5167, #5164, #5165, #5177, #5178, #5179, #5180, #5181)

社区贡献者

兼容性与更新

Python 3.11+、Node.js 22.22.3+ 要求不变。存在显式兼容变化:File 要求当前物理格式,识别出的 store 在激活前备份/升级;非空退休实验 Todo event 源须先用兼容旧版保存/导出,再迁移。Supervisor 实验 schema 独立,未知旧 schema 原样拒绝,不做默认 provider promotion。

基础统计只在可见披露后默认启用,原显式 opt-out 保持关闭;通过 CLI 或 App Settings → Capability Center 检查/关闭。包获取、Host 材料交付、运行时激活和扩展 readiness 是独立读数。

loopx update check
loopx update plan
loopx update apply
loopx --version
loopx doctor --deep
loopx --format json authority-archive upgrade --all-known --require-current
loopx usage-ping status

刷新材料后重启 Host。源码/外部包管理更新先预览 authority-archive upgrade,再显式 --all-known --execute,最后读回当前格式;不要用旧原始备份覆盖后续写入。原生 provider 的 selector/lease/writer fence 归属保持。

升级决策

**谁需要升级:**使用 Goal Chat、Todo/quota 恢复、File/SQLite 历史、Pi 安装、Windows 更新或贡献任务发现的用户。
**解决了什么:**响应丢失歧义、Chat continuation/读回缺口、重复退休 Todo authority 与统计 policy 不可见问题。
**是否有破坏性变更:**有。要求当前 File 物理格式与旧 Todo event 源显式恢复;基础统计在披露后默认启用,原 opt-out 保持。Provider 选择不变,局部 instance enforcement 不开放 M3 执行权限。
**如何验证:**通过下方命令确认安装版本、deep doctor、当前格式与本地真实 usage 开关。
**贡献者:**上方署名 12 位社区开发者,包含首次外部贡献者 @JunZ-Leo、@fengyin-solo、@jackie-cqz、@kokokoXUY、@gcl-coder,具体贡献均链接对应 PR。

loopx --version
loopx doctor --deep
loopx --format json authority-archive upgrade --all-known --require-current
loopx usage-ping status

发布验证

同一干净提交 fce1a4bac83ac9bdc9b8a6fc16a7849e06569ec9 通过全部八项发布资格。最终提交官方 CI JUnit 测试用例:12,695 通过、0 失败、65 跳过;514 项公共 smoke 在官方 CI 原预算下通过,全部 19 项 premerge 通过。Ruff、mypy、公开边界扫描、实际安装/1.2.0 升级/sdist 重建/Host 材料及打包 Chat HTTP 通过。真实 doubao-seed-2-1-pro-260628 验证 21 个场景各两次、6 个对照、42 次 actor 调用,零失败、零跳过。同源已安装包通过 18 项浏览器场景与 5 项 Python 3.11 检查。可选的 native Codex Goal live probe 因独立 API profile 不可用而按测试指南跳过,不宣称其真实执行通过;这些资格不等于 benchmark 提分或生产长时程完成。发行后独立读回通过:wheel/sdist 与全部四个 Mac/Windows 工件的校验和及 GitHub 构建证明绑定同一 tag 源码;PyPI 分发包与 GitHub 已证明的文件一致,全新 Python 3.11 PyPI 安装通过 deep doctor、打包 Chat HTTP 与 Host 材料安装/卸载。macOS updater 用随包公钥验签通过,feed 与 desktop-stable 一致,stable 指向该 tag 提交;线上首页、安装脚本及中英文文档读回通过,全部六个同源 CI/发布 workflow 通过。

版本/tag:1.2.1/v1.2.1;资格源码:fce1a4bac83ac9bdc9b8a6fc16a7849e06569ec9。macOS 使用 ad-hoc signing,未做 Apple notarization;Windows 工件没有 publisher signing。平台构建/attestation 读回不替代所有用户环境的实际验证。

可选能力启用与使用

Basic usage statistics

启用: 首次可见披露后默认开启基础统计;之前明确关闭的选择保持关闭。loopx usage-ping enable 显式允许所有通道;打包 App 设置 → 能力中心使用相同开关与发送预览。

验证: loopx usage-ping status 读取策略、接收方与待发送预览。Heartbeat、CLI 计数与 Goal 时长使用独立总体;是估算,不是唯一 Goal 数、完成量、CPU 时间或账单。

停用 / 回退: loopx usage-ping disable 关闭全部通道并清除本地随机 ID、待发送计数和时长游标;环境变量 LOOPX_USAGE_PING=0 或 DO_NOT_TRACK=1 也可抑制发送。分发方可设置 LOOPX_USAGE_POLICY=consent_required 要求明确同意。

权限边界: Heartbeat 含随机安装 ID 与平台/版本字段;聚合不含身份或 join key。不发送对话、路径、Goal/Agent ID、原始 prompt 或凭据;Cloudflare 仍处理网络元数据。本地时长读取受限,不授予 Goal 写入、调度或执行权限。

文档: 版本化使用文档

loopx usage-ping status
loopx usage-ping enable
loopx usage-ping status
loopx usage-ping disable

Pi user-global extension

启用: loopx slash-commands --install --surface pi --pi-scope user 在用户级安装可发现的扩展代码;项目绑定仍在本项目,默认安装范围仍是 project。

验证: loopx slash-commands --inspect --surface pi 读取两个范围,报告过期、部分安装、用户文件及重复加载。

停用 / 回退: loopx slash-commands --uninstall --surface pi --pi-scope user 删除受管用户级文件并保留用户修改。

权限边界: 安装仅交付 Host 材料,不移动项目绑定,也不授予仓库、凭据、网络、合并或 Goal 执行权限。

文档: 版本化使用文档

loopx slash-commands --install --surface pi --pi-scope user
loopx slash-commands --inspect --surface pi
loopx slash-commands --uninstall --surface pi --pi-scope user

External delivery targets

启用: 已有 sender 绑定通道和注册接收方时,先预览 grant-delivery-target;加 --execute 只授权准确的接收对。CHANNEL_ID、GOAL_ID、AGENT_ID 使用实际注册身份,并使用连接的 registry/runtime。

验证: 同一 grant 命令不加 --execute 读取目标与计数预览;这是策略读回,不证明 worker 已采纳或执行请求。

停用 / 回退: loopx manager-inbox revoke-delivery-target --channel-id "$CHANNEL_ID" --goal-id "$GOAL_ID" --agent-id "$AGENT_ID" --execute 撤销未来投递与 replay。

权限边界: 不创建 sender 身份、不启动 worker,投递许可不授予受保护操作、合并或其他 Goal 访问权限。

文档: 版本化使用文档

loopx manager-inbox grant-delivery-target --channel-id "$CHANNEL_ID" --goal-id "$GOAL_ID" --agent-id "$AGENT_ID"
loopx manager-inbox grant-delivery-target --channel-id "$CHANNEL_ID" --goal-id "$GOAL_ID" --agent-id "$AGENT_ID" --execute
loopx manager-inbox revoke-delivery-target --channel-id "$CHANNEL_ID" --goal-id "$GOAL_ID" --agent-id "$AGENT_ID" --execute

Capability inspection

启用: loopx capability inspect --goal-id "$GOAL_ID" --format json 是显式只读入口;同时提供 --agent-id "$AGENT_ID" --phase before_plan 才读取既有受限 TS 上下文投影。

验证: 读取有效配置、来源、版本及 not_requested/no_contribution;provider 原生可用性仍读 capability list/show。空贡献不表示全部能力关闭。

停用 / 回退: 停止调用该检查命令即可;没有新启用 envelope 或持久开关要清除。

权限边界: 检查不写状态、不扣额、不启用能力、不启动 worker、不召回私有记忆。配置与上下文是独立读数,不是联合执行快照。

文档: 版本化使用文档

loopx capability inspect --goal-id "$GOAL_ID" --format json
loopx capability inspect --goal-id "$GOAL_ID" --agent-id "$AGENT_ID" --phase before_plan --format json

Authority format upgrade

启用: 正常安装/更新会先备份并升级识别出的 File/SQLite store,再激活运行时。源码或外部包管理更新先预览 authority-archive upgrade,再显式使用 --all-known --execute。

验证: loopx --format json authority-archive upgrade --all-known --require-current 检查格式兼容;authority-archive inspect --source "$STORE_PATH" 识别实际 store/备份。此操作不等于 provider 切换。

停用 / 回退: 不要用旧原始备份覆盖新写入。二进制回退前,目标运行时必须通过 --require-current;备份只恢复到隔离目录,再按文档升级/导出并执行受 fence 保护的恢复。必需格式兼容没有关闭开关。

权限边界: 升级保留 provider 身份、版本和原回执,不改 selector、registry、lease 或 writer fence。未知/损坏历史、备份失败会阻止激活;已完成的逐 store 升级仍据实报告。

文档: 版本化使用文档

loopx --format json authority-archive upgrade
loopx --format json authority-archive upgrade --all-known --execute
loopx --format json authority-archive upgrade --all-known --require-current

Goal Chat workflow

启用: 运行 loopx chat 并打开显示的本地地址;仍使用原 owner/provider 配置。Chat 展示进行中的活动,接收 steering/中断,并可把长回复保存为报告。

验证: 打开 Goal,检查当前活动与保存的报告;loopx --format json status --goal-id "$GOAL_ID" 读取原生状态。注册或 attached claim 本身不证明执行。

停用 / 回退: 用既有 Chat 控件取消选定请求;Ctrl-C 停止本地服务。停止服务不等于停止独立受管 Goal 或撤销其权限。

权限边界: 继续使用现有 Goal/Host 归属和受保护操作 gate,不授予新的仓库、网络、合并或外部收件方权限。

文档: 版本化使用文档

loopx chat
loopx --format json status --goal-id "$GOAL_ID"

Query-ready Reward Memory consumption

启用: 通过原 Goal 配置与已验证 Agent/corpus/surface 绑定启用 Reward Memory,再显式调用导出 API run_reward_memory_decision:query_ready=True,提供真实冻结的问题/当前产物、preview/recall_only/execute 模式及文档中的应用策略。没有新全局开关或自动生成问题。

验证: loopx reward-memory evaluate --format json 运行受限合同套件;调用方另读 context_delivery_verified 与真实归因的 applied/ignored/refuted 判断。导入/配置不证明实际 provider 调用或效用提升。

停用 / 回退: 调用方回到 run_reward_memory_automatic_recall_hook,原可选 callback 语义不变。通过原配置 owner 设置 automatic_recall=false,或先预览再 execute configure-goal --clear-reward-memory-config 关闭实验。

权限边界: 问题、经验、当前产物及判断正文仅留在调用方私有上下文;TS 持有准入/完成语义,仅接收紧凑投影。准确保留结果的 replay 不重复查询,不提供跨 session 持久化、所有前端/Lark 消费、记忆写入、合并或行动权限。

文档: 版本化使用文档

python3 -c "from loopx.capabilities.reward_memory import run_reward_memory_decision, assess_reward_memory_decision"
loopx reward-memory evaluate --format json
loopx configure-goal --goal-id "$GOAL_ID" --clear-reward-memory-config
loopx configure-goal --goal-id "$GOAL_ID" --clear-reward-memory-config --execute

Archive recovery audit

启用: 使用原 administration 命令 authority-archive audit,提供实际审阅的 archive、SHA-256、注册 Goal 身份与隔离恢复目录。没有持久启用开关;默认 exact 模式检查全部 commit 与原始回执。

验证: 先用 authority-archive verify 取得源 digest,再 audit 实际恢复后的 provider。显式 --allow-newer-head 只验证保留的 archive 前缀,后续写入不在该结果范围内。

停用 / 回退: 停止调用 audit 即可,不改变 store 或配置。restore 仍是对隔离目录的独立 preview/--execute 操作,不能覆盖后来已确认的写入来回退数据。

权限边界: Audit 只读,不授予活动 provider 选择、执行安全、writer fence 移除、lease 转移或 rollback 权限。私有输入副本需要约 archive 大小的临时磁盘空间;进程突然死亡可留下私有临时文件。

文档: 版本化使用文档

loopx --format json authority-archive verify --archive "$ARCHIVE_PATH"
loopx --format json authority-archive audit --goal-id "$GOAL_ID" --archive "$ARCHIVE_PATH" --archive-sha256 "$ARCHIVE_SHA256" --destination "$RESTORED_PATH"
loopx --format json authority-archive audit --goal-id "$GOAL_ID" --archive "$ARCHIVE_PATH" --archive-sha256 "$ARCHIVE_SHA256" --allow-newer-head

Experimental supervisor log

启用: 对既有已注册 Goal 和 peer,用 configure-goal 显式配置 supervisor 与选定 peer;不创建 session,也不提供默认 host adapter。无配置时流程关闭。

验证: supervisor-observe 与 supervisor-event list 读取真实 scoped proposal/receipt。先预览 proposal,再显式 --execute 发布;记录 proposal 不表示已执行工作。

停用 / 回退: configure-goal --clear-supervisor --execute 清除启用。开始新日志前保存旧的不兼容实验日志:未知 schema 原样拒绝,不自动转换。

权限边界: supervisor_log_event_v0 为 local-private,与 Todo 状态独立。TS 持有 identity/sequence,既有 Host 持有 capability、authority 和外部执行。不授予 Todo 修改、scheduler、merge 或外部动作恰好一次权限。

文档: 版本化使用文档

loopx configure-goal --goal-id "$GOAL_ID" --supervisor-agent "$SUPERVISOR_AGENT_ID" --supervised-agent "$PEER_AGENT_ID" --execute
loopx supervisor-observe --goal-id "$GOAL_ID" --agent-id "$SUPERVISOR_AGENT_ID"
loopx supervisor-event list --goal-id "$GOAL_ID" --agent-id "$SUPERVISOR_AGENT_ID"
loopx configure-goal --goal-id "$GOAL_ID" --clear-supervisor --execute

Partial first-party Goal instance enforcement

启用: 仅在全新的隔离本地项目中,project register 创建首个 Goal 时显式选择 --goal-instance-profile source_session_v1。现有项目不自动迁移;安装与 codec 支持不等于启用。

验证: project resolve 使用注册返回的 --goal-id 与 --goal-instance-id 读回真实 GoalRef;bind/resolve/unbind 使用返回的 goal_instance_id。受支持的 Turn、Codex、DSH、Kunlun 状态路径拒绝旧 instance 返回;其余 M3 owner 与 external-effect drain 仍处于 hold,execution_authority 继续为 false。

停用 / 回退: 用 project unbind-session 移除精确 session 绑定。不可兼容切换前可放弃隔离演练,发布后按文档 forward-repair journal 修复;不能删除 envelope 或运行旧二进制绕过 lifetime 检查,没有受支持的活动项目降级开关。

权限边界: 这是局部 local-profile enforcement,不是完整 M3 启用、全局路由、provider promotion 或执行权限。旧项目维持原行为;instance 读回不导出用户 session、凭据或私有 Host 内容。

文档: 版本化使用文档

loopx --registry "$ISOLATED_REGISTRY" project register --project-id instance-rehearsal --project-kind personal --knowledge-root "$ISOLATED_KNOWLEDGE_ROOT" --goal-id instance-rehearsal --objective "Inspect exact local Goal identity" --acceptance "Resolve the registered instance" --next-effect "Read project resolve" --stop-condition "Stop after identity readback" --goal-instance-profile source_session_v1 --operation-id register-rehearsal --format json > "$ISOLATED_REGISTRATION_JSON"
GOAL_INSTANCE_ID="$(node -p 'JSON.parse(require("fs").readFileSync(process.argv[1], "utf8")).goal.goal_instance_id' "$ISOLATED_REGISTRATION_JSON")"
loopx --registry "$ISOLATED_REGISTRY" project resolve --project-id instance-rehearsal --goal-id instance-rehearsal --goal-instance-id "$GOAL_INSTANCE_ID"
loopx --registry "$ISOLATED_REGISTRY" project unbind-session --session-id "$SESSION_ID" --goal-id instance-rehearsal --goal-instance-id "$GOAL_INSTANCE_ID" --operation-id unbind-rehearsal

Decision Context source freshness

启用: 实验入口默认关闭:仅 ignored 私有 decision_context_profile_v0 的 enabled=true、enabled_agents 包含准确 Agent,且源显式配置 freshness_seconds 时启用。定时引用 capture 另显式设置 automation.automatic_capture=true、已启用 incremental/exact-readable source_ids、interval_seconds 与 max_pending_batches,由自有受限 host scheduler 调用 capture --execute。

验证: 以相同 profile/spool/cursor 参数运行 capture-status,读取最近成功读取、过期、连续失败与告警;prepare-evidence/prepare-review 同样投影 source_freshness。doctor 检查已登记 capture host 健康;进程健康、最近尝试或 profile 已开不证明内容新鲜。

停用 / 回退: 先停 host scheduler,设置 automation.automatic_capture=false 停 capture;enabled=false 或移除私有 profile 关闭入口,保留私有 spool 与回执。明确退休 host 后,移除配置 runtime-root/decision-context/capture-hosts 下对应的 host health record;旧二进制不遵守 recovery holds。

权限边界: Capture 仅存有界引用回执与私有 replay cursor,不存源正文;provider 读取继续使用原授权。不授予外部执行、记忆写入、自动语义评审、Goal promotion 或新 heartbeat。未扫描/失败源仍显示,结论必须披露覆盖缺口。

文档: 版本化使用文档

loopx decision-context inspect-profile --goal-id "$GOAL_ID" --agent-id "$AGENT_ID" --profile "$PRIVATE_PROFILE" --format json
loopx decision-context capture --goal-id "$GOAL_ID" --agent-id "$AGENT_ID" --profile "$PRIVATE_PROFILE" --spool "$PRIVATE_SPOOL" --cursor-state "$REVIEWED_CURSORS" --execute --format json
loopx decision-context capture-status --goal-id "$GOAL_ID" --agent-id "$AGENT_ID" --profile "$PRIVATE_PROFILE" --spool "$PRIVATE_SPOOL" --cursor-state "$REVIEWED_CURSORS" --format json
loopx doctor --deep

Host-native child reports

启用: 已有注册 Goal/coordinator 时,显式配置 --multi-subagent-feature enabled --max-children 2;在已准入且有 settlement binding 的 Turn 中,用稳定 operation_id 与既有不透明 host entrypoint 执行 native-child record --execute。实际 child 由 Host 工具创建,此命令不启动 child。

验证: native-child read 读取准确 Turn report;status 与 agent-context after_delegate_result 投影同一数据。分别检查 decision/result/review,只有 completed 可被接受,须携带公开安全 evidence-ref 与 validation-ref。回执为 coordinator_reported、host_attested=false;缺记录表示 unknown。

停用 / 回退: configure-goal --multi-subagent-feature off --execute 关闭配置的 child-worker 路径;Host 集成停止写 report,保留既有审计记录。若曾启用配置 UI,重启 Dashboard 时移除 --enable-goal-subagent-configuration 即移除编辑器。

权限边界: 报告不授予启动 child、调度、扣额、authority 写入或仓库/凭据/合并权限;max_children 只是 Goal 上限,不是已观察 Host 容量。不存原始 prompt、错误正文、对话、路径或凭据;不能替代 LoopX delegation receipt 与真实 parent validation。

文档: 版本化使用文档

loopx --registry "$REGISTRY" configure-goal --goal-id "$GOAL_ID" --multi-subagent-feature enabled --max-children 2 --execute
loopx --registry "$REGISTRY" native-child read --goal-id "$GOAL_ID" --agent-id "$COORDINATOR" --turn-instance-id "$TURN" --format json
loopx --registry "$REGISTRY" configure-goal --goal-id "$GOAL_ID" --multi-subagent-feature off --execute

Managed CLI Host process lifetime

启用: 既有 generic-cli/codex-cli turn run-once 自动使用共享 process supervisor,无新开关。--host 显式选择原 adapter,只有 --execute 执行已准入 Turn;已有 Goal 先 turn plan,再按版本化 quickstart 提供独立 validator。

验证: 仓库 loopx-turn-codex-cli-e2e-smoke.py 运行隔离、无模型的真实集成,验证独立 postcondition 与幂等 replay;实际执行须读 typed Turn result/validation/spend receipt,进程退出零或 pipe 关闭不能证明完成。真实 Codex 调用仍须显式 --real-codex-cli。

停用 / 回退: 停止调用或停 owning host scheduler;timeout/owner EOF 清理受管工作。POSIX 清理独立 process group,包括 leader 退出后的遗留 child;不要在该 group 启动预期长期服务。无绕过 supervision 的开关;包回退另须满足当前 authority-format 兼容。

权限边界: 这是进程 supervision,不是 sandbox 或执行授权。不增加 provider lease renewal、远端 effect 取消、attached App session 取消或 in-process DSH supervision。Windows tree cleanup 尽力而为;逃逸 descendants 与 SIGKILL supervisor 本身不在保证内。原输出仅瞬态。

文档: 版本化使用文档

loopx turn plan --goal-id "$GOAL_ID" --agent-id "$AGENT_ID" --host codex-cli --execution-mode isolated-headless
uv run --extra test python examples/loopx-turn-codex-cli-e2e-smoke.py

Compare: v1.2.0…v1.2.1

Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>

@huangruiteng huangruiteng left a comment •

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Reviewed exact head: 5146@4fd27d01934a72f783b4033d5cba321630bdccf5.

动机

维护者要求发布 LoopX1.2.1。当前主干已经包含待发布改动,但运行时与 PyPI 项目版本仍为1.2.0,无法形成新的命名安装包。公开时间线也遗漏了已经发布的1.2.0,导致仓库卫生检查失败。这项准备把现有版本来源同步到1.2.1,并补记实际发布过的历史记录。

改动思路

沿用 loopx.__version__ 与 pyproject.toml 的既有版本约定,不添加版本服务或新的发布分支规则。时间线仅补充已存在的1.2.0发布时间和提交,不提前声称1.2.1已经发布。更小的只改一个常量方案会让运行时和包元数据不一致;把完整发布测试放到尚未合入的分支上,也无法证明最终合并提交。版本 PR 因此是有用且可回退的发布准备阶段。

具体改动

完整 base-to-head 只有三个文件、7行增加和2行删除:loopx/__init__.py:5 与 pyproject.toml:7 同步为1.2.1,docs/product/release-readiness.md 补上1.2.0实际发布记录。已经通过真实 CLI 版本读回、版本/manifest/更新契约 smoke,以及41个发布与更新测试;一个原有 Windows 专属测试在 macOS 跳过。前端和打包 Chat 构建成功,仓库卫生检查通过。风险预合入检查执行当前目录和文档选择的检查,质量回执绑定当前最终差异;这些局部结果不冒充最终发布提交的全量资格。持续工作与用户体验均保持:本 PR 不改配额、状态、重试、安装 owner 或能力开关,现有用户仍显式检查、升级并读取 doctor。剩余工作由本次发布操作负责:在干净的合并提交运行完整发布资格,再发布 tag、包和双语说明,边界是先固定不可变的发布源码。

对主干的风险

版本值会参与包元数据、manifest、更新判断和标签匹配,单边修改可能造成安装成功但版本不一致,既有契约测试覆盖了该失败方式。此处同步更新两个现有来源,历史发布说明以远程 release 时间与真实提交为依据,不增加状态或权限机制。没有新的前端交互、首屏、自动部署或默认能力变化。当前验证不代表已安装用户运行时已经升级,也不代表已发布包已通过下载校验;最终发布仍须满足同一干净提交的全量检查、实际默认模型行为、安装/升级/host 和远程产物读回。原有 Windows skip 保留为未执行,不标记为通过。

我的整体评价

这个准备阶段符合命名版本的必要契约,范围完整且足够小。未来改动便利性检查认为两个既有版本字段和一条历史记录无需额外重构。当前 head 可以合入;合入是发布准备完成,发布请求仍由后续精确提交资格与真实产物交付完成。无行动项或未修复问题。

English verdict: APPROVE

@huangruiteng
huangruiteng merged commit 6830e4f into main Sep 26, 2026
7 of 8 checks passed
@huangruiteng
huangruiteng deleted the codex/release-v1.2.1 branch September 26, 2026 19:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant