Skip to content

feat(goal-channel): compose scoped claims and private reconnect context (#5198) - #5248

Draft
LIHUA919 wants to merge 19 commits into
loopx-project:mainfrom
LIHUA919:codex/im-ov-room-claim
Draft

LIHUA919 wants to merge 19 commits into
loopx-project:mainfrom
LIHUA919:codex/im-ov-room-claim

Conversation

@LIHUA919

@LIHUA919 LIHUA919 commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Result and scope

Related to #5198 (S3/S6/S9). Proposed head: 87ac09725; base: main at 738115bde87e. This proposal joins existing Goal Channel delivery, canonical Todo claims and private read-only Turn Recall. It delivers the local legacy-profile stage; the full live collaboration acceptance remains open.

goal-channel work project|claim publishes content-minimal orientation and historical claim receipts with current ownership. offer|revoke grants one revision-bound native claim interaction to explicit principals; the existing default-off collector verifies provider membership, originating card, source route, registered Agent, binding and expiry. Exact retries recover the canonical receipt; transport recovery only repairs the result card.

work resume reads current channel identity, canonical work and an admitted Turn, retrieves scoped context anew, then rereads authority and quota. Changes discard earlier observations, context and references. Only explicitly requested scoped artifact pointers covered by current verified recall receipts are carried. The private packet sends no room message, accepts no claim, renews no lease, spends no quota and skips memory-ingest reconciliation.

Ownership and compatibility

Reuse the existing typed Todo, Goal Channel, collector and recall owners. No new store, provider, scheduler or configuration editor. Existing Agent connection and Reward Memory editors remain sufficient for this explicit CLI path. No authored frontend or public first-screen change; native card screenshots remain unqualified.

Promoted direct claims deliberately reject foreign bound_agent. Both existing claim wire versions and the domain owner reject explicit unqualified goal_ref before provider or historical-receipt access. Source-session business effects remain closed: lifetime-bound head/receipts, retirement serialization and old-writer fencing must first qualify under the existing shared-authority/Goal-instance owners. That later profile boundary is not a prerequisite for the supported legacy-profile local stage.

Future-facing pass: reuse shared typed admission/readback and the public quota loader; keep private offers outside Todo lifecycle authority. Collector feature-off behavior and ordinary recall defaults remain unchanged.

Validation

Synthetic Lark/provider transport and disposable real File/SQLite stores; no active Goal was promoted or used for testing.

  • 110 room/claim/callback/restore regressions passed. Competition now uses two source CLI processes with separate TS runtimes; a new client/runtime retries the winning tuple, followed by separate direct CLI ownership readback. One transition and one result card; no private content or execution grant.
  • 58 outbound-guidance and runtime UTF-8 checks passed after repairing a stale loader mock and explicit UTF-8 offer reading. Changed Python Ruff and diff checks passed.
  • All 19 standard premerge checks passed against pinned main 738115bde87e. An earlier concurrent run timed out one unchanged smoke; it passed alone in 48.09 seconds under the original 120-second limit, followed by the successful full rerun. No limits changed.
  • Full CI: the prior head had two proposal regressions, now repaired locally, plus six failures also present on pinned main 738115bde87e (main run, prior-head run). The base failures concern canonical User Todo fixtures and scheduler ACK. Exact-head CI on 87ac09725 completed with those same six pinned-main failures (run). No additional proposal failure was observed. DCO, dependency review, builds, typed core, dashboard acceptance and real PostgreSQL integration passed; full-CI and merge acceptance remain blocked.

Negative coverage includes stale/duplicate claims, revoked principals/Agent/binding, Bot/message/card mismatch, expiry, authority loss, retrieval-time scope/quota/selection/revision changes, expired/foreign memory and read-only ingest isolation. No PostgreSQL provider changed; local evidence does not qualify shared-service operation.

Remaining gates

Keep draft status and maintainer merge ownership. Untested: authorized native non-production rendering/listener, independently authenticated hosts, live daemon reconnect, scoped OpenViking retrieval and arbitrary external artifact target access. Reuse #3245, #4339 and #3964 for their existing authority, handoff and provisioning boundaries. A merged PR alone does not close #5198 or the RFC.

@LIHUA919 LIHUA919 changed the title feat(goal-channel): compose canonical local room work (#5198) feat(goal-channel): compose scoped room claims and callbacks (#5198) Sep 28, 2026
@mergify

mergify Bot commented Sep 28, 2026

Copy link
Copy Markdown

This pull request has merge conflicts with main and cannot be merged
until they are resolved. Please rebase or merge the base branch, @LIHUA919.

Choose the remote for the base repository, not an out-of-date fork.
For a fork clone, first inspect git remote -v; upstream must point
to https://github.com/loopx-project/loopx.git. If it is absent, add it
with git remote add upstream https://github.com/loopx-project/loopx.git.
Then run:

git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEAD

For a same-repository clone whose origin points to
https://github.com/loopx-project/loopx.git, use origin instead of
upstream for fetch/rebase. If you prefer merging the base, use
git merge <base-remote>/main and push normally.

Keep the DCO Signed-off-by trailer on every commit when you rebase.
https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/syncing-a-fork

@mergify mergify Bot added the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Sep 28, 2026
…dback

Signed-off-by: Lihua <1017343802@qq.com>
…alification

Signed-off-by: Lihua <1017343802@qq.com>
Signed-off-by: Lihua <1017343802@qq.com>
@LIHUA919 LIHUA919 changed the title feat(goal-channel): compose scoped room claims and callbacks (#5198) feat(goal-channel): compose scoped claims and private reconnect context (#5198) Sep 28, 2026
@mergify mergify Bot removed the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Sep 28, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Task][RFC]: Deliver the Agent IM / LoopX / OpenViking collaboration contract

1 participant