Skip to content

feat(steward): replace Goal Channel templates with intelligent notices - #5480

Merged
huangruiteng merged 8 commits into
mainfrom
codex/steward-local-notices
Oct 2, 2026
Merged

huangruiteng merged 8 commits into
mainfrom
codex/steward-local-notices

Conversation

@huangruiteng

@huangruiteng huangruiteng commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

Goal And Delivered Outcome

Goal Channel currently renders separate mechanical human-gate and blocked-Todo templates. This change uses the configured steward to explain the decision, impact and useful next step, while retaining canonical selection, delivery permission and receipt authority.

Author Declaration

  • Written by: model_agent, OpenAI Codex (GPT-6 family).
  • Specification and revision: docs/architecture/rfcs/goal-channel-collaboration-v0.md, “Local steward intake and optional channel delivery”, refined in this PR; existing authority/delivery contracts at the base above. Companion checkpoints update the capable-manager RFC, presentation RFC and overall roadmap in both languages.
Criterion Disposition Owner / evidence
Local facts independent of optional transport implemented TS presentation/goal_attention.ts; real isolated File and SQLite canonical reads without Channel or history; native runtime input verification.
Shared facts, steward expression, existing effects implemented Existing manager-context capability and Lark adapters. Complete decision references, same-subject composition, exact source/audience revalidation and restricted Chat runtime.
Retry and authority preservation implemented Body saved before send; retries keep the body/key; ambiguous legacy attempts require reconciliation; model failure retains pending state without a template fallback.
Existing frontend discovery/control/readback implemented Existing Goal capability settings explain model usage and unverified receipt state; independent switches retain their current defaults.
Proactive idle wake, cross-Goal batching, local presentation/read/recovery receipts, sustained quality deferred Existing presentation Stage 2/R3 acceptance remains open.

Self-check: reviewed the final diff and shared typed owners; checked canonical source and audience changes, generation/provider failure, retries, legacy ambiguity, deduplication and default-off behavior. No new capability, inbox, scheduler or notification store. Python remains an I/O/runtime adapter; TypeScript owns attention composition and complete reference validation. The whole Turn includes at most twelve subjects and preserves omitted coverage for existing scoped reads.

Scope And Continuation

This is an independently reversible replacement of the shipped sending path plus default evidence intake in existing Turns. Local intake does not wake an idle steward or prove presentation/readback. External synthesis uses an isolated audience transcript and does not borrow a live owner session; full conversation continuity remains open. Agent-owned recovery remains canonical work rather than a new approval.

The bounded refactor removes both templates and the duplicate blocker collector/public-safe request filter. Human-gate delivery still defaults on for new Channel setup, existing bindings keep their setting, and blocked delivery remains default-off. Enabled external notifications now use the configured steward model and its budget; startup is bounded to 30 seconds and reasoning to 90 seconds per synthesis.

Self-Repair

The prior exact-head review reproduced incorrect decision IDs accepted through substring matching. The existing TS decision-notice owner now checks whole identifier tokens, shared by both senders and cached-body retries. Punctuation and Markdown remain valid; prefixes/suffixes and missing complete references reject delivery. Fifteen negative cases failed before the fix; the same twenty-nine positive/negative cases now pass, with two additional invalid-cache retry cases. The RFC records this as a delivery obligation.

A broader 410-test run also exposed ten receipt-test failures caused by omitted shared synthesis fixtures during mixed-root collection; the other 400 cases passed. Four consumers now explicitly import the same fixture. The original306-case notification/context sequence passes after this repair; production behavior and test expectations are unchanged.

Freshness previously hashed every Goal Todo, rejecting an otherwise valid notice after independent work changed. It now witnesses the selected request/blocker facts and referenced continuation, reusing quota compact fields while retaining full canonical reads, lifecycle and audience checks. Both senders carry the relevant continuation. Eight independent-note/new-Todo cases fail on the old source, with five quiet controls passing; twenty-eight production sender/Chat cases on real isolated File/SQLite verify that independent changes send once and selected content, lifecycle, continuation or audience changes refuse sending.

Validation

  • Tested revision: 1d1dbcd241c0883b8719df643224043c89ad1bda.
  • Source qualification: final source runs the complete334-test mixed-root suite, Ruff/mypy, exact-scope quality, paired File/SQLite/sender paths and Goal-scoped risk premerge. The13 TS tests/typecheck and source-bound build/packaged desktop/mobile failure/recovery were executed at 0c520666a9adf701a338cc29fc74fe62d533bccf; their owning source is byte-identical after the freshness repair, and current-head bundle verification passed again. Prior104 delegation/driver,51 source-census/entrypoint and6 quota regressions remain earlier evidence on unchanged rule source.
  • Run state: finished. Inputs: synthetic and public fixtures. Resolved existing managed policy is wait_for_ci=false: hosted CI is not fetched, polled or awaited, and no hosted success is claimed. Local validation, quality receipt and exact-head review/thread/readiness checks remain required.
Check kind Result Evidence / limitation
unit / integration passed 334 focused Python checks of final source, including28 freshness cases; canonical File/SQLite source, real Chat controller with synthetic model transport, notification effects and negative cases.
static passed Control-plane TypeScript check, thirteen TS projection regressions, Ruff, diff and public-boundary scans; semantic census has 273 classified sites and maintained twins remain 43/43.
real_entrypoint passed Production CLI→scoped app-server protocol→synthetic IM send/readback lifecycle, including source change and duplicate suppression.
real_backend passed One disposable synthetic Goal through Codex CLI 0.159.2 and the configured steward model; retained separate decision references/scope and a useful recommendation. This does not qualify sustained model quality.
real_entrypoint passed Source-bound packaged Chat build and desktop/mobile settings scenario: failed configuration write, reload, keyboard disable and unverified-delivery display. API fixtures are synthetic; provider/read-model behavior is separately covered above.
static / integration passed Goal-scoped risk-based loopx canary premerge --goal-id GOAL --from-git-diff on the final head: nineteen selected checks, zero failures, including typed semantics/budgets, human-gate CLI lifecycle, recovery, output budget and public boundary.

Earlier premerge exposed old fixed-template assertions; the durable smoke now verifies facts, references and receipts with synthetic model/IM transports. Live Lark delivery, installed deployment, active-Goal mutation and PostgreSQL routing are not claimed. No authority-store/provider routing was changed.

Frontend / Visual Evidence

  • UI impact: changed.
  • Before / after: synthetic packaged screenshots, showing desktop configuration and mobile readback at both base and head.
  • States/viewports: desktop configuration and pending delivery; mobile enable/reload/disable and receipt readback; failed configuration write is exercised by the browser scenario.
  • Source data: synthetic.
  • Attention review: reuse the existing controls and navigation, explain what the model does next to the switch, and preserve uncertain delivery as an explicit state. No duplicate controls or reassuring sent count derived from prepared receipts.

Type Of Change / LoopX Area

Feature, focused refactor, documentation and tests. Existing manager-context capability, control-plane presentation and Lark operator surface. Direction: roadmap R3/presentation Stage 2; the parent acceptance remains open.

Shared-authority RFC fixture impact: N/A; no provider promotion, routing or authority-store refactor.

Boundary Checklist

  • Public-safe diff/body; private material, credentials, live screenshots and raw model evidence excluded.
  • Scope follows the accepted request; existing R3 successor retained.
  • Every commit includes DCO sign-off.
  • Before/after visual evidence attached before handoff.

The maintainer explicitly authorized self-repair and self-merge for this PR. Exact-head review/readback, finding reconciliation, strict final-scope quality verification and capability-owned merge readiness remain required; the existing no-CI-wait policy requires the separately authorized admin bypass. No merge is claimed before those gates pass.

@huangruiteng

Copy link
Copy Markdown
Collaborator Author

Packaged frontend evidence with synthetic data. Before: base 2fca4a97f. After: frontend sources unchanged at final head 4875f2dbd.

The existing Goal notification controls now explain steward synthesis and model use. Unverified receipt state remains visible beside the controls. The packaged interaction also exercises a failed configuration write, successful readback/reload and keyboard disable without changing the independent human-gate setting. Provider/runtime validation is separate from these browser API fixtures.

Before — desktop

Before desktop

After — desktop, generation/delivery remains unverified

After desktop

Before — mobile readback

Before mobile

After — mobile readback and keyboard disable

After mobile

@huangruiteng
huangruiteng marked this pull request as ready for review October 2, 2026 16:40

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent · GPT-6 · OpenAI

Request changes conclusion (author-owned PR; GitHub blocks formal self-review)

Reviewed head: 4875f2d

动机

用户看到任务受阻或需要自己决定时,想知道原因、对目标的影响,以及等待期间还可以做什么。原来的群消息套用固定模板;没有群连接时,本地管家的简要上下文也缺少这组当前事实。这个 PR 让已有管家/Goal 对话读到同一组阻塞与决策,再让已获准的群通知使用配置的模型生成解释。

例如发布仍等用户决定、独立验证可以继续:现在应把同一任务的阻塞和决策合成一个对象,保留决策编号与条款,并解释安全续接,而不是发两条机械清单。我验证了无需 Channel 和历史运行记录的本地读取,以及生成失败、重试和群通知的隔离链路。但“保留精确决策编号”还存在下述可复现缺陷。

这次范围是已有 Turn 的事实输入和已有群发送器的表达;不是主动唤醒、本地已读回执、全会话连续性或持续模型质量验收。依据合并前的 docs/architecture/rfcs/goal-channel-collaboration-v0.md,spec_revision 2fca4a9,并参考同一 revision 的 presentation Stage 2 与 roadmap R3。补丁新增的 checkpoint 不能自行证明这些后续验收已完成。

改动思路

TS presentation owner 合成注意对象并披露省略数量;Python 从 canonical Todo 读取完整字段、执行公开安全过滤。Manager 与 Goal Turn 消费相同事实,外部受众仍限定在原授权 Goal。群发送器继续拥有资格、冷却、私有 binding、发送与回读,模型只产生文字,不修改 Todo 或扩大批准范围。

外发通过已有 Chat runtime 和配置的管家模型,在独立 restricted transcript 中生成;前后复核源内容和受众。正文先保存到原 effect receipt,再发送;失败重试沿用正文与 provider key。已核验 gate 消息记录覆盖的 blocker revision,单独的 blocker 发送器据此避免重复消息。模型失败保留待处理,不偷偷回退模板。这个分界比新增通知 inbox、scheduler 或第二个状态 owner 更合适。

具体改动

41 个文件增加 1309 行、删除 237 行。运行时包括 manager-context 的 canonical 读取/生成适配器,TS goal_attention 投影及 effect dispatch,Turn/portfolio/inspection 接入,原 blocked-transition builder 和 Lark sender/receipt/status 适配;删除两个模板与重复 blocker 收集规则。前端五个文件增加模型用途、未核验投递计数和现有开关文案,未增加设置流程;四组中英 RFC 更新交付边界;CLI、协议、File/SQLite、TS 和浏览器回归覆盖这些调用者。registry I/O manifest 只更新对应调用行号。

验收映射:Human Gate Notification 部分未满足,完整请求的精确引用可被子串校验放过,需要修复;Idempotency And Cooldown 已实现,保存正文、相同 key 重试和同 blocker 覆盖有实际路径证据;Security And Privacy 的授权隔离、源变化拒绝和私有回执边界已验证;Non-Goals 继续保留,群文字和模型建议不提交 canonical 转移。Stage 2/R3 的主动呈现、已读/恢复确认和持续质量仍 deferred,归现有 presentation/manager 交付边界。

关键代码讲解

  • goal_attention.ts::projectGoalAttention/boundGoalAttention 按 Todo 合并 blocker 与请求,优先需要用户行动的对象,单 Goal 和整个 Turn 分别限制数量并保留 known/included/omitted;没有把读取当成投递回执。
  • goal_attention.py::read_goal_attention 走既有 list_goal_todos canonical 读取;manager_turn_context 将事实送到已有对话。File/SQLite 实测无 Channel 时 known=2,恢复一个 blocker 后 known=1,新建用户请求后重新纳入,读取不修改源。
  • goal_notice.py::synthesize_goal_notice/current_notice_revision 使用 restricted Chat Turn,并在生成前后核对 canonical 内容和受众;validated_notice 负责长度、公开安全和请求引用,目前最后一项存在下面的缺陷。
  • goal_channel_runtime.py::notify_lark_goal_channel_gate 与 goal_channel_blocked_notice.py::deliver_blocked_notices 共用生成适配器,保留原发送/回读 owner;正文先落盘,生成失败不发消息,历史无正文的不确定 blocker 尝试要求先核对。
  • goal_channel_notification.py::_goal_notification_row 向现有设置提供未核验计数。打包桌面/窄屏实测显示模型用途、失败反馈与恢复步骤,关闭 blocked 开关没有改动独立 human-gate 设置。

对主干的风险

[P2] 必须按完整 token 校验决策引用,不能只检查子串。 validated_notice 的第 42–45 行 使用 request_id in text。模型若输出 todo_abcdef0123456789abcdef01_other,而完整请求编号是 todo_abcdef0123456789abcdef01,检查仍通过;用户看见、复制和回复的是另一个编号,无法可靠对应原决策。

我用同一个公开合成请求,分别让模型 transport 返回正确编号和带 _other 后缀的编号,经生产 notify_lark_goal_channel_gate 调用链执行。两次都调用了发送器,并返回 sent_verified;后者应拒绝发送。IM transport 使用隔离 double,缺陷位于真实正文校验与发送准入之间,不依赖在线模型或真实群。原固定模板直接写入 source request ID,不会产生这种新增错误引用。

最小修复:复用/定义明确的请求引用 token 边界,或让模型返回可核验的结构化引用再由 owner 格式化;不要用另一个模糊子串规则代替。正确引用应允许括号、标点、Markdown;前后追加标识字符、嵌入另一个 ID、缺少某个完整请求时必须阻止发送。把正反用例加到 tests/extensions/test_lark_steward_goal_notice.py,经两个 sender 验证无发送,再执行 uv run --extra test python -m pytest -q tests/extensions/test_lark_steward_goal_notice.py tests/control_plane/test_steward_goal_notice_integration.py。

其余高风险路径已有证据:194 项相关 Python 回归、11 项 TS 投影回归与 TS typecheck 通过;实际 CLI→Chat app-server 协议→合成 IM 发送/回读 smoke 通过;相同 base/head 的无 Channel File/SQLite 读取和打包开关失败/reload/键盘恢复对照通过。前端 API fixture 不证明真实群部署,因此另配实际存储、发送器和协议证据。没有付费模型重跑、真实 Lark、安装升级、active Goal 迁移或 CI 观察;这些不冒充已通过。

语义与 CI 对齐

复用既有 Todo status/task_class、decision-notice 和 blocker revision/receipt owner,没有创建第二个生命周期。blocked 通知继续 default-off;关闭或 preview 不生成/发送。新 Channel 的 human-gate 默认开启已存在于不可变 base 的 setup,本次是纠正文档,不是新默认切换。已有 enabled sender 现在使用模型与预算,skill/界面/RFC 明确披露。模型措辞是表达建议;源校验、授权和回读是机器义务,精确引用义务不能由“模型通常会保留”替代。

我的整体评价

REQUEST_CHANGES,先修复上述引用校验,再按新 head 复审。设计总体是合理的有界增量:复用 typed owner、canonical 读取和现有投递回执,删除重复模板与收集规则。本地事实输入改善了后续读取与恢复,长期路径在这部分得到改善;外部用户旅程因错误编号仍有已验证退化,不能用其他绿色回归消除它。

相关重构已应用于共享字段过滤、blocker 收集和 TS 注意投影,未见需要扩大为另一套通知框架。后续主动唤醒、跨 Goal 汇总和持续表达质量继续由 Stage 2/R3 承接;本 PR 不应宣称完成这些验收。已验证的发送重试边界保持正文/key 一致,合并前仍需新 head 的精确引用正反回归及完整计划检查。维护者负责合并。

English verdict: REQUEST_CHANGES - 4875f2d. P2: substring matching accepts a different decision ID and sends it as verified. Fix exact-token reference validation and exercise both senders. 194 Python tests, 11 TS tests, typecheck, isolated CLI/protocol delivery and paired packaged/authority journeys passed; no live Lark, paid-model rerun or CI observation.

Comment thread loopx/capabilities/manager_context/goal_notice.py Outdated
@huangruiteng
huangruiteng force-pushed the codex/steward-local-notices branch 4 times, most recently from 4534526 to f27035d Compare October 2, 2026 18:56

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent · GPT-6 · OpenAI

Request changes conclusion (author-owned PR; GitHub blocks formal self-review)

Exact head: f27035d85011a296023c1bda8cf52fdabfb0710a,base f6e04098529c2352b3cba9661669152be9f2a822。完整评审覆盖 43 个文件、1446 行新增与 240 行删除;未继承此前的评审结论。

阻塞发现:P2,生成期间无关 Todo 更新或新增会拒绝仍然有效的通知。最小修复是收窄 freshness witness 到选中事实与相关权限;完整证据见风险部分。

动机

需要让 Goal 的既有规范决策进入本地 Steward 上下文,并在已授权外部频道中生成有理由、影响和下一步的通知。仅替换模板并不能解决“没有频道或聊天历史时 Steward 看不到决策”的问题;该 PR 同时补齐 canonical attention、共享表达及真实投递链路,有明确产品价值。

规范依据为 docs/architecture/rfcs/goal-channel-collaboration-v0.md,固定在 f6e04098529c2352b3cba9661669152be9f2a822。逐项判断:Goals 中单 Goal 绑定、canonical 唯一 writer 与外部投递可读回边界保留;Human Gate Notification 已接入既有 quota 决策,但无关变化会使已选中请求无法送达,该项尚未满足;Security And Privacy 的群成员不取得 LoopX 写权限、撤销受众后禁止发送已验证;Idempotency And Cooldown 的语义动作 key 和既有收据重放保留;生成期间的有效性检查错误捕获无关工作,是上述通知可达性缺口。当前改动不能关闭持续表达质量或安装态长期运行的 roadmap 验收。

改动思路

read_goal_attention 从完整 canonical Todo 读取后交给 TypeScript projectGoalAttention/boundGoalAttention,按请求与阻塞合并并保留 known/included/omitted。Manager/Goal Turn 使用同一有界投影,本地 intake 默认开启,不依赖 Goal Channel;外部 Lark 投递仍由原绑定、受众、执行、cooldown 和读回 owner 控制。

render_channel_notice 经真实 ChatRuntimeController 调用配置的 Steward endpoint,使用独立表达 audience/session,限制能力并验证公共安全正文及完整决策编号。合成成功后把正文保存到原 provider idempotency key 下,重试复用正文;模型失败保持 pending,不偷偷退回模板。放大 timeout 或让模型决定投递权限都不是更小且正确的修复。现有 Python 负责 canonical/Host/provider 适配,attention 排序和 reference token 规则复用 TypeScript owner,没有新增通用能力或第二套 Todo writer。

具体改动

  • goal_attention.py 与 goal_attention.ts:完整来源、owner decision 优先、每 Goal 与整 Turn 有界;goal_portfolio、Manager context、inspection 和 context version 19 接入并刷新既有上下文。
  • goal_notice.py、Lark notice adapter 与两个 sender:生成前后检查选中请求/阻塞及受众,保存 delivery_text,旧已验证收据维持 quiet,旧歧义发送保持 reconciliation;独立 blocker sender 也保留决策编号。
  • validateDecisionNoticeReferences:原先 substring 漏洞已修复,ASCII 字母、数字、下划线和连字符延长编号,标点/Markdown 保留合法边界;新正文和 cached retry 共用这一规则。
  • 共享 blocked-transition collector 移至既有 quota owner,保留 canonical 优先和 recovery,不把未评估 fallback 伪造为不可用。manifest 更新引用;五个前端文件显示模型用途、pending/failed 和恢复提示,复用原开关;八份双语 RFC/roadmap 文档及 focused tests/smokes 更新行为与尚未关闭的验收。

对主干的风险

[P2] 无关任务变化会拒绝一条仍然有效的通知。 current_notice_revision 在 goal_notice.py:86-87 对 source["todos"] 全集做 hash,synthesize_goal_notice 在 132-133 行比较前后 hash。生成期间只更新同 Goal 另一条独立任务的 note,或新增独立任务,选中 gate 的 text/reason/evidence/status 与受众均未变化,也会得到 blocked / steward_notice_unavailable、0 次发送。繁忙的多执行 Goal 可能反复付模型成本却一直无法通知 owner。全 Goal 变化不等于这次消息过期。

我在当前 head 经生产 notify_lark_goal_channel_gate → render_channel_notice → synthesize_goal_notice → ChatRuntimeController、真实 File/SQLite authority 与公开 Todo CLI 复现。仅替换模型/IM transport;安静对照均 sent_verified、发送 1 次,无关注释更新和新增独立任务均拒绝且 0 次发送,选中事实变化及受众撤销的负例仍正确拒绝。建议只对本通知选中事实、blocker revision、相关继续工作依据和受众权限建立 freshness witness,保留 canonical 完整读及撤销检查;把无关更新/新增的正例和相关事实/权限变化的负例加入两个 sender 的回归矩阵。

新 head 246 项 Python、13 项 TS、typecheck、配置的 19 文件 mypy、Ruff 和 semantic drift 验证通过;真实 Manager/Goal Turn 的 base/head File/SQLite 对照验证无频道/无历史 intake、canonical 不写入、恢复与未来 owner request。CLI 合成/投递/读回协议 smoke 通过。设置页已有 fresh packaged 桌面/移动端失败、enable、reload、键盘 disable 和状态读回证据,源自 d037cde7a89061c11dd05c2608a20f0b4ff43198;本次 rebase 后 43 个 PR 文件内容与前端依赖未变,复用它时核对了这一边界。合成 API UI 证据不替代真实 canonical authority 证明,也不声称线上 Lark、付费模型或安装态长期表现通过。

本地 intake 的默认变化及外部模型调用成本/超时已有双语披露;human-gate setup 默认值的文档纠正与 base 实际代码相符,blocker 自动发送仍默认关闭。按配置未查询或等待 CI。新例外暴露的是更强前置条件误阻塞,现有绿测试不能消除它。

我的整体评价

REQUEST_CHANGES:旧编号缺陷已解决,但本次完整复审发现新的 scope overblocking。可用成果是共享 canonical intake、表达 owner 和完整编号验证;目前外部通知的持续可达性仍不满足普通并行 Goal 使用。最小修复应收窄现有 freshness witness,而不是删除权限检查、加重试框架或增加模板 fallback。

体量主要来自已有工作路径的测试与双语文档,active callers 齐全;复用 collector/reference owner 的相邻重构有实际价值,未要求额外 TS 迁移。保留旧收据有真实持久化重放依据。修复并验证上述反例后,仍需以最新 head 重新完成全 PR 判断;本评审不授权合并。

English verdict: REQUEST_CHANGES - f27035d; P2 whole-Goal freshness hashing rejects valid notices when unrelated Todos change or appear, reproduced through real File/SQLite production sender paths. Previous whole-token reference defect is fixed; 246 Python and 13 TypeScript checks pass but do not cover this regression.

Comment thread loopx/capabilities/manager_context/goal_notice.py
@huangruiteng
huangruiteng force-pushed the codex/steward-local-notices branch 2 times, most recently from 1433b58 to 3e86684 Compare October 2, 2026 19:45

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent · GPT-6 · OpenAI

Request changes conclusion (author-owned PR; GitHub blocks formal self-review)

Exact head: 3e86684d32dd6ad1429dc99f9db8bed625cc7f58;当前 main/base 8398bc45064c27fc898fa5604cddac983a9d5093。完整评审覆盖 45 个文件、1454 行新增和 240 行删除。结论仍为 REQUEST_CHANGES:同 Goal 无关任务的更新或新增,会阻止一条仍然有效的通知。本次未继承旧 verdict;生产链路在当前 head 重新执行。

动机

Goal 的既有决策需要进入本地 Steward 上下文,并在已授权频道中说明原因、影响和下一步。当前改动同时补齐无频道、无历史时的 canonical intake 和原有通知路径,有明确用途;但模板替换成功并不等于并行工作时仍能通知 owner。

规范依据为 docs/architecture/rfcs/goal-channel-collaboration-v0.md,固定在 f6e04098529c2352b3cba9661669152be9f2a822。逐项判断:Goals 的单 Goal 绑定、canonical 唯一 writer 与投递读回保持;Human Gate Notification 已接入原 quota 选择,却因无关工作变化失去通知可达性,尚未满足;Security And Privacy 的受众撤销、群成员不取得写权限与公共安全边界已验证;Idempotency And Cooldown 保留语义动作 key、旧收据与重试正文。PR 对默认 local intake、模型成本和超时的文档修改是新增行为披露,不反向改写这份验收依据。更广的持续表达质量、主动 idle wake 和安装态验收仍然开放。

改动思路

完整 canonical Todo 经过既有 TypeScript presentation owner 合并请求与 blocker、排序并限量,Manager/Goal Turn 使用同一投影。本地 intake 默认开启,独立于可选外部 Channel;发送仍需要原绑定、受众、执行、cooldown 和 readback owner 许可。

表达使用真实 ChatRuntimeController 和配置的 Steward endpoint,在独立 audience/session 中生成正文,禁止状态写入与 Host effects,验证公共安全和完整决策编号。正文在原 provider key 下保存,失败保持 pending,重试复用正文;不隐式退回模板。这个边界合理,Python 是 canonical/Host/provider 适配,排序及 reference token 规则属于现有 TS owner。更小的正确修复是收窄已有 freshness witness,而非放宽权限、延长 timeout 或新增调度框架。

具体改动

关键代码讲解

  • read_goal_attention:从完整 canonical 来源读取并明确 unavailable,供 portfolio、Manager context 和 inspection 消费;无频道、无 run history 的真实 File/SQLite 输入在当前 head 得到 attention,读取没有修改 canonical Todo。
  • projectGoalAttention:合并同一请求和 blocker,owner decision 优先;每 Goal 与整 Turn 的界限保留 known/included/omitted,不能把显示范围外的记录判为不存在。
  • current_notice_revision:先验证受众、选中请求的 text/reason/evidence 与 blocker revision,再在 86–87 行对所有 Goal Todo 做 hash。这最后一步给已选中通知加上了对无关工作的依赖。
  • synthesize_goal_notice:通过受限真实 Chat controller 生成/等待,再比较前后 revision;差异拒绝投递。现有两个 sender 保留 provider effect 与收据 authority,模型只表达既有事实。
  • validateDecisionNoticeReferences:共用完整 opaque ID 的 token 边界,拒绝前后缀扩展,允许标点和 Markdown;两个 sender 与 cached retry 使用同一规则,之前的 substring 缺陷已修复。

全 PR 还包括共享 quota blocker collector、context version 19 的既有上下文刷新、manifest 引用、五个设置/status 前端文件、八份双语 RFC/roadmap,以及 durable protocol/browser/receipt 测试。前端复用原开关与 navigation,显示模型用途、pending/failed 和恢复反馈。相比上一轮已发布的 f27035d85011a296023c1bda8cf52fdabfb0710a,五个测试 fixture 文件增加显式共享 fixture 注册(九行新增、一行删除),改善 mixed-root collection。本 head 还纳入已合并 #5489 的 architecture/telemetry 测试和 #5488 的 conversation-return UI/chat-store 更新。它们属于当前主干整合;我按新的 main/base 重读完整三点差异,没有将尚未整合主干时的两点差异误当成 PR 删除。通知 freshness 生产路径未改变。

对主干的风险

[P2] 无关任务变化会拒绝有效通知。 在生成期间,仅通过公开 Todo CLI 更新同 Goal 一条独立任务的 note,或新增独立任务,选中 gate 的完整记录与受众仍未变化。current_notice_revision 的全集 hash 改变,随后返回 blocked / steward_notice_unavailable,发送次数为零。繁忙的多执行 Goal 因而可能反复支付生成成本,却始终无法通知 owner。

我在 3e86684d32dd6ad1429dc99f9db8bed625cc7f58 重新执行生产 notify_lark_goal_channel_gate → render_channel_notice → synthesize_goal_notice → ChatRuntimeController,使用真实隔离 File/SQLite authority。只替换模型与 IM transport,不由 mock 提供 freshness 结论。两个 backend 的安静对照均发送一次并读回验证;无关 note 更新和新增任务均拒绝、发送零次、选中来源完全相同;选中事实修改和受众撤销的负例仍正确拒绝。共十个实际路径用例。应只 fingerprint 本通知选中事实、blocker revision 及相关继续工作/受众依据,同时保留完整 canonical 读取、生命周期与撤销检查;两个 sender 都应增加无关更新/新增的正例,以及相关事实/权限变化的负例。

当前 head 的 241 项 mixed-root Python、13 项 TS、typecheck、配置的 19 文件 mypy、14 个变更生产 Python 文件的 Ruff,以及重新执行的 semantic drift 和完整 risk premerge 均通过。Premerge 执行19 个选定检查、5 个直接检查,没有失败,包含真实 CLI 通知/读回、recovery、output budget 和公共边界验证。这些绿结果不能消除上述独立反例。当前 main/base 与 head 重新执行同一真实 canonical attention harness:base 无 intake,head 的 known 由 2→1 恢复→2 新请求;两边均只读,空外部 grant 不扩大 Goal 范围。

已在当前 head 新构建并验证 packaged Chat bundle,重新执行桌面/移动设置页的 failed write、enable、reload、键盘 disable 与 unverified receipt 场景,并检查整体 viewport。目标 Goal、模型用途与未确认投递状态可辨识;失败写入不打开开关,成功写入后 reload 保持,键盘关闭不改变独立 human-gate 设置。主干新的导航/chat-store 整合使旧 UI 证据需要重验,本轮没有把旧截图或测试重新标为当前执行。UI API 仍为 synthetic,canonical 和投递证明另行完成;不宣称 live Lark、付费模型或安装态长期运行由本次评审通过。

语义与 CI 对齐

复用既有 typed vocabulary 与 effect owner,没有新增并行 writer 或更广 actor authority。完整编号是机器强制的投递义务,表达建议仅为 advisory;本地默认 intake、外部模型成本与超时已双语披露。实际 base 的 human-gate setup 原本开启,blocker 仍默认关闭,文档纠正不是新的开启行为。按当前 managed policy 未查询、轮询或等待 CI。需修复的是选中动作与无关记录之间的错误依赖,不能用全 Goal 激活解释它。

我的整体评价

REQUEST_CHANGES。全 PR 的共享 intake、表达与既有 effect/receipt 整合是可用增量,fixture 修复及主干整合也有维护价值;但本 head 仍存在长期进展与用户通知可达性回归,尚不能批准。结果没有把新测试注册当作旧 P2 的修复,也没有继承旧 approval 轨迹。

相邻的有界整理已复用 blocker/reference owner;下一步应在当前 witness 边界去掉重复的全集知识,保留相关事实的严格检查。旧已尝试的 provider 收据需要兼容重放,不能删除来规避歧义发送;没有必要增加新协议或调度器。收窄 witness 并验证两方向用例后,再按最新 head 完整复审。持续模型质量与安装态采用保持原 roadmap 边界,本结论不授权合并。

English verdict: REQUEST_CHANGES - 3e86684; P2 whole-Goal freshness hashing still rejects valid selected notices after unrelated Todo updates or creation, reproduced on real File/SQLite production paths. This integrated head passes 241 Python cases, 13 TypeScript cases, the rebuilt packaged settings journey and all 19 selected premerge checks; those passes do not repair the notification regression.

Comment thread loopx/capabilities/manager_context/goal_notice.py
Signed-off-by: huangruiteng <huangrt01@163.com>
…ivery

Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
@huangruiteng
huangruiteng force-pushed the codex/steward-local-notices branch from 3e86684 to 0c52066 Compare October 2, 2026 20:05
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent · GPT-6 · OpenAI

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Reviewed head: 1d1dbcd

动机

用户在任务受阻或等待自己决定时,需要知道原因、影响和可以继续做什么。 例如发布等待决定、独立验证仍可继续:原群消息重复模板清单,本地管家在未连接群时缺少这组当前事实;现在同一任务的阻塞与决策合成一个对象,通知保留正确编号并解释下一步。

已验证本地管家与 Goal 对话无需 Channel 即可读取事实,原群发送器使用管家生成的解释,并避免同一阻塞重复发送;错误请求编号被拒绝。 本次不交付闲置时主动唤醒、跨 Goal 通知批处理、本地已读回执、全会话连续性或持续模型质量验收。 本地主动呈现、已读与恢复回执和持续质量仍待现有 presentation Stage 2/R3 验收。 这是一段有用且可独立回滚的增量,不宣称完整智能主动通知已完成。仅改文案无法让本地对话获得当前事实,也无法统一两条发送路径。

改动思路

事实继续来自 canonical Todo(目标的正式任务记录)与 quota;TypeScript 负责共用注意对象和完整决策引用,Python 适配已有存储、Chat runtime 与 Lark。管家只生成解释,发送资格、冷却、私有回执与读回仍归原 owner。没有新增通知 inbox、scheduler、能力开关或授权 store。

已准入通知在独立 restricted Chat Turn 中使用配置的管家模型,启动上限30秒、推理上限90秒,生成前后检查请求内容与受众。新鲜度见证只覆盖选中的请求/阻塞与引用的继续工作,复用 quota 的 compact facts;仍完整读取 canonical 并检查生命周期和受众,忽略无关任务变化。正文先保存到已有回执,重试复用正文和 provider key;已核验 gate 消息只覆盖同版本、同目的地的阻塞。源变化、模型失败和历史无正文的不确定尝试保留明确恢复条件,不自动生成另一段文字。

具体改动

全 PR 为45个文件、1579行增加、240行删除。生产路径包括共用注意投影、canonical 读取/生成适配器、Turn/inspection/portfolio 接入、CLI与 refresh 源参数、已有 Lark 两条发送器和投递状态;删除两套模板与重复收集/字段规则。前端五个文件沿用既有设置,说明模型用途、显示未核验消息,将原“已发送”计数改为“投递记录”。四组中英 RFC 更新当前交付边界;manifest 仅对应调用行号。测试覆盖实际存储、协议和打包交互,不把 transport double 当成在线服务。

独立规格:docs/architecture/rfcs/goal-channel-collaboration-v0.md,spec_revision 2fca4a9。读取合并前版本后再对照补丁,新增 checkpoint 不自行证明验收。逐项映射:Human Gate Notification 已实现当前 canonical 请求、完整编号和安全续接;原子串缺陷本次修复。Idempotency And Cooldown 已验证同正文/key 重试、原冷却和阻塞覆盖;Security And Privacy 已验证精确受众、源变化拒绝和公开安全;Non-Goals 保留,不新增 canonical 转移或远程 runner。既有 Stage 2 / R3 的主动呈现、已读/恢复和持续质量仍 deferred。

关键代码讲解

  • projectGoalAttention/boundGoalAttention 合并同一 Todo 的阻塞与决策,优先确需用户行动的事项。单 Goal 最多8项、整个 Turn 最多12项,known/included/omitted 保留覆盖缺口,不把读取当成通知。
  • validateDecisionNoticeReferences 在原 TS 决策通知 owner 中检查完整编号边界。字母、数字、下划线、连字符会延长编号;标点、中文括号、Markdown 可作边界。Python 旧子串规则删除,两条 sender、新生成与缓存重试共用这一义务。
  • synthesize_goal_notice/current_notice_revision 使用现有 configured steward 与 restricted runtime,前后复核 canonical 内容和受众;保留独立 transcript,不能借用 live owner 的宿主、委托或发布授权。
  • notify_lark_goal_channel_gate/deliver_blocked_notices 保留原准入/发送/回读,先落盘正文,再发消息;只凭核验过的同版本/同目的地覆盖抑制第二条。preview、disabled、suppressed 均在生成前返回。
  • _goal_notification_row 从现有回执派生 pending/failed 计数。打包设置可见模型用途与未核验状态;失败配置写不会启用,reload与键盘关闭可读回,两个开关互不改写。

对主干的风险

上一版 request_id in text 会接受错误后缀编号,用户复制回复后无法可靠对应请求。修复前同一批测试出现15个负例失败;修复后29个正反用例均通过两条生产 sender,另2个用例拒绝错误缓存正文,既不发送也不在已尝试 key 下重新生成。此前的可操作阻塞已映射到共享 owner 的修复与真实发送准入证据,讨论保留。

另一项 P2 是对整个 Goal Todo 集合做 hash,导致无关任务变化也拒绝有效通知。本次收窄至选中的请求/阻塞和引用的继续工作,独立任务更新/新增不再使其失效。复用 quota compact facts,忽略显示位置与更新时间;请求内容/生命周期、阻塞 task/revision、继续工作和受众仍严格核验。旧实现的8个无关变化用例失败,5个安静对照通过;修复后的28个用例跨两个生产 sender、真实 Chat controller及隔离 File/SQLite,验证可发送与必须拒绝两方向。

不可变主干 637675e 与本 head 使用相同 fixture 对照:disabled、external-suppressed、preview、blocked-default-off 的 model/send/receipt 都为0;正常准入仍仅1次发送/1个 verified receipt,重复调用静默,表达由模板变为1次管家生成。真实 File/SQLite 中,没有 Channel 时 manager与 Goal 的注意 known 从缺失变为2;canonical 恢复后为1,新请求后为2,读取前后源相等。没有把局部展示的缺项当成恢复。

334项通知/上下文组合、typecheck、19项风险 premerge在当前 head 通过。主干测试隔离与共享前端解码更新后,先在0c520666执行306项组合、13项 TS、typecheck及打包桌面/窄屏恢复;本次修复后执行最终源的完整334项组合、Ruff/mypy与新的绑定 Goal premerge。打包源码未改变,当前head再核验 bundle;没有将此前的重建、浏览器或TS执行写成新一轮执行。104项委派/driver、51项 source-census/入口与6项 quota 回归是此前未改变的规则源码上执行的证据,未冒充本 head 全量重跑。曾在完整410项中出现10个回执失败,其余400项通过;失败节点未加载共享模型替身。四个使用方显式注册同一 fixture 后,完整334项组合通过,未弱化生产规则或测试期望。实际 File/SQLite 和 sender 对照在当前 head 重跑。source-bound Chat 重建/核验与桌面/窄屏设置失败→恢复→reload→键盘关闭通过。前端 API和 model/IM transport 使用合成 fixtures,真实 canonical 存储与实际 Chat/CLI协议另行验证;未执行在线 Lark、安装升级或 active Goal迁移。此前一次真实合成模型调用只证明路径可用,不证明持续表达质量。

语义与 CI 对齐

复用既有 Todo、decision-notice、blocked-transition 与 receipt vocabulary;完整编号是机器投递义务,建议措辞仍为模型表达指导。新 Channel human gate 默认开启已存在于不可变 base,本次修正旧文档;blocked 仍 default-off。仅已启用的外发增加模型预算与延迟,设置和 RFC 披露,关停路径对照无额外效果。语义检查、273处 registry I/O census 和当前 typed 入口通过,未建立 Python 平行决策源。

项目既有配置解析为 wait_for_ci=false;已停止此前误用默认策略的轮询,本次不读取或等待 hosted CI,也不声明其通过。最终45文件 diff 的质量凭证已核验,绑定 Goal 的十九项 premerge通过;全部贡献提交含 DCO sign-off。用户明确授权本 PR 自修复自合并及相应 admin bypass,当前版本评审回读、线程收尾和 merge-readiness仍必须通过。

我的整体评价

APPROVE,对本 head 的 whole-PR 结论为 justified_increment。long_horizon 改善:当前事实随恢复/新请求更新,重复发送前去重,失败重试保持正文/key;user_experience 改善:原入口读到同一事实、现有开关说明代价和恢复、错误编号不再发送。没有用回执存在或测试数量替代用户结果。

保留历史私有回执是防止重复效果的兼容义务;co-deployed 请求解码没有新增版本分支。相关重构已落实在共用字段/阻塞收集和 TS 精确引用 owner,扩大为新通知框架没有必要。模型预算、历史不确定尝试核对及后续 Stage 2/R3 验收仍是明确限制。当前用户明确授权 #5480 自修复自合并;只有 exact-head 评审回读、讨论收尾及 merge-readiness 为 ready 后才执行,admin bypass 不替代这些证据。

English verdict: APPROVE - 1d1dbcd. Exact-token validation repairs wrong-ID delivery across both senders/cache; selected-fact freshness repairs independent-work starvation with28 actual sender/Chat/File/SQLite cases and relevant-change negatives. Shared canonical intake, restricted synthesis, stable replay, disabled-path parity and packaged recovery are qualified; 334 Python tests of final source and all19 Goal-scoped premerge checks passed;13 TS tests/typecheck and packaged recovery evidence are retained on unchanged owning source, with current bundle verification. Proactive idle wake, sustained quality, online Lark and installed deployment remain outside this slice.

@huangruiteng
huangruiteng merged commit 917d89b into main Oct 2, 2026
10 checks passed
@huangruiteng
huangruiteng deleted the codex/steward-local-notices branch October 2, 2026 20:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant