Skip to content

feat(execution): separate work declarations, refinement bounds and session policy - #81

Merged
wefio merged 3 commits into
mainfrom
feat/opaque-work-declarations
Oct 2, 2026
Merged

wefio merged 3 commits into
mainfrom
feat/opaque-work-declarations

Conversation

@wefio

@wefio wefio commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

变更描述

What(改了什么):共享派发携带不透明、带 digest 的声明;refinement 执行协议显式声明的资源约束;通用会话契约不再要求补丁解释。包含 ab8e0f76 与 803d7d98 两个独立提交。

Why(为什么改 / 解决什么问题):词汇门禁只能暴露耦合,不能证明机制已经支持其他形态。本 PR 用非补丁数值声明、真实黑板租约/交付/独立裁决,以及显式资源约束和通用会话输入验证更窄的边界;不把受控证据等同于完整 peer 协议安装。

Changes(关键改动点,按文件或模块列出):

  • ooo-dispatch.ts 的共享端口只要求 WorkDeclaration.digest;票据必须声明 declaration(允许显式 null),原对象不变地交给 worker。采用方拥有冻结、解释和具名拒绝,拒绝在租约/worker 前发生。
  • 默认 board/runner 与评估 driver 特化补丁类型,保留已有补丁周期、取消、TTL 和独立 verdict 行为。
  • task-semantics.ts 的 refinement 要求显式 constraints(包括空列表),within-parent-writes 比较规范化 effects.proposeWrite;协议选择名字和启用,不从补丁字段取权限。漏掉父权限义务、不支持的原语、未知字段和重复名字按声明位置拒绝。
  • ooo-session-mechanism.ts 提供不要求补丁字段的 input/state/runner 和调用方 completion bounds;ooo-patch-session.ts 拥有默认渲染、工具/产物策略、最少一次快照读取。兼容导出引用同一实现,不复制函数。
  • 默认会话采用方仍在词汇扫描面内,移动不是文件豁免:当前 285 occurrences / 29 files / 0 errors,不声称零策略。补充模块与 refinement 测试的路由。
  • docs/experiments/execution/field-ownership-2026-10-01.{md,json} 与可复跑 evals/ooo-execution/field-ownership.ts 保留历史源哈希、五个编译模型、资源/effect/content/dependency/operation 的受控观测;原始报告未被后续 replay 覆盖。
  • 同步英中边界决策与拥有方设计;声明存储的 typed Task-Unit 表 / opaque payload / NULL board payload 冲突继续开放。

依赖 / 合并顺序:#80 当前仍 OPEN,head 为 256bcc0e66ebe8a946e300b8d465731caea02bf4;本 PR 的新工作只有它之后的 ab8e0f76 与 803d7d98。

仓库 CI 只响应目标为 main 的 PR,因此 #81 以 main 为 base;在 #80 合并前,完整 diff 暂时包含它的父提交。后续切片的独立审查范围是 256bcc0e…803d7d98。先单独审查并合并 #80,再重新确认本 PR 的 diff、base 与检查;不要把本 PR 合回 #80 分支而改变其已审查 head。此提交不授权合并任何 PR。

本地实测

  • 两个切片分别经 scoped Agent verification;最终 16 项 blocking checks 通过,产品测试 1610/1610。150000ms 总期限不变。
  • 当前提交后的 npm run verify:static 通过。
  • 权限/会话/driver/patch-cycle 定向 89/89;路由 22/22;11 个本次改动 TypeScript 文件 LSP 0 diagnostics。第一切片另有 47 个定向用例与 16 文件 LSP 检查,二者不是合并计数。
  • 最终全量变异 110/110 caught,22/22 byte-identically restored;the-pass-asks-a-unit-it-already-failed-again 是现有 30s cap 捕获,不是断言捕获。无残留 mutation lock。
  • 保存早期失败记录:修复本次空接口 lint 和漏模块路由;两个完整运行分别遇到 reasoning-workspace / stg-isolated 的 Windows 清理目录 EPERM。对应聚焦重试为 5/5、10/10,后续两个完整产品运行均 1610/1610;不推断成功重试解释了失败原因。此前因失败产品 receipt 产生的 RTM 失败记录也保留。

未验证项

Not verified(没验证什么):

  • 没有 live LLM/embedding 或官方完整基准消费;本地研究/chaos advisory 未运行。
  • 本地为 Windows / Node v24.19.0;其他平台、Node 22、clean-checkout 覆盖率由待观察的 forge CI 单独判断,不能用本地结果替代。
  • 数值 session 用例是受控契约/完成条件验证,不是生产 harness 的 peer 协议安装,也不证明所有 lifecycle 策略已经无耦合。
  • 未实现四角色协议接口、payload/selectors/projections/version/quarantine/threat model、重启 run facts 的第二协议覆盖,或任何 schema 迁移。frame/storage 仍 proposed,未获得独立迁移批准。
  • 当前 effect class 门禁不等于资源写集互斥;字段实验不决定通用输入/依赖粒度或 operation 的存储归属。
  • 两次本地 Windows EPERM 根因仍未确定;失败记录保留,未修改清理逻辑、断言、并发或期限。
  • CI 尚待完成。绿色检查不是合并授权。

完成检查项

本地质量检查

  • npm run verify:static 通过。
  • 按改动路由跑 npm run agent:verify -- <路径>,16 blocking checks / 1610 product cases 通过。
  • 依赖/lockfile 未改;check:lock 通过。Dependency audit 由 CI 独立检查。
  • 子包未改;verify:packages 仍按共享静态契约通过。
  • docs:check:308 files,0 errors / 0 warnings;英中决策与拥有方设计同步。
  • ## 未验证项 已填写;非平凡改动携带决策记录。
  • complexity:gate 通过,阈值 15 未改。
  • 未提交可再生产物。

RCP(Repository Control Plane)

  • 首个实质写入前登记 repo-development entries 1790861187483_000179 / 1790908829584_000180;后者已 resolve,前者待 PR 交付完成。
  • 改动路由 reconcile 已通过;.nmg/verification/latest.json 保存最终 scoped blocking 证据。提交仅改变 HEAD,不改变被验证内容;原始失败 receipt 另存。
  • 通过 node bin/nmg-rcp.mjs forge-status --pr <编号> 确认所需检查成功。
  • 仅提交本 PR 拥有的路径;无关 ooo-ordinary-handoff.test.ts 工作树标记保留,未暂存/清理。

CI 完成确认

  • RCP 观察的 All checks passed 为 SUCCESS。
  • CodeFactor 通过。
  • Static job(含 dependency audit)通过。

wefio added 3 commits October 1, 2026 20:45
…urface

Implement the explicitly approved mechanism-not-policy classification/check
slice. Keep a maintained vocabulary and exact counts keyed by path, named
scope and word; classify all 307 occurrences in 123 records across 28 files.
Scan identifiers and runtime/SQL literals, ignore TypeScript comments, and
refuse new, changed or stale sites without a reviewed table update.

Wire check:policy-words into the shared blocking static contract and its
agent plan, with a guard against duplicate/missing execution. Move the paired
record to implemented with explicit approval, update inbound links, and
retain the work-shape rewrite, field experiments and frame/storage migration
as deferred/unapproved scope rather than claiming separation.

Validation: targeted tests 16/16; keyless product tests 1594/1594; scoped
agent:verify passed all 16 blocking checks under the existing 150s cap.
The initial full run hit that cap and remains recorded as incomplete.
Full mutation sweep caught 110/110 and restored 22/22 byte-identically;
one repeated-dispatch mutant was caught by its 30s cap, not an assertion.
Require a digest-bearing declaration carrier, preserve adopter specialization,
and pass the frozen declaration unchanged instead of reconstructing patch work.
Move preparation to the default adopters and distinguish named claim refusals
from failed units. Keep the patch driver's worker specialized at its boundary.

Add non-patch numeric fixtures, including real store lease/delivery/independent
verdict coverage, and a compile-time guard against the optional-carrier hole.
Retire eight policy-word groups whose twenty occurrences were removed; keep
all remaining classifications and the blocking ratchet intact.

Record reproducible field probes and correct effect-class/write-set confusion.
Keep permission/session separation, storage ownership and the independent
frame proposal explicitly open; no protocol framework or schema migration.

Validation: 16 blocking Agent checks at the unchanged 150s deadline; 1598
product tests; 47 targeted cases; 110/110 mutation teeth caught and 22/22
byte-identical restorations. One catch remains the existing 30s execution cap.
Scoped LSP: zero diagnostics across 16 changed TypeScript files.
Enforce explicitly named refinement constraints against normalized resource
identities instead of consulting a parent patch envelope. Preserve parent
permission obligations and refuse malformed or unsupported declarations.

Separate generic session input/state/runner contracts and caller-declared
completion bounds from default patch rendering and artifact interpretation.
Keep compatibility exports as references to the same implementation. Register
the adopter's route and retain its policy-word classifications in the scan.

Update bilingual ownership decisions and add controlled numeric, malformed
constraint, generic-session and forwarded-export coverage. Storage ownership
and the independent frame proposal remain open; no schema or live-provider
changes are included.

Verification: 89 targeted cases, 1610 product cases, 16 scoped blocking checks,
zero diagnostics on 11 touched TypeScript files; 110 mutation teeth caught
and 22 targets restored byte-identically. One tooth was caught by its existing
30-second cap. Preserve earlier failed verification receipts and two observed
Windows cleanup EPERMs; successful focused/full retries do not explain them.
@wefio
wefio changed the base branch from feat/mechanism-not-policy-boundary to main October 2, 2026 07:12
@wefio wefio closed this Oct 2, 2026
@wefio wefio reopened this Oct 2, 2026
@wefio
wefio marked this pull request as ready for review October 2, 2026 07:25
@wefio
wefio merged commit 2850ff9 into main Oct 2, 2026
7 checks passed
@wefio
wefio deleted the feat/opaque-work-declarations branch October 2, 2026 07:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant