Skip to content

fix(quota): settle registered causal waits without spending - #5230

Merged
huangruiteng merged 1 commit into
mainfrom
codex/causal-blocked-closeout-20260928
Sep 28, 2026
Merged

huangruiteng merged 1 commit into
mainfrom
codex/causal-blocked-closeout-20260928

Conversation

@huangruiteng

@huangruiteng huangruiteng commented Sep 27, 2026 •

Copy link
Copy Markdown
Collaborator

Goal And Delivered Outcome

  • Outcome basis: a reproduced quota settlement defect, not a new maturity/promotion claim.
  • Goal/source and gap: managed advancement work can register a legitimate monitor_changed or todo_done dependency, but blocked no-spend settlement required a 1–30-minute timer. The old Turn could strand independent work.
  • Before → after: the identical real CLI harness on base d0bc16a2fa75e85aa7052d8cb30f715080175328 fails for both File and SQLite at the timer-only closeout check. This head closes the exact blocked Turn without spending, preserves the open Todo and validator, and admits independent work on the next Turn.
  • Intended base: main.

中文:已登记的因果等待不应被迫改成短定时器才能结算。本修复让旧 Turn 无扣额关闭,原 Todo 继续等真实依赖;不把等待视作交付、完成或交易许可。

Scope And Continuation

  • Complete within the code-fix scope: TS quota owner qualifies a frozen causal proof by reusing the existing Todo resume evaluator. Python transports canonical facts; no second decision owner.
  • Exact Goal/Agent/Todo/Turn guards and durable receipt checks remain. Reject missing/duplicate/archived targets, ready/completed waits, monitor generation advance/regression/missing facts and stale projections. Historical replay uses frozen facts; an existing debit is never erased.
  • Retain legacy bounded and Turn-owned retries. No provider routing, writer authority, scheduling deadline or completion-validator change.
  • Remaining work: maintainer review/merge and deployment, then actual managed-consumer adoption. Test acceptance is not live adoption. Old runtimes cannot interpret new causal receipts; reconcile with a compatible runtime before rollback.
  • Excluded: local experiment artifacts, private Goal state, runtime logs, configuration, baseline checkout and personal data.

Validation

  • Tested revision: ac46be75db82aa7d641cc796d55cba87dea91cc3 (final source identical to the local validation head).
  • Run state: finished for checks listed as passed.
  • Input classes: synthetic.
Check kind Result Public-safe evidence / limitation
real_entrypoint / real_backend passed uv run python -m pytest tests/control_plane/test_causal_blocked_closeout_cli.py -q: 4 cases, File + SQLite × monitor_changed + todo_done, production CLI parser/dispatch and real TS/provider processes; 12.68 s, unchanged 20-second validator.
regression_parity passed Identical harness hash on immutable base versus head: baseline File and SQLite monitor waits fail at timer-only closeout; head passes.
unit passed New causal proof, settlement readback, vision checkpoint, quota Turn contract and Turn settlement TS suites: 115 pass, no skips. Wrong identities/missing receipts remain fail-closed; historical debit preserved.
integration passed Legacy retry/vision/owed-signal/blocked settlement subset: 26 pass, 73 intentionally deselected. Chat Todo/context: 28 pass.
static passed Control-plane TypeScript typecheck, scoped Ruff, mypy (19 modules), diff hygiene and public-boundary scan.
integration passed Exact-head risk-selected premerge gate: 5 catalog canaries, 8 risk-profile smokes and public-boundary check pass, with no failures or skips. It does not grant merge authority.
real_backend not_run PostgreSQL qualification and live managed research adoption are outside this bounded settlement fix.

Coverage: both causal kinds and both local authority providers; exact refresh replay, zero debits, original-validator preservation, independent next-Turn selection, pending/generation/receipt negatives and legacy retry parity. No production financial effects exercised.

Frontend / Visual Evidence

  • UI impact: none.
  • Before/After/States/viewports: N/A; no visual change.
  • Source data: none.
  • Existing dashboard reads canonical resume_when, resume_ready and resume receipts; Chat/Lark updates use the same Todo owner. Those projections and configuration do not change. Existing Chat/context tests pass. No separate UI/chat authority, new setting or frontend control is needed.

Type of Change

  • Bug fix
  • Documentation update
  • Test update

LoopX Area

  • Control plane (goals, todos, quota, scheduler, registry, runtime)

Technical Direction

Core control-plane hardening, following the existing TS single-owner direction. This is not a migration/promotion milestone.

Shared-authority RFC fixture impact

  • Production-scale fixture schema: unchanged; synthetic isolated settlement fixtures.
  • Semantic dimension: extend blocked no-spend proof, preserve exact identity/generation/idempotency/completion boundaries.
  • Provider arms: real File and SQLite; no storage/CAS changes.
  • Three-arm promotion rehearsal: N/A, no promotion/runtime routing/compatibility projection change claimed. PostgreSQL not qualified here.

Boundary Checklist

  • Diff/body/attachments exclude private state, credentials, raw traces, internal links and local machine paths.
  • No duplicated maintainer benchmark work.
  • Scoped to reproduced causal blocked-Turn defect.
  • UI impact marked none with existing-path rationale.
  • DCO trailer present; author and committer use verified GitHub noreply identity.

Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

结论:APPROVE,限本次因果等待结算修复。评审版本 ac46be75db82aa7d641cc796d55cba87dea91cc3;代码验收不等于部署或投研实际采用,Core 合并仍由 maintainer 决定。

动机

原有 Todo 能登记真实依赖,但 quota 的阻塞无扣额结算仅接受短定时器,两者不一致会让已经发现依赖的旧 Turn 卡住,持续挡住独立工作。相同实链路夹具在不可变主干基线的 File、SQLite 上都停在 timer-only 拒绝;修复版可关闭精确 Turn,并让下一轮选到独立任务。这个有界修复完成了代码侧目标,没有宣称整个长程研究目标已经闭环。

改动思路

最强的反对理由是:新回执格式增加兼容成本,且不能为了恢复进度降低验收。单纯接受一个因果字符串确实更少,但无法证明目标存在、仍待满足或代际未变;强制短定时器又改变了真实依赖。因此选择扩展既有 TS quota owner,复用 Todo resume evaluator,删除 Python 中平行的等待资格判断。既有 effect method 用显式 schema 区分纯预检和持久读回,没有新增调度器、配置源或 provider。

新增事实由普通 Todo 登记与 blocked refresh 路径自动产生,只冻结最小必要字段,不要求人手工同步第二份状态。当前等待资格按 canonical 事实重算;已经提交的历史 Turn 读回冻结事实,不因今天的依赖变化重新打开。等待与完成仍归原 Todo owner,结算与幂等归原 quota 回执链。

具体改动

关键代码讲解

  1. prepareBlockedWait 是新的纯 TS 预检入口。它要求同一未完成 advancement Todo;因果分支要求开放、active、pending 的 Agent Todo 和唯一已登记目标,并复用现有条件解析与 pending 判断。Monitor 当前 generation 必须显式、合法且等于登记基线;目标缺失、归档、完成、重复及陈旧投影均拒绝。旧有界 timer 和 Turn 自有五分钟重试仍有独立、明确的兼容分支。

  2. isCausalBlockedWait 核验历史 proof 的 schema、精确 Todo、等待字符串和严格观察时间,再重算冻结事实。settlement_phase 将它接到原共享谓词,因此 vision checkpoint 与 quota readback 不会各自发明因果判断。

  3. require_blocked_retry_wait 删除原 Python 预检规则,只传两类完整 Todo 事实给既有 TS 方法;错误仍进入原 refresh 拒绝路径。历史 Turn retry 的 selection overlay 没有改成新的 causal 调度规则。

  4. readQuotaSettlement 仅增加显式预检 schema 的分流。普通持久读回仍需同一 Goal、Agent、Todo、Turn 的 guard 和 writeback 回执;没有 spend 事实才可无扣额结算,已经发生的扣额不会被抹去。

其余改动是三组回归测试与中英协议:真实 File/SQLite 的两类依赖结算、精确刷新重放、零扣额、原验收器保留和下一轮独立工作;TS 反例覆盖身份错配、缺回执和代际问题。Dashboard 已消费 canonical 等待及回执,Chat/Lark 已走同一 Todo update owner;没有新增设置或投影,因而不需要新前端控件或第二套聊天状态。

对主干的风险

主要风险是虚构等待能误关 Turn,或者把真实扣额、Todo 完成及交付信用混为一谈。预检的已登记 pending 事实与读回的精确 durable receipt 共同防止这些问题;已有 debit 被保留。反向风险也测了:后来发生依赖变化不能重开历史 Turn;48 条未来监控不会因首屏截断而隐藏目标;原验收器、租约和独立工作树要求保持有效。单独的大量可执行承诺仍触发既有 long-chain 重规划,不因这个修复被豁免。

真实 CLI 四个 provider/kind 用例通过,完整关键 TS 组 115 项通过、无跳过;旧 retry/vision/owed-signal 子集 26 项、Chat/context 28 项通过。不可变基线与本 head 的旧短重试 CLI 组均通过。精确提交上的风险选取 premerge gate、TS typecheck、Ruff/mypy 和公共边界检查通过;按 Goal policy 不查询或等待 CI。没有把预期的旧版本失败、夹具误触既有门禁或未执行的 PostgreSQL 验收写成通过。

语义与 CI 对齐

本 PR 扩展既有 blocked closeout proof 词汇,不改变 Todo 条件含义或 actor 权限。新增 schema 在原 TS owner 内,Python 是适配层,符合仓库 TS-first 方向。既有 quota_blocked_retry_v0 是已持久化契约,不宜为减少分支而删除;新 causal proof 要用兼容运行时读回,降级前先完成或核对回执,不能删除 writer fence 或改历史。这不是 provider promotion 或 TS 全量迁移里程碑,PostgreSQL/live adoption 留作各自真实验收。

我的整体评价

long_horizon 与 user_experience 都是 improved:合法等待不再靠伪造短 timer 释放旧 Turn,重试幂等且后续独立工作能够继续。机制成本与实际 continuation 缺陷相称,复用了原条件 owner,也实际删除了重复决策;没有再引入 owner 同步负担。基础短重试和 peer hard-lease 路径有基线/head 对照,因果新路径有旧版本失败和修复版通过。剩余风险是部署版本兼容和真实采用,不能靠 PR、测试数量或本次结算回执替代;没有发现本有界改动的阻塞项。发布前远端 head 已核对为上述精确 SHA,合并权限与安装分开处理。

English verdict: APPROVE - ac46be7. Registered pending causal waits settle the exact blocked Turn without debit or Todo completion and release independent work. Real File/SQLite CLI, historical-defect counterfactual, legacy retry parity, 115 TS tests and exact-head native premerge checks pass. Deployment, PostgreSQL qualification and live adoption are not claimed.

@huangruiteng
huangruiteng merged commit c65b1c8 into main Sep 28, 2026
30 of 34 checks passed
@huangruiteng
huangruiteng deleted the codex/causal-blocked-closeout-20260928 branch September 28, 2026 03:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant