release: prepare v1.2.4 and reconcile migration examples - #5439
Conversation
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Reviewed exact head: 445208a32b4c81514e9e9c74e80fe55ffc61616f; base: 46a8c9b65ee8e2df5123a5762317e28b40d167fa.
动机
用户恢复 v1.2.4 发布。这个已有 PR 先准备可冻结的版本源码,并修复迁移命令缺失于帮助目录、公开示例仍硬编码旧状态目录这两个实际兼容问题。合并此 PR 不等于发布验证完成。
改动思路
沿用已有 package/runtime 版本镜像、COMMAND_GROUPS 与生成手册,以及 bootstrap 的 state_file 返回值。Python 留在既有打包、文件系统和示例适配层;没有新增控制面决策源、权限或迁移执行器。相关小重构已去掉 demo 重复的目录知识,没有新增 helper。
具体改动
loopx/__init__.py与pyproject.toml同步为 1.2.4,四份中英 Developer Book 当前锚点随版本更新。help_surface.COMMAND_GROUPS收录现有migrate-local-state --help;man/loopx.1由同一目录渲染,明确离线预览、停止 writer 与凭据绑定回退。CLI_OUTPUT_COMMAND_CLASSIFICATIONS按精确 command id 使用既有explicit_cold_path_exception。这条离线命令不进入自动轮询热路径,也不放宽任何输出预算。_seed_visible_demo_control_plane使用 bootstrap 返回的实际状态文件;现有 worker-loop smoke 按新安装.loopx路由检查。已有登记旧目录仍由原 bootstrap/路径 owner 决定,没有搬动数据。
对主干的风险
完整差异仅 11 个文件,24 行增加、11 行删除。最强反例是版本镜像不一致、示例误写另一状态路径,或帮助出现被误认为迁移授权。现有版本不匹配、迁移 plan/receipt/活跃 writer 拒绝用例均通过;命令可见性不触发执行。129 项聚焦测试通过,3 项既有平台用例跳过,未算通过。帮助/真实隔离安装手册、书籍、版本、发布物和 auto-research smokes 全部通过;Ruff 零问题,mypy 的配置范围 19 文件通过。前端发布构建校验通过且保留上一交付资源。初次并发依赖安装造成的文件读取冲突已顺序重跑通过,未修改断言。
同一 auto-research smoke 在不可变主干 46a8c9b 因旧 .codex 状态文件不存在而失败,在本 head 的 .loopx 路由通过。native premerge 全部 14 项选定检查通过,零未解决 hold;最终质量 receipt cqr_91a43704d0c39ce4b44c 对应该精确 scope。差异语义 advisory 与公开边界检查通过;没有私有状态、日志或凭据进入改动。未改 UI 首屏、Lark/CLI 配置入口、PostgreSQL authority 或用户安装路由,因此无新增 companion 页面或真实 PG 重构验证要求。
最终合入提交仍需执行 pytest、Ruff、mypy、风险 canary、完整 public fleet、安装/升级/host、公开边界及真实默认 Doubao 八组发布验证。此评审不把旧 head 的结果移作最终 release 证明,也不声明完整发布或模型通过。
我的整体评价
APPROVE:这是完整而可回退的发布准备阶段,修复两个已交付契约的消费者问题,复用现有 owner。按用户恢复发布的授权完成合入后,继续在最终提交上验证、发布 tag/包和更新入口。本 Goal 不查询或等待 PR CI;没有未解决源码 blocker。
English verdict: APPROVE - exact head 445208a. Eleven focused release-preparation paths reuse canonical version/help/classification/bootstrap owners. 129 tests pass, three platform skips are disclosed; manual installer, book, version, artifact and demo smokes, Ruff, mypy, frontend build, native premerge and exact-scope quality pass. No migration execution or authority change. Final release qualification remains required on the merged commit before publication.
Signed-off-by: huangruiteng <huangrt01@163.com>
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Reviewed exact head: 2cb9505dc9bfb39291054f5a746ef34c7e99a471; base: 83faf456fa7d5a91f30a2be3e51efa482302be48.
动机
用户恢复 v1.2.4 发布。这个已有 PR 先准备可冻结的版本源码,并修复迁移命令缺失于帮助目录、公开示例仍硬编码旧状态目录这两个实际兼容问题。合并此 PR 不等于发布验证完成。
改动思路
沿用已有 package/runtime 版本镜像、COMMAND_GROUPS 与生成手册,以及 bootstrap 的 state_file 返回值。Python 留在既有打包、文件系统和示例适配层;没有新增控制面决策源、权限或迁移执行器。相关小重构已去掉 demo 重复的目录知识,没有新增 helper。
具体改动
loopx/__init__.py与pyproject.toml同步为 1.2.4,四份中英 Developer Book 当前锚点随版本更新。help_surface.COMMAND_GROUPS收录现有migrate-local-state --help;man/loopx.1由同一目录渲染,明确离线预览、停止 writer 与凭据绑定回退。CLI_OUTPUT_COMMAND_CLASSIFICATIONS按精确 command id 使用既有explicit_cold_path_exception。这条离线命令不进入自动轮询热路径,也不放宽任何输出预算。_seed_visible_demo_control_plane使用 bootstrap 返回的实际状态文件;现有 worker-loop smoke 按新安装.loopx路由检查。已有登记旧目录仍由原 bootstrap/路径 owner 决定,没有搬动数据。
对主干的风险
完整差异仅 11 个文件,24 行增加、11 行删除。最强反例是版本镜像不一致、示例误写另一状态路径,或帮助出现被误认为迁移授权。现有版本不匹配、迁移 plan/receipt/活跃 writer 拒绝用例均通过;命令可见性不触发执行。129 项聚焦测试通过,3 项既有平台用例跳过,未算通过。同步新主干后,真实隔离安装手册及 48 项安装/doctor/host 用例再次通过;11 个最终差异 blob 与已测前一 head 相同,已核验依赖和边界失效范围。帮助/真实隔离安装手册、书籍、版本、发布物和 auto-research smokes 全部通过;Ruff 零问题,mypy 的配置范围 19 文件通过。前端发布构建校验通过且保留上一交付资源。初次并发依赖安装造成的文件读取冲突已顺序重跑通过,未修改断言。
native premerge 全部选定检查通过,零未解决 hold;最终质量 receipt cqr_d8dd14f2456dc97cb857 对应该精确 scope。差异语义 advisory 与公开边界检查通过;没有私有状态、日志或凭据进入改动。未改 UI 首屏、Lark/CLI 配置入口、PostgreSQL authority 或用户安装路由,因此无新增 companion 页面或真实 PG 重构验证要求。
最终合入提交仍需执行 pytest、Ruff、mypy、风险 canary、完整 public fleet、安装/升级/host、公开边界及真实默认 Doubao 八组发布验证。此评审不把旧 head 的结果移作最终 release 证明,也不声明完整发布或模型通过。
我的整体评价
APPROVE:这是完整而可回退的发布准备阶段,修复两个已交付契约的消费者问题,复用现有 owner。按用户恢复发布的授权完成合入后,继续在最终提交上验证、发布 tag/包和更新入口。本 Goal 不查询或等待 PR CI;没有未解决源码 blocker。
English verdict: APPROVE - exact head 2cb9505. Eleven focused release-preparation paths reuse canonical version/help/classification/bootstrap owners. 129 tests pass, three platform skips are disclosed; manual installer, book, version, artifact and demo smokes, Ruff, mypy, frontend build, native premerge and exact-scope quality pass. No migration execution or authority change. Final release qualification remains required on the merged commit before publication.
Signed-off-by: huangruiteng <huangrt01@163.com>
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Reviewed exact head: 2e91aa19202e47faf4c8ae173192345b3b2729dd; base: f03ac9d89dccb67c71e0deea6ef999f6f7f95ddc.
动机
用户恢复 v1.2.4 发布。这个已有 PR 先准备可冻结的版本源码,并修复迁移命令缺失于帮助目录、公开示例仍硬编码旧状态目录这两个实际兼容问题。合并此 PR 不等于发布验证完成。
改动思路
沿用已有 package/runtime 版本镜像、COMMAND_GROUPS 与生成手册,以及 bootstrap 的 state_file 返回值。Python 留在既有打包、文件系统和示例适配层;没有新增控制面决策源、权限或迁移执行器。相关小重构已去掉 demo 重复的目录知识,没有新增 helper。
具体改动
loopx/__init__.py与pyproject.toml同步为 1.2.4,四份中英 Developer Book 当前锚点随版本更新。help_surface.COMMAND_GROUPS收录现有migrate-local-state --help;man/loopx.1由同一目录渲染,明确离线预览、停止 writer 与凭据绑定回退。CLI_OUTPUT_COMMAND_CLASSIFICATIONS按精确 command id 使用既有explicit_cold_path_exception。这条离线命令不进入自动轮询热路径,也不放宽任何输出预算。_seed_visible_demo_control_plane使用 bootstrap 返回的实际状态文件;现有 worker-loop smoke 按新安装.loopx路由检查。已有登记旧目录仍由原 bootstrap/路径 owner 决定,没有搬动数据。
对主干的风险
完整差异仅 11 个文件,24 行增加、11 行删除。最强反例是版本镜像不一致、示例误写另一状态路径,或帮助出现被误认为迁移授权。现有版本不匹配、迁移 plan/receipt/活跃 writer 拒绝用例均通过;命令可见性不触发执行。129 项聚焦测试通过,3 项既有平台用例跳过,未算通过。同步新主干后,真实隔离安装手册及 48 项安装/doctor/host 用例再次通过;11 个最终差异 blob 与已测前一 head 相同,已核验依赖和边界失效范围。帮助/真实隔离安装手册、书籍、版本、发布物和 auto-research smokes 全部通过;Ruff 零问题,mypy 的配置范围 19 文件通过。前端发布构建校验通过且保留上一交付资源。初次并发依赖安装造成的文件读取冲突已顺序重跑通过,未修改断言。
此前 2cb9505 的 native premerge 14 项检查通过;最终差异的 11 个 blob 及所有 production/build dependency 未改变,新增主干仅修改两个不相关恢复测试,已完整核验。当前 head 再运行版本负向、book、diff、静态检查和严格质量校验,作为相同风险边界的验证集合,零未解决 hold;最终质量 receipt cqr_6db5618d59f5e5379982 对应该精确 scope。差异语义 advisory 与公开边界检查通过;没有私有状态、日志或凭据进入改动。未改 UI 首屏、Lark/CLI 配置入口、PostgreSQL authority 或用户安装路由,因此无新增 companion 页面或真实 PG 重构验证要求。
最终合入提交仍需执行 pytest、Ruff、mypy、风险 canary、完整 public fleet、安装/升级/host、公开边界及真实默认 Doubao 八组发布验证。此评审不把旧 head 的结果移作最终 release 证明,也不声明完整发布或模型通过。
我的整体评价
APPROVE:这是完整而可回退的发布准备阶段,修复两个已交付契约的消费者问题,复用现有 owner。按用户恢复发布的授权完成合入后,继续在最终提交上验证、发布 tag/包和更新入口。本 Goal 不查询或等待 PR CI;没有未解决源码 blocker。
English verdict: APPROVE - exact head 2e91aa1. Eleven focused release-preparation paths reuse canonical version/help/classification/bootstrap owners. 129 tests pass, three platform skips are disclosed; manual installer, book, version, artifact and demo smokes, Ruff, mypy, frontend build, native premerge and exact-scope quality pass. No migration execution or authority change. Final release qualification remains required on the merged commit before publication.
LoopX v1.2.4
More reliable Chat coordination, explicit local state migration, and scoped preferences for long-running agents.
State Kernel & Control Plane
.loopx. Only explicit offline plans migrate state. Monitor, GoalRef, quota and Turn recovery preserve original identity and uncertain effects. #5490, #5491, #5474, #5457, #5450, #4915, #5324, #5432, #5393, #5389, #5332, #5417, #5441.Capabilities & Workflows
Quality & Testing
Benchmarks & Integrations
Keep Codex context: Planning, heartbeat and successive Todos can share an exact native conversation. Validation and settlement remain independent. #5527.
Opted-in operation hosts: Confirmed operations can continue on the original managed Turn through explicitly enabled native tools. Human confirmation remains separate from permission to execute. Delegated completion keeps the original claim proof, and empty-Todo replans reach their intended recovery path. #5466. An accepted start is not proof of consumption or task completion. #5327, #5378, #5383.
Documentation
Community Contributors
Release Decision
Illustrated upgrade and usage guide (personal Feishu account). The guide covers updates since the previous personal release announcement (v1.2.0).
Who should upgrade: Workspace Chat, App approval and managed-host users.
What this release solves: Recover Chat work, inspect teams, retain Codex context and control state migration.
Breaking changes: Yes. Codex exec defaults to resume/agent; rename explicit
resume-if-availabletoresume. Existing Todo bindings stay separate; select--session-scope todofor task isolation. State migration remains explicit; legacy/custom routes are retained.How to verify: Confirm version 1.2.4, read
doctor, then inspect a known Goal and its stored route before resuming workers.Pin
loopx==1.2.4; package rollback usesloopx==1.2.3. Freeze writers before reverting migrated state. Install guide.Upgrade/revert paired Python/TypeScript runtime together; persisted journal/receipt identities remain compatible.
Contributors: 13 community contributors, including @jackie-cqz; see linked contributions above.
Optional Capability Activation & Use
Codex exec conversation continuity
Activation: Codex exec now defaults to resume/agent. Benchmark fresh stays the default; select resume explicitly there. Rename explicit resume-if-available to resume.
Validation: The plan below reads context_policy and scope without launching a model. Actual execution still requires an independent validator.
Disable / rollback: Select --iteration-context fresh or --session-scope todo per invocation; package rollback retains old Todo bindings.
Authority boundary: History grants no Todo completion, lease, quota or tool approval; no cross-home session import. Drift requires repair or explicit fresh.
Docs: v1.2.4
Goal capability improvement preview
Activation: Experimental default-off M1 preview. Review the bounded Goal intent below, then repeat with
--execute. It enables no capability; App/Lark companion delivery remains partial.Validation:
capability inspectreads the original Goal configuration. With no explicit gap, advice continues current work; caller candidate references are unauthenticated advice.Disable / rollback: Preview
configure-goal --goal-id "$GOAL_ID" --clear-capability-improvement-configuration, then repeat with--executeto restore off. Undo any separately approved trial through its original capability owner.Authority boundary: No automatic catalog scan, installation, provider call, scheduling or new execution grant; existing Todo/lease/quota/provider checks still apply. Do not supply private evidence in public gap references.
Docs: Guide
Goal task ownership migration
Activation: Goal settings → Task ownership: choose a policy, inspect preserved claims/leases, then Back up and apply. Requires an already promoted canonical Goal and authorized, settled source executions.
Validation: Read the current policy separately from any historical receipt; after response loss or same-tab reload, retry the saved original preview. CLI readback is below.
Disable / rollback: Discard preview and start again cancels an unapplied browser carrier without deleting server backup/plan. To reverse an applied policy, create a new reviewed migration and backup; never restore an old archive over later writes.
Authority boundary: Changes ownership policy only, not storage or capability grants; no automatic live-Goal migration. A new legacy target is rejected. Preserve server plans/backups for recovery if browser storage is cleared.
Docs: Guide
loopx --format json handoff-mode show --goal-id "$GOAL_ID"Authority archive restore completion
Activation: Invoke the read-only query only for a previously reviewed restore, using that operation's exact Goal, verified archive digest, provider and destination. No persistent switch is enabled.
Validation:
receipt_foundproves a matching historical completion receipt;receipt_missingproves neither failure nor worker liveness. Audit the current copy before any separately authorized provider adoption.Disable / rollback: Stop invoking the query; it creates no destination or stored activation to undo. To resume recovery, repeat only the original reviewed
restore --executecommand with the same inputs and destination. Preserve partial output.Authority boundary: Metadata readback does not open a provider, acquire a restore lock, replay history, cancel a worker or change active authority. Both outcomes report current integrity unverified and worker liveness unknown.
Docs: Guide
Local state migration
Activation: Run the preview explicitly after stopping all writers. Review the plan; execution requires that exact
--expected-plan-idand--execute.Validation: Inspect the selected route and project registries before restarting writers.
Disable / rollback: Keep the private backup. Preview
migrate-local-state --rollback-receipt "$RECEIPT"; with unchanged contents and stopped writers repeat with--execute.Authority boundary: Offline local migration only; no permission to move live writer state, unrelated Codex sessions or credentials. Upgrade itself does not migrate.
Docs: Guide
Agent preferences
Activation: Use
semantic-preference agent rememberfor an explicit user source. Preview before--execute; pass the fresh read revision (noneonly for an empty store) and a stable operation id.Validation: Read the exact Goal/Agent scope after a correction; uncertain retries reuse the same operation id and request.
Disable / rollback: Use
agent retirewith the key, explicit forget-source, fresh revision and a new operation id; inspect history. Retirement preserves private audit history and is not physical erasure.Authority boundary: Scoped private preference state; quotes from documents or generated lessons are not user write sources. Preferences do not grant merge or execution permission.
Docs: Guide
Reward Memory utility
Activation: Opt in per command by passing a reviewed utility-observation file to
reward-memory utility-project.Validation: Inspect item attribution, evidence tier and unknown/ambiguous outcomes in the JSON projection.
Disable / rollback: Stop invoking the command and discard its read-only output; no persisted memory/provider rollback is required.
Authority boundary: Read-only projection. It does not rank, retire or write memories, launch an experiment or turn task success into memory credit.
Docs: Guide
Goal Chat coordination
Activation: Open Goal → Chat → Enable LoopX and review Settings, the sender binding and positive turn allowance. Team prerequisite checks are explicitly requested reads.
Validation: Open Team execution and Check prerequisites; inspect the original operation and canonical Todo after an accepted result.
Disable / rollback: Use Pause or Exit LoopX to stop coordinator continuation; already delegated members need their existing stop controls.
Authority boundary: A prerequisite read does not dispatch work or raise quota. Missing/unknown execution facts remain unknown; sender, lease and authority checks still apply.
Docs: Guide
loopx chat --goal-id "$GOAL_ID"Confirmed operation continuation
Activation: Opt in on the bound Turn with
--host codex-cli --codex-operation-tools --codex-model "$MODEL" --codex-reasoning-effort "$EFFORT". Configureoperation_callbacks.managed_turn_wakeonly for the original delegation requester/binding; preview the Turn before execution.Validation: Validate the collector plan and inspect the original native session's pending/consume/report receipts. Configuration readback alone is not execution proof.
Disable / rollback: Remove
managed_turn_waketo stop new callback continuations, and omit--codex-operation-toolsfrom future Turns. Pause the original sender if needed; these steps do not undo already performed effects.Authority boundary: Human confirmation is not a general execution grant. Original Goal/Agent/Todo, session profile, sandbox, quota and lease remain required. Start acceptance is not completion.
Docs: Guide
loopx lark-inbox collector-plan --project . --config .loopx/config/lark-collector.json --format jsonUsage statistics
Activation: After a visible initial/renewed notice, the normal opt-out distribution enables basic statistics by default, with device context
unknown; explicit opt-out survives upgrade. Consent-required distributions wait for explicit enable. Set voluntary context withloopx usage-ping context --context personal; labeling does not enable statistics, change the ID or relabel history.Validation: Read stored/effective context, notice, sending and installation_preview. Environment context override wins. Runtime clocks are independently unioned observed minutes, not uptime, people, completion or billing.
Disable / rollback: Run
loopx usage-ping disableor setLOOPX_USAGE_PING=0. Disable clears local ID/counts/measurement history but retains voluntary label; stored opt-out survives upgrade and already-sent records cannot be recalled.Authority boundary: Bounded, lossy installation/diagnostic data; no raw conversation, private path or command argument values. This does not grant account or data-source access.
Docs: Guide
PR review closeout
Activation: Invoke
pr-reviewexplicitly for the managed Goal and exact PR head, after publishing the qualified review.Validation: Read approval closeout and then exact-head merge readiness; preserve unresolved findings and changed-head invalidation.
Disable / rollback: Stop invoking this command to disable this per-command workflow. An installed optional merge skill can be removed through its normal workflow-skills uninstall path.
Authority boundary: Closeout does not grant approval, merge or admin-bypass authority and does not clear unverified review threads.
Docs: Guide
Extension runtime readiness
Activation: Install the chosen reviewed extension manifest; opt in with
loopx extension enable "$EXTENSION_ID" --execute. Re-run extension doctor in each intended runtime; presence in another Python environment is not activation.Validation: Read the doctor and catalog in the same environment that will invoke the provider. A newly changed artifact must be requalified.
Disable / rollback: Run
loopx extension disable "$EXTENSION_ID" --execute. Use extension rollback for a retained revision; requalify the current runtime before enabling it again.Authority boundary: Readiness is scoped to the manifest revision and exact local entrypoint. It grants neither provider permission nor external sending authority; Goal Channel still requires its scoped binding and explicit notification authorization.
Docs: Guide
loopx extension doctor "$EXTENSION_ID" --execute --format json loopx extension list --format jsonLocal performance diagnosis
Activation: Opt in per command with performance-diagnosis plan or inspect, or open Settings → Capabilities → Device defaults → Performance diagnosis and choose a local Speedscope/V8 CPU profile. Plan only returns capture argv; execute it separately under existing host authority. For the managed host workflow, run
loopx workflow-skills --install, then restart the host; installation exposes files and does not activate a capture.Validation: Read back managed material with
loopx workflow-skills --format jsonand capability details withloopx capability show performance-diagnosis --format json; inspect an existing profile with the command below. In Settings verify ranked self/inclusive activity, then select malformed input and verify that the previous result is replaced by an error. Each profile stays separate.Disable / rollback: Stop invoking the commands. Remove the managed bundle with
loopx workflow-skills --uninstall; inspect the report because locally modified files are preserved. In Settings use Clear/cancel or leave Settings to drop the result and terminate the worker. Remove optional profiler tools from their isolated environment; retain private evidence before deleting capture files.Authority boundary: Browser inspection stays in memory and does not upload, save preferences or auto-collect. Plans grant no attach, elevation, Goal mutation, upload or execution authority. Sample rankings are neither elapsed-time nor root-cause proof.
Docs: Guide
Isolated public smoke workflow
Activation: Invoke canary smoke-suite explicitly from the intended source checkout, with the supported Python/Node and required jq/zsh tools already on PATH. Each executed check now isolates HOME/config/temp and removes inherited user routes; selected caller PATH stays first.
Validation: Read failure_count, timeout_count, tracked-side-effect guard and each executed check in the JSON result. A focused selection is not complete fleet qualification; full-public requires the complete current inventory and smoke-health readback.
Disable / rollback: Stop invoking the workflow. Revert the source/package to the prior version to revert this default; there is no persistent enable flag or user-state migration to undo. Check children clean up only their fixture-owned managed runtime.
Authority boundary: Explicit disposable fixture execution only. This does not authorize real Goal mutation, external sending, tool installation or stopping unrelated processes. Missing tools and contract failures remain failures.
Docs: Guide
Blocked Todo channel notices
Activation: With the existing authorized Lark Goal Channel ready, opt in separately using goal-channel configure --goal-id "$GOAL_ID" --auto-notify-blocked-notices; preview first, then add --execute. The Goal capability editor exposes the same independent default-off setting.
Validation: Read Goal Channel status and current-target delivery counts after an authorized material refresh. Pending or sent-but-unverified receipts are not delivered proof; channel changes need fresh send/readback.
Disable / rollback: Run goal-channel configure --goal-id "$GOAL_ID" --no-auto-notify-blocked-notices --execute. Existing human-gate notifications remain independently configured; retained private delivery history is not erased.
Authority boundary: Requires existing extension, bot, channel, identity and membership authority. It authorizes only scoped notices, never Todo recovery, permission escalation or processing a Chat reply as an approval.
Docs: Guide
Goal-scoped reliability diagnostics
Activation: Experimental and default off. Load the separately installed dsh-loopx-plugin/observer entry before DSH starts and explicitly set LOOPX_DSH_SHADOW_OBSERVER_GOAL_ID, LOOPX_DSH_SHADOW_OBSERVER_SESSION_ID and the complete LOOPX_DSH_SHADOW_OBSERVER_RUN_IDENTITY_JSON from the versioned reference. All three must be valid; file availability alone activates nothing.
Validation: Read reliability-diagnostics status --with-receipt for the exact Goal. New ledgers use by-goal with SHA-256 of exact UTF-8 identity. Upgrade CLI and plugin together with writers frozen; legacy ledgers stay readable but block appends until the documented owner-verified offline reconciliation.
Disable / rollback: Remove the observer row and unset all three activation variables before restarting DSH. For ledger rollback freeze writers and restore retained original bytes using the versioned local-retention procedure; never merge ambiguous legacy identities or silently move active evidence.
Authority boundary: Passive, session-scoped diagnostic ledger only: no raw transcript, credentials, command execution, send, scheduler or worker-state influence. Prototype coverage does not qualify C0/C1 live behavior or overhead.
Docs: Guide
loopx reliability-diagnostics status --goal-id "$GOAL_ID" --with-receipt --format jsonDeveloper Book text-statistics extension
Activation: In a reviewed v1.2.4 checkout, create an isolated Python environment, install the provider explicitly, preview manifest install and then execute it. It is a teaching package outside the default catalog, not a published standalone PyPI package.
Validation: Run provider doctor/tests and the managed extension request; inspect the actual fixed result and disabled rejection.
Disable / rollback: Disable the same extension state with
loopx extension disable loopx-text-stats --state-file "$extension_state" --execute; uninstall the exercise environment/package or restore its reviewed prior package for rollback.Authority boundary: No model, network, arbitrary file, credentials or Goal/Todo access. An empty declared permission list does not sandbox third-party Python; review code before installation.
Docs: Guide
Steward Goal attention and human-gate notices
Activation: With an explicitly set-up Goal Channel and verified provider binding, new setup enables human-gate notices by default; existing bindings keep their stored choice. Preview with
loopx goal-channel configure --goal-id "$GOAL_ID" --auto-notify-human-gates, then repeat with--executeto enable. Blocked notices are a separate default-off choice. The configured steward runtime explains canonical selected requests; this is a staged RFC integration.Validation: Run Goal Channel doctor and inspect the stored binding, then inspect the exact selected gate and send/readback receipt after an authorized refresh. A configuration check alone is not delivery proof. In the App, inspect the notification settings for the same Goal.
Disable / rollback: Run
loopx goal-channel configure --goal-id "$GOAL_ID" --no-auto-notify-human-gates --execute. For one refresh use--suppress-external-sinks; turn-bound resumption requires the returned--resume-external-sinkskey. Revert to a compatible prior package for the local attention view; no new attention enable flag exists.Authority boundary: A notice does not approve a request, recover a Todo or grant execution authority. Preserve exact request scope, evidence, original binding and provider permission. No raw state, private paths, logs, credentials, message ids or provider payloads enter public notices; model synthesis cannot expand authorization.
Docs: Guide
Receiver assessment and work links
Activation: Explicitly acknowledge an existing scoped request and optionally link a receiver-owned Todo below. Scoped MCP uses
assess_request/link_work; there is no new switch.Validation: Read
receiver_followthrough: assessment, current linked work, owed return and unavailable evidence remain distinct. Return an audience-ready conclusion withmanager-inbox report --goal-id "$GOAL_ID" --agent-id "$AGENT_ID" --request-id "$REQUEST_ID" --reply-text 'Result and remaining gap.'; reading or completing a Todo alone returns no answer.Disable / rollback: Stop adding links; record defer/reject with the actual reason for unaccepted requests. Stop owned work through its existing controls. Links remain receipts, not work cancellation or reversible effects.
Authority boundary: No Todo creation, reprioritization, claim transfer or new private Core access. Missing/changed ownership stays unknown. CLI/MCP are shipped; full automatic frontend/Lark delegation remains unqualified.
Docs: Guide
中文摘要
本版本改善长期任务中的 Chat 协作、状态恢复和用户偏好,并提供显式的本地目录迁移。
状态内核与控制面
可靠续跑: App Goal 初始化中断后续跑原操作;跨页面保留会话恢复 owner、归档任务历史和检查器事实。上下文读取可观察已有、精确作用域的本地 peer 路由,丢失或有歧义的来源保持未知;生命周期专用项目不再提供运行时接收者。#5500、#5507、#5398、#5509、#5522。
显式规划与所有权: 首次 replan 建议在选择前不预绑定;已获准的结算重试保留原决策。压缩视图保留当前 owner 的 frontier 计数。Goal 设置支持先预览任务所有权策略迁移、验证备份,再从响应丢失或刷新页面中恢复同一操作;不会自动搬迁存储、迁移活动 Goal 或授予执行权。#5498、#5495、#5502、#5508。
上下文交接与阻塞工作: 上下文交接保留来源授权;请求/结果链接保留接收者判断与当前工作,不新增权限。replan 与进展检查按当前 work-item 绑定识别已记录阻塞,避免把无关工作误当成当前工作。#5492、#5486、#5519。
归档恢复回读: 恢复响应丢失或超过等待预算时明确返回结果未知,并提供精确的完成凭据查询。查询只读有界元数据,不重放恢复或启用 provider;当前完整性仍需单独 audit。Windows 归档备份跳过平台不支持的目录同步,保留文件持久化写入。#5490、#5491。
状态与恢复: 升级诊断与服务保留已声明的 runtime 路由,宿主观察文件和精确普通 native 锁不再使首次配置误报目录歧义。#5474。已结算 monitor 恢复 quiet-due 调度,不擅自重开任务。#5457、#5450。新安装使用
.loopx;已注册的旧目录及自定义路径保留,升级不自动搬数据。离线迁移提供预览、绑定计划和私有回滚凭据。GoalRef 日志恢复保持原结算身份,周期 replan 仅累计有实质变化的 monitor poll。#4915、#5324、#5432、#5393。Quota 与 replan 恢复: 来源绑定的额度结算在扣减、void 和重放前检查精确 Goal 实例,防止旧结果跨越删除重建边界。到期的自主 replan 在 quiet monitor 下仍保留有界执行义务,受 user gate 覆盖的普通工作继续拒绝。本次仅核验 quota 层,不等于启用完整 Goal 实例生命周期。#5389、#5332。
Turn 恢复与私有诊断: 类型化 Turn 准入保留已提交但无效证据的可恢复状态,避免结果不确定时重试重复 effect。诊断账本按精确 Goal 标识隔离,旧账本停止新写入,须显式离线核对。 #5417、#5441。
能力与工作流
实验性能力改进意图: 默认关闭、按 Goal 启用的 M1 后端预览,在既有 before-plan/replan 中给出有界建议,不启用其他能力、不安装、不调用 provider。CLI/共享设置 API 已交付;打包 App 交互、本地化和 Lark 配套验收仍为 partial。#5493。
审批与 Chat 提案: Workspace App 可批准、拒绝或撤回正式 User gate,再恢复符合条件的关联工作。Chat Todo 提案可见、刷新后可恢复,确认后才应用;延期提案仍保持等待。保存的回答返回原 Goal 与会话,不确定的 steering 请求保留恢复状态。#5415、#5266、#5416、#5430。
团队可见性: Goal Work Map 连通里程碑、Todo 与执行,Turn 步骤让当前会话进展更清楚。Chat 展示持久执行清单,并按需检查前提。未知执行状态仍显示未知,读取不会派发工作。切换会话后仍能查看晚到结果,生命周期预览保留基于 revision 的来源依据。#5488、#5471。英文环境中的内置导航与操作标签已补齐,用户文本保留原语言。#5429, #5433、#5420、#5421。
Goal 决策上下文: 共享 attention 视图连接决策、目标、作用域及证据;Goal Channel 通过已配置 steward runtime 解释选中的请求,选择、批准、冷却及发送权限仍由既有 owner 决定。新建 channel 开启人工决策通知,已有绑定保留原设置,阻塞通知仍默认关闭。本次阶段集成不代表完整 steward 生命周期或持续自主运行已合格。#5480。
偏好与证据: Goal/Agent 显式偏好支持基于 revision 的纠正、退役和私有历史。Reward Memory 新增只读效用归因投影,任务成功本身不能证明记忆贡献。两者均不增加执行权限或改变记忆 provider 的生命周期。#5320、#3829。
作用域内的阻塞通知: Goal Channel 的独立、默认关闭设置交付 blocked Todo 通知,保留 pending 与回读证据,不增加 Todo 恢复权限。 #5452。
质量与测试
跨平台与评审正确性: 已有 peer 交接保留 Windows 锁与原子发布语义;File 冷读复用 replay 状态,归档 round trip 覆盖落后 consumer。评审者归属绑定已记录的执行元数据,落后 main 但已批准且无冲突的 head 可就绪;这些观察不授予合并权限。#5456、#5494、#5516、#5514、#5518。
检查进程归属: 仓库检查失败时先停止自身子进程再清理 fixture,覆盖父进程退出但输出管道仍被占用的情况;检查期限不变,无关进程继续运行。#5501。结算验证已执行所有权策略迁移后的真实业务路径,不仅核对迁移读回。#5503。
安装使用与运行时间: 重新告知保护关联安装标识的有界每日功能计数和各自测量的运行时间;基础统计在可见告知后默认开启,设备用途默认为“未知”;主动关闭后跨升级保留。修改自愿标签不改变统计开关。已完成任务的数值provider包络修复Codex计时,不把空闲或延迟token记录算入。收集端增量部署须先于客户端升级。#5477。
验证与维护: 安装快照排除可重建的 Cargo 编译缓存;扩展就绪按实际 runtime 产物隔离,延期 Lark 通知在应当发送时才检查发送准入。#5461、#5460。 恢复 dashboard 缺失的 CSS token,并增加定义检查。#5343。 改善批量来源验证、当前 quota 投影、凭据值识别、精确 head 评审收尾、差异语义 advisory,以及安装 cohort 使用诊断。本版本不新增 benchmark 成绩、持续运行达标或真实金融执行结论。#5367、#5370、#5335、#5317、#5366。
本地性能诊断: 显式规划捕获但不执行,沿用有界 TypeScript 规则检查已有 Speedscope/V8 CPU 证据,也可在 Settings 中使用仅浏览器内存的本地检查入口。#5454。
Chat 路径隐私与可靠验证: Chat 的流式分块和 JSON 状态均隐藏完整的已声明 runtime 路径。显式 smoke 为每项检查隔离 HOME/config/temp,保留选定工具链顺序,只停止自己的 managed runtime。中断的安装测试先停止自己创建的进程组再清理;生产摘要校验复用既有摘要规则;普查登记已有动态决定引用匹配。#5499。#5496。 #5472、#5473、#5470。
基准与集成
文档
社区贡献者
升级决策
图文升级与使用指南(维护者个人飞书账号),从上次个人发布介绍 v1.2.0 讲起。
谁需要升级: 使用 Workspace Chat、App 审批或本地 managed host 协调长期 Goal 的用户。
解决了什么: 可恢复的提案与回答、清晰的团队执行事实、显式状态目录迁移和基于 revision 的偏好纠正。
是否有破坏性变更: 有。Codex exec 默认 resume/agent,旧显式 resume-if-available 须改为 resume;既有 Todo 绑定保留且不自动导入。按题目隔离可选 --session-scope todo。状态目录仍仅显式迁移,旧路由保留。
如何验证: 确认版本为 1.2.4,读取
doctor,恢复 worker 前检查已知 Goal 及其保存的路由。安装包固定 loopx==1.2.4,回退固定 loopx==1.2.3;迁移回退前冻结 writer。
Turn 恢复更新 Python/TypeScript 配对的瞬时协议,须同时升级或回退两者;已保存的 journal/receipt 身份保持兼容。旧诊断账本须按下方流程冻结 writer 后显式处理,不自动迁移。
贡献者: 本次有 13 位社区贡献者,包括 @jackie-cqz;具体贡献与 PR 链接见上方“社区贡献者”。
可选能力启用与使用
Codex exec conversation continuity
启用: 普通 Codex exec 默认 resume/agent;benchmark 的 fresh 默认不变,需显式选择 resume。旧显式名称 resume-if-available 已移除。
验证: 下方 plan 只读回本次 context_policy 与绑定范围,不启动模型;实际执行仍需独立 validator。
停用 / 回退: 单次选择 --iteration-context fresh 或 --session-scope todo;按安装指南回退软件,保留已有 Todo 绑定。
权限边界: 历史复用不继承 Todo 完成、租约、配额或工具审批;不导入其他 home 的会话。失配须修复或显式 fresh。
文档: v1.2.4
Goal capability improvement preview
启用: 实验性 M1 后端预览,默认关闭。先运行下列有界 Goal 意图预览,审阅后才加
--execute;不是第二个能力开关,App/Lark 配套交互仍为 partial。验证:
capability inspect回读原 Goal 配置。没有明确 gap 时继续当前工作;调用方提供的候选引用只是未认证建议。停用 / 回退: 预览
configure-goal --goal-id "$GOAL_ID" --clear-capability-improvement-configuration,审阅后加--execute恢复关闭。另行获准的试用按原能力 owner 回退。权限边界: 不自动扫描目录、安装、调用 provider、调度或新增执行权;原 Todo/lease/quota/provider 准入仍有效。公开 gap 引用不要包含私有材料。
文档: Guide
Goal task ownership migration
启用: 在 Goal 设置 → 任务所有权中选“协作认领”或“独占执行租约”,预览保留的认领/租约,再显式“备份并应用”。需已有 canonical promotion 且来源执行已获准处理并停稳。
验证: 区分历史操作凭据与另行回读的当前策略;响应丢失或同标签页刷新后重试保存的原预览,CLI 回读命令如下。
停用 / 回退: “放弃预览并重新开始”丢弃尚未应用的浏览器 carrier,不删除 server 计划/备份。已应用策略要反向修改时,新建审阅迁移与备份,不能用旧归档覆盖后续写入。
权限边界: 只修改所有权策略,不改变存储或能力授权,不自动迁移活动 Goal;不接受新增 legacy 目标。清除浏览器存储前保留 server 计划/备份以便恢复。
文档: Guide
loopx --format json handoff-mode show --goal-id "$GOAL_ID"Authority archive restore completion
启用: 仅对已审阅的恢复操作运行只读查询,沿用该操作精确的 Goal、已验证归档 digest、provider 和目的目录;没有持久化开关。
验证:
receipt_found表示找到匹配的历史完成凭据;receipt_missing不能证明失败或 worker 存活。另行授权启用 provider 前,仍须 audit 当前副本。停用 / 回退: 停止调用查询即可;查询不创建目的目录或待撤销的启用状态。需要续跑恢复时,仅重用原审阅的
restore --execute命令、同一输入与目的目录,保留部分输出。权限边界: 元数据回读不打开 provider、不获取恢复锁、不重放历史、不取消 worker、不改变活动 authority。两种结果均明确当前完整性未验证、worker 存活未知。
文档: Guide
Local state migration
启用: 停止所有 writer 后显式运行预览,核对计划。执行须提供该计划的
--expected-plan-id及--execute。验证: 恢复 writer 前核对选中的路由及项目 registry。
停用 / 回退: 保留私有备份。先运行
migrate-local-state --rollback-receipt "$RECEIPT"预览;内容未变且 writer 已停时,加--execute执行。权限边界: 仅授权离线本地迁移,不授权移动活跃 writer 状态、无关 Codex 会话或凭据。升级本身不迁移。
文档: Guide
Agent preferences
启用: 仅根据用户显式来源使用
semantic-preference agent remember。先预览再加--execute,传入新鲜 revision(仅空 store 用none)及稳定 operation id。验证: 纠正后读取精确 Goal/Agent 作用域;结果不确定时复用原 operation id 和原请求。
停用 / 回退: 用
agent retire提供 key、用户明确忘记来源、新鲜 revision 和新 operation id,再读取历史。退役保留私有审计历史,不等于物理删除。权限边界: 这是作用域内的私有偏好状态,文档引用或模型生成经验不构成用户写入来源,也不授予合并或执行权限。
文档: Guide
Reward Memory utility
启用: 逐条命令启用:向
reward-memory utility-project传入已审阅的效用观察文件。验证: 检查 JSON 投影中的条目归因、证据层级,以及未知或有歧义的结果。
停用 / 回退: 停止调用并丢弃只读输出;无需回滚记忆或 provider 的持久状态。
权限边界: 只读投影,不排序、退役或写入记忆,不启动实验,也不将任务成功直接归因为记忆贡献。
文档: Guide
Goal Chat coordination
启用: 进入 Goal → Chat → Enable LoopX,核对 Settings、sender binding 和正数 turn allowance。团队前提检查由用户按需读取。
验证: 打开 Team execution 并执行 Check prerequisites;accepted 后检查原操作与正式 Todo。
停用 / 回退: 用 Pause 或 Exit LoopX 停止 coordinator 续跑;已派发成员使用其既有停止控制。
权限边界: 前提读取不派发工作或增加 quota,缺失或未知执行事实保持未知,sender、lease 与权限检查仍有效。
文档: Guide
loopx chat --goal-id "$GOAL_ID"Confirmed operation continuation
启用: 在已绑定 Turn 中逐次指定
--host codex-cli --codex-operation-tools --codex-model "$MODEL" --codex-reasoning-effort "$EFFORT"。operation_callbacks.managed_turn_wake只配置原 delegation requester/binding,执行前先预览 Turn。验证: 验证 collector plan,再检查原生会话的 pending/consume/report 凭据。配置读取本身不能证明已执行。
停用 / 回退: 删除
managed_turn_wake停止新 callback 续跑,未来 Turn 省略--codex-operation-tools。必要时暂停原 sender;这些操作不撤销已经发生的效果。权限边界: 人的确认不是通用执行授权;原 Goal/Agent/Todo、session profile、sandbox、quota 和 lease 仍须满足。start accepted 不代表完成。
文档: Guide
loopx lark-inbox collector-plan --project . --config .loopx/config/lark-collector.json --format jsonUsage statistics
启用: 首次/重新可见告知后,普通opt-out分发默认开启基础统计,设备用途默认为“未知”;已显式关闭则跨升级保留关闭,consent-required渠道仍需显式enable。
loopx usage-ping context --context personal保存自愿标签,不启用统计、不换ID、不改历史;环境变量优先。验证: 回读stored/effective context、notice、sending和installation_preview。三个口径只表示各自已观测并集分钟,不能相加或解释为在线、人、完成率和计费。
停用 / 回退: 运行
loopx usage-ping disable或设置LOOPX_USAGE_PING=0;关闭清ID/计数/测量历史、保留自愿标签,opt-out跨升级保留,已发送记录不能撤回。权限边界: 仅发送有界、允许丢失的安装及诊断数据,不包含原始对话、私有路径或命令参数值,不授予账户或数据源访问。
文档: Guide
PR review closeout
启用: 逐次显式调用
pr-review,指定 managed Goal 和精确 PR head,并先发布已验证评审。验证: 读取 approval closeout,再核对精确 head 的 merge readiness;保留未解决意见和 head 变更失效规则。
停用 / 回退: 停止调用即可停用这个逐次命令流程;已安装的可选 merge skill 通过既有 workflow-skills uninstall 路径移除。
权限边界: closeout 不授予批准、合并或 admin bypass 权限,不清除未验证的 review thread。
文档: Guide
Extension runtime readiness
启用: 显式安装已审阅的扩展 manifest,再运行
loopx extension enable "$EXTENSION_ID" --execute启用。在每个目标 runtime 中重新执行 doctor;另一 Python 环境中的可用性不代表本环境已启用。验证: 在实际调用 provider 的同一环境读取 doctor 与 catalog;入口产物改变后须重新验证。
停用 / 回退: 运行
loopx extension disable "$EXTENSION_ID" --execute停用;用 extension rollback 回到保留 revision。再次启用前验证当前 runtime。权限边界: 就绪凭据绑定 manifest revision 和本地精确入口,不授予 provider 权限或外部发送授权;Goal Channel 仍要求作用域绑定及明确通知授权。
文档: Guide
loopx extension doctor "$EXTENSION_ID" --execute --format json loopx extension list --format jsonLocal performance diagnosis
启用: 逐条命令使用 performance-diagnosis plan / inspect,或进入 Settings → Capabilities → Device defaults → Performance diagnosis 选择本地 Speedscope/V8 CPU 文件。plan 只返回捕获 argv,执行仍须遵循既有 Host 授权。托管宿主流程通过
loopx workflow-skills --install安装后重启宿主;安装仅提供文件,不自动捕获。验证: 用
loopx workflow-skills --format json回读托管材料,用loopx capability show performance-diagnosis --format json检查能力详情,再用下方命令检查既有 profile;在 Settings 核对 self/inclusive 排序,再选损坏文件,确认旧结果被明确错误替换。不同 profile 保持独立。停用 / 回退: 停止调用命令;用
loopx workflow-skills --uninstall移除托管 bundle,核对报告,因为本地修改过的文件会保留。Settings 中 Clear/cancel 或离开 Settings 会清除结果并终止 worker。可选 profiler 从其隔离环境卸载,删除捕获文件前保留私有证据。权限边界: 浏览器仅在内存检查,不上传、不保存偏好、不自动采集。plan 不授予 attach、提权、Goal 修改、上传或执行权限;采样排序不是耗时或根因证明。
文档: Guide
Isolated public smoke workflow
启用: 从目标源码 checkout 显式运行 canary smoke-suite,提前在 PATH 中准备受支持的 Python/Node 及 jq/zsh。每项执行隔离 HOME/config/temp 并移除继承的用户路由,保留调用方选定工具的优先级。
验证: 读取 JSON 的 failure_count、timeout_count、tracked-side-effect guard 及各项结果。局部选择不能证明全量 fleet 通过,full-public 必须覆盖当前完整清单并经 smoke-health 回读。
停用 / 回退: 停止调用即可停用;回退源码或包到前一版本可撤销该默认行为,没有需删除的持久启用标志或用户数据迁移。子检查只清理自己的 fixture managed runtime。
权限边界: 仅授权显式的一次性 fixture 执行,不授权修改真实 Goal、外部发送、安装工具或停止无关进程;缺失工具与合同失败仍是失败。
文档: Guide
Blocked Todo channel notices
启用: 先确认已有 Lark Goal Channel 授权及就绪,再单独用 goal-channel configure --goal-id "$GOAL_ID" --auto-notify-blocked-notices 启用;先预览,再加 --execute。Goal 能力编辑器提供同一独立、默认关闭设置。
验证: 在获授权的实质 refresh 后读取 Goal Channel status 及当前目标的发送计数。pending 或 sent-but-unverified 不是已交付证明,切换频道须重新发送及回读。
停用 / 回退: 运行 goal-channel configure --goal-id "$GOAL_ID" --no-auto-notify-blocked-notices --execute 停用;human-gate 通知仍独立配置,已有私有发送历史不删除。
权限边界: 须满足已有 extension、bot、频道、身份及成员授权,仅授权作用域内通知,不授予 Todo 恢复、权限升级或将 Chat 回复视为批准。
文档: Guide
Goal-scoped reliability diagnostics
启用: 实验能力,默认关闭。DSH 启动前加载单独安装的 dsh-loopx-plugin/observer 入口,并显式设置 LOOPX_DSH_SHADOW_OBSERVER_GOAL_ID、LOOPX_DSH_SHADOW_OBSERVER_SESSION_ID 及版本化文档中的完整 LOOPX_DSH_SHADOW_OBSERVER_RUN_IDENTITY_JSON;三者均有效才启用,文件存在不构成激活。
验证: 对精确 Goal 读取 reliability-diagnostics status --with-receipt。新账本位于 by-goal,名称由精确 UTF-8 身份的 SHA-256 派生。冻结 writer 后同时升级 CLI 和 plugin;旧账本仍可读取,但须按文档经 owner 离线核对后才恢复追加。
停用 / 回退: 移除 observer row、unset 三个启用变量后重启 DSH。回退账本前冻结 writer,再按版本化 local-retention 流程恢复保留的原始字节;不合并有身份歧义的旧账本,不静默搬动活跃证据。
权限边界: 仅被动、按 session 记录诊断账本,不读取原始对话或凭据,不执行命令、发送消息或影响 scheduler/worker 状态;prototype 覆盖不等于 C0/C1 实机或开销达标。
文档: Guide
loopx reliability-diagnostics status --goal-id "$GOAL_ID" --with-receipt --format jsonDeveloper Book text-statistics extension
启用: 在已评审v1.2.4源码中创建隔离Python环境,显式安装provider,预览manifest安装再执行。它是默认目录之外的教学包,不是独立已发布PyPI包。
验证: 运行provider doctor/测试与受管extension请求,回读固定结果,并验证停用后请求拒绝。
停用 / 回退: 对同一extension_state执行
loopx extension disable loopx-text-stats --state-file "$extension_state" --execute;卸载练习包/环境,或恢复已评审旧provider版本回退。权限边界: 不授予模型、网络、任意文件、凭据或Goal/Todo访问;permissions为空不沙箱隔离第三方Python,安装前需review。
文档: Guide
Steward Goal attention and human-gate notices
启用: 在显式 setup 且验证 provider 绑定的 Goal Channel 中,新绑定默认开启人工决策通知,已有绑定保留原选择。先运行
loopx goal-channel configure --goal-id "$GOAL_ID" --auto-notify-human-gates预览,再加--execute启用。阻塞通知独立且默认关闭。已配置 steward runtime 解释正式选中请求;这是 RFC 的阶段集成。验证: 运行 Goal Channel doctor 并检查已保存绑定;授权 refresh 后核对精确选中 gate 与发送/回读凭据。配置检查本身不能证明交付。App 中检查同一 Goal 的通知设置。
停用 / 回退: 运行
loopx goal-channel configure --goal-id "$GOAL_ID" --no-auto-notify-human-gates --execute。单次 refresh 可用--suppress-external-sinks,Turn 绑定恢复需返回的--resume-external-sinkskey。本地 attention 视图可退回兼容旧包,没有新启用 flag。权限边界: 通知不批准请求、不恢复 Todo、不授予执行权限;保留精确请求范围、证据、原绑定及 provider 权限。不公开原始状态、私有路径、日志、凭据、消息标识或 provider payload;模型解释不扩大授权。
文档: Guide
Receiver assessment and work links
启用: 对已有作用域请求显式记录评估,按需关联接收者已有 Todo,命令如下;scoped MCP 使用
assess_request/link_work,无新默认开关。验证: 回读
receiver_followthrough的评估、当前关联工作、待答复及不可用证据。完成后用manager-inbox report --goal-id "$GOAL_ID" --agent-id "$AGENT_ID" --request-id "$REQUEST_ID" --reply-text '结果与剩余问题。'返回原受众;已读或 Todo 完成不等于已返回答案。停用 / 回退: 停止新增关联;未接受的请求按真实原因记录 defer/reject。通过原控制停止已有执行;关联凭据保留,不等于取消工作或撤销效果。
权限边界: 不创建、重排、转交 Todo 或新增私有 Core 访问;来源缺失或所有权变化保持 unknown。已交付 CLI/MCP,完整 frontend/Lark 自动委派尚未验收。
文档: Guide
验证 / Qualification
Maintainer accepted risk-based qualification at source fc42b84; the complete hosted matrix is not a publication hold and is not claimed passed. The prior source 6ad4d91 passed 516/516 public smokes, 19 risk checks plus 5 direct checks, 335 isolated PostgreSQL tests, 42 real Doubao calls and Node-forward regression. #5527 added 278 focused passes at its integration parent and 10 final-head continuity passes (including native Codex with scripted loopback responses), scoped static/semantic checks and 4 risk checks plus 5 direct checks. Its benchmark-sensitive hold was resolved by explicit maintainer merge authorization. Final-source wheel/sdist, installed Chat and source/checksum readbacks qualify packaging. Initial native cleanup permission failure and optional/platform skips remain recorded; native Codex Goal was skipped for unavailable isolated API profile.
维护者按风险验证接受源码 fc42b84,不再等待完整云端矩阵,也不声明其已通过。前一源码 6ad4d91 的公开 smoke 516/516、风险 19+5、隔离真实 PostgreSQL 335 项、Doubao 42 次真实调用与 Node 前向回归通过;#5527 补充父提交 278 项定向通过、最终提交 10 项续接通过(含原生 Codex/脚本化本地响应)、静态/语义和风险 4+5 检查。benchmark-sensitive hold 经本次明确维护者合并授权处理。最终源码安装包与 Chat、校验和和构建来源另行回读;首次原生进程清理权限失败及条件跳过保留记录。原生 Codex Goal 因缺少隔离 API profile 跳过。