Repository navigation
Conversation
Four sites compiled the cli_-prefixed application id themselves -- the transport hub, bot_scopes, event_collector_runtime and goal_channel_delivery_contract, the last with its own anchors on the same body -- and eight more modules import the transport hub's name, so a bound fix had three possible homes. The shape now lives in identity_shapes.LARK_APP_ID_PATTERN, which already owns the other four Lark identifier bodies and states why anchored and unanchored spellings stay distinct. Every caller applies fullmatch, where the anchors are redundant, so no product answer changes; the guard's tricky-value table pins that. event_collector_runtime is declared by file and count instead of converted, because loopx-project#5248 restructures that file. Signed-off-by: Hsuehtan <296098438+Hsuehtan@users.noreply.github.com>
Three couplings showed up when the shape was actually run, not assumed: - The unfoldable layer is gated on identifier field names. Keying it on the cli_ prefix instead dragged in a setup-URL pattern and a markdown heading built from data, exactly the noise the layer's comment warns about, so the token is the field name app_id. - An alias import does create a module-level binding, so the consumer assertion that rejected one was wrong; object identity is the wiring proof. - The declared-site fixture in the staleness test carried the old budget of one construction; with the declared file now holding two, it has to state both. Signed-off-by: Hsuehtan <296098438+Hsuehtan@users.noreply.github.com>
Hsuehtan
requested review from
huangruiteng,
loopx-agent and
steven-kid
as code owners
October 7, 2026 12:19
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Goal And Delivered Outcome
loopx/extensions/lark/identity_shapes.py, whose docstring already states that one module decidesboth spellings of the Lark identifier bodies, and the guard
tests/architecture/test_lark_identity_shape_owner.py, which scans folded values for that rule.Refs [Task]: Semantic vocabulary convergence follow-ups after RFC PR #4433 / 语义词表收敛后续任务 #4447 (semantic vocabulary convergence), Track A, under the
owner_exclusivitypolicy ofloopx/semantics/vocabulary_v0.json; the house precedent for this file family is refactor(status): single-source the carriers the facade restated #5195, refactor(public-safety): centralize compact identifier shapes #5351, refactor(work-lane): decide the contract wire version in one owner #5387, refactor(lark): decide the sink visibility pair in one owner #5597, refactor(control-plane): decide the agent-lane progress scope in one owner #5684 and refactor(reward-memory): decide five field vocabularies in one owner each #5654 -- the last two being why a guard of this shape reads literals by value rather than by name.cli_-prefixed application id — the identity of the Lark application a Botbelongs to — was compiled by four modules and handed on to eight more:
goal_channel_transport.py:19(unanchored),bot_scopes.py:14(unanchored),goal_channel_delivery_contract.py:12(the same body, its own anchors), andevent_collector_runtime.py:33(unanchored, left in place — see Scope). The transport hub's copy iswhat
goal_channel_setup,goal_channel_runtime,goal_channel_blocked_notice,goal_channel_targets,goal_topic_connections,private_conversations,event_inboxandchat_lark_apiimport, so a bound fix had three writable homes and one import chain.identity_shapes.LARK_APP_ID_PATTERNis the only compile of that body inthe package, and the guard's census fails if any module restates it. No product answer changes: every
call site applies
fullmatch, where the anchors are redundant — pinned by the newtest_the_app_id_answer_is_the_same_anchored_or_notover 11 boundary values. Proven by theunitrow (62 → 84 collected cases in the guard) and the
integrationrow (net-zero arch/canary diff).Author Declaration
mainataa87cc019.Implemented against
identity_shapes.py:1-16): "Searchingfor an identifier inside larger text is the same decision about a different question, so it is stated
here too and nowhere else … both spellings stay distinct and one module decides both", plus the
guard's three questions (second definition / consumer wiring / anchored-vs-search separation).
identity_shapes.LARK_APP_ID_PATTERNtest_no_module_restates_a_lark_identifier_shapeANCHORED_EXPORTS["app_id"],SEARCH_IDENTIFIERSunchangedtest_owner_states_both_spellings_and_nothing_elsebot_scopes+ the delivery contracttest_every_app_id_caller_holds_the_owners_object,test_the_delivery_contract_holds_the_owners_object_tooDECLARED_INDIVIDUAL_SITEScount 1 → 2test_a_converted_declared_site_is_not_silently_reintroducedcli_probe rowstest_the_scan_reports_a_restated_shapeIDENTIFIER_RELEVANCE_TOKENSgated onapp_id, not oncli_test_no_lark_module_hides_an_unfoldable_identifier_constructioncli_pulled a setup-URL pattern and a data-built markdown heading into the unfoldable layer, so thegate uses the field name; the first draft's consumer assertion (that an alias import should not appear
as a module-level binding) was wrong and was replaced by the object-identity proof the sibling hub test
already uses. Left out on purpose:
SAFE_PROFILE_PATTERN, which the transport hub still compiles andwhich two Lark surfaces share — a different decision, named under Scope.
Scope And Continuation
ANCHORED_EXPORTS, the hub's re-export switched to the same alias-import form its other threere-exports already use, the delivery contract's anchored duplicate folded into the owner's single
spelling, and the census/guard extended (bodies, exports, probes, consumers, declaration budget).
loopx/extensions/lark/event_collector_runtime.pydeclared, not converted: feat(goal-channel): compose scoped claims and private reconnect context (#5198) #5248 isrestructuring that file, so its
cli_compile is added to its existing declaration with the countgoing 1 → 2 and the reason written next to it. Converting it deletes the entry, and the staleness
test fails if someone converts it and leaves the entry (mutation
N7).chat_action_normalization's principal rule^[a-z][a-z0-9._-]{0,30}:<opaque>$embeds an opaque body behind a required family prefix — adifferent question, which is why it is not in the census's bodies and why converting it here would
have been a silent narrowing. Three further rules share the same
{1,200}bound(
loopx/chat_endpoints.py,loopx/chat_store.py,multi_subagent/native_child_receipts.py) withdifferent character classes or starts, and stay separate under the registry's rule that a shared
name with different values is not drift.
entry without touching the owner's other four shapes. Successor:
SAFE_PROFILE_PATTERN, compiled inthe transport hub and again in
document_comment_provider.py; and converting the declaredevent_collector_runtimesite once feat(goal-channel): compose scoped claims and private reconnect context (#5198) #5248 lands.Validation
3ebb47000(2 commits, 5 files, +118 −18)unitpython -m pytest -q tests/architecture/test_lark_identity_shape_owner.py-> 84 passed; the same file collects 62 at the base revision, so the +22 cases are the new consumer, equivalence and probe rows.unitpython -m pytest -q tests/extensions -k lark-> 788 passed / 0 failed, 623 deselected: the Lark provider, transport, inbox, setup, targets and delivery surfaces that read the gathered shape.integrationpython -m pytest -q tests/architecture tests/canary— head 2 failed / 1466 passed, unmodified base worktree at the same revision's parent 2 failed / 1444 passed, failure ids identical (test_top_level_module_budget…= the 148-vs-147 pin reported in #5685,test_source_session_registry_denial…). Same interpreter, same qualified Node line, both runs in one window.staticpython -m ruff check loopx/extensions/lark tests/architecture/test_lark_identity_shape_owner.pyclean;python -m mypy->Success: no issues found in 19 source files;loopx check --scan-path loopx/extensions/lark --scan-path tests/architecture/test_lark_identity_shape_owner.py->errors=0.censuspython examples/semantic-vocabulary-drift-smoke.pymeasured on this head and on an unmodified worktree at the base revision, byte-for-byte the same line: same_runtime_forks=2/2 same_runtime_fork_definitions=5/5 conflicting_values=16/16 conflicting_definitions=54/54 schema_version_same_runtime_forks=0/0 multi_value_twins=8/8 multi_value_forks=2/2 multi_value_forks_semantic=1/1 multi_value_fork_definitions=6/6 same_runtime_forks_semantic=2/2 conflicting_values_semantic=0/0, twins_raw=45, generated_verified=2, independently_maintained=43/43. No registry budget and noBUDGET_ANCHORliteral moves in this PR, and the registry I/O census test inside the compared architecture selection reports the same outcome on both sides.regression_parityfullmatch" predicts.ruff format --checkis not a gate here; the guard file already reports 12 hunks at base and 12 at head, and the four product files report 0 both sides.re.compile(X), aninline
re.fullmatchand a two-literal concatenation are all offenders — two of the three convertedsites were written exactly that way, and the probe rows now include both
cli_spellings. Gaps namedplainly: (a)
event_collector_runtime.pyis declared, not converted, so the package still holds asecond compile of this body until feat(goal-channel): compose scoped claims and private reconnect context (#5198) #5248 lands; (b) the unfoldable layer keys on
app_id, so a modulethat builds this body from data without naming an
app_idfield would be reported as foldable — thedeclared-layer comment states that trade-off; (c) the TS side is untouched, and the Lark app id has no
TypeScript counterpart in this package, so no twin budget moves.
See validation disclosure guidance.
Frontend / Visual Evidence
Type of Change
fullmatch, so the anchors areredundant; the equivalence is asserted over boundary values rather than claimed
LoopX Area
Technical Direction
Shared-authority RFC fixture impact
N/A — no TypeScript control-plane migration or shared Goal Authority claim. No
.tsfile, noconformance fixture and no dual-runtime twin budget is touched by this diff.