Repository navigation
feat(agent): add deliverable batch orchestration - #112
Merged
Merged
Conversation
Qiyuanqiii
marked this pull request as ready for review
August 19, 2026 21:46
This was referenced Aug 19, 2026
8 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
摘要
batch-delivery.v1:将已经审批并 admission 的核心 child DAG 物化为最多两个可并行交付的 child,每个 child 使用独立 Git worktree、branch、generation lease、一次性 owner token 与缩小工具 profile。Closes #103.
协议、DAG 与缩权 child
batch-delivery.v1只消费现有协调器已经审批并 admission 的 core child proposal;Prepare 会重新加载并精确绑定同一 Run、Workspace、root Agent、proposal、DAG、预算和 expected artifacts,拒绝自环、循环、未知依赖、重复 task、超过两个 child、预算漂移和不规范所有权声明。每个 task 声明:
git_diff_check、go_test、npm_test中的显式验证集合;每个 child 获得独立 branch/worktree、base/head、随机 owner token、正数 generation、有限 lease 和
batch-delivery-workspace-tools.v1。明文 token 只在首次 Prepare 或 CAS rotation 响应中返回一次,SQLite 仅保存 digest;丢失 token 必须通过 expected-generation CAS 轮换,旧 generation 立即失效。工具矩阵固定为 owned Scope 内的:
list、read、glob、grep;create|patchproposal,以及复用 FileEdit 精确 hash/approval/apply 路径的写入;delete、rename/copy、Shell、任意 argv/process、network、credential、Debug、approval grant、远端 Git、PR 操作和继续派生 child 均不可用。原有 SpecialistRunner 仍保持 no-tool;本协议不会让任意 Specialist 隐式继承 root authority。
Worktree、Git 与提交收据
Prepare 只接受 clean、已提交、未漂移的 source base,并由 Go 创建和回读独立 worktree/branch。root、child 与 integration 必须属于同一个 canonical common Git directory;symlink、junction/reparse、大小写别名和跨仓库 worktree 均 fail closed。
Git 调用使用字面 argv、固定 author/email/message、关闭 hooks 与 attributes 外部路径,并拒绝本地 executable clean/smudge/process/diff/textconv/merge driver。commit 前先写入 durable intent;崩溃恢复只接受 prior HEAD 的一个直属、非 merge 提交,并重新证明 branch、parent、author、message、owned paths、无 delete/rename/copy 与 clean state,多提交或外部漂移保留现场并进入显式恢复路径。
ready_for_review收据包含:Submit 在验证前后各做一次完整 inspection,要求 branch/HEAD/diff/changed paths/clean state 完全相同;Store 提交收据时还原子复核当前 generation、未过期 lease、active child 状态和 Run 仍为 running。作者摘要或“完成”声明不构成证据。
邮箱、独立复核与有序合并
schema v118 持久化 plan、child workspace、generation mailbox、receipt、review、merge queue/step 和 operation facts。邮箱消息按 task/generation/sequence 排序,并对 operation digest 做 exactly-once;stale generation、越权 actor、非法前驱和重复 intent 均被 Go 与 SQLite 双重拒绝。
Reviewer 不读取作者摘要作为信任来源,而是从收据 head 重新计算 merge-base 完整 diff、调用链、changed paths 和 tests。接受还要求 Reviewer 分别确认 full diff、call chain 与 test evidence;验证完成后再次证明 exact Git state,任何漂移都返回 changes-requested 或 blocked。
Merge 使用独立 integration worktree/branch:
base 漂移不会自动重放,必须由操作者提供
confirm_replay;文本、语义或测试冲突不会自动选择任一方覆盖。结果仅是本地 integration branch/head,不 push、不创建远端 PR、也不合并远端分支。取消、失败隔离与启动恢复
needs_operator_attention;merge queue 每个副作用前和 Store terminal commit 时都重新检查当前 Run。宿主验证与进程边界
默认只允许不会执行仓库代码的
git diff --check。go_test/npm_test会运行 child-authored code,因此必须同时满足:full_access(或显式更高的debug)permission;--enable-batch-validation-execution均开启;--enable-batch-delivery-control。验证使用固定宿主可执行文件、Workspace 内 real cwd、去凭据/offline 环境、关闭 stdin;Go 使用
-count=1禁用 test cache,npm 通过固定 Node + npm-cli.js 启动。Windows 将完整后代绑定 kill-on-close Job Object;Unix 使用 inherited process group 并在所有返回路径回收。输出只以完整观察流 SHA-256、byte count 和有界 prefix digest 持久化,raw stdout/stderr 不进入 SQLite、DTO 或错误消息。这仍是显式
full_access宿主执行,不是 OS filesystem/network sandbox。POSIX 进程若主动 daemonize 并脱离 inherited process group,仍可能逃逸;需要可证明隔离时应使用独立容器边界,不能把 offline env 描述为 packet-level containment。HTTP、OpenAPI 与 Desktop
认证 API 新增:
GET 使用 read bearer;mutation 使用独立 control bearer、严格 JSON、duplicate/unknown-field 拒绝、有界 body 与 Run URL ownership 校验。Prepare/review/merge/cancel 使用
Idempotency-Key;owner renewal 使用 generation CAS;reconcile 本身收敛幂等。普通 DTO 不包含 child/integration root、owner-token digest、tool-profile fingerprint、operation/request fingerprint;raw owner token 只出现在一次性 authority 响应。Desktop/React 增加 Batch Delivery 投影、child/mailbox/receipt/review/merge 状态、显式 reviewer attestations、base replay 确认、cancel/reconcile 及中英诊断。Bootstrap/runtime capability 严格保持 Go 与前端一致:通用 control token 不会自动开放 Desktop batch control,宿主验证能力也不会仅因 batch control 存在而变 true。
生成后的 OpenAPI 为 124 paths / 138 operations / 325 schemas,TypeScript schema 已确定性重建。
主线兼容性
本分支直接基于当前
main495c27a(包含 PR #111 / schema v117 Workspace Checkpoints),本 PR 顺延为 schema v118 与 ADR 0119,不改写既有迁移历史。验收条件对应
本地验证
go test -p 2 -count=1 -timeout 30m ./...:全仓通过;internal/application422.773s、internal/httpapi138.928s、internal/store完整 v1-v118 迁移/恢复矩阵 1006.877s。go test -count=1 -timeout 10m ./internal/application -run '^TestBatchDelivery'通过(67.525s)。go test -race定向覆盖 Application 的真实 Git/权限漂移/独立复核/累积验证,以及 Store mailbox exactly-once、generation/lease/Run commit fencing。go test -count=1 -timeout 10m -tags 'desktop,wv2runtime.error' ./cmd/cyberagent-desktop ./internal/desktop ./internal/webui。go vet ./...、go mod verify、go mod tidy -diff。staticcheck -checks='SA*,S1*,QF*'覆盖全部受影响 Go 包;Desktop 使用完整desktop,wv2runtime.error平台标签。npm run check:api,并验证连续生成的 TypeScript schema 无漂移。npm run typecheck、完整npm test -- --reporter=dot(61 files / 251 tests)、npm run build。npm audit --audit-level=high:0 vulnerabilities。git diff --check、冲突标记、绝对本机路径、凭据形态与构建产物扫描。额外
govulncheck ./...如实报告本机 Go 1.26.5 标准库的 5 项可达已知问题(GO-2026-6218、GO-2026-6090、GO-2026-6089、GO-2026-5972、GO-2026-5026,均由 Go 1.26.6 修复);它们不是本次仓库依赖或代码引入,不能把该本机扫描描述为 zero finding。远端 CI
go vet与固定版govulncheck通过(Go control plane 18m45s);TypeScript 1m13s、Rust 1m03s、Windows Desktop 7m52s、macOS Desktop 2m37s。安全审计
提交前安全 diff 扫描发现 1 项 medium 与 6 项 low,均已修复并增加回归:
另补强 common Git repository identity、worktree link/reparse、npm scope、累积 validation contract 与 state-drift rollback fencing。没有提交 owner token、credential、原始验证输出、本地数据库、worktree 绝对路径或构建产物。
非目标与仍需人工证据
batch-delivery.v1产品能力。PR 暂保持 Draft。远端 Ubuntu/Windows/macOS/TypeScript/Rust/release 平台证据已闭环;合并前仍建议人工确认 Desktop 的 batch timeline、Reviewer 三项 attestation、base replay/blocked conflict 与 cancel/reconcile 交互。尚未取得的人工交互证据不会写成已完成。