Skip to content
Open
Show file tree
Hide file tree
Changes from 21 commits
Commits
Show all changes
28 commits
Select commit Hold shift + click to select a range
f8f4952
feat(explore): enforce scoped composition lineage and lifecycle evidence
LIHUA919 Sep 29, 2026
1a5f6f4
test(explore): qualify composition write gates across real entrypoints
LIHUA919 Sep 29, 2026
21a2d9d
docs(explore): document scoped lineage and no-spend retirement
LIHUA919 Sep 29, 2026
3bf0dbe
fix(explore): register completion evidence registry read
LIHUA919 Sep 29, 2026
758a141
Merge remote-tracking branch 'origin/main' into codex/explore-composi…
LIHUA919 Sep 29, 2026
14650fd
chore(validation): refresh integrated registry census coordinates
LIHUA919 Sep 29, 2026
85c7958
fix(explore): qualify execution against current live lineage
LIHUA919 Sep 29, 2026
8a16deb
test(explore): cover diagnostic history before bound execution
LIHUA919 Sep 29, 2026
1636697
docs(explore): reconcile implemented composition boundary
LIHUA919 Sep 29, 2026
20ce37d
Merge remote-tracking branch 'origin/main' into codex/explore-composi…
LIHUA919 Sep 29, 2026
862d31c
Merge latest main and refresh registry I/O census
LIHUA919 Sep 29, 2026
fed89c2
test: preserve admitted required-read commands in interaction smoke
LIHUA919 Sep 29, 2026
fdc2b80
test: track generated twins and turn-start hook projection
LIHUA919 Sep 30, 2026
4e3d77f
Merge latest main with release-book qualification
LIHUA919 Sep 30, 2026
3adb543
Merge latest main into M3 Explore PR
LIHUA919 Sep 30, 2026
6395df7
test(runtime): align source-read and disclosure fixtures
LIHUA919 Sep 30, 2026
5f9705d
test(coverage): exclude disposable probe checkout from shards
LIHUA919 Sep 30, 2026
d25d511
Merge origin/main into codex/explore-composition-write-gate
LIHUA919 Oct 1, 2026
4cb2bce
Merge latest main into research composition write gate
LIHUA919 Oct 2, 2026
d133416
Merge current main into research composition write gate
LIHUA919 Oct 3, 2026
272e222
Merge current main into research composition gate
LIHUA919 Oct 10, 2026
49b5433
Merge current main into research composition write gate
LIHUA919 Oct 10, 2026
29a381c
Merge current main with terminal lifecycle reentry
LIHUA919 Oct 10, 2026
37ec71e
Merge current main and preserve Explore legacy completion guard
LIHUA919 Oct 10, 2026
68b091d
Document legacy Explore guard dependency after Todo move
LIHUA919 Oct 10, 2026
013f43c
Merge current main into research composition write gate
LIHUA919 Oct 10, 2026
7ee8ba5
Merge commit '5f3ae2add3e0262b263199539e5acb0347ac68ef' into codex/ex…
LIHUA919 Oct 10, 2026
e6e94ee
Merge remote-tracking branch 'origin/main' into codex/explore-composi…
LIHUA919 Oct 11, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ const capabilityCopy: Record<WorkspaceLocale, Record<string, LocalizedCopy>> = {
},
explore_harness: {
displayName: "Explore Harness",
description: "Keeps an evidence graph of exploration, with optional branch planning. Planning includes evidence; worker permissions remain separate.",
description: "Keeps an exploration evidence graph with optional branch planning. Explicit composition replans require a bound experiment or typed result; worker permissions and task completion remain separate.",
},
lark_event_inbox: {
displayName: "Lark event inbox",
Expand Down Expand Up @@ -104,7 +104,7 @@ const capabilityCopy: Record<WorkspaceLocale, Record<string, LocalizedCopy>> = {
},
explore_harness: {
displayName: "探索 Harness",
description: "记录探索证据图谱,可选开启分支规划;规划自动配套证据层,派生 Agent 权限独立。",
description: "记录探索证据图谱,可选开启分支规划。显式组合的重新规划需绑定实验或类型化结果;派生 Agent 权限与任务完成独立判断。",
},
lark_event_inbox: {
displayName: "飞书事件收件箱",
Expand Down Expand Up @@ -167,6 +167,8 @@ const fieldCopy: Record<WorkspaceLocale, FieldCopy> = {
reasoning_effort: { label: "Child reasoning effort", description: "For example max; the host must support this model and effort." },
max_children: { label: "Maximum children", description: "Hard upper bound for concurrently delegated child work." },
profile: { label: "Planner profile", description: "Select one registered Explore Harness profile." },
composition_mode: { label: "Composition policy", description: "Replan requires an exact experiment successor or typed result; it grants no execution authority.", options: {disabled: "Off", explicit_only: "Explicit candidates"} },
composition_scope_id: { label: "Research coverage scope", description: "An opaque scope id required by the explicit-only composition policy." },
profile_preset: { label: "Report profile", description: "Capability-owned report profile, such as weekly-progress." },
wait_for_ci: { label: "Wait for CI", description: "Disable to use local validation without querying or waiting for CI. Merge authority is unchanged." },
review_order: { label: "Review direction", description: "Forward visits other authors first and oldest first. Reverse inverts the whole actionable queue." },
Expand Down Expand Up @@ -199,6 +201,8 @@ const fieldCopy: Record<WorkspaceLocale, FieldCopy> = {
reasoning_effort: { label: "子 Agent 推理档位", description: "例如 max;宿主须支持所选模型与档位。" },
max_children: { label: "最大子 Agent 数", description: "可同时委派的子任务硬上限。" },
profile: { label: "规划 Profile", description: "选择一个已注册的 Explore Harness profile。" },
composition_mode: { label: "组合策略", description: "重新规划需要精确的实验后继或类型化结果;它不授予执行权限。", options: {disabled: "关闭", explicit_only: "仅显式候选"} },
composition_scope_id: { label: "研究覆盖范围", description: "显式组合策略要求填写不含私有内容的范围标识。" },
profile_preset: { label: "报告 Profile", description: "由该能力管理的报告 profile,例如 weekly-progress。" },
wait_for_ci: { label: "等待 CI", description: "关闭后使用本地验证,不查询或等待 CI;不改变合并权限。" },
review_order: { label: "审阅方向", description: "正向先审其他作者,同层先审较早就绪的 PR;反向将整个可执行队列倒序。" },
Expand Down
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
import { useEffect, useMemo, useState } from "react";
import { useEffect, useLayoutEffect, useMemo, useState } from "react";
import { AlertTriangle, Code2, LoaderCircle, RefreshCw } from "lucide-react";

import {
Expand Down Expand Up @@ -72,7 +72,9 @@ function useCapabilityMutation({ goalId, onApplied, selected, t }: Readonly<{
? parseEditableCapabilityJson(selected.configuration_editor, jsonDraft) : null, [selected, jsonDraft]);
const jsonValid = editorMode === "guided" || parsedJson !== null;

useEffect(() => {
// Initialize the new capability's draft before it can receive input. A
// post-paint reset can otherwise erase the first toggle after selection.
useLayoutEffect(() => {
setEditorMode("guided");
setJsonDraft("");
const current = (selected?.capability_id === "pull_request_review" ? selected.effective_configuration?.configuration : selected?.current)
Expand Down
44 changes: 36 additions & 8 deletions docs/architecture/rfcs/research-exploration-control-plane-v0.md
Original file line number Diff line number Diff line change
Expand Up @@ -151,11 +151,11 @@ milestone status.

| Gap | Consequence |
|---|---|
| No shared research write-time gate | The cold evidence codec cannot discharge or enforce a live composition obligation. |
| No exact obligation/Todo/result lineage | A research receipt is not proof of an authorized Todo transition or accepted Goal closure. |
| Cold shadow not adopted by hot status/frontier | The existing #3173 projection remains behavior-compatible; canonical research obligations still need M3 integration. |
| No dismissal or deferral contract | Evidence invalidation is visible, but typed candidate retirement and resumption remain unimplemented. |
| No experiment-result adoption gate | Negative evidence can be recorded without proving that the next bound decision used its scope, validity or uncertainty. Proposed single-experiment integration is defined in §11.5; current cold receipts do not enforce it. |
| Mainline M3 write-time gate and exact lineage are not integrated | Open PR #5280 proposes an exact obligation/Todo/experiment/input gate. Its local receipt tests do not establish accepted Goal closure, and current-head CI, mergeability and maintainer effect acceptance remain open. |
| Cold shadow not adopted by hot status/frontier on main | The existing #3173 projection remains behavior-compatible; the proposed M3 consumer adoption still needs integrated entrypoint qualification. |
| Dismissal and deferral are not integrated | PR #5280 locally implements typed candidate dismissal, blocker waits and exact invalidated-duty retirement; review and mainline readback remain separate gates. |
| No experiment-result adoption gate | Negative evidence can be recorded without proving that the next bound decision used its scope, validity or uncertainty. Proposed single-experiment integration is defined in §11.5; current cold receipts and PR #5280 do not enforce it. |
| Execution attribution is not effect authority | An exact Todo/experiment/input receipt does not grant a task lease, effect permission or accepted Goal closure. |
| Live qualification incomplete | Deterministic and real CLI/file-log tests establish state semantics, not model selection quality or scientific truth; no live Lark sync is qualified by projection tests. |
| No promotion evidence for inferred combinations | Shared constraints are not known to be precise enough to trigger obligations. |

Expand Down Expand Up @@ -234,8 +234,9 @@ execution, and result into one ambiguous relation. This RFC rejects that shape.

The research envelope and closure basis have an active CLI caller and the
[versioned evidence protocol](../../reference/protocols/research-observation-v0.md).
The action signature, shared write gate and model selection below remain design
targets. The cold shadow does not promote them into current behavior.
The opt-in M3 development path implements exact execution lineage and shared
write gates and bounded retirement transitions. Model selection below
remain design targets; the cold shadow does not activate enforcement.

### 7.1 Compose; do not mutate v0 silently

Expand Down Expand Up @@ -919,7 +920,7 @@ control-plane failures.
| M0 | RFC, current-state inventory, and explicit ownership decision | Maintainer review; no runtime behavior | Accepted design |
| M1 | Characterization fixtures plus typed research observation and closure contract in Explore | Deterministic normalization, privacy, compatibility, and negative tests | Implemented evidence/CLI slice; live research qualification remains separate |
| M2 | Explicit-only composition candidate, canonical gap projection, and read-only status shadow | No pairwise inference; bounded packet; projection parity | Partial: #3173 legacy quota/successor; canonical binary cold shadow in CLI/Lark projection; hot status adoption and live Lark qualification remain |
| M3 | Goal-frontier obligation, exact Todo/experiment lineage, shared write-time gate; proposed §11.5 single-experiment result/adoption prerequisite | State/replay matrix, real provider/state readback, default-off parity and packaged journey before enforcement | Not started; §11.5 is a design proposal, not delivered runtime |
| M3 | Goal-frontier obligation, exact Todo/experiment lineage, shared write-time gate; proposed §11.5 single-experiment result/adoption prerequisite | State/replay matrix, real provider/state readback, default-off parity and packaged journey before enforcement | Proposed in open PR #5280, not integrated: local state/replay and premerge checks exist, while current-head CI, mainline conflict, public effect case and maintainer acceptance remain open. §11.5 is a design proposal, not delivered runtime |
| M4 | Bounded multi-candidate cards, `composition_selection_v0`, real model-tool behavior qualification, and repeated live shadow | Model autonomously selects a legal semantic action from the delivered candidate set; selection quality is no worse than the declared fallback; compact receipts only | Not started |
| M5 | Shared-constraint candidate ranking in shadow mode | Precision and cost evidence; no automatic trigger | Not started |
| M6 | Optional inferred trigger | Explicit maintainer decision and measured promotion thresholds | Deferred |
Expand Down Expand Up @@ -954,6 +955,33 @@ M3 is the first behavior-changing slice. It should be a separate PR so the
obligation and write gate can be reviewed and reverted independently from the
evidence schema.

The M3 development boundary joins current same-agent Todo, experiment and input
facts in the typed Explore owner. Goal policy is explicitly scoped and disabled
by default; the existing capability editor and CLI share its configuration
owner. Quota and refresh reuse one live frontier, with the original duty pinned
through scalar rollout fields and both receipt adapters. Real CLI tests reject
unrelated/deferred successors and invalidated writeback, then settle the original
Turn through its exact successor. File/SQLite tests distinguish canonical Todos
from stale display rows; packaged UI checks exercise policy preview, activation,
disable, readback and narrow screens. Native actor/lease and CAS admission remain in force; a fixed IO host
locks the graph while the typed owner qualifies and persists completion evidence.
Real File/SQLite and legacy tests cover missing evidence, direct IPC self-approval,
terminal-verb bypass, retained archive lineage and immutable completion replay.
Agent-scoped status, Explore and existing Lark Summary fields use the same live
facts. Typed candidate dismissal permits scoped terminal retirement; a fresh
canonical blocker and common Todo resume condition defer the gap without closing
it. Real CLI validates exact observed/dismissed/blocked progress source through
the original Turn, with independent File/SQLite lease-safe wait/resume evidence.
Invalidated input/scope/activation produces source-qualified retirement for the
original duty. Common readback retains its guard and historical debit, closes
that Turn without spend, and keeps the current frontier and runnable/paused work
visible. IO assembly stays in existing CLI/refresh composition roots; the shared
gate consumes supplied capability facts and the typed owner remains singular.
The local state/replay matrix and 19 standard risk-selected premerge checks pass.
Two existing scheduler ACK tests fail identically on the unchanged base under the
same local runtime; this is retained as a baseline limitation, not called green.
Maintainer-reviewed integration and independent live qualification remain.

## 17. Rejected Alternatives

### 17.1 Automatically pair nodes with a shared closure stage
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -132,11 +132,11 @@ hypothesis”或“新 probe family”。它无法持久表达:A 和 B 都已

| 缺口 | 后果 |
|---|---|
| 没有 shared research write-time gate | Cold evidence codec 不能解除或强制 live composition obligation。 |
| 没有精确 obligation/Todo/result lineage | Research receipt 不证明已授权 Todo transition 或已接受 Goal closure。 |
| Cold shadow 未接入 hot status/frontier | 既有 #3173 投影保持行为兼容;canonical research obligation 仍需 M3 集成。 |
| 没有 dismissal/deferral contract | Evidence invalidation 可见,但类型化 candidate retirement/resumption 尚未实现。 |
| 没有 experiment-result adoption gate | 负证据可被记录,但不能证明下一绑定决策使用了其 scope、validity 与 uncertainty。§11.5 提议 single-experiment 集成;当前 cold receipt 不强制执行该提案。 |
| Mainline 尚未集成 M3 写入门禁与精确 lineage | 开放的 PR #5280 提议精确 obligation/Todo/experiment/input 门禁;本地 receipt 测试不证明 Goal 已接受关闭,当前 head 的 CI、可合并性与维护者效果验收仍未完成。 |
| Cold shadow 尚未在 main 接入 hot status/frontier | 既有 #3173 投影保持行为兼容;提议中的 M3 消费端仍需集成后的入口资格验证。 |
| Dismissal 与 deferral 尚未集成 | PR #5280 在本地实现 typed candidate dismissal、blocker wait 与精确 invalidated-duty retirement;review 和主干回读仍是独立门槛。 |
| 尚无 experiment-result adoption gate | 负证据可被记录,但不能证明下一绑定决策使用了其 scope、validity 与 uncertainty。§11.5 提议 single-experiment 集成;当前 cold receipt 与 PR #5280 均未强制执行。 |
| 执行 attribution 不是 effect 权限 | 精确 Todo/experiment/input receipt 不授予 task lease、effect 权限或已接受的 Goal closure。 |
| Live qualification 不完整 | Deterministic 与真实 CLI/file-log 测试证明状态语义,不证明 model selection 质量或科学结论;projection 测试不构成 live Lark sync 资格。 |
| inferred combination 没有 promotion evidence | 共享 constraint 的精度还不足以直接触发 obligation。 |

Expand Down Expand Up @@ -211,8 +211,8 @@ A、B 之间的 `joint_probe` 直连边会把 candidate、execution 和 result

Research envelope 与 closure basis 已有真实 CLI caller 和
[版本化证据协议](../../reference/protocols/research-observation-v0.zh-CN.md)。
下文 action signature、shared write gate 和 model selection 仍为设计目标;
cold shadow 不会将其 promotion 为当前行为。
Opt-in M3 开发路径已实现精确 execution lineage 和共享 write gate。下文 model
selection 仍为设计目标;有界 retirement 已实现,cold shadow 不会激活门禁。

### 7.1 组合,而不是静默修改 v0

Expand Down Expand Up @@ -839,7 +839,7 @@ rule,以及 model variance 与 control-plane failure 的分离。
| M0 | RFC、current-state inventory 与显式 ownership decision | Maintainer review;无 runtime behavior | 已接受的设计 |
| M1 | Characterization fixture,以及 Explore 中的 typed research observation 与 closure contract | Deterministic normalization、privacy、compatibility 与 negative test | Evidence/CLI 切片已实现;真实研究 qualification 独立保留 |
| M2 | Explicit-only composition candidate、canonical gap projection 与 read-only status shadow | 不做 pairwise inference;packet 有界;projection parity | 部分实现:#3173 legacy quota/successor;CLI/Lark projection 的 canonical binary cold shadow;hot status adoption 与 live Lark qualification 仍未完成 |
| M3 | Goal-frontier obligation、精确 Todo/experiment lineage、共享 write-time gate;§11.5 提议 single-experiment result/adoption prerequisite | State/replay matrix、真实 provider/state readback、default-off parity;enforcement 前验证 packaged journey | 未开始;§11.5 是设计提案,不是已交付 runtime |
| M3 | Goal-frontier obligation、精确 Todo/experiment lineage、共享 write-time gate;§11.5 提议 single-experiment result/adoption prerequisite | State/replay matrix、真实 provider/state readback、default-off parity;enforcement 前验证 packaged journey | 开放 PR #5280 提案,尚未集成:已有本地 state/replay 与 premerge 检查,但当前 head 的 CI、主干冲突、公开效果案例与维护者验收仍未闭合。§11.5 是设计提案,不是已交付 runtime |
| M4 | 有界 multi-candidate card、`composition_selection_v0`、真实 model-tool behavior qualification 与重复 live shadow | 模型从交付 candidate set 中自主选择合法 semantic action;选择质量不劣于 declared fallback;只保留 compact receipt | 未开始 |
| M5 | Shared-constraint candidate 在 shadow mode 中排序 | 有 precision/cost evidence;不自动触发 | 未开始 |
| M6 | 可选 inferred trigger | 显式 maintainer decision 与量化 promotion threshold | 延后 |
Expand Down Expand Up @@ -872,6 +872,27 @@ milestone gap,不另建平行 task tree。
M3 是第一个 behavior-changing slice。它应单独成 PR,使 obligation 与 write gate
能够独立于 evidence schema 评审和回滚。

M3 开发边界在 typed Explore owner 中连接当前同一 Agent 的 Todo、experiment
和 input 事实。Goal policy 显式限定范围且默认关闭;既有能力编辑器与 CLI 共享
配置 owner。Quota 与 refresh 复用同一 live frontier,原 duty 通过 rollout 标量
字段和两端 receipt adapter 固定。真实 CLI 测试拒绝无关/延期 successor 与失效
writeback,再通过精确 successor 结算原 Turn。File/SQLite 测试区分 canonical
Todo 与陈旧显示行;打包 UI 验证策略预览、启用、关闭、读回和窄屏。Native actor/lease 与 CAS admission
仍强制执行;固定 IO host 锁定图,typed owner 校验并持久化 completion evidence。
真实 File/SQLite 与 legacy 测试覆盖缺少证据、direct IPC 自报 approval、terminal
verb 绕过、保留 archive lineage 和不可变 completion 回放。Agent 范围的 status、
Explore 与既有 Lark Summary 字段使用同一 live fact。Typed candidate dismissal
允许 scoped terminal retirement;新 canonical blocker 与通用 Todo resume condition
使 gap 暂缓,但不关闭。真实 CLI 通过原 Turn 校验 observed/dismissed/blocked 的
精确 progress source;File/SQLite 独立验证 lease-safe wait/resume。
输入/scope/activation 失效时,为原 duty 生成 source-qualified retirement。
通用 readback 保留原 guard 与历史 debit,无支出关闭该 Turn,同时保持当前
frontier 与 runnable/paused work 可见。IO 装配保留在既有 CLI/refresh composition
root;共享门禁消费传入的 capability fact,typed owner 始终只有一个。
本地 state/replay matrix 与 19 项 standard 风险验证通过。两个既有 scheduler ACK
测试在相同本地 runtime、未修改 base 上也以相同方式失败;保留为 baseline 限制,
不称为 green。Maintainer review 集成与独立 live qualification 仍未完成。

## 17. 被拒绝的替代方案

### 17.1 自动组合拥有共享 closure stage 的 node
Expand Down
Loading
Loading