[codex] 完成 #766:插件依赖、执行归属与可选能力正交化 - #769
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
问题与结果
Fixes #766。
插件原来可以读取未声明服务,执行保护依赖业务作者手工取得 owner scope,UI 与具体工具包的变化还会牵动计算能力。本 PR 让依赖、执行、可选能力和持久业务选择各有明确合同:未声明读取失败;入口、事件和后台任务由框架保护真实 owner;卸载 UI 不会重建模型实例;旧 binding 使用当前兼容实现,不兼容明确失败。
按维护者要求做两项设计取舍:来源继续拥有各自的持久指针、准入和结算,共用 ReplyProgram 执行入口,不增加万能 Turn 控制器;消息日志与权限留在原 Core owner,宿主装配通过明确端口移出 Manager,不增加只包装宿主权限的插件。选择依据与 DSH 对照见
docs/design/issue-766-orthogonal-capabilities.md。本 PR 不包含 #750 的正式发布验收、#661 的真实 Mobile/Wake 压力验收、外部已安装插件换代、合并或部署。
Change intent
change_type: refactorsemantic_delta: breaking(扩展合同收紧;内置默认业务行为和持久数据格式保持)capability_owner: mixed;组合内核拥有依赖与执行接纳,业务插件拥有工具选择和 UI,安装控制器拥有 selection 与恢复。consumer_scope: Core 与内置插件;外部插件须迁移显式依赖和公共合同导入。runtime_patch: required;客户端不能保证服务端 activation、排空和资源寿命。authoritative_state_owner: MessageLog、原插件数据 owner、PluginSelection 保持。client_only_alternative: 不适用,问题位于服务端组合与生命周期。concept_gate: required;改变公共合同、依赖图与执行归属。protected_state: sessions.db、来源恢复指针、plugin-data、binding/归档、安装回退日志。改动范围
agent.plugins.host接收窄端口和实时事实,PluginUpdates 只依赖三方法安装端口。agent.plugin_contracts;ServiceKey 值类型改为不变型;删除重复声明,R6 守卫全部同名 key。python scripts/plugin_boundary.py catalog生成静态能力→提供→消费位置表。investigation_tools选工具并持久保存原选择;Reply 动态借用可选工具搜索展示。删除无消费者的旧工具包服务。investigation_tools,默认仍为 recall_memory、web_fetch;无数据库迁移,无 schema lineage 或最终 schema identity 变化。来源指针、消息、ModelsStore 路径不变。工具搜索展示合同升级为 v2,不提供 v1 shim。ad40a70ddbedd99db1e695eb4ba76c7e66eb3ab2;实现b58d6ba79ec17aa346f82b710e6a9df7c4c5822c。DSH 对照477b4f4205;无跨仓发布或 provider revision 变更。/mnt/data/coding/issue766-backup-20260925/base-ad40a70d.tar与before-completion.tar。代码回退不表示外部效果回滚。验证
pytest -q tests,41 passed。--check;前端npm run typecheck。inject=(TASKS,),没有新增测试或修改断言。正交性与概念完整性
b58d6ba79ec17aa346f82b710e6a9df7c4c5822c。工作手册