Repository navigation
docs(platform): record trusted execution semantic contract R1 (#328) - #346
waterbro-8 wants to merge 1 commit into
Conversation
|
@PeterGuy326 奕舟,#327 / #328 的 R1 设计已经写成文档 PR,请你过 Gate D0(先不开发)。 整体路线:记忆分四层——源日志、链式 segment+head+索引、mem 里的 durable 派生记录、下一 turn 的逐条准入。FIFO 只管短窗,LRU 只管进程缓存,TTL 只管召回资格、不默默删源。多 Agent 用 branch head,禁止互相覆盖 checkpoint。验收看净 token 和质量,不看毛 prompt 缩短。 和 #328 的关系:327 管「带什么上下文」;328 管「对哪个业务对象做了什么、有没有 readback」。技术证明继续走 #302 GitHub ops;Sales Workbench 未承诺。 分仓(接受后再建子 issue):
PR:
本轮只有文档,没有运行时改动。 |
自验结果(文档 PR,对照 #328)本 PR 是纯文档 R1(ADR-0009 + CI:红,不能当绿
其余(ubuntu verify、macOS unpacked、两边 unsigned installer、CodeQL、Scorecard)是绿的。未在本地复现 Electron / Windows 冒烟。 对照 #328
合并
|
PeterGuy326
left a comment
There was a problem hiding this comment.
Request changes。
这是一份方向清楚的 R1/R2 设计稿,但当前还不能作为可信执行契约合并。
阻塞项:
- P1:ActionProposal 没有携带自身的 target digest/version;不变量和 idempotencyKey 明确依赖 targetDigest,且 target 变化必须使 proposal 失效,但示例的 proposal.target 只有 kind/locator,无法把审批绑定到具体 head。
- P1:approval 只有 approvalId 和 state=granted,没有 approver principal、proposal/target 绑定、授予/过期/撤销信息。canRun 要求有效 permission/approval;不补这些绑定,批准能力可能被跨 proposal/target 重放。
- P2:示例中的 sha256:1111、sha256:aaaa、sha:deadbeef 等与前面约定的 sha256: 不一致,也不是完整 SHA-256 值;请统一成合法示例或显式 placeholder。
另外,当前 head 的 Node 24 / macos-14 和 Unpacked staging smoke / Windows x64 仍失败,导致 Layout parity 被 skip;即使失败看起来与文档无关,也需要在当前 head 上重跑并恢复合并门禁。修订后请重新请求 review。
| "schemaVersion": "action-proposal.v1", | ||
| "proposalId": "ap_merge_12", | ||
| "intent": "squash_merge", | ||
| "target": { "kind": "github.pull_request", "locator": "github.com/bytefolk/roleweave/pull/12" }, |
There was a problem hiding this comment.
[P1] 把目标版本绑定进 ActionProposal。上面的不变量和校验函数依赖 targetDigest 来生成幂等键并在目标变化时失效,但 proposal 的 target 只有 kind/locator;外层 BusinessObjectRef 的 digest/targetVersion 没有成为 proposal 字段,也没有被 approval 或 idempotencyKey 引用。执行器因此无法证明批准的是当前 PR head。请在 action-proposal.v1 中显式携带 targetDigest/targetVersion,并将它绑定到 approval、幂等键和 receipt/readback。
| "head_sha_unchanged" | ||
| ], | ||
| "permissionScope": "contents:write", | ||
| "approval": { "required": true, "approvalId": "cap_merge_1", "state": "granted" }, |
There was a problem hiding this comment.
[P1] 把 approval 绑定到提案和授权主体。canRun 要求有效 permission/approval,但示例只有 approvalId 与 state,没有 approver principal、proposalId/targetDigest、授予时间、过期/撤销语义或 capability grant。这样一个 granted approval 可能被重放到另一个 proposal/target。请补齐字段并定义校验与失效规则。
| 见 ADR-0009 表格。附加字段约定: | ||
|
|
||
| - 所有 ref 带 `workspaceId`(或等价 scope)与 `asOf` 时间。 | ||
| - digest 使用 `sha256:<hex>`。 |
There was a problem hiding this comment.
[P2] 统一 digest 示例格式。后面的示例使用 sha256:1111、sha256:aaaa、sha:deadbeef,既不是完整 SHA-256,也和这里约定的 sha256: 不一致。请使用 64-hex 示例或显式标注 placeholder,否则实现/fixture 校验会遇到不一致的规范。
|
Cleanup after 胡奕舟 2026-09-19 09:21「你们的 pr 清理一下」。 R1 docs PR ( Closing as superseded. If ADR-0009 still needs to land as a separate doc, open a follow-up against current
|
Summary
Records the R1→R2 design decision for #328 without changing runtime behavior.
docs/design/trusted-execution-v1.md: example payloads (read-only analysis + squash-merge action), safety tests to add later, workbench trace, security/retention, pilot metrics.docs/design/workflow-handoff-v1.md.Do not implement #328 runtime until this decision is accepted.
Test plan