Skip to content

fix(managed-agent): #13163 follow-ups: cold-cache cancel and deferred review suggestions #13269

Description

@yiliang114

Follow-ups and delivery status for #13163, which addresses #13162 items 1–3. After multiple substantive review rounds, optional suggestions remain here under the AGENTS.md scope rule. The bounded cancellation fix and the remaining inherited ordering/recovery gaps are distinguished below.

1. Cold-cache cancellation: bounded fix delivered in #13163

The correction first delivered at 60030e4b0f9c and carried by merged head 52704a9de0c6 gives persisted, submitted cancellation its own attachment recovery, validates the frozen Session identity without mutable create grants, and passively reuses the original resident Harness connection. Independent H2 reproduction was red before the correction. The exact historical head 52704a9de0c6 passed the complete Java suite (562 entries: 561 executed passes, one Linux-only skip) and both macOS-executable real Hosted scenarios, including cancellation after Java cache loss with can_create revoked and the registry draining. This closes the cache-loss acceptance case that keeps the original Harness and Broker/worker alive. New API cancellation requests still require the creator's read grant; accepted cancellation continues retrying after subsequent read revocation.

After the required #13173 synchronization, parked passive recovery adopts the original Runtime and reads status without preparing/executing work. Repeated passive loads retain the owed cancellation lease until terminal success or teardown. The merged CLI session/recovery suites pass 205 tests; WebShell passes 61. The final merge preserves the concurrent automated update with all 1722 verification inputs unchanged. Exact original Runtime receiver identity is asserted in helper coverage; the route proves the serial repeated-load/cancel/release lifecycle. Concurrent load/cancel/close schedules remain optional follow-up coverage.

Previous synchronized delivery b27a5958a16e preserves concurrent cleanup f8e83fc7707e and main through 5ddfacc9d4c1. Build/typecheck and 91 focused synchronization tests passed; the 30 Java tests recompiled 94 production and 104 test sources, including the retained main non-Broker rename-retirement case. The current verification report separates these results from the earlier full suite.

Current-head SDK Java CI has now completed successfully. The run records PR head b27a5958a16e; both database jobs checked out merge 707910c9904b, whose parents are exactly this head and main 5ddfacc9d4c1. Managed Agent ran 561 unit tests and 52 non-Hosted database integration tests. The Hosted MySQL JUnit reports contain 18 executed scenarios across all seven expected classes, including all four public-Workspace scenarios; the updated cold-cache cancellation and separate generation/storage refusal assertions are in the executed files scenario. These counts have zero failures, errors or skips. Broker fault gates (44 tests), O4 MySQL gates (40 tests), latency checks and all three owner-failover E2E steps also passed. This is current Linux CI evidence, separate from the historical local H2 results; it does not expand the recovery or physical-tool interruption guarantee.

The historical WebShell Smoke job also completed successfully, checking out exact head b27a5958a16e. The transcript browser gate passed six tests. Of 208 Playwright cases, 207 passed on their first attempt and one mobile-WebKit /btw drawer case passed on configured retry, with zero final failures. Its first attempt expected the side-question menu item to disappear after selecting Shell mode. The test, mock daemon, Add menu, editor and ordinary Session route are byte-identical to main; the root cause is not established. The retry is retained in the verification record.

Remaining recovery boundary: this evidence does not establish Broker/worker process-death adoption, or an original prompt admission whose reply was lost before its event epoch was saved. The latter path can still attempt submission and be refused by new-work authority. It needs separate fenced recovery/cancellation coverage; do not treat the cold-cache result as resolving every restart/takeover case. #13083 and #13054 remain their own recovery work.

Completed suggestions in the same correction: R1-2 now independently varies storage and generation; removing only the storage comparison makes the new test fail (2 tests, 1 failure, 0 errors), and restoration passes. R1-3 now exercises those variants through the real Hosted integration; local H2 passed, and the current Hosted MySQL CI run passed the same updated scenario as recorded above. R1-17 now explicitly states that workspaceTurns advertises submit/rename authority, with cancellation under its separate rule; the generated mirror and equality test are synchronized.

2. Review suggestion status

Tests that cannot fail: R1-9 (HarnessCoordinator.java:158), R1-12 (ManagedWorkspaceAdmissionTest.java:1149), R1-14 (HostedPublicWorkspaceIT.java:325), R2-2 (HostedPublicWorkspaceIT.java:166), R2-5 (ManagedWorkspaceAdmissionTest.java:799), R2-9 (RuntimeHarnessDrainTest.java:282). Each assertion or guard passes with the clause it is meant to pin removed. Tighten each so it goes red under the named mutation.
Missing coverage: R1-3 (HostedPublicWorkspaceIT.java:346), R1-11 (HostedPublicWorkspaceIT.java:319). R1-3 is addressed by the real Hosted generation/storage scenarios described above. R1-11 diagnostics remain optional follow-up work.
Dead code and duplication: R2-3 (ApiModels.java:93), R2-4 (ManagedWorkspaceRegistry.java:52), R2-6 (ManagedWorkspaceAdmissionTest.java:1273). Completed in preserved concurrent head f8e83fc7707e: the unused constructors and wrapper are removed, and this PR's duplicate rename-retirement test is deleted while main's existing test remains. Both exceptions reach the same retirement branch in the same store state. Current test compilation and the retained main regression passed in the 30-test focused Java run; no behavior was added.
Published wording: R2-7 (managed-agent-public-api.openapi.json:5185), R2-10 (README.md:196). Align the contract and README sentences with what the code enforces.
Cost: R1-6 (ManagedAgentService.java:626). maySubmitWorkspaceTurn runs three JDBC round trips per row of the WebShell session list.

The inherited Harness wedge from @wenshao's round-2 verification is tracked in #13054 and is not repeated here.

3. Late rename may leave the private Harness title stale

Review discussion. Independent real service/H2 reproduction used a stateful Harness fixture and a deterministic held-call schedule: K1 renames to A; a same-key sibling fails and retires K1; fresh K2 completes B; releasing the original K1 writes A at the Harness, then returns 409 session_mutation_superseded from SQL. Final state: public SQL title B, private Harness title A. The probe ran 1 test, 1 failed equality assertion, 0 errors; it did not run live Hosted transport.

The duplicate delivery, sibling retirement and external-write-before-SQL-completion already exist at the PR base ba09794545. #13163 adds a useful SQL completion guard, but it cannot fence the earlier external side effect. README and both design languages now restrict that guarantee to the public SQL title and receipt. The temporary red regression was archived and removed from the shipped passing suite.

Acceptance: concurrent same-key delivery, failure, fresh-key success and delayed older completion must leave public and private persisted titles consistent. A transport variant must cover an accepted remote write finishing after client timeout. The ordering decision belongs at the final durable Harness write and must preserve an explicitly chosen same-key retry contract across server replicas; a process-local lock or an after-the-fact SQL check does not establish it.

4. Owner-assignment workflow checkout failure — resolved

The post-push owner-assignment job fails before running the assignment script. Its checkout uses base commit 2a6879e648e1, supplies three file paths and leaves cone-mode sparse checkout enabled; Git refuses the first path because it is not a directory. This was a base-workflow checkout configuration failure, not a product-test result from #13163. Upstream #13306 fixes cone-mode checkout and #13310 uses the REST assignees endpoint; both are included in b27a5958a16e. The new synchronization job completed successfully: its log checks out trusted base 5ddfacc9d4c1, invokes the assignment script, and deliberately reports Assignment: skipped — no area path matched. No new assignee is claimed. Managed Agent database CI has now passed. WebShell Smoke has also passed (207 first-attempt passes plus one retry pass); two fresh review approvals remain pending.

5. Round-4 non-blocking follow-ups

R4-1 is fixed in a18ea0e42249: early acquisition notification keeps the exact Runtime identity reachable during final-authorization refusal or exception, so resident retirement releases it. It is not deferred. This repair lands only the verified Critical; the remaining Suggestions below stay here.

Discussion Remaining work
R4-2 Overlapping passive loads of one resident Session are not serialized by opening; evaluate the current contract before adding state.
R4-3 Lease retention now has discriminating R4-1 tests and a failing mutation; the recovery-report identity/checkpoint/activation validation assertions remain to be strengthened.
R4-4 The resident recovery catch still discards the original failure cause; the new owed-identity diagnostic does not replace that cause.
R4-5 Default cold submit/action/continue paths can repeat Workspace authorization SQL; evaluate the duplicated admission cost.
R4-6 Cold-cancel regression needs assertions discriminating pending recovery and the recovered snapshot, rather than construction-only checks.
R4-7 opt-in Decouple deployment opt-in from connector availability in the guard test; this overlaps R1-12.
R4-7 storage guard Reach authorizeCancellation with the storage guard enabled and prove cancellation independently of current mount readiness. The held-model/H2 UI run does not provide this oracle.

6. Current-head local verification intermittency

Conflict merge 762f4a2d2b83 is MERGEABLE; build/typecheck and targeted style checks pass. Fresh Java verification passes 127 cases and Checkstyle/SpotBugs, with Java/manifest inputs byte-identical to this head. The independent complete CLI run is retained as exit 1: 213 of 219 passed, six failed, no skips or unhandled errors. All six R4-1 lease cases, four main lost-reply redrive cases and live resident identity/profile negatives passed.

The six failures were four pre-model Hook waiting variants (three also hit ENOTEMPTY during cleanup), unknown Hook fence reload=true (ENOENT during writer release), and takeover cancel admission when detached (cold-load 401). They occur before the changed resident branch. One bounded, original-source reproduction of the three families passed all 23 selected cases, including the six failed variants; 171 were deliberately filtered. No assertion or waiting budget changed. This establishes intermittency, not its cause or a green full run.

Remaining work: capture timing/terminal state during the Hook waits, ensure owner writes finish before deleting fixture storage, and capture the unexpected cold-load response body/listener identity. The untracked replacement listener and short default waits are hypotheses, not proven causes. With nine substantive review rounds and no verified defect in this merge increment, further test-lifecycle diagnosis is deferred here. No speculative timeout or production fix was landed. Historical full/native/UI/CI results elsewhere in this issue retain their named heads.

7. round-2026-10-07 suggestion batch deferred from #13163

The review lane's account changed, so its 2026-10-07 round restarted finding numbering at R1-*. Those ids collide with the R1-*/R2-*/R4-* ids in sections 2 and 5 above and are unrelated findings — cite this batch by discussion link, never by id. All 21 are Suggestion-severity; the same round's three Criticals were fixed on the PR and are not listed here. Each thread carries an individual reply stating the reason, and each was resolved as deferral recorded, not as fixed. Head at deferral time: f2864f6a1d.

sdk-java — no JDK 21 / Maven / ~/.m2 on the editing host, so the fix cannot be compiled or run where it is written; CI's SDK Java lane is the only oracle

Discussion Location Remaining work
R1-8 sdk-java/managed-agent-server/src/main/java/com/alibaba/qwen/code/managedagent/service/ManagedAgentService.java:228 Thread the SessionRecord that requireReadableSession already returns into requireBoundCreator/requireSubmitter instead of re-reading it (submitTurn 3→8 round-trips, renameSession 7→9).
R1-34 sdk-java/managed-agent-server/src/main/java/com/alibaba/qwen/code/managedagent/service/ManagedAgentService.java:912 Give the singular and batch maySubmitWorkspaceTurn twins one shared binding-stamp predicate; today one answers in SQL and the other in Java and nothing enforces the parity the comment claims.
R1-10 sdk-java/managed-agent-server/src/main/java/com/alibaba/qwen/code/managedagent/store/WorkspaceExecutionStore.java:93 Split authorizeAttachment's two interleaved ternary SQL statements into named constants so the parenthesisation stops being load-bearing and the fold is compile-time again.
R1-35 sdk-java/managed-agent-server/src/main/java/com/alibaba/qwen/code/managedagent/store/WorkspaceExecutionStore.java:129 Re-indent the ternary's false-branch conjuncts in the row mapper so the cancellation branch's exemption from can_create is visible without matching a paren across twelve lines.
R1-18 sdk-java/managed-agent-server/src/test/java/com/alibaba/qwen/code/managedagent/ManagedSessionLifecycleTest.java:538 Add service/HTTP-tier coverage for session_mutation_superseded propagation, so reordering the ApiException re-throw after the catch-all cannot silently turn a documented 409 into a retryable 503.
R1-20 sdk-java/managed-agent-server/src/main/java/com/alibaba/qwen/code/managedagent/service/ManagedAgentService.java:263 Apply the diff's own keyed-mutation rule to cancelTurn: answer the same-key replay before requireCanceller, which currently conjoins identity terms with the state term.
R1-23 sdk-java/managed-agent-server/src/main/java/com/alibaba/qwen/code/managedagent/harness/QwenHostedHarnessConnector.java:450 Reduce requireReadyForNewWork's cost (0→6 queries by default, 12 cold with the caller's repeat), charged per approval delivery against a 1s rescan; terminalizing the refusal does not address it.
R1-26 sdk-java/managed-agent-server/src/test/java/com/alibaba/qwen/code/managedagent/ManagedWorkspaceAdmissionTest.java:1207 Make the re-registration test discriminate the submit leg, whose command row is written 'COMPLETED', not only the rename leg's 'PENDING'.
R1-27 sdk-java/managed-agent-server/src/test/java/com/alibaba/qwen/code/managedagent/harness/QwenHostedHarnessConnectorTest.java:344 The @ValueSource(booleans) parameterization changes a stub nothing reads, so both arms run identical code; also give the default configuration some resolveAction coverage.

published contract surface — the change is a maintainer decision, not a review fix

Discussion Location Remaining work
R1-17 sdk-java/managed-agent-server/src/main/resources/openapi/managed-agent-public-api.openapi.json:5067 Move info.version and add a version-history entry: the diff tightens the WebShellSessionCapabilities required list and narrows workspaceTurns while the contract still reads 1.33.0.
R1-31 sdk-java/managed-agent-server/src/main/resources/openapi/managed-agent-public-api.openapi.json:5096 Fix the schema-property description at :5096, the one that ships in the generated SDK, to match :207/:1212 and the code (renameSession ends at requireSubmitter).
R1-6 web-shell/client/components/managed/java-managed-agent-provider.ts:301 canCancel lost its only server-published discriminator; publish a cancel/creator term on WebShellSessionCapabilities so a revoked creator is distinguishable from a never-authorized reader.

packages/cli/src/serve/hosted-harness-session.ts — production edits deferred because the file is under concurrent edit on the branch; R1-14 is the one worth picking up first

Discussion Location Remaining work
R1-14 cli/src/serve/hosted-harness-session.ts:2157 Bind cause and write a stderr line in the cancellation-reattach catch, mirroring the two siblings added in the same diff; today an environmental failure there is an unbounded silent retry.
R1-7 cli/src/serve/hosted-harness-session.ts:2123 Substitute the shared matchesRecovery predicate for the hand-inlined three-clause negation on the load path.
R1-22 cli/src/serve/hosted-harness-session.ts:2078 Add coverage for a hooks-owning Session on the passive resident load path; the case added since sits in the no-tool block and would not notice a revert of the if (parked) scoping.
R1-29 cli/src/serve/hosted-harness-session.test.ts:9015 Drain refusedAdoptions on the close path too, or correct the field doc: a refuse-then-close Session keeps its entry for the daemon's lifetime and suppresses every later stays owed line.

test quality — assertions that stay green under the mutation they exist to catch

Discussion Location Remaining work
R1-3 cli/src/serve/hosted-harness-session.test.ts:9249 The waitFor(toHaveBeenCalledOnce) in the stranded-drive-redrive test is already satisfied by loadReplacement(), so the DELETE races the redrive; wait on a count the redrive itself moves.
R1-12 cli/src/serve/hosted-harness-session.test.ts:7733 Assert the Session Store writer was not reopened via the existing-but-unused state.storeOptions instrument, which the test's own name and the design doc promise.
R1-21 cli/src/serve/hosted-harness-session.test.ts:9284 Constrain the authorization spy in the cold-adoption test as its resident sibling does, so an added gating call cannot relocate the failFinalAuthorization injection.
R1-28 cli/src/serve/hosted-harness-session.test.ts:8952 Pin the three identity comparisons of the resident-passive guard; every current test only exercises the !recovery term, so deleting any of them stays green.
R1-33 web-shell/client/components/managed/ManagedSessionsPage.test.tsx:920 Assert the standalone Cancel control's absence, not only its presence: click() ends in expect(button).toBeDefined(), so it can never detect an unexpected button.
中文说明

#13163(处理 #13162 第 1–3 项)的后续及交付状态。经过多轮实质评审后,可选建议按 AGENTS.md 的范围规则继续记录于此。下文区分已交付的有限取消修复和剩余的继承排序/恢复缺口。

1. 冷缓存取消:#13163 已交付有明确边界的修复

初次交付 60030e4b0f9c、此前合并 head 52704a9de0c6 为已持久化、已提交的取消提供专用挂接恢复,校验冻结的会话身份,不依赖可变的创建授权,并被动复用原始驻留 Harness 连接。独立 H2 复现在修复前变红;该历史版本的 562 项 Java 入口中 561 项执行通过、1 项 Linux 专属跳过;macOS 可运行的两项真实 Hosted 场景通过,包括 Java 缓存丢失、can_create 撤销且 registry drain 后的取消。这解决保持原 Harness 与 Broker/worker 存活的缓存丢失验收场景。新的 API 取消请求仍要求创建者读取授权,已受理取消在之后失去读取权限时继续重试。

同步 #13173 后,停驻的被动恢复认领原 Runtime、读取状态,不准备或执行工作;重复被动 load 保留取消路径待归还的租约,直到终态成功或拆除。合并版 CLI 会话/恢复 205 项、WebShell 61 项通过;最终合并保留并发自动更新,1722 个验证输入未变。helper 覆盖已断言原 Runtime 接收者身份,路由证明串行重复 load/cancel/release 生命周期;并发 load/cancel/close 调度仍作为可选后续覆盖。

此前同步交付 b27a5958a16e 保留并发清理 f8e83fc7707e,并包含 main 至 5ddfacc9d4c1。build/typecheck 与 91 项针对性同步测试通过;其中 30 项 Java 回归重编译全部 94 个生产和 104 个测试源码,并实际执行保留的 main 非 Broker 改名退役用例。此前验证报告 区分本轮与此前全量结果。

此前 head b27a5958a16e 的 SDK Java CI 已成功完成。该运行记录 PR head b27a5958a16e;两个数据库任务均检出 merge 707910c9904b,其父提交正是该 head 与 main 5ddfacc9d4c1。Managed Agent 执行 561 项单测、52 项非 Hosted 数据库集成测试;Hosted MySQL 的 JUnit 报告包含全部 7 个预期测试类的 18 项已执行场景,其中公开 Workspace 的 4 项全部执行,文件场景包含更新后的冷缓存取消及独立 generation/storage 拒绝断言。这些计数均为零失败、零错误、零跳过。Broker 故障通道 44 项、O4 MySQL 通道 40 项、延迟检查与 3 个 owner failover E2E 步骤也通过。这是当前 Linux CI 证据,与历史本地 H2 结果分开记录,不扩大恢复或物理工具中断的保证。

此前 head b27a5958a16e 的 WebShell Smoke 任务 也已成功完成,检出精确 head b27a5958a16e。Transcript 浏览器检查 6 项通过;208 项 Playwright 用例中,207 项首轮通过,1 项 mobile-WebKit /btw 抽屉用例在配置重试后通过,最终零失败。该用例首轮在切换 Shell mode 后仍看到侧问菜单项。相关测试、mock daemon、Add 菜单、编辑器与普通 Session 路由均与 main 字节一致,根因尚未确定,验收记录保留此次重试。

剩余恢复边界: 这些证据不证明 Broker/worker 进程死亡后的接管,也不解决原始 prompt 准入回复丢失、event epoch 尚未保存的场景。后一路径仍可能尝试提交,并被新工作授权拒绝,需要单独的 fenced 恢复与取消覆盖。不能把冷缓存结果推广为所有重启/接管情况均已解决;#13083 与 #13054 仍独立推进。

本次同时完成的建议: R1-2 现在独立改变 storage 和 generation;只删除 storage 比较后测试失败(2 tests、1 failure、0 errors),恢复后通过。R1-3 已在真实 Hosted 集成中覆盖这些变体,本地 H2 通过,当前 Hosted MySQL CI 也已通过同一项更新后的场景,见上文。R1-17 明确 workspaceTurns 表示提交/改名授权,取消遵循独立规则,生成镜像与逐字节一致性测试同步通过。

2. 评审建议状态

测试无法失败: R1-9 (HarnessCoordinator.java:158)、R1-12 (ManagedWorkspaceAdmissionTest.java:1149)、R1-14 (HostedPublicWorkspaceIT.java:325)、R2-2 (HostedPublicWorkspaceIT.java:166)、R2-5 (ManagedWorkspaceAdmissionTest.java:799)、R2-9 (RuntimeHarnessDrainTest.java:282)。每个断言或守卫在去掉其要钉住的条件后仍然通过。逐条收紧,使其在对应变异下失败。
缺少覆盖: R1-3 (HostedPublicWorkspaceIT.java:346)、R1-11 (HostedPublicWorkspaceIT.java:319)。R1-3 已由上文真实 Hosted generation/storage 场景处理;R1-11 诊断增强继续作为可选后续。
死代码与重复: R2-3 (ApiModels.java:93)、R2-4 (ManagedWorkspaceRegistry.java:52)、R2-6 (ManagedWorkspaceAdmissionTest.java:1273)。保留的并发 head f8e83fc7707e 已删除未使用构造器、wrapper 和本 PR 新增的重复改名退役测试,保留 main 既有测试。两类异常在相同存储状态到达同一退役分支;当前 30 项针对性 Java 验证通过全部测试编译,并实际执行保留的 main 用例,未新增行为。
对外措辞: R2-7 (managed-agent-public-api.openapi.json:5185)、R2-10 (README.md:196)。让契约与 README 中的语句与代码实际执行的规则一致。
开销: R1-6 (ManagedAgentService.java:626)。maySubmitWorkspaceTurn 在 WebShell 会话列表的每一行上执行三次 JDBC 往返。

@wenshao 第 2 轮验证中提到的继承自 main 的 Harness 卡住问题由 #13054 跟踪,此处不再重复。

3. 晚到改名可能使私有 Harness 标题过期

评审讨论。独立的真实 service/H2 复现使用有状态 Harness 夹具与确定的挂起调用:K1 改为 A,同 key 的兄弟请求失败并退役 K1,新的 K2 完成 B,最后释放原 K1,在 Harness 写入 A 后才由 SQL 返回 409 session_mutation_superseded。最终公开 SQL 标题为 B,私有 Harness 标题为 A。Probe 运行 1 项测试、1 个相等断言失败、0 errors,未使用真实 Hosted 传输。

重复投递、兄弟请求退役及先外部写入后完成 SQL 的流程在 PR 基线 ba09794545 已存在。#13163 新增的 SQL 完成 guard 有效,但无法 fence 更早发生的外部副作用。README 与双语设计现已把保证限定为公开 SQL 标题和回执。临时红回归已归档,并从交付的绿色测试套件撤回。

验收: 同 key 并发投递、失败、新 key 成功与旧请求延迟完成后,公开与私有持久标题必须一致。传输层变体必须覆盖客户端超时后,已受理的远端写入仍晚到完成的情况。排序决策应在 Harness 最终持久写入处生效,并跨服务副本保留明确选择的同 key 重试契约;进程内锁或事后的 SQL 检查不能证明这一点。

4. 自动 owner 分配任务的 checkout 失败——已解决

推送后的 owner 分配任务 在执行分配脚本前失败。checkout 使用 base 2a6879e648e1,提供三个单文件路径却保留 cone-mode sparse checkout,Git 因首个路径不是目录而拒绝。这是任务所用 base workflow 的 checkout 配置失败,不是 #13163 的产品测试结果。上游 #13306 修复 cone-mode checkout,#13310 改用 REST assignees 接口,均已包含于 b27a5958a16e。新的同步任务 成功;日志确认 checkout 到可信 base 5ddfacc9d4c1,执行分配脚本后按规则输出 Assignment: skipped — no area path matched,不宣称新增 assignee。Managed Agent 数据库 CI 已通过;WebShell Smoke 也已通过(207 项首轮、1 项重试);两个新的批准仍待完成。

5. 第四轮非阻塞后续

R4-1 已在 a18ea0e42249 修复:认领后提前记录 Runtime 精确身份,最终授权拒绝或抛错时仍可由驻留 Session 退役释放,不将其延期。本轮仅落已核实 Critical;其余 Suggestion 在此跟踪。

讨论 剩余工作
R4-2 同一驻留 Session 的重叠被动加载没有 opening 串行化;增加状态前先确认契约。
R4-3 租约记录已由 R4-1 的回归及变异验证覆盖;恢复报告的身份、checkpoint、activation 校验仍需具有判别力的断言。
R4-4 驻留恢复 catch 仍丢失原始原因;新增待归还身份诊断不等同于记录错误原因。
R4-5 默认部署的冷 submit/action/continue 路径可能重复 Workspace 授权 SQL,需评估重复准入开销。
R4-6 冷缓存取消测试需要区分 pending recovery 与恢复快照,而非仅断言构造固定值。
R4-7 opt-in guard 测试需解耦部署 opt-in 与 connector 可用性,与 R1-12 重叠。
R4-7 storage guard 启用 storage guard 后实际走到取消授权,验证取消独立于当前挂载可用性;本次挂起模型/H2 UI 回归不提供该判别。

6. 当前 head 本地验证的间歇失败

冲突合并 762f4a2d2b83 已为 MERGEABLE;build/typecheck、针对性格式及 lint 检查通过。新跑 Java 127 项与 Checkstyle/SpotBugs 通过,Java/依赖清单输入与当前 head 相同。独立完整 CLI 运行保留为 exit 1:219 项中 213 项通过、6 项失败,零跳过、无未处理错误;六项 R4-1 租约、四项主线丢失回复 redrive 与驻留身份/profile 负例均实际通过。

六失败是四个 pre-model Hook 等待变体(其中三个清理时也出现 ENOTEMPTY)、unknown Hook fence reload=true(writer release 时 ENOENT),以及 detached 时接管 cancel 的冷加载 401,均在变更的驻留分支前发生。保持原源码、断言和等待预算,只做一次有界原始复现:23 项全通过,包含原六个失败变体,171 项主动过滤。它证明间歇性,不证明根因,也不将完整运行称为绿色。

后续需要采集 Hook 等待的时序/终态、确保 owner 写入结束后再删除夹具目录,并保存冷加载异常响应正文及监听身份。未登记的恢复监听器和短默认等待仅是假设。PR 已经过九轮实质评审,本次合并没有已确认缺陷,测试生命周期诊断在此延期;未落猜测性的超时或生产修复。本文其他全量/native/UI/CI 结果仍归属于各自标注的历史 head。

7. 2026-10-07 从 #13163 延期的一批建议

评审 lane 换了账号,其 2026-10-07 那一轮的编号从 R1-* 重新开始。这些 id 与上文第 2、5 节的 R1-*/R2-*/R4-* 撞号,且是完全不同的 finding —— 引用本批只能按 discussion 链接,不要按 id。21 条全部为 Suggestion 级;同一轮的 3 条 Critical 已在 PR 上修复,不在此列。每条线程都有单独的回复说明理由,且 resolve 的含义是**「已记录延期」而非「已修复」**。延期时的 head:f2864f6a1d。

sdk-java —— 编辑所在主机没有 JDK 21 / Maven / ~/.m2,写出来的改动无法就地编译或运行;CI 的 SDK Java lane 是唯一的验证手段

Discussion Location Remaining work
R1-8 sdk-java/managed-agent-server/src/main/java/com/alibaba/qwen/code/managedagent/service/ManagedAgentService.java:228 Thread the SessionRecord that requireReadableSession already returns into requireBoundCreator/requireSubmitter instead of re-reading it (submitTurn 3→8 round-trips, renameSession 7→9).
R1-34 sdk-java/managed-agent-server/src/main/java/com/alibaba/qwen/code/managedagent/service/ManagedAgentService.java:912 Give the singular and batch maySubmitWorkspaceTurn twins one shared binding-stamp predicate; today one answers in SQL and the other in Java and nothing enforces the parity the comment claims.
R1-10 sdk-java/managed-agent-server/src/main/java/com/alibaba/qwen/code/managedagent/store/WorkspaceExecutionStore.java:93 Split authorizeAttachment's two interleaved ternary SQL statements into named constants so the parenthesisation stops being load-bearing and the fold is compile-time again.
R1-35 sdk-java/managed-agent-server/src/main/java/com/alibaba/qwen/code/managedagent/store/WorkspaceExecutionStore.java:129 Re-indent the ternary's false-branch conjuncts in the row mapper so the cancellation branch's exemption from can_create is visible without matching a paren across twelve lines.
R1-18 sdk-java/managed-agent-server/src/test/java/com/alibaba/qwen/code/managedagent/ManagedSessionLifecycleTest.java:538 Add service/HTTP-tier coverage for session_mutation_superseded propagation, so reordering the ApiException re-throw after the catch-all cannot silently turn a documented 409 into a retryable 503.
R1-20 sdk-java/managed-agent-server/src/main/java/com/alibaba/qwen/code/managedagent/service/ManagedAgentService.java:263 Apply the diff's own keyed-mutation rule to cancelTurn: answer the same-key replay before requireCanceller, which currently conjoins identity terms with the state term.
R1-23 sdk-java/managed-agent-server/src/main/java/com/alibaba/qwen/code/managedagent/harness/QwenHostedHarnessConnector.java:450 Reduce requireReadyForNewWork's cost (0→6 queries by default, 12 cold with the caller's repeat), charged per approval delivery against a 1s rescan; terminalizing the refusal does not address it.
R1-26 sdk-java/managed-agent-server/src/test/java/com/alibaba/qwen/code/managedagent/ManagedWorkspaceAdmissionTest.java:1207 Make the re-registration test discriminate the submit leg, whose command row is written 'COMPLETED', not only the rename leg's 'PENDING'.
R1-27 sdk-java/managed-agent-server/src/test/java/com/alibaba/qwen/code/managedagent/harness/QwenHostedHarnessConnectorTest.java:344 The @ValueSource(booleans) parameterization changes a stub nothing reads, so both arms run identical code; also give the default configuration some resolveAction coverage.

已发布契约面 —— 属维护者裁决,不是评审修复

Discussion Location Remaining work
R1-17 sdk-java/managed-agent-server/src/main/resources/openapi/managed-agent-public-api.openapi.json:5067 Move info.version and add a version-history entry: the diff tightens the WebShellSessionCapabilities required list and narrows workspaceTurns while the contract still reads 1.33.0.
R1-31 sdk-java/managed-agent-server/src/main/resources/openapi/managed-agent-public-api.openapi.json:5096 Fix the schema-property description at :5096, the one that ships in the generated SDK, to match :207/:1212 and the code (renameSession ends at requireSubmitter).
R1-6 web-shell/client/components/managed/java-managed-agent-provider.ts:301 canCancel lost its only server-published discriminator; publish a cancel/creator term on WebShellSessionCapabilities so a revoked creator is distinguishable from a never-authorized reader.

packages/cli/src/serve/hosted-harness-session.ts —— 该文件正被并发编辑,故生产改动延期;其中 R1-14 最值得优先捡起

Discussion Location Remaining work
R1-14 cli/src/serve/hosted-harness-session.ts:2157 Bind cause and write a stderr line in the cancellation-reattach catch, mirroring the two siblings added in the same diff; today an environmental failure there is an unbounded silent retry.
R1-7 cli/src/serve/hosted-harness-session.ts:2123 Substitute the shared matchesRecovery predicate for the hand-inlined three-clause negation on the load path.
R1-22 cli/src/serve/hosted-harness-session.ts:2078 Add coverage for a hooks-owning Session on the passive resident load path; the case added since sits in the no-tool block and would not notice a revert of the if (parked) scoping.
R1-29 cli/src/serve/hosted-harness-session.test.ts:9015 Drain refusedAdoptions on the close path too, or correct the field doc: a refuse-then-close Session keeps its entry for the daemon's lifetime and suppresses every later stays owed line.

测试质量 —— 在其本应捕获的变异下仍然通过的断言

Discussion Location Remaining work
R1-3 cli/src/serve/hosted-harness-session.test.ts:9249 The waitFor(toHaveBeenCalledOnce) in the stranded-drive-redrive test is already satisfied by loadReplacement(), so the DELETE races the redrive; wait on a count the redrive itself moves.
R1-12 cli/src/serve/hosted-harness-session.test.ts:7733 Assert the Session Store writer was not reopened via the existing-but-unused state.storeOptions instrument, which the test's own name and the design doc promise.
R1-21 cli/src/serve/hosted-harness-session.test.ts:9284 Constrain the authorization spy in the cold-adoption test as its resident sibling does, so an added gating call cannot relocate the failFinalAuthorization injection.
R1-28 cli/src/serve/hosted-harness-session.test.ts:8952 Pin the three identity comparisons of the resident-passive guard; every current test only exercises the !recovery term, so deleting any of them stays green.
R1-33 web-shell/client/components/managed/ManagedSessionsPage.test.tsx:920 Assert the standalone Cancel control's absence, not only its presence: click() ends in expect(button).toBeDefined(), so it can never detect an unexpected button.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions