Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
126 commits
Select commit Hold shift + click to select a range
4da84e9
feat(managed-agent): admit later Turns of a Workspace-bound Session f…
Sep 30, 2026
1dc0d0c
feat(web-shell): let the creator send later Turns to a bound Session
Sep 30, 2026
aedd7a6
feat(managed-agent): let the bound Session creator cancel a running Turn
Sep 30, 2026
e12dc74
feat(managed-agent): let the bound Session creator rename it
Sep 30, 2026
3df9ee1
style(web-shell): keep the workspaceTurns expression on one line as P…
Sep 30, 2026
a550540
test(managed-agent): read the renamed title from the public Session m…
Sep 30, 2026
b8c5830
fix(web-shell): match the generated optional workspaceTurns capability
Sep 30, 2026
8a058da
Merge origin/main into feat/hosted-bound-later-turns
yiliang114 Sep 30, 2026
f2a028b
test(managed-agent): keep the approval run out of the later-Turn checks
Sep 30, 2026
61ee97e
Merge origin/main into feat/hosted-bound-later-turns
yiliang114 Sep 30, 2026
e96c116
docs(managed-agent): Align G0 gating statements with creator later-Tu…
yiliang114 Sep 30, 2026
2f4abb1
chore(managed-agent): Bump the public API contract to 1.27.0
yiliang114 Sep 30, 2026
af0373c
fix(web-shell): hide execution-unavailable banner line when creator c…
yiliang114 Sep 30, 2026
3a736a3
test(sdk-java): pin bound-Session admission clauses with negative con…
yiliang114 Oct 1, 2026
5d4499c
test(sdk-java): exercise later Turns under approval-mode=default and …
yiliang114 Oct 1, 2026
26de98c
fix(sdk-java): align bound-Session later-Turn admission with the exec…
yiliang114 Oct 1, 2026
f2601d6
Merge origin/main into feat/hosted-bound-later-turns
yiliang114 Oct 1, 2026
dc22300
Merge remote-tracking branch 'origin/main' into feat/hosted-bound-lat…
yiliang114 Oct 1, 2026
66646a6
fix(sdk-java): cancel a live bound Turn through its running attachment
Oct 1, 2026
485c92b
Merge branch 'main' into feat/hosted-bound-later-turns
yiliang114 Oct 1, 2026
9a60cff
fix(managed-agent): stop a bound Turn under refused authorization
Oct 1, 2026
c809439
fix(managed-agent): fail the Turn when a cancel attach is refused
yiliang114 Oct 1, 2026
2431e5e
fix(managed-agent): retire a refused rename command instead of wedgin…
yiliang114 Oct 1, 2026
3f0432b
refactor(managed-agent): drop the dead read-grant operand and fix the…
yiliang114 Oct 1, 2026
ff91ed5
Merge branch 'main' into feat/hosted-bound-later-turns
yiliang114 Oct 1, 2026
31060be
Merge #13112's head into the #13162 follow-up
Oct 1, 2026
f2f8752
refactor(managed-agent): cancel an admitted Turn without attaching
Oct 1, 2026
179aa05
docs(managed-agent): state the full later-Turn admission rule and nar…
yiliang114 Oct 1, 2026
8a26cc9
fix(managed-agent): deliver cancellation through the running owner
yiliang114 Oct 1, 2026
925cffe
fix(ci): bound hosted browser dependency installation
yiliang114 Oct 1, 2026
fa31c02
Merge remote-tracking branch 'origin/main' into codex/ci-browser-inst…
yiliang114 Oct 1, 2026
f6fd035
fix(managed-agent): align cancellation test with runtime recovery
yiliang114 Oct 1, 2026
d857f0f
Merge remote-tracking branch 'origin/main' into codex/pr13163-owner-c…
yiliang114 Oct 1, 2026
77373a0
fix(ci): record the ci.yml growth in the workflow size baseline
yiliang114 Oct 1, 2026
4a79dcf
fix(ci): reserve browser smoke time after slow dependency downloads
yiliang114 Oct 1, 2026
1b5d007
merge(ci): give hosted browser acceptance its full test budget
yiliang114 Oct 1, 2026
ba222e2
fix(ci): keep time for smoke after slow hosted installs
yiliang114 Oct 1, 2026
fd81587
Merge commit 'ba222e2429bd870f49064f5ef5cb5dd50daab6cb' into codex/pr…
yiliang114 Oct 1, 2026
9dffa01
test(web-shell): wait for step expansion before selecting next group
yiliang114 Oct 1, 2026
b73ec01
test(ci): align hosted browser timeout contract
yiliang114 Oct 1, 2026
4ba2b45
Merge commit 'b73ec018e92d202907787ebd146e4717241cdcb2' into codex/pr…
yiliang114 Oct 1, 2026
7b53bba
Merge remote-tracking branch 'origin/main' into feat/hosted-bound-lat…
yiliang114 Oct 2, 2026
e5b2e8c
fix(managed-agent): retry transient cancel-attach refusals instead of…
yiliang114 Oct 2, 2026
43be009
fix(managed-agent): retire the rename command row on every answered f…
yiliang114 Oct 2, 2026
dba017b
docs(managed-agent): qualify Workspace cancel contract
yiliang114 Oct 2, 2026
7720f6d
docs(web-shell): scope Session creation capabilities
yiliang114 Oct 2, 2026
71e9007
docs(managed-agent): state the retired-rename-command contract in the…
yiliang114 Oct 2, 2026
fe91f94
test(managed-agent): pin the command half of requireNoOpenOperation
yiliang114 Oct 2, 2026
7275c03
chore: merge origin/main to refresh the lint gate baseline
yiliang114 Oct 2, 2026
7e5cbdc
fix(ci): sync Hosted later-turn branch with main
yiliang114 Oct 2, 2026
bf1bada
test(web-shell): pin the bound-Session Cancel control at the page level
yiliang114 Oct 2, 2026
f04bf98
fix(managed-agent): answer same-key retries from the record, retire r…
yiliang114 Oct 2, 2026
733e457
fix(managed-agent): clear rename admission when harness is disabled
yiliang114 Oct 2, 2026
220b036
fix(managed-agent): repair the two red required lanes on this head
yiliang114 Oct 2, 2026
bf24730
fix(managed-agent): preserve rename receipts and retry cancellation
yiliang114 Oct 2, 2026
ef77ebf
Merge remote-tracking branch 'origin/main' into feat/hosted-bound-lat…
Oct 2, 2026
b9b4da4
test(managed-agent): expect the closed Session status for a queued bo…
Oct 2, 2026
c3925ff
Merge origin/main into fix/13162-cancel-refused-authorization
yiliang114 Oct 2, 2026
3cd09be
test(managed-agent): read the renamed Session title from metadata
yiliang114 Oct 2, 2026
22a4012
Merge branch 'main' into feat/hosted-bound-later-turns
yiliang114 Oct 2, 2026
9c0bcf4
fix(managed-agent): restore admission error precedence in CI
yiliang114 Oct 2, 2026
03bdd6c
fix(managed-agent): keep the Workspace refusal ahead of the Harness gate
yiliang114 Oct 2, 2026
8953b8f
fix(runtime-broker): close drained lost workspace bindings
yiliang114 Oct 2, 2026
6c5bdee
Merge main into feat/hosted-bound-later-turns
yiliang114 Oct 2, 2026
fb7296c
merge: preserve hosted admission with current workspace retention
yiliang114 Oct 2, 2026
d20a189
merge: retain concurrent PR branch synchronization
yiliang114 Oct 2, 2026
f1387d8
merge: sync cancellation PR with current main
yiliang114 Oct 2, 2026
a745197
fix(managed-agent): retain replay authority while syncing later-turn …
yiliang114 Oct 2, 2026
61ce828
merge: sync refused-authorization cancellation with main
yiliang114 Oct 3, 2026
9cb70b7
Merge branch 'main' into fix/13162-cancel-refused-authorization
yiliang114 Oct 3, 2026
3363fff
docs(managed-agent): state the cancel rule and refusal codes the code…
yiliang114 Oct 3, 2026
2f0d389
fix(managed-agent): answer bound replays only to the creator and keep…
Oct 3, 2026
1701827
fix(managed-agent): keep a retired rename from reverting a newer title
yiliang114 Oct 3, 2026
41cb651
style(web-shell): format the bound Cancel page test with Prettier
Oct 3, 2026
262eb3a
style(web-shell): apply prettier to ManagedSessionsPage.test.tsx
yiliang114 Oct 3, 2026
29e4d17
fix(managed-agent): recover cold-cache cancels without new-work grants
yiliang114 Oct 3, 2026
60030e4
docs(managed-agent): include storage in both capability descriptions
yiliang114 Oct 3, 2026
9fa6b8d
Merge commit 'refs/prheads/13163' into prmerge-13163
yiliang114 Oct 3, 2026
c11d0b5
Merge origin/main into fix/13162-cancel-refused-authorization
yiliang114 Oct 3, 2026
125954a
merge: sync main and preserve cancellation runtime adoption
yiliang114 Oct 3, 2026
52704a9
merge: preserve concurrent PR synchronization
yiliang114 Oct 3, 2026
3683f11
merge: reconcile the unpushed Java admission fix with the live PR head
yiliang114 Oct 3, 2026
8d98903
refactor(managed-agent): delete the review-minted dead surface and it…
yiliang114 Oct 3, 2026
0d4504a
merge: sync main for managed-agent PR
yiliang114 Oct 3, 2026
f8e83fc
fix(managed-agent): dedupe by dropping this PR's own added test, not …
yiliang114 Oct 3, 2026
3c657d6
merge: preserve concurrent PR cleanup
yiliang114 Oct 3, 2026
b27a595
merge: sync PR owner assignment fix
yiliang114 Oct 3, 2026
a18ea0e
fix(serve): retain passive recovery leases on refusal
yiliang114 Oct 4, 2026
762f4a2
Merge origin/main into fix/13162-cancel-refused-authorization
yiliang114 Oct 4, 2026
04b778a
Merge origin/main into fix/13162-cancel-refused-authorization
yiliang114 Oct 4, 2026
288e7fe
Merge origin/main into fix/13162-cancel-refused-authorization
yiliang114 Oct 4, 2026
30f092d
fix(managed-agent): keep the re-registration guard on the page twin
yiliang114 Oct 4, 2026
df8bdc5
fix(managed-agent): keep the Session lifecycle term on cancel admission
yiliang114 Oct 4, 2026
6739048
Merge origin/main into fix/13162-cancel-refused-authorization
yiliang114 Oct 4, 2026
b683a3d
fix(managed-agent): record a passive adoption stranded by a concurren…
yiliang114 Oct 5, 2026
1fbd319
Merge branch 'main' into fix/13162-cancel-refused-authorization
yiliang114 Oct 5, 2026
d210e2d
Merge origin/main into fix/13162-cancel-refused-authorization
yiliang114 Oct 5, 2026
df2547d
Merge branch 'main' into fix/13162-cancel-refused-authorization
yiliang114 Oct 5, 2026
b8f92ce
fix(managed-agent): fence every resident reattach and keep its refusa…
yiliang114 Oct 5, 2026
d71675b
Merge origin/main into fix/13162-cancel-refused-authorization
yiliang114 Oct 5, 2026
b6eff8f
fix(managed-agent): fence the parked passive recovery against teardown
yiliang114 Oct 5, 2026
eb3b933
Merge origin/main into fix/13162-cancel-refused-authorization
yiliang114 Oct 6, 2026
25eb9ae
Merge origin/main into fix/13162-cancel-refused-authorization
yiliang114 Oct 6, 2026
d7aa13a
fix(managed-agent): preserve concurrent recovery and rename ordering
yiliang114 Oct 6, 2026
eeffbb8
Merge main to preserve managed-agent migration order
yiliang114 Oct 6, 2026
6e6da3c
fix(test): import Mockito times in coordinator tests
yiliang114 Oct 6, 2026
13df2a6
Merge origin/main into fix/13162-cancel-refused-authorization
yiliang114 Oct 6, 2026
4b6a2c8
Merge origin/main into fix/13162-cancel-refused-authorization
yiliang114 Oct 7, 2026
684a290
Merge remote-tracking branch 'origin/main' into fix/13162-cancel-refu…
yiliang114 Oct 7, 2026
504ecd9
fix(managed-agent): settle cancelled recovery and refused approvals
yiliang114 Oct 7, 2026
2748c36
chore(repo): retain published PR base synchronization
yiliang114 Oct 7, 2026
f2864f6
fix(serve): preserve live cancellation reattachment
yiliang114 Oct 7, 2026
0227b25
fix(serve): restore resident recovery outcomes
yiliang114 Oct 7, 2026
a9f7fec
fix(managed-agent): retry transient approval mount failures
yiliang114 Oct 7, 2026
3580cd3
Merge origin/main into fix/13162-cancel-refused-authorization
yiliang114 Oct 7, 2026
89aa9d4
fix(managed-agent): renumber the mutation-attempt migration to V51
yiliang114 Oct 7, 2026
3c42bc6
test(managed-agent): expect the V51 mutation-attempt migration in the…
yiliang114 Oct 7, 2026
ce56f43
test(managed-agent): keep Hosted fixture ports distinct
yiliang114 Oct 7, 2026
234037e
fix(managed-agent): retry operator-reversible refusals on the action-…
yiliang114 Oct 8, 2026
2740c23
fix(cli): refuse a resident inapplicable redrive while a prompt slot …
yiliang114 Oct 8, 2026
a4b5452
Merge origin/main into fix/13162-cancel-refused-authorization
yiliang114 Oct 8, 2026
576a39a
test(managed-agent): pin V52 after renumbering the mutation-attempt m…
Oct 8, 2026
00be8ed
fix(managed-agent): preserve approval retries during cold attachment
yiliang114 Oct 8, 2026
f52f123
test(managed-agent): pin the legacy receipt rewrite and the acquire v…
yiliang114 Oct 8, 2026
7867f4b
test(sdk-java): allow heartbeat recovery time after refused detach
yiliang114 Oct 8, 2026
d4cfa63
Merge branch 'main' into fix/13162-cancel-refused-authorization
yiliang114 Oct 8, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
58 changes: 46 additions & 12 deletions docs/design/2026-09-29-hosted-public-workspace-admission.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,31 @@ Turn against the creator's Workspace grants, so any other actor, and every
deployment without the opt-in, keeps the existing refusal:
`workspace_unavailable` when the actor can read the Workspace,
`session_not_found` when they cannot. The creator may also rename the Session.
Admitting new work requires the creator's create grant on an `ACTIVE`
Comment thread
yiliang114 marked this conversation as resolved.
Workspace at the generation and storage the Session was bound to, so a
re-registration refuses submit and rename before any command is written.
Cancelling only aborts work already running: while the deployment still enables
Workspace files, the creator who can still read the Workspace may cancel even
after the create grant is revoked, the Workspace starts draining or it is
re-registered. A live cancel reuses the running Turn's resident attachment.
A cold connector cache re-attaches for the persisted cancellation, validating
its frozen Session binding and exact tenant/Session identity without requiring
mutable creation grants, registry state or mount readiness. New API requests
still require the creator's read grant; a cancellation already accepted keeps
retrying if that grant is later revoked. New work always rechecks execution
authority, including when physical recovery is disabled. Passive load of a
resident Harness Session returns the original client identity after validating
its tenant, Workspace, Session Store URL and frozen profile. It does not reopen
the writer or drive work; an inactive parked Runtime Turn is reported again if
a prior load reply was lost. Passive recovery may adopt the original Runtime
and query status, but does not prepare or execute work. On the cancellation
path, the adopted lease stays owed through lost replies and retryable refusals
until terminal success or teardown. This does not prove recovery after Broker/worker
process death or resolve an original prompt admission whose reply was lost.
A cancel the Harness did not take is re-sent while the Turn is still cancelling. After each
successful lease renewal, the running owner observes cancellation requested
through any API replica and sends it on the executor, keeping network waits
off the lease scheduler. Failed deliveries retry at the lease renewal interval.
Workspace close follows its separate close capability and lifecycle admission.
Archive, delete and unarchive follow the separate retention capabilities after
reliable Workspace close. Cwd operations remain gated for bound Sessions.
Expand All @@ -46,7 +71,7 @@ reliable Workspace close. Cwd operations remain gated for bound Sessions.
checks, Session creation, initial Turn and actor-scoped idempotency remain in
the existing creation transaction. Replays preserve the original identities
and binding; changed payloads conflict.
- Before attaching a bound Session, the connector rechecks the persisted binding
- Before attaching a bound Session for new work, the connector rechecks the persisted binding
through `WorkspaceExecutionStore.authorize`. Broker acquisition and execution
retain their own grant, generation, storage and ownership checks. No failed
binding falls back to the global Workspace or an unbound no-tool Session.
Expand All @@ -56,21 +81,22 @@ reliable Workspace close. Cwd operations remain gated for bound Sessions.
- Cold load of unsettled input remains blocked. G0 does not enable in-flight
continuation, adopt workers, remove affinity or change the G1 failover gates.

- A live cancellation reuses its admitted Harness attachment and is retried by the current lease owner. It never certifies a terminal failure from a fresh attach refusal. Recorded rename failures retain a `FAILED` command receipt and digest; same-content retries are replays, conflicting content remains rejected, and a concurrent success can complete the retained receipt.
- A cancellation reuses its admitted Harness attachment or passively re-attaches from a cold connector cache and is retried by the current lease owner. It never certifies a terminal failure from a fresh attach refusal. Recorded rename failures retain a `FAILED` command receipt and digest; same-content retries are replays, conflicting content remains rejected, and a concurrent success can complete the retained receipt.

## Changes and ownership

| Layer | Change | Scope |
| ----------------------------------- | ------------------------------------------------------------------------ | ---------------------------------------- |
| Java configuration | Explicit file admission opt-in and dependency validation | Deployment |
| Creation service and SQL store | Admit initial input only under fixed, authorized Workspace configuration | Tenant, creator and persisted Workspace |
| Coordinator | Dispatch admitted bound Turns only when the opt-in is enabled | Persisted Session and leased Turn |
| Java connector and private SDK DTOs | Resolve the Session binding and pass the profile on create/load | Persisted Session and live Harness owner |
| Existing Broker/worker | Reuse production routing and fencing | Selected Runtime and persisted Workspace |
| Contract and README | Document the narrow creation capability and remaining gates | Public REST and WebShell adapter |
| Layer | Change | Scope |
| ----------------------------------- | ------------------------------------------------------------------------------------ | ---------------------------------------- |
| Java configuration | Explicit file admission opt-in and dependency validation | Deployment |
| Creation service and SQL store | Admit initial input only under fixed, authorized Workspace configuration | Tenant, creator and persisted Workspace |
| Coordinator | Dispatch admitted bound Turns only when the opt-in is enabled | Persisted Session and leased Turn |
| Java connector and private SDK DTOs | Resolve the Session binding and pass the profile on create/load | Persisted Session and live Harness owner |
| Hosted private load route | Reuse resident connection after frozen identity checks; report parked Turn passively | Live Session owner |
| Existing Broker/worker | Reuse production routing and fencing | Selected Runtime and persisted Workspace |
| Contract and README | Document the narrow creation capability and remaining gates | Public REST and WebShell adapter |

Production behavior changes under `packages/sdk-java/managed-agent-server`, in
the private Hosted DTOs in `packages/sdk-java/qwencode`, and in the WebShell
the private Hosted DTOs in `packages/sdk-java/qwencode`, in the CLI Hosted Session routes (`packages/cli`), and in the WebShell
managed Sessions page and its providers (`packages/web-shell`); it covers the
initial Workspace Read/Write/Edit Turn and the creator's later-Turn submit,
cancel and rename admission. No core authority, tool
Expand Down Expand Up @@ -111,7 +137,11 @@ while cwd remains gated), and unbound
no-tool regression paths.

Focused SDK serialization, connector, store/admission and coordinator tests
cover create/load identity, authorization rechecks and disabled gates. Run the
cover create/load identity, authorization rechecks and disabled gates. The real
Hosted stack must cancel after creation authority is revoked and the connector
cache is cleared; generation-only and storage-only drift must refuse new work
before any command is written. New cancellation requests after read revocation
must remain hidden, while previously accepted cancellations still retry. Run the
Hosted integration on H2 locally and include it in the existing Hosted MySQL CI
suite. Record separately whether local MySQL is available. Build, typecheck,
bundle, focused tests and two clean diff audits precede completion.
Expand All @@ -125,3 +155,7 @@ creator, above), lifecycle enablement,
distributed provisioning and W0e/G1–G3 recovery remain separate. The existing
`EmbeddedRuntimeBroker` is a production component and remains allowed; the E2E
must not replace it or bypass admission with direct store calls.

The late-rename supersession check protects the public SQL title and receipt.
It runs after the Harness title write, so it does not order overlapping Harness
writes. That inherited lifecycle issue remains tracked in #13269.
Original file line number Diff line number Diff line change
Expand Up @@ -10,18 +10,18 @@ Hosted Read/Write/Edit 已能经过生产 Broker 和 worker 执行,但目前

G0 开放随创建会话准入的一次初始文件工具轮次,使用现有公开 REST 路由及共享 service 的 WebShell 创建适配器。发现接口仍仅广播 Workspace 绑定能力,不宣称完整的 Workspace 执行支持。G0 本身无需修改 UI;后续改动唯一的 UI 变化是为创建者开放输入框与取消控件。

后续改动在同一开关下为会话创建者开放后续 Turn,并允许创建者取消正在运行的 Turn,由 Hosted Harness 中止该 Turn 并按原始 Runtime 身份结算。执行时每个 Turn 都按创建者的 Workspace 授权校验,因此其他 actor 以及未开启该开关的部署仍得到现有拒绝:actor 可读取该 Workspace 时为 `workspace_unavailable`,不能读取时为 `session_not_found`。创建者也可以重命名该会话。工作区关闭通过独立的关闭能力及生命周期准入控制;归档、删除与取消归档遵循可靠工作区关闭后的独立保留能力;cwd 操作仍保持门禁。
后续改动在同一开关下为会话创建者开放后续 Turn,并允许创建者取消正在运行的 Turn,由 Hosted Harness 中止该 Turn 并按原始 Runtime 身份结算。执行时每个 Turn 都按创建者的 Workspace 授权校验,因此其他 actor 以及未开启该开关的部署仍得到现有拒绝:actor 可读取该 Workspace 时为 `workspace_unavailable`,不能读取时为 `session_not_found`。创建者也可以重命名该会话。准入新工作要求创建者在 `ACTIVE` 的 Workspace 上持有创建授权,且 Workspace 的 generation 与存储与会话绑定时一致,因此重新注册后提交和改名会在写入任何命令之前被拒绝。取消只中止已在运行的工作:部署仍开启 Workspace 文件能力时,仍能读取该 Workspace 的创建者,即使创建授权被撤销、Workspace 进入 drain 或被重新注册,也可以取消。正常取消复用运行中 Turn 驻留在内存中的挂接。连接器缓存丢失后,按已持久化的取消请求重新挂接,验证冻结的 Session 绑定和精确的 tenant/Session 身份,不再要求可变的创建授权、registry 状态或挂载就绪。新的 API 请求仍要求创建者的读取授权;已受理的取消即使随后失去读取授权也继续重试。新工作始终重新验证执行授权,包括关闭物理恢复功能时。对 Harness 中驻留会话的 passive load,在验证租户、Workspace、Session Store URL 和冻结 profile 后返回原始 client 身份,不重新打开 writer 或驱动工作;若之前的 load 回复丢失,会再次报告未运行但仍停驻的 Runtime Turn。被动恢复可以采用原 Runtime 并查询状态,但不会 prepare 或 execute;取消路径中,已接管的租约跨丢失回复和可重试拒绝保持待归还,直到终态成功或拆除会话。这不证明 Broker/worker 进程死亡后的恢复,也不解决原始 prompt 准入回复丢失的问题。Harness 未接收的取消会在 Turn 仍处于取消中时重发。每次成功续租后,执行 owner 检查任意 API 副本受理的取消请求,并在 executor 中发送,避免网络等待阻塞续租调度器。投递失败按续租间隔重试。工作区关闭通过独立的关闭能力及生命周期准入控制;归档、删除与取消归档遵循可靠工作区关闭后的独立保留能力;cwd 操作仍保持门禁。

## 决策

- 部署显式启用 `harness.workspace-files-enabled`(环境变量 `QWEN_MANAGED_AGENT_WORKSPACE_FILES_ENABLED`),默认关闭。它要求 Hosted Harness、HTTP Session Store,以及同机、会话隔离的 local-process Broker。原有无绑定的无工具会话行为不变。关闭开关后拒绝携带输入的创建请求(包括重试);空输入的绑定会话创建和读取保持可用。
- 仅接受 `qwen-code` 及现已支持并冻结的 `managed-runtime-tools/1` / `preapproved-workspace-tools/1` Workspace 配置组合。服务端选择 `hosted-workspace-files/1`。公开请求不能选择 profile,也不能通过 metadata 提升权限。
- Workspace 解析、ACTIVE 状态、创建者读取/创建权限、固定 profile 校验、会话创建、初始 Turn 和 actor 范围的幂等继续位于现有创建事务内。重试保留原身份与绑定;载荷改变产生冲突。
- 连接有绑定的会话之前,connector 通过 `WorkspaceExecutionStore.authorize` 重新检查持久绑定。Broker 获取与执行仍保留各自的权限、代数、存储和所有权检查。任何绑定失败都不能回退到全局 Workspace 或无绑定的无工具会话。
- 为新工作连接有绑定的会话之前,connector 通过 `WorkspaceExecutionStore.authorize` 重新检查持久绑定。Broker 获取与执行仍保留各自的权限、代数、存储和所有权检查。任何绑定失败都不能回退到全局 Workspace 或无绑定的无工具会话。
- 私有 create 与 load 都传递所选 profile 及持久 Workspace ID,包括创建冲突和创建结果不明后回退到 load 的路径。Harness 现有的不可变 definition 检查固定 profile。
- 冷加载未结算输入仍被阻塞。G0 不启用在飞续接、接管 worker、取消 owner 粘性,也不改动 G1 failover 门禁。

- 取消运行中的 Turn 复用已准入的 Harness 连接,并由当前租约 owner 重试,不根据重新连接的拒绝伪造终态失败。已记录的重命名失败保留 `FAILED` 命令回执与摘要;相同内容重试仍是重放,不同内容继续冲突,并发成功请求仍可完成该回执。
- 取消运行中的 Turn 复用已准入的 Harness 连接,或在连接器冷缓存下被动重新挂接,并由当前租约 owner 重试,不根据重新连接的拒绝伪造终态失败。已记录的重命名失败保留 `FAILED` 命令回执与摘要;相同内容重试仍是重放,不同内容继续冲突,并发成功请求仍可完成该回执。

## 改动与归属

Expand All @@ -31,10 +31,11 @@ G0 开放随创建会话准入的一次初始文件工具轮次,使用现有
| 创建 service 与 SQL store | 仅在固定且获授权的 Workspace 配置下接受初始输入 | 租户、创建者及持久 Workspace |
| Coordinator | 仅在开关启用时派发已准入的绑定轮次 | 持久会话及持有租约的 Turn |
| Java connector 与私有 SDK DTO | 解析会话绑定,create/load 传递 profile | 持久会话及存活 Harness owner |
| Hosted 私有 load 路由 | 校验冻结身份后复用驻留连接,被动报告停驻 Turn | 存活 Session owner |
| 现有 Broker/worker | 复用生产路由与 fencing | 所选 Runtime 及持久 Workspace |
| 契约与 README | 记录有限的创建能力及剩余门禁 | 公开 REST 与 WebShell 适配器 |

生产行为在 `packages/sdk-java/managed-agent-server`、`packages/sdk-java/qwencode` 的私有 Hosted DTO,以及 WebShell 托管会话页及其 provider(`packages/web-shell`)中变化,覆盖初始 Workspace Read/Write/Edit Turn 与创建者后续 Turn 的提交、取消和重命名准入。不需要为 core authority、工具执行循环、数据库 schema 或公开请求字段新增抽象。
生产行为在 `packages/sdk-java/managed-agent-server`、`packages/sdk-java/qwencode` 的私有 Hosted DTO、CLI Hosted 会话路由(`packages/cli`),以及 WebShell 托管会话页及其 provider(`packages/web-shell`)中变化,覆盖初始 Workspace Read/Write/Edit Turn 与创建者后续 Turn 的提交、取消和重命名准入。不需要为 core authority、工具执行循环、数据库 schema 或公开请求字段新增抽象。

合入的改动还涉及该范围之外的两处,均不增加运行时行为:

Expand All @@ -47,8 +48,10 @@ G0 开放随创建会话准入的一次初始文件工具轮次,使用现有

初始轮次必须在所选 Workspace 的相对 cwd 下写、编辑并读取文件,产生持久工具历史和恰好一个公开终态事件,且不改动 Harness 的诱饵目录。重复创建幂等键,验证相同 Session/Turn 且无额外模型/工具副作用。验证改变载荷冲突、未授权租户/actor 无法创建或读取、不支持的 profile 与不可用 Workspace 被拒绝,以及关闭开关后保持原门禁。覆盖共享 WebShell 创建适配器、实际发生变化的后续操作门禁(创建者的后续 Turn 提交、取消与重命名被放行;关闭与保留操作遵循独立能力,cwd 操作仍受限)和无绑定无工具回归路径。

SDK 序列化、connector、store/准入及 coordinator 的定向测试覆盖 create/load 身份、权限复核与关闭的门禁。本地通过 H2 跑 Hosted 集成,并加入现有 Hosted MySQL CI 套件;单独记录本地 MySQL 是否可用。完成前执行 build、typecheck、bundle、定向测试和两轮无发现的完整 diff 自查。
SDK 序列化、connector、store/准入及 coordinator 的定向测试覆盖 create/load 身份、权限复核与关闭的门禁。真实 Hosted 链路必须在创建授权被撤销且连接器缓存清空后完成取消;只变 generation 或只变 storage 时,必须在写入任何命令之前拒绝新工作。撤销读取授权后的新取消请求仍必须隐藏会话,而已经受理的取消继续重试。本地通过 H2 跑 Hosted 集成,并加入现有 Hosted MySQL CI 套件;单独记录本地 MySQL 是否可用。完成前执行 build、typecheck、bundle、定向测试和两轮无发现的完整 diff 自查。

## 边界与待定事项

本次实现把 G0 放在 #12952 下;以后调整到 D 或 W 跟踪不改变契约,也不决定 G3 的范围。Shell、审批、D8 AgentDefinition、公开 profile 选择、后续 Turn(此后已对创建者开放,见上文)、生命周期开放、分布式供给及 W0e/G1–G3 恢复均另行推进。现有 `EmbeddedRuntimeBroker` 是生产组件,可以继续使用;E2E 不得替换它或通过直接调用 store 绕过准入。

晚到改名的 supersession 检查保护公开 SQL 标题与回执。该检查发生在 Harness 写入标题之后,因此不保证重叠 Harness 写入的顺序。这个继承的生命周期问题继续由 #13269 跟踪。
Loading