Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
22 commits
Select commit Hold shift + click to select a range
1b2496d
fix(managed-agent): stop database amplification on session hot paths
Oct 2, 2026
f75955c
fix(managed-agent): pin the head-path proof in the fencing tests
Oct 2, 2026
7de5860
fix(managed-agent): pin the per-row retention flags on bound pages
Oct 2, 2026
b0d357a
fix(managed-agent): keep the text-order snapshot test deterministic
Oct 2, 2026
b6ba408
fix(managed-agent): keep singleAppendsContinueTheTextPartBeforeThem d…
Oct 2, 2026
9a4bcd8
fix(managed-agent): close out the second review round on #13181
Oct 3, 2026
7f5081b
fix(managed-agent): close the audit round on the R2 fixes
Oct 3, 2026
e7f7c7d
fix(managed-agent): close the second audit round on the R2 fixes
Oct 3, 2026
d0cacdb
test(managed-agent): correct the publish positive-control comment's l…
Oct 3, 2026
93b9f46
fix(managed-agent): merge main and renumber the PR's migrations to V3…
Oct 3, 2026
2a5d6e1
test(managed-agent): pin the creator-submit capability's batched page…
Oct 3, 2026
4e77d9f
docs(managed-agent): state the conditional creator/grant batches in t…
Oct 3, 2026
7f4d6aa
test(managed-agent): exercise the can_create grant term across two wo…
Oct 3, 2026
f92d32d
fix(managed-agent): close out the third review round on #13181
Oct 3, 2026
232340e
fix(managed-agent): align the commit-side scope check with the read p…
Oct 3, 2026
b81978c
Merge branch 'main' into fix/13181-managed-agent-query-amplification
wenshao Oct 3, 2026
79a746a
fix(managed-agent): merge main (turn deadlines, prefix retraction, lo…
Oct 4, 2026
6817658
fix(managed-agent): close out the fourth review round on #13181
Oct 4, 2026
e9d04c4
docs(managed-agent): state the widened commit-side scope check in sec…
Oct 4, 2026
a5a549e
fix(managed-agent): close the audit round on the R4 fixes
Oct 4, 2026
884a5b3
Merge remote-tracking branch 'origin/fix/13181-managed-agent-query-am…
Oct 4, 2026
4d3b135
Merge branch 'main' into fix/13181-managed-agent-query-amplification
Oct 4, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion docs/design/2026-09-26-managed-workspace-admission.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ The bound creation command is keyed by tenant, authenticated actor bytes, and id

## Access and execution gate

A current read grant is required for bound Session GET/list, events, items, transcript, and SSE. List filtering precedes pagination. SSE captures the authorized immutable Session binding when opening and rechecks its current read grant before every event, including terminal events. Unbound streams do not query the Session on each delivery. Existing streams can drain committed events through `session.deleted` and complete immediately; opening a new stream or reading a deleted Session still returns 404. Revocation completes the stream without another event. Without a read grant, direct requests return 404. Bound Turn submission/cancellation and Session lifecycle mutations remain unavailable, with no command written or Hosted Harness/Broker call. The Store rejects direct bound Turn and lifecycle writes; recovery fails any already-persisted bound Turn before calling the Hosted Harness, and the embedded Broker refuses to resolve a bound Session to its global Workspace. An actor without read access receives 404 even on those unavailable HTTP operations. Unbound legacy behavior remains unchanged.
A current read grant is required for bound Session GET/list, events, items, transcript, and SSE. List filtering precedes pagination. SSE captures the authorized immutable Session binding when opening and rechecks its current read grant at most once per `read-grant-recheck-interval` while a stream is open, including before terminal events (`PT0S` restores the original per-event check). Unbound streams do not query the Session on each delivery. Existing streams can drain committed events through `session.deleted` and complete immediately; opening a new stream or reading a deleted Session still returns 404. A failed recheck completes the stream without delivering that event; events committed while a recheck window is still open are delivered first, so a revocation takes effect at the next recheck, and an idle stream's connection closes at most one `events.poll-interval` later. Without a read grant, direct requests return 404. Bound Turn submission/cancellation and Session lifecycle mutations remain unavailable, with no command written or Hosted Harness/Broker call. The Store rejects direct bound Turn and lifecycle writes; recovery fails any already-persisted bound Turn before calling the Hosted Harness, and the embedded Broker refuses to resolve a bound Session to its global Workspace. An actor without read access receives 404 even on those unavailable HTTP operations. Unbound legacy behavior remains unchanged. (The original per-event recheck was superseded 2026-10-02 by issue #13181's windowed recheck — see [Managed Agent Query Amplification Fix](2026-10-02-managed-agent-query-amplification.md) §4.)

Agent, Bundle, and configuration compatibility validation originally assigned to W0b is deferred to W0c before bound execution is enabled. W0c must resolve and validate the frozen configuration/policy references against the Agent and Bundle, not silently substitute current Registry values; incompatible bindings remain non-executable and require a new compatible Session. Metadata admission here does not certify compatibility.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ Registry 由管理员填充 SQL,按租户隔离,并以精确的 Workspace ID

## 访问权限与执行门禁

绑定 Session 的 GET/list、事件、item、transcript 和 SSE 要求当前读权限。列表在分页之前过滤。SSE 在打开时保存已授权且不可变的 Session 绑定,并在每个事件(包括终态事件)投递前重新检查当前读权限。未绑定流不会在每次投递时查询 Session。已有流可读取已提交事件直到 `session.deleted`,随后立即正常结束;新打开流或读取已删除 Session 仍返回 404。撤权会正常结束流,不再投递事件。无读权限的直接请求返回 404。绑定 Turn 的提交/取消和 Session 生命周期修改继续不可用,不写命令,也不调用 Hosted Harness/Broker。Store 拒绝直接写入绑定 Turn 和生命周期命令;恢复调度在调用 Hosted Harness 前使任何已持久化的绑定 Turn 失败;嵌入式 Broker 拒绝把绑定 Session 解析到全局 Workspace。无读权限的 actor 在这些不可用 HTTP 操作上也得到 404。未绑定旧路径行为不变。
绑定 Session 的 GET/list、事件、item、transcript 和 SSE 要求当前读权限。列表在分页之前过滤。SSE 在打开时保存已授权且不可变的 Session 绑定,并在流打开期间至多每个 `read-grant-recheck-interval` 重新检查一次当前读权限,包括终态事件之前(`PT0S` 恢复原先的逐事件检查)。未绑定流不会在每次投递时查询 Session。已有流可读取已提交事件直到 `session.deleted`,随后立即正常结束;新打开流或读取已删除 Session 仍返回 404。复检失败会结束流且不投递该事件;复检窗口未到期前提交的事件仍会先投递,因此撤权在下一次复检时生效,空闲流的连接至多再晚一个 `events.poll-interval` 关闭。无读权限的直接请求返回 404。绑定 Turn 的提交/取消和 Session 生命周期修改继续不可用,不写命令,也不调用 Hosted Harness/Broker。Store 拒绝直接写入绑定 Turn 和生命周期命令;恢复调度在调用 Hosted Harness 前使任何已持久化的绑定 Turn 失败;嵌入式 Broker 拒绝把绑定 Session 解析到全局 Workspace。无读权限的 actor 在这些不可用 HTTP 操作上也得到 404。未绑定旧路径行为不变。(原先的逐事件复检于 2026-10-02 被 issue #13181 的窗口化复检取代——见[查询放大修复设计](2026-10-02-managed-agent-query-amplification.zh-CN.md) §4。)

原定由 W0b 负责的 Agent、Bundle 和配置兼容性校验延后至 W0c,必须在启用绑定执行之前完成。W0c 必须解析并校验冻结的配置/策略引用与 Agent、Bundle 的兼容性,不能静默改用当前 Registry 值;不兼容的绑定保持不可执行,需新建兼容 Session。此处的元数据准入不证明兼容性。

Expand Down
24 changes: 12 additions & 12 deletions docs/design/2026-09-29-managed-tool-result-public-projection.md
Original file line number Diff line number Diff line change
Expand Up @@ -126,7 +126,7 @@ Current receipts are parsed once with the extension records and captured with a

Projection runs on a dedicated single-thread scheduler, while existing Harness, lifecycle, and message schedules retain the default scheduler. A READY source is not reclaimed: this implementation emits projection_revision 1 exactly once. Replay consumers retain monotonic revision guards for duplicate/stale events; supporting a second policy projection requires the separately reviewed representation migration above. Public delivery pending is reserved; accepted receipts currently publish committed or blocked. Missing public Turn mapping has its own unsupported diagnostic.

Metadata evaluates the current raw-read policy once per request and batches publication availability checks per Session scope. Content requests retain fresh authorization and catalog checks at every chunk boundary. An initial guard and range bounds run before metadata closure reads. Fixed-revision reads still verify the complete immutable metadata closure; reducing closure verification or throttling current grants is not part of this change. Audit records distinguish denied, rejected, interrupted, and completed reads, including completed zero-byte streams.
Metadata evaluates the current raw-read policy once per request and batches publication availability checks per Session scope. Content requests retain fresh authorization and catalog checks at every chunk boundary. An initial guard and range bounds run before metadata closure reads. Fixed-revision reads still verify the complete immutable metadata closure; reducing closure verification or throttling current grants is not part of this change. Audit records distinguish denied, rejected, interrupted, and completed reads, including completed zero-byte streams. (Superseded 2026-10-02 by issue #13181: the per-chunk access re-check is windowed by `qwen.managed-agent.artifacts.read-revalidation-interval`, default 5s; the read lease's durability checks still run per chunk. See [Managed Agent Query Amplification Fix](2026-10-02-managed-agent-query-amplification.md) §7.)

The preview source window is up to 8 KiB, with independent UTF-8 byte and 200-line limits. Automatic previews reuse each artifact's verified metadata handle and are omitted when verifying the intersecting segments would read more than 1 MiB. Artifact metadata and requested content remain available. WebShell retains four pages including lookback bytes, keeps an output panel mounted across a same-Session refresh, and settles assistant text before a new result row in the current Turn. Transient 429/503 content reads retry the identical request once after Retry-After (a maximum five-second wait; a longer Retry-After is returned as an error without an early retry); cancellation also aborts that wait. Java-produced contract fixtures are compared on every normal test run, normalizing only timestamps and randomly assigned event IDs.

Expand Down Expand Up @@ -173,7 +173,7 @@ Preview policy is separate and versioned. A preview stored in shared Session eve

Unknown or unreadable resources use the product's 404 policy. A caller allowed to discover an Artifact but forbidden to read its original bytes receives `403 artifact_content_forbidden`. Only an authorized caller may observe an expired-version `410`. O3 does not expire retained representations; `410` is reserved for a future retention implementation, while current missing/quarantined content is unavailable. Authorization runs before range/precondition errors disclose length or version. Audit actor, scoped IDs, decision, and byte count; do not log content, credentials, or signed links.

Check access and current catalog/representation availability on request admission, before the first byte, and at bounded stream chunk boundaries. Revocation/deletion or quarantine stops subsequent chunks; bytes already delivered cannot be retracted. The transport aborts cleanly on client disconnect and releases its concurrency slot. Public metadata and byte responses use `Cache-Control: private, no-store`.
Check access and current catalog/representation availability on request admission, before the first byte, and at bounded stream chunk boundaries. Revocation/deletion or quarantine stops subsequent chunks; bytes already delivered cannot be retracted. The transport aborts cleanly on client disconnect and releases its concurrency slot. Public metadata and byte responses use `Cache-Control: private, no-store`. (Superseded 2026-10-02 by issue #13181: the in-stream access re-check runs at most once per `read-revalidation-interval`, default 5s — revocation/deletion lands at the first chunk boundary after the window's end; the per-chunk lease checks are unchanged. See [Managed Agent Query Amplification Fix](2026-10-02-managed-agent-query-amplification.md) §7.)

## 7. Exact bytes, HTTP, and bounded downloads

Expand Down Expand Up @@ -220,16 +220,16 @@ Opening a result pins its revision. A `412` requires explicit refresh; a `410` s

O3 adds public reference mappings and read admission; O4 owns physical garbage collection. Retain source receipts, binding identities, outcomes, manifests, pages, and segments while pending/ready results depend on them. O2 currently retains used/uncertain content without automatic GC. O3 must not introduce a TTL cleanup that defeats this guarantee. A future O4 implementation must honor public references, projection backfill windows, and in-flight read holds before enabling deletion.

| Failure | Required result |
| --------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Receipt commits, process dies before projection | Pending row is durable; a replacement materializer publishes the original source. |
| Object I/O succeeds, public projection transaction fails | Retry identical source; no public event or partial Artifact membership escapes the failed transaction. |
| Projection commits, response/SSE is lost | Result/list/Snapshot recovery returns the same IDs and revisions. |
| Turn completed before projection | Late result updates its settled Item; no new Turn or model continuation. |
| Session deletion races projection | Session-row gate prevents public writes after deletion starts; source is retained/suppressed for recovery policy. |
| Access revoked during a range/download | Stop future delivery at the stated chunk boundary; no Runtime action. |
| Accepted bytes become corrupt or missing | Availability becomes unavailable with bounded diagnostics; original execution/capture facts are preserved. |
| An uncertain publication candidate's operation deadline expires before durable finish/receipt | No public accepted Artifact; [#13019](https://github.com/QwenLM/qwen-code/issues/13019) owns that liveness policy. This is not expiry of retained publication data. |
| Failure | Required result |
| --------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Receipt commits, process dies before projection | Pending row is durable; a replacement materializer publishes the original source. |
| Object I/O succeeds, public projection transaction fails | Retry identical source; no public event or partial Artifact membership escapes the failed transaction. |
| Projection commits, response/SSE is lost | Result/list/Snapshot recovery returns the same IDs and revisions. |
| Turn completed before projection | Late result updates its settled Item; no new Turn or model continuation. |
| Session deletion races projection | Session-row gate prevents public writes after deletion starts; source is retained/suppressed for recovery policy. |
| Access revoked during a range/download | Stop future delivery at the stated chunk boundary; no Runtime action. (Since 2026-10-02, issue #13181: at the first chunk boundary after the revalidation window's end, default 5s.) |
| Accepted bytes become corrupt or missing | Availability becomes unavailable with bounded diagnostics; original execution/capture facts are preserved. |
| An uncertain publication candidate's operation deadline expires before durable finish/receipt | No public accepted Artifact; [#13019](https://github.com/QwenLM/qwen-code/issues/13019) owns that liveness policy. This is not expiry of retained publication data. |

O3 cannot certify O2 durability, solve orphan Runtime cleanup, or make partial output safe for model continuation. Its reads remain independent of those execution recovery actions.

Expand Down
Loading
Loading