Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
29 commits
Select commit Hold shift + click to select a range
5b31445
feat(managed-agent): add reliable ACTIVE Workspace deletion
doudouOUC Oct 4, 2026
61978cb
fix(managed-agent): align lifecycle CI fixtures
doudouOUC Oct 4, 2026
7f3e9df
fix(hosted): authorize detach after durable lifecycle recovery (#13354)
doudouOUC Oct 4, 2026
1edeff3
fix(hosted): scope lifecycle fence locks and authorization errors
doudouOUC Oct 4, 2026
7462de8
fix(managed-agent): resolve L3 migration version collision (#13354)
doudouOUC Oct 4, 2026
63e5dbc
fix(managed-agent): address PR review feedback (#13354)
doudouOUC Oct 4, 2026
841b501
fix(managed-agent): address PR CI fixture failures (#13354)
doudouOUC Oct 4, 2026
8356fb7
codex: address PR review feedback (#13354)
doudouOUC Oct 4, 2026
3cabc9f
codex: address PR review feedback (#13354)
doudouOUC Oct 5, 2026
facc4ab
fix(managed-agent): preserve main credential and migration contracts …
doudouOUC Oct 5, 2026
c65e46d
codex: address PR review feedback (#13354)
doudouOUC Oct 5, 2026
de70a07
Merge branch 'main' into codex/workspace-session-l3
wenshao Oct 5, 2026
0ddcd11
fix(managed): preserve L3 lifecycle across CSI integration
doudouOUC Oct 5, 2026
a85d082
fix(managed): restore original lifecycle Hook owner before dispatch
doudouOUC Oct 5, 2026
3649f88
codex: address PR review feedback (#13354)
doudouOUC Oct 6, 2026
1d16b9c
codex: integrate main H3 contracts for PR #13354
doudouOUC Oct 6, 2026
2d5a13a
fix(managed-agent): preserve retained owners during W2 integration
doudouOUC Oct 6, 2026
4270eb5
fix: preserve L3 contracts across H5 integration
doudouOUC Oct 6, 2026
323390f
fix: preserve L3 deletion witnesses across H0c integration
doudouOUC Oct 6, 2026
ba79b85
fix: integrate main restore authority witness
doudouOUC Oct 7, 2026
e792060
test(managed-agent): repair lifecycle receipt journal fixture
doudouOUC Oct 7, 2026
805c030
fix(managed-agent): preserve L3 delivery across Harness generation ch…
doudouOUC Oct 7, 2026
2c4036c
fix(managed-agent): register L3 internal authorization surfaces
doudouOUC Oct 7, 2026
732c1ac
fix(managed-runtime): preserve L3 authority during H4a integration
doudouOUC Oct 7, 2026
4f94b0c
fix(cli): integrate hosted Workspace context with L3 lifecycle
doudouOUC Oct 7, 2026
d0aa0d9
fix(managed-agent): integrate L3 with storage migration
doudouOUC Oct 7, 2026
a98d534
fix(managed-agent): fail closed on stale lifecycle capability client
doudouOUC Oct 7, 2026
df1ecdc
fix(managed-agent): align native lifecycle test contracts
doudouOUC Oct 7, 2026
e01b283
codex: address PR review feedback (#13354)
doudouOUC Oct 8, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 8 additions & 8 deletions docs/design/2026-10-02-managed-workspace-w2-cwd-change.md

Large diffs are not rendered by default.

16 changes: 8 additions & 8 deletions docs/design/2026-10-02-managed-workspace-w2-cwd-change.zh-CN.md

Large diffs are not rendered by default.

16 changes: 10 additions & 6 deletions docs/design/2026-10-07-managed-agent-actor-roles.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ Two gaps, different in kind:
slice, per merged capability. For the 56 public and WebShell routes the API
contract test already fails a mapped route that the OpenAPI contract lacks,
and fires a cross-tenant probe at every contract operation. Nothing gates
the 22 internal routes, nothing probes a caller below read or with read but
the original slice-A baseline's 22 internal routes, nothing probes a caller below read or with read but
Comment thread
doudouOUC marked this conversation as resolved.
without the family's power, and nothing ties a route to the admission rule
it should follow — so a route can land with the wrong check and every test
stays green, which is the failure mode that matters most while this surface
Expand Down Expand Up @@ -72,7 +72,8 @@ tenant may mutate them today; internal store/publication routes admit a writer
HMAC credential, not an actor. The public surface is `/v1/agents/**` plus
`/api/agent/web-shell/v1/**` (`PublicSurface`), realised by ten Spring
controllers — the section-10 matrix enumerates the current 32 public + 24
WebShell + 22 internal routes (78 in total, counted by the slice-A gate).
WebShell + 24 internal routes (80 in total, including the two L3 authorization
routes, counted by the gate).

There is no production provisioning of workspace registry/access rows —
today only tests and fixture entry points write them, and a deployment writes
Expand Down Expand Up @@ -220,7 +221,7 @@ the published shape of the 56 public and WebShell routes and which the API
contract test keeps in bijection with the mounted handlers. The rule class is
deliberately not an `x-qwen-*` extension on the spec: the spec is the
published, machine-consumed contract (the WebShell client types are generated
from it), it does not describe the 22 internal routes, and an admission rule
from it), it does not describe the 24 internal routes, and an admission rule
class is a server-internal classification. A new public or WebShell route is
therefore named three times — controller, spec, registry — and each pairing
is gated: the contract test fails a route the spec lacks, and the
Expand Down Expand Up @@ -365,16 +366,17 @@ Same as the issue's, plus the explicit deferrals named there:

## 10. Surface route matrix (the slice-A registry, bilingual summary)

`api/SurfaceRegistry.java` at slice-A head carries 78 route constants: 32
public + 24 WebShell + 22 internal handler methods of the ten controllers.
`api/SurfaceRegistry.java` integrated with L3 carries 80 route constants: 32
public + 24 WebShell + 24 internal handler methods of the ten controllers,
including the two L3 authorization routes.
The gate derives everything from scanning, so the count is information, not
an asserted constant.

Rule classes name today's admission: `WORKSPACE_CREATE` (2), `READER` (24),
`READER_ACTOR` (6), `READER_ACTOR_POLICY` (1), `OPERATOR` as today's
submitter family (4), `OWNER` as today's creator families — lifecycle and
cwd plus Action respond — (12), `WORKSPACE_DISCOVERY` (4), `TENANT_SCOPED`
(3), `INTERNAL_WRITER` (22). The design's `legacy_create` and
(3), `INTERNAL_WRITER` (24). The design's `legacy_create` and
`legacy_tenant` names are kept in the class documentation as the names of
the legacy arms: a route carries exactly one rule class and, per the
separation rule, it is the bound-Session one. Slice C flips cwd and Action
Expand Down Expand Up @@ -448,6 +450,8 @@ store route and a publication route.
| `POST /api/agent/web-shell/v1/artifacts/query` | WEBSHELL | ARTIFACT_LIST | READER_ACTOR |
| `POST /api/agent/web-shell/v1/workspaces/query` | WEBSHELL | WORKSPACE_LIST | WORKSPACE_DISCOVERY |
| `POST /api/agent/web-shell/v1/workspaces/get` | WEBSHELL | WORKSPACE_GET | WORKSPACE_DISCOVERY |
| `POST /internal/managed-session-store/v1/sessions/{sessionId}/execution:authorize` | INTERNAL | STORE_EXECUTION_AUTHORIZE | INTERNAL_WRITER |
| `POST /internal/managed-session-store/v1/sessions/{sessionId}/lifecycle:authorize` | INTERNAL | STORE_LIFECYCLE_AUTHORIZE | INTERNAL_WRITER |
| `POST /internal/managed-session-store/v1/sessions/{sessionId}/writers:acquire` | INTERNAL | STORE_WRITER_ACQUIRE | INTERNAL_WRITER |
| `POST /internal/managed-session-store/v1/sessions/{sessionId}/writers:renew` | INTERNAL | STORE_WRITER_RENEW | INTERNAL_WRITER |
| `POST /internal/managed-session-store/v1/sessions/{sessionId}/writers:seal` | INTERNAL | STORE_WRITER_SEAL | INTERNAL_WRITER |
Expand Down
14 changes: 8 additions & 6 deletions docs/design/2026-10-07-managed-agent-actor-roles.zh-CN.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@
两个性质不同的缺口:

- **R1 —— 没有角色词表。** 到目前为止合入的每个绑定 Session 操作都只准入其创建者,对其他任何人返回 `404` 或 `403`。`AuthenticatedTenantActor` 只带 `tenantId()` 与 `actorId()`,此外什么都没有。两个产品行为今天被阻塞:同一 Workspace 上的第二个操作者无法回答一个正阻塞 Turn 的审批;绑定 Workspace 的 Session 无法移交,因为没有任何东西能表达「与创建者不同的所有者」。
- **R2 —— 没有系统性验收。** 准入覆盖是逐切片随各合入能力累积的。对 56 条公开与 WebShell 路由,API 契约测试已经会让契约里缺失的已挂载路由失败,并对每个契约 operation 发跨租户探针。但 22 条内部路由没有任何门禁,没有探针覆盖低于读权限或有读但无该族权限的调用方,也没有任何东西把一条路由与它应遵循的准入规则绑在一起 —— 于是一条路由可能带着错误的校验落地而所有测试保持全绿,而这个面还在快速增长,这恰恰是最要紧的失效模式。
- **R2 —— 没有系统性验收。** 准入覆盖是逐切片随各合入能力累积的。对 56 条公开与 WebShell 路由,API 契约测试已经会让契约里缺失的已挂载路由失败,并对每个契约 operation 发跨租户探针。但原切片 A 基线的 22 条内部路由没有任何门禁,没有探针覆盖低于读权限或有读但无该族权限的调用方,也没有任何东西把一条路由与它应遵循的准入规则绑在一起 —— 于是一条路由可能带着错误的校验落地而所有测试保持全绿,而这个面还在快速增长,这恰恰是最要紧的失效模式。

## 2. 现状

Expand All @@ -32,7 +32,7 @@
| 生命周期(close、archive、unarchive、delete)+ cwd 变更 | `POST …/close` / `…/archive` / `…/unarchive`、`DELETE`、`POST …/cwd`,及 WebShell 孪生 | `requireWorkspaceCreator`(先 can_read 再创建命令行) | 403 `session_operation_forbidden` |
| Action(审批)回答 | `POST …/actions/{id}/responses`、WebShell `actions/respond` | `requireOwner`(creator_actor_key,回退创建命令) | 403 `action_forbidden` |

其余已实现的规则形态:绑定读取与全部 list/stream/catalog 路由要求 `can_read`(否则 404);绑定创建要求 actor + `can_create` + `ACTIVE` Workspace(按失败点返回 401/404/403/409);artifact 字节读取叠加部署策略门(`403 artifact_content_forbidden`);Workspace 发现只列出 `can_read` 行(无 actor 返回 401);legacy(未绑定)Session 与 agent 定义是**租户级**的 —— 租户内任何 actor 今天都可以改它们;内部 store/publication 路由准入 writer HMAC 凭据而非 actor。公开面是 `/v1/agents/**` 加 `/api/agent/web-shell/v1/**`(`PublicSurface`),由十个 Spring controller 实现 —— 第 10 节的矩阵枚举当前的 32 条公开 + 24 条 WebShell + 22 条内部路由(切片 A 门禁实计共 78 条)。
其余已实现的规则形态:绑定读取与全部 list/stream/catalog 路由要求 `can_read`(否则 404);绑定创建要求 actor + `can_create` + `ACTIVE` Workspace(按失败点返回 401/404/403/409);artifact 字节读取叠加部署策略门(`403 artifact_content_forbidden`);Workspace 发现只列出 `can_read` 行(无 actor 返回 401);legacy(未绑定)Session 与 agent 定义是**租户级**的 —— 租户内任何 actor 今天都可以改它们;内部 store/publication 路由准入 writer HMAC 凭据而非 actor。公开面是 `/v1/agents/**` 加 `/api/agent/web-shell/v1/**`(`PublicSurface`),由十个 Spring controller 实现 —— 第 10 节的矩阵枚举当前的 32 条公开 + 24 条 WebShell + 24 条内部路由(含 L3 两条授权入口,门禁实计共 80 条)。

workspace registry/access 行没有任何生产置备路径 —— 今天只有测试与 fixture 入口写它们,部署环境靠带外方式写入;全仓没有 role 列、owner 列,也没有按租户存放 actor 的表。

Expand Down Expand Up @@ -112,7 +112,7 @@ owner 的更新路径(移交命令)是建在此列之上的后续切片;

注册表放在 `src/test/java`,因为生产代码里没有任何地方读它:下文的门禁与验收探针是它仅有的消费者,本切片如此,切片 C 也如此 —— C 的强制执行读的是存储的角色。只有出现运行时消费者时它才移到 `src/main`。

它不取代 OpenAPI 契约(`managed-agent-public-api.openapi.json`):契约仍是 56 条公开与 WebShell 路由对外发布形态的唯一来源,API 契约测试让它与已挂载的 handler 保持双射。规则类刻意不作为 `x-qwen-*` 扩展写进契约:契约是对外发布、被机器消费的(WebShell 客户端类型由它生成),它不描述 22 条内部路由,而准入规则类是服务端内部的分类。因此一条新的公开或 WebShell 路由要被点名三次 —— controller、契约、注册表 —— 且每一对都有门禁:契约测试让契约缺失的路由失败,对账门禁让注册表缺失的路由失败。
它不取代 OpenAPI 契约(`managed-agent-public-api.openapi.json`):契约仍是 56 条公开与 WebShell 路由对外发布形态的唯一来源,API 契约测试让它与已挂载的 handler 保持双射。规则类刻意不作为 `x-qwen-*` 扩展写进契约:契约是对外发布、被机器消费的(WebShell 客户端类型由它生成),它不描述 24 条内部路由,而准入规则类是服务端内部的分类。因此一条新的公开或 WebShell 路由要被点名三次 —— controller、契约、注册表 —— 且每一对都有门禁:契约测试让契约缺失的路由失败,对账门禁让注册表缺失的路由失败。

### D6 —— 构建门禁

Expand Down Expand Up @@ -179,14 +179,14 @@ A ∥ B 是安全的:文件不相交(A 纯新增;B 改 store 侧)。C

## 10. Surface 路由矩阵(切片 A 注册表,双语摘要)

切片 A 头的 `api/SurfaceRegistry.java` 携带 78 条路由常量:十个
controller 的 32 公开 + 24 WebShell + 22 internal handler 方法。门禁从扫描推导一切,计数只是信息,不是被断言的常量。
与 L3 整合后的 `api/SurfaceRegistry.java` 携带 80 条路由常量:十个
controller 的 32 公开 + 24 WebShell + 24 internal handler 方法(含 L3 两条授权入口)。门禁从扫描推导一切,计数只是信息,不是被断言的常量。

规则类按今天的准入命名:`WORKSPACE_CREATE`(2)、`READER`(24)、
`READER_ACTOR`(6)、`READER_ACTOR_POLICY`(1)、`OPERATOR` 作为今天的
submitter 族(4)、`OWNER` 作为今天的 creator 各族 —— lifecycle、cwd
与 Action respond(12)、`WORKSPACE_DISCOVERY`(4)、`TENANT_SCOPED`
(3)、`INTERNAL_WRITER`(22)。设计列出的 `legacy_create` 与
(3)、`INTERNAL_WRITER`(24)。设计列出的 `legacy_create` 与
`legacy_tenant` 两个名字保留在类的文档里,作为 legacy 分支的名字:
每条路由恰有一个规则类,按分离规则取的是绑定 Session 的类。切片 C
会把 cwd 与 Action respond 从 `OWNER` 翻到 `OPERATOR`,归一
Expand Down Expand Up @@ -253,6 +253,8 @@ submitter 族的拒绝码,并且只有在探针需要不同期望时才拆开
| `POST /api/agent/web-shell/v1/artifacts/query` | WEBSHELL | ARTIFACT_LIST | READER_ACTOR |
| `POST /api/agent/web-shell/v1/workspaces/query` | WEBSHELL | WORKSPACE_LIST | WORKSPACE_DISCOVERY |
| `POST /api/agent/web-shell/v1/workspaces/get` | WEBSHELL | WORKSPACE_GET | WORKSPACE_DISCOVERY |
| `POST /internal/managed-session-store/v1/sessions/{sessionId}/execution:authorize` | INTERNAL | STORE_EXECUTION_AUTHORIZE | INTERNAL_WRITER |
| `POST /internal/managed-session-store/v1/sessions/{sessionId}/lifecycle:authorize` | INTERNAL | STORE_LIFECYCLE_AUTHORIZE | INTERNAL_WRITER |
| `POST /internal/managed-session-store/v1/sessions/{sessionId}/writers:acquire` | INTERNAL | STORE_WRITER_ACQUIRE | INTERNAL_WRITER |
| `POST /internal/managed-session-store/v1/sessions/{sessionId}/writers:renew` | INTERNAL | STORE_WRITER_RENEW | INTERNAL_WRITER |
| `POST /internal/managed-session-store/v1/sessions/{sessionId}/writers:seal` | INTERNAL | STORE_WRITER_SEAL | INTERNAL_WRITER |
Expand Down
Loading
Loading