Skip to content

refactor(public-safety): centralize compact identifier shapes - #5351

Open
karenchuu wants to merge 1 commit into
loopx-project:mainfrom
karenchuu:karenchuu/compact-identifier-shapes-owner
Open

karenchuu wants to merge 1 commit into
loopx-project:mainfrom
karenchuu:karenchuu/compact-identifier-shapes-owner

Conversation

@karenchuu

Copy link
Copy Markdown
Contributor

Summary

Centralizes the identical compact public-safe reference, compact token, and module-qualified surface regular expressions in loopx/public_safe_text.py. Reward Memory, Semantic Preference, Decision Context, and Material Lifecycle retain their existing field-level behavior and error messages while consuming the shared compiled patterns.

Also adds a focused ownership regression test that verifies the listed consumers share the owner objects (is, not ==) and no longer restate the literals.

Delivery brief

  • Goal/source: remove demonstrated duplicated identifier/surface-shape decisions across the named capability contracts.
  • Current gap: three shape rules were independently compiled in 12 modules, so a one-character edit in any one of them would silently drift the others.
  • Observable result: each migrated consumer aliases the canonical compiled pattern; validation semantics remain unchanged.
  • Owning boundary: loopx/public_safe_text.py owns syntax shapes only, while callers retain contract-specific field names, thresholds, policy and diagnostics.

Relationship to #5350 and #5296

This replaces #5350, which carried the same content from a different account; #5350 is closed with a pointer here.

Rebased onto a7e6b826a. Two files conflict on the way because #5296 landed between the original branch point and this base: decision_context/packets.py and material_lifecycle/_validation.py no longer carry _LOCAL_PATH_RE (that check now goes through find_public_safe_local_path). Resolution kept #5296's owner call and its explanatory comments verbatim, and removed only the duplicated _TOKEN_RE literal in favour of the shared import. Both files keep a net line delta of 0, which is what preserves the two project_registry_io census sites recorded for _validation.py.

Validation

  • pytest -q tests/control_plane/test_compact_identifier_shape_owner.py — 3 passed.
  • pytest -q tests/architecture --ignore=tests/architecture/test_semantic_production.py — 1009 passed / 0 failed (2m21s); tests/architecture/test_semantic_production.py separately — 34 passed.
  • pytest -q tests/architecture/test_project_registry_io_census.py — 7 passed (needs the typescript dev dependency installed; run from a tree with node_modules).
  • pytest -q tests/capabilities tests/test_decision_context_material.py plus the new guard — 1831 passed / 9 failed / 42 skipped (4m15s). All 9 failures are in tests/capabilities/test_repository_change_window.py, which spawns the loopx console script; they reproduce identically (9 failed / 8 passed) on an unmodified worktree at a7e6b826a under the same interpreter and PATH, so they are an environment artifact of this machine and not a regression from this change.
  • examples/semantic-vocabulary-drift-smoke.py — ok. Measured counts are byte-identical between the unmodified base and this head (multi_value_twins=8/8, same_runtime_forks=11/11, conflicting_values=16/16, schema_version_same_runtime_forks=2/2), so no budget anchor moves: the three shapes were never registered as twins, and removing the duplicates does not by itself lower a budget.
  • python -m ruff check on all 14 changed files — all checks passed; python -m mypy (no arguments, as CI runs it) — Success: no issues found in 19 source files; git diff --check — clean.
  • loopx check --scan-path over public_safe_text.py, the four capability packages and the new guard — errors=0, public boundary scan clean: 77 files.
  • loopx canary premerge with the 14 changed files listed explicitly — selected=10 executed=10 failures=0 advisory_failures=0.
  • Disclosure: this run reused an already-installed local virtualenv interpreter and a node_modules symlink from another worktree (after diffing package.json dependencies and devDependencies field by field, identical) instead of a fresh uv sync --extra test, and pointed PYTHONPATH at this tree. The commands above are what actually ran, with PYTHONPATH and PATH (Node 22.23.2) set that way.

Scope

  • Changed surfaces: shared public-safe shape owner; Reward Memory, Semantic Preference, Decision Context, and Material Lifecycle Python contract validation.
  • No frontend, CLI, permission, persistence, default-off, or authority behavior changes.
  • Future-facing refactor pass: applied; this removes duplicate shape authority without changing validation behavior.
  • Not in scope: chat_action_store.py / chat_actions.py / goals/deletion_service.py each compile the same ^[A-Za-z0-9._:-]{1,200}$, and global_risks.py / global_todos.py / summary_all.py each restate the same SCHEMA_VERSION value. Those are separate owners with different contract lifetimes and are left for their own PRs rather than folded in here.

Signed-off-by: karenchuu <25980598+karenchuu@users.noreply.github.com>

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

动机

这是对 #5136 所要求的共享公共安全规则归属的一个完整、有限的维护切片,不是关闭整个治理议题。三个完全相同的标识符格式在多个能力中重复编译,后续修正容易只改一处;本次把真正相同的格式收拢,保留不同字段的脱敏与长度政策。长期维护成本降低,用户现有输入、失败提示和启用流程不变。

改动思路

复用已经存在的 public_safe_text 词法 owner,调用方仍负责字段校验、清洗、错误顺序和公共安全政策,没有增加 capability、provider、状态或通用验证框架。做法是导入共享编译对象并保留现有别名,而不是用一个更宽的正则覆盖全部字段。前者删除重复规则知识,后者会错误合并允许斜杠的引用与不允许斜杠的短 token。已检查相关旧 PR #5350、已合入的 #5296,以及议题中要求保留目的地政策的维护者说明。

具体改动

整体为 14 文件、116 行增加/24 行删除;77 行属于集中归属测试。其余是已有 owner 增加三项编译定义,以及十二个生产模块改用导入别名。没有更改十二个模块中的函数/类实现体;我逐项做了 base/head AST 对照。对象身份测试能防止再次复制编译,但不能单独证明行为一致,因此额外通过真实公共构建函数比较完整输出和错误文本。

关键代码讲解

  • public_safe_text.py:153 的 PUBLIC_SAFE_REFERENCE_PATTERN 保留原有 200 字符上限及斜杠、井号规则;它只描述格式,不能替代调用方的本地路径、凭据和字段安全检查。
  • 同文件 :156 的 COMPACT_TOKEN_PATTERN 保留 128 字符上限且不接受斜杠;:157 的 MODULE_QUALIFIED_SURFACE_PATTERN 保留小写、至少两段的模块标识规则。不同约束仍是三个对象,不是一个联合匹配器。
  • decision_context/packets.py:280 的 build_decision_evidence_packet 继续走原有 token 校验并生成无外部写入的公共证据包;semantic_preference/contract.py:538 的 application_receipt 继续分开校验 surface 与引用。两个函数实现未改,完整返回值、默认值和错误对照一致。memory_utility 的另一个 200 字符 opaque 规则以及 corpus-id 规则也没有被错误收拢。

对主干的风险

最强反例是:共享对象身份测试全绿,但新的 owner 悄悄放宽 token,导致所有调用方同时错误接受斜杠。我在进程内故意放宽 packet token 后,真实公共 packet 接受 a/b,违反独立拒绝 oracle;恢复后,原 head 正确拒绝。相同固定输入在不可变 base 与 head 上执行,115 组完整记录/异常文本一致,覆盖空值、去空白、非法首字符、Unicode、128/129 和 200/201 长度及 surface 分段。

本地验证:能力相关测试 1840 passed、42 skipped;架构测试 1043 passed;Ruff、Mypy(19 个配置内源文件)、DCO、diff hygiene 均通过。按确切 diff 执行 premerge:直接检查及 10 个选中 canary 全通过;另行公共边界扫描 52 文件、0 error。42 个跳过项属于未具备的 Linux namespace/tini 环境及未显式开启的付费 live-review 测试,不计作通过。没有运行全仓 pytest、Windows 主机或部署激活,也没有查询/等待远端 CI。新增 diff-advisory 参数在这个旧源码 parser 上不支持,返回 exit 2;支持的完整语义漂移 smoke 已通过,未将该错误伪称为成功。

语义与 CI 对齐

复用既有格式与 owner,不创建新状态词汇;全树语义检查通过。没有新增默认启用、调度义务、权限模型或协议版本;原有 disabled profile 的完整结果也在同输入对照内。前端、Lark 和 CLI 配置没有变更:此次只换词法对象归属,实际构建函数、字段和错误路径保持一致,因此不需要配套编辑器或 UI 交付。评审结论依据本地确切源码证据,远端 CI 未被用作拒绝或批准的推断来源。

我的整体评价

APPROVE,适用于 b2bdd97。长期维度改善,用户体验保持;原有可达调用方的别名值得保留,重复编译规则已删除。未来演进检查已经体现在这个窄 owner 整理中,不需要再添加抽象或迁移任务。覆盖足以支持行为保持的源码维护切片,但不等于所有平台、付费模型或整个父议题已完成。没有发现当前 head 的可复现阻断问题;该生产改动的合并仍由维护者决定。

English verdict: APPROVE - Exact shared-shape consolidation preserves the native caller contracts; focused semantic parity, negative probes and repository checks passed, with platform/live-test limits disclosed.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants