Skip to content

fix(ego-source-reader): preserve native control stops when CLI output is discarded - #6261

Merged
huangruiteng merged 5 commits into
mainfrom
codex/ego-reader-control-race-20261011
Oct 11, 2026
Merged

huangruiteng merged 5 commits into
mainfrom
codex/ego-reader-control-race-20261011

Conversation

@loopx-agent

Copy link
Copy Markdown
Collaborator

When Ego changes a TaskSpace to user control or inactive after inventory, its native hard-stop sink can discard the console marker. The source reader then reports a generic browser failure and loses the control boundary needed for autonomous continuation.

Preserve only the two existing native stop codes in a private temporary file before rethrowing, and return source_reader_not_agent_owned while discarding partial output. Cleanup is automatic; ordinary failures retain their existing behavior. Text and image regression cases exercise resolve, navigation and extraction in real Node children, including the output-discarding sink and absence of retries or replacement spaces.

Validation on c2427f2 against df826263:

  • 256 focused tests passed (source reader, dashboard command and Chat bundle); rebuilt bundle verified.
  • Ruff, mypy (19 configured sources), CLI output-budget regression, standard premerge canaries and public-boundary scan passed.
  • Full Python suite on frozen parent b924616: 20,808 passed, 343 skipped, 517 subtests passed, zero failures. All three changed blobs are identical at the PR head; the full suite was not rerun on the newer integration head.
  • Controlled native SDK rejection, owned-space shutdown checks and a real rendered browser read were verified. Live human handoff/return is still unverified; this PR does not grant control, force a takeover or expand protected actions.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
…rol-race-20261011

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent | gpt-6.1-sol | OpenAI | runtime_reported | xhigh

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

APPROVE — 精确 head c2427f2da3b21d487eec0ff3df6b6d67bdc47ee6 未发现阻断问题。COMMENTED 是作者账户下的评审记录,平台批准和 merge 权限仍需单独判断。

动机

启用可选公开来源读取器的用户,在读取中途失去浏览器控制时需要准确的停止原因。旧适配器虽然停止操作,但 Ego 丢弃控制停止时的控制台输出,调用方只能看到普通读取失败,无法区分应等待控制归还还是处理技术错误。本次源码、独立安装包和真实 Ego CLI 验证:两个原生停止码都返回既有的 source_reader_not_agent_owned,部分内容不返回,不重试、不替换或夺取 Page。范围为既有可选适配器的错误传输;不新增配置、控制权限或发布权限,不证明真人交接已验收。

改动思路

保留现有 Python provider IO owner;同一 _run 覆盖文本、图片和生命周期调用,仅用私有短期文件跨越 Ego 会丢弃的输出通道。本 PR 交付可用的停止原因传输与负例回归,不扩展共享控制面、浏览器控制模型或普通默认 host。不修复会继续丢失已复现的停止原因;解析错误文案或控制台 sentinel 都无法解决输出被丢弃的问题。改 Ego 本体则扩大了独立部署边界。Python 留在现有 provider IO 归属,不创建另一份通用控制面判断。

具体改动

  • _run(loopx/extensions/ego_source_reader.py:186)在原固定脚本外捕获异常,只把精确的 EGO_TASK_SPACE_USER_IN_CONTROL / EGO_TASK_SPACE_INACTIVE 写进私有临时目录;随后重新抛出。Python 读回后生成既有停止结果并丢弃部分 stdout/stderr,目录按调用生命周期清理。
  • _read(同文件 :432)沿用已有停止解码;普通错误、超时、URL/origin 拒绝及确认 not-found 后的单次恢复保持。read_public_image(:489)失败只返回文本错误,不带部分图片。
  • 新参数化测试执行生产脚本的真实 Node 子进程,模型化 SDK 拒绝和输出丢弃。文档说明传输、清理和权限边界,明确没有证明真人交接。

先读接受合同 docs/integrations/ego-source-reader.md,不可变版本 df826263926651ab9c50acee182ef96e2a60ff4b,再读完整三文件 diff。验收映射:ownership-stop 保留 Page、不再读取或捕获;ordinary-failure 不把技术错误当交接;sanitized-errors 省略原始诊断;scoped-host 仍只由显式 MCP entry 激活;owned-shutdown 仍只清理自己的且当前 Agent-owned 的空间。均有对应真实调用或负例,候选文档没有反向定义旧验收。

对主干的风险

最强反例是已知停止修好了,却把未知错误也当用户控制、泄露部分内容或引发额外重试。独立冻结 38 场景覆盖文本/图片及 resolve、navigation、wait、extraction、capture:base 18 个停止分类断言失败;head 与独立 wheel 各 38/38 通过;其余 20 个完整观察不经语义归一化即一致。每案只调用一次子进程,临时目录清理均成立;真实子进程 timeout/OSError 的清理另行通过。

实际安装的 Ego CLI 受控异常验证中,base 丢弃两个停止码,head 保留;普通异常仍由普通错误路径处理。这证明原生输出 sink 传输,不等于真人接管及交还控制的测试。独立安装包在源码外以 Python -I 运行:真实 Ego Page 连续读取同一公开页面、非法 URL 拒绝、自己拥有的空间关闭回读通过;真实 stdio MCP 两个工具的广告和读取回读也通过。

独立运行 198 项 reader 测试、15 项普通 MCP/host 测试、Ruff、配置中的 mypy(19 文件)、正常 chat bundle/wheel 构建和 diff 检查通过。先跑 diff semantic advisory,再跑完整 semantic smoke;无新共享词汇,完整扫描的 45 个未解决 producer site 仍保留。默认关闭时 base/head/wheel 的未配置和非法 URL 结果一致;普通 host 工具/权限未扩展。CI 未查询、轮询或等待。

安装探针曾错误要求页面标题必须出现在正文;已保存的实际结果确认合法 title 和非空正文。修正该测试假设后复用已记录的同一 Page 完成旅程,未把这个探针失败写成产品修复。Python 3.14 依赖 warning 保留;当前 stdio 与测试通过。完整全套、真人交接和新增真实图片 capture 未在本次资格化,作者旧全套结果未作为独立证据。

我的整体评价

这是边界清楚且可回滚的现有 provider 修复:实际调用方拿到准确停止原因,后续合法同空间读取仍可用,没有新增操作步骤。未来改动适配性检查认为现有 _run 与 decoder 已是合适公共边界,不需要再拆 helper、增持久状态或搬到第二个 TS owner。当前 native code 用精确匹配,不用 substring 文案规则;临时文件只输送拒绝,不能授予操作权。复用经验中的“首个有用结果与后续读取”建议;恢复 RFC 的更广阶段不适用于此限定修复,也不宣称经验效用已证明。

无阻断 finding。APPROVE 只绑定本 head;依赖 warning 与未验证的人机交接保留,维护者 merge 和当前平台保护独立处理。

English verdict: APPROVE - c2427f2da3b21d487eec0ff3df6b6d67bdc47ee6; both native control stops survive the actual discarded-output sink, without retry or partial content. Same38-input base/head/wheel comparison,198reader+15ordinary-host tests,and installed actual Ego/stdin MCP passed;live human handoff remains unverified. No merge performed.

@loopx-agent

Copy link
Copy Markdown
Collaborator Author

Reviewer: model_agent | gpt-6.1-sol | OpenAI | runtime_reported | xhigh

English verdict: APPROVE - c2427f2da3b21d487eec0ff3df6b6d67bdc47ee6. No blocking finding.

Motivation

Users of the explicitly enabled rendered-source reader need a truthful reason when browser control changes during a read. Previously the operation stopped,but Ego discarded console output and the adapter collapsed the native stop into a generic read failure. This can misdirect recovery. The change preserves the existing sanitized stop result without retry,Page replacement,takeover or partial evidence.

Design

The existing Python provider IO owner wraps its fixed script,copies only two exact native codes into a private per-call temporary file,then rethrows. The existing decoder consumes that result. Ordinary failure,origin/URL validation,30-second budget,live ownership and owned shutdown remain in their current owners. A console parser cannot restore discarded data;changing Ego globally would be a larger independently deployed repair.

Whole change

The three-file diff changes _run,adds18parameterized child-process regressions and documents the error transport/privacy/authority limits. No new input,persistent state,actor lifecycle or automatic host activation is introduced. Accepted specification: docs/integrations/ego-source-reader.md at df826263926651ab9c50acee182ef96e2a60ff4b. Criteria ownership-stop,ordinary-failure,sanitized-errors,scoped-host,owned-shutdown map to current code and decisive checks. The candidate documentation is disclosure,not the source of prechange acceptance.

Risk and evidence

A frozen38-case oracle executes public text/image functions and production scripts in real Node children,with only the SDK rejection/sink controlled. Base fails18stop classifications;head and separately installed wheel pass38/38. The other20whole observations are identical without semantic normalization. Each case invokes one child and cleans its temporary transport. Exact unknown/prefixed-code controls remain ordinary failures.

The actual installed Ego CLI independently loses the two controlled native codes on base and preserves them on head. Installed Python-I also reads an actual public Page twice in the same owned space,rejects an invalid URL,and confirms owned shutdown;real stdio MCP tool advertisement and source readback pass. Real-child timeout/OSError cleanup passes. These observations do not qualify a live human handoff/control return or new live image capture.

Passed independently:198reader tests,15ordinary-host tests,Ruff,configured19-file mypy,normal frontend/wheel build,diff checks and full semantic smoke after the diff advisory. The scan retains45unresolved producer sites. Disabled/unconfigured/invalid results match base/head/wheel;ordinary host contracts do not acquire the optional tools. CI was not fetched,polled or awaited.

An initial live probe incorrectly required the title inside body text. Saved output demonstrates successful nonempty rendered content with the correct title. The corrected probe reuses its recorded Page and completes the journey;this is a test-assumption correction,not a claimed product fix. The Python3.14 dependency warning is retained while current stdio/tests pass. The author's historical full-suite claim is not independent evidence.

Overall assessment

The bounded repair is useful,proportionate and placed in the existing optional provider. The future-facing pass finds no needed companion abstraction:retain the common _run and existing decoder. The reused review experience informs useful result/repeated continuation checks;its broader recovery-RFC stages do not apply and no causal memory-utility claim is made. This author-owned COMMENTED approval is an exact-head review record;GitHub approval and maintainer merge authority remain separate. No merge performed.

@huangruiteng
huangruiteng merged commit a3eec33 into main Oct 11, 2026
0 of 5 checks passed
@huangruiteng
huangruiteng deleted the codex/ego-reader-control-race-20261011 branch October 11, 2026 19:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants