清理旧策划修订写入入口并记录认证契约冲突

删除无生产调用的用户修订写入函数,保留持久记录兼容与门禁
调整原有门禁测试的历史记录夹具,保持行为断言
将 OAuth 契约冲突与关闭条件记录到 AGC 主方案
警告清单仅保留 AuthBridge 暂缓状态及主方案链接
This commit is contained in:
2026-09-23 17:58:17 +00:00
parent c62a911745
commit 7d6fff577d
3 changed files with 60 additions and 66 deletions
@@ -532,19 +532,10 @@ pub(crate) fn mark_static_delegate_delivery_ready_with_result_at(
/// claim 里的 `structuredResult` 是「父 Agent 在那个 action 上观察到了什么」的冻结
/// 快照;delivery 是当前真相。两者绝大多数时候必须逐字相等——不等就是漂移或篡改。
///
/// 唯一的例外是审批:用户在审批卡上点「修改 / 退回」后,
/// `mark_static_delegate_delivery_user_revision_requested_at` 会把 delivery 从
/// `EvidenceReady` 原地改写成 `UserRevisionRequested`,而 claim 快照仍停在
/// `EvidenceReady`。那不是漂移,是一次只由审批产生、且只能朝这个方向走的合法转移;
/// 快照记的那句「当时观察到 evidence-ready」现在依然为真,不该被改写。
///
/// 按全等判会把它当成冲突:`agent.run_status` 每次重放这条 claim 都 failed,
/// Supervisor 永远拿不到回执、也就永远建不出修订委派。生产实测卡死在第 43 轮空转,
/// 报「静态委派 claim 与 delivery 身份或结果冲突」。原型没有 claim 这层快照,单一
/// 真相就地改,结构上不存在这个冲突——这里翻译的是同一个语义:比较的是「delivery 是
/// 不是 receipt 的合法后继」,不是「两者永远全等」。
///
/// 放行面刻意压到最小:除 `contractStatus` 外每个字段都必须逐字不变,且方向唯一。
/// 兼容旧策划审批留下的持久记录:delivery 已从 `EvidenceReady` 转为
/// `UserRevisionRequested`,claim 仍保存当时观察到的 `EvidenceReady`。
/// 旧审批写入入口已退役,这里只识别存量记录的合法后继,不要求恢复旧写入链。
/// 除 `contractStatus` 外每个字段都必须逐字不变,且仅允许上述单向转移。
fn static_delegate_structured_result_follows_claim_snapshot(
snapshot: Option<&StaticDelegateStructuredResult>,
current: Option<&StaticDelegateStructuredResult>,
@@ -565,42 +556,6 @@ fn static_delegate_structured_result_follows_claim_snapshot(
rebased == *snapshot
}
/// Mark an already claimed, evidence-ready planning delivery as waiting for a
/// user-requested revision. Approval is the only producer of this durable
/// status; keeping the transition here makes its evidence precondition and
/// idempotency explicit instead of allowing a generic delivery writer to
/// manufacture the state.
pub(crate) fn mark_static_delegate_delivery_user_revision_requested_at(
root: &Path,
parent_agent_id: &str,
parent_run_id: &str,
delegation_id: &str,
) -> Result<StaticDelegateDeliveryRecord, String> {
validate_static_delegate_id(parent_agent_id, "parentAgentId", 96)?;
validate_static_delegate_id(parent_run_id, "parentRunId", 160)?;
validate_static_delegate_id(delegation_id, "delegationId", 160)?;
let mut delivery = read_static_delegate_delivery_at(root, delegation_id)?
.ok_or_else(|| format!("静态委派 delivery 不存在:{delegation_id}"))?;
if delivery.parent_agent_id != parent_agent_id || delivery.parent_run_id != parent_run_id {
return Err("用户修订只能改写同一 Supervisor 父 run 的 delivery".to_string());
}
if delivery.status != StaticDelegateDeliveryStatus::ClaimedByParent {
return Err("用户修订只能改写已由 Supervisor 认领的 delivery".to_string());
}
let Some(result) = delivery.structured_result.as_mut() else {
return Err("用户修订的原 delivery 缺少 structuredResult".to_string());
};
match result.contract_status {
StaticDelegateContractStatus::UserRevisionRequested => return Ok(delivery),
StaticDelegateContractStatus::EvidenceReady => {}
_ => return Err("用户修订只能从 EvidenceReady delivery 派生".to_string()),
}
result.contract_status = StaticDelegateContractStatus::UserRevisionRequested;
delivery.updated_at = unix_timestamp();
write_static_delegate_delivery_at(root, &delivery)?;
Ok(delivery)
}
pub(crate) fn suppress_static_delegate_delivery_at(
root: &Path,
expected: &StaticDelegateDeliveryRecord,
@@ -3297,16 +3252,10 @@ mod tests {
parent_run_id,
"m1c1-user-revision-barrier-first",
None,
StaticDelegateContractStatus::EvidenceReady,
StaticDelegateContractStatus::UserRevisionRequested,
);
// 直接构造旧审批已写入的持久状态,验证现役 barrier 的读取行为。
write_static_delegate_delivery_at(&root, &first).expect("write first delivery");
mark_static_delegate_delivery_user_revision_requested_at(
&root,
GAME_CREATOR_PROJECT_SUPERVISOR_AGENT_ID,
parent_run_id,
&first.delegation_id,
)
.expect("mark first delivery for user revision");
let first_barrier = static_delegate_completion_barrier_at(
&root,
@@ -3362,13 +3311,13 @@ mod tests {
"the previous revision is satisfied once its continuation is claimed"
);
mark_static_delegate_delivery_user_revision_requested_at(
&root,
GAME_CREATOR_PROJECT_SUPERVISOR_AGENT_ID,
parent_run_id,
&continuation.delegation_id,
)
.expect("mark a repair-node delivery for the second revision");
continuation
.structured_result
.as_mut()
.expect("continuation structured result")
.contract_status = StaticDelegateContractStatus::UserRevisionRequested;
write_static_delegate_delivery_at(&root, &continuation)
.expect("write repair-node delivery awaiting a second revision");
let second_barrier = static_delegate_completion_barrier_at(
&root,
GAME_CREATOR_PROJECT_SUPERVISOR_AGENT_ID,