规划移除GameAgent宿主运行时间上限 #652

Merged
lhk229 merged 4 commits from plan/remove-gameagent-runtime-time-limits into master 2026-10-06 18:13:40 +08:00
Member

补充移除累计执行与整轮墙钟上限的行为规范
新增里程碑及实施计划,明确保留独立超时与生命周期控制
明确删除退役代码并限制旧配置和执行账本的数据迁移范围

补充移除累计执行与整轮墙钟上限的行为规范 新增里程碑及实施计划,明确保留独立超时与生命周期控制 明确删除退役代码并限制旧配置和执行账本的数据迁移范围
lhk229 added 1 commit 2026-10-06 16:32:32 +08:00
规划移除GameAgent宿主运行时间上限
Project CI / AI game creator shell Rust lane 1/2 (pull_request) Has been cancelled
Project CI / AI game creator shell Rust lane 2/2 (pull_request) Has been cancelled
Project CI / AI game creator shell Rust crates (pull_request) Has been cancelled
Project CI / Backend tests (pull_request) Has been cancelled
Project CI / Native shell tests (pull_request) Has been cancelled
Project CI / Frontend tests (pull_request) Has been cancelled
Project CI / Repository checks (pull_request) Has been cancelled
Project CI / AI game creator shell web tests (pull_request) Has been cancelled
f33b7be0ca
补充移除累计执行与整轮墙钟上限的行为规范
新增里程碑及实施计划,明确保留独立超时与生命周期控制
明确删除退役代码并限制旧配置和执行账本的数据迁移范围
lhk229 added 1 commit 2026-10-06 17:06:48 +08:00
移除GameAgent宿主运行时间上限
Project CI / AI game creator shell Rust lane 1/2 (pull_request) Has been cancelled
Project CI / AI game creator shell Rust lane 2/2 (pull_request) Has been cancelled
Project CI / AI game creator shell Rust crates (pull_request) Has been cancelled
Project CI / Backend tests (pull_request) Has been cancelled
Project CI / Native shell tests (pull_request) Has been cancelled
Project CI / Frontend tests (pull_request) Has been cancelled
Project CI / Repository checks (pull_request) Has been cancelled
Project CI / AI game creator shell web tests (pull_request) Has been cancelled
e8c6846689
删除累计执行与整轮墙钟限制、配置字段及专属计时任务
迁移旧配置与执行账本,保留原回合身份、用时和终态
保留Codex与Claude独立超时、取消、进程清理和交付复核
补充长回合、配置恢复与账本迁移回归并更新提示词和规范
记录257项定向测试及类型检查结果和未验证平台边界
lhk229 added 1 commit 2026-10-06 17:07:09 +08:00
merge latest master
Project CI / AI game creator shell Rust lane 1/2 (pull_request) Has been cancelled
Project CI / AI game creator shell Rust lane 2/2 (pull_request) Has been cancelled
Project CI / AI game creator shell Rust crates (pull_request) Has been cancelled
Project CI / Backend tests (pull_request) Has been cancelled
Project CI / Native shell tests (pull_request) Has been cancelled
Project CI / Frontend tests (pull_request) Has been cancelled
Project CI / Repository checks (pull_request) Has been cancelled
Project CI / AI game creator shell web tests (pull_request) Has been cancelled
74996e88fc
lhk229 reviewed 2026-10-06 17:22:03 +08:00
lhk229 left a comment
Author
Member

Summary

This change removes the Direct host cumulative-execution and wall-clock caps (maxExecutionSeconds / maxTurnSeconds, ledger maxExecutionMs / maxTurnMs), bumps the execution ledger to agc-direct-execution.v4, and keeps delivery-review counts, cancellation, process-exit proof, and the Codex/Claude independent timeouts. The ledger migration and the in-memory config strip look consistent with that goal, but GUI startup still deserializes saved configs through deny_unknown_fields before the new migration runs, so existing AppData files that contain the retired fields fail setup. Prompt and shared-decision text also still describe a host time budget the runtime no longer enforces.

Issue counts by severity

  • bugs: 1
  • suggestions: 2
  • nits: 0
## Summary This change removes the Direct host cumulative-execution and wall-clock caps (`maxExecutionSeconds` / `maxTurnSeconds`, ledger `maxExecutionMs` / `maxTurnMs`), bumps the execution ledger to `agc-direct-execution.v4`, and keeps delivery-review counts, cancellation, process-exit proof, and the Codex/Claude independent timeouts. The ledger migration and the in-memory config strip look consistent with that goal, but GUI startup still deserializes saved configs through `deny_unknown_fields` before the new migration runs, so existing AppData files that contain the retired fields fail setup. Prompt and shared-decision text also still describe a host time budget the runtime no longer enforces. ## Issue counts by severity - bugs: 1 - suggestions: 2 - nits: 0
@@ -53,2 +53,2 @@
"agc_delivery_status.description": "只读查询本轮合同、视觉/玩法证据评估、时间预算和终态;ready不会自动结束执行,正常响应结束后才复核。未登记不阻断普通操作或正常回复。completed、exhausted或interrupted后停止新操作;未通过项可在剩余预算内处理。",
"agc_run_validation.description": "运行构建或定点测试:purpose=build只允许npm run build;purpose=test(缺省)允许node --test或npm测试脚本。与内置试玩和原生执行共享宿主时间预算,返回实际退出码与有界输出,真实完成回执可满足冻结合同。超限后基于已有证据收尾,不切换工具绕过。",
"agc_delivery_status.description": "只读查询本轮合同、视觉/玩法证据评估、已用执行时间、交付复核次数和终态;ready不会自动结束执行,正常响应结束后才复核。未登记不阻断普通操作或正常回复。completed、exhausted或interrupted后停止新操作;原回合活动且交付复核次数未耗尽时可处理未通过项。",
"agc_run_validation.description": "运行构建或定点测试:purpose=build只允许npm run build;purpose=test(缺省)允许node --test或npm测试脚本。与内置试玩和原生执行共享宿主回合归属与操作控制,返回实际退出码与有界输出,真实完成回执可满足冻结合同。回合关闭后停止新操作,不切换工具绕过。",
Author
Member

[suggestion] agc_run_validation.description now says playtest and native execution share host turn ownership and operation control, but agc_browser_playtest.description (line 46) still tells the model it “与 agc_run_validation 共用当前回合预算”. That is the old shared time-budget wording. The host no longer enforces it, and delivery status no longer returns maxExecutionMs, so the model can still conserve or try to route around a budget that does not exist. agc_browser_playtest.parameters.attempt (“不能用此字段重置预算”) is still accurate for the persisted attempt counter and can stay.

Suggestion: Change the playtest description to the same operation-control wording as agc_run_validation, and drop “回合预算” unless it explicitly means the remaining delivery-review count.

**[suggestion]** `agc_run_validation.description` now says playtest and native execution share host turn ownership and operation control, but `agc_browser_playtest.description` (line 46) still tells the model it “与 agc_run_validation 共用当前回合预算”. That is the old shared time-budget wording. The host no longer enforces it, and delivery status no longer returns `maxExecutionMs`, so the model can still conserve or try to route around a budget that does not exist. `agc_browser_playtest.parameters.attempt` (“不能用此字段重置预算”) is still accurate for the persisted attempt counter and can stay. **Suggestion:** Change the playtest description to the same operation-control wording as `agc_run_validation`, and drop “回合预算” unless it explicitly means the remaining delivery-review count.
lhk229 marked this conversation as resolved
@@ -3995,2 +3995,4 @@
read_game_creator_snapshot_file_to_string(read_path, "客户端配置", 256 * 1024)?
};
// 恢复读取备份时迁移实际读取的文件,避免替换主文件失败前删掉唯一备份。
let content = migrate_game_creator_runtime_limits(read_path, content)?;
Author
Member

[bug] Retired validation fields are stripped only inside read_game_creator_config_file. GUI setup never reaches that path first. configure_game_creator_runtime_config_dir calls migrate_legacy_game_creator_agent_mode (and that function returns an error out of Tauri setup) before set_game_creator_runtime_config_dir. migrate_legacy_game_creator_agent_mode reads the raw file and serde_json::from_strs it into GameCreatorAppConfigFile, whose validation field is DirectValidationConfig with deny_unknown_fields. Any saved config that still has validation.maxExecutionSeconds or validation.maxTurnSeconds therefore fails with “解析客户端配置失败” and the app does not start. Those keys are not hypothetical: persist_game_creator_app_config writes the full GameCreatorAppConfig, and the previous DirectValidationConfig always serialized both second fields (model changes and reasoning-effort changes both persist). The new migration tests only call read_game_creator_config_file, so they miss this startup parser. A second gap on the same path: even after a successful strip, write-back requires game_creator_config_path_is_runtime_managed, which is false until the runtime dir is set at the end of configure_game_creator_runtime_config_dir. A normal GUI launch without --config-dir would not persist the migration if the strip were only done in memory there.

Suggestion: Strip maxExecutionSeconds and maxTurnSeconds before the typed parse in migrate_legacy_game_creator_agent_mode (or call migrate_game_creator_runtime_limits on the raw bytes first). Set the runtime config dir before that write-back so the file being migrated is treated as managed. Add a regression that runs migrate_legacy_game_creator_agent_mode against a config containing the retired fields and asserts setup can continue and the keys are gone on disk.

**[bug]** Retired validation fields are stripped only inside `read_game_creator_config_file`. GUI setup never reaches that path first. `configure_game_creator_runtime_config_dir` calls `migrate_legacy_game_creator_agent_mode` (and that function returns an error out of Tauri `setup`) before `set_game_creator_runtime_config_dir`. `migrate_legacy_game_creator_agent_mode` reads the raw file and `serde_json::from_str`s it into `GameCreatorAppConfigFile`, whose `validation` field is `DirectValidationConfig` with `deny_unknown_fields`. Any saved config that still has `validation.maxExecutionSeconds` or `validation.maxTurnSeconds` therefore fails with “解析客户端配置失败” and the app does not start. Those keys are not hypothetical: `persist_game_creator_app_config` writes the full `GameCreatorAppConfig`, and the previous `DirectValidationConfig` always serialized both second fields (model changes and reasoning-effort changes both persist). The new migration tests only call `read_game_creator_config_file`, so they miss this startup parser. A second gap on the same path: even after a successful strip, write-back requires `game_creator_config_path_is_runtime_managed`, which is false until the runtime dir is set at the end of `configure_game_creator_runtime_config_dir`. A normal GUI launch without `--config-dir` would not persist the migration if the strip were only done in memory there. **Suggestion:** Strip `maxExecutionSeconds` and `maxTurnSeconds` before the typed parse in `migrate_legacy_game_creator_agent_mode` (or call `migrate_game_creator_runtime_limits` on the raw bytes first). Set the runtime config dir before that write-back so the file being migrated is treated as managed. Add a regression that runs `migrate_legacy_game_creator_agent_mode` against a config containing the retired fields and asserts setup can continue and the keys are gone on disk.
lhk229 marked this conversation as resolved
@@ -9808,3 +9808,3 @@
- 普通工具准入只检查原回合活动状态、时间预算、并发和既有权限,不要求先登记交付合同;成功/失败/取消只结算本次操作,删除全局 Draining 与执行/返修批次计数。
- 普通工具准入只检查原回合活动状态、并发和既有权限,不要求先登记交付合同;成功/失败/取消只结算本次操作,删除全局 Draining 与执行/返修批次计数。
- 验证失败和源码漂移影响对应证据,不阻断无关工作。远端不确定结果沿资源自身 operation/幂等记录核对;本地执行器失控或持久状态损坏仍结束回合。
- 保留累计执行时间、整轮墙钟、原生执行前审批、关闭时清理与原回合写入/付费提交检查。模型执行结束时先关闭准入,确认清理后才允许交付反馈继续;普通失败不进入关闭阶段。
Author
Member

[suggestion] This PR edits the 2026-10-04 “普通操作与交付复核解耦” entry but leaves it saying, in the present tense, “保留累计执行时间、整轮墙钟”. That now contradicts both the code and the new 2026-10-06 decision. The same file’s 2026-10-05 exit-proof entry (line 9833, in this diff) still says a no-contract close newly produces a budget report and should prefer it; close no longer creates that report. docs/project-memory/shared-memory/pitfalls.md (Claude timeout note) still says DirectProject maxTurnSeconds fires before CLAUDE_CODE_TURN_MAX_DURATION, which this PR’s claude_code_cli.rs comment correctly removed.

Suggestion: In the edited 2026-10-04 and 2026-10-05 entries, point at the 2026-10-06 decision instead of restating the removed caps and the budget report. Update the Claude pitfall so the 45-minute hard cap and silence budget are the remaining limits.

**[suggestion]** This PR edits the 2026-10-04 “普通操作与交付复核解耦” entry but leaves it saying, in the present tense, “保留累计执行时间、整轮墙钟”. That now contradicts both the code and the new 2026-10-06 decision. The same file’s 2026-10-05 exit-proof entry (line 9833, in this diff) still says a no-contract close newly produces a budget report and should prefer it; close no longer creates that report. `docs/project-memory/shared-memory/pitfalls.md` (Claude timeout note) still says DirectProject `maxTurnSeconds` fires before `CLAUDE_CODE_TURN_MAX_DURATION`, which this PR’s `claude_code_cli.rs` comment correctly removed. **Suggestion:** In the edited 2026-10-04 and 2026-10-05 entries, point at the 2026-10-06 decision instead of restating the removed caps and the budget report. Update the Claude pitfall so the 45-minute hard cap and silence budget are the remaining limits.
lhk229 marked this conversation as resolved
lhk229 added 1 commit 2026-10-06 17:40:47 +08:00
修复宿主时间上限移除后的启动配置迁移
Project CI / AI game creator shell Rust lane 1/2 (pull_request) Successful in 6m31s
Project CI / AI game creator shell Rust lane 2/2 (pull_request) Successful in 5m33s
Project CI / AI game creator shell Rust crates (pull_request) Successful in 4m22s
Project CI / Frontend tests (pull_request) Successful in 3m47s
Project CI / Backend tests (pull_request) Successful in 8m38s
Project CI / AI game creator shell web tests (pull_request) Successful in 3m7s
Project CI / Repository checks (pull_request) Successful in 6m56s
Project CI / Native shell tests (pull_request) Successful in 9m31s
d681b24f7d
在桌面启动严格解析前清理退役字段并沿启动入口安全写回
补充运行配置目录尚未注册时主配置与本地覆盖迁移回归
修正浏览器试玩提示及共享记忆中的旧时间预算说明
验证19项配置测试、24项提示词测试及文档编码格式检查
lhk229 merged commit 9f1c5df446 into master 2026-10-06 18:13:40 +08:00
lhk229 deleted branch plan/remove-gameagent-runtime-time-limits 2026-10-06 18:13:40 +08:00
Sign in to join this conversation.