规划移除GameAgent宿主运行时间上限 #652
Reference in New Issue
Block a user
Delete Branch "plan/remove-gameagent-runtime-time-limits"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
补充移除累计执行与整轮墙钟上限的行为规范
新增里程碑及实施计划,明确保留独立超时与生命周期控制
明确删除退役代码并限制旧配置和执行账本的数据迁移范围
Summary
This change removes the Direct host cumulative-execution and wall-clock caps (
maxExecutionSeconds/maxTurnSeconds, ledgermaxExecutionMs/maxTurnMs), bumps the execution ledger toagc-direct-execution.v4, and keeps delivery-review counts, cancellation, process-exit proof, and the Codex/Claude independent timeouts. The ledger migration and the in-memory config strip look consistent with that goal, but GUI startup still deserializes saved configs throughdeny_unknown_fieldsbefore the new migration runs, so existing AppData files that contain the retired fields fail setup. Prompt and shared-decision text also still describe a host time budget the runtime no longer enforces.Issue counts by severity
@@ -53,2 +53,2 @@"agc_delivery_status.description": "只读查询本轮合同、视觉/玩法证据评估、时间预算和终态;ready不会自动结束执行,正常响应结束后才复核。未登记不阻断普通操作或正常回复。completed、exhausted或interrupted后停止新操作;未通过项可在剩余预算内处理。","agc_run_validation.description": "运行构建或定点测试:purpose=build只允许npm run build;purpose=test(缺省)允许node --test或npm测试脚本。与内置试玩和原生执行共享宿主时间预算,返回实际退出码与有界输出,真实完成回执可满足冻结合同。超限后基于已有证据收尾,不切换工具绕过。","agc_delivery_status.description": "只读查询本轮合同、视觉/玩法证据评估、已用执行时间、交付复核次数和终态;ready不会自动结束执行,正常响应结束后才复核。未登记不阻断普通操作或正常回复。completed、exhausted或interrupted后停止新操作;原回合活动且交付复核次数未耗尽时可处理未通过项。","agc_run_validation.description": "运行构建或定点测试:purpose=build只允许npm run build;purpose=test(缺省)允许node --test或npm测试脚本。与内置试玩和原生执行共享宿主回合归属与操作控制,返回实际退出码与有界输出,真实完成回执可满足冻结合同。回合关闭后停止新操作,不切换工具绕过。",[suggestion]
agc_run_validation.descriptionnow says playtest and native execution share host turn ownership and operation control, butagc_browser_playtest.description(line 46) still tells the model it “与 agc_run_validation 共用当前回合预算”. That is the old shared time-budget wording. The host no longer enforces it, and delivery status no longer returnsmaxExecutionMs, so the model can still conserve or try to route around a budget that does not exist.agc_browser_playtest.parameters.attempt(“不能用此字段重置预算”) is still accurate for the persisted attempt counter and can stay.Suggestion: Change the playtest description to the same operation-control wording as
agc_run_validation, and drop “回合预算” unless it explicitly means the remaining delivery-review count.@@ -3995,2 +3995,4 @@read_game_creator_snapshot_file_to_string(read_path, "客户端配置", 256 * 1024)?};// 恢复读取备份时迁移实际读取的文件,避免替换主文件失败前删掉唯一备份。let content = migrate_game_creator_runtime_limits(read_path, content)?;[bug] Retired validation fields are stripped only inside
read_game_creator_config_file. GUI setup never reaches that path first.configure_game_creator_runtime_config_dircallsmigrate_legacy_game_creator_agent_mode(and that function returns an error out of Taurisetup) beforeset_game_creator_runtime_config_dir.migrate_legacy_game_creator_agent_modereads the raw file andserde_json::from_strs it intoGameCreatorAppConfigFile, whosevalidationfield isDirectValidationConfigwithdeny_unknown_fields. Any saved config that still hasvalidation.maxExecutionSecondsorvalidation.maxTurnSecondstherefore fails with “解析客户端配置失败” and the app does not start. Those keys are not hypothetical:persist_game_creator_app_configwrites the fullGameCreatorAppConfig, and the previousDirectValidationConfigalways serialized both second fields (model changes and reasoning-effort changes both persist). The new migration tests only callread_game_creator_config_file, so they miss this startup parser. A second gap on the same path: even after a successful strip, write-back requiresgame_creator_config_path_is_runtime_managed, which is false until the runtime dir is set at the end ofconfigure_game_creator_runtime_config_dir. A normal GUI launch without--config-dirwould not persist the migration if the strip were only done in memory there.Suggestion: Strip
maxExecutionSecondsandmaxTurnSecondsbefore the typed parse inmigrate_legacy_game_creator_agent_mode(or callmigrate_game_creator_runtime_limitson the raw bytes first). Set the runtime config dir before that write-back so the file being migrated is treated as managed. Add a regression that runsmigrate_legacy_game_creator_agent_modeagainst a config containing the retired fields and asserts setup can continue and the keys are gone on disk.@@ -9808,3 +9808,3 @@- 普通工具准入只检查原回合活动状态、时间预算、并发和既有权限,不要求先登记交付合同;成功/失败/取消只结算本次操作,删除全局 Draining 与执行/返修批次计数。- 普通工具准入只检查原回合活动状态、并发和既有权限,不要求先登记交付合同;成功/失败/取消只结算本次操作,删除全局 Draining 与执行/返修批次计数。- 验证失败和源码漂移影响对应证据,不阻断无关工作。远端不确定结果沿资源自身 operation/幂等记录核对;本地执行器失控或持久状态损坏仍结束回合。- 保留累计执行时间、整轮墙钟、原生执行前审批、关闭时清理与原回合写入/付费提交检查。模型执行结束时先关闭准入,确认清理后才允许交付反馈继续;普通失败不进入关闭阶段。[suggestion] This PR edits the 2026-10-04 “普通操作与交付复核解耦” entry but leaves it saying, in the present tense, “保留累计执行时间、整轮墙钟”. That now contradicts both the code and the new 2026-10-06 decision. The same file’s 2026-10-05 exit-proof entry (line 9833, in this diff) still says a no-contract close newly produces a budget report and should prefer it; close no longer creates that report.
docs/project-memory/shared-memory/pitfalls.md(Claude timeout note) still says DirectProjectmaxTurnSecondsfires beforeCLAUDE_CODE_TURN_MAX_DURATION, which this PR’sclaude_code_cli.rscomment correctly removed.Suggestion: In the edited 2026-10-04 and 2026-10-05 entries, point at the 2026-10-06 decision instead of restating the removed caps and the budget report. Update the Claude pitfall so the 45-minute hard cap and silence budget are the remaining limits.