Conversation
Competing implementation of #112734 Phase 0B alongside #113295 (JoaoMarcos44). This PR uses a per-profile |
|
Summary What changed (claimed)
Strengths
Findings
Verdict Reviewed using Hermes-Agent |
0318bc4 to
4e9d3c7
Compare
f54dea1 to
1b6d3df
Compare
1b6d3df to
1788b53
Compare
6500f10 to
34009a9
Compare
…arch#112734 Phase 0B) Extract the admit/validate revision pattern from the Bot Screen lease-epoch mechanics into one internal record: admit at epoch N, do work, validate N, publish/commit. Only facts the runtime can prove today are populated (profile key, backend generation, display identity on X11, sticky target); control_epoch and snapshot_id stay None until NousResearch#108914 lands and validate open. Wires admit/validate at the capture fence (before any sink) and the input boundary, preserving the existing target-mismatch behavior exactly.
34009a9 to
7aa50f6
Compare
|
Closing my competing Phase 0B carrier. #113295 already covers the same old RFC slice with a different mechanism, and more importantly #108914 has since merged the real lease/epoch publication fence that both designs treated as future work. The remaining backend/display/snapshot invalidation questions should now be derived from current native seams, not by asking maintainers to choose between two September 16 abstraction layers. Thanks @JoaoMarcos44 for carrying the parallel investigation; I’m removing my duplicate review burden rather than competing for ownership. |
Status — draft; redesign against merged Bot Screen lease/fence
Fresh audit against upstream
mainatd0288be5b3330d2442e3907185b8e9d0958297bb(September 25, 2026).The original premise that #108914 was unmerged is now obsolete: #108914 merged on September 23 and current
computer_usealready carries a real lease epoch fence around capture/input publication. The broader ExecutionRevision idea may still be useful for backend/display/snapshot invalidation, but it should now be re-derived from those native seams rather than layering the old abstraction unchanged.Historical execution below belongs to the old head/environment and is retained as provenance, not current-main acceptance evidence.
Status — draft; redesign against merged Bot Screen lease/fence
Fresh audit against upstream
mainatd0288be5b3330d2442e3907185b8e9d0958297bb(September 25, 2026).The original premise that #108914 was unmerged is now obsolete: #108914 merged on September 23 and current
computer_usealready carries a real lease epoch fence around capture/input publication. The broader ExecutionRevision idea may still be useful for backend/display/snapshot invalidation, but it should now be re-derived from those native seams rather than layering the old abstraction unchanged.Historical execution in the body below belongs to the old head/environment and is retained as provenance, not current-main acceptance evidence.
What does this PR do?
Implements Phase 0B of #112734: the internal
ExecutionRevisioncontract for computer_use. It extracts theadmit at epoch N → do work → validate epoch N → publish / commitpattern from the Bot Screen lease-epoch mechanics (#108914) into one internal record, so stale work is invalidated before publication instead of via scattered special-case checks.The design question in #112734 asked whether the first PR should extract #108914's proven revision/fence semantics behind one internal contract. #108914 is still open and unmerged, so this PR builds the contract on
mainusing only facts the runtime can prove today — the lease-epoch half plugs in when #108914 lands, with no API change.Related Issue
Related to #112734 (Phase 0B — revisioned execution)
Related to #112639 (parent RFC: computer-use speedup)
Type of Change
Changes Made
tools/computer_use/execution_revision.py(new): frozenExecutionRevisiondataclass with independent typed fields (profile_key,display_identity,backend_generation,control_epoch,app,pid,window_id,snapshot_id— all butprofile_keyoptional);ExecutionStatewithadmit()/validate(); explicit invalidation reasons (control_epoch_changed,display_changed,backend_replaced,target_changed,snapshot_stale); per-operation dependency sets (CAPTURE_DEPS,INPUT_DEPS); the sticky-target substring rule astarget_mismatch().tools/computer_use/tool.py: per-session backend generation counter bumped in_install_backend; per-profileExecutionStateregistry keyed by scoped sid;_guarded_capture()admits beforebackend.capture()and validates before the result reaches any sink (persist/spill/aux-vision/model) — a stale revision fails closed withrevision_invalidated; the_dispatchinput guard now admits a revision and runs the target check against it (identical rule and error JSON as before).tests/computer_use/test_execution_revision.py(new, 14 tests): the Phase 0B exit-gate cases — stale revision rejected at the publish boundary, takeover/hand-back epoch mismatch fails closed, display rebind invalidates capture, backend rebind invalidates input, target/snapshot changes invalidate, unprovable facts never invent staleness, plus wiring tests for the capture fence and the unchanged input guard.Deliberately deferred (blocked on #108914, still open): populating
control_epochfrom the Bot Screen lease epochs andsnapshot_idfrom driver snapshot tokens — both stayNoneand validate open until then. Complements #112778 (phase spans), #113225 (critical-path report), and #113252 (shadow semantic state) without duplicating any of them.How to Test
scripts/run_tests.sh tests/computer_use/test_execution_revision.py— 14 passedscripts/run_tests.sh tests/computer_use/ tests/tools/test_computer_use_input_target_guard.py— 77 passed, 0 failed, 1 skippedtest_computer_use_input_target_guard.pysuite passes unchanged — the input guard's rule and error JSON are identical through the revision path.Checklist
Code
scripts/run_tests.shand all tests passDocumentation & Housekeeping
cli-config.yaml.exampleif I added/changed config keys — N/ACONTRIBUTING.mdorAGENTS.mdif I changed architecture or workflows — N/ADISPLAY); elsewhere it validates openThis PR was authored with AI assistance (Muse, Meta's Muse Spark) under the contributor's direction, including implementation and tests.