fix: 深审超时治理 — review 单次调用默认 300→1200s + 超时结构化标因 (#54) - #56
Merged
Merged
Conversation
根因 (#54 调研): 未显式设 ZCODE_BRIDGE_REVIEW_TIMEOUT 的调用方 (人工/agent 的 --call 与 MCP 直调) 走 300s 默认预算, 而 depth=deep 复核是多轮读文件+推理循环, 闸门侧实测两仓 21/28 次深审中位时长 305s/409s (57%/71% 超 300s) — 对 deep 档 必然超时, 表现为 'LLM 阶段 300s 超时 exit2/isError 无 verdict'。review-gate 自身显式设 3600 不受默认值影响, 因此只有闸门外的调用方受害。 变更: - _review_timeout() 默认 300 → 1200, docstring 记实测依据与取舍 (挂死子进程 占用 ReviewFileLock 的时长随之变长, 锁等待仍 300s) - _run_zcode_headless 超时分支: structured_output=True 时 result 顶层附 timeout {seconds} — 与 quota_limit/refusal 同型的机器契约, 调用方可据此 区分预算不足与其他失败, 不必解析 isError 文本 - README env 表 + 并发最坏阻塞估算同步 (约 20 分钟 → 约 85 分钟, 注明依据) 测试: RC4 默认值断言更新 300→1200; 新增 TestTimeoutAttribution TA1/TA2 (结构化键存在/普通形状不变)。全套 542 passed, ruff 干净。
按 code-reviewer 审查意见修复 (无 P0/P1):
- P2-1 (方向 B, 保守): 锁等待维持 300s 不动, 语义文档化 — 深审常态超
300s 后并发直调的第二个 review 在锁等待耗尽时快速失败 (fail-fast,
调用方稍后重试); 并为锁超时失败补结构化键 lock_timeout {seconds}
(与 timeout/refusal 同型机器契约, 仅 structured_output)。docstring 与
主 README 并发段落同步说明。
- P2-2: review-gate 源码注释与子包 README 的「mcp-server 默认 300s」
过期陈述同步为 1200/上限 3600 (本 PR 改默认值时漏改的两处)。
- P3-1: 「对 deep 档必然超时」→「多数超时」(与 57%/71% 实测自洽),
mcp-server docstring + 主 README env 表两处。
- P3-2: TA1/TA2 补子进程调用计数断言 ==1, 钉住「超时不进限流重试
循环」(对齐 SQ1 惯例)。
- P3-3: 模块 docstring 覆盖清单补 #54 条目。
- P3-4: timeout/lock_timeout 键的仓内消费方不在本 PR 接线 (gate 失败
分类变更属 #54 后续 degraded verdict 议题), PR 描述记消费计划。
测试: 新增 TA3 (锁超时键 + 锁失败先于 spawn + 与 timeout 键区分);
全套 543 passed, ruff 干净。
tizerluo
force-pushed
the
fix/54-review-timeout-defaults
branch
from
October 3, 2026 18:10
2b2436e to
63c9f58
Compare
Owner
Author
R1 审查修复(code-reviewer 全项采纳)审查结论:无 P0/P1,2×P2 + 4×P3。逐条处置:
测试:新增 TA3(锁超时键存在 / 锁失败先于子进程 spawn / 与 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
根因(#54 调研结论,脱敏摘要)
三次「LLM 阶段 300s 超时、exit2/isError、无 verdict」全部来自未显式设
ZCODE_BRIDGE_REVIEW_TIMEOUT的调用方(人工/agent 的--call与 MCP 直调),不是常驻 gate 的问题——gate 一直显式传 3600,对同样 head 的审查全部成功(journal/state 双证)。两层叠加:
_review_timeout()默认 300s,而 depth=deep 复核是多轮「读文件+推理」循环。gate 侧 49 次深审实测:两仓中位时长 305s / 409s,57% / 71% 超 300s——300s 默认对 deep 档是必然超时(--call模式对 isError 约定退出码 2,即 issue 的「exit2/isError」;mimosa 扫描有独立预算先正常完成,故呈现「Mimosa 正常但无 verdict」)。ZCODE_MODEL等注入环境变量被包装器/新版 runtime 忽略,子进程可能落在 providerOrder 首位的慢模型上(实测单请求 TTFT 87-213s),令深审更不可能在 300s 内完成。本 PR 不修 [compat] 0.16.9 官方 runtime headless:ZCODE_MODEL 等 env 注入疑似失效,模型选择走配置文件(闸门机升级实证) #55,仅消除预算层。变更
_review_timeout()默认 300 → 1200:docstring 记实测依据与取舍——挂死子进程占用ReviewFileLock的时长随之变长(锁等待仍 300s)。_run_zcode_headless超时分支:structured_output=True时 result 顶层附timeout: {"seconds": N}——与quota_limit/refusal同型的机器契约,调用方可区分「预算不足/过慢」与其他失败,不必解析 isError 文本(issue 建议的 degraded verdict 的前置件)。测试
TestTimeoutAttributionTA1/TA2(结构化键存在 / 普通形状不变)。Closes #54 的修复部分(issue 中的超时三发已由本 PR 消除复发条件;#55 另行跟进模型解析)。