Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion docs/architecture/rfcs/STATUS.md
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,7 @@ appendix may keep dated history, but no dated log heading may precede it.
| [RFC: Research Exploration Control Plane v0](research-exploration-control-plane-v0.md) | Accepted | none | — |
| [RFC: Semantic Vocabulary Convergence and Commit-Time Drift Checks (v0)](semantic-vocabulary-convergence-v0.md) | Accepted | none | [5 entries](ledger/semantic-vocabulary-convergence-v0/) |
| [RFC: Shared Goal Alignment and Governed Amendment Protocol (v0)](shared-goal-alignment-and-governed-amendment-v0.md) | Accepted | none | [2 entries](ledger/shared-goal-alignment-and-governed-amendment-v0/) |
| [RFC: LoopX Shared Control-Plane Authority and Pluggable State Providers (v0)](shared-goal-authority-state-provider-v0.md) | Accepted | none | [19 entries](ledger/shared-goal-authority-state-provider-v0/) |
| [RFC: LoopX Shared Control-Plane Authority and Pluggable State Providers (v0)](shared-goal-authority-state-provider-v0.md) | Accepted | none | [20 entries](ledger/shared-goal-authority-state-provider-v0/) |
| [RFC: Single-Owner Local Daemon (v0)](single-owner-local-daemon-v0.md) | Accepted | none | — |
| [RFC: TypeScript Control-Plane Migration Direction v0](typescript-control-plane-migration-v0.md) | Accepted | none | [12 entries](ledger/typescript-control-plane-migration-v0/) |

Expand Down
2 changes: 1 addition & 1 deletion docs/architecture/rfcs/STATUS.zh-CN.md
Original file line number Diff line number Diff line change
Expand Up @@ -54,7 +54,7 @@
| [RFC:研究型探索控制面 v0](research-exploration-control-plane-v0.zh-CN.md) | 已接受 | 无 | — |
| [RFC:语义词表收敛与提交期漂移检查(v0)](semantic-vocabulary-convergence-v0.zh-CN.md) | 已接受 | 无 | [5 条](ledger/semantic-vocabulary-convergence-v0/) |
| [RFC:共享 Goal 对齐与受治理 Amendment 协议(v0)](shared-goal-alignment-and-governed-amendment-v0.zh-CN.md) | 已接受 | 无 | [2 条](ledger/shared-goal-alignment-and-governed-amendment-v0/) |
| [RFC:LoopX 共享控制面权威与可插拔状态 Provider(v0)](shared-goal-authority-state-provider-v0.zh-CN.md) | 已接受 | 无 | [19 条](ledger/shared-goal-authority-state-provider-v0/) |
| [RFC:LoopX 共享控制面权威与可插拔状态 Provider(v0)](shared-goal-authority-state-provider-v0.zh-CN.md) | 已接受 | 无 | [20 条](ledger/shared-goal-authority-state-provider-v0/) |
| [RFC: Single-Owner Local Daemon (v0)](single-owner-local-daemon-v0.md) | 已接受 | none | — |
| [RFC:LoopX 控制面 TypeScript 渐进迁移方向 v0](typescript-control-plane-migration-v0.zh-CN.md) | 已接受 | 无 | [12 条](ledger/typescript-control-plane-migration-v0/) |

Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,98 @@
# Local default cutover: recovery audit and remaining delivery scopes

- Audited baseline: `157ab7b11`, 2026-09-27, plus this delivery.
- Owner: overall roadmap #4574 R5/G2; shared authority D2/D3; TS T3/T4.
- Supersedes the **current count**, not historical evidence, in the
[September 24 reconciliation](2026-09-24-default-cutover-reconciliation.md).

## What is already delivered

Complete source transport/assembly, transaction outbox capture, reviewed
promotion, canonical pagination, File checkpoint/delta format upgrade and
bounded Python prototype retirement are on main. In particular #5013, #5063,
#5102 and #5105 must not be commissioned again. Two running promoted Goals do
not prove every supported source, consumer, rollback or execution lifecycle.

The older three-row plan grouped migration/rollback too broadly to be three
reviewable PR commitments. This audit splits its recovery prerequisite from
activation. The reason is concrete: restore verified an archive and then
reopened its mutable source pathname; a replacement could enter the isolated
target before the final digest mismatch stopped recovery. There was also no
independent read-only CLI proof of a restored store's complete retained history
and receipt lookup. These are recovery gaps, not missing capture writers.

## Four scoped deliveries starting with this PR

| Delivery | Observable result and remaining boundary |
| --- | --- |
| **1. This PR: reviewed restore and independent history audit** | A private verified input is consumed throughout restore. File/SQLite roundtrips preserve every logical row and original receipt. Audit checks historical transactions and receipt lookup independently, with explicit exact-head versus retained-prefix semantics. Real process death at a checkpoint can resume without rerunning acknowledged commits. SQLite batches receipt proofs in one read transaction without weakening scalar verification. No live selector/fence changes. |
| **2. External execution interval protection** | Existing lease owners supervise real Host execution, renewal, authority loss, cancellation and uncertain effects. Test expiry/reclaim while the old executor is still running. Post-execution rejection alone is insufficient. Attached Hosts without cancellation need an explicit supported boundary. |
| **3. Whole-Goal activation and rollback integration** | Reconcile #5054's retained-source inventory, then exercise source drain, saved reviewed cutover, all retained command consumers and fenced recovery/rollback together. Bind a recovered copy through an explicit transition; do not revive a source lease or overwrite later writes. Delete only Python decisions whose callers have actually moved. |
| **4. Default entrypoints and final bounded retirement** | New Goal creation, settings, installation, packaged frontend/Lark/CLI consistently use the qualified local profile. Existing Goals have explicit migration and disable/recovery paths. Remove last legacy business writers after their caller inventory and rollback constraints pass; retain rendering and Host IO. |

This is **four planned new delivery PRs including this one, three afterwards**,
not a guarantee that no acceptance defect will require another PR. The original
three *architectural packages* are not a decrementing PR counter. This PR closes
one named recovery slice inside package 2; it does not close all of package 2.
Future checkpoints must identify which row actually completed rather than
repeating a range such as “5–8”.

Existing PRs are separate: #5054 retires the old Todo event path and isolates
supervisor logging; #4931 optimizes SQLite retained proof reads. They were open
at the audited baseline. Do not duplicate them or request a new capture writer
for a source being retired. #4915 is filesystem placement, not authority default
selection. Further SQLite work should reuse #4224's evidence/contract and
coordinate any overlapping implementation with #4931.

## Evidence gates are not PR allocations

The latest #4224 formal 1 MiB report still has receipt p95 269.03 ms versus 50 ms
and scan-100 p95 801.81 ms versus 250 ms. No exact-head formal rerun on #4931 or
complete passing D2 report was present at this audit. The planned soak end date
is not an observed pass. Domain workload, steady-state RSS, large-history
recovery, consumer lag, upgrade/rollback and platform coverage remain distinct
rows. This PR's small checkpoint/crash matrix does not qualify the formal
100k/300k workload or replace ten days of natural elapsed soak.

D1 consumer parity, D3 reviewed cohort activation and maintainer default choice
also require real evidence. A File opt-in, qualified SQLite default and migration
of all existing Goals are distinct claims. It is therefore not honest to give
an unconditional total PR count or a calendar deadline today.

PostgreSQL reuses the same archive auditor and logical transactions. Its real
isolated store integration is exercised here; authenticated transport, tenant
policy, restore-incarnation operations, failover/pooling and capacity remain its
separate medium-term path. Local default does not require that service deployment.

## Delivery contract

The existing authority-archive CLI owns this administrative journey. TS owns
format verification, snapshot lifetime, historical comparison, resume decisions
and provider readback; Python only projects CLI input/output. This introduces no
capability/provider registration, storage format or new settings. Frontend and
Lark business readers continue through the same provider interfaces; no
companion configuration editor is needed.

The negative matrix covers replaced and damaged input, old-history divergence
behind a matching head, missing or unavailable receipt lookup, incomplete pages,
incarnation changes and concurrent appends. File/SQLite process-death tests and
real PostgreSQL cross-provider tests retain actual storage. The local-source
rehearsal uses a detached byte-verified copy, never an active Goal mutation.
Public evidence excludes private Goal state and raw logs.

[Commands, semantic changes and operational limits](../../../../reference/file-authority-state-log.md#provider-migration-and-recovery).

The detached real-source rehearsal exposed a 300-second restore RPC timeout:
per-row receipt readback repeatedly replayed the same SQLite checkpoint window.
The bounded batch receipt method addresses that redundancy at the existing
provider port; the scalar method delegates to the same proof owner. Archive
restore and audit share page comparison, while uncertain writes force immediate
proof. This complements, rather than replaces, #4931's proof-encoding work and
neither raises the RPC budget nor qualifies D2's separate performance gates.

Validation on this delivery: 336 native archive/SQLite conformance and crash
checks, four CLI checks, and four cross-provider checks against an isolated
PostgreSQL 16 server passed, with no skipped checks in these suites. A detached
129-commit real-source snapshot passed File and SQLite restore and independent
audit. Recovery of the earlier timed-out SQLite destination passed without
reissuing its committed operations. These checks do not claim active cutover.
Original file line number Diff line number Diff line change
@@ -0,0 +1,76 @@
# 本地默认切换:恢复审计与剩余交付范围

- 核对基线:2026-09-27 `157ab7b11`,加本次交付。
- 归属:总目标 #4574 R5/G2;shared authority D2/D3;TS T3/T4。
- 取代[九月二十四日清单](2026-09-24-default-cutover-reconciliation.zh-CN.md)的
**当前数量口径**,不覆盖历史证据。

## 已交付的部分

完整来源传输/组装、事务 outbox 捕获、reviewed promotion、canonical 分页、File
checkpoint/delta 格式升级和有界 Python 原型退役已在 main。尤其 #5013、#5063、
#5102、#5105 不能重复安排。两个 Goal 已晋升,不代表所有保留来源、消费者、回退
和执行生命周期都通过验收。

此前三行计划把“迁移/回退”合得太宽,不能据此承诺三个可审查 PR。本次将恢复前置
与正式激活分开,依据是实际缺陷:restore 验证归档后重新打开可变路径,被替换的
内容可能先写入隔离目标,直到最终摘要不符才失败。此外缺少独立只读 CLI,证明恢复
目标的完整历史及回执查询仍正确。这是恢复缺口,不是尚未实现事件捕获。

## 从本次开始的四个交付范围

| 交付 | 可观察结果及剩余边界 |
| --- | --- |
| **1. 本次:审核输入恢复与独立历史审计** | 恢复始终消费私有、已验证的输入副本。File/SQLite 往返保留逐笔逻辑状态和原回执。审计独立核对历史与回执查询,明确 exact 与 retained-prefix 两种语义。检查点提交后进程被杀可续传,不重复执行已提交的命令。不修改线上 selector/fence。 |
| **2. 外部执行区间保护** | 既有 lease owner 覆盖真实 Host 执行、续约、权限丢失、取消及不确定副作用。必须测试旧 executor 尚在运行时的过期/接管;结束后拒绝写回不够。不可取消的 attached Host 需明确支持边界。 |
| **3. 整 Goal 激活及回退集成** | 对齐 #5054 的保留来源清单,联合验证来源 drain、保存的 reviewed cutover、全部保留命令消费者及 fenced recovery/rollback。通过明确转换绑定恢复副本,不复活旧租约,不覆盖后来写入。仅删除 caller 已迁走的 Python 决策。 |
| **4. 默认入口与最后一批有界退役** | 新建 Goal、settings、安装及打包 frontend/Lark/CLI 一致使用合格本地 profile;存量 Goal 有明确迁移及停用/恢复路径。caller 清单与回退约束通过后,删除最后的旧业务 writer,保留渲染及 Host IO。 |

这是**包含本次在内四个规划新 PR,本次交付后剩三个**;不保证验收不会再发现需要
修复的缺陷。原来的三个“架构工作包”不是倒计时 PR 数。本次关闭第 2 包中的一个
具名恢复切片,没有把整个第 2 包标为完成。后续必须指出哪行真正交付,不能再重复
一个不变的“5–8”。

已有 PR 单列:#5054 退役旧 Todo event 路径并隔离 supervisor 日志,#4931 优化
SQLite retained proof 读取。二者在本次核对时仍开放,不重复实现,也不为将退役的
来源新增捕获 writer。#4915 属于目录布局,不能算 authority 默认切换。后续 SQLite 工作复用 #4224 的资格合同及证据,与 #4931 的重叠实现协调。

## 证据门不是 PR 配额

#4224 最新正式 1 MiB 报告仍有 receipt p95 269.03 ms / 50 ms 和 scan-100 p95
801.81 ms / 250 ms 两项失败。本次核对未发现 #4931 精确 head 的正式复测或完整
D2 通过报告。计划 soak 结束日期不等于实测通过。domain workload、steady-state
RSS、大历史恢复、consumer lag、升级/回退及平台覆盖是各自独立的项目。本次小型
检查点/进程崩溃矩阵不证明正式 100k/300k 负载,也不替代十天自然时间 soak。

D1 消费者一致性、D3 经审核的 cohort 激活及维护者默认值选择同样需要实证。
File opt-in、合格 SQLite 默认和全部存量 Goal 迁移是不同主张;目前不能诚实地给出
无条件的 PR 总数或完成日期。

PostgreSQL 复用同一归档审计和逻辑事务,本次运行真实隔离 store 集成;认证传输、
tenant 策略、恢复 incarnation、failover/pool 及容量仍属于独立中期路线。本地默认
不必等待 PostgreSQL 服务部署。

## 本次交付合同

现有 authority-archive CLI 拥有此管理旅程;TS 负责格式验证、副本生命周期、历史
比对、续传判断及 provider 回读,Python 仅适配 CLI 输入输出。不新增 capability、
provider 注册、磁盘格式或 settings。frontend/Lark 业务读取仍走同一 provider 接口,
无需新增配置编辑器。

负例覆盖输入替换/损坏、最终状态相同但旧历史不同、回执查询丢失/不可用、分页不
完整、incarnation 改变及并发追加。File/SQLite 进程崩溃测试与真实 PostgreSQL
跨 provider 测试使用实际存储。本机来源演练使用独立且核对字节的快照,不修改活跃
Goal。公开材料排除私有 Goal 内容及原始日志。

[操作、语义变化及限制](../../../../reference/file-authority-state-log.md#provider-migration-and-recovery)。

隔离真实快照演练暴露了恢复 RPC 的 300 秒超时:逐笔回执回读反复重放同一个 SQLite
检查点窗口。本次在现有 provider 接口增加有界批量查询,标量查询委托给同一个证明
实现;恢复和审计共享分页比对,遇到不确定写入立即回读。此处减少重复重放,与
#4931 的证明编码优化互补;不提高 RPC 预算,也不替代 D2 的独立性能验收。

本次交付验证:336 项原生归档/SQLite 一致性及崩溃检查、4 项 CLI 检查、真实隔离
PostgreSQL 16 的 4 项跨 provider 检查全部通过,这些套件没有跳过项。129 笔历史的
独立真实来源快照通过 File、SQLite 恢复及独立审计;此前超时的 SQLite 目标也成功
恢复,没有重发已提交操作。这些结果不表示已经完成活跃 Goal 切换。
21 changes: 11 additions & 10 deletions docs/architecture/rfcs/shared-goal-authority-state-provider-v0.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,16 +24,17 @@
[Chinese version](./shared-goal-authority-state-provider-v0.zh-CN.md) and this
English version are semantic mirrors. A difference between them is a defect.

## Current delivery frontier (2026-09-25)

Audit `37bbaec79` and current PR states: complete-source transport, transaction
capture, source assembly and the five previously open caller/event fixes are
merged, not future implementation. After the current promotion-admission repair,
three named code boundaries remain planned: external-effect execution fencing;
event-writer binding plus whole-Goal migration/rollback; default onboarding plus
bounded Python retirement. #4931 and outstanding D2 evidence are tracked
separately. Three is a delivery plan, not a guaranteed total PR count.
[Current inventory and exits](ledger/shared-goal-authority-state-provider-v0/2026-09-24-default-cutover-reconciliation.md).
## Current delivery frontier (2026-09-27)

Audit `157ab7b11` and current PR states: source capture, pagination, File format
upgrade and Python prototype retirement are delivered. This delivery repairs
reviewed-input recovery and adds independent retained-history audit. Plan four
scoped PRs starting here: this recovery slice, external execution interval
protection, whole-Goal activation/rollback integration, and default entrypoints
with final bounded Python retirement. Three planned scopes follow this PR;
existing #5054/#4931 and D2/D3 evidence remain separate. This is not a guaranteed
count of future defect repairs.
[Current inventory, rationale and exits](ledger/shared-goal-authority-state-provider-v0/2026-09-27-recovery-audit.md).

File retained-state storage now reuses the existing TS checkpoint/delta codec,
stacked on #5063's verified read cache and RPC budgets. Original revisions,
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -21,13 +21,14 @@
- 语言说明:[英文版](./shared-goal-authority-state-provider-v0.md)与本中文版互为
语义镜像;两者不一致属于缺陷

## 当前交付边界(2026-09-25)

按 `37bbaec79` 与当前 PR 状态核对:完整来源传输、事务捕获、来源组装及此前五个
在途 caller/event 修复都已合入,不再计入待开发。当前晋升准入修复之后,规划三个
明确代码边界:外部动作执行区间保护、事件 writer 绑定与整 Goal 迁移/回退闭环、
默认启用与最后一批有界 Python 退役。#4931 与 D2 的剩余资格证据单列;三个是
可命名的开发批次,不是保证总 PR 数。[唯一当前清单与退出条件](ledger/shared-goal-authority-state-provider-v0/2026-09-24-default-cutover-reconciliation.zh-CN.md)。
## 当前交付边界(2026-09-27)

按 `157ab7b11` 与当前 PR 核对,来源捕获、分页、File 格式升级及 Python 原型
退役已交付。本次修复审核输入恢复并增加独立历史审计;从本次开始规划四个交付
PR:本次恢复切片、外部执行区间保护、整 Goal 激活/回退集成、默认入口及最后
一批有界 Python 退役。本次之后剩后三个规划范围;#5054/#4931 已有 PR,D2/D3
缺失证据另列,不能保证最终缺陷修复数量。
[当前清单、依据及退出条件](ledger/shared-goal-authority-state-provider-v0/2026-09-27-recovery-audit.zh-CN.md)。

File 历史存储在 #5063 的读取缓存和 RPC 预算之上,复用现有 TS checkpoint/delta
编码;物理格式升级保留原版本、回执和每条完整历史投影。正常读写只接受 v1,
Expand Down
Loading
Loading