From 76381668e189ed070d7fb412fe2f831cadb75fca Mon Sep 17 00:00:00 2001 From: huangruiteng <14976749+huangruiteng@users.noreply.github.com> Date: Mon, 28 Sep 2026 01:12:06 +0800 Subject: [PATCH] docs: reconcile authority retirement cadence with merged delivery Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com> --- .../2026-09-28-retirement-cadence.md | 134 ++++++++++++++++++ .../2026-09-28-retirement-cadence.zh-CN.md | 106 ++++++++++++++ .../rfcs/loopx-overall-roadmap-v0.md | 2 + .../rfcs/loopx-overall-roadmap-v0.zh-CN.md | 2 + ...shared-goal-authority-state-provider-v0.md | 32 ++--- ...-goal-authority-state-provider-v0.zh-CN.md | 24 ++-- .../typescript-control-plane-migration-v0.md | 32 ++--- ...script-control-plane-migration-v0.zh-CN.md | 24 ++-- 8 files changed, 294 insertions(+), 62 deletions(-) create mode 100644 docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md create mode 100644 docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md diff --git a/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md b/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md new file mode 100644 index 000000000..39f5f1ce7 --- /dev/null +++ b/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md @@ -0,0 +1,134 @@ +# Local authority: retirement cadence after integration + +- Audit: `ce3862e33`, September 28, 2026; [中文](2026-09-28-retirement-cadence.zh-CN.md). +- Owners: overall roadmap R3/R4/R5/R6; shared authority D1–D3; TS migration T0–T4. +- This replaces the **current inventory/estimates** in the September 27 recovery + and Host-supervision ledgers, not their historical validation results. + +## Reconciled baseline + +| Already merged | What no longer belongs in the remaining-work count | +| --- | --- | +| #5054 | Experimental Todo events projection/backfill/completion retired; supervisor log separated | +| #5102 / #5105 | File format upgrade/backup and native qualification/Python prototype retirement | +| #5140 / #5156 | Archive recovery/audit and shared-runtime read fairness | +| #5144 | Managed command/Codex CLI process supervision; **not** attached-Host cancellation | +| #5173 | Reviewed File↔SQLite cutover for already-promoted, quiescent Goals | +| #5175 | One native source-outbox drain; Python sequencing and obsolete entry-planning RPC removed | +| #5169 | Verified identical operation replay on File/SQLite | +| #5170 | App delegated-result continuity; not every Turn/instance consumer | + +At this audit #4931 (SQLite read cost), #5106 (collaboration GoalRef), #5130 +(session GoalRef), #5139 (App Turn acceptance recovery) and #4915 (local-state +location migration) remain open. Integrate/review those owners rather than +reimplementing them. Their scopes are dependencies only for affected callers; +local default does not wait for unrelated cloud or hundred-Agent work. + +**File as the default store factory is not File as the default authority for +all new/existing Goals.** Unpromoted Markdown writers remain reachable. Two +successful Goal migrations, or File↔SQLite transfer, do not prove their absence. +No fixed “5–8 PRs remaining” is carried forward: below are named delivery and +qualification boundaries, not a promise about defect count or merge count. + +## When and how to delete + +| Boundary | Actual reachable code/caller | Earliest safe deletion and retained obligation | +| --- | --- | --- | +| Duplicate decisions / obsolete internal crossings | Inspect each touched TS owner and its Python caller; #5175 already removed the drain coordinator | In the same PR that switches the **last** caller and proves independent semantics. Delete handler/registration, helpers and obsolete implementation-only tests together. Do not invent more shadow/bridge layers. No additional dead module is certified by this planning audit. | +| Legacy Todo mutation | `loopx/todos.py` still imports `line_update.py` plus `provider_create.py`, `provider_update.py`, `provider_terminal_lifecycle.py` | After new-Goal and upgrade paths select canonical authority, covered existing cohorts migrate, and unupgraded callers receive an explicit upgrade/recovery route. Remove the writable Markdown branch by caller family; retain human narrative rendering and qualified import/export. An absent provider must not silently reactivate the old writer. | +| Shadow capture/drain | `runtime_shadow_writer_adapter.py`, `local_authority_shadow_outbox.py`, `runtime_shadow.py`; configure/CLI and old writers still use these | Remove producers/hooks after the last supported source writer exits. Keep the migration-owned reader/reconciler until prepared/committed outboxes are reconciled or explicitly dispositioned. Zero pending entries in one local Goal is insufficient. | +| Python command facades | `authority_core.py`, canonical Todo adapters and `quota/monitor_poll.py` have real runtime callers | Delete per complete native entrypoint adoption, including private validator/Host effects, output projection and error/retry behavior. Moving pure policy to TS does not make input/IO adapters dead. Do not delete whole files based on language or line count. | +| Historical formats and receipts | File/SQLite migration codecs, logical archives and command receipt recovery | Remove obsolete normal write paths; retain explicit migration/backup restore and original receipt readers for the supported upgrade boundary. Any eventual reader removal needs a format support decision and tested conversion, independent of business-writer deletion. | + +Use one retirement manifest in the implementation PR: symbol/path, production +callers (including dynamic handlers/packaging), replacement owner, persisted +obligation, positive/negative evidence and rollback. Compare against the immutable +base. A zero-import search is necessary for internal removal, not sufficient for +public CLI/import or serialized contracts. Retain public behavior tests; remove +only characterization scaffolding whose retired implementation has no consumer. +Deletion is code retirement, not deletion of users' state, receipts or backups. + +## Next delivery order + +| Order | Complete outcome / owner | Concrete exit and deletion opportunity | +| --- | --- | --- | +| A — start now | Whole-Goal execution/consumer integration; R3/R5 and existing Host/Turn owners | Trace capture→drain→promotion→CLI/status/quota/App/Lark reads and writes→settlement→restart→reverse migration with new writes. Inventory managed, attached and external execution; real cancellation acknowledgement/settlement is required, expiry alone is not proof. Reuse #5173/#5175. Retire only duplicated coordination within this complete journey. | +| B — alongside A | Local profile qualification; D1/D2, reuse #4931 | Matched File/SQLite workload including domain graph, metadata, history, latency/RSS, burst/lag and cold installed CLI. Record platform/runtime and declared limits. Fix a demonstrated failing row at its owner. SQLite remains a candidate; an optimization or small rehearsal does not choose the release default. File is the control arm, not an automatic fallback if qualification fails. | +| C — after A and profile decision | New-Goal/default/install/settings adoption plus supported existing-Goal upgrade; D3/T3 | New and upgraded installs, CLI, packaged App and Lark agree on one selected authority. Verified backups, reviewed migration, crash retry, non-upgraded rejection and rollback carrying new writes all work. Release default is an explicit decision. Remove migrated legacy writer branches in the same caller-family PR; do not leave a “cleanup someday” tail. | +| D — with C, per last caller | Remaining transport and capture retirement; T4 | Delete unused facade/dispatch/producers once native consumers adopt them; retain necessary host IO and migration readers. Full Python removal is not a prerequisite for canonical defaults, nor an automatic consequence of them. | + +Canonical execution tasks already cover whole-Goal promotion, local profile +qualification with a deletion inventory, and durable Markdown projection/rebuild. +Reconcile their evidence and continue those owners; projection failure must have +an explicit rebuild path without making Markdown a second writable authority. + +A/C may split if distinct execution or onboarding owners need independent +rollback; name the reason and exact remaining exit when splitting. B is evidence +work and can reveal additional fixes, not a predetermined PR. After these local +outcomes, R6 still needs authenticated PostgreSQL transport, tenant/identity +operations, pooling/cancellation/failover and cross-host qualification; reuse the +existing store/archive/service owners. Do not delay local deletion for R6. + +R3 instance/session adoption and R4 intent/acceptance continuity remain separate +product outcomes. Reuse the [deferred continuity scenarios](../../goal-immutability-coherence-defense-v0.md) +where the changed caller needs them; do not turn them into an unimplemented +universal gate. CAS success does not prove current Goal identity or task quality. + +## Aggressive local qualification before deleting writers + +These are proposed engineering windows from a frozen candidate, not promised +release dates. Run faults on disposable runtimes and detached verified copies; +never kill/rewrite live Goals to make a test pass. + +1. **Now / first 1–2 working days:** pin binary/source and actual Node/SQLite + driver; inventory installed versions, callers, providers and pending work. + Keep independent legacy/File/SQLite arms. Prove backup restoration, exact + Todo JSON/history/receipt parity and forward writes. Seed null/absent/false, + archived dependencies, leases, validators, in-flight Turns and pending outbox. +2. **Next 2–3 working days, if the prior row passes:** remove the intended legacy + branch in an isolated candidate (or make it fail loudly), exercise real + commands and installed UI/host consumers. Inject process death before/after + commit and selector publication, stale instance/revision, lock contention, + unavailable runtime and interrupted projections. Retry must settle once; + recovery must permit subsequent legitimate work. Test restore with a retained + migration-capable binary, not by deleting the selector or restoring old bytes + over newly acknowledged writes. +3. **Continuous observation on a qualified candidate:** collect actual elapsed + time and workload coverage, command latency, memory/disk/WAL growth, oldest + pending item/consumer lag, ambiguous-result recovery, duplicate-effect and + stale-instance incidents. Daily readback and periodic recovery checks use an + isolated observer/copy. Formal D2's applicable ten-day natural-time soak + cannot be accelerated by looping tests or backdating timestamps. Count it + only from a recorded start, with restart gaps and source changes explicit. +4. **Cohort then default:** after the above required evidence, perform reviewed + backup/migration and observation of a bounded authorized cohort; expand only + on demonstrated recovery. A local all-Goal migration does not prove external + installs upgraded. Keep the old binary/artifacts for diagnosis, but select + only a binary compatible with the current format for operation/rollback. + +Stop candidate writes on lost acknowledged data, duplicate effect, cross-instance +contamination, selector/receipt disagreement or unrecoverable ambiguity; keep +read-only evidence and recover through the owning journal. Treat latency/memory +regressions against declared budgets as failed rows, not invitations to increase +limits. Local investigation may be aggressive; promotion/deletion evidence must +remain independently checkable. + +## Evidence from this planning pass + +At `ce3862e33`, local real-backend migration/crash suites passed 15 cases; +19 real CLI archive/upgrade/cutover and bounded source-capture tests passed. +The existing SQLite rehearsal completed 100 and 1,000 commits with cold CLI +sampling and cleanup. Its report remains **incomplete**, with formal workload, +capacity, platform and elapsed-soak rows missing; this run starts no soak. + +A detached previously captured real source with 1,101 complete Todo records was +reconstructed into three synthetic source transactions. The current production +CLI drained all three, with full original Todo JSON unchanged. Four resulting +transactions were restored/audited into SQLite; a fifth synthetic acknowledged +write was then exported/restored/audited into File and retained. No active Goal +was changed. This proves bounded source drain and logical archive continuity, +**not** replay of all 224 original transactions, a live selector cutover, fresh +capture of current production state, or D2 qualification. Raw private snapshots +and diagnostics remain outside the repository. No production code is deleted +by this planning PR; it establishes the deletion exits and records their actual +validation boundary. diff --git a/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md b/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md new file mode 100644 index 000000000..7045afbde --- /dev/null +++ b/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md @@ -0,0 +1,106 @@ +# 合并后的本地权威退役节奏 + +- 核对基线:`ce3862e33`,2026-09-28;[English](2026-09-28-retirement-cadence.md)。 +- Owner:总 roadmap R3/R4/R5/R6、shared authority D1–D3、TS 迁移 T0–T4。 +- 本记录替代 9 月 27 日 recovery、Host supervision 记录的**当前清单和估算**, + 不替代其历史验证结果。 + +## 重新核对的基线 + +| 已合并 | 不再计入剩余工作的内容 | +| --- | --- | +| #5054 | 旧 Todo events 投影、回填、completion 已退役;supervisor 日志已分离 | +| #5102 / #5105 | File 格式升级/备份、原生验证及 Python 原型删除 | +| #5140 / #5156 | Archive 恢复/审计与共享 runtime 读取公平性 | +| #5144 | Managed command/Codex CLI 进程监督;**不代表** attached Host 取消闭环 | +| #5173 | 已晋升且静止 Goal 的 reviewed File↔SQLite 切换 | +| #5175 | 完整 outbox drain 由 TS 拥有;Python 编排及旧逐条规划 RPC 已删除 | +| #5169 | File/SQLite 完整意图与历史证明匹配的操作重放 | +| #5170 | App 委派结果连续性;不代表全部 Turn/实例消费者完成 | + +本次核对时,#4931(SQLite 读取成本)、#5106(collaboration GoalRef)、#5130 +(session GoalRef)、#5139(App Turn 接受恢复)、#4915(本地状态路径迁移)仍开放。 +复用和推进这些 owner,不重复实现;只对确实受影响的调用方建立依赖,本地默认切换 +不等待无关云端或百 Agent 工作。 + +**File 是默认 store factory,不等于所有新旧 Goal 默认以 File 为权威。** +未晋升的 Markdown writer 仍可达。两个 Goal 迁移成功、或 File↔SQLite 传输成功, +都不能证明旧 writer 已没有消费者。本轮不再沿用“还剩 5–8 个 PR”;以下列出的是 +交付和验证边界,不承诺缺陷数量或合并数量。 + +## 什么时候删、怎么删 + +| 边界 | 真实可达的代码/调用方 | 最早删除条件及保留义务 | +| --- | --- | --- | +| 重复决策/废弃内部 RPC | 逐项检查 TS owner 与 Python caller;#5175 已删 drain 编排 | 切走**最后调用方**且独立语义验证通过的同一个 PR,连同 handler、注册、helper 和仅服务旧实现的测试一起删。不新增 shadow/bridge 层。本规划未认证额外某个模块已死。 | +| 旧 Todo 写入 | `loopx/todos.py` 仍导入 `line_update.py` 和 `provider_create.py`、`provider_update.py`、`provider_terminal_lifecycle.py` | 新 Goal/升级路径选择 canonical authority,目标存量 cohort 完成迁移,未升级调用方有明确升级/恢复路线后,按调用家族删 Markdown 可写分支。保留人工叙述渲染和合格 import/export;provider 缺失不能悄悄恢复旧 writer。 | +| Shadow 捕获/drain | `runtime_shadow_writer_adapter.py`、`local_authority_shadow_outbox.py`、`runtime_shadow.py`;configure/CLI 和旧 writer 仍调用 | 最后受支持的源 writer 退出后删 producer/hook;prepared/committed outbox 已对账或明确处置前,保留迁移 owner 内的 reader/reconciler。一个本机 Goal 无积压不足以删除。 | +| Python 命令 facade | `authority_core.py`、canonical Todo adapter、`quota/monitor_poll.py` 仍有运行时调用方 | 完整 native 入口接管后逐组删除,包括私有 validator/Host 效果、输出投影及错误/重试行为。纯策略进入 TS 不代表输入/IO adapter 已死;不能按语言或行数整文件删。 | +| 历史格式/回执 | File/SQLite 迁移 codec、逻辑 archive、command receipt recovery | 退役旧正常写路径,但保留受支持升级边界的显式迁移、备份恢复和原回执读取。将来删 reader 须另有格式支持决策和转换验证,不能搭业务 writer 删除顺风车。 | + +实施 PR 维护一份退役清单:symbol/path、生产调用方(含动态 handler/打包)、替代 +owner、持久兼容义务、正反例证据及回退方式,和不可变基线比较。零 import 搜索对 +内部删除必要但不充分,不能忽略公开 CLI/import 和序列化契约。保留公共行为测试, +只删没有消费者的旧实现专属 characterization。删的是代码,不是用户状态、回执和备份。 + +## 下一轮交付顺序 + +| 顺序 | 完整结果/owner | 具体出口与删除机会 | +| --- | --- | --- | +| A:现在开始 | 整 Goal 执行/消费者集成;R3/R5、现有 Host/Turn owner | 串起捕获→drain→晋升→CLI/status/quota/App/Lark 读写→settlement→重启→携带新写入迁回。核对 managed、attached、external 执行;真正取消确认/settlement 才是结束证明,过期不算。复用 #5173/#5175,在完整链路内删除重复编排。 | +| B:与 A 并行 | 本地 profile 验证;D1/D2,复用 #4931 | File/SQLite 同负载比较,包含领域图、metadata、历史、延迟/RSS、burst/lag、安装后冷 CLI,记录平台/runtime/限额。哪里失败就修其 owner。SQLite 仍是候选;优化或小演练不能决定发布默认值。File 是对照组,不是资格失败后的自动替代。 | +| C:A 与 profile 决策通过后 | 新 Goal/默认/安装/设置接入,加受支持存量升级;D3/T3 | 新装和升级、CLI、打包 App、Lark 使用同一选定权威。备份验证、reviewed migration、中断恢复、未升级拒绝及携带新写入回退可用;发布默认值显式决定。同一调用家族 PR 删除已替代的 legacy writer,不留“以后再清理”。 | +| D:伴随 C,按最后调用方推进 | 其余传输与捕获退役;T4 | native 消费者接管后删 facade/dispatch/producer,保留必要 Host IO 和迁移 reader。全部 Python 消失既不是 canonical 默认的前置,也不是切换后的自动结果。 | + +Canonical 任务已覆盖整 Goal 晋升、本地 profile 与退役清单、持久 Markdown 投影/ +显式重建。先对齐这些任务的证据并沿用已有 owner;投影失败应能明确重建,不能 +因此把 Markdown 重新变成第二套可写权威。 + +A/C 若因不同执行或 onboarding owner 需要独立回退,可以拆分,但须写明原因和 +剩余出口。B 是证据工作,可能暴露新的修复,不预先折算为 PR。之后 R6 仍须完成 +PostgreSQL 认证传输、tenant/identity 运维、连接池/取消/failover 和跨 Host 验证, +复用现有 store/archive/service owner;不让 R6 阻止本地代码退役。 + +R3 实例/session 接入和 R4 意图/验收连续性仍是独立产品结果。受影响调用方复用 +[后续连续性场景](../../goal-immutability-coherence-defense-v0.zh-CN.md),不把它扩张为 +尚未实现的全局门禁;CAS 成功不能证明当前 Goal 身份或任务质量。 + +## 删除 writer 前,本机可以积极做的验证 + +以下是冻结候选版本后的工程窗口,不是承诺发布日期。故障注入只用可丢弃 runtime +和经过验证的隔离副本,不能为了测试杀掉或改写活跃 Goal。 + +1. **现在/最初 1–2 个工作日:** 固定 binary/source 和实际 Node/SQLite driver; + 清点安装版本、caller、provider 和积压。保留独立 legacy/File/SQLite 三臂, + 验证备份可恢复、完整 Todo JSON/历史/回执一致和后续新写入。覆盖 null/缺失/ + false、归档依赖、lease、validator、in-flight Turn、pending outbox。 +2. **前项通过后,接下来 2–3 个工作日:** 在隔离候选中删除拟退役分支或让它明确 + 失败,走真实命令及安装后的 UI/Host 消费者。注入 commit/selector 发布前后 + 进程死亡、过期实例/revision、锁竞争、runtime 不可用和投影中断。重试只能 + settlement 一次,恢复后合法工作能继续。用保留的迁移兼容 binary 验证恢复, + 不删除 selector,也不拿旧字节覆盖已确认的新写入。 +3. **合格候选的连续观察:** 记录真实经过时间与负载覆盖、命令延迟、内存/磁盘/ + WAL 增长、最老积压/consumer lag、不确定结果恢复、重复效果和实例污染。 + 每日读回,定期在隔离 observer/副本中验证恢复。适用的 D2 十天自然时间 soak + 不能靠循环测试或回填时间戳加速;有记录的起点才开始计时,明确重启间隙和源码变化。 +4. **先 cohort 后默认:** 所需证据通过后,对有限且获授权 cohort 做 reviewed + 备份/迁移/观察,以恢复证据决定扩面。本机所有 Goal 迁移也不等于外部用户 + 已升级。旧 binary/artifact 保留用于诊断,但操作/回退必须用与当前格式兼容的版本。 + +发生已确认数据丢失、重复效果、跨实例污染、selector/receipt 不一致或不可恢复的 +不确定结果时,停止候选写入、保留只读证据,通过所属 journal 恢复。延迟/内存超过 +既定预算要记录失败,不能直接提高限额。本机调查可以激进,晋升和删除证据必须可核验。 + +## 本轮实际验证 + +在 `ce3862e33` 上,本机真实 backend 的迁移/中断恢复套件通过 15 项; +真实 CLI 的 archive/升级/切换与有界源捕获测试通过 19 项。 +SQLite 既有 rehearsal 完成 100 和 1,000 次提交、冷 CLI 采样及清理;报告仍为 +**incomplete**,正式负载、容量、平台和 elapsed-soak 项未完成,本次没有启动 soak。 + +将先前捕获的真实来源隔离快照中 1,101 个完整 Todo 重建为三笔合成源事务,当前生产 +CLI 全部 drain,原 Todo JSON 完整相等。所得四笔事务恢复/审计到 SQLite 后追加 +第五笔已确认合成写入,再 export/restore/audit 到 File,新写入保留。没有修改 +活跃 Goal。这证明有界 drain 和逻辑 archive 连续性,**不是**全部原始 224 笔历史重放、 +live selector cutover、重新捕获当前生产状态或 D2 验收。私有快照和原始诊断不入库。 +本规划 PR 不删除生产代码,只确定删除出口并记录实际验证边界。 diff --git a/docs/architecture/rfcs/loopx-overall-roadmap-v0.md b/docs/architecture/rfcs/loopx-overall-roadmap-v0.md index baa67d82f..4d75623b9 100644 --- a/docs/architecture/rfcs/loopx-overall-roadmap-v0.md +++ b/docs/architecture/rfcs/loopx-overall-roadmap-v0.md @@ -6,6 +6,8 @@ - Ownership: overall product outcomes, cross-domain dependencies, priorities and portfolio acceptance here; concrete rules in domain RFCs/stable protocols; execution state in canonical Todos. - Language: [中文版](loopx-overall-roadmap-v0.zh-CN.md) is the semantic mirror. +**Local authority retirement checkpoint (2026-09-28).** R5/T4 now use the [reconciled deletion and qualification cadence](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md). Reviewed local cutover and native drain are merged; whole-Goal execution/consumer closure, profile qualification and default-entry adoption still have separate exits. Delete a replaced writer with its last caller; retain necessary migration/receipt readers. Existing GoalRef/Turn PRs own their affected consumers. R6 PostgreSQL service qualification is separate, and the historical PR-count estimates are not current forecasts. + ## 1. Overall Objective and Product Routes LoopX aims to let people express, revise and accept complex goals through a local frontend or Lark, while a persistent steward coordinates long-running LoopX Agents with independent work commitments across local managed and cloud runtimes. Single-Agent long-horizon reliability is the foundation. Multi-Agent collaboration, handoff, recovery and convergence on shared goals are core capabilities. Hundred-Agent scale is a separate system qualification. diff --git a/docs/architecture/rfcs/loopx-overall-roadmap-v0.zh-CN.md b/docs/architecture/rfcs/loopx-overall-roadmap-v0.zh-CN.md index 9a5af93e0..fc6bf9ae9 100644 --- a/docs/architecture/rfcs/loopx-overall-roadmap-v0.zh-CN.md +++ b/docs/architecture/rfcs/loopx-overall-roadmap-v0.zh-CN.md @@ -6,6 +6,8 @@ - 责任:总纲拥有产品目标、跨领域依赖、优先级和组合验收;领域 RFC/稳定协议拥有具体规则;运行 Todo 拥有执行状态。 - 语言:[English](loopx-overall-roadmap-v0.md) 与本文互为语义镜像。 +**本地权威退役 checkpoint(2026-09-28)。** R5/T4 采用[重新核对的删除和验证节奏](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md)。Reviewed 本地切换和 native drain 已合入;整 Goal 执行/消费者闭环、profile 验证、默认入口接入仍分别验收。切走最后调用方时同步删旧 writer,保留必要迁移/回执 reader。已有 GoalRef/Turn PR 负责各自消费者;R6 PostgreSQL 服务验证另列,历史 PR 数量估算不再作为当前预测。 + ## 1. 总目标与产品路线 LoopX 的目标是让人用本地前端或 Lark 提出、修订和验收复杂目标,由持久管家协调多个拥有独立工作承诺的长程 LoopX Agent,在本地 managed 与云端 runtime 上持续完成可验证的工作。单 Agent 的长程可靠性是基础,多个 Agent 的协作、handoff、恢复和共享目标收敛是核心能力,百 Agent 规模是需要独立证明的系统资格。 diff --git a/docs/architecture/rfcs/shared-goal-authority-state-provider-v0.md b/docs/architecture/rfcs/shared-goal-authority-state-provider-v0.md index e47af2309..7a80a7e03 100644 --- a/docs/architecture/rfcs/shared-goal-authority-state-provider-v0.md +++ b/docs/architecture/rfcs/shared-goal-authority-state-provider-v0.md @@ -24,24 +24,20 @@ [Chinese version](./shared-goal-authority-state-provider-v0.zh-CN.md) and this English version are semantic mirrors. A difference between them is a defect. -## Current delivery frontier (2026-09-27) - -Audit `157ab7b11` and current PR states: source capture, pagination, File format -upgrade and Python prototype retirement are delivered. This delivery repairs -reviewed-input recovery and adds independent retained-history audit. Plan four -scoped PRs starting here: this recovery slice, external execution interval -protection, whole-Goal activation/rollback integration, and default entrypoints -with final bounded Python retirement. Three planned scopes follow this PR; -existing #5054/#4931 and D2/D3 evidence remain separate. This is not a guaranteed -count of future defect repairs. -[Current inventory, rationale and exits](ledger/shared-goal-authority-state-provider-v0/2026-09-27-recovery-audit.md). - -Managed Host supervision lands in the same window as a separate delivered slice: -one TS supervisor now owns generic command and Codex CLI process lifetimes, so -authority-bound execution stays open rather than closing here, and the old three -architectural packages remain a pointer instead of a decrementing PR counter. -Its named plan, changed estimate and boundaries are recorded separately. -[Named plan, changed estimate and boundaries](ledger/shared-goal-authority-state-provider-v0/2026-09-27-host-supervision.md). +## Current delivery frontier (2026-09-28) + +Audit `ce3862e33`: #5054, #5140, #5144, #5156, #5173, #5175 and #5169 +are merged. Do not count event retirement, archive recovery, managed process +supervision, reviewed local cutover or native drain as new pending PRs. +#4931 remains an open SQLite optimization, not a completed D2 qualification. + +Next: qualify whole-Goal execution/consumer integration and matched local +profiles in parallel; then unify new-Goal/install/settings and supported upgrade +entrypoints, deleting each replaced writer with its last caller. Retain necessary +Host IO, original receipts and migration readers. No additional dead Python +module is certified by this audit, and no fixed remaining-PR total is promised. +[Deletion inventory, engineering windows, local evidence and remaining work](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md) +supersedes older current-count estimates; their execution evidence stays historical. File retained-state storage now reuses the existing TS checkpoint/delta codec, stacked on #5063's verified read cache and RPC budgets. Original revisions, diff --git a/docs/architecture/rfcs/shared-goal-authority-state-provider-v0.zh-CN.md b/docs/architecture/rfcs/shared-goal-authority-state-provider-v0.zh-CN.md index c44ebd5d8..dfd0181d9 100644 --- a/docs/architecture/rfcs/shared-goal-authority-state-provider-v0.zh-CN.md +++ b/docs/architecture/rfcs/shared-goal-authority-state-provider-v0.zh-CN.md @@ -21,19 +21,17 @@ - 语言说明:[英文版](./shared-goal-authority-state-provider-v0.md)与本中文版互为 语义镜像;两者不一致属于缺陷 -## 当前交付边界(2026-09-27) - -按 `157ab7b11` 与当前 PR 核对,来源捕获、分页、File 格式升级及 Python 原型 -退役已交付。本次修复审核输入恢复并增加独立历史审计;从本次开始规划四个交付 -PR:本次恢复切片、外部执行区间保护、整 Goal 激活/回退集成、默认入口及最后 -一批有界 Python 退役。本次之后剩后三个规划范围;#5054/#4931 已有 PR,D2/D3 -缺失证据另列,不能保证最终缺陷修复数量。 -[当前清单、依据及退出条件](ledger/shared-goal-authority-state-provider-v0/2026-09-27-recovery-audit.zh-CN.md)。 - -同一窗口另有已交付的进程监督切片:通用命令与 Codex CLI 的进程生命周期改由 -一个 TS supervisor 承担,因此执行中租约约束仍开放,不由本次关闭;旧“三个 -架构包”仍是指针,不是递减 PR 计数器。该切片的逐项计划、估算变化与边界单列。 -[核对的逐项计划、估算变化与边界](ledger/shared-goal-authority-state-provider-v0/2026-09-27-host-supervision.zh-CN.md)。 +## 当前交付边界(2026-09-28) + +按 `ce3862e33` 核对,#5054、#5140、#5144、#5156、#5173、#5175、#5169 +均已合并。事件退役、archive 恢复、managed 进程监督、reviewed 本地切换和 native +drain 不再计作新待办 PR。#4931 仍是开放的 SQLite 优化,不是已完成 D2 验收。 + +接下来并行验证整 Goal 执行/消费者集成和本地 profile,再统一新 Goal/安装/设置 +及受支持升级入口,切走最后调用方时同步删除对应旧 writer。保留必要 Host IO、 +原回执与迁移 reader。本轮未认证额外某个 Python 模块已死,也不承诺固定剩余 PR 数。 +[删除清单、工程窗口、本机证据及剩余工作](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md) +替代旧记录的当前数量估算,旧执行证据仍按历史保留。 ## Todo 事件路径退役(2026-09-25) diff --git a/docs/architecture/rfcs/typescript-control-plane-migration-v0.md b/docs/architecture/rfcs/typescript-control-plane-migration-v0.md index a360916cd..7191f79bc 100644 --- a/docs/architecture/rfcs/typescript-control-plane-migration-v0.md +++ b/docs/architecture/rfcs/typescript-control-plane-migration-v0.md @@ -29,24 +29,20 @@ required for the first App outcome. These are planned product consumers of T0–T4, not additional provider promotion or completed migration claims. -## Current delivery frontier (2026-09-27) - -Audit `157ab7b11` and current PR states: source capture, pagination, File format -upgrade and Python prototype retirement are delivered. This delivery repairs -reviewed-input recovery and adds independent retained-history audit. Plan four -scoped PRs starting here: this recovery slice, external execution interval -protection, whole-Goal activation/rollback integration, and default entrypoints -with final bounded Python retirement. Three planned scopes follow this PR; -existing #5054/#4931 and D2/D3 evidence remain separate. This is not a guaranteed -count of future defect repairs. -[Current inventory, rationale and exits](ledger/shared-goal-authority-state-provider-v0/2026-09-27-recovery-audit.md). - -Managed Host supervision lands in the same window as a separate delivered slice: -one TS supervisor now owns generic command and Codex CLI process lifetimes, so -authority-bound execution stays open rather than closing here, and the old three -architectural packages remain a pointer instead of a decrementing PR counter. -Its named plan, changed estimate and boundaries are recorded separately. -[Named plan, changed estimate and boundaries](ledger/shared-goal-authority-state-provider-v0/2026-09-27-host-supervision.md). +## Current delivery frontier (2026-09-28) + +Audit `ce3862e33`: #5054, #5140, #5144, #5156, #5173, #5175 and #5169 +are merged. Do not count event retirement, archive recovery, managed process +supervision, reviewed local cutover or native drain as new pending PRs. +#4931 remains an open SQLite optimization, not a completed D2 qualification. + +Next: qualify whole-Goal execution/consumer integration and matched local +profiles in parallel; then unify new-Goal/install/settings and supported upgrade +entrypoints, deleting each replaced writer with its last caller. Retain necessary +Host IO, original receipts and migration readers. No additional dead Python +module is certified by this audit, and no fixed remaining-PR total is promised. +[Deletion inventory, engineering windows, local evidence and remaining work](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md) +supersedes older current-count estimates; their execution evidence stays historical. ## Native authority qualification and prototype retirement (2026-09-26) diff --git a/docs/architecture/rfcs/typescript-control-plane-migration-v0.zh-CN.md b/docs/architecture/rfcs/typescript-control-plane-migration-v0.zh-CN.md index c477ef4d2..14e75dafe 100644 --- a/docs/architecture/rfcs/typescript-control-plane-migration-v0.zh-CN.md +++ b/docs/architecture/rfcs/typescript-control-plane-migration-v0.zh-CN.md @@ -27,19 +27,17 @@ R1–R3 的 TS 消费者包括 App 产品路径,不只 CLI 结算。 这里是 T0–T4 的产品消费计划,不新增 provider promotion,也不声称迁移完成。 -## 当前交付边界(2026-09-27) - -按 `157ab7b11` 与当前 PR 核对,来源捕获、分页、File 格式升级及 Python 原型 -退役已交付。本次修复审核输入恢复并增加独立历史审计;从本次开始规划四个交付 -PR:本次恢复切片、外部执行区间保护、整 Goal 激活/回退集成、默认入口及最后 -一批有界 Python 退役。本次之后剩后三个规划范围;#5054/#4931 已有 PR,D2/D3 -缺失证据另列,不能保证最终缺陷修复数量。 -[当前清单、依据及退出条件](ledger/shared-goal-authority-state-provider-v0/2026-09-27-recovery-audit.zh-CN.md)。 - -同一窗口另有已交付的进程监督切片:通用命令与 Codex CLI 的进程生命周期改由 -一个 TS supervisor 承担,因此执行中租约约束仍开放,不由本次关闭;旧“三个 -架构包”仍是指针,不是递减 PR 计数器。该切片的逐项计划、估算变化与边界单列。 -[核对的逐项计划、估算变化与边界](ledger/shared-goal-authority-state-provider-v0/2026-09-27-host-supervision.zh-CN.md)。 +## 当前交付边界(2026-09-28) + +按 `ce3862e33` 核对,#5054、#5140、#5144、#5156、#5173、#5175、#5169 +均已合并。事件退役、archive 恢复、managed 进程监督、reviewed 本地切换和 native +drain 不再计作新待办 PR。#4931 仍是开放的 SQLite 优化,不是已完成 D2 验收。 + +接下来并行验证整 Goal 执行/消费者集成和本地 profile,再统一新 Goal/安装/设置 +及受支持升级入口,切走最后调用方时同步删除对应旧 writer。保留必要 Host IO、 +原回执与迁移 reader。本轮未认证额外某个 Python 模块已死,也不承诺固定剩余 PR 数。 +[删除清单、工程窗口、本机证据及剩余工作](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md) +替代旧记录的当前数量估算,旧执行证据仍按历史保留。 ## Todo 事件路径退役(2026-09-25)