docs: record local authority adoption and isolate rehearsal processes - #5217
Conversation
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Reviewed exact head: 941c729632748b2185dd8b222029472497e42a55; immutable merge base: 71525ab908e24dc9f3e4ace922d1d2ef3437ce4d.
动机
独立数据目录并不保证演练与日常工作隔离。这个 PR 把真实的进程复用陷阱写进已有验证指南和诊断 skill,同时修正采用记录的验收边界。我在相同源码的真实 Effect 进程上验证了陷阱与恢复方法,因此这不是仅凭作者描述接受的文档修改;但也不把历史安装记录当成本轮完成正式推广或 soak 的证据。
改动思路
沿现有 _runtime_fingerprint、_runtime_dir 与 tempfile 缓存行为解释隔离,不新增第二个运行时、provider 选择器或恢复 API。数据隔离保留,另在现有临时目录下建立进程发现 namespace;父进程和子命令一起设置 TMPDIR/TEMP/TMP,已缓存的 tempfile.tempdir 同作用域覆盖并恢复。先核对 serving PID,再做重型工作,结束后只停止该 namespace 的服务。共享机器资源仍会干扰耗时,干净重采样不证明并发公平性。
具体改动
关键内容讲解
四个文件构成同一个安全演练/采用核对边界。双语 retirement ledger 增加 #4931 的已合并状态和 71525ab90 采用 checkpoint,区分安装配对、保留完整历史恢复、未重测的追加写入反向迁移,以及 A/C、D2 和默认切换仍未完成的事项。379/993 是历史 checkpoint 的计数,不是本轮独立读取私有 archive 得到的结论。
testing-and-quality 新增双语进程隔离步骤:目录必须已存在,三个环境变量一起设置,处理 Python 缓存,确认 PID,在同一临时环境中停止演练进程;超时不是服务端停止的证明,也不允许并发重复 restore。targeted-diagnostics 复用此流程,且将 File-v0 的旧 whole-history-write 假设改为检查实际 File checkpoint/delta 格式。该 reference 会随 workflow-skills 安装,被 self-repair 的定向诊断步骤加载;因此评审按 agent 行为面而非“无行为 docs-only”处理。临时目标安装及文件逐字 readback 已通过,不改本机现用 skill。
未来演进检查:复用既有指南、fixture、archive 和诊断 owner 足够,不需要另添 namespace 框架或重复 roadmap。这里仅退役错误假设,未删除历史格式读取、receipt 支持或任何生产 writer。
对主干的风险
最危险的反例是 agent 以为换了 runtime-root/destination 就已隔离,最后把活跃服务停止,或将污染耗时归因于 provider。独立探针在两个私有合成 namespace 上运行真实父/子进程:相同 fingerprint、不同数据路径仍复用 PID;只换三个环境变量而不处理缓存仍落在旧 namespace;同时处理环境与缓存后 PID 分离,停止第二个服务后第一个仍能响应,最后两边仅停止自己的进程并恢复缓存。这三种观察在 base/head 相同,证明是纠正操作方法,不是暗改 runtime 语义。
36 项测试通过,包含 15 项诊断 lookup/真实安装以及真实 File/SQLite 的 CLI archive、restore、exact audit、独立重开、错误目标拒绝和依赖 capture。14 个相对链接解析通过,双语计数/未验收边界一致,四文件 public-boundary 扫描通过。不接触活跃 Goal 或私有快照,不发起推广;没有重新认证作者的历史安装、379/993 原始 archive、全 Goal settlement、性能、公平性、平台矩阵或自然时间 soak。
语义与 CI 对齐
复用既有 File/SQLite、archive、PID namespace 和 D1–D3 词汇;这里的安全验证步骤是工程指引,不是新增 must_attempt_work 或运行时许可。指引适用于被明确选择的隔离演练,skill 安装本身不激活 provider,也不授予删除/切换权威权限。默认 provider 与 effect 规则的源码树在 base/head 逐文件不变;变化只在这四个文档/指令面。
首次 premerge 的 semantic 检查因新 worktree 缺根目录 TypeScript 开发依赖失败;安装锁定依赖后完整重新执行,3 项 direct、19 项选中检查全部执行,required failure 为 0,包含一项 ratchet advisory。loopx.status 119/117 超限的相同命令在 base/head 给出相同完整失败明细,与本 PR 无因果关系,不能据此 REQUEST_CHANGES。仓库 CI impact plan 将 skill reference 判为 full,不接受作者“documentation only”作为自动豁免。遵守 wait_for_ci=false,未查询或等待远程 CI。
我的整体评价
APPROVE:长期运行 improved,因为它防止演练干扰正常工作及错误重试;用户体验 preserved,因为没有新增日常准入或手动同步要求。这个有界增量把隔离方法和历史 checkpoint 放在原 owner,下一个执行步骤仍由既有 A/C 集成、B profile qualification 和 D2 自然时间观察承接。文档没有据成功恢复就宣布默认切换、正式 release 或退役旧 writer;本轮验证也不扩大这些结论。无须扩大重构或让无关红检查否定此 PR。
English verdict: APPROVE - 941c729632748b2185dd8b222029472497e42a55; real base/head process-isolation controls, 36 tests, installed-reference readback and link/privacy checks passed. Historical adoption is explicitly bounded; no provider promotion, fairness or elapsed-soak qualification is implied.
|
Frame-aligned conclusion at 941c729: APPROVE. Checked the shared-authority retirement cadence and real-path / isolated-rehearsal guide. Local historical adoption is not formal D1–D3 acceptance: A/C integration/default adoption, appended-history reverse migration, B-profile elapsed D2 soak and fairness remain explicitly unqualified. No private historical archive was reopened or recertified by this review. 本轮亲自跑真实父/子 Effect 进程,证明只换数据路径或仅换环境变量会复用旧 namespace;完整环境+缓存方法能隔离 PID,停止演练服务后对照服务仍响应。错误隔离 oracle 在真实路径失败,完整方法通过。36 项 native 测试、隔离安装 reference 的逐字 readback、14 个链接及 public-boundary 检查通过;完整 canary 复跑 required failure 为 0。四个文档面包含已安装指令行为,不能用 docs-only 声明豁免仓库 full CI 分类;status 119/117 是同明细的继承失败,不是本 PR blocker。不查询远程 CI,不推广 provider、不停止活跃服务、不合并。 |
The merged SQLite replay optimization and retirement plan needed a concrete adoption checkpoint. This updates the existing bilingual ledger with qualified installation/recovery evidence and replaces stale File-v0 assumptions in self-repair guidance.
A separate archive destination does not isolate the managed Effect process: identical source fingerprints can reuse the same server. The testing guide now specifies temporary-directory/process isolation, checking the serving PID, safe cleanup and excluding contaminated latency measurements. Documentation only: no provider default, permission, runtime rule or deletion gate changes.
Validation: 15 repair-pattern lookup tests pass, 14 relative links resolve, four changed files pass the public-boundary scan. Risk-based premerge is ready: three direct checks, nine catalog checks, eight risk smokes and the boundary check pass; the maintainability ratchet has an inherited advisory failure (
loopx.statusreexports 119 versus ceiling 117), unchanged by this diff. The first attempt lacked root npm dependencies; dependencies were installed and validation rerun. Two unrelated existing Goal projection warnings remain.The checkpoint distinguishes full-history restore/audit from untested whole-Goal settlement, concurrent administrative-work fairness, release-default qualification and elapsed soak. Raw snapshots and operational diagnostics are excluded. The future-facing pass reuses existing guide/RFC owners without adding a parallel roadmap or test framework.