diff --git a/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md b/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md index 39f5f1ce7..5cb3ea4a1 100644 --- a/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md +++ b/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md @@ -1,6 +1,6 @@ # Local authority: retirement cadence after integration -- Audit: `ce3862e33`, September 28, 2026; [中文](2026-09-28-retirement-cadence.zh-CN.md). +- Audit: `ce3862e33`; adoption follow-up: `71525ab90`, September 28, 2026; [中文](2026-09-28-retirement-cadence.zh-CN.md). - Owners: overall roadmap R3/R4/R5/R6; shared authority D1–D3; TS migration T0–T4. - This replaces the **current inventory/estimates** in the September 27 recovery and Host-supervision ledgers, not their historical validation results. @@ -17,8 +17,9 @@ | #5175 | One native source-outbox drain; Python sequencing and obsolete entry-planning RPC removed | | #5169 | Verified identical operation replay on File/SQLite | | #5170 | App delegated-result continuity; not every Turn/instance consumer | +| #4931 | Owned TS state replay reduces SQLite/archive historical reconstruction; no default change or D2 qualification | -At this audit #4931 (SQLite read cost), #5106 (collaboration GoalRef), #5130 +At the adoption follow-up #5106 (collaboration GoalRef), #5130 (session GoalRef), #5139 (App Turn acceptance recovery) and #4915 (local-state location migration) remain open. Integrate/review those owners rather than reimplementing them. Their scopes are dependencies only for affected callers; @@ -132,3 +133,36 @@ capture of current production state, or D2 qualification. Raw private snapshots and diagnostics remain outside the repository. No production code is deleted by this planning PR; it establishes the deletion exits and records their actual validation boundary. + +## Adoption follow-up and next decision + +At `71525ab90`, the installed CLI, locally built App/bundled runtime and both +services resolve to the same source. Installation doctor reports the pair as +matching; the actual chat page renders and the previous delivery's entry JS/CSS +remain available with identical bytes. This is local installation evidence, +not a signed/notarized release or a messaging/settlement acceptance result. + +Fresh logical archives retain 379 and 993 original transactions. Restore plus +exact audit matches the 379-transaction archive on File and SQLite and the +993-transaction archive on SQLite, including the original transaction/receipt +proofs and complete projections. This extends the earlier synthetic-drain +evidence to retained real history. It does not test reverse migration after a +new write in this run; the earlier bounded result remains separately scoped. +Private archives, registry data and raw diagnostics remain outside Git. + +The initial rehearsal separated data but reused a live Effect process. Those +latency samples are excluded. The final audit used a verified independent +process; ordinary command resampling succeeded after shared work settled. +The [testing guide](../../../../development/testing-and-quality.md#isolate-the-managed-effect-process-as-well-as-the-data) +now specifies both isolation boundaries. Concurrent heavy-admin fairness is +not qualified by the clean resample. + +Keep existing authority providers unchanged. Reuse #4931's measured SQLite +candidate decision for B, rather than reopening the same optimization. Before +selecting a consumer optimization, trace whole-command costs and duplicated +projections: a history row limit does not bound semantic history, and status +and quota can still produce multi-megabyte diagnostic packets. Preserve +decision completeness and existing drill-down contracts at their shared typed +owner; do not infer that backend switching alone fixes these costs. A/C still +need integrated execution/adoption evidence, and no D2 elapsed soak starts or +legacy-writer deletion is certified by this follow-up. diff --git a/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md b/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md index 7045afbde..7a1e91a61 100644 --- a/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md +++ b/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md @@ -1,6 +1,6 @@ # 合并后的本地权威退役节奏 -- 核对基线:`ce3862e33`,2026-09-28;[English](2026-09-28-retirement-cadence.md)。 +- 核对基线:`ce3862e33`;采用后续核对:`71525ab90`,2026-09-28;[English](2026-09-28-retirement-cadence.md)。 - Owner:总 roadmap R3/R4/R5/R6、shared authority D1–D3、TS 迁移 T0–T4。 - 本记录替代 9 月 27 日 recovery、Host supervision 记录的**当前清单和估算**, 不替代其历史验证结果。 @@ -17,8 +17,9 @@ | #5175 | 完整 outbox drain 由 TS 拥有;Python 编排及旧逐条规划 RPC 已删除 | | #5169 | File/SQLite 完整意图与历史证明匹配的操作重放 | | #5170 | App 委派结果连续性;不代表全部 Turn/实例消费者完成 | +| #4931 | TS 私有状态重放降低 SQLite/archive 历史重建成本;未切默认、未完成 D2 | -本次核对时,#4931(SQLite 读取成本)、#5106(collaboration GoalRef)、#5130 +采用后续核对时,#5106(collaboration GoalRef)、#5130 (session GoalRef)、#5139(App Turn 接受恢复)、#4915(本地状态路径迁移)仍开放。 复用和推进这些 owner,不重复实现;只对确实受影响的调用方建立依赖,本地默认切换 不等待无关云端或百 Agent 工作。 @@ -104,3 +105,27 @@ CLI 全部 drain,原 Todo JSON 完整相等。所得四笔事务恢复/审 活跃 Goal。这证明有界 drain 和逻辑 archive 连续性,**不是**全部原始 224 笔历史重放、 live selector cutover、重新捕获当前生产状态或 D2 验收。私有快照和原始诊断不入库。 本规划 PR 不删除生产代码,只确定删除出口并记录实际验证边界。 + +## 采用后续核对与下一步决策 + +在 `71525ab90` 上,已安装 CLI、本地构建 App/bundled runtime 及两个服务使用同一 +源码;安装 doctor 确认配对,实际 chat 页面可渲染,上一份交付的入口 JS/CSS 仍可 +取回且字节相同。这是本机安装证据,不是签名/公证 release,也不代表发送消息或 +settlement 链路验收。 + +新捕获的逻辑 archive 分别保留 379、993 笔原始事务。379 笔 archive 恢复到 File +和 SQLite 后均通过 exact audit;993 笔在 SQLite 上通过。核对包括原事务/回执证明 +和完整 projection,将之前的合成 drain 证据推进到真实保留历史。本轮没有再验证 +追加新写入后的反向迁移,之前的有界结果仍单独计证。私有 archive、registry 和 +原始诊断不入 Git。 + +首轮演练隔离了数据,却复用了活跃 Effect 进程,因此排除其受污染耗时。最后一次 +审计核对了独立进程;共享重型工作结束后的日常命令重新采样成功。 +[验证指南](../../../../development/testing-and-quality.md#isolate-the-managed-effect-process-as-well-as-the-data) +已明确两层隔离。干净重采样不代表重型管理工作并发时的公平性已验收。 + +现有权威 provider 保持不变。B 复用 #4931 实测形成的 SQLite 候选决策,不重新做同一 +优化。消费者优化先追踪完整命令成本与重复投影:history 的行数限制不限制 semantic +history,status/quota 仍可能生成数 MB 诊断包。在现有共享 typed owner 保留决策 +完整性与 drill-down 合同,不能推断换后端就能消除这些成本。A/C 仍需执行/采用集成 +证据;本轮没有启动 D2 自然时间 soak,也没有认证旧 writer 可以删除。 diff --git a/docs/development/testing-and-quality.md b/docs/development/testing-and-quality.md index d6ca22466..444ec37c8 100644 --- a/docs/development/testing-and-quality.md +++ b/docs/development/testing-and-quality.md @@ -261,6 +261,43 @@ not overwritten or restored by the test. Stop the temporary server afterward. lease。私有快照和原始输出不得进入 Git 或公开 review;快照演练前后比较源指纹。 发现并发源变更只报告,不擅自覆盖或恢复。测试后停止临时数据库。 +#### Isolate the managed Effect process as well as the data + +A separate worktree, registry, `--runtime-root` or archive `--destination` +isolates neither CPU work nor the managed Effect server. Its discovery directory +uses Python's temporary directory and user identity; the server is selected by +source fingerprint. Identical checkouts and an installed release can therefore +share the same process. A large restore/audit can delay ordinary CLI requests +even when it writes only to a disposable store. + +Before a snapshot rehearsal, create a private existing temporary directory and +set **all three** of `TMPDIR`, `TEMP`, and `TMP` to it for every child command. +Keep the separate data/registry paths too: process isolation does not isolate +data. In a Python process that already imported `tempfile`, also scope and +restore its cached `tempfile.tempdir`; the existing +`tests/control_plane/canonical_authority_fixture.py::isolate_sqlite_runtime` +fixture demonstrates both boundaries. Record the serving runtime PID and verify +it differs from the live server before dispatching expensive work. Stop only +that isolated runtime after its requests settle, retaining the same temporary +environment for shutdown; never restart a live server as test cleanup. + +Process isolation still shares machine resources. Run matched timing arms +sequentially without overlapping builds or recovery work. If interference is +discovered, retain failures and durable-receipt evidence, mark latency samples +contaminated and resample after quiescence. A client timeout does not prove its +server operation stopped; do not launch a duplicate restore while the first +request may still be running. Neither a successful restore nor a clean resample +qualifies concurrent administrative-work fairness or elapsed soak. + +独立 worktree、registry、`--runtime-root` 或 archive `--destination` 不会隔离 +Effect 后台进程;相同源码指纹可能让源码环境与已安装版本共享进程。演练前创建私有 +临时目录,对所有子命令同时设置 `TMPDIR`、`TEMP`、`TMP`;Python 进程若已缓存 +`tempfile.tempdir`,须在同一作用域覆盖并恢复。数据/registry 仍须单独隔离,且在 +重型操作前核对服务 PID 与活跃服务不同。等请求结束后,只在同一临时环境中停止 +演练进程。进程隔离不消除整机资源竞争:耗时对照顺序运行,发现竞争则保留失败与 +回执、作废受污染耗时并重新采样;超时不能当作服务端已停止,也不能因此重复恢复。 +恢复成功不证明并发管理操作公平性或自然时间 soak 已合格。 + Keep a deterministic, public-safe production-scale fixture beside the focused cases. Its envelope should cover realistic role/status distributions, multi-agent claims, user gates and standing decisions, current and retired diff --git a/skills/loopx-self-repair/references/targeted-diagnostics.md b/skills/loopx-self-repair/references/targeted-diagnostics.md index 8ded4ec29..bf973a617 100644 --- a/skills/loopx-self-repair/references/targeted-diagnostics.md +++ b/skills/loopx-self-repair/references/targeted-diagnostics.md @@ -57,6 +57,17 @@ and synthetic fixture or authorized read-only snapshot. Preserve integrity, receipt recovery and lease/CAS semantics; do not benchmark by mutating an active Goal. Check existing PRs before starting an overlapping store refactor. +A different registry, `--runtime-root`, archive destination or worktree does not +isolate the Effect server: identical source fingerprints can reuse the same +process through the user's temporary directory. Follow the testing guide's +**Isolate the managed Effect process as well as the data** procedure: use a +private existing directory for `TMPDIR`, `TEMP` and `TMP`, account for Python's +cached `tempfile.tempdir`, and check the serving PID before heavy work. Stop +only the isolated server after requests settle. If a rehearsal shared the live +server, retain its correctness/receipt evidence but exclude affected timings; +resample without overlapping heavy work before attributing a regression to a +provider or upgrade. Process isolation alone does not remove host CPU contention. + When unrelated lightweight rules and `runtime.ping` slow down together, test shared event-loop starvation before attributing the timeout to the named rule. Compare cold, warm and alternating-Goal reads in a separate runtime using fixed @@ -81,9 +92,11 @@ precondition must still come from its authority owner. Do not add a Python cache that bypasses the typed owner, or assume different providers share a filesystem invalidation rule. -Separate this from storage-specific work. File-v0's retained journal decoding -and whole-file rewrite, SQLite transactions/indexes, and PostgreSQL queries and -network round trips have different costs. Prove a shared optimization through +Separate this from storage-specific work. Current File checkpoint/delta +verification and replay, SQLite transactions/indexes, and PostgreSQL queries and +network round trips have different costs. Identify the actual stored format; +do not apply retired File-v0 whole-history-write assumptions to File-v1. +Prove a shared optimization through the common read/transaction contract, then qualify each affected real backend. Preserve original-receipt recovery, stale-revision rejection and missing-state fail-closed behavior. A successful promotion establishes authority ownership;