Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Local authority: retirement cadence after integration

- Audit: `ce3862e33`, September 28, 2026; [中文](2026-09-28-retirement-cadence.zh-CN.md).
- Audit: `ce3862e33`; adoption follow-up: `71525ab90`, September 28, 2026; [中文](2026-09-28-retirement-cadence.zh-CN.md).
- Owners: overall roadmap R3/R4/R5/R6; shared authority D1–D3; TS migration T0–T4.
- This replaces the **current inventory/estimates** in the September 27 recovery
and Host-supervision ledgers, not their historical validation results.
Expand All @@ -17,8 +17,9 @@
| #5175 | One native source-outbox drain; Python sequencing and obsolete entry-planning RPC removed |
| #5169 | Verified identical operation replay on File/SQLite |
| #5170 | App delegated-result continuity; not every Turn/instance consumer |
| #4931 | Owned TS state replay reduces SQLite/archive historical reconstruction; no default change or D2 qualification |

At this audit #4931 (SQLite read cost), #5106 (collaboration GoalRef), #5130
At the adoption follow-up #5106 (collaboration GoalRef), #5130
(session GoalRef), #5139 (App Turn acceptance recovery) and #4915 (local-state
location migration) remain open. Integrate/review those owners rather than
reimplementing them. Their scopes are dependencies only for affected callers;
Expand Down Expand Up @@ -132,3 +133,36 @@ capture of current production state, or D2 qualification. Raw private snapshots
and diagnostics remain outside the repository. No production code is deleted
by this planning PR; it establishes the deletion exits and records their actual
validation boundary.

## Adoption follow-up and next decision

At `71525ab90`, the installed CLI, locally built App/bundled runtime and both
services resolve to the same source. Installation doctor reports the pair as
matching; the actual chat page renders and the previous delivery's entry JS/CSS
remain available with identical bytes. This is local installation evidence,
not a signed/notarized release or a messaging/settlement acceptance result.

Fresh logical archives retain 379 and 993 original transactions. Restore plus
exact audit matches the 379-transaction archive on File and SQLite and the
993-transaction archive on SQLite, including the original transaction/receipt
proofs and complete projections. This extends the earlier synthetic-drain
evidence to retained real history. It does not test reverse migration after a
new write in this run; the earlier bounded result remains separately scoped.
Private archives, registry data and raw diagnostics remain outside Git.

The initial rehearsal separated data but reused a live Effect process. Those
latency samples are excluded. The final audit used a verified independent
process; ordinary command resampling succeeded after shared work settled.
The [testing guide](../../../../development/testing-and-quality.md#isolate-the-managed-effect-process-as-well-as-the-data)
now specifies both isolation boundaries. Concurrent heavy-admin fairness is
not qualified by the clean resample.

Keep existing authority providers unchanged. Reuse #4931's measured SQLite
candidate decision for B, rather than reopening the same optimization. Before
selecting a consumer optimization, trace whole-command costs and duplicated
projections: a history row limit does not bound semantic history, and status
and quota can still produce multi-megabyte diagnostic packets. Preserve
decision completeness and existing drill-down contracts at their shared typed
owner; do not infer that backend switching alone fixes these costs. A/C still
need integrated execution/adoption evidence, and no D2 elapsed soak starts or
legacy-writer deletion is certified by this follow-up.
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# 合并后的本地权威退役节奏

- 核对基线:`ce3862e33`,2026-09-28;[English](2026-09-28-retirement-cadence.md)。
- 核对基线:`ce3862e33`;采用后续核对:`71525ab90`,2026-09-28;[English](2026-09-28-retirement-cadence.md)。
- Owner:总 roadmap R3/R4/R5/R6、shared authority D1–D3、TS 迁移 T0–T4。
- 本记录替代 9 月 27 日 recovery、Host supervision 记录的**当前清单和估算**,
不替代其历史验证结果。
Expand All @@ -17,8 +17,9 @@
| #5175 | 完整 outbox drain 由 TS 拥有;Python 编排及旧逐条规划 RPC 已删除 |
| #5169 | File/SQLite 完整意图与历史证明匹配的操作重放 |
| #5170 | App 委派结果连续性;不代表全部 Turn/实例消费者完成 |
| #4931 | TS 私有状态重放降低 SQLite/archive 历史重建成本;未切默认、未完成 D2 |

本次核对时,#4931(SQLite 读取成本)、#5106(collaboration GoalRef)、#5130
采用后续核对时,#5106(collaboration GoalRef)、#5130
(session GoalRef)、#5139(App Turn 接受恢复)、#4915(本地状态路径迁移)仍开放。
复用和推进这些 owner,不重复实现;只对确实受影响的调用方建立依赖,本地默认切换
不等待无关云端或百 Agent 工作。
Expand Down Expand Up @@ -104,3 +105,27 @@ CLI 全部 drain,原 Todo JSON 完整相等。所得四笔事务恢复/审
活跃 Goal。这证明有界 drain 和逻辑 archive 连续性,**不是**全部原始 224 笔历史重放、
live selector cutover、重新捕获当前生产状态或 D2 验收。私有快照和原始诊断不入库。
本规划 PR 不删除生产代码,只确定删除出口并记录实际验证边界。

## 采用后续核对与下一步决策

在 `71525ab90` 上,已安装 CLI、本地构建 App/bundled runtime 及两个服务使用同一
源码;安装 doctor 确认配对,实际 chat 页面可渲染,上一份交付的入口 JS/CSS 仍可
取回且字节相同。这是本机安装证据,不是签名/公证 release,也不代表发送消息或
settlement 链路验收。

新捕获的逻辑 archive 分别保留 379、993 笔原始事务。379 笔 archive 恢复到 File
和 SQLite 后均通过 exact audit;993 笔在 SQLite 上通过。核对包括原事务/回执证明
和完整 projection,将之前的合成 drain 证据推进到真实保留历史。本轮没有再验证
追加新写入后的反向迁移,之前的有界结果仍单独计证。私有 archive、registry 和
原始诊断不入 Git。

首轮演练隔离了数据,却复用了活跃 Effect 进程,因此排除其受污染耗时。最后一次
审计核对了独立进程;共享重型工作结束后的日常命令重新采样成功。
[验证指南](../../../../development/testing-and-quality.md#isolate-the-managed-effect-process-as-well-as-the-data)
已明确两层隔离。干净重采样不代表重型管理工作并发时的公平性已验收。

现有权威 provider 保持不变。B 复用 #4931 实测形成的 SQLite 候选决策,不重新做同一
优化。消费者优化先追踪完整命令成本与重复投影:history 的行数限制不限制 semantic
history,status/quota 仍可能生成数 MB 诊断包。在现有共享 typed owner 保留决策
完整性与 drill-down 合同,不能推断换后端就能消除这些成本。A/C 仍需执行/采用集成
证据;本轮没有启动 D2 自然时间 soak,也没有认证旧 writer 可以删除。
37 changes: 37 additions & 0 deletions docs/development/testing-and-quality.md
Original file line number Diff line number Diff line change
Expand Up @@ -261,6 +261,43 @@ not overwritten or restored by the test. Stop the temporary server afterward.
lease。私有快照和原始输出不得进入 Git 或公开 review;快照演练前后比较源指纹。
发现并发源变更只报告,不擅自覆盖或恢复。测试后停止临时数据库。

#### Isolate the managed Effect process as well as the data

A separate worktree, registry, `--runtime-root` or archive `--destination`
isolates neither CPU work nor the managed Effect server. Its discovery directory
uses Python's temporary directory and user identity; the server is selected by
source fingerprint. Identical checkouts and an installed release can therefore
share the same process. A large restore/audit can delay ordinary CLI requests
even when it writes only to a disposable store.

Before a snapshot rehearsal, create a private existing temporary directory and
set **all three** of `TMPDIR`, `TEMP`, and `TMP` to it for every child command.
Keep the separate data/registry paths too: process isolation does not isolate
data. In a Python process that already imported `tempfile`, also scope and
restore its cached `tempfile.tempdir`; the existing
`tests/control_plane/canonical_authority_fixture.py::isolate_sqlite_runtime`
fixture demonstrates both boundaries. Record the serving runtime PID and verify
it differs from the live server before dispatching expensive work. Stop only
that isolated runtime after its requests settle, retaining the same temporary
environment for shutdown; never restart a live server as test cleanup.

Process isolation still shares machine resources. Run matched timing arms
sequentially without overlapping builds or recovery work. If interference is
discovered, retain failures and durable-receipt evidence, mark latency samples
contaminated and resample after quiescence. A client timeout does not prove its
server operation stopped; do not launch a duplicate restore while the first
request may still be running. Neither a successful restore nor a clean resample
qualifies concurrent administrative-work fairness or elapsed soak.

独立 worktree、registry、`--runtime-root` 或 archive `--destination` 不会隔离
Effect 后台进程;相同源码指纹可能让源码环境与已安装版本共享进程。演练前创建私有
临时目录,对所有子命令同时设置 `TMPDIR`、`TEMP`、`TMP`;Python 进程若已缓存
`tempfile.tempdir`,须在同一作用域覆盖并恢复。数据/registry 仍须单独隔离,且在
重型操作前核对服务 PID 与活跃服务不同。等请求结束后,只在同一临时环境中停止
演练进程。进程隔离不消除整机资源竞争:耗时对照顺序运行,发现竞争则保留失败与
回执、作废受污染耗时并重新采样;超时不能当作服务端已停止,也不能因此重复恢复。
恢复成功不证明并发管理操作公平性或自然时间 soak 已合格。

Keep a deterministic, public-safe production-scale fixture beside the focused
cases. Its envelope should cover realistic role/status distributions,
multi-agent claims, user gates and standing decisions, current and retired
Expand Down
19 changes: 16 additions & 3 deletions skills/loopx-self-repair/references/targeted-diagnostics.md
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,17 @@ and synthetic fixture or authorized read-only snapshot. Preserve integrity,
receipt recovery and lease/CAS semantics; do not benchmark by mutating an active
Goal. Check existing PRs before starting an overlapping store refactor.

A different registry, `--runtime-root`, archive destination or worktree does not
isolate the Effect server: identical source fingerprints can reuse the same
process through the user's temporary directory. Follow the testing guide's
**Isolate the managed Effect process as well as the data** procedure: use a
private existing directory for `TMPDIR`, `TEMP` and `TMP`, account for Python's
cached `tempfile.tempdir`, and check the serving PID before heavy work. Stop
only the isolated server after requests settle. If a rehearsal shared the live
server, retain its correctness/receipt evidence but exclude affected timings;
resample without overlapping heavy work before attributing a regression to a
provider or upgrade. Process isolation alone does not remove host CPU contention.

When unrelated lightweight rules and `runtime.ping` slow down together, test
shared event-loop starvation before attributing the timeout to the named rule.
Compare cold, warm and alternating-Goal reads in a separate runtime using fixed
Expand All @@ -81,9 +92,11 @@ precondition must still come from its authority owner. Do not add a Python
cache that bypasses the typed owner, or assume different providers share a
filesystem invalidation rule.

Separate this from storage-specific work. File-v0's retained journal decoding
and whole-file rewrite, SQLite transactions/indexes, and PostgreSQL queries and
network round trips have different costs. Prove a shared optimization through
Separate this from storage-specific work. Current File checkpoint/delta
verification and replay, SQLite transactions/indexes, and PostgreSQL queries and
network round trips have different costs. Identify the actual stored format;
do not apply retired File-v0 whole-history-write assumptions to File-v1.
Prove a shared optimization through
the common read/transaction contract, then qualify each affected real backend.
Preserve original-receipt recovery, stale-revision rejection and missing-state
fail-closed behavior. A successful promotion establishes authority ownership;
Expand Down
Loading