From c60116eb582293329e50340db5d49cf9bad0f64a Mon Sep 17 00:00:00 2001 From: huangruiteng Date: Fri, 2 Oct 2026 23:18:33 +0800 Subject: [PATCH] docs(rfc): reconcile SQLite adoption and legacy retirement exits Signed-off-by: huangruiteng --- .../2026-09-28-retirement-cadence.md | 150 +++++++++++++++--- .../2026-09-28-retirement-cadence.zh-CN.md | 123 +++++++++++--- .../rfcs/loopx-overall-roadmap-v0.md | 4 +- .../rfcs/loopx-overall-roadmap-v0.zh-CN.md | 4 +- ...shared-goal-authority-state-provider-v0.md | 44 ++--- ...-goal-authority-state-provider-v0.zh-CN.md | 30 ++-- .../typescript-control-plane-migration-v0.md | 30 ++-- ...script-control-plane-migration-v0.zh-CN.md | 23 +-- 8 files changed, 300 insertions(+), 108 deletions(-) diff --git a/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md b/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md index f453715744..ee501e19ee 100644 --- a/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md +++ b/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md @@ -1,6 +1,6 @@ # Local authority: retirement cadence after integration -- Audit: `ce3862e33`; adoption follow-up: `71525ab90`, September 28, 2026; [中文](2026-09-28-retirement-cadence.zh-CN.md). +- Current plan: October 2, 2026, `9b0486dc1`; historical audit: `ce3862e33`; adoption follow-up: `71525ab90`, September 28, 2026; [中文](2026-09-28-retirement-cadence.zh-CN.md). - Owners: overall roadmap R3/R4/R5/R6; shared authority D1–D3; TS migration T0–T4. - This replaces the **current inventory/estimates** in the September 27 recovery and Host-supervision ledgers, not their historical validation results. @@ -72,31 +72,129 @@ conversion. Local CLI adoption at `db3672f3c` verifies a clean source manifest, qualified SQLite runtime, current known authority formats and healthy canonical contract readback. This does not certify every installed Host or D2. -## Next delivery order +## Current closeout: validation, migration and deletion (2026-10-02) -| Order | Complete outcome / owner | Concrete exit and deletion opportunity | +Rechecked against main `9b0486dc1` and the linked PR heads. This is the current +execution plan for **R5 / D1–D3 / T0–T4**, replacing the previous A–D schedule; +older measurements remain source-specific evidence. R6 is a separate successor. +Storage format, authority selection and ownership policy are three distinct +migrations. A SQLite database does not imply canonical default creation or the +retirement of the `legacy` handoff policy. + +### Actual baseline and merge queue + +| State | Delivered boundary / next action | +| --- | --- | +| Merged: #4931, #5251 | SQLite replay/proof and allocation improvements. Reuse these implementations and retain their matched evidence; D2 is not certified by their merge. | +| Merged: #5395, #5417 | Unused Python lease/handoff crossings and duplicate settlement admission/recovery decisions retired. Continue deletion at actual last callers; do not count these again. | +| Merged: #5436 | Original delegated Host lease renewal. Final Todo validation and stop acknowledgement remain distinct boundaries. | +| Review: [#5413](https://github.com/loopx-project/loopx/pull/5413), `2c99505c7` | Separate provider promotion from backed-up policy migration; reject fresh legacy configuration but recover historical operations. CLI recovery repair: 99 affected tests and actual old-to-new CLI experiments on File/SQLite pass; final-head independent review remains. Existing legacy Goals are not automatically migrated. | +| Review: [#5466](https://github.com/loopx-project/loopx/pull/5466), `60a052383` | Preserve the original lease through final acceptance. Merge after independent review, then validate the installed execution path. | +| Review: [#5283](https://github.com/loopx-project/loopx/pull/5283), `73d1fe663` | Reduce preflight projection cost without reducing decision inputs; final capture reports provider unavailability explicitly. Author reports 96 unchanged-source File/SQLite inspections and full projection parity; independent review and installed readback remain. Do not declare the historical transient open failure explained by a synthetic failure. | +| Affected-lane dependencies | [#5308](https://github.com/loopx-project/loopx/pull/5308) must prove child stop before settled acknowledgement; [#5398](https://github.com/loopx-project/loopx/pull/5398) preserves complete UI history/inspector facts. Scope these to consumers actually included in the trial. They are not SQLite-engine prerequisites or permission to ship a known broken journey. | + +There are **three prioritized open closeout PRs**, not three PRs to universal +completion. The remaining implementation packages are creation/default adoption, +policy migration plus legacy-policy retirement, and old-writer/capture retirement. +They may combine only when caller ownership and rollback are coherent. Validation +can expose concrete repairs; do not manufacture a fixed remaining-PR total or +restart completed work to maintain one. + +### Ordered delivery packages and exits + +| Package / existing owner | Work and decisive exit | Dependency / deletion / schedule | +| --- | --- | --- | +| Close current heads; R3/R5 | Resolve exact-head findings in the three PRs above, inspect affected failures/conflicts, and present reviewed heads for maintainer merge. Record what is merged versus installed. | First target: 1–2 working days, subject to actual review/fix results. No unrelated optimization PR before closing these outcomes. | +| Installed recovery candidate; D1/D3, existing whole-Goal promotion task | Pin one merged source and actual CLI/App/Effect Node/SQLite identity. Independently restore a verified backup, run the matrix below on detached real data plus synthetic negatives, and complete File→SQLite→new writes→File. Then perform authorized per-Goal adoption and ordinary readback. | Begin immediately after relevant merges; target 1–2 working days for the bounded matrix. Keep the compatible recovery binary and archives. No live corruption/crash injection. | +| Bounded opt-in cohort; D2/D3 | When installed recovery and relevant execution controls pass, offer a reversible trial to at most 20 core developers. Publish workload/platform limits, backup/migration/disable instructions, known gaps, stop conditions and reporting route. Collect real daily use and failed cases. | Does not wait for every formal D2 axis or a new ten-day certificate. No invitation until rollback retains new writes. Does not certify a release default. | +| Canonical creation/default adoption; D3/T3 | Reuse `machine_configuration/goal_storage.py` and `local_authority_defaults.ts`. Current setting only chooses the **post-promotion target** (`promotion_performed: false`). Complete new-Goal initialization, retry and upgrade, settings plus packaged App/CLI/Lark readback; explicit existing selectors stay pinned. | Implement after the bounded candidate is useful; activate the release default only at the decision below. Remove replaced creation/selection decisions in this package. Changing `file` to `sqlite` in one setting is insufficient. | +| Two ownership policies; R3/R5/T4 | Use #5413's backup/plan/migrate owner. Inventory old/missing modes, finish eligible claims/leases and Host effects, migrate each authorized Goal, then narrow normal runtime types and defaults to `soft_claim` / `hard_lease`. Expose preview, authorized apply, result and failure/recovery in the existing Goal settings surface through the same owner; a CLI-only migration stage is partial. | Can proceed alongside cohort observation. Policy migration is independent of File↔SQLite conversion. Delete legacy execution only after the supported upgrade path and affected callers pass; never silently reinterpret legacy as soft. | +| Legacy writer and crossing removal; T3/T4 | Switch each last real caller to its TS owner, verify the matrix, delete Python decisions/private dispatch and old Markdown writes together. Reconcile shadow backlog before removing producers. Test the packaged CLI with retired paths absent. | Start already-proven internal deletions now; writer deletion follows that caller family's migration/adoption, not every R6 task or all Python disappearing. Each deletion has a concrete inventory and rollback. | +| Release-default decision; R5/D2/D3 | Reconcile supported installations, current-release comparison, representative sustained reads/writes/recovery, resource growth and existing soak applicability. Publish exact supported profile, failed/missing rows, release/upgrade guidance and disable path; disclose the default change. | No date inferred from test/PR counts. Formal ten-day/100k qualification retains its own required evidence. Existing File selections remain supported and pinned; unavailable SQLite never silently revives an old writer. | + +These windows are engineering targets, not acceptance certificates. Assess older +soak evidence from #4224 by source and changed boundary before deciding which +parts need rerunning; an unrelated commit does not erase elapsed time. The +current public record does not establish a completed applicable soak result. + +### One reusable validation matrix + +Record candidate and independent control revisions, actual runtime, complete +fixture/history digest, commands, pass/fail/untested, and stop/rollback outcome. +Use the current supported release as the performance control; retain the original +pre-migration baseline as a separate product comparison. Isolate both data and +Effect processes. Do not truncate metadata, history or decision inputs to win. + +| Boundary | Required experiment and invariant | Existing evidence owner | +| --- | --- | --- | +| Backup and complete data | Verify online SQLite snapshot and logical archive restore. Compare full Todo JSON, absent/null/false, unknown metadata, role/task class, archived dependencies, validation contracts/revisions, claims/lease generations, original events/receipts/cursors and the supported Goal/source state. Enumerate every stored family; counts or a final-head hash alone are insufficient. | `test_authority_archive.py`, `authority_archive_audit.test.ts`, archive crash/restore and migration suites | +| Forward and reverse migration | File→SQLite; add/update/complete and replay a real new operation; restart; export to File; assert all old facts **and the new writes** survive. Lost responses and identical retries return original outcomes; a different intent with the same operation ID rejects. | `local_authority_migration.test.ts`, archive and reviewed-cutover CLI suites | +| Mutation and ownership | Create/claim/update/complete/supersede/archive; quota selection→refresh→spend; same-Todo contention, stale revision/epoch, lease renew/release and applicable policy migration. One commit/effect/settlement, no ownership invention. | Real File/SQLite command suites; #5413/#5436/#5466; shared changes also use isolated real PostgreSQL | +| Interruption and recovery | Process death before/after durable commit and selector publication; provider unavailable/busy, disk-full injection, stalled projection and lagged consumer. Reopen/retry settles once and permits legitimate subsequent work. A still-running child cannot be called stopped/settled. | Existing crash/migration/process suites; #5308's affected Host lane | +| Installed consumers | CLI `status`, quota, Todo list/detail; packaged App list/inspector and ordinary mutation; Lark when included. Counts, metadata, freshness, error/recovery feedback and original-route results agree with canonical facts. Test restart and old page resource loading. | Existing projection/consumer tasks and packaged frontend smokes; #5398 where affected | +| Cost and endurance | Same data, history, durability and commands: cold full CLI versus warm store, p50/p95/p99/sample count, RSS, database/WAL and write growth, lock contention and consumer lag. Preserve failed formal macOS cold-CLI and missing axes; disclose absolute and relative current-release regressions. | #4224, SQLite comparison/rehearsal runner and existing performance-diagnosis capability | +| Deletion proof | Remove/disable the candidate old path in a disposable checkout; run real entrypoints and historical recovery. Inspect imports, dynamic handlers, packaging and fixtures for the last caller. Unsupported old input requests migration, never a Markdown fallback. | Implementation PR's retirement inventory and independent semantics/negative tests | + +For a bounded cohort, a material user-journey regression or failed recovery blocks +that affected lane. A proposed microbenchmark target is not a universal veto; +review measured tradeoffs without rewriting frozen reports. Data loss, altered +receipts, duplicate effects, wrong Goal identity or broken fencing always stop +writes at the affected boundary. Keep read-only evidence and recover through the +journal; rollback must export current committed state, not overwrite it with a +pre-migration snapshot. + +### Migration order and exact retirement boundaries + +1. Inventory each Goal's selected provider/format, promotion state, policy, + runtime, pending Turn/outbox/projection and actual writers. Existing canonical + SQLite Goals need validation, not another promotion. Canonical File Goals need + provider migration only when selected; unpromoted Markdown Goals need complete + capture and writer fencing. Do not confuse a database file with its selector. +2. Make and independently restore verified backups before migration. Stop new + admission for that Goal, drain/settle real in-flight work, revalidate the + source digest and plan, then use the reviewed CAS/selector owner. Neither lease + expiry nor a process exit alone proves external effects stopped. +3. Adopt and read back each authorized Goal; later writes remain canonical. + Source/provider/policy migrations keep separate receipts and recovery. A plan + without a result or an ambiguous response is resumed through its operation ID, + never by editing registry/selector bytes or replaying effects as new. +4. Delete according to this inventory; current source paths are candidates, not + a claim that every listed module is already dead: + +| Retire | Replacement and earliest exit | Keep / explicitly do not delete | | --- | --- | --- | -| A — start now | Whole-Goal execution/consumer integration; R3/R5 and existing Host/Turn owners | Trace capture→drain→promotion→CLI/status/quota/App/Lark reads and writes→settlement→restart→reverse migration with new writes. Inventory managed, attached and external execution; real cancellation acknowledgement/settlement is required, expiry alone is not proof. Reuse #5173/#5175. Retire only duplicated coordination within this complete journey. | -| B — alongside A | Local profile qualification; D1/D2, reuse #4931 | Matched File/SQLite workload including domain graph, metadata, history, latency/RSS, burst/lag and cold installed CLI. Record platform/runtime and declared limits. Fix a demonstrated failing row at its owner. SQLite remains a candidate; an optimization or small rehearsal does not choose the release default. File is the control arm, not an automatic fallback if qualification fails. | -| C — after A and profile decision | New-Goal/default/install/settings adoption plus supported existing-Goal upgrade; D3/T3 | New and upgraded installs, CLI, packaged App and Lark agree on one selected authority. Verified backups, reviewed migration, crash retry, non-upgraded rejection and rollback carrying new writes all work. Release default is an explicit decision. Remove migrated legacy writer branches in the same caller-family PR; do not leave a “cleanup someday” tail. | -| D — with C, per last caller | Remaining transport and capture retirement; T4 | Delete unused facade/dispatch/producers once native consumers adopt them; retain necessary host IO and migration readers. Full Python removal is not a prerequisite for canonical defaults, nor an automatic consequence of them. | - -Canonical execution tasks already cover whole-Goal promotion, local profile -qualification with a deletion inventory, and durable Markdown projection/rebuild. -Reconcile their evidence and continue those owners; projection failure must have -an explicit rebuild path without making Markdown a second writable authority. - -A/C may split if distinct execution or onboarding owners need independent -rollback; name the reason and exact remaining exit when splitting. B is evidence -work and can reveal additional fixes, not a predetermined PR. After these local -outcomes, R6 still needs authenticated PostgreSQL transport, tenant/identity -operations, pooling/cancellation/failover and cross-host qualification; reuse the -existing store/archive/service owners. Do not delay local deletion for R6. - -R3 instance/session adoption and R4 intent/acceptance continuity remain separate -product outcomes. Reuse the [deferred continuity scenarios](../../goal-immutability-coherence-defense-v0.md) -where the changed caller needs them; do not turn them into an unimplemented -universal gate. CAS success does not prove current Goal identity or task quality. +| `legacy` as a live ownership policy; missing-mode runtime default | `handoff_mode_policy.ts`, `handoff_mode_facts.ts` and actual lease/Todo/Host callers use the two explicit policies after versioned upgrade and consumer qualification | Old values only in migration decoding and original-receipt recovery. Replaying an old operation grants no new execution and cannot replace a later policy. Missing receipt rejects fresh legacy intent. | +| Writable Markdown Todo branches in `todos.py` / `todos/line_update.py` | Canonical create/update/terminal owners; new/default and supported existing Goal paths migrated | Human narrative, permanent Markdown projection/rebuild, validated import/export and old backup recovery; no missing-provider fallback | +| `runtime_shadow_writer_adapter.py` and obsolete capture producers | Last supported source writer removed; pending prepared/committed outbox classified and reconciled | Migration-owned historical outbox reader until its actual recovery obligation ends; no second ongoing capture authority | +| Duplicate Python decisions and private RPC facades | TS transaction owns semantics, effects and output; last production/dynamic/packaged caller switched with parity and recovery | Still-used transport, Host IO, specialist providers; do not delete `authority_core.py` or provider adapters wholesale because they are Python | +| Old normal format readers/writers | Versioned backup/upgrade before normal runtime opening; runtime uses current format only | Migration-only codecs and original history/receipts for the declared support window. Reader removal needs a separate compatibility decision, not all installed users inferred upgraded from local success. | + +Policy defaults are based on execution responsibility, not database brand: +`soft_claim` is the candidate for a local workflow whose ownership is cooperative +and whose effects need no exclusive execution grant; `hard_lease` is the candidate +for shared/cloud or overlapping workers and fenced external effects, including +local managed execution when required. Unknown topology requires explicit choice; +no implicit legacy default and no blanket soft fallback. Existing explicit +policies remain pinned until a reviewed migration. Final defaults are qualified +through their actual callers, not decided solely by “local” versus “cloud”. + +### Canonical Todo ownership and update rules + +Reuse the existing SQLite admission/Python retirement task as the program owner; +record the next concrete package, dependency, exact evidence and deletion exit in +its note. Reuse the whole-Goal promotion, canonical consumer inventory, permanent +Markdown projection, Host lease lifetime and full-summary/detail tasks for their +boundaries. Do not duplicate their work because an older note names a merged PR. +The existing closeout monitor should group the related head/review/merge changes, +then wake the relevant owning task; quiet polling is not advancement. + +Implementation gaps need actionable work with an explicit owner and acceptance: +canonical default/upgrade adoption; two-policy migration plus legacy execution +removal; and last-writer/capture deletion. Link these through existing task +successor/dependency fields rather than creating a second RFC or one monitor per +PR. Complete them only after installed readback and the documented deletion, +not at plan publication, review request or merge. Private Goal inventories, +backup paths, measurements and canonical task IDs stay outside public docs. ## Aggressive local qualification before deleting writers @@ -135,7 +233,9 @@ never kill/rewrite live Goals to make a test pass. isolated observer/copy. Formal D2's applicable ten-day natural-time soak cannot be accelerated by looping tests or backdating timestamps. Count it only from a recorded start, with restart gaps and source changes explicit. -4. **Cohort then default:** after the above required evidence, perform reviewed +4. **Cohort then default:** use the three-decision table in RFC Section 7.2; a + bounded opt-in trial may precede formal elapsed qualification after installed + recovery and the relevant execution controls pass. Perform reviewed backup/migration and observation of a bounded authorized cohort; expand only on demonstrated recovery. A local all-Goal migration does not prove external installs upgraded. Keep the old binary/artifacts for diagnosis, but select diff --git a/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md b/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md index 92523f6dd7..706c533239 100644 --- a/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md +++ b/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md @@ -1,6 +1,6 @@ # 合并后的本地权威退役节奏 -- 核对基线:`ce3862e33`;采用后续核对:`71525ab90`,2026-09-28;[English](2026-09-28-retirement-cadence.md)。 +- 当前计划:2026-10-02,`9b0486dc1`;历史核对基线:`ce3862e33`;采用后续核对:`71525ab90`,2026-09-28;[English](2026-09-28-retirement-cadence.md)。 - Owner:总 roadmap R3/R4/R5/R6、shared authority D1–D3、TS 迁移 T0–T4。 - 本记录替代 9 月 27 日 recovery、Host supervision 记录的**当前清单和估算**, 不替代其历史验证结果。 @@ -63,27 +63,109 @@ owner、持久兼容义务、正反例证据及回退方式,和不可变基线 `db3672f3c`,验证了干净源码清单、具备资格的 SQLite runtime、已知权威格式均为 当前版本及健康的 canonical 合同读回。这不证明所有已安装 Host 或 D2 已验收。 -## 下一轮交付顺序 +## 当前收尾:验证、迁移与删除(2026-10-02) -| 顺序 | 完整结果/owner | 具体出口与删除机会 | -| --- | --- | --- | -| A:现在开始 | 整 Goal 执行/消费者集成;R3/R5、现有 Host/Turn owner | 串起捕获→drain→晋升→CLI/status/quota/App/Lark 读写→settlement→重启→携带新写入迁回。核对 managed、attached、external 执行;真正取消确认/settlement 才是结束证明,过期不算。复用 #5173/#5175,在完整链路内删除重复编排。 | -| B:与 A 并行 | 本地 profile 验证;D1/D2,复用 #4931 | File/SQLite 同负载比较,包含领域图、metadata、历史、延迟/RSS、burst/lag、安装后冷 CLI,记录平台/runtime/限额。哪里失败就修其 owner。SQLite 仍是候选;优化或小演练不能决定发布默认值。File 是对照组,不是资格失败后的自动替代。 | -| C:A 与 profile 决策通过后 | 新 Goal/默认/安装/设置接入,加受支持存量升级;D3/T3 | 新装和升级、CLI、打包 App、Lark 使用同一选定权威。备份验证、reviewed migration、中断恢复、未升级拒绝及携带新写入回退可用;发布默认值显式决定。同一调用家族 PR 删除已替代的 legacy writer,不留“以后再清理”。 | -| D:伴随 C,按最后调用方推进 | 其余传输与捕获退役;T4 | native 消费者接管后删 facade/dispatch/producer,保留必要 Host IO 和迁移 reader。全部 Python 消失既不是 canonical 默认的前置,也不是切换后的自动结果。 | - -Canonical 任务已覆盖整 Goal 晋升、本地 profile 与退役清单、持久 Markdown 投影/ -显式重建。先对齐这些任务的证据并沿用已有 owner;投影失败应能明确重建,不能 -因此把 Markdown 重新变成第二套可写权威。 +按 main `9b0486dc1` 和所列 PR head 重新核对。本节是 **R5 / D1–D3 / T0–T4** +的当前执行计划,替代旧 A–D 排期;历史测量仍只适用于原源码和负载。R6 单独推进。 +存储格式、权威选择、所有权策略是三种不同迁移:有 SQLite 数据库,不代表新 Goal +已经默认使用 canonical authority,也不代表 `legacy` handoff 策略已经退役。 -A/C 若因不同执行或 onboarding owner 需要独立回退,可以拆分,但须写明原因和 -剩余出口。B 是证据工作,可能暴露新的修复,不预先折算为 PR。之后 R6 仍须完成 -PostgreSQL 认证传输、tenant/identity 运维、连接池/取消/failover 和跨 Host 验证, -复用现有 store/archive/service owner;不让 R6 阻止本地代码退役。 +### 实际基线与合并队列 -R3 实例/session 接入和 R4 意图/验收连续性仍是独立产品结果。受影响调用方复用 -[后续连续性场景](../../goal-immutability-coherence-defense-v0.zh-CN.md),不把它扩张为 -尚未实现的全局门禁;CAS 成功不能证明当前 Goal 身份或任务质量。 +| 状态 | 已交付边界/下一步 | +| --- | --- | +| 已合并:#4931、#5251 | SQLite 重放/证明和分配优化;复用实现及匹配证据,合并不等于 D2 已验收。 | +| 已合并:#5395、#5417 | 无调用方的 Python lease/handoff 跨界、重复结算准入/恢复决策已退役。继续按最后调用方删除,不重复计账。 | +| 已合并:#5436 | 委派 Host 原租约续期;最终 Todo 验收和停止确认仍是不同边界。 | +| 复审中:[#5413](https://github.com/loopx-project/loopx/pull/5413),`2c99505c7` | provider 晋升与带备份的策略迁移解耦;禁止新 legacy 配置,允许恢复历史操作。CLI 恢复修复的 99 项相关测试、File/SQLite 真实旧 CLI→新 CLI 演练通过,最终 head 独立复审待完成。没有自动迁移存量 legacy Goal。 | +| 待审:[#5466](https://github.com/loopx-project/loopx/pull/5466),`60a052383` | 原租约保持到最终验收;独立评审、维护者合并后验证安装态执行路径。 | +| 待审:[#5283](https://github.com/loopx-project/loopx/pull/5283),`73d1fe663` | 不缩减决策输入地降低 preflight 投影成本,末次 capture 显式报告 provider 不可用。作者报告固定源码下 96 次 File/SQLite 检查及完整投影等价;仍需独立复审和安装后读回。合成故障不证明历史瞬态打开失败的根因。 | +| 按实际路径建立依赖 | [#5308](https://github.com/loopx-project/loopx/pull/5308) 要证明子进程停止后才报告已结算;[#5398](https://github.com/loopx-project/loopx/pull/5398) 保留 UI 历史和 inspector 完整事实。只对纳入试用的相关消费者建依赖,不将其说成 SQLite 引擎前置,也不能发布已知损坏的用户路径。 | + +当前优先收尾的是 **3 个已存在的开放 PR**,不等于再合 3 个就全部结束。 +剩余实现包是 canonical 创建/默认接入、策略迁移与 legacy 策略删除、旧 writer/ +捕获退役。仅当调用方归属和回退边界一致时才合并成同一个 PR。验证可能暴露具体修复, +不再制造固定“剩余 PR 数”,也不为维持这个数字重做已完成的工作。 + +### 有依赖顺序的交付包与出口 + +| 交付包/既有 owner | 要做什么、凭什么完成 | 依赖/删除机会/节奏 | +| --- | --- | --- | +| 现有 head 收尾;R3/R5 | 修完上述 3 个 PR 的 exact-head finding,处理相关失败与冲突,提交已评审 head 给维护者合并;区分已合并和已安装。 | 第一目标为 1–2 个工作日,取决于真实评审/修复结果;收尾前不另开无关优化。 | +| 安装态恢复候选;D1/D3、整 Goal 晋升任务 | 固定合并源码和 CLI/App/Effect 实际 Node/SQLite 身份;独立恢复并验证备份,用隔离真实快照及合成负例执行下表,完成 File→SQLite→新增写入→File。之后按授权逐 Goal 采用并日常回读。 | 相关 PR 合并后立即开始,有界矩阵目标 1–2 个工作日;保留兼容的恢复版本和 archive,不对活跃 Goal 注入崩溃/损坏。 | +| 有界自愿试用;D2/D3 | 安装态恢复及相关执行控制通过后,邀请不超过 20 位核心开发者。公开负载/平台范围、备份迁移关闭步骤、已知缺口、停止条件与反馈入口;观察真实日常使用和失败。 | 不必等待全部正式 D2 轴或一份新的十天证书;携带新写入回退未通过前不邀请。试用不认证发布默认值。 | +| Canonical 创建/默认接入;D3/T3 | 复用 `machine_configuration/goal_storage.py` 和 `local_authority_defaults.ts`。当前设置只选择**晋升后的目标**,返回 `promotion_performed: false`。补齐新建初始化/重试、升级、设置及打包 App/CLI/Lark 读回,已有显式 selector 保持固定。 | 有界候选可用后实现,发布默认启用仍服从下方决策;同包删除被替代的创建/选择决策。只把设置里的 file 改成 sqlite 不够。 | +| 两种所有权策略;R3/R5/T4 | 复用 #5413 的 backup/plan/migrate owner。清点旧/缺省 mode,结清适用的 claim/lease 和 Host 效果,逐个迁移获授权 Goal,再将正常运行类型及默认值收敛为 soft_claim / hard_lease。复用既有 Goal 设置入口和同一 owner,提供预览、获授权执行、结果及失败/恢复;只有 CLI 的迁移阶段标为部分交付。 | 与试用观察并行;不和 File↔SQLite 转换绑定。受支持升级路径和调用方通过后删除 legacy 执行,不能默默把 legacy 当成 soft。 | +| 旧 writer/跨界删除;T3/T4 | 最后真实调用方切到 TS owner 后验证下表,同时删除 Python 决策/私有 dispatch 和旧 Markdown 写入;清理 capture producer 前对账 outbox。在旧路径已不存在的包上验证 CLI。 | 已证明无消费者的内部删除现在就做;业务 writer 删除随对应迁移接入,不等 R6 全部完成或所有 Python 消失。每批有具体清单和回退方式。 | +| 发布默认决策;R5/D2/D3 | 对账受支持安装、当前 release 对照、代表性持续读写/恢复、资源增长和既有 soak 适用性;发布明确 profile、failed/missing、升级说明及关闭路径,显式披露默认变化。 | 不按测试/PR 数推算日期;正式十天/100k 资格保留各自证据要求。已有 File 选择继续受支持并固定;SQLite 不可用不能静默唤回旧 writer。 | + +以上是工程目标,不是资格证书。先按源码和变化边界核对 #4224 的旧 soak,再决定 +哪些证据需补跑;无关提交不抹掉自然时间。当前公开记录未证明已完成且适用于当前 +候选的 soak 结果。 + +### 一份可复用的验证矩阵 + +每行记录候选/独立对照源码、实际 runtime、完整 fixture/历史摘要、命令、 +通过/失败/未测和停止/回退结果。性能使用当前受支持 release 做对照,最初迁移前 +基线保留为独立产品比较。同时隔离数据与 Effect 进程,不靠截断 metadata、历史或 +决策输入赢指标。 + +| 边界 | 必做实验及不变量 | 复用的证据 owner | +| --- | --- | --- | +| 备份与完整数据 | 验证 SQLite 在线快照及逻辑 archive 恢复;比较完整 Todo JSON、缺省/null/false、未知 metadata、role/task class、归档依赖、验收合同/版本、claim/lease generation、原 events/receipt/cursor,以及受支持 Goal/source 状态。枚举全部持久状态家族,不能只比数量或最后 head hash。 | `test_authority_archive.py`、`authority_archive_audit.test.ts`、archive crash/restore 和迁移套件 | +| 正反向迁移 | File→SQLite,真正新增/修改/完成并重放一笔新操作,重启后导回 File;全部旧事实和**新增写入**都保留。丢响应与相同重试回原结果,同 operation ID 不同意图拒绝。 | `local_authority_migration.test.ts`、archive 与 reviewed-cutover CLI 套件 | +| 写入与所有权 | create/claim/update/complete/supersede/archive,quota 选择→refresh→spend,同 Todo 竞争、旧 revision/epoch、lease 续期/释放及适用策略迁移;一笔 commit/effect/settlement,不凭空造所有权。 | 真实 File/SQLite 命令套件;#5413/#5436/#5466;共享修改还须隔离真实 PostgreSQL | +| 中断与恢复 | durable commit/selector 发布前后进程中断、provider unavailable/busy、空间不足注入、投影卡住和 consumer 滞后;重启/重试只结算一次且后续合法工作可继续。子进程还活着不能报告已停止/已结算。 | 既有 crash/migration/process 套件;#5308 相关 Host 路径 | +| 安装态消费者 | CLI status/quota/Todo list/detail;打包 App 列表/inspector 和普通修改;纳入范围时验证 Lark。数量、metadata、新鲜度、错误/恢复反馈、原路返回与 canonical 事实一致,覆盖重启和旧标签页资源。 | 既有投影/消费者任务、打包前端 smoke;受影响处采用 #5398 | +| 成本与持续运行 | 相同数据/历史/durability/命令,分别测完整冷 CLI 和 warm store,报告 p50/p95/p99/样本数、RSS、DB/WAL/写增长、锁竞争及 consumer lag。正式 macOS 冷 CLI 失败及缺项保持可见,披露相对当前 release 的绝对值与相对变化。 | #4224、SQLite comparison/rehearsal runner、既有 performance-diagnosis capability | +| 删除证明 | 一次性 checkout 中删掉/禁用候选旧路径,跑真实入口与历史恢复;检查 import、动态 handler、打包和 fixture 最后调用方。不支持的旧输入提示迁移,不能退回 Markdown 写入。 | 实现 PR 的退役清单、独立语义和负例测试 | + +有界试用中,显著用户路径退化或恢复失败阻止该路径采用;提议的微基准预算不构成 +所有合并的否决权,实测权衡不能重写冻结报告。数据丢失、原回执改变、重复效果、 +Goal 身份错误或 fence 破坏始终停止相关写入,保留只读证据并按 journal 恢复。 +回退必须导出当前已提交状态,不能用迁移前快照盖掉后续写入。 + +### 迁移顺序与准确删除边界 + +1. 逐 Goal 清点 provider/格式、晋升状态、策略、runtime、未结 Turn/outbox/projection + 和真实 writer。已 canonical 的 SQLite Goal 做验证,不重复 promote;canonical + File 按需做 provider 迁移;未晋升 Markdown 做完整捕获和 writer fence。 + 数据库文件不等于已选中的 authority。 +2. 迁移前备份并独立恢复验证;停止该 Goal 新准入,drain/结算真实在途工作,重新 + 校验 source digest 和计划,再走已有 CAS/selector owner。lease 过期或进程退出 + 均不能单独证明外部效果已停止。 +3. 按授权逐个采用并回读,后续写入以 canonical 为准。source/provider/policy 迁移 + 各有独立回执和恢复。计划无结果或丢响应按 operation ID 续接,不能手改 registry/ + selector,或把已发生效果当成新操作重做。 +4. 按下表删除;以下是真实源码候选,不是在宣称每个模块现在就能整文件删除: + +| 删除对象 | 替代和最早出口 | 保留/明确不删 | +| --- | --- | --- | +| 活跃所有权策略 legacy,以及缺 mode 的运行默认值 | `handoff_mode_policy.ts`、`handoff_mode_facts.ts` 和真实 lease/Todo/Host 调用方完成版本化升级、消费者验收,正常路径只运行两种显式策略 | 旧值只留迁移解析和原回执恢复。重放旧操作不授予新执行权、不覆盖后来的策略;没有旧回执就拒绝新 legacy 意图。 | +| `todos.py` / `todos/line_update.py` 的可写 Markdown Todo 分支 | canonical create/update/terminal owner;新建/默认与受支持存量 Goal 路径完成迁移 | 人工叙述、永久 Markdown 投影/重建、合格 import/export 与旧备份恢复;provider 缺失不回退 | +| `runtime_shadow_writer_adapter.py` 等旧捕获 producer | 最后受支持源 writer 已退役,prepared/committed outbox 均已分类和对账 | 真实恢复义务结束前,迁移内历史 outbox reader 保留;不保留第二套持续捕获权威 | +| Python 重复决策和私有 RPC facade | TS 事务拥有语义、效果与输出;最后生产/动态/打包调用方切走并完成等价/恢复验证 | 仍使用的 transport、Host IO、专门 provider;不因 Python 语言就整删 authority_core.py 或 provider adapter | +| 旧正常格式 reader/writer | 正常 runtime 打开前走版本化备份升级,日常只读写当前格式 | 支持窗口内的迁移 codec、原历史/回执。删 reader 需明确兼容决策,不能由本机升级成功推断全部用户升级。 | + +策略默认值按执行责任而不是数据库品牌选择:协作式所有权、效果不需要排他执行 +凭据的本地工作流候选为 `soft_claim`;共享/云端、重叠 worker 和须 fence 的外部 +效果候选为 `hard_lease`,本地 managed 执行需要时同样采用 hard。未知拓扑要求 +明确选择,不隐含 legacy,也不统一降到 soft。既有显式策略经 reviewed migration +才改变;最终默认值须用真实调用方验证,不能仅按“本地/云端”字面分类。 + +### Canonical Todo 归属与更新规则 + +沿用 SQLite 准入/Python 退役任务作为计划 owner,在 note 写入下一个具体交付包、 +依赖、精确证据和删除出口。整 Goal 晋升、canonical 消费者清单、永久 Markdown +投影、Host lease 生命周期、完整 summary/detail 复用各自任务;旧 note 提到已合并 +PR 不构成重复开工的理由。现有收尾 monitor 归并相关 head/review/merge 变化, +唤醒对应 owner;安静轮询不算推进。 + +实际实现缺口要有 owner 和验收:canonical 默认/升级接入、两策略迁移及 legacy +执行删除、最后 writer/capture 删除。用现有 successor/dependency 字段关联, +不另造 RFC,不给每个 PR 建一个 monitor。安装回读及约定删除完成后才结项,发布 +计划/请求评审/合并均不能代替完成。私有 Goal 清单、备份路径、测量和 Todo ID +不进入公共文档。 ## 删除 writer 前,本机可以积极做的验证 @@ -103,7 +185,8 @@ R3 实例/session 接入和 R4 意图/验收连续性仍是独立产品结 WAL 增长、最老积压/consumer lag、不确定结果恢复、重复效果和实例污染。 每日读回,定期在隔离 observer/副本中验证恢复。适用的 D2 十天自然时间 soak 不能靠循环测试或回填时间戳加速;有记录的起点才开始计时,明确重启间隙和源码变化。 -4. **先 cohort 后默认:** 所需证据通过后,对有限且获授权 cohort 做 reviewed +4. **先 cohort 后默认:** 按 RFC 7.2 的三层决策,安装恢复及相关执行控制通过后, + 有界自愿试用可以先于正式自然时间资格开展。对有限且获授权 cohort 做 reviewed 备份/迁移/观察,以恢复证据决定扩面。本机所有 Goal 迁移也不等于外部用户 已升级。旧 binary/artifact 保留用于诊断,但操作/回退必须用与当前格式兼容的版本。 diff --git a/docs/architecture/rfcs/loopx-overall-roadmap-v0.md b/docs/architecture/rfcs/loopx-overall-roadmap-v0.md index 25b1c7f766..9019a2bc8c 100644 --- a/docs/architecture/rfcs/loopx-overall-roadmap-v0.md +++ b/docs/architecture/rfcs/loopx-overall-roadmap-v0.md @@ -8,7 +8,7 @@ - Ownership: overall product outcomes, cross-domain dependencies, priorities and portfolio acceptance here; concrete rules in domain RFCs/stable protocols; execution state in canonical Todos. - Language: [中文版](loopx-overall-roadmap-v0.zh-CN.md) is the semantic mirror. -**Local authority retirement checkpoint (2026-09-28).** R5/T4 now use the [reconciled deletion and qualification cadence](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md). Reviewed local cutover and native drain are merged; whole-Goal execution/consumer closure, profile qualification and default-entry adoption still have separate exits. Delete a replaced writer with its last caller; retain necessary migration/receipt readers. Existing GoalRef/Turn PRs own their affected consumers. R6 PostgreSQL service qualification is separate, and the historical PR-count estimates are not current forecasts. +**Local authority closeout checkpoint (2026-10-02).** R5/T4 use the [current validation → migration → deletion plan](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md#current-closeout-validation-migration-and-deletion-2026-10-02), rechecked at `9b0486dc1`. Close existing #5413/#5466/#5283, qualify one installed reversible candidate, then decide a bounded opt-in cohort separately from release-default admission. Canonical creation, legacy-policy migration and last-writer deletion have named exits; delete replaced Python owners with their last callers. R6 remains separate. No fixed remaining-PR count or historical test count certifies completion. Conversational preparation from [PR #4376](https://github.com/loopx-project/loopx/pull/4376) is integrated under R1/GQ01 through the existing Chat draft and reviewed Goal @@ -705,7 +705,7 @@ L3 checkpoint: standalone acquisition/takeover, atomic claim admission and maint - **Owner:** TS T0–T4 and shared-authority D1–D3; retain their numbering and gates. - **Selection:** prioritize an entire hot-path transaction or recovery lifecycle used by R1–R4. Record before/after callers, owners, crossings, actual deletions and performance. Stop adding per-field Python→TS RPCs; do not rebuild the merged Todo update. - **Delivery:** qualify full-source reads, one-way Markdown projection, event/receipt retention, restart recovery, capacity and long-term cost on the selected local profile. Source failure cannot fall back to legacy. R1 cannot put large plan bodies into the coordination head. -- **Exit:** affected real CLI/backend, immutable baseline versus candidate comparison, negative/mutation coverage, three-arm rehearsal and applicable D2 soak of at least ten days. D3 retains explicit cutover approval. This audit runs no new soak and promotes no provider. +- **Exit:** use shared-authority Section 7.2's separate decisions for a bounded change, reversible opt-in cohort and released default. Each requires affected real CLI/backend and independent baseline/negative/recovery evidence at its own scope. Formal D2 retains applicable volume and at least ten-day evidence; a cohort need not wait for that certificate. D3 retains explicit cutover authority. This plan runs no soak or provider promotion. - **Rollback:** reviewed fenced export/import and schema-aware downgrade; replacing a binary cannot restore old write authority. The [Goal instance/recovery proposal](goal-instance-identity-and-orphan-recovery-v0.md) diff --git a/docs/architecture/rfcs/loopx-overall-roadmap-v0.zh-CN.md b/docs/architecture/rfcs/loopx-overall-roadmap-v0.zh-CN.md index ac79d75100..8efbf2dfbf 100644 --- a/docs/architecture/rfcs/loopx-overall-roadmap-v0.zh-CN.md +++ b/docs/architecture/rfcs/loopx-overall-roadmap-v0.zh-CN.md @@ -7,7 +7,7 @@ - 责任:总纲拥有产品目标、跨领域依赖、优先级和组合验收;领域 RFC/稳定协议拥有具体规则;运行 Todo 拥有执行状态。 - 语言:[English](loopx-overall-roadmap-v0.md) 与本文互为语义镜像。 -**本地权威退役 checkpoint(2026-09-28)。** R5/T4 采用[重新核对的删除和验证节奏](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md)。Reviewed 本地切换和 native drain 已合入;整 Goal 执行/消费者闭环、profile 验证、默认入口接入仍分别验收。切走最后调用方时同步删旧 writer,保留必要迁移/回执 reader。已有 GoalRef/Turn PR 负责各自消费者;R6 PostgreSQL 服务验证另列,历史 PR 数量估算不再作为当前预测。 +**本地权威收尾检查点(2026-10-02)。** R5/T4 使用按 `9b0486dc1` 复核的[验证→迁移→删除计划](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md#当前收尾验证迁移与删除2026-10-02)。先收尾现有 #5413/#5466/#5283,验证一个安装态可回退候选,再分别决定有界自愿试用和发布默认准入。Canonical 创建、legacy 策略迁移与最后 writer 删除各有明确出口;Python 替代 owner 随最后调用方删除。R6 独立,不用固定剩余 PR 数或历史测试数量证明完成。 ## 1. 总目标与产品路线 @@ -512,7 +512,7 @@ L3 检查点:独立领取/接管、原子 claim 准入与维护共用 typed le - **Owner:** TS RFC T0–T4、shared-authority D1–D3;保留两套编号及原门禁。 - **选择规则:** 优先迁移 R1–R4 热路径的一笔完整事务或恢复生命周期,附前后 caller/owner/crossing 表、实际删除和性能证据。不要继续按单字段增加 Python→TS RPC;不要重建已合入的 Todo update。 - **交付:** 用已选本地 profile 验证完整来源读取、单向 Markdown 投影、event/receipt 保留、重启恢复、容量与长期成本;source 失败不能回退 legacy。R1 不能把大计划正文塞入 coordination head。 -- **退出:** 相关真实 CLI/backend、不可变 baseline 与候选对照、负例/mutation、三臂演练及适用 D2 至少十日 soak;D3 切换保留明确批准。此次审计没有执行新的 soak,也未晋升 provider。 +- **退出:** 按 shared-authority 7.2 分别决定有界改动、可回退自愿 cohort、发布默认值,各自在适用范围具备真实 CLI/backend、独立基线、负例和恢复证据。正式 D2 保留适用容量及至少十日证据,cohort 不必等该证书。D3 保留明确切换权限。本计划没有启动 soak 或晋升 provider。 - **回滚:** 按已审阅的 fenced export/import 和 schema-aware downgrade,不能靠替换二进制恢复旧写权威。 [Goal instance/recovery 提案](goal-instance-identity-and-orphan-recovery-v0.zh-CN.md) diff --git a/docs/architecture/rfcs/shared-goal-authority-state-provider-v0.md b/docs/architecture/rfcs/shared-goal-authority-state-provider-v0.md index aa0c3bebe2..825404c8a6 100644 --- a/docs/architecture/rfcs/shared-goal-authority-state-provider-v0.md +++ b/docs/architecture/rfcs/shared-goal-authority-state-provider-v0.md @@ -24,21 +24,22 @@ [Chinese version](./shared-goal-authority-state-provider-v0.zh-CN.md) and this English version are semantic mirrors. A difference between them is a defect. -## Current delivery frontier (2026-09-28) - -Audit `ce3862e33`: #5054, #5140, #5144, #5156, #5173, #5175 and #5169 -are merged. Do not count event retirement, archive recovery, managed process -supervision, reviewed local cutover or native drain as new pending PRs. -The SQLite read-proof optimization [#4931](https://github.com/loopx-project/loopx/pull/4931) -has since merged at `9482a9496`; D2 qualification remains incomplete. - -Next: qualify whole-Goal execution/consumer integration and matched local -profiles in parallel; then unify new-Goal/install/settings and supported upgrade -entrypoints, deleting each replaced writer with its last caller. Retain necessary -Host IO, original receipts and migration readers. No additional dead Python -module is certified by this audit, and no fixed remaining-PR total is promised. -[Deletion inventory, engineering windows, local evidence and remaining work](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md) -supersedes older current-count estimates; their execution evidence stays historical. +## Current delivery frontier (2026-10-02) + +At main `9b0486dc1`, #4931, #5251, #5395, #5417 and #5436 are merged. +Do not recount their storage improvements or Python retirement as pending work. +The [current validation, migration and deletion plan](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md#current-closeout-validation-migration-and-deletion-2026-10-02) +prioritizes #5413/#5466/#5283 closeout, installed reversible qualification, +bounded opt-in adoption, canonical creation/defaults and last-caller deletion. +Existing Goal migration, two-policy ownership retirement and storage-format +upgrade have separate receipts and exits. Original-receipt recovery does not +justify retaining `legacy` as a live policy. Required migration readers remain. + +A bounded cohort can start after its installed recovery and relevant execution +controls pass; it does not certify a released default or formal ten-day D2. +Frozen failures/missing evidence remain visible. T4 deletes proven redundant +owners alongside implementation, without waiting for R6 or all Python to vanish. +This replaces stale current-count estimates, not historical execution evidence. File retained-state storage now reuses the existing TS checkpoint/delta codec, stacked on #5063's verified read cache and RPC budgets. Original revisions, @@ -1347,9 +1348,11 @@ to an independent reference; no lost acknowledged commit or repeated effect is acceptable. Use disposable goals, never active user state. Compressed clocks do not qualify wall-clock endurance; publishing this RFC starts no soak or monitor. -A code PR can land while soak evidence remains pending, with promotion held. -Promotion requires both exits, explicit import/fencing/export rehearsal and -maintainer review. Publish compact reproducible evidence, not raw private logs. +A code PR can land while formal soak evidence remains pending. Formal profile +promotion requires both exits, explicit import/fencing/export rehearsal and +maintainer review. A separately authorized, bounded opt-in cohort uses the +installed recovery decision above; it does not claim that formal profile. +Publish compact reproducible evidence, not raw private logs. #### SQLite-for-file transition milestones (proposal) @@ -1363,8 +1366,9 @@ is gated by evidence below, not by calendar dates or this PR's merge status. | --- | --- | --- | | Candidate conformance | Review #4121's atomic commits, original receipts, cursor/digest integrity, typed provider-open failures, real CLI and OS/runtime tests. | Candidate only. File remains default; no live migration or promotion. | | Bounded local profile (L) | Meet this section's unchanged workload/budget matrix, including 64 KiB matched 10k/100k runs, 1 MiB and 300k headroom, cold startup, lock wait, RSS and logical write growth. Qualify bounded checkpoints/deltas and receipt lookup while preserving exact historical scans. | No default flip. Keep integrity checks; if their cost grows beyond the profile, fix the design or narrow the explicitly supported profile. | -| Fenced migration and recovery (I/F prerequisites) | On disposable Goals, prove file-to-SQLite import, exact receipt/replay equivalence, consumer cursor/outbox preservation, crash/disk-full recovery and reverse export/rollback. Include the required independent legacy/file/PostgreSQL read-only rehearsal where shared routing or projections change. | Tooling and migration manifest must be reviewed first. Today's empty-goal selector is not an existing-goal migration API. Never test on an active user's Goal. | -| Elapsed qualification and opt-in canary | Complete an actual >=10-day synthetic soak, including the specified restart, sleep, day-1 retry and 24 h consumer-lag cases. Then request separate authorization for a small opt-in operator canary with recorded stop/rollback criteria. | All C/I and selected-provider holds still apply. Evidence from accelerated volume cannot replace elapsed time; a canary does not authorize a general default. | +| Fenced migration and recovery (I/F prerequisites) | On disposable Goals, prove file-to-SQLite import, exact receipt/replay equivalence, consumer cursor/outbox preservation, crash/disk-full recovery and reverse export/rollback. Include the required independent legacy/file/PostgreSQL read-only rehearsal where shared routing or projections change. | Tooling and migration manifest must be reviewed first. Use the reviewed existing-Goal archive/cutover API; an empty-goal selector alone is insufficient. Never test on an active user's Goal. | +| Recoverable opt-in canary | Verified installed backup/migration/restart, ordinary commands, relevant interruption/concurrency controls and reverse migration preserving new writes; separately authorized and limited to the demonstrated workload. | May precede formal ten-day qualification. Record stop/rollback criteria; no general default or formal-horizon claim. | +| Formal elapsed qualification | Complete the actual >=10-day synthetic soak with specified restart, sleep, day-1 retry and 24 h consumer lag; reconcile existing evidence with changed boundaries. | Accelerated volume does not replace elapsed time; formal profile holds and frozen reports remain explicit. | | New-Goal default decision (F) | Maintainers accept the qualified profile and canary results, operational diagnostics, backup/restore procedure, release instructions and default-disable path. Ship the default change in a separate disclosed release change. | Apply only to newly created eligible local Goals. Existing explicit file selections remain pinned. Unsupported runtimes/filesystems require an explicit supported choice; no silent backend switch on open failure. | | Existing-Goal migration and file retirement | Migrate opt-in cohorts using the reviewed fenced workflow; reconcile receipts, history, projections and rollback after each cohort. Inventory the last file-primary callers and compatibility windows before removing any path. | Each Goal needs explicit migration authority. Retire file as the ordinary primary only after that evidence; retain reference/import/export support until its own callers and retention duties end. | diff --git a/docs/architecture/rfcs/shared-goal-authority-state-provider-v0.zh-CN.md b/docs/architecture/rfcs/shared-goal-authority-state-provider-v0.zh-CN.md index c2b242c91a..0d5a573321 100644 --- a/docs/architecture/rfcs/shared-goal-authority-state-provider-v0.zh-CN.md +++ b/docs/architecture/rfcs/shared-goal-authority-state-provider-v0.zh-CN.md @@ -21,18 +21,18 @@ - 语言说明:[英文版](./shared-goal-authority-state-provider-v0.md)与本中文版互为 语义镜像;两者不一致属于缺陷 -## 当前交付边界(2026-09-28) +## 当前交付边界(2026-10-02) -按 `ce3862e33` 核对,#5054、#5140、#5144、#5156、#5173、#5175、#5169 -均已合并。事件退役、archive 恢复、managed 进程监督、reviewed 本地切换和 native -drain 不再计作新待办 PR。此后 SQLite 读取证明优化 -[#4931](https://github.com/loopx-project/loopx/pull/4931) 已在 `9482a9496` 合并;D2 资格化仍未完成。 +按 main `9b0486dc1` 核对,#4931、#5251、#5395、#5417、#5436 已合并, +不再把这些存储改进和 Python 退役重复记作待办。 +[当前验证、迁移与删除计划](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md#当前收尾验证迁移与删除2026-10-02) +优先收尾 #5413/#5466/#5283,再做安装态可回退验证、有界自愿采用、canonical +创建/默认接入及最后调用方删除。存量 Goal 迁移、两策略退役和格式升级各有独立 +回执及出口;原回执恢复不能成为保留 legacy 活跃策略的理由,必要迁移 reader 保留。 -接下来并行验证整 Goal 执行/消费者集成和本地 profile,再统一新 Goal/安装/设置 -及受支持升级入口,切走最后调用方时同步删除对应旧 writer。保留必要 Host IO、 -原回执与迁移 reader。本轮未认证额外某个 Python 模块已死,也不承诺固定剩余 PR 数。 -[删除清单、工程窗口、本机证据及剩余工作](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md) -替代旧记录的当前数量估算,旧执行证据仍按历史保留。 +有界 cohort 在安装恢复和相关执行控制通过后可开始,不代表发布默认值或正式十天 +D2 已通过;冻结的失败/缺项保持可见。T4 随实现删除已证明重复的 owner,不等 R6 +或所有 Python 消失。本节替代陈旧的当前数量估算,不覆盖历史执行证据。 ## Todo 事件路径退役(2026-09-25) @@ -1031,8 +1031,9 @@ crash、disk-full、backup/restore lineage,以及一次受支持 upgrade/rollb 一次性 goal,不碰活跃用户状态。压缩时钟不证明自然时间耐久性;发布本 RFC 不启动 soak 或 monitor。 -代码 PR 可在 soak 证据待补时合入,但 promotion 继续 hold。两个出口、显式 import/ -fencing/export 演练与 maintainer review 都通过才可晋升。发布紧凑可复现证据,不发布 +代码 PR 可在正式 soak 证据待补时合入。正式 profile 晋升仍须两个出口、显式 +import/fencing/export 演练及 maintainer review;另行授权、有界 opt-in cohort +按上方安装态恢复决策执行,不宣称正式 profile 通过。发布紧凑可复现证据,不发布 原始私有日志。 #### SQLite 替换 file 的阶段节点(提案) @@ -1046,8 +1047,9 @@ fencing/export 演练与 maintainer review 都通过才可晋升。发布紧凑 | --- | --- | --- | | 候选 conformance | 评审 #4121 的原子提交、原始 receipt、cursor/digest 完整性、typed provider-open 失败、真实 CLI 与 OS/runtime 测试。 | 仅候选。file 仍默认;不迁移活跃 Goal,不授予 promotion。 | | 有界本地 profile(L) | 满足本节不变的负载与预算矩阵:64 KiB 下匹配的 10k/100k、1 MiB 与 300k 余量、冷启动、锁等待、RSS、逻辑写入增长;资格化有界 checkpoint/delta 和 receipt 查询,同时保留精确历史 scan。 | 不切默认。保留完整性校验;成本超出 profile 时修正设计或明确缩小支持范围。 | -| 带 fence 的迁移与恢复(I/F 前置) | 在一次性 Goal 上证明 file→SQLite 导入、原始 receipt/replay 等价、consumer cursor/outbox 保留、crash/disk-full 恢复和反向导出/回滚;共享路由或投影变化时纳入要求的独立 legacy/file/PostgreSQL 只读演练。 | 先评审工具与 migration manifest。当前空 Goal selector 不是已有 Goal 的迁移 API;不得用活跃用户 Goal 做测试。 | -| 自然时间资格化与 opt-in canary | 完成真实 >=10 天合成 soak,覆盖本节规定的重启、休眠、第 1 天 retry、24 h consumer lag;随后单独申请小规模 opt-in operator canary,记录停止与回滚条件。 | C/I 与所选 provider 的全部 hold 仍有效。加速容量不替代自然时间;canary 不授权通用默认。 | +| 带 fence 的迁移与恢复(I/F 前置) | 在一次性 Goal 上证明 file→SQLite 导入、原始 receipt/replay 等价、consumer cursor/outbox 保留、crash/disk-full 恢复和反向导出/回滚;共享路由或投影变化时纳入要求的独立 legacy/file/PostgreSQL 只读演练。 | 先评审工具与 migration manifest。采用已有 reviewed archive/cutover API,空 Goal selector 本身不足以完成存量迁移;不得用活跃用户 Goal 做测试。 | +| 可恢复的 opt-in canary | 安装态备份/迁移/重启、普通命令、相关中断/并发控制及携带新写入反向迁移通过;独立授权,限于已证明负载。 | 可先于正式十天资格;记录停止/回退条件,不宣称通用默认或正式时长已通过。 | +| 正式自然时间资格 | 完成实际 >=10 天合成 soak,含规定重启、休眠、第 1 天 retry 和 24 h consumer lag;按变化边界对账既有证据。 | 加速容量不替代自然时间;正式 profile 的 hold 和冻结报告仍显式保留。 | | 新 Goal 默认决策(F) | 维护者接受合格 profile、canary 结果、运维诊断、backup/restore 流程、发布操作说明和关闭默认的路径;在独立且明确披露的发布改动中切默认。 | 仅适用于新建且符合条件的本地 Goal;已有显式 file 选择保持固定。不受支持的 runtime/filesystem 需显式选择支持方案,打开失败不能静默切 backend。 | | 已有 Goal 迁移与 file 退役 | 按已评审的 fenced workflow 逐批 opt-in 迁移,每批核对 receipt、历史、投影和回滚;删除路径前列清最后的 file-primary caller 与兼容窗口。 | 每个 Goal 需要明确迁移权限;证据满足后才退役常规 primary 角色。参考/导入/导出支持保留到其 caller 与保留责任分别结束。 | diff --git a/docs/architecture/rfcs/typescript-control-plane-migration-v0.md b/docs/architecture/rfcs/typescript-control-plane-migration-v0.md index 3dfb1df65d..31c798af48 100644 --- a/docs/architecture/rfcs/typescript-control-plane-migration-v0.md +++ b/docs/architecture/rfcs/typescript-control-plane-migration-v0.md @@ -29,20 +29,22 @@ required for the first App outcome. These are planned product consumers of T0–T4, not additional provider promotion or completed migration claims. -## Current delivery frontier (2026-09-28) - -Audit `ce3862e33`: #5054, #5140, #5144, #5156, #5173, #5175 and #5169 -are merged. Do not count event retirement, archive recovery, managed process -supervision, reviewed local cutover or native drain as new pending PRs. -#4931 remains an open SQLite optimization, not a completed D2 qualification. - -Next: qualify whole-Goal execution/consumer integration and matched local -profiles in parallel; then unify new-Goal/install/settings and supported upgrade -entrypoints, deleting each replaced writer with its last caller. Retain necessary -Host IO, original receipts and migration readers. No additional dead Python -module is certified by this audit, and no fixed remaining-PR total is promised. -[Deletion inventory, engineering windows, local evidence and remaining work](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md) -supersedes older current-count estimates; their execution evidence stays historical. +## Current delivery frontier (2026-10-02) + +At main `9b0486dc1`, #4931, #5251, #5395, #5417 and #5436 are merged. +Do not recount their storage improvements or Python retirement as pending work. +The [current validation, migration and deletion plan](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md#current-closeout-validation-migration-and-deletion-2026-10-02) +prioritizes #5413/#5466/#5283 closeout, installed reversible qualification, +bounded opt-in adoption, canonical creation/defaults and last-caller deletion. +Existing Goal migration, two-policy ownership retirement and storage-format +upgrade have separate receipts and exits. Original-receipt recovery does not +justify retaining `legacy` as a live policy. Required migration readers remain. + +A bounded cohort can start after its installed recovery and relevant execution +controls pass; it does not certify a released default or formal ten-day D2. +Frozen failures/missing evidence remain visible. T4 deletes proven redundant +owners alongside implementation, without waiting for R6 or all Python to vanish. +This replaces stale current-count estimates, not historical execution evidence. ## Native authority qualification and prototype retirement (2026-09-26) diff --git a/docs/architecture/rfcs/typescript-control-plane-migration-v0.zh-CN.md b/docs/architecture/rfcs/typescript-control-plane-migration-v0.zh-CN.md index 82a3651a2d..42db11d366 100644 --- a/docs/architecture/rfcs/typescript-control-plane-migration-v0.zh-CN.md +++ b/docs/architecture/rfcs/typescript-control-plane-migration-v0.zh-CN.md @@ -27,17 +27,18 @@ R1–R3 的 TS 消费者包括 App 产品路径,不只 CLI 结算。 这里是 T0–T4 的产品消费计划,不新增 provider promotion,也不声称迁移完成。 -## 当前交付边界(2026-09-28) - -按 `ce3862e33` 核对,#5054、#5140、#5144、#5156、#5173、#5175、#5169 -均已合并。事件退役、archive 恢复、managed 进程监督、reviewed 本地切换和 native -drain 不再计作新待办 PR。#4931 仍是开放的 SQLite 优化,不是已完成 D2 验收。 - -接下来并行验证整 Goal 执行/消费者集成和本地 profile,再统一新 Goal/安装/设置 -及受支持升级入口,切走最后调用方时同步删除对应旧 writer。保留必要 Host IO、 -原回执与迁移 reader。本轮未认证额外某个 Python 模块已死,也不承诺固定剩余 PR 数。 -[删除清单、工程窗口、本机证据及剩余工作](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md) -替代旧记录的当前数量估算,旧执行证据仍按历史保留。 +## 当前交付边界(2026-10-02) + +按 main `9b0486dc1` 核对,#4931、#5251、#5395、#5417、#5436 已合并, +不再把这些存储改进和 Python 退役重复记作待办。 +[当前验证、迁移与删除计划](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md#当前收尾验证迁移与删除2026-10-02) +优先收尾 #5413/#5466/#5283,再做安装态可回退验证、有界自愿采用、canonical +创建/默认接入及最后调用方删除。存量 Goal 迁移、两策略退役和格式升级各有独立 +回执及出口;原回执恢复不能成为保留 legacy 活跃策略的理由,必要迁移 reader 保留。 + +有界 cohort 在安装恢复和相关执行控制通过后可开始,不代表发布默认值或正式十天 +D2 已通过;冻结的失败/缺项保持可见。T4 随实现删除已证明重复的 owner,不等 R6 +或所有 Python 消失。本节替代陈旧的当前数量估算,不覆盖历史执行证据。 ## Todo 事件路径退役(2026-09-25)