|
| 1 | +# Default cutover: reconciled implementation frontier |
| 2 | + |
| 3 | +- Baseline: `d64c4d377` on `main`, 2026-09-24; open PR states are a snapshot, not merge promises. |
| 4 | +- Owners: overall roadmap #4574 R5/G2; shared authority L2–L9/D1–D3; TS migration T1–T4. |
| 5 | +- Delivery: complete source transport through existing typed projection and shadow management owners. |
| 6 | +- This checkpoint supersedes numerical remaining-PR estimates in earlier delivery entries. |
| 7 | + |
| 8 | +## Correct the accounting |
| 9 | + |
| 10 | +The previous “5–8”, “6–8” and “7–9” numbers counted broad work packages as |
| 11 | +remaining PRs, then retained the estimate after parts landed and additional |
| 12 | +prerequisites appeared. They are not an audited PR backlog and are withdrawn. |
| 13 | +A code gap, an open PR, integration acceptance, an elapsed-time qualification |
| 14 | +and a maintainer cutover decision are different units. Do not add or decrement |
| 15 | +them as though they were interchangeable PRs. |
| 16 | + |
| 17 | +| Evidence at this baseline | Current disposition | |
| 18 | +| --- | --- | |
| 19 | +| #4870 claim-preserving writes; #4888 reviewed cutover; #4920 drain planning | Implemented. Exercise their combined head; do not commission replacements. | |
| 20 | +| #4922 complete canonical snapshot pagination; #4960 qualified SQLite runtime admission; #4961 display refresh recovery; #4964 shared source summaries | Implemented. Consumer and packaged-client acceptance still needs integration evidence; a whole new pagination/recovery implementation is not pending. | |
| 21 | +| #4967 typed complete-source assembly; #4968 native outbox delivery/recovery | Implemented. Large source RPC failure below is a separate demonstrated gap, not absence of capture assembly. | |
| 22 | +| #5003 atomic event-owned completion | Open. Solves batch publication/retry, **not** the event writer's shadow-capture binding. | |
| 23 | +| #4994 explicit leased Agent handoff; #4995 generated Monitor proof; #4991 rejected poll reservation; #4992 deferred receipt-bound Turn | Open. Integrate their exact reviewed heads before deciding what caller work remains; do not recreate them under a new caller-refactor PR. | |
| 24 | +| #4931 retained SQLite proof encoding, contributor #4224 | Open optimization plus incomplete D2 qualification. A speedup is not capacity/recovery/soak acceptance. | |
| 25 | +| #4915 default `.loopx` filesystem placement | Separate configuration migration; does not select File/SQLite authority. | |
| 26 | + |
| 27 | +There are six relevant open implementation PRs above (#5003, #4994, #4995, |
| 28 | +#4991, #4992, #4931), plus the separately classified #4915 to avoid conflating |
| 29 | +filesystem placement with authority. These are not six unstarted requirements, |
| 30 | +nor a claim that every one is a mandatory storage-default dependency. |
| 31 | + |
| 32 | +## Four concrete next delivery boundaries |
| 33 | + |
| 34 | +These are **four proposed new batches including this delivery**, in addition to |
| 35 | +integrating existing work. They are not a guaranteed total remaining PR count. |
| 36 | +The command inventory and exact-profile acceptance can reveal further defects; |
| 37 | +record a new demonstrated gap rather than silently keeping a range unchanged. |
| 38 | + |
| 39 | +| Batch | Observable result and owning boundary | Exit and remaining dependency | |
| 40 | +| --- | --- | --- | |
| 41 | +| A. Complete source pipeline (this delivery) | A source larger than the RPC envelope can pass typed projection, bootstrap, writer capture, inspect, qualify and reviewed promotion without truncation. Python transports bytes; TS retains source admission and authority. | Large real CLI journey; File/SQLite complete reads; source-witness rejection; detached real-source rehearsal. Does not bind the event writer or qualify a provider default. | |
| 42 | +| B. External-effect executor fence | Current execution proof protects the actual external-effect interval, including takeover, timeout, exit and uncertain completion, using the existing lease/effect owners. | Stale executors cannot execute or settle fenced work; exact receipt recovery. #4994/#4995 caller integration is reused; a point-in-time proof check alone is insufficient. | |
| 43 | +| C. Event-writer binding and whole-Goal migration/rollback | Bind the actual event writer lock/publication lifecycle to the existing outbox lineage, then exercise mixed Markdown/event/lease writers, drain, reviewed cutover, canonical consumers and fenced export/rollback as one journey. Retire replaced Python decisions at their TS owner. | Integrate #5003 rather than reimplement atomic completion. Preserve `event_log_writer_not_bound` until the real binding passes. D1 consumers, command inventory and D3 cohort evidence must close; if this requires separate code, name the discovered boundary explicitly. | |
| 44 | +| D. Default/onboarding and final bounded Python retirement | Qualified local profile is selected consistently by new Goal creation, settings, installation and packaged frontend/Lark/CLI; existing Goals follow explicit migration/disable guidance. Delete only business writers whose callers have switched. | B/C and applicable D1–D3 evidence, rollback and entrypoint readback. Keep permanent Python rendering, host IO and legal import/export. | |
| 45 | + |
| 46 | +D2 capacity, crash/restore/upgrade/runtime coverage and **at least ten days of |
| 47 | +natural elapsed soak** are evidence gates on an exact SQLite profile, not an |
| 48 | +assumed one- or two-PR allocation. #4224 retains ownership. D3 integration and |
| 49 | +owner-approved cohort cutover are also not automatically new PRs. No fixed |
| 50 | +completion date or exact total PR count is defensible while these are open. |
| 51 | +A File-only bounded cutover, a qualified SQLite default and migration of every |
| 52 | +existing Goal have distinct acceptance scopes; none proves the other two. |
| 53 | + |
| 54 | +PostgreSQL reuses the typed commands and AuthorityStore, while deployed |
| 55 | +transport, authentication/tenant policy, restore identity, operations and |
| 56 | +capacity qualification remain its separate medium-term path. Local default |
| 57 | +does not wait for PostgreSQL deployment; a passing conformance suite does not |
| 58 | +establish production service readiness. |
| 59 | + |
| 60 | +## Complete-source transport and budget decision |
| 61 | + |
| 62 | +At this baseline `test_canonical_snapshot_integration` fails before provider |
| 63 | +admission: complete source projection exceeds the 2 MiB request limit. Paging |
| 64 | +canonical reads already exists, but source capture and management still send |
| 65 | +whole projections. Trimming source records would invalidate digests and parity; |
| 66 | +increasing the generic RPC budget would enlarge every method's exposure. |
| 67 | + |
| 68 | +The existing coordination contract generates both schema names and the byte cap |
| 69 | +for Python and TS. Python file exchange stays in its existing source projection |
| 70 | +adapter; there is no independently maintained same-name Python/TS module pair. |
| 71 | +Only source-bearing handlers accept a private host-local transfer envelope. |
| 72 | +Python writes a temporary request; TS verifies its method, byte length, SHA-256, |
| 73 | +regular-file identity and private directory, then invokes the same handler. |
| 74 | +TS writes an exclusively created result and returns a small bound receipt; |
| 75 | +Python verifies the response bytes and cleans up temporary files on both success |
| 76 | +and failure. Inline callers remain compatible. These artifacts are transient |
| 77 | +transport, not another authority store or durable business receipt. |
| 78 | + |
| 79 | +The RPC limit remains 2 MiB. **The new artifact limit is 16 MiB per request or |
| 80 | +result**, a separate explicit bound, not unlimited streaming or an assertion |
| 81 | +that all goals fit. Oversize input rejects before execution. Result delivery can |
| 82 | +fail after a mutation; callers must recover using the existing operation identity, |
| 83 | +never infer that an RPC error means no commit. No automatic mutation retry is |
| 84 | +added. Memory still includes complete parsed objects; this does not solve |
| 85 | +arbitrarily large provider history or capacity qualification. |
| 86 | + |
| 87 | +The cap accommodates the multi-megabyte complete-source fixture and source |
| 88 | +management's repeated representation while keeping allocation bounded. In 32 |
| 89 | +interleaved warm calls of the same small source on the same host, inline versus |
| 90 | +artifact median was 9.15/11.62 ms and p95 11.60/15.93 ms. This measured local IO |
| 91 | +cost is accepted for complete-source calls; it is not a global latency claim. |
| 92 | +Future size changes require a measured workload and the existing budget review. |
| 93 | + |
| 94 | +Validation uses real File/SQLite and a disposable PostgreSQL 16 server. The |
| 95 | +large CLI regression qualifies and promotes only a synthetic isolated Goal. |
| 96 | +A live source rehearsal that detected concurrent changes was discarded; the |
| 97 | +accepted real-source rehearsal verifies a detached copy against its capture |
| 98 | +witness and exercises all mutations there. Private sources, identifiers and |
| 99 | +raw output are excluded from public artifacts. No active Goal is promoted. |
| 100 | + |
| 101 | +No frontend settings or API shape changes are needed: the same CLI and Python |
| 102 | +management adapters invoke the same domain handlers and return the same results. |
| 103 | +The public change is that supported complete-source operations no longer fail |
| 104 | +solely because their source crosses the RPC envelope. Defaults, authorization, |
| 105 | +source freshness, event-writer holds and provider promotion criteria are unchanged. |
| 106 | + |
| 107 | +A related runtime repair handles socket errors when a caller closes an oversized |
| 108 | +response before draining it. One disconnected caller no longer crashes the |
| 109 | +shared runtime; the regression asserts that subsequent paged reads retain the |
| 110 | +same process identity. It neither cancels nor retries the business operation. |
0 commit comments