Skip to content

Commit 69cfd35

Browse files
committed
Merge commit '35ced6710' into codex/retire-python-lease-facades
Signed-off-by: huangruiteng <huangrt01@163.com>
2 parents 82b153e + 35ced67 commit 69cfd35

25 files changed

Lines changed: 654 additions & 40 deletions

‎docs/architecture/rfcs/long-running-agent-reliability-diagnostics-governed-delivery-v0.md‎

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -532,8 +532,15 @@ envelope and stats records, integrity receipt, read-only diagnostic
532532
projection, a deterministic DSH-shaped fixture, and producer-side
533533
public-safety rejection before the first ledger append. Still open before P0
534534
exit: an eligible C1 observer run on a real `dsh` session, the reported
535-
overhead measurement, and the ledger retention and deletion profile from
536-
decision 4 below.
535+
overhead measurement, and deployment-owner acceptance of the ledger retention
536+
and deletion profile from decision 4 below. The
537+
[local retention reference (v0)](../../../loopx/capabilities/reliability_diagnostics/docs/local-retention-v0.md)
538+
and its synthetic CLI lifecycle smoke supply a canonical-layout offline
539+
export/delete/restore rehearsal, including literal shell boundary checks,
540+
installed-package readback and preservation of negative evidence. They do not
541+
implement automated retention or prove real-observer
542+
shutdown, filename/tenant isolation, C0/C1 or a deployment's deletion policy.
543+
Implementation and milestone evidence remain in [task #5211](https://github.com/loopx-project/loopx/issues/5211).
537544

538545
### P1 — Benchmark-qualified diagnostic pilot
539546

‎docs/architecture/rfcs/long-running-agent-reliability-diagnostics-governed-delivery-v0.zh-CN.md‎

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -453,7 +453,14 @@ overhead;不存在 production authority。
453453
`packages/dsh-loopx-plugin`)落地:provider-neutral envelope 与 stats record、integrity receipt、
454454
read-only diagnostic projection、deterministic DSH-shaped fixture,以及首次写入 ledger 之前的
455455
producer 侧 public-safety 拒绝。P0 exit 之前仍未完成:在真实 `dsh` session 上的 eligible C1
456-
observer run、overhead 测量报告,以及下文 decision 4 的 ledger retention 与 deletion profile。
456+
observer run、overhead 测量报告,以及部署 owner 对下文 decision 4 的 ledger retention 与
457+
deletion profile 的接受决定。
458+
[本地 retention 参考方案(v0)](../../../loopx/capabilities/reliability_diagnostics/docs/local-retention-v0.md#中文)
459+
及其合成 CLI lifecycle smoke 提供 canonical 布局的离线导出/删除/恢复演练,包含实际 shell
460+
边界检查、安装包读回与负面证据保留;
461+
它们没有实现自动 retention,也未证明真实 observer 停写、文件名/租户隔离、C0/C1 或部署的
462+
删除 policy。实现 PR 和 milestone 证据继续归入
463+
[task #5211](https://github.com/loopx-project/loopx/issues/5211)。
457464

458465
### P1 — Benchmark-qualified diagnostic pilot
459466

‎docs/architecture/rfcs/shared-goal-authority-state-provider-v0.md‎

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,8 @@
2929
Audit `ce3862e33`: #5054, #5140, #5144, #5156, #5173, #5175 and #5169
3030
are merged. Do not count event retirement, archive recovery, managed process
3131
supervision, reviewed local cutover or native drain as new pending PRs.
32-
#4931 remains an open SQLite optimization, not a completed D2 qualification.
32+
The SQLite read-proof optimization [#4931](https://github.com/loopx-project/loopx/pull/4931)
33+
has since merged at `9482a9496`; D2 qualification remains incomplete.
3334

3435
Next: qualify whole-Goal execution/consumer integration and matched local
3536
profiles in parallel; then unify new-Goal/install/settings and supported upgrade
@@ -3263,7 +3264,8 @@ new implementation work; changing languages or moving a helper is not an exit.
32633264
**Earlier 2026-09-24 implementation context.** Display refresh advances
32643265
projection recovery/client closure without claiming every consumer qualified. SQLite #4910 added the larger measurement axes; #4224 records
32653266
failed 1 MiB receipt/scan budgets and still-missing recovery/soak evidence.
3266-
#4931 is the in-review read-proof optimization, not proof that D2 passed.
3267+
At that checkpoint #4931 was still in review. Its subsequent merge supplies
3268+
read-proof optimization, not proof that D2 passed.
32673269
Snapshot pagination #4922 has merged and still must be qualified at its accepted
32683270
head. None of these PR statuses grants cutover or changes the selected profile.
32693271

‎docs/architecture/rfcs/shared-goal-authority-state-provider-v0.zh-CN.md‎

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,8 @@
2525

2626
按 `ce3862e33` 核对,#5054、#5140、#5144、#5156、#5173、#5175、#5169
2727
均已合并。事件退役、archive 恢复、managed 进程监督、reviewed 本地切换和 native
28-
drain 不再计作新待办 PR。#4931 仍是开放的 SQLite 优化,不是已完成 D2 验收。
28+
drain 不再计作新待办 PR。此后 SQLite 读取证明优化
29+
[#4931](https://github.com/loopx-project/loopx/pull/4931) 已在 `9482a9496` 合并;D2 资格化仍未完成。
2930

3031
接下来并行验证整 Goal 执行/消费者集成和本地 profile,再统一新 Goal/安装/设置
3132
及受支持升级入口,切走最后调用方时同步删除对应旧 writer。保留必要 Host IO、
@@ -2512,8 +2513,8 @@ SQLite 证明与 provider-neutral 归档恢复共用持有私有状态的 TS 重
25122513

25132514
**2026-09-24 基线核对。** 保留 claim 的 #4870、reviewed cutover #4888、shadow drain
25142515
规划 #4920 已合并,快照分页 #4922、SQLite runtime 准入 #4960 与刷新显示恢复 #4961 也已
2515-
合并,后续应验收组合 head,而不是继续沿用旧的 PR hold;SQLite 读取证明优化 #4931 仍在
2516-
评审。#4224 实测 1 MiB receipt/scan 超预算,恢复和自然时间资格仍有缺项,不能将优化 PR
2516+
合并,后续应验收组合 head,而不是继续沿用旧的 PR hold;SQLite 读取证明优化 #4931 当时仍在
2517+
评审,此后已合并。#4224 实测 1 MiB receipt/scan 超预算,恢复和自然时间资格仍有缺项,不能将优化 PR
25172518
当成 D2 通过。摘要规则收口推进投影恢复边界,但没有把其他调用方或默认切换标记完成;
25182519
剩余工作按当前核对表归类,不再按 helper 迁移数量机械扣减。
25192520

‎docs/development/contributor-tasks.md‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -101,11 +101,11 @@ issue.
101101

102102
| ID | Anchor | Gap and exit | Validation | Status |
103103
| --- | --- | --- | --- | --- |
104-
| GH-A01 | S12 · [#4941](https://github.com/loopx-project/loopx/issues/4941) | Windows users on a `cp936`-style locale hit structured state files read or written with the locale codec; #4338, #4942 and #4997 fixed the reported sites and main now has no bare `read_text()` / `write_text()` under `loopx/`. The gap is that nothing stops the class from returning. Exit: a repository guard test fails on any text-mode file I/O under `loopx/` without an explicit encoding, the reporter confirms on a `cp936` host, and #4941 closes. | New guard test next to `tests/capabilities/test_connector_registry_encoding.py` and `tests/test_runtime_subprocess_utf8.py`; `python3 -m pytest -q` on both | Available |
104+
| GH-A01 | S12 · [#4941](https://github.com/loopx-project/loopx/issues/4941) | Product fixes and the package-wide UTF-8 text-I/O guard are merged, including [#5160](https://github.com/loopx-project/loopx/pull/5160). The remaining gap is native reporter verification and issue closeout. Exit: confirm the repaired read/write paths on a `cp936` host and close #4941; reuse the landed guard instead of implementing another one. | `uv run --extra test python -m pytest -q tests/test_loopx_text_io_utf8.py tests/capabilities/test_connector_registry_encoding.py tests/test_runtime_subprocess_utf8.py`; reporter's native-host readback | Blocked: reporter verification and issue closeout |
105105
| GH-A02 | S4/S10 · [#3927](https://github.com/loopx-project/loopx/issues/3927) | A Codex App automation that silently stops delivering scheduled prompts is indistinguishable from a healthy quiet goal; the owner learns days later. Exit: `loopx doctor` or the heartbeat readback reports a missed-delivery window as a typed diagnosis with the last observed tick. | `python3 -m pytest -q tests/test_doctor_installation_scope.py` plus a missed-window fixture; `loopx doctor --deep` readback | Needs design |
106-
| GH-A03 | S3 · [#4336](https://github.com/loopx-project/loopx/issues/4336) | A 0.4.3 install saw `installed` in a progress summary matched as `stalled` and got `autonomous_replan_required` on a healthy goal. Typed progress observations replaced that prose matcher after #3161, but no public regression pins the contract, so a compatibility path could bring it back silently. Exit: a `quota should-run` regression with `installed` / `uninstalled` / `installation completed` summaries emits no no-progress trigger, a typed no-progress observation still does, and the issue records the upgrade guidance. | New focused pytest plus `python3 examples/control_plane/autonomous-replan-no-change-smoke.py` if present; `loopx check --scan-path loopx/control_plane/quota` | Available |
106+
| GH-A03 | S3 · [#4336](https://github.com/loopx-project/loopx/issues/4336) | Issue #4336 was closed, while [#4397](https://github.com/loopx-project/loopx/pull/4397) remains open with requested changes and [#5162](https://github.com/loopx-project/loopx/pull/5162) closed without merge. Typed progress already owns the runtime rule. Exit: reconcile the closed issue with the current PR review before claiming another regression is required; retain one canonical negative case and upgrade guidance only if that review confirms the gap. | Current `quota should-run` typed/prose regression and the existing PR's focused tests; exact-head review readback | Blocked: closed issue and PR review reconciliation |
107107
| GH-A04 | S5 · [#4381](https://github.com/loopx-project/loopx/issues/4381) | Users have to open the dashboard to learn why a task is blocked and what unblocks it; the projection already knows. Exit: the existing blocker projection is delivered through the goal channel / status readback with the recovery action, without a second notifier. | `python3 examples/issue-fix-outcome-projection-smoke.py`, focused status readback smoke | Needs design |
108-
| GH-A05 | S12 · [#4800](https://github.com/loopx-project/loopx/issues/4800) | Default local state lives under `.codex`, which confuses non-Codex hosts and upgrades. Exit: an agreed default path and an explicit, reversible migration command; no silent move. | Design note first; then `python3 examples/loopx-update-smoke.py` and an install smoke on a clean profile | Needs design |
108+
| GH-A05 | S12 · [#4800](https://github.com/loopx-project/loopx/issues/4800) | The explicit `.loopx` migration PR [#4915](https://github.com/loopx-project/loopx/pull/4915) remains open with green CI, requested changes on its exact head, and a conflict with main. Exit: repair the reviewed real-CLI explicit-route regression and merge conflict, revalidate the default/legacy/conflict, migration and rollback contract, then obtain maintainer review and complete issue closeout; ordinary reads must not move existing state. | The existing PR's migration/SSH/registry tests, native Windows junction checks and clean-profile install/update smokes | Claimed |
109109

110110
Closed defects that show the lane's shape: #4155 and #4997 (Windows), #4012
111111
(macOS 26.5 app), #3796 / #3867 / #4195 (DSH plugin install), #4051
@@ -134,7 +134,7 @@ the section; "extend the fixture" is not an obligation.
134134
| ID | Anchor | Gap and exit | Validation | Status |
135135
| --- | --- | --- | --- | --- |
136136
| GH-C89b | [goal-direction-baseline-v0](../architecture/rfcs/goal-direction-baseline-v0.md) · §7 synthetic case F2 | The RFC landed in #4172 at milestone M0 (design note plus fixture plan F1–F8, no code). Nothing yet proves the M0 claim that a revision change exposes `re_evaluation_required` while inputs, Vision, Todos, leases and Goal route stay byte-identical. Exit: synthetic case F2 is implemented as a public-safe fixture with the RFC's key allowlist, and the RFC's milestone table advances past M0 or records why not. | New focused smoke or pytest implementing F2; public-boundary scan; `loopx check --scan-path docs/architecture/rfcs` | Available |
137-
| GH-R5A | R5 / [shared-goal-authority-state-provider-v0](../architecture/rfcs/shared-goal-authority-state-provider-v0.md) · D2 durability / [#4224](https://github.com/loopx-project/loopx/issues/4224) [#3245](https://github.com/loopx-project/loopx/issues/3245) | The SQLite local authority candidate has capacity profiles but no crash/replay boundary qualified against the D2 acceptance in the RFC. Exit: one crash-during-commit and one replay-after-partial-write case pass on the real backend with the RFC's stated outcome, or the RFC records why D2 changes. | `npm run test:control-plane`; the isolated SQLite integration suite | Available |
137+
| GH-R5A | R5 / [shared-goal-authority-state-provider-v0](../architecture/rfcs/shared-goal-authority-state-provider-v0.md) · D2 durability / [#4224](https://github.com/loopx-project/loopx/issues/4224) [#3245](https://github.com/loopx-project/loopx/issues/3245) | Existing contributor-owned capacity and process-recovery work includes merged #4328 and read-proof optimization [#4931](https://github.com/loopx-project/loopx/pull/4931). D2 still lacks complete reference-profile reruns, large-history recovery/consumer-lag, restore/upgrade/runtime coverage and elapsed-soak evidence. Exit: reconcile the RFC §7.2 passed/failed/missing ledger against the merged source while retaining the original failed budgets and separate promotion holds. | Declared reference-runtime capacity profiles and real SQLite process/recovery suites; independently recorded platform and >=10-day elapsed-soak evidence | Claimed |
138138
| GH-C102 | [shared-goal-authority-state-provider-v0](../architecture/rfcs/shared-goal-authority-state-provider-v0.md) · one named invariant | Extend the shared production-scale coordination fixture only for an accepted RFC invariant or a reproduced public regression that the current envelope does not cover, naming the invariant section in the PR. Update the checked-in envelope, shared generator and an independent negative or mutation assertion; run the same dimension through every affected provider arm. Do not add a dimension because the fixture accepts one. Exit: the named invariant has a passing positive case and a failing mutation case on every affected arm. | `npm run test:control-plane`; for PostgreSQL, `LOOPX_TEST_POSTGRES_URL="$DISPOSABLE_POSTGRES_URL" npm run test:postgresql-authority-store`; `loopx check --scan-path tests/fixtures/control_plane --scan-path tests/control_plane_ts` | Available (named invariant required) |
139139
| GH-B01 | S11 / [long-horizon benchmark research program](../architecture/rfcs/long-horizon-harness-benchmark-research-program-v0.md) · treatment integrity / [#3243](https://github.com/loopx-project/loopx/issues/3243) | Adapter-fidelity and treatment-integrity gaps are asserted but not reproducible from public fixtures. Exit: one reproducible gap with the existing focused fixtures, reported without live scoring. | Deterministic fixtures in `tests/capabilities/test_benchmark_toolkit.py`; no live runs | Needs design |
140140

0 commit comments

Comments
 (0)