Skip to content

[Task][RFC]: Complete Goal lifetime fencing and governed orphan recovery #5206

Description

@huangruiteng

Outcome / 目标

完成 Goal 生命周期隔离与孤儿状态恢复。One task tracks this RFC's delivery; keep implementation PRs and milestone evidence here instead of creating a parallel task tree.

Canonical design: RFC. Roadmap: S2/S3/S9 · R5, under #4574. Design acceptance is distinct from implementation, live qualification and promotion.

Current boundary

Source audit: main at ce3862e33 (2026-09-28). This is source/PR inspection, not a new test or live-qualification claim.

The RFC header is behind implementation: #4917’s codec is no longer the only foundation. Main contains typed GoalRef matching and source-session lifetime/recreation transactions; #4940 is closed. #5130 and #5106 are open for attached-session and collaboration propagation.

Work remaining

  • Finish the current binding-owner inventory and remaining admission/commit fences using the source registry’s exact GoalRef.
  • Complete preview/backup/journal/apply/resume/readback for supported orphan dispositions with explicit activation and compatibility boundaries.

Ownership and ongoing work

Reuse #4800/#4915 for paths and #3245 for authority promotion. Do not reimplement delivered source-session transactions or take over the active migration writers. Record remaining binding families, not an obsolete codec-only status.

Contribution route: implementation/integration overlaps active work. Start from the linked current owners/PRs and identify an unowned acceptance gap in a claim comment; do not begin a competing rewrite.

Acceptance

  • Delete/recreate of one alias cannot accept old session, inbox, host or execution authority; late A results cannot settle B.
  • Concurrent retirement, stale global projections, crash recovery and ambiguous commit preserve exact original identity and receipts.
  • Recovery never guesses a candidate or mutates active state as a test; isolated real-provider evidence and CLI/product readback cover the advertised path.
  • Reconcile the RFC's current delivery checkpoint and this issue with the integrated revision, commands, passed/failed/untested evidence and remaining gates. Close the accepted scope only; no claim that a merged PR alone completes the RFC.

Starting points and delivery boundary

Base: latest main. Reuse the existing typed owner and provider boundaries. Include affected CLI/frontend/Lark companions; verify real entrypoints and backend where changed. Preserve existing first-screen review and maintainer merge gates. Public artifacts contain only synthetic/public-safe evidence, no private operational state. This task does not authorize provider promotion, benchmark launches, release/deployment or unrelated protected effects.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions