Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -195,3 +195,48 @@ live NoKV 测试。确定性 fake 的通过结果与这项静态 API 核对必
因绑定具体部署形态保留在本地忽略状态,不入公共树。回执增长、并发包络
等数字是单节点 dev 栈的量化观测,按第 5 节规则不构成生产结论;其含义
已写入 RFC 第 11 节 Stage 2 状态小节。

## 8. Stage ladder E2E 复跑记录(2026-09-03)

按第 5 节的复跑要求逐项记录本轮 stage ladder 证据:

1. **精确 commit**:LoopX 侧为 `test/shared-authority-e2e-ladder` 分支(基于
PR #3818 第三轮修订头,含单一 effective runtime root 修复;ladder 报告的 `bindings.loopx_commit` 与
`bindings.loopx_tree_dirty` 记录实际运行的树)。NoKV 侧本轮在本机单节点栈上
执行(`nokv` 83971e62ab,Python SDK 0.11.0,`nokv serve` 以静态 etcd 路由 +
RustFS 对象存储运行;报告只记录 `bindings.nokv_client_config_sha256` 与 SDK
版本,不记录任何连接值);PostgreSQL 侧无可达栈,对应行按设计报告 `unverified`。
2. **探针源码**:`loopx/control_plane/testing/authority_e2e_ladder.py`、
`loopx/control_plane/testing/authority_e2e_fixtures.py` 与只读 TypeScript
探针 `tests/control_plane_ts/authority_store_readback_probe.ts`(随分支评审;
报告 `bindings.probe_sha256[]` 记录其 digest)。入口为
`examples/shared-goal-authority-e2e/ladder.py`,pytest 投影为
`tests/control_plane/test_shared_goal_authority_e2e.py`。各行驱动的是真实
`python -m loopx.cli` 与生产 `FileAuthorityStore`,不是参考实现。
3. **断言**:本轮 9 个 deterministic 行全部 pass,2 个 NoKV live 行在本机栈上
pass:`s0.nokv_live_matrix` 十三个 NoKV 场景行全为 true 且与 file provider 的
十二个共享行逐行一致;`s2a.nokv_live_qualification` 对既有 workbench 以新铸
tenant/goal 运行已合并的 live 资格探针,13 项 check 全部 `passed`,final
generation `3`,SDK `0.11.0` / API `1`,且报告声明未改变 authority source、未
证明可用性。deterministic 行:`s0.file_matrix_twelve_rows`
十二个 file provider 场景行全为 true;`s1.cli_document_decodes_through_ts_store`
三次 CLI 写入经 TypeScript store 回读 cursor `3`、operation id 按序一致、首条
receipt found;七个 `s2c1.*` 行(configure 往返、12 个 writer family 全部
captured 且候选 cursor `12`、default-off 隔离、候选失败保主写、SIGKILL 崩溃
间隙只丢失一次 observation、`--runtime-root` 与 `common_runtime_root` 不同时
五次写入落入单一 store identity 且候选 cursor `5`、`migrate-state` 新 lineage
cursor `1`)。
4. **负例**:幂等 re-acquire 不携带 `authority_shadow`;default-off goal 无
`authority-shadow/` 目录且响应字段与 observed goal 一致;候选目录被占用时
`outcome=failed` / `reason_code=shadow_observation_failed` 但主写已提交;
迁移后的候选序列化中不含旧 store identity、legacy revision、源路径与私有
字节;报告隐私扫描把注入的临时路径改写为 `fail/privacy_violation`,仅泄露到
bindings 块时 `summary.privacy_violations=1` 且退出码为 1,且 live 变量清空时
ladder 退出码为 1(均由 pytest 钉住)。
5. **未执行与限定**:`s2b.postgresql_conformance_live`(`postgres_url_missing`)
本轮 unverified;在没有 NoKV 与 PostgreSQL 栈的 CI 环境里三个 live 行都报告
`unverified`。9 个 `s2c2.*` 行以 pending 声明,未宣称;选中任一 pending 行而不传
`--allow-pending` 时 ladder 以非零退出,零执行的报告不可能显示为 green。默认
全量运行退出码为 1,`--allow-unverified --allow-pending` 才为 0。Stage 2C
parity、outbox、drain 与增长门槛均未验证;本记录不构成任何 provider 晋升
或生产结论。
Original file line number Diff line number Diff line change
Expand Up @@ -1563,6 +1563,79 @@ flip, rollback, and retention decisions below - not a diagnostic CLI that
creates a second writer. This status section claims proven contracts, not a
shipped production capability.

#### Stage-ladder end-to-end evidence (2026-09-03)

What exists on this branch is one incremental end-to-end "stage ladder" that
exercises every completed stage claim of this RFC through the real
`python -m loopx.cli` and reports a machine-checkable verdict per row:
`loopx/control_plane/testing/authority_e2e_ladder.py` (row registry, runners,
the `loopx_shared_goal_authority_e2e_report_v0` JSON report, exit policy, and
privacy scan), `loopx/control_plane/testing/authority_e2e_fixtures.py` (goal
workspaces, CLI runners, the observation-lock window, candidate read-back), the
read-only TypeScript probe
`tests/control_plane_ts/authority_store_readback_probe.ts`, the pytest
projection `tests/control_plane/test_shared_goal_authority_e2e.py`, and the
entry point `examples/shared-goal-authority-e2e/ladder.py`.

Per stage, this increment implements:

- Stage 0: `s0.file_matrix_twelve_rows` runs the retained live matrix script
and requires exactly the twelve shared scenario rows to be true on the file
provider; `s0.nokv_live_matrix` requires the same rows plus
`restored_lineage_fails_closed` and identical file/NoKV outcomes on a live
NoKV stack.
- Stage 1: `s1.cli_document_decodes_through_ts_store` writes three
observations through the product CLI (`todo add`, `task-lease acquire`,
`todo update`) and reads them back through `FileAuthorityStore` with
`loadAuthority`, paged `scanCommitted`, and `readReceipt`: cursor `3`, the
three operation ids in order, and the first receipt found.
- Stage 2A: `s2a.nokv_live_qualification` runs the merged live qualification
probe (`examples/nokv-authority-store/live-qualification.ts --execute-live`)
against an existing workbench with a fresh tenant/goal pair and requires
`ok=true`, the single-node store-conformance scope, every check passed, NoKV
SDK `0.11.0` / API `1`, and no promotion or availability claim.
- Stage 2B: `s2b.postgresql_conformance_live` runs the PostgreSQL integration
test file under node's TAP reporter and requires at least nine passes, zero
failures, and zero skips.
- Stage 2C observation foundation: seven `s2c1.*` rows port the local-shadow CLI
E2E and migration assertions and pin the single-lineage guarantee. The configure round trip previews, enables,
reads back, and disables the observer; every writer family (handoff-mode,
todo add/update/complete/supersede/capture-followups/archive-completed,
task-lease acquire/renew/transfer) captures with
`primary_writeback_preserved`, `provider_to_local_writes=false`, and
`candidate_read_for_decision=false`, while an idempotent re-acquire does not
observe; default-off goals stay isolated; candidate failure preserves the
primary commit; a POSIX SIGKILL in the crash gap loses only that
observation; a `--runtime-root` override that differs from
`common_runtime_root` keeps todo add, task-lease acquire, todo update,
follow-up capture, and a leased completion in one store identity while the
registry root gains neither a candidate lineage nor lease state; and
`migrate-state` seeds a fresh lineage without legacy bytes.

Live rows are environment-gated (`LOOPX_TEST_POSTGRES_URL`;
`NOKV_COORDINATION_LIVE=1` plus the `NOKV_*` stack variables;
`LOOPX_NOKV_AUTHORITY_LIVE=1` plus the `LOOPX_NOKV_AUTHORITY_*` inputs).
Without a stack they report `unverified`, and the ladder exits non-zero unless
`--allow-unverified` is passed; an unverified row is never counted as green.
A pending row is an unmet obligation as well: selecting one exits non-zero
unless `--allow-pending` is passed, so a report cannot read as green while it
executed nothing.
The report binds the LoopX commit, tree dirtiness, probe digests, and hashed
connection facts, and its privacy scan turns any leak of a temporary root,
home directory, connection URL, or configuration path into
`fail/privacy_violation`; a leak confined to the bindings block is redacted
and still fails the run through `summary.privacy_violations`, which no flag
relaxes.

Delivery boundary: test-only. No production entry point constructs any store;
the ladder adds no product path and reads the candidate only through the
retained TypeScript store. The Stage 2C parity half
(`s2c2.*`: outbox entries, idempotent drain, SIGKILL before and during drain,
rollback with pending entries, parity equal and divergent,
migration seed-and-drain, growth measurement) are declared as pending rows,
not claimed. This subsection records executable evidence for the stages above;
it does not promote any provider or complete the Stage 2C promotion.

### P0: contract and deterministic proof

- this ownership matrix and explicit shared-mode boundary;
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1250,6 +1250,66 @@ visible governance 台账中属 coverage-only。该接受允许内聚的 referen
retention 决策,不能用一个会制造第二 writer 的诊断 CLI 代替。本状态节声明的是已
证明的合同,不是已 ship 的生产能力。

#### Stage ladder 端到端证据(2026-09-03)

本分支上存在一条增量式端到端 "stage ladder":它通过真实的
`python -m loopx.cli` 逐行演练本 RFC 每个已完成阶段的声明,并按行给出可机器
判定的结论:`loopx/control_plane/testing/authority_e2e_ladder.py`(行注册表、
runner、`loopx_shared_goal_authority_e2e_report_v0` JSON 报告、退出策略与隐私
扫描)、`loopx/control_plane/testing/authority_e2e_fixtures.py`(goal 工作区、
CLI runner、observation-lock 窗口、候选回读)、只读 TypeScript 探针
`tests/control_plane_ts/authority_store_readback_probe.ts`、pytest 投影
`tests/control_plane/test_shared_goal_authority_e2e.py`,以及入口
`examples/shared-goal-authority-e2e/ladder.py`。

按阶段,本增量实现:

- Stage 0:`s0.file_matrix_twelve_rows` 运行保留的 live matrix 脚本,要求 file
provider 上恰好十二个共享场景行全为 true;`s0.nokv_live_matrix` 要求 live
NoKV 栈上同样的行加 `restored_lineage_fails_closed` 全为 true,且 file/NoKV
逐行结果一致。
- Stage 1:`s1.cli_document_decodes_through_ts_store` 通过产品 CLI 写入三次
observation(`todo add`、`task-lease acquire`、`todo update`),再经
`FileAuthorityStore` 的 `loadAuthority`、分页 `scanCommitted` 与
`readReceipt` 回读:cursor 为 `3`、三个 operation id 按序一致、首条 receipt
可找到。
- Stage 2A:`s2a.nokv_live_qualification` 对一个已存在的 workbench 以新铸的
tenant/goal 运行已合并的 live 资格探针
(`examples/nokv-authority-store/live-qualification.ts --execute-live`),要求
`ok=true`、单节点 store conformance 范围、每项 check 通过、NoKV SDK `0.11.0`
/ API `1`,且不宣称晋升或可用性。
- Stage 2B:`s2b.postgresql_conformance_live` 在 node TAP reporter 下运行
PostgreSQL 集成测试文件,要求至少九个 pass、零 fail、零 skip。
- Stage 2C 观察基础:七个 `s2c1.*` 行移植本地 shadow CLI E2E 与迁移断言,并钉住单一
lineage 保证。
configure 往返先预览、再开启、回读、最后关闭 observer;每个 writer family
(handoff-mode、todo add/update/complete/supersede/capture-followups/
archive-completed、task-lease acquire/renew/transfer)都以
`primary_writeback_preserved`、`provider_to_local_writes=false`、
`candidate_read_for_decision=false` 完成 capture,而幂等 re-acquire 不产生
observation;default-off goal 保持隔离;候选失败不推翻主写;POSIX SIGKILL
落在崩溃间隙时只丢失该次 observation;`--runtime-root` 与 `common_runtime_root`
不同时,todo add、task-lease acquire、todo update、follow-up 捕获与带 lease 的
complete 仍落入同一个 store identity,registry root 既不产生候选 lineage 也不
产生 lease 状态;`migrate-state` 在不携带 legacy 字节的前提下建立新 lineage。

Live 行按环境门控(`LOOPX_TEST_POSTGRES_URL`;`NOKV_COORDINATION_LIVE=1` 加
`NOKV_*` 栈变量;`LOOPX_NOKV_AUTHORITY_LIVE=1` 加 `LOOPX_NOKV_AUTHORITY_*` 输入)。
没有栈时它们报告 `unverified`,除非传入 `--allow-unverified`,否则 ladder 以非零
退出;unverified 行永不计为 green。pending 行同样是未兑现的义务:选中它而不传
`--allow-pending` 就非零退出,所以一份零执行的报告不可能显示为 green。
报告绑定 LoopX commit、工作树是否 dirty、探针 digest 与经哈希的连接事实;其隐私
扫描会把任何临时根目录、home 目录、连接 URL 或配置路径的泄露改写为
`fail/privacy_violation`;仅出现在 bindings 块的泄露会被抹除并同样判定为失败,
`summary.privacy_violations` 阻止 green 退出,任何开关都不能放宽。

交付边界:test-only。没有任何生产入口构造任何 store;ladder 不新增产品路径,
只经保留的 TypeScript store 读取候选。Stage 2C parity 后半段
(`s2c2.*`:outbox 条目、幂等 drain、drain 前与 drain 中的 SIGKILL、带 pending
条目的 rollback、parity 相等与分歧、迁移 seed-and-drain、增长
度量)以 pending 行声明,而非宣称已完成。本小节记录的是上述阶段的可执行证据;
它不晋升任何 provider,也不完成 Stage 2C promotion。

### P0:合同与 deterministic proof

- 本 ownership matrix 与显式 shared-mode boundary;
Expand Down
Loading
Loading