feat(authority): bound PostgreSQL commit admission - #3933
Conversation
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
动机
PostgreSQL authority provider 目前缺少单笔原子提交的容量准入边界。这个 PR 为 canonical commit envelope 增加可配置上限,在进入数据库连接与事务前拒绝超限请求,同时继续把 retention、partitioning、持续吞吐实测、认证授权与 promotion 保留为显式 hold,避免把局部门禁误写成完整生产资格。
改动思路
核心链路清晰且边界正确:PostgreSqlAuthorityStore 构造器校验 max_commit_bytes 必须是正的 safe integer;canonicalCommitEnvelopeBytes 对规范化后的 {operation_id, events, next_projection, receipts} 计算 canonical bytes;commitAuthority 先规范化并校验 expected revision,再做容量判断,只有未超限才建立连接并进入 tenant-scoped transaction。provider profile 同步加入 retention_partitioning_and_measured_capacity hold,明确本次实现只是单笔准入,不承担更高层的容量与晋升声明。
具体改动
- 默认上限
DEFAULT_POSTGRESQL_MAX_COMMIT_BYTES为 16 MiB,部署可下调;非法配置在构造阶段 fail closed。 - 正向路径保持原有 authority 语义:合法且未超限的 commit 会建立连接、设置 transaction-local tenant context、校验 store identity/CAS/operation id,并在同一事务中写入 commit、events、receipts 与 head。
- 负向路径新增 typed failure:非法 commit 仍返回
invalid_commit_request;超限 commit 返回store_capacity_exhausted,且测试证明不会调用connect()。 - authority typed state、CAS revision、cursor 与 receipt 语义未被改写;默认运行路径没有新增 PostgreSQL caller,也没有发生 provider promotion。
- 中英文 RFC 对 provider-local ceiling、尚未完成的生产 hold,以及 P/C/I/F 并行交付依赖保持一致。
对主干的风险
风险可控且与改动规模相称。主要兼容性变化是默认 PostgreSQL adapter 现在对单笔 canonical payload 施加 16 MiB 上限;该 provider 仍是 Stage 2B candidate、没有 production runtime caller,且文档明确该上限不等价于 throughput、retention 或 partitioning 资格。expected_provider_revision 未计入 envelope,符合其作为 CAS 输入而非持久化原子内容的角色。容量判断发生在规范化之后、连接之前,不会绕过 tenant authority,也不会把基础设施策略扩散成领域决策。残余验证风险是本地环境没有 LOOPX_TEST_POSTGRES_URL,因此真实 PostgreSQL integration case 未独立重跑;不过针对改动的测试、control-plane 全套测试、typecheck 与 diff check 均通过。CI 的 Python pytest 失败来自既有 split-root fence 测试,不在本 PR 六个文件的变更范围内;Sonar code analysis、DCO、dependency review、构建和 Windows PowerShell 均通过。
我的整体评价
未发现阻断问题。实现聚焦、fail-closed、typed failure 完整,正负路径都有针对性覆盖;文档没有把指导性容量 ceiling 提升成 promotion obligation 或生产能力声明,authority 边界与 domain neutrality 得以保留。我认为该 exact head 可以按审批结论通过;由于这是作者自有 PR,GitHub 不允许正式 self-approval,因此以 COMMENTED review 记录该结论。
English verdict: Approval conclusion — no blocking findings on exact head 16727b8aeace3d86dbdf30741650f8ff632c4b2b; safe to merge once repository-required checks and maintainer policy are satisfied.
Summary
Delivery plan
The PostgreSQL provider plane proceeds independently from
main; it does not wait for or stack on #3870. The revised or replacement capture work for #3870 must still deliver complete versioned Todo/lease records into the singlecoordination.runtime_shadow.commitlineage. Provider and capture work meet only at parity/binding qualification, before any promotion claim.Validation
npm run typecheck:control-planenpm run test:postgresql-authority-storeagainst PostgreSQL 16: 14/14 passednpm run test:control-planewith PostgreSQL 16 available: 558/558 passed, 0 skippedloopx checkpublic/private scan on all six changed filesgit diff --checkloopx canary premerge --from-git-diff --goal-id loopx-meta: 13/13 selected checks passed, 0 manual holdsmain:cqr_46f0137731263293d463Manual holds
This PR does not claim authenticated service/API authorization, restore-incarnation rotation, pool/cancellation/failover qualification, retention/partitioning/measured capacity, runtime binding, parity, or authority-source promotion.
Future-facing pass
Kept the resource admission logic provider-local: PostgreSQL meters one atomic commit, while NoKV meters its cumulative document envelope. A shared helper would imply a false cross-provider storage contract; the only reused primitive is canonical JSON encoding.