Skip to content

feat(authority): bound PostgreSQL commit admission - #3933

Merged
huangruiteng merged 2 commits into
mainfrom
codex/postgresql-authority-provider-20260904
Sep 4, 2026
Merged

huangruiteng merged 2 commits into
mainfrom
codex/postgresql-authority-provider-20260904

Conversation

@huangruiteng

Copy link
Copy Markdown
Collaborator

Summary

  • reject PostgreSQL authority commits whose canonical atomic envelope exceeds a configurable limit before opening a database connection
  • fail closed on invalid capacity configuration and keep retention, partitioning, and measured capacity as explicit promotion holds
  • reorganize the shared-authority RFC into parallel PostgreSQL provider, canonical capture, integration, and promotion lanes

Delivery plan

The PostgreSQL provider plane proceeds independently from main; it does not wait for or stack on #3870. The revised or replacement capture work for #3870 must still deliver complete versioned Todo/lease records into the single coordination.runtime_shadow.commit lineage. Provider and capture work meet only at parity/binding qualification, before any promotion claim.

Validation

  • npm run typecheck:control-plane
  • npm run test:postgresql-authority-store against PostgreSQL 16: 14/14 passed
  • npm run test:control-plane with PostgreSQL 16 available: 558/558 passed, 0 skipped
  • loopx check public/private scan on all six changed files
  • git diff --check
  • loopx canary premerge --from-git-diff --goal-id loopx-meta: 13/13 selected checks passed, 0 manual holds
  • change-quality receipt after rebasing onto current main: cqr_46f0137731263293d463

Manual holds

This PR does not claim authenticated service/API authorization, restore-incarnation rotation, pool/cancellation/failover qualification, retention/partitioning/measured capacity, runtime binding, parity, or authority-source promotion.

Future-facing pass

Kept the resource admission logic provider-local: PostgreSQL meters one atomic commit, while NoKV meters its cumulative document envelope. A shared helper would imply a false cross-provider storage contract; the only reused primitive is canonical JSON encoding.

Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

动机

PostgreSQL authority provider 目前缺少单笔原子提交的容量准入边界。这个 PR 为 canonical commit envelope 增加可配置上限,在进入数据库连接与事务前拒绝超限请求,同时继续把 retention、partitioning、持续吞吐实测、认证授权与 promotion 保留为显式 hold,避免把局部门禁误写成完整生产资格。

改动思路

核心链路清晰且边界正确:PostgreSqlAuthorityStore 构造器校验 max_commit_bytes 必须是正的 safe integer;canonicalCommitEnvelopeBytes 对规范化后的 {operation_id, events, next_projection, receipts} 计算 canonical bytes;commitAuthority 先规范化并校验 expected revision,再做容量判断,只有未超限才建立连接并进入 tenant-scoped transaction。provider profile 同步加入 retention_partitioning_and_measured_capacity hold,明确本次实现只是单笔准入,不承担更高层的容量与晋升声明。

具体改动

  • 默认上限 DEFAULT_POSTGRESQL_MAX_COMMIT_BYTES 为 16 MiB,部署可下调;非法配置在构造阶段 fail closed。
  • 正向路径保持原有 authority 语义:合法且未超限的 commit 会建立连接、设置 transaction-local tenant context、校验 store identity/CAS/operation id,并在同一事务中写入 commit、events、receipts 与 head。
  • 负向路径新增 typed failure:非法 commit 仍返回 invalid_commit_request;超限 commit 返回 store_capacity_exhausted,且测试证明不会调用 connect()。
  • authority typed state、CAS revision、cursor 与 receipt 语义未被改写;默认运行路径没有新增 PostgreSQL caller,也没有发生 provider promotion。
  • 中英文 RFC 对 provider-local ceiling、尚未完成的生产 hold,以及 P/C/I/F 并行交付依赖保持一致。

对主干的风险

风险可控且与改动规模相称。主要兼容性变化是默认 PostgreSQL adapter 现在对单笔 canonical payload 施加 16 MiB 上限;该 provider 仍是 Stage 2B candidate、没有 production runtime caller,且文档明确该上限不等价于 throughput、retention 或 partitioning 资格。expected_provider_revision 未计入 envelope,符合其作为 CAS 输入而非持久化原子内容的角色。容量判断发生在规范化之后、连接之前,不会绕过 tenant authority,也不会把基础设施策略扩散成领域决策。残余验证风险是本地环境没有 LOOPX_TEST_POSTGRES_URL,因此真实 PostgreSQL integration case 未独立重跑;不过针对改动的测试、control-plane 全套测试、typecheck 与 diff check 均通过。CI 的 Python pytest 失败来自既有 split-root fence 测试,不在本 PR 六个文件的变更范围内;Sonar code analysis、DCO、dependency review、构建和 Windows PowerShell 均通过。

我的整体评价

未发现阻断问题。实现聚焦、fail-closed、typed failure 完整,正负路径都有针对性覆盖;文档没有把指导性容量 ceiling 提升成 promotion obligation 或生产能力声明,authority 边界与 domain neutrality 得以保留。我认为该 exact head 可以按审批结论通过;由于这是作者自有 PR,GitHub 不允许正式 self-approval,因此以 COMMENTED review 记录该结论。

English verdict: Approval conclusion — no blocking findings on exact head 16727b8aeace3d86dbdf30741650f8ff632c4b2b; safe to merge once repository-required checks and maintainer policy are satisfied.

@huangruiteng
huangruiteng merged commit ce51eca into main Sep 4, 2026
9 of 11 checks passed
@huangruiteng
huangruiteng deleted the codex/postgresql-authority-provider-20260904 branch September 4, 2026 15:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant