Skip to content

fix(authority): keep event lookup inside control plane - #3938

Merged
huangruiteng merged 1 commit into
mainfrom
codex/fix-3870-postmerge-smokes
Sep 4, 2026
Merged

huangruiteng merged 1 commit into
mainfrom
codex/fix-3870-postmerge-smokes

Conversation

@huangruiteng

Copy link
Copy Markdown
Collaborator

Summary

Motivation and design

The authority-shadow drain path needs to confirm whether a prepared event-log entry reached canonical storage. The implementation in #3870 obtained that read helper through loopx.status, which inverted the intended dependency direction: control-plane coordination depended on a top-level compatibility facade that itself depends on control-plane modules.

This patch calls the existing provider-neutral resolver in control_plane.goals directly. It changes no schema, state, transaction, or candidate-decision behavior.

Validation

  • examples/control_plane/todo-readmodel-boundary-smoke.py: passed
  • focused authority-shadow pytest suite: 33 passed
  • mypy: no issues in 21 configured files
  • Ruff on the changed module: passed
  • control-plane maintainability ratchet: passed, no new or stale debt
  • LoopX premerge: 12/12 selected checks passed, 0 failures, 0 warnings, 0 manual holds
  • change-quality receipt: cqr_6e35a7e0855af76151aa, exact committed diff verified
  • DCO sign-off present

Post-merge #3870 CI triage

The merge-commit Full Public Smokes run also reports three failures that reproduce on #3870's base commit: the Todo CLI module-size ratchet, the configure-goal feature-set assertion, and the concise-help line budget. They are pre-existing main failures and are intentionally excluded from this one-file regression fix.

Follow-up to #3870.

Signed-off-by: huangruiteng <huangrt01@163.com>
@huangruiteng

Copy link
Copy Markdown
Collaborator Author

No blocking finding in the changed surface.

Product and architecture judgment

  • Motivation: PR feat(authority): add transaction-bound runtime shadow capture #3870 correctly moved local authority shadow decisions into the control plane, but its event-presence lookup introduced one reverse dependency from control_plane/coordination back to the top-level loopx.status facade. The public boundary smoke detected that after merge.
  • Resolution: this follow-up imports the existing goal projection and path-resolution owners directly and supplies the resolver explicitly. It changes no transaction, candidate-decision, persistence, permission, or PostgreSQL behavior.
  • Design judgment: this is the smallest reusable repair. It restores the intended bounded-context dependency without adding a wrapper, schema, allowlist, or second source of truth. No adjacent refactor is warranted for this one-call-site cleanup.

Validation

  • Exact diff: 1 Python file, 7 additions and 2 deletions; clean worktree and git diff --check passed.
  • Regression boundary: todo-readmodel-boundary-smoke.py passed.
  • Focused authority/shadow suite: 33 passed.
  • Static checks: mypy checked 21 files with 0 issues; Ruff passed; TypeScript typecheck passed.
  • TypeScript control plane: 556 passed, with 1 expected PostgreSQL-environment skip.
  • LoopX premerge: 12/12 selected checks passed, 0 failures, 0 warnings, 0 manual holds; self-merge allowed.
  • Change-quality receipt: cqr_6e35a7e0855af76151aa, verified against exact fingerprint 6e35a7e0855af76151aa73d5ff2daa865344b258475f8d536183a5fb7c02a45d.
  • GitHub checks passed: DCO, dependency review, build, Windows, SonarCloud analysis, and its non-blocking wrapper.

Python CI exception

The complete parallel Python suite was run twice. Both runs reached over 5,600 passing tests, but failed in different pre-existing timing/race-sensitive tests outside this PR's changed module:

  1. Attempt 1: 5,635 passed, 20 skipped; one wall-clock assertion observed 0.2097s against a 0.13s threshold in the post-writeback lock timing test.
  2. Attempt 2: 5,634 passed, 20 skipped; two scheduler parity tests monkeypatched process-wide time.sleep, which interfered with subprocess.run's polling sleep and raised the test sentinel from inside Python's subprocess wait loop.

The three affected tests pass together locally in five consecutive runs (7/7 each run). Neither failure has a call path to the sole import-boundary edit, and the rerun changing failure identity is further evidence of suite-level flakiness rather than this PR's behavior. Per owner authorization, I am treating only this unrelated required check as an admin-bypass exception; the failure is not concealed or reported as green.

Merge decision: self-merge with admin bypass is justified for this narrow post-merge boundary repair.

@huangruiteng
huangruiteng merged commit e26928f into main Sep 4, 2026
9 of 11 checks passed
@huangruiteng
huangruiteng deleted the codex/fix-3870-postmerge-smokes branch September 4, 2026 19:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant