fix(review): require executable migration parity evidence - #4034
Conversation
Signed-off-by: huangruiteng <huangrt01@163.com>
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
动机
APPROVE,精确 head 93cf3f7dd6e726064ef2ff53c462f50e066e86f1。未发现阻断项。#4017 已要求比较 caller 可观测语义;本 PR 补足“比较执行过”的可重放记录,避免把文字表格、相同 reason code 或新规则下的 provider conformance 当作兼容证明。这是审查与迁移资格要求的加强,不是自动发现所有语义回归的实现。
改动思路
继续使用既有 pull-request-review capability 的唯一 contract owner。loopx/pr_review.py 的 packet builder 通过 build_agent_response_contract() 投影要求;build_review_plan() 按 changed area 决定适用性,没有新增按 PR 标题猜测 refactor 的规则。离线 baseline/head/mutation 证据不参与生产 authority,也不要求保留 Python 双跑。
正向:行为变更 PR 的 review plan 要求 observable_semantics,评审者记录同一 fixture 的基线/精确 head 执行、完整诊断与持久化读回,再通过敏感性运行证明 oracle 能识别缺陷。负向:缺 backend、基线或执行证据保持 not_yet_proven;该结论继续阻止批准。机器投影的是评审义务,不是已经执行验证的收据。
具体改动
六文件 +142/-1:生产 contract +30/-1,测试 +23,四个文档 +89;无新状态、CLI、provider 或生成代码。
build_review_execution_contract()的 observable_semantics 新增execution_receipts、normalization_rules,列明 revision、command、entrypoint、backend、fixture/observation 指纹、exit status 与证据指针。完整诊断、字段存在性和效果不能被归一化掉。- 同一 contract 增加 sensitivity 字段:独立 invariant、历史缺陷/刻意 mutation、预期及实际失败、passing-head receipt。它扩展现有证据组,而非引入第二套 verdict owner。
build_review_plan()和build_agent_response_contract()的既有调用关系保持不变;我比较了 runtime、docs、空对象及 areas=null 输入,baseline/head 的 plan 完全一致。- contract pytest 固定字段与语义要求;中英文 canonical RFC、testing guide 与 capability README 同步说明真实 backend、同一 harness、独立 oracle 及 promotion hold。双语要求一致,没有把机器强制义务称作可选建议。
对主干的风险
审查包变大、评审者需要更多可复查证据,这是公开披露的有意要求变化;没有 opt-in/default-off 声称,不涉及运行时权限或 actor 命名变化。最大残余风险仍是 Agent 没有执行要求:这些测试只证明 contract 被正确投影,不能证明任意 PR 已完成 parity。
独立验证:47 个 contract/queue tests 通过;Ruff、mypy、docs-governance 和 diff check 通过。对不可变 parent 0fb497af83dcb697f1617657869f05fd48668d2e 与本 head 执行相同 capability 公开导出函数,使用同一合成 fixture,输出指纹与独立 oracle 结果;基线缺少新 receipt 要求而失败,head 通过,刻意删除 exit_status 的结果再次被 oracle 拒绝。除明确扩展的 observable_semantics 组外,完整 response contract 与全部上述 plan 保持相同。该边界是纯投影函数,没有数据库 backend;本验证未声称运行了历史 Todo/租约业务迁移或测试了 PostgreSQL。GitHub 检查已通过,发布类任务按条件跳过。
我的整体评价
范围与问题相称:加强现有 contract 和 canonical docs,比新增一个未接入的通用 parity 框架更直接。Future-facing pass 已应用在同一 owner 中,不需要额外 companion abstraction。批准的是这项证据契约增强,不是对未来重构的预先批准,也不是合并授权。
English verdict: APPROVE at 93cf3f7dd6e726064ef2ff53c462f50e066e86f1. No blocking finding. The existing capability contract now requests replayable baseline/head and sensitivity receipts without adding runtime authority. Independently verified 47 tests, Ruff, mypy, docs governance, exact-revision projection parity, and a rejected dropped-exit-status mutation. This validates contract projection, not execution of arbitrary future migrations.
Summary
observable_semanticsreview evidence with replayable baseline/head execution receipts and mutation-sensitivity fieldsThis is a bounded follow-up to #4017. It closes the remaining gap where a refactor could describe parity without recording the exact public entrypoint, affected backend, fixture/observation fingerprints, exit status, and a sensitivity run that actually fails the historical defect or a deliberate semantic mutation.
The expected invariant remains independent of the TypeScript candidate, and the evidence is offline qualification only: this change adds no runtime state, provider, dual-run path, or second authority.
Validation
python -m pytest -q tests/capabilities/test_pr_review_contract.py tests/capabilities/test_pr_review_queue.py— 47 passedpython -m ruff check loopx/capabilities/pr_review_queue/review_contract.py tests/capabilities/test_pr_review_contract.py— passedpython -m mypy loopx/capabilities/pr_review_queue/review_contract.py— passedpython examples/docs-governance-smoke.py— passedloopx checkpublic/private scan — cleanloopx canary premerge --from-git-diff --goal-id loopx-meta— 18/18 selected checks passed, no manual holdscqr_de21a71470e38f5bc5b7— valid for fingerprintde21a71470e38f5bc5b70dacd2b61e19108757859a80333ffbc5466ad6129572Review boundary
Future-facing pass applied: the change strengthens the existing review contract and canonical RFC rather than adding a parallel harness or abstraction. No runtime behavior, authority, or provider implementation changes. This PR should receive independent review because it tightens public review and migration policy.