Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 12 additions & 0 deletions .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
Expand Up @@ -48,6 +48,18 @@
- Target base branch:
- Direction tracker or promotion unit:

## Shared-authority RFC fixture impact

<!--
Complete this section only when the PR claims progress against the TypeScript
control-plane migration or shared Goal Authority RFC. Otherwise write N/A.
-->

- Production-scale fixture schema:
- Semantic dimensions changed, or reviewed no-impact rationale:
- Provider conformance arms run:
- Read-only legacy/file/PostgreSQL three-arm rehearsal (required for promotion, runtime-routing, or compatibility-projection changes):

## Boundary Checklist

- [ ] I did not commit `.loopx/`, `.codex/goals/`, live `ACTIVE_GOAL_STATE.md`, credentials, private benchmark traces, verifier output, raw agent sessions, internal document links, or local machine paths.
Expand Down
12 changes: 10 additions & 2 deletions .github/workflows/python-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -87,7 +87,15 @@ jobs:
run: |
npm ci --ignore-scripts
npm run typecheck:control-plane
npm run test:control-plane
npm run test:control-plane:coverage

- name: Upload TypeScript control-plane coverage
uses: actions/upload-artifact@v7
with:
name: typescript-control-plane-coverage
path: coverage/control-plane/lcov.info
if-no-files-found: error
retention-days: 3

- name: Lint test suite
run: >-
Expand Down Expand Up @@ -247,7 +255,7 @@ jobs:
env:
LOOPX_SHADOW_COMPARISON_OUTPUT: .local/stage2c-observables
# Keep each module's shared workspace and ordered parity rows on one worker.
run: python -m pytest -q -n 2 --dist loadfile -m stage2c_e2e --durations=20 --junitxml=stage2c-e2e.xml
run: python -m pytest -q -n 4 --dist loadfile -m stage2c_e2e --durations=20 --junitxml=stage2c-e2e.xml
- name: Reject deliberate correctness regressions
if: matrix.suite == 'mutants'
run: python examples/shared-goal-authority-e2e/mutants.py --output .local/stage2c-mutants
Expand Down
7 changes: 7 additions & 0 deletions .github/workflows/sonarcloud.yml
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,13 @@ jobs:
with:
name: python-coverage-xml

- name: Download this run's TypeScript coverage
if: steps.sonar-token.outputs.available == 'true'
uses: actions/download-artifact@v7
with:
name: typescript-control-plane-coverage
path: coverage/control-plane

- name: SonarCloud scan
if: steps.sonar-token.outputs.available == 'true'
# Analysis-only: findings are reported to the PR/dashboard but never
Expand Down
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ dist/
.mypy_cache/
.coverage
coverage.xml
coverage/
htmlcov/
.playwright-cli/
output/playwright/
Expand Down
68 changes: 55 additions & 13 deletions docs/architecture/rfcs/shared-goal-authority-state-provider-v0.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
- Status: Draft, under maintainer review
- Initially proposed by: NoKV Lab
- Widened by: LoopX maintainers
- Date: 2026-08-05; revised 2026-09-05
- Date: 2026-08-05; revised 2026-09-07
- Scope: one provider-neutral LoopX authority contract with built-in file,
optional NoKV, and optional PostgreSQL provider profiles, complementing
[`host-integration-surface-v0`](../../reference/protocols/host-integration-surface-v0.md)
Expand Down Expand Up @@ -2344,12 +2344,12 @@ write that cannot preserve the contract.
promotion, add sustained mixed-writer parity runs, event-only Todo coverage,
and the selected provider profile's recovery/capacity evidence.
- Completion of the compatibility projection outbox and conformance rows for
file, NoKV, and PostgreSQL. The first provider-first slice now reuses the
committed authority journal as the durable intent for native Todo create,
claim, and narrow update, then renders native active/archive records into
machine-owned Markdown regions with idempotent replay. Remaining native Todo
mutations, lease-file projection, backlog/status readback, and provider-
neutral authority binding still need the same contract. Providers do not
file, NoKV, and PostgreSQL. Provider-first create, claim, narrow update,
complete, supersede, and role-scoped archive reuse the committed authority
journal as durable intent and render native active/archive records into
machine-owned Markdown regions with idempotent replay. Lease-file projection,
backlog/status readback, the provider-neutral authority binding, and the
remaining command inventory still need the same contract. Providers do not
promote together; each profile must pass it before it is eligible.
- Retention, fast path, and measured capacity for the selected first-promotion
profile; the reference executor's removal and status flips (question 13).
Expand Down Expand Up @@ -2419,14 +2419,56 @@ parity at the same revision before changing a binding or manifest. Questions 8
and 10's completeness rule applies to domain facts and retained compatibility
provenance; it does not require native callers to manufacture Markdown addresses.

### Provider-first terminal lifecycle checkpoint (2026-09-07)

Promoted `complete`, `supersede`, and role-scoped `archive` now use one native
TypeScript transaction across file, NoKV, and PostgreSQL. The authority owner
decides actor/claim/lease admission; derives successor priority, capability and
Agent bindings, exclusions, continuation, and predecessor relations from typed
caller intent; reduces completion policy; commits the Todo/lease/head/outbox
write set with CAS; and persists replay receipts. Python remains an adapter for
registry facts, the caller-approved validation effect, intent/result transport,
and compatibility projection drain; it does not select a different terminal or
successor outcome for a provider. The legacy Markdown and event writers reuse
the same pure TypeScript successor decision before materializing their records.

Validation declarations cross the canonical boundary as a required marker and
SHA-256 digest only. Raw argv stays in a 0600 host-local sidecar and recovery
must prove the digest before executing it. This keeps provider heads portable
and public-safe without turning recovery into a silent validation bypass.
Imported v0 `index` remains the archive-order compatibility fact; native records
fall back to durable completion/update time and Todo identity. Legacy lease
files whose Todo no longer exists in the current canonical collection remain
historical audit material and are excluded from live projection.

Qualification uses one read-only, production-complex snapshot for three arms:
an immutable legacy baseline clone, an isolated file store, and an isolated
real PostgreSQL tenant. The provider heads compare exactly; the legacy result
compares through the declared compatibility projection. Archive comparison
removes provider-retained archived records and their historical leases from the
legacy hot view, and ignores absolute imported indexes only after separately
proving identical per-role relative order. Domain fields, archive selection,
active leases, and non-target records are never normalized; the source snapshot
must remain unchanged. The executable rehearsal is
`examples/control_plane/authority-three-arm-rehearsal.py`. A checked-in,
deterministic, public-safe scale fixture exercises the same distribution and
pressure, including hard-lease fences, across every provider conformance suite. It cannot replace the
read-only three-arm rehearsal because all providers share the new semantic
owner and can therefore agree on the same regression.

Every pull request that claims progress against this RFC follows the
[production-scale fixture stewardship contract](../../development/testing-and-quality.md#production-scale-fixture-stewardship--生产规模-fixture-维护契约).
It declares fixture impact, exercises every affected provider arm, and keeps
the read-only three-arm rehearsal as a separate promotion gate.

### Next delivery and parallel provider work

The immediate kernel sequence is: (1) a real provider-first Todo lifecycle caller
with the replaced Python decisions removed; (2) explicit v0 import plus sustained
consumer/capture/recovery qualification; (3) reviewed promotion with fenced
export and cleanup. Each slice must prove an end-to-end transaction, not merely
another schema identifier consolidation. Native contract acceptance alone is
not permission to bypass any promotion hold.
The immediate kernel sequence is: (1) finish the remaining provider-first Todo
command inventory behind the same runtime boundary; (2) explicit v0 import plus
sustained consumer/capture/recovery qualification; (3) reviewed promotion with
fenced export and cleanup. Each slice must prove an end-to-end transaction, not
merely another schema identifier consolidation. Native contract acceptance
alone is not permission to bypass any promotion hold.

The first replacement-first `claim` slice routes both the default Markdown
writer and the promoted provider transaction through one TypeScript decision.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
- 状态:Draft,正在接受 maintainer review
- 最初提案方:NoKV Lab
- 扩展修订方:LoopX maintainer
- 日期:2026-08-05;修订于 2026-09-05
- 日期:2026-08-05;修订于 2026-09-07
- 范围:一个 provider-neutral 的 LoopX 权威合同,支持内置 file、可选 NoKV
与可选 PostgreSQL provider profile,用来补充
[`host-integration-surface-v0`](../../reference/protocols/host-integration-surface-v0.md)
Expand Down Expand Up @@ -1858,12 +1858,12 @@ integrity chain、确定性 scan 与 recovery readback。物理 profile 可以
提交到既有 `coordination.runtime_shadow` file-v0 lineage,不再创建第二套 local-shadow
candidate。晋升前仍需补持续 mixed-writer parity、event-only Todo 覆盖和所选 provider
profile 的 recovery/capacity 证据。
- 补齐兼容投影 outbox 与 file、NoKV、PostgreSQL 的 conformance row。首个
provider-first 切片已把 committed authority journal 复用为 native Todo create、
claim 和窄 update 的持久 intent,再以幂等 replay 把 native active/archive record
渲染到机器所有的 Markdown region。其余 native Todo mutation、lease-file 投影、
backlog/status 回读和 provider-neutral authority binding 仍需落实同一合同。三个
provider 不必同时晋升,但每个 profile 都必须先通过该合同才具备资格。
- 补齐兼容投影 outbox 与 file、NoKV、PostgreSQL 的 conformance row。Provider-first
create、claim、窄 update、complete、supersede 与按 role 执行的 archive 已把 committed
authority journal 复用为持久 intent,再以幂等 replay 把 native active/archive record
渲染到机器所有的 Markdown region。lease-file 投影、backlog/status 回读、
provider-neutral authority binding 与剩余 command inventory 仍需落实同一合同。
三个 provider 不必同时晋升,但每个 profile 都必须先通过该合同才具备资格。
- 首个晋升 profile 的 retention、fast path 与实测 capacity;参考执行器的删除与
status flip(问题 13)。
- 晋升后的 rollback:已交付的 rollback 隔离的是晋升前 lineage。首次权威写
Expand Down Expand Up @@ -1917,10 +1917,45 @@ render/export/rollback 与 selection parity,再改变 binding 或 manifest。
的完整性要求覆盖 domain fact 与保留的 compatibility provenance,但不要求原生
caller 伪造 Markdown 地址。

### Provider-first terminal lifecycle 检查点(2026-09-07)

Promotion 后的 `complete`、`supersede` 与按 role 执行的 `archive`,现在在 file、
NoKV、PostgreSQL 上使用同一笔 TypeScript 原生事务。authority owner 决定
actor/claim/lease admission,从 typed caller intent 推导 successor 的 priority、capability
与 Agent binding、exclusion、continuation 和 predecessor relation,reduce completion
policy,以 CAS 提交 Todo/lease/head/outbox write set,并持久化 replay receipt。Python
只保留 registry fact、caller-approved validation effect、intent/result transport 与兼容投影
drain 的 adapter 职责,不再针对不同 provider 选择另一种 terminal 或 successor outcome。
Legacy Markdown 与 event writer 在物化 record 前复用同一个纯 TypeScript successor
decision。

Validation declaration 只以 required marker 与 SHA-256 digest 跨越 canonical 边界。
raw argv 留在权限为 0600 的 host-local sidecar,恢复时必须先证明 digest 匹配才可执行。
这使 provider head 保持可移植、public-safe,同时不会让 recovery 静默绕过 validation。
导入 v0 的 `index` 继续作为归档顺序兼容事实;native record 回退到持久
completion/update 时间与 Todo identity。Todo 已不在当前 canonical collection 中的
legacy lease file 继续作为历史审计材料保留,但不进入 live projection。

资格验证使用同一份只读、生产复杂度快照做三臂对照:不可变 legacy baseline clone、
隔离 file store、隔离的真实 PostgreSQL tenant。两个 provider head 精确比较;legacy
结果按显式 compatibility projection 比较。归档时仅从 legacy hot view 排除 provider
保留的 archive 记录及其历史 lease,并且只有先证明每个 role 的相对顺序完全一致,才可
忽略导入 `index` 的绝对值;domain 字段、归档选择、active lease 与非目标记录不得归一化,
源快照必须不变。可执行演练为
`examples/control_plane/authority-three-arm-rehearsal.py`。受检入的确定性 public-safe
规模 fixture 在每个 provider conformance suite 中制造同样的分布、压力与 hard-lease
fence。它不能替代只读三臂演练,因为所有 provider 共享新的 semantic owner,可能同时
同意同一个回归。

凡声称推进本 RFC 的 PR,都必须遵守
[production-scale fixture 维护契约](../../development/testing-and-quality.md#production-scale-fixture-stewardship--生产规模-fixture-维护契约):
声明 fixture 影响、覆盖所有受影响的 provider arm,并把只读三臂演练保留为独立的
promotion gate。

### 下一步交付与并行 provider 工作

kernel 的近期顺序是:(1)真实 provider-first Todo lifecycle caller,并删除被替代
的 Python decision;(2)显式 v0 import 加持续 consumer/capture/recovery 资格化;
kernel 的近期顺序是:(1)在同一 runtime boundary 后补完剩余 provider-first Todo
command inventory;(2)显式 v0 import 加持续 consumer/capture/recovery 资格化;
(3)具备 fenced export 和 cleanup 的已评审 promotion。每个切片必须证明端到端
transaction,不能只做另一轮 schema identifier 统一。接受 native contract 不等于
可以绕过任何 promotion hold。
Expand Down
Loading
Loading