Skip to content

fix(delivery): respect canonical waits and define RFC execution stages - #4137

Merged
huangruiteng merged 5 commits into
mainfrom
codex/canonical-delivery-response
Sep 9, 2026
Merged

huangruiteng merged 5 commits into
mainfrom
codex/canonical-delivery-response

Conversation

@huangruiteng

@huangruiteng huangruiteng commented Sep 9, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Rebased onto main after fix(delivery): unify typed claim diagnostics before writeback #4136. One TS delivery_response_v0 read decision reconciles outcome-history supervision with a positively established current canonical Todo wait across quota, handoff and work-lane consumers.
  • Address review P1: parse the current resume_when; require exact target identity and supported completion classes. Monitor generation, capability and PR repository/number bind to the current Todo. Missing actors, self-dependencies, unknown classes and stale/mismatched conditions cannot grant the exemption. Python transports these facts without duplicating the decision.
  • Preserve independent runnable work, surface-only/small-delivery supervision, claim/exclusion, existing Todo/replan obligations and hard gates. No settlement, writer, provider routing or persisted history changes.
  • Keep the original four-stage roadmap visible in both RFC languages. Link the overview to T0–T4 and D1–D3 execution cards with concrete owners, deletion targets, real-path evidence and stop rules. Permanent Markdown projection remains; automatic Markdown-to-authority import does not.

Validation

  • Tested revision: 788d915b373e8e52dcbcda754bdecaf1ca2cfa87 (same runtime/test tree as the completed final runs).
  • Run state: finished (local); hosted checks tracked separately.
  • Input classes: synthetic.
Check kind Result Public-safe evidence / limitation
static passed TypeScript typecheck, diff hygiene, added-content public/private scan
integration passed Full TS suite: 884 passed, 1 optional PostgreSQL integration skipped
integration passed 126 Python regressions across response/history/claim/semantics/resume planning and maintainability
real_entrypoint passed Final 45-test Python batch: response adapters, delivery CLI, resume adapter, canonical resume planning CLI and handoff-mode CLI; overlaps the earlier batch
mutation passed Both target-identity removal and unrestricted task-class mutants killed by assertion; unchanged controls pass
real_backend not_applicable No AuthorityStore/provider transaction, schema or promotion change. Existing canonical read-path CLI fixtures use isolated synthetic File authority; no active Goal mutated. Real PostgreSQL was not run.

Tests retain valid Todo/monitor/capacity/PR waits and reject individual identity mutations. Consumer regressions prove stale proof cannot suppress the floor or hide independent runnable work. Missing/other actors, owner/exclusion, self dependencies, satisfied state, source absence, hard gates and unknown-history retention remain covered. No live model qualification or performance claim.

Scope / architecture

  • Intentional behavior change: a scoped typed blocker with a proven current wait can defer historical outcome-floor pressure. This is not retirement of the outcome floor, and does not discharge durable work.
  • Review refinement: incomplete legacy conditions remain readable but cannot prove the stronger exemption. Canonical work state, not an additional agent-maintained declaration, supplies the facts.
  • Existing resume and work-item owners suffice; no new capability, provider, ledger or framework. The bounded refactor removes duplicated positive-proof checks from the consumer and keeps the decision in TS.
  • RFC cards are implementation guidance, not automatic promotion, provider switching, soak scheduling or merge authorization. Full writer deletion remains conditional on command coverage, qualification and approved cutover; duplicate-rule deletion starts earlier.
  • Target base: main; no unrelated stacked history.

Boundary checklist

  • Public-safe synthetic fixtures and aggregate evidence only; no raw logs, private evidence, credentials or local paths.
  • DCO sign-off on every commit.
  • Owner authorized self-merge and this PR's temporary local Git-gate bypass; no permanent gate changes.

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Request changes conclusion (author-owned PR; GitHub blocks formal self-review)

Exact head: c4a489e57efdeb463aa8b6ebbfc1bf38e8dda5db

动机

这个 PR 处理的是一个真实控制面冲突:历史 outcome-gap streak 可能要求继续推进,但当前 canonical Todo 明确处于合法依赖等待。如果 quota、handoff、work lane 各自解释,两套状态会不断争夺权威。目标应当是:只有与当前 Todo、actor、typed blocker 和 pending dependency 精确绑定的等待才能暂缓历史监督;缺失/非法状态、旧 blocker 文案、其他 actor 或 exclusion 都必须继续 fail closed。

改动思路

将组合决策集中到只读 delivery_response_v0 是正确方向。Python adapter 从 canonical Todo summary 选 source row,TS projectDeliveryResponse 联合历史 signal、run/Todo binding、claim scope 和 resume condition,最后只返回 outcome_floor_applicable、follow-through 与 reason。quota、handoff 和 work lane 复用同一结果,而 canonical planner 仍负责选择其他可执行工作;没有新增 writer、settlement 或持久状态。

最强反例在“positive proof”本身:resumeConditionHasKnownPendingTarget 没有证明 resume_condition.target_todo_id 等于 resume_when 编码的 target,而且对 todo_done 只要求 task class 是任意非空且不等于 continuous_monitor 的字符串。Python bridge 还会从 compact condition 中丢掉 target_todo_id。因此 stale/mismatched condition 也能被当作 canonical wait,恰好违反 PR 的核心承诺。

具体改动

关键代码讲解

  1. delivery_history.ts:114 的 projectDeliveryResponse 正确要求 bound outcome_gap、typed blocked observation、同 actor/claim、active advancement Todo,并让不充分证明回落到 history_supervision。
  2. resume_condition.ts:406 的 resumeConditionHasKnownPendingTarget 覆盖 todo、monitor、capacity、PR 四类条件,但目标身份检查不完整:只排除 self dependency,未比较 target_todo_id 与 parsed resume_when,任意非-monitor task class 也可通过。
  3. delivery_history.py 的 project_delivery_response 复用 todo_planning_source_items,避免按展示上限选错 Todo;但 compact 字段表没有保留 target identity,放大了上述漏洞。
  4. quota.py、handoff delivery contract 和 work-lane context 都消费这一个 response,避免了三套规则;status.py 只保留 blocker binding/evidence ids,不携带 evidence body,public/private 边界合理。
  5. 四份双语 RFC 将重叠 roadmap 改成 T0–T4/D1–D3 条件式执行卡,明确 merge、promotion、soak、真实 backend 与 authority gate,不把文档计划写成机器义务;这部分与迁移方向一致。

最小修复应由现有 resume owner 解析 resume_when 并验证 exact target:Todo/monitor 条件必须保留且匹配 target_todo_id,target task class 只能取合法 typed 值;缺失、未知、mismatch 一律返回 history_supervision。增加按 target id 和 task class 分别 mutation 的负向测试。

对主干的风险

已用真实 TS handler 和 Python effect-runtime adapter 复现:run/Todo/actor 都合法,Todo 的 resume_when 指向 todo_dependency,但 condition 指向 todo_other 且带任意非-monitor class,结果仍为 canonical_todo_wait、outcome_floor_applicable=false。这会让 quota 不再进入 outcome floor,并让 handoff/work lane 的 follow-through 消失;影响的是机器义务,不是展示差异。

独立验证中,78 个 Python tests、12 个 Node tests、TypeScript typecheck 通过;现有反例覆盖 missing source、self dependency、other actor、exclusion 与 satisfied state,却没有覆盖 cross-target mismatch。远端 required checks 仍红,原因是 stacked base #4136 的 state_refresh.py module budget;本 PR 修复自身 target-proof 后,还需在已修复的 base/main 上 rebase 并完整重跑。

我的整体评价

共享 response owner、canonical state 优先于历史 hint、三消费者复用以及 RFC 路线压缩都是正确且成比例的设计,不应退回每个 caller 各写一个 exemption。当前 P1 是其核心安全边界少了一次 exact identity equality:一个“看起来 pending”的投影不能等价于已证明的依赖目标。补齐目标绑定、合法 class 和 stale-state mutation 后,这个 PR 才具备批准条件。

English verdict: REQUEST_CHANGES at exact head c4a489e — the canonical-wait exemption does not bind the projected condition to the exact resume_when target and can suppress outcome-floor supervision for stale/malformed state; 78 Python tests, 12 Node tests, and TS typecheck pass, while the stacked required CI gate remains red.

@huangruiteng
huangruiteng force-pushed the codex/delivery-followthrough-policy branch from d19df6b to f23f242 Compare September 9, 2026 09:00
Base automatically changed from codex/delivery-followthrough-policy to main September 9, 2026 09:14
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
@huangruiteng
huangruiteng force-pushed the codex/canonical-delivery-response branch from c4a489e to 788d915 Compare September 9, 2026 09:57
@huangruiteng

Copy link
Copy Markdown
Collaborator Author

Review follow-up — P1 addressed

Exact reviewed head: 788d915b373e8e52dcbcda754bdecaf1ca2cfa87.

The cross-target counterexample was valid. Positive wait proof now parses the waiting Todo's resume_when in the existing TS resume owner and checks the projected target against it. Completion targets use the supported non-monitor classes, not an arbitrary string. Monitor baseline, capacity identity and PR repository/number also bind to the current Todo. Missing actor identity is insufficient. The Python bridge retains the proof fields; no parallel Python authority was added.

One detail in the earlier review needed correction: the previous PR head already retained target_todo_id after the self-dependency follow-up. The remaining bug was the missing equality and permissive class rule, not field omission at that exact head. The current bridge also retains the other condition-family identity fields needed for exact proof.

Product / architecture assessment

No remaining blocking finding in the reviewed diff. The problem is conflicting historical pressure versus current work state, not a need for another agent-authored declaration. A single read decision used by quota, handoff and work lane is proportionate. Legacy partial conditions can still be read; only a positively established canonical wait can relax supervision. Other runnable work and durable Todo/replan/settlement authority remain intact.

Applied the capability-owned review lenses: typed target/schema checks rather than prose heuristics; domain-neutral obligations; explicit disclosure of the outcome-floor behavior correction; machine-enforced work requirements distinguished from RFC guidance; no new opt-in/default-off claim; no new actor or write authority. Reuse/observable-semantics review retains the existing resume owner and tests both valid waits and malformed/stale inputs. No provider transaction is affected.

Validation and limits

  • 126 Python regression tests passed, including maintainability and canonical resume planning.
  • Final 45-test Python adapter/real-CLI batch passed (overlaps the above), covering delivery CLI, resume adapter, canonical planning CLI and handoff mode.
  • Full TS suite: 884 passed, one optional PostgreSQL integration skipped; typecheck passed.
  • Two source mutants independently remove exact target binding and task-class restriction. Both unchanged controls pass and both mutants fail assertions.
  • Diff/public-private checks clean. Synthetic isolated fixtures only. No live Goal, registry, model run, promotion, storage transaction or settlement mutated.
  • This is the risk-based premerge equivalent for the changed read-policy/consumer surfaces, not a claim of full Python, PostgreSQL or live-model qualification. Hosted checks at the new head are still running; old stacked-base failures are not evidence about this head. Merge remains held pending assessment of the new checks.

Roadmap retained

The original four directions remain in the bilingual Shared Authority RFC's Refactoring roadmap overview / 重构主线总览. They link to TS T0–T4 and durability D1–D3; permanent Markdown rendering and the explicit import boundary are preserved. This does not authorize cutover or delete future work.

@huangruiteng

Copy link
Copy Markdown
Collaborator Author

Final self-review / merge decision

Head: 788d915b373e8e52dcbcda754bdecaf1ca2cfa87; base: main including merged #4136.

No blocking finding remains after the exact-target refinement described above. Both full hosted Python shards, pytest aggregation, checks, Windows, stage2c real E2E/mutants/installed and their correctness aggregate, both builds, dependency review, DCO and the required merge gate passed at this head. SonarCloud's explicitly non-blocking analysis is still in progress; this is not a claim that it has passed. Deployment/publication jobs are expected skips for a PR.

Additional local qualification: 98 Goal-frontier/replan/blocked-successor regressions passed; Ruff and Mypy passed; all four RFC execution-card headings and relative Markdown targets verified. This supplements the previously reported response/CLI suites, 884 TS tests and two mutation controls.

The sole optional PostgreSQL test remains a disclosed skip because no provider/storage transaction changes in this PR; no active-state promotion or live-model qualification was performed. No manual hold remains on the read-policy change. Future provider promotion/soak and full legacy-writer retirement remain gated in the RFCs and are not authorized by this merge.

Decision: proceed with owner-authorized admin self-merge of this exact head. The temporary local Git-hook bypass was scoped to this PR's commits/push; repository settings and runtime authority gates were not changed.

@huangruiteng
huangruiteng merged commit 4d1772f into main Sep 9, 2026
19 checks passed
@huangruiteng
huangruiteng deleted the codex/canonical-delivery-response branch September 9, 2026 10:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant