fix(delivery): respect canonical waits and define RFC execution stages - #4137
Conversation
huangruiteng
left a comment
There was a problem hiding this comment.
Request changes conclusion (author-owned PR; GitHub blocks formal self-review)
Exact head: c4a489e57efdeb463aa8b6ebbfc1bf38e8dda5db
动机
这个 PR 处理的是一个真实控制面冲突:历史 outcome-gap streak 可能要求继续推进,但当前 canonical Todo 明确处于合法依赖等待。如果 quota、handoff、work lane 各自解释,两套状态会不断争夺权威。目标应当是:只有与当前 Todo、actor、typed blocker 和 pending dependency 精确绑定的等待才能暂缓历史监督;缺失/非法状态、旧 blocker 文案、其他 actor 或 exclusion 都必须继续 fail closed。
改动思路
将组合决策集中到只读 delivery_response_v0 是正确方向。Python adapter 从 canonical Todo summary 选 source row,TS projectDeliveryResponse 联合历史 signal、run/Todo binding、claim scope 和 resume condition,最后只返回 outcome_floor_applicable、follow-through 与 reason。quota、handoff 和 work lane 复用同一结果,而 canonical planner 仍负责选择其他可执行工作;没有新增 writer、settlement 或持久状态。
最强反例在“positive proof”本身:resumeConditionHasKnownPendingTarget 没有证明 resume_condition.target_todo_id 等于 resume_when 编码的 target,而且对 todo_done 只要求 task class 是任意非空且不等于 continuous_monitor 的字符串。Python bridge 还会从 compact condition 中丢掉 target_todo_id。因此 stale/mismatched condition 也能被当作 canonical wait,恰好违反 PR 的核心承诺。
具体改动
关键代码讲解
delivery_history.ts:114的projectDeliveryResponse正确要求 bound outcome_gap、typed blocked observation、同 actor/claim、active advancement Todo,并让不充分证明回落到history_supervision。resume_condition.ts:406的resumeConditionHasKnownPendingTarget覆盖 todo、monitor、capacity、PR 四类条件,但目标身份检查不完整:只排除 self dependency,未比较target_todo_id与 parsedresume_when,任意非-monitor task class 也可通过。delivery_history.py的project_delivery_response复用todo_planning_source_items,避免按展示上限选错 Todo;但 compact 字段表没有保留 target identity,放大了上述漏洞。quota.py、handoff delivery contract 和 work-lane context 都消费这一个 response,避免了三套规则;status.py只保留 blocker binding/evidence ids,不携带 evidence body,public/private 边界合理。- 四份双语 RFC 将重叠 roadmap 改成 T0–T4/D1–D3 条件式执行卡,明确 merge、promotion、soak、真实 backend 与 authority gate,不把文档计划写成机器义务;这部分与迁移方向一致。
最小修复应由现有 resume owner 解析 resume_when 并验证 exact target:Todo/monitor 条件必须保留且匹配 target_todo_id,target task class 只能取合法 typed 值;缺失、未知、mismatch 一律返回 history_supervision。增加按 target id 和 task class 分别 mutation 的负向测试。
对主干的风险
已用真实 TS handler 和 Python effect-runtime adapter 复现:run/Todo/actor 都合法,Todo 的 resume_when 指向 todo_dependency,但 condition 指向 todo_other 且带任意非-monitor class,结果仍为 canonical_todo_wait、outcome_floor_applicable=false。这会让 quota 不再进入 outcome floor,并让 handoff/work lane 的 follow-through 消失;影响的是机器义务,不是展示差异。
独立验证中,78 个 Python tests、12 个 Node tests、TypeScript typecheck 通过;现有反例覆盖 missing source、self dependency、other actor、exclusion 与 satisfied state,却没有覆盖 cross-target mismatch。远端 required checks 仍红,原因是 stacked base #4136 的 state_refresh.py module budget;本 PR 修复自身 target-proof 后,还需在已修复的 base/main 上 rebase 并完整重跑。
我的整体评价
共享 response owner、canonical state 优先于历史 hint、三消费者复用以及 RFC 路线压缩都是正确且成比例的设计,不应退回每个 caller 各写一个 exemption。当前 P1 是其核心安全边界少了一次 exact identity equality:一个“看起来 pending”的投影不能等价于已证明的依赖目标。补齐目标绑定、合法 class 和 stale-state mutation 后,这个 PR 才具备批准条件。
English verdict: REQUEST_CHANGES at exact head c4a489e — the canonical-wait exemption does not bind the projected condition to the exact resume_when target and can suppress outcome-floor supervision for stale/malformed state; 78 Python tests, 12 Node tests, and TS typecheck pass, while the stacked required CI gate remains red.
d19df6b to
f23f242
Compare
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
c4a489e to
788d915
Compare
Review follow-up — P1 addressedExact reviewed head: The cross-target counterexample was valid. Positive wait proof now parses the waiting Todo's One detail in the earlier review needed correction: the previous PR head already retained Product / architecture assessmentNo remaining blocking finding in the reviewed diff. The problem is conflicting historical pressure versus current work state, not a need for another agent-authored declaration. A single read decision used by quota, handoff and work lane is proportionate. Legacy partial conditions can still be read; only a positively established canonical wait can relax supervision. Other runnable work and durable Todo/replan/settlement authority remain intact. Applied the capability-owned review lenses: typed target/schema checks rather than prose heuristics; domain-neutral obligations; explicit disclosure of the outcome-floor behavior correction; machine-enforced work requirements distinguished from RFC guidance; no new opt-in/default-off claim; no new actor or write authority. Reuse/observable-semantics review retains the existing resume owner and tests both valid waits and malformed/stale inputs. No provider transaction is affected. Validation and limits
Roadmap retainedThe original four directions remain in the bilingual Shared Authority RFC's Refactoring roadmap overview / 重构主线总览. They link to TS T0–T4 and durability D1–D3; permanent Markdown rendering and the explicit import boundary are preserved. This does not authorize cutover or delete future work. |
Final self-review / merge decisionHead: No blocking finding remains after the exact-target refinement described above. Both full hosted Python shards, pytest aggregation, checks, Windows, stage2c real E2E/mutants/installed and their correctness aggregate, both builds, dependency review, DCO and the required merge gate passed at this head. SonarCloud's explicitly non-blocking analysis is still in progress; this is not a claim that it has passed. Deployment/publication jobs are expected skips for a PR. Additional local qualification: 98 Goal-frontier/replan/blocked-successor regressions passed; Ruff and Mypy passed; all four RFC execution-card headings and relative Markdown targets verified. This supplements the previously reported response/CLI suites, 884 TS tests and two mutation controls. The sole optional PostgreSQL test remains a disclosed skip because no provider/storage transaction changes in this PR; no active-state promotion or live-model qualification was performed. No manual hold remains on the read-policy change. Future provider promotion/soak and full legacy-writer retirement remain gated in the RFCs and are not authorized by this merge. Decision: proceed with owner-authorized admin self-merge of this exact head. The temporary local Git-hook bypass was scoped to this PR's commits/push; repository settings and runtime authority gates were not changed. |
Summary
delivery_response_v0read decision reconciles outcome-history supervision with a positively established current canonical Todo wait across quota, handoff and work-lane consumers.resume_when; require exact target identity and supported completion classes. Monitor generation, capability and PR repository/number bind to the current Todo. Missing actors, self-dependencies, unknown classes and stale/mismatched conditions cannot grant the exemption. Python transports these facts without duplicating the decision.Validation
788d915b373e8e52dcbcda754bdecaf1ca2cfa87(same runtime/test tree as the completed final runs).Tests retain valid Todo/monitor/capacity/PR waits and reject individual identity mutations. Consumer regressions prove stale proof cannot suppress the floor or hide independent runnable work. Missing/other actors, owner/exclusion, self dependencies, satisfied state, source absence, hard gates and unknown-history retention remain covered. No live model qualification or performance claim.
Scope / architecture
main; no unrelated stacked history.Boundary checklist