Skip to content

fix(governance): unify canonical work snapshots for alignment and amendments - #4143

Merged
huangruiteng merged 2 commits into
mainfrom
codex/canonical-goal-governance
Sep 10, 2026
Merged

huangruiteng merged 2 commits into
mainfrom
codex/canonical-goal-governance

Conversation

@huangruiteng

Copy link
Copy Markdown
Collaborator

Summary

Close a bounded T3 consumer slice: shared-goal alignment and amendment admission now read one complete Todo/lease snapshot and share a TypeScript-owned work selector.

  • After promotion, use canonical state, including authoritative empty state. Missing/stale Markdown and old lease files cannot become fallback authority; reads never repair the display. Before promotion, retain the legacy adapter.
  • Remove the alignment-specific Python claim/unclaimed/peer selectors and amendment's second Markdown parse. Reuse the canonical summary and existing typed lease rules, not a second inventory or writer.
  • Bind amendment source digests to the canonical provider revision, even when the separate state-event sequence does not advance.
  • Update both migration RFCs and the alignment/amendment RFC in English and Chinese, preserving the wider roadmap and its holds.

Production code: +261/-250 (net +11). The remaining diff is durable validation and documentation. Commits separate implementation/validation from RFC updates.

Issue Or Task

Maintainer-requested next cohesive step against the TypeScript control-plane and shared Goal Authority RFCs. Independent of open #4142; no dependency on its authoring-scope changes.

Intentional semantic changes

  1. Promoted alignment/admission follows canonical Todos and leases, not the display. Provider failure fails closed; canonical empty state is not treated as a missing source.
  2. Executor exclusions apply consistently to both eligible-work counts and recommendations. Peer-held or executor-excluded open Todos remain valid amendment impact context: proposing a shared-plan change is not executing that Todo.
  3. Alignment basis and amendment target inventory use the same captured snapshot. A changed canonical revision produces needs_rebase even when the event sequence remains zero or otherwise unchanged.
  4. A promoted Goal without an event log uses canonical_todo_snapshot, event sequence 0, and an unbound Agent frontier. This is not a fabricated Goal intent revision or proof of Agent acknowledgement.
  5. Selected active leases use the existing typed expiry/owner/epoch rules; malformed active expiry is rejected instead of being interpreted as inactive. Corrupt unrelated legacy lease records do not block an unselected claim.

Unchanged: provider defaults, promotion holds, permanent Markdown projection, Todo writers, claim/lease ownership, user gates, amendment approval and commit authority. Admission remains canonical_effect=none; it does not reserve the snapshot or replace commit-time revalidation/CAS. Registry, events and run history are not claimed to be one atomic Goal transaction.

Validation

  • Tested revision: ba3de4371f3368722e205598336bb86e33741fdb (rebased on 0b511e7edf059e2fd31bd09c7138a9f6502e034f).
  • Run state: finished
  • Input classes: synthetic, public_fixture
Check kind Result Public-safe evidence / limitation
static passed Control-plane TypeScript typecheck; touched Python Ruff checks; repository-configured mypy targets; diff whitespace check. Mypy is scoped to its configured targets, not a new claim of whole-repository typing.
integration passed Focused Python alignment, amendment, lifecycle, canonical authority, resume/projection recovery and maintainability regression set: 175 passed.
unit passed npm run test:control-plane: 941 passed, no failures or skips, with PostgreSQL integration enabled.
real_backend passed Isolated PostgreSQL 16.15 server: 36 integration tests included in the full TS run. Shared conformance covers File, NoKV test backend and real PostgreSQL, with legacy/native record shapes. No claim of live NoKV qualification or PostgreSQL public CLI routing.
real_entrypoint passed Actual alignment CLI and amendment entrypoint against isolated canonical FileAuthorityStore fixtures: missing/stale/empty display, unavailable provider, authoritative leases, stale proposal bases and one-read snapshot consistency.
regression_parity passed Four baseline failures reproduced before implementation. Three source mutants were killed by assertions: ignoring exclusion, admitting a changed canonical zero-event basis, and falling back to legacy after promotion.
integration passed Checked-in production-scale fixture: 464 Todos and 64 leases; full collections retained through one provider read. Real CLI reads without display; typed selection yields 13 own claims, 24 peer claims and no eligible unclaimed work for the fixture Agent.

Coverage and gaps: this risk-based set exercises the changed production readers, typed selectors, admission freshness, optional list response parity, full fixture and real backend. Initial development failures (transport expectation, lease error mapping, fixture import and mutation-runner single-test selection) were corrected before the passing runs. This does not qualify whole-Goal promotion, Stage 3 amendment commits, every T3 consumer, or the entire Python repository suite. No live Goal was promoted or mutated. Hosted CI remains independently authoritative for its checks.

Type of Change

  • Bug fix
  • Documentation update
  • Test update
  • Behavior-changing refactor; not described as full zero-behavior-change parity.

LoopX Area

  • Control plane (goals, todos, quota, scheduler, registry, runtime)

Technical Direction

  • Shared Goal Authority and cross-host coordination
  • Target base branch: main
  • Direction tracker or promotion unit: TypeScript RFC T3, bounded alignment/amendment consumer closure. No promotion requested; T1/T2 and provider qualification remain independent.

Shared-authority RFC fixture impact

  • Production-scale fixture schema: loopx_coordination_production_scale_fixture_v0, checked in at tests/fixtures/control_plane/coordination_production_scale_v0.json.
  • Semantic dimensions: ownership/exclusion eligibility, monitor versus advancement context, lifecycle filtering, canonical lease source and source revision freshness. No fixture data expansion was needed.
  • Provider conformance arms: File, NoKV test backend, isolated real PostgreSQL; legacy/native Todo records in each arm.
  • Read-only legacy/file/PostgreSQL rehearsal: legacy and promoted File public entrypoints plus PostgreSQL shared-reader/typed-selector conformance are covered. Not a full public PostgreSQL CLI or promotion-routing rehearsal; this PR changes neither routing selection nor compatibility projection writes.

Boundary Checklist

  • No private state, credentials, raw traces, internal links, connection strings or local machine paths in the diff or this PR.
  • No duplicate benchmark delivery or new benchmark job.
  • Scope is the shared-goal governance reader boundary, not full provider migration.
  • Every commit includes DCO sign-off.

Future-facing pass applied: retire duplicate selectors and reuse one source snapshot and typed lease owner. Other quota frontier consumers and eventual commit-time authority are explicitly outside this slice; no speculative commit framework was added.

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

审阅绑定 exact head:ba3de4371f3368722e205598336bb86e33741fdb。

动机

这个 PR 解决的是一个真实的控制面语义风险:alignment 与 amendment 原先各自重建 Todo/lease 事实,即使局部测试都通过,也可能在 canonical promotion、provider revision 变化或并发读取时得到不同的决策基础。只修其中一个调用方不足以消除双重规则所有权;把一次操作需要的工作事实收束到同一个完整快照,是更小也更稳的边界。

改动思路

Python 的 read_shared_goal_work_source 只负责选择并读取权威来源:promotion 前读取 legacy Markdown/lease,promotion 后读取同一 provider revision 下的 canonical Todo 与 lease,而且 canonical empty 仍然是权威状态,不回退也不修复 display。Typed TypeScript 的 sharedGoalWorkFacts 统一负责 open advancement、excluded agent、peer claim、resume state 与 active lease 的选择规则;alignment 和 amendment 保留各自的下游语义。

具体改动

关键代码讲解

  • shared_goal_work_source.py 把 legacy/canonical 读取封装成一个只读快照,canonical basis 同时携带 source_authority、provider_revision 与 records digest。
  • shared_goal_work.ts 从同一快照派生当前 Agent claim、eligible unclaimed、peer-bound Todo 与 amendment inventory;重复 Todo、非法状态和被选中 claim 的坏 lease 会在 typed boundary 失败。
  • shared_goal_alignment.py/.ts 与 goal_amendment_proposal.py/.ts 都消费这一个源;provider revision 的变化会进入 source basis,避免 event sequence 未变化时错误复用旧 amendment base。
  • 我检查了 base 0b511e7edf059e2fd31bd09c7138a9f6502e034f 到 exact head 的完整 21-file diff、现有 canonical/lease reader 与未改调用方,没有发现第二个写入权威或未使用的 speculative seam。

验证结果:聚焦 Python 生产入口回归为 97 passed;shared_goal_work、alignment、amendment 的 TypeScript 测试为 74 passed;Ruff、git diff --check、DCO 与 public/private 扫描通过。远端 CI 也全部成功或为预期 skip。

对主干的风险

代码判断可批准,但 GitHub 当前把该 exact head 标记为 CONFLICTING/DIRTY。合并前必须基于最新 main 解决冲突,并在新 head 上重跑聚焦测试与检查;本结论不自动继承到冲突解决后的 head。其余残余风险主要是 promotion 后 fail-closed 会把 provider 故障直接暴露给调用方,这是 PR 已披露且有回归覆盖的有意语义。

我的整体评价

这是同一 change reason 下的合理收束:删除 alignment/amendment 的重复选择知识,让 Python 保持 source/effect adapter,typed state rule 归回 TypeScript owner;没有借机扩张到 claim、approval 或 commit authority。future-facing pass 已应用在最相关的边界上,其他 T3 consumer 与 commit-time CAS 延后是合适的。

English verdict: APPROVE — exact head ba3de4371f3368722e205598336bb86e33741fdb is approved on code and semantics; rebase the current conflict and rerun validation before merge.

…shots

Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
@huangruiteng
huangruiteng force-pushed the codex/canonical-goal-governance branch from ba3de43 to ed4f794 Compare September 10, 2026 08:03
@huangruiteng

Copy link
Copy Markdown
Collaborator Author

Rebase and final qualification for ed4f794764600510f38e538a2f9d1556c4557327:

  • Rebased onto current main. Conflicts were additive mutant registration and bilingual RFC context; both contributions and the future roadmap were retained. Range-diff confirms no product-logic change from the rebase.
  • Changed surfaces: canonical Todo/lease snapshot reads for shared-goal alignment and governed amendments, typed work selection, and revision-bound proposal admission. Authoritative empty state remains empty; provider failure does not fall back to stale Markdown; reading does not repair display or grant write authority.
  • Validation: 956 TypeScript tests passed with zero skips, including File/NoKV and an isolated real PostgreSQL 16.15 server; 110 focused Python tests passed, including real CLI/canonical governance and representative complex data; TypeScript typecheck, Ruff and diff checks passed.
  • Hosted DCO, dependency review, checks, minimum-Node compatibility, release build and installed stage2c passed. Other hosted jobs are still running. The advisory forward-Node lane reproduces the known baseline EISDIR diagnostic-string mismatch; this is not claimed green and is unrelated to the changed selector/admission logic.
  • Architecture/future-facing assessment: one canonical snapshot and one typed work selector replace duplicated Python decisions. Provider defaults, promotion hold, lease authority and final commit CAS remain unchanged. No broader migration scaffolding is needed in this batch. Public/private boundary reviewed; no live goal state was mutated for testing.

No remaining findings in this bounded rebase. Proceeding with owner-authorized admin self-merge based on the above risk-based production-path qualification; temporary Git-gate bypass is command-scoped only.

@huangruiteng
huangruiteng merged commit 8bd22d7 into main Sep 10, 2026
14 of 16 checks passed
@huangruiteng
huangruiteng deleted the codex/canonical-goal-governance branch September 10, 2026 08:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant