fix(governance): unify canonical work snapshots for alignment and amendments - #4143
Conversation
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
审阅绑定 exact head:ba3de4371f3368722e205598336bb86e33741fdb。
动机
这个 PR 解决的是一个真实的控制面语义风险:alignment 与 amendment 原先各自重建 Todo/lease 事实,即使局部测试都通过,也可能在 canonical promotion、provider revision 变化或并发读取时得到不同的决策基础。只修其中一个调用方不足以消除双重规则所有权;把一次操作需要的工作事实收束到同一个完整快照,是更小也更稳的边界。
改动思路
Python 的 read_shared_goal_work_source 只负责选择并读取权威来源:promotion 前读取 legacy Markdown/lease,promotion 后读取同一 provider revision 下的 canonical Todo 与 lease,而且 canonical empty 仍然是权威状态,不回退也不修复 display。Typed TypeScript 的 sharedGoalWorkFacts 统一负责 open advancement、excluded agent、peer claim、resume state 与 active lease 的选择规则;alignment 和 amendment 保留各自的下游语义。
具体改动
关键代码讲解
shared_goal_work_source.py把 legacy/canonical 读取封装成一个只读快照,canonical basis 同时携带source_authority、provider_revision与 records digest。shared_goal_work.ts从同一快照派生当前 Agent claim、eligible unclaimed、peer-bound Todo 与 amendment inventory;重复 Todo、非法状态和被选中 claim 的坏 lease 会在 typed boundary 失败。shared_goal_alignment.py/.ts与goal_amendment_proposal.py/.ts都消费这一个源;provider revision 的变化会进入 source basis,避免 event sequence 未变化时错误复用旧 amendment base。- 我检查了 base
0b511e7edf059e2fd31bd09c7138a9f6502e034f到 exact head 的完整 21-file diff、现有 canonical/lease reader 与未改调用方,没有发现第二个写入权威或未使用的 speculative seam。
验证结果:聚焦 Python 生产入口回归为 97 passed;shared_goal_work、alignment、amendment 的 TypeScript 测试为 74 passed;Ruff、git diff --check、DCO 与 public/private 扫描通过。远端 CI 也全部成功或为预期 skip。
对主干的风险
代码判断可批准,但 GitHub 当前把该 exact head 标记为 CONFLICTING/DIRTY。合并前必须基于最新 main 解决冲突,并在新 head 上重跑聚焦测试与检查;本结论不自动继承到冲突解决后的 head。其余残余风险主要是 promotion 后 fail-closed 会把 provider 故障直接暴露给调用方,这是 PR 已披露且有回归覆盖的有意语义。
我的整体评价
这是同一 change reason 下的合理收束:删除 alignment/amendment 的重复选择知识,让 Python 保持 source/effect adapter,typed state rule 归回 TypeScript owner;没有借机扩张到 claim、approval 或 commit authority。future-facing pass 已应用在最相关的边界上,其他 T3 consumer 与 commit-time CAS 延后是合适的。
English verdict: APPROVE — exact head ba3de4371f3368722e205598336bb86e33741fdb is approved on code and semantics; rebase the current conflict and rerun validation before merge.
…shots Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
ba3de43 to
ed4f794
Compare
|
Rebase and final qualification for
No remaining findings in this bounded rebase. Proceeding with owner-authorized admin self-merge based on the above risk-based production-path qualification; temporary Git-gate bypass is command-scoped only. |
Summary
Close a bounded T3 consumer slice: shared-goal alignment and amendment admission now read one complete Todo/lease snapshot and share a TypeScript-owned work selector.
Production code: +261/-250 (net +11). The remaining diff is durable validation and documentation. Commits separate implementation/validation from RFC updates.
Issue Or Task
Maintainer-requested next cohesive step against the TypeScript control-plane and shared Goal Authority RFCs. Independent of open #4142; no dependency on its authoring-scope changes.
Intentional semantic changes
needs_rebaseeven when the event sequence remains zero or otherwise unchanged.canonical_todo_snapshot, event sequence 0, and an unbound Agent frontier. This is not a fabricated Goal intent revision or proof of Agent acknowledgement.Unchanged: provider defaults, promotion holds, permanent Markdown projection, Todo writers, claim/lease ownership, user gates, amendment approval and commit authority. Admission remains
canonical_effect=none; it does not reserve the snapshot or replace commit-time revalidation/CAS. Registry, events and run history are not claimed to be one atomic Goal transaction.Validation
ba3de4371f3368722e205598336bb86e33741fdb(rebased on0b511e7edf059e2fd31bd09c7138a9f6502e034f).npm run test:control-plane: 941 passed, no failures or skips, with PostgreSQL integration enabled.Coverage and gaps: this risk-based set exercises the changed production readers, typed selectors, admission freshness, optional list response parity, full fixture and real backend. Initial development failures (transport expectation, lease error mapping, fixture import and mutation-runner single-test selection) were corrected before the passing runs. This does not qualify whole-Goal promotion, Stage 3 amendment commits, every T3 consumer, or the entire Python repository suite. No live Goal was promoted or mutated. Hosted CI remains independently authoritative for its checks.
Type of Change
LoopX Area
Technical Direction
mainShared-authority RFC fixture impact
loopx_coordination_production_scale_fixture_v0, checked in attests/fixtures/control_plane/coordination_production_scale_v0.json.Boundary Checklist
Future-facing pass applied: retire duplicate selectors and reuse one source snapshot and typed lease owner. Other quota frontier consumers and eventual commit-time authority are explicitly outside this slice; no speculative commit framework was added.