fix(todos): support lease-fenced canonical text and note updates - #4152
Conversation
Signed-off-by: Lihua <1017343802@qq.com>
Signed-off-by: Lihua <1017343802@qq.com>
…rent Signed-off-by: huangruiteng <huangrt01@163.com> # Conflicts: # docs/architecture/rfcs/typescript-control-plane-migration-v0.md # docs/architecture/rfcs/typescript-control-plane-migration-v0.zh-CN.md
Signed-off-by: huangruiteng <huangrt01@163.com>
huangruiteng
left a comment
There was a problem hiding this comment.
审阅 head:bf9a2f9867e20921f9795c88c87f63f395c644e6。发现的 main 集成问题已修复并直接推回原作者 fork;没有剩余已验证的代码阻塞,合并等待当前 CI。
动机
之前 native todo update 遇到任何 lease 都拒绝,即使调用者正持有合法执行凭证,也不能修正文案或备注。这个 PR 填补的是现有 text/note 更新路径的实用缺口,不是引入新的 lease 生命周期或完整 metadata writer。
改动思路
沿现有 CLI → Python compatibility adapter → TS canonical update → provider CAS/receipt 链路传递凭证,复用 evaluateCoordinationTerminalFence 判断身份、有效期与版本。只消费它的准入结果,不执行 terminal 的 lease effect,因此编辑不会获取、续期、释放或转移 lease。
具体改动
targetRejection保留 role/archive、exclusion、bound-agent 和 claim-owner 检查,再以 canonical lease 验证当前执行凭证。历史 lease 不能被当作无 lease 来绕过检查。updateRequestSha只在传入凭证时纳入 proof 字段,保持已存在的无凭证 v0 receipt 指纹;--update-operation-id与 lease 执行身份分开,支持跨调用重试。executeCoordinationTodoUpdate在同一个 provider revision 上检查并提交,仍只允许 text/note patch/clear。并发 lease 转移导致 CAS 失败;相同历史 operation 的 replay 只返回既有回执,不授予新写入权限。- CLI 参数校验、Python adapter 和真实 CLI 测试闭合传参到落盘/readback,双语 RFC 与 Todo 合同说明新能力和仍未闭合的边界。
main 已把时间解析迁到 runtime_timestamp.ts,原分支仍从旧模块导入 parseLeaseTimestamp。实际集成后触发 TS2305 和 runtime 导入失败;现已改为复用 parseIsoTimestamp,核对实现一致,没有重新增加旧导出或另一套解析器。RFC 冲突保留两边实施 checkpoint,没有删除后续规划。
对主干的风险
重点反证不是“传对凭证能成功”,而是编辑是否暗中改变 lease、以及验证后 lease 被转移是否仍能写入。File/NoKV/真实 PostgreSQL 的共享用例检查 lease 不变、并发转移 CAS 拒绝、提交响应丢失恢复、过期后的历史 replay、错误/缺失凭证和新请求拒绝;非法 epoch/expiry、released lease 等负例也覆盖。
本地通过 998 项 TS(含隔离真实 PostgreSQL 16.15,零失败/跳过)、267 项 Python(canonical CLI、legacy/handoff 与参数诊断)、类型检查及 Ruff。独立 base/head 六场景真实 FileAuthorityStore 对照中,无 lease 的 claimed/unclaimed 更新完整观察结果和原 receipt 指纹一致;valid lease 从原先 unsupported 变为正确更新,过期、错误和缺失凭证仍无写入。真实 CLI 用例删除 Markdown 展示后仍完成 text/note 更新和 canonical readback,证明展示不是 authority 输入。
限制:没有使用生产 Goal,没有宣布完整 native metadata、promotion 或分布式部署已闭合。线上 CI 尚有分片运行,不能把本地通过当作线上已通过。
我的整体评价
批准。它复用既有 typed fence 和事务边界,解决实际缺口,规模与价值匹配。最重要的伴随 refinement 是适配 main 的公共时间 codec;无需再造更新专用 lease 状态机。感谢 @LIHUA919 的完整正反例与跨 provider 验证。修复已经进入同一个 fork 分支,CI 通过后按维护者授权合并。
English verdict: APPROVE bf9a2f9867e20921f9795c88c87f63f395c644e6, pending final CI. The main-integration timestamp import failure is fixed in the original fork. Lease-fenced text/note updates reuse existing TS admission and provider CAS without mutating leases; 998 TS tests including real PostgreSQL, 267 Python tests, typecheck, and independent baseline/head no-lease parity passed. Full metadata editing and promotion defaults remain outside scope.
…rent Signed-off-by: huangruiteng <huangrt01@163.com>
huangruiteng
left a comment
There was a problem hiding this comment.
审阅 head:2437b48793d96df9f120aff9e300fda4687b438f。发现的 main 集成问题已修复并直接推回原作者 fork;没有剩余已验证的代码阻塞,合并等待当前 CI。
本轮在前次修复后又集成了已合并的 #4171(Git 空事务兼容修复);13 个 Todo PR 文件相对前次审阅没有变化。下述测试在新 head 重新执行,不继承旧 head 的 CI 结论。
动机
之前 native todo update 遇到任何 lease 都拒绝,即使调用者正持有合法执行凭证,也不能修正文案或备注。这个 PR 填补的是现有 text/note 更新路径的实用缺口,不是引入新的 lease 生命周期或完整 metadata writer。
改动思路
沿现有 CLI → Python compatibility adapter → TS canonical update → provider CAS/receipt 链路传递凭证,复用 evaluateCoordinationTerminalFence 判断身份、有效期与版本。只消费它的准入结果,不执行 terminal 的 lease effect,因此编辑不会获取、续期、释放或转移 lease。
具体改动
targetRejection保留 role/archive、exclusion、bound-agent 和 claim-owner 检查,再以 canonical lease 验证当前执行凭证。历史 lease 不能被当作无 lease 来绕过检查。updateRequestSha只在传入凭证时纳入 proof 字段,保持已存在的无凭证 v0 receipt 指纹;--update-operation-id与 lease 执行身份分开,支持跨调用重试。executeCoordinationTodoUpdate在同一个 provider revision 上检查并提交,仍只允许 text/note patch/clear。并发 lease 转移导致 CAS 失败;相同历史 operation 的 replay 只返回既有回执,不授予新写入权限。- CLI 参数校验、Python adapter 和真实 CLI 测试闭合传参到落盘/readback,双语 RFC 与 Todo 合同说明新能力和仍未闭合的边界。
main 已把时间解析迁到 runtime_timestamp.ts,原分支仍从旧模块导入 parseLeaseTimestamp。实际集成后触发 TS2305 和 runtime 导入失败;现已改为复用 parseIsoTimestamp,核对实现一致,没有重新增加旧导出或另一套解析器。RFC 冲突保留两边实施 checkpoint,没有删除后续规划。
对主干的风险
重点反证不是“传对凭证能成功”,而是编辑是否暗中改变 lease、以及验证后 lease 被转移是否仍能写入。File/NoKV/真实 PostgreSQL 的共享用例检查 lease 不变、并发转移 CAS 拒绝、提交响应丢失恢复、过期后的历史 replay、错误/缺失凭证和新请求拒绝;非法 epoch/expiry、released lease 等负例也覆盖。
本地通过 998 项 TS(含隔离真实 PostgreSQL 16.15,零失败/跳过)、273 项 Python(canonical CLI、legacy/handoff 与参数诊断)、类型检查及 Ruff。独立 base/head 六场景真实 FileAuthorityStore 对照中,无 lease 的 claimed/unclaimed 更新完整观察结果和原 receipt 指纹一致;valid lease 从原先 unsupported 变为正确更新,过期、错误和缺失凭证仍无写入。真实 CLI 用例删除 Markdown 展示后仍完成 text/note 更新和 canonical readback,证明展示不是 authority 输入。
另补充真实公共 CLI 的 base/head 八场景对照:legacy 和 promoted 两条路径分别检查 claimed、unclaimed、other-owner、empty-note。退出码、完整错误、text/note/owner/audit actor 与展示存在性观察完全一致。空字符串 note 单独传入仍按原合同拒绝,未擅自扩展清空字段的 CLI 语义。
限制:没有使用生产 Goal,没有宣布完整 native metadata、promotion 或分布式部署已闭合。线上 CI 尚有分片运行,不能把本地通过当作线上已通过。
我的整体评价
批准。它复用既有 typed fence 和事务边界,解决实际缺口,规模与价值匹配。最重要的伴随 refinement 是适配 main 的公共时间 codec;无需再造更新专用 lease 状态机。感谢 @LIHUA919 的完整正反例与跨 provider 验证。修复已经进入同一个 fork 分支,CI 通过后按维护者授权合并。
English verdict: APPROVE 2437b48793d96df9f120aff9e300fda4687b438f, pending final CI. The main-integration timestamp import failure is fixed in the original fork. Lease-fenced text/note updates reuse existing TS admission and provider CAS without mutating leases; 998 TS tests including real PostgreSQL, 273 Python tests, typecheck, and independent baseline/head no-lease parity passed. Full metadata editing and promotion defaults remain outside scope.
Summary
Promoted Todos with a hard lease reject even the current holder's text/note corrections. Accept explicit execution proof through the existing TypeScript terminal fence, and commit the edit and proof-bound receipt against one provider revision. The lease is preserved exactly.
Expose
--update-operation-idfor real CLI retries after a lost response. Changed edit intent or proof conflicts; historical replay does not renew a lease or confer current execution authority. No-proof v0 receipt fingerprints remain unchanged. Python remains a narrow adapter; other metadata and lifecycle changes are outside this slice.Issue Or Task
Closes #4105. Related migration tracker: #3225. Draft pending maintainer scope/review and required CI; no maintainer assignment is claimed.
Validation
35762fb1d(rebased on081ff998f; affected product/test/doc trees unchanged from pre-rebase validation).loopx canary premerge --from-git-diffremains red on dashboard output budget: 18,387 characters vs 18,215. The unchanged baseline reproduces exactly the same failure. Required CI/maintainer review remain holds.Initial full-suite attempts lacked
pythonon PATH and contained the old unsupported-lease expectation; corrected before passing. An earlier canary was invalidated by concurrent documentation edits and also exposed a pre-existing deferred-condition text assertion, reproduced on baseline; frozen-source rerun removes the concurrent-edit failures. No output budget or unrelated smoke was weakened.Coverage and gaps: the shipped update transaction, Python dispatch, historical receipt compatibility, authorization, concurrency and real provider backend are covered. No whole-Goal promotion, soak, model call, live Goal mutation, packaging/distribution qualification or performance uplift is claimed.
Type of Change
LoopX Area
Technical Direction
mainShared-authority RFC fixture impact
loopx_coordination_production_scale_fixture_v0, unchanged; existing fixture tests run in the full suite.Future-facing pass applied: reuse the existing typed terminal fence with auto-acquisition/delegation disabled, existing provider CAS and receipt machinery. No new capability/provider or parallel permission engine. Placement remains the built-in coordination Todo transaction and existing CLI adapter. Product delta: +89/-13; no additional runtime crossing introduced by the fence (in-process TS call).
Boundary Checklist