Skip to content

fix(todos): support lease-fenced canonical text and note updates - #4152

Merged
huangruiteng merged 5 commits into
loopx-project:mainfrom
LIHUA919:codex/todo-4105-lease-update
Sep 10, 2026
Merged

huangruiteng merged 5 commits into
loopx-project:mainfrom
LIHUA919:codex/todo-4105-lease-update

Conversation

@LIHUA919

Copy link
Copy Markdown
Contributor

Summary

Promoted Todos with a hard lease reject even the current holder's text/note corrections. Accept explicit execution proof through the existing TypeScript terminal fence, and commit the edit and proof-bound receipt against one provider revision. The lease is preserved exactly.

Expose --update-operation-id for real CLI retries after a lost response. Changed edit intent or proof conflicts; historical replay does not renew a lease or confer current execution authority. No-proof v0 receipt fingerprints remain unchanged. Python remains a narrow adapter; other metadata and lifecycle changes are outside this slice.

Issue Or Task

Closes #4105. Related migration tracker: #3225. Draft pending maintainer scope/review and required CI; no maintainer assignment is claimed.

Validation

  • Tested revision: 35762fb1d (rebased on 081ff998f; affected product/test/doc trees unchanged from pre-rebase validation).
  • Run state: finished
  • Input classes: synthetic, public_fixture
Check kind Result Public-safe evidence / limitation
static passed TypeScript typecheck; changed-Python Ruff; configured mypy (21 files); diff whitespace and public-boundary scans.
unit passed Complete control-plane TypeScript suite: 955 passed, zero failed/skipped.
real_backend passed Disposable isolated PostgreSQL 16.14; shared conformance also runs File, NoKV single-envelope test backend and NoKV JSON-lines test process. No live NoKV deployment qualification is claimed.
integration passed Affected Python authority, handoff and CLI argument tests: 205 passed.
real_entrypoint passed Real subprocess CLI with Markdown deleted: preview, proof-bearing edit, persisted readback, explicit operation retry and changed-intent rejection.
regression_parity passed New File v0/native lease update cases failed before implementation. Wrong actor/key/version, expiry, released/malformed lease, unclaimed lease, transfer race and response-loss recovery are covered; lease bytes stay unchanged. Existing unclaimed non-lease correction tests pass.
integration failed Risk-based loopx canary premerge --from-git-diff remains red on dashboard output budget: 18,387 characters vs 18,215. The unchanged baseline reproduces exactly the same failure. Required CI/maintainer review remain holds.

Initial full-suite attempts lacked python on PATH and contained the old unsupported-lease expectation; corrected before passing. An earlier canary was invalidated by concurrent documentation edits and also exposed a pre-existing deferred-condition text assertion, reproduced on baseline; frozen-source rerun removes the concurrent-edit failures. No output budget or unrelated smoke was weakened.

Coverage and gaps: the shipped update transaction, Python dispatch, historical receipt compatibility, authorization, concurrency and real provider backend are covered. No whole-Goal promotion, soak, model call, live Goal mutation, packaging/distribution qualification or performance uplift is claimed.

Type of Change

  • Bug fix
  • Documentation update
  • Test update

LoopX Area

  • Control plane (goals, todos, quota, scheduler, registry, runtime)

Technical Direction

Shared-authority RFC fixture impact

  • Production-scale fixture schema: loopx_coordination_production_scale_fixture_v0, unchanged; existing fixture tests run in the full suite.
  • Semantic dimensions: leased text/note edits now require the active execution key/version, the matching claim owner and a consistent provider head; released/expired leases fail closed. No default routing or promotion change.
  • Provider conformance arms: File, NoKV test backends, isolated real PostgreSQL; v0/native records in each arm.
  • Read-only legacy/file/PostgreSQL three-arm promotion rehearsal: not requested or claimed; this change does not promote a Goal or alter compatibility projection mechanics.

Future-facing pass applied: reuse the existing typed terminal fence with auto-acquisition/delegation disabled, existing provider CAS and receipt machinery. No new capability/provider or parallel permission engine. Placement remains the built-in coordination Todo transaction and existing CLI adapter. Product delta: +89/-13; no additional runtime crossing introduced by the fence (in-process TS call).

Boundary Checklist

…rent

Signed-off-by: huangruiteng <huangrt01@163.com>

# Conflicts:
#	docs/architecture/rfcs/typescript-control-plane-migration-v0.md
#	docs/architecture/rfcs/typescript-control-plane-migration-v0.zh-CN.md
Signed-off-by: huangruiteng <huangrt01@163.com>

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

审阅 head:bf9a2f9867e20921f9795c88c87f63f395c644e6。发现的 main 集成问题已修复并直接推回原作者 fork;没有剩余已验证的代码阻塞,合并等待当前 CI。

动机

之前 native todo update 遇到任何 lease 都拒绝,即使调用者正持有合法执行凭证,也不能修正文案或备注。这个 PR 填补的是现有 text/note 更新路径的实用缺口,不是引入新的 lease 生命周期或完整 metadata writer。

改动思路

沿现有 CLI → Python compatibility adapter → TS canonical update → provider CAS/receipt 链路传递凭证,复用 evaluateCoordinationTerminalFence 判断身份、有效期与版本。只消费它的准入结果,不执行 terminal 的 lease effect,因此编辑不会获取、续期、释放或转移 lease。

具体改动

  • targetRejection 保留 role/archive、exclusion、bound-agent 和 claim-owner 检查,再以 canonical lease 验证当前执行凭证。历史 lease 不能被当作无 lease 来绕过检查。
  • updateRequestSha 只在传入凭证时纳入 proof 字段,保持已存在的无凭证 v0 receipt 指纹;--update-operation-id 与 lease 执行身份分开,支持跨调用重试。
  • executeCoordinationTodoUpdate 在同一个 provider revision 上检查并提交,仍只允许 text/note patch/clear。并发 lease 转移导致 CAS 失败;相同历史 operation 的 replay 只返回既有回执,不授予新写入权限。
  • CLI 参数校验、Python adapter 和真实 CLI 测试闭合传参到落盘/readback,双语 RFC 与 Todo 合同说明新能力和仍未闭合的边界。

main 已把时间解析迁到 runtime_timestamp.ts,原分支仍从旧模块导入 parseLeaseTimestamp。实际集成后触发 TS2305 和 runtime 导入失败;现已改为复用 parseIsoTimestamp,核对实现一致,没有重新增加旧导出或另一套解析器。RFC 冲突保留两边实施 checkpoint,没有删除后续规划。

对主干的风险

重点反证不是“传对凭证能成功”,而是编辑是否暗中改变 lease、以及验证后 lease 被转移是否仍能写入。File/NoKV/真实 PostgreSQL 的共享用例检查 lease 不变、并发转移 CAS 拒绝、提交响应丢失恢复、过期后的历史 replay、错误/缺失凭证和新请求拒绝;非法 epoch/expiry、released lease 等负例也覆盖。

本地通过 998 项 TS(含隔离真实 PostgreSQL 16.15,零失败/跳过)、267 项 Python(canonical CLI、legacy/handoff 与参数诊断)、类型检查及 Ruff。独立 base/head 六场景真实 FileAuthorityStore 对照中,无 lease 的 claimed/unclaimed 更新完整观察结果和原 receipt 指纹一致;valid lease 从原先 unsupported 变为正确更新,过期、错误和缺失凭证仍无写入。真实 CLI 用例删除 Markdown 展示后仍完成 text/note 更新和 canonical readback,证明展示不是 authority 输入。

限制:没有使用生产 Goal,没有宣布完整 native metadata、promotion 或分布式部署已闭合。线上 CI 尚有分片运行,不能把本地通过当作线上已通过。

我的整体评价

批准。它复用既有 typed fence 和事务边界,解决实际缺口,规模与价值匹配。最重要的伴随 refinement 是适配 main 的公共时间 codec;无需再造更新专用 lease 状态机。感谢 @LIHUA919 的完整正反例与跨 provider 验证。修复已经进入同一个 fork 分支,CI 通过后按维护者授权合并。

English verdict: APPROVE bf9a2f9867e20921f9795c88c87f63f395c644e6, pending final CI. The main-integration timestamp import failure is fixed in the original fork. Lease-fenced text/note updates reuse existing TS admission and provider CAS without mutating leases; 998 TS tests including real PostgreSQL, 267 Python tests, typecheck, and independent baseline/head no-lease parity passed. Full metadata editing and promotion defaults remain outside scope.

…rent

Signed-off-by: huangruiteng <huangrt01@163.com>

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

审阅 head:2437b48793d96df9f120aff9e300fda4687b438f。发现的 main 集成问题已修复并直接推回原作者 fork;没有剩余已验证的代码阻塞,合并等待当前 CI。

本轮在前次修复后又集成了已合并的 #4171(Git 空事务兼容修复);13 个 Todo PR 文件相对前次审阅没有变化。下述测试在新 head 重新执行,不继承旧 head 的 CI 结论。

动机

之前 native todo update 遇到任何 lease 都拒绝,即使调用者正持有合法执行凭证,也不能修正文案或备注。这个 PR 填补的是现有 text/note 更新路径的实用缺口,不是引入新的 lease 生命周期或完整 metadata writer。

改动思路

沿现有 CLI → Python compatibility adapter → TS canonical update → provider CAS/receipt 链路传递凭证,复用 evaluateCoordinationTerminalFence 判断身份、有效期与版本。只消费它的准入结果,不执行 terminal 的 lease effect,因此编辑不会获取、续期、释放或转移 lease。

具体改动

  • targetRejection 保留 role/archive、exclusion、bound-agent 和 claim-owner 检查,再以 canonical lease 验证当前执行凭证。历史 lease 不能被当作无 lease 来绕过检查。
  • updateRequestSha 只在传入凭证时纳入 proof 字段,保持已存在的无凭证 v0 receipt 指纹;--update-operation-id 与 lease 执行身份分开,支持跨调用重试。
  • executeCoordinationTodoUpdate 在同一个 provider revision 上检查并提交,仍只允许 text/note patch/clear。并发 lease 转移导致 CAS 失败;相同历史 operation 的 replay 只返回既有回执,不授予新写入权限。
  • CLI 参数校验、Python adapter 和真实 CLI 测试闭合传参到落盘/readback,双语 RFC 与 Todo 合同说明新能力和仍未闭合的边界。

main 已把时间解析迁到 runtime_timestamp.ts,原分支仍从旧模块导入 parseLeaseTimestamp。实际集成后触发 TS2305 和 runtime 导入失败;现已改为复用 parseIsoTimestamp,核对实现一致,没有重新增加旧导出或另一套解析器。RFC 冲突保留两边实施 checkpoint,没有删除后续规划。

对主干的风险

重点反证不是“传对凭证能成功”,而是编辑是否暗中改变 lease、以及验证后 lease 被转移是否仍能写入。File/NoKV/真实 PostgreSQL 的共享用例检查 lease 不变、并发转移 CAS 拒绝、提交响应丢失恢复、过期后的历史 replay、错误/缺失凭证和新请求拒绝;非法 epoch/expiry、released lease 等负例也覆盖。

本地通过 998 项 TS(含隔离真实 PostgreSQL 16.15,零失败/跳过)、273 项 Python(canonical CLI、legacy/handoff 与参数诊断)、类型检查及 Ruff。独立 base/head 六场景真实 FileAuthorityStore 对照中,无 lease 的 claimed/unclaimed 更新完整观察结果和原 receipt 指纹一致;valid lease 从原先 unsupported 变为正确更新,过期、错误和缺失凭证仍无写入。真实 CLI 用例删除 Markdown 展示后仍完成 text/note 更新和 canonical readback,证明展示不是 authority 输入。

另补充真实公共 CLI 的 base/head 八场景对照:legacy 和 promoted 两条路径分别检查 claimed、unclaimed、other-owner、empty-note。退出码、完整错误、text/note/owner/audit actor 与展示存在性观察完全一致。空字符串 note 单独传入仍按原合同拒绝,未擅自扩展清空字段的 CLI 语义。

限制:没有使用生产 Goal,没有宣布完整 native metadata、promotion 或分布式部署已闭合。线上 CI 尚有分片运行,不能把本地通过当作线上已通过。

我的整体评价

批准。它复用既有 typed fence 和事务边界,解决实际缺口,规模与价值匹配。最重要的伴随 refinement 是适配 main 的公共时间 codec;无需再造更新专用 lease 状态机。感谢 @LIHUA919 的完整正反例与跨 provider 验证。修复已经进入同一个 fork 分支,CI 通过后按维护者授权合并。

English verdict: APPROVE 2437b48793d96df9f120aff9e300fda4687b438f, pending final CI. The main-integration timestamp import failure is fixed in the original fork. Lease-fenced text/note updates reuse existing TS admission and provider CAS without mutating leases; 998 TS tests including real PostgreSQL, 273 Python tests, typecheck, and independent baseline/head no-lease parity passed. Full metadata editing and promotion defaults remain outside scope.

@huangruiteng
huangruiteng merged commit 344f2fe into loopx-project:main Sep 10, 2026
21 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Task]: Support lease-fenced text/note updates for promoted canonical Todos

2 participants