feat(coordination): close canonical lease acquisition and current-proof recovery - #4669
Conversation
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
…undaries Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Exact reviewed head: 4493a26b125b0c45b8a239bee3da21f8d172ec54.
动机
按 #4574 R5、TS migration RFC 的整笔事务/迁移成本要求,以及 shared-authority L3 验收判断本批。#4666 已解决既有 lease 的维护;不可变基线 8330a974c 上,promoted Goal 的独立 acquire 仍撞旧 writer fence。只改路由不能解决创建 CAS 原样重试、旧 receipt 与当前执行权的区别、重复 claim 准入,以及实际完成时缺失 Markdown 的失败。本批交付新领取/接管到 canonical Todo 完成的可用增量;默认化、D2/D3 和跨外部 effect 的 executor 持锁仍未交付。
改动思路
CLI → Python 注册事实/传输 → 既有 native handler → provider/source fence → 完整 canonical head → typed acquire decision → 一笔 CAS 保存 lease/event/receipt → 当前 proof 回读。File/SQLite 和 service-owned PostgreSQL 共享业务规则,provider 只管持久化。旧文件 caller 继续调用同一个纯决策与 materializer;原子 claim 删掉独立的 lease facts、冲突扫描和记录生成。无新 capability、通用 patch API、凭据参数或自动 promotion。
反对扩大设计的最强理由是:完整 head 读取和 receipt 会增加领取成本,且不能替代外部执行的锁。实际边界因此限制为已存在的领取/维护/完成 caller;没有把 executor lock 宣称为同一数据库事务,也没有凭 receipt 存在就授予当前执行权。净增的生产机制对应先前不可用的整笔 canonical 领取,而不是未来 provider 框架。
具体改动
关键代码讲解
coordination/task_lease_acquire.ts:23的executeCanonicalTaskLeaseAcquire绑定 Goal/Todo/owner/key 及原始参数摘要,先恢复同一操作,再用当前 owner/key/epoch/有效性检查成功语义。续约后返回当前lease,原决定保留在original_receipt;到期、释放或转交后拒绝旧执行。提交响应丢失只读回执,不重发写入。work_items/task_lease_acquire_decision.ts:310的decideTaskLeaseAcquire保留旧 eligibility、版本和 scope 冲突优先级;新执行前检查 safe-integer generation。materializeTaskLeaseAcquire同时服务旧文件、canonical 独立领取和原子 claim,下一次代际规则修改只有一个 owner。coordination/task_lease_state.ts:39的canonicalTaskLeaseAcquireFacts从完整保留集合构造事实;归档或失效 holder 不形成有效冲突,显示上限以外的有效 lease 仍必须阻挡。当前 Todo、注册 actor 和 persisted lease 身份共同决定 eligibility,不能由调用者的旧 Todo/mode 提示覆盖。work_items/task_lease_acquire_adapter.py:397的execute_native_task_lease_acquire选择封闭 canonical wire,传注册事实并校验 provider 来源;不重建 canonical Todo/lease head、不追加 shadow authority。未 promoted caller 保留原路径。todos/provider_terminal_lifecycle.py同步修复 complete/supersede 对缺失展示文件的前置依赖,由既有 outbox 完成重建。
其余范围包括生成的双语言 schema binding、native handler 导入、共享 provider opening 和既有维护 validator 的复用;验证复用原有规模 fixture、进程 helper、caller matrix 和四臂演练。双语 roadmap/RFC checkpoint 与原操作文档原位更新。没有新增设置或前端交互;当前受影响的产品入口是 CLI,未宣称打包前端/Lark 验收。
对主干的风险
重点反例是“receipt 正确存在,但执行已被接管”:acquire 成功前必须再读当前 generation;转交/释放后的重试拒绝且状态不变。竞争 CAS、提交前后 SIGKILL、注册源/fence 改变、无 provider、越过显示上限的 scope 冲突、归档/excluded/claim-conflicting/deregistered holder 均有覆盖。旧 wire 仍被 fence 阻挡,absent/disabled/capture 的 caller 矩阵保留独立负例。原子 claim 的 Todo-required scopes 和 standalone 的 caller scopes 保持各自已有意图,scope 不授予文件或业务权限。
语义与 CI 对齐
复用既有 lease、epoch、receipt 和 provider 词汇,仅为 canonical acquire 增加封闭请求 schema;没有第二份 Python 状态机、文本子串准入或领域专属义务。原样创建重试、归档 holder 冲突、generation 耗尽和缺失展示完成均是公开披露的语义变化;旧 fixture 期待值在保留不可变基线的同时按独立前置状态更新,不靠放宽断言消除失败。当前 review policy revision 6、wait_for_ci=false:评审未查询或等待远端 CI,使用真实本地验证;功能和真实路径的必需检查全部通过,用户接受的性能例外单独披露。
- Full TS: 1952 passed, 0 failed; its single environment-selected PostgreSQL service skip was resolved by the separate real service suite (10 passed, 0 skipped).
- Stage2C E2E shards: 113 + 112 passed, no skips; focused CLI/matrix 28 passed, adjacent Python lease/claim/readback 70 passed.
- Real File conformance 127 passed; real SQLite/PostgreSQL conformance 273 passed, including full-state scope/CAS/recovery tests. These suites overlap the full TS run and are not added into a total.
- TypeScript noEmit, mypy (22 files), changed Python Ruff, generated-contract check and whitespace checks pass. Fresh wheel and sdist each pass both File/SQLite CLI journeys.
- The full-CLI replay performance check did not pass; the owner explicitly accepts this scoped exception; the numerical failure remains disclosed.
真实只读快照的四臂输入为 355 Todos/10 初始 leases(含隔离合成追加);正常操作结果和三个 provider 最终 head 一致,源和无关记录不变。故意破坏 takeover epoch 递增时,同一公共 native 演练按独立 oracle 失败(2 → 1),证明结果比较能抓住代际隔离退化。NoKV 仅测试 transport,PostgreSQL 使用真实隔离服务器;跨主机部署和 D2 soak 仍不在本次证据内。
回滚保留 canonical state、receipt 与 writer fence,恢复兼容代码;不可删除 fence 后复活旧文件。新增协议会被不支持它的旧 runtime 拒绝,这一兼容边界已写入操作文档。
我的整体评价
这是独立可用、可回退的 R5/L3 增量,不是全部默认化目标完成。34 文件 +1431/-694;其中生产代码 +707/-519,净 +188,测试/fixture/docs/generated 单列。acquire IO 文件的大段搬移不算删除语义;claim 和 maintenance 的重复事实/记录规则才是真正收敛。未来收敛已应用到同域的 decision/facts/provider fence;更大的 executor effect-lock 生命周期保留在 L3 的既有边界,不引入空框架。
Fixed 64 interleaved legacy CLI pairs against 8330a974c: acquire p50/p95 1337.00/2433.55 → 1272.07/2213.36 ms; replay 1328.84/2059.92 → 1401.69/2233.97 ms. Replay p95 +8.45% / +174.05 ms exceeds the RFC gate; noisy host timings do not qualify it. The earlier concurrent-load 24-pair run also showed higher replay tails and is retained, not discarded. Cold-start p50/p95: 204.11/210.60 → 205.86/211.05 ms (12 samples). Typed transport p50/p95: 0.372/0.593 → 0.389/0.569 ms (128); the full Python facade including source fingerprint is 7.15/9.09 → 7.88/9.47 ms. Candidate daemon RSS is 105.83 MiB idle / 106.14 MiB after burst. Warm complete adapter acquire/replay p95 (24): legacy baseline 55.19/47.21, candidate legacy 58.03/52.56, File 80.39/40.25, SQLite 37.31/26.11 ms. Each acquire/replay makes exactly one native request. Canonical acquisition had no successful baseline and is not a speedup claim. The owner explicitly accepts these measured results for this PR. This is a scoped acceptance exception, not a numerical pass or a global budget change; the earlier failed assessment and raw samples are retained.
Exact-scope quality receipt cqr_230e19840a3398050777 is valid for fingerprint 230e19840a3398050777b04bfbdf4b92dfe77c5318fa894efa5793b9a276ad19 (34 files): zero blockers, one resolved warning, zero advisories. One allowed bounded safe-fix pass was applied. The owner explicitly accepts the recorded CLI replay-tail difference for this PR; the default latency gate is waived for this scope only, with its earlier failed assessment retained. Global thresholds are unchanged. Final canary premerge --from-git-diff --goal-id loopx-meta: passed, 19/19 selected checks, zero failures/skips, exact quality receipt valid; no manual hold.
批准结论。 用户在获知两轮计时和 +8.45% replay p95 后,明确接受本 PR 的性能差异。原始数值不改写为通过;例外只作用于本 PR,未降低全局阈值。功能/真实 provider/安装包证据通过,精确质量记录现已有效。保留性能风险说明,交由维护者合并;本评审不是自动合并授权。
English verdict: APPROVE - 4493a26b125b0c45b8a239bee3da21f8d172ec54: canonical acquisition now provides current execution proof and reaches Todo completion; legacy/provider boundaries, real backends, process loss and packaged CLI are verified. Executor effect locks and default-provider qualification remain separate. The owner explicitly accepts the measured +8.45% replay p95 for this PR only; numerical failure remains disclosed and global thresholds unchanged. Maintainer merge required.
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval): reviewed exact head 4493a26b125b0c45b8a239bee3da21f8d172ec54, no blocking findings in the contract/decision half; the large reported suites and the disclosed performance exception are named below and are not claimed as re-verified by me. Merge remains the maintainer's decision.
动机
已提升(promoted)的 Goal 能续租已有 lease,但独立的 task-lease acquire 仍然走被 fence 挡住的 legacy writer——也就是说,同一个 lease 决策在做 acquire 时没有 canonical 所有者,在 claim/renew 时却有,操作者拿不到一条运行时已经承认的路径。这个切片补的正是这个洞:让 fresh acquisition 和 takeover 走已选中的 authority,并把结果证明一路带到真实的 CLI Todo completion。我判它是 justified_increment:它没有把 fence 放宽(那会重新引入第二权威),而是复用既有的 receipt 原语与 provider CAS 形状,把 claim/lifecycle 里重复的 lease fact 构造删掉、改成共享。相对 RFC 的立场也一致——状态机与 effect 权威留在 typed TS 边界,Python 只做 transport/registration。
改动思路
边界上的路由决策是本次最关键、也最容易出错的地方:execute_native_task_lease_acquire 先问 local_authority_is_promoted,promoted 时改用 canonical facts 与 canonical request schema,不再附加 shadow binding;非 promoted 时逐字保留原路径(legacy facts、shadow binding、_finalize_native_acquire_result)。canonical 分支返回前还会断言 payload 的 source_authority ∈ {file_v0, sqlite_v0}、decision_read_from_provider is True、legacy_fallback_used is False,任一不满足就 raise——这是 fail-closed,而不是"看起来成功就当成功"。决策侧 coordination/task_lease_acquire.ts 只有 128 行、复用 CoordinationCommandReceipt:lease + event + 不可变 receipt 由一次 create-CAS 写入;receipt 必须同时匹配原始参数与执行身份;receipt 活过了它所属的执行代际就不能再授予执行;当前 eligibility/owner/key/epoch 与非回退 version 在成功路径上重新校验。claim 侧从"自己重建 lease facts/records"改为调用同一组共享 facts/materialization,于是两个命令对"当前该做什么"不会再各写一份规则。
具体改动
34 个文件、+1431/-694;作者自己的口径是排除 generated、generator、tests/fixtures/docs 后 +707/-519 = +188 产品行,其中 claim 少 90 行、lifecycle 少 22 行,被共享调用替代;legacy acquire 的 387 行主要是搬进决策所有者,作者明确不把这些算作"消除的行为"——这个区分是诚实的,我按同样口径读。新增 coordination/task_lease_acquire.ts、task_lease_state.ts,重写 work_items/task_lease_acquire_decision.ts,改 todo_claim.ts / task_lease_lifecycle.ts、Python adapter 与 effect handler,更新 generated 契约三元组与生成器、四个 TS 测试、Python 测试、两个 fixture、一个 rehearsal example,以及五个文档面(含双语镜像)。
关键代码讲解
execute_native_task_lease_acquire(task_lease_acquire_adapter.py:411):canonical 分支早返回,因此不会走 _finalize_native_acquire_result,也就不存在"provider 写完再补一条 shadow"的双写;provenance 断言放在 retry 循环内、finalization 之前,重试后仍缺证据就 raise 而不是退回 legacy 路由。
executeCanonicalTaskLeaseAcquire(coordination/task_lease_acquire.ts:23):receipt 的身份/参数/代际三重复核决定了 exact retry 与拒绝的边界;durable receipt 但当前权威不可用时返回显式 ambiguous + retry_with_same_operation_id,而被retired 的 execution 复用同一 idempotency key 则以 idempotency_key_reuse 明确失败——不会"复活"旧执行。
todo_claim.ts 的共享 facts/materialization:archived/失效 holder 不再制造 scope contention,active 重叠 holder 仍然拒绝(包括超出展示上限的记录),不安全的 generation 递增在 writeback 之前就拒绝。这三条正是 acquire 与 claim 必须一致的部分。
对主干的风险
性能门是失败并被豁免的,我保留这个区分。 PR 自己披露固定 64 对交错测量:acquire p95 1337.00→1272.07 ms 变好,replay p95 1328.84→1401.69 ms,+8.45% / +174.05 ms 超过 RFC 门限,并且全局阈值未改、早先的失败评估被保留、由 owner 针对本 PR 明确接受。我没有重新测量,也不会把这个豁免表述成"通过";如果 replay 尾巴以后重要,应在后续 lifecycle companion 落地后单独复测。
仍存在双读者窗口(P3,已由 PR 命名)。 adapter 的 canonical 分支不可能双写(早返回已证明),但 PR 明确保留 legacy fact builder 给 unpromoted/executor 调用者,所以 promoted Goal 上"provider 状态"与"剩余 legacy 读取者"会在一段时间内共存。这是读侧不一致的风险,不是写竞争;修法就是作者写的"随真实调用者一起退役",而不是加兼容包装。
我核对过、可以依赖的部分。 生成契约与生成器同步(--check exit 0);task_lease_acquire + task_lease_eligibility 两个 TS 套件 61 通过 / 0 失败(含 exhausted version/epoch 拒绝、owner-eligibility 跨 adapter 优先级、release 作为 fenced cleanup、production-scale history 约束);tests/control_plane/test_canonical_lease_acquire.py 2 通过;caller-parity fixture 行数仍是 46,只是把 acquire 那两条从 -engaged/-engaged-capture 换成 -canonical/-canonical-capture——是移动覆盖而不是删掉覆盖,这一点我逐行比对过。unpromoted Goal 的行为、schema 与 shadow binding 没有变化;没有新增 settings 字段、前端控件、Lark 命令或公开输入选项。
我没能复现的证据(作者报告、我未重跑):full TS 1952、真实 File 127、真实 SQLite/PostgreSQL 273、PostgreSQL service 10、Stage2C 113+112、wheel/sdist 两条 CLI journey,以及那段只读私有 rehearsal(355 Todos / 10 leases)。这些恰好是"真实 provider 一致性"那一半;我的批准只覆盖契约/决策这一半。
我的整体评价
这是把一个"缺失的 canonical 命令"补上,同时删掉第二份规则,而不是给每个命令加适配层——形状正确:一个 typed 决策 + 一次 CAS + 一份不可变 receipt,边界上 fail-closed,promoted/unpromoted 两条路的语义分得干净,文档(两个 RFC 镜像、roadmap 检查点、renew 参考)与代码同 diff 更新,且对"搬代码不等于消除行为""性能门没通过而是被豁免"这两件事都写得很清楚。因此我对契约与决策这一半给出批准结论,把未复现的大套件、真实 provider 一致性与那条性能豁免明确留在后续。合并与否是你的决定;这个评论不构成合并许可。
English verdict: APPROVE — at 4493a26b125b0c45b8a239bee3da21f8d172ec54 standalone acquisition and atomic claim share one full-head lease decision, the Python boundary is fail-closed on provider provenance and never appends a shadow write on the canonical path, the generated contract is in sync, 61 focused TS cases and 2 focused Python cases pass, and the caller-parity matrix keeps all 46 rows while moving the acquire arm to the canonical case; the CLI replay-tail gate is a disclosed failure with an owner-scoped acceptance rather than a pass, and the large real-provider suites plus the private rehearsal remain author-reported and were not re-executed here.
|
Correction to my review of this head — I have to withdraw one evidence row. My review's structured evidence recorded
So: treat the check-status half of that review as withdrawn. What still stands is the part I actually read and executed — the fail-closed provenance boundary in the adapter, the generator Please either re-run the workflow to see whether the cancellation was the cause, or push the fix for |
|
Reproduced locally at The case's oracle is
A node id that no longer collects makes the control run exit non-zero, so the gate aborts before it ever mutates anything, and the three aggregate jobs ( That also means the coverage loss is real, not cosmetic: while these two cases point at a missing row, the native fence remediation message and the fence envelope schema leak have no deliberate-regression check at all. Fixing it should be two references — point them at I am the reviewer of record for this fixture change, and I read the rename while reviewing without checking what referenced the old id — that is my miss, not just CI noise. Once the references are fixed and the run is green I will re-verify. |
…60918 Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
…isition Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
…60918 Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval): reviewed exact head ae0f5bdc56a021c25b9886ecce61e685adf97b1c, no blocking finding. Required CI was still running when I reviewed (named below); real File/SQLite/PostgreSQL rehearsal numbers remain author-reported. Merge remains the maintainer's decision.
动机
独立的 task-lease acquire 路径此前仍会进入被 fence 的 legacy writer,而已提升的 File/SQLite Goal 明明已经能维护 lease——同一个"谁拥有 lease 准入与物化"的规则存在两份实现。更隐蔽的是:上一次红掉的 stage2c (mutants 0) 不是代码回归,而是本 PR 把 parity 行 cli-task_lease_acquire-engaged 改名为 -canonical 后,两个 deliberate-regression case 还指向旧 id,导致"未变 oracle"直接中止,那个 gate 一段时间内其实什么都没守。这一轮我复核了改名后的完整链路,并确认这两个 case 重新真的能杀掉突变。它推进 #4574 R5 与 shared-authority L3,但不完成 L3,也不改 provider 默认值。
改动思路
产品侧的思路是"收敛到一个所有者",不是"再包一层":
- 准入归位。新增
work_items/task_lease_acquire_decision.ts::decideTaskLeaseAcquire作为唯一准入所有者(scope 重叠、eligibility、owner/key/epoch、version 不回退),coordination/task_lease_acquire.ts::executeCanonicalTaskLeaseAcquire通过一次 provider CAS 落盘 lease、event 与不可变 acquisition receipt。 - 共享事实而不是复制。
coordination/task_lease_state.ts::canonicalTaskLeaseAcquireFacts让 acquire 与原子 Todo claim 共用 full-head lease facts;todo_claim.ts/task_lease_lifecycle.ts因此各净减约 90/22 行,而 legacy acquire 删掉的 387 行是搬进 cohesive 决策所有者,不算"被消灭的行为"。 - 当前证明随 CLI 走完。成功 acquisition 之后额外校验当前 eligibility/owner/key/epoch,并返回 current proof + 原 receipt;release、expiry、transfer 都不能复活旧执行。
- 门禁修复。
examples/shared-goal-authority-e2e/mutants.py里两个 fence case 的目标从已删除的cli-task_lease_acquire-engaged改到仍然存在的^fence parity: ts-acquire-engaged$与cli-todo_capture_followups-engaged。
具体改动
相对 merge-base 共 35 个文件、+1435/-696:12 个产品文件(+708/-519)、14 个测试/夹具(+593/-94)、7 个文档(+130/-83)、2 个生成契约(+4)。产品增量集中在 lease/coordination 路径,其余是把 legacy acquire 的事实构造搬进决策所有者、以及双语 RFC/roadmap 检查点。
关键符号(均在本次 head 核对过行号):
task_lease_acquire_decision.ts:310:唯一准入决策;非法 generation 增量、失效 holder、同一 execution identity 下意图变化都在写回前拒绝。task_lease_acquire.ts:23:一次 provider CAS 落 lease+event+receipt;create-CAS 精确重试恢复原操作。task_lease_state.ts:39:acquire/claim/lifecycle 共用的完整 lease facts。task_lease_acquire_adapter.py:Python 桥只做公开 CLI 传输与 registration facts,不再重建 canonical head,也不追加第二次 shadow 写入。mutants.py:333/338:修复后的两个 fence case;parity 夹具保持 46 行,acquire 臂由-engaged改名为-canonical,absent/invalid/unreadable 臂未动。
我实际复跑的验证
mutants.py --case native_fence_remediation_truncated --case python_fence_remediation_truncated:两个 case 都是control_exit=0(oracle 现在能过)、mutant_exit=1、killed_by_assertion=true——这次是真的在守合同,不是空跑。我在21828688e和合并后的ae0f5bdc上各跑一遍,结果一致。- TS:
node --test task_lease_acquire / task_lease_eligibility / legacy_writer_fence_caller_parity / canonical_task_lease_renew→ 149 passed / 0 failed。 - Python:
test_canonical_lease_acquire.py+test_shadow_fence_caller_parity_e2e.py→ 28 passed。
对主干的风险
CI 在我评审时仍未跑完,请不要把这条读成绿灯。 gh pr checks 4669 当时 Sign-off/build/dependency-review/postgresql-authority/Windows/node-forward-compatibility 已通过,但 test-shard 1-4、kernel-static-checks、stage2c(e2e/mutants/installed)、dashboard-acceptance、node-minimum-compatibility 仍 pending。我在结构化证据里把 repository_required_checks 记为 unverified(pending) 而非 pass——这正是上次我在这个 PR 上犯过的错,这次不重复。
其余需要明说的边界:
- 本 head 是 main 的合并:
ae0f5bdc引入 #4673(site 内容),本 PR 自身的 35 文件 diff 与21828688e逐字节一致,文件集合完全相同,合并后我把 mutants 与两组测试都在新 head 上重跑确认无变化。 - 真实的 File/SQLite/PostgreSQL conformance 与"CLI 走完 acquire→retry→renew→proof→release→新执行→complete/readback"的 rehearsal 数字是作者报告,我没有独立复现;我只独立复现了 mutants 门禁与上面两组测试。
- CLI replay-tail 性能门禁未通过,PR 已明确写为 owner 认可的 scoped exception、全局阈值不变——这是披露过的例外,不是被我判为通过。
- 本 PR 只推进 R5/L3,executor holder/terminal locks(L2/L4/L5)与 D2/D3 仍需各自的验收;rollback 保留 canonical state/receipt/fence,旧 lease 文件不会被复活。
我的整体评价
形状是对的:一份准入决策、一份 lease facts、一次 provider CAS,Python 只做传输不重建 canonical head,legacy fact builder 明确保留给尚未提升的 caller 而不是加兼容包装。门禁那块尤其值得肯定——发现问题后不是放宽断言,而是把两个 case 重新指向仍然存在的合同行,并且我用"oracle 通过 + 突变被杀"独立验证了它确实恢复守卫能力。
我给出的是契约与门禁这一半的批准结论:CI 跑绿、且 maintainer 确认 replay-tail 例外后即可合并;这条评论不构成合并许可。
English verdict: APPROVE — at ae0f5bdc56a021c25b9886ecce61e685adf97b1c standalone task-lease acquire now completes through the canonical authority with one shared decision/materialization owner, and the two shadow-fence mutants again pass their unchanged oracle and are killed by assertion (verified locally: control_exit=0 / mutant_exit=1, plus 149 TS and 28 Python cases). The PR's own 35-file diff is byte-identical to the previously reviewed 21828688e; the only change is a merge of origin/main (#4673). Required CI and the owner-waived CLI replay-tail gate remain open, so this is a review approval only, not merge authority.
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
精确审查 head:ae0f5bdc56a021c25b9886ecce61e685adf97b1c。本轮重新审查完整 PR,修复并验证旧 CI 阻塞;不继承先前被撤回的 CI 证据。
动机
已 promoted 的 Goal 可以维护已有 lease,但独立 task-lease acquire 仍进入被 fence 拦截的 legacy writer,无法开始新的执行。本 PR 补齐新领取与接管,并将当前执行 proof 带到真实 CLI Todo completion。它是 #4574 R5 / shared-authority L3 的合理增量:executor 外部 effect 持锁、L2/L4/L5 剩余 caller、跨 Agent 返回和 D2/D3/default 资格仍分别验收。
直接取消旧 fence 会重新引入第二个 writer;仅给领取加一个临时分支又会继续复制 claim 的规则。当前改动复用已有 provider/CAS/receipt,收敛实际 caller 的 facts、准入和 materializer,能够独立验证和回滚。
改动思路
Python 只选择 scoped 路由、传注册事实并验证来源;TS 决定是否允许领取,provider 负责原子持久化。acquire 和维护共用 provider opening、promotion/source fence。独立领取、旧文件入口与原子 claim 共用 acquire decision/materializer;claim 保留 Todo-required scopes,standalone 保留 caller-requested scopes,两者都不扩张权限。
CoordinationCommandReceipt 保留原始决定;acquire 成功还必须读取当前权威,核对资格、owner/key/epoch 和非回退 version。这样原样 create-CAS 重试可恢复,续约后返回当前 proof,而释放、到期或转交后的旧 receipt 不会重新授权。维护和 claim 的历史 replay 语义仍保持。
具体改动
coordination/task_lease_acquire.ts:23:executeCanonicalTaskLeaseAcquire绑定原操作与参数,执行一次 lease/event/receipt CAS,再经currentProof校验当前执行;提交响应丢失按同一 identity 恢复。work_items/task_lease_acquire_decision.ts:310:decideTaskLeaseAcquire统一 eligibility、CAS、scope 冲突与代际规则;safe-integer 耗尽在写入前拒绝。materializeTaskLeaseAcquire被旧入口、canonical acquire 和 claim 共同使用。coordination/task_lease_state.ts:从完整 canonical 集合构造 facts;显示上限以外的有效重叠 holder 仍阻挡,归档/排除/注销/claim-conflicting/过期 holder 按其失效语义处理。维护复用相同 record validator。work_items/task_lease_acquire_adapter.py:397:canonical 路径不重建 Todo/lease head、不追加 shadow write;成功响应缺少可信 provider provenance 时 fail closed。provider_terminal_lifecycle.py让 canonical complete/supersede 经现有 outbox 恢复缺失展示文件。- 生成契约、handler 导入、规模 fixture、provider conformance、真实进程终止和 CLI matrix 同步更新;双语 RFC/roadmap 和操作文档替换旧 checkpoint。没有新增设置项、前端控件或 Lark 输入,因此本轮入口验证是源代码及安装包 CLI,不宣称前端/Lark 协作验收。
本轮额外修复 examples/shared-goal-authority-e2e/mutants.py 的两个旧 node id。不能简单改成 cli-task_lease_acquire-canonical:该成功路径已经绕开 legacy fence,无法检测所注入的缺陷。现在两项 probe 使用仍被 fence 拦截的原生 ts-acquire-engaged;正常 control 通过,截断 remediation 和泄漏 envelope schema 均由断言杀死。保留既有 Python fence probe。同步 latest main 时也纳入 #4670 的 no-change idempotent 修复,并运行其真实 CLI 回归。
对主干的风险
最重要的反例是“回执仍存在,但执行已被别人接管”。已在真实 provider 上验证该拒绝及无副作用,并通过相同 public native 入口注入 epoch 不递增的故障:独立 oracle 期望 2、实际 1,确实失败。另覆盖源/fence 改变、无 provider、CAS 竞争、提交前后进程终止、完整 scope 集合与缺失 Markdown。
采用仓库公开生产规模 fixture,固定 466 Todos / 65 leases,对照不可变 8330a974c、候选 legacy、File、SQLite 和隔离 PostgreSQL 16.15。成功 lease 结果一致,三个 provider 最终 head 相同,无关记录未变;canonical create-CAS/current-proof 与历史 replay 改善作为明确语义差异保留。候选 legacy 与旧版本的规范化 observation hash 相同。没有操作活动 Goal 或提交原始日志。
以下行为验证实际执行于 21828688e。最终 ae0f5bdc5 仅同步 main 的独立网站改动;已逐项核对 runtime、测试、依赖均未变,完整 PR diff 字节相同(SHA256 b04012a5c6ae072c870542dfbe4d82b15f94fe72d0050216666e29071de0bcf0)。以下复用不将旧运行重新标记为新运行;最终 head 已重跑真实四臂 replay、质量门和 premerge;CI 以最终 head 的独立结果为准。
本轮实际运行:
- 全量 TS:首次 1941 pass / 12 fail / 0 skip;12 个失败来自未激活环境而使用系统旧 Python。激活 checkout 的 Python 3.13 后,包含全部失败项的两个套件 54/54 pass,无未解决失败;真实 PostgreSQL store/service 已包含在全量执行中。
- 源代码 File/SQLite acquire、maintenance 和 fence caller matrix:30/30 pass。
- 新建 wheel 和 sdist 分别运行 File/SQLite acquire → retry → renew → current proof → release → new execution → complete/readback:各 2/2 pass。
- 两项修复 probe 的 control 与 mutation 均验证;完整 mutation suite:54/54 controls 通过,54/54 故意故障均由断言杀死。
- TypeScript noEmit、Ruff、mypy(22 files)、生成契约一致性及 diff/DCO 检查通过。35 文件 public boundary scan 无错误;两个既有、与本 diff 无关的 registry projection 警告未算作本 PR 缺陷。
canary premerge --from-git-diff --goal-id:19/19 选中检查通过,0 failure/skip/manual hold,精确质量记录有效。- 最终 head 的 CLI 输出预算及 base/head differential 单独复跑通过。CI 首次尝试的 TS 覆盖率、lint、mypy 已通过,但 job 达 15 分钟上限,在最后 CLI 输出检查被取消,连带汇总门禁失败;该次取消保留为失败尝试。
- 最终 GitHub CI:24 项通过、4 项条件跳过;Python Tests run 35256444269 attempt 2 成功,merge-gate 及所有必需检查通过。首次内核超时经定向重跑解决,未改代码、超时或门槛;publish/deploy 在 PR 中不执行,presentation 因相关表面未变而跳过。无未解决失败或必需项跳过。
此前固定 64 对 CLI 计时的 replay p95 为 2059.92 → 2233.97 ms(+8.45% / +174.05 ms),数值门槛失败,owner 已接受本 PR 范围的例外。未重新计时,也未将例外改写为数值通过;全局门槛未改变。canonical acquisition 原来不可用,不宣称速度提升。
我的整体评价
完整 diff 为 35 文件;新增原生领取事务和当前 proof 校验具有实际 caller 与完整 CLI 结果。大段 decision 搬移不等于删除行为;实际简化是 claim/lifecycle 的重复 facts/materialization 收敛。已应用同域、行为可验证的共享 owner;更大 executor 迁移保留在既有边界,不追加空框架。
本轮无未解决阻塞发现。精确质量记录 cqr_00802808248d3470d990 对 35 文件范围有效(fingerprint 00802808248d3470d990c02b0a15a4567e6c70f54297febd9bf4250e9266487b),0 blockers、1 个已接受性能 warning;仅应用一轮有界测试修复。回滚必须保留 canonical state、receipts 与 writer fence,恢复兼容代码,不能复活旧 lease 文件。自合并仅依据本次 owner 明确授权,并仍要求 unchanged-head merge-readiness 通过。
English verdict: APPROVE - ae0f5bdc56a021c25b9886ecce61e685adf97b1c: canonical acquisition/current-proof recovery reaches real CLI completion; full-provider, immutable-baseline, installed-package and mutation evidence is verified. Stale fence mutation oracles are repaired at the retained native entrypoint. Final CI and premerge pass. The previously accepted replay p95 increase remains disclosed as a scoped exception, not a numerical pass.
Performance acceptance: the owner explicitly accepts the measured CLI replay-tail difference for this PR. The earlier failed numerical gate remains disclosed below; global thresholds are unchanged.
Promoted File/SQLite Goals could maintain an existing lease, but standalone
task-lease acquirestill entered the fenced legacy writer. This closes fresh acquisition and takeover through the selected authority, and carries the resulting proof through real CLI Todo completion. Advances #4574 R5 and shared-authority L3; it does not complete L3 or change provider defaults.Behavior and ownership
Initial implementation validation (
4493a26b1)Real read-only source rehearsal: 355 Todos / 10 initial leases, including two isolated synthetic Todos and one synthetic lease; immutable baseline
8330a974c, File, SQLite and real PostgreSQL. Normal operation results and all three final provider heads agree; source and non-target records are unchanged. A deliberate takeover-epoch mutation fails the same public-entrypoint rehearsal (expected 2, observed 1). Source text and raw local evidence remain private.The baseline promoted CLI fails at the legacy fence; the candidate completes acquire → exact retry → renewal → current-proof retry → release → new execution → completion/readback, including absent-display recovery. Fixtures retain independent targets for successful acquisition, existing-lease maintenance and keyless rejection.
Migration economics
execute_native_task_lease_acquire: +15/-3 lines for route/schema/provenance and bypassing shadow finalization; +4 generated schema bindings. No new leaf RPC.8330a974c: acquire p50/p95 1337.00/2433.55 → 1272.07/2213.36 ms; replay 1328.84/2059.92 → 1401.69/2233.97 ms. Replay p95 +8.45% / +174.05 ms exceeds the RFC gate; noisy host timings do not qualify it. The earlier concurrent-load 24-pair run also showed higher replay tails and is retained, not discarded. Cold-start p50/p95: 204.11/210.60 → 205.86/211.05 ms (12 samples). Typed transport p50/p95: 0.372/0.593 → 0.389/0.569 ms (128); the full Python facade including source fingerprint is 7.15/9.09 → 7.88/9.47 ms. Candidate daemon RSS is 105.83 MiB idle / 106.14 MiB after burst. Warm complete adapter acquire/replay p95 (24): legacy baseline 55.19/47.21, candidate legacy 58.03/52.56, File 80.39/40.25, SQLite 37.31/26.11 ms. Each acquire/replay makes exactly one native request. Canonical acquisition had no successful baseline and is not a speedup claim. The owner explicitly accepts these measured results for this PR. This is a scoped acceptance exception, not a numerical pass or a global budget change; the earlier failed assessment and raw samples are retained.Delivery and rollback
CLI acquire/readback/completion changes are verified on real File/SQLite. No settings fields, frontend controls, Lark command or public input options are added; packaged CLI validation covers the shipped entrypoint. This does not claim packaged frontend or cross-agent result-return acceptance. PostgreSQL is exercised through the existing service-owned opening contract on an isolated real server; no credential-bearing CLI or cross-host deployment is introduced.
Executor holder/terminal locks across external effects remain distinct; L2/L4/L5 companions, D2 soak, D3 and new-Goal defaults retain their existing acceptance. Rollback preserves canonical state/receipts/fence and restores compatible code; never revive stale lease files. Bilingual RFC/roadmap checkpoints and the existing operation guide are updated in place.
Review repair and final validation
The final review head integrates current
mainand fixes two stale mutation oracles. Promoted CLI acquire now succeeds through canonical authority, so its former fenced test id cannot be replaced by the new success case. Both probes now exercise the retained nativets-acquire-engagedentrypoint; controls pass and deliberate diagnostic/envelope regressions fail by assertion.The complete 35-file PR diff is byte-identical to reviewed
21828688eafter the final main integration; added main work is confined to independent site/share-bundle surfaces. Actual review validation at21828688e: full TS 1941 pass / 12 old-system-Python environment failures; activating the checkout Python and rerunning both affected suites resolves all 12 (54/54 pass), with no unresolved failures or skips. Source CLI/caller parity: 30/30; fresh wheel and sdist CLI journeys: 2/2 each; full mutation suite: 54/54 controls pass and 54/54 mutants killed. TypeScript noEmit, Ruff, mypy (22 files), generated contracts, DCO/diff hygiene and 35-file public boundary scan pass.Public synthetic replay compares immutable
8330a974c, candidate legacy, File, SQLite and isolated PostgreSQL 16.15 with 466 Todos / 65 leases. Successful lease observations agree; all provider heads agree and non-target records are unchanged. A takeover epoch mutation fails the same public entrypoint. This supplements the earlier source rehearsal with a public fixture.Final head
ae0f5bdc56a021c25b9886ecce61e685adf97b1c: real four-arm replay rerun passed; premerge 19/19 passed, zero failures/skips/manual holds. Exact-scope quality receiptcqr_00802808248d3470d990is valid for fingerprint00802808248d3470d990c02b0a15a4567e6c70f54297febd9bf4250e9266487b(35 files). Final-head GitHub CI: 24 checks passed, 4 conditional skips (PR-only publish/deploy exclusions and unchanged presentation surface). Python Tests run 35256444269 attempt 2 succeeded; all required checks, including merge-gate, passed. Attempt 1 kernel timeout and dependent failures are preserved; targeted rerun resolved them without changing code, timeouts or gates. The final-head CLI output budget/base-head differential also passed a separate local rerun. Old-head run 35254932620 was cancelled after main integration and is not final-head evidence.The prior measured replay-tail regression remains accepted only for this PR; it is not a numerical pass or a global policy change. Self-merge is explicitly authorized for this request and still requires unchanged-head review and merge-readiness.