Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion docs/architecture/rfcs/loopx-overall-roadmap-v0.md
Original file line number Diff line number Diff line change
Expand Up @@ -235,7 +235,7 @@ These priorities do not change live Goal quota or authorize experiments/cloud re

### R5: TS Convergence and Local Persistence

Existing-lease L3 checkpoint: renew/transfer/release share one TS transaction and provider handle; real File/SQLite/PostgreSQL and immutable-legacy comparison cover handover, cleanup and historical replay. [Boundary and remaining callers](../../reference/canonical-lease-renew.md); R5, D2/D3 and new-Goal default qualification remain open.
L3 checkpoint: standalone acquisition/takeover, atomic claim admission and maintenance share typed lease facts/rules and provider opening. Exact acquisition retry verifies current execution proof; real CLI completion can recover missing Markdown display. Full-state scope conflicts, process interruption and File/SQLite/PostgreSQL read-only rehearsal are covered. [Remaining executor and integration boundaries](../../reference/canonical-lease-renew.md); R5, D2/D3 and default qualification remain open.

- **Owner:** TS T0–T4 and shared-authority D1–D3; retain their numbering and gates.
- **Selection:** prioritize an entire hot-path transaction or recovery lifecycle used by R1–R4. Record before/after callers, owners, crossings, actual deletions and performance. Stop adding per-field Python→TS RPCs; do not rebuild the merged Todo update.
Expand Down
2 changes: 1 addition & 1 deletion docs/architecture/rfcs/loopx-overall-roadmap-v0.zh-CN.md
Original file line number Diff line number Diff line change
Expand Up @@ -235,7 +235,7 @@ R2 的一条依赖必须通过真实 LoopX Agent 间的请求/产物交接完成

### R5:TS 收敛与本地持久化

既有 lease 的 L3 检查点:renew/transfer/release 共用 TS 事务和 provider handle;真实 File/SQLite/PostgreSQL 与不可变 legacy 对照覆盖转交、清理和历史 replay。[交付边界与剩余 caller](../../reference/canonical-lease-renew.md);R5、D2/D3 和新 Goal 默认化资格仍未完成。
L3 检查点:独立领取/接管、原子 claim 准入与维护共用 typed lease facts/rules 和 provider opening;原领取重试校验当前执行 proof,真实 CLI 完成可恢复缺失 Markdown 展示。覆盖完整 scope 冲突、进程中断及 File/SQLite/PostgreSQL 只读演练。[剩余 executor 与集成边界](../../reference/canonical-lease-renew.md);R5、D2/D3 和默认化资格仍未完成。

- **Owner:** TS RFC T0–T4、shared-authority D1–D3;保留两套编号及原门禁。
- **选择规则:** 优先迁移 R1–R4 热路径的一笔完整事务或恢复生命周期,附前后 caller/owner/crossing 表、实际删除和性能证据。不要继续按单字段增加 Python→TS RPC;不要重建已合入的 Todo update。
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3039,7 +3039,7 @@ or moving a helper is not by itself a package exit.
| --- | --- | --- |
| A / L1: Monitor configuration (this slice) | Existing `todo update` config enters the TS planner/CAS/receipt; delete Python's duplicate intent field catalog. Separate authoring from observed hashes, times and generations. | Ordinary CLI/API, clear/omission, active lease proof, no-op/replay, failed display delivery, complete fixture and real providers. This does not complete delegated Chat or leased polling. |
| A / L2: Complete public mutation admission | Inventory actual CLI/Turn/Chat callers; close remaining effect-owned user decisions, delegated owner actions and Monitor lifecycle transitions with validated actor/grant facts. | Build on merged T1 owners, not a generic raw patch. Prove permission rejection and exact caller response; remove replaced Python admission and name every remaining unsupported command. |
| A / L3: Canonical lease lifecycle | Existing-lease renew/transfer/release now share one TS transaction, record materializer and provider opening handle; CLI readback and service-factory PostgreSQL are exercised. | Native/imported scale fixtures, real process loss, stale proof, no-op receipts and historical replay pass. [Operation and four-arm rehearsal](../../reference/canonical-lease-renew.md) distinguish preserved legacy outcomes from improved replay. Acquire/reclaim and executor fence adoption remain explicit caller work; D1–D3/default holds remain. |
| A / L3: Canonical lease lifecycle | Standalone acquire/takeover, atomic claim lease admission and maintenance reuse TS facts/decision/materialization and one provider opening fence. Acquire success verifies current execution proof; canonical completion can recover missing display. | Full-head scope conflict, archived/ineffective holders, exact create-CAS retry, stale execution, process loss and real CLI/four-arm rehearsal are covered. [Operation and remaining callers](../../reference/canonical-lease-renew.md). Executor-held external-effect fences remain explicit work; D1–D3/default holds remain. |
| B / L4: Leased Monitor poll and settlement | Compose observation, generation and independent successors with the current lease fence. Reuse the existing quota settlement protocol and exact business receipt. | L2/L3; real polling failure, duplicate/no-change observations, crash between business and quota settlement, and competing writers. Do not pretend separate authorities share a database transaction. |
| B / L5: Consumer and display closure | Reconcile #4316, audit Turn/quota/Dashboard/Chat source reads, and finish D1 freshness/recovery through the existing projection outbox. | CLI, Lark/Chat and packaged frontend read back their affected interactions; absent/stale display, empty canonical state, pending projection and data beyond UI limits. Delete post-promotion legacy fallbacks with each consumer. |
| A–C / L6: Local durability qualification | Continue contributor-owned #4224/#4328 on the selected SQLite profile; reuse File/NoKV references and complete 7.2's ledger. | Capacity, real process/crash/restore/upgrade, retained receipts/scans, consumer lag, supported runtimes/OS and the separately authorized >=10-day synthetic soak. Missing measurements remain holds. |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2409,7 +2409,7 @@ canonical renew 候选,#4328 是 SQLite D2 首批测量/恢复候选;它
| --- | --- | --- |
| A/L1:Monitor 配置(本切片) | 现有 `todo update` 配置进入 TS planner/CAS/receipt,删除 Python 重复 intent 字段表;区分配置与观察 hash、时间、代数。 | 普通 CLI/API、清除/省略、active lease proof、no-op/replay、展示失败恢复、完整 fixture 和真实 provider。不宣称完成委托 Chat 或 leased polling。 |
| A/L2:公共 mutation admission 闭合 | 盘点 CLI/Turn/Chat 实际 caller;以可信 actor/grant 事实闭合剩余 effect-owned 用户决策、委托 owner 动作和 Monitor lifecycle。 | 复用已合并 T1 owner,不开通通用 raw patch;验证权限拒绝和 caller 响应,删除替代的 Python admission,列全未支持命令。 |
| A/L3:canonical lease 生命周期 | 既有 lease 的 renew/transfer/release 已共用 TS 整笔事务、record materializer 与 provider opening handle;覆盖 CLI 回读和 service-factory PostgreSQL。 | native/imported 规模 fixture、真实进程中断、旧 proof、no-op receipt 与历史 replay 已验证。[操作与四臂演练](../../reference/canonical-lease-renew.md) 区分保持的旧结果和改进的 replay。Acquire/reclaim 与 executor fence 接入仍是明确 caller 工作;D1–D3/default hold 保留。 |
| A/L3:canonical lease 生命周期 | 独立 acquire/接管、原子 claim 的 lease 准入及维护复用 TS facts/decision/materializer 与同一 provider opening fence。Acquire 成功必须校验当前执行 proof;canonical 完成可恢复缺失展示。 | 已覆盖完整 head scope 冲突、归档/失效 holder、创建 CAS 原样重试、旧执行、进程中断、真实 CLI 与四臂演练。[操作及剩余 caller](../../reference/canonical-lease-renew.md)。跨外部 effect 的 executor 持锁 fence 仍为明确工作;保留 D1–D3/default hold。 |
| B/L4:leased Monitor poll 与 settlement | 组合观察、变化代数、独立 successor 和现有 lease fence;复用 quota settlement 与精确业务回执。 | L2/L3;真实 polling 失败、重复/无变化、业务提交到 quota settlement 间崩溃和并发。不能假装不同 authority 共享一个数据库事务。 |
| B/L5:consumer 与展示闭合 | 核对 #4316,审计 Turn/quota/Dashboard/Chat 的来源,复用 projection outbox 完成 D1 新鲜度和恢复。 | 验证 CLI、Lark/Chat、打包 frontend 的受影响交互;缺失/陈旧展示、权威空状态、pending 投影及超过 UI 上限的数据。逐个删除晋升后的 legacy fallback。 |
| A–C/L6:本地持久化资格 | 延续 contributor 认领的 #4224/#4328,在选定 SQLite profile 上补齐第 7.2 节 ledger,复用 File/NoKV 对照。 | capacity、真实进程/crash/restore/upgrade、历史 receipt/scan、consumer lag、支持的 runtime/OS,以及另行授权的 >=10 天合成 soak。缺项继续 hold。 |
Expand Down
30 changes: 17 additions & 13 deletions docs/architecture/rfcs/typescript-control-plane-migration-v0.md
Original file line number Diff line number Diff line change
Expand Up @@ -109,19 +109,23 @@ native creation, archival, receipt replay, and store reopen are tested without
Markdown metadata. Python only adapts the typed read result to the compatibility
summary. This is a contract checkpoint, not a completed CLI lifecycle cutover.

### Existing-lease transaction closure (2026-09-17)

Renew, transfer and release now share `coordination/task_lease_lifecycle.ts` and
the existing typed lifecycle decision/record materializer. The Python adapter
routes promoted commands once; the local opening handle owns provider identity,
including service-factory PostgreSQL. Renew-only constructors and duplicated
record materialization are retired; legacy storage remains for its real callers.
Transfer preserves Todo claims/scopes; release accepts expired or deregistered
owners only with matching proof. No-op cleanup seals a receipt; historical
replay cannot reacquire execution authority. Archived renew/transfer and unsafe
generation increments fail closed. See [operation, compatibility and four-arm
rehearsal](../../reference/canonical-lease-renew.md). This closes existing-lease
L3 mutations, not acquisition/reclaim, executor fences, D2/D3 or new-Goal defaults.
### Lease acquisition and lifecycle convergence (2026-09-18)

Standalone acquire/takeover and maintenance now share the local provider/source
fence. `task_lease_acquire_decision.ts` owns acquire admission and materialization;
legacy acquire and canonical atomic Todo claim reuse it. `task_lease_state.ts`
provides full canonical facts, including archived-holder exclusion from scope
conflicts. Python sends registration facts through one native request, without
reconstructing the canonical Todo/lease head. Generation exhaustion fails closed.

An acquire receipt alone is not current execution authority: exact create-CAS
retry recovers the original decision and verifies the current owner/key/epoch;
renewal returns current proof while expiry/release/transfer cannot revive it.
Canonical completion can rebuild missing Markdown display through the existing
outbox. Real CLI, scale/native/imported fixtures, process loss and four-arm
read-only rehearsal cover the boundary. See [operation and compatibility](../../reference/canonical-lease-renew.md).
Executor-held external-effect locks, remaining L2/L4/L5 consumers, D2/D3 and
new-Goal defaults remain separate; this is not full L3 or T4 retirement.

### Local provider opening boundary (2026-09-13)

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -89,16 +89,20 @@ coordination 路径使用同一份语言中立的 `coordination_state_contract_v
仅将 typed read result 适配为兼容 summary。这是 contract 检查点,不是已经完成的
CLI lifecycle cutover。

### 既有 lease 整笔事务闭合(2026-09-17)

renew、transfer、release 共用 `coordination/task_lease_lifecycle.ts` 与既有 typed
lifecycle decision/record materializer。Python 对 promoted 命令只路由一次;local
opening handle 持有 provider 身份,含 service factory 的 PostgreSQL。独立的 renew
构造器与重复记录修改规则已移除,旧存储仅为实际 caller 保留。转交保留 Todo claim
和 scopes;到期或 owner 注销后,释放仍须匹配当前 proof。no-op 清理封存 receipt,
历史 replay 不重新授予执行权;归档后的续租/转交与不安全 generation 递增会拒绝。
见[操作、兼容与四臂演练](../../reference/canonical-lease-renew.md)。本次闭合 L3
既有 lease 修改,不包含 acquire/reclaim、executor fence、D2/D3 或新 Goal 默认化。
### Lease 领取与生命周期收敛(2026-09-18)

独立 acquire/接管和维护共用 local provider/source fence。`task_lease_acquire_decision.ts`
拥有领取准入和 materializer,legacy acquire 与 canonical 原子 Todo claim 复用;
`task_lease_state.ts` 解释完整 canonical facts,归档 holder 不再阻塞 scope。Python
只通过一次 native 请求传注册事实,不重建 canonical Todo/lease head;generation
耗尽明确拒绝。

Acquire receipt 本身不证明当前执行权:创建 CAS 的原样重试恢复原决定,再检查
当前 owner/key/epoch;续约后返回当前 proof,过期/释放/转交不会复活旧执行。
Canonical 完成可经既有 outbox 重建缺失的 Markdown 展示。真实 CLI、规模及
native/imported fixture、进程中断和只读四臂演练覆盖此边界。见[操作与兼容](../../reference/canonical-lease-renew.md)。
跨外部 effect 的 executor 持锁、剩余 L2/L4/L5 caller、D2/D3 和新 Goal 默认化仍
独立验收;本批不是全部 L3 或 T4 retirement。

### Local provider opening 边界(2026-09-13)

Expand Down
Loading
Loading