Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -2949,8 +2949,9 @@ outbox renderer: display failure is pending, not rollback or successor recreatio
Quota consumes the same v0 business receipt for its separate settlement.
Validation covers the real CLI with missing display, operation replay after a
renderer failure, and complex-data concurrency/lost-acknowledgement recovery on
File, NoKV and isolated real PostgreSQL. Retained Monitor leases and cross-owner
successor claims remain explicitly unsupported. This slice changes neither the
File, NoKV and isolated real PostgreSQL. The L4 extension below closes retained
Monitor lease proof and crash-safe settlement; cross-owner successor claims
remain explicitly unsupported. This slice changes neither the
provider default, writer fence nor promotion approval, and does not replace the
independent legacy three-arm comparison or D2 soak.

Expand Down Expand Up @@ -3040,7 +3041,7 @@ or moving a helper is not by itself a package exit.
| A / L1: Monitor configuration (this slice) | Existing `todo update` config enters the TS planner/CAS/receipt; delete Python's duplicate intent field catalog. Separate authoring from observed hashes, times and generations. | Ordinary CLI/API, clear/omission, active lease proof, no-op/replay, failed display delivery, complete fixture and real providers. This does not complete delegated Chat or leased polling. |
| A / L2: Complete public mutation admission | Inventory actual CLI/Turn/Chat callers; close remaining effect-owned user decisions, delegated owner actions and Monitor lifecycle transitions with validated actor/grant facts. | Build on merged T1 owners, not a generic raw patch. Prove permission rejection and exact caller response; remove replaced Python admission and name every remaining unsupported command. |
| A / L3: Canonical lease lifecycle | Standalone acquire/takeover, atomic claim lease admission and maintenance reuse TS facts/decision/materialization and one provider opening fence. Acquire success verifies current execution proof; canonical completion can recover missing display. | Full-head scope conflict, archived/ineffective holders, exact create-CAS retry, stale execution, process loss and real CLI/four-arm rehearsal are covered. [Operation and remaining callers](../../reference/canonical-lease-renew.md). Executor-held external-effect fences remain explicit work; D1–D3/default holds remain. |
| B / L4: Leased Monitor poll and settlement | Compose observation, generation and independent successors with the current lease fence. Reuse the existing quota settlement protocol and exact business receipt. | L2/L3; real polling failure, duplicate/no-change observations, crash between business and quota settlement, and competing writers. Do not pretend separate authorities share a database transaction. |
| B / L4: Leased Monitor poll and settlement | Current execution proof now binds CLI intent, observation/generation/independent-successor CAS and historical business receipt. Quota pending admission is frozen before the business write; recovery preserves that decision after lease retirement. | Existing L3 lease lifecycle, real File/SQLite/PostgreSQL, mixed fixtures, process death between business/quota commits, competing renewal and unchanged polling. [Operation and snapshot rehearsal](../../reference/protocols/quota-monitor-observation-receipt-v0.md). No lease lifecycle effects or quota spend; separate authorities stay separate. Event callers, wider L2 admission and D1–D3/default remain open. |
| B / L5: Consumer and display closure | Reconcile #4316, audit Turn/quota/Dashboard/Chat source reads, and finish D1 freshness/recovery through the existing projection outbox. | CLI, Lark/Chat and packaged frontend read back their affected interactions; absent/stale display, empty canonical state, pending projection and data beyond UI limits. Delete post-promotion legacy fallbacks with each consumer. |
| A–C / L6: Local durability qualification | Continue contributor-owned #4224/#4328 on the selected SQLite profile; reuse File/NoKV references and complete 7.2's ledger. | Capacity, real process/crash/restore/upgrade, retained receipts/scans, consumer lag, supported runtimes/OS and the separately authorized >=10-day synthetic soak. Missing measurements remain holds. |
| A–C / L7: Capture continuity | Resolve #4315 with source-correlated archive retirement and identical lease membership at bootstrap and later writers; activate its row/mutant and complete the mixed-writer/event-source matrix. | Real CLI/File capture, history retained, partial drain unqualified, crash/replay and a new lease after archive/rebootstrap. Keep the legacy migration window provable; T4 cannot be used to skip this row. |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2340,7 +2340,8 @@ route planner 本身仍不授予权限。CLI 将已提交回执交给既有 jour
展示失败标为 pending,不回滚提交、不重新生成后继;quota 继续消费同一 v0 业务回执
完成独立记账。验证覆盖真实 CLI 的缺失 display、renderer 失败后的 operation 重放,
及 File/NoKV/真实隔离 PostgreSQL 的复杂数据、并发和丢回执恢复。
带 lease Monitor、跨 owner claim 等未闭合能力仍明确拒绝;此切片不改变 provider
下述 L4 扩展闭合了 Monitor lease proof 与崩溃后结算;跨 owner claim 仍明确拒绝。
此切片不改变 provider
默认、writer fence 或 promotion 审批,也不替代三臂 legacy 对照及 D2 soak。

- 从 `loopx/control_plane/todos/provider_projection.py`、既有 Todo-section renderer、
Expand Down Expand Up @@ -2410,7 +2411,7 @@ canonical renew 候选,#4328 是 SQLite D2 首批测量/恢复候选;它
| A/L1:Monitor 配置(本切片) | 现有 `todo update` 配置进入 TS planner/CAS/receipt,删除 Python 重复 intent 字段表;区分配置与观察 hash、时间、代数。 | 普通 CLI/API、清除/省略、active lease proof、no-op/replay、展示失败恢复、完整 fixture 和真实 provider。不宣称完成委托 Chat 或 leased polling。 |
| A/L2:公共 mutation admission 闭合 | 盘点 CLI/Turn/Chat 实际 caller;以可信 actor/grant 事实闭合剩余 effect-owned 用户决策、委托 owner 动作和 Monitor lifecycle。 | 复用已合并 T1 owner,不开通通用 raw patch;验证权限拒绝和 caller 响应,删除替代的 Python admission,列全未支持命令。 |
| A/L3:canonical lease 生命周期 | 独立 acquire/接管、原子 claim 的 lease 准入及维护复用 TS facts/decision/materializer 与同一 provider opening fence。Acquire 成功必须校验当前执行 proof;canonical 完成可恢复缺失展示。 | 已覆盖完整 head scope 冲突、归档/失效 holder、创建 CAS 原样重试、旧执行、进程中断、真实 CLI 与四臂演练。[操作及剩余 caller](../../reference/canonical-lease-renew.md)。跨外部 effect 的 executor 持锁 fence 仍为明确工作;保留 D1–D3/default hold。 |
| B/L4:leased Monitor poll 与 settlement | 组合观察、变化代数、独立 successor 和现有 lease fence;复用 quota settlement 与精确业务回执。 | L2/L3;真实 polling 失败、重复/无变化、业务提交到 quota settlement 间崩溃和并发。不能假装不同 authority 共享一个数据库事务。 |
| B/L4:leased Monitor poll 与 settlement | 当前 execution proof 贯穿 CLI intent、观察/generation/独立 successor CAS 和历史业务回执;业务写入前冻结 quota 准入,租约结束后仍按原决策恢复结算。 | 既有 L3 lease lifecycle、真实 File/SQLite/PostgreSQL、混合 fixture、业务与 quota 间真实进程退出、并发 renewal 和 unchanged poll;见[操作与快照演练](../../reference/protocols/quota-monitor-observation-receipt-v0.md)。不操作 lease lifecycle、不消耗 quota,不把两个 authority 假装成同一事务。Event caller、更广 L2 准入及 D1–D3/default 仍开放。 |
| B/L5:consumer 与展示闭合 | 核对 #4316,审计 Turn/quota/Dashboard/Chat 的来源,复用 projection outbox 完成 D1 新鲜度和恢复。 | 验证 CLI、Lark/Chat、打包 frontend 的受影响交互;缺失/陈旧展示、权威空状态、pending 投影及超过 UI 上限的数据。逐个删除晋升后的 legacy fallback。 |
| A–C/L6:本地持久化资格 | 延续 contributor 认领的 #4224/#4328,在选定 SQLite profile 上补齐第 7.2 节 ledger,复用 File/NoKV 对照。 | capacity、真实进程/crash/restore/upgrade、历史 receipt/scan、consumer lag、支持的 runtime/OS,以及另行授权的 >=10 天合成 soak。缺项继续 hold。 |
| A–C/L7:capture 连续性 | 修复 #4315:归档的源事务明确退休 lease 引用,bootstrap 与后续 writer 使用一致成员范围;执行 row/mutant 和 mixed-writer/event-source 矩阵。 | 真实 CLI/File capture、保留历史、半完成 drain 不合格、crash/replay,以及归档/rebootstrap 后再申请 lease。不能借 T4 跳过迁移窗口证明。 |
Expand Down
31 changes: 23 additions & 8 deletions docs/architecture/rfcs/typescript-control-plane-migration-v0.md
Original file line number Diff line number Diff line change
Expand Up @@ -675,14 +675,29 @@ Retrying the original operation recovers the original successors instead of
creating new work. A fresh observation with no successor remains valid. User
gates use the existing actor-bound scope, never an inferred global gate.

Boundaries still open: any retained Monitor lease fails closed in this native
operation; cross-owner successor claims are not implicitly authorized. Unpromoted
Goals retain their legacy writer. Quota accounting stays in its existing
preflight/writeback/settlement protocol and reuses the v0 receipt shape and raw
observation identity. Canonical commit success is independent of pending Markdown
delivery. This does not finish all T2 commands or authorize whole-Goal promotion.

- Finish the retained lease and event callers of `monitor_poll_writeback.py`.
The leased Monitor path now reuses the current nonterminal lease fence with
Todo metadata updates. Public `quota monitor-poll` carries the execution key and
version through its pending plan, canonical transaction and business receipt.
Observation, generation and independent successors share one CAS; the lease is
unchanged. Canonical due monitors are selectable again, but scheduling does not
grant mutation authority. Runtime time, not the supplied observation timestamp,
determines whether a fresh write's lease is active.

Quota preflight now freezes its admitted decision in a versioned pending receipt.
Recovery settles the original business receipt even after the Monitor becomes
not due or its lease is released; it never substitutes a new lease or re-runs
business effects. Proof-less v0 request identities and completed receipts remain
compatible. Old pending receipts without an admission basis retain current-state
admission and explicitly report when historical recovery cannot be proven.
See [Monitor observation and recovery](../../reference/protocols/quota-monitor-observation-receipt-v0.md).

Boundaries still open: cross-owner successor claims are not implicitly authorized;
unpromoted Goals retain their legacy writer and reject explicit lease proof.
Quota and business authority remain separate recoverable transactions. Canonical
commit success is independent of pending Markdown delivery. This does not finish
all T2 commands or authorize whole-Goal promotion.

- Finish the retained event callers of `monitor_poll_writeback.py`.
Reuse existing monitor generation, independent-successor and settlement
owners. Compose one transaction rather than adding a second monitor engine.
- Preserve unchanged polling/reschedule behavior, generation fences,
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -529,13 +529,22 @@ generation,不能对相同证据重复声明 `material_change=true` 就继续
原 operation 重试恢复原后继,不创建新工作;不附带后继的新 observation 仍可接受。
User gate 复用既有 actor-bound scope,不推导全局 gate。

尚未闭合:原生操作遇到任何保留的 Monitor lease 仍 fail closed,不隐式授权跨 owner
的 successor claim;未 promotion Goal 仍走旧 writer。Quota 记账继续使用现有
preflight/writeback/settlement 协议,沿用 v0 回执形状及原始 observation identity。
Canonical 提交成功独立于 Markdown delivery pending。这不代表全部 T2 命令或整 Goal
promotion 已完成。

- 继续闭合 `monitor_poll_writeback.py` 保留的 lease 与 event caller,复用 monitor
带 lease Monitor 现与 Todo metadata update 共用当前非终结 lease fence。公开
`quota monitor-poll` 将 execution key/version 贯穿 pending plan、canonical transaction
和业务回执;观察、generation 与独立后继在同一 CAS 提交,lease 保持不变。
Canonical 到期 Monitor 恢复可选,但调度不授予写权限;租约是否有效取 runtime
当前时间,不取调用方提交的观察时间。

Quota preflight 将原始准入决策冻结到版本化 pending receipt;即使 Monitor 已不再
到期或 lease 已释放,恢复仍可凭原业务回执结算,不替换租约、不重做业务。
无 proof 的 v0 request identity 和已完成回执保持兼容;无原准入依据的旧 pending
沿用当前准入,无法证明历史恢复时明确报错。见[观察与恢复协议](../../reference/protocols/quota-monitor-observation-receipt-v0.md)。

尚未闭合:不隐式授权跨 owner successor claim;未晋升 Goal 保留旧 writer,并拒绝
显式 lease proof。业务与 quota 仍是分别可恢复的事务,canonical 成功独立于 Markdown
delivery pending;这不代表全部 T2 命令或整 Goal promotion 已完成。

- 继续闭合 `monitor_poll_writeback.py` 保留的 event caller,复用 monitor
generation、独立 successor 和 settlement owner,组成一笔事务,不建第二套引擎。
- 保持 unchanged poll/reschedule、generation fence、material-change successor
去重和可归属 settlement。Monitor 不是 delivery 执行任务;独立 advancement Todo
Expand Down
Loading
Loading