refactor(todos): unify canonical User completion updates and reviewed recovery - #4699
Conversation
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Reviewed exact head: f695c2561f0e3cab330e3d126f08b35cd4b46d50.
未发现阻断项。整体判断为 justified_increment:完整闭合用户完成更新及其恢复路径;不代表本地默认切换、D2/D3 或旧 Python writer 退出已经完成。
动机
按 #4574 R5、TS T1/T2 与 shared-authority L2 的实际 caller 验收,本 PR 修复一个已在固定主干重现的断点:promoted User todo update --status done 先执行声明验证,随后被旧 Markdown writer fence 拒绝。若只放宽路由、不复用 terminal owner,会分裂完成权限、验证、lease release 和 recovery authority。既有 Chat User completion 还会漏掉 reviewed operation 恢复入口。
改动思路
采用已有 TS terminal 事务作为完成 owner,从 ordinary update 提取真实输入 decoder/materializer;共用已有 public planner、lifecycle decision、completion reducer、CAS/receipt/projection outbox。Python 传递意图、执行声明效果并交回结果;不新增业务规则副本。File/SQLite/NoKV/PostgreSQL 共用同一语义,provider 保留各自持久化边界。
最强反对理由是“一个入口缺口不值得再加一套完成框架”。本 diff 没有新增第二个框架:新增模块承接真实被提取的编辑规则,原 terminal transport 的内联效果/失败处理移至既有 validation owner,供两个入口复用。仍保留的 Python Markdown/event writer 具有未晋升 Goal caller;它们不是这次已退休的代码。这个边界允许独立验证和回滚,后续继续原有 L2/L3/L5、D2/D3 计划。
具体改动
关键代码讲解
normalizeTodoUpdateInput/prepareUpdatedTodo统一字段、clear、authoring 与 materialization。新 v3 envelope 才接受 completion;v0–v2 拒绝该新字段,普通请求 hash 和既有 terminal receipt identity 保留。TodoCompletionEdit只传编辑字段,并在运行时拒绝额外 authority facts,不能把Pick当作运行时裁剪。executeCoordinationTodoTerminalLifecycle分别检查原 Todo 的 complete 权限和候选 Todo 的 update 权限。反例是只有 update 委托的 A 清除 B 的 claim 后尝试完成:必须拒绝,不能从编辑后的无主状态获得权限。关联 successor 的存在性、自环检查提前到外部验证之前;此顺序也适用于原有 complete/supersede。- 完成续提绑定签发的 provider revision,保留 registry witness 并更新 observed time;任何中途 provider commit、登记撤销或过期显式 proof 都不能提交。Todo、release、投影意图和业务回执原子持久化;release 保留 version/epoch。旧回执证明历史成功,不重新授予执行权限。
- 已完成 User Todo 的新备注保留 completed_at,不重跑已退休的私有验证声明。精确 operation replay 返回原回执;修改意图复用同一 ID 会失败。显示恢复读取当前 canonical head,不能写回旧 Markdown 真相。
update_canonical_todo_if_promoted与 terminal adapter 共用execute_completion_validation_effects/completion_validation_failure。Chat preview 保存 canonical basis,apply 沿用 proposal operation ID;验证失败不产生成功 receipt,投影中断/action 回包丢失均恢复原操作。共享 review plan、打包 bundle 和既有浏览器 fixture 一起覆盖 retry 可发现性。Agent complete 保留独立入口。
文档与验证:扩展现有完整 legacy/native 合成图的四 provider conformance,增加真实 CLI、Chat service、HTTP、安装 wheel 和 packaged browser 用例;双语 RFC checkpoint、执行记录、操作/回滚文档和两张合成截图同步。
对主干的风险
语义与 CI 对齐
复用既有 Todo/lease/receipt 词汇,仅扩展 update v3 transport;新的完成 caller 与更早的 successor 拒绝已在双语 RFC、操作文档和回归中披露。schema、actor、source 与 lease 条件都是机器强制准入;未使用文字启发式分类,也未把强制条件称为 guidance。按已解析策略不读取 CI,仓库本地检查与真实后端仍执行。
- 完成/验证边界: 显式披露新 User caller 及更早的 successor 拒绝。原 Todo 权限、过期 proof、同 operation 改意图、并发 revision、登记撤销、dry-run 无效果均有负例;没有新增通用 raw patch 或跨 Goal 权限。
- 来源一致性: registry witness 是乐观检查,不是跨资源事务或 executor-held 外部效果锁。验证命令自身可能产生外部效果;本 PR 保证不把失效依据提交为 canonical completion,未宣称撤销已经运行的命令。
- 兼容/回滚: 未晋升路径保留;旧 wire 与既有终态回执不改名。新 v3 操作的 pending projection 应恢复后再降级,不能通过解除 fence 恢复陈旧 Markdown writer。
- 展示/打包: 改动是既有 recovery availability,无首页/布局/config 新设计。合成 before/after 截图证明旧列表隐藏、新版可重试;真实 HTTP/provider 用例补足浏览器 mock 的边界。
- 验证: 726 个相关 TS/真实 provider 用例零跳过,17 个聚焦完成/wire 用例、206 个相关 Python 用例、18 个最新版 wheel caller 用例通过;TS typecheck、Ruff、配置范围 mypy、文档/边界扫描及 packaged browser 通过。冻结历史全图 rehearsal 保留全部既有 Todo/lease,并核对 baseline ordinary edit 与当前三个 provider 的完整 head。该私有历史输入不公开,不代表活动 Goal 或 soak。
- 性能/资格: 通过安装后的 console-script 所指向的入口,对相同 50-Todo 状态执行各 64 组交错普通编辑:File 基线/候选 p50/p95 为 847/1257 与 764/1252 ms;SQLite 为 583/871 与 588/820 ms。新完成 CLI 各 16 个样本、不含外部验证命令,p95 分别为 1115/1113 ms。8 次冷启动 p50/p95 221/342 ms;128 次暖 ping 0.54/1.42 ms;256 次请求前后 RSS 为 107.16/109.36 MiB。初始 16 样本 direct-module 测量出现较高尾延迟,且仅在候选侧交错了额外完成写入;后续同状态、相同正式入口对照排除了这种干扰。两组观察均保留,不宣称性能提升或 D2 容量/soak 已通过。
- 合并门: 绑定主干
8ea943359后,19/19 selected checks 与 5 项 direct checks 全部通过,无失败、跳过或 manual hold;35 文件精确质量回执cqr_ab6c1a86e4e5590298ff有效,safe-fix 一轮、阻断/警告/建议均为零。初次所有检查通过但因 upstream 移动导致回执 stale,已重新资格化并完整重跑,未豁免门禁。新增主干 DCO 验证 11 项通过。按已解析策略未读取或轮询 CI。未测试真实多 host PostgreSQL 部署、十日 soak 和活动 cohort cutover;这些保留在各自验收边界。
我的整体评价
建议合入这个有界 caller 闭合 PR,保留维护者合并决定。未来重构检查已应用于同一边界:编辑规则独立归属、复用 terminal/receipt/outbox、统一传输处理,未引入未使用的抽象。下一步应按现有 caller/consumer 清单及 D2/D3 证据推进,不能从本 PR 的代码或测试数量推导默认化已就绪。
English verdict: APPROVE - f695c2561f0e3cab330e3d126f08b35cd4b46d50. Canonical User completion updates now reuse the existing typed terminal authority and reviewed Chat recovery, with source/lease/permission counterexamples, real provider and packaged-entrypoint validation. No blocking finding; local-default, soak, cross-host PostgreSQL and legacy-writer retirement remain separate qualification boundaries.
f695c25 to
f6998d0
Compare
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Reviewed exact head: f6998d0cfb85e7e6fa137faac3f43bb71f3f0a11.
未发现阻断项。整体判断为 justified_increment:本 PR 完整闭合 promoted User Todo 的完成更新及 Chat 原操作恢复;它不宣称本地 authority 默认化、D2/D3、十日 soak 或旧 Python writer 退出已经完成。
动机
按 #4574 R5、TypeScript migration T1/T2 与 shared-authority L2 的 caller 验收,固定主干可重现的问题是:todo update --status done 已执行声明的验证命令,却随后被 legacy Markdown writer fence 拒绝。仅放宽路由会让验证副作用与完成状态分离;在 Python 重新实现完成会分裂权限、lease release、receipt 与 recovery 的权威。Chat 的 User completion 同时缺少已提交操作的可发现恢复入口。
修复后的可观察结果是:同一公开 CLI/Python/Chat 操作在 promoted Goal 上进入 canonical terminal 事务,验证失败或 source/lease 漂移不会写入成功 receipt;提交响应或展示投影丢失时,以原 operation id 恢复。未晋升 Goal 与 Agent completion 的既有入口保持不变。
改动思路
复用既有 TypeScript terminal owner,而不是增加第二套完成状态机。ordinary update 中已有的字段归一化与 materialization 被提取为 todo_update_intent.ts,供普通更新与 User completion 共用;terminal owner 仍统一负责原 Todo 权限、候选编辑权限、completion reducer、lease release、CAS、business receipt 与 projection outbox。Python 只负责搬运意图、执行已声明的宿主验证效果并把结果交回 typed resume;File、SQLite、NoKV、PostgreSQL 保留各自存储边界但共享同一语义。
最强反对理由是“为一个入口缺口引入了过多机制”。审查结果不支持该反对:新模块承接的是从既有 hot path 抽出的真实规则,Python terminal adapter 中重复的 effect/failure plumbing 被删除,未增加 provider、scheduler、独立状态或未使用框架。剩余 legacy writer 有未迁移 caller,保留有明确退出条件;当前边界可独立测试、回滚和继续迁移。
具体改动
关键代码讲解
normalizeTodoUpdateInput/prepareUpdatedTodo(todo_update_intent.ts:40/114)集中维护 patch、clear、planning intent、审计字段和 User authoring scope。新 completion payload 仅由 v3 envelope 接受;v0-v2 与普通更新 receipt identity 不变。运行时白名单阻止TodoCompletionEdit携带额外 authority facts。executeCoordinationTodoTerminalLifecycle(todo_terminal_lifecycle.ts:722)先保留原 Todo 作为 complete 权限依据,再对编辑后的候选执行 update admission,避免“仅有 update 委托的 actor 先清 claim 再获得 complete 权限”。验证续提绑定签发的 provider revision,并在 CAS 前重查 registry/source/lease。update_canonical_todo_if_promoted(provider_update.py:34)仅在已有 promotion gate 内构造 v3 completion 请求;收到execute_validation后执行声明效果并以同一 operation 恢复。missing canonical authority 不回退到旧 Markdown。execute_completion_validation_effects/completion_validation_failure(completion_validation.py:732/774)成为两个 terminal caller 共用的宿主效果与失败映射,消除原 adapter 重复实现。- Chat 的 canonical basis 与 apply 路径保留 proposal operation id;打包 bundle 已按源码刷新。变异测试 locator 同步到提取后的
todo_update_intent.ts,因此 CI 不再因旧文件定位漂移而失败。
文档同步披露了新 caller、早于验证发生的 successor 拒绝、恢复顺序、rollback 边界与仍未完成的迁移项;测试覆盖 legacy/native schema、四类 provider、真实 CLI/HTTP、Chat 与 packaged browser。
对主干的风险
语义与 CI 对齐
本次扩展既有 Todo/lease/receipt 词汇,仅增加 update v3 的 completion intent;没有字符串 denylist、产品特定控制面文案或把机器强制条件描述成 guidance。默认开关仍由 local_authority_is_promoted 所有;未晋升路径、普通 v0-v2 update、Agent complete 与既有 terminal receipt identity 保持兼容。
- 权限:原 Todo complete 权限与候选 update 权限分别验证,update-only grant 不能通过清除他人 claim 洗白完成权限。
- 时序:successor 缺失/自环在外部验证前拒绝;provider revision、registry witness、lease version/epoch 任一变化均阻止提交。
- 恢复:历史 receipt 只证明已提交操作,不重新授予执行权限;pending v3 操作应先恢复再降级,不能解除 fence 后回写旧 Markdown。
- 展示:只改变已有 recovery action 的可见性,没有首页、布局或配置设计变化;合成截图和 packaged browser smoke 覆盖原操作重试。
- CI 修复:旧 mutant locator 已指向抽取后的规则 owner;rebase 遗留的重复
sourceChanged()检查已删除并保留 typedAUTHORITY_SOURCE_CHANGED;Chat bundle 已重建。 - 新 exact head 验证:TypeScript typecheck;控制面
2032 passed / 0 failed / 18 conditional skips;22 个聚焦 Python 测试;mypy 22 文件;Ruff;docs governance;全量 deliberate mutants;change-quality receiptcqr_9df029dadecc44161e2d;premerge 10/10 catalog canaries、8/8 risk smokes、公共边界与 diff 检查均通过。重放前的相同六提交 patch 还通过真实隔离 PostgreSQL ladder/store/service169/169 + 169/169 + 10/10(零跳过)和 packaged Personal Workspace browser smoke;git range-diff逐提交证明重放等价。远端 CI 不作为本 review 的判定证据。
残余风险:registry witness 是乐观并发检查,外部验证副作用不能因后续拒绝自动撤销;未覆盖真实多 host PostgreSQL 部署、十日 soak 与活动 cohort cutover。这些属于已记录的后续资格边界,不是当前 caller 闭合的阻断项。
我的整体评价
建议合入该有界 caller 闭合,且保留维护者的最终合并决定。代码复用了既有 terminal/receipt/outbox 与 typed vocabulary;相关 future-facing refactor 已完成为共享 edit intent 和 validation-effect owner,没有发现需要本 PR 再扩张的相邻重构。仓库政策明确禁止作者自合并 loopx/** 控制面行为变更,因此即使 exact-head review、质量回执、premerge 与远端 CI 最终均通过,本 PR 仍应由另一位维护者合并。
English verdict: APPROVE - f6998d0cfb85e7e6fa137faac3f43bb71f3f0a11. Canonical User completion now reuses the typed terminal authority and reviewed Chat recovery. Source, lease, delegation, replay, and validation-failure boundaries are covered with no blocking finding; default rollout, soak, cross-host PostgreSQL, and legacy-writer retirement remain separate. Repository policy requires maintainer merge for this control-plane change.
f6998d0 to
48573ca
Compare
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Reviewed exact head: 48573cabea996c6c9ef2935bbfce5b24a338d117.
未发现阻断项。整体判断为 justified_increment:本 PR 完整闭合 promoted User Todo 的完成更新及 Chat 原操作恢复;它不宣称本地 authority 默认化、D2/D3、十日 soak 或旧 Python writer 退出已经完成。
动机
按 #4574 R5、TypeScript migration T1/T2 与 shared-authority L2 的 caller 验收,固定主干可重现的问题是:todo update --status done 已执行声明的验证命令,却随后被 legacy Markdown writer fence 拒绝。仅放宽路由会让验证副作用与完成状态分离;在 Python 重新实现完成会分裂权限、lease release、receipt 与 recovery 的权威。Chat 的 User completion 同时缺少已提交操作的可发现恢复入口。
修复后的可观察结果是:同一公开 CLI/Python/Chat 操作在 promoted Goal 上进入 canonical terminal 事务,验证失败或 source/lease 漂移不会写入成功 receipt;提交响应或展示投影丢失时,以原 operation id 恢复。未晋升 Goal 与 Agent completion 的既有入口保持不变。
改动思路
复用既有 TypeScript terminal owner,而不是增加第二套完成状态机。ordinary update 中已有的字段归一化与 materialization 被提取为 todo_update_intent.ts,供普通更新与 User completion 共用;terminal owner 仍统一负责原 Todo 权限、候选编辑权限、completion reducer、lease release、CAS、business receipt 与 projection outbox。Python 只负责搬运意图、执行已声明的宿主验证效果并把结果交回 typed resume;File、SQLite、NoKV、PostgreSQL 保留各自存储边界但共享同一语义。
最强反对理由是“为一个入口缺口引入了过多机制”。审查结果不支持该反对:新模块承接的是从既有 hot path 抽出的真实规则,Python terminal adapter 中重复的 effect/failure plumbing 被删除,未增加 provider、scheduler、独立状态或未使用框架。剩余 legacy writer 有未迁移 caller,保留有明确退出条件;当前边界可独立测试、回滚和继续迁移。
具体改动
关键代码讲解
normalizeTodoUpdateInput/prepareUpdatedTodo(todo_update_intent.ts:40/114)集中维护 patch、clear、planning intent、审计字段和 User authoring scope。新 completion payload 仅由 v3 envelope 接受;v0-v2 与普通更新 receipt identity 不变。运行时白名单阻止TodoCompletionEdit携带额外 authority facts。executeCoordinationTodoTerminalLifecycle(todo_terminal_lifecycle.ts:722)先保留原 Todo 作为 complete 权限依据,再对编辑后的候选执行 update admission,避免“仅有 update 委托的 actor 先清 claim 再获得 complete 权限”。验证续提绑定签发的 provider revision,并在 CAS 前重查 registry/source/lease。update_canonical_todo_if_promoted(provider_update.py:34)仅在已有 promotion gate 内构造 v3 completion 请求;收到execute_validation后执行声明效果并以同一 operation 恢复。missing canonical authority 不回退到旧 Markdown。execute_completion_validation_effects/completion_validation_failure(completion_validation.py:732/774)成为两个 terminal caller 共用的宿主效果与失败映射,消除原 adapter 重复实现。- Chat 的 canonical basis 与 apply 路径保留 proposal operation id;打包 bundle 已按源码刷新。变异测试 locator 同步到提取后的
todo_update_intent.ts,因此 CI 不再因旧文件定位漂移而失败。
文档同步披露了新 caller、早于验证发生的 successor 拒绝、恢复顺序、rollback 边界与仍未完成的迁移项;测试覆盖 legacy/native schema、四类 provider、真实 CLI/HTTP、Chat 与 packaged browser。
对主干的风险
语义与 CI 对齐
本次扩展既有 Todo/lease/receipt 词汇,仅增加 update v3 的 completion intent;没有字符串 denylist、产品特定控制面文案或把机器强制条件描述成 guidance。默认开关仍由 local_authority_is_promoted 所有;未晋升路径、普通 v0-v2 update、Agent complete 与既有 terminal receipt identity 保持兼容。
- 权限:原 Todo complete 权限与候选 update 权限分别验证,update-only grant 不能通过清除他人 claim 洗白完成权限。
- 时序:successor 缺失/自环在外部验证前拒绝;provider revision、registry witness、lease version/epoch 任一变化均阻止提交。
- 恢复:历史 receipt 只证明已提交操作,不重新授予执行权限;pending v3 操作应先恢复再降级,不能解除 fence 后回写旧 Markdown。
- 展示:只改变已有 recovery action 的可见性,没有首页、布局或配置设计变化;合成截图和 packaged browser smoke 覆盖原操作重试。
- CI 修复:旧 mutant locator 已指向抽取后的规则 owner;rebase 遗留的重复
sourceChanged()检查已删除并保留 typedAUTHORITY_SOURCE_CHANGED;Chat bundle 已重建。 - 新 exact head 验证:22 个聚焦 Python authority/completion 测试、mypy 22 文件、Ruff、exact-scope quality receipt
cqr_b9ad743e19ef6d55fb6a与 premerge 10/10 catalog canaries、8/8 risk smokes、公共边界和 diff 检查均通过。相同 TypeScript diff 的 typecheck 与全量控制面为2032 passed / 0 failed / 18 conditional skips;重放前的相同产品 patch 还通过全量 deliberate mutants、真实隔离 PostgreSQL ladder/store/service169/169 + 169/169 + 10/10(零跳过)和 packaged Personal Workspace browser smoke;git range-diff逐提交证明重放等价。远端 CI 不作为本 review 的判定证据。
残余风险:registry witness 是乐观并发检查,外部验证副作用不能因后续拒绝自动撤销;未覆盖真实多 host PostgreSQL 部署、十日 soak 与活动 cohort cutover。这些属于已记录的后续资格边界,不是当前 caller 闭合的阻断项。
我的整体评价
建议合入该有界 caller 闭合,且保留维护者的最终合并决定。代码复用了既有 terminal/receipt/outbox 与 typed vocabulary;相关 future-facing refactor 已完成为共享 edit intent 和 validation-effect owner,没有发现需要本 PR 再扩张的相邻重构。仓库政策明确禁止作者自合并 loopx/** 控制面行为变更,因此即使 exact-head review、质量回执、premerge 与远端 CI 最终均通过,本 PR 仍应由另一位维护者合并。
English verdict: APPROVE - 48573cabea996c6c9ef2935bbfce5b24a338d117. Canonical User completion now reuses the typed terminal authority and reviewed Chat recovery while preserving the established HTTP 400/failed-proposal behavior when validation invalidates its authority source. Source, lease, delegation, replay, and validation-failure boundaries are covered with no blocking finding; default rollout, soak, cross-host PostgreSQL, and legacy-writer retirement remain separate. Repository policy requires maintainer merge for this control-plane change.
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Reviewed exact head: 48573cabea996c6c9ef2935bbfce5b24a338d117.
未发现阻断项。整体判断为 justified_increment:本 PR 完整闭合 promoted User Todo 的完成更新及 Chat 原操作恢复;它不宣称本地 authority 默认化、D2/D3、十日 soak 或旧 Python writer 退出已经完成。
动机
按 #4574 R5、TypeScript migration T1/T2 与 shared-authority L2 的 caller 验收,固定主干可重现的问题是:todo update --status done 已执行声明的验证命令,却随后被 legacy Markdown writer fence 拒绝。仅放宽路由会让验证副作用与完成状态分离;在 Python 重新实现完成会分裂权限、lease release、receipt 与 recovery 的权威。Chat 的 User completion 同时缺少已提交操作的可发现恢复入口。
修复后的可观察结果是:同一公开 CLI/Python/Chat 操作在 promoted Goal 上进入 canonical terminal 事务,验证失败或 source/lease 漂移不会写入成功 receipt;提交响应或展示投影丢失时,以原 operation id 恢复。未晋升 Goal 与 Agent completion 的既有入口保持不变。
改动思路
复用既有 TypeScript terminal owner,而不是增加第二套完成状态机。ordinary update 中已有的字段归一化与 materialization 被提取为 todo_update_intent.ts,供普通更新与 User completion 共用;terminal owner 仍统一负责原 Todo 权限、候选编辑权限、completion reducer、lease release、CAS、business receipt 与 projection outbox。Python 只负责搬运意图、执行已声明的宿主验证效果并把结果交回 typed resume;File、SQLite、NoKV、PostgreSQL 保留各自存储边界但共享同一语义。
最强反对理由是“为一个入口缺口引入了过多机制”。审查结果不支持该反对:新模块承接的是从既有 hot path 抽出的真实规则,Python terminal adapter 中重复的 effect/failure plumbing 被删除,未增加 provider、scheduler、独立状态或未使用框架。剩余 legacy writer 有未迁移 caller,保留有明确退出条件;当前边界可独立测试、回滚和继续迁移。
具体改动
关键代码讲解
normalizeTodoUpdateInput/prepareUpdatedTodo(todo_update_intent.ts:40/114)集中维护 patch、clear、planning intent、审计字段和 User authoring scope。新 completion payload 仅由 v3 envelope 接受;v0-v2 与普通更新 receipt identity 不变。运行时白名单阻止TodoCompletionEdit携带额外 authority facts。executeCoordinationTodoTerminalLifecycle(todo_terminal_lifecycle.ts:722)先保留原 Todo 作为 complete 权限依据,再对编辑后的候选执行 update admission,避免“仅有 update 委托的 actor 先清 claim 再获得 complete 权限”。验证续提绑定签发的 provider revision,并在 CAS 前重查 registry/source/lease。update_canonical_todo_if_promoted(provider_update.py:34)仅在已有 promotion gate 内构造 v3 completion 请求;收到execute_validation后执行声明效果并以同一 operation 恢复。missing canonical authority 不回退到旧 Markdown。execute_completion_validation_effects/completion_validation_failure(completion_validation.py:732/774)成为两个 terminal caller 共用的宿主效果与失败映射,消除原 adapter 重复实现。- Chat 的 canonical basis 与 apply 路径保留 proposal operation id;打包 bundle 已按源码刷新。变异测试 locator 同步到提取后的
todo_update_intent.ts,因此 CI 不再因旧文件定位漂移而失败。
文档同步披露了新 caller、早于验证发生的 successor 拒绝、恢复顺序、rollback 边界与仍未完成的迁移项;测试覆盖 legacy/native schema、四类 provider、真实 CLI/HTTP、Chat 与 packaged browser。
对主干的风险
语义与 CI 对齐
本次扩展既有 Todo/lease/receipt 词汇,仅增加 update v3 的 completion intent;没有字符串 denylist、产品特定控制面文案或把机器强制条件描述成 guidance。默认开关仍由 local_authority_is_promoted 所有;未晋升路径、普通 v0-v2 update、Agent complete 与既有 terminal receipt identity 保持兼容。
- 权限:原 Todo complete 权限与候选 update 权限分别验证,update-only grant 不能通过清除他人 claim 洗白完成权限。
- 时序:successor 缺失/自环在外部验证前拒绝;provider revision、registry witness、lease version/epoch 任一变化均阻止提交。
- 恢复:历史 receipt 只证明已提交操作,不重新授予执行权限;pending v3 操作应先恢复再降级,不能解除 fence 后回写旧 Markdown。
- 展示:只改变已有 recovery action 的可见性,没有首页、布局或配置设计变化;合成截图和 packaged browser smoke 覆盖原操作重试。
- CI 修复:旧 mutant locator 已指向抽取后的规则 owner;rebase 遗留的重复
sourceChanged()检查已删除并保留 typedAUTHORITY_SOURCE_CHANGED;Chat bundle 已重建。 - 新 exact head 验证:22 个聚焦 Python authority/completion 测试、mypy 22 文件、Ruff、exact-scope quality receipt
cqr_b9ad743e19ef6d55fb6a与 premerge 10/10 catalog canaries、8/8 risk smokes、公共边界和 diff 检查均通过。相同 TypeScript diff 的 typecheck 与全量控制面为2032 passed / 0 failed / 18 conditional skips;重放前的相同产品 patch 还通过全量 deliberate mutants、真实隔离 PostgreSQL ladder/store/service169/169 + 169/169 + 10/10(零跳过)和 packaged Personal Workspace browser smoke;git range-diff逐提交证明重放等价。远端 CI 不作为本 review 的判定证据。
残余风险:registry witness 是乐观并发检查,外部验证副作用不能因后续拒绝自动撤销;未覆盖真实多 host PostgreSQL 部署、十日 soak 与活动 cohort cutover。这些属于已记录的后续资格边界,不是当前 caller 闭合的阻断项。
我的整体评价
建议合入该有界 caller 闭合,且保留维护者的最终合并决定。代码复用了既有 terminal/receipt/outbox 与 typed vocabulary;相关 future-facing refactor 已完成为共享 edit intent 和 validation-effect owner,没有发现需要本 PR 再扩张的相邻重构。仓库政策明确禁止作者自合并 loopx/** 控制面行为变更,因此即使 exact-head review、质量回执、premerge 与远端 CI 最终均通过,本 PR 仍应由另一位维护者合并。
English verdict: APPROVE - 48573cabea996c6c9ef2935bbfce5b24a338d117. Canonical User completion now reuses the typed terminal authority and reviewed Chat recovery while preserving the established HTTP 400/failed-proposal behavior when validation invalidates its authority source. Source, lease, delegation, replay, and validation-failure boundaries are covered with no blocking finding; default rollout, soak, cross-host PostgreSQL, and legacy-writer retirement remain separate. Repository policy requires maintainer merge for this control-plane change.
…hority Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
…providers Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
48573ca to
2058d38
Compare
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Reviewed exact head: 2058d381672e053f53fb193e5de637771aa5e2e1.
未发现阻断项。整体判断为 justified_increment:本 PR 完整闭合 promoted User Todo 的完成更新及 Chat 原操作恢复;它不宣称本地 authority 默认化、D2/D3、十日 soak 或旧 Python writer 退出已经完成。
动机
按 #4574 R5、TypeScript migration T1/T2 与 shared-authority L2 的 caller 验收,固定主干可重现的问题是:todo update --status done 已执行声明的验证命令,却随后被 legacy Markdown writer fence 拒绝。仅放宽路由会让验证副作用与完成状态分离;在 Python 重新实现完成会分裂权限、lease release、receipt 与 recovery 的权威。Chat 的 User completion 同时缺少已提交操作的可发现恢复入口。
修复后的可观察结果是:同一公开 CLI/Python/Chat 操作在 promoted Goal 上进入 canonical terminal 事务,验证失败或 source/lease 漂移不会写入成功 receipt;提交响应或展示投影丢失时,以原 operation id 恢复。未晋升 Goal 与 Agent completion 的既有入口保持不变。
改动思路
复用既有 TypeScript terminal owner,而不是增加第二套完成状态机。ordinary update 中已有的字段归一化与 materialization 被提取为 todo_update_intent.ts,供普通更新与 User completion 共用;terminal owner 仍统一负责原 Todo 权限、候选编辑权限、completion reducer、lease release、CAS、business receipt 与 projection outbox。Python 只负责搬运意图、执行已声明的宿主验证效果并把结果交回 typed resume;File、SQLite、NoKV、PostgreSQL 保留各自存储边界但共享同一语义。
最强反对理由是“为一个入口缺口引入了过多机制”。审查结果不支持该反对:新模块承接的是从既有 hot path 抽出的真实规则,Python terminal adapter 中重复的 effect/failure plumbing 被删除,未增加 provider、scheduler、独立状态或未使用框架。剩余 legacy writer 有未迁移 caller,保留有明确退出条件;当前边界可独立测试、回滚和继续迁移。
具体改动
关键代码讲解
normalizeTodoUpdateInput/prepareUpdatedTodo(todo_update_intent.ts:40/114)集中维护 patch、clear、planning intent、审计字段和 User authoring scope。新 completion payload 仅由 v3 envelope 接受;v0-v2 与普通更新 receipt identity 不变。运行时白名单阻止TodoCompletionEdit携带额外 authority facts。executeCoordinationTodoTerminalLifecycle(todo_terminal_lifecycle.ts:722)先保留原 Todo 作为 complete 权限依据,再对编辑后的候选执行 update admission,避免“仅有 update 委托的 actor 先清 claim 再获得 complete 权限”。验证续提绑定签发的 provider revision,并在 CAS 前重查 registry/source/lease。update_canonical_todo_if_promoted(provider_update.py:34)仅在已有 promotion gate 内构造 v3 completion 请求;收到execute_validation后执行声明效果并以同一 operation 恢复。missing canonical authority 不回退到旧 Markdown。execute_completion_validation_effects/completion_validation_failure(completion_validation.py:732/774)成为两个 terminal caller 共用的宿主效果与失败映射,消除原 adapter 重复实现。- Chat 的 canonical basis 与 apply 路径保留 proposal operation id;打包 bundle 已按源码刷新。变异测试 locator 同步到提取后的
todo_update_intent.ts,因此 CI 不再因旧文件定位漂移而失败。
文档同步披露了新 caller、早于验证发生的 successor 拒绝、恢复顺序、rollback 边界与仍未完成的迁移项;测试覆盖 legacy/native schema、四类 provider、真实 CLI/HTTP、Chat 与 packaged browser。
对主干的风险
语义与 CI 对齐
本次扩展既有 Todo/lease/receipt 词汇,仅增加 update v3 的 completion intent;没有字符串 denylist、产品特定控制面文案或把机器强制条件描述成 guidance。默认开关仍由 local_authority_is_promoted 所有;未晋升路径、普通 v0-v2 update、Agent complete 与既有 terminal receipt identity 保持兼容。
- 权限:原 Todo complete 权限与候选 update 权限分别验证,update-only grant 不能通过清除他人 claim 洗白完成权限。
- 时序:successor 缺失/自环在外部验证前拒绝;provider revision、registry witness、lease version/epoch 任一变化均阻止提交。
- 恢复:历史 receipt 只证明已提交操作,不重新授予执行权限;pending v3 操作应先恢复再降级,不能解除 fence 后回写旧 Markdown。
- 展示:只改变已有 recovery action 的可见性,没有首页、布局或配置设计变化;合成截图和 packaged browser smoke 覆盖原操作重试。
- CI 修复:旧 mutant locator 已指向抽取后的规则 owner;rebase 遗留的重复
sourceChanged()检查已删除并保留 typedAUTHORITY_SOURCE_CHANGED;Chat bundle 已重建。 - 新 exact head 验证:exact-scope quality receipt
cqr_498c49e213d317641bce与 premerge 10/10 catalog canaries、8/8 risk smokes、公共边界和 diff 检查均通过。git range-diff证明 7/7 提交与已验证 head 逐个等价;相同产品 patch 通过 22 个聚焦 Python authority/completion 测试、mypy 22 文件、Ruff、TypeScript typecheck、全量控制面2032 passed / 0 failed / 18 conditional skips、全量 deliberate mutants、真实隔离 PostgreSQL ladder/store/service169/169 + 169/169 + 10/10(零跳过)和 packaged Personal Workspace browser smoke。远端 CI 不作为本 review 的判定证据。
残余风险:registry witness 是乐观并发检查,外部验证副作用不能因后续拒绝自动撤销;未覆盖真实多 host PostgreSQL 部署、十日 soak 与活动 cohort cutover。这些属于已记录的后续资格边界,不是当前 caller 闭合的阻断项。
我的整体评价
建议合入该有界 caller 闭合,且保留维护者的最终合并决定。代码复用了既有 terminal/receipt/outbox 与 typed vocabulary;相关 future-facing refactor 已完成为共享 edit intent 和 validation-effect owner,没有发现需要本 PR 再扩张的相邻重构。仓库政策明确禁止作者自合并 loopx/** 控制面行为变更,因此即使 exact-head review、质量回执、premerge 与远端 CI 最终均通过,本 PR 仍应由另一位维护者合并。
English verdict: APPROVE - 2058d381672e053f53fb193e5de637771aa5e2e1. Canonical User completion now reuses the typed terminal authority and reviewed Chat recovery while preserving the established HTTP 400/failed-proposal behavior when validation invalidates its authority source. Source, lease, delegation, replay, and validation-failure boundaries are covered with no blocking finding; default rollout, soak, cross-host PostgreSQL, and legacy-writer retirement remain separate. Repository policy requires maintainer merge for this control-plane change.
Goal And Delivered Outcome
Related to #4574 (R5), TS migration T1/T2 and shared-authority local-default L2; base:
main.On fixed main
0d90d6f66, a promoted Usertodo update --status doneexecutes its declared validation command, then fails the legacy writer fence on both File and SQLite. This PR routes that existing caller through the canonical TS edit/terminal transaction, including combined edits, original and candidate authority, source-bound validation, exact lease release, business receipt and projection recovery. Chat User completion uses the same reviewed basis and operation identity; failed validation cannot produce an applied proposal.Scope And Continuation
The complete User completion-update journey is delivered: CLI/Python → TS admission/effect/resume/CAS → canonical readback/display → Chat original-operation retry. Ordinary update decoding/materialization and Python validation-effect/failure plumbing are shared rather than duplicated. Agent completion retains its dedicated command.
Intentional semantic changes: linked successor existence/self-cycle checks precede validation effects, including existing complete/supersede; User completion resume rejects any intervening provider revision, registry drift or expired explicit lease proof; update-only delegation cannot clear ownership to gain completion permission. A completed User Todo accepts new annotations without rerunning its retired private validation declaration or changing completion time. Ordinary v0–v2 updates and existing terminal receipt identities remain compatible; the new completion envelope requires v3.
This is an independently testable and reversible L2 increment. Remaining caller/event/Monitor inventory, executor-held external-effect fencing, D1 consumer recovery, SQLite D2 capacity/elapsed soak and D3 whole-Goal qualification retain their existing roadmap owners. New-Goal defaults and existing-Goal cohort migration remain separate changes. The already merged #4315 repair is reconciled in L7. No default selector or active Goal is promoted, and the still-used legacy Python writer, permanent rendering and import/export paths remain.
Validation
personal-workspace-browser-smoke.mjs,typed-actionsscenario; original proposal ID retained for both edit and complete retries. Shared action-review tests/smoke and packaged build pass.On the installed console-script entrypoint with matching 50-Todo states, 64 interleaved ordinary-edit pairs per provider report File baseline/candidate p50/p95 847/1257 vs 764/1252 ms and SQLite 583/871 vs 588/820 ms. New completion CLI p95 is 1115 ms (File) and 1113 ms (SQLite), 16 samples each, without an external validation command. Eight cold starts p50/p95 221/342 ms; 128 warm pings 0.54/1.42 ms; daemon RSS 107.16 to 109.36 MiB across 256 requests. These are bounded local measurements, not D2 capacity/soak evidence. The initial 16-sample direct-module run showed higher tails; it interleaved additional completion writes only on the candidate, so the matched-state console-entrypoint confirmation above is the acceptance comparison. Both observations are retained privately; no speedup claim is made.
Coverage limits: PostgreSQL proves the provider/service contract against a disposable real server, not authenticated multi-host deployment. Registry witnessing remains optimistic, not an executor-held or cross-resource authorization lock. Browser transport fixtures and real HTTP/provider tests are complementary. No CI fetch/poll was performed under the resolved review policy; no soak/default/cohort promotion is claimed. Initial local fixture/document-index setup failures were repaired and their relevant checks rerun.
Frontend / Visual Evidence
UI impact: changed recovery availability only; existing layout, action and configuration owners are retained. The same synthetic pending completion is hidden before and has an original-operation retry after. Desktop viewport: 1512 × 982; after image crops the open drawer. No mobile/responsive styling changed.
Before · After
Shared-authority RFC fixture impact
Uses the existing
productionScaleCoordinationFixturelegacy/native complete graphs; adds leased User completion, stale/expired proof, authority laundering, wrong role/class, invalid successors, changed source revision, immutable replay and post-completion annotation. Conformance arms: File, SQLite, NoKV and isolated PostgreSQL. The frozen baseline/File/SQLite/PostgreSQL rehearsal is described above; no private snapshot is committed.Boundary Checklist
Type: bug fix, cohesive refactor, documentation and regression coverage. Area: control plane, shared authority, packaged presentation.