Skip to content

refactor(todos): unify canonical User completion updates and reviewed recovery - #4699

Merged
huangruiteng merged 7 commits into
mainfrom
codex/canonical-local-lifecycle-20260918
Sep 18, 2026
Merged

huangruiteng merged 7 commits into
mainfrom
codex/canonical-local-lifecycle-20260918

Conversation

@huangruiteng

@huangruiteng huangruiteng commented Sep 18, 2026 •

Copy link
Copy Markdown
Collaborator

Goal And Delivered Outcome

Related to #4574 (R5), TS migration T1/T2 and shared-authority local-default L2; base: main.

On fixed main 0d90d6f66, a promoted User todo update --status done executes its declared validation command, then fails the legacy writer fence on both File and SQLite. This PR routes that existing caller through the canonical TS edit/terminal transaction, including combined edits, original and candidate authority, source-bound validation, exact lease release, business receipt and projection recovery. Chat User completion uses the same reviewed basis and operation identity; failed validation cannot produce an applied proposal.

Scope And Continuation

The complete User completion-update journey is delivered: CLI/Python → TS admission/effect/resume/CAS → canonical readback/display → Chat original-operation retry. Ordinary update decoding/materialization and Python validation-effect/failure plumbing are shared rather than duplicated. Agent completion retains its dedicated command.

Intentional semantic changes: linked successor existence/self-cycle checks precede validation effects, including existing complete/supersede; User completion resume rejects any intervening provider revision, registry drift or expired explicit lease proof; update-only delegation cannot clear ownership to gain completion permission. A completed User Todo accepts new annotations without rerunning its retired private validation declaration or changing completion time. Ordinary v0–v2 updates and existing terminal receipt identities remain compatible; the new completion envelope requires v3.

This is an independently testable and reversible L2 increment. Remaining caller/event/Monitor inventory, executor-held external-effect fencing, D1 consumer recovery, SQLite D2 capacity/elapsed soak and D3 whole-Goal qualification retain their existing roadmap owners. New-Goal defaults and existing-Goal cohort migration remain separate changes. The already merged #4315 repair is reconciled in L7. No default selector or active Goal is promoted, and the still-used legacy Python writer, permanent rendering and import/export paths remain.

Validation

  • Tested revision: f695c25 (pre-rebase runtime/tests are byte-identical; final qualification below).
  • Run state: finished.
  • Input classes: synthetic, public_fixture, authorized_private_read_only.
Check kind Result Evidence / limitation
static passed TS typecheck; changed Python Ruff; configured 22-file mypy; docs governance; diff/public-boundary scan.
unit / real_backend passed 726 authority/provider/runtime/terminal/acceptance tests, zero skips; real File/SQLite/NoKV and isolated PostgreSQL 16. The focused completion/wire selection adds 17 passing cases over both legacy/native fixture schemas.
integration passed 206 selected Python Todo/Chat/acceptance tests, covering unchanged legacy and canonical routes.
real_entrypoint passed Installed-wheel provenance and 18 real CLI/Chat/HTTP cases: validation failure, revoked registry, absent display, response loss and original-operation recovery.
real_entrypoint passed Packaged personal-workspace-browser-smoke.mjs, typed-actions scenario; original proposal ID retained for both edit and complete retries. Shared action-review tests/smoke and packaged build pass.
regression_parity passed Fixed-main public CLI reproduces validation-before-writer-fence; current File/SQLite succeeds. Authorized frozen full-graph rehearsal preserves all pre-existing Todos/leases, matches baseline ordinary-edit heads, and produces equal completion heads across File/SQLite/PostgreSQL. Frozen historical snapshot, not live state or D2 soak; private input is not published.
manual passed Synthetic packaged before/after recovery screenshots below; no responsive layout change.
integration passed Exact-scope change-quality receipt and risk-based premerge: Passed 19/19 selected checks plus 5 direct checks, no failures/skips/manual holds, against immutable main 8ea9433. Exact 35-file quality receipt cqr_ab6c1a86e4e5590298ff is valid (scope ab6c1a86e4e5590298ffdb1a1c037510bf70327fe8e04703a6afa7ae868fe9d5); one bounded safe-fix pass, zero blockers/warnings/advisories. An initial run passed every check but its receipt became stale after upstream moved; it was requalified and rerun rather than waived. The integrated DCO base tests also pass (11 cases)..

On the installed console-script entrypoint with matching 50-Todo states, 64 interleaved ordinary-edit pairs per provider report File baseline/candidate p50/p95 847/1257 vs 764/1252 ms and SQLite 583/871 vs 588/820 ms. New completion CLI p95 is 1115 ms (File) and 1113 ms (SQLite), 16 samples each, without an external validation command. Eight cold starts p50/p95 221/342 ms; 128 warm pings 0.54/1.42 ms; daemon RSS 107.16 to 109.36 MiB across 256 requests. These are bounded local measurements, not D2 capacity/soak evidence. The initial 16-sample direct-module run showed higher tails; it interleaved additional completion writes only on the candidate, so the matched-state console-entrypoint confirmation above is the acceptance comparison. Both observations are retained privately; no speedup claim is made.

Coverage limits: PostgreSQL proves the provider/service contract against a disposable real server, not authenticated multi-host deployment. Registry witnessing remains optimistic, not an executor-held or cross-resource authorization lock. Browser transport fixtures and real HTTP/provider tests are complementary. No CI fetch/poll was performed under the resolved review policy; no soak/default/cohort promotion is claimed. Initial local fixture/document-index setup failures were repaired and their relevant checks rerun.

Frontend / Visual Evidence

UI impact: changed recovery availability only; existing layout, action and configuration owners are retained. The same synthetic pending completion is hidden before and has an original-operation retry after. Desktop viewport: 1512 × 982; after image crops the open drawer. No mobile/responsive styling changed.

Before · After

Shared-authority RFC fixture impact

Uses the existing productionScaleCoordinationFixture legacy/native complete graphs; adds leased User completion, stale/expired proof, authority laundering, wrong role/class, invalid successors, changed source revision, immutable replay and post-completion annotation. Conformance arms: File, SQLite, NoKV and isolated PostgreSQL. The frozen baseline/File/SQLite/PostgreSQL rehearsal is described above; no private snapshot is committed.

Boundary Checklist

  • Public code/docs/synthetic fixtures and screenshots only; no private state, credentials, raw traces, connection strings or local paths.
  • No maintainer-owned benchmark run or unrelated cleanup.
  • Scoped to the existing caller closure; remaining roadmap work is not declared complete.
  • UI recovery evidence and installed artifact validation included.
  • Every commit carries DCO sign-off.

Type: bug fix, cohesive refactor, documentation and regression coverage. Area: control plane, shared authority, packaged presentation.

@huangruiteng
huangruiteng marked this pull request as ready for review September 18, 2026 13:18

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Reviewed exact head: f695c2561f0e3cab330e3d126f08b35cd4b46d50.

未发现阻断项。整体判断为 justified_increment:完整闭合用户完成更新及其恢复路径;不代表本地默认切换、D2/D3 或旧 Python writer 退出已经完成。

动机

按 #4574 R5、TS T1/T2 与 shared-authority L2 的实际 caller 验收,本 PR 修复一个已在固定主干重现的断点:promoted User todo update --status done 先执行声明验证,随后被旧 Markdown writer fence 拒绝。若只放宽路由、不复用 terminal owner,会分裂完成权限、验证、lease release 和 recovery authority。既有 Chat User completion 还会漏掉 reviewed operation 恢复入口。

改动思路

采用已有 TS terminal 事务作为完成 owner,从 ordinary update 提取真实输入 decoder/materializer;共用已有 public planner、lifecycle decision、completion reducer、CAS/receipt/projection outbox。Python 传递意图、执行声明效果并交回结果;不新增业务规则副本。File/SQLite/NoKV/PostgreSQL 共用同一语义,provider 保留各自持久化边界。

最强反对理由是“一个入口缺口不值得再加一套完成框架”。本 diff 没有新增第二个框架:新增模块承接真实被提取的编辑规则,原 terminal transport 的内联效果/失败处理移至既有 validation owner,供两个入口复用。仍保留的 Python Markdown/event writer 具有未晋升 Goal caller;它们不是这次已退休的代码。这个边界允许独立验证和回滚,后续继续原有 L2/L3/L5、D2/D3 计划。

具体改动

关键代码讲解

  1. normalizeTodoUpdateInput / prepareUpdatedTodo 统一字段、clear、authoring 与 materialization。新 v3 envelope 才接受 completion;v0–v2 拒绝该新字段,普通请求 hash 和既有 terminal receipt identity 保留。TodoCompletionEdit 只传编辑字段,并在运行时拒绝额外 authority facts,不能把 Pick 当作运行时裁剪。
  2. executeCoordinationTodoTerminalLifecycle 分别检查原 Todo 的 complete 权限和候选 Todo 的 update 权限。反例是只有 update 委托的 A 清除 B 的 claim 后尝试完成:必须拒绝,不能从编辑后的无主状态获得权限。关联 successor 的存在性、自环检查提前到外部验证之前;此顺序也适用于原有 complete/supersede。
  3. 完成续提绑定签发的 provider revision,保留 registry witness 并更新 observed time;任何中途 provider commit、登记撤销或过期显式 proof 都不能提交。Todo、release、投影意图和业务回执原子持久化;release 保留 version/epoch。旧回执证明历史成功,不重新授予执行权限。
  4. 已完成 User Todo 的新备注保留 completed_at,不重跑已退休的私有验证声明。精确 operation replay 返回原回执;修改意图复用同一 ID 会失败。显示恢复读取当前 canonical head,不能写回旧 Markdown 真相。
  5. update_canonical_todo_if_promoted 与 terminal adapter 共用 execute_completion_validation_effects / completion_validation_failure。Chat preview 保存 canonical basis,apply 沿用 proposal operation ID;验证失败不产生成功 receipt,投影中断/action 回包丢失均恢复原操作。共享 review plan、打包 bundle 和既有浏览器 fixture 一起覆盖 retry 可发现性。Agent complete 保留独立入口。
    文档与验证:扩展现有完整 legacy/native 合成图的四 provider conformance,增加真实 CLI、Chat service、HTTP、安装 wheel 和 packaged browser 用例;双语 RFC checkpoint、执行记录、操作/回滚文档和两张合成截图同步。

对主干的风险

语义与 CI 对齐

复用既有 Todo/lease/receipt 词汇,仅扩展 update v3 transport;新的完成 caller 与更早的 successor 拒绝已在双语 RFC、操作文档和回归中披露。schema、actor、source 与 lease 条件都是机器强制准入;未使用文字启发式分类,也未把强制条件称为 guidance。按已解析策略不读取 CI,仓库本地检查与真实后端仍执行。

  • 完成/验证边界: 显式披露新 User caller 及更早的 successor 拒绝。原 Todo 权限、过期 proof、同 operation 改意图、并发 revision、登记撤销、dry-run 无效果均有负例;没有新增通用 raw patch 或跨 Goal 权限。
  • 来源一致性: registry witness 是乐观检查,不是跨资源事务或 executor-held 外部效果锁。验证命令自身可能产生外部效果;本 PR 保证不把失效依据提交为 canonical completion,未宣称撤销已经运行的命令。
  • 兼容/回滚: 未晋升路径保留;旧 wire 与既有终态回执不改名。新 v3 操作的 pending projection 应恢复后再降级,不能通过解除 fence 恢复陈旧 Markdown writer。
  • 展示/打包: 改动是既有 recovery availability,无首页/布局/config 新设计。合成 before/after 截图证明旧列表隐藏、新版可重试;真实 HTTP/provider 用例补足浏览器 mock 的边界。
  • 验证: 726 个相关 TS/真实 provider 用例零跳过,17 个聚焦完成/wire 用例、206 个相关 Python 用例、18 个最新版 wheel caller 用例通过;TS typecheck、Ruff、配置范围 mypy、文档/边界扫描及 packaged browser 通过。冻结历史全图 rehearsal 保留全部既有 Todo/lease,并核对 baseline ordinary edit 与当前三个 provider 的完整 head。该私有历史输入不公开,不代表活动 Goal 或 soak。
  • 性能/资格: 通过安装后的 console-script 所指向的入口,对相同 50-Todo 状态执行各 64 组交错普通编辑:File 基线/候选 p50/p95 为 847/1257 与 764/1252 ms;SQLite 为 583/871 与 588/820 ms。新完成 CLI 各 16 个样本、不含外部验证命令,p95 分别为 1115/1113 ms。8 次冷启动 p50/p95 221/342 ms;128 次暖 ping 0.54/1.42 ms;256 次请求前后 RSS 为 107.16/109.36 MiB。初始 16 样本 direct-module 测量出现较高尾延迟,且仅在候选侧交错了额外完成写入;后续同状态、相同正式入口对照排除了这种干扰。两组观察均保留,不宣称性能提升或 D2 容量/soak 已通过。
  • 合并门: 绑定主干 8ea943359 后,19/19 selected checks 与 5 项 direct checks 全部通过,无失败、跳过或 manual hold;35 文件精确质量回执 cqr_ab6c1a86e4e5590298ff 有效,safe-fix 一轮、阻断/警告/建议均为零。初次所有检查通过但因 upstream 移动导致回执 stale,已重新资格化并完整重跑,未豁免门禁。新增主干 DCO 验证 11 项通过。按已解析策略未读取或轮询 CI。未测试真实多 host PostgreSQL 部署、十日 soak 和活动 cohort cutover;这些保留在各自验收边界。

我的整体评价

建议合入这个有界 caller 闭合 PR,保留维护者合并决定。未来重构检查已应用于同一边界:编辑规则独立归属、复用 terminal/receipt/outbox、统一传输处理,未引入未使用的抽象。下一步应按现有 caller/consumer 清单及 D2/D3 证据推进,不能从本 PR 的代码或测试数量推导默认化已就绪。

English verdict: APPROVE - f695c2561f0e3cab330e3d126f08b35cd4b46d50. Canonical User completion updates now reuse the existing typed terminal authority and reviewed Chat recovery, with source/lease/permission counterexamples, real provider and packaged-entrypoint validation. No blocking finding; local-default, soak, cross-host PostgreSQL and legacy-writer retirement remain separate qualification boundaries.

@huangruiteng
huangruiteng force-pushed the codex/canonical-local-lifecycle-20260918 branch from f695c25 to f6998d0 Compare September 18, 2026 15:34

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Reviewed exact head: f6998d0cfb85e7e6fa137faac3f43bb71f3f0a11.

未发现阻断项。整体判断为 justified_increment:本 PR 完整闭合 promoted User Todo 的完成更新及 Chat 原操作恢复;它不宣称本地 authority 默认化、D2/D3、十日 soak 或旧 Python writer 退出已经完成。

动机

按 #4574 R5、TypeScript migration T1/T2 与 shared-authority L2 的 caller 验收,固定主干可重现的问题是:todo update --status done 已执行声明的验证命令,却随后被 legacy Markdown writer fence 拒绝。仅放宽路由会让验证副作用与完成状态分离;在 Python 重新实现完成会分裂权限、lease release、receipt 与 recovery 的权威。Chat 的 User completion 同时缺少已提交操作的可发现恢复入口。

修复后的可观察结果是:同一公开 CLI/Python/Chat 操作在 promoted Goal 上进入 canonical terminal 事务,验证失败或 source/lease 漂移不会写入成功 receipt;提交响应或展示投影丢失时,以原 operation id 恢复。未晋升 Goal 与 Agent completion 的既有入口保持不变。

改动思路

复用既有 TypeScript terminal owner,而不是增加第二套完成状态机。ordinary update 中已有的字段归一化与 materialization 被提取为 todo_update_intent.ts,供普通更新与 User completion 共用;terminal owner 仍统一负责原 Todo 权限、候选编辑权限、completion reducer、lease release、CAS、business receipt 与 projection outbox。Python 只负责搬运意图、执行已声明的宿主验证效果并把结果交回 typed resume;File、SQLite、NoKV、PostgreSQL 保留各自存储边界但共享同一语义。

最强反对理由是“为一个入口缺口引入了过多机制”。审查结果不支持该反对:新模块承接的是从既有 hot path 抽出的真实规则,Python terminal adapter 中重复的 effect/failure plumbing 被删除,未增加 provider、scheduler、独立状态或未使用框架。剩余 legacy writer 有未迁移 caller,保留有明确退出条件;当前边界可独立测试、回滚和继续迁移。

具体改动

关键代码讲解

  1. normalizeTodoUpdateInput / prepareUpdatedTodo(todo_update_intent.ts:40/114)集中维护 patch、clear、planning intent、审计字段和 User authoring scope。新 completion payload 仅由 v3 envelope 接受;v0-v2 与普通更新 receipt identity 不变。运行时白名单阻止 TodoCompletionEdit 携带额外 authority facts。
  2. executeCoordinationTodoTerminalLifecycle(todo_terminal_lifecycle.ts:722)先保留原 Todo 作为 complete 权限依据,再对编辑后的候选执行 update admission,避免“仅有 update 委托的 actor 先清 claim 再获得 complete 权限”。验证续提绑定签发的 provider revision,并在 CAS 前重查 registry/source/lease。
  3. update_canonical_todo_if_promoted(provider_update.py:34)仅在已有 promotion gate 内构造 v3 completion 请求;收到 execute_validation 后执行声明效果并以同一 operation 恢复。missing canonical authority 不回退到旧 Markdown。
  4. execute_completion_validation_effects / completion_validation_failure(completion_validation.py:732/774)成为两个 terminal caller 共用的宿主效果与失败映射,消除原 adapter 重复实现。
  5. Chat 的 canonical basis 与 apply 路径保留 proposal operation id;打包 bundle 已按源码刷新。变异测试 locator 同步到提取后的 todo_update_intent.ts,因此 CI 不再因旧文件定位漂移而失败。

文档同步披露了新 caller、早于验证发生的 successor 拒绝、恢复顺序、rollback 边界与仍未完成的迁移项;测试覆盖 legacy/native schema、四类 provider、真实 CLI/HTTP、Chat 与 packaged browser。

对主干的风险

语义与 CI 对齐

本次扩展既有 Todo/lease/receipt 词汇,仅增加 update v3 的 completion intent;没有字符串 denylist、产品特定控制面文案或把机器强制条件描述成 guidance。默认开关仍由 local_authority_is_promoted 所有;未晋升路径、普通 v0-v2 update、Agent complete 与既有 terminal receipt identity 保持兼容。

  • 权限:原 Todo complete 权限与候选 update 权限分别验证,update-only grant 不能通过清除他人 claim 洗白完成权限。
  • 时序:successor 缺失/自环在外部验证前拒绝;provider revision、registry witness、lease version/epoch 任一变化均阻止提交。
  • 恢复:历史 receipt 只证明已提交操作,不重新授予执行权限;pending v3 操作应先恢复再降级,不能解除 fence 后回写旧 Markdown。
  • 展示:只改变已有 recovery action 的可见性,没有首页、布局或配置设计变化;合成截图和 packaged browser smoke 覆盖原操作重试。
  • CI 修复:旧 mutant locator 已指向抽取后的规则 owner;rebase 遗留的重复 sourceChanged() 检查已删除并保留 typed AUTHORITY_SOURCE_CHANGED;Chat bundle 已重建。
  • 新 exact head 验证:TypeScript typecheck;控制面 2032 passed / 0 failed / 18 conditional skips;22 个聚焦 Python 测试;mypy 22 文件;Ruff;docs governance;全量 deliberate mutants;change-quality receipt cqr_9df029dadecc44161e2d;premerge 10/10 catalog canaries、8/8 risk smokes、公共边界与 diff 检查均通过。重放前的相同六提交 patch 还通过真实隔离 PostgreSQL ladder/store/service 169/169 + 169/169 + 10/10(零跳过)和 packaged Personal Workspace browser smoke;git range-diff 逐提交证明重放等价。远端 CI 不作为本 review 的判定证据。

残余风险:registry witness 是乐观并发检查,外部验证副作用不能因后续拒绝自动撤销;未覆盖真实多 host PostgreSQL 部署、十日 soak 与活动 cohort cutover。这些属于已记录的后续资格边界,不是当前 caller 闭合的阻断项。

我的整体评价

建议合入该有界 caller 闭合,且保留维护者的最终合并决定。代码复用了既有 terminal/receipt/outbox 与 typed vocabulary;相关 future-facing refactor 已完成为共享 edit intent 和 validation-effect owner,没有发现需要本 PR 再扩张的相邻重构。仓库政策明确禁止作者自合并 loopx/** 控制面行为变更,因此即使 exact-head review、质量回执、premerge 与远端 CI 最终均通过,本 PR 仍应由另一位维护者合并。

English verdict: APPROVE - f6998d0cfb85e7e6fa137faac3f43bb71f3f0a11. Canonical User completion now reuses the typed terminal authority and reviewed Chat recovery. Source, lease, delegation, replay, and validation-failure boundaries are covered with no blocking finding; default rollout, soak, cross-host PostgreSQL, and legacy-writer retirement remain separate. Repository policy requires maintainer merge for this control-plane change.

@huangruiteng
huangruiteng force-pushed the codex/canonical-local-lifecycle-20260918 branch from f6998d0 to 48573ca Compare September 18, 2026 15:56

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Reviewed exact head: 48573cabea996c6c9ef2935bbfce5b24a338d117.

未发现阻断项。整体判断为 justified_increment:本 PR 完整闭合 promoted User Todo 的完成更新及 Chat 原操作恢复;它不宣称本地 authority 默认化、D2/D3、十日 soak 或旧 Python writer 退出已经完成。

动机

按 #4574 R5、TypeScript migration T1/T2 与 shared-authority L2 的 caller 验收,固定主干可重现的问题是:todo update --status done 已执行声明的验证命令,却随后被 legacy Markdown writer fence 拒绝。仅放宽路由会让验证副作用与完成状态分离;在 Python 重新实现完成会分裂权限、lease release、receipt 与 recovery 的权威。Chat 的 User completion 同时缺少已提交操作的可发现恢复入口。

修复后的可观察结果是:同一公开 CLI/Python/Chat 操作在 promoted Goal 上进入 canonical terminal 事务,验证失败或 source/lease 漂移不会写入成功 receipt;提交响应或展示投影丢失时,以原 operation id 恢复。未晋升 Goal 与 Agent completion 的既有入口保持不变。

改动思路

复用既有 TypeScript terminal owner,而不是增加第二套完成状态机。ordinary update 中已有的字段归一化与 materialization 被提取为 todo_update_intent.ts,供普通更新与 User completion 共用;terminal owner 仍统一负责原 Todo 权限、候选编辑权限、completion reducer、lease release、CAS、business receipt 与 projection outbox。Python 只负责搬运意图、执行已声明的宿主验证效果并把结果交回 typed resume;File、SQLite、NoKV、PostgreSQL 保留各自存储边界但共享同一语义。

最强反对理由是“为一个入口缺口引入了过多机制”。审查结果不支持该反对:新模块承接的是从既有 hot path 抽出的真实规则,Python terminal adapter 中重复的 effect/failure plumbing 被删除,未增加 provider、scheduler、独立状态或未使用框架。剩余 legacy writer 有未迁移 caller,保留有明确退出条件;当前边界可独立测试、回滚和继续迁移。

具体改动

关键代码讲解

  1. normalizeTodoUpdateInput / prepareUpdatedTodo(todo_update_intent.ts:40/114)集中维护 patch、clear、planning intent、审计字段和 User authoring scope。新 completion payload 仅由 v3 envelope 接受;v0-v2 与普通更新 receipt identity 不变。运行时白名单阻止 TodoCompletionEdit 携带额外 authority facts。
  2. executeCoordinationTodoTerminalLifecycle(todo_terminal_lifecycle.ts:722)先保留原 Todo 作为 complete 权限依据,再对编辑后的候选执行 update admission,避免“仅有 update 委托的 actor 先清 claim 再获得 complete 权限”。验证续提绑定签发的 provider revision,并在 CAS 前重查 registry/source/lease。
  3. update_canonical_todo_if_promoted(provider_update.py:34)仅在已有 promotion gate 内构造 v3 completion 请求;收到 execute_validation 后执行声明效果并以同一 operation 恢复。missing canonical authority 不回退到旧 Markdown。
  4. execute_completion_validation_effects / completion_validation_failure(completion_validation.py:732/774)成为两个 terminal caller 共用的宿主效果与失败映射,消除原 adapter 重复实现。
  5. Chat 的 canonical basis 与 apply 路径保留 proposal operation id;打包 bundle 已按源码刷新。变异测试 locator 同步到提取后的 todo_update_intent.ts,因此 CI 不再因旧文件定位漂移而失败。

文档同步披露了新 caller、早于验证发生的 successor 拒绝、恢复顺序、rollback 边界与仍未完成的迁移项;测试覆盖 legacy/native schema、四类 provider、真实 CLI/HTTP、Chat 与 packaged browser。

对主干的风险

语义与 CI 对齐

本次扩展既有 Todo/lease/receipt 词汇,仅增加 update v3 的 completion intent;没有字符串 denylist、产品特定控制面文案或把机器强制条件描述成 guidance。默认开关仍由 local_authority_is_promoted 所有;未晋升路径、普通 v0-v2 update、Agent complete 与既有 terminal receipt identity 保持兼容。

  • 权限:原 Todo complete 权限与候选 update 权限分别验证,update-only grant 不能通过清除他人 claim 洗白完成权限。
  • 时序:successor 缺失/自环在外部验证前拒绝;provider revision、registry witness、lease version/epoch 任一变化均阻止提交。
  • 恢复:历史 receipt 只证明已提交操作,不重新授予执行权限;pending v3 操作应先恢复再降级,不能解除 fence 后回写旧 Markdown。
  • 展示:只改变已有 recovery action 的可见性,没有首页、布局或配置设计变化;合成截图和 packaged browser smoke 覆盖原操作重试。
  • CI 修复:旧 mutant locator 已指向抽取后的规则 owner;rebase 遗留的重复 sourceChanged() 检查已删除并保留 typed AUTHORITY_SOURCE_CHANGED;Chat bundle 已重建。
  • 新 exact head 验证:22 个聚焦 Python authority/completion 测试、mypy 22 文件、Ruff、exact-scope quality receipt cqr_b9ad743e19ef6d55fb6a 与 premerge 10/10 catalog canaries、8/8 risk smokes、公共边界和 diff 检查均通过。相同 TypeScript diff 的 typecheck 与全量控制面为 2032 passed / 0 failed / 18 conditional skips;重放前的相同产品 patch 还通过全量 deliberate mutants、真实隔离 PostgreSQL ladder/store/service 169/169 + 169/169 + 10/10(零跳过)和 packaged Personal Workspace browser smoke;git range-diff 逐提交证明重放等价。远端 CI 不作为本 review 的判定证据。

残余风险:registry witness 是乐观并发检查,外部验证副作用不能因后续拒绝自动撤销;未覆盖真实多 host PostgreSQL 部署、十日 soak 与活动 cohort cutover。这些属于已记录的后续资格边界,不是当前 caller 闭合的阻断项。

我的整体评价

建议合入该有界 caller 闭合,且保留维护者的最终合并决定。代码复用了既有 terminal/receipt/outbox 与 typed vocabulary;相关 future-facing refactor 已完成为共享 edit intent 和 validation-effect owner,没有发现需要本 PR 再扩张的相邻重构。仓库政策明确禁止作者自合并 loopx/** 控制面行为变更,因此即使 exact-head review、质量回执、premerge 与远端 CI 最终均通过,本 PR 仍应由另一位维护者合并。

English verdict: APPROVE - 48573cabea996c6c9ef2935bbfce5b24a338d117. Canonical User completion now reuses the typed terminal authority and reviewed Chat recovery while preserving the established HTTP 400/failed-proposal behavior when validation invalidates its authority source. Source, lease, delegation, replay, and validation-failure boundaries are covered with no blocking finding; default rollout, soak, cross-host PostgreSQL, and legacy-writer retirement remain separate. Repository policy requires maintainer merge for this control-plane change.

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Reviewed exact head: 48573cabea996c6c9ef2935bbfce5b24a338d117.

未发现阻断项。整体判断为 justified_increment:本 PR 完整闭合 promoted User Todo 的完成更新及 Chat 原操作恢复;它不宣称本地 authority 默认化、D2/D3、十日 soak 或旧 Python writer 退出已经完成。

动机

按 #4574 R5、TypeScript migration T1/T2 与 shared-authority L2 的 caller 验收,固定主干可重现的问题是:todo update --status done 已执行声明的验证命令,却随后被 legacy Markdown writer fence 拒绝。仅放宽路由会让验证副作用与完成状态分离;在 Python 重新实现完成会分裂权限、lease release、receipt 与 recovery 的权威。Chat 的 User completion 同时缺少已提交操作的可发现恢复入口。

修复后的可观察结果是:同一公开 CLI/Python/Chat 操作在 promoted Goal 上进入 canonical terminal 事务,验证失败或 source/lease 漂移不会写入成功 receipt;提交响应或展示投影丢失时,以原 operation id 恢复。未晋升 Goal 与 Agent completion 的既有入口保持不变。

改动思路

复用既有 TypeScript terminal owner,而不是增加第二套完成状态机。ordinary update 中已有的字段归一化与 materialization 被提取为 todo_update_intent.ts,供普通更新与 User completion 共用;terminal owner 仍统一负责原 Todo 权限、候选编辑权限、completion reducer、lease release、CAS、business receipt 与 projection outbox。Python 只负责搬运意图、执行已声明的宿主验证效果并把结果交回 typed resume;File、SQLite、NoKV、PostgreSQL 保留各自存储边界但共享同一语义。

最强反对理由是“为一个入口缺口引入了过多机制”。审查结果不支持该反对:新模块承接的是从既有 hot path 抽出的真实规则,Python terminal adapter 中重复的 effect/failure plumbing 被删除,未增加 provider、scheduler、独立状态或未使用框架。剩余 legacy writer 有未迁移 caller,保留有明确退出条件;当前边界可独立测试、回滚和继续迁移。

具体改动

关键代码讲解

  1. normalizeTodoUpdateInput / prepareUpdatedTodo(todo_update_intent.ts:40/114)集中维护 patch、clear、planning intent、审计字段和 User authoring scope。新 completion payload 仅由 v3 envelope 接受;v0-v2 与普通更新 receipt identity 不变。运行时白名单阻止 TodoCompletionEdit 携带额外 authority facts。
  2. executeCoordinationTodoTerminalLifecycle(todo_terminal_lifecycle.ts:722)先保留原 Todo 作为 complete 权限依据,再对编辑后的候选执行 update admission,避免“仅有 update 委托的 actor 先清 claim 再获得 complete 权限”。验证续提绑定签发的 provider revision,并在 CAS 前重查 registry/source/lease。
  3. update_canonical_todo_if_promoted(provider_update.py:34)仅在已有 promotion gate 内构造 v3 completion 请求;收到 execute_validation 后执行声明效果并以同一 operation 恢复。missing canonical authority 不回退到旧 Markdown。
  4. execute_completion_validation_effects / completion_validation_failure(completion_validation.py:732/774)成为两个 terminal caller 共用的宿主效果与失败映射,消除原 adapter 重复实现。
  5. Chat 的 canonical basis 与 apply 路径保留 proposal operation id;打包 bundle 已按源码刷新。变异测试 locator 同步到提取后的 todo_update_intent.ts,因此 CI 不再因旧文件定位漂移而失败。

文档同步披露了新 caller、早于验证发生的 successor 拒绝、恢复顺序、rollback 边界与仍未完成的迁移项;测试覆盖 legacy/native schema、四类 provider、真实 CLI/HTTP、Chat 与 packaged browser。

对主干的风险

语义与 CI 对齐

本次扩展既有 Todo/lease/receipt 词汇,仅增加 update v3 的 completion intent;没有字符串 denylist、产品特定控制面文案或把机器强制条件描述成 guidance。默认开关仍由 local_authority_is_promoted 所有;未晋升路径、普通 v0-v2 update、Agent complete 与既有 terminal receipt identity 保持兼容。

  • 权限:原 Todo complete 权限与候选 update 权限分别验证,update-only grant 不能通过清除他人 claim 洗白完成权限。
  • 时序:successor 缺失/自环在外部验证前拒绝;provider revision、registry witness、lease version/epoch 任一变化均阻止提交。
  • 恢复:历史 receipt 只证明已提交操作,不重新授予执行权限;pending v3 操作应先恢复再降级,不能解除 fence 后回写旧 Markdown。
  • 展示:只改变已有 recovery action 的可见性,没有首页、布局或配置设计变化;合成截图和 packaged browser smoke 覆盖原操作重试。
  • CI 修复:旧 mutant locator 已指向抽取后的规则 owner;rebase 遗留的重复 sourceChanged() 检查已删除并保留 typed AUTHORITY_SOURCE_CHANGED;Chat bundle 已重建。
  • 新 exact head 验证:22 个聚焦 Python authority/completion 测试、mypy 22 文件、Ruff、exact-scope quality receipt cqr_b9ad743e19ef6d55fb6a 与 premerge 10/10 catalog canaries、8/8 risk smokes、公共边界和 diff 检查均通过。相同 TypeScript diff 的 typecheck 与全量控制面为 2032 passed / 0 failed / 18 conditional skips;重放前的相同产品 patch 还通过全量 deliberate mutants、真实隔离 PostgreSQL ladder/store/service 169/169 + 169/169 + 10/10(零跳过)和 packaged Personal Workspace browser smoke;git range-diff 逐提交证明重放等价。远端 CI 不作为本 review 的判定证据。

残余风险:registry witness 是乐观并发检查,外部验证副作用不能因后续拒绝自动撤销;未覆盖真实多 host PostgreSQL 部署、十日 soak 与活动 cohort cutover。这些属于已记录的后续资格边界,不是当前 caller 闭合的阻断项。

我的整体评价

建议合入该有界 caller 闭合,且保留维护者的最终合并决定。代码复用了既有 terminal/receipt/outbox 与 typed vocabulary;相关 future-facing refactor 已完成为共享 edit intent 和 validation-effect owner,没有发现需要本 PR 再扩张的相邻重构。仓库政策明确禁止作者自合并 loopx/** 控制面行为变更,因此即使 exact-head review、质量回执、premerge 与远端 CI 最终均通过,本 PR 仍应由另一位维护者合并。

English verdict: APPROVE - 48573cabea996c6c9ef2935bbfce5b24a338d117. Canonical User completion now reuses the typed terminal authority and reviewed Chat recovery while preserving the established HTTP 400/failed-proposal behavior when validation invalidates its authority source. Source, lease, delegation, replay, and validation-failure boundaries are covered with no blocking finding; default rollout, soak, cross-host PostgreSQL, and legacy-writer retirement remain separate. Repository policy requires maintainer merge for this control-plane change.

…hority

Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
…providers

Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
@huangruiteng
huangruiteng force-pushed the codex/canonical-local-lifecycle-20260918 branch from 48573ca to 2058d38 Compare September 18, 2026 16:27

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Reviewed exact head: 2058d381672e053f53fb193e5de637771aa5e2e1.

未发现阻断项。整体判断为 justified_increment:本 PR 完整闭合 promoted User Todo 的完成更新及 Chat 原操作恢复;它不宣称本地 authority 默认化、D2/D3、十日 soak 或旧 Python writer 退出已经完成。

动机

按 #4574 R5、TypeScript migration T1/T2 与 shared-authority L2 的 caller 验收,固定主干可重现的问题是:todo update --status done 已执行声明的验证命令,却随后被 legacy Markdown writer fence 拒绝。仅放宽路由会让验证副作用与完成状态分离;在 Python 重新实现完成会分裂权限、lease release、receipt 与 recovery 的权威。Chat 的 User completion 同时缺少已提交操作的可发现恢复入口。

修复后的可观察结果是:同一公开 CLI/Python/Chat 操作在 promoted Goal 上进入 canonical terminal 事务,验证失败或 source/lease 漂移不会写入成功 receipt;提交响应或展示投影丢失时,以原 operation id 恢复。未晋升 Goal 与 Agent completion 的既有入口保持不变。

改动思路

复用既有 TypeScript terminal owner,而不是增加第二套完成状态机。ordinary update 中已有的字段归一化与 materialization 被提取为 todo_update_intent.ts,供普通更新与 User completion 共用;terminal owner 仍统一负责原 Todo 权限、候选编辑权限、completion reducer、lease release、CAS、business receipt 与 projection outbox。Python 只负责搬运意图、执行已声明的宿主验证效果并把结果交回 typed resume;File、SQLite、NoKV、PostgreSQL 保留各自存储边界但共享同一语义。

最强反对理由是“为一个入口缺口引入了过多机制”。审查结果不支持该反对:新模块承接的是从既有 hot path 抽出的真实规则,Python terminal adapter 中重复的 effect/failure plumbing 被删除,未增加 provider、scheduler、独立状态或未使用框架。剩余 legacy writer 有未迁移 caller,保留有明确退出条件;当前边界可独立测试、回滚和继续迁移。

具体改动

关键代码讲解

  1. normalizeTodoUpdateInput / prepareUpdatedTodo(todo_update_intent.ts:40/114)集中维护 patch、clear、planning intent、审计字段和 User authoring scope。新 completion payload 仅由 v3 envelope 接受;v0-v2 与普通更新 receipt identity 不变。运行时白名单阻止 TodoCompletionEdit 携带额外 authority facts。
  2. executeCoordinationTodoTerminalLifecycle(todo_terminal_lifecycle.ts:722)先保留原 Todo 作为 complete 权限依据,再对编辑后的候选执行 update admission,避免“仅有 update 委托的 actor 先清 claim 再获得 complete 权限”。验证续提绑定签发的 provider revision,并在 CAS 前重查 registry/source/lease。
  3. update_canonical_todo_if_promoted(provider_update.py:34)仅在已有 promotion gate 内构造 v3 completion 请求;收到 execute_validation 后执行声明效果并以同一 operation 恢复。missing canonical authority 不回退到旧 Markdown。
  4. execute_completion_validation_effects / completion_validation_failure(completion_validation.py:732/774)成为两个 terminal caller 共用的宿主效果与失败映射,消除原 adapter 重复实现。
  5. Chat 的 canonical basis 与 apply 路径保留 proposal operation id;打包 bundle 已按源码刷新。变异测试 locator 同步到提取后的 todo_update_intent.ts,因此 CI 不再因旧文件定位漂移而失败。

文档同步披露了新 caller、早于验证发生的 successor 拒绝、恢复顺序、rollback 边界与仍未完成的迁移项;测试覆盖 legacy/native schema、四类 provider、真实 CLI/HTTP、Chat 与 packaged browser。

对主干的风险

语义与 CI 对齐

本次扩展既有 Todo/lease/receipt 词汇,仅增加 update v3 的 completion intent;没有字符串 denylist、产品特定控制面文案或把机器强制条件描述成 guidance。默认开关仍由 local_authority_is_promoted 所有;未晋升路径、普通 v0-v2 update、Agent complete 与既有 terminal receipt identity 保持兼容。

  • 权限:原 Todo complete 权限与候选 update 权限分别验证,update-only grant 不能通过清除他人 claim 洗白完成权限。
  • 时序:successor 缺失/自环在外部验证前拒绝;provider revision、registry witness、lease version/epoch 任一变化均阻止提交。
  • 恢复:历史 receipt 只证明已提交操作,不重新授予执行权限;pending v3 操作应先恢复再降级,不能解除 fence 后回写旧 Markdown。
  • 展示:只改变已有 recovery action 的可见性,没有首页、布局或配置设计变化;合成截图和 packaged browser smoke 覆盖原操作重试。
  • CI 修复:旧 mutant locator 已指向抽取后的规则 owner;rebase 遗留的重复 sourceChanged() 检查已删除并保留 typed AUTHORITY_SOURCE_CHANGED;Chat bundle 已重建。
  • 新 exact head 验证:exact-scope quality receipt cqr_498c49e213d317641bce 与 premerge 10/10 catalog canaries、8/8 risk smokes、公共边界和 diff 检查均通过。git range-diff 证明 7/7 提交与已验证 head 逐个等价;相同产品 patch 通过 22 个聚焦 Python authority/completion 测试、mypy 22 文件、Ruff、TypeScript typecheck、全量控制面 2032 passed / 0 failed / 18 conditional skips、全量 deliberate mutants、真实隔离 PostgreSQL ladder/store/service 169/169 + 169/169 + 10/10(零跳过)和 packaged Personal Workspace browser smoke。远端 CI 不作为本 review 的判定证据。

残余风险:registry witness 是乐观并发检查,外部验证副作用不能因后续拒绝自动撤销;未覆盖真实多 host PostgreSQL 部署、十日 soak 与活动 cohort cutover。这些属于已记录的后续资格边界,不是当前 caller 闭合的阻断项。

我的整体评价

建议合入该有界 caller 闭合,且保留维护者的最终合并决定。代码复用了既有 terminal/receipt/outbox 与 typed vocabulary;相关 future-facing refactor 已完成为共享 edit intent 和 validation-effect owner,没有发现需要本 PR 再扩张的相邻重构。仓库政策明确禁止作者自合并 loopx/** 控制面行为变更,因此即使 exact-head review、质量回执、premerge 与远端 CI 最终均通过,本 PR 仍应由另一位维护者合并。

English verdict: APPROVE - 2058d381672e053f53fb193e5de637771aa5e2e1. Canonical User completion now reuses the typed terminal authority and reviewed Chat recovery while preserving the established HTTP 400/failed-proposal behavior when validation invalidates its authority source. Source, lease, delegation, replay, and validation-failure boundaries are covered with no blocking finding; default rollout, soak, cross-host PostgreSQL, and legacy-writer retirement remain separate. Repository policy requires maintainer merge for this control-plane change.

@huangruiteng
huangruiteng merged commit 876fea9 into main Sep 18, 2026
23 checks passed
@huangruiteng
huangruiteng deleted the codex/canonical-local-lifecycle-20260918 branch September 18, 2026 16:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant