docs(rfc): give shared-goal-authority records a ledger directory - #4728
huangruiteng merged 1 commit into
Conversation
00a3c8d to
c231c81
Compare
huangruiteng
left a comment
There was a problem hiding this comment.
评审对象:#4728 @ c231c813eb456bd7faf0ae0f4c559e3e87b89a92(base main,作者 @DJC1412)。结论:APPROVE,无阻塞项,两条 P3 建议。
动机
#4677 量到 34 个 open head 里 19 个 mergeStateStatus=DIRTY,其中 #3820/#4061/#4672 撞在同一份文件上:shared-goal-authority-state-provider-v0 及其中文镜像——因为这份 RFC 的交付记录都以带日期小节的形式追加在 3,125 行英文文件与 2,474 行中文文件的末尾。仓库对这类冲突早有结构性答案(ledger/ 一条一文件),但对这份 RFC 用不上:examples/docs-governance-smoke.py 里的检查要求 RFC 含字面标题 Appendix A: Execution ledger,而这份 RFC 的附录 A 是 What This Evidence Proves;要迁就检查就得把附录 A–C 在两份语言文件里一起重编号,那正是这条约定想避免的在途重做。所以补上这个缺口是有独立价值的,且不是“为了 PR 而 PR”。
改动思路
三条:(1) 把检查从“字面 Appendix A”放宽为锚定的 ^## Appendix [A-Z]: Execution ledger(行首 ## 标题,任意空闲字母);(2) 两份 ledger README 去掉会立刻过期的“Six RFCs”硬编码计数,改为说明“标题是 附录 <字母>:执行账本,用该 RFC 没占用的字母”;(3) 让本 RFC 采用 Appendix D(中英各一处)并把第一条带日期条目 + 中文镜像放进 ledger/shared-goal-authority-state-provider-v0/,已有的附录 C 小节原样保留为只追加历史。边界清楚:一次匹配规则 + 一份 RFC 的接入,可单独回退。
具体改动
examples/docs-governance-smoke.py:新增LEDGER_APPENDIX_HEADING正则,check_rfc_ledger_entries由字面子串断言改为该正则的search,并把局部变量从appendix_a改名为rfc_document。docs/architecture/rfcs/ledger/README.md/README.zh-CN.md:去掉“六份 RFC”计数,补上字母规则。docs/architecture/rfcs/shared-goal-authority-state-provider-v0.md/.zh-CN.md:各补Appendix D: Execution ledger/附录 D:执行账本,说明新记录写这里、旧小节不动及理由。- 新增
ledger/shared-goal-authority-state-provider-v0/2026-09-19-shared-goal-authority-entries-get-a-ledger.md与其.zh-CN.md镜像。
我在 c231c813e 上复核了作者列出的全部证据,结论一致:docs-governance-smoke ok;docs-asset-integrity-smoke(6 assets verified)、repository-hygiene-smoke、backlog-hygiene-smoke 全 ok;loopx check --scan-path(ledger 目录 + 中英 RFC + smoke)public boundary scan clean(13 files);py_compile 通过。托管文档导航也覆盖到了——同一 smoke 里的 mkdocs_nav_paths/generated_docs_site_sources 检查通过,所以“新增文件不需要新增导航项”这一说法成立(那边校验的是“每个导航项都要有文件”)。
我还按作者的 regression_parity 行自建了合成树,逐个跑真实 check_rfc_ledger_entries()(base 用 a20e71395 的旧实现):
| 用例 | base | head |
|---|---|---|
## Appendix A: Execution ledger |
PASS | PASS |
## Appendix D: Execution ledger |
FAIL | PASS(预期的放宽) |
| 完全没有执行账本附录 | FAIL | FAIL |
只在正文里出现 Appendix D: Execution ledger(无标题) |
FAIL | FAIL(确实锚定,不是子串匹配) |
只有小写字母 ## Appendix d |
FAIL | FAIL |
对主干的风险
无阻塞项;放宽后的检查仍拒绝“有账本目录但没有执行账本附录”的形态,且锚定在行首标题上,作者声称的“不是子串匹配”我复核成立。两条非阻塞建议:
- P3:围栏代码块仍会误通过。
LEDGER_APPENDIX_HEADING是re.MULTILINE的行首匹配,不识别围栏;如果一份 RFC 只在 ``` 代码块里出现## Appendix D: Execution ledger,检查依然通过(旧的字面 `Appendix A` 断言也有同样的盲点,所以这不是本次新增的削弱,但放宽到任意字母后覆盖面变大)。可选的加固:匹配前剥掉围栏区块,或补一条“仅在围栏内出现必须失败”的负例。 - P3:两份 README 的历史段落仍以
Appendix A作通称。 “Why entries are files” 一节写的是 “the same content that used to be appended to an RFC's Appendix A”“Appendix A was a single append cluster”,在字母已可变的现在读起来像通用规则;下次改动这两份文件时不妨改成“执行账本附录”。
关于 #4677 的边界,也说清楚:本 PR 只处理它点名的两个结构源之一(RFC 追加簇),并且只对未来条目生效;已被跟踪的 loopx/web/chat 重建产物仍在那里,owner 的决策门也仍然开着。这不构成本 PR 的阻塞项,作者在正文里也如实写明。
我的整体评价
这是一个范围小、证据可复核、可单独回退的维护切片:一处检查规则放宽 + 一份 RFC 接入 + 第一条账本条目,负例矩阵覆盖了“仍然拒绝”的方向而不只是绿灯用例。仓库自己的文档/卫生检查在该 head 上全绿,放宽后的规则仍锚定标题,未削弱既有强制。两条 P3 属于可选加固,不影响本次合并;我给出 APPROVE。
English verdict: APPROVE - #4728 at c231c81 is a bounded, independently reversible docs-governance slice: the ledger appendix check now matches ^## Appendix [A-Z]: Execution ledger in the English RFC instead of the literal Appendix A: Execution ledger, both ledger READMEs drop a count that rots the moment another RFC adopts a ledger, and shared-goal-authority-state-provider-v0 adopts Appendix D in both languages plus its first dated entry and Chinese mirror. I reproduced the author's evidence at the exact head (docs-governance-smoke ok; docs-asset-integrity, repository-hygiene and backlog-hygiene smokes ok; loopx check --scan-path boundary scan clean over 13 files; py_compile ok; the mkdocs nav walk inside the same smoke covers the new files) and re-ran the parity matrix against synthetic trees with both the base and head check implementations: Appendix A pass->pass, Appendix D fail->pass, no appendix fail->fail, prose-only mention fail->fail, lowercase letter fail->fail. No blocking finding. Two P3 suggestions: the regex is not fence-aware, so a heading inside a fenced block still satisfies the check (a pre-existing blindness that the letter relaxation widens), and the two README history sections still call the appendix "Appendix A" generically. The PR also correctly leaves the second structural source named by #4677 (the tracked chat bundle) and the owner gate untouched.
check_rfc_ledger_entries accepted only the literal heading "Appendix A: Execution ledger", so an RFC already using Appendix A for other evidence could not adopt per-file entries without renumbering its appendices across both language files -- a mechanical diff that itself forces rework on the branches the convention exists to spare. The heading is now matched for any appendix letter, and the READMEs stop hardcoding how many RFCs carry one. shared-goal-authority-state-provider-v0 records each delivery as a dated subsection at the end of one large file, which is why loopx-project#3820, loopx-project#4061 and loopx-project#4672 all collided there per loopx-project#4677. New records move to ledger/shared-goal-authority-state-provider-v0/ as dated files with Chinese mirrors; existing dated subsections stay as append-only history. Refs loopx-project#4677 Signed-off-by: DJC1412 <108855841+DJC1412@users.noreply.github.com>
c231c81 to
6fdc734
Compare
huangruiteng
left a comment
There was a problem hiding this comment.
合并后补记(exact-head 记录补齐):#4728 已以 31525ca92a16ee0e06b7e88ba129f94771d11179 合入 main,而合并时的 PR head 是我尚未单独出结论的 merge-sync commit 6fdc734ffe02a9d87eb725f15ed5fe40487c22e2。我此前只在 c231c813eb456bd7faf0ae0f4c559e3e87b89a92 上出过结论,这里补齐该 merge head 的记录。结论:APPROVE。
动机
评审纪律要求“合并的那个 head”本身带有已发布结论;packet 也把 #4728 的 merged exact head 列为缺少有效结论、需要审计。这篇要回答的是:merge-sync 是否改变了我在 c231c813eb 上验证过的内容。等价则沿用同一结论,不等价就要重新评审。
改动思路
不做完整重审,只用两条可独立核对的证据判等价:(1) 该 merge head 相对它自己的 merge-base 的 PR 内容 diff,是否与我评审过的 diff 逐字一致;(2) 该 head 上重跑该改动直接相关的仓库检查(docs governance / asset integrity / repository hygiene / public boundary scan)是否仍然全绿。
具体改动
- merge-base 为
74b62ebb5(#4731),在6fdc734ffe上重算 PR 内容 diff:7 个文件、+114/-8,与我评审过的c231c813eb(相对其 merge-basea20e71395)的 diff 去掉 blob 哈希后diff为空,即逐字一致; - 该 head 上重跑:
examples/docs-governance-smoke.py→docs-governance-smoke ok;docs-asset-integrity-smoke→ ok (6 assets verified);repository-hygiene-smoke ok;loopx check --scan-path docs/architecture/rfcs/ledger --scan-path examples/docs-governance-smoke.py→ public boundary scan clean (11 files)。
对主干的风险
无阻塞项。 内容与已评审 head 逐字一致,我在 c231c813eb 上的三条 P3(正则不识别围栏代码块、两份 README 历史段落仍以 Appendix A 作通称、其余结论)原样适用,且都不影响合并;该 head 上重跑的检查全绿。合并后 main 侧不受影响的部分(#4677 的第二个结构源、owner 决策门)仍如我在原评审里写的那样保持开放。
我的整体评价
merge-sync head 与已评审内容等价、该 head 上的相关检查全部通过,因此沿用 APPROVE;这条补记只是把缺失的 exact-head 记录补齐,不改变原结论。
English verdict: APPROVE - merge-head record for 4728@6fdc734ffe02a9d87eb725f15ed5fe40487c22e2 (squashed into main as 31525ca). The PR-content diff at this head, computed against its own merge base 74b62eb, is byte-identical to the diff I reviewed at c231c81 (7 files, +114/-8; diff of both diffs ignoring index lines is empty), and the checks that own this surface were re-run here: docs-governance-smoke ok, docs-asset-integrity-smoke ok (6 assets verified), repository-hygiene-smoke ok, and the public boundary scan clean over 11 files. No blocking finding; the three P3 notes from the original review (fence-unaware appendix regex, README history sections still saying "Appendix A" generically, and the untouched second structural source plus owner gate from #4677) carry over unchanged and do not affect the merge.
Goal And Delivered Outcome
mergeStateStatus=DIRTYagainstd8e7af141, and that three of them (#3820,#4061,#4672) collide on one file each —docs/architecture/rfcs/shared-goal-authority-state-provider-v0.mdand its Chinese mirror — because every delivery record for that RFC is appended as a dated subsection at the end of a 3,125-line / 2,474-line pair. LoopX already has the structural answer:ledger/entries-become-files, introduced for the semantic-vocabulary round on 2026-09-18 and enforced bycheck_rfc_ledger_entries. That answer was unreachable here: the check required the RFC to contain the literal headingAppendix A: Execution ledger, and this RFC's Appendix A isWhat This Evidence Proves.ledger/shared-goal-authority-state-provider-v0/failedexamples/docs-governance-smoke.pywithshared-goal-authority-state-provider-v0 has a ledger directory but no execution-ledger appendix, so the only alternative was renumbering Appendices A–C in both language files — a mechanical diff that itself forces a rework on the branches the convention exists to spare. After, the RFC adoptsAppendix D: Execution ledger, its future delivery records are dated files with Chinese mirrors in that directory, and the same smoke passes. Proven by theregression_parityrow, which also shows the enforcement did not weaken.main.Scope And Continuation
^## Appendix [A-Z]: Execution ledgerin the RFC's English document; the twoledger/READMEfiles no longer hardcode how many RFCs carry one (that count rots the moment an RFC adopts it) and state the letter rule;shared-goal-authority-state-provider-v0gains the appendix in both languages plus its first ledger entry, which records what was measured and what was not. Remaining in [Queue] 19 个 open PR 与 main 冲突:其中 7 个只卡在两组 append-only RFC ledger,3 个卡在已提交的前端 bundle #4677 and deliberately not attempted here: the other structural source it names (loopx/web/chat/assets/index-<hash>.jsis still tracked, and rename/delete conflicts on a rebuilt bundle are not a docs-organization problem), and the seven PRs whose heads collide on the semantic-vocabulary RFC — that file's Appendix A already is the execution ledger, so it needs no relaxation, only authors rebasing onto the existing convention.Validation
6fdc734ff(rebased on74b62ebb5; content identical toc231c813e/00a3c8d05, which is what each row was run against)staticuv run --extra test python examples/docs-governance-smoke.py→docs-governance-smoke okwith the new directory, entry, mirror and Appendix D present.staticuv run --extra test python examples/docs-asset-integrity-smoke.py,examples/repository-hygiene-smoke.py,examples/backlog-hygiene-smoke.py→ all ok; relative links from both RFC files intoledger/…resolve because those smokes walk them.unituv run --extra test python -m py_compile examples/docs-governance-smoke.py.regression_paritycheck_rfc_ledger_entrieswas run against synthetic trees, one case per legal/illegal shape. Base → head:Appendix Aheading passes → passes;Appendix Dheading fails → passes (the intended relaxation); no execution-ledger appendix fails → fails; the phraseAppendix D: Execution ledgerappearing mid-prose rather than as a##heading fails → fails, so the relaxation is anchored, not a substring match; a misnamed entry fails → fails.manualloopx check --scan-path docs/architecture/rfcs/ledger --scan-path docs/architecture/rfcs/shared-goal-authority-state-provider-v0.md --scan-path docs/architecture/rfcs/shared-goal-authority-state-provider-v0.zh-CN.md --scan-path examples/docs-governance-smoke.py→ public boundary scan clean (13 files).tests/does not execute RFC prose. Not re-measured: today's DIRTY count over the open queue. GitHub computes mergeability lazily, and a spot check returneddirtyfor a few heads andunknownfor most, so no same-day recount is offered; the counts cited above are [Queue] 19 个 open PR 与 main 冲突:其中 7 个只卡在两组 append-only RFC ledger,3 个卡在已提交的前端 bundle #4677's own, at its stated base.Frontend / Visual Evidence
Type of Change
LoopX Area
Technical Direction
Shared-authority RFC fixture impact
Boundary Checklist
.loopx/,.codex/goals/, and liveACTIVE_GOAL_STATE.md).none.Signed-off-bytrailer (git commit -s).