test(coordination): qualify settlement after ownership policy migration - #5503
Conversation
Signed-off-by: huangruiteng <huangrt01@163.com>
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Reviewer: model_agent | GPT-5 | OpenAI
English verdict: APPROVE
Exact head: 5503@f1c3a1fdaa508bf5de27a47097229f467ea82312; immutable baseline: 8b5335a72df3be1a9d177bfe1e293cafdcbfd384. 作者账号只能发布 COMMENTED 结论,不是 GitHub 正式自批准。按当前 capability 做完整 docs-and-smoke review,未获取、轮询或等待 CI。
动机
维护者需要知道:把一个已有 Goal 的所有权策略迁到 hard lease 后,Agent 是否还能合法修改任务、结算本轮并进入下一轮。
原来迁移、租约和结算分别有测试,但没有把迁移后的这些步骤连在同一次真实操作中验证;现在同一 File/SQLite Goal 先迁移,再拒绝无租约修改、允许带租约写入,执行 CLI 返回的结算命令,重试不重复扣额,迁移重放不丢失新写入,下一轮仍能选择原任务。
本轮在精确 head 上运行真实 CLI 和隔离 File/SQLite,相关两套完整测试 37 项通过。新增旅程移除了 Markdown 来源,比较重放前后的完整 Todo,并验证只有一笔 spend;这补上了迁移后继续工作的集成证据。
没有修改生产规则或自动迁移任何运行中的 Goal;不宣称 PostgreSQL、打包 App/Lark、安装采用、性能、崩溃恢复或长期运行验收已完成。
安装态消费者、带新写入的 provider 往返恢复、性能与持续运行仍由既有 R3/R5/D1–D3/T0–T4 交付路径验收;这份 source 测试不关闭这些主线。
成功生成迁移计划、持有租约或得到一张结算回执,单独都不能证明下一次工作可继续。这份测试的价值是补齐同一次旅程的交叉边界,不是增加测试数量或制造新的退休完成标签。
改动思路
不新增生产规则、开关或 authority owner。复用原 handoff-mode 迁移、task lease、canonical Todo writer 和结算链;既有 _source 只增加可选 handoff_mode 参数,默认值不变。两种真实 backend 的同一链路先迁移、再修改、再结算、最后读回和下一轮准入;Python 在这里是原 CLI 集成测试,不是新增通用控制面决策源。
具体改动
全部三文件、+89/-18:一个既有测试模块和两份英/中文退休 checkpoint。书面基准是 docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md,spec_revision 8b5335a72df3be1a9d177bfe1e293cafdcbfd384,使用修改前的验收矩阵,不以本 PR 新添的证据行自证。
Mutation and ownership:implemented,本次验证已有 claim 的策略迁移→无租约写拒绝→原租约写入→quota/refresh/返回的 spend→重试一次→下一轮工作。其他 CRUD/竞争与旧 epoch 项不因这两臂被宣告全面完成。Interruption and recovery:deferred,重试和保留新写入得到本次证据;完整崩溃、provider、子进程停止等仍归原恢复验收。Installed consumers:deferred,未执行打包 App/Lark/安装运行时采用,不用 source 测试代替它们。
关键内容讲解
test_quota_authority_settlement_journey.py:134的test_migrated_hard_lease_can_write_settle_retry_and_continue:分别在 File/SQLite 创建合成 canonical legacy Goal,迁移到 hard_lease,并移除临时 Markdown。后面的命令不能偷用旧 Markdown writer。- 原
_execute将 refresh 返回的命令原样拆成 argv;不额外补 actor/Todo/Turn 绑定来让测试通过。第一次 spend appended=true,重试 false,实际 history 只有一笔。 - 对新写入后的迁移重放,不只比数量或 hash,而是先单独 list 读完整 Todo、确认新文本,再比重放后的完整对象;释放原租约后新 Turn 选择原身份,且不是 unsettled recovery。
- 双语 checkpoint 同步纠正 #5413/#5466 的 merged 状态、保留 #5283 的冷 CLI 失败以及 #5500 的创建恢复前置边界,移除固定“剩余三 PR”说法。独立 GitHub metadata 读回证实前两项已合并;合并与 installed qualification 仍明确分开。
独立执行:uv run --extra test python -m pytest -q tests/control_plane/test_quota_authority_settlement_journey.py tests/control_plane/test_canonical_handoff_mode.py,37 passed,无跳过。包含新两臂及邻接的 terminal/blocked/absent、排除、同伴 claim、缺 capability、canonical provider 不可用和策略迁移测试。差异词汇 advisory 先于全树 semantic drift;之后 Ruff、配置的 19-source mypy 与 diff check 均通过。没有修改断言、提高 timeout 或改写旧失败记录。
对主干的风险
主要风险是把“迁移成功”误报为“执行和退休完成”,或重放迁移覆盖后来的写入。本测试跨真实 CLI/原 store 检查无租约拒绝、合法写入、结算幂等和新写入保留;邻接负例继续 fail closed。没有 runtime 改动,因此不产生新的默认行为、TS/Python双决策、权限或 schema 迁移。也未把 hard-lease enforced 拒绝叫成可忽略 guidance。
前端、Lark、CLI:只改变 source CLI 的回归覆盖;没有新用户入口或配置。生产 UI 未改变,未宣称 packaged journey 已验证;PostgreSQL writer 未触及,不以 File/SQLite 测试充当 PostgreSQL 证据。性能、长期运行和部署身份仍是已有路径的未验证部分。
可维护性检查:新增旅程放在已有 settlement 测试与 shared fixture 内,不另建 runner;邻近规则仍由原 typed owner 决定。近期同作者批次有不同已证实缺口,没有发现重复同形 smoke 或仅测试字段存在的批量脚手架。本次相关小重构已落实为 fixture 参数复用;没有更大的生产重构需要捆绑进来。
我的整体评价
APPROVE 这个 justified_increment。long_horizon improved:补上策略迁移后结算/重放/下一轮的真实交叉边界,并让原 checkpoint 保持当前事实。user_experience improved 是间接保障 Agent 日常续跑,不是新 UI 或已安装改善。
这是可独立审查、可撤销的 source qualification;不关闭 R3/R5/D1–D3/T0–T4,也不新增仪式性后续任务。没有本次 scoped blocker。发布后仍执行 approval-closeout;只有逐项证明旧 finding 已修复/反证且有权限才撤销旧阻塞评审,不自动合并或迁移运行中的 Goal。
|
Merge decision for exact head The independent review published on this unchanged head concludes APPROVE and reports 37 passing real CLI/File/SQLite tests across the complete settlement-journey and canonical handoff-mode modules. The contribution is confined to one regression test module and its bilingual RFC checkpoint; it changes no runtime, authority policy, default, permission or UI behavior. Author premerge validation is now complete: all four direct checks, ten catalog canaries, eight risk-profile smokes and the public/private boundary scan passed. No failures, selected skips or manual holds were reported. Exact-scope change-quality receipt The real provider journey proves migration followed by fenced writing, idempotent settlement, replay preserving later writes, lease release and next-Turn admission. Existing fixture reuse is the bounded refactor; no new framework or duplicate production owner was introduced. This is enough for this coverage-only slice. Installed App/Lark, external Host effects, PostgreSQL, endurance and release-default qualification remain outside this diff; legacy runtime retirement remains open in the existing roadmap. The merge-readiness command returned ready for this head with no unresolved threads; it will be rechecked immediately before the authorized admin-bypass merge. |
Goal And Delivered Outcome
The ownership-policy migration suite tested preservation and individual edits, but did not prove that an Agent could settle a delivery and enter its next Turn after upgrading an existing Goal to
hard_lease.This adds that composed journey to the existing real CLI fixture on File and SQLite: backed-up migration, rejected unleased edit, leased write, returned settlement command and duplicate retry, migration replay after new work, lease release, and next-Turn admission. The old Markdown source is removed before work so it cannot hide a fallback dependency. The bilingual retirement checkpoint also records #5413/#5466 as merged and retains the outstanding preflight and creation-recovery work.
main.docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.mdat8b5335a72, “One reusable validation matrix” / “Mutation and ownership”.Scope And Continuation
Test and checkpoint update only; no runtime, policy, default, provider, or CLI contract change. Reuses the existing canonical-store fixture and settlement helpers rather than creating another harness. Existing helper defaults remain unchanged. The next implementation boundary remains Goal settings migration through the typed owner, followed by supported creation/upgrade adoption and last-caller deletion. A passing synthetic journey is not a release-default or sustained-operation certificate.
Validation
f1c3a1fdaa508bf5de27a47097229f467ea82312(same test content exercised before commit).uv run --extra test python -m pytest tests/control_plane/test_quota_authority_settlement_journey.py -k migrated_hard -q: both provider arms passed-k 'exact_selection_reaches or returned_command': 4 existing cases passed; no helper-default changetests/control_plane/test_canonical_handoff_mode.py -k 'reviewed or recovers_retired or provider_failure': 8 cases passed, including stale registration, original legacy receipt recovery and provider failure without fallbackloopx checkhad no errors and two unrelated existing registry warningsCoverage is the bounded CLI migration-to-next-Turn journey. No new PostgreSQL, installed frontend, external Host effect, crash injection or endurance qualification was run; none is claimed by this test-only diff. Frontend policy migration remains an explicit gap in the existing RFC package.
Frontend / Visual Evidence
UI impact: none. This only extends source CLI tests and the RFC checkpoint; no user interaction or capability activation is added. No screenshots are applicable.
Type of Change
LoopX Area
Shared-authority RFC fixture impact
Boundary Checklist