Skip to content

test(coordination): qualify settlement after ownership policy migration - #5503

Merged
huangruiteng merged 1 commit into
mainfrom
codex/handoff-policy-retirement-1003
Oct 3, 2026
Merged

huangruiteng merged 1 commit into
mainfrom
codex/handoff-policy-retirement-1003

Conversation

@huangruiteng

Copy link
Copy Markdown
Collaborator

Goal And Delivered Outcome

The ownership-policy migration suite tested preservation and individual edits, but did not prove that an Agent could settle a delivery and enter its next Turn after upgrading an existing Goal to hard_lease.

This adds that composed journey to the existing real CLI fixture on File and SQLite: backed-up migration, rejected unleased edit, leased write, returned settlement command and duplicate retry, migration replay after new work, lease release, and next-Turn admission. The old Markdown source is removed before work so it cannot hide a fallback dependency. The bilingual retirement checkpoint also records #5413/#5466 as merged and retains the outstanding preflight and creation-recovery work.

  • Basis: shared-authority R3/R5 and TS retirement T4; intended base main.
  • Written by: model_agent — OpenAI Codex.
  • Specification: docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md at 8b5335a72, “One reusable validation matrix” / “Mutation and ownership”.
Criterion Disposition Evidence
Migration retains ownership facts but grants no execution implemented in this validation slice Rejection before lease acquisition; subsequent real leased edit
Original operations settle once and allow later work implemented in this validation slice Duplicate spend stays one debit; old migration replay preserves the edited Todo; next Turn runs
Supported migration UI, installed consumers and final legacy deletion deferred, existing two-policy package remains open Existing RFC acceptance is unchanged; this PR supplies one missing caller qualification

Scope And Continuation

Test and checkpoint update only; no runtime, policy, default, provider, or CLI contract change. Reuses the existing canonical-store fixture and settlement helpers rather than creating another harness. Existing helper defaults remain unchanged. The next implementation boundary remains Goal settings migration through the typed owner, followed by supported creation/upgrade adoption and last-caller deletion. A passing synthetic journey is not a release-default or sustained-operation certificate.

Validation

  • Tested revision: f1c3a1fdaa508bf5de27a47097229f467ea82312 (same test content exercised before commit).
  • Run state: finished.
  • Input classes: public_fixture, synthetic.
  • Runtime: Python 3.13.13, Node 24.21.0; isolated real File store and SQLite 3.53.4.
Check kind Result Evidence / limitation
real_entrypoint / real_backend passed uv run --extra test python -m pytest tests/control_plane/test_quota_authority_settlement_journey.py -k migrated_hard -q: both provider arms passed
real_entrypoint passed Same module, -k 'exact_selection_reaches or returned_command': 4 existing cases passed; no helper-default change
real_entrypoint / real_backend passed tests/control_plane/test_canonical_handoff_mode.py -k 'reviewed or recovers_retired or provider_failure': 8 cases passed, including stale registration, original legacy receipt recovery and provider failure without fallback
static passed Compile check, diff whitespace check and public-boundary scan; loopx check had no errors and two unrelated existing registry warnings
static passed Diff semantic advisory: no new production vocabulary; this is not a semantic-equivalence proof

Coverage is the bounded CLI migration-to-next-Turn journey. No new PostgreSQL, installed frontend, external Host effect, crash injection or endurance qualification was run; none is claimed by this test-only diff. Frontend policy migration remains an explicit gap in the existing RFC package.

Frontend / Visual Evidence

UI impact: none. This only extends source CLI tests and the RFC checkpoint; no user interaction or capability activation is added. No screenshots are applicable.

Type of Change

  • Test update
  • Documentation update

LoopX Area

  • Control plane (goals, todos, quota, scheduler, registry, runtime)

Shared-authority RFC fixture impact

  • Reuses the existing synthetic canonical Todo fixture, including a selected task beyond the default display window.
  • Composes existing policy, lease and settlement semantics without changing their definitions.
  • Provider arms: real File and SQLite. No promotion/runtime-routing/compatibility-projection source changes; a new PostgreSQL rehearsal is not required for this fixture-only change.

Boundary Checklist

  • No private Goal state, raw logs, credentials, local paths or internal links in the diff or this description.
  • No unrelated benchmark work.
  • Scope remains the migration-to-settlement validation gap.
  • UI impact is none.
  • Commit includes DCO sign-off.

Signed-off-by: huangruiteng <huangrt01@163.com>

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Reviewer: model_agent | GPT-5 | OpenAI

English verdict: APPROVE

Exact head: 5503@f1c3a1fdaa508bf5de27a47097229f467ea82312; immutable baseline: 8b5335a72df3be1a9d177bfe1e293cafdcbfd384. 作者账号只能发布 COMMENTED 结论,不是 GitHub 正式自批准。按当前 capability 做完整 docs-and-smoke review,未获取、轮询或等待 CI。

动机

维护者需要知道:把一个已有 Goal 的所有权策略迁到 hard lease 后,Agent 是否还能合法修改任务、结算本轮并进入下一轮。

原来迁移、租约和结算分别有测试,但没有把迁移后的这些步骤连在同一次真实操作中验证;现在同一 File/SQLite Goal 先迁移,再拒绝无租约修改、允许带租约写入,执行 CLI 返回的结算命令,重试不重复扣额,迁移重放不丢失新写入,下一轮仍能选择原任务。

本轮在精确 head 上运行真实 CLI 和隔离 File/SQLite,相关两套完整测试 37 项通过。新增旅程移除了 Markdown 来源,比较重放前后的完整 Todo,并验证只有一笔 spend;这补上了迁移后继续工作的集成证据。

没有修改生产规则或自动迁移任何运行中的 Goal;不宣称 PostgreSQL、打包 App/Lark、安装采用、性能、崩溃恢复或长期运行验收已完成。

安装态消费者、带新写入的 provider 往返恢复、性能与持续运行仍由既有 R3/R5/D1–D3/T0–T4 交付路径验收;这份 source 测试不关闭这些主线。

成功生成迁移计划、持有租约或得到一张结算回执,单独都不能证明下一次工作可继续。这份测试的价值是补齐同一次旅程的交叉边界,不是增加测试数量或制造新的退休完成标签。

改动思路

不新增生产规则、开关或 authority owner。复用原 handoff-mode 迁移、task lease、canonical Todo writer 和结算链;既有 _source 只增加可选 handoff_mode 参数,默认值不变。两种真实 backend 的同一链路先迁移、再修改、再结算、最后读回和下一轮准入;Python 在这里是原 CLI 集成测试,不是新增通用控制面决策源。

具体改动

全部三文件、+89/-18:一个既有测试模块和两份英/中文退休 checkpoint。书面基准是 docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md,spec_revision 8b5335a72df3be1a9d177bfe1e293cafdcbfd384,使用修改前的验收矩阵,不以本 PR 新添的证据行自证。

  • Mutation and ownership:implemented,本次验证已有 claim 的策略迁移→无租约写拒绝→原租约写入→quota/refresh/返回的 spend→重试一次→下一轮工作。其他 CRUD/竞争与旧 epoch 项不因这两臂被宣告全面完成。
  • Interruption and recovery:deferred,重试和保留新写入得到本次证据;完整崩溃、provider、子进程停止等仍归原恢复验收。
  • Installed consumers:deferred,未执行打包 App/Lark/安装运行时采用,不用 source 测试代替它们。

关键内容讲解

  • test_quota_authority_settlement_journey.py:134 的 test_migrated_hard_lease_can_write_settle_retry_and_continue:分别在 File/SQLite 创建合成 canonical legacy Goal,迁移到 hard_lease,并移除临时 Markdown。后面的命令不能偷用旧 Markdown writer。
  • 原 _execute 将 refresh 返回的命令原样拆成 argv;不额外补 actor/Todo/Turn 绑定来让测试通过。第一次 spend appended=true,重试 false,实际 history 只有一笔。
  • 对新写入后的迁移重放,不只比数量或 hash,而是先单独 list 读完整 Todo、确认新文本,再比重放后的完整对象;释放原租约后新 Turn 选择原身份,且不是 unsettled recovery。
  • 双语 checkpoint 同步纠正 #5413/#5466 的 merged 状态、保留 #5283 的冷 CLI 失败以及 #5500 的创建恢复前置边界,移除固定“剩余三 PR”说法。独立 GitHub metadata 读回证实前两项已合并;合并与 installed qualification 仍明确分开。

独立执行:uv run --extra test python -m pytest -q tests/control_plane/test_quota_authority_settlement_journey.py tests/control_plane/test_canonical_handoff_mode.py,37 passed,无跳过。包含新两臂及邻接的 terminal/blocked/absent、排除、同伴 claim、缺 capability、canonical provider 不可用和策略迁移测试。差异词汇 advisory 先于全树 semantic drift;之后 Ruff、配置的 19-source mypy 与 diff check 均通过。没有修改断言、提高 timeout 或改写旧失败记录。

对主干的风险

主要风险是把“迁移成功”误报为“执行和退休完成”,或重放迁移覆盖后来的写入。本测试跨真实 CLI/原 store 检查无租约拒绝、合法写入、结算幂等和新写入保留;邻接负例继续 fail closed。没有 runtime 改动,因此不产生新的默认行为、TS/Python双决策、权限或 schema 迁移。也未把 hard-lease enforced 拒绝叫成可忽略 guidance。

前端、Lark、CLI:只改变 source CLI 的回归覆盖;没有新用户入口或配置。生产 UI 未改变,未宣称 packaged journey 已验证;PostgreSQL writer 未触及,不以 File/SQLite 测试充当 PostgreSQL 证据。性能、长期运行和部署身份仍是已有路径的未验证部分。

可维护性检查:新增旅程放在已有 settlement 测试与 shared fixture 内,不另建 runner;邻近规则仍由原 typed owner 决定。近期同作者批次有不同已证实缺口,没有发现重复同形 smoke 或仅测试字段存在的批量脚手架。本次相关小重构已落实为 fixture 参数复用;没有更大的生产重构需要捆绑进来。

我的整体评价

APPROVE 这个 justified_increment。long_horizon improved:补上策略迁移后结算/重放/下一轮的真实交叉边界,并让原 checkpoint 保持当前事实。user_experience improved 是间接保障 Agent 日常续跑,不是新 UI 或已安装改善。

这是可独立审查、可撤销的 source qualification;不关闭 R3/R5/D1–D3/T0–T4,也不新增仪式性后续任务。没有本次 scoped blocker。发布后仍执行 approval-closeout;只有逐项证明旧 finding 已修复/反证且有权限才撤销旧阻塞评审,不自动合并或迁移运行中的 Goal。

@huangruiteng

Copy link
Copy Markdown
Collaborator Author

Merge decision for exact head f1c3a1fdaa508bf5de27a47097229f467ea82312: eligible for the repository's authorized tests/docs-only self-merge path.

The independent review published on this unchanged head concludes APPROVE and reports 37 passing real CLI/File/SQLite tests across the complete settlement-journey and canonical handoff-mode modules. The contribution is confined to one regression test module and its bilingual RFC checkpoint; it changes no runtime, authority policy, default, permission or UI behavior.

Author premerge validation is now complete: all four direct checks, ten catalog canaries, eight risk-profile smokes and the public/private boundary scan passed. No failures, selected skips or manual holds were reported. Exact-scope change-quality receipt cqr_bb94efc3fe5b6927d7b4 remains valid against 8b5335a72. DCO and a separate added-line private-material scan are clean. Goal policy sets wait_for_ci=false; remote CI was not queried or represented as passing.

The real provider journey proves migration followed by fenced writing, idempotent settlement, replay preserving later writes, lease release and next-Turn admission. Existing fixture reuse is the bounded refactor; no new framework or duplicate production owner was introduced. This is enough for this coverage-only slice. Installed App/Lark, external Host effects, PostgreSQL, endurance and release-default qualification remain outside this diff; legacy runtime retirement remains open in the existing roadmap. The merge-readiness command returned ready for this head with no unresolved threads; it will be rechecked immediately before the authorized admin-bypass merge.

@huangruiteng
huangruiteng merged commit d74554b into main Oct 3, 2026
24 of 31 checks passed
@huangruiteng
huangruiteng deleted the codex/handoff-policy-retirement-1003 branch October 3, 2026 01:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant