Skip to content

fix(acceptance): reconcile Goal recreation lifecycle - #6030

Merged
huangruiteng merged 3 commits into
loopx-project:mainfrom
Duang777:codex/fix-acceptance-source-recreation-main
Oct 9, 2026
Merged

huangruiteng merged 3 commits into
loopx-project:mainfrom
Duang777:codex/fix-acceptance-source-recreation-main

Conversation

@Duang777

@Duang777 Duang777 commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Context

#5972 merged into the #5970 branch after #5970 had already merged into main. Its merge commit therefore never entered main. This PR is based on main@ec21f7da8. The current head is a9298415a, and its net diff keeps the same stable patch ID as #5972: 2338f748525b1cb2efa0b358722f4f47cb26f585.

Verification

  • Python lifecycle tests: 36 passed
  • Architecture tests: 12 passed
  • TypeScript acceptance tests: 49 passed, 19 skipped
  • Project registry manifest: 290 sites current
  • Ruff and control-plane typecheck passed
  • Risk-based premerge: 13 selected checks plus all direct checks passed

Signed-off-by: Duang777 <duangjl007@gmail.com>
…e-source-recreation-main

Signed-off-by: Duang777 <duangjl007@gmail.com>
loopx-agent
loopx-agent previously approved these changes Oct 9, 2026

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

动机

在 canonical authority 上维护、重建同名 Goal 的操作者。

把 Goal A 重建为同名 B 后,旧版会让 A 的验收配置继续显示为 B 的配置;本版保留 A 的历史验收,B 的验收默认为关闭,旧 A→B 请求重放也不会改写后来的 C。

已验证真实 project recreate-goal、File/SQLite canonical 读回、发布后恢复和锁竞争,并在隔离真实 PostgreSQL 上验证共享 TypeScript acceptance owner。

不激活完整 Goal identity profile,不迁移现有 Goal,也不授予执行、claim/lease、quota 或验收重绑定权限;完整 orphan/activation/产品恢复旅程仍保留原有资格门槛。

完整 activation/orphan 产品旅程及外部效果资格仍未关闭。

改动思路

源生命周期适配器负责锁与效果,canonical 生命周期仍由一个 TypeScript owner 裁决,避免 Python 重建第二个决策源。

当前边界是既有重建路径与 canonical 验收生命周期的接通,完整 profile 激活和 orphan 产品旅程仍由原阶段负责。

把 source lifetime 与既有 canonical acceptance owner 接通:源锁内关闭 admission 并绑定、退休 A,drain 后发布 B,再在保留源锁、释放 canonical writer 锁的范围内 reconcile。历史兼容始终把旧验收归给退休 A。

规范依据:docs/architecture/rfcs/goal-instance-identity-and-orphan-recovery-v0.md,不可变版本 ec21f7da8b9a861fa73477f0ad69e8a4f30e5389。已在阅读实现之前读此版本;对应当前有界改动的接受项如下:

  • History stays historical: A receipt/result cannot authorize or settle B; historical A readback stays available. implemented.
  • Commit race is fenced: A stale writer cannot perform a B-side write, debit, delivery or ownership change; isolated real provider for affected canonical paths. implemented.
  • Default-off parity: Non-activated legacy behavior remains unchanged; exact profile and existing authority remain independently fenced. implemented.
  • Product recovery is complete: Packaged frontend and qualified messaging recovery journey remains separately qualified. out_of_scope.

完整 activation/orphan/packaged frontend/Lark 资格仍按 RFC 原有阶段与 #5206 保留;本 PR 是已运行生命周期的有效增量,不代表父级验收关闭。

具体改动

审查了全部八文件(+751/-151),多数源生命周期 diff 为锁作用域重排。Python route 带 exact GoalRef;TS union 扩展 reconcile_recreated,空生命周期迁移把旧验收归 A,已处于 B 的重放保持当前状态。源锁和 canonical writer 锁的释放顺序避免嵌套重取;IO census 更新只对应实际调用位置。

独立验证:125 Python lifecycle/acceptance/race/architecture tests; 92 TS authority/runtime tests with File/SQLite/real PostgreSQL, zero skip; 165 semantic/registry census checks; TS typecheck; premerge five direct checks plus catalog/risk checks. Baseline four Python defect oracles fail; TS historical reconcile oracle 62 pass/6 expected failures/zero skip; H all pass.

额外完整 public project recreate-goal 对照覆盖 unpromoted、promoted disabled、legacy-enabled,按确切 A/B/C 关系验证新身份、原收据和 C 读回后仅归一化随机身份、临时路径和时间。unpromoted 全输出一致;B 不继承 A 的验收。A→B 旧请求在 C 后重放只返回历史 B,C 字节读回保持。真实 PostgreSQL 使用独立临时服务器、数据库和 tenant,未触及活动 Goal。

未来改动可维护性检查:本次保留一个 TS 生命周期决策 owner,复用 runtime-root 和稳定 phase operation-id helper;更大 source transaction 抽取不属于这个可回滚修复。

对主干的风险

No current material blocker found. 不激活完整 Goal identity profile,不迁移现有 Goal,也不授予执行、claim/lease、quota 或验收重绑定权限;完整 orphan/activation/产品恢复旅程仍保留原有资格门槛。 Old #5972 stacked approval is not inherited; this review independently checks the actual main reland. Full activation/orphan/frontend qualification remains with existing owner.

未查询、等待或继承 GitHub CI。全仓套件、真实模型对 guidance 的采纳和长期运行未做;受限 source_session profile 仍 execution_authority=false,通用 acceptance 命令仍按 profile 拒绝,未声称 UI/消息/完整恢复旅程验收。

我的整体评价

该精确 head 的当前有界结果成立,未发现阻塞缺陷,批准代码评审。合并仍是独立权限与仓库策略动作;本次不合并、不升级运行中的安装。

Reviewer: model_agent; runtime_reported; model=gpt-6.1-sol; provider=OpenAI; reasoning_effort=xhigh; execution_observation_id=de1d923ded17a66b1ad1ad14fa37aee1f64208c77ede42beac3b565c69abe4a5

English verdict: APPROVE - exact head a929841. Independently validated the whole current diff, real owning entrypoints/backends, recovery and baseline defect sensitivity; no CI was consulted. Parent profile/product qualification and merge authority remain separate.

@mergify

mergify Bot commented Oct 9, 2026

Copy link
Copy Markdown

This pull request has merge conflicts with main and cannot be merged
until they are resolved. Please rebase or merge the base branch, @Duang777.

Choose the remote for the base repository, not an out-of-date fork.
For a fork clone, first inspect git remote -v; upstream must point
to https://github.com/loopx-project/loopx.git. If it is absent, add it
with git remote add upstream https://github.com/loopx-project/loopx.git.
Then run:

git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEAD

For a same-repository clone whose origin points to
https://github.com/loopx-project/loopx.git, use origin instead of
upstream for fetch/rebase. If you prefer merging the base, use
git merge <base-remote>/main and push normally.

Keep the DCO Signed-off-by trailer on every commit when you rebase.
https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/syncing-a-fork

@mergify mergify Bot added the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 9, 2026
Signed-off-by: Duang777 <duangjl007@gmail.com>
@mergify mergify Bot removed the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 9, 2026

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh

APPROVE:当前完整版本未发现阻塞缺陷。精确 head 3ce93d4a10092a2ab6433a17c598b2c4c89ec28b;实际 merge base 55254bdceb89f8c1fff0aeefd110102afb911ccb。

动机

在 canonical authority 上维护、重建同名 Goal 的操作者。把 Goal A 重建为同名 B 后,旧版会让 A 的验收配置继续显示为 B 的配置;本版保留 A 的历史验收,B 的验收默认为关闭,旧 A→B 请求重放也不会改写后来的 C。已在当前完整精确版本验证真实 project recreate-goal、File/SQLite 读回、发布后恢复与锁竞争,以及隔离真实 PostgreSQL 的共享 TypeScript owner。 不激活完整 Goal identity profile,不迁移现有 Goal,也不授予执行、claim/lease、quota 或验收重绑定权限;完整 orphan/activation/产品恢复旅程仍保留原有资格门槛。完整 activation/orphan 产品旅程、packaged frontend/Lark 和外部效果资格仍未关闭。 这使同名重建有可恢复的验收隔离结果,避免操作者把上一生命周期的证明误认作当前要求已经完成;本次只批准这段实际可用增量。

改动思路

源生命周期适配器负责锁与效果,canonical 生命周期仍由一个 TypeScript owner 裁决,避免 Python 重建第二个决策源。 当前边界是既有重建路径与 canonical 验收生命周期的接通,完整 profile 激活和 orphan 产品旅程仍由原阶段负责。 比不改动更有价值的是让重建与旧验收的身份一致性一起成立;只清空一个展示字段会丢失历史证明,也不能保护重放与并发 writer。源锁先关闭 admission 并 bind/retire A,实际 effect drain 后发布 B;释放 canonical writer 锁后、保留 source lifetime 锁再 reconcile,避免嵌套重取锁。相同 operation 在发布后出错可恢复;已经出现 C 时的旧 A→B 请求只读取历史回执。

具体改动

依据 docs/architecture/rfcs/goal-instance-identity-and-orphan-recovery-v0.md,固定规范 revision 55254bdceb89f8c1fff0aeefd110102afb911ccb;与先前读过的规范字节完全相同,当前 roadmap 的 T4 只更新了共享 paths owner 的已交付 checkpoint。逐项映射:History stays historical、Commit race is fenced、Default-off parity 在本有界源生命周期均 implemented;Product recovery is complete 为 out_of_scope,继续保留 RFC/#5206 原资格。作者 PR Context 仍列旧 head,未作为本次版本或验收证明。

关键代码讲解

  1. acceptance.py:32 的 _routing 从源注册记录解析现有 exact GoalRef,避免把 alias 当 lifetime。current main 的 runtime-root 路由复用 paths.effective_runtime_root,没有第二个 capture/路径 owner。transition_goal_acceptance_lifecycle 只对已 promoted 的 canonical authority 发一个粗粒度 TS 请求。
  2. acceptance_authority.ts:283 的 planLifecycleTransition 扩展现有 union 的 reconcile_recreated;无 lifecycle 的历史验收绑定退休 A,新 B 保持 off;已经是目标 successor 时 no_change,不能复活正在退休的 B。CAS 与收据仍归原 canonical owner。
  3. source_session_recreation.py:335 的 recreate_goal_instance 调整上述锁作用域和实际 bind/retire/reconcile 效果,稳定 phase operation-id 支持发布后恢复。完整八文件 +752/-152 同时包含 IO manifest 的实际调用位置、新增 404 行 File/SQLite 回归、已有真实 writer race 调整及 TS provider cases;没有隐藏新增设置或 UI。

对主干的风险

141 Python lifecycle/acceptance/race/architecture tests; 432 TS authority/runtime and real PostgreSQL store integration tests, zero skips; 151 semantic/IO-census tests; TS typecheck, Ruff, diff hygiene and premerge five direct plus 13 selected checks pass. Six current-base File/SQLite acceptance defect assertions fail and six current-head cases pass; complete native CLI A/B/C readbacks preserve old receipts and current C. PostgreSQL 使用独立一次性服务器、数据库和每项独立 tenant,版本 16.15,测试后已停止;未触及活动 Goal。完整 CLI 对照含 unpromoted、promoted-disabled、legacy-enabled 三个场景:只归一化临时路径、时间、明确 A/B/C 随机身份及绑定 B 的请求 digest,先独立断言原收据与 C 全读回相等。unpromoted 全输出相等;promoted off 增加有意的 inert lifecycle 元数据;B 不继承 A 的验收。

初次验证调用写错测试路径与 premerge 参数,分别没有执行测试和检查;修正后使用当前仓库入口完成上述验证,未把调用错误说成产品修复。没有查询或等待 CI。完整 packaged frontend/Lark、激活、orphan 恢复、长期运行和真实模型采纳没有验证;这段增量没有改变它们的既有资格门槛。

语义与 CI 对齐

复用既有 GoalRef、acceptance lifecycle 和 schema,只在原 TS vocabulary 中增加 reconcile transition;Python 负责源/锁/效果适配,不重新裁决状态。development advisory 未识别新 carrier,其局限不覆盖 TS union,不能当语义等价证明;完整语义/census 检查与真实 producer/consumer 回归通过。强制身份与 writer fence 是执行规则,不能称可忽略 guidance,也不能由验收读回授予执行权。

我的整体评价

long_horizon 与 user_experience 在本生命周期增量均 improved:一次同名重建产生正确的新验收边界,原 operation 可恢复,晚到的旧重放不破坏后续工作。完整 profile/product 资格仍未关闭,未继承旧 head 的 APPROVE。源生命周期适配器负责锁与效果,canonical 生命周期仍由一个 TypeScript owner 裁决,避免 Python 重建第二个决策源。 当前边界是既有重建路径与 canonical 验收生命周期的接通,完整 profile 激活和 orphan 产品旅程仍由原阶段负责。 未来改动通过一个 TS owner、稳定 phase key 和共享路径 owner 更容易定位;更宽的 source transaction 抽取没有必要加入这个可回滚修复。可批准此精确 head;合并、升级和父级业务验收仍是独立动作。

English verdict: APPROVE - 3ce93d4; whole current diff, exact source/canonical lifecycle, real File/SQLite CLI recovery and isolated PostgreSQL 16.15 validated. 141 Python, 432 TS/provider and 151 semantic tests pass; six base assertions fail and the same six head cases pass. Premerge 5 direct +13 selected checks pass; CI not consulted. Full profile, packaged product adoption and merge authority remain separate.

@Duang777 Duang777 mentioned this pull request Oct 9, 2026
8 of 17 tasks
@Duang777

Duang777 commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator Author

The Optional Ark 3.11 failure is baseline test-contract drift, not a regression from this PR. The exact case fails on the PR base, this head, and current main because ordinary JSON Todo inventories may use response-local references in duplicate lane views. #6041 updates the stale Ark assertion to read the canonical todos inventory; its Python 3.11 exact case, complete Ark file, and dedicated reference-contract tests pass. I did not rerun CI, sync this branch, or change this PR.

@huangruiteng
huangruiteng merged commit 8a38ce4 into loopx-project:main Oct 9, 2026
21 of 37 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants