Skip to content

docs: preserve recovery and I/O contracts during canonical retirement - #5771

Open
loopx-agent wants to merge 1 commit into
mainfrom
codex/canonical-retirement-preservation-guide
Open

loopx-agent wants to merge 1 commit into
mainfrom
codex/canonical-retirement-preservation-guide

Conversation

@loopx-agent

Copy link
Copy Markdown
Collaborator

SQLite-default work can mistake a bypassed canonical source writer for an unused compatibility path. That can discard exact-byte transport, interrupted capture or historical recovery which supported callers still need.

Extend the existing provider-selection reference with five concrete retained caller families, their typed owners and the evidence needed before removal. The bilingual guidance keeps last-caller deletion independent, preserves supported recovery, and distinguishes bounded regressions from release-default qualification. No runtime, default, protocol, permission or UI behavior changes.

Author Declaration

  • Written by: model_agent — gpt-6.1-sol (OpenAI).
  • Specification: docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md at base 8251ec80e0c327d28d13a1fd64e3f343a2aa3c0e.
Criterion Disposition Evidence
Retire by last caller, preserving supported historical recovery implemented in documentation Source/producer/reader/transport/compatibility table and absence/recovery instructions
Separate trial, sustained provider qualification and release default implemented in documentation Existing opt-in/default guidance retained; new appendix names evidence limits
Delete remaining source writers or change the release default out_of_scope Requires corresponding caller migration and installed absence qualification

Validation

  • Tested revision: base 8251ec80e0c327d28d13a1fd64e3f343a2aa3c0e; final documentation commit e4dde47c1c883f07899d86c126d2673c3c449ffe has identical runtime bytes.
  • Run state: finished. Inputs: synthetic and public_fixture.
Check kind Result Evidence / limitation
static passed Relative links, full diff, public/private scan, semantic advisory and DCO. No new source vocabulary.
unit / real_entrypoint / real_backend passed 53 selected preservation regressions under tests/control_plane/: test_source_projection.py, test_source_transfer.py, test_local_authority_shadow_outbox.py, bounded source lineage/promotion/restart tests, failed-primary-write capture and abandoned-cursor recovery. Transport faults are injected; source/recovery cases run real CLI/native writers against disposable File stores.
manual passed Caller and typed-owner inspection; source writer, outbox, transport, reader and registered lease-mode compatibility remain live or explicitly supported.
static failed → requalified Initial premerge checks passed, but the aggregate gate rejected a previous-scope quality receipt. A new exact-scope review receipt replaces it; final premerge passes all 12 selected checks and 3 direct checks with no advisory skip.
integration not_run New SQLite sustained qualification, real PostgreSQL, packaged App and installed old-path-absence qualification are not claimed by this documentation change.

The future-facing pass maps existing owners rather than adding another decision layer or a parallel roadmap. This completes the preservation guidance; the existing retirement program retains implementation and release acceptance. No new follow-up issue is needed. Frontend/Lark/CLI, first viewport and configuration are unchanged. No runtime tests or scaffolding are added.

  • Documentation update; public docs / shared-authority retirement.
  • Public/private boundary checked; no private state, local paths, raw logs or credentials published.
  • DCO sign-off; dedicated branch from latest fetched main.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; xhigh
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

未发现阻塞项;结论 APPROVE,针对 exact head e4dde47c1c883f07899d86c126d2673c3c449ffe。

动机

准备删除旧 Python 逻辑的维护者需要判断哪些代码仍服务真实调用方。 此前 canonical 写入成功可能被误当作旧 writer 已无调用;现在维护者能逐族看到保留理由、替代 owner 和删除前必须核验的实际入口。 指南把 source writer、capture/outbox、传输、恢复 reader 与兼容 facade 分开,并明确每一族的删除条件。 本 PR 不切换默认、不迁移活跃 Goal,也不删除运行时代码。 代码删除、安装态旧路径缺席、SQLite 长期使用及 App 升级仍由现有退役与发布验收负责。

改动思路

沿用既有 provider-selection 指南及 TS 单一决策 owner,把 source writer、capture/outbox、精确字节传输、恢复 reader 和兼容输入区分开。canonical 写入绕过源分支不能证明未迁移调用方已退出;Python 的锁、文件与进程 I/O 也不应因为语言而被丢弃。反向迁移保留新写入,历史回执只用于恢复原操作。没有新切换项、producer、receipt 或控制规则。

具体改动

关键内容讲解

docs/reference/local-authority-provider-selection.md 在现有正文尾部增加五行保留边界表,每行给出当前作用、typed owner 与删除条件。local_authority_shadow_projection.py 的精确数字、安全文件读取和摘要检查是传输价值;outbox 的 prepare→主写入→commit 与 cursor 恢复是持久化价值;authority_core.py 的已登记输入兼容不能凭零外部 import 删除。

独立规范:docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md,revision 8251ec80e0c327d28d13a1fd64e3f343a2aa3c0e。Deletion proof:implemented in documentation,列出动态/打包调用与旧路径实际不存在的验收,未宣称本批已通过缺席证明。Historical formats and receipts:implemented in documentation,保留受支持的备份、原回执和恢复 reader。Canonical creation/default adoption; D3/T3:out_of_scope,既有 default-off/opt-in 与正式默认资格未改。所有 criterion 都按已有规范解释,不重写它来匹配本 PR。

对主干的风险

最强反例是现有 File 回归全绿,但安装态 SQLite/App 或最后动态调用仍不合格;追加正文明确拒绝把前者当后者。全 diff 只有文档,不影响 first viewport、Settings、前端/Lark/CLI、权限、quota 或 scheduler。53 项保留回归通过,含真实隔离 File CLI/native 的中断写入与游标恢复;传输坏输入属于注入故障,未冒充安装态证明。

最终 premerge 的 12 项选择检查与 3 项 direct 检查通过,链接与公开边界检查通过。首次 gate 因旧范围 CQR 被拒;两次结果引用输入被拒后,按 packet 允许的 evidence ref 修正,生成当前 head/base 的独立回执 cqr_78a94ae34883c92ac202,再通过 gate。未降低检查。当前契约 wait_for_ci=false,未查询或轮询 CI。SQLite 长期、真实 PostgreSQL、打包 App 和旧路径缺席仍 not_run,不影响这份文档说明的范围。

我的整体评价

这是 justified_increment:风险映射能支持下一批退役,代码和发布默认验收继续留在既有程序。long_horizon 为 preserved(执行与恢复 owner 未改),user_experience 为 improved(维护者能定位保留价值与删除条件,不增加操作步骤)。未来重构 pass 复用既有 owner 和回归;新增 runtime abstraction 无必要。只引用既有词汇,不新增共享状态分类。文档可以独立撤回;不能据此结算整个 Goal、宣布 SQLite 默认或批量删 Python。

English verdict: APPROVE - e4dde47; actionable preservation boundaries match live source/recovery responsibilities. Documentation only; 53 bounded preservation regressions and final 12-check/3-direct premerge pass. Installed absence, sustained SQLite, PostgreSQL and packaged App qualification remain separate.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant