docs: preserve recovery and I/O contracts during canonical retirement - #5771
loopx-agent wants to merge 1 commit into
Conversation
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; xhigh
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
未发现阻塞项;结论 APPROVE,针对 exact head e4dde47c1c883f07899d86c126d2673c3c449ffe。
动机
准备删除旧 Python 逻辑的维护者需要判断哪些代码仍服务真实调用方。 此前 canonical 写入成功可能被误当作旧 writer 已无调用;现在维护者能逐族看到保留理由、替代 owner 和删除前必须核验的实际入口。 指南把 source writer、capture/outbox、传输、恢复 reader 与兼容 facade 分开,并明确每一族的删除条件。 本 PR 不切换默认、不迁移活跃 Goal,也不删除运行时代码。 代码删除、安装态旧路径缺席、SQLite 长期使用及 App 升级仍由现有退役与发布验收负责。
改动思路
沿用既有 provider-selection 指南及 TS 单一决策 owner,把 source writer、capture/outbox、精确字节传输、恢复 reader 和兼容输入区分开。canonical 写入绕过源分支不能证明未迁移调用方已退出;Python 的锁、文件与进程 I/O 也不应因为语言而被丢弃。反向迁移保留新写入,历史回执只用于恢复原操作。没有新切换项、producer、receipt 或控制规则。
具体改动
关键内容讲解
docs/reference/local-authority-provider-selection.md 在现有正文尾部增加五行保留边界表,每行给出当前作用、typed owner 与删除条件。local_authority_shadow_projection.py 的精确数字、安全文件读取和摘要检查是传输价值;outbox 的 prepare→主写入→commit 与 cursor 恢复是持久化价值;authority_core.py 的已登记输入兼容不能凭零外部 import 删除。
独立规范:docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md,revision 8251ec80e0c327d28d13a1fd64e3f343a2aa3c0e。Deletion proof:implemented in documentation,列出动态/打包调用与旧路径实际不存在的验收,未宣称本批已通过缺席证明。Historical formats and receipts:implemented in documentation,保留受支持的备份、原回执和恢复 reader。Canonical creation/default adoption; D3/T3:out_of_scope,既有 default-off/opt-in 与正式默认资格未改。所有 criterion 都按已有规范解释,不重写它来匹配本 PR。
对主干的风险
最强反例是现有 File 回归全绿,但安装态 SQLite/App 或最后动态调用仍不合格;追加正文明确拒绝把前者当后者。全 diff 只有文档,不影响 first viewport、Settings、前端/Lark/CLI、权限、quota 或 scheduler。53 项保留回归通过,含真实隔离 File CLI/native 的中断写入与游标恢复;传输坏输入属于注入故障,未冒充安装态证明。
最终 premerge 的 12 项选择检查与 3 项 direct 检查通过,链接与公开边界检查通过。首次 gate 因旧范围 CQR 被拒;两次结果引用输入被拒后,按 packet 允许的 evidence ref 修正,生成当前 head/base 的独立回执 cqr_78a94ae34883c92ac202,再通过 gate。未降低检查。当前契约 wait_for_ci=false,未查询或轮询 CI。SQLite 长期、真实 PostgreSQL、打包 App 和旧路径缺席仍 not_run,不影响这份文档说明的范围。
我的整体评价
这是 justified_increment:风险映射能支持下一批退役,代码和发布默认验收继续留在既有程序。long_horizon 为 preserved(执行与恢复 owner 未改),user_experience 为 improved(维护者能定位保留价值与删除条件,不增加操作步骤)。未来重构 pass 复用既有 owner 和回归;新增 runtime abstraction 无必要。只引用既有词汇,不新增共享状态分类。文档可以独立撤回;不能据此结算整个 Goal、宣布 SQLite 默认或批量删 Python。
English verdict: APPROVE - e4dde47; actionable preservation boundaries match live source/recovery responsibilities. Documentation only; 53 bounded preservation regressions and final 12-check/3-direct premerge pass. Installed absence, sustained SQLite, PostgreSQL and packaged App qualification remain separate.
SQLite-default work can mistake a bypassed canonical source writer for an unused compatibility path. That can discard exact-byte transport, interrupted capture or historical recovery which supported callers still need.
Extend the existing provider-selection reference with five concrete retained caller families, their typed owners and the evidence needed before removal. The bilingual guidance keeps last-caller deletion independent, preserves supported recovery, and distinguishes bounded regressions from release-default qualification. No runtime, default, protocol, permission or UI behavior changes.
Author Declaration
docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.mdat base8251ec80e0c327d28d13a1fd64e3f343a2aa3c0e.Validation
8251ec80e0c327d28d13a1fd64e3f343a2aa3c0e; final documentation commite4dde47c1c883f07899d86c126d2673c3c449ffehas identical runtime bytes.tests/control_plane/:test_source_projection.py,test_source_transfer.py,test_local_authority_shadow_outbox.py, bounded source lineage/promotion/restart tests, failed-primary-write capture and abandoned-cursor recovery. Transport faults are injected; source/recovery cases run real CLI/native writers against disposable File stores.The future-facing pass maps existing owners rather than adding another decision layer or a parallel roadmap. This completes the preservation guidance; the existing retirement program retains implementation and release acceptance. No new follow-up issue is needed. Frontend/Lark/CLI, first viewport and configuration are unchanged. No runtime tests or scaffolding are added.
main.