Skip to content

refactor(shadow): keep historical status independent of legacy capture - #6232

Merged
huangruiteng merged 3 commits into
mainfrom
codex/c1-shadow-readback-isolation-20261011
Oct 11, 2026
Merged

huangruiteng merged 3 commits into
mainfrom
codex/c1-shadow-readback-isolation-20261011

Conversation

@loopx-agent

Copy link
Copy Markdown
Collaborator

Goal And Delivered Outcome

authority-shadow status currently imports the legacy capture/drain producer even though it only reads history. Removing obsolete source modules therefore breaks retained operator diagnostics. This separates the historical filesystem codecs and candidate-read transport, so the existing status command works with those producers physically absent and preserves its complete response and original bytes.

Basis: accepted R5/T4 last-caller retirement and retained recovery duties. Intended base: main; implementation baseline adb247e5f3fac8e2e3f7152239955b49480d0b9f.

Author Declaration

  • Written by: model_agent, OpenAI GPT-6 family / Codex.
  • Specification: docs/architecture/rfcs/typescript-control-plane-migration-v0.md, revision adb247e5f3fac8e2e3f7152239955b49480d0b9f.
Criterion Disposition Owning path Decisive validation
T4: inventory real callers and retain necessary historical/effect IO implemented within this caller local_authority_shadow_history.py, local_authority_shadow_readback.py, status CLI Same source and installed CLI journeys with four whole capture modules absent
Validation and stop rules for every card implemented within this read-only refactor Existing typed read/drain owners and real filesystem codecs Immutable baseline counterexample, AST parity, File history, normal wheel, affected capture/drain and typed suites
Complete writer retirement and persistence/default qualification deferred Existing T4/shared-authority program Live writers, outbox disposition and installed adoption remain separate exits

Scope And Continuation

  • Move 25 unchanged function/class definitions into retained read modules; old producer imports remain aliases for existing live consumers, including cursor_path.
  • Status CLI loads readback directly; drain loads its existing orchestration only in the drain branch. Python retains historical filesystem decoding/presentation IO; TypeScript retains candidate proof, write/drain and receipt-proven cleanup authority.
  • Update the one registry codec census site and paired RFC/reference boundaries. Remove an unused private constant; no new capability, schema, provider, setting, Python decision owner or producer deletion.
  • This completes the historical status caller's dependency exit. Remaining live writer/capture callers and persistent obligations continue under existing T4. Reverting code restores the old import layout without rewriting data.

Validation

  • Tested revision: 999c1cb055b0b99c2356a0de58ece0581e4741a3 (candidate bytes unchanged across build/test and commits).
  • Run state: finished.
  • Input classes: synthetic, public_fixture; disposable runtimes only.
Check kind Result Evidence / limitation
real_entrypoint / real_backend passed test_shadow_readback_writer_isolation.py: 5 source + 5 normal-wheel journeys. Default-off absent/disabled/retired settings create no runtime; retained pending, residue, corrupt cursor/entry, damaged/missing candidate preserve results and original bytes after whole-module removal. Both canonical File/SQLite recipient contexts retain the original File candidate history; this does not add a SQLite shadow reader.
regression_parity passed The identical final oracle fails on the immutable baseline in all 5 absent-producer arms, after every producer-present invariant passes. All 25 moved definition ASTs are unchanged; each retained response and original byte inventory is compared across present/absent and repeated cold reads.
integration passed 81 affected native capture/drain/CLI/cursor/Goal-identity tests; existing writers, errors, delivery and recovery remain operational.
unit / static passed 44 related TS tests; complete control-plane suite 4400 passed, 37 PostgreSQL environment skips; typecheck, configured mypy19, dependency-aware typing of both new modules, changed Ruff, full semantic smoke and 10-path public scan.
static failed Extra standalone mypy with imports skipped: 3 pre-existing no-any-return diagnostics. Independent baseline/head use the same interpreter, configuration, options and logical owner inventory; complete diagnostics match under AST-symbol mapping for drain_lock_target, entry_identity, runtime_root_digest. The optional failure remains failed; required/configured and dependency-aware checks pass.
manual / packaging passed Standard frontend rebuild, normal wheel build/install, package/typed-runtime provenance and all changed runtime/manifest wheel bytes match candidate. Initial stale-bundle build rejection retained; no packaging bypass.

Coverage: actual status CLI and retained filesystem/candidate backend, compatibility aliases, active capture and drain, positive/negative read semantics and packaged absence are covered. Initial regression run caught a missing cursor_path alias; it was restored and the full affected set rerun. Initial test assumptions about the damaged candidate status and a response key were corrected against the existing typed/response contract before rerunning the final immutable-base/source/wheel oracle. This changes no PostgreSQL transaction; skipped PG checks remain unverified. No active Goal migration, destructive history cleanup or installed-user trial is claimed.

Frontend / Visual Evidence

UI impact: none. Existing CLI diagnostics change their import dependency; App/Lark interaction, prompt, help and first viewport are unchanged. No new caller-facing capability or configuration editor is introduced.

Type Of Change / Area

  • Refactoring, bug fix for producer-absent status, focused validation and documentation.
  • Control plane; R5/T4 retained IO and last-caller retirement.

Shared-authority RFC fixture impact

Production-scale fixture dimensions are unchanged: no transaction, authority route, selection, ordering, scope, activation or compatibility projection rule changes. Real retained File candidate reads and existing typed/capture/drain tests cover the affected IO. Canonical File/SQLite recipient initialization is synthetic and isolated. Promotion/legacy/File/PostgreSQL rehearsal is not applicable to this read-only module split; it is not a promotion/default qualification result.

Boundary Checklist

  • Public-safe code, synthetic tests and docs; no private Goal state, raw evidence, local paths, credentials or internal links in the diff or public artifacts.
  • No benchmark jobs or scoring changes.
  • Scoped to the historical status caller, with existing continuation owner.
  • UI impact none.
  • All three commits include DCO sign-off.

…oducers

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

未发现当前切片的阻塞项。Exact head: 999c1cb。

动机

在退役旧 Markdown 写入模块时,需要查询保留历史和待恢复记录的维护者。 status 是检查当前历史与恢复线索的既有只读命令;捕获和排空模块负责记录及送达写入事务。用原有 status 命令检查历史:此前即使只读,也会加载旧捕获和排空模块,模块移除后查询报错;本批改为直接加载保留的读取代码,原命令继续返回相同诊断。 真实源码和正常安装包均验证:旧生产模块物理缺席时仍能查询待处理、残留、损坏及缺失状态,并保留原始文件、身份和完整响应;重复冷启动查询也不产生写入。 本批不删除仍有调用方的生产模块,不迁移活动 Goal,不增加 SQLite shadow reader,也不改变默认 provider、历史格式或清理权限。 完整旧写入链路退役、试用和发布默认资格仍待现有 T4/持久性验收继续,不由此次只读查询通过替代。

改动思路

将同一份历史文件解码和只读传输从写入编排中移出,既解除真实查询依赖,又保留现有 TypeScript 证明与效果 owner;复制规则或增加空壳旧模块都会留下第二份维护成本。 当前 PR 完成历史 status 调用方的独立读取出口,并保留捕获、排空及旧导入别名供真实调用方使用;后续只有最后调用方和持久义务退出后才能删除生产模块。

保留空壳 producer 或复制 codecs 只会延长错误依赖;直接删除全部 writer 则破坏仍受支持的调用。该拆分复用原定义,将只读 IO、候选读取传输与真正写入效果区分开。Python 保留原始文件解码和 CLI 展示,TypeScript 继续拥有 binding、候选证明、排空和凭 receipt 清理的决策。没有新 provider、capability、schema、设置、RPC 或 Python 决策源;既有用户无需额外导航、开关或确认。

具体改动

独立规范依据:docs/architecture/rfcs/typescript-control-plane-migration-v0.md,变更前不可变修订 adb247e5f3fac8e2e3f7152239955b49480d0b9f。T4 的真实调用方检查与必要历史/effect IO 保留在本调用族内 implemented;完整 writer 退役没有完成。Validation and stop rules for every card 要求的独立正反例、真实 CLI/backend、基线/head、完整控制面检查和 canary 已执行。当前 RFC checkpoint 仅更新实际证据边界,不能反向定义本次验收。

关键代码讲解

  • handle_authority_shadow_command(loopx/cli_commands/authority_shadow.py:137)让 status 直接 import readback/history;只有 drain 分支加载原 adapter。原参数、错误处理、退出状态与 drain 验证保持。
  • list_entries(local_authority_shadow_history.py:297)继续遍历完整原始 prepared/committed 记录,检查身份、schema、digest 和孤立 marker,并按原 sequence 排序。outbox_summary(:464)继续保留 committed pending,即使 cursor 声称已到达该位置;cursor 不是送达证明。
  • local_authority_shadow_status(local_authority_shadow_readback.py:76)沿原 TS candidate read 返回完整结果;候选缺失时提前返回 missing,避免打开 store 时铸造新身份;损坏候选仍是 typed failed,transport 异常才映射 unavailable。

25 个函数/class 定义的 AST 与原位置完全相同。旧 outbox/adapter 只对真实消费者保留直接别名,不留第二份实现;cursor_path 包含在兼容导出中,未用私有常量删除。manifest 只移动一个 registry codec_read 位置。新增 153 行测试复用正常 source/wheel fixture;英文/中文 RFC 与 retirement reference 更新了查询出口和回退边界,未改首屏。

真实 CLI 流程含三种未启用配置,以及 canonical File/SQLite recipient 下保留的原 File shadow candidate。后者不是新的 SQLite shadow reader。每条流程先验证 producer 存在的独立不变量,再删除四个整模块和 legacy_mutation,比较完整响应及原始字节;保留 pending、prepared、cursor residue、损坏 cursor、异常 entry、损坏/缺失 candidate。重复冷启动查询仍只读。已有写入/排空调用另由完整受影响测试集验证。

对主干的风险

主要风险是搬迁中遗漏旧导出或改变错误语义。初次受影响测试捕获 cursor_path 别名遗漏,已恢复并重跑全部 81 项;另两处测试的损坏候选状态和响应 key 假设按既有 typed/响应契约纠正后,最终同一 oracle 在不可变 base、源码及 wheel 全部重跑。没有将生产 failed 改为 unavailable,也没有放宽历史有效性判断。

最终源码 5 条、正常 wheel 5 条、相关 TS44 项、完整控制面 4400 项通过;同一最终 oracle 在不可变 base 的全部 5 个模块缺席分支失败,且 producer 存在侧的独立断言先全部通过,证明回归测试能识别原缺陷。typecheck、配置内 mypy19、两新模块依赖感知 typing、最终 Ruff、全树 semantic smoke、10 路径 public scan 和原生 premerge5 direct+19 selected 通过,无 manual hold。wheel 中 6 个变化的 runtime/manifest 成员与 candidate 字节一致;最初 stale frontend bundle 拒绝构建保留,随后按标准流程重建 Chat bundle 并正常打包,未绕过验证。

额外 imports-skipped typing 仍失败三项:drain_lock_target、entry_identity、runtime_root_digest 的 no-any-return。在同一 interpreter/probe/configuration/options 与完整逻辑 owner inventory 上独立跑 base/head,全部诊断经 AST symbol 映射后内容一致,三处 return 表达式未改变;native CQR 接受该独立归因。此可选失败仍为失败,不能称全绿。完整 TS 另有 37 项 PostgreSQL 环境跳过,保留为未验证;此次不改 PG 事务或重新宣称其资格。

语义与 CI 对齐

已有 schema、默认配置、输入、prompt/help、scheduler/quota、身份及 receipt 契约保持。未启用配置下不创建 runtime;模块安装、旧开关或 canonical recipient 不是 capture 激活信号。保留历史只读不授予排空、恢复写入或清理权限;无新增 substring 分类。遵循当前 native wait_for_ci=false 策略,没有查询或等待 GitHub CI。检查最新主干的相邻变更与当前 owner 无语义交叠。

回退是撤销代码布局,不改原始数据、cursor、binding 或身份;现有 drain/recovery 路径保留。该 PR 不迁移活动 Goal,不做 live Host/cohort/default/D2 资格,不删除活跃生产模块或历史。未来重构已在本批消除原定义重复和错误依赖,完整 producer 删除仍按真实最后调用方验收。

我的整体评价

APPROVE,属于 justified_increment。long_horizon improved:后续重启仍可读原始历史和待处理记录,重复查询无副作用。user_experience improved:使用原命令即可读回状态,无需为只读检查重新安装旧生产模块。文字 diff 较大,实质为 25 个定义的机械搬迁、单一只读 owner 和直连 import;生产净增 67 行,没有投机框架。当前 PR 完成历史 status 调用方的独立读取出口,并保留捕获、排空及旧导入别名供真实调用方使用;后续只有最后调用方和持久义务退出后才能删除生产模块。 完整旧写入链路退役、试用和发布默认资格仍待现有 T4/持久性验收继续,不由此次只读查询通过替代。 可选 typing 原失败及环境跳过保持公开。运行行为 PR 留给维护者合并,此评审不授予 bypass 权限。

English verdict: APPROVE — 999c1cb. Retained status no longer imports legacy capture producers; original codecs and live capture/drain callers remain. Source5/normal-wheel5, affected81, typed44/full4400, static/semantic and native premerge pass; the same frozen-base oracle detects all5 absence failures. Three independently attributed optional baseline typing diagnostics remain failed;37 PG environment skips remain unverified. Full retirement, active-user adoption and release qualification remain separate.

@huangruiteng
huangruiteng merged commit a52c8c2 into main Oct 11, 2026
1 of 7 checks passed
@huangruiteng
huangruiteng deleted the codex/c1-shadow-readback-isolation-20261011 branch October 11, 2026 11:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants