Repository navigation
refactor(shadow): keep historical status independent of legacy capture - #6232
Conversation
…oducers Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
未发现当前切片的阻塞项。Exact head: 999c1cb。
动机
在退役旧 Markdown 写入模块时,需要查询保留历史和待恢复记录的维护者。 status 是检查当前历史与恢复线索的既有只读命令;捕获和排空模块负责记录及送达写入事务。用原有 status 命令检查历史:此前即使只读,也会加载旧捕获和排空模块,模块移除后查询报错;本批改为直接加载保留的读取代码,原命令继续返回相同诊断。 真实源码和正常安装包均验证:旧生产模块物理缺席时仍能查询待处理、残留、损坏及缺失状态,并保留原始文件、身份和完整响应;重复冷启动查询也不产生写入。 本批不删除仍有调用方的生产模块,不迁移活动 Goal,不增加 SQLite shadow reader,也不改变默认 provider、历史格式或清理权限。 完整旧写入链路退役、试用和发布默认资格仍待现有 T4/持久性验收继续,不由此次只读查询通过替代。
改动思路
将同一份历史文件解码和只读传输从写入编排中移出,既解除真实查询依赖,又保留现有 TypeScript 证明与效果 owner;复制规则或增加空壳旧模块都会留下第二份维护成本。 当前 PR 完成历史 status 调用方的独立读取出口,并保留捕获、排空及旧导入别名供真实调用方使用;后续只有最后调用方和持久义务退出后才能删除生产模块。
保留空壳 producer 或复制 codecs 只会延长错误依赖;直接删除全部 writer 则破坏仍受支持的调用。该拆分复用原定义,将只读 IO、候选读取传输与真正写入效果区分开。Python 保留原始文件解码和 CLI 展示,TypeScript 继续拥有 binding、候选证明、排空和凭 receipt 清理的决策。没有新 provider、capability、schema、设置、RPC 或 Python 决策源;既有用户无需额外导航、开关或确认。
具体改动
独立规范依据:docs/architecture/rfcs/typescript-control-plane-migration-v0.md,变更前不可变修订 adb247e5f3fac8e2e3f7152239955b49480d0b9f。T4 的真实调用方检查与必要历史/effect IO 保留在本调用族内 implemented;完整 writer 退役没有完成。Validation and stop rules for every card 要求的独立正反例、真实 CLI/backend、基线/head、完整控制面检查和 canary 已执行。当前 RFC checkpoint 仅更新实际证据边界,不能反向定义本次验收。
关键代码讲解
handle_authority_shadow_command(loopx/cli_commands/authority_shadow.py:137)让 status 直接 import readback/history;只有 drain 分支加载原 adapter。原参数、错误处理、退出状态与 drain 验证保持。list_entries(local_authority_shadow_history.py:297)继续遍历完整原始 prepared/committed 记录,检查身份、schema、digest 和孤立 marker,并按原 sequence 排序。outbox_summary(:464)继续保留 committed pending,即使 cursor 声称已到达该位置;cursor 不是送达证明。local_authority_shadow_status(local_authority_shadow_readback.py:76)沿原 TS candidate read 返回完整结果;候选缺失时提前返回 missing,避免打开 store 时铸造新身份;损坏候选仍是 typed failed,transport 异常才映射 unavailable。
25 个函数/class 定义的 AST 与原位置完全相同。旧 outbox/adapter 只对真实消费者保留直接别名,不留第二份实现;cursor_path 包含在兼容导出中,未用私有常量删除。manifest 只移动一个 registry codec_read 位置。新增 153 行测试复用正常 source/wheel fixture;英文/中文 RFC 与 retirement reference 更新了查询出口和回退边界,未改首屏。
真实 CLI 流程含三种未启用配置,以及 canonical File/SQLite recipient 下保留的原 File shadow candidate。后者不是新的 SQLite shadow reader。每条流程先验证 producer 存在的独立不变量,再删除四个整模块和 legacy_mutation,比较完整响应及原始字节;保留 pending、prepared、cursor residue、损坏 cursor、异常 entry、损坏/缺失 candidate。重复冷启动查询仍只读。已有写入/排空调用另由完整受影响测试集验证。
对主干的风险
主要风险是搬迁中遗漏旧导出或改变错误语义。初次受影响测试捕获 cursor_path 别名遗漏,已恢复并重跑全部 81 项;另两处测试的损坏候选状态和响应 key 假设按既有 typed/响应契约纠正后,最终同一 oracle 在不可变 base、源码及 wheel 全部重跑。没有将生产 failed 改为 unavailable,也没有放宽历史有效性判断。
最终源码 5 条、正常 wheel 5 条、相关 TS44 项、完整控制面 4400 项通过;同一最终 oracle 在不可变 base 的全部 5 个模块缺席分支失败,且 producer 存在侧的独立断言先全部通过,证明回归测试能识别原缺陷。typecheck、配置内 mypy19、两新模块依赖感知 typing、最终 Ruff、全树 semantic smoke、10 路径 public scan 和原生 premerge5 direct+19 selected 通过,无 manual hold。wheel 中 6 个变化的 runtime/manifest 成员与 candidate 字节一致;最初 stale frontend bundle 拒绝构建保留,随后按标准流程重建 Chat bundle 并正常打包,未绕过验证。
额外 imports-skipped typing 仍失败三项:drain_lock_target、entry_identity、runtime_root_digest 的 no-any-return。在同一 interpreter/probe/configuration/options 与完整逻辑 owner inventory 上独立跑 base/head,全部诊断经 AST symbol 映射后内容一致,三处 return 表达式未改变;native CQR 接受该独立归因。此可选失败仍为失败,不能称全绿。完整 TS 另有 37 项 PostgreSQL 环境跳过,保留为未验证;此次不改 PG 事务或重新宣称其资格。
语义与 CI 对齐
已有 schema、默认配置、输入、prompt/help、scheduler/quota、身份及 receipt 契约保持。未启用配置下不创建 runtime;模块安装、旧开关或 canonical recipient 不是 capture 激活信号。保留历史只读不授予排空、恢复写入或清理权限;无新增 substring 分类。遵循当前 native wait_for_ci=false 策略,没有查询或等待 GitHub CI。检查最新主干的相邻变更与当前 owner 无语义交叠。
回退是撤销代码布局,不改原始数据、cursor、binding 或身份;现有 drain/recovery 路径保留。该 PR 不迁移活动 Goal,不做 live Host/cohort/default/D2 资格,不删除活跃生产模块或历史。未来重构已在本批消除原定义重复和错误依赖,完整 producer 删除仍按真实最后调用方验收。
我的整体评价
APPROVE,属于 justified_increment。long_horizon improved:后续重启仍可读原始历史和待处理记录,重复查询无副作用。user_experience improved:使用原命令即可读回状态,无需为只读检查重新安装旧生产模块。文字 diff 较大,实质为 25 个定义的机械搬迁、单一只读 owner 和直连 import;生产净增 67 行,没有投机框架。当前 PR 完成历史 status 调用方的独立读取出口,并保留捕获、排空及旧导入别名供真实调用方使用;后续只有最后调用方和持久义务退出后才能删除生产模块。 完整旧写入链路退役、试用和发布默认资格仍待现有 T4/持久性验收继续,不由此次只读查询通过替代。 可选 typing 原失败及环境跳过保持公开。运行行为 PR 留给维护者合并,此评审不授予 bypass 权限。
English verdict: APPROVE — 999c1cb. Retained status no longer imports legacy capture producers; original codecs and live capture/drain callers remain. Source5/normal-wheel5, affected81, typed44/full4400, static/semantic and native premerge pass; the same frozen-base oracle detects all5 absence failures. Three independently attributed optional baseline typing diagnostics remain failed;37 PG environment skips remain unverified. Full retirement, active-user adoption and release qualification remain separate.
Goal And Delivered Outcome
authority-shadow statuscurrently imports the legacy capture/drain producer even though it only reads history. Removing obsolete source modules therefore breaks retained operator diagnostics. This separates the historical filesystem codecs and candidate-read transport, so the existing status command works with those producers physically absent and preserves its complete response and original bytes.Basis: accepted R5/T4 last-caller retirement and retained recovery duties. Intended base:
main; implementation baselineadb247e5f3fac8e2e3f7152239955b49480d0b9f.Author Declaration
docs/architecture/rfcs/typescript-control-plane-migration-v0.md, revisionadb247e5f3fac8e2e3f7152239955b49480d0b9f.local_authority_shadow_history.py,local_authority_shadow_readback.py, status CLIScope And Continuation
cursor_path.Validation
999c1cb055b0b99c2356a0de58ece0581e4741a3(candidate bytes unchanged across build/test and commits).test_shadow_readback_writer_isolation.py: 5 source + 5 normal-wheel journeys. Default-off absent/disabled/retired settings create no runtime; retained pending, residue, corrupt cursor/entry, damaged/missing candidate preserve results and original bytes after whole-module removal. Both canonical File/SQLite recipient contexts retain the original File candidate history; this does not add a SQLite shadow reader.no-any-returndiagnostics. Independent baseline/head use the same interpreter, configuration, options and logical owner inventory; complete diagnostics match under AST-symbol mapping fordrain_lock_target,entry_identity,runtime_root_digest. The optional failure remains failed; required/configured and dependency-aware checks pass.Coverage: actual status CLI and retained filesystem/candidate backend, compatibility aliases, active capture and drain, positive/negative read semantics and packaged absence are covered. Initial regression run caught a missing
cursor_pathalias; it was restored and the full affected set rerun. Initial test assumptions about the damaged candidate status and a response key were corrected against the existing typed/response contract before rerunning the final immutable-base/source/wheel oracle. This changes no PostgreSQL transaction; skipped PG checks remain unverified. No active Goal migration, destructive history cleanup or installed-user trial is claimed.Frontend / Visual Evidence
UI impact: none. Existing CLI diagnostics change their import dependency; App/Lark interaction, prompt, help and first viewport are unchanged. No new caller-facing capability or configuration editor is introduced.
Type Of Change / Area
Shared-authority RFC fixture impact
Production-scale fixture dimensions are unchanged: no transaction, authority route, selection, ordering, scope, activation or compatibility projection rule changes. Real retained File candidate reads and existing typed/capture/drain tests cover the affected IO. Canonical File/SQLite recipient initialization is synthetic and isolated. Promotion/legacy/File/PostgreSQL rehearsal is not applicable to this read-only module split; it is not a promotion/default qualification result.
Boundary Checklist