Skip to content

docs(rfc): define quota action authority and contention follow-ups - #5349

Open
cocolord wants to merge 1 commit into
mainfrom
codex/action-authority-rfc-0930
Open

cocolord wants to merge 1 commit into
mainfrom
codex/action-authority-rfc-0930

Conversation

@cocolord

Copy link
Copy Markdown
Collaborator

Goal and result

A current quota packet can select a shell-only Todo while agent_scoped_user_gate_override.selected_action still names a higher-priority Todo requiring unavailable network capability. This bilingual RFC defines one final action projection in the existing TypeScript quota owner, preserving recommendation, Turn binding, current admission and historical settlement as separate facts.

The proposed first slice keeps existing wire fields and receipt identities. It includes compatibility/negative-test gates, rollback, and planning ROI estimates: 1–3 engineer-days for action projection; 2–4 for a separate canonical claim retry slice. These are estimates, not measured production savings. Whole-pipeline rewrites and ranking/claim-next changes are deferred.

Contention evidence and placement

  • Identical-profile Agents both receive the same first unclaimed recommendation.
  • Forced command-level interleavings on real File and SQLite stores yield one applied claim and one CAS conflict even for independent Todos; retrying the original operation succeeds. The same-Todo control rejects the loser with claim_owner_mismatch.
  • The local runtime writer lock can serialize these calls. This evidence does not establish the cause or rate of every deployed contention incident.
  • Reuse the existing shared-authority rules for bounded receipt/head revalidation at the typed claim owner. No new scheduler, capability, provider or general receipt-layer retry authority.
  • refactor(quota): resolve fallback advice from one typed snapshot #4061 owns fallback-declaration snapshot coherence; this RFC covers final action projection and does not duplicate that implementation.

Validation and scope

Tested content is committed at 32b641715 (finished; synthetic/public fixtures).

Check Result / boundary
Current-source action fixture Contradiction reproduced; full-capability control removes it
Existing scoped-user-gate smoke Passed despite the missing combined case
File/SQLite independent/same-target probes Four expected interleavings confirmed; no live Goal changed
RFC generator and 13 architecture tests Passed
Docs-governance smoke and new relative links Passed
Public-boundary check, all five changed files, isolated empty registry Zero errors/warnings
Diff whitespace Passed

Initial header/mirror checks caught missing Chinese supersession and semantic-mirror declarations; both were corrected. An isolated-scan registry setup error was corrected before the clean final scan.

All changed paths are core documentation. Temporary probes, generated dependency state, raw logs and private context are excluded. No runtime implementation, default change, promotion, benchmark run or public first-viewport change is included. Runtime acceptance rows remain implementation gates. The bounded refactor pass localizes the next changes to existing quota and claim owners. DCO signed; base main, merge base b79bcb194. This PR requests design review, not merge authorization for runtime changes.

Signed-off-by: lusendong.6789 <lusendong.6789@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

这个不用 rfc,直接伴随着 ts 重构 rfc 提 pr 吧

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants