Skip to content

Retire unused Python lease facades and stabilize control-plane regressions - #5395

Merged
huangruiteng merged 14 commits into
mainfrom
codex/retire-python-lease-facades
Oct 1, 2026
Merged

huangruiteng merged 14 commits into
mainfrom
codex/retire-python-lease-facades

Conversation

@huangruiteng

Copy link
Copy Markdown
Collaborator

Lease and handoff entrypoints already execute complete TypeScript transactions, but unused Python facades still duplicate snapshot normalization, result translation and error formatting. Remove those facades and three private RPC registrations while preserving the live Todo bridge and native transaction rules. This delivers the shared-authority / TypeScript T4 last-caller retirement slice; it does not qualify the default provider or close sustained-operation acceptance.

Scope And Continuation

  • Retire unused acquire/renew/transfer/release, owner-eligibility and handoff-transition facades. Keep live owner-eligibility/write-scope RPCs, registered lease-mode input, migration readers, storage formats and receipts unchanged. Retired RPC names explicitly reject requests.
  • Preserve generation, replay, conflict, quiescence, malformed-state and cleanup coverage at the native owner. Replace a claim-wait elapsed-time assertion with event ordering that proves lock release and stale-instance rejection.
  • Repair adjacent regressions without relaxing production deadlines: healthy NoKV/worker fixtures use the real default; controlled-clock cases prove timeout and fencing; HTTP cases prove actual cancellation and sanitized readback; async quota observations wait for typed start/end events. Limit TS test and coverage fanout to four files, retaining the SQLite rehearsal workload and deadlines.
  • Reconcile the existing bilingual retirement ledger and vocabulary notes. Public CLI schemas and frontend interactions are unchanged, so no frontend companion is needed. The duplicate-import prerequisite is already delivered by community PR fix(control-plane): remove duplicate lease digest import #5391 and is outside this diff.

Validation

Run state: finished. Input classes: synthetic, public_fixture.

Validation on immutable head 69cfd35e700807bdcb3fd345b4700e52705ad86a, compared with main baseline 35ced67104284b78ea3c536c1ebdc871fe12d160:

  • Full TS: 3,585 passed, 31 default-environment PostgreSQL skips. Applicable PostgreSQL integration was run separately against a real isolated PostgreSQL 16 server; the final 42-case run passed without skips and includes File/SQLite companion cases. Earlier unchanged core/archive/service and acceptance/continuation/team/workspace runs also passed.
  • Focused Python: 119 quota/worker/telemetry cases, 67 retirement/instance/identifier cases, and 56 packaged-dashboard/bundle cases passed. The initial full Python sweep had 14,401 passes, 7 failures and 70 skips; its stale Chat build and deadline/observation failures were resolved and their affected modules rerun. A later run overlapped a checkout update and was discarded; all 119 affected cases were repeated on the fixed head. The full Python suite was not repeated.
  • Typecheck, Ruff, configured mypy, semantic inventory and all 19 selected premerge checks passed. Exact-diff quality receipt is valid. Negative mutation checks reject lost HTTP cancellation and broken claim-poll locking.

Entry Points And RFC Evidence

UI impact: none; CLI and frontend result contracts remain unchanged. The packaged Chat build was regenerated for validation, with no generated assets committed.

Production fixture schema is unchanged. Native synthetic cases cover malformed leases, generation/replay, conflicts and quiescence; real File/SQLite and isolated PostgreSQL conformance arms pass. No promotion, routing or compatibility-projection change is introduced, so a new three-arm promotion rehearsal is not applicable. D2 sustained operation, default admission and later Python retirements remain in the existing RFC checkpoint, outside this last-caller slice.

No provider-default switch or state conversion. Rollback is a code revert. Maintainer merge required.

Boundary Checklist

  • Public-safe diff and evidence; no private state, credentials, raw logs or local paths.
  • Scoped control-plane refactor, test repair and existing RFC checkpoint update; no benchmark work or visual changes.
  • All branch commits carry DCO sign-off.

huangruiteng and others added 14 commits September 30, 2026 15:19
…ences

Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
…ease-facades

Signed-off-by: huangruiteng <huangrt01@163.com>

# Conflicts:
#	tests/control_plane/test_prompt_upgrade_hook.py
Signed-off-by: huangruiteng <huangrt01@163.com>
…cally

Signed-off-by: huangruiteng <huangrt01@163.com>
…ease-facades

Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
…tire-python-lease-facades

Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
@huangruiteng

Copy link
Copy Markdown
Collaborator Author

Final scope remains head 69cfd35e700807bdcb3fd345b4700e52705ad86a against 35ced67104284b78ea3c536c1ebdc871fe12d160.

The last-caller audit was also repeated against newer main 6a8a042ab868a0694e8c19a1ba29c534c575864a: removed facade command types and lease-only snapshot helpers have no production caller outside their former owning files, and the candidate contains no remaining production reference. The RFC records the initial audit revision; this readback confirms intervening merges did not reintroduce callers.

Changed surfaces: internal coordination facades, three private RPC registrations, native regression coverage, test scheduling/observation and existing RFC guidance. Goal-aware premerge passed five direct checks and 19 selected checks with zero failures, warnings or manual holds; strict quality receipt verifies the final scope. Typecheck, Ruff, configured mypy and semantic checks passed. Real File/SQLite CLI cases and isolated PostgreSQL integration passed; full TS and focused Python outcomes and the earlier failed full sweep are disclosed in the PR body.

No production deadline, provider default, persistent format, receipt, migration reader, public result schema or frontend interaction changed. Public/private boundary checks are clean. The bounded future-facing pass removes duplicate authority/translation and keeps the active Todo and owner/scope bridges; it adds no replacement framework. Reverting the code requires no data conversion.

Independent review requested from the designated reviewer. This is an author-owned runtime PR, so a passed validation gate does not grant self-merge authority; maintainer merge remains required.

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Reviewed exact head: 69cfd35e700807bdcb3fd345b4700e52705ad86a
Immutable comparison base: 35ced67104284b78ea3c536c1ebdc871fe12d160

动机

本次评审按 pull-request-review capability 的 policy revision 12 执行,判断的是完整 PR,而非继承作者的测试结论。当前交付目标是清除已无生产调用方的 Python lease/handoff decision facade,同时保留真实执行入口、历史数据和恢复行为。它对应 shared-authority RFC 的 T4 最后调用方退役边界,不是 D2 持续资格、provider 默认切换或整个 Python 层退役。相关的 native lease lifecycle、canonical acquisition 和 worktree 隔离已由既有实现负责;本 PR 不再复制这些规则。

改动思路

我首先挑战了“只是删死代码”的假设:若旧 facade 仍被实际 caller 使用,或者 facade-only 测试承载了尚未迁到 native 层的权限、CAS、清理或恢复语义,就不能凭净减行数批准。对 base、exact head 及当前 main 的符号/方法名检索显示,被删边界只由自身定义、旧 core 测试和对应 RPC 注册消费;生产调用已经进入完整 TS transaction。仍被 Python 使用的 Todo 授权、owner eligibility、write-scope overlap、迁移读取和 receipt/lease codec 没有被删。

另一个风险是用更宽松的测试掩盖运行回归。因此逐项核对了 timing 修复:healthy fixture 使用生产 deadline;超时场景仍明确测试 deadline;HTTP 仍用真实 fetch 和 AbortSignal;claim 等待改为线程事件证明锁在轮询间可用;quota telemetry 等待终态及重放不重复效果。npm 测试并发上限变为 4,但 SQLite 容量和完整测试集合没有缩小。

具体改动

19 个文件,+242/-1024:生产/语义注册 4 个文件 +13/-567;测试/fixture 9 个文件 +169/-451;文档 5 个文件 +58/-4;测试运行配置 +2/-2。没有新增模块、运行参数、状态字段或默认 provider。

关键代码讲解

  • loopx/control_plane/coordination/authority_core.py:262 — _typescript_todo_decision 保留 live Todo 输入、typed lifecycle decision 和结果适配。调用方仍经 mutation_authority.py 进入它;删除 lease/handoff facade 不等于删除 Todo 的 ownership/terminal fence。
  • loopx/control_plane/coordination/local_snapshot.py:36 — todo_snapshot_from_mapping 保留 claim、exclude、binding 和 decision-scope 的正规化。只删没有 caller 的 lease snapshot/error 转译,未修改持久化记录。
  • loopx/control_plane/effect_runtime_handlers.ts:442 — createEffectRuntimeHandlers 删除三个瞬时私有 decision RPC,保留 acquire/inspect/lifecycle native transaction、owner eligibility、scope overlap、legacy handoff planner 和 canonical mode-set。旧方法现在在 dispatch 边界 fail closed,不会进入另一个 decision owner。
  • tests/test_attached_session_goal_instance.py:527 — claim waiter 被停在两次 poll 之间;此时 Goal recreation 必须完成,随后 waiter 以 stale_goal_instance 拒绝。它证明锁和旧实例隔离,不再把一次机器上的 recreation 速度作为正确性。
  • tests/control_plane_ts/usage_statistics.test.ts:234 — 对真实不响应 HTTP collector 发起请求,保留两个 3000ms AbortSignal deadline,验证 cancellation 和不保留异常详情;测试 watchdog 与产品 deadline 分开。

正向实走:公开 task-lease CLI 在 File/SQLite 上 acquire → 重放及独立 inspect → renew → transfer → release → inspect → 用新 key/version 重新 acquire。每次都核对 durable lease,重放还核对原始 receipt;缺失 Markdown 不会被 resurrect。错误路径覆盖错 owner、stale CAS、excluded owner 与 CAS 同时不合法时的优先级,以及拒绝后 lease 不变和另一个 Todo 的独立执行。

语义与 CI 对齐

保留 LeaseAction/LeaseModeGateCommand 的 compatibility-only 注册,没有以删 facade 为名降低语义覆盖门槛。变更前 advisory 未发现新增 vocabulary carrier;当前全树 semantic-vocabulary-drift smoke 实际执行并通过。核心错误仍是领域中性的 typed rejection;没有新增 guidance/must-attempt、激活门或跨 Agent 权限。

独立验证结果:

  • npm run test:control-plane:3585 passed、0 failed、31 个默认 PostgreSQL skips。另以隔离 PostgreSQL 16.15 实例,在 base/head 各跑 309 项 store 和 10 项 service 检查,均通过、无 skip;含 tenant 隔离、CAS/replay、原子 rollback、丢失 COMMIT 回复及 incarnation fencing。
  • 聚焦 Python 回归:207 passed,覆盖改动测试及公开 lease、handoff、真实 sibling worktree。另在 immutable base 上运行同一组公开 lease/handoff/worktree 回归,54 passed。
  • reviewer 生成的同一合成公开 CLI harness:base/head 的 28 项 File/SQLite 观察完全一致;完整错误诊断保留比较,只排除时间戳、随机 store/receipt 标识和临时 locator。单次运行内部的持久化/receipt 相等仍单独断言,没有被正规化掉。
  • 三个退役方法通过真实 Python→TS RPC 进程验证:退役 oracle 在 base 上按预期失败,exact head 全部以 unsupported-method 拒绝,证明测试能检测边界被重新接回。
  • control-plane TypeScript typecheck、配置的 mypy(19 files)、7 个变更 Python 路径的 Ruff、public/private 扫描及 exact diff check 均通过。
  • 当前 19-file exact-scope qualification 已记录并读回有效;使用上述 immutable base 的 canary premerge --from-git-diff 风险检查通过。safe-fix allowed、实际未改源码;无 blocker/warning/advisory,未放宽验证门。
  • Chat bundle 在各自源码树构建后,base/head 各 63 项 bundle/dashboard 回归通过。未构建时两边同样出现 5 个 missing-manifest 失败;这是缺少忽略的构建产物,不是 PR 差异。重复使用已旋转 incarnation 的 PostgreSQL 测试库也在两边同样拒绝;改用新隔离数据库后通过,原失败没有当作产品失败或删除。

按照 Goal 的 wait_for_ci=false,未查询、等待或依据 GitHub CI 作结论。没有运行完整 Python 全树回归,也没有声称真实 NoKV deployment、长期 soak、生产切换或新版本已安装。

对主干的风险

最大的风险是删除私有 facade 后存在未发现的独立消费者,或将错误优先级、历史 replay、release cleanup 也误删。当前仓库内 caller 审计、source-fingerprinted runtime 复用、配对公开入口和真实 provider 验证没有支持这一风险的证据。兼容性区分清楚:删的是同包 co-deployed 的瞬时请求边界,保留的是持久化 lease/receipt、迁移读取、真实 native 规则和显式注册的旧输入词表。

测试改动没有改变生产 timeout 或 HTTP cancellation,也没有降低 capacity/semantic ratchet。范围是可逆的最后调用方清理;回滚可恢复内部 crossing,无需转换数据。缺失的长期 default/profile 资格仍由既有 RFC 工作负责,不能由本次通过的测试代替。控制面 PR 留给 maintainer 合并,评审结论不授予 bypass 或 self-merge 权限。

我的整体评价

结论:APPROVE,无阻塞项。这个独立增量确实移除了无用的第二入口并保留继续执行/恢复的能力,scope 与 T4 目标相称。future-facing pass 已应用在本 PR 的 facade 删除和已有 owner 复用上;不建议顺手删除仍活跃的 Todo bridge、历史 codec 或已登记兼容词表,也不扩大到 provider 默认迁移。评审仅绑定上述 exact head;head 变化需重新核对。

English verdict: APPROVE — exact head 69cfd35e700807bdcb3fd345b4700e52705ad86a. No blocking finding: obsolete co-deployed decision facades/RPCs are retired without changing the retained lease, Todo, receipt or migration contracts. Independently verified full TS, focused Python, matched public File/SQLite CLI, real PostgreSQL, semantic and built-bundle regressions. Runtime PR remains for maintainer merge; no CI or author-validation inheritance.

@huangruiteng
huangruiteng merged commit 8474c8d into main Oct 1, 2026
33 of 35 checks passed
@huangruiteng
huangruiteng deleted the codex/retire-python-lease-facades branch October 1, 2026 08:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant