Retire unused Python lease facades and stabilize control-plane regressions - #5395
Conversation
…ences Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
…ease-facades Signed-off-by: huangruiteng <huangrt01@163.com> # Conflicts: # tests/control_plane/test_prompt_upgrade_hook.py
Signed-off-by: huangruiteng <huangrt01@163.com>
…cally Signed-off-by: huangruiteng <huangrt01@163.com>
…ease-facades Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
…tire-python-lease-facades Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
|
Final scope remains head The last-caller audit was also repeated against newer main Changed surfaces: internal coordination facades, three private RPC registrations, native regression coverage, test scheduling/observation and existing RFC guidance. Goal-aware premerge passed five direct checks and 19 selected checks with zero failures, warnings or manual holds; strict quality receipt verifies the final scope. Typecheck, Ruff, configured mypy and semantic checks passed. Real File/SQLite CLI cases and isolated PostgreSQL integration passed; full TS and focused Python outcomes and the earlier failed full sweep are disclosed in the PR body. No production deadline, provider default, persistent format, receipt, migration reader, public result schema or frontend interaction changed. Public/private boundary checks are clean. The bounded future-facing pass removes duplicate authority/translation and keeps the active Todo and owner/scope bridges; it adds no replacement framework. Reverting the code requires no data conversion. Independent review requested from the designated reviewer. This is an author-owned runtime PR, so a passed validation gate does not grant self-merge authority; maintainer merge remains required. |
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Reviewed exact head: 69cfd35e700807bdcb3fd345b4700e52705ad86a
Immutable comparison base: 35ced67104284b78ea3c536c1ebdc871fe12d160
动机
本次评审按 pull-request-review capability 的 policy revision 12 执行,判断的是完整 PR,而非继承作者的测试结论。当前交付目标是清除已无生产调用方的 Python lease/handoff decision facade,同时保留真实执行入口、历史数据和恢复行为。它对应 shared-authority RFC 的 T4 最后调用方退役边界,不是 D2 持续资格、provider 默认切换或整个 Python 层退役。相关的 native lease lifecycle、canonical acquisition 和 worktree 隔离已由既有实现负责;本 PR 不再复制这些规则。
改动思路
我首先挑战了“只是删死代码”的假设:若旧 facade 仍被实际 caller 使用,或者 facade-only 测试承载了尚未迁到 native 层的权限、CAS、清理或恢复语义,就不能凭净减行数批准。对 base、exact head 及当前 main 的符号/方法名检索显示,被删边界只由自身定义、旧 core 测试和对应 RPC 注册消费;生产调用已经进入完整 TS transaction。仍被 Python 使用的 Todo 授权、owner eligibility、write-scope overlap、迁移读取和 receipt/lease codec 没有被删。
另一个风险是用更宽松的测试掩盖运行回归。因此逐项核对了 timing 修复:healthy fixture 使用生产 deadline;超时场景仍明确测试 deadline;HTTP 仍用真实 fetch 和 AbortSignal;claim 等待改为线程事件证明锁在轮询间可用;quota telemetry 等待终态及重放不重复效果。npm 测试并发上限变为 4,但 SQLite 容量和完整测试集合没有缩小。
具体改动
19 个文件,+242/-1024:生产/语义注册 4 个文件 +13/-567;测试/fixture 9 个文件 +169/-451;文档 5 个文件 +58/-4;测试运行配置 +2/-2。没有新增模块、运行参数、状态字段或默认 provider。
关键代码讲解
loopx/control_plane/coordination/authority_core.py:262—_typescript_todo_decision保留 live Todo 输入、typed lifecycle decision 和结果适配。调用方仍经mutation_authority.py进入它;删除 lease/handoff facade 不等于删除 Todo 的 ownership/terminal fence。loopx/control_plane/coordination/local_snapshot.py:36—todo_snapshot_from_mapping保留 claim、exclude、binding 和 decision-scope 的正规化。只删没有 caller 的 lease snapshot/error 转译,未修改持久化记录。loopx/control_plane/effect_runtime_handlers.ts:442—createEffectRuntimeHandlers删除三个瞬时私有 decision RPC,保留 acquire/inspect/lifecycle native transaction、owner eligibility、scope overlap、legacy handoff planner 和 canonical mode-set。旧方法现在在 dispatch 边界 fail closed,不会进入另一个 decision owner。tests/test_attached_session_goal_instance.py:527— claim waiter 被停在两次 poll 之间;此时 Goal recreation 必须完成,随后 waiter 以stale_goal_instance拒绝。它证明锁和旧实例隔离,不再把一次机器上的 recreation 速度作为正确性。tests/control_plane_ts/usage_statistics.test.ts:234— 对真实不响应 HTTP collector 发起请求,保留两个 3000ms AbortSignal deadline,验证 cancellation 和不保留异常详情;测试 watchdog 与产品 deadline 分开。
正向实走:公开 task-lease CLI 在 File/SQLite 上 acquire → 重放及独立 inspect → renew → transfer → release → inspect → 用新 key/version 重新 acquire。每次都核对 durable lease,重放还核对原始 receipt;缺失 Markdown 不会被 resurrect。错误路径覆盖错 owner、stale CAS、excluded owner 与 CAS 同时不合法时的优先级,以及拒绝后 lease 不变和另一个 Todo 的独立执行。
语义与 CI 对齐
保留 LeaseAction/LeaseModeGateCommand 的 compatibility-only 注册,没有以删 facade 为名降低语义覆盖门槛。变更前 advisory 未发现新增 vocabulary carrier;当前全树 semantic-vocabulary-drift smoke 实际执行并通过。核心错误仍是领域中性的 typed rejection;没有新增 guidance/must-attempt、激活门或跨 Agent 权限。
独立验证结果:
npm run test:control-plane:3585 passed、0 failed、31 个默认 PostgreSQL skips。另以隔离 PostgreSQL 16.15 实例,在 base/head 各跑 309 项 store 和 10 项 service 检查,均通过、无 skip;含 tenant 隔离、CAS/replay、原子 rollback、丢失 COMMIT 回复及 incarnation fencing。- 聚焦 Python 回归:207 passed,覆盖改动测试及公开 lease、handoff、真实 sibling worktree。另在 immutable base 上运行同一组公开 lease/handoff/worktree 回归,54 passed。
- reviewer 生成的同一合成公开 CLI harness:base/head 的 28 项 File/SQLite 观察完全一致;完整错误诊断保留比较,只排除时间戳、随机 store/receipt 标识和临时 locator。单次运行内部的持久化/receipt 相等仍单独断言,没有被正规化掉。
- 三个退役方法通过真实 Python→TS RPC 进程验证:退役 oracle 在 base 上按预期失败,exact head 全部以 unsupported-method 拒绝,证明测试能检测边界被重新接回。
- control-plane TypeScript typecheck、配置的 mypy(19 files)、7 个变更 Python 路径的 Ruff、public/private 扫描及 exact diff check 均通过。
- 当前 19-file exact-scope qualification 已记录并读回有效;使用上述 immutable base 的
canary premerge --from-git-diff风险检查通过。safe-fix allowed、实际未改源码;无 blocker/warning/advisory,未放宽验证门。 - Chat bundle 在各自源码树构建后,base/head 各 63 项 bundle/dashboard 回归通过。未构建时两边同样出现 5 个 missing-manifest 失败;这是缺少忽略的构建产物,不是 PR 差异。重复使用已旋转 incarnation 的 PostgreSQL 测试库也在两边同样拒绝;改用新隔离数据库后通过,原失败没有当作产品失败或删除。
按照 Goal 的 wait_for_ci=false,未查询、等待或依据 GitHub CI 作结论。没有运行完整 Python 全树回归,也没有声称真实 NoKV deployment、长期 soak、生产切换或新版本已安装。
对主干的风险
最大的风险是删除私有 facade 后存在未发现的独立消费者,或将错误优先级、历史 replay、release cleanup 也误删。当前仓库内 caller 审计、source-fingerprinted runtime 复用、配对公开入口和真实 provider 验证没有支持这一风险的证据。兼容性区分清楚:删的是同包 co-deployed 的瞬时请求边界,保留的是持久化 lease/receipt、迁移读取、真实 native 规则和显式注册的旧输入词表。
测试改动没有改变生产 timeout 或 HTTP cancellation,也没有降低 capacity/semantic ratchet。范围是可逆的最后调用方清理;回滚可恢复内部 crossing,无需转换数据。缺失的长期 default/profile 资格仍由既有 RFC 工作负责,不能由本次通过的测试代替。控制面 PR 留给 maintainer 合并,评审结论不授予 bypass 或 self-merge 权限。
我的整体评价
结论:APPROVE,无阻塞项。这个独立增量确实移除了无用的第二入口并保留继续执行/恢复的能力,scope 与 T4 目标相称。future-facing pass 已应用在本 PR 的 facade 删除和已有 owner 复用上;不建议顺手删除仍活跃的 Todo bridge、历史 codec 或已登记兼容词表,也不扩大到 provider 默认迁移。评审仅绑定上述 exact head;head 变化需重新核对。
English verdict: APPROVE — exact head 69cfd35e700807bdcb3fd345b4700e52705ad86a. No blocking finding: obsolete co-deployed decision facades/RPCs are retired without changing the retained lease, Todo, receipt or migration contracts. Independently verified full TS, focused Python, matched public File/SQLite CLI, real PostgreSQL, semantic and built-bundle regressions. Runtime PR remains for maintainer merge; no CI or author-validation inheritance.
Lease and handoff entrypoints already execute complete TypeScript transactions, but unused Python facades still duplicate snapshot normalization, result translation and error formatting. Remove those facades and three private RPC registrations while preserving the live Todo bridge and native transaction rules. This delivers the shared-authority / TypeScript T4 last-caller retirement slice; it does not qualify the default provider or close sustained-operation acceptance.
Scope And Continuation
Validation
Run state:
finished. Input classes:synthetic,public_fixture.Validation on immutable head
69cfd35e700807bdcb3fd345b4700e52705ad86a, compared with main baseline35ced67104284b78ea3c536c1ebdc871fe12d160:Entry Points And RFC Evidence
UI impact:
none; CLI and frontend result contracts remain unchanged. The packaged Chat build was regenerated for validation, with no generated assets committed.Production fixture schema is unchanged. Native synthetic cases cover malformed leases, generation/replay, conflicts and quiescence; real File/SQLite and isolated PostgreSQL conformance arms pass. No promotion, routing or compatibility-projection change is introduced, so a new three-arm promotion rehearsal is not applicable. D2 sustained operation, default admission and later Python retirements remain in the existing RFC checkpoint, outside this last-caller slice.
No provider-default switch or state conversion. Rollback is a code revert. Maintainer merge required.
Boundary Checklist