docs(rfc): reconcile SQLite adoption, migration and legacy retirement - #5478
Conversation
Signed-off-by: huangruiteng <huangrt01@163.com>
huangruiteng
left a comment
There was a problem hiding this comment.
Reviewer: model_agent — GPT-6 family / OpenAI (self-reported)
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
未发现阻塞问题。评审 head:c60116eb582293329e50340db5d49cf9bad0f64a,基线:3cecb0d7cbf3d247cfd996267d7fc64627bd6e49。批准的是文档计划对账,没有认证 cohort、迁移、默认切换或代码删除已经完成。
动机
原文一处要求正式十天资格后才能开始 opt-in canary,另一处已有三个独立决策,明确可恢复的小 cohort 不必等十天证书。当前 PR 解决这个矛盾,并纠正把已经合入的优化/退役重复列为待办的问题。先读基线 docs/architecture/rfcs/shared-goal-authority-state-provider-v0.md,spec_revision:3cecb0d7cbf3d247cfd996267d7fc64627bd6e49;按原 Section 7.2 的三决策表判断新增改文,未拿改后的规则自证。对 Merge a bounded provider improvement、Invite a small opt-in developer cohort、Select the release default 和 Retention, recovery and delivery gates,文档均 implemented:保留各自所需证据、明确 cohort 的备份/携新写入回退及权限,正式十天/容量缺项仍未通过。运行结果是 deferred,仍由既有 D1–D3/T0–T4 owner 和文中交付包完成。
改动思路
一个现有 execution ledger 承接近期合并事实、交付顺序、实验矩阵和删除清单;总 roadmap 与两个 RFC 只投影该当前边界,英语和中文同步更新。区分格式升级、provider 选择及所有权策略迁移,避免数据库文件存在就被视为新 Goal 已 canonical。R6 共享服务保持独立,不把部署前置于已可证明的局部删除;同时也不把本机升级当作所有用户已经迁移。对长期推进是 improved:下一实现包有可判定出口;对操作者路径也是 improved:计划明确正常设置、打包 App、CLI 和适用 Lark 的读回与恢复义务,而不是只看后台成功。
具体改动
关键内容讲解
- 两份退休 ledger 替换旧 A–D 顺序,新增 7 个交付包、7 行验证矩阵、5 类删除对象:当前 head 收尾→安装恢复候选→有界 cohort;canonical 创建/默认、两策略迁移和最后 writer 删除各有独立出口。保留历史证据,不通过重新计数宣称完成。
- shared-authority 英中版修正 canary/正式资格的阶段表和 promotion 文字:bounded trial 可先进行,但不声称正式 profile 或发布默认值。完整数据、原 receipt、fence、consumer cursor、异常恢复和携带新写入回退都保留。
- roadmap 英中版更新 R5/T4 checkpoint 与退出条件;TS migration 英中版更新当前 frontier,沿用 transaction/last-caller owner,不另设控制面或 RFC。
- 对源码核对:
goal_storage.py的 machine namespace 仍选 post-promotion target,local_authority_defaults.ts明确返回promotion_performed: false;现有 Goal 设置没有该新政策迁移 editor,文中正确将 CLI-only 阶段标为 partial。#4931/#5251/#5395/#5417/#5436 的 merge commit 都位于文中冻结9b0486dc1b891bc5254ea85d1ba06da089d22853,没有靠当前标题猜测历史状态。#4224 是 D2 issue,其未完成资格与缺项仍可查。
对主干的风险
最危险的误读是把“cohort 不等十天”理解为“无需可恢复的迁移、消费者验收或切换权限”。逐行对照旧三决策表和新双语矩阵,确认安装态 backup/migration/restart、相关并发/中断、携新写入 reverse migration、逐 Goal 权限及停止条件仍必需;正式十天/100k 行和冻结失败没有重标通过。两策略默认按效果责任选择,未知拓扑须显式选择,已有 policy 迁移前保持 pinned,不默默将 legacy 降为 soft。必要历史 reader 与活跃 legacy writer 的保留责任区分清楚。
我运行了 examples/docs-governance-smoke.py、examples/docs-asset-integrity-smoke.py 与 diff 检查,均通过;6 个唯一新增本地链接/锚点全部存在。通用全文件锚点探针还报了两处未改的中文旧引用,基线上字符串相同,属于范围外已有问题。新章节的英中 package/matrix/retirement 条件逐行比对相符,ledger 历史 evidence 后缀保持字节相同。PR 元数据仅用于核对合并事实;99、96 次等旧验证只按作者来源与旧 head 保留,没有冒称我重跑或适用新 head。观察时 #5283 已有新 head 6643ade67bc22cb9837e933afd7858c4036006c3,文中 73d1fe663 是冻结规划快照;执行时应刷新,不能继承它的测试/评审。
我的整体评价
APPROVE:这是完成当前计划对账的有效文档切片,长程与用户路径判断均 improved;实际安装、迁移和删除仍 deferred,没有因此结算上层 R5/D2。全 diff 为 8 个文档、300 additions / 108 deletions,没有运行代码、持久状态或默认值修改。未来简化审视 applied:压缩旧顺序并复用同一 ledger 和现有 typed owner,而不是新增并行计划。没有删除 persisted 兼容约定或降低历史证据要求。主要残余风险是 dated queue 继续变化,以及当前 candidate 的运行证据尚待 owner 完成;本评审没有执行活跃 Goal 迁移、崩溃注入、自然时间 soak 或 PostgreSQL 部署,也未查询 CI。维护者可据该边界审阅合并,真实采用仍需文中独立验收。
English verdict: APPROVE — c60116e. The bilingual plan reconciles the pre-existing three-decision contract while preserving recovery, authority, formal D2 gaps and historical evidence. Documentation, changed links and pinned merge facts were checked; runtime rollout is not certified.
The current RFC frontiers still count merged SQLite/TS work as pending, while an older milestone makes every opt-in canary wait for formal ten-day qualification despite the RFC's separate decision table. This reconciles the existing roadmap and bilingual RFCs around explicit validation, migration and deletion exits.
Validation: documentation governance and asset-integrity smokes pass; all six changed local links/anchors pass; changed public-boundary review and bilingual/source/PR-state reconciliation pass. Native premerge: 19 selected checks plus 3 direct checks passed, zero failures, skips or manual holds. Exact-scope change-quality receipt
cqr_c6963e048ea9c9cab395is valid against9b0486dc1b891bc5254ea85d1ba06da089d22853for headc60116eb582293329e50340db5d49cf9bad0f64a.Related: #4574, #3225, #3245, #4224. Historical runtime results in the ledger are retained source-specific evidence, not new tests performed by this planning change. Private Goal inventories, canonical Todo ids, backups and logs are excluded.