Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view

Large diffs are not rendered by default.

Large diffs are not rendered by default.

4 changes: 2 additions & 2 deletions docs/architecture/rfcs/loopx-overall-roadmap-v0.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
- Ownership: overall product outcomes, cross-domain dependencies, priorities and portfolio acceptance here; concrete rules in domain RFCs/stable protocols; execution state in canonical Todos.
- Language: [中文版](loopx-overall-roadmap-v0.zh-CN.md) is the semantic mirror.

**Local authority retirement checkpoint (2026-09-28).** R5/T4 now use the [reconciled deletion and qualification cadence](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md). Reviewed local cutover and native drain are merged; whole-Goal execution/consumer closure, profile qualification and default-entry adoption still have separate exits. Delete a replaced writer with its last caller; retain necessary migration/receipt readers. Existing GoalRef/Turn PRs own their affected consumers. R6 PostgreSQL service qualification is separate, and the historical PR-count estimates are not current forecasts.
**Local authority closeout checkpoint (2026-10-02).** R5/T4 use the [current validation → migration → deletion plan](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md#current-closeout-validation-migration-and-deletion-2026-10-02), rechecked at `9b0486dc1`. Close existing #5413/#5466/#5283, qualify one installed reversible candidate, then decide a bounded opt-in cohort separately from release-default admission. Canonical creation, legacy-policy migration and last-writer deletion have named exits; delete replaced Python owners with their last callers. R6 remains separate. No fixed remaining-PR count or historical test count certifies completion.

Conversational preparation from [PR #4376](https://github.com/loopx-project/loopx/pull/4376)
is integrated under R1/GQ01 through the existing Chat draft and reviewed Goal
Expand Down Expand Up @@ -705,7 +705,7 @@ L3 checkpoint: standalone acquisition/takeover, atomic claim admission and maint
- **Owner:** TS T0–T4 and shared-authority D1–D3; retain their numbering and gates.
- **Selection:** prioritize an entire hot-path transaction or recovery lifecycle used by R1–R4. Record before/after callers, owners, crossings, actual deletions and performance. Stop adding per-field Python→TS RPCs; do not rebuild the merged Todo update.
- **Delivery:** qualify full-source reads, one-way Markdown projection, event/receipt retention, restart recovery, capacity and long-term cost on the selected local profile. Source failure cannot fall back to legacy. R1 cannot put large plan bodies into the coordination head.
- **Exit:** affected real CLI/backend, immutable baseline versus candidate comparison, negative/mutation coverage, three-arm rehearsal and applicable D2 soak of at least ten days. D3 retains explicit cutover approval. This audit runs no new soak and promotes no provider.
- **Exit:** use shared-authority Section 7.2's separate decisions for a bounded change, reversible opt-in cohort and released default. Each requires affected real CLI/backend and independent baseline/negative/recovery evidence at its own scope. Formal D2 retains applicable volume and at least ten-day evidence; a cohort need not wait for that certificate. D3 retains explicit cutover authority. This plan runs no soak or provider promotion.
- **Rollback:** reviewed fenced export/import and schema-aware downgrade; replacing a binary cannot restore old write authority.

The [Goal instance/recovery proposal](goal-instance-identity-and-orphan-recovery-v0.md)
Expand Down
4 changes: 2 additions & 2 deletions docs/architecture/rfcs/loopx-overall-roadmap-v0.zh-CN.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@
- 责任:总纲拥有产品目标、跨领域依赖、优先级和组合验收;领域 RFC/稳定协议拥有具体规则;运行 Todo 拥有执行状态。
- 语言:[English](loopx-overall-roadmap-v0.md) 与本文互为语义镜像。

**本地权威退役 checkpoint(2026-09-28)。** R5/T4 采用[重新核对的删除和验证节奏](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md)。Reviewed 本地切换和 native drain 已合入;整 Goal 执行/消费者闭环、profile 验证、默认入口接入仍分别验收。切走最后调用方时同步删旧 writer,保留必要迁移/回执 reader。已有 GoalRef/Turn PR 负责各自消费者;R6 PostgreSQL 服务验证另列,历史 PR 数量估算不再作为当前预测。
**本地权威收尾检查点(2026-10-02)。** R5/T4 使用按 `9b0486dc1` 复核的[验证→迁移→删除计划](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md#当前收尾验证迁移与删除2026-10-02)。先收尾现有 #5413/#5466/#5283,验证一个安装态可回退候选,再分别决定有界自愿试用和发布默认准入。Canonical 创建、legacy 策略迁移与最后 writer 删除各有明确出口;Python 替代 owner 随最后调用方删除。R6 独立,不用固定剩余 PR 数或历史测试数量证明完成。

## 1. 总目标与产品路线

Expand Down Expand Up @@ -512,7 +512,7 @@ L3 检查点:独立领取/接管、原子 claim 准入与维护共用 typed le
- **Owner:** TS RFC T0–T4、shared-authority D1–D3;保留两套编号及原门禁。
- **选择规则:** 优先迁移 R1–R4 热路径的一笔完整事务或恢复生命周期,附前后 caller/owner/crossing 表、实际删除和性能证据。不要继续按单字段增加 Python→TS RPC;不要重建已合入的 Todo update。
- **交付:** 用已选本地 profile 验证完整来源读取、单向 Markdown 投影、event/receipt 保留、重启恢复、容量与长期成本;source 失败不能回退 legacy。R1 不能把大计划正文塞入 coordination head。
- **退出:** 相关真实 CLI/backend、不可变 baseline 与候选对照、负例/mutation、三臂演练及适用 D2 至少十日 soak;D3 切换保留明确批准。此次审计没有执行新的 soak,也未晋升 provider。
- **退出:** 按 shared-authority 7.2 分别决定有界改动、可回退自愿 cohort、发布默认值,各自在适用范围具备真实 CLI/backend、独立基线、负例和恢复证据。正式 D2 保留适用容量及至少十日证据,cohort 不必等该证书。D3 保留明确切换权限。本计划没有启动 soak 或晋升 provider。
- **回滚:** 按已审阅的 fenced export/import 和 schema-aware downgrade,不能靠替换二进制恢复旧写权威。

[Goal instance/recovery 提案](goal-instance-identity-and-orphan-recovery-v0.zh-CN.md)
Expand Down
44 changes: 24 additions & 20 deletions docs/architecture/rfcs/shared-goal-authority-state-provider-v0.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,21 +24,22 @@
[Chinese version](./shared-goal-authority-state-provider-v0.zh-CN.md) and this
English version are semantic mirrors. A difference between them is a defect.

## Current delivery frontier (2026-09-28)

Audit `ce3862e33`: #5054, #5140, #5144, #5156, #5173, #5175 and #5169
are merged. Do not count event retirement, archive recovery, managed process
supervision, reviewed local cutover or native drain as new pending PRs.
The SQLite read-proof optimization [#4931](https://github.com/loopx-project/loopx/pull/4931)
has since merged at `9482a9496`; D2 qualification remains incomplete.

Next: qualify whole-Goal execution/consumer integration and matched local
profiles in parallel; then unify new-Goal/install/settings and supported upgrade
entrypoints, deleting each replaced writer with its last caller. Retain necessary
Host IO, original receipts and migration readers. No additional dead Python
module is certified by this audit, and no fixed remaining-PR total is promised.
[Deletion inventory, engineering windows, local evidence and remaining work](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md)
supersedes older current-count estimates; their execution evidence stays historical.
## Current delivery frontier (2026-10-02)

At main `9b0486dc1`, #4931, #5251, #5395, #5417 and #5436 are merged.
Do not recount their storage improvements or Python retirement as pending work.
The [current validation, migration and deletion plan](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md#current-closeout-validation-migration-and-deletion-2026-10-02)
prioritizes #5413/#5466/#5283 closeout, installed reversible qualification,
bounded opt-in adoption, canonical creation/defaults and last-caller deletion.
Existing Goal migration, two-policy ownership retirement and storage-format
upgrade have separate receipts and exits. Original-receipt recovery does not
justify retaining `legacy` as a live policy. Required migration readers remain.

A bounded cohort can start after its installed recovery and relevant execution
controls pass; it does not certify a released default or formal ten-day D2.
Frozen failures/missing evidence remain visible. T4 deletes proven redundant
owners alongside implementation, without waiting for R6 or all Python to vanish.
This replaces stale current-count estimates, not historical execution evidence.

File retained-state storage now reuses the existing TS checkpoint/delta codec,
stacked on #5063's verified read cache and RPC budgets. Original revisions,
Expand Down Expand Up @@ -1347,9 +1348,11 @@ to an independent reference; no lost acknowledged commit or repeated effect is
acceptable. Use disposable goals, never active user state. Compressed clocks do
not qualify wall-clock endurance; publishing this RFC starts no soak or monitor.

A code PR can land while soak evidence remains pending, with promotion held.
Promotion requires both exits, explicit import/fencing/export rehearsal and
maintainer review. Publish compact reproducible evidence, not raw private logs.
A code PR can land while formal soak evidence remains pending. Formal profile
promotion requires both exits, explicit import/fencing/export rehearsal and
maintainer review. A separately authorized, bounded opt-in cohort uses the
installed recovery decision above; it does not claim that formal profile.
Publish compact reproducible evidence, not raw private logs.

#### SQLite-for-file transition milestones (proposal)

Expand All @@ -1363,8 +1366,9 @@ is gated by evidence below, not by calendar dates or this PR's merge status.
| --- | --- | --- |
| Candidate conformance | Review #4121's atomic commits, original receipts, cursor/digest integrity, typed provider-open failures, real CLI and OS/runtime tests. | Candidate only. File remains default; no live migration or promotion. |
| Bounded local profile (L) | Meet this section's unchanged workload/budget matrix, including 64 KiB matched 10k/100k runs, 1 MiB and 300k headroom, cold startup, lock wait, RSS and logical write growth. Qualify bounded checkpoints/deltas and receipt lookup while preserving exact historical scans. | No default flip. Keep integrity checks; if their cost grows beyond the profile, fix the design or narrow the explicitly supported profile. |
| Fenced migration and recovery (I/F prerequisites) | On disposable Goals, prove file-to-SQLite import, exact receipt/replay equivalence, consumer cursor/outbox preservation, crash/disk-full recovery and reverse export/rollback. Include the required independent legacy/file/PostgreSQL read-only rehearsal where shared routing or projections change. | Tooling and migration manifest must be reviewed first. Today's empty-goal selector is not an existing-goal migration API. Never test on an active user's Goal. |
| Elapsed qualification and opt-in canary | Complete an actual >=10-day synthetic soak, including the specified restart, sleep, day-1 retry and 24 h consumer-lag cases. Then request separate authorization for a small opt-in operator canary with recorded stop/rollback criteria. | All C/I and selected-provider holds still apply. Evidence from accelerated volume cannot replace elapsed time; a canary does not authorize a general default. |
| Fenced migration and recovery (I/F prerequisites) | On disposable Goals, prove file-to-SQLite import, exact receipt/replay equivalence, consumer cursor/outbox preservation, crash/disk-full recovery and reverse export/rollback. Include the required independent legacy/file/PostgreSQL read-only rehearsal where shared routing or projections change. | Tooling and migration manifest must be reviewed first. Use the reviewed existing-Goal archive/cutover API; an empty-goal selector alone is insufficient. Never test on an active user's Goal. |
| Recoverable opt-in canary | Verified installed backup/migration/restart, ordinary commands, relevant interruption/concurrency controls and reverse migration preserving new writes; separately authorized and limited to the demonstrated workload. | May precede formal ten-day qualification. Record stop/rollback criteria; no general default or formal-horizon claim. |
| Formal elapsed qualification | Complete the actual >=10-day synthetic soak with specified restart, sleep, day-1 retry and 24 h consumer lag; reconcile existing evidence with changed boundaries. | Accelerated volume does not replace elapsed time; formal profile holds and frozen reports remain explicit. |
| New-Goal default decision (F) | Maintainers accept the qualified profile and canary results, operational diagnostics, backup/restore procedure, release instructions and default-disable path. Ship the default change in a separate disclosed release change. | Apply only to newly created eligible local Goals. Existing explicit file selections remain pinned. Unsupported runtimes/filesystems require an explicit supported choice; no silent backend switch on open failure. |
| Existing-Goal migration and file retirement | Migrate opt-in cohorts using the reviewed fenced workflow; reconcile receipts, history, projections and rollback after each cohort. Inventory the last file-primary callers and compatibility windows before removing any path. | Each Goal needs explicit migration authority. Retire file as the ordinary primary only after that evidence; retain reference/import/export support until its own callers and retention duties end. |

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -21,18 +21,18 @@
- 语言说明:[英文版](./shared-goal-authority-state-provider-v0.md)与本中文版互为
语义镜像;两者不一致属于缺陷

## 当前交付边界(2026-09-28)
## 当前交付边界(2026-10-02)

按 `ce3862e33` 核对,#5054、#5140、#5144、#5156、#5173、#5175、#5169
均已合并。事件退役、archive 恢复、managed 进程监督、reviewed 本地切换和 native
drain 不再计作新待办 PR。此后 SQLite 读取证明优化
[#4931](https://github.com/loopx-project/loopx/pull/4931) 已在 `9482a9496` 合并;D2 资格化仍未完成。
按 main `9b0486dc1` 核对,#4931、#5251、#5395、#5417、#5436 已合并,
不再把这些存储改进和 Python 退役重复记作待办。
[当前验证、迁移与删除计划](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md#当前收尾验证迁移与删除2026-10-02)
优先收尾 #5413/#5466/#5283,再做安装态可回退验证、有界自愿采用、canonical
创建/默认接入及最后调用方删除。存量 Goal 迁移、两策略退役和格式升级各有独立
回执及出口;原回执恢复不能成为保留 legacy 活跃策略的理由,必要迁移 reader 保留。

接下来并行验证整 Goal 执行/消费者集成和本地 profile,再统一新 Goal/安装/设置
及受支持升级入口,切走最后调用方时同步删除对应旧 writer。保留必要 Host IO、
原回执与迁移 reader。本轮未认证额外某个 Python 模块已死,也不承诺固定剩余 PR 数。
[删除清单、工程窗口、本机证据及剩余工作](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md)
替代旧记录的当前数量估算,旧执行证据仍按历史保留。
有界 cohort 在安装恢复和相关执行控制通过后可开始,不代表发布默认值或正式十天
D2 已通过;冻结的失败/缺项保持可见。T4 随实现删除已证明重复的 owner,不等 R6
或所有 Python 消失。本节替代陈旧的当前数量估算,不覆盖历史执行证据。

## Todo 事件路径退役(2026-09-25)

Expand Down Expand Up @@ -1031,8 +1031,9 @@ crash、disk-full、backup/restore lineage,以及一次受支持 upgrade/rollb
一次性 goal,不碰活跃用户状态。压缩时钟不证明自然时间耐久性;发布本 RFC 不启动 soak
或 monitor。

代码 PR 可在 soak 证据待补时合入,但 promotion 继续 hold。两个出口、显式 import/
fencing/export 演练与 maintainer review 都通过才可晋升。发布紧凑可复现证据,不发布
代码 PR 可在正式 soak 证据待补时合入。正式 profile 晋升仍须两个出口、显式
import/fencing/export 演练及 maintainer review;另行授权、有界 opt-in cohort
按上方安装态恢复决策执行,不宣称正式 profile 通过。发布紧凑可复现证据,不发布
原始私有日志。

#### SQLite 替换 file 的阶段节点(提案)
Expand All @@ -1046,8 +1047,9 @@ fencing/export 演练与 maintainer review 都通过才可晋升。发布紧凑
| --- | --- | --- |
| 候选 conformance | 评审 #4121 的原子提交、原始 receipt、cursor/digest 完整性、typed provider-open 失败、真实 CLI 与 OS/runtime 测试。 | 仅候选。file 仍默认;不迁移活跃 Goal,不授予 promotion。 |
| 有界本地 profile(L) | 满足本节不变的负载与预算矩阵:64 KiB 下匹配的 10k/100k、1 MiB 与 300k 余量、冷启动、锁等待、RSS、逻辑写入增长;资格化有界 checkpoint/delta 和 receipt 查询,同时保留精确历史 scan。 | 不切默认。保留完整性校验;成本超出 profile 时修正设计或明确缩小支持范围。 |
| 带 fence 的迁移与恢复(I/F 前置) | 在一次性 Goal 上证明 file→SQLite 导入、原始 receipt/replay 等价、consumer cursor/outbox 保留、crash/disk-full 恢复和反向导出/回滚;共享路由或投影变化时纳入要求的独立 legacy/file/PostgreSQL 只读演练。 | 先评审工具与 migration manifest。当前空 Goal selector 不是已有 Goal 的迁移 API;不得用活跃用户 Goal 做测试。 |
| 自然时间资格化与 opt-in canary | 完成真实 >=10 天合成 soak,覆盖本节规定的重启、休眠、第 1 天 retry、24 h consumer lag;随后单独申请小规模 opt-in operator canary,记录停止与回滚条件。 | C/I 与所选 provider 的全部 hold 仍有效。加速容量不替代自然时间;canary 不授权通用默认。 |
| 带 fence 的迁移与恢复(I/F 前置) | 在一次性 Goal 上证明 file→SQLite 导入、原始 receipt/replay 等价、consumer cursor/outbox 保留、crash/disk-full 恢复和反向导出/回滚;共享路由或投影变化时纳入要求的独立 legacy/file/PostgreSQL 只读演练。 | 先评审工具与 migration manifest。采用已有 reviewed archive/cutover API,空 Goal selector 本身不足以完成存量迁移;不得用活跃用户 Goal 做测试。 |
| 可恢复的 opt-in canary | 安装态备份/迁移/重启、普通命令、相关中断/并发控制及携带新写入反向迁移通过;独立授权,限于已证明负载。 | 可先于正式十天资格;记录停止/回退条件,不宣称通用默认或正式时长已通过。 |
| 正式自然时间资格 | 完成实际 >=10 天合成 soak,含规定重启、休眠、第 1 天 retry 和 24 h consumer lag;按变化边界对账既有证据。 | 加速容量不替代自然时间;正式 profile 的 hold 和冻结报告仍显式保留。 |
| 新 Goal 默认决策(F) | 维护者接受合格 profile、canary 结果、运维诊断、backup/restore 流程、发布操作说明和关闭默认的路径;在独立且明确披露的发布改动中切默认。 | 仅适用于新建且符合条件的本地 Goal;已有显式 file 选择保持固定。不受支持的 runtime/filesystem 需显式选择支持方案,打开失败不能静默切 backend。 |
| 已有 Goal 迁移与 file 退役 | 按已评审的 fenced workflow 逐批 opt-in 迁移,每批核对 receipt、历史、投影和回滚;删除路径前列清最后的 file-primary caller 与兼容窗口。 | 每个 Goal 需要明确迁移权限;证据满足后才退役常规 primary 角色。参考/导入/导出支持保留到其 caller 与保留责任分别结束。 |

Expand Down
Loading
Loading