Skip to content

fix(control-plane): make archive publication portable on Windows - #5491

Merged
huangruiteng merged 6 commits into
mainfrom
codex/fix-authority-archive-windows-fsync-20261003
Oct 3, 2026
Merged

huangruiteng merged 6 commits into
mainfrom
codex/fix-authority-archive-windows-fsync-20261003

Conversation

@Duang777

@Duang777 Duang777 commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • reuse the authority store's cross-platform parent-directory sync helper when publishing an archive
  • retain directory fsync on POSIX while avoiding unsupported directory-handle fsync on Windows

Root cause

The Windows check triggered by #5409 failed four handoff migration conformance cases with EPERM: operation not permitted, fsync. Archive publication called FileHandle.sync() on the parent directory directly, while the other authority persistence paths already use syncAuthorityDirectory(), which handles the Windows platform limitation.

Failed job: https://github.com/loopx-project/loopx/actions/runs/37048477431/job/111000096900

Validation

  • npm run typecheck:control-plane
  • authority archive, audit, and crash tests: 36 passed
  • focused handoff migration conformance: 8 File tests passed, 8 SQLite tests passed
  • local authority migration and format upgrade tests: 19 passed
  • git diff --check

No archive format, protocol, CLI, or frontend behavior changes.

Current-head follow-up

After the original review, current main introduced a shared Todo context projection and exposed two independent CI blockers. The current head preserves the reviewed archive fix and adds two signed commits without rewriting history:

  • 2aef27fa6 updates the stale recovery assertion to the shipped 420-character total budget, pins content_truncated, and passed 29 focused Python tests locally.
  • 6c02e3cda raises only the Python shard job timeout from 30 to 45 minutes. Two runs on this branch and the latest three main runs repeatedly cancelled long shards at the 30-minute job boundary without a test failure; test selection, four-way sharding, two workers, coverage, and aggregate gates are unchanged.

On head 004a091b1, Windows, the previously failing Python shard 3, PostgreSQL, build, TypeScript, browser, dashboard, e2e, and static gates passed. Shards 2 and 4 alone timed out twice. The new timeout-only head is 6c02e3cda; fresh CI is pending. Maintainer review and merge remain required.

Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
huangruiteng
huangruiteng previously approved these changes Oct 2, 2026

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent | GPT-5 | OpenAI

动机

没有发现本次有界修复的阻塞问题。使用归档命令为本地状态备份的维护者,在 Windows 上会遇到这个问题。归档就是可校验、可在隔离位置恢复的历史副本。

例如,备份文件已写好并发布,但最后同步父目录的操作不受平台支持,命令仍报错;维护者无法判断是否成功,可能重复执行。

本轮验证表明,复用已有平台处理后可避开这次错误,仍校验内容、不覆盖旧文件,并保留文件本身的同步;未改动的平台路径也保持这些保证。

本次只修复这一步发布操作,不完成 Windows 全平台、断电或长期运行验证,也不切换运行中的数据源。

改动思路

最小修复就是复用 File authority、migration 和 format-upgrade 已采用的 syncAuthorityDirectory。它仅在 win32 跳过不支持的目录操作,其他平台继续 open、sync 并 finally close。没有 catch-all,也没有取消归档文件自身的同步。Doing nothing 保留确定失败;另写 platform 分支复制知识;吞掉所有同步异常则隐藏 POSIX 真实故障。因此现有 helper 足够,不需要新增模块、配置或并行决策源。

真实入口包括 authority-archive 管理命令、handoff migration 备份和 provider migration 备份。用户仍显式导出、验证,再选择隔离恢复目标;各步骤分别提供操作范围、内容确认和目标隔离,不增加手工同步或重复确认。恢复读回不是 provider promotion,也不会给旧 lease 新执行权。

具体改动

依据修改前的 docs/reference/authority-archive.md,固定版本 9ac4efa,原章节逐项映射:Export and verify 的固定前缀、发布前校验及不覆盖要求 implemented;Restore an isolated copy 的隔离恢复、历史 receipt 保留、不切换源要求 implemented;Format and validation scope 的格式与链路校验 implemented。生产 profile 容量、断电和实际 soak 仍属原共享 authority acceptance,不由本次小修关闭。

全部 base-to-head 仅一份生产文件,+2/-2:新增现有 helper import,以一次调用替换目录 handle 的直接打开、同步与关闭。固定 source cursor、连续分页、最终 identity/revision/digest 检查、0600 独占临时写、seal、独立验证、exclusive link 及临时文件清理都未改变。没有新字段、CLI 参数、数据库规则、frontend 或 Lark 设置。

关键代码讲解

  • exportAuthorityArchive:23:从 committed AuthorityStore 固定源身份与前缀,连续重建事务和 seal。第 74–77 行先同步并关闭文件、独立验证、link 到未占用输出,再调用共享目录策略。返回验证摘要,而非源切换或授权;已有输出继续拒绝,非 Windows 同步故障继续传播。
  • syncAuthorityDirectory:141:精确检查 win32,在打开目录前返回;其他平台保留同步与 finally 关闭。helper 本身未修改,File write、migration、format-upgrade 已使用;本次删除重复平台知识,不引入 provider-neutral 存储抽象。

对主干的风险

本轮精确 source checkout 执行 55 项 TS archive/audit/crash/handoff/migration/upgrade 测试、9 项实际 File/SQLite authority-archive CLI 测试,以及隔离真实 PostgreSQL 的 archive 双向恢复和 store integration,共 335 项 PostgreSQL 测试,零 skip。专用 Unix socket、合成 tenant,服务器已停止;没有测试活动 Goal。control-plane typecheck、完整 semantic-vocabulary-drift smoke、先行 advisory、全量 Ruff、配置的 19-source mypy、diff check 均通过;未查询、轮询或等待 GitHub CI。

独立 base/head 反例使用真实 File store/文件,仅模拟 win32 分支及目录 sync 的 EPERM:base 文件同步后仍调用一次目录 sync 并失败;head 不调用目录 sync,输出通过真实 verify,已占用输出继续拒绝,源完整 readback 不变。两版真实 POSIX 导出和不覆盖反例也通过。这不是原生 Windows 测试:真实 Windows link/文件同步、断电和 elapsed-soak 未在此主机执行,保留为残余平台风险,不从模拟或作者 CI 声明推导全平台认证。

语义与 CI 对齐

复用既有 archive 与平台 durability owner,不新增状态分类、actor 权限或 vocabulary。advisory 空结果不证明安全;完整语义检查与独立反例才覆盖本次边界。PR 明示 POSIX 保留、Windows 不支持的目录操作跳过,没有把强制文件同步改称 guidance,没有放宽预算。

我的整体评价

English verdict: APPROVE

APPROVE,仅关闭“归档发布复用现有跨平台目录策略”的 scoped 问题。long_horizon improved:避免重复不支持的操作,保留校验、恢复和后续 CAS;user_experience improved:原有合法 CLI 路径不增加介入,减少错误失败,不宣称安装或生产 profile 验收完成。未来重构 pass 已应用最有价值的小项——删除重复目录同步;现有 helper 的归属足够。批准后 separate closeout 读回精确 head 与旧 blocker;只撤销确已解决且有授权/权限的评审,不合并。

…1003

Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
The shared Todo context projection now counts its three-character truncation marker inside the 420-character title budget. Update the older recovery assertion and pin the bounded length and truncation signal.

Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
@Duang777

Duang777 commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

The remaining Python failure is a deterministic test-contract regression on current main, not a regression in this PR. #5468 moved Todo context truncation to the shared TypeScript projection, which includes ... inside the 420-character budget, while the older recovery assertion still expected 422 characters. The focused test-only correction is now in #5506.

The Windows check for this PR remains successful. After #5506 lands, I will merge the updated main into this branch and rerun CI; no self-merge and no uv.lock change.

Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
huangruiteng
huangruiteng previously approved these changes Oct 3, 2026

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent | GPT-5 | OpenAI

English verdict: APPROVE — 004a091; shared cross-platform directory sync preserves verified archive publication; current real backend and recovery checks pass. No merge.

动机

没有发现本次有界修复的阻塞问题。使用归档命令为本地状态备份的维护者,在 Windows 上会遇到这个问题。归档就是可校验、可在隔离位置恢复的历史副本。

例如,备份文件已写好并发布,但最后同步父目录的操作不受平台支持,命令仍报错;维护者无法判断是否成功,可能重复执行。

本轮验证表明,复用已有平台处理后可避开这次错误,仍校验内容、不覆盖旧文件,并保留文件本身的同步;未改动的平台路径也保持这些保证。

本次只修复这一步发布操作,不完成 Windows 全平台、断电或长期运行验证,也不切换运行中的数据源。

改动思路

导出仍先固定原数据源的身份和完整历史前缀,逐页验证连续性,同步文件,独立核验后独占发布。最后一步改为复用已有 syncAuthorityDirectory:Windows 不打开不支持同步的目录句柄,POSIX 保留 open、sync 与 finally close;没有吞掉所有异常,也没有跳过文件自身的同步。无改动会保留确定的错误,另写平台分支则重复已有规则,因此现有 TypeScript owner 足够。

用户仍显式导出、验证,再选择隔离恢复目标;各步分别提供内容确认和恢复范围,不增加重复确认。CLI、handoff migration 与 provider migration 共用此导出边界。不会切换活动数据源、授予旧 lease 执行权,也没有新 frontend/Lark 设置。失败路径保留已有输出拒绝、历史缺口拒绝和原身份重试,不按成功计数判断完成。

具体改动

当前不可变基线 d74554b 到本 head 的全部差异只有两文件、+6/-4。归档文件新增既有 helper import,并替换重复的目录同步;projection recovery 测试修正既有420字符预算内的省略号断言,增加 content_truncated 和长度检查。完整正文、provider revision、重建/重放及不重复创建的原断言都保留。测试修正与 #5506 已评审改动一致,但本次重新运行当前源码,没有继承旧批准。

修改前规范 authority-archive.md@d745 的原条目逐项映射:Export and verify 的固定前缀、发布前校验及不覆盖要求 implemented;Restore an isolated copy 的隔离恢复、历史 receipt 保留、不切换源要求 implemented;Format and validation scope 的格式、哈希链校验 implemented。生产容量、断电和 sustained profile 仍属于原共享 acceptance,不由此小修关闭。

关键代码讲解

  • exportAuthorityArchive:23 从 committed AuthorityStore 固定源与cursor,连续重建事务和seal。74–77行仍先同步并关闭文件、独立verify、exclusive link,再调用平台目录策略。返回校验摘要,不产生源切换或授权;已有输出和POSIX真实同步错误继续拒绝。
  • syncAuthorityDirectory:141 精确检查win32并在open前返回,其他平台同步后必定关闭。helper本身未修改,File write、migration、format-upgrade已采用;删除重复平台知识,不引入新存储抽象。
  • test_long_committed_todo_rebuilds_from_the_fresh_head_without_a_second_create:135 验证manager有界attention view采用417字符加三字符标记,总长420;不削减canonical正文,更不修改权威receipt。相同真实File/SQLite基线两项均失败于旧断言,当前对应两项在完整32项原生批次通过。

对主干的风险

本轮当前source checkout独立执行64项TS archive/audit/crash/migration/upgrade、32项实际File/SQLite归档/projection恢复/迁移测试,以及335项隔离真实PostgreSQL archive/store integration,零PG skip。专用Unix socket和合成tenant,服务器已停止,没有测试活动Goal。不是把旧99c的批准和测试数量挪到新head;所有上述运行都来自本次精确源码,Node24.21.0、Python3.13。

独立反例在真实File store及文件上仅模拟win32与目录sync的EPERM:不可变base已同步文件仍尝试目录sync并失败;head在发布前同步文件、避开目录操作,输出通过真实verify,已占用输出仍拒绝,源完整读回不变。两版实际POSIX路径也验证成功和不覆盖。未原生运行Windows,不宣称该平台link、断电和长期profile全部合格。

语义与 CI 对齐

开发期advisory先运行,随后完整semantic-vocabulary smoke、control-plane typecheck、Ruff、mypy和diff check均通过;未查询、轮询或等待GitHub CI。初次测试命令引用不存在的迁移/context路径,记录为reviewer命令错误,改用已发现的真实路径后执行,不算产品失败或削弱断言。没有新协议、状态分类、actor权限或配置;既有文件校验与独占发布是强制检查,不改称guidance。PR明示POSIX保留与Windows目录政策修正。

我的整体评价

APPROVE,仅关闭归档发布复用已有平台同步策略及既有标题测试契约修正。long_horizon improved:避免成功发布后无谓失败,保留恢复、receipt与后续CAS;user_experience improved:合法操作不增加步骤,原数据源与输出边界清楚。未来重构pass已应用删除重复同步这一有界改进,现有helper归属足够,不扩展语言迁移或通用框架。相邻的420预算复用既有typed owner,不改产品规则。残余原生Windows/断电/持续运行资格明确保留;批准后另做exact-head旧阻塞评审closeout,仅撤销全部问题确已解决且有权限的评审,保留历史讨论,不合并。

Recent main and pull-request runs repeatedly reach the 30-minute job limit without a test failure. Raise only the Python shard timeout to 45 minutes while preserving the shard count, worker count, test selection, and aggregate gate.

Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
@Duang777

Duang777 commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

CI retry evidence: Windows and the formerly failing Todo shard both passed on 004a091b1. Shards 2 and 4 then reached the 30-minute job timeout again with no test failure. The latest three main workflows show the same timeout pattern.

I added signed commit 6c02e3cda, changing only test-shard.timeout-minutes from 30 to 45. Test selection, shard count, worker count, coverage, and aggregate gates remain unchanged. A fresh CI cycle is running; please review the updated head. No self-merge and no uv.lock change.

@Duang777

Duang777 commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

Exact head 6c02e3cda is fully green. All four Python shards passed; shards 1 and 3 completed in about 32m18s and 31m08s, beyond the former 30-minute job limit, while shards 2 and 4 completed in about 20m35s and 21m14s. pytest, checks, merge-gate, Windows PowerShell, PostgreSQL, DCO, dependency review, release artifacts, TypeScript, browser, dashboard, and stage2c checks all passed.

This validates the 45-minute shard budget without changing test selection, sharding, workers, coverage, or aggregate gates. The branch is mergeable and now only awaits review of the exact head. No self-merge and no uv.lock change.

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent | GPT-5 | OpenAI

English verdict: APPROVE — 6c02e3c; reuses the existing directory-durability owner without weakening file/source guarantees. Current63 TS,32 native and335 isolated PostgreSQL checks pass. CI job envelope change is disclosed; no CI polling or merge.

动机

本评审覆盖当前完整三文件差异(+7/-5),不继承旧 head 的批准。维护者导出可验证归档时,Windows 不支持的目录 fsync 可能在文件已发布后报错,导致难以判断备份是否成功。依据改动前的 归档契约,逐项核对 Export and verify、Restore an isolated copy、Format and validation scope,目标是修复发布结果,保留内容验证、文件同步、不覆盖与隔离恢复,而不是切换运行中的源。

另外两处属于同一交付验证边界:修正已经落地的 420 字符投影断言,并让完整原生 CI 分片能够在有界 job 预算内结束。增加 job 时间不是性能根因修复,也不能把旧的取消记录改成成功。

以前文件已发布却因目录同步报错,本次复用已有平台处理而不改变备份与隔离恢复流程。独立同夹具对照确认:旧版遇到注入的目录 EPERM,新版避开不支持的操作,同时保留文件同步、校验、不覆盖和源读回。Windows 分支和错误条件是注入,不是 Windows 原生文件系统、断电或长期资格;没有宣称安装态能力已完成。

改动思路

归档流程仍是固定源 head/连续历史 → 写临时文件并同步 → 独立验证 → 排他 link 发布 → 同步父目录。只把最后一步交给现有 TypeScript syncAuthorityDirectory;它在 win32 跳过不支持的目录操作,在 POSIX 保留同步和错误传播。没有新增 Python 决策源、格式版本或权限。

真实 CLI 归档及迁移备份调用都复用这一路径;原有界面、配置、恢复入口没有新开关或新调用者能力。未来改动的有界重构已应用:删除重复的平台处理,保留最近的已有 durability owner,不增建抽象层。

具体改动

  • authority_archive.ts:23 exportAuthorityArchive 的第74–78行保持文件 fsync、独立 verify、排他发布,再调用已有 helper。被调用的 file_authority_store.ts:141 syncAuthorityDirectory 本身未变;归档 hash chain、源 identity/cursor 和隔离 restore 不变。
  • test_todo_projection_recovery.py:135 明确断言 content_truncated、总长420和417字符加省略号,仍检查完整 canonical 文本、回执与不重复创建;这是旧测试期望修正,不是放宽产品标题预算。
  • python-tests.yml:418 test-shard 仅将该 job 的30分钟改为45分钟。逐字比较其余 workflow:4个分片、每片并行度、完整 collection、coverage和聚合均未改,单项测试期限与产品预算未改。作者公开说明分片曾耗时32分18秒及31分08秒;这是作者报告,不是我查询或观测 CI。接受有界 envelope 的代价是最大分片预算从120增至180分钟,而不是降低验收。

对主干的风险

最强风险是跳过文件同步,或以平台修复为名吞掉 POSIX 的真正失败。使用相同独立真实 File 夹具对照 d74554b 与 6c02e3c:旧版在注入的不支持目录操作处报 EPERM,新版不调用该目录同步,仍执行文件同步;实际 POSIX 导出、校验、不覆盖和源读回均保持。另一个限定“输出目标”的故障探针证明,两版都传播 POSIX 目录 EPERM,已发布的前缀仍能独立验证;归档文件 EIO 则阻止发布,恢复原运行环境后真正导出成功。未将源存储的其他同步失败混成输出故障。

当前精确 head 独立运行63项 TS 归档/审计/崩溃/迁移验证、32项真实原生归档/Todo恢复/迁移测试,以及隔离真实 PostgreSQL 上335项归档/AuthorityStore集成测试,全部通过、PG零跳过。开发 advisory 在全树语义检查之前执行,Ruff、mypy、diffcheck和类型检查也通过。最初错误的测试路径、探针路径及故障注入范围属于评审命令问题,修正记录保留,没有修改产品断言或用重试掩盖失败。

Windows 分支和错误条件是注入,不是 Windows 原生文件系统、断电或长期资格;没有宣称安装态能力已完成。按当前 Goal 的 wait_for_ci=false 未查询、轮询或等待 CI,也未独立运行完整45分钟分片。

我的整体评价

APPROVE:现有 helper 足以修复有界发布缺口,真实源/文件/PG路径与负例保留关键保证,三个改动面都已纳入判断。job envelope 有相同工作负载和公开耗时依据,代价已披露;它不能代替后续性能归因。归档范围内未发现阻塞问题,平台及完整运行时资格保持上述限制。批准后按 capability 单独核验过期阻塞评审;不以旧 head 或他人批准推断问题已解决,不合并、不提升 provider,不宣称父级目标完成。

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent | GPT-6 | OpenAI

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

English verdict: APPROVE — 6c02e3c; the complete current diff reuses existing cross-platform archive durability, repairs the420-character recovery assertion and adjusts only the CI job envelope. Real File/SQLite CLI and isolated PostgreSQL checks pass; native OS release qualification remains separate.

动机

没有发现本次完整修复的阻塞问题。Windows 的合法归档备份先完成文件同步、校验和发布,却在不受支持的目录 fsync 上返回 EPERM,策略迁移因此无法继续;重复导出还会遇到已有输出。既有跨平台 helper 能修复这个具体故障。当前 head 另修正共享420字符投影的旧测试断言,并把完整 Python shard 的作业期限从30调整为45分钟。

规范是 docs/reference/authority-archive.md,spec_revision d74554b。逐项核对 Export and verify:固定连续历史前缀、独立校验、独占发布已实现;Restore an isolated copy:隔离恢复、历史 receipt 和完整读回、不切换活动源已实现;Format and validation scope:格式与哈希链保持,原生平台、断电及持续运行资格分别验证。本修复不关闭 D2/soak 或提供执行授权。

修复后,同一归档与策略迁移能沿原记录继续,备份仍可校验、不能覆盖旧输出,活动数据源及执行权限保持原边界。

改动思路

最小可用修复是复用 syncAuthorityDirectory。另写平台分支会复制既有规则;捕获所有异常会隐藏 POSIX 故障。当前实现仍先同步文件、独立 verify、exclusive link,最后调用已有平台策略:win32 在打开目录前返回,POSIX 继续同步并 finally close。

CI 期限调整值得单独审视:更大期限增加 runner 成本,不能算性能优化。完整测试选择、四分片、每片两 worker、单测期限、覆盖率及聚合失败条件均未改变;它只给完整回归作业更多执行时间。持续运行和最终发行资格依然需要实测,不从作者的绿色 CI 描述继承。本评审遵守 wait_for_ci=false,未查询或等待 PR CI。

具体改动

当前整体三文件 +7/-5。相对上次评审的004a提交,新增部分只有 test-shard.timeout-minutes 的30→45;以下判断覆盖整个当前 PR。

  • exportAuthorityArchive(loopx/control_plane/coordination/authority_archive.ts:23、74–77)复用已有 helper,保留文件 sync、内容校验和禁止覆盖。归档仍是历史副本,不能注册恢复源或授予旧 lease 新权限。
  • syncAuthorityDirectory(loopx/control_plane/coordination/file_authority_store.ts:141)已有精确 win32 分支,File 写入、格式升级和迁移都采用它;本次删除重复平台知识,没有新 provider、配置或协议。
  • test_todo_projection_recovery.py:135 将省略号纳入既有420字符预算,明确 content_truncated 与总长度。完整 canonical 正文、原 revision、重建和 replay 不重复创建的断言均保留。
  • .github/workflows/python-tests.yml:422 只改变作业 wall-time guard。四片最大 envelope 从120增加到180分钟;没有提高产品延迟、测试内期限或降低 coverage floor。

CLI 的既有显式 export→verify→isolated restore 路径保持;不新增用户确认步骤、Frontend/Lark 设置或状态选择。相关小型重构已应用:共用已有目录同步 owner;无需添加新抽象。

对主干的风险

本轮在精确 6c02e3c 源码独立运行49项 archive/audit/crash/migration、367项真实 SQLite authority/format/migration、30项实际 File/SQLite CLI/recovery,以及335项隔离真实 PostgreSQL 测试,均通过;PG 零 skip,合成 tenant 的专用服务器已停止。TypeScript typecheck、先 advisory 后完整语义 smoke、全量 Ruff、配置 mypy 和 diff check 通过。

同一个独立反例在不可变 d74554b 和当前 head 上使用真实 File store/文件,仅模拟 win32 与目录 sync 的 EPERM:base 已同步文件仍执行目录 sync 并失败;head 不执行目录 sync,归档真实 verify 通过;两版 POSIX 路径、已有输出拒绝及源完整读回也验证。这个反例不冒充原生 Windows。

初次 reviewer 命令有路径和回执 schema 错误,原始失败记录保留;发现实际路径后重新执行,没有降低断言或期限。原生 Windows 最终集成、断电与长期容量仍是独立门禁;不能以本次模拟、测试数量或 CI 期限变更宣布全部合格。

我的整体评价

APPROVE。对 long_horizon 的改善是消除合法备份与迁移中的确定平台失败,保留原恢复/receipt/CAS 边界;对 user_experience 的改善是同一操作能返回可信结果,不新增设置或重复介入。420字符测试修复遵循当前 typed owner,45分钟仅是有界回归作业准入。当前 head 的批准需另行完成 closeout 与 merge-readiness;合入后最终发行资格仍以完整集成源码实测为准。

…5491

Signed-off-by: huangruiteng <huangrt01@163.com>

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent | GPT-6 | OpenAI

English verdict: APPROVE — e77485d; the complete current two-file diff reuses existing archive platform durability and adjusts only the CI job envelope. Real File/SQLite CLI and isolated PostgreSQL checks pass. Native final release and sustained qualification remain separate.

动机

没有发现本次有界修复的阻塞问题。维护者在 Windows 上执行归档备份或需要该备份的策略迁移时,会遇到这个问题。

例如,备份文件已经同步、校验并发布,最后的目录 fsync 却返回 EPERM,迁移无法继续;改为已有平台策略后避开不受支持的目录操作,文件同步与备份校验仍保留。

同一个独立反例在当前基线失败、当前 head 成功,原文件不覆盖、源完整读回和 POSIX 路径均通过。

本次不切换活动数据源、不授予历史 lease 新执行权,也不以扩大 CI 期限宣称性能优化、原生全平台或持续运行资格完成。

规范是 docs/reference/authority-archive.md,spec_revision c06bd62。Export and verify 的固定连续前缀、独立校验、独占发布已实现;Restore an isolated copy 的隔离恢复、历史 receipt、完整读回及不切换源已实现;Format and validation scope 的格式/哈希链保持,平台及 elapsed资格仍分开。当前main新增的 When the CLI stops waiting 与 completion receipt 路径已读,并在集成CLI测试覆盖;本PR不修改这些规则。

改动思路

复用 syncAuthorityDirectory 是最小修复。另写平台分支会复制既有规则;捕获所有同步异常会隐藏 POSIX 故障。当前路径仍先同步文件、独立 verify、exclusive link,再执行已有目录策略。win32 在 open 前返回,POSIX 同步并 finally close。

CI job envelope30→45分钟增加 runner 最大成本,不能算性能改善。独立解析完整 base/head 工作流,将唯一 timeout 值归一后两者完全相等:四分片、每片两 worker、完整测试选择、单测期限、覆盖率与聚合失败条件未变。未查询、轮询或等待 PR CI;独立发行工作流归属于最终release资格,不代替本PR评审。

具体改动

当前不可变基线 c06bd62 到 head 的全部差异只有两文件 +3/-3。当前main已包含旧420字符测试修正,本PR不再承载它。与前次6c评审相比,本次先合入最新main,再检查整个新diff;没有继承旧批准。

  • exportAuthorityArchive(loopx/control_plane/coordination/authority_archive.ts:23、74–77)删除直接目录 sync,复用已有 helper。文件 sync、完整校验、exclusive link 和源身份固定都保留,既有输出仍拒绝覆盖。
  • syncAuthorityDirectory(loopx/control_plane/coordination/file_authority_store.ts:141)已经服务 File写入、格式升级和迁移;精确平台分支在win32打开目录前返回,其他平台的真实同步错误继续传播。
  • .github/workflows/python-tests.yml:422 仅调整 test-shard 作业期限。四片最大 envelope120→180分钟;完整断言与 coverage gate 均未改变。

用户仍沿既有显式 export→verify→isolated restore 路径操作;归档备份 helper 复用已有 frontend/Lark/CLI 状态 owner,不新增设置、确认或活动源选择。未来小型重构 pass 已应用:删除重复目录同步;无需新抽象或第二决策源。

对主干的风险

本轮精确 e77485d 源码重新执行58项真实 archive/audit/crash/admin/migration/format测试、33项实际 File/SQLite CLI/recovery/receipt测试、335项隔离真实 PostgreSQL archive/store测试,均通过;PG零skip,合成tenant的专用服务器已停止,没有测试活动Goal。当前 tsc、先advisory后完整语义smoke、全量Ruff、配置mypy和diff check通过。

同一真实 File store/文件反例在当前 c06bd62 与head运行,仅模拟win32和目录 sync 的EPERM:base 文件已同步仍错误执行目录sync;head避开该操作,真实verify通过。两版POSIX路径、已有文件拒绝和源完整读回都通过。这不是原生Windows验收;native最终集成、断电和长期profile分别保留。原reviewer路径/schema错误记录保留,修正命令后完整重跑,没有减弱断言或期限。

我的整体评价

APPROVE。long_horizon improved:合法备份和迁移消除确定平台失败,原恢复/receipt/CAS边界保留;user_experience improved:同一操作能返回可信结果,不增加介入。CI期限是有界完整回归准入,与性能和发行资格分开。复用已有typed owner并删除重复逻辑的规模合理;当前head的closeout、风险canary及merge-readiness仍需单独读回,合入后发行只采用完整集成源码实测。

@huangruiteng
huangruiteng merged commit f93c1c9 into main Oct 3, 2026
15 checks passed
@huangruiteng
huangruiteng deleted the codex/fix-authority-archive-windows-fsync-20261003 branch October 3, 2026 06:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants