From 136299143b1348bc53225fde51305151120ebe5f Mon Sep 17 00:00:00 2001
From: hyk <4408344+hhyykk@users.noreply.github.com>
Date: Wed, 7 Oct 2026 19:45:50 +0800
Subject: [PATCH] docs(control-plane): reconcile current migration delivery
checkpoint
Signed-off-by: hyk <4408344+hhyykk@users.noreply.github.com>
---
.../2026-09-28-retirement-cadence.md | 32 +++++++++++--------
.../2026-09-28-retirement-cadence.zh-CN.md | 31 ++++++++++--------
.../typescript-control-plane-migration-v0.md | 32 ++++++++++++++-----
...script-control-plane-migration-v0.zh-CN.md | 31 ++++++++++++------
4 files changed, 81 insertions(+), 45 deletions(-)
diff --git a/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md b/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md
index ba3668565f..5854037a27 100644
--- a/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md
+++ b/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md
@@ -1,6 +1,6 @@
# Local authority: retirement cadence after integration
-- Current plan: October 2, 2026, `9b0486dc1`; historical audit: `ce3862e33`; adoption follow-up: `71525ab90`, September 28, 2026; [中文](2026-09-28-retirement-cadence.zh-CN.md).
+- Current plan: October 7, 2026, `06b6caa07`; historical audit: `ce3862e33`; adoption follow-up: `71525ab90`, September 28, 2026; [中文](2026-09-28-retirement-cadence.zh-CN.md).
- Owners: overall roadmap R3/R4/R5/R6; shared authority D1–D3; TS migration T0–T4.
- This replaces the **current inventory/estimates** in the September 27 recovery
and Host-supervision ledgers, not their historical validation results.
@@ -19,9 +19,10 @@
| #5170 | App delegated-result continuity; not every Turn/instance consumer |
| #4931 | Owned TS state replay reduces SQLite/archive historical reconstruction; no default change or D2 qualification |
-At the adoption follow-up #5106 (collaboration GoalRef), #5130
+At the September 28 adoption follow-up #5106 (collaboration GoalRef), #5130
(session GoalRef), #5139 (App Turn acceptance recovery) and #4915 (local-state
-location migration) remain open. Integrate/review those owners rather than
+location migration) were open. This is a historical inventory, not today's merge
+queue. Recheck those owners rather than
reimplementing them. Their scopes are dependencies only for affected callers;
local default does not wait for unrelated cloud or hundred-Agent work.
@@ -123,9 +124,11 @@ entrypoint tests, not attached-App or sustained-cost qualification. No store,
writer, outbox, historical format/receipt reader or permanent Host IO is retired;
C1, D2 and release-default adoption remain separate acceptance boundaries.
-## Current closeout: validation, migration and deletion (2026-10-02)
+
-Rechecked against main `8b5335a72` and the linked PR heads. This is the current
+## Current closeout: validation, migration and deletion (2026-10-07)
+
+Rechecked against main `06b6caa07` and the linked merged PRs. This is the current
execution plan for **R5 / D1–D3 / T0–T4**, replacing the previous A–D schedule;
older measurements remain source-specific evidence. R6 is a separate successor.
Storage format, authority selection and ownership policy are three distinct
@@ -141,13 +144,14 @@ retirement of the `legacy` handoff policy.
| Merged: #5436 | Original delegated Host lease renewal. Final Todo validation and stop acknowledgement remain distinct boundaries. |
| Merged: [#5413](https://github.com/loopx-project/loopx/pull/5413), head `2c99505c7` | Separate provider promotion from backed-up policy migration; reject fresh legacy configuration but recover historical operations. Retain the original CLI recovery evidence. Existing legacy Goals are not automatically migrated; a successful plan does not qualify their execution consumers. |
| Merged: [#5466](https://github.com/loopx-project/loopx/pull/5466), merge `066b5bf26` | Preserve the original lease through final acceptance. Installed consumer qualification remains distinct from merge. |
-| Review: [#5283](https://github.com/loopx-project/loopx/pull/5283), `1012d37f3` | Preflight optimization remains under review. Retain failed cold-CLI qualification rows; functional projection parity alone does not establish a performance pass. Do not declare the historical transient open failure explained by a synthetic failure. |
-| Approved, awaiting maintainer merge: [#5500](https://github.com/loopx-project/loopx/pull/5500), `a9e3d722c` | Recover the original canonical Goal creation operation through App retries. This creation/default-adoption prerequisite does not retire existing ownership policies. |
-| Affected-lane dependencies | [#5308](https://github.com/loopx-project/loopx/pull/5308) must prove child stop before settled acknowledgement; [#5398](https://github.com/loopx-project/loopx/pull/5398) preserves complete UI history/inspector facts. Scope these to consumers actually included in the trial. They are not SQLite-engine prerequisites or permission to ship a known broken journey. |
-
-The remaining open heads above concern preflight and creation recovery, not a
-fixed number of PRs to universal completion. The implementation packages remain creation/default adoption,
-policy migration plus legacy-policy retirement, and old-writer/capture retirement.
+| Merged: [#5283](https://github.com/loopx-project/loopx/pull/5283), merge `fd65e71f4` | Reuse the preflight optimization. Retain failed cold-CLI qualification rows; functional projection parity or merge alone does not establish a performance pass. Do not declare the historical transient open failure explained by a synthetic failure. |
+| Merged: [#5500](https://github.com/loopx-project/loopx/pull/5500), merge `9c8961076` | App retries recover the original canonical Goal creation operation. This delivered recovery boundary does not retire existing ownership policies. |
+| Merged: [#5805](https://github.com/loopx-project/loopx/pull/5805), merge `3a1a92ebd` | Canonical creation is the unconfigured new-Goal source default, with SQLite and `hard_lease`. Existing selections and explicit disabled/v0 behavior remain pinned; installed adoption, D2/D3 and release-default qualification remain separate. |
+| Merged affected-lane owners: [#5308](https://github.com/loopx-project/loopx/pull/5308), merge `7b13f88e8`; [#5398](https://github.com/loopx-project/loopx/pull/5398), merge `3870aa12d` | Reuse child-stop-before-settlement control and complete UI history/inspector facts. Qualify the actual consumers included in the trial; merge is neither a SQLite-engine qualification nor permission to ship a known broken journey. |
+
+The October 2 preflight/creation recovery queue above is merged; do not recreate
+those repairs. Remaining packages are installed creation/default and upgrade
+adoption, policy migration plus legacy-policy retirement, and old-writer/capture retirement.
They may combine only when caller ownership and rollback are coherent. Validation
can expose concrete repairs; do not manufacture a fixed remaining-PR total or
restart completed work to maintain one.
@@ -199,10 +203,10 @@ below.
| Package / existing owner | Work and decisive exit | Dependency / deletion / schedule |
| --- | --- | --- |
-| Close current heads; R3/R5 | Resolve exact-head findings in the open PRs above, inspect affected failures/conflicts, and present reviewed heads for maintainer merge. Record what is merged versus installed. | First target: 1–2 working days, subject to actual review/fix results. No unrelated optimization PR before closing these outcomes. |
+| Qualify merged consumers and current findings; R3/R5 | Reuse the merged owners above, inspect current affected failures and related open PRs, and assign only demonstrated remaining repairs. Record what is merged versus installed. | The old merge queue is closed. Proceed to the bounded installed matrix; do not reopen merged work or make unrelated consumers a universal prerequisite. |
| Installed recovery candidate; D1/D3, existing whole-Goal promotion task | Pin one merged source and actual CLI/App/Effect Node/SQLite identity. Independently restore a verified backup, run the matrix below on detached real data plus synthetic negatives, and complete File→SQLite→new writes→File. Then perform authorized per-Goal adoption and ordinary readback. | Begin immediately after relevant merges; target 1–2 working days for the bounded matrix. Keep the compatible recovery binary and archives. No live corruption/crash injection. |
| Bounded opt-in cohort; D2/D3 | When installed recovery and relevant execution controls pass, offer a reversible trial to at most 20 core developers. Publish workload/platform limits, backup/migration/disable instructions, known gaps, stop conditions and reporting route. Collect real daily use and failed cases. | Does not wait for every formal D2 axis or a new ten-day certificate. No invitation until rollback retains new writes. Does not certify a release default. |
-| Canonical creation/default adoption; D3/T3 | Reuse `machine_configuration/goal_storage.py` and `local_authority_defaults.ts`. Current setting only chooses the **post-promotion target** (`promotion_performed: false`). Complete new-Goal initialization, retry and upgrade, settings plus packaged App/CLI/Lark readback; explicit existing selectors stay pinned. | Implement after the bounded candidate is useful; activate the release default only at the decision below. Remove replaced creation/selection decisions in this package. Changing `file` to `sqlite` in one setting is insufficient. |
+| Installed canonical creation/default adoption; D3/T3 | Reuse #5500/#5805, `machine_configuration/goal_storage.py` and `coordination/local_authority_defaults.ts`. Unconfigured new Goals already initialize canonical SQLite/`hard_lease`; v0 and v1 `canonical_creation=false` retain post-promotion target behavior. Qualify installed initialization/retry, settings, upgrade and packaged App/CLI readback, with Lark when an affected caller is included. Existing Goal selections stay pinned. | Do not implement a second creation/default owner. Follow the [configuration/disable contract](../../../../reference/local-authority-provider-selection.md#new-goal-authority-machine-setting); removing the preference restores the source candidate default rather than disabling creation. Existing-Goal adoption and release-default qualification remain independent exits. |
| Two ownership policies; R3/R5/T4 | Use #5413's backup/plan/migrate owner. Inventory old/missing modes, finish eligible claims/leases and Host effects, migrate each authorized Goal, then narrow normal runtime types and defaults to `soft_claim` / `hard_lease`. Expose preview, authorized apply, result and failure/recovery in the existing Goal settings surface through the same owner; a CLI-only migration stage is partial. | Can proceed alongside cohort observation. Policy migration is independent of File↔SQLite conversion. Delete legacy execution only after the supported upgrade path and affected callers pass; never silently reinterpret legacy as soft. |
| Legacy writer and crossing removal; T3/T4 | Switch each last real caller to its TS owner, verify the matrix, delete Python decisions/private dispatch and old Markdown writes together. Reconcile shadow backlog before removing producers. Test the packaged CLI with retired paths absent. | Start already-proven internal deletions now; writer deletion follows that caller family's migration/adoption, not every R6 task or all Python disappearing. Each deletion has a concrete inventory and rollback. |
| Release-default decision; R5/D2/D3 | Reconcile supported installations, current-release comparison, representative sustained reads/writes/recovery, resource growth and existing soak applicability. Publish exact supported profile, failed/missing rows, release/upgrade guidance and disable path; disclose the default change. | No date inferred from test/PR counts. Formal ten-day/100k qualification retains its own required evidence. Existing File selections remain supported and pinned; unavailable SQLite never silently revives an old writer. |
diff --git a/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md b/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md
index 1560f9eddf..1dacd6dc48 100644
--- a/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md
+++ b/docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md
@@ -1,6 +1,6 @@
# 合并后的本地权威退役节奏
-- 当前计划:2026-10-02,`9b0486dc1`;历史核对基线:`ce3862e33`;采用后续核对:`71525ab90`,2026-09-28;[English](2026-09-28-retirement-cadence.md)。
+- 当前计划:2026-10-07,`06b6caa07`;历史核对基线:`ce3862e33`;采用后续核对:`71525ab90`,2026-09-28;[English](2026-09-28-retirement-cadence.md)。
- Owner:总 roadmap R3/R4/R5/R6、shared authority D1–D3、TS 迁移 T0–T4。
- 本记录替代 9 月 27 日 recovery、Host supervision 记录的**当前清单和估算**,
不替代其历史验证结果。
@@ -19,9 +19,9 @@
| #5170 | App 委派结果连续性;不代表全部 Turn/实例消费者完成 |
| #4931 | TS 私有状态重放降低 SQLite/archive 历史重建成本;未切默认、未完成 D2 |
-采用后续核对时,#5106(collaboration GoalRef)、#5130
+在 9 月 28 日采用后续核对时,#5106(collaboration GoalRef)、#5130
(session GoalRef)、#5139(App Turn 接受恢复)、#4915(本地状态路径迁移)仍开放。
-复用和推进这些 owner,不重复实现;只对确实受影响的调用方建立依赖,本地默认切换
+这是历史清单,不是今天的合并队列。重新核对这些 owner,不重复实现;只对确实受影响的调用方建立依赖,本地默认切换
不等待无关云端或百 Agent 工作。
**File 是默认 store factory,不等于所有新旧 Goal 默认以 File 为权威。**
@@ -107,9 +107,11 @@ actor。基线 Python bridge 已拒绝这些状态,直接基线 TS 尚未如
App 或持续成本资格。未退役 store、writer、outbox、历史格式/回执 reader 或永久
Host IO;C1、D2 和发布默认采用仍是独立验收边界。
-## 当前收尾:验证、迁移与删除(2026-10-02)
+
-按 main `8b5335a72` 和所列 PR head 重新核对。本节是 **R5 / D1–D3 / T0–T4**
+## 当前收尾:验证、迁移与删除(2026-10-07)
+
+按 main `06b6caa07` 和所列已合并 PR 重新核对。本节是 **R5 / D1–D3 / T0–T4**
的当前执行计划,替代旧 A–D 排期;历史测量仍只适用于原源码和负载。R6 单独推进。
存储格式、权威选择、所有权策略是三种不同迁移:有 SQLite 数据库,不代表新 Goal
已经默认使用 canonical authority,也不代表 `legacy` handoff 策略已经退役。
@@ -123,13 +125,14 @@ Host IO;C1、D2 和发布默认采用仍是独立验收边界。
| 已合并:#5436 | 委派 Host 原租约续期;最终 Todo 验收和停止确认仍是不同边界。 |
| 已合并:[#5413](https://github.com/loopx-project/loopx/pull/5413),head `2c99505c7` | provider 晋升与带备份的策略迁移解耦;禁止新 legacy 配置,允许恢复历史操作。保留原 CLI 恢复证据。没有自动迁移存量 legacy Goal,成功生成计划也不代表执行消费者已验收。 |
| 已合并:[#5466](https://github.com/loopx-project/loopx/pull/5466),merge `066b5bf26` | 原租约保持到最终验收;安装态消费者验收与合并分开记录。 |
-| 待审:[#5283](https://github.com/loopx-project/loopx/pull/5283),`1012d37f3` | preflight 优化仍在评审;冷 CLI 资格失败行保留,功能投影等价不等于性能通过。合成故障不证明历史瞬态打开失败的根因。 |
-| 已批准,待维护者合并:[#5500](https://github.com/loopx-project/loopx/pull/5500),`a9e3d722c` | App 重试恢复原 canonical Goal 创建操作;这是创建/默认接入的前置修复,不退役存量所有权策略。 |
-| 按实际路径建立依赖 | [#5308](https://github.com/loopx-project/loopx/pull/5308) 要证明子进程停止后才报告已结算;[#5398](https://github.com/loopx-project/loopx/pull/5398) 保留 UI 历史和 inspector 完整事实。只对纳入试用的相关消费者建依赖,不将其说成 SQLite 引擎前置,也不能发布已知损坏的用户路径。 |
-
-上述开放 head 分别解决 preflight 与创建恢复,不代表固定“剩余 PR 数”。
-剩余实现包仍是 canonical 创建/默认接入、策略迁移与 legacy 策略删除、旧 writer/
-捕获退役。仅当调用方归属和回退边界一致时才合并成同一个 PR。验证可能暴露具体修复,
+| 已合并:[#5283](https://github.com/loopx-project/loopx/pull/5283),merge `fd65e71f4` | 复用 preflight 优化;冷 CLI 资格失败行保留,功能投影等价或合并均不等于性能通过。合成故障不证明历史瞬态打开失败的根因。 |
+| 已合并:[#5500](https://github.com/loopx-project/loopx/pull/5500),merge `9c8961076` | App 重试恢复原 canonical Goal 创建操作;这条已交付恢复边界不退役存量所有权策略。 |
+| 已合并:[#5805](https://github.com/loopx-project/loopx/pull/5805),merge `3a1a92ebd` | 未配置的新 Goal 在源码中默认创建 canonical SQLite/`hard_lease`。存量选择和显式关闭/v0 行为保持固定;安装采用、D2/D3 与发布默认资格仍分别验收。 |
+| 已合并的相关路径 owner:[#5308](https://github.com/loopx-project/loopx/pull/5308),merge `7b13f88e8`;[#5398](https://github.com/loopx-project/loopx/pull/5398),merge `3870aa12d` | 复用子进程停止后才结算的控制,以及完整 UI 历史/inspector 事实。验收实际纳入试用的消费者;合并既不是 SQLite 引擎资格,也不能用于发布已知损坏的用户路径。 |
+
+10 月 2 日的 preflight/创建恢复队列已合并,不重做这些修复。剩余交付包是安装态
+canonical 创建/默认与升级采用、策略迁移与 legacy 策略删除、旧 writer/捕获退役。
+仅当调用方归属和回退边界一致时才合并成同一个 PR。验证可能暴露具体修复,
不再制造固定“剩余 PR 数”,也不为维持这个数字重做已完成的工作。
Goal 设置的策略迁移已复用 CLI 的同一 TS 备份迁移 owner:读取当前策略、预览
@@ -167,10 +170,10 @@ Goal 的 provider 或所有权策略;继续保留这些已有出口。恢复
| 交付包/既有 owner | 要做什么、凭什么完成 | 依赖/删除机会/节奏 |
| --- | --- | --- |
-| 现有 head 收尾;R3/R5 | 修完上述开放 PR 的 exact-head finding,处理相关失败与冲突,提交已评审 head 给维护者合并;区分已合并和已安装。 | 第一目标为 1–2 个工作日,取决于真实评审/修复结果;收尾前不另开无关优化。 |
+| 已合并消费者与当前 finding 验收;R3/R5 | 复用上述已合并 owner,核对当前相关失败和开放 PR,只分配已证实的剩余修复;区分已合并和已安装。 | 旧合并队列已关闭,进入有界安装态矩阵;不重开已合并工作,也不把无关消费者当成统一前置。 |
| 安装态恢复候选;D1/D3、整 Goal 晋升任务 | 固定合并源码和 CLI/App/Effect 实际 Node/SQLite 身份;独立恢复并验证备份,用隔离真实快照及合成负例执行下表,完成 File→SQLite→新增写入→File。之后按授权逐 Goal 采用并日常回读。 | 相关 PR 合并后立即开始,有界矩阵目标 1–2 个工作日;保留兼容的恢复版本和 archive,不对活跃 Goal 注入崩溃/损坏。 |
| 有界自愿试用;D2/D3 | 安装态恢复及相关执行控制通过后,邀请不超过 20 位核心开发者。公开负载/平台范围、备份迁移关闭步骤、已知缺口、停止条件与反馈入口;观察真实日常使用和失败。 | 不必等待全部正式 D2 轴或一份新的十天证书;携带新写入回退未通过前不邀请。试用不认证发布默认值。 |
-| Canonical 创建/默认接入;D3/T3 | 复用 `machine_configuration/goal_storage.py` 和 `local_authority_defaults.ts`。当前设置只选择**晋升后的目标**,返回 `promotion_performed: false`。补齐新建初始化/重试、升级、设置及打包 App/CLI/Lark 读回,已有显式 selector 保持固定。 | 有界候选可用后实现,发布默认启用仍服从下方决策;同包删除被替代的创建/选择决策。只把设置里的 file 改成 sqlite 不够。 |
+| 安装态 canonical 创建/默认采用;D3/T3 | 复用 #5500/#5805、`machine_configuration/goal_storage.py` 和 `coordination/local_authority_defaults.ts`。未配置的新 Goal 已初始化 canonical SQLite/`hard_lease`;v0 与 v1 `canonical_creation=false` 保留晋升后目标行为。验收安装态初始化/重试、设置、升级及打包 App/CLI 读回,纳入相关调用方时验证 Lark;存量 Goal 选择保持固定。 | 不实现第二份创建/默认值 owner。遵循[配置/关闭契约](../../../../reference/local-authority-provider-selection.md#new-goal-authority-machine-setting);移除偏好会恢复源码候选默认值,不会关闭创建。存量 Goal 采用和发布默认资格仍有独立出口。 |
| 两种所有权策略;R3/R5/T4 | 复用 #5413 的 backup/plan/migrate owner。清点旧/缺省 mode,结清适用的 claim/lease 和 Host 效果,逐个迁移获授权 Goal,再将正常运行类型及默认值收敛为 soft_claim / hard_lease。复用既有 Goal 设置入口和同一 owner,提供预览、获授权执行、结果及失败/恢复;只有 CLI 的迁移阶段标为部分交付。 | 与试用观察并行;不和 File↔SQLite 转换绑定。受支持升级路径和调用方通过后删除 legacy 执行,不能默默把 legacy 当成 soft。 |
| 旧 writer/跨界删除;T3/T4 | 最后真实调用方切到 TS owner 后验证下表,同时删除 Python 决策/私有 dispatch 和旧 Markdown 写入;清理 capture producer 前对账 outbox。在旧路径已不存在的包上验证 CLI。 | 已证明无消费者的内部删除现在就做;业务 writer 删除随对应迁移接入,不等 R6 全部完成或所有 Python 消失。每批有具体清单和回退方式。 |
| 发布默认决策;R5/D2/D3 | 对账受支持安装、当前 release 对照、代表性持续读写/恢复、资源增长和既有 soak 适用性;发布明确 profile、failed/missing、升级说明及关闭路径,显式披露默认变化。 | 不按测试/PR 数推算日期;正式十天/100k 资格保留各自证据要求。已有 File 选择继续受支持并固定;SQLite 不可用不能静默唤回旧 writer。 |
diff --git a/docs/architecture/rfcs/typescript-control-plane-migration-v0.md b/docs/architecture/rfcs/typescript-control-plane-migration-v0.md
index 8611182b18..a4457bd66a 100644
--- a/docs/architecture/rfcs/typescript-control-plane-migration-v0.md
+++ b/docs/architecture/rfcs/typescript-control-plane-migration-v0.md
@@ -4,7 +4,7 @@
- Supersedes / closes: none
- Proposed by: LoopX maintainers
- Date: 2026-08-15
-- Last revised: 2026-10-01
+- Last revised: 2026-10-07
- Scope: an incremental, replacement-first migration of the LoopX control-plane
core from Python to TypeScript without maintaining two semantic
implementations
@@ -29,15 +29,30 @@ required for the first App outcome. These are planned product consumers of
T0–T4, not additional provider promotion or completed migration claims.
-## Current delivery frontier (2026-10-02)
+
-At main `9b0486dc1`, #4931, #5251, #5395, #5417 and #5436 are merged.
-Do not recount their storage improvements or Python retirement as pending work.
+## Current delivery frontier (2026-10-07)
+
+Rechecked at main `06b6caa07`: #5413/#5466/#5283 and the affected creation,
+Host-stop and UI-history owners #5500/#5805/#5308/#5398 are merged. Reuse
+their delivered boundaries rather than reopening the October 2 merge queue.
The [current validation, migration and deletion plan](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.md#current-closeout-validation-migration-and-deletion-2026-10-02)
-prioritizes #5413/#5466/#5283 closeout, installed reversible qualification,
-bounded opt-in adoption, canonical creation/defaults and last-caller deletion.
+now prioritizes installed reversible qualification, affected consumer adoption,
+policy migration and last-caller deletion; it records the merged sources and
+the remaining evidence separately.
+
+Canonical new-Goal creation is already implemented by #5500/#5805. The existing
+machine setting and `coordination/local_authority_defaults.ts` choose canonical
+SQLite with `hard_lease` for unconfigured new Goals; CLI bootstrap and App
+creation share the typed initialization and original-operation recovery owner.
+Explicit v0 settings and v1 `canonical_creation=false` preserve post-promotion
+target behavior. Existing Goals keep their recorded selection. See the
+[configuration and disable contract](../../reference/local-authority-provider-selection.md#new-goal-authority-machine-setting).
+This is the source candidate, not certification of installed adoption, a released
+default, full shared Goal intent or D2/D3. Do not rebuild a creation/default owner.
+
Existing Goal migration, two-policy ownership retirement and storage-format
-upgrade have separate receipts and exits. Original-receipt recovery does not
+upgrade retain separate receipts and exits. Original-receipt recovery does not
justify retaining `legacy` as a live policy. Required migration readers remain.
A bounded cohort can start after its installed recovery and relevant execution
@@ -2130,7 +2145,8 @@ Keep the remaining Python current-time/raw-summary rule: bounded resume/handoff
sources and scheduler freshness still need a cohesive already-needed batch,
with same-load cost and installed File/SQLite negative cases before retirement.
Do not open a duplicate follow-up or treat rule relocation as optimization.
-Default SQLite, full T4 and live host wait qualification remain open.
+Release-default SQLite qualification, full T4 and live host wait qualification
+remain open; the source new-Goal default is recorded in the current frontier above.
One TS summary batch now owns selected-source counts, display allocation,
recent-completion chronology, orchestration candidate positions and closure
diff --git a/docs/architecture/rfcs/typescript-control-plane-migration-v0.zh-CN.md b/docs/architecture/rfcs/typescript-control-plane-migration-v0.zh-CN.md
index 1f54e5340d..52d333d2f8 100644
--- a/docs/architecture/rfcs/typescript-control-plane-migration-v0.zh-CN.md
+++ b/docs/architecture/rfcs/typescript-control-plane-migration-v0.zh-CN.md
@@ -4,7 +4,7 @@
- 替代 / 关闭:无
- Proposed by:LoopX maintainers
- Date:2026-08-15
-- Last revised:2026-10-01
+- Last revised:2026-10-07
- Scope:LoopX 控制面核心从 Python 到 TypeScript 的增量、replacement-first
迁移;不长期维护两份语义实现
- Tracking issue:[#3225](https://github.com/loopx-project/loopx/issues/3225)
@@ -27,14 +27,27 @@ R1–R3 的 TS 消费者包括 App 产品路径,不只 CLI 结算。
这里是 T0–T4 的产品消费计划,不新增 provider promotion,也不声称迁移完成。
-## 当前交付边界(2026-10-02)
+
-按 main `9b0486dc1` 核对,#4931、#5251、#5395、#5417、#5436 已合并,
-不再把这些存储改进和 Python 退役重复记作待办。
+## 当前交付边界(2026-10-07)
+
+按 main `06b6caa07` 复核,#5413/#5466/#5283,以及创建、Host 停止、UI 历史
+相关 owner #5500/#5805/#5308/#5398 均已合并。复用各自已交付的边界,不重开
+10 月 2 日的合并队列。
[当前验证、迁移与删除计划](ledger/shared-goal-authority-state-provider-v0/2026-09-28-retirement-cadence.zh-CN.md#当前收尾验证迁移与删除2026-10-02)
-优先收尾 #5413/#5466/#5283,再做安装态可回退验证、有界自愿采用、canonical
-创建/默认接入及最后调用方删除。存量 Goal 迁移、两策略退役和格式升级各有独立
-回执及出口;原回执恢复不能成为保留 legacy 活跃策略的理由,必要迁移 reader 保留。
+现在优先安装态可回退验证、相关消费者采用、策略迁移及最后调用方删除,并分别
+记录已合并源码和仍缺的证据。
+
+#5500/#5805 已实现 canonical 新 Goal 创建。既有机器设置与
+`coordination/local_authority_defaults.ts` 为未配置的新 Goal 选择 canonical
+SQLite/`hard_lease`;CLI bootstrap 和 App 创建共享 typed 初始化及原操作恢复
+owner。显式 v0 设置和 v1 `canonical_creation=false` 保留晋升后目标行为;存量
+Goal 保持已记录的选择。见[配置及关闭契约](../../reference/local-authority-provider-selection.md#new-goal-authority-machine-setting)。
+这是源码候选,不认证安装采用、发布默认、完整共享 Goal 意图或 D2/D3;不重建
+创建/默认值 owner。
+
+存量 Goal 迁移、两策略退役和格式升级仍各有独立回执及出口;原回执恢复不能成为
+保留 legacy 活跃策略的理由,必要迁移 reader 保留。
有界 cohort 在安装恢复和相关执行控制通过后可开始,不代表发布默认值或正式十天
D2 已通过;冻结的失败/缺项保持可见。T4 随实现删除已证明重复的 owner,不等 R6
@@ -1581,8 +1594,8 @@ quota 压缩、Monitor 等待、scheduler 接续三个真实调用方。此前
Monitor due/gap 共用同一观察时刻,保留旧版 planning wire,删除 Python 的第二份
gate 筛选。剩余 Python 当前时刻/原始摘要规则继续保留:有界 resume/handoff 来源
和 scheduler 新鲜度还需要合入已有批次,并先验证同负载代价及安装态 File/SQLite
-负例,再删除。不要新增重复任务,也不要把规则迁移算作优化。默认 SQLite、完整 T4
-和真实 App 等待态验收仍开放。
+负例,再删除。不要新增重复任务,也不要把规则迁移算作优化。SQLite 发布默认
+资格、完整 T4 和真实 App 等待态验收仍开放;源码新 Goal 默认值见上方当前边界。
已选来源的计数、展示分配、最近完成时间顺序、编排候选位置与收尾证明,收口到一个
TS 摘要批次;Python 保留旧格式解码、公开字段筛选及渲染。删除旧 Python claim 分配