Skip to content

feat(coordination): inspect cold sources through CLI and Goal settings - #5995

Merged
huangruiteng merged 11 commits into
mainfrom
codex/cold-source-inspection-r123
Oct 9, 2026
Merged

huangruiteng merged 11 commits into
mainfrom
codex/cold-source-inspection-r123

Conversation

@loopx-agent

@loopx-agent loopx-agent commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

Unmigrated Markdown Goals need complete original-source facts before reviewed import. The new readonly inventory includes current and archived Todo records, historical leases and original capture/operation/outbox/rollback evidence without manufacturing a capture, settling leases or granting migration authority.

The existing CLI and Goal data-storage settings read the same coordination-owned TypeScript result. HTTP exposes path-free facts; read failures clear stale observations and support fresh recovery. Existing source codecs, strict lease file readers, history verification and drain proof remain the owners. The branch integrates main at bae2316; current head is 633d6cb.

Validation at this head:

  • 63 source cases and the same 63 cases against an independently installed wheel pass, including seven real receiver cases with four Python producer files physically absent.
  • 25 strict-source admission cases and 19 focused TypeScript cases pass. Existing shared adapter cases pass on the immutable main baseline (11) and are included in the current source/wheel suites.
  • Rebuilt frontend and real installed HTTP pass the packaged English/Chinese desktop and 390px journey: retained originals, failure clears stale facts, fresh recovery and zero mutation.
  • Required TypeScript types, configured mypy (19 files), Ruff, semantic checks and the 290-site I/O census pass. Native premerge passes five direct and nineteen selected checks. Additional scoped adapter typing retains five inherited errors versus six on main; this is not a claim of full-tree type cleanliness.
  • Current-scope change-quality qualification and exact-head published author review pass. Independent review remains required before merging.

The bounded refactor reuses main's regular-file/nofollow lease transport instead of keeping duplicate cold-only filesystem rules. Existing history, OS-lock and recovery logic remains. Inventory and original disposition are a usable prerequisite; this PR does not complete automatic Host discovery/stop, pending-outbox settlement, complete cold import/history recovery, default SQLite qualification or final writer retirement. Those remain under the existing source-preservation and migration acceptance.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
…rough

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

精确 head:499751fe01a1e5bd3bfdaeefbc90510a97e22746;基线:3ed5d6bc88ffaaa05f2b1bc6a98ed5d921379fd1。

动机

需要迁移旧 Markdown Goal 的操作员。 过去必须先启用 shadow,且盘点只包含当前图需要的归档;现在可直接读取全部支持格式的 Todo 和历史 lease。 独立安装的 CLI 返回完整正文、无关归档和仍需结算的 active lease,源数据与写入权不变。 本 PR 不执行导入、不授予 lease、不改变默认 provider,也不退役旧 writer。 完整导入仍需 Goal storage 前端、停 Host/writer、原 outbox 对账、备份绑定的确认、fence 和同操作恢复。

按接受于上述基线的 docs/architecture/rfcs/loopx-overall-roadmap-v0.md 判断 R5:复用类型化 owner、完整来源、失败不退回旧源和恢复边界。并对照 TypeScript migration 的 T4 保留永久投影、历史读取/回执和 Host IO。这里是 justified increment,不是 R5、D1/D2 或 T4 的整项完成;本 PR 对 RFC 的修改只记录这个范围,没有降低原验收。

改动思路

复用既有 TS 来源与 lease 校验、锁及完整记录 codec,把文件读取留在原 Python adapter;无需新增持久化状态或第二个迁移决策源。 本批交付可独立使用和撤销的只读 CLI 盘点;完整审核导入继续由既有 R5/T4 的 Goal storage owner 承担。

不做改动会继续缺少独立的完整盘点入口;直接复用旧 inspect 会混淆 live graph 的 shadow 资格与冷源全量读取。新 read-only RPC 放在 coordination owner,沿用 source artifact transport,未新增 import 框架或 provider 事务。相邻简化已应用:完整记录分支直接读原记录,避免再走注意力摘要与依赖归档补齐;旧 capture 分支保留原默认语义。

具体改动

  • handle_coordination_shadow_command 在显式 inspect-source 分支调用来源盘点,无 --execute,不要求 shadow opt-in。
  • build_runtime_shadow_source_snapshot 的新显式模式纳入所有支持格式的 active/archive 记录,保留长正文与原 source section;缺归档角色、重复身份或不支持 lease 文件明确拒绝。
  • inspectColdCoordinationSource 复用 registry/state/lease 字节见证及锁,拒绝 canonical selector/document/fence;所有 retained lease 经既有 typed lease validator 校验并单独返回。过期或孤立但仍 active 的 lease 不能被当作 Host 已停止,三个 readiness 字段始终 false。
  • lazy effect handler、两处 census 行号、14 项实际 CLI 测试,以及双语操作文档/R5 checkpoint 构成完整本批范围。无 App/Lark 交互改动,不把重建现有 Chat 资源算成新前端交付。

对主干的风险

主要反例是“新盘点成功却丢失无关归档,或把过期历史 lease 当成可执行/已停写证明”。长正文、无关归档、过期孤立 lease、无效历史、源变化、已选 canonical provider 与非法文件测试覆盖这些分支;原数据和配置不变。

同夹具基线/head 对照:旧 capture 仍只选 live graph 所需记录,关闭 shadow 的旧 inspect 完整拒绝 payload 相等;新增命令在基线 exit 2(不存在),当前 exit 0 并返回两条完整记录。当前 source 38 项、独立安装 wheel 14 项通过;较早 45 项 source run 已覆盖保持不变的真实 File/SQLite 晋升与恢复。完整 TS 控制面 4,244 通过、0 失败,32 项 PostgreSQL 集成因环境未配置跳过;本批未修改共享 store 事务,不声明这些 provider 资格。Ruff、mypy、typecheck、census、全树语义与公共边界通过。

初始 wheel 构建正确拒绝旧 Chat bundle,正常重建后安装验证通过;初始 premerge 正确拒绝前一 diff 的 stale 质量回执,当前范围重新资格验证后 5 项 direct、18 项 selected 与原生质量回执均通过。未降低限额、删除断言或忽略失败。Windows/Lark/完整冷导入、停 Host/outbox 与持续 D2 未据此验收。未发现本批 blocker;JSON 仍可能含敏感正文及来源路径,文档明确要求私有保存。

我的整体评价

APPROVE,这个只读前置有真实操作入口和独立安装证据,复用边界合适,兼容性与未完成范围公开。本批交付可独立使用和撤销的只读 CLI 盘点;完整审核导入继续由既有 R5/T4 的 Goal storage owner 承担。 原任务继续保持 open;不要据此宣布默认 SQLite、旧 writer 截止或完整导入完成。runtime 改动交维护者合并,评审结论不提供 merge authority。

English verdict: APPROVE - 499751f. Complete supported cold-source inventory is independently usable without capture or authority changes; source/wheel, baseline parity, full TS and native premerge pass. Full import/frontend and PostgreSQL qualification remain outside this bounded stage.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
@loopx-agent loopx-agent changed the title feat(coordination): inspect cold Markdown sources before capture feat(coordination): inspect cold sources and retain original capture history Oct 8, 2026

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

动机

需要迁移旧 Markdown Goal、核对原始历史和未结算工作的人。

过去先启用 shadow 才能 inspect,且全量冷源盘点缺少原 capture/outbox 历史;现在一个显式命令读取完整支持格式的 Todo、lease 和原文件见证,原字节保持。

独立安装的 CLI 可盘点原 store/identity、management、outbox 和本 Goal 的 rollback 归档;损坏、非法路径或缺少完成操作归档明确拒绝,导入准备标志仍为 false。

本 PR 不执行导入、不停 Host、不 drain/replay outbox、不授予 lease、不改变默认 provider,也不退役旧 writer。

完整导入仍需 Goal storage 前端、停 Host/writer、lease/outbox 处置、备份绑定的确认、fence 和同操作恢复。

Accepted basis: docs/architecture/rfcs/loopx-overall-roadmap-v0.md, revision 3ed5d6bc88ffaaa05f2b1bc6a98ed5d921379fd1, criterion R5(沿既有 T0–T4 owner 做完整来源/原回执保留,区分有界交付、试用和正式默认资格)。本次 checkpoint 只记录已交付边界,不改原验收或 D2 失败/未测事实。

改动思路

复用既有 TS 来源、lease、历史 reader、原始目录盘点及 manifest/result 校验;Python 仅保留现有文件适配,不增加持久化状态或第二个迁移决策源。

扩展同一个 PR 交付可独立使用和撤销的只读来源盘点;完整审核导入继续由既有 R5/T4 的 Goal storage owner 承担。

最强反对理由是只读 CLI 前置项可能继续碎片化、拖延实际导入,也可能扩大已有 management 模块。这里扩展同一条已存在的操作、复用原 owner 的私有校验,形成一个可审计的完整支持来源盘点;不增加逐文件 RPC 或并行迁移框架。范围/源码/安装包证据支持这个阶段,完整导入仍不能据此结项。

具体改动

Whole-PR review: 3ed5d6bc88ffaaa05f2b1bc6a98ed5d921379fd1 → d4c0466b3a6ecac39bf44315fb842b6fc17e2cfc,10 files, 640+/6−。单独核对了前次 review 499751fe01a1e5bd3bfdaeefbc90510a97e22746 → 当前 head:加入原 capture/identity、management、raw outbox、本 Goal rollback 归档和 legacy observation 读回;不继承旧 APPROVE。

  • coordination_shadow.py:220:显式 coordination-shadow inspect-source --goal-id <goal>,经既有有界 artifact transport 调用 typed owner;没有 execute 开关。默认 capture 仍用原 live graph/归档依赖范围。
  • runtime_shadow.py:263:完整支持的 active/archive 正文、metadata 和原 lease 见证。过期、脱离当前 graph 的 active lease 仍需原工作结算。
  • cold_source_inspection.ts:19:先核验 artifact 父路径,再持既有锁核验 canonical presence、源字节、原历史和原 lease;二次读取见证检查变化。所有 import/Host-stop/outbox-reconciliation readiness 保持 false。
  • shadow_management.ts:515:复用原 inventory/loadManifest/validateReplayResult。当前 terminal result 仍在 state、后续才归档的生命周期分别处理;完成 rollback 缺少原 candidate/outbox 归档即拒绝,prepared residue 仅观察。原文件 hashes 和 compact proof 不替代备份,不制造导入或送达回执。

验证通过:当前来源/冷源 39 项,加最终历史 observation 2 项;既有 management/drain/CLI 42 项。独立 wheel 初轮 24 项,两个真实进程中断场景随后用私有调度 driver 导入实际安装的生产 owner 通过(开发 driver 本身未随 wheel 发布,没有替换产品逻辑)。最初缺少 terminal archive 的负例失败已在原生命周期修复并重跑;失败记录保留。

typecheck:control-plane、Ruff、配置范围 mypy、语义 advisory 后全树 smoke、registry IO census、公共边界扫描通过。全 TS 4244 pass/0 fail,32 项环境相关跳过保留未验证;最终 cold-only 修改由当前真实 CLI/wheel 和最终 typecheck 覆盖。当前 loopx canary premerge --from-git-diff 5 direct +18 selected 全通过,CQR 与当前 base/head/diff 匹配。

同一 immutable base/head 夹具通过真实 CLI 对照:旧 disabled inspect 完整 payload 和默认 capture records 相同;新显式操作从 base exit2 变为当前 exit0,完整 active/archive 返回且原字节不变。实际 capture、原始 malformed outbox、before/after-commit crash、legacy history positive/corrupt、缺失 terminal archives、symlink ancestor、变化/canonical/非法源均有真实边界证据。

对主干的风险

这是显式操作的行为扩展,旧 capture、原持久化 codec 和真实 recovery reader 继续保留;没有 heartbeat/Turn 指令注入、默认 provider、quota、scheduler 或 provider transaction 改动。命令输出含完整来源及本机路径,属于操作员的私有材料;compact proof/hash 不等于备份、Host 停止或 outbox 已结算。非法/变化的源明确拒绝,不回退旧 writer。复用大模块中的有界 helper,maintainability ratchet 通过;无证据支持现在删除有价值的历史 reader。

未声称完整 Goal storage App 导入、Windows、真实模型采用、PostgreSQL、D2 或正式默认资格。无 PostgreSQL transaction/protocol 变化,32 PG 环境跳过不计作通过。回滚可撤回新增只读 action/handler;业务原字节/授权不变。

我的整体评价

本 head 的独立只读交付有实际可用结果,原始历史/receipt 义务与关闭隔离有真实源码和安装包证据,未发现当前阶段 blocker。未来重构检查已应用在同一 PR:复用原 typed/history/management owner,不复制 Python 决策、不追加 per-file RPC;完整导入与前端仍由原 owner 接续。本控制面 PR 留给 maintainer 合并,验证与此评审不授予自合并权。

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

English verdict: APPROVE - d4c0466b3a6ecac39bf44315fb842b6fc17e2cfc for the explicitly invoked, supported cold-source/original-history inspection prerequisite. Whole import, stop/settlement, packaged frontend and default/writer-cutoff qualification remain open; maintainer merge required.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
@loopx-agent
loopx-agent requested a review from maxliux5 as a code owner October 8, 2026 23:59
@loopx-agent loopx-agent changed the title feat(coordination): inspect cold sources and retain original capture history feat(coordination): inspect cold sources through CLI and Goal settings Oct 8, 2026

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh

动机

准备把旧 Markdown Goal 导入 canonical 的用户,需要核对原任务、历史和未结算工作。

过去 App 只要求先走 CLI promotion,看不到旧源任务或历史残留;现在现有“Goal 数据存储”设置直接读取校验后的盘点,无需先启用旧 writer。

真实安装的后端与打包 App 已验证当前和归档任务计数、过期孤立 active lease、原 capture/outbox 存在性;来源损坏时清除旧事实,修复后重新读取恢复。

本 PR 只交付 CLI 与 App 只读盘点,不执行旧源导入、停 Host、outbox 处置或 lease 授权,不改变默认 provider 或退役旧 writer。

完整导入仍需原 Host/writer 停止证明、原 lease/outbox 处置、备份绑定的源与目标确认、fence、持久化同操作恢复及相应 App 操作。

Accepted basis: docs/architecture/rfcs/loopx-overall-roadmap-v0.md, revision 3ed5d6bc88ffaaa05f2b1bc6a98ed5d921379fd1, criterion R5。完整来源与原回执保留、可恢复迁移、试用和正式默认资格继续分开;本次 checkpoint 不改验收或 D2 失败/未测事实。

改动思路

App 和 CLI 复用同一 TS 完整来源及历史校验 owner;Python 只适配现有文件 IO,HTTP 仅返回无路径派生计数,不增加持久化盘点或平行迁移决策源。

在同一个 PR 补齐现有 Goal storage 的可用盘点交互;真实导入的效果授权与恢复继续由原 R5/T4 owner 接续。

最强反对理由是持续追加前置项可能拖延实际导入,计数还可能掩盖未读历史。当前 App 必须先完成与 CLI 相同的完整来源校验,才产生有限摘要;同一 PR 补齐可用的设置交互和失败恢复。真正导入需要停写、处置和备份绑定的持久化操作,继续保持原 owner 的独立效果授权边界,没有加入未使用的导入框架。

具体改动

Whole PR: 3ed5d6bc88ffaaa05f2b1bc6a98ed5d921379fd1 → 393001d92876fa67b45f64402ec19b9e343f2f01,16 files,971+/17−;生产329+/15−、验证524行、文档116行、census2+/2−。单独核对前次 review d4c0466b3a6ecac39bf44315fb842b6fc17e2cfc 到当前 head 的 App 补充,重新判断整个 PR,没有继承旧 APPROVE。

  • CLI coordination-shadow inspect-source --goal-id <goal> 读取完整支持的 active/archive 正文、metadata、历史 lease 和原始 capture/management/outbox/rollback 文件见证。过期孤立 active lease 仍需要原工作处置;缺失 terminal archive、损坏历史和非法路径拒绝;观察不产生 stop/settlement 证明。
  • cold_source_inspection.ts:111 的 App projection 先调用完整原 owner,仅返回计数、存在性和 literal false readiness。
  • goal_storage_api.py:54 保留 canonical migration-readback 为第一入口;只有明确 noncanonical 才盘点。输入错误400、已注册来源不可读503、类型化冲突409;响应不含路径、原文或原回执。
  • GoalStorageSettings:8 从现有 settings caller 接入,显示原来源和历史残留;每次读先清除旧事实,错误后可重新读取,冷源没有 provider selector/确认/导入按钮。原 canonical opaque carrier 与恢复控件保留。

当前来源 HTTP14通过,独立安装 wheel 在 checkout 外同样14通过;打包 ZH/EN desktop/mobile 使用真实 wheel storage/ownership HTTP,验证原 outbox、孤立 lease、来源损坏时清空旧计数、修复后恢复、键盘读取和零写入;整个视口已查看。Workspace/discovery 列表是合成夹具,storage/ownership 及来源损坏并非 API mock;不声称本机已安装该候选。

相同最终夹具的原 canonical8项在前次 immutable wheel 与当前源码/wheel 均通过,涵盖 File/SQLite、新数据、重启、原操作回执、拒绝和无自动迁移。前次 wheel 对新增的较早4个冷源 HTTP 用例实际4失败,当前6个冷源用例通过:旧实现没有盘点/冲突拒绝;记录不冒充主干全量对照。CLI/off 与原历史验证复用前次 d4c0466b3a6ecac39bf44315fb842b6fc17e2cfc 证据,已检查相关 CLI、文件适配、management 和完整 inspector 未被 App 补充改写;原证据保持原 revision。

当前全 TS 4244 pass/0 fail/32 PostgreSQL 环境跳过;control/frontend typecheck、Ruff、配置范围19-file mypy、semantic advisory 后全树检查、census、公共边界通过。最终 exact CQR 和 loopx canary premerge --from-git-diff 5 direct +19 selected 通过,未咨询或等待远端 CI。

先前缺少 snapshot 必需 None 参数和来源错误被归为400的问题已有因果修复与原负例重跑。额外的非配置 mypy loopx 诊断4857 errors/588 files仍保留;5个涉及 CLI/IO 的诊断点对应 main 未改语句,未执行全树 baseline,因此不称全部为已证明的历史错误,也不声称 Python 全树类型资格。该诊断不替代仓库声明的19-file oracle;没有调整硬预算或必需测试。

对主干的风险

App 非 canonical GET/文案有明确行为变化:由“先 CLI promotion”变成来源盘点与导入待完成;不能以 capture 默认 false 声称 UI 无变化。原 capture、默认 provider、quota/scheduler/heartbeat/Turn 指令和 provider transaction 没有改变。非 canonical 盘点始终只读,canonical 拒绝不回退旧 writer。

原 persisted history/receipt 和真实恢复 reader 有价值,保留;计数、hash、compact proof 不能替代备份或 Host 停止。CLI 全文/本机路径仅供操作员私有盘点,HTTP 精简白名单不泄漏。回滚可以撤回新增盘点 action/projection,原业务数据与授权保持。完整导入、Windows/Lark/真实模型、PG32跳过、D2和默认资格仍未验证;无 PG transaction 变化。当前窄源码及实际 API/打包交互证据足够判断此盘点边界,不能据此删除最后 writer。

我的整体评价

当前 head 给用户提供了可使用的 CLI 与 App 来源盘点,实际 owning backend、负例、纠正后读取、默认 capture 与 canonical 兼容路径均有证据,未发现这一交付边界的 blocker。未来重构检查已在本 PR 应用:复用现有 typed source/history 和 Goal storage 交互,删除过时 promotion 文案,不复制 Python 决策或增加配置开关。完整 effectful import 接续原 R5/T4 owner;本控制面 PR 留 maintainer 合并。

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

English verdict: APPROVE - 393001d92876fa67b45f64402ec19b9e343f2f01 for supported read-only cold-source CLI and packaged App inventory. Full import, stop/disposition, backup-bound recovery and default/writer-cutoff qualification remain open; maintainer merge required.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh

动机

准备将旧 Markdown Goal 导入 canonical 的用户,需要核对原任务、历史与未处理的操作。

过去能看到 outbox 文件却无法判断哪些仍待处理;现在 CLI 按原 Todo/lease 分区核对精确回执,显示待处理记录和有提交凭证的残留,原字节保持。

源码和独立安装包已通过真实 Todo/lease 进程中断与 HTTP 验证;损坏或不相符的凭证显示失败,设置页仍只显示无路径数量,导入资格不变。

本 PR 交付只读来源盘点及原 outbox 预览,不执行导入、停 Host、replay、清理或 lease 授权,不改变 SQLite 默认值或退役旧 writer。

完整导入仍需原 Host/writer 停止证明、原 lease/outbox 处置、备份绑定的源与目标确认、fence、持久化同操作恢复及相应 App 操作。

改动思路

CLI 与 App 复用同一 TS 来源校验,原 outbox 预览直接复用既有 drain 证明 owner;Python 保留文件适配,HTTP 保留无路径摘要,没有新增持久化状态或第二决策源。

同一个 PR 交付可用的完整来源盘点与原 outbox 预览;完整导入的效果授权、停写证明和恢复继续由既有 R5/T4 owner 接续。

原来源字节、lease 和历史回执是事实源;计数和分区处置预览均从原 owner 派生,每次重新读取。原生 drain 的文件、lineage、head、cursor 与回执字节规则属于正确性约束;盘点是只读投影,不能调用效果 executor。原活跃 capture 才能产生分区计划,中断或 inactive capture 仍需原 management 恢复。HTTP 继续只返回现有无路径摘要。

最强反对理由是不断扩展前置可能拖延真正导入,也可能只留下更多摘要。这里在同一个 PR 结束完整支持格式的来源观察,新增预览直接复用已有 verifier,没有新的迁移框架或第二个 Python 决策源。后续实际导入须接续原效果 owner,不能把这个阶段当成导入完成。

具体改动

基线 3ed5d6bc88ffaaa05f2b1bc6a98ed5d921379fd1,评审 head 271ad06561dbc39c2c3a545c0f545258c4036f3e。整个 PR 为16文件、1094+/17−;生产364+/15−、验证585行、文档143行、census2+/2−。前次评审 393001d92876fa67b45f64402ec19b9e343f2f01 到本次为6个既有路径126+/3−;重新判断整个交付,没有继承旧 APPROVE。

接受依据是 docs/architecture/rfcs/loopx-overall-roadmap-v0.md,固定 revision 3ed5d6bc88ffaaa05f2b1bc6a98ed5d921379fd1 的 R5。当前实现完整来源与原回执保留的只读前置;R5 的完整导入、selected-profile 恢复/成本、试用和正式默认退出仍 deferred。修改 checkpoint 只记录这个范围,没有改写验收或 D2 原失败/未测事实。

关键代码讲解

  • reviewRetainedOutbox(cold_source_inspection.ts:24)取得原 capture binding,分别用 drainInventory 和 planShadowDrain 读取 Todo/lease 分区。输出 pending、receipt-proven residue 与拟议 cursor,明确 executed=false、execution_authority_granted=false;无证明的记录保留原失败码及文件。
  • inspectColdCoordinationSource(同文件45行)在原 maintenance/source 锁下核验原始来源与历史,读取一次完整 proof 供两个计划使用,然后保留紧凑响应。原 planner 要求 proof 到达当前 head;有界读取未达到 head 时拒绝,不能据缺少记录声称已结算。二次字节见证检查防止陈旧来源。active 历史 lease 即使过期或不在当前图,也仍需原工作处置。
  • inspectColdCoordinationStorage(同文件146行)从完整原 owner 派生计数和存在性;HTTP 不返回正文、路径、原执行密钥或 outbox_review。
  • 既有 Goal storage GET 保留 canonical readback 为第一入口;明确 noncanonical 才盘点,输入400、不可读来源503、类型化冲突409。既有 GoalStorageSettings(8行)显示来源、数量和不可导入边界,失败清空旧事实、纠正后重新读取;canonical 原操作恢复继续由原 carrier 承担。

当前源码与独立 wheel 的相同45项 CLI/HTTP 验证均通过,包括真实 Todo/lease SIGKILL 的 before/after-commit 窗口、回执字节改变、孤立 marker、外来 lineage、历史归档、canonical File/SQLite 新数据/重启/原回执,以及源/lease/cursor 原字节不变。原 drain52项和完整控制面4244项通过、0失败,32项 PostgreSQL 环境跳过。TS typecheck、配置19-file mypy、Ruff、先 diff advisory 后全树语义、7项 census 和公共边界通过。当前已提交范围原生 CQR 与 premerge 的5 direct、10 catalog、8 profile 及公共边界通过,无 manual hold,未咨询远端 CI。

前次 head 的打包中英桌面/390px设置交互及 immutable baseline/off/canonical 对照证据保留原 revision。当前6路径改动没有改变 App 文件、HTTP 白名单、普通 capture/CLI adapter 或原 management/history owner;当前真实 HTTP/wheel 重新验证变化的后端和隐私断言。没有声称本次重新跑视觉检查或本机已安装候选。

对主干的风险

主要反例是盘点把 marker 存在当作提交证明、用陈旧 preview 清理原记录,或通过 HTTP 泄漏原执行身份。真实原文件负例和 original planner 的 exact-head/byte/cursor 证明防止前两种误判;任何实际处置都必须由原 drain 再读取当前事实,外层 readiness 始终 false;HTTP 白名单与当前断言防止第三种。现有 capture 默认关闭、provider/scheduler/quota/heartbeat/Turn 指令没有变化,noncanonical App 的可见盘点和显式 CLI 预览属于已披露行为扩展。

失败记录仍保留:新5个预览 oracle 在前次产品上先失败;初次实现4失败/25通过,原因是紧凑 proof 没有原事务,已在同 owner 补齐内部证明并保持输出紧凑。独立 wheel 初次7失败/30通过/8 setup error,第二次7失败/38通过,是 source-relative 夹具和未发布测试 driver;外部故障夹具改为导入真实安装模块后45通过,产品文件和断言未变。旧 Chat bundle 的构建拒绝也通过正常重建解决,没有绕过。没有调高硬门槛或选择性删除失败。

原 persisted history/receipt、备份 reader 和 Host IO 继续保留,预览/hash 不能替代完整备份或 Host 停止证明。全量非配置 Python typing 的先前4857错误没有全树 baseline 资格;当前仅声明配置范围通过。完整 cold import/App apply、停写与原处置、Windows/Lark/模型采用、PG、D2和正式默认资格仍未验证。

语义与 CI 对齐

复用既有 source/lease/drain 类型化语义,新组合停留在本地只读 projection,没有平行分类词表或 Python policy。保持观察与授权、expiry 与 Host 停止、preview 与 settlement 的区别。当前策略采用本地必需验证、wait_for_ci=false;跳过的32项 PG 不计作通过。正式 D2 的13通过、1失败、11缺失及2.059倍读取增长仍是原证据,没有据此次盘点改写。

我的整体评价

未发现当前只读交付的 blocker。long_horizon 保持原操作与恢复义务,user_experience 改善迁移前的真实核对;完整导入仍开放。未来重构检查已应用:原证明只读一次供两分区复用,响应保持紧凑,没有新增兼容 wrapper、配置或效果框架。原备份/回执格式有真实持久化消费者,应保留到其升级支持退出。当前范围可独立使用、测试和撤销;runtime/control-plane 合并交维护者。

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

English verdict: APPROVE - 271ad06561dbc39c2c3a545c0f545258c4036f3e for verified read-only cold-source CLI/App inventory and original native outbox preview. Source/wheel45, drain52, full TS4244 and exact-scope premerge pass. Effectful import, stop/disposition, default qualification and maintainer merge remain separate.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh

动机

此前原始 outbox 已可预览,但尚未证明退役生产者后原效果可恢复;现在真实中断来源交由缺少旧生产者的独立 TS 接收端处置,未发生写入不计实际应用,已提交不重复,活跃 lease 保持待结算。CLI/App 仍只读,未获得导入资格。

准备将旧 Markdown Goal 导入 canonical 的用户,需要核对原任务、历史与未处理的操作。

过去能看到 outbox 文件却无法判断哪些仍待处理;现在 CLI 按原 Todo/lease 分区核对精确回执,显示待处理记录和有提交凭证的残留,原字节保持。

源码和独立安装包已通过真实 Todo/lease 进程中断与 HTTP 验证;损坏或不相符的凭证显示失败,设置页仍只显示无路径数量,导入资格不变。

本 PR 交付只读来源盘点及原 outbox 预览,不执行导入、停 Host、replay、清理或 lease 授权,不改变 SQLite 默认值或退役旧 writer。

完整导入仍需原 Host/writer 停止证明、原 lease/outbox 处置、备份绑定的源与目标确认、fence、持久化同操作恢复及相应 App 操作。

改动思路

CLI 与 App 复用同一 TS 来源校验,原 outbox 预览直接复用既有 drain 证明 owner;Python 保留文件适配,HTTP 保留无路径摘要,没有新增持久化状态或第二决策源。

同一个 PR 交付可用的完整来源盘点与原 outbox 预览;完整导入的效果授权、停写证明和恢复继续由既有 R5/T4 owner 接续。

原来源字节、lease 和历史回执是事实源;计数和分区处置预览均从原 owner 派生,每次重新读取。原生 drain 的文件、lineage、head、cursor 与回执字节规则属于正确性约束;盘点是只读投影,不能调用效果 executor。原活跃 capture 才能产生分区计划,中断或 inactive capture 仍需原 management 恢复。HTTP 继续只返回现有无路径摘要。

最强反对理由是不断扩展前置可能拖延真正导入,也可能只留下更多摘要。这里在同一个 PR 结束完整支持格式的来源观察,新增预览直接复用已有 verifier,没有新的迁移框架或第二个 Python 决策源。后续实际导入须接续原效果 owner,不能把这个阶段当成导入完成。

具体改动

基线 3ed5d6bc88ffaaa05f2b1bc6a98ed5d921379fd1,评审 head 94a8a871487a9135397a39221137d6d010e92dcb。整个 PR 为17文件、1296+/17−;生产364+/15−、验证758行、文档172行、census2+/2−。前次评审 271ad06561dbc39c2c3a545c0f545258c4036f3e 到本次新增173行真实接收端测试并更新三份既有文档29行;产品树没有变化。重新判断整个交付,没有继承旧 APPROVE。

接受依据是 docs/architecture/rfcs/loopx-overall-roadmap-v0.md,固定 revision 3ed5d6bc88ffaaa05f2b1bc6a98ed5d921379fd1 的 R5。当前实现完整来源与原回执保留的只读前置;R5 的完整导入、selected-profile 恢复/成本、试用和正式默认退出仍 deferred。修改 checkpoint 只记录这个范围,没有改写验收或 D2 原失败/未测事实。

关键代码讲解

  • reviewRetainedOutbox(cold_source_inspection.ts:24)取得原 capture binding,分别用 drainInventory 和 planShadowDrain 读取 Todo/lease 分区。输出 pending、receipt-proven residue 与拟议 cursor,明确 executed=false、execution_authority_granted=false;无证明的记录保留原失败码及文件。
  • inspectColdCoordinationSource(同文件45行)在原 maintenance/source 锁下核验原始来源与历史,读取一次完整 proof 供两个计划使用,然后保留紧凑响应。原 planner 要求 proof 到达当前 head;有界读取未达到 head 时拒绝,不能据缺少记录声称已结算。二次字节见证检查防止陈旧来源。active 历史 lease 即使过期或不在当前图,也仍需原工作处置。
  • inspectColdCoordinationStorage(同文件146行)从完整原 owner 派生计数和存在性;HTTP 不返回正文、路径、原执行密钥或 outbox_review。
  • 既有 Goal storage GET 保留 canonical readback 为第一入口;明确 noncanonical 才盘点,输入400、不可读来源503、类型化冲突409。既有 GoalStorageSettings(8行)显示来源、数量和不可导入边界,失败清空旧事实、纠正后重新读取;canonical 原操作恢复继续由原 carrier 承担。

生产版本 271ad06561dbc39c2c3a545c0f545258c4036f3e 的源码与独立 wheel 相同45项 CLI/HTTP 验证通过,包括真实 Todo/lease SIGKILL 的 before/after-commit 窗口、回执字节改变、孤立 marker、外来 lineage、历史归档、canonical File/SQLite 新数据/重启/原回执,以及源/lease/cursor 原字节不变。原 drain52项和完整控制面4244项通过、0失败,32项 PostgreSQL 环境跳过。TS typecheck、配置19-file mypy、Ruff、先 diff advisory 后全树语义、7项 census 和公共边界通过。当前两次提交只改测试/文档;本次源码与独立安装包的相同38项来源/处置测试均通过。已核对当前与前次的 loopx/apps/examples 差异为空、base 仍为同一3ed revision,以上未变产品证据保留原 revision。当前已提交范围原生 CQR 与 premerge 的5 direct、10 catalog、8 profile 及公共边界通过,无 manual hold,未咨询远端 CI。

前次 head 的打包中英桌面/390px设置交互及 immutable baseline/off/canonical 对照证据保留原 revision。当前4路径改动没有改变 App 文件、HTTP 白名单、普通 capture/CLI adapter 或原 management/history owner;本次 wheel 核验真实旧写入与独立 TS 接收端;当前没有后端或 HTTP 白名单变动,相关证据保留上一产品 revision。没有声称本次重新跑视觉检查或本机已安装候选。

新增 test_cold_source_disposition_e2e.py 使用既有真实 crash 夹具产生原记录,再复制当前或安装包 runtime,物理删除四个旧 Python 生产者,通过 shipped dispatchEffectRuntimeMethod 运行原 drain/read/rollback,保留真实 OS-lock Host。四种 Todo 窗口证明:旧字节 no-op 只推进处置序号,精确新字节证明无 marker 提交,已提交凭证重放无第二次效果;两种 lease 窗口保持原 active lease 和待结算状态;A→B→A 无法证明时拒绝,完整归档 candidate/outbox,重试同一操作且原字节不变。并未证明所有原 Host 停止,也没有开放导入按钮。

对主干的风险

主要反例是盘点把 marker 存在当作提交证明、用陈旧 preview 清理原记录,或通过 HTTP 泄漏原执行身份。真实原文件负例和 original planner 的 exact-head/byte/cursor 证明防止前两种误判;任何实际处置都必须由原 drain 再读取当前事实,外层 readiness 始终 false;HTTP 白名单与当前断言防止第三种。现有 capture 默认关闭、provider/scheduler/quota/heartbeat/Turn 指令没有变化,noncanonical App 的可见盘点和显式 CLI 预览属于已披露行为扩展。

失败记录仍保留:新5个预览 oracle 在前次产品上先失败;初次实现4失败/25通过,原因是紧凑 proof 没有原事务,已在同 owner 补齐内部证明并保持输出紧凑。独立 wheel 初次7失败/30通过/8 setup error,第二次7失败/38通过,是 source-relative 夹具和未发布测试 driver;外部故障夹具改为导入真实安装模块后45通过,产品文件和断言未变。旧 Chat bundle 的构建拒绝也通过正常重建解决,没有绕过。没有调高硬门槛或选择性删除失败。

原 persisted history/receipt、备份 reader 和 Host IO 继续保留,预览/hash 不能替代完整备份或 Host 停止证明。全量非配置 Python typing 的先前4857错误没有全树 baseline 资格;当前仅声明配置范围通过。完整 cold import/App apply、全局停写与实际 lease 结算、Windows/Lark/模型采用、PG、D2和正式默认资格仍未验证。

本次初次测试因错误的 readback 字段/schema 引用失败,改用注册 schema 和精确原 receipt 查询后源码38/独立安装包38通过,未修改产品决策或放宽重复效果/未提交 oracle。首轮 premerge 的5 direct、10 catalog、8 profile 和公共边界均通过,但启动时读取旧 CQR 而拒绝;当前 exact receipt 记录后重新执行原生 gate。

语义与 CI 对齐

复用既有 source/lease/drain 类型化语义,新组合停留在本地只读 projection,没有平行分类词表或 Python policy。保持观察与授权、expiry 与 Host 停止、preview 与 settlement 的区别。当前策略采用本地必需验证、wait_for_ci=false;跳过的32项 PG 不计作通过。正式 D2 的13通过、1失败、11缺失及2.059倍读取增长仍是原证据,没有据此次盘点改写。

我的整体评价

未发现当前只读交付的 blocker。long_horizon 保持原操作与恢复义务,user_experience 改善迁移前的真实核对;完整导入仍开放。未来重构检查已应用:原证明只读一次供两分区复用,退役核验复用真实故障夹具与原效果 owner,并明确 OS-lock/历史读取须保留,响应保持紧凑,没有新增兼容 wrapper、配置或效果框架。原备份/回执格式有真实持久化消费者,应保留到其升级支持退出。当前范围可独立使用、测试和撤销;runtime/control-plane 合并交维护者。

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

English verdict: APPROVE - 94a8a871487a9135397a39221137d6d010e92dcb for verified read-only cold-source CLI/App inventory and original native outbox preview. Current source/wheel38 qualify retained-original recovery with old Python producers absent. Unchanged production retains revision-bound source/wheel45, drain52 and TS4244 evidence; current exact-scope premerge passes. Global stop, lease settlement, effectful import/default qualification and maintainer merge remain separate.

@mergify

mergify Bot commented Oct 9, 2026

Copy link
Copy Markdown

This pull request has merge conflicts with main and cannot be merged
until they are resolved. Please rebase or merge the base branch, @loopx-agent.

Choose the remote for the base repository, not an out-of-date fork.
For a fork clone, first inspect git remote -v; upstream must point
to https://github.com/loopx-project/loopx.git. If it is absent, add it
with git remote add upstream https://github.com/loopx-project/loopx.git.
Then run:

git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEAD

For a same-repository clone whose origin points to
https://github.com/loopx-project/loopx.git, use origin instead of
upstream for fetch/rebase. If you prefer merging the base, use
git merge <base-remote>/main and push normally.

Keep the DCO Signed-off-by trailer on every commit when you rebase.
https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/syncing-a-fork

@mergify mergify Bot added the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 9, 2026
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
@mergify mergify Bot removed the needs-rebase Mergify: the pull request has merge conflicts with its base branch label Oct 9, 2026

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Exact head: 633d6cb
English verdict: APPROVE

动机

准备从未迁移 Markdown Goal 导入统一存储、核对原始历史的维护者。

以前没有独立的完整旧源盘点入口,设置页只能泛泛要求先迁移;现在 CLI 和同一 Goal 设置展示当前/归档任务、未结算历史 lease、原 capture/outbox,失败时清空旧事实并可重试。

完整记录与原始字节见证可核对;UI 只披露无路径的事实,明确尚不能导入或授予执行权限。已有原始处置能在 Python producer 缺席的接收端继续恢复。

这批不执行导入、不创建 capture、不停 Host、不结算 lease,也不授权默认 SQLite 或删除最后 writer。

停止所有相关 writer/Host、实际 pending outbox 处置、完整源备份绑定确认与冷导入/历史恢复仍由现有 R5/T4 承接;独立精确 head 复审待原始会话转交恢复。

改动思路

复用完整记录 codec、源锁/字节校验、management 历史验证及 drain proof/plan;Python 只传输源,TypeScript 解释状态。已有 Goal 设置展示同一观察,不增加导入开关或另一套判断。
Specification basis: docs/reference/local-authority-provider-selection.md @ bae2316, criterion: Inventory and back up the complete supported source.
Architecture boundary: Read-only original inventory and existing receiver disposition; full stopped-writer/import/history/default acceptance remains separate.
Architecture judgment: Compose verified originals within coordination; no new policy, generic framework or Python decision owner.

具体改动

17 文件 +1292/-17。CLI inspect-source 与两个 TS read effect 包含完整当前/归档文本、历史 lease 与 capture/operation/outbox/rollback 原文件见证;过期 active lease 仍需结算。只读处置预览复用原始 receipt proof,未知记录保留原字节和错误。HTTP 仅投影无路径的数量/存在性;设置页失败清空旧事实并可重新读取,明确尚不能导入。合并最新主干时复用严格 regular-file/nofollow 源租约读取;三处旧错误文案断言改为 exact source_lease_inventory_invalid,并检查不创建 authority/shadow。

对主干的风险

当前源码63、独立 wheel63、严格源准入25、TS19,以及配置内mypy19、类型、Ruff、semantic/I/O290、原生premerge5direct+19selected通过。复制测试的源码路径与非安装测试驱动最初导致 wheel 失败;私有 helper 改指安装生产 owner 后同断言通过。额外 adapter mypy 仍有5条既有错误,未声明全树类型干净;相同主干 adapter 有6条。打包中英文 desktop/390px 与真实安装 HTTP 校验库存、原 outbox、失败清空/恢复及零写入;UI 与原94a8源代码一致,截图已核对。七项接收端用例物理移除四个 Python producer 文件,验证 markerless abandoned/committed、原 receipt 精确 replay、lease 不变及 ambiguous 同操作回滚,保留 OS-lock 与历史读取器。

我的整体评价

APPROVE,该完整库存阶段与原始处置验证可独立审核;不能记为完整冷导入或最后 writer 退役。面向未来的有界重构已应用:复用主干 lease 准入,取消重复冷源 filesystem 分支,没有增加泛化 framework 或 Python 第二决策源。原请求要求独立精确 head 复审;自审、readiness 和已知 CI 状态均不能替代它,尚无合并声明。

语义与 CI 对齐

扩展现有 coordination owner 的只读请求/结果契约与两个已有调用者使用的 effect method;不创建 actor 生命周期或独立权限模型。typed owner 与 CLI/HTTP 传输复用同一 source/error/proof 语义,advisory、完整 semantic check 与 I/O census 通过。主干新增 node_probe vocabulary 属于合入的既有主干历史。

@huangruiteng
huangruiteng merged commit 31b74bc into main Oct 9, 2026
12 of 29 checks passed
@huangruiteng
huangruiteng deleted the codex/cold-source-inspection-r123 branch October 9, 2026 06:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants