Skip to content

fix(status): use canonical authority for promoted Todo health - #5237

Merged
huangruiteng merged 7 commits into
mainfrom
codex/canonical-contract-health
Sep 28, 2026
Merged

huangruiteng merged 7 commits into
mainfrom
codex/canonical-contract-health

Conversation

@huangruiteng

@huangruiteng huangruiteng commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Problem And Result

A promoted Goal could have healthy canonical Todos while status exited 1 because its obsolete Markdown display contained an invalid User Todo. Health now follows the same fence-selected canonical authority as attention, while preserving the supported Todo metadata and active User class/scope rules. A valid record structure alone cannot make invalid active work healthy.

The shared TypeScript owner evaluates class, scope, status, executor exclusions, claim conflicts and removed policies without writing state or reauthorizing completed history. Python transports only semantic fields in batches of 512; narrative text never enters this diagnostic RPC. Missing providers and corrupt read models remain Goal-scoped failures with no Markdown fallback. Unpromoted Goals retain legacy checks; invalid UTF-8 now produces a structured read error and still rejects the command.

Related: #4574 and the shared-authority RFC. This closes the reproduced diagnostic-authority defect, including the semantic regressions identified in review. It does not close provider-default selection, writer retirement or D2 sustained acceptance.

Scope And Ownership

  • Existing canonical snapshot/record readers and typed Todo authoring rules are reused. The bounded companion refactor shares class, ownership and removed-policy classification with their current callers.
  • Five production files, two focused test files and the existing bilingual RFC ledger change. No new capability, provider, CLI option, stored format, migration or permission owner.
  • Completed/deferred User history and archived executor metadata keep their existing treatment. Legal implicit gate bindings and executor exclusions remain healthy.
  • Contract and attention still read separate snapshots; no command-wide consistent snapshot or cross-request cache is claimed. The ledger labels earlier structural-only timing samples as inapplicable to the final semantic correction.

Validation

Tested source: 5f37c82718e83c2b392c908add283af4ad990533, based on main at 0730b6cc221082600288b453b447133ac732d978. Fixtures are public-safe synthetic data in isolated stores. Latest-main chat GoalRef registration in the shared Effect dispatcher is integrated; typed dispatch, static checks and all real-source counterfactuals were rerun on this exact head.

Check Result
Python production entrypoint / real backend 182 passed across canonical status, contract health, authoring scope and status wiring/history suites. Real File/SQLite, legacy/native records, all existing diagnostic codes and legal/terminal controls.
Typed control-plane contracts 127 passed, zero skips: authoring/metadata, snapshot paging, projections, edits, terminal decisions and Effect handlers.
Independent base/head counterfactuals 91 paired API/CLI cases with equal fixture fingerprints and unchanged storage/display inventories. Canonical errors remain unhealthy; obsolete display cannot invalidate or rescue canonical state.
Bounded diagnostic transport Full public status passes with 1,100 valid User Todos and narratives exceeding 2 MiB across both providers and record formats.
Static / boundary TypeScript typecheck, configured mypy (19 files), changed-file Ruff, diff hygiene and all-nine-file public-boundary scan passed. Every branch commit is DCO signed.
Premerge 19 selected/executed checks passed, five direct checks passed; no failures, skipped required checks or manual holds. Exact-scope quality receipt verified valid; one bounded safe-fix pass, zero blockers/warnings and one inherited scale advisory.

Scale limitation preserved: with 4,101 Agent Todos, whole status hits the same existing todo.succession.project response-budget failure on immutable main and this head for File/SQLite. The repaired contract API reads the collection successfully. This is remaining caller-payload acceptance, not a claimed whole-command scale improvement; the RPC limit was not relaxed.

Remote CI is not queried or awaited under the configured review policy. PostgreSQL providers, D2 soak and installed adoption are outside this local diagnostic repair.

User Entry Points

The public CLI and shared status health projection change their existing healthy/error result. Existing presentation consumers render the existing error fields; no editor, layout, configuration input or packaged frontend changes are needed. The real CLI journey, state readback and read-only behavior were exercised. Installation/adoption after merge remains separately owned.

Merge Authority

The maintainer explicitly requested self-repair and self-merge for this PR. Exact-head published review and merge readiness remain required; validation alone does not grant merge authority. Public changes exclude private state, raw evidence, credentials, local paths and generated artifacts.

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Request changes conclusion (author-owned PR; GitHub blocks formal self-review)

English verdict: REQUEST_CHANGES at 5fc568aeb7229248a41069e646eb89933fcf6afb.

[P1] canonical 分支跳过了仍有效的未完成 User Todo 语义校验。不是 CI 问题,也不是要求重新授权历史操作。

动机

健康的 canonical Todo 不应被过时 Markdown 投影判坏,这个修复方向成立。但“以 canonical 为事实来源”不能变成“canonical 结构合法就视为全部健康”。

改动思路

复用现有 canonical reader 是正确选择。缺口在 _todo_contract_diagnostics:474–475 的 continue 跳过了后面的全部 class/scope 诊断。TS read-model/record validator 验证结构、身份、状态、digest 等,并未验证 open User Todo 必须有 user_action|user_gate。这一现行要求仍由 todos/authoring_scope.ts::requireTaskClass 和非 done 分支维护。

具体改动

我用真实 File / SQLite,各跑 legacy / native 两种 canonical 记录,保持 digest/manifest 合法;只让一个未完成 User Todo 缺少 task_class,Markdown 与它一致,并去掉 claim 元数据避免混入其他非法条件。四组结果完全一致:base 返回 user_todo_task_class_missing、status exit 1;head 返回健康、exit 0,诊断消失。check_contract 的接入点 会把这个错误健康结论交给现有 status 消费者。

反向控制也已验证:合法 user_action 与已完成且缺 class 的历史 Todo,在 base/head 上都健康(8 组);修法不该给完成态补新门槛。另有 55 组独立 API/CLI 对照,验证过时/缺失/无效 UTF-8 投影、缺 provider、坏 digest、非法 native 状态、跨 Goal 过滤,以及 4,101 条 canonical 记录;读操作都未改写 provider 或投影。

最小修法:保留 canonical source routing,在共享 TS 语义 owner 中复用/提取只读的非终态 class/scope 检查,对 canonical 记录产生 Goal-scoped 诊断;不要回读 Markdown、复制一套 Python 决策,也不要重新授权历史操作。补四组合缺 class 反例,并保留合法/完成态与坏 provider/digest 的控制。

对主干的风险

本地 head 60 个 Python、40 个 TS 测试通过;base 对应 36/40;Ruff、配置内 mypy(19 files)通过。19 项 premerge 检查本身全部通过,最初 aggregate 因本次 review 尚无质量回执而 hold;现在 exact-scope 质量回执明确记录上述语义 blocker。现有绿测试没有覆盖这个干净的 canonical 反例。按配置未查询、等待或重跑 GitHub CI。

这只评估本次本地 provider 诊断修复;没有 PostgreSQL、D2 默认选择、writer retirement 或 retained-history SLO 的验收结论。

我的整体评价

有实际价值、范围合适,但暂不能批准。未来维护方向已做有界审视:继续复用现有 typed Todo 语义 owner,让下一次规则修改不需要分别修 legacy 与 canonical 的健康判断。补齐上述反例后再审 exact head;本轮不合并。

Comment thread loopx/contract.py
@huangruiteng

Copy link
Copy Markdown
Collaborator Author

Review frame alignment — exact head 5fc568aeb7229248a41069e646eb89933fcf6afb

当前边界是 shared authority RFC 中 canonical source 的诊断一致性:过时/缺失的 Markdown 显示投影不能判坏或救活 canonical Todo。本轮不把它当作 writer retirement、D2 默认切换、PostgreSQL 迁移或 retained-history SLO 的完成证据。

同时,结构有效不等于语义健康。现有 typed authoring scope 对当前非终态 User Todo 的显式 class 要求未被当前方向撤销。独立基线/head 反例因此评估的是保留现行健康诊断,而非重新审批历史执行。详见本次 exact-head review 的四组合反例和八组合法/完成态控制。

@huangruiteng
huangruiteng force-pushed the codex/canonical-contract-health branch 2 times, most recently from 03fcfd8 to e540191 Compare September 28, 2026 13:53

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Exact head: e540191dc8090b4db1a34c5d7648417fdab3c6ce. 基线为最新主干 7fa104dc02bb07946b68bf1c7c4a77186f51cc6d。本次重新执行当前 policy revision 11 的完整评审;此前旧 head 的 REQUEST_CHANGES 不作为本次批准证据。

动机

按既有评审框架和共享权威 RFC,本轮目标是让健康检查读取真正的 Todo 权威,同时保留当前语义约束。主干上,过时展示副本可让健康 Goal 的 status 退出 1;原 PR 又会漏报 canonical 中的非法任务。最终修复解决了这个完整诊断缺陷,有助于连续读取与后续工作,也让使用者得到真实、可纠正的状态;不代表 R5、D2 或旧 writer 退役完成。

改动思路

入口仍是现有 status/check_contract。先按 Goal 与 activation 过滤,再由既有 durable fence 选择完整 canonical 快照;结构、记录身份和 digest 校验通过后,使用共享 TS owner 产生只读语义诊断,Python 只传事实并适配现有健康投影。缺 provider 或损坏快照不能回退展示文件。未晋升 Goal 保留旧格式检查;非法 UTF-8 的合同 API 改为结构化读取错误,公共 CLI 仍拒绝。

我批判性检查了草稿和整个改动。空白类名绕过 scope、done 标志掩盖 open、正文撑破 RPC 预算都已修复;还用 18 组真实存储反例确认并修复了 User-only 方案漏掉 Agent 元数据的问题。直接跳过所有检查、回读 Markdown 或用带默认值的写入 planner 替代诊断都无法满足本轮契约。当前方案复用类、作用域、认领/排除与废弃策略 owner,没有新增存储、权限或通用框架。

具体改动

整个 PR 涵盖五个生产文件、两个薄的回归测试文件和现有双语 RFC 账本。后者保留 A/C/D2 的未完成边界,明确早期只校验结构的计时不能证明最终语义修复成本,并记录完整 status 的已知规模限制。测试覆盖原有诊断代码、两种记录格式与真实 File/SQLite、合法隐式绑定、执行者排除及完成/deferred/归档控制。既有状态展示消费相同的错误字段,没有新配置输入或布局,因此无需 frontend/Lark 配套编辑。

关键代码讲解

  1. _todo_contract_diagnostics 在过滤后选权威,调用完整读取与语义检查,把 provider/runtime 失败归到 Goal;canonical 数据既不能被旧显示判坏,也不能由它救活。
  2. todoMetadataDiagnostics 保留非法状态、Agent 路由、废弃策略、认领/排除冲突与成员检查;归档终态的既有豁免仍保留,不把诊断变成重新授权。
  3. evaluateTodoContractDiagnostics 同时检查两个角色的元数据,再为非终态 User 复用 class/scope;终态由 status 决定,不能靠矛盾的 done 布尔值隐藏错误。返回的是固定公开安全说明,不包含正文。
  4. todo_contract_diagnostics 只传必要字段,每批最多 512 条,聚合已校验数量和诊断;保留所有记录而不使用展示上限,也不放宽 RPC 消息预算。
  5. removedTodoContinuationPolicy 共享两个旧策略标记的识别。显式迁移仍由原调用方验证修复条件,识别本身不授予修复或认领权限。

对主干的风险

最强反例是“结构有效但当前元数据非法”:过去绿测试仍能让它误报健康。最终 91 组 immutable-main/exact-head 配对 API/CLI 用例使用相同输入指纹,全部读操作的 provider 与展示库存不变;非法 class/scope、Agent 元数据和来源损坏拒绝,合法终态与绑定继续通过。对照比较保留完整错误、退出码与库存;仅规范化捕获时间和新建存储的物理标识,错误文字从展示行/正文改为 canonical Todo 身份和固定说明是有意变化。

验证:182 个 Python、127 个 TS 测试通过,零跳过;TS typecheck、mypy 19 文件、Ruff、DCO、九文件公共边界及 diff 检查通过。premerge 五项直接检查与 19 项选定检查全部通过,失败/required skip/manual hold 均为零。质量回执与最终 fingerprint 匹配;safe-fix 允许并执行一轮,零 blocker/warning,一个已有规模 advisory。主干的公共文本分类 owner 更新已集成,公共 API/CLI、边界及验证在新基线上重跑;此前存储空间中断的测试也已重新完成,未把中断当作通过。

仍有明确限制:4,101 条 Agent Todo 的完整 status 在基线和本 head 上,都出现相同的 todo.succession.project 响应预算错误(两种 provider),属于未改动的整命令调用链;本 head 合同 API 能读该集合,1,100 条含大正文 User Todo 的公共 status 四组合通过。没有放宽预算或声称规模验收完成。合同和 attention 仍各读快照,PostgreSQL/D2/安装采用不在本轮验收内。

语义与 CI 对齐

复用既有 Todo 状态、错误码及权威词汇;只读 DTO 的名称与其范围一致,不增加 actor、peer、lease 或执行权。健康约束是机器拒绝,不称作指导;错误保持领域中性。没有新 optional activation;既有来源切换两侧及 Goal/activation 过滤均已真实验证,未晋升公共 CLI 的三组对照保持行为。按当前策略不查询、等待或推断 GitHub CI。

我的整体评价

APPROVE。长周期影响与用户体验均改善:真实状态可以被反复读取,过时展示不再制造修复负担,非法 canonical 任务不会被掩盖。这个切片有实际闭环,额外代码用于保留可达契约、真实失败路径与合法历史控制;有界未来维护梳理已应用,共享类/ownership/旧策略识别,未添加兼容壳或未来脚手架。维护者已针对本 PR 明确授权自修复自合并;仍须在发布本 exact-head 评审并读回后,通过同一 head 的 merge-readiness,验证本身不授予 merge 权限。

English verdict: APPROVE - e540191dc8090b4db1a34c5d7648417fdab3c6ce; canonical authority routing now preserves User and Agent semantic health with bounded readonly transport. 182 Python tests, 127 TS tests and 19 premerge checks passed; inherited whole-status scale limit is disclosed.

@huangruiteng

huangruiteng commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator Author

Review frame closeout — 5f37c82718e83c2b392c908add283af4ad990533

对照原有评审框架与当前 shared-authority RFC,本轮已核实:canonical 来源一致、结构损坏拒绝、活跃 User class/scope 与 Agent/旧格式元数据诊断均保留;展示副本不能判坏或救活 canonical state。旧 head 的语义缺口已实质修复,新 head 的独立完整评审已经发布并读回。

182 Python、127 TS、91 组新基线配对及 19 项 premerge 通过;所有配对读操作未改写存储或展示。4,101 Agent Todo 的完整 status 仍有基线一致的 succession RPC 响应预算限制,已保留在双语账本;合同 API 与 1,100 User Todo 公共 status 已验证。因此本轮关闭诊断缺陷,不关闭 D2、默认 provider、整命令规模/一致快照或旧 writer 退役,也不把早期计时当作最终版本性能证据。

自合并只使用维护者针对本 PR 的明确授权,并继续要求同一 exact head 的 merge-readiness;检查通过本身不授予 merge 权限。

Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
@huangruiteng
huangruiteng force-pushed the codex/canonical-contract-health branch from e540191 to 5f37c82 Compare September 28, 2026 14:09

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Exact head: 5f37c82718e83c2b392c908add283af4ad990533. 基线为最新主干 0730b6cc221082600288b453b447133ac732d978。本次重新执行当前 policy revision 11 的完整评审;此前旧 head 的 REQUEST_CHANGES 不作为本次批准证据。

动机

按既有评审框架和共享权威 RFC,本轮目标是让健康检查读取真正的 Todo 权威,同时保留当前语义约束。主干上,过时展示副本可让健康 Goal 的 status 退出 1;原 PR 又会漏报 canonical 中的非法任务。最终修复解决了这个完整诊断缺陷,有助于连续读取与后续工作,也让使用者得到真实、可纠正的状态;不代表 R5、D2 或旧 writer 退役完成。

改动思路

入口仍是现有 status/check_contract。先按 Goal 与 activation 过滤,再由既有 durable fence 选择完整 canonical 快照;结构、记录身份和 digest 校验通过后,使用共享 TS owner 产生只读语义诊断,Python 只传事实并适配现有健康投影。缺 provider 或损坏快照不能回退展示文件。未晋升 Goal 保留旧格式检查;非法 UTF-8 的合同 API 改为结构化读取错误,公共 CLI 仍拒绝。

我批判性检查了草稿和整个改动。空白类名绕过 scope、done 标志掩盖 open、正文撑破 RPC 预算都已修复;还用 18 组真实存储反例确认并修复了 User-only 方案漏掉 Agent 元数据的问题。直接跳过所有检查、回读 Markdown 或用带默认值的写入 planner 替代诊断都无法满足本轮契约。当前方案复用类、作用域、认领/排除与废弃策略 owner,没有新增存储、权限或通用框架。

具体改动

整个 PR 涵盖五个生产文件、两个薄的回归测试文件和现有双语 RFC 账本。后者保留 A/C/D2 的未完成边界,明确早期只校验结构的计时不能证明最终语义修复成本,并记录完整 status 的已知规模限制。测试覆盖原有诊断代码、两种记录格式与真实 File/SQLite、合法隐式绑定、执行者排除及完成/deferred/归档控制。既有状态展示消费相同的错误字段,没有新配置输入或布局,因此无需 frontend/Lark 配套编辑。

关键代码讲解

  1. _todo_contract_diagnostics 在过滤后选权威,调用完整读取与语义检查,把 provider/runtime 失败归到 Goal;canonical 数据既不能被旧显示判坏,也不能由它救活。
  2. todoMetadataDiagnostics 保留非法状态、Agent 路由、废弃策略、认领/排除冲突与成员检查;归档终态的既有豁免仍保留,不把诊断变成重新授权。
  3. evaluateTodoContractDiagnostics 同时检查两个角色的元数据,再为非终态 User 复用 class/scope;终态由 status 决定,不能靠矛盾的 done 布尔值隐藏错误。返回的是固定公开安全说明,不包含正文。
  4. todo_contract_diagnostics 只传必要字段,每批最多 512 条,聚合已校验数量和诊断;保留所有记录而不使用展示上限,也不放宽 RPC 消息预算。
  5. removedTodoContinuationPolicy 共享两个旧策略标记的识别。显式迁移仍由原调用方验证修复条件,识别本身不授予修复或认领权限。

对主干的风险

最强反例是“结构有效但当前元数据非法”:过去绿测试仍能让它误报健康。最终 91 组 immutable-main/exact-head 配对 API/CLI 用例使用相同输入指纹,全部读操作的 provider 与展示库存不变;非法 class/scope、Agent 元数据和来源损坏拒绝,合法终态与绑定继续通过。对照比较保留完整错误、退出码与库存;仅规范化捕获时间和新建存储的物理标识,错误文字从展示行/正文改为 canonical Todo 身份和固定说明是有意变化。

验证:182 个 Python、127 个 TS 测试通过,零跳过;TS typecheck、mypy 19 文件、Ruff、DCO、九文件公共边界及 diff 检查通过。premerge 五项直接检查与 19 项选定检查全部通过,失败/required skip/manual hold 均为零。质量回执与最终 fingerprint 匹配;safe-fix 允许并执行一轮,零 blocker/warning,一个已有规模 advisory。已集成主干的公共文本分类 owner 和聊天 GoalRef 调度注册;相关调度、公共 API/CLI、边界及验证均在最新基线上重跑;此前存储空间中断的测试也已重新完成,未把中断当作通过。

仍有明确限制:4,101 条 Agent Todo 的完整 status 在基线和本 head 上,都出现相同的 todo.succession.project 响应预算错误(两种 provider),属于未改动的整命令调用链;本 head 合同 API 能读该集合,1,100 条含大正文 User Todo 的公共 status 四组合通过。没有放宽预算或声称规模验收完成。合同和 attention 仍各读快照,PostgreSQL/D2/安装采用不在本轮验收内。

语义与 CI 对齐

复用既有 Todo 状态、错误码及权威词汇;只读 DTO 的名称与其范围一致,不增加 actor、peer、lease 或执行权。健康约束是机器拒绝,不称作指导;错误保持领域中性。没有新 optional activation;既有来源切换两侧及 Goal/activation 过滤均已真实验证,未晋升公共 CLI 的三组对照保持行为。按当前策略不查询、等待或推断 GitHub CI。

我的整体评价

APPROVE。长周期影响与用户体验均改善:真实状态可以被反复读取,过时展示不再制造修复负担,非法 canonical 任务不会被掩盖。这个切片有实际闭环,额外代码用于保留可达契约、真实失败路径与合法历史控制;有界未来维护梳理已应用,共享类/ownership/旧策略识别,未添加兼容壳或未来脚手架。维护者已针对本 PR 明确授权自修复自合并;仍须在发布本 exact-head 评审并读回后,通过同一 head 的 merge-readiness,验证本身不授予 merge 权限。

English verdict: APPROVE - 5f37c82718e83c2b392c908add283af4ad990533; canonical authority routing now preserves User and Agent semantic health with bounded readonly transport. 182 Python tests, 127 TS tests and 19 premerge checks passed; inherited whole-status scale limit is disclosed.

@huangruiteng
huangruiteng merged commit 962abb4 into main Sep 28, 2026
19 of 26 checks passed
@huangruiteng
huangruiteng deleted the codex/canonical-contract-health branch September 28, 2026 14:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant