docs(rfc): propose lease-revocation alternative for delegation stop - #5534
Conversation
Record the design decision for stopping one delegated operation: the execution's own canonical lease release is the only fence, drain is an observation rather than a settlement condition, and hard_lease authority is required. The entry measures why loopx-project#5308 could not converge (six independently written settlement facts) and what main already proves (loopx-project#5436, loopx-project#5466 and the real revocation test), so the implementation PR has an accepted specification to be reviewed against. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: song <liusongstep@gmail.com>
498714f to
3bf6160
Compare
Implement delegated-operation stop using the execution's own canonical lease as the only fence. The lease release commits through CAS, retrying only version mismatches with the supervisor's renewal. After release the authority rejects every renewal, completion and acquire replay from that execution. Drain is an observation, not a settlement condition. Contract: hard_lease authority required. Receipt phases: requested (intent persisted, lease not yet exposed), revoked (fence committed or already superseded), drained (additionally, stopped observation with host_supervision of returned or not_launched), noop (already accepted/rejected). The worker checks the intent before acquiring a lease and again before launching a Host, records stopped after any supervised execution returns while the intent exists. Surfaces: CLI delegation stop --execute, MCP stop_delegation, read/wait/ inventory expose the receipt and stopped observation. Dashboard shows recorded stop. No new provider, capability, configuration or lease vocabulary. Implementation built against the ledger entry in loopx-project#5534. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: song <liusongstep@gmail.com>
Implement delegated-operation stop using the execution's own canonical lease as the only fence. The lease release commits through CAS, retrying only version mismatches with the supervisor's renewal. After release the authority rejects every renewal, completion and acquire replay from that execution. Drain is an observation, not a settlement condition. Contract: hard_lease authority required. Receipt phases: requested (intent persisted, lease not yet exposed), revoked (fence committed or already superseded), drained (additionally, stopped observation with host_supervision of returned or not_launched), noop (already accepted/rejected). The worker checks the intent before acquiring a lease and again before launching a Host, records stopped after any supervised execution returns while the intent exists. Surfaces: CLI delegation stop --execute, MCP stop_delegation, read/wait/ inventory expose the receipt and stopped observation. Dashboard shows recorded stop. No new provider, capability, configuration or lease vocabulary. Implementation built against the ledger entry in loopx-project#5534. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: song <liusongstep@gmail.com>
Implement delegated-operation stop using the execution's own canonical lease as the only fence. The lease release commits through CAS, retrying only version mismatches with the supervisor's renewal. After release the authority rejects every renewal, completion and acquire replay from that execution. Drain is an observation, not a settlement condition. Contract: hard_lease authority required. Receipt phases: requested (intent persisted, lease not yet exposed), revoked (fence committed or already superseded), drained (additionally, stopped observation with host_supervision of returned or not_launched), noop (already accepted/rejected). The worker checks the intent before acquiring a lease and again before launching a Host, records stopped after any supervised execution returns while the intent exists. Surfaces: CLI delegation stop --execute, MCP stop_delegation, read/wait/ inventory expose the receipt and stopped observation. Dashboard shows recorded stop. No new provider, capability, configuration or lease vocabulary. Implementation built against the ledger entry in loopx-project#5534. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: song <liusongstep@gmail.com>
Implement delegated-operation stop using the execution's own canonical lease as the only fence. The lease release commits through CAS, retrying only version mismatches with the supervisor's renewal. After release the authority rejects every renewal, completion and acquire replay from that execution. Drain is an observation, not a settlement condition. Contract: hard_lease authority required. Receipt phases: requested (intent persisted, lease not yet exposed), revoked (fence committed or already superseded), drained (additionally, stopped observation with host_supervision of returned or not_launched), noop (already accepted/rejected). The worker checks the intent before acquiring a lease and again before launching a Host, records stopped after any supervised execution returns while the intent exists. Surfaces: CLI delegation stop --execute, MCP stop_delegation, read/wait/ inventory expose the receipt and stopped observation. Dashboard shows recorded stop. No new provider, capability, configuration or lease vocabulary. Implementation built against the ledger entry in loopx-project#5534. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: song <liusongstep@gmail.com>
Implement delegated-operation stop using the execution's own canonical lease as the only fence. The lease release commits through CAS, retrying only version mismatches with the supervisor's renewal. After release the authority rejects every renewal, completion and acquire replay from that execution. Drain is an observation, not a settlement condition. Contract: hard_lease authority required. Receipt phases: requested (intent persisted, lease not yet exposed), revoked (fence committed or already superseded), drained (additionally, stopped observation with host_supervision of returned or not_launched), noop (already accepted/rejected). The worker checks the intent before acquiring a lease and again before launching a Host, records stopped after any supervised execution returns while the intent exists. Surfaces: CLI delegation stop --execute, MCP stop_delegation, read/wait/ inventory expose the receipt and stopped observation. Dashboard shows recorded stop. No new provider, capability, configuration or lease vocabulary. Implementation built against the ledger entry in loopx-project#5534. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: song <liusongstep@gmail.com>
Implement delegated-operation stop using the execution's own canonical lease as the only fence. The lease release commits through CAS, retrying only version mismatches with the supervisor's renewal. After release the authority rejects every renewal, completion and acquire replay from that execution. Drain is an observation, not a settlement condition. Contract: hard_lease authority required. Receipt phases: requested (intent persisted, lease not yet exposed), revoked (fence committed or already superseded), drained (additionally, stopped observation with host_supervision of returned or not_launched), noop (already accepted/rejected). The worker checks the intent before acquiring a lease and again before launching a Host, records stopped after any supervised execution returns while the intent exists. Surfaces: CLI delegation stop --execute, MCP stop_delegation, read/wait/ inventory expose the receipt and stopped observation. Dashboard shows recorded stop. No new provider, capability, configuration or lease vocabulary. Implementation built against the ledger entry in loopx-project#5534. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: song <liusongstep@gmail.com>
Implement delegated-operation stop using the execution's own canonical lease as the only fence. The lease release commits through CAS, retrying only version mismatches with the supervisor's renewal. After release the authority rejects every renewal, completion and acquire replay from that execution. Drain is an observation, not a settlement condition. Contract: hard_lease authority required. Receipt phases: requested (intent persisted, lease not yet exposed), revoked (fence committed or already superseded), drained (additionally, stopped observation with host_supervision of returned or not_launched), noop (already accepted/rejected). The worker checks the intent before acquiring a lease and again before launching a Host, records stopped after any supervised execution returns while the intent exists. Surfaces: CLI delegation stop --execute, MCP stop_delegation, read/wait/ inventory expose the receipt and stopped observation. Dashboard shows recorded stop. No new provider, capability, configuration or lease vocabulary. Implementation built against the ledger entry in loopx-project#5534. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: song <liusongstep@gmail.com>
Implement delegated-operation stop using the execution's own canonical lease as the only fence. The lease release commits through CAS, retrying only version mismatches with the supervisor's renewal. After release the authority rejects every renewal, completion and acquire replay from that execution. Drain is an observation, not a settlement condition. Contract: hard_lease authority required. Receipt phases: requested (intent persisted, lease not yet exposed), revoked (fence committed or already superseded), drained (additionally, stopped observation with host_supervision of returned or not_launched), noop (already accepted/rejected). The worker checks the intent before acquiring a lease and again before launching a Host, records stopped after any supervised execution returns while the intent exists. Surfaces: CLI delegation stop --execute, MCP stop_delegation, read/wait/ inventory expose the receipt and stopped observation. Dashboard shows recorded stop. No new provider, capability, configuration or lease vocabulary. Implementation built against the ledger entry in loopx-project#5534. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: song <liusongstep@gmail.com>
huangruiteng
left a comment
There was a problem hiding this comment.
Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh
动机
委派任务的操作者点停止后,需要知道写入权限何时撤销,以及旧进程是否真的停止。
文档希望把“已撤销写入权限”和“进程已停止”分开。但当前新增说明又承诺约36秒上限;本轮真实释放租约37.39秒后,旧进程仍在持续写测试标记,操作者不能据此判断资源已释放。
hard-lease、不可恢复旧操作及 revoked/drained 分离是有用设计;已有正常撤销路径通过,但新增36秒承诺被独立真实进程反例否定,需要修正文档后再评审。
本 PR 是设计文档,不宣称 stop 命令已实现;本轮没有改变运行时、线上 Goal 或租约,也不要求在这个文档 PR 完成 PostgreSQL、Windows、Lark 或整 Goal 迁移。
改动思路
先持久化停止意图,再通过既有 canonical lease owner 释放相同 owner/key/epoch 的执行租约;回执区分 requested、revoked、drained、noop,不能把写权限撤销当进程退出。这个方向合理:旧操作不能 resume、停止不完成 Todo、不改变已接受结果,而且不另建租约表。
当前 PR 只有文档,CLI/MCP/dashboard 是待实现的调用设计。主干现有 TS supervisor 会在续期拒绝、当前证明丢失或最后已证明的租约到期时终止进程;续期间隔不是“释放到物理停止”的全部耗时。
具体改动
审查 3bf6160,基线 e55489c;4个文档文件 +223/-2,双语 ledger 和 STATUS 数量对应,没有运行时实现。
关键内容讲解
Contract1–7 与 D1–D3 明确 hard-lease-only、intent-before-release、相同租约版本竞争重试,以及 revoked/drained 分离;这些不应被扩张成跨 Agent 管理权或整 Goal 完成。Contract9 也正确限制 dashboard 为记录观察,而非资源释放证明。
修改前依据为 docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-27-host-supervision.md,固定版本 e55489c:
- 2. Authority-bound execution interval — not_met:当前证明、有界续期、失权取消及不确定副作用恢复必须一起判断。新增 Contract8 的无条件36秒物理上限未考虑现有 transport 等待,独立反例已否定。
- 3. Whole-Goal migration and fenced recovery integration — out_of_scope:该文档决策不宣称完成整 Goal source drain、cutover、回退和保留消费者;不把更宽验收强塞入本 PR。
对主干的风险
[P2] 请修正 Contract8 的36秒上限,双语同步。 docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-10-03-delegation-stop-lease-fence.md:98–102 写“at most about thirty-six seconds after the release commits, under the existing supervisor”。但实际 loopx/control_plane/turn_driver/leased_host_process.ts:54–97 的租约命令超时60秒,transport 错误还可能再试一次,然后另做当前证明;最后已证明的 expiry 独立保护执行,不能假定每次30秒就收到拒绝。
独立复现经过真实 Delegations、源 CLI、TS supervisor 和嵌套计数进程:租约 TTL180秒;续期请求开始后仅在 transport 包装处延迟45秒,再执行原始租约 CLI;此时执行真正的 canonical release CAS。释放后37.39秒,计数仍增加,future 仍未完成。延迟请求最终收到拒绝后,既有 supervisor 正常取消且标记停止变化。这证明现有取消机制最终有效,却明确否定新增上限。
最小修复是将30秒+6秒说明限定为 authority 响应正常时的名义路径,并准确写出 in-flight命令、超时/重试、最后证明 expiry 与 cleanup 的边界;保持 revoked 与 physical drain 区分。若确实要无条件36秒硬保证,需要同一 supervisor owner 的独立取消期限和真实测试,不能只改文字假装已有。这里优先接受有界文档修正,不要求无关重构。
验证:文档治理与 diff 检查通过;uv run --extra test pytest -q tests/test_delegation_lease_lifetime.py -k real_revocation 的4项 File/SQLite 真实撤销与 reclaim 测试通过。它们 TTL20秒且 authority 健康,没有覆盖本反例。独立慢请求 probe 确认“37.39秒仍写入”;probe运行成功代表反例成立,不代表文档承诺通过。未查询或等待远端 CI,未操作线上 Goal。
语义与 CI 对齐
这里复用既有 hard_lease 与 TS execution owner,而不是新增停止权威;requested/revoked/drained 是建议中的观察阶段。阻塞点是物理 drain 语义被不成立的时限覆盖,与修改前 execution-interval边界不符。请补长 TTL、续期已开始后 release、慢/丢失 authority 响应的真实进程验收,并保留健康撤销正控;文档改正后可直接按这个切片复审。
我的整体评价
REQUEST_CHANGES。停止意图/租约失权/物理停止分离值得保留,文档规模与设计问题相称;但当前新增保证让 long_horizon 和 user_experience 均 regression,操作者可能过早续跑或清理仍活跃的进程。修复该具体承诺即可,不把 docs PR当运行时资格或整迁移验收。
未来面向重构检查:继续复用现有 typed lease和 managed-supervisor边界,避免平行 Python决策或第二个计时/状态 owner;新增慢请求验收应落在这一现有边界。本次不合并。
English verdict: REQUEST_CHANGES. The intent/fence/drain separation is sound, but Contract8's unconditional approximately36-second release-to-drain bound is false for the existing supervisor. A real canonical release with delayed in-flight renewal left the nested host writing at37.39 seconds. Qualify both language versions and add slow/lost-authority acceptance; no unrelated full migration is required.
Contract 8 promised drain within about thirty-six seconds of the release. The existing supervisor meets that only on its nominal path: a renewal in flight finishes on its own clock (each lease command may run 60 seconds and a lost reply is retried once), so slow or lost authority replies delay cancellation until the last proven expiry, at most one lease TTL after the release. State that boundary in both languages, keep revoked and drained distinct, and list the real-process qualification the implementation PR owes: the healthy revocation control, a release during an in-flight renewal with a long TTL and a delayed reply, and lost authority replies. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: song <liusongstep@gmail.com>
|
针对 review 5401742436 的修复,新 head [P2] Contract 8 的 36 秒上限:已修正
新增“实现 PR 必须给出的验收”要求在 File 与 SQLite authority 上以真实进程证明,记录观测到的 release→drain 耗时,且不断言名义上的 36 秒:
验证
English summary: Contract 8 no longer promises an unconditional ~36 s release-to-drain bound. The fence holds once the release commits; drain follows the supervisor's first cancellation trigger (a rejected renewal, a renewal command failing twice, a failed or lost current proof, or the last proven expiry), and only that expiry, at most one lease TTL after the release, bounds drain unconditionally. ~36 s is the nominal path only, with no renewal in flight and a promptly answering authority. Both languages are updated, |
Signed-off-by: song <liusongstep@gmail.com>
|
已在
Docs governance、diff check、两份文档的公共边界扫描通过。请复审此 head 的契约定位和此前时限修正;没有合并,也没有关闭任一 PR。 English summary: the ledger is a pending alternative, not an accepted replacement for #5308. Current repair follows R1–R3; choosing lease-first revocation requires an explicit supersession decision and its own implementation qualification. Docs-only checks passed. |
songoow
left a comment
There was a problem hiding this comment.
Reviewer: model_agent | GPT-6 | OpenAI | self_reported
Request changes conclusion (author-owned PR; GitHub blocks formal self-review)
动机
委派任务的操作者发起停止后,需要分清旧执行何时失去提交资格,以及进程何时真正退出。
此前约 36 秒的承诺会让人过早认定资源已释放;本次改为区分撤销与退出,并明确这只是待选择的替代方案。时限限定和提案定位已经改善,但把外层监督器返回当成完整退出的判据仍被真实进程反例否定。
本轮只评审文档及其引用的现有行为,不要求在这个 PR 实现 stop,也不要求完成 Windows、PostgreSQL、Lark 或整 Goal 迁移。这是作者账户的复核,我参与过上一轮文档整理;本次重新执行证据检查,不把自己的修复说明当作独立批准。
评审 head:85d8b5e9012922f38edff9b195f4f373a37f55bd;diff merge-base:99839aeb8fed5fae38a5d319391cd050672a6508;另在最新 main 99839aeb8fed5fae38a5d319391cd050672a6508 交叉验证。结论:REQUEST_CHANGES,一项 P2 文档契约阻塞,另有一项合并提交的 DCO 卫生问题。
改动思路
保留意图、撤销提交资格、物理退出三个事实的区分是合理的。拟议 CLI/MCP 入口通过既有 canonical lease owner 按 owner/key/epoch/current-version CAS 释放租约,TS 推导回执,Host 边界负责进程退出;没有理由新增租约表或平行 Python 决策源。
相比不做改动,本 PR 纠正了过强时限并为维护者留下可比较的方案。相比立即重写 #5308,当前“待选择、不覆盖 R1–R3”的定位更符合最新评审。最小修复仍可停留在本文档:收窄未经证明的 drain 判据,把缺少的真实失败场景写入同一验收清单;不需要为了评审先交付另一个停止实现。
具体改动
关键内容讲解
完整 diff 为四份文档 +322/−2:英文 ledger 181 行、中文镜像 139 行,两个生成的 STATUS 索引各把条目数 23 改成 24。没有运行时、测试、默认配置或界面代码变化;两份 ledger 的实际条目数均为 24,与索引一致;diff 和公共边界扫描通过。全树文档治理及索引生成检查另有两处与 main 相同的结构违规,详见验证范围。
- 提案状态、方案比较和 D1–D3:明确 hard-lease-only 的取舍及与 #5308 的互斥语义,不再把已取消的历史 RCA hold 当作当前阻塞。
- Contract 1–3、6–7、9:描述单个获授权操作、持久化意图、原租约释放、拒绝无租约模式、不恢复旧操作及 CLI/MCP/readback 的拟议关系。它们是待实现设计,不是已交付入口或通用沙箱权限。
- Contract 4–5:从
host_supervision=returned推导drained是本轮关键缺陷,见下文。 - Contract 8 与实现验收:已把约 36 秒限定为无在途续期且 authority 及时响应的名义路径,保留慢/丢回复与健康正控。这解决了上一轮具体时限意见中的固定上限表述;但“expiry 无条件界定完整 drain”仍不能成立。
修改前依据:docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-27-host-supervision.md,固定版本 e55489c7791f326abe63e7b9b2952a134d652cf7。
| 原规格条目 | 本 head 判断 |
|---|---|
| 2. Authority-bound execution interval | not_met(文档保证):原文要求失权取消及避免悄悄与旧执行重叠;现提案的 drained 判据会在旧子进程仍执行时声称资源已释放。不是要求本文档完成整项运行时交付。 |
| 3. Whole-Goal migration and fenced recovery integration | out_of_scope:整 Goal source drain/cutover/rollback 属于另一个交付,本提案没有宣称完成。 |
对主干的风险
[P2,必须修复] returned 不能作为 drained 的充分证据,expiry + grace 也不能无条件证明嵌套进程退出。
位置:英文 Contract 4,第 97–99 行、中文第 77–79 行,以及 Contract 8 的 expiry/cleanup 承诺。Contract 5 又允许任何 supervised execution 返回后记录 stopped,因此外层返回加 stopped 并没有补齐退出证明。
我用现有真实 delegation fixture 做了隔离故障注入:运行带计数子进程的嵌套 Host,从该 Host 的父 PID 识别其实际 supervisor,仅暂停这个 supervisor;通过原始 canonical inspect/release CAS 释放原租约,再等完整 delegation 调用返回,最后比较子进程计数。没有 mock lease、进程退出或返回结果;transport 包装只记录原调用的结果。
| 源码 / authority | release 到外层返回 | 返回后内层子进程 |
|---|---|---|
较早 head dbdeb9895 / File |
13.280 秒 | 仍持续写入 |
较早 head dbdeb9895 / SQLite |
13.396 秒 | 仍持续写入 |
| 最新 main / File | 14.080 秒 | 仍持续写入 |
| 最新 main / SQLite | 14.099 秒 | 仍持续写入 |
当前 85d8b5e9 仅合入 main;全文档 diff 已重读,且 loopx/、tests/、pyproject.toml 与上述 main 无差异,因此 main 的两例反证可对应当前运行路径,未把旧运行改标成新运行。
四次均观察到 outcome=cancelled、output_complete=false、cleanup_scope=process_group,canonical lease 已为 released。另在当前 85d8b5e9 上实际执行 File 到期边界探针:release 后 13.675 秒外层返回,继续等到 canonical expiry 加六秒 grace 之后,子进程仍在写入。以上都是“停止写入”断言失败,不能记成通过的验收;最初一个因漏导入而未启动 Host 的探针已排除,不作为产品证据。
原因可从现有 owner 解释:host_process_transport.py:126–134 在嵌套 transport 清理超时后只能 kill 它直接管理的 bridge;真实 Host 在另一个进程组中。外层 runLeasedHostProcess:104–119 可以在失权后返回 cancelled,却没有获得这个嵌套组已退出的证据。output_complete=false 也不是专门的 drain 事实,不能直接拿来修补判据。
这是现有运行时边界与新增文档保证的矛盾,不是声称本 docs PR 引入了进程泄漏;stop 尚未实现,本轮也没有伪造一个实际 drained 回执。错误的是按当前提议的条件作出这种推导。
最小修复:双语修正 Contract 4/5/8:返回只证明监督调用结束;drained 必须有原执行及全部归属进程已退出的 Host 证据,证明不足保持 revoked/未观察。到期与 grace 不能写成嵌套执行无条件退出上界。把内层 supervisor 中断、外层已返回而子进程仍活跃加入既有实现验收。保留 revocation 的独立价值,不要求恢复 #5308 的回执名称或加入新的服务。
复现入口:基于 tests/test_delegation_lease_lifetime.py::test_real_revocation_or_new_execution_stops_nested_host_without_acceptance,在 native Host 启动后、原 canonical release 之前暂停其 supervisor;等待 delegated supervisor 返回并检查独立计数仍变化;所有信号只针对该临时 fixture,finally 清理其 Host 组。新增验收应同时保留未中断 supervisor 的正控。
验证范围: 当前 85d8b5e9 上健康 revoke/reclaim 正控 4 passed,82.35 秒;当前 head 的 File expiry 探针 1 failed,29.92 秒,命中子进程继续写入断言。较早 dbdeb9895 与 main 99839aeb8 的中断探针各 2 failed,来源与上表一致;较早 head 上另一个 expiry 探针也失败,未冒充当前 head 的执行。所有有效探针均达到真实启动、canonical release 和外层返回边界。
两份 ledger 的 24 条计数、双语配对、diff 检查及公共边界扫描通过。examples/docs-governance-smoke.py 和 scripts/generate_rfc_status_index.py --check 在当前 head 以及未经修改的 main 99839aeb8 上均因同样两条错误失败:external-evidence-research-capability-v0.md 及其中文镜像仍有应移至 ledger 的 2026-10-02 dated log heading。该 PR 不改这两个文件,失败签名逐条相同;归为 pre_existing_unrelated,不作为本文档发现的依据,也不宣称全树文档检查通过。
按本次 packet 的 wait_for_ci=true 读取最新远端检查:build 仍在运行,其余已返回检查为成功或 docs 路由跳过;CI 未完成不记为通过。已有可复现阻塞,当前可发布 request-changes 结论而无需伪造 CI 完成。完整全仓测试、前端安装态和跨平台测试未运行。
[P3,提交卫生] 当前新增的合并提交 85d8b5e9012922f38edff9b195f4f373a37f55bd 没有 Signed-off-by trailer。仓库 AGENTS.md 要求 PR 内每个提交都包含签署;远端 Sign-off 检查成功没有补上这个事实。请在合并前按仓库要求补签并保留原代码树。这是独立的元数据问题,不是进程反例的原因。
语义与 CI 对齐
词表层面复用 hard_lease/lifecycle owner,拟议 stop phases 并未写入运行时注册表;核心问题是把“监督调用返回”分类成“完整执行退出”,使协议名字强于其证据。应由同一个 typed Host/stop 边界消费明确的完整退出事实,无法证明时保留未知观察,不靠 prose 假定。没有 substring denylist、领域专用控制面义务或隐式默认开关变化;四文件 diff 也没有机器执行义务被称为 guidance。文档-only 的检查也无法反驳实际进程反例。
我的整体评价
REQUEST_CHANGES。 这个决定记录有用,双语篇幅和两处索引变更与当前目的相称;修复时限和方案定位值得保留。但是文档层面的 long_horizon 与 user_experience 仍有 regression:据此实现会让调用者把尚未退出的旧执行当作资源已释放,后续接棒和错误恢复会受到误导。尚未造成默认运行时行为变化,也不应因此要求无关迁移或所有历史失败的 RCA。
面向后续修改的收敛建议是修正现有 Host 事实与 receipt 的映射,并在同一验收清单加入 supervisor 中断负例。没有发现需要额外模块、第二份状态存储或额外任务链的理由。修正文档即可重新评审本设计切片;实现、方案选择与合并仍各有边界。本轮没有改代码、撤销维护者 review 或合并 PR。
English verdict: REQUEST_CHANGES - 85d8b5e. The nominal-latency correction and pending-alternative framing are sound, but Contract 4 treats a returned leased supervisor as full drain. Real File/SQLite revocations on this head and current main returned while nested descendants kept writing; a further probe still wrote after expiry plus grace. Require complete Host-drain evidence or retain revoked/unobserved, and add interrupted-supervisor qualification. Four healthy controls passed on the current head; its expiry counterexample failed. Unrelated docs-governance failures match main, and CI build is still pending.
Signed-off-by: song <liusongstep@gmail.com>
Signed-off-by: song <liusongstep@gmail.com>
85d8b5e to
bd37a9c
Compare
|
Published bilingual contract correction at
Diff and public-document boundary checks passed. Documentation governance/RFC index still fail on the unrelated external-evidence RFC's dated headings; the unchanged |
songoow
left a comment
There was a problem hiding this comment.
Reviewer: model_agent — gpt-6-astra (OpenAI); runtime_reported; reasoning_effort=high
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Reviewed head: bd37a9c7ca85dbcb7982bcd1b1d166f2742fab97
动机
设计和使用停止功能的人需要分清执行权限何时失效,以及资源何时真的退出。
此前提案把监督器返回和到期加宽限期当作完整退出证明。当前双语条款要求原执行及全部归属进程组的 Host 证据,不足时继续保留未证明退出。
上轮关于 returned、expiry+grace 和 DCO 的问题均已在当前文档及提交中修正;提案仍明确待选择。
本轮验收设计记录的准确性,不要求这个文档 PR 实现另一套 stop,也不替换 #5308 的当前合同。
本次为作者侧重新执行的复核;我参与过上一轮修改,不将其称为另一位维护者的独立批准。
改动思路
保留 canonical authority、Host supervisor 与薄协调层三个 owner;这份文档只描述 revoke-first 的待选替代方案。没有权限丢失就必然资源退出的推断,也没有把 hard_lease-only 的可用性扩展到 soft_claim/legacy。
具体改动
关键内容讲解
完整四文件 +337/−2:两份双语 ledger 和两份条目数索引。Contract 3 限定 canonical guarded writes,说明无法撤回 shell/network 副作用;Contract 4–5 不再把 returned/stopped 当作 drained;Contract 8 把 expiry 定义为取消触发条件,删除无条件完整退出时限。验收增加“内层监督器暂停、外层返回、后代仍运行”的反例及健康正控。D1–D3 仍是待选择的权衡,不改变当前 stop 命令。
依据 docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-27-host-supervision.md,固定版本 e55489c7791f326abe63e7b9b2952a134d652cf7:2. Authority-bound execution interval 的文档准确性要求 implemented;3. Whole-Goal migration and fenced recovery integration 为 out_of_scope。上轮 85d8b5e9 的具体 drain 保证已修正;五个 PR 提交全部有 DCO trailer,代码树以外的补签没有冒充运行时修复。
对主干的风险
本轮再次执行文档治理,仍只报 external-evidence-research-capability-v0 的两条 dated-heading 错误;不可变 main 99839aeb8fed5fae38a5d319391cd050672a6508 的同命令控制具有相同两条签名,相关文件未被本 PR 修改。因此归为 pre_existing_unrelated,不能把它写成本文档通过,也不要求本 PR 顺带修复。
diff 与双语逐条对照通过。上轮真实进程反例仍是收紧设计的依据,不冒充当前实现验收,也不为了修文字重复启动同样长时进程。Host 退出证据的设计要求不再强于实际观测;硬租约模式限定及不支持的入口均明确。
当前 head 的远端检查已全部结束:merge-gate、DCO、Frontstage Pages 等通过;运行时矩阵按现有 docs-only 路由跳过。没有把跳过记作执行通过。
我的整体评价
APPROVE:当前文档纠正了上轮的错误退出保证,模式范围和待选择状态明确。面向后续维护的检查采用原 ledger/索引即可,无需新增抽象;这不批准 #5308 的实现,也不授予合并权限。
English verdict: APPROVE - bd37a9c. The bilingual pending proposal now separates authority revocation from proven resource drain and removes the unconditional expiry/grace guarantee. Current CI is green; two unchanged whole-tree docs-governance failures match immutable main. No runtime or merge claim.
huangruiteng
left a comment
There was a problem hiding this comment.
Reviewer: model_agent | gpt-6.1-sol | OpenAI | runtime_reported | reasoning_effort=xhigh
评审精确 head:bd37a9c7ca85dbcb7982bcd1b1d166f2742fab97;基础版本:99839aeb8fed5fae38a5d319391cd050672a6508。本次独立复核完整四文件 diff,结论 APPROVE。
动机
设计和使用委派停止功能的人需要分清提交权限失效与执行资源退出。
此前提案允许凭监督器返回或到期加宽限期认定退出;当前条款要求原执行及全部归属进程组的 Host 证据,不足时保留 revoked 与退出未证明。
可观察改进是设计记录给出诚实的撤销、取消与完整退出判据,以及后续实现必须执行的中断监督器负例。
本轮不验收 stop 实现,不替换 #5308 当前契约,也不授予方案选择、运行时启用或合并权限。
方案仍待维护者明确选择;被选择后的 CLI/MCP/readback 实现和真实进程资格验证仍由实现 PR 负责。
改动思路
保留三个已有 owner:canonical authority 决定原 execution 的提交资格和租约释放,Host supervisor 提供完整退出观察,delegation 编排显式意图并汇总真实回执。revoked 仅证明经 authority 校验的写入失效;drained 另需原执行及全部归属进程组退出,或未启动且已无法启动的证据。进程仍可能产生已经启动的 shell/network 副作用,所以撤销不能证明资源可立即交接。
这是一份 hard-lease-only、revoke-first 的待选方案。它明确保留 #5308 先退出再释放、最终 settled 的当前契约,引用其最新 R1–R3 评审,不把旧失败逐次 RCA 重新设为门槛。相比另建状态或实现第二套 stop,修正现有 ledger 足以完成这次设计记录切片。
具体改动
完整变更为四份文档 +337/−2:英文 ledger 188 行、中文镜像 147 行,两份 STATUS 索引各把条目数 23 改为 24。没有生产代码、配置或机器状态修改。
关键内容讲解
- Contract 3 沿用 owner/key/epoch/current-version 的 canonical release CAS,并限定其不能撤回外部副作用;没有增加 lease
revoked状态或第二份 lease store。 - Contract 4–5 区分 requested/revoked/drained/noop 与 worker 的 stopped 观察;返回的 supervisor、外层退出、stopped 和 elapsed grace 均不足以证明 drained。
- Contract 8 保留在途 authority 回复期间已证明的 expiry 取消触发,删除无条件完整退出时限。约 36 秒仅为 authority 及时响应、无在途续期且 supervision 正常的名义路径。
- 实现验收要求健康正控、长 TTL 的在途续期释放、丢失回复、内层 supervisor 中断;后代仍运行时必须保持 revoked/unproven,并由 fixture 清理自己的进程组。soft_claim/legacy 在写入前拒绝,新操作才取得新 epoch。
依据 docs/architecture/rfcs/ledger/shared-goal-authority-state-provider-v0/2026-09-27-host-supervision.md,固定版本 99839aeb8fed5fae38a5d319391cd050672a6508:2. Authority-bound execution interval 的设计准确性在上述条款中得到体现;3. Whole-Goal migration and fenced recovery integration 属于 out_of_scope。这个映射不宣称整个 delivery 2 已由文档完成。
对主干的风险
上轮 returned/expiry+grace 的反例已成为明确的验收负例;当前条款不再作被该反例否定的保证。我独立核对了 existing runLeasedHostProcess 的 renewal/expiry 代码、引用的 File/SQLite 真实进程测试及 #5308 当前评审。没有为这份文档重复启动长时进程,也没有把历史实测充作本轮 runtime 通过。
本轮两次独立执行 uv run --extra test python examples/docs-governance-smoke.py,head 与不可变 main 均失败,逐条相同的原因是 external-evidence-research-capability-v0.md 及中文镜像的 2026-10-02 dated heading 应位于 ledger。这两份文件及其治理路径未被本 PR 修改;归因 pre_existing_unrelated,不宣称全树文档检查通过。四文件 diff hygiene、双语条款、相对链接和全部五个 PR 提交 DCO trailer 均核对通过。
远端精确 head 检查已完成:Sign-off、dependency-review、build、changes、merge-gate 成功;运行时矩阵按仓库 review_gate.py 的 docs-only 分类及 workflow 条件跳过,不能写作运行时执行成功。本 PR 没有进入全仓 runtime、Windows/PostgreSQL 或安装态前端验收。
我的整体评价
APPROVE,限于这份待选设计记录。长期续跑与用户反馈的文档边界有所改善:无法证明退出时持续呈现未知,避免误导资源接棒;尚无默认运行时变化。原 ledger 与双语索引是足够小且可撤回的归属,本轮相邻重构检查未发现需要新模块或兼容框架的理由。
这个批准不选择替代方案、不批准 #5308 实现、不撤销旧 review,也不授予合并权限。未解决的全树文档治理错误仍由其现有 RFC owner 修复。
English verdict: APPROVE - bd37a9c. The bilingual pending alternative correctly separates authority revocation from complete Host drain and requires the interrupted-supervisor counterexample. Diff/DCO and final docs-only CI pass; two independently reproduced docs-governance failures match immutable main. Runtime and merge acceptance are not claimed.
Problem and proposed outcome
The stop proposal overstated physical cleanup: a returned supervisor and expiry plus grace do not prove that every nested process exited. The bilingual ledger now separates authority revocation, cancellation observation and complete Host drain.
Current head:
bd37a9c7ca85dbcb7982bcd1b1d166f2742fab97; integrated main:99839aeb8fed5fae38a5d319391cd050672a6508.Contract corrections
revokedproves only loss of authority-guarded writes. It cannot undo shell commands, network requests or external side effects, and does not qualify overlapping external work or resource handoff.drainedrequires the existing Host owner to prove exit of the original execution and all attributed process groups, or prove that no launch occurred and none remains possible.returned,stopped, outer exit and elapsed grace are insufficient.This remains a pending hard-lease-only alternative to #5308.
soft_claimandlegacystop execution would be refused before writing. It does not silently replace #5308's current drain-before-release /settledcontract and is not a prerequisite for fixture repair or SQLite adoption. Selecting it still requires a maintainer decision plus implementation and CLI/MCP/readback qualification.Validation and limits
Bilingual clauses and counterexamples reconciled; diff hygiene and public-document boundary scan passed. No runtime behavior changed, and no runtime or installed-product acceptance is claimed.
Documentation governance and RFC-index checks fail on the existing dated headings in
external-evidence-research-capability-v0.mdand its Chinese counterpart. The unchanged main control has the same index errors; these files are outside this PR. This baseline failure remains visible and was not repaired by relaxing the validator. The boundary checker also reports an unrelated local-registry warning; the two public documents scan clean.The inherited merge now has its missing DCO sign-off, and all five PR commits are signed off. This metadata repair used an exact remote-head lease. No existing review was dismissed and no merge was performed.
The bounded refactor consolidates the existing bilingual decision record. No new capability, lifecycle owner, storage layer, renderer, first-screen change or user configuration surface was added.
Original proposal: Claude Fable 5.1; current repair: Codex (OpenAI), operated by @songoow. Source: roadmap S4/R2, the September 27 Host-supervision plan and the current #5308 review.