Repository navigation
feat(coordination): review cold Goal imports through CLI and App - #6004
Conversation
…covery Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
…ceptance Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
…ckups Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh
Exact head: 00e5382
English verdict: APPROVE for this declared CLI/coordination prerequisite. This is an author-owned COMMENTED self-review, not a GitHub approval or merge grant. Runtime changes remain for maintainer merge.
动机
持有尚未导入 canonical 的 Markdown Goal、准备停止旧写入路径的维护者会遇到这个问题。
以前冷 Goal 必须先运行旧 writer 产生合格 shadow 才能迁移;本批增加了备份后预览、明确确认、导入 File/SQLite 并读取原操作回执的 CLI 路径。
已验证完整 active/archive Todo 记录进入协调存储,重试和重启保留原导入回执及后续 canonical 写入。
本批不宣布新 Goal 默认 SQLite,不删除最后 writer,不宣称整个 Goal 的历史恢复或已停止所有 Host。
剩余 packaged App 确认、实际 Host 停写与 lease/outbox 处置、完整历史恢复和旧 producer 缺席时的完整 CLI 入口,继续由现有 R5/T4 验收承接。
改动思路
在既有 TS coordination owner 中增加冷源前置检查,复用迁移、锁、provider 身份和回执;Python 只处理 tar/Host IO,避免第二个决策源。
本 PR 交付可执行的 CLI/协调事务阶段;App、完整恢复和最后 caller 退役保留为同一验收的后续工作,writer cutoff 前必须通过。
The accepted pre-change basis is docs/reference/local-authority-provider-selection.md at 0e5acfecf87743d76bd87b3f70c2a270c0e36179. Literal criteria: Inventory and back up the complete supported source (full Goal history/reactivation still deferred); Stop source writers and affected Hosts (real Host/disposition journey deferred; this stage enforces operator attestation and refuses unsettled sources); Preview an immutable source/target-bound plan (implemented); Recover the same operation after interruption (implemented for the coordination transaction; complete restore remains separate); shared by CLI and App (App companion remains the existing R5 gap). These dispositions retain the original acceptance before writer cutoff; they do not rewrite it to match this patch.
具体改动
- CLI prepare/apply/recover delegates to one typed coordination transaction. Prepare saves a source/target/backup-bound immutable carrier; apply rechecks source/backup under shared locks before fencing; recovery uses the original operation and receipt, never a fresh Markdown snapshot. No lease or execution grant is minted.
- Full active/archive Todo records use the existing canonical codec. Python witnesses actual tar members and embedded/external source maps; typed source coverage owns qualification. Prepare may select empty target identity metadata, but it does not fence/import.
complete_goal_backup_verified=falseremains explicit. - Self-review caught duplicate SHA validation and a physical-path alias mismatch. Both use their existing owners now: canonical digest matcher plus consumer guard, and CLI Host path normalization. The alias test failed before the fix and passes across prepare/apply/source-free recovery. A private receiver mutation omitting independent archive records failed the same real CLI tests on both providers; unmodified final wheel passes.
对主干的风险
Reviewed local evidence: final wheel 8 passed on real CLI/native runtime + File/SQLite; final source/default capture selection 24 passed; immutable base/head capture selection 16 each, with the complete default projection/snapshot/guard observation identical. Full control-plane TS 4258 passed, 0 failed, 32 skipped at the prior digest-fixed head; the final commit changes only CLI Host normalization and its Python regression, and all TS files are unchanged. Typecheck, configured mypy (19 files), changed-path Ruff, registry manifest (290 sites), semantic/public boundary checks pass. Final native premerge: 5 direct + 17 selected checks, no failures/manual holds, valid exact-scope CQR.
Material negatives cover stale plan/source/archive/manifest, forged backup source maps, expired/orphan/unsafe leases, unresolved outbox, target/completion identity loss, original receipt after later writes, and a real child killed after durable fence then recovered. Installed counterfactuals also cover an unrelated Goal, a newly created Goal, a future Todo inside the explicitly fenced Goal, scope escape and refusal-to-useful-recovery. Forward/reversed inventories both retain all 42 records beyond display limits, independent archive evidence and full body.
Earlier failures remain recorded: duplicate SHA-owner check, missing consumer registration, runtime-alias refusal, and full CLI with four old producers removed. The first three have direct before/after coverage; the last remains a T4 gap: feedback still needs live prose-write protection from the adapter. The runtime arm works with those files physically absent; this does not authorize wholesale deletion. The tar descriptor in TS tests is a trusted-adapter fixture; real CLI tests cover actual archive parsing. No packaged App, attached-Host stop/restart, complete Goal-history restore, Windows/Lark or PostgreSQL cold import qualification is claimed. No remote CI was fetched, polled or awaited under the native review policy.
我的整体评价
This is a justified, independently usable increment toward safe cold-source migration and subsequent retirement. The future-facing pass removed duplicated digest knowledge and normalized Host paths while retaining valuable prose protection; no parallel Python decision owner was added. The deferred work stays in the existing R5/T4 acceptance and Goal storage/Host/caller owners, rather than becoming a broad prerequisite for unrelated progress. The transaction is additive and explicit; after apply, binary rollback alone cannot undo the durable writer fence—use the supported original-operation recovery and separately qualified restore journey. APPROVE this stage; maintainer merge and full migration/default/cutoff qualification remain separate.
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
…ort-r128 Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
…ld-source-import-r128 Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
loopx-agent
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh
Exact head: 6dfdf01
English verdict: APPROVE - HEAD 6dfdf01; backup-bound cold CLI stage and producer-free legal import/recovery qualified by source12, independent wheel12 and exact-scope premerge. Author-owned COMMENTED review; maintainer merge remains required.
动机
持有尚未导入 canonical 的 Markdown Goal、准备停止旧写入路径的维护者会遇到这个问题。
以前冷 Goal 必须先运行旧 writer 产生合格 shadow 才能迁移;本批增加了备份后预览、明确确认、导入 File/SQLite 并读取原操作回执的 CLI 路径。
已验证完整 active/archive Todo 记录进入协调存储,重试和重启保留原导入回执及后续 canonical 写入;冷导入 CLI 在四个旧 producer 物理缺席时仍可运行。
本批不宣布新 Goal 默认 SQLite,不删除最后 writer,不宣称整个 Goal 的历史恢复或已停止所有 Host。
剩余 packaged App 确认、实际 Host 停写与 lease/outbox 处置、完整历史恢复和其他 CLI caller 的退役,继续由现有 R5/T4 验收承接。
改动思路
在既有 TS coordination owner 中增加冷源前置检查,复用迁移、锁、provider 身份和回执;Python 只处理 tar/Host IO,避免第二个决策源。
本 PR 交付可执行的 CLI/协调事务阶段;App、完整恢复和最后 caller 退役保留为同一验收的后续工作,writer cutoff 前必须通过。
冷导入不再通过完整 CLI 和两个 state_refresh facade 加载旧 producer;cli_runtime 复用既有注册器与 handler,两处调用直接复用同一个 Goal 路径解析函数。无需新增 shim 或第二个 Python 决策源。错误参数仍进入原完整解析器,其他 caller 的退役另行验收。
Accepted pre-change basis: docs/reference/local-authority-provider-selection.md at 0e5acfe. Criteria dispositions: Inventory and back up the complete supported source — coordination bytes/records qualified, complete Goal history remains deferred; Stop source writers and affected Hosts — explicit operator attestation plus lease/outbox refusal, actual Host/disposition journey deferred; Preview an immutable source/target-bound plan — implemented; Recover the same operation after interruption — coordination transaction implemented, including producer-free cold CLI; shared by CLI and App — App companion remains deferred in existing R5. No criterion is removed to fit this stage.
具体改动
- prepare/apply/recover 委托给 TS executeColdSourceImport:实际 tar 成员和源字节绑定不可变 plan/provider 身份;锁内复核源和备份,先 fence 再提交。恢复读取原回执,后续 canonical 写入不会被重建覆盖,也不生成新 lease/grant。
- runtime_shadow 只在显式冷导入时读取完整 active/archive Todo、metadata、独立归档证据和完整正文;既有 capture 默认分支保持不变。cold_source_backup.py 只负责可信 Host/tar IO,资格和迁移规则复用现有 typed owner。
- 既有 fence decoder 增加冷导入精确 schema,effect handler 复用原 bulk transport;registry census 只更新行号。文档给出实际命令、确认和恢复边界,roadmap 保留 App/Host/完整恢复原验收。
- 本轮复审补齐 cli_runtime 现有选择分发和两处直接 resolver 导入。先证实 File/SQLite 的缺文件案例失败,再修复三条加载边;同一真实 CLI 在独立 wheel 中通过。feedback 仍需要的 prose-write protection 保留。上一轮 SHA 单 owner、Host 路径别名修复和 archive 缺失 mutation 证据仍有效,涉及的 typed 代码与测试未改变。
对主干的风险
当前 head 源码 12 passed、独立安装 wheel 12 passed;父进程和子进程包来源都已核对,其中 File/SQLite 真正删除四个旧 producer 文件后运行 prepare/apply/readback/source-free recovery。九组合法 help/非法参数与完整 CLI 逐字一致;未开启 shadow 的 inspect 输出一致,源字节和 fence 不变。合入主干 Node probe 变更后,相关 probe/permission/Turn-journal 59 passed。
保留证据带原执行版本:较早的 product revision CLI/promotion 71 passed、capture/promotion 27 passed;不可变原 base/head capture 各 16 passed,完整默认 projection/snapshot/guard 观察一致。未改动的 typed transaction/tests 复用 2a8888c 上全套 4258 passed / 0 failed / 32 skipped。当前 configured mypy19、changed-path Ruff、registry census290、semantic/public-boundary 检查通过;固定 base 9632a9b 的原生质量回执 cqr_6ee57c1ab8415d53e981 有效,premerge 5 direct +17 selected 全通过,无失败或 manual hold。没有读取、轮询或等待远程 CI。
负例覆盖源/plan/archive/manifest 变化、伪造 source map、unsafe/expired/orphan lease、未结算 outbox、目标及完成身份丢失;原回执保留后续写入,真实进程在 fence 后 SIGKILL 再恢复。原 installed scope 对照与两种顺序的42记录盘点仍有效:无关 Goal、新建 Goal、覆盖 Goal 的未来 Todo、scope escape、拒绝后的有效恢复均保留。TS backup descriptor 是可信 adapter fixture;真实 CLI 使用实际 archive。
先前失败没有抹掉:SHA 重复 owner、consumer 漏注册、路径 alias、以及本轮完整 CLI/两处 facade 加载旧 producer 的失败均保留,并有直接修复与反例。当前通过只证明合法冷导入命令的加载边界;错误参数兼容 fallback 和其他 caller 尚不能据此删除 producer。实际附着 Host 停写/重启、packaged App、完整 Goal 历史恢复、Windows/Lark/PostgreSQL 冷导入仍未验收。导入后更换二进制不会撤销 durable fence。
我的整体评价
没有此阶段的阻塞发现。相对原问题,完整备份绑定、预览确认、fence 和原回执恢复组成可用的 CLI 阶段;移除三个加载依赖使这一阶段能独立于旧 normal producer 运行。未来方向的重构复用了既有 typed/CLI/路径 owner,并保留有价值的写保护。仍需通过原 Goal storage App/Host/完整历史验收才能宣告 writer cutoff 或默认 SQLite;本 PR 交给维护者合并,未取得自合并权限。
…ort-r128 Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
…ates Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Exact head: 6099e08
English verdict: APPROVE - HEAD 6099e08; the backed-up CLI/App cold-import stage has real File/SQLite, original-operation and packaged UI evidence. Full Host/history/cutoff acceptance remains open. COMMENTED author review; maintainer merge required.
动机
持有尚未导入 canonical 的 Markdown Goal、准备停止旧写入路径的维护者会遇到这个问题。
以前 App 只能把旧 Markdown Goal 指向 CLI 晋升;现在可在现有 Goal 数据存储设置中备份、盘点、选择执行策略并确认导入 File/SQLite。
已验证 active/archive Todo 进入协调存储,页面重载保留原操作但重置确认,来源变化拒绝,导入成功后丢失响应仍能读回原回执和当前存储。
本批不宣布新 Goal 默认 SQLite,不删除最后 writer,不宣称整个 Goal 历史恢复或自动停止 Host。
实际附着 Host 停写与 lease/outbox 处置、完整 Goal 历史恢复,以及 App 在旧正常 writer 物理缺席时的加载仍未验收,继续由现有 R5/T4 承接。
改动思路
在既有 TS coordination owner 中复用迁移、锁、provider 身份、fence 和原回执;Python 负责备份/HTTP IO,App 复用数据存储设置与原操作缓存,没有第二个导入决策源。
本 PR 交付可用的 CLI/App 冷源导入与只读恢复阶段;实际 Host 停写、完整历史恢复和 App 旧 writer 缺席仍由原验收承接,writer cutoff 前必须通过。
不修改现有 shadow 晋升的操作数量资格,也不伪造捕获历史。冷导入需要自己的来源检查和持久化操作,但提交和原回执读回沿用现有 owner。备份预览产生可审核的来源身份,执行策略是用户选择,停写确认是操作人声明;文件锁不能证明 Host 已停止。App 只缓存 Goal/operation/hash 三个标识,重新打开页面会重置确认并只读原操作;只有再次明确确认才可能执行。既有 canonical provider 切换保持其原始 carrier 和读回路径。
具体改动
Accepted pre-change basis: docs/reference/local-authority-provider-selection.md at 0e5acfe. 以下逐项保留原验收,而不是用本次文档修改重新定义通过:
- Inventory and back up the complete supported source:协调来源的完整 active/archive Todo、metadata 和实际归档字节已覆盖;完整 Goal 历史恢复仍 deferred,结果明确 complete_goal_backup_verified=false。
- Stop source writers and affected Hosts:stop attestation 和 unsafe/unsettled lease、capture/outbox 拒绝已实现;实际附着 Host 停写、逐项处置与重启仍 deferred。
- Preview an immutable source/target-bound plan:implemented;目标 provider/identity、来源字节、备份成员和原操作绑定,锁内复核后先 fence 再提交。
- Recover the same operation after interruption:CLI 协调事务的真实中断、后续写入和原回执恢复通过;App 只读重载和失响应恢复通过。完整验收仍 deferred,因为 App 在旧正常 writer 物理缺席时的加载和完整历史恢复尚未通过;物理缺席当前只证明 CLI。
- shared by CLI and App:implemented;真实 wheel CLI/HTTP 与 packaged App 复用同一 TS 冷导入 owner 和现有数据存储设置。
关键代码讲解
- executeColdSourceImport(cold_source_import.ts:179)拥有源/备份资格、不可变 carrier、目标身份、fence 和原回执。新增 readback 分支只读:已 fence 但尚未提交时返回 prepared,不创建 head 或完成 marker;已完成但目标消失或 marker 被损坏时拒绝重新播种。完成路径复用 promotion_receipt,后续 canonical 写入不会被旧操作覆盖。
- read_cold_source_backup(cold_source_backup.py:23)读取实际 tar 成员、嵌入/外部 source map 和同一个打开文件的前后哈希。它只见证 Host IO;不解包、不停止 Host,也不决定迁移资格。runtime_shadow 只有显式冷导入才读取完整 active/archive 记录,原 capture 默认分支保留。
- _storage_import(goal_storage_api.py:101)只接受注册 Goal、精确 body 和不透明标识,使用原备份 owner;浏览器不能指定 source/plan 路径。调用同一 typed effect 后独立读取当前存储,HTTP 只返回公开字段,异常路径和来源内容不外泄。configuration_api 注册三条同源路由。
- GoalStorageSettings(goal-storage-settings.tsx:8)复用现有设置、缓存、in-flight 和 generation guard。冷 Goal 必须明确选择策略,备份后显示包含归档的盘点;重载重置确认。结果把原导入回执与当前存储分开,失响应保留原 carrier。EN/ZH 文案也将上方 ownership 的 CLI 指引改为下方真实入口。
- 既有 cli_runtime 选择分发、Goal resolver、legacy fence decoder 和 bulk transport 被复用;生成的 registry IO census 只更新位置。合法冷 CLI 在四个旧 producer 物理缺席时可运行,错误参数仍保留完整解析器的兼容诊断。有实际调用方的 feedback prose-write guard 保留,未因删除目标而丢掉保护规则。
对主干的风险
最强反例是页面重载偷偷完成已 fence 的操作,或恢复把丢失的已完成存储重建并抹掉新数据。新增只读 pending-fence 负例验证 head/marker 都不产生;corrupt marker 与 lost completed target 明确拒绝。实际 App 中先改变来源,确认得到 source_changed_retry;恢复审核来源后,真实提交成功再故意丢弃响应,页面保留原操作,随后核验原回执和当前 SQLite。网络故障是测试注入,提交与读回使用真实后端,没有用 mock 提供待证明的 postcondition。
当前 source CLI/HTTP/ownership 29 passed,runtime/census 9 passed,独立安装 wheel CLI/HTTP 13 passed,typed cold transaction 14 passed。TS 全量 4259 passed、0 failed、32 个原有 PostgreSQL 环境 skips;此次只支持 File/SQLite 且没有修改共享 PostgreSQL provider,不把 skips 当通过。原 canonical HTTP 的 8 个用例在固定 main 基线 fac40bb 和本 head 都通过,覆盖无自动迁移、来源冲突、原回执和后续写入。packaged App 的 EN/ZH、390px 视图及恢复交互已检查,未切活动 Goal。
当前 control-plane/dashboard typecheck、mypy19、changed Python Ruff、manifest290、semantic 和 public boundary 通过;最终原生 premerge 5 direct +19 selected 全通过,无 failure/manual hold。旧 capture 的不可变 base/head 默认输出对照、42 记录和 archive-omission mutation 保留其原执行版本;涉及的 codec/fence/default 分支经本轮改动检查,新的 App 分支另有当前 real-path 证据。没有读取、轮询或等待远程 CI。
较早 HTTP str/Path 错误在 IO adapter 修复,原断言不变后通过;第一次 premerge 选到缺 pytest 的全局解释器,按源码规则用 uv run --extra test 重跑通过。此前 digest owner、consumer 注册、路径 alias 和 producer-loading 的失败证据保留。当前通过不等于整个 Goal 的恢复、实际 Host 停止、App producer-free loading 或所有平台均已验收;Windows/Lark/PostgreSQL 冷导入没有资格结论。应用后的 durable fence 不会因二进制降级而撤销,必须保留支持的原操作恢复和另行验收的历史恢复路径。
语义与 CI 对齐
已有 coordination/fence/full-record/receipt vocabularies 被复用,冷操作新增的是同一请求的本地 readback action;没有第二个 Python 状态决策源或新的跨域状态词汇。所有准入以 typed schema/transition 为依据,不靠 prose substring。diff-scoped advisory 在全树语义检查前执行,其 unsupported/dynamic 限制没有被当作语义等价证明。备份/身份/确认是机器前置条件,实际 Host 停写是操作人义务,两者没有混称 guidance;默认存储与普通 capture 行为没有暗改。
我的整体评价
本轮重新判断整个 PR,结论是 justified_increment;long_horizon improved,因为重复执行和重启持续使用原操作且保留后续写入;user_experience improved,因为 App 用户已有完整备份预览、必要确认、错误纠正与只读恢复路径。相对 CLI-only 的阶段,App 伴随改动有明确现用调用方,未新建配置开关、第二个导入器或抽象框架。未来方向的窄重构已应用:共用 completion marker 校验、原事务的只读分支和既有缓存。原 writer 的有价值保护与持久化恢复义务继续保留。
没有本阶段的阻塞发现,APPROVE 可用的 CLI/App 阶段。原 R5/T4 的 Host、完整历史、App 加载独立性和最后 caller 截止继续由既有 owner 承接,不能据此宣布默认 SQLite 或全面退役。此评审是作者账号 COMMENTED 结论,并非 GitHub formal approval 或合并授权;运行时/App 变更留给维护者合并。
…ort-r128 Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
|
This pull request has merge conflicts with Choose the remote for the base repository, not an out-of-date fork. git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEADFor a same-repository clone whose Keep the DCO |
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Exact head: d899a10
English verdict: APPROVE - HEAD d899a10; the backed-up CLI/App cold-import stage has real File/SQLite, original-operation and packaged UI evidence. The actual operator-led POSIX Host/native lease path passes; automatic shutdown, outbox/history/cutoff acceptance remains open. COMMENTED author review; maintainer merge required.
动机
持有尚未导入 canonical 的 Markdown Goal、准备停止旧写入路径的维护者会遇到这个问题。
以前 App 只能把旧 Markdown Goal 指向 CLI 晋升;现在可在现有 Goal 数据存储设置中备份、盘点、选择执行策略并确认导入 File/SQLite。
已验证 active/archive Todo 进入协调存储,页面重载保留原操作但重置确认,来源变化拒绝,导入成功后丢失响应仍能读回原回执和当前存储。 已用真实 owned Host、原生源租约和独立 wheel 验证:进程退出与租约结算分离,过期 active 仍拒绝,原生释放后旧 grant 在实际 Host 启动前拒绝。
本批不宣布新 Goal 默认 SQLite,不删除最后 writer,不宣称整个 Goal 历史恢复或自动停止 Host。
pending outbox 的原生逐项处置、完整 Goal 历史与备份恢复,以及 App 在旧正常 writer 物理缺席时的加载仍未验收,继续由现有 R5/T4 承接。
改动思路
在既有 TS coordination owner 中复用迁移、锁、provider 身份、fence 和原回执;Python 负责备份/HTTP IO,App 复用数据存储设置与原操作缓存,没有第二个导入决策源。
本 PR 交付可用的 CLI/App 冷源导入、只读恢复及 POSIX 人工停写的真实进程/原生租约验证;自动发现/停止 Host、live 模型、完整历史和 App 旧 writer 缺席仍由原验收承接,writer cutoff 前必须通过。
不修改现有 shadow 晋升的操作数量资格,也不伪造捕获历史。冷导入需要自己的来源检查和持久化操作,但提交和原回执读回沿用现有 owner。备份预览产生可审核的来源身份,执行策略是用户选择,停写确认是操作人声明;文件锁不能证明 Host 已停止。App 只缓存 Goal/operation/hash 三个标识,重新打开页面会重置确认并只读原操作;只有再次明确确认才可能执行。既有 canonical provider 切换保持其原始 carrier 和读回路径。
具体改动
Accepted pre-change basis: docs/reference/local-authority-provider-selection.md at 0e5acfe. 以下逐项保留原验收,而不是用本次文档修改重新定义通过:
- Inventory and back up the complete supported source:协调来源的完整 active/archive Todo、metadata 和实际归档字节已覆盖;完整 Goal 历史恢复仍 deferred,结果明确 complete_goal_backup_verified=false。
- Stop source writers and affected Hosts:stop attestation 和 unsafe/unsettled lease、capture/outbox 拒绝已实现;POSIX 人工停止真实 owned Host、原生释放租约、切换后旧 grant 重启拒绝已通过;自动发现/停止、live 模型和 pending outbox 逐项处置仍 deferred。
- Preview an immutable source/target-bound plan:implemented;目标 provider/identity、来源字节、备份成员和原操作绑定,锁内复核后先 fence 再提交。
- Recover the same operation after interruption:CLI 协调事务的真实中断、后续写入和原回执恢复通过;App 只读重载和失响应恢复通过。完整验收仍 deferred,因为 App 在旧正常 writer 物理缺席时的加载和完整历史恢复尚未通过;物理缺席当前只证明 CLI。
- shared by CLI and App:implemented;真实 wheel CLI/HTTP 与 packaged App 复用同一 TS 冷导入 owner 和现有数据存储设置。
关键代码讲解
- executeColdSourceImport(cold_source_import.ts:179)拥有源/备份资格、不可变 carrier、目标身份、fence 和原回执。新增 readback 分支只读:已 fence 但尚未提交时返回 prepared,不创建 head 或完成 marker;已完成但目标消失或 marker 被损坏时拒绝重新播种。完成路径复用 promotion_receipt,后续 canonical 写入不会被旧操作覆盖。
- read_cold_source_backup(cold_source_backup.py:23)读取实际 tar 成员、嵌入/外部 source map 和同一个打开文件的前后哈希。它只见证 Host IO;不解包、不停止 Host,也不决定迁移资格。runtime_shadow 只有显式冷导入才读取完整 active/archive 记录,原 capture 默认分支保留。
- _storage_import(goal_storage_api.py:101)只接受注册 Goal、精确 body 和不透明标识,使用原备份 owner;浏览器不能指定 source/plan 路径。调用同一 typed effect 后独立读取当前存储,HTTP 只返回公开字段,异常路径和来源内容不外泄。configuration_api 注册三条同源路由。
- GoalStorageSettings(goal-storage-settings.tsx:8)复用现有设置、缓存、in-flight 和 generation guard。冷 Goal 必须明确选择策略,备份后显示包含归档的盘点;重载重置确认。结果把原导入回执与当前存储分开,失响应保留原 carrier。EN/ZH 文案也将上方 ownership 的 CLI 指引改为下方真实入口。
- 既有 cli_runtime 选择分发、Goal resolver、legacy fence decoder 和 bulk transport 被复用;生成的 registry IO census 只更新位置。合法冷 CLI 在四个旧 producer 物理缺席时可运行,错误参数仍保留完整解析器的兼容诊断。有实际调用方的 feedback prose-write guard 保留,未因删除目标而丢掉保护规则。
对主干的风险
最强反例是页面重载偷偷完成已 fence 的操作,或恢复把丢失的已完成存储重建并抹掉新数据。新增只读 pending-fence 负例验证 head/marker 都不产生;corrupt marker 与 lost completed target 明确拒绝。实际 App 中先改变来源,确认得到 source_changed_retry;恢复审核来源后,真实提交成功再故意丢弃响应,页面保留原操作,随后核验原回执和当前 SQLite。网络故障是测试注入,提交与读回使用真实后端,没有用 mock 提供待证明的 postcondition。
当前源码真实 Host/native lease 4 passed,canonical HTTP/runtime/census 17 passed;独立新 wheel 在 checkout 外以隔离解释器验证 package 来源,CLI9、HTTP4、真实 Host4 共17 passed。TS 全量4259 passed、0 failed、32个原有 PostgreSQL 环境 skips;本次只支持 File/SQLite,未改共享 PG provider,不把 skip 当通过。当前 control-plane typecheck、mypy19、changed Ruff、census290、full semantic、公私边界及 CQR42be9016 通过;native premerge5 direct+19 selected 全通过,无失败或 manual hold。当前 integrated main 是 b44b84f。
四个旧 producer 物理缺席的 CLI 恢复在新 wheel 继续通过;当前 App/生产源码与6099e08815891f92e4a5266d263c8d02d9533ae5逐路径 diff 为空,先前该精确版本的 packaged App EN/ZH、390px、source drift 与真实提交后响应丢失证据明确沿用该版本,不伪称 UI 本轮重跑。canonical HTTP8 在先前 main fac40bb 与6099对照通过,当前相同8例继续通过。更早默认 capture 完整输出对照、42记录/归档遗漏 mutation 保留原执行版本,本轮 full typed suite 重新覆盖受影响规则。没有读取、轮询或等待远程 CI。
新增真实 Host 负例不是勾选 checkbox:启动 owned supervisor+实际子进程,独立证明 PID 活着且 prepare 因未结算 lease 拒绝;停止后证明 PID 已不存在,但 active lease 仍拒绝。TTL真实到期也不算结算。原 owner/key/current-version 原生释放后才备份/prepare/apply,导入后完整 released lease 相等;旧 execution context 在 initial_proof 被 lease_inactive 拒绝,nested Host record=not_launched、marker不存在。proof CLI 本身运行并 drain,所以 aggregate=drained;首次测试把 aggregate误当实际 Host,断言失败已按既有 owner语义修正,生产没有改。此验证不证明自动 Host census或全部历史。
较早 HTTP str/Path 错误在 IO adapter 修复,原断言不变后通过;第一次 premerge 选到缺 pytest 的全局解释器,按源码规则用 uv run --extra test 重跑通过。此前 digest owner、consumer 注册、路径 alias 和 producer-loading 的失败证据保留。当前通过不等于整个 Goal 的恢复、自动 Host 停止、outbox 处置、App producer-free loading 或所有平台均已验收;Windows/Lark/PostgreSQL 冷导入没有资格结论。应用后的 durable fence 不会因二进制降级而撤销,必须保留支持的原操作恢复和另行验收的历史恢复路径。
语义与 CI 对齐
已有 coordination/fence/full-record/receipt vocabularies 被复用,冷操作新增的是同一请求的本地 readback action;没有第二个 Python 状态决策源或新的跨域状态词汇。所有准入以 typed schema/transition 为依据,不靠 prose substring。diff-scoped advisory 在全树语义检查前执行,其 unsupported/dynamic 限制没有被当作语义等价证明。备份/身份/确认及 released lease 是机器前置条件,实际 Host 停写是操作人义务;当前文档明确停进程与原生结算先于新备份/预览,过期和退出都不能冒充结算,两者没有混称 guidance;默认存储与普通 capture 行为没有暗改。
我的整体评价
本轮重新判断整个 PR,结论是 justified_increment;long_horizon improved,因为重复执行和重启持续使用原操作且保留后续写入;user_experience improved,因为 App 用户已有完整备份预览、必要确认、错误纠正与只读恢复路径。相对 CLI-only 的阶段,App 伴随改动有明确现用调用方,未新建配置开关、第二个导入器或抽象框架。未来方向的窄重构已应用:共用 completion marker 校验、原事务的只读分支和既有缓存。原 writer 的有价值保护与持久化恢复义务继续保留。
没有本阶段的阻塞发现,APPROVE 可用的 CLI/App 阶段。原 R5/T4 的自动/完整 Host 生命周期、outbox、完整历史、App 加载独立性和最后 caller 截止继续由既有 owner 承接,不能据此宣布默认 SQLite 或全面退役。此评审是作者账号 COMMENTED 结论,并非 GitHub formal approval 或合并授权;运行时/App 变更留给维护者合并。
Current future-facing pass: real process validation reuses the existing leased supervisor/native lease owner; automatic discovery registry was considered and deferred. The source stop/settle-before-backup sequence now has real rejection and restart evidence.
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Exact head: 5009c81
English verdict: APPROVE - HEAD 5009c81; the backed-up CLI/App cold-import stage has real File/SQLite, original-operation and packaged UI evidence. The actual operator-led POSIX Host/native lease path passes; automatic shutdown, outbox/history/cutoff acceptance remains open. COMMENTED author review; maintainer merge required.
动机
持有尚未导入 canonical 的 Markdown Goal、准备停止旧写入路径的维护者会遇到这个问题。
以前 App 只能把旧 Markdown Goal 指向 CLI 晋升;现在可在现有 Goal 数据存储设置中备份、盘点、选择执行策略并确认导入 File/SQLite。
已验证 active/archive Todo 进入协调存储,页面重载保留原操作但重置确认,来源变化拒绝,导入成功后丢失响应仍能读回原回执和当前存储。 已用真实 owned Host、原生源租约和独立 wheel 验证:进程退出与租约结算分离,过期 active 仍拒绝,原生释放后旧 grant 在实际 Host 启动前拒绝。
本批不宣布新 Goal 默认 SQLite,不删除最后 writer,不宣称整个 Goal 历史恢复或自动停止 Host。
pending outbox 的原生逐项处置、完整 Goal 历史与备份恢复,以及 App 在旧正常 writer 物理缺席时的加载仍未验收,继续由现有 R5/T4 承接。
改动思路
本轮重新核验整体 PR;相对上一版,整合 main 647e216,保留主干严格租约来源检查,删除冷盘点重复的文件检查。主干来源/完整备份边界与本 PR 阶段说明均保留。CLI/HTTP/Host/source-lease/census 51 项、独立 wheel 17 项、TS 全套 4266 通过/0失败/32原 PG 环境 skips,premerge 5+19 通过。App/transaction 文件没有改变,旧 UI 实路证据仍归原修订,新 wheel 的 HTTP/backend 已重跑。
在既有 TS coordination owner 中复用迁移、锁、provider 身份、fence 和原回执;Python 负责备份/HTTP IO,App 复用数据存储设置与原操作缓存,没有第二个导入决策源。
本 PR 交付可用的 CLI/App 冷源导入、只读恢复及 POSIX 人工停写的真实进程/原生租约验证;自动发现/停止 Host、live 模型、完整历史和 App 旧 writer 缺席仍由原验收承接,writer cutoff 前必须通过。
不修改现有 shadow 晋升的操作数量资格,也不伪造捕获历史。冷导入需要自己的来源检查和持久化操作,但提交和原回执读回沿用现有 owner。备份预览产生可审核的来源身份,执行策略是用户选择,停写确认是操作人声明;文件锁不能证明 Host 已停止。App 只缓存 Goal/operation/hash 三个标识,重新打开页面会重置确认并只读原操作;只有再次明确确认才可能执行。既有 canonical provider 切换保持其原始 carrier 和读回路径。
具体改动
Accepted pre-change basis: docs/reference/local-authority-provider-selection.md at 0e5acfe. 以下逐项保留原验收,而不是用本次文档修改重新定义通过:
- Inventory and back up the complete supported source:协调来源的完整 active/archive Todo、metadata 和实际归档字节已覆盖;完整 Goal 历史恢复仍 deferred,结果明确 complete_goal_backup_verified=false。
- Stop source writers and affected Hosts:stop attestation 和 unsafe/unsettled lease、capture/outbox 拒绝已实现;POSIX 人工停止真实 owned Host、原生释放租约、切换后旧 grant 重启拒绝已通过;自动发现/停止、live 模型和 pending outbox 逐项处置仍 deferred。
- Preview an immutable source/target-bound plan:implemented;目标 provider/identity、来源字节、备份成员和原操作绑定,锁内复核后先 fence 再提交。
- Recover the same operation after interruption:CLI 协调事务的真实中断、后续写入和原回执恢复通过;App 只读重载和失响应恢复通过。完整验收仍 deferred,因为 App 在旧正常 writer 物理缺席时的加载和完整历史恢复尚未通过;物理缺席当前只证明 CLI。
- shared by CLI and App:implemented;真实 wheel CLI/HTTP 与 packaged App 复用同一 TS 冷导入 owner 和现有数据存储设置。
关键代码讲解
- executeColdSourceImport(cold_source_import.ts:179)拥有源/备份资格、不可变 carrier、目标身份、fence 和原回执。新增 readback 分支只读:已 fence 但尚未提交时返回 prepared,不创建 head 或完成 marker;已完成但目标消失或 marker 被损坏时拒绝重新播种。完成路径复用 promotion_receipt,后续 canonical 写入不会被旧操作覆盖。
- read_cold_source_backup(cold_source_backup.py:23)读取实际 tar 成员、嵌入/外部 source map 和同一个打开文件的前后哈希。它只见证 Host IO;不解包、不停止 Host,也不决定迁移资格。runtime_shadow 只有显式冷导入才读取完整 active/archive 记录,原 capture 默认分支保留。
- _storage_import(goal_storage_api.py:101)只接受注册 Goal、精确 body 和不透明标识,使用原备份 owner;浏览器不能指定 source/plan 路径。调用同一 typed effect 后独立读取当前存储,HTTP 只返回公开字段,异常路径和来源内容不外泄。configuration_api 注册三条同源路由。
- GoalStorageSettings(goal-storage-settings.tsx:8)复用现有设置、缓存、in-flight 和 generation guard。冷 Goal 必须明确选择策略,备份后显示包含归档的盘点;重载重置确认。结果把原导入回执与当前存储分开,失响应保留原 carrier。EN/ZH 文案也将上方 ownership 的 CLI 指引改为下方真实入口。
- 既有 cli_runtime 选择分发、Goal resolver、legacy fence decoder 和 bulk transport 被复用;生成的 registry IO census 只更新位置。合法冷 CLI 在四个旧 producer 物理缺席时可运行,错误参数仍保留完整解析器的兼容诊断。有实际调用方的 feedback prose-write guard 保留,未因删除目标而丢掉保护规则。
对主干的风险
原生独立 peer 转交仍被 original source conversation unavailable 拒绝;这是另外的协作/合并门,作者自审不能代替独立复审。此评审不证明已经转交、独立验收或合并。初次 wheel 因前端包过期拒绝,重建后安装验证通过;误选不存在测试文件的首次 pytest 未执行测试,修正后的完整范围通过。
最强反例是页面重载偷偷完成已 fence 的操作,或恢复把丢失的已完成存储重建并抹掉新数据。新增只读 pending-fence 负例验证 head/marker 都不产生;corrupt marker 与 lost completed target 明确拒绝。实际 App 中先改变来源,确认得到 source_changed_retry;恢复审核来源后,真实提交成功再故意丢弃响应,页面保留原操作,随后核验原回执和当前 SQLite。网络故障是测试注入,提交与读回使用真实后端,没有用 mock 提供待证明的 postcondition。
当前源码真实 Host/native lease 4 passed,canonical HTTP/runtime/census 17 passed;独立新 wheel 在 checkout 外以隔离解释器验证 package 来源,CLI9、HTTP4、真实 Host4 共17 passed。TS 全量4259 passed、0 failed、32个原有 PostgreSQL 环境 skips;本次只支持 File/SQLite,未改共享 PG provider,不把 skip 当通过。当前 control-plane typecheck、mypy19、changed Ruff、census290、full semantic、公私边界及 CQR42be9016 通过;native premerge5 direct+19 selected 全通过,无失败或 manual hold。当前 integrated main 是 b44b84f。
四个旧 producer 物理缺席的 CLI 恢复在新 wheel 继续通过;当前 App/生产源码与6099e08815891f92e4a5266d263c8d02d9533ae5逐路径 diff 为空,先前该精确版本的 packaged App EN/ZH、390px、source drift 与真实提交后响应丢失证据明确沿用该版本,不伪称 UI 本轮重跑。canonical HTTP8 在先前 main fac40bb 与6099对照通过,当前相同8例继续通过。更早默认 capture 完整输出对照、42记录/归档遗漏 mutation 保留原执行版本,本轮 full typed suite 重新覆盖受影响规则。没有读取、轮询或等待远程 CI。
新增真实 Host 负例不是勾选 checkbox:启动 owned supervisor+实际子进程,独立证明 PID 活着且 prepare 因未结算 lease 拒绝;停止后证明 PID 已不存在,但 active lease 仍拒绝。TTL真实到期也不算结算。原 owner/key/current-version 原生释放后才备份/prepare/apply,导入后完整 released lease 相等;旧 execution context 在 initial_proof 被 lease_inactive 拒绝,nested Host record=not_launched、marker不存在。proof CLI 本身运行并 drain,所以 aggregate=drained;首次测试把 aggregate误当实际 Host,断言失败已按既有 owner语义修正,生产没有改。此验证不证明自动 Host census或全部历史。
较早 HTTP str/Path 错误在 IO adapter 修复,原断言不变后通过;第一次 premerge 选到缺 pytest 的全局解释器,按源码规则用 uv run --extra test 重跑通过。此前 digest owner、consumer 注册、路径 alias 和 producer-loading 的失败证据保留。当前通过不等于整个 Goal 的恢复、自动 Host 停止、outbox 处置、App producer-free loading 或所有平台均已验收;Windows/Lark/PostgreSQL 冷导入没有资格结论。应用后的 durable fence 不会因二进制降级而撤销,必须保留支持的原操作恢复和另行验收的历史恢复路径。
语义与 CI 对齐
已有 coordination/fence/full-record/receipt vocabularies 被复用,冷操作新增的是同一请求的本地 readback action;没有第二个 Python 状态决策源或新的跨域状态词汇。所有准入以 typed schema/transition 为依据,不靠 prose substring。diff-scoped advisory 在全树语义检查前执行,其 unsupported/dynamic 限制没有被当作语义等价证明。备份/身份/确认及 released lease 是机器前置条件,实际 Host 停写是操作人义务;当前文档明确停进程与原生结算先于新备份/预览,过期和退出都不能冒充结算,两者没有混称 guidance;默认存储与普通 capture 行为没有暗改。
我的整体评价
本轮重新判断整个 PR,结论是 justified_increment;long_horizon improved,因为重复执行和重启持续使用原操作且保留后续写入;user_experience improved,因为 App 用户已有完整备份预览、必要确认、错误纠正与只读恢复路径。相对 CLI-only 的阶段,App 伴随改动有明确现用调用方,未新建配置开关、第二个导入器或抽象框架。未来方向的窄重构已应用:共用 completion marker 校验、原事务的只读分支和既有缓存。原 writer 的有价值保护与持久化恢复义务继续保留。
没有本阶段的阻塞发现,APPROVE 可用的 CLI/App 阶段。原 R5/T4 的自动/完整 Host 生命周期、outbox、完整历史、App 加载独立性和最后 caller 截止继续由既有 owner 承接,不能据此宣布默认 SQLite 或全面退役。此评审是作者账号 COMMENTED 结论,并非 GitHub formal approval 或合并授权;运行时/App 变更留给维护者合并。
Current future-facing pass: real process validation reuses the existing leased supervisor/native lease owner; automatic discovery registry was considered and deferred. The source stop/settle-before-backup sequence now has real rejection and restart evidence.
|
This pull request has merge conflicts with Choose the remote for the base repository, not an out-of-date fork. git fetch upstream
git rebase upstream/main
# Resolve each conflict, git add the resolved files, then git rebase --continue.
git push --force-with-lease origin HEADFor a same-repository clone whose Keep the DCO |
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent; model=gpt-6.1-sol; provider=OpenAI; runtime_reported; reasoning_effort=xhigh.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval). Exact head 9a94b2e; integrated immutable main 20dd1a3. No blocking finding in this additive stage.
动机
持有尚未晋升的 Markdown Goal、准备停止旧写入路径的用户和维护者。
以前冷旧 Goal 必须先运行旧 writer 才能产生晋升所需的 capture;现在可以在现有数据存储设置中备份、盘点、选择 File/SQLite 与执行策略,再确认导入。
真实 CLI/App 已验证 active/archive Todo 导入、来源变化拒绝、页面重载重置确认,以及提交成功但响应丢失后读回同一原回执,避免重复导入或覆盖后续写入。
本批不改变新 Goal 发布默认,不删除最后旧 writer,不把协调源备份宣称为整个 Goal 历史恢复,也不自动关闭 Host。
完整 Goal 历史与备份恢复、pending outbox 的原生逐项处置,以及 App 在正常旧 writer 物理缺席时的加载仍沿既有 R5/T4 验收。
改动思路
复用既有 TS 事务、provider 解码和 App carrier;Python 只承担可信备份与 Host/HTTP I/O,避免第二个资格或恢复决策源。
当前交付可用的 CLI/App 协调源导入与原操作恢复;完整历史、outbox 处置和最后 writer 退役继续由原 R5/T4 验收。
Cold import supplies its own verified source/backup qualification; it does not weaken shadow counts or fabricate capture history. The existing Goal settings supplies the source and Goal. Storage/policy is actual intent, backup preview pins bytes, and stop confirmation attests the operator's current action. These steps keep one authority boundary; no separate importer screen or browser authority cache.
具体改动
全 PR 27 个文件 +1827/-35,包含 typed cold transaction、可信 tar byte adapter、已有 CLI/HTTP/App 入口、完整协调源回归及公开支持说明。本轮相对 5009 的修复合入 main 并保留双方 roadmap/source-safety 边界;修复空 SQLite 预览被误认成已晋升、外置 registry 原始字节没有进入备份的问题,补齐真实打包 App 两种目标的恢复测试。
关键代码讲解
- cold_source_import.ts:179 executeColdSourceImport 复用源盘点、handoff migration、provider、writer lock/fence 和原回执。apply 先核验全部冻结身份及源,再 fence 和提交;recover 读原操作,不能造新授权或覆盖后续写入。
- cold_source_inspection.ts:45 inspectColdCoordinationSource 复用 provider 解码和 existing-only head。预览合法创建的空 SQLite 仍可被盘点;已提交/fenced、丢失身份和损坏 selector 仍明确拒绝,绝不重建空库或回退 File。
- cold_source_backup.py:23 read_cold_source_backup 核对实际 tar/manifest 的成员和整包摘要;state_backup 的已有发现范围补进原始 registry,即使它不位于 .loopx。配置投影不能代替实际源字节。
- GoalStorageSettings:8 复用当前 opaque carrier/cache。预览、切换和重载重置停写确认;失响应时读原回执。测试把真实提交的响应丢掉,重载后 applyCount 仍为 1。
Accepted specification: docs/reference/local-authority-provider-selection.md at 20dd1a3, judged before this PR's documentation edits. Criterion dispositions:
- Inventory and back up the complete supported source — deferred full criterion. Coordination records and backed-up exact raw registry/source bytes verified; complete_goal_backup_verified=false. Whole Goal-history recovery stays R5/T4.
- Source lease JSON inventory is fail-closed — implemented; shared regular-file/link/inode/orphan-byte protections retained and real CLI/App refusal qualified.
- Stop source writers and affected Hosts — deferred full criterion. Real owned POSIX stop/native release/stale grant refusal verified; automatic discovery/live models and pending outbox reconciliation remain open.
- Preview an immutable source/target-bound plan — implemented through existing typed owner and CLI/App; source drift, no-confirm reload, lost identity and backup integrity tested.
- Recover the same operation after interruption — deferred full criterion. Actual CLI producer absence, File/SQLite original receipt and later-write recovery verified; App lost-response recovery verified, producer-free App loading/full history open.
- shared by CLI and App — implemented for this bounded coordination stage through existing settings and real native backend.
对主干的风险
最强集成反例不是伪造 hash,而是“单元 prepare 通过,但用户选择空 SQLite 后重载被错误挡住”,以及“常规仓库 registry 夹具掩盖外置 registry 未被备份”。本轮真实入口发现并修复两者。初次源码 95/1 和扩大范围 109/3 的失败记录保留;后者三项是损坏 selector 的拒绝原因兼容,最终全部受影响 48 项通过,未改旧断言。缺失/已提交/损坏 SQLite 的反方向仍 fail-closed。
验证:112 项源码选择中 109 项在最终原因码修复前已通过,最终受影响 48 项重验通过;独立安装的 fresh wheel17 通过;全 TS 4268 通过、0 失败、32 既有 PG 环境 skips,最终受影响 typed52 通过。配置 TS typecheck、mypy19 与单独 backup、Ruff、registry census290、语义检查和质量回执通过。真实打包 App EN/ZH、桌面/390px键盘、File/SQLite确认、readonly reload、expired-lease拒绝、unavailable恢复及提交失响应原回执读回通过。原生 premerge5 direct+19 selected全通过、无 manual hold。
当前 main 与 head 用同一 persisted fixture 在真实默认源 snapshot/legacy write_check 比较,完整输出相同;既有 canonical HTTP migration 路径也通过。原5009的 cold transaction/fence/CLI loading/source adapter blob与当前相同,旧 scope/42record/mutation事实仅按原 revision复用;本轮变化的inspection/backup/API/UI已重新验证。没有共享 PG provider语义重构,不宣称真实 PG server资格。
预合并曾因自选 TMPDIR 位于 Git 仓库内部,破坏“无 Git 仓库”测试前提。独立临时目录的 git probe 明确非仓库,同一未改 smoke 和整套 premerge通过。早期 browser wait/mobile navigation 和旧 bundle指纹问题也保留,正确 rebuild和真实新浏览器回归通过,未删除断言/放宽阈值。CI遵循当前 wait_for_ci=false,未查询、轮询或等待。
语义与 CI 对齐
启用范围是明确确认的一个 Goal,包含它未来的正常协调写入;其他当前/新 Goal 不自动启用。发现/help/backup/preview不授予 commit,停写 checkbox不绕过原生未结算 lease/outbox拒绝。旧 lease、history和receipt不授予新的 Host执行权限。通用 work/quota/settlement义务、auto-loaded prompt和新建默认未改。malformed selector原拒绝原因保留,registry备份是派生实际字节,provider marker不是晋升事实。
我的整体评价
没有本批阻塞发现。当前完整 head 的审查结论是 justified_increment,长期恢复与用户路径 improved;它交付可操作、可核验的阶段,不替代最后 writer 截止前的完整 R5/T4。复用既有 TS 事务、provider 解码和 App carrier;Python 只承担可信备份与 Host/HTTP I/O,避免第二个资格或恢复决策源。 当前交付可用的 CLI/App 协调源导入与原操作恢复;完整历史、outbox 处置和最后 writer 退役继续由原 R5/T4 验收。 未来重构审视已应用在 provider 分类和原始 registry backup归属上,未增加框架。正常 producer/feedback prose guard与受支持历史读者仍有价值,不能凭本批 CLI producer-free结果全删。
按用户原自合并请求和当前原生合并门继续;自审、readiness和消息排队本身不证明 MERGED 或送达。
English verdict: APPROVE — 9a94b2e. The current main integration, explicit CLI/App coordination import, opposite-direction refusal, original-operation recovery and feature-off parity are verified. Full Goal-history recovery, pending outbox disposition, producer-free App loading and release-default/writer retirement remain separately open.
Cold unpromoted Markdown Goals cannot qualify ordinary shadow promotion after their old writer stops. This adds an explicit backup-bound coordination import into an empty canonical File/SQLite target through the installed CLI and existing App Goal storage settings. The user reviews the full active/archive source, chooses storage and policy, confirms stopped writers, then imports and independently reads the original receipt. Restart and response-loss recovery keep the original operation and later canonical writes.
The TypeScript coordination owner reuses source projection, handoff migration, provider identity, locks, writer fences and promotion receipts. Python performs trusted tar, HTTP and Host I/O. This main integration also fixes two real App/backup defects: an empty SQLite target selected during preview was wrongly classified as already promoted; a registry outside .loopx was omitted from exact raw-source backup. Missing, malformed or committed selected authority still fails closed. The browser stores opaque operation identifiers, resets stop confirmation on reload and never automatically reapplies a completed import.
Delivery boundary
This is a usable additive CLI/App coordination stage of R5/T4. A verified coordination source archive is not a complete Goal-history backup. Operator stop confirmation does not automatically shut down Hosts. Real owned POSIX Host exit, active/expired native lease refusal, native release and stale-grant restart rejection are verified; automatic discovery/stop, live model sessions, pending outbox disposition, complete Goal-history recovery and App loading with normal legacy writers physically absent remain open. The selected CLI imports and recovers with four normal producer modules absent. Their other live callers and the valuable feedback prose-write guard remain. No release-default activation or final writer cutoff is claimed. Binary downgrade does not clear the durable fence.
Validation
Reviewed head: 9a94b2e; integrated main: 20dd1a3. Mutating checks use disposable synthetic Goals.
Earlier integration failures are retained in review evidence. Empty-preview and raw-registry defects were fixed; malformed-selector refusal compatibility was restored without weakening assertions. A premerge no-Git fixture initially inherited the repository through a nested temporary directory; the same unchanged smoke and full gate passed after a verified standalone temporary directory. Remote CI was not fetched, polled or awaited under the current policy.
Exact-head author-owned review: #6004 (review). The future-facing pass reuses existing provider-head classification and backup discovery instead of adding another decision owner. Complete source/history recovery and retirement acceptance stay separate.