Skip to content

Commit 10ff24e

Browse files
committed
docs(todos): explain dated execution fences and wait repair
Signed-off-by: hyk <4408344+hhyykk@users.noreply.github.com>
1 parent a25de24 commit 10ff24e

2 files changed

Lines changed: 38 additions & 7 deletions

File tree

‎docs/reference/canonical-lease-renew.md‎

Lines changed: 33 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -281,7 +281,7 @@ renewal receipt schema, identity and digest encoding remain compatible.
281281

282282
For maintenance, `status=replayed` and `idempotent=true` return historical results even after a
283283
later renewal, transfer, release or expiry. They do not grant present execution
284-
rights or renew again. A newly pending or invalid canonical `todo_done` wait
284+
rights or renew again. A newly pending or invalid canonical `todo_done` or `resume_at` wait
285285
rejects renew/transfer retries as well as new requests; the original receipt is
286286
retained, and release remains available. Freeze the original request after a lost/ambiguous
287287
response; recover its receipt, then inspect current state before new work.
@@ -326,14 +326,18 @@ Switching away from `hard_lease` also invalidates atomic claim/acquire success.
326326
| `owner_conflicts_with_claim` | Current Todo ownership changed | Let the current owner continue or use an authorized handover. |
327327
| `canonical_acquire_readback_required` | History is known, current proof is unavailable | Restore the provider and retry the same operation. |
328328
| Acceptance/source rejection | Current control-plane authority changed | Resolve that boundary before attempting work. |
329-
| `todo_dependency_pending` / `todo_dependency_invalid` | The canonical completion prerequisite is unfinished or invalid | Complete the actual prerequisite, or repair the wait through its authorized Todo owner. |
329+
| `todo_dependency_pending` / `todo_dependency_invalid` | The canonical prerequisite is unfinished, the scheduled resume time has not arrived, or the condition is invalid | Complete the actual prerequisite, wait until the scheduled time, or repair the condition through its authorized Todo owner. |
330330

331331
For canonical File, SQLite and PostgreSQL Goals, `resume_when=todo_done:todo_prerequisite`
332-
now fences execution as well as runnable selection. The existing TypeScript resume
332+
and `resume_when=resume_at:<timezone-aware-rfc3339-timestamp>` fence execution as
333+
well as runnable selection. The existing TypeScript resume
333334
rule reads the exact prerequisite from the same provider head: its actual `done`
334335
status satisfies the wait, including retained archived completion. A cached
335336
`resume_ready=true`, an old acquisition receipt, or a superseded prerequisite
336337
cannot authorize execution. Missing targets and unfinished dependency cycles fail closed.
338+
Date waits use the operation's runtime-clock snapshot and become eligible at or
339+
after the scheduled instant. An old projected ready flag cannot replace that
340+
evaluation; reaching the time does not bypass the other authority checks.
337341

338342
While the wait is unsatisfied, standalone and atomic claim/acquire, renew/transfer,
339343
continuation adoption, Monitor execution and new completion reject it. Inspection
@@ -343,20 +347,42 @@ assignment and wait editing retain their existing authority. Other resume-condit
343347
their existing behavior; this repair does not introduce governed amendments.
344348

345349
Inspect the waiting task with `loopx todo list --goal-id example-goal --todo-id todo_work`.
346-
Complete its prerequisite through the normal validation and lease owner, then
350+
Complete its prerequisite through the normal validation and lease owner, or wait
351+
until its scheduled resume time, then
347352
read the same task again: `resume_ready=true` allows acquisition under the usual
348353
owner/key/version checks. If the wait itself needs correction, use the existing
349354
authorized `todo update --resume-when ...` or `--clear-resume-when` operation;
350355
neither inspecting nor editing the wait grants execution authority.
356+
In hard-lease mode, ordinary edits still need an active execution proof. After
357+
release or expiry, use the existing narrow owner pause/reopen lifecycle, with a
358+
stable operation id, current provider revision and explicit reason:
351359

352-
在 canonical File、SQLite 和 PostgreSQL Goal 中,`todo_done` 等待现在同时约束
360+
```bash
361+
loopx todo update --goal-id example-goal --todo-id todo_work --agent-id owner \
362+
--status blocked --clear-resume-when --reason 'Correct the scheduled wait' \
363+
--update-operation-id pause-wait --update-expected-provider-revision <readback-revision>
364+
loopx todo update --goal-id example-goal --todo-id todo_work --agent-id owner \
365+
--status open --clear-resume-when --reason 'Resume after correcting the wait' \
366+
--update-operation-id reopen-wait --update-expected-provider-revision <fresh-readback-revision>
367+
```
368+
369+
Read back between operations and acquire a fresh lease before executing. Do not
370+
attach an old lease proof or bundle ownership, text or work-requirement edits.
371+
372+
在 canonical File、SQLite 和 PostgreSQL Goal 中,`todo_done` 和 `resume_at` 等待同时约束
353373
实际执行入口,而不只是候选任务展示。必须由真实前置 Todo 的 `done` 状态满足条件,
354374
保留的已归档完成记录仍有效;缓存的 ready 标志、旧领取收据和 superseded 状态不能
355-
代替完成。等待期间,领取/原子认领、续租/转交、继续执行、Monitor 执行和新完成均
375+
代替完成。日期等待使用本次操作的 runtime-clock 快照,到达指定时刻后才满足条件;
376+
旧 ready 投影不能代替实时判断,到期也不跳过其他权限检查。
377+
等待期间,领取/原子认领、续租/转交、继续执行、Monitor 执行和新完成均
356378
被拒绝;新等待也会拒绝续租/转交的重试,原收据仍保留。检查保留原 lease 记录,
357379
但有效 `active=false`。释放、历史完成读回、授权 supersede、普通分配和等待修复
358-
沿用原规则。前置任务正常完成后,重新读回并按原 owner、key、
380+
沿用原规则。前置任务正常完成或到达指定恢复时刻后,重新读回并按原 owner、key、
359381
version 规则继续执行。其他恢复条件及 governed amendment 的边界保持独立。
382+
hard-lease 普通编辑仍须提供有效执行 proof。租约释放或到期后,可按上面的既有窄范围
383+
流程,以明确理由、稳定操作 ID 和当前 provider revision 暂停并清除等待;读回后再用
384+
新 revision 明确重新打开,最后领取新租约。不能附带旧 proof、文案、归属或工作要求修改,
385+
也不能把暂停或重新打开当作执行授权。
360386

361387
A successful readback is still a point-in-time proof, not a lock over subsequent
362388
external effects. Execution must retain its existing mutation fences; this

‎docs/reference/protocols/typed-date-resume-trigger-v0.md‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -56,6 +56,11 @@ same receipt and never increment the generation beyond `1`.
5656
- CLI authoring validates and reads back the canonical UTC token.
5757
- Status and quota keep a future Todo outside executable lanes. Other eligible
5858
work may continue according to the existing fallback policy.
59+
- Canonical execution admission evaluates the same typed condition against the
60+
operation's runtime-clock snapshot. Future waits reject new acquisition and
61+
completion, even when a cached projection or old lease receipt says ready.
62+
Lease release, authorized condition repair and historical terminal readback
63+
retain their existing authority; reaching the time does not grant a lease.
5964
- Once due, quota returns the existing `successor_replan_required` lifecycle
6065
action. A receipt is proof of the condition transition, not execution
6166
authority and not an implicit reopen.

0 commit comments

Comments
 (0)