Skip to content

refactor(todos): retire unused decision-scope scalar crossings - #5710

Merged
huangruiteng merged 2 commits into
mainfrom
codex/decision-scope-retirement-220616
Oct 6, 2026
Merged

huangruiteng merged 2 commits into
mainfrom
codex/decision-scope-retirement-220616

Conversation

@loopx-agent

@loopx-agent loopx-agent commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Goal And Delivered Outcome

Three scalar Python adapters still expose decision-scope RPC operations after production callers moved to the shared TS rule owner. The course also teaches the former Python implementation. Remove those unused crossings together, preserve the internal scope/exact-target rules and production combined operations, and make unsupported requests report request rejection instead of an internal failure.

Basis: accepted TS migration T4 and roadmap S2/S12; concrete last-caller retirement. Base: main.

Author Declaration

  • Written by: model_agent — OpenAI GPT-6.
  • Implemented against: docs/architecture/rfcs/typescript-control-plane-migration-v0.md, decision dependency consumer closure, and docs/reference/protocols/decision-scope-v0.md, at base 18241d3ab8126c147af62f7a91258958b0f243b3.
Criterion Disposition Owning boundary Decisive evidence
Delete last unused crossings without duplicating decisions implemented todos/decision_scope.py and .ts Tracked caller search; removed adapters absent in wheel; retired RPCs rejected
Retain typed scope, exact-target, owner and terminal rules implemented Existing TS decision-dependency owner Independent rule assertions and real File/SQLite gate rejection
Preserve real consumer and recovery behavior implemented Quota CLI and existing stores Installed selection, stale display, foreign owner/capability gates, migration/write/refresh/spend/replay/next Turn
Whole provider/default/upgrade qualification out_of_scope Existing authority program No change to provider selection, persistence or promotion

Scope And Continuation

Complete within this retirement scope. consistency, standing, combined relation, batch relations, fallback, and gate_scopes remain. covers, scope_relation, and exact_relation are removed internal operations; external code using those undocumented operations must use the combined owner. Input codecs, nullable/schema/cardinality checks, legacy writers and historical recovery remain. No new frontend/Lark/CLI journey or optional switch is introduced.

The larger default-provider/upgrade/writer program remains open. This slice is independently reversible and does not certify full Python retirement. Future-facing pass applied: narrowed the RPC result union, reused the existing request-error contract, replaced a self-derived batch expectation with independent expected states, and updated stale owner documentation.

Validation

  • 48 focused Python tests and 9 typed decision-scope tests passed at the proposed head. Full control-plane TS suite: 4065 passed, 0 failed; 31 PostgreSQL-dependent cases skipped without an isolated PostgreSQL URL (not counted as passes).
  • Repository control-plane typecheck and changed-Python Ruff checks passed.
  • A fresh wheel passed 18 isolated real CLI scenarios across legacy/File/SQLite; all 40 CLI subprocess receipts confirm installed package origin. Fixture setup also uses package-owned TS backends. Three retired RPC requests reject; two retained relation paths still diagnose exact-target conflicts.
  • Immutable base/head wheels ran the same 18 fixtures: 20 complete guard observations match after ephemeral fixture-root substitution only; the three retirement rejection oracles fail on the old baseline and pass at head. Six additional scope scenarios per arm, with 14 further CLI package receipts, preserve existing/new independent-subject fallback, refuse display-only escape, and restore work after real owner gate completion. Native Turn settlement remains mandatory.
  • Diff advisory found no supported new vocabulary carriers; the full semantic check is included in premerge.
  • Native exact-scope change-quality receipt verified (cqr_2462099bd30c2e98de27). Canary premerge passed all 19 selected checks, diff/compile/maintainability and public-boundary checks, with no failures or manual holds.
  • Initial test failures were repaired: empty fixture user queues, an assertion against an omitted consistent projection, and unsupported-operation error classification. The first wheel installation probe used an incorrect artifact version; the discovered 1.3.0 artifact was subsequently installed and verified.
  • PostgreSQL store integration: not required for this slice; no store, commit, provider routing or retained shared decision rule changes. Full App interaction and global default/upgrade acceptance were not tested here.
  • Merge hold: control-plane change; exact-head review and maintainer merge required.

UI And Shared-authority Fixture Impact

UI impact: none; course content only, no first-screen change. The wheel's frontend bundle builds, without claiming an interactive App journey.

Existing production-scale coordination fixture preserves conflicts beyond display limits. Real File/SQLite consumer arms and legacy selection were run; a three-arm promotion rehearsal is not applicable because this change does not promote authority or change runtime routing/compatibility projection.

Boundary Checklist

  • Public-safe code/docs/tests only; private state, paths, credentials and raw evidence excluded.
  • No benchmark launches or scoring changes.
  • One bounded last-caller retirement; DCO sign-off present.
  • Control-plane behavior is proposed for maintainer merge.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

对精确 head f574ec73fc0a7bdca7ee0e2993359ec87ea72686 的整项评审:未发现阻塞问题。公开变更与本地该 head 的完整 diff 一致;评审结论不授予合并权限。

动机

维护者在继续修改 Todo 决策依赖时,会遇到没有生产调用方的三个旧入口和失真的课程代码。
以前维护者容易沿课程中的 Python 示例继续扩展旧 scalar 入口;现在课程指向现有 TS owner,三个旧请求明确拒绝,仍被真实 CLI 使用的组合规则继续工作。
这次交付删除三个失去调用方的内部入口,并通过前后安装包的真实 CLI 对照确认准入、诊断、gate 恢复和结算没有漂移。
这次不完成 canonical SQLite 发布默认、整项 ownership/旧 writer 退役、全部 Python 删除或历史恢复验收。

这里的 RPC 是 Python 到现有 TS 规则的内部请求。删除失去调用方的请求,可避免后续维护继续围绕旧接口增加决策分支;没有测量或声称本批会加速日常 CLI。

改动思路

先从不可变基线搜索真实生产调用方,而不是把 Python 文件名当作删除理由。生产端仍由 global_todos.py 调用批量 relations,由 quota 的 stall/prepare/monitor 调用 consistency 或 gate scopes;user_completion.ts 仍直接使用 TS coverage 规则来消费批准范围。因此保留 TS 内部 decisionScopeCovers、decisionScopeRelation、exactTodoGateRelation 和组合 owner,以及 Python 输入 codec、结果 schema、nullable 和批量 cardinality 校验,只退役三个无生产调用方的外层 scalar 请求。

正向路径从安装包的真实 CLI 进入隔离 File/SQLite:ownership migration 保留 claim,未经 lease 的写入拒绝;取得原生 lease 后更新 Todo,独立读回持久状态,refresh 后按返回命令 spend,再次 spend 不重复扣账,迁移重放不回滚新增数据,释放 lease 后下一 Turn 继续。覆盖与一致性是只读判断,不产生批准、执行 lease 或外部副作用。

独立任务通过原生 scoped fallback 继续;它的 normal_delivery_allowed=false 与对应 interaction 的 delivery_allowed=true 并不矛盾。新任务用原生 Todo add 创建后验证,没有通过改 metadata 或绕过未结算 Turn 来制造可执行结果。

具体改动

接受的规格为 docs/architecture/rfcs/typescript-control-plane-migration-v0.md,固定 revision 18241d3ab8126c147af62f7a91258958b0f243b3,按这份修改前规格逐项判断:

  • Current delivery frontier (2026-10-02):implemented。核对最后调用方后删除已证明冗余的入口,保留历史失败与证据边界,不等待全部 Python 消失。
  • T4:implemented 的是其调用方盘点、冗余入口删除和保留必要 bridge 这一有界部分;不是宣告完整 writer 退役完成。仍有生产调用方的 TS 内部规则、Python codec 和历史格式恢复都保留。
  • D1–D3:out_of_scope。本 PR 没有改变 provider/store/writer/promotion,不能替代完整 durability/default cutover 资格。
  • Validation and stop rules for every card:implemented。完成独立正反例、基线/head 安装包对照、完整 TS suite/typecheck、受影响 Python/CLI 和风险 canary;未缩减复杂夹具或生产 authority。

关键代码讲解

  1. evaluateDecisionScope 删除 covers/scope_relation/exact_relation 三个分发分支并去掉 boolean 结果类型。六个活跃操作保留同一 envelope。未知操作复用既有 EffectRuntimeRequestError,真实运行时返回请求拒绝,避免把有意退役错误记成内部崩溃。
  2. todo_gate_relation 是保留的生产组合适配器,继续经 _facts、typed runtime 和 _optional_relation 处理 nullable、schema 与非法响应;删除邻近三个 helper 没有另建 Python 决策源。
  3. todoGateRelation 本体未变:scope 覆盖但 exact target 指向其它 Todo 时先产生 projection_repair_required,不会被 broad scope 抹平。组合、批量和批准消费仍需要它依赖的内部函数。

七个文件的其余内容也已检查:课程替换旧 Python 规则示例并明确一致性不等于批准/lease;协议披露六个保留操作和三个退役操作;Python boundary test 迁移旧断言并增加真实 RPC 拒绝;TS 批量期望改为独立的 state/id 常量;File/SQLite CLI 测试加入 canonical gate 与陈旧显示冲突。没有新模块、状态、公开 CLI 开关、可选 capability、安装指令或 UI 入口。

对主干的风险

最大风险是误删仍有价值的覆盖、精确目标或批准消费逻辑,以及验证子进程实际上导入源树而没有测试安装包。本批保留相关规则,并对每个 CLI 子进程验证 wheel 来源;fixture 的真实 TS provider 也来自对应安装包。两臂使用相同夹具,18 个场景各有 40 条来源回执;20 个完整 guard 观察(准入、诊断、interaction、work lane、remediation)只替换临时 fixture-root 路径后相等。新增六个 scope 场景各臂再有 14 条 CLI 来源回执,覆盖已有/新建独立任务、显示逃逸,以及实际 owner 批准后恢复执行。

三个“旧操作必须拒绝”的相同 oracle 在基线均以 DID NOT RAISE EffectRuntimeRejected 失败,在 head 均通过,证明它会捕获退役回归;保留的 relation/relations 对陈旧精确目标均继续返回修复要求。不能把三个旧入口拒绝本身当作 SQLite 默认、旧 writer 或历史恢复验收。

本地验证:48 个 Python 检查、9 个专项 TS 检查、完整 TS suite(ℹ tests 4096; ℹ pass 4065; ℹ fail 0; ℹ skipped 31)、typecheck、Ruff、CQR 有效,原生 premerge 19 项全部通过,premerge 无失败/skip/manual hold;完整 TS suite 有 31 项 PostgreSQL URL 相关 skip(未配置隔离服务器),未将它们记为通过。按 managed review 的 wait_for_ci=false 没有查询或等待远端 CI。首次 RPC probe 曾暴露 TypeError/internal-error 分类,最终复用原错误 owner 修复并由真实 RPC 复验;夹具初次缺 user queue/误判可选字段、baseline 构建 cwd/陈旧 frontend,以及 scoped fallback/未结算 Turn 的错误探测顺序均保留在证据中,合格对照使用当前契约,没有放宽断言或生产门禁。

语义与 CI 对齐

语义分类是 reuse_existing:缩小现有 transient operation 集合,复用已登记的 request error 和 relation vocabulary;没有新增 actor 生命周期、state 或 authority。开发 advisory 与完整语义 canary 均通过;advisory 不覆盖动态构造,不能替代调用方盘点与真实入口验证。共享错误仍是 goal-neutral 文案,机器拒绝没有被称作“建议”。本 PR 没有 opt-in/default-off 声称,相关 isolation 行经检查为 not_applicable。

我的整体评价

交付判断是 goal_achieved,限于本批完整的无调用方内部入口退役。long_horizon=preserved:相同安装路径下迁移、实际写入、一次结算、重试与下一 Turn 保留,独立/新建任务不会因 scoped gate 获得或失去无关权限。user_experience=preserved:没有新增操作步骤或默认值变更,实际 owner 决定可解除对应 gate 并由独立读回证明。

从机制成本看,本批削减三个 crossing 而不删除活跃规则,新增主要是独立边界验证和当前文档;比另建兼容 facade 或全量 Python 重写更小、可回退。未来重构检查已应用于错误分类、结果 union 和同源 oracle。残余风险是仓库外未登记动态调用者不能穷尽证明;完整 App、canonical SQLite 发布默认、全 writer/历史恢复和 durability 资格继续按各自退出条件推进。精确 head 新鲜读回不变时,本 PR 可交维护者合并。

English verdict: APPROVE - Retire only the three unused internal scalar crossings; preserve the existing typed rules, codecs, authority boundaries and installed CLI settlement behavior at f574ec73fc0a7bdca7ee0e2993359ec87ea72686. Broader default/writer qualification remains separate.

@huangruiteng
huangruiteng merged commit 4c42b4b into main Oct 6, 2026
5 of 7 checks passed
@huangruiteng
huangruiteng deleted the codex/decision-scope-retirement-220616 branch October 6, 2026 05:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants