Skip to content

feat(coordination): default new Goals to canonical SQLite - #5805

Merged
huangruiteng merged 1 commit into
mainfrom
codex/sqlite-default-release-qualification
Oct 6, 2026
Merged

huangruiteng merged 1 commit into
mainfrom
codex/sqlite-default-release-qualification

Conversation

@loopx-agent

@loopx-agent loopx-agent commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

Goal And Delivered Outcome

Unconfigured new Goals currently use target-only File defaults. This candidate makes CLI and packaged App creation use canonical SQLite with hard_lease, through the existing configuration and TypeScript initialization owners. Explicit v0/v1 choices, creation-off, existing Goals and original-operation retries keep their route.

Basis: shared Goal authority RFC, R5/L9; base main.

Author Declaration

  • Written by: model_agent, GPT-6, OpenAI.
  • Specification: docs/architecture/rfcs/shared-goal-authority-state-provider-v0.md, L9 at 22d59bcf524bb4f0e3ed0761400194b2f9798b00.
Criterion Disposition Implementation Evidence
New-Goal default and settings/readback implemented goal_storage, existing TS creation, guided editor CLI/wheel and packaged App creation/configuration
Explicit choices and frozen existing route implemented registered v0/v1 shapes and editor compatibility creation/retry/negative matrix
L8/D3 integrated upgrade, D2 sustained/platform qualification deferred existing RFC gates retained candidate evidence does not certify release activation
Last-caller writer retirement out_of_scope existing writers/recovery readers retained creation-default change does not migrate their callers

Scope And Continuation

Default changes only unconfigured future creation. Settings reads the same registered default; v0 stays creation-off during guided/JSON conversion. Malformed configuration, a directory or broken symlink fails before Goal publication. Bootstrap compares resolved runtime locations, fixing a canonical workspace's relative-path false migration rejection.

This is an independently reversible candidate, not a release, global installation or forced migration. Integrated upgrade/reverse-cutover and sustained/platform qualification remain with existing RFC acceptance. The related simplification removes the absent-setting branch; no parallel Python decision owner or speculative framework is added.

Validation

  • Tested source owners: 0830ae10ba9cb2be92b17772bcfe027345ef76bf. Earlier runs cover identical owners before the final broken-symlink guard; that final guard was tested in source and a rebuilt, isolated wheel. Subsequent baseline merges touched unrelated tests/chat code.
  • Run state: finished. Inputs: synthetic, public_fixture.
Check kind Result Evidence / limitation
regression_parity passed Default characterization failed before the change; source creation/handoff matrix: 79 passed. Final malformed-config negatives: 4 passed; configuration contract: 11 passed.
integration passed TS real File/SQLite creation: 10 passed; machine config/API/lifecycle companion: 55 passed.
integration passed Native diff-selected premerge canary: 8 catalog checks + 8 risk-profile checks, direct compile/diff/module checks and public-boundary scan; no failures/skips/manual holds.
static passed Dashboard typecheck, configuration editor smoke, chat bundle build, semantic inventory/advisory, explicit-path public scan and diff check.
real_entrypoint passed Fresh candidate wheel: 49 passed, 2 source-only promotion tests excluded; final wheel negatives: 4 passed. Seven owning files match source hashes.
real_backend passed Isolated SQLite: App preview/confirm/create, injected initialization failure and original retry, settings preview/apply/remove/readback, complete Todo metadata, native quota→refresh→spend and settled guard.
real_backend passed Native archive restore/audit to isolated SQLite and File: all five commits, complete projection/newer writes and original creation receipt match. No active cutover.
manual not_run Live model execution, Lark accounts/consumers, English interactive walkthrough, D2 soak/platform and full existing-Goal migration.

Earlier fixture failures were resolved: a non-Git App fixture lacked workspace admission; a copied source package shadowed the wheel; a relative-runtime false migration rejection needed the production fix. Failed attempts are retained in private evidence. Successful App recovery uses the real owning backend with model execution disabled. No live Goal was corrupted or promoted to test recovery.

Frontend / Visual Evidence

Existing Settings surface; no layout/navigation change. Source data: synthetic.

Before: released target-only editor.

After: retained v0, SQLite default and removal readback.

Desktop creation and recovery plus narrow settings inspection were exercised. Existing preview/revision checks and one-step retry remain. The viewport adds no panel: the same provider/creation/policy controls disclose the default and opt-out; readback distinguishes saved preference from migration.

Type / Area

  • Feature / bug fix / documentation / tests
  • Control plane, machine capability and existing dashboard settings

Shared-authority RFC fixture impact

No production-scale schema or provider transaction rule changes. Real File/SQLite creation and archive restore use existing contracts. PostgreSQL and the legacy/file/PostgreSQL promotion rehearsal were not run: no promotion, service routing or compatibility projection is changed; existing-Goal qualification remains deferred.

Boundary Checklist

  • No private state, raw logs, credentials, internal links or host-local paths in public scope.
  • Scoped to R5/L9 candidate; existing retirement work is retained.
  • Visual evidence uses isolated synthetic data.
  • Signed-off commit; maintainer merge required for this control-plane change.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent, gpt-6.1-sol, OpenAI, runtime_reported, reasoning_effort=xhigh.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

动机

APPROVE;未发现本候选范围的阻塞问题。首次通过 CLI 或 App 创建 Goal 的用户。以前未配置设备先手动设置存储;现在创建即可使用 SQLite 权威存储,后续重试仍保持原操作。CLI 与打包 App 已读回新建、设置、失败重试及原回执。本 PR 不迁移已有 Goal、不退役历史恢复代码,也不发布或全机激活。长期运行、平台资格与完整旧 Goal 升级仍需原 RFC 验收。

改动思路

同一配置 owner 已能表达该默认;补齐 CLI 缺省分支和 v0 表单投影即可,不需要新增迁移框架。 当前 PR 交付新建候选与恢复读回,发布激活和已有 Goal 整体迁移保持独立。 配置目录只给出设备默认,Python 负责读取和 Host IO,已有 TypeScript owner 解释旧选择与 canonical 创建,写入后以原始操作和回执恢复;表单只做 v0 的关闭投影。若只改默认值而忽略 CLI 缺省分支或表单回填,两个入口会分叉,且旧偏好可能被自动启用。当前改动保留原生预览/确认与 revision 校验,模型执行和观察器不会获得迁移权限。

具体改动

规范依据:docs/architecture/rfcs/shared-goal-authority-state-provider-v0.md,版本 22d59bcf524bb4f0e3ed0761400194b2f9798b00,按改动前的约定判断。L9:实现新建默认、显式选择和关闭说明;L8:完整旧 Goal 集成升级/回退延期,仍由既有资格流程验收;L6:长期/平台资格延期;T4:本次不退役 writer 或历史读回代码。新增 checkpoint 明确候选范围,未改写这些准入条件。

关键代码讲解

  • goal_storage_machine_configuration_namespace 将未配置未来新建的默认改为 SQLite/hard lease;new_goal_storage_target 复用这份注册配置,不新增 Python 判断源。
  • goalStorageEditorValue 按精确 v0 schema 投影 false,Settings 初始化和 JSON→表单两处使用它,已有 v0 和显式关闭不会继承新默认的 true。
  • read_machine_configuration 对目录及断链报错,合法缺省与损坏配置分开;bootstrap_project 按实际文件位置比较 runtime,修复相对路径被误判为 authority 移动。
  • 现有创建/恢复测试覆盖新默认与冻结目标,文档替换过时的 opt-in 叙述并提供合成截图。没有新 schema、CLI、journal、迁移框架或 agent 提示。

对主干的风险

主要风险是旧 v0 表单被自动启用、已有 Goal 被新默认改写,或者重试重建空库并丢失新增 Todo。原生分支保留冻结 target/operation,失败仍由原创建操作恢复,丢失已完成存储须备份恢复。目录/断链不会误当未配置。配对真实 CLI 在不可变 base 与 head 上运行五种输入,只有缺省默认发生预期变化;v0、显式关闭/启用与坏 JSON 的退出/持久化结果保持。

源码创建/交接矩阵 79 项通过,最终配置负例与 wheel 负例各 4 项,配置契约 11 项;真实 TS File/SQLite 创建 10 项、配置/API/生命周期 55 项通过。隔离 wheel 49 项通过、2 项仅源码晋升测试未在最小 wheel harness 中运行。打包 App 实测创建、失败→原卡重试、设置预览/应用/移除/读回;模型执行禁用,未操作真实账户。真实 SQLite 的 Todo 更新与 quota→refresh→spend 已结算;备份恢复到隔离 SQLite/File 后,完整投影、新写入和原创建回执逐字段相等,五个提交经 native audit 匹配。默认创建的前置失败、非 Git fixture、源包遮蔽 wheel 以及相对 runtime 回归均保留并由对应当前路径证据覆盖。

语义与 CI 对齐

复用既有 v0/v1 和执行策略词汇,精确 schema 判断替代缺省猜测,没有 substring 或业务专用义务。默认变化在中英文 Settings、参考文档与测试中披露;显式关闭保持 target-only,移除偏好恢复新默认。原生 exact-scope quality receipt 通过,diff-selected canary 的 17 项与 5 项直接检查通过,无失败/跳过/手动 hold;包含语义漂移、first-connect、Todo、quota wake 和公开边界。按本 Goal 当前契约不查询 CI;绿色本地检查也不授予自合并权限。

我的整体评价

这是 justified_increment:新建候选已得到真实入口和后续读回,完整发布/迁移资格仍独立。长期推进在此范围 preserved:创建后的 Todo 新写入、重启和原操作重试不丢失;同一 Turn 原生结算后停止重复准入。用户体验 improved:未配置新用户少一次强制设置;原预览/确认和重试入口保留,显式关闭可读回。新增生产逻辑局限在已有 owner;相关简化已移除缺省特殊分支,保留持久化 v0/回执兼容的价值,未以减少 Python 行数为由删除恢复能力。

最强未测项是 D2 长期/平台与 L8 整体升级、live model/Lark;这些是发布激活的独立边界,不能用本 PR 的创建成功替代。运行时变更交维护者合并,当前 head 无阻塞发现,后续修改须重新核验。

English verdict: APPROVE - HEAD 0830ae1; candidate default and retained choices validated through real CLI/App/SQLite and archive recovery; sustained release and existing-Goal qualification remain separate.

@huangruiteng
huangruiteng merged commit 3a1a92e into main Oct 6, 2026
9 checks passed
@huangruiteng
huangruiteng deleted the codex/sqlite-default-release-qualification branch October 6, 2026 19:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants