Skip to content

fix(goals): serialize recreation with canonical writers - #5817

Merged
huangruiteng merged 1 commit into
loopx-project:mainfrom
Duang777:codex/fix-goal-recreation-canonical-race
Oct 6, 2026
Merged

huangruiteng merged 1 commit into
loopx-project:mainfrom
Duang777:codex/fix-goal-recreation-canonical-race

Conversation

@Duang777

@Duang777 Duang777 commented Oct 6, 2026

Copy link
Copy Markdown
Collaborator

Goal And Delivered Outcome

  • Outcome basis / optional anchor: Self-contained concurrency defect reproduced against the public source-session and canonical-authority contracts.
  • Goal/source and gap: Goal recreation held the source lifetime guard but not the canonical writer guard. An admitted Goal A update could pause before provider commit, Goal B could be published, and the old update could then commit through the same alias-addressed authority.
  • Observable before -> after, with the validation row that proves it: Removing the new guard makes the deterministic SQLite barrier regression fail because Goal B publishes while Goal A's update is paused. With the guard, recreation waits, the update commits first, and the registry then publishes Goal B.
  • Issue/task and intended base: No linked issue; intended base is main.

Author Declaration

  • Written by: OpenAI Codex agent, directed by the human operator.

Implemented against

  • Specification and revision: No written specification; the reproduced race and existing source-session/canonical-writer contracts at 332f6de00 are the basis.
  • Criteria:
Criterion (spec clause) Disposition Symbol / path Test or command
Goal B publication waits for every admitted canonical writer on Goal A implemented recreate_goal_instance test_goal_recreation_waits_for_an_admitted_canonical_update
Preserve the existing source-lock then maintenance-lock order implemented recreate_goal_instance source-session lifetime tests and standard premerge gate
Keep the registry I/O census current implemented project_registry_io_manifest_v1.json generate_project_registry_io_manifest.py --check
  • Self-check before submission: Read the source-session lifecycle, canonical writer lock, provider selection, and registry transaction paths. Verified the real SQLite commit boundary and reviewed the final three-file diff. Goal deletion remains outside this focused recreation fix.

Scope And Continuation

  • Completed scope and remaining work: Complete for recreation publication racing with an already admitted canonical writer. A separate deletion/alias-state audit is not bundled here.
  • Slice boundary / successor: N/A for this defect; deletion lifecycle behavior should be investigated independently if selected.

Validation

  • Tested revision: 254b3c0c7b23d9cfcbdddf9949d8c925e05e1876
  • Run state: finished
  • Input classes: synthetic, public_fixture
Check kind Result Public-safe evidence / limitation
regression_parity passed Deterministic real-SQLite barrier test fails with the production guard removed and passes with it restored.
integration passed pytest tests/control_plane/test_shadow_native_todo_update_e2e.py tests/cli_commands/test_source_session_lifetime.py -q: 47 passed.
unit passed node --test tests/control_plane_ts/source_session_lifetime.test.ts: 9 passed.
static passed Control-plane TypeScript typecheck, Ruff on changed Python, manifest check, compile check, and diff check passed.
integration passed loopx canary premerge --from-git-diff --git-diff-base upstream/main: 13/13 selected checks passed.
integration passed Before the final upstream rebase, the complete TypeScript control-plane suite passed 4,107 tests with 31 environment-dependent skips; exact-head targeted TS and premerge checks were rerun after rebase.
  • Coverage and gaps: The regression uses the public native update path, the real provider selector, real SQLite storage, the real recreation entrypoint, and a pause at the provider commit boundary. No external PostgreSQL service was available; the repaired maintenance lock is provider-neutral and precedes publication.

Frontend / Visual Evidence

  • UI impact: none
  • Before: N/A
  • After: N/A
  • States and viewports shown: N/A
  • Source data: none
  • Attention review: N/A; no UI changed.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Refactoring (no functional changes)
  • Documentation update
  • Test update

LoopX Area

  • Control plane (goals, todos, quota, scheduler, registry, runtime)
  • Benchmark boundary (adapters, runners, verifiers, scoring, evidence)
  • Capability or extension (providers, adapters, skills)
  • Public docs or presentation surface (README, protocols, dashboard)
  • Build, packaging, installer, or CI
  • Host or runtime integration

Technical Direction

  • Direction / acceptance reference, when applicable: Core control-plane hardening; source-session Goal lifetime and canonical authority consistency.

Shared-authority RFC fixture impact

  • Production-scale fixture schema: unchanged.
  • Semantic dimensions changed, or reviewed no-impact rationale: Goal recreation publication now shares the existing canonical maintenance exclusion boundary; no wire or provider schema changes.
  • Provider conformance arms run: File and SQLite paths in the focused E2E file; complete TypeScript provider suite before rebase; exact-head SQLite regression and source-session tests after rebase.
  • Read-only legacy/file/PostgreSQL three-arm rehearsal (required for promotion, runtime-routing, or compatibility-projection changes): N/A; this does not change promotion, routing, or compatibility projection.

Boundary Checklist

  • Neither the diff nor this PR body/comments/attachments disclose private state, credentials, raw traces or verifier output, internal links, or local machine paths (including .loopx/, .codex/goals/, and live ACTIVE_GOAL_STATE.md).
  • I did not duplicate maintainer-owned benchmark work unless a maintainer split out a public issue for it.
  • I kept the change scoped to the linked issue/task.
  • I completed the visual evidence section for UI changes, or marked UI impact none.
  • Every commit includes a DCO Signed-off-by trailer (git commit -s).

Signed-off-by: Duang777 <duangjl007@gmail.com>

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

动机

重建同名 Goal 的维护者,以及已经获准更新该 Goal 任务的 Agent。

任务写入已通过检查并停在提交前时,旧版允许维护者先把 Goal A 换成 B,随后旧写入落到复用地址;本版重建会等待旧写入提交再发布 B,无需操作者人工猜测写入是否结束。

独立真实 File 和 SQLite 对照均看到 head 等待→旧写入完成→发布新实例,之后旧 witness 被拒绝、同操作可重试、新实例能继续更新。

不改变执行权限、租约/CAS、默认provider或schema;不宣称 PostgreSQL/R6、全部实例激活、App/Lark 或长期业务验收完成。

M3整体激活、其它 effect owner与旧/热二进制覆盖仍按已有 RFC 保持未验;真实 PostgreSQL、App/Lark/host部署和长周期运行未在本批验证。

改动思路

复用现有 provider-neutral maintenance guard 和 Python跨runtime锁适配器;实例/重试决策仍由已有 TypeScript source-session owner决定。只在publication前串行化,不创建新权威、provider或可选策略。

本批修复 source_session_v1 重建与本机 canonical writer 的实际竞争;不交付完整 M3 激活、所有旧writer盘点或R6跨host服务资格。

完整审查三路径:runtime +27/-6;manifest +12/-4;测试 +114/-7。285个原registry I/O site的身份、策略和classification保持,新增一个真实codec读取、更新四处坐标。作者关于“无书面规范”的表述不作为依据:已先读基础版本的 Goal lifetime契约,按 local-recreation-drain(先排空已获准写入再发布)的约束判断;未将未来所有M3/R6义务变成本批全完成声明。

具体改动

精确 head 254b3c0c7b23d9cfcbdddf9949d8c925e05e1876,真实 merge-base 332f6de00fe7aa81a65c977ea25073ebf4954ce6。

  1. source_session_recreation.py:66 从project registry解析原runtime并定位已有maintenance地址。
  2. :281 仍由现有typed决策负责prepare/drain/replay;:389–405 先取得source lifetime锁,再取得canonical maintenance锁,锁内重验并发布registry、gate和journal。
  3. unchanged local_authority_write.ts:10 的Todo等canonical writer持有同一个锁直到实际provider commit;只做最后一次source hash检查不能替代这段串行化。
  4. 新SQLite barrier回归复用已有fixture与真实provider selector;另以独立File/SQLite、真实CLI和冻结B/H探针验证竞争与恢复,不以作者测试数量替代结论。

对主干的风险

最强风险是lock顺序反转或只是hash重读而保留check-to-commit空窗。本版复用source→maintenance顺序,并以真实提交暂停和独立基础对照核验。

同一冻结独立探针在真实 File/SQLite 和实际 CLI 上:B 两路均在旧 Todo 写入暂停提交时先发布 B;H 两路保留 A 并等待,释放写入后才发布 B。两版均拒绝旧 registry witness 的新操作、拒绝旧 instance 的新重建,允许同 operation 的历史重建幂等读回与当前 B 的后续新写入。未重建 Markdown 显示。

同两个现有 Python 文件 B46/H47通过;typed source-session suite B9/H9通过;Ruff、配置mypy19源文件、TS typecheck、diff advisory、全树semantic及风险premerge三直接检查和13选择项通过。独立真实File/SQLite并发、stale-witness拒绝、重复重建恢复、错误instance拒绝和B后续写入完成。

独立探针首次因其Node stdin迭代提前关闭而报BrokenPipeError;保留失败,改argv传入请求,未修改production或放松assert。相同修正后的探针在B两路仍确定性暴露原竞争,在H两路通过。实测旧witness新操作拒绝、错误instance新重建拒绝、同operation回放同实例、当前B继续写入;这区分了历史receipt读回与新执行许可。

我的整体评价

Verdict: APPROVE. 本机recreation/canonical-write竞争的独立可交付修复;problem_context: justified_increment。M3整体激活、其它 effect owner与旧/热二进制覆盖仍按已有 RFC 保持未验;真实 PostgreSQL、App/Lark/host部署和长周期运行未在本批验证。

未来变更检查:考虑了最近的typed lifecycle owner和维护锁地址。当前私有地址适配与existing guard复用已足够,无需另建capability、规则owner或广泛语言迁移;Goal删除/全部writer资格仍由既有lifetime inventory接续。

30秒production锁超时未实际等满;本机File/SQLite的真实commit、CLI重建与恢复已测。未运行真实PostgreSQL或App/Lark部署;该diff未改authority store实现、server-side事务或R6共享服务,不能用本机文件锁宣称远程资格。未查询、轮询或等待CI。合并权限与readiness另验,评审不授runtime自合并权。

English verdict: APPROVE for the bounded local recreation/write serialization repair at the exact head above. The immutable base reproduces publication before an admitted commit on both real File and SQLite providers; the head drains that commit before publication. Stale new operations reject, idempotent recreation replays, and a fresh successor operation continues. Broader activation, PostgreSQL service, host adoption and sustained-operation qualification remain unverified.

Reviewer: model_agent; model gpt-6.1-sol; provider OpenAI; reasoning xhigh; declaration source runtime_reported.

@huangruiteng
huangruiteng merged commit 5939670 into loopx-project:main Oct 6, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants