Repository navigation
fix(todos): bind route-replan facts to typed succession evidence - #5831
Conversation
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
English verdict: APPROVE - 35b0f33. No blocking finding. Independent installed baseline/head CLI probes show six stale route-fact reads accepted before and rejected now, with fresh-read recovery and unchanged legacy/File/SQLite providers. Legal parity, source/TS tests and exact-head canary pass. Maintainer merge required.
动机
使用 Todo 查询、状态和 quota 摘要的操作者会遇到这个问题。
完整来源已经求值后,若 handoff 文本或重规划标记被改动,旧版仍接受筛选结果;本次改为拒绝旧证据,并允许重新读取原始来源后继续。
已验证真实安装态 CLI 拒绝两类陈旧事实,重新读取后仍保留 handoff 阻塞状态和正确建议。
本批只处理读取证据和重复决策,不改变 provider 默认、writer、lease 或结算权限。
SQLite 默认发布资格、完整 writer 退役和持续运行质量仍未闭合。
改动思路
用既有 TS 求值器绑定建议与完整来源,比保留 Python 决策再增加同步规则更简单;本批只改变读取证据,不引入新的持久化状态或运行权限。
当前 PR 的边界是 route-replan 证据新鲜度与重复 Python 决策退役,历史 IO 和整个默认切换验收继续保留。
先从完整 Todo 来源产生一次带来源哈希的求值,再由同一 TS 请求验证筛选后的摘要。改变 route 文本或明确布尔值会使旧证据失配;正确恢复是重新读取完整来源,既不会采用旧快照,也不会产生 writer 或重复结算。显式 false 优先于历史提示,完成、延后与原始 done 的既有语义保留。原 handoff 状态机仍独立检查后继和排除身份,重规划建议不能解除其阻塞。
具体改动
规格:docs/reference/todo-work-counts.md,基线 da45cfe771e96d20b9c5129a021a8c971ee03324。对已接受条款的映射:full-source succession evidence implemented,route 输入和摘要均绑定求值;read-only observations implemented,建议不授予收尾权限;legacy and promoted Goals implemented,三个实际来源经安装态同输入比较。较大 T4/writer/default 退出条件继续保留,不能由本 PR 的通过替代。
关键代码讲解
succession.ts:71 routeReplanRequired接受已有 bool/null 与历史 label,保留明确 false 优先及旧提示的有限用途;policy 从 Python 移到既有 owner。succession.ts:122 validateTodoSuccession把 route 输入纳入原来源哈希,另外检查返回建议与规则一致,拒绝伪造求值。原后继证据与 handoff 状态机保持。summary_projection.ts:54 validateSummarySuccession校验摘要 replan 与同一次求值一致,摘要不能改写 closure 前的判断。succession_warning.py:159 succession_facts只携带原事实,普通项和已有明确标记的项不发送旧文本;handoff_gate.py和todo_summary.py删除重复判断及求摘要前的 handoff 重建。
内部 JSON positional wire 与 Python/TS 一起部署并校验完整列顺序,不新增 RPC、持久字段或平行版本决策。四个测试文件分别保护旧行为、变更后证据、伪造摘要和真实 provider readback;双语 reference 说明拒绝边界与兼容性。6 个生产文件 +46/-28,测试 +96/-5、文档 +13;新增代码服务已存在的调用路径。
对主干的风险
无阻塞发现。保留的历史词语匹配可能误报建议,明确布尔值可覆盖;它不能证明后继、授权执行或解除 gate,因此没有把旧文本扩大为业务 authority。共同部署 wire 的不匹配失败应通过匹配版本包恢复,既有 Todo、备份、回执和 Markdown writer 不受删除影响。
我用独立安装的基线/候选 wheel 进入真实 CLI,在求值后、筛选前分别变更文本与标记:三个 provider 共六例,基线全部 exit0 接受,候选全部 exit1 报 matching full-source。随后三个来源的普通 fresh read 都恢复建议 true/gate blocking,来源和 provider 没有改变。此故障注入仅修改进程内测试事实,真实 Node、CLI 和存储路径没有被 mock;不能由此外推模型质量或长期运行验收。
安装态公共 fixture 基线13通过/2预期失败,候选15通过;真实5000条 File/SQLite查询覆盖新 wire 的容量边界。源码68项相关 Python、完整 provider 模块8项、TS35项及 mypy/typecheck/Ruff 通过;exact-head 原生 canary 的10项目录、8项风险检查和公开边界均通过。初次合成 fixture、compact字段假设与旧生成 bundle 的失败已保留,最终用独立 wheel 和完整真实查询重新验证,未放宽产品拒绝规则。
语义与 CI 对齐
复用既有 vocabulary 与 owner;差分 advisory 无受支持新 vocabulary carrier,全树语义检查通过。行为变化是 stale route 证据被拒绝,双语文档及 before/after 已披露,provider 默认没有改动。按照本次 review packet,GitHub CI 不查询、不等待;本地仓库检查为决定性证据。#5825 的 terminal witness 校验与本批共享 owner、处理不同缺口;若它先合并须复核集成。PostgreSQL存储、Windows、完整App交互、模型和持续负载未在本批验收。
我的整体评价
justified_increment:已完成可独立验证和回滚的读取修复及一处 Python 决策退役,完整 writer/default 项目仍开放。long_horizon=preserved,新拒绝有已执行的 fresh-read 恢复路径且不添加循环或结算状态;user_experience=improved,同一 CLI 给出明确错误和原读取恢复,不新增设置、确认或重录资料。architecture=retain、范围=proportionate;删除重复知识比增加第二个规则 owner 更易维护。保留仍有价值的历史 IO、格式与 Host 边界;没有用行数或测试数量宣称完整 SQLite 默认资格。审查整个 35b0f33ce3ced7d1c7196d42808686412364d3c8,通过后仍由 maintainer 合并。
…ute-facts Both read-correction descriptions stay: main's #5825 closure-witness validation and this branch's route-replan source binding. Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
loopx-agent
left a comment
There was a problem hiding this comment.
Reviewer: model_agent · gpt-6.1-sol · OpenAI · runtime_reported · xhigh
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
精确 head:b59064a98dd363676499f469693a2a9ee91ac44b;上一被批准 head:35b0f33ce3ced7d1c7196d42808686412364d3c8;当前 base:main(4905c3f2a 已并入)。
动机
筛选后的 Todo 摘要此前可能在 route 标记或历史 handoff 文本变化后继续复用旧的完整来源证据:那条 replan 判断在 Python 里单独求值,且不参与来源哈希,因此「求值后改动事实」不会被拒绝。本 head 把该判断收进既有 TS succession owner,并在摘要收口前拒绝过期或自相矛盾的 route 证据;同时按上一轮 review 的提示,重新核验了先合入的 #5825 在同一 owner 上的集成。
改动思路
先把当前主干并入(#5825 的 terminal witness 校验已经在 main 上)。冲突只有一处文档:两侧在同一位置各加了一段读取修正说明——主干是 #5825 的 quota closure witness 校验,本分支是 route-replan 证据绑定——因此两段都保留,不做取舍。生产代码的合并是纯增量的:相对 main,succession.ts 只新增 done/route_flag/legacy_route_label 三个事实与 routeReplanRequired,succession_wire_v1.json 只增加三列事实与一列求值(无删除),Python 侧删除重复判断、改由 TS 结果驱动,#5825 的 terminal witness 逻辑原样保留。
具体改动
11 文件、+155/−33。succession.ts 新增 routeReplanRequired(显式布尔优先,含 false;历史 label 只在仍为 handoff 且未终结时作为有界建议)并把它纳入 validateTodoSuccession,summary_projection.ts 校验摘要 replan 与同一次求值一致;succession_warning.py 只携带原事实并在有类型化标记时不再发送旧文本,handoff_gate.py/todo_summary.py 删除重复判断与求摘要前的 handoff 重建;wire v1 增加列;四个测试文件与双语文档同步。验证:tests/control_plane/test_succession_provider_readback.py、test_todo_succession_read_model.py 与 #5825 的 test_todo_closure_source_contract.py 合计 54 passed;TS todo_succession.test.ts、todo_summary_projection.test.ts、quota_selection.test.ts 全部通过;npm run typecheck:control-plane、改动文件 ruff、仓库配置的 19 文件 mypy、语义 vocabulary smoke 与公共边界扫描(67 文件)均通过;git diff --check 干净。
对主干的风险
行为变化是把「过期 route 证据」从静默接受改为拒绝,并保留显式 false、已完成/延后行为、owner 排除与后继语义;历史 label 只是有界重规划建议,不解除 gate、不证明后继、不授予执行权,也不能据此扩大业务 authority。与 #5825 的集成已按上一轮要求复核:同文件的 terminal witness 校验未被覆盖,wire 只增列,#5825 自己的测试在合并后的树上通过。内部 wire 与 Python/TS 需同版本部署,列不匹配时以匹配版本包恢复;既有 Todo、备份、回执与 Markdown writer 不受影响。未测量的部分与上一轮一致:PostgreSQL 存储、Windows、完整 App 交互、模型与持续负载不在本批范围。控制面合并资格仍由维护者决定。
我的整体评价
APPROVE:route-replan 判断回到唯一 TS owner,摘要与来源证据绑定且拒绝过期事实,Python 重复决策已退役;与已合入的 #5825 在同 owner 上共存且双方测试通过。
English verdict: APPROVE - b59064a. Current main (including #5825) is integrated: the merged wire only gains columns, #5825's terminal-witness validation is untouched, and the route-replan advisory now lives in the TS succession owner with stale or contradictory route evidence rejected before summary closure. 54 Python tests, the succession/summary/quota TypeScript suites, control-plane typecheck, ruff, the configured mypy set, the semantic smoke and the boundary scan pass.
Goal And Delivered Outcome
Filtered Todo summaries could reuse full-source succession evidence after a route flag or historical handoff label changed. Those replan facts were evaluated separately in Python and omitted from the source hash. This PR puts that advisory in the existing TS succession owner and rejects stale or contradictory route evidence before summary closure.
main.false, completed/deferred behavior, ownership exclusions and successor semantics.Author Declaration
docs/reference/todo-work-counts.mdfull-source evidence and closure boundary;docs/architecture/rfcs/typescript-control-plane-migration-v0.mdcontinuation readback/T4, baselineda45cfe771e96d20b9c5129a021a8c971ee03324.succession.ts; Python transports facts and renders resultsScope And Continuation
The internal columnar wire adds raw completion, optional route flag and historical label facts, plus one advisory result. It is co-deployed with Python/TS and validates exact column order; mismatched pairs fail explicitly. No persisted record schema, provider default, writer, lease, quota rule or configuration changes.
The historical substring hint remains compatibility-only: it cannot clear a handoff, supply a successor or authorize execution. Ordinary and explicitly flagged rows send no prose label. Python's duplicate decision and pre-summary handoff reconstruction are removed. Old writers, backup/format readers and original receipts remain supported; this deletion does not force existing Goals to upgrade. Reverting the matching package restores the prior read model without data migration.
The bounded future-facing pass is applied through the existing owner and fused request, with no new RPC or speculative abstraction. Further writer/hint retirement still requires its last real callers to migrate. This PR does not qualify SQLite release defaults or complete the larger retirement program.
Validation
35b0f33ce3ced7d1c7196d42808686412364d3c8; product bytes in the installed candidate match all six changed production files.test_todo_succession_read_model.pyroute cases andtest_succession_provider_readback.pyhistorical-route/large-Goal casesFrontend / Visual Evidence
UI impact: none. Existing status/Todo/quota projection consumers use the shared owner; no new caller capability, setting or visual asset. No new frontend/Lark journey is claimed.
Boundary Checklist
origin/main, explicit paths, DCO sign-off.