Skip to content

Commit 7cbc57a

Browse files
authored
Merge pull request #4351 from huangruiteng/codex/canonical-monitor-configuration
refactor(todos): canonicalize Monitor configuration and plan local defaults
2 parents 2b4c3cf + 89195a8 commit 7cbc57a

15 files changed

Lines changed: 538 additions & 98 deletions

‎docs/architecture/rfcs/shared-goal-authority-state-provider-v0.md‎

Lines changed: 61 additions & 23 deletions
Original file line numberDiff line numberDiff line change
@@ -2984,30 +2984,68 @@ independent legacy three-arm comparison or D2 soak.
29842984

29852985
#### Execution handoff and integration order
29862986

2987-
| Ready condition | Next action | What it does not authorize |
2987+
**Local-default delivery program (2026-09-14).** The outcome is a new local
2988+
Goal whose normal CLI, Turn and operator actions use one TS-owned canonical
2989+
transaction path, with Markdown as a permanent projection. An omitted selector
2990+
resolving to File is not this outcome: existing Goals still have a legacy
2991+
writer until an explicit whole-Goal cutover.
2992+
2993+
Qualify **one** long-lived local default profile. SQLite is the current D2
2994+
candidate; File remains the real reference/explicit profile and migration
2995+
rehearsal backend. Do not publish two ambiguous defaults, declare the current
2996+
File history layout long-horizon-qualified, or silently fall back from a
2997+
selected SQLite store. The final profile decision must cite its D2 evidence.
2998+
PostgreSQL shares the TS semantic contracts but has independent service,
2999+
tenant, restore and capacity qualification; its deployment must not delay the
3000+
local profile's work.
3001+
3002+
The reconciled baseline includes #4286 (command receipts/archive), #4289
3003+
(typed work/ownership intent), #4292 (declarative decision metadata), and #4304
3004+
(canonical handoff mode). Candidate #4316 closes Goal Channel observation;
3005+
#4317 unifies provider opening; #4348 adds canonical renew; #4328 is the first
3006+
SQLite D2 measurement/recovery batch. They are review candidates, not merged
3007+
prerequisites or proof of the full cards. #4334 is the independent PostgreSQL
3008+
service-admission candidate. Re-read actual heads before composing work; do
3009+
not carry their already-merged ancestors as new changes.
3010+
3011+
The identifiers below are **planned PR packages**, not reserved GitHub numbers.
3012+
A package may split at a real effect/compatibility boundary; changing languages
3013+
or moving a helper is not by itself a package exit.
3014+
3015+
| Wave / package | Reviewable delivery and TS ownership payoff | Dependencies and exit evidence |
29883016
| --- | --- | --- |
2989-
| Current refactor stack is reconciled | T1; D1 and D2 may proceed independently | Default provider changes or another generic migration framework |
2990-
| T1 closes field semantics | T2; close T3 consumers as their contracts become available | Per-command split authority within one Goal |
2991-
| T1–T3 and D1/D2 plus capture qualify | D3 rehearsal, then explicit promotion request | Skipping soak, bypassing failed evidence, or production promotion by the agent |
2992-
| Approved cutover and legacy window finish | T4 full-writer retirement | Deleting permanent Markdown presentation or historical receipts still needed for replay |
2993-
2994-
Expect roughly **five to seven cohesive implementation/qualification batches**
2995-
after reconciling the current stack, not a fixed PR quota: T1, T2, T3, D1, D2,
2996-
D3 and T4 can share a PR only when their dependencies, review and rollback
2997-
remain clear. Semantic deletion starts in T1; full legacy-writer deletion waits
2998-
for D3/T4. Elapsed-time soak is separate and is not shortened by splitting PRs.
2999-
3000-
For each handoff, record the exact base/head, selected card, actual callers
3001-
removed, changed authority/observable semantics, real-backend results, remaining
3002-
holds and one next executable action. If an earlier stage already landed,
3003-
verify its evidence and skip its implementation; if prerequisites fail, stop
3004-
that dependent stage. Do not turn hypothetical post-merge readiness into an
3005-
automatic promotion, automation, merge or release permission.
3006-
3007-
The current default and Appendix C promotion holds remain unchanged. This plan
3008-
does not declare the whole Todo family, long-goal profile, or shared deployment
3009-
production-ready. Providers keep CAS/transactions durable; they never own a
3010-
second Todo state machine.
3017+
| A / L1: Monitor configuration (this slice) | Existing `todo update` config enters the TS planner/CAS/receipt; delete Python's duplicate intent field catalog. Separate authoring from observed hashes, times and generations. | Ordinary CLI/API, clear/omission, active lease proof, no-op/replay, failed display delivery, complete fixture and real providers. This does not complete delegated Chat or leased polling. |
3018+
| A / L2: Complete public mutation admission | Inventory actual CLI/Turn/Chat callers; close remaining effect-owned user decisions, delegated owner actions and Monitor lifecycle transitions with validated actor/grant facts. | Build on merged T1 owners, not a generic raw patch. Prove permission rejection and exact caller response; remove replaced Python admission and name every remaining unsupported command. |
3019+
| A / L3: Canonical lease lifecycle | Reconcile #4348 renew; close transfer/release and their CLI consumers through the same typed lease rules, atomic head/event/receipt and replay. | One canonical Todo/lease revision; lost replies, stale versions, competing owners, expired/released history and cleanup proofs. Receipt replay is never a fresh execution grant. |
3020+
| B / L4: Leased Monitor poll and settlement | Compose observation, generation and independent successors with the current lease fence. Reuse the existing quota settlement protocol and exact business receipt. | L2/L3; real polling failure, duplicate/no-change observations, crash between business and quota settlement, and competing writers. Do not pretend separate authorities share a database transaction. |
3021+
| B / L5: Consumer and display closure | Reconcile #4316, audit Turn/quota/Dashboard/Chat source reads, and finish D1 freshness/recovery through the existing projection outbox. | CLI, Lark/Chat and packaged frontend read back their affected interactions; absent/stale display, empty canonical state, pending projection and data beyond UI limits. Delete post-promotion legacy fallbacks with each consumer. |
3022+
| A–C / L6: Local durability qualification | Continue contributor-owned #4224/#4328 on the selected SQLite profile; reuse File/NoKV references and complete 7.2's ledger. | Capacity, real process/crash/restore/upgrade, retained receipts/scans, consumer lag, supported runtimes/OS and the separately authorized >=10-day synthetic soak. Missing measurements remain holds. |
3023+
| A–C / L7: Capture continuity | Resolve #4315 with source-correlated archive retirement and identical lease membership at bootstrap and later writers; activate its row/mutant and complete the mixed-writer/event-source matrix. | Real CLI/File capture, history retained, partial drain unqualified, crash/replay and a new lease after archive/rebootstrap. Keep the legacy migration window provable; T4 cannot be used to skip this row. |
3024+
| C / L8: Whole-Goal rehearsal and cohort migration | Integrate one exact revision/profile after L2–L7; drain capture, fence old writers, verify canonical readback and projection, then rehearse fenced export/rollback. | D3 evidence packet binds lineage, cursor, source digest, command coverage and profile. Existing Goal migration requires explicit cohort approval; no per-command split authority or stale Markdown revival. |
3025+
| D / L9: New-Goal default and bounded retirement | A dedicated default-change PR makes new-Goal creation/onboarding choose the qualified local profile, including settings/readback, installer and packaged clients. Retire old business writers only as their final callers and migration window close. | L8's integrated product/rollback qualification; distinguish new Goal default from existing Goal migration. Publish compatibility/disable guidance, keep explicit provider choice, permanent rendering and validated import/export. T4 can continue after the default ships. |
3026+
3027+
**Cadence is evidence-based.** First reconcile the active stack, then deliver A
3028+
packages as complete operations while L6/L7 progress independently. B integrates
3029+
those contracts into complete user flows; C has one reproducible qualification
3030+
checkpoint; D changes the default in its own reviewable PR. This is roughly
3031+
nine cohesive packages at this checkpoint, not a line-count target or a promise
3032+
of nine merges. Avoid concurrent edits to the same transaction owner; share
3033+
fixture/contracts early and rebase after the owner lands.
3034+
3035+
There is no defensible calendar completion date before the L2/L3 command
3036+
inventory and L6 missing-evidence ledger close. The >=10-day soak is a real
3037+
elapsed-time lower bound **after the measured profile is ready**, not ten days
3038+
from this plan. It may overlap compatible work after explicit launch approval;
3039+
changes to the qualified durability semantics require an impact-based rerun.
3040+
Accelerated fixtures cannot replace elapsed time. Native TS CLI/distribution
3041+
cleanup, removal of every Python adapter, and PostgreSQL service deployment are
3042+
not prerequisites for this local default.
3043+
3044+
Every package records actual caller/owner deletion, added bridge LOC and its
3045+
exit, request/response counts, real-backend results, baseline parity and disclosed
3046+
semantic corrections. A green unit suite, a canonical selector, or a new config
3047+
field alone cannot advance a package to default readiness. Planned integration,
3048+
soak, release, merge and live promotion retain their respective authorization.
30113049

30123050
### Parallel delivery plan
30133051

‎docs/architecture/rfcs/shared-goal-authority-state-provider-v0.zh-CN.md‎

Lines changed: 47 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -2366,26 +2366,54 @@ route planner 本身仍不授予权限。CLI 将已提交回执交给既有 jour
23662366

23672367
#### 执行交接与汇合顺序
23682368

2369-
| 就绪条件 | 下一动作 | 不授予的权限 |
2369+
**本地默认化交付计划(2026-09-14)。** 目标是新建本地 Goal 后,日常 CLI、Turn 和
2370+
操作者动作都通过 TS 拥有的 canonical 事务运行,Markdown 永久作为展示投影。
2371+
“未指定 selector 时选择 File”不等于达成目标:已有 Goal 在明确的整 Goal cutover
2372+
之前,仍有 legacy writer。
2373+
2374+
长程默认应选定**一个**合格本地 profile。SQLite 是当前 D2 候选;File 保留为真实
2375+
对照、显式可选 profile 和迁移演练后端。不能发布两个含混的默认项,不能把现有 File
2376+
历史布局直接称为长程合格,也不能从选定 SQLite 静默回退。最终选择必须引用 D2
2377+
证据。PostgreSQL 复用 TS 语义合同,但 service、tenant、restore 和 capacity 单独
2378+
资格化;其部署不阻塞本地路线。
2379+
2380+
核对基线:#4286(命令回执/归档)、#4289(typed 工作/归属 intent)、#4292
2381+
(声明式 decision metadata)、#4304(canonical handoff mode)已合并。#4316
2382+
是 Goal Channel observation 候选,#4317 是 provider opening 候选,#4348 是
2383+
canonical renew 候选,#4328 是 SQLite D2 首批测量/恢复候选;它们尚不能算作已
2384+
合并前提或完整执行卡证据。#4334 是独立 PostgreSQL service admission 候选。
2385+
组合前重读实际 head,不能把已合并祖先再次算成新变化。
2386+
2387+
下表编号表示**计划 PR 包**,不是预留 GitHub 编号。可沿真实 effect/兼容边界拆分;
2388+
仅换语言或移动 helper 不构成一个包的退出条件。
2389+
2390+
| 波次/PR 包 | 完整交付内容与 TS 归属收益 | 依赖与退出证据 |
23702391
| --- | --- | --- |
2371-
| 当前 refactor stack 已核对 | T1;D1、D2 可独立推进 | 修改默认 provider 或新增通用迁移框架 |
2372-
| T1 字段语义闭合 | T2;所需合同就绪后推进 T3 consumer | 同一 Goal 按命令拆分 authority |
2373-
| T1–T3、D1/D2 和 capture 均合格 | D3 演练,再请求 promotion 批准 | 跳过 soak、绕过失败证据或自行生产晋升 |
2374-
| 批准的 cutover 和 legacy 窗口结束 | T4 完整 writer 退役 | 删除永久 Markdown 展示或 replay 仍需的历史 receipt |
2375-
2376-
核对当前 stack 后,预估还需**五到七个完整实现/资格化批次**,不是固定 PR 配额:
2377-
T1、T2、T3、D1、D2、D3、T4 仅在依赖、评审和回滚清晰时可同 PR 交付。
2378-
T1 就开始删除重复语义;完整 legacy writer 删除等待 D3/T4。Soak 的真实经过时间
2379-
独立计算,不能靠拆 PR 缩短。
2380-
2381-
每次交接记录精确 base/head、执行卡、实际删除的 caller、authority/可观察语义变化、
2382-
真实 backend 结果、剩余 hold 和一个可执行的下一动作。前序已合入则验证证据后跳过
2383-
重复实现;前提不满足就暂停依赖阶段。不能把“假设合并后”的就绪状态当成自动
2384-
promotion、automation、merge 或 release 授权。
2385-
2386-
当前默认和附录 C promotion hold 均不改变。这份计划不宣称完整 Todo 命令族、长程
2387-
profile 或 shared deployment 已生产就绪。provider 负责 durable CAS/transaction,
2388-
不拥有第二份 Todo 状态机。
2392+
| A/L1:Monitor 配置(本切片) | 现有 `todo update` 配置进入 TS planner/CAS/receipt,删除 Python 重复 intent 字段表;区分配置与观察 hash、时间、代数。 | 普通 CLI/API、清除/省略、active lease proof、no-op/replay、展示失败恢复、完整 fixture 和真实 provider。不宣称完成委托 Chat 或 leased polling。 |
2393+
| A/L2:公共 mutation admission 闭合 | 盘点 CLI/Turn/Chat 实际 caller;以可信 actor/grant 事实闭合剩余 effect-owned 用户决策、委托 owner 动作和 Monitor lifecycle。 | 复用已合并 T1 owner,不开通通用 raw patch;验证权限拒绝和 caller 响应,删除替代的 Python admission,列全未支持命令。 |
2394+
| A/L3:canonical lease 生命周期 | 核对 #4348 renew,继续 transfer/release 及 CLI consumer;复用 typed lease 规则和原子 head/event/receipt。 | 同一 canonical Todo/lease revision;丢回复、旧版本、owner 竞争、过期/释放历史和清理凭据。旧回执 replay 不是新执行权。 |
2395+
| B/L4:leased Monitor poll 与 settlement | 组合观察、变化代数、独立 successor 和现有 lease fence;复用 quota settlement 与精确业务回执。 | L2/L3;真实 polling 失败、重复/无变化、业务提交到 quota settlement 间崩溃和并发。不能假装不同 authority 共享一个数据库事务。 |
2396+
| B/L5:consumer 与展示闭合 | 核对 #4316,审计 Turn/quota/Dashboard/Chat 的来源,复用 projection outbox 完成 D1 新鲜度和恢复。 | 验证 CLI、Lark/Chat、打包 frontend 的受影响交互;缺失/陈旧展示、权威空状态、pending 投影及超过 UI 上限的数据。逐个删除晋升后的 legacy fallback。 |
2397+
| A–C/L6:本地持久化资格 | 延续 contributor 认领的 #4224/#4328,在选定 SQLite profile 上补齐第 7.2 节 ledger,复用 File/NoKV 对照。 | capacity、真实进程/crash/restore/upgrade、历史 receipt/scan、consumer lag、支持的 runtime/OS,以及另行授权的 >=10 天合成 soak。缺项继续 hold。 |
2398+
| A–C/L7:capture 连续性 | 修复 #4315:归档的源事务明确退休 lease 引用,bootstrap 与后续 writer 使用一致成员范围;执行 row/mutant 和 mixed-writer/event-source 矩阵。 | 真实 CLI/File capture、保留历史、半完成 drain 不合格、crash/replay,以及归档/rebootstrap 后再申请 lease。不能借 T4 跳过迁移窗口证明。 |
2399+
| C/L8:整 Goal 演练与分组迁移 | L2–L7 后汇合一个精确 revision/profile;drain capture、fence 旧 writer、回读 canonical 与投影、演练 fenced export/rollback。 | D3 包绑定 lineage、cursor、source digest、命令覆盖和 profile;已有 Goal 分组迁移需明确批准,不能按命令拆 authority 或复活旧 Markdown。 |
2400+
| D/L9:新 Goal 默认与有界退役 | 单独 default-change PR 让新建/onboarding 选择合格本地 profile,配齐 settings/readback、installer 和打包客户端;最后 caller 与迁移窗口退出才删除旧业务 writer。 | L8 整体产品/回滚资格;区分新 Goal 默认和已有 Goal 迁移。发布兼容/停用说明,保留显式 provider、永久 renderer 和合法 import/export。T4 可在默认启用后继续收尾。 |
2401+
2402+
**开发节奏以证据推进。** 先核对在途 stack,再按完整操作交付 A;L6/L7 可独立推进。
2403+
B 汇合为完整用户流程,C 形成一次可复现资格检查点,D 用独立 PR 修改默认。此时约
2404+
九个完整包,不是代码行数指标,也不承诺恰好九次 merge。同一 transaction owner
2405+
避免并发重写,先共享 fixture/合同,owner 合入后再 rebase。
2406+
2407+
L2/L3 命令盘点与 L6 缺失证据未闭合前,不给虚假的日历承诺。>=10 天 soak 是
2408+
**被测 profile 就绪之后**的真实时间下限,不是从写计划当天计时;明确授权后可与
2409+
兼容工作重叠,涉及持久化语义的后续变化须按影响重新验证。加速 fixture 不能替代
2410+
真实经过时间。本地默认不依赖完整 TS CLI/distribution 清理、删除所有 Python
2411+
adapter,也不依赖 PostgreSQL service 部署。
2412+
2413+
每包记录实际 caller/owner 删除、bridge LOC 与退出条件、跨运行时次数、真实后端、
2414+
基线 parity 和公开的语义纠正。单元测试绿、canonical selector 或新增配置字段,均
2415+
不能单独代表默认化就绪。计划中的 integration、soak、release、merge 和生产晋升
2416+
仍分别保留授权边界。
23892417

23902418
### 并行交付计划
23912419

‎docs/architecture/rfcs/typescript-control-plane-migration-v0.md‎

Lines changed: 21 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -548,7 +548,7 @@ atomic follow-up are not fully closed. Lease-edit PR #4152 is merged; bounded
548548
planning updates now reuse that fence and the existing CAS/receipt transaction.
549549
Continue with the remaining field/effect inventory, not another update engine.
550550

551-
Work-requirement editing is now closed for non-Monitor Agent Todos without a
551+
Work-requirement editing was first closed for non-Monitor Agent Todos without a
552552
retained lease: `action_kind`, `task_domain`, `task_repository`,
553553
`required_write_scopes`, `required_capabilities`, `target_capabilities` and
554554
`explore_result_node_refs` use the existing v1 planning transaction. Public
@@ -598,6 +598,26 @@ part of T1 without granting approval, lease, completion, or promotion authority.
598598
competing revisions, retry and lost-response recovery through the public
599599
command and affected real providers.
600600

601+
Monitor configuration now uses the existing native planning transaction as well
602+
as the public legacy planner. A typed authoring codec owns target/cadence/due/
603+
expiry/watch-only fields; observation hashes, timestamps, effect identities and
604+
generations stay with the polling lifecycle. The Python duplicate field allowlist
605+
and blanket native Monitor exclusion are removed. Configuration preserves
606+
observation history and cannot retarget an already observed Monitor. The lower
607+
import/observation codec retains its callers and is not exposed as a raw update.
608+
Ordinary CLI/API edits, explicit clears, receipt recovery and the existing active
609+
lease proof are covered; owner-confirmed Chat delegation and leased Monitor
610+
polling remain separate incomplete paths. No configuration prose grants authority.
611+
612+
The local-default program is maintained once in the shared RFC's
613+
[execution sequence](shared-goal-authority-state-provider-v0.md#execution-handoff-and-integration-order).
614+
L1–L4 close mutation semantics before L5 consumer integration; L6/L7 cover
615+
storage and capture; L8 qualifies whole-Goal migration; L9 changes new-Goal
616+
creation defaults. Each package must remove duplicate decisions with its new
617+
owner. A full TS launcher is not required: a bounded Python input/effect adapter
618+
is acceptable while one coarse TS request owns the transaction. Do not turn
619+
these packages into repeated leaf-RPC additions or bypass a retained caller.
620+
601621
**T2 — close monitor writeback and its atomic follow-up.**
602622

603623
Bounded prerequisite delivered: `scheduler/monitor_successor.ts` owns successor

0 commit comments

Comments
 (0)