Conversation
Verify that delayed results arriving after instance replacement are traceable to their original instance and not silently rebound. 6 tests cover: - retired_goal_instances records old→new lineage with successor ref - sequential recreations accumulate entries without losing lineage - retired session ids are recorded in session_receipts retire entry - lifetime_receipts record the recreation event with old→new mapping - old session receipts are NOT auto-rebound to the new instance - full receipt trail spans registration→recreation for lineage rebuild Design owner: handoff and Effect recovery owners (R3). Qualification: goal-immutability-coherence-defense-v0.md. Signed-off-by: Duang777 <duang777@gmail.com> Signed-off-by: duanjialing.777 <duanjialing.777@bytedance.com>
huangruiteng
left a comment
There was a problem hiding this comment.
Reviewed exact head: 5a11b0f79a86756359ad1a2b5afc4ab90dbeb15d
Comparison base: bb0b2baa81bffbef3d96d3b1cc7ae29f915b1bbb
动机
A 的请求结果若在同名后继 B 建立后才抵达,需保留原 request/result/Effect 归属,并让有权限的恢复者拿到结果或明确终态。R3 设计文档 把这列为延后的非规范性方向;我不要求本 PR 实现完整 R3 runtime,但它自称提供 R3 recoverable late-result disposition 的验证,因此测试必须碰到结果到达与处置。
改动思路
新增测试复用真实 source-session 登记、绑定与重建服务。它证明 A→B 退休映射、session/lifetime receipt 和旧绑定不自动落到 B;这些是实例生命周期事实。更小且更有价值的方案是在已有 host/Effect recovery 或 lifetime suite 中补真实迟到结果与丢响应案例,收敛重复的 metadata 断言。
具体改动
整份 diff 只有 tests/control_plane/test_goal_late_result_disposition.py,+380/-0、六项 synthetic registry 测试;无生产代码或 CLI/UI 变化。流程为 register A → 可选 bind → recreate B → load registry,没有提交/接收 late result,也没有调用 Effect 恢复。新六项均通过,现有 CLI+host suite 在 base/head 各 30 通过。
对主干的风险
[P2,阻塞] 没有验证标称的 R3 结果处置。 235 行称 recreation receipt 是 reconcile late results 的权威记录,377 行称可 trace late result,但从未提供结果。即使结果被丢弃、误归 B 或外部 Effect 重跑,六项断言仍只会看到相同元数据。请经真实 host/Effect result-arrival/lost-response owner,检查原 request/result/effect 关联、授权 return 或明确终态,以及不重绑/重跑和 B 合法继续。若目标仅为 receipt lineage,请收窄名称/声明并整合进既有 lifetime suite,不称其为 R3 disposition。
[P2,阻塞] 新增文件的 Ruff 失败。 uv run --extra test ruff check tests/control_plane/test_goal_late_result_disposition.py 报 F401:18 行 pytest、20 行 EffectRuntimeRejected 未使用。请移除或在真实恢复测试中使用。
我的整体评价
REQUEST_CHANGES:问题是测试对承诺的结果处置没有判别力,不是在指控现有生产代码已有漏洞。Future-facing pass 是复用 host/lifetime owner、削掉重复元数据场景并补敏感 oracle,无需新抽象。#5229 提交早于 #5227/#5228 的评审反馈;我不按作者或提交时间判负,也不建议账号限制。未查询或等待远端 CI,未修改、合并 PR。
English verdict: REQUEST_CHANGES - 5a11b0f. The six tests pass without delivering or disposing of any late result, and PR-local Ruff fails on two unused imports. Add a real result/effect recovery oracle or narrow and consolidate the claimed scope.
|
Closing after review. The tests inspect retirement metadata but never deliver or dispose of a late result, so they do not prove R3. The useful instance-lineage assertions already belong to the source-session lifetime suite and are covered by the narrowed #5227 update. No code from this PR should merge; real late-result disposition remains an explicit design gap. |
Goal / Source
Recoverable late-result disposition slice (R3) from
goal-immutability-coherence-defense-v0.md: when an old request's result arrives after instance replacement, the system must preserve the original lineage, not silently discard or auto-rebind the result to the new instance.What Changed
Added
tests/control_plane/test_goal_late_result_disposition.pywith 6 end-to-end tests verifying that the source-session lifecycle correctly tracks retired instances, preserves receipt lineages, and prevents auto-rebinding.Test Matrix
test_retired_instances_tracks_old_to_new_lineagetest_retired_instances_preserved_across_sequential_recreationstest_retired_instance_sessions_recorded_in_retire_receipttest_lifetime_receipts_record_recreation_eventtest_session_receipts_not_rebound_to_new_instancetest_full_receipt_trail_spans_registration_and_recreationValidation
Existing control plane test suite unchanged.
Design Owner
handoff and Effect recovery owners (R3) -- retired_goal_instances, session_receipts, and lifetime_receipts form the authoritative late-result reconciliation trail.