Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
14 commits
Select commit Hold shift + click to select a range
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,26 @@ public CLI/import or serialized contracts. Retain public behavior tests; remove
only characterization scaffolding whose retired implementation has no consumer.
Deletion is code retirement, not deletion of users' state, receipts or backups.

### Proposed T4 slice: unused Python lease/handoff facades

Caller audit at `e240730ec` finds the following internal crossings unused by
production. Native decision and transaction owners remain; this is independent
of D2 qualification and default-entry adoption.

| Removed boundary | Last caller / replacement | Compatibility and validation |
| --- | --- | --- |
| `authority_core.py` acquire/renew/transfer/release, owner-eligibility and handoff-transition command facades | Only the old core tests; real lease and handoff adapters already use whole native transactions | No persisted command format or public CLI schema changes. Retain independent native generation, replay, conflict, cleanup and quiescence tests; exercise real File/SQLite entrypoints. |
| `task_lease.acquire.decide`, `task_lease.lifecycle.decide`, `coordination.handoff_mode.plan` RPC registrations | Only those retired facades / handler tests; native transactions call the same typed rules directly | Obsolete private RPCs now reject unsupported methods. Keep `task_lease.owner_eligibility` and write-scope overlap: actual Python callers remain. |
| Lease-only `local_snapshot.py` normalization and error projection | No remaining caller; native executors own lease facts and errors | Keep `todo_snapshot_from_mapping`, used by live Todo mutation authorization. No store, receipt, backup or migration reader is removed. |

`authority_core.py` is still a live Todo bridge. `LeaseAction` and
`LeaseModeGateCommand` also remain because the semantic-vocabulary registry
explicitly retains that input contract until its M4 review. This slice does not
lower semantic coverage floors to discard a declared compatibility obligation.
Old facade-only tests retire with their implementation; public/native behavior
tests remain. Reverting this slice restores the internal crossing without a data
conversion. Maintainer review is required; this proposal is not installed behavior.

## Next delivery order

| Order | Complete outcome / owner | Concrete exit and deletion opportunity |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,23 @@ owner、持久兼容义务、正反例证据及回退方式,和不可变基线
内部删除必要但不充分,不能忽略公开 CLI/import 和序列化契约。保留公共行为测试,
只删没有消费者的旧实现专属 characterization。删的是代码,不是用户状态、回执和备份。

### 提议的 T4 切片:已无调用方的 Python lease/handoff facade

在 `e240730ec` 核对调用方后,下列内部跨界已无生产消费者。原生决策和事务 owner
保留;这项删除不等待 D2 资格或默认入口接入,也不宣称完成它们。

| 删除边界 | 最后调用方/替代 owner | 兼容与验证 |
| --- | --- | --- |
| `authority_core.py` 的 acquire/renew/transfer/release、owner eligibility、handoff transition command facade | 只剩旧 core 测试;真实 lease/handoff adapter 已直接使用完整 native 事务 | 不改持久化命令格式或公共 CLI schema。保留独立的原生 generation、重放、冲突、清理、静止规则测试,并走真实 File/SQLite 入口。 |
| `task_lease.acquire.decide`、`task_lease.lifecycle.decide`、`coordination.handoff_mode.plan` RPC 注册 | 只剩这些旧 facade/handler 测试;原生事务直接复用同一 TS 规则 | 废弃私有 RPC 明确拒绝;保留仍有 Python 调用方的 `task_lease.owner_eligibility` 和 write-scope overlap。 |
| `local_snapshot.py` 中仅供 lease 的规范化和错误投影 | 已无调用方;原生执行器拥有 lease 事实与错误 | 保留真实 Todo mutation authorization 使用的 `todo_snapshot_from_mapping`;不删 store、回执、备份或迁移 reader。 |

`authority_core.py` 仍是活跃 Todo bridge。`LeaseAction`、`LeaseModeGateCommand`
也保留:semantic-vocabulary 注册表明确将该输入契约保留到 M4 评审。本切片不通过
降低语义覆盖下限丢弃已有兼容义务。仅服务旧 facade 的测试随实现退役,公共/原生
行为测试保留。回退该切片可恢复内部跨界,无需转换数据。须由维护者评审;这是提议,
不代表已安装行为。

## 下一轮交付顺序

| 顺序 | 完整结果/owner | 具体出口与删除机会 |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -449,8 +449,9 @@ not that a Host has emitted every member or that every host execution is valid.
`input_producer` cannot select arbitrary code: the verifier is fixed in the smoke.

`lease_action` is explicitly legacy/compatibility-only: in-repository runtime
callers use separate acquire/renew/transfer/release command classes. Its four
members remain available to the existing typed `LeaseModeGateCommand` input
callers use whole native acquire/renew/transfer/release transactions. Unconsumed
Python command facades are retired independently of this declared input contract.
Its four members remain available to the existing typed `LeaseModeGateCommand` input
interface until M4 caller/migration review. No persisted usage is asserted.
The producer list is empty only because every value carries an explicit reason
and retirement milestone. A newly observed producer invalidates that declaration. Kernel families without producer metadata are printed as coverage pending; their
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -339,8 +339,9 @@ TypeScript 的对象写入、赋值及声明返回使用仓库的 TypeScript
存在允许的生产路径,不表示 Host 实际发出过全部成员或所有 Host 执行都合法。
`input_producer` 不能从数据任意指定执行代码,验证入口固定在 smoke 中。

`lease_action` 明确分类为 legacy/兼容保留:仓库运行时调用者使用分开的
acquire/renew/transfer/release command 类。四个成员为旧的类型化
`lease_action` 明确分类为 legacy/兼容保留:仓库运行时调用者直接使用
完整的 native acquire/renew/transfer/release 事务。已无调用方的 Python command
facade 独立退役,不因此丢弃这个已声明的输入契约。四个成员为旧的类型化
`LeaseModeGateCommand` 输入接口保留到 M4 调用者/迁移评审;不声称存在持久化
使用。只有每个值都带保留理由及退休里程碑时,生产者列表才能为空。新发现的
生产者必须让原兼容声明失败。
Expand Down
15 changes: 15 additions & 0 deletions docs/development/testing-and-quality.md
Original file line number Diff line number Diff line change
Expand Up @@ -468,6 +468,21 @@ override when a separate compatible environment is intentional.
Python `>=3.11`;不会静默退回不兼容的系统 `python3`。回归测试会拦截测试入口
重新引入裸 `python3` 子进程或默认值。

The control-plane test and coverage commands run at most four test files at a
time. Many files start additional Node/Python processes or exercise real SQLite;
CPU-count-based fan-out can starve those children and turn resource contention
into apparent transport failures. The SQLite capacity rehearsal remains in the
full suite with its existing workload and deadlines; this concurrency bound
does not relax capacity admission criteria. Test transport timeouts with
controlled clocks or observable request cancellation, separately from loaded
whole-suite throughput measurements.
Healthy external-worker fixtures use the production quota timeout; only timeout
cases inject a short deadline. Detached telemetry integration waits for a local
start/end record with a bounded watchdog. That observation includes process
startup and is separate from the HTTP cancellation contract. Rebuild Chat after
changing shared TS inputs before running packaged-dashboard tests; a stale
source witness must still reject the bundle.

Canary executes Python checks with the interpreter that launched LoopX
(`sys.executable`). Its displayed `python3` command is not a second interpreter
selection. Keep subprocesses on `sys.executable`; use `uv run` at the developer
Expand Down
Loading
Loading