Skip to content

fix(reliability): preserve diagnostic event chronology - #5572

Merged
huangruiteng merged 3 commits into
loopx-project:mainfrom
catwithtudou:codex/fix-diagnostic-event-chronology
Oct 5, 2026
Merged

huangruiteng merged 3 commits into
loopx-project:mainfrom
catwithtudou:codex/fix-diagnostic-event-chronology

Conversation

@catwithtudou

@catwithtudou catwithtudou commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Goal And Delivered Outcome

Fix a reproduced reliability-diagnostics readback defect: accepted timezone-aware timestamps were sorted as text. An error at 12:00+02:00, recovery at 10:01Z, and successful turn end at 10:02Z consequently appeared errored and unrecovered, with reversed receipt bounds. They now read back as idle, recovered, and chronologically bounded, while preserving the original ledger bytes.

  • Basis: self-contained reproduced defect; intended base main, investigated at 6f5505ee6b860c4994e959465736c59001d44399.
  • Existing owner: the built-in reliability-diagnostics envelope/receipt/projection. No new provider or decision owner. This completes the timestamp readback fix, not the parent reliability qualification program.
accepted timestamp → exact UTC time value → event ordering and millisecond deltas
original timestamp text → unchanged ledger and receipt evidence

Author Declaration

  • Written by: model_agent · GPT-6 · OpenAI (self-reported).

Implemented against

Specification: loopx/capabilities/reliability_diagnostics/README.md at baseline 6f5505ee6, “Observer envelope” and “Diagnostic projection”: timezone-aware ISO-8601 input; stage from the last event; recovery following a completed step/non-error turn end; stall relative to --as-of.

Criterion Disposition Implementation / evidence
Accepted offsets and fractional seconds preserve chronology implemented observed_at_microseconds and LedgerReading.ordered_envelopes; independent offset, fraction, and equal-instant vectors
Stage, recovery, age, and receipt bounds agree with event instants implemented Shared exact time values in receipt and projection; real CLI ingest → status/receipt regression
Read-only diagnostic boundary implemented Original timestamps, ledger bytes, schema and authority unchanged; existing provider remains default-off

Self-check: reviewed both callers of the ordering property, the accepted timestamp parser, current related PRs, and the capability contract. A first implementation using only datetime failed independent review because it truncated accepted submicrosecond precision; the final implementation retains it using standard-library rational arithmetic. Standards and specification review have no remaining findings.

Scope And Continuation

Complete within this scope. Reuse the existing Python diagnostic data adapter rather than add a parallel TypeScript owner or perform an unrelated language migration. The related simplification is one shared time interpretation for sorting and deltas; no new dependency, migration, activation, schema, or authority change.

Rollback restores readback logic; no persisted data is rewritten. No successor issue is needed for this bounded defect.

Validation

  • Tested revision: c848353251c9dd7058c091f4cd40e9b2f52db423 for final focused tests and premerge; broader-run provenance is stated below.
  • Run state: finished.
  • Broader-run provenance: the full Python run started before the final integer fast path and exact millisecond-division amendment. All four affected diagnostics test files, the producer/retention/CLI smokes, static checks, and premerge were rerun on the final revision above; the broad run is not represented as an exact-final-head full-suite qualification.
  • Base movement: validation comparisons remain pinned to 6f5505ee6; later main 30efccd6c changes unrelated Lark material and does not touch this repair.
  • Input classes: synthetic, public_fixture.
  • Environment: Python 3.12.10; qualified Node 22.22.3 / SQLite 3.51.3 for broader checks; disposable file-backed runtime for CLI regression.
Check kind Result Public-safe evidence / limitation
regression_parity passed The 17 new cases applied to unchanged baseline product code produce 13 failed / 4 passed; final head passes all 17. Includes independently expected UTC instants and a real CLI reproduction.
unit passed Four tests/capabilities/test_reliability_diagnostics*.py files: 162 passed on final head.
real_entrypoint passed Original dsh-shadow-observer-fixture-smoke.py and ledger-retention-smoke.py pass; CLI regression covers ingest, receipt, combined status, recovery, and unchanged ledger bytes.
static passed Repository Ruff, configured mypy, semantic advisory and full semantic smoke, git diff --check, and public-boundary scan.
real_entrypoint passed examples/control_plane/cli-output-budget-regression-smoke.py; risk-based loopx canary premerge --from-git-diff --git-diff-base 6f5505ee6: 19/19 selected checks passed.
static failed Additional explicit mypy of the three diagnostics modules finds existing no-any-return errors in envelope _sequence and intake _count; identical errors reproduce on unchanged base. Configured repository mypy passes.
unit failed Complete broader Python run with qualified Node: 16,084 passed / 115 failed / 83 skipped. Re-running the 115 failed cases on unchanged base gives 78 failed / 37 passed; those 37 also pass when rerun on final head. See provenance and disposition below.
manual not_run Native Windows, installed/live DSH, and performance qualification are outside this readback repair.

Full-run failure disposition: 78 failing cases also fail on unchanged 6f5505ee6, across existing control-plane contracts, collaboration, inventory, configuration backup, UTF-8 policy, and recovery. Related upstream repair work includes #5533 and the inventory fix #5548; this PR does not claim those branches repair every observed failure. The other 37 cases pass in isolation on both base and final head; their full-run failure cause is unresolved. The full suite is therefore not green, and an exact-final-head complete rerun was not performed. No unrelated tests were disabled or expectations relaxed.

Canonical public-fixture CLI JSON is byte-identical between unchanged base and final head. The intended changed cases are demonstrated by the independently expected chronology regressions above.

Coverage: default-off producer behavior and public consumers retain their existing validation; new regressions check event order, recovery, stall age/gaps, equal-time session/sequence ties, exact fractional precision, and byte-preserving readback. No claim that all upstream integration checks are green or the parent RFC is complete.

CI follow-up (2026-10-05)

The Python Tests run remains failed, separate from the exact-head approval. Its Stage2C mutation job and #5584 both stop at the obsolete remove_refresh_cas source locator. The focused case reproduces mutation locator drift on unchanged main f35978e3a1289a146687346467b848bfca8fa2b0.

An existing maintenance PR, #5613 at 994b9ea6e8f268254bdc1b4864f1dfb5c91f24e4, replaces that obsolete case with the current public refresh no-write oracle. Independently running its --case public_refresh_writes_owned_paragraph gives control exit 0, mutant exit 1, killed by assertion. This is focused evidence for that blocker only; the full mutation suite and all failed Python shards were not requalified here. The historical local full-suite analysis above does not establish that every current CI failure is inherited. The diagnostics branch is unchanged; the upstream maintenance repair is not duplicated here.

Frontend / Visual Evidence

  • UI impact: none. Existing CLI data readback changes; no frontend interaction or documentation chrome changes.
  • Before/after: described above and asserted by the public CLI regression.
  • States/viewports, source data, attention review: not applicable to this nonvisual fix.

Type of Change

  • Bug fix
  • Documentation update
  • Test update

LoopX Area

  • Capability or extension (providers, adapters, skills)

Technical Direction

Observer-first reliability diagnostics: correct existing passive readback. No live deployment or parent-RFC completion claim.

Shared-authority RFC fixture impact

N/A: no shared-authority provider, promotion, routing, or compatibility projection changes.

Boundary Checklist

  • No private state, credentials, raw traces, internal links, or local machine paths in the diff or this PR.
  • No duplicated maintainer-owned benchmark work.
  • Scoped to the reproduced defect.
  • UI impact marked none.
  • Every commit includes a DCO sign-off using the contributor's GitHub noreply address.

Signed-off-by: catwithtudou <42607255+catwithtudou@users.noreply.github.com>
Signed-off-by: catwithtudou <42607255+catwithtudou@users.noreply.github.com>
Signed-off-by: catwithtudou <42607255+catwithtudou@users.noreply.github.com>
@catwithtudou
catwithtudou marked this pull request as ready for review October 4, 2026 12:09

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

动机

通过 CLI 读取被动诊断事件、判断错误是否恢复的操作者。 错误在 12:00+02:00、恢复在 10:01Z、结束在 10:02Z,旧版本按字符串排序后显示错误未恢复并颠倒 receipt 时间边界;当前按实际 UTC 时刻读回 idle、已恢复及正确边界。 同一隔离真实 CLI 输入在基础版本显示 errored/unrecovered、末事件年龄 600000 ms;当前显示 idle/recovered、480000 ms,并保留原始时间戳文本及账本字节。小数精度年龄也修正,既有公开 fixture 的完整 status JSON 保持字节一致。 本次只完成已有诊断读回修复,不激活 observer、不提供自动恢复、工作调度或权限,也不宣称父级长期可靠性计划、性能或已安装 DSH 验收完成。

改动思路

独立对照原始契约 loopx/capabilities/reliability_diagnostics/README.md 的基础版本 6f5505ee6b860c4994e959465736c59001d44399,再审完整精确 head。Existing Python reliability_diagnostics envelope/receipt/projection are passive provider-data adapters, not a second TS control-plane decision authority. Existing typed event/stage enums and ledger intake remain authoritative. Criterion bounded-user-outcome: 错误在 12:00+02:00、恢复在 10:01Z、结束在 10:02Z,旧版本按字符串排序后显示错误未恢复并颠倒 receipt 时间边界;当前按实际 UTC 时刻读回 idle、已恢复及正确边界。 Disposition: implemented。本次的边界是已有调用者的完整有界结果,父级项目验收保持独立。

具体改动

6 files +172/-3。observed_at_microseconds: Computes integer UTC microseconds and rational residual precision, including accepted fractional offsets.; LedgerReading.ordered_envelopes: Orders by actual instant with the unchanged session/sequence tie break; preserves original timestamp text.; _ms_between: Uses the same exact interpretation and integer millisecond truncation for age/gap.

对主干的风险

162 diagnostics tests; actual base/head ingest/status/receipt with identical fixtures, invalid --as-of and byte preservation; DSH producer fixture and retention CLI smoke;Ruff, semantic advisory then full semantic and diff checks pass. No exact-head full-repository run, native Windows, installed/live DSH, performance or parent-RFC qualification. Author historical full-suite failures remain unresolved; independent current affected-path tests and real base/head evidence are sufficient for this bounded readback review, without claiming the full suite green. Raw DSH-shaped ingest lacks linked observer stats and yields unchanged invalid integrity on both revisions; it is a fail-closed parity control, not producer readiness. Producer fixture/retention smokes separately pass.

我的整体评价

APPROVE:有界时间顺序修复成立。原 ledger、schema、默认关闭和无控制权边界保持;无需迁移。
Future-facing pass: Applied: one shared exact-time interpretation for ordering and deltas; additional typed control-plane rewrite is unrelated. CI was not consulted or awaited. Review approval, merge readiness and parent acceptance are separate.

Reviewer: model_agent; model=gpt-6.1-sol; provider=OpenAI; reasoning_effort=xhigh; declaration_source=runtime_reported.

English verdict: APPROVE - 5572@c848353251c9dd7058c091f4cd40e9b2f52db423

No blocking finding. Strongest unrun qualification is installed/live DSH and a full exact-head repository run; neither is claimed by this bounded diagnostic readback acceptance.

@huangruiteng
huangruiteng merged commit 71becf2 into loopx-project:main Oct 5, 2026
27 of 52 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants