Skip to content

fix(coordination): revalidate canonical claims after CAS contention - #5371

Open
cocolord wants to merge 2 commits into
mainfrom
codex/claim-contention-retry-1001
Open

cocolord wants to merge 2 commits into
mainfrom
codex/claim-contention-retry-1001

Conversation

@cocolord

Copy link
Copy Markdown
Collaborator

Goal And Delivered Outcome

Two canonical claim commands for independent Todos can read the same provider head. Previously one succeeded and the other returned a revision conflict even though its target and write scopes were still eligible.

The TS claim owner now absorbs up to two conclusive provider-revision CAS conflicts. Every attempt uses the original operation/lease identity, rereads the receipt and complete authority, and revalidates source registration, ownership, acceptance and lease scopes. Same-Todo or overlapping-scope losers receive the current semantic rejection. Explicit revisions/transfer grants remain pinned; ambiguous writes keep the existing receipt-recovery path.

This is a bounded canonical-writer adoption under the existing TypeScript migration/shared-authority contracts. Base: main; independent of #5370.

Scope And Continuation

Complete within this scope: automatic revalidation of unrelated CAS contention in canonical claims, with public CLI adoption and no new API or provider. The generic receipt helper remains recovery-only. Recommendations are still advisory, and local writer serialization remains unchanged. Sustained multi-host contention frequency and throughput are not established by these synthetic races.

Future-facing pass: the existing claim transaction is retained as a private attempt function rather than duplicating authorization or lease rules. Retry ownership stays in the typed claim command. A broader claim-next/reservation protocol is outside this fix.

Validation

  • Tested revision: runtime commit 2761dc2a7; final head adds only the bilingual RFC checkpoint.
  • Run state: finished.
  • Input classes: synthetic, public_fixture.
Check kind Result Evidence / limitation
regression_parity passed Deterministic real-provider CAS barriers reproduce the prior failure. Independent claims both finish; same target and overlapping write scopes retain one owner. Latest acceptance, source changes, pinned revision and retry exhaustion are covered.
real_backend passed Complete File/SQLite authority suites: 646 passed, zero skips. Complete isolated PostgreSQL 16.15 authority suite: 314 passed, zero skips.
regression_parity passed After strengthening the final assertions and adding the acceptance-race case, all seven contention cases pass on each of File, SQLite and isolated PostgreSQL (21 checks). Both winning ownership records survive independent rebase.
real_entrypoint passed Seven source CLI tests in test_canonical_claim_execution_proof.py and test_canonical_claim_transfer.py: claim, current lease proof, replay, retirement and transfer on real local providers.
integration passed The full provider suites retain response-loss/ambiguous-receipt recovery tests proving that uncertain writes do not trigger a fresh commit.
static passed TS typecheck, semantic inventory advisory, maintainability ratchet, diff check and public-boundary scan. Contract check has zero errors and two unrelated existing local-state warnings.

Old bare-conflict assertions were renamed and updated to the new semantic rejection; ownership and receipt invariants remain. PostgreSQL ran in a disposable loopback cluster with synthetic tenants and was stopped afterward. No active Goal state or provider was used. NoKV integration and sustained multi-host throughput were not run; no provider-specific code changes. Maintainer review/merge remains required.

Frontend / Visual Evidence

UI impact: none. The existing canonical CLI claim path inherits this behavior; no frontend/Lark action contract changes.

Shared-authority RFC fixture impact

Existing native Todo/lease fixture schema is retained. Changed dimensions: claim retry admission, operation identity, write-scope exclusion and latest authority after CAS. The native/legacy provider suites preserve compatibility and receipt behavior. File, SQLite and PostgreSQL conformance arms were executed; promotion/three-arm rehearsal is not applicable because routing, promotion and projection schemas are unchanged.

Boundary Checklist

  • Public-safe product code, bilingual docs and synthetic conformance tests only.
  • No private state, raw logs, credentials, connection strings or local machine paths.
  • Every commit includes DCO sign-off; runtime change is left for maintainer merge.

cocolord and others added 2 commits October 1, 2026 03:43
Signed-off-by: lusendong.6789 <lusendong.6789@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>
Signed-off-by: lusendong.6789 <lusendong.6789@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>
@cocolord

Copy link
Copy Markdown
Collaborator Author

Self-review of head a38d31c62a74fbc031a4e2957397f8eaddfd3102: no blocking issue found within the submitted scope; maintainer review and merge are still required.

  • Changed surface/owner: the typed canonical claim command retries only conflict_kind=provider_revision_mismatch, at most twice. Each attempt retains the original intent and runs the full existing receipt/source/ownership/acceptance/lease checks. Generic receipt recovery and provider storage protocols are unchanged.
  • Typed-state/domain-neutrality lenses: reuses existing conflict and rejection contracts; no text-based classification or new obligation vocabulary. Explicit revisions and transfer grants remain pinned. Ambiguous effects do not become fresh writes.
  • Behavior disclosure: independent targets can absorb an unrelated head change; same-Todo and write-scope losers now receive the current semantic rejection. Recommendations remain advisory and local writer serialization is unchanged.
  • Coverage: complete File/SQLite authority suites (646 passed), isolated real PostgreSQL 16.15 suite (314 passed), final seven contention cases on all three providers (21 passed), and seven real CLI claim/transfer tests passed. Existing ambiguous-response/receipt tests retain their one-commit invariant. TS typecheck, semantic advisory, maintainability and boundary checks passed.
  • Failures/skips: the initial full run exposed eight old bare-CAS expectations; renamed semantic-rejection assertions now pass with ownership/receipt invariants retained. No unresolved executed-test failure or backend skip. NoKV and sustained multi-host throughput were not run. Manual hold: maintainer review/merge; these races do not establish field contention frequency.
  • Future-facing pass: extracted a private complete attempt under the existing command owner, avoiding a second planner or a retry policy in the generic receipt helper.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant