docs(p1r): 收口 Account Stage A final review
This commit is contained in:
parent
862fe9ec1d
commit
d2895cd55a
@ -261,3 +261,9 @@ P1R Account Stage A New-API / Quota / Integration 解锁执行版已新增:`do
|
||||
P1R Account Stage A 解锁执行版首轮 feasibility/testing review(Hypatia)FAIL,3 项反馈已验证有效并修订:第一,Stage A HTTP+DB `_test` 命令不得通过 `-Dp1r.*password` 传密码,已改为只通过环境变量 `P1R_ACCOUNT_STAGE_A_DB_PASSWORD` / `P1R_FLYWAY_PASSWORD` 读取,并要求 IT 内加入 `assertNoPasswordSystemProperties()`、`assertNoCredentialQuery()` 和 `_test` URL 断言;第二,Remaining21 通用 allowed/protected diff 模板原只用 `git diff --name-only`,不能覆盖 untracked,已改为合并 `git -c core.quotePath=false diff --name-only`、`git -c core.quotePath=false diff --cached --name-only`、`git -c core.quotePath=false ls-files --others --exclude-standard`,避免中文路径被 quotePath 转义后误判;第三,Stage A coverage check 原在 Maven root 语境下使用 repo-root 相对路径,已补明确 `cd /Users/qingse/.config/superpowers/worktrees/oh-my-muse/dev-1.0.0` 后运行 scanner/jq,Maven 命令同步补 `-am`。由于文档已修订,Hypatia FAIL 之前的任何 PASS 不能作为最终 gate;下一步必须基于最新版重新派发 fresh feasibility/testing re-review,并等待 scope review 或按 scope 反馈修订后做 final re-check。
|
||||
|
||||
P1R Account Stage A 解锁执行版第二轮 feasibility/testing re-review(Meitner)FAIL,3 个 P1 已按收敛要求最小修订,不再扩展新方案:第一,runtime unavailable 与全表 no-write 语义冲突已拆开,参数校验、幂等冲突、越权、cross tenant、missing resource 仍要求全表 no-write,runtime unavailable 只允许新增或更新一条 `failed/unavailable` integration call,并用 allowed-delta snapshot 证明 binding/quota request、command succeeded fact、audit succeeded fact 和 outbox 没有成功事实;第二,quota submit worker 已冻结为“不新增 SQL migration”默认方案,复用 `muse_account_integration_call.retry_count/next_retry_at/status/errorCode/errorMessage` 承载 retry/lease/dead-letter,quota request 状态只允许 `queued -> processing -> completed/failed`,默认 `maxAttempts=3`,claim/terminal update 必须带 tenant 和状态条件,tenant context 推荐 `TenantContextHolder.setTenantId(...)` 并 finally clear;如需新增字段或索引,必须退出 Stage A unlock 另起 SQL migration 审批;第三,Stage A 与 Remaining21 的 Maven 模板已补 `-am` 和 `-Dsurefire.failIfNoSpecifiedTests=false`。Ramanujan scope review 已 PASS;Meitner FAIL 已修但未重新 review。当前按用户要求立刻收敛、记录进度并整理提交;后续如继续 Stage A implementation,必须基于最新版重新做 feasibility/testing final re-check,双 PASS 前不得 implementation 或 completed promotion。
|
||||
|
||||
P1R Account Stage A 解锁执行版 final review 进展:fresh scope final re-check(Maxwell)PASS,无 P0/P1 findings,确认 Stage A 仍只覆盖 9 个 operation,不夹带 Stage B/C/D/E、Account domain completed、Market/Content/总 P1R completed,OpenAPI、scanner、coverage report、completed allowlist 仍为保护面;其 P2 基线提交号过期已修为 `862fe9e`。fresh feasibility/testing final review(Huygens)FAIL,2 个 P1 与 1 个 P2 已按收敛要求修订:第一,quota worker 事务边界已冻结为 `claimNext` 独立事务、外部 New-API submit 不在数据库事务内、`finalizeSuccess` / `finalizeFailure` / `finalizeRetryable` 独立短事务,并补外部成功但 finalize 失败时不得二次 submit、后续恢复先查 integration call / externalCallId / correlationId 的要求;第二,Stage A 两条 member Maven 命令已补 `-am` 且保留 `-Dsurefire.failIfNoSpecifiedTests=false`;第三,Stage A 执行版与 memory 的基线提交号已更新为 `862fe9e`。当前仍只改文档,未修改 OpenAPI、scanner、coverage report、业务实现、SQL migration 或测试代码;下一步必须基于最新版重新做 feasibility/testing final re-check,PASS 前不得 implementation 或 completed promotion。
|
||||
|
||||
P1R Account Stage A 解锁执行版 narrow final re-check(Sagan)FAIL,1 个 P1 已按收敛要求修订:quota worker retry / lease 恢复状态路径不再二选一,已冻结为初次 claim 从 `queued` 进入 `processing`,retryable 失败保持 quota request 为 `processing` 并只推进 integration call 的 `retry_count/next_retry_at/errorCode/errorMessage`,下一轮 claim 只允许 `processing + next_retry_at <= now` 的恢复路径;HTTP+DB / focused tests 也改为按该唯一路径断言 double-claim、runtime unavailable allowed-delta、finalize conflict、lease 恢复和 maxAttempts terminal failed。Sagan 已确认 Maven `-am` 与 final review 起点基线两个反馈关闭。当前仍只改文档,未修改 OpenAPI、scanner、coverage report、业务实现、SQL migration 或测试代码;下一步必须基于最新版重新做 feasibility/testing final re-check,PASS 前不得 implementation 或 completed promotion。
|
||||
|
||||
P1R Account Stage A 解锁执行版 final review 已收口:fresh feasibility/testing final re-check(Volta)PASS,无 P0/P1/P2 findings;Volta 确认 Sagan 唯一 P1 已关闭,执行版已冻结唯一状态路径:初次 claim 从 `queued` 到 `processing`,retryable / runtime unavailable / timeout / 外部 5xx 的 `finalizeRetryable` 必须保持 quota request 为 `processing`,只推进 integration call 的 `retry_count/next_retry_at/errorCode/errorMessage`,下一轮 claim 只允许 `processing + next_retry_at <= now`;测试要求覆盖同一路径的 double-claim、runtime unavailable allowed-delta 且 request 保持 `processing`、finalize conflict、lease 恢复、maxAttempts terminal failed。本轮 final gate 结果为 scope final PASS(Maxwell)+ feasibility/testing final PASS(Volta)。当前 Stage A 执行版可进入用户批准后的 implementation 准备,但仍不是 implementation approved,也不是 completed approval;未获用户明确批准前不得修改业务实现、SQL、测试、OpenAPI、scanner、coverage report 或 completed allowlist。
|
||||
|
||||
@ -29,13 +29,13 @@ A4 用 Stage A HTTP+DB + opt-in live acceptance 形成 unlock evidence
|
||||
/Users/qingse/.config/superpowers/worktrees/oh-my-muse/dev-1.0.0
|
||||
```
|
||||
|
||||
当前分支基线:
|
||||
本轮 final review 起点基线:
|
||||
|
||||
```text
|
||||
main...origin/main
|
||||
HEAD=3a27e7e test(p1r): 收口 Account Security Events completed approval 门禁
|
||||
origin/main=3a27e7e
|
||||
origin/dev/1.0.0=3a27e7e
|
||||
HEAD=862fe9e docs(p1r): 收敛 Account Stage A 解锁计划
|
||||
origin/main=862fe9e
|
||||
origin/dev/1.0.0=862fe9e
|
||||
```
|
||||
|
||||
当前 coverage summary:
|
||||
@ -246,7 +246,7 @@ NewApiAccountFacade.QuotaSubmitResult
|
||||
并发与幂等要求:
|
||||
|
||||
- 不新增 SQL migration 时,worker 必须复用现有字段承载重试:`muse_account_integration_call.retry_count`、`next_retry_at`、`status`、`errorCode`、`errorMessage`。
|
||||
- worker claim 必须使用 tenant 范围内的条件更新:只允许将 `quota_request.status=queued` 且对应 `integration_call.next_retry_at is null or <= now` 的记录改为 `processing`,并同步把 integration call 改为 `retrying` 或等价运行态。
|
||||
- worker claim 必须使用 tenant 范围内的条件更新,并冻结为单一路径:初次 claim 只允许 `quota_request.status=queued`;retry / lease 恢复 claim 只允许 `quota_request.status=processing` 且对应 `integration_call.next_retry_at <= now` 且 integration call 未 terminal。claim 成功后 quota request 统一保持或进入 `processing`,并同步把 integration call 改为 `retrying` 或等价运行态。
|
||||
- lease 超时恢复必须由 `integration_call.next_retry_at` 表达;crash 后只扫描 `next_retry_at <= now` 且未 terminal 的记录。
|
||||
- retry budget 必须由 stage implementation 固定,默认 `maxAttempts=3`;达到上限后 quota request 必须进入 `failed`,integration call 必须进入 `failed` 并写失败原因。
|
||||
- tenant context 必须在 claim、submit、terminal update 前显式设置,推荐使用 `TenantContextHolder.setTenantId(...)` 并在 finally 中 clear。
|
||||
@ -256,6 +256,16 @@ NewApiAccountFacade.QuotaSubmitResult
|
||||
- worker 重试不得覆盖已 terminal 的 request。
|
||||
- 如果上述状态机需要新增字段或索引,必须先退出当前 Stage A unlock,另起 SQL migration 审批并把 V22 schema、mapper、rollback 写入新的 allowed diff。
|
||||
|
||||
worker 事务边界必须冻结为短事务模型:
|
||||
|
||||
- `claimNext` 独立事务:用 tenant + request/call status + `next_retry_at` 条件原子 claim 一条 quota request;初次 claim 匹配 `queued`,重试和 crash 恢复只匹配 `processing + next_retry_at <= now`,并同步把 quota request 置为 `processing`、integration call 置为运行态,同时递增或记录本轮 attempt。该事务提交后才能调用外部 New-API。
|
||||
- 外部 New-API submit 不得包在数据库事务内;调用前后必须保留可审计日志,日志只能包含 requestId/correlationId/tenantId/attempt/status/errorCode,不得写 token、secret 或完整外部响应。
|
||||
- `finalizeSuccess` 独立事务:仅在 quota request 仍为 `processing` 且 integration call 仍为本轮运行态时写 `completed`、`externalCallId`、`responseSummary`、`finishedAt`,并清空 `next_retry_at`;若条件更新为 0,必须记录 conflict 日志并停止覆盖。
|
||||
- `finalizeFailure` 独立事务:不可恢复失败或 maxAttempts 用状态条件写 quota request `failed`、integration call `failed`、`errorCode`、`errorMessage`、`finishedAt`,并清空 `next_retry_at`。
|
||||
- `finalizeRetryable` 独立事务:runtime unavailable、timeout 或外部 5xx 等可重试错误只更新 integration call `errorCode/errorMessage/retry_count/next_retry_at`,quota request 必须保持 `processing`,不得回写 `queued`;下一轮 claim 必须由 `processing + next_retry_at <= now` 驱动;达到 `maxAttempts=3` 后必须走 `finalizeFailure`。
|
||||
- 外部 submit 成功但 finalize 失败时,不得二次提交同一外部请求;后续恢复只能先查 integration call / externalCallId / correlationId 的已有结果,再决定 finalize 或 fail closed。
|
||||
- Stage A HTTP+DB / focused tests 必须按 `queued -> processing -> completed/failed` 唯一路径覆盖:double-claim 只有一个 worker 成功、runtime unavailable 只产生 allowed-delta 且 request 保持 `processing`、finalize conflict 不覆盖 terminal fact、`processing + next_retry_at <= now` 可恢复、maxAttempts 后 terminal failed。
|
||||
|
||||
### A4:HTTP+DB unlock gate
|
||||
|
||||
Stage A implementation 必须新增 HTTP+DB `_test` 主证据,但该证据只证明 Muse Account 侧真实 HTTP 入口、真实服务、真实 mapper、真实 PostgreSQL 和 facade 合同可闭合;如果使用 test-local facade,不得把它写成外部 New-API completed 证据。
|
||||
@ -296,7 +306,7 @@ A0 facade wiring:
|
||||
|
||||
```bash
|
||||
JAVA_HOME=$(/usr/libexec/java_home -v 21) PATH="$JAVA_HOME/bin:$PATH" \
|
||||
mvn -pl muse-module-member/muse-module-member-server -Dtest=NewApiAccountFacadeConfigurationTest \
|
||||
mvn -pl muse-module-member/muse-module-member-server -am -Dtest=NewApiAccountFacadeConfigurationTest \
|
||||
-Dsurefire.failIfNoSpecifiedTests=false test
|
||||
```
|
||||
|
||||
@ -304,7 +314,7 @@ Stage A focused member tests:
|
||||
|
||||
```bash
|
||||
JAVA_HOME=$(/usr/libexec/java_home -v 21) PATH="$JAVA_HOME/bin:$PATH" \
|
||||
mvn -pl muse-module-member/muse-module-member-server \
|
||||
mvn -pl muse-module-member/muse-module-member-server -am \
|
||||
-Dtest=AccountNewApiBindingServiceTest,AccountQuotaServiceTest,AccountUsageServiceTest \
|
||||
-Dsurefire.failIfNoSpecifiedTests=false test
|
||||
```
|
||||
|
||||
@ -8,17 +8,17 @@
|
||||
|
||||
本轮没有进入 implementation,没有推进任何 operation completed,没有修改 OpenAPI、scanner、coverage report、业务实现、SQL migration 或测试代码。
|
||||
|
||||
当前仍不能开始 Stage A implementation,除非后续基于最新版 Stage A 执行版重新完成 feasibility/testing final re-check,并由用户明确批准 implementation。
|
||||
当前仍不能直接开始 Stage A implementation;final review 已收口,下一步必须由用户明确批准 implementation。
|
||||
|
||||
## 当前基线
|
||||
|
||||
当前主分支基线:
|
||||
本轮 final review 起点基线:
|
||||
|
||||
```text
|
||||
main...origin/main
|
||||
HEAD=3a27e7e test(p1r): 收口 Account Security Events completed approval 门禁
|
||||
origin/main=3a27e7e
|
||||
origin/dev/1.0.0=3a27e7e
|
||||
HEAD=862fe9e docs(p1r): 收敛 Account Stage A 解锁计划
|
||||
origin/main=862fe9e
|
||||
origin/dev/1.0.0=862fe9e
|
||||
```
|
||||
|
||||
当前 coverage summary:
|
||||
@ -53,13 +53,17 @@ origin/dev/1.0.0=3a27e7e
|
||||
- Account Remaining21 审阅版 fresh 双 review PASS。
|
||||
- Account Remaining21 执行版 final fresh review PASS。
|
||||
- Stage A 执行版 scope review PASS。
|
||||
- Stage A 执行版 scope final re-check PASS。
|
||||
- Stage A 执行版 feasibility/testing final re-check PASS。
|
||||
|
||||
未最终通过:
|
||||
已修并收口:
|
||||
|
||||
- Stage A 执行版 feasibility/testing review 第一轮 FAIL,已修。
|
||||
- Stage A 执行版 feasibility/testing re-review 第二轮 FAIL,3 个 P1 已按收敛要求修订,但未重新 review。
|
||||
- Stage A 执行版 feasibility/testing re-review 第二轮 FAIL,3 个 P1 已按收敛要求修订。
|
||||
- Stage A 执行版 feasibility/testing final review 第三轮 FAIL,2 个 P1 与 1 个 P2 已按收敛要求修订。
|
||||
- Stage A 执行版 feasibility/testing final re-check 第四轮 FAIL,1 个 P1 已按收敛要求修订。
|
||||
|
||||
因此 Stage A 执行版目前是“已收敛、待 final feasibility/testing re-check”,不是可实施状态。
|
||||
因此 Stage A 执行版目前是“final review 已收口,可进入用户批准后的 Stage A implementation 准备”,但仍不是 implementation approved,也不是 completed approval。
|
||||
|
||||
## Stage A 当前边界
|
||||
|
||||
@ -97,6 +101,21 @@ Meitner 反馈已修:
|
||||
- quota worker claim/retry/事务边界已固定为不新增 SQL 的默认方案。
|
||||
- Stage A 与 Remaining21 Maven 模板补 `-Dsurefire.failIfNoSpecifiedTests=false`。
|
||||
|
||||
Huygens 反馈已修:
|
||||
|
||||
- quota worker 已进一步冻结为短事务模型:`claimNext` 独立事务、外部 New-API submit 不在数据库事务内、`finalizeSuccess` / `finalizeFailure` / `finalizeRetryable` 独立事务,并补 double-claim、runtime unavailable allowed-delta、finalize conflict、lease 恢复、maxAttempts terminal failed 测试要求。
|
||||
- Stage A 两条 member Maven 命令已补 `-am`。
|
||||
- Stage A 执行版与本 memory 的基线提交号已更新为 `862fe9e`。
|
||||
|
||||
Sagan 反馈已修:
|
||||
|
||||
- quota worker retry / lease 恢复路径已冻结为唯一状态合同:初次 claim 从 `queued` 进入 `processing`;runtime unavailable / timeout / 外部 5xx 的 `finalizeRetryable` 必须保持 quota request 为 `processing` 并只推进 integration call `retry_count/next_retry_at/errorCode/errorMessage`;下一轮 claim 只允许 `processing + next_retry_at <= now` 的恢复路径,不再允许实现者自行选择回写 `queued`。
|
||||
|
||||
Volta final re-check 结论:
|
||||
|
||||
- Feasibility/testing final re-check PASS,无 P0/P1/P2 findings。
|
||||
- 已确认唯一状态路径、`finalizeRetryable` 语义、同一路径测试要求,以及本轮只改三份文档。
|
||||
|
||||
## 已执行检查
|
||||
|
||||
已执行并通过:
|
||||
@ -129,9 +148,8 @@ muse-cloud/sql/muse/**
|
||||
|
||||
如果继续 Stage A:
|
||||
|
||||
1. 基于最新版 Stage A 执行版重新做 feasibility/testing final re-check。
|
||||
2. 双 review 全部 PASS 后,由用户明确批准 Stage A implementation。
|
||||
3. implementation 先做 A0 facade 装配硬化。
|
||||
4. A1 查证 New-API Account 管理端点;查不到则停止,不实现伪造 HTTP adapter。
|
||||
5. A1 查证成功后再继续 A2/A3/A4。
|
||||
6. Stage A implementation fresh 双 review PASS 后,另起 operation-level completed approval。
|
||||
1. 等用户明确批准 Stage A implementation。
|
||||
2. implementation 先做 A0 facade 装配硬化。
|
||||
3. A1 查证 New-API Account 管理端点;查不到则停止,不实现伪造 HTTP adapter。
|
||||
4. A1 查证成功后再继续 A2/A3/A4。
|
||||
5. Stage A implementation fresh 双 review PASS 后,另起 operation-level completed approval。
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user