RFC-0010:Phase 1 Exact Edge Read / Selector Survival
| 项目 | 内容 |
|---|---|
| 状态 | Accepted |
| 版本 | 0.2.0 |
| 日期 | 2026-09-01 |
| 依赖 | RFC-0008、RFC-0009、ADR-CORE-002、SemanticRef 0.1、ArtifactGraph 0.2 |
| 下一消费者 | exact.fillet@1 |
Aira 在进入 fillet 前,增加版本化的 Exact edge read/selector profile:
- capability:
cap:model.read.exact-edge@1; - read profile:
aira.read.exact-edge/0.1.0; - selector contract:
aira.semantic-ref.exact-edge-selector/0.1.0; - EdgeGraph extension:
aira.artifact-graph.exact-edge/0.1.0。
它仍通过冻结的九元 Aira Interface 与 model.read 执行,不增加 selectEdge、queryEdge 或任意
kernel-specific meta-operation。model.proposePatch 可在后续 fillet Operation Module 中内嵌同一个 selector
definition;read 与 authoring 使用完全相同的 selector bytes、hash 和解析语义。
2. 为什么不能使用 index
Section titled “2. 为什么不能使用 index”OCCT explorer 顺序、pointer、shape hash code、STEP entity number、tessellation index 与 Three.js draw index 都不是 authoring identity。参数变化、重新求值、kernel/WASM 升级或 B-Rep 导入可能改变这些值,而模型仍在 视觉上相同。任何按这些值静默重新绑定的实现都会把“执行成功”误当成“选对了边”。
因此 v0 的合法 selector basis 只有:
authoring-role:由版本锁定的 Operation Module 明确发布的 Edge role;incident-semantic-refs:取两个或以上已解析 face SemanticRef 的共同拓扑边界。
长度、方向、centroid、curve kind、bounding box 和“第 N 条边”不得成为 v0 的身份依据。它们只进入 witness、 诊断与独立检查;以后若引入几何谓词,必须另起版本并证明 tolerance/evolution 语义。
3. 双层合同
Section titled “3. 双层合同”3.1 EdgeGraph extension
Section titled “3.1 EdgeGraph extension”不修改已冻结的 ArtifactGraph 0.2。每个 Exact evaluation 产生一个 companion EdgeGraph,绑定:
artifactGraphHash、artifactId、Exact B-RepcontentHash;- naming algorithm、execution manifest 与 Revision/Evaluation context;
- 完整 face sub-entity ID 集合与每条 Edge 的 artifact-local content identity;
- 完整 lineage origins、incident face sub-entity IDs、curve/measure witness;
- EdgeGraph canonical hash。
Edge 是 extension 中的一等 sub-entity,不是 face 上的 edgeCount。Edge ID 仍是 artifact-local identity,跨
Revision 的稳定性由 SemanticRef definition、authoring witness、kernel history 与 evolution policy 提供。
3.2 Selector definition
Section titled “3.2 Selector definition”Selector definition 是可 canonical hash 的 declarative value,包含:
- body/producer/output scope;
entityKind = Edge;- selector basis;
- set-valued cardinality;
- split/merge/delete/kind-change policy;
- canonical ordering。
selectorId 从 scope、basis、cardinality、evolution policy 与 ordering 的 canonical hash 机械生成。AI 不提交 hash、kernel ID 或 witness;runtime
扩展并验证权威 request。相同 bytes 在 read 与 fillet input 中含义相同。
4. 解析语义
Section titled “4. 解析语义”4.1 authoring-role
Section titled “4.1 authoring-role”只有当前 Catalog Snapshot 中 Operation Module 明确声明的 entityKind=Edge role 才合法。Runtime 通过
module hash、role key 与 direct history 找到全集;不存在的 role 返回 EDGE_SELECTOR_ROLE_UNKNOWN,不退化为
字符串或几何猜测。
锁定的 exact.linearExtrude@1.0.0 目前只发布 Face role,不发布 Edge role。因此本 RFC 的三个真实
rectangle/extrude Gate 全部使用 incident-semantic-refs;不得为通过测试向 graph 注入虚构 Edge role 或
伪造 module hash。authoring-role 分支在 v0 只验证通用合同和 fail-closed 负例,直到后续某个版本锁定的
Operation Module 明确发布 Edge role 才进入正向产品 corpus。
4.2 incident-semantic-refs
Section titled “4.2 incident-semantic-refs”Runtime 先按 RFC-0008 解析所有 face SemanticRef,再在绑定的 Exact EdgeGraph 中求 incident face set 的交集。 任一 face resolution 为 missing、ambiguous、unknown 或 changed-kind 时,edge selector 不执行推测性降级。
输入 face SemanticRef ID 视为无序集合,canonical code-unit 排序后进入 definition hash。闭合流形 ExactSolid 的普通 edge 应有两个 incident faces;非流形、退化或 history 不完整必须显式诊断。
4.3 集合与演化
Section titled “4.3 集合与演化”结果始终是集合:
- 0 个候选:
missing; - 超出声明 cardinality:
ambiguous; - evidence 不完整:
unknown; - 满足 cardinality 与 evolution policy:
resolved。
split/merge/delete 继续沿用 SemanticRef 0.1 的显式 policy。exactly-one 是验收条件,不是“取排序后的第一个”。
任何候选全集都进入 evidence 与 Diagnostic;失败时 publishable=false。
5. AI-facing projection
Section titled “5. AI-facing projection”catalog.describe(cap:model.read.exact-edge@1) 一次返回:
- 两类 selector basis 的完整 schema 与例子;
- cardinality/evolution policy;
- 稳定 Diagnostic codes;
- EdgeGraph、SemanticRef、Query plan/receipt 的证据绑定;
- 明确禁止的 index、pointer 与 heuristic fallback。
AI-facing Intent 只包含 source/target Revision 与 selector inputs。Runtime 负责编译 definition、读取 durable face definitions/witness、构造 EdgeGraph snapshot、执行 Query,并返回 receipt-bound set-valued result。
6. 稳定 Diagnostic
Section titled “6. 稳定 Diagnostic”| Code | 含义 |
|---|---|
EDGE_SELECTOR_SCOPE_NOT_FOUND |
body、producer 或 output scope 不存在 |
EDGE_SELECTOR_ROLE_UNKNOWN |
role 未被锁定 module 发布 |
EDGE_SELECTOR_FACE_REF_INVALID |
basis 不是两个以上唯一 Face SemanticRef |
EDGE_SELECTOR_FACE_REF_UNRESOLVED |
输入 face ref 为 missing/ambiguous/unknown/changed-kind |
EDGE_SELECTOR_HISTORY_INCOMPLETE |
Exact history 无法覆盖候选 edge |
EDGE_SELECTOR_NON_MANIFOLD |
incident topology 不满足当前 closed-manifold contract |
EDGE_SELECTOR_MISSING |
完整证据下候选数为 0 |
EDGE_SELECTOR_AMBIGUOUS |
候选数超过声明 cardinality |
EDGE_SELECTOR_SPLIT_REJECTED |
split 与 policy 冲突 |
EDGE_SELECTOR_MERGE_REJECTED |
merge 与 policy 冲突 |
EDGE_SELECTOR_DELETE_REJECTED |
delete 与 policy 冲突 |
EDGE_SELECTOR_EVIDENCE_UNKNOWN |
证据不完整,禁止发布 |
EDGE_SELECTOR_BINDING_MISMATCH |
Revision/ArtifactGraph/EdgeGraph/module/schema/hash 绑定不一致 |
7. 首个 survival corpus
Section titled “7. 首个 survival corpus”首个 corpus 以 rectangle → linear extrude 为确定性根,不让 fillet 反向定义 selector:
cap.start ∩ side.uMin:底部uMinperimeter edge,exactly-one;cap.end ∩ side.uMin:顶部uMinperimeter edge,exactly-one;side.uMin ∩ side.vMin:对应 profile vertex 的 sweep edge,exactly-one;- width/height/distance edit 后三者 resolved,artifact-local ID 可变化但 selector identity 不变;
- positive ↔ symmetric extent 与 direction flip 的 policy 结果显式;
- face split、edge split、merge、delete 各自保留候选全集并按 policy 判定;
- duplicate face refs、单 face ref、跨 body ref、unknown role、stale Revision、tampered graph/hash 全部 fail closed;
- 遍历顺序、B-Rep serialization ordinal 和 mesh triangulation 改变不得改变 canonical selector result。
Revolve edge corpus 后续复用相同合同,但 seam 不自动成为稳定 authoring role;RFC-0009 的这一边界保持不变。
8. Acceptance Gate
Section titled “8. Acceptance Gate”- schema、canonical hash、TS/Rust validator 与负例 corpus 一致;
- ArtifactGraph 0.2、SemanticRef 0.1、read 0.1 与 AMIR/Core 0.1–0.4 历史 bytes 不变;
- 真实 OCCT EdgeGraph 覆盖 rectangle/extrude 全部 edges,lineage 与 incident faces 完整;
- survival corpus 零 silent wrong rebind;
- Query plan/root hash/receipt 可独立重建;
- stale CAS、cancel、kernel/history/checker/tamper failure 零 user-head publication;
- IndexedDB reopen 后 selector definition、witness、result 与 receipt identity 不变;
- Google Chrome 通过 discovery +
model.read完成三个 selector 的 current/across read,Three.js 高亮与 read-back 一致,console 0; - fresh detached checkout 可重建全部 contract/kernel/browser evidence;
- provider 调用为 0,production capability 仍为 false,直到独立 activation 裁决。
只有十项全部关闭后 RFC 才能 Accepted,随后才允许 exact.fillet@1 进入独立 RFC/Operation Module。
8.1 Accepted 收据(2026-09-01)
Section titled “8.1 Accepted 收据(2026-09-01)”十项 Gate 已全部关闭。提交 94437de 已在全新 detached checkout
独立干净 worktree 中使用 frozen/offline lockfile(198 个包、下载 0)和
receipt-matching sealed runtime 复验:Exact Edge kernel 12/12、Chrome receipt verifier、完整
pnpm check(345 个 JS/WASM tests、45 个 Rust tests)以及全局证据重放(30 个 verifier、68 份报告、
419 条路径)全部通过,missing/ignored/untracked 均为 0:
- 验证记录:完整 Exact EdgeGraph、 12/12 contract/kernel Gate、三类 incident-face selector 与 fail-closed corpus;原机器报告保留在验证提交历史中;
- Chrome 收据:原生九元
Aira Interface discovery/describe/
model.read、IndexedDB reopen、current/across Revision 结果与 receipt identity、Three.js 三条稳定artifactSubEntityId高亮和 read-back; - 验证记录:浏览器视觉合同、运行时边界与 fresh-checkout 关闭记录。
本 Accepted profile 仍保持 providerCallsExecuted=false、backendServicesStarted=false 与
productionCapabilityEnabled=false。它不授权 fillet,也不修改冻结的九元 meta-operation surface。
exact.fillet@1 现在可以进入独立 RFC/Operation Module,但必须重新通过自己的适用性、失败诊断、
SemanticRef survival、Exact/mesh evidence、IndexedDB 与 Google Chrome 产品 Gate。
9. 明确拒绝
Section titled “9. 明确拒绝”- 不暴露 OCCT explorer/API、raw C++/JS eval 或 Three.js object index;
- 不把 locator 当成 SemanticRef;
- 不用 geometry-nearest、longest、first、screen-space pick 静默重新绑定;
- 不因 selector read 成功就修改用户 head;
- 不把 fillet、chamfer 或完整 edge DSL 捆进本 Gate;
- 不通过修改冻结 schema bytes 伪装 additive evolution。