跳转到内容

RFC-0010:Phase 1 Exact Edge Read / Selector Survival

项目 内容
状态 Accepted
版本 0.2.0
日期 2026-09-01
依赖 RFC-0008、RFC-0009、ADR-CORE-002、SemanticRef 0.1、ArtifactGraph 0.2
下一消费者 exact.fillet@1

Aira 在进入 fillet 前,增加版本化的 Exact edge read/selector profile:

  • capability:cap:model.read.exact-edge@1;
  • read profile:aira.read.exact-edge/0.1.0;
  • selector contract:aira.semantic-ref.exact-edge-selector/0.1.0;
  • EdgeGraph extension:aira.artifact-graph.exact-edge/0.1.0。

它仍通过冻结的九元 Aira Interface 与 model.read 执行,不增加 selectEdge、queryEdge 或任意 kernel-specific meta-operation。model.proposePatch 可在后续 fillet Operation Module 中内嵌同一个 selector definition;read 与 authoring 使用完全相同的 selector bytes、hash 和解析语义。

OCCT explorer 顺序、pointer、shape hash code、STEP entity number、tessellation index 与 Three.js draw index 都不是 authoring identity。参数变化、重新求值、kernel/WASM 升级或 B-Rep 导入可能改变这些值,而模型仍在 视觉上相同。任何按这些值静默重新绑定的实现都会把“执行成功”误当成“选对了边”。

因此 v0 的合法 selector basis 只有:

  1. authoring-role:由版本锁定的 Operation Module 明确发布的 Edge role;
  2. incident-semantic-refs:取两个或以上已解析 face SemanticRef 的共同拓扑边界。

长度、方向、centroid、curve kind、bounding box 和“第 N 条边”不得成为 v0 的身份依据。它们只进入 witness、 诊断与独立检查;以后若引入几何谓词,必须另起版本并证明 tolerance/evolution 语义。

不修改已冻结的 ArtifactGraph 0.2。每个 Exact evaluation 产生一个 companion EdgeGraph,绑定:

  • artifactGraphHash、artifactId、Exact B-Rep contentHash;
  • naming algorithm、execution manifest 与 Revision/Evaluation context;
  • 完整 face sub-entity ID 集合与每条 Edge 的 artifact-local content identity;
  • 完整 lineage origins、incident face sub-entity IDs、curve/measure witness;
  • EdgeGraph canonical hash。

Edge 是 extension 中的一等 sub-entity,不是 face 上的 edgeCount。Edge ID 仍是 artifact-local identity,跨 Revision 的稳定性由 SemanticRef definition、authoring witness、kernel history 与 evolution policy 提供。

Selector definition 是可 canonical hash 的 declarative value,包含:

  • body/producer/output scope;
  • entityKind = Edge;
  • selector basis;
  • set-valued cardinality;
  • split/merge/delete/kind-change policy;
  • canonical ordering。

selectorId 从 scope、basis、cardinality、evolution policy 与 ordering 的 canonical hash 机械生成。AI 不提交 hash、kernel ID 或 witness;runtime 扩展并验证权威 request。相同 bytes 在 read 与 fillet input 中含义相同。

只有当前 Catalog Snapshot 中 Operation Module 明确声明的 entityKind=Edge role 才合法。Runtime 通过 module hash、role key 与 direct history 找到全集;不存在的 role 返回 EDGE_SELECTOR_ROLE_UNKNOWN,不退化为 字符串或几何猜测。

锁定的 exact.linearExtrude@1.0.0 目前只发布 Face role,不发布 Edge role。因此本 RFC 的三个真实 rectangle/extrude Gate 全部使用 incident-semantic-refs;不得为通过测试向 graph 注入虚构 Edge role 或 伪造 module hash。authoring-role 分支在 v0 只验证通用合同和 fail-closed 负例,直到后续某个版本锁定的 Operation Module 明确发布 Edge role 才进入正向产品 corpus。

Runtime 先按 RFC-0008 解析所有 face SemanticRef,再在绑定的 Exact EdgeGraph 中求 incident face set 的交集。 任一 face resolution 为 missing、ambiguous、unknown 或 changed-kind 时,edge selector 不执行推测性降级。

输入 face SemanticRef ID 视为无序集合,canonical code-unit 排序后进入 definition hash。闭合流形 ExactSolid 的普通 edge 应有两个 incident faces;非流形、退化或 history 不完整必须显式诊断。

结果始终是集合:

  • 0 个候选:missing;
  • 超出声明 cardinality:ambiguous;
  • evidence 不完整:unknown;
  • 满足 cardinality 与 evolution policy:resolved。

split/merge/delete 继续沿用 SemanticRef 0.1 的显式 policy。exactly-one 是验收条件,不是“取排序后的第一个”。 任何候选全集都进入 evidence 与 Diagnostic;失败时 publishable=false。

catalog.describe(cap:model.read.exact-edge@1) 一次返回:

  • 两类 selector basis 的完整 schema 与例子;
  • cardinality/evolution policy;
  • 稳定 Diagnostic codes;
  • EdgeGraph、SemanticRef、Query plan/receipt 的证据绑定;
  • 明确禁止的 index、pointer 与 heuristic fallback。

AI-facing Intent 只包含 source/target Revision 与 selector inputs。Runtime 负责编译 definition、读取 durable face definitions/witness、构造 EdgeGraph snapshot、执行 Query,并返回 receipt-bound set-valued result。

Code 含义
EDGE_SELECTOR_SCOPE_NOT_FOUND body、producer 或 output scope 不存在
EDGE_SELECTOR_ROLE_UNKNOWN role 未被锁定 module 发布
EDGE_SELECTOR_FACE_REF_INVALID basis 不是两个以上唯一 Face SemanticRef
EDGE_SELECTOR_FACE_REF_UNRESOLVED 输入 face ref 为 missing/ambiguous/unknown/changed-kind
EDGE_SELECTOR_HISTORY_INCOMPLETE Exact history 无法覆盖候选 edge
EDGE_SELECTOR_NON_MANIFOLD incident topology 不满足当前 closed-manifold contract
EDGE_SELECTOR_MISSING 完整证据下候选数为 0
EDGE_SELECTOR_AMBIGUOUS 候选数超过声明 cardinality
EDGE_SELECTOR_SPLIT_REJECTED split 与 policy 冲突
EDGE_SELECTOR_MERGE_REJECTED merge 与 policy 冲突
EDGE_SELECTOR_DELETE_REJECTED delete 与 policy 冲突
EDGE_SELECTOR_EVIDENCE_UNKNOWN 证据不完整,禁止发布
EDGE_SELECTOR_BINDING_MISMATCH Revision/ArtifactGraph/EdgeGraph/module/schema/hash 绑定不一致

首个 corpus 以 rectangle → linear extrude 为确定性根,不让 fillet 反向定义 selector:

  1. cap.start ∩ side.uMin:底部 uMin perimeter edge,exactly-one;
  2. cap.end ∩ side.uMin:顶部 uMin perimeter edge,exactly-one;
  3. side.uMin ∩ side.vMin:对应 profile vertex 的 sweep edge,exactly-one;
  4. width/height/distance edit 后三者 resolved,artifact-local ID 可变化但 selector identity 不变;
  5. positive ↔ symmetric extent 与 direction flip 的 policy 结果显式;
  6. face split、edge split、merge、delete 各自保留候选全集并按 policy 判定;
  7. duplicate face refs、单 face ref、跨 body ref、unknown role、stale Revision、tampered graph/hash 全部 fail closed;
  8. 遍历顺序、B-Rep serialization ordinal 和 mesh triangulation 改变不得改变 canonical selector result。

Revolve edge corpus 后续复用相同合同,但 seam 不自动成为稳定 authoring role;RFC-0009 的这一边界保持不变。

  1. schema、canonical hash、TS/Rust validator 与负例 corpus 一致;
  2. ArtifactGraph 0.2、SemanticRef 0.1、read 0.1 与 AMIR/Core 0.1–0.4 历史 bytes 不变;
  3. 真实 OCCT EdgeGraph 覆盖 rectangle/extrude 全部 edges,lineage 与 incident faces 完整;
  4. survival corpus 零 silent wrong rebind;
  5. Query plan/root hash/receipt 可独立重建;
  6. stale CAS、cancel、kernel/history/checker/tamper failure 零 user-head publication;
  7. IndexedDB reopen 后 selector definition、witness、result 与 receipt identity 不变;
  8. Google Chrome 通过 discovery + model.read 完成三个 selector 的 current/across read,Three.js 高亮与 read-back 一致,console 0;
  9. fresh detached checkout 可重建全部 contract/kernel/browser evidence;
  10. provider 调用为 0,production capability 仍为 false,直到独立 activation 裁决。

只有十项全部关闭后 RFC 才能 Accepted,随后才允许 exact.fillet@1 进入独立 RFC/Operation Module。

十项 Gate 已全部关闭。提交 94437de 已在全新 detached checkout 独立干净 worktree 中使用 frozen/offline lockfile(198 个包、下载 0)和 receipt-matching sealed runtime 复验:Exact Edge kernel 12/12、Chrome receipt verifier、完整 pnpm check(345 个 JS/WASM tests、45 个 Rust tests)以及全局证据重放(30 个 verifier、68 份报告、 419 条路径)全部通过,missing/ignored/untracked 均为 0:

  • 验证记录:完整 Exact EdgeGraph、 12/12 contract/kernel Gate、三类 incident-face selector 与 fail-closed corpus;原机器报告保留在验证提交历史中;
  • Chrome 收据:原生九元 Aira Interface discovery/describe/model.read、IndexedDB reopen、current/across Revision 结果与 receipt identity、Three.js 三条稳定 artifactSubEntityId 高亮和 read-back;
  • 验证记录:浏览器视觉合同、运行时边界与 fresh-checkout 关闭记录。

本 Accepted profile 仍保持 providerCallsExecuted=false、backendServicesStarted=false 与 productionCapabilityEnabled=false。它不授权 fillet,也不修改冻结的九元 meta-operation surface。 exact.fillet@1 现在可以进入独立 RFC/Operation Module,但必须重新通过自己的适用性、失败诊断、 SemanticRef survival、Exact/mesh evidence、IndexedDB 与 Google Chrome 产品 Gate。

  • 不暴露 OCCT explorer/API、raw C++/JS eval 或 Three.js object index;
  • 不把 locator 当成 SemanticRef;
  • 不用 geometry-nearest、longest、first、screen-space pick 静默重新绑定;
  • 不因 selector read 成功就修改用户 head;
  • 不把 fillet、chamfer 或完整 edge DSL 捆进本 Gate;
  • 不通过修改冻结 schema bytes 伪装 additive evolution。