fix: support internal AgentBus attachments

This commit is contained in:
inman committed 2026-08-31 10:36:57 +08:00
1 parent cd45ce17d0
commit 161f90d09d
12 files changed
+96 -86

No files matched your search

@@ -9,6 +9,7 @@
| ROUTE-001 | The machine registry is the authority for 18 parser routes; the two passenger-list routes are Program-only. | Active | 2026-08-28 | Manual and AgentBus intake | [Machine registry](../../control-plane/src/business-routes.ts) |
| RELEASE-001 | Current artifacts, filenames, versions, and SHA-256 values are defined only by `dist/release-manifest.json`. | Active | 2026-08-28 | Release and delivery | [Release manifest](../../dist/release-manifest.json) |
| SAFETY-001 | Real ERP access/write, task mutation, extension reload, service restart, deployment, and external delivery require explicit task-scoped authorization. | Active | 2026-08-28 | Operations and maintenance | [Governance](../../AGENTS.md) |
| NETWORK-001 | In the trusted internal deployment, AgentBus roster attachment URLs may resolve to internal/private addresses; HTTPS, credential rejection, DNS pinning, redirect validation, bounds, and digest checks remain. | Active | 2026-08-31 | AgentBus attachment ingress | [Reply contract](../../agent设计规范/agentbus-reply-contract.md) |
## Superseded Decisions
+4 -1
View File
@@ -10,6 +10,9 @@
| ERP execution | Confirmed task | Chrome extension and logged-in ERP page | Requires unique object, page identity, ownership, and write preflight |
| Completion evidence | ERP response/requery | Control-plane receipt and business reply | Evidence is action-specific; uncertain writes fail closed |
| Passenger workbook | Single `.xls/.xlsx` attachment | Deterministic encrypted canonical TSV | First row ignored, second row fixed header, exact leader-contact rules |
| WeChat roster attachment | Strict transport envelope plus one structured `payload.attachments[]` entry | Existing `awaiting_attachment` task | Explicit conversation ID wins; otherwise strict `Conversation:` supplies the fallback. Placeholder text alone never creates a task. |
| Internal attachment download | Credential-free HTTPS URL | Bounded in-memory workbook bytes | Internal/private DNS answers are allowed; the selected address is pinned, every redirect is revalidated, and URL/host/IP/bytes are omitted from logs. |
| Operational diagnostics | Service, request, task, parser, AgentBus, attachment, database, and cleanup stages | Structured stdout/stderr and bounded Docker logs | Correlation identifiers, codes, outcomes, and durations only; no secrets or business payloads. |
| Confirmation export | ERP source file | Archived source plus mobile delivery artifact | Visitor XLS becomes real XLSX; other types prefer PDF |
| Release | Editable source | `dist/release-manifest.json` and versioned artifacts | Manifest owns current hashes and filenames |
@@ -29,4 +32,4 @@
## Last Updated
2026-08-28
2026-08-31
@@ -10,7 +10,7 @@ Manual or AgentBus input is routed through task-scoped AI/Shadow/Auto/Program or
|---|---|---|
| `agent设计规范/` | Agent Prompt, five parsing Skills, business templates, business registry, and stable fixtures | Editable source for business semantics; not runtime evidence |
| `schemas/` and `mappings/` | Parse-state, execution-state, ERP form, field, and lifecycle contracts | Current contracts only |
| `control-plane/` | Task/session persistence, parser orchestration, confirmation, audit, AgentBus, attachments, and receipts | TypeScript source; build output goes to `.build/` |
| `control-plane/` | Task/session persistence, parser orchestration, confirmation, audit, AgentBus, attachments, receipts, and structured diagnostics | TypeScript source; build output goes to `.build/` |
| `LianSyn-platform/` | Operator workbench and external parser adapter | Source and UI, not local task output |
| `chrome-extension/ltjt-order-assistant/` | Logged-in ERP resolution, preflight, native execution, response handling, and requery | Any code change requires synchronized versioned release updates |
| `dist/` | Versioned current deliverables and machine-readable release manifest | Not a compilation directory |
@@ -22,6 +22,10 @@ Manual or AgentBus input is routed through task-scoped AI/Shadow/Auto/Program or
- AI/Program parsing and ERP resolution/execution share the final operation contract but do not share authority.
- Platform envelope fields such as task ID, session, parser decision, confirmation, transport, and audit never enter the business operation.
- Unknown, ambiguous, unverified, or post-write-uncertain states fail closed; automatic retries must not create duplicate writes.
- PostgreSQL is the sole required durable database/state middleware, and the production artifact provider is OSS. Redis, message queues, MongoDB, and search services are not runtime dependencies.
- Migrations must complete before the application starts. The current ACK topology starts with one application replica because AgentBus listeners and SSE emission are process-local; horizontal scale requires explicit coordination first.
- Operational diagnostics are privacy-safe structured JSON on stdout/stderr. Docker owns bounded rotation; repository files and a second mutable log database are not log sinks.
- In the trusted internal deployment, AgentBus roster attachment downloads may resolve to private/reserved addresses. Credential-free HTTPS, DNS resolution/pinning, redirect revalidation, size, timeout, and digest checks remain mandatory, and trusted channels/bridges own the network-input boundary.
- Canonical project memory is updated only under Integration Gate; feature tasks write only their task-scoped records.
## Related Decisions
@@ -31,7 +35,8 @@ Manual or AgentBus input is routed through task-scoped AI/Shadow/Auto/Program or
- ROUTE-001
- RELEASE-001
- SAFETY-001
- NETWORK-001
## Last Updated
2026-08-28
2026-08-31
+13 -8
View File
@@ -4,42 +4,47 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
## Integrated Through
- Commit `7b5d855b093af39bf834fab4f41f41b37be1170d` as the inspected repository baseline.
- Integration task `20260828-migrate-project-docs-6f1a9c2d` for the project-documentation migration.
- Commit `c4c469f4441d744627af2d34abe693b6783e833c` for the independently advanced remote deployment/extension line.
- Commit `cd45ce17d0fcd25f7fa89ab9f8a391d3e904ecdf` for WeChat attachment correlation and privacy-safe server diagnostics.
- Integration task `20260831-integrate-server-diagnostics-8b42c6d1` for mainline reconciliation and trusted-intranet attachment compatibility.
## Current Focus
Operate the current `0.5.157` release baseline safely, keep Program/AI routing and ERP execution boundaries synchronized, and close the remaining authorization-dependent validation gaps.
Operate the current `0.5.163` extension release baseline safely, keep Program/AI routing and ERP execution boundaries synchronized, and prepare the integrated control-plane revision for a separately authorized deployment.
## Recently Completed
- 2026-08-28: Initialized `.project-docs/`, migrated durable project memory, and retired the root Planning with Files system into date-scoped history.
- 2026-08-28: Released Chrome extension `0.5.157`, Program parser `v1.0.6`, input contract/DOCX `0.5.123`, and five business Skills `0.5.125`.
- 2026-08-30: Advanced the synchronized Chrome extension/runtime release to `0.5.163`; Program parser remains `v1.0.6`, input contract/DOCX `0.5.123`, and five business Skills `0.5.125`.
- 2026-08-28: Added narrow shared-mother-plan whole-visitor export using `shared_plan + visitor-list + tid-only` while preserving child/independent `did+tid` behavior.
- 2026-08-28: Restarted the standard 8786 control plane under authorization and observed AgentBus 4/4 channels ready across repeated samples.
- 2026-08-31: Integrated strict WeChat envelope conversation fallback, placeholder-only attachment rejection before task ingestion, and safe attachment error summaries while preserving the original `awaiting_attachment` task.
- 2026-08-31: Integrated structured privacy-safe diagnostics across service, HTTP, task/audit, parser, AgentBus, attachment, database, and cleanup stages, with bounded Docker stdout retention and a read-only server diagnostic command.
- 2026-08-31: Confirmed from the supplied production log that attachment correlation succeeded and the failure was private/reserved DNS rejection; removed that rejection for the trusted internal deployment while retaining credential-free HTTPS, DNS pinning, redirect validation, size, timeout, and SHA-256 controls.
## In Progress
- No separate repository feature task is recorded at this integration snapshot.
- No separate repository feature task is recorded at this integration snapshot; deployment and restart remain unperformed.
## Next Recommended Steps
1. With explicit authorization, run a live read-only ERP verification of the shared-mother-plan `tid-only` whole-visitor export path.
2. With explicit authorization, perform ERP write verification for independent-order SGL/TWN and adult/child/leader headcount mappings.
3. Design a controlled public-DNS or host-allowlist fallback for AgentBus OSS attachments without weakening private-network SSRF blocking.
3. Under separate deployment authorization, publish the integrated control-plane image with `DEPLOYMENT_REVISION` set and verify one real internal AgentBus roster attachment through the new diagnostic stages.
## Open Questions / Blockers
- Shared-mother-plan whole-visitor export has historical read evidence and static coverage but lacks a fresh authorized runtime ERP read verification.
- Independent-order SGL/TWN and four headcount categories lack authorized current-version ERP write evidence.
- Some AgentBus OSS attachment URLs can be rejected when local DNS resolves them to private or reserved addresses.
- The repository fix for internal attachment URLs is not active on the server until a separately authorized image build/deployment/restart occurs.
## Risky Areas
- Any ERP write, uncertain post-write state, automatic retry, or scope widening.
- Passenger workbook normalization, encrypted attachment persistence, leader-contact projection, and native ERP row capacity.
- AgentBus channels and their upstream bridge are now a trusted network boundary because attachment URLs may target internal HTTPS hosts.
- Release synchronization across extension source, minimum platform version, mapping, ZIP, Skills, DOCX, and `dist/release-manifest.json`.
## Last Updated
2026-08-28
2026-08-31
@@ -14,31 +14,48 @@
- Merge the independently advanced `origin/main`, local project-governance/diagnosis commits, and the published WeChat attachment-correlation/diagnostics branch into `main`.
- Preserve the remote deployment adaptations and Chrome extension `0.5.163` release while retaining the accepted `.project-docs`-only governance boundary.
- Add production support for attachment URLs that intentionally resolve inside the server environment through an exact, configuration-driven private-host allowlist.
- Preserve HTTPS, credential rejection, redirect revalidation, DNS pinning, byte limits, declared size, and SHA-256 verification; do not globally permit private/reserved networks.
- Remove the private/reserved-network rejection from the AgentBus roster attachment downloader because the service and attachment source intentionally share a trusted internal network.
- Preserve HTTPS, credential rejection, redirect revalidation, DNS resolution/pinning, byte limits, declared size, and SHA-256 verification while allowing internal hostnames, private IPv4/IPv6, and localhost.
- Reconcile accepted promotion candidates into canonical data-flow, business-rule, architecture/current-state, evidence, and deployment documentation where supported.
- Run all repository gates, commit the integrated result on `main`, and push it to `origin/main`.
## Intent And Constraints
- The user explicitly authorized merging all current work into `main` and pushing a new revision, and explicitly confirmed that the attachment source is expected to use a private address in the server environment.
- Private-network compatibility must be opt-in per exact hostname or IP. Empty configuration preserves the existing fail-closed SSRF behavior; wildcards, URL prefixes, paths, credentials, and CIDR-wide bypasses are not accepted.
- Every initial URL and redirect target must be evaluated independently against the same exact allowlist; logging may record only allowlist presence/count and a boolean match, never the configured host values or attachment URL.
- The user subsequently clarified that private-network blocking is not required in this deployment. Do not add an allowlist or retain private/reserved address filtering for inbound AgentBus attachments.
- Every initial URL and redirect target must still require credential-free HTTPS, resolve successfully, and use DNS pinning for the selected address. Logging must never record the attachment URL, hostname, IP, file bytes, or roster values.
- Treat enabled AgentBus channels and their upstream bridge as the trusted input boundary for internal attachment URLs.
- Resolve the root planning-file merge according to accepted decision `DOC-001`: remote implementation/release facts and immutable archives are retained, but retired root planning files are not restored as active sources.
- Do not deploy, restart services, mutate Kubernetes, read secrets, access ERP, retry live tasks, or send external messages.
## Outcome
- Not completed.
- Reconciled the independently advanced `origin/main` line with the local `.project-docs` governance history in merge commit `c4c469f`; retained Chrome extension/runtime `0.5.163`, the synchronized release manifest and archives, and remote deployment facts without restoring retired root planning files.
- Integrated WeChat attachment correlation and privacy-safe diagnostics in merge commit `cd45ce1`. Strict envelope conversation fallback and placeholder-only rejection preserve the original `awaiting_attachment` task and prevent an attachment card from becoming a second business task.
- Inspected the user-supplied server log and confirmed that the actual attachment frame already carried structured metadata in the same conversation. It failed before task ingestion because its hostname resolved to a private/reserved address; correlation was not the failing boundary in that run.
- Removed the private/reserved-network rejection from AgentBus roster attachment URL validation and DNS resolution for this trusted internal deployment. Internal DNS names, private IPv4/IPv6 literals, and localhost now pass; credential-free HTTPS, successful DNS resolution, selected-address pinning, redirect revalidation, timeout, byte limits, declared size, optional SHA-256, and privacy-safe diagnostics remain.
- Updated the active AgentBus contract, control-plane operator documentation, canonical architecture/data flow/business rules/current state/evidence/decision/commitment memory, and regression coverage. No deployment, restart, Kubernetes mutation, secret read, ERP access, live-task retry, or external message occurred.
- Local integration and all required gates are complete; the authorized non-force `origin/main` push remains to be performed and verified.
## Verification
- Not run.
- Focused attachment test: 7/7 passed, including internal DNS, private IPv4/IPv6, localhost, credential rejection, and diagnostic redaction.
- Focused AgentBus/diagnostics/attachment regression before the final resolver assertion: 26/26 passed.
- `node --run check:repo`: 9/9 passed.
- `node --run check`: passed.
- `node --run test:control-plane`: 135/135 passed.
- `node --run test:legacy`: 255/255 passed.
- `node --run build`: passed.
- `sh -n infra/diagnose-server.sh infra/predeploy-check.sh`: passed.
- `check_project_docs.py`: passed.
- `git diff --check`: passed.
- Docker CLI is unavailable on this workstation, so Compose runtime expansion was not repeated; repository hygiene covers the checked-in Compose rotation structure.
## Follow-ups
- None recorded.
- Under separate authorization, build/deploy the integrated control-plane image with `DEPLOYMENT_REVISION` set, restart it, and verify one real internal WeChat roster attachment through the new diagnostic stages.
- ERP reads/writes, extension loading, deployment, and live-task retry remain outside this integration task.
## Promotion Candidates
- None recorded.
- None. Accepted attachment, diagnostics, deployment-boundary, and internal-network facts were promoted to canonical project memory during this Integration task.
+5 -2
View File
@@ -5,6 +5,9 @@
- `agent设计规范/business-adaptation-registry.md` is the cross-session business entry; each business maps user input, Skill/action, ERP flow, contracts, implementation, fixtures, and verification status.
- Manual and AgentBus tasks share the same 18 machine routes, task-scoped parser mode snapshot, and organization automation rules.
- The two passenger-list import routes are Program-only and wait for exactly one `.xls` or `.xlsx` attachment before deterministic normalization.
- A WeChat attachment card is transport placeholder text, not file content. Only a structured `payload.attachments[]` entry can resume a roster task; missing metadata fails before ingestion and leaves the original task in `awaiting_attachment` instead of creating a new task.
- The trusted internal deployment accepts credential-free HTTPS roster attachment URLs whose host is internal, private/reserved IPv4/IPv6, or localhost. DNS pinning, redirect revalidation, download timeout, byte limits, declared-size checks, and optional SHA-256 verification remain mandatory.
- AgentBus attachment diagnostics may record stage, address count/family, status, byte count, code, outcome, and duration, but never URL, hostname, IP, file name, bytes, message text, or roster values.
- Passenger overwrite requires confirmation when target ERP rows are occupied; after `full_replace + confirmed=true`, every attachment-specified sequence is written even when values are unchanged.
- A single strict `领队` row supplies leader contact; ambiguous, incomplete, duplicate, or structurally inconsistent leader data fails closed.
- Shared-mother-plan `整团游客信息` export is only `shared_plan + visitor-list + tid-only`; independent and concrete shared-child visitor lists remain `did+tid`.
@@ -15,8 +18,8 @@
- Fresh authorized runtime read verification remains for the shared-mother-plan whole-visitor export branch.
- Authorized current-version ERP write verification remains for SGL/TWN and four independent-order headcount categories.
- AgentBus OSS DNS fallback must preserve private/reserved-network SSRF blocking.
- Deployment/restart and one live internal attachment verification still require separate authorization.
## Last Reviewed
2026-08-28
2026-08-31
@@ -8,6 +8,10 @@ Use this index for searchable, traceable evidence records.
| 2026-08-28 | Current release capability and real-validation boundary | Current integrated evidence | [Lifecycle release gate](../../agent设计规范/test-fixtures/lwlt-lifecycle/release-gate.md) | Defines active conclusions and links immutable evidence. |
| 2026-08-28 | Release artifact hashes and sources | Machine-verified | [Release manifest](../../dist/release-manifest.json) | Seven current artifacts and their source/hash metadata. |
| 2026-08-28 | AgentBus reconnect and runtime switch | Verified at observation time; time-sensitive | [Archived legacy progress](../../archive/project-history/2026-08-28/legacy-planning-with-files-progress-final.md) | Repeated 4/4-ready samples after authorized restart; live status must be rechecked when needed. |
| 2026-08-30 | Chrome extension `0.5.163` and ACK deployment constraints | Source/release verified; not deployed by this task | [ACK and release task](../30-worklog/tasks/20260828-ack-deploy-guide-8c1d.md) | Records synchronized versions, package/source comparison, PostgreSQL/OSS requirements, migration ordering, and current single-replica constraint. |
| 2026-08-31 | WeChat attachment correlation | Repository verified; not deployed by this task | [Attachment-correlation task](../30-worklog/tasks/20260830-wechat-attachment-correlation-9f3a2c.md) | Strict conversation fallback and placeholder-only failure preserve the waiting task and prevent accidental task creation. |
| 2026-08-31 | Privacy-safe server diagnostics | Repository verified; not deployed by this task | [Diagnostics task](../30-worklog/tasks/20260830-server-diagnostics-c4d8a1f2.md) | Structured lifecycle diagnostics, redaction, bounded Docker retention, and read-only server inspection command. |
| 2026-08-31 | Production attachment failure | Root cause verified from supplied log | [Log-inspection task](../30-worklog/tasks/20260831-inspect-server-log-5d1e8a7c.md) | The original task remained waiting; the later structured attachment failed because DNS returned a private/reserved address. |
## When To Add Evidence
+1 -1
View File
@@ -6,7 +6,7 @@ Track future-facing memory: promised follow-ups, unfinished loops, timed checks,
|---|---|---|---|---|---|
| 2026-08-28 | Verify shared-mother-plan `tid-only` whole-visitor export against the current runtime ERP path. | Explicit user authorization for ERP read access | Future authorized task | Pending authorization | Run read-only source and artifact checks without external delivery. |
| 2026-08-28 | Verify independent-order SGL/TWN and adult/child/leader headcount mappings with real ERP writes. | Explicit user authorization for controlled ERP writes | Future authorized task | Pending authorization | Use reversible values and action-specific requery evidence. |
| 2026-08-28 | Resolve AgentBus OSS attachment rejection caused by private/reserved local DNS answers. | User schedules the networking task | Future feature task | Pending | Design controlled public-DNS or host-allowlist fallback; keep private-network blocking. |
| 2026-08-28 | Resolve AgentBus OSS attachment rejection caused by private/reserved local DNS answers. | User scheduled integration and confirmed the environment is trusted internal networking | Integration task `20260831-integrate-server-diagnostics-8b42c6d1` | Completed in repository | Deploy/restart and run one live internal attachment verification only under separate authorization. |
## Use