Revert "merge: integrate extension auto-update"

This reverts commit 322475860a, reversing
changes made to f52d9d7413.
This commit is contained in:
inman committed 2026-09-03 16:45:14 +08:00
1 parent b2e33e2e5d
commit 81a0cdac8e
47 files changed
+169 -3108

No files matched your search

+11 -15
View File
@@ -4,8 +4,8 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
## Integrated Through
- Merge commit `3224758` integrating source commits `500034b` and `f08aac0` from tasks `20260903-adaptive-wait-auto-update-7b3e9a2c` and `20260903-service-extension-update-8d42c6f1` for adaptive ERP entry readiness plus central-service/private-OSS/ECS-Cloud-Assistant extension updates, migration 019, and extension `0.5.167`.
- Integration task `20260903-finalize-extension-update-a6c4e192` for acceptance of EXT-001, canonical update/release reconciliation, full release verification, and normal non-force synchronization to `origin/main`.
- Integration task `20260903-backup-revert-extension-update-c71a4e92` for preserving the complete former `0.5.167`/migration-019 iteration at remote branch `codex/backup-extension-update-20260903-b2e33e2`, reverting merge `3224758` without rewriting history, and restoring the active product/release baseline to `f52d9d7` (`0.5.165`, migration 018).
- Merge commit `3224758` and integration task `20260903-finalize-extension-update-a6c4e192` remain historical records of the briefly integrated extension-update design; that design is no longer active and is preserved on the backup branch only.
- Commit `c4c469f4441d744627af2d34abe693b6783e833c` for the independently advanced remote deployment/extension line.
- Commit `cd45ce17d0fcd25f7fa89ab9f8a391d3e904ecdf` for WeChat attachment correlation and privacy-safe server diagnostics.
- Commit `161f90d09d6ad1368973b1a85d51059059495223` for trusted-intranet attachment compatibility and canonical reconciliation.
@@ -33,7 +33,7 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
## Current Focus
Operate the repository's current `0.5.167` extension baseline and fixed-scope account model safely, bind each enabled AgentBus channel to one employee/ERP identity and ECS Windows host, provision narrow route grants, use explicit leadership-dashboard filters, and preserve Program/AI plus per-assigned-account ERP execution boundaries. Same-account tasks remain FIFO and single-active; distinct accounts are independent, and administrator visibility never enters another account's executable event/result path. Migration 019, one-time profile bootstrap, restricted RAM/OSS configuration, extension publication, Cloud Assistant canary, and service rollout remain separately authorized runtime work.
Operate the repository's current `0.5.165` extension baseline and fixed-scope account model safely, bind each enabled AgentBus channel to one employee/ERP identity, provision narrow route grants, use explicit leadership-dashboard filters, and preserve Program/AI plus per-assigned-account ERP execution boundaries. Same-account tasks remain FIFO and single-active; distinct accounts are independent, and administrator visibility never enters another account's executable event/result path. Migration 018, extension reload, guarded product-search retry, and service rollout remain separately authorized runtime work.
## Recently Completed
@@ -57,29 +57,26 @@ Operate the repository's current `0.5.167` extension baseline and fixed-scope ac
- 2026-09-02: Integrated extension `0.5.165`: scatter-plan creation and independent batch-order creation now try loaded product candidates, then the form's native non-empty `S_chanpinming` search, and finally one bounded empty-query compatibility reload. A user-authorized search-only ERP check returned exactly one target row in both forms without selecting or saving it; zero or multiple local matches continue to fail closed.
- 2026-09-03: Accepted AUTH-002 and integrated account-scoped ERP queues. Each immutable assignee now owns one FIFO/single-active claim partition, different accounts no longer block one another, and executable SSE/results/cleanup commands are owner-only even when an administrator is signed in.
- 2026-09-03: Restored explicit permanent force deletion as a separate operation from reversible archive/restore. It bypasses lifecycle-state gates, physically removes task-owned platform records, retains a minimal deletion audit marker, performs post-commit cleanup best effort, and warns that prior ERP effects are not rolled back.
- 2026-09-03: Added an immediate-first, conditional 100 ms readiness probe for scatter-plan entry. It proceeds without a fixed delay when the current ERP document is ready and fails closed before any write after the bounded timeout.
- 2026-09-03: Integrated extension `0.5.167` and migration 019. The separate central service can publish validated private OSS releases, group multiple accounts by ECS Windows host, wait for all mapped ERP workers to become safe, deploy through one-shot Cloud Assistant PowerShell with hash/staging/rollback/no-downgrade checks, and require profile reload plus target-version heartbeat before reopening ERP claims.
- 2026-09-03: Backed up the complete adaptive-readiness and central extension-update iteration at remote branch `codex/backup-extension-update-20260903-b2e33e2`, then reverted it from `main` with a normal history-preserving commit. The active repository again uses extension `0.5.165` and migration 018; the reverted iteration was never deployed by these tasks.
## In Progress
- The standard database currently contains one administrator account and no non-administrator task grants. Multi-account operational smoke testing remains for an administrator-led staging window.
- Migrations `018_agentbus_account_workers` and `019_extension_host_updates`, employee ERP identities/channel/host bindings, extension `0.5.167`, account-scoped queue/routing changes, force-delete behavior, and the merged dashboard/update runtime have not been applied to or restarted on the production service in this integration task.
- Migration `018_agentbus_account_workers`, employee ERP identities/channel bindings, extension `0.5.165`, account-scoped queue/routing changes, force-delete behavior, and the merged dashboard/runtime changes have not been applied to or restarted on the standard service in this integration task.
## Next Recommended Steps
1. In an explicitly authorized rollout window, back up PostgreSQL, apply migrations through 019, deploy the central service with automatic extension updates still disabled, manually load bootstrap extension `0.5.167` from the shared ProgramData directory in every profile, and verify each runtime heartbeat.
2. Configure a least-privilege ECS RAM identity, private OSS release prefix, HTTPS `APP_ORIGIN`, and exact account-to-ECS mappings; then enable updates and run one controlled higher-version canary through waiting → running → deployed → reload → verified before widening rollout.
3. Through the administrator UI, create representative team-lead and ordinary accounts, assign narrow task grants, and verify owner isolation, leadership dashboard reads, grant/revoke behavior, and denial prompts without ERP writes.
4. In the same authorized staging window, verify that an administrator receives no employee executable events/results, then force-delete disposable waiting and active employee tasks and confirm database absence plus cleanup only in the owning employee plugin.
5. With explicit authorization, run a live read-only ERP verification of the shared-mother-plan `tid-only` whole-visitor export path.
6. With explicit authorization, perform ERP write verification for independent-order SGL/TWN and adult/child/leader headcount mappings.
1. In an explicitly authorized staging/rollout window, back up PostgreSQL, apply migration 018, restart the control plane, load extension `0.5.165`, verify its runtime handshake, configure employee ERP identities and channel bindings, and run the multi-cloud-PC/identity/failover plus account-queue matrix before production assurance.
2. Through the administrator UI, create representative team-lead and ordinary accounts, assign narrow task grants, and verify owner isolation, leadership dashboard reads, grant/revoke behavior, and denial prompts without ERP writes.
3. In the same authorized staging window, verify that an administrator receives no employee executable events/results, then force-delete disposable waiting and active employee tasks and confirm database absence plus cleanup only in the owning employee plugin.
4. With explicit authorization, run a live read-only ERP verification of the shared-mother-plan `tid-only` whole-visitor export path.
5. With explicit authorization, perform ERP write verification for independent-order SGL/TWN and adult/child/leader headcount mappings.
## Open Questions / Blockers
- Shared-mother-plan whole-visitor export has historical read evidence and static coverage but lacks a fresh authorized runtime ERP read verification.
- Independent-order SGL/TWN and four headcount categories lack authorized current-version ERP write evidence.
- The production service has not been verified at merge commit `3224758`; its runtime schema, extension, account UI, queue/routing, force-delete, dashboard, and extension-update behavior must not be represented as the newly integrated repository state until an authorized rollout.
- Extension auto-update cannot be enabled safely until every existing Chrome profile has loaded bootstrap `0.5.167` from the shared ProgramData directory and the restricted ECS/OSS/HTTPS configuration plus one-host canary have been verified.
- The standard service was last restarted before commits `3062ed5`, `b5f5847`, `cc09506`, `336ca6e`, `e4fd916`, and `d09b303`; its runtime schema, extension, account UI, queue/routing, force-delete, and dashboard behavior must not be represented as the newly integrated repository state until an authorized rollout.
- AgentBus account-worker routing still lacks a live two-employee/two-cloud-PC staging matrix covering mismatched ERP login, same-account device conflict, 90-second stale failover, same-account FIFO, cross-account independence, administrator executable-feed isolation, and both manual and automatic channel work.
- Lifecycle-independent force deletion has repository regression evidence but lacks an authorized runtime smoke test for waiting/active deletion, database absence, OSS cleanup, and owner-plugin-only cleanup.
- A live internal AgentBus attachment verification remains separately unperformed.
@@ -92,7 +89,6 @@ Operate the repository's current `0.5.167` extension baseline and fixed-scope ac
- Account role changes, session revocation, creator-based task-route revocation, cross-user dashboard projection, and encrypted input audit are security-sensitive boundaries.
- AgentBus channel ownership, immutable task assignment, expected ERP identity, browser-worker freshness/failover, and administrator non-execution are security- and write-safety-sensitive boundaries.
- Account-scoped advisory locking, per-assignee FIFO queries, executable SSE/result routing, and irreversible force deletion are concurrency-, authorization-, and evidence-sensitive boundaries.
- Host-wide idle aggregation, update/claim serialization, short-lived package capabilities, Cloud Assistant idempotency, ProgramData path restriction, rollback, and post-reload version verification are security- and write-availability-sensitive boundaries.
- Release synchronization across extension source, minimum platform version, mapping, ZIP, Skills, DOCX, and `dist/release-manifest.json`.
## Last Updated
+2 -1
View File
@@ -9,4 +9,5 @@ This is integrated history. Feature tasks write only their task-scoped records;
| 2026-08-28 | Shared mother-plan whole-visitor export | Released strict `shared_plan + visitor-list + tid-only` routing and execution boundaries in extension `0.5.157`. | [Release gate](../../agent设计规范/test-fixtures/lwlt-lifecycle/release-gate.md) |
| 2026-09-02 | AgentBus account workers | Integrated one-to-one employee channel ownership, immutable task assignment, expected ERP identity, single-fresh-worker enforcement, migration 018, and extension `0.5.164`. | [Integration task](tasks/20260902-integrate-all-push-c93a7f21.md) |
| 2026-09-02 | Leadership dashboard query and filter contract | Integrated bounded single-connection reads, 20-row paging, cancellation/timeout feedback, display-only metrics, and explicit result filtering. | [Integration task](tasks/20260902-integrate-all-push-c93a7f21.md) |
| 2026-09-03 | Adaptive ERP readiness and extension host updates | Integrated immediate-first scatter-plan readiness plus private OSS release publication, multi-account ECS host safety, Cloud Assistant deployment, and heartbeat-verified extension `0.5.167`. | [Integration task](tasks/20260903-finalize-extension-update-a6c4e192.md) |
| 2026-09-03 | Adaptive ERP readiness and extension host updates | Integrated immediate-first scatter-plan readiness plus private OSS/ECS host updating as extension `0.5.167`; this iteration was later reverted from `main` before deployment. | [Original integration task](tasks/20260903-finalize-extension-update-a6c4e192.md) |
| 2026-09-03 | Extension-update iteration backup and rollback | Preserved exact commit `b2e33e2` on remote branch `codex/backup-extension-update-20260903-b2e33e2` and restored active extension `0.5.165` plus migration 018 through a non-force revert. | [Rollback task](tasks/20260903-backup-revert-extension-update-c71a4e92.md) |
@@ -0,0 +1,57 @@
# Task: Back up and revert extension update iteration
## Identity
- Task ID: 20260903-backup-revert-extension-update-c71a4e92
- Mode: Integration
- Branch: codex/20260903-finalize-extension-update-a6c4e192-finalize-extension-update
- Worktree: /Users/inmanx/Documents/lwltAPI-finalize-extension-update-a6c4e192
- Base commit: b2e33e2e5d29138891eabc93969cf24907492dfe
- Owner: codex
- Status: Planning
## Scope
- Preserve the complete extension-update iteration currently at remote `main` commit `b2e33e2` on a dedicated remote backup branch before changing `main`.
- Revert merge commit `3224758` through a normal history-preserving commit, restoring the active product source, migration boundary, extension release, and governed artifacts to the pre-iteration `f52d9d7` baseline.
- Preserve the source and integration task records as historical evidence, mark accepted decision `EXT-001` as reverted, and reconcile canonical project memory to the restored active architecture.
- Run the complete repository, release, document, test, and build gates, then advance remote `main` with a normal non-force push.
## Intent And Constraints
- The user explicitly requested a branch backup followed by rollback of this plugin-update iteration. This supplies the required human decision to reverse accepted architecture and product behavior.
- The exact backup ref is `codex/backup-extension-update-20260903-b2e33e2`; it must resolve remotely to `b2e33e2e5d29138891eabc93969cf24907492dfe` before the rollback continues.
- Roll back both commits carried by merge `3224758`: adaptive ERP entry readiness (`500034b`, extension `0.5.166`) and central OSS/ECS Cloud Assistant updates (`f08aac0`, migration 019 and extension `0.5.167`). The restored current release is extension `0.5.165` with required migration 018.
- Use `git revert`, not a force push or history rewrite. Keep prior task records and the reverted ADR so the decision trail remains auditable and recoverable from the backup branch.
- The local `main` checkout is owned by task `20260902-migrate-restart-confirmed-4f8c2a71` and contains its untracked task record. Do not alter, adopt, stash, reset, or clean that worktree.
- Do not deploy, restart, migrate a database, access ERP, publish to OSS, invoke Cloud Assistant, reload Chrome, mutate live tasks, or inspect secrets.
## Outcome
- Remote backup branch `codex/backup-extension-update-20260903-b2e33e2` was created first and independently verified at exact commit `b2e33e2e5d29138891eabc93969cf24907492dfe`.
- Reverted merge `3224758` in the isolated Integration worktree while retaining both source task records and the former integration record. Product source, dependencies, migration readiness, extension source, release package, mappings, tests, and operational documentation now match the pre-iteration `f52d9d7` tree exactly.
- Restored extension `0.5.165`, release ZIP SHA-256 `14f3150ab26d99131e32321ddc805a85550438bc2810a1e20921f7922b25aaac`, and required schema migration `018_agentbus_account_workers`; removed active migration 019 and the central OSS/ECS update implementation from the main-line result.
- Marked `EXT-001` as Reverted and reconciled the decision index, system overview, data flow, current state, task history, evidence index, and rollout commitment. Final rollback commit and remote `main` synchronization remain pending.
## Verification
- `git ls-remote --heads origin refs/heads/codex/backup-extension-update-20260903-b2e33e2`: returned exact commit `b2e33e2e5d29138891eabc93969cf24907492dfe`.
- `npm ci --no-audit --no-fund`: completed from the restored lockfile.
- `node --run check:repo`: 10/10 passed, including exact release-set hashes and extension ZIP/source equality.
- `node --run check`: passed.
- `node --run test:control-plane`: 162/162 passed.
- `node --run test:legacy`: 268/268 passed.
- `node --run build`: passed.
- `node --check` passed for extension `background.js`, `business-bridge.js`, and `inpage.js`.
- `unzip -t dist/ltjt-order-assistant-0.5.165.zip`: passed; SHA-256 equals the restored release manifest.
- Explicit version check returned source/release/artifact `0.5.165` and required migration `018_agentbus_account_workers`.
- `git diff --exit-code f52d9d7 -- . ':(exclude).project-docs'`: passed, proving the active product tree exactly matches the pre-iteration baseline.
- `check_project_docs.py`, `check_doc_drift.py --task-id 20260903-backup-revert-extension-update-c71a4e92`, and `git diff --check`: passed before commit.
## Follow-ups
- None planned. The reverted implementation remains available only on the named backup branch unless a future explicit decision revives it.
## Promotion Candidates
- None recorded.