docs: migrate project memory governance

This commit is contained in:
inman committed 2026-08-30 15:31:12 +08:00
1 parent 7b5d855b09
commit e7aa58a203
37 files changed
+942 -34

No files matched your search

@@ -0,0 +1,32 @@
# Data Flow
## Primary Flows
| Flow | Source | Destination | Notes |
|---|---|---|---|
| Business directive | Manual workbench or AgentBus | Route orchestrator | Source changes input/reply adaptation, not parser or confirmation policy |
| Parsing | Route orchestrator | AI Skill or deterministic Program parser | AI/Shadow/Auto/Program mode is frozen per task |
| Operation | Parser | Control-plane task and confirmation | Must validate against the same final contract |
| ERP execution | Confirmed task | Chrome extension and logged-in ERP page | Requires unique object, page identity, ownership, and write preflight |
| Completion evidence | ERP response/requery | Control-plane receipt and business reply | Evidence is action-specific; uncertain writes fail closed |
| Passenger workbook | Single `.xls/.xlsx` attachment | Deterministic encrypted canonical TSV | First row ignored, second row fixed header, exact leader-contact rules |
| Confirmation export | ERP source file | Archived source plus mobile delivery artifact | Visitor XLS becomes real XLSX; other types prefer PDF |
| Release | Editable source | `dist/release-manifest.json` and versioned artifacts | Manifest owns current hashes and filenames |
## State Ownership
- PostgreSQL owns durable control-plane task, session, confirmation, channel, audit, and outcome state.
- Production attachment bytes use the configured OSS provider; normalized sensitive fields remain encrypted.
- Chrome extension local state is bounded execution/reconciliation support, not canonical business history.
- `.project-docs/30-worklog/tasks/` owns task-local project memory; canonical project state is an integrated projection.
## External Interfaces
- Operator workbench at the control-plane service.
- AgentBus WebSocket channels and attachment delivery.
- Logged-in ERP browser pages under the Chrome extension host permissions.
- PostgreSQL, OSS, deployment gateway, and authenticated artifact download.
## Last Updated
2026-08-28
@@ -0,0 +1,34 @@
# Module Map
## Source Layout
| Path | Responsibility | Owner Notes |
|---|---|---|
| `agent设计规范/` | Business prompt, Skills, templates, registry, business pages, fixtures | Update business entry and Skill before downstream contracts when user fields change |
| `schemas/` | Current parse, execution, and ERP schemas | Historical schemas belong in `archive/` |
| `mappings/` | Current ERP fields, lifecycle, and extension-version mapping | Must stay synchronized with execution code |
| `control-plane/` | TypeScript control plane, migrations, parser and tests | Never hand-edit `.build/` output |
| `LianSyn-platform/` | Operator UI and external Agent parsing adapter | No task output or release packages |
| `chrome-extension/` | Current ERP extension source | Version bump and release synchronization required for code changes |
| `tools/` | Reusable builders, tests, diagnostics, and controlled write helpers | Tool outputs do not stay here |
| `infra/` | Deployment, backup, restore, and gateway configuration | No local secrets or database backups |
| `.project-docs/` | Durable task and canonical project memory | Governed by worktree ownership and Integration Gate |
| `dist/` | Current versioned delivery artifacts | Defined by `release-manifest.json` |
| `archive/` | Immutable dated history and evidence | Read-only authority boundary |
## Dependency Direction
- Business input/AgentBus → route orchestration → AI or Program parser → unified operation → control plane → Chrome extension → ERP.
- Business source documentation → Schema/mapping/implementation/tests → versioned artifacts; generated artifacts never become editable sources.
- Task-scoped `.project-docs` records propose durable changes; canonical documents consume them only through Integration Gate.
## Risky Or Sensitive Areas
- ERP write boundaries and reconciliation after uncertain responses.
- Attachment encryption, OSS network validation, and passenger workbook normalization.
- Cross-file release version and hash synchronization.
- Concurrent worktree ownership and canonical document integration.
## Last Updated
2026-08-28
@@ -0,0 +1,37 @@
# System Overview
## Current Architecture
Manual or AgentBus input is routed through task-scoped AI/Shadow/Auto/Program orchestration into one validated operation contract. The control plane owns task/session/confirmation/audit state, and the Chrome extension resolves the unique ERP object, enforces page and write gates, performs native actions, and returns action-specific evidence.
## Main Components
| Component | Responsibility | Notes |
|---|---|---|
| `agent设计规范/` | Agent Prompt, five parsing Skills, business templates, business registry, and stable fixtures | Editable source for business semantics; not runtime evidence |
| `schemas/` and `mappings/` | Parse-state, execution-state, ERP form, field, and lifecycle contracts | Current contracts only |
| `control-plane/` | Task/session persistence, parser orchestration, confirmation, audit, AgentBus, attachments, and receipts | TypeScript source; build output goes to `.build/` |
| `LianSyn-platform/` | Operator workbench and external parser adapter | Source and UI, not local task output |
| `chrome-extension/ltjt-order-assistant/` | Logged-in ERP resolution, preflight, native execution, response handling, and requery | Any code change requires synchronized versioned release updates |
| `dist/` | Versioned current deliverables and machine-readable release manifest | Not a compilation directory |
| `.project-docs/` | Task-isolated project memory and integrated canonical context | No runtime dependency |
| `archive/` | Date-scoped immutable history and evidence | Never defines current behavior |
## Important Boundaries
- AI/Program parsing and ERP resolution/execution share the final operation contract but do not share authority.
- Platform envelope fields such as task ID, session, parser decision, confirmation, transport, and audit never enter the business operation.
- Unknown, ambiguous, unverified, or post-write-uncertain states fail closed; automatic retries must not create duplicate writes.
- Canonical project memory is updated only under Integration Gate; feature tasks write only their task-scoped records.
## Related Decisions
- DOC-001
- ARCH-001
- ROUTE-001
- RELEASE-001
- SAFETY-001
## Last Updated
2026-08-28