# Task: Integrate server diagnostics into main ## Identity - Task ID: 20260831-integrate-server-diagnostics-8b42c6d1 - Mode: Integration - Branch: main - Worktree: /Users/inmanx/Documents/lwltAPI - Base commit: 14aa6402d6cff52ccf7abb373eb1896e16f6ae98 - Owner: codex - Status: In progress ## Scope - Merge the independently advanced `origin/main`, local project-governance/diagnosis commits, and the published WeChat attachment-correlation/diagnostics branch into `main`. - Preserve the remote deployment adaptations and Chrome extension `0.5.163` release while retaining the accepted `.project-docs`-only governance boundary. - Remove the private/reserved-network rejection from the AgentBus roster attachment downloader because the service and attachment source intentionally share a trusted internal network. - Preserve HTTPS, credential rejection, redirect revalidation, DNS resolution/pinning, byte limits, declared size, and SHA-256 verification while allowing internal hostnames, private IPv4/IPv6, and localhost. - Reconcile accepted promotion candidates into canonical data-flow, business-rule, architecture/current-state, evidence, and deployment documentation where supported. - Run all repository gates, commit the integrated result on `main`, and push it to `origin/main`. ## Intent And Constraints - The user explicitly authorized merging all current work into `main` and pushing a new revision, and explicitly confirmed that the attachment source is expected to use a private address in the server environment. - The user subsequently clarified that private-network blocking is not required in this deployment. Do not add an allowlist or retain private/reserved address filtering for inbound AgentBus attachments. - Every initial URL and redirect target must still require credential-free HTTPS, resolve successfully, and use DNS pinning for the selected address. Logging must never record the attachment URL, hostname, IP, file bytes, or roster values. - Treat enabled AgentBus channels and their upstream bridge as the trusted input boundary for internal attachment URLs. - Resolve the root planning-file merge according to accepted decision `DOC-001`: remote implementation/release facts and immutable archives are retained, but retired root planning files are not restored as active sources. - Do not deploy, restart services, mutate Kubernetes, read secrets, access ERP, retry live tasks, or send external messages. ## Outcome - Reconciled the independently advanced `origin/main` line with the local `.project-docs` governance history in merge commit `c4c469f`; retained Chrome extension/runtime `0.5.163`, the synchronized release manifest and archives, and remote deployment facts without restoring retired root planning files. - Integrated WeChat attachment correlation and privacy-safe diagnostics in merge commit `cd45ce1`. Strict envelope conversation fallback and placeholder-only rejection preserve the original `awaiting_attachment` task and prevent an attachment card from becoming a second business task. - Inspected the user-supplied server log and confirmed that the actual attachment frame already carried structured metadata in the same conversation. It failed before task ingestion because its hostname resolved to a private/reserved address; correlation was not the failing boundary in that run. - Removed the private/reserved-network rejection from AgentBus roster attachment URL validation and DNS resolution for this trusted internal deployment. Internal DNS names, private IPv4/IPv6 literals, and localhost now pass; credential-free HTTPS, successful DNS resolution, selected-address pinning, redirect revalidation, timeout, byte limits, declared size, optional SHA-256, and privacy-safe diagnostics remain. - Updated the active AgentBus contract, control-plane operator documentation, canonical architecture/data flow/business rules/current state/evidence/decision/commitment memory, and regression coverage. No deployment, restart, Kubernetes mutation, secret read, ERP access, live-task retry, or external message occurred. - Local integration and all required gates are complete; the authorized non-force `origin/main` push remains to be performed and verified. ## Verification - Focused attachment test: 7/7 passed, including internal DNS, private IPv4/IPv6, localhost, credential rejection, and diagnostic redaction. - Focused AgentBus/diagnostics/attachment regression before the final resolver assertion: 26/26 passed. - `node --run check:repo`: 9/9 passed. - `node --run check`: passed. - `node --run test:control-plane`: 135/135 passed. - `node --run test:legacy`: 255/255 passed. - `node --run build`: passed. - `sh -n infra/diagnose-server.sh infra/predeploy-check.sh`: passed. - `check_project_docs.py`: passed. - `git diff --check`: passed. - Docker CLI is unavailable on this workstation, so Compose runtime expansion was not repeated; repository hygiene covers the checked-in Compose rotation structure. ## Follow-ups - Under separate authorization, build/deploy the integrated control-plane image with `DEPLOYMENT_REVISION` set, restart it, and verify one real internal WeChat roster attachment through the new diagnostic stages. - ERP reads/writes, extension loading, deployment, and live-task retry remain outside this integration task. ## Promotion Candidates - None. Accepted attachment, diagnostics, deployment-boundary, and internal-network facts were promoted to canonical project memory during this Integration task.