Files
LWLT-AIBOT/.project-docs/30-worklog/tasks/20260831-integrate-server-diagnostics-8b42c6d1.md
T

5.4 KiB

Task: Integrate server diagnostics into main

Identity

  • Task ID: 20260831-integrate-server-diagnostics-8b42c6d1
  • Mode: Integration
  • Branch: main
  • Worktree: /Users/inmanx/Documents/lwltAPI
  • Base commit: 14aa6402d6
  • Owner: codex
  • Status: In progress

Scope

  • Merge the independently advanced origin/main, local project-governance/diagnosis commits, and the published WeChat attachment-correlation/diagnostics branch into main.
  • Preserve the remote deployment adaptations and Chrome extension 0.5.163 release while retaining the accepted .project-docs-only governance boundary.
  • Remove the private/reserved-network rejection from the AgentBus roster attachment downloader because the service and attachment source intentionally share a trusted internal network.
  • Preserve HTTPS, credential rejection, redirect revalidation, DNS resolution/pinning, byte limits, declared size, and SHA-256 verification while allowing internal hostnames, private IPv4/IPv6, and localhost.
  • Reconcile accepted promotion candidates into canonical data-flow, business-rule, architecture/current-state, evidence, and deployment documentation where supported.
  • Run all repository gates, commit the integrated result on main, and push it to origin/main.

Intent And Constraints

  • The user explicitly authorized merging all current work into main and pushing a new revision, and explicitly confirmed that the attachment source is expected to use a private address in the server environment.
  • The user subsequently clarified that private-network blocking is not required in this deployment. Do not add an allowlist or retain private/reserved address filtering for inbound AgentBus attachments.
  • Every initial URL and redirect target must still require credential-free HTTPS, resolve successfully, and use DNS pinning for the selected address. Logging must never record the attachment URL, hostname, IP, file bytes, or roster values.
  • Treat enabled AgentBus channels and their upstream bridge as the trusted input boundary for internal attachment URLs.
  • Resolve the root planning-file merge according to accepted decision DOC-001: remote implementation/release facts and immutable archives are retained, but retired root planning files are not restored as active sources.
  • Do not deploy, restart services, mutate Kubernetes, read secrets, access ERP, retry live tasks, or send external messages.

Outcome

  • Reconciled the independently advanced origin/main line with the local .project-docs governance history in merge commit c4c469f; retained Chrome extension/runtime 0.5.163, the synchronized release manifest and archives, and remote deployment facts without restoring retired root planning files.
  • Integrated WeChat attachment correlation and privacy-safe diagnostics in merge commit cd45ce1. Strict envelope conversation fallback and placeholder-only rejection preserve the original awaiting_attachment task and prevent an attachment card from becoming a second business task.
  • Inspected the user-supplied server log and confirmed that the actual attachment frame already carried structured metadata in the same conversation. It failed before task ingestion because its hostname resolved to a private/reserved address; correlation was not the failing boundary in that run.
  • Removed the private/reserved-network rejection from AgentBus roster attachment URL validation and DNS resolution for this trusted internal deployment. Internal DNS names, private IPv4/IPv6 literals, and localhost now pass; credential-free HTTPS, successful DNS resolution, selected-address pinning, redirect revalidation, timeout, byte limits, declared size, optional SHA-256, and privacy-safe diagnostics remain.
  • Updated the active AgentBus contract, control-plane operator documentation, canonical architecture/data flow/business rules/current state/evidence/decision/commitment memory, and regression coverage. No deployment, restart, Kubernetes mutation, secret read, ERP access, live-task retry, or external message occurred.
  • Local integration and all required gates are complete; the authorized non-force origin/main push remains to be performed and verified.

Verification

  • Focused attachment test: 7/7 passed, including internal DNS, private IPv4/IPv6, localhost, credential rejection, and diagnostic redaction.
  • Focused AgentBus/diagnostics/attachment regression before the final resolver assertion: 26/26 passed.
  • node --run check:repo: 9/9 passed.
  • node --run check: passed.
  • node --run test:control-plane: 135/135 passed.
  • node --run test:legacy: 255/255 passed.
  • node --run build: passed.
  • sh -n infra/diagnose-server.sh infra/predeploy-check.sh: passed.
  • check_project_docs.py: passed.
  • git diff --check: passed.
  • Docker CLI is unavailable on this workstation, so Compose runtime expansion was not repeated; repository hygiene covers the checked-in Compose rotation structure.

Follow-ups

  • Under separate authorization, build/deploy the integrated control-plane image with DEPLOYMENT_REVISION set, restart it, and verify one real internal WeChat roster attachment through the new diagnostic stages.
  • ERP reads/writes, extension loading, deployment, and live-task retry remain outside this integration task.

Promotion Candidates

  • None. Accepted attachment, diagnostics, deployment-boundary, and internal-network facts were promoted to canonical project memory during this Integration task.