docs: record model capability main branch delivery
Electron E2E / Electron E2E (macos-latest) (push) Has been cancelled
Electron E2E / Electron E2E (ubuntu-latest) (push) Has been cancelled
Electron E2E / Electron E2E (windows-latest) (push) Has been cancelled

This commit is contained in:
brother7 committed 2026-09-12 22:14:51 +08:00
1 parent 2888aaedac
commit 1d661f7a56
7 files changed
+87 -6

No files matched your search

@@ -1,5 +1,9 @@
# Data Flow
## Managed model capability flow
one-api 官方接口/文档事实与实际 group 路由交集 -> Works 完整快照和业务授权 -> model-config v2 -> Main 安全 Provider metadata -> 产品 reasoningChoice/图片输入校验 -> 冻结父/子运行上下文 -> Pi 请求钩子清除 SDK 控制字段并写入原生字段。Renderer 消费相同能力投影,缺失事实不做名称推测;详情见[官方能力决策](../10-decisions/ADR-2026-09-12-official-model-capabilities.md)。
## Primary Flows
| Flow | Source | Destination | Notes |
@@ -28,7 +28,7 @@ Makelore 是 Electron 桌面客户端。Renderer 负责项目操作与状态展
| Makelore Code Workspace | project/Agent/Conversation schema v2、产品中立 Snapshot/Patch、Composer 与时间线 | Conversation 本地创建且不等待 worker;sleep 关闭旧 SSE,视图挂载、项目切换、visibility/focus 会静默刷新已选 Snapshot;旧 OpenCode 会话备份后不再继续,Renderer 不导入 Pi RPC/event 类型 |
| Coding Host API & Composition | 唯一 `/api/coding/*` composition、202 acceptance/dedupe、SSE、附件/文件/交互/诊断 | Electron Main 拥有 project/Conversation 服务、选中目标、认证和错误脱敏;SSE 公开面只有 Snapshot 与 `patch-batch` |
| Pi Conversation Runtime | 一个长驻 Pi `0.84.2` Agent Server 承载每条 active/warm Conversation 的隔离逻辑 Runtime/Session/JSONL channel | 严格 LF JSONL RPC、generation recovery、Snapshot hydration;正式包从 staged `pi-runtime` manifest/root 定位并校验 Pi 包入口;top-level 逻辑 turn 并发 4、warm idle LRU 8;Server 退出统一使旧 channel 失效并按需单实例重启 |
| Pi Provider & Managed Resources | Provider catalog、thread-local secret projection、model/resource revision、Prompt/Skill/extension materialization、selected-model tools | 父凭据只进入选中逻辑线程的内存 credential store,child 凭据只进入该短命进程;Works `model_capabilities` 由 Main 严格归一化并作为安全 Provider metadata 持久化。Web Search 仅在精确 capability 存在时随冻结的 selected model/provider/credential 进入 parent tool catalog,并走普通模型计费;不回退 `agent_browser` 或独立 Hosted Provider。服务端 reasoning levels 优先于本地 profile,缺字段则清理 override 并回退;不扫描项目或用户的 `.pi/.agents/.codex`,不把 secret 或原始响应放进 argv、catalog 或 Renderer |
| Pi Provider & Managed Resources | Provider catalog、thread-local secret projection、model/resource revision、Prompt/Skill/extension materialization、selected-model tools | Works `model_capabilities_v2` 由 Main 归一化并持久化,作为受管模型图片/思考能力唯一依据;未知不回退本地 profile。Main 保存原生 reasoningChoice 并冻结供应商字段,经 Pi 请求钩子发送。父/子凭据仍限于目标执行上下文;Web Search 保持独立适配器、所选模型及普通模型计费,不回退 agent_browser;secret 不进入 argv、catalog 或 Renderer |
| Pi Extension, Subagents & Lifecycle | 必需的生成式 Makelore extension、Main 显式选定的已安装 extensions、UI interaction、ephemeral child、write lease 与 background run lease | Makelore bridge 固定为首个 extension,其余选定 extension 全部经 Pi 的 explicit additional paths 加载且 ambient discovery 关闭;child 并发 4、单次最多 8、禁止递归;active/uncertain run 不因页面隐藏或 confirmation timeout 被停止,replacement/stop 必须可解释并清理所有 ownership |
| Shared Agent Browser | Project-scoped sandboxed `WebContentsView`、Renderer 右侧面板与 Main-owned CDP bridge | 用户和 Agent 操作同一页面;Renderer 必须先提供可见 bounds,Agent `open` 最多等待 5 秒取得可见 viewport。Console/Network 诊断按 owner 引用计数;关闭面板、切换项目/模块、隐藏窗口或后台休眠会清理 view、debugger 与轮询。 |
| Code-owned Official Project Plugins | Existing Account acquisition or system-included delivery → project enablement → effective parent snapshot | Data Service、Game Resource 与 Project Scaffold 都不要求 Agent assignment,项目启用后自动进入每个父 Agent;child 不继承 Plugin。三者不经过设备下载、更新、Beta 或 artifact 签名;Game Resource 的一次确认由 Main 提交一次、内部轮询并把全部终态输出自动写入冻结的原项目,恢复本地交付不得重新生成或计费;Project Scaffold 的 `.mjs` 仍只来自签名客户端固定资源。需要分配的 Marketplace 下载包保持原规则。 |
@@ -69,11 +69,11 @@ Makelore 是 Electron 桌面客户端。Renderer 负责项目操作与状态展
- 正式包中的 Agent Server 必须以显式 staged `pi-runtime` 的 manifest/root 解析 Pi 依赖,校验导入入口未逃逸对应包目录;不得依赖脚本相邻目录、应用 `node_modules` 或系统包解析作为 fallback。
- 父 Pi worker 与 Agent Server 必须获得应用选择且不可被 worker overlay 覆盖的 `MAKELORE_NODE_EXECUTABLE`。包含脚本的 Device Package Skill 只能显式使用该 Node 路径,不得依赖系统 PATH。
- selected Provider credential 只投影到目标父逻辑线程的内存 credential store 或目标 child 进程;跨账号模型变化必须重建目标逻辑线程。确定性 Works user-context 缺失是 Provider-auth failure:失效缓存 credential、fail fast、固定脱敏提示,不得归类为 Pi crash。
- Works 下发的 per-model reasoning capability 是可选 Main-owned metadata,不是
Renderer 或 one-api 的权威。存在时只接受受支持的安全形状并覆盖目标模型的
本地 effort map;缺失时移除旧 override 并使用已验证本地 profile。`off` 在 Pi
wire 上表示 `thinking.type=disabled` 且不发送 `reasoning_effort`,启用档位保持
provider 原生值,当前 DeepSeek 产品投影为 `off`/`low`/`high`/`max`。
- one-api 获取官方能力事实,Works 应用业务权限后下发 v2,Main 负责归一化、
持久化与运行前校验。受管模型缺失能力保持未知,不使用模型名推测。
reasoningChoice 保存 default/disabled/enabled 与可选原生 effort,独立于 Pi
枚举;Main 冻结每次运行的供应商字段,Pi 钩子在请求时应用。default 不发送
控制字段;关闭及启用遵循实际 control_format。BYOK 和 Web Search 保持独立。
- Guided Hotspot Binding is implemented behind a Main-owned capability that is true by default; exact `NIANCODE_AI_HARDWARE_GUIDED_HOTSPOT_BINDING=0` disables it, while capability-read failure falls back to direct six-digit Binding. The guided state is process-local, opener failures expose only the same fixed address for manual copy, and Binding conflicts refresh the safe account overview.
- Robot hotspot scanning and connection are local Main operations that return before Works credentials/upstream access. Renderer may submit only an opaque candidate ID from the latest bounded scan; Main alone filters open printable `Xiaozhi-*` SSIDs, performs platform association, and verifies the exact current SSID.
- Hotspot discovery and connection do not authenticate a Robot. BSSID, interface/profile details, native diagnostics, location data, and Wi-Fi credentials never cross the Main boundary; permission or platform failure keeps the system-settings/manual path available.