docs: promote plugin marketplace Release A

This commit is contained in:
brother7 committed 2026-08-30 15:36:52 +08:00
1 parent 40df677a31
commit 30f84fe973
8 files changed
+42 -1439

No files matched your search

+21
View File
@@ -2,6 +2,27 @@
## Durable Rules
- Marketplace Release A is curated: only Operations publishes packages. Users may
acquire an eligible Plugin for free; only server-declared metered operations may
later consume Token Points, and system-included Data Service remains zero-charge.
- Account Library, Device Installation, project enablement, Agent assignment, runtime
authorization, and billing are separate states. No read, install, acquisition, or
assignment may silently advance another state.
- Marketplace packages become effective only after closed manifest/descriptor parsing,
canonical archive and client-compatibility checks, Ed25519 verification, immutable
Package Store selection, project enablement, Agent projection, and current server
policy admission. Unknown or unavailable IDs remain persisted but do not materialize.
- A parent Pi worker freezes the exact verified package root, Skills, tools, policy,
Account, project, and Release for its lifetime; child workers receive no Plugin
resources. Lifecycle invalidation blocks new actions but does not hot-swap a running
worker or delete bytes it still owns.
- System-included Data Service ships with MakeLore and has no Library acquisition,
Admission, download, update, or device-uninstall action. Users may still enable it
per project and assign its Skill to an Agent.
- Production Marketplace trust fails closed while the official Ed25519 public key is
absent. Test-only/integration keys and packaged unknown-key rejection are evidence,
not authority to activate production. Release B hosted Provider runtime remains
closed behind its separate Provider gate.
- 面向用户的 AI 编程新建流程必须在 `mini_game`、`mini_program`、`custom` 中选择;`ProjectType` 是产品类型,创建后不能通过 UI 或 Host API 修改,未传类型的兼容 API 调用按 `custom` 处理。
- 新建小游戏和小程序会生成平台固定版本的受控 Vite 发布模板,并可使用项目配置中的单一“提交审核”入口;`custom` 和缺少类型字段的旧项目不提供一键发布。
- `ProjectType` 不等于 `BuildPreset`:第一期两个可发布产品类型都映射到内部受控 Vite preset;本地 `projectType` 不是授权边界,Main-owned 安全打包、Host API 和服务端包体校验仍必须执行。