merge: integrate remote main
Some checks failed
Electron E2E / Electron E2E (macos-latest) (push) Has been cancelled
Electron E2E / Electron E2E (ubuntu-latest) (push) Has been cancelled
Electron E2E / Electron E2E (windows-latest) (push) Has been cancelled

This commit is contained in:
2026-09-07 13:43:27 +08:00
124 changed files with 4233 additions and 6599 deletions

View File

@@ -4,6 +4,21 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
## Integrated Through
- Local AI Design activity frontier
`4b894c7e320cdf829888f63f501d176f051be7d7` and fetched remote frontier
`918f8f80dca61b0f561f96b168e4ef541734d414` are reconciled by the ordinary
two-parent merge prepared under task
`20260907-complete-current-merge-b61e4a93`. The semantic resolution keeps the
remote Code/Canvas/Plugin/Learning-removal product state while adding the local
Main-normalized, operation-scoped Design activity panel to the matching pending or
canonical user turn. Activity and assistant delta remain transient projections;
the central active production plan remains the Current Specification projection.
Typecheck, 90 focused tests, lint with 0 errors and 5 existing warnings, all Vite
targets, targeted Electron E2E 12/12, pressure 1/1, and staged-diff checks passed.
The ordinary unit suite passed 1,933 tests with 2 skips; its sole failure was the
unchanged Pi real-process two-second timing assertion, which also missed its limit
in isolation on this Windows host. No push, package, deployment, publication,
production database, paid Provider, or historical user-data change is claimed.
- AI Design operation activity source
`81b524a02c2cf51304090afa8fb89d27c72c5d2b` from task
`20260907-design-agent-activity-client-b6d913e4` is integrated by task
@@ -21,23 +36,6 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
tests, TypeScript, changed-file ESLint, and all Vite production targets. No server,
database, billing, Quote/Task, navigation, package, deployment, publication, or paid
Provider call changed.
- Coding project setup UX source `8042d2be265e40288e628fcdc755e9f29151306b`
from task `20260906-project-setup-ux-90fe6cf2` is integrated onto local `main`
by task `20260906-integrate-project-setup-ux-4b7d2e91`. A Coding Conversation is
ready only when the project is persisted as initialized and has at least one enabled,
unarchived project Agent with a non-empty name, avatar, role, responsibility, and
resolved model. Project-list entry, direct route resolution, the module gate, and the
Coding chat recovery surface all reuse that predicate. Project Configuration presents
the missing first Agent as a required step, sends users to model settings when no model
exists, persists the first valid Agent before entering chat, offers creation instead of
an unrecoverable edit for disabled-only projects, and uses labelled deterministic exit
actions with unsaved-change confirmation. A direct `/chat` visit without a ready Agent
renders a configuration recovery action without creating a Conversation/runtime or
exposing the Composer. Source verification passed 63 focused tests, the 1,928-test full
unit suite with 2 skips plus pressure, typecheck, lint with 0 errors/5 unchanged warnings,
all Vite targets, the targeted Electron flow, and independent review. Persistence,
Pi/runtime, Provider, Plugin, package, deployment, publication, and remote state are
unchanged.
- Token Point V2 account-usage source `6348e402a4e8dde712e5cba4620bb883ffe24e0b`
from task `20260906-trace-makelore-usage-3d7a5c1e` is integrated onto local
`main` by task `20260906-integrate-token-points-v2-7b4e1c92`. The account menu
@@ -103,6 +101,88 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
Vite targets. One unrelated two-second Pi real-process timing assertion failed in the
ordinary full run and passed 6/6 in isolation. A rebuilt/installed-client smoke remains
pending; local source integration does not replace an already installed binary.
- Remote `main` frontier `da29294` is semantically integrated with local
frontier `f53683a` under task
`20260907-integrate-remote-before-push-a4c9e27b`. The merge retains the
local directory-only project creation, Main-owned UUID, direct `/chat`
entry, non-blocking no-Agent state, Project Configuration-owned Plugin
sheet, and retired Learning surface. It also incorporates the compatible
remote official project-wide Plugin activation, automatic Game Resource
delivery, Agent Browser restoration, and Token Points V2 projection. The
remote initialized/full-Agent Conversation gate is intentionally not
adopted: `initialized` remains schema compatibility only, while truly
invalid project metadata still routes to Project Configuration. Verification
passed typecheck, 1,912 full-suite tests with 3 skips plus pressure 1/1, lint
with 0 errors and 5 existing warnings, production Vite build, and targeted
Electron 6/6. No live paid Provider generation, installed-client smoke,
deployment, publication, or production database change is claimed.
- September 6 completed product sources are integrated onto local `main` by task
`20260907-merge-all-changes-8f3c2a`: project-gate removal `af13aca` via
`39d7b7e`, Code landing `ce90f57` via `a91c7e3`, Plugin rehoming `be1764e`
via `f6c5961`, Canvas right-Works/reference-plan redesign `1562a49` via
`ea1219c`, and Canvas inspiration removal `b22559a` via `e069ec6`. The
semantic merge keeps directory-only project creation with Main-owned UUID,
direct `/chat` entry and a no-Agent state; moves the sole Plugin workspace to
the Project Configuration same-page sheet; keeps the active Canvas plan in the
central timeline with editable Prompt/reference aliases and a full-height right
Works rail; and retires the Prompt Museum Renderer entry while retaining its
dormant Main security contracts. Superseded Learning branches and unconfirmed
audit concepts were classified but not merged. Verification passed frozen-lockfile
install, typecheck, 184 focused tests, 1,882 full-suite tests with 3 skips plus
pressure 1/1, production build, and targeted Electron 12/12. Lint reported 0
errors and 5 existing warnings. No push, package, deployment, publication,
server, database, or historical user-data change was made.
- Remote `main` frontier `d642d7607c26dee01ef65b4e70dd756465dea16a`
is integrated with local frontier
`53f3db3aced61533944eab5e6b3c8c2293f733f8` by the ordinary two-parent merge
`a2cb07fedcf22bb14141a27cee2218c149b8c63e` under task
`20260905-integrate-remote-main-b83d6f`. The remote ADR-008 interactive AI
application type, bundled `makelore.project-scaffold` Skill, and bundled-delivery
status correction are retained alongside the local Learning removal: the product
still exposes only Code, Canvas, and Robot. Three canonical-document conflicts were
reconciled semantically, the application tree merged without content conflicts,
and README now describes minimal project creation plus explicit scaffold execution.
Verification passed 228 focused Vitest tests, the 12-test scaffold suite with the
canonical macOS temporary path, typecheck, 1,859 full-suite tests with 3 conditional
skips plus pressure 1/1, production build, and targeted Electron 1/1. Lint reported
0 errors and 12 existing warnings. The default macOS `/var` temporary-path alias
still makes two copied-script scaffold tests exit before emitting JSON; the same
tests pass through the canonical `/private/var` path and remain a harness/path
portability follow-up. The two remote task records stay intact in remote parent
`d642d76` rather than being copied into this integration result. No push, package,
deployment, publication, or production database change was made.
- Remote `main` frontier `336e0bb0caf24537b7b0f350aba3e04a37f5544c`
is integrated with local frontier
`2d3c103bac83fccffb15b760a6e79912c352541a` by the ordinary two-parent merge
`2d0322ef7a98c99fb28de4902506ea135ccd9389` under task
`20260904-merge-remote-main-91c4e7`. The remote AI Design streamed-reply,
pending-chat, and Quote handoff changes are retained, while the local Learning
removal remains authoritative: the active product still exposes only Code,
Canvas, and Robot. A matching `design.assistant.delta` may appear only as one
provisional assistant bubble for its pending chat and is replaced by the
canonical turn; the removed generic organizing-progress banner stays absent.
Remote source task records remain in their source-parent history rather than being
copied into this integration result. Verification passed frozen-lockfile install,
35 focused tests, typecheck, 1,845 full-suite tests with 3 conditional skips plus
the pressure test 1/1, production build, and targeted Electron 5/5. Lint reported
0 errors and 12 existing warnings. No remote push, deployment, publication, or
packaged-app lifecycle change was made.
- Learning-removal source `5a7cb9b2085848631bdf7de45fe1cac74b905ed9` from task
`20260903-remove-learning-7a91` is integrated onto the latest local `main` as
`bd0873f34823754760368d8d37703c74bf65106d` by task
`20260904-integrate-remove-learning-6e4a9c21`, preserving the later AI Design
and unified Plugin workspace changes. Makelore now exposes only Code, Canvas,
and Robot; the Learning route tree, Renderer, Main Host API, download service,
shared DTOs, artwork, tests, server contract, and packaging surface are removed.
Stale Learning URLs return to the module chooser and retired Host API paths use
the standard not-found boundary. Historical course data remains untouched and
unread, while `makelore-learning:v1` stays byte-for-byte frozen only as a shared
account-partition compatibility salt. ADR-005 and the Learning deployment
commitment are superseded by the user's explicit 2026-09-04 product decision.
Integration verification passed dependency lock install, 8 focused files / 109
tests, typecheck, full unit 1,844 with 3 skips plus pressure 1/1, production build,
targeted Electron 8/8, and full Electron 33/33 with 1 platform skip. Lint reported
0 errors and only existing warnings in current source and a historical worktree.
- Unified Plugin workspace bundled-delivery fix source
`6bd9287c879dca93da11e17533f84e3535fc656a` from task
`20260905-plugin-download-action-6c8e4a21` is integrated onto local `main` as
@@ -272,8 +352,9 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
local and remote mainline histories with normal merge `d25ed08`: fetched
`origin/main` frontier `28e1690` and local frontier `301c149` are both ancestors
of the integrated tree. It also reviewed every local worktree/branch; historical
Learning Player source `b1f51be` remains intentionally excluded under ADR-005,
rather than being mistaken for current product work. No history rewrite or
Learning Player source `b1f51be` remains intentionally excluded and the later
complete Learning removal supersedes ADR-005, rather than that source being
mistaken for current product work. No history rewrite or
force-push is part of this integration.
- Packaged Pi runtime-root source `5d7a235` from task
`20260902-build-unsigned-mac-9d7e4a2c` is integrated through merge `4babd6d`.
@@ -332,8 +413,8 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
and collapsed process previews remain anchored to their first displayable
line. Those predecessor Project Configuration Plugin surfaces are superseded by
the reviewed unified `/plugins` workspace above and are not restored. Historical
source `b1f51be` remains explicitly excluded because
ADR-005 continues to retire the OpenMAIC Learning Player packaging chain.
source `b1f51be` remains explicitly excluded; the 2026-09-04 product decision
supersedes ADR-005 and removes the remaining Learning catalog surface as well.
- Youth-facing AI Design client source
`0fd32a2d49045a8f9e7f2e19ba6477f48f93e30c` is integrated over Model Tools
frontier `7552cf59526449c29d663a769c0fb62d84a1a759` through merge
@@ -664,14 +745,15 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
their existing boundaries. The matching Works Square source is `65ea070`.
- Learning project-catalog source commit `38db158` from feature task
`20260819-learning-project-catalog-impl-4e9c71a2` was merged as `d967b0f` by integration task
`20260820-integrate-learning-catalog-a73e91c4`. Learning keeps its login and
`20260820-integrate-learning-catalog-a73e91c4`. At that historical checkpoint Learning kept its login and
`module_access.learning` gate but now contains only a server-driven project list,
safe README detail, direct credential-free HTTPS Markdown images, and a Main-owned verified
native ZIP save path. Course generation, progress, local library, OpenMAIC player,
Agent/ASR/classroom runtime, Learning IPC and player-artifact packaging were removed
without a compatibility read path. Historical course data is left untouched. The
matching Works Square operations/admin/API implementation and real-account package
smoke remain pending.
smoke remained pending. The 2026-09-04 removal recorded at the top of this file
supersedes that catalog and its deployment obligation.
- Square-auth lifecycle source commit `dc776ff` from feature task
`20260819-square-auth-proxy-client-8c4f2a` was merged as `f52c2c8` and promoted
from verified candidate `e7ec12d` to local `main` by integration task
@@ -706,7 +788,7 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
- Project-cover source commit `145a6ce571d646325092d1e722282babea503954` from feature task `20260817-project-cover-upload-a6a98e56`, integrated by task `20260813-sync-push-main-9c2f71`. First submission now requires a bounded PNG/JPEG/WebP cover, shows preview/file/reselect feedback, and sends metadata plus cover through Main-owned `POST /api/projects/with-cover`; conflicts stop before version upload and existing draft/published projects remain version-only. The matching Works Square server source is `407c883` (local merge `0cedfc4`). No client package, production deployment, or real-account smoke occurred.
- `3b37ac3` / `55e61b7`: macOS Robot hotspot discovery performs one bounded worker-thread rescan after an empty or SSID-redacted CoreWLAN result; persistent SSID redaction maps to the existing permission error instead of a misleading empty-device state, while firmware and the open `Xiaozhi-*` contract remain unchanged.
- `f5d47c8` / `b6148a5`: AI Programming voice capture is available after an Agent is selected but before the lazy first OpenCode session exists; transcription fills the composer draft without creating an empty session, while runtime, loading, transcribing, busy, and recording guards remain unchanged.
- `4013edc` / `3b799af`: integrated per-user Code/Canvas/Learning/Robot entry policy from Works Square, projected by Electron Main as four booleans and enforced before disabled module routes initialize.
- `4013edc` / `3b799af`: historically integrated per-user Code/Canvas/Learning/Robot entry policy from Works Square. The 2026-09-04 removal narrows the current Main projection to Code/Canvas/Robot while preserving the same pre-initialization route gate.
- `01bee31`: historically enabled the AI Learning course catalog/generation/download/playback architecture. Its Learning course/runtime behavior is superseded by `38db158` above; its unrelated `game-engine` removal and project-root `planning-with-files` behavior remain historical context.
- `26b52d7`: Canvas Prompt Museum, editable server-priced generation Quotes, project deletion/task-detail workflow, cloud-default Canvas development entry, and Chinese-only UI consolidation from the authoritative remote main. Its transient bundled `game-engine` Skill is superseded by `01bee31`.
- `f8d82e6`: Prompt Museum media rendering now accepts only the server-controlled relative media route, fetches it through a Main-owned bounded Works-authenticated proxy with one refresh retry, and keeps credential-free HTTPS CDN media direct. Renderer-side validation and card-local placeholders cover invalid or failed media; attribution URLs remain optional.
@@ -732,23 +814,25 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
## Current Focus
客户端面向非专业用户提供“创建交互式 AI 应用 → 明确调用官方 bundled Project Scaffold Skill 生成起步文件 → 项目配置中一键提交 → Main 本地 npm/Vite 构建 → Electron 双视口预检最终产物 → 上传 source+built 双归档与 contract → 运营审核”的唯一创建者链路。项目创建只生成 `.makelore/project.json` 和 `knowledge/`;`makelore.project-scaffold` 只负责不覆盖的固定起步树与只读发布准备度说明,不能安装、构建、上传、提审或批准。其 `.mjs` 只从签名客户端固定资源加载,Marketplace 下载 artifact 仍拒绝脚本。Main 对安全源码快照运行安装包内固定 npm 11.6.2 的 `npm ci --ignore-scripts`,再显式调用项目 `package-lock.json` 锁定的 Vite;Vite config/plugins 以当前桌面用户权限执行,因此只适用于用户信任的本地项目,不是 sandbox。预检由 Main 以临时 loopback origin 和 Electron WebContents/CDP 检查与最终 `built_archive` 相同的内存文件字节,覆盖桌面/移动视口、运行错误、白屏和外域访问;不使用 Playwright。该检查仍可由非官方客户端绕过,不产生可信 receipt,也不复刻生产 opaque-origin。服务端不再替客户端运行项目 Vite,而是把源码、构建归档和 contract 视为不可信输入,逐字节重算与校验并固化不可变 Release;人工审核仍不可绕过。`custom` 和缺少类型字段的旧项目不提供该入口;历史 `mini_game` / `mini_program` 只在读取边界归一为规范 `interactive_ai_app`。已发布作品优先使用安全投影后的 `play_url`,`runtime_url` 仅保留一个客户端版本的兼容回退。
客户端面向非专业用户提供“选择目录创建交互式 AI 应用 → 直接进入聊天 → 按项目需要可选调用官方 bundled Project Scaffold Skill → 项目配置中一键提交 → Main 本地 npm/Vite 构建 → Electron 双视口预检最终产物 → 上传 source+built 双归档与 contract → 运营审核”的唯一创建者链路。普通新建不展示类型、模板、原始 UUID、绑定或独立副本选项;Renderer 写入内部默认 `interactive_ai_app`,Main 生成 UUID,并只创建 `.makelore/project.json` 与 `knowledge/`。有效旧配置仅缺 `projectId` 时由 Main 串行补齐;旧 `initialized` 仅保留兼容,不再阻断导航、聊天或首个 Agent。既有 `custom` 和历史类型继续兼容,但不作为普通新建选择。`makelore.project-scaffold` 不是创建前置条件,只负责不覆盖的固定起步树与只读发布准备度说明,不能安装、构建、上传、提审或批准;其 `.mjs` 只从签名客户端固定资源加载,Marketplace 下载 artifact 仍拒绝脚本。Main 对安全源码快照运行安装包内固定 npm 11.6.2 的 `npm ci --ignore-scripts`,再显式调用项目 `package-lock.json` 锁定的 Vite;Vite config/plugins 以当前桌面用户权限执行,因此只适用于用户信任的本地项目,不是 sandbox。预检由 Main 以临时 loopback origin 和 Electron WebContents/CDP 检查与最终 `built_archive` 相同的内存文件字节,覆盖桌面/移动视口、运行错误、白屏和外域访问;不使用 Playwright。该检查仍可由非官方客户端绕过,不产生可信 receipt,也不复刻生产 opaque-origin。服务端把源码、构建归档和 contract 视为不可信输入,逐字节重算与校验并固化不可变 Release;人工审核仍不可绕过。历史 `mini_game` / `mini_program` 只在读取边界归一为规范 `interactive_ai_app`。已发布作品优先使用安全投影后的 `play_url`,`runtime_url` 仅保留一个客户端版本的兼容回退。
AI Design Canvas 现在默认以对话和一张持续可见的“我的创作”卡服务 8-16 岁创作者;专业字段矩阵收进按需打开的“精细调整”,移动端保持对话优先并只挂载一个卡片/底部面板。Creation Card、精细调整、Quote、Task 与结果提示都只投影权威状态,已知问题按 code 转成通俗中文,未知服务端或 Provider 文本不会直接显示。一个 Workspace 仍只公开一个 current Direction、一个 persistent Agent Session 和一个 Current Specification;conversation timeline 只记录交互历史。Chat、direct edits、decision responses、proposal acceptance、locks、Asset binding 与 restore 都通过 `design.input.apply` 进入同一服务端 reducer,Renderer drafts 在 accepted 前保持本地。Main 持有 Works Token、stream ticket、WebSocket、request deadline、stable command/operation IDs 与错误脱敏;unknown result 只能复用原 identity,结构化业务错误不得重放。Generation 由服务端对 exact Specification revision 编译 immutable Quote,客户端只展示 public output plan、warnings、expiry 与 Token Points,并以 Quote ID 调用 `design.generation.confirm`;Provider Prompt、model、route、storage 和 billing atoms 不进入 Renderer。Task/Asset events 独立收敛 Workspace resources,不改写 Living Form。Development 与 packaged builds 均使用 Works Square V2,V1 DTO、local semantic adapter、mutable Quote PATCH 与 editable provider Prompt 已移除。
AI Design Canvas 现在以中央 conversation timeline 加唯一 active 制作方案、右侧 320–340 px 全高 Works rail 的两区布局服务创作者;Canvas 路由不挂载全局左栏,紧凑宽度把同一 Works rail 放进右侧 Sheet。Active 方案的 `content.concept` 直接作为可编辑“创作提示词”,类型、画幅、视频时长和数量保持紧凑直控;已提交、运行中或终止方案折叠进对话历史。Reference 使用稳定 reference ID、真实 Workspace Asset binding 与连续 `@图片N` alias;Prompt 是用途的唯一可见表达,binding row 只管理缩略图、文件、alias、替换与删除。未绑定 alias 提供定点上传并阻止 Quote,Prompt/reference/参数变更产生新 Specification revision 和新 immutable Quote。一个 Workspace 仍只公开一个 current Direction、一个 persistent Agent Session 和一个 Current Specification;conversation timeline 只记录交互历史。Chat、direct edits、decision responses、proposal acceptance、locks、Asset binding 与 restore 都通过 `design.input.apply` 进入同一服务端 reducer,Renderer drafts 在 accepted 前保持本地。Main 持有 Works Token、stream ticket、WebSocket、request deadline、stable command/operation IDs 与错误脱敏;unknown result 只能复用原 identity,结构化业务错误不得重放。Generation 由服务端对 exact Specification revision 编译 immutable Quote,客户端只展示 public output plan、warnings、expiry 与 Token Points,并以 Quote ID 调用 `design.generation.confirm`;Provider Prompt、model、route、storage 和 billing atoms 不进入 Renderer。Task/Asset events 独立收敛 Workspace resources,不改写 Living Form。Development 与 packaged builds 均使用 Works Square V2,V1 DTO、local semantic adapter、mutable Quote PATCH 与 editable provider Prompt 已移除。
新提交的 Design chat 会立即从现有 pending operation 投影为带“发送中”或“正在确认”的临时用户气泡,服务端确认的 canonical turn 到达后再替换它;确定失败时原草稿重新出现在输入框。`design.assistant.progress` 经 Main 归一为固定通俗阶段,只在对应用户气泡下形成可更新、可折叠的“AI 处理过程”,不成为对话消息、右侧摘要或模型思考过程。`design.assistant.delta` 仅把已验证并提交的回复临时绘制为同一 operation 的未完成助手气泡,随后由 canonical turn 替换;不生成独立全局整理栏。右侧 Current Specification 摘要继续承担“AI 当前听懂的内容”。重复连接和事件按 connection generation、operation identity 与 `chunkIndex` 收敛。
新提交的 Design chat 会立即从现有 pending operation 投影为带“发送中”或“正在确认”的临时用户气泡,服务端确认的 canonical turn 到达后再替换它;确定失败时原草稿重新出现在输入框。`design.assistant.progress` 经 Main 归一为固定通俗阶段,只在对应用户气泡下形成可更新、可折叠的“AI 处理过程”,不成为对话消息、中央制作方案或模型思考过程。匹配同一 pending chat 的 `design.assistant.delta` 只临时绘制为一个未完成助手气泡,随后由 canonical turn 替换;它不进入 conversation timeline,也不生成独立全局整理栏。中央 active 制作方案继续呈现 AI 当前整理出的 Current Specification 公共投影。重复连接和事件按 connection generation、operation identity 与 `chunkIndex` 收敛。
Canvas 侧栏提供“获取灵感”进入 Prompt Museum。列表、筛选、分页、详情、作者/来源/许可证和图片地址全部由服务端经 Main-owned Host API 提供,客户端不打包静态数据集;服务端相对媒体只允许固定 `/api/image-prompt-museum/{entry}/media/{thumbnail|number}` 形状,并由 Main 注入 Works Bearer、执行一次 401 刷新、可信 raster MIME 与 10 MiB 上限后转为 Renderer data URL;credential-free HTTPS CDN 图片保持直连。图片失败只显示卡片内占位,不阻断卡片或详情;缺少来源 URL 时显示纯文本。“使用此 Prompt”只把原文带回当前 Canvas 输入框,不自动发送。该模块不是投稿、点赞、评论或排行榜社区。客户端契约已就绪,但不据此宣称 Works Square 内容后台和生产数据已经部署。`pnpm run dev` 现在默认使用云端 Canvas 适配器,本地适配器只能通过显式开发命令启用;产品 UI 只保留中文。
Prompt Museum 已退出当前产品面:Canvas 不再显示“获取灵感”,App 不挂载或 lazy-load Museum Renderer 页面,历史 `/image-prompts/*` 只重定向到 `/image-canvas`。Main-owned 固定 API、Works 认证、相对媒体路径校验、单次 401 刷新、可信 raster MIME/10 MiB 上限与共享 DTO 暂作为 dormant 兼容/安全基础设施保留,不代表可见模块或生产内容已启用;恢复入口需要新的明确产品决定。`pnpm run dev` 与 packaged Canvas 均使用云端 V2 适配器,产品 UI 只保留中文。
密码登录提供可选“记住密码”。该记录与七天登录会话分离,只在正式安装包且系统安全存储可用时由 Electron Main 加密落盘;Renderer 仅在登录页内存中接收回填,不写 Zustand/localStorage,Works Square 也不持久化桌面密码。退出登录和短信登录不删除记录,成功的未勾选密码登录会清除旧记录。未打包开发版禁用该选项,避免未签名 Electron 调试进程触发 macOS 钥匙串。
Makelore 在会话恢复、登录和刷新后由 Electron Main 请求 Works `/api/auth/me`,Renderer 只获得 Code、Canvas、Learning、Robot 四个布尔权限。缺失 `module_access` 或任一字段时默认开启;服务端 `design` 显式映射客户端 `painting`。被关闭的模块卡片置灰且不可点击,根路由、深层路由和别名路由均在 `MainLayout` 或模块初始化前阻断。Code provider 等待认证权限加载完成;权限查询返回终止性 `401` 时同时清理 Main 和 Renderer 会话。`/settings` 是全局设置,不受 Code 入口策略阻断。该机制只是客户端入口策略,不代替服务端 API 授权。
Makelore 在会话恢复、登录和刷新后由 Electron Main 请求 Works `/api/auth/me`,Renderer 只获得 Code、Canvas、Robot 三个布尔权限。缺失 `module_access` 或任一字段时默认开启;服务端 `design` 显式映射客户端 `painting`,额外旧字段被忽略。被关闭的模块卡片置灰且不可点击,根路由、深层路由和别名路由均在 `MainLayout` 或模块初始化前阻断。Code provider 等待认证权限加载完成;权限查询返回终止性 `401` 时同时清理 Main 和 Renderer 会话。`/settings` 是全局设置,不受 Code 入口策略阻断。该机制只是客户端入口策略,不代替服务端 API 授权。
插件在编程侧栏只有一个“插件”入口,`/plugins` 是唯一产品页面,并以统一列表投影 Marketplace、账号 Library、官方设备状态、本机 Device Packages、当前项目状态与 retained IDs;旧 `/plugin-marketplace`、`/my-plugins` 与 `/project-plugins` 路由只做确定性筛选重定向。获取、设备安装、项目启用、Agent Skill 分配、运行授权和计费仍是独立生命周期,不因界面统一而自动推进;原生 selected-model Web Search 不进入插件列表。Game Resource 在一次计费确认后由 Main 提交一次并内部轮询,终态全部输出自动写入调用时冻结的原项目;Agent 不再轮询状态、选择保存路径或进行第二次保存确认,交付恢复也不得重新生成或重复计费。
插件工作区由 Project Configuration 页面拥有:模型、Skill、知识旁的“插件” ResourceCard 打开 `/project-config/plugins` 对应的同页宽 Sheet,配置页保持挂载;没有 active project 时仍可查看账号与本机插件。Code 侧栏不再提供独立入口,`/plugins`、`/plugin-marketplace`、`/my-plugins` 与 `/project-plugins` 只保留查询/筛选意图并兼容重定向。统一列表继续投影 Marketplace、账号 Library、官方设备状态、本机 Device Packages、当前项目状态与 retained IDs;获取、设备安装、项目启用、运行授权和计费仍是独立生命周期。Data Service、Game Resource 与 Project Scaffold 在满足交付/获取条件并由项目启用后自动进入每个父 Agent,不提供伙伴分配;采用 assignment scope 的其他插件继续由 Agent Skill 分配控制。Game Resource 在一次计费确认后由 Main 提交一次并内部轮询,终态全部输出自动写入调用时冻结的原项目;Agent 不再轮询状态、选择保存路径或进行第二次保存确认,交付恢复也不得重新生成或重复计费。原生 selected-model Web Search 不进入插件列表。
AI 学习现在是已启用的运营精选项目目录,并继续受登录和 `module_access.learning` 控制。Renderer 通过 Main-owned Host API 获取分页项目卡片和 README 详情;Markdown 支持 GFM、禁用原始 HTML。服务端发布时只校验图片 URL 为无凭据、默认端口、无 fragment 且当前 DNS 结果全部为公网地址的 HTTPS URL,保留地址而不下载、识别格式、转码或镜像;客户端仅为 README 图片节点启用直连,因此 SVG 和 Electron 支持的其他格式可直接显示,单图失败不阻断详情。封面和历史发布媒体继续走受控路径。详情页的下载按钮打开系统保存对话框;Main 将 ZIP 流式写入临时文件,只允许最多五跳同 Works origin 重定向,不校验 `Content-Length`、`archiveBytes`、实际流字节数或客户端大小上限,校验 SHA-256 和 ZIP 签名后原子保存,Renderer 只接收 `saved` 或 `cancelled`。课程生成、进度、本地课程库、OpenMAIC player、Agent、ASR、课堂 runtime、Learning IPC 和 player artifact 打包已删除且没有兼容读取路径;历史课程数据保留但不再读取。服务端和客户端源码契约已完成,不代表生产部署或真实账号安装包联调已经完成。
Learning 已从 Makelore 产品中移除:没有模块卡片、路由、侧栏、Renderer 页面、Main Host API、下载服务、共享 DTO、素材或打包 fallback。旧 Learning URL 回到模块选择页,旧 API 使用标准 404 边界。客户端不扫描、读取、迁移或自动删除历史课程数据;名称仍含 Learning 的冻结账号分区盐仅为跨模块持久状态兼容标识,不代表产品模块仍存在。
AI 编程已经硬切到精确 pin 的 Pi `0.84.2`,不存在 OpenCode fallback 或双 runtime。project、Agent 与 Conversation 只在 `.makelore/project.json` 和 `.makelore/conversations.json` 使用本地 schema v2;当前客户端不从 `.niancode` 或 `.opencode` 读取、迁移或删除项目元数据。Coding Project 只有在 `initialized` 且至少存在一个启用、未归档、名称/头像/角色/职责/解析模型完整的项目 Agent 时才可进入 Conversation;项目入口、路由门禁、配置完成和 Chat 恢复必须复用共享判定,不能单独信任 `initialized`。Electron Main 按需启动一个长驻父 Agent Server,每条 active/warm Conversation 在其中拥有独立 Runtime/Session/channel、credential store、extension context、generation/seq、Snapshot/Patch、model/thinking、队列、interaction 与错误状态,Composer 在 lazy prepare 期间仍可编辑;正式包从 staged `pi-runtime` manifest/root 定位并校验 Pi 包入口,不从脚本目录或应用 `node_modules` 回退。Renderer 只通过 `/api/coding/*` 和 Snapshot-first/`patch-batch` SSE 消费产品中立合同;gap/reconnect 只恢复目标 Conversation,accepted/uncertain mutation 不自动重放。`lifecycle:sleep` 会关闭旧事件流,视图挂载、项目上下文变化、页面重新可见或窗口 focus 会静默刷新已选 Snapshot,使后台 terminal 状态收敛且不重放 mutation。隐藏 Conversation 的红点只在新 pending interaction 或新 completed/failed/aborted terminal transition 出现,不由助手/thinking/工具过程或单个工具失败触发。Session hydration 沿完整 active branch 投影可见历史,Pi compaction 只改变模型上下文并保持 summary 私有;Renderer 首次挂载最近 120 个节点,向上滚动时按 100 个节点追加更早内容并补偿新增高度以保持阅读锚点。折叠的 thinking、助手过程说明与工具输出固定展示第一条可见内容和首个非空行,横向偏移保持为零,展开后仍显示完整内容。未解析 Conversation 第一次选模先 validate 并持久化 resolved metadata,再 prepare;同账号模型切换使用 target `set_model`,跨账号只重建目标逻辑线程。Web Search 只作为所选模型 capability 进入父 worker 并使用相同 model/provider/credential 与普通模型计费,不经过 Marketplace/Hosted client/Plugin Charge 或浏览器 fallback;child 不继承。Conversation 工具可检查并在独立确认后安装 npm、Git、本地 Plugin 目录或 loose `SKILL.md` 为 Main-owned immutable Device Package;不运行生命周期脚本,可执行 extension 具有桌面用户权限,新/idle parent 自动刷新,active parent 结算后刷新,child 为空。每个 Main-selected generation 都保留全部显式安装且当前启用的 Skill 路径;生成的 Makelore bridge 是必需的首个 extension,其余 extension 全部经 `additionalExtensionPaths` 加载,并继续关闭 ambient discovery。top-level 逻辑 turn 并发为 4,warm idle logical-thread LRU 为 8;independent child 进程并发为 4 并使用 FIFO 进程预算 8;coding child 与 parent 共用项目 write lease。同一助手工具批次内,内置 `bash`/`edit`/`write` 与声明需要该 write lease 的动态产品工具按顺序执行,避免 Pi 在批量 prepare 阶段形成租约自锁;纯只读工具批次仍可并行。prompt/compact confirmation timeout 后仍保留 run/Agent-Server-or-child-process/background ownership,迟到 success/failure/exit/abort 单调且 exactly-once 收敛,页面隐藏不会停止 active/uncertain run。线程级替换只使目标 generation 失效;整个 Agent Server 退出会统一使所有旧 channel 失效,但 Main/Renderer 存活且下次恢复只重启一个 Server。Pi `0.84.2` 手动 compact 不发 `agent_settled`,由 correlated compact RPC 结果终结。父 Provider credential 只进入选中逻辑线程的内存 credential store,child 凭据只进入该短命进程;确定性的 Works user-context 缺失会失效 gateway credential、fail fast、不重放并投影固定 Provider-auth 错误,不归类为 Pi crash。精确的 `403 token_point_balance_exhausted` / `词元点数余额不足` 上游响应会在 Main 内归类为不可重试的配额耗尽,Renderer 只收到稳定 `CODING_PROVIDER_QUOTA_EXHAUSTED` 与安全中文提示;重开会话仍保留该提示,不暴露上游 request id 或原始错误正文。真实 Provider 验证仍为用户明确接受的未验证风险;macOS arm64 仅有本地未签名 mounted-image initialize/shutdown 证据,签名/公证/完整 process-enumeration、macOS x64 与 native non-WSL Linux 仍未通过平台发布门禁。
Code 入口现在始终落在 `/chat`。没有本地项目时显示 Makelore 品牌引导、单一橙色“新增项目”动作和真实项目卡横向列表;空列表不伪造示例。有项目但尚无 Agent 时保持项目可进入,并提供非阻塞的首个 Agent 设置入口。项目创建和项目卡选择都复用 Sidebar 的既有验证/激活流程,不建立第二套状态。
AI 编程已经硬切到精确 pin 的 Pi `0.84.2`,不存在 OpenCode fallback 或双 runtime。project、Agent 与 Conversation 只在 `.makelore/project.json` 和 `.makelore/conversations.json` 使用本地 schema v2;当前客户端不从 `.niancode` 或 `.opencode` 读取、迁移或删除项目元数据。只要项目 metadata 有效即可进入 `/chat`;`initialized` 仅为 schema 兼容字段,不构成导航或 Conversation gate。项目尚无启用且未归档的 Agent 时显示非阻塞设置入口,不创建伪 Agent;真正开始 Conversation 前仍由现有 Agent/模型校验给出明确恢复路径。Electron Main 按需启动一个长驻父 Agent Server,每条 active/warm Conversation 在其中拥有独立 Runtime/Session/channel、credential store、extension context、generation/seq、Snapshot/Patch、model/thinking、队列、interaction 与错误状态,Composer 在 lazy prepare 期间仍可编辑;正式包从 staged `pi-runtime` manifest/root 定位并校验 Pi 包入口,不从脚本目录或应用 `node_modules` 回退。Renderer 只通过 `/api/coding/*` 和 Snapshot-first/`patch-batch` SSE 消费产品中立合同;gap/reconnect 只恢复目标 Conversation,accepted/uncertain mutation 不自动重放。`lifecycle:sleep` 会关闭旧事件流,视图挂载、项目上下文变化、页面重新可见或窗口 focus 会静默刷新已选 Snapshot,使后台 terminal 状态收敛且不重放 mutation。隐藏 Conversation 的红点只在新 pending interaction 或新 completed/failed/aborted terminal transition 出现,不由助手/thinking/工具过程或单个工具失败触发。Session hydration 沿完整 active branch 投影可见历史,Pi compaction 只改变模型上下文并保持 summary 私有;Renderer 首次挂载最近 120 个节点,向上滚动时按 100 个节点追加更早内容并补偿新增高度以保持阅读锚点。折叠的 thinking、助手过程说明与工具输出固定展示第一条可见内容和首个非空行,横向偏移保持为零,展开后仍显示完整内容。未解析 Conversation 第一次选模先 validate 并持久化 resolved metadata,再 prepare;同账号模型切换使用 target `set_model`,跨账号只重建目标逻辑线程。Web Search 只作为所选模型 capability 进入父 worker 并使用相同 model/provider/credential 与普通模型计费,不经过 Marketplace/Hosted client/Plugin Charge 或浏览器 fallback;child 不继承。Conversation 工具可检查并在独立确认后安装 npm、Git、本地 Plugin 目录或 loose `SKILL.md` 为 Main-owned immutable Device Package;不运行生命周期脚本,可执行 extension 具有桌面用户权限,新/idle parent 自动刷新,active parent 结算后刷新,child 为空。每个 Main-selected generation 都保留全部显式安装且当前启用的 Skill 路径;生成的 Makelore bridge 是必需的首个 extension,其余 extension 全部经 `additionalExtensionPaths` 加载,并继续关闭 ambient discovery。top-level 逻辑 turn 并发为 4,warm idle logical-thread LRU 为 8;independent child 进程并发为 4 并使用 FIFO 进程预算 8;coding child 与 parent 共用项目 write lease。同一助手工具批次内,内置 `bash`/`edit`/`write` 与声明需要该 write lease 的动态产品工具按顺序执行,避免 Pi 在批量 prepare 阶段形成租约自锁;纯只读工具批次仍可并行。prompt/compact confirmation timeout 后仍保留 run/Agent-Server-or-child-process/background ownership,迟到 success/failure/exit/abort 单调且 exactly-once 收敛,页面隐藏不会停止 active/uncertain run。线程级替换只使目标 generation 失效;整个 Agent Server 退出会统一使所有旧 channel 失效,但 Main/Renderer 存活且下次恢复只重启一个 Server。Pi `0.84.2` 手动 compact 不发 `agent_settled`,由 correlated compact RPC 结果终结。父 Provider credential 只进入选中逻辑线程的内存 credential store,child 凭据只进入该短命进程;确定性的 Works user-context 缺失会失效 gateway credential、fail fast、不重放并投影固定 Provider-auth 错误,不归类为 Pi crash。精确的 `403 token_point_balance_exhausted` / `词元点数余额不足` 上游响应会在 Main 内归类为不可重试的配额耗尽,Renderer 只收到稳定 `CODING_PROVIDER_QUOTA_EXHAUSTED` 与安全中文提示;重开会话仍保留该提示,不暴露上游 request id 或原始错误正文。真实 Provider 验证仍为用户明确接受的未验证风险;macOS arm64 仅有本地未签名 mounted-image initialize/shutdown 证据,签名/公证/完整 process-enumeration、macOS x64 与 native non-WSL Linux 仍未通过平台发布门禁。
Updater 仍由 Electron Main 选择目标 feed、记录原始诊断并保持失败语义。正式稳定源缺少对应平台 manifest 时,设置页只显示一条简洁中文提示并允许重试,不把缺包误报为已是最新版,也不向普通界面暴露堆栈、URL、路径或错误码;签名产物发布和真实升级安装仍属于外部 Release Gate。
@@ -756,6 +840,17 @@ Robot 绑定设备默认先显示“引导配网 / 已有激活码”路径选
## Recently Completed
- 2026-09-07: Semantically integrated all completed current-product Code,
Project Configuration, Plugin, and Canvas branches. Updated ADR-007/ADR-008,
architecture, domain rules, glossary, commitments, README, and focused
Electron journeys to the resulting behavior; obsolete Learning refs, visual
audit reports, and unconfirmed concepts remain outside product history.
- 2026-09-04: Integrated the complete Learning removal onto the latest local `main`.
The module chooser, guarded routes, sidebar, auth projection, Main dispatcher,
lifecycle state, build output, and docs now contain only Code, Canvas, and Robot.
Stale Learning routes return to the chooser, the retired API is unregistered, and
historical course data remains untouched. Full unit, build, and Electron E2E gates
passed on the integrated tree.
- 2026-09-03: Reconciled local `main@7a37593` with fetched
`origin/main@8e947b4` through a normal two-parent merge. The result keeps the
reviewed single `/plugins` workspace and Device Package multi-extension
@@ -850,10 +945,9 @@ Robot 绑定设备默认先显示“引导配网 / 已有激活码”路径选
## Next Recommended Steps
1. 在停止服务的目标数据库完成 Design V2 cutover dry-run、清零 blocker、显式 apply/validate,再用成对部署的服务端与安装包真实账号执行 direct edit、chat edit、Quote request/confirm、后台完成、结果下载和 interrupted unknown-result replay smoke; paid Provider activation 另行授权。
2. 部署 Works `module_access` migration 与 `/api/auth/me` 权限 API,打包新 Makelore 客户端,再用真实账号分别关闭 Code、Canvas、Learning、Robot 执行卡片、根/深层/别名路由 smoke;同时独立验证模块 API 服务端授权。
3. 部署 Works Square Learning 项目管理、对象存储、README HTTPS URL 校验和 list/detail/media/archive API,再使用真实账号验证发布/下架、分页、远程 README 图片(含 SVG、失效 origin 和隐私提示)、ZIP 校验/保存以及 Windows 与签名 macOS 安装包。
4. 对 default-on Guided Hotspot Binding 核对指定固件镜像与六位码发行/消费契约,补齐 Windows 真机热点连接、签名 macOS x64/arm64 CoreWLAN/CoreLocation/worker 打包验证、真实 Host API/native seam Electron E2E 和完整真机 smoke;发布支持保留精确 `=0` 回滚,不把缺失证据表述为已验收。
5. 成组核对客户端 source+built+contract 上传 → 服务端逐字节校验 → OSS immutable Release → CDN/Edge 的发布契约与客户端 `play_url` 消费契约。
2. 部署 Works `module_access` migration 与 `/api/auth/me` 权限 API,打包新 Makelore 客户端,再用真实账号分别关闭 Code、Canvas、Robot 执行卡片、根/深层/别名路由 smoke;同时独立验证模块 API 服务端授权。
3. 对 default-on Guided Hotspot Binding 核对指定固件镜像与六位码发行/消费契约,补齐 Windows 真机热点连接、签名 macOS x64/arm64 CoreWLAN/CoreLocation/worker 打包验证、真实 Host API/native seam Electron E2E 和完整真机 smoke;发布支持保留精确 `=0` 回滚,不把缺失证据表述为已验收。
4. 成组核对客户端 source+built+contract 上传 → 服务端逐字节校验 → OSS immutable Release → CDN/Edge 的发布契约与客户端 `play_url` 消费契约。
## Open Questions / Blockers
@@ -861,9 +955,9 @@ Robot 绑定设备默认先显示“引导配网 / 已有激活码”路径选
## Risky Areas
- 四模块权限只控制 Makelore 客户端入口和初始化,不是 API 授权边界。不得因卡片置灰或路由阻断而放宽 Works/模块服务端的身份与权限校验;旧服务端缺少对象/字段时默认开启是显式兼容策略。
- 三模块权限只控制 Makelore 客户端入口和初始化,不是 API 授权边界。不得因卡片置灰或路由阻断而放宽 Works/模块服务端的身份与权限校验;旧服务端缺少对象/字段时默认开启是显式兼容策略。
- Prompt Museum 相对媒体必须保持固定的服务端路径并由 Main 处理;如果服务端增加媒体变体,需同步维护 entry/path 语法、Works Bearer 所有权、单次刷新、10 MiB 限制、可信 raster MIME 白名单与 Renderer data URL 校验。HTTPS 直连媒体必须继续无凭据,图片失败必须局限在卡片/详情视图。
- Learning 项目目录依赖真实 Works 运营发布和固定 API 契约;README 图片只允许服务端校验后的无凭据 HTTPS URL,并由 Markdown 图片节点直接加载,不得扩展为任意网络或归档代理。第三方 origin 的可用性、格式支持和请求隐私是已接受边界。Main 必须保持 Bearer 所有权、封面/历史媒体受控读取、一次 401 refresh、同源最多五跳、SHA-256/ZIP 签名和原子保存;客户端下载明确不执行大小门禁,不得把上游错误、Token、对象存储 URL 或本地路径投影到 Renderer。历史课程数据不再读取但也不得被隐式删除。
- Learning 必须保持完全退役;不得因旧链接、旧服务端字段或历史数据而恢复入口、路由、API、下载或打包 fallback。历史课程数据不再读取、迁移,也不得被隐式删除。
- Works Project 首次封面已由服务端源 `407c883`(本地 merge `0cedfc4`)提供单请求原子绑定与失败补偿,客户端源 `145a6ce` 因此要求首次发布上传 PNG/JPEG/WebP 封面;部署、安装包和真实账号/对象存储 smoke 仍未完成。服务端仍没有已有 metadata 的 revision/ETag 与 draft-only 条件写,因此已有 draft/published 继续只允许 version-only,客户端不得以无条件 PATCH 替代。
- Guided Hotspot Binding 默认开启并提供未经认证的热点扫描/显式连接,但当前 Hotspot/portal 仍是开放 SoftAP + 明文 HTTP,且精确出货镜像、激活码发行契约、签名 macOS、Windows 真机与完整整链尚未验证。界面必须保留环境警告,异常发布可用精确环境值 `0` 回滚;不得把 SSID 前缀宣称为可信设备发现、自动认领或在线证明。
- 一键提交已成功但本机 submission binding 落盘失败时必须保持提交成功、显示固定 `binding_warning` 并继续轮询,避免用户误判上传失败。