Merge origin/main and preserve nonblocking project entry
Electron E2E / Electron E2E (macos-latest) (push) Has been cancelled
Electron E2E / Electron E2E (ubuntu-latest) (push) Has been cancelled
Electron E2E / Electron E2E (windows-latest) (push) Has been cancelled

This commit is contained in:
inman committed 2026-09-07 12:53:55 +08:00
commit 918f8f80dc
66 files changed
+4068 -519

No files matched your search

+31 -10
View File
@@ -7,7 +7,11 @@
later consume Token Points, and system-included Data Service remains zero-charge.
- Account Library, Device Installation, project enablement, Agent assignment, runtime
authorization, and billing are separate states. No read, install, acquisition, or
assignment may silently advance another state.
assignment may silently advance another state. The code-owned project-wide identities
are `makelore.data-service`, `makelore.game-resource`, and
`makelore.project-scaffold`: their existing delivery/acquisition and project enablement
remain separate, but project enablement intentionally makes their Skills/tools
available to every parent Agent without creating or requiring assignment state.
- Marketplace packages become effective only after closed manifest/descriptor parsing,
canonical archive and client-compatibility checks, Ed25519 verification, immutable
Package Store selection, project enablement, Agent projection, and current server
@@ -18,11 +22,11 @@
worker or delete bytes it still owns.
- System-included Data Service ships with MakeLore and has no Library acquisition,
Admission, download, update, or device-uninstall action. Users may still enable it
per project and assign its Skill to an Agent.
per project; project enablement makes its Skill/tools available to every parent Agent.
- Code-owned Game Resource is the optional bundled hosted Plugin. Its exact schema-2
manifest, Skill, and tools ship with MakeLore, so it has no device download, update,
Beta, signature, or device-uninstall state. Account Library acquisition/removal,
project enablement, Agent assignment, current server policy, immutable Admission,
project enablement, current server policy, immutable Admission,
explicit confirmation, and Token Point billing remain distinct.
- Production Marketplace trust fails closed while the official Ed25519 public key is
absent. Test-only/integration keys and packaged unknown-key rejection are evidence,
@@ -30,8 +34,10 @@
implemented, but production package trust and real Provider activation remain closed
until the official key and separate server pricing, credential, Admission, and
acceptance gates are ready.
- A `platform_hosted` Skill or tool may enter only an installed, enabled, assigned,
trusted, compatible, policy-admitted parent Pi logical thread. Unknown, disabled, or
- A `platform_hosted` Skill or tool may enter only a delivered/installed, enabled,
trusted, compatible, policy-admitted parent Pi logical thread. Agent assignment is an
additional gate only for Plugin identities whose activation scope requires it; the
three code-owned project-wide identities bypass that gate. Unknown, disabled, or
ineligible assignments stay inert; child workers receive no hosted Plugin projection.
- A metered hosted mutation requires explicit client confirmation before resolve,
Admission, or charging. Works Square owns price, payer, Token Point policy, and receipt
@@ -41,8 +47,13 @@
- Electron Main to fixed Works Square routes is the only hosted Plugin transport.
Packages, Renderer state, Pi arguments/results, logs, and saved project metadata must
not expose Provider credentials, URLs, credit balances, raw responses, or Provider job
IDs. Saving a hosted result must use bounded project-relative paths and the existing
project write lease.
IDs. A confirmed Game Resource generation is one Main-owned submit-and-deliver
operation: submit once, poll internally, download every terminal output, and save it
below `assets/generated/game-resource/<executionId>/` in the project frozen at call
time. Provider/billing state and local delivery state remain separate. A delivery
retry or application restart may resume only local download/save work and must never
submit or charge again. The shared project write lease is held only while materializing
terminal outputs; the Agent does not choose paths, poll status, or confirm saving again.
- Native Web Search is a selected-model capability, not a Marketplace Plugin. Only an
exact verified capability may place `makelore_web_search` in a frozen parent worker;
it uses that worker's current model/provider/credential and ordinary model billing.
@@ -67,10 +78,19 @@
`插件` ResourceCard opens `/project-config/plugins` as a same-page wide sheet while
the configuration page remains mounted. Code sidebar must not add a standalone
Plugin entry; `/plugins` and older Plugin URLs are compatibility redirects only.
- 共享开发浏览器必须绑定当前项目和当前 generation。Renderer 的 `project_id` 与
viewport presentation 仅可由具备 Renderer capability 的请求使用;Agent `open`
必须等待真实可见 bounds 后才报告成功。非 Web 协议、文件注入、跨 target 与宿主级
CDP 命令保持拒绝,诊断按 owner 引用计数;关闭面板、项目/模块切换、窗口隐藏或
后台休眠必须销毁 view、detach debugger 并停止无所有者轮询。
- Code-owned official bundled Plugins may be `platform_hosted` or `skill_only`.
`makelore.project-scaffold` retains Account Library, project enablement, Agent
assignment, Release, and Admission state while its exact Skill/templates/`.mjs`
ship only in the signed client. Downloadable Marketplace artifacts remain P0
Data Service is system-included; Game Resource and `makelore.project-scaffold` retain
Account Library, project enablement, Release, and Admission state where applicable,
while their exact resources ship only in the signed client. All three are project-wide:
once their delivery/acquisition condition is satisfied and they are enabled for a
project, every parent Agent receives the full resource set without partner assignment;
child Agents remain empty. Downloadable
Marketplace artifacts remain P0
text/image-only and must reject `.mjs`; official bundled authority is not inferred
from provider metadata or an uploaded ZIP.
- 面向用户的 AI 编程新建流程只要求选择目录,不展示 `ProjectType`、模板、原始项目 UUID、绑定或独立副本选项。Renderer 写入内部默认 `interactive_ai_app`,Main 自动生成 UUID;创建后类型仍不能通过 UI 或 Host API 修改。既有 `custom` 项目继续可用,历史 `mini_game` / `mini_program` 仅在读取边界归一为 `interactive_ai_app` 且不改写配置;未传类型的底层兼容 API 调用仍按 `custom` 处理。
@@ -92,6 +112,7 @@
- 已发布作品优先读取 `play_url`,只有字段缺失时才使用一个客户端版本的 `runtime_url` 回退。公共播放 URL 必须是 Works Square 同源 HTTPS、无 userinfo/loopback、精确 `/apps/{encodeURIComponent(app_id)}/`、无 query/fragment,且上游明确 `playable === true` 并提供非空版本名;否则按不可播放处理。
- `works-cloud-deploy.json` 仅是已安装客户端的数据兼容文件名,不表示客户端仍提供 cloud deployment coordinator。
- Works Square 会话按真实键盘、鼠标或触摸活动滑动续期,连续 7 天未使用才要求重新授权。
- 账号词元点数只能通过 Main-owned Works Square V2 余额路由投影。只有 `can_manage_membership=true` 的账号可向 Renderer 暴露套餐、周期、本周/永久/总点数;其他账号的这些字段必须统一为 `null`,并只以 `shared_available` 表达是否可用。格式或枚举不符合闭合 DTO 时整份响应 fail closed。
- “记住密码”是独立于七天会话的可选桌面凭据记录:只能由 Electron Main 在正式安装包中通过可用的系统安全存储加密落盘,账号密码不得进入 Renderer 持久状态、日志或 Works Square 持久化。退出登录和短信登录保留记录;只有成功的未勾选密码登录清除旧记录。系统安全存储不可用或未打包开发版必须禁用该选项。
- 运营端可按用户关闭 Code、Canvas 或 Robot 客户端入口,默认全开。Makelore 通过 Main-owned `/api/auth/me` 只消费三布尔安全投影;缺失 `module_access` 或字段按开启处理,服务端 `design` 对应现有客户端 `painting`,额外旧字段被忽略。
- 关闭的模块卡片必须置灰且无法点击;其根路由、深层路由和别名路由必须在 `MainLayout` 或模块初始化前阻断。Code provider 只能在 auth policy hydration 完成且 Code 已开启时初始化;`/settings` 是全局设置,不得随 Code 关闭而失去访问。
+1
View File
@@ -4,6 +4,7 @@
|---|---|---|
| `ProjectType` | 项目配置中持有且之后不可变的内部产品类型 | 普通新建不展示选择并默认 `interactive_ai_app`;既有 `custom` 继续兼容,历史 `mini_game` / `mini_program` 读取时归一为前者,缺少字段按 `custom` 处理 |
| `BuildPreset` | 平台内部用于构建和验收项目包的受控实现 | 不等于 `ProjectType` 或 Scaffold 状态;交互式 AI 应用使用固定 Vite preset |
| Official Project Plugin | 由 MakeLore 代码所有、以项目启用作为生效范围的官方 Plugin | 当前闭合集合为 `makelore.data-service`、`makelore.game-resource`、`makelore.project-scaffold`;满足既有交付/获取条件并启用项目后自动进入每个 parent Agent,不使用伙伴分配,child 为空 |
| Project Scaffold Skill | 官方 bundled Marketplace Plugin `makelore.project-scaffold` 中由用户明确调用、独立版本化的起步文件生成与发布准备度指导 | `.mjs` 只来自固定客户端资源;不覆盖路径、不安装/构建/上传/提审;项目创建服务和 Main/Works 发布权威不属于该 Skill |
| Main-owned Release Build | Electron Main 对安全源码快照执行固定 npm 与项目 lockfile Vite 的本地构建 | Vite config/plugins 以桌面用户权限执行,不是 sandbox;Renderer 不获得路径、归档或 origin |
| Artifact Contract | 与 source/built 双归档一并上传的严格版本化清单 | 服务端把三者视为不可信输入并独立逐字节重算、校验 |