Merge origin/main and preserve nonblocking project entry
Electron E2E / Electron E2E (macos-latest) (push) Has been cancelled
Electron E2E / Electron E2E (ubuntu-latest) (push) Has been cancelled
Electron E2E / Electron E2E (windows-latest) (push) Has been cancelled

This commit is contained in:
inman committed 2026-09-07 12:53:55 +08:00
commit 918f8f80dc
66 files changed
+4068 -519

No files matched your search

+31 -10
View File
@@ -7,7 +7,11 @@
later consume Token Points, and system-included Data Service remains zero-charge.
- Account Library, Device Installation, project enablement, Agent assignment, runtime
authorization, and billing are separate states. No read, install, acquisition, or
assignment may silently advance another state.
assignment may silently advance another state. The code-owned project-wide identities
are `makelore.data-service`, `makelore.game-resource`, and
`makelore.project-scaffold`: their existing delivery/acquisition and project enablement
remain separate, but project enablement intentionally makes their Skills/tools
available to every parent Agent without creating or requiring assignment state.
- Marketplace packages become effective only after closed manifest/descriptor parsing,
canonical archive and client-compatibility checks, Ed25519 verification, immutable
Package Store selection, project enablement, Agent projection, and current server
@@ -18,11 +22,11 @@
worker or delete bytes it still owns.
- System-included Data Service ships with MakeLore and has no Library acquisition,
Admission, download, update, or device-uninstall action. Users may still enable it
per project and assign its Skill to an Agent.
per project; project enablement makes its Skill/tools available to every parent Agent.
- Code-owned Game Resource is the optional bundled hosted Plugin. Its exact schema-2
manifest, Skill, and tools ship with MakeLore, so it has no device download, update,
Beta, signature, or device-uninstall state. Account Library acquisition/removal,
project enablement, Agent assignment, current server policy, immutable Admission,
project enablement, current server policy, immutable Admission,
explicit confirmation, and Token Point billing remain distinct.
- Production Marketplace trust fails closed while the official Ed25519 public key is
absent. Test-only/integration keys and packaged unknown-key rejection are evidence,
@@ -30,8 +34,10 @@
implemented, but production package trust and real Provider activation remain closed
until the official key and separate server pricing, credential, Admission, and
acceptance gates are ready.
- A `platform_hosted` Skill or tool may enter only an installed, enabled, assigned,
trusted, compatible, policy-admitted parent Pi logical thread. Unknown, disabled, or
- A `platform_hosted` Skill or tool may enter only a delivered/installed, enabled,
trusted, compatible, policy-admitted parent Pi logical thread. Agent assignment is an
additional gate only for Plugin identities whose activation scope requires it; the
three code-owned project-wide identities bypass that gate. Unknown, disabled, or
ineligible assignments stay inert; child workers receive no hosted Plugin projection.
- A metered hosted mutation requires explicit client confirmation before resolve,
Admission, or charging. Works Square owns price, payer, Token Point policy, and receipt
@@ -41,8 +47,13 @@
- Electron Main to fixed Works Square routes is the only hosted Plugin transport.
Packages, Renderer state, Pi arguments/results, logs, and saved project metadata must
not expose Provider credentials, URLs, credit balances, raw responses, or Provider job
IDs. Saving a hosted result must use bounded project-relative paths and the existing
project write lease.
IDs. A confirmed Game Resource generation is one Main-owned submit-and-deliver
operation: submit once, poll internally, download every terminal output, and save it
below `assets/generated/game-resource/<executionId>/` in the project frozen at call
time. Provider/billing state and local delivery state remain separate. A delivery
retry or application restart may resume only local download/save work and must never
submit or charge again. The shared project write lease is held only while materializing
terminal outputs; the Agent does not choose paths, poll status, or confirm saving again.
- Native Web Search is a selected-model capability, not a Marketplace Plugin. Only an
exact verified capability may place `makelore_web_search` in a frozen parent worker;
it uses that worker's current model/provider/credential and ordinary model billing.
@@ -67,10 +78,19 @@
`插件` ResourceCard opens `/project-config/plugins` as a same-page wide sheet while
the configuration page remains mounted. Code sidebar must not add a standalone
Plugin entry; `/plugins` and older Plugin URLs are compatibility redirects only.
- 共享开发浏览器必须绑定当前项目和当前 generation。Renderer 的 `project_id` 与
viewport presentation 仅可由具备 Renderer capability 的请求使用;Agent `open`
必须等待真实可见 bounds 后才报告成功。非 Web 协议、文件注入、跨 target 与宿主级
CDP 命令保持拒绝,诊断按 owner 引用计数;关闭面板、项目/模块切换、窗口隐藏或
后台休眠必须销毁 view、detach debugger 并停止无所有者轮询。
- Code-owned official bundled Plugins may be `platform_hosted` or `skill_only`.
`makelore.project-scaffold` retains Account Library, project enablement, Agent
assignment, Release, and Admission state while its exact Skill/templates/`.mjs`
ship only in the signed client. Downloadable Marketplace artifacts remain P0
Data Service is system-included; Game Resource and `makelore.project-scaffold` retain
Account Library, project enablement, Release, and Admission state where applicable,
while their exact resources ship only in the signed client. All three are project-wide:
once their delivery/acquisition condition is satisfied and they are enabled for a
project, every parent Agent receives the full resource set without partner assignment;
child Agents remain empty. Downloadable
Marketplace artifacts remain P0
text/image-only and must reject `.mjs`; official bundled authority is not inferred
from provider metadata or an uploaded ZIP.
- 面向用户的 AI 编程新建流程只要求选择目录,不展示 `ProjectType`、模板、原始项目 UUID、绑定或独立副本选项。Renderer 写入内部默认 `interactive_ai_app`,Main 自动生成 UUID;创建后类型仍不能通过 UI 或 Host API 修改。既有 `custom` 项目继续可用,历史 `mini_game` / `mini_program` 仅在读取边界归一为 `interactive_ai_app` 且不改写配置;未传类型的底层兼容 API 调用仍按 `custom` 处理。
@@ -92,6 +112,7 @@
- 已发布作品优先读取 `play_url`,只有字段缺失时才使用一个客户端版本的 `runtime_url` 回退。公共播放 URL 必须是 Works Square 同源 HTTPS、无 userinfo/loopback、精确 `/apps/{encodeURIComponent(app_id)}/`、无 query/fragment,且上游明确 `playable === true` 并提供非空版本名;否则按不可播放处理。
- `works-cloud-deploy.json` 仅是已安装客户端的数据兼容文件名,不表示客户端仍提供 cloud deployment coordinator。
- Works Square 会话按真实键盘、鼠标或触摸活动滑动续期,连续 7 天未使用才要求重新授权。
- 账号词元点数只能通过 Main-owned Works Square V2 余额路由投影。只有 `can_manage_membership=true` 的账号可向 Renderer 暴露套餐、周期、本周/永久/总点数;其他账号的这些字段必须统一为 `null`,并只以 `shared_available` 表达是否可用。格式或枚举不符合闭合 DTO 时整份响应 fail closed。
- “记住密码”是独立于七天会话的可选桌面凭据记录:只能由 Electron Main 在正式安装包中通过可用的系统安全存储加密落盘,账号密码不得进入 Renderer 持久状态、日志或 Works Square 持久化。退出登录和短信登录保留记录;只有成功的未勾选密码登录清除旧记录。系统安全存储不可用或未打包开发版必须禁用该选项。
- 运营端可按用户关闭 Code、Canvas 或 Robot 客户端入口,默认全开。Makelore 通过 Main-owned `/api/auth/me` 只消费三布尔安全投影;缺失 `module_access` 或字段按开启处理,服务端 `design` 对应现有客户端 `painting`,额外旧字段被忽略。
- 关闭的模块卡片必须置灰且无法点击;其根路由、深层路由和别名路由必须在 `MainLayout` 或模块初始化前阻断。Code provider 只能在 auth policy hydration 完成且 Code 已开启时初始化;`/settings` 是全局设置,不得随 Code 关闭而失去访问。