merge: promote verified remote integration to main
This commit is contained in:
@@ -7,6 +7,7 @@
|
||||
| Marketplace catalog and Account Library | Signed-in Renderer intent | bounded Host API → Main Marketplace client/cache → Works Square catalog, Library, resolve, Admission, and download APIs | Main binds requests to the current Account and response generation. Free acquisition changes only Account Library; it does not install, enable a project, assign an Agent Skill, or authorize runtime execution. |
|
||||
| Marketplace device installation | Account Library entry and explicit channel | Main resolve/Admission/download → descriptor/signature/archive/client compatibility verification → immutable Package Store index switch | Stable and explicit Beta remain distinct even when they resolve to the same immutable Release. Failed install/update retains the previous current release; explicit uninstall waits only for protecting worker/account references and completes after the final worker exits. |
|
||||
| Effective Plugin worker snapshot | Installed trusted package + project selection + Agent assignments + current server policy | effective resolver → Registry/resource loader/Extension Host/tool catalog → parent Pi worker | One frozen snapshot supplies Skills, tools, package roots, and runtime authorization. Disable, account/project switch, logout, Renderer crash, Main shutdown, or worker generation change invalidates future actions without mutating persisted unknown assignments; child workers receive no Plugin projection. |
|
||||
| Hosted Game Resource operation | Eligible parent `makelore.game-resource` tool call plus explicit confirmation | frozen Plugin adapter → capability Registry → Main `GameResourceClient` → fixed Works Square game-resource route → provider-neutral receipt/result | Server policy owns pricing, payer, Admission and receipt state. Stable logical operation identity survives response loss/Main restart; `submission_unknown` is not replayed as a fresh request. Result saving uses a bounded project-relative path and the existing project write lease. |
|
||||
| 桌面认证生命周期 | Renderer 登录、刷新与注销请求 | Host API → Main Works Session → Works Square `/api/auth/{login,mobile-login,refresh,logout}` → one-feel auth | Main 加密持有并先持久化轮换 token;客户端不携带 OAuth client secret;连续 7 天未使用才清除会话,终止性 `400`/`401` fail closed |
|
||||
| 用户模块入口策略 | 会话恢复 / 登录 / 刷新 | Electron Main → Works `/api/auth/me` → 四布尔安全投影 → Renderer auth store → 卡片/路由/provider gate | 缺失对象或字段默认 `true`;`design` 映射 `painting`;终止性 `401` 清理 Main/Renderer 会话;全局 `/settings` 不受 Code gate |
|
||||
| 项目创建 | 新建项目对话框 | Host API → Main 项目初始化 | 创建时固定 `ProjectType`;小游戏/小程序原子生成受控模板,自定义只生成项目空间 |
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
| `electron/coding-plugins/manifest.ts`, `release-descriptor.ts`, `signature-verifier.ts`, and `trusted-keys.ts` | Closed Plugin package/descriptor parsing, compatibility checks, canonical archive validation, and Ed25519 trust | Schema 1 bundled compatibility and schema 2 `skill_only`/declarative `platform_hosted` are parsed fail closed. The production trust store accepts no Marketplace package until the official public key is built in. |
|
||||
| `electron/coding-plugins/account-plugin-cache.ts`, `marketplace-client.ts`, and `package-store.ts` | Main-owned Account Library cache, authenticated server client, and atomic immutable device installation store | Account acquisition and device installation are separate. Package bytes switch atomically only after descriptor, signature, archive, client-range, and provenance checks; failed updates preserve the prior current release. |
|
||||
| `electron/coding-plugins/effective-resolver.ts`, `registry.ts`, `project-service.ts`, and `electron/coding-runtime/pi/**` | One effective installed-plugin projection and frozen parent logical-thread runtime snapshot | Project enablement and Agent Skill assignment are preserved independently. Only trusted, compatible, installed, policy-admitted resources enter a new parent logical thread; child workers remain empty and active threads retain frozen bytes until disposal. |
|
||||
| `electron/coding-plugins/adapters/game-resource.ts` and `electron/services/game-resource-client.ts` | Provider-neutral `makelore.game-resource` hosted tool adapter and Main-owned Works Square transport | Tools materialize only from an eligible frozen `platform_hosted` parent snapshot. Metered mutations require explicit confirmation and stable logical operation identity; Renderer/Pi never receive Provider URLs, credentials, balances, raw responses, or Provider job IDs. |
|
||||
| `electron/api/routes/plugin-marketplace.ts`, `src/stores/plugin-marketplace.ts`, `src/pages/PluginMarketplace/`, `src/pages/MyPlugins/`, and `src/pages/ProjectPlugins/` | Bounded Main routes and Renderer projections for catalog, Library, device, and project actions | Renderer receives no Account token, filesystem path, Admission, package bytes, or signed download URL. Catalog/Library/device/project generations prevent stale A/B or cross-action results from replacing current state. |
|
||||
| `src/components/works/ProjectPublishAction.tsx` | 可发布项目的一键提交、云构建轮询与用户可理解状态 | 只通过 Renderer API 提交非敏感元数据;绑定告警不终止轮询 |
|
||||
| `src/lib/works-square.ts` | Renderer 侧 Works Square Host API 契约与安全错误映射 | 不接触 Token、ZIP、本地绝对路径或自动部署状态 |
|
||||
@@ -53,6 +54,7 @@
|
||||
## Dependency Direction
|
||||
|
||||
- Renderer UI → Renderer API contract → Main Host routes → Main services → Works Square;Renderer 不反向读取 Main 凭据、文件系统或归档。
|
||||
- Hosted Plugin parent tool → frozen Registry adapter → Main `GameResourceClient` → fixed Works Square game-resource routes. Stable logical operation identity survives response loss and Main restart; ambiguous submission remains reviewable and is never converted into an automatic fresh mutation. Saving a result uses the existing bounded project path and project write lease.
|
||||
- AI 编程 Renderer product Snapshot/commands → typed `/api/coding/*` Host API → Main Coding composition → target `CodingConversationRuntime` → shared Agent Server 内的目标 Pi 逻辑线程;Pi Provider 请求再经 Main AI proxy 访问模型上游。Renderer 不持有 Pi wire、凭据或本地 runtime URL。
|
||||
- Project configuration 决定产品分流;Main release builder 生成 source/built/contract,服务端独立重算和校验决定发布安全,本地 `ProjectType` 不是授权结论。
|
||||
- Built artifact preflight 检查最终上传的同字节快照,但客户端可被绕过且不产生可信 receipt;服务端仍是合同、摘要和不可变 Release 安全权威。
|
||||
@@ -63,6 +65,7 @@
|
||||
## Risky Or Sensitive Areas
|
||||
|
||||
- `electron/api/routes/works.ts` 同时承担发布 capability、上游安全投影和错误脱敏,变更时必须验证未在拒绝前读取凭据或项目文件。
|
||||
- `platform_hosted` mutation eligibility, explicit confirmation, stable identity, Admission and receipt status form one authority chain. `submission_unknown` cannot create a new request, and a billing `pending_review` receipt cannot be inferred from transport ambiguity. Production remains fail closed until the official Marketplace signing key and server-side activation gates are ready.
|
||||
- `project-release-builder.ts` 执行受信本地项目的 Vite config/plugins,拥有桌面用户权限;必须保持路径、环境、时间、输出、进程树和临时目录限制,不得包装为 sandbox。
|
||||
- `electron/agent-browser/module.ts` 的预检必须继续拒绝外域访问、隔离临时 partition 并清理所有 view/listener;不能因本地通过而跳过服务端逐字节校验。生产 opaque-origin 行为不由该 loopback 检查覆盖。
|
||||
- `works-cloud-deploy.json` 是兼容文件名;不得因名称重新引入自动部署协调语义。
|
||||
|
||||
@@ -4,6 +4,22 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
|
||||
|
||||
## Integrated Through
|
||||
|
||||
- Hosted Game Resource Plugin source `fe656dd865f1941f1dc2d369ce3bb09efb955fd8`
|
||||
and verification record `421c8254d51318355faec3ae94f8e1cfd4d054c5`
|
||||
from task `20260831-meowa-hosted-plugin-client-8d3a5b72` are integrated with
|
||||
fetched `origin/main` `38f85f6b5e4dc4e2c5e5b9f8f4506554cfd578f5`
|
||||
in merge `372b5345dae57ce19d2630b24277596db284194c` by task
|
||||
`20260831-integrate-remote-main-6b3d9e1a`. MakeLore now supports generic
|
||||
schema-2 `platform_hosted` Marketplace packages and a provider-neutral
|
||||
`makelore.game-resource` adapter. Its Skill and tools enter only an installed,
|
||||
enabled, assigned, admitted parent Pi logical thread; child and ineligible
|
||||
threads receive no projection. Hosted mutations require explicit confirmation,
|
||||
keep stable logical operation identity across uncertain results, and travel only
|
||||
through Electron Main to fixed Works Square routes. The old always-mounted Meowa
|
||||
tools, direct proxy, local credential configuration, and package-time credential
|
||||
path are removed. Production activation remains held until the official signing
|
||||
key, rotated server credential, positive Token Point pricing, and server Admission
|
||||
gates are ready and verified.
|
||||
- Local source snapshot `33fb31fb285b5cfb00d194a036aaf6e21cf8c5a1`,
|
||||
based on the prior local delivery `48a9189`, is integrated over fetched upstream
|
||||
`62304dc85b3c1069cd656dfacb61ee820e216fa2` in merge commit
|
||||
@@ -26,9 +42,10 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
|
||||
projections without receiving credentials, paths, Admissions, or signed URLs.
|
||||
Data Service remains system-included and consumes zero Token Points. R7 Standards
|
||||
and Spec reviews passed with zero findings, and XMA-01 passed all twelve live groups
|
||||
against real PostgreSQL and a signed-in packaged Windows client. Production trust
|
||||
activation remains HOLD until the official Ed25519 public key is built in; Release B
|
||||
and hosted Provider runtime remain closed.
|
||||
against real PostgreSQL and a signed-in packaged Windows client. The later
|
||||
`platform_hosted` client runtime is integrated above; production package trust and
|
||||
real Provider activation remain held behind the official signing key and the
|
||||
separate server, pricing, credential-rotation, and Admission gates.
|
||||
- AI Design Living Form V2 client source
|
||||
`b0b5a602b501308a23eb27e2f51a5169b9e46b1e` is integrated with matching Works
|
||||
Square server source `b5351d54f595ce8eb873593e462e4a556bea0b05` by task
|
||||
@@ -198,6 +215,14 @@ Robot 绑定设备默认先显示“引导配网 / 已有激活码”路径选
|
||||
|
||||
## Recently Completed
|
||||
|
||||
- 2026-08-31: Integrated the provider-neutral `makelore.game-resource` hosted Plugin
|
||||
client with fetched `origin/main`. Generic schema-2 `platform_hosted` packages now
|
||||
materialize frozen Skill/tool snapshots only for eligible parent Pi logical threads;
|
||||
paid operations require explicit confirmation and stable logical identity, while
|
||||
Electron Main alone owns the fixed Works transport. Legacy always-mounted Meowa
|
||||
tools and client credential paths are removed. Focused/full unit tests, typecheck,
|
||||
lint and Vite/Electron builds passed; production signing, pricing, credential
|
||||
rotation, real Provider acceptance, push, deployment, and publication remain open.
|
||||
- 2026-08-31: Integrated the occupied local source snapshot over upstream Marketplace Release A and AI Design Living Form V2. Makelore Code now amortizes parent Pi startup through one long-lived Agent Server while preserving isolated per-Conversation logical runtimes, sessions, credentials, extensions and channels; child Agents remain independent processes. ADR-006 and current architecture now use `.makelore` as the sole project configuration source and explicitly reject legacy metadata reads or migration.
|
||||
- 2026-08-26: Fast-forwarded the complete Pi hard-cutover and installed-package resilience chain into local `main`, including per-Conversation workers/Snapshot projection, extension/subagents, bounded process/write/background ownership and the deterministic Works user-context Provider-auth correction. The final Windows installer, packaged Pi runtime, extension/child, 4+4 pressure, uncertainty/late-settle and zero-lingering-process proofs passed. Real Provider turns are explicitly waived rather than passed; macOS and native non-WSL Linux remain release evidence gaps.
|
||||
- 2026-08-20: Replaced AI Learning's course generation/player stack with the curated project catalog defined by ADR-005. The authenticated/module-gated client now renders project cards and safe README detail, loads validated credential-free HTTPS Markdown images directly, and saves verified ZIP archives through the native dialog. Old course/runtime/player packaging was removed; server/client regressions and full suites passed, while production deployment and real-account package smoke remain pending.
|
||||
|
||||
@@ -0,0 +1,79 @@
|
||||
# Task: Integrate fetched origin main with local hosted plugin delivery
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20260831-integrate-remote-main-6b3d9e1a
|
||||
- Mode: Integration
|
||||
- Branch: codex/20260831-pull-remote-merge-4a91c7e2-pull-remote-merge
|
||||
- Worktree: D:\Datas\OthersProjects\makelore-pull-remote-merge-4a91c7e2
|
||||
- Base commit: 372b5345dae57ce19d2630b24277596db284194c
|
||||
- Owner: codex
|
||||
- Status: Ready for Integration
|
||||
|
||||
## Scope
|
||||
|
||||
- Own the sole Integration Gate for the fetched `origin/main` merge and its canonical
|
||||
project-memory promotion.
|
||||
- Verify that merge `372b5345dae57ce19d2630b24277596db284194c` preserves both the
|
||||
remote shared Pi Agent Server architecture and the local hosted Game Resource Plugin
|
||||
lifecycle without restoring always-mounted game-resource tools.
|
||||
- Record the resulting Git topology, verification evidence, and the occupied local
|
||||
`main` promotion constraint without modifying or releasing another task's ownership.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- Concurrent Task Gate: PASS. This task owns the sole Integration lock in isolated
|
||||
worktree `D:\Datas\OthersProjects\makelore-pull-remote-merge-4a91c7e2`; the original
|
||||
`main` worktree remains owned by task `20260831-meowa-hosted-plugin-client-8d3a5b72`.
|
||||
- Planning Gate: PASS after reading the required startup set, all 196 peer task scopes,
|
||||
the complete local hosted-plugin and remote integration source records, and the
|
||||
canonical architecture/domain targets. Thirty-two peer tasks remained in planning and
|
||||
164 were ready for integration; no peer owned this isolated branch or semantic merge.
|
||||
- Preserve both parent histories with an ordinary merge. Do not rebase, force-update,
|
||||
stash, clean, push, deploy, or move the occupied `main` ref.
|
||||
- Canonical documentation may be updated only under this Integration ownership; source
|
||||
task records remain immutable.
|
||||
|
||||
## Outcome
|
||||
|
||||
- Fetched `origin/main` at `38f85f6b5e4dc4e2c5e5b9f8f4506554cfd578f5` and
|
||||
merged it with local tip `421c8254d51318355faec3ae94f8e1cfd4d054c5` in
|
||||
`372b5345dae57ce19d2630b24277596db284194c`.
|
||||
- Resolved the sole conflict in
|
||||
`electron/coding-runtime/pi/extensions/makelore-runtime.ts` by retaining the remote
|
||||
`createMakeloreRuntime(runtimeDefaults)`/runtime-flag Agent Server architecture while
|
||||
retaining local dynamic Plugin registration and removal of the obsolete static
|
||||
`game_asset_browser` and `game_asset_review` registrations.
|
||||
- Promoted the hosted Plugin facts into `current-state.md`, `module-map.md`,
|
||||
`data-flow.md`, and `business-rules.md`: generic schema-2 `platform_hosted` execution
|
||||
and `makelore.game-resource` are implemented, while production signature, pricing,
|
||||
rotated credential, Admission, and real Provider gates remain closed.
|
||||
- The verified result remains on branch
|
||||
`codex/20260831-pull-remote-merge-4a91c7e2-pull-remote-merge`. The occupied original
|
||||
`main` worktree/ref was not modified, and no push or deployment was performed.
|
||||
|
||||
## Verification
|
||||
|
||||
- Repository-pinned `pnpm@10.33.4` installation with `--frozen-lockfile`: passed.
|
||||
- Merge-focused suite: 12 files, 145 passed, 2 skipped.
|
||||
- `pnpm run typecheck`: passed.
|
||||
- `pnpm test`: 212 files, 1,721 passed, 2 skipped.
|
||||
- `pnpm run lint:check`: passed with 0 errors and 5 existing warnings.
|
||||
- `pnpm run build:vite`: passed for Renderer, Electron Main, Preload, and utility worker.
|
||||
- Unresolved merge paths: 0. Staged and unstaged `git diff --check`: passed before the
|
||||
merge commit.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- Promote this verified branch to local `main` only after task
|
||||
`20260831-meowa-hosted-plugin-client-8d3a5b72` releases its ownership; do not bypass
|
||||
that gate.
|
||||
- Revoke the historical client-exposed Meowa credential externally, then complete the
|
||||
official signing-key, rotated server credential, positive pricing, production
|
||||
Admission, packaged install/update/rollback, uncertain-result, and real Provider
|
||||
acceptance gates before production activation.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- None. The accepted hosted Plugin candidates were promoted into canonical memory by
|
||||
this Integration task.
|
||||
@@ -0,0 +1,69 @@
|
||||
# Task: Pull and merge remote repository
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20260831-pull-remote-merge-4a91c7e2
|
||||
- Mode: Feature
|
||||
- Branch: codex/20260831-pull-remote-merge-4a91c7e2-pull-remote-merge
|
||||
- Worktree: D:\Datas\OthersProjects\makelore-pull-remote-merge-4a91c7e2
|
||||
- Base commit: 421c8254d51318355faec3ae94f8e1cfd4d054c5
|
||||
- Owner: codex
|
||||
- Status: Transferred to Integration Gate
|
||||
|
||||
## Scope
|
||||
|
||||
- Inspect the configured Git remotes, current branch relationship, and clean/dirty state in the owned isolated worktree.
|
||||
- Fetch the configured upstream and merge the remote default-branch changes into this task branch without rewriting history or touching the occupied `main` worktree.
|
||||
- Report the resulting commit relationship, conflicts if any, and the remaining promotion constraint for local `main`.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- Preserve all local and peer work. Do not stash, reset, clean, overwrite, force-update, or release another task's ownership.
|
||||
- Keep every Git and documentation operation rooted in `D:\Datas\OthersProjects\makelore-pull-remote-merge-4a91c7e2`.
|
||||
- Use the configured remote/upstream rather than inventing a repository URL or target branch.
|
||||
- A fast-forward or ordinary merge is allowed; rebase and history rewriting are outside the user's request.
|
||||
- The original `main` worktree remains owned by `20260831-meowa-hosted-plugin-client-8d3a5b72`; do not move `main` until that owner is explicitly released.
|
||||
|
||||
## Outcome
|
||||
|
||||
- Fetched configured upstream `origin/main` at
|
||||
`38f85f6b5e4dc4e2c5e5b9f8f4506554cfd578f5`. The local branch was two commits
|
||||
ahead and the remote was three commits ahead of merge base
|
||||
`62304dc85b3c1069cd656dfacb61ee820e216fa2`, so a fast-forward was not possible.
|
||||
- Merged the remote branch with the local hosted Game Resource Plugin delivery.
|
||||
One content conflict occurred in
|
||||
`electron/coding-runtime/pi/extensions/makelore-runtime.ts`.
|
||||
- Preserved the remote parent Pi Agent Server and runtime-flag factory while
|
||||
preserving the local rule that game-resource tools are dynamically exposed
|
||||
only through an eligible hosted Plugin. The two obsolete always-mounted static
|
||||
game-asset registrations were not restored.
|
||||
- The feature-mode documentation drift gate correctly blocked completion because
|
||||
the fetched remote history contains accepted canonical project-memory changes.
|
||||
Final ownership and documentation completion are transferred to integration task
|
||||
`20260831-integrate-remote-main-6b3d9e1a` after this merge commit is finalized.
|
||||
- The occupied original `main` worktree and its owner were not modified or released.
|
||||
|
||||
## Verification
|
||||
|
||||
- `pnpm install --frozen-lockfile` with repository-pinned `pnpm@10.33.4`: passed.
|
||||
- Merge-focused suite: 12 files, 145 passed, 2 skipped.
|
||||
- `pnpm run typecheck`: passed.
|
||||
- `pnpm test`: 212 files, 1,721 passed, 2 skipped.
|
||||
- `pnpm run lint:check`: passed with 0 errors and 5 existing warnings.
|
||||
- `pnpm run build:vite`: passed for Renderer, Electron Main, Preload, and utility worker.
|
||||
- Unresolved merge paths: 0. Staged and unstaged `git diff --check`: passed.
|
||||
- `check_doc_drift.py --task-id 20260831-pull-remote-merge-4a91c7e2`:
|
||||
correctly blocked feature completion because remote canonical documents require
|
||||
Integration Gate ownership; this result triggered the mode transition rather
|
||||
than being bypassed.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- Complete the canonical-document-aware merge under integration task
|
||||
`20260831-integrate-remote-main-6b3d9e1a`.
|
||||
- Promote the verified integration branch to local `main` only after task
|
||||
`20260831-meowa-hosted-plugin-client-8d3a5b72` releases the original worktree.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- None recorded.
|
||||
@@ -21,8 +21,23 @@
|
||||
per project and assign its Skill to an Agent.
|
||||
- Production Marketplace trust fails closed while the official Ed25519 public key is
|
||||
absent. Test-only/integration keys and packaged unknown-key rejection are evidence,
|
||||
not authority to activate production. Release B hosted Provider runtime remains
|
||||
closed behind its separate Provider gate.
|
||||
not authority to activate production. Generic `platform_hosted` client execution is
|
||||
implemented, but production package trust and real Provider activation remain closed
|
||||
until the official key and separate server pricing, credential, Admission, and
|
||||
acceptance gates are ready.
|
||||
- A `platform_hosted` Skill or tool may enter only an installed, enabled, assigned,
|
||||
trusted, compatible, policy-admitted parent Pi logical thread. Unknown, disabled, or
|
||||
ineligible assignments stay inert; child workers receive no hosted Plugin projection.
|
||||
- A metered hosted mutation requires explicit client confirmation before resolve,
|
||||
Admission, or charging. Works Square owns price, payer, Token Point policy, and receipt
|
||||
state. Stable logical operation identity survives response loss and Main restart;
|
||||
`submission_unknown` must not become a fresh request or be conflated with a billing
|
||||
`pending_review` receipt.
|
||||
- Electron Main to fixed Works Square routes is the only hosted Plugin transport.
|
||||
Packages, Renderer state, Pi arguments/results, logs, and saved project metadata must
|
||||
not expose Provider credentials, URLs, credit balances, raw responses, or Provider job
|
||||
IDs. Saving a hosted result must use bounded project-relative paths and the existing
|
||||
project write lease.
|
||||
- 面向用户的 AI 编程新建流程必须在 `mini_game`、`mini_program`、`custom` 中选择;`ProjectType` 是产品类型,创建后不能通过 UI 或 Host API 修改,未传类型的兼容 API 调用按 `custom` 处理。
|
||||
- 新建小游戏和小程序会生成平台固定版本的受控 Vite 发布模板,并可使用项目配置中的单一“提交审核”入口;`custom` 和缺少类型字段的旧项目不提供一键发布。
|
||||
- `ProjectType` 不等于 `BuildPreset`:第一期两个可发布产品类型都映射到内部受控 Vite preset;本地 `projectType` 不是授权边界,Main-owned 安全打包、Host API 和服务端包体校验仍必须执行。
|
||||
|
||||
Reference in New Issue
Block a user