docs: reconcile official scaffold plugin integration

This commit is contained in:
2026-09-04 22:42:29 +08:00
parent 2bc3e44208
commit b92e7ba5bb
15 changed files with 98 additions and 307 deletions

View File

@@ -4,24 +4,31 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
## Integrated Through
- Interactive AI application and explicit scaffold source `959b633` is integrated
through merge `4bc3e0ea5331a7d3f3576768c0119c02c0f0f952` and canonically reconciled by
task `20260904-reconcile-project-scaffold-f7b4d2a9`. New projects use one
- Interactive AI application source `959b633` and official Marketplace packaging
source `ddb678b46ff10a28e04beeafcfc00c8c8a23ff9f` are integrated through merges
`4bc3e0ea5331a7d3f3576768c0119c02c0f0f952` and
`2bc3e4420852388ce46841e05c1cbf49e80b250c`, then canonically reconciled by tasks
`20260904-reconcile-project-scaffold-f7b4d2a9` and
`20260904-project-scaffold-integration-client-4f2a8c71`. New projects use one
`interactive_ai_app` / “交互式 AI 应用” type or `custom`; historical `mini_game`
and `mini_program` values normalize at the read boundary without a batch rewrite.
Project creation owns only `.makelore/project.json` and `knowledge/`. The independent
`makelore-project-scaffold` Device Package provides an explicit, non-overwriting,
fixed six-file Vite starter and read-only publication-readiness guidance; it does not
install, build, upload, submit, or approve. Non-empty Skill `scripts/` are now disclosed
as desktop-user executable code and use the non-overridable application Node exposed as
`MAKELORE_NODE_EXECUTABLE`. Main and Works Square retain build, preflight, artifact,
Project creation owns only `.makelore/project.json` and `knowledge/`. The official
code-owned bundled Marketplace Plugin `makelore.project-scaffold` version `1.0.0`
provides the explicit `makelore-project-scaffold` Skill, a non-overwriting fixed
six-file Vite starter, and read-only publication-readiness guidance; it does not
install, build, upload, submit, or approve. Its `.mjs` uses the non-overridable
application Node exposed as `MAKELORE_NODE_EXECUTABLE` and is executable only because
it ships in the fixed signed-client resource root. Downloadable Marketplace artifacts
remain text/image-only and reject `.mjs`; acquisition, project enablement, Agent
assignment, and immutable bundled Release/Admission remain distinct. Main and Works
Square retain build, preflight, artifact,
upload, immutable Release, and review authority. Exact integration verification passed
the 12-test scaffold suite, 123 focused Vitest tests, typecheck, scoped ESLint, and the
Renderer/Main/Preload/utility Vite build. Source evidence additionally includes the
project-configuration Electron flow, real scaffold-to-locked-Vite build, plugin/Skill
validation, and installed Device Package prepare→confirm→commit/resource reads. Immutable
distribution plus installed Windows, signed macOS, and native Linux proof remain pending;
no plugin publication, production upload, approval, or remote push is claimed.
validation and bundled resource loading. A packaged-app smoke plus installed Windows,
signed macOS, and native Linux proof remain pending; no live Marketplace migration,
production upload, approval, deployment, or remote push is claimed.
- AI Design streamed-reply diagnosis
`229b1b1ce39b7f1541a93ea3c980ab82b6d6266c` and client fix
`23f96a523eb37d8397bb3766ce95a59d56e59225` from tasks
@@ -605,7 +612,7 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
## Current Focus
客户端面向非专业用户提供“创建交互式 AI 应用 → 明确调用 Scaffold Skill 生成起步文件 → 项目配置中一键提交 → Main 本地 npm/Vite 构建 → Electron 双视口预检最终产物 → 上传 source+built 双归档与 contract → 运营审核”的唯一创建者链路。项目创建只生成 `.makelore/project.json` 和 `knowledge/`;`makelore-project-scaffold` 只负责不覆盖的固定起步树与只读发布准备度说明,不能安装、构建、上传、提审或批准。Main 对安全源码快照运行安装包内固定 npm 11.6.2 的 `npm ci --ignore-scripts`,再显式调用项目 `package-lock.json` 锁定的 Vite;Vite config/plugins 以当前桌面用户权限执行,因此只适用于用户信任的本地项目,不是 sandbox。预检由 Main 以临时 loopback origin 和 Electron WebContents/CDP 检查与最终 `built_archive` 相同的内存文件字节,覆盖桌面/移动视口、运行错误、白屏和外域访问;不使用 Playwright。该检查仍可由非官方客户端绕过,不产生可信 receipt,也不复刻生产 opaque-origin。服务端不再替客户端运行项目 Vite,而是把源码、构建归档和 contract 视为不可信输入,逐字节重算与校验并固化不可变 Release;人工审核仍不可绕过。`custom` 和缺少类型字段的旧项目不提供该入口;历史 `mini_game` / `mini_program` 只在读取边界归一为规范 `interactive_ai_app`。已发布作品优先使用安全投影后的 `play_url`,`runtime_url` 仅保留一个客户端版本的兼容回退。
客户端面向非专业用户提供“创建交互式 AI 应用 → 明确调用官方 bundled Project Scaffold Skill 生成起步文件 → 项目配置中一键提交 → Main 本地 npm/Vite 构建 → Electron 双视口预检最终产物 → 上传 source+built 双归档与 contract → 运营审核”的唯一创建者链路。项目创建只生成 `.makelore/project.json` 和 `knowledge/`;`makelore.project-scaffold` 只负责不覆盖的固定起步树与只读发布准备度说明,不能安装、构建、上传、提审或批准。其 `.mjs` 只从签名客户端固定资源加载,Marketplace 下载 artifact 仍拒绝脚本。Main 对安全源码快照运行安装包内固定 npm 11.6.2 的 `npm ci --ignore-scripts`,再显式调用项目 `package-lock.json` 锁定的 Vite;Vite config/plugins 以当前桌面用户权限执行,因此只适用于用户信任的本地项目,不是 sandbox。预检由 Main 以临时 loopback origin 和 Electron WebContents/CDP 检查与最终 `built_archive` 相同的内存文件字节,覆盖桌面/移动视口、运行错误、白屏和外域访问;不使用 Playwright。该检查仍可由非官方客户端绕过,不产生可信 receipt,也不复刻生产 opaque-origin。服务端不再替客户端运行项目 Vite,而是把源码、构建归档和 contract 视为不可信输入,逐字节重算与校验并固化不可变 Release;人工审核仍不可绕过。`custom` 和缺少类型字段的旧项目不提供该入口;历史 `mini_game` / `mini_program` 只在读取边界归一为规范 `interactive_ai_app`。已发布作品优先使用安全投影后的 `play_url`,`runtime_url` 仅保留一个客户端版本的兼容回退。
AI Design Canvas 现在默认以对话和一张持续可见的“我的创作”卡服务 8-16 岁创作者;专业字段矩阵收进按需打开的“精细调整”,移动端保持对话优先并只挂载一个卡片/底部面板。Creation Card、精细调整、Quote、Task 与结果提示都只投影权威状态,已知问题按 code 转成通俗中文,未知服务端或 Provider 文本不会直接显示。一个 Workspace 仍只公开一个 current Direction、一个 persistent Agent Session 和一个 Current Specification;conversation timeline 只记录交互历史。Chat、direct edits、decision responses、proposal acceptance、locks、Asset binding 与 restore 都通过 `design.input.apply` 进入同一服务端 reducer,Renderer drafts 在 accepted 前保持本地。Main 持有 Works Token、stream ticket、WebSocket、request deadline、stable command/operation IDs 与错误脱敏;unknown result 只能复用原 identity,结构化业务错误不得重放。Generation 由服务端对 exact Specification revision 编译 immutable Quote,客户端只展示 public output plan、warnings、expiry 与 Token Points,并以 Quote ID 调用 `design.generation.confirm`;Provider Prompt、model、route、storage 和 billing atoms 不进入 Renderer。Task/Asset events 独立收敛 Workspace resources,不改写 Living Form。Development 与 packaged builds 均使用 Works Square V2,V1 DTO、local semantic adapter、mutable Quote PATCH 与 editable provider Prompt 已移除。