merge: sync remote main and preserve local integrations

This commit is contained in:
2026-08-16 21:49:41 +08:00
101 changed files with 16895 additions and 2760 deletions

View File

@@ -4,6 +4,7 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
## Integrated Through
- `26b52d7`: Canvas Prompt Museum, editable server-priced generation Quotes, project deletion/task-detail workflow, cloud-default Canvas development entry, Chinese-only UI consolidation, and bundled `game-engine` Skill from the authoritative remote main.
- `c1326a2`: Guided Hotspot Binding now scans bounded open `Xiaozhi-*` candidates and connects the user-selected hotspot inside the page through Main-owned Windows WLAN and macOS CoreWLAN/CoreLocation adapters; system Wi-Fi remains fallback, exact `=0` rollback and firmware/cloud contracts are unchanged.
- `b78fc07`: Guided Hotspot Binding is enabled by default in Electron Main, with exact environment value `0` as rollback and direct six-digit fallback on capability-read failure; firmware and Host/cloud contracts are unchanged.
- `b7a1590` / `14afe4a`: initial firmware-zero-change Guided Hotspot Binding V1 implementation and decision used a Main-owned default-off capability, fixed portal action, in-memory Renderer journey, and existing six-digit Binding contract; `b78fc07` above supersedes only that default.
@@ -28,7 +29,9 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
客户端面向非专业用户提供“创建小游戏或小程序 → 项目配置中一键提交 → Main 本地 npm/Vite 构建 → Electron 双视口预检最终产物 → 上传 source+built 双归档与 contract → 运营审核”的唯一创建者链路。Main 对安全源码快照运行安装包内固定 npm 11.6.2 的 `npm ci --ignore-scripts`,再显式调用项目 `package-lock.json` 锁定的 Vite;Vite config/plugins 以当前桌面用户权限执行,因此只适用于用户信任的本地项目,不是 sandbox。预检由 Main 以临时 loopback origin 和 Electron WebContents/CDP 检查与最终 `built_archive` 相同的内存文件字节,覆盖桌面/移动视口、运行错误、白屏和外域访问;不使用 Playwright。该检查仍可由非官方客户端绕过,不产生可信 receipt,也不复刻生产 opaque-origin。服务端不再替客户端运行项目 Vite,而是把源码、构建归档和 contract 视为不可信输入,逐字节重算与校验并固化不可变 Release;人工审核仍不可绕过。自定义和缺少类型字段的旧项目不提供该入口。已发布作品优先使用安全投影后的 `play_url`,`runtime_url` 仅保留一个客户端版本的兼容回退。
AI 绘画的一个 Workspace 可包含多条 Conversation。消息、Brief、Quote 和 `turnRevision` 随 Conversation 隔离;生成任务和资产保持 Workspace 级共享。图片 Brief 支持文生图,以及从当前项目已完成作品或本地上传中选择一张参考图继续生成;视频复用同一选择器绑定首帧。两条路径都通过现有 Workspace Asset 契约提交一个真实 Asset ID。每条 Conversation 使用服务端持久 Agent Gateway Session;连接正常时命令、Run 与设计事件共用双向 WebSocket,只有发送、断连或 ACK 超时等传输故障才以同一 `client_command_id` 回退 REST,结构化业务错误不重复提交且未知上游文本由 Main 脱敏。确认生成会按 Quote 对账 Workspace 任务;任务已经落库但 Run 随后失败时仍恢复任务列表,内部对账失败不覆盖当前 UI 错误,同时 Conversation 写入继续受 Workspace-load 与 Conversation-selection generation 保护。
AI 绘画的一个 Workspace 可包含多条 Conversation。消息、Brief、Quote 和 `turnRevision` 随 Conversation 隔离;生成任务和资产保持 Workspace 级共享。图片 Brief 支持文生图,以及从当前项目已完成作品或本地上传中选择一张参考图继续生成;视频复用同一选择器绑定首帧。两条路径都通过现有 Workspace Asset 契约提交一个真实 Asset ID。每条 Conversation 使用服务端持久 Agent Gateway Session;连接正常时命令、Run 与设计事件共用双向 WebSocket,只有发送、断连或 ACK 超时等传输故障才以同一 `client_command_id` 回退 REST,结构化业务错误不重复提交且未知上游文本由 Main 脱敏。确认栏允许编辑服务端最终 Prompt 与 generation options,每次修改都由服务端 Quote 重算设计点,确认时提交最新原值;客户端不推算供应商或积分价格。任务详情可预览/下载结果。侧栏删除项目要求完整输入项目名,删除当前项目后切换到最近更新的剩余项目;服务端删除/结算语义仍由 Works Square 契约负责。确认生成会按 Quote 对账 Workspace 任务;任务已经落库但 Run 随后失败时仍恢复任务列表,内部对账失败不覆盖当前 UI 错误,同时 Conversation 写入继续受 Workspace-load 与 Conversation-selection generation 保护。
Canvas 侧栏提供“获取灵感”进入 Prompt Museum。列表、筛选、分页、详情、作者/来源/许可证和图片地址全部由服务端经 Main-owned Host API 提供,客户端不打包静态数据集;“使用此 Prompt”只把原文带回当前 Canvas 输入框,不自动发送。该模块不是投稿、点赞、评论或排行榜社区。客户端契约已就绪,但不据此宣称 Works Square 内容后台和生产数据已经部署。`pnpm run dev` 现在默认使用云端 Canvas 适配器,本地适配器只能通过显式开发命令启用;产品 UI 只保留中文。
AI 编程首次发送在新建 OpenCode session 已知为空时不再等待冗余历史读取,prompt 可直接进入 Host API;普通历史会话仍刷新消息。Main AI proxy 只把明确的上游分组饱和投影为当前 OpenCode 的终止状态,配额耗尽保持独立终止态,通用限速继续保留 `429`。上下文压缩以每个 Session 的持久时间线事件呈现:自动与手动压缩使用不同文案,运行态原位弱化显示,完成后静态保留并可从历史恢复;`session.compacted` 只完成对应事件,只有真实 idle 才结束 run 和释放排队消息。
@@ -38,6 +41,7 @@ Robot 绑定设备默认先显示“引导配网 / 已有激活码”路径选
## Recently Completed
- 2026-08-16: Integrated remote `26b52d7`: Canvas now has server-backed Prompt Museum navigation, editable server-repriced generation Quotes, task result details/downloads, guarded project deletion, cloud-default development, Chinese-only UI, and an optional bundled `game-engine` Skill. Client integration is verified separately from production Prompt Museum data/backend deployment.
- 2026-08-16: Integrated Windows/macOS in-page Robot hotspot discovery, explicit selection, connection, and exact-current-SSID verification behind the existing default-on guided capability. Candidate IDs are bounded and short-lived, native diagnostics stay in Main, system settings remain fallback, and firmware/Portal/Binding contracts are unchanged.
- 2026-08-16: Enabled the existing Guided Hotspot Binding journey by default after explicit product confirmation. Exact `NIANCODE_AI_HARDWARE_GUIDED_HOTSPOT_BINDING=0` remains the operational rollback; fixed portal ownership, direct-code fallback, security warnings, firmware-zero-change, and Binding-without-online semantics are preserved.
- 2026-08-16: Initially implemented ADR-002's Robot onboarding V1 without changing firmware, behind a default-off Main capability and fixed portal opener. The later `b78fc07` decision above changes only the default; the same firmware/issuer/native-opener/physical evidence remains outstanding.

View File

@@ -8,10 +8,11 @@
- Worktree: D:\Datas\OthersProjects\makelore
- Base commit: 4fbd1d3b24493532ce479729da2c5e5e1709c8a9
- Owner: codex
- Status: Blocked
- Status: In Progress
## Scope
- On 2026-08-16, resume the existing Integration owner after the user restored remote credentials: fetch authoritative `origin/main`, complete the already-started merge of remote tip `26b52d7`, preserve both remote Canvas/Prompt Museum work and local Robot hotspot work, run merged-tree verification and independent review, then perform a normal non-forced push and verify remote-tip equality.
- On 2026-08-16, resume the existing Integration owner to merge reviewed cross-platform in-app Robot hotspot connection source `c1326a2` into local `main`, supersede only ADR-002's manual operating-system hotspot-selection step, preserve firmware/credential/Binding boundaries, and keep remote push outside this resumption.
- On 2026-08-16, resume the existing Integration owner to merge reviewed default-on Guided Hotspot Binding source `b78fc07` into local `main`, accept the user's explicit reversal of the prior default-off policy, preserve exact environment value `0` as rollback, and keep firmware edits and remote push outside this resumption.
- On 2026-08-16, resume the existing Integration owner to merge reviewed Robot Guided Hotspot Binding implementation commit `b7a1590` into local `main`, reconcile canonical memory from planned to implemented/default-off, and keep firmware edits, capability enablement, and remote push outside this resumption.
@@ -50,6 +51,7 @@
- The reviewed implementation may move canonical truth from planned to present, but release guidance must retain the exact shipped-firmware, issuer/validator, gate-on Electron, and physical-device smoke prerequisites. The source task record remains read-only and must stay on its feature history.
- The user's latest instruction explicitly authorizes default-on and supersedes only the earlier default-off/capability-not-enabled constraint. It does not authorize firmware changes, automatic discovery/claim claims, arbitrary portal URLs, Wi-Fi credential handling, or remote push. Missing installed-Electron/physical-device evidence remains an explicit residual release risk, not completed evidence.
- The user has now explicitly authorized page-owned selection and connection of nearby open `Xiaozhi-*` provisioning hotspots on both Windows and macOS. This supersedes only manual operating-system hotspot selection; discovery remains unauthenticated convenience, Main remains the sole native-network owner, and signed macOS plus physical-Robot smoke remain release gates.
- The latest instruction explicitly authorizes fetching, semantically resolving conflicts, and pushing `main`. Use the existing merge topology; do not rebase, reset, stash, discard remote/local commits, or force-push. Preserve remote Prompt Museum/Canvas/Chinese-only/Skill behavior alongside the already reviewed local Robot native hotspot path and `koffi` packaging.
## Project Context Loaded
@@ -97,6 +99,16 @@ Relevant understanding:
Gate result:
- Passed.
### 2026-08-16 Remote `26b52d7` Synchronization Resume
- Reused the existing Integration owner and refreshed its reservation. Local `main` entered this resumption at `9af6c526a9500a0dbfb88e39ba0dee1eb7e1d097`; the worktree already contained an unfinished merge whose `MERGE_HEAD` was `26b52d76e3dedd754ca1b1c428abaa074b7f98da`.
- A fresh authoritative `git fetch origin main --prune` succeeded and confirmed `origin/main`, `FETCH_HEAD`, and the existing `MERGE_HEAD` are the same `26b52d7` commit. The merge base is `bfcb88cfefe714a60927a77822ae5a727ebe6604`; local has 12 first-parent/integration commits and remote has one consolidation commit beyond that base.
- Read the active integration record and canonical architecture/domain/current-state/evidence memory, inspected the remote change set, and assigned a read-only Sol audit. Remote scope adds the server-driven Canvas Prompt Museum, cloud Canvas development entry, bundled `game-engine` Skill, Chinese-only locale consolidation, and associated Canvas/workspace tests; it does not remove the local Robot hotspot module or `koffi` dependency.
- The only textual conflict was `README.md`. It was resolved semantically by retaining the remote Canvas “获取灵感” description and the local Windows/macOS in-page Robot hotspot workflow. No product file was resolved by choosing one side wholesale.
- Read-only audit caught a non-textual lockfile merge conflict: the staged lock retained `koffi` but lost the local top-level `isbinaryfile` override while `package.json` still required it, making frozen installation fail with `ERR_PNPM_LOCKFILE_CONFIG_MISMATCH`. The merged lock restores the exact override and will be accepted only after a successful frozen install.
- Audit also rejected the remote Prompt Museum route because it forwarded unknown upstream/local error text and unvalidated success JSON. The merge adds strict bounded list/detail projection with HTTPS URL validation, fixed safe error mapping, stable 401-refresh failure handling, and focused regression tests. A remote E2E assertion was corrected to match the documented latest-message sidebar preview rather than an older user message.
- Gate result: Passed for completing the current normal merge, canonical promotion, proportionate merged-tree verification, independent final review, and a non-forced push. If the remote advances again before push, fetch and integrate that new tip before publishing.
### 2026-08-16 Cross-Platform Robot Hotspot Integration Resume
- Reused the existing Integration owner because it exclusively owns clean local `main` at `abecd5f34485ab467e5f032c618083d88e34b74d`; `task_context.py touch` refreshed the reservation and the registry reports this exact `main` worktree/branch owner.
@@ -157,6 +169,13 @@ Gate result:
## Plan
### 2026-08-16 Remote `26b52d7` Synchronization Plan
1. Complete the existing merge against freshly fetched `origin/main=26b52d7`, resolving README to preserve both remote Canvas Prompt Museum and local Robot hotspot behavior, then confirm there are no unmerged entries or dependency regressions.
2. Promote confirmed remote product/architecture facts into canonical current-state, component, flow, domain, glossary, and evidence memory without claiming server deployment or production smoke that has not occurred.
3. Install the frozen lockfile and run focused Prompt Museum/Canvas/language/Skill plus Robot regressions, the full unit suite, typecheck, lint, production build, selected Electron E2E, project-document gates, and whitespace/topology checks.
4. Obtain an independent read-only Sol Standards/Spec PASS, create the normal merge commit with local `9af6c52` as first parent and remote `26b52d7` as second parent, fetch once more to detect races, then push without force and verify `origin/main` equals local `main`.
### 2026-08-16 Cross-Platform Robot Hotspot Integration Plan
1. Merge reviewed source `c1326a2` into local `main` with a normal no-ff merge while preserving source history; exclude the source-owned task record and proposal from the integrated tree.
@@ -222,6 +241,12 @@ Gate result:
## Outcome
- On 2026-08-16, resumed the unfinished merge with local `main` at `9af6c526a9500a0dbfb88e39ba0dee1eb7e1d097` and freshly fetched remote `main` at `26b52d76e3dedd754ca1b1c428abaa074b7f98da`; `bfcb88cfefe714a60927a77822ae5a727ebe6604` is their merge base. README was the only textual conflict and now preserves both remote Canvas Prompt Museum wording and local Windows/macOS Robot hotspot behavior.
- Integrated the remote Canvas enhancements: editable server-repriced generation Quotes, result detail/download UX, exact-name project deletion, Prompt Museum, Chinese-only locale normalization, cloud-default development entry, and optional bundled `game-engine` Skill. Existing local Robot hotspot source, default-on rollback semantics, Koffi 2.16.3, packaging configuration, and firmware-zero-change boundary remain intact.
- Repaired the automatically merged lockfile by restoring the package-declared `isbinaryfile` override; frozen installation now succeeds. Corrected README's development-mode paragraph to match the remote cloud-default package script.
- Closed the read-only audit's Prompt Museum boundary findings: Main now projects only bounded list/detail DTOs, accepts only HTTPS URLs without userinfo, maps errors to fixed safe codes/messages, and returns a stable auth error when token refresh is unavailable. Unknown upstream/local details and malformed success payloads no longer reach Renderer.
- The first final Sol review returned `FAIL` because the merged lock declared the `isbinaryfile` override but left `@electron/osx-sign` on 4.0.10, and because successful Prompt Museum token refresh lacked focused coverage. Fixed pnpm 10.33.4 lock regeneration now resolves the signing chain to 5.0.7, and the route test verifies `forceRefresh: true`, the fresh Bearer token, the successful projected DTO, and exactly one retry.
- Corrected one remote Electron E2E expectation to assert the documented latest-message sidebar preview. Production behavior was already correct; no Canvas component change was required.
- On 2026-08-16, formed reviewed in-app Robot hotspot source commit `c1326a298026a697181c822cdd3062cc96c3aa2d` as the exact direct child of local `main` at `abecd5f34485ab467e5f032c618083d88e34b74d`, then started a normal `--no-ff --no-commit` merge. Git reported no textual conflicts.
- The staged main tree now owns Windows WLAN and macOS CoreWLAN/CoreLocation scan/connect/verify adapters behind one bounded Main Module and typed Host seam. Renderer exposes explicit candidate selection, safe recovery, system-Wi-Fi fallback, and the unchanged fixed-Portal/six-digit Binding continuation.
- Excluded the source-owned task record and proposal from the integrated tree while preserving both on source commit/branch `c1326a2`. Accepted ADR-003 and reconciled ADR-002, current state, architecture, domain rules, evidence, and release commitments without claiming signed macOS or physical-Robot acceptance.
@@ -326,6 +351,17 @@ Gate result:
## Verification
- Remote `26b52d7` merged-tree frozen install — passed with pnpm 10.33.4 after restoring the exact top-level lockfile override.
- Combined Prompt Museum/Canvas/language/Skill/Robot regression selection — 16 files / 284 tests passed before the Prompt Museum hardening; post-hardening Museum selection — 3 files / 12 tests passed.
- Prompt Museum hardening tests first reproduced all three audit findings, then passed after the fix. The final 3 files / 13 tests cover stable refresh-auth failure, successful `forceRefresh` with the new Bearer and one retry, unknown upstream/local detail redaction, and malformed/unsafe success DTO rejection. Typecheck and focused ESLint passed.
- Full unit suite first passed 1848/1849 with one unrelated `opencode-manager` port-release test exceeding its 10-second timeout under full concurrency. The isolated test passed 1/1, the initial bounded four-worker rerun passed 161 files / 1849 tests, and the final post-lock/post-refresh rerun passed 161 files / 1850 tests.
- Full `pnpm run typecheck` and `pnpm run lint:check` passed; lint reports 0 errors and the existing 6 warnings.
- `pnpm run build:vite` passed for Renderer, Electron Main, and Preload; only existing mixed-import and large-chunk warnings remain. The emitted Main build retains Windows/macOS Robot native chunks.
- Selected Electron E2E initially passed 5/6 and exposed a stale sidebar-preview assertion. After aligning it with latest-message behavior, the Canvas E2E passed 1/1; Chinese-only, main navigation, and project Skill checks had already passed 5/5.
- Final pnpm 10.33.4 lock validation passed both the main-worktree frozen install and a truly clean frozen install in an isolated temporary directory (955 packages, no pre-existing `node_modules`). The final lock contains only `isbinaryfile@5.0.7`; both `@electron/osx-sign` and the other consumer resolve 5.0.7. Post-regeneration typecheck, lint, full tests, and Renderer/Main/Preload build all passed.
- First final Sol review — `FAIL` on the stale `@electron/osx-sign → isbinaryfile 4.0.10` snapshot and missing successful-refresh test; both findings were fixed before the final re-review.
- Final Sol re-review — `PASS` on Standards and Spec with no remaining P0-P3 findings. It confirmed the single-version 5.0.7 override graph, Koffi 2.16.3, successful-refresh coverage, correct merge topology, Robot/Canvas behavior preservation, canonical consistency, and clean staged state.
- Project-document structure and task-aware drift passed. Staged/unstaged whitespace checks pass, and the merge has no unmerged entries or conflict markers.
- 2026-08-16 cross-platform Robot hotspot source final Sol review — `PASS` on Standards and Spec with no P0-P3 findings; macOS termination/cancellation races, Renderer post-connect state, default-on rollback, security boundaries, and firmware-zero-change were confirmed.
- Staged merged-main Robot hotspot selection — 4 files / 132 tests passed.
- Staged merged-main `pnpm test` — 157 files / 1796 tests passed.
@@ -427,6 +463,7 @@ Gate result:
## Follow-ups
- Before releasing Prompt Museum and the expanded Canvas deletion/repricing workflow, use a real Works account to validate Museum list/detail/pagination/attribution/CDN content, latest Quote pricing/confirmation, project soft-delete visibility, queued reservation release, and running-task settlement. Client tests do not prove the content backend or production billing/deletion semantics are deployed.
- Before claiming complete compatibility for the default-on Robot journey, verify the exact shipped firmware/fixed portal, six-digit issuer/validator freshness and consumption semantics, real Host API/native opener behavior, and a physical-device provisioning + Binding smoke. Keep exact `NIANCODE_AI_HARDWARE_GUIDED_HOTSPOT_BINDING=0` in support rollback instructions.
- The earlier default-false production instruction is superseded by the user's explicit default-on decision. Keep exact value `0` only as rollback, and do not touch `D:\Datas\HardwareProjects\xiaozhi-esp32-firmware` for this V1.
- Before the next default-on release or any complete-compatibility claim, identify the exact shipped Robot component/firmware image, verify that the deployed issuer produces six ASCII digits with compatible freshness/consumption semantics, and pass a real device smoke through the Host API/Electron flow.
@@ -447,6 +484,7 @@ Gate result:
## Promotion Candidates
- Remote `26b52d7` facts were promoted into current state, architecture, domain rules, glossary, evidence, README, and release commitments: Prompt Museum remains read-only/server-driven, Quote pricing is service-owned, Canvas deletion is an explicit Workspace mutation, development is cloud-default, UI language is Chinese-only, and `game-engine` is an optional bundled Skill. Production Museum content and real-account billing/deletion acceptance remain pending commitments rather than completed evidence.
- The default-on candidate from `b78fc07` was promoted into ADR-002, current state, decision/success criteria, Robot architecture/domain/glossary, README, and a concrete release-validation commitment. No unresolved canonical candidate remains; the missing native/physical evidence is tracked as a pending commitment rather than overclaimed.
- The implementation truth from `b7a1590` was originally promoted as implemented/default-off. `b78fc07` now supersedes only that default; its former enablement evidence requirements remain tracked as default-on release validation and rollback commitments.
- The Guided Hotspot Binding V1 candidate from `14afe4a` was promoted into ADR-002, success criteria, system/module/data-flow architecture, business rules, glossary, and current state. No unresolved candidate remains for this design acceptance.