chore(coding): record ML-09 remediation merge

This commit is contained in:
2026-08-27 01:06:33 +08:00
parent 38843e091f
commit bb832c6666
2 changed files with 63 additions and 138 deletions

View File

@@ -8,7 +8,7 @@
- Worktree: D:\Datas\OthersProjects\makelore-data-service-client-b72e4c19 - Worktree: D:\Datas\OthersProjects\makelore-data-service-client-b72e4c19
- Base commit: f2456039230f68e3ecb2c8653fc3379c23bbe5ce - Base commit: f2456039230f68e3ecb2c8653fc3379c23bbe5ce
- Owner: codex-root - Owner: codex-root
- Status: In Progress (ML-01 through ML-08 integrated; ML-09/X-01 pending) - Status: In Progress (ML-01 through ML-09 integrated; review/X-01 pending)
## Scope ## Scope
@@ -162,6 +162,19 @@
changes. The five required verification commands and their one known E2E changes. The five required verification commands and their one known E2E
failure are recorded below. The product HEAD immediately before this failure are recorded below. The product HEAD immediately before this
documentation update was `a981b07faaa64b20bf9aef6353218fef26695ca2`. documentation update was `a981b07faaa64b20bf9aef6353218fef26695ca2`.
- Integrated ML-09 remediation source commit
`b5060f254bfdb3a748739b74b1f583cc0236fa7c` from its exact parent
`239e20d2cf2242d636f9d42684f76f5777d9d1ee` as coordinator product commit
`38843e091fbbe68ec934336b8ed3a08c955afb28`, with no cherry-pick conflict.
The eight accepted review findings are all represented in the coordinator:
normal Pi parent Data Service allowlisting; camelCase Skill input;
credential-free HTTP/HTTPS loopback Origins; browser-generation lifecycle
fencing; README/Skill workflow documentation; narrow shared route parsers;
removal of the unused Agent Browser `onLifecycle` option; and removal of the
unused `handleDataServiceRoute` alias. The foreign ML-09 task record was
deleted from this coordinator while its source record remains in
`D:\Datas\OthersProjects\makelore-ml09-data-service-remediation-5e7c2a91`.
The product frontier after this merge is `38843e091fbbe68ec934336b8ed3a08c955afb28`.
## Verification ## Verification
@@ -382,6 +395,48 @@
20260826-makelore-data-service-client-b72e4c19` check passed using the 20260826-makelore-data-service-client-b72e4c19` check passed using the
configured bundled Python runtime. Test/build output remained ignored and configured bundled Python runtime. Test/build output remained ignored and
the worktree was clean before this task-record update. the worktree was clean before this task-record update.
- ML-09 precondition: coordinator was clean at exact ML-08 HEAD
`239e20d2cf2242d636f9d42684f76f5777d9d1ee`; the remediation source parent
matched that HEAD exactly and cherry-pick produced product commit
`38843e091fbbe68ec934336b8ed3a08c955afb28`.
- ML-09 focused remediation ledger: the 10-file equivalent set
(`data-service-sdk-assets`, `data-service-server-registration`,
`pi-rpc-foundation`, `pi-worker-process-real`, `preview-data-session`,
`agent-browser-core`, `agent-browser-routes`, `data-service-routes`,
`pi-extension-bundle`, and `pi-extension-ui-projector`) passed with 142
tests and 2 skipped; Vitest reported 16.45s.
- ML-09 adjacent regressions covering tool profile, Data Service client/routes,
preview/browser adapter, Skill resource, and Pi host paths: 8 files / 77
tests passed; Vitest reported 6.75s.
- ML-09 `pnpm typecheck`: exit 0, passed, approximately 5.31s.
- ML-09 `pnpm lint:check`: exit 0, passed with 0 errors and the same 5
existing warnings in `src/pages/Home/index.tsx` and
`src/pages/Makelore/index.tsx`.
- ML-09 `pnpm build`: exit 0, passed through Vite, staged Pi runtime, and
Windows Electron/NSIS packaging. Existing dynamic-import/chunk-size,
optional-resource, npm shell deprecation, absent optional resource, and
non-fatal NSIS patch/signing warnings remained visible.
- ML-09 `pnpm test:electron:windows`: exit 0, 2 files / 4 tests passed
(Vitest 1.04s; command approximately 2.28s).
- ML-09 affected E2E `pnpm exec playwright test
tests/e2e/project-configuration-skills.spec.ts --config=playwright.config.ts`:
exit 0, 1 test passed (2.9s).
- ML-09 affected Pi E2E `pnpm exec playwright test
tests/e2e/pi-coding-first-chat.spec.ts --config=playwright.config.ts`:
exit 1, 1 test passed and 1 failed (33.8s). The known failure remains at
`tests/e2e/pi-coding-first-chat.spec.ts:575`: `当前对话模型` resolves to a
disabled combobox and `selectOption` times out after 30s. It is not counted
as an E2E pass and no remediation diff evidence connects it to ML-09.
- ML-09 eight-item boundary checks all passed: the exact ten Data Service
names are used by the normal Pi parent default while child profiles remain
explicit and Data Service-free; Skill input uses only `injectProjectData`;
loopback Origin and generation guards are present; README/Skill docs are
present; both route modules use the narrow parser module while retaining
route-specific failures; `subscribeLifecycle` remains without
`onLifecycle`; and only `handleDataServiceRoutes` remains. The merged path
audit matched the expected 15 source paths with no extra or missing path,
and the added-lines scope scan found no Firebase, Redis, retry/cache, or
published-runtime expansion.
## Follow-ups ## Follow-ups
@@ -395,13 +450,13 @@
and ML-07 consumes only that local capability while keeping ordinary and ML-07 consumes only that local capability while keeping ordinary
arbitrary URL opens data-free. arbitrary URL opens data-free.
- The broader ML-00 through ML-09 coordinator task remains in progress; this - The broader ML-00 through ML-09 coordinator task remains in progress; this
record now has ML-08 command verification but does not claim ML-09 review, record now has ML-08 and ML-09 verification but does not claim review
release proof, or live acceptance. The client/server draft PR promotion is closure, release proof, or live acceptance. The client/server draft PR
externally blocked in this environment because GitLab HTTPS credentials are promotion is externally blocked in this environment because GitLab HTTPS
unavailable non-interactively and `gh`/`glab` are not installed; no draft PR credentials are unavailable non-interactively and `gh`/`glab` are not
is claimed from this worktree. installed; no draft PR is claimed from this worktree.
- ML-09 remains pending for repository-local review and one remediation - ML-09 remediation is integrated; review closure remains pending, including
implementer if findings require it. X-01 remains a TODO after both reviews: the known Pi model-combobox E2E deviation. X-01 remains a TODO after review:
exercise real PostgreSQL with a signed-in MakeLore preview and record live exercise real PostgreSQL with a signed-in MakeLore preview and record live
acceptance separately; repository E2E results cannot substitute for it. acceptance separately; repository E2E results cannot substitute for it.

View File

@@ -1,130 +0,0 @@
# Task: ML-09 data service remediation
## Identity
- Task ID: 20260827-ml09-data-service-remediation-5e7c2a91
- Mode: Feature
- Branch: codex/20260827-ml09-data-service-remediation-5e7c2a91-ml09-data-service-remediation
- Worktree: D:\Datas\OthersProjects\makelore-ml09-data-service-remediation-5e7c2a91
- Base commit: 239e20d2cf2242d636f9d42684f76f5777d9d1ee
- Owner: codex
- Status: Ready for Integration
## Scope
- ML-09 repository-local remediation on the exact ML-08 client head
`239e20d2cf2242d636f9d42684f76f5777d9d1ee`.
- Resolve every accepted Standards/Spec review finding in one focused pass:
normal Pi worker Data Service tool allowlist, Pi camelCase Skill input,
loopback preview Origin acceptance, browser-generation lifecycle fencing,
README/Skill documentation, narrow parser sharing, and removal of two
unused compatibility seams.
- Keep the remediation limited to existing Data Service, Pi, Skill, preview,
routing, and tests; do not alter the unrelated Pi E2E selector failure.
## Intent And Constraints
- Follow the MakeLore Data Service P0 specification sections 9.4, 10.1-10.3,
11-13 and ticket ML-09 in the accepted ticket graph. Main remains the only
Works credential owner; preview capability remains explicit, exact-Origin,
data-only, loopback-bound, and generation-bound.
- Preserve child explicit profiles, existing Agent Browser abstraction, route
auth/error/response ownership, ten public Data Service operations, and the
fixed SDK/Skill protocol. Do not add a generic route/repository/wrapper,
Firebase compatibility, retries, broad CORS, or unrelated E2E changes.
- Confirmed facts: the client coordinator has integrated ML-01 through ML-08
and is clean at the stated base; the server contract/ADR are the canonical
cross-repository inputs. The known full-E2E Pi model-combobox timeout is
pre-existing and outside this remediation unless red evidence ties it to
this diff. Review ledger accepted eight findings: allowlist, camelCase
Skill field, loopback Origin, generation equality, README, narrow parser
sharing, unused `onLifecycle`, and unused `handleDataServiceRoute`.
- Unverified external inputs remain signed-in live acceptance, deployed server
state, and production packaging; this task cannot claim them.
## Planning Gate
- Result: Passed on 2026-08-27.
- Concurrent gate ran `check_project_docs.py`, then `task_context.py start`
with an occupied coordinator as source, producing the isolated worktree and
matching Git-common ownership. `status --json` verified the task ID, feature
mode, absolute worktree, branch, and exact base.
- Read the active task record, project positioning, integrated current state,
decision index, system overview, architecture/domain/evidence/reflection/
commitment/stale indexes, client coordinator scope, and the server's
canonical Data Service spec, ticket graph, integration contract, and ADR.
- Other active Data Service coordinator scope is read-only context; it owns
the parent integration worktree, while this task owns only this remediation
worktree. ML-01 through ML-08 source worktrees are released or integrated;
no semantic file-ownership conflict is unresolved.
## Plan
1. Inspect current Pi tool registration, Skill assets, preview session/server,
route modules, shared route helpers, and lifecycle wiring; add red tests for
each accepted finding before the smallest corresponding implementation.
2. Implement the eight fixes without widening P0 boundaries; run affected
focused suites after each cohesive group.
3. Run full unit (including pressure), typecheck, lint, build, Electron, and
affected E2E checks available in this environment; retain any real
prerequisite or pre-existing failure as an explicit deviation.
4. Run diff/doc-drift checks, update this task record with outcome and evidence,
commit once, and complete the Task Documentation Gate.
## Outcome
- Completed the eight accepted ML-09 remediation findings on the exact ML-08
client head:
- Normal Pi parent workers now default to the exact ten Data Service tools
from the shared contract; read-only and coding child profiles remain their
original explicit arrays, and the packaged child proof rejects all parent
product tools including Data Service tools.
- The bundled Skill now uses Pi's camelCase `injectProjectData: true` open
input. The raw Host HTTP snake_case adapter remains separate.
- Preview sessions accept credential-free HTTP and HTTPS loopback Origins,
including default ports, while retaining loopback, exact-origin, no-path,
and no-credentials restrictions. Lifecycle invalidation is fenced to the
session's current browser generation.
- README now names the fifth opt-in `data-service` Skill and documents its
short inspect/confirm/configure/SDK/preview read-back workflow without
duplicating the protocol.
- Identical Data Service record/body/path/query/revision/data parsers now
live in the narrow `data-service-parsers.ts` module. Each route retains its
own parser failure type/messages, authentication, response projection, and
CORS behavior.
- Removed the unused Agent Browser constructor `onLifecycle` option and the
unused `handleDataServiceRoute` alias; production `subscribeLifecycle` and
`handleDataServiceRoutes` remain.
## Verification
- RED: the new allowlist, Skill, Origin/generation, README, and alias
assertions failed at the unfixed base as expected.
- Focused remediation suites: 10 files, 142 passed, 2 skipped.
- Full unit and pressure suites: 188 files, 1,612 passed, 2 skipped; pressure
suite 1 passed.
- `pnpm run typecheck`: passed.
- `pnpm run lint:check`: passed with five existing warnings in
`src/pages/Home/index.tsx` and `src/pages/Makelore/index.tsx`; no errors.
- `pnpm run build`: passed, including Vite, staged Pi runtime, and Windows
Electron packaging. Existing chunk-size, optional-resource, and NSIS patch
warnings remained non-fatal.
- `pnpm run test:electron:windows`: 2 files, 4 passed.
- Affected E2E: `project-configuration-skills.spec.ts` 1 passed. The Pi chat
spec had 1 passed and 1 timeout on the known model-combobox selector; the
failure is the same pre-existing baseline issue and has no diff evidence,
so it was not changed.
- `git diff --check` and the project-docs ownership/drift checks passed.
## Follow-ups
- Parent integration must merge this single remediation commit into the client
coordinator branch, then run the cross-repository X-01 against real
PostgreSQL and a logged-in MakeLore preview. This task did not claim live
acceptance or server deployment state.
## Promotion Candidates
- None recorded; the remediation changes are repository-local and the
canonical cross-repository contract/ADR already describe the retained
boundaries.