docs: record module access integration

This commit is contained in:
2026-08-17 10:15:51 +08:00
parent 4013edcbbc
commit f0d660926f
2 changed files with 6 additions and 5 deletions

View File

@@ -8,7 +8,7 @@
- Worktree: D:\Datas\OthersProjects\makelore
- Base commit: 4fbd1d3b24493532ce479729da2c5e5e1709c8a9
- Owner: codex
- Status: In Progress
- Status: Completed
## Scope
@@ -106,7 +106,7 @@ Gate result:
- Reused the existing Integration owner after the user explicitly authorized takeover while preserving its uncommitted record. Registry status still identifies task `20260813-sync-push-main-9c2f71`, mode `integration`, branch `main`, and worktree `D:\Datas\OthersProjects\makelore`; no new task context was created.
- Verified source task `20260817-makelore-module-access-6f2a91c4` is `ready_for_integration`, source tip `3b799af` is present as the current `MERGE_HEAD`, and the no-ff/no-commit merge stages the reviewed product changes. Its task record remains read-only on the source branch and is deliberately excluded from the integrated `main` tree.
- Read the source outcome, verification, follow-up and promotion candidate against the Main-owned Works Session boundary and current four-module model. No accepted ADR or peer source contradicts default-open compatibility, `design` → `painting`, pre-layout route blocking, global `/settings`, terminal `401` session cleanup, or the explicit non-authorization boundary.
- Integration outcome remains pending until canonical reconciliation, merged-tree checks, independent final review and the final merge commit complete. The final merge SHA does not yet exist and must not be invented.
- Canonical reconciliation, merged-tree checks and independent final review all passed. Git created normal no-ff merge commit `4013edcbbc982fcbef0a0ff6287c5307cd87bf8a` with first parent `eb16f73e4dece86a193dee0f797a58d77869470f` and reviewed source `3b799af17370dfa6c4c995c3fcbab8f2d84c3dda` as second parent.
- Gate result: Passed for canonical promotion and merged-tree verification. Works migration/API deployment, a newly built client package, real-account four-module smoke and server-side API authorization validation remain release commitments.
### 2026-08-16 Remote `26b52d7` Synchronization Resume
@@ -265,7 +265,7 @@ Gate result:
## Outcome
- 2026-08-17 module-access staged integration passed merged-tree verification and independent final review and is ready for its merge commit. Canonical reconciliation records the source tip `3b799af`, Main-owned four-boolean projection, default-open compatibility, `design` → `painting`, disabled card/root/deep/alias guards before initialization, Code policy hydration, terminal `401` dual-session cleanup, global `/settings`, and the client-entry-only security boundary; the exact merge SHA will be recorded only after Git creates it.
- Created normal no-ff module-access merge commit `4013edcbbc982fcbef0a0ff6287c5307cd87bf8a` with preserved integration-history commit `eb16f73e4dece86a193dee0f797a58d77869470f` as first parent and reviewed source tip `3b799af17370dfa6c4c995c3fcbab8f2d84c3dda` as second parent. Canonical reconciliation records the Main-owned four-boolean projection, default-open compatibility, `design` → `painting`, disabled card/root/deep/alias guards before initialization, Code policy hydration, terminal `401` dual-session cleanup, global `/settings`, and the client-entry-only security boundary.
- A mandatory pre-push fetch found authoritative `origin/main` had advanced to `01bee3188be4b03b6b358c2da60f1f9ed22d707f`, so no stale push was attempted. Started a second normal `--no-ff --no-commit` merge with reviewed local merge `bb16c1d12a24b2957149db960edba6e6660691aa` as first parent and `01bee31` as second parent; README was the only textual conflict and was reconciled to preserve both the enabled Learning module and the detailed Robot hotspot flow.
- Preserved the remote Learning product scope, four-module navigation, profile reuse, removal of `game-engine`, and project-root `planning-with-files` output. The merged tree no longer depends on a sibling OpenMAIC checkout: CI/release packaging requires the fixed manifest artifact, while an explicit local source remains development-only.
- Closed merge-audit security/correctness findings across Learning: strict Host/service DTO and safe-error projection; bounded Agent/ASR/runtime and ZIP consumption; Main-derived opaque account partitions for generation, local courses, IPC and player registration; fixed-binding checks across token acquisition, fetch and 401 refresh; stale account/epoch result rejection; 512 MiB archives; same-Works-origin redirects with a 5-hop cap and no resource Bearer; a nonce-protected account-bound player HTTP session; and an exact-source/origin single-document iframe bridge.
@@ -394,6 +394,7 @@ Gate result:
- 2026-08-17 merged-tree TypeScript `tsc --noEmit` and scoped ESLint on all changed TypeScript/TSX files — passed.
- 2026-08-17 merged-tree Renderer/Electron Main/Preload `pnpm run build:vite` — passed; only the existing chunk-size and mixed static/dynamic import warnings remain.
- 2026-08-17 independent staged-merge Sol review — `PASS`, no blocking Standards or Spec findings. It independently reran 69 focused tests, typecheck, scoped ESLint, `build:vite`, document drift, registry doctor and diff checks, and confirmed the intended two-parent topology and source-task-record exclusion.
- Post-commit topology check confirmed merge `4013edc` has exact parents `eb16f73` and `3b799af`, the source tip is a `main` ancestor, the source task record is absent from `main`, and the product worktree is clean before this evidence-only update.
- Remote `01bee31` merged-tree `pnpm install --frozen-lockfile` passed with the package-pinned pnpm 10.33.4; Electron 40.10.6 was restored with `pnpm rebuild electron` before desktop smoke.
- Learning/Robot/Canvas/publish/OpenCode focused selection — 26 files / 418 tests passed.
- Bounded full unit suite — 175 files / 1944 tests passed.