merge: integrate remote learning module safely
Some checks failed
Electron E2E / Electron E2E (macos-latest) (push) Has been cancelled
Electron E2E / Electron E2E (ubuntu-latest) (push) Has been cancelled
Electron E2E / Electron E2E (windows-latest) (push) Has been cancelled

This commit is contained in:
2026-08-17 01:05:49 +08:00
125 changed files with 11451 additions and 12132 deletions

View File

@@ -10,6 +10,11 @@
- Electron 双视口预检必须检查与最终 `built_archive` 相同的内存文件字节;预检失败不得上传,预检成功不得被表述为可信审核凭据。
- 上传协议必须同时携带源码归档、构建归档和严格版本化 artifact contract;服务端独立重算摘要、校验合同并固化不可变 Release。
- Renderer 不得获得发布凭据、归档、临时目录、构建 origin 或任意本地路径;旧客户端和旧 sandbox/browser 任务必须提示升级后重新构建提交。
- Works Project 在没有 metadata revision/条件写与 cover 回收合同的阶段,首次 create 只能原子保存文字资料且不上传封面;已有项目只能 version-only。客户端不得通过无条件 PATCH、先上传封面或吞掉并发冲突来模拟原子性。
- Learning 课程目录、生成、下载、Agent、ASR 与 classroom runtime 必须保持 Main-owned;Renderer 不得获得 Works Token、Provider/模型配置、本地 archive 路径或任意网络代理能力。
- Learning 课程包必须匹配声明大小与 SHA-256 后原子安装并在播放前复验;媒体必须是 MIME/扩展匹配的被动图片、音视频或字体,可执行同源文档在安装和服务两层拒绝。大课模块必须绑定同一 aggregate 课程身份,课堂联网只允许固定 capability、方法和有界请求/响应。
- Learning 本地库、下载、播放器注册和 IPC 结果必须绑定 Electron Main 从当前登录身份派生的不透明账号分区;切换账号、注销或会话 epoch 变化后,旧账号文件、播放器 URL 和迟到结果不得继续可见。
- Learning 归档必须限制为最多 512 MiB;下载最多跟随 5 次同 Works origin 的 HTTP(S) 重定向且不得向资源重定向转发 Bearer。播放器必须校验精确 loopback origin、账号绑定与短效 nonce;只有显式课堂读取能注册资源,Agent/runtime 必须先验证调用前已存在的 active registration,再做无副作用权威解析,不能接受任意来源消息、自注册课程或跨账号资源。
- Robot Guided Hotspot Binding 必须保持固件零改动、Main-owned default-on capability、精确环境值 `0` 回滚、固定系统浏览器 Portal 和现有六位 Binding facade。Windows/macOS 页面内只能扫描开放 `Xiaozhi-*` 短效候选并连接用户明确选择的项;Makelore 不得接触家庭 Wi-Fi 凭据,也不得把热点发现或 Binding 成功等同于可信身份/在线。
## Quality Checks
@@ -17,8 +22,9 @@
- 发布安装包前运行 `pnpm verify:publish-runtime`,并对最终 Windows 产物运行 `pnpm verify:artifact:win`;固定 npm 闭包缺失或版本不符时 fail closed。
- 至少覆盖 release builder/静态产物服务/发布路由/Renderer 状态的聚焦测试、typecheck、scoped lint、Vite 构建和真实 Electron 双视口 production-seam E2E。
- 真实生产发布仍需成组验证服务端合同、不可变 Release、运营审核、CDN/App 播放;客户端本地验证不能替代该整链验收。
- Learning 上线前必须使用真实 Works 账号、固定 URL/SHA-256 的 production Stage artifact 和正式安装包验证目录/生成/材料/取消恢复、下载、离线多模块播放、进度、Agent、ASR 与 PBL/评分;客户端自动化不得替代 Windows 与签名 macOS 整链验收。
- Robot 默认引导路径必须通过聚焦 Renderer/Main/native 测试并保留 `NIANCODE_AI_HARDWARE_GUIDED_HOTSPOT_BINDING=0` 回滚。真实 Host API/native seam Electron E2E、Windows Robot 真机、签名 macOS x64/arm64、指定固件镜像与六位码发行契约未完成前,不得宣称完整双平台硬件兼容或端到端配网已经验收。
## Last Reviewed
2026-08-16
2026-08-17

View File

@@ -6,7 +6,7 @@
|---|---|---|---|
| 登录续期 | Renderer 活动信号 | Main Works Session | 连续 7 天未使用才清除会话 |
| 项目创建 | 新建项目对话框 | Host API → Main 项目初始化 | 创建时固定 `ProjectType`;小游戏/小程序原子生成受控模板,自定义只生成项目空间 |
| 一键提交 | `ProjectPublishAction` | Renderer capability → Host API → Main 本地 npm/Vite build → built snapshot preflight → source+built+contract 上传 | 只对小游戏/小程序开放;Main 自动版本、幂等重试和脱敏,Renderer 轮询服务端校验/固化状态 |
| 一键提交 | `ProjectPublishAction` | Renderer capability → Host API → Main 本地 npm/Vite build → built snapshot preflight → source+built+contract 上传 | 只对小游戏/小程序开放;首次 create 原子写入文字资料但不上传封面,已有 draft/published 只提交版本并沿用云端资料/封面;状态竞态固定失败,不做无条件 metadata PATCH |
| 构建产物预检 | Main-owned built snapshot | 一次性 loopback origin → fresh Electron WebContents/CDP(桌面、移动) | 检查错误、白屏和外域;不调用 Playwright,检查与上传归档相同字节,但不产生可信 receipt |
| 提交绑定 | 云端成功上传响应 | Main → submission binding v2 | 只持久化成功的 app/version/review/hash;落盘失败返回固定告警但不反转提交 |
| 运营发布 | Works Square 审核与交付 | 公共 `play_url` | 客户端只消费服务端发布结果;真实合同校验 → OSS/CDN 生产链仍待整链验收 |
@@ -22,6 +22,9 @@
| 设计 Quote 编辑与重报价 | 当前 Conversation 的 active Quote | Renderer 修改最终 Prompt/参数 → Main Host API → Works Square Quote update → 当前 Conversation | 服务端返回最新参数与设计点;报价完成前不能确认,确认提交最新原值,客户端不自行计价 |
| 设计项目删除 | Canvas 侧栏精确项目名确认 | Renderer → Main Host API → Works Square Workspace DELETE | 删除成功后清理当前 Workspace/Conversation/task stream 并选择最近更新的剩余项目;结算与软删除语义由服务端负责 |
| Prompt Museum 浏览与使用 | Canvas 侧栏“获取灵感” | Renderer → Main Host API → Works Square list/detail;选中 Prompt → 进程内 pending state → 当前 Canvas 输入框 | 只发送白名单筛选/游标;Works Token 留在 Main,Prompt 不自动发送,Museum 不包含客户端静态数据集 |
| Learning 课程生成 | Learning 生成工作台 | 无材料:Renderer → Host API;有材料:Renderer → 白名单 IPC → Main strict bounded multipart → Works Square generation | 需求最多 4,000 字;最多 5 个材料、单个 50 MiB、总计 150 MiB;外层对象、id/order/MIME/时间/字节先严格投影,Token 和 multipart 网络请求留在 Main |
| Learning 下载与播放 | 课程卡片 / 已安装课程 | Main 账号分区 → 同 Works origin、最多 5 跳的受控下载重定向 → 512 MiB 上限与大小/SHA-256 校验 → 原子本地安装 → account-bound verified loopback production Stage | 资源重定向不携带 Bearer;播放前重验 archive;课程媒体仅允许 MIME/扩展匹配的被动图片、音视频和字体,运行时同时加 nosniff/CSP 并拒绝可执行文档 |
| Learning 联网课堂 | 本地 production Stage 的 Agent/ASR/PBL/评分请求 | nonce-protected loopback player → iframe exact source/origin + 单文档 bridge → Renderer 绑定当前已读课程/模块/账号 epoch → allowlisted IPC → Main 验证调用前 active registration → 无副作用权威解析课程/模块 → Works Square | 只有显式课堂读取会注册资源;Agent/runtime 不能靠自身请求注册课程。只允许固定 capability、方法和有界 body/response;二次 iframe 导航永久关闭 bridge,账号变化会丢弃迟到结果并关闭/轮换 player session |
| Robot 引导式热点配网 V1(已实现、默认开启) | Robot Binding 页面 | 用户选择引导配网 → 进入固件配网模式 → Renderer 经 Host API 请求 Main 扫描 → 用户选择短效候选 → Windows/macOS Adapter 连接并核验当前 SSID → Main 打开固定 Portal → 用户在 Portal 配置 Wi-Fi → 电脑恢复互联网 → 现有六位 Binding | 精确环境值 `0` 或 capability 读取失败回退直接六位码;系统 Wi-Fi 保留兜底,Makelore 不收集 Wi-Fi 密码、不修改固件,热点发现/`bound` 都不等于可信身份或 online/ready |
## State Ownership
@@ -33,6 +36,7 @@
- 旧 schema v1 `submitted` 记录迁移并保留;旧 `armed`、`waiting_for_package`、`waiting_for_login`、`uploading`、`failed` 归一为 `legacy_retired`,不再启动 watcher 或上传任务。
- AI 绘画 Conversation 持有消息、Brief、Quote、`turnRevision` 和服务端 Session 绑定;Workspace 持有 Conversation 列表、生成任务和资产。
- Prompt Museum pending Prompt 是 Renderer 进程内一次性导航状态;Canvas 消费后立即清除,不进入 Workspace/Conversation 直到用户主动发送。
- Learning Main 本地课程库按当前认证身份派生的不透明 account partition 持有 archive 路径、安装记录和 player registration;Renderer 只接收课程 DTO、classroom 投影和当前账号的 loopback player URL。账号 epoch 变化会使旧异步结果、runtime 事件、player URL/cookie 与注册资源失效。云端进度以课程 aggregate hash 为身份,模块进度附带受控 module id/hash。
- 图生图参考图与视频首帧都先归一为当前 Workspace 的 Asset;从作品选择时复用生成结果 Asset,本地选择时先走既有上传接口,再把唯一 Asset ID 随 Turn 提交。选择或上传成功后关闭选择器。
- 本地开发适配器将旧单会话 schema v2 原子迁移为带默认 Conversation 的 schema v3;打包应用不使用该本地适配器作为云端失败回退。
- 注销和退出会关闭本地事件流并清除本机 Conversation Session-id 缓存;服务端持久 Session 保留,下一次访问从 Conversation API 重新读取。
@@ -52,8 +56,10 @@
- 服务端安全投影后的公共 `play_url`;只接受同源 HTTPS、精确 App 路径和可信版本状态。
- Works Square Workspace/Conversation API、每个 Conversation 的持久 Agent Gateway Session、单次 WebSocket ticket、双向命令/事件帧与幂等 REST 传输回退。
- Works Square Prompt Museum list/detail API;Main 添加当前账号 Bearer Token,Renderer 只使用 Host API 投影。
- Works Square Learning catalog/generation/progress/download、Agent、ASR 与 classroom runtime API;Main 添加当前账号 Bearer Token 并限制路径、DTO、材料、能力与响应大小。
- 版本化 OpenMAIC production Stage artifact;CI 按固定 URL/SHA-256 获取,打包前清单校验,运行时只从已验证安装资源或显式开发根加载。
- 已实现的本机 Robot provisioning capability、固定 portal-open 与 hotspot scan/connect Host API。它们是本地 Main 操作,不读取 Works access token、不调用上游,也不接受任意 URL/SSID/BSSID/interface/profile。
## Last Updated
2026-08-16
2026-08-17

View File

@@ -32,7 +32,9 @@
| `shared/image-prompt-museum.ts` | Prompt Museum 列表、分类、详情、署名与分页共享 DTO | 客户端不包含内容数据集,只定义服务端字段契约 |
| `electron/api/routes/image-prompt-museum.ts` | Main-owned Museum 列表/详情代理与 Works 登录态 | 仅 GET 固定路径和白名单查询;Renderer 不获得 Bearer Token |
| `src/pages/ImagePromptMuseum/index.tsx` / `src/lib/image-prompt-museum.ts` / `src/stores/image-prompt-museum.ts` | Museum 搜索/筛选/详情与一次性 Prompt 回填 | 原 Prompt 只带回 Canvas 输入框,不自动发送;页面不接受投稿或互动 |
| `.opencode/skills/game-engine/` | 可选游戏引擎专项 Skill、模板与参考资料 | 随产品打包但创建伙伴时不默认勾选;未选择时保持 Skill 拒绝权限 |
| `shared/learning.ts` / `src/lib/learning.ts` | Learning 课程、生成、进度、播放与 runtime 的共享 DTO/Renderer facade | 普通云端数据走 Host API;材料、课程包与本地播放器能力走白名单 IPC,Renderer 不持有 Token、归档路径或账号分区键 |
| `electron/api/routes/learning.ts` / `electron/services/learning-*.ts` | Main-owned Learning 云端代理、账号分区本地课程库、Agent/ASR/runtime 与播放器服务 | 固定 Works 路径/能力、输入与响应边界;课程包和外部 production Stage artifact 使用大小/摘要/清单校验;player HTTP session 使用账号绑定与 nonce,iframe bridge 使用 exact source/origin 和单文档生命周期 |
| `src/pages/Learning/` / `src/components/layout/LearningSidebar.tsx` | 课程广场、生成工作台、模块选择和嵌入式课堂 | 大课保持单课程 aggregate,模块只选择同一已验证包内的 production Stage |
| `src/pages/AiHardware/index.tsx` | Robot 管理、现有六位 Binding,以及已实现的 default-on 引导式热点配网状态机 | 只编排非敏感步骤;不接收 Wi-Fi 密码,不把 `bound` 展示为在线证明 |
| `src/lib/ai-hardware.ts` | Renderer 侧 Robot Host API 类型、安全错误映射和稳定 Binding/hotspot facade | 读取 Main-owned capability,调用固定 portal-open,并只传递短效 hotspot candidate ID;不添加任意 URL、SSID 或 Renderer IPC |
| `electron/api/routes/ai-hardware.ts` | Main-owned Robot 云端代理,以及本地 capability/portal/hotspot actions | 默认开启、精确环境值 `0` 回滚;所有本地操作必须在 Works token/上游访问前返回,且只投影稳定安全错误 |
@@ -49,6 +51,7 @@
- Built artifact preflight 检查最终上传的同字节快照,但客户端可被绕过且不产生可信 receipt;服务端仍是合同、摘要和不可变 Release 安全权威。
- Robot Renderer → typed AI hardware API → Main Host route → Robot Hotspot Module → Windows/macOS Adapter。云端 Binding 仍由 Main 代理;热点选择/连接移入页面,但家庭 Wi-Fi 凭据输入仍只留在固件 Portal,系统 Wi-Fi 保留为兜底。
- Prompt Museum Renderer → typed Host API facade → Main fixed list/detail route → Works Square。Museum 只把用户明确选择的 Prompt 原文暂存到进程内 Store 并导航回当前 Canvas;不会直接触发 Agent 命令或生成任务。
- Learning Renderer → typed Host API / allowlisted IPC → Main account-bound Learning services → Works Square 或 verified local course/player artifact。Main 从认证身份派生本地不透明分区并以 epoch 拒绝迟到结果;课程 aggregate hash 是云端身份,模块 id/hash 不提升为独立权益主体。
## Risky Or Sensitive Areas
@@ -63,6 +66,7 @@
- 多 Conversation 事件处理必须区分对话快照与 Workspace 任务更新;不得用任务时间戳推进 Conversation 流水位,也不得让旧会话的迟到流覆盖当前会话。
- Quote 编辑、重报价、确认和项目删除都跨 Renderer/Main/Works Square。异步结果必须核对当前 Workspace + Conversation;删除当前项目时必须先使旧选择和事件流失效,再加载剩余 Workspace。
- Prompt Museum 图片和来源 URL 来自服务端数据。服务端必须完成内容授权/署名审核;若未来需要凭据化素材,应新增 Main-owned 媒体代理,不能把对象存储凭据放进 Renderer URL。
- Learning 的远端 JSON、错误、下载重定向、课程 ZIP、播放器 artifact 与 iframe runtime 都跨信任边界;必须保持严格 DTO/路径/大小/摘要/账号 epoch/同源重定向/player nonce/exact source+origin/单文档 bridge/能力投影、一次 401 refresh 和固定安全错误,不能把 Renderer/课程内容变成任意 Works 代理。
- Gateway 命令的 REST fallback 只处理 WebSocket 发送、断连和 ACK 超时,必须复用 `client_command_id`;业务错误回退会造成重复提交。Quote 任务恢复只更新 Workspace 所有的任务,不能覆盖当前 Conversation。
- `closeEventSessions` 只负责本地流和缓存生命周期;远端 Conversation Session 是服务端持久资源。
- 单图来源选择器当前仍由精确中文 quick reply 触发,并以 Brief medium 判断图生图或视频首帧用途;扩展更多输入用途前应先把消息协议升级为结构化 action/purpose,避免展示文案与行为继续耦合。

View File

@@ -23,6 +23,8 @@ Makelore 是 Electron 桌面客户端。Renderer 负责项目操作与状态展
| AI Design Gateway Routing | Main 云端适配器 ↔ Conversation WebSocket;Main → Host API/SSE → Renderer store | 命令、Run 与设计事件共用双向 WebSocket;Conversation 更新按 Workspace + Conversation 路由,任务更新按 Workspace 归并 |
| AI Design Quote & Task Controls | 当前 Conversation Quote 与 Workspace 任务 | 最终 Prompt/generation options 每次修改由服务端重新计价;任务结果在详情中预览并经 Main-owned asset download 保存 |
| Prompt Museum | Canvas “获取灵感”页面 → Main Host API → Works Square | 服务端驱动的审核内容、筛选和分页;Renderer 不持有 Works Token 或内置数据集,“使用此 Prompt”只回填输入框 |
| Learning Workspace | 课程广场、生成工作台与本地课程播放器 | Renderer 只持有安全课程/进度/任务状态;材料字节、课程归档、播放器产物和云端凭据由 Main 持有 |
| Learning Main Boundary | Host API + bounded IPC services → Works Square / account-partitioned verified local course library | 课程 API、生成、下载、Agent、ASR 与固定 runtime capability 由 Main 执行;课程包和 production Stage artifact 在使用前校验,账号切换使旧本地库、player registration 与迟到结果失效 |
| Robot Workspace | Account-scoped agent configuration, device activation/binding, assignment, and credential-recovery UI | Renderer receives only safe Works Square projections. Configuration choices come from the USER-scoped safe catalog; unavailable current values remain editable without exposing provider credentials or configuration internals. |
| AI Hardware Main Route | Fixed `/api/works/ai-hardware` Host API to Works Square proxy | Main owns Bearer auth, stable operation IDs, bounded retry, ETag/If-Match, request/response limits, error redaction, and the fixed no-store configuration-catalog proxy. Versioned responses accept only canonical strong or weak numeric ETags that equal the DTO revision; mutations always emit strong `If-Match`. It never forwards Renderer authorization headers. |
@@ -31,10 +33,11 @@ Makelore 是 Electron 桌面客户端。Renderer 负责项目操作与状态展
## Important Boundaries
- Robot is the single enabled hardware product module; there is no separate Hardware card. Learning remains disabled.
- Code、Canvas、Learning 与 Robot 是四个已启用顶层产品模块;Robot 仍是唯一硬件产品模块,不存在单独 Hardware 卡片。
- Product UI language is Chinese-only. Unsupported system or persisted language values normalize to `zh`; removed locale files are not runtime fallbacks.
- Packaged Canvas remains cloud-only with no local fallback. `pnpm run dev` now uses the cloud adapter; the local Workspace adapter requires the explicit development command and remains unpackaged-only.
- Prompt Museum is a read-only curated inspiration surface, not a user-content community. Main owns Works authentication and forwards only the bounded list/detail routes; the client never bundles museum content or automatically submits a selected Prompt.
- Learning uses a Main-owned cloud and local-package boundary. Renderer does not receive Works credentials, archive paths, provider/model configuration, or an arbitrary network proxy. Main derives an opaque account partition from the authenticated identity, bounds same-origin archive redirects and package extraction, and serves registered course assets only from an account-bound loopback player with exact-origin and nonce checks; classroom runtime is limited to explicit capabilities and aggregate-course identity.
- AI hardware network access is Main-owned. Renderer cannot hold Works Square or Xiaozhi credentials and cannot select arbitrary upstream paths or headers.
- Robot model, language, and voice choices are dynamically projected from the Xiaozhi USER catalog through Works Square and Electron Main; the catalog is bounded, account-scoped, and `private, no-store` at each public hop.
- One local account maps to one server-side Xiaozhi account binding. Agents and devices are resources beneath that account binding, not separate Xiaozhi users.

View File

@@ -4,7 +4,8 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
## Integrated Through
- `26b52d7`: Canvas Prompt Museum, editable server-priced generation Quotes, project deletion/task-detail workflow, cloud-default Canvas development entry, Chinese-only UI consolidation, and bundled `game-engine` Skill from the authoritative remote main.
- `01bee31`: enabled AI Learning course catalog/generation/download/playback, Main-owned cloud/runtime bridges, verified external OpenMAIC player-artifact packaging, account profile reuse, removal of the transient `game-engine` Skill, and project-root `planning-with-files` output from the authoritative remote main. The merge hardens this with strict DTO/error projection, account-isolated local state, bounded same-origin downloads/packages, a nonce-protected account-bound player HTTP session, and an exact-source/origin single-document iframe bridge.
- `26b52d7`: Canvas Prompt Museum, editable server-priced generation Quotes, project deletion/task-detail workflow, cloud-default Canvas development entry, and Chinese-only UI consolidation from the authoritative remote main. Its transient bundled `game-engine` Skill is superseded by `01bee31`.
- `c1326a2`: Guided Hotspot Binding now scans bounded open `Xiaozhi-*` candidates and connects the user-selected hotspot inside the page through Main-owned Windows WLAN and macOS CoreWLAN/CoreLocation adapters; system Wi-Fi remains fallback, exact `=0` rollback and firmware/cloud contracts are unchanged.
- `b78fc07`: Guided Hotspot Binding is enabled by default in Electron Main, with exact environment value `0` as rollback and direct six-digit fallback on capability-read failure; firmware and Host/cloud contracts are unchanged.
- `b7a1590` / `14afe4a`: initial firmware-zero-change Guided Hotspot Binding V1 implementation and decision used a Main-owned default-off capability, fixed portal action, in-memory Renderer journey, and existing six-digit Binding contract; `b78fc07` above supersedes only that default.
@@ -33,6 +34,8 @@ AI 绘画的一个 Workspace 可包含多条 Conversation。消息、Brief、Quo
Canvas 侧栏提供“获取灵感”进入 Prompt Museum。列表、筛选、分页、详情、作者/来源/许可证和图片地址全部由服务端经 Main-owned Host API 提供,客户端不打包静态数据集;“使用此 Prompt”只把原文带回当前 Canvas 输入框,不自动发送。该模块不是投稿、点赞、评论或排行榜社区。客户端契约已就绪,但不据此宣称 Works Square 内容后台和生产数据已经部署。`pnpm run dev` 现在默认使用云端 Canvas 适配器,本地适配器只能通过显式开发命令启用;产品 UI 只保留中文。
AI 学习现在是已启用顶层模块。Renderer 浏览 Works 课程、提交单课生成需求、显示任务进度并打开已安装课程;材料上传经 Main IPC 严格投影,需求最多 4,000 字,文件最多 5 个、单个 50 MiB、总计 150 MiB。Main 持有 Works Token、生成/课程下载/Agent/ASR/课堂 runtime 访问和按认证身份派生的不透明账号分区;账号切换、注销或 epoch 变化会隐藏旧本地课程、关闭旧 player server 并丢弃迟到结果。课程归档最大 512 MiB,只允许同 Works origin、最多 5 跳且不携带资源 Bearer 的下载重定向,按服务端声明大小与 SHA-256 校验后原子安装并在播放前再次校验。安装期和 player server 只允许 MIME/扩展匹配的被动图片、音视频和字体;同源 HTML/SVG/XML/脚本/PDF 被拒绝,运行时响应带 nosniff/sandbox CSP/CORP/no-store。只有显式 `readClassroom` 会注册课程;Agent/runtime 先验证调用前既存 active registration,再用无副作用 resolver 核对本地 aggregate/module,不能靠自身请求注册。HTTP URL/cookie 由短效 nonce 保护;iframe bridge 校验精确 source/origin,只允许初始 player 文档,二次导航后永久关闭。课程 aggregate `contentHash` 是云端权益/进度身份,模块 hash 只作为受控上下文。打包必须提供由固定清单与 SHA-256 验证的 OpenMAIC production Stage 产物;当前客户端自动化不等同于真实 Works 课程服务、生产播放器产物或签名安装包验收。
AI 编程首次发送在新建 OpenCode session 已知为空时不再等待冗余历史读取,prompt 可直接进入 Host API;普通历史会话仍刷新消息。Main AI proxy 只把明确的上游分组饱和投影为当前 OpenCode 的终止状态,配额耗尽保持独立终止态,通用限速继续保留 `429`。上下文压缩以每个 Session 的持久时间线事件呈现:自动与手动压缩使用不同文案,运行态原位弱化显示,完成后静态保留并可从历史恢复;`session.compacted` 只完成对应事件,只有真实 idle 才结束 run 和释放排队消息。
Updater 仍由 Electron Main 选择目标 feed、记录原始诊断并保持失败语义。正式稳定源缺少对应平台 manifest 时,设置页只显示一条简洁中文提示并允许重试,不把缺包误报为已是最新版,也不向普通界面暴露堆栈、URL、路径或错误码;签名产物发布和真实升级安装仍属于外部 Release Gate。
@@ -41,7 +44,8 @@ Robot 绑定设备默认先显示“引导配网 / 已有激活码”路径选
## Recently Completed
- 2026-08-16: Integrated remote `26b52d7`: Canvas now has server-backed Prompt Museum navigation, editable server-repriced generation Quotes, task result details/downloads, guarded project deletion, cloud-default development, Chinese-only UI, and an optional bundled `game-engine` Skill. Client integration is verified separately from production Prompt Museum data/backend deployment.
- 2026-08-17: Integrated remote `01bee31`: Learning is enabled with course browsing, strict bounded generation materials, verified atomic course installation, multi-module playback, Main-owned Agent/ASR/runtime bridges, and a manifest-verified external OpenMAIC player artifact. Merge review added account-isolated generation/library/player state, fixed-binding token/fetch/401 guards, passive-only course media with hardened responses, pre-existing active-registration checks before side-effect-free identity resolution, nonce-protected single-document player sessions, and a recoverable deep-link profile error gate. Publishing now reflects the actual Works contract: first create is coverless, existing draft/published are version-only, and races fail closed without cover/PATCH side effects. The transient `game-engine` Skill was removed and `planning-with-files` writes its files to the project root. Production Works/player-artifact/signed-package acceptance remains pending.
- 2026-08-16: Integrated remote `26b52d7`: Canvas now has server-backed Prompt Museum navigation, editable server-repriced generation Quotes, task result details/downloads, guarded project deletion, cloud-default development, and Chinese-only UI. That tip briefly bundled `game-engine`; authoritative successor `01bee31` removed it. Client integration is verified separately from production Prompt Museum data/backend deployment.
- 2026-08-16: Integrated Windows/macOS in-page Robot hotspot discovery, explicit selection, connection, and exact-current-SSID verification behind the existing default-on guided capability. Candidate IDs are bounded and short-lived, native diagnostics stay in Main, system settings remain fallback, and firmware/Portal/Binding contracts are unchanged.
- 2026-08-16: Enabled the existing Guided Hotspot Binding journey by default after explicit product confirmation. Exact `NIANCODE_AI_HARDWARE_GUIDED_HOTSPOT_BINDING=0` remains the operational rollback; fixed portal ownership, direct-code fallback, security warnings, firmware-zero-change, and Binding-without-online semantics are preserved.
- 2026-08-16: Initially implemented ADR-002's Robot onboarding V1 without changing firmware, behind a default-off Main capability and fixed portal opener. The later `b78fc07` decision above changes only the default; the same firmware/issuer/native-opener/physical evidence remains outstanding.
@@ -67,9 +71,9 @@ Robot 绑定设备默认先显示“引导配网 / 已有激活码”路径选
## Next Recommended Steps
1. 对 default-on Guided Hotspot Binding 核对指定固件镜像与六位码发行/消费契约,补齐 Windows 真机热点连接、签名 macOS x64/arm64 CoreWLAN/CoreLocation/worker 打包验证、真实 Host API/native seam Electron E2E 和完整真机 smoke;发布支持保留精确 `=0` 回滚,不把缺失证据表述为已验收。
2. 成组核对客户端 source+built+contract 上传 → 服务端逐字节校验 → OSS immutable Release → CDN/Edge 的发布契约与客户端 `play_url` 消费契约。
3. 配置真实生产环境,分别执行“小游戏/小程序创建 → 客户端本地构建与同字节预检 → 提交 → 服务端合同/摘要校验与不可变 Release 固化 → 运营批准 → App 播放”。
1. 使用真实 Works 账号和固定 SHA-256 的 production Stage artifact 验收 Learning 课程目录/生成/材料上传/取消恢复、下载、离线播放、进度、Agent、ASR、PBL/评分 runtime,并完成 Windows 与签名 macOS 安装包 smoke。
2. 对 default-on Guided Hotspot Binding 核对指定固件镜像与六位码发行/消费契约,补齐 Windows 真机热点连接、签名 macOS x64/arm64 CoreWLAN/CoreLocation/worker 打包验证、真实 Host API/native seam Electron E2E 和完整真机 smoke;发布支持保留精确 `=0` 回滚,不把缺失证据表述为已验收。
3. 成组核对客户端 source+built+contract 上传 → 服务端逐字节校验 → OSS immutable Release → CDN/Edge 的发布契约与客户端 `play_url` 消费契约。
## Open Questions / Blockers
@@ -77,6 +81,8 @@ Robot 绑定设备默认先显示“引导配网 / 已有激活码”路径选
## Risky Areas
- Learning 的课程目录、生成、Agent、ASR 与 runtime 都依赖真实 Works 权益和服务端契约;本地课程归档与播放器 artifact 必须在信任前完成边界、大小与摘要校验。账号分区/epoch、fixed-binding token+fetch guards、同源重定向、512 MiB 上限、player nonce、exact source/origin 与单文档 bridge 边界不可放宽;不得把模块/场景自报身份当成 aggregate 课程权益,也不得把上游错误、Token、内部 URL 或本地归档路径投影到 Renderer。
- Works Project 服务当前没有 metadata revision/ETag、draft-only 条件写或封面删除/原子绑定合同;首次发布暂不上传封面,已有 draft/published 只允许 version-only。恢复封面或已有资料编辑前必须先扩展并真实验证服务端原子合同,客户端不得以无条件 PATCH 或孤立上传替代。
- Guided Hotspot Binding 默认开启并提供未经认证的热点扫描/显式连接,但当前 Hotspot/portal 仍是开放 SoftAP + 明文 HTTP,且精确出货镜像、激活码发行契约、签名 macOS、Windows 真机与完整整链尚未验证。界面必须保留环境警告,异常发布可用精确环境值 `0` 回滚;不得把 SSID 前缀宣称为可信设备发现、自动认领或在线证明。
- 一键提交已成功但本机 submission binding 落盘失败时必须保持提交成功、显示固定 `binding_warning` 并继续轮询,避免用户误判上传失败。
- 公共 `play_url` 必须满足 Works Square 同源 HTTPS、无 userinfo/loopback、精确 `/apps/{app_id}/` 路径、无 query/fragment、版本非空且上游标记可播放。
@@ -97,4 +103,4 @@ Robot 绑定设备默认先显示“引导配网 / 已有激活码”路径选
## Last Updated
2026-08-16
2026-08-17

View File

@@ -109,6 +109,13 @@ Gate result:
- Audit also rejected the remote Prompt Museum route because it forwarded unknown upstream/local error text and unvalidated success JSON. The merge adds strict bounded list/detail projection with HTTPS URL validation, fixed safe error mapping, stable 401-refresh failure handling, and focused regression tests. A remote E2E assertion was corrected to match the documented latest-message sidebar preview rather than an older user message.
- Gate result: Passed for completing the current normal merge, canonical promotion, proportionate merged-tree verification, independent final review, and a non-forced push. If the remote advances again before push, fetch and integrate that new tip before publishing.
### 2026-08-16 Remote `01bee31` Race Resume
- After creating reviewed merge commit `bb16c1d12a24b2957149db960edba6e6660691aa`, the mandatory pre-push fetch detected that authoritative `origin/main` had advanced from `26b52d7` to `01bee3188be4b03b6b358c2da60f1f9ed22d707f`. The push was stopped before any remote ref changed; local `main` is clean and is 13 commits ahead / 1 commit behind the new remote tip.
- The new remote commit is a direct child of the already integrated `26b52d7` and adds the enabled AI Learning module, Main-owned learning services/routes/runtime, verified external player-artifact packaging, profile/navigation changes, and focused tests. It also removes the transient bundled `game-engine` Skill and changes `planning-with-files` project output placement.
- This remote product change supersedes canonical statements that Learning is disabled and that `game-engine` is bundled. It does not authorize weakening the existing Robot native-network, Canvas cloud-workspace, Host API, authentication, or packaging boundaries. The merge must retain the reviewed Prompt Museum DTO/redaction fixes, the regenerated single-version `isbinaryfile@5.0.7` graph, Koffi packaging, and the cross-platform Robot hotspot path.
- Gate result: Passed for a second normal no-ff merge of `origin/main=01bee31`, semantic reconciliation of overlapping source and project memory, proportionate full verification, another independent final Sol review, and a non-forced push only after a fresh remote-race check.
### 2026-08-16 Cross-Platform Robot Hotspot Integration Resume
- Reused the existing Integration owner because it exclusively owns clean local `main` at `abecd5f34485ab467e5f032c618083d88e34b74d`; `task_context.py touch` refreshed the reservation and the registry reports this exact `main` worktree/branch owner.
@@ -176,6 +183,13 @@ Gate result:
3. Install the frozen lockfile and run focused Prompt Museum/Canvas/language/Skill plus Robot regressions, the full unit suite, typecheck, lint, production build, selected Electron E2E, project-document gates, and whitespace/topology checks.
4. Obtain an independent read-only Sol Standards/Spec PASS, create the normal merge commit with local `9af6c52` as first parent and remote `26b52d7` as second parent, fetch once more to detect races, then push without force and verify `origin/main` equals local `main`.
### 2026-08-16 Remote `01bee31` Race Plan
1. Merge freshly fetched `origin/main=01bee31` into clean local merge commit `bb16c1d` without rewriting history; resolve overlaps by retaining the reviewed local Robot/Canvas/security/lock fixes and the remote Learning product behavior.
2. Reconcile README, AGENTS product guidance, and canonical project memory for enabled Learning, removed `game-engine`, changed planning-file placement, and the Main-owned learning/player-artifact boundary without claiming unavailable cloud, signed-package, or physical-device evidence.
3. Run frozen-lock validation, Learning/Robot/Canvas focused tests, the bounded full unit suite, typecheck, lint, production build, relevant Electron E2E, document gates, whitespace/unmerged checks, and exact merge-topology checks.
4. Obtain a new independent read-only Sol Standards/Spec PASS on the final tree, create the second normal merge commit, fetch again for races, push without force, and verify local `main` exactly equals `origin/main`.
### 2026-08-16 Cross-Platform Robot Hotspot Integration Plan
1. Merge reviewed source `c1326a2` into local `main` with a normal no-ff merge while preserving source history; exclude the source-owned task record and proposal from the integrated tree.
@@ -241,6 +255,18 @@ Gate result:
## Outcome
- A mandatory pre-push fetch found authoritative `origin/main` had advanced to `01bee3188be4b03b6b358c2da60f1f9ed22d707f`, so no stale push was attempted. Started a second normal `--no-ff --no-commit` merge with reviewed local merge `bb16c1d12a24b2957149db960edba6e6660691aa` as first parent and `01bee31` as second parent; README was the only textual conflict and was reconciled to preserve both the enabled Learning module and the detailed Robot hotspot flow.
- Preserved the remote Learning product scope, four-module navigation, profile reuse, removal of `game-engine`, and project-root `planning-with-files` output. The merged tree no longer depends on a sibling OpenMAIC checkout: CI/release packaging requires the fixed manifest artifact, while an explicit local source remains development-only.
- Closed merge-audit security/correctness findings across Learning: strict Host/service DTO and safe-error projection; bounded Agent/ASR/runtime and ZIP consumption; Main-derived opaque account partitions for generation, local courses, IPC and player registration; fixed-binding checks across token acquisition, fetch and 401 refresh; stale account/epoch result rejection; 512 MiB archives; same-Works-origin redirects with a 5-hop cap and no resource Bearer; a nonce-protected account-bound player HTTP session; and an exact-source/origin single-document iframe bridge.
- Closed Renderer integration findings: ordinary OpenCode errors are visible again; Learning deep links cannot bypass the required profile gate; course/module loads use latest-request guards; generation state is account-scoped; and published-project resubmission explicitly preserves existing metadata/cover while uploading only a new version.
- Added a real Electron Learning navigation smoke and corrected three OpenCode slash-command E2E setup races by entering Code through the module chooser after setup. Production behavior was unchanged by the OpenCode test correction.
- Fixed the repository E2E script to invoke the declared `@playwright/test@1.59.0` CLI directly. The prior `pnpm playwright test` path selected a transitive alpha `playwright` CLI from `@playwright/mcp`, producing a false version-mismatch failure.
- The first independent final Learning merge review returned `FAIL` on four P1, three P2 and one P3 findings: Renderer-self-asserted course identity, account-switch token TOCTOU, old player/progress/form reuse, same-origin navigation bridge recovery, overlay-only profile gating, non-authoritative published status, premature documentation claims, and direct Renderer event IPC. The merge now revalidates installed/registered course identity in Main, threads captured binding guards through token/fetch/401 boundaries, closes and rotates player sessions, partitions/clears Renderer state, permanently disables a navigated iframe bridge, blocks Learning Outlet execution until profile readiness, re-reads strict project status after 409, corrects canonical nonce wording, and routes events through an allowlisted API-client seam.
- The second independent Learning merge review returned `FAIL` on two P1 and four P2 findings: Agent/runtime could register the requested course before checking active-player identity; executable same-origin course assets could message before a second iframe load; profile sync errors could leave an empty deep link; Works cover/metadata lacked atomic concurrency; material-generation IPC was not fully strict; and canonical evidence overclaimed closure. The final code separates side-effect-free `resolveClassroom` from explicit player registration, validates pre-existing active registration before Agent/runtime resolution, restricts course media to exact passive MIME/extension pairs with nosniff/sandbox CSP, renders a retryable profile error gate, strictly projects generation upload DTOs before auth/network, and adopts an honest coverless-first-create / existing-version-only Works workflow whose races fail closed without cover or PATCH side effects.
- The third independent Learning merge review returned `FAIL` on one P2 integration mismatch: the package consumer admitted `fonts/*`, while the player server only routed `audio|media`, so a declared playable font would install and then 404. Consumer and server now share the exact root/module `audio|media|fonts` directory contract and passive extension/MIME set; unsupported directories fail installation/HTTP lookup, and real registered ZIP-to-HTTP tests verify root WOFF and module WOFF2 with the expected MIME and security headers.
- The fourth independent Learning merge review returned `FAIL` on one remaining P2 composition bug: allowing a manifest-relative `modules/<id>/...` path caused the authoritative module root to be prepended twice. Manifest media paths now begin only with relative `audio|media|fonts`; the module prefix comes solely from `location.root`. A consumer-to-classroom-URL-to-registered-ZIP-to-real-HTTP test proves exactly one module prefix, correct WOFF2 bytes/MIME/security headers, and rejection of manifest-supplied `modules/` or other directories.
- The fifth and final independent Learning merge review returned `PASS` on Standards and Spec with no P0-P3 findings. It confirmed the consumer-generated modular font URL traverses the registered ZIP and real player HTTP response with one module prefix, and found no regression in registration, media safety, profile recovery, Works version-only behavior, generation DTOs, identity guards, canonical documents, packaging, Robot/Canvas, or the lock graph.
- The second merge remains uncommitted pending final project-document gates and independent Sol review. No remote ref has changed and no force option has been or will be used.
- On 2026-08-16, resumed the unfinished merge with local `main` at `9af6c526a9500a0dbfb88e39ba0dee1eb7e1d097` and freshly fetched remote `main` at `26b52d76e3dedd754ca1b1c428abaa074b7f98da`; `bfcb88cfefe714a60927a77822ae5a727ebe6604` is their merge base. README was the only textual conflict and now preserves both remote Canvas Prompt Museum wording and local Windows/macOS Robot hotspot behavior.
- Integrated the remote Canvas enhancements: editable server-repriced generation Quotes, result detail/download UX, exact-name project deletion, Prompt Museum, Chinese-only locale normalization, cloud-default development entry, and optional bundled `game-engine` Skill. Existing local Robot hotspot source, default-on rollback semantics, Koffi 2.16.3, packaging configuration, and firmware-zero-change boundary remain intact.
- Repaired the automatically merged lockfile by restoring the package-declared `isbinaryfile` override; frozen installation now succeeds. Corrected README's development-mode paragraph to match the remote cloud-default package script.
@@ -351,6 +377,19 @@ Gate result:
## Verification
- Remote `01bee31` merged-tree `pnpm install --frozen-lockfile` passed with the package-pinned pnpm 10.33.4; Electron 40.10.6 was restored with `pnpm rebuild electron` before desktop smoke.
- Learning/Robot/Canvas/publish/OpenCode focused selection — 26 files / 418 tests passed.
- Bounded full unit suite — 175 files / 1944 tests passed.
- `pnpm run typecheck` passed. `pnpm run lint:check` passed with 0 errors and 7 existing warnings.
- `pnpm run build:vite` passed for Renderer, Electron Main, and Preload; only existing mixed-import and large-chunk warnings remain.
- Corrected official `pnpm run test:e2e -- <selected specs>` passed 9/9 across Learning navigation, module navigation, Canvas workspace, first chat, OpenCode slash/compaction/layout, and project Skills.
- Learning player/account-focused joint selection passed 22/22 before final review. After the review findings were fixed, the combined 12-file selection passed 122/122, including fixed-binding token/fetch/refresh guards, authoritative course identity, A→B player/progress/form isolation, permanent post-navigation bridge denial, executable profile gating, strict project status/409 races, and the allowlisted event subscription seam.
- Post-review final bounded unit suite — 175 files / 1973 tests passed. Final `pnpm run typecheck` passed; `pnpm run lint:check` passed with 0 errors and the same 7 existing warnings; Renderer/Main/Preload `build:vite` passed with only existing mixed-import/chunk-size warnings.
- Post-review Electron E2E selection — 9/9 passed across Learning/module navigation, Canvas workspace, first chat, OpenCode slash/compaction/layout, and project Skills.
- Fourth-review final combined regression selection — 9 files / 161 tests passed across course library/IPC identity, consumer-generated classroom URL through real player HTTP, package media paths, generation DTO, profile gate, Works route and publish UI.
- Fourth-review final full suite — 175 files / 2028 tests passed. `pnpm run typecheck` passed; `pnpm run lint:check` passed with 0 errors and the same 7 warnings; Renderer/Main/Preload `pnpm run build:vite` passed with only existing mixed-import/chunk-size warnings.
- Fifth independent final review — Standards `PASS`, Spec `PASS`, overall `PASS`; no P0-P3 findings. It rechecked exact merge topology, clean staged state, the real consumer→URL→registered ZIP→HTTP font path, and all prior review closures.
- Second-review final Electron E2E — 4/4 passed for four-module layout, Learning enter/return, sidebar return, and project Skill behavior using the corrected declared Playwright CLI.
- Remote `26b52d7` merged-tree frozen install — passed with pnpm 10.33.4 after restoring the exact top-level lockfile override.
- Combined Prompt Museum/Canvas/language/Skill/Robot regression selection — 16 files / 284 tests passed before the Prompt Museum hardening; post-hardening Museum selection — 3 files / 12 tests passed.
- Prompt Museum hardening tests first reproduced all three audit findings, then passed after the fix. The final 3 files / 13 tests cover stable refresh-auth failure, successful `forceRefresh` with the new Bearer and one retry, unknown upstream/local detail redaction, and malformed/unsafe success DTO rejection. Typecheck and focused ESLint passed.
@@ -463,6 +502,9 @@ Gate result:
## Follow-ups
- Before releasing Learning, run a real Works account through catalog, generation/material/cancel-resume, bounded download, offline multi-module playback, progress, Agent, ASR and PBL/scoring using the exact production Stage artifact. Validate packaged loopback cookie/nonce behavior on Windows and a signed macOS build; current automation is not that acceptance.
- Before restoring project cover upload or editing metadata on an existing draft/published project, add and verify a server-owned revision/ETag plus draft-only conditional write and atomic cover attachment or cleanup. Until then the client intentionally creates new projects without a cover and treats existing projects as version-only.
- Packaging audit follow-ups outside this merge remain: verify macOS/Linux OpenCode multi-architecture staging, remove any unsupported Windows ARM64 advertising, pin the uv installer by digest, and replace unauthenticated curl-style installer paths before those release lanes are trusted.
- Before releasing Prompt Museum and the expanded Canvas deletion/repricing workflow, use a real Works account to validate Museum list/detail/pagination/attribution/CDN content, latest Quote pricing/confirmation, project soft-delete visibility, queued reservation release, and running-task settlement. Client tests do not prove the content backend or production billing/deletion semantics are deployed.
- Before claiming complete compatibility for the default-on Robot journey, verify the exact shipped firmware/fixed portal, six-digit issuer/validator freshness and consumption semantics, real Host API/native opener behavior, and a physical-device provisioning + Binding smoke. Keep exact `NIANCODE_AI_HARDWARE_GUIDED_HOTSPOT_BINDING=0` in support rollback instructions.
- The earlier default-false production instruction is superseded by the user's explicit default-on decision. Keep exact value `0` only as rollback, and do not touch `D:\Datas\HardwareProjects\xiaozhi-esp32-firmware` for this V1.
@@ -484,6 +526,7 @@ Gate result:
## Promotion Candidates
- Remote `01bee31` facts and the reviewed merge hardening were promoted into README, AGENTS, success criteria, current state, architecture/data flow, business rules, glossary, evidence and commitments: Learning is enabled but remains Main-owned, account-partitioned, bounded, artifact-verified and pending real Works/signed-package acceptance; `game-engine` is removed and planning files belong in the project root.
- Remote `26b52d7` facts were promoted into current state, architecture, domain rules, glossary, evidence, README, and release commitments: Prompt Museum remains read-only/server-driven, Quote pricing is service-owned, Canvas deletion is an explicit Workspace mutation, development is cloud-default, UI language is Chinese-only, and `game-engine` is an optional bundled Skill. Production Museum content and real-account billing/deletion acceptance remain pending commitments rather than completed evidence.
- The default-on candidate from `b78fc07` was promoted into ADR-002, current state, decision/success criteria, Robot architecture/domain/glossary, README, and a concrete release-validation commitment. No unresolved canonical candidate remains; the missing native/physical evidence is tracked as a pending commitment rather than overclaimed.
- The implementation truth from `b7a1590` was originally promoted as implemented/default-off. `b78fc07` now supersedes only that default; its former enablement evidence requirements remain tracked as default-on release validation and rollback commitments.

View File

@@ -13,6 +13,7 @@
- 客户端预检是可绕过的 UX fail-fast,不上传可信 receipt,也不声称具备生产 opaque-origin parity。服务端把源码、构建归档和 contract 当作不可信字节,独立重算、校验并固化不可变 Release;人工审核仍是不可绕过发布门禁。未来若要求 runtime 强门禁,必须由可信 verifier 绑定精确构建产物。
- 发布安全边界由 Electron Main 持有,Renderer 不接触账号 Token、ZIP、幂等键和本地绝对路径。
- 发布 Host API 必须在读取凭据、查询项目和打包前校验 Renderer capability;仅持有 Host token/base 的非 UI 调用方不得发起发布。
- 当前 Works Project 契约没有可验证的 metadata revision/ETag、draft-only 条件写或封面删除/原子绑定能力。首次发布只允许在 project create 中原子保存文字资料并暂不上传封面;已有 draft/published 只提交新版本并沿用平台资料与封面。404→create 409 等状态竞态必须固定失败并要求重新确认,不得上传孤立封面、无条件 PATCH 或静默丢弃表单资料。
- 客户端只持久化服务端已接受的 submission binding v2。旧 `submitted` 绑定必须保留;旧 `armed`、`waiting_for_package`、`waiting_for_login`、`uploading`、`failed` 必须迁移为可理解的 `legacy_retired`,不得恢复后台任务。
- 云端上传成功但本机 submission binding 保存失败时,提交仍视为成功;客户端显示固定、无本地路径的告警并继续轮询服务端校验与 Release 固化状态,避免诱导重复提交。
- 旧客户端缺少 source+built+contract 新协议,或服务端仍存在旧 sandbox/browser 任务时,必须提示升级客户端并重新构建提交;不得把它们伪装为新版瞬时故障。新版合同校验后的 `BUILD_STALE`、归档存储或 ReleaseStore 瞬时失败由运营在“构建异常”中重试。
@@ -34,6 +35,13 @@
- Prompt Museum 只展示服务端审核并带稳定作者、来源、许可证/署名和素材授权信息的内容;客户端不内置数据集、不推断缺失版权、不提供投稿/点赞/评论/收藏/关注/排行,也不自动发送或生成选中的 Prompt。
- Prompt Museum Renderer 只能通过 Main-owned 固定 GET 路由读取列表和详情。Works Token 不得进入 Renderer;列表查询只允许搜索、使用场景、风格、主体、语言、模型、游标和限制字段。需要受保护图片时必须新增 Main-owned 媒体代理,不能把 access token、内部路径或用户隐私放进图片 URL。
- 产品界面当前只支持中文;系统语言与历史持久设置中的其他值必须归一为 `zh`,不得保留不可达的伪语言选择。
- Learning 是已启用顶层模块。课程目录、生成、进度、下载、Agent、ASR 与课堂 runtime 的 Works 访问必须由 Electron Main 持有;Renderer 不得获得 Works Token、Provider/模型配置、归档路径或任意上游代理能力。
- 有材料的课程生成需求最多 4,000 字,最多接受 5 个文件,单个不超过 50 MiB、总计不超过 150 MiB;Main 必须在取 Token/发请求前严格投影外层对象、布尔选项、材料 id/name/MIME/size/lastModified/order/bytes 并拒绝重复或不连续顺序。材料字节不持久化到 Renderer 状态;无材料请求使用有界 JSON,所有生成控制路径和身份必须使用受限格式。
- Learning 本地生成任务、课程库、player registration 与 IPC 生命周期必须绑定 Electron Main 从认证用户派生的不透明账号分区;刷新只能保留原账号 binding,账号切换、注销、epoch 变化或卸载后必须拒绝旧异步结果、runtime 事件与资源访问。Renderer 持久化键不得使用 Token。
- 课程包最大 512 MiB,必须按服务端声明字节数和 SHA-256 完整下载并原子安装,播放前重新校验;下载只允许 HTTP(S)、无 userinfo、同 Works origin 的最多 5 次重定向,资源请求不得携带 Works Bearer。ZIP entry 数量、单项/总解压大小、压缩比、路径、JSON 深度/节点、模块 id/hash、场景数量和媒体引用必须保持边界。课程媒体仅允许与声明 MIME 精确匹配的 PNG/GIF/JPEG/WebP、MP3/M4A/AAC/WAV/OGG、MP4/WebM、WOFF/WOFF2/TTF/OTF;HTML/SVG/XML/脚本/PDF、未知/双扩展、控制字符和 MIME 不匹配必须 fail closed。大课模块属于同一 aggregate,不得把模块自报身份提升为独立课程权益。
- Learning player 只向当前账号注册并提供已验证课程资源;账号变化必须关闭/轮换 server 和 HTTP URL/cookie nonce。所有 course asset 响应必须使用被动 MIME、`nosniff`、sandbox CSP、same-origin CORP 和 no-store。iframe bridge 必须校验精确 loopback origin 与 source、只信任初始 player 文档并在二次 load 后永久关闭;`postMessage` 不得使用 `*`。只有显式 `readClassroom` 可以注册资源;Agent/runtime 在任何解析前先验证调用前既存 active registration,再用无副作用 resolver 反查当前账号已安装、复验的 aggregate/模块,课程内容不能靠请求自身注册或跨账号复用 URL/cookie。
- OpenMAIC production Stage 不从相邻源码或未验证本机构建目录回退。正式打包必须提供经过版本清单与 SHA-256 验证的 artifact;课堂只允许固定 Agent/ASR/PBL/评分能力,不能代理任意 URL 或方法。
- `game-engine` 不再是内置 OpenCode Skill。`planning-with-files` 在复杂任务中把 `task_plan.md`、`findings.md`、`progress.md` 写到当前项目根目录;不得写入 Skill 安装目录或用户目录。
- Robot V1 在现有 Binding 体验内扫描符合条件的开放 `Xiaozhi-*` 配网热点,并只连接用户明确选择的短效候选;该便利信号不得宣称为可信设备发现、自动下发家庭 Wi-Fi、自动认领或自动确认在线。
- Guided Hotspot Binding capability 由 Electron Main 持有且默认开启。精确 `NIANCODE_AI_HARDWARE_GUIDED_HOTSPOT_BINDING=0` 关闭引导;关闭或 capability 读取失败时保留现有六位码 Binding,Renderer 可以读取但不能覆盖它。
- Robot hotspot scan/connect 必须由 Electron Main 持有并在读取 Works 凭据前本地完成。Renderer 只能提交最近扫描生成的短效不透明 candidate ID,不能提交任意 SSID、BSSID、接口、profile 或命令。
@@ -56,7 +64,8 @@
- AI Canvas 双向 Gateway 与 Quote 任务恢复仍需真实账号执行一次生产确认 smoke,核对 WebSocket 不产生 `/runs/{run_id}` 轮询、任务按 Quote 出现在 Workspace 列表,并区分真正的 `agent_runtime_unavailable` worker 故障。
- Robot Guided Hotspot Binding default-on 发布仍需确认指定硬件/固件确实提供被审计的开放 Hotspot/Portal、部署端签发严格六位 ASCII 数字码且与 Works validator 的时效/消费语义一致,并完成 Windows 真机、签名 macOS x64/arm64 native worker/association 与真实设备端到端 smoke。
- Prompt Museum 客户端契约和页面完成不等于 Works Square 内容后台、审核数据或 CDN 已部署;上线前需以真实登录账号验证列表、详情、署名链接、分页、图片和 Prompt 回填。
- Learning 客户端集成不等于 Works 课程服务、权益、生成流水线、production Stage artifact 或签名安装包已验收;上线前需以真实账号和固定 artifact 完成 Windows/macOS 整链 smoke。
## Last Reviewed
2026-08-16
2026-08-17

View File

@@ -19,6 +19,12 @@
| Design Generation Quote | 服务端对当前最终 Prompt 与 generation parameters 返回的可确认报价 | 客户端可编辑后请求重报价,但不自行计算尺寸、供应商价格或设计点 |
| Prompt Museum | Canvas 的服务端驱动、只读策展灵感模块 | 展示经审核的预览、Prompt、分类和署名;不是社区,客户端不打包内容数据集 |
| Pending Museum Prompt | 用户点击“使用此 Prompt”后在 Renderer 进程内保存的一次性回填状态 | Canvas 消费后清除;只填充输入框,不自动发送或生成 |
| Learning Course Aggregate | Works 权益、进度和本地安装的产品级课程身份 | 由 `courseId + contentHash` 标识;大课的模块仍属于同一 aggregate |
| Frozen Learning Package | 下载后按字节数和 SHA-256 校验并原子安装的不可变课程 ZIP | 播放前重验;模块、场景、媒体与路径必须通过本地边界校验 |
| Learning Player Artifact | Makelore 打包的 OpenMAIC production Stage 静态产物 | CI 固定 URL/SHA-256,打包与运行时验证 artifact 清单;不依赖相邻源码仓库 |
| Learning Runtime Capability | 本地课堂可请求的固定 Works 联网能力 | 仅 Agent、ASR、quiz/PBL/评分等白名单路径;课程内容不能指定任意 URL、方法或身份 |
| Learning Account Partition | Electron Main 从当前认证身份派生的不透明本地分区键 | 隔离生成恢复、已安装课程、player registration 和异步生命周期;不把 Token 或原始账号标识用作授权 |
| Learning Player Session | 当前账号专属的 verified loopback production Stage 会话 | HTTP URL/cookie 使用短效 nonce;iframe bridge 使用精确 origin/source 和单文档生命周期;账号切换或注销后旧 URL、cookie 和注册资源失效 |
| Robot Provisioning | 让 Robot 获得目标 Wi-Fi 凭据并尝试联网的阶段 | 与云端 Activation、账号 Binding、协议在线是不同阶段;V1 由现有固件 Hotspot portal 完成 |
| Robot Activation | Robot 联网后向既有服务获取六位激活码的阶段 | 激活码由设备展示/播报给用户;Makelore 不生成该码 |
| Robot Binding | 用户把六位激活码和 Agent 提交到 Works Square,建立账号侧设备关系 | `bound` 不等于设备当前 online 或 protocol-ready |

View File

@@ -4,6 +4,7 @@ Use this index for searchable, traceable evidence records.
| Date | Topic | Status | Source | Detail |
|---|---|---|---|---|
| 2026-08-17 | 远程 `01bee31` Learning 主线集成与安全收口 | 合并树自动化与独立双轴复审通过;真实 Works、固定生产播放器 artifact 与签名安装包待验收 | 远程提交 `01bee31`、集成任务 `20260813-sync-push-main-9c2f71` | pnpm 10.33.4 frozen install、26 files / 418 pre-review focused、175 files / 1944 pre-review full;四轮审查修复后统一 9 files / 161、最终 175 files / 2028 full、typecheck、lint(0 errors / 7 existing warnings)、Renderer/Main/Preload build 与最终 Electron E2E 4/4 通过(更早跨模块选择 9/9 亦通过);第五轮 Standards/Spec 最终复审 PASS、无 P0-P3。最终树严格投影 generation IPC;分离显式 player registration 与无副作用 identity resolve;manifest 只接受相对 `audio|media|fonts`,权威 root 注入单一 module 前缀,consumer 生成 URL 已穿过 registered ZIP 的真实 HTTP/Woff2/MIME/security-header 测试;保持 fixed-binding 账号/Token/fetch/401 guard、512 MiB/ZIP/同源 5 跳下载、nonce player、exact-source/origin bridge 与可恢复 profile gate。Works 发布因缺少 revision/cover cleanup 合同采用 coverless first-create、existing version-only、竞态 fail-closed;不据此宣称生产服务或签名包已验收 |
| 2026-08-16 | 远程 `26b52d7` Canvas/Prompt Museum 主线集成 | 合并树自动化验证通过;真实服务端内容、计费与删除结算待验收 | 远程提交 `26b52d7`、集成任务 `20260813-sync-push-main-9c2f71` | 主工作区及独立临时目录 clean frozen install(955 packages)、16 files / 284 focused、Prompt Museum 3 files / 13、161 files / 1850 full、typecheck、lint、Renderer/Main/Preload build、Electron E2E 6/6 与文档门禁通过。合并额外修复 lock override 实际签名依赖图、Prompt Museum 未知错误脱敏/严格 DTO+HTTPS 投影/401 refresh,以及过期 E2E 断言;不据此宣称 Museum 后台审核数据、Quote 真实计费或 Workspace 删除结算已部署 |
| 2026-08-16 | Robot Windows/macOS 配网页内热点连接 | 实现与本地自动化验证通过;双平台实机发布证据待完成 | 源提交 `c1326a2`、ADR-003、集成任务 `20260813-sync-push-main-9c2f71` | 4 files / 132 focused tests、157 files / 1796 full tests、typecheck、lint、Renderer/Main/Preload build 与独立 Standards/Spec review 通过;Electron 40.10.6 加载 Koffi/wlanapi 成功,Windows 权限拒绝安全投影通过。签名 macOS x64/arm64、Windows Robot 真机和真实 Host/native Electron E2E 未完成,不得据此宣称双平台硬件验收 |
| 2026-08-11 | AI 设计多会话客户端集成 | 本地功能验证通过;仓库基线仍有既有失败 | `30-worklog/tasks/20260811-merge-all-code-a7c91e.md`、`4980894`、`03dae62` | 8 files / 116 focused tests、typecheck、changed-file ESLint、production build 与新增 Electron E2E 通过;生产 migration 0033/API 尚待验收,全量 lint/unit/E2E 的既有失败已单独记录 |

View File

@@ -4,6 +4,8 @@ Track future-facing memory: promised follow-ups, unfinished loops, timed checks,
| Date | Commitment | Trigger / Due | Owner | Status | Next Action |
|---|---|---|---|---|---|
| 2026-08-16 | 验收 AI Learning 的真实 Works、课程包与 production Stage 发布链 | 发布包含 `01bee31` Learning 行为的安装包前 | 客户端/服务端/发布集成 | Pending | 使用真实账号核对课程广场、单课生成(无材料/5 文件边界)、取消/恢复/finalize、同源最多 5 跳下载、512 MiB archive 上限、大小/SHA-256/原子安装、账号切换隔离、离线多模块播放、进度、Agent、ASR、PBL/评分权益;以固定 URL/SHA-256 的 player artifact 构建并完成 Windows 与签名 macOS 安装包 smoke,验证 packaged Chromium 的 loopback cookie/nonce,不以客户端单测替代生产验收 |
| 2026-08-17 | 恢复 Works 项目封面与已有资料编辑的原子合同 | 再启用首次封面上传或 draft/published metadata 编辑前 | Works 服务端/客户端发布集成 | Pending | 服务端提供可验证的 metadata revision/ETag 与 draft-only 条件写,以及原子 cover 绑定或失败清理/回收;客户端用真实竞态验证 404→create 409、draft→published 与 cover 失败均不产生孤立对象、不覆盖已发布资料。合同落地前保持首次 coverless、已有项目 version-only |
| 2026-08-16 | 验收 Prompt Museum 与 Canvas 删除/重报价的真实服务端链路 | 发布包含 `26b52d7` Canvas 行为的安装包前 | 客户端/服务端集成 | Pending | 使用真实 Works 账号核对 Museum 列表/详情/分页/筛选/署名/CDN/Prompt 回填;核对最终 Prompt/options 重报价和确认设计点;删除 Workspace 后确认软删除可见性、未提交任务取消/预留积分释放、已运行任务结算。保留 Main 错误脱敏和严格 DTO/HTTPS 投影,不以客户端回归替代服务端验收 |
| 2026-08-16 | 验收 default-on Robot Guided Hotspot Binding 的 Windows/macOS 真实设备链路 | 下一份包含页面内热点连接行为的安装包发布前 | 客户端/硬件/服务端集成 | Pending | 核对精确出货固件与固定 Portal、六位码发行/消费语义;执行 Windows Robot 真机扫描/连接、签名 macOS x64/arm64 CoreLocation/CoreWLAN/worker/ASAR/Koffi smoke,以及真实 Host/native Electron 端到端配网+Binding;保留 `NIANCODE_AI_HARDWARE_GUIDED_HOTSPOT_BINDING=0` 回滚并记录支持矩阵 |
| 2026-08-10 | 完成客户端提交到 App `play_url` 播放的真实生产整链验收 | source+built+contract 服务端协议、OSS immutable Release、CDN/Edge 与 App 消费链成组集成后 | 客户端/服务端集成 | Pending | 使用真实账号执行小游戏和小程序创建、客户端本地构建与同字节预检、双归档提交、服务端逐字节校验/不可变 Release 固化、运营批准、CDN 发布、App 播放与监控核对;如需不可绕过 runtime gate,另行设计可信 verifier |