# Current State This file is the integrated default-branch snapshot. Feature tasks record progress in `30-worklog/tasks/{task_id}.md` and propose canonical changes for the Integration Gate. Feature tasks must not rewrite this file; it changes only in integration mode. ## Integrated Through - 2026-09-18:集成任务 `20260918-merge-agent-apply-86d41b2e` 收录 MakeLore 智能体应用入口源 `b28f6f0`([源任务](tasks/20260918-agent-apply-visible-5a83c1e2.md))。 已发布助手在工作区顶部直接应用已保存修改,并明确区分未保存、已保存待应用、 已应用及状态未知;使用与分享页共用原操作身份和失败重试。 保存与应用继续分离,不改后端、模型资格、计费或渠道路由。 产品树与已验证源一致,沿用 52 项相关单测、类型检查、scoped lint、Vite 构建和 Electron 大小窗口操作证据。主分支落地状态见集成记录;未推送、打包或部署。 - 2026-09-16:任务 `20260916-merge-design-video-client-4f6d28a1` 将 Design 视频准备源 `1acca836fe035dd462110cdc7683645c1e031f54`(源任务 `20260916-design-media-client-a7d3e9c1`)从 `b723c722` 无冲突快进合入本地 `main`。 视频开始画面有明确绑定入口;真实分媒体能力驱动参数,prepare 成功后才按最新 revision 请求 Quote,明确失败阻断报价,用户确认仍是唯一生成授权。历史视频支持原生 controls、 放大预览和下载,历史图片可明确用作视频开始画面。主目录 76 项相关单测、2 项跨仓流程、 类型检查和 Vite Renderer/Main/Preload/utility 构建通过;产品文件与源一致,源记录原样导入, 三份原有未跟踪任务文档保持不变。未推送、打包或部署;跨仓测试使用模型/报价等夹具, 真实短视频生成和播放字节仍待成对发布后单独验收。 - 2026-09-15:任务 `20260915-merge-image-preview-56ab481e` 将图片预览源 `41664b2ae3b1139f7f00401e2aeb5b483319d29e` 无冲突合入本地 `main`,合并提交 `9b64dd9b3917999fd1f10683ee78ac1746de6f81`。AI 设计任务图片新增放大查看,支持完整适配窗口、原始尺寸滚动、关闭/Esc 和焦点返回,桌面与紧凑布局共用且不触发下载;Main-owned Asset 契约保持。合并后的类型检查、31 项相关单测、Vite 全目标构建和 Windows Electron 交互验收通过;产品及源任务记录与已验证源一致,三份原有未跟踪文档原样保留。用户授权的旧 Agent-tabs 残留目录已改名 `.retained` 保留,并用 bundled scripts 恢复登记。未推送、打包或安装;详见[集成记录](tasks/20260915-merge-image-preview-56ab481e.md)。 - 2026-09-15:任务 `20260915-merge-agent-tabs-2fd41184` 经用户确认登记移交,将源 `868ab54be6575ea6bd170d2ece7b7c8d4f6c0007` 无冲突快进合入本地 `main`。智能体编辑区改为“我的要求”与“高级设置”双 Tab,选中态与方向键切换明确,高级分类记忆、切换回顶、未保存输入及试用状态保留。产品树与已验证源一致,沿用 47 项相关单测、类型检查、scoped lint、Vite 全目标构建及 Electron 交互验收,详见[源任务](tasks/20260915-agent-editor-tabs-8c46f6f5.md)。源记录原样导入,三份原有未跟踪文档保留;未推送、打包或安装客户端。 - 2026-09-15:任务 `20260915-merge-knowledge-status-ml-7a69bec0` 经用户确认登记移交,将已独立审查源 `fee2f4c` 无冲突快进合入本地 `main`。知识文档上传、导入与替换自动衔接解析索引,明确阶段、真实可用性和失败恢复;每 5 秒串行刷新已加载页面,旧可用内容在替换清理重试时保留。沿用源 49 项相关单测、类型检查、scoped lint、Vite 全目标构建、真实 Electron E2E 1 passed,以及独立 Reviewer Standards/Spec PASS。全量唯一 Pi runtime v6/v7 旧断言失败与本改动无关,详见[源任务](tasks/20260915-knowledge-status-ml-3065956f.md)。产品树与已审查源一致;原有三份文档保留,未推送、打包或部署。需配套更新 Yuxi API/worker 与客户端后验收实际上传。 - 2026-09-15:任务 `20260915-merge-windows-titlebar-bde0505c` 经用户授权移交主目录登记,将修复源 `dae64e52b94f54c61b14d744ef6e6d0580af2d3a` 无冲突快进合入本地 `main`。Windows Code 对话标题栏按共用的 148 px 窗口按钮与 96 px Logo 尺寸限制可交互区域,浏览器、中止和恢复按钮保持在 Logo 左侧。产品树与已验证源一致,沿用 42 项相关单测、类型检查、scoped lint、Vite 全目标构建及 Electron 标题栏/Code 交互验证;覆盖最小 1024 px 窗口、125% 缩放和窗口最大化/还原。详见[源任务](tasks/20260915-windows-logo-overlap-5106511f.md)。原有三份未跟踪文档保持,源记录原样导入;未推送、打包或安装客户端。 - 2026-09-15:任务 `20260915-merge-platform-embedding-ml-4e78b319` 经用户授权移交主目录登记,将独立审查通过的 `c466039adb789368189e43971afe489d450d5c82` 无冲突快进合入本地 `main`。知识库 embedding 统一由 Yuxi 配置并直连供应商,平台承担费用,不计算用户用量、词元点数或金额预算;聊天计费保持。客户端知识模型列表沿用 id/name/dimension 契约,配置说明只指向 Yuxi,知识及预算页面明确平台承担向量化成本。 本次新规则取代早期知识库目录交集、one-api 向量接口和创建者付款说明,历史记录保留。源聚焦单测 22 passed、Electron E2E 1 passed、typecheck、scoped lint 与 Vite build 通过;最终文字调整后聚焦 22 单测再次通过,独立 Reviewer Standards/Spec PASS;详见[源任务](tasks/20260914-yuxi-embedding-ml-a174ed62.md)。原有三份文档保持,无新 SQL 或专用环境变量,未推送或部署;真实供应商及完整知识库拓扑验收另行执行。 - 2026-09-14:任务 `20260914-agent-ui-integration-4a838e7c` 将引导式智能体 UI 源 `6e6a8c92ddb66747a71af714809e2205292a0bf9` 无冲突合入本地 `main`,合并提交 `5a974cf78493b8dd92e176cc26fbe323a18e9570`。面向非专业用户与 8–15 岁学生的创建引导、基础要求、高级设置折叠、保存后重新试用、历史对比及首次自用确认已集成,见[已接受决策](../10-decisions/ADR-2026-09-11-personal-cloud-agents.md)。保留主分支连接时差修复,产品代码与已验证源一致;集成时补充两条异步状态测试等待。组合验证累计 89 项相关单测、类型检查、Vite 全目标构建、Electron 引导用例通过;全量测试沿用源记录中已确认的 Pi v6/v7 既有失败限制。原有三份未跟踪记录原样保留;已授权的源工作区清理因 Git 目录非空错误受阻,残余保留,分支和提交完整。未推送、打包或部署。详见[集成记录](tasks/20260914-agent-ui-integration-4a838e7c.md)。 - 2026-09-14:任务 `20260914-merge-cloud-reconnect-8fe72c41` 经用户授权移交主目录登记,将源 `8a67e8bd47d814b533476a6e36421f7a5d983a27` 无冲突快进合入本地 `main`。云智能体 Main 凭证处理不再因签发端轻微快于客户端而拒绝正常的五分钟凭证,改为限制本地复用时长;服务端过期校验及既有刷新余量不变。产品树与已验证源一致,沿用 33 项相关测试、类型检查、scoped ESLint 和 Vite 全目标构建。该缺陷已复现,尚不能据此认定线上所有不可用提示均由此引起;详见[源任务](tasks/20260914-cloud-reconnect-5ad71e6c.md)。原有三份未跟踪文档保留;需要重新打包安装客户端才生效,未推送、打包、安装或部署。 - 2026-09-14:任务 `20260914-merge-ppt-makelore-2e8ec5dc` 经用户授权移交主目录登记,将已独立审查的 `4f2caf7` 从 `9044f7d` 无冲突快进合入本地 `main`。新建云智能体默认 300 步,保留显式 40/自定义设置;微信会话优先展示原生 Run 状态及失败原因,再显示部分正文,涵盖关闭历史会话与仅排队状态。产品树与已验证源一致,沿用 42 项回归、类型检查、lint、Vite 构建及 Electron 验收,详见[源任务](tasks/20260914-makelore-ppt-failure-7c4a.md)。原有三份未跟踪文档保留;未推送、打包、安装或部署。需配套更新 Yuxi API/worker,已有智能体调整限制后重新发布。 - 2026-09-14:任务 `20260914-merge-agents-entry-aecd607d` 经用户确认主目录登记移交,将源 `9317d0acc7cfa6eab2379ab37acefbac8e435fad` 无冲突快进合入本地 `main`。Agents 入口换为蓝紫色全息智能体插画,标语为“打造你想象中的AI助手”,顺序为 Agents、Code、Canvas、Robot;源记录原样导入,产品树与已验证源一致,沿用其类型检查、相关单测、构建和 Electron 双窗口验证。原有 3 份未跟踪文档保持原样;未推送、打包、安装或部署。详见[源任务](tasks/20260914-agents-entry-art-0242f8f3.md)。 - 2026-09-14:任务 `20260914-land-scan-account-ml-8fb88137` 经用户确认登记移交,将已独立审查源 `21e707d` 无冲突快进合入本地 `main`。微信渠道统一按扫码账号使用,删除使用范围、邀请与调用者管理;历史受邀内容不改归属、不继续入站/恢复/投递。源记录原样导入,产品树与已验证源保持一致,证据及限制见[源任务](tasks/20260914-wechat-scan-owner-ml-b4169ea9.md)。本次无新 SQL/环境变量;未推送、部署或清理工作区。 - 2026-09-14:任务 `20260914-merge-user-channels-ml-e672b0c4` 经用户授权移交主目录,将已审查源 `b7d8b1298f02e4b10b6d0089594d48720efc03e7` 无冲突快进合入本地 `main`。用户级多微信账号、先扫码后选择目标、多个账号路由同一智能体及切换保留登录已集成;智能体发布页使用渠道摘要/入口。产品树与已审查源一致,源记录只读导入,验证和实际部署边界见[源任务](tasks/20260913-user-channels-ml-8d61e4a9.md)。原有 3 份未跟踪文档保留;未推送、部署或清理工作区。 - 2026-09-13:任务 `20260913-merge-wechat-self-ml-a904d7c1` 将已审查源 `8c1b161d0e14394beb62ae7f7e05c96cfed045b2` 无冲突快进合入本地 `main`。个人微信发布页移除本人配对入口,扫码本人直接使用;首条消息建立本人历史和通知目标,其他联系人仍通过独立邀请接入。源任务记录原样导入,独立 Reviewer 最终 PASS,验证与线上限制见[源任务](tasks/20260913-wechat-auto-self-ml-3679bce2.md)。原有 3 份未跟踪文档保持不变;未推送、部署或清理工作区。 - 2026-09-13:任务 `20260913-merge-agentbus-channels-ml-c4e81f2a` 经用户授权移交主目录后,将渠道源 `2e710db0fb512f276fda8ae8a3939d366b34a972` 从 `03774d0625a5a0d0221dbb9989e88a9406e0fa48` 无冲突快进合入本地 `main`。产品代码与已审查、测试的源完全一致,源任务记录原样导入;个人微信、共享 SSO 与按用户隔离规则见 [渠道决策](../10-decisions/ADR-2026-09-11-personal-cloud-agents.md)。原有 3 份文档改动原样保留;未推送或部署。授权清理的源工作区因 Git 目录非空错误部分移除,残余保留,分支和提交完整。 - 2026-09-13:续接任务 `20260912-land-model-capabilities-c6fa4309`,将图片附件修复源 `03fc50f7a9009b8e5c43fada8bc3365103dc732c` 从 `1d661f7` 无冲突快进合入本地 main。发送时、Pi 实时消息与历史恢复均保留图片引用,重复投影复用附件文件。产品树与已验证源完全相同,复用其相关回归、真实 Pi 新会话/恢复会话 HTTP、Electron 图片刷新、类型检查与构建证据。三个原有未跟踪记录保持原样;工作区清理等待单独确认,未推送、打包或安装。详见[图片流转](../20-architecture/data-flow.md#code-image-attachment-projection)。 - 2026-09-12:任务 `20260912-land-model-capabilities-c6fa4309` 经用户授权交接主目录及集成锁,将模型能力源 `26cbb29` 合入本地 main,合并为 `2888aaed`;保留已有知识库和云智能体界面。受管模型采用 Works v2 官方能力,Main 持久化并验证原生 reasoningChoice、冻结供应商控制字段,图片附件与 Pi input 一致。合并后 57 项相关测试、类型检查、Vite 全目标构建、Electron 受管模型用例 1 项通过;源任务验证保持有效。3 份原有未跟踪记录原样保留,未推送、打包、部署或清理工作区。见[官方模型能力决策](../10-decisions/ADR-2026-09-12-official-model-capabilities.md)。 - 2026-09-12:任务 `20260912-merge-kb-embedding-49e2b6c` 在用户确认主目录占用移交后,将本地 main 从 `a0b869a` 无冲突快进到知识库修复源 `3507f70e114be94913c72aa9e70eb6f9455cd86d`。创建知识库明确区分模型目录加载/失败/空状态,提供管理员配置说明及原地刷新;刷新保留名称,未知创建继续复用原请求身份。模型由平台管理员在 Yuxi 定义并启用(含维度)、在 Works Square 激活相同模型 ID,one-api 提供实际向量接口。客户端继续消费 Main Host API。源 50 项相关测试、类型检查、scoped ESLint、Vite 构建和 Windows Electron fixture 1 项通过;快进合并未改写产品代码,复用源验证。原有 3 个未跟踪文档保留;未推送、打包或部署,线上具体配置缺口及真实收费调用未验证。 - 2026-09-12:任务 `20260912-merge-agent-draft-d960aa87` 经用户明确同意释放旧任务占用并保留 3 份原有未跟踪记录,将本地 main 从 `70fa916` 无冲突快进到 `dca6deab292028c9f3cfd097a8c52ba0d43b35a9`。Agents 采用账号级全高桌面分栏,指令/能力/知识/限制分类,保存与试用修订分离、独立费用保存及后台会话未读保护;详情见[个人云智能体决策](../10-decisions/ADR-2026-09-11-personal-cloud-agents.md)。源最终 65 项相关测试、类型检查、scoped ESLint、Vite 构建和 Windows Electron 大小窗口/内容缩放验收通过;合并未改写产品代码,复用这些验证证据。尚未推送、制作安装包或更新已安装客户端。 - 2026-09-12:任务 `20260912-merge-chat-send-6ca06743` 在用户确认主目录接管后,将本地 `main` 从 `2cedc9df` 快进到修复源 `954b275f10fd447dd9ebd7a2d25f1229c366bd17`。Code 的排队/引导选项在任务结束后不再阻止普通发送,成功接收的排队请求及时清理本地接收记录,实际队列仍由 Main Snapshot/Patch 投影。源验证通过 57 项相关单测、类型检查、scoped ESLint、Vite 生产构建和 1 项 Electron 交互用例;合并后产品树与已验证提交一致,原有 3 份未提交记录保留。尚未推送、打包或更新已安装的 1.4.3 客户端。 - 2026-09-11:任务 `20260911-land-cloud-agents-fd05bb3d` 在用户确认目录接管后,将本地 `main` 从 `927a85fa` 快进到已验证集成 `5d8e91c7`,完整包含云智能体源 `303f262`。原有 3 份未提交记录原样保留;源码与审查版本一致。主分支落地已完成,未推送、部署或清理工作区。 - 2026-09-11:个人云智能体源 `303f262`(任务 `20260910-personal-agent-platform-d15b2559`,含前置提交)由 `20260911-integrate-cloud-agents-ef7bd545` 无冲突集成,实际主分支落地见本集成任务。源代码保留已审查内容;个人创作者、创建者付款、调用者内容隔离、配置/发布/分享/API/日程、恢复、资源维护和费用上限均已实现。源批次测试通过,真实模型、完整部署及安装包验收仍待执行;已确认费用规则取代旧“每日预算未定”。见 [个人云智能体决策](../10-decisions/ADR-2026-09-11-personal-cloud-agents.md)。 - Expiring reset-card wallet source commit `01525834fd326a0fbcd6f537b11d6f278470f992` from task `20260908-reset-card-wallet-client-6c3e8a1f` is integrated onto local `main` by task `20260908-integrate-reset-card-wallet-9c4e2a71`. The account menu now owns a lazy-loaded reset-card wallet backed by Main-owned list/redeem routes and the Works Square billing authority. It shows available, elapsed, and redeemed Operations grants with explicit local-time expiry, blocks known-expired and family-shared redemption attempts, and refreshes both the card list and authoritative Token Point V2 balance only after server-confirmed fulfillment. Paid reset-card checkout remains an immediate server-side reset and does not enter this inventory. Source verification passed 78 focused tests, typecheck, scoped and full lint, all Vite production targets, and 3/3 Electron E2E runs. The full unit run's only failure was the previously recorded Pi real-process two-second cold timing assertion, which passed 6/6 in isolation; no Pi code was changed. A compatible Works Square deployment with migration `20260908_reset_card_grants_0087` and a rebuilt client remain release gates; no package, deployment, production mutation, remote push, or publication is claimed. - AI Design confirmation-handoff client source commit `1a52831b26a226ee675c815e8975b4258a10fa18` from task `20260908-design-confirmation-handoff-client-8c3f1a72` is integrated as product commit `3c4e866c2d3847d870f2502f8232ab19e35f1e8e` by task `20260908-design-confirmation-integration-client-8d4b6f20`. The active creation card now remains visible for meaningful canonical content even when the compact concept field is empty. A missing aspect ratio is visibly unselected and must be written through typed Design operations before Quote preparation. An offered Quote retains the explicit confirmation control, which submits only the server-issued Quote ID; chat text and the preparation action still cannot synthesize a Task. Verification passed 64 focused tests, TypeScript, scoped ESLint, all Vite production targets, and exact-range diff checks. No Electron contract, DTO, persistence, package, deployment, or production activation changed. - AI Design chat-to-Quote client regression source commit `6b1e3937d709b74d407379c210a4bf09e8f4b158` from task `20260907-design-chat-generation-handoff-client-7d3a9c41` is integrated as merge `7defe46de2d4c693a620ca0be10201a18ccd910e` by task `20260908-integrate-design-chat-generation-client-7d3a9c42`. The existing Store contract now has regression coverage for one accepted chat operation receiving its committed chat Direction projection immediately followed by the offered immutable Quote projection. The optimistic user message and activity settle once, while the Quote remains visible without a second Renderer mutation. No client product code, DTO, route, automatic confirmation, Task authorization, package, or deployment changed; generation still begins only after explicit Quote-ID confirmation. - Native text context-menu source frontier `6fbb9c077ecda23e2ee6472631fe374527c49cb7` from task `20260907-input-context-menu-a7c31e` is fast-forwarded onto local `main` by task `20260907-integrate-context-menu-5a9e3c71`. The primary Renderer window now receives one Electron Main-owned native menu for editable controls or an existing text selection, exposing Chinese Cut, Copy, Paste, and Select All roles according to Chromium edit capabilities. The same window-level listener covers both Code and AI Design textareas without Renderer clipboard IPC or a duplicate Canvas listener; ordinary non-editable content remains unaffected. Verification passed the 5 focused unit cases, typecheck, full lint with 0 errors and 5 existing warnings, all Vite targets, and an Electron E2E that observed one popup for each Composer. The full unit run passed 1,938 tests with 2 skips; its only failure was the unchanged Pi real-process two-second timing assertion, which passed all 6 tests in isolation. No push, package, deployment, publication, Provider call, or user-data mutation was performed. - Local AI Design activity frontier `4b894c7e320cdf829888f63f501d176f051be7d7` and fetched remote frontier `918f8f80dca61b0f561f96b168e4ef541734d414` are reconciled by the ordinary two-parent merge prepared under task `20260907-complete-current-merge-b61e4a93`. The semantic resolution keeps the remote Code/Canvas/Plugin/Learning-removal product state while adding the local Main-normalized, operation-scoped Design activity panel to the matching pending or canonical user turn. Activity and assistant delta remain transient projections; the central active production plan remains the Current Specification projection. Typecheck, 90 focused tests, lint with 0 errors and 5 existing warnings, all Vite targets, targeted Electron E2E 12/12, pressure 1/1, and staged-diff checks passed. The ordinary unit suite passed 1,933 tests with 2 skips; its sole failure was the unchanged Pi real-process two-second timing assertion, which also missed its limit in isolation on this Windows host. No push, package, deployment, publication, production database, paid Provider, or historical user-data change is claimed. - AI Design operation activity source `81b524a02c2cf51304090afa8fb89d27c72c5d2b` from task `20260907-design-agent-activity-client-b6d913e4` is integrated by task `20260907-land-design-agent-activity-e3b7a1c9`. Electron Main now normalizes the server's four closed public stages into fixed youth-safe copy; Renderer attaches one transient, update-in-place `AI 处理过程` panel to the exact optimistic user message and collapses completed work without creating a chat Turn or duplicating the right-side Current Specification. Workspace, Direction, operation, pre-command turn sequence, connection generation, cursor, and terminal events keep replay and stale results scoped; unknown outcomes retain the original identity. Integration review additionally preserves prior completed/unknown activity when a later chat starts and keeps each pending user's activity and provisional reply together in visual order. Final committed assistant text continues through the existing provisional assistant bubble and canonical Turn replacement. Focused verification passed 69 tests, TypeScript, changed-file ESLint, and all Vite production targets. No server, database, billing, Quote/Task, navigation, package, deployment, publication, or paid Provider call changed. - Token Point V2 account-usage source `6348e402a4e8dde712e5cba4620bb883ffe24e0b` from task `20260906-trace-makelore-usage-3d7a5c1e` is integrated onto local `main` by task `20260906-integrate-token-points-v2-7b4e1c92`. The account menu now uses the Main-owned `/api/works/billing/points` route and the Works Square `/api/billing/points` authority instead of the retired rolling-window usage contract. Managing accounts see the authoritative plan, weekly remaining/allowance, total remaining points, and refresh time; loading and retrieval failures remain explicit. Every non-managing account receives only coarse `shared_available` state, including both family-shared members and youth self entitlements, and never receives plan, cycle, or exact balance fields through the Main projection. Source verification passed 72 focused tests, typecheck, scoped lint, all Vite targets, diff/source checks, and two matching Works Square V2 contract tests. The deployed service/database state and signed-in packaged-client smoke remain release evidence gaps; no server deployment, database migration, package, publication, or remote push is claimed. - Automatic Game Resource delivery source `6113a2453299141eab8420a56e93675712dd607b` from task `20260906-game-resource-auto-delivery-7a4e2c91` is integrated onto local `main` as product commit `4df4bc96245c01cd95e35ddf1b2b03d0e0d231c5` by task `20260906-game-resource-auto-delivery-integration-8c4e1a72`. One confirmed `game_resource_generate` call is now a Main-owned submit-and-deliver operation: Main submits once, polls the accepted execution internally, downloads every terminal output, and saves the files under the frozen original project at `assets/generated/game-resource//`. Provider execution, billing, and local delivery remain separate states. A durable user-data receipt resumes only the local download/save phase after an interruption, so it cannot create a second Provider submission or Token Point charge. The shared project write lease is held only while terminal outputs are materialized, and the Agent-visible status/save tools and second save confirmation are removed. Source verification passed 99 focused tests, the 1,901-test full unit suite with 2 skips plus pressure, typecheck, lint with 0 errors/5 unchanged warnings, all Vite targets, 8 Electron tests, the unified Plugin E2E journey, and Windows x64 runtime staging. No live paid Provider generation, client installation, deployment, publication, or push is claimed. - Official project-wide Plugin activation source `718783f6837e29f56c9add633596249c03e5701f` from task `20260905-official-plugin-project-scope-6e4a9c21` is integrated onto local `main` as `e0de7aa28c1d6e97454f0e4073ae9153e746bb4b` by task `20260905-official-plugin-project-scope-integration-8b3d6f42`. The shared activation predicate now treats `makelore.data-service`, `makelore.game-resource`, and `makelore.project-scaffold` as code-owned official project Plugins: after their existing system delivery or Account acquisition and project enablement, every parent Agent receives the full Skill/tool set without an Agent-assignment gate or partner-assignment action. Child Agents remain empty; downloaded Marketplace and local Device Packages retain their existing lifecycles, and stored assignments for the three official identities may remain inert. Source verification passed 30 focused, 70 adjacent, and 37 resolver/composition tests, typecheck, lint with 0 errors/5 unchanged warnings, all Vite targets, and the targeted Electron project-Plugin journey. The ordinary full unit run had one unrelated two-second Pi real-process timing miss among 1,889 passes/2 skips; that exact file passed 6/6 in isolation. A rebuilt and installed client smoke is still required; this source integration does not change an already running binary. - Project Scaffold project-wide activation source `300ac89a81409440aac84ff45b1d9ca2fa186629` from task `20260905-project-plugin-scope-7c4e9a21` is integrated onto local `main` as `6710527e8f7150a6c4997d566a380454e33f455e`. The code-owned `makelore.project-scaffold` remains Account-acquired and project-enabled, but no longer has an Agent-assignment gate or partner-assignment action. Main now materializes its complete Skill set for every parent Agent in the enabled project; child Agents remain empty, active generations keep their existing freeze boundary. This was the initial narrow exception and is superseded by the three-identity official rule above; Plugins outside that set retain their assignment semantics. Source verification passed 45 focused and 87 adjacent tests, typecheck, lint with 0 errors/5 unchanged warnings, pressure, and all Vite targets. One unrelated two-second Pi real-process timing assertion failed in the ordinary full run and passed 6/6 in isolation. A rebuilt/installed-client smoke remains pending; local source integration does not replace an already installed binary. - Remote `main` frontier `da29294` is semantically integrated with local frontier `f53683a` under task `20260907-integrate-remote-before-push-a4c9e27b`. The merge retains the local directory-only project creation, Main-owned UUID, direct `/chat` entry, non-blocking no-Agent state, Project Configuration-owned Plugin sheet, and retired Learning surface. It also incorporates the compatible remote official project-wide Plugin activation, automatic Game Resource delivery, Agent Browser restoration, and Token Points V2 projection. The remote initialized/full-Agent Conversation gate is intentionally not adopted: `initialized` remains schema compatibility only, while truly invalid project metadata still routes to Project Configuration. Verification passed typecheck, 1,912 full-suite tests with 3 skips plus pressure 1/1, lint with 0 errors and 5 existing warnings, production Vite build, and targeted Electron 6/6. No live paid Provider generation, installed-client smoke, deployment, publication, or production database change is claimed. - September 6 completed product sources are integrated onto local `main` by task `20260907-merge-all-changes-8f3c2a`: project-gate removal `af13aca` via `39d7b7e`, Code landing `ce90f57` via `a91c7e3`, Plugin rehoming `be1764e` via `f6c5961`, Canvas right-Works/reference-plan redesign `1562a49` via `ea1219c`, and Canvas inspiration removal `b22559a` via `e069ec6`. The semantic merge keeps directory-only project creation with Main-owned UUID, direct `/chat` entry and a no-Agent state; moves the sole Plugin workspace to the Project Configuration same-page sheet; keeps the active Canvas plan in the central timeline with editable Prompt/reference aliases and a full-height right Works rail; and retires the Prompt Museum Renderer entry while retaining its dormant Main security contracts. Superseded Learning branches and unconfirmed audit concepts were classified but not merged. Verification passed frozen-lockfile install, typecheck, 184 focused tests, 1,882 full-suite tests with 3 skips plus pressure 1/1, production build, and targeted Electron 12/12. Lint reported 0 errors and 5 existing warnings. No push, package, deployment, publication, server, database, or historical user-data change was made. - Remote `main` frontier `d642d7607c26dee01ef65b4e70dd756465dea16a` is integrated with local frontier `53f3db3aced61533944eab5e6b3c8c2293f733f8` by the ordinary two-parent merge `a2cb07fedcf22bb14141a27cee2218c149b8c63e` under task `20260905-integrate-remote-main-b83d6f`. The remote ADR-008 interactive AI application type, bundled `makelore.project-scaffold` Skill, and bundled-delivery status correction are retained alongside the local Learning removal: the product still exposes only Code, Canvas, and Robot. Three canonical-document conflicts were reconciled semantically, the application tree merged without content conflicts, and README now describes minimal project creation plus explicit scaffold execution. Verification passed 228 focused Vitest tests, the 12-test scaffold suite with the canonical macOS temporary path, typecheck, 1,859 full-suite tests with 3 conditional skips plus pressure 1/1, production build, and targeted Electron 1/1. Lint reported 0 errors and 12 existing warnings. The default macOS `/var` temporary-path alias still makes two copied-script scaffold tests exit before emitting JSON; the same tests pass through the canonical `/private/var` path and remain a harness/path portability follow-up. The two remote task records stay intact in remote parent `d642d76` rather than being copied into this integration result. No push, package, deployment, publication, or production database change was made. - Remote `main` frontier `336e0bb0caf24537b7b0f350aba3e04a37f5544c` is integrated with local frontier `2d3c103bac83fccffb15b760a6e79912c352541a` by the ordinary two-parent merge `2d0322ef7a98c99fb28de4902506ea135ccd9389` under task `20260904-merge-remote-main-91c4e7`. The remote AI Design streamed-reply, pending-chat, and Quote handoff changes are retained, while the local Learning removal remains authoritative: the active product still exposes only Code, Canvas, and Robot. A matching `design.assistant.delta` may appear only as one provisional assistant bubble for its pending chat and is replaced by the canonical turn; the removed generic organizing-progress banner stays absent. Remote source task records remain in their source-parent history rather than being copied into this integration result. Verification passed frozen-lockfile install, 35 focused tests, typecheck, 1,845 full-suite tests with 3 conditional skips plus the pressure test 1/1, production build, and targeted Electron 5/5. Lint reported 0 errors and 12 existing warnings. No remote push, deployment, publication, or packaged-app lifecycle change was made. - Learning-removal source `5a7cb9b2085848631bdf7de45fe1cac74b905ed9` from task `20260903-remove-learning-7a91` is integrated onto the latest local `main` as `bd0873f34823754760368d8d37703c74bf65106d` by task `20260904-integrate-remove-learning-6e4a9c21`, preserving the later AI Design and unified Plugin workspace changes. Makelore now exposes only Code, Canvas, and Robot; the Learning route tree, Renderer, Main Host API, download service, shared DTOs, artwork, tests, server contract, and packaging surface are removed. Stale Learning URLs return to the module chooser and retired Host API paths use the standard not-found boundary. Historical course data remains untouched and unread, while `makelore-learning:v1` stays byte-for-byte frozen only as a shared account-partition compatibility salt. ADR-005 and the Learning deployment commitment are superseded by the user's explicit 2026-09-04 product decision. Integration verification passed dependency lock install, 8 focused files / 109 tests, typecheck, full unit 1,844 with 3 skips plus pressure 1/1, production build, targeted Electron 8/8, and full Electron 33/33 with 1 platform skip. Lint reported 0 errors and only existing warnings in current source and a historical worktree. - Unified Plugin workspace bundled-delivery fix source `6bd9287c879dca93da11e17533f84e3535fc656a` from task `20260905-plugin-download-action-6c8e4a21` is integrated onto local `main` as `6d102b2`. Code-owned bundled official Plugins, including `makelore.project-scaffold`, now show `随应用提供` when no device-package record exists instead of falsely showing `未下载官方包`. This is presentation-only: bundled Plugins still have no device download/update/uninstall flow, and the existing server-authoritative `免费获取` action remains required before project enablement. Focused Plugin tests, typecheck, scoped lint, and all Vite targets passed; the ordinary full unit run had one unrelated Pi real-process two-second timing miss among 1,887 passing tests and 2 skips, and that exact test passed 6/6 in isolation with the pressure suite passing 1/1. The production Marketplace currently returns `404 plugin_not_found` for Project Scaffold and still requires deployment of the current server plus migration through `20260904_project_scaffold_0085`; no deployment or production database change is claimed here. - Interactive AI application source `959b633` and official Marketplace packaging source `ddb678b46ff10a28e04beeafcfc00c8c8a23ff9f` are integrated through merges `4bc3e0ea5331a7d3f3576768c0119c02c0f0f952` and `2bc3e4420852388ce46841e05c1cbf49e80b250c`, then canonically reconciled by tasks `20260904-reconcile-project-scaffold-f7b4d2a9` and `20260904-project-scaffold-integration-client-4f2a8c71`; verified integration head `b92e7ba5bbde186626d93787ca358fbf4c2523a3` was landed on local `main` by task `20260904-project-scaffold-main-merge-e7b4c291`. New projects use one `interactive_ai_app` / “交互式 AI 应用” type or `custom`; historical `mini_game` and `mini_program` values normalize at the read boundary without a batch rewrite. Project creation owns only `.makelore/project.json` and `knowledge/`. The official code-owned bundled Marketplace Plugin `makelore.project-scaffold` version `1.0.0` provides the explicit `makelore-project-scaffold` Skill, a non-overwriting fixed six-file Vite starter, and read-only publication-readiness guidance; it does not install, build, upload, submit, or approve. Its `.mjs` uses the non-overridable application Node exposed as `MAKELORE_NODE_EXECUTABLE` and is executable only because it ships in the fixed signed-client resource root. Downloadable Marketplace artifacts remain text/image-only and reject `.mjs`; acquisition, project enablement, and immutable bundled Release/Admission remain distinct. Project Scaffold is project-wide after enablement and has no Agent-assignment state; the same activation scope now also covers Data Service and Game Resource, while Plugins outside the code-owned set retain their own assignment rules. Main and Works Square retain build, preflight, artifact, upload, immutable Release, and review authority. Exact integration verification passed the 12-test scaffold suite, 123 focused Vitest tests, typecheck, scoped ESLint, and the Renderer/Main/Preload/utility Vite build. Source evidence additionally includes the project-configuration Electron flow, real scaffold-to-locked-Vite build, plugin/Skill validation and bundled resource loading. A packaged-app smoke plus installed Windows, signed macOS, and native Linux proof remain pending; no live Marketplace migration, production upload, approval, deployment, or remote push is claimed. - AI Design streamed-reply diagnosis `229b1b1ce39b7f1541a93ea3c980ab82b6d6266c` and client fix `23f96a523eb37d8397bb3766ce95a59d56e59225` from tasks `20260904-diagnose-design-stream-6a4e9c21` and `20260904-fix-design-stream-4f7b91c2` are integrated onto local `main` and canonically reconciled by task `20260904-integrate-design-stream-5e7c2a91`. The existing post-validation `design.assistant.delta` transport is visible again as exactly one provisional assistant-shaped bubble tied to its pending chat identity; canonical `workspace.turns` still owns history and replaces the unfinished bubble, while unknown outcomes keep the same identity and partial reply. The removed generic “AI 正在整理你的想法” banner is not restored. A ready conversation now offers an inline Quote step; successful Quote requests reveal the confirmation on desktop or open it on mobile, but only explicit immutable Quote-ID confirmation creates a paid Task. Unknown Quote requests disable both entry points and retry the original operation. Focused tests passed 35/35, the Electron Quote-confirm-Task flow passed 1/1, typecheck, scoped lint, Vite build, document gates, and independent review passed. The ordinary full suite had one unrelated Pi real-process 2-second timing miss among 1,873 passing tests and 2 skips; that exact test passed immediately in isolation, and the pressure test passed 1/1. Provider-native first-token streaming remains a separate server follow-up; no server, database, billing, Plugin, packaging, deployment, publication, or remote push changed. - AI Design conversation-feedback sources `403236115bf81e7617856cd8219b1be23f6abbb8` from task `20260904-design-summary-separation-9c4e7a21` and `3bda17aa3c1d034ddb3feaa08e516398e91cba0a` from task `20260904-remove-design-progress-4e8a1c73` are integrated onto local `main` and canonically reconciled by task `20260904-finalize-design-feedback-7c4e2a91`. A submitted chat appears immediately as a provisional user bubble from its existing pending operation, shows `发送中` or `正在确认`, restores the retained draft after definitive failure, and is replaced by the canonical Workspace turn without a second message store. Raw `design.assistant.delta` text remains internal transport state: it is neither a finished reply nor a visible progress banner. The right-side “AI 听懂的想法” remains the single organized-understanding projection, while connection generation fencing and `chunkIndex` deduplication still converge repeated streams. Current Specification, immutable Quote confirmation, server/Main contracts, plugins, packaging, deployment, publication, and paid Provider behavior are unchanged. Source verification passed focused/adjacent tests, typecheck, scoped lint, production build, and both existing AI Design Electron checks individually; the banner-removal follow-up passed its focused 10-test file, typecheck, and scoped lint. - Conversation-first AI Design client source `fe50e4ba198649a07c5c9443f15edf7dfa2a47e6` from task `20260903-design-guided-conversation-client-8b4e1c72` is integrated onto local `main` by task `20260904-integrate-guided-design-6a3f9c82`. ImageCanvas now makes free-form conversation the dominant creation surface: first-use guidance invites creators aged 8–16 to describe a subject, scene, or feeling in their own words, the Agent-facing examples only prefill the composer, and ordinary persisted Decision Prompts no longer appear as required option-card forms. The secondary surface is now a compact “AI 听懂的想法” projection whose constraints, references, and video details are collapsed by default; manual field editing is explicitly optional. ADR-007 remains intact: Current Specification is still the server semantic authority, Quote confirmation still submits only immutable Quote identity, and Main transport/operation certainty is unchanged. Focused/adjacent 45-test, typecheck, scoped lint, production build, pressure 1/1, and Electron E2E 2/2 passed. The ordinary full suite passed 1,866 tests with 2 conditional skips and one unrelated Pi real-process 2-second timing assertion at 2,232 ms; that exact file passed 5/5 in isolation. No server contract, paid generation, package, deployment, publication, or remote push is claimed. - AI Design command-outcome source `83f3f134a6779251aaa18f3290308cd9221b038f` from task `20260903-design-message-send-client-8d3f2a71` is integrated on `main` as `a16dfd0d6f48b99899ba84ac63bde4dcd661d067` by task `20260903-design-message-send-client-integration-6f3a8c21`. Electron Main now carries explicit outcome certainty through the local route, Host API, Renderer API, store, and chat presentation: failed/cancelled Agent Runs settle as definitive failures, while commands accepted before polling, auth, transport, or canonical-refresh uncertainty retain the same pending operation ID. Definitive failures preserve the user's draft, remove partial assistant streams, and show fixed youth-readable Chinese copy instead of claiming the message was not sent; unknown outcomes preserve the draft, identity, and partial stream without silently creating a new mutation. Focused Design tests passed 61/61, typecheck, scoped ESLint, production build, pressure 1/1, and AI Design Electron E2E 2/2 passed. The ordinary full suite passed 1,865 tests with 2 conditional skips and one unrelated Pi real-process 2-second timing assertion at 2,433 ms; that exact file passed 5/5 immediately in isolation. No server contract, database, navigation, package, deployment, publication, push, or paid Provider call changed. - Integration task `20260903-complete-remote-merge-b41e7c92` combines local parent `7a37593e4be3c39a9782975de53f56a76dd53ef0` and fetched `origin/main` parent `8e947b4f0e1ff0409e52a9d528ae3bb240ceb687` through a normal two-parent merge. The later reviewed unified `/plugins` workspace remains authoritative, while the remote runtime-root, Conversation reconciliation, history, quota, tool-batch, and settlement corrections are retained. The superseded Project Configuration Plugin Services sheet is not restored; no rebase, history rewrite, force-push, package, deployment, or publication is part of this integration. - Unified Plugin workspace product head `d7058e6383f1e9dd72c32570cf83b9f439d91033` is integrated on local `main` by task `20260903-plugin-navigation-integration-4f7c2a96` after fixed-range R4 Standards and Spec review passed with zero findings. Code now has one canonical `/plugins` route and one `插件` sidebar entry; the former Marketplace, My Plugins, and Project Plugins routes are replace-only redirects into deterministic filters. A pure Renderer projection composes official catalog/Library/device state, local Device Packages, current-project state, and retained IDs while preserving their existing owners and source-qualified identities. Local Skill/extension installation remains conversation-only, native selected-model Web Search remains outside the Plugin list, and partial source failures do not erase other sources. Focused 83-test, typecheck, full-unit, lint, Vite, and targeted 4/4 Electron evidence passed across implementation, remediation, and final acceptance. No server contract, runtime, billing, package, deployment, publication, or user-machine installation changed. - Packaged Device Package preparation source `5a2f0eb6785b59d8b455ed5cb1d9773351ff895a` from task `20260902-local-skill-install-fix-6b3e91a4` and installed-resource activation source `17664c5fffcfe695653b4146503e645f54767c4b` from task `20260903-load-installed-resources-8f3c1a72` were verified in integration candidate `bd377c9` and promoted to local `main` by task `20260903-promote-installed-resources-main-5c8e1a72`. Packaged inspection now imports package-management authority from the distributed physical Pi runtime instead of the incomplete `app.asar` dependency graph. The parent Agent Server keeps the generated Makelore bridge as its required first extension and loads every further Main-selected, installed, and enabled Device Package extension through Pi `0.84.2`'s explicit additional-extension input; all selected Skill paths remain intact and ambient discovery remains disabled. Packaged prepare passed for loose Skill, npm, and Git sources without committing a package, and a real Agent Server regression registered commands from two external extensions. Focused/full unit and pressure tests, typecheck, scoped lint, production build, Windows packaging, and artifact/runtime verification passed across the two source tasks. The currently installed 1.2.6 client was not replaced; rebuilt exact-main installation and live prepare/confirm/activation remain release acceptance work. - Integration task `20260903-integrate-latest-6f2c8e1a` preserves the divergent local and remote mainline histories with normal merge `d25ed08`: fetched `origin/main` frontier `28e1690` and local frontier `301c149` are both ancestors of the integrated tree. It also reviewed every local worktree/branch; historical Learning Player source `b1f51be` remains intentionally excluded and the later complete Learning removal supersedes ADR-005, rather than that source being mistaken for current product work. No history rewrite or force-push is part of this integration. - Packaged Pi runtime-root source `5d7a235` from task `20260902-build-unsigned-mac-9d7e4a2c` is integrated through merge `4babd6d`. `resources/pi-agent-server.mjs` now anchors `@earendil-works/pi-ai` discovery to the staged `pi-runtime` package manifest, selects its import entry, and rejects entries escaping the package root. The corrected local-only unsigned arm64 DMG passed exact mounted-image initialize/shutdown with SHA-256 `6d0216da6c30f7fed537041b37c69811b8e025af3e9cccf85a64c690e29ecb7b`; it is not signed, notarized, published, or cross-platform release evidence. - Conversation-attention source `f2c3755` from task `20260902-conversation-badge-a7c49e` is integrated through merge `bbfe16d`. Hidden Conversation red markers now represent only a newly pending interaction or a newly completed/failed/aborted run; assistant/thinking/tool progress and an individual tool failure remain visible without becoming attention notifications. - Foreground-reconciliation source `7aa118b` from task `20260903-diagnose-recurring-stall-a83f5c21` is integrated through merge `04320dd`. Coding closes its old event stream on `lifecycle:sleep` and silently reloads the selected Main-owned Snapshot on view/project context, visibility, or focus transitions. A stale Renderer `live` state can therefore converge to an already persisted terminal state without replaying an accepted mutation. - Reconciliation checkpoint `cdbc262` was verified by final-gate task `20260903-finalize-main-integration-b7e2c4a9`: focused Vitest passed 5 files / 70 tests, Electron Coding E2E passed 4/4, full Vitest passed 1,832 with 3 skips plus pressure 1/1, typecheck passed, lint reported 0 errors and 5 existing warnings, and Renderer/Main/Preload/utility production build passed. A fresh fetch found the checkpoint 42 commits ahead / 0 behind `origin/main` before promotion. - Bash tool-bridge source `49112b6` from task `20260902-fix-bash-tool-bridge-9c4e7a12` is integrated through merge `55bf80e` by task `20260902-integrate-bash-tool-bridge-e81a5c6d`. Pi's prepare-all behavior can no longer deadlock two tools against Makelore's same-project write lease before either tool starts: built-in `bash`, `edit`, and `write`, plus dynamically declared product tools that acquire that lease, execute sequentially within an assistant tool batch. Read-only batches retain parallel execution, and Bash command timeout remains authoritative once its child process starts. - Coding terminal-settlement source `f1fd13a` from task `20260901-fix-session-settlement-a47d2e91` is integrated through merge `e76a1e1` by task `20260902-integrate-session-settlement-6e41c8b2`. Normal prompt completion still uses authoritative `agent_settled`; when that handshake is missing after Pi has terminalized, Main probes only the accepted target thread after a bounded 30-second grace period. Exact idle evidence hydrates the persisted final assistant response and releases ownership once; contradictory state becomes an explicit target-only protocol failure. Accepted or uncertain mutations are never replayed, and sibling Conversations remain available. - Plugin-navigation sources `b3f4166` and `e237941` from task `20260831-consolidate-plugin-navigation-3d9a6c71` are integrated through merge `a278ca3`. Coding history/quota source `d523b72` from task `20260831-fix-history-quota-errors-6c2a91e4` is integrated through merge `69832e0`, and assistant progress-preview source `8d878eb` from task `20260831-show-progress-messages-a14f9c2d` is integrated through merge `a8fd95f`. At that source frontier, Project Configuration owned the visible Plugin Services surface; Pi compaction no longer removes visible active-branch history; recognized Token Point exhaustion remains safely actionable after reopen; and collapsed process previews remain anchored to their first displayable line. Those predecessor Project Configuration Plugin surfaces are superseded by the reviewed unified `/plugins` workspace above and are not restored. Historical source `b1f51be` remains explicitly excluded; the 2026-09-04 product decision supersedes ADR-005 and removes the remaining Learning catalog surface as well. - Youth-facing AI Design client source `0fd32a2d49045a8f9e7f2e19ba6477f48f93e30c` is integrated over Model Tools frontier `7552cf59526449c29d663a769c0fb62d84a1a759` through merge `16157388afc2f6103aaee0bfd3c4e4e80c8fec48` with startup correction `c5447ae90c434c06dbafa724b229d8459cb829d0` by task `20260902-design-youth-client-integration-7a6d3c92`. Canvas now defaults to conversation plus one compact “我的创作” card for creators aged 8-16, with contextual “精细调整” instead of an always-visible professional field matrix. The card remains a pure projection of the canonical V2 Current Specification; direct choices use typed commands, Quote blockers follow Specification revision, terminal blocked Quotes settle pending operations, and code-based Chinese copy prevents raw compiler/Provider text from reaching the youth UI. Video editing preserves stable canonical Shot identities and all hidden production metadata for up to 24 Shots. No database, DTO/API, pricing, Provider route, or compatibility path changed. Integration verification passed 40 focused youth tests, 5 Device Package tests, typecheck, scoped lint, production build, and 2 Electron E2E flows. The Electron run also exposed and closed an existing current-frontier startup crash: the ESM-only Pi package manager is now loaded only when remote Device Package installation needs it. At that source-task checkpoint no package, deployment, publication, remote push, or paid request was claimed. - Model Tools and Device Packages client cutover is implemented by task `20260902-model-tools-client-integration-5d8b2f73`. Web Search is now a parent-only core tool of the frozen selected model/provider/credential; it no longer depends on Marketplace acquisition, Release, Admission, the hosted client, or Plugin Token Point receipts, and it never falls back to `agent_browser`. Electron Main also owns a conversation-only Device Package manager for npm, Git, local Plugin directories, and loose `SKILL.md` sources. Preview and a distinct confirmation turn precede immutable local commit; lifecycle scripts stay disabled; new and idle parent workers refresh automatically while active workers switch after settlement; child workers remain empty. At that frontier My Plugins separated Official Plugins from Device Installed packages and exposed no visible install picker; the unified `/plugins` workspace recorded above now presents those sources together without merging authority. The later packaged prepare and multi-extension activation corrections are recorded above; rebuilt exact-main installed-client acceptance and real selected-model search remain external gates. No paid Provider request, production install, publish, push, or PR is claimed. - Windows titlebar Logo-overlap correction source `99a210e244731d1cdc923e9dd4adf6e09e64c2a4` from task `20260901-windows-titlebar-logo-overlap-5100e298` is integrated onto local `main` through product commit `e800d42595484389432fd08b11c2202074a7009e` by task `20260902-windows-titlebar-integration-afc9e259`. The shared `ProductTitleBar` now uses one 148 px Windows caption-control region (three 44 px buttons plus 8 px padding on each side) both to size the control wrapper and to inset the Makelore Logo. Canvas and Coding Electron geometry checks confirm that the Logo ends before the minimize button; macOS keeps its zero inset and native traffic-light behavior. Focused 11-test, full 1,788-test plus pressure, typecheck, scoped/full lint, Vite build, and two Electron E2E checks passed. No package, deployment, publication, backend contract, or unrelated product layout changed. - Web Search unavailable-Release diagnostic correction source `2e093bd22c0a3c46cc08b8eede8c1bc02afd690b` from task `20260901-web-search-runtime-stale-r2-6f4a2d91` is integrated on local `main` through product commit `93e3143` by task `20260902-web-search-client-integration-a4c8e291`. When the server resolve API explicitly returns `action='unavailable'` for `plugin_release_not_ready` or `plugin_client_incompatible`, Electron Main now preserves the existing typed `plugin_release_unavailable` result instead of mislabeling it as the unrelated frozen-worker `plugin_runtime_stale` error. Exact Release, Account/project, policy, Admission, Provider, confirmation, billing, and child-isolation gates are unchanged. The current installed client still predates this diagnostic correction, and actual usability still requires Works Square to deploy/apply the missing official bundled Release and compatibility migrations; no package, restart, deployment, publication, or paid Provider request occurred. - Web Search frozen-worker stale-Library correction source `3620cdc277fa0a99757c57a549008f9ecd380558` from task `20260901-web-search-stale-resources-8b4e2c71` is integrated onto local `main` through product commit `40e1912` by task `20260901-web-search-stale-integration-9c5f3d82`. Live client evidence showed an eligible parent worker with the official Web Search Skill, tool, Release and policy failing `409 plugin_runtime_stale` because invocation re-ran full materialization and treated one transient Account Library refresh as permanent worker invalidation. New workers still require a current Library; a previously frozen worker may now use the last verified Library projection only long enough to obtain the server-owned exact Release Admission. Account/session change, project disable, acquisition removal, runtime suspension, Release/version change, policy/billing gates and child isolation remain fail closed. Focused 19, adjacent 55, full 1,786 plus pressure, typecheck and scoped lint passed. The currently running installed binary predates this source fix; no restart, package, deploy, publication or paid Provider call was performed. - Web Search Agent-assignment catalog fix source `612794463de1b14fd748202a00115c6f93c7346b` from task `20260901-web-search-tool-routing-fix-6f9d3b82` is integrated onto local `main` through product commit `adc28db7855f8b1770f1c1d46af77b7cc88cfa1a` by task `20260901-web-search-tool-routing-integration-7a4e1c93`. The unscoped partner Skill picker now lists every project-enabled Plugin Skill before first assignment and does not invoke runtime Admission resolution; Agent-scoped/runtime projections still use only the resolver-approved effective subset. This closes the confirmed circular state where an enabled Web Search Skill was hidden until already assigned, leaving the actual Pi worker with only `agent_browser`. Focused 45-test, full 1,785-test plus pressure, typecheck, and scoped-lint verification passed. Existing workers remain frozen; the affected local Agent assignment was corrected separately and takes effect on a new Conversation. - Official bundled Plugin client cutover is integrated on local `main` through product commit `1530ac774091c7083dbff19e0fbd69e929ac8718` by task `20260901-official-bundled-plugins-client-integration-b8d5f3a2`. Game Resource and Web Search now ship as exact schema-2 resource packages with MakeLore; their acquired Library entries resolve through the server Admission path without Package Store download, update, Beta, signature, or device-uninstall state. Project enablement, Agent assignment, parent-only materialization, Provider policy, confirmation, and Token Point billing remain enforced. The verified Windows installer embeds source `b1657300f29f9744551f31029eb192ee82f01b92`, is 208,297,578 bytes, and has SHA-256 `449288AF079E030F3F700F0FF1701971F7AB4806E0366CE989F4E8F2FE33ACA3`. - Conversation abort reconciliation source `d2ef37bc4d7d3609cec0a55c4ae8ffb2734696d5` from task `20260901-conversation-abort-stall-6f4c2a91` is merged into local `main` as `85900717906713d8343c2087eade904aead8f111` through verified candidate `599d1847f73a590690cbac2ee1c5bf36e8cd83f1` by task `20260901-merge-abort-main-a83d4c71`. Both visible abort actions now call the Main-owned abort route and then silently reload only the target Conversation's authoritative Snapshot. This closes the installed 1.2.1 case where Pi had already recorded bash results and a final assistant `stop`, but Renderer missed the terminal SSE patch and a later valid abort no-op left the UI showing an executing turn. Pi `0.84.2`, Host API, replay, recovery, and background-lifecycle contracts are unchanged. Focused 35-test, 1,780-test full-suite plus pressure, typecheck, lint, production-build, and Electron E2E verification passed. The existing 1.2.1 artifact predates this fix; a newly versioned package and installed-client acceptance remain pending. - Agent Server background-sleep race fix source `12d7588b3ebd4d192c2e14ae285d4f6ddebeeb42` from task `20260901-agent-received-stall-8b6d4c21` is merged into local `main` as `c2137c9f3f2e05441064cc90bfeed115363ac04e` by task `20260901-integrate-agent-stall-4f2c8a91`. Background sleep now rechecks active Coding work after asynchronous worker cleanup before stopping the shared Agent Server, and a server start racing an in-flight stop waits for that stop and creates one fresh process. This closes the confirmed lifecycle windows that can leave a locally accepted prompt optimistic with no live Agent Server or Pi session write; accepted/uncertain prompts are still never auto-replayed. Source tests and a real Electron-Node Agent Server race test pass. The currently installed binary predates this integration; a rebuilt/reinstalled Windows package and repetition of the reported interaction remain pending release evidence. - Works-provisioned model-reasoning capability source `ae7936174208a1d13cdfd260d5c6f2b70b450b60` from task `20260901-server-model-capabilities-9e31b6c4` is merged into local `main` as `6a8ebe1b671ca24150c2226b9111b9d07174e37b` by task `20260901-integrate-model-capabilities-9b3e7c1a`, paired with Works Square source `9e1b6886b360175f1ca1596fb07f71e3bf86c894`. Electron Main now strictly normalizes and persists the optional safe `model_capabilities` metadata, removes a stale override when the field is absent, and includes it in Provider runtime-shape invalidation. Server levels override the verified local reasoning map; old servers and direct Providers retain the local fallback. DeepSeek exposes `off`/`low`/`high`/`max`: Pi disables thinking without `reasoning_effort` for `off`, and sends the exact enabled effort otherwise. Native `max` reaches project persistence, Snapshot/Patch, Host API, runtime, and the composer label `最高`. Pi remains `0.84.2`; no one-api, dependency, package, deployment, or real Provider acceptance is claimed. - Marketplace weak-ETag interoperability fix source `b3cfe7e1ceb7da65ccc99214db09102b4fc1cace` from task `20260901-plugin-catalog-load-client-7d4a8c21` is promoted to local `main` by task `20260901-plugin-catalog-main-integration-8e5c2a91` through product commit `38f2358`. The Main-owned Marketplace client now accepts both strong and valid weak composite catalog ETags, preserves the exact received validator for the next `If-None-Match`, and retains catalog-generation and Token Point pricing identity checks. This closes the installed-client failure where the production gateway's compressed `W/"plugins-..."` response was incorrectly surfaced as `plugin_backend_unavailable`; it does not add a local fallback catalog or change server, Provider, trust, pricing, or billing authority. The rebuilt Windows 1.2.0 installer embeds verification head `6083de6aee8942a78191ed18a00bfd9f4ba0902d`, is 294,864,542 bytes with SHA-256 `1301AE189BCBD44AA0E373982981E80B324EC45CDDF8F30415C2810F68319C06`, and was installed over the prior 1.2.0 at the existing user-selected location. The signed-in installed client then loaded the deployed generation-2 catalog and rendered exactly Data Service, Game Resource, and Web Search without the unavailable catalog error. At that checkpoint Game Resource and Web Search still showed no stable Release; the official bundled cutover recorded above supersedes that delivery model. - Earlier packaged Pi Agent Server resolver source `7df245af5a04f62be48980831ff41987ba686009` from task `20260901-local-runtime-unavailable-8b42c7f1` is promoted to local `main` by task `20260901-promote-local-runtime-main-a7c4e291` through verified integration candidate `42ea83c0cbad52432eca99e4161e0360bef3e219` and source merge `96402551f46d875ba3db0a2f625397aba2f332fb`. Electron Main now starts only the shared Agent Server with Node's `import.meta.resolve` parent-URL capability enabled, so the unchanged server script resolves `@earendil-works/pi-ai` from the explicit packaged `pi-runtime` root instead of the sibling `resources/resources` directory. A production-shaped sibling-layout test reproduces the installed failure before the fix and initializes successfully through Electron Node after it; Pi remains pinned at `0.84.2`, and no bundle layout, Provider, Renderer, or recovery contract changed. This flag-only resolver was later superseded by source `5d7a235` above, which explicitly resolves the package manifest and entry from the staged runtime root and has mounted-image macOS arm64 evidence. A signed/notarized artifact, Windows rebuild, and installed first-Conversation acceptance remain pending. - Native Web Search client tickets MLW-01 through MLW-03 are integrated by source coordinator `20260831-web-search-client-integration-7d2f5b94` and promoted to local `main` by task `20260901-web-search-client-main-merge-5a9d3b82` from reviewed coordinator closure `ae81949a49d7df3be4859e6c111235a991a504e4` through product commit `49de82c4860fd0b377070279b6411237dc6b9564`; the final fixed-range Standards and Spec reviews passed at `4de3feefe451dc34dc46b323e2ea5e0b4e4840e8` with zero actionable findings, against frozen Works Square DTO frontier `a49c696ebc4213e3d62ece780961efbe17576f8e`. MakeLore now reuses the shared hosted Admission resolver, calls the single fixed Web Search typed route from Electron Main, materializes the signed Marketplace Skill/tool only in an eligible frozen parent Pi snapshot, and renders the closed billing receipt without parsing Web Search payloads in Renderer. The packaged Windows app proves that the route and receipt parser are main-reachable while OpenAI Provider authority is absent. The exact reviewed Windows package passed artifact verification; installer SHA-256 is `2492F88BB6F813834ECD24B392EB8337220E131E746547851393E4885C4B5BEF` and `app.asar` SHA-256 is `27EFABBB741F0A62CB58452801DD1D8893B8E5131EA1D30F74D610DEAD3F7A1D`. Real PostgreSQL and paid OpenAI acceptance remain external HOLDs; production activation still requires the official Ed25519 key, OpenAI key/model, price, and privacy copy. No deployment, publication, push, or PR occurred. - Human-authorized takeover task `20260831-promote-main-merge-5e9c7a31` completed the already-started local `main` merge as `03a9e866d4366e0a1cb416e26b424fe981071310`, recorded the transfer in `2ca60445d41628f1fa10e132994d2e2954b0bd4f`, and promoted verified integration tip `93fba75f7493d21cffc28847ceae26fee52a00a8` through merge `b928b9ac603b9797e89c1a6d8e561ad3c6eadf37`. Local `main` now contains both local hosted-Plugin history and fetched `origin/main` `38f85f6b5e4dc4e2c5e5b9f8f4506554cfd578f5`; the promotion merge changed only canonical project memory and task records, not product code. No remote push, deployment, or publication was performed. - Hosted Game Resource Plugin source `fe656dd865f1941f1dc2d369ce3bb09efb955fd8` and verification record `421c8254d51318355faec3ae94f8e1cfd4d054c5` from task `20260831-meowa-hosted-plugin-client-8d3a5b72` are integrated with fetched `origin/main` `38f85f6b5e4dc4e2c5e5b9f8f4506554cfd578f5` in merge `372b5345dae57ce19d2630b24277596db284194c` by task `20260831-integrate-remote-main-6b3d9e1a`. MakeLore now supports generic schema-2 `platform_hosted` Marketplace packages and a provider-neutral `makelore.game-resource` adapter. Its Skill and tools enter only an installed, enabled, assigned, admitted parent Pi logical thread; child and ineligible threads receive no projection. Hosted mutations require explicit confirmation, keep stable logical operation identity across uncertain results, and travel only through Electron Main to fixed Works Square routes. The old always-mounted Meowa tools, direct proxy, local credential configuration, and package-time credential path are removed. Production activation remains held until the official signing key, rotated server credential, positive Token Point pricing, and server Admission gates are ready and verified. - Local source snapshot `33fb31fb285b5cfb00d194a036aaf6e21cf8c5a1`, based on the prior local delivery `48a9189`, is integrated over fetched upstream `62304dc85b3c1069cd656dfacb61ee820e216fa2` in merge commit `28897cd4a2b7179d9ccb444218a1d74a2bbc004b` by task `20260831-merge-upstream-main-7c3a91f2`. The integration preserves Plugin Marketplace Release A and AI Design Living Form V2 while adopting one long-lived parent Pi Agent Server with isolated per-Conversation logical Runtime, Session, credential store, extension context, generation and JSONL channel. Parent logical turns remain capped at 4, warm idle threads at 8, and independent child processes at 4 against the FIFO process budget of 8. `.makelore/project.json` and `.makelore/conversations.json` are authoritative; current code does not read or migrate project metadata from `.niancode` or `.opencode`. - MakeLore curated Plugin Marketplace Release A source `40df677a31ff7651f962151eb84b925987781c03` from task `20260828-plugin-marketplace-client-5f8b3d72` is integrated by task `20260830-integrate-plugin-marketplace-client-6e3b9d82`. Electron Main now owns the authenticated Marketplace/Library client, immutable Package Store, trusted release verification, effective installed-plugin resolution, and frozen Pi worker materialization. Its original Marketplace, My Plugins, and Project Plugins Renderer surfaces are superseded by the unified `/plugins` projection recorded above; Renderer still receives no credentials, paths, Admissions, or signed URLs. Data Service remains system-included and consumes zero Token Points. R7 Standards and Spec reviews passed with zero findings, and XMA-01 passed all twelve live groups against real PostgreSQL and a signed-in packaged Windows client. The later `platform_hosted` client runtime is integrated above; production package trust and real Provider activation remain held behind the official signing key and the separate server, pricing, credential-rotation, and Admission gates. - AI Design Living Form V2 client source `b0b5a602b501308a23eb27e2f51a5169b9e46b1e` is integrated with matching Works Square server source `b5351d54f595ce8eb873593e462e4a556bea0b05` by task `20260830-integrate-marketplace-design-client-main-9d5f3b82`. Canvas now exposes one current Direction, one persistent Agent Session, one Current Specification and Living Form, one conversation timeline, immutable Quotes, Tasks, and Assets. Chat, direct edits, decisions, locks, and Asset binding share one server reducer; Main is the only V2 transport authority, and V1 DTO/local semantic fallback paths are removed. Production database cutover, real-account installed-client smoke, and paid Provider activation remain separate operator gates. - Updater downgrade-prevention source commit `2e61800` from feature task `20260826-fix-version-update-check-7c91a4` is integrated by task `20260826-recover-pi-updater-integration-8f3a6c21`. Every automatic-update channel assignment now immediately restores `autoUpdater.allowDowngrade=false`, so installed `2.0.0` does not treat an online `1.1.9` manifest as an available update; later explicit channel changes preserve the same invariant. - Local `main` is integrated through delivery `48a9189` by task `20260826-integrate-pi-provider-fix-6e4c2a91`. The strict 101-commit fast-forward replaces OpenCode with pinned Pi `0.84.2` as Makelore Code's sole production runtime, adds schema-v2 project/Agent/Conversation storage, the predecessor persistent per-Conversation worker topology, product Snapshot/Patch contracts, `/api/coding/*`, Provider/resource isolation, extension/subagents, process and write budgets, and background-run uncertainty ownership. Implementation `a098266` additionally validates/persists an unresolved Conversation model before first prepare and converts the exact Works missing user-context response into a non-replayed Provider-auth failure after expiring the cached gateway credential. Task `20260831-merge-upstream-main-7c3a91f2` supersedes only that parent-process topology with the shared Agent Server described above. The final Windows installer and final packaged Pi proof passed; real Provider turns remain explicitly waived with `realTurnVerified=false`, while macOS x64/arm64 and native non-WSL Linux remain unverified. Older OpenCode entries below are retained only as historical integration evidence and are superseded for current behavior. - OpenCode model-switch runtime correction source commit `cce7722` from feature task `20260821-model-switch-runtime-fix-a83d6c91` is integrated on local `main` by task `20260821-integrate-model-switch-fix-8f2d6c41`. The Main-owned client now maps Makelore's internal `modelID` to OpenCode 1.18.9's wire field `id`. An owned fresh runtime receives the current per-process Host API token when its local-proxy provider config is built, so persisting that already active token no longer creates a false manual-restart requirement; attached/unknown generations and timeout/partial persistence remain fail-closed. A rebuilt-client real local smoke is still pending. - Login-layout source commit `4d512b1` from feature task `20260821-remember-below-login-4a7c91d2` was merged into local `main` as `22f4bbc` by integration task `20260820-integrate-remember-password-5d7e3a1c`. Password login now places the existing remember-password control directly below the submit button and above the agreement; authentication, persistence, and secure-storage behavior are unchanged. - Remember-password source commit `990639f` from feature task `20260820-makelore-remember-password-b63e1c` was merged into local `main` as `2b9f84e` by integration task `20260820-integrate-remember-password-5d7e3a1c`. Password login now offers an optional Main-owned remembered credential: packaged builds encrypt the username and password through OS-protected storage, Renderer persistence and Works Square never receive that record, and unavailable secure storage disables the option. Logout and SMS login preserve it; a successful unchecked password login clears it. Packaged Windows and signed macOS smoke remain pending. - OpenCode Session model and partner hot-add source commit `c0163bc` from feature task `20260820-session-model-agent-hotfix-6e4c9a2f` is integrated on local `main` by task `20260820-integrate-session-model-hotfix-7b3e91c4`. Page selection and `/models` / `/model` now switch the active OpenCode Session model without provider persistence or runtime restart, while a partner model remains only the new-Session default. Agent readiness is tracked per id: a new unique id may be accepted after live discovery in an owned fresh generation, while same-id edits, delete/recreate and attached/unknown generations remain pending. - Learning archive size-validation source commit `8509084` from feature task `20260820-remove-download-size-check-4f8a2c1d` is integrated by task `20260820-integrate-download-size-6e3a91c2` through merge `0c1a360`. Electron Main no longer rejects a project ZIP because `Content-Length`, `archiveBytes`, actual streamed bytes, or the former 512 MiB ceiling differ; same-origin redirects, SHA-256, ZIP signature, temporary-file cleanup, and atomic save remain enforced. - Direct Learning README-image source commit `9956739` from feature task `20260820-direct-readme-client-a4d8e2c7` is integrated by task `20260820-integrate-direct-readme-client-b7e41c9d`. README Markdown image nodes now load validated credential-free HTTPS URLs directly, including SVG, while raw HTML, covers, historical media reads, and the Main-owned verified ZIP save path retain their existing boundaries. The matching Works Square source is `65ea070`. - Learning project-catalog source commit `38db158` from feature task `20260819-learning-project-catalog-impl-4e9c71a2` was merged as `d967b0f` by integration task `20260820-integrate-learning-catalog-a73e91c4`. At that historical checkpoint Learning kept its login and `module_access.learning` gate but now contains only a server-driven project list, safe README detail, direct credential-free HTTPS Markdown images, and a Main-owned verified native ZIP save path. Course generation, progress, local library, OpenMAIC player, Agent/ASR/classroom runtime, Learning IPC and player-artifact packaging were removed without a compatibility read path. Historical course data is left untouched. The matching Works Square operations/admin/API implementation and real-account package smoke remained pending. The 2026-09-04 removal recorded at the top of this file supersedes that catalog and its deployment obligation. - Square-auth lifecycle source commit `dc776ff` from feature task `20260819-square-auth-proxy-client-8c4f2a` was merged as `f52c2c8` and promoted from verified candidate `e7ec12d` to local `main` by integration task `20260819-promote-square-auth-client-73e4c1`. Desktop login, refresh, and logout now use fixed Works Square endpoints; Electron Main remains the sole token owner, persists rotated credentials before exposing the refreshed session, and keeps the existing seven-day inactivity boundary. The client no longer embeds a confidential OAuth client secret or refreshes directly against the custom identity service. The matching Square service change must be deployed first. - AI Design request-freeze source commit `87e4140` from feature task `20260819-design-freeze-live-6e2c` is integrated on `main` through `5bff5d3` by promotion task `20260819-promote-design-freeze-main-91c2e4`. Main-owned Workspace JSON requests and shared Works token refreshes now have a complete 30-second lifecycle deadline, including response-body consumption. Timeout settles as stable `504 DESIGN_WORKSPACE_REQUEST_TIMEOUT`; low-level Electron-to-Node fetch fallback is limited to `GET`/`HEAD`/`OPTIONS`, so mutation failures are not implicitly replayed. The native password/SMS login and temporary `disable-http2` diagnostic bootstrap remain included. Automated client verification does not yet prove the installed-client freeze is resolved or establish HTTP/2 as the root cause. - AI Design history source commit `bf0b805` from feature task `20260819-history-load-stall-a92d` is integrated on local `main`. Conversation reads start with the newest ten messages and fetch older pages through opaque cursors; the Canvas keeps its scroll position while prepending. A selected Conversation renders before generation-task reconciliation finishes, rapid A → B → A switching reuses an in-flight event-stream open, and a pending relay/open has bounded cleanup. This is a local source integration only; no packaged-client or deployed-service smoke is claimed. - `6478591` / `3a6d388`: AI Canvas task-stream reconciliation now reuses an in-flight `connecting` Conversation stream instead of opening a duplicate; rapid Conversation-switching regression coverage is present. Canonical `main` promotion is pending release of the occupied main worktree, and real slow-handshake Electron smoke remains pending. - `ce897f1` / `6504073`: AI Programming now isolates prompt lifecycle, loading and errors by OpenCode Session. Main serializes only runtime/configuration acceptance, verifies project Agent content against an owned fresh runtime generation before execution, and returns typed terminal pending responses without automatically restarting, reloading or disposing the shared runtime. A run that receives no explicit busy/assistant/terminal acknowledgement within 10 seconds ends only that Session and is never replayed automatically. The application-side isolation is verified; real bundled OpenCode/provider two-Session execution concurrency is not claimed. - Project-cover source commit `145a6ce571d646325092d1e722282babea503954` from feature task `20260817-project-cover-upload-a6a98e56`, integrated by task `20260813-sync-push-main-9c2f71`. First submission now requires a bounded PNG/JPEG/WebP cover, shows preview/file/reselect feedback, and sends metadata plus cover through Main-owned `POST /api/projects/with-cover`; conflicts stop before version upload and existing draft/published projects remain version-only. The matching Works Square server source is `407c883` (local merge `0cedfc4`). No client package, production deployment, or real-account smoke occurred. - `3b37ac3` / `55e61b7`: macOS Robot hotspot discovery performs one bounded worker-thread rescan after an empty or SSID-redacted CoreWLAN result; persistent SSID redaction maps to the existing permission error instead of a misleading empty-device state, while firmware and the open `Xiaozhi-*` contract remain unchanged. - `f5d47c8` / `b6148a5`: AI Programming voice capture is available after an Agent is selected but before the lazy first OpenCode session exists; transcription fills the composer draft without creating an empty session, while runtime, loading, transcribing, busy, and recording guards remain unchanged. - `4013edc` / `3b799af`: historically integrated per-user Code/Canvas/Learning/Robot entry policy from Works Square. The 2026-09-04 removal narrows the current Main projection to Code/Canvas/Robot while preserving the same pre-initialization route gate. - `01bee31`: historically enabled the AI Learning course catalog/generation/download/playback architecture. Its Learning course/runtime behavior is superseded by `38db158` above; its unrelated `game-engine` removal and project-root `planning-with-files` behavior remain historical context. - `26b52d7`: Canvas Prompt Museum, editable server-priced generation Quotes, project deletion/task-detail workflow, cloud-default Canvas development entry, and Chinese-only UI consolidation from the authoritative remote main. Its transient bundled `game-engine` Skill is superseded by `01bee31`. - `f8d82e6`: Prompt Museum media rendering now accepts only the server-controlled relative media route, fetches it through a Main-owned bounded Works-authenticated proxy with one refresh retry, and keeps credential-free HTTPS CDN media direct. Renderer-side validation and card-local placeholders cover invalid or failed media; attribution URLs remain optional. - `c1326a2`: Guided Hotspot Binding now scans bounded open `Xiaozhi-*` candidates and connects the user-selected hotspot inside the page through Main-owned Windows WLAN and macOS CoreWLAN/CoreLocation adapters; system Wi-Fi remains fallback, exact `=0` rollback and firmware/cloud contracts are unchanged. - `b78fc07`: Guided Hotspot Binding is enabled by default in Electron Main, with exact environment value `0` as rollback and direct six-digit fallback on capability-read failure; firmware and Host/cloud contracts are unchanged. - `b7a1590` / `14afe4a`: initial firmware-zero-change Guided Hotspot Binding V1 implementation and decision used a Main-owned default-off capability, fixed portal action, in-memory Renderer journey, and existing six-digit Binding contract; `b78fc07` above supersedes only that default. - `ea75b06`: Robot configuration reads accept canonical weak numeric response ETags introduced by public response compression only when the numeric revision exactly matches the strictly projected DTO; configuration and assignment writes continue to emit strong `If-Match`. - `fe55dee`: Robot configuration editing uses the safe Xiaozhi/Works catalog for model, language, and voice selections, with bounded sliders for TTS numeric controls and no-store catalog responses. - `fd9b5b46a913c515e94e4e26f185d43866c2581f` / `7a811590c4943b7b1b7ea5f3b4d3ce3ce05622a5`: Codex-style persistent AI Programming context-compaction timeline, run-lifecycle separation, polling-idle completion, and cold-hydration hardening. - `22378efcee07e7fb80b651e65e3202f1a1dfea1d`: AI Canvas bidirectional Agent WebSocket commands, idempotent transport fallback, and Quote-based generation-task recovery. - `aba5cae286807093cf4ef643fe9f498050985c31`: Robot / AI hardware module, Main-owned Works Square proxy, and cross-repository wire contract. - `86ece3a` / `4dde8f3`:客户端登录七天滑动续期及集成提交。 - `724290e` / `dcc92fc`:Main-owned 一键打包提交审核及集成提交。 - `493b31c`:客户端三类 `ProjectType`、小游戏/小程序受控发布模板与自定义项目发布隔离。 - `4df0477` / `8dd99c1`:客户端静态发布唯一链路、旧 Compose 协调链退役及安全边界补强。 - `4980894` / `03dae62`:AI 绘画 Enter 发送及同一 Workspace 下的多 Conversation 客户端模型。 - `926056a`:Makelore 内置 Electron WebContents/CDP 发布前本地预览检查。 - `5b44864`:Main-owned 本地 npm/Vite 构建、同字节 Electron 双视口预检、source+built 双归档与 artifact contract 上传。 - `08da976` / `0ee5254`:AI 编程首次发送已知空 session 快速路径与明确上游饱和终止态投影。 - `809364e` / `88281b8` / `7a807a2`:AI 绘画单参考图图生图选择/上传交互、最新客户端主线集成及旧版 Brief medium 缺失兼容。 - `f05b9d4` / `e221374`:Updater 稳定源缺包诊断与用户错误脱敏修复,以及当前 `main` 上的图生图最终合并提交。 - `f4113a8`:远程主线客户端收口,包含启动预热、课程 Skill、项目 Agent 模型配置、浅色界面整合,并移除独立真机预览与内置 Superpowers。 ## Current Focus 客户端面向非专业用户提供“选择目录创建交互式 AI 应用 → 直接进入聊天 → 按项目需要可选调用官方 bundled Project Scaffold Skill → 项目配置中一键提交 → Main 本地 npm/Vite 构建 → Electron 双视口预检最终产物 → 上传 source+built 双归档与 contract → 运营审核”的唯一创建者链路。普通新建不展示类型、模板、原始 UUID、绑定或独立副本选项;Renderer 写入内部默认 `interactive_ai_app`,Main 生成 UUID,并只创建 `.makelore/project.json` 与 `knowledge/`。有效旧配置仅缺 `projectId` 时由 Main 串行补齐;旧 `initialized` 仅保留兼容,不再阻断导航、聊天或首个 Agent。既有 `custom` 和历史类型继续兼容,但不作为普通新建选择。`makelore.project-scaffold` 不是创建前置条件,只负责不覆盖的固定起步树与只读发布准备度说明,不能安装、构建、上传、提审或批准;其 `.mjs` 只从签名客户端固定资源加载,Marketplace 下载 artifact 仍拒绝脚本。Main 对安全源码快照运行安装包内固定 npm 11.6.2 的 `npm ci --ignore-scripts`,再显式调用项目 `package-lock.json` 锁定的 Vite;Vite config/plugins 以当前桌面用户权限执行,因此只适用于用户信任的本地项目,不是 sandbox。预检由 Main 以临时 loopback origin 和 Electron WebContents/CDP 检查与最终 `built_archive` 相同的内存文件字节,覆盖桌面/移动视口、运行错误、白屏和外域访问;不使用 Playwright。该检查仍可由非官方客户端绕过,不产生可信 receipt,也不复刻生产 opaque-origin。服务端把源码、构建归档和 contract 视为不可信输入,逐字节重算与校验并固化不可变 Release;人工审核仍不可绕过。历史 `mini_game` / `mini_program` 只在读取边界归一为规范 `interactive_ai_app`。已发布作品优先使用安全投影后的 `play_url`,`runtime_url` 仅保留一个客户端版本的兼容回退。 AI Design Canvas 现在以中央 conversation timeline 加唯一 active 制作方案、右侧 320–340 px 全高 Works rail 的两区布局服务创作者;Canvas 路由不挂载全局左栏,紧凑宽度把同一 Works rail 放进右侧 Sheet。Active 方案的 `content.concept` 直接作为可编辑“创作提示词”,类型、画幅、视频时长和数量保持紧凑直控;已提交、运行中或终止方案折叠进对话历史。Reference 使用稳定 reference ID、真实 Workspace Asset binding 与连续 `@图片N` alias;Prompt 是用途的唯一可见表达,binding row 只管理缩略图、文件、alias、替换与删除。未绑定 alias 提供定点上传并阻止 Quote,Prompt/reference/参数变更产生新 Specification revision 和新 immutable Quote。一个 Workspace 仍只公开一个 current Direction、一个 persistent Agent Session 和一个 Current Specification;conversation timeline 只记录交互历史。Chat、direct edits、decision responses、proposal acceptance、locks、Asset binding 与 restore 都通过 `design.input.apply` 进入同一服务端 reducer,Renderer drafts 在 accepted 前保持本地。Main 持有 Works Token、stream ticket、WebSocket、request deadline、stable command/operation IDs 与错误脱敏;unknown result 只能复用原 identity,结构化业务错误不得重放。Generation 由服务端对 exact Specification revision 编译 immutable Quote,客户端只展示 public output plan、warnings、expiry 与 Token Points,并以 Quote ID 调用 `design.generation.confirm`;Provider Prompt、model、route、storage 和 billing atoms 不进入 Renderer。Task/Asset events 独立收敛 Workspace resources,不改写 Living Form。Development 与 packaged builds 均使用 Works Square V2,V1 DTO、local semantic adapter、mutable Quote PATCH 与 editable provider Prompt 已移除。 新提交的 Design chat 会立即从现有 pending operation 投影为带“发送中”或“正在确认”的临时用户气泡,服务端确认的 canonical turn 到达后再替换它;确定失败时原草稿重新出现在输入框。`design.assistant.progress` 经 Main 归一为固定通俗阶段,只在对应用户气泡下形成可更新、可折叠的“AI 处理过程”,不成为对话消息、中央制作方案或模型思考过程。匹配同一 pending chat 的 `design.assistant.delta` 只临时绘制为一个未完成助手气泡,随后由 canonical turn 替换;它不进入 conversation timeline,也不生成独立全局整理栏。中央 active 制作方案继续呈现 AI 当前整理出的 Current Specification 公共投影。重复连接和事件按 connection generation、operation identity 与 `chunkIndex` 收敛。 Prompt Museum 已退出当前产品面:Canvas 不再显示“获取灵感”,App 不挂载或 lazy-load Museum Renderer 页面,历史 `/image-prompts/*` 只重定向到 `/image-canvas`。Main-owned 固定 API、Works 认证、相对媒体路径校验、单次 401 刷新、可信 raster MIME/10 MiB 上限与共享 DTO 暂作为 dormant 兼容/安全基础设施保留,不代表可见模块或生产内容已启用;恢复入口需要新的明确产品决定。`pnpm run dev` 与 packaged Canvas 均使用云端 V2 适配器,产品 UI 只保留中文。 密码登录提供可选“记住密码”。该记录与七天登录会话分离,只在正式安装包且系统安全存储可用时由 Electron Main 加密落盘;Renderer 仅在登录页内存中接收回填,不写 Zustand/localStorage,Works Square 也不持久化桌面密码。退出登录和短信登录不删除记录,成功的未勾选密码登录会清除旧记录。未打包开发版禁用该选项,避免未签名 Electron 调试进程触发 macOS 钥匙串。 Makelore 在会话恢复、登录和刷新后由 Electron Main 请求 Works `/api/auth/me`,Renderer 只获得 Code、Canvas、Robot 三个布尔权限。缺失 `module_access` 或任一字段时默认开启;服务端 `design` 显式映射客户端 `painting`,额外旧字段被忽略。被关闭的模块卡片置灰且不可点击,根路由、深层路由和别名路由均在 `MainLayout` 或模块初始化前阻断。Code provider 等待认证权限加载完成;权限查询返回终止性 `401` 时同时清理 Main 和 Renderer 会话。`/settings` 是全局设置,不受 Code 入口策略阻断。该机制只是客户端入口策略,不代替服务端 API 授权。 插件工作区由 Project Configuration 页面拥有:模型、Skill、知识旁的“插件” ResourceCard 打开 `/project-config/plugins` 对应的同页宽 Sheet,配置页保持挂载;没有 active project 时仍可查看账号与本机插件。Code 侧栏不再提供独立入口,`/plugins`、`/plugin-marketplace`、`/my-plugins` 与 `/project-plugins` 只保留查询/筛选意图并兼容重定向。统一列表继续投影 Marketplace、账号 Library、官方设备状态、本机 Device Packages、当前项目状态与 retained IDs;获取、设备安装、项目启用、运行授权和计费仍是独立生命周期。Data Service、Game Resource 与 Project Scaffold 在满足交付/获取条件并由项目启用后自动进入每个父 Agent,不提供伙伴分配;采用 assignment scope 的其他插件继续由 Agent Skill 分配控制。Game Resource 在一次计费确认后由 Main 提交一次并内部轮询,终态全部输出自动写入调用时冻结的原项目;Agent 不再轮询状态、选择保存路径或进行第二次保存确认,交付恢复也不得重新生成或重复计费。原生 selected-model Web Search 不进入插件列表。 Learning 已从 Makelore 产品中移除:没有模块卡片、路由、侧栏、Renderer 页面、Main Host API、下载服务、共享 DTO、素材或打包 fallback。旧 Learning URL 回到模块选择页,旧 API 使用标准 404 边界。客户端不扫描、读取、迁移或自动删除历史课程数据;名称仍含 Learning 的冻结账号分区盐仅为跨模块持久状态兼容标识,不代表产品模块仍存在。 Code 入口现在始终落在 `/chat`。没有本地项目时显示 Makelore 品牌引导、单一橙色“新增项目”动作和真实项目卡横向列表;空列表不伪造示例。有项目但尚无 Agent 时保持项目可进入,并提供非阻塞的首个 Agent 设置入口。项目创建和项目卡选择都复用 Sidebar 的既有验证/激活流程,不建立第二套状态。 AI 编程已经硬切到精确 pin 的 Pi `0.84.2`,不存在 OpenCode fallback 或双 runtime。project、Agent 与 Conversation 只在 `.makelore/project.json` 和 `.makelore/conversations.json` 使用本地 schema v2;当前客户端不从 `.niancode` 或 `.opencode` 读取、迁移或删除项目元数据。只要项目 metadata 有效即可进入 `/chat`;`initialized` 仅为 schema 兼容字段,不构成导航或 Conversation gate。项目尚无启用且未归档的 Agent 时显示非阻塞设置入口,不创建伪 Agent;真正开始 Conversation 前仍由现有 Agent/模型校验给出明确恢复路径。Electron Main 按需启动一个长驻父 Agent Server,每条 active/warm Conversation 在其中拥有独立 Runtime/Session/channel、credential store、extension context、generation/seq、Snapshot/Patch、model/thinking、队列、interaction 与错误状态,Composer 在 lazy prepare 期间仍可编辑;正式包从 staged `pi-runtime` manifest/root 定位并校验 Pi 包入口,不从脚本目录或应用 `node_modules` 回退。Renderer 只通过 `/api/coding/*` 和 Snapshot-first/`patch-batch` SSE 消费产品中立合同;gap/reconnect 只恢复目标 Conversation,accepted/uncertain mutation 不自动重放。`lifecycle:sleep` 会关闭旧事件流,视图挂载、项目上下文变化、页面重新可见或窗口 focus 会静默刷新已选 Snapshot,使后台 terminal 状态收敛且不重放 mutation。隐藏 Conversation 的红点只在新 pending interaction 或新 completed/failed/aborted terminal transition 出现,不由助手/thinking/工具过程或单个工具失败触发。Session hydration 沿完整 active branch 投影可见历史,Pi compaction 只改变模型上下文并保持 summary 私有;Renderer 首次挂载最近 120 个节点,向上滚动时按 100 个节点追加更早内容并补偿新增高度以保持阅读锚点。折叠的 thinking、助手过程说明与工具输出固定展示第一条可见内容和首个非空行,横向偏移保持为零,展开后仍显示完整内容。未解析 Conversation 第一次选模先 validate 并持久化 resolved metadata,再 prepare;同账号模型切换使用 target `set_model`,跨账号只重建目标逻辑线程。Web Search 只作为所选模型 capability 进入父 worker 并使用相同 model/provider/credential 与普通模型计费,不经过 Marketplace/Hosted client/Plugin Charge 或浏览器 fallback;child 不继承。Conversation 工具可检查并在独立确认后安装 npm、Git、本地 Plugin 目录或 loose `SKILL.md` 为 Main-owned immutable Device Package;不运行生命周期脚本,可执行 extension 具有桌面用户权限,新/idle parent 自动刷新,active parent 结算后刷新,child 为空。每个 Main-selected generation 都保留全部显式安装且当前启用的 Skill 路径;生成的 Makelore bridge 是必需的首个 extension,其余 extension 全部经 `additionalExtensionPaths` 加载,并继续关闭 ambient discovery。top-level 逻辑 turn 并发为 4,warm idle logical-thread LRU 为 8;independent child 进程并发为 4 并使用 FIFO 进程预算 8;coding child 与 parent 共用项目 write lease。同一助手工具批次内,内置 `bash`/`edit`/`write` 与声明需要该 write lease 的动态产品工具按顺序执行,避免 Pi 在批量 prepare 阶段形成租约自锁;纯只读工具批次仍可并行。prompt/compact confirmation timeout 后仍保留 run/Agent-Server-or-child-process/background ownership,迟到 success/failure/exit/abort 单调且 exactly-once 收敛,页面隐藏不会停止 active/uncertain run。线程级替换只使目标 generation 失效;整个 Agent Server 退出会统一使所有旧 channel 失效,但 Main/Renderer 存活且下次恢复只重启一个 Server。Pi `0.84.2` 手动 compact 不发 `agent_settled`,由 correlated compact RPC 结果终结。父 Provider credential 只进入选中逻辑线程的内存 credential store,child 凭据只进入该短命进程;确定性的 Works user-context 缺失会失效 gateway credential、fail fast、不重放并投影固定 Provider-auth 错误,不归类为 Pi crash。精确的 `403 token_point_balance_exhausted` / `词元点数余额不足` 上游响应会在 Main 内归类为不可重试的配额耗尽,Renderer 只收到稳定 `CODING_PROVIDER_QUOTA_EXHAUSTED` 与安全中文提示;重开会话仍保留该提示,不暴露上游 request id 或原始错误正文。真实 Provider 验证仍为用户明确接受的未验证风险;macOS arm64 仅有本地未签名 mounted-image initialize/shutdown 证据,签名/公证/完整 process-enumeration、macOS x64 与 native non-WSL Linux 仍未通过平台发布门禁。 Updater 仍由 Electron Main 选择目标 feed、记录原始诊断并保持失败语义。正式稳定源缺少对应平台 manifest 时,设置页只显示一条简洁中文提示并允许重试,不把缺包误报为已是最新版,也不向普通界面暴露堆栈、URL、路径或错误码;签名产物发布和真实升级安装仍属于外部 Release Gate。 Robot 绑定设备默认先显示“引导配网 / 已有激活码”路径选择。引导路径在页面内扫描附近符合条件的开放 `Xiaozhi-*` 热点,要求用户明确选择后由 Main-owned Windows/macOS 原生适配器连接并核验当前 SSID;失败时保留系统 Wi-Fi 兜底。macOS 在首次 CoreWLAN 结果为空或 SSID 全不可见时只进行一次 250 ms worker-thread 延迟重扫;第二次仍有网络但没有可读 SSID 时显示定位权限错误,不再冒充“没有发现设备热点”。后续继续使用固定 `http://192.168.4.1/` 系统浏览器页面、恢复互联网和现有六位 Binding;精确环境值 `0` 可回滚为直接六位码。Makelore 不接收 Wi-Fi 密码、不修改固件,也不把热点发现或 Binding 成功等同于可信身份/在线。签名 macOS、Windows 真机、指定固件/发行契约和完整整链仍未完成验证。 ## Recently Completed - 2026-09-07: Semantically integrated all completed current-product Code, Project Configuration, Plugin, and Canvas branches. Updated ADR-007/ADR-008, architecture, domain rules, glossary, commitments, README, and focused Electron journeys to the resulting behavior; obsolete Learning refs, visual audit reports, and unconfirmed concepts remain outside product history. - 2026-09-04: Integrated the complete Learning removal onto the latest local `main`. The module chooser, guarded routes, sidebar, auth projection, Main dispatcher, lifecycle state, build output, and docs now contain only Code, Canvas, and Robot. Stale Learning routes return to the chooser, the retired API is unregistered, and historical course data remains untouched. Full unit, build, and Electron E2E gates passed on the integrated tree. - 2026-09-03: Reconciled local `main@7a37593` with fetched `origin/main@8e947b4` through a normal two-parent merge. The result keeps the reviewed single `/plugins` workspace and Device Package multi-extension activation while integrating the remote Pi runtime-root, Conversation foreground/history/quota, tool-batch, and settlement corrections; the predecessor Project Configuration Plugin Services sheet remains retired. - 2026-09-03: Integrated the paired Device Package prepare and activation fixes. Packaged Main now resolves package inspection from the physical bundled Pi runtime, and the parent Agent Server loads the required generated Makelore bridge plus every explicit installed/enabled Pi extension while retaining all selected Skills and keeping ambient discovery off. Source verification passed packaged npm/Git/loose-Skill prepare, a real Agent Server with two external extension commands, full unit/pressure, typecheck, lint, build, Windows packaging, and artifact checks. The installed 1.2.6 client is unchanged, so exact-main rebuild/install and live activation are still pending. - 2026-09-03: Reconciled fetched `origin/main` with the complete local mainline and integrated the three cleanly owned latest source tasks through normal merge commits. The result contains Model Tools/Device Packages, youth-facing Canvas, packaged Pi runtime-root resolution, foreground Conversation reconciliation, and attention-only unread markers without rewriting either mainline history. - 2026-09-03: Corrected packaged Pi dependency discovery to resolve the package manifest and entry from staged `pi-runtime`. A local-only unsigned macOS arm64 DMG passed mounted-image Agent Server initialize/shutdown; signing, notarization, full macOS process proof, other architectures, publication, and installation of this corrected build remain outside that evidence. - 2026-09-03: Integrated Renderer foreground recovery and Conversation attention semantics. Returning to a selected Conversation now refreshes its authoritative terminal Snapshot after lifecycle sleep without prompt replay, while hidden red markers are reserved for new interactions and terminal task outcomes. - 2026-09-02: Integrated the Pi write-leased tool-batch correction. Multiple Bash/edit/write or lease-requiring product tools emitted by one assistant response now execute sequentially instead of waiting on a lease before any command can start; read-only batches remain parallel. A real Agent Server regression covers two Bash calls, a command-level timeout, and rejection of the former HTTP-idle-timeout `fetch failed` path. - 2026-09-02: Integrated bounded recovery for a missing Pi prompt settlement. A final persisted assistant response can no longer leave the Composer permanently processing merely because `agent_settled` was lost: Main waits for the normal handshake, then uses exact target-thread idle evidence to hydrate and settle once, or emits a safe target-only protocol failure. Focused runtime/process tests, typecheck, and the Vite/Electron production build passed on the integrated tree. - 2026-09-01: Integrated the predecessor Plugin navigation work plus complete active-branch Coding history with scroll-anchor preservation, narrow Token Point quota feedback, and stable first-line process previews. The predecessor Project Configuration sheet is superseded by the reviewed unified `/plugins` workspace and is not present in the current product. Combined typecheck, focused/full unit tests, lint, Vite/Electron builds, and five focused Electron E2E scenarios passed. The obsolete Learning Player packaging branch remains excluded by explicit human confirmation and ADR-005 remains authoritative. - 2026-08-31: Integrated the provider-neutral `makelore.game-resource` hosted Plugin client with fetched `origin/main`. Generic schema-2 `platform_hosted` packages now materialize frozen Skill/tool snapshots only for eligible parent Pi logical threads; paid operations require explicit confirmation and stable logical identity, while Electron Main alone owns the fixed Works transport. Legacy always-mounted Meowa tools and client credential paths are removed. Focused/full unit tests, typecheck, lint and Vite/Electron builds passed; production signing, pricing, credential rotation, real Provider acceptance, push, deployment, and publication remain open. - 2026-08-31: Integrated the occupied local source snapshot over upstream Marketplace Release A and AI Design Living Form V2. Makelore Code now amortizes parent Pi startup through one long-lived Agent Server while preserving isolated per-Conversation logical runtimes, sessions, credentials, extensions and channels; child Agents remain independent processes. ADR-006 and current architecture now use `.makelore` as the sole project configuration source and explicitly reject legacy metadata reads or migration. - 2026-08-26: Fast-forwarded the complete Pi hard-cutover and installed-package resilience chain into local `main`, including per-Conversation workers/Snapshot projection, extension/subagents, bounded process/write/background ownership and the deterministic Works user-context Provider-auth correction. The final Windows installer, packaged Pi runtime, extension/child, 4+4 pressure, uncertainty/late-settle and zero-lingering-process proofs passed. Real Provider turns are explicitly waived rather than passed; macOS and native non-WSL Linux remain release evidence gaps. - 2026-08-20: Replaced AI Learning's course generation/player stack with the curated project catalog defined by ADR-005. The authenticated/module-gated client now renders project cards and safe README detail, loads validated credential-free HTTPS Markdown images directly, and saves verified ZIP archives through the native dialog. Old course/runtime/player packaging was removed; server/client regressions and full suites passed, while production deployment and real-account package smoke remain pending. - 2026-08-19: Integrated native password/SMS login, the temporary HTTP/2-disabled diagnostic bootstrap, and the AI Design freeze fix. Workspace JSON calls and shared token refresh now settle within 30 seconds, transport abort is paired with deterministic rejection, and implicit Electron-to-Node fallback no longer replays mutation requests. Installed-client Quote retry/confirm smoke and the final HTTP/2 policy decision remain pending. - 2026-08-17: Integrated application-side multi-Session isolation for AI Programming. Session A may remain busy while Session B is independently accepted or terminally rejected; errors, startup deadlines and uncertain-failure cleanup stay Session-scoped. Main now fail-closes stale Agent/provider runtime state before execution, applies bounded manager/project FIFO acceptance with revocable timeouts, and never refreshes the shared runtime automatically from ordinary execution paths. Full unit, typecheck, lint, build, focused Electron E2E and independent Sol review passed; a real paid-provider/bundled-runtime concurrency smoke remains pending. - 2026-08-17: Replaced the temporary coverless-first-create fallback with a required PNG/JPEG/WebP picker, preview, file name, reselect action, Renderer/Main signature and size validation, and one Main-owned multipart metadata-plus-cover create request. Create conflicts fail before version upload; existing project metadata and covers remain unchanged. - 2026-08-17: Corrected macOS Robot hotspot discovery after a system-visible `Xiaozhi-*` report. CoreWLAN now gets one bounded retry when its first result is empty or all SSIDs are unavailable; a persistent non-empty redacted result becomes the existing safe permission state. Open-only filtering, firmware, Host/Renderer contracts, exact-current-SSID verification, and the system-Wi-Fi fallback are unchanged; signed-package physical smoke remains pending. - 2026-08-17: Created merge commit `4013edc` for the reviewed per-user module-entry policy source tip `3b799af`. Main exposes only four booleans from `/api/auth/me`; missing fields remain enabled, `design` maps to `painting`, disabled root/deep/alias routes stop before module initialization, Code provider startup waits for policy hydration, terminal `401` clears both session layers, and global settings remains reachable. - 2026-08-17: Integrated remote `01bee31`, which at that checkpoint introduced Learning course browsing/generation/install/playback and its OpenMAIC runtime boundary alongside unrelated repository consolidation. ADR-005 and source `38db158` supersede and remove that Learning course/runtime behavior; historical downloaded data remains untouched. The unrelated `game-engine` removal and project-root `planning-with-files` behavior remain current. - 2026-08-16: Integrated remote `26b52d7`: Canvas now has server-backed Prompt Museum navigation, editable server-repriced generation Quotes, task result details/downloads, guarded project deletion, cloud-default development, and Chinese-only UI. That tip briefly bundled `game-engine`; authoritative successor `01bee31` removed it. Client integration is verified separately from production Prompt Museum data/backend deployment. - 2026-08-18: Integrated Prompt Museum media rendering from `f8d82e6`: relative protected media is fetched through Main with bounded trusted-raster validation and one 401 refresh, HTTPS media remains direct, invalid/failed images are card-local placeholders, and missing attribution URLs render without broken links. Focused unit/Electron E2E, typecheck, scoped lint, and Vite build passed; real Works/CDN production smoke remains pending. - 2026-08-16: Integrated Windows/macOS in-page Robot hotspot discovery, explicit selection, connection, and exact-current-SSID verification behind the existing default-on guided capability. Candidate IDs are bounded and short-lived, native diagnostics stay in Main, system settings remain fallback, and firmware/Portal/Binding contracts are unchanged. - 2026-08-16: Enabled the existing Guided Hotspot Binding journey by default after explicit product confirmation. Exact `NIANCODE_AI_HARDWARE_GUIDED_HOTSPOT_BINDING=0` remains the operational rollback; fixed portal ownership, direct-code fallback, security warnings, firmware-zero-change, and Binding-without-online semantics are preserved. - 2026-08-16: Initially implemented ADR-002's Robot onboarding V1 without changing firmware, behind a default-off Main capability and fixed portal opener. The later `b78fc07` decision above changes only the default; the same firmware/issuer/native-opener/physical evidence remains outstanding. - 2026-08-15: Corrected the deployed Robot configuration-read contract after the compressed public Works response was observed with `ETag: W/\"0\"` and matching numeric `config_revision: 0`. Electron Main now accepts only canonical strong or weak numeric response tags, still requires exact DTO revision equality, and always sends strong `If-Match` for mutations. No production client rollout is claimed. - 2026-08-16: Integrated selection-oriented Robot configuration editing. Enabled model and caller-safe voice metadata now flows from Xiaozhi through Works Square and Electron Main without exposing provider secrets; unavailable current values and `clear_fields` semantics remain intact. Production deployment of the matching service endpoints is still required. - 2026-08-15:AI 编程上下文压缩改为 Codex 风格的会话内时间线事件;手动与自动压缩原位展示并持久保留,历史回放去重且状态只允许从 running 单调进入 completed,压缩完成不再冒充整个 run idle。 - 2026-08-14: AI Canvas Agent 命令与流式事件改为共用双向 Conversation WebSocket,并保留仅面向传输故障的幂等 REST 回退;结构化 Gateway 错误不重试且未知文本脱敏;确认生成按 Quote 恢复已落库任务,切换 Conversation 后仍同步 Workspace 任务且不覆盖新会话状态或错误。 - 2026-08-13: Integrated the enabled `Makelore Robot` top-level module at `/ai-hardware`. Renderer uses typed safe DTOs while Electron Main owns Works Square authentication, idempotency identities, ETag/If-Match forwarding, response projection, limits, timeouts, and credential recovery. Robot and Canvas routes no longer initialize AI Programming projects/providers. No production deployment or real activation-code smoke is claimed. - 2026-08-08:合并登录续期和一键发布;发布成功后保存精确 app/version/review 映射,Renderer 不接触 Token、ZIP 或本地路径。 - 2026-08-08:补齐跨平台 Electron E2E fixture、Windows ZIP 预检和异常成功响应安全投影。 - 2026-08-09:新建项目支持小游戏、小程序和自定义三类不可变产品类型;前两类生成固定 Vite 发布模板,自定义及缺少类型字段的旧项目不显示一键提交入口。 - 2026-08-10:删除客户端旧 Compose deploy-check、watcher/arm/upload 协调和手工 ZIP 路由;submission binding v2 保留旧 `submitted` 绑定并把旧中间态归一为 `legacy_retired`,同时补齐 Renderer capability、`play_url` 安全投影和本机绑定失败告警。 - 2026-08-11:AI 绘画支持在同一设计项目内创建和切换多条独立 Conversation;保留项目级任务/资产,并使用 Workspace + Conversation 身份保护异步与流式更新。退出时关闭本地流并清除本地 Session-id 缓存,不删除服务端持久 Conversation Session。 - 2026-08-12:一键提交前复用当前项目的内置浏览器 loopback preview,以 fresh 临时 Electron WebContents/CDP 执行桌面/移动 UX 预检;服务端仍执行唯一受控构建、不可变 Release 安全门禁和人工审核。 - 2026-08-12:发布架构反转为 Main-owned 本地构建;固定 npm 11.6.2 按项目 lockfile 安装并执行项目 Vite,Electron 预检最终上传同字节产物,再上传 source+built 双归档和严格 contract。服务端仅校验并固化不可信字节,不再承担项目 Vite 构建。 - 2026-08-12:AI 编程新 session 的首条 prompt 不再被已知空历史读取阻塞;明确上游分组饱和会快速终止,通用 `429` 仍保持原有限速语义。 - 2026-08-13:AI 绘画把原视频首帧选择器泛化为单图来源选择器;图片 Brief 可选择项目作品或上传本地图作为图生图参考图,视频及未决 medium 保持历史首帧行为,成功提交后关闭弹窗。 - 2026-08-13:Updater 对 Works Square 稳定源缺少 Windows/macOS manifest 保持错误状态,在 Main 日志保留原始诊断,并在设置页去重、脱敏为可操作的中文提示;未发布任何新安装包。 ## In Progress - 先部署支持规范 `interactive_ai_app` 与历史别名的服务端,再安装匹配客户端;随后成组验证显式 Scaffold Skill、source+built+contract 校验、OSS immutable Release、运营审核、CDN/Edge 与 App 消费链。 ## Next Recommended Steps 1. 在停止服务的目标数据库完成 Design V2 cutover dry-run、清零 blocker、显式 apply/validate,再用成对部署的服务端与安装包真实账号执行 direct edit、chat edit、Quote request/confirm、后台完成、结果下载和 interrupted unknown-result replay smoke; paid Provider activation 另行授权。 2. 部署 Works `module_access` migration 与 `/api/auth/me` 权限 API,打包新 Makelore 客户端,再用真实账号分别关闭 Code、Canvas、Robot 执行卡片、根/深层/别名路由 smoke;同时独立验证模块 API 服务端授权。 3. 对 default-on Guided Hotspot Binding 核对指定固件镜像与六位码发行/消费契约,补齐 Windows 真机热点连接、签名 macOS x64/arm64 CoreWLAN/CoreLocation/worker 打包验证、真实 Host API/native seam Electron E2E 和完整真机 smoke;发布支持保留精确 `=0` 回滚,不把缺失证据表述为已验收。 4. 成组核对客户端 source+built+contract 上传 → 服务端逐字节校验 → OSS immutable Release → CDN/Edge 的发布契约与客户端 `play_url` 消费契约。 ## Open Questions / Blockers - 客户端与模拟上游回归已完成;真实服务端新协议、OSS/CDN、运营审核、App 播放、生产账号和环境变量仍待部署环境确认,不能据此宣称生产发布链已经验收。当前已验证的 Windows 安装器未上传或发布。 ## Risky Areas - 三模块权限只控制 Makelore 客户端入口和初始化,不是 API 授权边界。不得因卡片置灰或路由阻断而放宽 Works/模块服务端的身份与权限校验;旧服务端缺少对象/字段时默认开启是显式兼容策略。 - Prompt Museum 相对媒体必须保持固定的服务端路径并由 Main 处理;如果服务端增加媒体变体,需同步维护 entry/path 语法、Works Bearer 所有权、单次刷新、10 MiB 限制、可信 raster MIME 白名单与 Renderer data URL 校验。HTTPS 直连媒体必须继续无凭据,图片失败必须局限在卡片/详情视图。 - Learning 必须保持完全退役;不得因旧链接、旧服务端字段或历史数据而恢复入口、路由、API、下载或打包 fallback。历史课程数据不再读取、迁移,也不得被隐式删除。 - Works Project 首次封面已由服务端源 `407c883`(本地 merge `0cedfc4`)提供单请求原子绑定与失败补偿,客户端源 `145a6ce` 因此要求首次发布上传 PNG/JPEG/WebP 封面;部署、安装包和真实账号/对象存储 smoke 仍未完成。服务端仍没有已有 metadata 的 revision/ETag 与 draft-only 条件写,因此已有 draft/published 继续只允许 version-only,客户端不得以无条件 PATCH 替代。 - Guided Hotspot Binding 默认开启并提供未经认证的热点扫描/显式连接,但当前 Hotspot/portal 仍是开放 SoftAP + 明文 HTTP,且精确出货镜像、激活码发行契约、签名 macOS、Windows 真机与完整整链尚未验证。界面必须保留环境警告,异常发布可用精确环境值 `0` 回滚;不得把 SSID 前缀宣称为可信设备发现、自动认领或在线证明。 - 一键提交已成功但本机 submission binding 落盘失败时必须保持提交成功、显示固定 `binding_warning` 并继续轮询,避免用户误判上传失败。 - 公共 `play_url` 必须满足 Works Square 同源 HTTPS、无 userinfo/loopback、精确 `/apps/{app_id}/` 路径、无 query/fragment、版本非空且上游标记可播放。 - `/api/works/projects/publish-source` 必须在读取凭据和项目文件前校验 Renderer capability;Host token/base 不能替代该 UI 边界。 - `works-cloud-deploy.json` 仅是已安装数据的兼容文件名,不代表客户端仍拥有自动部署协调器;旧中间态不得恢复为后台任务。 - 刷新凭据、发布 Token、ZIP、幂等键和重试只能由 Electron Main 持有。 - 本地 `projectType` 只决定产品分流和显式 Scaffold Skill 选择,Skill 的静态检测也只提供准备度证据;两者都不得作为授权依据或替代 Main/服务端的构建、包体校验和审核。 - 本地构建必须使用安装版 Electron Node、固定 npm 11.6.2 和项目 `package-lock.json` 锁定的 Vite,不得回退到全局 PATH、已有 `node_modules` 或未验证的 npm 闭包;依赖安装需要网络。 - 项目 Vite config/plugins 以桌面用户权限执行,不能称为 sandbox;此风险边界必须在发布说明中保留。 - AI Design 的 Current Specification 是唯一语义权威。Direction events 必须按 Workspace/Direction/revision/operation identity 收敛;assistant delta、event cursor、Task progress 和 Asset updates 不得改写 Living Form。 - AI Design 的用户交互以自然对话为主:先理解并复述用户已经说清楚的内容,再一次只推进一个关键问题。Current Specification 的客户端投影只作为“AI 已理解”的辅助摘要和可选手动调整面板;新增字段不得自动变成必填问题或选项卡表单。 - Design unknown-result replay 必须复用原 stable command 与 semantic operation ID;业务错误不得重复提交。Immutable Quote confirmation 只提交 Quote ID,Task recovery 不授权新的生成 intent。 - AI 绘画 Main-owned Workspace JSON 请求和共享 Works token refresh 必须在 30 秒内结束并释放共同等待者;只允许 `GET`/`HEAD`/`OPTIONS` 在 Electron transport 失败后透明改走 Node fetch,PATCH/POST 等 mutation 必须由具有显式幂等身份的上层协议决定是否重试。临时 `disable-http2` 只用于安装包诊断,不能替代该有限生命周期与非重放边界。 - 服务端 current Direction Session 与 semantic history 不由客户端在注销或退出时删除;Main 只关闭本地流、清除 drafts/pending state 和本机凭据。 - 客户端对最终构建字节的 loopback 检查没有可信 receipt,且不复刻生产 opaque-origin;服务端必须独立重算 source/built/contract、校验不可变 Release,人工审核仍不可绕过。如未来需要不可绕过的 runtime gate,必须引入可信 verifier 并绑定精确构建产物。 - Pi RPC confirmation timeout 是不确定性边界,不是释放 run permit、process ownership 或 Main background lease 的依据;accepted/uncertain mutation 不得自动重放,迟到 terminal 必须 exactly-once 收敛。隐藏/显示、abort、recover、replacement 与 app quit 都必须保留可解释 reason 并最终清零 ownership。 - Pi `0.84.2` 手动 compact 不发 `agent_settled`。只有 correlated compact RPC success 或权威 compaction failure 可以结束 compact;普通 prompt 仍需自己的 terminal/settled 语义,不能相互释放 lease。 - 本地 provider-shaped loopback 和单一 Agent Server 内 4 条重叠父逻辑线程 + 4 child process proof 证明客户端序列化、调度与隔离 seam,不证明真实 Provider 会并发、不会限流或正确隔离账号凭据。真实认证、endpoint/proxy/rate-limit、协议和图片差异仍为 `Explicitly Waived / Accepted Risk`,`realTurnVerified=false`。 - Provider/resource freshness 属于目标 Conversation logical-thread generation。idle stale 在下一 prompt 前重建,running stale 在 settled 后重建;同账号 refresh single-flight 且最多一次 reopen。确定性 Works user-context 缺失必须失效缓存凭据并 fail fast,不能触发无限 Pi 重试、自动 replay 或把 Provider 故障写成 runtime crash。 - AI Design 图片/视频引用必须以 typed Asset binding 写入 Specification,不能从本地化 quick reply、V1 Brief 或本地路径推断 action/purpose。 - Updater 源码错误提示不能代替发布正式签名产物;稳定 feed 缺 manifest 必须保持失败,Renderer 不得展示原始堆栈、URL、路径或错误码。升级链只有在旧版本完成发现、下载、重启和安装 smoke 后才可视为生产就绪。 ## Last Updated 2026-09-15