# Task: Implement MakeLore Plugin Platform P0 client ## Identity - Task ID: 20260827-makelore-plugin-client-7d3a91c4 - Mode: Feature - Branch: codex/20260827-makelore-plugin-client-7d3a91c4-makelore-plugin-client - Worktree: D:\Datas\OthersProjects\makelore-plugin-client-7d3a91c4 - Base commit: eb5d15d68470b30ec181164f08f0d7b027ef0006 - Owner: codex-root - Status: In Progress (ML-00 through ML-05 integrated; ML-06 frontier pending) ## Scope - Coordinate the repository-local `implement-spec` unit for ML-00 through ML-07 from exact accepted Data Service head `eb5d15d68470b30ec181164f08f0d7b027ef0006`. - Deliver the fixed bundled package, project selection, strict policy/capability registry and envelope, dynamic Pi Skill/tool materialization, Host/lifecycle integration, Plugin Center, packaged proof, verification, and fixed-range review. - Own only this isolated client branch, repository-local integration, project task record, client verification, and the client half of X-01 evidence. ## Intent And Constraints - Preserve accepted Data Service project identity, Main-owned credential and typed operation seams, exact-Origin preview lifecycle, SDK/Skill behavior, and Pi 0.84.2 hard-cutover contracts. - Keep package availability, local enablement, Agent Skill assignment, backend configuration, invocation, and billing policy independently observable. - P0 scans only fixed bundled roots and adds no arbitrary code/MCP/hooks, marketplace, download/update, generic invoke/config/ledger, Plugin Credits, `plugin_charges`, publication coupling, or external-browser capability. - Renderer cannot choose project authority, owner, credential, policy, price, or request identity; child workers receive no plugin Skills/tools. - All implementation tickets use exact-frontier isolated worktrees and one commit; implementers are not alone in the repository and must not revert other changes. - The user root `main` worktree is read-only. The user did not request publication; no PR is claimed unless one actually exists. ## Project Context Loaded - Task ID/mode/branch/worktree/base match the Git-common owner record exactly. - Read `AGENTS.md`, the mandatory project-memory entry set, active task record, positioning/current-state/decision/architecture/data-flow/domain/evidence/ reflection/commitment/stale material, the implementation spec, detailed-design sections 6-9 and 14-17, ticket graph, and the accepted Data Service client peer. - Other local owners: 149 including this task (12 planning, 137 ready for integration). The only same-topic peer is the completed Data Service coordinator whose exact evidence head is this task's base; it is not resumed or modified. - Overlap assessment: no unresolved semantic conflict. ML-01 through ML-05 have disjoint primary ownership and execute strictly in graph order; ML-02 waits for both ML-01 and the exact WS-02 catalog DTO. - Current integrated memory predates this unintegrated Data Service/plugin work; accepted branch/task evidence and the frozen spec control this feature branch. - Likely modules are the package/project-service, policy/capability registry, Pi resource/runtime, Host composition/lifecycle, Renderer Plugin Center, and packaged-proof paths named by the ticket graph. - Gate result: Passed on 2026-08-27. ## Ticket Ownership - ML-00, ML-06, and X-01 client evidence: coordinator in this worktree. - ML-01 through ML-05: isolated implementers from exact frontier commits, with ML-02 waiting for WS-02's catalog shape. - ML-07: fixed-range Standards/Spec reviewers; accepted findings go to one isolated remediation owner before repeat review. ## Outcome - ML-00 completed: the client coordination unit is isolated from exact accepted Data Service evidence head, ownership/planning gates passed, and no product file changed before the first implementation frontier. - Integrated ML-01 from replacement source commit `c092863ee600808e8a7c15440b3c370fd649a885` at the exact ML-00 frontier `2ab1c51a2404086cbd688ac80154765d7c5d4662` as coordinator product commit `422150d4fabdcc703952797875f88f239ca1e37a`, with no cherry-pick conflict. The superseded `f83038d371888cca87f0f04d0e61906d499668eb` was not cherry-picked. ML-01 adds the fixed bundled Data Service plugin manifest and capability projection, atomic project plugin selection service, package-owned Skill/SDK resource move, and core Skill registry projection. The coordinator foreign ML-01 task record is removed in the docs checkpoint while its source record remains in `D:\Datas\OthersProjects\makelore-plugin-ml01-package-selection-8d3c7a21`. The exact downstream product frontier handed to ML-02 is `422150d4fabdcc703952797875f88f239ca1e37a`. - Integrated ML-02 from source task `20260827-plugin-ml02-policy-registry-3f7b2c91` and sole source commit `0064043c8f1e0e80c0b73dd0064b3abe8ba30b01`, whose exact parent was the coordinator frontier `d9c9a2b0dd8fd495c6aa5a0994598192ad9c8e58`. The cherry-pick produced coordinator product commit `a0361a3cda08ab4d7454d35caa56a5a4304a9dca` without conflict. The foreign ML-02 task record was deleted from this coordinator while its source record remains in `D:\Datas\OthersProjects\makelore-plugin-ml02-policy-registry-3f7b2c91`. ML-02 consumes the frozen WS-02 catalog DTO: schema version 1, one `makelore.data-service` plugin, three capabilities/fourteen operations, and `platform_metered` unavailable projected as `billing_unavailable`. The coordinator-approved one-time ownership transfer covered only the `ToolDetails` envelope discriminator/display branch in `src/pages/Chat/CodingConversationTimeline.tsx`; no other Renderer, worker, Host, preview, or P1 path was transferred or changed. The exact downstream product frontier handed to ML-03 is `a0361a3cda08ab4d7454d35caa56a5a4304a9dca`. - Integrated ML-03 from source task `20260827-plugin-ml03-worker-materialization-9b2e6c41` and sole source commit `945d6bd81016eec373a82f63182cf1f7cf0718f5`, whose exact parent was the coordinator frontier `c4dd8923a0076920e8a7fd8820fdc01bdfde1760`. The cherry-pick produced coordinator product commit `fd891ff3bb87a29381a0a7006fb4618ec4fe144f` without conflict. The foreign ML-03 task record was deleted from this coordinator while its source record remains in `D:\Datas\OthersProjects\makelore-plugin-ml03-worker-materialization-9b2e6c41`. ML-03 owns exactly six Pi product files and five Pi-focused tests: one frozen effective worker-resource snapshot, dynamic Skill/declaration/bridge/CLI materialization, child-empty exposure, known-disabled/re-enabled assignment behavior, old-worker refusal, and removal of the static Data Service worker list. The source task execution briefly shared a worktree with an earlier agent; that agent was interrupted when discovered, and the final commit was then fully reviewed by serial takeover. This record does not claim that the source task was never concurrently shared. The exact downstream product frontier handed to ML-04 is `fd891ff3bb87a29381a0a7006fb4618ec4fe144f`. ## Verification - `git rev-parse HEAD` before the checkpoint returned exact `eb5d15d68470b30ec181164f08f0d7b027ef0006`. - The fresh worktree initially had no `node_modules`, so the first typecheck failed only because `tsc` was unavailable. `corepack pnpm install --frozen-lockfile` installed the locked 997-package graph with pnpm `10.33.4`; no source or lockfile changed. - `corepack pnpm run typecheck` then passed. - The nine-file Data Service/Pi/package baseline (`data-service-sdk-assets`, `data-service-server-registration`, `pi-product-tools`, `pi-extension-host`, `pi-worker-process-real`, `coding-conversation-contracts`, `preview-data-session`, `data-service-routes`, and `pi-product-artifact`) passed `70 passed, 2 skipped` in 10.21s with one worker. - No client product file changed; only this task-scoped record is committed by ML-00. The root `main` worktree was restored clean at `f245603...` after an initial task-context claim selected the clean root despite isolation arguments; the generated record/claim were removed through the normal release path before the successful isolated start from `eb5d15d...`. - ML-01 precondition and merge: coordinator was clean at exact frontier `2ab1c51a2404086cbd688ac80154765d7c5d4662`; replacement source parent matched exactly; cherry-pick produced `422150d4fabdcc703952797875f88f239ca1e37a` without conflict. - ML-01 focused verification: `corepack pnpm exec vitest run tests/unit/data-service-sdk-assets.test.ts tests/unit/coding-plugin-manifest.test.ts tests/unit/project-plugin-service.test.ts tests/unit/skill-display.test.ts tests/unit/pi-product-tools.test.ts --maxWorkers=1` — 5 files / 45 tests passed (Vitest 3.15s). - ML-01 `corepack pnpm run typecheck` — passed. - ML-01 `corepack pnpm run lint:check` — passed with 0 errors and the same 5 pre-existing warnings in `src/pages/Home/index.tsx` and `src/pages/Makelore/index.tsx`. - Scoped ESLint over ML-01-owned source/tests — passed with no output. - The Skill and SDK resource move is byte-for-byte (`R100`). The ML-01-owned `tests/unit/data-service-sdk-assets.test.ts` assertion now targets the canonical package path and passed; this merger did not edit unrelated tests. Any remaining consumer of the removed legacy `resources/coding-skills/data-service` path must migrate under its owning ticket, not this merger. - ML-01 path/scope audit matched the source change set: package manifest/service, existing Skill registry/shared definitions, plugin resources, and focused tests only. No P1 policy/capability-invoke, Pi runtime, Host, Renderer, marketplace/download/update, generic execution, pricing, or billing paths were added. `git diff --check` passed. - ML-02 precondition and merge: coordinator was clean at exact frontier `d9c9a2b0dd8fd495c6aa5a0994598192ad9c8e58`; source commit `0064043c8f1e0e80c0b73dd0064b3abe8ba30b01` had that exact parent and cherry-picked without conflict as `a0361a3cda08ab4d7454d35caa56a5a4304a9dca`. The source change set was limited to the policy client, capability registry/Data Service adapter, Pi product-tool delegation, bounded shared contracts, focused tests, and the one approved timeline branch. No other Renderer, worker, Host, preview, or P1 file was present; the source task record remains in its worktree. - ML-02 focused verification: `corepack pnpm exec vitest run tests/unit/plugin-policy-client.test.ts tests/unit/coding-capability-registry.test.ts tests/unit/data-service-plugin-adapter.test.ts tests/unit/pi-product-tools.test.ts tests/unit/coding-conversation-contracts.test.ts --maxWorkers=1` — 5 files / 38 tests passed (Vitest 3.26s). - Transferred timeline verification: `corepack pnpm exec vitest run tests/unit/coding-conversation-timeline.test.tsx --maxWorkers=1` — 1 file / 4 tests passed (Vitest 1.65s). - Relevant adjacent regressions: `coding-plugin-manifest`, `project-plugin-service`, `skill-display`, `coding-chat-panel`, `coding-product-services`, `coding-product-tools-facade`, `data-service-client`, and `data-service-routes` — 8 files / 57 tests passed (Vitest 9.69s, one worker). - `corepack pnpm run typecheck` — passed. `corepack pnpm run lint:check` — passed with 0 errors and the same 5 pre-existing warnings in `src/pages/Home/index.tsx` and `src/pages/Makelore/index.tsx`. - Product contract audit passed: no `details.schema === 'data-service.v1'` consumer remains; every `data-service.v1` occurrence in `src/`, `electron/`, `shared/`, and `tests/` is the nested `payload_schema` contract. The ML-02 net change passed `git diff --check`. - ML-03 precondition and merge: coordinator was clean at exact frontier `c4dd8923a0076920e8a7fd8820fdc01bdfde1760`; source commit `945d6bd81016eec373a82f63182cf1f7cf0718f5` had that exact parent and cherry-picked without conflict as `fd891ff3bb87a29381a0a7006fb4618ec4fe144f`. The merged change set contains exactly six Pi product files and five named Pi tests, with no other Host, Renderer, registry, preview, or P1 path; the source task record remains in its worktree. The source execution's brief shared-worktree incident and interruption were retained accurately; the merger's review and verification were performed serially after takeover. - ML-03 owned focused verification: `corepack pnpm exec vitest run tests/unit/pi-resource-loader.test.ts tests/unit/pi-extension-host.test.ts tests/unit/pi-extension-bundle.test.ts tests/unit/pi-worker-process-real.test.ts tests/unit/pi-rpc-foundation.test.ts --maxWorkers=1` — 5 files / 43 passed / 2 skipped (Vitest 7.65s; the skips are staged-runtime gated). - All Pi regressions: `pi-*.test.ts` — 30 files / 169 passed / 2 skipped (Vitest 19.34s, one worker). - `corepack pnpm run typecheck` — passed. `corepack pnpm run lint:check` — passed with 0 errors and the same 5 pre-existing warnings in `src/pages/Home/index.tsx` and `src/pages/Makelore/index.tsx`. - `corepack pnpm run build:vite` — passed for Renderer, Main, Preload, and utility bundles; only existing dynamic-import/chunk-size warnings were emitted. The ML-03 changed files contain no static Data Service worker list; dynamic declarations, bridge allowlisting, CLI agreement, child-empty exposure, disabled/re-enabled assignment, and old-worker behavior are covered by the owned focused suite. `git diff --check` passed. - ML-04 precondition and merge: coordinator was clean at exact frontier `a92cd904d33d4fa0b7c2413188186852a39eb6d4`; source commit `1e925bc10ade8aed1a580362dfa65223993e3a24` had that exact parent and cherry-picked without conflict as `a18727ecf8f40c1d85e2d40922bcf3bc8d1a0ed3`. The product change set contains four Main API files (`coding-composition`, `coding-product-services`, `route-handlers`, and `routes/coding-plugins`), three new focused tests, and one existing Data Service server-registration test update. There are no changes to `project-service`, preview, Renderer, P1, `electron/api/context.ts`, `electron/api/server.ts`, or `electron/main/index.ts`; the source task record remains in its worktree. - ML-04 focused verification: `corepack pnpm exec vitest run tests/unit/coding-plugin-routes.test.ts tests/unit/coding-plugin-composition.test.ts tests/unit/coding-plugin-lifecycle.test.ts tests/unit/coding-product-services.test.ts tests/unit/data-service-server-registration.test.ts tests/unit/coding-core-routes.test.ts tests/unit/coding-project-identity.test.ts tests/unit/main-quit-lifecycle.test.ts --maxWorkers=1` — 8 files / 47 tests passed (Vitest 4.73s). The route tests confirm exact GET `/api/coding/plugins?projectId=...` and PUT `/api/coding/plugins/{plugin_id}` bodies with Main-only authority; composition/lifecycle tests cover bounded projection and `list`/`setEnabled`/`deactivate` wiring. - ML-04 adjacent policy/capability/Data Service/Pi/preview regressions: `coding-capability-registry`, `plugin-policy-client`, `data-service-plugin-adapter`, `coding-conversation-contracts`, `pi-product-tools`, `data-service-routes`, `data-service-sdk-assets`, `pi-extension-bundle`, `pi-extension-host`, `pi-resource-loader`, `preview-data-session`, and `pi-worker-process-real` — 12 files / 86 passed / 2 skipped (Vitest 8.37s, one worker; skips are staged-runtime gated). - `corepack pnpm run typecheck` — passed. `corepack pnpm run lint:check` — passed with 0 errors and the same 5 pre-existing warnings in `src/pages/Home/index.tsx` and `src/pages/Makelore/index.tsx`. - `corepack pnpm run build:vite` — passed for Renderer, Main, Preload, and utility bundles; only existing dynamic-import/chunk-size warnings were emitted. `git diff --check` passed. ## ML-05 Integration - Integrated ML-05 from source task `20260827-plugin-ml05-plugin-center-6c1e9a42` and sole source commit `379e575efba8cecb17b10e5e195f05924b827782`, whose exact parent was the coordinator frontier `b6d9e6156fdc98aa792045692cc25fdce993a531`. The cherry-pick produced coordinator product commit `cb1fd2629ce861f72eada35a83e730986fb1c3d1` without conflict. The source commit contained its source task record plus fourteen Renderer/product-test files; the foreign task record was deleted from this coordinator in this checkpoint while the source record remains in `D:\Datas\OthersProjects\makelore-plugin-ml05-plugin-center-6c1e9a42`. ML-05 adds the project-scoped Plugin Center, typed project-plugin client/store, Data Service settings surface, and project navigation. It does not add Main authority, worker, preview, policy, marketplace, or P1 behavior. The exact downstream product frontier handed to ML-06 is the post-merge docs checkpoint recorded below. - ML-05 focused regression command (using the repository's actual singular `coding-plugin-routes.test.ts` filename) passed 13 files / 75 tests in 8.64s with one worker. `corepack pnpm run typecheck` passed. `corepack pnpm run lint:check` passed with 0 errors and the same 5 pre-existing warnings in `src/pages/Home/index.tsx` and `src/pages/Makelore/index.tsx`. - `corepack pnpm run build:vite` passed for Renderer, Main, Preload, and utility bundles with only existing dynamic-import/chunk-size warnings. After this required build, `corepack pnpm exec playwright test tests/e2e/project-plugins.spec.ts --config=playwright.config.ts` passed 1/1 test in 1.7s. A preliminary direct Playwright invocation against stale `dist-electron` timed out waiting for the new navigation test id; it is not counted as a product failure because the repository E2E contract builds first. ## Follow-ups - ML-06 is the coordinator-owned packaged-proof frontier from the exact post-ML-05 product/docs checkpoint; it may edit only the Pi artifact proof library, verifier, and focused test named by the ticket. It must prove the bundled plugin manifest, Skill, SDK assets, adapter/tool catalog, and core resources without restoring a static Data Service list or adding checksums, arbitrary execution, generic config/ledger/invoke, publication, or P1 scope. - The legacy `resources/coding-skills/data-service` path is intentionally removed by ML-01; any unowned downstream reference must be migrated by its owning ticket. This merger made no such downstream edit. ## Promotion Candidates - None recorded.