# Task: Implement MakeLore Development Data Service P0 client ## Identity - Task ID: 20260826-makelore-data-service-client-b72e4c19 - Mode: Feature - Branch: codex/20260826-makelore-data-service-client-b72e4c19-makelore-data-service-client - Worktree: D:\Datas\OthersProjects\makelore-data-service-client-b72e4c19 - Base commit: f2456039230f68e3ecb2c8653fc3379c23bbe5ce - Owner: codex-root - Status: In Progress (implementation, review, and X-01 complete; draft PR publication externally blocked) ## Scope - Coordinate the repository-local `implement-spec` run for client tickets ML-00 through ML-09 from post-Pi-integration base `f2456039230f68e3ecb2c8653fc3379c23bbe5ce`. - Deliver durable MakeLore project identity, Main-owned Data Service cloud/Host operations, purpose-specific Pi tools, preview data sessions and CDP injection, the thin generated SDK, bundled Data Service Skill, focused/full verification, repository-local review, and one remediation pass when findings require it. - Own the client implementation branch and merge only commits returned by isolated ticket worktrees in dependency order. ## Intent And Constraints - Follow the server repository's implementation specification, ticket graph, canonical integration contract, and accepted ADR without reopening the frozen P0 product scope. - Preserve the integrated Pi `0.84.2` hard cutover, product-neutral Snapshot/Patch contracts, Main/Renderer trust boundary, current Host route ordering, and the existing Agent Browser abstraction. - `.niancode/project.json` owns the durable optional `projectId`; local project IDs, Pi session/resource IDs, and the `opencode-projects` compatibility store name remain local identities. - Electron Main remains the only Works credential owner. Generated code receives only an ephemeral exact-Origin data capability; no credential, owner, path, arbitrary endpoint, or cloud project ID becomes a model-controlled input. - Do not restore OpenCode, add Firebase compatibility, published-runtime support, retries for ambiguous writes, a filesystem-copy engine, or a generic operation multiplexer. - The root `main` worktree remains clean and unowned. All writes stay in this isolated coordinator worktree or ticket-specific linked worktrees. ## Planning Gate - Result: Passed on 2026-08-26. - Loaded MakeLore `AGENTS.md`, required project-memory entry documents, current state, accepted auth and Pi decisions, relevant architecture/domain/evidence/commitment material, the cross-repository Data Service spec/graph/contract, and the exact Pi, Host API, project-storage, session, and Agent Browser seams at the recorded base. - Registry review found 147 historical owners. Most are ready-for-integration and represented in the selected base. Ten remain marked planning; nine have placeholder scopes and therefore unknown coordination state, while one owns an unrelated AI Design E2E file. No declared Data Service or owned-path semantic conflict exists. - Real PostgreSQL, signed-in accounts, deployment inputs, and platform-specific E2E prerequisites remain external acceptance inputs and will not be inferred as passed. ## Ticket Ownership - ML-00: coordinator in this worktree. - ML-01 through ML-07: isolated implementer worktrees from the exact merged frontier commit, with the file ownership defined by the ticket graph. - ML-08: repository-local merger in this implementation worktree. - ML-09: read-only review followed by one isolated remediation implementer if needed. - X-01: coordinated only after reviewed server and client branches are ready. ## Outcome - Integrated ML-01 project identity from the exact integration frontier `7e54b8fbda1899b73334d7c3e732ce8e73460ed8` with no cherry-pick conflict. Implementer commit `274172ac9d7ea2468242448d4b0b19fd2205f8fb` was cherry-picked as feature commit `43f58fc` (`feat(coding): add durable project identity core`). The delivered scope is limited to identity core, coding-project Host routes/composition and callback wiring, release-proof fixtures, and focused tests. The implementer task record was removed from this coordinator's net diff; the source worktree retains its own record. - Integrated ML-02 identity UX from the exact ML-01 frontier `5ac08d509f8962a3c2c0ec1b1afef84a435f116d` with no cherry-pick conflict. Implementer commit `363660a81b3f79ffab4594763170932790f41299` was cherry-picked as feature commit `ce8e210` (`feat(coding): add project identity UX`). The delivered scope is limited to the Sidebar and Project Configuration identity controls, Renderer facade/store projections, focused tests, and identity E2E; no Main, cloud, session, or provisioning logic was added. The foreign ML-02 task record was deleted from this coordinator's net diff after cherry-pick; the source worktree retains its own record. - Integrated ML-03 Main Data Service from the exact ML-02 frontier `003fe210f49de37c7ddf49cf10acde38705bf8c3` with no cherry-pick conflict. Implementer commit `10d8132cc34f1a69fafdd9e9f7ff3693888fc3fc` was cherry-picked as feature commit `c19227a` (`feat(coding): add Main Data Service Host adapter`). The delivered scope is limited to the Main-owned cloud client, shared safe DTOs, `DataServiceOperations` coding composition, fixed `/api/works/data-service` Host routes, route precedence before the Works catch-all, and focused tests; no preview/Pi/Renderer credential or unrelated transport logic was added. The foreign ML-03 task record was deleted from this coordinator after cherry-pick; the source worktree retains its own record. The ML-04 frontier is this integrated commit plus the coordinator's cleanup/record commit. - Applied the ML-03 post-merge correctness correction from source commit `0ecceef15d2e43190f835fd71a7a1478222f1ba8` onto coordinator frontier `e15d8b7f51bea6b56558c981964082a4e76e523c`. The expected modify/delete conflict was limited to the already-removed foreign ML-03 task record; it was kept deleted, and the correction cherry-picked as feature commit `6b36753` (`fix(coding): reject mismatched Data Service errors`). The Main client now rejects known error codes paired with undocumented HTTP statuses as `upstream_invalid_response`, with one focused regression test. The ML-04 frontier is `6b36753` plus this coordinator record commit. - Integrated ML-04 from source commits `e4fdeaea02cab216f4e7ff4543d57ca9e2aab33b` and `93609d5890b6be4c51c083125d3d8ab7ebd3d02d` in the requested order as coordinator commits `1d63233cd03425e9158b9c4868b3cfc0e508bc6f` and `f61990f3a7f5ea417ca3eecc6702e71398f77d7f`. Git auto-merged the known `data-service-client.ts` overlap without a conflict; the ML-03 `ERROR_STATUS_BY_CODE` ↔ HTTP-status validation remains alongside the ML-04 trusted `projectPath` authority seam. The ten parent-only underscore tools, closed inputs, shared in-process `DataServiceOperations`, safe details and literal confirmation behavior are retained. The foreign ML-04 task record was removed from this coordinator after both cherry-picks; the source record remains in `D:\Datas\OthersProjects\makelore-ml04-pi-data-tools-8d3c91a7`. The ML-04 frontier is `f61990f3a7f5ea417ca3eecc6702e71398f77d7f` plus this coordinator cleanup/record commit. - Integrated ML-05 from source commit `080b8801d29274b506700f94391339d98fb7aa0d` at the exact ML-04 frontier `bec67082b3dade05e900911c13ad804e781309f6` as coordinator commit `e842dd4` (`feat(coding): add preview data runtime session`), with no cherry-pick conflict. The delivered scope is limited to the Main-owned ephemeral preview session manager, exact `/api/runtime/data/v1` data-only routes, early route precedence, trusted Data Service forwarding, lifecycle invalidation wiring, and focused loopback coverage; ML-06 pre-document injection was not included. The foreign ML-05 task record was removed from this coordinator after cherry-pick; the source record remains in `D:\Datas\OthersProjects\makelore-ml05-preview-data-session-5c8e2a71`. The ML-06 frontier is `e842dd4` plus this coordinator cleanup/record commit. - Integrated ML-06 from source commit `992a0a68d743f766f19bc34c245adca4431ba321` at the exact ML-05 frontier `14fec701086f60d78466b8e1cc3fb57ca8d7e200` as coordinator commit `38d63a9` (`feat(agent-browser): add opt-in preview data injection`), with no cherry-pick conflict. The delivered scope is limited to the explicit Agent Browser preview-data opt-in, exact-Origin CDP pre-document script lifecycle, child-session tracking/cleanup, and Main/session invalidation wiring; the ordinary arbitrary-URL path remains data-free and no second BrowserWindow or preload was added. The foreign ML-06 task record was removed from this coordinator after cherry-pick; the source record remains in `D:\Datas\OthersProjects\makelore-ml06-agent-browser-injection-2c7e91a4`. The ML-07 frontier is `38d63a9` plus this coordinator cleanup/record commit. - Integrated ML-07 from source commit `d22ceef104b4f95e7a35888875dcb1c18245c190` at the exact ML-06 frontier `552c6162a57894b713ea1f47d356fa48c0fc0cf1` as coordinator commit `549069d` (`feat(coding): add generated Data Service SDK skill`), with no cherry-pick conflict. The delivered scope is limited to the bundled Data Service Skill, canonical TypeScript/JavaScript SDK assets, existing skill registry/display registration, and focused SDK/install/workflow tests. The source commit and coordinator range contain no root `task_plan.md`, `findings.md`, or `progress.md` scratch files. The foreign ML-07 task record was removed from this coordinator after cherry-pick; the source record remains in `D:\Datas\OthersProjects\makelore-ml07-data-service-sdk-skill-6b4e91c2`. The ML-08 frontier is `549069d` plus this coordinator cleanup/record commit. - Completed ML-08 merge-and-verify on the exact clean product frontier `a981b07faaa64b20bf9aef6353218fef26695ca2`, with fixed client base `f2456039230f68e3ecb2c8653fc3379c23bbe5ce`. ML-01 through ML-07 are present in dependency order through that product HEAD; this step made no product changes. The five required verification commands and their one known E2E failure are recorded below. The product HEAD immediately before this documentation update was `a981b07faaa64b20bf9aef6353218fef26695ca2`. - Integrated ML-09 remediation source commit `b5060f254bfdb3a748739b74b1f583cc0236fa7c` from its exact parent `239e20d2cf2242d636f9d42684f76f5777d9d1ee` as coordinator product commit `38843e091fbbe68ec934336b8ed3a08c955afb28`, with no cherry-pick conflict. The eight accepted review findings are all represented in the coordinator: normal Pi parent Data Service allowlisting; camelCase Skill input; credential-free HTTP/HTTPS loopback Origins; browser-generation lifecycle fencing; README/Skill workflow documentation; narrow shared route parsers; removal of the unused Agent Browser `onLifecycle` option; and removal of the unused `handleDataServiceRoute` alias. The foreign ML-09 task record was deleted from this coordinator while its source record remains in `D:\Datas\OthersProjects\makelore-ml09-data-service-remediation-5e7c2a91`. The product frontier after this merge is `38843e091fbbe68ec934336b8ed3a08c955afb28`. - Final ML-09 repository-local review is complete over the fixed client review range `f2456039230f68e3ecb2c8653fc3379c23bbe5ce` → `bb832c66660d993baa6147cf058078a5cd89fcb2`. Standards: PASS. Spec: PASS. ML-00 through ML-09 product delivery, review, and the single remediation pass are complete; this conclusion does not claim the external X-01 live acceptance. ## Verification - `pnpm exec vitest run tests/unit/coding-project-identity.test.ts tests/unit/coding-projects-migration.test.ts tests/unit/coding-core-routes.test.ts tests/unit/coding-projects-schema-v2.test.ts`: 4 files / 48 tests passed. - `pnpm typecheck`: passed. - `pnpm lint:check`: passed with 0 errors and 5 pre-existing warnings in `src/pages/Home/index.tsx` and `src/pages/Makelore/index.tsx`; none are in the ML-01 paths. - `git diff --check`: passed. - Cherry-pick parent, coordinator branch, and required integration frontier were verified against `7e54b8fbda1899b73334d7c3e732ce8e73460ed8` before integration; the cherry-pick completed without conflicts. - ML-02 focused Renderer tests: `pnpm exec vitest run tests/unit/coding-projects-facade.test.ts tests/unit/project-config-store.test.ts tests/unit/coding-workspace-store.test.ts --maxWorkers=1`: 3 files / 10 tests passed. - `pnpm build:vite`: passed; generated the Main/Preload bundles required by the Electron fixture. - `pnpm test:electron:windows`: 2 files / 4 tests passed. - `pnpm exec playwright test tests/e2e/coding-project-identity.spec.ts --config=playwright.config.ts`: 2 tests passed after the Vite build. - `pnpm exec playwright test tests/e2e/project-configuration-skills.spec.ts --config=playwright.config.ts`: 1 test passed. - `pnpm typecheck`: passed. - `pnpm lint:check`: passed with 0 errors and 5 pre-existing warnings in `src/pages/Home/index.tsx` and `src/pages/Makelore/index.tsx`; none are in the ML-02 paths. - `git diff --check`: passed; the net ML-02 path audit contains only Renderer UI/facade/store and tests, with no `electron/`, `resources/`, or `scripts/` files. - Implementer-provided broader results (not rerun by this merger): `pnpm test` passed with 183 files / 1554 tests and 2 skipped; the full E2E run passed 25 tests and reproduced one pre-existing PI model-combobox failure at `tests/e2e/pi-coding-first-chat.spec.ts:575` on its direct rerun. This unrelated failure remains visible and is not masked by the focused passes. - ML-03 focused tests: `pnpm exec vitest run tests/unit/data-service-client.test.ts tests/unit/data-service-routes.test.ts tests/unit/data-service-server-registration.test.ts --maxWorkers=1` — 3 files / 17 tests passed. - ML-03 regression tests: `pnpm exec vitest run tests/unit/coding-core-routes.test.ts tests/unit/coding-project-identity.test.ts tests/unit/host-api-proxy.test.ts tests/unit/works-routes.test.ts --maxWorkers=1` — 4 files / 82 tests passed. - `pnpm typecheck`: passed. - `pnpm lint:check`: passed with 0 errors and the same 5 existing warnings in `src/pages/Home/index.tsx` and `src/pages/Makelore/index.tsx`. - `git diff --check`: passed. - Coordinator branch, clean state, exact ML-02 HEAD, and ML-03 commit parent were verified before integration; cherry-pick completed without conflicts. - ML-03 correction focused tests: the same 3-file command passed 18 tests after integrating `6b36753`. - ML-03 correction `pnpm typecheck`: passed. - ML-03 correction `pnpm lint:check`: passed with 0 errors and the same 5 existing warnings in `src/pages/Home/index.tsx` and `src/pages/Makelore/index.tsx`. - ML-03 correction `git diff --check`: passed. - Correction cherry-pick was applied from the exact `e15d8b7` coordinator frontier; only the expected foreign task-record modify/delete conflict occurred, and the source record remains in the source worktree. - The coordinator already had this task's Git-common ownership in feature mode under `codex-root`; the required integration-mode resume was rejected by the task gate, so the same task was resumed in its existing feature mode without changing ownership, branch, or worktree. - ML-04 Pi focused suite: `pnpm exec vitest run tests/unit/pi-product-tools.test.ts tests/unit/pi-extension-bundle.test.ts tests/unit/pi-extension-host.test.ts --maxWorkers=1` — 3 files / 23 tests passed. - ML-04 Data Service/projector + Pi focused suite: `pnpm exec vitest run tests/unit/data-service-client.test.ts tests/unit/data-service-routes.test.ts tests/unit/data-service-server-registration.test.ts tests/unit/coding-conversation-contracts.test.ts tests/unit/coding-conversation-timeline.test.tsx tests/unit/coding-product-tools-facade.test.ts tests/unit/pi-extension-ui-projector.test.ts tests/unit/pi-product-tools.test.ts tests/unit/pi-extension-bundle.test.ts tests/unit/pi-extension-host.test.ts --maxWorkers=1` — 10 files / 62 tests passed. - ML-04 `pnpm typecheck`: passed. - ML-04 `pnpm lint:check`: passed with 0 errors and the same 5 pre-existing warnings in `src/pages/Home/index.tsx` and `src/pages/Makelore/index.tsx`. - ML-04 `git diff --check`: passed after the foreign task-record cleanup. - ML-05 source focused/loopback suite: `pnpm exec vitest run tests/unit/preview-data-session.test.ts tests/unit/data-service-routes.test.ts tests/unit/coding-core-routes.test.ts tests/unit/agent-browser-core.test.ts tests/unit/coding-attachments-routes.test.ts --maxWorkers=1` — 5 files / 107 tests passed. - ML-05 adjacent Data Service/client regressions: `pnpm exec vitest run tests/unit/data-service-client.test.ts tests/unit/data-service-routes.test.ts tests/unit/data-service-server-registration.test.ts tests/unit/coding-conversation-contracts.test.ts tests/unit/coding-conversation-timeline.test.tsx tests/unit/coding-product-tools-facade.test.ts tests/unit/pi-extension-ui-projector.test.ts tests/unit/pi-product-tools.test.ts tests/unit/pi-extension-bundle.test.ts tests/unit/pi-extension-host.test.ts --maxWorkers=1` — 10 files / 62 tests passed. - ML-05 `pnpm typecheck`: passed. - ML-05 `pnpm lint:check`: passed with 0 errors and the same 5 pre-existing warnings in `src/pages/Home/index.tsx` and `src/pages/Makelore/index.tsx`. - ML-05 `pnpm build`: passed Vite, Electron, Pi runtime, and Windows NSIS packaging; the existing dynamic-import/chunk, optional dependency, and absent optional packaged-resource warnings remained visible. - ML-05 `pnpm test:electron:windows`: 2 files / 4 tests passed. - ML-05 `git diff --check`: passed; the only coordinator deletion is the foreign ML-05 task record, and the source worktree retains it. - ML-05 exclusion scan over the merged diff found no `injectProjectData`, `__MAKELORE_DATA__`, `Page.addScriptToEvaluateOnNewDocument`, script-ID tracking, or navigation injection markers. - ML-06 was integrated from source commit `992a0a68d743f766f19bc34c245adca4431ba321` at the exact ML-05 frontier `14fec701086f60d78466b8e1cc3fb57ca8d7e200` as coordinator commit `38d63a9` (`feat(agent-browser): add opt-in preview data injection`), with no cherry-pick conflict. The change adds only the explicit Agent Browser preview-data opt-in, exact-Origin CDP pre-document script lifecycle, child-session tracking/cleanup, and Main/session invalidation wiring. The foreign ML-06 task record was removed from this coordinator after cherry-pick; the source record remains in `D:\Datas\OthersProjects\makelore-ml06-agent-browser-injection-2c7e91a4`. The ML-07 frontier is `38d63a9` plus this coordinator cleanup/record commit. - ML-06 focused Vitest: `pnpm exec vitest run tests/unit/agent-browser-core.test.ts tests/unit/agent-browser-routes.test.ts tests/unit/pi-product-tools.test.ts tests/unit/coding-core-routes.test.ts --maxWorkers=1` — 4 files / 122 tests passed. - ML-05 preview regressions after ML-06: `pnpm exec vitest run tests/unit/preview-data-session.test.ts tests/unit/data-service-routes.test.ts tests/unit/coding-core-routes.test.ts tests/unit/agent-browser-core.test.ts tests/unit/coding-attachments-routes.test.ts --maxWorkers=1` — 5 files / 120 tests passed. - ML-06 `pnpm test:electron:windows`: 2 files / 4 tests passed. - ML-06 `pnpm typecheck`: passed. - ML-06 `pnpm lint:check`: passed with 0 errors and the same 5 pre-existing warnings in `src/pages/Home/index.tsx` and `src/pages/Makelore/index.tsx`. - ML-06 `pnpm build:vite`: passed for renderer, Main, preload, and utility worker; existing dynamic-import and large-chunk warnings remained visible. - ML-06 full E2E `pnpm test:e2e`: 25 tests passed and 1 existing test failed at `tests/e2e/pi-coding-first-chat.spec.ts:575` because the `当前对话模型` combobox remained disabled until timeout. A direct rerun of that test reproduced the same timeout; this is not an ML-06 injection path and is not counted as an E2E pass. - ML-06 boundary checks passed: no new `BrowserWindow` or preload was added, the ordinary arbitrary-URL path remains data-free, and the expected changed path list contains only Agent Browser/session wiring, route/Pi propagation, focused tests, and the task record. - ML-06 `git diff --check`: passed after foreign task-record cleanup. - ML-07 focused SDK/Skill assets: `pnpm exec vitest run tests/unit/data-service-sdk-assets.test.ts --maxWorkers=1` — after normalizing coordinator checkout line endings to the source's canonical LF bytes, 1 file / 14 tests passed. The initial checkout run had 13 passed and 1 frontmatter assertion failure caused solely by CRLF; the normalized working files hash exactly to their committed blobs. - ML-07 adjacent registry/display/resource/Pi suite: `pnpm exec vitest run tests/unit/data-service-sdk-assets.test.ts tests/unit/skill-display.test.ts tests/unit/pi-resource-loader.test.ts tests/unit/pi-product-tools.test.ts --maxWorkers=1` — 4 files / 34 tests passed. Packaged resource listing includes `SKILL.md`, `assets/`, `assets/makelore-data.ts`, and `assets/makelore-data.js`. - ML-07 full unit verification: the normal parallel runner had 1 Vitest fork worker exit unexpectedly after 187/188 files and 1606 passed tests (2 skipped), with no assertion failure. The serial rerun `pnpm exec vitest run --exclude tests/unit/coding-chat-pressure.test.tsx --maxWorkers=1` passed 188 files / 1610 tests with 2 skipped, followed by `pnpm exec vitest run tests/unit/coding-chat-pressure.test.tsx --maxWorkers=1` — 1 test passed. - ML-07 `pnpm typecheck`: passed. - ML-07 `pnpm lint:check`: passed with 0 errors and the same 5 pre-existing warnings in `src/pages/Home/index.tsx` and `src/pages/Makelore/index.tsx`. - ML-07 `pnpm build`: passed Vite, Electron, Pi runtime, and Windows NSIS packaging; existing dynamic-import/chunk, optional dependency, and absent optional packaged-resource warnings remained visible. - ML-07 `pnpm test:electron:windows`: 2 files / 4 tests passed. - ML-07 affected E2E: `pnpm exec playwright test tests/e2e/project-configuration-skills.spec.ts --config=playwright.config.ts` — 1 test passed. - ML-07 SDK static boundary checks found no cloud credential, external URL, retry call, cache/offline storage, Firebase, or Works Square behavior; the only Authorization/Bearer use is the injected local preview token required by the contract. Skill checks confirmed inspect → explicit `data_service_configure` → `agent_browser` → read-back → report ordering and the exact-copy/no-op/conflict policy. - ML-07 root-scratch and boundary scans passed; changed paths are limited to the Data Service skill assets, registry/display registration, focused tests, and the task record. `git diff --check` passed after foreign task-record cleanup. - ML-08 precondition: coordinator branch was clean at product HEAD `a981b07faaa64b20bf9aef6353218fef26695ca2`, based on `f2456039230f68e3ecb2c8653fc3379c23bbe5ce`; no product file was changed by this verification step. - ML-08 command ledger (run in this coordinator worktree): `pnpm typecheck` — exit 0, passed, approximately 5.32s. - `pnpm lint:check` — exit 0, passed with 0 errors and the same 5 existing warnings in `src/pages/Home/index.tsx` and `src/pages/Makelore/index.tsx`, approximately 10.01s. - `pnpm test` — exit 0, passed; main suite 188 files / 1610 tests passed / 2 skipped (Vitest-reported 42.86s), followed by the pressure suite 1 file / 1 test passed (1.77s). No assertion failure or worker exit occurred. - `pnpm test:electron:windows` — exit 0, passed; 2 files / 4 tests passed (Vitest-reported 1.02s; command approximately 2.34s). - `pnpm test:e2e` — exit 1; its required `build:vite` phases completed successfully, then Playwright ran 26 tests with 25 passed and 1 failed. The failure is the known `tests/e2e/pi-coding-first-chat.spec.ts:575` `locator.selectOption` 30s timeout because combobox `当前对话模型` remained disabled; this is not an E2E pass and remains a release/acceptance deviation. Playwright reported approximately 1.0m for the run. The build emitted only existing dynamic-import and chunk-size warnings. - ML-08 post-command hygiene: `git diff --check` passed; the first drift invocation was unavailable because `python` is not on the PowerShell PATH, then the same `check_doc_drift.py --task-id 20260826-makelore-data-service-client-b72e4c19` check passed using the configured bundled Python runtime. Test/build output remained ignored and the worktree was clean before this task-record update. - ML-09 precondition: coordinator was clean at exact ML-08 HEAD `239e20d2cf2242d636f9d42684f76f5777d9d1ee`; the remediation source parent matched that HEAD exactly and cherry-pick produced product commit `38843e091fbbe68ec934336b8ed3a08c955afb28`. - ML-09 focused remediation ledger: the 10-file equivalent set (`data-service-sdk-assets`, `data-service-server-registration`, `pi-rpc-foundation`, `pi-worker-process-real`, `preview-data-session`, `agent-browser-core`, `agent-browser-routes`, `data-service-routes`, `pi-extension-bundle`, and `pi-extension-ui-projector`) passed with 142 tests and 2 skipped; Vitest reported 16.45s. - ML-09 adjacent regressions covering tool profile, Data Service client/routes, preview/browser adapter, Skill resource, and Pi host paths: 8 files / 77 tests passed; Vitest reported 6.75s. - ML-09 `pnpm typecheck`: exit 0, passed, approximately 5.31s. - ML-09 `pnpm lint:check`: exit 0, passed with 0 errors and the same 5 existing warnings in `src/pages/Home/index.tsx` and `src/pages/Makelore/index.tsx`. - ML-09 `pnpm build`: exit 0, passed through Vite, staged Pi runtime, and Windows Electron/NSIS packaging. Existing dynamic-import/chunk-size, optional-resource, npm shell deprecation, absent optional resource, and non-fatal NSIS patch/signing warnings remained visible. - ML-09 `pnpm test:electron:windows`: exit 0, 2 files / 4 tests passed (Vitest 1.04s; command approximately 2.28s). - ML-09 affected E2E `pnpm exec playwright test tests/e2e/project-configuration-skills.spec.ts --config=playwright.config.ts`: exit 0, 1 test passed (2.9s). - ML-09 affected Pi E2E `pnpm exec playwright test tests/e2e/pi-coding-first-chat.spec.ts --config=playwright.config.ts`: exit 1, 1 test passed and 1 failed (33.8s). The known failure remains at `tests/e2e/pi-coding-first-chat.spec.ts:575`: `当前对话模型` resolves to a disabled combobox and `selectOption` times out after 30s. It is not counted as an E2E pass and no remediation diff evidence connects it to ML-09. - ML-09 eight-item boundary checks all passed: the exact ten Data Service names are used by the normal Pi parent default while child profiles remain explicit and Data Service-free; Skill input uses only `injectProjectData`; loopback Origin and generation guards are present; README/Skill docs are present; both route modules use the narrow parser module while retaining route-specific failures; `subscribeLifecycle` remains without `onLifecycle`; and only `handleDataServiceRoutes` remains. The merged path audit matched the expected 15 source paths with no extra or missing path, and the added-lines scope scan found no Firebase, Redis, retry/cache, or published-runtime expansion. - Final ML-09 review ledger: fixed range `f2456039230f68e3ecb2c8653fc3379c23bbe5ce` → `bb832c66660d993baa6147cf058078a5cd89fcb2`; Standards PASS and Spec PASS. ML-00 through ML-09 product/review scope is complete. This documentation update changes no product files; the worktree remains held for X-01. ### X-01 cross-repository acceptance - The installed Windows client used for final acceptance was staged from product HEAD `c52a559b46f72273a02e2dba18e65a5f6c4224c9`, against reviewed server product `13d4bc1b87c9d66cdd26b9a3c40f69d9c039a2e9`, disposable real PostgreSQL at Alembic revision `20260826_0058_data_service`, and a disposable local signed identity provider. Test identities were isolated aliases for account A, account B, expired-session refresh, capacity quota, and mutation-rate cases; no production credential or secret was used or persisted. - Live acceptance exposed four client defects on the actual CDP path. The single ML-09 remediation owner fixed them in committed product changes: preserve/defer the exact target origin across initial `about:blank` injection (`0a4f526`, `afb5c10`), enable the Page domain before installing root/child scripts (`23c49aa`), and bound crashed-target cleanup so close/reopen cannot hang (`c52a559`). Each source task added focused regression tests, passed its project-documentation gates, and was integrated in order without editing the user root worktree. - All 15 specification section 14 groups then passed through the packaged client: lazy provisioning; configure plus preview write/read; restart and move; bind/raw copy sharing; independent-copy separation; two-way owner isolation; one session refresh; no-op/conflict/delete-recreate revision behavior; item/byte pagination and cursor expiry; atomic quota/rate failures; collection/reset/orphan removal; exact Origin and all ten lifecycle invalidations; external `runtime_unavailable`; and the credential-absence ledger. Every invalidated preview endpoint became unusable, and the data capability could not call general Host routes. - Final product-head verification passed `pnpm typecheck`, `pnpm lint:check` with zero errors and the same five existing warnings, `pnpm test` with 188 files / 1615 tests passed and 2 skipped plus the single pressure test, and `pnpm test:electron:windows` with 2 files / 4 tests. The packaged current-head build was used for the successful live run. The earlier full Playwright run remains accurately recorded as 25 passed / 1 existing unrelated model-selector timeout; it is not relabeled as passed. - Final post-X-01 review fixed the full committed product range `f2456039230f68e3ecb2c8653fc3379c23bbe5ce` → `c52a559b46f72273a02e2dba18e65a5f6c4224c9`. The independent Standards reviewer returned PASS with no actionable finding, including the four CDP/lifecycle fixes and all prior ML-09 remediations. The independent Spec reviewer returned PASS with no actionable finding across specification sections 8 through 14, exact-Origin installation/exposure, bounded crash cleanup, identity and Main-only credential boundaries, SDK/Skill behavior, and the frozen P0 scope. - The disposable client profiles and preview projects were removed by the harness; local server/identity-provider processes were stopped, the PostgreSQL container was removed, and all untracked operational scripts were deleted. No acceptance harness is a product artifact. - Go decision for implemented P0 behavior: **GO**, subject to publishing both draft PRs once repository credentials/tooling are available. Rollout remains server-first, and published works/external browser data runtime remain outside P0. ## Follow-ups - GitLab HTTPS PR authentication remains unavailable non-interactively in this environment and `gh`/`glab` are not installed; draft PR promotion remains blocked and no draft PR is claimed from this worktree. - The existing full E2E deviation remains: 25 passed / 1 failed at `tests/e2e/pi-coding-first-chat.spec.ts:575` because the `当前对话模型` combobox stays disabled until the 30s selector timeout. ## Promotion Candidates - None recorded.