# Task: Meowa hosted plugin client package and Marketplace integration ## Identity - Task ID: 20260831-meowa-hosted-plugin-client-8d3a5b72 - Mode: Feature - Branch: main - Worktree: D:\Datas\OthersProjects\makelore - Base commit: 62304dc85b3c1069cd656dfacb61ee820e216fa2 - Owner: codex-root-meowa-client - Status: Transferred to Integration Gate ## Scope - Add the signed Marketplace package definition/Skill and hosted adapter for the provider-neutral `makelore.game-resource` Plugin. - Move Meowa-backed generation and existing game-asset browser/review tools behind Plugin selection, install, Agent assignment, runtime policy, Release Admission, lifecycle, and `makelore-capability.v1` receipts. - Remove the direct always-mounted Meowa proxy, local credential configuration, embedded credential source, and packaging-time plaintext key path. - Preserve existing local game-asset review UI behavior where it is reached by Plugin tools. - On the human-authorized takeover, finish the already-started `origin/main` merge in this worktree without discarding its staged remote changes or the unrelated untracked task record. ## Intent And Constraints - Plugin/package/UI use `makelore.game-resource`; they never expose `meowa`, a Provider URL, Provider credit balance, or credentials as public authority. - Acquisition is free; hosted operations are `platform_metered` and display the server Token Point policy/receipts. The client cannot quote or choose price/payer/meter. - Stable logical operation identity survives response loss/Main restart. Accepted jobs map to dispatched; ambiguous submission maps to pending review with no automatic new request. - Existing project/Agent config keeps unknown or disabled Plugin assignments inert. Child workers receive no unassigned game-resource Skill/tools. - Preserve the user-authorized unrelated untracked record `.project-docs/30-worklog/tasks/20260827-plugin-ml07-spec-7c5a2e91.md` byte-for-byte and never stage, edit, delete, stash, or clean it. - Existing live-shaped credential is never printed or invoked; remove its source and all release-bundle/env-to-secure-store credential paths. User/operator must revoke it. - Production trust stays fail closed until the official Marketplace Ed25519 public key is supplied; ephemeral integration keys do not authorize production activation. - Concurrent Task Gate: PASS via authorized `--adopt-existing`; no other writer owns the client root or this semantic slice. - Planning Gate: PASS after reading required client project memory/AGENTS, Marketplace Release B contract, current package store/effective resolver/registry/Pi composition, prior Meowa audit, and official Meowa public contracts. - Takeover gate: PASS. The in-progress merge was verified to use local parent `421c8254d51318355faec3ae94f8e1cfd4d054c5` and fetched `origin/main` `38f85f6b5e4dc4e2c5e5b9f8f4506554cfd578f5`, exactly matching the previously verified isolated integration. No abort, reset, stash, clean, rebase, or force-update was used. ## Outcome - Added generic schema-2 `platform_hosted` package parsing, immutable Package Store support, Marketplace/Library resolve and Admission projection, effective Skill/tool materialization, and capability-registry dispatch for user-acquired hosted Plugins. - Added the provider-neutral `GameResourceClient` and `makelore.game-resource` adapter. The seven Marketplace tools are mounted only for an installed, enabled, assigned, admitted parent worker. Child or unassigned workers receive neither its Skill nor tools. - Generation requires an explicit Main-side `confirmed: true` before resolve/admission or charging. Stable logical operation identity survives replay; `submission_unknown` is distinct from a billing `pending_review` receipt and cannot silently create a new job. Saving output uses the existing project write lease and bounded project-relative paths. - Removed the always-mounted Meowa Pi tools, direct Main proxy route, local Provider URL, env/secure-store release credential source, package-time key injection, and their tests. The public client now knows only Works Square hosted game-resource routes and never sees Meowa/provider URLs, credentials, raw responses, credit balance, or provider job IDs. - Extended the final `app.asar` verifier to prove both `skill_only` and `platform_hosted`, the reachable game-resource hosted route, and absence of five legacy Meowa client-authority markers. Production Marketplace trust remains the empty code-owned fail-closed store; no temporary key was added to the shipped client. - Preserved the unrelated untracked `.project-docs/30-worklog/tasks/20260827-plugin-ml07-spec-7c5a2e91.md` without editing, staging, deleting, stashing, or cleaning it. - Completed the inherited remote merge as `03a9e866d4366e0a1cb416e26b424fe981071310`. The sole conflict retained the remote shared Agent Server factory/runtime flags and local dynamic Plugin registration, while omitting the obsolete static `game_asset_browser` and `game_asset_review` tools. Its product and canonical-document tree matches verified merge `372b534` except for that isolated task's own `20260831-pull-remote-merge-4a91c7e2.md` record. ## Verification - Hosted/Marketplace/Pi/package focused suite: `13 files, 153 passed, 2 skipped`. - Official `pnpm test` at product commit `fe656dd865f1941f1dc2d369ce3bb09efb955fd8` passed: `207 files / 1687 passed / 2 skipped`, followed by the pressure test independently at `1 passed`. - `pnpm typecheck` passed. `pnpm lint:check` passed with 0 errors and the same 5 existing Home/Makelore warnings. Renderer/Main/Preload/utility Vite/Electron build and Windows x64/NSIS packaging completed successfully before final documentation. - `pnpm verify:artifact:pi` passed against the packaged application and reports `schema2PlatformHosted=true`, `legacyMeowaClientAuthorityAbsent=true`, Data Service's exact ten bundled tools, and the existing Pi 0.84.2 closure. - `pnpm verify:artifact:win` passed with embedded/verification HEAD both exactly `fe656dd865f1941f1dc2d369ce3bb09efb955fd8`; the NSIS installer is 294,692,931 bytes with SHA-256 `66C3802040643C35F419CD0EF5D6CB804DD69A34F8338FE0C997EE8CA895632C`. - `git diff --check` passed for the task changes. No real Provider request, production Marketplace signature, production install, push, deploy, or publication was performed. - Takeover merge verification: unresolved paths 0; conflict markers 0; staged and unstaged `git diff --check` passed; repository-pinned `pnpm@10.33.4` typecheck passed; 12 merge-focused files passed 145 tests with 2 skipped. ## Follow-ups - Revoke the previously client-exposed Meowa credential externally; removing its source and package path cannot invalidate a credential already leaked into history/artifacts. - After the server has a rotated Meowa credential, positive Token Point pricing, and the official signing key pair, run signed package install/update/rollback, Agent/Pi, response-loss/pending-review, and real Provider acceptance using the packaged client. - Keep production installation/activation fail closed until the official Ed25519 public key is built into `trusted-keys.ts` through the normal reviewed release process. - Complete canonical promotion under an Integration Gate task. The feature-mode drift gate must not be bypassed merely because the fetched remote history contains accepted canonical documentation. ## Promotion Candidates - Target: `.project-docs/30-worklog/current-state.md`. Proposal: record that MakeLore implements generic `platform_hosted` Marketplace packages and the `makelore.game-resource` adapter, while production activation remains held. Evidence: focused tests, typecheck/lint/build, and final `app.asar` proof. Future impact: future hosted Plugins reuse the same package/Admission/worker lifecycle. No semantic conflict; human confirmation is required only to lift production HOLDs. - Target: `.project-docs/20-architecture/{module-map,data-flow}.md` and `.project-docs/40-domain/business-rules.md`. Proposal: document Main -> Works Square as the only hosted Plugin transport, dynamic parent-worker Skill/tool projection, explicit paid confirmation, stable logical operation identity, project write leases, and the prohibition on provider credentials/URLs/IDs in packages or Renderer/Pi results. Evidence: client/service/adapter/registry/package-store code plus tests and packaged artifact verification. Future impact: prevents reintroducing provider-specific always-mounted client proxies. No semantic conflict; no product-direction confirmation is required.