Files
makelore/.project-docs/30-worklog/tasks/20260828-plugin-marketplace-client-5f8b3d72.md
T

17 KiB

Task: Implement curated plugin marketplace Release A client

Identity

  • Task ID: 20260828-plugin-marketplace-client-5f8b3d72
  • Mode: Feature
  • Branch: codex/20260828-plugin-marketplace-client-5f8b3d72-plugin-marketplace-client
  • Worktree: D:\Datas\OthersProjects\makelore-plugin-marketplace-client-5f8b3d72
  • Base commit: 1ca8deb54b
  • Owner: codex-root
  • Status: In Progress

Scope

  • Coordinate the repository-local Marketplace Release A MakeLore unit from exact completed Plugin P0 evidence head 1ca8deb54b7b530ab8c5b6a5b7e613730c3b97ec.
  • Deliver MLM-00 through MLM-06, the packaged-client half of XMA-01, dependency-ordered integration, fixed-base review/remediation, package proof, and exact final evidence on this isolated branch.
  • Own only this coordinator worktree/branch, coordinator task record, merger/package proof verification, and cross-repository acceptance ledger.

Intent And Constraints

  • Implement Marketplace Release A only: schema-v2 declarative parsing, code-owned Ed25519 trust, Main-owned Works Marketplace/Library access, atomic Package Store, one effective plugin snapshot, and Marketplace/My Plugins/Project Plugins UI.
  • Keep acquisition, device installation, project selection, backend configuration, Agent assignment, authorization, invocation, and billing separate. No UI action may silently chain another state mutation.
  • Preserve the completed Plugin P0/Data Service behavior: exact bundled schema 1, project ID retention, ten typed tools, four preview operations, closed capability envelope, child-empty workers, and zero Token Point transactions.
  • Keep Release B closed: no hosted adapter, Provider endpoint/credential, Plugin Charges, Plugin Credits, arbitrary local code/scripts/native/hooks/LSP/stdio MCP, or generic invoke/config/ledger.
  • Product trust accepts only code-owned official public keys. Tests may inject ephemeral verifiers through service dependencies; no production private key or arbitrary runtime public-key override may be committed.
  • Use exact-frontier isolated implementers, disjoint ownership, one source commit per ticket, one repository-local merger, read-only fixed-range reviewers, and one remediation owner at a time. Implementers are not alone and must preserve others' work.
  • The user root main worktree, old P0 coordinator, live services, push, deployment, publication, and PR fabrication are outside authority. No PR is created for this local-only delivery.

Project Context Loaded

  • Concurrent and Planning Gates passed in the registered isolated worktree. Task ID, owner, mode, branch, worktree, and exact base match the task-context owner record.
  • Fully read AGENTS.md, the implementation specification, ticket graph, accepted detailed design, project-memory startup set, relevant architecture/evidence/ commitment/stale material, completed Plugin P0 client record, and current manifest, registry, project selection, effective Pi, Host composition, Plugin Center, tests, and package scripts.
  • Exact Git facts: HEAD is 1ca8deb54b7b530ab8c5b6a5b7e613730c3b97ec; reviewed product head 78fb7d730731a7b0ebadf12418ca4c2eb6ef3310 is an ancestor. The remaining base delta is P0 evidence only. User root main is not the source or implementation worktree.
  • The completed P0 coordinator is read-only evidence. Other same-topic local owners are completed implementers/remediators or read-only historical reviewers; no active peer owns this new branch or has a semantic conflict with the Release A DAG.
  • Canonical integrated memory predates the unintegrated P0 coordinator; its exact task evidence and this frozen base/spec control Marketplace work.
  • Likely modules are exactly the MLM-01 through MLM-04 ownership sets: schema-v2 and signature primitives; Marketplace client/account cache/Package Store; effective resolver/Main/Pi lifecycle; Renderer pages/stores/routes; and MLM-05 package proof.

Ticket Ownership

  • MLM-00, MLM-05, MLM-06 coordination, and XMA-01 client evidence: this coordinator.
  • MLM-01 through MLM-04: exact-frontier isolated implementers in graph order. MLM-02 remains blocked until MLM-01 is integrated and the WSM-03/WSM-04 DTO is frozen.
  • MLM-06 Standards and Spec axes: independent read-only reviewers. Accepted root causes route to one isolated remediation implementer at a time before repeat review.
  • MLM-01 source task 20260828-plugin-mlm01-5c8d1e4f was dispatched from exact coordinator frontier 4d8b1fcec0a751d2935effc7816c7e59f568ec65, completed as source commit 352a3b7280bb48854beb5281d2b4923b76793367, and was integrated without conflict as coordinator product commit 898e2b7bdde4bdd77a5659d7b4e294d0607656e3.
  • MLM-02 source task 20260828-plugin-marketplace-mlm02-9b7c4e1a was dispatched from exact post-MLM-01 frontier c73fcf1d2d2e5dccea6f3b403a3b7c00bdc0b25a, completed as source commit 1b6f5aaccaf55fc98657fc93824015471818f6e6, and was integrated without conflict as coordinator product commit 4052fa85cc4c9bfb0bed5b529dd6209007a65ef3.
  • Current client frontier contains the frozen MLM-02 Marketplace client/account cache/Package Store contract. MLM-03 may now start from the documentation checkpoint recorded after this integration.
  • MLM-03 task 20260828-plugin-marketplace-mlm03-4c8e1a7d was dispatched from exact frontier 1d64b89499f68de721e0f1c845dad2c57f1a78ed. Its original agent was interrupted after becoming unresponsive; a serial finisher resumed the same registered owner and preserved the dirty worktree with no concurrent writer. The completed source commit 7ad6b8c66d9ca64b5778690667c91c424aae456a was integrated without conflict as coordinator product commit 05917a789a9b9f30ed9500f4cd1210ec72119646. Coordinator-transferred Package Store ownership was limited to removing unconditional latest-Release protection while preserving account-snapshot and active-worker protection.
  • MLM-04 task 20260828-marketplace-mlm04-renderer-e4c7a2 completed from exact frontier 8b6824a8ba08d8df98fc75af17e170bf3d8ed630 as source commit d61221d34da49f97dd4a9aeb1081fb3544cc6c86 and was integrated without conflict as coordinator product commit 97c9ad1aad2638609168a8e1901b61b5ba671def. Three coordinator-approved seam transfers remained minimal: joined safe Library/installation projection, explicit project unknownPluginIds, and disable-only removal for an already selected unknown ID. No Main route, registry, Pi, or Package Store source was otherwise expanded.
  • MLM-05 merger task 20260828-marketplace-mlm05-merger-c73a91e4 verified the already integrated source/product ledger from exact frontier 2c4f766b3b61d4540919495043322d438cc17ec3. Its artifact-proof-only source commit 3ab257d3f0226ecba40166f306b939319061e551 was integrated without conflict as coordinator product commit 43c464a556d32a1ac564a5bb79f92741c4d9d635.
  • MLM-06 fixed-range Standards and Spec review found eleven deduplicated roots. The sole remediation task 20260828-marketplace-mlm06-remediation-6d3a9c82 completed from exact frontier 8dfa5428606076b847966750134061de6fbe91ba as source commit 291b64ab0ef4779a44e09a386de31332abe1f57b and was integrated without conflict as coordinator product commit 1614f7efc1fc81efc3b4d1c80827948976f1427b.
  • MLM-06 R2 fixed-range Standards and Spec review found eight remaining roots. The same sole remediation owner completed task 20260828-marketplace-mlm06-r2-remediation-6f4a2d91 from exact frontier 2c3baf6dff975ce229d80a35450c5e79e271651b as source commit f7d2dc148896bfbe0ee8a9e7f040f3e05c634b2e. It was integrated without conflict as coordinator product commit 11d0af01663ad5b35a86fbe037c9277a5283f9a3; the source/product trees are identical after excluding the task-scoped handoff record.

Outcome

  • MLM-00 completed. The coordinator unit is isolated from the exact accepted P0 evidence head, both documentation gates pass, semantic overlap is clear, and no client product file changed before opening MLM-01.
  • The official platform public key is not present and remains a production activation input; the parser/signature implementation and injected-key acceptance still proceed.
  • No push, PR, deployment, production key generation, or publication was attempted.
  • MLM-01 delivered schema-1 compatibility, closed schema-2 skill_only and declarative platform_hosted parsing, bounded JSON Schema validation, fixed release descriptor bytes, Ed25519 verification, compatibility/provenance checks, and a code-owned production trust seam. The official Ed25519 public key remains absent, so the production activation hold is preserved and the default trust store fails closed; no production private key or runtime key override was added.
  • MLM-02 delivered the bounded authenticated Marketplace client, session/account cache, and atomic immutable Package Store. Acquisition and download remain separate from project enablement, Agent assignment, runtime authorization, and billing; distributed packages are descriptor/signature/size/SHA/schema/client-range verified before an atomic index switch, and install failure preserves the previous release. Account A/B snapshots remain isolated and logout/account switch invalidates them. The official public key activation hold remains unchanged.
  • MLM-03 delivered one effective installed-plugin resolver, Main-owned Marketplace routes, and a frozen parent-worker snapshot shared across resource loading, Extension Host, tool declarations, CLI/context, and runtime authorization. Child workers remain empty; active Releases are registered for Package Store cleanup; old workers reject new plugin actions after invalidation. Unknown or uninstalled Skill assignments remain in project/Agent configuration but do not enter runtime projections, and automatically become effective again when the trusted package source returns.
  • MLM-04 delivered global Marketplace and My Plugins pages plus the joined Project Plugins state. The four user actions remain distinct and call only their matching Main route; fresh installation/account projection, stale/error states, retained unknown project IDs, typed Data Service settings, account/project generation, and mutation epochs are bounded in Renderer state. No account, filesystem path, Release Admission, token, or signed URL authority enters Renderer.
  • MLM-06 remediation paired every frozen Skill with its verified package root, separated explicit device uninstall from Library removal, added exact Package Store orphan recovery and current-Release selection, bounded whole-response deadlines, and serialized same-account reads and cross-Plugin mutations by intent. It also exposed explicit beta and bounded unavailable states through Main/Renderer, made the packed trust proof read the real app.asar, and synchronized README. Official-key absence remains a fail-closed production activation hold.
  • MLM-06 R2 remediation closes source ownership collisions, per-Plugin mutation ordering, protected-current uninstall projection, current-client compatibility revalidation, installed-channel projection, same-account cache completion order, reachable packaged trust proof, and the shared My Plugins E2E gap. Explicit Beta remains on its selected channel; when the server's bounded Library authority changes the current channel version, Renderer reports a truthful channel-change/unavailable state without inventing a yanked field. Unknown assignments and incompatible packages remain persisted but do not enter a new effective worker snapshot.

Verification

  • git rev-parse HEAD returned exact 1ca8deb54b7b530ab8c5b6a5b7e613730c3b97ec; ancestry of reviewed product head 78fb7d7... passed. The only initial status entry was this task record.
  • corepack pnpm --version reported the repository-pinned 10.33.4.
  • This fresh worktree lacked dependencies, so corepack pnpm install --frozen-lockfile restored the locked 997-package graph entirely from the package store; no source or lockfile changed.
  • corepack pnpm run typecheck passed.
  • The ten-file manifest/capability-policy/project-selection/Pi/Host/Plugin Center baseline passed 68 passed, 2 skipped (70 total) in 10.27 seconds with one worker. The two skips are the existing staged-runtime gates.
  • The run was proportionate: a type/parser/registry/Pi failure would have stopped MLM-01 because schema-v2 primitives cannot safely extend a broken claimed P0 base.
  • MLM-01 source verification passed the complete repository suite (1713 passed, 2 skipped) plus the single-worker pressure case (1 passed), typecheck, lint, Vite build, documentation drift, and task-context completion. Source parent, clean status, changed-file ownership, and ready_for_integration status were independently verified before integration.
  • MLM-02 source verification passed focused 14, adjacent parser/contract 43, full Vitest 1727 passed, 2 skipped, and the pressure case 1 passed, plus typecheck, owned/full lint (zero errors and five pre-existing warnings), Vite build, diff/doc gates, and task-context completion. Its exact sole parent, five owned paths, clean status, and READY_FOR_INTEGRATION state were independently verified before cherry-pick.
  • MLM-03 verification passed 142 focused/adjacent tests with two staged-runtime skips, full Vitest 1738 passed, 2 skipped, the pressure case, typecheck, lint with zero errors and five unchanged warnings, Vite build, Windows package, Windows and Pi artifact verification, publish-runtime verification, diff/doc gates, and task-context completion. The Windows installer embedded exact source HEAD 7ad6b8c...; production signing, real Provider, macOS, and native Linux activation evidence remain explicit external/platform holds rather than passes.
  • MLM-04 verification passed 73 focused/adjacent tests across 12 files, typecheck, lint with zero errors and five unchanged warnings, Vite build, two Marketplace/ Project Plugins Electron Playwright cases, six Windows Electron Vitest cases, and documentation drift. Its task record also captured the actual interface-polish Before/After changes: bounded hit targets, explicit transitions, wrapping, and tabular dynamic values within the existing design system.
  • MLM-05 verification passed 121 focused tests, 78 P0/Data Service/Pi/preview regressions with two staged-runtime skips, nine packed-proof tests, full Vitest 1761 passed, 2 skipped, the pressure case, typecheck, lint with zero errors and five unchanged warnings, Vite build, six Windows Electron tests, two targeted Marketplace E2E cases, Windows package, and Pi artifact verification. The full E2E run passed 27 cases; its sole failure was the unchanged pi-coding-first-chat.spec.ts disabled-model-combobox timeout. The packed proof found schema-2 skill_only, unknown-key fail-closed, Library/install/update/ effective routes, Renderer assets, and no private-key/runtime-key override. Official public-key production trust remains HOLD.
  • MLM-06 verification passed focused 82 tests, trust/contract 30 tests, adjacent 66 tests, complete single-worker Vitest 1779 passed, 2 skipped, the pressure case, typecheck, lint with zero errors and five unchanged warnings, Vite build, six Windows Electron tests, and Marketplace E2E. Full E2E passed 27 of 28; the only failure remained the unchanged disabled-model-combobox timeout. The four-worker unit run reached 207/208 files and 1769 passes before one assertion-free worker exit; the complete one-worker rerun is the product result. Windows x64 staging and building passed; the aggregate package:win arm64 uv download hit an external GitHub connect timeout. Both Pi and Windows artifact verifiers passed on the clean final source commit, with embedded gitCommit and verificationHead equal to 291b64a...; the real packed trust source contains no private key and fails closed while the official public key is absent.
  • MLM-06 R2 verification passed six focused files / 69 tests, 39 adjacent tests, complete single-worker Vitest 1789 passed, 2 skipped, the pressure case, typecheck, lint with zero errors and five unchanged warnings, Vite builds, six Windows Electron tests, and both Marketplace E2E cases. Windows x64 staging and unpacked building passed. The artifact unit suite passed 12/12 and the fresh release/win-unpacked Pi verifier passed after following package.json.main through the real Windows app.asar with native entry separators; Marketplace trust remains official-key-absent fail-closed with no private-key material. XMA-01 was not run and no full-E2E pass beyond the targeted Marketplace file is claimed here.

Follow-ups

  • None recorded.

Promotion Candidates

  • After MLM-06 review and XMA-01, promote the Marketplace Main/Package Store/effective resolver chain into .project-docs/20-architecture/module-map.md and data-flow.md, including account cache, immutable installation, frozen worker snapshot, and lifecycle invalidation.
  • Refresh .project-docs/30-worklog/current-state.md and .project-docs/40-domain/business-rules.md with the separation between Account Library, Device Installation, project enablement, Agent assignment, runtime authorization, and billing; retain the official public-key activation hold.
  • Add the final MLM-05/MLM-06/XMA-01 evidence to the evidence index only after live acceptance; repository package/tests must not be promoted as signed-in live proof.