10 KiB
10 KiB
Task: Marketplace client and Package Store (MLM-02)
Identity
- Task ID: 20260828-plugin-marketplace-mlm02-9b7c4e1a
- Mode: Feature
- Branch: codex/20260828-plugin-marketplace-mlm02-9b7c4e1a-marketplace-mlm02
- Worktree: D:\Datas\OthersProjects\makelore-plugin-marketplace-mlm02-9b7c4e1a
- Base commit:
c73fcf1d2d - Owner: codex
- Status: Ready for Integration
Scope
- Implement ticket MLM-02 from the exact client coordinator frontier
c73fcf1d2d2e5dccea6f3b403a3b7c00bdc0b25ain this isolated worktree. - Own only new
electron/coding-plugins/marketplace-client.ts,electron/coding-plugins/package-store.ts,electron/coding-plugins/account-plugin-cache.ts, and focused Marketplace, account-cache, download, and Package Store tests plus this task record. - Consume the integrated MLM-01 parser/signature/trust primitives and frozen WSM-03/WSM-04 Marketplace DTO contract; do not wire registry, resolver, Pi, Host routes, Renderer, project state, server, Operations, or Release B.
Intent And Constraints
- Main derives the current account from the existing session boundary; Renderer never supplies account IDs, Bearer tokens, admissions, or package paths.
- Parse closed catalog/detail/Library/resolve/download DTOs with bounded request body/deadline handling, composite ETag and stale metadata, and exactly one authenticated 401 refresh/retry. Preserve a stable resolve request identity for one logical sync across retry/restart; changed logical requests receive a new identity.
- Package installation is a controlled temporary-file/extraction transaction: verify descriptor, code-owned key, Ed25519 signature, size, SHA-256, exact manifest, plugin/version/client range, then atomically switch the immutable release directory and index. Every interruption or failure preserves the old release/index.
- Account Library and Release Admission projections are session/account-scoped
and never enter shared
index.json; logout/account switch invalidates them. Cleanup must respect active workers and every account snapshot, with no token, project, TP, or arbitrary Renderer path in the shared index. - Stable automatic update and explicit beta selection are separate; no hot swap for current workers. Production official-key absence remains an activation hold; no private key, test key, environment trust override, or Release B runtime is added.
Project Context Loaded
Read:
C:\Users\7brot\.agents\skills\implement-spec\SKILL.mdC:\Users\7brot\.codex\skills\maintain-project-docs\SKILL.mdAGENTS.md,.project-docs/05-agent-entry/read-before-planning.md,planning-gate.md, andread-before-coding.md.project-docs/05-agent-entry/memory-index.md,.project-docs/00-brief/project-positioning.md,.project-docs/30-worklog/current-state.md, this task record,.project-docs/10-decisions/decision-index.md,.project-docs/20-architecture/system-overview.md,module-map.md,data-flow.md,.project-docs/40-domain/business-rules.md,glossary.md,.project-docs/50-evidence/evidence-index.md,.project-docs/60-reflection/reflection-index.md,.project-docs/80-commitments/commitments.md, and.project-docs/90-maintenance/stale-items.md- implementation spec
2026-08-28-makelore-plugin-marketplace-implementation-spec.md§§3–6, 7.2–7.3, 8.1, 10.1–10.3, 13.2–13.3 and 16; ticket graph MLM-02; accepted design sections 6, 8.2–8.3, 9.1, 11.2–11.5, 14–15, 18.3, and 19.2–20; and the frozen server DTO/API source atf9c41bd.... - Peer records for MLM-01, the client coordinator, WSM-03, and WSM-04 (read-only).
Relevant understanding:
- The project is an Electron Main/Renderer client; Main owns authentication, filesystem, network, and package trust while Renderer consumes safe projections.
- Marketplace Release A separates publication, Library acquisition, device installation, project enablement, Agent assignment, runtime authorization, and billing. Acquire/download/install/enable/assignment must not write Token Points.
- The exact server contract has anonymous catalog/detail, authenticated Library,
digest-idempotent stable/beta resolve, account-bound expiring admissions, and
admission-authorized download grants/content.
removed_attombstones remain in Library snapshots;system_includedData Service bypasses Library/admission. - MLM-01 is integrated at the dispatch base and provides exact schema-v1/v2 parsing, descriptor bytes, SemVer checks, Ed25519 verification, and a code-owned fail-closed trust store. The official production public key is not supplied.
- Current canonical memory predates Marketplace; the committed spec/design, frozen server DTOs, exact frontier, and peer task outcomes are authoritative.
Task context:
- Task ID:
20260828-plugin-marketplace-mlm02-9b7c4e1a - Mode: Feature
- Branch:
codex/20260828-plugin-marketplace-mlm02-9b7c4e1a-marketplace-mlm02 - Worktree:
D:\Datas\OthersProjects\makelore-plugin-marketplace-mlm02-9b7c4e1a - Base commit:
c73fcf1d2d2e5dccea6f3b403a3b7c00bdc0b25a - Other active local tasks: client coordinator and completed MLM-01 peer; separate server/Operations WSM-03/WSM-04 peers own disjoint files.
- Overlap/semantic assessment: no unresolved conflict. MLM-01 owns parser/trust; MLM-02 owns only the three Main modules and focused tests; MLM-03 owns resolver, routes, Pi/lifecycle. WSM-03/04 DTOs are frozen read-only inputs.
Gate result:
- Concurrent Task Gate: Passed.
check_project_docs.pypassed;task_context.py startcreated the isolated owner worktree, andstatus --jsonmatches this task ID, owner, feature mode, absolute worktree, branch, and exact base. - Planning Gate: Passed. Required memory, spec/ticket/design, frozen server DTO, and peer scopes were read; no unresolved semantic conflict or ownership overlap blocks this plan. Coordinator and user root worktrees remain untouched.
Implementation Plan
- Inspect the existing Main HTTP/session, safe file/archive, package parser, and test seams without editing; write red focused contract tests for bounded DTO parsing, auth refresh/retry, stable request identity, account invalidation, and atomic Package Store failure preservation.
- Implement the smallest cohesive authenticated MarketplaceClient with closed response parsers, cache validators/stale state, session-derived account, one 401 retry, and logical resolve identity management.
- Implement account cache and Package Store with controlled temp paths, exact MLM-01 descriptor/signature/manifest verification, atomic immutable index switching, account/worker-aware cleanup, and stable-vs-beta update policy.
- Run focused tests and interruption/account/path regression matrices, typecheck, scoped/full lint, proportionate build, then task-aware diff/doc gates. Complete the task and make exactly one clean source commit with sole parent the exact dispatch base.
Outcome
- Implemented MLM-02 from the exact client frontier. Main now owns closed Marketplace catalog/detail/Library/resolve/download parsing, bounded requests, composite cache metadata, stale projections, one-refresh authentication retry, and stable logical resolve identity.
- Added an in-memory account/epoch cache and a device-only immutable Package Store with controlled temporary extraction, schema-2 Skill-only manifest checks, descriptor/client-range/size/SHA/Ed25519 verification, atomic release-directory and index replacement, old-release preservation, stable-versus-explicit-beta selection, and account/worker-aware cleanup hooks.
- Scope remains limited to the three new Main modules, focused tests, and this task record. No registry, effective resolver, Pi, Host route, Renderer, project-file, server, Operations, Token Point, hosted-runtime, or Release B code was changed. The official production public key is not present, so production activation remains an explicit hold; tests use ephemeral injected keys only and contain no production private key.
Verification
corepack pnpm install --frozen-lockfile: passed; no dependency or lockfile change.- Initial focused red checkpoint: collection failed because the new owned
account-plugin-cachemodule was absent; no pre-existing implementation was accepted as a fallback. corepack pnpm exec vitest run tests/unit/coding-plugin-marketplace-client.test.ts --maxWorkers=1: 14 passed.corepack pnpm exec vitest run tests/unit/coding-plugin-manifest.test.ts tests/unit/coding-plugin-marketplace-contract.test.ts tests/unit/coding-plugin-marketplace-client.test.ts --maxWorkers=1: 43 passed.corepack pnpm run typecheck: passed.- Owned ESLint over the three Main modules and focused test: passed.
corepack pnpm run lint:check: 0 errors, 5 pre-existing warnings insrc/pages/Home/index.tsxandsrc/pages/Makelore/index.tsx.corepack pnpm run build:vite: passed; only existing dynamic-import and chunk size warnings.- Full Vitest: 1,727 passed, 2 skipped; the separate coding-chat pressure test passed 1/1.
- Focused failure matrix covers 401 refresh/retry, bounded/closed DTO parsing, detail release projection, stable resolve identity, account A/B cache isolation, download interruption, bad signature, invalid ZIP extraction, index replacement failure, incompatible client, account switch, and path containment; old release/index retention is asserted for the covered install failure points.
git diff --check: passed; exactly the five owned paths are changed.- Task-aware
check_doc_drift.py: passed.task_context.py completereturnedREADY_FOR_INTEGRATIONfor this task and exact base/worktree/branch.
Follow-ups
- Production activation remains blocked until the official Ed25519 public key is supplied through the code-owned trust store and the corresponding production private key is available only from deployment secret management.
- MLM-03 may consume these Main modules for the effective resolver and local routes; no runtime integration is included here.
Promotion Candidates
- None. No canonical project-memory change is proposed.