8.5 KiB
8.5 KiB
Task: Meowa hosted plugin client package and Marketplace integration
Identity
- Task ID: 20260831-meowa-hosted-plugin-client-8d3a5b72
- Mode: Feature
- Branch: main
- Worktree: D:\Datas\OthersProjects\makelore
- Base commit:
62304dc85b - Owner: codex-root-meowa-client
- Status: Transferred to Integration Gate
Scope
- Add the signed Marketplace package definition/Skill and hosted adapter for the
provider-neutral
makelore.game-resourcePlugin. - Move Meowa-backed generation and existing game-asset browser/review tools behind Plugin
selection, install, Agent assignment, runtime policy, Release Admission, lifecycle, and
makelore-capability.v1receipts. - Remove the direct always-mounted Meowa proxy, local credential configuration, embedded credential source, and packaging-time plaintext key path.
- Preserve existing local game-asset review UI behavior where it is reached by Plugin tools.
- On the human-authorized takeover, finish the already-started
origin/mainmerge in this worktree without discarding its staged remote changes or the unrelated untracked task record.
Intent And Constraints
- Plugin/package/UI use
makelore.game-resource; they never exposemeowa, a Provider URL, Provider credit balance, or credentials as public authority. - Acquisition is free; hosted operations are
platform_meteredand display the server Token Point policy/receipts. The client cannot quote or choose price/payer/meter. - Stable logical operation identity survives response loss/Main restart. Accepted jobs map to dispatched; ambiguous submission maps to pending review with no automatic new request.
- Existing project/Agent config keeps unknown or disabled Plugin assignments inert. Child workers receive no unassigned game-resource Skill/tools.
- Preserve the user-authorized unrelated untracked record
.project-docs/30-worklog/tasks/20260827-plugin-ml07-spec-7c5a2e91.mdbyte-for-byte and never stage, edit, delete, stash, or clean it. - Existing live-shaped credential is never printed or invoked; remove its source and all release-bundle/env-to-secure-store credential paths. User/operator must revoke it.
- Production trust stays fail closed until the official Marketplace Ed25519 public key is supplied; ephemeral integration keys do not authorize production activation.
- Concurrent Task Gate: PASS via authorized
--adopt-existing; no other writer owns the client root or this semantic slice. - Planning Gate: PASS after reading required client project memory/AGENTS, Marketplace Release B contract, current package store/effective resolver/registry/Pi composition, prior Meowa audit, and official Meowa public contracts.
- Takeover gate: PASS. The in-progress merge was verified to use local parent
421c8254d51318355faec3ae94f8e1cfd4d054c5and fetchedorigin/main38f85f6b5e4dc4e2c5e5b9f8f4506554cfd578f5, exactly matching the previously verified isolated integration. No abort, reset, stash, clean, rebase, or force-update was used.
Outcome
- Added generic schema-2
platform_hostedpackage parsing, immutable Package Store support, Marketplace/Library resolve and Admission projection, effective Skill/tool materialization, and capability-registry dispatch for user-acquired hosted Plugins. - Added the provider-neutral
GameResourceClientandmakelore.game-resourceadapter. The seven Marketplace tools are mounted only for an installed, enabled, assigned, admitted parent worker. Child or unassigned workers receive neither its Skill nor tools. - Generation requires an explicit Main-side
confirmed: truebefore resolve/admission or charging. Stable logical operation identity survives replay;submission_unknownis distinct from a billingpending_reviewreceipt and cannot silently create a new job. Saving output uses the existing project write lease and bounded project-relative paths. - Removed the always-mounted Meowa Pi tools, direct Main proxy route, local Provider URL, env/secure-store release credential source, package-time key injection, and their tests. The public client now knows only Works Square hosted game-resource routes and never sees Meowa/provider URLs, credentials, raw responses, credit balance, or provider job IDs.
- Extended the final
app.asarverifier to prove bothskill_onlyandplatform_hosted, the reachable game-resource hosted route, and absence of five legacy Meowa client-authority markers. Production Marketplace trust remains the empty code-owned fail-closed store; no temporary key was added to the shipped client. - Preserved the unrelated untracked
.project-docs/30-worklog/tasks/20260827-plugin-ml07-spec-7c5a2e91.mdwithout editing, staging, deleting, stashing, or cleaning it. - Completed the inherited remote merge as
03a9e866d4366e0a1cb416e26b424fe981071310. The sole conflict retained the remote shared Agent Server factory/runtime flags and local dynamic Plugin registration, while omitting the obsolete staticgame_asset_browserandgame_asset_reviewtools. Its product and canonical-document tree matches verified merge372b534except for that isolated task's own20260831-pull-remote-merge-4a91c7e2.mdrecord.
Verification
- Hosted/Marketplace/Pi/package focused suite:
13 files, 153 passed, 2 skipped. - Official
pnpm testat product commitfe656dd865f1941f1dc2d369ce3bb09efb955fd8passed:207 files / 1687 passed / 2 skipped, followed by the pressure test independently at1 passed. pnpm typecheckpassed.pnpm lint:checkpassed with 0 errors and the same 5 existing Home/Makelore warnings. Renderer/Main/Preload/utility Vite/Electron build and Windows x64/NSIS packaging completed successfully before final documentation.pnpm verify:artifact:pipassed against the packaged application and reportsschema2PlatformHosted=true,legacyMeowaClientAuthorityAbsent=true, Data Service's exact ten bundled tools, and the existing Pi 0.84.2 closure.pnpm verify:artifact:winpassed with embedded/verification HEAD both exactlyfe656dd865f1941f1dc2d369ce3bb09efb955fd8; the NSIS installer is 294,692,931 bytes with SHA-25666C3802040643C35F419CD0EF5D6CB804DD69A34F8338FE0C997EE8CA895632C.git diff --checkpassed for the task changes. No real Provider request, production Marketplace signature, production install, push, deploy, or publication was performed.- Takeover merge verification: unresolved paths 0; conflict markers 0; staged and
unstaged
git diff --checkpassed; repository-pinnedpnpm@10.33.4typecheck passed; 12 merge-focused files passed 145 tests with 2 skipped.
Follow-ups
- Revoke the previously client-exposed Meowa credential externally; removing its source and package path cannot invalidate a credential already leaked into history/artifacts.
- After the server has a rotated Meowa credential, positive Token Point pricing, and the official signing key pair, run signed package install/update/rollback, Agent/Pi, response-loss/pending-review, and real Provider acceptance using the packaged client.
- Keep production installation/activation fail closed until the official Ed25519 public
key is built into
trusted-keys.tsthrough the normal reviewed release process. - Complete canonical promotion under an Integration Gate task. The feature-mode drift gate must not be bypassed merely because the fetched remote history contains accepted canonical documentation.
Promotion Candidates
- Target:
.project-docs/30-worklog/current-state.md. Proposal: record that MakeLore implements genericplatform_hostedMarketplace packages and themakelore.game-resourceadapter, while production activation remains held. Evidence: focused tests, typecheck/lint/build, and finalapp.asarproof. Future impact: future hosted Plugins reuse the same package/Admission/worker lifecycle. No semantic conflict; human confirmation is required only to lift production HOLDs. - Target:
.project-docs/20-architecture/{module-map,data-flow}.mdand.project-docs/40-domain/business-rules.md. Proposal: document Main -> Works Square as the only hosted Plugin transport, dynamic parent-worker Skill/tool projection, explicit paid confirmation, stable logical operation identity, project write leases, and the prohibition on provider credentials/URLs/IDs in packages or Renderer/Pi results. Evidence: client/service/adapter/registry/package-store code plus tests and packaged artifact verification. Future impact: prevents reintroducing provider-specific always-mounted client proxies. No semantic conflict; no product-direction confirmation is required.