Files
makelore/.project-docs/30-worklog/tasks/20260901-web-search-mlw03-composition-d9f5b3e2.md
T

7.0 KiB

Task: Implement MLW-03 composition and packaged proof

Identity

  • Task ID: 20260901-web-search-mlw03-composition-d9f5b3e2
  • Mode: Feature
  • Branch: codex/20260901-web-search-mlw03-composition-d9f5b3e2-web-search-mlw03-composition
  • Worktree: D:\Datas\OthersProjects\makelore-web-search-mlw03-composition-d9f5b3e2
  • Base commit: 68cb2e73be
  • Owner: web-search-mlw03-implementer
  • Status: Ready for Integration

Scope

  • Wire the code-owned Web Search adapter into electron/api/coding-composition.ts so the existing effective-plugin snapshot is the only parent-worker materialization and invocation authority.
  • Add the Web Search parent/child/current-authority scenario to tests/unit/coding-capability-registry.test.ts and the composition registration proof to tests/unit/coding-plugin-composition.test.ts.
  • Add only a generic closed billing-state projection to src/pages/Chat/CodingConversationTimeline.tsx with focused coverage in tests/unit/coding-conversation-timeline.test.tsx; do not parse web-search.v1 or add Web Search-specific Renderer state.
  • Extend the packaged main-reachable proof in scripts/lib/pi-product-artifact.mjs and tests/unit/pi-product-artifact.test.ts for the fixed hosted Web Search route, receipt-unavailable parser, and absence of provider authority. The verifier script is a necessary adjacent proof file required by the MLW-03 acceptance criteria and has no competing ticket owner.
  • Update README.md to describe the shipped native hosted Web Search capability and its production activation holds.
  • Do not modify MLW-01 admission ownership, MLW-02 client/adapter/envelope ownership, project selection services, Marketplace pages, Provider/Server code, or Release B surfaces.

Intent And Constraints

  • Exact source base is 68cb2e73beb17d5041198d020aaa7b2884124950; server DTO authority is frozen at a49c696ebc4213e3d62ece780961efbe17576f8e.
  • Concurrent Task Gate and Planning Gate passed after verifying task identity, branch/worktree/base, clean product state, coordinator/MLW-01/MLW-02 peers, canonical implementation spec/design, and project memory. The older broad Web Search client task remains at its original base with no product diff and does not conflict with this exact-base ticket.
  • Use test-first natural boundaries. Parent workers may receive one dynamically installed Web Search Skill/tool; child workers receive none. Disabled, uninstalled, stale, account-switched, project-switched, or logged-out state must affect only the next frozen worker snapshot.
  • Keep provider key, model choice, provider URL, signed URL, admission authority, and account authority out of Renderer/package artifacts. No static tool allowlist, generic invoke route, pi-web-search, or third-party Pi extension.
  • Real PostgreSQL, live paid OpenAI, production signing key, production OpenAI key/model/price/privacy copy, push, PR, deployment, and publication remain out of scope or explicitly held.

Plan

  1. Add focused failing tests for composition registration, dynamic parent/child/current invocation, generic billing projection, and packaged reachability/provider-authority exclusions.
  2. Implement the smallest composition/timeline/artifact/README changes that turn those tests green.
  3. Run focused and adjacent regressions, typecheck, lint, Vite/Electron/package proof as applicable, full unit pressure, documentation gates, and produce one clean source commit.

Outcome

  • Registered the code-owned Web Search adapter in both production capability execution and project-plugin inspection/deactivation paths. Marketplace-installed schema-v2 definitions remain the only Skill/tool source; no Web Search definition or tool allowlist was added to composition.
  • Added an end-to-end registry proof for the frozen Web Search parent snapshot: one parent Skill/tool, no child inheritance, exact Main request/admission/envelope mapping, and refusal of a subsequent old-worker action after the project is disabled.
  • Added a generic closed billing-state renderer for all makelore-capability.v1 tools. receipt_unavailable is displayed as 收费状态未同步,请勿重复发起; the timeline does not inspect web-search.v1 answer/source payloads or add Web Search-specific state.
  • Extended the package-main-reachable artifact proof to require the Web Search plugin ID, fixed Works route, and receipt-unavailable parser while rejecting embedded OpenAI key/origin authority. The built app remains fail-closed for the absent official Marketplace signing key.
  • Updated README current-product documentation for native hosted Web Search, dynamic Marketplace Skill materialization, explicit Token Point confirmation, and production activation holds.

Verification

  • TDD boundary: after dependency materialization, the first focused run failed exactly four assertions (missing composition registration, generic receipt projection, Web Search artifact result field, and provider-authority rejection). The implementation turned the same boundary green: 4 files / 40 tests.
  • Focused plus adjacent Web Search/admission/composition/lifecycle/Pi/timeline/artifact suite: 10 files / 82 tests passed.
  • Full unit suite: 214 files / 1,751 tests passed / 2 staged-runtime tests skipped; isolated pressure suite: 1/1 passed.
  • pnpm run typecheck: passed. Scoped ESLint: passed. Full pnpm run lint:check: 0 errors and the unchanged 5 warnings in Home/Makelore.
  • pnpm run build:vite: passed for Renderer, Main, Preload, and utility worker. Electron Windows Vitest: 2 files / 6 tests passed. Marketplace, Project Plugins, and Skill configuration Playwright targets: 4/4 passed.
  • pnpm run package:win: passed and produced the unpacked x64 app plus NSIS installer. The first installer was 208,252,283 bytes with SHA-256 E6ABFA36C219F71FDBCAE811BA01DAEFFFAA3625FCCA17FE40C12CE507D0808E; a clean-source-HEAD package/verification is required immediately after the sole commit before handoff.
  • pnpm run verify:artifact:pi: passed against the real built app.asar; Marketplace proof includes the Web Search ID, fixed route, receipt parser, absent Web Search provider authority, and official-key-absent fail-closed trust. Existing Pi runtime result remains the inherited partial-pass for deferred cross-platform/real-provider evidence.
  • pnpm run verify:publish-runtime: passed with npm 11.6.2. The pre-commit verify:artifact:win correctly refused to claim a clean artifact while the source diff was uncommitted; it is not a product failure and must be rerun on the source commit.
  • git diff --check: passed.

Follow-ups

  • Real PostgreSQL lifecycle remains an external HOLD because no local service, Docker runtime, or TEST_POSTGRESQL_DATABASE_URL is available; SQLite is not accepted as a substitute.
  • Live OpenAI acceptance remains HOLD because paid calls were not authorized. Production activation also remains HOLD for the official Ed25519 public key, WEB_SEARCH_OPENAI_API_KEY, approved model, price, and privacy copy.
  • XWS-01 and the fixed-range Standards/Spec review remain coordinator-owned after MLW-03 integration.

Promotion Candidates

  • None recorded.