Files
makelore/.project-docs/30-worklog/tasks/20260827-makelore-plugin-client-7d3a91c4.md

524 lines
32 KiB
Markdown

# Task: Implement MakeLore Plugin Platform P0 client
## Identity
- Task ID: 20260827-makelore-plugin-client-7d3a91c4
- Mode: Feature
- Branch: codex/20260827-makelore-plugin-client-7d3a91c4-makelore-plugin-client
- Worktree: D:\Datas\OthersProjects\makelore-plugin-client-7d3a91c4
- Base commit: eb5d15d68470b30ec181164f08f0d7b027ef0006
- Owner: codex-root
- Status: Ready for Integration
## Scope
- Coordinate the repository-local `implement-spec` unit for ML-00 through ML-07
from exact accepted Data Service head
`eb5d15d68470b30ec181164f08f0d7b027ef0006`.
- Deliver the fixed bundled package, project selection, strict policy/capability
registry and envelope, dynamic Pi Skill/tool materialization, Host/lifecycle
integration, Plugin Center, packaged proof, verification, and fixed-range review.
- Own only this isolated client branch, repository-local integration, project task
record, client verification, and the client half of X-01 evidence.
## Intent And Constraints
- Preserve accepted Data Service project identity, Main-owned credential and typed
operation seams, exact-Origin preview lifecycle, SDK/Skill behavior, and Pi 0.84.2
hard-cutover contracts.
- Keep package availability, local enablement, Agent Skill assignment, backend
configuration, invocation, and billing policy independently observable.
- P0 scans only fixed bundled roots and adds no arbitrary code/MCP/hooks,
marketplace, download/update, generic invoke/config/ledger, Plugin Credits,
`plugin_charges`, publication coupling, or external-browser capability.
- Renderer cannot choose project authority, owner, credential, policy, price, or
request identity; child workers receive no plugin Skills/tools.
- All implementation tickets use exact-frontier isolated worktrees and one commit;
implementers are not alone in the repository and must not revert other changes.
- The user root `main` worktree is read-only. The user did not request publication;
no PR is claimed unless one actually exists.
## Project Context Loaded
- Task ID/mode/branch/worktree/base match the Git-common owner record exactly.
- Read `AGENTS.md`, the mandatory project-memory entry set, active task record,
positioning/current-state/decision/architecture/data-flow/domain/evidence/
reflection/commitment/stale material, the implementation spec, detailed-design
sections 6-9 and 14-17, ticket graph, and the accepted Data Service client peer.
- Other local owners: 149 including this task (12 planning, 137 ready for
integration). The only same-topic peer is the completed Data Service coordinator
whose exact evidence head is this task's base; it is not resumed or modified.
- Overlap assessment: no unresolved semantic conflict. ML-01 through ML-05 have
disjoint primary ownership and execute strictly in graph order; ML-02 waits for
both ML-01 and the exact WS-02 catalog DTO.
- Current integrated memory predates this unintegrated Data Service/plugin work;
accepted branch/task evidence and the frozen spec control this feature branch.
- Likely modules are the package/project-service, policy/capability registry,
Pi resource/runtime, Host composition/lifecycle, Renderer Plugin Center, and
packaged-proof paths named by the ticket graph.
- Gate result: Passed on 2026-08-27.
## Ticket Ownership
- ML-00, ML-06, and X-01 client evidence: coordinator in this worktree.
- ML-01 through ML-05: isolated implementers from exact frontier commits, with ML-02
waiting for WS-02's catalog shape.
- ML-07: fixed-range Standards/Spec reviewers; accepted findings go to one isolated
remediation owner before repeat review.
## Outcome
- ML-00 completed: the client coordination unit is isolated from exact accepted
Data Service evidence head, ownership/planning gates passed, and no product file
changed before the first implementation frontier.
- Integrated ML-01 from replacement source commit
`c092863ee600808e8a7c15440b3c370fd649a885` at the exact ML-00 frontier
`2ab1c51a2404086cbd688ac80154765d7c5d4662` as coordinator product commit
`422150d4fabdcc703952797875f88f239ca1e37a`, with no cherry-pick conflict.
The superseded `f83038d371888cca87f0f04d0e61906d499668eb` was not
cherry-picked. ML-01 adds the fixed bundled Data Service plugin manifest and
capability projection, atomic project plugin selection service, package-owned
Skill/SDK resource move, and core Skill registry projection. The coordinator
foreign ML-01 task record is removed in the docs checkpoint while its source
record remains in
`D:\Datas\OthersProjects\makelore-plugin-ml01-package-selection-8d3c7a21`.
The exact downstream product frontier handed to ML-02 is
`422150d4fabdcc703952797875f88f239ca1e37a`.
- Integrated ML-02 from source task
`20260827-plugin-ml02-policy-registry-3f7b2c91` and sole source commit
`0064043c8f1e0e80c0b73dd0064b3abe8ba30b01`, whose exact parent was the
coordinator frontier `d9c9a2b0dd8fd495c6aa5a0994598192ad9c8e58`.
The cherry-pick produced coordinator product commit
`a0361a3cda08ab4d7454d35caa56a5a4304a9dca` without conflict. The foreign
ML-02 task record was deleted from this coordinator while its source record
remains in
`D:\Datas\OthersProjects\makelore-plugin-ml02-policy-registry-3f7b2c91`.
ML-02 consumes the frozen WS-02 catalog DTO: schema version 1, one
`makelore.data-service` plugin, three capabilities/fourteen operations, and
`platform_metered` unavailable projected as `billing_unavailable`. The
coordinator-approved one-time ownership transfer covered only the
`ToolDetails` envelope discriminator/display branch in
`src/pages/Chat/CodingConversationTimeline.tsx`; no other Renderer,
worker, Host, preview, or P1 path was transferred or changed. The exact
downstream product frontier handed to ML-03 is
`a0361a3cda08ab4d7454d35caa56a5a4304a9dca`.
- Integrated ML-03 from source task
`20260827-plugin-ml03-worker-materialization-9b2e6c41` and sole source commit
`945d6bd81016eec373a82f63182cf1f7cf0718f5`, whose exact parent was the
coordinator frontier `c4dd8923a0076920e8a7fd8820fdc01bdfde1760`.
The cherry-pick produced coordinator product commit
`fd891ff3bb87a29381a0a7006fb4618ec4fe144f` without conflict. The foreign
ML-03 task record was deleted from this coordinator while its source record
remains in
`D:\Datas\OthersProjects\makelore-plugin-ml03-worker-materialization-9b2e6c41`.
ML-03 owns exactly six Pi product files and five Pi-focused tests: one frozen
effective worker-resource snapshot, dynamic Skill/declaration/bridge/CLI
materialization, child-empty exposure, known-disabled/re-enabled assignment
behavior, old-worker refusal, and removal of the static Data Service worker
list. The source task execution briefly shared a worktree with an earlier
agent; that agent was interrupted when discovered, and the final commit was
then fully reviewed by serial takeover. This record does not claim that the
source task was never concurrently shared. The exact downstream product
frontier handed to ML-04 is
`fd891ff3bb87a29381a0a7006fb4618ec4fe144f`.
- ML-04 and ML-05 are integrated through their exact dependency frontiers. ML-04
composes the bounded Main-owned project plugin Host projection and lifecycle;
ML-05 adds the project-level Plugin Center and typed Data Service settings without
moving project, credential, policy, or billing authority into Renderer.
- ML-06 completed from exact post-ML-05 checkpoint
`8fea40238fcb6431fd805c7dd0d717bef0cfd1bb`. Packaged-proof commit
`7141a91a2c1c00881b18702508d2be8a398a0823` verifies the bundled plugin
manifest, capability manifest, Skill, TS/JS SDK assets, adapter/tool catalog,
core coding resources, and final Pi runtime artifact. The implementation range
contains no arbitrary plugin execution, generic invoke/config/ledger,
marketplace, publication coupling, `plugin_charges`, Plugin Credits, or P1 code.
- The first ML-07 fixed-range review over exact `eb5d15d...9407c67` returned
Standards FAIL and Spec FAIL. Ten independent accepted root causes were assigned
to one isolated remediation owner; the package-parser duplication finding was
reported by both axes and counted once. Source remediation commit
`2492f8af5ba27d914b2c0b2789b46f78305c924d` had exact parent
`9407c67df21c2f0f50bb0362c826fcff643d9d5f` and was integrated without conflict
as coordinator product commit `cf13aa7`. The foreign remediation task record is
removed from this coordinator while remaining in its source worktree.
## Verification
- `git rev-parse HEAD` before the checkpoint returned exact
`eb5d15d68470b30ec181164f08f0d7b027ef0006`.
- The fresh worktree initially had no `node_modules`, so the first typecheck failed
only because `tsc` was unavailable. `corepack pnpm install --frozen-lockfile`
installed the locked 997-package graph with pnpm `10.33.4`; no source or lockfile
changed.
- `corepack pnpm run typecheck` then passed.
- The nine-file Data Service/Pi/package baseline (`data-service-sdk-assets`,
`data-service-server-registration`, `pi-product-tools`, `pi-extension-host`,
`pi-worker-process-real`, `coding-conversation-contracts`,
`preview-data-session`, `data-service-routes`, and `pi-product-artifact`) passed
`70 passed, 2 skipped` in 10.21s with one worker.
- No client product file changed; only this task-scoped record is committed by
ML-00. The root `main` worktree was restored clean at `f245603...` after an
initial task-context claim selected the clean root despite isolation arguments;
the generated record/claim were removed through the normal release path before
the successful isolated start from `eb5d15d...`.
- ML-01 precondition and merge: coordinator was clean at exact frontier
`2ab1c51a2404086cbd688ac80154765d7c5d4662`; replacement source parent matched
exactly; cherry-pick produced `422150d4fabdcc703952797875f88f239ca1e37a`
without conflict.
- ML-01 focused verification:
`corepack pnpm exec vitest run tests/unit/data-service-sdk-assets.test.ts
tests/unit/coding-plugin-manifest.test.ts tests/unit/project-plugin-service.test.ts
tests/unit/skill-display.test.ts tests/unit/pi-product-tools.test.ts
--maxWorkers=1` — 5 files / 45 tests passed (Vitest 3.15s).
- ML-01 `corepack pnpm run typecheck` — passed.
- ML-01 `corepack pnpm run lint:check` — passed with 0 errors and the same 5
pre-existing warnings in `src/pages/Home/index.tsx` and
`src/pages/Makelore/index.tsx`.
- Scoped ESLint over ML-01-owned source/tests — passed with no output.
- The Skill and SDK resource move is byte-for-byte (`R100`). The ML-01-owned
`tests/unit/data-service-sdk-assets.test.ts` assertion now targets the
canonical package path and passed; this merger did not edit unrelated tests.
Any remaining consumer of the removed legacy
`resources/coding-skills/data-service` path must migrate under its owning
ticket, not this merger.
- ML-01 path/scope audit matched the source change set: package manifest/service,
existing Skill registry/shared definitions, plugin resources, and focused tests
only. No P1 policy/capability-invoke, Pi runtime, Host, Renderer,
marketplace/download/update, generic execution, pricing, or billing paths were
added. `git diff --check` passed.
- ML-02 precondition and merge: coordinator was clean at exact frontier
`d9c9a2b0dd8fd495c6aa5a0994598192ad9c8e58`; source commit
`0064043c8f1e0e80c0b73dd0064b3abe8ba30b01` had that exact parent and
cherry-picked without conflict as
`a0361a3cda08ab4d7454d35caa56a5a4304a9dca`. The source change set was
limited to the policy client, capability registry/Data Service adapter, Pi
product-tool delegation, bounded shared contracts, focused tests, and the
one approved timeline branch. No other Renderer, worker, Host, preview, or
P1 file was present; the source task record remains in its worktree.
- ML-02 focused verification:
`corepack pnpm exec vitest run tests/unit/plugin-policy-client.test.ts
tests/unit/coding-capability-registry.test.ts
tests/unit/data-service-plugin-adapter.test.ts tests/unit/pi-product-tools.test.ts
tests/unit/coding-conversation-contracts.test.ts --maxWorkers=1` — 5 files /
38 tests passed (Vitest 3.26s).
- Transferred timeline verification:
`corepack pnpm exec vitest run tests/unit/coding-conversation-timeline.test.tsx
--maxWorkers=1` — 1 file / 4 tests passed (Vitest 1.65s).
- Relevant adjacent regressions:
`coding-plugin-manifest`, `project-plugin-service`, `skill-display`,
`coding-chat-panel`, `coding-product-services`, `coding-product-tools-facade`,
`data-service-client`, and `data-service-routes` — 8 files / 57 tests passed
(Vitest 9.69s, one worker).
- `corepack pnpm run typecheck` — passed. `corepack pnpm run lint:check` —
passed with 0 errors and the same 5 pre-existing warnings in
`src/pages/Home/index.tsx` and `src/pages/Makelore/index.tsx`.
- Product contract audit passed: no `details.schema === 'data-service.v1'`
consumer remains; every `data-service.v1` occurrence in `src/`, `electron/`,
`shared/`, and `tests/` is the nested `payload_schema` contract. The ML-02
net change passed `git diff --check`.
- ML-03 precondition and merge: coordinator was clean at exact frontier
`c4dd8923a0076920e8a7fd8820fdc01bdfde1760`; source commit
`945d6bd81016eec373a82f63182cf1f7cf0718f5` had that exact parent and
cherry-picked without conflict as
`fd891ff3bb87a29381a0a7006fb4618ec4fe144f`. The merged change set contains
exactly six Pi product files and five named Pi tests, with no other Host,
Renderer, registry, preview, or P1 path; the source task record remains in
its worktree. The source execution's brief shared-worktree incident and
interruption were retained accurately; the merger's review and verification
were performed serially after takeover.
- ML-03 owned focused verification:
`corepack pnpm exec vitest run tests/unit/pi-resource-loader.test.ts
tests/unit/pi-extension-host.test.ts tests/unit/pi-extension-bundle.test.ts
tests/unit/pi-worker-process-real.test.ts tests/unit/pi-rpc-foundation.test.ts
--maxWorkers=1` — 5 files / 43 passed / 2 skipped (Vitest 7.65s; the skips
are staged-runtime gated).
- All Pi regressions:
`pi-*.test.ts` — 30 files / 169 passed / 2 skipped (Vitest 19.34s, one
worker).
- `corepack pnpm run typecheck` — passed. `corepack pnpm run lint:check` —
passed with 0 errors and the same 5 pre-existing warnings in
`src/pages/Home/index.tsx` and `src/pages/Makelore/index.tsx`.
- `corepack pnpm run build:vite` — passed for Renderer, Main, Preload, and
utility bundles; only existing dynamic-import/chunk-size warnings were
emitted. The ML-03 changed files contain no static Data Service worker list;
dynamic declarations, bridge allowlisting, CLI agreement, child-empty
exposure, disabled/re-enabled assignment, and old-worker behavior are
covered by the owned focused suite. `git diff --check` passed.
- ML-04 precondition and merge: coordinator was clean at exact frontier
`a92cd904d33d4fa0b7c2413188186852a39eb6d4`; source commit
`1e925bc10ade8aed1a580362dfa65223993e3a24` had that exact parent and
cherry-picked without conflict as
`a18727ecf8f40c1d85e2d40922bcf3bc8d1a0ed3`. The product change set contains
four Main API files (`coding-composition`, `coding-product-services`,
`route-handlers`, and `routes/coding-plugins`), three new focused tests, and
one existing Data Service server-registration test update. There are no
changes to `project-service`, preview, Renderer, P1, `electron/api/context.ts`,
`electron/api/server.ts`, or `electron/main/index.ts`; the source task record
remains in its worktree.
- ML-04 focused verification:
`corepack pnpm exec vitest run tests/unit/coding-plugin-routes.test.ts
tests/unit/coding-plugin-composition.test.ts tests/unit/coding-plugin-lifecycle.test.ts
tests/unit/coding-product-services.test.ts tests/unit/data-service-server-registration.test.ts
tests/unit/coding-core-routes.test.ts tests/unit/coding-project-identity.test.ts
tests/unit/main-quit-lifecycle.test.ts --maxWorkers=1` — 8 files / 47 tests
passed (Vitest 4.73s). The route tests confirm exact GET
`/api/coding/plugins?projectId=...` and PUT `/api/coding/plugins/{plugin_id}`
bodies with Main-only authority; composition/lifecycle tests cover bounded
projection and `list`/`setEnabled`/`deactivate` wiring.
- ML-04 adjacent policy/capability/Data Service/Pi/preview regressions:
`coding-capability-registry`, `plugin-policy-client`,
`data-service-plugin-adapter`, `coding-conversation-contracts`,
`pi-product-tools`, `data-service-routes`, `data-service-sdk-assets`,
`pi-extension-bundle`, `pi-extension-host`, `pi-resource-loader`,
`preview-data-session`, and `pi-worker-process-real` — 12 files / 86 passed /
2 skipped (Vitest 8.37s, one worker; skips are staged-runtime gated).
- `corepack pnpm run typecheck` — passed. `corepack pnpm run lint:check` —
passed with 0 errors and the same 5 pre-existing warnings in
`src/pages/Home/index.tsx` and `src/pages/Makelore/index.tsx`.
- `corepack pnpm run build:vite` — passed for Renderer, Main, Preload, and
utility bundles; only existing dynamic-import/chunk-size warnings were
emitted. `git diff --check` passed.
## ML-05 Integration
- Integrated ML-05 from source task
`20260827-plugin-ml05-plugin-center-6c1e9a42` and sole source commit
`379e575efba8cecb17b10e5e195f05924b827782`, whose exact parent was the
coordinator frontier `b6d9e6156fdc98aa792045692cc25fdce993a531`.
The cherry-pick produced coordinator product commit
`cb1fd2629ce861f72eada35a83e730986fb1c3d1` without conflict. The source
commit contained its source task record plus fourteen Renderer/product-test
files; the foreign task record was deleted from this coordinator in this
checkpoint while the source record remains in
`D:\Datas\OthersProjects\makelore-plugin-ml05-plugin-center-6c1e9a42`.
ML-05 adds the project-scoped Plugin Center, typed project-plugin client/store,
Data Service settings surface, and project navigation. It does not add Main
authority, worker, preview, policy, marketplace, or P1 behavior. The exact
downstream product frontier handed to ML-06 is the post-merge docs checkpoint
recorded below.
- ML-05 focused regression command (using the repository's actual singular
`coding-plugin-routes.test.ts` filename) passed 13 files / 75 tests in 8.64s
with one worker. `corepack pnpm run typecheck` passed. `corepack pnpm run
lint:check` passed with 0 errors and the same 5 pre-existing warnings in
`src/pages/Home/index.tsx` and `src/pages/Makelore/index.tsx`.
- `corepack pnpm run build:vite` passed for Renderer, Main, Preload, and utility
bundles with only existing dynamic-import/chunk-size warnings. After this
required build, `corepack pnpm exec playwright test
tests/e2e/project-plugins.spec.ts --config=playwright.config.ts` passed 1/1
test in 1.7s. A preliminary direct Playwright invocation against stale
`dist-electron` timed out waiting for the new navigation test id; it is not
counted as a product failure because the repository E2E contract builds first.
## ML-06 Merge, Package Proof, And Verification
- Exact ML-06 base/checkpoint:
`8fea40238fcb6431fd805c7dd0d717bef0cfd1bb`; packaged-proof product head:
`7141a91a2c1c00881b18702508d2be8a398a0823`. The product commit changed only
`scripts/lib/pi-product-artifact.mjs` and
`tests/unit/pi-product-artifact.test.ts`; no semantic merge conflict or
ownership transfer occurred.
- `corepack pnpm exec vitest run tests/unit/pi-product-artifact.test.ts
--maxWorkers=1` — 1 file / 7 tests passed.
- `corepack pnpm run typecheck` — passed. `corepack pnpm run lint:check` —
0 errors and the same 5 pre-existing warnings in `src/pages/Home/index.tsx`
and `src/pages/Makelore/index.tsx`.
- `corepack pnpm test` — normal suite 200 files / 1,667 passed / 2 skipped,
followed by the isolated pressure suite 1 file / 1 passed. Combined result:
1,668 passed / 2 staged-runtime skips.
- `corepack pnpm test:electron:windows` — 2 files / 5 tests passed.
- `corepack pnpm test:e2e` rebuilt Renderer/Main/Preload/utility and completed
26 passed / 1 failed. The failure exactly reproduces the frozen baseline:
`pi-coding-first-chat.spec.ts` timed out after 30 seconds because the existing
`当前对话模型` combobox remained disabled at `selectOption`. The new
`project-plugins.spec.ts` passed. The failure is recorded, not converted to a
pass and not attributed to Plugin Center.
- A fresh `corepack pnpm run package:win` rerun could not reacquire fixed uv
`0.10.0`: GitHub first reset the connection and the one targeted retry timed
out before product packaging. The worktree remained clean. The already-built
Windows artifact was independently verified as current head rather than
assumed from its timestamp:
- `corepack pnpm run verify:artifact:win` passed and reported both
`gitCommit` and `verificationHead` as exact
`7141a91a2c1c00881b18702508d2be8a398a0823`, with packaged
Python, uv, npm, Electron, Node, and native modules present.
- `corepack pnpm run verify:artifact:pi` passed the outer product-artifact
contract and proved one `makelore.data-service` package, its manifest,
capability manifest, `data-service` Skill, both SDK assets, adapter, exact
ten-tool catalog, core coding resources, Pi closure, and packaged runtime
probe. The nested legacy runtime report remains `partial-pass` only for its
recorded cross-platform/real-provider waivers; no such waiver is promoted to
a Plugin Platform pass.
- `git diff --check eb5d15d...7141a91` passed. Full-range path/content review
found only canonical manifest/registry lists and negative unsupported-component
tests; it found no static Pi CLI Data Service allowlist, arbitrary execution,
generic ledger/config/invoke, marketplace/publication coupling, checksums, or
P1 implementation.
## ML-07 First Review And Remediation
- Fixed range `eb5d15d68470b30ec181164f08f0d7b027ef0006` through
`9407c67df21c2f0f50bb0362c826fcff643d9d5f`: Standards FAIL and Spec FAIL.
Accepted issues were production package-parser/static-definition duplication,
disabled Skill implicit activation, missing preview/exact operation policy join,
the direct Pi Data Service fallback, missing request/fault evidence, unbounded
policy fetch/body, ready-enable settings loss, unsafe Skill-ID typing,
out-of-order project-load commits, and stale README inventory.
- The sole remediation commit makes the parsed frozen package definitions the Main
authority; projects three capabilities/fourteen exact operations while keeping
preview non-tool; removes the second Pi direct path; makes disabled retained Skill
availability explicit; bounds policy refresh; preserves ready settings on enable;
uses `CodingSkillId`; guards A/B loads; and updates README.
- Source verification: focused 10 files / 60 tests; full 202 files / 1,680 passed /
2 staged-runtime skips; typecheck passed; ESLint 0 errors with the same 5 existing
warnings; full Windows build/NSIS passed; Pi artifact proof passed with four core
Skills plus the package-owned Data Service. Stable replay and one-401-refresh
request identity remains `pi:run-a:resource-a`; all ten tools traverse the real
adapter/registry/conversation parser with bounded quota, size, revision, and
Retry-After contexts.
- Repeat Standards and Spec review must use the unchanged base `eb5d15d...` and the
post-remediation coordinator documentation checkpoint as its exact head.
## ML-07 Repeat Review And R2 Remediation
- Repeat fixed-range review over exact `eb5d15d...29cf322` confirmed the first
remediation but returned Standards FAIL and Spec FAIL on four remaining issues:
the Data Service adapter still consulted a static tool-definition catalog; late
project-A mutations could overwrite loaded project B; persisted reconnect/replay
identity evidence was still a direct repeated invocation; and child/core-only
workers still waited on optional policy refresh.
- The same sole remediation implementer returned source commit
`278e53304a10a0336b8b737b85c158c5f2a40d84` with exact parent
`29cf322f1ac0500295c1afec076800aea3908eb3`; it integrated without conflict as
coordinator commit `f0ac7d7`. The foreign source task record is removed here and
remains in its isolated source worktree.
- The adapter now validates the parsed registry-supplied tool; project-scoped enable,
configure, reset, collection removal, and project removal all reject stale
generation/project completions; policy refresh occurs only for an assigned
server-backed parent; and the extension bundle test persists run/resource identity,
reconnects/reimports, replays the same resource through the authenticated bridge
and real registry, and preserves exact
`pi:persisted-run:persisted-resource`.
- Source verification: affected 8 files / 44 tests passed; typecheck passed; focused
ESLint clean and full lint 0 errors with the same 5 existing warnings; Windows
staged/unpacked build passed; Pi packaged artifact verification passed.
Coordinator `corepack pnpm test` passed 201 normal files / 1,685 tests with 2
staged-runtime skips, followed by the isolated pressure file 1/1 (202 files /
1,686 passed / 2 skipped total).
## ML-07 R3 Review And Remediation
- The third fixed-range Standards and Spec reviews over exact
`eb5d15d68470b30ec181164f08f0d7b027ef0006...405b9f64fd6872f6b4bd4c4429e6aaff2fa0b84a`
agreed on one remaining medium-severity root cause: a same-project manual refresh
could race enable/configure/reset/removal mutations, allowing an old GET to
overwrite a successful mutation or causing the successful mutation and its
authoritative reload to be discarded.
- The same sole remediation implementer returned source commit
`92bce15a7e70440e78b2ff8d90b2e57470d14d77` with exact parent
`405b9f64fd6872f6b4bd4c4429e6aaff2fa0b84a`; it integrated without conflict as
coordinator commit `e3e34d3`. The foreign source task record is removed here and
remains in its isolated source worktree.
- A per-project operation epoch now separates internal load flights by project and
epoch. Successful mutations advance the epoch before committing, so reads begun
before or during the mutation cannot win and post-mutation authoritative reloads
cannot coalesce with stale flights. The existing stable public pending key and the
latest-requested-project A-to-B guard remain intact.
- Source verification recorded the expected red failures for all supported race
orderings, then 13/13 store tests and 4 files / 22 expanded focused tests passed;
typecheck, scoped ESLint, full lint, diff, documentation drift, and task completion
gates passed. No UI, Main, Preload, package, or asset ownership was used.
- After integration, coordinator `corepack pnpm test` passed 201 normal files /
1,692 tests with 2 staged-runtime skips, followed by the isolated pressure file
1/1 (202 files / 1,693 passed / 2 skipped total). Coordinator typecheck passed;
full lint reported 0 errors and the unchanged 5 warnings in Home and Makelore.
## ML-07 R4 Review And Remediation
- The fourth fixed-range review over exact
`eb5d15d68470b30ec181164f08f0d7b027ef0006...07ea9da858b4a412191747a6c80f465cf2d46d45`
returned Spec PASS and Standards FAIL on one supported remaining load-ordering
case. With A1 pending, then B pending, selecting A again reused A1 before
renewing its generation, so B retained the only committable generation and
could leave the active A page displaying B's projection.
- The same sole remediation implementer returned source commit
`d0addfa743d97d4ac9c3385a1d364f94b1ccf6d5` with exact parent
`07ea9da858b4a412191747a6c80f465cf2d46d45`; it integrated without conflict as
coordinator commit `7fab721`. The foreign source task record is removed here
and remains in its isolated source worktree.
- Each keyed load flight now owns a mutable generation token. Reselecting that
same key/epoch after another project intent intervenes promotes the shared
flight to a new global generation before returning it; consecutive same-project
duplicate loads still share one request and one promise. B therefore loses
commit eligibility, while A completes without a manual retry and the stable
public pending key remains unchanged.
- Source red evidence was 2 new failures with 13 existing passes; after the fix,
store tests passed 15/15 and the expanded four-file suite passed 24/24.
Typecheck, scoped ESLint, full lint with 0 errors and the unchanged 5 warnings,
diff, project-documentation drift, and task completion gates passed. No UI,
Main, Preload, package, or asset ownership was used.
- After integration, coordinator `corepack pnpm test` passed 201 normal files /
1,694 tests with 2 staged-runtime skips, followed by the isolated pressure file
1/1 (202 files / 1,695 passed / 2 skipped total). Coordinator typecheck passed;
full lint reported 0 errors and the unchanged 5 warnings in Home and Makelore.
## ML-07 R5 Final Review And Cross-Repository X-01
- The final independent Standards and Spec reviews both PASS with zero
actionable findings over fixed range
`eb5d15d68470b30ec181164f08f0d7b027ef0006...78fb7d730731a7b0ebadf12418ca4c2eb6ef3310`;
the merge base is the exact accepted Data Service base and `git diff --check`
is clean. R5 reconfirmed the intent-aware A1/B/A2 shared-flight fix in both
completion orders, the R3 mutation epochs, the complete package-to-policy-to-
Pi-to-preview authority chain, and all P0 exclusions.
- Exact-head coordinator verification is 201 normal files / 1,694 passed / 2
staged-runtime skips plus the isolated pressure file 1/1, for 202 files /
1,695 passed / 2 skipped total. Typecheck passed; full lint has zero errors and
the unchanged five out-of-range Home/Makelore warnings. The reviewers did not
represent their dependency-free fresh worktrees as additional test passes.
- X-01 ran against this exact client head and server head
`e862a74532a1e57086659f3bf3201ea17e7b60a8`. The packaged Windows artifact was
independently verified at the exact client head; its installer SHA-256 is
`ED2C4BA9337E53446E73EFFC305B0082A4E1FE3C454238495EDA7B9A94F2D677`.
The Pi artifact proof contains one Data Service package, five fixed package
files, exactly ten tools, and four core Skills.
- The final live harness exited zero with all implementation-spec section 10.3
groups `1` through `12` passing against PostgreSQL 16.13 and the packaged,
normally initialized, signed-in application. The real parent provider request,
persisted worker context, and live Pi CLI all carried the same exact ten Data
Service tools; the real child carried none. All ten tools executed and produced
`makelore-capability.v1` details.
- Enable created only local selection. Configure created the backend and the Skill
installed the byte-exact packaged SDK. Exact-Origin preview put/get succeeded;
disable rejected an old-worker new invoke, invalidated preview, removed the Skill
from the next worker, and preserved cloud data; re-enable restored the retained
assignment/backend/data. Move, rename, raw copy, independent copy, bind-existing,
and a second signed-in owner with the same durable ID all matched the frozen
identity/owner-isolation contract.
- Live faults preserved quota `current=20/limit=20`, size
`actual=40011/limit=32768`, revision `current_revision=1`, and rate
`retry_after_seconds=46`. The size case used the server's supported isolated
32 KiB configuration so it could traverse the bounded 64 KiB Pi bridge; no
committed limit changed. Catalog first-failure/current/stale states, exact
three-capability/fourteen-operation join, and included-only billing all passed.
- Plugin Center showed `当前包含,不按单次调用扣点`; Data Service usage reached
120 documents while real Token Point transactions stayed `0 -> 0`. Preview
invalidation passed for disable, identity change, project switch, cross-Origin
navigation, Agent Browser renderer crash, logout, and Main shutdown.
- With 20 live instances/120 documents retained, server downgrade to `0063`
refused and left exact Alembic head `20260827_data_service_0064`; this is the
server-first rollback boundary, not a repository-test inference.
- Final cleanup stopped only the verified acceptance IdP helpers, removed the
exact disposable PostgreSQL container, and moved the exact X-01 temp directory
to the Windows Recycle Bin. All acceptance ports are closed; the container and
original temp path are absent. The recycled temp directory remains recoverable.
## Follow-ups
- None. No PR, push, publication, or user root-worktree mutation was performed.
## Promotion Candidates
- None recorded.