65 KiB
Current State
This file is the integrated default-branch snapshot. Feature tasks record progress in 30-worklog/tasks/{task_id}.md and propose canonical changes for the Integration Gate. Feature tasks must not rewrite this file; it changes only in integration mode.
Integrated Through
- Unified Plugin workspace product head
d7058e6383f1e9dd72c32570cf83b9f439d91033is integrated on localmainby task20260903-plugin-navigation-integration-4f7c2a96after fixed-range R4 Standards and Spec review passed with zero findings. Code now has one canonical/pluginsroute and one插件sidebar entry; the former Marketplace, My Plugins, and Project Plugins routes are replace-only redirects into deterministic filters. A pure Renderer projection composes official catalog/Library/device state, local Device Packages, current-project state, and retained IDs while preserving their existing owners and source-qualified identities. Local Skill/extension installation remains conversation-only, native selected-model Web Search remains outside the Plugin list, and partial source failures do not erase other sources. Focused 83-test, typecheck, full-unit, lint, Vite, and targeted 4/4 Electron evidence passed across implementation, remediation, and final acceptance. No server contract, runtime, billing, package, deployment, publication, or user-machine installation changed. - Packaged Device Package preparation source
5a2f0eb6785b59d8b455ed5cb1d9773351ff895afrom task20260902-local-skill-install-fix-6b3e91a4and installed-resource activation source17664c5fffcfe695653b4146503e645f54767c4bfrom task20260903-load-installed-resources-8f3c1a72were verified in integration candidatebd377c9and promoted to localmainby task20260903-promote-installed-resources-main-5c8e1a72. Packaged inspection now imports package-management authority from the distributed physical Pi runtime instead of the incompleteapp.asardependency graph. The parent Agent Server keeps the generated Makelore bridge as its required first extension and loads every further Main-selected, installed, and enabled Device Package extension through Pi0.84.2's explicit additional-extension input; all selected Skill paths remain intact and ambient discovery remains disabled. Packaged prepare passed for loose Skill, npm, and Git sources without committing a package, and a real Agent Server regression registered commands from two external extensions. Focused/full unit and pressure tests, typecheck, scoped lint, production build, Windows packaging, and artifact/runtime verification passed across the two source tasks. The currently installed 1.2.6 client was not replaced; rebuilt exact-main installation and live prepare/confirm/activation remain release acceptance work. - Youth-facing AI Design client source
0fd32a2d49045a8f9e7f2e19ba6477f48f93e30cis integrated over Model Tools frontier7552cf59526449c29d663a769c0fb62d84a1a759through merge16157388afc2f6103aaee0bfd3c4e4e80c8fec48with startup correctionc5447ae90c434c06dbafa724b229d8459cb829d0by task20260902-design-youth-client-integration-7a6d3c92. Canvas now defaults to conversation plus one compact “我的创作” card for creators aged 8-16, with contextual “精细调整” instead of an always-visible professional field matrix. The card remains a pure projection of the canonical V2 Current Specification; direct choices use typed commands, Quote blockers follow Specification revision, terminal blocked Quotes settle pending operations, and code-based Chinese copy prevents raw compiler/Provider text from reaching the youth UI. Video editing preserves stable canonical Shot identities and all hidden production metadata for up to 24 Shots. No database, DTO/API, pricing, Provider route, or compatibility path changed. Integration verification passed 40 focused youth tests, 5 Device Package tests, typecheck, scoped lint, production build, and 2 Electron E2E flows. The Electron run also exposed and closed an existing current-frontier startup crash: the ESM-only Pi package manager is now loaded only when remote Device Package installation needs it. No package, deployment, publication, push, or paid request is claimed. - Model Tools and Device Packages client cutover is implemented by task
20260902-model-tools-client-integration-5d8b2f73. Web Search is now a parent-only core tool of the frozen selected model/provider/credential; it no longer depends on Marketplace acquisition, Release, Admission, the hosted client, or Plugin Token Point receipts, and it never falls back toagent_browser. Electron Main also owns a conversation-only Device Package manager for npm, Git, local Plugin directories, and looseSKILL.mdsources. Preview and a distinct confirmation turn precede immutable local commit; lifecycle scripts stay disabled; new and idle parent workers refresh automatically while active workers switch after settlement; child workers remain empty. At that frontier My Plugins separated Official Plugins from Device Installed packages and exposed no visible install picker; the unified/pluginsworkspace recorded above now presents those sources together without merging authority. The later packaged prepare and multi-extension activation corrections are recorded above; rebuilt exact-main installed-client acceptance and real selected-model search remain external gates. No paid Provider request, production install, publish, push, or PR is claimed. - Windows titlebar Logo-overlap correction source
99a210e244731d1cdc923e9dd4adf6e09e64c2a4from task20260901-windows-titlebar-logo-overlap-5100e298is integrated onto localmainthrough product commite800d42595484389432fd08b11c2202074a7009eby task20260902-windows-titlebar-integration-afc9e259. The sharedProductTitleBarnow uses one 148 px Windows caption-control region (three 44 px buttons plus 8 px padding on each side) both to size the control wrapper and to inset the Makelore Logo. Canvas and Coding Electron geometry checks confirm that the Logo ends before the minimize button; macOS keeps its zero inset and native traffic-light behavior. Focused 11-test, full 1,788-test plus pressure, typecheck, scoped/full lint, Vite build, and two Electron E2E checks passed. No package, deployment, publication, backend contract, or unrelated product layout changed. - Web Search unavailable-Release diagnostic correction source
2e093bd22c0a3c46cc08b8eede8c1bc02afd690bfrom task20260901-web-search-runtime-stale-r2-6f4a2d91is integrated on localmainthrough product commit93e3143by task20260902-web-search-client-integration-a4c8e291. When the server resolve API explicitly returnsaction='unavailable'forplugin_release_not_readyorplugin_client_incompatible, Electron Main now preserves the existing typedplugin_release_unavailableresult instead of mislabeling it as the unrelated frozen-workerplugin_runtime_staleerror. Exact Release, Account/project, policy, Admission, Provider, confirmation, billing, and child-isolation gates are unchanged. The current installed client still predates this diagnostic correction, and actual usability still requires Works Square to deploy/apply the missing official bundled Release and compatibility migrations; no package, restart, deployment, publication, or paid Provider request occurred. - Web Search frozen-worker stale-Library correction source
3620cdc277fa0a99757c57a549008f9ecd380558from task20260901-web-search-stale-resources-8b4e2c71is integrated onto localmainthrough product commit40e1912by task20260901-web-search-stale-integration-9c5f3d82. Live client evidence showed an eligible parent worker with the official Web Search Skill, tool, Release and policy failing409 plugin_runtime_stalebecause invocation re-ran full materialization and treated one transient Account Library refresh as permanent worker invalidation. New workers still require a current Library; a previously frozen worker may now use the last verified Library projection only long enough to obtain the server-owned exact Release Admission. Account/session change, project disable, acquisition removal, runtime suspension, Release/version change, policy/billing gates and child isolation remain fail closed. Focused 19, adjacent 55, full 1,786 plus pressure, typecheck and scoped lint passed. The currently running installed binary predates this source fix; no restart, package, deploy, publication or paid Provider call was performed. - Web Search Agent-assignment catalog fix source
612794463de1b14fd748202a00115c6f93c7346bfrom task20260901-web-search-tool-routing-fix-6f9d3b82is integrated onto localmainthrough product commitadc28db7855f8b1770f1c1d46af77b7cc88cfa1aby task20260901-web-search-tool-routing-integration-7a4e1c93. The unscoped partner Skill picker now lists every project-enabled Plugin Skill before first assignment and does not invoke runtime Admission resolution; Agent-scoped/runtime projections still use only the resolver-approved effective subset. This closes the confirmed circular state where an enabled Web Search Skill was hidden until already assigned, leaving the actual Pi worker with onlyagent_browser. Focused 45-test, full 1,785-test plus pressure, typecheck, and scoped-lint verification passed. Existing workers remain frozen; the affected local Agent assignment was corrected separately and takes effect on a new Conversation. - Official bundled Plugin client cutover is integrated on local
mainthrough product commit1530ac774091c7083dbff19e0fbd69e929ac8718by task20260901-official-bundled-plugins-client-integration-b8d5f3a2. Game Resource and Web Search now ship as exact schema-2 resource packages with MakeLore; their acquired Library entries resolve through the server Admission path without Package Store download, update, Beta, signature, or device-uninstall state. Project enablement, Agent assignment, parent-only materialization, Provider policy, confirmation, and Token Point billing remain enforced. The verified Windows installer embeds sourceb1657300f29f9744551f31029eb192ee82f01b92, is 208,297,578 bytes, and has SHA-256449288AF079E030F3F700F0FF1701971F7AB4806E0366CE989F4E8F2FE33ACA3. - Conversation abort reconciliation source
d2ef37bc4d7d3609cec0a55c4ae8ffb2734696d5from task20260901-conversation-abort-stall-6f4c2a91is merged into localmainas85900717906713d8343c2087eade904aead8f111through verified candidate599d1847f73a590690cbac2ee1c5bf36e8cd83f1by task20260901-merge-abort-main-a83d4c71. Both visible abort actions now call the Main-owned abort route and then silently reload only the target Conversation's authoritative Snapshot. This closes the installed 1.2.1 case where Pi had already recorded bash results and a final assistantstop, but Renderer missed the terminal SSE patch and a later valid abort no-op left the UI showing an executing turn. Pi0.84.2, Host API, replay, recovery, and background-lifecycle contracts are unchanged. Focused 35-test, 1,780-test full-suite plus pressure, typecheck, lint, production-build, and Electron E2E verification passed. The existing 1.2.1 artifact predates this fix; a newly versioned package and installed-client acceptance remain pending. - Agent Server background-sleep race fix source
12d7588b3ebd4d192c2e14ae285d4f6ddebeeb42from task20260901-agent-received-stall-8b6d4c21is merged into localmainasc2137c9f3f2e05441064cc90bfeed115363ac04eby task20260901-integrate-agent-stall-4f2c8a91. Background sleep now rechecks active Coding work after asynchronous worker cleanup before stopping the shared Agent Server, and a server start racing an in-flight stop waits for that stop and creates one fresh process. This closes the confirmed lifecycle windows that can leave a locally accepted prompt optimistic with no live Agent Server or Pi session write; accepted/uncertain prompts are still never auto-replayed. Source tests and a real Electron-Node Agent Server race test pass. The currently installed binary predates this integration; a rebuilt/reinstalled Windows package and repetition of the reported interaction remain pending release evidence. - Works-provisioned model-reasoning capability source
ae7936174208a1d13cdfd260d5c6f2b70b450b60from task20260901-server-model-capabilities-9e31b6c4is merged into localmainas6a8ebe1b671ca24150c2226b9111b9d07174e37bby task20260901-integrate-model-capabilities-9b3e7c1a, paired with Works Square source9e1b6886b360175f1ca1596fb07f71e3bf86c894. Electron Main now strictly normalizes and persists the optional safemodel_capabilitiesmetadata, removes a stale override when the field is absent, and includes it in Provider runtime-shape invalidation. Server levels override the verified local reasoning map; old servers and direct Providers retain the local fallback. DeepSeek exposesoff/low/high/max: Pi disables thinking withoutreasoning_effortforoff, and sends the exact enabled effort otherwise. Nativemaxreaches project persistence, Snapshot/Patch, Host API, runtime, and the composer label最高. Pi remains0.84.2; no one-api, dependency, package, deployment, or real Provider acceptance is claimed. - Marketplace weak-ETag interoperability fix source
b3cfe7e1ceb7da65ccc99214db09102b4fc1cacefrom task20260901-plugin-catalog-load-client-7d4a8c21is promoted to localmainby task20260901-plugin-catalog-main-integration-8e5c2a91through product commit38f2358. The Main-owned Marketplace client now accepts both strong and valid weak composite catalog ETags, preserves the exact received validator for the nextIf-None-Match, and retains catalog-generation and Token Point pricing identity checks. This closes the installed-client failure where the production gateway's compressedW/"plugins-..."response was incorrectly surfaced asplugin_backend_unavailable; it does not add a local fallback catalog or change server, Provider, trust, pricing, or billing authority. The rebuilt Windows 1.2.0 installer embeds verification head6083de6aee8942a78191ed18a00bfd9f4ba0902d, is 294,864,542 bytes with SHA-2561301AE189BCBD44AA0E373982981E80B324EC45CDDF8F30415C2810F68319C06, and was installed over the prior 1.2.0 at the existing user-selected location. The signed-in installed client then loaded the deployed generation-2 catalog and rendered exactly Data Service, Game Resource, and Web Search without the unavailable catalog error. At that checkpoint Game Resource and Web Search still showed no stable Release; the official bundled cutover recorded above supersedes that delivery model. - Packaged Pi Agent Server resolver fix source
7df245af5a04f62be48980831ff41987ba686009from task20260901-local-runtime-unavailable-8b42c7f1is promoted to localmainby task20260901-promote-local-runtime-main-a7c4e291through verified integration candidate42ea83c0cbad52432eca99e4161e0360bef3e219and source merge96402551f46d875ba3db0a2f625397aba2f332fb. Electron Main now starts only the shared Agent Server with Node'simport.meta.resolveparent-URL capability enabled, so the unchanged server script resolves@earendil-works/pi-aifrom the explicit packagedpi-runtimeroot instead of the siblingresources/resourcesdirectory. A production-shaped sibling-layout test reproduces the installed failure before the fix and initializes successfully through Electron Node after it; Pi remains pinned at0.84.2, and no bundle layout, Provider, Renderer, or recovery contract changed. The currently installed application predates this source integration; a rebuilt and verified Windows artifact plus first-Conversation acceptance remain pending. - Native Web Search client tickets MLW-01 through MLW-03 are integrated by source
coordinator
20260831-web-search-client-integration-7d2f5b94and promoted to localmainby task20260901-web-search-client-main-merge-5a9d3b82from reviewed coordinator closureae81949a49d7df3be4859e6c111235a991a504e4through product commit49de82c4860fd0b377070279b6411237dc6b9564; the final fixed-range Standards and Spec reviews passed at4de3feefe451dc34dc46b323e2ea5e0b4e4840e8with zero actionable findings, against frozen Works Square DTO frontiera49c696ebc4213e3d62ece780961efbe17576f8e. MakeLore now reuses the shared hosted Admission resolver, calls the single fixed Web Search typed route from Electron Main, materializes the signed Marketplace Skill/tool only in an eligible frozen parent Pi snapshot, and renders the closed billing receipt without parsing Web Search payloads in Renderer. The packaged Windows app proves that the route and receipt parser are main-reachable while OpenAI Provider authority is absent. The exact reviewed Windows package passed artifact verification; installer SHA-256 is2492F88BB6F813834ECD24B392EB8337220E131E746547851393E4885C4B5BEFandapp.asarSHA-256 is27EFABBB741F0A62CB58452801DD1D8893B8E5131EA1D30F74D610DEAD3F7A1D. Real PostgreSQL and paid OpenAI acceptance remain external HOLDs; production activation still requires the official Ed25519 key, OpenAI key/model, price, and privacy copy. No deployment, publication, push, or PR occurred. - Human-authorized takeover task
20260831-promote-main-merge-5e9c7a31completed the already-started localmainmerge as03a9e866d4366e0a1cb416e26b424fe981071310, recorded the transfer in2ca60445d41628f1fa10e132994d2e2954b0bd4f, and promoted verified integration tip93fba75f7493d21cffc28847ceae26fee52a00a8through mergeb928b9ac603b9797e89c1a6d8e561ad3c6eadf37. Localmainnow contains both local hosted-Plugin history and fetchedorigin/main38f85f6b5e4dc4e2c5e5b9f8f4506554cfd578f5; the promotion merge changed only canonical project memory and task records, not product code. No remote push, deployment, or publication was performed. - Hosted Game Resource Plugin source
fe656dd865f1941f1dc2d369ce3bb09efb955fd8and verification record421c8254d51318355faec3ae94f8e1cfd4d054c5from task20260831-meowa-hosted-plugin-client-8d3a5b72are integrated with fetchedorigin/main38f85f6b5e4dc4e2c5e5b9f8f4506554cfd578f5in merge372b5345dae57ce19d2630b24277596db284194cby task20260831-integrate-remote-main-6b3d9e1a. MakeLore now supports generic schema-2platform_hostedMarketplace packages and a provider-neutralmakelore.game-resourceadapter. Its Skill and tools enter only an installed, enabled, assigned, admitted parent Pi logical thread; child and ineligible threads receive no projection. Hosted mutations require explicit confirmation, keep stable logical operation identity across uncertain results, and travel only through Electron Main to fixed Works Square routes. The old always-mounted Meowa tools, direct proxy, local credential configuration, and package-time credential path are removed. Production activation remains held until the official signing key, rotated server credential, positive Token Point pricing, and server Admission gates are ready and verified. - Local source snapshot
33fb31fb285b5cfb00d194a036aaf6e21cf8c5a1, based on the prior local delivery48a9189, is integrated over fetched upstream62304dc85b3c1069cd656dfacb61ee820e216fa2in merge commit28897cd4a2b7179d9ccb444218a1d74a2bbc004bby task20260831-merge-upstream-main-7c3a91f2. The integration preserves Plugin Marketplace Release A and AI Design Living Form V2 while adopting one long-lived parent Pi Agent Server with isolated per-Conversation logical Runtime, Session, credential store, extension context, generation and JSONL channel. Parent logical turns remain capped at 4, warm idle threads at 8, and independent child processes at 4 against the FIFO process budget of 8..makelore/project.jsonand.makelore/conversations.jsonare authoritative; current code does not read or migrate project metadata from.niancodeor.opencode. - MakeLore curated Plugin Marketplace Release A source
40df677a31ff7651f962151eb84b925987781c03from task20260828-plugin-marketplace-client-5f8b3d72is integrated by task20260830-integrate-plugin-marketplace-client-6e3b9d82. Electron Main now owns the authenticated Marketplace/Library client, immutable Package Store, trusted release verification, effective installed-plugin resolution, and frozen Pi worker materialization. Its original Marketplace, My Plugins, and Project Plugins Renderer surfaces are superseded by the unified/pluginsprojection recorded above; Renderer still receives no credentials, paths, Admissions, or signed URLs. Data Service remains system-included and consumes zero Token Points. R7 Standards and Spec reviews passed with zero findings, and XMA-01 passed all twelve live groups against real PostgreSQL and a signed-in packaged Windows client. The laterplatform_hostedclient runtime is integrated above; production package trust and real Provider activation remain held behind the official signing key and the separate server, pricing, credential-rotation, and Admission gates. - AI Design Living Form V2 client source
b0b5a602b501308a23eb27e2f51a5169b9e46b1eis integrated with matching Works Square server sourceb5351d54f595ce8eb873593e462e4a556bea0b05by task20260830-integrate-marketplace-design-client-main-9d5f3b82. Canvas now exposes one current Direction, one persistent Agent Session, one Current Specification and Living Form, one conversation timeline, immutable Quotes, Tasks, and Assets. Chat, direct edits, decisions, locks, and Asset binding share one server reducer; Main is the only V2 transport authority, and V1 DTO/local semantic fallback paths are removed. Production database cutover, real-account installed-client smoke, and paid Provider activation remain separate operator gates. - Updater downgrade-prevention source commit
2e61800from feature task20260826-fix-version-update-check-7c91a4is integrated by task20260826-recover-pi-updater-integration-8f3a6c21. Every automatic-update channel assignment now immediately restoresautoUpdater.allowDowngrade=false, so installed2.0.0does not treat an online1.1.9manifest as an available update; later explicit channel changes preserve the same invariant. - Local
mainis integrated through delivery48a9189by task20260826-integrate-pi-provider-fix-6e4c2a91. The strict 101-commit fast-forward replaces OpenCode with pinned Pi0.84.2as Makelore Code's sole production runtime, adds schema-v2 project/Agent/Conversation storage, the predecessor persistent per-Conversation worker topology, product Snapshot/Patch contracts,/api/coding/*, Provider/resource isolation, extension/subagents, process and write budgets, and background-run uncertainty ownership. Implementationa098266additionally validates/persists an unresolved Conversation model before first prepare and converts the exact Works missing user-context response into a non-replayed Provider-auth failure after expiring the cached gateway credential. Task20260831-merge-upstream-main-7c3a91f2supersedes only that parent-process topology with the shared Agent Server described above. The final Windows installer and final packaged Pi proof passed; real Provider turns remain explicitly waived withrealTurnVerified=false, while macOS x64/arm64 and native non-WSL Linux remain unverified. Older OpenCode entries below are retained only as historical integration evidence and are superseded for current behavior. - OpenCode model-switch runtime correction source commit
cce7722from feature task20260821-model-switch-runtime-fix-a83d6c91is integrated on localmainby task20260821-integrate-model-switch-fix-8f2d6c41. The Main-owned client now maps Makelore's internalmodelIDto OpenCode 1.18.9's wire fieldid. An owned fresh runtime receives the current per-process Host API token when its local-proxy provider config is built, so persisting that already active token no longer creates a false manual-restart requirement; attached/unknown generations and timeout/partial persistence remain fail-closed. A rebuilt-client real local smoke is still pending. - Login-layout source commit
4d512b1from feature task20260821-remember-below-login-4a7c91d2was merged into localmainas22f4bbcby integration task20260820-integrate-remember-password-5d7e3a1c. Password login now places the existing remember-password control directly below the submit button and above the agreement; authentication, persistence, and secure-storage behavior are unchanged. - Remember-password source commit
990639ffrom feature task20260820-makelore-remember-password-b63e1cwas merged into localmainas2b9f84eby integration task20260820-integrate-remember-password-5d7e3a1c. Password login now offers an optional Main-owned remembered credential: packaged builds encrypt the username and password through OS-protected storage, Renderer persistence and Works Square never receive that record, and unavailable secure storage disables the option. Logout and SMS login preserve it; a successful unchecked password login clears it. Packaged Windows and signed macOS smoke remain pending. - OpenCode Session model and partner hot-add source commit
c0163bcfrom feature task20260820-session-model-agent-hotfix-6e4c9a2fis integrated on localmainby task20260820-integrate-session-model-hotfix-7b3e91c4. Page selection and/models//modelnow switch the active OpenCode Session model without provider persistence or runtime restart, while a partner model remains only the new-Session default. Agent readiness is tracked per id: a new unique id may be accepted after live discovery in an owned fresh generation, while same-id edits, delete/recreate and attached/unknown generations remain pending. - Learning archive size-validation source commit
8509084from feature task20260820-remove-download-size-check-4f8a2c1dis integrated by task20260820-integrate-download-size-6e3a91c2through merge0c1a360. Electron Main no longer rejects a project ZIP becauseContent-Length,archiveBytes, actual streamed bytes, or the former 512 MiB ceiling differ; same-origin redirects, SHA-256, ZIP signature, temporary-file cleanup, and atomic save remain enforced. - Direct Learning README-image source commit
9956739from feature task20260820-direct-readme-client-a4d8e2c7is integrated by task20260820-integrate-direct-readme-client-b7e41c9d. README Markdown image nodes now load validated credential-free HTTPS URLs directly, including SVG, while raw HTML, covers, historical media reads, and the Main-owned verified ZIP save path retain their existing boundaries. The matching Works Square source is65ea070. - Learning project-catalog source commit
38db158from feature task20260819-learning-project-catalog-impl-4e9c71a2was merged asd967b0fby integration task20260820-integrate-learning-catalog-a73e91c4. Learning keeps its login andmodule_access.learninggate but now contains only a server-driven project list, safe README detail, direct credential-free HTTPS Markdown images, and a Main-owned verified native ZIP save path. Course generation, progress, local library, OpenMAIC player, Agent/ASR/classroom runtime, Learning IPC and player-artifact packaging were removed without a compatibility read path. Historical course data is left untouched. The matching Works Square operations/admin/API implementation and real-account package smoke remain pending. - Square-auth lifecycle source commit
dc776fffrom feature task20260819-square-auth-proxy-client-8c4f2awas merged asf52c2c8and promoted from verified candidatee7ec12dto localmainby integration task20260819-promote-square-auth-client-73e4c1. Desktop login, refresh, and logout now use fixed Works Square endpoints; Electron Main remains the sole token owner, persists rotated credentials before exposing the refreshed session, and keeps the existing seven-day inactivity boundary. The client no longer embeds a confidential OAuth client secret or refreshes directly against the custom identity service. The matching Square service change must be deployed first. - AI Design request-freeze source commit
87e4140from feature task20260819-design-freeze-live-6e2cis integrated onmainthrough5bff5d3by promotion task20260819-promote-design-freeze-main-91c2e4. Main-owned Workspace JSON requests and shared Works token refreshes now have a complete 30-second lifecycle deadline, including response-body consumption. Timeout settles as stable504 DESIGN_WORKSPACE_REQUEST_TIMEOUT; low-level Electron-to-Node fetch fallback is limited toGET/HEAD/OPTIONS, so mutation failures are not implicitly replayed. The native password/SMS login and temporarydisable-http2diagnostic bootstrap remain included. Automated client verification does not yet prove the installed-client freeze is resolved or establish HTTP/2 as the root cause. - AI Design history source commit
bf0b805from feature task20260819-history-load-stall-a92dis integrated on localmain. Conversation reads start with the newest ten messages and fetch older pages through opaque cursors; the Canvas keeps its scroll position while prepending. A selected Conversation renders before generation-task reconciliation finishes, rapid A → B → A switching reuses an in-flight event-stream open, and a pending relay/open has bounded cleanup. This is a local source integration only; no packaged-client or deployed-service smoke is claimed. 6478591/3a6d388: AI Canvas task-stream reconciliation now reuses an in-flightconnectingConversation stream instead of opening a duplicate; rapid Conversation-switching regression coverage is present. Canonicalmainpromotion is pending release of the occupied main worktree, and real slow-handshake Electron smoke remains pending.ce897f1/6504073: AI Programming now isolates prompt lifecycle, loading and errors by OpenCode Session. Main serializes only runtime/configuration acceptance, verifies project Agent content against an owned fresh runtime generation before execution, and returns typed terminal pending responses without automatically restarting, reloading or disposing the shared runtime. A run that receives no explicit busy/assistant/terminal acknowledgement within 10 seconds ends only that Session and is never replayed automatically. The application-side isolation is verified; real bundled OpenCode/provider two-Session execution concurrency is not claimed.- Project-cover source commit
145a6ce571d646325092d1e722282babea503954from feature task20260817-project-cover-upload-a6a98e56, integrated by task20260813-sync-push-main-9c2f71. First submission now requires a bounded PNG/JPEG/WebP cover, shows preview/file/reselect feedback, and sends metadata plus cover through Main-ownedPOST /api/projects/with-cover; conflicts stop before version upload and existing draft/published projects remain version-only. The matching Works Square server source is407c883(local merge0cedfc4). No client package, production deployment, or real-account smoke occurred. 3b37ac3/55e61b7: macOS Robot hotspot discovery performs one bounded worker-thread rescan after an empty or SSID-redacted CoreWLAN result; persistent SSID redaction maps to the existing permission error instead of a misleading empty-device state, while firmware and the openXiaozhi-*contract remain unchanged.f5d47c8/b6148a5: AI Programming voice capture is available after an Agent is selected but before the lazy first OpenCode session exists; transcription fills the composer draft without creating an empty session, while runtime, loading, transcribing, busy, and recording guards remain unchanged.4013edc/3b799af: integrated per-user Code/Canvas/Learning/Robot entry policy from Works Square, projected by Electron Main as four booleans and enforced before disabled module routes initialize.01bee31: historically enabled the AI Learning course catalog/generation/download/playback architecture. Its Learning course/runtime behavior is superseded by38db158above; its unrelatedgame-engineremoval and project-rootplanning-with-filesbehavior remain historical context.26b52d7: Canvas Prompt Museum, editable server-priced generation Quotes, project deletion/task-detail workflow, cloud-default Canvas development entry, and Chinese-only UI consolidation from the authoritative remote main. Its transient bundledgame-engineSkill is superseded by01bee31.f8d82e6: Prompt Museum media rendering now accepts only the server-controlled relative media route, fetches it through a Main-owned bounded Works-authenticated proxy with one refresh retry, and keeps credential-free HTTPS CDN media direct. Renderer-side validation and card-local placeholders cover invalid or failed media; attribution URLs remain optional.c1326a2: Guided Hotspot Binding now scans bounded openXiaozhi-*candidates and connects the user-selected hotspot inside the page through Main-owned Windows WLAN and macOS CoreWLAN/CoreLocation adapters; system Wi-Fi remains fallback, exact=0rollback and firmware/cloud contracts are unchanged.b78fc07: Guided Hotspot Binding is enabled by default in Electron Main, with exact environment value0as rollback and direct six-digit fallback on capability-read failure; firmware and Host/cloud contracts are unchanged.b7a1590/14afe4a: initial firmware-zero-change Guided Hotspot Binding V1 implementation and decision used a Main-owned default-off capability, fixed portal action, in-memory Renderer journey, and existing six-digit Binding contract;b78fc07above supersedes only that default.ea75b06: Robot configuration reads accept canonical weak numeric response ETags introduced by public response compression only when the numeric revision exactly matches the strictly projected DTO; configuration and assignment writes continue to emit strongIf-Match.fe55dee: Robot configuration editing uses the safe Xiaozhi/Works catalog for model, language, and voice selections, with bounded sliders for TTS numeric controls and no-store catalog responses.fd9b5b46a913c515e94e4e26f185d43866c2581f/7a811590c4943b7b1b7ea5f3b4d3ce3ce05622a5: Codex-style persistent AI Programming context-compaction timeline, run-lifecycle separation, polling-idle completion, and cold-hydration hardening.22378efcee07e7fb80b651e65e3202f1a1dfea1d: AI Canvas bidirectional Agent WebSocket commands, idempotent transport fallback, and Quote-based generation-task recovery.aba5cae286807093cf4ef643fe9f498050985c31: Robot / AI hardware module, Main-owned Works Square proxy, and cross-repository wire contract.86ece3a/4dde8f3:客户端登录七天滑动续期及集成提交。724290e/dcc92fc:Main-owned 一键打包提交审核及集成提交。493b31c:客户端三类ProjectType、小游戏/小程序受控发布模板与自定义项目发布隔离。4df0477/8dd99c1:客户端静态发布唯一链路、旧 Compose 协调链退役及安全边界补强。4980894/03dae62:AI 绘画 Enter 发送及同一 Workspace 下的多 Conversation 客户端模型。926056a:Makelore 内置 Electron WebContents/CDP 发布前本地预览检查。5b44864:Main-owned 本地 npm/Vite 构建、同字节 Electron 双视口预检、source+built 双归档与 artifact contract 上传。08da976/0ee5254:AI 编程首次发送已知空 session 快速路径与明确上游饱和终止态投影。809364e/88281b8/7a807a2:AI 绘画单参考图图生图选择/上传交互、最新客户端主线集成及旧版 Brief medium 缺失兼容。f05b9d4/e221374:Updater 稳定源缺包诊断与用户错误脱敏修复,以及当前main上的图生图最终合并提交。f4113a8:远程主线客户端收口,包含启动预热、课程 Skill、项目 Agent 模型配置、浅色界面整合,并移除独立真机预览与内置 Superpowers。
Current Focus
客户端面向非专业用户提供“创建小游戏或小程序 → 项目配置中一键提交 → Main 本地 npm/Vite 构建 → Electron 双视口预检最终产物 → 上传 source+built 双归档与 contract → 运营审核”的唯一创建者链路。Main 对安全源码快照运行安装包内固定 npm 11.6.2 的 npm ci --ignore-scripts,再显式调用项目 package-lock.json 锁定的 Vite;Vite config/plugins 以当前桌面用户权限执行,因此只适用于用户信任的本地项目,不是 sandbox。预检由 Main 以临时 loopback origin 和 Electron WebContents/CDP 检查与最终 built_archive 相同的内存文件字节,覆盖桌面/移动视口、运行错误、白屏和外域访问;不使用 Playwright。该检查仍可由非官方客户端绕过,不产生可信 receipt,也不复刻生产 opaque-origin。服务端不再替客户端运行项目 Vite,而是把源码、构建归档和 contract 视为不可信输入,逐字节重算与校验并固化不可变 Release;人工审核仍不可绕过。自定义和缺少类型字段的旧项目不提供该入口。已发布作品优先使用安全投影后的 play_url,runtime_url 仅保留一个客户端版本的兼容回退。
AI Design Canvas 现在默认以对话和一张持续可见的“我的创作”卡服务 8-16 岁创作者;专业字段矩阵收进按需打开的“精细调整”,移动端保持对话优先并只挂载一个卡片/底部面板。Creation Card、精细调整、Quote、Task 与结果提示都只投影权威状态,已知问题按 code 转成通俗中文,未知服务端或 Provider 文本不会直接显示。一个 Workspace 仍只公开一个 current Direction、一个 persistent Agent Session 和一个 Current Specification;conversation timeline 只记录交互历史。Chat、direct edits、decision responses、proposal acceptance、locks、Asset binding 与 restore 都通过 design.input.apply 进入同一服务端 reducer,Renderer drafts 在 accepted 前保持本地。Main 持有 Works Token、stream ticket、WebSocket、request deadline、stable command/operation IDs 与错误脱敏;unknown result 只能复用原 identity,结构化业务错误不得重放。Generation 由服务端对 exact Specification revision 编译 immutable Quote,客户端只展示 public output plan、warnings、expiry 与 Token Points,并以 Quote ID 调用 design.generation.confirm;Provider Prompt、model、route、storage 和 billing atoms 不进入 Renderer。Task/Asset events 独立收敛 Workspace resources,不改写 Living Form。Development 与 packaged builds 均使用 Works Square V2,V1 DTO、local semantic adapter、mutable Quote PATCH 与 editable provider Prompt 已移除。
Canvas 侧栏提供“获取灵感”进入 Prompt Museum。列表、筛选、分页、详情、作者/来源/许可证和图片地址全部由服务端经 Main-owned Host API 提供,客户端不打包静态数据集;服务端相对媒体只允许固定 /api/image-prompt-museum/{entry}/media/{thumbnail|number} 形状,并由 Main 注入 Works Bearer、执行一次 401 刷新、可信 raster MIME 与 10 MiB 上限后转为 Renderer data URL;credential-free HTTPS CDN 图片保持直连。图片失败只显示卡片内占位,不阻断卡片或详情;缺少来源 URL 时显示纯文本。“使用此 Prompt”只把原文带回当前 Canvas 输入框,不自动发送。该模块不是投稿、点赞、评论或排行榜社区。客户端契约已就绪,但不据此宣称 Works Square 内容后台和生产数据已经部署。pnpm run dev 现在默认使用云端 Canvas 适配器,本地适配器只能通过显式开发命令启用;产品 UI 只保留中文。
密码登录提供可选“记住密码”。该记录与七天登录会话分离,只在正式安装包且系统安全存储可用时由 Electron Main 加密落盘;Renderer 仅在登录页内存中接收回填,不写 Zustand/localStorage,Works Square 也不持久化桌面密码。退出登录和短信登录不删除记录,成功的未勾选密码登录会清除旧记录。未打包开发版禁用该选项,避免未签名 Electron 调试进程触发 macOS 钥匙串。
Makelore 在会话恢复、登录和刷新后由 Electron Main 请求 Works /api/auth/me,Renderer 只获得 Code、Canvas、Learning、Robot 四个布尔权限。缺失 module_access 或任一字段时默认开启;服务端 design 显式映射客户端 painting。被关闭的模块卡片置灰且不可点击,根路由、深层路由和别名路由均在 MainLayout 或模块初始化前阻断。Code provider 等待认证权限加载完成;权限查询返回终止性 401 时同时清理 Main 和 Renderer 会话。/settings 是全局设置,不受 Code 入口策略阻断。该机制只是客户端入口策略,不代替服务端 API 授权。
AI 学习现在是已启用的运营精选项目目录,并继续受登录和 module_access.learning 控制。Renderer 通过 Main-owned Host API 获取分页项目卡片和 README 详情;Markdown 支持 GFM、禁用原始 HTML。服务端发布时只校验图片 URL 为无凭据、默认端口、无 fragment 且当前 DNS 结果全部为公网地址的 HTTPS URL,保留地址而不下载、识别格式、转码或镜像;客户端仅为 README 图片节点启用直连,因此 SVG 和 Electron 支持的其他格式可直接显示,单图失败不阻断详情。封面和历史发布媒体继续走受控路径。详情页的下载按钮打开系统保存对话框;Main 将 ZIP 流式写入临时文件,只允许最多五跳同 Works origin 重定向,不校验 Content-Length、archiveBytes、实际流字节数或客户端大小上限,校验 SHA-256 和 ZIP 签名后原子保存,Renderer 只接收 saved 或 cancelled。课程生成、进度、本地课程库、OpenMAIC player、Agent、ASR、课堂 runtime、Learning IPC 和 player artifact 打包已删除且没有兼容读取路径;历史课程数据保留但不再读取。服务端和客户端源码契约已完成,不代表生产部署或真实账号安装包联调已经完成。
AI 编程已经硬切到精确 pin 的 Pi 0.84.2,不存在 OpenCode fallback 或双 runtime。project、Agent 与 Conversation 只在 .makelore/project.json 和 .makelore/conversations.json 使用本地 schema v2;当前客户端不从 .niancode 或 .opencode 读取、迁移或删除项目元数据。Electron Main 按需启动一个长驻父 Agent Server,每条 active/warm Conversation 在其中拥有独立 Runtime/Session/channel、credential store、extension context、generation/seq、Snapshot/Patch、model/thinking、队列、interaction 与错误状态,Composer 在 lazy prepare 期间仍可编辑。Renderer 只通过 /api/coding/* 和 Snapshot-first/patch-batch SSE 消费产品中立合同;gap/reconnect 只恢复目标 Conversation,accepted/uncertain mutation 不自动重放。未解析 Conversation 第一次选模先 validate 并持久化 resolved metadata,再 prepare;同账号模型切换使用 target set_model,跨账号只重建目标逻辑线程。Main-selected Device Package generation 把所有显式安装且当前启用的 Skill 路径和 extension 路径交给未来或空闲 parent;生成的 Makelore bridge 始终是必需的首个 extension,其余全部经 additionalExtensionPaths 加载,同时保持 ambient discovery 关闭。active parent 在 turn settled 后刷新,child 始终为空。top-level 逻辑 turn 并发为 4,warm idle logical-thread LRU 为 8;independent child 进程并发为 4 并使用 FIFO 进程预算 8;coding child 与 parent 共用项目 write lease。prompt/compact confirmation timeout 后仍保留 run/Agent-Server-or-child-process/background ownership,迟到 success/failure/exit/abort 单调且 exactly-once 收敛,页面隐藏不会停止 active/uncertain run。线程级替换只使目标 generation 失效;整个 Agent Server 退出会统一使所有旧 channel 失效,但 Main/Renderer 存活且下次恢复只重启一个 Server。Pi 0.84.2 手动 compact 不发 agent_settled,由 correlated compact RPC 结果终结。父 Provider credential 只进入选中逻辑线程的内存 credential store,child 凭据只进入该短命进程;确定性的 Works user-context 缺失会失效 gateway credential、fail fast、不重放并投影固定 Provider-auth 错误,不归类为 Pi crash。真实 Provider 验证仍为用户明确接受的未验证风险,macOS x64/arm64 与 native non-WSL Linux 也未通过平台发布门禁。
Updater 仍由 Electron Main 选择目标 feed、记录原始诊断并保持失败语义。正式稳定源缺少对应平台 manifest 时,设置页只显示一条简洁中文提示并允许重试,不把缺包误报为已是最新版,也不向普通界面暴露堆栈、URL、路径或错误码;签名产物发布和真实升级安装仍属于外部 Release Gate。
Robot 绑定设备默认先显示“引导配网 / 已有激活码”路径选择。引导路径在页面内扫描附近符合条件的开放 Xiaozhi-* 热点,要求用户明确选择后由 Main-owned Windows/macOS 原生适配器连接并核验当前 SSID;失败时保留系统 Wi-Fi 兜底。macOS 在首次 CoreWLAN 结果为空或 SSID 全不可见时只进行一次 250 ms worker-thread 延迟重扫;第二次仍有网络但没有可读 SSID 时显示定位权限错误,不再冒充“没有发现设备热点”。后续继续使用固定 http://192.168.4.1/ 系统浏览器页面、恢复互联网和现有六位 Binding;精确环境值 0 可回滚为直接六位码。Makelore 不接收 Wi-Fi 密码、不修改固件,也不把热点发现或 Binding 成功等同于可信身份/在线。签名 macOS、Windows 真机、指定固件/发行契约和完整整链仍未完成验证。
Recently Completed
- 2026-09-03: Integrated the paired Device Package prepare and activation fixes. Packaged Main now resolves package inspection from the physical bundled Pi runtime, and the parent Agent Server loads the required generated Makelore bridge plus every explicit installed/enabled Pi extension while retaining all selected Skills and keeping ambient discovery off. Source verification passed packaged npm/Git/loose-Skill prepare, a real Agent Server with two external extension commands, full unit/pressure, typecheck, lint, build, Windows packaging, and artifact checks. The installed 1.2.6 client is unchanged, so exact-main rebuild/install and live activation are still pending.
- 2026-08-31: Integrated the provider-neutral
makelore.game-resourcehosted Plugin client with fetchedorigin/main. Generic schema-2platform_hostedpackages now materialize frozen Skill/tool snapshots only for eligible parent Pi logical threads; paid operations require explicit confirmation and stable logical identity, while Electron Main alone owns the fixed Works transport. Legacy always-mounted Meowa tools and client credential paths are removed. Focused/full unit tests, typecheck, lint and Vite/Electron builds passed; production signing, pricing, credential rotation, real Provider acceptance, push, deployment, and publication remain open. - 2026-08-31: Integrated the occupied local source snapshot over upstream Marketplace Release A and AI Design Living Form V2. Makelore Code now amortizes parent Pi startup through one long-lived Agent Server while preserving isolated per-Conversation logical runtimes, sessions, credentials, extensions and channels; child Agents remain independent processes. ADR-006 and current architecture now use
.makeloreas the sole project configuration source and explicitly reject legacy metadata reads or migration. - 2026-08-26: Fast-forwarded the complete Pi hard-cutover and installed-package resilience chain into local
main, including per-Conversation workers/Snapshot projection, extension/subagents, bounded process/write/background ownership and the deterministic Works user-context Provider-auth correction. The final Windows installer, packaged Pi runtime, extension/child, 4+4 pressure, uncertainty/late-settle and zero-lingering-process proofs passed. Real Provider turns are explicitly waived rather than passed; macOS and native non-WSL Linux remain release evidence gaps. - 2026-08-20: Replaced AI Learning's course generation/player stack with the curated project catalog defined by ADR-005. The authenticated/module-gated client now renders project cards and safe README detail, loads validated credential-free HTTPS Markdown images directly, and saves verified ZIP archives through the native dialog. Old course/runtime/player packaging was removed; server/client regressions and full suites passed, while production deployment and real-account package smoke remain pending.
- 2026-08-19: Integrated native password/SMS login, the temporary HTTP/2-disabled diagnostic bootstrap, and the AI Design freeze fix. Workspace JSON calls and shared token refresh now settle within 30 seconds, transport abort is paired with deterministic rejection, and implicit Electron-to-Node fallback no longer replays mutation requests. Installed-client Quote retry/confirm smoke and the final HTTP/2 policy decision remain pending.
- 2026-08-17: Integrated application-side multi-Session isolation for AI Programming. Session A may remain busy while Session B is independently accepted or terminally rejected; errors, startup deadlines and uncertain-failure cleanup stay Session-scoped. Main now fail-closes stale Agent/provider runtime state before execution, applies bounded manager/project FIFO acceptance with revocable timeouts, and never refreshes the shared runtime automatically from ordinary execution paths. Full unit, typecheck, lint, build, focused Electron E2E and independent Sol review passed; a real paid-provider/bundled-runtime concurrency smoke remains pending.
- 2026-08-17: Replaced the temporary coverless-first-create fallback with a required PNG/JPEG/WebP picker, preview, file name, reselect action, Renderer/Main signature and size validation, and one Main-owned multipart metadata-plus-cover create request. Create conflicts fail before version upload; existing project metadata and covers remain unchanged.
- 2026-08-17: Corrected macOS Robot hotspot discovery after a system-visible
Xiaozhi-*report. CoreWLAN now gets one bounded retry when its first result is empty or all SSIDs are unavailable; a persistent non-empty redacted result becomes the existing safe permission state. Open-only filtering, firmware, Host/Renderer contracts, exact-current-SSID verification, and the system-Wi-Fi fallback are unchanged; signed-package physical smoke remains pending. - 2026-08-17: Created merge commit
4013edcfor the reviewed per-user module-entry policy source tip3b799af. Main exposes only four booleans from/api/auth/me; missing fields remain enabled,designmaps topainting, disabled root/deep/alias routes stop before module initialization, Code provider startup waits for policy hydration, terminal401clears both session layers, and global settings remains reachable. - 2026-08-17: Integrated remote
01bee31, which at that checkpoint introduced Learning course browsing/generation/install/playback and its OpenMAIC runtime boundary alongside unrelated repository consolidation. ADR-005 and source38db158supersede and remove that Learning course/runtime behavior; historical downloaded data remains untouched. The unrelatedgame-engineremoval and project-rootplanning-with-filesbehavior remain current. - 2026-08-16: Integrated remote
26b52d7: Canvas now has server-backed Prompt Museum navigation, editable server-repriced generation Quotes, task result details/downloads, guarded project deletion, cloud-default development, and Chinese-only UI. That tip briefly bundledgame-engine; authoritative successor01bee31removed it. Client integration is verified separately from production Prompt Museum data/backend deployment. - 2026-08-18: Integrated Prompt Museum media rendering from
f8d82e6: relative protected media is fetched through Main with bounded trusted-raster validation and one 401 refresh, HTTPS media remains direct, invalid/failed images are card-local placeholders, and missing attribution URLs render without broken links. Focused unit/Electron E2E, typecheck, scoped lint, and Vite build passed; real Works/CDN production smoke remains pending. - 2026-08-16: Integrated Windows/macOS in-page Robot hotspot discovery, explicit selection, connection, and exact-current-SSID verification behind the existing default-on guided capability. Candidate IDs are bounded and short-lived, native diagnostics stay in Main, system settings remain fallback, and firmware/Portal/Binding contracts are unchanged.
- 2026-08-16: Enabled the existing Guided Hotspot Binding journey by default after explicit product confirmation. Exact
NIANCODE_AI_HARDWARE_GUIDED_HOTSPOT_BINDING=0remains the operational rollback; fixed portal ownership, direct-code fallback, security warnings, firmware-zero-change, and Binding-without-online semantics are preserved. - 2026-08-16: Initially implemented ADR-002's Robot onboarding V1 without changing firmware, behind a default-off Main capability and fixed portal opener. The later
b78fc07decision above changes only the default; the same firmware/issuer/native-opener/physical evidence remains outstanding. - 2026-08-15: Corrected the deployed Robot configuration-read contract after the compressed public Works response was observed with
ETag: W/\"0\"and matching numericconfig_revision: 0. Electron Main now accepts only canonical strong or weak numeric response tags, still requires exact DTO revision equality, and always sends strongIf-Matchfor mutations. No production client rollout is claimed. - 2026-08-16: Integrated selection-oriented Robot configuration editing. Enabled model and caller-safe voice metadata now flows from Xiaozhi through Works Square and Electron Main without exposing provider secrets; unavailable current values and
clear_fieldssemantics remain intact. Production deployment of the matching service endpoints is still required. - 2026-08-15:AI 编程上下文压缩改为 Codex 风格的会话内时间线事件;手动与自动压缩原位展示并持久保留,历史回放去重且状态只允许从 running 单调进入 completed,压缩完成不再冒充整个 run idle。
- 2026-08-14: AI Canvas Agent 命令与流式事件改为共用双向 Conversation WebSocket,并保留仅面向传输故障的幂等 REST 回退;结构化 Gateway 错误不重试且未知文本脱敏;确认生成按 Quote 恢复已落库任务,切换 Conversation 后仍同步 Workspace 任务且不覆盖新会话状态或错误。
- 2026-08-13: Integrated the enabled
Makelore Robottop-level module at/ai-hardware. Renderer uses typed safe DTOs while Electron Main owns Works Square authentication, idempotency identities, ETag/If-Match forwarding, response projection, limits, timeouts, and credential recovery. Robot and Canvas routes no longer initialize AI Programming projects/providers. No production deployment or real activation-code smoke is claimed. - 2026-08-08:合并登录续期和一键发布;发布成功后保存精确 app/version/review 映射,Renderer 不接触 Token、ZIP 或本地路径。
- 2026-08-08:补齐跨平台 Electron E2E fixture、Windows ZIP 预检和异常成功响应安全投影。
- 2026-08-09:新建项目支持小游戏、小程序和自定义三类不可变产品类型;前两类生成固定 Vite 发布模板,自定义及缺少类型字段的旧项目不显示一键提交入口。
- 2026-08-10:删除客户端旧 Compose deploy-check、watcher/arm/upload 协调和手工 ZIP 路由;submission binding v2 保留旧
submitted绑定并把旧中间态归一为legacy_retired,同时补齐 Renderer capability、play_url安全投影和本机绑定失败告警。 - 2026-08-11:AI 绘画支持在同一设计项目内创建和切换多条独立 Conversation;保留项目级任务/资产,并使用 Workspace + Conversation 身份保护异步与流式更新。退出时关闭本地流并清除本地 Session-id 缓存,不删除服务端持久 Conversation Session。
- 2026-08-12:一键提交前复用当前项目的内置浏览器 loopback preview,以 fresh 临时 Electron WebContents/CDP 执行桌面/移动 UX 预检;服务端仍执行唯一受控构建、不可变 Release 安全门禁和人工审核。
- 2026-08-12:发布架构反转为 Main-owned 本地构建;固定 npm 11.6.2 按项目 lockfile 安装并执行项目 Vite,Electron 预检最终上传同字节产物,再上传 source+built 双归档和严格 contract。服务端仅校验并固化不可信字节,不再承担项目 Vite 构建。
- 2026-08-12:AI 编程新 session 的首条 prompt 不再被已知空历史读取阻塞;明确上游分组饱和会快速终止,通用
429仍保持原有限速语义。 - 2026-08-13:AI 绘画把原视频首帧选择器泛化为单图来源选择器;图片 Brief 可选择项目作品或上传本地图作为图生图参考图,视频及未决 medium 保持历史首帧行为,成功提交后关闭弹窗。
- 2026-08-13:Updater 对 Works Square 稳定源缺少 Windows/macOS manifest 保持错误状态,在 Main 日志保留原始诊断,并在设置页去重、脱敏为可操作的中文提示;未发布任何新安装包。
In Progress
- 成组集成服务端 source+built+contract 校验、OSS immutable Release、CDN/Edge 与 App 消费链后,使用真实账号和生产配置执行客户端提交到作品播放的整链验收。
Next Recommended Steps
- 在停止服务的目标数据库完成 Design V2 cutover dry-run、清零 blocker、显式 apply/validate,再用成对部署的服务端与安装包真实账号执行 direct edit、chat edit、Quote request/confirm、后台完成、结果下载和 interrupted unknown-result replay smoke; paid Provider activation 另行授权。
- 部署 Works
module_accessmigration 与/api/auth/me权限 API,打包新 Makelore 客户端,再用真实账号分别关闭 Code、Canvas、Learning、Robot 执行卡片、根/深层/别名路由 smoke;同时独立验证模块 API 服务端授权。 - 部署 Works Square Learning 项目管理、对象存储、README HTTPS URL 校验和 list/detail/media/archive API,再使用真实账号验证发布/下架、分页、远程 README 图片(含 SVG、失效 origin 和隐私提示)、ZIP 校验/保存以及 Windows 与签名 macOS 安装包。
- 对 default-on Guided Hotspot Binding 核对指定固件镜像与六位码发行/消费契约,补齐 Windows 真机热点连接、签名 macOS x64/arm64 CoreWLAN/CoreLocation/worker 打包验证、真实 Host API/native seam Electron E2E 和完整真机 smoke;发布支持保留精确
=0回滚,不把缺失证据表述为已验收。 - 成组核对客户端 source+built+contract 上传 → 服务端逐字节校验 → OSS immutable Release → CDN/Edge 的发布契约与客户端
play_url消费契约。
Open Questions / Blockers
- 客户端与模拟上游回归已完成;真实服务端新协议、OSS/CDN、运营审核、App 播放、生产账号和环境变量仍待部署环境确认,不能据此宣称生产发布链已经验收。当前已验证的 Windows 安装器未上传或发布。
Risky Areas
- 四模块权限只控制 Makelore 客户端入口和初始化,不是 API 授权边界。不得因卡片置灰或路由阻断而放宽 Works/模块服务端的身份与权限校验;旧服务端缺少对象/字段时默认开启是显式兼容策略。
- Prompt Museum 相对媒体必须保持固定的服务端路径并由 Main 处理;如果服务端增加媒体变体,需同步维护 entry/path 语法、Works Bearer 所有权、单次刷新、10 MiB 限制、可信 raster MIME 白名单与 Renderer data URL 校验。HTTPS 直连媒体必须继续无凭据,图片失败必须局限在卡片/详情视图。
- Learning 项目目录依赖真实 Works 运营发布和固定 API 契约;README 图片只允许服务端校验后的无凭据 HTTPS URL,并由 Markdown 图片节点直接加载,不得扩展为任意网络或归档代理。第三方 origin 的可用性、格式支持和请求隐私是已接受边界。Main 必须保持 Bearer 所有权、封面/历史媒体受控读取、一次 401 refresh、同源最多五跳、SHA-256/ZIP 签名和原子保存;客户端下载明确不执行大小门禁,不得把上游错误、Token、对象存储 URL 或本地路径投影到 Renderer。历史课程数据不再读取但也不得被隐式删除。
- Works Project 首次封面已由服务端源
407c883(本地 merge0cedfc4)提供单请求原子绑定与失败补偿,客户端源145a6ce因此要求首次发布上传 PNG/JPEG/WebP 封面;部署、安装包和真实账号/对象存储 smoke 仍未完成。服务端仍没有已有 metadata 的 revision/ETag 与 draft-only 条件写,因此已有 draft/published 继续只允许 version-only,客户端不得以无条件 PATCH 替代。 - Guided Hotspot Binding 默认开启并提供未经认证的热点扫描/显式连接,但当前 Hotspot/portal 仍是开放 SoftAP + 明文 HTTP,且精确出货镜像、激活码发行契约、签名 macOS、Windows 真机与完整整链尚未验证。界面必须保留环境警告,异常发布可用精确环境值
0回滚;不得把 SSID 前缀宣称为可信设备发现、自动认领或在线证明。 - 一键提交已成功但本机 submission binding 落盘失败时必须保持提交成功、显示固定
binding_warning并继续轮询,避免用户误判上传失败。 - 公共
play_url必须满足 Works Square 同源 HTTPS、无 userinfo/loopback、精确/apps/{app_id}/路径、无 query/fragment、版本非空且上游标记可播放。 /api/works/projects/publish-source必须在读取凭据和项目文件前校验 Renderer capability;Host token/base 不能替代该 UI 边界。works-cloud-deploy.json仅是已安装数据的兼容文件名,不代表客户端仍拥有自动部署协调器;旧中间态不得恢复为后台任务。- 刷新凭据、发布 Token、ZIP、幂等键和重试只能由 Electron Main 持有。
- 本地
projectType只决定产品分流和模板选择,不得作为授权依据或替代 Main/服务端的包体校验。 - 本地构建必须使用安装版 Electron Node、固定 npm 11.6.2 和项目
package-lock.json锁定的 Vite,不得回退到全局 PATH、已有node_modules或未验证的 npm 闭包;依赖安装需要网络。 - 项目 Vite config/plugins 以桌面用户权限执行,不能称为 sandbox;此风险边界必须在发布说明中保留。
- AI Design 的 Current Specification 是唯一语义权威。Direction events 必须按 Workspace/Direction/revision/operation identity 收敛;assistant delta、event cursor、Task progress 和 Asset updates 不得改写 Living Form。
- Design unknown-result replay 必须复用原 stable command 与 semantic operation ID;业务错误不得重复提交。Immutable Quote confirmation 只提交 Quote ID,Task recovery 不授权新的生成 intent。
- AI 绘画 Main-owned Workspace JSON 请求和共享 Works token refresh 必须在 30 秒内结束并释放共同等待者;只允许
GET/HEAD/OPTIONS在 Electron transport 失败后透明改走 Node fetch,PATCH/POST 等 mutation 必须由具有显式幂等身份的上层协议决定是否重试。临时disable-http2只用于安装包诊断,不能替代该有限生命周期与非重放边界。 - 服务端 current Direction Session 与 semantic history 不由客户端在注销或退出时删除;Main 只关闭本地流、清除 drafts/pending state 和本机凭据。
- 客户端对最终构建字节的 loopback 检查没有可信 receipt,且不复刻生产 opaque-origin;服务端必须独立重算 source/built/contract、校验不可变 Release,人工审核仍不可绕过。如未来需要不可绕过的 runtime gate,必须引入可信 verifier 并绑定精确构建产物。
- Pi RPC confirmation timeout 是不确定性边界,不是释放 run permit、process ownership 或 Main background lease 的依据;accepted/uncertain mutation 不得自动重放,迟到 terminal 必须 exactly-once 收敛。隐藏/显示、abort、recover、replacement 与 app quit 都必须保留可解释 reason 并最终清零 ownership。
- Pi
0.84.2手动 compact 不发agent_settled。只有 correlated compact RPC success 或权威 compaction failure 可以结束 compact;普通 prompt 仍需自己的 terminal/settled 语义,不能相互释放 lease。 - 本地 provider-shaped loopback 和单一 Agent Server 内 4 条重叠父逻辑线程 + 4 child process proof 证明客户端序列化、调度与隔离 seam,不证明真实 Provider 会并发、不会限流或正确隔离账号凭据。真实认证、endpoint/proxy/rate-limit、协议和图片差异仍为
Explicitly Waived / Accepted Risk,realTurnVerified=false。 - Provider/resource freshness 属于目标 Conversation logical-thread generation。idle stale 在下一 prompt 前重建,running stale 在 settled 后重建;同账号 refresh single-flight 且最多一次 reopen。确定性 Works user-context 缺失必须失效缓存凭据并 fail fast,不能触发无限 Pi 重试、自动 replay 或把 Provider 故障写成 runtime crash。
- AI Design 图片/视频引用必须以 typed Asset binding 写入 Specification,不能从本地化 quick reply、V1 Brief 或本地路径推断 action/purpose。
- Updater 源码错误提示不能代替发布正式签名产物;稳定 feed 缺 manifest 必须保持失败,Renderer 不得展示原始堆栈、URL、路径或错误码。升级链只有在旧版本完成发现、下载、重启和安装 smoke 后才可视为生产就绪。
Last Updated
2026-09-03