Skip to content

Commit 6b340bc

Browse files
committed
fix: close final artifact delivery chain
1 parent ab762fa commit 6b340bc

9 files changed

Lines changed: 280 additions & 17 deletions

File tree

‎changelogs/unreleased.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,7 @@
1414
- **本地候选修复 — 派生资产新鲜度与默认验证漏检**:刷新 `content/skills/portfolio.json`,并将 `skill-portfolio-current` 纳入 changed/iterative 默认验证不变量,使 clean-tree `npm test` 计划覆盖 portfolio freshness;同步 validation DAG 断言与 Windows 中文文件名负向测试夹具,避免默认验证对派生资产 stale false-green。本项仅为本地源码候选,未 tag、未 publish、未刷新 MCP。
1515
- **本地候选修复 — 提交后 Profile current truth 与 changed-route 防漏检**:新增轻量 `profile-current` validation node,并将其纳入 changed/iterative 默认验证不变量,使 clean-tree post-commit replay 也会检查 active Profile `ProfileCurrentTruthV1` 是否对齐当前源码 HEAD/source candidate;`profile-governance` 保持边界/综合验证,不被每次 clean changed-route 强制拉起。本项仅为本地源码候选,未 tag、未 publish、未刷新 MCP。
1616
- **本地候选修复 — AI 验证入口 authority 提示收敛**:`run-validation` 在 Codex/AI 环境缺少 ContextRead epoch 或 source-message digest 时继续 fail-closed,但 `Next` 提示改为明确分流到 `npm run test:changed:plan`、绑定 task/context/source-message 的 `test:changed:ai`,或真实人类交互式终端 `npm test`;新增 validation DAG 断言锁住该错误投影,避免把 authority fail-closed 误判为源码测试失败或诱导绕过执行权限。本项仅为本地源码候选,未 tag、未 publish、未刷新 MCP。
17+
- **本地候选修复 — 最终产物文件输出链路闭环**:`ArtifactDeliveryManifestV1` 增加 `sourceArtifactIds` 自证 planned/observed/internalDelivered 原始规范化清单,完整性校验不再从 entries 自我重建;新增 `composeFinalArtifactDeliveryEnvelope` 与 `createVisibleManifestFromTaskDeliveryManifest`,让最终回复可由 manifest→visible set→delivery attempts→envelope 单链生成,并把任务目录 `TaskArtifactDeliveryManifestV2` 桥接进最终可见 manifest;同步修正报告规范“完成交付文件”示例的路径列、schema、report/user-visible-output Skill 文档和回归测试。本项仅为本地源码候选,未 tag、未 publish、未刷新 MCP。
1718
- **本地候选修复 — 验证入口、产物状态投影与 Profile 当前真相刷新**:收紧 active-root 产物 stale CP 状态检测,避免把“待用户确认是否提交”等非 CP 文案误判为 CP1/CP2 阻断;默认 `test:fast/full/delivery/boundary/profile-deploy/package-release` 改为 `human-cli --plan` 入口并补充 `:ai` 严格变体,避免 Codex/AI 环境缺 `contextEpoch` 时本地 plan 命令误红;新增 `profile-current:refresh` 标准命令,用于更新 active Profile `ProfileCurrentTruthV1` 的当前源码 HEAD 与 source candidate 身份。本项仅为本地源码候选,未 tag、未 publish、未刷新 MCP。
1819
- **本地候选修复 — 验证入口派生资产与 Profile 边界**:将默认 `test` / `test:changed` / scoped route 入口恢复为执行型验证,新增显式 `test:plan` / `test:*:plan` 作为零执行预览入口,避免 plan-only 被误读为测试已执行;把 `scripts/refresh-profile-current-truth.js` 纳入 profile boundary 与 `profile-governance` 输入闭包,确保修改 Profile current truth refresh 脚本时触发 profile 验证;刷新 `content/skills/portfolio.json`。本项仅为本地源码候选,未 tag、未 publish、未刷新 MCP。
1920
- **本地候选修复 — 运行态可观测性与历史债务收敛**:`validate.js` 现在对每个 V 探针输出 start/done heartbeat,V7 改为有界 fast-path smoke,避免聚合校验无界卡死;visible reply evidence 绑定当前 promptCount,无 payload 时不再继承旧 precheck;`memory_status` 增加 `summaryCurrentProjection`,显式区分 append-only SUMMARY 历史与当前折叠状态;artifact checker 新增 digest-bound `HistoricalArtifactIssueDispositionV1`,用于精确处置历史 unknown/stale/conflict 产物噪声。本项仅为本地源码候选,未 tag、未 publish、未刷新 MCP。

‎content/duplication-inventory.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"schemaVersion": "ControlContentDuplicationInventoryV1",
3-
"sourceBundleDigest": "6d8df3539c86fedfaa072b40ad9252c885a441031f0da9be9e3c8051f7cb46c2",
3+
"sourceBundleDigest": "cd043acf3101b3ee19e5667dab766d9b8720b1639e1e1851edd3d365b480f470",
44
"thresholds": {
55
"minParagraphChars": 100,
66
"sectionThreshold": 0.94,

‎content/instructions/16-report.instructions.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -109,7 +109,7 @@ reports/<子目录>/<agent>/YYYYMMDD/NN--<简述>.md
109109
- 报告必须登记到 `ArtifactDeliveryManifestV1`,最终用户面由 `UserFacingArtifactSetV1` 投影为语义链接(详见 [`02-output-paths.instructions.md`](./02-output-paths.instructions.md) §产物路径输出格式):
110110
```markdown
111111
#### 完成交付文件
112-
- [最终执行与验证报告](capability-selected-target) — 汇总完成范围、验证结果和残余风险;操作:查看结论
112+
- [最终执行与验证报告](capability-selected-target) — 汇总完成范围、验证结果和残余风险;路径:`.devcodex/.../reports/.../NN--报告.md`;操作:查看结论
113113
```
114114
> Rich clickable 已验证时不得重复绝对路径;只有用户要求、链接失败、工作区外、歧义或无法定位时追加绝对路径 fallback。session/SUMMARY/raw ledger 默认不进入用户列表。
115115
- C13 只约束新建 DevCodex 规范资产 `.md`;报告不因 C13 强制压缩或拆分,超长报告按可读性、索引导航和项目规范决定是否拆分

‎content/skills/report/SKILL.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -109,7 +109,7 @@ resume、ECR 或 ContextRead 的已发布依赖,也不能据其状态要求用
109109
- 正式复审/ECR 写 `ReviewExecution`:引用 `ReviewExecutionPlanV1`、fresh receipt digests、EvidenceSaturation、唯一 `ReviewStateSnapshotV1.snapshotDigest` 与 `StageTimingV1`;报告不得重新推导 review counts 或把 failed/inconclusive receipt 写成可复用。
110110
- **ReviewGradeCard(C19↔R)**:CP 确认后前置复审与 ECR 在报告中须记录 `c19Label`(轻量/标准/全面/发布安全)与 `reviewClass`(R0~R4)、`riskClass`/`riskFlags`、`contentPack`、`result`;默认 ECR 为 **R2(标准)**,禁止写「永远轻量一眼通过」而无 `skipReason` 的 R1 降级;R3/R4 须引用 checklist 或独立证据口径。
111111

112-
最终回复是独立交付 surface:报告必须先登记到 `ArtifactDeliveryManifestV1`,再由 `UserFacingArtifactSetV1` 投影。默认用户面显示最终报告、直接交付物和 required evidence;session/daily/SUMMARY/task/checkpoint/raw receipt/manifest/ledger 默认 internal-only,但仍写入并参与 ECR。可见回复证据使用 `verified-present / verified-missing / unverified`,legacy 文本最多 `unverified-legacy`,不可观察时不得断言缺失。
112+
最终回复是独立交付 surface:报告必须先登记到 `ArtifactDeliveryManifestV1`,再由 `UserFacingArtifactSetV1` 投影;生产代码优先调用 `composeFinalArtifactDeliveryEnvelope` 串起 manifest、visible set、delivery attempts 与 envelope,任务目录 `delivery-manifest.json` 需要对外可见时先经 `createVisibleManifestFromTaskDeliveryManifest` 投影,不得直接手写最终清单。默认用户面显示最终报告、直接交付物和 required evidence;session/daily/SUMMARY/task/checkpoint/raw receipt/manifest/ledger 默认 internal-only,但仍写入并参与 ECR。可见回复证据使用 `verified-present / verified-missing / unverified`,legacy 文本最多 `unverified-legacy`,不可观察时不得断言缺失。
113113

114114
## 输出规则
115115

‎content/skills/user-visible-output-contract/SKILL.md‎

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ description: 用户可见输出契约 Owner — 统一入口检查、完成检
88

99
当任务需要输出 PC0~PC10、FC/SC/RC/T、CP/危险动作确认、长任务进度、最终结果、阻断原因或文件交付列表时,本 Skill 是用户可见语义与渲染的唯一 Owner。
1010

11-
本 Skill 只负责 `ArtifactDeliveryManifestV1 → ArtifactAnchorProjectionV1 / UserFacingArtifactSetV1 → PostCompletionActionSetV1 → EntryCheckModelV3 → DevCodexVisibleEnvelopeV3 → renderer`。它不替代 `compliance` 的检查含义、`cp-gate` 的确认状态、`report`/`memory` 的写入职责、`host-contract-verification` 的宿主 direct replay,也不判断专业内容质量。`DevCodexVisibleEnvelopeV1/V2` 只保留读取兼容,禁止新生产者继续写入。
11+
本 Skill 只负责 `ArtifactDeliveryManifestV1 → ArtifactAnchorProjectionV1 / UserFacingArtifactSetV1 → PostCompletionActionSetV1 → EntryCheckModelV3 → DevCodexVisibleEnvelopeV3 → renderer`。最终结果生产者优先调用 `composeFinalArtifactDeliveryEnvelope` 串起 manifest、visible set、delivery attempts 与 envelope,禁止在最终回复中手写一套“主要产物”清单绕过该链路。它不替代 `compliance` 的检查含义、`cp-gate` 的确认状态、`report`/`memory` 的写入职责、`host-contract-verification` 的宿主 direct replay,也不判断专业内容质量。`DevCodexVisibleEnvelopeV1/V2` 只保留读取兼容,禁止新生产者继续写入。
1212

1313
确定性实现位于 `hooks/_runtime/visible-output-contract.cjs`,结构约束位于 `visible-output-contract.schema.json`。
1414

@@ -37,7 +37,7 @@ description: 用户可见输出契约 Owner — 统一入口检查、完成检
3737

3838
## 单向链路
3939

40-
1. `ArtifactDeliveryManifestV1`:记录本任务所有持久化 mutation、恢复证据和审计证据;planned、observed、internalDelivered 必须精确对账。
40+
1. `ArtifactDeliveryManifestV1`:记录本任务所有持久化 mutation、恢复证据和审计证据;planned、observed、internalDelivered 必须精确对账,并在 `sourceArtifactIds.plannedArtifactIds / observedArtifactIds / internalDeliveredArtifactIds` 中保留原始规范化清单,供落盘后重新复算 manifestId 与 reconciliation。
4141
2. `ArtifactAnchorProjectionV1`:可选上下文锚点投影,只携带 canonical path、contentDigest、projectionDigest、truthSourceKind、stalePolicy 与 evidenceRefs,不复制正文。
4242
3. `UserFacingArtifactSetV1`:只能由 manifest 纯函数投影,禁止模型临场挑“主要产物”。
4343
4. `PostCompletionActionSetV1`:从已验证缺口、Profile 和用户授权边界投影“当前必做 / 唯一主动作 / 最多两个条件动作”;不得把产物文件当动作。
@@ -57,8 +57,10 @@ description: 用户可见输出契约 Owner — 统一入口检查、完成检
5757
- `visibility=decision-required|result|evidence|optional-detail|internal-only`。
5858
- `deliveryRequirement=required|supporting|internal`;required 不得隐藏,internal 必须为 internal-only。
5959
- `reconciliation` 必须满足 planned=observed=entries=internalDelivered;missing/unexpected/conflicting 任一非空即 BLOCK。
60+
- `sourceArtifactIds` 必须保留规范化后的 planned / observed / internalDelivered 三组清单;完整性校验不得从 `entries` 自我重建三组清单来冒充原始输入已复证。
6061
- 同一 artifactId 或 canonicalPath 重复、`file://`、非语义 displayName、缺 digest/evidence 均为非法。
6162
- 根 manifest 的序列化容器不登记为自身 entry,避免 self-hash 无限递归;其 storage path 与文件 SHA256 必须由上级 ECR/validation receipt 记录。其他批次 manifest 或 raw manifest 作为普通输入时仍属于 `raw-manifest/internal-only`,不得借此例外漏记。
63+
- 任务目录级 `TaskArtifactDeliveryManifestV2` 不直接替代最终用户可见 manifest;需要进入最终回复或 ECR 时,必须通过 `createVisibleManifestFromTaskDeliveryManifest` 投影为 `ArtifactDeliveryManifestV1`,再继续 `UserFacingArtifactSetV1` 与 envelope 链路。
6264

6365
## ArtifactAnchorProjectionGate
6466

‎content/skills/user-visible-output-contract/visible-output-contract.schema.json‎

Lines changed: 31 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,8 @@
1717
{ "$ref": "#/$defs/DevCodexVisibleEnvelopeV1" },
1818
{ "$ref": "#/$defs/DevCodexVisibleEnvelopeV2" },
1919
{ "$ref": "#/$defs/EntryCheckModelV3" },
20-
{ "$ref": "#/$defs/DevCodexVisibleEnvelopeV3" }
20+
{ "$ref": "#/$defs/DevCodexVisibleEnvelopeV3" },
21+
{ "$ref": "#/$defs/FinalArtifactDeliveryEnvelopeCompositionV1" }
2122
],
2223
"$defs": {
2324
"status": {
@@ -54,8 +55,8 @@
5455
"type": "object",
5556
"additionalProperties": false,
5657
"required": [
57-
"schemaVersion", "taskId", "candidateIdentity", "generatedAt", "entries", "reconciliation",
58-
"manifestId", "validation"
58+
"schemaVersion", "taskId", "candidateIdentity", "generatedAt", "entries", "sourceArtifactIds",
59+
"reconciliation", "manifestId", "validation"
5960
],
6061
"properties": {
6162
"schemaVersion": { "const": "ArtifactDeliveryManifestV1" },
@@ -68,6 +69,16 @@
6869
},
6970
"generatedAt": { "type": "string", "format": "date-time" },
7071
"entries": { "type": "array", "items": { "$ref": "#/$defs/artifactEntry" } },
72+
"sourceArtifactIds": {
73+
"type": "object",
74+
"additionalProperties": false,
75+
"required": ["plannedArtifactIds", "observedArtifactIds", "internalDeliveredArtifactIds"],
76+
"properties": {
77+
"plannedArtifactIds": { "type": "array", "items": { "type": "string", "minLength": 1 } },
78+
"observedArtifactIds": { "type": "array", "items": { "type": "string", "minLength": 1 } },
79+
"internalDeliveredArtifactIds": { "type": "array", "items": { "type": "string", "minLength": 1 } }
80+
}
81+
},
7182
"reconciliation": {
7283
"type": "object",
7384
"additionalProperties": false,
@@ -116,6 +127,23 @@
116127
"validation": { "$ref": "#/$defs/validation" }
117128
}
118129
},
130+
"FinalArtifactDeliveryEnvelopeCompositionV1": {
131+
"type": "object",
132+
"additionalProperties": false,
133+
"required": [
134+
"schemaVersion", "artifactManifest", "userFacingArtifactSet", "linkCapability",
135+
"artifactDeliveryAttempts", "envelope", "validation"
136+
],
137+
"properties": {
138+
"schemaVersion": { "const": "FinalArtifactDeliveryEnvelopeCompositionV1" },
139+
"artifactManifest": { "$ref": "#/$defs/ArtifactDeliveryManifestV1" },
140+
"userFacingArtifactSet": { "$ref": "#/$defs/UserFacingArtifactSetV1" },
141+
"linkCapability": { "$ref": "#/$defs/HostLinkCapabilityDecisionV2" },
142+
"artifactDeliveryAttempts": { "type": "array", "items": { "$ref": "#/$defs/ArtifactDeliveryAttemptV1" } },
143+
"envelope": { "$ref": "#/$defs/DevCodexVisibleEnvelopeV3" },
144+
"validation": { "$ref": "#/$defs/validation" }
145+
}
146+
},
119147
"ArtifactAnchorV1": {
120148
"type": "object",
121149
"additionalProperties": false,

0 commit comments

Comments
 (0)