|
29888
|
5
|
5
|
5
|
117
|
0
|
0
|
refs/heads/main
|
0
|
|
1789444434
|
Edit
Delete
|
|
29887
|
5
|
1
|
5
|
117
|
0
|
0
|
|
0
|
|
1789444404
|
Edit
Delete
|
|
29886
|
5
|
5
|
5
|
116
|
0
|
0
|
refs/heads/feat/workspace-manifest-anchor
|
0
|
{"Commits":[{"Sha1":"02587c528 {"Commits":[{"Sha1":"02587c52835c0d763ab44c302cb862b5cb1a0125","Message":"feat(contracts): anchor workspace root on a manifest file, not directory names\n\ndetectWorkspaceRoot() only recognised an ancestor holding both 基础/ and doc/.\nThe directory migration splits 基础/ into 基础基座/ + 基础设施/ + 基础框架/ +\n平台治理/ and moves doc/ under 平台治理/, after which that probe returns null\nand every gate depending on it fails closed with WORKSPACE_ROOT_UNRESOLVED —\na one-constant breakage that is very hard to diagnose from the error alone.\n\nA candidate now qualifies when it holds the workspace.json manifest, falling\nback to the existing marker directories so checkouts without the manifest keep\nworking unchanged. Directory reshuffles then only touch the manifest.\n\nAdds 3 cases: manifest alone qualifies with both markers absent, an explicit\n--workspace-root carrying the manifest is accepted, and marker-only detection\nstill works. 101 → 104 tests, all passing.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T20:40:01-07:00"},{"Sha1":"e0fb26df05caf3f1cecc8328b586aa304eff51eb","Message":"chore(contracts): rename hi-atelier app to 嗨赞造意\n\napp.name 由「嗨设首席」改为「嗨赞造意」,与目录名\n业务应用/嗨赞造意/image-generation 一致。id (hi-atelier)、\nrepository、domain、owner 均不变。\n\n来源冻结目录 platform-contracts/ 按 PF-04 阶段 1 规定不改\n(CHG-001 包指纹以该目录为准,改动会触发就绪度重基线),\n两边口径差随阶段 2 物理移除消除。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T20:35:51-07:00"}],"HeadCommit":{"Sha1":"02587c52835c0d763ab44c302cb862b5cb1a0125","Message":"feat(contracts): anchor workspace root on a manifest file, not directory names\n\ndetectWorkspaceRoot() only recognised an ancestor holding both 基础/ and doc/.\nThe directory migration splits 基础/ into 基础基座/ + 基础设施/ + 基础框架/ +\n平台治理/ and moves doc/ under 平台治理/, after which that probe returns null\nand every gate depending on it fails closed with WORKSPACE_ROOT_UNRESOLVED —\na one-constant breakage that is very hard to diagnose from the error alone.\n\nA candidate now qualifies when it holds the workspace.json manifest, falling\nback to the existing marker directories so checkouts without the manifest keep\nworking unchanged. Directory reshuffles then only touch the manifest.\n\nAdds 3 cases: manifest alone qualifies with both markers absent, an explicit\n--workspace-root carrying the manifest is accepted, and marker-only detection\nstill works. 101 → 104 tests, all passing.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T20:40:01-07:00"},"CompareURL":"luoanwu/enterprise-platform/compare/517414d8806adba9ad700d6508e6c563513a583e...02587c52835c0d763ab44c302cb862b5cb1a0125","Len":2}...
|
1789444131
|
Edit
Delete
|
|
29885
|
5
|
5
|
5
|
116
|
0
|
0
|
refs/heads/feat/workspace-manifest-anchor
|
0
|
|
1789444131
|
Edit
Delete
|
|
29819
|
5
|
5
|
5
|
80
|
0
|
0
|
refs/heads/main
|
1
|
{"Commits":[{"Sha1":"bda8349f3 {"Commits":[{"Sha1":"bda8349f3440331dc74da6a4a41880607201d63d","Message":"chore: refresh governance evidence reports\n\nRegenerate reports/*.latest.json from the latest local gate run\n(contract-consumers, device-boundaries, dual-backend-parity,\nmigrations, naming, os-product-compat, schema-sync,\nstatemachine-write-guard, validation-source, evidence-current).\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T19:51:44-07:00"}],"HeadCommit":{"Sha1":"bda8349f3440331dc74da6a4a41880607201d63d","Message":"chore: refresh governance evidence reports\n\nRegenerate reports/*.latest.json from the latest local gate run\n(contract-consumers, device-boundaries, dual-backend-parity,\nmigrations, naming, os-product-compat, schema-sync,\nstatemachine-write-guard, validation-source, evidence-current).\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T19:51:44-07:00"},"CompareURL":"luoanwu/juhai-device-cloud/compare/7307924582aa9ace4042b51463833ebd9bc9d17e...bda8349f3440331dc74da6a4a41880607201d63d","Len":1}...
|
1789440869
|
Edit
Delete
|
|
29818
|
5
|
5
|
5
|
84
|
0
|
0
|
refs/heads/main
|
1
|
{"Commits":[{"Sha1":"558e30bac {"Commits":[{"Sha1":"558e30bac2666ebe08fed4d2649e433638ead6c6","Message":"feat(knowledge): harden auth and knowledge indexing retry path\n\n- packages/auth: expand JWT verification and trust-boundary handling\n with matching acceptance tests on both fastify and nestjs backends\n- knowledge indexing: add retry/backoff handling across\n knowledge-indexer, knowledge-retrieval and products/juhai.knowledgecloud\n- governance: tighten check-auth-governance, check-knowledge-index-governance,\n check-os-product and check-ui-acceptance gates\n- refresh reports/*.latest.json evidence\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T19:51:59-07:00"}],"HeadCommit":{"Sha1":"558e30bac2666ebe08fed4d2649e433638ead6c6","Message":"feat(knowledge): harden auth and knowledge indexing retry path\n\n- packages/auth: expand JWT verification and trust-boundary handling\n with matching acceptance tests on both fastify and nestjs backends\n- knowledge indexing: add retry/backoff handling across\n knowledge-indexer, knowledge-retrieval and products/juhai.knowledgecloud\n- governance: tighten check-auth-governance, check-knowledge-index-governance,\n check-os-product and check-ui-acceptance gates\n- refresh reports/*.latest.json evidence\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T19:51:59-07:00"},"CompareURL":"luoanwu/juhai-knowledge-cloud/compare/4459ca7bf19df30ae3879f2027b7fb05b3e3ba2d...558e30bac2666ebe08fed4d2649e433638ead6c6","Len":1}...
|
1789440865
|
Edit
Delete
|
|
29817
|
5
|
5
|
5
|
82
|
0
|
0
|
refs/heads/main
|
1
|
{"Commits":[{"Sha1":"ab2e7f155 {"Commits":[{"Sha1":"ab2e7f155b4fbe2e9bebc1ac4887247efc0e97c7","Message":"feat(ticket): govern automation configuration provenance\n\n- automation: record configuration provenance via new\n automation_configuration_provenance migration and configuration plugin\n- add packages/configuration-client and packages/notification-delivery\n- attachments: align service and package contracts, add package tests\n- web: rework UnifiedCalendarPanel and ticket page acceptance paths\n- add scripts/check-configuration-consumer gate and its evidence report\n- gitignore .codex/ alongside .codex-audit/ (local UX audit screenshots,\n not product source or governance input)\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T19:52:26-07:00"}],"HeadCommit":{"Sha1":"ab2e7f155b4fbe2e9bebc1ac4887247efc0e97c7","Message":"feat(ticket): govern automation configuration provenance\n\n- automation: record configuration provenance via new\n automation_configuration_provenance migration and configuration plugin\n- add packages/configuration-client and packages/notification-delivery\n- attachments: align service and package contracts, add package tests\n- web: rework UnifiedCalendarPanel and ticket page acceptance paths\n- add scripts/check-configuration-consumer gate and its evidence report\n- gitignore .codex/ alongside .codex-audit/ (local UX audit screenshots,\n not product source or governance input)\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T19:52:26-07:00"},"CompareURL":"luoanwu/juhai-ai-work-order-system/compare/f78be17ac5fecb9cfa36e167b1e85ea26a48fa45...ab2e7f155b4fbe2e9bebc1ac4887247efc0e97c7","Len":1}...
|
1789440864
|
Edit
Delete
|
|
29816
|
5
|
5
|
5
|
83
|
0
|
0
|
refs/heads/main
|
1
|
{"Commits":[{"Sha1":"a0ebf7769 {"Commits":[{"Sha1":"a0ebf7769727344892ab96c1240bd809b5791430","Message":"feat(hr): emit canonical employment facts and harden database RLS\n\n- enterprise fact relay: new relay module/service on both backends with\n recovery migration, publishing canonical employment fact intents\n- packages/contracts: add enterprise-fact contract and tests\n- database RLS: role hardening migration plus greatly expanded\n database-rls and personnel integration coverage\n- products/juhai.hr: personnel-core migrations for fact intents and relay recovery\n- governance: add check-api-migration-safety and os-product / database-rls\n governance libs with tests\n- web: rework RecruitmentWorkspace and personnel directory views\n- refresh reports evidence and os-product bundles\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T19:52:55-07:00"}],"HeadCommit":{"Sha1":"a0ebf7769727344892ab96c1240bd809b5791430","Message":"feat(hr): emit canonical employment facts and harden database RLS\n\n- enterprise fact relay: new relay module/service on both backends with\n recovery migration, publishing canonical employment fact intents\n- packages/contracts: add enterprise-fact contract and tests\n- database RLS: role hardening migration plus greatly expanded\n database-rls and personnel integration coverage\n- products/juhai.hr: personnel-core migrations for fact intents and relay recovery\n- governance: add check-api-migration-safety and os-product / database-rls\n governance libs with tests\n- web: rework RecruitmentWorkspace and personnel directory views\n- refresh reports evidence and os-product bundles\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T19:52:55-07:00"},"CompareURL":"luoanwu/juhai-ai-hr-system/compare/6823a38dc4626db9f396978663efbc2493a1276c...a0ebf7769727344892ab96c1240bd809b5791430","Len":1}...
|
1789440861
|
Edit
Delete
|
|
29815
|
5
|
5
|
5
|
81
|
0
|
0
|
refs/heads/main
|
1
|
{"Commits":[{"Sha1":"2085f1a31 {"Commits":[{"Sha1":"2085f1a31a52687344dd74911761be941a185b3c","Message":"feat(service): add notification delivery and device reference projection\n\n- notification delivery: new service-operations delivery path with\n service_notification_intents migration and integration tests on both backends\n- device reference projection: consume device-cloud reference contract\n via new packages/contracts/src/device-cloud.ts and projection migration\n- publish juhai-service-os-product 0.3.0 and refresh product/manifest locks\n- extend check-dual-backend-parity gate; refresh reports evidence\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T19:52:09-07:00"}],"HeadCommit":{"Sha1":"2085f1a31a52687344dd74911761be941a185b3c","Message":"feat(service): add notification delivery and device reference projection\n\n- notification delivery: new service-operations delivery path with\n service_notification_intents migration and integration tests on both backends\n- device reference projection: consume device-cloud reference contract\n via new packages/contracts/src/device-cloud.ts and projection migration\n- publish juhai-service-os-product 0.3.0 and refresh product/manifest locks\n- extend check-dual-backend-parity gate; refresh reports evidence\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T19:52:09-07:00"},"CompareURL":"luoanwu/juhai-after-sales-service-system/compare/466e9752ba0f670d790b5134ff2d12e5b0e974ea...2085f1a31a52687344dd74911761be941a185b3c","Len":1}...
|
1789440859
|
Edit
Delete
|
|
29814
|
5
|
5
|
5
|
72
|
0
|
0
|
refs/heads/main
|
0
|
{"Commits":[{"Sha1":"ec9e07de4 {"Commits":[{"Sha1":"ec9e07de44a5619a8a6b5648f00f5ea7f7dcafcf","Message":"feat(quotation): 接入公共文件平台并补齐 outbox 重放与通知投递\n\n- 新增 packages/public-file,对象存储改走公共文件平台契约,\n 两端 object-storage 与 files 路由同步重构\n- 新增 outbox-operations 模块与路由,配套 outbox_replay_operations 迁移,\n 支持事件重放运维操作\n- 新增 notification-delivery 模块与 packages/notification-delivery,\n 配套 quotation_notification_delivery 迁移\n- packages/contracts 补 notification / outbox-operations 契约与测试\n- 刷新 reports 证据\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T19:52:39-07:00"}],"HeadCommit":{"Sha1":"ec9e07de44a5619a8a6b5648f00f5ea7f7dcafcf","Message":"feat(quotation): 接入公共文件平台并补齐 outbox 重放与通知投递\n\n- 新增 packages/public-file,对象存储改走公共文件平台契约,\n 两端 object-storage 与 files 路由同步重构\n- 新增 outbox-operations 模块与路由,配套 outbox_replay_operations 迁移,\n 支持事件重放运维操作\n- 新增 notification-delivery 模块与 packages/notification-delivery,\n 配套 quotation_notification_delivery 迁移\n- packages/contracts 补 notification / outbox-operations 契约与测试\n- 刷新 reports 证据\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T19:52:39-07:00"},"CompareURL":"luoanwu/juhai-quotation-system/compare/125c54d328d3da221b5d91c0a2dd0475712c6e96...ec9e07de44a5619a8a6b5648f00f5ea7f7dcafcf","Len":1}...
|
1789440856
|
Edit
Delete
|
|
29813
|
5
|
5
|
5
|
51
|
0
|
0
|
refs/heads/main
|
0
|
{"Commits":[{"Sha1":"fe40791d1 {"Commits":[{"Sha1":"fe40791d1aec2f0e2a6fa6826d26b210add5f8bd","Message":"加固 JWT 信任边界并补充平台接入文档\n\n- server/src/lib/jwt.ts 收紧令牌校验,新增 jwt-trust-boundary 单元测试\n- 补充 docs/platform-onboarding.md 平台接入说明\n- 同步 env/docker-compose/vitest 配置与 r0-r1 鉴权测试\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T19:51:34-07:00"}],"HeadCommit":{"Sha1":"fe40791d1aec2f0e2a6fa6826d26b210add5f8bd","Message":"加固 JWT 信任边界并补充平台接入文档\n\n- server/src/lib/jwt.ts 收紧令牌校验,新增 jwt-trust-boundary 单元测试\n- 补充 docs/platform-onboarding.md 平台接入说明\n- 同步 env/docker-compose/vitest 配置与 r0-r1 鉴权测试\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T19:51:34-07:00"},"CompareURL":"luoanwu/yggdrasil-local-life-tools/compare/88fb2aa68377d24865992a812dc9dfb5f200569c...fe40791d1aec2f0e2a6fa6826d26b210add5f8bd","Len":1}...
|
1789440853
|
Edit
Delete
|
|
29812
|
5
|
5
|
5
|
116
|
0
|
0
|
refs/heads/main
|
0
|
{"Commits":[{"Sha1":"517414d88 {"Commits":[{"Sha1":"517414d8806adba9ad700d6508e6c563513a583e","Message":"chore(reports): rebind after merging main into the fact-read pick\n\n合并 main(6 提交)后根 pnpm check exit 0,31 项。\n\n合并过程记录两件事:\n1. runtime/clients/fact/README.md 两边都新建过——main 侧是 U-31/34 的中文接入契约,\n 本分支侧是 3074b75 的英文 reader 文档。两者内容不重叠,合并而非二选一:\n 接入契约保持 1—4 节,reader 文档作为第 5 节并入。\n2. 合并后 module-fact 构建失败(FactReadRuntime 未导出)。根因不是合并本身:\n modules/* 用 composite:true,包根的 tsconfig.tsbuildinfo 残留让 tsc -p 认为无变化,\n exit 0 却不产出更新后的 dist/index.d.ts;turbo 随后把这份**空产出缓存**了,\n 于是后续每次构建都从缓存恢复错误的 dist——删 dist 重建也没用,因为 tsbuildinfo 还在。\n 清掉 runtime 下全部 tsconfig.tsbuildinfo + turbo run build --force 后恢复正常。\n 这是 C69 形态在本仓的复现,且被 turbo 缓存放大了一层。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T19:26:21-07:00"},{"Sha1":"2a3471d25243924c1d27cf96654b8d4fa33978ca","Message":"Merge branch 'main' into feat/fact-read-http-pick\n\n# Conflicts:\n#\treports/caddy.latest.json\n#\treports/catalog-drift.latest.json\n#\treports/catalog-reconciliation.latest.json\n#\treports/facts.latest.json\n#\treports/fixtures.latest.json\n#\treports/migration-decs.latest.json\n#\treports/module-imports.latest.json\n#\truntime/clients/fact/README.md\n#\truntime/reports/agent-adapters.latest.json\n#\truntime/reports/conformance-matrix.latest.json\n#\truntime/reports/contract-consumers.latest.json\n#\truntime/reports/docs-truth.latest.json\n#\truntime/reports/dual-backend-parity.latest.json\n#\truntime/reports/fork-readiness.latest.json\n#\truntime/reports/governance-docs.latest.json\n#\truntime/reports/governance-rules.latest.json\n#\truntime/reports/governance-status.latest.json\n#\truntime/reports/governance.latest.json\n#\truntime/reports/migrations.latest.json\n#\truntime/reports/naming.latest.json\n#\truntime/reports/runtime-governance.latest.json\n#\truntime/reports/schema-sync.latest.json\n#\truntime/reports/statemachine-write-guard.latest.json\n#\truntime/reports/validation-source.latest.json\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T19:23:23-07:00"},{"Sha1":"176c33149337c2eb03a0cdfb11ed910f75700e0c","Message":"chore(reports): rebind gate reports to the fact-read pick\n\n本分支只从 codex/ms3-fact-read-http 摘取 3074b75(fact-read),不带该分支的\nscope / permission-invalidation / OpenBao 工作。九处冲突按同一规则解决:只保留\nfact-read,剔除 scope/permission 引用,证据数字与棘轮取 HEAD——本分支尚未跑过\nruntime/UI 验收,不得引用原分支 clean 3260390 的 779 tests / 97 项主线专项。\n\n本地验证:turbo typecheck --force 28/28(0 cached,非缓存命中);\n@juhai/client-fact 13/13(含新增 reader.test.ts 10 例);\n@juhai/module-fact 42/42(含新增 read-runtime.test.ts 4 例);\n根 pnpm check exit 0(30 项,check:pins 36 处 / 34 个 package.json)。\n\n未跑:e2e/fact-read-http.test.ts(需真实 M5 库 + JWT 环境)与 runtime/UI 整轮——\nmainline 清单与地板已登记该套件 10 例,但本分支没有它的运行证据。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T18:58:31-07:00"},{"Sha1":"a45389784a7c399a941306eb1454ff456e97ebcb","Message":"docs(pf-15): record the evidence binding of the adversarial round\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:37:13-07:00"},{"Sha1":"96c108dc65e3ce9838b554cafdf428023be0fd25","Message":"chore(reports): bind the read-surface adversarial evidence @ 830291c\n\nMainline acceptance re-run on an isolated compose project\n(enterprise-platform-ms23-ci: its own Postgres with tmpfs data, Redis and\nRedpanda), on databases created fresh for this round, so no state from the\nimplementing session took part: fact-read-http 11, fact-persistence 11,\naudit-tamper 8, mainline-revocation-chaos 18 — validateMainlineReport now\nreturns no errors, which it did not before this round (the floor had been\nraised to require the read suite while the stored report still had three).\nRevocation stays partial with employment Scope explicit, p95 5043 ms.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:37:02-07:00"}],"HeadCommit":{"Sha1":"517414d8806adba9ad700d6508e6c563513a583e","Message":"chore(reports): rebind after merging main into the fact-read pick\n\n合并 main(6 提交)后根 pnpm check exit 0,31 项。\n\n合并过程记录两件事:\n1. runtime/clients/fact/README.md 两边都新建过——main 侧是 U-31/34 的中文接入契约,\n 本分支侧是 3074b75 的英文 reader 文档。两者内容不重叠,合并而非二选一:\n 接入契约保持 1—4 节,reader 文档作为第 5 节并入。\n2. 合并后 module-fact 构建失败(FactReadRuntime 未导出)。根因不是合并本身:\n modules/* 用 composite:true,包根的 tsconfig.tsbuildinfo 残留让 tsc -p 认为无变化,\n exit 0 却不产出更新后的 dist/index.d.ts;turbo 随后把这份**空产出缓存**了,\n 于是后续每次构建都从缓存恢复错误的 dist——删 dist 重建也没用,因为 tsbuildinfo 还在。\n 清掉 runtime 下全部 tsconfig.tsbuildinfo + turbo run build --force 后恢复正常。\n 这是 C69 形态在本仓的复现,且被 turbo 缓存放大了一层。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T19:26:21-07:00"},"CompareURL":"luoanwu/enterprise-platform/compare/727044996fde65045ab4ca56a060c0a32fa24c0a...517414d8806adba9ad700d6508e6c563513a583e","Len":7}...
|
1789439267
|
Edit
Delete
|
|
29811
|
5
|
5
|
5
|
116
|
0
|
0
|
refs/heads/main
|
0
|
{"Commits":[{"Sha1":"727044996 {"Commits":[{"Sha1":"727044996fde65045ab4ca56a060c0a32fa24c0a","Message":"chore(reports): rebind after merging main into the U-31/33/34 branch\n\n合并 main(6 个提交)后重跑根 pnpm check:exit 0,31 项。\nmodule-imports 报告的合并冲突按「报告是运行产物」取 main 版本后由本轮重新生成。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T19:21:58-07:00"},{"Sha1":"9a7231221ba190a84f91f1f2771017927d991328","Message":"Merge branch 'main' into feat/u31-u33-u34-consumer-feedback\n\n# Conflicts:\n#\treports/module-imports.latest.json\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T19:21:34-07:00"},{"Sha1":"a76562a9c4710a6763243f4f1e1b87f12461b429","Message":"chore(reports): rebind gate reports to 66d02e6\n\n本轮 pnpm check(exit 0,30 项)与治理回归 183/183 的报告产物,按仓纪律 §5 落在实现提交之后。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T06:52:39-07:00"},{"Sha1":"66d02e665eba56a132e0c68a0916fdbb54f535e1","Message":"feat(governance,client-fact): land U-31 / U-33 / U-34 consumer feedback\n\n真实上层接入(digital-employee-os 的 os-employment-projection)暴露的三条缺口,\n按回灌纪律「机器门禁 \u003e 手册条目 \u003e 口头经验」落到本仓。\n\nU-33(机器门禁):check:pins 只读 package.json 的版本字符串,\n`\"@juhai/client-fact\": \"1.0.0-rc.2\"` 在它眼里是完美 exact pin,而 pnpm-lock.yaml 可以把同一个\n包解析到临时目录的 tarball(实测:会话 scratchpad 下的 file:/private/tmp/...tgz)。这比明着写\nfile: 依赖更危险——所有既有门禁全绿,只有别人 clone 后 pnpm install 失败才暴露。现把判据下沉到\nlockfile 的解析结果:@juhai/* 的 resolution tarball 必须落在 .npmrc 声明的 scope registry 下;\n非 registry 来源须在 platform-dependency-deviations.json 完整登记(五字段全填且未过期);\n临时目录来源不可登记豁免。\n\n不误伤既有上层仓的三条:无 lockfile 不判定;lockfile 里没有 @juhai 外部条目(纯 workspace 消费)\n不判定、也不要求 .npmrc;只有真的存在外部解析才要求声明 registry。本仓自测 checked=0 通过,\n对 OS 仓实测 4 个解析来源全部合规。\n\nU-34 / U-31(包契约):client-fact 此前没有 README,而 clients/README 却说\"实现与验收见包 README\"。\n新建并加进 files:\n- baseUrl 必须含 /api 前缀——本包用相对 URL 解析端点,少写 /api 不报错而是让所有回查 404,\n 消费者若把 404 当\"事实不存在\"就会判 UNTRUSTED_FACT、三次进死信;一个配置漏字母把整条摄入\n 变成全量死信。同时写明 404 / 不可达 / 未配置三种情况的不同处置。\n- 迁移模板只给表:策略无 TO 子句(对 PUBLIC 生效,system 角色同样被挡)且全文无 GRANT,\n 消费者若用低权限运行角色,照抄后对五张表没有任何权限。契约改为\"表 DDL 逐字照用,\n GRANT 与策略角色绑定由消费者按自身角色模型补齐\"。\n- 附 rc.3 的 STALE 行为变更与\"升级后应删除边界翻译\"。\n\n验证:新增 governance/test/check-pins.test.mjs 10 例(1 正向 + 6 负向判据 + 3 条不误伤);\n治理回归 183/183;根 pnpm check exit 0(30 项)。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T06:52:14-07:00"}],"HeadCommit":{"Sha1":"727044996fde65045ab4ca56a060c0a32fa24c0a","Message":"chore(reports): rebind after merging main into the U-31/33/34 branch\n\n合并 main(6 个提交)后重跑根 pnpm check:exit 0,31 项。\nmodule-imports 报告的合并冲突按「报告是运行产物」取 main 版本后由本轮重新生成。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T19:21:58-07:00"},"CompareURL":"luoanwu/enterprise-platform/compare/35e44a1d97cad7b20404416743167de2aa15c277...727044996fde65045ab4ca56a060c0a32fa24c0a","Len":4}...
|
1789438964
|
Edit
Delete
|
|
29810
|
5
|
5
|
5
|
76
|
0
|
0
|
refs/heads/main
|
0
|
{"Commits":[{"Sha1":"23d1b7ac7 {"Commits":[{"Sha1":"23d1b7ac7da6d8779bf29f8fabd126d9f7a15493","Message":"chore(reports): 27/27 静态门禁在 clean HEAD 全链通过\n\n首次跑完整条 check-all:27/27 步骤 exit 0,含此前因 fail-fast 从未执行到的\ncheck:governance、lint、typecheck 与末位的 check:platform-provenance。\n\n解锁点是 runtime-acceptance 转 passed(c9d2f3a 的 clean SHA 三级证据):\ncheck:docs-truth 的 governance-number-evidence-shape 要求 runtime/governance/baseline\n三份数字真源都 passed,此前它是 failed,把整条链卡在第 23 步。\n\ncheck:platform-provenance 作为末位步骤首次被执行到并通过——@juhai/* 四个解析来源\n全部落在 .npmrc 声明的 registry 下,0 违规 / 0 登记偏差。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T19:02:12-07:00"}],"HeadCommit":{"Sha1":"23d1b7ac7da6d8779bf29f8fabd126d9f7a15493","Message":"chore(reports): 27/27 静态门禁在 clean HEAD 全链通过\n\n首次跑完整条 check-all:27/27 步骤 exit 0,含此前因 fail-fast 从未执行到的\ncheck:governance、lint、typecheck 与末位的 check:platform-provenance。\n\n解锁点是 runtime-acceptance 转 passed(c9d2f3a 的 clean SHA 三级证据):\ncheck:docs-truth 的 governance-number-evidence-shape 要求 runtime/governance/baseline\n三份数字真源都 passed,此前它是 failed,把整条链卡在第 23 步。\n\ncheck:platform-provenance 作为末位步骤首次被执行到并通过——@juhai/* 四个解析来源\n全部落在 .npmrc 声明的 registry 下,0 违规 / 0 登记偏差。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T19:02:12-07:00"},"CompareURL":"luoanwu/digital-employee-os/compare/070b9440b579a7662952fe817638313fadcf01bd...23d1b7ac7da6d8779bf29f8fabd126d9f7a15493","Len":1}...
|
1789438843
|
Edit
Delete
|
|
29793
|
5
|
5
|
5
|
76
|
0
|
0
|
refs/heads/feat/os-04-employment-projection
|
0
|
{"Commits":[{"Sha1":"23d1b7ac7 {"Commits":[{"Sha1":"23d1b7ac7da6d8779bf29f8fabd126d9f7a15493","Message":"chore(reports): 27/27 静态门禁在 clean HEAD 全链通过\n\n首次跑完整条 check-all:27/27 步骤 exit 0,含此前因 fail-fast 从未执行到的\ncheck:governance、lint、typecheck 与末位的 check:platform-provenance。\n\n解锁点是 runtime-acceptance 转 passed(c9d2f3a 的 clean SHA 三级证据):\ncheck:docs-truth 的 governance-number-evidence-shape 要求 runtime/governance/baseline\n三份数字真源都 passed,此前它是 failed,把整条链卡在第 23 步。\n\ncheck:platform-provenance 作为末位步骤首次被执行到并通过——@juhai/* 四个解析来源\n全部落在 .npmrc 声明的 registry 下,0 违规 / 0 登记偏差。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T19:02:12-07:00"},{"Sha1":"070b9440b579a7662952fe817638313fadcf01bd","Message":"docs(governance): 登记 C253 与 G25 闭合项,刷新锚点\n\nC253(新增闭合记录):三个基座门禁把实时频道订阅写死成基础频道,而 dispatcher 按 Redis 逻辑库分区发布——\n只有 db 0 能过,而 O1 纪律要求验收用独立逻辑库;三处失败信息还分别指向凭据隔离、依赖恢复与多进程领取,\n把门禁自己的假设伪装成被测对象的问题,并连带让静态链长期止步第 23 步。\n\nG25 同步:⑤ SDK 的 STALE 语义已闭合(rc.3 已发布、本仓已升级并删除边界翻译,判定回到 SDK 单源);\n新增 ⑥ 运行态证据已就位(clean HEAD runtime passed + 静态 27/27),并明确它**不改变** ①②④ 的未闭环判断。\n\n本轮静态 27/27 复跑通过;锚点按 C241 指向父提交。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:24:34-07:00"},{"Sha1":"c9d2f3acf72a2b36c581d7f44cc8eea0d2b91080","Message":"chore(reports): 首次 clean SHA 绑定的三级证据(runtime passed + 静态 27/27)\n\n`6396f7f` clean 树上:\n- `pnpm check:runtime` **status=passed、worktreeDirty=false**——本仓 `reports/runtime-acceptance.latest.json`\n 第一次绑定 clean commit(733 tests / 0 failures、行为矩阵 204/204、十步全绿)。M0「reports 首次绑定\n clean SHA」与 OS-04 退出门要求的真实 DB 证据同时满足。\n- `pnpm check` **27/27 步骤全部通过**,23 份静态报告同样 `worktreeDirty:false`。\n\n动态区按本轮报告更新:静态证据行改写为 clean HEAD 27/27;锚点指向父提交(C241/C232)。\n边界:本地单机证据,未推送、远端 CI 未跑;G14 的远端拦截、试点 A 的 HR 端到端与目标环境签收仍 OPEN。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:22:15-07:00"},{"Sha1":"6396f7f20f8e418463280f27609295d18666bb28","Message":"docs(governance): 刷新快照锚点到 666f5e2(批次收尾)\n\nC241/C232:推送批次最后一个提交必须把锚点指向其父提交,纯报告刷新提交同样算提交。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:00:44-07:00"},{"Sha1":"666f5e2fee8caa849d6d44387e8d046aa898b02f","Message":"chore(reports): clean SHA 上重跑 runtime,按已跟踪测试数校正动态区\n\n`7fb2dd6` clean 树整轮 runtime 只余 own-test-cases 漂移:新增的两份 Kafka 投递测试在提交后才计入\ngit 已跟踪集合(C70 口径),因此 90/730 → 92/736。本提交同步数字并带上本轮报告;\n锚点仍指向 `bc99e5b`(落后 2,超 +1 自指窗),由下一个提交刷新。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:00:33-07:00"}],"HeadCommit":{"Sha1":"23d1b7ac7da6d8779bf29f8fabd126d9f7a15493","Message":"chore(reports): 27/27 静态门禁在 clean HEAD 全链通过\n\n首次跑完整条 check-all:27/27 步骤 exit 0,含此前因 fail-fast 从未执行到的\ncheck:governance、lint、typecheck 与末位的 check:platform-provenance。\n\n解锁点是 runtime-acceptance 转 passed(c9d2f3a 的 clean SHA 三级证据):\ncheck:docs-truth 的 governance-number-evidence-shape 要求 runtime/governance/baseline\n三份数字真源都 passed,此前它是 failed,把整条链卡在第 23 步。\n\ncheck:platform-provenance 作为末位步骤首次被执行到并通过——@juhai/* 四个解析来源\n全部落在 .npmrc 声明的 registry 下,0 违规 / 0 登记偏差。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T19:02:12-07:00"},"CompareURL":"luoanwu/digital-employee-os/compare/3c100f855828a6b046679818aafce7f1bbf3bfb8...23d1b7ac7da6d8779bf29f8fabd126d9f7a15493","Len":7}...
|
1789437763
|
Edit
Delete
|
|
29774
|
5
|
5
|
5
|
116
|
0
|
0
|
refs/heads/feat/fact-read-http-pick
|
0
|
{"Commits":[{"Sha1":"176c33149 {"Commits":[{"Sha1":"176c33149337c2eb03a0cdfb11ed910f75700e0c","Message":"chore(reports): rebind gate reports to the fact-read pick\n\n本分支只从 codex/ms3-fact-read-http 摘取 3074b75(fact-read),不带该分支的\nscope / permission-invalidation / OpenBao 工作。九处冲突按同一规则解决:只保留\nfact-read,剔除 scope/permission 引用,证据数字与棘轮取 HEAD——本分支尚未跑过\nruntime/UI 验收,不得引用原分支 clean 3260390 的 779 tests / 97 项主线专项。\n\n本地验证:turbo typecheck --force 28/28(0 cached,非缓存命中);\n@juhai/client-fact 13/13(含新增 reader.test.ts 10 例);\n@juhai/module-fact 42/42(含新增 read-runtime.test.ts 4 例);\n根 pnpm check exit 0(30 项,check:pins 36 处 / 34 个 package.json)。\n\n未跑:e2e/fact-read-http.test.ts(需真实 M5 库 + JWT 环境)与 runtime/UI 整轮——\nmainline 清单与地板已登记该套件 10 例,但本分支没有它的运行证据。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T18:58:31-07:00"},{"Sha1":"a45389784a7c399a941306eb1454ff456e97ebcb","Message":"docs(pf-15): record the evidence binding of the adversarial round\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:37:13-07:00"},{"Sha1":"96c108dc65e3ce9838b554cafdf428023be0fd25","Message":"chore(reports): bind the read-surface adversarial evidence @ 830291c\n\nMainline acceptance re-run on an isolated compose project\n(enterprise-platform-ms23-ci: its own Postgres with tmpfs data, Redis and\nRedpanda), on databases created fresh for this round, so no state from the\nimplementing session took part: fact-read-http 11, fact-persistence 11,\naudit-tamper 8, mainline-revocation-chaos 18 — validateMainlineReport now\nreturns no errors, which it did not before this round (the floor had been\nraised to require the read suite while the stored report still had three).\nRevocation stays partial with employment Scope explicit, p95 5043 ms.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:37:02-07:00"},{"Sha1":"830291c1795695f979219d89c55b6b5455a6169e","Message":"fix(fact): refuse a bearer carried in the read surface URL\n\nAdversarial acceptance of the accepted-fact read candidate on an isolated\nstack found that `?access_token=\u003cjwt\u003e` alone returned 200: the shared\nAuthGuard accepts a query token so WS/SSE, which have no header, can\nauthenticate, and the new route inherited it. A consumer read has a header,\nand a bearer in the URL is copied into every proxy access log, so the route\nnow refuses the channel itself with 401 FACT_READ_URL_CREDENTIAL_REFUSED —\nincluding when a valid header accompanies it, since the token has already\nreached the log line. An empty `?access_token=` is not a credential.\n\nAlso records what the round could not fix in code: a consumer registration\nthat is deactivated answers 403 and is retryable, while one that is still\nactive but out of source-domain/type scope answers the same 404 as an\nunknown id, which the Inbox turns into a dead letter. Narrowing the scope of\na live consumer therefore dead-letters facts already in flight; the SDK\nREADME now states the deactivate-first rule. The read path writes no audit\nrecord, registered as CHG-004 material rather than opening a write path in a\nread-only runtime.\n\nRead suite 10 -\u003e 11 cases; MAINLINE_SUITES floor raised with it.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:33:43-07:00"},{"Sha1":"78edacc6e101fa24876cac37302ffb425fd94597","Message":"feat(fact): authenticate accepted-fact reads for remote Inbox verification\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-12T20:14:01-07:00"}],"HeadCommit":{"Sha1":"176c33149337c2eb03a0cdfb11ed910f75700e0c","Message":"chore(reports): rebind gate reports to the fact-read pick\n\n本分支只从 codex/ms3-fact-read-http 摘取 3074b75(fact-read),不带该分支的\nscope / permission-invalidation / OpenBao 工作。九处冲突按同一规则解决:只保留\nfact-read,剔除 scope/permission 引用,证据数字与棘轮取 HEAD——本分支尚未跑过\nruntime/UI 验收,不得引用原分支 clean 3260390 的 779 tests / 97 项主线专项。\n\n本地验证:turbo typecheck --force 28/28(0 cached,非缓存命中);\n@juhai/client-fact 13/13(含新增 reader.test.ts 10 例);\n@juhai/module-fact 42/42(含新增 read-runtime.test.ts 4 例);\n根 pnpm check exit 0(30 项,check:pins 36 处 / 34 个 package.json)。\n\n未跑:e2e/fact-read-http.test.ts(需真实 M5 库 + JWT 环境)与 runtime/UI 整轮——\nmainline 清单与地板已登记该套件 10 例,但本分支没有它的运行证据。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T18:58:31-07:00"},"CompareURL":"luoanwu/enterprise-platform/compare/036a308f27acf35a46f068c96fea7723ef74d05e...176c33149337c2eb03a0cdfb11ed910f75700e0c","Len":5}...
|
1789437578
|
Edit
Delete
|
|
29773
|
5
|
5
|
5
|
116
|
0
|
0
|
refs/heads/feat/fact-read-http-pick
|
0
|
|
1789437578
|
Edit
Delete
|
|
29580
|
5
|
5
|
5
|
116
|
0
|
0
|
refs/heads/main
|
0
|
{"Commits":[{"Sha1":"35e44a1d9 {"Commits":[{"Sha1":"35e44a1d97cad7b20404416743167de2aa15c277","Message":"chore(reports): bind check:evidence baseline @ 5f0473b\n\n13 份已登记报告新鲜,5 条 warn(port-conformance、runtime/ui 验收、\nrevocation-sla、mainline-acceptance —— 都是需要真实库/容器才能重跑的,\n已在 evidence-scopes.json 写明 promoteBy),32 份未登记只计 info。\nmodule-imports 顺带在干净树重跑回绑(315 文件 0 违规)。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:37:16-07:00"},{"Sha1":"5f0473b6d7bf2089d3715c6f637320d6d96ac862","Message":"feat(governance): gate machine-evidence freshness by scope, not commit distance\n\n仓纪律 5 只要求报告绑 gitSha + worktreeDirty=false,没有任何检查关心那个 SHA\n相对 HEAD 是否已经过期;runtime 的 check:docs-truth 断言 N 也只比对「文档声明的\nSHA == 报告 provenance 的 SHA」。于是 CLAUDE.md 的「当前状态」可以逐字引用一份\n早被后续提交推翻的报告,而全链门禁一片绿。\n\n2026-09-14 实锤:main 上 stack-image-pins.latest.json 绑 7e279c5,其后\nstack/compose.yaml 已被改(ai-gateway 去掉空 DATABASE_URL),那份「12 镜像\n0 未锁」的结论形式上已失效,无人察觉。\n\n判据特意不用「落后几个提交」——实测那样会误报 38 条(runtime 验收落后 32 个\n提交,作用域却一行没动)。判据是:绑定 SHA → HEAD 之间有没有改到该报告自己\n覆盖的文件,作用域逐条登记在 governance/evidence-scopes.json。\n\n- severity 逐条登记:静态检查 error,需真实库/容器重跑的验收先 warn 并写\n promoteBy,覆盖面与严格度都按登记涨,不搞一刀切。\n- 脏绑报告在干净树上判红(说明脏绑被提交了),在脏树上只 warn(改到一半)。\n- 例外须带 reason/recordedAt/resolveBy(G-13),失效判 EXCEPTION_STALE。\n- 未登记的报告只计 SCOPE_UNDECLARED(info),不判红。\n\n10 个用例,含一个真实 git 仓集成用例钉住核心判据:作用域外连改三个提交仍绿,\n作用域内一改即红。放在根 check 链尾。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:36:33-07:00"}],"HeadCommit":{"Sha1":"35e44a1d97cad7b20404416743167de2aa15c277","Message":"chore(reports): bind check:evidence baseline @ 5f0473b\n\n13 份已登记报告新鲜,5 条 warn(port-conformance、runtime/ui 验收、\nrevocation-sla、mainline-acceptance —— 都是需要真实库/容器才能重跑的,\n已在 evidence-scopes.json 写明 promoteBy),32 份未登记只计 info。\nmodule-imports 顺带在干净树重跑回绑(315 文件 0 违规)。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:37:16-07:00"},"CompareURL":"luoanwu/enterprise-platform/compare/9807535a2b81bc14a35ffc306d7b1b0910f0f99f...35e44a1d97cad7b20404416743167de2aa15c277","Len":2}...
|
1789408337
|
Edit
Delete
|
|
29579
|
5
|
5
|
5
|
76
|
0
|
0
|
refs/heads/main
|
0
|
{"Commits":[{"Sha1":"070b9440b {"Commits":[{"Sha1":"070b9440b579a7662952fe817638313fadcf01bd","Message":"docs(governance): 登记 C253 与 G25 闭合项,刷新锚点\n\nC253(新增闭合记录):三个基座门禁把实时频道订阅写死成基础频道,而 dispatcher 按 Redis 逻辑库分区发布——\n只有 db 0 能过,而 O1 纪律要求验收用独立逻辑库;三处失败信息还分别指向凭据隔离、依赖恢复与多进程领取,\n把门禁自己的假设伪装成被测对象的问题,并连带让静态链长期止步第 23 步。\n\nG25 同步:⑤ SDK 的 STALE 语义已闭合(rc.3 已发布、本仓已升级并删除边界翻译,判定回到 SDK 单源);\n新增 ⑥ 运行态证据已就位(clean HEAD runtime passed + 静态 27/27),并明确它**不改变** ①②④ 的未闭环判断。\n\n本轮静态 27/27 复跑通过;锚点按 C241 指向父提交。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:24:34-07:00"},{"Sha1":"c9d2f3acf72a2b36c581d7f44cc8eea0d2b91080","Message":"chore(reports): 首次 clean SHA 绑定的三级证据(runtime passed + 静态 27/27)\n\n`6396f7f` clean 树上:\n- `pnpm check:runtime` **status=passed、worktreeDirty=false**——本仓 `reports/runtime-acceptance.latest.json`\n 第一次绑定 clean commit(733 tests / 0 failures、行为矩阵 204/204、十步全绿)。M0「reports 首次绑定\n clean SHA」与 OS-04 退出门要求的真实 DB 证据同时满足。\n- `pnpm check` **27/27 步骤全部通过**,23 份静态报告同样 `worktreeDirty:false`。\n\n动态区按本轮报告更新:静态证据行改写为 clean HEAD 27/27;锚点指向父提交(C241/C232)。\n边界:本地单机证据,未推送、远端 CI 未跑;G14 的远端拦截、试点 A 的 HR 端到端与目标环境签收仍 OPEN。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:22:15-07:00"},{"Sha1":"6396f7f20f8e418463280f27609295d18666bb28","Message":"docs(governance): 刷新快照锚点到 666f5e2(批次收尾)\n\nC241/C232:推送批次最后一个提交必须把锚点指向其父提交,纯报告刷新提交同样算提交。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:00:44-07:00"},{"Sha1":"666f5e2fee8caa849d6d44387e8d046aa898b02f","Message":"chore(reports): clean SHA 上重跑 runtime,按已跟踪测试数校正动态区\n\n`7fb2dd6` clean 树整轮 runtime 只余 own-test-cases 漂移:新增的两份 Kafka 投递测试在提交后才计入\ngit 已跟踪集合(C70 口径),因此 90/730 → 92/736。本提交同步数字并带上本轮报告;\n锚点仍指向 `bc99e5b`(落后 2,超 +1 自指窗),由下一个提交刷新。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:00:33-07:00"},{"Sha1":"7fb2dd6d376fdbe58e31bd99060c033c67bac808","Message":"chore(reports): 首次整轮 runtime 绿盘 + 静态 27/27,刷新锚点\n\n本批次证据(本地 dirty 工作区,共享底座 PG 55470 + OS 专用 Redis 6404/3):\n- `pnpm check:runtime` status=passed、exit 0:733 tests / 0 failures、行为矩阵 204/204,\n 十步全绿(迁移 deploy/status、七包测试、auth-startup、db-credential-separation、tracing、\n dependency-resilience、capacity、write-capacity、multi-instance、docs-truth 复验)。\n- `pnpm check` **27/27 步骤全部通过**——此前长期止于第 23 步 `check:docs-truth` 的\n `governance-number-evidence-shape`(它要求一份 passed 的 runtime 报告,而整轮从未跑通)。\n 两件事同时闭合:门禁频道假设修复让 runtime 能跑完,动态数字随即可以按真实报告对齐。\n\n按 C241/C232:本批次最后一个提交把快照锚点指向父提交 `bc99e5b`(落后 HEAD 0,写锚点自占 +1 自指窗)。\n边界:这些报告绑定的是 **dirty 工作区指纹**,不是 clean commit;clean SHA 绑定需要在本提交之上重跑。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T09:48:04-07:00"}],"HeadCommit":{"Sha1":"070b9440b579a7662952fe817638313fadcf01bd","Message":"docs(governance): 登记 C253 与 G25 闭合项,刷新锚点\n\nC253(新增闭合记录):三个基座门禁把实时频道订阅写死成基础频道,而 dispatcher 按 Redis 逻辑库分区发布——\n只有 db 0 能过,而 O1 纪律要求验收用独立逻辑库;三处失败信息还分别指向凭据隔离、依赖恢复与多进程领取,\n把门禁自己的假设伪装成被测对象的问题,并连带让静态链长期止步第 23 步。\n\nG25 同步:⑤ SDK 的 STALE 语义已闭合(rc.3 已发布、本仓已升级并删除边界翻译,判定回到 SDK 单源);\n新增 ⑥ 运行态证据已就位(clean HEAD runtime passed + 静态 27/27),并明确它**不改变** ①②④ 的未闭环判断。\n\n本轮静态 27/27 复跑通过;锚点按 C241 指向父提交。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:24:34-07:00"},"CompareURL":"luoanwu/digital-employee-os/compare/18a1b036f3dbb3f51ac773862e0cafac278bb34e...070b9440b579a7662952fe817638313fadcf01bd","Len":16}...
|
1789407027
|
Edit
Delete
|
|
29578
|
5
|
5
|
5
|
57
|
0
|
0
|
refs/heads/audit/adversarial-acceptance-20260913
|
0
|
{"Commits":[{"Sha1":"0724820e7 {"Commits":[{"Sha1":"0724820e7884688d0466bc74563122005bbac86e","Message":"docs(releases): record cost-fix1 deployment and video delivery probe\n\nThe F1 fix is live as release-20260914-cost-fix1 (commit 591c7732,\nfingerprint 603541f5): five components healthy, 11 probes, OCR ok. Post-\ndeploy adversarial recheck with real paid calls confirmed online image\ngeneration still produces real pixels and a real Wan 3.0 storyboard video\n(11.3MB MP4, ftypisom, 5s) records its cost honestly as UNKNOWN. current.md\nnow points at cost-fix1; the round log gains the video section.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:24:52-07:00"}],"HeadCommit":{"Sha1":"0724820e7884688d0466bc74563122005bbac86e","Message":"docs(releases): record cost-fix1 deployment and video delivery probe\n\nThe F1 fix is live as release-20260914-cost-fix1 (commit 591c7732,\nfingerprint 603541f5): five components healthy, 11 probes, OCR ok. Post-\ndeploy adversarial recheck with real paid calls confirmed online image\ngeneration still produces real pixels and a real Wan 3.0 storyboard video\n(11.3MB MP4, ftypisom, 5s) records its cost honestly as UNKNOWN. current.md\nnow points at cost-fix1; the round log gains the video section.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:24:52-07:00"},"CompareURL":"luoanwu/image-generation/compare/591c7732f49294e52a383f9b42d3bb0d4a595712...0724820e7884688d0466bc74563122005bbac86e","Len":1}...
|
1789406734
|
Edit
Delete
|
|
29577
|
5
|
5
|
5
|
57
|
0
|
0
|
refs/heads/main
|
0
|
{"Commits":[{"Sha1":"0724820e7 {"Commits":[{"Sha1":"0724820e7884688d0466bc74563122005bbac86e","Message":"docs(releases): record cost-fix1 deployment and video delivery probe\n\nThe F1 fix is live as release-20260914-cost-fix1 (commit 591c7732,\nfingerprint 603541f5): five components healthy, 11 probes, OCR ok. Post-\ndeploy adversarial recheck with real paid calls confirmed online image\ngeneration still produces real pixels and a real Wan 3.0 storyboard video\n(11.3MB MP4, ftypisom, 5s) records its cost honestly as UNKNOWN. current.md\nnow points at cost-fix1; the round log gains the video section.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:24:52-07:00"}],"HeadCommit":{"Sha1":"0724820e7884688d0466bc74563122005bbac86e","Message":"docs(releases): record cost-fix1 deployment and video delivery probe\n\nThe F1 fix is live as release-20260914-cost-fix1 (commit 591c7732,\nfingerprint 603541f5): five components healthy, 11 probes, OCR ok. Post-\ndeploy adversarial recheck with real paid calls confirmed online image\ngeneration still produces real pixels and a real Wan 3.0 storyboard video\n(11.3MB MP4, ftypisom, 5s) records its cost honestly as UNKNOWN. current.md\nnow points at cost-fix1; the round log gains the video section.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:24:52-07:00"},"CompareURL":"luoanwu/image-generation/compare/591c7732f49294e52a383f9b42d3bb0d4a595712...0724820e7884688d0466bc74563122005bbac86e","Len":1}...
|
1789406721
|
Edit
Delete
|
|
29576
|
5
|
5
|
5
|
116
|
0
|
0
|
refs/heads/main
|
0
|
{"Commits":[{"Sha1":"9807535a2 {"Commits":[{"Sha1":"9807535a2b81bc14a35ffc306d7b1b0910f0f99f","Message":"chore(reports): bind the ai-gateway first-start evidence @ 51351b3\n\nliveliness / readiness 200(db: Not connected)、带 master key 的 /v1/models\n200 返回 platform-default-chat、无 key 401 / 错 key 400;/v1/chat/completions\n401 是供应商侧 replace-me,链路本身通。干净树绑 51351b3。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:10:43-07:00"},{"Sha1":"51351b3b0af2fc485c59fbddc4e1ade821c38f6a","Message":"fix(stack): stop injecting an empty DATABASE_URL into ai-gateway\n\nLiteLLM 见到空串即以 \"unsupported scheme '\u003cmissing scheme\u003e'\" 退出,而\n`DATABASE_URL: ${LITELLM_DATABASE_URL:-}` 在变量未设时注入的正是空串。\n这个定义从 2026-09-11 写下起就没被验证过——stack-up 记录里 ai-gateway\n一直是\"未起\",所以缺陷一直没暴露。\n\n- compose.yaml:ai-gateway 不再声明 DATABASE_URL(无 DB 模式)。\n- overlays/ai-gateway-db.yaml:要 DB 模式改为显式叠加,且 LITELLM_DATABASE_URL\n 必填;注释写明不得指向 platform_aigateway_*(M7 权威库)。\n- stack/README:镜像行改为 digest 实况,litellm tag 已首次 pull 核实;\n 两处\"ai-gateway 未起\"改为 12 服务全跑。\n- CLAUDE.md stack 行补 2026-09-14 增量,只引机器证据。\n\n本轮只动 D-7 采纳组件,未动 M7 模块(仍 state=shape / blocked_by DEC-007)。\n供应商密钥仍是 replace-me,真实模型调用返回供应商 401,已在记录里写明。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:06:42-07:00"},{"Sha1":"92a5a9fdd1468c29a4aed90328034e02d39ac9d3","Message":"chore(reports): bind the B-7 resident-runtime evidence @ 092df0e\n\n七 profile 装载、内核与七个模块 /health 全 200、无凭证决策端点 401、经 Caddy\n入口 200;容器 restart unless-stopped、healthy。provenance 干净树绑 092df0e。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:10:32-07:00"},{"Sha1":"092df0eefc510ce4a0f4f39400f1193c66ad6d8f","Message":"feat(stack): run the platform runtime as a resident dev container (B-7)\n\n核实报告的 B-7 记「没有可被 HR / OS 调用的地址」:compose 的 runtime 一直是\n候选注释块,七个 platform_\u003cm\u003e_dev 库建了但零张表。本次启用该服务并把它跑起来。\n\n- compose.yaml:启用 runtime,镜像改 ${PLATFORM_RUNTIME_IMAGE:?};补上原模板\n 缺的七个 DATABASE_URL_\u003cMODULE\u003e——模板写于一模块一库之前,只有内核三个 URL,\n 按原样启用四个 authority 模块会连不上自己的库。\n- overlays/dev.yaml:restart unless-stopped + 回环 53001。\n- provision/redis-dbs.json:登记逻辑库 14(七 profile 同进程只能独占一个)。\n- runbook §2 / stack README:dev 常驻形态与起停命令。\n\n供给与验收留在 docs/B-7-dev常驻运行时启动记录-2026-09-14.md;环境变量文件在\n仓外 .secrets/,不入 git。ai-gateway 容器因 ghcr 拉取经本机代理被 reset 未起,\n已在记录里写明,不冒充全量。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T09:51:41-07:00"},{"Sha1":"036a308f27acf35a46f068c96fea7723ef74d05e","Message":"feat(client-fact): U-29 判落后版本为 STALE,不再当毒消息\n\n真实消费者接入(digital-employee-os 的 os-employment-projection)暴露:applyOne 在\nversion \u003c= watermark 时抛 FactRejected(\"UNPROCESSED_VERSION_BEHIND_WATERMARK\"),\n而 handle 把任何 FactRejected 计入 attempts——至少一次投递下的**正常迟到重投**三次即\n被打进死信,与\"内容有毒\"共用一套判据;类型里写着的 \"STALE\" 返回值反而不可达。\n平台自己的主线 e2e 用合成宿主表,从不重放已过水位的事实,因此一直照不出这条。\n\n改为返回 \"STALE\",并顺手删掉该 fact 可能留在 gap 缓冲里的副本:落后事实永远等不到\nprevious_version = 水位,留着只会把缓冲占满到 GAP_BUFFER_FULL,drain 循环也会空转。\n\n证据:runtime/test/e2e/mainline.test.ts 新增断言——清掉 processed 行后重放旧事实,\n连判三次 STALE、platform_client_fact_failure 无行、投影仍停在 11;该文件 6/6 通过\n(真实 M3/M5/M6 库 + Redpanda,MAINLINE_ENV=ms23)。治理负向回归 173/173、\ncheck:pins 34 个 package.json 全 exact pin、根 pnpm check 全链通过。\n\n发布列车三件套同步升到 1.0.0-rc.3,**尚未发布**:rc.2 已在 Registry 且不可覆盖,\n上层在 rc.3 发布前继续 pin rc.2 并在边界做错误码翻译。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T22:10:52-07:00"}],"HeadCommit":{"Sha1":"9807535a2b81bc14a35ffc306d7b1b0910f0f99f","Message":"chore(reports): bind the ai-gateway first-start evidence @ 51351b3\n\nliveliness / readiness 200(db: Not connected)、带 master key 的 /v1/models\n200 返回 platform-default-chat、无 key 401 / 错 key 400;/v1/chat/completions\n401 是供应商侧 replace-me,链路本身通。干净树绑 51351b3。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:10:43-07:00"},"CompareURL":"luoanwu/enterprise-platform/compare/d1ef5414093aa67ff4b8e2b7af8d13be86aed7ba...9807535a2b81bc14a35ffc306d7b1b0910f0f99f","Len":5}...
|
1789405885
|
Edit
Delete
|
|
29575
|
5
|
5
|
5
|
57
|
0
|
0
|
refs/heads/audit/adversarial-acceptance-20260913
|
0
|
{"Commits":[{"Sha1":"591c7732f {"Commits":[{"Sha1":"591c7732f49294e52a383f9b42d3bb0d4a595712","Message":"docs(governance): record the adversarial cost-recording fix round\n\nPoint the twelve heavy baseline rows at the reverified fingerprint\n603541f5 (the F1 fix), and log the adversarial acceptance round: the\nonline-image cost-recording blind spot, its fix and regression, the live\npaid delivery proof, the boundary probes that held, and the video path\nconfirmed correct. Evidence under reports/adversarial-acceptance-2026-09-14/.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:07:22-07:00"}],"HeadCommit":{"Sha1":"591c7732f49294e52a383f9b42d3bb0d4a595712","Message":"docs(governance): record the adversarial cost-recording fix round\n\nPoint the twelve heavy baseline rows at the reverified fingerprint\n603541f5 (the F1 fix), and log the adversarial acceptance round: the\nonline-image cost-recording blind spot, its fix and regression, the live\npaid delivery proof, the boundary probes that held, and the video path\nconfirmed correct. Evidence under reports/adversarial-acceptance-2026-09-14/.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:07:22-07:00"},"CompareURL":"luoanwu/image-generation/compare/13fe1037486e5d393f986446219e457190ec1863...591c7732f49294e52a383f9b42d3bb0d4a595712","Len":1}...
|
1789405680
|
Edit
Delete
|
|
29574
|
5
|
5
|
5
|
57
|
0
|
0
|
refs/heads/main
|
0
|
{"Commits":[{"Sha1":"591c7732f {"Commits":[{"Sha1":"591c7732f49294e52a383f9b42d3bb0d4a595712","Message":"docs(governance): record the adversarial cost-recording fix round\n\nPoint the twelve heavy baseline rows at the reverified fingerprint\n603541f5 (the F1 fix), and log the adversarial acceptance round: the\nonline-image cost-recording blind spot, its fix and regression, the live\npaid delivery proof, the boundary probes that held, and the video path\nconfirmed correct. Evidence under reports/adversarial-acceptance-2026-09-14/.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:07:22-07:00"}],"HeadCommit":{"Sha1":"591c7732f49294e52a383f9b42d3bb0d4a595712","Message":"docs(governance): record the adversarial cost-recording fix round\n\nPoint the twelve heavy baseline rows at the reverified fingerprint\n603541f5 (the F1 fix), and log the adversarial acceptance round: the\nonline-image cost-recording blind spot, its fix and regression, the live\npaid delivery proof, the boundary probes that held, and the video path\nconfirmed correct. Evidence under reports/adversarial-acceptance-2026-09-14/.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:07:22-07:00"},"CompareURL":"luoanwu/image-generation/compare/13fe1037486e5d393f986446219e457190ec1863...591c7732f49294e52a383f9b42d3bb0d4a595712","Len":1}...
|
1789405669
|
Edit
Delete
|
|
29573
|
5
|
5
|
5
|
57
|
0
|
0
|
refs/heads/audit/adversarial-acceptance-20260913
|
0
|
{"Commits":[],"HeadCommit":{"S {"Commits":[],"HeadCommit":{"Sha1":"13fe1037486e5d393f986446219e457190ec1863","Message":"fix(cost): record and cap online image generation invocations\n\nAdversarial acceptance found that generateConnectedImage — the online\nimage path for DASHSCOPE_WAN and OpenAI-compatible connections — called\nthe provider directly via postJson without withRecordedModelCall, the\none place that both writes a ModelInvocation and enforces the per-task\nbudget cap before dispatch. A real Wan 2.7 Pro custom-image generation\n(kind IMAGE / DESIGN_MASTER) therefore produced a genuine paid image\n(providerRequestId, ~28s, real PNG) but left no cost record, and the\nbrand's maxCostMicrosPerTask never applied. Every recorded wan2.7-image\ninvocation in the live DB came from ROLE/STILL (sidecar path); none from\nIMAGE — matching the gap. Video (sidecar) and text (connector) were\nalready wrapped and unaffected.\n\nWrap the online image call in withRecordedModelCall via a new\nconnectorImageCallPlan (modality IMAGE, connector-direct, external), map\nModelCostLimitError to the same COST_LIMIT_BLOCKED channel the text path\nuses, and report usage.images = 1 so the realized cost is ESTIMATED at\nthe catalog price, matching ROLE/STILL. Without an invocation context the\nwrapper passes through unchanged, so bare unit calls are unaffected.\n\nRegression in model-connector.client.test.ts: with a scope the online\nWan call records one IMAGE invocation (RUNNING -\u003e SUCCEEDED, 500000\nmicros, ESTIMATED); a per-task cap below the catalog price blocks before\ndispatch (COST_LIMIT_BLOCKED), the request never leaves the host, and one\nBLOCKED row is written.\n\nEvidence: acceptance-artifacts/adversarial-acceptance-2026-09-13/.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:01:08-07:00"},"CompareURL":"luoanwu/image-generation/compare/main...13fe1037486e5d393f986446219e457190ec1863","Len":0}...
|
1789405494
|
Edit
Delete
|
|
29572
|
5
|
5
|
5
|
57
|
0
|
0
|
refs/heads/audit/adversarial-acceptance-20260913
|
0
|
|
1789405494
|
Edit
Delete
|
|
29571
|
5
|
5
|
5
|
57
|
0
|
0
|
refs/heads/main
|
0
|
{"Commits":[{"Sha1":"13fe10374 {"Commits":[{"Sha1":"13fe1037486e5d393f986446219e457190ec1863","Message":"fix(cost): record and cap online image generation invocations\n\nAdversarial acceptance found that generateConnectedImage — the online\nimage path for DASHSCOPE_WAN and OpenAI-compatible connections — called\nthe provider directly via postJson without withRecordedModelCall, the\none place that both writes a ModelInvocation and enforces the per-task\nbudget cap before dispatch. A real Wan 2.7 Pro custom-image generation\n(kind IMAGE / DESIGN_MASTER) therefore produced a genuine paid image\n(providerRequestId, ~28s, real PNG) but left no cost record, and the\nbrand's maxCostMicrosPerTask never applied. Every recorded wan2.7-image\ninvocation in the live DB came from ROLE/STILL (sidecar path); none from\nIMAGE — matching the gap. Video (sidecar) and text (connector) were\nalready wrapped and unaffected.\n\nWrap the online image call in withRecordedModelCall via a new\nconnectorImageCallPlan (modality IMAGE, connector-direct, external), map\nModelCostLimitError to the same COST_LIMIT_BLOCKED channel the text path\nuses, and report usage.images = 1 so the realized cost is ESTIMATED at\nthe catalog price, matching ROLE/STILL. Without an invocation context the\nwrapper passes through unchanged, so bare unit calls are unaffected.\n\nRegression in model-connector.client.test.ts: with a scope the online\nWan call records one IMAGE invocation (RUNNING -\u003e SUCCEEDED, 500000\nmicros, ESTIMATED); a per-task cap below the catalog price blocks before\ndispatch (COST_LIMIT_BLOCKED), the request never leaves the host, and one\nBLOCKED row is written.\n\nEvidence: acceptance-artifacts/adversarial-acceptance-2026-09-13/.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:01:08-07:00"}],"HeadCommit":{"Sha1":"13fe1037486e5d393f986446219e457190ec1863","Message":"fix(cost): record and cap online image generation invocations\n\nAdversarial acceptance found that generateConnectedImage — the online\nimage path for DASHSCOPE_WAN and OpenAI-compatible connections — called\nthe provider directly via postJson without withRecordedModelCall, the\none place that both writes a ModelInvocation and enforces the per-task\nbudget cap before dispatch. A real Wan 2.7 Pro custom-image generation\n(kind IMAGE / DESIGN_MASTER) therefore produced a genuine paid image\n(providerRequestId, ~28s, real PNG) but left no cost record, and the\nbrand's maxCostMicrosPerTask never applied. Every recorded wan2.7-image\ninvocation in the live DB came from ROLE/STILL (sidecar path); none from\nIMAGE — matching the gap. Video (sidecar) and text (connector) were\nalready wrapped and unaffected.\n\nWrap the online image call in withRecordedModelCall via a new\nconnectorImageCallPlan (modality IMAGE, connector-direct, external), map\nModelCostLimitError to the same COST_LIMIT_BLOCKED channel the text path\nuses, and report usage.images = 1 so the realized cost is ESTIMATED at\nthe catalog price, matching ROLE/STILL. Without an invocation context the\nwrapper passes through unchanged, so bare unit calls are unaffected.\n\nRegression in model-connector.client.test.ts: with a scope the online\nWan call records one IMAGE invocation (RUNNING -\u003e SUCCEEDED, 500000\nmicros, ESTIMATED); a per-task cap below the catalog price blocks before\ndispatch (COST_LIMIT_BLOCKED), the request never leaves the host, and one\nBLOCKED row is written.\n\nEvidence: acceptance-artifacts/adversarial-acceptance-2026-09-13/.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T10:01:08-07:00"},"CompareURL":"luoanwu/image-generation/compare/9f02b16c4968771143aee412b6f58291cbbe9dfb...13fe1037486e5d393f986446219e457190ec1863","Len":1}...
|
1789405394
|
Edit
Delete
|
|
29570
|
5
|
5
|
5
|
57
|
0
|
0
|
refs/heads/main
|
0
|
{"Commits":[{"Sha1":"9f02b16c4 {"Commits":[{"Sha1":"9f02b16c4968771143aee412b6f58291cbbe9dfb","Message":"docs(ops): record the 2026-09-14 service restart\n\nRestarted the six application containers in place on the user's request,\nkeeping release-20260913-drainability1, its images and every data volume.\nAll five components came back healthy within 12 seconds with the image\nrevision label still equal to the deployed fingerprint; all eleven release\nprobes pass, sidecar healthz ok with paddle-ocr ready, and the creative\nqueue is byte-identical before and after (one pre-existing isolated\nUNKNOWN operation, blockingUnknown=0) with zero QUEUED/RUNNING RenderJob.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T06:54:00-07:00"}],"HeadCommit":{"Sha1":"9f02b16c4968771143aee412b6f58291cbbe9dfb","Message":"docs(ops): record the 2026-09-14 service restart\n\nRestarted the six application containers in place on the user's request,\nkeeping release-20260913-drainability1, its images and every data volume.\nAll five components came back healthy within 12 seconds with the image\nrevision label still equal to the deployed fingerprint; all eleven release\nprobes pass, sidecar healthz ok with paddle-ocr ready, and the creative\nqueue is byte-identical before and after (one pre-existing isolated\nUNKNOWN operation, blockingUnknown=0) with zero QUEUED/RUNNING RenderJob.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T06:54:00-07:00"},"CompareURL":"luoanwu/image-generation/compare/6d311a68c7d30ec257cc1316a3fb3cb57699ed00...9f02b16c4968771143aee412b6f58291cbbe9dfb","Len":1}...
|
1789394053
|
Edit
Delete
|
|
29569
|
5
|
5
|
5
|
116
|
0
|
0
|
refs/heads/feat/u31-u33-u34-consumer-feedback
|
0
|
{"Commits":[{"Sha1":"a76562a9c {"Commits":[{"Sha1":"a76562a9c4710a6763243f4f1e1b87f12461b429","Message":"chore(reports): rebind gate reports to 66d02e6\n\n本轮 pnpm check(exit 0,30 项)与治理回归 183/183 的报告产物,按仓纪律 §5 落在实现提交之后。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T06:52:39-07:00"},{"Sha1":"66d02e665eba56a132e0c68a0916fdbb54f535e1","Message":"feat(governance,client-fact): land U-31 / U-33 / U-34 consumer feedback\n\n真实上层接入(digital-employee-os 的 os-employment-projection)暴露的三条缺口,\n按回灌纪律「机器门禁 \u003e 手册条目 \u003e 口头经验」落到本仓。\n\nU-33(机器门禁):check:pins 只读 package.json 的版本字符串,\n`\"@juhai/client-fact\": \"1.0.0-rc.2\"` 在它眼里是完美 exact pin,而 pnpm-lock.yaml 可以把同一个\n包解析到临时目录的 tarball(实测:会话 scratchpad 下的 file:/private/tmp/...tgz)。这比明着写\nfile: 依赖更危险——所有既有门禁全绿,只有别人 clone 后 pnpm install 失败才暴露。现把判据下沉到\nlockfile 的解析结果:@juhai/* 的 resolution tarball 必须落在 .npmrc 声明的 scope registry 下;\n非 registry 来源须在 platform-dependency-deviations.json 完整登记(五字段全填且未过期);\n临时目录来源不可登记豁免。\n\n不误伤既有上层仓的三条:无 lockfile 不判定;lockfile 里没有 @juhai 外部条目(纯 workspace 消费)\n不判定、也不要求 .npmrc;只有真的存在外部解析才要求声明 registry。本仓自测 checked=0 通过,\n对 OS 仓实测 4 个解析来源全部合规。\n\nU-34 / U-31(包契约):client-fact 此前没有 README,而 clients/README 却说\"实现与验收见包 README\"。\n新建并加进 files:\n- baseUrl 必须含 /api 前缀——本包用相对 URL 解析端点,少写 /api 不报错而是让所有回查 404,\n 消费者若把 404 当\"事实不存在\"就会判 UNTRUSTED_FACT、三次进死信;一个配置漏字母把整条摄入\n 变成全量死信。同时写明 404 / 不可达 / 未配置三种情况的不同处置。\n- 迁移模板只给表:策略无 TO 子句(对 PUBLIC 生效,system 角色同样被挡)且全文无 GRANT,\n 消费者若用低权限运行角色,照抄后对五张表没有任何权限。契约改为\"表 DDL 逐字照用,\n GRANT 与策略角色绑定由消费者按自身角色模型补齐\"。\n- 附 rc.3 的 STALE 行为变更与\"升级后应删除边界翻译\"。\n\n验证:新增 governance/test/check-pins.test.mjs 10 例(1 正向 + 6 负向判据 + 3 条不误伤);\n治理回归 183/183;根 pnpm check exit 0(30 项)。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T06:52:14-07:00"},{"Sha1":"036a308f27acf35a46f068c96fea7723ef74d05e","Message":"feat(client-fact): U-29 判落后版本为 STALE,不再当毒消息\n\n真实消费者接入(digital-employee-os 的 os-employment-projection)暴露:applyOne 在\nversion \u003c= watermark 时抛 FactRejected(\"UNPROCESSED_VERSION_BEHIND_WATERMARK\"),\n而 handle 把任何 FactRejected 计入 attempts——至少一次投递下的**正常迟到重投**三次即\n被打进死信,与\"内容有毒\"共用一套判据;类型里写着的 \"STALE\" 返回值反而不可达。\n平台自己的主线 e2e 用合成宿主表,从不重放已过水位的事实,因此一直照不出这条。\n\n改为返回 \"STALE\",并顺手删掉该 fact 可能留在 gap 缓冲里的副本:落后事实永远等不到\nprevious_version = 水位,留着只会把缓冲占满到 GAP_BUFFER_FULL,drain 循环也会空转。\n\n证据:runtime/test/e2e/mainline.test.ts 新增断言——清掉 processed 行后重放旧事实,\n连判三次 STALE、platform_client_fact_failure 无行、投影仍停在 11;该文件 6/6 通过\n(真实 M3/M5/M6 库 + Redpanda,MAINLINE_ENV=ms23)。治理负向回归 173/173、\ncheck:pins 34 个 package.json 全 exact pin、根 pnpm check 全链通过。\n\n发布列车三件套同步升到 1.0.0-rc.3,**尚未发布**:rc.2 已在 Registry 且不可覆盖,\n上层在 rc.3 发布前继续 pin rc.2 并在边界做错误码翻译。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T22:10:52-07:00"}],"HeadCommit":{"Sha1":"a76562a9c4710a6763243f4f1e1b87f12461b429","Message":"chore(reports): rebind gate reports to 66d02e6\n\n本轮 pnpm check(exit 0,30 项)与治理回归 183/183 的报告产物,按仓纪律 §5 落在实现提交之后。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-14T06:52:39-07:00"},"CompareURL":"luoanwu/enterprise-platform/compare/d1ef5414093aa67ff4b8e2b7af8d13be86aed7ba...a76562a9c4710a6763243f4f1e1b87f12461b429","Len":3}...
|
1789393970
|
Edit
Delete
|
|
29568
|
5
|
5
|
5
|
116
|
0
|
0
|
refs/heads/feat/u31-u33-u34-consumer-feedback
|
0
|
|
1789393970
|
Edit
Delete
|
|
29480
|
5
|
5
|
5
|
76
|
0
|
0
|
refs/heads/feat/os-04-employment-projection
|
0
|
{"Commits":[{"Sha1":"3c100f855 {"Commits":[{"Sha1":"3c100f855828a6b046679818aafce7f1bbf3bfb8","Message":"feat(deps): pin client-fact 1.0.0-rc.3 and drop the STALE boundary translation\n\n平台已修 U-29(enterprise-platform main 036a308):applyOne 在 version \u003c= watermark 时\n返回 \"STALE\" 并清掉该事实留在 gap 缓冲里的副本,不再抛 FactRejected 被 handle 计入\nattempts——此前至少一次投递下的正常迟到重投三次即被打进死信,与\"内容有毒\"共用一套判据。\n\n该修复随 1.0.0-rc.3 发布(同一本地旁路通道,见基础设施仓 G-12),本仓两后端 pin 到\nrc.3 后删除 ingest 里的「错误码 → 结果词」边界翻译:判定完全回到 SDK,本仓只留事务、\n可信回查与 apply。FactRejected 的 import 保留——回查逻辑仍在用。\n\n验证:typecheck 13/13;两后端 employment 真实 DB 验收各 9/9 在无翻译的情况下通过\n(含\"落后版本 STALE:投影停在较新的版本,不回滚\"这条);check:platform-provenance 仍绿。\n\n边界不变:rc.3 与 rc.2 一样没有任何 CI 阶段门证据,可宣称\"依赖来源合规\",\n不得宣称\"经过发布门禁验证\"。\n\nscripts/ 与 reports/ 的并发改动不在本提交内(另有会话在本仓工作)。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T23:00:25-07:00"},{"Sha1":"6fc1ecc41ab5e4e1283e84efa1a4964111293ec5","Message":"feat(employment): 接通 Kafka 投递通道并按平台 fact-read 契约回查\n\nG25① 投递通道:此前只有受权限保护的 HTTP 投递入口,生产形态(平台 fact 模块按 source_domain\n中继到 broker)无人消费。现两后端各加一个消费者,挂在 dispatcher 进程(C56:API 进程不跑后台交接):\n- PLATFORM_FACT_BROKERS 未配置就**不启动**,不造空转的假消费者;\n- autoCommit:false,ingest 成功才提交位点,抛错不提交交给 broker 重投(SDK 幂等表保证无副作用);\n- 同一 topic 承载该域全部事实类型,形状不匹配即\"不是我们的消息\":跳过并提交,否则别人的消息\n 会永远卡住本消费组的分区头。\n信任判断仍全在 FactInbox:消费者只搬运,落库前一样要过 M5 权威回查。\n\nG25② 回查契约:路径与状态码改为平台候选契约 fact-read-api.v1\n(GET {base}/v1/facts/accepted/{factId},Bearer JWT),错误码 FACT_EXPORT_* → FACT_READ_*;\n**只有 404 是\"不存在\"**,其余状态一律当依赖故障抛错——返回 null 会让 SDK 判 UNTRUSTED 并计毒消息,\n把平台的一次 502 变成消费者的死信。平台实现仍只在基础设施仓分支 codex/ms3-fact-read-http,\n未合入 main;合入后本仓应改用 SDK 的 createFactReader 并删掉本地 fetch。\n\n证据(本地,工作树 dirty):\n- 真实 Redpanda(127.0.0.1:59092)两后端各 3 例:落投影 / 异类型跳过不挡后续 / 重投单次效果;\n- 改名后 HTTP 验收两后端各 9/9 复跑;lint 5/5、typecheck 13/13;\n- 内核边界 142/142 受管面、242/242 文件锁(消费者归 Enterprise Fact Consumer pack);\n- 根 pnpm check 仍止于 docs-truth 的 governance-number-evidence-shape——它要求 passed 的\n runtime-acceptance,而整轮 check:runtime 在本机环境卡在 db-credential-separation\n (已在**未带本改动的 HEAD** 上复现同一失败,属环境问题,非本轮回归)。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T22:24:55-07:00"}],"HeadCommit":{"Sha1":"3c100f855828a6b046679818aafce7f1bbf3bfb8","Message":"feat(deps): pin client-fact 1.0.0-rc.3 and drop the STALE boundary translation\n\n平台已修 U-29(enterprise-platform main 036a308):applyOne 在 version \u003c= watermark 时\n返回 \"STALE\" 并清掉该事实留在 gap 缓冲里的副本,不再抛 FactRejected 被 handle 计入\nattempts——此前至少一次投递下的正常迟到重投三次即被打进死信,与\"内容有毒\"共用一套判据。\n\n该修复随 1.0.0-rc.3 发布(同一本地旁路通道,见基础设施仓 G-12),本仓两后端 pin 到\nrc.3 后删除 ingest 里的「错误码 → 结果词」边界翻译:判定完全回到 SDK,本仓只留事务、\n可信回查与 apply。FactRejected 的 import 保留——回查逻辑仍在用。\n\n验证:typecheck 13/13;两后端 employment 真实 DB 验收各 9/9 在无翻译的情况下通过\n(含\"落后版本 STALE:投影停在较新的版本,不回滚\"这条);check:platform-provenance 仍绿。\n\n边界不变:rc.3 与 rc.2 一样没有任何 CI 阶段门证据,可宣称\"依赖来源合规\",\n不得宣称\"经过发布门禁验证\"。\n\nscripts/ 与 reports/ 的并发改动不在本提交内(另有会话在本仓工作)。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T23:00:25-07:00"},"CompareURL":"luoanwu/digital-employee-os/compare/454681c0f8e6137d1c37b6b843b0694ffc4ef966...3c100f855828a6b046679818aafce7f1bbf3bfb8","Len":2}...
|
1789365667
|
Edit
Delete
|
|
29471
|
5
|
5
|
5
|
57
|
0
|
0
|
refs/heads/feat/content-block-index-20260913
|
0
|
{"Commits":[{"Sha1":"6d311a68c {"Commits":[{"Sha1":"6d311a68c7d30ec257cc1316a3fb3cb57699ed00","Message":"docs(ops): record the second service restart on 2026-09-13\n\nRestarted the six application containers in place on the user's request,\nkeeping release-20260913-drainability1, its images and every data volume.\nAll five components came back healthy within 30 seconds with the image\nrevision label still equal to the deployed fingerprint; workspace, gateway\nhealth with database and redis up, the three retired legacy routes at 404,\nsidecar healthz ok with paddle-ocr ready, and the creative queue at zero\nboth before and after.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T22:44:28-07:00"}],"HeadCommit":{"Sha1":"6d311a68c7d30ec257cc1316a3fb3cb57699ed00","Message":"docs(ops): record the second service restart on 2026-09-13\n\nRestarted the six application containers in place on the user's request,\nkeeping release-20260913-drainability1, its images and every data volume.\nAll five components came back healthy within 30 seconds with the image\nrevision label still equal to the deployed fingerprint; workspace, gateway\nhealth with database and redis up, the three retired legacy routes at 404,\nsidecar healthz ok with paddle-ocr ready, and the creative queue at zero\nboth before and after.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T22:44:28-07:00"},"CompareURL":"luoanwu/image-generation/compare/9b6c67138ce98d75ab96f8879b73cd3090825f1f...6d311a68c7d30ec257cc1316a3fb3cb57699ed00","Len":1}...
|
1789364777
|
Edit
Delete
|
|
29470
|
5
|
5
|
5
|
57
|
0
|
0
|
refs/heads/main
|
0
|
{"Commits":[{"Sha1":"6d311a68c {"Commits":[{"Sha1":"6d311a68c7d30ec257cc1316a3fb3cb57699ed00","Message":"docs(ops): record the second service restart on 2026-09-13\n\nRestarted the six application containers in place on the user's request,\nkeeping release-20260913-drainability1, its images and every data volume.\nAll five components came back healthy within 30 seconds with the image\nrevision label still equal to the deployed fingerprint; workspace, gateway\nhealth with database and redis up, the three retired legacy routes at 404,\nsidecar healthz ok with paddle-ocr ready, and the creative queue at zero\nboth before and after.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T22:44:28-07:00"}],"HeadCommit":{"Sha1":"6d311a68c7d30ec257cc1316a3fb3cb57699ed00","Message":"docs(ops): record the second service restart on 2026-09-13\n\nRestarted the six application containers in place on the user's request,\nkeeping release-20260913-drainability1, its images and every data volume.\nAll five components came back healthy within 30 seconds with the image\nrevision label still equal to the deployed fingerprint; workspace, gateway\nhealth with database and redis up, the three retired legacy routes at 404,\nsidecar healthz ok with paddle-ocr ready, and the creative queue at zero\nboth before and after.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T22:44:28-07:00"},"CompareURL":"luoanwu/image-generation/compare/9b6c67138ce98d75ab96f8879b73cd3090825f1f...6d311a68c7d30ec257cc1316a3fb3cb57699ed00","Len":1}...
|
1789364728
|
Edit
Delete
|
|
29469
|
5
|
5
|
5
|
57
|
0
|
0
|
refs/heads/feat/content-block-index-20260913
|
0
|
{"Commits":[{"Sha1":"9b6c67138 {"Commits":[{"Sha1":"9b6c67138ce98d75ab96f8879b73cd3090825f1f","Message":"docs(releases): record the drainability1 deployment\n\nrelease-20260913-drainability1 is live on 03af8485 (fingerprint\nb9a349f9…), so the service and main now share one fingerprint. Five\ncomponents healthy with restarts=0, 13 backups, no schema change, queue\nhealthy before and after, 11 boundary probes as expected. Verified after\nthe switch that the retired instances/:id/render-jobs route is absent\nfrom the running api image and that the database holds no QUEUED or\nRUNNING RenderJob.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T22:37:48-07:00"}],"HeadCommit":{"Sha1":"9b6c67138ce98d75ab96f8879b73cd3090825f1f","Message":"docs(releases): record the drainability1 deployment\n\nrelease-20260913-drainability1 is live on 03af8485 (fingerprint\nb9a349f9…), so the service and main now share one fingerprint. Five\ncomponents healthy with restarts=0, 13 backups, no schema change, queue\nhealthy before and after, 11 boundary probes as expected. Verified after\nthe switch that the retired instances/:id/render-jobs route is absent\nfrom the running api image and that the database holds no QUEUED or\nRUNNING RenderJob.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T22:37:48-07:00"},"CompareURL":"luoanwu/image-generation/compare/03af8485a034617648b6ab8e8591683d7eab86ce...9b6c67138ce98d75ab96f8879b73cd3090825f1f","Len":1}...
|
1789364340
|
Edit
Delete
|
|
29468
|
5
|
5
|
5
|
57
|
0
|
0
|
refs/heads/main
|
0
|
{"Commits":[{"Sha1":"9b6c67138 {"Commits":[{"Sha1":"9b6c67138ce98d75ab96f8879b73cd3090825f1f","Message":"docs(releases): record the drainability1 deployment\n\nrelease-20260913-drainability1 is live on 03af8485 (fingerprint\nb9a349f9…), so the service and main now share one fingerprint. Five\ncomponents healthy with restarts=0, 13 backups, no schema change, queue\nhealthy before and after, 11 boundary probes as expected. Verified after\nthe switch that the retired instances/:id/render-jobs route is absent\nfrom the running api image and that the database holds no QUEUED or\nRUNNING RenderJob.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T22:37:48-07:00"}],"HeadCommit":{"Sha1":"9b6c67138ce98d75ab96f8879b73cd3090825f1f","Message":"docs(releases): record the drainability1 deployment\n\nrelease-20260913-drainability1 is live on 03af8485 (fingerprint\nb9a349f9…), so the service and main now share one fingerprint. Five\ncomponents healthy with restarts=0, 13 backups, no schema change, queue\nhealthy before and after, 11 boundary probes as expected. Verified after\nthe switch that the retired instances/:id/render-jobs route is absent\nfrom the running api image and that the database holds no QUEUED or\nRUNNING RenderJob.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T22:37:48-07:00"},"CompareURL":"luoanwu/image-generation/compare/03af8485a034617648b6ab8e8591683d7eab86ce...9b6c67138ce98d75ab96f8879b73cd3090825f1f","Len":1}...
|
1789364329
|
Edit
Delete
|
|
29435
|
5
|
5
|
5
|
57
|
0
|
0
|
refs/heads/feat/content-block-index-20260913
|
0
|
{"Commits":[{"Sha1":"03af8485a {"Commits":[{"Sha1":"03af8485a034617648b6ab8e8591683d7eab86ce","Message":"docs(releases): record the block-index1 deployment\n\nrelease-20260913-block-index1 is live on d3fbd406 (fingerprint\nf368d571…): five components healthy with restarts=0, 13 backups, no\nschema change, queue healthy before and after, and all 11 boundary\nprobes as expected. The record keeps the two aborted starts — a\nconcurrent second invocation hitting .release-lock, then the preflight\nrefusing on renderRunning=1 until a 15-hour-old wan3.0-video job settled\nSUCCEEDED through a normal poll-on-read. current.md also states that main\nhas since moved to 68192ddd, which is not deployed.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T22:27:14-07:00"},{"Sha1":"68192ddd237389ed9c7bca797b2ff8a31e77b5f0","Message":"docs(governance): record the verified ui-acceptance purge\n\nThe purge ran on the host while the heavy gates were executing. Verified\nafter the fact: ui-acceptance rows 3258 -\u003e 0, QUEUED RenderJob 39 -\u003e 0,\ndemo-tenant RenderJob unchanged at 387, total RenderJob 471 -\u003e 387 (exactly\nthe 84 rows those tenants held). \"Zero QUEUED RenderJob across the database\"\nis a meaningful invariant again.\n\nOnly the deploy remains; release.sh is blocked by the auto-mode classifier.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:42:38-07:00"},{"Sha1":"9cc15150d067694c6a44837fe08ccbaf47d84767","Message":"test(gates): re-run all eight heavy gates at the new fingerprint\n\nThe earlier claim that heavy gates could not run in this session was wrong.\nWhat auto mode blocks is reading the production stack's credentials -- and the\nexisting runner never needed them: it provisions its own isolated postgres,\nredis and minio containers with self-generated passwords and copies the virus\ndatabase out of hi-atelier-clamav-1 into a private clamd. Reused that recipe\nwith distinct container names and ports.\n\nAll eight gates pass: runtime, public-file, inference, script, shijie,\nproduction, ui, deps. clamd probe is real (PING/PONG, EICAR FOUND, clean OK).\nPer the repo's own lesson that ALL_GATES_PASSED does not by itself prove the\nreports are current, each report's sourceFingerprint was machine-compared\nagainst the working tree: all eight equal b9a349f9 with status=passed.\n\ncheck:ui is the evidence that matters here -- with the demo-button click gone,\nthe OCR and export assertions now run against the instance left by the real\nCreativeOperation path, and the browser run confirms that instance still has no\nrendered asset, so the assertions keep their meaning.\n\nThe 12 baseline rows marked OPEN in the previous commit are restored to GREEN\non this fresh evidence. check:governance exits 0 with heavyGateDocDrift 0.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:26:25-07:00"},{"Sha1":"befdfea0383f867d23cae49c9b3288b18ff39c1d","Message":"docs(governance): ratchet the new gate and mark stale heavy rows OPEN\n\nRegisters renderJobDrainabilityViolations and\nrenderJobDrainabilitySelftestFailures in reports/baseline.json at 0 (the\nstrictest value for a down ratchet; --update-baseline validates before\nwriting so it cannot bootstrap a brand-new metric), and adds the gate to the\nCLAUDE.md baseline table plus a source-map row naming\nexecuteCreativeOperation as the single outward render entry point.\n\nThis round touched apps/ and scripts/, so the source fingerprint moved from\nf368d571 to b9a349f9 and 12 baseline rows bound to the old evidence went\nstale. Auto mode blocked re-running the heavy gates (reading MinIO/ClamAV\ncredentials and provisioning an isolated database are both denied), so those\nrows are marked 🟡 OPEN rather than left claiming ✅ on stale evidence.\nheavyGateDocDrift returns to 0 because the doc no longer outruns the machine\nevidence, not because the evidence is fresh.\n\ncheck:governance now exits 0; check:scripts 94/94 pass. check:ui still needs\na real re-run before this round can be called ready.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:12:50-07:00"},{"Sha1":"75ab917550cf4fc78362fcd8672127bff55fddb5","Message":"fix(material): retire the registration-only render-jobs entry point\n\nPOST /material-factory/instances/:id/render-jobs created a RenderJob at the\nschema default QUEUED and returned. Nothing in the repo drains a factory-path\nQUEUED row: render-worker only claims productionId+revisionId+CLAIMED, no\nBullMQ queue scans them, the outbox dispatcher only publishes to Redis, and\npoll-on-read filters sourceAssetId/maskAssetId NOT NULL which that path never\nsets. Every call therefore minted a permanently stuck row -- 39 of them in the\nlocal production database.\n\nRemoved the route from both backends, the enqueueRenderJob web wrapper, and the\ndemo-gated \"create demo instance\" button that the UI acceptance script clicked\nonce per run. requestRenderJob stays as the internal first step of\nrunRenderPipeline, which transitions QUEUED-\u003eRUNNING synchronously; the real\nuser path (executeCreativeOperation -\u003e creative worker) is unchanged.\n\nAdded check:render-drainability, a static gate with 8 negative injections that\nfails if any route, web wrapper, demo button or acceptance click comes back, or\nif either backend's runRenderPipeline loses its synchronous QUEUED-\u003eRUNNING\ntransition. Registered in governance-report with a violations + selftest\nratchet.\n\nVerified: turbo typecheck 23/23, turbo lint 11/11, naming/validation/\ncontract-consumers/module-boundary/schema gates pass, gate selftest 8/8 red.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:03:03-07:00"}],"HeadCommit":{"Sha1":"03af8485a034617648b6ab8e8591683d7eab86ce","Message":"docs(releases): record the block-index1 deployment\n\nrelease-20260913-block-index1 is live on d3fbd406 (fingerprint\nf368d571…): five components healthy with restarts=0, 13 backups, no\nschema change, queue healthy before and after, and all 11 boundary\nprobes as expected. The record keeps the two aborted starts — a\nconcurrent second invocation hitting .release-lock, then the preflight\nrefusing on renderRunning=1 until a 15-hour-old wan3.0-video job settled\nSUCCEEDED through a normal poll-on-read. current.md also states that main\nhas since moved to 68192ddd, which is not deployed.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T22:27:14-07:00"},"CompareURL":"luoanwu/image-generation/compare/d3fbd4067795e6e683483f03dad85573cd6a7cd1...03af8485a034617648b6ab8e8591683d7eab86ce","Len":6}...
|
1789363669
|
Edit
Delete
|
|
29434
|
5
|
5
|
5
|
57
|
0
|
0
|
refs/heads/main
|
0
|
{"Commits":[{"Sha1":"03af8485a {"Commits":[{"Sha1":"03af8485a034617648b6ab8e8591683d7eab86ce","Message":"docs(releases): record the block-index1 deployment\n\nrelease-20260913-block-index1 is live on d3fbd406 (fingerprint\nf368d571…): five components healthy with restarts=0, 13 backups, no\nschema change, queue healthy before and after, and all 11 boundary\nprobes as expected. The record keeps the two aborted starts — a\nconcurrent second invocation hitting .release-lock, then the preflight\nrefusing on renderRunning=1 until a 15-hour-old wan3.0-video job settled\nSUCCEEDED through a normal poll-on-read. current.md also states that main\nhas since moved to 68192ddd, which is not deployed.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T22:27:14-07:00"}],"HeadCommit":{"Sha1":"03af8485a034617648b6ab8e8591683d7eab86ce","Message":"docs(releases): record the block-index1 deployment\n\nrelease-20260913-block-index1 is live on d3fbd406 (fingerprint\nf368d571…): five components healthy with restarts=0, 13 backups, no\nschema change, queue healthy before and after, and all 11 boundary\nprobes as expected. The record keeps the two aborted starts — a\nconcurrent second invocation hitting .release-lock, then the preflight\nrefusing on renderRunning=1 until a 15-hour-old wan3.0-video job settled\nSUCCEEDED through a normal poll-on-read. current.md also states that main\nhas since moved to 68192ddd, which is not deployed.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T22:27:14-07:00"},"CompareURL":"luoanwu/image-generation/compare/68192ddd237389ed9c7bca797b2ff8a31e77b5f0...03af8485a034617648b6ab8e8591683d7eab86ce","Len":1}...
|
1789363656
|
Edit
Delete
|
|
29433
|
5
|
5
|
5
|
116
|
0
|
0
|
refs/heads/main
|
0
|
{"Commits":[{"Sha1":"d1ef54140 {"Commits":[{"Sha1":"d1ef5414093aa67ff4b8e2b7af8d13be86aed7ba","Message":"feat(governance): G-12 local release bypass, used once for the rc.2 train\n\nGitHub Actions 因账户计费暂停(自 2026-09-13T05:35Z 起每次 run 在 0–3 秒未启动即\nfailure),发布链要求的「main 上成功 Platform CI run + runnerNormalized:\"ci\" 候选证据」\n无法满足。为解开下游 digital-employee-os 的依赖冻结(该仓任何 pnpm install 都因\n@juhai/client-fact 未发布而 404,连 CVE 都修不了),本轮以本地旁路发布了列车三件套\ncontracts / governance / client-fact 1.0.0-rc.2。\n\npublish-rc.mjs 新增显式命名的开关 PLATFORM_RELEASE_BYPASS_CI_EVIDENCE,\n**只解除 CI 身份检查这一条**:不可覆盖已发布版本、Registry integrity 自校验、\n仅 RC 版本、--ignore-scripts 全部保留;无开关时仍拒绝运行(已验证)。\n\n不伪装 CI:provenance.json 由本地生成并如实写 runner:\"local\" /\nreleaseChannel:\"local-bypass\" / reports:[]。prepare-package-release.mjs 的七道\nrequire 与 lib/provenance.mjs 的 runner 归一化(G-11 的 gitea-actions→other)均未改动。\n\n代价已登记在 docs/G-12本地旁路发布记录-2026-09-13.md:这三个包无任何阶段门证据,\n且版本号被本地包永久占用,计费恢复后只能由 CI 发下一个 RC;旁路开关应在那时删除。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T22:02:47-07:00"}],"HeadCommit":{"Sha1":"d1ef5414093aa67ff4b8e2b7af8d13be86aed7ba","Message":"feat(governance): G-12 local release bypass, used once for the rc.2 train\n\nGitHub Actions 因账户计费暂停(自 2026-09-13T05:35Z 起每次 run 在 0–3 秒未启动即\nfailure),发布链要求的「main 上成功 Platform CI run + runnerNormalized:\"ci\" 候选证据」\n无法满足。为解开下游 digital-employee-os 的依赖冻结(该仓任何 pnpm install 都因\n@juhai/client-fact 未发布而 404,连 CVE 都修不了),本轮以本地旁路发布了列车三件套\ncontracts / governance / client-fact 1.0.0-rc.2。\n\npublish-rc.mjs 新增显式命名的开关 PLATFORM_RELEASE_BYPASS_CI_EVIDENCE,\n**只解除 CI 身份检查这一条**:不可覆盖已发布版本、Registry integrity 自校验、\n仅 RC 版本、--ignore-scripts 全部保留;无开关时仍拒绝运行(已验证)。\n\n不伪装 CI:provenance.json 由本地生成并如实写 runner:\"local\" /\nreleaseChannel:\"local-bypass\" / reports:[]。prepare-package-release.mjs 的七道\nrequire 与 lib/provenance.mjs 的 runner 归一化(G-11 的 gitea-actions→other)均未改动。\n\n代价已登记在 docs/G-12本地旁路发布记录-2026-09-13.md:这三个包无任何阶段门证据,\n且版本号被本地包永久占用,计费恢复后只能由 CI 发下一个 RC;旁路开关应在那时删除。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T22:02:47-07:00"},"CompareURL":"luoanwu/enterprise-platform/compare/6d3900abae6fc251b39e4bebcaa74190e25774bb...d1ef5414093aa67ff4b8e2b7af8d13be86aed7ba","Len":1}...
|
1789362252
|
Edit
Delete
|
|
29432
|
5
|
5
|
5
|
76
|
0
|
0
|
refs/heads/feat/os-04-employment-projection
|
0
|
{"Commits":[{"Sha1":"454681c0f {"Commits":[{"Sha1":"454681c0f8e6137d1c37b6b843b0694ffc4ef966","Message":"feat(deps): resolve @juhai/client-fact from the registry, G25③ gate green\n\n@juhai/client-fact@1.0.0-rc.2(连同 contracts / governance 同版本)已发布到 Gitea\nRegistry,pnpm install 后 lock 重新解析到 registry tarball,pnpm-lock.yaml 中\n/private/tmp 残留归零。check:platform-provenance 从 3 处诚实红转为通过,\ngovernance/platform-dependency-deviations.json 的 client-fact 条目解除(历史留痕在\n$history,不删机制)。\n\n依赖冻结同时解开:此前任何 pnpm install 都会因该包 404 失败,连 CVE 都修不了(C252\n即撞上此事),现在恢复正常。\n\n**边界,不得外推**:发布是本地旁路执行的。GitHub Actions 因账户计费暂停,自 09-13\n起每次 run 都在 0–3 秒未启动即失败,因此这三个包没有任何 CI 阶段门证据——包内\nprovenance.json 如实写 runner:\"local\" / releaseChannel:\"local-bypass\" / reports:[],\n不伪装 CI(基础设施仓 G-12)。可以宣称\"依赖来源合规\",不得宣称\"经过发布门禁验证\"。\n\nreports/ 未纳入本提交:另有并发会话正在本仓跑 runtime 编排(04:29 的\nruntime-acceptance 报告由它写入),报告归它管。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:55:39-07:00"}],"HeadCommit":{"Sha1":"454681c0f8e6137d1c37b6b843b0694ffc4ef966","Message":"feat(deps): resolve @juhai/client-fact from the registry, G25③ gate green\n\n@juhai/client-fact@1.0.0-rc.2(连同 contracts / governance 同版本)已发布到 Gitea\nRegistry,pnpm install 后 lock 重新解析到 registry tarball,pnpm-lock.yaml 中\n/private/tmp 残留归零。check:platform-provenance 从 3 处诚实红转为通过,\ngovernance/platform-dependency-deviations.json 的 client-fact 条目解除(历史留痕在\n$history,不删机制)。\n\n依赖冻结同时解开:此前任何 pnpm install 都会因该包 404 失败,连 CVE 都修不了(C252\n即撞上此事),现在恢复正常。\n\n**边界,不得外推**:发布是本地旁路执行的。GitHub Actions 因账户计费暂停,自 09-13\n起每次 run 都在 0–3 秒未启动即失败,因此这三个包没有任何 CI 阶段门证据——包内\nprovenance.json 如实写 runner:\"local\" / releaseChannel:\"local-bypass\" / reports:[],\n不伪装 CI(基础设施仓 G-12)。可以宣称\"依赖来源合规\",不得宣称\"经过发布门禁验证\"。\n\nreports/ 未纳入本提交:另有并发会话正在本仓跑 runtime 编排(04:29 的\nruntime-acceptance 报告由它写入),报告归它管。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:55:39-07:00"},"CompareURL":"luoanwu/digital-employee-os/compare/d2e3e2c8588a95797304a776a4e76bb035960fdb...454681c0f8e6137d1c37b6b843b0694ffc4ef966","Len":1}...
|
1789361939
|
Edit
Delete
|
|
29431
|
5
|
5
|
5
|
57
|
0
|
0
|
refs/heads/main
|
0
|
{"Commits":[{"Sha1":"68192ddd2 {"Commits":[{"Sha1":"68192ddd237389ed9c7bca797b2ff8a31e77b5f0","Message":"docs(governance): record the verified ui-acceptance purge\n\nThe purge ran on the host while the heavy gates were executing. Verified\nafter the fact: ui-acceptance rows 3258 -\u003e 0, QUEUED RenderJob 39 -\u003e 0,\ndemo-tenant RenderJob unchanged at 387, total RenderJob 471 -\u003e 387 (exactly\nthe 84 rows those tenants held). \"Zero QUEUED RenderJob across the database\"\nis a meaningful invariant again.\n\nOnly the deploy remains; release.sh is blocked by the auto-mode classifier.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:42:38-07:00"}],"HeadCommit":{"Sha1":"68192ddd237389ed9c7bca797b2ff8a31e77b5f0","Message":"docs(governance): record the verified ui-acceptance purge\n\nThe purge ran on the host while the heavy gates were executing. Verified\nafter the fact: ui-acceptance rows 3258 -\u003e 0, QUEUED RenderJob 39 -\u003e 0,\ndemo-tenant RenderJob unchanged at 387, total RenderJob 471 -\u003e 387 (exactly\nthe 84 rows those tenants held). \"Zero QUEUED RenderJob across the database\"\nis a meaningful invariant again.\n\nOnly the deploy remains; release.sh is blocked by the auto-mode classifier.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:42:38-07:00"},"CompareURL":"luoanwu/image-generation/compare/9cc15150d067694c6a44837fe08ccbaf47d84767...68192ddd237389ed9c7bca797b2ff8a31e77b5f0","Len":1}...
|
1789361014
|
Edit
Delete
|
|
29430
|
5
|
5
|
5
|
116
|
0
|
0
|
refs/heads/main
|
0
|
{"Commits":[{"Sha1":"6d3900aba {"Commits":[{"Sha1":"6d3900abae6fc251b39e4bebcaa74190e25774bb","Message":"docs(ci): correct the claim that switching channels needs a DEC revision\n\nThe README (and the plan) said changing the release gate to accept Gitea\nevidence \"extends what DEC-031 accepts as CI evidence, needs a CHG\". That\nis wrong. DEC-031's approval record, its accompanying clauses, DEC-010's\ncondition and design §13 all state capabilities -- clean tag, CI green,\nthree-tier evidence on one SHA, required checks, enforcement over admins,\nCODEOWNERS, linear history, runner=ci -- and never name a CI vendor. The\nonly GitHub mention is §23 listing .github/ under SRE ownership.\n\nSo switching the primary channel is an implementation and repository\nconfiguration change plus a platform-owner call on which channel is\nprimary; no DEC revision, no CHG. Evidence, three options, a file-level\nchange list (CI-1..6) and four items that must be verified first (V-2:\nwhether Gitea can enforce protection over admins) are in\n基础设施/docs/CI验证通道口径裁决材料-2026-09-13.md.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:42:24-07:00"}],"HeadCommit":{"Sha1":"6d3900abae6fc251b39e4bebcaa74190e25774bb","Message":"docs(ci): correct the claim that switching channels needs a DEC revision\n\nThe README (and the plan) said changing the release gate to accept Gitea\nevidence \"extends what DEC-031 accepts as CI evidence, needs a CHG\". That\nis wrong. DEC-031's approval record, its accompanying clauses, DEC-010's\ncondition and design §13 all state capabilities -- clean tag, CI green,\nthree-tier evidence on one SHA, required checks, enforcement over admins,\nCODEOWNERS, linear history, runner=ci -- and never name a CI vendor. The\nonly GitHub mention is §23 listing .github/ under SRE ownership.\n\nSo switching the primary channel is an implementation and repository\nconfiguration change plus a platform-owner call on which channel is\nprimary; no DEC revision, no CHG. Evidence, three options, a file-level\nchange list (CI-1..6) and four items that must be verified first (V-2:\nwhether Gitea can enforce protection over admins) are in\n基础设施/docs/CI验证通道口径裁决材料-2026-09-13.md.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:42:24-07:00"},"CompareURL":"luoanwu/enterprise-platform/compare/eb3cf2c38148bfc0dac9ab1e8cdd5733ae8aa13f...6d3900abae6fc251b39e4bebcaa74190e25774bb","Len":1}...
|
1789360955
|
Edit
Delete
|
|
29429
|
5
|
5
|
5
|
116
|
0
|
0
|
refs/heads/main
|
0
|
{"Commits":[{"Sha1":"eb3cf2c38 {"Commits":[{"Sha1":"eb3cf2c38148bfc0dac9ab1e8cdd5733ae8aa13f","Message":"chore(reports): rebind to 64914b9 and refresh the foundation audit snapshot\n\nThe audit snapshot that the MS-4 exit condition cites had not been rerun\nsince 2026-09-05 -- before the decision meeting. It still reported 2 DECs\napproved and 30 pending against today's 32/0, and still raised\nFACT_DECISIONS_PENDING_OR_UNKNOWN, which that meeting resolved. Refreshed\nhere and in 基础/reports/基础目录统一审计.latest.json (the source copy,\noutside version control).\n\nStatus stays BLOCKED. Seven blockers persist, INVENTORY_INVALID is new\n(企业 IdP lacks 开发计划.md). Each is now attributed in plan deviation #32,\nwhich also records that the cited \"19/19\" denominator does not exist in\nthe report at all: it is 25 directories / 21 formal / 4 unregistered\ncandidates, with 20 of 21 formal entries document-complete.\n\nGate reports rebound to 64914b9 on a clean tree; `pnpm check` exits 0.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:26:55-07:00"},{"Sha1":"64914b92b50df251607e0e4c3ece6b91a90d747e","Message":"feat(governance): require migration-DEC exceptions to carry their own exit\n\nG-13. The exception file silences DECISION_HEADER_MISSING -- the gate\nbehind repo discipline 3 (\"authoritative-table migrations must cite an\napproved DEC\"). Nothing checked that an exception says why it exists, when\nit should go, or who recorded it, so a one-line entry could mute a real\nviolation and leave no trace. That is a back door, not an exception.\n\nEXCEPTION_INCOMPLETE now fails an exception missing any of migrations /\nreason / resolveBy / recordedAt, whitespace-only values included. The two\nreal entries (24 identity migrations awaiting PF-07 phase 2) already carry\nall four, so the live report is unchanged: 39 migrations, 0 violations,\n24 exceptions applied.\n\nEXCEPTION_STALE already forced removal once a migration gained a header;\nthe pair now covers both ends -- an exception cannot outlive its condition\nand cannot exist without stating one.\n\nLocal: governance 171 -\u003e 173, root `pnpm check` exit 0.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:25:08-07:00"},{"Sha1":"cb504a5cbfc0795f42410402cc6fdccc17159f7a","Message":"docs(contracts): register the G-12 linter change against the import source\n\nPF-04 phase 1 requires every divergence from platform-contracts/ to be\nrecorded in SOURCE.md, and corrects what the 2026-09-10 sync note said.\nThat note filed all six PLATFORM_PROJECT_UNREGISTERED findings under\n\"waiting for CHG-001\"; two of them were scan false positives that no\nchange request could ever clear. Four real candidate platforms remain.\n\nThe source directory itself stays untouched per phase 1, so the formal\ncheck behind 基础/scripts/audit-foundation.mjs still reports six until\nphase 2 removes the old copy.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:23:44-07:00"},{"Sha1":"7adc31e54817d8d9b9f35a2fac25719aba53cbac","Message":"chore(reports): rebind gate reports to ac3683d; fixtures now passed\n\nRegenerated on a clean tree; `pnpm check` exits 0 with 28/28 turbo tasks.\n\nfixtures moves from partial to passed: 8 suites / 89 cases / 0 failures /\n0 unavailable. The previous copy was produced in a detached worktree with\nno workspace ancestor, so the dec-039-party-model suite (workspaceRelative,\n25 cases) reported unavailable; in the main worktree it runs and passes.\nThe --allow-unavailable-suite flag stays -- a standalone CI clone still\ncannot see it.\n\nrelease-manifest stays partial on the same four deliverables.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:22:40-07:00"},{"Sha1":"ac3683d122be41adf616c6a2223040a2578283f0","Message":"fix(contracts): stop counting 基础/ tooling directories as unregistered platforms\n\nG-12. The platform-directory scan excluded only `scripts`, so `基础/reports`\nand `基础/tests` -- that directory's own tooling and output folders, added\nlater -- were reported as PLATFORM_PROJECT_UNREGISTERED. Two false\npositives sat mixed in with the four genuinely unregistered candidate\nplatforms, and they were invisible in CI because the whole check is\nskipped in a standalone clone (needsWorkspace).\n\nThey also masked a second defect. `E2 evidence files must contain a passed\nreport` pinned itself to enterprise-idp, whose evidence_level dropped to E0\nwhen the IdP source moved into identity/; the evidence check only runs at\nE2, so the injected fault could never be detected and the case failed on\nHEAD for anyone with the workspace checked out. The case now sets\nevidence_level itself instead of depending on catalog state.\n\nThe four real offenders (企业搜索 / 外部连接器 / 开发者自助 / 数据治理与隐私,\nall candidate-not-registered pending CHG) still report, and a new case\nasserts both halves: tooling directories must not report, real ones must.\n\nLocal: contracts check:local 100/101 -\u003e 101/101 (exit 0), governance\n171/171, root `pnpm check` exit 0 with 28/28 turbo tasks.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:22:10-07:00"}],"HeadCommit":{"Sha1":"eb3cf2c38148bfc0dac9ab1e8cdd5733ae8aa13f","Message":"chore(reports): rebind to 64914b9 and refresh the foundation audit snapshot\n\nThe audit snapshot that the MS-4 exit condition cites had not been rerun\nsince 2026-09-05 -- before the decision meeting. It still reported 2 DECs\napproved and 30 pending against today's 32/0, and still raised\nFACT_DECISIONS_PENDING_OR_UNKNOWN, which that meeting resolved. Refreshed\nhere and in 基础/reports/基础目录统一审计.latest.json (the source copy,\noutside version control).\n\nStatus stays BLOCKED. Seven blockers persist, INVENTORY_INVALID is new\n(企业 IdP lacks 开发计划.md). Each is now attributed in plan deviation #32,\nwhich also records that the cited \"19/19\" denominator does not exist in\nthe report at all: it is 25 directories / 21 formal / 4 unregistered\ncandidates, with 20 of 21 formal entries document-complete.\n\nGate reports rebound to 64914b9 on a clean tree; `pnpm check` exits 0.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:26:55-07:00"},"CompareURL":"luoanwu/enterprise-platform/compare/3308542265e6a301126e1135310b11fbcddd5c5d...eb3cf2c38148bfc0dac9ab1e8cdd5733ae8aa13f","Len":8}...
|
1789360315
|
Edit
Delete
|
|
29428
|
5
|
5
|
5
|
76
|
0
|
0
|
refs/heads/feat/os-04-employment-projection
|
0
|
{"Commits":[{"Sha1":"d2e3e2c85 {"Commits":[{"Sha1":"d2e3e2c8588a95797304a776a4e76bb035960fdb","Message":"fix(deps): C252 raise sharp/multer overrides past 4 new high advisories\n\n推送前自检实查 pnpm audit --prod --audit-level high 为 4 high:\n- sharp 0.35.3 → 0.35.4(libheif GHSA-g89c-p67h-r497 / GHSA-2jg2-4ch7-h545)\n- multer 2.2.0 → 2.3.0(三个 DoS:构造字段名、中止上传 fd 泄漏、超大数组索引)\n\n两者都是 C168 为供应链治理精确钉版的 override——这是 C243(Go 模块)、C245(fast-uri)\n之后第四次同形态复发:override 钉版本身就是下一次转红的位置。\n\n修复过程暴露一个更硬的结构性问题(已并入 C252 记录):pnpm install 因\n@juhai/client-fact@1.0.0-rc.2 不在 Registry 直接 404 失败。lock 里的 file: 解析只在\n该条目不被重算时有效,任何依赖变更都会让 pnpm 回到 package.json 的声明去 registry 找。\n**包未发布不只让 CI 装不上,本机也做不了安全修复。**\n\n绕行方式:重建锁时临时把两个 app 的 client-fact specifier 指向本地 tarball,install 后\n改回 exact pin——这正是现状 lock 的产生方式,不新增偏差形态;\ncheck:platform-provenance 仍诚实红 3 处(两个 app 的 package.json 与 HEAD 逐字一致)。\n\n验证:audit 0 high / 3 moderate、typecheck 13/13、NestJS 与 Fastify 的\nhttp+http-limits 各 17/17、contracts 24 文件 312/312、web build 通过、\n@img/sharp-darwin-arm64@0.35.4 已装、employment 主线 9/9 复跑。不建忽略清单。\n\n快照锚点指向父提交(C232/C241)。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:27:19-07:00"}],"HeadCommit":{"Sha1":"d2e3e2c8588a95797304a776a4e76bb035960fdb","Message":"fix(deps): C252 raise sharp/multer overrides past 4 new high advisories\n\n推送前自检实查 pnpm audit --prod --audit-level high 为 4 high:\n- sharp 0.35.3 → 0.35.4(libheif GHSA-g89c-p67h-r497 / GHSA-2jg2-4ch7-h545)\n- multer 2.2.0 → 2.3.0(三个 DoS:构造字段名、中止上传 fd 泄漏、超大数组索引)\n\n两者都是 C168 为供应链治理精确钉版的 override——这是 C243(Go 模块)、C245(fast-uri)\n之后第四次同形态复发:override 钉版本身就是下一次转红的位置。\n\n修复过程暴露一个更硬的结构性问题(已并入 C252 记录):pnpm install 因\n@juhai/client-fact@1.0.0-rc.2 不在 Registry 直接 404 失败。lock 里的 file: 解析只在\n该条目不被重算时有效,任何依赖变更都会让 pnpm 回到 package.json 的声明去 registry 找。\n**包未发布不只让 CI 装不上,本机也做不了安全修复。**\n\n绕行方式:重建锁时临时把两个 app 的 client-fact specifier 指向本地 tarball,install 后\n改回 exact pin——这正是现状 lock 的产生方式,不新增偏差形态;\ncheck:platform-provenance 仍诚实红 3 处(两个 app 的 package.json 与 HEAD 逐字一致)。\n\n验证:audit 0 high / 3 moderate、typecheck 13/13、NestJS 与 Fastify 的\nhttp+http-limits 各 17/17、contracts 24 文件 312/312、web build 通过、\n@img/sharp-darwin-arm64@0.35.4 已装、employment 主线 9/9 复跑。不建忽略清单。\n\n快照锚点指向父提交(C232/C241)。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:27:19-07:00"},"CompareURL":"luoanwu/digital-employee-os/compare/5288ac175ac522dbf9881cc17eb269e95e8062c3...d2e3e2c8588a95797304a776a4e76bb035960fdb","Len":1}...
|
1789360072
|
Edit
Delete
|
|
29427
|
5
|
5
|
5
|
57
|
0
|
0
|
refs/heads/main
|
0
|
{"Commits":[{"Sha1":"9cc15150d {"Commits":[{"Sha1":"9cc15150d067694c6a44837fe08ccbaf47d84767","Message":"test(gates): re-run all eight heavy gates at the new fingerprint\n\nThe earlier claim that heavy gates could not run in this session was wrong.\nWhat auto mode blocks is reading the production stack's credentials -- and the\nexisting runner never needed them: it provisions its own isolated postgres,\nredis and minio containers with self-generated passwords and copies the virus\ndatabase out of hi-atelier-clamav-1 into a private clamd. Reused that recipe\nwith distinct container names and ports.\n\nAll eight gates pass: runtime, public-file, inference, script, shijie,\nproduction, ui, deps. clamd probe is real (PING/PONG, EICAR FOUND, clean OK).\nPer the repo's own lesson that ALL_GATES_PASSED does not by itself prove the\nreports are current, each report's sourceFingerprint was machine-compared\nagainst the working tree: all eight equal b9a349f9 with status=passed.\n\ncheck:ui is the evidence that matters here -- with the demo-button click gone,\nthe OCR and export assertions now run against the instance left by the real\nCreativeOperation path, and the browser run confirms that instance still has no\nrendered asset, so the assertions keep their meaning.\n\nThe 12 baseline rows marked OPEN in the previous commit are restored to GREEN\non this fresh evidence. check:governance exits 0 with heavyGateDocDrift 0.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:26:25-07:00"},{"Sha1":"befdfea0383f867d23cae49c9b3288b18ff39c1d","Message":"docs(governance): ratchet the new gate and mark stale heavy rows OPEN\n\nRegisters renderJobDrainabilityViolations and\nrenderJobDrainabilitySelftestFailures in reports/baseline.json at 0 (the\nstrictest value for a down ratchet; --update-baseline validates before\nwriting so it cannot bootstrap a brand-new metric), and adds the gate to the\nCLAUDE.md baseline table plus a source-map row naming\nexecuteCreativeOperation as the single outward render entry point.\n\nThis round touched apps/ and scripts/, so the source fingerprint moved from\nf368d571 to b9a349f9 and 12 baseline rows bound to the old evidence went\nstale. Auto mode blocked re-running the heavy gates (reading MinIO/ClamAV\ncredentials and provisioning an isolated database are both denied), so those\nrows are marked 🟡 OPEN rather than left claiming ✅ on stale evidence.\nheavyGateDocDrift returns to 0 because the doc no longer outruns the machine\nevidence, not because the evidence is fresh.\n\ncheck:governance now exits 0; check:scripts 94/94 pass. check:ui still needs\na real re-run before this round can be called ready.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:12:50-07:00"},{"Sha1":"75ab917550cf4fc78362fcd8672127bff55fddb5","Message":"fix(material): retire the registration-only render-jobs entry point\n\nPOST /material-factory/instances/:id/render-jobs created a RenderJob at the\nschema default QUEUED and returned. Nothing in the repo drains a factory-path\nQUEUED row: render-worker only claims productionId+revisionId+CLAIMED, no\nBullMQ queue scans them, the outbox dispatcher only publishes to Redis, and\npoll-on-read filters sourceAssetId/maskAssetId NOT NULL which that path never\nsets. Every call therefore minted a permanently stuck row -- 39 of them in the\nlocal production database.\n\nRemoved the route from both backends, the enqueueRenderJob web wrapper, and the\ndemo-gated \"create demo instance\" button that the UI acceptance script clicked\nonce per run. requestRenderJob stays as the internal first step of\nrunRenderPipeline, which transitions QUEUED-\u003eRUNNING synchronously; the real\nuser path (executeCreativeOperation -\u003e creative worker) is unchanged.\n\nAdded check:render-drainability, a static gate with 8 negative injections that\nfails if any route, web wrapper, demo button or acceptance click comes back, or\nif either backend's runRenderPipeline loses its synchronous QUEUED-\u003eRUNNING\ntransition. Registered in governance-report with a violations + selftest\nratchet.\n\nVerified: turbo typecheck 23/23, turbo lint 11/11, naming/validation/\ncontract-consumers/module-boundary/schema gates pass, gate selftest 8/8 red.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:03:03-07:00"},{"Sha1":"9ae843f023c4987a566a4c92e0011fe0caf49c70","Message":"docs(governance): audit the 39 abandoned APPEARANCE_EDIT QUEUED rows\n\nRead-only investigation; no production rows were mutated.\n\nRoot cause: POST /instances/:id/render-jobs (requestRenderJob) is a\nregistration-only endpoint by design and has never had a consumer. The\nrender worker requires productionId+revisionId+CLAIMED, no BullMQ queue\nscans factory QUEUED rows, the outbox dispatcher only publishes to Redis,\nand poll-on-read filters sourceAssetId/maskAssetId NOT NULL -- which these\nrows never have. QUEUED is effectively terminal on that path.\n\nThe rows come from the demo-gated \"create demo instance\" button in\nEditStudio, clicked by check-ui-acceptance.mjs; all 39 tenants match the\nui-acceptance-\u003cts\u003e-\u003crunid\u003e format. Not a dispatcher regression: both the\nbutton and its acceptance click date to the initial commit fc2ce503. They\nstopped on 09-05 because heavy gates moved to an isolated database, not\nbecause of a code fix.\n\nThe real user path (run-real-pipeline -\u003e CreativeOperation -\u003e creative\nworker) drains normally, and prod runs SINGLE_TENANT so the demo button is\nnot rendered for real users.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T20:57:21-07:00"}],"HeadCommit":{"Sha1":"9cc15150d067694c6a44837fe08ccbaf47d84767","Message":"test(gates): re-run all eight heavy gates at the new fingerprint\n\nThe earlier claim that heavy gates could not run in this session was wrong.\nWhat auto mode blocks is reading the production stack's credentials -- and the\nexisting runner never needed them: it provisions its own isolated postgres,\nredis and minio containers with self-generated passwords and copies the virus\ndatabase out of hi-atelier-clamav-1 into a private clamd. Reused that recipe\nwith distinct container names and ports.\n\nAll eight gates pass: runtime, public-file, inference, script, shijie,\nproduction, ui, deps. clamd probe is real (PING/PONG, EICAR FOUND, clean OK).\nPer the repo's own lesson that ALL_GATES_PASSED does not by itself prove the\nreports are current, each report's sourceFingerprint was machine-compared\nagainst the working tree: all eight equal b9a349f9 with status=passed.\n\ncheck:ui is the evidence that matters here -- with the demo-button click gone,\nthe OCR and export assertions now run against the instance left by the real\nCreativeOperation path, and the browser run confirms that instance still has no\nrendered asset, so the assertions keep their meaning.\n\nThe 12 baseline rows marked OPEN in the previous commit are restored to GREEN\non this fresh evidence. check:governance exits 0 with heavyGateDocDrift 0.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:26:25-07:00"},"CompareURL":"luoanwu/image-generation/compare/d3fbd4067795e6e683483f03dad85573cd6a7cd1...9cc15150d067694c6a44837fe08ccbaf47d84767","Len":4}...
|
1789360061
|
Edit
Delete
|
|
29426
|
5
|
5
|
5
|
76
|
0
|
0
|
refs/heads/feat/os-04-employment-projection
|
0
|
{"Commits":[{"Sha1":"5288ac175 {"Commits":[{"Sha1":"5288ac175ac522dbf9881cc17eb269e95e8062c3","Message":"chore(reports): refresh provenance report and anchor\n\n复验时重跑 check:platform-provenance 产生的报告刷新(仍为诚实红 3 处)。\n按 C241:只刷新 reports/ 的提交同样是提交,随带把快照锚点指向父提交 63e695b。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:20:45-07:00"},{"Sha1":"63e695b509c2300e6ec30626a92ad51438a5e309","Message":"docs(governance): correct clean-HEAD step count and name the unrun steps\n\n上一提交把静态门禁结果写成「23 个步骤 exit 0,止于第 24 步」——数错了:日志里第一行\n`\u003e digital-employee-os@0.1.0 check` 是包装命令本身,实际是**前 22 个门禁步骤通过、\n第 23 步 check:docs-truth 失败**(23 份 clean 报告的数字无误,报告数 ≠ 步数)。\n\n更重要的是上一提交只提了 check:platform-provenance 未执行,漏了 fail-fast 同样跳过的\ncheck:governance、lint、typecheck——那会让人以为治理棘轮与类型检查已在 clean HEAD 通过。\n现逐一点名四个未执行步骤。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:20:21-07:00"},{"Sha1":"450faaffcfcad7c776b48fd01cec7ac3e28112fa","Message":"docs(governance): record first clean-HEAD static evidence and OS-04 DB runs\n\n首次在 clean HEAD(46f89b7)执行 `pnpm check`:23 个步骤 exit 0 并写下 23 份\nworktreeDirty:false 的报告——本仓 reports/ 第一次绑定 clean SHA(此前 54 份全部是\n历史 dirty 树产物)。整轮仍未通过,止于第 24 步 check:docs-truth 的\ngovernance-number-evidence-shape:它要求 runtime/governance/baseline 三份数字真源\n都 passed,而 runtime-acceptance.latest.json 仍是 failed。末位的\ncheck:platform-provenance 因 fail-fast 未执行;单独运行按 G25③ 诚实红 3 处。\n\nOS-04 employment 投影在 clean 源码上跑了真实 DB:NestJS 9/9、Fastify 9/9、\ncontracts 24 文件 312/312(共享开发库 digital_employee_os_dev_*)。\n显式登记边界:这是 vitest 单文件运行,没有 latest 报告承载,**不构成阶段门证据**;\nOS-04 退出门仍要求 check:runtime 整轮在 clean HEAD 通过。\n\n快照锚点指向父提交(C232/C241)。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:19:56-07:00"},{"Sha1":"46f89b728979d21972828899f1a1eb51472b7f34","Message":"docs(governance): register G25③ dependency-provenance gate and refresh anchor\n\nCLAUDE.md(AGENTS.md 为其符号链接,自动跟随):\n- G25③ 从「包未发布」改写为机器化表述:说明 pin 形态合规 ≠ 解析来源合规这一形态,\n 以及 check:platform-provenance 的四条判据与「临时目录来源不可登记豁免」\n- GOVERNANCE-BASELINE 新增 platform-dependency-provenance 行,诚实标 🟡 OPEN(红 3 处)\n- 验证命令段补 check:platform-provenance 与其 self-test\n- 快照基准提交锚点指向父提交 0a99a6a(C232/C241)\n\nreports/:本批 reports 为 dirty 工作区产物,按事实作用域纪律只绑定各自\nprovenance,不作阶段门证据;clean HEAD 三级门禁重跑仍是 OS-04 退出门的前置。\n被此前工作删除的 8 份报告已恢复到 HEAD 版本——它们本身也是 dirty 且锚在 9159f925,\n恢复只是让工作树不带删除态,不等于取回合格证据。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:17:01-07:00"},{"Sha1":"0a99a6a1702cbe04afe319e239601a14e9f83a8e","Message":"feat(governance): gate @juhai/* dependency provenance at the lockfile\n\n`juhai-governance check:pins` 只读 package.json 的版本字符串:\n`\"@juhai/client-fact\": \"1.0.0-rc.2\"` 在它眼里是完美 exact pin,而 pnpm-lock.yaml\n实际把它解析到 file:/private/tmp/claude-501/\u003c会话目录\u003e/scratchpad/pkg/*.tgz。\npin 形态合规、解析来源不合规,是比明着写 file: 依赖更危险的形态——它在所有既有门禁里\n都是绿的,只有别人 clone 后 pnpm install 失败时才暴露。\n\n新门禁把判据从「声明」下沉到「解析结果」:\n- importers 的 @juhai/* specifier 必须是 exact x.y.z[-pre] 或 workspace:*\n- packages 的 resolution tarball 必须落在 .npmrc 声明的 @juhai:registry 下\n (registry 地址单源读 .npmrc,不在脚本里硬编码;未声明即红,不静默放行)\n- 非 registry 来源须在 governance/platform-dependency-deviations.json 完整登记\n (reason/registeredAt/expiresAt/blockedBy/replacementPlan 五字段全填且未过期;\n 半份登记不算登记——它看起来像已受控)\n- 临时目录来源不可登记豁免:登记一个不可复现的构建没有意义\n\n--self-test 以合成 lock 跑 7 条判据(1 正 6 负)自证,避免「只会红的假门禁」。\n当前实跑诚实红 3 处,转绿的唯一路径是基础设施仓执行 CL-5 发布列车。\n\ncheck-all.mjs 是 fail-fast,本门禁因此排在末尾:诚实报红不应连带抹掉其余门禁的证据。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:16:43-07:00"}],"HeadCommit":{"Sha1":"5288ac175ac522dbf9881cc17eb269e95e8062c3","Message":"chore(reports): refresh provenance report and anchor\n\n复验时重跑 check:platform-provenance 产生的报告刷新(仍为诚实红 3 处)。\n按 C241:只刷新 reports/ 的提交同样是提交,随带把快照锚点指向父提交 63e695b。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T21:20:45-07:00"},"CompareURL":"luoanwu/digital-employee-os/compare/18a1b036f3dbb3f51ac773862e0cafac278bb34e...5288ac175ac522dbf9881cc17eb269e95e8062c3","Len":6}...
|
1789359716
|
Edit
Delete
|
|
29425
|
5
|
5
|
5
|
76
|
0
|
0
|
refs/heads/feat/os-04-employment-projection
|
0
|
|
1789359716
|
Edit
Delete
|
|
29424
|
5
|
5
|
5
|
116
|
0
|
0
|
refs/heads/feat/ms4-clients-image-publish
|
0
|
{"Commits":[{"Sha1":"6696c8475 {"Commits":[{"Sha1":"6696c84752f17514ebec69e1788bcb93ee445db6","Message":"fix(governance): 端口一致性覆盖地板登记 client-audit 套件(34 例),测试夹具总数改由 PORT_SUITES 推导\n\ncheck:port-conformance 对 suite 数量与总数逐一核对,新增 S-6 套件必须同步登记,否则 suite coverage/count mismatch。\n\nCo-Authored-By: Claude Fable 5.1 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T20:58:20-07:00"},{"Sha1":"edcb7a6da44583a9420636855c513feceb0d9dbe","Message":"feat(clients,governance): client-audit / client-ai 与镜像发布通道(MS-4 Manifest 缺项收口)\n\n- @juhai/client-audit@1.0.0-rc.0(CL-6):内核 AuditSinkPort → audit-append.v1 候选契约(POST /v1/audit/events 批量);\n 同步投递审计失败即写链失败;缓冲投递 = 宿主持久缓冲 + 稳定 event_id / digest 至少一次(C10.02);敏感 details 本地即拒;\n 单测 14 例;S-6 夹具对 stub server 四画像(sink / rejecting / 503 / down)同步 + 缓冲 34 例(runtime/test/port/client-audit.test.ts)\n- @juhai/client-ai@1.0.0-rc.0(CL-7):ai-route.v1 候选契约 SDK(POST /v1/ai/route 路由 → 网关端点 + secret:// 凭据引用;\n POST /v1/ai/usage usage_id 幂等记账,有界重试);未配置 / 传输失败一律拒绝,无静默回退;单测 14 例含 stub server 五画像\n- governance/publish-image.mjs(pnpm image:publish):clean head 构建的镜像推 registry,registry manifest digest 取自 push 输出并与\n RepoDigests 互证后写回 reports/image-digest.json(published / registryRef / registryDigest);不一致 / 取不到 / 源码不匹配即失败不改报告\n- governance/prepare-image-release.mjs:镜像发布门(runtime-v\u003csemver\u003e clean tag + 同源成功 CI + 候选 eligible + Required Check)\n- .github/workflows/publish-image.yml:手动通道 build → push → syft SBOM → cosign sign+verify → release:manifest → artifact(不改 main)\n- 治理测试 +17(publish-image.test.mjs);runbook §8 / staging 说明 §5 / owner-matrix / governance README / clients README 同步\n\nRelease Manifest:client-* 缺项 4 → 2(scope / credential 分别在 PR #32 / #42);registryDigest / signature 待 Secret 配置后 dispatch。\n\nCo-Authored-By: Claude Fable 5.1 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T20:54:23-07:00"}],"HeadCommit":{"Sha1":"6696c84752f17514ebec69e1788bcb93ee445db6","Message":"fix(governance): 端口一致性覆盖地板登记 client-audit 套件(34 例),测试夹具总数改由 PORT_SUITES 推导\n\ncheck:port-conformance 对 suite 数量与总数逐一核对,新增 S-6 套件必须同步登记,否则 suite coverage/count mismatch。\n\nCo-Authored-By: Claude Fable 5.1 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T20:58:20-07:00"},"CompareURL":"luoanwu/enterprise-platform/compare/3308542265e6a301126e1135310b11fbcddd5c5d...6696c84752f17514ebec69e1788bcb93ee445db6","Len":2}...
|
1789358504
|
Edit
Delete
|
|
29423
|
5
|
5
|
5
|
116
|
0
|
0
|
refs/heads/feat/ms4-clients-image-publish
|
0
|
|
1789358504
|
Edit
Delete
|
|
29422
|
5
|
5
|
5
|
57
|
0
|
0
|
refs/heads/feat/content-block-index-20260913
|
0
|
{"Commits":[],"HeadCommit":{"S {"Commits":[],"HeadCommit":{"Sha1":"d3fbd4067795e6e683483f03dad85573cd6a7cd1","Message":"feat(content): number every editable content block\n\nThe 核对 step already refers to paragraphs as \"第 N 块\" and offers a 定位\nbutton per issue, but the editor itself never showed a number, so the\nreader had to count. Each editable block now carries its position as a\nbadge left of the type selector (aria-label \"第 N 块\"); preview mode\nrenders no toolbar, so the numbers stay out of the finished draft. The\nbrowser acceptance asserts the badge reads \"1\" while editing and is\nabsent in preview.\n\nVerified on source fingerprint\nsha256:f368d571fff347125bde8e62213bc4476098bccc0c80a0a886c75f92f3f10c45\nin an isolated stack: runtime, public-file, inference, script,\nproduction, ui, deps and shijie all passed, then the full `pnpm check`\nchain. The CLAUDE.md baseline rows now point at this fingerprint.\nEvidence: reports/content-block-index-2026-09-13/ and\nacceptance-artifacts/content-block-index-2026-09-13/.\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-13T20:33:39-07:00"},"CompareURL":"luoanwu/image-generation/compare/main...d3fbd4067795e6e683483f03dad85573cd6a7cd1","Len":0}...
|
1789357192
|
Edit
Delete
|
|
29421
|
5
|
5
|
5
|
57
|
0
|
0
|
refs/heads/feat/content-block-index-20260913
|
0
|
|
1789357192
|
Edit
Delete
|