| content |
{"Commits":[{"Sha1":"1ccb3b69c {"Commits":[{"Sha1":"1ccb3b69c365de2f80a4032ee4035a6999253197","Message":"chore(reports): OPS-1 应用后门禁回绑 @ 6378b6f\n\nruntime 16 项静态门禁(含新增 check:platform-ops-definitions)、module-imports 0、fixtures 189/189、facts 16、catalog / drift、migration-decs、caddy、工作台两份快照(controlled_operations=recorded,5 条定义 1 条已实现);check:evidence partial(fresh 26 / stale 9,余 9 份均为需真实库或容器重跑的 warn 级)。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-17T15:59:06-07:00"},{"Sha1":"6378b6fbbdc70f947a007c7a644eea2929ed8484","Message":"feat(runtime,contracts): OPS-1 平台运维命令 API 首条命令 permission.invalidation(CHG-005 / X09;CHG-018 条件 A 受控执行面)\n\n目录负责人 2026-09-17 批准 CHG-005 并点选「登记 + 契约 + 实现第一条命令」。\n- 候选 Schema:contracts/candidates/schemas/platform-ops/{operation-definitions,operation-request,operation-receipt}.v1.schema.json(补齐 OpenAPI 原引用的三份缺文件)。\n- 定义快照:runtime/scripts/sync-platform-ops-definitions.mjs → packages/contracts/src/platform-ops-definitions.ts(5 条),check:platform-ops-definitions 进 runtime check 链(负向已验证:改一条 risk 即 exit 1)。\n- 线上形状:packages/contracts/src/platform-ops.ts(请求 / 回执 Zod、ReasonCode、opr_ 编码、规范化 JSON),单测 4/4。\n- 模块接口:module-kit PlatformOpsRuntime(plan / execute / receipt)+ PlatformModule.opsRuntime 钩子;M3 实现以 operationId 为账本幂等键(invalidation_ledger.fact_id),审计经既有 outbox 中继(details 带 operation_id / definition_id / reason_code)。\n- 装配点:/api/platform/ops/{definitions,{definitionId},receipts/{operationId}},三重守卫(platform:ops scope ∧ 管理客户端 ∧ 管理员白名单,未配置即失败关闭)、Idempotency-Key、dry-run、plan_digest、executable 判定;auth 增 token scope/scp → AuthContext.scopes。\n- 工作台运维快照:controlled_operations 由固定 unavailable 改为登记五条定义与本仓实现状态,不声称任何环境可执行。\n验收:contracts 4/4、装配点纯函数 6/6、permission 隔离库集成 2/2(platform_permission_test,非超级用户角色)、真实 HTTP 4/4(内核库 + Redis :56379/7 + AUTH_MODE=jwt,覆盖 401/403/URL 凭证/executable/planned/缺键 400/409 不可执行/succeeded→replayed→409 冲突/回执一致/跨租户 404)、governance 265/265、runtime 静态门禁全过。记录见 docs/平台运维命令OPS-1实现记录-2026-09-17.md。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-17T15:58:44-07:00"}],"HeadCommit":{"Sha1":"1ccb3b69c365de2f80a4032ee4035a6999253197","Message":"chore(reports): OPS-1 应用后门禁回绑 @ 6378b6f\n\nruntime 16 项静态门禁(含新增 check:platform-ops-definitions)、module-imports 0、fixtures 189/189、facts 16、catalog / drift、migration-decs、caddy、工作台两份快照(controlled_operations=recorded,5 条定义 1 条已实现);check:evidence partial(fresh 26 / stale 9,余 9 份均为需真实库或容器重跑的 warn 级)。\n\nCo-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"hillao@juhailaoluodeMacBook-Pro.local","AuthorName":"juhailaoluo pro","CommitterEmail":"hillao@juhailaoluodeMacBook-Pro.local","CommitterName":"juhailaoluo pro","Timestamp":"2026-09-17T15:59:06-07:00"},"CompareURL":"luoanwu/enterprise-platform/compare/908cf2d862dd87d195567ab8b87bee0f487755af...1ccb3b69c365de2f80a4032ee4035a6999253197","Len":2}... |