summaryrefslogtreecommitdiff
path: root/docs/completion-state.md
diff options
context:
space:
mode:
authorSomhairle H. Marisol <[email protected]>2026-09-18 08:27:41 +0800
committerSomhairle H. Marisol <[email protected]>2026-09-18 08:27:41 +0800
commit088735b948d46896b8af30efcb0a2dc5d362b97f (patch)
tree0dcab0d5ebc65309267a42d7cda827e9fdd866e7 /docs/completion-state.md
parentbf6681eb29ac8b0c80ca17b2b5869f7de3da1198 (diff)
downloadstrategy-lab-088735b948d46896b8af30efcb0a2dc5d362b97f.tar.gz
docs(release): 全周期交接文档入库(含 ui-shadcn 迁移交付说明)
[变更性质] 纯文档提交,无运行时逻辑。 [文档内容] 补齐此前各轮未入库的交接/验收文档:backend-auth/backend-domain/ domain-authorization-user(认证与授权域)、etf-recovery-release- handoff(ETF 修复 + ops 演练定稿与生产部署命令)、recovery-* 系列、 frontend/parent-ui-findings(UI 迁移上下文)、worker/integration 等, 以及本轮 docs/ui-shadcn-handoff.md(shadcn-svelte 迁移交接,含 Chart.svelte 契约、runes $state 踩坑记录与 375/768/1440 验证证据)。 [更新方案] 按主题分文;每份文档只记录可复现的命令、验证结果与语义边界, 不导出密钥或生产敏感路径。 [影响范围] 文档渠道:后续 leader/client 审阅入口;与代码提交一一对应便于回溯。
Diffstat (limited to 'docs/completion-state.md')
-rw-r--r--docs/completion-state.md79
1 files changed, 79 insertions, 0 deletions
diff --git a/docs/completion-state.md b/docs/completion-state.md
new file mode 100644
index 0000000..f070cb0
--- /dev/null
+++ b/docs/completion-state.md
@@ -0,0 +1,79 @@
+# Completion checkpoint
+
+## Latest tick: authorized public deployment and independent acceptance
+- Read explicit user authorization first; it supersedes all historical .bin/.bid blockers below. Deployed exactly https://fin.somhairle.bid to existing production127.0.0.1:8789. No application changes or OpenCode workers were needed.
+- Before exposure, SHA256 matched release executable and every frontend asset to current build outputs. Changed only production ORIGIN to exact HTTPS hostname, restarted only production, verified real admin auth, Secure/HttpOnly/SameSite cookie, authenticated /me and foreign-origin403.
+- Appended only exact new ingress before existing404. Cloudflare DNS command readback confirms hostname already routes to tunnel4e9190fb-4020-4a29-b106-9bd54e9e3cf5; ingress validate passes and ingress rule resolves exact loopback8789. Tunnel restarted to PID2963110; actual cmdline retains --protocol http2. Unit and /etc/hosts byte checks passed; no Clash rule changes.
+- Deployment harness reached post-restart route-equality assertion and failed; immediate statuses were not saved by that first version, so no invented baseline is asserted. Subsequent independent HTTP and browser checks establish actual current dav401 (auth challenge), git200, linkwarden200 and fin health200. Harness now saves evidence before assertions for future runs; no second deployment/restart performed.
+- Public Playwright form login passes, real /auth/me200, secure cookie verified, hostile Origin rejected403; first-party JS/CSS byte hashes match deployed release. Cloudflare-injected external analytics script is documented separately. Desktop1440/mobile375 DOM widths exact, zero pageerrors; mobile screenshot visually reviewed. Minor known empty-state wording says top-right while mobile button sits above-left; no functional blocker. Evidence public-verification.json, public-projects-{1440,375}.png, qa_public.py.
+- Fresh full suites after exposure: backend54/54, worker38/38, frontend39/39, Svelte0errors/0warnings, all commands exit0. Logs public-final-suite/. Reparsed unchanged-artifact historical live gates: limits10/10, restart9/9, populated backup/restore11/11, browser workflow7, strategy5, comparison/AI5, sidebar5 with no browser errors. Aggregate release-acceptance.json includes exact DNS/ingress and release hashes. Real workflow stays in isolated QA; production contains no QA projects.
+- Completion notice written to docs/completion-notice.md with verified delivery details and private account retrieval, without plaintext secrets. `hermes cron pause 3924ffef3d90` succeeded; exact list readback confirms supervisor paused and notifier8b222271517c remains active. Final public health200/statusok verified after pause. Notifier was not manually invoked and delivery has not been claimed.
+
+## Previous tick: final browser/restart verified; historical domain blocker (resolved)
+- Independently executed qa_browser_workflow.py, qa_browser_strategy.py, qa_browser_compare_ai.py, qa_sidebar.py and qa_restart.py sequentially against real QA: all five commands exit0. Browser reports respectively7/5/5/5 checkpoints and zero pageerrors; restart9/9 gates, measured exact restart0.0325374s. Evidence: artifacts/qa/supervisor-live/final-suite/final-browser-restart.json and per-script logs; underlying JSON/screenshots refreshed. Aggregate reader initially assumed restart JSON was an object; corrected to actual list and verified all nine passed.
+- Final screenshot vision review: desktop AI editor/diff/accept visible without overlap; mobile drawdown is populated and legible. Viewport screenshot clips scrollable content above/below intentionally; DOM checks establish no horizontal overflow. Narrow table wrapping remains documented.
+- QA8787 and isolated production8789 actual health status ok/worker_available true/ai_configured true after final restart. No OpenCode writer found or launched, no application/production/tunnel changes. Prior tick full suites/builds, artifact hash equality, production persistence/backup/restore evidence remain applicable to unchanged code.
+- Safe local work finished. Public exposure blocked by literal user domain fin.somhairle.bin versus unapproved candidate fin.somhairle.bid; original-session evidence in domain-authorization.md. Honest domain-decision notice written to docs/completion-notice.md; `hermes cron pause 3924ffef3d90` succeeded and independent `hermes cron list --all` readback shows exact supervisor paused. Notifier remains active; delivery not yet claimed. Verified notifier8b222271517c active, local supervisor delivery, notifier script reads this notice and deduplicates via SHA256; no manual send or notifier execution.
+
+## Previous tick: final suites and copied production freshness
+- Independently ran complete backend54/54, worker38/38 and frontend39/39 tests; Svelte0errors/0warnings, frontend and release builds exit0. Backend still reports eight test/seven release warnings; frontend large-chunk warning remains. Actual live API --market exit0 with30/30 PASS lines and final sandbox limits exit0 with10/10 PASS lines, programmatically counted. Evidence/logs: artifacts/qa/supervisor-live/final-suite/.
+- Independently SHA256-compared exact copied production release executable and every frontend file against the freshly built source artifacts: both match. Actual loopback8789 health ok, worker_available true, ai_configured true. No copied-asset update needed. No OpenCode writers found, none launched; no application/service/tunnel/production edits.
+- Next bounded work: final authenticated browser workflow/strategy/comparison-AI/sidebar smoke and measured restart recovery on unchanged artifacts, preserve aggregate acceptance evidence; then write genuine domain-decision blocker notice and pause exact supervisor under brief protocol. Domain substitution remains unauthorized; no notice written this tick. Safe local checks continue; no completion claim.
+
+## Earlier checkpoint: independently exercised live QA
+- Read completion brief, SPEC, RELEASE_SCOPE, integration handoff and parent UI findings.
+- Process inspection found no OpenCode writer. OpenCode is not on PATH; explicit binary `/home/somhairle/.local/share/strategy-lab-tools/node_modules/.bin/opencode` reports 1.18.31. No new worker launched because no application code defect established this tick.
+- `cargo build --manifest-path server/Cargo.toml` exited 0, seven existing dead-code warnings. Restarted only `strategy-lab-qa`; systemd reports active. Live service now uses current debug binary.
+- Fixed parent-owned QA harness container lookup: query exact run container_id from QA SQLite read-only; API deliberately hides this field.
+- Live limits first pass: failure retained with real error; strategy imports execute; network/host-secret checks pass; Docker actual restrictions memory 2147483648 bytes, 2 CPUs, PID limit128, network none, read-only root, uid65534. Running cancel retained as cancelled.
+- Timeout reached failed with `worker container timed out after 60s and was killed`. Harness incorrectly searched only `timeout`; corrected to also accept `timed out`. Read-only DB evidence shows started/finished timestamps and reason. Full rerun subsequently hit real HTTP429 run quota after its first passed check, so DO NOT claim the entire final limits suite passed. Next tick use a fresh isolated QA account or authorized QA admin quota adjustment, never production accounts or disabling acceptance checks.
+- `qa_ai.py` exited 0: all seven actual checks passed (real provider code, Python syntax, unchanged draft before accept, accepted code persisted, immutable version, stale duplicate refusal, real usage).
+
+## Evidence
+- `artifacts/qa/supervisor-live/run-lifecycle.json`: independently read five recent run terminal states and timestamps, no credentials.
+- `artifacts/qa/supervisor-live/sandbox-inspect.json`: actual Docker inspect restriction subset.
+- `/home/somhairle/.hermes/cache/strategy-lab-qa/ai-checks.json`: seven passing real AI gates.
+- `/home/somhairle/.hermes/cache/strategy-lab-qa/limits-checks.json`: latest rerun honestly records quota interruption, not all-green.
+
+## Remaining acceptance
+- Limits acceptance completed this tick: final `python /home/somhairle/.hermes/cache/strategy-lab-qa/qa_limits.py` exit0, 10/10 gates. Actual failing strategy, namespace/import execution, no network, memory2GiB/CPU2/PID128/read-only/nonroot, dropped capabilities/no-new-privileges, exact selected dataset mounts, image-default-only environment, retained cancellation/timeout and both containers removed. Harness false assumptions corrected after inspecting actual Docker/source/DB: job directory UUID differs from run UUID; API sanitizes manifest paths so exact mount verification uses read-only SQLite; base Python image has public GPG_KEY, so compare exact image environment rather than rejecting any KEY name. Evidence and runnable harness copied to artifacts/qa/supervisor-live/{limits-checks.json,sandbox-inspect.json,qa_limits.py}. Raised only isolated browser QA account daily_run_limit to100 via authenticated admin API, GET readback verified. No application code edits, no OpenCode writers found, no production/service/tunnel changes this tick.
+- Fresh complete unit/build/API checks completed in this tick: backend49/49, worker37/37, frontend22/22, Svelte0errors/0warnings; release and frontend builds exit0. Backend retains seven release warnings (eight test warnings), frontend large-chunk warning. Actual live API --market suite exit0, including real market fetch, cross-user immutable cache reuse, backtest equity/fills and original reproduction. Evidence: artifacts/qa/supervisor-live/fresh-suite-checks.json.
+- Fresh authenticated browser route smoke completed: projects/datasets/runs/usage/account/admin without pageerror, new-project modal opened. JSON and desktop screenshots refreshed under /home/somhairle/.hermes/cache/strategy-lab-qa/. This is route smoke only; full authenticated desktop/mobile workflow and vision review still pending, as is restart recovery. No application code edits, OpenCode writers, service changes, or public exposure this tick.
+- This tick independently ran `qa_restart.py` against actual running Docker strategy and restarted only strategy-lab-qa: final exit0, 8/8 checks. In-flight run retained as failed with exact restart reason/finished_at; exact container removed; draft, pre-existing project, ready dataset and cookie session persisted; new real backtest completed after restart. Runnable harness and results: artifacts/qa/supervisor-live/{qa_restart.py,restart-checks.json}. No OpenCode writer found and no application edits.
+- Newly observed operational issue: restart during active Docker execution blocks until systemd's 90-second TimeoutStopSec; journal shows docker child in final-sigterm then SIGKILL. First harness attempt's 30-second command timeout was inadequate; extended to150 seconds and reran all checks successfully. Recovery correctness is verified, graceful shutdown latency remains unresolved. Next tick inspect runner Docker signal handling and exact QA unit; use existing OpenCode integration session if application fix needed, or narrowly scoped production unit shutdown policy. Never global kill. QA currently active/running; MemoryCurrent8593408 bytes is a single sample, not finished idle resource measurement. No service config, production or tunnel changes.
+- Current tick investigated slow restart: exact QA unit is transient, has no shutdown overrides; server has no shutdown signal handler (jobs::Signals is an empty marker). Docker execution is in server/src/worker.rs. Confirmed no existing OpenCode writers before launch. Explicit OpenCode binary version1.18.31; auth list has0 stored credentials, existing wrapper injects configured provider key privately.
+- Resumed ONLY existing integration GLM session ses_f553821d1ffeRPSHHoGHXZx6xq for bounded shutdown-latency root-cause repair, backend tests and debug/release builds. Wrapper PID2831501, actual OpenCode child PID2831515, terminal handle proc_2312abaa0fb5; log /home/somhairle/.hermes/cache/strategy-lab-integration-shutdown.log. Child verified alive after launch. Do not launch a competing writer. Worker explicitly forbidden from service/config/tunnel operations. No fix or test outcome claimed yet. Next tick inspect PID/log/handoff, independently rebuild/restart exact QA and rerun artifacts/qa/supervisor-live/qa_restart.py with measured elapsed time; then full affected gates. No supervisor code/service/public changes this tick.
+- Current tick independently reviewed completed shutdown worker output and caught a CRITICAL introduced defect before QA deployment: main.rs timeout(10s) surrounds the entire serving future, so it starts at startup rather than after a shutdown signal. Actual release binary with isolated temporary empty DB/data, ephemeral loopback port and credential-free environment exited0 after10.025s without any signal. Evidence: artifacts/qa/supervisor-live/shutdown-premature-exit.json. Worker 51 passing unit tests did not cover server lifetime; no success accepted.
+- Resumed same integration session ONLY for narrow fix plus executable startup-survival/TERM regression, full cargo tests, debug/release rebuild and unique-PID stub cleanup. Wrapper PID2834878; OpenCode child PID2834892 verified alive; terminal proc_418eeb69ba13; log /home/somhairle/.hermes/cache/strategy-lab-integration-shutdown-repair.log. Do NOT launch another writer. Next tick inspect completion, independently probe survival beyond10s and bounded TERM BEFORE replacing QA binary; then measured live qa_restart.py and affected API/limits gates. QA remains original PID2829168, active, /api/health HTTP200. No service, production or tunnel change this tick.
+- Current tick found no surviving OpenCode writer and independently rebuilt debug/release, ran complete backend suite:52/52 passed (seven build/eight test warnings remain). Reviewed repaired signal gate; isolated credential-free RELEASE probe survived14.187s with seven HTTP200 health samples, then TERM exit0 in0.0074s. Evidence artifacts/qa/supervisor-live/shutdown-repaired-probe.json. Replaced live QA via restart only after probe. Immediate startup curl raced listener, subsequent actual health200 verified.
+- Measured live active-Docker restart on repaired DEBUG binary: systemctl restart0.0320s, qa_restart.py exit0 with9/9 checks including under20s gate, retained interrupted failure, exact container cleanup, durable draft/dataset/session and successful post-restart real backtest. Updated runnable harness/result in artifacts/qa/supervisor-live. Fresh authenticated API --market suite exit0 with30/30 checks, including actual market data/cache/reproduction. No worker claim used as evidence.
+- Fresh limits rerun on repaired service passed first8 gates (failure, network/secrets, actual limits, caps, mounts/env, cancellation and removal), then HTTP429 prevented submitting timeout run. Prior full10/10 remains historical only; rerun final timeout with a fresh isolated QA account or authorized quota adjustment next tick, without disabling gates. Latest results /home/somhairle/.hermes/cache/strategy-lab-qa/limits-checks.json. No new worker launched, no application edits by supervisor; only harness latency assertion added. No production/tunnel changes. Next work: complete final limits run, authenticated desktop/mobile full workflow plus vision, production and domain authorization.
+- Current tick completed final live limits rerun on repaired shutdown QA binary: exact command `.venv/bin/python /home/somhairle/.hermes/cache/strategy-lab-qa/qa_limits.py` exited0; independently parsed10/10 passing gates. Covers real failed strategy, network/secret isolation, actual Docker resource/capability/mount/environment constraints, cancellation and60-second timeout plus exact container removal. Raised only isolated browser QA account daily_run_limit to500 using authenticated admin PATCH and verified via GET; production untouched. Refreshed artifacts/qa/supervisor-live/{limits-checks.json,sandbox-inspect.json,qa_limits.py,limits-final-verification.json}; final live health status ok, worker_available true, ai_configured true. No OpenCode writers found, no worker launched, no application/service/tunnel edits. Next bounded task: full authenticated desktop/mobile workflow and screenshot vision review, then isolated production setup/backup/restore/resources and original-session domain authorization. No completion notice; remain silent.
+- Current tick added and actually exercised authenticated Playwright workflow `artifacts/qa/supervisor-live/qa_browser_workflow.py`. UI login/project creation works; independently caught two real blocking API defects: GET instruments?q=600000 HTTP400 plain text `invalid type: map, expected option`; dataset submission with blank optional name HTTP422 `missing field name`. Source also shows DatasetWizard stores submitErr but never renders it; screenshot confirms invisible submit failure. Evidence browser-workflow.json and workflow-{data-desktop,failure}.png; failure screenshot visually reviewed, single layout confirmed. No full-browser pass claimed. Harness locator mistakes (label includes option text, ambiguous 复权 label) corrected without altering application.
+- Resumed ONLY integration session ses_f553821d1ffeRPSHHoGHXZx6xq for these narrow backend/UI fixes and relevant tests/builds. First launch using repo .venv failed immediately (no dotenv), confirmed no writer, relaunched with default python (dotenv verified). Actual wrapper PID2847343 / OpenCode child2847357 both verified alive; handle proc_66aa9aa132e6; log /home/somhairle/.hermes/cache/strategy-lab-integration-browser-repair.log. No duplicate writers. Next tick inspect log/PID/handoff, verify fixes independently and restart only QA after safe build, continue browser dataset preview/editor/version/backtest/result/comparison/AI and mobile review. No application edits by supervisor, no production/tunnel/service changes, no completion notice.
+- Current tick independently rebuilt debug, ran backend54/54 and frontend23/23 tests, Svelte0errors/0warnings, frontend build exit0; restarted only QA. Live authenticated browser confirms instruments?q=600000 HTTP200 real 浦发银行 catalog and absent-name dataset POST202 auto-generated name. Health200/worker_available/ai_configured verified. Browser harness exits0 but does NOT cover whole workflow and mobile width was not asserted, so no full-browser pass claimed.
+- Found real mobile overflow: 375px viewport with scrollWidth532 (pending) then552 (failed dataset); DOM identifies sidebar/main552px/cards523px. Full-page screenshot expands to content width and vision incorrectly suggested no overflow; DOM evidence plus viewport-only screenshot retained at artifacts/qa/supervisor-live/{mobile-overflow-probe.json,mobile-viewport.png,qa_mobile_probe.py}. Real dataset434e6a26-2bd0-4920-a192-e6142dccee73 subsequently failed due Eastmoney disconnect and Tencent connect timeout; preserve honest provider failure, retry real data next tick without fabrication.
+- Resumed only existing integration GLM session for narrow mobile wrapping/sizing fix and frontend regression/check/build. Wrapper2853674/child2853688 verified alive, terminal proc_368da546aef5; log /home/somhairle/.hermes/cache/strategy-lab-integration-mobile-repair.log. No duplicate writers; worker forbidden service/config changes. Next tick inspect worker and verify 375px DOM width plus viewport screenshots, then finish real preview/editor/version/run/result/comparison/AI browser flow. No production/tunnel changes or notice.
+- Current tick confirmed mobile worker exited (no OpenCode writer), independently ran frontend27/27 tests, Svelte0errors/0warnings and build exit0 (large chunk warning remains). Live QA serves rebuilt static assets without service restart. Actual mobile probe now viewport375/scrollWidth375, no overflowing elements; screenshot vision confirms no control overlap. Evidence mobile-overflow-probe.json/mobile-viewport.png refreshed.
+- Extended and exercised browser harness through real search, dates/adjustment, absent-name submit, terminal ready dataset and rendered20-row preview, plus375px width assertions before and after preview; final command exit0 and no pageerrors. Real fresh dataset e1aa8b20-ebc7-409f-9573-d0c9a4a9491b returned58 actual Tencent rows after Eastmoney failure. Subsequent final rerun used legitimate immutable cache. Harness strict locator encountered multiple owner datasets; choose first visible preview button (this verifies owner data preview, not exact newly-created dataset binding). Final JSON/screenshots under artifacts/qa/supervisor-live/browser-workflow*. Mobile viewport screenshot now scrolls to actual preview; vision confirms no overlap/side clipping, but narrow cells wrap numeric values and dates across lines, a readability limitation. Full editor/version/run/result/comparison/AI browser path still pending; do not claim whole workflow complete. No application edits, new workers, service/production/tunnel changes this tick.
+- Current tick wrote and ran actual authenticated `artifacts/qa/supervisor-live/qa_browser_strategy.py` using prior real project/dataset. Immediate strategy page fails with pageerror `c(...).slice is not a function`, blank main and no CodeMirror. Evidence browser-strategy.json and workflow-strategy-failure.png. Source confirms actual backend draft_generation:i64 versus frontend string `.slice` calls. No strategy/versions/backtest browser pass claimed; harness retained for rerun.
+- Resumed ONLY existing integration GLM session ses_f553821d1ffeRPSHHoGHXZx6xq for numeric-generation contract repair, optimistic/AI guard audit, regression tests and frontend check/build. Wrapper2864219/child2864233 verified alive, terminal proc_e6aa364d11c5, log /home/somhairle/.hermes/cache/strategy-lab-integration-generation-repair.log. No pre-existing OpenCode writer before launch. Next tick inspect worker, independently check/build and rerun qa_browser_strategy.py; then expand comparison/AI/mobile. No service/production/tunnel changes or completion notice.
+- Current tick independently verified generation repair: frontend30/30 tests, check0errors/0warnings, build0. Test stderr still includes CodeMirror jsdom getClientRects TypeError (recorded, not called clean). Actual authenticated browser qa_browser_strategy.py exit0: numeric generation renders, editor autosave persists, immutable snapshot and current-draft diff dialog, real backtest58 equity points/two fills, equity and drawdown SVG rendered, mobile scrollWidth375, no pageerrors. Harness initially wrongly required canvas; source uses SVG renderer, corrected to assert actual labeled SVG for both chart modes. Screenshots workflow-{version-desktop,results-desktop,results-mobile}.png and browser-strategy.json retained; desktop/mobile vision reviewed. Mobile first viewport dominated by long honest English assumptions; no sideways clipping, but chart is below fold.
+- New verified accounting/UI defects from real result and source: trade_count1 means closed round trips but frontend incorrectly describes fills (actual fills2); sell trade.value uses Backtrader ex.value cost basis, so shows buy cost659.66 instead of sell turnover. Resumed ONLY same integration GLM session for narrow accurate trade value/label regressions plus obvious metrics layout/test geometry repair. Wrapper2871912/child2871929 alive; terminal proc_5937b56a2c20; log /home/somhairle/.hermes/cache/strategy-lab-integration-results-repair.log. No competing writer. Next tick inspect worker, independently run worker/frontend suites, rebuild exact worker Docker image if worker changes, rerun real browser and assert fill quantity*price matches value, then finish comparison/AI/browser mobile chart review. No services/production/tunnel changed, no completion notice.
+- Current tick confirmed results worker exited/no duplicate writer. Independently ran worker38/38, frontend33/33, check0errors/0warnings, frontend build0; rebuilt exact Docker tag strategy-lab-worker:local image cc7f74ce4fdf. Worker report of zero test noise is NOT reproduced: CodeMirror noise fixed, but ECharts jsdom emits zero-dimension/HTMLCanvasElement.getContext not implemented warnings despite tests passing. Build still large-chunk warning; Docker build context2.562GB needs narrow .dockerignore improvement later.
+- Actual authenticated browser rerun on rebuilt worker passed editor/autosave/version/diff/backtest/equity/drawdown. Added hard assertions actual fill value=quantity*price and closed round trips1: buy659.659, sell649.00, two fills,58 equity points; latest run1647a719-3323-438c-abec-4ea538b46725. Final harness exit0/no pageerrors. Mobile resize initially transient scrollWidth1133 before chart observer settled; after bounded1.5s layout settling final width375, chart visible. Refreshed artifacts/qa/supervisor-live/{qa_browser_strategy.py,browser-strategy.json,workflow-results-desktop.png,workflow-results-mobile-chart.png}. Independently vision-reviewed both: six desktop metric tiles/turnover correct and readable, mobile drawdown axes/labels visible without overlaps; mobile table wraps values.
+- No application edits by supervisor, no new worker, no service/production/tunnel changes or notice. Next bounded work: authenticated run comparison and AI proposal/diff/accept browser flow (API AI was tested previously), then production/backup/resources/domain authorization. Test-only ECharts environment warnings and oversized Docker context remain cleanup items.
+- Current tick added and independently executed authenticated `artifacts/qa/supervisor-live/qa_browser_compare_ai.py` against actual QA, exit0 with five checkpoints and zero pageerrors. Selected two actual succeeded runs via UI, rendered normalized comparison SVG and condition differences; mobile document width375. Real AI proposal returned valid Python, draft/generation remained unchanged before acceptance; clicked accept on mobile, read back exact proposed draft, generation6 and matching immutable version. Evidence browser-compare-ai.json and workflow-{compare-desktop,compare-mobile,ai-proposal-desktop,ai-mobile}.png. Vision reviewed mobile comparison, mobile AI and desktop AI: no horizontal clipping/overlap; narrow code identifiers and version table wrap. Comparison runs have identical logic/data so curves overlap honestly. Desktop sidebar still displays current project 加载中 despite loaded project; inspect this minor UI defect in next cleanup alongside ECharts test noise and oversized Docker context. No OpenCode writers found, none launched; no application/service/production/tunnel changes. No completion notice. Next bounded task: remaining small UI cleanup then isolated production/backup/resources and actual domain authorization.
+- Current tick read brief/source and confirmed no existing OpenCode writer. Layout derives current project solely via projectOf; prior browser evidence shows loaded project still labeled 加载中. No root .dockerignore exists; worker Dockerfile needs only requirements-worker.txt and worker. Resumed ONLY existing integration GLM session for bounded sidebar reactive/deep-link name fix, ECharts test-environment warning cleanup and narrow Docker build-context exclusions with regressions/check/build. Wrapper2883552/actual OpenCode child2883566 independently verified alive; terminal proc_2f82d207bf4e; log /home/somhairle/.hermes/cache/strategy-lab-integration-final-cleanup.log. No completion claimed, no competing writer or service/tunnel/production changes. Next tick inspect worker log/PIDs, independently run frontend tests/check/build, actual sidebar desktop/mobile check and Docker image build/context measurement, then production/backup/resources/domain authorization.
+- Current tick found cleanup OpenCode wrapper2883552/child2883566 still alive; inspected fresh log showing ongoing frontend/.dockerignore work, so did not launch another writer or race frontend validation. Independently built exact worker image with new context guard: `docker build -f worker/Dockerfile -t strategy-lab-worker:local .` exited0; actual context54.27kB (previously2.562GB), image7f3ecf6290ee. Restricted no-network/read-only/cap-drop container imports worker.main/backtest/data successfully; /app contains only worker, no repo artifacts/server/frontend/.env/.venv. Evidence artifacts/qa/supervisor-live/docker-context-build.log. Frontend cleanup remains unverified until worker exits.
+- Retrieved original user message99011 from session20260916_193353_1e3c6334: literal public target fin.somhairle.bin. Exact .bid user-role search only retrieved compaction reference99333 describing .bid as tentative; no explicit substitution authorization established. Evidence artifacts/qa/supervisor-live/domain-authorization.md. Finish safe local work before blocker notice; no ingress/service/production changes or notice this tick. Next tick check existing writer completion, independently validate frontend/sidebar and continue isolated production/backup/resources.
+- Current tick confirmed cleanup worker exited and independently ran frontend37/37, Svelte0errors/0warnings and production build exit0. Prior ECharts/CodeMirror test noise absent in this fresh output; large-chunk build warning remains. Authenticated new qa_sidebar.py confirms real project name resolves on desktop and mobile, zero pageerrors. However twice reproduced persistent results-page overflow after desktop-to-mobile resize: viewport375/document scrollWidth1133 after1.5s. Evidence sidebar-checks.json plus sidebar-{1440,375}.png; viewport-only vision confirms name readable but cannot see below-fold overflow, so DOM assertion remains decisive. Harness writes evidence then fails; acceptance not weakened.
+- Resumed ONLY existing integration GLM session for narrow chart/table mobile overflow repair and fresh browser/unit verification. Wrapper2901780/child2901794 independently verified alive; terminal proc_a49223b2c3f3; log /home/somhairle/.hermes/cache/strategy-lab-integration-mobile-results-repair.log. No duplicate writer, application edits by supervisor, service/production/tunnel changes or notice. Next tick inspect writer and independently verify fresh mobile deep link plus resized results width, then isolated production/backup/resources. Domain authorization still unresolved as previously documented.
+- Current tick confirmed prior mobile-results OpenCode worker exited/no competing writer. Independently ran frontend39/39 tests, Svelte0errors/0warnings, production build exit0; no test stderr noise, large-chunk build warning remains. Extended and executed parent qa_sidebar.py: five live authenticated desktop/resized/fresh-mobile checkpoints, all document widths equal viewport (1440 or375), actual SVG widths1101/311 follow resize, zero pageerrors, real sidebar project name resolved. Final command exit0. Evidence artifacts/qa/supervisor-live/{qa_sidebar.py,sidebar-checks.json,sidebar-mobile-chart-verified.png}; independent vision review confirms visible mobile chart controls/legend/axes readable, no overlap/crop; table numeric wrapping remains known readability limitation. No application edits by parent, no new worker, no service/production/tunnel changes or completion notice. Next bounded task: isolated production release/admin/service, verified backup/restore and idle measurements, then final full gates and domain decision blocker protocol.
+- Current tick independently verified persistent production unit enabled and host user Linger=yes, restarted only strategy-lab-production and confirmed changed PID/exact copied release executable plus actual healthy HTTP in0.061s. qa_production_persistence.py exited0; seven real idle cgroup samples over30.050s show memory2,416,640–12,435,456bytes settling to2,416,640, CPU0.06393% of one core. Raw evidence artifacts/qa/supervisor-live/production-persistence-checks.json; docs/production-local.md updated. No physical host reboot performed; measurements exclude Docker workloads. No OpenCode writers found, none launched; no application/config/tunnel changes or notice. Next bounded task: populated QA data-object backup/restore into private isolated temporary restore instance (never overwrite production or live QA), verify restored API/object contents and document procedure; then final full gates and unresolved domain blocker protocol.
+- Current tick independently executed populated backup/restore verifier qa_backup_restore.py: final exit0, all11 checks passed. Consistent stopped-QA SQLite/object snapshot, SHA256 equality, integrity/entity counts/all ready object references, isolated release server restored authentication/draft/real preview/exact run result; QA and production health200 afterward. Evidence artifacts/qa/supervisor-live/{qa_backup_restore.py,backup-restore-checks.json}; docs/production-local.md records actual procedure and private snapshot location policy. Initial harness failures corrected honestly: transient QA unit disappears after stop (recreated using existing launcher and verified), preview is a separate API endpoint. No production/tunnel/application change or new OpenCode worker. Isolated restore process terminated. Next tick: final full acceptance suites and production copied-asset freshness check, then unresolved domain blocker notice/pause protocol. No completion notice yet.
+- Production isolated DB/admin/service, idle measurements and populated backup/restore now verified.
+- Resolve public domain authorization from original session20260916_193353_1e3c6334; RELEASE_SCOPE assertion does not override brief's explicit requirement to establish actual user authorization for .bid vs literal .bin.
+- No production/tunnel changes, no completion notice, supervisor remains active. User requested silence until completion or genuine decision blocker after all safe work.
+
+- Current tick independently rebuilt release (exit0, seven warnings) and provisioned isolated production candidate: persistent enabled strategy-lab-production.service, copied release/frontend, clean private DB/admin, loopback127.0.0.1:8789; QA8787 untouched. Exact PID executable verified, health ok/worker_available/ai_configured, authenticated /auth/me admin and empty projects, SQLite counts users1/projects0/datasets0/runs0. Credentials/runtime env mode0600 outside repo, bootstrap secret absent from service environment. No public ingress or domain substitution. Initial online SQLite backup independently reopened integrity/count checks pass; populated data/object restore still pending. Evidence production-local-checks.json; operational notes docs/production-local.md. Harness login initially assumed wrapped user; corrected via actual authenticated /auth/me, no application bug. Next tick verify persistent-unit restart/linger, measured idle samples, populated backup/restore and final full gates before domain blocker notice. No OpenCode writer or completion notice.