From 088735b948d46896b8af30efcb0a2dc5d362b97f Mon Sep 17 00:00:00 2001 From: "Somhairle H. Marisol" Date: Fri, 18 Sep 2026 08:27:41 +0800 Subject: docs(release): 全周期交接文档入库(含 ui-shadcn 迁移交付说明) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit [变更性质] 纯文档提交,无运行时逻辑。 [文档内容] 补齐此前各轮未入库的交接/验收文档:backend-auth/backend-domain/ domain-authorization-user(认证与授权域)、etf-recovery-release- handoff(ETF 修复 + ops 演练定稿与生产部署命令)、recovery-* 系列、 frontend/parent-ui-findings(UI 迁移上下文)、worker/integration 等, 以及本轮 docs/ui-shadcn-handoff.md(shadcn-svelte 迁移交接,含 Chart.svelte 契约、runes $state 踩坑记录与 375/768/1440 验证证据)。 [更新方案] 按主题分文;每份文档只记录可复现的命令、验证结果与语义边界, 不导出密钥或生产敏感路径。 [影响范围] 文档渠道:后续 leader/client 审阅入口;与代码提交一一对应便于回溯。 --- docs/completion-brief.md | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) create mode 100644 docs/completion-brief.md (limited to 'docs/completion-brief.md') diff --git a/docs/completion-brief.md b/docs/completion-brief.md new file mode 100644 index 0000000..103ab3e --- /dev/null +++ b/docs/completion-brief.md @@ -0,0 +1,16 @@ +# Autonomous completion brief +User authorizes finishing Strategy Lab development/deployment using OpenCode GLM-5.3-Flash; latest request: notify only when everything is finished, no routine progress messages. Work scope this repo only. Never modify other Hermes profiles or unrelated services. + +Read SPEC.md, RELEASE_SCOPE.md, docs/integration-handoff.md, docs/parent-ui-findings.md and current code. Independent latest tests: cargo49 passed, worker37 passed, frontend22 passed, svelte-check0 errors/warnings. Earlier real HTTP30 gates passed including actual Tencent行情, cross-user content cache, backtest and reproduction. Latest fixes not yet rechecked in LIVE service: strategy exec single namespace; cancellation race; AI stable session header; doubled Layout. No public deployment yet. Backend still has warnings. + +Tools: OpenCode wrapper /home/somhairle/.hermes/cache/strategy-lab-run-opencode.py with STRATEGY_AGENT_SLOT=integration; session ses_f553821d1ffeRPSHHoGHXZx6xq, model strategy-go/glm-5.3-flash. Log /home/somhairle/.hermes/cache/strategy-lab-integration.log. Check child PIDs and logs before launch: completion exit_code=None is unreliable. Only one integrator, no competing writers. Never global pkill/killall. Code workers must not touch services. Parent/supervisor alone manages exact app units. + +QA systemd user unit strategy-lab-qa runs 127.0.0.1:8787. Launcher /home/somhairle/.hermes/cache/strategy-lab-qa-service.py loads only required credentials privately, currently executes DEBUG binary: rebuild it before restart, even if release binary was built. QA DB/private creds under /home/somhairle/.hermes/cache/strategy-lab-qa/service; never print credentials or mix QA accounts into production. Test commands: launcher test --market; qa venv/bin/python browser_smoke.py; python qa_ai.py; python qa_limits.py, all under /home/somhairle/.hermes/cache/strategy-lab-qa/. Browser Playwright installed in that venv. Scripts may have test-harness mistakes: fix those honestly, never weaken acceptance. qa_limits.py has correct private-account filename/browser-account.private.json and a['project']['id'], flat run parameters. Still must repair Docker inspect: API hides container_id, read exact container_id for that run from QA sqlite read-only; names are sl-run-RANDOM UUID, not run ID. Timeout fixed by BACKTEST_TIMEOUT_SECS=60 in QA launcher; per-run timeout field unsupported. First limits test failed due real namespace bug and cancel race, now code fixed. Need independently verify failed/cancelled/timeout statuses and actual no-network, no-secret mounts/env, CPU/memory/PID/read-only container restrictions. + +AI real /ai/assist previously returned MissingSessionID. Latest ai.rs uses honest own User-Agent and stable per-owner/project x-opencode-session per official https://opencode.ai/docs/go/#where-can-i-use-it (custom coding agents allowed). Verify actual model response, Python syntax, unchanged draft before accept, accepted immutable revision, stale accept refusal, usage recorded. Internal POC only; no commercial third-party resale promise. + +Remaining acceptance: full authenticated browser path selecting/searching symbol, dates/fields/indicators/adjustment, data preview, strategy editor/version, run/result/comparison, AI, desktop/mobile no errors; screenshots vision review. Real security/cancel/timeout/restart recovery; repeat all tests after changes. Production release binary, persistent user systemd service, clean separate DB/admin account securely provisioned; documented limits, backup/restore and measured idle resources. Source/runtime docs and screenshots delivered. Never claim complete while any named criterion pending. Record progress+evidence+blockers in docs/completion-state.md EVERY tick; bounded work each tick, long OpenCode can run background but never duplicate it. No blind sleep loops. + +Public domain user originally typed fin.somhairle.bin (NXDOMAIN), release doc tentatively fin.somhairle.bid using existing somhairle.bid Tunnel; not explicitly confirmed. Do NOT silently substitute domain: establish authorization from original session history (session20260916_193353_1e3c6334) if available; otherwise mark this a genuine user decision blocker, finish all safe local work then report blocker rather than claim complete. Existing ~/.cloudflared/config.yml ingress dav:6065 git:8090 linkwarden:3000 fallback404; preserve everything. Existing /etc/systemd/system/cloudflared.service MUST retain --protocol http2. Read before append, preserve /etc/hosts and Clash Merge rules; never overwrite. Only expose after permission/security gates, verify both local and public actual endpoint. Do not expose bootstrap creds in logs/source. + +Completion protocol: only after all criteria and public target verified write docs/completion-notice.md containing concise Chinese user-facing completion message, URL, account provisioning instructions without plaintext secrets, actual tests/limitations and artifact paths. Write only verified result, never a placeholder. If truly blocked needing user input after safe work, write honest docs/completion-notice.md headed '需要你确认,尚未全部完成' with only essential question and completed evidence. A separate no-agent notifier sends file once. Then list cron jobs and pause this job by exact ID/name Strategy Lab completion supervisor. Until complete/blocker, local output only; no progress notifications. -- cgit v1.2.3