# Strategy Lab Implementation Plan > Agentic workers: execute the approved SPEC.md task-by-task, use TDD and actual tool evidence. User explicitly selected OpenCode + GLM-5.3-Flash. Goal: working private self-service strategy research platform, not a mockup. Architecture: static Svelte client, Rust/Axum API and persistent SQLite queue, isolated Python AKShare/Backtrader worker; replaceable remote model adapter. Tech Stack: Rust, Axum, rusqlite, Svelte, TypeScript, Vite, Backtrader, AKShare, Docker. ## Task A — Runtime prerequisites and contract 1. Install latest npm opencode-ai and record version (done 1.18.31). 2. Secure launcher reads only active Hermes OPENCODE_GO_API_KEY and injects subprocess environment; no key copied to source (done). 3. Smoke actual glm-5.3-flash call and record success (done). 4. Install Rust compiler and verify Docker and Node/Python tools (done). 5. Freeze SPEC.md HTTP/worker contracts; do not overwrite other agents' work. ## Task B — Worker, tests before implementation Files worker/{main,data,backtest}.py, worker/Dockerfile, requirements-worker.txt, tests/worker/, docs/worker.md. 1. Write failing normalization tests: preserve raw fields/units, reject bad dates/missing data, no substituted symbols. 2. Run pytest, then implement adapters and test until green. 3. Write failing deterministic Backtrader accounting/next-bar tests using labeled synthetic input. 4. Implement mature-engine runner and manifest/result protocol; rerun tests. 5. Probe real AKShare endpoints and report exact successes/failures, write actual evidence. 6. Build Docker image, backtest without network and credentials, measure memory. ## Task C — Backend, tests before implementation Files server/Cargo.toml, server/src/{main,db,auth,projects,datasets,runs,worker,ai}.rs, server/tests/, docs/backend.md. 1. Write failing owner/auth and immutable revision tests; implement SQLite schema and handlers. 2. Write failing request validation/cache key tests; implement safe dataset jobs and immutable blobs. 3. Write failing run lifecycle/restart/cancel tests; implement bounded Docker runner. 4. Write failing AI stale-generation/owner tests; implement configurable API adapter and real usage ledger. 5. Run cargo test, cargo build --release (CARGO_BUILD_JOBS=2 to avoid memory pressure). ## Task D — Frontend, checks and interaction tests Files frontend/package.json, frontend/src/... , docs/frontend.md. 1. Add executable tests for workflow state and API errors before implementation. 2. Build login, project list, actual self-service data wizard/preview. 3. Build editor/autosave/version diff/restore, dataset selector, run controls and status. 4. Build result charts/trades/run comparison, AI proposed-code diff/accept/usage. 5. Run check/test/build and Playwright browser smoke; no fixture data in production. ## Task E — Integration and independent QA 1. Read all outputs; reconcile HTTP and worker contract differences through OpenCode fixes. 2. Start service loopback with secrets injected at runtime; health check independently. 3. Create private account, actual data request, cache reuse request, version/restore/run/compare, real AI suggestion+accept. 4. Negative tests authentication, cross-user access, stale edits, timeout/network worker policies. 5. Browser QA all main pages, screenshot and visual inspection, fix concrete problems. 6. Measure process RSS/CPU/build sizes and actual experiment duration. Record actual outcomes, no estimates called measured. 7. README with reproducible install/run/test, data/model licensing and internal-only limitations. Backup/restart test. Deliver local URL/source/screenshots. No public publishing, payment integration or API resale. Any unimplemented acceptance item must be explicitly listed as incomplete rather than claimed complete.