summaryrefslogtreecommitdiff
path: root/docs/completion-brief.md
blob: 103ab3ed90ca4102f7906db1dcbf7feadfa9e029 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
# Autonomous completion brief
User authorizes finishing Strategy Lab development/deployment using OpenCode GLM-5.3-Flash; latest request: notify only when everything is finished, no routine progress messages. Work scope this repo only. Never modify other Hermes profiles or unrelated services.

Read SPEC.md, RELEASE_SCOPE.md, docs/integration-handoff.md, docs/parent-ui-findings.md and current code. Independent latest tests: cargo49 passed, worker37 passed, frontend22 passed, svelte-check0 errors/warnings. Earlier real HTTP30 gates passed including actual Tencent行情, cross-user content cache, backtest and reproduction. Latest fixes not yet rechecked in LIVE service: strategy exec single namespace; cancellation race; AI stable session header; doubled Layout. No public deployment yet. Backend still has warnings.

Tools: OpenCode wrapper /home/somhairle/.hermes/cache/strategy-lab-run-opencode.py with STRATEGY_AGENT_SLOT=integration; session ses_f553821d1ffeRPSHHoGHXZx6xq, model strategy-go/glm-5.3-flash. Log /home/somhairle/.hermes/cache/strategy-lab-integration.log. Check child PIDs and logs before launch: completion exit_code=None is unreliable. Only one integrator, no competing writers. Never global pkill/killall. Code workers must not touch services. Parent/supervisor alone manages exact app units.

QA systemd user unit strategy-lab-qa runs 127.0.0.1:8787. Launcher /home/somhairle/.hermes/cache/strategy-lab-qa-service.py loads only required credentials privately, currently executes DEBUG binary: rebuild it before restart, even if release binary was built. QA DB/private creds under /home/somhairle/.hermes/cache/strategy-lab-qa/service; never print credentials or mix QA accounts into production. Test commands: launcher test --market; qa venv/bin/python browser_smoke.py; python qa_ai.py; python qa_limits.py, all under /home/somhairle/.hermes/cache/strategy-lab-qa/. Browser Playwright installed in that venv. Scripts may have test-harness mistakes: fix those honestly, never weaken acceptance. qa_limits.py has correct private-account filename/browser-account.private.json and a['project']['id'], flat run parameters. Still must repair Docker inspect: API hides container_id, read exact container_id for that run from QA sqlite read-only; names are sl-run-RANDOM UUID, not run ID. Timeout fixed by BACKTEST_TIMEOUT_SECS=60 in QA launcher; per-run timeout field unsupported. First limits test failed due real namespace bug and cancel race, now code fixed. Need independently verify failed/cancelled/timeout statuses and actual no-network, no-secret mounts/env, CPU/memory/PID/read-only container restrictions.

AI real /ai/assist previously returned MissingSessionID. Latest ai.rs uses honest own User-Agent and stable per-owner/project x-opencode-session per official https://opencode.ai/docs/go/#where-can-i-use-it (custom coding agents allowed). Verify actual model response, Python syntax, unchanged draft before accept, accepted immutable revision, stale accept refusal, usage recorded. Internal POC only; no commercial third-party resale promise.

Remaining acceptance: full authenticated browser path selecting/searching symbol, dates/fields/indicators/adjustment, data preview, strategy editor/version, run/result/comparison, AI, desktop/mobile no errors; screenshots vision review. Real security/cancel/timeout/restart recovery; repeat all tests after changes. Production release binary, persistent user systemd service, clean separate DB/admin account securely provisioned; documented limits, backup/restore and measured idle resources. Source/runtime docs and screenshots delivered. Never claim complete while any named criterion pending. Record progress+evidence+blockers in docs/completion-state.md EVERY tick; bounded work each tick, long OpenCode can run background but never duplicate it. No blind sleep loops.

Public domain user originally typed fin.somhairle.bin (NXDOMAIN), release doc tentatively fin.somhairle.bid using existing somhairle.bid Tunnel; not explicitly confirmed. Do NOT silently substitute domain: establish authorization from original session history (session20260916_193353_1e3c6334) if available; otherwise mark this a genuine user decision blocker, finish all safe local work then report blocker rather than claim complete. Existing ~/.cloudflared/config.yml ingress dav:6065 git:8090 linkwarden:3000 fallback404; preserve everything. Existing /etc/systemd/system/cloudflared.service MUST retain --protocol http2. Read before append, preserve /etc/hosts and Clash Merge rules; never overwrite. Only expose after permission/security gates, verify both local and public actual endpoint. Do not expose bootstrap creds in logs/source.

Completion protocol: only after all criteria and public target verified write docs/completion-notice.md containing concise Chinese user-facing completion message, URL, account provisioning instructions without plaintext secrets, actual tests/limitations and artifact paths. Write only verified result, never a placeholder. If truly blocked needing user input after safe work, write honest docs/completion-notice.md headed '需要你确认,尚未全部完成' with only essential question and completed evidence. A separate no-agent notifier sends file once. Then list cron jobs and pause this job by exact ID/name Strategy Lab completion supervisor. Until complete/blocker, local output only; no progress notifications.