diff --git a/docs/LOGBOOK.md b/docs/LOGBOOK.md index 3672a9d9..4b765b8a 100644 --- a/docs/LOGBOOK.md +++ b/docs/LOGBOOK.md @@ -1,4 +1,4 @@ -## 2026-06-14|P2-132 Post-release verifier / rollback gate 本地完成,正式驗證待推進 +## 2026-06-14|P2-132 Post-release verifier / rollback gate 完成與正式驗證 **背景**:P2-131 已把 owner release approval gate 正式驗證完成;但 approval gate 仍不得被誤讀成 owner release approved、maintenance window approved、rollback owner confirmed、post-release verifier ready、release verification passed 或 live apply release passed。P2-132 因此只建立 post-release verifier / rollback gate,把批准門檻轉成正式釋出後驗證與 rollback release 的可審核 hold,不開啟 verifier live read、不確認 rollback owner、不釋放 live apply、不套用 writer、不寫 receipt、不寫 result capture / learning / PlayBook trust / reviewer queue / Gateway queue,也不送 Telegram 或呼叫 Bot API。 @@ -19,13 +19,19 @@ **CD 狀態同步**: - Feature commit `040c320c` 已推送 Gitea main;Gitea Actions Code Review / ai-code-review 成功,CD tests 成功。 - 同一輪 CD 的 build-and-deploy 與 post-deploy-checks 停在 `Blocked by required conditions`,正式 API `GET /api/v1/agents/agent-result-capture-post-release-verifier-rollback-gate` 仍回 `Not Found`,確認 P2-132 尚未部署到正式站。 -- 已準備以無行為變更的 `apps/**` 錨點重新觸發 CD;完成後需重新驗證 Gitea status、正式 API readback 與 desktop / mobile smoke。 +- 已以無行為變更的 `apps/**` 錨點重新觸發 CD,retrigger commit `333731e5` 已部署;deploy marker `934af770` 已回寫。 + +**正式驗證**: +- Gitea Actions:`#2919` ai-code-review 成功;`#2918` CD 的 tests、build-and-deploy、post-deploy-checks 成功。 +- 正式 API health 回 `healthy`、`environment=prod`、`mock_mode=false`。 +- 正式 API:`GET /api/v1/agents/agent-result-capture-post-release-verifier-rollback-gate` 回 `schema_version=ai_agent_result_capture_post_release_verifier_rollback_gate_v1`、current `P2-132`、next `P2-133`、completion `100`、runtime authority `result_capture_post_release_verifier_rollback_gate_only_no_live_write`。 +- 正式 API rollup:post-release verifier gate `5`、rollback release gate `5`、release verification hold `5`、live-apply post-release gate `5`、blocked post-release transition `6`、operator action `5`、需批准 `8`、阻擋 `9`、正式寫入 / 發送 `0`。 +- 正式 desktop / mobile smoke:`/zh-TW/governance?tab=automation-inventory` 可見 P2-132 區塊,必要數字皆可見;禁用內部協作片語命中 `0`、水平溢位 `0`、P2-132 高風險控制 `0`、console error `0`、API bad response `0`、actionable request failure `0`。raw `_rsc` / 導覽 `ERR_ABORTED` 皆為 Next.js 預取取消,非 API 或資源錯誤。 **安全邊界**: - P2-132 仍是 post-release verifier / rollback gate;不接受口頭批准、不把 approval gate 解讀成 owner release approved、不批准維護窗口、不確認 rollback owner、不啟用 post-release verifier live read、不釋放 rollback release、不釋放 live apply、不套用 writer、不執行正式寫入、不寫 receipt、不寫 result capture、不寫 learning、不更新 PlayBook trust、不寫 reviewer queue、不寫 Gateway queue、不送 Telegram、不呼叫 Bot API、不寫 report receipt、不讀 canonical runtime target、不做 live query、不寫 production target、不讀 secret、不執行 destructive action、不回傳內部協作內容。 **下一步**: -- 推送 P2-132 feature commit 到 Gitea main,等待 CD tests、build-and-deploy、post-deploy-checks 全綠,再做正式 API readback 與 desktop / mobile governance smoke。 - `P2-133`:final release candidate readback;只有 P2-132 正式驗證後才可把 post-release verifier gate、rollback release gate、release verification hold、live-apply post-release gate 與 blocked post-release transition 轉成 release candidate readback,仍不得直接開啟 result capture writer、learning writer、PlayBook trust writer、reviewer queue write、Gateway queue write、Telegram send、Bot API call 或 production write。 ## 2026-06-14|P2-131 Owner release approval gate 完成與正式驗證 diff --git a/docs/ai/AI_AGENT_AUTOMATION_WORKLIST_2026-06-04.md b/docs/ai/AI_AGENT_AUTOMATION_WORKLIST_2026-06-04.md index 5239a158..a090f195 100644 --- a/docs/ai/AI_AGENT_AUTOMATION_WORKLIST_2026-06-04.md +++ b/docs/ai/AI_AGENT_AUTOMATION_WORKLIST_2026-06-04.md @@ -12,15 +12,15 @@ | Nemotron 實際整合應用 | 30% | 完整回放前仍被關卡擋下 | `blocked_needs_evidence`,下一關是 `refresh_source_evidence_then_5_record_smoke_only` | | 工具 / 服務 / 套件 AI 自動化 | 92% | P0 已完成;P1 服務 / runtime / 監控 / provider / service health / 備份 / DR / 套件與供應鏈只讀基線已完成;P1-007 失敗限定通知合約與前端 redaction 合約已完成;下一主線是 P2-004 依賴 / 供應鏈漂移監控 | 狀態分類、盤點 schema、權限矩陣、靜態盤點種子、只讀 API、UI 骨架、驗證、自動化待辦 schema / 快照 / API / 分組 UI、Backup / DR 目標盤點、準備度矩陣、備份通知政策、Backup / DR 證據 UI、復原演練批准包模板、異地 / escrow 準備度狀態、任務批准邊界、確定性進度彙總、Python 套件 / 供應鏈只讀基線、JS pnpm/npm 只讀基線、Docker build surface 只讀基線、CVE / license / drift 嚴重度政策、定期依賴漂移與外部資料來源檢查設計、依賴升級批准包模板、runtime_surface_inventory_v1 schema / snapshot / API / UI、gitea_workflow_runner_health_v1 schema / snapshot / API / UI、observability_contract_matrix_v1 schema / snapshot / API / UI、ai_provider_route_matrix_v1 schema / snapshot / API / UI、service_health_gap_matrix_v1 schema / snapshot / API / UI、service health evidence cards UI、service_health_failure_notification_policy_v1 schema / snapshot / API / UI 已完成 | | OpenClaw / Hermes / NemoTron 佈建布局 | 45% | P1-401 / P1-402 已完成;仍是只讀 layout 與治理頁顯示,不是 runtime deploy | `ai_agent_deployment_layout_v1` schema、`ai_agent_deployment_layout_2026-06-11.json`、`GET /api/v1/agents/agent-deployment-layout`、治理頁自動化盤點 UI、`AI_AGENT_DEPLOYMENT_LAYOUT_2026-06-11.md` | -| OpenClaw / Hermes / NemoTron 主動溝通、學習與成長證據 | 100% | P2-401A 到 P2-132 已完成只讀證據面、runtime / report / result-capture gates、no-write readback、promotion review、writer implementation review、writer dry-run fixture、writer dry-run readback、owner promotion execution gate、owner-approved execution rehearsal、owner acceptance / maintenance window gate、owner acceptance readback / preflight hold、owner-approved preflight release package、owner-approved release readiness readback、owner release approval gate 與 post-release verifier / rollback gate;P2-132 已本地驗證,固定 5 個 post-release verifier gate、5 個 rollback release gate、5 個 release verification hold、5 個 live-apply post-release gate、6 個 blocked post-release transition 與 5 個 operator action,正式站 CD / API / smoke 待推進。runtime worker、DB migration、production Redis consumer group、canonical runtime readback、live query、runtime score、result capture write、Telegram 實發、delivery receipt E2E、live report delivery、reviewer queue write、Gateway queue write、AI analysis runtime、中低風險 auto worker、KM / LOGBOOK / audit DB / timeline / PlayBook trust 寫入、SDK / 付費服務仍未開 gate | `ai_agent_result_capture_post_release_verifier_rollback_gate_v1`、`GET /api/v1/agents/agent-result-capture-post-release-verifier-rollback-gate`、`ai_agent_result_capture_owner_release_approval_gate_v1`、`GET /api/v1/agents/agent-result-capture-owner-release-approval-gate`、正式站 deploy marker `03617db7`、正式站 `/zh-TW/governance?tab=automation-inventory` desktop / mobile smoke、`ai_agent_result_capture_owner_approved_release_readiness_readback_v1`、`GET /api/v1/agents/agent-result-capture-owner-approved-release-readiness-readback`、正式站 deploy marker `6fcf7241`、`ai_agent_result_capture_owner_approved_preflight_release_package_v1`、`GET /api/v1/agents/agent-result-capture-owner-approved-preflight-release-package`、`ai_agent_result_capture_owner_acceptance_readback_preflight_hold_v1`、`GET /api/v1/agents/agent-result-capture-owner-acceptance-readback-preflight-hold`、`ai_agent_result_capture_owner_acceptance_maintenance_gate_v1`、`GET /api/v1/agents/agent-result-capture-owner-acceptance-maintenance-gate`、`ai_agent_result_capture_owner_approved_execution_rehearsal_v1`、`GET /api/v1/agents/agent-result-capture-owner-approved-execution-rehearsal`、`ai_agent_result_capture_owner_promotion_review_v1`、`ai_agent_result_capture_writer_dry_run_readback_v1`、`ai_agent_result_capture_writer_dry_run_fixture_v1`、`ai_agent_result_capture_writer_implementation_review_v1`、`ai_agent_result_capture_write_gate_review_v1`、`ai_agent_interaction_learning_proof_v1`、MASTER §3.2.1b / §3.2.1d / §3.4.3 | +| OpenClaw / Hermes / NemoTron 主動溝通、學習與成長證據 | 100% | P2-401A 到 P2-132 已完成只讀證據面、runtime / report / result-capture gates、no-write readback、promotion review、writer implementation review、writer dry-run fixture、writer dry-run readback、owner promotion execution gate、owner-approved execution rehearsal、owner acceptance / maintenance window gate、owner acceptance readback / preflight hold、owner-approved preflight release package、owner-approved release readiness readback、owner release approval gate 與 post-release verifier / rollback gate;P2-132 已正式驗證,固定 5 個 post-release verifier gate、5 個 rollback release gate、5 個 release verification hold、5 個 live-apply post-release gate、6 個 blocked post-release transition 與 5 個 operator action。runtime worker、DB migration、production Redis consumer group、canonical runtime readback、live query、runtime score、result capture write、Telegram 實發、delivery receipt E2E、live report delivery、reviewer queue write、Gateway queue write、AI analysis runtime、中低風險 auto worker、KM / LOGBOOK / audit DB / timeline / PlayBook trust 寫入、SDK / 付費服務仍未開 gate | `ai_agent_result_capture_post_release_verifier_rollback_gate_v1`、`GET /api/v1/agents/agent-result-capture-post-release-verifier-rollback-gate`、正式站 deploy marker `934af770`、正式站 `/zh-TW/governance?tab=automation-inventory` desktop / mobile smoke、`ai_agent_result_capture_owner_release_approval_gate_v1`、`GET /api/v1/agents/agent-result-capture-owner-release-approval-gate`、正式站 deploy marker `03617db7`、`ai_agent_result_capture_owner_approved_release_readiness_readback_v1`、`GET /api/v1/agents/agent-result-capture-owner-approved-release-readiness-readback`、正式站 deploy marker `6fcf7241`、`ai_agent_result_capture_owner_approved_preflight_release_package_v1`、`GET /api/v1/agents/agent-result-capture-owner-approved-preflight-release-package`、`ai_agent_result_capture_owner_acceptance_readback_preflight_hold_v1`、`GET /api/v1/agents/agent-result-capture-owner-acceptance-readback-preflight-hold`、`ai_agent_result_capture_owner_acceptance_maintenance_gate_v1`、`GET /api/v1/agents/agent-result-capture-owner-acceptance-maintenance-gate`、`ai_agent_result_capture_owner_approved_execution_rehearsal_v1`、`GET /api/v1/agents/agent-result-capture-owner-approved-execution-rehearsal`、`ai_agent_result_capture_owner_promotion_review_v1`、`ai_agent_result_capture_writer_dry_run_readback_v1`、`ai_agent_result_capture_writer_dry_run_fixture_v1`、`ai_agent_result_capture_writer_implementation_review_v1`、`ai_agent_result_capture_write_gate_review_v1`、`ai_agent_interaction_learning_proof_v1`、MASTER §3.2.1b / §3.2.1d / §3.4.3 | | AI Agent 主動營運委派與版本生命週期 | 100% | P2-402A / P2-402B / P2-402C / P2-402D / P2-402E / P2-402F / P2-402G 已完成;已建立 repo-only 版本新鮮度快照、工具採用批准包、Telegram action-required digest policy、Gitea PR 草案 lane、host / K3s / stateful 版本只讀盤點、API 與 governance UI。定期排程、外部版本查詢、工具安裝、CI 變更、套件升級、主機更新、container pull、實際 PR creation、auto merge、Telegram 實發、SSH、kubectl、重啟仍未開 gate | `ai_agent_proactive_operations_contract_v1`、`ai_agent_version_freshness_snapshot_v1`、`ai_agent_tool_adoption_approval_package_v1`、`ai_agent_telegram_action_required_digest_policy_v1`、`ai_agent_gitea_pr_draft_lane_v1`、`ai_agent_host_stateful_version_inventory_v1`、`GET /api/v1/agents/agent-proactive-operations-contract`、`GET /api/v1/agents/agent-version-freshness-snapshot`、`GET /api/v1/agents/agent-tool-adoption-approval-package`、`GET /api/v1/agents/agent-telegram-action-required-digest-policy`、`GET /api/v1/agents/agent-gitea-pr-draft-lane`、`GET /api/v1/agents/agent-host-stateful-version-inventory`、`/zh-TW/governance?tab=automation-inventory`、MASTER §3.2.1c | | 本工作清單與分析報告 | 100% | 已完成 | 本 MD 文件 | -AI Agent 自動化工作包目前完成度:**99.4%**。本工作清單文件本身完成度:**100%**。 +AI Agent 自動化工作包目前完成度:**99.5%**。本工作清單文件本身完成度:**100%**。 三 Agent 佈建布局目前完成度:**45%**。第一波已完成只讀 schema / snapshot / API / 測試 / 報告,第二波已接入治理頁自動化盤點 UI;正式 runtime 佈署、Telegram E2E 發送與 AgentSession 工作流仍需逐項 gate。 -三 Agent 主動溝通、學習與成長證據目前完成度:**100%**。P2-403A 到 P2-132 已把互動證據、報表治理、runtime readback、reviewer / result capture / writer gates、no-write readback、promotion review、writer implementation review、writer dry-run fixture、writer dry-run readback、owner promotion execution gate、owner-approved execution rehearsal、owner acceptance / maintenance window gate、owner acceptance readback / preflight hold、owner-approved preflight release package、owner-approved release readiness readback、owner release approval gate 與 post-release verifier / rollback gate 全部固定成可驗證證據。P2-132 已本地驗證,固定 5 個 post-release verifier gate、5 個 rollback release gate、5 個 release verification hold、5 個 live-apply post-release gate、6 個 blocked post-release transition 與 5 個 operator action;正式 API、desktop / mobile smoke 待 CD 完成後驗證。目前 live AgentSession、Agent message、handoff、canonical runtime readback、live query、runtime score、result capture write、learning write、Telegram receipt、Gateway queue write、reviewer queue write、runtime verifier execution、live report delivery、AI analysis runtime、中低風險 auto worker、Telegram 實發、shadow worker live、delivery receipt E2E、KM / LOGBOOK / audit DB / timeline / PlayBook trust runtime 寫入仍全部為 `0`。真正下一步是 `P2-133`。 +三 Agent 主動溝通、學習與成長證據目前完成度:**100%**。P2-403A 到 P2-132 已把互動證據、報表治理、runtime readback、reviewer / result capture / writer gates、no-write readback、promotion review、writer implementation review、writer dry-run fixture、writer dry-run readback、owner promotion execution gate、owner-approved execution rehearsal、owner acceptance / maintenance window gate、owner acceptance readback / preflight hold、owner-approved preflight release package、owner-approved release readiness readback、owner release approval gate 與 post-release verifier / rollback gate 全部固定成可驗證證據。P2-132 已正式驗證,deploy marker `934af770`,固定 5 個 post-release verifier gate、5 個 rollback release gate、5 個 release verification hold、5 個 live-apply post-release gate、6 個 blocked post-release transition 與 5 個 operator action;正式 API、desktop / mobile smoke、禁用內部協作片語 `0`、水平溢位 `0`、P2-132 危險入口 `0` 均通過。目前 live AgentSession、Agent message、handoff、canonical runtime readback、live query、runtime score、result capture write、learning write、Telegram receipt、Gateway queue write、reviewer queue write、runtime verifier execution、live report delivery、AI analysis runtime、中低風險 auto worker、Telegram 實發、shadow worker live、delivery receipt E2E、KM / LOGBOOK / audit DB / timeline / PlayBook trust runtime 寫入仍全部為 `0`。真正下一步是 `P2-133`。 AI Agent 主動營運委派與版本生命週期目前完成度:**100%**。已完成 12 類版本 domain、24 類可委派能力、5 種 cadence、8 類 MCP、4 類 RAG memory、只讀 API、`P2-402B` repo-only daily version freshness snapshot、`P2-402C` Renovate / OSV-Scanner / Trivy / Syft / Grype 工具採用批准包、`P2-402D` Telegram action-required digest policy、`P2-402E` Gitea PR 草案 lane、`P2-402F` host OS / K3s / stateful services 版本只讀盤點,以及 `P2-402G` governance UI 顯示可委派能力;`P2-403A` 到 `P2-132` 已補互動、學習證據面、live read model gate、Redis dry-run gate、learning writeback approval package、Telegram receipt approval package、owner-approved learning dry-run preview、runtime write gate review、post-write verifier package、runtime verifier evidence review、報表真相、TG 戰情室收斂、日週月報、Agent 工作量、圖表化報告、風險自動化政策、報表 runtime 啟動前閘門、no-write dry-run 證據包、fixture/readback/verifier dry-run 證據包、shadow/no-write execution gate、操作類別權限模型、13 類候選操作 dry-run 證據、任務結果稽核軌跡、matched PlayBook 學習缺口、critic / reviewer result capture、owner-approved result capture dry-run / readback、result capture writer dry-run fixture、writer dry-run readback、owner promotion execution gate、owner-approved execution rehearsal、owner acceptance / maintenance window gate、owner acceptance readback / preflight hold、owner-approved preflight release package、owner-approved release readiness readback、owner release approval gate 與 post-release verifier / rollback gate。下一步是 `P2-133`;外部 registry / package source / host probe / SSH / kubectl / 工具安裝 / CI 變更 / 實際 PR creation / Telegram 實發與 learning write 仍需 gate。 diff --git a/docs/superpowers/specs/2026-04-15-MASTER-ai-autonomous-flywheel-v2.md b/docs/superpowers/specs/2026-04-15-MASTER-ai-autonomous-flywheel-v2.md index 21e1df46..080b00f8 100644 --- a/docs/superpowers/specs/2026-04-15-MASTER-ai-autonomous-flywheel-v2.md +++ b/docs/superpowers/specs/2026-04-15-MASTER-ai-autonomous-flywheel-v2.md @@ -669,7 +669,7 @@ Alert / Sentry / SigNoz / Gitea / Market Watch / Operator | `docs/evaluations/ai_agent_result_capture_owner_approved_preflight_release_package_2026-06-14.json` + `GET /api/v1/agents/agent-result-capture-owner-approved-preflight-release-package` | P2-129 owner-approved preflight release package;承接 P2-128 owner acceptance readback / live-apply preflight hold,建立 5 個 owner-approved release package、5 個 release preflight check、5 個 live-apply release gate、5 個 rollback release check、6 個 blocked release transition 與 5 個 operator action;runtime authority 固定 `result_capture_owner_approved_preflight_release_package_only_no_live_write`;owner release approved、maintenance window approved、rollback owner confirmed、post-release verifier ready、live apply release passed、writer apply、execution apply、receipt write、canonical runtime target read、live query、reviewer queue write、Gateway queue write、Telegram send、Bot API call、report receipt write、result capture write、learning write、PlayBook trust write、production write、secret read 與 destructive action 全部 `0 / false`;deploy marker `7e5b4793` 已正式驗證,已由 P2-130 承接 | | `docs/evaluations/ai_agent_result_capture_owner_approved_release_readiness_readback_2026-06-14.json` + `GET /api/v1/agents/agent-result-capture-owner-approved-release-readiness-readback` | P2-130 owner-approved release readiness readback;承接 P2-129 owner-approved preflight release package,建立 5 個 release readiness readback、5 個 owner release readiness check、5 個 live-apply readiness gate、5 個 rollback readiness check、6 個 blocked readiness transition 與 5 個 operator action;runtime authority 固定 `result_capture_owner_approved_release_readiness_readback_only_no_live_write`;owner release approved、maintenance window approved、rollback owner confirmed、post-release verifier ready、release readiness passed、live apply release passed、writer apply、execution apply、receipt write、canonical runtime target read、live query、reviewer queue write、Gateway queue write、Telegram send、Bot API call、report receipt write、result capture write、learning write、PlayBook trust write、production write、secret read 與 destructive action 全部 `0 / false`;deploy marker `6fcf7241` 已正式驗證,下一步 P2-131 | | `docs/evaluations/ai_agent_result_capture_owner_release_approval_gate_2026-06-14.json` + `GET /api/v1/agents/agent-result-capture-owner-release-approval-gate` | P2-131 owner release approval gate;承接 P2-130 owner-approved release readiness readback,建立 5 個 owner release approval packet、5 個 maintenance window approval gate、5 個 live-apply release approval gate、5 個 rollback owner approval check、6 個 blocked approval transition 與 5 個 operator action;runtime authority 固定 `result_capture_owner_release_approval_gate_only_no_live_write`;owner release approved、maintenance window approved、rollback owner confirmed、post-release verifier ready、release approval passed、live apply release passed、writer apply、execution apply、receipt write、canonical runtime target read、live query、reviewer queue write、Gateway queue write、Telegram send、Bot API call、report receipt write、result capture write、learning write、PlayBook trust write、production write、secret read 與 destructive action 全部 `0 / false`;deploy marker `03617db7` 已正式驗證,已由 P2-132 承接 | -| `docs/evaluations/ai_agent_result_capture_post_release_verifier_rollback_gate_2026-06-14.json` + `GET /api/v1/agents/agent-result-capture-post-release-verifier-rollback-gate` | P2-132 post-release verifier / rollback gate;承接 P2-131 owner release approval gate,建立 5 個 post-release verifier gate、5 個 rollback release gate、5 個 release verification hold、5 個 live-apply post-release gate、6 個 blocked post-release transition 與 5 個 operator action;runtime authority 固定 `result_capture_post_release_verifier_rollback_gate_only_no_live_write`;owner release approved、maintenance window approved、rollback owner confirmed、post-release verifier ready、release verification passed、rollback release passed、live apply release passed、writer apply、execution apply、receipt write、canonical runtime target read、live query、reviewer queue write、Gateway queue write、Telegram send、Bot API call、report receipt write、result capture write、learning write、PlayBook trust write、production write、secret read 與 destructive action 全部 `0 / false`;本地測試 / build / guard 已通過,正式 CD 與 production smoke 待推進,下一步 P2-133 | +| `docs/evaluations/ai_agent_result_capture_post_release_verifier_rollback_gate_2026-06-14.json` + `GET /api/v1/agents/agent-result-capture-post-release-verifier-rollback-gate` | P2-132 post-release verifier / rollback gate;承接 P2-131 owner release approval gate,建立 5 個 post-release verifier gate、5 個 rollback release gate、5 個 release verification hold、5 個 live-apply post-release gate、6 個 blocked post-release transition 與 5 個 operator action;runtime authority 固定 `result_capture_post_release_verifier_rollback_gate_only_no_live_write`;owner release approved、maintenance window approved、rollback owner confirmed、post-release verifier ready、release verification passed、rollback release passed、live apply release passed、writer apply、execution apply、receipt write、canonical runtime target read、live query、reviewer queue write、Gateway queue write、Telegram send、Bot API call、report receipt write、result capture write、learning write、PlayBook trust write、production write、secret read 與 destructive action 全部 `0 / false`;deploy marker `934af770` 已正式驗證,下一步 P2-133 | | `docs/evaluations/ai_agent_live_read_model_gate_2026-06-11.json` + `GET /api/v1/agents/agent-live-read-model-gate` | P2-403B AgentSession / Redis Streams live read model gate;定義 safe fields、Redis envelope、worker gate、rollback plan 與 no-write smoke,不連 DB、不讀寫 Redis、不啟動 worker | #### 3.2.1c 2026-06-11 AI Agent 主動營運委派與版本生命週期契約 @@ -790,7 +790,7 @@ Repo / registry / release notes / K8s / host / observability / backup evidence 50. 建立 owner-approved preflight release package。✅ P2-129 已完成並正式驗證;owner-approved release package `5`、release preflight check `5`、live-apply release gate `5`、rollback release check `5`、blocked release transition `6`、operator action `5`,approval-required package / preflight / release gate / rollback `2 / 2 / 2 / 2`、blocked package / preflight / release gate / rollback `1 / 1 / 1 / 1`、critical blocker `5`;owner release approved、maintenance window approved、rollback owner confirmed、post-release verifier ready、live apply release passed、writer apply、execution apply、receipt write、reviewer queue write、Gateway queue write、Telegram send、Bot API call、report receipt write、result capture write、learning write、PlayBook trust write、production write 仍為 `0 / false`;deploy marker `7e5b4793`、正式 API readback 與 desktop / mobile smoke 已完成。已由 P2-130 承接。 51. 建立 owner-approved release readiness readback。✅ P2-130 已完成並正式驗證;release readiness readback `5`、owner release readiness check `5`、live-apply readiness gate `5`、rollback readiness check `5`、blocked readiness transition `6`、operator action `5`,approval-required readback / owner check / readiness gate / rollback `2 / 2 / 2 / 2`、blocked readback / owner check / readiness gate / rollback `1 / 1 / 1 / 1`、critical blocker `5`;owner release approved、maintenance window approved、rollback owner confirmed、post-release verifier ready、release readiness passed、live apply release passed、writer apply、execution apply、receipt write、reviewer queue write、Gateway queue write、Telegram send、Bot API call、report receipt write、result capture write、learning write、PlayBook trust write、production write 仍為 `0 / false`;deploy marker `6fcf7241`、正式 API readback 與 desktop / mobile smoke 已完成。已由 P2-131 承接。 52. 建立 owner release approval gate。✅ P2-131 已完成並正式驗證;owner release approval packet `5`、maintenance window approval gate `5`、live-apply release approval gate `5`、rollback owner approval check `5`、blocked approval transition `6`、operator action `5`,approval-required packet / maintenance / live apply / rollback `2 / 2 / 2 / 2`、blocked packet / maintenance / live apply / rollback `1 / 1 / 1 / 1`、critical blocker `5`;owner release approved、maintenance window approved、rollback owner confirmed、post-release verifier ready、release approval passed、live apply release passed、writer apply、execution apply、receipt write、reviewer queue write、Gateway queue write、Telegram send、Bot API call、report receipt write、result capture write、learning write、PlayBook trust write、production write 仍為 `0 / false`;deploy marker `03617db7`、正式 API readback 與 desktop / mobile smoke 已完成。已由 P2-132 承接。 -53. 建立 post-release verifier / rollback gate。🟡 P2-132 已本地完成,正式驗證待推進;post-release verifier gate `5`、rollback release gate `5`、release verification hold `5`、live-apply post-release gate `5`、blocked post-release transition `6`、operator action `5`,approval-required verifier / rollback / verification / live apply `2 / 2 / 2 / 2`、blocked verifier / rollback / verification / live apply `1 / 1 / 1 / 1`、critical blocker `5`;owner release approved、maintenance window approved、rollback owner confirmed、post-release verifier ready、release verification passed、rollback release passed、live apply release passed、writer apply、execution apply、receipt write、reviewer queue write、Gateway queue write、Telegram send、Bot API call、report receipt write、result capture write、learning write、PlayBook trust write、production write 仍為 `0 / false`;本地 API/service regression、typecheck、production build 與 guard 已完成。正式 API readback 與 desktop / mobile smoke 完成後才可由 P2-133 承接。 +53. 建立 post-release verifier / rollback gate。✅ P2-132 已完成並正式驗證;post-release verifier gate `5`、rollback release gate `5`、release verification hold `5`、live-apply post-release gate `5`、blocked post-release transition `6`、operator action `5`,approval-required verifier / rollback / verification / live apply `2 / 2 / 2 / 2`、blocked verifier / rollback / verification / live apply `1 / 1 / 1 / 1`、critical blocker `5`;owner release approved、maintenance window approved、rollback owner confirmed、post-release verifier ready、release verification passed、rollback release passed、live apply release passed、writer apply、execution apply、receipt write、reviewer queue write、Gateway queue write、Telegram send、Bot API call、report receipt write、result capture write、learning write、PlayBook trust write、production write 仍為 `0 / false`;deploy marker `934af770`、正式 API readback 與 desktop / mobile smoke 已完成。下一步 P2-133。 #### 3.2.1d 2026-06-11 Agent 互動、學習與成長證據面 @@ -2111,15 +2111,19 @@ Phase 6 完成後 - 政策裁決:P2-126 只允許 owner-approved execution rehearsal、no-write apply check、post-write verifier rehearsal、rollback drill、blocked live apply 與 operator handoff 可視化;不得把 rehearsal 解讀成 owner approval record 已收、no-write apply 已執行、writer apply、execution apply、receipt write、result capture write、learning write、PlayBook trust write、reviewer queue write、Gateway queue write、Telegram 實發、Bot API 呼叫、report receipt write 或 live writer 已啟用。 - 本波仍不讀 canonical runtime target、不做 live query、不寫 reviewer queue、不寫 Gateway queue、不送 Telegram、不呼叫 Bot API、不寫 report receipt、不寫 result capture、不寫 learning、不更新 PlayBook trust、不寫 production target、不讀 secret、不執行 destructive action、不回傳內部協作內容;已由 P2-127 承接。 -### 2026-06-14 07:46 (台北) — §3.2 / §5 — 本地完成 P2-132 post-release verifier / rollback gate — 把 release approval 轉成釋出後驗證與 rollback hold +### 2026-06-14 07:48 (台北) — §3.2 / §5 — 完成並正式驗證 P2-132 post-release verifier / rollback gate — 把 release approval 轉成釋出後驗證與 rollback hold - 新增 `ai_agent_result_capture_post_release_verifier_rollback_gate_v1` schema / committed snapshot / loader / API / 測試,承接 P2-131 owner release approval gate,定義 5 個 post-release verifier gate、5 個 rollback release gate、5 個 release verification hold、5 個 live-apply post-release gate、6 個 blocked post-release transition 與 5 個 operator action。 - Governance automation inventory 新增 P2-132 區塊,將 post-release verifier gate、rollback release gate、release verification hold、live-apply post-release gate、blocked post-release transition 與 operator action 全部以只讀方式呈現。 - 本地 API/service regression:P2-132 + P2-131 `14 passed`;JSON parse、Python 3.11 py_compile、`pnpm --filter @awoooi/web typecheck` 與 production build 通過;`git diff --check`、`doc-secrets-sanity-check.py docs .gitea`、`source-control-owner-response-guard.py --root .`、`security-mirror-progress-guard.py --root .` 通過。 - 本地 snapshot 固定 `schema_version=ai_agent_result_capture_post_release_verifier_rollback_gate_v1`、current `P2-132`、next `P2-133`、completion `100`;post-release verifier gate `5`、rollback release gate `5`、release verification hold `5`、live-apply post-release gate `5`、blocked post-release transition `6`、operator action `5`、approval-required verifier / rollback / verification / live apply `2 / 2 / 2 / 2`、blocked verifier / rollback / verification / live apply `1 / 1 / 1 / 1`、critical blocker `5`。 +- 正式部署:feature commit `040c320c` 推送後,首次 CD `#2916` tests 成功但 build-and-deploy / post-deploy checks 長時間停在 required conditions;已以無行為變更 `apps/**` 錨點 commit `333731e5` 重新觸發 CD,deploy marker `934af770` 回寫並部署。 +- Gitea Actions:`#2919` ai-code-review 成功;`#2918` CD tests、build-and-deploy、post-deploy-checks 成功。 +- 正式 API readback:`schema_version=ai_agent_result_capture_post_release_verifier_rollback_gate_v1`、current `P2-132`、next `P2-133`、completion `100`、runtime authority `result_capture_post_release_verifier_rollback_gate_only_no_live_write`;post-release verifier gate `5`、rollback release gate `5`、release verification hold `5`、live-apply post-release gate `5`、blocked post-release transition `6`、operator action `5`、正式寫入 / 發送 `0`。 +- 正式 desktop / mobile smoke:P2-132 區塊與必要數字皆可見;禁用內部協作片語 `0`、水平溢位 `0`、P2-132 高風險控制 `0`、console error `0`、API bad response `0`、actionable request failure `0`。 - 本地 0 / false 邊界:owner release approved、maintenance window approved、rollback owner confirmed、post-release verifier ready、release verification passed、rollback release passed、live apply release passed、writer apply、execution apply、receipt write、reviewer queue write、Gateway queue write、Telegram send、Bot API call、report receipt write、result capture write、learning write、PlayBook trust write、production write、secret read 與 destructive operation 均為 `0 / false`。 - 政策裁決:P2-132 只允許 post-release verifier / rollback gate 可視化;不得把 verifier gate 解讀成 post-release verifier ready、release verification passed、rollback release passed、live apply release passed、writer apply、execution apply、receipt write、result capture write、learning write、PlayBook trust write、reviewer queue write、Gateway queue write、Telegram 實發、Bot API 呼叫、report receipt write 或 live writer 已啟用。 -- 本波仍不讀 canonical runtime target、不做 live query、不寫 reviewer queue、不寫 Gateway queue、不送 Telegram、不呼叫 Bot API、不寫 report receipt、不寫 result capture、不寫 learning、不更新 PlayBook trust、不寫 production target、不讀 secret、不執行 destructive action、不回傳內部協作內容;正式 CD / production API / desktop mobile smoke 通過後才可由 P2-133 承接。 +- 本波仍不讀 canonical runtime target、不做 live query、不寫 reviewer queue、不寫 Gateway queue、不送 Telegram、不呼叫 Bot API、不寫 report receipt、不寫 result capture、不寫 learning、不更新 PlayBook trust、不寫 production target、不讀 secret、不執行 destructive action、不回傳內部協作內容;下一步 P2-133。 ### 2026-06-14 07:08 (台北) — §3.2 / §5 — 完成並正式驗證 P2-131 owner release approval gate — 把 readiness 轉成可審核批准門檻