From a0d38af4f1957caebfd7bf42d419265402ab5748 Mon Sep 17 00:00:00 2001 From: ogt Date: Thu, 23 Jul 2026 09:22:46 +0800 Subject: [PATCH] docs(ai): record V10.816 runtime closure --- docs/AI_INTELLIGENCE_MODULE_SOT.md | 16 ++++++++-------- docs/guides/ai_automation_mainline_work_items.md | 14 +++++++------- 2 files changed, 15 insertions(+), 15 deletions(-) diff --git a/docs/AI_INTELLIGENCE_MODULE_SOT.md b/docs/AI_INTELLIGENCE_MODULE_SOT.md index 2128be3..84857f2 100644 --- a/docs/AI_INTELLIGENCE_MODULE_SOT.md +++ b/docs/AI_INTELLIGENCE_MODULE_SOT.md @@ -1,21 +1,21 @@ # PChome 業績成長自動化作戰系統 — AI 競價情報模組 Single Source of Truth -> **最後更新**: 2026-07-22 (台北時間) -> **狀態**: 🟠 Partial。Production runtime 是 V10.815、exact Gitea object `283c8c80c631f5d97315708885413b62ee5a34ea`;Windows 99 controlled run `736e6de1-fbc3-4c9b-bcfe-9b6ef488b932` 已完成 `36/36` source hash、`12/12` runtime env、三應用健康與 `momo-db` identity unchanged 的獨立讀回。PixelRAG receipt -> BGE-M3 -> pgvector no-write canary 已通過,但 `RAG_ENABLED=false` 與 embedding redundancy degraded 仍阻擋 activation。GCP-A 仍不可達;GCP-B exact-digest `qwen3:14b` chat 逾時,較小的 `qwen2.5:7b-instruct` 亦逾時,證明問題包含共享 CPU/queue,而非只靠換小模型即可解決。111 exact-digest `qwen3:8b` decision-only probe 於 `19.053s` 通過。V10.816 source candidate 已把這份實證接成 model-aware、bounded、exact-digest 的 GCP-A -> GCP-B -> 111 fallback;尚未完成本版 production deploy/readback 前,不得宣稱正式 runtime 已採用。 -> **適用版本**: V10.815 production runtime;V10.816 source candidate;AI Agent/MCP/RAG full product integration remains partial +> **最後更新**: 2026-07-23 (台北時間) +> **狀態**: 🟠 Partial。Production runtime 是 V10.816、exact Gitea runtime marker `2757585e5e3455e96c743ddfd82d59304f32c3f0`。Windows 99 controlled run `1b335e97-fa31-418b-b925-759bc1036267` 已完成 `20/20` changed-source hash、`30/30` runtime env、三應用健康、`momo-db` identity unchanged、獨立 verifier 與公開 readback。PixelRAG receipt -> exact-digest BGE-M3 -> read-only pgvector canary 實際通過,但 `RAG_ENABLED=false` 仍阻擋 activation。NemoTron 實際走完 GCP-A -> GCP-B -> 111 三候選,由 111 exact-digest `qwen3:8b` 回傳合法 decision envelope,狀態為 `canary_passed_degraded_fallback`;工具、DB、價格、insight 與 Telegram 執行數皆為零。完整 AI Agent/MCP/RAG 產品閉環仍未完成,GCP 容量、RAG activation、MCP runtime 與業績 outcome telemetry 都必須繼續列為缺口。 +> **適用版本**: V10.816 production runtime;AI Agent/MCP/RAG full product integration remains partial --- -## 零之負五、AI Agent 產品整合 truth 與 internal RAG/NemoTron canary(V10.815 production / V10.816 source) +## 零之負五、AI Agent 產品整合 truth 與 internal RAG/NemoTron canary(V10.816 production) - `/api/ai-automation/agent-product-integration` 與 `scripts/ops/report_ai_agent_product_integration.py` 分開輸出四 Agent source/scheduler wiring、七日 `ai_calls` 實際呼叫與錯誤率、MCP/RAG telemetry、action plan/outcome、AutoHeal incident retry,以及九階段 closure。只有四 Agent 全部有健康 runtime、MCP/RAG 已啟用且有 telemetry、internal RAG canary 已通過、受控執行/驗證/重試/學習都有實證時才可回 `fully_integrated`。 - `/api/ai-automation/internal-rag-candidate-canary` 只有 GET,永遠是 no-model/no-DB-write readback;production execute 由 `momo-scheduler` 每日 04:45 自動跑一次。V10.815 production 已使用先由 Ollama `/api/tags` 驗證 manifest digest、再以 canary 專用 `150s` timeout 容納 GCP-B 冷啟動的契約;一般 embedding 呼叫仍保留既有短 timeout cap,不把所有 request 放大成 150 秒。至少一台核准 GCP host 必須同時通過 digest 與 1024 維 embedding,111 不可形成 quorum;單一 GCP 可進 degraded read-only pgvector shadow probe,但 `rag_embedding_redundancy_degraded` 仍阻擋正式 activation。 - RAG canary 不 INSERT/UPDATE `ai_insights`、`competitor_prices`、`external_offers` 或任何正式價格表;artifact 與 scheduler receipt 共用 `trace_id/run_id/work_item_id`,明確輸出 `transaction_read_only`、similarity、embedding signature、expected/observed digest、GCP reachability、Telegram acknowledgement 與 zero-write/rollback terminal。digest drift、零核准 GCP host、向量維度錯誤、pgvector probe 失敗或 semantic threshold 未達都必須 fail closed。 - `bge-m3:latest` 只可在 expected digest gate 下使用:source contract 固定 digest,runtime 每次 canary 由 `/api/tags` 比對,漂移時在 embedding/DB 前阻擋。Ollama 官方 `/api/tags` 明確提供模型 `digest`,因此 immutable contract 使用「固定 expected digest + runtime verifier」,不是只信任 floating tag。MCP runtime 仍受 localhost-only、read-only tool contract 與 required secret presence preflight 約束,不可因 registry 已存在就宣稱上線。 -- V10.815 production 提供 `/api/ai-automation/nemotron-decision-canary`、`scripts/ops/run_nemotron_decision_canary.py` 與每日 05:00 scheduler lane。V10.816 source 將 production dispatcher 與 canary 共用 `services/nemotron_runtime_candidate_service.py`:GCP-A/GCP-B 必須使用 exact-digest `qwen3:14b`,每台 chat 最多 60 秒;最終 111 fallback 必須使用 exact-digest `qwen3:8b`,最多 45 秒並固定 `num_ctx=4096`、`num_predict=512`,所有 payload 固定 `think=false`。Production Ollama + NIM 共用單一 180 秒 monotonic deadline,canary 的 `timeout_sec` 也是整次執行上限,不再對每個候選重新計時。每次呼叫前後都驗證 digest;畸形 `/api/tags` payload/model/details schema 必須 fail closed 並轉下一候選,不能中斷 fallback。實際 model/provider/host/fallback/attempts 必須進 logger、通知 footprint 與 receipt。 +- V10.816 production 提供 `/api/ai-automation/nemotron-decision-canary`、`scripts/ops/run_nemotron_decision_canary.py` 與每日 05:00 scheduler lane,且 production dispatcher 與 canary 共用 `services/nemotron_runtime_candidate_service.py`:GCP-A/GCP-B 必須使用 exact-digest `qwen3:14b`,每台 chat 最多 60 秒;最終 111 fallback 必須使用 exact-digest `qwen3:8b`,最多 45 秒並固定 `num_ctx=4096`、`num_predict=512`,所有 payload 固定 `think=false`。Production Ollama + NIM 共用單一 180 秒 monotonic deadline,canary 的 `timeout_sec` 也是整次執行上限,不再對每個候選重新計時。每次呼叫前後都驗證 digest;畸形 `/api/tags` payload/model/details schema 必須 fail closed 並轉下一候選,不能中斷 fallback。實際 model/provider/host/fallback/attempts 必須進 logger、通知 footprint 與 receipt。 - 模型輸出必須在選定候選前通過 deterministic tool contract:工具在 allowlist、必要欄位與型別正確、SKU 必須來自本次輸入、每個 SKU 恰好一個 call 且全數覆蓋。Production 去重使用 `services/nemotron_dispatch_reservation_service.py` 在三容器共用 `/app/data` 上執行 `flock`、file fsync、atomic replace 與 parent-directory fsync 的 process/container-shared ownership-token store;state 只保存 SHA-256 SKU key、owner token、phase 與 expiry,不保存商品名稱或原始資料。In-flight lease 必須涵蓋最大模型 deadline;每個 handler 前須由原 owner 原子寫入 `side_effect_started` 並切換為四小時 crash quarantine,寫入失敗就不得執行副作用。舊 token 不可 release/commit 新 owner,state/lock 無法讀寫、schema 損壞或平台缺少 process-shared lock 時 fail closed。本地非 production 測試才使用記憶體 backend。告警工具必須有 EventRouter delivered/durable-queue acknowledgement,推薦工具必須有 DB write 或 durable notification,KM 工具必須有持久化 insight,才可提交四小時 TTL;若 durable side effect 已完成但 dedupe commit 未驗證,結果仍按已派發計數、輸出 `dedupe_commit_unverified`,並保留 quarantine,絕不可 release 後重送。模型契約錯誤、reservation ownership lost、boundary 未建立或 handler 未回 durable outcome 時才 release 自己持有的 lease。程序若在 boundary 後、side effect 前崩潰,最多抑制該 SKU 四小時;這是避免重複通知/寫入的 at-most-once 取捨,必須由 receipt/告警揭露而非靜默重試。 - Decision-only canary 只產生 synthetic decision,並共用 production `_validate_tool_call_contract()` 驗證完整 call set,不可只看第一筆;多餘、重複、未知、缺欄位或未綁定 SKU 的 call 都必須 fail closed。Canary 同時驗證 post-call digest,固定 `tool_execution_count=0`、`database_call_performed=false`、`writes_price_tables=false`、`writes_ai_insights=false`、`telegram_sent=false`。使用 111 成功時狀態必須是 `canary_passed_degraded_fallback`,不能偽裝成 GCP healthy;scheduler 只在 model canary 後發生命週期 acknowledgement 並原子回寫 receipt。111 的 `num_ctx=4096`、`num_predict=512` 是不可被 env 弱化的固定 NemoTron 契約;候選失敗鏈只輸出 label/tier/model/status/digest-match/error-class 的 privacy-safe footprint。 -- `AI Agent product integration truth` 會讀取 fresh NemoTron decision-only receipt;這份 shadow canary能證明模型決策路徑真的執行,但不能冒充正式商品 action、agent outcome 或完整 Controlled Apply。V10.816 的 source/test 綠燈仍需 production deploy、fresh degraded-fallback receipt 與獨立 readback 才能提升 runtime 狀態。 +- `AI Agent product integration truth` 會讀取 fresh NemoTron decision-only receipt;這份 shadow canary 能證明模型決策路徑真的執行,但不能冒充正式商品 action、agent outcome 或完整 Controlled Apply。V10.816 run `1b335e97-fa31-418b-b925-759bc1036267` 已取得 fresh degraded-fallback receipt 與獨立零寫入 readback,因此 model-aware dispatcher 可標記為 production verified;四 Agent 業績 outcome、MCP runtime 與 RAG activation 仍保持 partial。 - V10.812 起四 Agent activity 依角色證據判定:Hermes/OpenClaw 仍以實際 `ai_calls` 為主,NemoTron 可加入其派發/insight durable evidence,ElephantAlpha 可由其 `ai_insights`/action plan 證明 active;沒有成功 call 或 verified executed action 時只能是 `runtime_active_unverified`,不得把 deterministic artifact 數量包裝成 healthy integration。 --- @@ -61,7 +61,7 @@ - `services/security_governance_review_service.py`、`scripts/ops/report_security_governance_review.py` 與 `/api/ai-automation/security-governance-review` 提供 machine-readable checks、completion、release gate 與 ordered work items。 - Gitea CD 必須執行 `report_security_governance_review.py --strict`,且不得解析 GitHub action/source/image。 - production 安全與治理完成度必須分開顯示 program、asset coverage、runtime closure;目前結論是 partial,不是 complete。 -- 目前 ordered P0 以 `docs/guides/ai_automation_mainline_work_items.md` 為準:SEC-P0-001 access exposure 已關閉,current P0 是 identity/RBAC,之後依序為 webhook trust、supply chain、asset reconciliation、controlled-apply envelope、internal RAG canary 與 MCP/RAG runtime closure。 +- 目前 ordered P0 只以 `docs/guides/ai_automation_mainline_work_items.md` 為準;current P0 是 `GROWTH-P0-001 comparison coverage truth + autonomous refresh`,安全、治理、RAG/MCP 與 release 缺口依該表固定次序推進,不得用單一 canary 或 source-ready 狀態改寫優先順序。 - V10.786 起 `/metrics` 不再是 public exception;應用中央政策與 Nginx exact-match edge policy 僅允許 loopback / Docker transport,Prometheus 必須以內部 canary 證明 target `up`,且 public/LAN readback 必須拒絕。監控 Compose 不得保存明文 Grafana 管理密碼,Prometheus 對外埠預設只綁 loopback。 - V10.787 依 live ingress 修正 metrics transport:production ingress 實際位於 188,110 global Prometheus 只能經專用 `172.20.0.1:19191` Docker-only Nginx bridge 抓取;bridge 以系統 CA、`mo.wooo.work` SNI/Host 轉送至 188,應用僅額外允許 `192.168.0.110/32` 單一監控主機,不得放行整段 LAN,也不得把 110 的其他 vhost 誤當 EwoooC production ingress。controlled apply 支援新 include 建立、Prometheus bind-mount reconciliation、`momo_app_info`/health/database product marker canary、精確 scrape URL、worker reload convergence 與失敗自動移除/回滾;production 已讀回 public 404、internal 200、target up、Prometheus identity preserved、8/8 anonymous matrix 與 `momo-db` unchanged,證據在 `governance/evidence/SEC-P0-001-20260711T122758Z.json`。 - V10.788 把既有 `users/login_history/user_permissions` 正式接入登入:`auto` 模式先以 hybrid 維持回滾能力,只計 active admin 的 database-auth success durable receipts,預設連續兩次後自動轉為 database-only;legacy shared Session 下一次請求自動撤銷。鎖定改由 `login_history` 跨 worker 持久化,Session 綁定 password/role/active identity version,中央 policy 區分 read/operate/admin,且只有 allowlisted direct proxy peer 才能提供 `X-Forwarded-For/X-Real-IP`。帳號建立、身份更新、密碼變更、停用與權限異動會在同一交易寫入不含密碼的 audit event,commit 失敗時兩者一併 rollback。`/api/auth/governance` 與 `report_auth_identity_governance.py` 僅輸出非機密 readback;source ready 不等於 production cutover completed。 @@ -283,7 +283,7 @@ SQL漏斗(~300筆) | 角色 | 模型 | 主機 | 成本 | 每日限額 | |------|------|------|------|---------| | Hermes 分析師 | hermes3:latest / bge-m3 | GCP-A → GCP-B → 111 Ollama | 零 | 無限 | -| NemoTron 派發器 | qwen3:14b;111 fallback 降級 llama3.2;NIM fallback | GCP-A → GCP-B → 111;NVIDIA NIM 備援 | Ollama 零;NIM 配額內免費 | NIM 80 | +| NemoTron 派發器 | GCP exact-digest qwen3:14b;111 exact-digest qwen3:8b;NIM fallback | GCP-A → GCP-B → 111;NVIDIA NIM 備援 | Ollama 零;NIM 配額內免費 | NIM 80 | | OpenClaw 策略師 | qwen2.5-coder:7b / qwen3:14b;111 fallback 降級 llama3.2 | Ollama-first;Gemini emergency fallback only | Ollama 零;Gemini 預設封鎖 | — | | ElephantAlpha 編排者 | ElephantAlpha | 依部署環境 | 受控 | AI 例外決策 / 任務制 | diff --git a/docs/guides/ai_automation_mainline_work_items.md b/docs/guides/ai_automation_mainline_work_items.md index a7b4aa7..48a7080 100644 --- a/docs/guides/ai_automation_mainline_work_items.md +++ b/docs/guides/ai_automation_mainline_work_items.md @@ -1,6 +1,6 @@ # AI Automation Mainline Work Items -> Updated: 2026-07-22 Asia/Taipei +> Updated: 2026-07-23 Asia/Taipei > Governance: `global_product_governance_v2` + ADR-038 > Current P0: `GROWTH-P0-001 comparison coverage truth + autonomous refresh` @@ -23,10 +23,10 @@ | 5 | `SUPPLY-P0-001` | In progress | Gitea-only secure software supply chain | Gitea-native checkout, secret-safe `.dockerignore`, commit-bound source receipt and governance gate are active. Exit: exact dependency lock, internal SAST/SCA/secret scan, SBOM, image digest/provenance, vulnerability SLA and production digest readback. | | 6 | `GOV-P0-001` | In progress | Canonical full asset graph + runtime reconciliation | `governance/ewoooc_asset_inventory.json` seeds hosts, services, data, AI, routes, supply chain, observability and recovery. Exit: same-run probe receipt for every asset; drift auto-creates work items. | | 7 | `GOV-P0-002` | Not started | Unified controlled-apply envelope | Introduce one `trace_id/run_id/work_item_id` across sensor, identity, SOT diff, decision, risk, dry-run, execution, verifier, rollback/retry and learning acknowledgement. Start with EventRouter + AutoHeal. | -| 8 | `RAG-P0-001` | In progress (`rag_canary_passed_nemotron_fallback_source_ready`) | Internal RAG candidate canary + NemoTron decision-only proof | V10.815 production run `736e6de1-fbc3-4c9b-bcfe-9b6ef488b932` passed PixelRAG receipt -> exact-digest BGE-M3 -> read-only pgvector canary with zero business writes; activation remains correctly blocked by `RAG_ENABLED=false` and degraded embedding redundancy. GCP-A is unreachable; GCP-B exact-digest `qwen3:14b` chat timed out at 300s and `qwen2.5:7b-instruct` at 240s, while 111 exact-digest `qwen3:8b` produced the required tool call in 19.053s with no tool/DB/Telegram execution. V10.816 source now implements exact-digest GCP-A -> GCP-B -> 111 model-aware fallback with one 180-second production deadline, bounded 111 context/output, deterministic one-call-per-SKU tool validation, truthful failure footprints and a process-shared `side_effect_started` boundary. Durable side effects remain quarantined for four hours even when dedupe commit verification fails, including mixed forced-review/model batches, so app/scheduler/bot cannot reopen the same SKU and duplicate the action;mixed-path dispatched/skipped metrics preserve input-count truth. Focused model/dedupe regression is `93 passed`. Next: deploy V10.816, obtain shared-store and fresh production `canary_passed_degraded_fallback` receipts plus independent zero-write readback; then restore GCP capacity/redundancy before controlled `RAG_ENABLED` shadow activation and query/hit/feedback telemetry. | +| 8 | `RAG-P0-001` | In progress (`runtime_verified_degraded_fallback_activation_blocked`) | Internal RAG candidate canary + NemoTron decision-only proof | V10.816 is live at exact runtime marker `2757585e5e3455e96c743ddfd82d59304f32c3f0`. Windows 99 run `1b335e97-fa31-418b-b925-759bc1036267` verified PixelRAG receipt -> exact-digest BGE-M3 -> read-only pgvector with `ready_count=1`, `canary_passed_activation_blocked` and zero business writes. The same run exercised all three bounded NemoTron candidates and returned `canary_passed_degraded_fallback` from 111 exact-digest `qwen3:8b`; model identity, deterministic one-call-per-SKU envelope and zero tool/DB/price/insight/Telegram execution passed. App and scheduler independently passed the shared reservation canary, cross-container visibility passed, and the four-hour `side_effect_started` quarantine is active. Final terminal: `v10816_source_runtime_rag_nemotron_verified_no_db_mutation`. Next: restore GCP-A reachability and GCP-B bounded inference capacity, then run controlled `RAG_ENABLED` shadow activation with query/hit/feedback telemetry before any formal product write. | | 9 | `MCP-P0-001` | In progress (`federation_source_ready`) | MCP/RAG production runtime closure | V10.796 source adds a strict public aggregate receipt for canonical `ewoooc` and `momo-pro-system` identities without opening authenticated internal APIs or exposing endpoint/tool payload data. Exit still requires V10.796 production `/health`, two fresh AWOOOI durable receipts with fingerprint recompute, live MCP servers/router/RAG, approved caller/tool boundary and production query canary. Current source readiness must not be reported as runtime closure. | | 10 | `SEC-P0-004` | Not started | Security operations lifecycle and metrics | Add durable security incident state and publish MTTA, MTTR, recurrence, false positive, human intervention, verifier pass, rollback and freshness. Exit: detect-to-learn production receipt. | -| 11 | `REL-P0-001` | In progress (`v10815_runtime_verified_v10816_pending`) | Formal deploy and visible proof discipline | Production V10.815 runs exact Gitea object `283c8c80c631f5d97315708885413b62ee5a34ea`; dev merge `df83c646cdb3fde5e33f045bff19c5a392f84b86` has an identical tree. Host 110 still has no matching EwoooC runner, so formal CD remains unavailable and is not replaced by fallback evidence. Windows 99 controlled run `736e6de1-fbc3-4c9b-bcfe-9b6ef488b932` corrected and deployed the complete 36-file source set, verified `36/36` hashes and `12/12` runtime env checks, recreated only app/scheduler/bot, and left `momo-db` identity unchanged; rollback is retained at `/home/ollama/momo-deploy-backups/ewoooc-20260722T115155Z-283c8c8-full-736e6de1`. Internal/external `/health` is healthy at V10.815 and public JS/CSS match the tested hashes. V10.816 remains source-only until Gitea integration plus a new Windows 99 controlled deployment and independent runtime readback complete. | +| 11 | `REL-P0-001` | In progress (`v10816_runtime_verified_cd_runner_gap`) | Formal deploy and visible proof discipline | Production V10.816 runs exact Gitea runtime marker `2757585e5e3455e96c743ddfd82d59304f32c3f0`; its runtime tree was integrated to `main`, feature branch and `dev` before controlled deployment. Windows 99 run `1b335e97-fa31-418b-b925-759bc1036267` verified `20/20` changed source hashes and `30/30` runtime env contracts, recreated only app/scheduler/bot, preserved `momo-db`, passed independent runtime/public readback and finalized the RAG/NemoTron canaries. Rollback is retained at `/home/ollama/momo-deploy-backups/ewoooc-20260723T011250Z-2757585-v10816-1b335e97`; public `/health` reports V10.816 and the exact sales-analysis URL reaches the normal `/login` boundary. Host 110 still lacks a matching EwoooC runner, so formal Gitea CD remains an explicit gap rather than being conflated with the verified Windows 99 release. | ### GROWTH-P0-001 Fixed Execution Lanes @@ -45,8 +45,8 @@ This is an acceptance surface inside the current growth P0; it does not reorder | Layer | Current status | Exit evidence | |---|---|---| | Source and scheduler wiring | Source ready (`4/4`) | Hermes, NemoTron, OpenClaw and ElephantAlpha source markers plus scheduler ownership are machine-read and reported separately from runtime. | -| Agent runtime activity | Production partial; V10.816 bounded fallback source ready | V10.815 runtime proved the RAG no-write lane and separately proved 111 `qwen3:8b` can execute the NemoTron tool contract in 19.053s, but production dispatcher does not use that model-aware fallback until V10.816 is deployed. A fresh decision-only pass proves shadow model execution only, not formal product action. Exit requires all four Agents role-active and healthy in the bounded window, without treating class presence, configured fallback or shadow canary as an executed business outcome. | -| MCP/RAG dependency | Runtime disabled / telemetry empty | Production currently reports `MCP_ROUTER_ENABLED=false`, `RAG_ENABLED=false`, zero `mcp_calls` and zero `rag_query_log` activity. Exit requires enabled approved routes, live health, non-zero agent/product telemetry and the internal RAG candidate canary. | +| Agent runtime activity | Production partial; bounded fallback runtime verified | V10.816 production exercised the actual model-aware dispatcher: GCP-A -> GCP-B -> 111, with 111 exact-digest `qwen3:8b` returning a valid decision envelope after three attempts. This proves decision-only fallback execution and shared dedupe boundaries, not a formal business action or four-Agent closure. Exit requires all four Agents role-active and healthy in the bounded window with linked product outcomes. | +| MCP/RAG dependency | RAG canary verified; activation and MCP runtime still blocked | Production RAG executed one read-only candidate canary successfully, but `RAG_ENABLED=false` continues to block activation; MCP router remains disabled and non-zero product telemetry is still absent. Exit requires approved routes enabled, live MCP health, non-zero agent/product telemetry, rollback coverage and a fresh internal RAG shadow receipt. | | Controlled automation closure | Runtime partial | `/api/ai-automation/agent-product-integration`, CLI and smoke must report Detect -> Normalize -> Correlate -> Decide -> Check -> Controlled Apply -> Verify -> Retry/Rollback -> Learn/Writeback. Completion requires bounded execution, linked outcome/incident verification and durable learning evidence; aggregate source presence is insufficient. | ### Analytics Period-Linkage Closure @@ -72,7 +72,7 @@ This bounded interruption is closed and control returns to `GROWTH-P0-001` witho | 17 | `UX-P1-001` | In progress | Professional full-site UI/UX | V10.815 closes the exact sales-analysis period/filter linkage and keeps the prior four-tab rendering guards: real payload values, visible single points, bounded extreme percentages, date-label auto-skip, zoom bounds and explicit loading/error/empty states. Public assets are hash-verified; authenticated V10.815 visual proof and the broader site-wide first-viewport, progressive-disclosure, accessibility and loading/error/degraded-state audit remain in progress. | | 18 | `PIXELRAG-P1-001` | Not started | Ollama-first multimodal embedding benchmark | Verify approved visual embedding on GCP-A -> GCP-B -> 111 and design pgvector-compatible visual metadata; FAISS remains disallowed without ADR. | | 19 | `MARKET-P1-001` | In progress | Marketplace source contracts | Yahoo Shopping remains active in V10.810 production with public-boundary allowlists, bounded streaming/rate, provenance, current product-detail readback, stock/spec/variant guards, source-specific promotion partition, idempotent exact canary activation and durable activation readback across no-write runs. Four fresh verified Yahoo offers now contribute formal evidence across completed batches; non-exact and unit-price candidates do not. Shopee, Coupang, ETMall, Friday and Rakuten still require equivalent structured contracts, and blocked pages remain non-product data. | -| 20 | `QA-P1-001` | In progress | Deterministic test and CI governance | V10.816 source-candidate broad regression is `2,223 passed / 15 skipped / 0 failed`; focused model/dedupe regression is `93 passed`, and independent ninth-round review found no material issue. V10.815 production parity remains `36/36` source hashes plus `12/12` runtime env checks, and public HTTPS serves its exact tested sales JS/CSS. No matching EwoooC runner has executed V10.816, so formal CI/CD or production parity is not claimed and Windows 99 exact-object deployment receipts remain a separate evidence layer. | +| 20 | `QA-P1-001` | In progress | Deterministic test and CI governance | V10.816 broad regression is `2,223 passed / 15 skipped / 0 failed`; focused model/dedupe regression is `93 passed`, and independent ninth-round review found no material issue. Production parity is verified for all `20/20` changed source hashes and `30/30` runtime env contracts, with an independent Windows 99 verifier plus RAG/NemoTron canaries. No matching EwoooC runner executed V10.816, so formal Gitea CI/CD remains missing even though the bounded production release is verified. | ## P2 @@ -97,7 +97,7 @@ These are reusable foundations, not proof that the full program is complete. | Completed | PromotionGate replay | No production write. | | Completed | Embedding-signature guard replay | Signature readiness only. | | Completed | Candidate knowledge replay | Internal RAG preview only; no DB/model call. | -| Source ready; production pending | Model-aware NemoTron dispatcher fallback | V10.816 source uses one modular exact-digest candidate registry for production and canary: GCP-A/GCP-B `qwen3:14b` with 60-second attempts, then 111 `qwen3:8b` with 45 seconds, `think=false`, fixed `num_ctx=4096` / `num_predict=512` and one total deadline. Production and canary share the full one-call-per-SKU tool contract; malformed model identity schema fails closed and continues the approved candidate chain. Two-phase dedupe uses `/app/data` shared `flock` + fsync + atomic JSON ownership-token leases across Gunicorn workers and app/scheduler/bot containers. Before any handler, the owner persists `side_effect_started` with a four-hour quarantine; only an explicit DB write, durable insight, delivered notification or durable EventRouter queue acknowledgement counts as dispatched. A later commit-verification failure is surfaced but never releases the quarantine, preventing duplicate action after a durable effect. Privacy-safe state hashes SKU values; privacy-safe attempt summaries preserve label/tier/model/status/digest/error-class in structured and recipient-visible footprints. Production deployment, shared-store canary, fresh degraded-fallback receipt and independent readback remain P0; GCP-A replacement, GCP-B capacity and RAG shadow activation remain unresolved rather than hidden by the fallback. | +| Production verified; degraded fallback | Model-aware NemoTron dispatcher fallback | V10.816 production uses one modular exact-digest candidate registry for production and canary: GCP-A/GCP-B `qwen3:14b` with 60-second attempts, then 111 `qwen3:8b` with 45 seconds, `think=false`, fixed `num_ctx=4096` / `num_predict=512` and one total deadline. Run `1b335e97-fa31-418b-b925-759bc1036267` passed the shared app/scheduler and cross-container reservation canaries, then produced a valid decision from `ollama_111_fallback` after three attempts with no tool or business-data writes. Privacy-safe state hashes SKU values and the four-hour `side_effect_started` quarantine remains fail-closed after durable-effect uncertainty. GCP-A replacement, GCP-B capacity and controlled RAG activation remain unresolved and are not hidden by the fallback. | | Completed | PixelRAG application portfolio | Commerce/RAG/UX/ops/marketing/governance inventory. | | Completed | Ollama-first VLM route readiness and replay worker | Evidence-bound artifact output; no direct price write. | | Completed | Platform probe worker | Shopee/Coupang barriers become structured fallback/backoff receipts. |