新增市場情報 report catalog record run package gate
All checks were successful
CD Pipeline / deploy (push) Successful in 1m4s

This commit is contained in:
OoO
2026-05-20 19:36:42 +08:00
parent 8edd8a8604
commit e506251194
9 changed files with 1213 additions and 106 deletions

View File

@@ -4,6 +4,7 @@
================================================================================
【已完成】
- V10.347 補市場情報 candidate queue review AI summary Telegram dispatch report catalog record run package新增 read-only report catalog record run package builder、POST endpoint、UI 按鈕與 deployment readiness smoke target在 record write gate 後整理 payload manifest、CLI command bundle、backup/dry-run trace 與後續 run readiness separate gateAPI/UI 不讀 approval/Telegram token、不呼叫 LLM、不補產報表、不派送 Telegram、不開 DB、不寫檔、不執行 CLI、不寫 catalog record、不更新 review_state、不掛 scheduler。
- V10.344 補市場情報 candidate queue review AI summary Telegram dispatch report catalog record write gate新增 read-only report catalog record write builder、POST endpoint、UI 按鈕與 deployment readiness smoke target在 write preflight 後檢查 catalog record key/schema/hash trace、operator dry-run、backup 與 commit separate gateAPI/UI 不讀 approval/Telegram token、不呼叫 LLM、不補產報表、不派送 Telegram、不開 DB、不寫檔、不寫 catalog record、不更新 review_state、不掛 scheduler。
- V10.342 補市場情報 candidate queue review AI summary Telegram dispatch report catalog write preflight新增 read-only report catalog write preflight builder、POST endpoint、UI 按鈕與 deployment readiness smoke target在 report catalog index 後整理 catalog record identity、write source trace、record schema preflight 與 runtime safety只放行到後續 report catalog record write gateAPI/UI 不讀 approval/Telegram token、不呼叫 LLM、不補產報表、不派送 Telegram、不開 DB、不寫 catalog preflight file、不寫 catalog record、不更新 review_state、不掛 scheduler。
- V10.339 補市場情報 candidate queue review AI summary Telegram dispatch report catalog index新增 read-only report catalog index builder、POST endpoint、UI 按鈕與 deployment readiness smoke target在 report catalog handoff 後整理 catalog index identity、handoff source trace、index manifest 與 runtime safety只放行到後續 report catalog write preflight gateAPI/UI 不讀 approval/Telegram token、不呼叫 LLM、不補產報表、不派送 Telegram、不開 DB、不寫 catalog index file、不寫 catalog record、不更新 review_state、不掛 scheduler。

View File

@@ -320,7 +320,7 @@ YOUTUBE_API_KEY = os.getenv('YOUTUBE_API_KEY', '')
# ==========================================
# 系統版本與路徑
# ==========================================
SYSTEM_VERSION = "V10.346"
SYSTEM_VERSION = "V10.347"
LOG_FILE_PATH = os.path.join(BASE_DIR, 'logs/system.log')
public_url = PUBLIC_URL # 用於模板顯示

View File

@@ -12,6 +12,10 @@
## 📅 詳細更新日誌 (考古存檔)
### 2026-05-20市場情報 Telegram dispatch report catalog record run package
- **V10.347 report catalog record run package**: 新增 `candidate_queue_review_ai_summary_persistence_telegram_dispatch_report_catalog_record_run_package` service、POST endpoint、UI 按鈕與 deployment readiness smoke target在 record write gate 後整理 payload manifest、CLI command bundle、backup/dry-run trace 與後續 run readiness separate gate。
- **只讀安全邊界**: 本階段只放行到後續 report catalog record run readiness gateAPI/UI 不讀 approval/Telegram token、不呼叫 LLM、不補產報表、不派送 Telegram、不開 DB、不寫檔、不執行 CLI、不寫 catalog record、不更新 `review_state`、不掛 scheduler。
### 2026-05-20市場情報 Telegram dispatch report catalog record write gate
- **V10.344 report catalog record write gate**: 新增 `candidate_queue_review_ai_summary_persistence_telegram_dispatch_report_catalog_record_write` service、POST endpoint、UI 按鈕與 deployment readiness smoke target在 catalog write preflight 後檢查 catalog record key/schema/hash trace、operator dry-run、backup 與 commit separate gate。
- **只讀安全邊界**: 本階段只放行到後續 report catalog record run package gateAPI/UI 不讀 approval/Telegram token、不呼叫 LLM、不補產報表、不派送 Telegram、不開 DB、不寫檔、不寫 catalog record、不更新 `review_state`、不掛 scheduler。

View File

@@ -34,6 +34,9 @@ from services.market_intel.candidate_queue_review_ai_summary_persistence_telegra
from services.market_intel.candidate_queue_review_ai_summary_persistence_telegram_dispatch_report_catalog_record_write import (
build_candidate_queue_review_ai_summary_persistence_telegram_dispatch_report_catalog_record_write,
)
from services.market_intel.candidate_queue_review_ai_summary_persistence_telegram_dispatch_report_catalog_record_run_package import (
build_candidate_queue_review_ai_summary_persistence_telegram_dispatch_report_catalog_record_run_package,
)
from services.market_intel.candidate_queue_review_ai_summary_persistence_telegram_dispatch_report_closeout import (
build_candidate_queue_review_ai_summary_persistence_telegram_dispatch_report_closeout,
)
@@ -416,6 +419,37 @@ def _build_ai_summary_persistence_telegram_dispatch_report_catalog_write_preflig
)
def _build_ai_summary_persistence_telegram_dispatch_report_catalog_record_write(
*,
service,
sample_result,
operator_evidence,
writer_output,
smoke_result,
payload_error,
limit,
execute_requested,
apply_real_write,
):
report_catalog_write_preflight = _build_ai_summary_persistence_telegram_dispatch_report_catalog_write_preflight(
service=service,
sample_result=sample_result,
operator_evidence=operator_evidence,
writer_output=writer_output,
smoke_result=smoke_result,
payload_error=payload_error,
limit=limit,
execute_requested=execute_requested,
apply_real_write=apply_real_write,
)
return build_candidate_queue_review_ai_summary_persistence_telegram_dispatch_report_catalog_record_write(
telegram_dispatch_report_catalog_write_preflight=report_catalog_write_preflight,
operator_evidence=operator_evidence,
execute_requested=execute_requested,
apply_real_write=apply_real_write,
)
@market_intel_review_bp.route(
"/api/market_intel/manual_sample_review/"
"candidate_queue_review_ai_summary_persistence_telegram_dispatch_report_input",
@@ -721,7 +755,7 @@ def market_intel_manual_sample_candidate_queue_review_ai_summary_persistence_tel
sample_result, operator_evidence, writer_output, smoke_result, payload_error, limit = (
_extract_run_payload()
)
report_catalog_write_preflight = _build_ai_summary_persistence_telegram_dispatch_report_catalog_write_preflight(
data = _build_ai_summary_persistence_telegram_dispatch_report_catalog_record_write(
service=service,
sample_result=sample_result,
operator_evidence=operator_evidence,
@@ -732,8 +766,36 @@ def market_intel_manual_sample_candidate_queue_review_ai_summary_persistence_tel
execute_requested=execute_requested,
apply_real_write=apply_real_write,
)
data = build_candidate_queue_review_ai_summary_persistence_telegram_dispatch_report_catalog_record_write(
telegram_dispatch_report_catalog_write_preflight=report_catalog_write_preflight,
data["phase"] = service.phase
return jsonify(data), 400 if payload_error else 200
@market_intel_review_bp.route(
"/api/market_intel/manual_sample_review/"
"candidate_queue_review_ai_summary_persistence_telegram_dispatch_report_catalog_record_run_package",
methods=["POST"],
)
@login_required
def market_intel_manual_sample_candidate_queue_review_ai_summary_persistence_telegram_dispatch_report_catalog_record_run_package():
service = MarketIntelService()
execute_requested = request.args.get("execute", "false").lower() == "true"
apply_real_write = request.args.get("apply_real_write", "false").lower() == "true"
sample_result, operator_evidence, writer_output, smoke_result, payload_error, limit = (
_extract_run_payload()
)
report_catalog_record_write = _build_ai_summary_persistence_telegram_dispatch_report_catalog_record_write(
service=service,
sample_result=sample_result,
operator_evidence=operator_evidence,
writer_output=writer_output,
smoke_result=smoke_result,
payload_error=payload_error,
limit=limit,
execute_requested=execute_requested,
apply_real_write=apply_real_write,
)
data = build_candidate_queue_review_ai_summary_persistence_telegram_dispatch_report_catalog_record_run_package(
telegram_dispatch_report_catalog_record_write=report_catalog_record_write,
operator_evidence=operator_evidence,
execute_requested=execute_requested,
apply_real_write=apply_real_write,

View File

@@ -0,0 +1,611 @@
"""候選審核 queue AI summary Telegram dispatch report catalog record run package。
本模組只把 catalog record write gate 整理成後續 CLI run readiness 可審核的
payload、command、backup 與 dry-run trace不讀 approval 或 Telegram token、
不呼叫 LLM、不派送 Telegram、不開 DB、不寫檔、不執行 CLI、不寫 catalog record、
不 commit、不更新 review_state、不掛 scheduler。
"""
from services.market_intel.candidate_queue_review_ai_summary_persistence_telegram_dispatch_report_archive_summary import (
SAFE_APPROVAL_ENV_VAR,
SAFE_TOKEN_METADATA_KEYS,
TARGET_COLUMN,
TARGET_TABLE,
_as_dict,
_as_list,
_contains_forbidden_token_key,
_has_text,
_safe_int,
_safe_text,
_strip_safe_token_boolean_keys,
)
from services.market_intel.candidate_queue_review_ai_summary_persistence_telegram_dispatch_report_catalog_record_write import (
FALSE_RESPONSE_KEYS as REPORT_CATALOG_RECORD_WRITE_FALSE_RESPONSE_KEYS,
)
REQUIRED_CATALOG_RECORD_WRITE_BOUNDARIES = {
"do_not_read_approval_token_from_report_catalog_record_write_api",
"do_not_read_telegram_token_from_report_catalog_record_write_api",
"do_not_call_llm_from_report_catalog_record_write",
"do_not_generate_report_from_report_catalog_record_write_api",
"do_not_write_report_catalog_record_write_artifact_from_api",
"do_not_write_report_catalog_record_from_api",
"do_not_dispatch_telegram_from_report_catalog_record_write_api",
"do_not_open_database_connection_from_report_catalog_record_write",
"do_not_update_review_state_from_report_catalog_record_write",
"do_not_attach_scheduler_from_report_catalog_record_write",
"future_market_intel_report_catalog_record_run_package_must_use_separate_gate",
}
FALSE_RESPONSE_KEYS = tuple(
dict.fromkeys(
REPORT_CATALOG_RECORD_WRITE_FALSE_RESPONSE_KEYS
+ (
"telegram_dispatch_report_catalog_record_run_readiness_file_written",
"report_catalog_record_run_readiness_file_written",
"catalog_record_run_readiness_file_written",
"telegram_dispatch_report_catalog_record_run_receipt_file_written",
"report_catalog_record_run_receipt_file_written",
"catalog_record_run_receipt_file_written",
"catalog_record_cli_executed",
"catalog_record_writer_cli_executed",
"catalog_record_postwrite_smoke_file_written",
)
)
)
def _record_write_summary(telegram_dispatch_report_catalog_record_write):
record_write = _as_dict(telegram_dispatch_report_catalog_record_write)
preflight = _as_dict(record_write.get("telegram_dispatch_report_catalog_write_preflight"))
operator_write = _as_dict(
record_write.get("operator_telegram_dispatch_report_catalog_record_write")
)
promotion = _as_dict(record_write.get("promotion_gate"))
sections = _as_list(record_write.get("telegram_dispatch_report_catalog_record_write_sections"))
safe_boundaries = set(str(item) for item in _as_list(record_write.get("safe_boundaries")))
missing_boundaries = sorted(REQUIRED_CATALOG_RECORD_WRITE_BOUNDARIES - safe_boundaries)
section_keys = sorted(
str(item.get("key"))
for item in sections
if isinstance(item, dict) and item.get("key")
)
return {
"provided": bool(record_write),
"mode": record_write.get("mode"),
"target_operation": record_write.get("target_operation"),
"catalog_record_write_passed": bool(
record_write.get("telegram_dispatch_report_catalog_record_write_passed")
or record_write.get(
"summary_persistence_telegram_dispatch_report_catalog_record_write_passed"
)
or record_write.get("report_catalog_record_write_passed")
),
"ready_for_next_manual_phase": bool(record_write.get("ready_for_next_manual_phase")),
"ready_for_market_intel_report_catalog_record_write": bool(
record_write.get("ready_for_market_intel_report_catalog_record_write")
),
"ready_for_market_intel_report_catalog_record_cli_run": bool(
record_write.get("ready_for_market_intel_report_catalog_record_cli_run")
),
"ready_for_market_intel_report_catalog_record_commit": bool(
record_write.get("ready_for_market_intel_report_catalog_record_commit")
),
"statement_count": _safe_int(record_write.get("statement_count")),
"expected_summary_payload_hash": _safe_text(
record_write.get("expected_summary_payload_hash"),
80,
),
"target_report_family": preflight.get("target_report_family"),
"language": preflight.get("language"),
"report_output_artifact_path": preflight.get("report_output_artifact_path"),
"report_output_hash": preflight.get("report_output_hash"),
"report_catalog_index_artifact_path": preflight.get(
"report_catalog_index_artifact_path"
),
"report_catalog_write_preflight_artifact_path": preflight.get(
"report_catalog_write_preflight_artifact_path"
),
"catalog_record_key_recorded": bool(
operator_write.get("catalog_record_key_recorded")
or preflight.get("catalog_record_key_recorded")
),
"catalog_family_recorded": bool(
operator_write.get("catalog_family_recorded")
or preflight.get("catalog_family_recorded")
),
"catalog_index_key_recorded": bool(
operator_write.get("catalog_index_key_recorded")
or preflight.get("catalog_index_key_recorded")
),
"catalog_record_schema_recorded": bool(
operator_write.get("catalog_record_schema_recorded")
or preflight.get("catalog_record_schema_recorded")
),
"report_catalog_record_write_artifact_path": operator_write.get(
"report_catalog_record_write_artifact_path"
),
"report_catalog_write_preflight_artifact_path_recorded": bool(
operator_write.get("report_catalog_write_preflight_artifact_path_recorded")
),
"report_catalog_index_artifact_path_recorded": bool(
operator_write.get("report_catalog_index_artifact_path_recorded")
),
"report_output_artifact_path_recorded": bool(
operator_write.get("report_output_artifact_path_recorded")
),
"catalog_record_backup_artifact_path_recorded": bool(
operator_write.get("catalog_record_backup_artifact_path_recorded")
),
"catalog_record_write_dry_run_artifact_path_recorded": bool(
operator_write.get("catalog_record_write_dry_run_artifact_path_recorded")
),
"operator_confirmed_report_catalog_record_write": bool(
operator_write.get("operator_confirmed_report_catalog_record_write")
),
"operator_confirmed_catalog_record_write_is_cli_only": bool(
operator_write.get("operator_confirmed_catalog_record_write_is_cli_only")
),
"operator_confirmed_catalog_record_write_dry_run_reviewed": bool(
operator_write.get("operator_confirmed_catalog_record_write_dry_run_reviewed")
),
"operator_confirmed_catalog_record_backup_required": bool(
operator_write.get("operator_confirmed_catalog_record_backup_required")
),
"operator_confirmed_report_catalog_record_commit_requires_separate_gate": bool(
operator_write.get(
"operator_confirmed_report_catalog_record_commit_requires_separate_gate"
)
),
"operator_confirmed_postwrite_smoke_required": bool(
operator_write.get("operator_confirmed_postwrite_smoke_required")
),
"promotion_allowed": bool(promotion.get("allowed")),
"promotion_next_manual_phase": promotion.get("next_manual_phase"),
"promotion_requires_real_db_write": bool(promotion.get("requires_real_db_write")),
"promotion_requires_cli_run": bool(promotion.get("requires_cli_run")),
"promotion_requires_postwrite_smoke": bool(
promotion.get("requires_postwrite_smoke")
),
"promotion_run_package_separate_gate": bool(
promotion.get("report_catalog_record_run_package_requires_separate_gate")
),
"promotion_commit_separate_gate": bool(
promotion.get("report_catalog_record_commit_requires_separate_gate")
),
"safe_boundaries_complete": not missing_boundaries,
"missing_safe_boundaries": missing_boundaries,
"section_keys": section_keys,
"section_count": len(section_keys),
"forbidden_token_key_detected": _contains_forbidden_token_key(
_strip_safe_token_boolean_keys(record_write)
),
"blocked_count": len(_as_list(record_write.get("blocked_reasons"))),
**{key: bool(record_write.get(key)) for key in FALSE_RESPONSE_KEYS},
}
def _operator_summary(operator_evidence):
operator_evidence = _as_dict(operator_evidence)
return {
"provided_keys": sorted(operator_evidence.keys()),
"report_catalog_record_run_package_artifact_path": _safe_text(
operator_evidence.get("report_catalog_record_run_package_artifact_path")
or operator_evidence.get(
"telegram_dispatch_report_catalog_record_run_package_artifact_path"
)
or operator_evidence.get(
"market_intel_report_catalog_record_run_package_artifact_path"
)
),
"report_catalog_record_write_artifact_path_recorded": _has_text(
operator_evidence.get("report_catalog_record_write_artifact_path")
or operator_evidence.get(
"telegram_dispatch_report_catalog_record_write_artifact_path"
)
),
"report_catalog_write_preflight_artifact_path_recorded": _has_text(
operator_evidence.get("report_catalog_write_preflight_artifact_path")
or operator_evidence.get(
"telegram_dispatch_report_catalog_write_preflight_artifact_path"
)
),
"report_output_artifact_path_recorded": _has_text(
operator_evidence.get("report_output_artifact_path")
or operator_evidence.get("telegram_dispatch_report_output_artifact_path")
),
"catalog_record_key_recorded": _has_text(
operator_evidence.get("catalog_record_key")
or operator_evidence.get("report_catalog_key")
),
"catalog_record_schema_recorded": _has_text(
operator_evidence.get("catalog_record_schema")
or operator_evidence.get("report_catalog_record_schema")
),
"catalog_record_payload_manifest_path_recorded": _has_text(
operator_evidence.get("catalog_record_payload_manifest_path")
or operator_evidence.get("report_catalog_record_payload_manifest_path")
),
"catalog_record_backup_artifact_path_recorded": _has_text(
operator_evidence.get("catalog_record_backup_artifact_path")
or operator_evidence.get("report_catalog_backup_artifact_path")
or operator_evidence.get("metadata_json_backup_artifact_path")
),
"catalog_record_write_dry_run_artifact_path_recorded": _has_text(
operator_evidence.get("catalog_record_write_dry_run_artifact_path")
or operator_evidence.get("report_catalog_record_dry_run_artifact_path")
),
"catalog_record_cli_command_recorded": _has_text(
operator_evidence.get("catalog_record_cli_command")
or operator_evidence.get("report_catalog_record_cli_command")
),
"operator_confirmed_report_catalog_record_run_package": bool(
operator_evidence.get("operator_confirmed_report_catalog_record_run_package")
or operator_evidence.get(
"operator_confirmed_market_intel_report_catalog_record_run_package"
)
),
"operator_confirmed_catalog_record_payload_manifest_reviewed": bool(
operator_evidence.get(
"operator_confirmed_catalog_record_payload_manifest_reviewed"
)
),
"operator_confirmed_catalog_record_cli_command_reviewed": bool(
operator_evidence.get("operator_confirmed_catalog_record_cli_command_reviewed")
or operator_evidence.get("operator_confirmed_cli_command_reviewed")
),
"operator_confirmed_catalog_record_run_is_cli_only": bool(
operator_evidence.get("operator_confirmed_catalog_record_run_is_cli_only")
or operator_evidence.get("operator_confirmed_catalog_record_write_is_cli_only")
),
"operator_confirmed_catalog_record_backup_available": bool(
operator_evidence.get("operator_confirmed_catalog_record_backup_available")
or operator_evidence.get("operator_confirmed_catalog_record_backup_required")
),
"operator_confirmed_report_catalog_record_run_readiness_requires_separate_gate": bool(
operator_evidence.get(
"operator_confirmed_report_catalog_record_run_readiness_requires_separate_gate"
)
),
"operator_confirmed_report_catalog_record_commit_requires_separate_gate": bool(
operator_evidence.get(
"operator_confirmed_report_catalog_record_commit_requires_separate_gate"
)
),
"operator_confirmed_postwrite_smoke_required": bool(
operator_evidence.get("operator_confirmed_postwrite_smoke_required")
or operator_evidence.get(
"operator_confirmed_catalog_record_postwrite_smoke_required"
)
),
"operator_confirmed_no_token_in_report_catalog_record_run_package": bool(
operator_evidence.get(
"operator_confirmed_no_token_in_report_catalog_record_run_package"
)
or operator_evidence.get("operator_confirmed_no_token_in_artifacts")
),
"operator_confirmed_no_api_file_write": bool(
operator_evidence.get("operator_confirmed_no_api_file_write")
),
"operator_confirmed_no_api_catalog_record_write": bool(
operator_evidence.get("operator_confirmed_no_api_catalog_record_write")
or operator_evidence.get("operator_confirmed_no_api_db_write")
),
"operator_confirmed_no_api_telegram_dispatch": bool(
operator_evidence.get("operator_confirmed_no_api_telegram_dispatch")
),
"operator_confirmed_no_api_db_write": bool(
operator_evidence.get("operator_confirmed_no_api_db_write")
),
"operator_confirmed_no_llm_call": bool(
operator_evidence.get("operator_confirmed_no_llm_call")
),
"operator_confirmed_no_scheduler_attach": bool(
operator_evidence.get("operator_confirmed_no_scheduler_attach")
),
"catalog_record_run_package_notes_recorded": _has_text(
operator_evidence.get("report_catalog_record_run_package_notes")
or operator_evidence.get("catalog_record_run_package_notes")
),
"safe_token_metadata_only": all(
key in SAFE_TOKEN_METADATA_KEYS or key == "approval_env_var"
for key in operator_evidence
if "token" in str(key).lower() or str(key).lower() == "approval_env_var"
)
and operator_evidence.get("approval_env_var", SAFE_APPROVAL_ENV_VAR)
== SAFE_APPROVAL_ENV_VAR,
"forbidden_token_submitted_to_api": _contains_forbidden_token_key(
operator_evidence
),
}
def _payload_manifest(summary, operator):
return {
"target_table": TARGET_TABLE,
"target_column": TARGET_COLUMN,
"record_family": summary["target_report_family"],
"record_key_recorded": summary["catalog_record_key_recorded"]
and operator["catalog_record_key_recorded"],
"record_schema_recorded": summary["catalog_record_schema_recorded"]
and operator["catalog_record_schema_recorded"],
"report_output_hash": summary["report_output_hash"],
"expected_summary_payload_hash": summary["expected_summary_payload_hash"],
"statement_count": summary["statement_count"],
"source_artifacts": {
"record_write_gate": operator["report_catalog_record_write_artifact_path_recorded"],
"write_preflight": operator["report_catalog_write_preflight_artifact_path_recorded"],
"report_output": operator["report_output_artifact_path_recorded"],
"backup": operator["catalog_record_backup_artifact_path_recorded"],
"dry_run": operator["catalog_record_write_dry_run_artifact_path_recorded"],
},
"execute_in_api": False,
}
def _command_bundle(summary, operator):
return {
"script_path": "scripts/market_intel/write_report_catalog_record.py",
"approval_env_var": SAFE_APPROVAL_ENV_VAR,
"dry_run_command": (
"python scripts/market_intel/write_report_catalog_record.py "
"--input <catalog_record_payload_manifest.json> --dry-run"
),
"real_run_command_requires_separate_gate": True,
"api_must_not_execute_command": True,
"cli_command_recorded_by_operator": operator["catalog_record_cli_command_recorded"],
"expected_statement_count": summary["statement_count"],
}
def _run_package_sections(summary, operator):
return [
{
"key": "catalog_record_run_package_identity",
"title": "Catalog record run package identity",
"facts": [
f"family={summary['target_report_family'] or 'missing'}",
f"record_key={summary['catalog_record_key_recorded']}",
f"schema={summary['catalog_record_schema_recorded']}",
],
},
{
"key": "catalog_record_payload_manifest",
"title": "Catalog record payload manifest",
"facts": [
f"manifest={operator['catalog_record_payload_manifest_path_recorded']}",
f"statement_count={summary['statement_count']}",
f"report_hash={summary['report_output_hash'] or 'missing'}",
],
},
{
"key": "catalog_record_command_bundle",
"title": "Catalog record command bundle",
"facts": [
f"cli_command={operator['catalog_record_cli_command_recorded']}",
"execute_in_api=false",
"real_run_requires_separate_gate=true",
],
},
{
"key": "catalog_record_run_package_safety",
"title": "Catalog record run package safety",
"facts": [
"package_file_written=false",
"cli_executed=false",
"database_write_executed=false",
"scheduler_attached=false",
],
},
]
def _run_package_gates(summary, operator, apply_real_write):
return [
{
"key": "report_catalog_record_write_preview_provided",
"label": "必須提供上一階段 report catalog record write preview",
"passed": bool(
summary["provided"]
and summary["mode"]
== "candidate_queue_review_ai_summary_persistence_telegram_dispatch_report_catalog_record_write_preview"
),
},
{
"key": "report_catalog_record_write_passed",
"label": "report catalog record write gate 必須已通過",
"passed": summary["catalog_record_write_passed"],
},
{
"key": "report_catalog_record_write_ready_for_run_package",
"label": "catalog record write 只能放行到 catalog record run package",
"passed": bool(
summary["ready_for_market_intel_report_catalog_record_write"]
and summary["ready_for_market_intel_report_catalog_record_cli_run"]
and summary["ready_for_next_manual_phase"]
and not summary["ready_for_market_intel_report_catalog_record_commit"]
and summary["promotion_allowed"]
and summary["promotion_next_manual_phase"]
== "market_intel_report_catalog_record_run_package"
and summary["promotion_requires_real_db_write"]
and summary["promotion_requires_cli_run"]
and summary["promotion_requires_postwrite_smoke"]
and summary["promotion_run_package_separate_gate"]
and summary["promotion_commit_separate_gate"]
),
},
{
"key": "catalog_record_run_package_traceability_complete",
"label": "run package 必須保留 record write gate、preflight、record key/schema、backup、dry-run 與 report hash trace",
"passed": bool(
summary["target_report_family"]
and summary["report_output_artifact_path"]
and summary["report_output_hash"]
and summary["report_catalog_record_write_artifact_path"]
and summary["report_catalog_write_preflight_artifact_path"]
and summary["catalog_record_key_recorded"]
and summary["catalog_record_schema_recorded"]
and summary["catalog_record_backup_artifact_path_recorded"]
and summary["catalog_record_write_dry_run_artifact_path_recorded"]
and summary["operator_confirmed_report_catalog_record_write"]
and summary["operator_confirmed_catalog_record_write_is_cli_only"]
and summary["operator_confirmed_catalog_record_write_dry_run_reviewed"]
and summary["operator_confirmed_catalog_record_backup_required"]
and summary[
"operator_confirmed_report_catalog_record_commit_requires_separate_gate"
]
and summary["operator_confirmed_postwrite_smoke_required"]
),
},
{
"key": "report_catalog_record_write_runtime_boundaries_clear",
"label": "record write payload 不得顯示 API 寫檔、DB、Telegram、LLM、CLI 或 scheduler 副作用",
"passed": all(not summary[key] for key in FALSE_RESPONSE_KEYS),
},
{
"key": "report_catalog_record_write_safe_boundaries_complete",
"label": "record write 必須保留 run package separate gate 與 runtime 安全邊界",
"passed": summary["safe_boundaries_complete"],
},
{
"key": "operator_confirmed_report_catalog_record_run_package",
"label": "操作員確認 run package payload、CLI command、backup、dry-run 與後續 readiness gate",
"passed": bool(
operator["report_catalog_record_run_package_artifact_path"]
and operator["report_catalog_record_write_artifact_path_recorded"]
and operator["report_catalog_write_preflight_artifact_path_recorded"]
and operator["report_output_artifact_path_recorded"]
and operator["catalog_record_key_recorded"]
and operator["catalog_record_schema_recorded"]
and operator["catalog_record_payload_manifest_path_recorded"]
and operator["catalog_record_backup_artifact_path_recorded"]
and operator["catalog_record_write_dry_run_artifact_path_recorded"]
and operator["catalog_record_cli_command_recorded"]
and operator["operator_confirmed_report_catalog_record_run_package"]
and operator["operator_confirmed_catalog_record_payload_manifest_reviewed"]
and operator["operator_confirmed_catalog_record_cli_command_reviewed"]
and operator["operator_confirmed_catalog_record_run_is_cli_only"]
and operator["operator_confirmed_catalog_record_backup_available"]
and operator[
"operator_confirmed_report_catalog_record_run_readiness_requires_separate_gate"
]
and operator[
"operator_confirmed_report_catalog_record_commit_requires_separate_gate"
]
and operator["operator_confirmed_postwrite_smoke_required"]
),
},
{
"key": "operator_confirmed_report_catalog_record_run_package_runtime_boundaries",
"label": "操作員確認本 API 不寫檔、不執行 CLI、不寫 DB、不派送 Telegram、不呼叫 LLM、不掛 scheduler",
"passed": bool(
operator["operator_confirmed_no_token_in_report_catalog_record_run_package"]
and operator["operator_confirmed_no_api_file_write"]
and operator["operator_confirmed_no_api_catalog_record_write"]
and operator["operator_confirmed_no_api_telegram_dispatch"]
and operator["operator_confirmed_no_api_db_write"]
and operator["operator_confirmed_no_llm_call"]
and operator["operator_confirmed_no_scheduler_attach"]
),
},
{
"key": "report_catalog_record_run_package_no_token_submitted_to_api",
"label": "catalog record run package payload 不得包含 approval 或 Telegram token key",
"passed": not operator["forbidden_token_submitted_to_api"]
and not summary["forbidden_token_key_detected"],
},
{
"key": "report_catalog_record_run_package_apply_real_write_not_requested_from_api",
"label": "API/UI report catalog record run package 不接受 apply_real_write",
"passed": not apply_real_write,
},
]
def build_candidate_queue_review_ai_summary_persistence_telegram_dispatch_report_catalog_record_run_package(
*,
telegram_dispatch_report_catalog_record_write,
operator_evidence=None,
execute_requested=False,
apply_real_write=False,
):
"""建立 Telegram dispatch report catalog record run package不執行副作用。"""
summary = _record_write_summary(telegram_dispatch_report_catalog_record_write)
operator = _operator_summary(operator_evidence)
sections = _run_package_sections(summary, operator)
gates = _run_package_gates(summary, operator, bool(apply_real_write))
blocked_reasons = [gate["key"] for gate in gates if not gate["passed"]]
run_package_passed = bool(not blocked_reasons)
return {
"mode": "candidate_queue_review_ai_summary_persistence_telegram_dispatch_report_catalog_record_run_package_preview",
"target_table": TARGET_TABLE,
"target_column": TARGET_COLUMN,
"target_json_path": [
"market_intel_ai_summary",
"telegram_dispatch_report_catalog_record_run_package",
],
"target_operation": "package_market_intel_report_catalog_record_run",
"execute_requested": bool(execute_requested),
"apply_real_write_requested": bool(apply_real_write),
"report_catalog_record_run_package_reviewed": True,
"telegram_dispatch_report_catalog_record_run_package_passed": run_package_passed,
"summary_persistence_telegram_dispatch_report_catalog_record_run_package_passed": run_package_passed,
"report_catalog_record_run_package_passed": run_package_passed,
"ready_for_next_manual_phase": run_package_passed,
"ready_for_market_intel_report_catalog_record_run_package": run_package_passed,
"ready_for_market_intel_report_catalog_record_run_readiness": run_package_passed,
"ready_for_market_intel_report_catalog_record_cli_run": False,
"ready_for_market_intel_report_catalog_record_commit": False,
**{key: False for key in FALSE_RESPONSE_KEYS},
"statement_count": summary["statement_count"],
"expected_summary_payload_hash": summary["expected_summary_payload_hash"],
"blocked_reasons": blocked_reasons,
"gates": gates,
"telegram_dispatch_report_catalog_record_write": summary,
"telegram_dispatch_report_catalog_record_run_package_sections": sections,
"operator_telegram_dispatch_report_catalog_record_run_package": operator,
"payload_manifest": _payload_manifest(summary, operator),
"command_bundle": _command_bundle(summary, operator),
"promotion_gate": {
"allowed": run_package_passed,
"next_manual_phase": "market_intel_report_catalog_record_run_readiness",
"requires_real_db_write": True,
"requires_cli_run": True,
"requires_scheduler_attach": False,
"requires_operator_approval": True,
"requires_postwrite_smoke": True,
"api_must_not_generate_report": True,
"api_must_not_write_file": True,
"api_must_not_execute_cli": True,
"api_must_not_write_catalog_record": True,
"api_must_not_write_database": True,
"api_must_not_dispatch_telegram": True,
"report_catalog_record_run_readiness_requires_separate_gate": True,
"report_catalog_record_commit_requires_separate_gate": True,
},
"next_operator_steps": [
"保存 report catalog record run package artifact path",
"確認 payload manifest、dry-run command、backup artifact 與 postwrite smoke requirement",
"下一階段 report catalog record run readiness 必須另開 gate本 API 不寫檔、不執行 CLI、不寫 catalog record",
"若任何 run package gate 阻擋,停在 report catalog record write gate 並保留 feature flags 關閉",
],
"safe_boundaries": [
"do_not_read_approval_token_from_report_catalog_record_run_package_api",
"do_not_read_telegram_token_from_report_catalog_record_run_package_api",
"do_not_call_llm_from_report_catalog_record_run_package",
"do_not_generate_report_from_report_catalog_record_run_package_api",
"do_not_write_report_catalog_record_run_package_artifact_from_api",
"do_not_execute_catalog_record_cli_from_api",
"do_not_write_report_catalog_record_from_api",
"do_not_dispatch_telegram_from_report_catalog_record_run_package_api",
"do_not_open_database_connection_from_report_catalog_record_run_package",
"do_not_update_review_state_from_report_catalog_record_run_package",
"do_not_attach_scheduler_from_report_catalog_record_run_package",
"future_market_intel_report_catalog_record_run_readiness_must_use_separate_gate",
"report_catalog_record_run_package_preview_only",
"no_remove_orphans",
"no_momo_db_lifecycle_change",
],
}

File diff suppressed because one or more lines are too long

View File

@@ -1,3 +1,3 @@
"""市場情報 rollout phase 單一來源。"""
MARKET_INTEL_PHASE = "phase_107_candidate_queue_review_ai_summary_persistence_telegram_dispatch_report_catalog_record_write"
MARKET_INTEL_PHASE = "phase_108_candidate_queue_review_ai_summary_persistence_telegram_dispatch_report_catalog_record_run_package"

View File

@@ -760,6 +760,9 @@
<button class="market-intel-icon-button" type="button" title="檢查 queue review AI summary Telegram dispatch report catalog record write gate" data-market-intel-sample-candidate-queue-review-ai-summary-persistence-telegram-dispatch-report-catalog-record-write>
<i class="fas fa-database" aria-hidden="true"></i>
</button>
<button class="market-intel-icon-button" type="button" title="產生 queue review AI summary Telegram dispatch report catalog record run package" data-market-intel-sample-candidate-queue-review-ai-summary-persistence-telegram-dispatch-report-catalog-record-run-package>
<i class="fas fa-box" aria-hidden="true"></i>
</button>
</div>
</div>
</div>
@@ -1141,6 +1144,7 @@
const sampleCandidateQueueReviewAiSummaryPersistenceTelegramDispatchReportCatalogIndex = sampleReviewRoot ? sampleReviewRoot.querySelector('[data-market-intel-sample-candidate-queue-review-ai-summary-persistence-telegram-dispatch-report-catalog-index]') : null;
const sampleCandidateQueueReviewAiSummaryPersistenceTelegramDispatchReportCatalogWritePreflight = sampleReviewRoot ? sampleReviewRoot.querySelector('[data-market-intel-sample-candidate-queue-review-ai-summary-persistence-telegram-dispatch-report-catalog-write-preflight]') : null;
const sampleCandidateQueueReviewAiSummaryPersistenceTelegramDispatchReportCatalogRecordWrite = sampleReviewRoot ? sampleReviewRoot.querySelector('[data-market-intel-sample-candidate-queue-review-ai-summary-persistence-telegram-dispatch-report-catalog-record-write]') : null;
const sampleCandidateQueueReviewAiSummaryPersistenceTelegramDispatchReportCatalogRecordRunPackage = sampleReviewRoot ? sampleReviewRoot.querySelector('[data-market-intel-sample-candidate-queue-review-ai-summary-persistence-telegram-dispatch-report-catalog-record-run-package]') : null;
const sampleReviewEndpoint = "{{ url_for('market_intel.market_intel_manual_sample_review') }}";
const sampleReviewEvaluateEndpoint = "{{ url_for('market_intel.market_intel_manual_sample_review_evaluate') }}";
const sampleCandidateHandoffEndpoint = "{{ url_for('market_intel.market_intel_manual_sample_candidate_handoff') }}";
@@ -1199,6 +1203,7 @@
const sampleCandidateQueueReviewAiSummaryPersistenceTelegramDispatchReportCatalogIndexEndpoint = "{{ url_for('market_intel_review.market_intel_manual_sample_candidate_queue_review_ai_summary_persistence_telegram_dispatch_report_catalog_index') }}";
const sampleCandidateQueueReviewAiSummaryPersistenceTelegramDispatchReportCatalogWritePreflightEndpoint = "{{ url_for('market_intel_review.market_intel_manual_sample_candidate_queue_review_ai_summary_persistence_telegram_dispatch_report_catalog_write_preflight') }}";
const sampleCandidateQueueReviewAiSummaryPersistenceTelegramDispatchReportCatalogRecordWriteEndpoint = "{{ url_for('market_intel_review.market_intel_manual_sample_candidate_queue_review_ai_summary_persistence_telegram_dispatch_report_catalog_record_write') }}";
const sampleCandidateQueueReviewAiSummaryPersistenceTelegramDispatchReportCatalogRecordRunPackageEndpoint = "{{ url_for('market_intel_review.market_intel_manual_sample_candidate_queue_review_ai_summary_persistence_telegram_dispatch_report_catalog_record_run_package') }}";
const schedulerMeta = schedulerRoot ? schedulerRoot.querySelector('[data-market-intel-scheduler-meta]') : null;
const schedulerBody = schedulerRoot ? schedulerRoot.querySelector('[data-market-intel-scheduler-body]') : null;
const schedulerRefresh = schedulerRoot ? schedulerRoot.querySelector('[data-market-intel-scheduler-refresh]') : null;
@@ -8576,6 +8581,144 @@
}
};
const renderCandidateQueueReviewAiSummaryPersistenceTelegramDispatchReportCatalogRecordRunPackage = data => {
const blockers = (data.blocked_reasons || []).join(' / ');
const gates = data.gates || [];
const recordWrite = data.telegram_dispatch_report_catalog_record_write || {};
const operator = data.operator_telegram_dispatch_report_catalog_record_run_package || {};
const sections = data.telegram_dispatch_report_catalog_record_run_package_sections || [];
const command = data.command_bundle || {};
const manifest = data.payload_manifest || {};
const promotion = data.promotion_gate || {};
sampleReviewMeta.innerHTML = [
`mode=${data.mode || 'unknown'}`,
`run_package=${data.telegram_dispatch_report_catalog_record_run_package_passed ? 'pass' : 'blocked'}`,
`readiness=${data.ready_for_market_intel_report_catalog_record_run_readiness ? 'ready' : 'blocked'}`,
`cli=${data.catalog_record_cli_executed ? 'executed' : 'blocked'}`,
`db=${data.database_write_executed ? 'written' : 'blocked'}`
].map(item => `<span class="market-intel-pill">${escapeHtml(item)}</span>`).join('');
sampleReviewBody.innerHTML = `
<div class="market-intel-empty mb-3">此卡只產生 Telegram dispatch report catalog record run package 預覽API/UI 不讀 token、不寫檔、不執行 CLI、不開 DB、不寫 catalog record、不掛 scheduler。${blockers ? `阻擋:${escapeHtml(blockers)}` : ''}</div>
<div class="market-intel-deploy-grid">
<div>
<p class="market-intel-deploy-section-title">RUN PACKAGE GATES</p>
<div class="market-intel-check-list">${
gates.map(item => `
<div class="market-intel-check">
<div>
<strong>${escapeHtml(item.key)}</strong>
<small>${escapeHtml(item.label)}</small>
</div>
<span>${item.passed ? 'PASS' : 'BLOCK'}</span>
</div>
`).join('') || '<div class="market-intel-empty">尚未提供 run package gate。</div>'
}</div>
</div>
<div>
<p class="market-intel-deploy-section-title">RUN PACKAGE SECTIONS</p>
<div class="market-intel-check-list">${
sections.map(item => `
<div class="market-intel-check">
<div>
<strong>${escapeHtml(item.key)}</strong>
<small>${escapeHtml((item.facts || []).join(' / '))}</small>
</div>
<span>READY</span>
</div>
`).join('') || '<div class="market-intel-empty">尚未提供 run package sections。</div>'
}</div>
</div>
<div>
<p class="market-intel-deploy-section-title">RECORD WRITE</p>
<div class="market-intel-check-list">
${[
['provided', recordWrite.provided],
['mode', recordWrite.mode || 'missing'],
['record_write_passed', recordWrite.catalog_record_write_passed],
['cli_ready', recordWrite.ready_for_market_intel_report_catalog_record_cli_run],
['report_family', recordWrite.target_report_family || 'missing'],
['report_hash', recordWrite.report_output_hash || 'missing'],
['dry_run', recordWrite.catalog_record_write_dry_run_artifact_path_recorded]
].map(([key, value]) => `
<div class="market-intel-check">
<div><strong>${escapeHtml(key)}</strong></div>
<span>${escapeHtml(String(value))}</span>
</div>
`).join('')}
</div>
</div>
<div>
<p class="market-intel-deploy-section-title">PACKAGE INPUT</p>
<div class="market-intel-check-list">
${[
['package_path', operator.report_catalog_record_run_package_artifact_path || 'missing'],
['write_gate_path', operator.report_catalog_record_write_artifact_path_recorded],
['manifest_path', operator.catalog_record_payload_manifest_path_recorded],
['backup', operator.catalog_record_backup_artifact_path_recorded],
['dry_run', operator.catalog_record_write_dry_run_artifact_path_recorded],
['cli_command', operator.catalog_record_cli_command_recorded],
['runtime_clear', operator.operator_confirmed_no_token_in_report_catalog_record_run_package && operator.operator_confirmed_no_api_file_write && operator.operator_confirmed_no_api_catalog_record_write && operator.operator_confirmed_no_api_telegram_dispatch && operator.operator_confirmed_no_api_db_write && operator.operator_confirmed_no_llm_call && operator.operator_confirmed_no_scheduler_attach]
].map(([key, value]) => `
<div class="market-intel-check">
<div><strong>${escapeHtml(key)}</strong></div>
<span>${escapeHtml(String(value))}</span>
</div>
`).join('')}
</div>
</div>
<div>
<p class="market-intel-deploy-section-title">COMMAND / PROMOTION</p>
<div class="market-intel-check-list">
${[
['script', command.script_path || 'missing'],
['api_must_not_execute', command.api_must_not_execute_command],
['manifest_execute_in_api', manifest.execute_in_api],
['next_phase', promotion.next_manual_phase || 'missing'],
['run_readiness_gate', promotion.report_catalog_record_run_readiness_requires_separate_gate],
['commit_gate', promotion.report_catalog_record_commit_requires_separate_gate]
].map(([key, value]) => `
<div class="market-intel-check">
<div><strong>${escapeHtml(key)}</strong></div>
<span>${escapeHtml(String(value))}</span>
</div>
`).join('')}
</div>
</div>
</div>
`;
};
const loadCandidateQueueReviewAiSummaryPersistenceTelegramDispatchReportCatalogRecordRunPackage = async () => {
if (!sampleReviewMeta || !sampleReviewBody || !sampleReviewInput) return;
let parsed;
try {
parsed = JSON.parse(sampleReviewInput.value || '{}');
} catch (error) {
sampleReviewMeta.innerHTML = '<span class="market-intel-pill">json_error</span>';
sampleReviewBody.innerHTML = `<div class="market-intel-empty">JSON 格式錯誤:${escapeHtml(error.message)}</div>`;
return;
}
const body = parsed && parsed.sample_result ? parsed : { sample_result: parsed };
sampleReviewBody.innerHTML = '<div class="market-intel-empty">產生 queue review AI summary Telegram dispatch report catalog record run package 預覽中...</div>';
try {
const response = await fetch(`${sampleCandidateQueueReviewAiSummaryPersistenceTelegramDispatchReportCatalogRecordRunPackageEndpoint}?execute=false&apply_real_write=false`, {
method: 'POST',
credentials: 'same-origin',
headers: {
'Content-Type': 'application/json',
'X-CSRFToken': csrfToken
},
body: JSON.stringify(body)
});
const data = await response.json();
if (!response.ok && !data.mode) throw new Error(`HTTP ${response.status}`);
renderCandidateQueueReviewAiSummaryPersistenceTelegramDispatchReportCatalogRecordRunPackage(data);
} catch (error) {
sampleReviewMeta.innerHTML = '<span class="market-intel-pill">error</span>';
sampleReviewBody.innerHTML = `<div class="market-intel-empty">queue review AI summary Telegram dispatch report catalog record run package 失敗:${escapeHtml(error.message)}</div>`;
}
};
const renderCandidateQueueReviewDecisionWriter = data => {
const blockers = (data.blocked_reasons || []).join(' / ');
const summary = data.statement_summary || {};
@@ -10351,6 +10494,9 @@
if (sampleCandidateQueueReviewAiSummaryPersistenceTelegramDispatchReportCatalogRecordWrite) {
sampleCandidateQueueReviewAiSummaryPersistenceTelegramDispatchReportCatalogRecordWrite.addEventListener('click', loadCandidateQueueReviewAiSummaryPersistenceTelegramDispatchReportCatalogRecordWrite);
}
if (sampleCandidateQueueReviewAiSummaryPersistenceTelegramDispatchReportCatalogRecordRunPackage) {
sampleCandidateQueueReviewAiSummaryPersistenceTelegramDispatchReportCatalogRecordRunPackage.addEventListener('click', loadCandidateQueueReviewAiSummaryPersistenceTelegramDispatchReportCatalogRecordRunPackage);
}
if (schedulerRefresh) {
schedulerRefresh.addEventListener('click', loadScheduler);
}

File diff suppressed because it is too large Load Diff