Skip to content

同步本地主线:上游合并、撞号重定版、深链导航与 portal α.4 外网登录修复(60 提交 / 162 文件 / 36 个 tag) - #4

Open
hkluoji-lab wants to merge 80 commits into
techflag:mainfrom
hkluoji-lab:main
Open

hkluoji-lab wants to merge 80 commits into
techflag:mainfrom
hkluoji-lab:main

Conversation

@hkluoji-lab

Copy link
Copy Markdown

内容

  • 合并上游 de5077b(合并基点 f00e273),冲突按既定策略保留本地导航决策:未实现入口保留侧栏行并标「(待开放)」,已实现页面由所属插件自持入口
  • 撞号重定版:root 0.1.0-alpha.8、bundle alpha.50、skills alpha.32、office alpha.8、workbench alpha.13、library alpha.3
  • 修复 ?workdsh-view= 深链冷启动被官方首次导航恢复清空
  • 探针外观断言改为官方主题契约
  • 依赖统一锁定 alpha.2 基线,lockfile 重生成

验证(真实执行)

  • pnpm install / build / typecheck 均通过
  • check:plan PASS、check:versions PASS(513 条锁定 alpha.2)
  • test:integration 110/110、test:planning 2/2、test:activity 14/14、test:office:csv 2/2、test:office:content 21/21、probe:install 三段 PASS

已知未通过(如实登记)

  • probe:browser 停在第 162 行后的 mcp-client(playwright-mcp) 同 Host 重名阻塞(非本 PR 引入)
  • probe:experts 既有未通过

24 个 tag 已同步到 fork https://github.com/hkluoji-lab/workdsh ,PR 不携带 tag 对象。

证据见 docs/STATUS.md 顶部小节。

techflag and others added 30 commits September 16, 2026 16:10
Replace the WorkDSH label rendered by the public sidebar.brand.name slot
with DSH JOB AI, leaving the mark, the owner and the test id untouched.
The browser probe assertion follows the new visible text, and the bundle
module version moves to 0.1.0-alpha.46 with a changelog entry.
Refresh docs/deepseek-harness-docs against tag dsh-v0.1.6-alpha.1 so the
mirror matches the pinned release (530 files, verified file by file),
follow the upstream rename of the code-runtime page to ptc-runtime and
unify the remaining 0.1.5-rc.1 references in docs and on the website.

Drop the pnpm overrides for the three package names retired in this
version line; the resolved lock already used their replacements, so the
installed tree is unchanged. The version check now also fails when an
override points at a package that no longer resolves, which is how the
stale entries went unnoticed.
Move the documented and scripted preview address off 18989 so the local
preview matches the address actually in use; WORKDSH_PREVIEW_PORT still
overrides it.
合并远端 v0.1.0-alpha.5 线(专家团韧性验收、PPT 原生画布坐标修正、office/activity/contracts 更新)
与本地 DSH 0.1.6-alpha.1 线(文档镜像同步、退役包名清理、品牌 DSH JOB AI、预览端口 3031)。

docs/STATUS.md 冲突按倒序流水账规则解决:远端两节(16:14 前)在前,本地四节在后,两边内容全部保留。
README.md、README.zh-CN.md、package.json 自动合并。
…lanned module

左侧「助理」此前只是 workbench 通过官方 sidebar.panellist 贡献的展示占位。
ADR-0027 将其定义为引用型工作入口包:只承担职责描述与技能、专家、连接器实例的
引用,不拥有执行、会话、凭据、数据与权限。本地文件继续由原生工作区与 office
内容服务承担;唤起本机应用或小程序只能经官方 computer-use 或显式授权命令并经过
审批;出站写入遵守 ADR-0007 的审批与回执边界;入站机器人常驻服务属部署形态,
不在业务插件内自建。

新增 P1-12 任务定义与 packages/plugins/assistant 规划骨架(README 与目录占位,
无 package.json、无加载入口)。不修改 development-order.json,P1-12 保持未排期,
D00—D15 门槛与顺序不变。
…deps as a graph

用户确认 P1-12 按独立模块推进,排在 D08 之后,并纳入首期集成与组合验收,
必须在 D10 之前完成。development-order 追加 D16(dependsOn [D08]),
D10 的依赖改为 [D09, D16],lastReconciled 更新为 2026-09-16。

为在不重编号 D00—D15 的前提下表达该约束,依赖由线性链放宽为显式图,
currentStep 改为按依赖就绪判定;步骤数不少于 16 与编号连续性的断言保留。
两者必须同批落地,否则旧校验器会拒绝新的依赖声明。
An aborted fetch does not always reject with DOMException AbortError:
when the plugin lifetime ends (dispose or dev module reload) or a request
is superseded, the browser can reject with a TypeError: Failed to fetch
that carries no code at all. The management client and its callers only
classified failures by error type, so every normal cancellation was
logged and surfaced as a skill service fault on the skills page.

Attribute transport failures by our own signal state first (timeout, then
cancelled) and fall back to the error type, keep server-side business
errors out of the transport catch, and let the panel hold a single
in-flight read that aborts its superseded request while revalidation
waits for it.

Verified with typecheck, build, preview:install (byte-compared), the
skills probe (8 PASS) and a browser run: no module console output on a
cold load or after repeated refresh and tab switching, all requests 200.
…aries

- probe:experts installed six tarballs with --offline into a fresh mkdtemp
  HOME, which cannot resolve transitive packages on a clean machine; use
  --prefer-offline like the other packaged probes.
- BusinessPanel gains a required `boundary` field so each planned entry
  names its own development step, missing data and one real next step
  instead of sharing hard-coded placeholder text.
- expose the skill catalog builder as `catalog:build` and document the
  marketplace image contract it requires.
The second Session created in one Host fails inside the official
browser-use MCP mount: the mcp__playwright-mcp__* registrations land in
the global tool layer, so the second agent collides on the same server
name and sessionController.create rejects with gateway/internal.

Recorded evidence: the official log lines (the default exporter only
buffers in memory), the ternary branch in dsh-tools/dsh-system-prompt
that identifies a global-layer duplicate, the two dsh-scope module
instances the Host resolves, the controlled probe that reproduces the
invisible scope tag, the dependency declaration that creates the second
copy, and the bundle insert that mounts the official browser plugins.

Also re-aligns the module/step ledger with the released module versions
and adds the boundary note for the planned assistant entry pack.
The Trae credential popup now hands git a working token, but Gitee
answers 403 Access denied for techflag/workdsh, and the techflag account
cannot be signed into from this machine. The ten local commits therefore
stay local until the repository owner grants write access or another
authorised account is used, so stop retrying the push.

Also corrects the earlier note that claimed the Trae askpass IPC never
responds from a terminal: it did respond, and 403 was the real failure.
The repeated `/plugins/events` failures on dsh.10ge.cn are not a deployment
defect: the endpoint is an SSE stream that goes idle after the handshake, and
the office egress path silently clears it every ~120-127s. Six A/B probes
(Cloudflare x gzip x client x TCP keepalive) plus 70 server-side
`canceled by remote` events in 3h place the cause outside dsh, Caddy and the
tunnel. The retry noise is the client's expected backoff; `/modlens/config`
403 is loopback-only by design and needs no fix.

Record the read-only statistics device started to confirm this over >=24h
(hourly cron, `/var/lib/dsh-sse-watch/`); no production config was changed and
no heartbeat relay was added.

Also record why `git pull --tags origin main` kept failing: the repo sets
neither `pull.rebase` nor `pull.ff`, so the divergence was resolved with an
explicit `--no-rebase` merge instead of touching git config.
The GitHub credential on this machine has no write access to
techflag/workdsh and the Gitee remote has no stored credential, so the
only available return channel was a fork pull request. Records the three
remote locations, the three-way review of the four files both sides
touched, the verification chain on the merged tree, and the two traps
hit on the way (git add -u for the ignored /docs/, and the missing
pull.rebase/pull.ff).
ADR-0028 fixes the ownership and boundary of the idle-heartbeat relay
between dsh and Caddy, so /plugins/events stops being reclaimed by the
office egress at ~127s. STATUS records the derived-only deployment, the
byte-exact smoke and public-endpoint evidence, the browser-side checks,
and the two cancellations that remain unexplained.
…library panel to its plugin

Sidebar entries for 助理/项目/定时任务/更多 pointed at placeholder main panels, and
the library row collided with the panel the library plugin registers.

- workbench only registers a `main` occupant for its own `pending` entries, so
  `workdsh-library` is owned by workdsh-plugin-library alone.
- those four entries carry a structured reason and the currently usable path; the
  sidebar label gets a 待开放 suffix, since the official `sidebar.panellist`
  contract exposes no disabled semantics.
- bundle 0.1.0-alpha.47, workbench 0.1.0-alpha.11; probe assertion follows the labels.
- record the deployment, the container registry constraint, and the profile-layer
  computer-use disable in STATUS and the dsh-10ge-ops skill.
- /modlens/config 403 定位为第三方插件 @liustack/modlens 的 loopback-only 同源防线:
  容器内 Host=127.0.0.1:3080 → 200、Host=dsh.10ge.cn → 403,非 WorkDSH 缺陷,不改其代码。
- 本地预览 profile 补装 workdsh-plugin-library(11 → 12 项依赖)后复验:
  1440×1000 实测导航六项逐字一致、资料库为真实页面(网格 292px 868px)、
  四个待开放入口渲染徽标与原因,pageerror/console error 均 0,无 layout.selectPanel 报错。
- 登记新发现(未修改):仅装 bundle 不装 library 时,「资料库」入口无 main 面板会抛错。
工作台此前无条件注册「资料库」侧栏行,而 main 面板 key workdsh-library 归
workdsh-plugin-library;只装组合包不装资料库时点击该行会抛
layout.selectPanel: main panel "workdsh-library" is not registered。

- 侧栏行改由拥有该 main 面板的插件注册:library 自持 sidebar.panellist
  (id workdsh-library / label 资料库 / order 50),workbench 只登记四项未实现入口
- businessPanels 的 pending 改为必填,main 与 sidebar 行成对注册
- library 补 @deepseek-ai/dsh-client-ui-sidebar 开发依赖(缺它时 sidebar.panellist
  不在槽位联合类型里,构建报 TS2769)
- 版本:workbench alpha.12 / library alpha.2 / bundle alpha.48(组合包与资料库需同批安装)
- probe-browser 重写技能页陈旧断言,并说明 probe:browser 仍被 Host 侧 MCP 会话创建阻塞
bundle alpha.48 + library alpha.2 已装到线上 web profile 并重启:健康检查
healthy、插件加载错误 0;真实浏览器复验导航六项(资料库@y=280)与资料库
页面 292px 868px 正常,selectPanel 报错 0。同时登记 lingshu-bridge 缺
python 的既有现象(非本轮引入,未处理)。
线上 dsh 容器 rootfs 只读、镜像内无 python,第三方插件
@furongjun1999/dsh-memory 的 md_cg 桥 spawn python ENOENT,重试 8 次后
进入 failed 终态。改为把 python-build-standalone 落在持久挂载
/data/dsh/tools/python3.11、把插件自带 md_cg 链入其 site-packages,并在
profile cordis.patch.yml 指定 config.python;重启后子进程持续存活、
00:34 之后无任何 lingshu-bridge 错误行。
逐包解包比对 sha256:10 个 workdsh 包中 8 个与线上完全一致,skills 仅
package.json 依赖键顺序不同,office 的 client.browser.js 为唯一实质差异
(本地 65,204,471 B vs 线上 65,068,085 B)。上传覆盖后用 pnpm add 触发
重新解包(install/--force 均判定 up to date),校验线上产物 sha256 与本地
一致,重启后健康、office 接口 200。同时登记 pnpm 不重算 file: integrity
与旧制品被同名覆盖两条遗留。
本地 3031 直接读开发机 ~/.agents/skills(23 个用户技能 + 6 个内置 = 29),
线上 /data/dsh/home/.agents/skills 为空,15 个全是内置(6 WorkDSH + 9 univer/vision)。
整包同步 23 个用户技能到该持久目录并重启,线上复验 38 个(23 manageable + 15 readonly)。
官方 sidebar.brand.mark 的 owner props 是 SidebarBrandMarkOwnerProps,本次由
workdsh-ui 的 LogoMark 换成自绘 SVG 字标:1/眼球/G/E 共用同一光学高度,眼球
用 24 齿虹膜环 + 白色巩膜 + 蓝色虹膜 + 深瞳 + 高光构成;环取 currentColor,
避免固定浅灰环在浅色主题侧栏上消失。官方模块加载器不提供静态资源路由,故以
纯 SVG 内联,不引入位图资源、不新增资源目录。

名称 DSH JOB AI 与两个席位的 owner props 未改动;LogoMark 仍导出。
版本 0.1.0-alpha.48 -> alpha.49,MODULE-VERSIONS 与 CHANGELOG 同步。
- 侧栏品牌位换成 10GE 字标(bundle alpha.49):本地构建与预览安装、线上真实
  客户端几何复验、三方同源 sha256、部署步骤与未执行项。
- 线上 502:@awiki/dsh-plugin 与官方 0.1.6-alpha.1 不兼容,ESM 具名导入失败使
  整棵插件树启动失败;按 computer-use 先例在 profile patch 层禁用其条目后恢复。
- minimumReleaseAge:定位为 pnpm 11 内置默认值(24h),exclude 条目由 pnpm
  自身写入且同名条目被首条遮蔽;去重后线上校验安装 exit=0。
复验确认品牌位 10GE 环在浅色调色板下可见(对比度 11.94:1),
并定位到应用锁定深色源于 workdsh-client 的主题注册与回切,
故浅色数据取自 DOM 级调色板替换而非应用内真实切换。
客户端只保留注册壳,打开文档时才经 /workdsh-office/runtime.js 注入
office-runtime.js 与 editor.html;两者由插件自己的 ctx.webServer 前缀路由托管
(白名单 + ETag + must-revalidate)。运行时入口经 kernel client 模块表
物化,故 inject 需声明 "modules"。

体积与首屏:dist/client.browser.js 65.2MB → 16,677 B;首屏插件字节
16,450,968 B,零 /workdsh-office/ 请求。线上三条路径复验:docx/pptx/xlsx
编辑器分别在 25.0s/30.1s/20.0s 打开且可编辑。模块版本 0.1.0-alpha.6。

STATUS 同时记录:容器两次停机经查实为外部 docker restart(优雅 SIGTERM、
约 2 秒窗口、当日 Container Id 未变、OOMKilled=false),并逐项排除看门狗、
1Panel 定时任务、tunnel/sse 脚本与 sudo 记录;复验测试数据(8 个会话、
3 条 Office 记录、2 个导出文件及相关簿记)已备份后清理,仅保留审计历史引用。
插件随包技能落在依赖包目录内,不在可管理根,面板只能渲染成禁用的「关」
且无法停用。改为在注册表层抑制:新增 suppression provider 与
.workdsh-state/skills/suppressed.json,list/detail/setEnabled 识别
origin='plugin' 来源,开关走真实启停并禁止改写包内文件。
pnpm 对未决的生命周期脚本会写入字面量 "set this to true or false"
(pnpm #11535);该占位一旦留下就会永久阻断后续所有审批。安装脚本原来
只声明 protobufjs 一项,其余交给 pnpm 追问,线上因此累积了六个占位值。

改为按锁定 Harness 版本声明完整决定表,写入时合并重复 allowBuilds 块、
保留其他来源的显式审批、丢弃无布尔值的陈旧条目,使重复执行幂等。
luoji and others added 5 commits September 24, 2026 07:05
线上首次上「收敛注入」(α.53 只到本地候选)并上线助理入口;同批按原版本号
重发压缩后的自有 client 制品,线上下发口径自有 client raw 857,294 → 497,569 B
(约 −42%)。bundle 与 assistant 必须同批安装,否则「助理」入口消失。

详见 docs/STATUS.md 2026-09-24(续十一):10 步窗口实测、首次运行哈希清单路径
bug 触发自动回滚(回滚链路首次真实验证)、官方 `dsh plugin add --offline` 三次
EACCES 失败后回退 `pnpm add`、浏览器级复验(侧栏未替换、面板真渲染、能力选择器
技能 34/专家 12/连接器 3 分组、创建→详情→编辑→归档全链路、0 个 selectPanel 报错)。
线上历史部署窗口曾以 root 直接跑 pnpm,在 data/dsh 与 data/workspace
留下 160,967 个 root:root 条目,导致官方 CLI 以 uid 1000 访问时 EACCES。
归一属主后官方 dsh plugin add --offline 恢复可用,并已实测复验无回归。
按用户裁决删除 /tmp 脚本与 profile 备份,保留属主备份与上传目录。
verifyPassword 原先是两次 scryptSync,会阻塞与 Caddy forward_auth 共用的
单线程事件循环——任何一次登录都会让同进程内所有并发请求排队等 KDF。改为
promisify(scrypt) 提交到 libuv 线程池;常量时间比较与「两侧都过 KDF」的
安全语义不变。

容器内 A/B 实测(Node v24.21.0,6 并发登录 / 12 次 KDF,默认线程池 4):
事件循环最长阻塞 321.1ms → 1.9ms,墙钟 319.8ms → 91.3ms。单测 6/6,
容器内与公网 forward_auth 链路复验通过,已就地部署(alpha.2 → alpha.3)。

STATUS 续十三同时登记同批体检项:P1-3 容器资源上限(12C / 8G / pids 4096,
含 compose 不能写顶层 pids_limit 的陷阱)、P2-3 宿主 HTTP/3 接收缓冲
(rmem_max 212992 → 16777216)、P2-4 按「挂载点 + entrypoint + 运行进程」
三判据删除陈旧树(data/dsh 8.8G → 8.0G)、P2-1 判定无需修复(该镜像 Caddy
无 brotli 编码器,但 CF 边缘已对 CSS/JS 下发更小的 br)。
外网用户反馈用配置口径完全正确的口令仍被提示密码错。线上排查:同一凭据
从公网实测可登录,`login.blocked` 为 0,失败的 10 次请求与成功的 7 次请求
来源 IP 都被记成隧道主机地址——说明问题不在凭据本身,而在"看着一样、字节
不同"的输入差异,以及限流分桶退化这两个可复现的缺陷。

- 凭据归一化:全角符号(U+FF01—U+FF5E)折叠为半角、去首尾空白(含 U+3000),
  提交值与配置值走同一函数后比较;不做大小写折叠、不做截断
- 失败限流改按真实客户端 IP 分桶:优先取 cf-connecting-ip。此前取
  X-Forwarded-For,经 Cloudflare 隧道时恒为隧道主机地址,全站共用一个桶,
  任何一人失败十次即可让所有人 15 分钟登不上
- 新增 accounts.json 账号表承载额外成员账号;官方只提供一组口令,多账号在
  官方侧没有落点。文件缺失/写坏只告警不锁站,主账号仍可用
- 会话签名密钥由全部账号派生,账号增删改即让既有会话失效
- 失败日志只登记输入形态(pwLength / pwFullWidth / usernameNormalized),
  不落任何凭据内容
- 登录页补充"符号请用英文半角输入"提示
- 新增账号表契约测试(含缺失/写坏/重复/只配一半官方口令四类容错)

验证:单测 12/12 通过;容器内备用端口预演全绿后切换;公网复验门禁 7 项、
双账号成功与失败路径全部符合预期;修复后失败日志的 ip 已是真实终端地址。
@hkluoji-lab hkluoji-lab changed the title 同步本地主线:合并 GitHub 上游、撞号重定版与深链导航修复(37 提交 / 24 个 tag) 同步本地主线:上游合并、撞号重定版、深链导航与 portal α.4 外网登录修复(59 提交 / 160 文件 / 24 个 tag) Sep 24, 2026
@hkluoji-lab hkluoji-lab changed the title 同步本地主线:上游合并、撞号重定版、深链导航与 portal α.4 外网登录修复(59 提交 / 160 文件 / 24 个 tag) 同步本地主线:上游合并、撞号重定版、深链导航与 portal α.4 外网登录修复(59 提交 / 160 文件 / 36 个 tag) Sep 24, 2026
用户反馈「从模板创建」只有 5 个模板并询问是否还有其他模板。核查确认模板的唯一
真源是 project-manager.ts 的硬编码数组,PROJECT-DESIGN 7.1.1 只规定交互、未定义
清单,5 个即全部,因此按用户裁决扩充而非补漏。

- 新增 10 个:内容营销与社媒运营、客户跟进与商机管理、数据分析与经营报表、
  活动策划与执行、招投标与解决方案、招聘与人才选拔、培训与课程开发、
  财务预算与成本核算、品牌与视觉设计、网站建设与 SEO 增长。
- 语义不变:模板仍是纯预填数据(名称、场景描述、初始指令),不自动执行、
  不预先绑定专家或技能、不改变项目权限语义。
- 版本 0.1.0-alpha.3 → 0.1.0-alpha.4;模块版本线仍 0.1。

验证:模块内 10/10 测试通过;增量部署 dsh.10ge.cn 后浏览器级复验为「项目」面板
15 张模板卡片、新建项目弹框模板下拉 16 项(1 占位 + 15),页面零错误。
@hkluoji-lab hkluoji-lab changed the title 同步本地主线:上游合并、撞号重定版、深链导航与 portal α.4 外网登录修复(59 提交 / 160 文件 / 36 个 tag) 同步本地主线:上游合并、撞号重定版、深链导航与 portal α.4 外网登录修复(60 提交 / 162 文件 / 36 个 tag) Sep 24, 2026
luoji added 6 commits September 25, 2026 08:50
依赖面(两批合并落地)
- DSH 整族 0.1.6-alpha.2 → 0.1.7-alpha.1 → 0.1.7-alpha.2:根 devDependencies 中
  23 条 DSH、pnpm.overrides 271 条 DSH、13 个模块 package.json 全部精确锁版
- Cordis 4.0.2 → 4.0.4,并同批升 5 个伴生包(group 1.0.4 / loader 1.0.5 /
  include 1.0.9 / timer 1.1.6 / schemastery 3.18.4):官方在 alpha.2 把 caret 收紧
  为 tilde,单独升 Cordis 会 peer 冲突
- 改名 1 条:dsh-agent-presets 按官方移除,改由 dsh-agent-preset +
  dsh-agent-preset-registry 承载(服务名 agentPresets)

alpha.1 批次实现面
- experts:预设改经官方 AgentPresetRegistry 注册,并由 ctx.effect 释放
- activity:事件投影适配 Session 格式 V4(tool 消息一等化、subagentCatalog)
- office:文档预览退为 builtin 备选,WorkDSH 编辑器保留为「打开方式」入口
- 主题语义 token 统一 --dsw-alias-*
- 预览安装链把根 pnpm.overrides 投影进 Profile,避免 caret 浮到 rc 通道

文档
- 新增官方文档镜像 docs/dsh-v0.1.7-alpha.1/ 与 docs/dsh-v0.1.7-alpha.2/
- 新增两批升级证据 docs/evidence/dsh-0.1.7-alpha.1-upgrade.md 与
  docs/evidence/dsh-0.1.7-alpha.2-upgrade.md
- 基线表述与镜像路径重锚:AGENTS.md、HARNESS-OFFICIAL-DEVELOPMENT.md、
  MODULE-VERSIONS、corpusRoot、6 个包 README、22 文件 60 处镜像路径 token

0.1.7-alpha.2 门禁实测
- check:versions PASS:539 条锁定 0.1.7-alpha.2,Cordis 4.0.4 only
- typecheck / build / check:plan / audit:harness-docs 退出码均为 0
- 单测 127/127(integration 111、activity 14、planning 2)
- 探针 7 项全绿:theme / settings / activity / install / skills / experts / office:native

线上 dsh.10ge.cn 未动,仍为 0.1.7-alpha.1:本批先把升级落在仓库。
- STATUS 续二十:把「未提交、未推送」改为实际结果——合并提交 c8a05e1
  (1263 文件 / +1687541 −5657)、push fork main(9b8215a070..c8a05e1)、
  PR techflag#4 head 自动跟随(仍 dirty,为既有冲突)
- 登记 .gitignore 第 15 行 /docs/ 的处置:按用户裁决 git add -f 强加两批证据
  与两份官方文档镜像;加 alpha.1 镜像的理由是 19 个已跟踪 docs 文件共 26 处引用它
- MODULE-VERSIONS 与升级证据同步该结果;线上 dsh.10ge.cn 仍未动,未发布 npm
按用户指令执行上线部署(d3 备份 → d4 新树 → d5 Phase 1 → d6 换树 → d7 复验全绿),
线上现役 0.1.7-alpha.2(Cordis 4.0.4)。补记:STATUS 新增「续二十一」台账节、
MODULE-VERSIONS 新增 2026-09-25 更新(四)、证据文档新增「线上切换与复验」章节
与回退锚点;换树后 1 次负载相关 SIGSEGV 已隔离并登记为边界(上游已知 V8 缺陷)。
线上无可复现的业务 500;唯一真实缺陷是门户(3083) 与 Caddy 并行拉起、
Caddy 不等后端就绪导致的启动期 502 竞态(表现为重启/换版后首次访问偶发
失败、刷新即恢复)。已在 entrypoint 的 `caddy run` 之前插入
wait_for_port() 门禁并线上复验(150s 打压 0×5xx),此处同步门户部署手册
与项目台账,含备份锚点、派生脚本、判据与运行期残留窗口说明。
提交时只禁用按钮、没有复位路径:一次未完成的提交(网络中断、边缘 502、或
页面被 bfcache 恢复)会让按钮永久停在禁用态,之后怎么点都不发请求、不跳转、
也不报错,现场表现即「输入账号密码点了完全没反应」——服务端全量日志里连一条
login.failed 都没有,说明 POST 根本没离开浏览器。

- site/portal.js:提交后 12 秒看门狗复位并提示「网络无响应,请重试。」;
  pageshow(persisted) 同样复位;错误提示按父级作用域复用既有 .form-error
  (服务端注入的那条是 form 的兄弟节点),避免同页出现两条提示。
- src/server.mjs:styles.css / portal.js 由 public, max-age=3600 收紧为
  no-cache,文件名无内容指纹时盲缓存会让新旧行为并存最长 1 小时。
- README 同步缓存口径并登记自愈一节;STATUS 登记「续二十三」。
会话 Cookie 带 Secure,在 http 页面会被浏览器拒绝保存:登录实际成功,
会话存不下来,之后 / 判未登录即 302 回门户首页。手机端高发,因为安卓
自带浏览器与 Chrome 在地址栏输入裸域名默认补 http://。

线上 Caddyfile 追加 @insecure_scheme 规则(只在 CF 明确透传 http 时
301,头缺失不跳)与 /__portal_scheme_probe 诊断端点;README 登记规则、
三个 Caddy 实测坑、备份回滚与验收实测,STATUS 记录判据分流与真实
安卓 Chrome 端到端 5/5 PASS。
luoji and others added 14 commits September 29, 2026 22:30
将仓库侧版本承载面从 0.1.7-alpha.2 收敛到官方 latest 0.1.7-rc.2,与线上
运行面(续二十一/续二十七)对齐;不 bump 任何业务模块版本,不含业务逻辑改动。

- 版本承载:根 package.json 与 14 个模块 package.json 的 DSH 依赖、pnpm.overrides
  (279+5 条,新增 dsh-client-shortcuts / dsh-client-ui-shortcuts /
  dsh-llm-deepseek-account / dsh-llm-deepseek-api-key / dsh-util-code-language)
  统一 0.1.7-rc.2;pnpm-lock.yaml 重生成。
- peer 重指:8 插件(activity/assistant/connectors/experts/library/office/projects/skills)
  dsh peer 由精确 alpha.2 改为 caret ^0.1.7-rc.2,共 75 条。
  (automations 未部署、workbench/bundle 无 dsh peer,不在范围。)
- 镜像与文档:rc.2 官方文档镜像 docs/dsh-v0.1.7-rc.2(569 文件)落盘,24 处镜像路径
  token 与 corpusRoot 重锚;补入此前从未入库的 docs/DSH-0.1.7-alpha.1-UPGRADE-PLAN.md
  (HEAD 版 STATUS.md 已引用其 6 处)。
- 脚本/测试:check-published-versions.mjs 与 pack-*/probe-* 共 8 脚本、
  project-installer.test.mjs 硬编码版本同步。
- 证据与台账:docs/evidence/dsh-0.1.7-rc.2-upgrade.md、MODULE-VERSIONS、AGENTS.md
  基线声明、STATUS 续二十七/续二十八两节。

门禁(在本提交快照上实测):
- node scripts/check-plan.mjs → PASS: 31 modules; 50 documents
- node scripts/check-published-versions.mjs → PASS: 550 DSH lock entries pinned to 0.1.7-rc.2
- typecheck / build 13 包退出码 0(批次内执行)
未执行:0.2.0-rc 通道交叉验证;npm 发布面(whoami/publish 受阻,保留制品形态)。
登记 D12 定时任务模块的在建骨架与设计/探针证据。**本模块未完成**:D12 在
development-order.json 仍为 todo,模块未接入 build/typecheck 的 13 个 filter,
不得视为已实现能力。

- 契约:packages/contracts 新增 ./automations 子路径(四对象 AutomationRule /
  ScheduleOccurrence / AutomationRun / WebhookDelivery),0.1.0-alpha.10 → alpha.11。
- 插件:packages/plugins/automations 领域与调度骨架(domain/scheduler/services/
  storage,含 owner 唯一性与 loop),cordis.patch.yml 与 tsconfig;tests 两个 mjs。
- 探针与脚本:scripts/probe-automation-bases.mjs(P-AU-1~4)、build-automations.mjs;
  根 package.json 增 probe:automations。
- 设计与证据:docs/design/automations(PRD/UX/CONTRACTS/ACCEPTANCE/README)、
  docs/evidence/automations-bases-probe.md、docs/modules.json 登记 moduleVersion 0.1。
- 未做:未声明 dsh.bundle、未提供可加载 exports 的假成功;未改 PLAN/development-order
  排期;未 bump 模块版本;未发布;线上未动。
收口台账:记录提交 1(1fb8e18bb2 rc.2 基线随升)/ 提交 2(c440cfe639 automations
在建骨架 WIP)的拆分边界、文件数与门禁复跑;修正续二十八「未提交未推送」为已入库
已推送;并登记 automations 未完成口径与 alpha.1 遗留计划归属。
按用户裁决「按方案 (b) 执行 0.2.x 适配,先重出插件制品并自建派生镜像」执行首批适配:

- 基线承载:根与 14 模块 package.json 自 0.1.7-rc.2 切至 0.2.0-rc.2;pnpm.overrides
  289 条(281 dsh = 280 rc.2 + 1 例外 dsh-typert-generator 0.2.0-rc.1,8 非 dsh);
  devDependencies 32 条(23 dsh,同一例外);12 manifest 的 dsh peer 96 条全 caret;
  pnpm-lock 重解析为 rc.2(3284 行,0.1.7-rc.2 残留 0 行)。
- 制品重出:8 个 tgz 置于 .artifacts/0.2.0-rc.2-release(未入库,含 release-manifest
  与 SHA256SUMS,校验 8/8 OK),保持 local-artifact 形态,不发布 npm。
- 派生镜像:1panel/deepseek-harness:0.2.0-rc.2-localbuild-patched 在服务器本地构建
  与验证(healthy / inner3080=200 / Exit=0 / Restarts=0)。定界 401 根因:base 镜像内
  1Panel 自打的 dsh-client-connection auth-proxy 补丁在整树替换 node_modules 后丢失,
  派生镜像等价重放该补丁。生产容器全程未动,未部署、未接入编排。
- 附属同步:AGENTS.md 3 处、7 脚本 10 处、6 README 9 处、1 测试 1 处硬编码版本改
  0.2.0-rc.2;文档镜像路径等 3 处历史引用有意保留。
- 证据与台账:新增 docs/evidence/dsh-0.2.0-rc.2-upgrade.md;STATUS 补登「续三十」。
- 门禁:check-published-versions PASS(559 条锁定 0.2.0-rc.2;Cordis 4.0.4 only);
  check-plan PASS(31 modules; 50 documents)。
证据文档扩为十节,新增「十、线上升级部署」记录 Phase1 12 制品重装、
Phase2 换树与双份 auth 补丁、升级后三层健康与存量数据未改写,并修正
前五/六/七/八节及结论中「未部署」的过时表述;STATUS 新增续三十一节。

升级中暴露并已修复:identity-portal 失实 peer(业务面回归)、4 个第三方
bundle 门禁跳过(dshmarket/agent-teams/mcp-connector 升级 + builtin-browser 移除)。
问题1 公告 ACK 无法保存:dsh-app-boot 物理双副本致 profile reload 抛
requires the root Include entry,profile 副本根 include 兜底后落盘
welcomeNoticeVersion=2026-09-28.1(补丁 sha 与本地复算逐字节一致、revision=1)。
问题2 自动化任务消失:ui-schedule 原为悬空行,改为正式 insert 后首页预载
恢复含 @deepseek-ai/dsh-client-ui-schedule(200/305008B,含 sidebar.panellist)。
未执行项如实登记:浏览器真人复测、全局侧三包补丁、兜底脚本入库。
用户要求去掉 LOGO 中的 DSH 前缀,文案由 `DSH 企业AI工作台` 改为 `企业AI工作台`。
文案缩短后(18px 自然宽约 112px)回归官方默认排版 18px/600/line-height 24px,
不再需要 α.56 的 14px 收缩,与左侧 24px 高 10GE 字标形成字号与明度层次。

仍显式保留 nowrap/ellipsis/max-width,避免官方 `.brandName` 无 nowrap 时换行被
`.brand{overflow:hidden}` 裁切;颜色回到单层官方语义 token,未引入第二套主题。
GeWordmark 字标、席位、owner props、priority 与官方 Sidebar owner 均未改动。

线上实测:brandText="企业AI工作台"、lines=1、overflowPx=0、fontSize=18px/
fontWeight=600,旧文案命中 0;容器 healthy、restarts=0、/ =302、/login =200。

同步 probe-browser.mjs 品牌断言;STATUS 登记部署踩坑——容器内 pnpm install 会
剥离 dsh-client-connection 的 ONEPANEL_DSH_AUTH_PROXY 补丁,导致就绪探针超时
exit 1 与全站 502,须在 install 后校验 md5 69f8b3ef85e03eed4f0e8ac4295c61c5。
- 根 package.json overrides 296+ 条 0.2.0-rc.2 → 0.2.1-alpha.2,cordis 家族 5 条切 alpha 通道
- 14 个模块 package.json dsh 依赖全量切 alpha.2;pnpm-lock 全量重解析;check-published-versions 期望值随升
- STATUS 登记续四十/四十一:线上换树 + profile 重装 + --force-recreate + 门禁/存量/业务面回归全绿
- agent-teams 经 dsh plugin allow-version 豁免后激活(compatibility.json 9 条)
- 补交 library 0.1.0-alpha.4 遗留:import 分支 source 透传 + 客户端 origin 参数 + CHANGELOG/MODULE-VERSIONS
- 独立插件 workdsh-plugin-drive@0.1.0-alpha.1:domain(per-record nodes/files/revisions/receipts) + session/event 自动捕获(user/message 附件引用、deliverables/presented 字节归档,receipts 幂等)+ drive-manager(归档/搜索/会话聚合/重命名/移动/删除/配额) + 7 个 Agent 工具 + Remote /api/workdsh-drive
- client:sidebar.panellist「网盘」order=55 + 配对 main 页面 + 三栏筛选/面包屑/搜索/上传/预览/操作菜单 + 会话预览 tab;bundle α.58 productViews 登记 drive 映射
- 探针验证 4/4 通过(生命周期/幂等/两主体两组织授权矩阵/捕获幂等/remote 转发);typecheck/build/check-plan PASS;浏览器实测侧栏「网盘」入口、页面渲染与自动化任务导航正常
- 台账:STATUS 续四十四、development-order D18 证据、modules.json 登记、PLUGIN-DELIVERY 复用记录;部署线上(drive+bundle α.58 已装并激活)
- 全文内容搜索:文本类文件归档建降采样内容索引(textIndex),search 按文件名+正文匹配,正文命中返回上下文片段;修复捕获路径 mediaType 恒为 application/octet-stream 导致索引对真实文件从不生效(按扩展名推断文本类型)
- 回收站与恢复:侧栏新增入口,删除→回收站→恢复→彻底删除闭环,删除文案改为「移入回收站」
- 配额:sidebar footer 展示真实「已用 X / 总量 Y」
- 修复预览无返回入口:预览头新增「← 返回列表」
- 验证:drive test 4/4、check-plan PASS;线上(dsh.10ge.cn)真实模型端到端通过(模型生成并交付文件→自动归档→正文标记词搜索命中 excerpt;回收站删除恢复闭环;服务端确认 textIndex 收录)
- 证据:docs/evidence/drive-plugin-alpha2.md

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant