P0-P8: Full V1.0.0 Alpha implementation + audit reports
Implements 123 tasks across 9 phases (T-001..T-809) totaling 146 source files. Monorepo (P0): - 7-package Bun + Turborepo + TypeScript monorepo - dependency-cruiser enforcing 7 forbidden edges + 5 deep-import rules Contracts (P0): - 16 type files (ids/error/event/runtime/ipc/task/worker-result/tool/artifact/evidence/project/provider/permission/ui/capability/platform) Storage & Events (P1): - DatabaseManager + MigrationRunner (19 tables, 22 indexes, 5 schema_meta seeds) - 16 repositories (Repository<T,I,U> pattern, INV-1 status columns via EventStore.project only) - EventSchemaRegistry (54 durable + 7 ephemeral), EventStore, EventBus, EventIngestor - Project/Session/Artifact/Evidence stores + 8-step Recovery Tools & Permission (P2): - PathClassifier (8 categories), CommandRiskAnalyzer (10 categories), SecretRedactor - PermissionEngine 6-layer evaluation (capability→profile→task_scope→risk→credential→user_prompt) - ToolRegistry with 20+ tools across fs/shell/git/project/artifact/context/permission/doctor - CapabilityManifestValidator + CapabilityRegistry LLM & Context (P3): - ModelConfigLoader, CapabilityMatrix, AnthropicCanonicalConverter - AnthropicAdapter + OpenAICompatibleAdapter - ProviderManager facade - PromptLayerLoader (L0/L1/L3/L5), CompactionPolicy, ContextAssembler Worker IPC & Scheduler (P4): - WorkerProtocol (NDJSON), WorkerProcess (exit codes 0-5), WorkerManager (spawn/handshake) - WorkerRuntime (INV-3: IPC only, no direct fs/shell/SQLite) - 5 worker roles (Executor/Reviewer/Debugger/Compactor/ExperienceMiner) - TaskGraph, WavePlanner, RetryPlanner, AgentMonitor, WorkspaceManager - Scheduler (state machine), 8-step Recovery C++ Toolchain (P5): - DiagnosticParser, CppProjectDetector, CMakeConfigurator, CppBuilder - CppTestRunner, CppcheckRunner, ClangdClient - CppToolRegistrar + capability manifest Projection & TUI (P6): - ProjectionStore (hydrate/apply/snapshot/subscribe) - TuiApp + 8 components (Session/Task/Agent/Tool/Diff/Evidence/Permission/Blocker/Hud) - ProjectionClient in-process ref Agents & Knowledge (P7): - MainAgent, ArchitectureDesigner - DebugKnowledgeStore + LearnedMemoryStore (single-writer, outbox model) - Role integration wiring CLI & Doctor & Release (P8): - Logger + DeveloperLogEncryptor (AES-256-GCM) - DoctorService (self_bootstrap first) - RuntimeApp + ServiceRegistry - 11 CLI commands: run/init/doctor/provider/resume/compact/history/session/restore/e2e/release - CliEntrypoint + air<TODO> Audit (in AirPlan/docs/): - Deepseek开发阶段审计.md (97 findings) - Opus开发阶段审计.md (140+ findings, 18 P0 blockers) - MiniMaxM3开发阶段审计.md (18 P0 blockers, focuses on executability) - AirPlan/TODO.md (technical debt + 42 TODOs by phase) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
157
packages/workers/src/WorkerRuntime.ts
Executable file
157
packages/workers/src/WorkerRuntime.ts
Executable file
@@ -0,0 +1,157 @@
|
||||
/**
|
||||
* WorkerRuntime - In-worker side-effect surface
|
||||
*
|
||||
* Implements contracts §10; DD §8.3.
|
||||
* INV-3: workers reach fs/shell/network/SQLite ONLY through parent-mediated tool IPC.
|
||||
*
|
||||
* @module packages/workers/src/WorkerRuntime
|
||||
*/
|
||||
|
||||
export interface WorkerRuntimeConfig {
|
||||
agent_id: string
|
||||
session_id: string
|
||||
}
|
||||
|
||||
export interface ToolCallRequest {
|
||||
call_id: string
|
||||
name: string
|
||||
arguments: Record<string, unknown>
|
||||
}
|
||||
|
||||
export interface ToolCallResult {
|
||||
call_id: string
|
||||
type: 'text' | 'error' | 'artifact'
|
||||
content: Record<string, unknown>
|
||||
}
|
||||
|
||||
export class WorkerRuntime {
|
||||
private agent_id: string
|
||||
private session_id: string
|
||||
private pending_calls: Map<string, { resolve: (r: ToolCallResult) => void; reject: (e: Error) => void }> = new Map()
|
||||
private output: (line: string) => void
|
||||
|
||||
constructor(config: WorkerRuntimeConfig, output: (line: string) => void) {
|
||||
this.agent_id = config.agent_id
|
||||
this.session_id = config.session_id
|
||||
this.output = output
|
||||
}
|
||||
|
||||
/**
|
||||
* Call a tool through the parent process via IPC.
|
||||
* INV-3: This is the ONLY way workers interact with the outside world.
|
||||
*/
|
||||
async call_tool(name: string, args: Record<string, unknown>): Promise<ToolCallResult> {
|
||||
const call_id = crypto.randomUUID()
|
||||
|
||||
const promise = new Promise<ToolCallResult>((resolve, reject) => {
|
||||
this.pending_calls.set(call_id, { resolve, reject })
|
||||
|
||||
// Set timeout
|
||||
setTimeout(() => {
|
||||
this.pending_calls.delete(call_id)
|
||||
reject(new Error(`Tool call timeout: ${name}`))
|
||||
}, 300000) // 5 minutes
|
||||
})
|
||||
|
||||
// Send tool.call via IPC
|
||||
this.send_message('tool.call', {
|
||||
call_id,
|
||||
name,
|
||||
arguments: args
|
||||
})
|
||||
|
||||
return promise
|
||||
}
|
||||
|
||||
/**
|
||||
* Emit an event to the parent.
|
||||
*/
|
||||
emit(type: string, payload: Record<string, unknown>): void {
|
||||
this.send_message('event', { type, ...payload })
|
||||
}
|
||||
|
||||
/**
|
||||
* Create a checkpoint.
|
||||
*/
|
||||
checkpoint(name: string, data?: Record<string, unknown>): void {
|
||||
this.send_message('worker.checkpoint', { name, data })
|
||||
}
|
||||
|
||||
/**
|
||||
* Report worker result to parent.
|
||||
*/
|
||||
async report_result(result: Record<string, unknown>): Promise<void> {
|
||||
this.send_message('worker.result', result)
|
||||
}
|
||||
|
||||
/**
|
||||
* Send heartbeat.
|
||||
*/
|
||||
heartbeat(): void {
|
||||
this.send_message('worker.heartbeat', { timestamp: new Date().toISOString() })
|
||||
}
|
||||
|
||||
/**
|
||||
* Handle incoming message from parent (tool.result, agent.cancel, agent.ping).
|
||||
*/
|
||||
handle_message(type: string, payload: Record<string, unknown>): void {
|
||||
switch (type) {
|
||||
case 'tool.result': {
|
||||
const call_id = payload.call_id as string
|
||||
const pending = this.pending_calls.get(call_id)
|
||||
if (pending) {
|
||||
this.pending_calls.delete(call_id)
|
||||
pending.resolve(payload as unknown as ToolCallResult)
|
||||
}
|
||||
break
|
||||
}
|
||||
|
||||
case 'agent.cancel':
|
||||
// Cancel all pending calls
|
||||
for (const [id, pending] of this.pending_calls) {
|
||||
pending.reject(new Error('Agent cancelled'))
|
||||
this.pending_calls.delete(id)
|
||||
}
|
||||
break
|
||||
|
||||
case 'agent.ping':
|
||||
// Respond to ping
|
||||
this.send_message('worker.heartbeat', { timestamp: new Date().toISOString() })
|
||||
break
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Send ready handshake.
|
||||
*/
|
||||
send_ready(protocol_version: number, worker_version: string): void {
|
||||
this.send_message('worker.ready', {
|
||||
protocol_version,
|
||||
worker_version,
|
||||
agent_id: this.agent_id,
|
||||
session_id: this.session_id
|
||||
})
|
||||
}
|
||||
|
||||
/**
|
||||
* Send error.
|
||||
*/
|
||||
send_error(message: string): void {
|
||||
this.send_message('worker.error', { message })
|
||||
}
|
||||
|
||||
// ============================================================================
|
||||
// Private
|
||||
// ============================================================================
|
||||
|
||||
private send_message(type: string, payload: Record<string, unknown>): void {
|
||||
const msg = {
|
||||
id: crypto.randomUUID(),
|
||||
type,
|
||||
direction: 'worker_to_parent',
|
||||
timestamp: new Date().toISOString(),
|
||||
payload
|
||||
}
|
||||
this.output(JSON.stringify(msg))
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user