P0-P8: Full V1.0.0 Alpha implementation + audit reports

Implements 123 tasks across 9 phases (T-001..T-809) totaling 146 source files.

Monorepo (P0):
- 7-package Bun + Turborepo + TypeScript monorepo
- dependency-cruiser enforcing 7 forbidden edges + 5 deep-import rules

Contracts (P0):
- 16 type files (ids/error/event/runtime/ipc/task/worker-result/tool/artifact/evidence/project/provider/permission/ui/capability/platform)

Storage & Events (P1):
- DatabaseManager + MigrationRunner (19 tables, 22 indexes, 5 schema_meta seeds)
- 16 repositories (Repository<T,I,U> pattern, INV-1 status columns via EventStore.project only)
- EventSchemaRegistry (54 durable + 7 ephemeral), EventStore, EventBus, EventIngestor
- Project/Session/Artifact/Evidence stores + 8-step Recovery

Tools & Permission (P2):
- PathClassifier (8 categories), CommandRiskAnalyzer (10 categories), SecretRedactor
- PermissionEngine 6-layer evaluation (capability→profile→task_scope→risk→credential→user_prompt)
- ToolRegistry with 20+ tools across fs/shell/git/project/artifact/context/permission/doctor
- CapabilityManifestValidator + CapabilityRegistry

LLM & Context (P3):
- ModelConfigLoader, CapabilityMatrix, AnthropicCanonicalConverter
- AnthropicAdapter + OpenAICompatibleAdapter
- ProviderManager facade
- PromptLayerLoader (L0/L1/L3/L5), CompactionPolicy, ContextAssembler

Worker IPC & Scheduler (P4):
- WorkerProtocol (NDJSON), WorkerProcess (exit codes 0-5), WorkerManager (spawn/handshake)
- WorkerRuntime (INV-3: IPC only, no direct fs/shell/SQLite)
- 5 worker roles (Executor/Reviewer/Debugger/Compactor/ExperienceMiner)
- TaskGraph, WavePlanner, RetryPlanner, AgentMonitor, WorkspaceManager
- Scheduler (state machine), 8-step Recovery

C++ Toolchain (P5):
- DiagnosticParser, CppProjectDetector, CMakeConfigurator, CppBuilder
- CppTestRunner, CppcheckRunner, ClangdClient
- CppToolRegistrar + capability manifest

Projection & TUI (P6):
- ProjectionStore (hydrate/apply/snapshot/subscribe)
- TuiApp + 8 components (Session/Task/Agent/Tool/Diff/Evidence/Permission/Blocker/Hud)
- ProjectionClient in-process ref

Agents & Knowledge (P7):
- MainAgent, ArchitectureDesigner
- DebugKnowledgeStore + LearnedMemoryStore (single-writer, outbox model)
- Role integration wiring

CLI & Doctor & Release (P8):
- Logger + DeveloperLogEncryptor (AES-256-GCM)
- DoctorService (self_bootstrap first)
- RuntimeApp + ServiceRegistry
- 11 CLI commands: run/init/doctor/provider/resume/compact/history/session/restore/e2e/release
- CliEntrypoint + air<TODO>

Audit (in AirPlan/docs/):
- Deepseek开发阶段审计.md (97 findings)
- Opus开发阶段审计.md (140+ findings, 18 P0 blockers)
- MiniMaxM3开发阶段审计.md (18 P0 blockers, focuses on executability)
- AirPlan/TODO.md (technical debt + 42 TODOs by phase)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
AirCoding
2026-06-02 19:19:55 +08:00
parent 071283df8f
commit a773bac28c
179 changed files with 21855 additions and 0 deletions

View File

@@ -0,0 +1,157 @@
/**
* WorkerRuntime - In-worker side-effect surface
*
* Implements contracts §10; DD §8.3.
* INV-3: workers reach fs/shell/network/SQLite ONLY through parent-mediated tool IPC.
*
* @module packages/workers/src/WorkerRuntime
*/
export interface WorkerRuntimeConfig {
agent_id: string
session_id: string
}
export interface ToolCallRequest {
call_id: string
name: string
arguments: Record<string, unknown>
}
export interface ToolCallResult {
call_id: string
type: 'text' | 'error' | 'artifact'
content: Record<string, unknown>
}
export class WorkerRuntime {
private agent_id: string
private session_id: string
private pending_calls: Map<string, { resolve: (r: ToolCallResult) => void; reject: (e: Error) => void }> = new Map()
private output: (line: string) => void
constructor(config: WorkerRuntimeConfig, output: (line: string) => void) {
this.agent_id = config.agent_id
this.session_id = config.session_id
this.output = output
}
/**
* Call a tool through the parent process via IPC.
* INV-3: This is the ONLY way workers interact with the outside world.
*/
async call_tool(name: string, args: Record<string, unknown>): Promise<ToolCallResult> {
const call_id = crypto.randomUUID()
const promise = new Promise<ToolCallResult>((resolve, reject) => {
this.pending_calls.set(call_id, { resolve, reject })
// Set timeout
setTimeout(() => {
this.pending_calls.delete(call_id)
reject(new Error(`Tool call timeout: ${name}`))
}, 300000) // 5 minutes
})
// Send tool.call via IPC
this.send_message('tool.call', {
call_id,
name,
arguments: args
})
return promise
}
/**
* Emit an event to the parent.
*/
emit(type: string, payload: Record<string, unknown>): void {
this.send_message('event', { type, ...payload })
}
/**
* Create a checkpoint.
*/
checkpoint(name: string, data?: Record<string, unknown>): void {
this.send_message('worker.checkpoint', { name, data })
}
/**
* Report worker result to parent.
*/
async report_result(result: Record<string, unknown>): Promise<void> {
this.send_message('worker.result', result)
}
/**
* Send heartbeat.
*/
heartbeat(): void {
this.send_message('worker.heartbeat', { timestamp: new Date().toISOString() })
}
/**
* Handle incoming message from parent (tool.result, agent.cancel, agent.ping).
*/
handle_message(type: string, payload: Record<string, unknown>): void {
switch (type) {
case 'tool.result': {
const call_id = payload.call_id as string
const pending = this.pending_calls.get(call_id)
if (pending) {
this.pending_calls.delete(call_id)
pending.resolve(payload as unknown as ToolCallResult)
}
break
}
case 'agent.cancel':
// Cancel all pending calls
for (const [id, pending] of this.pending_calls) {
pending.reject(new Error('Agent cancelled'))
this.pending_calls.delete(id)
}
break
case 'agent.ping':
// Respond to ping
this.send_message('worker.heartbeat', { timestamp: new Date().toISOString() })
break
}
}
/**
* Send ready handshake.
*/
send_ready(protocol_version: number, worker_version: string): void {
this.send_message('worker.ready', {
protocol_version,
worker_version,
agent_id: this.agent_id,
session_id: this.session_id
})
}
/**
* Send error.
*/
send_error(message: string): void {
this.send_message('worker.error', { message })
}
// ============================================================================
// Private
// ============================================================================
private send_message(type: string, payload: Record<string, unknown>): void {
const msg = {
id: crypto.randomUUID(),
type,
direction: 'worker_to_parent',
timestamp: new Date().toISOString(),
payload
}
this.output(JSON.stringify(msg))
}
}