Files
AirCoding/AirPlan/TODO.md
AirCoding a773bac28c P0-P8: Full V1.0.0 Alpha implementation + audit reports
Implements 123 tasks across 9 phases (T-001..T-809) totaling 146 source files.

Monorepo (P0):
- 7-package Bun + Turborepo + TypeScript monorepo
- dependency-cruiser enforcing 7 forbidden edges + 5 deep-import rules

Contracts (P0):
- 16 type files (ids/error/event/runtime/ipc/task/worker-result/tool/artifact/evidence/project/provider/permission/ui/capability/platform)

Storage & Events (P1):
- DatabaseManager + MigrationRunner (19 tables, 22 indexes, 5 schema_meta seeds)
- 16 repositories (Repository<T,I,U> pattern, INV-1 status columns via EventStore.project only)
- EventSchemaRegistry (54 durable + 7 ephemeral), EventStore, EventBus, EventIngestor
- Project/Session/Artifact/Evidence stores + 8-step Recovery

Tools & Permission (P2):
- PathClassifier (8 categories), CommandRiskAnalyzer (10 categories), SecretRedactor
- PermissionEngine 6-layer evaluation (capability→profile→task_scope→risk→credential→user_prompt)
- ToolRegistry with 20+ tools across fs/shell/git/project/artifact/context/permission/doctor
- CapabilityManifestValidator + CapabilityRegistry

LLM & Context (P3):
- ModelConfigLoader, CapabilityMatrix, AnthropicCanonicalConverter
- AnthropicAdapter + OpenAICompatibleAdapter
- ProviderManager facade
- PromptLayerLoader (L0/L1/L3/L5), CompactionPolicy, ContextAssembler

Worker IPC & Scheduler (P4):
- WorkerProtocol (NDJSON), WorkerProcess (exit codes 0-5), WorkerManager (spawn/handshake)
- WorkerRuntime (INV-3: IPC only, no direct fs/shell/SQLite)
- 5 worker roles (Executor/Reviewer/Debugger/Compactor/ExperienceMiner)
- TaskGraph, WavePlanner, RetryPlanner, AgentMonitor, WorkspaceManager
- Scheduler (state machine), 8-step Recovery

C++ Toolchain (P5):
- DiagnosticParser, CppProjectDetector, CMakeConfigurator, CppBuilder
- CppTestRunner, CppcheckRunner, ClangdClient
- CppToolRegistrar + capability manifest

Projection & TUI (P6):
- ProjectionStore (hydrate/apply/snapshot/subscribe)
- TuiApp + 8 components (Session/Task/Agent/Tool/Diff/Evidence/Permission/Blocker/Hud)
- ProjectionClient in-process ref

Agents & Knowledge (P7):
- MainAgent, ArchitectureDesigner
- DebugKnowledgeStore + LearnedMemoryStore (single-writer, outbox model)
- Role integration wiring

CLI & Doctor & Release (P8):
- Logger + DeveloperLogEncryptor (AES-256-GCM)
- DoctorService (self_bootstrap first)
- RuntimeApp + ServiceRegistry
- 11 CLI commands: run/init/doctor/provider/resume/compact/history/session/restore/e2e/release
- CliEntrypoint + air<TODO>

Audit (in AirPlan/docs/):
- Deepseek开发阶段审计.md (97 findings)
- Opus开发阶段审计.md (140+ findings, 18 P0 blockers)
- MiniMaxM3开发阶段审计.md (18 P0 blockers, focuses on executability)
- AirPlan/TODO.md (technical debt + 42 TODOs by phase)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-02 19:19:55 +08:00

10 KiB
Executable File
Raw Permalink Blame History

AirCoding V1.0.0 Alpha — 技术债务与待办清单

生成于2026-06-02 | 基于全阶段审计结果

P0 — Monorepo 骨架

  • T-001 Monorepo 骨架 (Bun workspaces + Turborepo)
  • T-002..014 合约源文件 (16 个文件)
  • T-015 合约 barrel + 导入边界 lint
  • TODO: 为所有包添加 tsconfig.json paths 别名

P1 — 存储、事件、制品

  • T-101 DatabaseManager
  • T-102 MigrationRunner (17 张表,缺 provider_configs + capability_registry)
  • T-103..119 16 个仓库
  • T-120 SessionStore 聚合
  • T-121..124 事件系统 (SchemaRegistry, EventStore, EventBus, EventIngestor)
  • T-125..129 Project/Session/Artifact/Evidence/Recovery
  • TODO(P1): 向 MigrationRunner 添加 provider_configs 表P3 需要)
  • TODO(P1): 向 MigrationRunner 添加 capability_registry 表P2 需要)
  • TODO(P1): INV-1验证所有 status 列的 UPDATE 只能通过 EventStore.project() 进行 — 5 个仓库已审计并修复
  • TODO(P1): INV-2外键关联断开 — 在应用层强制执行引用完整性

P2 — 工具、权限、能力

  • T-201 PathClassifier (8 个路径类别)
  • T-202 CommandRiskAnalyzer (10 个风险类别)
  • T-203 SecretRedactor
  • T-204 PermissionEngine (6 层评估)
  • T-205 ToolRegistry (分支表)
  • T-206..213 内置工具 (21 个工具定义)
  • T-214 BuiltInToolRegistrar
  • T-215 CapabilityManifestValidator
  • T-216 CapabilityRegistry
  • TODO(P2): 将 CapabilityRegistry 连接到 DoctorService 以进行 INV-4 合规

P3 — 提供者与上下文

  • T-301 ModelConfigLoader
  • T-302 CapabilityMatrix (与合约 ProviderCapabilityMatrix 不同的自定义类型)
  • T-303 AnthropicCanonicalConverter
  • T-304 AnthropicAdapter (移除了 implements ProviderAdapter — 签名不匹配)
  • T-305 OpenAICompatibleAdapter (同上)
  • T-306 ProviderManager (同步方法 vs 合约异步接口)
  • T-307 PromptLayerLoader
  • T-308 内置提示资源 (L0 + 5 个角色提示)
  • T-309 CompactionPolicy
  • T-310 ContextAssembler
  • BUG(P3-1): CapabilityMatrix.ts:本地 ProviderCapability 类型与 contracts/src/provider.ts 完全无关——要么对齐要么移除
  • BUG(P3-2): AnthropicAdapter.ts:70:多余的 from_provider 转换,将 CanonicalMessage[] 强制转换为 unknown[]
  • TODO(P3): ContextAssembler.ts:146-149L6EvidenceStore、L7/L8SessionStore 消息/工具输出)是存根
  • TODO(P3): runtime/src/index.ts 缺少 context/index.js 重新导出(已在 P4 修复中添加)

P4 — Worker IPC 与调度器

  • T-401 WorkerProtocol (NDJSON 编码/解码,方向验证)
  • T-402 WorkerProcess (stdout=协议,退出码 0-5)
  • T-403 WorkerManager (spawn + 握手cancel)
  • T-404 WorkerRuntime (INV-3仅通过 IPC call_tool)
  • T-405..409 Worker 角色 (Executor, Reviewer, Debugger, Compactor, ExperienceMiner)
  • T-410 worker 入口点 (main.ts)
  • T-411 TaskGraph (可运行任务,依赖图,循环检测)
  • T-412 WavePlanner (计划 waves分配工作空间)
  • T-413 RetryPlanner (指数退避的 retry 决策)
  • T-414 WorkspaceManager (创建/合并/清理/GC)
  • T-415 AgentMonitor (心跳 + 超时INV-1 豁免)
  • T-416 Scheduler (状态机INV-5 从 SQLite 重建)
  • T-417 Recovery (8 步序列5 步是存根)
  • T-418 worker-fixture E2E 测试 (存根)
  • BUG(P4-1): Scheduler.ts:146agent_id.split('_')[1] 无法提取 task_id — 已修复
  • BUG(P4-2): Scheduler.ts:128-131DISPATCHING 是无操作 — 已修复
  • BUG(P4-3): Scheduler.ts:任务从未过渡到 'running' — 已修复(添加了 mark_terminal running + AgentMonitor 集成)
  • BUG(P4-4): AgentMonitor.tsremove() 从未被调用 — 已修复(添加了 lost agent 清理)
  • BUG(P4-5): WorkerManager.ts:180-193send_and_wait 是定时休眠,不是真正的等待 — 死代码
  • BUG(P4-6): WorkspaceManager.ts:在合并逻辑运行之前设置状态 — 已修复 INV-1 注释

P5 — C++ 工具链

  • T-501 DiagnosticParser (GCC/Clang 正则,确定性签名)
  • T-502 CppProjectDetector (CMake/Make 检测)
  • T-503 CMakeConfigurator (CMake+Ninjacompile_commands.json)
  • T-504 CppBuilder (构建 + 解析诊断)
  • T-505 CppTestRunner (ctest 运行 + 解析)
  • T-506 CppcheckRunner (cppcheck 调用)
  • T-507 ClangdClient (LSP 客户端存根)
  • T-508 CppToolRegistrar + capability.ts
  • BUG(P5-1): DiagnosticParser.ts:10ParsedDiagnostic 不匹配合约的 Diagnostic 类型(缺少 diagnostic_idcreated_at
  • BUG(P5-2): CppTestRunner.ts:55-58parse_ctest_output 正则完全错误 — 将百分比误认为计数
  • BUG(P5-3): CppcheckRunner.ts:34execSync 命令注入漏洞 —— 用 execFileSync + args 数组替换
  • BUG(P5-4): CMakeConfigurator.ts:39-44execSync 命令注入漏洞
  • BUG(P5-5): CppcheckRunner.ts:34cppcheck 输出的正则表达式是 GCC 格式 — 与 cppcheck 格式不匹配
  • BUG(P5-6): CppProjectDetector.ts:67command_exists() 只检查 /usr/bin/usr/local/bin
  • BUG(P5-7): CppProjectDetector.ts:72find_cpp_sources() 始终返回 []
  • TODO(P5): ClangdClient.ts:26,35:两个方法都是存根 — 实现 LSP JSON-RPC 协议
  • TODO(P5): 合约 Diagnostic 类型:对齐 ParsedDiagnostic 或迁移合约

P6 — 投影与 TUI

  • T-601 ProjectionStore (hydration应用事件订阅)
  • T-602 ProjectionClient + TuiApp
  • T-603..610 8 个 TUI 组件
  • BUG(P6-1): types.ts:10-35SessionProjection/TaskProjection/AgentProjection 不匹配合约投影类型
  • BUG(P6-2): PermissionPrompt.tsx:8-15:使用直接回调,不是 UiCommandChannel违反 INV-3
  • BUG(P6-3): TuiApp.tsx:72-81render() 输出到 console.log — 未使用 OpenTUI
  • BUG(P6-4): TuiApp.tsx:72-81render() 不委托给任何导入的组件(未使用的导入)
  • TODO(P6): 集成 OpenTUI @opentui/* 渲染器npm-dep不要重新实现
  • TODO(P6): 添加 theme/keymap/ 目录T-610
  • TODO(P6): 所有组件返回的是 string 而不是 JSX 元素 — 要么接受要么迁移到 React/JSX

P7 — Agent 集成

  • T-701 MainAgent (状态机,意图分类)
  • T-702 ArchitectureDesigner (影响评估,结果类别)
  • T-703 DebugKnowledgeStore (INV-2 outbox 模型)
  • T-704 LearnedMemoryStore (INV-2 outbox 模型)
  • T-705 Role 集成 wiring
  • T-706 E2E fixtures (direct-mode + architecture-gate)
  • BUG(P7-1): MainAgent.ts:85-93AWAITING_CONFIRMATION 从未被 handle_user_message 设置 — 确认门是死代码
  • BUG(P7-2): wiring.ts:51-52,72-73INV-2 outbox 事件有文档说明但从未发出 — 存根
  • BUG(P7-3): DebugKnowledgeStore.ts:63-71debug.record.created 事件从未发出
  • BUG(P7-4): LearnedMemoryStore.ts:62-69memory.promoted 事件从未发出
  • BUG(P7-5): ArchitectureDesigner.ts:24architecture.impact.completed 事件从未发出
  • TODO(P7): 将 MainAgent 连接到 EventBus/Scheduler 以进行实际的事件驱动状态转换
  • TODO(P7): 在 DebugKnowledgeStore/LearnedMemoryStore 中实现实际的 outbox 事件发出

P8 — CLI、Doctor、发布

  • T-801 Logger + DeveloperLogEncryptor
  • T-802 DoctorService
  • T-803 RuntimeApp + ServiceRegistry + createRuntime + loadConfig
  • T-804..808 CLI 命令 (run, init, doctor, provider, resume, compact, history, session, restore, e2e, release)
  • T-809 CliEntrypoint
  • BUG(P8-1): Logger.ts:36air.developer.log 从未写入 — DeveloperLogEncryptor 已断开连接
  • BUG(P8-2): DeveloperLogEncryptor.ts:32-33:声称 INV-3使用 SecretRedactor但从未导入/调用
  • BUG(P8-3): DeveloperLogEncryptor.ts:22:回退加密密钥硬编码为 'dev-key'
  • BUG(P8-4): RuntimeApp.ts:36-45 vs ServiceRegistry.ts:36-63:并行重复的服务图 — RuntimeApp 未使用 ServiceRegistry
  • BUG(P8-5): RuntimeApp.ts:51-65start() 在 doctor 检查后不启动任何子系统
  • BUG(P8-6): RuntimeApp.ts:70-74shutdown() 是存根 — 不刷新日志、关闭数据库或停止 worker
  • BUG(P8-7): DoctorService.ts:38:没有 read_only 模式(实现计划要求)
  • BUG(P8-8): DoctorService.ts:70-72fix() 是存根 — 不安装依赖(违反 INV-4
  • BUG(P8-9): DoctorService.ts5/7 检查是硬编码的 passed: true 存根
  • BUG(P8-10): ServiceRegistry.ts:缺少 EventBus、EventIngestor、ToolRegistry、PermissionEngine、DatabaseManager
  • BUG(P8-11): createRuntime.ts:24-25:会话/项目 ID 从 Date.now() 生成 — 不从 .air/shared/project.json 加载
  • BUG(P8-12): init.ts:17-57:创建了 .air/local/ 但从未写入 config.json
  • TODO(P8): 所有 CLI 命令:通过 RuntimeApp→ToolRegistry→PermissionEngine 路由副作用INV-3
  • TODO(P8): 命令注入:审查所有 execSync 调用并用 execFileSync + args 数组替换
  • TODO(P8): releaseCommand:带有实际验证套件的存根
  • TODO(P8): e2eCommand:带有硬编码 的存根 — 实现实际验证

跨领域问题

  • TODO: 合约对齐P5Diagnostic, ProviderCapabilityP6投影类型P7事件全部需要与 contracts 包重新同步
  • TODO: INV-2 outbox所有 4 个知识/调试存储声称 outbox 模式但实际上不发出事件 — 在 wiring 或存储层实现事件发出
  • TODO: INV-3 副作用CLI 命令init、doctor和 TUIPermissionPrompt绕过 ToolRegistry+PermissionEngine
  • TODO: 常量枚举capability.ts 使用了错误的枚举值('toolchain'→已修复,'trusted'→已修复)
  • TODO: 安全:所有 execSync 调用需要迁移到 execFileSync + args 数组以防止命令注入
  • TODO: 测试3/4 个 E2E 测试是存根或仅单元测试 — 实现完整的集成测试
  • TODO: 文档:contracts 包需要为所有导出的类型提供 JSDoc