Skip to content

[REQ-128][CODE] 激活 Agent、managed Plugin、secret/workspace MCP mixed Bundle #697

Description

@jinjunnn

Outcome

在所有 enabling prerequisites 已落地后,把 Agent、managed Plugin、secret/workspace MCP
作为一个mixed Bundle,经一次digest-bound admission、一次transaction与一个
PackageLedgerMutationV1原子激活。

Covers

alpha-work#49 AC5。builder抽取已拆到#705,V3到#706,secret prepared到#712。

Solution baseline

Accepted REQ-128 baseline
§2.7–§2.9。

Development plan

  1. 消费web compiler已flatten的root+leaf graph;nested Bundle门前拒,不runtime递归。
  2. 用[REQ-128][CODE] 抽取 Bundle 共用 planning builders 与 health probe router #705 builders/router构造Agent、[REQ-128][CODE] 安装并预检 managed OpenCode Plugin artifact #699 managed Plugin、[REQ-128][CODE] 将 MCP secret version 作为 prepared resource 纳入 Bundle #712 secret/workspace MCP
    与既有Skill/Cloud items。
  3. required child全有或全无;已策展但host unsupported optional child在preview/receipt
    精确skip。
  4. 所有items在[REQ-128][CODE] 绑定 package 授权、认证与事务 admission #713 admission后一次进入runExtensionTransaction;Plugin probe在授权后、
    switch前执行。
  5. child不独立commit ledger;root只提交[REQ-128][CODE] 切换 BundleGraph V3 ledger、claim set 与全部 writer #706 mutation。
  6. capability扩大被拒、probe失败、crash时旧Bundle generation继续健康。

Acceptance and named gates

  • canonical mixed Bundle:Skill + Agent + managed Plugin + secret MCP +
    curated host-unsupported optional child。
  • download/secret populate/config/probe/root receipt及全部 TX_CRASH_POINTS fault matrix;
    始终全旧或全新。
  • production wiring经过真实ext-ipc recovery options,不只测helper。
  • 无secret orphan、无double load、无child-only record、optional原因preview=receipt。
  • packaged evidence:真实mixed install→restart→hook/tool→uninstall。

Dependencies

Blocked by alpha-code#705、#706、#712、#699、#713。

Out of scope

graph update/uninstall(#698)、nested Bundle、npm runtime install、第二套installer。

Exit condition

Merged activation PR + fault/crash/packaged evidence + docs同步。

Activity

  1. added
    type:featureNew user or system capability
    prio:P1High-value near-term delivery
    area:dataPersistence or data quality
    area:runtimeServices, jobs, infrastructure, or operations
    area:securitySecurity or access control
    source:skill-auditOriginated from a skill or repository audit
    on Jul 30, 2026
  2. self-assigned this
    on Jul 30, 2026
  3. changed the title [-][REQ-128][CODE] 将 Agent、Plugin、secret/workspace MCP 纳入 Bundle 原子事务[/-] [+][REQ-128][CODE] 激活 Agent、managed Plugin、secret/workspace MCP mixed Bundle[/+] on Jul 30, 2026
  4. jinjunnn commented on Aug 1, 2026

    @jinjunnn
    OwnerAuthor

    追加:safe view 的 components[] / skipReasonCode 今天无人渲染、无文案(第 5 跳的一部分)

    来自 alpha-code#749 PR #751 的独立复验(2026-07-31):

    #749 已让安全视图带上逐组件的 components[](含 role / required / included /
    skipReasonCode)。但实测:

    • rg skipReasonCode packages/ui-mac/src/renderer 零命中
      (extension-detail.tsx:325 的 .components 是 SBOM,无关);
    • 三个 skip token 在 en.ts / zh.ts 里没有任何文案。

    ⇒ §4.3 那条「让用户在每一步被告知同一件事」的动机,今天在任何一步都还没兑现。
    #749 的 AC 只要求 safe view 带上,没要求渲染,所以这不是它的欠账 —— 它属于本票的第 5 跳
    (详情页显示 root + 各 leaf 的 required / optional / skipped)。

    另一处同源、原报告没提的:授权确认屏也是一个 preview。
    packagePlanPreview(main/package-admission.ts)的 items[] 今天只含 root,
    不含任何 skipped 组件信息。方案 §4.3 里「preview 与 receipt 逐字相同」那句话中的 preview,
    指的是 catalog safe view,不是用户真正点"确认"的那个面。本票要把两个 preview 面都覆盖到,
    否则用户在确认屏上看不到"这个包里有组件不会被装"。

    本票退出门追加:

    • 详情页渲染逐组件行,skipped 组件显示具名原因(en/zh 文案齐全);
    • 授权确认屏的 items[] 含 skipped 组件及其原因;
    • 一条断言:三个面(safe view / 确认屏 / receipt)对同一个 skipped 组件给出的原因逐字相同。
  5. added 5 commits that reference this issue on Aug 1, 2026
  6. added a commit that references this issue on Aug 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:dataPersistence or data qualityarea:runtimeServices, jobs, infrastructure, or operationsarea:securitySecurity or access controlprio:P1High-value near-term deliverysource:skill-auditOriginated from a skill or repository audittype:featureNew user or system capability

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions