Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 8 additions & 2 deletions README.en.md
Original file line number Diff line number Diff line change
Expand Up @@ -61,7 +61,7 @@ The allowed direction is always `TypeScript -> Go -> LLM/Rust/Docker`. TypeScrip
| Models and context | Mock, Anthropic-compatible, OpenAI-compatible, and loopback-only Ollama providers, routing, qualification, capability probing, streaming, compaction, hierarchical project instructions, explicit user/project memory, and Session continuity trees |
| Planning and collaboration | Plan/Delivery, work items, notes, up to two core children, 1/2/4/6 read-only fan-out tiers, shared budgets and cancellation |
| Tools and permissions | Tool Gateway, JSON Schema validation, Policy, Scope, human approval, four host-permission tiers, fixed commands, an ordinary-mode Run-owned command runtime, per-command PowerShell/Git Bash approval, and time-bound Debug terminal input |
| Code workflows | Native folder selection and Workspace import, workspace browsing, repository state/history, diff review, file-edit proposals, verification plans, Code Journey, and Handoff |
| Code workflows | Native folder selection and Workspace import, workspace browsing, repository state/history, diff review, file-edit proposals, transactional Workspace Checkpoints, Undo/Redo/Rewind, independent Forks, verification plans, Code Journey, and Handoff |
| Observability | Append-only Run events, Live Activity, public model commentary, Harness facts, Artifacts, Findings/Evidence/Reports, and SARIF |
| Extension seams | Mode-aware inert Skill packages, human-reviewed generated candidates, Provider and Tool interfaces, Go/Rust JSON protocol, embedded WASI Analyzer, Sandbox contracts, and a network-none Docker product execution that is disabled by default |
| Clients | `cyberagent` CLI, Bubble Tea TUI, authenticated HTTP/OpenAPI, React/Vite, and Windows/macOS Desktop portable preview |
Expand All @@ -79,6 +79,12 @@ Schema v115 introduces `agent-code-tools.v1`, allowing the root Supervisor to co

Read results are deterministically ordered, paginated, and bounded. Root escape, casing aliases, hidden entries outside the Go allowlist (`.github` is the sole code-evidence exception), ignored entries, links or reparse points, binary/non-UTF-8 data, and oversized files fail closed. `workspace_change` creates replace/create/move proposals only; `workspace_delete` is a separate exactly confirmed deletion proposal; `workspace_apply` can apply only an approved exact revision and rechecks source and destination hashes to detect review-time drift. Calls, results or refusals, authority snapshots, budget charges, and bounded Artifacts enter the resumable Supervisor ledger. `cyberagent run show <run-id>`, the Run Detail API, and the Desktop Run page expose the current generation and per-tool availability. This protocol grants no Shell, Git, network, or Sandbox authority. See the [Usage Guide](docs/usage.md) and [ADR 0116](docs/adr/0116-model-callable-workspace-tools.md).

### Transactional Workspace Checkpoints

Schema v117 `workspace-checkpoint.v1` records immutable checkpoints before and after file tools, Run-owned command batches/background Jobs, typed Git writes, and the agent-merge boundary. Each checkpoint binds the base commit, branch, raw Git index, a deterministic tracked/untracked manifest, content hashes, trigger receipt, attempt/capability generation, and recovery grade. Ordinary file and index bytes are deduplicated by SHA-256; ignored, generated, large, sensitive-looking, linked, and external state is represented explicitly instead of being silently advertised as recoverable. Because no portable filesystem watcher is installed, Shell boundaries are explicitly `partial` and cover only observed Workspace/Git state, not effects outside the root.

The Desktop **Workspace Checkpoints** tab, `cyberagent workspace checkpoint ...`, and authenticated OpenAPI routes call the same Application service. Rewind, Undo, and Redo first perform a live/current/target three-way preview, then require the exact cursor CAS and current authority. A restore is a new append-only write: it does not rewrite history, invoke `git reset --hard`, or blanket-delete untracked files. Fork creates a distinct Git worktree, Workspace, Mission/Run/Session, and does not inherit approval, credential, capability, lease, process, or network authority. HTTP/Desktop neither accept nor return an absolute worktree path; Go derives a deterministic sibling from the trusted source Workspace. See [Workspace Checkpoints](docs/workspace-checkpoints.md) and [ADR 0118](docs/adr/0118-transactional-workspace-checkpoints.md).

### Real Git, PowerShell, and Bash

Prayu invokes real Git and operating-system shells; it is not a command emulator. It deliberately does not give the model a permanent, unreviewed raw terminal. The Code workflow separates execution by risk:
Expand All @@ -98,7 +104,7 @@ Every `debug_terminal` write still passes Shell Policy; commands that require se
### Security boundaries

- Provider-private thinking, raw prompts, raw deltas, tool arguments, raw tool output, and API keys are never exposed as public activity.
- Project instructions, long-term memory, and checkpoints are always untrusted, non-authorizing context. Fork/Resume never restores approvals, capabilities, credentials, network access, processes, terminal leases, or execution profiles. See the [bilingual context, threat-model, and deletion guide](docs/context-continuity.md) and [ADR 0115](docs/adr/0115-non-authorizing-durable-context-continuity.md).
- Project instructions, long-term memory, and conversation checkpoints are always untrusted, non-authorizing context; Workspace Checkpoints retain bounded file/index state only. Neither kind of Fork/Resume restores approvals, capabilities, credentials, network access, processes, terminal leases, or execution profiles. See the [bilingual context, threat-model, and deletion guide](docs/context-continuity.md), [Workspace Checkpoints](docs/workspace-checkpoints.md), [ADR 0115](docs/adr/0115-non-authorizing-durable-context-continuity.md), and [ADR 0118](docs/adr/0118-transactional-workspace-checkpoints.md).
- File edits, host commands, browser CDP, terminal input, and Sandbox execution are independent authorization surfaces.
- The ordinary command runtime accepts only `network=disabled` and `credentials=none`, clears credential-helper/profile/high-risk environment paths, and rejects explicit network intent. It is not a provable OS network sandbox: `full_access` remains host execution, and a command that needs network access must use a separate per-call reviewed path.
- Conservative commands use Go-owned fixed templates. PowerShell/Bash is available only through one of three independent paths: the Code/Deliver/root + `full_access` Run-owned runtime, per-command approval, or a revocable Debug lease. General host execution and Debug authority cannot be enabled by a model, Skill, or repository document.
Expand Down
13 changes: 10 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -61,7 +61,7 @@ CLI / TUI / React / Windows Desktop / CI
| 模型与上下文 | Mock、Anthropic-compatible、OpenAI-compatible 与 loopback-only Ollama Provider、模型路由、资格校验、能力探测、流式响应、上下文压缩、层级项目指令、显式 user/project 长期记忆与 Session 恢复树 |
| 计划与协作 | Plan/Delivery、工作项、备注、最多两个核心 child、1/2/4/6 档只读 Fan-out、共享预算与取消扇出 |
| 工具与权限 | Tool Gateway、JSON Schema 校验、Policy、Scope、人工审批、四档宿主权限、受控固定命令、普通模式 Run-owned 命令运行时、逐条审批 PowerShell/Git Bash,以及限时 Debug 终端输入 |
| 代码工作流 | 系统目录选择与 Workspace 导入、工作区浏览、仓库状态、提交历史、Diff 审阅、文件编辑提案、验证计划、Code Journey 与 Handoff |
| 代码工作流 | 系统目录选择与 Workspace 导入、工作区浏览、仓库状态、提交历史、Diff 审阅、文件编辑提案、事务化 Workspace Checkpoint、Undo/Redo/Rewind、独立 Fork、验证计划、Code Journey 与 Handoff |
| 可观测性 | 追加式 Run 事件、Live Activity、公开模型进度、Harness 事实、Artifact、Finding/Evidence/Report、SARIF |
| 扩展 | 模式感知的惰性 Skill 包、生成候选人工审查、Provider/Tool 接口、Go/Rust JSON 协议、内嵌 WASI Analyzer、Sandbox 合同与默认关闭的 network-none Docker 产品执行 |
| 客户端 | `cyberagent` CLI、Bubble Tea TUI、认证 HTTP/OpenAPI、React/Vite、Windows/macOS Desktop 便携预览 |
Expand All @@ -79,6 +79,12 @@ Schema v115 引入 `agent-code-tools.v1`,让 root Supervisor 能在真实 Work

只读结果稳定排序、分页且有界,并拒绝根目录逃逸、大小写别名、未列入 Go allowlist 的隐藏项(仅 `.github` 作为代码证据开放)、忽略项、链接或重解析点、二进制、非 UTF-8 与超限文件。`workspace_change` 只创建 replace/create/move 提案;`workspace_delete` 是独立、需精确确认的删除提案;`workspace_apply` 只能应用已经批准的精确版本,并重新检查原文件与目标文件哈希,避免审阅后内容漂移。每次调用、结果/拒绝、authority 快照、预算消耗与有界 Artifact 都进入可恢复 Supervisor 账本。`cyberagent run show <run-id>`、Run Detail API 和 Desktop Run 页面可查看当前 generation、逐工具可用性与拒绝原因。该协议不授予 Shell、Git、网络或 Sandbox 权限;完整设计见[使用手册](docs/usage.md)和 [ADR 0116](docs/adr/0116-model-callable-workspace-tools.md)。

### 事务化 Workspace Checkpoint

Schema v117 的 `workspace-checkpoint.v1` 在文件工具、Run-owned 命令批次/后台 Job、typed Git 写入与 agent merge 边界前后记录不可变检查点。检查点固定 base commit、branch、原始 Git index、稳定排序的 tracked/untracked manifest、内容哈希、触发收据、attempt/capability generation 与恢复等级;普通文件和 index 以 SHA-256 内容寻址去重,ignored/generated/large/sensitive/link/external 状态会显式标记而不是静默承诺可恢复。Shell 没有可移植 watcher,因此其边界明确降级为 `partial`,只承诺观测到的 Workspace/Git 状态,不宣称回滚根目录外副作用。

Desktop 的 **工作区检查点 / Checkpoints**、CLI 的 `cyberagent workspace checkpoint ...` 和认证 OpenAPI 共用同一个 Application 服务。Rewind、Undo、Redo 先做 live/current/target 三方预览,再以精确 cursor CAS 和当前权限确认写入;恢复本身是一次新的追加式写操作,不改写旧历史、不调用 `git reset --hard`、不批量清理 untracked 文件。Fork 从历史检查点建立独立 Git worktree、Workspace、Mission/Run/Session,且不继承审批、凭据、capability、lease、进程或网络授权;HTTP/Desktop 不接受或返回绝对 worktree 路径,由 Go 从受信源 Workspace 确定性生成同级目标。完整操作说明见 [Workspace Checkpoints](docs/workspace-checkpoints.md),设计与失败语义见 [ADR 0118](docs/adr/0118-transactional-workspace-checkpoints.md)。

### 真实 Git、PowerShell 与 Bash

Prayu 调用真实的 Git 和操作系统 Shell,不是命令模拟器;但它也不会给模型一个永久、无审阅的裸终端。当前 Code 工作流按风险拆成以下入口:
Expand All @@ -98,7 +104,7 @@ Prayu 调用真实的 Git 和操作系统 Shell,不是命令模拟器;但它
### 安全边界

- 不公开 Provider 私有 thinking、原始 Prompt、raw delta、工具参数、工具原始输出或 API key。
- 项目指令、长期记忆和 Checkpoint 始终是不可信、非授权上下文;Fork/Resume 不恢复审批、capability、凭据、网络、进程、终端租约或执行档位。详见[双语上下文/威胁模型与删除说明](docs/context-continuity.md)和 [ADR 0115](docs/adr/0115-non-authorizing-durable-context-continuity.md)。
- 项目指令、长期记忆和对话 Checkpoint 始终是不可信、非授权上下文;Workspace Checkpoint 只保存有界文件/index 状态。两类 Fork/Resume 都不恢复审批、capability、凭据、网络、进程、终端租约或执行档位。详见[双语上下文/威胁模型与删除说明](docs/context-continuity.md)、[Workspace Checkpoints](docs/workspace-checkpoints.md)、[ADR 0115](docs/adr/0115-non-authorizing-durable-context-continuity.md)和 [ADR 0118](docs/adr/0118-transactional-workspace-checkpoints.md)。
- 文件编辑、宿主命令、浏览器 CDP、终端输入和 Sandbox 是彼此独立的授权面。
- 普通命令运行时只接受 `network=disabled` 与 `credentials=none`,清空 credential helper/Profile/高风险环境入口并拒绝显式网络意图;它不是可证明的 OS 网络沙箱,`full_access` 仍是宿主执行能力,需要联网的命令必须改走独立逐次审阅路径。
- 受控命令默认使用 Go 固定模板;PowerShell/Bash 只通过 Code/Deliver/root + `full_access` 的 Run-owned runtime、逐条审批,或可撤销 Debug 租约三条独立路径开放。通用宿主执行与 Debug 能力不会因模型、Skill 或仓库文档而自动开启。
Expand Down Expand Up @@ -322,7 +328,7 @@ Get-AuthenticodeSignature .\PrayuDesktop.msix | Format-List Status, StatusMessag
完整逐切片原始记录保留在 [`PROGRESS_BOOK.md`](docs/PROGRESS_BOOK.md),当前检查点与验收证据保留在 [`PROJECT_STATUS.md`](docs/PROJECT_STATUS.md),恢复上下文见 [`PROJECT_MEMORY.md`](docs/PROJECT_MEMORY.md)。这些账本是历史记录,不应被当作待重新执行的任务列表。

<details>
<summary><strong>SQLite Schema v1-v116 迁移审计表 / Migration ledger</strong></summary>
<summary><strong>SQLite Schema v1-v117 迁移审计表 / Migration ledger</strong></summary>

此表是 Store 防漏迁移测试使用的审计合同。新增 schema 时必须按顺序追加,不得改写或删除既有行。

Expand Down Expand Up @@ -444,6 +450,7 @@ Get-AuthenticodeSignature .\PrayuDesktop.msix | Format-List Status, StatusMessag
| v114 | 层级项目指令快照、显式长期记忆与非授权会话连续性树 | hierarchical project-instruction snapshots, explicit long-term memory, and non-authorizing session continuity trees |
| v115 | 模型可调用的工作区工具与哈希保护文件变更 | model-callable workspace tools and hash-guarded file mutations |
| v116 | 增加 Run-owned command-runtime.v2 Job 与 Supervisor 调用账本 | add Run-owned command-runtime.v2 jobs and Supervisor call ledger support |
| v117 | 增加事务化 workspace-checkpoint.v1、恢复/Fork 账本与内容寻址 blob | add transactional workspace-checkpoint.v1, restore/Fork ledger, and content-addressed blobs |

</details>

Expand Down
1 change: 1 addition & 0 deletions docs/DESKTOP_TEST_MATRIX.md
Original file line number Diff line number Diff line change
Expand Up @@ -52,6 +52,7 @@
- [ ] 长对话滚动
- [ ] Markdown 渲染
- [ ] Live Activity / 事件流
- [ ] 工作区检查点:时间线来源/恢复等级、Rewind 三方预览、冲突禁用、显式确认、Fork 后切换独立 Run
- [ ] 审批队列
- [ ] 设置页(含"高度敏感权限"Full CDP 标签)

Expand Down
34 changes: 31 additions & 3 deletions docs/PROJECT_MEMORY.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,37 @@

> Scope checkpoint (2026-08-13): continue only the general-purpose Agent Harness and Code workflow. CTF-specific solving/offensive automation is an optional add-on with no active slices; retain generic extension seams only. Historical Cyber percentages are not current planning metrics. See [PRODUCT_SCOPE.md](PRODUCT_SCOPE.md).

Last updated: 2026-08-15

## Current Single-Slice Checkpoint: Structured Dependency Waiting / Issue #50
Last updated: 2026-08-19

## Current Single-Slice Checkpoint: Transactional Workspace Checkpoints / Issue #101

2026-08-19 的 issue #101 落地 `workspace-checkpoint.v1`(ADR 0118,schema v117)。每个
检查点不可变绑定 Run/Mission/Session/Workspace、attempt/capability generation、触发收据、
parent/cursor、规范根指纹、base commit/branch、原始 Git index 与稳定 tracked/untracked
manifest;普通文件/index 以 SHA-256 内容寻址去重。固定上限为 20,000 entries、4 MiB/
file、32 MiB/index、64 MiB/checkpoint、2,000 preview changes、256 conflicts、2 GiB
全局 blob store。ignored/generated/large/sensitive/link/reparse/special/unreadable/external
都显式标记;没有静态加密声明,疑似敏感文件不会写入 blob。SQLite sealing/refcount/
immutability/GC/quota trigger 与 schema v1-v116 downgrade chain 均已覆盖测试。

FileEdit 与 `agent-code-tools.v1` 写入、Run-owned command foreground/background、typed Git
写入以及未来 agent merge writer 共用 operation-keyed before/after boundary。Shell 没有
portable watcher,因此即便 in-root bytes 可存储也明确为 partial;根外、registry/service/
network side effects 不在恢复承诺中。Preview 比较 reviewed cursor、target 与 freshly
captured live state;external edit、dirty index、root/branch/commit/case/link drift 都冲突。
Undo/Redo/Rewind 是 append-only 新写,要求 paused Code/Deliver、active Session、无 live
execution lease、当前权限/进程 capability、显式 operator 与 exact CAS cursor,不使用
`git reset --hard` 或 blanket untracked deletion。

Fork 创建并验证独立 Git worktree/branch,再原子注册 Workspace/Mission/Run/Session/events/
continuity node;只复制目标 bytes/index,不继承 permission/profile authority、approval、
credential、capability、lease、terminal/process/network grant,source cursor 不变。启动时
reconciliation 关闭普通 interrupted boundary、只在 identity/authority/cursor 仍匹配时恢复
prepared restore,并完成已注册但 checkpoint 尚未落盘的 Fork 而不复制 worktree。CLI、
OpenAPI 与 Desktop Checkpoints tab 共用 Application 服务。不要把 conversation continuity
checkpoint 当成 Workspace bytes,也不要把 Workspace restore 当成历史 authority 恢复。

## Previous Single-Slice Checkpoint: Structured Dependency Waiting / Issue #50

2026-08-15 的 issue #50 落地结构化依赖等待(ADR 0102,schema v101)。`agent_dependency_edges`
持久化版本化 wait edge(source/target/reason/deadline/generation/failure_policy,
Expand Down
Loading