Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/),

### Added

- Added preview-first host Adapters for Codex, Claude Code, and Kimi Code CLI, with pinned public contracts, App-owned ownership manifests, exact logical Diff, explicit confirmation, host discovery verification, drift protection, and rollback without changing File/Git knowledge authority.
- Added an explicitly started, loopback-only, read-only OPC Dashboard for project status, acceptance, knowledge governance, manager queue, lineage evidence, and provider health.
- Added fixed-field privacy projection, safe optional-provider degradation, synthetic demo data, and local server security gates without introducing Node, a database, or remote assets.
- Added evidence-gated capability evolution for versioned repository roles, Skills, and organization policies, with exact Git provenance, paired bounded pilots, manager and independent-QA approvals, one-path unstaged promotion/rollback, explicit commit confirmation, v0.1 compatibility, and private auditable history.
Expand Down
8 changes: 8 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -88,6 +88,13 @@ preserve project `.opc`, File/Git knowledge, Git history, user configuration,
and Mem0 data. See [OPC App](docs/opc-app.en.md) for the product, installation,
privacy, and recovery contract.

The App also exposes a preview-first Adapters page for already installed Codex,
Claude Code, and Kimi Code CLI hosts. Codex reuses the existing Marketplace
lifecycle, Claude uses its public plugin CLI when the pinned version is safe,
and Kimi manages only its documented user Skill projection while non-interactive
Plugin management remains blocked. See [Host Adapters](docs/host-adapters.md)
for the capability matrix, limits, ownership rules, and independent QA steps.

### Compatible local Dashboard

The `main` branch includes an explicitly started, loopback-only, read-only Dashboard for manager visibility. It is not part of stable `v0.1.0`, does not scan for projects, and has no approval or promotion actions:
Expand Down Expand Up @@ -193,6 +200,7 @@ Capability evolution is an evidence-gated private lifecycle for versioned roles,
| [Capability evolution](docs/capability-evolution.md) | Versioned role/Skill/policy pilots, evidence gates, one-path Git handoff, observation, and rollback |
| [OPC Dashboard](docs/opc-dashboard.md) | Explicitly started local read-only manager view, data semantics, security boundaries, and limitations |
| [OPC App](docs/opc-app.en.md) | Independent local control plane, App-owned settings, install lifecycle, privacy, and Dashboard compatibility |
| [Host Adapters](docs/host-adapters.md) | Codex, Claude, and Kimi capability matrix, preview/apply lifecycle, limits, and recovery |
| [v0.2 release readiness](docs/release-readiness-v0.2.0.md) | Public synthetic evidence, private 3–5 task pilot protocol, exact-commit gates, blockers, and non-claims |
| [Roadmap](docs/roadmap.md) | Planned delivery stages |

Expand Down
7 changes: 7 additions & 0 deletions README.zh-CN.md
Original file line number Diff line number Diff line change
Expand Up @@ -97,6 +97,12 @@ App 的更新、回滚与卸载不会删除项目 `.opc`、File/Git knowledge、
用户配置或 Mem0 数据。产品边界、安装、隐私与恢复契约见
[OPC App](docs/opc-app.md)。

App 还提供默认只预览的 Adapters 页面,用来管理用户已安装的 Codex、Claude
Code 与 Kimi Code CLI 中的 OPC 集成。Codex 复用现有 Marketplace 生命周期;
Claude 仅在钉住的安全版本范围内调用公开 Plugin CLI;Kimi 只管理官方公开的
用户 Skill 投影,非交互 Plugin 安装仍明确阻止。能力矩阵、所有权规则、限制与
独立验收步骤见 [Host Adapters](docs/host-adapters.md)。

### 兼容的本地 Dashboard

`main` 提供一个显式启动、仅本机访问、只读的经理 Dashboard。它不属于稳定版 `v0.1.0`,不会扫描磁盘发现项目,也没有批准或晋升操作:
Expand Down Expand Up @@ -208,6 +214,7 @@ Hook/运行事件只进入私有 `PLUGIN_DATA` 或项目 `.opc` 回退,绝不
| [受控能力进化](docs/capability-evolution.md) | 角色/Skill/策略版本、证据门禁、单路径 Git 交接、观察与回滚 |
| [OPC Dashboard](docs/opc-dashboard.md) | 显式启动的本地只读经理视图、数据语义、安全边界与已知限制 |
| [OPC App](docs/opc-app.md) | 独立本地控制平面、App 自有设置、安装生命周期、隐私与 Dashboard 兼容性 |
| [Host Adapters](docs/host-adapters.md) | Codex、Claude、Kimi 能力矩阵、预览/执行生命周期、限制与恢复 |
| [v0.2 发布就绪度](docs/release-readiness-v0.2.0.md) | 公开 synthetic 证据、私有 3–5 task 协议、exact-commit Gate、阻断项与非主张 |
| [路线图](docs/roadmap.md) | 分阶段交付计划 |

Expand Down
56 changes: 56 additions & 0 deletions docs/adr/0018-host-adapters-use-public-contracts.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,56 @@
# ADR-0018: Host Adapters use public lifecycle contracts

- Status: Accepted
- Date: 2026-07-25
- Depends on: ADR-0002, ADR-0005, ADR-0017

## Context

OPC must project one canonical package into several local Agent hosts without
making their extension models appear equivalent. Blind file copying would
bypass official discovery, create ambiguous ownership, and make safe uninstall
impossible.

## Decision

The App calls a host-neutral Adapter core with stable `probe`, preview-plan,
explicit `apply`, `verify`, and `rollback` stages. Host implementations remain
separate:

- Codex delegates to the existing Marketplace/Plugin lifecycle and
`plugin_admin.py`.
- Claude uses its documented non-interactive Marketplace Plugin CLI and
preserves plugin data during uninstall. One stable App-owned marketplace
path is registered once; update and rollback atomically change that source
and use public marketplace/plugin update commands. Marketplace removal is
not an update or rollback primitive.
- Kimi manages documented user Skill directories and passes their common scan
root once to `--skills-dir`. Plugin automation remains blocked while the
public Plugin manager is interactive-only.

Preview plans are short-lived, one-time, and process-local. Apply re-captures
and compares the source, host/version, official discovery, capability contract,
ownership manifest, and resolved target state before the first write.

File/Git remains authoritative. Adapter manifests and backups are operational,
rebuildable App state, not organizational memory. A host target may be changed
or removed only when the manifest proves OPC ownership and the current hash
still matches. Unknown host versions and unsupported mechanisms fail closed.

Each host has one mutation lock spanning final state verification, host writes,
fresh-process verification, manifest publication, and operation-record
publication. An operation record is written before mutation and retains only
logical rollback identity, prior manifest, hashes, status, and a stable error
code. Completed or recoverable failed operations appear in the App as recovery
entries. Rollback is a separate Host/Origin/CSRF-protected request and the UI
requires its own confirmation dialog; it rechecks the recorded post-operation
fingerprint before changing anything. Codex and Claude cannot claim byte-level
host-cache drift because their public discovery contracts do not expose a
supported cache digest; Kimi can hash its managed public Skill directories.

## Consequences

The three hosts can expose different support levels without false parity.
Plans are auditable and writes require explicit confirmation. Real installed
state still needs independent host-specific QA; Developer-run disposable-host
acceptance is implementation evidence, not release approval.
2 changes: 2 additions & 0 deletions docs/architecture.md
Original file line number Diff line number Diff line change
Expand Up @@ -145,6 +145,7 @@ sequenceDiagram
| Mem0 索引 | 用户私有数据目录 | 可删除、可重建,不是权威源 |
| Dashboard 展示状态 | 进程内即时只读投影,不持久化 | 关闭本地进程即消失,不成为事实来源 |
| OPC App 接入清单与偏好 | `OPC_APP_HOME` 或平台用户状态目录 | 独立于 runtime、checkout、项目和知识;可删除重建 |
| Host Adapter manifest、投影与备份 | `OPC_APP_HOME/adapters` | 仅记录 OPC 所有权、版本、Ref、哈希和恢复引用;不是组织知识 |
| OPC App runtime releases | 平台用户数据目录 | 内容哈希版本可升级/回滚;卸载不触碰 App 状态或业务数据 |
| 原始运行日志 | 默认最小化并设置保留策略 | 不进入公共仓库和知识层 |

Expand Down Expand Up @@ -189,6 +190,7 @@ v0.1 以 `plugins/codex-opc-team/scripts/opc_memory.py` 为真实可调用契约
| 健康与运行状态 | `MemoryService.status()` / `doctor()` |
| 本地只读经理视图 | `opc_dashboard.py` 的固定字段 `/api/snapshot`;loopback-only,不提供治理写操作 |
| 共享本地投影服务 | `opc_snapshot_service.py`;旧 Dashboard 与 OPC App 使用同一 snapshot builder、DTO 和脱敏器 |
| Host Adapter 核心 | `opc_adapters.py`;UI 只调用 probe/plan/apply/verify/rollback 契约,不实现宿主安装逻辑 |
| 独立本地控制平面 | `opc_app.py`;治理 API 只读,唯一写状态为显式项目清单与当前选择,不承担 Agent Harness |
| 候选只读回放与 control/treatment 证据 | `opc_shadow.py preview` / `evaluate` / `report`;不属于 `MemoryService` 状态迁移 |
| 角色/Skill/组织策略版本生命周期 | `opc_evolution.py` 的 private proposal/pilot/evaluate/transition/confirm;只产生一个 unstaged allowlisted diff,不修改全局 Codex 配置 |
Expand Down
Loading