11 KiB
11 KiB
Current Platform E2E Baseline Proof Report
Date: 2026-07-08
Classification Legend
real: backed by executable platform/run/plugin evidence in this baseline.partial: some real backing exists, but a missing integration step prevents full end-to-end proof.demo-only: visible behavior is local fallback, seed data, or simulated behavior.blocked: verification could not run because of a reproducible environment, service, auth, or tooling blocker.
Command Evidence
| Area | Command | Result | Evidence |
|---|---|---|---|
| Platform | cd platform && go test ./... -count=1 |
Passed | Packages api, config, domain, dto, model, repo, service, and validator passed. |
| Run | cd run && go test ./... -count=1 |
Passed | Packages api, config, protocol, runtime, and spool passed. |
| Plugins | cd plugins && npm run typecheck |
Passed | TypeScript completed with no errors. |
| Plugins | cd plugins && npm run test |
Passed | Vitest reported 1 test file / 10 tests passed. |
| Plugins | cd plugins && npm run validate:manifest |
Passed after sandbox retry | Initial sandbox run failed with listen EPERM for the tsx IPC pipe; escalated run printed validated examples/dev-game-plugin/manifest.json. |
| Frontend | cd platform_web && npm run typecheck |
Passed | TypeScript completed with no errors. |
| Frontend | cd platform_web && npm test |
Passed | Vitest reported 11 test files / 47 tests passed. |
| Frontend | cd platform_web && npm run build |
Passed | Vite built dist/ assets successfully. |
| Browser server | cd platform_web && VITE_ENABLE_LOCAL_AUTH_FALLBACK=true npm run dev -- --port 5173 |
Passed after sandbox retry | Initial sandbox run failed with listen EPERM 127.0.0.1:5173; escalated run served http://127.0.0.1:5174/. |
Browser Walkthrough Evidence
The browser walkthrough used http://127.0.0.1:5174/ with VITE_ENABLE_LOCAL_AUTH_FALLBACK=true.
| Page / Flow | Browser Result | Classification | Follow-up |
|---|---|---|---|
| Auth entry | Login screen showed 本地回退可用 and 进入本地回退工作台, proving the auth API was unavailable in this local browser stack. |
partial |
Use a local stack that starts platform API, run, and frontend together so browser auth can prove real sessions. |
| 服务器管理 | Local fallback entered #/servers as Local Server Operator; page showed 服务器列表加载失败 with path /api/v1/jobs was not found. |
partial |
Fix local browser stack/API routing and rerun server lifecycle walkthrough against real platform APIs. |
| 首页 | Navigating to #/home as fallback server admin redirected/rendered the server workspace rather than 首页. |
blocked |
Verify with a real platform-admin session. |
| 插件市场 | Navigating to #/plugins as fallback server admin redirected/rendered the server workspace. |
blocked |
Verify with a real platform-admin session and API-backed plugin marketplace data. |
| 用户管理 | Navigating to #/users as fallback server admin redirected/rendered the server workspace. |
blocked |
Verify with a real platform-admin session. |
| AI 提供商管理 | Navigating to #/aiProviders as fallback server admin redirected/rendered the server workspace. |
blocked |
Verify with a real platform-admin session and API-backed provider data. |
| Personal/account settings | #/profile rendered 个人设置, 本地会话, editable profile fields, palette/background controls, and logout. |
demo-only |
Rerun with a real API-authenticated user to prove profile/theme persistence. |
| Visible unsafe fields | Browser-visible fallback pages did not expose raw host paths, run credentials, direct sockets, raw AI keys, or plugin-owned transport details. | partial |
Repeat on real server/plugin/detail pages after API-backed browser stack works. |
Platform API and Storage Matrix
| Flow | Classification | Evidence | Follow-up |
|---|---|---|---|
| Auth/session API | real for handler/service tests; partial for browser |
platform test suite passed; browser auth used local fallback because API was unavailable. |
Add a repeatable local full-stack browser auth smoke path. |
| Users API | real for platform tests; blocked in browser |
platform test suite passed; fallback role cannot open 用户管理. |
Browser verify with real platform-admin session. |
| Server instances and lifecycle APIs | real for platform tests; partial in browser |
platform tests include server lifecycle/API packages; browser server page failed /api/v1/jobs. |
Fix local stack/proxy and rerun create/start/stop browser flow. |
| Plugin registry and marketplace APIs | real for platform/plugin tests; blocked in browser |
platform and plugins tests passed; fallback role could not open 插件市场. |
Browser verify marketplace with API-backed admin session. |
| AI provider APIs | real for platform tests; blocked in browser |
platform validator/dto/API tests passed and protect raw keys; fallback role could not open AI 提供商管理. |
Browser verify create/test/status with API-backed admin session. |
| Jobs API | real for platform/run tests; partial in browser |
platform and run tests passed; browser surfaced path /api/v1/jobs was not found. |
Start compatible platform API with frontend proxy for browser proof. |
| Logs API/storage | partial |
platform and run tests passed for log-related packages, but this baseline did not prove restart-surviving log history in a live stack. |
Add local durable log history smoke with restart/query evidence. |
| Artifacts API/storage | real for chunk/checksum/download tests; partial for live stack |
platform and run tests passed; artifact download tests prove platform-mediated references and safe fields. No live browser artifact download was reachable. |
Rerun browser server detail artifact flow with real API stack. |
| Config diff/write and file dispatch | real for platform tests; partial for browser |
platform tests passed; browser could not reach server detail/config due server list API failure. |
Rerun config diff/write dispatch in browser with real server instance. |
| Storage durability | partial |
Package tests passed, but this baseline did not run a database restart or cross-process durability smoke. | Add explicit MySQL-backed create/restart/query proof in local debug workspace. |
Run Channel Matrix
| Flow | Classification | Evidence | Follow-up |
|---|---|---|---|
| Control hello/heartbeat | real at package level |
cd run && go test ./... -count=1 passed api and protocol packages. |
Include a live run-to-platform heartbeat in local debug workspace. |
| Job claim/ack/progress/result | real at package level |
run package tests passed for API/runtime behavior. |
Add integrated platform/run smoke with actual queued job. |
| Lifecycle install/start/stop executor | real at package level; partial end to end |
run runtime tests passed; browser could not prove create/start/stop because platform API stack was unavailable. |
Implement/verify real game plugin lifecycle proof. |
| Log spool/ingest acknowledgement | real at package level; partial for durable history |
run spool tests passed; no live restart/query proof ran. |
Add durable log history smoke. |
| Artifact chunk/resume/checksum | real at package level |
run artifact API tests passed and platform artifact tests passed. |
Add browser artifact download walkthrough against a real completed artifact. |
| Channel isolation | partial |
Prior package-level tests passed, but this baseline did not run concurrent live artifact/file transfer alongside heartbeat/job/log traffic. | Implement hardening proof for log/artifact channel isolation. |
Plugin Boundary Matrix
| Flow | Classification | Evidence | Follow-up |
|---|---|---|---|
| Manifest schema validation | real |
npm run validate:manifest passed for examples/dev-game-plugin/manifest.json after sandbox retry. |
|
| Unsafe manifest rejection | real |
npm run test passed; tests include rejection of direct run and raw AI key requests. |
|
| SDK bridge request envelopes | real |
npm run typecheck and npm run test passed; tests cover typed bridge request envelopes without owning transport. |
|
| AI invocation request boundaries | real at SDK/manifest level |
Tests and schema include ai.invoke; plugin docs state provider keys remain platform-mediated. |
|
| Real multi-instance game server operation | partial |
Plugin manifests and SDK can request lifecycle/log/artifact/AI capabilities, but this baseline did not prove a real plugin creating/managing multiple live server instances through platform/run. | Generate/implement implement-real-game-plugin-lifecycle-proof. |
Required First-Party Area Summary
| Area | Current Baseline Classification | Reason |
|---|---|---|
| 首页 | blocked |
Fallback server-admin browser session redirected/rendered server workspace; no platform-admin browser proof. |
| 服务器管理 | partial |
API/package evidence exists, but browser flow failed /api/v1/jobs without a live platform API stack. |
| 插件市场 | blocked |
Fallback browser session could not access platform-admin route; package/API tests pass. |
| 用户管理 | blocked |
Fallback browser session could not access platform-admin route; package/API tests pass. |
| AI 提供商管理 | blocked |
Fallback browser session could not access platform-admin route; package/API tests pass. |
Follow-up OpenSpec Recommendations
implement-real-game-plugin-lifecycle-proof: prove one game management plugin can create and manage multiple server instances only through platform-mediated platform/run contracts.implement-local-debug-workspace: provide one repeatable command path that starts platform, run, frontend, storage, and plugin fixtures for browser/API proof without relying on local fallback.implement-browser-acceptance-suite: automate browser coverage for 首页、服务器管理、插件市场、用户管理、AI 提供商管理 and plugin/server detail operations.harden-log-artifact-channel-isolation: run concurrent artifact/file operations while proving control heartbeat, job ack/result, and durable log ingest continue independently.- Reopen/finish
fix-env-profile-settingstask3.5in a working browser/dev-server session to close the older guard.
Bottom Line
The codebase has substantial real backend/run/plugin capability evidence from tests, but the current local browser proof is not yet a real platform-wide E2E baseline. The visible browser experience fell back to a local server-admin session, server management failed on /api/v1/jobs, and platform-admin first-party areas could not be reached. The next architecture work should make the real full-stack proof path repeatable, then prove a game plugin lifecycle against it.