AI Agent 产品交付入口与全生命周期协议
基于 MSG Chain 官方
product_delivery_entry.json(schema_version: v1)
生成管道:msg_whitepaper_pipeline_v1
元数据画像:public_stable
文档版本: 2026-07⚠️ No-Go Disclaimer: MSGChain 主网裁决为 No-Go。本文件所有内容反映的是开发阶段的技术设计,不代表主网未独立核验上线状态。生产部署状态请以白皮书为准:https://msgchain.org/whitepaper/
1. 概述
1.1 什么是 product_delivery_entry.json
product_delivery_entry.json 是 MSG Chain 白皮书机器层(Machine Layer)中定义的单机入口点(Single Machine Entry),专门面向需要从受限编码(scoped coding)转向有门禁的构建、测试、部署、验证与上线工作流的 AI Agent。
该文件托管于:
https://msgchain.org/whitepaper/product_delivery_entry.json
它的核心定位是:AI Agent 全生命周期产品交付的起始文件。无论 Agent 走合约引导路线、dApp 引导路线还是完整生命周期路线,都从 product_delivery_entry.json 开始。
1.2 在 12 步引导序列中的位置
developer_entry.json 定义了三种引导顺序(bootstrap order),product_delivery_entry.json 在每一种中都排在第一位:
| 引导路线 | 第一步 | 总步数 |
|---|---|---|
recommended_full_lifecycle_order |
product_delivery_entry.json |
20 步 |
recommended_contract_bootstrap_order |
product_delivery_entry.json |
19 步 |
recommended_dapp_bootstrap_order |
product_delivery_entry.json |
16 步 |
这意味着任何外部 AI Agent 在接入 MSG Chain 产品交付体系时,必须首先解析 product_delivery_entry.json,获取整个交付流程的元信息和入口指引。
1.3 与 developer_entry.json 的关系
product_delivery_entry.json 和 developer_entry.json 是互补关系:
product_delivery_entry.json:面向交付场景,定义产品交付的五阶段模型(scope → codegen → quality_gate → deploy_and_verify → launch),以及每个阶段是否需要人类输入。developer_entry.json:面向开发场景,定义开发者能力矩阵、沙箱策略、API 契约、合约模板、执行包等开发资源的入口。
两者关系在 developer_entry.json 的 entry_points 中有明确声明:
"product_delivery_entry_json": "product_delivery_entry.json",
"product_delivery_entry_json_public_url": "https://msgchain.org/whitepaper/product_delivery_entry.json"
1.4 在 agent_entry.json 中的引用
agent_entry.json(Agent 入口文件)同样将 product_delivery_entry.json 列为关键入口点,并包含在推荐的爬取顺序(recommended_crawl_order)中。它在 crawl_contract 中指定了 developer_entry 和 product_delivery_entry 作为知识网络的组成部分。
1.5 文件元属性
| 属性 | 值 |
|---|---|
schema_version |
v1 |
generated_by |
msg_whitepaper_pipeline_v1 |
project |
MSG Chain AI Delivery Entry |
public_base_url |
https://msgchain.org/whitepaper/ |
metadata_profile |
public_stable |
2. 产品交付入口协议
2.1 Schema 结构总览
product_delivery_entry.json 的顶层字段结构如下:
product_delivery_entry.json
├── schema_version: "v1"
├── generated_by: "msg_whitepaper_pipeline_v1"
├── project: "MSG Chain AI Delivery Entry"
├── description: "Single machine entry for AI agents..."
├── public_base_url: "https://msgchain.org/whitepaper/"
├── entry_points: { ... } # 入口点映射
├── recommended_full_lifecycle_order: [...] # 19+1 步全生命周期顺序
├── phases: [...] # 5 个交付阶段
├── hard_boundaries: [...] # 2 条硬边界
└── metadata_profile: "public_stable"
2.2 Entry Points(入口点)
entry_points 字段定义了 AI Agent 从产品交付入口可到达的所有子资源。共计 14 个入口点,覆盖 6 大类资源:
2.2.1 开发者入口
| 键 | 值 | 公开 URL |
|---|---|---|
developer_entry_json |
developer_entry.json |
https://msgchain.org/whitepaper/developer_entry.json |
2.2.2 外部 AI Agent 引导
| 键 | 值 | 公开 URL |
|---|---|---|
external_ai_agent_bootstrap_prompt_json |
integration_examples/external_ai_agent_bootstrap_prompt.json |
https://msgchain.org/whitepaper/integration_examples/external_ai_agent_bootstrap_prompt.json |
external_ai_agent_bootstrap_prompt_md |
integration_examples/external_ai_agent_bootstrap_prompt.md |
https://msgchain.org/whitepaper/integration_examples/external_ai_agent_bootstrap_prompt.md |
2.2.3 Quick Start(快速入门)
| 键 | 值 | 公开 URL |
|---|---|---|
quickstart_index_json |
quickstart/index.json |
https://msgchain.org/whitepaper/quickstart/index.json |
quickstart_contract_and_dapp_json |
quickstart/contract_and_dapp_minimal.json |
https://msgchain.org/whitepaper/quickstart/contract_and_dapp_minimal.json |
2.2.4 链配置
| 键 | 值 | 公开 URL |
|---|---|---|
developer_sandbox_strategy_json |
chain_config/developer_sandbox_strategy.json |
https://msgchain.org/whitepaper/chain_config/developer_sandbox_strategy.json |
2.2.5 合约与 API 参考
| 键 | 值 | 公开 URL |
|---|---|---|
contract_reference_index_json |
contract_reference/index.json |
https://msgchain.org/whitepaper/contract_reference/index.json |
core_contracts_json |
contract_reference/core_contracts.json |
https://msgchain.org/whitepaper/contract_reference/core_contracts.json |
formal_contracts_json |
api_specs/formal_contracts.json |
https://msgchain.org/whitepaper/api_specs/formal_contracts.json |
2.2.6 执行与交付包
| 键 | 值 | 公开 URL |
|---|---|---|
execution_pack_index_json |
execution_pack/index.json |
https://msgchain.org/whitepaper/execution_pack/index.json |
release_pack_index_json |
release_pack/index.json |
https://msgchain.org/whitepaper/release_pack/index.json |
e2e_fixtures_index_json |
e2e_fixtures/index.json |
https://msgchain.org/whitepaper/e2e_fixtures/index.json |
2.3 五阶段交付模型
phases 数组定义了产品交付的五个阶段,每个阶段包含 id、goal 和 requires_human_input 三个属性。
Phase 1: scope(范围锁定)
- 目标:先锁定产品范围、业务规则、验收口径
- 需要人类输入:是
- 说明:这是整个交付流程的起点。AI Agent 不能自行决定产品范围,必须由人类提供业务需求、产品目标和验收标准。此阶段产生
需求范围和验收标准两个产出物。
Phase 2: codegen(代码生成)
- 目标:用 developer machine pack 生成合约或 dApp 起步资产
- 需要人类输入:否
- 说明:AI Agent 可在此阶段自主执行代码生成。它读取
developer_entry.json、合约模板和配方文件,生成合约源码、测试骨架或 dApp 前端结构。此阶段是 AI coding 能力的主要发挥区域。
Phase 3: quality_gate(质量门禁)
- 目标:按真实命令执行 lint/test/build/contract test
- 需要人类输入:否
- 说明:AI Agent 可以自主执行
make lint、make test、make ci-contracts等命令。这些命令在execution_pack/command_registry.json中有完整定义。此阶段不需要人类介入,但执行结果必须形成可审计的原始输出。
Phase 4: deploy_and_verify(部署与验证)
- 目标:准备发布计划、执行 smoke check、收集 query/receipt/log 证据
- 需要人类输入:是
- 说明:此阶段 AI Agent 可以准备部署计划、编写 smoke check 脚本、规划回滚策略,但涉及真实环境变量、签名账户、访问凭据等操作必须由人类完成。Agent 在此阶段的主要任务是准备证据,包括原始查询结果、交易回执和日志。
Phase 5: launch(上线)
- 目标:在审批通过后上线并保留 rollback 句柄
- 需要人类输入:是
- 说明:最终上线动作必须经过人类审批。AI Agent 不能自主执行生产上线。上线后必须保留回滚句柄,确保在出现问题时可以快速回退。
2.4 各阶段人类参与度一览
| 阶段 | AI 可自主操作 | 需要人类输入 | 关键行为 |
|---|---|---|---|
| scope | 部分 | 是 | 锁定范围、规则、验收标准 |
| codegen | 全部 | 否 | 生成源码、测试、dApp 骨架 |
| quality_gate | 全部 | 否 | 执行 lint/test/build/contract test |
| deploy_and_verify | 准备阶段 | 是 | 部署计划、smoke check、证据收集 |
| launch | 不允许自主 | 是 | 审批后上线,保留回滚句柄 |
2.5 硬边界(Hard Boundaries)
hard_boundaries 数组定义了两条不可逾越的硬边界:
[
"不能把执行层协议包解释成 100% 零人工生产上线承诺。",
"没有真实环境变量、签名账户、审批和 raw evidence 时,AI agent 必须停在计划态或 stub 态。"
]
边界 1:执行层协议包(execution pack)提供的是机器化的流程定义,并不等同于 AI Agent 可以完全自主完成生产上线。人类审批是最终的防线。
边界 2:在以下条件未满足时,AI Agent 必须停在"计划态"或"stub 态":
- 真实环境变量(如 API 端点、网络地址)
- 签名账户(用于签署交易)
- 审批流程(人类或多签)
- 原始证据(raw evidence,如 tx hash、receipt、log)
3. 全生命周期交付流程
3.1 推荐的 20 步全生命周期顺序
developer_entry.json 中 recommended_full_lifecycle_order 定义了全生命周期产品交付的 20 步引导顺序(product_delivery_entry.json 自身为首步,共 20 个文件)。这与 product_delivery_entry.json 中定义的 recommended_full_lifecycle_order 完全一致。
完整顺序如下:
Step 1: product_delivery_entry.json ← 本文件(交付入口)
Step 2: developer_entry.json ← 开发者入口
Step 3: quickstart/index.json ← 快速入门索引
Step 4: quickstart/contract_and_dapp_minimal.json ← Contract + dApp 快速开始
Step 5: chain_config/developer_sandbox_strategy.json ← 沙箱策略
Step 6: contract_reference/index.json ← 合约参考索引
Step 7: contract_reference/core_contracts.json ← 核心合约清单
Step 8: api_specs/formal_contracts.json ← 正式 API/Schema 契约
Step 9: integration_examples/external_ai_agent_bootstrap_prompt.json ← Agent 引导提示
Step 10: developer_capability_matrix.json ← 开发者能力矩阵
Step 11: chain_config/index.json ← 链配置索引
Step 12: contract_templates/index.json ← 合约模板索引
Step 13: examples/index.json ← dApp 示例索引
Step 14: execution_pack/index.json ← 执行包索引
Step 15: execution_pack/delivery_workflows.json ← 交付工作流
Step 16: execution_pack/command_registry.json ← 命令注册表
Step 17: release_pack/index.json ← 发布包索引
Step 18: e2e_fixtures/index.json ← 端到端测试夹具
Step 19: modules/review_playbook.html ← 审查剧本
Step 20: modules/evidence_index.html ← 证据索引
3.2 步骤详解
Step 1: product_delivery_entry.json
用途:交付入口。AI Agent 读取本文件以了解交付阶段模型、入口点和硬边界。
文件:product_delivery_entry.json
关键内容:
- 5 个交付阶段及其人类输入要求
- 14 个入口点指向所有子资源
- 2 条硬边界
Agent 动作:
entry = fetch("https://msgchain.org/whitepaper/product_delivery_entry.json")
phases = entry["phases"]
hard_boundaries = entry["hard_boundaries"]
Step 2: developer_entry.json
用途:开发者入口。提供开发者能力矩阵、API 规范、合约模板、链配置、执行包、发布包等资源的完整索引。
文件:developer_entry.json
关键内容:
- 8 个 key_modules
- 3 种 bootstrap order
- 4 个人类输入要求
- 3 条当前边界
Agent 动作:根据交付目标(合约/dApp/全生命周期)选择对应的 bootstrap order。
Step 3: quickstart/index.json
用途:快速入门索引。提供快速开始资源的入口。
文件:quickstart/index.json
Agent 动作:定位快速开始资源,为后续的快速启动步骤做准备。
Step 4: quickstart/contract_and_dapp_minimal.json
用途:Contract + dApp 快速开始步骤定义。这是一个 7 步指南,指导外部 AI Agent 快速搭建最小可运行的合约和 dApp。
文件:quickstart/contract_and_dapp_minimal.json
关键内容:
- 7 个步骤,每一步定义了
action、consumes和purpose - 5 个命令入口点(deps, lint, test, ci_contracts, build_linux)
- 3 个工作流入口点(contract_delivery_guarded_v1, dapp_delivery_guarded_v1, product_launch_guarded_v1)
- 4 步最小本地命令序列
- 2 条边界
Agent 动作:以 7 步流程为指引,生成合约和 dApp 代码。
Step 5: chain_config/developer_sandbox_strategy.json
用途:沙箱策略。定义开发者沙箱的可用性和默认策略。
文件:chain_config/developer_sandbox_strategy.json
边界:当前 public sandbox 默认为 disabled/fail-closed。AI Agent 必须使用 local-only 路径。
Step 6: contract_reference/index.json
用途:合约参考索引。提供核心合约清单和合约目录的入口。
文件:contract_reference/index.json
Step 7: contract_reference/core_contracts.json
用途:核心合约清单。列出所有核心合约的 canonical key、address、schema 和 msg.rs 路径。
文件:contract_reference/core_contracts.json
Agent 动作:读取核心合约的接口定义、消息模型和 schema,为代码生成提供准确的类型信息。
Step 8: api_specs/formal_contracts.json
用途:正式 API/Schema 契约索引。提供机器可消费的 API 定义、RPC 方法和错误码。
文件:api_specs/formal_contracts.json
关联文件:
api_specs/rpc_methods.jsonapi_specs/error_codes.jsonapi_specs/openapi/public_query.yamlapi_specs/openapi/contract_surface.yamlapi_specs/openapi/agent_surface.yaml
Step 9: integration_examples/external_ai_agent_bootstrap_prompt.json
用途:外部 AI Agent 引导提示。提供一个可读的引导提示模板,帮助外部 AI Agent 理解 MSG Chain 的架构和接入方式。
文件:integration_examples/external_ai_agent_bootstrap_prompt.json
关联文件:
integration_examples/external_ai_agent_bootstrap_prompt.md(Markdown 版本)
Step 10: developer_capability_matrix.json
用途:开发者能力矩阵。描述 MSG 开发者表面的机器就绪状态,共计 12 个表面。
文件:developer_capability_matrix.json
表面分类:
| 表面 | 机器就绪度 | 写入路径 | 生产支持 |
|---|---|---|---|
| contract_runtime | assisted_codegen | 是 | 是 |
| core_contract_reference_pack | source_backed_reference | 否 | 否 |
| registry_resolution | production_reference | 否 | 是 |
| rpc_gateway | assisted_codegen | 是 | 是 |
| formal_api_schema_pack | source_backed_reference | 否 | 否 |
| wallet_frontend | guarded_integration | 是 | 否 |
| explorer_receipts | read_only_assist | 否 | 否 |
| agent_query_and_guarded_write | guarded_write | 否 | 否 |
| sdk_surface | local_candidate | 否 | 否 |
| chain_config_pack | starter_ready | 否 | 是 |
| public_sandbox_strategy | fail_closed_reference | 否 | 否 |
| contract_template_pack | starter_ready | 否 | 否 |
Step 11: chain_config/index.json
用途:链配置索引。提供链配置文件的入口。
文件:chain_config/index.json
关联文件:chain_config/network_presets.json
Step 12: contract_templates/index.json
用途:合约模板索引。提供合约模板的入口,用于快速生成合约代码。
文件:contract_templates/index.json
Step 13: examples/index.json
用途:dApp 示例索引。提供 dApp 示例代码的入口。
文件:examples/index.json
Step 14: execution_pack/index.json
用途:执行包索引。提供面向执行的操作包入口,用于将 AI 编码转化为有门禁的构建/测试/部署/验证工作流。
文件:execution_pack/index.json
包含子文件:
| 文件 | 用途 |
|---|---|
execution_pack/command_registry.json |
命令注册表 |
execution_pack/approval_gates.json |
审批门禁定义 |
execution_pack/delivery_workflows.json |
交付工作流 |
execution_pack/ci_cd_templates.json |
CI/CD 模板 |
execution_pack/governance_templates.json |
治理模板 |
execution_pack/multisig_approval_flow.json |
多签审批流程 |
execution_pack/evidence_requirements.json |
证据要求 |
execution_pack/artifact_contracts.json |
制品合约 |
Step 15: execution_pack/delivery_workflows.json
用途:交付工作流。定义了三条受保护的交付工作流:合约交付、dApp 交付和产品上线。
文件:execution_pack/delivery_workflows.json
工作流清单:
contract_delivery_guarded_v1:面向 CosmWasm 合约交付,5 个阶段dapp_delivery_guarded_v1:面向 MSG dApp 交付,4 个阶段product_launch_guarded_v1:面向合约 + dApp + 文档组合上线,3 个阶段
Step 16: execution_pack/command_registry.json
用途:命令注册表。定义 AI Agent 可执行的标准化命令,包括命令字符串、工作目录、安全标识和输出物。
文件:execution_pack/command_registry.json
命令清单:
| 命令 ID | 命令 | 阶段 | 安全 | 需要审批 |
|---|---|---|---|---|
| deps | make deps | prepare | 是 | 否 |
| lint | make lint | quality_gate | 是 | 否 |
| test | make test | quality_gate | 是 | 否 |
| test_quantum | make test-quantum | quality_gate | 是 | 否 |
| build_linux | make build-linux | build | 是 | 否 |
| ci_contracts | make ci-contracts | contract_validation | 是 | 否 |
| package_deploy | make package | artifact_packaging | 是 | 否 |
| cloudflare_pages_deploy | npx wrangler pages deploy | release | 否 | 是 |
Step 17: release_pack/index.json
用途:发布包索引。提供发布相关的清单和 Manifest。
文件:release_pack/index.json
包含子文件(共 11 个):
| 文件 | 用途 |
|---|---|
release_pack/.env.example |
环境变量样例 |
release_pack/cloudflare_pages_release_checklist.json |
Cloudflare Pages 发布清单 |
release_pack/contract_release_checklist.json |
合约发布清单 |
release_pack/smoke_checks.json |
Smoke Check 定义 |
release_pack/developer_capability_manifest.json |
能力 Manifest |
release_pack/developer_api_schema_pack_manifest.json |
API Schema 包 Manifest |
release_pack/developer_contract_schema_abi_pack_manifest.json |
合约 Schema/ABI 包 Manifest |
release_pack/developer_public_sandbox_strategy_manifest.json |
公开沙箱策略 Manifest |
release_pack/developer_dapp_starter_e2e_manifest.json |
dApp Starter E2E Manifest |
release_pack/developer_sdk_signed_release_candidate_manifest.json |
SDK 签名发布候选 Manifest |
release_pack/developer_business_examples_manifest.json |
业务示例 Manifest |
Step 18: e2e_fixtures/index.json
用途:端到端测试夹具。提供 E2E 测试用的数据夹具。
文件:e2e_fixtures/index.json
包含子文件:
| 文件 | 用途 |
|---|---|
e2e_fixtures/registry_query_fixture.json |
注册中心查询夹具 |
e2e_fixtures/agent_registry_query_fixture.json |
Agent 注册中心查询夹具 |
e2e_fixtures/contract_execute_receipt_template.json |
合约执行回执模板 |
Step 19: modules/review_playbook.html
用途:审查剧本。定义交付审核的流程和标准。
文件:modules/review_playbook.html
公开 URL:https://msgchain.org/whitepaper/modules/review_playbook.html
Step 20: modules/evidence_index.html
用途:证据索引。提供交付过程中收集的证据索引。
文件:modules/evidence_index.html
公开 URL:https://msgchain.org/whitepaper/modules/evidence_index.html
3.3 三种引导路线的映射
developer_entry.json 定义了三种引导路线,每种路线都从 product_delivery_entry.json 开始:
合约引导路线(recommended_contract_bootstrap_order)
共 19 步,侧重智能合约开发:
product_delivery_entry.json → developer_capability_matrix.json
→ quickstart/contract_and_dapp_minimal.json → chain_config/index.json
→ chain_config/developer_sandbox_strategy.json → api_specs/rpc_methods.json
→ api_specs/openapi/contract_surface.yaml → api_specs/formal_contracts.json
→ contract_reference/index.json → contract_reference/core_contracts.json
→ contract_templates/index.json → recipes/contract_minimal.json
→ execution_pack/index.json → execution_pack/command_registry.json
→ e2e_fixtures/index.json → modules/contract.html
→ modules/registry.html → modules/rpc.html
→ module_exports/contract.json
dApp 引导路线(recommended_dapp_bootstrap_order)
共 16 步,侧重去中心化应用开发:
product_delivery_entry.json → developer_capability_matrix.json
→ quickstart/contract_and_dapp_minimal.json → chain_config/index.json
→ chain_config/developer_sandbox_strategy.json → api_specs/rpc_methods.json
→ api_specs/openapi/public_query.yaml → api_specs/formal_contracts.json
→ examples/index.json → recipes/dapp_minimal.json
→ execution_pack/index.json → execution_pack/command_registry.json
→ release_pack/index.json → modules/keplr.html
→ modules/rpc.html → modules/explorer.html
→ module_exports/keplr.json
全生命周期引导路线(recommended_full_lifecycle_order)
共 20 步,覆盖完整的端到端产品交付。前面已详述。
3.4 与 execution_pack 的集成
execution_pack 是 product_delivery_entry.json 的重要下游。在 recommended_full_lifecycle_order 中,第 14-16 步都是 execution_pack 的文件:
- Step 14 (
execution_pack/index.json):选择工作流类型(合约/dApp/产品上线) - Step 15 (
execution_pack/delivery_workflows.json):读取具体工作流定义 - Step 16 (
execution_pack/command_registry.json):执行命令
execution_pack 的边界与 product_delivery_entry.json 一致:
"执行层协议包把流程机器化,不等于授权 AI 跨越生产审批。"
"涉及真实部署、私钥、资金、治理、域名与 CI/CD 权限时必须转入人工确认。"
3.5 与 release_pack 的集成
release_pack 在第 17 步引入,提供发布前的清单检查和环境变量模板:
- 合约发布清单:
release_pack/contract_release_checklist.json - Cloudflare Pages 发布清单:
release_pack/cloudflare_pages_release_checklist.json - Smoke Check 定义:
release_pack/smoke_checks.json
3.6 与 e2e_fixtures 的集成
e2e_fixtures 在第 18 步引入,提供 E2E 测试用的数据夹具:
- 注册中心查询夹具(
registry_query_fixture.json) - Agent 注册中心查询夹具(
agent_registry_query_fixture.json) - 合约执行回执模板(
contract_execute_receipt_template.json)
这些夹具用于:
- 验证部署后的合约状态
- 生成预期回执格式
- 作为证据收集的参考模板
4. 交付工作流
4.1 三条受保护交付工作流
execution_pack/delivery_workflows.json 定义了三条受保护的工作流,每条都从 product_delivery_entry.json 开始:
4.2 合约交付工作流(contract_delivery_guarded_v1)
适用于:CosmWasm 合约交付
阶段分解:
Phase 1: scope(范围)
- 消费:
product_delivery_entry.json - 产出:需求范围、验收标准
- 审批门禁:
scope_lock - 说明:使用
product_delivery_entry.json中的phases[0](scope)定义范围锁定的标准。人类必须确认产品目标和业务规则。
Phase 2: design_and_codegen(设计与代码生成)
- 消费:
developer_entry.json、contract_templates/index.json、recipes/contract_minimal.json - 产出:合约源码、测试骨架
- 审批门禁:无
- 说明:AI Agent 在范围锁定后自主执行代码生成。使用合约模板和配方生成最小可运行合约,补充业务消息模型。
Phase 3: build_and_test(构建与测试)
- 消费:
execution_pack/command_registry.json - 产出:
make lint、make test、make ci-contracts、cargo test原始输出 - 审批门禁:无
- 说明:AI Agent 自主执行质量门禁。命令包括:
make lint:gofmt check、go vet、golangci-lintmake test:Go 主仓库测试make ci-contracts:所有合约 wasm 构建和 cargo testmake build-linux:生成节点二进制
Phase 4: deploy_plan(部署计划)
- 消费:
release_pack/index.json、e2e_fixtures/index.json - 产出:部署计划、query/receipt 校验计划、rollback plan
- 审批门禁:
secret_injection(密钥注入门禁) - 说明:AI Agent 准备部署计划,但涉及真实密钥和签名的操作必须通过审批门禁。Agent 在此阶段的任务包括:
- 编写部署脚本
- 规划 query/receipt 校验步骤
- 准备回滚计划
Phase 5: real_release(真实发布)
- 消费:
approval_gates.json - 产出:tx hash、receipt、post-state query、raw evidence
- 审批门禁:
production_release(生产发布门禁) - 说明:最终上线必须通过
production_release门禁。AI Agent 不能自主执行此阶段。产出物包括:- 交易哈希(tx hash)
- 回执(receipt)
- 状态后查询(post-state query)
- 原始证据(raw evidence)
4.3 dApp 交付工作流(dapp_delivery_guarded_v1)
适用于:MSG dApp 交付
Phase 1: scope(范围)
- 消费:
product_delivery_entry.json - 产出:页面范围、钱包/查询/交易需求
- 审批门禁:
scope_lock
Phase 2: scaffold(脚手架搭建)
- 消费:
developer_entry.json、examples/index.json、chain_config/index.json、recipes/dapp_minimal.json - 产出:前端骨架、钱包接入层、query/execute adapter
- 审批门禁:无
Phase 3: quality_gate(质量门禁)
- 消费:
execution_pack/command_registry.json - 产出:构建输出、测试输出、发布前 checklist
- 审批门禁:无
Phase 4: site_release(站点发布)
- 消费:
release_pack/index.json、execution_pack/approval_gates.json - 产出:站点发布计划、smoke checks、回滚预案
- 审批门禁:
production_release
4.4 产品上线工作流(product_launch_guarded_v1)
适用于:合约 + dApp + 文档组合上线
Phase 1: compose(组合)
- 消费:
developer_entry.json、execution_pack/index.json - 产出:子任务图、依赖图、阶段退出条件
- 审批门禁:
scope_lock
Phase 2: evidence_closeout(证据结案)
- 消费:
e2e_fixtures/index.json、execution_pack/evidence_requirements.json - 产出:raw query、receipt、log、artifact manifest
- 审批门禁:无
Phase 3: launch(上线)
- 消费:
release_pack/index.json、execution_pack/approval_gates.json - 产出:上线记录、smoke pass、回滚句柄
- 审批门禁:
production_release
4.5 命令注册表使用
execution_pack/command_registry.json 定义了 11 个标准化命令,其中 10 个对 AI Agent 安全可执行:
| 命令 ID | 阶段 | Agent 安全 | 需要审批 |
|---|---|---|---|
| deps | prepare | 是 | 否 |
| lint | quality_gate | 是 | 否 |
| test | quality_gate | 是 | 否 |
| test_quantum | quality_gate | 是 | 否 |
| build_linux | build | 是 | 否 |
| ci_contracts | contract_validation | 是 | 否 |
| package_deploy | artifact_packaging | 是 | 否 |
| whitepaper_generate | docs_generate | 是 | 否 |
| whitepaper_audit | docs_quality_gate | 是 | 否 |
| whitepaper_sync | site_sync | 是 | 否 |
| cloudflare_pages_deploy | release | 否 | 是 |
重要:cloudflare_pages_deploy 是唯一需要人类审批的命令。它的执行命令是:
npx wrangler pages deploy . --project-name msgchainorg --branch msgchainorg --commit-dirty=true
4.6 审批门禁类型
工作流中定义了三种审批门禁:
| 门禁 ID | 阶段 | 说明 |
|---|---|---|
scope_lock |
scope | 范围锁定审批,确保产品目标和验收标准已确认 |
secret_injection |
deploy_plan | 密钥注入审批,涉及真实环境变量和签名账户 |
production_release |
real_release / site_release / launch | 生产发布审批,最终上线授权 |
4.7 证据收集体系
product_delivery_entry.json 和 execution_pack 共同定义了证据收集要求。在 deploy_and_verify 和 launch 阶段,AI Agent 必须收集以下证据类型:
4.7.1 区块证据类型
| 证据类型 | 来源 | 用途 |
|---|---|---|
| tx hash | 链上交易 | 唯一标识一笔已提交的交易 |
| receipt | 链上回执 | 验证交易执行结果 |
| post-state query | 链上查询 | 验证部署后的合约状态 |
| log | 节点日志 | 审计和调试 |
4.7.2 证据要求文件
execution_pack/evidence_requirements.json 定义了完整的证据标准。E2E 夹具提供了模板参考:
e2e_fixtures/registry_query_fixture.json:注册中心查询结果格式e2e_fixtures/agent_registry_query_fixture.json:Agent 注册中心查询结果格式e2e_fixtures/contract_execute_receipt_template.json:合约执行回执格式
4.7.3 证据收集原则
- 原始性:证据必须是原始输出,不能被 AI Agent 改写
- 可验证性:证据必须能被第三方独立验证
- 完整性:证据必须包含完整的上下文信息
- 可审计性:证据必须带有时间戳和来源标记
5. 与 Quick Start 集成
5.1 7 步快速启动模型
quickstart/contract_and_dapp_minimal.json 定义了外部 AI Agent 开发 Contract + dApp 的 7 步快速启动流程。
Step 1: read capability + sandbox boundaries
Step 2: read contract interface pack
Step 3: scaffold contract
Step 4: scaffold dapp
Step 5: bind source-backed API and schema contracts
Step 6: follow local starter and E2E boundary
Step 7: prepare guarded release plan
5.2 步骤与交付阶段的映射
| Quick Start 步骤 | 对应交付阶段 | 详细说明 |
|---|---|---|
| Step 1: 读取能力 + 沙箱边界 | scope | 相当于 product_delivery_entry.json 的 scope 阶段。AI Agent 首先读取 developer_entry.json 和 chain_config/developer_sandbox_strategy.json,判断 public sandbox 是否可用,默认按 local fail-closed 路径起步。 |
| Step 2: 读取合约接口包 | codegen 准备 | 读取 contract_reference/core_contracts.json 和 api_specs/formal_contracts.json,获取核心合约 schema、msg.rs、OpenAPI 与 tool manifest。 |
| Step 3: 搭建合约 | codegen | 从合约模板(contract_templates/index.json)和配方(recipes/contract_minimal.json)进入,再按核心合约接口包补充业务消息模型。 |
| Step 4: 搭建 dApp | codegen | 生成钱包、query、execute adapter 与最小前端结构,使用 examples/index.json 和 recipes/dapp_minimal.json。 |
| Step 5: 绑定 API 和 Schema | codegen 收尾 | 把 request/response、receipt/event、contract schema 与 error code 统一到正式索引。 |
| Step 6: 遵循本地 Starter 和 E2E 边界 | quality_gate | 先走 local verified path,不把 local starter 误当 public E2E。使用 quickstart/ai_agent_dapp_starter_README.md 和 release_pack/developer_dapp_starter_e2e_manifest.json。 |
| Step 7: 准备受保护发布计划 | deploy_and_verify | 形成命令、验收、receipt/query/log 证据计划。使用 release_pack/index.json、execution_pack/index.json 和 e2e_fixtures/index.json。 |
5.3 Step 1 详解:读取能力与沙箱边界
消费文件:
developer_entry.json:获取开发者能力矩阵和人类输入要求chain_config/developer_sandbox_strategy.json:获取沙箱默认策略
判断逻辑:
if sandbox_strategy.public_available == true:
use public testnet
else:
use local fail-closed path (default)
边界(来自 contract_and_dapp_minimal.json):
"Quick Start 的目标是让外部 AI 更快进入正确入口,不是替代正式生产契约、公共测试网或最终上线审批。"
"当前 public sandbox 默认为 disabled/fail-closed;没有显式 public proof 前,AI 必须使用 local-only 路径并保留 No-Go 边界。"
5.4 Step 2 详解:读取合约接口包
消费文件:
contract_reference/core_contracts.json:核心合约的 canconical key、address、schema 和 msg.rs 路径api_specs/formal_contracts.json:正式 API/Schema 契约索引
目的:先拿到核心合约 schema、msg.rs、OpenAPI 与 tool manifest,而不是只看模块叙事。
5.5 Step 3 详解:搭建合约
消费文件:
contract_templates/index.json:合约模板索引recipes/contract_minimal.json:最小合约配方
AI Agent 动作:
- 从模板索引选择适用的合约模板
- 根据配方生成合约代码
- 补充业务消息模型
- 生成 cargo test 骨架
5.6 Step 4 详解:搭建 dApp
消费文件:
examples/index.json:dApp 示例索引recipes/dapp_minimal.json:最小 dApp 配方chain_config/network_presets.json:网络预设
AI Agent 动作:
- 使用 dApp 配方生成前端骨架
- 创建钱包接入层
- 生成 query/execute adapter
- 创建最小前端结构
5.7 Step 5 详解:绑定 API 和 Schema
消费文件:
api_specs/formal_contracts.json
AI Agent 动作:
- 将 request/response 类型统一到正式契约
- 绑定 receipt/event schema
- 绑定 error code 和错误处理逻辑
5.8 Step 6 详解:遵循本地 Starter 和 E2E 边界
消费文件:
quickstart/ai_agent_dapp_starter_README.md(本地开发指南)release_pack/developer_dapp_starter_e2e_manifest.json(E2E Manifest)
边界检查清单:
- [ ] 是否已走 local verified path?
- [ ] 是否误将 local starter 当作 public E2E?
- [ ] 是否已记录 local 测试结果作为证据?
5.9 Step 7 详解:准备受保护发布计划
消费文件:
release_pack/index.json:发布包索引execution_pack/index.json:执行包索引e2e_fixtures/index.json:E2E 夹具
产出物:
- 命令执行计划(基于
execution_pack/command_registry.json) - 验收计划(基于
execution_pack/evidence_requirements.json) - 证据收集计划(receipt/query/log)
5.10 最小本地命令序列
contract_and_dapp_minimal.json 定义了 4 步最小本地命令序列:
Order 1: make deps → 准备依赖环境
Order 2: make lint → 尽早发现静态错误
Order 3: make test → 验证主仓库逻辑
Order 4: make ci-contracts → 验证合约 build 与测试闭环
所有命令均来自 execution_pack/command_registry.json,对 AI Agent 安全可执行。
5.11 工作流入口点
Quick Start 定义了 3 个工作流入口点,指向 execution_pack/delivery_workflows.json:
| 工作流 ID | 适用场景 |
|---|---|
contract_delivery_guarded_v1 |
合约交付 |
dapp_delivery_guarded_v1 |
dApp 交付 |
product_launch_guarded_v1 |
产品上线 |
6. 边界与门禁
6.1 人类输入要求(Human Inputs Required)
developer_entry.json 定义了 4 项必须的人类输入要求。这些输入在任何 AI Agent 的交付流程中都不可绕过:
| 编号 | 输入要求 | 适用范围 | 对应交付阶段 |
|---|---|---|---|
| 1 | 产品目标与业务规则 | scope 阶段 | scope |
| 2 | 真实部署权限与签名账户 | deploy_and_verify / launch | deploy_and_verify, launch |
| 3 | 生产环境变量、域名、CI/CD 或发布权限 | deploy_and_verify / launch | deploy_and_verify, launch |
| 4 | 治理、多签、金库、审批等高风险动作的授权与窗口 | launch | launch |
6.1.1 输入要求 1:产品目标与业务规则
当 AI Agent 可以做什么:
- 协助梳理需求
- 生成用户故事
- 建议技术方案
- 评估可行性
当 AI Agent 不能做什么:
- 代替人类决定产品方向
- 自行定义验收标准
- 擅自修改业务规则
6.1.2 输入要求 2:真实部署权限与签名账户
当 AI Agent 可以做什么:
- 准备部署计划
- 编写部署脚本
- 规划部署步骤
- 生成合约 wasm 编译结果
当 AI Agent 不能做什么:
- 持有私钥
- 签署交易
- 执行真实部署
- 访问签名账户
6.1.3 输入要求 3:生产环境变量与发布权限
当 AI Agent 可以做什么:
- 生成
.env.example模板 - 建议环境变量值
- 验证环境变量格式
当 AI Agent 不能做什么:
- 注入真实密钥
- 操作 CI/CD 管道
- 控制域名 DNS
- 访问生产环境
6.1.4 输入要求 4:高风险动作的授权
当 AI Agent 可以做什么:
- 生成多签交易数据
- 准备治理提案文档
- 模拟时间锁执行
- 计算金库操作参数
当 AI Agent 不能做什么:
- 发起多签交易
- 执行治理提案
- 操作时间锁
- 控制金库资金
6.2 三条当前边界
developer_entry.json 定义了三条当前边界(current_boundaries):
边界 1:入口不等于完全自动化
"当前开发协议层可显著提升 AI coding 的可执行性,但仍不能诚实承诺'只靠入口即可 100% 自动完成任何产品上线'。"
解释:product_delivery_entry.json 和 developer_entry.json 提供了结构化的入口文件,但产品的完整交付仍然需要人类参与。AI Agent 不应误以为仅靠入口文件就能完全自主完成所有产品上线。
对 Agent 的约束:
- 必须检查每个阶段是否需要人类输入
- 在
requires_human_input: true的阶段必须等待人类批准 - 不能承诺 100% 零人工交付
边界 2:已补充但仍不是生产就绪
"当前已补 Quick Start、source-backed 合约消费索引、正式 API/Schema 契约索引与 fail-closed sandbox 策略,但仍不等于 signed public SDK、public sandbox 或 not independently verified for production 交付。"
解释:虽然已有 Quick Start、合约索引和沙箱策略,但以下内容仍未就绪:
- 签名的公开 SDK
- 公开的开发者沙箱
- 生产就绪的交付流水线
对 Agent 的约束:
- 必须区分"已实现"和"生产就绪"的区别
- 不能将
source_backed_reference误认为production_supported - 必须按照
developer_capability_matrix.json中的machine_readiness字段判断能力级别
边界 3:密钥和权限相关操作必须有人类门禁
"涉及私钥、部署权限、生产域名、资金操作、DAO/timelock/threshold 的动作,必须保留人类确认与审批门禁。"
解释:以下操作必须经过人类审批:
- 私钥操作
- 部署权限操作
- 域名控制操作
- 资金操作
- DAO 治理操作
- 时间锁操作
- 阈值签名操作
6.3 额外硬边界
product_delivery_entry.json 自身定义了额外的 2 条硬边界(hard_boundaries):
硬边界 A:执行层协议包不等于零人工上线
"不能把执行层协议包解释成 100% 零人工生产上线承诺。"
解释:execution_pack 提供的是流程的机器化定义,而不是完全自动化的授权。AI Agent 必须清楚地区分"流程定义"和"执行授权"。
硬边界 B:无原始证据时必须停在计划态
"没有真实环境变量、签名账户、审批和 raw evidence 时,AI agent 必须停在计划态或 stub 态。"
解释:在以下条件未满足时,AI Agent 必须停在计划态或 stub 态:
- 真实环境变量:未提供
- 签名账户:未提供
- 审批流程:未通过
- 原始证据:未收集
6.4 执行包的边界
execution_pack/index.json 也定义了自己的边界:
"执行层协议包把流程机器化,不等于授权 AI 跨越生产审批。"
"涉及真实部署、私钥、资金、治理、域名与 CI/CD 权限时必须转入人工确认。"
这与 product_delivery_entry.json 的硬边界保持一致。
6.5 能力矩阵的边界参考
developer_capability_matrix.json 为每个开发者表面定义了 machine_readiness 级别:
| 就绪级别 | 含义 | AI Agent 行为 |
|---|---|---|
assisted_codegen |
AI 可辅助代码生成 | 可自主执行 codegen 和 quality_gate |
source_backed_reference |
源码支持参考 | 可读取作为参考,不可用于写入 |
production_reference |
生产参考 | 可查询生产数据,不可修改 |
guarded_integration |
受保护集成 | 可在受保护环境下使用 |
read_only_assist |
只读辅助 | 只能读取,不可写入 |
guarded_write |
受保护写入 | 写入需经过审批 |
local_candidate |
本地候选 | 仅限 local 环境使用 |
starter_ready |
快速入门就绪 | 可用于起步,不可用于生产 |
fail_closed_reference |
故障关闭参考 | 默认不可用 |
6.6 引用关系验证
边界体系形成多层验证网:
product_delivery_entry.json
├── hard_boundaries: 2 条 (双层)
└── phases[].requires_human_input: 5 个阶段标识
developer_entry.json
├── human_inputs_required: 4 项
├── current_boundaries: 3 条
└── key_modules[].status: implemented/partial
execution_pack/index.json
└── boundary: 2 条
contract_and_dapp_minimal.json
└── boundary: 2 条
developer_capability_matrix.json
└── items[].machine_readiness: 12 个表面级别
6.7 AI Agent 边界检查清单
在交付流程的每个阶段,AI Agent 应执行以下边界检查:
□ 阶段 1 (scope):
- 人类是否已确认产品目标? [必须]
- 人类是否已提供业务规则? [必须]
- 验收标准是否已锁定? [必须]
□ 阶段 2 (codegen):
- 是否已读取能力矩阵? [建议]
- 是否已遵循沙箱策略? [必须]
□ 阶段 3 (quality_gate):
- 命令是否来自 command_registry? [必须]
- 命令是否 safe_for_agent? [必须]
- 命令原始输出是否已保存? [建议]
□ 阶段 4 (deploy_and_verify):
- 是否处于计划态? [必须]
- 人类是否已注入密钥? [必须]
- 人类是否已提供签名账户? [必须]
- 证据模板是否已准备? [建议]
□ 阶段 5 (launch):
- 人类审批是否已通过? [必须]
- 回滚句柄是否已保留? [必须]
- raw evidence 是否已收集? [必须]
6.8 证据感知交付
product_delivery_entry.json 的设计强调"证据感知"(evidence-aware)的交付模型。这意味着:
- 每个交付动作都应产生可验证的证据:AI Agent 执行的每个命令都应保存原始输出
- 证据类型标准化:tx hash、receipt、post-state query、log
- 证据索引:
modules/evidence_index.html提供证据的索引入口 - 证据价值:没有证据的动作不能被认定为"已完成"
7. 代码示例
7.1 产品交付入口发现器
import json
from typing import Any
import httpx
PRODUCT_DELIVERY_ENTRY = 'https://msgchain.org/whitepaper/product_delivery_entry.json'
DEVELOPER_ENTRY = 'https://msgchain.org/whitepaper/developer_entry.json'
EXECUTION_PACK_INDEX = 'https://msgchain.org/whitepaper/execution_pack/index.json'
DELIVERY_WORKFLOWS = 'https://msgchain.org/whitepaper/execution_pack/delivery_workflows.json'
COMMAND_REGISTRY = 'https://msgchain.org/whitepaper/execution_pack/command_registry.json'
async def fetch_json(url: str) -> dict[str, Any]:
async with httpx.AsyncClient() as client:
response = await client.get(url)
response.raise_for_status()
return response.json()
async def discover_product_delivery() -> dict[str, Any]:
entry = await fetch_json(PRODUCT_DELIVERY_ENTRY)
return {
'schema_version': entry.get('schema_version'),
'project': entry.get('project'),
'description': entry.get('description'),
'entry_points': entry.get('entry_points', {}),
'phases': entry.get('phases', []),
'human_gates': [
p.get('id') for p in entry.get('phases', [])
if p.get('requires_human_input', False)
],
'hard_boundaries': entry.get('hard_boundaries', []),
}
async def get_delivery_phases() -> list[dict[str, Any]]:
entry = await fetch_json(PRODUCT_DELIVERY_ENTRY)
return entry.get('phases', [])
7.2 交付就绪验证器
async def validate_delivery_readiness(phase: str) -> dict[str, Any]:
entry = await fetch_json(PRODUCT_DELIVERY_ENTRY)
phases = entry.get('phases', [])
phase_map = {p['id']: p for p in phases}
if phase not in phase_map:
return {
'ready': False,
'reason': f'phase "{phase}" not found in product_delivery_entry.json',
'valid_phases': list(phase_map.keys()),
}
phase_def = phase_map[phase]
if phase == 'scope':
return {
'ready': True,
'requires_human': True,
'consumes': ['product_delivery_entry.json'],
'human_gates': ['产品目标与业务规则'],
'next_steps': [
'read developer_entry.json',
'read quickstart/contract_and_dapp_minimal.json',
],
}
if phase == 'codegen':
developer_entry = await fetch_json(DEVELOPER_ENTRY)
return {
'ready': True,
'requires_human': False,
'consumes': [
'developer_entry.json',
'contract_templates/index.json',
'recipes/contract_minimal.json',
'examples/index.json',
'recipes/dapp_minimal.json',
],
'capability_matrix': developer_entry.get('entry_points', {}).get(
'developer_capability_matrix_json', 'not found'
),
'human_gates': [],
'sandbox_note': 'default to local fail-closed; check developer_sandbox_strategy.json',
}
if phase == 'quality_gate':
cmd_registry = await fetch_json(COMMAND_REGISTRY)
safe_commands = [
cmd for cmd in cmd_registry.get('commands', [])
if cmd.get('safe_for_agent', False)
]
return {
'ready': True,
'requires_human': False,
'commands': safe_commands,
'human_gates': [],
'note': 'all safe_for_agent commands are agent-executable',
}
if phase in ('deploy_and_verify', 'launch'):
return {
'ready': True,
'requires_human': True,
'consumes': [
'release_pack/index.json',
'execution_pack/approval_gates.json',
'e2e_fixtures/index.json',
],
'human_gates': [
'真实部署权限与签名账户',
'生产环境变量与发布权限',
'治理、多签、金库、审批等高风险动作的授权与窗口',
],
'conditions': [
'真实环境变量 must be provided',
'签名账户 must be provided',
'审批 must be completed',
'raw evidence must be collected',
],
}
return {'ready': False, 'reason': 'unexpected phase'}
7.3 全生命周期引导器
async def resolve_full_lifecycle_order() -> list[dict[str, Any]]:
developer_entry = await fetch_json(DEVELOPER_ENTRY)
order = developer_entry.get('recommended_full_lifecycle_order', [])
resolved = []
base = 'https://msgchain.org/whitepaper/'
for step_no, path in enumerate(order, 1):
resolved.append({
'step': step_no,
'path': path,
'url': base + path,
})
return resolved
async def execute_lifecycle_step(step_path: str) -> dict[str, Any]:
base = 'https://msgchain.org/whitepaper/'
url = base + step_path
data = await fetch_json(url)
return {
'path': step_path,
'url': url,
'schema_version': data.get('schema_version'),
'description': data.get('description', data.get('project', '')),
'entry_points': list(data.get('entry_points', {}).keys())[:5],
}
7.4 交付工作流执行器
async def load_delivery_workflows() -> list[dict[str, Any]]:
workflows_data = await fetch_json(DELIVERY_WORKFLOWS)
return workflows_data.get('workflows', [])
async def get_workflow(workflow_id: str) -> dict[str, Any]:
workflows = await load_delivery_workflows()
for wf in workflows:
if wf.get('workflow_id') == workflow_id:
return wf
return {}
async def run_scope_phase(workflow_id: str) -> dict[str, Any]:
workflow = await get_workflow(workflow_id)
if not workflow:
return {'status': 'error', 'message': f'workflow {workflow_id} not found'}
phases = workflow.get('phases', [])
scope_phase = next((p for p in phases if p.get('id') == 'scope'), None)
if not scope_phase:
return {'status': 'error', 'message': 'no scope phase found'}
return {
'status': 'blocked',
'phase': 'scope',
'approval_gate': scope_phase.get('approval_gate'),
'consumes': scope_phase.get('consumes', []),
'produces': scope_phase.get('produces', []),
'message': 'human must confirm product goals and business rules',
}
7.5 命令注册表执行器
async def get_available_commands(stage: str | None = None) -> list[dict[str, Any]]:
cmd_data = await fetch_json(COMMAND_REGISTRY)
commands = cmd_data.get('commands', [])
if stage:
commands = [c for c in commands if c.get('stage') == stage]
return [
{
'id': cmd['id'],
'command': cmd['command'],
'stage': cmd['stage'],
'safe_for_agent': cmd['safe_for_agent'],
'requires_human_approval': cmd['requires_human_approval'],
'outputs': cmd['outputs'],
}
for cmd in commands
]
async def execute_command_safely(cmd_id: str) -> dict[str, Any]:
commands = await get_available_commands()
cmd_map = {c['id']: c for c in commands}
if cmd_id not in cmd_map:
return {
'status': 'error',
'message': f'command "{cmd_id}" not found in command_registry.json',
}
cmd = cmd_map[cmd_id]
if cmd['requires_human_approval']:
return {
'status': 'blocked',
'command_id': cmd_id,
'command': cmd['command'],
'reason': 'this command requires human approval',
'next_step': 'wait for production_release gate approval',
}
if not cmd['safe_for_agent']:
return {
'status': 'blocked',
'command_id': cmd_id,
'reason': 'command is not safe for agent execution',
}
return {
'status': 'ready',
'command_id': cmd_id,
'command': cmd['command'],
'stage': cmd['stage'],
'expected_outputs': cmd['outputs'],
'message': 'agent may execute this command autonomously',
}
7.6 证据收集器
async def collect_evidence() -> dict[str, Any]:
evidence = {
'tx_hash': None,
'receipt': None,
'post_state_query': None,
'logs': [],
'artifact_manifest': None,
}
cmd_outputs = await execute_command_safely('package_deploy')
if cmd_outputs.get('status') == 'ready':
evidence['artifact_manifest'] = {
'type': 'deploy_package',
'command_id': 'package_deploy',
'outputs': cmd_outputs.get('expected_outputs', []),
}
return evidence
async def verify_evidence_requirements() -> dict[str, Any]:
try:
evidence_req = await fetch_json(
'https://msgchain.org/whitepaper/execution_pack/evidence_requirements.json'
)
return evidence_req
except Exception:
return {
'note': 'evidence_requirements.json not yet available',
'fallback': 'use e2e_fixtures templates',
}
7.6 Quick Start 执行器
async def execute_quickstart() -> dict[str, Any]:
quickstart = await fetch_json(
'https://msgchain.org/whitepaper/quickstart/contract_and_dapp_minimal.json'
)
steps = quickstart.get('steps', [])
results = []
for step_def in steps:
step_no = step_def.get('step')
action = step_def.get('action')
consumes = step_def.get('consumes', [])
step_result = {
'step': step_no,
'action': action,
'consumes': consumes,
'purpose': step_def.get('purpose'),
'read_files': [],
}
for file_path in consumes:
try:
url = f'https://msgchain.org/whitepaper/{file_path}'
data = await fetch_json(url)
step_result['read_files'].append({
'path': file_path,
'status': 'found',
'keys': list(data.keys()),
})
except Exception:
step_result['read_files'].append({
'path': file_path,
'status': 'not_found',
})
results.append(step_result)
return {
'quickstart_id': quickstart.get('quickstart_id'),
'title': quickstart.get('title'),
'steps_completed': len(results),
'steps': results,
}
7.7 沙箱策略检查器
async def check_sandbox_availability() -> dict[str, Any]:
try:
sandbox = await fetch_json(
'https://msgchain.org/whitepaper/chain_config/developer_sandbox_strategy.json'
)
public_available = sandbox.get('public_available', False)
fail_closed = sandbox.get('fail_closed', True)
if fail_closed or not public_available:
return {
'status': 'local_only',
'mode': 'fail_closed',
'default_path': 'local fail-closed',
'message': 'public sandbox is disabled; use local-only path',
'see': 'quickstart/contract_and_dapp_minimal.json for local steps',
}
return {
'status': 'public_available',
'mode': 'public_testnet',
'message': 'public sandbox is available',
}
except Exception:
return {
'status': 'unknown',
'mode': 'fail_closed_default',
'message': (
'sandbox strategy not readable; '
'default to fail-closed local path'
),
}
7.8 人类门禁检查器
async def check_human_gates(phase_id: str) -> dict[str, Any]:
entry = await fetch_json(PRODUCT_DELIVERY_ENTRY)
phases = entry.get('phases', [])
phase_map = {p['id']: p for p in phases}
if phase_id not in phase_map:
return {'gate_status': 'unknown', 'phase': phase_id}
phase = phase_map[phase_id]
requires_human = phase.get('requires_human_input', True)
if not requires_human:
return {
'gate_status': 'open',
'phase': phase_id,
'requires_human': False,
'message': 'AI agent may proceed autonomously',
}
developer_entry = await fetch_json(DEVELOPER_ENTRY)
human_inputs = developer_entry.get('human_inputs_required', [])
return {
'gate_status': 'blocked',
'phase': phase_id,
'requires_human': True,
'human_inputs_required': human_inputs,
'message': 'waiting for human input before proceeding',
'gates': [
{
'id': 'scope_lock',
'applies_to': ['scope'],
'description': 'human must lock scope and acceptance criteria',
},
{
'id': 'secret_injection',
'applies_to': ['deploy_and_verify'],
'description': 'human must provide secrets and signing accounts',
},
{
'id': 'production_release',
'applies_to': ['launch'],
'description': 'human must approve production release',
},
],
}
7.9 完整交付流程编排器
async def orchestrate_product_delivery(
delivery_type: str = 'full_lifecycle'
) -> dict[str, Any]:
entry = await fetch_json(PRODUCT_DELIVERY_ENTRY)
phases = entry.get('phases', [])
phase_results = []
for phase in phases:
phase_id = phase['id']
requires_human = phase.get('requires_human_input', True)
readiness = await validate_delivery_readiness(phase_id)
gates = await check_human_gates(phase_id)
phase_results.append({
'phase': phase_id,
'goal': phase['goal'],
'requires_human': requires_human,
'ready': readiness.get('ready', False),
'gate_status': gates.get('gate_status', 'unknown'),
'gates_required': gates.get('gates', []),
})
capability_matrix = await fetch_json(
'https://msgchain.org/whitepaper/developer_capability_matrix.json'
)
return {
'product_delivery': {
'schema_version': entry.get('schema_version'),
'project': entry.get('project'),
'description': entry.get('description'),
},
'phases': phase_results,
'hard_boundaries': entry.get('hard_boundaries', []),
'human_inputs_required': (
await fetch_json(DEVELOPER_ENTRY)
).get('human_inputs_required', []),
'current_boundaries': (
await fetch_json(DEVELOPER_ENTRY)
).get('current_boundaries', []),
'surfaces': [
{
'surface_id': s['surface_id'],
'machine_readiness': s['machine_readiness'],
'write_path_ready': s['write_path_ready'],
'production_supported': s['production_supported'],
}
for s in capability_matrix.get('items', [])
],
'summary': {
'total_phases': len(phases),
'human_gated_phases': sum(
1 for p in phases if p.get('requires_human_input', False)
),
'agent_autonomous_phases': sum(
1 for p in phases if not p.get('requires_human_input', True)
),
'delivery_readiness': 'guarded' if any(
p.get('requires_human_input', False) for p in phases
) else 'autonomous',
},
}
7.10 CLI 入口示例
async def main():
import sys
action = sys.argv[1] if len(sys.argv) > 1 else 'discover'
if action == 'discover':
result = await discover_product_delivery()
print(json.dumps(result, indent=2, ensure_ascii=False))
elif action == 'phases':
phases = await get_delivery_phases()
print(json.dumps(phases, indent=2, ensure_ascii=False))
elif action == 'ready':
phase = sys.argv[2] if len(sys.argv) > 2 else 'scope'
result = await validate_delivery_readiness(phase)
print(json.dumps(result, indent=2, ensure_ascii=False))
elif action == 'workflows':
workflows = await load_delivery_workflows()
print(json.dumps(workflows, indent=2, ensure_ascii=False))
elif action == 'commands':
stage = sys.argv[2] if len(sys.argv) > 2 else None
cmds = await get_available_commands(stage)
print(json.dumps(cmds, indent=2, ensure_ascii=False))
elif action == 'gates':
phase = sys.argv[2] if len(sys.argv) > 2 else 'scope'
result = await check_human_gates(phase)
print(json.dumps(result, indent=2, ensure_ascii=False))
elif action == 'quickstart':
result = await execute_quickstart()
print(json.dumps(result, indent=2, ensure_ascii=False))
elif action == 'lifecycle':
order = await resolve_full_lifecycle_order()
print(json.dumps(order, indent=2, ensure_ascii=False))
elif action == 'orchestrate':
result = await orchestrate_product_delivery()
print(json.dumps(result, indent=2, ensure_ascii=False))
else:
print(f'Usage: {sys.argv[0]} [discover|phases|ready|workflows|commands|gates|quickstart|lifecycle|orchestrate]')
if __name__ == '__main__':
import asyncio
asyncio.run(main())
7.11 TypeScript 版本入口
const PRODUCT_DELIVERY_ENTRY = 'https://msgchain.org/whitepaper/product_delivery_entry.json';
const DEVELOPER_ENTRY = 'https://msgchain.org/whitepaper/developer_entry.json';
interface DeliveryPhase {
id: string;
goal: string;
requires_human_input: boolean;
}
interface ProductDeliveryEntry {
schema_version: string;
project: string;
description: string;
entry_points: Record<string, string>;
phases: DeliveryPhase[];
hard_boundaries: string[];
}
async function discoverProductDelivery(): Promise<ProductDeliveryEntry> {
const response = await fetch(PRODUCT_DELIVERY_ENTRY);
return response.json();
}
async function checkPhaseGate(phaseId: string): Promise<{
status: string;
requiresHuman: boolean;
gates: string[];
}> {
const entry = await discoverProductDelivery();
const phase = entry.phases.find(p => p.id === phaseId);
if (!phase) {
return { status: 'unknown', requiresHuman: true, gates: [] };
}
const developerResponse = await fetch(DEVELOPER_ENTRY);
const developerEntry = await developerResponse.json();
return {
status: phase.requires_human_input ? 'blocked' : 'open',
requiresHuman: phase.requires_human_input,
gates: phase.requires_human_input
? developerEntry.human_inputs_required || []
: [],
};
}
7.12 Rust 版本入口
use serde::Deserialize;
use reqwest;
#[derive(Debug, Deserialize)]
struct ProductDeliveryEntry {
schema_version: String,
project: String,
description: String,
phases: Vec<Phase>,
hard_boundaries: Vec<String>,
}
#[derive(Debug, Deserialize)]
struct Phase {
id: String,
goal: String,
requires_human_input: bool,
}
#[derive(Debug, Deserialize)]
struct DeveloperEntry {
human_inputs_required: Vec<String>,
current_boundaries: Vec<String>,
}
async fn discover_product_delivery() -> Result<ProductDeliveryEntry, reqwest::Error> {
let resp = reqwest::get(
"https://msgchain.org/whitepaper/product_delivery_entry.json"
).await?;
let entry: ProductDeliveryEntry = resp.json().await?;
Ok(entry)
}
async fn check_human_gates(
phase_id: &str
) -> Result<Vec<String>, reqwest::Error> {
let entry = discover_product_delivery().await?;
let phase = entry.phases.iter()
.find(|p| p.id == phase_id);
if let Some(p) = phase {
if p.requires_human_input {
let dev_resp = reqwest::get(
"https://msgchain.org/whitepaper/developer_entry.json"
).await?;
let dev_entry: DeveloperEntry = dev_resp.json().await?;
return Ok(dev_entry.human_inputs_required);
}
}
Ok(vec![])
}
7.13 边界断言工具
def assert_hard_boundaries_respected(
phase_id: str,
has_env: bool = False,
has_signer: bool = False,
has_approval: bool = False,
has_evidence: bool = False,
) -> None:
"""
Assert that the hard boundary conditions from product_delivery_entry.json
are respected before proceeding with deploy_and_verify or launch phases.
"""
if phase_id not in ('deploy_and_verify', 'launch'):
return
violations = []
if not has_env:
violations.append(
'硬边界违例: 没有真实环境变量时不能进入 deploy/launch 阶段。'
)
if not has_signer:
violations.append(
'硬边界违例: 没有签名账户时不能进入 deploy/launch 阶段。'
)
if not has_approval:
violations.append(
'硬边界违例: 没有审批时不能进入 deploy/launch 阶段。'
)
if not has_evidence:
violations.append(
'硬边界违例: 没有 raw evidence 时不能进入 deploy/launch 阶段。'
)
if violations:
raise RuntimeError(
'Product delivery hard boundary violate[未公开路径]'
+ '\n'.join(f' - {v}' for v in violations)
)
print(
f'Phase "{phase_id}": all hard boundary conditions satisfied. '
'Proceeding with guarded delivery.'
)
def validate_phase_transition(
current_phase: str,
next_phase: str,
approvals: dict[str, bool],
) -> bool:
"""
Validate that all required approvals are obtained before
transitioning between phases.
Required approvals by phase:
- scope_lock for scope transitions
- secret_injection for deploy_and_verify transitions
- production_release for launch transitions
"""
gate_map = {
'scope': 'scope_lock',
'deploy_and_verify': 'secret_injection',
'launch': 'production_release',
}
required_gate = gate_map.get(next_phase)
if required_gate and not approvals.get(required_gate, False):
print(
f'Cannot transition from "{current_phase}" to "{next_phase}": '
f'approval gate "{required_gate}" not yet satisfied.'
)
return False
return True
7.14 合约引导路线解析器
async def resolve_contract_bootstrap_order() -> list[dict[str, Any]]:
developer_entry = await fetch_json(DEVELOPER_ENTRY)
order = developer_entry.get('recommended_contract_bootstrap_order', [])
resolved = []
base = 'https://msgchain.org/whitepaper/'
for step_no, path in enumerate(order, 1):
resolved.append({
'step': step_no,
'path': path,
'url': base + path,
})
return resolved
async def validate_contract_bootstrap_path() -> dict[str, Any]:
order = await resolve_contract_bootstrap_order()
statuses = []
for step in order:
try:
async with httpx.AsyncClient() as client:
resp = await client.head(step['url'])
statuses.append({
'step': step['step'],
'path': step['path'],
'accessible': resp.status_code == 200,
'status_code': resp.status_code,
})
except Exception as e:
statuses.append({
'step': step['step'],
'path': step['path'],
'accessible': False,
'error': str(e),
})
accessible = sum(1 for s in statuses if s['accessible'])
return {
'total_steps': len(order),
'accessible': accessible,
'blocked': len(order) - accessible,
'details': statuses,
}
7.15 执行包索引解析
async def load_execution_pack_index() -> dict[str, Any]:
index = await fetch_json(EXECUTION_PACK_INDEX)
files = index.get('files', [])
file_details = []
for f in files:
file_details.append({
'id': f.get('id'),
'path': f.get('path'),
'public_url': f.get('public_url'),
})
return {
'description': index.get('description'),
'contract_package_count': index.get('contract_package_count'),
'files': file_details,
'boundaries': index.get('boundary', []),
}
7.16 完整启动脚本
async def bootstrap_product_delivery() -> dict[str, Any]:
discovery = await discover_product_delivery()
print(f'MSG Chain Product Delivery Entry: {discovery["schema_version"]}')
print(f'Project: {discovery["project"]}')
print(f'Description: {discovery["description"]}')
print(f'Phases: {len(discovery["phases"])}')
print(f'Hard Boundaries: {len(discovery["hard_boundaries"])}')
print()
phases_data = await get_delivery_phases()
for phase in phases_data:
icon = '🔒' if phase['requires_human_input'] else '🤖'
print(f' {icon} {phase["id"]}: {phase["goal"]}')
print()
boundaries = discovery['hard_boundaries']
for i, boundary in enumerate(boundaries, 1):
print(f' Boundary {i}: {boundary}')
print()
developer_data = await fetch_json(DEVELOPER_ENTRY)
human_inputs = developer_data.get('human_inputs_required', [])
print('Human Inputs Required:')
for inp in human_inputs:
print(f' - {inp}')
print()
boundaries_dev = developer_data.get('current_boundaries', [])
print('Current Developer Boundaries:')
for b in boundaries_dev:
print(f' - {b}')
return {
'product_delivery_schema': discovery['schema_version'],
'phase_count': len(discovery['phases']),
'human_gated_phases': [
p['id'] for p in phases_data if p['requires_human_input']
],
'agent_phases': [
p['id'] for p in phases_data if not p['requires_human_input']
],
'boundaries': boundaries,
'human_inputs': human_inputs,
}
if __name__ == '__main__':
import asyncio
result = asyncio.run(bootstrap_product_delivery())
print(json.dumps(result, indent=2, ensure_ascii=False))
附录
A. 文件引用总表
以下文件均在 MSG Chain 白皮书中实际存在,可通过公开 URL 访问:
| 文件路径 | 描述 | 公开 URL |
|---|---|---|
product_delivery_entry.json |
产品交付入口(本文核心) | https://msgchain.org/whitepaper/product_delivery_entry.json |
developer_entry.json |
开发者入口 | https://msgchain.org/whitepaper/developer_entry.json |
agent_entry.json |
Agent 入口 | https://msgchain.org/whitepaper/agent_entry.json |
quickstart/index.json |
快速入门索引 | https://msgchain.org/whitepaper/quickstart/index.json |
quickstart/contract_and_dapp_minimal.json |
7 步 Contract+dApp Quick Start | https://msgchain.org/whitepaper/quickstart/contract_and_dapp_minimal.json |
chain_config/developer_sandbox_strategy.json |
沙箱策略 | https://msgchain.org/whitepaper/chain_config/developer_sandbox_strategy.json |
chain_config/index.json |
链配置索引 | https://msgchain.org/whitepaper/chain_config/index.json |
contract_reference/index.json |
合约参考索引 | https://msgchain.org/whitepaper/contract_reference/index.json |
contract_reference/core_contracts.json |
核心合约清单 | https://msgchain.org/whitepaper/contract_reference/core_contracts.json |
api_specs/formal_contracts.json |
正式 API/Schema 契约 | https://msgchain.org/whitepaper/api_specs/formal_contracts.json |
developer_capability_matrix.json |
开发者能力矩阵 | https://msgchain.org/whitepaper/developer_capability_matrix.json |
execution_pack/index.json |
执行包索引 | https://msgchain.org/whitepaper/execution_pack/index.json |
execution_pack/delivery_workflows.json |
交付工作流定义 | https://msgchain.org/whitepaper/execution_pack/delivery_workflows.json |
execution_pack/command_registry.json |
命令注册表 | https://msgchain.org/whitepaper/execution_pack/command_registry.json |
release_pack/index.json |
发布包索引 | https://msgchain.org/whitepaper/release_pack/index.json |
e2e_fixtures/index.json |
E2E 夹具索引 | https://msgchain.org/whitepaper/e2e_fixtures/index.json |
B. 命令注册表完整列表
| 命令 ID | 命令 | 阶段 | 安全 | 需要审批 | 输出 |
|---|---|---|---|---|---|
| deps | make deps |
prepare | 是 | 否 | Go module cache, dependency verification |
| lint | make lint |
quality_gate | 是 | 否 | gofmt check, go vet, golangci-lint |
| test | make test |
quality_gate | 是 | 否 | pkg test results |
| test_quantum | make test-quantum |
quality_gate | 是 | 否 | pkg/quantum test results |
| build_linux | make build-linux |
build | 是 | 否 | bin/genesis_node_linux, bin/quantum_node_linux |
| ci_contracts | make ci-contracts |
contract_validation | 是 | 否 | all contract wasm build, all contract cargo test |
| package_deploy | make package |
artifact_packaging | 是 | 否 | deploy-<version>, deploy-<version>.tar.gz |
| whitepaper_generate | whitepaper_build_pipeline |
docs_generate | 是 | 否 | docs/architecture_diagrams/*.json, *.html |
| whitepaper_audit | whitepaper_quality_gate |
docs_quality_gate | 是 | 否 | module_audit_report.json |
| whitepaper_sync | python3 scripts/sync_whitepaper.py |
site_sync | 是 | 否 | ../msgchainorg/whitepaper/* |
| cloudflare_pages_deploy | npx wrangler pages deploy . --project-name msgchainorg ... |
release | 否 | 是 | pages deployment, pages.dev preview, custom domain rollout |
C. 版本历史
| 版本 | 日期 | 变更说明 |
|---|---|---|
| v1 | 2026-07 | 初始版本,基于 product_delivery_entry.json schema_version v1 |
本文档基于 MSG Chain 白皮书机器学习层的实际 JSON 文件生成。所有引用均指向真实存在的文件路径。AI Agent 应遵循本文档定义的阶段模型、门禁要求和边界约束进行产品交付。
