dApp Docs/AI Agent 产品交付入口与全生命周期协议
Development reference. Not independently verified for production.

AI Agent 产品交付入口与全生命周期协议

基于 MSG Chain 官方 product_delivery_entry.json(schema_version: v1)
生成管道: msg_whitepaper_pipeline_v1
元数据画像: public_stable
文档版本: 2026-07

⚠️ No-Go Disclaimer: MSGChain 主网裁决为 No-Go。本文件所有内容反映的是开发阶段的技术设计,不代表主网未独立核验上线状态。生产部署状态请以白皮书为准:https://msgchain.org/whitepaper/


1. 概述

1.1 什么是 product_delivery_entry.json

product_delivery_entry.json 是 MSG Chain 白皮书机器层(Machine Layer)中定义的单机入口点(Single Machine Entry),专门面向需要从受限编码(scoped coding)转向有门禁的构建、测试、部署、验证与上线工作流的 AI Agent。

该文件托管于:

https://msgchain.org/whitepaper/product_delivery_entry.json

它的核心定位是:AI Agent 全生命周期产品交付的起始文件。无论 Agent 走合约引导路线、dApp 引导路线还是完整生命周期路线,都从 product_delivery_entry.json 开始。

1.2 在 12 步引导序列中的位置

developer_entry.json 定义了三种引导顺序(bootstrap order),product_delivery_entry.json 在每一种中都排在第一位:

引导路线 第一步 总步数
recommended_full_lifecycle_order product_delivery_entry.json 20 步
recommended_contract_bootstrap_order product_delivery_entry.json 19 步
recommended_dapp_bootstrap_order product_delivery_entry.json 16 步

这意味着任何外部 AI Agent 在接入 MSG Chain 产品交付体系时,必须首先解析 product_delivery_entry.json,获取整个交付流程的元信息和入口指引。

1.3 与 developer_entry.json 的关系

product_delivery_entry.json 和 developer_entry.json 是互补关系:

两者关系在 developer_entry.json 的 entry_points 中有明确声明:

"product_delivery_entry_json": "product_delivery_entry.json",
"product_delivery_entry_json_public_url": "https://msgchain.org/whitepaper/product_delivery_entry.json"

1.4 在 agent_entry.json 中的引用

agent_entry.json(Agent 入口文件)同样将 product_delivery_entry.json 列为关键入口点,并包含在推荐的爬取顺序(recommended_crawl_order)中。它在 crawl_contract 中指定了 developer_entry 和 product_delivery_entry 作为知识网络的组成部分。

1.5 文件元属性

属性 值
schema_version v1
generated_by msg_whitepaper_pipeline_v1
project MSG Chain AI Delivery Entry
public_base_url https://msgchain.org/whitepaper/
metadata_profile public_stable

2. 产品交付入口协议

2.1 Schema 结构总览

product_delivery_entry.json 的顶层字段结构如下:

product_delivery_entry.json
├── schema_version: "v1"
├── generated_by: "msg_whitepaper_pipeline_v1"
├── project: "MSG Chain AI Delivery Entry"
├── description: "Single machine entry for AI agents..."
├── public_base_url: "https://msgchain.org/whitepaper/"
├── entry_points: { ... }        # 入口点映射
├── recommended_full_lifecycle_order: [...]  # 19+1 步全生命周期顺序
├── phases: [...]                # 5 个交付阶段
├── hard_boundaries: [...]       # 2 条硬边界
└── metadata_profile: "public_stable"

2.2 Entry Points(入口点)

entry_points 字段定义了 AI Agent 从产品交付入口可到达的所有子资源。共计 14 个入口点,覆盖 6 大类资源:

2.2.1 开发者入口

键 值 公开 URL
developer_entry_json developer_entry.json https://msgchain.org/whitepaper/developer_entry.json

2.2.2 外部 AI Agent 引导

键 值 公开 URL
external_ai_agent_bootstrap_prompt_json integration_examples/external_ai_agent_bootstrap_prompt.json https://msgchain.org/whitepaper/integration_examples/external_ai_agent_bootstrap_prompt.json
external_ai_agent_bootstrap_prompt_md integration_examples/external_ai_agent_bootstrap_prompt.md https://msgchain.org/whitepaper/integration_examples/external_ai_agent_bootstrap_prompt.md

2.2.3 Quick Start(快速入门)

键 值 公开 URL
quickstart_index_json quickstart/index.json https://msgchain.org/whitepaper/quickstart/index.json
quickstart_contract_and_dapp_json quickstart/contract_and_dapp_minimal.json https://msgchain.org/whitepaper/quickstart/contract_and_dapp_minimal.json

2.2.4 链配置

键 值 公开 URL
developer_sandbox_strategy_json chain_config/developer_sandbox_strategy.json https://msgchain.org/whitepaper/chain_config/developer_sandbox_strategy.json

2.2.5 合约与 API 参考

键 值 公开 URL
contract_reference_index_json contract_reference/index.json https://msgchain.org/whitepaper/contract_reference/index.json
core_contracts_json contract_reference/core_contracts.json https://msgchain.org/whitepaper/contract_reference/core_contracts.json
formal_contracts_json api_specs/formal_contracts.json https://msgchain.org/whitepaper/api_specs/formal_contracts.json

2.2.6 执行与交付包

键 值 公开 URL
execution_pack_index_json execution_pack/index.json https://msgchain.org/whitepaper/execution_pack/index.json
release_pack_index_json release_pack/index.json https://msgchain.org/whitepaper/release_pack/index.json
e2e_fixtures_index_json e2e_fixtures/index.json https://msgchain.org/whitepaper/e2e_fixtures/index.json

2.3 五阶段交付模型

phases 数组定义了产品交付的五个阶段,每个阶段包含 id、goal 和 requires_human_input 三个属性。

Phase 1: scope(范围锁定)

Phase 2: codegen(代码生成)

Phase 3: quality_gate(质量门禁)

Phase 4: deploy_and_verify(部署与验证)

Phase 5: launch(上线)

2.4 各阶段人类参与度一览

阶段 AI 可自主操作 需要人类输入 关键行为
scope 部分 是 锁定范围、规则、验收标准
codegen 全部 否 生成源码、测试、dApp 骨架
quality_gate 全部 否 执行 lint/test/build/contract test
deploy_and_verify 准备阶段 是 部署计划、smoke check、证据收集
launch 不允许自主 是 审批后上线,保留回滚句柄

2.5 硬边界(Hard Boundaries)

hard_boundaries 数组定义了两条不可逾越的硬边界:

[
  "不能把执行层协议包解释成 100% 零人工生产上线承诺。",
  "没有真实环境变量、签名账户、审批和 raw evidence 时,AI agent 必须停在计划态或 stub 态。"
]

边界 1:执行层协议包(execution pack)提供的是机器化的流程定义,并不等同于 AI Agent 可以完全自主完成生产上线。人类审批是最终的防线。

边界 2:在以下条件未满足时,AI Agent 必须停在"计划态"或"stub 态":


3. 全生命周期交付流程

3.1 推荐的 20 步全生命周期顺序

developer_entry.json 中 recommended_full_lifecycle_order 定义了全生命周期产品交付的 20 步引导顺序(product_delivery_entry.json 自身为首步,共 20 个文件)。这与 product_delivery_entry.json 中定义的 recommended_full_lifecycle_order 完全一致。

完整顺序如下:

Step  1: product_delivery_entry.json              ← 本文件(交付入口)
Step  2: developer_entry.json                     ← 开发者入口
Step  3: quickstart/index.json                    ← 快速入门索引
Step  4: quickstart/contract_and_dapp_minimal.json ← Contract + dApp 快速开始
Step  5: chain_config/developer_sandbox_strategy.json ← 沙箱策略
Step  6: contract_reference/index.json             ← 合约参考索引
Step  7: contract_reference/core_contracts.json    ← 核心合约清单
Step  8: api_specs/formal_contracts.json           ← 正式 API/Schema 契约
Step  9: integration_examples/external_ai_agent_bootstrap_prompt.json ← Agent 引导提示
Step 10: developer_capability_matrix.json          ← 开发者能力矩阵
Step 11: chain_config/index.json                   ← 链配置索引
Step 12: contract_templates/index.json             ← 合约模板索引
Step 13: examples/index.json                       ← dApp 示例索引
Step 14: execution_pack/index.json                 ← 执行包索引
Step 15: execution_pack/delivery_workflows.json    ← 交付工作流
Step 16: execution_pack/command_registry.json      ← 命令注册表
Step 17: release_pack/index.json                   ← 发布包索引
Step 18: e2e_fixtures/index.json                   ← 端到端测试夹具
Step 19: modules/review_playbook.html              ← 审查剧本
Step 20: modules/evidence_index.html               ← 证据索引

3.2 步骤详解

Step 1: product_delivery_entry.json

用途:交付入口。AI Agent 读取本文件以了解交付阶段模型、入口点和硬边界。

文件:product_delivery_entry.json

关键内容:

Agent 动作:

entry = fetch("https://msgchain.org/whitepaper/product_delivery_entry.json")
phases = entry["phases"]
hard_boundaries = entry["hard_boundaries"]

Step 2: developer_entry.json

用途:开发者入口。提供开发者能力矩阵、API 规范、合约模板、链配置、执行包、发布包等资源的完整索引。

文件:developer_entry.json

关键内容:

Agent 动作:根据交付目标(合约/dApp/全生命周期)选择对应的 bootstrap order。

Step 3: quickstart/index.json

用途:快速入门索引。提供快速开始资源的入口。

文件:quickstart/index.json

Agent 动作:定位快速开始资源,为后续的快速启动步骤做准备。

Step 4: quickstart/contract_and_dapp_minimal.json

用途:Contract + dApp 快速开始步骤定义。这是一个 7 步指南,指导外部 AI Agent 快速搭建最小可运行的合约和 dApp。

文件:quickstart/contract_and_dapp_minimal.json

关键内容:

Agent 动作:以 7 步流程为指引,生成合约和 dApp 代码。

Step 5: chain_config/developer_sandbox_strategy.json

用途:沙箱策略。定义开发者沙箱的可用性和默认策略。

文件:chain_config/developer_sandbox_strategy.json

边界:当前 public sandbox 默认为 disabled/fail-closed。AI Agent 必须使用 local-only 路径。

Step 6: contract_reference/index.json

用途:合约参考索引。提供核心合约清单和合约目录的入口。

文件:contract_reference/index.json

Step 7: contract_reference/core_contracts.json

用途:核心合约清单。列出所有核心合约的 canonical key、address、schema 和 msg.rs 路径。

文件:contract_reference/core_contracts.json

Agent 动作:读取核心合约的接口定义、消息模型和 schema,为代码生成提供准确的类型信息。

Step 8: api_specs/formal_contracts.json

用途:正式 API/Schema 契约索引。提供机器可消费的 API 定义、RPC 方法和错误码。

文件:api_specs/formal_contracts.json

关联文件:

Step 9: integration_examples/external_ai_agent_bootstrap_prompt.json

用途:外部 AI Agent 引导提示。提供一个可读的引导提示模板,帮助外部 AI Agent 理解 MSG Chain 的架构和接入方式。

文件:integration_examples/external_ai_agent_bootstrap_prompt.json

关联文件:

Step 10: developer_capability_matrix.json

用途:开发者能力矩阵。描述 MSG 开发者表面的机器就绪状态,共计 12 个表面。

文件:developer_capability_matrix.json

表面分类:

表面 机器就绪度 写入路径 生产支持
contract_runtime assisted_codegen 是 是
core_contract_reference_pack source_backed_reference 否 否
registry_resolution production_reference 否 是
rpc_gateway assisted_codegen 是 是
formal_api_schema_pack source_backed_reference 否 否
wallet_frontend guarded_integration 是 否
explorer_receipts read_only_assist 否 否
agent_query_and_guarded_write guarded_write 否 否
sdk_surface local_candidate 否 否
chain_config_pack starter_ready 否 是
public_sandbox_strategy fail_closed_reference 否 否
contract_template_pack starter_ready 否 否

Step 11: chain_config/index.json

用途:链配置索引。提供链配置文件的入口。

文件:chain_config/index.json

关联文件:chain_config/network_presets.json

Step 12: contract_templates/index.json

用途:合约模板索引。提供合约模板的入口,用于快速生成合约代码。

文件:contract_templates/index.json

Step 13: examples/index.json

用途:dApp 示例索引。提供 dApp 示例代码的入口。

文件:examples/index.json

Step 14: execution_pack/index.json

用途:执行包索引。提供面向执行的操作包入口,用于将 AI 编码转化为有门禁的构建/测试/部署/验证工作流。

文件:execution_pack/index.json

包含子文件:

文件 用途
execution_pack/command_registry.json 命令注册表
execution_pack/approval_gates.json 审批门禁定义
execution_pack/delivery_workflows.json 交付工作流
execution_pack/ci_cd_templates.json CI/CD 模板
execution_pack/governance_templates.json 治理模板
execution_pack/multisig_approval_flow.json 多签审批流程
execution_pack/evidence_requirements.json 证据要求
execution_pack/artifact_contracts.json 制品合约

Step 15: execution_pack/delivery_workflows.json

用途:交付工作流。定义了三条受保护的交付工作流:合约交付、dApp 交付和产品上线。

文件:execution_pack/delivery_workflows.json

工作流清单:

  1. contract_delivery_guarded_v1:面向 CosmWasm 合约交付,5 个阶段
  2. dapp_delivery_guarded_v1:面向 MSG dApp 交付,4 个阶段
  3. product_launch_guarded_v1:面向合约 + dApp + 文档组合上线,3 个阶段

Step 16: execution_pack/command_registry.json

用途:命令注册表。定义 AI Agent 可执行的标准化命令,包括命令字符串、工作目录、安全标识和输出物。

文件:execution_pack/command_registry.json

命令清单:

命令 ID 命令 阶段 安全 需要审批
deps make deps prepare 是 否
lint make lint quality_gate 是 否
test make test quality_gate 是 否
test_quantum make test-quantum quality_gate 是 否
build_linux make build-linux build 是 否
ci_contracts make ci-contracts contract_validation 是 否
package_deploy make package artifact_packaging 是 否
cloudflare_pages_deploy npx wrangler pages deploy release 否 是

Step 17: release_pack/index.json

用途:发布包索引。提供发布相关的清单和 Manifest。

文件:release_pack/index.json

包含子文件(共 11 个):

文件 用途
release_pack/.env.example 环境变量样例
release_pack/cloudflare_pages_release_checklist.json Cloudflare Pages 发布清单
release_pack/contract_release_checklist.json 合约发布清单
release_pack/smoke_checks.json Smoke Check 定义
release_pack/developer_capability_manifest.json 能力 Manifest
release_pack/developer_api_schema_pack_manifest.json API Schema 包 Manifest
release_pack/developer_contract_schema_abi_pack_manifest.json 合约 Schema/ABI 包 Manifest
release_pack/developer_public_sandbox_strategy_manifest.json 公开沙箱策略 Manifest
release_pack/developer_dapp_starter_e2e_manifest.json dApp Starter E2E Manifest
release_pack/developer_sdk_signed_release_candidate_manifest.json SDK 签名发布候选 Manifest
release_pack/developer_business_examples_manifest.json 业务示例 Manifest

Step 18: e2e_fixtures/index.json

用途:端到端测试夹具。提供 E2E 测试用的数据夹具。

文件:e2e_fixtures/index.json

包含子文件:

文件 用途
e2e_fixtures/registry_query_fixture.json 注册中心查询夹具
e2e_fixtures/agent_registry_query_fixture.json Agent 注册中心查询夹具
e2e_fixtures/contract_execute_receipt_template.json 合约执行回执模板

Step 19: modules/review_playbook.html

用途:审查剧本。定义交付审核的流程和标准。

文件:modules/review_playbook.html

公开 URL:https://msgchain.org/whitepaper/modules/review_playbook.html

Step 20: modules/evidence_index.html

用途:证据索引。提供交付过程中收集的证据索引。

文件:modules/evidence_index.html

公开 URL:https://msgchain.org/whitepaper/modules/evidence_index.html

3.3 三种引导路线的映射

developer_entry.json 定义了三种引导路线,每种路线都从 product_delivery_entry.json 开始:

合约引导路线(recommended_contract_bootstrap_order)

共 19 步,侧重智能合约开发:

product_delivery_entry.json → developer_capability_matrix.json
→ quickstart/contract_and_dapp_minimal.json → chain_config/index.json
→ chain_config/developer_sandbox_strategy.json → api_specs/rpc_methods.json
→ api_specs/openapi/contract_surface.yaml → api_specs/formal_contracts.json
→ contract_reference/index.json → contract_reference/core_contracts.json
→ contract_templates/index.json → recipes/contract_minimal.json
→ execution_pack/index.json → execution_pack/command_registry.json
→ e2e_fixtures/index.json → modules/contract.html
→ modules/registry.html → modules/rpc.html
→ module_exports/contract.json

dApp 引导路线(recommended_dapp_bootstrap_order)

共 16 步,侧重去中心化应用开发:

product_delivery_entry.json → developer_capability_matrix.json
→ quickstart/contract_and_dapp_minimal.json → chain_config/index.json
→ chain_config/developer_sandbox_strategy.json → api_specs/rpc_methods.json
→ api_specs/openapi/public_query.yaml → api_specs/formal_contracts.json
→ examples/index.json → recipes/dapp_minimal.json
→ execution_pack/index.json → execution_pack/command_registry.json
→ release_pack/index.json → modules/keplr.html
→ modules/rpc.html → modules/explorer.html
→ module_exports/keplr.json

全生命周期引导路线(recommended_full_lifecycle_order)

共 20 步,覆盖完整的端到端产品交付。前面已详述。

3.4 与 execution_pack 的集成

execution_pack 是 product_delivery_entry.json 的重要下游。在 recommended_full_lifecycle_order 中,第 14-16 步都是 execution_pack 的文件:

execution_pack 的边界与 product_delivery_entry.json 一致:

"执行层协议包把流程机器化,不等于授权 AI 跨越生产审批。"
"涉及真实部署、私钥、资金、治理、域名与 CI/CD 权限时必须转入人工确认。"

3.5 与 release_pack 的集成

release_pack 在第 17 步引入,提供发布前的清单检查和环境变量模板:

3.6 与 e2e_fixtures 的集成

e2e_fixtures 在第 18 步引入,提供 E2E 测试用的数据夹具:

这些夹具用于:

  1. 验证部署后的合约状态
  2. 生成预期回执格式
  3. 作为证据收集的参考模板

4. 交付工作流

4.1 三条受保护交付工作流

execution_pack/delivery_workflows.json 定义了三条受保护的工作流,每条都从 product_delivery_entry.json 开始:

4.2 合约交付工作流(contract_delivery_guarded_v1)

适用于:CosmWasm 合约交付

阶段分解:

Phase 1: scope(范围)

Phase 2: design_and_codegen(设计与代码生成)

Phase 3: build_and_test(构建与测试)

Phase 4: deploy_plan(部署计划)

Phase 5: real_release(真实发布)

4.3 dApp 交付工作流(dapp_delivery_guarded_v1)

适用于:MSG dApp 交付

Phase 1: scope(范围)

Phase 2: scaffold(脚手架搭建)

Phase 3: quality_gate(质量门禁)

Phase 4: site_release(站点发布)

4.4 产品上线工作流(product_launch_guarded_v1)

适用于:合约 + dApp + 文档组合上线

Phase 1: compose(组合)

Phase 2: evidence_closeout(证据结案)

Phase 3: launch(上线)

4.5 命令注册表使用

execution_pack/command_registry.json 定义了 11 个标准化命令,其中 10 个对 AI Agent 安全可执行:

命令 ID 阶段 Agent 安全 需要审批
deps prepare 是 否
lint quality_gate 是 否
test quality_gate 是 否
test_quantum quality_gate 是 否
build_linux build 是 否
ci_contracts contract_validation 是 否
package_deploy artifact_packaging 是 否
whitepaper_generate docs_generate 是 否
whitepaper_audit docs_quality_gate 是 否
whitepaper_sync site_sync 是 否
cloudflare_pages_deploy release 否 是

重要:cloudflare_pages_deploy 是唯一需要人类审批的命令。它的执行命令是:

npx wrangler pages deploy . --project-name msgchainorg --branch msgchainorg --commit-dirty=true

4.6 审批门禁类型

工作流中定义了三种审批门禁:

门禁 ID 阶段 说明
scope_lock scope 范围锁定审批,确保产品目标和验收标准已确认
secret_injection deploy_plan 密钥注入审批,涉及真实环境变量和签名账户
production_release real_release / site_release / launch 生产发布审批,最终上线授权

4.7 证据收集体系

product_delivery_entry.json 和 execution_pack 共同定义了证据收集要求。在 deploy_and_verify 和 launch 阶段,AI Agent 必须收集以下证据类型:

4.7.1 区块证据类型

证据类型 来源 用途
tx hash 链上交易 唯一标识一笔已提交的交易
receipt 链上回执 验证交易执行结果
post-state query 链上查询 验证部署后的合约状态
log 节点日志 审计和调试

4.7.2 证据要求文件

execution_pack/evidence_requirements.json 定义了完整的证据标准。E2E 夹具提供了模板参考:

4.7.3 证据收集原则

  1. 原始性:证据必须是原始输出,不能被 AI Agent 改写
  2. 可验证性:证据必须能被第三方独立验证
  3. 完整性:证据必须包含完整的上下文信息
  4. 可审计性:证据必须带有时间戳和来源标记

5. 与 Quick Start 集成

5.1 7 步快速启动模型

quickstart/contract_and_dapp_minimal.json 定义了外部 AI Agent 开发 Contract + dApp 的 7 步快速启动流程。

Step 1: read capability + sandbox boundaries
Step 2: read contract interface pack
Step 3: scaffold contract
Step 4: scaffold dapp
Step 5: bind source-backed API and schema contracts
Step 6: follow local starter and E2E boundary
Step 7: prepare guarded release plan

5.2 步骤与交付阶段的映射

Quick Start 步骤 对应交付阶段 详细说明
Step 1: 读取能力 + 沙箱边界 scope 相当于 product_delivery_entry.json 的 scope 阶段。AI Agent 首先读取 developer_entry.json 和 chain_config/developer_sandbox_strategy.json,判断 public sandbox 是否可用,默认按 local fail-closed 路径起步。
Step 2: 读取合约接口包 codegen 准备 读取 contract_reference/core_contracts.json 和 api_specs/formal_contracts.json,获取核心合约 schema、msg.rs、OpenAPI 与 tool manifest。
Step 3: 搭建合约 codegen 从合约模板(contract_templates/index.json)和配方(recipes/contract_minimal.json)进入,再按核心合约接口包补充业务消息模型。
Step 4: 搭建 dApp codegen 生成钱包、query、execute adapter 与最小前端结构,使用 examples/index.json 和 recipes/dapp_minimal.json。
Step 5: 绑定 API 和 Schema codegen 收尾 把 request/response、receipt/event、contract schema 与 error code 统一到正式索引。
Step 6: 遵循本地 Starter 和 E2E 边界 quality_gate 先走 local verified path,不把 local starter 误当 public E2E。使用 quickstart/ai_agent_dapp_starter_README.md 和 release_pack/developer_dapp_starter_e2e_manifest.json。
Step 7: 准备受保护发布计划 deploy_and_verify 形成命令、验收、receipt/query/log 证据计划。使用 release_pack/index.json、execution_pack/index.json 和 e2e_fixtures/index.json。

5.3 Step 1 详解:读取能力与沙箱边界

消费文件:

判断逻辑:

if sandbox_strategy.public_available == true:
    use public testnet
else:
    use local fail-closed path (default)

边界(来自 contract_and_dapp_minimal.json):

"Quick Start 的目标是让外部 AI 更快进入正确入口,不是替代正式生产契约、公共测试网或最终上线审批。"
"当前 public sandbox 默认为 disabled/fail-closed;没有显式 public proof 前,AI 必须使用 local-only 路径并保留 No-Go 边界。"

5.4 Step 2 详解:读取合约接口包

消费文件:

目的:先拿到核心合约 schema、msg.rs、OpenAPI 与 tool manifest,而不是只看模块叙事。

5.5 Step 3 详解:搭建合约

消费文件:

AI Agent 动作:

  1. 从模板索引选择适用的合约模板
  2. 根据配方生成合约代码
  3. 补充业务消息模型
  4. 生成 cargo test 骨架

5.6 Step 4 详解:搭建 dApp

消费文件:

AI Agent 动作:

  1. 使用 dApp 配方生成前端骨架
  2. 创建钱包接入层
  3. 生成 query/execute adapter
  4. 创建最小前端结构

5.7 Step 5 详解:绑定 API 和 Schema

消费文件:

AI Agent 动作:

  1. 将 request/response 类型统一到正式契约
  2. 绑定 receipt/event schema
  3. 绑定 error code 和错误处理逻辑

5.8 Step 6 详解:遵循本地 Starter 和 E2E 边界

消费文件:

边界检查清单:

5.9 Step 7 详解:准备受保护发布计划

消费文件:

产出物:

  1. 命令执行计划(基于 execution_pack/command_registry.json)
  2. 验收计划(基于 execution_pack/evidence_requirements.json)
  3. 证据收集计划(receipt/query/log)

5.10 最小本地命令序列

contract_and_dapp_minimal.json 定义了 4 步最小本地命令序列:

Order 1: make deps      → 准备依赖环境
Order 2: make lint      → 尽早发现静态错误
Order 3: make test      → 验证主仓库逻辑
Order 4: make ci-contracts → 验证合约 build 与测试闭环

所有命令均来自 execution_pack/command_registry.json,对 AI Agent 安全可执行。

5.11 工作流入口点

Quick Start 定义了 3 个工作流入口点,指向 execution_pack/delivery_workflows.json:

工作流 ID 适用场景
contract_delivery_guarded_v1 合约交付
dapp_delivery_guarded_v1 dApp 交付
product_launch_guarded_v1 产品上线

6. 边界与门禁

6.1 人类输入要求(Human Inputs Required)

developer_entry.json 定义了 4 项必须的人类输入要求。这些输入在任何 AI Agent 的交付流程中都不可绕过:

编号 输入要求 适用范围 对应交付阶段
1 产品目标与业务规则 scope 阶段 scope
2 真实部署权限与签名账户 deploy_and_verify / launch deploy_and_verify, launch
3 生产环境变量、域名、CI/CD 或发布权限 deploy_and_verify / launch deploy_and_verify, launch
4 治理、多签、金库、审批等高风险动作的授权与窗口 launch launch

6.1.1 输入要求 1:产品目标与业务规则

当 AI Agent 可以做什么:

当 AI Agent 不能做什么:

6.1.2 输入要求 2:真实部署权限与签名账户

当 AI Agent 可以做什么:

当 AI Agent 不能做什么:

6.1.3 输入要求 3:生产环境变量与发布权限

当 AI Agent 可以做什么:

当 AI Agent 不能做什么:

6.1.4 输入要求 4:高风险动作的授权

当 AI Agent 可以做什么:

当 AI Agent 不能做什么:

6.2 三条当前边界

developer_entry.json 定义了三条当前边界(current_boundaries):

边界 1:入口不等于完全自动化

"当前开发协议层可显著提升 AI coding 的可执行性,但仍不能诚实承诺'只靠入口即可 100% 自动完成任何产品上线'。"

解释:product_delivery_entry.json 和 developer_entry.json 提供了结构化的入口文件,但产品的完整交付仍然需要人类参与。AI Agent 不应误以为仅靠入口文件就能完全自主完成所有产品上线。

对 Agent 的约束:

边界 2:已补充但仍不是生产就绪

"当前已补 Quick Start、source-backed 合约消费索引、正式 API/Schema 契约索引与 fail-closed sandbox 策略,但仍不等于 signed public SDK、public sandbox 或 not independently verified for production 交付。"

解释:虽然已有 Quick Start、合约索引和沙箱策略,但以下内容仍未就绪:

对 Agent 的约束:

边界 3:密钥和权限相关操作必须有人类门禁

"涉及私钥、部署权限、生产域名、资金操作、DAO/timelock/threshold 的动作,必须保留人类确认与审批门禁。"

解释:以下操作必须经过人类审批:

6.3 额外硬边界

product_delivery_entry.json 自身定义了额外的 2 条硬边界(hard_boundaries):

硬边界 A:执行层协议包不等于零人工上线

"不能把执行层协议包解释成 100% 零人工生产上线承诺。"

解释:execution_pack 提供的是流程的机器化定义,而不是完全自动化的授权。AI Agent 必须清楚地区分"流程定义"和"执行授权"。

硬边界 B:无原始证据时必须停在计划态

"没有真实环境变量、签名账户、审批和 raw evidence 时,AI agent 必须停在计划态或 stub 态。"

解释:在以下条件未满足时,AI Agent 必须停在计划态或 stub 态:

  1. 真实环境变量:未提供
  2. 签名账户:未提供
  3. 审批流程:未通过
  4. 原始证据:未收集

6.4 执行包的边界

execution_pack/index.json 也定义了自己的边界:

"执行层协议包把流程机器化,不等于授权 AI 跨越生产审批。"
"涉及真实部署、私钥、资金、治理、域名与 CI/CD 权限时必须转入人工确认。"

这与 product_delivery_entry.json 的硬边界保持一致。

6.5 能力矩阵的边界参考

developer_capability_matrix.json 为每个开发者表面定义了 machine_readiness 级别:

就绪级别 含义 AI Agent 行为
assisted_codegen AI 可辅助代码生成 可自主执行 codegen 和 quality_gate
source_backed_reference 源码支持参考 可读取作为参考,不可用于写入
production_reference 生产参考 可查询生产数据,不可修改
guarded_integration 受保护集成 可在受保护环境下使用
read_only_assist 只读辅助 只能读取,不可写入
guarded_write 受保护写入 写入需经过审批
local_candidate 本地候选 仅限 local 环境使用
starter_ready 快速入门就绪 可用于起步,不可用于生产
fail_closed_reference 故障关闭参考 默认不可用

6.6 引用关系验证

边界体系形成多层验证网:

product_delivery_entry.json
  ├── hard_boundaries: 2 条 (双层)
  └── phases[].requires_human_input: 5 个阶段标识

developer_entry.json
  ├── human_inputs_required: 4 项
  ├── current_boundaries: 3 条
  └── key_modules[].status: implemented/partial

execution_pack/index.json
  └── boundary: 2 条

contract_and_dapp_minimal.json
  └── boundary: 2 条

developer_capability_matrix.json
  └── items[].machine_readiness: 12 个表面级别

6.7 AI Agent 边界检查清单

在交付流程的每个阶段,AI Agent 应执行以下边界检查:

□ 阶段 1 (scope):
  - 人类是否已确认产品目标? [必须]
  - 人类是否已提供业务规则? [必须]
  - 验收标准是否已锁定? [必须]

□ 阶段 2 (codegen):
  - 是否已读取能力矩阵? [建议]
  - 是否已遵循沙箱策略? [必须]

□ 阶段 3 (quality_gate):
  - 命令是否来自 command_registry? [必须]
  - 命令是否 safe_for_agent? [必须]
  - 命令原始输出是否已保存? [建议]

□ 阶段 4 (deploy_and_verify):
  - 是否处于计划态? [必须]
  - 人类是否已注入密钥? [必须]
  - 人类是否已提供签名账户? [必须]
  - 证据模板是否已准备? [建议]

□ 阶段 5 (launch):
  - 人类审批是否已通过? [必须]
  - 回滚句柄是否已保留? [必须]
  - raw evidence 是否已收集? [必须]

6.8 证据感知交付

product_delivery_entry.json 的设计强调"证据感知"(evidence-aware)的交付模型。这意味着:

  1. 每个交付动作都应产生可验证的证据:AI Agent 执行的每个命令都应保存原始输出
  2. 证据类型标准化:tx hash、receipt、post-state query、log
  3. 证据索引:modules/evidence_index.html 提供证据的索引入口
  4. 证据价值:没有证据的动作不能被认定为"已完成"

7. 代码示例

7.1 产品交付入口发现器

import json
from typing import Any
import httpx

PRODUCT_DELIVERY_ENTRY = 'https://msgchain.org/whitepaper/product_delivery_entry.json'
DEVELOPER_ENTRY = 'https://msgchain.org/whitepaper/developer_entry.json'
EXECUTION_PACK_INDEX = 'https://msgchain.org/whitepaper/execution_pack/index.json'
DELIVERY_WORKFLOWS = 'https://msgchain.org/whitepaper/execution_pack/delivery_workflows.json'
COMMAND_REGISTRY = 'https://msgchain.org/whitepaper/execution_pack/command_registry.json'


async def fetch_json(url: str) -> dict[str, Any]:
    async with httpx.AsyncClient() as client:
        response = await client.get(url)
        response.raise_for_status()
        return response.json()


async def discover_product_delivery() -> dict[str, Any]:
    entry = await fetch_json(PRODUCT_DELIVERY_ENTRY)
    return {
        'schema_version': entry.get('schema_version'),
        'project': entry.get('project'),
        'description': entry.get('description'),
        'entry_points': entry.get('entry_points', {}),
        'phases': entry.get('phases', []),
        'human_gates': [
            p.get('id') for p in entry.get('phases', [])
            if p.get('requires_human_input', False)
        ],
        'hard_boundaries': entry.get('hard_boundaries', []),
    }


async def get_delivery_phases() -> list[dict[str, Any]]:
    entry = await fetch_json(PRODUCT_DELIVERY_ENTRY)
    return entry.get('phases', [])

7.2 交付就绪验证器

async def validate_delivery_readiness(phase: str) -> dict[str, Any]:
    entry = await fetch_json(PRODUCT_DELIVERY_ENTRY)
    phases = entry.get('phases', [])
    phase_map = {p['id']: p for p in phases}

    if phase not in phase_map:
        return {
            'ready': False,
            'reason': f'phase "{phase}" not found in product_delivery_entry.json',
            'valid_phases': list(phase_map.keys()),
        }

    phase_def = phase_map[phase]

    if phase == 'scope':
        return {
            'ready': True,
            'requires_human': True,
            'consumes': ['product_delivery_entry.json'],
            'human_gates': ['产品目标与业务规则'],
            'next_steps': [
                'read developer_entry.json',
                'read quickstart/contract_and_dapp_minimal.json',
            ],
        }

    if phase == 'codegen':
        developer_entry = await fetch_json(DEVELOPER_ENTRY)
        return {
            'ready': True,
            'requires_human': False,
            'consumes': [
                'developer_entry.json',
                'contract_templates/index.json',
                'recipes/contract_minimal.json',
                'examples/index.json',
                'recipes/dapp_minimal.json',
            ],
            'capability_matrix': developer_entry.get('entry_points', {}).get(
                'developer_capability_matrix_json', 'not found'
            ),
            'human_gates': [],
            'sandbox_note': 'default to local fail-closed; check developer_sandbox_strategy.json',
        }

    if phase == 'quality_gate':
        cmd_registry = await fetch_json(COMMAND_REGISTRY)
        safe_commands = [
            cmd for cmd in cmd_registry.get('commands', [])
            if cmd.get('safe_for_agent', False)
        ]
        return {
            'ready': True,
            'requires_human': False,
            'commands': safe_commands,
            'human_gates': [],
            'note': 'all safe_for_agent commands are agent-executable',
        }

    if phase in ('deploy_and_verify', 'launch'):
        return {
            'ready': True,
            'requires_human': True,
            'consumes': [
                'release_pack/index.json',
                'execution_pack/approval_gates.json',
                'e2e_fixtures/index.json',
            ],
            'human_gates': [
                '真实部署权限与签名账户',
                '生产环境变量与发布权限',
                '治理、多签、金库、审批等高风险动作的授权与窗口',
            ],
            'conditions': [
                '真实环境变量 must be provided',
                '签名账户 must be provided',
                '审批 must be completed',
                'raw evidence must be collected',
            ],
        }

    return {'ready': False, 'reason': 'unexpected phase'}

7.3 全生命周期引导器

async def resolve_full_lifecycle_order() -> list[dict[str, Any]]:
    developer_entry = await fetch_json(DEVELOPER_ENTRY)
    order = developer_entry.get('recommended_full_lifecycle_order', [])

    resolved = []
    base = 'https://msgchain.org/whitepaper/'
    for step_no, path in enumerate(order, 1):
        resolved.append({
            'step': step_no,
            'path': path,
            'url': base + path,
        })

    return resolved


async def execute_lifecycle_step(step_path: str) -> dict[str, Any]:
    base = 'https://msgchain.org/whitepaper/'
    url = base + step_path
    data = await fetch_json(url)

    return {
        'path': step_path,
        'url': url,
        'schema_version': data.get('schema_version'),
        'description': data.get('description', data.get('project', '')),
        'entry_points': list(data.get('entry_points', {}).keys())[:5],
    }

7.4 交付工作流执行器

async def load_delivery_workflows() -> list[dict[str, Any]]:
    workflows_data = await fetch_json(DELIVERY_WORKFLOWS)
    return workflows_data.get('workflows', [])


async def get_workflow(workflow_id: str) -> dict[str, Any]:
    workflows = await load_delivery_workflows()
    for wf in workflows:
        if wf.get('workflow_id') == workflow_id:
            return wf
    return {}


async def run_scope_phase(workflow_id: str) -> dict[str, Any]:
    workflow = await get_workflow(workflow_id)
    if not workflow:
        return {'status': 'error', 'message': f'workflow {workflow_id} not found'}

    phases = workflow.get('phases', [])
    scope_phase = next((p for p in phases if p.get('id') == 'scope'), None)

    if not scope_phase:
        return {'status': 'error', 'message': 'no scope phase found'}

    return {
        'status': 'blocked',
        'phase': 'scope',
        'approval_gate': scope_phase.get('approval_gate'),
        'consumes': scope_phase.get('consumes', []),
        'produces': scope_phase.get('produces', []),
        'message': 'human must confirm product goals and business rules',
    }

7.5 命令注册表执行器

async def get_available_commands(stage: str | None = None) -> list[dict[str, Any]]:
    cmd_data = await fetch_json(COMMAND_REGISTRY)
    commands = cmd_data.get('commands', [])

    if stage:
        commands = [c for c in commands if c.get('stage') == stage]

    return [
        {
            'id': cmd['id'],
            'command': cmd['command'],
            'stage': cmd['stage'],
            'safe_for_agent': cmd['safe_for_agent'],
            'requires_human_approval': cmd['requires_human_approval'],
            'outputs': cmd['outputs'],
        }
        for cmd in commands
    ]


async def execute_command_safely(cmd_id: str) -> dict[str, Any]:
    commands = await get_available_commands()
    cmd_map = {c['id']: c for c in commands}

    if cmd_id not in cmd_map:
        return {
            'status': 'error',
            'message': f'command "{cmd_id}" not found in command_registry.json',
        }

    cmd = cmd_map[cmd_id]

    if cmd['requires_human_approval']:
        return {
            'status': 'blocked',
            'command_id': cmd_id,
            'command': cmd['command'],
            'reason': 'this command requires human approval',
            'next_step': 'wait for production_release gate approval',
        }

    if not cmd['safe_for_agent']:
        return {
            'status': 'blocked',
            'command_id': cmd_id,
            'reason': 'command is not safe for agent execution',
        }

    return {
        'status': 'ready',
        'command_id': cmd_id,
        'command': cmd['command'],
        'stage': cmd['stage'],
        'expected_outputs': cmd['outputs'],
        'message': 'agent may execute this command autonomously',
    }

7.6 证据收集器

async def collect_evidence() -> dict[str, Any]:
    evidence = {
        'tx_hash': None,
        'receipt': None,
        'post_state_query': None,
        'logs': [],
        'artifact_manifest': None,
    }

    cmd_outputs = await execute_command_safely('package_deploy')
    if cmd_outputs.get('status') == 'ready':
        evidence['artifact_manifest'] = {
            'type': 'deploy_package',
            'command_id': 'package_deploy',
            'outputs': cmd_outputs.get('expected_outputs', []),
        }

    return evidence


async def verify_evidence_requirements() -> dict[str, Any]:
    try:
        evidence_req = await fetch_json(
            'https://msgchain.org/whitepaper/execution_pack/evidence_requirements.json'
        )
        return evidence_req
    except Exception:
        return {
            'note': 'evidence_requirements.json not yet available',
            'fallback': 'use e2e_fixtures templates',
        }

7.6 Quick Start 执行器

async def execute_quickstart() -> dict[str, Any]:
    quickstart = await fetch_json(
        'https://msgchain.org/whitepaper/quickstart/contract_and_dapp_minimal.json'
    )
    steps = quickstart.get('steps', [])

    results = []
    for step_def in steps:
        step_no = step_def.get('step')
        action = step_def.get('action')
        consumes = step_def.get('consumes', [])

        step_result = {
            'step': step_no,
            'action': action,
            'consumes': consumes,
            'purpose': step_def.get('purpose'),
            'read_files': [],
        }

        for file_path in consumes:
            try:
                url = f'https://msgchain.org/whitepaper/{file_path}'
                data = await fetch_json(url)
                step_result['read_files'].append({
                    'path': file_path,
                    'status': 'found',
                    'keys': list(data.keys()),
                })
            except Exception:
                step_result['read_files'].append({
                    'path': file_path,
                    'status': 'not_found',
                })

        results.append(step_result)

    return {
        'quickstart_id': quickstart.get('quickstart_id'),
        'title': quickstart.get('title'),
        'steps_completed': len(results),
        'steps': results,
    }

7.7 沙箱策略检查器

async def check_sandbox_availability() -> dict[str, Any]:
    try:
        sandbox = await fetch_json(
            'https://msgchain.org/whitepaper/chain_config/developer_sandbox_strategy.json'
        )

        public_available = sandbox.get('public_available', False)
        fail_closed = sandbox.get('fail_closed', True)

        if fail_closed or not public_available:
            return {
                'status': 'local_only',
                'mode': 'fail_closed',
                'default_path': 'local fail-closed',
                'message': 'public sandbox is disabled; use local-only path',
                'see': 'quickstart/contract_and_dapp_minimal.json for local steps',
            }

        return {
            'status': 'public_available',
            'mode': 'public_testnet',
            'message': 'public sandbox is available',
        }
    except Exception:
        return {
            'status': 'unknown',
            'mode': 'fail_closed_default',
            'message': (
                'sandbox strategy not readable; '
                'default to fail-closed local path'
            ),
        }

7.8 人类门禁检查器

async def check_human_gates(phase_id: str) -> dict[str, Any]:
    entry = await fetch_json(PRODUCT_DELIVERY_ENTRY)
    phases = entry.get('phases', [])
    phase_map = {p['id']: p for p in phases}

    if phase_id not in phase_map:
        return {'gate_status': 'unknown', 'phase': phase_id}

    phase = phase_map[phase_id]
    requires_human = phase.get('requires_human_input', True)

    if not requires_human:
        return {
            'gate_status': 'open',
            'phase': phase_id,
            'requires_human': False,
            'message': 'AI agent may proceed autonomously',
        }

    developer_entry = await fetch_json(DEVELOPER_ENTRY)
    human_inputs = developer_entry.get('human_inputs_required', [])

    return {
        'gate_status': 'blocked',
        'phase': phase_id,
        'requires_human': True,
        'human_inputs_required': human_inputs,
        'message': 'waiting for human input before proceeding',
        'gates': [
            {
                'id': 'scope_lock',
                'applies_to': ['scope'],
                'description': 'human must lock scope and acceptance criteria',
            },
            {
                'id': 'secret_injection',
                'applies_to': ['deploy_and_verify'],
                'description': 'human must provide secrets and signing accounts',
            },
            {
                'id': 'production_release',
                'applies_to': ['launch'],
                'description': 'human must approve production release',
            },
        ],
    }

7.9 完整交付流程编排器

async def orchestrate_product_delivery(
    delivery_type: str = 'full_lifecycle'
) -> dict[str, Any]:
    entry = await fetch_json(PRODUCT_DELIVERY_ENTRY)

    phases = entry.get('phases', [])
    phase_results = []

    for phase in phases:
        phase_id = phase['id']
        requires_human = phase.get('requires_human_input', True)

        readiness = await validate_delivery_readiness(phase_id)
        gates = await check_human_gates(phase_id)

        phase_results.append({
            'phase': phase_id,
            'goal': phase['goal'],
            'requires_human': requires_human,
            'ready': readiness.get('ready', False),
            'gate_status': gates.get('gate_status', 'unknown'),
            'gates_required': gates.get('gates', []),
        })

    capability_matrix = await fetch_json(
        'https://msgchain.org/whitepaper/developer_capability_matrix.json'
    )

    return {
        'product_delivery': {
            'schema_version': entry.get('schema_version'),
            'project': entry.get('project'),
            'description': entry.get('description'),
        },
        'phases': phase_results,
        'hard_boundaries': entry.get('hard_boundaries', []),
        'human_inputs_required': (
            await fetch_json(DEVELOPER_ENTRY)
        ).get('human_inputs_required', []),
        'current_boundaries': (
            await fetch_json(DEVELOPER_ENTRY)
        ).get('current_boundaries', []),
        'surfaces': [
            {
                'surface_id': s['surface_id'],
                'machine_readiness': s['machine_readiness'],
                'write_path_ready': s['write_path_ready'],
                'production_supported': s['production_supported'],
            }
            for s in capability_matrix.get('items', [])
        ],
        'summary': {
            'total_phases': len(phases),
            'human_gated_phases': sum(
                1 for p in phases if p.get('requires_human_input', False)
            ),
            'agent_autonomous_phases': sum(
                1 for p in phases if not p.get('requires_human_input', True)
            ),
            'delivery_readiness': 'guarded' if any(
                p.get('requires_human_input', False) for p in phases
            ) else 'autonomous',
        },
    }

7.10 CLI 入口示例

async def main():
    import sys

    action = sys.argv[1] if len(sys.argv) > 1 else 'discover'

    if action == 'discover':
        result = await discover_product_delivery()
        print(json.dumps(result, indent=2, ensure_ascii=False))

    elif action == 'phases':
        phases = await get_delivery_phases()
        print(json.dumps(phases, indent=2, ensure_ascii=False))

    elif action == 'ready':
        phase = sys.argv[2] if len(sys.argv) > 2 else 'scope'
        result = await validate_delivery_readiness(phase)
        print(json.dumps(result, indent=2, ensure_ascii=False))

    elif action == 'workflows':
        workflows = await load_delivery_workflows()
        print(json.dumps(workflows, indent=2, ensure_ascii=False))

    elif action == 'commands':
        stage = sys.argv[2] if len(sys.argv) > 2 else None
        cmds = await get_available_commands(stage)
        print(json.dumps(cmds, indent=2, ensure_ascii=False))

    elif action == 'gates':
        phase = sys.argv[2] if len(sys.argv) > 2 else 'scope'
        result = await check_human_gates(phase)
        print(json.dumps(result, indent=2, ensure_ascii=False))

    elif action == 'quickstart':
        result = await execute_quickstart()
        print(json.dumps(result, indent=2, ensure_ascii=False))

    elif action == 'lifecycle':
        order = await resolve_full_lifecycle_order()
        print(json.dumps(order, indent=2, ensure_ascii=False))

    elif action == 'orchestrate':
        result = await orchestrate_product_delivery()
        print(json.dumps(result, indent=2, ensure_ascii=False))

    else:
        print(f'Usage: {sys.argv[0]} [discover|phases|ready|workflows|commands|gates|quickstart|lifecycle|orchestrate]')


if __name__ == '__main__':
    import asyncio
    asyncio.run(main())

7.11 TypeScript 版本入口

const PRODUCT_DELIVERY_ENTRY = 'https://msgchain.org/whitepaper/product_delivery_entry.json';
const DEVELOPER_ENTRY = 'https://msgchain.org/whitepaper/developer_entry.json';

interface DeliveryPhase {
  id: string;
  goal: string;
  requires_human_input: boolean;
}

interface ProductDeliveryEntry {
  schema_version: string;
  project: string;
  description: string;
  entry_points: Record<string, string>;
  phases: DeliveryPhase[];
  hard_boundaries: string[];
}

async function discoverProductDelivery(): Promise<ProductDeliveryEntry> {
  const response = await fetch(PRODUCT_DELIVERY_ENTRY);
  return response.json();
}

async function checkPhaseGate(phaseId: string): Promise<{
  status: string;
  requiresHuman: boolean;
  gates: string[];
}> {
  const entry = await discoverProductDelivery();
  const phase = entry.phases.find(p => p.id === phaseId);

  if (!phase) {
    return { status: 'unknown', requiresHuman: true, gates: [] };
  }

  const developerResponse = await fetch(DEVELOPER_ENTRY);
  const developerEntry = await developerResponse.json();

  return {
    status: phase.requires_human_input ? 'blocked' : 'open',
    requiresHuman: phase.requires_human_input,
    gates: phase.requires_human_input
      ? developerEntry.human_inputs_required || []
      : [],
  };
}

7.12 Rust 版本入口

use serde::Deserialize;
use reqwest;

#[derive(Debug, Deserialize)]
struct ProductDeliveryEntry {
    schema_version: String,
    project: String,
    description: String,
    phases: Vec<Phase>,
    hard_boundaries: Vec<String>,
}

#[derive(Debug, Deserialize)]
struct Phase {
    id: String,
    goal: String,
    requires_human_input: bool,
}

#[derive(Debug, Deserialize)]
struct DeveloperEntry {
    human_inputs_required: Vec<String>,
    current_boundaries: Vec<String>,
}

async fn discover_product_delivery() -> Result<ProductDeliveryEntry, reqwest::Error> {
    let resp = reqwest::get(
        "https://msgchain.org/whitepaper/product_delivery_entry.json"
    ).await?;
    let entry: ProductDeliveryEntry = resp.json().await?;
    Ok(entry)
}

async fn check_human_gates(
    phase_id: &str
) -> Result<Vec<String>, reqwest::Error> {
    let entry = discover_product_delivery().await?;

    let phase = entry.phases.iter()
        .find(|p| p.id == phase_id);

    if let Some(p) = phase {
        if p.requires_human_input {
            let dev_resp = reqwest::get(
                "https://msgchain.org/whitepaper/developer_entry.json"
            ).await?;
            let dev_entry: DeveloperEntry = dev_resp.json().await?;
            return Ok(dev_entry.human_inputs_required);
        }
    }

    Ok(vec![])
}

7.13 边界断言工具

def assert_hard_boundaries_respected(
    phase_id: str,
    has_env: bool = False,
    has_signer: bool = False,
    has_approval: bool = False,
    has_evidence: bool = False,
) -> None:
    """
    Assert that the hard boundary conditions from product_delivery_entry.json
    are respected before proceeding with deploy_and_verify or launch phases.
    """
    if phase_id not in ('deploy_and_verify', 'launch'):
        return

    violations = []

    if not has_env:
        violations.append(
            '硬边界违例: 没有真实环境变量时不能进入 deploy/launch 阶段。'
        )
    if not has_signer:
        violations.append(
            '硬边界违例: 没有签名账户时不能进入 deploy/launch 阶段。'
        )
    if not has_approval:
        violations.append(
            '硬边界违例: 没有审批时不能进入 deploy/launch 阶段。'
        )
    if not has_evidence:
        violations.append(
            '硬边界违例: 没有 raw evidence 时不能进入 deploy/launch 阶段。'
        )

    if violations:
        raise RuntimeError(
            'Product delivery hard boundary violate[未公开路径]'
            + '\n'.join(f'  - {v}' for v in violations)
        )

    print(
        f'Phase "{phase_id}": all hard boundary conditions satisfied. '
        'Proceeding with guarded delivery.'
    )


def validate_phase_transition(
    current_phase: str,
    next_phase: str,
    approvals: dict[str, bool],
) -> bool:
    """
    Validate that all required approvals are obtained before
    transitioning between phases.

    Required approvals by phase:
      - scope_lock for scope transitions
      - secret_injection for deploy_and_verify transitions
      - production_release for launch transitions
    """
    gate_map = {
        'scope': 'scope_lock',
        'deploy_and_verify': 'secret_injection',
        'launch': 'production_release',
    }

    required_gate = gate_map.get(next_phase)

    if required_gate and not approvals.get(required_gate, False):
        print(
            f'Cannot transition from "{current_phase}" to "{next_phase}": '
            f'approval gate "{required_gate}" not yet satisfied.'
        )
        return False

    return True

7.14 合约引导路线解析器

async def resolve_contract_bootstrap_order() -> list[dict[str, Any]]:
    developer_entry = await fetch_json(DEVELOPER_ENTRY)
    order = developer_entry.get('recommended_contract_bootstrap_order', [])

    resolved = []
    base = 'https://msgchain.org/whitepaper/'
    for step_no, path in enumerate(order, 1):
        resolved.append({
            'step': step_no,
            'path': path,
            'url': base + path,
        })

    return resolved


async def validate_contract_bootstrap_path() -> dict[str, Any]:
    order = await resolve_contract_bootstrap_order()

    statuses = []
    for step in order:
        try:
            async with httpx.AsyncClient() as client:
                resp = await client.head(step['url'])
                statuses.append({
                    'step': step['step'],
                    'path': step['path'],
                    'accessible': resp.status_code == 200,
                    'status_code': resp.status_code,
                })
        except Exception as e:
            statuses.append({
                'step': step['step'],
                'path': step['path'],
                'accessible': False,
                'error': str(e),
            })

    accessible = sum(1 for s in statuses if s['accessible'])
    return {
        'total_steps': len(order),
        'accessible': accessible,
        'blocked': len(order) - accessible,
        'details': statuses,
    }

7.15 执行包索引解析

async def load_execution_pack_index() -> dict[str, Any]:
    index = await fetch_json(EXECUTION_PACK_INDEX)

    files = index.get('files', [])
    file_details = []
    for f in files:
        file_details.append({
            'id': f.get('id'),
            'path': f.get('path'),
            'public_url': f.get('public_url'),
        })

    return {
        'description': index.get('description'),
        'contract_package_count': index.get('contract_package_count'),
        'files': file_details,
        'boundaries': index.get('boundary', []),
    }

7.16 完整启动脚本

async def bootstrap_product_delivery() -> dict[str, Any]:
    discovery = await discover_product_delivery()

    print(f'MSG Chain Product Delivery Entry: {discovery["schema_version"]}')
    print(f'Project: {discovery["project"]}')
    print(f'Description: {discovery["description"]}')
    print(f'Phases: {len(discovery["phases"])}')
    print(f'Hard Boundaries: {len(discovery["hard_boundaries"])}')
    print()

    phases_data = await get_delivery_phases()
    for phase in phases_data:
        icon = '🔒' if phase['requires_human_input'] else '🤖'
        print(f'  {icon} {phase["id"]}: {phase["goal"]}')
    print()

    boundaries = discovery['hard_boundaries']
    for i, boundary in enumerate(boundaries, 1):
        print(f'  Boundary {i}: {boundary}')
    print()

    developer_data = await fetch_json(DEVELOPER_ENTRY)
    human_inputs = developer_data.get('human_inputs_required', [])
    print('Human Inputs Required:')
    for inp in human_inputs:
        print(f'  - {inp}')
    print()

    boundaries_dev = developer_data.get('current_boundaries', [])
    print('Current Developer Boundaries:')
    for b in boundaries_dev:
        print(f'  - {b}')

    return {
        'product_delivery_schema': discovery['schema_version'],
        'phase_count': len(discovery['phases']),
        'human_gated_phases': [
            p['id'] for p in phases_data if p['requires_human_input']
        ],
        'agent_phases': [
            p['id'] for p in phases_data if not p['requires_human_input']
        ],
        'boundaries': boundaries,
        'human_inputs': human_inputs,
    }


if __name__ == '__main__':
    import asyncio
    result = asyncio.run(bootstrap_product_delivery())
    print(json.dumps(result, indent=2, ensure_ascii=False))

附录

A. 文件引用总表

以下文件均在 MSG Chain 白皮书中实际存在,可通过公开 URL 访问:

文件路径 描述 公开 URL
product_delivery_entry.json 产品交付入口(本文核心) https://msgchain.org/whitepaper/product_delivery_entry.json
developer_entry.json 开发者入口 https://msgchain.org/whitepaper/developer_entry.json
agent_entry.json Agent 入口 https://msgchain.org/whitepaper/agent_entry.json
quickstart/index.json 快速入门索引 https://msgchain.org/whitepaper/quickstart/index.json
quickstart/contract_and_dapp_minimal.json 7 步 Contract+dApp Quick Start https://msgchain.org/whitepaper/quickstart/contract_and_dapp_minimal.json
chain_config/developer_sandbox_strategy.json 沙箱策略 https://msgchain.org/whitepaper/chain_config/developer_sandbox_strategy.json
chain_config/index.json 链配置索引 https://msgchain.org/whitepaper/chain_config/index.json
contract_reference/index.json 合约参考索引 https://msgchain.org/whitepaper/contract_reference/index.json
contract_reference/core_contracts.json 核心合约清单 https://msgchain.org/whitepaper/contract_reference/core_contracts.json
api_specs/formal_contracts.json 正式 API/Schema 契约 https://msgchain.org/whitepaper/api_specs/formal_contracts.json
developer_capability_matrix.json 开发者能力矩阵 https://msgchain.org/whitepaper/developer_capability_matrix.json
execution_pack/index.json 执行包索引 https://msgchain.org/whitepaper/execution_pack/index.json
execution_pack/delivery_workflows.json 交付工作流定义 https://msgchain.org/whitepaper/execution_pack/delivery_workflows.json
execution_pack/command_registry.json 命令注册表 https://msgchain.org/whitepaper/execution_pack/command_registry.json
release_pack/index.json 发布包索引 https://msgchain.org/whitepaper/release_pack/index.json
e2e_fixtures/index.json E2E 夹具索引 https://msgchain.org/whitepaper/e2e_fixtures/index.json

B. 命令注册表完整列表

命令 ID 命令 阶段 安全 需要审批 输出
deps make deps prepare 是 否 Go module cache, dependency verification
lint make lint quality_gate 是 否 gofmt check, go vet, golangci-lint
test make test quality_gate 是 否 pkg test results
test_quantum make test-quantum quality_gate 是 否 pkg/quantum test results
build_linux make build-linux build 是 否 bin/genesis_node_linux, bin/quantum_node_linux
ci_contracts make ci-contracts contract_validation 是 否 all contract wasm build, all contract cargo test
package_deploy make package artifact_packaging 是 否 deploy-<version>, deploy-<version>.tar.gz
whitepaper_generate whitepaper_build_pipeline docs_generate 是 否 docs/architecture_diagrams/*.json, *.html
whitepaper_audit whitepaper_quality_gate docs_quality_gate 是 否 module_audit_report.json
whitepaper_sync python3 scripts/sync_whitepaper.py site_sync 是 否 ../msgchainorg/whitepaper/*
cloudflare_pages_deploy npx wrangler pages deploy . --project-name msgchainorg ... release 否 是 pages deployment, pages.dev preview, custom domain rollout

C. 版本历史

版本 日期 变更说明
v1 2026-07 初始版本,基于 product_delivery_entry.json schema_version v1

本文档基于 MSG Chain 白皮书机器学习层的实际 JSON 文件生成。所有引用均指向真实存在的文件路径。AI Agent 应遵循本文档定义的阶段模型、门禁要求和边界约束进行产品交付。