dApp Docs/AI Agent 发布包与版本交付指南
Development reference. Not independently verified for production.

MSG Chain 发布包(release_pack)与版本交付指南

目录

  1. 概述
  2. 发布包索引
  3. 发布流程
  4. 与执行包集成
  5. AI Agent 发布操作
  6. 边界声明
  7. 示例

1. 概述

1.1 什么是 release_pack

release_pack 是 MSG Chain 白皮书系统的发布包目录,存放与版本管理、发布检查、签名校验、
manifest 证据采集相关的机器可读文件。它不包含代码编译产物或部署脚本,而是记录"发布
前必须满足的条件"和"已完成的发布证据"。

release_pack 的核心职责:

1.2 release_pack 在 bootstrap 顺序中的位置

在 developer_entry.json:recommended_dapp_bootstrap_order(16 步)第 13 步引用 release_pack/index.json;recommended_full_lifecycle_order(20 步)第 17 步引用。在 agent_entry.json:recommended_crawl_order 将其列为关键爬取资源。这意味着 release_pack 处于"发布准备"阶段——代码已完成、测试已通过、执行命令已验证,现在进入发布计划与审批环节。

1.3 release_pack 文件清单

release_pack/index.json 登记了以下文件(截至 schema_v1):

release_pack/index.json 登记的文件(截至 schema_v1):

文件 用途
.env.example 发布环境变量模板
cloudflare_pages_release_checklist.json 站点发布检查清单
contract_release_checklist.json 合约发布检查清单
smoke_checks.json 冒烟测试检查点
developer_capability_manifest.json 能力 fail-closed manifest
developer_api_schema_pack_manifest.json API Schema pack manifest
developer_contract_schema_abi_pack_manifest.json 合约 Schema/ABI manifest
developer_public_sandbox_strategy_manifest.json 公开沙箱策略 manifest
developer_dapp_starter_e2e_manifest.json dApp starter E2E manifest
developer_sdk_signed_release_candidate_manifest.json SDK 签名发布候选 manifest
developer_business_examples_manifest.json 业务示例 library manifest

1.4 与 execution_pack 的关系

execution_pack 提供"如何执行"(命令注册表、审批门禁、交付工作流),release_pack 提供"发布什么"(发布资产索引、检查清单、capability 声明)。两者交叉点:

1.5 与 product_delivery_entry 的关系

product_delivery_entry.json 定义了 lifecycle order(20 步),release_pack 位于第 17 步,在 execution_pack/delivery_workflows.json 和 command_registry.json 之后、e2e_fixtures/index.json 之前。这个位置表示"先执行命令、再准备发布、最后采集 E2E 证据"。

1.6 当前状态

所有 release_pack 中的 manifest 均声明:

这意味着 release_pack 当前是计划态和 stub 态,不构成生产发布承诺。


2. 发布包索引

2.1 索引结构

release_pack/index.json 是发布包目录的入口文件,schema_version 当前为 v1。
它由 msg_whitepaper_pipeline_v1 自动生成。

import requests

RELEASE_INDEX = 'https://msgchain.org/whitepaper/release_pack/index.json'

async def discover_release_pack():
    index = await requests.get(RELEASE_INDEX).json()
    return {
        'version': index.get('schema_version'),
        'files': index.get('files', []),
        'generated_by': index.get('generated_by'),
        'metadata_profile': index.get('metadata_profile'),
    }

2.2 索引字段说明

2.3 索引遍历逻辑

AI agent 发现 release_pack 后应执行以下操作:

async def explore_release_pack():
    index = await fetch_json(RELEASE_INDEX)

    checklist_files = []
    manifest_files = []

    for f in index.get('files', []):
        file_id = f.get('id', '')
        file_url = f.get('public_url', '')

        if 'checklist' in file_id:
            checklist_files.append((file_id, file_url))
        elif 'manifest' in file_id:
            manifest_files.append((file_id, file_url))

    # 先加载检查清单,再加载 manifests
    checklists = {cid: await fetch_json(url) for cid, url in checklist_files}
    manifests = {mid: await fetch_json(url) for mid, url in manifest_files}

    return {
        'index': index,
        'checklists': checklists,
        'manifests': manifests,
    }

2.4 检查清单文件

cloudflare_pages_release_checklist.json:站点发布步骤包括内容同步确认、wrangler 配置、部署后回抓、版本回滚信息保留。boundary:站点发布需要真实账号和人类审批。

{
  "schema_version": "v1",
  "steps": [
    "确认最新白皮书与主站内容已同步到 msgchainorg 仓库",
    "确认 wrangler 项目名、分支与 token/account id 已配置",
    "部署后回抓 pages.dev 与正式域名关键入口",
    "保留上一版本回滚信息与 smoke test 结果"
  ],
  "boundary": ["站点发布动作仍需真实账号、发布凭据与人类审批。"],
  "metadata_profile": "public_stable"
}

contract_release_checklist.json:合约发布步骤包括 cargo test 通过、部署计划与 canonical key 寻址计划、记录 tx hash/receipt/post-state query/rollback plan、确认生产密钥和 Gas 预算。boundary:没有真实部署权限和签名账户时,AI 不得声称合约未独立核验上线状态。

{
  "schema_version": "v1",
  "steps": [
    "cargo test 或等效合约测试通过",
    "生成部署计划与 canonical key 寻址计划",
    "记录 tx hash /receipt /post-state query /rollback plan",
    "确认生产密钥、Gas 预算、治理或多签门禁"
  ],
  "boundary": ["没有真实部署权限与签名账户时,AI 不得声称合约未独立核验上线状态。"],
  "metadata_profile": "public_stable"
}

smoke_checks.json:4 个检查点(home/agent_entry/developer_entry/knowledge_network),用于发布后的快速验证。boundary:smoke pass 不等于业务功能全量验收。


### 2.5 环境变量模板

.env.example 列出了发布所需的最小环境变量集合:

MSG_RPC_URL=https://rpc.msgchain.org
MSG_REST_URL=https://api.msgchain.org
MSG_CHAIN_ID=msg-chain-1
MSG_CONTRACT_ADDRESS=
CLOUDFLARE_ACCOUNT_ID=
CLOUDFLARE_API_TOKEN=
CLOUDFLARE_PROJECT_NAME=


AI agent 的工作:检测这些变量是否已设置,如果缺失则必须停留在计划态。

### 2.6 Manifest 文件的通用结构

每个 manifest 文件遵循统一的 fail-closed 模式:

```json
{
  "schema_version": "v1",
  "mainnet_verdict": "No-Go",
  "mainnet_ready_claim": false,
  "scope": "...",
  "whitepaper_modules": [...],
  "source_files": [...],
  "production_requirements": [...],
  "known_blockers": [...],
  "closing_boundary": "...",
  "source_schema_version": "...",
  "source_path": "...",
  "metadata_profile": "public_stable"
}

所有 manifest 的共同特征:

2.7 索引的 AI agent 发现模式

当 AI agent 按 bootstrap 顺序读到 release_pack/index.json 时:

async def is_release_ready():
    """检查 release_pack 中的生产就绪状态"""
    index = await fetch_json(RELEASE_INDEX)
    all_blockers = []

    for f in index.get('files', []):
        fid = f['id']
        if 'manifest' not in fid:
            continue
        manifest = await fetch_json(f['public_url'])
        blockers = manifest.get('known_blockers', [])
        all_blockers.extend(blockers)

    if all_blockers:
        return {
            'ready': False,
            'blocker_count': len(all_blockers),
            'blockers': all_blockers,
            'verdict': 'No-Go',
        }

    return {'ready': True, 'verdict': 'Go'}

当前所有 manifest 均有已知阻塞项,因此 is_release_ready() 始终返回 {'ready': False}。


3. 发布流程

3.1 发布阶段总览

release_pack 参与的完整发布流程包含以下阶段:

[代码阶段] -> [质量门禁] -> [发布计划] -> [审批门禁] -> [实际发布] -> [证据采集]
                                    |
                             release_pack/index.json 在此处消费

3.2 发布计划阶段(deploy_plan)

在 delivery_workflows.json 的 contract_delivery_guarded_v1 中,deploy_plan 阶段:

AI agent 在此阶段应:

  1. 加载 release_pack/index.json,获取所有检查清单
  2. 根据发布类型选择对应 checklist(合约发布用 contract_release_checklist.json,
    站点发布用 cloudflare_pages_release_checklist.json)
  3. 逐项检查 checklist 中的条件是否满足
  4. 生成部署计划文档
  5. 确认 secret_injection 门禁是否通过(未通过则停留在计划态)

3.3 版本管理

当前 release_pack 中的版本号:

组件 版本 渠道 生产就绪
SDK 0.1.0-alpha alpha false
合约模板 counter_v1 0.1.0 starter false
genesis_registry_v1 1.0.0 official false
agent_registry_v1 0.1.0 official false
micropayment_session_v1 0.1.0 business false
agent_payment_v1 0.1.0 business false

版本号策略:

3.4 发布类型分叉

根据发布目标的不同,release_pack 的使用路径分叉:

3.4.1 合约发布路径

delivery_workflows.json -> contract_delivery_guarded_v1
  scope -> design_and_codegen -> build_and_test -> deploy_plan -> real_release
                                                     |
                                          release_pack/index.json 用于:
                                          1. contract_release_checklist.json 检查
                                          2. developer_contract_schema_abi_pack_manifest.json 确认 schema 完备性

3.4.2 dApp 站点发布路径

delivery_workflows.json -> dapp_delivery_guarded_v1
  scope -> scaffold -> quality_gate -> site_release
                                         |
                              release_pack/index.json 用于:
                              1. cloudflare_pages_release_checklist.json 检查
                              2. smoke_checks.json 冒烟检查定义
                              3. developer_dapp_starter_e2e_manifest.json 确认 E2E 证据

3.4.3 产品完整启动路径

delivery_workflows.json -> product_launch_guarded_v1
  compose -> evidence_closeout -> launch
                                     |
                          release_pack/index.json 用于:
                          1. 所有 manifest 综合检查
                          2. developer_capability_manifest.json 全局就绪判断
                          3. approval_gates.json 最终审批

3.5 签名与验证

release_pack 的 manifest 记录了 Dilithium 签名验证要求。

在 developer_sdk_signed_release_candidate_manifest.json 中:

{
  "id": "dilithium_signature_verification_receipt",
  "status": "missing_production_evidence",
  "required_evidence": [
    "Dilithium signature verification receipt",
    "canonical signed payload hash",
    "release signer trust anchor"
  ],
  "failure_mode": "fail-closed until SDK release signature verification is accepted"
}

签名验证流程伪码:

async def verify_release_signature(manifest_url: str, public_key: str):
    manifest = await fetch_json(manifest_url)
    sig_requirements = [
        req for req in manifest.get('production_requirements', [])
        if 'signature' in req.get('id', '') or 'sign' in req.get('id', '')
    ]
    for req in sig_requirements:
        if req['status'] == 'missing_production_evidence':
            print(f"WARNING: {req['id']} - {req['failure_mode']}")

    # 真实验证需要:
    # 1. Dilithium 签名验证库
    # 2. release signer public key manifest
    # 3. canonical signed payload hash 比对
    # 当前不可用,返回 fail-closed
    return {
        'verified': False,
        'reason': 'missing_production_evidence',
        'required': sig_requirements,
    }

3.6 证据采集

发布流程的每个阶段都需要采集证据。证据类型包括:

EVIDENCE_TYPES = {
    'raw_query': '链上查询原始结果',
    'receipt': '交易收据',
    'log': '执行日志',
    'artifact_manifest': '制品哈希清单',
    'tx_hash': '交易哈希',
    'post_state_query': '发布后状态查询',
    'rollback_plan': '回滚预案',
    'smoke_pass': '冒烟测试通过记录',
}

release_pack 中的 manifest 使用 source_files 记录源码证据:

async def collect_source_evidence(manifest):
    """采集 manifest 中声明的 source file 哈希"""
    evidence = []
    for sf in manifest.get('source_files', []):
        evidence.append({
            'path': sf['path'],
            'role': sf['role'],
            'sha256': sf['sha256'],
        })
    return evidence

3.7 发布就绪检查协议

AI agent 在执行发布计划前应运行以下协议:

RELEASE_READINESS_PROTOCOL = {
    'schema_version': 'v1',
    'checks': [
        {
            'id': 'checklist_complete',
            'description': '所有 checklist 步骤已完成',
            'source': 'contract_release_checklist.json 或 cloudflare_pages_release_checklist.json',
        },
        {
            'id': 'env_vars_set',
            'description': '必需环境变量已配置',
            'source': '.env.example',
        },
        {
            'id': 'no_known_blockers',
            'description': '所有 manifest 无已知阻塞项',
            'source': 'manifest[*].known_blockers',
        },
        {
            'id': 'approval_gates_passed',
            'description': 'secret_injection 和 production_release 门禁已通过',
            'source': 'delivery_workflows.json 对应阶段的 approval_gate',
        },
        {
            'id': 'evidence_collected',
            'description': '所需的发布证据已采集',
            'source': 'manifest[*].production_requirements',
        },
    ],
    'result': None,  # AI agent 填充 pass/fail/blocked
}

4. 与执行包集成

4.1 执行包概览

execution_pack 包含以下文件:

文件 用途
index.json 执行包索引
command_registry.json 命令注册表
approval_gates.json 审批门禁定义
delivery_workflows.json 交付工作流
ci_cd_templates.json CI/CD 模板
governance_templates.json 治理模板
multisig_approval_flow.json 多签审批流
evidence_requirements.json 证据要求
artifact_contracts.json 制品合约

4.2 命令注册表中的发布相关命令

command_registry.json 中与发布相关的命令:

{
  "id": "package_deploy",
  "command": "make package",
  "cwd": ".",
  "stage": "artifact_packaging",
  "safe_for_agent": true,
  "requires_human_approval": false,
  "outputs": ["deploy-<version>", "deploy-<version>.tar.gz"],
  "source": ["Makefile", "scripts/package_deploy.sh"]
}
{
  "id": "cloudflare_pages_deploy",
  "command": "npx wrangler pages deploy. --project-name msgchainorg ...",
  "cwd": "../msgchainorg",
  "stage": "release",
  "safe_for_agent": false,
  "requires_human_approval": true,
  "outputs": ["pages deployment", "pages.dev preview", "custom domain rollout"],
  "source": ["../msgchainorg/DEPLOY_CLOUDFLARE.md"]
}

注意:package_deploy 对 AI agent 安全,cloudflare_pages_deploy 需要人工审批。

4.3 approval_gates 定义

approval_gates.json 定义了四个审批门禁:

门禁 ID 阶段 人工输入要求 Agent 无输入时行为
scope_lock 编码前 产品目标、业务规则、验收标准 stop_and_request_scope
secret_injection 实际写入/部署前 签名账户、API token、环境变量、域名/CI 权限 remain_in_stub_or_plan_mode
production_release 启动前 最终审批、回滚确认、资金与治理风险确认 stop_before_release
governance_or_treasury 高风险写入 DAO 通过、timelock 结束、签名阈值达成 forbid_execution

4.4 delivery_workflows 中的 release_pack 消费点

4.4.1 contract_delivery_guarded_v1

phase: deploy_plan
  consumes: ["release_pack/index.json", "e2e_fixtures/index.json"]
  produces: ["部署计划", "query/receipt 校验计划", "rollback plan"]
  approval_gate: "secret_injection"

phase: real_release
  consumes: ["approval_gates.json"]
  produces: ["tx hash", "receipt", "post-state query", "raw evidence"]
  approval_gate: "production_release"

集成模式:deploy_plan -> 加载 release_pack/index.json 和 checklist -> 确认 secret_injection 门禁 -> 生成部署计划 -> real_release -> 加载 approval_gates.json -> 确认 production_release 门禁 -> 执行发布 -> 采集 evidence。

4.4.2 dapp_delivery_guarded_v1

phase: site_release
  consumes: ["release_pack/index.json", "execution_pack/approval_gates.json"]
  produces: ["站点发布计划", "smoke checks", "回滚预案"]
  approval_gate: "production_release"

集成模式:加载 cloudflare_pages_release_checklist.json 和 smoke_checks.json -> 检查 .env.example 环境变量 -> 确认 production_release 门禁 -> 运行 smoke check -> 生成发布结果。

4.4.3 product_launch_guarded_v1

phase: launch
  consumes: ["release_pack/index.json", "execution_pack/approval_gates.json"]
  produces: ["上线记录", "smoke pass", "回滚句柄"]
  approval_gate: "production_release"

5. AI Agent 发布操作

5.1 Agent 在发布中的角色

AI agent 在 MSG Chain 发布流程中的角色是"受约束的发布助手",而不是"自主发布者"。

Agent 可以:

Agent 不可:

5.2 安全边界

product_delivery_entry.json 定义了以下 hard_boundaries:

{
  "hard_boundaries": [
    "不能把执行层协议包解释成 100% 零人工生产上线承诺。",
    "没有真实环境变量、签名账户、审批和 raw evidence 时,AI agent 必须停在计划态或 stub 态。"
  ]
}

developer_entry.json 定义了 human_inputs_required:

{
  "human_inputs_required": [
    "产品目标与业务规则",
    "真实部署权限与签名账户",
    "生产环境变量、域名、CI/CD 或发布权限",
    "治理、多签、金库、审批等高风险动作的授权与窗口"
  ]
}

5.3 计划态 vs stub 态 vs 真实态

AI agent 的三态模型:

class AgentReleaseState:
    PLAN = 'plan'      # 已生成计划但未执行任何实际操作
    STUB = 'stub'      # 已执行模拟操作,产出框架结果
    REAL = 'real'      # 已执行真实操作(需要人工批准和签名)

    @staticmethod
    def determine(env_set: bool, gate_passed: bool, signed: bool):
        if not env_set or not gate_passed:
            return AgentReleaseState.PLAN
        if not signed:
            return AgentReleaseState.STUB
        return AgentReleaseState.REAL

在 release_pack 上下文的映射:

条件 允许的状态 示例
无环境变量 PLAN 生成 .env.example 填充文档
有环境变量,无审批 STUB 执行 make package 但不部署
有环境变量,有审批,无签名 STUB 准备 wrangler 命令但不执行
全部满足 REAL 执行发布并采集证据

5.4 证据采集

AI agent 在发布过程中负责采集以下证据:

async def collect_release_evidence(workflow_phase: str, artifacts: dict):
    """
    按工作流阶段采集证据。

    每个 evidence 条目包含:
    - type: 证据类型
    - source: 来源
    - content: 内容(或引用)
    - verified: 是否已验证
    """
    evidence = []

    if workflow_phase in ('deploy_plan', 'site_release'):
        evidence.append({
            'type': 'deployment_plan',
            'source': 'release_pack_guided_plan',
            'content': artifacts.get('plan'),
            'verified': False,
        })

    if workflow_phase == 'real_release':
        evidence.extend([
            {'type': 'tx_hash', 'source': 'chain', 'content': artifacts.get('tx_hash'), 'verified': True},
            {'type': 'receipt', 'source': 'chain', 'content': artifacts.get('receipt'), 'verified': True},
            {'type': 'post_state_query', 'source': 'rpc', 'content': artifacts.get('post_state'), 'verified': True},
        ])

    if workflow_phase in ('site_release', 'launch'):
        evidence.append({
            'type': 'smoke_pass',
            'source': 'smoke_checks.json',
            'content': artifacts.get('smoke_results'),
            'verified': False,
        })

    return evidence

5.5 人工审批交互

AI agent 在遇到以下情况时必须向人类请求输入:

HUMAN_INPUT_SCENARIOS = [
    {
        'trigger': 'scope_lock 门禁未通过',
        'question': '请提供产品目标、业务规则和验收标准。',
        'format': '自由文本',
    },
    {
        'trigger': 'secret_injection 门禁未通过',
        'question': '请提供以下信息:\n'
                     '- 真实签名账户地址\n'
                     '- API token(如 CLOUDFLARE_API_TOKEN)\n'
                     '- 环境变量(MSG_RPC_URL, MSG_REST_URL 等)\n'
                     '- 域名或 CI/CD 权限',
        'format': '环境变量键值对',
    },
    {
        'trigger': 'production_release 门禁未通过',
        'question': '请确认:\n'
                     '- 最终审批已通过\n'
                     '- 回滚预案已确认\n'
                     '- 资金与治理风险已评估',
        'format': '确认 / 拒绝',
    },
    {
        'trigger': 'signature_required',
        'question': '需要 Dilithium 签名验证。请提供签名账户或 release signer 公钥。',
        'format': '公钥 hex 或签名结果',
    },
]

5.6 Agent 行为约束规则

AGENT_RELEASE_RULES = {
    'must_always_check': [
        'release_pack/index.json 是否可访问',
        'approval_gates.json 的当前状态',
        '所有 manifest 的 mainnet_verdict',
        '命令注册表中需要人工审批的命令',
        '.env.example 中必需的环境变量',
    ],
    'must_never_assert': [
        '生产上线已完成(除非有人工签名和 raw evidence)',
        'mainnet 就绪(除非 mainnet_verdict 为 Go)',
        '无阻塞项(除非所有 known_blockers 为空)',
    ],
    'must_always_stop_before': [
        'cloudflare_pages_deploy 命令',
        '合约 store/instantiate/migrate 操作',
        '涉及私钥或多签的动作',
        '修改链上状态的生产写入',
    ],
}

5.7 Manifest 读取与解析

async def load_and_validate_manifest(manifest_url: str) -> dict:
    """加载 manifest 并提取 AI agent 需要的字段"""
    data = await fetch_json(manifest_url)

    # 验证 schema 版本
    assert data.get('schema_version') == 'v1', f"不支持的 schema 版本: {data.get('schema_version')}"

    # 提取生产就绪状态
    ready_state = {
        'mainnet_verdict': data.get('mainnet_verdict'),
        'mainnet_ready': data.get('mainnet_ready_claim', False),
        'scope': data.get('scope'),
    }

    # 提取阻塞项
    blockers = data.get('known_blockers', [])

    # 提取生产要求(含 fail_closed 模式)
    requirements = data.get('production_requirements', [])
    missing = [r for r in requirements if r['status'] == 'missing_production_evidence']

    # 提取边界声明
    boundary = data.get('closing_boundary', '')

    return {
        'ready_state': ready_state,
        'blockers': blockers,
        'missing_requirements': missing,
        'boundary': boundary,
        'production_ready': len(blockers) == 0 and len(missing) == 0,
    }

5.8 跨包依赖检查

AI agent 需要理解 release_pack 与其他包的依赖关系:

PACK_DEPENDENCIES = {
    'release_pack': {
        'depends_on': [
            'execution_pack/command_registry.json',
            'execution_pack/approval_gates.json',
            'execution_pack/delivery_workflows.json',
        ],
        'consumed_by': [
            'execution_pack/delivery_workflows.json',
        ],
        'integration_points': [
            ('contract_delivery_guarded_v1', 'deploy_plan', 'consumes'),
            ('contract_delivery_guarded_v1', 'real_release', 'consumes'),
            ('dapp_delivery_guarded_v1', 'site_release', 'consumes'),
            ('product_launch_guarded_v1', 'launch', 'consumes'),
        ],
    },
}

5.9 多 Manifest 协调策略

当 AI agent 需要评估整体发布就绪状态时,必须联合分析所有 manifest:

async def assess_overall_release_readiness():
    index = await fetch_json(RELEASE_INDEX)
    verdicts = {}
    all_blockers = []

    for f in index['files']:
        if 'manifest' not in f['id']:
            continue
        m = await fetch_json(f['public_url'])
        key = f['id'].replace('developer_', '').replace('_manifest', '')
        verdicts[key] = {
            'verdict': m['mainnet_verdict'],
            'ready': m['mainnet_ready_claim'],
            'blocker_count': len(m['known_blockers']),
            'scope': m.get('scope', '')[:80],
        }
        all_blockers.extend(m['known_blockers'])

    all_no_go = all(v['verdict'] == 'No-Go' for v in verdicts.values())
    any_ready = any(v['ready'] for v in verdicts.values())

    return {
        'overall_verdict': 'No-Go' if all_no_go else 'Mixed',
        'all_no_go': all_no_go,
        'any_ready_claim': any_ready,
        'total_blockers': len(all_blockers),
        'manifest_count': len(verdicts),
        'manifests': verdicts,
        'recommendation': (
            '发布不可执行' if all_no_go
            else '需逐个确认各 manifest 的生产要求'
        ),
    }

6. 边界声明

6.1 当前发布限制

release_pack 及其所有 manifest 当前均处于 fail-closed 状态。主要限制包括:

  1. 所有 manifest 均为 No-Go

    • developer_capability_manifest.json: mainnet_verdict = "No-Go"
    • developer_sdk_signed_release_candidate_manifest.json: mainnet_verdict = "No-Go"
    • developer_contract_schema_abi_pack_manifest.json: mainnet_verdict = "No-Go"
    • developer_api_schema_pack_manifest.json: mainnet_verdict = "No-Go"
    • developer_dapp_starter_e2e_manifest.json: mainnet_verdict = "No-Go"
    • developer_public_sandbox_strategy_manifest.json: mainnet_verdict = "No-Go"
    • developer_business_examples_manifest.json: mainnet_verdict = "No-Go"
  2. 所有生产要求均为 missing_production_evidence

    • 签名 manifest 缺失
    • 公开端点证据缺失
    • 外部审计报告缺失
    • 最终签名缺失
    • C total Go-No-Go 缺失
  3. SDK 为 alpha 版本

    • 版本号 0.1.0-alpha
    • 不是签名生产发布
    • 已知缺少导出路径(./tx, ./contract, ./indexer)
    • 有遗留未签名 tarball
  4. 所有合约 production_ready = false

    • 即使是 official_contract 类型的 genesis_registry_v1 也是 false
    • counter_v1 仅为 starter_template
    • 没有合约经过外部审计

6.2 生产缺口清单

PRODUCTION_GAPS = {
    'signing': {
        'missing': [
            'signed_sdk_release_manifest',
            'signed_contract_schema_abi_release_manifest',
            'signed_api_schema_release_manifest',
            'signed_dapp_starter_release_manifest',
            'signed_business_examples_release_manifest',
            'signed_disabled_public_sandbox_manifest',
        ],
        'blocker': '无签名发布 manifest,无法验证来源可信度',
    },
    'endpoints': {
        'missing': [
            'public_endpoint_capability_trace',
            'public_contract_query_execute_trace',
            'public_route_inventory_trace',
            'api_receipt_query_consistency',
        ],
        'blocker': '无公开端点证据,无法确认链上行为',
    },
    'sandbox': {
        'missing': [
            'sdk_preset_fail_closed_public_evidence',
            'public_faucet_absence_boundary',
            'local_development_runbook_evidence',
        ],
        'blocker': '公开沙箱策略未签名,SDK 网络预设未验证',
    },
    'audit': {
        'missing': [
            'external_audit_final_report',
            'zero_critical_high_findings',
        ],
        'blocker': '无外部审计报告',
    },
    'final_signatures': {
        'missing': [
            'final_readiness_signatures',
            'c_total_go_no_go_receipt',
        ],
        'blocker': '无最终就绪签名和 Go-No-Go 决策',
    },
}

6.3 Human-in-the-Loop 要求

以下情况必须有人的参与:

  1. 范围锁定(scope_lock)

    • 人提供:产品目标、业务规则、验收标准
    • Agent 在缺失时:stop_and_request_scope
  2. 秘密注入(secret_injection)

    • 人提供:签名账户、API token、环境变量、域名/CI 权限
    • Agent 在缺失时:remain_in_stub_or_plan_mode
  3. 生产发布(production_release)

    • 人提供:最终审批、回滚确认、资金与治理风险确认
    • Agent 在缺失时:stop_before_release
  4. 治理/金库(governance_or_treasury)

    • 人提供:DAO 通过、timelock 结束、签名阈值达成
    • Agent 在缺失时:forbid_execution

6.4 AI Agent 的责任边界

AGENT_BOUNDARIES = {
    'allowed_autonomous': [
        '读取 release_pack/index.json 及所有子文件',
        '加载 manifest 并解析 known_blockers',
        '生成部署计划(不执行)',
        '准备 smoke check 脚本',
        '收集和整理证据',
        '检查环境变量完备性',
        '向人类呈报发布就绪状态',
    ],
    'requires_human': [
        '设置环境变量和 API token',
        '提供签名账户',
        '通过 production_release 门禁',
        '执行 cloudflare_pages_deploy 命令',
        '执行合约 store/instantiate/migrate',
        '多签或治理操作',
        '最终就绪签名和 Go-No-Go',
    ],
    'never_allowed': [
        '修改 mainnet_verdict',
        '声明主网就绪',
        '越过审批门禁执行发布',
        '使用 stub 环境变量声称生产发布',
        '删除或修改 approval_gates',
    ],
}

6.5 "不是完整的自动发布管线"

product_delivery_entry.json 明确声明:

"不能把执行层协议包解释成 100% 零人工生产上线承诺。"

developer_entry.json 补充:

"当前开发协议层可显著提升 AI coding 的可执行性,但仍不能诚实承诺
'只靠入口即可 100% 自动完成任何产品上线'。"

release_pack 的所有 manifest 也在 closing_boundary 中重申这一立场。
以 developer_sdk_signed_release_candidate_manifest.json 为例:

"This manifest records local SDK package release-candidate boundaries only.
It does not publish npm, does not sign a release, does not turn alpha into
production, does not enable public SDK defaults, and does not change the
MSGChain mainnet No-Go decision."

developer_contract_schema_abi_pack_manifest.json 的 boundary 同样声明:

"This manifest records local contract schema and ABI pack coverage only.
It does not create production evidence, does not make counter_v1 a production
contract, does not enable public SDK defaults, does not publish signed contract
schema release artifacts, and does not change the MSGChain mainnet No-Go decision."

因此,release_pack 是发布流程的"检查点"和"证据采集器",不是"自动发布按钮"。

6.6 从 No-Go 到 Go 的路径

要从当前的 No-Go 状态过渡到 Go,需要逐项解决 known_blockers:

GO_TRANSITION_PATH = [
    {
        'stage': 'signing',
        'actions': [
            '生成 signed SDK release manifest',
            '生成 signed contract schema release manifest',
            '生成 signed API schema release manifest',
            '集成 Dilithium 签名验证',
        ],
        'depends_on': ['生产环境密钥管理', 'release signer 身份建立'],
    },
    {
        'stage': 'endpoints',
        'actions': [
            '部署公开 RPC/REST 端点',
            '收集 public endpoint capability traces',
            '验证 API receipt query 一致性',
            '运行 error code negative suite',
        ],
        'depends_on': ['签名发布完成后'],
    },
    {
        'stage': 'external_audit',
        'actions': [
            '完成外部安全审计',
            '关闭所有 critical/high 发现项',
            '获取审计签名',
        ],
        'depends_on': ['端点和 SDK 就绪'],
    },
    {
        'stage': 'final_signoff',
        'actions': [
            '收集最终就绪签名',
            '执行 C total Go-No-Go 评审',
            '将 mainnet_verdict 更新为 Go',
        ],
        'depends_on': ['前述三个阶段全部完成'],
    },
]

每个阶段完成后,对应 manifest 的 production_requirements 状态应从
missing_production_evidence 更新为 accepted,最终 mainnet_verdict 才能变为 Go。

6.6 Stub 实现说明

当前 release_pack 中的许多组件是 stub(桩)实现:

STUB_COMPONENTS = {
    'dilithium_signature_verification': {
        'status': 'not_integrated',
        'description': 'Dilithium 签名验证流程已定义但未接入真实签名库',
        'location': '所有 manifest 的 dilithium_signature_verification_receipt 要求',
    },
    'public_endpoint_traces': {
        'status': 'not_available',
        'description': '所有 public_*_trace 证据均为 missing_production_evidence',
        'location': 'SDK/dApp/contract manifest 中的 public endpoint 要求',
    },
    'approval_gate_runtime': {
        'status': 'schema_only',
        'description': 'approval_gates.json 定义了门禁但未实现运行时引擎',
        'location': 'execution_pack/approval_gates.json',
    },
    'c_total_go_no_go': {
        'status': 'not_conducted',
        'description': '最终的 C total Go-No-Go 评审尚未进行',
        'location': '所有 manifest 的 final_readiness_signatures 要求',
    },
}

7. 示例

7.1 合约发布准备流程

async def prepare_contract_release():
    index = await fetch_json(f'{RELEASE_PACK_BASE}/index.json')
    checklist = await fetch_json(f'{RELEASE_PACK_BASE}/contract_release_checklist.json')
    manifest = await fetch_json(f'{RELEASE_PACK_BASE}/developer_contract_schema_abi_pack_manifest.json')

    print(f"mainnet_verdict: {manifest['mainnet_verdict']}")
    print(f"known_blockers: {len(manifest['known_blockers'])}")

    for step in checklist['steps']:
        print(f"[check] {step}")

    gates = await fetch_json(APPROVAL_GATES_URL)
    secret_gate = [g for g in gates['gates'] if g['id'] == 'secret_injection'][0]

    return {
        'status': 'plan_only',
        'requires': secret_gate['required_human_inputs'],
        'action': 'awaiting_secret_injection',
    }

7.2 站点发布准备流程

async def prepare_site_release():
    checklist = await fetch_json(f'{RELEASE_PACK_BASE}/cloudflare_pages_release_checklist.json')
    smoke = await fetch_json(f'{RELEASE_PACK_BASE}/smoke_checks.json')

    env_template = await fetch_text(f'{RELEASE_PACK_BASE}/.env.example')
    required_vars = [line.split('=')[0] for line in env_template.strip().split('\n')
                     if line and not line.startswith('#')]

    gates = await fetch_json(APPROVAL_GATES_URL)
    prod_gate = [g for g in gates['gates'] if g['id'] == 'production_release'][0]

    return {
        'status': 'plan_only',
        'smoke_checks': [c['id'] for c in smoke['checks']],
        'required_env': required_vars,
        'requires_approval': prod_gate['required_human_inputs'],
    }

7.3 发布报告汇总

async def create_release_report():
    index = await fetch_json(f'{RELEASE_PACK_BASE}/index.json')
    report = {'overall_status': 'No-Go', 'blockers': [], 'manifests': {}}

    for f in index['files']:
        if 'manifest' in f['id']:
            m = await fetch_json(f['public_url'])
            report['manifests'][f['id']] = {
                'verdict': m['mainnet_verdict'],
                'blockers': len(m['known_blockers']),
            }
            report['blockers'].extend(m['known_blockers'])

    report['blocker_count'] = len(report['blockers'])
    return report

7.4 审批状态机

class ReleaseStateMachine:
    def __init__(self):
        self.state = 'scope_lock'

    async def load_gates(self):
        gates_data = await fetch_json(APPROVAL_GATES_URL)
        self.gates = {g['id']: g for g in gates_data['gates']}

    def transition(self):
        for gid in ['scope_lock', 'secret_injection', 'production_release', 'governance_or_treasury']:
            if gid in self.gates:
                gate = self.gates[gid]
                print(f"[Door] {gid}: 需要 {', '.join(gate['required_human_inputs'])}")
                self.state = gid
                return False
        self.state = 'released'
        return True

    async def run(self):
        await self.load_gates()
        while self.state != 'released':
            if not self.transition():
                print(f"阻塞于 {self.state}: {self.gates[self.state]['agent_action_if_missing']}")
                return False
        return True

附录

A. 参考 URL

资源 URL
release_pack/index.json https://msgchain.org/whitepaper/release_pack/index.json
smoke_checks.json https://msgchain.org/whitepaper/release_pack/smoke_checks.json
.env.example https://msgchain.org/whitepaper/release_pack/.env.example
contract_release_checklist.json https://msgchain.org/whitepaper/release_pack/contract_release_checklist.json
cloudflare_pages_release_checklist.json https://msgchain.org/whitepaper/release_pack/cloudflare_pages_release_checklist.json
developer_capability_manifest.json https://msgchain.org/whitepaper/release_pack/developer_capability_manifest.json
developer_sdk_signed_release_candidate_manifest.json https://msgchain.org/whitepaper/release_pack/developer_sdk_signed_release_candidate_manifest.json
developer_contract_schema_abi_pack_manifest.json https://msgchain.org/whitepaper/release_pack/developer_contract_schema_abi_pack_manifest.json
developer_api_schema_pack_manifest.json https://msgchain.org/whitepaper/release_pack/developer_api_schema_pack_manifest.json
developer_dapp_starter_e2e_manifest.json https://msgchain.org/whitepaper/release_pack/developer_dapp_starter_e2e_manifest.json
developer_public_sandbox_strategy_manifest.json https://msgchain.org/whitepaper/release_pack/developer_public_sandbox_strategy_manifest.json
developer_business_examples_manifest.json https://msgchain.org/whitepaper/release_pack/developer_business_examples_manifest.json
delivery_workflows.json https://msgchain.org/whitepaper/execution_pack/delivery_workflows.json
approval_gates.json https://msgchain.org/whitepaper/execution_pack/approval_gates.json
command_registry.json https://msgchain.org/whitepaper/execution_pack/command_registry.json
product_delivery_entry.json https://msgchain.org/whitepaper/product_delivery_entry.json
developer_entry.json https://msgchain.org/whitepaper/developer_entry.json
agent_entry.json https://msgchain.org/whitepaper/agent_entry.json

B. 术语对照

英文 中文
release_pack 发布包
execution_pack 执行包
delivery_workflow 交付工作流
manifest 声明清单
fail-closed 默认失败
approval_gate 审批门禁
stub 桩实现
plan mode 计划模式
smoke check 冒烟检查
checkpoint 检查点
known_blocker 已知阻塞项
canonical key 规范键