MSG Chain 发布包(release_pack)与版本交付指南
目录
- 概述
- 发布包索引
- 发布流程
- 与执行包集成
- AI Agent 发布操作
- 边界声明
- 示例
1. 概述
1.1 什么是 release_pack
release_pack 是 MSG Chain 白皮书系统的发布包目录,存放与版本管理、发布检查、签名校验、
manifest 证据采集相关的机器可读文件。它不包含代码编译产物或部署脚本,而是记录"发布
前必须满足的条件"和"已完成的发布证据"。
release_pack 的核心职责:
- 提供发布索引(index.json),让 AI agent 发现所有可用的发布检查清单和 manifest
- 记录合约发布、站点发布、SDK 发布等不同维度的检查步骤
- 存储各个发布层面的 capability manifest,声明生产就绪状态(当前全部为 No-Go)
- 与 execution_pack 的 delivery_workflows 配合,在部署计划阶段消费发布检查结果
- 与 product_delivery_entry 的 recommended_full_lifecycle_order 衔接,作为上线前
的最后证据采集入口
1.2 release_pack 在 bootstrap 顺序中的位置
在 developer_entry.json:recommended_dapp_bootstrap_order(16 步)第 13 步引用 release_pack/index.json;recommended_full_lifecycle_order(20 步)第 17 步引用。在 agent_entry.json:recommended_crawl_order 将其列为关键爬取资源。这意味着 release_pack 处于"发布准备"阶段——代码已完成、测试已通过、执行命令已验证,现在进入发布计划与审批环节。
1.3 release_pack 文件清单
release_pack/index.json 登记了以下文件(截至 schema_v1):
release_pack/index.json 登记的文件(截至 schema_v1):
| 文件 | 用途 |
|---|---|
| .env.example | 发布环境变量模板 |
| cloudflare_pages_release_checklist.json | 站点发布检查清单 |
| contract_release_checklist.json | 合约发布检查清单 |
| smoke_checks.json | 冒烟测试检查点 |
| developer_capability_manifest.json | 能力 fail-closed manifest |
| developer_api_schema_pack_manifest.json | API Schema pack manifest |
| developer_contract_schema_abi_pack_manifest.json | 合约 Schema/ABI manifest |
| developer_public_sandbox_strategy_manifest.json | 公开沙箱策略 manifest |
| developer_dapp_starter_e2e_manifest.json | dApp starter E2E manifest |
| developer_sdk_signed_release_candidate_manifest.json | SDK 签名发布候选 manifest |
| developer_business_examples_manifest.json | 业务示例 library manifest |
1.4 与 execution_pack 的关系
execution_pack 提供"如何执行"(命令注册表、审批门禁、交付工作流),release_pack 提供"发布什么"(发布资产索引、检查清单、capability 声明)。两者交叉点:
- delivery_workflows 的 deploy_plan 阶段消费 release_pack/index.json
- delivery_workflows 的 real_release 阶段消费 approval_gates.json
- delivery_workflows 的 site_release 和 launch 阶段消费 release_pack/index.json + approval_gates.json
1.5 与 product_delivery_entry 的关系
product_delivery_entry.json 定义了 lifecycle order(20 步),release_pack 位于第 17 步,在 execution_pack/delivery_workflows.json 和 command_registry.json 之后、e2e_fixtures/index.json 之前。这个位置表示"先执行命令、再准备发布、最后采集 E2E 证据"。
1.6 当前状态
所有 release_pack 中的 manifest 均声明:
- mainnet_verdict: "No-Go"
- mainnet_ready_claim: false
- 全部为 fail-closed 模式
- 所有 production_requirements 状态均为 "missing_production_evidence"
这意味着 release_pack 当前是计划态和 stub 态,不构成生产发布承诺。
2. 发布包索引
2.1 索引结构
release_pack/index.json 是发布包目录的入口文件,schema_version 当前为 v1。
它由 msg_whitepaper_pipeline_v1 自动生成。
import requests
RELEASE_INDEX = 'https://msgchain.org/whitepaper/release_pack/index.json'
async def discover_release_pack():
index = await requests.get(RELEASE_INDEX).json()
return {
'version': index.get('schema_version'),
'files': index.get('files', []),
'generated_by': index.get('generated_by'),
'metadata_profile': index.get('metadata_profile'),
}
2.2 索引字段说明
- schema_version: 当前 v1,AI agent 应检查此字段确定解析方式
- generated_by: 生成器标识
- files: 文件清单数组,每个文件含 id/path/public_url
- metadata_profile: "public_stable" 表示公开发布且稳定
2.3 索引遍历逻辑
AI agent 发现 release_pack 后应执行以下操作:
async def explore_release_pack():
index = await fetch_json(RELEASE_INDEX)
checklist_files = []
manifest_files = []
for f in index.get('files', []):
file_id = f.get('id', '')
file_url = f.get('public_url', '')
if 'checklist' in file_id:
checklist_files.append((file_id, file_url))
elif 'manifest' in file_id:
manifest_files.append((file_id, file_url))
# 先加载检查清单,再加载 manifests
checklists = {cid: await fetch_json(url) for cid, url in checklist_files}
manifests = {mid: await fetch_json(url) for mid, url in manifest_files}
return {
'index': index,
'checklists': checklists,
'manifests': manifests,
}
2.4 检查清单文件
cloudflare_pages_release_checklist.json:站点发布步骤包括内容同步确认、wrangler 配置、部署后回抓、版本回滚信息保留。boundary:站点发布需要真实账号和人类审批。
{
"schema_version": "v1",
"steps": [
"确认最新白皮书与主站内容已同步到 msgchainorg 仓库",
"确认 wrangler 项目名、分支与 token/account id 已配置",
"部署后回抓 pages.dev 与正式域名关键入口",
"保留上一版本回滚信息与 smoke test 结果"
],
"boundary": ["站点发布动作仍需真实账号、发布凭据与人类审批。"],
"metadata_profile": "public_stable"
}
contract_release_checklist.json:合约发布步骤包括 cargo test 通过、部署计划与 canonical key 寻址计划、记录 tx hash/receipt/post-state query/rollback plan、确认生产密钥和 Gas 预算。boundary:没有真实部署权限和签名账户时,AI 不得声称合约未独立核验上线状态。
{
"schema_version": "v1",
"steps": [
"cargo test 或等效合约测试通过",
"生成部署计划与 canonical key 寻址计划",
"记录 tx hash /receipt /post-state query /rollback plan",
"确认生产密钥、Gas 预算、治理或多签门禁"
],
"boundary": ["没有真实部署权限与签名账户时,AI 不得声称合约未独立核验上线状态。"],
"metadata_profile": "public_stable"
}
smoke_checks.json:4 个检查点(home/agent_entry/developer_entry/knowledge_network),用于发布后的快速验证。boundary:smoke pass 不等于业务功能全量验收。
### 2.5 环境变量模板
.env.example 列出了发布所需的最小环境变量集合:
MSG_RPC_URL=https://rpc.msgchain.org
MSG_REST_URL=https://api.msgchain.org
MSG_CHAIN_ID=msg-chain-1
MSG_CONTRACT_ADDRESS=
CLOUDFLARE_ACCOUNT_ID=
CLOUDFLARE_API_TOKEN=
CLOUDFLARE_PROJECT_NAME=
AI agent 的工作:检测这些变量是否已设置,如果缺失则必须停留在计划态。
### 2.6 Manifest 文件的通用结构
每个 manifest 文件遵循统一的 fail-closed 模式:
```json
{
"schema_version": "v1",
"mainnet_verdict": "No-Go",
"mainnet_ready_claim": false,
"scope": "...",
"whitepaper_modules": [...],
"source_files": [...],
"production_requirements": [...],
"known_blockers": [...],
"closing_boundary": "...",
"source_schema_version": "...",
"source_path": "...",
"metadata_profile": "public_stable"
}
所有 manifest 的共同特征:
- mainnet_verdict 均为 "No-Go"
- 全部 production_requirements 的 status 均为 "missing_production_evidence"
- 全部 closing_boundary 声明不构成生产发布
2.7 索引的 AI agent 发现模式
当 AI agent 按 bootstrap 顺序读到 release_pack/index.json 时:
async def is_release_ready():
"""检查 release_pack 中的生产就绪状态"""
index = await fetch_json(RELEASE_INDEX)
all_blockers = []
for f in index.get('files', []):
fid = f['id']
if 'manifest' not in fid:
continue
manifest = await fetch_json(f['public_url'])
blockers = manifest.get('known_blockers', [])
all_blockers.extend(blockers)
if all_blockers:
return {
'ready': False,
'blocker_count': len(all_blockers),
'blockers': all_blockers,
'verdict': 'No-Go',
}
return {'ready': True, 'verdict': 'Go'}
当前所有 manifest 均有已知阻塞项,因此 is_release_ready() 始终返回 {'ready': False}。
3. 发布流程
3.1 发布阶段总览
release_pack 参与的完整发布流程包含以下阶段:
[代码阶段] -> [质量门禁] -> [发布计划] -> [审批门禁] -> [实际发布] -> [证据采集]
|
release_pack/index.json 在此处消费
3.2 发布计划阶段(deploy_plan)
在 delivery_workflows.json 的 contract_delivery_guarded_v1 中,deploy_plan 阶段:
- 消费:release_pack/index.json, e2e_fixtures/index.json
- 产出:部署计划, query/receipt 校验计划, rollback plan
- 审批门禁:secret_injection(要求人工注入秘密)
AI agent 在此阶段应:
- 加载 release_pack/index.json,获取所有检查清单
- 根据发布类型选择对应 checklist(合约发布用 contract_release_checklist.json,
站点发布用 cloudflare_pages_release_checklist.json) - 逐项检查 checklist 中的条件是否满足
- 生成部署计划文档
- 确认 secret_injection 门禁是否通过(未通过则停留在计划态)
3.3 版本管理
当前 release_pack 中的版本号:
| 组件 | 版本 | 渠道 | 生产就绪 |
|---|---|---|---|
| SDK | 0.1.0-alpha | alpha | false |
| 合约模板 counter_v1 | 0.1.0 | starter | false |
| genesis_registry_v1 | 1.0.0 | official | false |
| agent_registry_v1 | 0.1.0 | official | false |
| micropayment_session_v1 | 0.1.0 | business | false |
| agent_payment_v1 | 0.1.0 | business | false |
版本号策略:
- alpha 前缀表示内部开发版本,不可用于生产
- starter 模板版本不可作为官方合约对待
- official 合约当前 production_ready = false
3.4 发布类型分叉
根据发布目标的不同,release_pack 的使用路径分叉:
3.4.1 合约发布路径
delivery_workflows.json -> contract_delivery_guarded_v1
scope -> design_and_codegen -> build_and_test -> deploy_plan -> real_release
|
release_pack/index.json 用于:
1. contract_release_checklist.json 检查
2. developer_contract_schema_abi_pack_manifest.json 确认 schema 完备性
3.4.2 dApp 站点发布路径
delivery_workflows.json -> dapp_delivery_guarded_v1
scope -> scaffold -> quality_gate -> site_release
|
release_pack/index.json 用于:
1. cloudflare_pages_release_checklist.json 检查
2. smoke_checks.json 冒烟检查定义
3. developer_dapp_starter_e2e_manifest.json 确认 E2E 证据
3.4.3 产品完整启动路径
delivery_workflows.json -> product_launch_guarded_v1
compose -> evidence_closeout -> launch
|
release_pack/index.json 用于:
1. 所有 manifest 综合检查
2. developer_capability_manifest.json 全局就绪判断
3. approval_gates.json 最终审批
3.5 签名与验证
release_pack 的 manifest 记录了 Dilithium 签名验证要求。
在 developer_sdk_signed_release_candidate_manifest.json 中:
{
"id": "dilithium_signature_verification_receipt",
"status": "missing_production_evidence",
"required_evidence": [
"Dilithium signature verification receipt",
"canonical signed payload hash",
"release signer trust anchor"
],
"failure_mode": "fail-closed until SDK release signature verification is accepted"
}
签名验证流程伪码:
async def verify_release_signature(manifest_url: str, public_key: str):
manifest = await fetch_json(manifest_url)
sig_requirements = [
req for req in manifest.get('production_requirements', [])
if 'signature' in req.get('id', '') or 'sign' in req.get('id', '')
]
for req in sig_requirements:
if req['status'] == 'missing_production_evidence':
print(f"WARNING: {req['id']} - {req['failure_mode']}")
# 真实验证需要:
# 1. Dilithium 签名验证库
# 2. release signer public key manifest
# 3. canonical signed payload hash 比对
# 当前不可用,返回 fail-closed
return {
'verified': False,
'reason': 'missing_production_evidence',
'required': sig_requirements,
}
3.6 证据采集
发布流程的每个阶段都需要采集证据。证据类型包括:
EVIDENCE_TYPES = {
'raw_query': '链上查询原始结果',
'receipt': '交易收据',
'log': '执行日志',
'artifact_manifest': '制品哈希清单',
'tx_hash': '交易哈希',
'post_state_query': '发布后状态查询',
'rollback_plan': '回滚预案',
'smoke_pass': '冒烟测试通过记录',
}
release_pack 中的 manifest 使用 source_files 记录源码证据:
async def collect_source_evidence(manifest):
"""采集 manifest 中声明的 source file 哈希"""
evidence = []
for sf in manifest.get('source_files', []):
evidence.append({
'path': sf['path'],
'role': sf['role'],
'sha256': sf['sha256'],
})
return evidence
3.7 发布就绪检查协议
AI agent 在执行发布计划前应运行以下协议:
RELEASE_READINESS_PROTOCOL = {
'schema_version': 'v1',
'checks': [
{
'id': 'checklist_complete',
'description': '所有 checklist 步骤已完成',
'source': 'contract_release_checklist.json 或 cloudflare_pages_release_checklist.json',
},
{
'id': 'env_vars_set',
'description': '必需环境变量已配置',
'source': '.env.example',
},
{
'id': 'no_known_blockers',
'description': '所有 manifest 无已知阻塞项',
'source': 'manifest[*].known_blockers',
},
{
'id': 'approval_gates_passed',
'description': 'secret_injection 和 production_release 门禁已通过',
'source': 'delivery_workflows.json 对应阶段的 approval_gate',
},
{
'id': 'evidence_collected',
'description': '所需的发布证据已采集',
'source': 'manifest[*].production_requirements',
},
],
'result': None, # AI agent 填充 pass/fail/blocked
}
4. 与执行包集成
4.1 执行包概览
execution_pack 包含以下文件:
| 文件 | 用途 |
|---|---|
| index.json | 执行包索引 |
| command_registry.json | 命令注册表 |
| approval_gates.json | 审批门禁定义 |
| delivery_workflows.json | 交付工作流 |
| ci_cd_templates.json | CI/CD 模板 |
| governance_templates.json | 治理模板 |
| multisig_approval_flow.json | 多签审批流 |
| evidence_requirements.json | 证据要求 |
| artifact_contracts.json | 制品合约 |
4.2 命令注册表中的发布相关命令
command_registry.json 中与发布相关的命令:
{
"id": "package_deploy",
"command": "make package",
"cwd": ".",
"stage": "artifact_packaging",
"safe_for_agent": true,
"requires_human_approval": false,
"outputs": ["deploy-<version>", "deploy-<version>.tar.gz"],
"source": ["Makefile", "scripts/package_deploy.sh"]
}
{
"id": "cloudflare_pages_deploy",
"command": "npx wrangler pages deploy. --project-name msgchainorg ...",
"cwd": "../msgchainorg",
"stage": "release",
"safe_for_agent": false,
"requires_human_approval": true,
"outputs": ["pages deployment", "pages.dev preview", "custom domain rollout"],
"source": ["../msgchainorg/DEPLOY_CLOUDFLARE.md"]
}
注意:package_deploy 对 AI agent 安全,cloudflare_pages_deploy 需要人工审批。
4.3 approval_gates 定义
approval_gates.json 定义了四个审批门禁:
| 门禁 ID | 阶段 | 人工输入要求 | Agent 无输入时行为 |
|---|---|---|---|
| scope_lock | 编码前 | 产品目标、业务规则、验收标准 | stop_and_request_scope |
| secret_injection | 实际写入/部署前 | 签名账户、API token、环境变量、域名/CI 权限 | remain_in_stub_or_plan_mode |
| production_release | 启动前 | 最终审批、回滚确认、资金与治理风险确认 | stop_before_release |
| governance_or_treasury | 高风险写入 | DAO 通过、timelock 结束、签名阈值达成 | forbid_execution |
4.4 delivery_workflows 中的 release_pack 消费点
4.4.1 contract_delivery_guarded_v1
phase: deploy_plan
consumes: ["release_pack/index.json", "e2e_fixtures/index.json"]
produces: ["部署计划", "query/receipt 校验计划", "rollback plan"]
approval_gate: "secret_injection"
phase: real_release
consumes: ["approval_gates.json"]
produces: ["tx hash", "receipt", "post-state query", "raw evidence"]
approval_gate: "production_release"
集成模式:deploy_plan -> 加载 release_pack/index.json 和 checklist -> 确认 secret_injection 门禁 -> 生成部署计划 -> real_release -> 加载 approval_gates.json -> 确认 production_release 门禁 -> 执行发布 -> 采集 evidence。
4.4.2 dapp_delivery_guarded_v1
phase: site_release
consumes: ["release_pack/index.json", "execution_pack/approval_gates.json"]
produces: ["站点发布计划", "smoke checks", "回滚预案"]
approval_gate: "production_release"
集成模式:加载 cloudflare_pages_release_checklist.json 和 smoke_checks.json -> 检查 .env.example 环境变量 -> 确认 production_release 门禁 -> 运行 smoke check -> 生成发布结果。
4.4.3 product_launch_guarded_v1
phase: launch
consumes: ["release_pack/index.json", "execution_pack/approval_gates.json"]
produces: ["上线记录", "smoke pass", "回滚句柄"]
approval_gate: "production_release"
5. AI Agent 发布操作
5.1 Agent 在发布中的角色
AI agent 在 MSG Chain 发布流程中的角色是"受约束的发布助手",而不是"自主发布者"。
Agent 可以:
- 发现并读取 release_pack 中的所有文件
- 执行 checklist 中的可自动化步骤
- 生成部署计划(plan 态)
- 准备 smoke check 脚本
- 采集和整理发布证据
- 检查环境变量是否完备
- 验证 manifest 的 known_blockers
- 生成发布就绪报告
- 向人类提示缺失的审批输入
Agent 不可:
- 越过 approval_gates 执行发布
- 在没有签名账户的情况下声称合约未独立核验上线状态
- 使用未设置的 CLOUDFLARE_API_TOKEN 执行 wrangler deploy
- 修改 mainnet_verdict 为 "Go"
- 跨过 human_in_the_loop 的 hard_boundaries
- 将 stub 态结果标记为生产证据
5.2 安全边界
product_delivery_entry.json 定义了以下 hard_boundaries:
{
"hard_boundaries": [
"不能把执行层协议包解释成 100% 零人工生产上线承诺。",
"没有真实环境变量、签名账户、审批和 raw evidence 时,AI agent 必须停在计划态或 stub 态。"
]
}
developer_entry.json 定义了 human_inputs_required:
{
"human_inputs_required": [
"产品目标与业务规则",
"真实部署权限与签名账户",
"生产环境变量、域名、CI/CD 或发布权限",
"治理、多签、金库、审批等高风险动作的授权与窗口"
]
}
5.3 计划态 vs stub 态 vs 真实态
AI agent 的三态模型:
class AgentReleaseState:
PLAN = 'plan' # 已生成计划但未执行任何实际操作
STUB = 'stub' # 已执行模拟操作,产出框架结果
REAL = 'real' # 已执行真实操作(需要人工批准和签名)
@staticmethod
def determine(env_set: bool, gate_passed: bool, signed: bool):
if not env_set or not gate_passed:
return AgentReleaseState.PLAN
if not signed:
return AgentReleaseState.STUB
return AgentReleaseState.REAL
在 release_pack 上下文的映射:
| 条件 | 允许的状态 | 示例 |
|---|---|---|
| 无环境变量 | PLAN | 生成 .env.example 填充文档 |
| 有环境变量,无审批 | STUB | 执行 make package 但不部署 |
| 有环境变量,有审批,无签名 | STUB | 准备 wrangler 命令但不执行 |
| 全部满足 | REAL | 执行发布并采集证据 |
5.4 证据采集
AI agent 在发布过程中负责采集以下证据:
async def collect_release_evidence(workflow_phase: str, artifacts: dict):
"""
按工作流阶段采集证据。
每个 evidence 条目包含:
- type: 证据类型
- source: 来源
- content: 内容(或引用)
- verified: 是否已验证
"""
evidence = []
if workflow_phase in ('deploy_plan', 'site_release'):
evidence.append({
'type': 'deployment_plan',
'source': 'release_pack_guided_plan',
'content': artifacts.get('plan'),
'verified': False,
})
if workflow_phase == 'real_release':
evidence.extend([
{'type': 'tx_hash', 'source': 'chain', 'content': artifacts.get('tx_hash'), 'verified': True},
{'type': 'receipt', 'source': 'chain', 'content': artifacts.get('receipt'), 'verified': True},
{'type': 'post_state_query', 'source': 'rpc', 'content': artifacts.get('post_state'), 'verified': True},
])
if workflow_phase in ('site_release', 'launch'):
evidence.append({
'type': 'smoke_pass',
'source': 'smoke_checks.json',
'content': artifacts.get('smoke_results'),
'verified': False,
})
return evidence
5.5 人工审批交互
AI agent 在遇到以下情况时必须向人类请求输入:
HUMAN_INPUT_SCENARIOS = [
{
'trigger': 'scope_lock 门禁未通过',
'question': '请提供产品目标、业务规则和验收标准。',
'format': '自由文本',
},
{
'trigger': 'secret_injection 门禁未通过',
'question': '请提供以下信息:\n'
'- 真实签名账户地址\n'
'- API token(如 CLOUDFLARE_API_TOKEN)\n'
'- 环境变量(MSG_RPC_URL, MSG_REST_URL 等)\n'
'- 域名或 CI/CD 权限',
'format': '环境变量键值对',
},
{
'trigger': 'production_release 门禁未通过',
'question': '请确认:\n'
'- 最终审批已通过\n'
'- 回滚预案已确认\n'
'- 资金与治理风险已评估',
'format': '确认 / 拒绝',
},
{
'trigger': 'signature_required',
'question': '需要 Dilithium 签名验证。请提供签名账户或 release signer 公钥。',
'format': '公钥 hex 或签名结果',
},
]
5.6 Agent 行为约束规则
AGENT_RELEASE_RULES = {
'must_always_check': [
'release_pack/index.json 是否可访问',
'approval_gates.json 的当前状态',
'所有 manifest 的 mainnet_verdict',
'命令注册表中需要人工审批的命令',
'.env.example 中必需的环境变量',
],
'must_never_assert': [
'生产上线已完成(除非有人工签名和 raw evidence)',
'mainnet 就绪(除非 mainnet_verdict 为 Go)',
'无阻塞项(除非所有 known_blockers 为空)',
],
'must_always_stop_before': [
'cloudflare_pages_deploy 命令',
'合约 store/instantiate/migrate 操作',
'涉及私钥或多签的动作',
'修改链上状态的生产写入',
],
}
5.7 Manifest 读取与解析
async def load_and_validate_manifest(manifest_url: str) -> dict:
"""加载 manifest 并提取 AI agent 需要的字段"""
data = await fetch_json(manifest_url)
# 验证 schema 版本
assert data.get('schema_version') == 'v1', f"不支持的 schema 版本: {data.get('schema_version')}"
# 提取生产就绪状态
ready_state = {
'mainnet_verdict': data.get('mainnet_verdict'),
'mainnet_ready': data.get('mainnet_ready_claim', False),
'scope': data.get('scope'),
}
# 提取阻塞项
blockers = data.get('known_blockers', [])
# 提取生产要求(含 fail_closed 模式)
requirements = data.get('production_requirements', [])
missing = [r for r in requirements if r['status'] == 'missing_production_evidence']
# 提取边界声明
boundary = data.get('closing_boundary', '')
return {
'ready_state': ready_state,
'blockers': blockers,
'missing_requirements': missing,
'boundary': boundary,
'production_ready': len(blockers) == 0 and len(missing) == 0,
}
5.8 跨包依赖检查
AI agent 需要理解 release_pack 与其他包的依赖关系:
PACK_DEPENDENCIES = {
'release_pack': {
'depends_on': [
'execution_pack/command_registry.json',
'execution_pack/approval_gates.json',
'execution_pack/delivery_workflows.json',
],
'consumed_by': [
'execution_pack/delivery_workflows.json',
],
'integration_points': [
('contract_delivery_guarded_v1', 'deploy_plan', 'consumes'),
('contract_delivery_guarded_v1', 'real_release', 'consumes'),
('dapp_delivery_guarded_v1', 'site_release', 'consumes'),
('product_launch_guarded_v1', 'launch', 'consumes'),
],
},
}
5.9 多 Manifest 协调策略
当 AI agent 需要评估整体发布就绪状态时,必须联合分析所有 manifest:
async def assess_overall_release_readiness():
index = await fetch_json(RELEASE_INDEX)
verdicts = {}
all_blockers = []
for f in index['files']:
if 'manifest' not in f['id']:
continue
m = await fetch_json(f['public_url'])
key = f['id'].replace('developer_', '').replace('_manifest', '')
verdicts[key] = {
'verdict': m['mainnet_verdict'],
'ready': m['mainnet_ready_claim'],
'blocker_count': len(m['known_blockers']),
'scope': m.get('scope', '')[:80],
}
all_blockers.extend(m['known_blockers'])
all_no_go = all(v['verdict'] == 'No-Go' for v in verdicts.values())
any_ready = any(v['ready'] for v in verdicts.values())
return {
'overall_verdict': 'No-Go' if all_no_go else 'Mixed',
'all_no_go': all_no_go,
'any_ready_claim': any_ready,
'total_blockers': len(all_blockers),
'manifest_count': len(verdicts),
'manifests': verdicts,
'recommendation': (
'发布不可执行' if all_no_go
else '需逐个确认各 manifest 的生产要求'
),
}
6. 边界声明
6.1 当前发布限制
release_pack 及其所有 manifest 当前均处于 fail-closed 状态。主要限制包括:
-
所有 manifest 均为 No-Go
- developer_capability_manifest.json: mainnet_verdict = "No-Go"
- developer_sdk_signed_release_candidate_manifest.json: mainnet_verdict = "No-Go"
- developer_contract_schema_abi_pack_manifest.json: mainnet_verdict = "No-Go"
- developer_api_schema_pack_manifest.json: mainnet_verdict = "No-Go"
- developer_dapp_starter_e2e_manifest.json: mainnet_verdict = "No-Go"
- developer_public_sandbox_strategy_manifest.json: mainnet_verdict = "No-Go"
- developer_business_examples_manifest.json: mainnet_verdict = "No-Go"
-
所有生产要求均为 missing_production_evidence
- 签名 manifest 缺失
- 公开端点证据缺失
- 外部审计报告缺失
- 最终签名缺失
- C total Go-No-Go 缺失
-
SDK 为 alpha 版本
- 版本号 0.1.0-alpha
- 不是签名生产发布
- 已知缺少导出路径(./tx, ./contract, ./indexer)
- 有遗留未签名 tarball
-
所有合约 production_ready = false
- 即使是 official_contract 类型的 genesis_registry_v1 也是 false
- counter_v1 仅为 starter_template
- 没有合约经过外部审计
6.2 生产缺口清单
PRODUCTION_GAPS = {
'signing': {
'missing': [
'signed_sdk_release_manifest',
'signed_contract_schema_abi_release_manifest',
'signed_api_schema_release_manifest',
'signed_dapp_starter_release_manifest',
'signed_business_examples_release_manifest',
'signed_disabled_public_sandbox_manifest',
],
'blocker': '无签名发布 manifest,无法验证来源可信度',
},
'endpoints': {
'missing': [
'public_endpoint_capability_trace',
'public_contract_query_execute_trace',
'public_route_inventory_trace',
'api_receipt_query_consistency',
],
'blocker': '无公开端点证据,无法确认链上行为',
},
'sandbox': {
'missing': [
'sdk_preset_fail_closed_public_evidence',
'public_faucet_absence_boundary',
'local_development_runbook_evidence',
],
'blocker': '公开沙箱策略未签名,SDK 网络预设未验证',
},
'audit': {
'missing': [
'external_audit_final_report',
'zero_critical_high_findings',
],
'blocker': '无外部审计报告',
},
'final_signatures': {
'missing': [
'final_readiness_signatures',
'c_total_go_no_go_receipt',
],
'blocker': '无最终就绪签名和 Go-No-Go 决策',
},
}
6.3 Human-in-the-Loop 要求
以下情况必须有人的参与:
-
范围锁定(scope_lock)
- 人提供:产品目标、业务规则、验收标准
- Agent 在缺失时:stop_and_request_scope
-
秘密注入(secret_injection)
- 人提供:签名账户、API token、环境变量、域名/CI 权限
- Agent 在缺失时:remain_in_stub_or_plan_mode
-
生产发布(production_release)
- 人提供:最终审批、回滚确认、资金与治理风险确认
- Agent 在缺失时:stop_before_release
-
治理/金库(governance_or_treasury)
- 人提供:DAO 通过、timelock 结束、签名阈值达成
- Agent 在缺失时:forbid_execution
6.4 AI Agent 的责任边界
AGENT_BOUNDARIES = {
'allowed_autonomous': [
'读取 release_pack/index.json 及所有子文件',
'加载 manifest 并解析 known_blockers',
'生成部署计划(不执行)',
'准备 smoke check 脚本',
'收集和整理证据',
'检查环境变量完备性',
'向人类呈报发布就绪状态',
],
'requires_human': [
'设置环境变量和 API token',
'提供签名账户',
'通过 production_release 门禁',
'执行 cloudflare_pages_deploy 命令',
'执行合约 store/instantiate/migrate',
'多签或治理操作',
'最终就绪签名和 Go-No-Go',
],
'never_allowed': [
'修改 mainnet_verdict',
'声明主网就绪',
'越过审批门禁执行发布',
'使用 stub 环境变量声称生产发布',
'删除或修改 approval_gates',
],
}
6.5 "不是完整的自动发布管线"
product_delivery_entry.json 明确声明:
"不能把执行层协议包解释成 100% 零人工生产上线承诺。"
developer_entry.json 补充:
"当前开发协议层可显著提升 AI coding 的可执行性,但仍不能诚实承诺
'只靠入口即可 100% 自动完成任何产品上线'。"
release_pack 的所有 manifest 也在 closing_boundary 中重申这一立场。
以 developer_sdk_signed_release_candidate_manifest.json 为例:
"This manifest records local SDK package release-candidate boundaries only.
It does not publish npm, does not sign a release, does not turn alpha into
production, does not enable public SDK defaults, and does not change the
MSGChain mainnet No-Go decision."
developer_contract_schema_abi_pack_manifest.json 的 boundary 同样声明:
"This manifest records local contract schema and ABI pack coverage only.
It does not create production evidence, does not make counter_v1 a production
contract, does not enable public SDK defaults, does not publish signed contract
schema release artifacts, and does not change the MSGChain mainnet No-Go decision."
因此,release_pack 是发布流程的"检查点"和"证据采集器",不是"自动发布按钮"。
6.6 从 No-Go 到 Go 的路径
要从当前的 No-Go 状态过渡到 Go,需要逐项解决 known_blockers:
GO_TRANSITION_PATH = [
{
'stage': 'signing',
'actions': [
'生成 signed SDK release manifest',
'生成 signed contract schema release manifest',
'生成 signed API schema release manifest',
'集成 Dilithium 签名验证',
],
'depends_on': ['生产环境密钥管理', 'release signer 身份建立'],
},
{
'stage': 'endpoints',
'actions': [
'部署公开 RPC/REST 端点',
'收集 public endpoint capability traces',
'验证 API receipt query 一致性',
'运行 error code negative suite',
],
'depends_on': ['签名发布完成后'],
},
{
'stage': 'external_audit',
'actions': [
'完成外部安全审计',
'关闭所有 critical/high 发现项',
'获取审计签名',
],
'depends_on': ['端点和 SDK 就绪'],
},
{
'stage': 'final_signoff',
'actions': [
'收集最终就绪签名',
'执行 C total Go-No-Go 评审',
'将 mainnet_verdict 更新为 Go',
],
'depends_on': ['前述三个阶段全部完成'],
},
]
每个阶段完成后,对应 manifest 的 production_requirements 状态应从
missing_production_evidence 更新为 accepted,最终 mainnet_verdict 才能变为 Go。
6.6 Stub 实现说明
当前 release_pack 中的许多组件是 stub(桩)实现:
STUB_COMPONENTS = {
'dilithium_signature_verification': {
'status': 'not_integrated',
'description': 'Dilithium 签名验证流程已定义但未接入真实签名库',
'location': '所有 manifest 的 dilithium_signature_verification_receipt 要求',
},
'public_endpoint_traces': {
'status': 'not_available',
'description': '所有 public_*_trace 证据均为 missing_production_evidence',
'location': 'SDK/dApp/contract manifest 中的 public endpoint 要求',
},
'approval_gate_runtime': {
'status': 'schema_only',
'description': 'approval_gates.json 定义了门禁但未实现运行时引擎',
'location': 'execution_pack/approval_gates.json',
},
'c_total_go_no_go': {
'status': 'not_conducted',
'description': '最终的 C total Go-No-Go 评审尚未进行',
'location': '所有 manifest 的 final_readiness_signatures 要求',
},
}
7. 示例
7.1 合约发布准备流程
async def prepare_contract_release():
index = await fetch_json(f'{RELEASE_PACK_BASE}/index.json')
checklist = await fetch_json(f'{RELEASE_PACK_BASE}/contract_release_checklist.json')
manifest = await fetch_json(f'{RELEASE_PACK_BASE}/developer_contract_schema_abi_pack_manifest.json')
print(f"mainnet_verdict: {manifest['mainnet_verdict']}")
print(f"known_blockers: {len(manifest['known_blockers'])}")
for step in checklist['steps']:
print(f"[check] {step}")
gates = await fetch_json(APPROVAL_GATES_URL)
secret_gate = [g for g in gates['gates'] if g['id'] == 'secret_injection'][0]
return {
'status': 'plan_only',
'requires': secret_gate['required_human_inputs'],
'action': 'awaiting_secret_injection',
}
7.2 站点发布准备流程
async def prepare_site_release():
checklist = await fetch_json(f'{RELEASE_PACK_BASE}/cloudflare_pages_release_checklist.json')
smoke = await fetch_json(f'{RELEASE_PACK_BASE}/smoke_checks.json')
env_template = await fetch_text(f'{RELEASE_PACK_BASE}/.env.example')
required_vars = [line.split('=')[0] for line in env_template.strip().split('\n')
if line and not line.startswith('#')]
gates = await fetch_json(APPROVAL_GATES_URL)
prod_gate = [g for g in gates['gates'] if g['id'] == 'production_release'][0]
return {
'status': 'plan_only',
'smoke_checks': [c['id'] for c in smoke['checks']],
'required_env': required_vars,
'requires_approval': prod_gate['required_human_inputs'],
}
7.3 发布报告汇总
async def create_release_report():
index = await fetch_json(f'{RELEASE_PACK_BASE}/index.json')
report = {'overall_status': 'No-Go', 'blockers': [], 'manifests': {}}
for f in index['files']:
if 'manifest' in f['id']:
m = await fetch_json(f['public_url'])
report['manifests'][f['id']] = {
'verdict': m['mainnet_verdict'],
'blockers': len(m['known_blockers']),
}
report['blockers'].extend(m['known_blockers'])
report['blocker_count'] = len(report['blockers'])
return report
7.4 审批状态机
class ReleaseStateMachine:
def __init__(self):
self.state = 'scope_lock'
async def load_gates(self):
gates_data = await fetch_json(APPROVAL_GATES_URL)
self.gates = {g['id']: g for g in gates_data['gates']}
def transition(self):
for gid in ['scope_lock', 'secret_injection', 'production_release', 'governance_or_treasury']:
if gid in self.gates:
gate = self.gates[gid]
print(f"[Door] {gid}: 需要 {', '.join(gate['required_human_inputs'])}")
self.state = gid
return False
self.state = 'released'
return True
async def run(self):
await self.load_gates()
while self.state != 'released':
if not self.transition():
print(f"阻塞于 {self.state}: {self.gates[self.state]['agent_action_if_missing']}")
return False
return True
附录
A. 参考 URL
| 资源 | URL |
|---|---|
| release_pack/index.json | https://msgchain.org/whitepaper/release_pack/index.json |
| smoke_checks.json | https://msgchain.org/whitepaper/release_pack/smoke_checks.json |
| .env.example | https://msgchain.org/whitepaper/release_pack/.env.example |
| contract_release_checklist.json | https://msgchain.org/whitepaper/release_pack/contract_release_checklist.json |
| cloudflare_pages_release_checklist.json | https://msgchain.org/whitepaper/release_pack/cloudflare_pages_release_checklist.json |
| developer_capability_manifest.json | https://msgchain.org/whitepaper/release_pack/developer_capability_manifest.json |
| developer_sdk_signed_release_candidate_manifest.json | https://msgchain.org/whitepaper/release_pack/developer_sdk_signed_release_candidate_manifest.json |
| developer_contract_schema_abi_pack_manifest.json | https://msgchain.org/whitepaper/release_pack/developer_contract_schema_abi_pack_manifest.json |
| developer_api_schema_pack_manifest.json | https://msgchain.org/whitepaper/release_pack/developer_api_schema_pack_manifest.json |
| developer_dapp_starter_e2e_manifest.json | https://msgchain.org/whitepaper/release_pack/developer_dapp_starter_e2e_manifest.json |
| developer_public_sandbox_strategy_manifest.json | https://msgchain.org/whitepaper/release_pack/developer_public_sandbox_strategy_manifest.json |
| developer_business_examples_manifest.json | https://msgchain.org/whitepaper/release_pack/developer_business_examples_manifest.json |
| delivery_workflows.json | https://msgchain.org/whitepaper/execution_pack/delivery_workflows.json |
| approval_gates.json | https://msgchain.org/whitepaper/execution_pack/approval_gates.json |
| command_registry.json | https://msgchain.org/whitepaper/execution_pack/command_registry.json |
| product_delivery_entry.json | https://msgchain.org/whitepaper/product_delivery_entry.json |
| developer_entry.json | https://msgchain.org/whitepaper/developer_entry.json |
| agent_entry.json | https://msgchain.org/whitepaper/agent_entry.json |
B. 术语对照
| 英文 | 中文 |
|---|---|
| release_pack | 发布包 |
| execution_pack | 执行包 |
| delivery_workflow | 交付工作流 |
| manifest | 声明清单 |
| fail-closed | 默认失败 |
| approval_gate | 审批门禁 |
| stub | 桩实现 |
| plan mode | 计划模式 |
| smoke check | 冒烟检查 |
| checkpoint | 检查点 |
| known_blocker | 已知阻塞项 |
| canonical key | 规范键 |
