diff --git a/AGENTS.md b/AGENTS.md index 8b211e4..818412f 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -80,7 +80,7 @@ - P01–P08 及 K01–K16 已完成**项目内隔离 Mock** 核验;本轮把分散的人类可读契约、文档与第三方对接合为唯一当前规范,不重审已确认规则。若未来另获启动开发/审查子 Agent 授权,必须按使用者指定的 `gpt-5.6-luna`、`max` 思考和 `fast: true` 逐项核验并显式配置,不静默换模型、降档或关闭 fast。 - 唯一现行 SaaS↔Dispatcher 业务规范是 [`docs/thirds/saas-dispatcher.md`](docs/thirds/saas-dispatcher.md);当前项目内 Schema、拓扑、正反例及来源/hash 在 [`contracts/local/`](contracts/local/);内部 Agent RPC 在 [`proto/agent/agent.proto`](proto/agent/agent.proto)。本地验收与外部缺口见 [`docs/evidence/saas-dispatcher-p08-acceptance.md`](docs/evidence/saas-dispatcher-p08-acceptance.md)。Markdown 不代替机器合同或外部签收,也不另外维护一份平行字段定义。 - 已由当前合同来源清单固定哈希的历史提案与计划保留**原字节**于 [`docs/archive/sources/`](docs/archive/sources/README.md),使用者原有未提交的两份旧对接文档也按原字节归档;旧上游 v1 在 [`docs/archive/upstream/`](docs/archive/upstream/README.md) 可离线校验,但不嵌入运行合同。旧 F/W 工作包、旧 MQ-only 合同及归档不作为当前运行入口。固定 MQ `v1`、HTTP `/internal/v1/dispatcher/...` 和业务 revision 是现行通信规则,不是自有实现代次;不得为历史路径新建兼容或回退。 -- 当前业务范围仍仅**单节点、单 Dispatcher、单 Agent、单 Cell、单租户和隔离 Mock**。根命令只接受显式 `agent`/`dispatcher`;mixed/real 启动即拒绝。另有严格隔离的 `--mode sip-only`:只允许 Dispatcher 读完整 SIP、持久接纳归属 `sip.config`、经已激活双向 TLS Agent 会话将完整快照应用到原生 Asterisk,并从运行态核对版本;不发现任务、不启动业务呼叫、不开放准入、不处理其他业务控制。测试机已凭使用者批准,将三条历史登记地址以**测试快照显式声明的** UDP/IP 鉴权、无需 REGISTER 配置写入并核对 Asterisk 运行态;供应商尚未确认这些实际线路是否满足上述参数,无拨号,不证明线路可用或生产签收。没有真实 SaaS、management、OSS、AI 供应商或生产签收;生产发布包仍为 `production_approval=false`。任何本机 Mock 或 SIP-only 核验均不授权真实呼叫。 +- 当前业务范围仍仅**单节点、单 Dispatcher、单 Agent、单 Cell、单租户和隔离 Mock**。根命令只接受显式 `agent`/`dispatcher`;mixed/real 启动即拒绝。另有严格隔离的 `--mode sip-only`:只允许 Dispatcher 读完整 SIP、持久接纳归属 `sip.config`、经已激活双向 TLS Agent 会话将完整快照应用到原生 Asterisk,并从运行态核对版本;不发现任务、不启动业务呼叫、不开放准入、不处理其他业务控制。测试机已凭使用者批准,将三条历史登记地址以**测试快照显式声明的** UDP/IP 鉴权、无需 REGISTER 配置写入并核对 Asterisk 运行态;供应商尚未确认这些实际线路是否满足上述参数,无拨号,不证明线路可用或生产签收。没有真实 SaaS、management、真实通话或生产签收;真实百炼 LLM 与 OSS 已各做一次**不拨号、独立的最小连接/写入诊断**(见 [`docs/evidence/real-ai-oss-one-shot-20261003.md`](docs/evidence/real-ai-oss-one-shot-20261003.md)),这不是获批任务的 ASR/LLM/TTS、录音和上传全链路签收。生产发布包仍为 `production_approval=false`。任何本机 Mock 或 SIP-only 核验均不授权真实呼叫。 - 开发按 TDD 分批,小步提交;不得覆盖使用者现存修改/未跟踪文件,不自动清理、迁移或覆盖任何现存 SQLite、spool、outbox 和 Agent 恢复文件。旧 `.executions` 及恢复根目录中旧 `.uploads`、`.upload-locks`、逐执行 `state.json` 的发现须只读失败关闭,现存未交付事实由使用者确认处置。真实云账号、EIP、线路、拨号、生产部署和共享数据操作分别需要明确授权。 ## SaaS、Dispatcher 与 Agent 的现行边界 @@ -91,6 +91,7 @@ - 独立 Dispatcher 的 SQLite 是任务、额度、inbox/outbox 的权威数据;Agent 无业务数据库,录音、执行与上传恢复只写受控私有文件。额度包含未知占用,新 boot/租约到期不得自动清除未知执行;不实现双活数据库、自动跨机热备、多 D 共享额度或第二租户公平。本轮不借本机 D1/D2 隔离夹具宣称多 D 运行。不得建立旧表/旧消息/旧 HTTP 执行兼容通道。 - Dispatcher↔Agent 复用 Unary gRPC 和受控 Endpoint;Agent 预绑定 D UUID 与服务端证书指纹,激活/会话代际、peer mTLS/SAN/SNI 和已签发期限须核对,新 boot 不清未知占用。Agent 不自行向 SaaS 取任务/AI/OSS 授权;Dispatcher 只用已经核验的 Agent `GetLoadedSIP` revision 开执行准入。本机 Mock 的加载回报不证明 Asterisk 已实际加载;仅隔离 SIP-only Agent 在配置原子写入、PJSIP reload 和运行态 endpoint/AOR/UDP transport 一致后持久标记 revision,每次加载查询重新核验。只支持明确的 UDP、IP/none 鉴权、无需 REGISTER 的 IPv4/PCMA 线路;未知字段和其他传输/鉴权/注册方式拒绝,不热更静态 transport。SIP 配置的唯一编辑/审批面仍是 management。 - AI 使用任务内不可变授权快照:仅经获批准百炼/火山 ASR、OpenAI 兼容 LLM、火山 TTS 能表达的参数进入每通话实例;ASR-only 不启动 LLM/TTS,完整 AI 不借旧语音测试的 LLM/TTS。只有最终用户 ASR 文本的明确字面关键词可触发拒联/挂断;不由 SDK 默认值、环境、CLI、metadata 或宽松 Schema 改写业务参数,不因 SDK 重试产生第二次发起/收费或重播。日志只存脱敏版本/摘要/计数,不存密钥、prompt、完整对话或音频。 +- **本项目既有私有配置的取用入口(仅在相应真实服务获得明确授权时使用,不是运行时回退)**:工作区 `.local/provider-ai.env` 为权限 `0600` 的历史百炼/火山凭据文件,按明确字段读取 `BAILIAN_API_KEY`、`BAILIAN_BASE_URL` 等所需项;仓库根 `aliyun-oss.env` 为权限 `0600` 的冒号分隔文件,按 `Bucket`、`Endpoint`、`Region`、`AccessKeyId`、`AccessKeySecret` 字段解析。一次性外部诊断仅以进程内存向现有 `AGENT_CALL_REAL_AI_INTEGRATION=1`、`AGENT_CALL_OSS_INTEGRATION=1` 测试注入获准字段;常规构建/测试不读这些文件,绝不 `source` 不可信内容、输出密钥/签名 URL、提交文件或覆盖/清理旧 OSS 对象。现行业务 AI 参数仍须来自 SaaS 批准的 task/providers 完整快照,OSS 须由 Dispatcher 私有 `DISPATCHER_OSS_CONFIG_FILE` 与获批上传授权提供;上述历史文件**不能**直接当 SaaS 快照、任务授权或真实通话准入。旧 `.local/asterisk-*/ari.conf` 仅为历史本机文件,不证明重装后主机已有 ARI 配置。 - Agent 录音经受控双向 TLS 向 D 领取短期 OSS 上传授权,每次尝试只作**一次 HTTPS PUT**;正常上传成功不写录音/结果业务文件。首次明确失败须先完整保存录音与结果两份恢复文件,才从该时刻启动 48 小时重试;按 1、2、4、8、16、32、60 分钟及其后每 60 分钟的固定节奏显式重新申请授权,同一 OSS 目标、同一消息身份。PUT 结果未知不得盲目重传;48 小时届满仍失败时保留文件待人工,**不伪造最终结果或自动清理**。D 不转发文件,已确认结束的通话及时释放执行占用;未知执行仍占用。只有真实终结后才通过唯一 `call.execute.result` 回报录音路径、最终转写和拒联事实;无录音或录音生成失败以空 `recording={}` 和真实结果收口,生成失败须说明原因。不能恢复的录音不声称零丢失,也不伪造 OSS/SaaS 应用回执。凭据/TOKEN/签名 URL 不写入样例、日志、源码或证据。 ## SIP 与真实呼叫限制 diff --git a/docs/evidence/sip-user-service-nonprod.md b/docs/evidence/sip-user-service-nonprod.md index 0ba813d..a3099bd 100644 --- a/docs/evidence/sip-user-service-nonprod.md +++ b/docs/evidence/sip-user-service-nonprod.md @@ -25,9 +25,14 @@ The test host's address and raw logs are omitted from committed evidence. - A replay of the already applied revision 12 returned to `(12,0,0)` with an empty control queue and unchanged managed-config and verified-state file modification times; no second native write/reload was needed. RabbitMQ publisher confirms only broker acceptance; the separate Agent/Asterisk readback and Dispatcher checkpoint established this isolated application's handling. Neither the publisher confirm nor the local Mock response proves external SaaS receipt or production readiness. A transient user-service startup delay was treated as unready rather than inventing a loaded revision. With lingering disabled, this test does **not** verify service availability after logout or reboot. - Restricted test certificates, environment files, raw logs and snapshots remain outside the repository; committed evidence contains no credential, service IP, caller identity, audio, or transcript. The test made **no call**, registration, media capture, or active-call reload. +## Capture-tool preflight — 2026-10-04 + +- On the same pinned Debian 13 test host, `rogee` now passes noninteractive `sudo -n true`. With explicit user authorization, installed Debian `tcpdump` **4.99.5-2** and `libpcap0.8t64` **1.10.5-2**; tcpdump executable SHA-256 `0d426e2571a22de0d30996fd01bb44c1f267f33065023abea092c88bad16d2d2`. +- `sudo -n tcpdump -D` reported **8 interfaces**. This is only a capability check: **no packet capture or call** was started. Asterisk ARI/HTTP config is still absent on this rebuilt host, the business call executable remains Mock-only, and a real provider/task snapshot has not been signed off. At inspection Asia/Shanghai was **08:15**, before the authorized 09:00 opening; installation of tcpdump alone is not dialing permission. + ## Still required before a real call or production acceptance 1. Verify the effect of endpoint updates **during an active authorized call** separately; SIP-only does not enable business dialing. Unsupported authentication/REGISTER and transport changes must continue to fail closed, and provider-side authentication, registration, routing and capacity remain unverified. 2. Obtain carrier-confirmed authentication, transport and registration requirements for each real line, provide approved real line configuration, and arrange each whitelist trial (trunk, original number, time, attempt count). The fixed Asia/Shanghai 09:00–20:00 gate and per-number daily cap remain mandatory. -3. Establish RabbitMQ/OSS/AI real integrations and nonproduction call-evidence capture. `deploys/test/nonprod-call-evidence.sh` requires root or the required capture capabilities; this host's `rogee` currently has no sudo. If tcpdump, logger, or ARI/PJSIP state is unavailable, do not dial. +3. Establish the approved task/provider snapshots, real ASR/TTS/recording chain and nonproduction call-evidence capture. One isolated Bailian LLM request and one unique-object OSS PUT succeeded independently ([evidence](real-ai-oss-one-shot-20261003.md)); neither proves a phone call or SaaS application receipt. tcpdump and passwordless sudo are now present, but `deploys/test/nonprod-call-evidence.sh` still targets a system-level Asterisk service rather than this host's `rogee` user service. Update and verify that diagnostic entry, ARI/HTTP config, PJSIP logger, and pre-dial capture before any call; any unavailable step fails closed. 4. Enable `rogee` user lingering and verify reboot-persistent `enabled+active` before claiming production readiness. Complete the host/network/dependency diagnostics and external signoffs separately; local `make check` cannot replace them.