6.1 KiB
2026-09-19 single-node AI closure attempt
Scope
This evidence covers the user-authorized scope amendment: project-owned v1 contracts, an automatically approved single-node real-mode Cell artifact, real provider ASR/LLM/TTS credentials, and a one-node ARI/ExternalMedia runtime. The second Cell is intentionally out of this iteration.
Completed
- Active contract bundle is
contracts/upstream/2026-09-19-p1-v1. static-cell-artifact-v1.jsonvalidates asmode=realwith ARI, per-trunk media profiles, the three provider bindings selecting PCMA/A-law 8 kHz RTP payload type 8 (plus an optional slin16/16 kHz profile), and 0600-WAV recording requirements.agent-version-full-production-v1.jsonselects Volcengine ASR, Bailian OpenAI-compatible LLM and Bailian Qwen3 TTS (qwen3-tts-flash, licensedCherryvoice). The prior environment voice reference was rejected by the provider and is not used by this v1 snapshot.AGENT_CALL_PROVIDER_SMOKE=1 go test -v ./internal/ai -run TestProviderFullAIChain -count=1passed provider ASR → LLM → TTS, including TTS WAV download, PCM16 decoding and 16 kHz resampling.- The shared
internal/callflowvalidates the immutable full-AI snapshot and runs the same sequence for mock, mixed and real adapters: opening prompt, bounded media capture, ASR, LLM, TTS, playback and RTP facts. The runtime now executes up to three effective turns, enforces a 120-second call limit from the AI snapshot, emits per-turn inbound/outbound WAV/hash facts, and ends early for an LLM[INVALID_CALL]marker or explicit refusal/automation signals. The Agent--call-onceentry only selects transport/provider adapters frommode; it is not a second real-only business flow. The mock path completed the shared sequence with 6,400 inbound bytes, 10 received packets and 2 sent packets. - The isolated
sip_mock_serverAsterisk/ARI mixed run completed the same shared flow through a real ExternalMedia bridge: 31 inbound RTP packets, 19,840 inbound bytes, 2 outbound packets, 24 transcript characters, 39 reply characters, and closed Agent-side inbound/outbound WAV facts. The redacted evidence isdocs/evidence/20260919-mixed-ari-callflow.json. - A fresh isolated PCMA
call-oncerun completed the same shared flow with the trunk-selectedpcma-8k-pt8profile: PCMA/8000/PT8 SDP, Asterisk ExternalMediaalaw, 110 received and 20 sent RTP packets, U1 scripted playback, non-silent callee RX/TX WAVs, and transcript/reply facts. The structured evidence isdocs/evidence/20260920-pcma-mixed-callflow.json. - The runtime now passes the selected trunk media format to Asterisk
ExternalMedia instead of hard-coding
slin16; the mock full-AI TTS fixture is deterministic and non-silent so the strict mock callee can advance its scripted dialogue. The unit suite asserts the fixture is non-silent. - On 2026-09-20, one freshly confirmed real attempt used
provider-secondand raw target15003164745. Asterisk answered, enteredStasis, joined the PJSIP and UnicastRTP channels to the Agent bridge, and the Agent observed 220 received and 136 sent RTP packets. The real ASR returned an empty transcript, so LLM/TTS and final recording/OSS/MQ facts were not reached. The attempt was not retried; details are indocs/evidence/20260920-real-provider-second-15003164745.json. - The three earlier bounded real-provider CallFlow attempts and their
no-
StasisStartcauses remain recorded indocs/evidence/20260919-real-provider-callflow-attempts.json. - The new 美吧口腔 policy is in
deploys/config/ai-dental-meiba-v1.json: it identifies 美吧口腔, asks which dental project the user wants, limits the call to three effective turns/120 seconds, and requires the[INVALID_CALL]early-stop marker for invalid calls. - A freshly confirmed three-turn deployment attempt was stopped before
StasisStartwith provider-secondcause=1, so the new three-turn, recording and two-sided transcript behavior was not yet exercised on a real phone. Details are indocs/evidence/20260920-real-provider-second-3turn-attempt.json. - The real transport adapter uses the Asterisk ARI SDK, a mixing bridge, Pion
RTP/UDP ExternalMedia, bounded turn capture, WAV recording and hashes. It
now derives the outbound RTP peer from Asterisk
UNICASTRTP_LOCAL_*, sends the opening prompt before waiting for caller audio, uses channel-specific bridge IDs, passes ARI originate timeouts in seconds as required by the ARI SDK, and captures PCM16 turns with bounded first-speech/max-turn/end-silence behavior modeled on the validated Python Cell. - ECS staging used a temporary SSH-injected credential file; it was deleted after the attempts. Credentials are not stored in this repository.
Uncompleted phone acceptance
Several explicitly authorized attempts through provider-second and
provider-third reached Asterisk originate but ended before StasisStart
(cause=1 for provider-second and cause=19 for provider-third/provider-primary).
The endpoints reported Avail; their local contract mappings, PCMA codec, caller
profiles, prefixes and contacts were validated. One earlier provider-second call
reached ExternalMedia and produced bidirectional RTP counters, but its ASR was
empty; the latest three-turn attempt again ended with cause=1 before
StasisStart. Real three-turn recording and two-sided recognition content are
still not signed as passed.
Raw PCAP could not be collected because the SSH rogee account has no
CAP_NET_RAW and no passwordless controlled sudo. The runtime now reports
application-level RTP packet/byte counters, but they remain zero when the
provider hangs up before media setup. No raw capture was retained.
Decision boundary
The remaining single-node AI closure gates are a stable real answered call, three-turn non-empty ASR/LLM/TTS media, per-turn two-sided recording and recognition facts, recording retention, OSS verified handoff and MQ business result closure. The isolated mixed ARI flow and the answered-but-empty-ASR real attempt are not substitutes for those gates. Do not claim full phone AI acceptance, P1, production cutover or billing until a freshly confirmed run proves all of those facts.