10 KiB
G0 status ledger — 2026-09-18 (updated 2026-09-19)
Decision
G0 is not passed. The project-owned W01/W02 and local implementation artifacts are sufficient to continue isolated development, but they are not an external contract publication, role sign-off, supplier acceptance, or production release authorization.
Environment: local development plus one owner-authorized real Debian ECS test
host that was created, hardened, and used for mock-mode binary smoke, an
isolated disposable RabbitMQ candidate receipt/event smoke, three bounded
provider INVITE signaling attempts plus a later allowed-window retry, and one
freshly user-confirmed physical provider-second outbound probe with temporary
packet capture. No approved production RabbitMQ, SaaS, OSS, AI supplier
acceptance, completed phone call, or connected RTP/media session was run; the
latest probe observed SIP signaling only and its raw capture was deleted after
sanitized analysis. The initial RunInstances attempt (and matching dry-run) was
rejected with InvalidAccountStatus.NotEnoughBalance; after account recovery
the same persisted request passed dry-run and created instance
i-2zeb69p1fo75r92wplbz with the fixed EIP. The parent source worktree was dirty; at the time of this evidence,
sip-go-agent was not an independent Git repository. The current independent
repository is go-sip; local release manifests preserve the historical fact.
Current blocker register
| Blocker | Affected W/Q/D | Responsible role | Parallel work | Release evidence required |
|---|---|---|---|---|
| External authoritative contract publication and role sign-off | W04, W05, W07, W08, W12, W14, D01–D04, D09 | S / 未指派 | Keep local contract-backed tests and generated-artifact checks green | Signed source commit/release, schema hash, role acceptance, approved broker/application-receipt semantics |
| Approved production static Cell artifact and management handoff | W06, W09, W13, W14, D06 | M / 未指派 | Maintain schema-first validation and native Asterisk package locks | Approved real-mode artifact, unique deployment writer, applied digest/revision, Asterisk load evidence and maintenance-window record |
| Production PKI, broker ACL/TLS, SaaS/OSS/AI credentials and budgets | W05–W14, D01–D08 | O + S / 未指派 | Continue isolated MQ/OSS/AI/MQ/PKI mocks and local fault tests | Expiring credentials/ACL records, approved endpoints and budgets, application receipt/verified OSS evidence, revoke/rotate evidence |
| Real SIP/media/recording/AI/OSS and two-Cell environment | W06, W09–W14, D05–D08 | O + M + S / 未指派 | Keep non-dialing Asterisk/ARI/RTP/SDK PoCs and deployment smoke isolated | Two physical Cells, approved trunks, final From/PAI/prefix proof, PCMA/RTP/recording/AI/OSS chain, failure/capacity evidence |
| Clean reproducible release and controlled cutover ownership | W13–W15 | O + 集成负责人 / 未指派 | Preserve dirty/non-production manifest and do not start production services | Clean source/ref and digest, approval matrix, old/new ownership proof, unknown-execution reconciliation and signed cutover record |
D01–D10 evidence
| Item | Local evidence completed | Remaining G0/P1 gate |
|---|---|---|
| D01 events | Strict project-owned schemas, eight event fixtures, rejection of call.transcript, contract hash checks, disposable RabbitMQ confirm/ACK/DLQ integration, Dispatcher tenant consume→SQLite inbox/task/outbox→event publish integration, and owner-authorized ECS candidate consume-only automatic outbox flush with temporary agent-call.command.result queue receipt |
External authoritative publication, role sign-off, approved broker ACL/version, crash ordering, and SaaS application receipt evidence |
| D02 dual AI modes | Full-AI/ASR-only schema branches, immutable snapshot digest/mode tests, bounded mock pipelines, and local contract/fixture SaaS Mock checks (docs/evidence/20260919-local-saas-contract-mock.md) |
Upstream source publication and real ASR-only/full-AI supplier acceptance |
| D03 authorization/parameters | Tenant/version/digest/time/revocation/egress authorization; optional Agent RPC permit/Execute guard; isolated OpenAI/DashScope/Volcengine API PoCs | SaaS AI-version GET/credential registry/validity contract, actual parameter capability, cancellation/backpressure, and supplier authorization |
| D04 Unary/last permit | Generated agent.v1 Unary service, TLS 1.3 mTLS/SAN checks, session fencing, CAS, SQLite reservation-to-Agent execution seam, unknown-result preservation, contract-backed local flow joining command/quota/Agent/event boundaries, owner-authorized ECS mock mTLS R01/R02→permit→Execute→accepted receipt smoke, and full Dispatcher.ExecuteReserved quota/command/reservation→mTLS Agent result with task_status=running |
Approved business semantics/sign-off, cross-Cell final barrier, ARI submission boundary, real MQ application receipt, and fault-injection evidence |
| D05 sessions/certificates | Peer/SAN validation, durable session-generation journal, old-generation fencing, boot/epoch tests, local trust-root rotation rejection; owner-authorized Debian ECS loopback-only smoke with disposable TLS1.3 CA/client/server certificates, pre-activation R01 GetAgentStatus + R02 session status, negative rejection of no-client/rogue-CA clients, project internal/rpc.DialFromFiles + dispatcher.AgentCoordinator, actual Dispatcher Cobra endpoint-inventory startup, same-host two-Agent/two-Cell session binding, configured Agent/Cell identity rejection, wrong-inventory PermissionDenied, restart-based CA root replacement with old-client rejection, same-boot Dispatcher generation 1→2 recovery, and Agent-side leaf fingerprint allowlist with same-CA unauthorized-client rejection |
Physical two-Cell/cross-host process interop, fleet-wide endpoint-role rotation/revocation distribution, cross-host deployment certificate interop, and production health evidence; smoke record: docs/evidence/20260918-w06-mtls-cloud.md |
| D06 static Cell artifact | Schema-first artifact validation, source/Cell/digest/revision/egress/trunk checks, real-mode startup path, activation rejection tests | Management approval matrix, unique deployment writer, actual Asterisk load evidence, and maintenance-window proof |
| D07 OSS handoff | HTTPS/host/redirect/size/checksum/expiry/object-key grant guards, 15-minute single-use grant policy with explicit re-request, upload binding/expiry completion checks, direct PUT and metadata RPC tests, source-asset retention after direct upload until verified handoff, Alibaba OSS SDK PUT/HEAD, durable completion, outbox and recording.ready closure (docs/archive/evidence/20260920-local-oss-mq-integration.md, docs/evidence/20260920-new-ecs-preflight.md) |
Production SaaS upload-session/complete/application receipt, production broker ACL/TLS, approved retention cleanup and current provider-third recording evidence |
| D08 profile/recovery | SQLite quotas, leases, reservation finalization, file recovery/quarantine, gopsutil host/process sampling with media/AI dimensions explicit unknown, two mock Cell isolation, one hardened Debian ECS host smoke | Approved numeric budget/profile, backup/RPO/RTO and disk/clock/lease fault evidence; no two-Cell or production capacity evidence |
| D09 independent contract package | Self-contained project-owned baseline, manifests, hashes, contract/proto checks, local release manifest | External source commit/release and reproducible clean isolated import/build sign-off |
| D10 reuse/PoCs | Go module licenses (including gopsutil), go mod verify, clean govulncheck; isolated ARI, OpenAI, DashScope and Volcengine compile/protocol-mock records; fixed Asterisk 22.10.1 + temporary ari/v5.3.1 runtime probes created Stasis channels, mixing bridges, PCMA ExternalMedia address/port/lifecycle, synthetic bridge forwarding, and a PJSIP/PJSUA2 mock leg with bidirectional PCMA and closed endpoint WAVs; owner-authorized ECS also recorded three non-connected provider INVITE outcomes |
Lockable production versions, Asterisk/provider/OSS/broker compatibility, successful supplier/real media, recording retention/OSS/reconnect evidence, DashScope endpoint injection, Volcengine TTS speed/volume/pitch reachability, and O review/sign-off |
References
- Project baseline: the historical pre-v1 contract snapshot (removed from the current work tree)
- Local evidence:
docs/evidence/20260918-local-development.json - W05 SQLite restart evidence:
docs/evidence/20260918-w05-restart.md - W06/W12 targeted local evidence:
docs/evidence/20260918-w06-w12-local.md - W06 cloud mTLS smoke:
docs/evidence/20260918-w06-mtls-cloud.md - Acceptance matrix:
docs/evidence/20260918-acceptance-matrix.md - Dependencies:
docs/evidence/20260918-dependencies.md - Media PoC boundary:
docs/evidence/20260918-media-poc-blocker.md - W09 isolated ARI runtime:
docs/evidence/20260918-w09-ari-runtime.md - W09 isolated SIP/ARI signaling:
docs/evidence/20260918-w09-sip-ari.md - W09 isolated PJSIP/RTP/ARI media:
docs/evidence/20260918-w09-sip-rtp-ari.md - AI SDK PoC:
docs/evidence/20260918-ai-sdk-poc.md - RabbitMQ integration:
docs/evidence/20260918-rabbitmq-integration.md - Local release entry:
scripts/build-release.sh - Initial real cloud provisioning failure:
docs/evidence/20260918-aliyun-provisioning-blocker.md - Successful cloud host bootstrap:
docs/evidence/20260918-cloud-host-bootstrap.md - Owner-authorized real SIP signaling attempts:
docs/evidence/20260918-real-sip-provider-calls.md - Later allowed-window retry:
docs/evidence/20260919-real-sip-provider-calls-retry.md - Latest confirmation-gated physical provider probe:
docs/evidence/20260919-real-provider-ecs-direct.md - ECS deployment/SIP boundary:
docs/evidence/20260918-ecs-sip-deployment.md - SIP routing implementation boundary:
docs/evidence/20260919-sip-routing-implementation-comparison.md
The next G0 decision requires the missing external source/role/authorization records and the corresponding isolated or real evidence; local green tests must not be relabeled as G0, P1, or production acceptance.