Files
go-sip/docs/evidence/20260918-g0-status.md
T

10 KiB
Raw Blame History

G0 status ledger — 2026-09-18 (updated 2026-09-19)

Decision

G0 is not passed. The project-owned W01/W02 and local implementation artifacts are sufficient to continue isolated development, but they are not an external contract publication, role sign-off, supplier acceptance, or production release authorization.

Environment: local development plus one owner-authorized real Debian ECS test host that was created, hardened, and used for mock-mode binary smoke, an isolated disposable RabbitMQ candidate receipt/event smoke, three bounded provider INVITE signaling attempts plus a later allowed-window retry, and one freshly user-confirmed physical provider-second outbound probe with temporary packet capture. No approved production RabbitMQ, SaaS, OSS, AI supplier acceptance, completed phone call, or connected RTP/media session was run; the latest probe observed SIP signaling only and its raw capture was deleted after sanitized analysis. The initial RunInstances attempt (and matching dry-run) was rejected with InvalidAccountStatus.NotEnoughBalance; after account recovery the same persisted request passed dry-run and created instance i-2zeb69p1fo75r92wplbz with the fixed EIP. The parent source worktree was dirty; at the time of this evidence, sip-go-agent was not an independent Git repository. The current independent repository is go-sip; local release manifests preserve the historical fact.

Current blocker register

Blocker Affected W/Q/D Responsible role Parallel work Release evidence required
External authoritative contract publication and role sign-off W04, W05, W07, W08, W12, W14, D01–D04, D09 S / 未指派 Keep local contract-backed tests and generated-artifact checks green Signed source commit/release, schema hash, role acceptance, approved broker/application-receipt semantics
Approved production static Cell artifact and management handoff W06, W09, W13, W14, D06 M / 未指派 Maintain schema-first validation and native Asterisk package locks Approved real-mode artifact, unique deployment writer, applied digest/revision, Asterisk load evidence and maintenance-window record
Production PKI, broker ACL/TLS, SaaS/OSS/AI credentials and budgets W05–W14, D01–D08 O + S / 未指派 Continue isolated MQ/OSS/AI/MQ/PKI mocks and local fault tests Expiring credentials/ACL records, approved endpoints and budgets, application receipt/verified OSS evidence, revoke/rotate evidence
Real SIP/media/recording/AI/OSS and two-Cell environment W06, W09–W14, D05–D08 O + M + S / 未指派 Keep non-dialing Asterisk/ARI/RTP/SDK PoCs and deployment smoke isolated Two physical Cells, approved trunks, final From/PAI/prefix proof, PCMA/RTP/recording/AI/OSS chain, failure/capacity evidence
Clean reproducible release and controlled cutover ownership W13–W15 O + 集成负责人 / 未指派 Preserve dirty/non-production manifest and do not start production services Clean source/ref and digest, approval matrix, old/new ownership proof, unknown-execution reconciliation and signed cutover record

D01–D10 evidence

Item Local evidence completed Remaining G0/P1 gate
D01 events Strict project-owned schemas, eight event fixtures, rejection of call.transcript, contract hash checks, disposable RabbitMQ confirm/ACK/DLQ integration, Dispatcher tenant consume→SQLite inbox/task/outbox→event publish integration, and owner-authorized ECS candidate consume-only automatic outbox flush with temporary agent-call.command.result queue receipt External authoritative publication, role sign-off, approved broker ACL/version, crash ordering, and SaaS application receipt evidence
D02 dual AI modes Full-AI/ASR-only schema branches, immutable snapshot digest/mode tests, bounded mock pipelines, and local contract/fixture SaaS Mock checks (docs/evidence/20260919-local-saas-contract-mock.md) Upstream source publication and real ASR-only/full-AI supplier acceptance
D03 authorization/parameters Tenant/version/digest/time/revocation/egress authorization; optional Agent RPC permit/Execute guard; isolated OpenAI/DashScope/Volcengine API PoCs SaaS AI-version GET/credential registry/validity contract, actual parameter capability, cancellation/backpressure, and supplier authorization
D04 Unary/last permit Generated agent.v1 Unary service, TLS 1.3 mTLS/SAN checks, session fencing, CAS, SQLite reservation-to-Agent execution seam, unknown-result preservation, contract-backed local flow joining command/quota/Agent/event boundaries, owner-authorized ECS mock mTLS R01/R02→permit→Execute→accepted receipt smoke, and full Dispatcher.ExecuteReserved quota/command/reservation→mTLS Agent result with task_status=running Approved business semantics/sign-off, cross-Cell final barrier, ARI submission boundary, real MQ application receipt, and fault-injection evidence
D05 sessions/certificates Peer/SAN validation, durable session-generation journal, old-generation fencing, boot/epoch tests, local trust-root rotation rejection; owner-authorized Debian ECS loopback-only smoke with disposable TLS1.3 CA/client/server certificates, pre-activation R01 GetAgentStatus + R02 session status, negative rejection of no-client/rogue-CA clients, project internal/rpc.DialFromFiles + dispatcher.AgentCoordinator, actual Dispatcher Cobra endpoint-inventory startup, same-host two-Agent/two-Cell session binding, configured Agent/Cell identity rejection, wrong-inventory PermissionDenied, restart-based CA root replacement with old-client rejection, same-boot Dispatcher generation 1→2 recovery, and Agent-side leaf fingerprint allowlist with same-CA unauthorized-client rejection Physical two-Cell/cross-host process interop, fleet-wide endpoint-role rotation/revocation distribution, cross-host deployment certificate interop, and production health evidence; smoke record: docs/evidence/20260918-w06-mtls-cloud.md
D06 static Cell artifact Schema-first artifact validation, source/Cell/digest/revision/egress/trunk checks, real-mode startup path, activation rejection tests Management approval matrix, unique deployment writer, actual Asterisk load evidence, and maintenance-window proof
D07 OSS handoff HTTPS/host/redirect/size/checksum/expiry/object-key grant guards, 15-minute single-use grant policy with explicit re-request, upload binding/expiry completion checks, direct PUT and metadata RPC tests, source-asset retention after direct upload until verified handoff, Alibaba OSS SDK PUT/HEAD, durable completion, outbox and recording.ready closure (docs/archive/evidence/20260920-local-oss-mq-integration.md, docs/evidence/20260920-new-ecs-preflight.md) Production SaaS upload-session/complete/application receipt, production broker ACL/TLS, approved retention cleanup and current provider-third recording evidence
D08 profile/recovery SQLite quotas, leases, reservation finalization, file recovery/quarantine, gopsutil host/process sampling with media/AI dimensions explicit unknown, two mock Cell isolation, one hardened Debian ECS host smoke Approved numeric budget/profile, backup/RPO/RTO and disk/clock/lease fault evidence; no two-Cell or production capacity evidence
D09 independent contract package Self-contained project-owned baseline, manifests, hashes, contract/proto checks, local release manifest External source commit/release and reproducible clean isolated import/build sign-off
D10 reuse/PoCs Go module licenses (including gopsutil), go mod verify, clean govulncheck; isolated ARI, OpenAI, DashScope and Volcengine compile/protocol-mock records; fixed Asterisk 22.10.1 + temporary ari/v5.3.1 runtime probes created Stasis channels, mixing bridges, PCMA ExternalMedia address/port/lifecycle, synthetic bridge forwarding, and a PJSIP/PJSUA2 mock leg with bidirectional PCMA and closed endpoint WAVs; owner-authorized ECS also recorded three non-connected provider INVITE outcomes Lockable production versions, Asterisk/provider/OSS/broker compatibility, successful supplier/real media, recording retention/OSS/reconnect evidence, DashScope endpoint injection, Volcengine TTS speed/volume/pitch reachability, and O review/sign-off

References

  • Project baseline: the historical pre-v1 contract snapshot (removed from the current work tree)
  • Local evidence: docs/evidence/20260918-local-development.json
  • W05 SQLite restart evidence: docs/evidence/20260918-w05-restart.md
  • W06/W12 targeted local evidence: docs/evidence/20260918-w06-w12-local.md
  • W06 cloud mTLS smoke: docs/evidence/20260918-w06-mtls-cloud.md
  • Acceptance matrix: docs/evidence/20260918-acceptance-matrix.md
  • Dependencies: docs/evidence/20260918-dependencies.md
  • Media PoC boundary: docs/evidence/20260918-media-poc-blocker.md
  • W09 isolated ARI runtime: docs/evidence/20260918-w09-ari-runtime.md
  • W09 isolated SIP/ARI signaling: docs/evidence/20260918-w09-sip-ari.md
  • W09 isolated PJSIP/RTP/ARI media: docs/evidence/20260918-w09-sip-rtp-ari.md
  • AI SDK PoC: docs/evidence/20260918-ai-sdk-poc.md
  • RabbitMQ integration: docs/evidence/20260918-rabbitmq-integration.md
  • Local release entry: scripts/build-release.sh
  • Initial real cloud provisioning failure: docs/evidence/20260918-aliyun-provisioning-blocker.md
  • Successful cloud host bootstrap: docs/evidence/20260918-cloud-host-bootstrap.md
  • Owner-authorized real SIP signaling attempts: docs/evidence/20260918-real-sip-provider-calls.md
  • Later allowed-window retry: docs/evidence/20260919-real-sip-provider-calls-retry.md
  • Latest confirmation-gated physical provider probe: docs/evidence/20260919-real-provider-ecs-direct.md
  • ECS deployment/SIP boundary: docs/evidence/20260918-ecs-sip-deployment.md
  • SIP routing implementation boundary: docs/evidence/20260919-sip-routing-implementation-comparison.md

The next G0 decision requires the missing external source/role/authorization records and the corresponding isolated or real evidence; local green tests must not be relabeled as G0, P1, or production acceptance.