feat: L0 线协议冻结 + 附件链路修复 + 人/Agent 区分

L0 核心:
- 严格解码 Decode(DisallowUnknownFields) 全覆盖 29 个 DecodeBody 调用点
- DecodeLenient 心跳专用:容忍新字段但回报 unknown_fields
- 400 消息列出本端点接受的全部字段(jsonFieldNames 反射 tag)
- 日历 status 校验(create 补字段 + update 拦非法值)
- 新增 strictdecode_test.go 10 例 + blob/list_test.go 6 例

A-4 附件挂载回滚:checkAttachable 在 CreateMail 前校验,失败按
解挂→释放 relay→删邮件→退预算回滚,幽灵邮件这条路堵住了

A-5 反向 GC:blob.Store.List() 枚举磁盘(跳 .upload-*),
SweepUnreferencedBlobs 按 attachments + calendar_attachments 反查,
48h 年龄下限兜上传窗口。已接进每小时 sweep 循环

C 人/Agent 区分:四个读路径 + threadCols 补 from_human / to_human
(EXISTS users 判定),models.Mail 加 ToHuman。前端判据从
workspace 启发式改成显式布尔,mailCounterpart/sessionCounterpart
从 session_workspace 取 path(修 dsh@dsh 拼接 bug)

契约文档:SSE new_mail 补 4 字段(in_reply_to/from_human/
permission_mode/permission_enforcement),B-5 加 B-5.6
(Agent→Agent 不转发),B-3.4 MUST 改条件式,心跳补 mode_enforcement
+ unknown_fields,demo 死链修复 + from_human 检查
验收清单加 Agent→Agent 负向对照项
This commit is contained in:
2026-09-06 15:18:06 +08:00
parent a44fd6949b
commit 79c4171c9d
40 changed files with 3369 additions and 116 deletions

View File

@ -80,6 +80,32 @@ func IsLunarRecurrence(r string) bool {
return r == RecurLunarMonthly || r == RecurLunarYearly
}
// 事件状态常量。
//
// 此前这三个值只以裸字符串形式散落在 handler、scheduler 与前端里,而更新端点
// 把 `status` 原样写进库 —— 于是一个拼错的值(比如 "pause")会变成一个
// **调度器不认识的状态**:DueEvents 只查 status='active',那条提醒于是静默失效。
// 人以为自己只是暂停了它,实际上再也恢复不了(界面的下拉框里没有这个选项)。
//
// 提成常量后,handler.validEventStatus 能对着这一份清单校验。
const (
// EventActive 生效中:到点会触发提醒。
EventActive = "active"
// EventPaused 暂停:保留事件与重复规则,但不触发。
EventPaused = "paused"
// EventCancelled 已取消:保留历史记录,不再触发也不再推进重复。
EventCancelled = "cancelled"
)
// ValidEventStatus 判断状态取值是否合法。
func ValidEventStatus(s string) bool {
switch s {
case EventActive, EventPaused, EventCancelled:
return true
}
return false
}
// 投递模式常量。
const (
DeliverSeparate = "separate"