diff --git a/vehicle-data-platform/docs/deployment.md b/vehicle-data-platform/docs/deployment.md index b50d05ee..b3af8446 100644 --- a/vehicle-data-platform/docs/deployment.md +++ b/vehicle-data-platform/docs/deployment.md @@ -191,6 +191,8 @@ test -n "$MYSQL_DSN" The API guards the access-threshold tables for compatibility, while alert APIs deliberately require the alert migrations to exist. Run every numbered migration explicitly before switching traffic so DDL permission and index creation failures are caught early. The migration journal records filename and SHA-256 and refuses a changed file; duplicate forward `ADD COLUMN` and `CREATE INDEX` statements are tolerated only when resuming partially executed MySQL DDL. Full-line SQL comments are removed before statement splitting, so punctuation in a comment cannot become executable SQL. Migration `008` adds forward-compatible access evidence columns and an index to the gateway-owned realtime snapshot table without changing its `(protocol, vin)` primary key. Migration `009` creates the per-group/topic/partition event-time checkpoint used to make MySQL effects authoritative before Kafka offsets are committed. Migration `014` backfills active vehicle-grant start times, creates the grant-interval history table and adds the active time lookup index; apply it before starting an API binary that writes grant history. Migration `015` adds platform-owned optimistic versions and immutable audits for per-vehicle location-source policy changes. It does not alter the gateway election SQL or expose the gateway `source_key`; the API resolves an opaque `sourceRef` server-side and the gateway applies the saved policy on the next valid vehicle report. +Production release `source-diagnosis-stable-20260716173740` applied migration `015` before switching API traffic. The release gate verified 23 current assets and 42 compatibility assets. The authenticated diagnostic smoke used a real multi-source vehicle, confirmed that `source_key` was absent, and exercised the admin PUT route with values identical to the current policy; version, audit count and recommended source remained unchanged. Viewer/operator/admin access returned 403/200/200, median response time across 20 reads was approximately 70 ms (P95 79 ms), and the platform plus both alert evaluators remained active. + Install and start the evaluator as a separate unit only after API smoke checks and a small enabled-rule review: ```bash diff --git a/vehicle-data-platform/docs/frontend-production-readiness.md b/vehicle-data-platform/docs/frontend-production-readiness.md index 3f9c43a9..050d3da6 100644 --- a/vehicle-data-platform/docs/frontend-production-readiness.md +++ b/vehicle-data-platform/docs/frontend-production-readiness.md @@ -323,6 +323,16 @@ Single-vehicle reverse geocoding is explicitly user-triggered and keyed by a rou Vehicle-scoped track, history, mileage and alert actions are grouped together and filtered by the authenticated menu grants. Track/history/mileage preserve monitor return context. Tests assert information hierarchy, nested context, zero suppression and the absence of a geocoding request before user action. The full frontend gate passed 49 files and 252 tests plus the production build. ECS smoke verified the real vehicle `LNXNEGRR7SR318212`, the live-first bundle markers, production health and all three services; the release gate served 23 current and 60 compatibility assets. +## 2026-07-16: operator source diagnosis workspace + +Release `source-diagnosis-stable-20260716173740` makes the operations page a single-vehicle evidence workspace before the existing global health panels. Vehicle candidates use bounded fuzzy search with 20-result pagination. Source evidence is fetched only after selection and is not attached to the recurring health/readiness polls. + +Every real location candidate exposes a provider label, masked terminal, protocol, first/latest report evidence, protocol interval, position/mileage, online and quality state, policy priority and a human-readable election explanation. The page distinguishes an independently configurable source from a read-only canonical fusion snapshot. Only administrators can save enablement, priority and a reason; operators are read-only and viewers cannot call the diagnostic endpoint. + +The browser never receives a gateway `source_key`. The API emits an opaque SHA-256 `sourceRef`, resolves it back to the current candidate server-side and writes the existing gateway policy table through optimistic platform-owned versions and immutable audits. The gateway election algorithm is unchanged and a saved policy is documented as taking effect on the next valid report. + +The V2 gate passed 49 files and 253 tests, the TypeScript/Vite production build and release-installer tests. Production migration `015` was applied before traffic switched. A real multi-source vehicle returned two location candidates without leaking source keys. A no-op admin save kept version `1`, audit count `0` and the GB32960 recommendation unchanged. Viewer/operator/admin authorization returned 403/200/200, 20 diagnostic calls measured about 70 ms median and 79 ms P95, and all three services remained active. + ## Release evidence template - Commit and release identifier diff --git a/vehicle-data-platform/docs/vehicle-data-platform-meeting-todo.md b/vehicle-data-platform/docs/vehicle-data-platform-meeting-todo.md index 747432e7..f6b6c4d9 100644 --- a/vehicle-data-platform/docs/vehicle-data-platform-meeting-todo.md +++ b/vehicle-data-platform/docs/vehicle-data-platform-meeting-todo.md @@ -305,7 +305,18 @@ ### P1-01 专业运维多来源诊断页 -状态:`进行中` +状态:`已完成` + +已上线结果(release `source-diagnosis-stable-20260716173740`): + +- 运维质量页新增“单车多来源诊断”工作台,支持车牌/VIN 模糊候选、20 辆一页分页和按需加载;没有选车时不读取来源明细,也不参与现有 15/30 秒全局健康轮询。 +- 单车一次展示全部位置来源和同协议多终端,包含提供方、脱敏终端、协议、在线/质量、首次和最近上报、协议上报周期、累计样本、坐标、速度、总里程、协议内选中、融合推荐和中文选举原因。 +- 推荐说明明确解释启用状态、质量、协议内选中、人工优先级,以及网关两分钟新鲜度、漂移冲突保护和连续有效样本;协议融合快照只读,不能被误当成独立终端策略。 +- operator 可只读诊断,viewer 被拒绝,admin 才可调整真实独立来源的启停、1–1000 优先级和备注。服务端使用乐观版本;实际变更写入操作人、版本、前后启停/优先级/备注和时间。 +- 前端只接收 SHA-256 形式的 `sourceRef`;原始 `source_key`、来源 IP 和未脱敏终端不出现在响应。保存后明确提示由车辆下一次有效上报触发网关重新选举,未修改网关原有选举 SQL。 +- 迁移 `015_vehicle_source_policy_audit.sql` 已在生产应用,建立平台自有版本和不可变审计表;发布安装器会把新增编号迁移带入每个不可变 release。 +- Go 全量测试、现行前端 49 个文件/253 项测试、TypeScript/Vite 构建、安装器测试均通过。旧版非生产入口测试仍有 51 个既有 `fetch(url, undefined)` 断言失败,与当前统一 `AbortSignal` 请求实现不一致,不作为 V2 发布门禁。 +- ECS 真实多来源车辆 `LB9A32A21R0LS1464` 验证返回 2 个位置来源、1 个可配置来源,当前推荐 GB32960;不变值管理员保存保持策略 v1、审计 0 和推荐来源不变。权限烟测为 viewer 403、operator 200、admin 200;20 次诊断请求中位约 70ms、P95 约 79ms,三个服务均 active。 目标: