--- title: Ax9000WRTBuild – Development Tasks (Shared) type: curated permalink: main/projects/6f47523e-e22e-4cdd-bd18-76e5e474ee0c/curated/ax9000-wrtbuild-development-tasks-shared stable_id: 67e34406-4966-4e48-ab88-69e2fb15a144 scope: project project_id: 6f47523e-e22e-4cdd-bd18-76e5e474ee0c workspace_type: general usage_profile_id: null preference_context: general document_type: tasks revision: 9 source_memory_ids: [] source_checkpoint_ids: [] source_file_ids: [] source_git_commit: a066d95b43240f85f5abcf18305c2edfe1da91a3 source_git_commits: - a066d95b43240f85f5abcf18305c2edfe1da91a3 source_agent_sync_ids: [] model_connection: Sub2API model_name: openai/gpt-oss-20b source_count: 52 source_revisions: memory:be916376-ddf7-44e0-be53-963d5b2aa655: '1' memory:1033d1fb-6d87-4009-8b39-498c8963f6aa: '1' memory:afa3e76f-eb77-49b5-9769-6ba559026c35: '1' memory:86452d01-8146-41aa-80f9-7d5481135394: '1' memory:61e30ee3-0e26-4d64-b00e-f77bc3a3fd60: '1' memory:7687d956-f904-4629-bd5d-4f5b55ec2b84: '1' memory:ce9006a3-2313-411f-b577-10bbb9b9c3bb: '1' memory:e61163f1-50db-49d4-839b-a8bdb67741c2: '1' memory:98bc33f7-c293-4e7c-aca8-f54752e2d5fa: '1' memory:aecf7e99-3d31-4d3f-ada5-928eee77c95b: '1' memory:5daa77ea-300c-4185-b408-8e5d021e67d5: '1' memory:86a5a0e1-2536-48c2-b48a-5e6b8e85cd50: '1' memory:52072cd9-4e1c-40c2-8393-3ec92b962a1d: '1' memory:4f66cf8b-520b-4407-80a6-be6b470b6713: '1' memory:c19a1ce5-b51c-4fe0-bdea-a7521dde7618: '1' source_dispositions: processed: 52 unchanged: 0 unsupported: 0 skipped: 0 cited_source_ids: - curated_baseline:67e34406-4966-4e48-ab88-69e2fb15a144 - memory:52072cd9-4e1c-40c2-8393-3ec92b962a1d - memory:4f66cf8b-520b-4407-80a6-be6b470b6713 - memory:c19a1ce5-b51c-4fe0-bdea-a7521dde7618 - memory:86a5a0e1-2536-48c2-b48a-5e6b8e85cd50 - memory:be916376-ddf7-44e0-be53-963d5b2aa655 - memory:1033d1fb-6d87-4009-8b39-498c8963f6aa - memory:afa3e76f-eb77-49b5-9769-6ba559026c35 - memory:86452d01-8146-41aa-80f9-7d5481135394 - memory:61e30ee3-0e26-4d64-b00e-f77bc3a3fd60 - memory:7687d956-f904-4629-bd5d-4f5b55ec2b84 - memory:ce9006a3-2313-411f-b577-10bbb9b9c3bb - memory:e61163f1-50db-49d4-839b-a8bdb67741c2 - memory:98bc33f7-c293-4e7c-aca8-f54752e2d5fa - memory:aecf7e99-3d31-4d3f-ada5-928eee77c95b - memory:5daa77ea-300c-4185-b408-8e5d021e67d5 job_cited_source_ids: [] conflicts: [] supersedes: [] preferences: [] source_cursor: 700 source_hash: 425f69c7d615a0522a06a54c0b88e30cbb169b3da8e430a957345bc06a169bb7 prompt_version: 2026-08-12.3 schema_version: '3' curation_job_id: 63262a75-ff99-4aa4-9c31-03f6b59df88f created_at: '2026-08-12T17:42:38.214414+00:00' updated_at: '2026-09-19T08:47:11.690265+00:00' tags: - project - tasks --- ## Current Outstanding Work | # | Task | Current Status | Suggested Approach | Source IDs | |---|------|-----------------|--------------------|------------| | 1 | Docker Hub proxy (“manual”) – `http://127.0.0.1:7897` | **待实现** – Docker Desktop must be configured to use the local proxy so that `docker pull` can resolve images without external network access. | • Set the proxy in Docker Desktop’s **Proxies** → `http://127.0.0.1:7897` (see fix 468f52a6‑e941‑49f7‑a422‑64bbcec6e0f4). | `67e34406-4966-4e48-ab88-69e2fb15a144` | | 2 | FastAPI JWT auth, bind to `127.0.0.1` | **待实现** – currently unauthenticated and bound to all interfaces. | • Add JWT middleware and `--host 127.0.0.1` to mitigate remote exploitation. | `67e34406-4966-4e48-ab88-69e2fb15a144` | | 3 | Migrate `.runtime/*.json` credentials to Vaultwarden | **待实现** – secrets currently stored in plaintext. | • Delete all `.runtime/*.json`, upload corresponding secrets to Vaultwarden via API, reference Vault paths in configuration. | `67e34406-4966-4e48-ab88-69e2fb15a144` | | 4 | Pin Docker image digest, Git commit SHA, `uv.lock` | **待实现** – dependencies could drift between runs. | • Record image digest, commit SHA, and lock file hash in a CI artifact or logging layer to ensure reproducibility. | `67e34406-4966-4e48-ab88-69e2fb15a144` | | 5 | Convert patch script (`patch_ax9000.py`) to `.patch` file and use `git am` | **待实现** – fragile text replacement. | • Create a `0001-.patch` and apply with `git am` during CI. | `67e34406-4966-4e48-ab88-69e2fb15a144` | | 6 | CI pipeline (GitHub Actions) – lint, tests, build, artifact upload | **待实现** – no CI defined yet. | • Add a workflow that checks syntax, runs unit‑tests, builds the image, and uploads `outputs/ax9000/` to a release artifact. | `67e34406-4966-4e48-ab88-69e2fb15a144` | | 7 | Unified JSON‑Schema → Pydantic & TypeScript | **待实现** – inconsistent UI/model. | • Adopt a single JSON‑Schema to generate Pydantic models in FastAPI and TS types for Vue to prevent mismatches. | `67e34406-4966-4e48-ab88-69e2fb15a144` | **Resolved Items** - Git repository on `main` is committed and pushed (`0e152f6c087c29b999258a24fffbdaab13fb9607`). - Docker image `openwrt‑local‑builder:25.12` exists locally. - FastAPI running at `0.0.0.0:9001`; Vue dev server available at `localhost:9000`. - Built firmware ZIP stored in `outputs/ax9000/`. **Open Work** Conflicts or unresolved settings are limited to the above task list; the system’s current state satisfies the component readiness tests, but the security, reproducibility, and infrastructure concerns need to be addressed before shipping. --- ## Preferences - **Answer‑First** – Deliver known answers immediately before discussion. (source: `9988effa-80c9-4062-97a2-8a5f40e3856a`) - **Development Preference – Use Chinese** – All communication in Chinese. (sources: `7429c22e-50ff-458a-97c0-423c679904c7`, `e4fc35f2-1606-4b79-9c1e-367edeea97d0`) - **Vault‑First Credential Access** – All secrets live in Vaultwarden, only one matching vault entry is used. (source: `105b328f-4bda-4641-90a7-7282ef156316`) - **Push After Commit** – Every finished feature is committed immediately and pushed if a remote exists. Rebase on new remote changes, avoid force‑push unless explicitly authorised. (source: `2406be77-e6ce-4572-890e-18747c968f55`) - **No Auto‑Project Creation** – In a temporary session without a project directory, never auto‑create a project. (source: `ac8bb556-947d-43a1-87d9-bfe7e8da310b`) - **MemRelay Only** – All memory persists in MemRelay; `aidocs/` is never updated unless exported. (sources: `bf88c265-4749-4c50-85bc-4bae25298cd5`, `25332e63-48d0-4daa-8c08-d676bb2d310d`) Each preference is classified at **scenario** level as they are supported by a single source ID and no counterexamples exist.