Skip to content

feat(zcode): integrate PowerContext with ZCode CLI and Windows desktop - #1752

Open
jackie-cqz wants to merge 10 commits into
oceanbase:masterfrom
jackie-cqz:feat/zcode-integration
Open

jackie-cqz wants to merge 10 commits into
oceanbase:masterfrom
jackie-cqz:feat/zcode-integration

Conversation

@jackie-cqz

@jackie-cqz jackie-cqz commented Sep 27, 2026 •

Copy link
Copy Markdown

Which issue or RFC does this PR close?

Closes #1751.

Rationale for this change

ZCode users need a repeatable way to capture project conversations as PowerContext Sources, generate Memory, and recall it in a fresh session. The integration also needs to expose PowerContext MCP operations without requiring users to manage separate Hook and MCP endpoints.

What changes are included in this PR?

  • Add a ZCode plugin with a UserPromptSubmit Hook, PowerContext MCP declaration, and project-context skill for the open-source CLI and official Windows desktop edition.
  • Add powercontext setup zcode and doctor zcode. Setup preserves unrelated ZCode settings, installs a managed plugin copy, and keeps Hook and MCP on one Server URL.
  • Preserve nullable Handoff carrier fields in the MCP input schema so a first prepared Handoff can be continued and committed verbatim.
  • Add focused CLI, Hook, MCP, integration-manifest, and Server-chain tests; document the integration in English and Chinese.

Are there any user-facing changes?

ZCode appears as an experimental community integration. Setup writes to the user's ZCode plugin configuration and requires a ZCode restart. No HTTP API or persisted artifact format changes are introduced. Bearer authentication is supported through the ZCode process environment. Cross-machine HTTPS has been validated through an SSH port forward; direct HTTPS ingress and other official desktop versions have not been validated.

How was this change tested?

  • python -m pytest -q tests/test_cli_zcode.py tests/test_mcp.py tests/e2e/test_zcode_service_chain.py: 19 passed.
  • python -m pytest -q tests/test_integration_manifest.py: 29 passed; generated capability documentation is current.
  • node --test integrations/zcode/plugins/powercontext/tests/plugin.test.mjs integrations/zcode/plugins/powercontext/tests/host.test.mjs with ZCODE_CLI_BIN set: 12 passed.
  • Website content generation, link validation, production build, and static export verification passed; the latter checked 833 public pages. Website lint and tests also passed.
  • Ruff and targeted ty check passed for changed Python files. Full-repository ty check on Windows still reports existing POSIX-only symbol diagnostics in unrelated modules; Linux CI remains to be run.
  • Official Windows desktop ZCode 3.14.3 was exercised with a real local PowerContext Server: prompt capture → automatic Memory generation → fresh-session recall; MCP Memory and Handoff calls; local Bearer authentication; Server outage/recovery; and installation from a clean user-owned profile. Open-source ZCode CLI 0.16.9 also completed a real-model and local-Server capture → scheduled Memory generation → fresh-session recall test in an isolated scope, with the generated entry citing the captured Source.
  • The open-source CLI connected from Windows to a PowerContext Server on a separate Linux machine through Caddy HTTPS over an SSH port forward, with a trusted private CA and Bearer token. Unauthenticated API access returned 401 and authenticated access returned 200. The CLI invoked MCP list_scopes against the remote Server, and its ordinary prompt was captured as a Source that was read back from the same remote Scope. Direct TLS on the remote listener could not be validated on the current network path because the handshake failed.

AI usage statement

OpenAI GPT-6 assisted with implementation, tests, documentation, and analysis of local validation results. The user performed the official ZCode desktop interactions and supplied the observed tool results.

@CLAassistant

CLAassistant commented Sep 27, 2026 •

Copy link
Copy Markdown

CLA assistant check
All committers have signed the CLA.

@jackie-cqz jackie-cqz changed the title [codex] Integrate PowerContext with ZCode CLI and Windows desktop feat(zcode): integrate PowerContext with ZCode CLI and Windows desktop Sep 27, 2026
@jackie-cqz
jackie-cqz marked this pull request as ready for review September 27, 2026 11:18

@Teingi Teingi left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Three issues remain in automatic prompt capture and ZCode diagnostics; details inline.

const MAX_CONTEXT_BYTES = 8_000
const MAX_QUERY_CHARACTERS = 8_192
const MAX_SOURCE_CHARACTERS = 200_000
const SECRET_PATTERN = /(?:\b(?:api[_-]?key|access[_-]?token|token|authorization|password|secret|private[_-]?key)\s*[:=]\s*\S+|\bbearer\s+\S+|\bsk-[A-Za-z0-9_-]{8,}|-----BEGIN [^-]*PRIVATE KEY-----)/iu

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] Exclude quoted credential keys from automatic Source capture

The key alternative only allows whitespace before : or =, so the closing quote in JSON bypasses this filter. With default capture enabled, {"password":"synthetic-password-for-review"} and {"access_token":"synthetic-token-for-review"} were posted verbatim to /v1/sources/content, while password=synthetic-password-for-review was correctly skipped. Ordinary pasted JSON configuration can therefore persist credentials as Source evidence. Handle quoted credential keys before automatic capture and cover these JSON forms alongside unquoted assignments.

Comment on lines +246 to +247
for await (const chunk of process.stdin) {
raw += chunk

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] Decode stdin as a continuous UTF-8 stream

process.stdin yields Buffer chunks, and raw += chunk decodes each independently. A multibyte character crossing a read boundary becomes replacement characters. On Node 24, a single stdin write containing 100,000 Chinese characters produced corrupted capture content; splitting a short valid payload inside 中 also changed its Source ID despite identical session, turn, and input. This corrupts Source evidence and makes retry identity depend on pipe boundaries. Use a streaming UTF-8 decoder or concatenate the bytes before decoding.

Comment on lines +208 to +210
endpoint = _url(_selected_url(host, prefix, native_url))
if native_url and native_url != endpoint:
raise ValueError("Cannot determine a single PowerContext transport: ZCode Hook and MCP URLs differ") # noqa: TRY003

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P2] Match the Hook's saved-URL precedence in doctor

_selected_url() prioritizes environment URLs over powercontext.json, but the installed Hook and MCP both keep the saved URL. With a healthy installation and a stale POWERCONTEXT_ZCODE_SERVER_URL=http://127.0.0.1:1, doctor zcode --json reports all five installation/readiness checks as OK, then adds this false transport mismatch and exits 1. Resolve diagnostics using the Hook's actual precedence so an unused fallback environment variable cannot mark a working installation as broken.

Copy link
Copy Markdown
Author

@Teingi please review again. thx.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat: integrate PowerContext with ZCode CLI and Windows desktop

3 participants