---
description: Ailoha iOS 前端 P0/P1 问题在 Release、main 与本地候选上的适用范围、失效条件、责任角色和验证状态
status: active
updated: 2026-08-28
sources:
  - repo://ailoha-agent-iOS@0b90745ed21438b194f8f9401a47d012cdbe66e5
  - repo://ailoha-agent-iOS@6922f359ad08da70242e4ec0c5c4a1486bc2908d
  - repo://ailoha-agent-iOS@5e6ac6e41c53780c85808c92290d2bd38f809123
  - brain://tasks/active/IOS-20260812-frontend-refactor-wave0/verification.md
confidence: high
sensitivity: internal
---

# 同一个前端问题，现在到底在哪条代码线上成立？

<!-- brain-capture:ios-frontend-revision-aware-claim-ledger -->

## 一句话结论

截至 2026-08-28，21 个 P0/P1 机制中，只有 Chat 双轨在 current main **结构性关闭**；颜色 token 在 main **部分迁移**；账户隔离、日志值最小化、跨进程恢复、导航、Onboarding 提交合同、可访问性、性能和 App 级验证等大多数问题在 Release 与 main 仍成立，或者只有本地未集成候选。以后不能再用一个“已解决 / 未解决”标签覆盖三条事实线。

## 读这张账本时先记住三件事

1. `R` 是当前 Release `0b90745`，观察于 2026-08-25；`M` 是 current main `6922f35`，观察于 2026-08-27；`L` 是 `5e6ac6e` 派生的脏工作区候选，观察于 2026-08-27。
2. `L 有候选` 只表示本机出现了实现和测试证据，不表示进入 main、Release、CI 或生产。
3. 下面的“责任角色”是代码 / 决策边界，不是 Linear assignee。当前问题目录没有绑定 canonical Linear issue，因此**人员 owner 全部未知**；创建任务时必须去 Linear 指定，不能从 Git 作者或本文推断。

## 先看会改变排期的四个结论

- **MIG-001 不应继续排成 main 的删除任务。** main 已删 Chat V1 和 flag，旧 consumer=0 的结构事实已经成立；main 剩下的是 V2 长会话、崩溃与回滚基线，Release 才仍有双轨迁移债。
- **DS-001 不是“main 完全没有 token”。** main 已有 manifest 与生成 Swift，但 `ALHColors` 仍是第二来源；任务应改成迁移收口和视觉回归。
- **A11Y-003 的旧扫描数字只适用于 Release。** Release 的 Swift 扫描是 0 处 Reduce Motion 读取；main 增加了 2 处读取，但 Onboarding 的循环视频、引导视频与 Try It 重复呼吸仍未覆盖，应该按代码线分别重验。
- **PRIV-001 / SEC-001 / XPROC-001 不能被本地 PASS 提前关闭。** Release/main 源码仍可复现关键机制，本地候选又缺受保护集成或真实系统 replay。

## P0 / P1 revision claim ledger

`验证状态` 的口径：`red` = 已有反例或静态事实直接击中；`missing` = 还没有能裁决该承诺的测试；`partial` = 窄层检查通过，但不覆盖完整承诺；`green-structural` = 结构条件成立，仍不代表运行或生产完成。

| ID | 适用代码线 | observed_at / 当前证据 | 什么能让这条 claim 失效 | 责任角色 / Linear owner | 当前 verifier 状态 |
|---|---|---|---|---|---|
| PRIV-001 | `R open` · `M open` · `L candidate only` | R/M 普通 logout 已同步重置 Task routing/state，并清 Import、Live Activity 等状态；但没有同步清 Contact 与 Calendar published state，也没有覆盖各服务迟到异步副作用的共同 session fence。M 联系人 page 1 响应前仍保留旧数组。 | 保留现有 Task reset；普通 logout 在身份释放前统一重置 Contact 与 Calendar，并让所有迟到工作通过共同 session / generation fence；A→logout→B 的第一帧和请求返回后都看不到 A 数据。 | Account lifecycle + App composition；Linear：未绑定 | `red`：current Contact/Calendar 与 late-response causal path；R/M `missing` hosted A→B；L 只有本地候选 |
| SEC-001 | `R open` · `M open` · `L request_changes` | M 仍把 APNs token 前 20 位、Soniox key 前 8 位和 screenshot update token 前缀写进日志消息；值会进入持久 logger。 | 所有 credential source 在构造消息前 value-free；source→所有已知 sink guard、真实日志文件与上传样本都证明无值 / 前缀。 | Security / privacy + Logging lifecycle；Linear：未绑定 | `red`：M 三个明确 caller；L guard successor 尚无最终独立批准 |
| XPROC-001 | `R open` · `M open` · `L protected replay missing` | R/M 的 Screenshot、Intent、App Group 与系统副作用跨 session；main 有更多清理和协调，但无 stale session 不可落地的完整合同。 | account × environment × session envelope 同时绑定 transport、EventKit、writer 与 recovery；旧 session 的 network / system / file write 均被 spy 拒绝。 | Cross-process lifecycle；Linear：未绑定 | `missing`：R/M 无 hosted/system replay；L 有窄候选，protected extension replay 未完成 |
| PRIV-002 | `R open` · `M open` · `L candidate only` | M `CalendarViewModel.clearCache()` 仍只清 range cache，不清 `events` / `eventsByDate`。 | 专用 account reset 同步清可观察 projection、cache、selection 和运行任务，并拒绝 reset 前迟到响应。 | Calendar state owner；Linear：未绑定 | `red`：current code；R/M `missing` 双账号 verifier；L hosted 候选通过 |
| STATE-001 | `R open` · `M open` · `L not targeted` | R/M `TaskStateManager` 持详情 / alias / pending，`HomeViewModel` 仍独立分页、merge 与乐观更新。 | 一份 canonical Task authority 拥有 entity、alias 与有序 transition；Home / Chat 只保留 query 和 UI projection。 | Task domain state；Linear：未绑定 | `missing`：没有证明跨 Home / Chat transition 唯一性的 App behavior test |
| NAV-001 | `R open` · `M open` · `L not targeted` | M 仍由 NotificationCenter 进入 external task，读取 `visibleTaskChatId` 后固定 sleep 0.1s，再按栈状态 replace / push。 | 一个 typed navigation effect owner 原子决定去重与栈变化；删除固定延时；冷 / 热 / 重复深链 reducer 与 hosted test 全部通过。 | App navigation；Linear：未绑定 | `red`：current 0.1s causal path；`missing` deterministic route verifier |
| ARCH-001 | `R open` · `M open` · `L not targeted` | R/M `ServiceLocator` 仍以 `[String: Any]` resolve，缺失时 fatal；`.shared` 又能绕过 locator。 | 选定 feature 的依赖、生命周期和 test double 由 typed composition root 声明；旧全局入口有删除账本且 consumer 归零。 | App composition；Linear：未绑定 | `missing`：无依赖方向 guard；main 新 Package 还被 GlobalImports 隐式暴露 |
| TEST-001 | `R open` · `M open` · `L candidate only` | R/M 都没有 App unit / UI test product；共享 scheme 仍引用不存在的 `ailoha-assistant-sharedTests.xctest`。 | hosted App target 进入受保护分支和 CI，scheme 引用真实 product，并覆盖账号、导航和一个跨进程恢复合同。 | iOS build / test infrastructure；Linear：未绑定 | `red`：project / scheme structural check；L 有未集成 hosted candidate |
| A11Y-001 | `R open` · `M open` · `L not targeted` | M 的 Lora / Manrope adapter 仍调用 `.custom(... fixedSize:)`；未发现 `@ScaledMetric` 或相对 text style 进入品牌字体入口。 | 品牌 typography 能按 text style 缩放；AX1–AX5、中英窄屏与截断检查覆盖关键流程。 | Design System typography；Linear：未绑定 | `red`：current adapter；`missing` current-main Dynamic Type runtime receipt |
| A11Y-002 | `R open` · `M open` · `L not targeted` | M Calendar 移动 / resize 仍依赖 LongPress + Drag；没有同等语义的 accessibility action 或替代编辑入口。 | VoiceOver 可命名选择、移动、调整时长并收到完成反馈；手势与替代入口修改同一 event authority。 | Calendar interaction + accessibility；Linear：未绑定 | `red`：current gesture surface；`missing` VoiceOver journey |
| A11Y-003 | `R open (old scan: 0 reads)` · `M open with partial coverage` · `L not targeted` | Release Swift 源扫描未发现 Reduce Motion 读取；M 有 2 处读取，但 Onboarding `LoopingVideoPlayerView`、`OnboardGuideVideoView` 与 Try It repeat-forever 呼吸仍不读取该偏好。 | 所有 active onboarding 自动媒体 / 重复动效有静态或低动 fallback；开启 Reduce Motion 仍能完成流程。 | Onboarding motion + Design System；Linear：未绑定 | `red`：R 无覆盖、M active consumers 仍缺；`missing` current journey receipt |
| DS-001 | `R open` · `M partial` · `L older baseline` | R 多源颜色常量；M 已有 JSON manifest → generated Swift，Widget 开始消费，但 `ALHColors` 仍手写 adaptive brand colors。 | App / Widget 语义色都来自一份 versioned manifest；legacy / raw consumer=0；Figma mapping 与视觉回归绑定同一 revision。 | Design System token authority + design owner；Linear：未绑定 | M `partial`：生成链存在；`missing` determinism + consumer ledger + App/Widget visual gate |
| PROD-001 | `R open` · `M open` · `L not targeted` | R/M Try It 仍由本地 `TryItChatMock` 与 overlay 演出联系人、Calendar 和岛效果；它是教学，不是首次真实价值证明。 | 产品明确标识 demo，并另有一条低风险真实闭环；或 Try It 本身接真实、可恢复能力且失败不伪装成功。 | Onboarding product + capability owner；Linear：未绑定 | `red`：current local constants；`missing` first-use real-loop E2E 与用户理解测试 |
| PROD-002 | `R open/unknown design` · `M open/unknown design` · `L not targeted` | M active reducer 从 name setup 开始，不渲染旧五选项；Coordinator 仍加载远端 / fallback questionnaire 并保留 step API，Figma 节点 successor 未确认。 | 具名 design owner 标记 current / dormant / superseded 与 successor；代码 active route、兼容 consumer 和删除条件一致。 | Onboarding product / design authority；Linear：未绑定 | `red`：runtime/design revision drift；`missing` design lifecycle decision |
| PERF-001 | `R risk` · `M runtime fact` · `L not targeted` | M Contact detail 仍约 36 个 published wrapper；editor draft 和四个 child 变化向 root 广播。Debug Simulator 中 12 次姓名输入稳定触发 12 次 Notes body、全量解析与日期分组；1k / 5k notes 每次无关投影中位数约 23.6 / 91.5ms。 | editor-local draft；Notes 只消费窄 input/projection；20 次无关输入的 Notes body/projection 为 0，note 事务与 full oracle 等价，真机 Release 达输入预算或 trace 推翻产品影响。 | Contact UI state + performance；Linear：未绑定 | `yellow`：页面 fan-out 已实测；生产 notes 分布、最低支持真机 Release 与 Instruments 仍 missing，不能称生产卡顿 |
| PERF-002 | `R risk` · `M risk` · `L not targeted` | M `events.didSet` 仍同步遍历全部事件、展开跨日 key、逐日排序并再次发布整份 `eventsByDate`；单事件更新也走这条全量路径。`getEventsForDate` 与缓存遍历读取一个 computed `cacheDateFormatter`，每次访问都会新建并配置 `DateFormatter`。运行影响尚未量化。 | 固定时区 / DST 与 1k / 10k 事件 fixture 下，全量 oracle 与增量结果一致；单 occurrence 只重算旧日 / 新日，series mutation、显示时区变化与权威窗口替换走 segment / full rebuild；日期 key formatter 不再按查询重建；同 SHA / Release configuration trace 达到预算。 | Calendar projection + performance；Linear：未绑定 | `missing`：全量重算与 formatter 重建是 current-main 代码事实，用户卡顿和预算超标未证明 |
| MIG-001 | `R open` · `M structurally closed` · `L historical branch` | R Router 仍按 flag 选 V1/V2；M 已删除 V1 和 debug flag，Router 只构造 V2。 | 结构 claim 的反证：main 再出现 V1、flag 或条件路由 consumer。后续上线 Gate：V2 长会话、崩溃与回滚基线通过，并进入 Release；这不会反过来改变“main 已结构关闭”的事实。 | Chat migration + Release owner；Linear：未绑定 | M `green-structural`；R `red`；M `missing` runtime / Release adoption proof |
| API-001 | `R open` · `M open` · `L not targeted` | R/M generated client、App façade 与 View / VM 的直接 `Api.*` consumer 并存，auth / error / retry / mock 边界随路径变化。 | UI 只依赖 feature protocol；transport gateway 统一 auth / error；直接 UI network consumer=0，有 contract tests。 | API boundary + each feature owner；Linear：未绑定 | `missing`：无 consumer guard 和跨 feature transport contract suite |
| OBS-001 | `R open` · `M open` · `L not targeted` | M task chat 已低基数化，但 share / contact / cluster 的 `trackName` 仍拼接实体 ID，并进入 event / screen observation。 | route event 名全部低基数；实体 ID 只进入显式私密字段；cardinality 与隐私测试覆盖新 route。 | Navigation observability + privacy；Linear：未绑定 | `red`：current route strings；`missing` cardinality/privacy guard |
| REL-001 | `R open` · `M open` · `L not targeted` | M transport / handler 已分层，但 reconnect 从 ARPC 回调 TaskLifecycle 统一重订阅；业务幂等与 topic owner 仍跨多个 service。 | 每个 feature repository 自有订阅 / 幂等；断线、重复、乱序和恢复 fixture 证明一次业务 transition。 | ARPC transport + Task lifecycle；Linear：未绑定 | `partial`：transport package tests 不覆盖 feature recovery；`missing` App-level reconnect matrix |
| REL-002 | `R unknown` · `M local contract open` · `L not targeted` | M active route 只渲染姓名页，只积累 `fullName`；bundled fallback 的 `personaType` / `painPoint` / `fullName` 都 required，submission 使用 loaded config version。OpenAPI 声明校验 required。 | DEV 新账号去敏 GET/POST 证明当前 name-only schema 一次 accepted；实现层用独立 name-only contract，且 required-field closure guard 对缺失 renderer/prefill/skip 的 fixture 会变红。 | Onboarding client contract + backend schema + product owner；Linear：未绑定 | `red`：current local config→client mismatch；`green`：现有 12 package tests + 2 guards 仍通过但不覆盖该合同；`missing` DEV/production response、5 screenshots、2 uncut videos |

## 推荐的执行顺序

### 1. 先补能裁决高风险问题的 verifier

不要先重构 20 个问题。先让三类承诺可以被自动反证：

1. A→logout→B，第一帧和迟到响应都不能出现 A 的 Contact / Calendar / Task；
2. credential 从 source 到持久日志 / 上传的任何路径都不能携带值或前缀；
3. reset / session rotate 后，旧 extension work 不能完成 network、EventKit 或 file write。

这些 verifier 既保护 Wave 0，也决定后续架构拆分是否安全。

### 2. 再收口已经发生一半的迁移

- Chat：main 不再做 V1 删除，改做 V2 runtime 和 Release adoption gate；
- Design Token：保留已建立的生成链，补 legacy consumer 和跨 target 视觉 gate；
- Package：验证 state / effect owner 与显式依赖，不用 Package 数量当完成度。

### 3. 性能与可访问性必须回到运行证据

`PERF-001` 的页面 fan-out 已从风险候选升级为 Debug Simulator 运行事实；`PERF-002` 的 Calendar 全量投影仍以源码/机制为主。Chat 已补 Debug 页面路径，多图也已有 Simulator 峰值机制收据；这些都不能写成生产卡顿、掉帧或 OOM。`A11Y-001/002/003` 有 current code 证据，但仍需要 Dynamic Type、VoiceOver、Reduce Motion 的可复验旅程。先固定设备、数据集、语言和系统设置，再谈改前改后收益。

## L0 / L1 / L2 方案层级

- **L0｜只补 freshness 和 verifier**：不动业务结构，先避免错排任务。适合当前所有未知是否超预算的性能项。
- **L1｜恢复单条不变量**：例如 account reset、低基数 route name、Onboarding motion fallback。每项可以独立测试和回滚。
- **L2｜修 owner 与 guardrail**：Task canonical authority、typed composition、feature-owned subscription、generated token source。只有 L1 反复暴露同根问题或迁移已经自然形成时才进入。

## 这张账本不解决什么

- 不声明任何人员是当前 owner；Linear 未绑定就是未知。
- 不把代码风险写成生产事故，也不把本地 PASS 写成已发布。
- 不代替真机性能、VoiceOver、APNs / extension 或真实账号验证。
- 不为 Talent Signal 视觉方向做选择；它继续停在 Gate 0。

## 内部阅读合同

从本页可以完成以下冷读任务：任选一条 P0/P1，指出它在哪条代码线成立、什么证据会让它失效、哪个系统角色应接手、现在缺哪一种 verifier。内部来源与 revision 检查已覆盖；团队产品 / iOS / 新成员各一人的真实冷读仍待执行。
