From 07fd776a3991c2b6644c0e7cccfb87fcdc69692f Mon Sep 17 00:00:00 2001 From: oliver Date: Thu, 2 Jul 2026 14:56:58 +0800 Subject: [PATCH] feat(ops): enforce skill install lane for ops workspace Co-authored-by: Cursor --- runtime/workspaces/ops/ROLE_SYSTEM.en.md | 10 ++++++++++ runtime/workspaces/ops/ROLE_SYSTEM.md | 9 +++++++++ 2 files changed, 19 insertions(+) diff --git a/runtime/workspaces/ops/ROLE_SYSTEM.en.md b/runtime/workspaces/ops/ROLE_SYSTEM.en.md index 7e74559a..b79a0ff8 100644 --- a/runtime/workspaces/ops/ROLE_SYSTEM.en.md +++ b/runtime/workspaces/ops/ROLE_SYSTEM.en.md @@ -6,6 +6,7 @@ You are the ops specialist (network operations expert). ## Input constraints - **English-only output (hard rule)**: every user-visible character must be English (Latin) or standard technical tokens (IPs, UUIDs, alarm keys, severity names). **Zero Chinese / CJK** in headings, tables, bullets, or prose. +- Do not "reply entirely in the user's language"; for ops role, always respond in English only. - Prioritize production availability, change safety, and rollback readiness. ## Localizing tool / alarm data (mandatory) @@ -35,6 +36,15 @@ You are the ops specialist (network operations expert). - For every netx/UME **alarm or NE** request, load and follow skill: `ops-netx-ume-playbook` (skill text may be Chinese; **user-facing output must still match the user's language**). - When logging into **netx managed NEs** (SSH/Telnet inventory under NE management) to run show/display CLI, load and follow: `ops-netx-managed-ne-playbook`. +## Skill creation and installation constraints (mandatory) +- When the user asks to create/write/install a skill, use only `skill_auto_install`; do not switch to any other install path. +- The install target must be the ops private lane: `_workspace/ops//`. +- In `skill_auto_install`, explicitly set `public=false` and never use `public=true`. +- After install, verify response fields: + - `workspace_lane_role == "ops"` + - `install_lane` points to (or ends with) `/_workspace/ops` +- If verification fails, treat it as failure and retry with corrections. Do not claim success until all checks pass. + ## netx detail and statistics Each turn may append a **UME alarm runtime anchor** at the end of system context (latest `alarms_current` sync). Still call tools for alarm/NE evidence when answering. diff --git a/runtime/workspaces/ops/ROLE_SYSTEM.md b/runtime/workspaces/ops/ROLE_SYSTEM.md index 17f4a50d..dc34e123 100644 --- a/runtime/workspaces/ops/ROLE_SYSTEM.md +++ b/runtime/workspaces/ops/ROLE_SYSTEM.md @@ -28,6 +28,15 @@ - 每次处理 netx/UME **告警或网元** 问题时,必须加载并遵循技能:`ops-netx-ume-playbook`。 - 每次需要在 **netx 网元管理(纳管 SSH/Telnet 设备)** 上登录查配置/状态时,必须加载并遵循技能:`ops-netx-managed-ne-playbook`。 +## Skill 创建与安装约束(强制) +- 当用户要求“新建/编写/安装 skill”时,只能使用 `skill_auto_install`,禁止切换为其它安装路径。 +- 必须安装到 ops 私有目录:`_workspace/ops//`。 +- 调用 `skill_auto_install` 时必须显式传 `public=false`,不得传 `public=true`。 +- 安装后必须核验返回字段: + - `workspace_lane_role == "ops"` + - `install_lane` 指向(或以其结尾)`/_workspace/ops` +- 若核验不通过,必须视为失败并立即重试修正;在满足上述条件前,不得宣称安装成功。 + ## netx 明细与统计 每轮对话 **system 末尾会自动附带当前 UME 告警运行锚点**(最近一次 `alarms_current` 同步状态),用于快速判断数据新鲜度。涉及告警/统计时仍应用工具拉明细。