For AI agents: the complete documentation index is available at https://a3s-lab.github.io/Use/llms.txt, the full documentation bundle is available at https://a3s-lab.github.io/Use/llms-full.txt, and this page is available as Markdown at https://a3s-lab.github.io/Use/guide/flow.md.
  • 简体中文
  • A3S Flow 工作流

    认知包 Flow 是由 A3S Flow 驱动的一等工作流贡献。它与包共享版本、Registry provenance、依赖 lock、generation 和原子安装/卸载边界。

    系统只有一个工作流引擎:

    包内源码 / Code flow.json 设计文档
                     ↓ 类型化适配器
                  A3S Flow
                     ↓
            本地 Code 宿主 / 远程 OS 目标

    a3s-flow 负责持久执行、事件历史、重放、调度、存储与 observation。A3S Use 负责分发、完整性、SemVer 依赖解析、能力依赖和包生命周期。A3S Code 提供产品发现与注入式 runtime host。

    Manifest 合约

    schema v3 在 a3s-use-extension.acl 中声明命名 Flow:

    flow "review" {
      engine         = "a3s-flow"
      runtime        = "native-ts"
      source         = "flows/review.ts"
      export         = "run"
      requires_tool  = ["convert"]
      requires_mcp   = ["library"]
      requires_okf   = ["domain-knowledge"]
      optional       = false
    }
    
    skill "review" {
      path          = "skills/review/SKILL.md"
      requires_flow = ["review"]
      optional      = false
    }
    
    ui "review" {
      entry     = "ui/review/index.html"
      skill     = "review"
      bind_flow = ["review"]
      optional  = false
    }

    engine = "a3s-flow" 是固定值。native-ts 是首个已准入的 runtime adapter,不是另一个工作流引擎。源码必须是有界 UTF-8 TypeScript 文件,export 必须是可移植的 TypeScript identifier。

    依赖与生命周期顺序

    Flow 不拥有 ambient permission ceiling。它只能使用显式声明的 Tool、MCP 与 OKF 能力;每种能力都由其 owner host 授权和观察。

    Tool / MCP / OKF
            ↓
          Flow
            ↓
          Skill
            ↓
            UI

    安装按正向顺序准备依赖图,并一次发布一个包 generation。Disable 先隐藏 generation,再停止它。Uninstall 排空已接受工作后反向移除表面。必需 Flow 缺失或损坏时,它依赖的 Skill/UI 与新包 generation 都不会发布。

    flow.json 的含义

    A3S Code 把 flow.json 作为 Workflow-as-a-Service 的可见设计文档。它不是第二种包格式或执行引擎。可执行设计携带严格、无路径的 installedFlow 引用,将其映射到一个精确的已安装包 generation:

    • Native TypeScript 是 A3S Flow 执行适配器。
    • flow.json 是可视化设计/部署文档。
    • A3S Code 是本地编辑器与宿主。
    • A3S OS 是远程部署目标。

    任何 adapter 都不能创建并行的 package receipt、dependency graph 或 lifecycle journal。

    当前实现边界

    A3S Use 已实现 manifest 准入、精确源码证据、签名 catalog 闭包、包生命周期顺序、reconciler owner、host-capabilities v6、managed scope v2、manager tools v5、类型化 capability projection 与具体的 A3sFlowLifecycleHost。该 host 委托真实 a3s-flow Native TypeScript preflight,持久化精确 generation 的源码/编译产物 binding,并在 observation 时重新检查两者。未注入 a3s-flow host adapter 时,standalone engine 会在变更前拒绝包含必需 Flow 的包。

    非激活的 Control Store qualification 现在也包含 committed-authority Flow owner。它通过 verified Artifact Store lease 读取有界源码快照,在 owner 自己的 workspace 中以 durable no-clobber 内容寻址方式持久化副本,然后只把该副本交给类型化的 a3s-flow Native TypeScript preflight。Artifact Store 的 package root 不会穿过 owner 边界。编译器/cache 路径只是运行时配置,不是 desired-state authority;源码替换或 preflight 失败不会写入 Control observation,Artifact Store 争用则沿同一个 effect key 安全延迟。Stop/remove 仍是与路径无关的 receipt。Runtime 与 dispatcher cutover gate 完成前,该 owner 不接入生产组合。

    有效源码只是必要条件,不是 readiness 充分证据。只有类型化 A3S Flow host 对同一准入 generation 返回成功 preflight 后,Flow 才能离开 pending 并进入已发布 catalog;源码损坏会覆盖过期的正向 host observation。

    A3S Code 通过共享 package lifecycle factory 注入该具体 host。CLI 与 TUI 解析同一个严格 flow.json 身份。每次新 run 前,Code 都重新检查当前包源码的 regular-file 属性、包内包含关系、大小、UTF-8 与 SHA-256,只暂存已验证字节,并在创建 binding 或 event 前完成 Native TypeScript preflight。两个入口无需 OS 登录,共用由跨进程锁保护的 .a3s/flow-runtime/ event store。

    CLI 与 TUI 是交互式本地执行表面。当前实现提供单节点 crash/restart durability;分布式 worker placement、suspended wait/retry/hook 自动恢复、生产 retention/garbage collection 与完整 real-process 跨平台覆盖仍是 release gate。路线图 会明确跟踪这些门禁。