feat: complete evidence restructuring worktree

This commit is contained in:
Codex
2026-08-26 11:39:02 +02:00
parent a54d4769dd
commit 38f02cfd08
56 changed files with 1981 additions and 1801 deletions
+30
View File
@@ -56,6 +56,34 @@ export function validateDeclarativePiConfig(raw: string): void {
assertDeclarativePiConfig(parsePiConfigJson(raw));
}
/** Return the selected provider's declarative apiKey value without knowing provider IDs in code. */
export function configuredPiProviderApiKey(
raw: string | undefined,
provider: string | undefined,
): string | undefined {
if (raw === undefined || provider === undefined) return undefined;
const parsed = parsePiConfigJson(raw);
if (!parsed || typeof parsed !== "object" || Array.isArray(parsed)) {
throw new PiManagedConfigError();
}
const providers = (parsed as { providers?: unknown }).providers;
if (!providers || typeof providers !== "object" || Array.isArray(providers)) {
throw new PiManagedConfigError();
}
const entry = Object.entries(providers as Record<string, unknown>)
.find(([id]) => id.trim().toLowerCase() === provider.trim().toLowerCase());
if (!entry) return undefined;
const config = entry[1];
if (!config || typeof config !== "object" || Array.isArray(config)) {
throw new PiManagedConfigError();
}
assertDeclarativePiConfig(config);
const apiKey = (config as { apiKey?: unknown }).apiKey;
if (apiKey === undefined) return undefined;
if (typeof apiKey !== "string" || apiKey.length === 0) throw new PiManagedConfigError();
return apiKey;
}
function configuredPiAgentDir(): string {
return resolve(process.env.PI_CODING_AGENT_DIR ?? join(homedir(), ".pi", "agent"));
}
@@ -102,6 +130,7 @@ export function readConfiguredPiAgentFile(
export interface PiRuntimeAgentSnapshot {
agentDir: string;
sessionDir: string;
models?: string;
cleanup: () => void;
}
@@ -152,6 +181,7 @@ export function createPiRuntimeAgentSnapshot(): PiRuntimeAgentSnapshot {
return {
agentDir: snapshotDir,
sessionDir: process.env.PI_CODING_AGENT_SESSION_DIR || join(sourceAgentDir, "sessions"),
models,
cleanup: () => {
if (cleaned) return;
cleaned = true;
+6
View File
@@ -9,8 +9,10 @@ import {
} from "../settings/settings-store.js";
import type { PiModel } from "./list-models.js";
import {
configuredPiProviderApiKey,
PI_MANAGED_CONFIG_ERROR_MESSAGE,
isPiManagedConfigError,
readConfiguredPiAgentFile,
} from "./managed-config.js";
import { createPiProviderSmoke, type PiProviderSmoke } from "./provider-smoke.js";
import { loadPiAuthProviders } from "./auth-providers.js";
@@ -119,6 +121,10 @@ export function createPiManagement(config: AppConfig, deps: PiManagementDeps): P
authProviders: loadPiAuthProviders(),
resolveCredentialValue: () => secretValue(config, "THT_MODEL_API_KEY"),
credentialFile: config.modelApiKeyFile,
configuredApiKey: configuredPiProviderApiKey(
readConfiguredPiAgentFile("models.json", true),
provider,
),
});
} catch {
return "missing";
+5 -1
View File
@@ -7,7 +7,10 @@ import { buildPiChildEnv, canonicalPiProvider } from "./provider-credentials.js"
import { loadPiAuthProviders } from "./auth-providers.js";
import { secretValue } from "../config/secret-bundle.js";
import { clearPrincipalEnvironment, principalEnvironment, type PrincipalContext } from "../auth/principal.js";
import { createPiRuntimeAgentSnapshot } from "./managed-config.js";
import {
configuredPiProviderApiKey,
createPiRuntimeAgentSnapshot,
} from "./managed-config.js";
export interface SessionRuntime {
rpc: RpcClient;
@@ -81,6 +84,7 @@ export class PiProcessManager {
authProviders: this.loadAuthProviders(agent.agentDir),
credentialValue: secretValue(this.cfg, "THT_MODEL_API_KEY"),
credentialFile: this.cfg.modelApiKeyFile,
configuredApiKey: configuredPiProviderApiKey(agent.models, provider),
additions: { THT_SESSION: sessionId, THT_AUTHOR: author },
});
env.PI_CODING_AGENT_DIR = agent.agentDir;
+23 -7
View File
@@ -42,9 +42,14 @@ const PROVIDER_KEY_ENV: Readonly<Record<string, string>> = {
const COMPOUND_PROVIDERS = new Set([
"amazon-bedrock", "azure-openai-responses", "cloudflare-ai-gateway", "cloudflare-workers-ai",
]);
const LOCAL_PROVIDERS = new Set([
"ollama", "lmstudio", "local", "aritmolab", "local-qwen", "faux",
]);
function configuredCredentialEnv(apiKey: string | undefined): string | null | undefined {
if (apiKey === undefined) return undefined;
if (!apiKey.startsWith("$")) return null;
const matched = /^\$(?:\{([A-Z][A-Z0-9_]*(?:API_KEY|TOKEN))\}|([A-Z][A-Z0-9_]*(?:API_KEY|TOKEN)))$/.exec(apiKey);
if (!matched) throw new Error("model provider credential is unavailable");
return matched[1] ?? matched[2];
}
export function canonicalPiProvider(provider: string | undefined): string | undefined {
const value = provider?.trim().toLowerCase();
@@ -106,6 +111,8 @@ export function buildPiChildEnv(opts: {
credentialFile?: string;
additions?: NodeJS.ProcessEnv;
credentialValue?: string;
/** Exact apiKey declaration from the selected provider in models.json. */
configuredApiKey?: string;
fsOps?: CredentialFsOps;
/**
* Providers pi can authenticate from its own auth store. For these, the single
@@ -147,17 +154,22 @@ export function buildPiChildEnv(opts: {
delete env.THT_SSL_CA_FILE;
for (const name of PI_0803_CREDENTIAL_ENV_NAMES) delete env[name];
const provider = canonicalPiProvider(opts.provider);
const configuredEnv = configuredCredentialEnv(opts.configuredApiKey);
if (configuredEnv) delete env[configuredEnv];
if (provider && COMPOUND_PROVIDERS.has(provider)) {
throw new Error(
"compound credential bundles are unsupported by THT_MODEL_API_KEY_FILE; "
+ "dedicated provider configuration is required",
);
}
if (provider && !LOCAL_PROVIDERS.has(provider)) {
if (provider) {
// pi self-authenticates this provider from its own auth store; injecting the
// single managed key here would force one provider's key onto another.
if (opts.authProviders?.has(provider)) return env;
const envName = PROVIDER_KEY_ENV[provider];
// A literal apiKey is entirely owned by models.json (commonly a non-secret
// placeholder for a local OpenAI-compatible endpoint) and needs no managed key.
if (configuredEnv === null) return env;
const envName = configuredEnv ?? PROVIDER_KEY_ENV[provider];
if (!envName || (!opts.credentialFile && opts.credentialValue === undefined)) {
throw new Error("model provider credential is unavailable");
}
@@ -169,7 +181,7 @@ export function buildPiChildEnv(opts: {
}
else if (opts.credentialFile) env[envName] = readCredential(opts.credentialFile, opts.fsOps ?? realFs);
else throw new Error("model provider credential is unavailable");
} else if (opts.credentialFile && !provider) {
} else if (opts.credentialFile) {
throw new Error("model provider credential is unavailable");
}
return env;
@@ -181,11 +193,14 @@ export function piProviderCredentialStatus(opts: {
credentialFile?: string;
resolveCredentialValue?: () => string | undefined;
authProviders?: ReadonlySet<string>;
configuredApiKey?: string;
fsOps?: CredentialFsOps;
}): PiCredentialStatus {
const provider = canonicalPiProvider(opts.provider);
if (!provider || LOCAL_PROVIDERS.has(provider)) return "missing";
if (!provider) return "missing";
if (opts.authProviders?.has(provider)) return "present";
const configuredEnv = configuredCredentialEnv(opts.configuredApiKey);
if (configuredEnv === null) return "missing";
try {
buildPiChildEnv({
ambient: {},
@@ -193,6 +208,7 @@ export function piProviderCredentialStatus(opts: {
credentialFile: opts.credentialFile,
credentialValue: opts.resolveCredentialValue?.(),
authProviders: opts.authProviders,
configuredApiKey: opts.configuredApiKey,
fsOps: opts.fsOps,
});
return "present";
+5 -3
View File
@@ -11,6 +11,7 @@ import { buildPiChildEnv, canonicalPiProvider } from "./provider-credentials.js"
import type { PiReasoning } from "./management.js";
import {
PiManagedConfigError,
configuredPiProviderApiKey,
isPiManagedConfigError,
parsePiConfigJson,
readConfiguredPiAgentFile,
@@ -65,11 +66,15 @@ export function createPiProviderSmoke(
const canonicalProvider = canonicalPiProvider(provider);
if (!canonicalProvider || timeoutMs <= 0) throw providerFailure();
const configuredAuthProviders = authProviders();
const configuredModels = options.readModelsStore
? options.readModelsStore()
: readConfiguredPiAgentFile("models.json", true);
const env = buildPiChildEnv({
provider: canonicalProvider,
authProviders: configuredAuthProviders,
credentialValue: secretValue(config, "THT_MODEL_API_KEY"),
credentialFile: config.modelApiKeyFile,
configuredApiKey: configuredPiProviderApiKey(configuredModels, canonicalProvider),
});
clearPrincipalEnvironment(env);
delete env.THT_DATA_ROOT;
@@ -90,9 +95,6 @@ export function createPiProviderSmoke(
);
writeDeclarativeAgentConfig(join(isolatedAgentDir, "auth.json"), authStore);
}
const configuredModels = options.readModelsStore
? options.readModelsStore()
: readConfiguredPiAgentFile("models.json", true);
if (configuredModels !== undefined) {
const modelsStore = selectedProviderModelsStore(
configuredModels,