fix: use Pi user auth and handle startup failures
This commit is contained in:
+23
-1
@@ -1,8 +1,30 @@
|
||||
# ThothII — Project State
|
||||
|
||||
> Starting-point snapshot for new sessions. Last updated: 2026-07-15 (central live log and compact CTE density live).
|
||||
> Starting-point snapshot for new sessions. Last updated: 2026-07-21 (local Pi user-auth wiring and startup error handling live).
|
||||
> Point a fresh session here ("read PROJECT_STATE.md") before substantial work.
|
||||
|
||||
## Local Pi user auth + startup failure handling — LIVE 2026-07-21
|
||||
|
||||
- The PSD Docker profile now bind-mounts the configurable host `PI_AUTH_FILE` read-only at
|
||||
`/home/thoth/.pi/agent/auth.json`; on this Mac it resolves to the real user profile
|
||||
`/Users/mp/.pi/agent/auth.json`. The container keeps its correct Linux identity
|
||||
`HOME=/home/thoth` while Pi sees the user's independent `deepseek` and `zai` credentials.
|
||||
- `deploy/pi/settings.json` is the non-secret model policy and exposes, in order,
|
||||
`zai/glm-5.2`, `deepseek/deepseek-v4-flash`, `deepseek/deepseek-v4-pro`, and
|
||||
`aritmolab/qwen3.6-35b-a3b`. The core image is aligned to Pi 0.80.3.
|
||||
- New-session creation now validates the saved provider/model against Pi before persistence;
|
||||
unavailable selections return sanitized `503 model_unavailable` without creating a manifest.
|
||||
A synchronous runtime-construction failure after persistence marks that session `failed` and
|
||||
returns the fixed startup-recovery message instead of leaving an ambiguous `open` session.
|
||||
- Verification: backend 235/235, TypeScript clean, dedicated Compose auth/model contract green
|
||||
with a demonstrated RED→GREEN cycle. Rebuilt core image
|
||||
`sha256:a8b4dd9f016c2335e4da897073bc6d5bdf1e8ce9b60dcfcca171b6677f563228`
|
||||
is healthy; live `/models` returned all four models; a real `deepseek-v4-pro` smoke reached its
|
||||
first reviewer gate, deleted only its own session, and restored the exact prior settings.
|
||||
- Deleted the three explicitly approved incomplete DeepSeek attempts:
|
||||
`a390c8b8-0a91-4a37-967b-ce7ff9be9797`, `a2f974b2-4c48-4967-b4b6-afdbc2b2d541`, and
|
||||
`f66e1959-3c71-4b10-8aa1-606992046b7e` (API delete 204, subsequent lookup 404 for each).
|
||||
|
||||
## User-owned sessions cutover — prepared, manual gate pending (2026-07-16)
|
||||
|
||||
- **Target contract:** the public server runs `AUTH_MODE=upstream` with Task 4 portal identity
|
||||
|
||||
Reference in New Issue
Block a user