Commit Graph
49 Commits
Author SHA1 Message Date
Codex f52bf22e05 feat: establish unified administration and model context baseline 2026-09-12 18:03:15 +02:00
Codex a6a5bf2036 fix: harden model catalog projections 2026-09-02 19:25:01 +02:00
Codex 7b7927bfe5 feat: unify installation model catalog 2026-09-02 18:45:33 +02:00
Codex 38f02cfd08 feat: complete evidence restructuring worktree 2026-08-26 11:39:02 +02:00
marcopan db375298d0 fix(test): hermetically exercise auth workflows 2026-08-25 18:27:41 +02:00
marcopan 7efaec434f fix: release Pi snapshots on failed initialization 2026-08-05 16:59:49 +02:00
marcopan bd798b1c96 fix: render registry workspaces for harness 2026-08-05 16:03:45 +02:00
marcopan fd1fd2f802 fix: refresh Pi credential readiness 2026-08-05 06:30:25 +02:00
marcopan 7df21b5f21 fix: harden Pi management readiness 2026-08-05 06:20:25 +02:00
marcopan 4422568f61 fix: bind pi runtime config at spawn 2026-08-05 05:23:58 +02:00
marcopan 2703864572 fix: reject executable pi configuration 2026-08-05 04:49:19 +02:00
marcopan 6b828288e3 fix: preserve custom provider smoke config 2026-08-05 01:35:42 +02:00
marcopan 174f854b96 fix: isolate pi provider smoke 2026-08-05 01:19:46 +02:00
marcopan 55926c75f8 fix: harden pi management verification 2026-08-05 01:00:13 +02:00
marcopan d6b4a08a02 feat: expose safe pi management api 2026-08-05 00:31:44 +02:00
marcopan 00761ae2ca fix: enforce one Pi runtime per user 2026-07-21 16:13:17 +02:00
marcopan 2ff63d371f feat: harden workflow gates and expose token usage 2026-07-21 12:14:26 +02:00
marcopan 0cf09777f2 Fix session resume and PSD container configuration 2026-07-20 20:22:47 +02:00
marcopanandClaude Fable 5 f772ef9dca fix(backend): robustness pass — spawn leak, timeouts, workspace fail-loud, 409 order, respond guard
Audit findings 4.1-4.6.

- spawnFor: a rejected configure/start no longer leaks a registered runtime
  with a live Pi child (identity-checked teardown + rethrow); every later
  start used to hit "session runtime already active".
- ThtRunner.run: default 60s timeout on every tht child (SIGKILL backstop),
  120s for DWH-touching calls (sql preview/export, search pack); a dropped
  VPN mid-call no longer wedges the HTTP request forever.
- configArg: a NAMED workspace whose yaml is missing now throws instead of
  silently falling back to the default config (operations were silently
  targeting the wrong workspace).
- resume: the finalized/archived 409 is evaluated BEFORE the alreadyActive
  fast-path — the manifest is the truth even with a lingering runtime.
- ollamaEnsure: exit-0 with non-JSON stdout is a failed check, not ok:true.
- SessionBridge.respond: only the response matching the pending descriptor
  is forwarded to Pi; stale/duplicate submissions return 409 instead of
  being sent with the current gate's RPC id.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20 01:37:20 +02:00
marcopanandClaude Opus 4.6 6ee5bda7f0 feat: gate decision-type validation, force-advance, and frontend fixes
Gate (tht-gate.js):
- Pre-validate decision types against workflow.yaml before showing reviewer widget
- Reject decisions emitted by later phases (min-phase check)
- Copy top-level `kind` into artifact when model forgets it (prevents loop)
- Force-advance on reviewer_decide/schema_linking when advance:true — skip
  redundant reviewer_confirm gate

Backend:
- Emit agent_end on clean Pi exit (code 0 + bridge idle) instead of marking failed

Frontend:
- Strip <think> tags from transcript and activity panel
- Fix mermaid render with offscreen container + cleanup
- Graceful mermaid error: show source code instead of red error, fall back to table

Workflow:
- F2 now emits table_promoted and table_excluded (early schema linking decisions)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-07-19 14:14:44 +02:00
marcopanandClaude Opus 4.8 c5fd03ed84 feat(backend): let pi self-authenticate providers from its own auth store
The backend injects a single managed model key (THT_MODEL_API_KEY[_FILE]) as
the selected provider's env var, but that key belongs to one provider — so
selecting a second cloud provider (e.g. DeepSeek while the managed key is zai's)
forced the wrong key onto it and failed auth. This is why the model could not be
switched to DeepSeek.

When the selected provider is present in pi's own auth store
(~/.pi/agent/auth.json), skip injection and let pi resolve that provider's key
itself. Deployments without an auth store (containers) yield an empty set, so the
managed-key injection stays authoritative and fail-fast there. authProviders is
injectable into PiProcessManager for deterministic tests.

Verified live: GLM 5.2, DeepSeek V4 Flash, and aritmolab Qwen3.6 all operate through the ThothII model selector.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-17 18:26:18 +02:00
User b454fb478b fix(backend): harden principal child isolation 2026-07-16 18:38:40 +02:00
User 458eb13c89 feat(backend): enforce user-owned sessions 2026-07-16 18:32:52 +02:00
User 6747f6f8a0 fix: serialize session lifecycle transitions 2026-07-15 01:37:42 +02:00
User 08b1f4909e fix: make session resume atomic across restarts 2026-07-15 00:42:35 +02:00
User df1e7dea9c fix(resume): recover cleanly after Pi exits 2026-07-14 21:35:50 +02:00
User aba8666f16 fix(backend): track Pi turn lifecycle 2026-07-14 20:39:45 +02:00
User 0cf86e3540 fix(backend): allow configured local Qwen provider 2026-07-14 18:44:12 +02:00
User c463de8da2 fix(backend): scope Pi model listing to enabled models 2026-07-14 18:33:15 +02:00
User 1b78f72b64 feat(backend): read Pi enabled model scope 2026-07-14 18:27:55 +02:00
User 6dbf93fff9 feat: harden runtime readiness and session workflow 2026-07-14 10:27:25 +02:00
User 34f1fa271f fix(bridge): forward tool/lifecycle events so user sees agent progress
The SessionBridge only forwarded text_delta and system_event types.
All tool_execution_*, agent_start, and turn_end events from the Pi
process were silently dropped, so the user saw a blank session even
though the agent was actively running (calling tools, querying the DB).

Forward:
- tool_execution_start/end as info events (visible in stepMessages)
- agent_start, turn_end as system_event (lifecycle tracking)

Also: log Pi stderr instead of draining silently, for debugging.
2026-07-13 00:22:54 +02:00
marcopan 7628eaa579 fix(docker): run real questions through trusted Pi gate 2026-07-12 19:20:10 +02:00
marcopan 8518a73685 fix(security): scrub raw deployment secret values 2026-07-12 11:34:32 +02:00
marcopan d500563963 fix(security): scrub deployment secrets from Pi child 2026-07-12 11:33:13 +02:00
marcopan 5fe74612fb feat(config): load one validated secret bundle 2026-07-12 11:06:19 +02:00
marcopan 2302286ea1 fix(backend): reject compound provider credentials 2026-07-12 08:10:47 +02:00
marcopan f064daef09 fix(backend): harden provider credential isolation 2026-07-12 08:05:51 +02:00
marcopan e40a9d9a56 fix(backend): inject provider credentials from file 2026-07-12 07:53:22 +02:00
marcopan 3ac0623247 fix(backend): make data root config authoritative 2026-07-11 21:35:54 +02:00
marcopan c6c00c336a feat(backend): support container runtime paths 2026-07-11 21:32:33 +02:00
marcopanandClaude Fable 5 2410f01b34 fix(bridge): forward Pi agent_end so the spinner stops at workflow completion
The FE derived 'working' purely as activeSession && !pendingWidget, so the
final workflow turn — the only one that ends without a follow-up gate —
left the spinner on forever (observed live: 21592s after F8 approve).

- SessionBridge maps Pi's agent_end -> SSE system_event {event: agent_end}
- PiProcessManager notifies the client (info error + synthetic agent_end)
  when the child dies unexpectedly; expected teardowns stay silent
- sessionStore tracks agentActive (on: user entry/text_delta/ui_request,
  off: agent_end); AppShell working now requires it; resume sets it
  optimistically

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-07 10:14:43 +02:00
marcopanandClaude Opus 4.8 37d40d6680 fix(backend): drop pi --approve flag (removed in pi 0.73 @mariozechner rebrand)
pi 0.73 rpc mode is headless and runs tools without an approval gate; the
removed --approve flag made pi exit with 'Unknown option: --approve', breaking
every session spawn. Spawn args are now just --mode rpc. +regression test.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-29 21:03:48 +02:00
marcopan 790ac71284 feat(backend): spawnFor new/resume prompt mode; resume sends /riprendi-sessione 2026-06-29 12:38:26 +02:00
marcopanandClaude Opus 4.8 c4b599ec00 feat(backend): ephemeral Pi model lister (get_available_models) with TTL cache
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-28 16:04:33 +02:00
marcopanandClaude Sonnet 4.6 c63b2bd126 fix(backend): idempotent spawnFor + identity-checked exit + unified SSE re-emit shape
- spawnFor now tears down any existing runtime for the same session id before
  the cap check, so resume/respawn neither leaks the old child nor falsely hits
  maxPiProcesses
- exit handler is identity-checked (captures rt) so a stale child's late exit
  cannot evict a newer runtime
- SSE pending re-emit now sends the full ClientEvent shape
  { type: "ui_request", ui_request } to match hub.publish live events
- tests: same-id respawn replaces runtime (count 1); old child exit does not
  evict new runtime; sse-hub re-emit asserts unified shape

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-27 21:53:12 +02:00
marcopanandClaude Sonnet 4.6 b16c94e30b feat(backend): resume + venv PATH + end-to-end F1 smoke (fake-pi-rpc)
- Add PiProcessManager.resume(sessionId, tht): reads provider/model/thinking
  from tht.sessionShow() and calls spawnFor with those values
- Add POST /sessions/:id/resume route: calls mgr.resume then re-wires
  bridge.onClientEvent → hub.publish
- Confirm venv PATH already present in real spawn (no change needed)
- Add e2e test: POST /sessions → SSE receives ui_request via pendingWidget
  re-emit → POST /sessions/s1/response → 204 (all over real HTTP against
  fake-pi-rpc)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-27 21:37:24 +02:00
marcopanandClaude Opus 4.8 f4c6126270 refactor(backend): drop dead SpawnFn alias + test Pi exit-handler cleanup
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-27 21:09:49 +02:00
marcopanandClaude Sonnet 4.6 de7200f7dd feat(backend): PiProcessManager (one Pi per session, cap, set_model/thinking)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-27 21:05:03 +02:00