From 2ebf00d6d457600f30f1a5cb2430ee0dc503877e Mon Sep 17 00:00:00 2001 From: Joakim Persson Date: Sat, 22 Aug 2026 21:19:48 +0200 Subject: [PATCH] v1.8.4: the om fix lands upstream, pi-atelier v0.8.2, todo edit Headline: pi-observational-memory 37986b6 -> ce9fc98. The ambient-credential gate fix (6f694e6 + 699ccc7) was merged upstream as PR #52 on 2026-08-22, closing issue #51, so this release picks it up through the ordinary PI_OBSMEM_REF=master path with nothing carried locally. Every image up to and including v1.8.3 silently recorded zero observations on a Bedrock host using ambient AWS credentials; from this one on, /opt is the fix and the settings.json packages[] workaround should be deleted (verify against /etc/pi-devbox/build-manifest.json first). npm still ships the broken 3.0.4, which does not matter here because the image clones the ref instead. Pin bump: PI_ATELIER_REF / PI_ATELIER_VERSION v0.8.1 -> v0.8.2, audited per the floor note above the ARG. The only version in between is 0.8.2 itself and both its entries are Workspace-Pulse-internal (inspection coalescing and serialization; fresh inspection guaranteed at Turn end, retired sessions can no longer publish stale results). Nothing touches pi's private TUI renderer, which is the coupling behind the 0.6.0/0.7.0-under-pi-0.84 startup hang, and pi is unchanged at 0.84.2 - so the bump stays outside that risk class. Also baked by this build, no pin needed: pi-extensions 98eb07b -> 2022887 (the todo edit action), pi-fork 4a09af4 -> f1ff808, pi-studio 0.9.44 -> v0.9.48, mempalace-toolkit b609cf5 -> fd8b15f (docs only - the pi-session false-success guard was already baked in v1.8.3, confirmed by ancestry), aws-cli 2.36.24 -> 2.36.29 and the other *_VERSION=latest tools. README: the pin table also said mempalace 3.6.0, stale since v1.8.3 bumped it to 3.7.1. Fixed in passing. Unchanged and verified current: pi 0.84.2 (npm latest, published 2026-08-14), MEMPALACE_VERSION 3.7.1 (PyPI latest), pi-toolkit 0e1369e. --- CHANGELOG.md | 123 ++++++++++++++++++++++++++++++++++++--------- Dockerfile.variant | 4 +- README.md | 4 +- 3 files changed, 104 insertions(+), 27 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 5bb3384..2f63203 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -11,25 +11,93 @@ Pre-v1.0.0 tags followed the pi npm version (`v{pi_version}[letter]`). --- -## Unreleased +## v1.8.4 — 2026-08-22 -Patch-shaped so far. Headline: **the bundled `todo` extension can finally edit -an item.** Nothing in the image itself changed — `pi-extensions` is fetched at -`PI_EXTENSIONS_REF=main`, so the next build bakes this with no pin to bump. -Recorded here because `/opt/pi-extensions` is baked, so "which behaviour does -this image have" is an image question even when the commit lives elsewhere. +Patch release, and the one that ends an eight-week bug: **the baked +`pi-observational-memory` finally records observations on a Bedrock host that +uses ambient AWS credentials.** The fix is ours, but it is no longer a patch — +upstream merged it, so this release picks it up through the ordinary +`PI_OBSMEM_REF=master` path with no local carry. Also **bumps pi-atelier +`v0.8.1` → `v0.8.2`** (audited below) and bakes the `todo` extension's new +`edit` action. `pi` stays `0.84.2` (still the npm latest, published +2026-08-14) and `MEMPALACE_VERSION` stays `3.7.1` (still the PyPI latest). + +### Fixed + +- **om consolidation on request-time-signed providers — upstream, not patched + (`pi-observational-memory` `37986b6` → `ce9fc98`).** Under `37986b6`, om's + pre-flight gate treated "pi exposes no `apiKey` and no auth header" as + *unauthenticated* and skipped every consolidation. On Bedrock with ambient + AWS credentials that is the normal case — pi signs SigV4 at request time — + so om recorded **nothing for eight weeks** with no error, no cost and no log + line. Every pi-devbox image up to and including v1.8.3 has that behaviour. + + Two commits, both authored here and now upstream verbatim: `6f694e6` fixes + the gate itself (it must not require a credential *payload*), and `699ccc7` + adds the second half of pi's own rule — `hasConfiguredAuth` reads an + availability snapshot that stays empty when the startup availability pass was + skipped/aborted/failed, so on the otherwise-fatal path om now asks pi to + re-check the credential live (refresh scoped to the provider, network-free), + rate-limited 60 s per provider, bounded by a raced timeout, logged as + `resolve.availability_recheck`. Filed as upstream issue #51, merged as PR #52 + (`ce9fc98`, 2026-08-22T04:46:18Z), which also carries PR #49's `env`/`baseUrl` + forwarding merged four minutes earlier; the maintainer resolved the textual + conflict between them keeping both behaviours. Verified on `ce9fc98` here: + `tsc --noEmit` clean, `vitest` 257 tests / 27 files green. + + **Note for anyone carrying the local workaround:** the interim fix was a + `packages[]` override in `~/.pi/agent/settings.json` pointing pi at a patched + clone outside the image. From this release on, delete the override — the + baked `/opt/pi-observational-memory` has the fix. Confirm with + `/etc/pi-devbox/build-manifest.json` → `components.pi-observational-memory` + before removing it. The npm-published `pi-observational-memory` is **still + `3.0.4` and still broken**; the image does not use npm for this component, so + the release cadence there is irrelevant to us. + +### Changed + +- **`PI_ATELIER_REF` / `PI_ATELIER_VERSION` `v0.8.1` → `v0.8.2`, audited per the + floor note above the ARG.** Only one version sits between old and new and its + changelog is two lines, both Workspace-Pulse-internal: inspection requests are + now coalesced and serialized so short Turns avoid duplicate Git work and + overlapping inspections cannot run concurrently, and live tool-driven Pulse + updates are preserved while a fresh inspection is guaranteed at Turn end and + retired sessions can no longer publish stale results. **Nothing touches pi's + private TUI renderer**, which is the coupling that produced the + 0.6.0/0.7.0-under-pi-0.84 startup hang, and `pi` is unchanged at `0.84.2`, so + this bump does not re-enter that risk class. Both the seam and the pin floor + (never pair pi-atelier < 0.7.1 with pi >= 0.84) are unaffected. +- **`pi-studio` `65995fe` (0.9.44) → `v0.9.48`** — 14 commits, four releases. + Studio-side only (`INSTALL_STUDIO=false` by default, so this lands in the + studio variant): open Studio in Muxy's browser, local PDF preview actions, + previews survive Pandoc probe failures, legacy LaTeX styles tolerated in + Pandoc previews, native dialogs replaced in embedded browsers, and file-copy + import fixes with an explicit fallback. CI resolves the highest semver tag, + not `main`, so this is `v0.9.48` exactly. +- **`pi-fork` `4a09af4` → `f1ff808`** — one commit, "Add fork runtime + awareness" (2026-08-19). +- **`mempalace-toolkit` `b609cf5` → `fd8b15f`** — two commits, **docs only** + (backup/recovery + units; the convos-miner mtime correction finished). The + `fix(pi-session)` false-success guard was already baked in v1.8.3 — checked + by ancestry (`git merge-base --is-ancestor 6e1f4f3 b609cf5`), not by reading + the log, because a commit's *date* does not tell you which side of a pin it + fell on. +- **`aws-cli` 2.36.24 → 2.36.29** and the other `*_VERSION=latest` tools + (bat/eza/fzf/gitleaks/nvim/micro/zoxide/yq/typst/tealdeer/agent-browser/ + playwright/gosu/git-lfs/uv) refresh implicitly, as designed. +- `pi-toolkit` unchanged (`0e1369e`, local `main` == baked). ### Added -- **`todo` extension: an `edit` action** (`pi-extensions` `2022887`). The tool is - a verbatim vendored copy of pi's own `examples/extensions/todo.ts`, which - offers list/add/toggle/clear and no way to change an item's text. On a - long-lived list that forces either a "patch" item describing a *different* - item, or clear-and-re-add of everything — both hit for real on 2026-08-17 while - tracking a 17-item fleet plan, which ended up with `#18` correcting `#17`. - `edit` takes `id` + `text` and keeps the id and the done status; `nextId` is - untouched. Id stability is the point, because ids are the only handle a palace - snapshot of a plan can refer to. +- **`todo` extension: an `edit` action** (`pi-extensions` `98eb07b` → + `2022887`). The tool is a verbatim vendored copy of pi's own + `examples/extensions/todo.ts`, which offers list/add/toggle/clear and no way + to change an item's text. On a long-lived list that forces either a "patch" + item describing a *different* item, or clear-and-re-add of everything — both + hit for real on 2026-08-17 while tracking a 17-item fleet plan, which ended up + with `#18` correcting `#17`. `edit` takes `id` + `text` and keeps the id and + the done status; `nextId` is untouched. Id stability is the point, because ids + are the only handle a palace snapshot of a plan can refer to. - Verified live in-container before committing, by repointing `~/.pi/agent/extensions/todo.ts` at a working copy for one session (unknown id and missing text both error as intended; editing a completed item kept its @@ -37,18 +105,27 @@ this image have" is an image question even when the commit lives elsewhere. ### Notes -- **No pi-atelier change was needed.** Its `tool_result` hook only checks that - `details.todos` is a well-shaped array and ignores the action string, so the - new action flows through its normalizer and sidebar untouched. Worth knowing - while reading agent transcripts: that hook *replaces* todo tool output with - `N/M done · see sidebar` whenever the sidebar todo panel is visible - (`showSidebarTodos`), so an agent sees only the counter and not the item text - — upstream's `list` otherwise returns every item. That is a deliberate - context saving, not a tool limitation. +- **No pi-atelier change was needed for the `todo` action.** Its `tool_result` + hook only checks that `details.todos` is a well-shaped array and ignores the + action string, so the new action flows through its normalizer and sidebar + untouched. Worth knowing while reading agent transcripts: that hook + *replaces* todo tool output with `N/M done · see sidebar` whenever the sidebar + todo panel is visible (`showSidebarTodos`), so an agent sees only the counter + and not the item text — upstream's `list` otherwise returns every item. That + is a deliberate context saving, not a tool limitation. - The vendored copy now carries a numbered **LOCAL DELTAS** list in its header (the earlier `ctx.mode !== "tui"` → `!ctx.hasUI` API fix, and this action), so reconciling a future upstream version stays mechanical rather than archaeological. +- **A second om fix is NOT in this image and will not be.** Upstream PR #24 + ("advance coverage watermark when observer records nothing", head + `joakimp:fix/observer-empty-coverage-watermark` `b577b29`) is open but + design-rejected by the maintainer on 2026-07-03: an empty observer verdict is + usually a *technical* failure, so advancing the watermark would leave a gap in + the observed session, and in the genuinely-nothing-to-observe case the next + observer simply gets more context. So the observer can still re-fire on a + growing span after an empty verdict — that is upstream's intended behaviour, + not an image defect. Do not "fix" it by rebasing that branch. --- diff --git a/Dockerfile.variant b/Dockerfile.variant index 5fafa5a..74ee775 100644 --- a/Dockerfile.variant +++ b/Dockerfile.variant @@ -92,9 +92,9 @@ ARG PI_OBSMEM_REF=master # the /opt checkout. Adding an install here would be a no-op that only costs # build time. ARG PI_ATELIER_REPO=https://github.com/michaelmjhhhh/pi-atelier.git -ARG PI_ATELIER_REF=v0.8.1 +ARG PI_ATELIER_REF=v0.8.2 # Human-readable tag PI_ATELIER_REF was resolved from; recorded as a label. -ARG PI_ATELIER_VERSION=v0.8.1 +ARG PI_ATELIER_VERSION=v0.8.2 RUN set -e && \ # git_fetch_ref: clone-equivalent helper that accepts EITHER a branch name diff --git a/README.md b/README.md index 458bc44..379a883 100644 --- a/README.md +++ b/README.md @@ -990,8 +990,8 @@ resolved to `latest` at build time: | Component | Pin | Where | |---|---|---| | pi | `0.84.2` | `ARG PI_VERSION` — `Dockerfile.variant` | -| pi-atelier | `v0.8.1` | `ARG PI_ATELIER_REF` — `Dockerfile.variant` | -| mempalace | `3.6.0` | `ARG MEMPALACE_VERSION` — `Dockerfile.base` | +| pi-atelier | `v0.8.2` | `ARG PI_ATELIER_REF` — `Dockerfile.variant` | +| mempalace | `3.7.1` | `ARG MEMPALACE_VERSION` — `Dockerfile.base` | The objective is **not** to freeze versions. Bumping is routine — usually one line plus a changelog note. The objective is that adopting a new upstream