v1.7.0: bundle pi-atelier at a pinned tag; pin pi to an audited 0.84.1
Publish Docker Image / resolve-versions (push) Successful in 9s
Lint / actionlint (push) Successful in 15s
Lint / hadolint (push) Successful in 13s
Publish Docker Image / base-decide (push) Successful in 8s
Publish Docker Image / build-base (push) Successful in 41m22s
Publish Docker Image / smoke-studio (push) Successful in 5m16s
Publish Docker Image / smoke (push) Successful in 7m31s
Publish Docker Image / build-variant-studio (push) Successful in 18m31s
Publish Docker Image / build-variant (push) Successful in 27m18s
Publish Docker Image / promote-base-latest (push) Successful in 11s
Publish Docker Image / update-description (push) Successful in 12s
Publish Docker Image / resolve-versions (push) Successful in 9s
Lint / actionlint (push) Successful in 15s
Lint / hadolint (push) Successful in 13s
Publish Docker Image / base-decide (push) Successful in 8s
Publish Docker Image / build-base (push) Successful in 41m22s
Publish Docker Image / smoke-studio (push) Successful in 5m16s
Publish Docker Image / smoke (push) Successful in 7m31s
Publish Docker Image / build-variant-studio (push) Successful in 18m31s
Publish Docker Image / build-variant (push) Successful in 27m18s
Publish Docker Image / promote-base-latest (push) Successful in 11s
Publish Docker Image / update-description (push) Successful in 12s
Two changes that belong together, because the first is what makes the second dangerous to get wrong. pi-atelier (TUI sidebar + status rail) is now vendored to /opt/pi-atelier at PI_ATELIER_REF=v0.8.0 and registered by entrypoint-user.sh — the pi-fork / pi-observational-memory / pi-studio pattern, deliberately NOT `pi install npm:pi-atelier`, which writes into ~/.pi/npm-global on the config volume where it shadows the image and pins nothing. Unlike its siblings it gets no `npm install`: atelier declares zero runtime deps (peerDeps only, satisfied by the baked pi) and has no build step, so pi loads its TypeScript straight from the checkout via package.json `pi.extensions`. pi is no longer resolved to npm `latest` at build time. The pin lives in Dockerfile.variant and CI reads it from there, so a local `docker build` and a CI release ship the same versions by construction. The pin is a CHECKPOINT, NOT A FREEZE: bumping stays a one-line change; what stops is *unreviewed* adoption of whatever shipped that morning, in the same build that then gets tagged and published. CI fails when a pin is not concrete or not actually published on npm, and warns — never adopts — when npm latest moves ahead, naming what to re-check. Why this pairing needed care: pi-atelier 0.6.0/0.7.0 wrap pi's PRIVATE TUI renderer, and under pi 0.84 that wrapper recurses — pi hangs at startup burning CPU with no error. Upstream fixed the recursion in 0.7.1 and restored the non-overlapping split in 0.7.2; 0.8.0 is additive on top. atelier's own peerDependencies still say >=0.80.7, which does not express that floor, so nothing in npm metadata could have warned us. The floor is therefore encoded as an executable rule — pi >= 0.84 => pi-atelier >= 0.7.1 — asserted in both smoke-test.sh (build time) and recreate-sanity-check.sh (after a real recreate), verified against a 4x4 version matrix. Existing volumes needed migration, not just vendoring: a hand-installed `npm:pi-atelier` entry is counted as already-registered by the entrypoint guard, so every existing volume would have kept its unpinned npm copy — and a 0.6.x copy next to pi 0.84 is exactly the startup hang. The entrypoint now drops that one exact string (settings.json.bak.atelier.<ts> backup, distinct prefix so it cannot clobber the template merge's backup in the same second) and lets the pinned /opt copy register. Tested against a real settings.json: only that entry removed, other packages and all keys intact, idempotent, and unparseable JSON leaves the file untouched. DEVBOX_ATELIER=0 opts out entirely — in the entrypoint rather than via `pi uninstall`, because this component's failure mode is "pi will not start", which cannot be repaired from inside pi. 0.84.1 was audited for this release, not merely adopted: theme/TUI changes are additive, the session format is unchanged (CURRENT_SESSION_VERSION = 3 in both 0.83.0 and 0.84.1 with an identical migrateV1ToV2/migrateV2ToV3 ladder, so existing transcripts are neither migrated nor at risk and pi-session-repair stays valid), and the Node engine floor is unmoved at >=22.19.0. CI resolves the atelier tag to its PEELED commit SHA — atelier uses annotated tags, so the unpeeled ref is a tag object, not a commit; pi-studio's lightweight tags never exposed that distinction. Also: docs for overriding the read-only ~/.ssh/config from the container — container-only keys in ~/.ssh-local, hardened authorized_keys, the fact that `from=` must allow the HOST's addresses because container egress is NAT'd through it, and the macOS-only-keyword trap (`UseKeychain` is fatal to Linux OpenSSH and takes out dssh/pi --ssh while the host keeps working). Corrects two claims in "Naming LAN peers": ssh-lan.conf is not ProxyJump-only, and first-time creation does need one restart because the Include is emitted only when the file already exists at start.
This commit is contained in:
+58
-4
@@ -169,9 +169,9 @@ if command -v pi &>/dev/null; then
|
||||
"$HOME/.pi/agent/extensions/mempalace.ts"
|
||||
fi
|
||||
|
||||
# pi-fork (fork tool) + pi-observational-memory (recall tool) + (in the
|
||||
# :latest-studio variant only) pi-studio (/studio command + studio_*
|
||||
# tools + theme). These are pi packages (not symlink-style extensions):
|
||||
# pi-fork (fork tool) + pi-observational-memory (recall tool) + pi-atelier
|
||||
# (TUI sidebar panels/split-pane) + (in the :latest-studio variant only)
|
||||
# pi-studio (/studio command + studio_* tools + theme). These are pi packages (not symlink-style extensions):
|
||||
# they're cloned to /opt with node_modules baked at BUILD time, then
|
||||
# registered here via `pi install <local-path>`. A local-path install is
|
||||
# instant + in-place (pi loads the extension directly from /opt) +
|
||||
@@ -206,9 +206,63 @@ if command -v pi &>/dev/null; then
|
||||
fi
|
||||
}
|
||||
|
||||
for _pkg in /opt/pi-fork /opt/pi-observational-memory /opt/pi-studio; do
|
||||
# ── pi-atelier: retire a stale `npm:pi-atelier`, plus an opt-out ──────
|
||||
# The image now vendors pi-atelier at a pinned, audited tag (PI_ATELIER_REF
|
||||
# in Dockerfile.variant). A leftover `npm:pi-atelier` entry from a
|
||||
# hand-install resolves through ~/.pi/npm-global, which lives on the
|
||||
# devbox-pi-config VOLUME — so it survives image upgrades and keeps whatever
|
||||
# version was installed by hand, unpinned and unaudited. That is not
|
||||
# academic: pi-atelier < 0.7.1 makes pi >= 0.84 hang at startup with
|
||||
# sustained CPU, so leaving it in place turns a pi bump into a TUI that will
|
||||
# not start. And `_pi_pkg_registered` deliberately counts `npm:<name>` as
|
||||
# registered (it respects a user's own npm install), so the loop below would
|
||||
# never replace it.
|
||||
#
|
||||
# We only DELETE the exact `npm:pi-atelier` string; the loop then registers
|
||||
# /opt/pi-atelier in pi's own canonical serialization, so this code never has
|
||||
# to guess the stored relative-path form. Idempotent — after the rewrite
|
||||
# there is no npm entry left to match.
|
||||
#
|
||||
# DEVBOX_ATELIER=0 goes further and removes pi-atelier from `packages`
|
||||
# altogether. That escape hatch lives HERE, in the entrypoint, precisely
|
||||
# because this component's known failure mode is "pi will not start" — which
|
||||
# you cannot repair with `pi uninstall`.
|
||||
_pi_atelier_drop() {
|
||||
# $1 = jq predicate over one `packages` entry, selecting what to REMOVE.
|
||||
# Returns 0 only when the file was actually rewritten (caller logs), 1 for
|
||||
# "nothing to do" — including missing jq or unparseable JSON, which must
|
||||
# never clobber user settings. Backs up first, same convention as the
|
||||
# template merge above.
|
||||
_ad_settings="$HOME/.pi/agent/settings.json"
|
||||
[ -f "$_ad_settings" ] || return 1
|
||||
command -v jq >/dev/null 2>&1 || return 1
|
||||
_ad_new=$(jq "(.packages // []) |= map(select(($1) | not))" "$_ad_settings" 2>/dev/null) || return 1
|
||||
[ -n "$_ad_new" ] || return 1
|
||||
if printf '%s' "$_ad_new" | jq -e --slurpfile cur "$_ad_settings" '. == $cur[0]' >/dev/null 2>&1; then
|
||||
return 1
|
||||
fi
|
||||
# `.bak.atelier.` rather than the merge's plain `.bak.` prefix: both can
|
||||
# fire in the same startup, and a bare seconds-resolution timestamp would
|
||||
# make the second cp overwrite the first one's backup.
|
||||
cp "$_ad_settings" "${_ad_settings}.bak.atelier.$(date +%Y%m%d-%H%M%S)"
|
||||
printf '%s\n' "$_ad_new" > "$_ad_settings"
|
||||
return 0
|
||||
}
|
||||
if [ "${DEVBOX_ATELIER:-1}" = "0" ]; then
|
||||
if _pi_atelier_drop '(. == "npm:pi-atelier") or ((type == "string") and endswith("/pi-atelier"))'; then
|
||||
echo "pi-atelier: unregistered per DEVBOX_ATELIER=0 (settings backup saved)"
|
||||
fi
|
||||
elif [ -d /opt/pi-atelier ]; then
|
||||
if _pi_atelier_drop '. == "npm:pi-atelier"'; then
|
||||
echo "pi-atelier: dropped stale npm: registration — the pinned /opt copy takes over (settings backup saved)"
|
||||
fi
|
||||
fi
|
||||
|
||||
for _pkg in /opt/pi-fork /opt/pi-observational-memory /opt/pi-studio /opt/pi-atelier; do
|
||||
[ -d "$_pkg" ] || continue
|
||||
_name=$(basename "$_pkg")
|
||||
# DEVBOX_ATELIER=0 → leave pi-atelier unregistered (handled just above).
|
||||
if [ "$_name" = "pi-atelier" ] && [ "${DEVBOX_ATELIER:-1}" = "0" ]; then continue; fi
|
||||
if ! _pi_pkg_registered "$_name"; then
|
||||
pi install "$_pkg" >/dev/null 2>&1 || \
|
||||
echo "WARN: pi install $_name failed (continuing)"
|
||||
|
||||
Reference in New Issue
Block a user