diff --git a/CHANGELOG.md b/CHANGELOG.md index 1a556c0..9b09bb5 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -11,23 +11,80 @@ Pre-v1.0.0 tags followed the pi npm version (`v{pi_version}[letter]`). --- -## Unreleased +## v1.9.5 — 2026-10-02 Three small fixes found by the v1.9.4 first-boot acceptance and the CI base -hash prediction, none release-worthy on its own, plus one boot-time wiring fix -that stops a recurring `git push` failure inside the container, and four small -base packages. Nothing here changes a pin. `entrypoint-user.sh` and -`Dockerfile.base` are both in the base hash, so the next tag rebuilds the base +hash prediction, plus one boot-time wiring fix that stops a recurring `git push` +failure inside the container, four small base packages, and the pi bump that +v1.9.4 deliberately held. Nothing here changes a variant. `entrypoint-user.sh` +and `Dockerfile.base` are both in the base hash, so this tag rebuilds the base (~64 min) regardless of what else it carries. ### Components that move with the next build -| Component | Baked in v1.9.4 | Next build | Why | +| Component | Baked in v1.9.4 | This release | Why | |---|---|---|---| +| pi | `0.85.1` | **`0.87.1`** | the hold is over: obsmem's `finishTurn` migration shipped (below) | +| pi-obsmem | `e7d77dc` (`master`) | **`731c3d4`** (pinned SHA) | PR #83 is merged but unreleased; pinned so a rebuild is reproducible (below) | | pi-extensions | `25c1265` | **`143a214`** | `install.sh`: skip hook activation on a clone this user cannot configure (below) | | mempalace-toolkit | `2167a1b` | **`975ab92`** | mailbox: an ask can declare `dormant_unless`, so deliberately-waiting work stops being announced (below) | | pi-studio | `v0.9.60` (`e04fc7a`) | **`v0.9.61`** (`641aa32`) | upstream release, adopted as-is; `-studio` variant only | +### Changed + +- **pi `0.85.1` → `0.87.1`, and pi-obsmem off `master` onto the pinned SHA + `731c3d4` — in one commit, because neither is safe alone.** v1.9.4 held pi at + 0.85.1 because 0.87.0 *removed* `shouldStopAfterTurn`, which + pi-observational-memory 3.1.4 still used; its `peerDependencies` are `*`, so + nothing would refuse at install time and the breakage would be silent at + runtime (turn caps ignored, workers losing their specialised prompts). PR #83 + merged 2026-09-23 and fixes exactly that. Re-measured 2026-10-01 across + `src/agents/{observer,reflector,dropper}/agent.ts`, using the same counting + method as the v1.9.4 audit so the two are comparable: + + | ref | `shouldStopAfterTurn` | `finishTurn` | `systemPrompt` | + |---|---|---|---| + | `e7d77dc` (3.1.4, baked in v1.9.4) | 3 | 0 | 3 | + | `731c3d4` (pinned here) | 0 | 3 | 0 | + + All three workers migrated, and the 0.86.0 `AgentContext.systemPrompt` reads + are gone too. The direction of the coupling is worth stating because it is not + symmetric: 3.1.4 + 0.87.1 ignores turn caps, and `731c3d4` + 0.85.1 breaks the + workers outright, since `finishTurn` does not exist before 0.87.0. They move + together or not at all. + + **Pinned to a SHA rather than waiting for a tag**, departing from the v1.9.4 + instruction to bump "once #83 has shipped in a release". The newest obsmem tag + is still 3.1.4, cut 2026-09-20 — *before* the merge — and upstream tags slowly + while moving `master` often: `e7d77dc` → `1529e14` → `731c3d4` in the nine days + to 2026-10-01. Waiting for a tag means holding pi indefinitely. The full + 40-char form is deliberate: `check-doc-drift.sh` recognises a literal SHA only + via a 40-char match, so a short pin would fall through to its branch-or-tag + lookup and quietly downgrade that component's drift check to a SKIP. + + **0.99.0/0.99.1/0.99.2 and 1.0.0 all exist upstream and are deliberately + skipped.** obsmem's only compatibility work names Pi 0.87 (`2b1dc1c`, "fix: + support Pi 0.87 agent APIs") and a repo-wide issue/PR search for `0.99` or + `1.0` returns zero matches, so nothing covers them. 0.87.1 is the highest + version the evidence reaches; 1.0.0 is its own round, with pi-atelier, + pi-fork, pi-extensions, pi-toolkit, mempalace-toolkit and pi-studio all + re-checked. + + **pi-atelier stays at v0.10.3 and is the residual risk.** Its + `peerDependencies` declare pi `>=0.84.0` — a floor, satisfied by 0.87.1 — on + both v0.10.3 and the current upstream v0.12.1, so it spans this bump either + way. But atelier hooks pi TUI internals (the `TuiMainScreen` prototype, + `renderLayoutFrame`) that a declared floor does not protect, and an + under-declared floor is precisely what failed to warn anyone at pi 0.84. + Acceptance must confirm the sidebar still **paints**, using the two-sided check + from 0.84.4 and 0.85.1 that can tell "loaded" from "silently absent". + +- **`check-doc-drift.sh` now checks the pi-obsmem pin** against README's + version-pin table, the same way it already checks pi, pi-atelier and + mempalace. The ref-move check also covers pi-obsmem, but for a pinned SHA it + can only ever answer "upstream did not move" — never "the table still says what + we bake", which is the claim a reader of the table actually relies on. + ### Added - **Mailbox: an ask can declare its own dormancy (`mempalace-toolkit` `975ab92`)** diff --git a/Dockerfile.variant b/Dockerfile.variant index c92af41..eb252d9 100644 --- a/Dockerfile.variant +++ b/Dockerfile.variant @@ -134,7 +134,41 @@ ARG USER_NAME=developer # contract) and its registerTool calls spread the built-in tools so they # carry parameter schemas (#9300). 0.86.1 as an intermediate is untested and # not worth the pty matrix for a stop that #83 will make moot. -ARG PI_VERSION=0.85.1 +# +# v1.9.5: 0.85.1 -> 0.87.1, and pi-obsmem moves off `master` to a pinned SHA in +# the SAME commit, because neither is safe alone. 0.87.0 REMOVED +# `shouldStopAfterTurn`, which 3.1.4 still used; the pinned tip uses +# `finishTurn`, which does not exist before 0.87.0. So 3.1.4 + 0.87.1 silently +# ignores turn caps, and the new tip + 0.85.1 breaks the workers outright — the +# pair only works together, exactly as the v1.9.4 note predicted. +# MEASURED 2026-10-01 across src/agents/{observer,reflector,dropper}/agent.ts, +# deliberately the same counting method as the v1.9.4 audit above so the two +# numbers are comparable: +# 3.1.4 (e7d77dc): shouldStopAfterTurn 3, finishTurn 0, systemPrompt 3 +# 731c3d4 (pinned) : shouldStopAfterTurn 0, finishTurn 3, systemPrompt 0 +# i.e. all three workers migrated, and the 0.86.0 `AgentContext.systemPrompt` +# reads are gone too. #82/#83 merged 2026-09-23. +# WHY A SHA AND NOT A TAG, departing from the v1.9.4 instruction to wait for a +# release: #83 is merged, but the newest obsmem tag is STILL 3.1.4, cut +# 2026-09-20 — before the merge. Upstream tags slowly while moving master often +# (e7d77dc -> 1529e14 -> 731c3d4 in the nine days to 2026-10-01), so waiting for +# a tag means holding pi indefinitely. A full SHA keeps the one property +# `master` does not have: rebuilding this tag later produces the SAME image. +# SKIPPING 0.99.0/0.99.1/0.99.2 and 1.0.0, which all exist upstream: obsmem's +# only compatibility work names Pi 0.87 ("fix: support Pi 0.87 agent APIs", +# 2b1dc1c), and a repo-wide issue/PR search for "0.99" or "1.0" returns ZERO +# matches. Its peerDependencies are `*`, so nothing would refuse at install +# time and a 1.0.0 bump would fail silently at RUNTIME. 0.87.1 is the highest +# version the evidence actually covers; 1.0.0 is a separate round. +# pi-atelier v0.10.3 is deliberately NOT bumped here: its peerDependencies +# declare pi >=0.84.0 — a FLOOR, satisfied by 0.87.1 — on both v0.10.3 and the +# current upstream v0.12.1, so it spans this bump either way. It is the residual +# risk, because atelier hooks pi TUI internals (the `TuiMainScreen` prototype, +# `renderLayoutFrame`) that a declared floor does not protect, and a floor is +# exactly what failed to warn us at pi 0.84. Acceptance must confirm the sidebar +# still PAINTS — the same two-sided check used at 0.84.4 and 0.85.1, which can +# tell "loaded" from "silently absent". +ARG PI_VERSION=0.87.1 ARG PI_TOOLKIT_REF=main ARG PI_EXTENSIONS_REF=main # Repo URLs default to the canonical gitea origin but are overridable so a @@ -149,7 +183,14 @@ ARG PI_EXTENSIONS_REPO=https://gitea.jordbo.se/joakimp/pi-extensions.git ARG PI_FORK_REPO=https://github.com/elpapi42/pi-fork.git ARG PI_FORK_REF=master ARG PI_OBSMEM_REPO=https://github.com/elpapi42/pi-observational-memory.git -ARG PI_OBSMEM_REF=master +# PINNED to a full 40-char SHA as of v1.9.5, not `master` — see the PI_VERSION +# note above for the measurement and the reasoning. Moves together with +# PI_VERSION by necessity, not by convention. The width matters: 731c3d4 is the +# same commit, but check-doc-drift.sh recognises a literal SHA only via a +# 40-char match (SHA40), so a short pin would fall through to its +# branch-or-tag lookup, fail, and downgrade that component's drift check to a +# silent SKIP — a pin that reads fine and is no longer verified. +ARG PI_OBSMEM_REF=731c3d49288580f4d79cabdbfbc0d16b34db0f41 # pi-atelier (TUI sidebar: ordered panels, split-pane, themes) is PINNED TO A # TAG, which CI resolves to that tag's commit SHA — same treatment as # pi-studio, for reproducibility plus cache-busting. diff --git a/README.md b/README.md index 92de055..ca2f893 100644 --- a/README.md +++ b/README.md @@ -1106,7 +1106,7 @@ persisted volumes survived, and pi runtime wiring is intact: ```bash ./scripts/recreate-sanity-check.sh # auto-detects variant ./scripts/recreate-sanity-check.sh --expected-image-version 1.8.9 # assert the pi-devbox release tag -./scripts/recreate-sanity-check.sh --expected-version 0.85.1 # assert the pi coding agent version +./scripts/recreate-sanity-check.sh --expected-version 0.87.1 # assert the pi coding agent version ``` Those are **two different versions**, and the flags are not interchangeable: @@ -1145,7 +1145,8 @@ resolved to `latest` at build time: | Component | Pin | Where | |---|---|---| -| pi | `0.85.1` | `ARG PI_VERSION` — `Dockerfile.variant` | +| pi | `0.87.1` | `ARG PI_VERSION` — `Dockerfile.variant` | +| pi-obsmem | `731c3d49288580f4d79cabdbfbc0d16b34db0f41` | `ARG PI_OBSMEM_REF` — `Dockerfile.variant` | | pi-atelier | `v0.10.3` | `ARG PI_ATELIER_REF` — `Dockerfile.variant` | | mempalace | `3.10.0` | `ARG MEMPALACE_VERSION` — `Dockerfile.base` | diff --git a/scripts/check-doc-drift.sh b/scripts/check-doc-drift.sh index bf8588c..5bc58bc 100755 --- a/scripts/check-doc-drift.sh +++ b/scripts/check-doc-drift.sh @@ -181,8 +181,14 @@ check_pin() { PI_ACTUAL="$(read_arg "$DF_VARIANT" PI_VERSION)" ATELIER_ACTUAL="$(read_arg "$DF_VARIANT" PI_ATELIER_REF)" MEMPALACE_ACTUAL="$(read_arg "$DF_BASE" MEMPALACE_VERSION)" +# pi-obsmem became a PIN in v1.9.5 (was the floating `master`), so it joins the +# reviewable table. It is also covered by the ref-move check below, but that one +# can only ever report "unchanged" for a pinned SHA -- it answers "did upstream +# move?", never "does the table still say what we bake?", which is this check. +OBSMEM_PIN_ACTUAL="$(read_arg "$DF_VARIANT" PI_OBSMEM_REF)" check_pin pi "$(read_pin_row pi)" "$PI_ACTUAL" "ARG PI_VERSION in $DF_VARIANT" +check_pin pi-obsmem "$(read_pin_row pi-obsmem)" "$OBSMEM_PIN_ACTUAL" "ARG PI_OBSMEM_REF in $DF_VARIANT" check_pin pi-atelier "$(read_pin_row pi-atelier)" "$ATELIER_ACTUAL" "ARG PI_ATELIER_REF in $DF_VARIANT" check_pin mempalace "$(read_pin_row mempalace)" "$MEMPALACE_ACTUAL" "ARG MEMPALACE_VERSION in $DF_BASE" diff --git a/scripts/lint-shell.sh b/scripts/lint-shell.sh old mode 100644 new mode 100755