release(v1.9.5): pi 0.87.1 with pi-obsmem pinned to the merged finishTurn fix
Lint / skill-floor (push) Successful in 7s
Lint / hadolint (push) Successful in 14s
Lint / actionlint (push) Successful in 19s
Lint / doc-drift (push) Successful in 12s

v1.9.4 held pi at 0.85.1 because 0.87.0 REMOVED `shouldStopAfterTurn`, which
pi-observational-memory 3.1.4 still used in all three workers. Its peerDeps are
`*`, so nothing refuses at install time and the breakage is silent at runtime --
turn caps ignored, workers losing their specialised prompts. PR #83 fixes that
and merged 2026-09-23.

Re-measured 2026-10-01 across src/agents/{observer,reflector,dropper}/agent.ts,
deliberately reusing the v1.9.4 audit's counting method so the numbers compare:

  e7d77dc (3.1.4, baked in v1.9.4): shouldStopAfterTurn 3, finishTurn 0, systemPrompt 3
  731c3d4 (pinned here)           : shouldStopAfterTurn 0, finishTurn 3, systemPrompt 0

All three workers migrated, and the 0.86.0 AgentContext.systemPrompt reads are
gone too. The coupling is asymmetric and that is why these move in ONE commit:
3.1.4 + 0.87.1 silently ignores turn caps, and 731c3d4 + 0.85.1 breaks the
workers outright, because finishTurn does not exist before 0.87.0.

Pinned to a SHA rather than waiting for a tag, departing from the v1.9.4
instruction to wait for a release: #83 is merged but the newest obsmem tag is
still 3.1.4, cut 2026-09-20, BEFORE the merge. Upstream tags slowly and moves
master often (e7d77dc -> 1529e14 -> 731c3d4 in nine days), so waiting means
holding pi indefinitely. A pinned SHA keeps the property `master` lacks:
rebuilding this tag later produces the same image.

The 40-char form is load-bearing, not pedantry. check-doc-drift.sh recognises a
literal SHA only through a 40-char match, so a 7-char pin would fall through to
its branch-or-tag lookup, fail to resolve, and downgrade pi-obsmem's drift check
to a silent SKIP -- a pin that reads correctly and is no longer verified. Full
gate run after this change: 23 OK, 0 DRIFT, 0 SKIP, 0 FAIL.

0.99.0/0.99.1/0.99.2 and 1.0.0 all exist upstream and are deliberately skipped:
obsmem's only compatibility work names Pi 0.87 (2b1dc1c) and a repo-wide
issue/PR search for 0.99 or 1.0 returns zero matches. 1.0.0 is its own round.

pi-atelier stays at v0.10.3 and is the residual risk. Its peerDeps declare pi
>=0.84.0 -- a floor, satisfied -- on both v0.10.3 and the current v0.12.1, so it
spans this bump. But atelier hooks pi TUI internals that a declared floor does
not protect, and an under-declared floor is exactly what failed to warn anyone
at pi 0.84. Acceptance must confirm the sidebar PAINTS, using the two-sided
check from 0.84.4/0.85.1 that distinguishes "loaded" from "silently absent".

Also here:
- check-doc-drift.sh gains a pi-obsmem pin check. The ref-move check covers the
  same component, but for a pinned SHA it can only answer "upstream did not
  move", never "the table still says what we bake".
- scripts/lint-shell.sh mode 100644 -> 100755. Pre-existing since f25efa0 and
  the only non-executable script in scripts/; it was latent because both CI
  steps call it as `bash scripts/lint-shell.sh`, but it failed rc=126 "bad
  interpreter" when invoked directly. Same dropped-exec-bit signature recorded
  on 2026-09-22, found the same way: by RUNNING it, not by reading a diff.
- Unreleased section renamed to `## v1.9.5 — 2026-10-02`, satisfying the
  release-gate rule that a tag's CHANGELOG must name its own version.
This commit is contained in:
Joakim Persson
2026-10-02 00:23:28 +02:00
parent cb8969ef2c
commit 9d0b3dec0b
5 changed files with 115 additions and 10 deletions
+63 -6
View File
@@ -11,23 +11,80 @@ Pre-v1.0.0 tags followed the pi npm version (`v{pi_version}[letter]`).
---
## Unreleased
## v1.9.5 — 2026-10-02
Three small fixes found by the v1.9.4 first-boot acceptance and the CI base
hash prediction, none release-worthy on its own, plus one boot-time wiring fix
that stops a recurring `git push` failure inside the container, and four small
base packages. Nothing here changes a pin. `entrypoint-user.sh` and
`Dockerfile.base` are both in the base hash, so the next tag rebuilds the base
hash prediction, plus one boot-time wiring fix that stops a recurring `git push`
failure inside the container, four small base packages, and the pi bump that
v1.9.4 deliberately held. Nothing here changes a variant. `entrypoint-user.sh`
and `Dockerfile.base` are both in the base hash, so this tag rebuilds the base
(~64 min) regardless of what else it carries.
### Components that move with the next build
| Component | Baked in v1.9.4 | Next build | Why |
| Component | Baked in v1.9.4 | This release | Why |
|---|---|---|---|
| pi | `0.85.1` | **`0.87.1`** | the hold is over: obsmem's `finishTurn` migration shipped (below) |
| pi-obsmem | `e7d77dc` (`master`) | **`731c3d4`** (pinned SHA) | PR #83 is merged but unreleased; pinned so a rebuild is reproducible (below) |
| pi-extensions | `25c1265` | **`143a214`** | `install.sh`: skip hook activation on a clone this user cannot configure (below) |
| mempalace-toolkit | `2167a1b` | **`975ab92`** | mailbox: an ask can declare `dormant_unless`, so deliberately-waiting work stops being announced (below) |
| pi-studio | `v0.9.60` (`e04fc7a`) | **`v0.9.61`** (`641aa32`) | upstream release, adopted as-is; `-studio` variant only |
### Changed
- **pi `0.85.1` → `0.87.1`, and pi-obsmem off `master` onto the pinned SHA
`731c3d4` — in one commit, because neither is safe alone.** v1.9.4 held pi at
0.85.1 because 0.87.0 *removed* `shouldStopAfterTurn`, which
pi-observational-memory 3.1.4 still used; its `peerDependencies` are `*`, so
nothing would refuse at install time and the breakage would be silent at
runtime (turn caps ignored, workers losing their specialised prompts). PR #83
merged 2026-09-23 and fixes exactly that. Re-measured 2026-10-01 across
`src/agents/{observer,reflector,dropper}/agent.ts`, using the same counting
method as the v1.9.4 audit so the two are comparable:
| ref | `shouldStopAfterTurn` | `finishTurn` | `systemPrompt` |
|---|---|---|---|
| `e7d77dc` (3.1.4, baked in v1.9.4) | 3 | 0 | 3 |
| `731c3d4` (pinned here) | 0 | 3 | 0 |
All three workers migrated, and the 0.86.0 `AgentContext.systemPrompt` reads
are gone too. The direction of the coupling is worth stating because it is not
symmetric: 3.1.4 + 0.87.1 ignores turn caps, and `731c3d4` + 0.85.1 breaks the
workers outright, since `finishTurn` does not exist before 0.87.0. They move
together or not at all.
**Pinned to a SHA rather than waiting for a tag**, departing from the v1.9.4
instruction to bump "once #83 has shipped in a release". The newest obsmem tag
is still 3.1.4, cut 2026-09-20 — *before* the merge — and upstream tags slowly
while moving `master` often: `e7d77dc` → `1529e14` → `731c3d4` in the nine days
to 2026-10-01. Waiting for a tag means holding pi indefinitely. The full
40-char form is deliberate: `check-doc-drift.sh` recognises a literal SHA only
via a 40-char match, so a short pin would fall through to its branch-or-tag
lookup and quietly downgrade that component's drift check to a SKIP.
**0.99.0/0.99.1/0.99.2 and 1.0.0 all exist upstream and are deliberately
skipped.** obsmem's only compatibility work names Pi 0.87 (`2b1dc1c`, "fix:
support Pi 0.87 agent APIs") and a repo-wide issue/PR search for `0.99` or
`1.0` returns zero matches, so nothing covers them. 0.87.1 is the highest
version the evidence reaches; 1.0.0 is its own round, with pi-atelier,
pi-fork, pi-extensions, pi-toolkit, mempalace-toolkit and pi-studio all
re-checked.
**pi-atelier stays at v0.10.3 and is the residual risk.** Its
`peerDependencies` declare pi `>=0.84.0` — a floor, satisfied by 0.87.1 — on
both v0.10.3 and the current upstream v0.12.1, so it spans this bump either
way. But atelier hooks pi TUI internals (the `TuiMainScreen` prototype,
`renderLayoutFrame`) that a declared floor does not protect, and an
under-declared floor is precisely what failed to warn anyone at pi 0.84.
Acceptance must confirm the sidebar still **paints**, using the two-sided check
from 0.84.4 and 0.85.1 that can tell "loaded" from "silently absent".
- **`check-doc-drift.sh` now checks the pi-obsmem pin** against README's
version-pin table, the same way it already checks pi, pi-atelier and
mempalace. The ref-move check also covers pi-obsmem, but for a pinned SHA it
can only ever answer "upstream did not move" — never "the table still says what
we bake", which is the claim a reader of the table actually relies on.
### Added
- **Mailbox: an ask can declare its own dormancy (`mempalace-toolkit` `975ab92`)**