diff --git a/CHANGELOG.md b/CHANGELOG.md index 9b09bb5..7ece776 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -11,28 +11,34 @@ Pre-v1.0.0 tags followed the pi npm version (`v{pi_version}[letter]`). --- -## v1.9.5 — 2026-10-02 +## v1.10.0 — 2026-10-02 Three small fixes found by the v1.9.4 first-boot acceptance and the CI base hash prediction, plus one boot-time wiring fix that stops a recurring `git push` -failure inside the container, four small base packages, and the pi bump that -v1.9.4 deliberately held. Nothing here changes a variant. `entrypoint-user.sh` -and `Dockerfile.base` are both in the base hash, so this tag rebuilds the base -(~64 min) regardless of what else it carries. +failure inside the container, four small base packages, **pi 1.0.0**, and +**pi-atelier v0.13.0**. `entrypoint-user.sh` and `Dockerfile.base` are both in +the base hash, so this tag rebuilds the base (~64 min) regardless of what else +it carries. + +A **minor**, not a patch: this was prepared as `v1.9.5` under the "patch — pi +version bumps" rule, but it now carries a pi MAJOR, a three-minor pi-atelier +jump, four new base packages and a new mailbox feature. The release carrying a +1.0.0 should not be the one numbered as a patch. ### Components that move with the next build | Component | Baked in v1.9.4 | This release | Why | |---|---|---|---| -| pi | `0.85.1` | **`0.87.1`** | the hold is over: obsmem's `finishTurn` migration shipped (below) | +| pi | `0.85.1` | **`1.0.0`** | the hold is over: obsmem's `finishTurn` migration shipped, and 1.0.0 ships no breaking change that reaches us (below) | | pi-obsmem | `e7d77dc` (`master`) | **`731c3d4`** (pinned SHA) | PR #83 is merged but unreleased; pinned so a rebuild is reproducible (below) | +| pi-atelier | `v0.10.3` (`ed3837b`) | **`v0.13.0`** (`34d26f1`) | closes the gap v1.9.5 flagged as the pi bump's residual risk; its own breaking change reaches nothing of ours (below) | | pi-extensions | `25c1265` | **`143a214`** | `install.sh`: skip hook activation on a clone this user cannot configure (below) | | mempalace-toolkit | `2167a1b` | **`975ab92`** | mailbox: an ask can declare `dormant_unless`, so deliberately-waiting work stops being announced (below) | | pi-studio | `v0.9.60` (`e04fc7a`) | **`v0.9.61`** (`641aa32`) | upstream release, adopted as-is; `-studio` variant only | ### Changed -- **pi `0.85.1` → `0.87.1`, and pi-obsmem off `master` onto the pinned SHA +- **pi `0.85.1` → `1.0.0`, and pi-obsmem off `master` onto the pinned SHA `731c3d4` — in one commit, because neither is safe alone.** v1.9.4 held pi at 0.85.1 because 0.87.0 *removed* `shouldStopAfterTurn`, which pi-observational-memory 3.1.4 still used; its `peerDependencies` are `*`, so @@ -62,22 +68,89 @@ and `Dockerfile.base` are both in the base hash, so this tag rebuilds the base via a 40-char match, so a short pin would fall through to its branch-or-tag lookup and quietly downgrade that component's drift check to a SKIP. - **0.99.0/0.99.1/0.99.2 and 1.0.0 all exist upstream and are deliberately - skipped.** obsmem's only compatibility work names Pi 0.87 (`2b1dc1c`, "fix: - support Pi 0.87 agent APIs") and a repo-wide issue/PR search for `0.99` or - `1.0` returns zero matches, so nothing covers them. 0.87.1 is the highest - version the evidence reaches; 1.0.0 is its own round, with pi-atelier, - pi-fork, pi-extensions, pi-toolkit, mempalace-toolkit and pi-studio all - re-checked. + **0.99.x was skipped and 1.0.0 was ADOPTED, because the evidence arrived.** + v1.9.5 was prepared holding at 0.87.1 on the grounds that obsmem's only + compatibility work names Pi 0.87 (`2b1dc1c`) and a repo-wide issue/PR search + for `0.99` or `1.0` returns zero matches. That reasoning had a hole worth + naming: *no issue mentions 1.0* is an absence of a statement, not a + measurement. So 1.0.0 was measured directly, against the published npm + tarballs for 0.87.1 and 1.0.0 unpacked side by side (2026-10-02): - **pi-atelier stays at v0.10.3 and is the residual risk.** Its - `peerDependencies` declare pi `>=0.84.0` — a floor, satisfied by 0.87.1 — on - both v0.10.3 and the current upstream v0.12.1, so it spans this bump either - way. But atelier hooks pi TUI internals (the `TuiMainScreen` prototype, - `renderLayoutFrame`) that a declared floor does not protect, and an - under-declared floor is precisely what failed to warn anyone at pi 0.84. - Acceptance must confirm the sidebar still **paints**, using the two-sided check - from 0.84.4 and 0.85.1 that can tell "loaded" from "silently absent". + - **1.0.0 has no `### Breaking Changes` section at all.** The changelog's + breaking sections belong to 0.87.0, 0.86.0, 0.84.3, 0.84.0, 0.83.0, 0.80.8, + 0.80.7 and 0.75.0 — none to anything between 0.88 and 1.0.0. The major is a + milestone (fullscreen default, leaner codemode), not an API break. The last + break that touched us was 0.87.0's `shouldStopAfterTurn` removal, absorbed + above. + - **`finishTurn` is still in 1.0.0's dist**, so the pinned obsmem SHA keeps + the API it migrated to. + - **All 8 `pi.*` APIs our extensions call exist in 1.0.0's dist** — + `registerTool`, `registerCommand`, `registerFlag`, `getFlag`, `on`, `exec`, + `sendMessage`, `sendUserMessage`, extracted from `mempalace.ts`, the + pi-extensions tree and obsmem's `src/`. + - `engines.node` is `>=22.19.0` on both; the image ships 24.x. + + **The 0.99.2 change that looked fatal and is not.** From 0.99.2 the default + MCP `exposure` is `codemode`, meaning such tools are "neither declared to the + model nor listed in the codemode description" and must be found with + `searchTools()`. That would gut the MemPalace protocol — every skill says to + call `mempalace_search` — if MemPalace were a builtin-MCP server. It is not: + `mempalace.ts` and `mcp-loader.ts` each run their own MCP client and surface + tools through `pi.registerTool()`, which is why they are named + `mempalace_search` rather than `mcp__mempalace__search`. Confirmed on a second + route: `settings.json` has neither an `mcpServers` block (builtin, + exposure-governed) nor an `mcp` block. Extension-registered tools are declared + like built-ins, so `exposure` cannot reach them. Noted here because the change + is filed under "Changed", not "Breaking", and would be easy to meet the hard + way. + + **What is NOT proven.** Grepping dist shows the symbols survive, not that + their signatures are unchanged — necessary, not sufficient. 1.0.0 is four days + old (published 2026-10-01T19:15Z) and neither obsmem nor atelier has a commit + naming it. Acceptance must prove the obsmem workers **cap turns** (peerDeps + are `*`, so a mismatch is silent at runtime) and that the atelier sidebar + **paints**. + + **User-visible behaviour change, deliberately not overridden.** 1.0.0 makes + the TUI fullscreen by default, replacing the terminal's normal scrollback; + `tuiMode: "regular"` restores the old behaviour. No baked default is set, so + the image inherits upstream's choice rather than silently pinning the fleet to + either one. If the fleet wants the old scrollback, that is a one-line settings + change, not a rebuild. + +- **pi-atelier `v0.10.3` (`ed3837b`) → `v0.13.0` (`34d26f1`)** — closes the + two-minor gap v1.9.5 named as the pi bump's residual risk. `peerDependencies` + are unchanged at pi `>=0.84.0` across v0.10.3, v0.12.1 and v0.13.0 — still a + floor, so still not evidence of anything; 1.0.0 satisfies it either way. What + was actually checked: + + - **v0.13.0 carries its own breaking change, unrelated to pi:** "the package + entry point now exports only the sidebar contribution protocol + (`registerSidebarPanel`, the ID and request guards, size limits, event + types). The internal registry and layout helpers are no longer exported." + That reaches nothing of ours — grepping `pi-atelier` and + `registerSidebarPanel` across mempalace-toolkit, pi-devbox, pi-extensions, + pi-fork, pi-observational-memory and pi-studio returns **zero matches in all + six**. atelier is a leaf here: it registers its own sidebar, and nothing + consumes its API. + - **Settings churn in the gap, checked against our own tree:** v0.12.0 removed + the `showSessionActions` setting (zero references here) and migrated the + Control Center shortcut Alt+A → F6 (zero references here, so no doc goes + stale). `showSidebarAgent` / `showSidebarTodos`, the only atelier keys README + names, are both still documented in v0.13.0's README. + - The TUI internals atelier patches (`TuiMainScreen`, `renderLayoutFrame`) are + both still present in pi 1.0.0's dist, and atelier's changelog shows it has + handled fullscreen vs regular renderers explicitly since 0.84 — so + fullscreen-by-default is terrain it already covers. + - **Residual:** v0.13.0 is a same-day upstream release (2026-10-02). + Acceptance proves the sidebar **paints** with the two-sided check from + 0.84.4/0.85.1 that can tell "loaded" from "silently absent" — "no crash" is + not the test. + - **Note for future bumps:** `v0.13.0` is an *annotated* tag, so + `git ls-remote --tags` reports the tag OBJECT (`dd06971`), not the commit. + The commit is `34d26f1`, via `ls-remote 'refs/tags/v0.13.0^{}'` — which is + what `check-doc-drift.sh` resolves and therefore what must be named here. + The gate caught the wrong SHA on the first attempt. - **`check-doc-drift.sh` now checks the pi-obsmem pin** against README's version-pin table, the same way it already checks pi, pi-atelier and @@ -239,9 +312,21 @@ and `Dockerfile.base` are both in the base hash, so this tag rebuilds the base ### Still open -- **pi 0.87.x + pi-observational-memory** — unchanged from v1.9.4: blocked on - upstream [PR #83](https://github.com/elpapi42/pi-observational-memory/pull/83) - (`shouldStopAfterTurn` → `finishTurn`); pi and pi-obsmem bump together. +- **pi 1.0.0 + pi-observational-memory, now adopted but not yet witnessed** — + the v1.9.4/v1.9.5 blocker (upstream + [PR #83](https://github.com/elpapi42/pi-observational-memory/pull/83), + `shouldStopAfterTurn` → `finishTurn`) is merged and pinned, and 1.0.0 measures + clean against every API we use. What remains is runtime proof, and it cannot + be had before the build: obsmem's `peerDependencies` are `*`, so an + incompatibility is silent — the workers simply stop capping turns. The newest + obsmem *tag* is still 3.1.4 (2026-09-20, before the merge), so this ships on a + pinned master commit; a 3.1.5 that tags the fix would let the pin become a + version again. +- **pi-atelier v0.13.0 and pi 1.0.0 are both days old** — adopted on measured + evidence (no breaking section, symbols present, no importers of the removed + exports), not on anyone's report of running them together. The three + first-boot acceptance asks carry both checks: workers **cap turns**, sidebar + **paints**. - **synlig hub** — upgraded to mempalace 3.10.0 on 2026-09-22T14:42:53Z (uv tool, hot backup first, 3 s downtime, 40996 embedding rows before == after). Client-visible: `event_list` without a cursor now returns newest first; diff --git a/Dockerfile.variant b/Dockerfile.variant index eb252d9..2e120dc 100644 --- a/Dockerfile.variant +++ b/Dockerfile.variant @@ -154,21 +154,48 @@ ARG USER_NAME=developer # (e7d77dc -> 1529e14 -> 731c3d4 in the nine days to 2026-10-01), so waiting for # a tag means holding pi indefinitely. A full SHA keeps the one property # `master` does not have: rebuilding this tag later produces the SAME image. -# SKIPPING 0.99.0/0.99.1/0.99.2 and 1.0.0, which all exist upstream: obsmem's -# only compatibility work names Pi 0.87 ("fix: support Pi 0.87 agent APIs", -# 2b1dc1c), and a repo-wide issue/PR search for "0.99" or "1.0" returns ZERO -# matches. Its peerDependencies are `*`, so nothing would refuse at install -# time and a 1.0.0 bump would fail silently at RUNTIME. 0.87.1 is the highest -# version the evidence actually covers; 1.0.0 is a separate round. -# pi-atelier v0.10.3 is deliberately NOT bumped here: its peerDependencies -# declare pi >=0.84.0 — a FLOOR, satisfied by 0.87.1 — on both v0.10.3 and the -# current upstream v0.12.1, so it spans this bump either way. It is the residual -# risk, because atelier hooks pi TUI internals (the `TuiMainScreen` prototype, -# `renderLayoutFrame`) that a declared floor does not protect, and a floor is -# exactly what failed to warn us at pi 0.84. Acceptance must confirm the sidebar -# still PAINTS — the same two-sided check used at 0.84.4 and 0.85.1, which can -# tell "loaded" from "silently absent". -ARG PI_VERSION=0.87.1 +# v1.9.5 SKIPPED 0.99.x and 1.0.0 for lack of evidence. v1.10.0 went and got the +# evidence instead of waiting for obsmem to mention a version, because "no issue +# names 1.0" is an absence of a statement, not a measurement. +# +# v1.10.0: 0.87.1 -> 1.0.0. MEASURED 2026-10-02 against the published npm +# tarballs for 0.87.1 and 1.0.0, unpacked side by side: +# 1. NO `### Breaking Changes` SECTION IN 1.0.0 AT ALL. The changelog's +# breaking sections belong to 0.87.0, 0.86.0, 0.84.3, 0.84.0, 0.83.0, +# 0.80.8, 0.80.7 and 0.75.0 — none to 0.88+..1.0.0. The major is a +# milestone (fullscreen default, leaner codemode), not an API break. The +# last break that touched us was 0.87.0's `shouldStopAfterTurn` removal, +# which v1.9.5 already absorbed. +# 2. `finishTurn` IS STILL IN 1.0.0's dist, so the obsmem SHA pinned below +# keeps the API it migrated to. (`shouldStopAfterTurn`: absent from both +# 0.87.1 and 1.0.0, as expected after its 0.87.0 removal.) +# 3. EVERY pi.* API our extensions call exists in 1.0.0's dist — all 8 of +# registerTool, registerCommand, registerFlag, getFlag, on, exec, +# sendMessage, sendUserMessage, extracted from mempalace.ts, the +# pi-extensions tree and obsmem's src/. +# 4. engines.node is `>=22.19.0` on both; the image ships 24.x. +# THE 0.99.2 CHANGE THAT LOOKED FATAL AND IS NOT: from 0.99.2 the DEFAULT MCP +# `exposure` is `codemode`, i.e. such tools are "neither declared to the model +# nor listed" and must be found with `searchTools()`. That would gut the +# MemPalace protocol if MemPalace were a builtin-MCP server. It is not: both +# mempalace.ts and mcp-loader.ts run their OWN MCP client and surface tools via +# `pi.registerTool()`, which is why they are named `mempalace_search` and not +# `mcp__mempalace__search`. Confirmed on a second route — settings.json has +# neither an `mcpServers` block (builtin, exposure-governed) nor an `mcp` block. +# Extension-registered tools are declared like built-ins, so `exposure` cannot +# reach them. +# WHAT IS NOT PROVEN, stated so acceptance does not mistake this for cleared: +# grepping dist shows the SYMBOLS survive, not that their SIGNATURES are +# unchanged — necessary, not sufficient. 1.0.0 is also four days of upstream old +# (published 2026-10-01T19:15Z) and neither obsmem nor atelier has a commit +# naming it. Acceptance must prove the obsmem workers CAP TURNS (peerDeps are +# `*`, so a mismatch is silent) and that the atelier sidebar PAINTS. +# USER-VISIBLE BEHAVIOUR CHANGE, deliberately NOT overridden here: 1.0.0 makes +# the TUI fullscreen by default, which replaces the terminal's normal +# scrollback. `tuiMode: "regular"` restores the old behaviour. No baked default +# is set, so the image inherits upstream's choice rather than silently pinning +# the fleet to either one. +ARG PI_VERSION=1.0.0 ARG PI_TOOLKIT_REF=main ARG PI_EXTENSIONS_REF=main # Repo URLs default to the canonical gitea origin but are overridable so a @@ -243,9 +270,35 @@ ARG PI_ATELIER_REPO=https://github.com/michaelmjhhhh/pi-atelier.git # the no-`npm install` reasoning above holds) and peerDependencies are still # pi >=0.84.0, so it still spans the pinned 0.85.1. 13 commits v0.10.1..v0.10.3, # all under src/ tests/ docs/ scripts/ plus metadata; no entry-point move. -ARG PI_ATELIER_REF=v0.10.3 +# +# v1.10.0: v0.10.3 -> v0.13.0, closing the two-minor gap v1.9.5 flagged as the +# residual risk of the pi bump. peerDependencies are UNCHANGED at pi >=0.84.0 +# across v0.10.3, v0.12.1 and v0.13.0 — still a FLOOR, so still not evidence of +# anything; the floor is satisfied by 1.0.0 either way. What was actually +# checked, 2026-10-02: +# - v0.13.0 CARRIES ITS OWN BREAKING CHANGE, unrelated to pi: "The package +# entry point now exports only the sidebar contribution protocol +# (`registerSidebarPanel`, guards, size limits, event types). The internal +# registry and layout helpers are no longer exported." Harmless HERE only +# because nothing of ours imports them: a grep for `pi-atelier` and +# `registerSidebarPanel` across mempalace-toolkit, pi-devbox, +# pi-extensions, pi-fork, pi-observational-memory and pi-studio returns +# ZERO matches in all six. atelier is a leaf here — it registers its own +# sidebar and no one consumes its API. +# - Settings churn in the gap, checked against our own tree: v0.12.0 REMOVED +# the `showSessionActions` setting (0 references here) and migrated the +# Control Center shortcut Alt+A -> F6 (0 references here, so no doc goes +# stale). `showSidebarAgent` / `showSidebarTodos`, the only atelier keys +# README names, are both still documented in v0.13.0's README. +# - The TUI internals atelier patches (`TuiMainScreen`, `renderLayoutFrame`) +# are both still present in pi 1.0.0's dist, and atelier's changelog shows +# it has handled fullscreen vs regular renderers explicitly since 0.84. +# - Residual: v0.13.0 is SAME-DAY upstream (2026-10-02). Acceptance proves +# the sidebar PAINTS with the two-sided check from 0.84.4/0.85.1 that can +# tell "loaded" from "silently absent" — "no crash" is not the test. +ARG PI_ATELIER_REF=v0.13.0 # Human-readable tag PI_ATELIER_REF was resolved from; recorded as a label. -ARG PI_ATELIER_VERSION=v0.10.3 +ARG PI_ATELIER_VERSION=v0.13.0 RUN set -e && \ # git_fetch_ref: clone-equivalent helper that accepts EITHER a branch name diff --git a/README.md b/README.md index ca2f893..78d7ca6 100644 --- a/README.md +++ b/README.md @@ -1106,7 +1106,7 @@ persisted volumes survived, and pi runtime wiring is intact: ```bash ./scripts/recreate-sanity-check.sh # auto-detects variant ./scripts/recreate-sanity-check.sh --expected-image-version 1.8.9 # assert the pi-devbox release tag -./scripts/recreate-sanity-check.sh --expected-version 0.87.1 # assert the pi coding agent version +./scripts/recreate-sanity-check.sh --expected-version 1.0.0 # assert the pi coding agent version ``` Those are **two different versions**, and the flags are not interchangeable: @@ -1145,9 +1145,9 @@ resolved to `latest` at build time: | Component | Pin | Where | |---|---|---| -| pi | `0.87.1` | `ARG PI_VERSION` — `Dockerfile.variant` | +| pi | `1.0.0` | `ARG PI_VERSION` — `Dockerfile.variant` | | pi-obsmem | `731c3d49288580f4d79cabdbfbc0d16b34db0f41` | `ARG PI_OBSMEM_REF` — `Dockerfile.variant` | -| pi-atelier | `v0.10.3` | `ARG PI_ATELIER_REF` — `Dockerfile.variant` | +| pi-atelier | `v0.13.0` | `ARG PI_ATELIER_REF` — `Dockerfile.variant` | | mempalace | `3.10.0` | `ARG MEMPALACE_VERSION` — `Dockerfile.base` | The objective is **not** to freeze versions. Bumping is routine — usually one