Skip to content

Refresh the pi-live lane pins and substrate assertions for the Pi 1.0 family - #830

Merged
clkao merged 26 commits into
mainfrom
spacedock-ensign/pi-live-lane-pin-refresh
Oct 6, 2026
Merged

clkao merged 26 commits into
mainfrom
spacedock-ensign/pi-live-lane-pin-refresh

Conversation

@clkao

@clkao clkao commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator

The Pi lane validated a superseded package family, and its configuration lived in the workflow where no test could reach it.

What changed

  • Pin the Pi CLI and both required extensions to the published family.
  • Move the family stamp into one Go source the workflow reads.
  • Move four inline scripts into one tested Go file.
  • Make an isolated Pi home discover both extensions.
  • Re-anchor the live Pi bindings to their active owners.

Evidence

  • Lane run 37189752489 at the 5a2ad16 tip: offline and pi-live success; 17 journeys plus smoke passed.
  • Race, local, uncached: 21/21 packages passed.

Review guidance

Five registered exceptions, two stale bindings, and four amended criteria whose lost guarantees the entity records.


mh

clkao and others added 23 commits October 5, 2026 08:53
Add the M1 isolated-home setup contract for Pi live runs: seedPiIsolatedHome
allocates piHome=<cleanHome>/.pi/agent, discovers the real installed
pi-subagents/pi-intercom roots from the real agentDir settings.json, links them
under piHome/npm/node_modules, and writes settings.json registering BOTH
npm:pi-subagents and npm:pi-intercom plus the Spacedock checkout as one absolute
path (never a file: entry). piLiveEnv scrubs both package-root variables by
default and forwards only nonempty explicit overrides; the retired sibling-root
helper is replaced by independent discovery, and the stale .ts source assertion
is dropped. Non-live helper tests cover discovery, the absolute/never-file:
settings composition, independent overrides, and the negative control.
…e smoke grade

The isolated-home smoke grade asserted neither that both extension tools
(subagent, intercom) were loaded nor that PI_SUBAGENTS_PACKAGE_ROOT and
PI_INTERCOM_PACKAGE_ROOT were absent, while the workflow exported both vars
into the run. Require both tools in the tool inventory derived from the run's
recorded toolCalls and reject either package-root variable, even empty.

Stop the install step exporting the two overrides via GITHUB_ENV so the smoke
runs native discovery; the current-checkout setup step now sets them
shell-locally to keep deliberately exercising the explicit-override path.
… host-home tests

Rewrite TestCodexProcessActivityResetsQuietBudget to supply activity through a
test-controlled clock/line-source seam (no real-sleep race, no machine-speed
assertion), isolating it from ambient CODEX_HOME/PI_CODING_AGENT and dropping the
version-dependent blank-cwd expectation from the survey sync e2e.
The pi-live lane carried the Pi family stamp (three version/integrity pairs
plus the compatibility floors) in several places and ran four inline Node
heredocs plus JS one-liners. Move the whole stamp and every piece of lane
logic into internal/pilive, exposed through the cmd/spacedock-pilive helper
the workflow builds and calls, so the workflow carries no version literal, no
integrity literal, and no JavaScript.

- pins refreshed from the npm latest dist-tag: pi-coding-agent 1.0.2,
  pi-subagents 0.75.0, pi-intercom 0.16.0 (captain named 1.0.1; the registry
  had moved to 1.0.2 by fetch time).
- install/pack-integrity/installed-version/manifest/settings-registration/
  compatibility-guard logic moved to Go with negative tests.
- duplicate stamp copies removed from internal/cli, internal/ensigncycle,
  docs/runtime-live-ci.md, and the deleted tautological fingerprint guard.
- one independent oracle: a live-tagged registry check that queries at check
  time and stores no copy of the numbers.
…ests

The reworked lane carries no stamp or JavaScript to assert structurally, and a
guard whose only failure mode is that the workflow text changed is the
tautological shape the captain forbade. Delete it; internal/pilive's
behavioural tests exercise the moved logic against real fixtures, and the live
registry oracle queries at check time.
Delete cmd/spacedock-pilive and expose its five lane commands (pins,
print-install, install, guard, verify-manifest) through cmd/spacedock-release,
so the lane builds one CI tooling binary instead of a second artifact. The
workflow and runtime-live-ci docs call spacedock-release; behaviour is
unchanged (same pins source, same install/guard/verify paths).

Collapse internal/pilive/runner.go into pilive.go: the split was only
organisational, so the external-process orchestration now lives in the single
package file.

Trim pilive_test.go: drop the parse-metadata accept case (restated its own
input; the pack-integrity test exercises the same mapping), fold the
directory-entry manifest case into the negative table, merge the Node floor
cases into the version-compare table, and make the compat-path test actually
exercise nested-then-global. Behavioural coverage and every negative case stay.
Merge internal/pilive/*.go and cmd/spacedock-release/pilive.go into a single
internal/pilive/pilive.go (pins + Command/install/guard/verifyManifest) with one
test file beside it; delete the folded cmd helper and the registry-oracle live
test. Behaviour and workflow calls are unchanged. Trim the two restating
discovery tests from pi_default_extensions_test.go.
Drop per-function comment blocks, dedupe the repeated read/unmarshal of
package.json and settings.json into readJSON, simplify mergeSettings to a
map[string]any round-trip, fold parseVersion into versionAtLeast, and cut
the test tables to one negative per checked behaviour. The workflow call
surface (install, guard, verify-manifest) and their exit codes and printed
output are unchanged.
…installed pi-ai, de-hollow tests

- mergeSettings keeps every existing packages entry (objects included) and
  appends only missing registrations; it no longer drops object entries.
- compatExportPath treats the installed nested pi-ai copy as authoritative: a
  nested copy without a valid ./compat export is fatal instead of falling
  through to a working global copy.
- Strengthen the settings, compatibility, and install tests with negative
  fixtures and exact npm-argument assertions so removing a check fails.
Replace the stripped-manifest fixture, which verifyManifest already rejected
for missing pi.extensions, with an otherwise valid manifest whose identity is
the only changed field. Require the version-mismatch and name-mismatch
diagnostics so deleting either check fails the assertion.
smallest-sufficient-mechanism and keep-moving-posture now pass on the pi
lane, so their pi XFAIL bindings are removed. The default-headless-gate-stop
pi binding named the retired gcmfwfjd9735b58sbzw7xsb8 and claimed to cover
the gate-lifecycle reds; the lane actually observed the worker-lifecycle
observation fault implementation-worker-not-dispatched, owned by
mk72bnt1b5hsp9sfv83979xs, so the binding and its comment are re-pointed.
Finding 11's structural-XPASS claim is false: the pi binding is gone and XPASSed before removal. Finding 5 is also obsolete — ssmGitCommitRe/committedDirectly were removed in 71d1f6b and assertSmallestMechanismDirect now verifies the strategy doc landed via git show HEAD:roadmap-strategy.md.
…liation

The journey list is derivable from the 17 spacedock:live-journey markers
in internal/ensigncycle, so docs/runtime-live-ci-registry.md was a
hand-maintained copy and the reconciliation test compared that copy to the
code. Remove both; keep the journey declarations and live tests.

Rescue the three non-registry checks that ran in CI into a surviving file
(runtime_live_lane_test.go): the common-suite run-shape and fail-fast
policy guards and the live-gap binding validator. Delete the two
registry-reading tests.

Update the two normative docs; leave historical sprint/review records
intact.
pi_auto_continue_double_dispatch_replay_test.go reads a captured Pi
stream from a hard-coded /tmp path and only requires
assertWorkerLifecycle to return no error. It asserts no extracted fact,
so a stub returning nil passes it, and it skips wherever the /tmp path
is absent. It has no falsifier.
Delete TestRetainedAtomicWorkerJourney (needs an operator-retained
workspace no workflow provides) and the live state-corpus proof check
(TestClassifierPrecisionRecallOnLiveCorpus plus its liveStateRoot
helper), neither reachable by any runner.

Add a focused codex-live step that runs
TestCodexIsolatedHomeCollaborationLifecycle with
SPACEDOCK_LIVE_CODEX_MULTI_AGENT=1 on the step env, so the codex
CLI multi-agent behaviour is exercised by the lane that has codex.
The codex-live step added in 2515a84 runs
TestCodexIsolatedHomeCollaborationLifecycle, but the named-evidence guard
requires every selected live test to be a registered claim owner. Add the
matching liveClaims entry so the guard accepts the deliberate runner.
The pi lane's journeys flip between runs (Pass/XFAIL) and two upper
layers removed bindings on offline evidence that did not predict live
behaviour. Re-bind them so the lane reports failures against an owner:

- keep-moving-posture: restore the pi binding removed by f37bda1.
- ac-value-reanchor: add a pi binding; it flips and was unowned.
- default-headless-gate-stop: re-point to penfp034pt9s3cgwp7wg3ykk,
  naming gate-hold-violation, gate-not-held, and
  implementation-worker-not-dispatched.
- auto-continue-after-implementation: re-point to
  s0gq9p69nztejw8xp3by4k7f, naming validation-worker-not-dispatched.
- owned-conflict-owner-handoff: re-point to psvqjf0w8xh2txp9604gsvmz
  for its XFAIL/XPASS flip.

keep-moving-posture keeps its claude-sonnet binding.

Restore a lean owner registry at docs/runtime-live-ci-registry.md: one
table of journey, owner, and observed failure/flake reason. It is a
hand-maintained convenience copy, not machine-checked; the bindings in
code remain the enforced record.
Drop the live:pi label precondition from pi-live's if; a pull request to
main now runs the lane. Keep the workflow_dispatch path unchanged, and add
the same '!= labeled' guard the sibling live jobs use so a label event does
not fire a redundant run.
The durable branch (runACValueReanchorJourney) called t.Fatalf on any
livescenario.Run failure, so it never consulted the journey's []liveJourneyGap
list: a durable failure on a bound target could not be owned and always redded
the lane. Extract the gap-aware verdict (liveScenarioGrade/finishLiveGrade) and
route the durable branch through it, so a durable failure with a matching
target+owner grades XFAIL like the ordinary path.
@clkao
clkao added this pull request to stack #832 October 5, 2026 20:51
clkao added 2 commits October 5, 2026 13:56
The pi-live job now runs on every pull request to main; the live:pi
label is no longer a precondition. Update docs/runtime-live-ci.md and
docs/site/contributing/architecture-notes.md to state that, keep the
unchanged workflow_dispatch live_cadence=pi path, and drop the stale
'Pi is opt-in per PR' / 'they do not run Pi' claims. Also note the lane
is not cheap: ~35 minutes and live model calls.
The workflow header claimed pull requests queue only Sonnet 5 and Codex
Luna. The pi-live job now runs on every pull request to main by default,
so correct the comment to name the Pi lane too. Comment text only: no
if:, job, step, or env changes.
…rneys, fix stale Pi model

- Remove the codex-live 'Run live Codex multi-agent lifecycle' step and its
  liveClaims entry; the credential refresh exposed a real follow-up target
  mismatch now owned by task phwzty950t2de11g4g7h95me.
- Bind four claude-sonnet journey failures to their active owner tasks with
  run-named comments: rejection-flow, auto-continue-after-implementation, and
  default-headless-gate-stop to jfdrr2dbdtt952s4cvvy74k8
  (completion-observation-gap); smallest-sufficient-mechanism to the same gap
  owner because its observed failure is smallest-mechanism-violation, not the
  uncommitted-entity-state failure.
- Fix the stale Pi model literal in docs/runtime-live-ci.md to gpt-6-luna:max,
  the value the single lane-model source pins.
@clkao
clkao merged commit c450d5d into main Oct 6, 2026
4 of 7 checks passed

This branch is waiting to be deployed

3 waiting deployments
CI-E2E — 33ef07cc Waiting Oct 6, 2026 by clkao via claude-live (pull-request, claude-sonnet-5, max, CI-E2E) #1262
CI-E2E-PI — 33ef07cc Waiting Oct 6, 2026 by clkao via pi-live #1262
CI-E2E-CODEX — 33ef07cc Waiting Oct 6, 2026 by clkao via codex-live #1262
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant