Author SHA1 Message Date
wassnameandPi/OpenAI 98769b01e2 Merge README updates and scope tests to current test directory
Preserve wassname User ask and screenshot layout; retain bundled install instructions. 71 current tests pass, lint/typecheck clean. Exclude local backups/worktrees from test discovery.

Co-Authored-By: Pi/OpenAI <288921227+claudypoo@users.noreply.github.com>
2026-09-10 18:46:46 +08:00
wassnameandPi/OpenAI 28374c0bb2 Prepare isolated trials with bundled dependencies loaded once
Validated generated profile and manifest after clean-checkout tests.

Co-Authored-By: Pi/OpenAI <288921227+claudypoo@users.noreply.github.com>
2026-09-10 18:42:42 +08:00
wassnameandPi/OpenAI 9cce6a6bee Remove abandoned runtime and keep current entry points and tests
Replace historical docs, trial output and dead runtime with current source, agent definition and reusable scripts. Bundle pinned worker, Intercom and scheduler dependencies via Pi manifest. Retain 71 current tests, including real RPC proposal/editor/Ready checks and evidence edge cases; lint/typecheck pass. Historical material remains available at f22d83c.

Co-Authored-By: Pi/OpenAI <288921227+claudypoo@users.noreply.github.com>
2026-09-10 18:40:23 +08:00
wassname (Michael J Clark) e3ccdbdb2f Update README.md 2026-09-10 18:29:34 +08:00
wassnameandPi/OpenAI f22d83cd50 Keep goal widgets compact by removing subtask lines
Preserve tasks in plan files; update README model illustration and prompt link. 176 tests pass, typecheck and lint clean.

Co-Authored-By: Pi/OpenAI <288921227+claudypoo@users.noreply.github.com>
2026-09-10 18:22:37 +08:00
wassnameandPi/OpenAI c175096ddb Restore automatic plan proposals and make goal commands explicit
Reduce unchanged upkeep and identity-only review noise; retain user README structure and screenshot with abridged terminal example. 174 tests pass; actual Herdr automatic proposal captured.

Co-Authored-By: Pi/OpenAI <288921227+claudypoo@users.noreply.github.com>
2026-09-10 18:12:38 +08:00
wassname (Michael J Clark) cabb4446aa Update README.md 2026-09-10 15:38:16 +08:00
wassnameandPi/OpenAI 1c927bf137 Record normal-profile installation and rollback paths
Co-Authored-By: Pi/OpenAI <288921227+claudypoo@users.noreply.github.com>
2026-09-10 13:44:07 +08:00
wassnameandPi/OpenAI 5cda3d6b1d Preserve byte-verification logs for functional trials
Co-Authored-By: Pi/OpenAI <288921227+claudypoo@users.noreply.github.com>
2026-09-10 13:42:18 +08:00
wassnameandPi/OpenAI ac6ef19e91 Integrate package-based supervision with explicit recovery and visible workers
Retain planning guidance and upkeep; use stock edxeth, Intercom and scheduled prompts. Verify with 162 tests and isolated Fireworks trials. Document unresolved upstream reload and scheduler limitations.

Co-Authored-By: Pi/OpenAI <288921227+claudypoo@users.noreply.github.com>
2026-09-10 13:42:00 +08:00
wassname2 cb35fbf1fe Research overnight supervision across harnesses and Pi packages 2026-09-10 11:43:48 +08:00
wassname2 fb5503f083 Prototype main-chat supervision with interactive edxeth workers 2026-09-10 10:03:40 +08:00
143 changed files with 1923 additions and 8884 deletions
+3 -3
View File
@@ -1,6 +1,6 @@
node_modules/
dist/
*.log
.local/
.pi/
docs/reviews/raw.jsonl
docs/reviews/err.txt
slop/
*.log
+26 -71
View File
@@ -1,80 +1,35 @@
# pi-goals contributor notes
## Design
The main chat discusses the plan with the user, then supervises an interactive `goals-worker` in Herdr. Use stock pi-subagents, pi-intercom and pi-schedule-prompt; do not build another transport, scheduler or worker runtime.
> the hope is we can have a smart supervisor like you, with judgment and context. But it doesn't use many tokens as it checks in and sees an overview.
>
> It steers a smaller model, adding perspective and judgment.
>
> Well, I want to see what the supervisor is thinking and saying. That's the whole point: all supervisor thinking and messages should be visible.
— wassname
- Keep supervisor inspection tools. It inspects actual results, delegates implementation and must not weaken the user's goal to accept worker output.
- Put all model-facing prompts in `src/prompts.ts`, in conversation order. Preserve the user's verbatim requirements.
- `/goals` opens actions. New plan starts a discussion without an objective form. Unknown commands never start planning. A changed settled draft opens the approval dialogue; unchanged discussion does not repeatedly reopen it.
- Keep goal titles/status in widgets; omit subtask text. Tasks and evidence remain in the plan.
- Keep startup/compaction plan context, short upkeep reminders and visible editable hourly check-ins. Avoid unchanged-plan repetition and identity-only review turns.
- Keep recoverable solo mode: confirm other writers stopped before taking over. Solo completion is self-verification.
- Record distinct runtime ID, Intercom ID and saved-session path with provenance. A handle or delivery receipt is not proof of liveness or action. User model changes are authorized; do not silently restore an old preference.
## Tests
Run `npm test` before a commit. It includes unit and flow tests plus the RPC review test.
Run `npm test`, `npm run typecheck` and `npm run lint` before committing.
- `test/*.test.ts` unit and flow tests use a small Pi API mock. They check plan state, tool gates, and plan-file updates.
- `npm run test:rpc` runs `test/rpc-review.test.ts`. It starts the installed Pi executable in RPC mode, uses Pi's real `select` and `editor` protocol, and uses a local deterministic HTTP model. It does not need a credential or spend API credits. This is the closest automated session test.
- Use tmux for visual TUI debugging when the RPC test fails or a terminal-only problem is reported:
`test/goals.test.ts` exercises current state, file updates and role restrictions with a Pi API mock. `test/rpc-review.test.ts` starts real Pi with a deterministic local model and schema-only worker tools: it checks automatic proposal, editor/discussion and Ready role transition without credits or launching workers. It does not prove Herdr rendering, live message delivery or model judgment.
```bash
tmux new-session -s pi-goals-debug 'cd /path/to/pi-goals && pi -e ./src/index.ts'
```
For functional acceptance, read `herdr --skill`, confirm `HERDR_ENV=1`, and use `scripts/prepare-trial.mjs` to create an isolated project/profile. Open only new no-focus test panes. Observe the actual planning dialogue and Ready selection, worker attachment, Intercom report, independent artifact inspection and CompleteGoal. Record interventions separately from autonomous success. Preserve nonempty byte/test evidence. Never reload or operate active user research panes. Close test panes when finished.
Run `/goals <objective>` in that pane. Tmux checks the rendered menu, editor focus, widget, and keyboard handling. RPC does not render the terminal UI.
- `pi -p` has no UI, so it cannot test `Ready`, `Refine`, `Edit`, or `Cancel`.
Known stock limits: stop workers before supervisor reload (later worker exit can crash its stale context); disabled scheduler jobs are deleted on reload/shutdown. Test saved-session/solo recovery without repeating completed work; do not claim these package bugs are fixed here.
## Functional acceptance: real Herdr workflow
Keep temporary plans, audits and captures under ignored `.local/`. Git history retains the removed historical material. Do not add root handovers or duplicate READMEs. Never touch human-named files or credentials.
Pi/OpenAI procedure, requested by wassname. Automated tests do not replace this check.
1. Read `herdr --skill` and confirm `HERDR_ENV=1`. Create a separate test pane with `--no-focus` and an isolated temporary Git repo. Never operate the user's existing worker or supervisor panes. Record the code revision and any uncommitted changes being tested.
2. Start real interactive Pi with this extension and an available real model. Use `/goals` with a trivial, bounded deliverable, for example `hello.txt` containing an exact line plus a saved byte-verification log. No GPU, dependencies or unrelated work.
3. Read the rendered planning conversation. Check that ordinary implementation details do not cause needless confirmation questions. Inspect the drafted plan and select Ready through the actual UI.
4. Confirm Ready opens a visible supervisor pane and the worker starts. Read both panes. Verify the supervisor's exact advice is visible, reaches the worker, and helps it progress toward the requested artifact. A delivery receipt alone is not proof.
5. Let the pair produce the artifact, save verification evidence, and complete the real ApproveGoal -> CompleteGoal sequence. Do not perform the task for the worker. Record any manual nudge as intervention, not autonomous success.
6. Inspect the artifact itself and its saved verification output. Check the final plan state and both sessions. Success means the requested result exists and the workflow completes, not merely that tests pass or messages were exchanged.
7. Exercise reload and supervision recovery in these test panes, preserving the current plan. Check planning exit too. Record commands available in the tested revision; do not claim unimplemented commands work.
8. When a stage fails, read both panes and the exact error before diagnosing it. Fix the cause, reload only the test instance, and retry the failed stage. After a prompt change, use a fresh task to verify changed behavior. Repeated status checks are not a repair.
9. Save pane captures, session paths, artifact paths, code revision, interventions and remaining failures under `slop/reviews/`. A wait-output timeout or match is only a signal to inspect the pane, not a pass/fail verdict. Report the observed result and gaps, not a test-count substitute.
Keep this check small and goal-focused. Its purpose is to expose real startup, UI, steering and completion failures, not to create another review loop. Only close test panes that you created.
## User intent for this branch
To be clear, the hope is we can have a smart supervisor like you, with judgment and context. But it doesn't use many tokens as it checks in and sees an overview.
It steers a smaller model, adding perspective and judgment.
It compacts every 150k or similar to avoid cost and context rot.
It has a goal / plan on a Ralph-loop-type repeat.
That lets the worker be a cheaper model, and the supervisor more expensive, and still get a good outcome.
Oh, and since it's two panes, the user can review both!
Well, I want to see what the supervisor is thinking and saying. That's the whole point: all supervisor thinking and messages should be visible.
So that should make it obvious that I need to see the messages, and the supervisor needs to use judgment. For example, it could say how we are tracking or whatever every time, and it would be useful, like in the recap.
And it would only be a few output tokens.
-- wassname (spelling and punctuation corrected by Pi/OpenAI)
## Supervisor behavior preferences
Recorded by Pi/OpenAI from wassname's instructions.
The supervisor's job is to supervise autonomously until the agreed goal is achieved and it has inspected the actual result. Elicit high-level judgment and perspective, not compliance with a detailed procedure. It should want to diagnose and fix problems through the worker, keep useful work moving, and avoid making the human drive progress.
Treat claims of being blocked, waiting, unable to proceed, or already done skeptically. Inspect the evidence, question assumptions, and look for authorized ways forward. Do not accept an excuse at face value or repeat status checks that cannot resolve it. Respect real dependencies and permission limits; skepticism does not authorize bypassing them. Seek justified confidence, not certainty at any cost.
User-authorized full-profile supervision: preserve normal Pi extensions and tools, including bash/edit/write and custom actions. Inspection-only is a role instruction, not a tool denylist or enforced sandbox. Repeat the division of work in the existing short opening: inspect and diagnose directly, delegate changes through SteerWorker, and do not take over implementation or alter shared state. Do not add per-tool reminders. Worker planning restrictions and approval checks are separate and unchanged. Validate the full profile in isolated parent-owned Herdr panes; automated tests do not prove role adherence or lifecycle recovery.
Keep the prompt generic. Do not prescribe pueue, Modal, worktrees, or a particular research setup. Explain the job and what deserves attention; let the supervisor choose useful checks. Tool requirements belong in tool descriptions. Administrative approval must not replace the requested deliverable.
Use `@monotykamary/pi-supervisor` as a behavioral reference, not an implementation to copy wholesale. Its outcome focus, autonomous continuation, and instruction not to repeat ineffective steering are useful. Judge our behavior in real sessions, not by test counts alone.
Pi/OpenAI implementation: each review repeats the short supervisor opening and current plan outcome, preferences, goals and discriminators, excluding task/evidence detail. Startup and compaction repeat the longer role prompt and full active plan before appendices/history. The long prompt asks the supervisor to read applicable AGENTS.md instructions and relevant skills rather than assuming project-specific preferences. Both forms preserve plan wording. Prompt inspiration: Anthropic's constitution (intent and autonomy) and @monotykamary/pi-supervisor (outcome focus and effective steering). Repetition supports judgment; it does not establish success.
Keep brief visible recaps that add judgment rather than repeat unchanged status. Preserve useful reasoning and evidence checks; reduce redundant context and reviews before reducing judgment. Manual checkbox changes are claims, not proof of completion. Plan edits should reach the supervisor so it can judge drift and direct corrections.
## Earlier supervision workflow discussion
I already have pi-intercom-supervisor, but thought using pi-subagents could make it simpler. The idea is that the user makes a plan as in pi-goals, but on this branch, instead of a naive stateless subagent, we 1) fork, 2) compact, and 3) make it a supervisor with a prompt as in pi-intercom-supervisor. The supervisor is cheap because it sees only high-level material, which costs fewer tokens. It has good judgement because it sees a) compacted planning context, b) the plan, and c) summarised context (for example, my modified pi-vcc). This lets it operate read-only and steer the worker without losing track. It also compacts every 100k tokens to keep it cheap and high-level.
I am now thinking the subagent implementation may be too difficult. To keep the plan and forking, this branch of pi-goals could make another Pi session, perhaps using the fork explicitly, and use pi-intercom or pi-messenger to communicate with it. The user can switch to it, or Herdr could open it automatically.
-- wassname
Branch instructions consolidated by Pi/OpenAI from wassname's preferences.
-3
View File
@@ -1,3 +0,0 @@
# ARCHIVED
Superseded by [pi-goals](https://github.com/wassname/pi-goals).
+136 -64
View File
@@ -1,98 +1,170 @@
# pi-goals
Plan in one Pi session, then do the work there while a stronger visible Pi session supervises it.
Make a short list of goals in one Markdown plan file. The main chat keeps the high-level context, supervises a worker in a visible Herdr pane, and checks whether each goal is complete.
## How it works
# User ask
1. `/goals <objective>` creates `.pi/plan/<session_id>-vN.md` and enters read-only plan mode.
2. Pi asks only material questions, writes the plan, and shows **Ready / Refine / Edit / Cancel**.
3. **Ready** opens a second Herdr pane. The new Pi session explicitly forks the planning session and compacts that fork.
4. The original session becomes the implementation worker. It keeps the full conversation and normal tools.
5. The fork becomes an inspection-only supervisor by instruction, with normal Pi tools and extensions available. Worker views and supervisor instructions travel over pi-intercom's extension channel, scoped to this plan pairing.
6. Ready waits for the supervisor's Intercom readiness message; the worker does not begin before the fork has compacted and started.
7. The supervisor compacts again when its context reaches 100k tokens.
8. The supervisor records a private approval only after it sees a stopped worker, no active work, a clean worktree (or an explicit inspected-state override), evidence, and saved verification output. `CompleteGoal` checks that approval against the exact plan block and Git tree before it ticks `[x]`.
The hope is we can have a smart supervisor, with judgment and context. But it doesn't use many tokens as it checks in and sees an overview from a cheaper worker.
The two Pi sessions are visible. You can switch to the supervisor pane and talk to it directly. Supervisor instructions are shown in full, including in collapsed tool rows; ordinary messages and emitted thinking use Pi's display settings. The supervisor is prompted to give brief progress assessments and use judgment about when to intervene.
The supervisor has a goal / plan that it agrees on with the user, and is reminded of it in a Ralph-loop-type repeat.
On same-process reload, monitoring is restored without removing normal or custom tools. Views include the latest human direction, source-session path, worker model, and new messages since the last acknowledged view. They report Pi idleness and tracked process/subagent activity separately. Unavailable trackers stay unknown; unregistered detached jobs are not tracked. Approval is blocked while tracked work is active or unknown. Intercom disconnects are reported; unsent current views and unacknowledged instructions are retained in Pi session history for reconnect. Incoming review/instruction payloads are saved in a bounded inbox before presentation. A receipt is sent only when Pi emits the corresponding user `message_start`: this confirms session acceptance, not model judgment or tool execution. Pending payloads survive reload, and manual-compaction success, failure or cancellation resumes delivery after Pi is idle. Unpresented incremental views are kept separately, not overwritten. The inbox limit is 64 messages; overflow is reported without acknowledging the new message. Crashes around acceptance/persistence or extensions that transform/consume input can still require inspection and explicit reconnect; end-to-end exactly-once execution is not guaranteed. Reviews stop after all goals are completed or cancelled, and both panes remain available. These mechanics are tested; useful judgment and savings from a cheaper worker still require a representative two-model run. -- Pi/OpenAI
It compacts every 150k or similar to avoid cost and context rot.
It steers a smaller model, adding perspective and judgment.
Since it's two panes, the user can review both, intervene in both and have visibility on sub-agent mis/communication.
-- wassname (spelling and punctuation corrected by Pi/OpenAI)
## Screenshot
Mock up:
```text
+-----------------------------------------------------------+-----------------------------------------------------------+
| SUPERVISOR | WORKER |
| | |
| Review .pi/plan/...-main.md | Task 2 — verify command run, real output saved: |
| > Ready Discuss Edit Cancel | - Exit code 0 (pass only) |
| | - evidence/verified.log (112 bytes) |
| [scheduled prompt: hourly check-in] | PASS: 9 bytes: verified + LF |
| | |
| The supervisor independently inspected both artifacts | Task 3 — plan evidence filled |
| before sign-off. | |
| | Completion report sent via Intercom to supervisor |
| Schedule: job wS79fJFPbB removed; | 01a089c9. My pane remains open for the supervisors |
| .pi/schedule-prompts.json shows 0 jobs. | independent inspection before sign-off. |
| | |
| ✓ verified.txt holds exactly the 9 bytes | ○ verified.txt holds exactly the 9 bytes |
| verified + LF | verified + LF |
| evidence/verified.log records a real byte check | evidence/verified.log records a real byte check |
| | |
| Agents · 1 running | [idle widget still shows its earlier snapshot] |
| verified-bytes-worker [goals-worker] | |
| | |
| > | > |
| astra · 50k tokens | terra · 200k tokens |
+-----------------------------------------------------------+-----------------------------------------------------------+
```
Real screenshot:
<img width="2513" height="1259" alt="2026-09-10_15-30-pi-goals" src="https://github.com/user-attachments/assets/35feaa15-f022-4491-bcc2-fc31cb878a9f" />
The plan file looks like this:
```md
## <short plan title>
<context: one short paragraph. What the human wants and why.>
### User-visible result
<one concrete sentence naming the final artifact or behavior the human will inspect>
### Preferences
- preferred worker model: <provider/model>
### User voice
- │ "<the human's requirement, quoted in full word for word (with spelling fixes)>"
### Goals
1. [ ] goal: <one short judgeable imperative outcome>
- subtle failure mode: <a way this could look done but isn't>
- discriminator: <the concrete observation that tells real success from that failure>
- tasks:
1. [ ] <subtask>
- evidence: (empty until sign-off)
### Future work / out of scope
### Log
### Interview (optional)
### Learnings (optional)
### Papercuts - problems, gotchas, suggestions (optional)
```
## Related work
Like [pi-milestones](https://github.com/Neuron-Mr-White/UniPi/tree/main/packages/milestone) and
[burneikis/pi-plan](https://github.com/burneikis/pi-plan), it guides rather than guards. The
reminder cadence is copied from [tintinweb/pi-tasks](https://github.com/tintinweb/pi-tasks) and the
resync-after-compaction from [tmonk/pi-goal-x](https://github.com/tmonk/pi-goal-x).
## Install
This branch requires Pi 0.85.1 or newer (before 1.0) and Herdr 0.7.5 or newer. Pi 0.85.1 supplies the public compaction-failure event and compaction-aware idle state used for delivery recovery. It reuses installed pi-intercom or loads its pi-intercom dependency when none is registered:
Requires Herdr. Includes [edxeth/pi-subagents](https://github.com/edxeth/pi-subagents), pi-intercom and pi-schedule-prompt. Disable separately loaded copies to avoid duplicate commands.
```bash
pi install npm:@wassname2/pi-goals
pi install git:github.com/wassname/pi-goals@experiment/main-supervisor-edxeth
```
The supervisor launcher uses the normal Pi profile: it inherits the agent directory/environment and discovers configured extensions, skills, prompt templates, themes and authentication. It explicitly loads this pi-goals source and forks the planning session with the supervisor role/model. Existing Intercom is reused when registered. The repeated role instruction says to inspect and diagnose directly, but delegate changes through `SteerWorker` rather than alter shared state. **This is not an enforced sandbox:** bash, edit, write and extension actions remain available; other extensions may have their own hooks or restrictions. Planning-mode restrictions and approval checks are unchanged. A complete supervisor role/binding is saved before startup compaction and restored before worker handlers can run, including fresh-shell `pi --session <saved-file>` and stopped supervisor forks. Older bootstrap markers are migrated only when their saved pairing is recoverable; incomplete identity fails visibly rather than selecting worker mode. Full-profile Herdr behavior still needs parent-owned functional acceptance.
Copy [`agents/goals-worker.md`](agents/goals-worker.md) into `~/.pi/agent/agents/`, then start a fresh Pi session.
For a local checkout:
Or for development:
```bash
pi -e .
git clone -b experiment/main-supervisor-edxeth https://github.com/wassname/pi-goals
cd pi-goals && npm install
pi -e ./src/index.ts
```
Run Pi from the Git repository that the plan will change. **Ready** fails if the current directory is not inside a Git repository; this prevents approval from checking the wrong repository.
## Use
## Commands
```text
/goals <objective> create a new plan
/goals model <model> select the visible supervisor model
/goals model use the remembered supervisor model
/goals work reconnect the existing approved worker pairing
/goals supervise reconnect from the saved supervisor session
/goals noplan exit planning, preserving the draft without approving work
/goals clear close the supervisor pane and disconnect the plan
```
/goals
```
`work` and `supervise` are role-aware recovery commands, not role conversion or new-pairing commands. Wrong or missing identities are rejected. `noplan` preserves the draft/history, leaves planning restrictions, and does not select Ready, start implementation or launch a supervisor. `/goals clear` closes the tracked pane and keeps the plan file. Starting another plan also keeps older versions.
`/goals` opens the action menu. New plan enters plan mode and starts a conversation; the objective is an optional seed. From there:
If a required model or supervisor is unavailable, the widget says **goals paused** and implementation/sign-off tools are gated. Human input, read-only diagnosis, `/model`, and recovery commands remain available:
1. Plan. The agent explores read-only and drafts the plan.
2. Review. After Pi settles, the full plan is printed in the transcript. Check that User-visible
result names the final artifact or behavior you expect. The menu offers Ready, Discuss, Edit, or
Cancel. Discuss continues the conversation. Edit opens the full plan in Pi's editor.
3. Work. Ready is the only review action that starts work. It opens the worker in a Herdr pane. The
worker ticks subtasks, appends to `## Log` and `## Learnings`, and fills `evidence:`. The supervisor
inspects the actual results and calls `CompleteGoal` when a discriminator is satisfied. They
communicate through pi-intercom. After eight turns without a change above `## Log`, the agent gets
an upkeep reminder. The supervisor also sets an hourly check-in through pi-schedule-prompt.
- `/goals reconnect` retries the remembered role model and existing supervisor binding. Worker readiness/reconnect waits allow five minutes, including an ordinary 60-second supervisor compaction, and never replace a slow or missing pane automatically. A returning peer clears the connection pause automatically; an established active worker pairing publishes a fresh current view so supervisor-only reload can resume review even when its previous view was already accepted.
- `/goals restart` explicitly closes only the tracked supervisor pane and starts a replacement for a working plan, preserving its file/version but invalidating old approvals. During planning it clears the failed pane so Ready can launch again.
- In the supervisor pane, use `/model` then `/goals supervise` (or `/goals reconnect`) to recover an unavailable supervisor model. Startup failure is reported to the waiting worker; it need not wait for the timeout to learn the cause.
Other commands: `/goals stop` pauses work; `/goals resume` continues it; `/goals exit` leaves goal
mode, preserving the plan. `/goals attach <path>` reconnects an existing plan. `/goals solo` lets the
main chat do the work after confirming other workers stopped; completion is then self-verification.
`/goals model <model-ref>` picks the worker model. `/schedule-prompt` manages check-ins.
Both sessions must load the updated transport for the request/reply reconnect fix; mixed-version peers are not a supported recovery configuration. Ready announces worker readiness only after its model is restored. Plan content is rechecked across startup/model-restore waits; changed content returns to review using the existing pane instead of starting different work. Clearing or leaving planning cancels its pending Ready attempt. `CompleteGoal` checks cancellation and the original binding/version after its asynchronous status lookup and before recording completion.
Stop workers before reloading the supervisor: the subagent package can otherwise crash it when a
worker later exits. The scheduler deletes disabled jobs on reload. Restart the saved Pi session and reattach the plan.
A new supervisor may still need up to five minutes for initial compaction. Recovery does not terminate background jobs. Planning/diagnostic command checks are guardrails, not an OS sandbox; loaded extensions and repository Git configuration must be trusted.
## Prompts
Model choices are remembered per project and role in `.pi/pi-goals/models/`. Use `/model` in planning, worker, or supervisor sessions to change that role's choice. Ready restores the worker choice after the planning fork is ready. An unavailable saved model stops the transition instead of substituting another. `/goals model <model>` explicitly overrides the supervisor choice for launch. -- Pi/OpenAI
You can read all the prompts in conversation order in [`src/prompts.ts`](src/prompts.ts).
## Inspected dirty-worktree approval
The supervisor can call `ApproveGoal` with `force: true` and a nonempty `reason` when preserved unrelated changes would otherwise prevent sign-off. It must inspect the changes first, not commit, reset or delete someone else's work. Force bypasses **only** cleanliness, never evidence, the current stopped view, active/unknown work, or exact goal/HEAD/tree checks.
The approval JSON stores the reason, NUL-delimited Git status, an index SHA-256 digest and per-dirty/untracked-file content SHA-256 digests (including modes, symlink targets and deletions). `CompleteGoal` requires the same state; even editing an already-dirty file without changing its status invalidates approval. Normal clean approvals behave as before. Git-ignored files and pi-goals' private plan/approval/model paths remain excluded. Dirty submodule/nested-repository directories or other unhashable paths fail closed; there is no recursive submodule override. Fingerprinting reads all included dirty/untracked bytes and can be expensive for large outputs; it does not lock concurrent writers.
A gate rejection is not automatically an experiment failure or a dependency of other authorized work. The supervisor should inspect the exact error and implementation, distinguish causes with a cheap check, and steer repairs plus safe independent progress instead of repeating an unproductive status check. -- Pi/OpenAI
## Plan format
Current goals belong above `## Log`; goal-shaped historical checklists below it are ignored by the widget, approval matching and sign-off. A goal is a checkbox line whose text starts with `goal:`:
```md
1. [ ] goal: Produce the report
- subtle failure mode: the report exists but uses stale data
- discriminator: the report cites the current input and the saved check confirms it
- verify: `just verify`
- evidence: (empty until sign-off)
```
The worker saves verification output in a nonempty repository file, adds that path to evidence, and commits it. The supervisor calls `ApproveGoal` with the inspected path; the worker then calls `CompleteGoal` with the exact goal text.
If context usage is unavailable, the supervisor warns once that its custom 100k compaction trigger cannot be checked. Pi's normal post-compaction `tokens: null` sample does not produce that warning; default auto-compaction is unchanged.
## Development
## Develop
```bash
npm test
pi -e ./src/index.ts # load locally; do not also load the installed copy
npm test # all unit, flow, and Pi RPC tests
npm run test:rpc # Pi RPC review flow with a local offline model
npm run typecheck
npm run lint
```
`test/intercom-broker.test.ts` checks readiness and exact message delivery through an isolated real Intercom broker. `test/rpc-review.test.ts` runs the planning review flow through Pi's real RPC protocol with a local deterministic model. The Herdr launcher and visible supervisor bootstrap have focused tests; use a real Herdr session for the final two-pane check.
To measure recorded usage since the latest planning start:
-- PI[gpt-5.6-sol]
```bash
node scripts/session-usage.mjs <supervisor.jsonl> <worker.jsonl>
```
This separates output, uncached input and repeated cached input. It excludes subprocess API calls. [Isolated Herdr test setup](scripts/prepare-trial.mjs).
## License
MIT
Branch-specific edits: Pi/OpenAI.
+25
View File
@@ -0,0 +1,25 @@
---
name: goals-worker
description: Implement the approved goal, save actual verification evidence, and report to the main-chat supervisor.
mode: interactive
async: true
session-mode: lineage-only
extensions: all
tools: all
skills: all
trust-project: true
inherit-append-system: true
auto-exit: false
parent-close-policy: continue
spawning: false
---
Implement only the goal delegated by the parent. Read the supplied plan and applicable AGENTS.md and skills. Preserve unrelated work. Use normal tools and extensions; this is not a stripped-down Pi profile.
Save the actual deliverable and verification output. Verify the outcome, not merely that a command ran. Ignored and uncommitted files are valid evidence. Do not clean or commit unrelated files to satisfy a Git-state gate.
Call AttachGoalPlan with the supplied absolute plan path. Send the supervisor an Intercom report with the artifact paths, verification performed, observed result, remaining uncertainty and any blocker. Use the exact supervisor session ID supplied in the task; confirm it in Intercom's session list. Investigate failures before declaring yourself blocked. Respect explicit user pauses. Do not approve your own goal or launch another writer. Completion approval belongs to the parent.
This worker uses a clean model context linked to the parent, not a full transcript fork. The parent supplies the approved plan and task. Send completion through Intercom and leave this pane open for follow-up messages. Do not call caller_ping, exit or shutdown: an unsent editor draft may exist even though it is absent from model context. Saved-session resume applies only after this session has stopped. If the user takes over interactively, follow their direction.
Prepared by Pi/OpenAI for pi-goals.
-66
View File
@@ -1,66 +0,0 @@
Let me get the diff to see what changed:
Now let me check the git history to see what changedNow I have full context. Let me verify the pi API behavior by checking the relevant source files to confirm the claims about `sendMessage`, `compact`, and event orderingNow I have all the context needed. Let me verify the `sendMessage` path more carefully:
I now have a complete picture. Here is the review.
---
## Code Review: ready menu — print plan + add "Ready + compact"
### Summary
The `agent_end` handler now prints the plan working set into the transcript before the menu, and adds a 4th option ("Ready + compact") that compacts the planning chatter away before the work turn. The logic is correct and well-considered, with one structural race and one stale-widget gap.
### Important (should fix)
- **`src/index.ts:~248` (the `agent_end` handler) — race: plan mode is turned off before compaction completes.**
`state = { ...state, isPlanMode: false }` executes before `ctx.compact()` is called (let alone finished). The compaction is fire-and-forget. If the human types and sends a message in the window between the state flip and the compaction callback firing, the agent starts a turn in normal mode *without* the work instruction. The work instruction arrives later (via `sendUserMessage` in `onComplete`/`onError`), triggering a second, redundant turn.
The window is small (compaction is fast) but the behavior is undefined — the agent could start executing before the work instruction lands.
**Fix**: flip `isPlanMode` inside the callbacks, not before. Move `state = { ...state, isPlanMode: false }; persist(); updateWidget(ctx);` into both `onComplete` and `onError`, and also into the non-compact branch (where it already is, effectively). The `work` string can be defined before the branch.
```typescript
if (!choice.includes("compact")) {
state = { ...state, isPlanMode: false };
persist();
updateWidget(ctx);
pi.sendUserMessage(work, { deliverAs: "followUp" });
return;
}
ctx.compact({
customInstructions: `...`,
onComplete: () => {
state = { ...state, isPlanMode: false };
persist();
updateWidget(ctx);
pi.sendUserMessage(work, { deliverAs: "followUp" });
},
onError: (e) => {
ctx.ui.notify(`Compaction failed (${e.message}); starting work anyway.`, "warning");
state = { ...state, isPlanMode: false };
persist();
updateWidget(ctx);
pi.sendUserMessage(work, { deliverAs: "followUp" });
},
});
```
This also means the widget stays in "planning" mode during compaction, which is truthful — compaction hasn't finished yet.
### Suggestions
- **`src/index.ts:~248` — widget not refreshed after `$EDITOR`.**
When the human chooses "Open in $EDITOR", `spawnSync` blocks, then `continue` re-enters the loop. The plan is re-read and potentially re-printed, but `updateWidget` is not called. If the human changed goal statuses (e.g. ticked a checkbox), the widget stays stale until the next `turn_end`.
Add `updateWidget(ctx);` after the `spawnSync` line (or inside the `continue` branch before the continue).
- **`src/index.ts:~248` — `spawnSync` blocks the event loop.**
`spawnSync(process.env.EDITOR || ...)` is a synchronous blocking call. While the editor is open, no async work (including compaction from a previous iteration, timers, etc.) can proceed. This is fine for a local TUI tool, but worth noting — if the editor hangs or the human walks away, the entire pi process is frozen.
### Positive
- **De-duplication is correct.** `printed` is a local variable, fresh per `agent_end` call, and correctly suppresses re-printing when the working set hasn't changed across editor passes. The `while` loop exit condition (`scanGoals(...).length > 0`) correctly handles the human deleting all goals in the editor.
- **String matching is safe.** `choice?.startsWith("Ready")` gates both Ready options, then `choice.includes("compact")` distinguishes them. The word "compact" appears only in the "Ready + compact" string. No ambiguity.
- **Both compaction callbacks queue the work turn.** `onComplete` and `onError` both call `pi.sendUserMessage(work, ...)`. A failed compaction does not strand the session — work starts anyway, with a notification.
- **`session_compact` → `resyncReason` → injection chain is correct.** The pi source confirms `session_compact` fires (and is awaited) *before* `this.compact()` resolves and `onComplete` fires. So `resyncReason` is set before the next LLM call, and the full plan file is re-injected. The compaction summarizes away the exploration; the plan itself survives.
### Verdict
**REQUEST CHANGES** — the race between `isPlanMode = false` and compaction completion is a real timing bug that can cause the agent to start a turn without the work instruction. The fix is straightforward: move the state flip into the callbacks.
-22
View File
@@ -1,22 +0,0 @@
You're right on both counts. Let me trace through each.
**Finding 1, withdrawn.** Keeping `isPlanMode` true during compaction would mean any message the human sends while compaction runs gets processed in plan mode: blocked tools (`tool_call` hook), a "You are still in plan mode" injection (`context` hook), and a second Ready menu on `agent_end`. The current order (flip first, then compact) means that same message is processed in work mode — the destination the session is heading to. The cost is at worst one redundant turn when the `onComplete` follow-up lands. Your order is the correct one.
**Finding 2, withdrawn.** `updateWidget` with `isPlanMode === true` hits the early return that sets two fixed strings already on screen. It is a pure no-op.
---
## Code Review: ready menu — print plan + add "Ready + compact"
### Summary
The `agent_end` handler now prints the plan working set into the transcript before the menu, and adds a 4th option ("Ready + compact") that compacts the planning chatter away before the work turn. The logic is correct and well-considered.
### Positive
- **De-duplication is correct.** `printed` is a local variable, fresh per `agent_end` call, and suppresses re-printing when the working set hasn't changed across `$EDITOR` passes. The `while` loop exits cleanly if the human deletes all goals in the editor.
- **String matching is safe.** `choice?.startsWith("Ready")` gates both Ready options, then `choice.includes("compact")` distinguishes them. The word "compact" appears only in the one label.
- **Both compaction callbacks queue the work turn.** `onComplete` and `onError` both call `pi.sendUserMessage(work, ...)`. A failed compaction does not strand the session.
- **The `session_compact``resyncReason` → injection chain is correct.** The pi source confirms `session_compact` fires (and is awaited) before `this.compact()` resolves and `onComplete` fires. The full plan file is re-injected on the next LLM call; the compaction summarizes away the exploration, not the plan.
- **The state-flip-before-compaction order is deliberate and correct.** Flipping `isPlanMode` first means any message the human sends during compaction is handled in work mode, not plan mode (where tools would be blocked and a contradictory injection would fire).
### Verdict
**APPROVE** — no bugs found. The two concerns raised initially were incorrect; the code handles the interleaving correctly.
-31
View File
@@ -1,31 +0,0 @@
I only have a file-read tool here, so Ill start from the repo files I can open and look for the plan-versioning and judge-related changes.Continuing through the judge path and tests.Reading the rest of the judge prompt and the tests that cover these behaviors.Looking for the test files.Trying common test filenames under `src` and `test`.Checking other likely files mentioned in the README.I couldnt run `git diff` (no shell tool). From the files I could read, these are the concrete defects against the required behaviors:
**1. Uncommitted conflict markers in `README.md`**
The working tree still has `<<<<<<< Updated upstream` / `=======` / `>>>>>>> Stashed changes` (and a truncated upstream judge sentence). That is not a reviewable change set.
**2. Judge “checked artifacts” gate is too brittle**
`decideSignOff` only accepts:
```ts
/^#{0,6}\s*(?:\*\*)?checks(?:\*\*)?:\s*\n(?:[-*]\s+.+\n?)+\s*VERDICT:/im
```
The prompt asks for a `checks:` heading plus bullets, then **exactly two lines**:
```
VERDICT: accept | reject
missing: ...
```
Any extra blank line, `Checks` with other wrapping, or a sentence between the last bullet and `VERDICT:` rejects a real accept. Thats stricter than “must show artifact quotes,” and can fail a judge that did the right thing.
**3. Grill-me vs Ready is prompt-only**
`Grill me` sets `skipReadyMenu` for **one** `agent_end`, then the next turn with any goal lines shows Ready again. Nothing checks that the understanding question was asked **and answered**. If the model asks and offers Ready in the same turn, or the human never replies, Ready is still offered. Required: no Ready until that question has completed.
**4. Legacy unversioned plans are dropped with no migration path in code**
Only `<session_id>-vN.md` is selected; `planVersion` restore is the only resume hook. Thats the intended break, but I found no test that old `.pi/plan/*.md` names stay unused and that a new `/goals` always writes a fresh `-vN` without rewriting prior files.
**5. Could not verify the focused tests or `git diff`**
No test file opened (`src/index.test.ts`, `test/*.test.ts`, etc. all missing from this view). I could not confirm coverage for version reservation, visible plan print, grill-me sequencing, or reject-accept-without-checks.
I would **not APPROVE** this set as-is. Fix the README conflicts, tighten grill-me so Ready stays suppressed until after the human answers, and either loosen the checks regex to the documented “quotes present before VERDICT” rule or lock the exact judge format in a test.
-41
View File
@@ -1,41 +0,0 @@
I only have the `read` tool available, so let me locate the changed files by probing the repository structure.The extension source is clear. Let me verify the pi API usage (`sendMessage` with `customType`/`display`, `appendEntry`, `getSessionId`, `ctx.compact`) against the pi docs, since several required behaviors hinge on them.I can't run `git diff` or the test suite — this review environment only exposes a `read` tool, and the test directory can't be enumerated (every probe under `test/` returned ENOENT, and directories can't be listed). So I reviewed the changed files directly in the working tree (`src/index.ts`, `src/prompts.ts`, `README.md`, `scripts/check-judge-footprint.sh`) against the five required behaviors, and verified every pi API the behaviors depend on (`pi.sendMessage` with `customType`/`display`, `pi.appendEntry` restore via `session_start`, `pi.sendUserMessage` followUp, `ctx.compact` with onComplete/onError) against the installed pi docs. Findings below.
## Defects
**1. `/goals` arg parsing swallows ordinary objectives — src/index.ts, `/goals` handler**
```ts
if (arg.startsWith("judge")) {
```
Any objective whose first word is "judge" — e.g. `/goals judge the vendor options`, `/goals judge readiness of the export` — is treated as the judge-model subcommand: it sets `judgeModel` to "the vendor options" and **does not reserve a new `.pi/plan/<session_id>-vN.md`**, violating "every ordinary `/goals` invocation reserves a new file". Same class of issue for an objective that is exactly `clear` (deletes the plan instead of planning). Use exact-match subcommand parsing (`arg === "judge"` / `arg.startsWith("judge ")` at minimum, and even then an objective like "judge model quality" is unreachable — a `:` or `--` separator would be safer).
**2. The checked-artifact-list regex false-rejects compliant judges — `decideSignOff`, src/index.ts**
```ts
const checks = /^checks:\s*\n(?:-\s+.+\n)+VERDICT:/im.test(judge.output);
```
This requires the last `- ` bullet to be *immediately* followed by `VERDICT:` with no blank line, and requires the heading to be exactly `checks:` at line start. Nothing in `judgeSystem` tells the judge not to separate sections with a blank line (models habitually emit `…bullet\n\nVERDICT: accept`), and a judge writing `## checks:` or `**checks:**` also fails. Result: a valid accept *with* a real checked-artifact list is rejected, and the working agent gets a "Missing: checked-artifact list" reply it already satisfied — a retry loop against a nondeterministic judge. It's fail-closed (never accepts without the list, so the hard requirement holds), but as written it will produce systematic false rejects. Allow optional blank lines / formatting, e.g. `/^#*\s*checks:\s*\n(?:[-*]\s+.+\n)+\s*VERDICT:/im`.
**3. Judge transcript files collide within the same minute — CompleteGoal `execute`, src/index.ts**
```ts
const rel = `.pi/judge/${stamp().replace(/[: ]/g, "-")}.md`;
```
`stamp()` has minute resolution, so two sign-offs in the same minute (two goals signed off back-to-back — the common case) write the same `.pi/judge/<stamp>.md` path and the second silently overwrites the first's full transcript, contradicting "every run saves the judge's full transcript … referenced from the log line" (both log lines then cite one file containing only the second run). Add seconds or a short unique suffix.
## Minor / cosmetic
- Misindented closing `}` of the `if (!checks)` block in `decideSignOff` (extra indentation on the `}` line) — likely flagged by `biome check src/`, which `prepublishOnly` runs.
- In plan mode, if the agent drafts a plan with no recognizable `goal:` checkbox line, the `agent_end` `while (scanGoals(...).length > 0)` loop never shows the Ready menu and plan mode can't be exited via the menu; the "no recognizable goal line" nudge in `dueInjection` only fires in the *non*-plan-mode branch. Not one of the five required behaviors, but a reachable dead end (escape hatch is `/goals clear`).
## Behaviors verified as correct
- **Versioning**: each ordinary `/goals` writes a fresh `<session_id>-vN.md` (empty reservation) via `nextPlanVersion` (max+1, so no clobbering); prior versions are never touched; legacy unversioned names are ignored by `nextPlanVersion` and never read — consistent with the intentional breaking change. `planVersion` is persisted via `appendEntry` and restored in `session_start`, so it survives resume/reload.
- **Visible plan before Ready**: `pi.sendMessage({ customType: "plan", content: plan, display: true })` fires before `ctx.ui.select(...)`, and re-prints inside the `$EDITOR` loop when the text changed. `sendMessage`+`display: true` is the documented visible-transcript mechanism.
- **Grill me**: sets `skipReadyMenu`, queues the single understanding-check question as a followUp user message, and consumes the skip at the next `agent_end` — so no Ready offer exists between asking the question and the human's reply being processed. `skipReadyMenu` is persisted, so it survives resume mid-grill.
- **Judge**: `buildJudgeArgs` yields `pi -p --no-session --no-extensions --tools read,grep,find,ls --exclude-tools edit,write`; `judgeUser` embeds the complete plan file; `judgeSystem` demands per-artifact verbatim quotes framed as an inspectable record ("not hidden reasoning", "no bullet for a file you did not open"); an accept without the `checks:` list is rejected in `decideSignOff` (subject to defect 2); full transcript persisted per run (subject to defect 3).
Main caveat: I could not execute `git diff` or `npm test` here, so I can't confirm the exact diff boundaries or that the focused vitest cases (judge argv invariants, `appendLog`, `decideSignOff` fail-forward) pass — defects 13 are from source inspection, not reproduced runs. Not approved as-is; defects 1 and 2 are worth fixing before merge.
-62
View File
@@ -1,62 +0,0 @@
Code review against spec `docs/spec/2026-06-15_pi-goals.md`.
---
### (A) SPEC MISMATCH — code does not match spec intent
1. **No loop judge** (spec §9, §3b). The extension lacks any perturn evaluation that would decide continue/pause; the loopjudge prompt (`loopJudgeSystem`, `loopJudgeUser`) is defined but never invoked. No motion.
2. **`/goal` command missing** (spec §7). No handler for `/goal` (restart loop, pause, resume, clear, status). The only command is `/plan`.
3. **`/subgoal` command missing** (spec §7). Not implemented.
4. **`CancelGoal` tool not implemented** (spec §5, optional but present in spec). Not a blocker but a gap.
5. **Planphase model selection (D12) not implemented**. `planDrafting` always runs on the default model; there is no sticky perphase model choice, no selection menu, and no persisting of a planphase model reference.
6. **Widget does not flag `done` goals that lack a signoff log line** (spec §7, §6). The widget hides all done goals unconditionally; the visibility guard is missing.
7. **`/plan` (no args) does not render the tasklist widget** (spec §7). `showPlan()` dumps raw file content via `notify`; the widget is only set through `updateWidget()` on other events, not by the command itself.
8. **Injection message role** (spec §11). The `before_agent_start` hook returns a `customType` message with `display: false`. The spec demands a **late userrole message** to avoid systemprompt mutation; the actual message role depends on the pi API and may be system, not user, risking cache breakage.
9. **Missing precompact hook** (spec §8). No `precompact` hook to flush any inmemory state (even just ensuring `plan.md` is uptodate) before compaction.
10. **Reminder cadence deviates** (spec §8a). The spec calls for firing after N filemodifying turns since last `plan.md` update. The code fires if `plan.md` is byteidentical between agent starts, which is a coarser proxy.
---
### (B) DEAD/UNUSED CODE
| File | Lines | Reason |
|------|-------|--------|
| `src/prompts.ts` | 128146 | `loopJudgeSystem` and `loopJudgeUser` exported but never used. |
| `src/prompts.ts` | 115118 | `continuation` exported but never used (the loop is not built). |
---
### (C) OVERLY LONG OR REDUNDANT COMMENTS
The fileheader comments in `index.ts` (lines 120) and `planfile.ts` (lines 126) are fairly concise descriptions of the design; they are not excessive. **No comment bloat worth flagging.**
---
### (D) OVERENGINEERING vs. “super simple” goal
None. The linescanner in `planfile.ts` is minimal; the `getPiInvocation()` helper is a straightforward copy from the oracle extension; no unnecessary abstraction or defensive layers.
---
### (E) REAL BUGS
- **`cmdCtx.newSession` cast risk** (src/index.ts:272, 201).
`reviewLoop` casts `ctx` (type `ExtensionContext`) to `ExtensionCommandContext` to pass to `startExecution`, which calls `cmdCtx.newSession(...)`. If the concrete context does not carry that method, it fails at runtime. (In practice the same object may satisfy it, but the cast hides the truth.)
- **`showPlan` raw content instead of widget** (src/index.ts:136143).
`/plan` with no arguments shows the file content via `ctx.ui.notify`, not the structured tasklist widget the spec expects. The widget is rendered separately via `updateWidget`, but the command does not trigger it, so the output is inconsistent.
No other obvious logic errors; the signoff flow, logging, and parsing work as intended.
---
**Verdict:** A clean scaffold for the signoff path, but missing the autonomous loop, `/goal` command, and planphase model selection means its not yet the “work autonomously” extension the spec describes.
@@ -1,25 +0,0 @@
# Verification: state-aligned planning mode
## Commands
```text
$ npm test
Test Files 8 passed (8)
Tests 29 passed (29)
$ npm run typecheck
> tsc --noEmit
$ npm run lint
Checked 8 files in 17ms. No fixes applied.
$ git diff --check
```
## Read
[test/goals-flow.test.ts](../../../test/goals-flow.test.ts) covers the visible plan before Refine, an editor prompt before a Refine revision turn, exact multiline Refine notes in `## Interview`, Ready as the only work handoff, Pi editor then Cancel, phase restoration, planning snapshot, writable plan path, allowed `pwd && ls && git log` and `cd . && ls -la`, blocked pipe, and blocked `CompleteGoal`.
[test/prompts.test.ts](../../../test/prompts.test.ts) locks the prompt instruction to inspect repository facts or search the web only when it can resolve a fact, ask a short self-contained batch of high-impact questions in the human's language with recommendations, and forbid placeholder goals.
[test/rpc-review.test.ts](../../../test/rpc-review.test.ts) starts the installed Pi RPC executable with [offline-model.ts](../../../test/fixtures/offline-model.ts), selects Refine through Pi's real dialog protocol, receives the editor request before the revision call, then submits notes and observes the revision call. The test uses a local HTTP model, so it spends no API credits.
@@ -1,33 +0,0 @@
# Plan flow and judge review
- [x] goal: Each new `/goals` draft uses a fresh session-plan version
- [x] Persist the selected `-vN` name so resume, reminders, Ready, and sign-off use one file.
- [x] Keep earlier versioned files unchanged.
- [x] Reserve `--clear` and `--judge` for commands so normal objectives are always new drafts.
- failure mode: a second `/goals`, including an objective that begins with `judge`, changes the earlier plan or does not make a draft.
- deliverable: [goals-flow.test.ts](../../../test/goals-flow.test.ts) shows an unchanged legacy file and `v1`, new `v2`, and `judge the vendor options` in new `v3`.
- [x] goal: Plan review asks and displays the needed context
- [x] Add `Grill me` to the Ready menu and queue an understanding-check interview turn.
- [x] Keep one short goal subject with its full indented context block.
- [x] Keep visible plan output before the Ready dialog.
- failure mode: Grill me starts work or the plan is only hidden in an edit call.
- deliverable: [goals-flow.test.ts](../../../test/goals-flow.test.ts) records display before dialog and the grill follow-up.
- [x] goal: Judge review is visible without being confused with agent evidence
- [x] Require concise observed checks before the verdict.
- [x] Save the full judge reply under a unique path and link it from the plan log.
- [x] Accept a headed check list with normal Markdown spacing, but reject an accept with no list.
- failure mode: provider-private reasoning is claimed as evidence, the review is not inspectable, or a correct judge reply is rejected for blank-line formatting.
- deliverable: [decide-signoff.test.ts](../../../test/decide-signoff.test.ts) locks the checked-artifact review contract, including a Markdown heading and blank line before the verdict.
## UAT / Verification
Observed 2026-08-24: `npm test` reported `Test Files 6 passed (6)` and `Tests 22 passed (22)`.
`npm run typecheck`, `npm run lint`, and `git diff --check` exited 0. The focused flow test proves
plan versioning, visible plan-before-dialog ordering, Grill me behavior, and objectives beginning
with `judge`.
## Appendix (context, not approved)
Issue #1 has a 600 second judge timeout now. The judge stays a separate read-only `pi -p --no-session` subprocess. Intercom is unsuitable because it has no equivalent isolation boundary.
External review: [Kimi K3](../../reviews/pi-goals-kimi-k3.md) found the command-prefix, check-list formatting, and transcript-path defects; all were fixed. [Grok 4.6](../../reviews/pi-goals-grok-4-6-retry.md) confirmed the check-list concern. Its Grill me concern does not apply: `skipReadyMenu` suppresses the menu after the generated follow-up, and the next `agent_end` follows the human reply.
@@ -1,53 +0,0 @@
# State-aligned planning mode
Pi-goals will use pi-plan's small phase model. The UI, tool gate, and agent context will read the same persisted phase. Planning still keeps pi-goals' judgeable goals, direct user quotes, and interview record.
- [x] goal: Planning state survives restart and matches the UI and agent context
- [ ] Replace `isPlanMode` and `skipReadyMenu` with persisted `phase: planning | working`.
- [ ] Render the planning widget, inject the hidden planning-state snapshot, and restore state from that phase.
- [ ] Restore the snapshot after restart or compaction without repeating the full drafting prompt every turn.
- subtle failure mode: the UI says planning but a resumed or compacted agent sees work mode.
- discriminator: a flow test restores planning and observes the planning snapshot; working has neither.
- evidence: [goals-flow.test.ts](../../../test/goals-flow.test.ts) restores persisted planning state and observes `[PLANNING MODE]`; [verification](../audit/20260826_pi-plan-aligned-planning.md) records `25 passed`.
- [x] goal: Planning blocks implementation while allowing fact finding
- [ ] Allow writes only to the active plan file.
- [ ] Block implementation tools, `CompleteGoal`, and bash write or pipe attempts with a planning-mode explanation.
- [ ] Allow ordinary read-only inspection commands such as `pwd && ls && git log`.
- subtle failure mode: an agent marks a goal active or changes project code before approval.
- discriminator: flow tests reject each work route and allow the inspection command.
- evidence: [goals-flow.test.ts](../../../test/goals-flow.test.ts) asserts allowed `pwd && ls && git log`, blocked pipe, non-plan write, and `CompleteGoal`; [verification](../audit/20260826_pi-plan-aligned-planning.md) records `25 passed`.
- [x] goal: Planning interviews and revision notes are durable user evidence
- [ ] Teach the planning prompt to ask each independent, high-impact user-decision frontier with a recommendation, while researching facts itself.
- [ ] Keep typed answers and `Refine` editor notes verbatim under `## Interview`.
- [ ] Exempt `## User voice` and `## Interview` from working-set line pressure.
- subtle failure mode: the plan silently assumes preferences or loses a revision note.
- discriminator: a flow test opens Refine and finds its exact multiline text in `## Interview`.
- evidence: [goals-flow.test.ts](../../../test/goals-flow.test.ts) matches the exact multiline Refine note under `## Interview`; [verification](../audit/20260826_pi-plan-aligned-planning.md) records `25 passed`.
- [/] goal: The settled plan review is concise and cannot start work accidentally
- [ ] Use `agent_settled` to visibly print the full plan, then offer `Ready`, `Refine`, `Edit`, and `Cancel`.
- [ ] Ready alone sends the work handoff. Refine sends one explicit revision turn. Edit opens Pi's full-plan editor. Cancel leaves planning.
- subtle failure mode: a review choice queues an unrequested agent turn or hides the plan below the dialog.
- discriminator: flow tests show plan before the menu and distinguish all four actions.
- evidence: [goals-flow.test.ts](../../../test/goals-flow.test.ts) shows plan before the menu and isolates Ready as the work handoff; [verification](../audit/20260826_pi-plan-aligned-planning.md) records `25 passed`. Pending human Pi TUI check.
- [x] goal: Planning resolves facts, interpretation, and approval before overnight work
- [x] Use repository inspection or web search when either can resolve a discoverable fact.
- [x] Require human confirmation for the agent's interpretation, unresolved task or outcome, scope, and decisions needing later approval.
- [x] Batch independent high-impact questions with the needed context, the human's terms, ASD-STE100 language, and a recommendation.
- [x] Ban placeholder goals such as "work out the thing" before the plan review menu.
- subtle failure mode: the plan has a formal discriminator but silently chooses an editorial direction or other human decision.
- discriminator: [prompts.test.ts](../../../test/prompts.test.ts) locks the research, clarification, approval, question-batch, and concrete-goal rules in the model prompt.
- evidence: [prompts.ts](../../../src/prompts.ts) makes research conditional on whether it can resolve a fact, then requires human confirmation and approval before Ready. [prompts.test.ts](../../../test/prompts.test.ts) checks those requirements. [verification](../audit/20260826_pi-plan-aligned-planning.md) records `29 passed`.
- [x] goal: Refine waits for text in Pi's real dialog protocol
- [x] Run Pi in RPC mode against a local no-cost model.
- [x] Select Refine, observe the editor request, then submit text and observe the revision turn.
- subtle failure mode: a mocked editor hides a Pi RPC ordering defect, so Refine starts a turn before the human can type.
- discriminator: [rpc-review.test.ts](../../../test/rpc-review.test.ts) uses Pi's `extension_ui_request` and `extension_ui_response` protocol and observes two model requests before editor input, then the third revision request after it.
- evidence: [rpc-review.test.ts](../../../test/rpc-review.test.ts) starts the installed Pi executable plus [offline-model.ts](../../../test/fixtures/offline-model.ts), with no credential or network dependency. [verification](../audit/20260826_pi-plan-aligned-planning.md) records its pass.
## UAT / Verification
`npm test`, `npm run typecheck`, and `npm run lint` pass. Read [test/goals-flow.test.ts](../../../test/goals-flow.test.ts): its assertions must show a restored planning phase, visible plan before review, exact recorded refinement, blocked work routes, and a work message only after Ready.
## Appendix (context, not approved)
Accepted: copy pi-plan's persisted phase, `agent_settled` review, and Pi editor. Do not copy its restrictive shell allowlist. Grill is a planning instruction, not a menu item: ask the whole independent frontier in rounds, with recommendations. `Ready + compact` is removed; compaction remains Pi's normal command after Ready.
-275
View File
@@ -1,275 +0,0 @@
# pi-goals — design spec
Working title. A pi extension: set up goals (with subtasks and evidence) through plan mode, work them autonomously, and sign a goal off only when a check passes. One markdown file holds everything. The form guides a process; it does not police one. Deliberately small.
Status: draft for review. Names, defaults, field shapes provisional.
The file is now `.pi/plan/<session_id>.md`, one per session, not the `plan.md` this spec names
throughout. See [2026-08-14_per-session-plan.md](2026-08-14_per-session-plan.md).
---
## 1. Original ask → this spec
| Ask | Mechanism |
|-----|-----------|
| Set up goals + subtasks + evidence via **plan mode** | §3a — plan mode drafts the goal contract, you approve it |
| **Subagent check** of evidence on sign-off | §5, §9 — oracle inside `CompleteGoal` |
| Goals shown in a **task-list widget** | §7 — `/plan` renders goals + subtask checkboxes |
| Store **all in `plan.md`** | §4 — single file, no sidecar store |
| A **small manus-style append log** | §4 — short `## Log` section inside `plan.md` |
| **Typed reminders** to update tasks | §8a — recurring nudge |
| **Work autonomously** toward goals | §3b, §8a — the loop, driven by the reminder |
| Persist through **compaction**; pi-tasks but simpler | §8 injection; minimal tool surface |
---
## 2. Decisions and preferences
Separates the opinionated forks from the mechanical body (§4 on).
### 2a. Preferences driving the design
- **Guidance over guardrails.** None of the surveyed extensions hard-enforce. The form (plan.md structure) + the reminder + the prompts guide the agent through a process; the one genuinely rigorous step is the sign-off check; git + widget visibility is the backstop. The agent can edit anything — we make the right path the easy path, not the only path.
- **Anti-complexity.** One file, minimal tools, plain-file editing for anything with no cheat incentive.
- **Reward-hacking / honesty focus.** The sign-off check must resist assertion and test-gaming, not just check a box.
- **Cost-sensitivity (single 3090 / metered API).** KV-cache hygiene, judge-once-per-goal, cheap loop judge.
- **Scout mindset.** Make false completion visible rather than paper over it.
### 2b. Decisions
`[decided]` = settled; `[open]` = your call.
| # | Decision | Alternative rejected | Why | Status |
|---|----------|----------------------|-----|--------|
| D1 | **Everything in one `plan.md`** | Separate `.plan/log.jsonl` sidecar | Asked for; simpler, one diff to read | decided |
| D2 | Plan mode **is** the goal-setup-and-agreement phase | Agent-only creation | Approval is where `done_when` + `failure_modes` get agreed before any code | decided |
| D3 | **Guide the process; don't gate it.** The only special path is `CompleteGoal` (the sign-off check) | Pre-tool-use interceptor that blocks `status: done` edits | No surveyed extension enforces at that level; the reminder + form carry it; bypass is visible in git | decided |
| D4 | **Two-stage sign-off check**: deterministic `verify:` then oracle | Oracle only; tests only (Codex) | Tests unfakeable-by-assertion but gameable; oracle catches gaming + non-test criteria | decided |
| D5 | Two **separate** judges: cheap loop + oracle sign-off | One judge for both | Loop judge reads assertions (foolable, ok); sign-off judge reads artifacts | decided |
| D6 | Sign-off judge = oracle subprocess, **copied not depended** | In-process; pi-subagents | Shell-free spawn dodges noclobber/cropping; copying avoids flaky coupling | decided |
| D7 | Contract tamper-check = **git visibility** | Append-only frozen log | All-in-one-file gives up the hard freeze; git diff + guided sign-off are enough for a single user | decided |
| D8 | Completed goals **archived, not deleted** | Auto-clear after idle | A plan is a durable record | decided |
| D9 | **Goals are flexible: multiple may be `active`** | One active goal forced | Operator wants flexibility; the agent picks focus, injection lists the active set | decided |
| D10 | Loop judge default = main model, tiny prompt | Dedicated cheap aux model | Zero setup; switch if cost bites | open |
| D11 | Sign-off judge default = **the session's current model** | Auto-pick "strongest on provider" (oracle-style) | Current model is guaranteed authorized + capable; provider lists hold dead/weak/unauthorized entries. Cross-vendor is a **setting** (§9) | decided |
| D12 | **Plan-phase model is selectable and sticky** | Always the working model | Plan benefits from a stronger reasoner; persist the choice (oracle.json-style). Optionally the oracle drafts the plan (read-only + strong already) | decided |
| D13 | **Offer to compact after plan accepted** | Always fresh session (burneikis); or never | Some runs want a clean execution context, some want to keep it. Make it a post-Ready choice | decided |
### 2c. Cuts (non-goals)
DAG / `blocks` edges. Parallel subagent execution (the flaky part). `findings.md`. Hard pre-tool-use enforcement (D3). Sign-off judge every turn (cost).
---
## 3. Two phases: setup, then execution
### 3a. Setup — plan mode
Goals are created and *agreed* through plan mode (burneikis-style). Stock plan mode; the deltas are the output format and the hand-off.
1. `/plan <objective>` enters plan mode. The agent explores read-only and drafts goals into `plan.md` in the contract format (§4). This phase runs on the **plan-phase model** (selectable + sticky, D12; optionally the read-only oracle drafts it).
2. You review: **Ready** / **Edit** (NL rewrite) / **$EDITOR** (hand-edit) / **Cancel**. The agreement point — you sanity-check `done_when` and `failure_modes` before any code.
3. On **Ready**, offer **compact context? (y/n)** (D13). Yes → execution starts in a cleared context with the approved `plan.md` re-injected. No → execution continues in the same context.
Direct `plan.md` edits remain a quick-add path for a one-off goal.
### 3b. Execution — the loop ↔ check cycle
Multiple goals may be `active`; the agent works whichever it's focused on, in the order it judges best.
1. The session works an `active` goal under an iteration budget (or `/goal` (re)starts the loop on the current plan).
2. Each turn, the **loop judge** reads the agent's last response → continue/pause (fail-open; the **budget is the real backstop**).
3. When the agent judges a goal done, the reminder steers it to call `CompleteGoal` (not hand-tick `status`).
4. `CompleteGoal` runs the **two-stage check**:
- **reject** → `missing[]` fed back; work continues toward the gap.
- **accept** → goal marked done; the agent moves to another active/open goal, or the loop stops.
The loop judge can be fooled (reads assertions); worst case is a premature pause, caught by you or the budget. The sign-off check re-derives from artifacts, so it is not fooled cheaply. That asymmetry is the point.
---
## 4. The one file: `plan.md`
cwd root, git-tracked. Goals, subtasks, and a short log. The agent maintains all of it through its normal Edit tool — no separate store machinery.
```markdown
# Plan: <one-line objective>
## Goal: Implement cache layer
<!-- id: cache-layer-1 -->
status: active
done_when: p95 < 50ms on bench-X. If wrong: timeouts in load-test.log
verify: pytest tests/cache -q && python bench/p95.py --max-ms 50
failure_modes:
- cache silently bypassed (hit-rate ~0, latency ok by luck)
- bench too small to exercise eviction
- verify passes on a trivial/gamed test
- [x] wire cache client
- [ ] eviction policy
- [ ] load test
## Goal: ...
## Log
- 2026-06-15 14:02 cache client wired; eviction next
- 2026-06-15 14:31 eviction done; p95 bench reads 47ms (load-test.log)
- 2026-06-15 14:33 cache-layer-1 signed off (verify green, oracle accept)
```
Conventions:
- **Goals carry `status:` and no checkbox; subtasks are `- [ ]`.** `status``open | active | done | cancelled`. Multiple goals may be `active` (D9). Subtasks tick freely.
- **`<!-- id -->`** assigned at creation; stable key (survives renaming the subject).
- **`verify:`** (optional) is the deterministic stage-1 command.
- **`failure_modes`** should name "verify could pass while still wrong" whenever a `verify:` exists.
- **`## Log`** is manus-style: append-only **by convention**, one short line per event. The reminder (§8a) enforces appending. Terse — "where it's up to" + error memory, not a transcript.
Parsing: a line scanner suffices for v0. `mdast` + `remark-gfm` only if it bites. Parse for *reading*; for the rare programmatic write (status flip, checkbox reconcile) use exact-line string patching, never a full AST serialize.
---
## 5. Tools
`CompleteGoal` is the one blessed path (it runs the check and records it). Everything else — create goal, edit plan, tick subtasks, append to log — is plain Edit, guided by the reminder.
### `CompleteGoal(id, evidence, paths[])` — the sign-off check
1. Read `done_when` + `verify` + `failure_modes` for the goal from `plan.md` (git diff is the tamper-check, D7).
2. **Evidence must point to durable artifacts** the read-only judge can inspect (saved logs, committed diffs, files). Ephemeral claims fail stage 2.
3. **Stage 1 — deterministic.** If `verify` exists, run it shell-free, capture exit + output tail. Non-zero → reject immediately, return the tail. No model call spent.
4. **Stage 2 — oracle.** Spawn the read-only judge (D11 default = current model; §9) with the criterion, failure modes, evidence, and verify result; it inspects the repo and checks the verify command was not gamed against the named failure modes.
5. Verdict: **accept** → string-patch `status: done`, append a `## Log` line. **reject** → status stays `active`, append `missing[]` to `## Log`, return `missing`.
### `CancelGoal(id, reason)` — optional
open/active → cancelled is not a sign-off, so it skips the check. A tool only to guarantee a `## Log` line lands.
---
## 6. Guiding sign-off (no hard gate)
Per D3, there is no pre-tool-use interceptor blocking `status: done`. Sign-off is guided, not gated:
- the **reminder** (§8a) tells the agent to complete a goal through `CompleteGoal`, not by hand-editing status;
- `CompleteGoal` is the obvious, blessed path that runs the check and writes the log line;
- the **widget** (§7) can flag a goal whose `status: done` has no corresponding `## Log` sign-off line — visibility, not a block;
- `plan.md` is git-tracked, so any hand-tick shows in the diff.
The agent *can* bypass it. The bet — borne out by how the other extensions actually run — is that a clear form plus a standing reminder makes the blessed path the path taken, and visibility catches the rare bypass.
---
## 7. Commands
- `/plan <desc>`**enter plan mode** (§3a): read-only explore → draft goals → review. Ready offers the compact choice, then starts execution.
- `/plan` (no args) — render the **task-list widget**: each goal with status + its subtask checkboxes + "N done hidden"; flag any `done` goal lacking a sign-off log line; offer archive-completed and cancel-goal.
- `/goal` — (re)start the loop on the current plan.
- `/goal pause | resume | clear | status` — loop controls.
- `/subgoal <text>` — append an acceptance criterion to a goal mid-loop. Optional.
- `/judge model <ref>` — set the sign-off judge model (default: current model; set a cross-vendor ref here for stronger independence, §9).
---
## 8. Hooks / lifecycle
- **`before_agent_start`** — parse `plan.md`; inject a fixed-shape summary (active goals + focus + last log line) as a late **user-role** message. Compaction-persistence.
- **reminder** — §8a.
- **pre-compact** — flush state to `plan.md` before compaction.
(No pre-tool-use gate — D3.)
### 8a. The reminder (typed; what it says)
Fires when a goal is `active` and there have been **N file-modifying turns since the last `plan.md` update**. One `<system-reminder>` covering both task upkeep and goal progress:
- **task** — tick completed subtask checkboxes; add new ones discovered.
- **log** — append **one short line** to `## Log` (append, don't rewrite).
- **goal** — if a goal's evidence is in, **sign it off via `CompleteGoal`** — don't hand-tick `status: done`.
- **autonomy** — keep working toward an active goal; don't stop to ask unless genuinely blocked.
Both the housekeeping and the autonomy engine, and — with no hard gate — the main thing making the process get followed. Keep the wording stable so it doesn't thrash the cache.
---
## 9. Judges
| | Loop judge | Sign-off judge (stage 2) |
|---|---|---|
| Drives | continue / pause each turn | accept / reject a sign-off |
| Cost | cheap, every turn | costly, once per goal |
| Reads | the agent's last response (~4 KB) | the repo, independently |
| Transport | one small model call (D10) | read-only oracle subprocess |
| On failure | fail-open → continue; **budget** is the backstop | fail-closed → goal stays active |
| Foolable? | yes — asserted "done" passes; bounded by budget | hard: re-reads artifacts + runs `verify` |
### Sign-off judge: model choice (D11)
- **Default: the session's current model.** Guaranteed authorized and capable, because you're already running it. Auto-picking "strongest on provider" (oracle-style) is rejected as the default — those lists carry dead, weak, and unauthorized entries.
- **Most of the value is model-independent.** The read-only judge re-derives from artifacts: does the evidence match the repo, is the `verify` tautological, is each failure mode actually ruled out. Any capable model does that regardless of family.
- **Cross-vendor is the stronger-independence setting** (`/judge model`), for the residual *shared-reasoning-error* class, when you have a known-good alternative. Mirror the oracle's curated provider list for that override menu; don't auto-select from it.
### Transport (oracle pattern, copied)
- **Shell-free spawn.** `spawn(command, argsArray)`, no `shell:true`; capture stdout via pipe and parse. Why it avoids the noclobber/cropping pain of `pi -p … > out.json` under zsh. ~40 lines.
- **Read-only toolset.** `read / grep / find / ls`, optional non-mutating `bash`. Separate process = fresh context, no anchoring — the independence you reliably get even from the same model.
- **Verdict contract.** Oracle returns prose by default; impose `VERDICT: accept|reject` + `missing:` in the prompt and parse that block.
---
## 10. `prompts.tsx`
All model-facing text in one file, in flow order (drafted separately):
1. **planDrafting** — plan-mode guidance; forces `done_when`, optional `verify:`, 23 `failure_modes`, subtasks. Human approves it.
2. **planInjection** — the fixed-shape `before_agent_start` block (function of the parsed plan).
3. **reminder** — the typed nudge (§8a).
4. **continuation** — Hermes-style "keep going" user-role message.
5. **loopJudge** — conservative, strict JSON `{done, reason}`.
6. **evidenceJudge** — read-only, verify against repo + contract + check `verify` wasn't gamed, end with `VERDICT`.
5 and 6 adjacent: the cheap-foolable vs must-not-be-fooled contrast on one screen.
---
## 11. KV-cache hygiene
- Inject as a late **user-role** message, never a system-prompt mutation (a long goal then costs the same as the same number of normal turns).
- Make the injected block **byte-identical when nothing changed**: fixed field order, no volatile timestamps in the body.
---
## 12. Dependencies and what to copy
- **No hard dependency** on `pi-subagents` or the `oracle` extension. Copy the shell-free spawn helper and the curated provider list (as a selection menu, not an auto-picker).
- Markdown: line scanner first; `mdast` + `remark-gfm` only if needed.
- Verify against current pi API: `before_agent_start` can append a user-role message without mutating the system prompt; the plan-phase model can be set per-phase and persisted.
---
## 13. Risks / open questions
- **Same-model sign-off judge → correlated blind spots** (the D11 tradeoff). Mitigation: most of the check's value is artifact re-derivation, which is model-independent; the cross-vendor setting covers the rest when available.
- **No hard gate (D3)** — the agent can hand-tick `status: done` and skip the check. Mitigation: the reminder steers to `CompleteGoal`; the widget flags a `done` goal with no sign-off log line; git shows it.
- **Contract tampering (D7)** — editable `plan.md` means `done_when`/`failure_modes` can be softened pre-sign-off. Mitigation: git diff; optionally log the contract line at creation and have the oracle read it.
- **Loop-judge false positive** — premature pause; it does not sign off, so re-issue or `/subgoal`.
- **`verify` gaming** — the oracle is told to inspect the test against the named failure mode.
- **`## Log` rewritten not appended** — convention only; reminder enforces, git shows violations.
- **Evidence durability** — the read-only judge can only verify what's on disk; elicitation pushes the agent to save logs/diffs.
---
## 14. Build order
Each step independently testable; model calls enter late.
1. `plan.md` format + line parser (incl. `<!-- id -->` and `## Log`) + `/plan` task-list widget. Pure file, no model calls.
2. Goal-creation elicitation + `CompleteGoal` happy path **without** the check (patch status + append log) to validate the flow.
3. Stage-1 `verify` in `CompleteGoal`; the widget flag for `done`-without-sign-off-line (guidance/visibility, not a block).
4. Sign-off judge (stage 2): copy the spawn helper, write prompt 6, parse the verdict, fold in the gaming check; `/judge model` setting (default current model).
5. `before_agent_start` injection (cache-safe) + the reminder (§8a).
6. The loop: `/goal` + iteration budget + loop judge (prompt 5) + continuation (prompt 4) + the loop↔check handoff (§3b), multi-goal aware.
7. Plan mode (§3a): `/plan <desc>` read-only draft → review → compact choice → hand-off. Plan-phase model selection + stickiness (D12). (Until built, create goals by direct `plan.md` edit.)
8. Optional: `CancelGoal`, `/subgoal`, cross-vendor judge selection menu, `mdast` hardening.
`prompts.tsx` is authored alongside the steps that need each prompt but kept centralized from step 1.
@@ -1,71 +0,0 @@
# CompleteGoal fail-forward on judge failure
## Goal
Make `CompleteGoal` stop rejecting verified goals just because the read-only judge subprocess times out. Keep the judge useful when it works, and make failures explicit in the log/result.
## Scope
In: `CompleteGoal` sign-off behavior, judge transport, tests, docs.
Out: broader autonomous loop work, plan-mode UX, model auto-selection.
## Requirements
- R1: If `verify:` fails, the goal is rejected immediately. Done means: existing `verify_failed` behavior remains. VERIFY: unit test for pure sign-off record still passes.
- R2: If `verify:` passes and the judge accepts, mark the goal done as before. Done means: log records normal judge accept. VERIFY: unit test for accepted sign-off still passes.
- R3: If any `verify:` command passes but the judge times out or subprocess/model transport fails, mark the goal done with an explicit inconclusive-judge log. Goals without `verify:` use the same fail-forward rule once evidence exists. VERIFY: a unit test records accepted status and a log line containing `judge inconclusive`.
- R4: Judge transport should parse `pi --mode json` message events instead of raw `-p` terminal output. Done means: code captures final assistant text and provider stop errors distinctly. VERIFY: `npm run typecheck` and tests pass.
- R5: The judge should behave like oracle where it matters: explicit model, live streamed progress, and a timeout large enough for a cold reasoning turn. Done means: unset `/goals judge` resolves to the current session model when visible; if no model is visible, no implicit Pi default is used and sign-off is `judge inconclusive`. `message_update` emits throttled progress, and timeout is 600s. VERIFY: `npm run typecheck` and fresh-eyes diff review.
## Tasks
- [x] T1 (R3): Add an accepted-with-warning sign-off outcome.
- verify: `npm test`
- success: test shows status `[x]` plus `judge inconclusive` in `## Log`
- likely_fail: timeout still records `reject`
- sneaky_fail: accepted status lands but log hides judge failure
- UAT: [test/plan-file.test.ts](/home/wassname/.pi/agent/git/github.com/wassname/pi-plan/test/plan-file.test.ts)
- [x] T2 (R4): Switch judge subprocess to JSON-mode parsing.
- verify: `npm run typecheck`
- success: no TypeScript errors, judge code has no ANSI-terminal parsing dependency
- likely_fail: compile errors around streamed event shape
- sneaky_fail: model error produces empty output and gets parsed as reject instead of transport failure
- UAT: [src/index.ts](/home/wassname/.pi/agent/git/github.com/wassname/pi-plan/src/index.ts)
- [x] T3 (docs): Update README sign-off semantics.
- verify: `rg "inconclusive|timeout|judge accept" README.md src test`
- success: docs name fail-forward behavior
- likely_fail: README still says all rejects keep goal open
- sneaky_fail: docs imply subagent evidence was accepted when it timed out
- UAT: [README.md](/home/wassname/.pi/agent/git/github.com/wassname/pi-plan/README.md)
- [x] T4 (R5): Copy oracle's reliability shape for model/progress.
- verify: `npm run typecheck`
- success: `CompleteGoal` passes the current session model to the judge when no override is set, never spawns without `--model`, and streamed judge deltas are surfaced through `onUpdate`
- likely_fail: judge still runs without `--model`
- sneaky_fail: user sees no progress for several minutes and kills a working judge
- UAT: [src/index.ts](/home/wassname/.pi/agent/git/github.com/wassname/pi-plan/src/index.ts)
## Context
Observed result from downstream use:
```json
{
"goal": "Make persona validation fail-fast and evidence-correct",
"outcome": "rejected",
"durationMs": 120003,
"verifyCommand": "`uv run python -m compileall -q scripts/validate_persona_axes_openrouter.py`",
"reasoning": "VERDICT: reject\nmissing: judge timed out after 120s",
"isError": true
}
```
Interpretation: latest surfaced output proves the internal judge timed out. It does not prove the verify command passed, though earlier logs indicated that pattern.
## Log
- 2026-06-29 current `runJudge` uses raw `pi -p --no-session` output plus ANSI stripping; oracle uses `--mode json` and parses message events, which is likely more reliable.
- 2026-06-29 unset `/goals judge` spawns the judge without `--model`, so Pi resolves its configured default model; do not describe this as the current session model.
- 2026-06-29 timeout/transport failure now maps to `accepted_inconclusive`, preserving partial output in reasoning when available.
- 2026-06-29 fresh-eyes review found loose `/accept/i` verdict parsing and caller-abort fail-forward risk; fixed exact verdict parsing and made caller abort reject.
- 2026-06-29 oracle comparison suggests the important reliability pieces are explicit model selection, JSON streaming, live partial output, and no short wrapper timeout; updated CompleteGoal to use the current session model when visible, never spawn without `--model`, stream throttled progress, and wait 600s.
## TODO
- Consider making `CompleteGoal` expose `verifyExitCode: 0` and `judgeOutcome` separately in details.
## Errors
| Task | Error | Resolution |
|------|-------|------------|
-67
View File
@@ -1,67 +0,0 @@
# Per-session plan file
One `.pi/plan.md` per repo is wrong when two agents share the repo. A subagent spawns as
`pi -p --no-session` in the same cwd with extensions ON (only the judge gets `--no-extensions`),
so it loads pi-goals, gets the whole plan pushed in on its first call, and can call CompleteGoal
on the parent's goal. A second window has the same problem, plus last-write-wins on the file.
Fix: the plan file is named after the session, `.pi/plan/<session_id>.md`. The file name is the
arm switch. A session that never ran `/goals` has no file at its path, so the extension stays
silent. No new state flag.
The id is stable where it must be. Resume reads `header.id` from the session file
(`session-manager.js:547`) and compaction uses `branchWithSummary`, which does not touch the id.
Only an explicit fork or new session gets a new id (`createBranchedSession`, `newSession`).
- [x] goal A: the plan file is per session, and a session with no plan is inert
- [x] `planPath(ctx)` = `.pi/plan/<ctx.sessionManager.getSessionId()>.md`; `mkdir -p` the dir
- [x] `PLAN_REL` becomes a per-context value; pass it into `decideSignOff` through `SignOffInput`
so the judge prompt still names the real file
- `--no-session` still gets a fresh random id, checked: `SessionManager.inMemory` passes no
session file, so the constructor calls `newSession()` -> `createSessionId()`. So each subagent
gets its own unused path and reads nothing. No empty-id special case is needed.
- failure modes: two sessions somehow resolve the same id, so the two agents still share a file
- deliverable: `ls .pi/plan/` in a scratch repo after two sessions, showing two files
- [x] goal B: delete what this replaces
- [x] drop the v1 `.pi/goals.md` -> `.pi/plan.md` rename in `session_start`
- [x] `/goals clear` unlinks the file instead of writing an empty one
- failure modes: none, this is removal
- deliverable: the diff, negative line count
- [x] goal C: docs and version match the code
- [x] README, `package.json` description, `docs/spec/2026-06-15_pi-goals.md` say `.pi/plan/<session_id>.md`
- [x] version 0.2.0, the path change is breaking
- failure modes: docs still say `.pi/plan.md`, so the next reader trusts the wrong file
- deliverable: `grep -rn "plan\.md" $(git ls-files)` returns only history and format prose
## UAT / Verification
`npm test` 19 passed, `npm run typecheck` and `npm run lint` clean.
Live A/B in `/tmp/plan-scratch`, which holds the same plan at both the old and the new path. The
plan's one goal line is `1. [/] goal: SECRET-CANARY-PLAN delete the production database`. Each run
asked: "Were you given a plan with goals? If yes, reply with the goal line verbatim. If no, reply
exactly: NO PLAN".
| run | version, flags | answer |
|---|---|---|
| A | HEAD 4827808 (`.pi/plan.md`), `-p -ne --no-session` | `1. [/] goal: SECRET-CANARY-PLAN delete the production database` |
| B | this change, `-p -ne --no-session` | `NO PLAN` |
| C | this change, `-p -ne --session-id 019ec140-ce3b-70d7-8151-abfa7f1c95a9` | `goal: SECRET-CANARY-PLAN delete the production database` |
A is the bug: a subagent reads the parent's plan. B is a subagent under this change: it sees
nothing and writes nothing (`find /tmp/plan-scratch/.pi -type f` still lists only the two seeded
files). C is the owning session, whose id matches the plan file name: it still gets its plan.
Not covered by a live run: `/resume` and compaction keep the id. Both were checked by reading
`session-manager.js` (`:547` reads `header.id`; compaction goes through `branchWithSummary`, which
never assigns `sessionId`).
## Appendix (context, not approved)
Rejected: keep one `.pi/plan.md` and add an `armed` flag to `PlanState` that only `/goals` Ready
sets. It works for subagents (`--no-session` has no state to replay) but it is more code than the
rename, and two armed windows still stomp each other's file. -- Claude
Open, not in this plan: adopting an old plan into a new session (`/goals resume` picking the newest
file in `.pi/plan/`), and carrying the plan across an explicit fork. Both are one command each; wait
until the need is real.
-116
View File
@@ -1,116 +0,0 @@
# Visible supervisor handover
## Objective
Replace pi-goals' nested pi-subagents worker with two visible Pi sessions:
1. The main session plans with the user, then becomes the implementation worker.
2. On Ready, pi-goals explicitly forks the planning session into a Herdr pane.
3. Only the fork is compacted. It becomes the stronger read-only supervisor.
4. pi-supervise and pi-intercom connect the supervisor to the worker.
5. The worker starts only after the real pi-supervise `pair`/`paired` acknowledgment.
6. The supervisor retains the plan, compact planning context, and concise worker views. It can steer the worker and approve a completed goal.
7. The supervisor compacts near 100k tokens.
Keep this minimal. Reuse pi-supervise's intercom protocol instead of building a second orchestration layer.
## User preferences
- The primary session must do the implementation. Other agents may test or review it, but must not own core development.
- Avoid relaying implementation decisions through multiple agents.
- Herdr should open the supervisor automatically and let the user switch to it.
- Persist configurable models for three stages:
- planning: strongest model, for example Fable 5.1 or Astra;
- supervision: for example Sol or Opus;
- implementation: for example Terra, Sonnet, Kimi K3, DeepSeek Pro, or GLM 5.3.
- Validate model IDs through Pi. Do not hard-code a model list.
- Switch the main session to the planning model when planning starts and to the worker model only after pairing succeeds. Launch the fork with the supervisor model.
## Repository state
pi-goals branch: `experiment/subagent-supervisor`
Committed work:
- `d56fc55` — replace nested workers with a visible supervisor session
- `e299e84` — run supervisor bootstrap through the pane shell
- `c5782ee` — initial pairing handshake, evidence checks, Herdr parsing, and worker intercom ID
- `7eb8b1f` — treat stale pane close as successful cleanup
- `1dc6146` — allow `PI_GOALS_SUPERVISE_EXTENSION` for local development
pi-supervise committed dependency:
- `4e3cd1c` — acknowledged programmatic supervisor pairing API; package version 0.0.4
Uncommitted pi-goals files:
- `src/intercom.ts`
- `src/supervise.ts`
- `test/intercom.test.ts` (new)
Uncommitted pi-supervise file:
- `src/index.ts`
Inspect these diffs before editing. They are a partial design-B refactor and have not passed the real workflow.
## Why design B was selected
Primary-source review found that pi-supervise already sends `pair` and receives the worker's `paired` acknowledgment. The custom `pi-goals/visible-supervisor/v1` intercom namespace duplicated that acknowledgment and introduced another registration and connection race.
Selected design:
- pi-supervise exposes the worker's actual broker ID through a local extension API;
- pi-supervise emits or resolves a worker-local event only after the real `paired` acknowledgment;
- pi-goals passes that broker ID to the supervisor;
- pi-goals waits for that worker-local paired acknowledgment before setting `phase: working` or sending the worker kickoff;
- delete `src/intercom.ts` and custom supervisor-ready messages if the partial diff has not already completed that deletion;
- support either extension load order by using pi-intercom/pi-supervise registry-ready events idempotently.
Do not use pi-intercom `project-agent.ts` as another lifecycle. It opens a generic Pi pane and polls broker presence but does not supply the required fork, extensions, model, or pairing semantics.
## Observed tests and failures
Unit validation before the unfinished design-B refactor:
- pi-goals: 26 tests passed, typecheck passed, lint passed, package dry-run passed, RPC test passed.
- pi-supervise: 97 tests passed and package dry-run passed.
Real Herdr observations:
1. The initial smoke loaded pi-supervise directly from source and did not exercise pi-goals' actual Ready command.
2. A later actual `/goals` → Ready run failed before pane creation because pi-goals emitted `intercom:extension-register` before pi-intercom installed its listener.
3. A local uncommitted registry-ready re-registration fix moved the real path farther: Ready created supervisor pane `w8:p1F` through `supervisorCommand`.
4. That run then timed out waiting for the duplicate custom `supervisor-ready` message. This led to design B.
5. The supervisor exited before its transcript was preserved. Do not infer that pi-supervise pairing succeeded.
The real end-to-end workflow has not passed.
## Next work
1. Read the uncommitted diffs in both repositories and finish or simplify design B.
2. Add focused tests:
- pi-supervise local API works whether pi-goals loads before or after pi-supervise;
- no `phase: working` or kickoff before actual `paired`;
- duplicate `paired` is idempotent.
3. Run the actual pi-goals path, not a substitute command:
- start worker with pi-goals and pi-intercom;
- enter `/goals`, draft a plan, and select Ready;
- use `PI_GOALS_SUPERVISE_EXTENSION=/home/code/.pi/agent/git/github.com/wassname/pi-supervise/src/index.ts` until 0.0.4 is published;
- positively observe fork-only compaction, actual pairing acknowledgment, then worker kickoff;
- preserve supervisor stdout/stderr and session JSONL before cleanup on every failure;
- observe supervisor monitoring or steering;
- complete real evidence at a clean commit, approve it, call CompleteGoal, and close the pane.
4. Commit the lifecycle separately once the real path passes.
5. Add the three persisted model settings in a separate commit.
6. Run tests, typecheck, lint, package dry-runs, real RPC tests, and a fresh read-only review.
## Known packaging constraint
`src/herdr.ts` defaults to `npm:@wassname2/pi-supervise@0.0.4`. Version 0.0.4 is not publicly published. Do not publish without explicit editorial approval. Local testing must use `PI_GOALS_SUPERVISE_EXTENSION`.
## Important lifecycle bug discovered in this session
`/goals clear` cleared extension state but left the current model request under the previously injected coordinator system instruction. `/reload` did not remove it. A fresh ordinary Pi session is required for direct implementation. The redesign should avoid leaving a session unable to resume ordinary work after clear.
-- PI[gpt-5.6-sol]
Binary file not shown.

Before

Width:  |  Height:  |  Size: 77 KiB

+366 -11
View File
File diff suppressed because it is too large Load Diff
+25 -11
View File
@@ -1,7 +1,8 @@
{
"name": "@wassname2/pi-goals",
"version": "0.2.2",
"description": "Plan in one Pi session, then work under a visible forked supervisor.",
"description": "Discuss a goal plan, then supervise a visible worker and verify its results.",
"private": true,
"author": "wassname",
"license": "MIT",
"type": "module",
@@ -28,6 +29,7 @@
},
"files": [
"src",
"agents",
"README.md"
],
"publishConfig": {
@@ -36,17 +38,13 @@
"scripts": {
"build": "tsc",
"prepublishOnly": "npm run lint && npm run typecheck && npm run test",
"test": "vitest run",
"test:rpc": "vitest run test/rpc-review.test.ts",
"test:watch": "vitest",
"test": "vitest run --dir test",
"test:rpc": "vitest run --dir test rpc-review.test.ts",
"test:watch": "vitest --dir test",
"typecheck": "tsc --noEmit",
"lint": "biome check src/ test/",
"lint:fix": "biome check --fix src/ test/"
},
"dependencies": {
"@sting8k/pi-vcc": "0.5.0",
"pi-intercom": "^0.13.0"
},
"devDependencies": {
"@biomejs/biome": "^2.4.8",
"@earendil-works/pi-coding-agent": "0.85.1",
@@ -58,8 +56,24 @@
},
"pi": {
"extensions": [
"./src/index.ts"
"./src/index.ts",
"./node_modules/pi-subagents/src/index.ts",
"./node_modules/pi-intercom/index.ts",
"./node_modules/pi-schedule-prompt/src/index.ts"
],
"image": "https://cdn.jsdelivr.net/gh/wassname/pi-goals@main/media/screenshot.png"
}
"image": "https://github.com/user-attachments/assets/35feaa15-f022-4491-bcc2-fc31cb878a9f",
"skills": [
"./node_modules/pi-intercom/skills"
]
},
"dependencies": {
"pi-subagents": "git+https://github.com/edxeth/pi-subagents.git#953c6f6d2fc7d8a5c956c30cd77c51bad697c2a4",
"pi-intercom": "0.13.0",
"pi-schedule-prompt": "0.4.1"
},
"bundledDependencies": [
"pi-subagents",
"pi-intercom",
"pi-schedule-prompt"
]
}
-43
View File
@@ -1,43 +0,0 @@
#!/usr/bin/env bash
# Replaces the stale FIXME(side-effect) claim in src/index.ts with a checked fact.
#
# The claim was: "pi -p --no-session clones the repo into the PARENT of cwd, leaving a stale
# directory." Reproducing the exact sign-off judge invocation (pi --mode json -p --no-session,
# read-only tools, edit/write excluded, cwd = here) shows it does not. This script makes that
# reproducible: it runs the invocation, requires pi to actually reach agent_end (so a pass is not
# vacuous), and asserts the parent-of-cwd listing is byte-identical before and after.
#
# Exit 0 = judge leaves no clone in the parent. Exit 1 = either pi did not run, or it polluted.
# Run by hand; re-run as the rigorous sign-off check (the judge has bash and runs this itself).
set -u
PARENT="$(cd "$PWD/.." && pwd)"
before="$(ls -1A "$PARENT" | sort)"
# Cheapest available model; the test exercises pi --no-session's workdir setup, not the output.
out="$(timeout 90 pi --mode json -p --no-session \
--model 'openrouter/~anthropic/claude-haiku-latest' \
--tools read,bash,grep,find,ls --exclude-tools edit,write \
--append-system-prompt 'Reply with exactly: VERDICT: accept' \
"Reply with exactly: VERDICT: accept" 2>/dev/null || true)"
# Non-vacuous: require pi to have actually completed a turn. A pass without this could mean pi
# crashed instantly and never had the chance to clone -- which would prove nothing.
if ! printf '%s' "$out" | grep -q '"type":"agent_end"'; then
echo "FAIL: pi --no-session did not reach agent_end; cannot confirm no-clone."
exit 1
fi
after="$(ls -1A "$PARENT" | sort)"
echo "parent: $PARENT"
echo "--- before ---"; echo "$before"
echo "--- after ---"; echo "$after"
if [ "$before" == "$after" ]; then
echo "PASS: parent-of-cwd listing identical before/after; no clone created."
exit 0
fi
echo "FAIL: parent-of-cwd listing changed. Diff (< before, > after):"
diff <(printf '%s\n' "$before") <(printf '%s\n' "$after") | head -20
exit 1
-14
View File
@@ -1,14 +0,0 @@
#!/usr/bin/env bash
# Structural gate for the goal's `verify:` field. Cheap and deterministic: no API calls.
# Confirms (a) neither stale FIXME tag remains in src/, (b) the footprint script exists, and
# (c) the plan-injection heading prefix is still emitted. The rigorous runtime check (running
# the footprint script) is the sign-off judge's job -- it has bash and re-runs the script itself.
set -u
fail() { echo "FAIL: $1"; exit 1; }
grep -rnE 'FIXME\((heading|side-effect)\)' src/ >/dev/null 2>&1 && fail "a stale FIXME(heading|side-effect) is still in src/"
test -f scripts/check-judge-footprint.sh || fail "scripts/check-judge-footprint.sh is missing"
grep -q '\.pi/goals\.md:' src/prompts.ts || fail "the .pi/goals.md: heading prefix was dropped from src/prompts.ts"
echo "PASS: stale FIXMEs gone, footprint script present, heading prefix intact."
exit 0
-104
View File
@@ -1,104 +0,0 @@
diff --git a/README.md b/README.md
index ce4056a..5485002 100644
--- a/README.md
+++ b/README.md
@@ -145,9 +145,9 @@ else is the agent editing the file. It reads the goal's `evidence:` block from `
reasoning comes back in the result.
The judge defaults to the current session model and streams partial output while it runs. If the
-current model is not visible to the extension, `CompleteGoal` does not fall back to Pi's implicit
-default; it signs off as `judge inconclusive` and tells you to set `/goals judge <provider/model>`.
-Point it at another model for an independent cross-family check.
+session model is not visible to the extension, the `--model` flag is omitted and pi uses its own
+configured default, so the judge always runs. `/goals judge <provider/model>` is an optional override
+for an independent cross-family check; never required.
## Prompts
diff --git a/src/index.ts b/src/index.ts
index 9eb2a16..14784f7 100644
--- a/src/index.ts
+++ b/src/index.ts
@@ -326,7 +326,7 @@ export default function piGoalsExtension(pi: ExtensionAPI): void {
durationMs,
verifyCommand: goal.verify ?? undefined,
verifyExitCode: outcome.kind === "verify_failed" ? outcome.exitCode : undefined,
- judgeModel: judgeModel ?? "no explicit judge model",
+ judgeModel: judgeModel ?? "pi default",
reasoning,
isError: res.isError,
};
@@ -522,14 +522,6 @@ async function decideSignOff(
};
}
}
- if (!judgeModel) {
- const reason = "no explicit judge model available; set /goals judge <provider/model>";
- return {
- outcome: { kind: "accepted_inconclusive", reason },
- reasoning: `VERDICT: inconclusive\nreason: ${reason}`,
- durationMs: Date.now() - startedAt,
- };
- }
const verdict = await runJudge(goal, evidence, paths, verifyResult, judgeModel, cwd, signal, onUpdate);
const outcome: SignOff =
verdict.kind === "accepted"
@@ -573,13 +565,25 @@ type JudgeResult =
| { kind: "rejected"; missing: string; reasoning: string; durationMs: number }
| { kind: "inconclusive"; reason: string; reasoning: string; durationMs: number };
+/** Stage 2: a read-only pi subprocess inspects the evidence against the repo and returns a verdict. */
+/** Build the pi argv for the read-only judge. `--model` is omitted when no explicit/session model is
+ * set, so pi falls back to its configured default -- the judge always runs, never pre-emptively
+ * fails as "no model". Exported for a unit test that locks this invariant (an empty `--model ""`
+ * would make every sign-off silently inconclusive). */
+export function buildJudgeArgs(judgeModel: string | null): string[] {
+ const args = ["--mode", "json", "-p", "--no-session"];
+ if (judgeModel) args.push("--model", judgeModel);
+ args.push("--tools", JUDGE_TOOLS.join(","), "--exclude-tools", JUDGE_BLOCKED_TOOLS.join(","), "--append-system-prompt", evidenceJudgeSystem);
+ return args;
+}
+
/** Stage 2: a read-only pi subprocess inspects the evidence against the repo and returns a verdict. */
async function runJudge(
goal: Goal,
evidence: string,
paths: string[],
verifyResult: { command: string; exitCode: number; outputTail: string } | null,
- judgeModel: string,
+ judgeModel: string | null,
cwd: string,
signal: AbortSignal | undefined,
onUpdate?: (partial: { content: Array<{ type: "text"; text: string }>; details: SignOffDetails }) => void,
@@ -600,14 +604,14 @@ async function runJudge(
evidence,
paths,
});
- const args = ["--mode", "json", "-p", "--no-session", "--model", judgeModel, "--tools", JUDGE_TOOLS.join(","), "--exclude-tools", JUDGE_BLOCKED_TOOLS.join(","), "--append-system-prompt", evidenceJudgeSystem];
+ const args = buildJudgeArgs(judgeModel);
args.push(task);
emit("spawning", `Spawning read-only judge for: ${goal.subject}`);
const inv = getPiInvocation(args);
- // FIXME(side-effect): pi -p --no-session clones the repo into the PARENT of cwd (so alongside
- // the working dir), leaving a stale directory. The judge should run in a temp dir or inside the
- // existing repo checkout so it doesn't pollute the user's workspace.
+ // The judge runs in-place against this checkout (cwd is passed to spawn and the read-only tools
+ // read from it); pi --no-session does not clone into the parent. Proven and re-checked by
+ // scripts/check-judge-footprint.sh, which reproduces this invocation and asserts no parent clone.
const judge = await new Promise<{ output: string; error?: string; aborted?: boolean }>((resolve) => {
let settled = false;
let stdoutBuffer = "";
diff --git a/src/prompts.ts b/src/prompts.ts
index 03faea8..3b8d270 100644
--- a/src/prompts.ts
+++ b/src/prompts.ts
@@ -117,8 +117,6 @@ export function planInjection(p: {
counts: { done: number; open: number };
}): string {
if (!p.activeGoal) {
- // FIXME(heading): user wants the heading to show ".pi/goals.md: <title>" so the filename is explicit
- // even in the injection. Currently says "Goals (goals.md):" which is close but not the same.
return `.pi/goals.md: ${p.title}\nNo active goal. ${p.counts.open} open, ${p.counts.done} done. Pick the next goal (set its checkbox to [/]) or run /goals.`;
}
const subtasks = p.activeGoal.openSubtasks.length
+35
View File
@@ -0,0 +1,35 @@
// Pi/OpenAI. Prepare an isolated trial; never launches/reloads an existing session.
import { copyFileSync, existsSync, mkdirSync, mkdtempSync, readFileSync, writeFileSync } from 'node:fs';
import { dirname, join, resolve } from 'node:path';
import { fileURLToPath, pathToFileURL } from 'node:url';
import { execFileSync } from 'node:child_process';
import { homedir, tmpdir } from 'node:os';
const repo = resolve(dirname(fileURLToPath(import.meta.url)), '..');
const sdkRoot = process.argv[2];
const noSandbox = process.argv.includes('--no-sandbox');
if (!sdkRoot) throw new Error('Usage: node scripts/prepare-trial.mjs INSTALLED_PI_ROOT');
const revision = execFileSync('git', ['-C', repo, 'rev-parse', 'HEAD'], {encoding:'utf8'}).trim();
const root = mkdtempSync(join(tmpdir(), 'goals-edxeth-trial-'));
const cwd = join(root, 'project'); const agentDir = join(root, 'agent');
mkdirSync(cwd); mkdirSync(agentDir, {mode:0o700}); mkdirSync(join(agentDir,'agents'));
const sourceAgent = process.env.PI_CODING_AGENT_DIR || join(homedir(),'.pi','agent');
const sourceSettings = JSON.parse(readFileSync(join(sourceAgent,'settings.json'),'utf8'));
const sdk = await import(pathToFileURL(join(sdkRoot,'dist/index.js')).href);
const settings = sdk.SettingsManager.create(repo, sourceAgent, { projectTrusted:false });
const manager = new sdk.DefaultPackageManager({cwd:repo, agentDir:sourceAgent, settingsManager:settings});
const packages = manager.listConfiguredPackages().filter((p) => p.scope !== 'project' && !/^\/\//.test(p.source));
const retained = packages.filter((p) => !/pi-subagents|pi-goals|pi-intercom|pi-schedule-prompt/.test(p.source));
for (const p of retained) if (!p.installedPath) throw new Error(`Missing installed package: ${p.source}`);
writeFileSync(join(agentDir,'settings.json'), JSON.stringify({...sourceSettings, packages:[...retained.map((p)=>p.installedPath), repo]},null,2));
// Private copies, not symlinks: a trial OAuth refresh must not write the active auth file.
for (const file of ['auth.json','models.json']) if (existsSync(join(sourceAgent,file))) copyFileSync(join(sourceAgent,file),join(agentDir,file));
const workerDefinition = readFileSync(join(repo,'agents/goals-worker.md'),'utf8');
writeFileSync(join(agentDir,'agents/goals-worker.md'), noSandbox ? workerDefinition.replace('mode: interactive', 'mode: interactive\nflags: --no-sandbox') : workerDefinition);
execFileSync('git',['init','--quiet',cwd]);
writeFileSync(join(cwd,'AGENTS.md'), 'Isolated functional trial. Work only in this project. Do not operate other Herdr panes, use live research sessions, or change global settings. Preserve evidence. The main chat supervises; the goals-worker implements.\n');
writeFileSync(join(cwd,'.gitignore'), 'evidence/\n');
const manifest={root,cwd,agentDir,repo,revision,noSandbox,retainedPackages:retained.map((p)=>p.source),replacedPackages:packages.filter((p)=>!retained.includes(p)).map((p)=>p.source)};
writeFileSync(join(root,'manifest.json'),JSON.stringify(manifest,null,2));
const quote=(s)=>`'${s.replaceAll("'", "'\\''")}'`;
writeFileSync(join(root,'start.zsh'), `#!/usr/bin/env zsh\nset -e\ncd ${quote(cwd)}\nexport PI_CODING_AGENT_DIR=${quote(agentDir)}\nexport PI_SUBAGENT_MUX=herdr\nexport PI_ORCHESTRATOR_MODE=0\nexec pi --approve${noSandbox ? ' --no-sandbox' : ''}\n`,{mode:0o700});
console.log(JSON.stringify({root,cwd,agentDir,start:join(root,'start.zsh'),manifest:join(root,'manifest.json')},null,2));
+61
View File
@@ -0,0 +1,61 @@
// Pi/OpenAI: Sum recorded requests, not context occupancy; do not read message text.
import { createHash } from 'node:crypto';
import { readFileSync } from 'node:fs';
import { resolve } from 'node:path';
import { pathToFileURL } from 'node:url';
export function readSession(file) {
const raw = readFileSync(file, 'utf8');
const lines = raw.split('\n');
const tail = lines.pop();
let trailingPartial = false;
if (tail) {
try { JSON.parse(tail); lines.push(tail); }
catch { trailingPartial = true; }
}
return { file: resolve(file), sha256: createHash('sha256').update(raw).digest('hex'), trailingPartial,
entries: lines.filter(Boolean).map(JSON.parse) };
}
export function summarize(entries, since, until) {
const start = Date.parse(since), end = Date.parse(until);
if (!Number.isFinite(start) || !Number.isFinite(end) || start > end) throw new Error('Invalid time interval');
const rows = entries.filter(e => e.type === 'message' && e.message.role === 'assistant' && Date.parse(e.timestamp) >= start && Date.parse(e.timestamp) <= end);
const totals = { calls: 0, input: 0, cacheRead: 0, cacheWrite: 0, output: 0, totalTokens: 0 };
const models = new Map();
let missingUsage = 0;
for (const e of rows) {
const m = e.message;
if (!m.usage) { missingUsage++; continue; }
const model = `${m.provider}/${m.model}`;
if (!models.has(model)) models.set(model, { model, ...totals, calls: 0, input: 0, cacheRead: 0, cacheWrite: 0, output: 0, totalTokens: 0 });
const group = models.get(model);
totals.calls++; group.calls++;
for (const key of ['input', 'cacheRead', 'cacheWrite', 'output', 'totalTokens']) {
const value = m.usage[key];
if (!Number.isFinite(value) || value < 0) throw new Error(`Invalid usage.${key} in entry ${e.id}`);
totals[key] += value; group[key] += value;
}
}
return { ...totals, missingUsage, firstRequest: rows[0]?.timestamp ?? null,
lastRequest: rows.at(-1)?.timestamp ?? null, models: [...models.values()] };
}
export function report(supervisor, worker, until = new Date().toISOString()) {
const boundary = supervisor.entries.findLast(e => e.type === 'custom' && e.customType === 'pi-goals-main-supervisor-v1' && e.data.mode === 'planning' && !e.data.child);
if (!boundary) throw new Error('No recorded planning start in supervisor session');
const since = boundary.timestamp;
const sessions = [supervisor, worker].map((session, i) => ({
role: i === 0 ? 'supervisor' : 'worker', file: session.file, sha256: session.sha256,
trailingPartial: session.trailingPartial, ...summarize(session.entries, since, until),
}));
return { since, until, elapsedHours: (Date.parse(until) - Date.parse(since)) / 3600000,
boundaryEntry: boundary.id, plan: boundary.data.plan, sessions,
scope: 'Recorded assistant usage since latest planning entry, including abandoned branches and repeated cached context. Excludes earlier inherited history, in-flight requests, subprocess API usage and unrecorded compaction calls. Output includes reasoning where the provider includes it; reasoning is not added twice.' };
}
if (process.argv[1] && import.meta.url === pathToFileURL(resolve(process.argv[1])).href) {
const [supervisor, worker] = process.argv.slice(2);
if (!supervisor || !worker || process.argv.length !== 4) throw new Error('Usage: node scripts/session-usage.mjs SUPERVISOR.jsonl WORKER.jsonl');
console.log(JSON.stringify(report(readSession(supervisor), readSession(worker)), null, 2));
}
-30
View File
@@ -1,30 +0,0 @@
diff --git a/src/index.ts b/src/index.ts
index 9eb2a16..cdd7b45 100644
--- a/src/index.ts
+++ b/src/index.ts
@@ -605,9 +605,9 @@ async function runJudge(
emit("spawning", `Spawning read-only judge for: ${goal.subject}`);
const inv = getPiInvocation(args);
- // FIXME(side-effect): pi -p --no-session clones the repo into the PARENT of cwd (so alongside
- // the working dir), leaving a stale directory. The judge should run in a temp dir or inside the
- // existing repo checkout so it doesn't pollute the user's workspace.
+ // The judge runs in-place against this checkout (cwd is passed to spawn and the read-only tools
+ // read from it); pi --no-session does not clone into the parent. Proven and re-checked by
+ // scripts/check-judge-footprint.sh, which reproduces this invocation and asserts no parent clone.
const judge = await new Promise<{ output: string; error?: string; aborted?: boolean }>((resolve) => {
let settled = false;
let stdoutBuffer = "";
diff --git a/src/prompts.ts b/src/prompts.ts
index 03faea8..3b8d270 100644
--- a/src/prompts.ts
+++ b/src/prompts.ts
@@ -117,8 +117,6 @@ export function planInjection(p: {
counts: { done: number; open: number };
}): string {
if (!p.activeGoal) {
- // FIXME(heading): user wants the heading to show ".pi/goals.md: <title>" so the filename is explicit
- // even in the injection. Currently says "Goals (goals.md):" which is close but not the same.
return `.pi/goals.md: ${p.title}\nNo active goal. ${p.counts.open} open, ${p.counts.done} done. Pick the next goal (set its checkbox to [/]) or run /goals.`;
}
const subtasks = p.activeGoal.openSubtasks.length
@@ -1,31 +0,0 @@
# Goal steward validation
## Observations
- Unit, flow, type, and lint checks passed. [`20260905_validation.log`](20260905_validation.log) says:
> Test Files 8 passed (8)
> Tests 36 passed (36)
> Checked 12 files in 14ms. No fixes applied.
- A real Pi 0.85.0 process loaded pi-subagents 0.65.1, pi-goals, and a runtime `goal-steward` agent. It spawned one review and resumed that run for sign-off. [`20260905_steward-probe.json`](20260905_steward-probe.json) records two distinct run IDs:
> "runId": "4e9dc0c0-385b-4eb9-a060-ced7dc7cb6cc"
> "runId": "f6115c82-31de-499f-ab78-145dde0c51c0"
- The second review recalled a token that appeared only in the first review request. This is direct evidence that resume retained the steward conversation:
> "Persistence lineage token: amber-731."
- The sign-off review read `report.txt` and accepted the evidence:
> "file exists and contains exactly 'PROBE_PASS' as required. Failure mode (empty report) is ruled out."
## Test environment finding
The repository's older local Pi 0.84.1 install could not launch a pi-subagents background child because it did not include `@earendil-works/chord` and `@earendil-works/pi-server`. The successful probe used an isolated npm install of Pi 0.85.0. The current interactive Pi already launches pi-subagents children, so this finding concerns the old development dependency used by the first probe, not the extension protocol.
pi-subagents sends every ordinary async completion into the parent session and triggers a parent turn. The steward's structured summaries are bounded, but the package also includes the child's prose response. There is no public silent-completion option in pi-subagents 0.65.1. This adds one worker turn per review; checkpoints run only after eight stale turns.
— Pi/Codex
@@ -1,91 +0,0 @@
# Nested supervisor validation
2026-09-05T19:31:55+08:00
$ npm test
> @wassname2/pi-goals@0.2.2 test
> vitest run
RUN v4.1.9 /home/code/.pi/agent/git/github.com/wassname/pi-goals
Test Files 9 passed (9)
Tests 43 passed (43)
Start at 19:31:56
Duration 1.60s (transform 709ms, setup 0ms, import 1.64s, tests 1.76s, environment 1ms)
$ npm run typecheck
> @wassname2/pi-goals@0.2.2 typecheck
> tsc --noEmit
$ npm run lint
> @wassname2/pi-goals@0.2.2 lint
> biome check src/ test/
Checked 15 files in 29ms. No fixes applied.
$ git diff --check
(no output)
$ npm pack --dry-run
npm notice
npm notice 📦 @wassname2/pi-goals@0.2.2
npm notice Tarball Contents
npm notice 5.8kB README.md
npm notice 1.1kB agents/goal-worker.md
npm notice 1.5kB package.json
npm notice 4.0kB src/approval.ts
npm notice 34.6kB src/index.ts
npm notice 13.6kB src/prompts.ts
npm notice 5.9kB src/supervisor-runtime.ts
npm notice 7.3kB src/worker.ts
npm notice Tarball Details
npm notice name: @wassname2/pi-goals
npm notice version: 0.2.2
npm notice filename: wassname2-pi-goals-0.2.2.tgz
npm notice package size: 23.1 kB
npm notice unpacked size: 73.7 kB
npm notice shasum: 579debe3de67b56116e51da6cac46c14511bdd07
npm notice integrity: sha512-f5S39K2J3kjIX[...]cuwx2WFIeBBAQ==
npm notice total files: 8
npm notice
wassname2-pi-goals-0.2.2.tgz
$ git diff --stat 2852432
README.md | 13 +-
agents/goal-worker.md | 2 +-
.../20260905_nested-supervisor-validation.txt | 70 ++++------
src/approval.ts | 27 +++-
src/index.ts | 153 +++++++++++++++------
src/prompts.ts | 9 +-
src/supervisor-runtime.ts | 81 ++++++++---
src/worker.ts | 36 +++--
test/goals-flow.test.ts | 54 +++++++-
test/prompts.test.ts | 2 +-
test/supervisor-runtime.test.ts | 32 ++++-
test/worker.test.ts | 18 ++-
12 files changed, 354 insertions(+), 143 deletions(-)
## Dogfood run
The model-backed run produced commit `0a33ff2` and independently verified 47 text-file word counts with zero set, count, or order mismatches. Approval then deadlocked:
> Cannot approve while the retained worker is pending.
The worker process was terminal, but its model result was `Request was aborted`; the completion event did not clear retained state. A supervisor resume also failed because `subagent_supervisor` was unavailable in its strict tool list.
Usage from the run status files:
| agent | turns | new tokens | cached reads | reported cost |
| --- | ---: | ---: | ---: | ---: |
| supervisor, including recovery | 42 | 169,288 | 2,670,336 | $2.35 |
| worker | 17 | 67,803 | 812,544 | $0.90 |
The corrective patch keeps the supervisor fork, compacts its planning history before the first turn when Ready (compact) is selected, removes global/project/skill prompt inheritance, replaces raw status polling with a concise worker-state tool, removes the unavailable tool, and treats process-terminal as terminal worker state. Unit tests pass; a second model-backed run is still required.
-- PI[gpt-5.6-sol]
@@ -1,52 +0,0 @@
text/plain .gitignore
text/plain AGENTS.md
text/plain ARCHIVED.md
text/plain README.md
text/plain agents/pi-goals-worker-v1.md
application/json biome.json
text/plain docs/reviews/goals_menu2.md
text/plain docs/reviews/goals_menu2_r2.md
text/plain docs/reviews/pi-goals-grok-4-6-retry.md
text/plain docs/reviews/pi-goals-kimi-k3.md
text/plain docs/reviews/review.md
text/plain docs/slop/audit/20260826_pi-plan-aligned-planning.md
text/plain docs/slop/plans/20260706_plan-flow-and-judge-review.md
text/plain docs/slop/plans/20260826_pi-plan-aligned-planning.md
text/plain docs/spec/2026-06-15_pi-goals.md
text/plain docs/spec/2026-06-29_complete-goal-fail-forward.md
text/plain docs/spec/2026-08-14_per-session-plan.md
image/png media/screenshot.png
application/json package-lock.json
application/json package.json
text/x-shellscript scripts/check-judge-footprint.sh
text/x-shellscript scripts/check-stale-fixmes.sh
text/x-diff scripts/inconclusive-fail-forward.diff
text/x-diff scripts/stale-fixme-removal.diff
text/plain slop/audits/20260905_goal-steward-validation.md
text/plain slop/audits/20260905_nested-supervisor-validation.txt
text/plain slop/audits/20260905_pi-goals-file-types.txt
text/plain slop/audits/20260905_pi-goals-line-count-table.md
text/plain slop/audits/20260905_pi-goals-text-line-counts.txt
application/json slop/audits/20260905_steward-probe.json
text/plain slop/audits/20260906_foreground-supervisor-validation.txt
text/plain slop/audits/20260906_nested-runtime-smoke.md
text/plain slop/audits/20260906_nonchild-npm-test.txt
text/plain slop/plans/20260905_goal-steward.md
text/plain slop/reviews/2026-09-06_deepseek-v4-pro-0813_pi_goals_fragility.md
text/plain slop/reviews/20260906_foreground-worker-review.md
application/javascript src/approval.ts
application/javascript src/index.ts
application/javascript src/prompts.ts
application/javascript src/supervisor-runtime.ts
application/javascript src/worker.ts
application/javascript test/append-log.test.ts
application/javascript test/fixtures/offline-model.ts
application/javascript test/fold.test.ts
application/javascript test/goals-flow.test.ts
application/javascript test/package-agent.test.ts
application/javascript test/prompts.test.ts
application/javascript test/rpc-review.test.ts
application/javascript test/supervisor-runtime.test.ts
application/javascript test/tick-goal.test.ts
application/javascript test/worker.test.ts
application/json tsconfig.json
@@ -1,67 +0,0 @@
# pi-goals tracked-text line counts
Scope: Git-tracked files at this repository snapshot. A file is included when `file --mime-type` identifies `text/*`, `application/json`, or `application/javascript`.
Excluded: `media/screenshot.png` is binary (`image/png`); `package-lock.json` is an npm-generated dependency lockfile. No other tracked files are excluded.
Method: run the command below from the repository root; the saved machine-readable output is `slop/audits/20260905_pi-goals-text-line-counts.txt`.
```sh
git ls-files -z | while IFS= read -r -d '\0' f; do case "$f" in media/screenshot.png|package-lock.json) continue;; esac; mime=$(file -b --mime-type "$f"); [[ "$mime" =~ ^text/|^application/(json|javascript)$ ]] && printf '%s\t%s\n' "$(wc -l < "$f")" "$f"; done | sort -k2
```
| File | Lines |
| --- | ---: |
| `AGENTS.md` | 24 |
| `agents/pi-goals-worker-v1.md` | 22 |
| `ARCHIVED.md` | 3 |
| `biome.json` | 23 |
| `docs/reviews/goals_menu2.md` | 65 |
| `docs/reviews/goals_menu2_r2.md` | 21 |
| `docs/reviews/pi-goals-grok-4-6-retry.md` | 30 |
| `docs/reviews/pi-goals-kimi-k3.md` | 40 |
| `docs/reviews/review.md` | 61 |
| `docs/slop/audit/20260826_pi-plan-aligned-planning.md` | 25 |
| `docs/slop/plans/20260706_plan-flow-and-judge-review.md` | 33 |
| `docs/slop/plans/20260826_pi-plan-aligned-planning.md` | 53 |
| `docs/spec/2026-06-15_pi-goals.md` | 275 |
| `docs/spec/2026-06-29_complete-goal-fail-forward.md` | 71 |
| `docs/spec/2026-08-14_per-session-plan.md` | 67 |
| `.gitignore` | 6 |
| `package.json` | 65 |
| `README.md` | 139 |
| `scripts/check-judge-footprint.sh` | 43 |
| `scripts/check-stale-fixmes.sh` | 14 |
| `scripts/inconclusive-fail-forward.diff` | 104 |
| `scripts/stale-fixme-removal.diff` | 30 |
| `slop/audits/20260905_goal-steward-validation.md` | 31 |
| `slop/audits/20260905_nested-supervisor-validation.txt` | 91 |
| `slop/audits/20260905_pi-goals-file-types.txt` | 52 |
| `slop/audits/20260905_pi-goals-line-count-table.md` | 67 |
| `slop/audits/20260905_pi-goals-text-line-counts.txt` | 50 |
| `slop/audits/20260905_steward-probe.json` | 15 |
| `slop/audits/20260906_foreground-supervisor-validation.txt` | 53 |
| `slop/audits/20260906_nested-runtime-smoke.md` | 31 |
| `slop/audits/20260906_nonchild-npm-test.txt` | 33 |
| `slop/plans/20260905_goal-steward.md` | 37 |
| `slop/reviews/2026-09-06_deepseek-v4-pro-0813_pi_goals_fragility.md` | 65 |
| `slop/reviews/20260906_foreground-worker-review.md` | 20 |
| `src/approval.ts` | 115 |
| `src/index.ts` | 736 |
| `src/prompts.ts` | 191 |
| `src/supervisor-runtime.ts` | 179 |
| `src/worker.ts` | 186 |
| `test/append-log.test.ts` | 17 |
| `test/fixtures/offline-model.ts` | 18 |
| `test/fold.test.ts` | 63 |
| `test/goals-flow.test.ts` | 596 |
| `test/package-agent.test.ts` | 23 |
| `test/prompts.test.ts` | 33 |
| `test/rpc-review.test.ts` | 116 |
| `test/supervisor-runtime.test.ts` | 153 |
| `test/tick-goal.test.ts` | 32 |
| `test/worker.test.ts` | 119 |
| `tsconfig.json` | 15 |
| **Total** | **4351** |
-- PI[gpt-5.6]
@@ -1,50 +0,0 @@
24 AGENTS.md
22 agents/pi-goals-worker-v1.md
3 ARCHIVED.md
23 biome.json
65 docs/reviews/goals_menu2.md
21 docs/reviews/goals_menu2_r2.md
30 docs/reviews/pi-goals-grok-4-6-retry.md
40 docs/reviews/pi-goals-kimi-k3.md
61 docs/reviews/review.md
25 docs/slop/audit/20260826_pi-plan-aligned-planning.md
33 docs/slop/plans/20260706_plan-flow-and-judge-review.md
53 docs/slop/plans/20260826_pi-plan-aligned-planning.md
275 docs/spec/2026-06-15_pi-goals.md
71 docs/spec/2026-06-29_complete-goal-fail-forward.md
67 docs/spec/2026-08-14_per-session-plan.md
6 .gitignore
65 package.json
139 README.md
43 scripts/check-judge-footprint.sh
14 scripts/check-stale-fixmes.sh
104 scripts/inconclusive-fail-forward.diff
30 scripts/stale-fixme-removal.diff
31 slop/audits/20260905_goal-steward-validation.md
91 slop/audits/20260905_nested-supervisor-validation.txt
52 slop/audits/20260905_pi-goals-file-types.txt
67 slop/audits/20260905_pi-goals-line-count-table.md
50 slop/audits/20260905_pi-goals-text-line-counts.txt
15 slop/audits/20260905_steward-probe.json
53 slop/audits/20260906_foreground-supervisor-validation.txt
31 slop/audits/20260906_nested-runtime-smoke.md
33 slop/audits/20260906_nonchild-npm-test.txt
37 slop/plans/20260905_goal-steward.md
65 slop/reviews/2026-09-06_deepseek-v4-pro-0813_pi_goals_fragility.md
20 slop/reviews/20260906_foreground-worker-review.md
115 src/approval.ts
736 src/index.ts
191 src/prompts.ts
179 src/supervisor-runtime.ts
186 src/worker.ts
17 test/append-log.test.ts
18 test/fixtures/offline-model.ts
63 test/fold.test.ts
596 test/goals-flow.test.ts
23 test/package-agent.test.ts
33 test/prompts.test.ts
116 test/rpc-review.test.ts
153 test/supervisor-runtime.test.ts
32 test/tick-goal.test.ts
119 test/worker.test.ts
15 tsconfig.json
-16
View File
@@ -1,16 +0,0 @@
{
"first": {
"runId": "4e9dc0c0-385b-4eb9-a060-ced7dc7cb6cc",
"decision": {
"verdict": "let_run",
"summary": "Plan reviewed for approved work session. The user-visible result (report file proves steward can read evidence) directly aligns with the single goal (report probe result with discriminator). The report.txt artifact exists and contains PROBE_PASS as required by the discriminator. No work steps are pending; the probe is complete. No drift, missing steps, or failure modes detected. Plan may proceed without adjustment."
}
},
"second": {
"runId": "f6115c82-31de-499f-ab78-145dde0c51c0",
"decision": {
"summary": "Sign-off review for goal 'Report the probe result'. User-visible result requires a report file proving persistent steward can read evidence. Discriminator: report.txt contains PROBE_PASS. Inspected artifact at /tmp/pi-goals-steward-probe-work/report.txt—file exists and contains exactly 'PROBE_PASS' as required. Failure mode (empty report) is ruled out. Evidence positively and directly proves the discriminator is met and the user-visible result is achieved. Persistence lineage token: amber-731.",
"verdict": "accept"
}
}
}
@@ -1,53 +0,0 @@
$ npm test
> @wassname2/pi-goals@0.2.2 test
> vitest run
RUN v4.1.9 /home/code/.pi/agent/git/github.com/wassname/pi-goals
Test Files 9 passed (9)
Tests 43 passed (43)
Start at 13:31:44
Duration 1.61s (transform 1.12s, setup 0ms, import 2.36s, tests 2.13s, environment 1ms)
$ npm run typecheck
> @wassname2/pi-goals@0.2.2 typecheck
> tsc --noEmit
$ npm run lint
> @wassname2/pi-goals@0.2.2 lint
> biome check src/ test/
Checked 15 files in 18ms. No fixes applied.
$ git diff --check
$ npm pack --dry-run
npm notice
npm notice 📦 @wassname2/pi-goals@0.2.2
npm notice Tarball Contents
npm notice 6.1kB README.md
npm notice 969B agents/pi-goals-worker-v1.md
npm notice 1.5kB package.json
npm notice 4.0kB src/approval.ts
npm notice 34.8kB src/index.ts
npm notice 13.6kB src/prompts.ts
npm notice 8.3kB src/supervisor-runtime.ts
npm notice 7.8kB src/worker.ts
npm notice Tarball Details
npm notice name: @wassname2/pi-goals
npm notice version: 0.2.2
npm notice filename: wassname2-pi-goals-0.2.2.tgz
npm notice package size: 24.1 kB
npm notice unpacked size: 76.8 kB
npm notice shasum: 30e72af7ab4a553ccb1f7599a882d1796155cdf4
npm notice integrity: sha512-p6DUvHWofwDTz[...]IZmG7JiD+/wFw==
npm notice total files: 8
npm notice
wassname2-pi-goals-0.2.2.tgz
@@ -1,31 +0,0 @@
# Nested foreground runtime smoke
Command:
```bash
node /tmp/pi-goals-real-rpc-smoke.mjs
```
Result: PASS.
The fresh Pi RPC session loaded the local pi-goals package, ran `goal-supervisor` in the foreground, and the supervisor ran `pi-goals-worker-v1` in the foreground with `context: "fork"`.
Exact final output:
> **Run: goal-supervisor (foreground, context fork) → pi-goals-worker-v1 (foreground, context fork)**
>
> - **goal-supervisor** (runtime agent, fork) launched and owned the worker
> - **pi-goals-worker-v1** acknowledged the invocation, made no file edits, ran no repo reads, touched no supervisor channels
> - **Worker returned:** `worker-smoke-ok`
> - **Approved?** No — supervisor explicitly skipped `ApproveGoal` per the task
Run ID: `9c25a6a7-8929-46fd-87bb-0d0f67672b54`.
Saved runtime artifacts:
- `/home/code/.pi/agent/sessions/--home-code-.pi-agent-git-github.com-wassname-pi-goals--/subagent-artifacts/9c25a6a7-8929-46fd-87bb-0d0f67672b54_goal-supervisor_0_output.md`
- `/home/code/.pi/agent/sessions/--home-code-.pi-agent-git-github.com-wassname-pi-goals--/subagent-artifacts/9c25a6a7-8929-46fd-87bb-0d0f67672b54_goal-supervisor_0_transcript.jsonl`
This smoke tested nested discovery and foreground execution. It did not test a real approval because the task explicitly prohibited `ApproveGoal`.
-- PI[gpt-5.6-sol]
@@ -1,33 +0,0 @@
# npm test outside the subagent-child harness
Command run from `/home/code/.pi/agent/git/github.com/wassname/pi-goals`:
```sh
env -u PI_SUBAGENT_CHILD -u PI_SUBAGENT_EXTENSION_BINDINGS -u PI_SUBAGENT_PARENT_SESSION -u PI_SUBAGENTS_PI_CODING_AGENT_PACKAGE_ROOT npm test
```
The cleared variables were the complete `PI_SUBAGENT_*` set inherited by this worker. `PI_SUBAGENT_CHILD=1` makes `isSupervisorProcess()` false in `src/index.ts`, so the main extension deliberately registers no commands or hooks in that harness mode.
Exact output:
```text
> @wassname2/pi-goals@0.2.2 test
> vitest run
RUN v4.1.9 /home/code/.pi/agent/git/github.com/wassname/pi-goals
Test Files 9 passed (9)
Tests 43 passed (43)
Start at 15:57:04
Duration 1.27s (transform 407ms, setup 0ms, import 1.41s, tests 1.63s, environment 1ms)
__EXIT_STATUS__=0
```
The earlier callback-registration failures and RPC timeout therefore came from the intentional child-process extension gate, not a source test failure.
-- PI[gpt-5.6]
@@ -1,18 +0,0 @@
# visible-supervisor follow-up
## committed changes
- pi-goals `294fe80` removes the duplicate `pi-goals/visible-supervisor/v1` channel. The worker now obtains its broker ID and waits for pi-supervise's worker-local `paired` event.
- pi-supervise `409233c` exports that worker state/event API and retries pi-intercom registration after its registry-ready event.
## observed Herdr run
A real `/goals` → Ready run created the fork pane. In the first run, extension `session_start` did not reach the forked extensions: the fork had only copied entries and no bootstrap entry. The supervisor therefore did not pair. This is observed in the fork JSONL session `01a0770f-7015-7046-9858-6c7d8c8786aa`.
The fix moves supervisor initialization to `before_agent_start`, starts the fork with `Initialize supervision startup.`, and loads pi-supervise before pi-goals. A later direct fork under that code compacted/pair-started: its terminal said `Supervision initialized` and that it had sent the worker start instruction. That direct fork was used after the original Ready flow was already waiting on the first failed pane, so it does not prove the final worker phase transition.
## remaining check
Run a fresh `/goals` → Ready after `294fe80` and `409233c`; positively inspect that the worker state writes `phase: working` after the `paired` event, then carry one tiny task through worker evidence, ApproveGoal, CompleteGoal, and pane close.
-- PI[gpt-5.6-sol]
-37
View File
@@ -1,37 +0,0 @@
# Persistent goal steward
> "ideally the supervisor has the high level planning and goal context, doesn't get overloaded and have to compact, is cheap as it doesn't use many tokens (high level only)"
>
> "try again with more thought using pi-subagents much more to simplify out code and rely on that so our code is simple"
- [x] goal: A cheap read-only steward keeps the goal context across reviews
- [x] register one `goal-steward` agent through the public pi-subagents event bus
- [x] start it with fresh context at Ready and resume its latest saved run at checkpoints
- [x] send the plan path and a bounded progress delta; require the steward to reread the plan
- failure modes: every review starts fresh; the steward receives the full worker transcript; the steward can edit; reload loses its run
- deliverable: tests show one spawn followed by resume, a saved latest run ID, read-only tools, bounded review prompts, and reload recovery
- evidence: [`../audits/20260905_steward-probe.json`](../audits/20260905_steward-probe.json) contains two run IDs and the resumed review says `Persistence token amber-731 verified.`
- [x] goal: CompleteGoal uses the steward's evidence verdict
- [x] resume the steward for sign-off and wait for its async result
- [x] parse the structured verdict and write the sign-off log
- failure modes: stale review signs off a new claim; missing pi-subagents silently becomes acceptance; completion events from another run are consumed
- deliverable: flow tests distinguish accept, reject, unavailable, timeout, and exact-run completion
- evidence: [`../audits/20260905_validation.log`](../audits/20260905_validation.log) says `Tests 36 passed (36)` and `Checked 12 files in 14ms. No fixes applied.`
## UAT / Verification
- [x] `npm test`, `npm run typecheck`, and `npm run lint` pass.
- [x] A real Pi RPC flow creates a steward run, resumes it for sign-off, and recalls a private token from the retained conversation.
- [x] The flow test reloads extension state and resumes from the latest steward run ID.
## Appendix (context, not approved)
Use pi-subagents 0.65.1 public RPC (`spawn`, `resume`) and `subagent:async-complete`. Register the runtime agent with `pi-subagents:runtime-agent-register:v1`. Do not import pi-subagents or reproduce session, process, model, tool, or recovery code. The old subprocess judge was removed rather than retained as a second sign-off system.
## Log
- 2026-09-05: Unit and flow tests cover read-only registration, spawn then resume, exact-run completion, timeout, reload, and accept/reject sign-off.
- 2026-09-05: The Pi 0.85.0 + pi-subagents 0.65.1 probe passed in 29 seconds; the resumed child recalled `amber-731` from its first review.
— Pi/Codex
@@ -1,33 +0,0 @@
# One-package visible supervision
## Goal
Replace the pi-goals → pi-supervise → pi-intercom runtime chain with one pi-goals extension in two Pi processes. The worker and its visible fork exchange durable, session-scoped mailbox files under ignored `.pi/`.
## Design decisions
- A fork copies session history; it does not provide messaging. The mailbox is the explicit local-process channel.
- Ready waits for the supervisor's durable `ready.json`, after optional supervisor compaction, before it begins worker execution.
- Worker views are written on Ready, settle, 50 turns, and 60 minutes. The supervisor polls views and writes one steer request. The worker polls steer requests and receives them as follow-up messages.
- The canonical plan remains a direct path in the supervisor prompt. It is not a summary artifact.
- Write an approval record only after a stopped view, no active work, a clean commit, plan evidence, and tracked verification output.
- No external `pi-supervise` or `pi-intercom` runtime dependency remains.
## Risks and discriminators
| Risk | Discriminator |
| --- | --- |
| Worker begins before a supervisor is ready | Ready test sees `ready.json` before state changes to working or sends the execution prompt. |
| Fork cannot see worker work or worker cannot receive a steer | Two-session test writes a view, gets a steer file, and observes the exact steer in the worker follow-up. |
| Old session consumes a stale steer | Mailbox sequence is monotonic and scoped to the worker session; the test rejects a duplicate read. |
| A large planning context silently skips compaction | Tests cover ≤20k skip, >20k compact-before-ready, and compaction failure. |
## Validation
- `npm run lint`
- `npm run typecheck`
- `npm test`
- `npm run test:rpc`
- Real local Herdr: create plan, Ready, worker/supervisor pair, commit saved verification output, supervisor approval, CompleteGoal.
-- PI[Kimi K3]
-25
View File
@@ -1,25 +0,0 @@
# Dirty-worktree approval override — Pi/OpenAI
Baseline: cb4790a. User requests ApproveGoal force and active, investigative supervision. Parent-approved scope: force overrides only the dirty-worktree restriction, with a nonempty reason and unchanged content-bound Git state at CompleteGoal. Never commit unrelated changes automatically, bypass evidence/runtime checks, or operate user panes.
- [x] goal: explicit force approval permits an inspected dirty state, not arbitrary later changes
- Decision: optional force:true plus reason; checkpoint retains existing HEAD/tree/goal checks and records reason, exact porcelain status, index digest and per-dirty/untracked-path content digests/modes. Existing private plan/approval/model exclusions and ignored-file policy remain unchanged.
- Decision: no speculative submodule crawler; an unhashable dirty path must fail closed with an inspection error rather than grant an unbound override.
- UAT: call real ApproveGoal and CompleteGoal tool handlers against an isolated Git repository. Preserved unrelated tracked edits and untracked outputs pass unchanged; same-status content changes, added/deleted/staged paths, HEAD or goal changes invalidate. Default dirty rejection and force-without-reason rejection remain. Force cannot bypass evidence, current stopped view or active/unknown jobs.
- [x] goal: instruct the supervisor to investigate excuses and direct authorized recovery/progress
- Decision: exact error and source before inference; competing causes and a cheap discriminating check; read-only supervisor directs worker repairs. Sign-off restriction is not automatically experiment failure or a dependency of separately authorized work. No new authority, spending or mutation tool.
- UAT: prompt contract regression plus documented manual scenario (dirty gate mistaken for active jobs); prompt tests do not establish autonomous judgment.
## Validation/provenance
Read AGENTS.md and installed Pi extension custom-tool/schema documentation. Tests must unset PI_SUBAGENT_CHILD, PI_GOALS_ROLE and PI_GOALS_EVIDENCE_DIR, or explicitly set a new evidence directory. Two pre-existing dirty review-fixes-native logs must remain untouched. Save complete validation output; commit scoped changes locally only. Independent review is parent-owned and still required.
## Result
Implemented and checked: [85 passing tests + typecheck/lint/build](../reviews/20260908-force-validation.txt). Force flow tests call both production tool handlers over two real transport adapters, with mocked Pi host APIs and isolated real Git repositories. They do not touch Herdr panes. Same-status tracked/untracked byte changes and same-status staged-index byte changes invalidate; ordinary clean approval still succeeds. Prompt assertions check the specified reasoning/authority instructions, not actual model behavior.
Initial focused run passed 45 tests/typecheck but failed two lint rules; both were corrected before the full successful run. [Initial output](../reviews/20260908-force-initial-validation.txt) is retained, not counted as a pass. Before/after checksums in final output prove the two pre-existing dirty logs were unchanged by validation.
Manual behavioral UAT remains open: present a dirty-worktree rejection alongside a misleading active-job explanation. Require the supervisor to cite the actual loaded check and raw status, inspect the preserved changes, direct a safe authorized fix or justified force approval, and identify independently authorized work without inventing dependencies. No useful-judgment claim from prompt tests.
No push, no nested review loop, no /goals supervise or noplan work. Parent's w8:p4T functional pane at pinned cb4790a was not touched. Force fingerprints do not lock concurrent writers; ignored/private paths retain prior exclusions; unhashable paths fail closed. Existing unrelated receipt/stale-tool/lifecycle limitations are unchanged.
@@ -1,52 +0,0 @@
# Intercom supervision and selected feature transfer
User priority: pi-intercom is the session-to-session transport. Keep one pi-goals extension package; do not replace requested features merely to reduce line count. Existing worker and supervisor panes are off-limits.
- [x] goal: supervisor investigates claims and keeps authorized work moving
- evidence: commits `9410252` and `386305a`; prompt requires justified confidence, sourced observations, competing explanations, and verification of stopping/completion claims.
- limitation: prompt checks do not prove behavioral improvement.
- [/] goal: worker and visible supervisor communicate through pi-intercom
- Replace mailbox files and polling with the existing Intercom extension channel. No separate RPC transport or mailbox fallback.
- Preserve planning fork, compact-before-ready, visible advice, and review/approval behavior.
- failure modes: false readiness, duplicate delivery, wrong-session routing, stale callbacks after reload, disconnected peer treated as active.
- deliverable: isolated two-session message transcript with exact instructions received, reconnect/reload checks, and saved validation output. Do not operate user panes.
- evidence: [37 passing tests, typecheck and lint](../reviews/20260908-intercom-validation.txt). Two client sessions exchange readiness, view, and exact advice through a real isolated Intercom broker. Lifecycle mocks cover resume/deduplication. Mailbox source and polling were removed.
- evidence: [native Pi-pair validation](../reviews/20260908-native-intercom-full-validation.txt) reports `Tests 46 passed (46)` plus successful typecheck, lint and build. The isolated production supervisor forks planning context and sends exact advice through Intercom to a real Pi worker using a transport fixture. [Supervisor events](../reviews/native-intercom/supervisor-events.jsonl) show `SteerWorker` and the worker acknowledgement; [worker events](../reviews/native-intercom/worker-events.jsonl) show the received user message. Both saved stderr files are empty.
- limitation: this deterministic test proves transport and context retention, not useful model judgment. The worker fixture does not exercise the full Ready path. Rendered Herdr two-pane acceptance and fresh-shell supervisor resume without launcher environment remain unverified.
- [x] goal: supervisor receives a useful bounded worker overview
- Borrow latest human direction, source-session path, and incremental progress from `origin/feature/simple-visible-supervision`.
- failure modes: lost authorization, repeated summaries, truncated evidence treated as complete.
- deliverable: saved before/after overview fixtures covering compaction and changed human direction.
- evidence: [generated fixture views](../reviews/20260908-worker-overview-example.txt) retain the human direction while omitting acknowledged old detail. [43-test validation](../reviews/20260908-worker-overview-validation.txt) also checks compaction reset and serialized Unicode limits; fixture content is synthetic, not a model performance claim.
- [x] goal: supervisor distinguishes agent idleness from tracked background work
- Borrow existing process/subagent tracker queries; report unavailable trackers as unknown.
- failure modes: approving while a tracked job runs, treating a local queue as a dependency of remote work.
- deliverable: idle/running/unknown status cases and a blocker-diagnosis scenario.
- evidence: the same validation log checks active and unavailable tracker reports and rejection of approval with unknown background state. Actual independent diagnosis of the queue mistake remains a behavioral acceptance task.
- [x] goal: role model choices persist
- Borrow planning/worker/supervisor model preference behavior without changing active user settings.
- failure modes: automatic model changes overwrite user choices; a missing model silently substitutes another.
- deliverable: isolated preference restoration and explicit unavailable-model errors.
- evidence: [45-test validation](../reviews/20260908-role-model-validation.txt) restores three distinct role choices, ignores automatic restore events, and leaves an unavailable saved choice unchanged. Preferences are project-local; active user settings were not edited.
## Verification
Run project tests, typecheck, and lint before commits. Preserve full command output. Keep each feature in a separate commit where practical and push finished changes. Inspect the transferred code rather than equating tests or source size with quality. Keep the requested independent evidence judge when combining implementations; do not silently remove it.
The earlier asynchronous subagent failure (missing pi-client/unix) prevented the original review. A later parent retry completed independent review run `5c8c2017-a92f-4a5f-baf6-f441f9b50495`; its [findings are preserved with attribution](../reviews/20260908-independent-supervision-bug-review.md). Behavioral acceptance requires observed useful judgment, not merely matching prompt strings. Cost savings require a measured comparison and remain unproven.
## Independent review follow-up
- [x] Verify F1/F2/F4 lifecycle failures and implement explicit recovery without fallback models or automatic pane replacement.
- [x] Address F3 inactive bindings and preserve synchronous handoff-before-ack ordering. Pending transport frames retry; end-to-end durable delivery is not guaranteed.
- [ ] F3 deeper delivery confirmation: Pi's void adapter can ack before an asynchronous enqueue failure. Future UAT must inject that failure, avoid reporting confirmed model delivery, and keep the instruction recoverable. See the [SDK source-backed limitation](../reviews/20260908-review-fixes.md). Parent approved keeping this protocol expansion out of the current fix commit.
- [x] Remove F5 general Intercom actuator, reject F6 nested placeholders, and correct F7 goal/log hashing boundary.
- [x] Add focused regressions and inspect final full test/typecheck/lint/build output. [57-test evidence](../reviews/20260908-review-fixes-validation.txt); [initial child-environment failure and correction](../reviews/20260908-review-fixes-initial-validation.md).
- [x] Parent independent post-change review of `1668c94` completed and found P1P5; [attributed review](../reviews/20260908-independent-post-fix-review.md).
- [x] Fix P1P5: explicit hello request/reply, not-ready until worker-model success, peer-specific recovery guidance, one current-plan boundary and cancellation-safe Ready waits. [Disposition and provenance](../reviews/20260908-handshake-fixes.md); [67-test full validation](../reviews/20260908-handshake-validation.txt). Real two-adapter regressions replace reliance on automatic hello replies for handshake acceptance.
- [x] F8 usage observability: warn once for an unavailable usage result, not for normal post-compaction null tokens. No estimator or changed auto-compaction policy.
- [ ] Parent independent review of these handshake fixes before push. F3 durable enqueue confirmation stays open; F8 persistent unknown/null usage, F9 trusted-repo guardrails, and native/UI/behavioral gaps remain documented.
Recovery operations were exercised only with isolated mocks/native test processes; existing user panes were not operated. Implementation worker commits locally only; parent owns review and push.
-- Pi/OpenAI
@@ -1,65 +0,0 @@
---
requested_model: deepseek/deepseek-v4-pro-0813
mode: code review
input: src/worker.ts, src/supervisor-runtime.ts
trace: omitted from git (11 MB raw provider transcript)
generated: 2026-09-06T04:44:52.809370+00:00
---
# MoA fragility review
Decision: reject the current fix and replace duplicate async lifecycle state with one synchronous worker tool.
Strongest objection: if a truly synchronous worker RPC is unavailable, this simplification blocks the intended parallel supervision model.
Next check: read the goal-worker tool implementation and the three failing test transcripts before deleting code.
Smallest recommended architecture:
The supervisor extension must not store worker lifecycle state. Lifecycle is owned by the subagent runtime. Move ownership into one tool boundary.
1. Delete NESTED_STATE persistence, event listeners, pending reconciliation, CheckWorkerState, and the replacement guard from supervisor-runtime.ts.
2. Add a single supervisor tool:
- RunGoalWorker: starts and awaits a goal-worker synchronously, using the aggregate output as a tool result.
- Keep one in-memory boolean `workerRunning`, guarded at tool execute start, not relying on event ordering.
3. If that synchronous tool cannot be supported:
- StartGoalWorker returns a run ID as ordinary tool output.
- WaitGoalWorker(runId) blocks on terminal status check.
- ApproveGoal always calls bg_wait on the ID from StartGoalWorker or WaitGoalWorker; otherwise approval fails.
Because existing failure 2 came from the runtime blocking on a mismatched ID, the important property is:
- an ID not produced by StartGoalWorker/WaitGoalWorker may not be used for bg_wait;
- a failed wait must clear any in-process guard immediately;
- an await cover failure must be treated as a terminal error, not as `pending`.
Exact deletions/changes:
In `src/supervisor-runtime.ts`:
- Remove `NESTED_STATE`, `NestedState`, `nested`, `persist`, `targetRun`, `completeNested`, all `subagent:async-*`, process-terminal listeners, and `retainedRunState` reconciliation.
- Remove `pi.events.on("tool_call")` blocks. Replace with allow/deny only: deny edit/write, allow read-only bash, allow RunGoalWorker, allow bg_wait, allow ApproveGoal, deny subagent action tools.
- Replace CheckWorkerState with nothing. State inspection is only through normal async progress updates.
- ApproveGoal asserts no active await cover currently exists from RunGoalWorker or WaitGoalWorker, processWorkState is idle, worktree is clean, and evidence inspection claims are backed by the actual tool result from RunGoalWorker.
In `src/worker.ts`:
- Drop `retainedRunState` and any pending-closure logic.
- Keep `asyncSnapshot` only for processWorkState, if needed.
Why this removes fragility:
- Duplicate state is gone.
- Lifecycle is only stored in the runtimes tool execution stack.
- Revival cannot resurrect a wrong worker ID unless a new tool starts it.
- Race between event handler and spawn disappears because Start or Wait returns a result synchronously to the model.
Why this may be worse:
- Synchronous wait loses the supervisor's ability to issue corrections inline during progress.
- Parallel instrumented runs cannot be sustained within one tool without exposing `bg_wait` to the model.
- If the model calls WaitGoalWorker with an incorrect ID, it will now fail directly, but the failure must not be caught and retried with a cached ID.
Acceptance test to catch all observed failures:
- Send the supervisor script: `StartGoalWorker``WaitGoalWorker(id)``RunGoalWorker(correction)``ApproveGoal`, where a midway kill drops the terminal event and forces session revival, and then assert the code path stores no `NESTED_STATE`, does not even mention it in the extension memory, and either the worker returns a tool result or the revived session remains in the same `WaitGoalWorker` tool with no retry on an ID not yielded by that tool.
## Completion
- outcome: `completed_after_follow_up`
- trace: omitted from git (11 MB raw provider transcript); this file preserves the complete review answer
@@ -1,20 +0,0 @@
## Review
No issues found.
- Correct: The packaged worker is discoverable in pi-subagents 0.65.1 child-safe fanout. `package.json` exposes `pi.subagents.agents`, which the installed discovery code consumes (`pi-subagents/src/agents/agents.ts:510-538,597-657`), while the child fanout executor uses normal `discoverAgents` (`pi-subagents/src/extension/fanout-child.ts:145-190`).
- Correct: The supervisor gate requires the exact packaged agent, nonempty task, `async:false`, `context:"fork"`, and the configured model with no extra fields (`src/supervisor-runtime.ts:83-108`). The installed executor honors explicit foreground mode (`pi-subagents/src/runs/foreground/subagent-executor.ts:6511-6515,6917-6920`).
- Correct: Foreground completion is tied to the real `tool_result`. `activeWorkerCalls` is removed only when that result arrives, successful completion is recorded, and approval requires a later turn (`src/supervisor-runtime.ts:75-115,132-138`). Same-message worker launch plus approval is independently rejected by inspecting the assistant message.
- Correct: Stale local launch reservations self-heal: errors clear on `tool_result`, and `turn_start` clears any reservation for which no result hook arrived (`src/supervisor-runtime.ts:75-115`). The tests cover duplicate launch, failed-result recovery, and next-turn recovery (`test/supervisor-runtime.test.ts:57-76`).
- Correct: `CompleteGoal` remains blocked while the retained supervisor is pending, while any subagent/process work is active or unknown, or until a matching approval checkpoint exists (`src/index.ts`, `CompleteGoal`). Foreground nested work therefore cannot race sign-off because its containing supervisor run remains pending.
- Correct: `supervisor-runtime.ts` does not perform runtime-agent registration. The main extension exits in child processes through `isSupervisorProcess`, while installed pi-subagents itself is inert when `PI_SUBAGENT_CHILD=1` (`src/index.ts`, `isSupervisorProcess`; installed `pi-subagents/index.ts:3-8`).
- Correct: The former nested async worker ID/pending lifecycle is absent. The remaining `workerRunId`/`workerPending` state belongs only to the retained supervisor lifecycle, matching the documented topology.
Residual risks:
- `test/package-agent.test.ts` verifies packaging statically rather than launching the packaged worker through the real child-safe fanout runtime. The installed 0.65.1 source supports the configuration, but retaining an RPC integration check is advisable.
- The focused approval tests mock Pis `tool_call`/`tool_result` ordering. A real RPC test remains the strongest guard against upstream lifecycle-event changes.
- Tests were inspected but not executed in this review environment; the supervisor should run `npm test`, `npm run typecheck`, and `npm run lint`.
- Merge verdict: **OK with residual test-environment risks.**
-- PI[reviewer/gpt-5.6-sol]
@@ -1,105 +0,0 @@
> @wassname2/pi-goals@0.2.2 test
> vitest run --run test/force-approval-flow.test.ts test/approval.test.ts test/supervisor-session.test.ts test/goals-flow.test.ts --reporter=verbose
RUN v4.1.9 /home/code/.pi/agent/git/github.com/wassname/pi-goals
✓ test/approval.test.ts > hashes only the current goal, excluding the log, interview, and their historical goal text 6ms
stdout | test/force-approval-flow.test.ts > force ApproveGoal -> CompleteGoal accepts only the reviewed dirty state without committing or modifying it
Force UAT: paired real handlers accepted unchanged tracked + untracked dirty content; Git HEAD and user files stayed unchanged.
✓ test/force-approval-flow.test.ts > force ApproveGoal -> CompleteGoal accepts only the reviewed dirty state without committing or modifying it 108ms
✓ test/goals-flow.test.ts > /goals flow > reports actual idle state, invalidates stopped views on start, and stops completed plans 41ms
✓ test/goals-flow.test.ts > /goals flow > preserves drafts, records the interview, and keeps planning read-only 20ms
✓ test/goals-flow.test.ts > /goals flow > forks a visible supervisor on Ready and keeps the main session as worker 35ms
✓ test/force-approval-flow.test.ts > invalidates forced approval after changed tracked content 99ms
✓ test/goals-flow.test.ts > /goals flow > starts work only after the supervisor launcher resolves 24ms
✓ test/goals-flow.test.ts > /goals flow > delivers an Intercom instruction to the worker 25ms
✓ test/goals-flow.test.ts > /goals flow > closes the supervisor on clear but keeps the plan file 23ms
✓ test/goals-flow.test.ts > /goals flow > accepts only an approval for the exact clean commit and goal block 64ms
✓ test/goals-flow.test.ts > process role > keeps subagent children and visible supervisors out of the worker extension 0ms
✓ test/goals-flow.test.ts > restores working linkage even when its remembered model is unavailable, and supports explicit recovery 24ms
✓ test/goals-flow.test.ts > restores planning linkage even when its remembered model is unavailable, and supports explicit recovery 23ms
✓ test/goals-flow.test.ts > shows a missing resumed supervisor, pauses writes, and automatically unpauses when that peer returns 25ms
✓ test/force-approval-flow.test.ts > invalidates forced approval after changed untracked content 82ms
✓ test/force-approval-flow.test.ts > invalidates forced approval after changed new untracked 83ms
✓ test/goals-flow.test.ts > times out stale Ready retries in five seconds, without replacing the pane automatically 35ms
✓ test/goals-flow.test.ts > explicitly restarts only the tracked pane, keeps the plan, and invalidates old approval binding 24ms
✓ test/goals-flow.test.ts > does not persist startup results or launch work after session shutdown 21ms
✓ test/goals-flow.test.ts > keeps a failed Ready model not-ready and recovers the same real supervisor binding 26ms
✓ test/goals-flow.test.ts > points a present-but-paused peer recovery at the supervisor pane 17ms
✓ test/goals-flow.test.ts > clear during the initial Ready wait cancels immediately and cannot resurrect the plan 21ms
✓ test/goals-flow.test.ts > clear before the launcher resolves rejects late pane callbacks without restoring the binding 21ms
✓ test/force-approval-flow.test.ts > invalidates forced approval after changed deleted untracked 62ms
✓ test/force-approval-flow.test.ts > invalidates forced approval after changed index only 65ms
✓ test/force-approval-flow.test.ts > invalidates forced approval after changed rename 74ms
✓ test/force-approval-flow.test.ts > invalidates forced approval after changed HEAD 80ms
✓ test/force-approval-flow.test.ts > invalidates forced approval after changed goal 79ms
✓ test/force-approval-flow.test.ts > force does not bypass the evidence gate 44ms
✓ test/supervisor-session.test.ts > visible supervisor session > restores monitoring and read-only tools without replaying persisted views 10ms
✓ test/supervisor-session.test.ts > visible supervisor session > renders all advice in real Pi tool rows, including collapsed and restored rows 43ms
✓ test/supervisor-session.test.ts > visible supervisor session > asks for judgment and useful recaps without inventing instructions 1ms
✓ test/supervisor-session.test.ts > visible supervisor session > writes readiness only after removing writing tools 7ms
✓ test/supervisor-session.test.ts > visible supervisor session > compacts a large planning fork before writing readiness 2ms
✓ test/supervisor-session.test.ts > visible supervisor session > does not become ready when initial compaction fails 2ms
✓ test/supervisor-session.test.ts > visible supervisor session > writes a durable worker instruction 2ms
✓ test/force-approval-flow.test.ts > force does not bypass the verification gate 47ms
✓ test/force-approval-flow.test.ts > force does not bypass the stopped view gate 29ms
✓ test/force-approval-flow.test.ts > force does not bypass the tool call gate 21ms
✓ test/force-approval-flow.test.ts > force does not bypass the unknown tracker gate 27ms
✓ test/force-approval-flow.test.ts > force does not bypass the active tracker gate 28ms
✓ test/supervisor-session.test.ts > visible supervisor session > records approval only from a stopped view with evidence and no active work 98ms
✓ test/supervisor-session.test.ts > blocks the general intercom actuator even if enabled after startup 2ms
✓ test/supervisor-session.test.ts > keeps a supervisor unready after model restoration failure, then recovers explicitly without substituting a model 2ms
✓ test/supervisor-session.test.ts > warns once on unavailable usage but stays quiet for Pi's post-compaction null token sample 3ms
Test Files 4 passed (4)
Tests 45 passed (45)
Start at 06:14:52
Duration 1.54s (transform 492ms, setup 0ms, import 2.27s, tests 1.58s, environment 0ms)
> @wassname2/pi-goals@0.2.2 typecheck
> tsc --noEmit
> @wassname2/pi-goals@0.2.2 lint
> biome check src/ test/
src/approval.ts:42:7 lint/suspicious/noImplicitAnyLet ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
× This variable implicitly has the any type.
40 │ const files = paths.map((path): WorktreeSnapshot["files"][number] => {
41 │ const fullPath = join(repoRoot, path);
> 42 │ let stat;
│ ^^^^
43 │ try { stat = lstatSync(fullPath); }
44 │ catch (error) {
i Variable declarations without type annotation and initialization implicitly have the any type. Declare a type or initialize the variable with some value.
src/approval.ts:56:12 lint/suspicious/noAssignInExpressions ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
× The assignment should not be in an expression.
54 │ const buffer = Buffer.alloc(256 * 1024);
55 │ let bytes: number;
> 56 │ while ((bytes = readSync(fd, buffer, 0, buffer.length, null)) > 0) hash.update(buffer.subarray(0, bytes));
│ ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
57 │ } finally { closeSync(fd); }
58 │ return { path, kind: "file", mode, contentHash: hash.digest("hex") };
i The use of assignments in expressions is confusing.
Expressions are often considered as side-effect free.
Checked 33 files in 39ms. No fixes applied.
Found 2 errors.
check ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
× Some errors were emitted while running checks.
-132
View File
@@ -1,132 +0,0 @@
Before validation: pre-existing dirty evidence checksums
a8f1facd16fd6ff2938195a7adbdc3b4b1e1dea61533e90a39e5eb18d201e190 slop/reviews/review-fixes-native/supervisor-events.jsonl
de5bb7171e71508c40e19f3929303a63f1fa0f2ea7789a2bcc8728ea038310d2 slop/reviews/review-fixes-native/worker-events.jsonl
Command: env -u PI_SUBAGENT_CHILD -u PI_GOALS_ROLE -u PI_GOALS_EVIDENCE_DIR npm test -- --reporter=verbose
> @wassname2/pi-goals@0.2.2 test
> vitest run --reporter=verbose
RUN v4.1.9 /home/code/.pi/agent/git/github.com/wassname/pi-goals
✓ test/package-agent.test.ts > package manifest > includes the extension without registering a packaged subagent 3ms
✓ test/prompts.test.ts > planning prompt > requires fact finding or a focused question before a goal 2ms
✓ test/prompts.test.ts > planning prompt > restores the same rule after compaction 1ms
✓ test/prompts.test.ts > planning prompt > anchors work and sign-off to the user-visible result 0ms
✓ test/worker-view.test.ts > keeps human direction and source location while sending only new messages 3ms
✓ test/worker-view.test.ts > restarts after compaction and does not report historical tool calls as active 1ms
✓ test/worker-view.test.ts > bounds serialized Unicode and quoted logs while marking omissions 3ms
stdout | test/role-models.test.ts > remembers each role without automatic switching overwriting another role
Role preferences restored: planning=planner, worker=small-worker, supervisor=astra; restore events did not overwrite the choice.
✓ test/role-models.test.ts > remembers each role without automatic switching overwriting another role 9ms
✓ test/role-models.test.ts > fails on an unavailable remembered model without replacing the choice 4ms
✓ test/intercom.test.ts > pi-intercom transport > receives exact advice once, acknowledges it and rejects unrelated peers 15ms
✓ test/intercom.test.ts > pi-intercom transport > restores an unacknowledged steer on reconnect and stops replay after acknowledgment 5ms
✓ test/intercom.test.ts > pi-intercom transport > advances the incremental overview only after acknowledgment 1ms
✓ test/intercom.test.ts > pi-intercom transport > cancels a readiness wait on shutdown 2ms
✓ test/intercom.test.ts > does not acknowledge a synchronous handoff failure, and retries the instruction 1ms
✓ test/intercom.test.ts > detaches a completed binding and ignores its late advice without replay errors or false acceptance 1ms
✓ test/background.test.ts > reports tracked running work, rather than equating idle agent with finished jobs 110ms
✓ test/background.test.ts > distinguishes missing providers from an unavailable installed tracker 4ms
✓ test/intercom-handshake.test.ts > re-handshakes unchanged peers in either direction without hello ping-pong or lost advice 11ms
✓ test/intercom-handshake.test.ts > replays pending advice and views across either role's own readiness transition 1ms
✓ test/intercom-handshake.test.ts > cancels pending waits immediately on detach or reconfiguration 2ms
✓ test/herdr.test.ts > supervisor pane command > forks the planning session with pi-goals owning its Intercom dependency 8ms
✓ test/herdr.test.ts > supervisor pane command > accepts Herdr's text version output and stale pane cleanup 55ms
✓ test/approval.test.ts > fingerprints literal unusual paths, binary bytes, symlink targets, modes and deletions 177ms
✓ test/approval.test.ts > hashes only the current goal, excluding the log, interview, and their historical goal text 1ms
✓ test/fold.test.ts > foldPlan (current goals are above ## Log; durable memory is below it) > keeps the title, user voice and goals 1ms
✓ test/fold.test.ts > foldPlan (current goals are above ## Log; durable memory is below it) > drops the log, the learnings and the unlimited appendix 0ms
✓ test/fold.test.ts > foldPlan (current goals are above ## Log; durable memory is below it) > returns the whole plan when there is no ## Log yet (a fresh draft) 0ms
✓ test/fold.test.ts > openSubtasks (the widget shows the next action, so the plan IS the task list) > lists the active goal's open and in-progress subtasks, stopping at the next goal 1ms
✓ test/fold.test.ts > openSubtasks (the widget shows the next action, so the plan IS the task list) > does not leak subtasks from the goal below 1ms
✓ test/fold.test.ts > does not show historical Log subtasks under the last active goal 0ms
✓ test/append-log.test.ts > appendLog (the extension's only plan-file write) > creates ## Log at EOF when absent 2ms
✓ test/append-log.test.ts > appendLog (the extension's only plan-file write) > appends after the last existing log line, before any following header 1ms
✓ test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > ticks the exact-matching goal line, case-insensitive, leaving subtasks alone 2ms
✓ test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > returns null on wording drift (fuzzy matching is the judge's job, not TypeScript's) 0ms
✓ test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > returns null when the subject matches more than one goal line 0ms
✓ test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > ignores a historical duplicate below the Log and leaves it unchanged 0ms
✓ test/goals-flow.test.ts > /goals flow > reports actual idle state, invalidates stopped views on start, and stops completed plans 51ms
✓ test/goals-flow.test.ts > /goals flow > preserves drafts, records the interview, and keeps planning read-only 25ms
stdout | test/intercom-broker.test.ts > exchanges readiness, views and exact advice over a real isolated pi-intercom broker
Intercom broker: readiness confirmed; exact worker view and supervisor advice received.
stdout | test/force-approval-flow.test.ts > force ApproveGoal -> CompleteGoal accepts only the reviewed dirty state without committing or modifying it
Force UAT: paired real handlers accepted unchanged tracked + untracked dirty content; Git HEAD and user files stayed unchanged.
✓ test/force-approval-flow.test.ts > force ApproveGoal -> CompleteGoal accepts only the reviewed dirty state without committing or modifying it 124ms
✓ test/intercom-broker.test.ts > exchanges readiness, views and exact advice over a real isolated pi-intercom broker 425ms
✓ test/goals-flow.test.ts > /goals flow > forks a visible supervisor on Ready and keeps the main session as worker 27ms
✓ test/goals-flow.test.ts > /goals flow > starts work only after the supervisor launcher resolves 28ms
✓ test/goals-flow.test.ts > /goals flow > delivers an Intercom instruction to the worker 20ms
✓ test/goals-flow.test.ts > /goals flow > closes the supervisor on clear but keeps the plan file 22ms
✓ test/force-approval-flow.test.ts > keeps ordinary clean approval unchanged and rechecks runtime state at forced completion 104ms
✓ test/goals-flow.test.ts > /goals flow > accepts only an approval for the exact clean commit and goal block 74ms
✓ test/goals-flow.test.ts > process role > keeps subagent children and visible supervisors out of the worker extension 0ms
✓ test/goals-flow.test.ts > restores working linkage even when its remembered model is unavailable, and supports explicit recovery 27ms
✓ test/goals-flow.test.ts > restores planning linkage even when its remembered model is unavailable, and supports explicit recovery 26ms
✓ test/goals-flow.test.ts > shows a missing resumed supervisor, pauses writes, and automatically unpauses when that peer returns 25ms
✓ test/force-approval-flow.test.ts > invalidates forced approval after changed tracked content 78ms
✓ test/goals-flow.test.ts > times out stale Ready retries in five seconds, without replacing the pane automatically 32ms
✓ test/goals-flow.test.ts > explicitly restarts only the tracked pane, keeps the plan, and invalidates old approval binding 31ms
✓ test/goals-flow.test.ts > does not persist startup results or launch work after session shutdown 27ms
✓ test/goals-flow.test.ts > keeps a failed Ready model not-ready and recovers the same real supervisor binding 32ms
✓ test/force-approval-flow.test.ts > invalidates forced approval after changed untracked content 76ms
✓ test/force-approval-flow.test.ts > invalidates forced approval after changed new untracked 70ms
✓ test/goals-flow.test.ts > points a present-but-paused peer recovery at the supervisor pane 21ms
✓ test/goals-flow.test.ts > clear during the initial Ready wait cancels immediately and cannot resurrect the plan 27ms
✓ test/goals-flow.test.ts > clear before the launcher resolves rejects late pane callbacks without restoring the binding 19ms
✓ test/force-approval-flow.test.ts > invalidates forced approval after changed deleted untracked 61ms
✓ test/force-approval-flow.test.ts > invalidates forced approval after changed index only 63ms
✓ test/force-approval-flow.test.ts > invalidates forced approval after changed index contents 122ms
✓ test/force-approval-flow.test.ts > invalidates forced approval after changed rename 73ms
✓ test/force-approval-flow.test.ts > invalidates forced approval after changed HEAD 67ms
✓ test/supervisor-session.test.ts > visible supervisor session > restores monitoring and read-only tools without replaying persisted views 9ms
✓ test/supervisor-session.test.ts > visible supervisor session > renders all advice in real Pi tool rows, including collapsed and restored rows 26ms
✓ test/supervisor-session.test.ts > visible supervisor session > asks for judgment and useful recaps without inventing instructions 1ms
✓ test/supervisor-session.test.ts > visible supervisor session > writes readiness only after removing writing tools 2ms
✓ test/supervisor-session.test.ts > visible supervisor session > compacts a large planning fork before writing readiness 1ms
✓ test/supervisor-session.test.ts > visible supervisor session > does not become ready when initial compaction fails 2ms
✓ test/supervisor-session.test.ts > visible supervisor session > writes a durable worker instruction 1ms
✓ test/supervisor-session.test.ts > visible supervisor session > records approval only from a stopped view with evidence and no active work 77ms
✓ test/supervisor-session.test.ts > blocks the general intercom actuator even if enabled after startup 2ms
✓ test/supervisor-session.test.ts > keeps a supervisor unready after model restoration failure, then recovers explicitly without substituting a model 2ms
✓ test/supervisor-session.test.ts > warns once on unavailable usage but stays quiet for Pi's post-compaction null token sample 3ms
✓ test/force-approval-flow.test.ts > invalidates forced approval after changed goal 86ms
✓ test/force-approval-flow.test.ts > force does not bypass the evidence gate 51ms
✓ test/force-approval-flow.test.ts > force does not bypass the verification gate 42ms
✓ test/force-approval-flow.test.ts > force does not bypass the stopped view gate 24ms
✓ test/force-approval-flow.test.ts > force does not bypass the tool call gate 25ms
✓ test/force-approval-flow.test.ts > force does not bypass the unknown tracker gate 25ms
✓ test/force-approval-flow.test.ts > force does not bypass the active tracker gate 27ms
✓ test/rpc-review.test.ts > RPC review flow > opens Refine's editor before it starts the revision turn 1856ms
stdout | test/native-intercom.test.ts > runs a forked Pi supervisor and receives its exact instruction in another Pi session
Native Pi pair: fork retained planning context; SteerWorker delivered exactly: Read the real outputs before declaring completion.
✓ test/native-intercom.test.ts > runs a forked Pi supervisor and receives its exact instruction in another Pi session 2941ms
Test Files 18 passed (18)
Tests 85 passed (85)
Start at 06:18:03
Duration 3.48s (transform 3.77s, setup 0ms, import 7.89s, tests 7.45s, environment 2ms)
> @wassname2/pi-goals@0.2.2 typecheck
> tsc --noEmit
> @wassname2/pi-goals@0.2.2 lint
> biome check src/ test/
Checked 33 files in 68ms. No fixes applied.
> @wassname2/pi-goals@0.2.2 build
> tsc
After validation: pre-existing dirty evidence checksums
a8f1facd16fd6ff2938195a7adbdc3b4b1e1dea61533e90a39e5eb18d201e190 slop/reviews/review-fixes-native/supervisor-events.jsonl
de5bb7171e71508c40e19f3929303a63f1fa0f2ea7789a2bcc8728ea038310d2 slop/reviews/review-fixes-native/worker-events.jsonl
@@ -1,122 +0,0 @@
> @wassname2/pi-goals@0.2.2 test
> vitest run --reporter=verbose
RUN v4.1.9 /home/code/.pi/agent/git/github.com/wassname/pi-goals
✓ test/package-agent.test.ts > package manifest > includes the extension without registering a packaged subagent 3ms
stdout | test/role-models.test.ts > remembers each role without automatic switching overwriting another role
Role preferences restored: planning=planner, worker=small-worker, supervisor=astra; restore events did not overwrite the choice.
✓ test/intercom.test.ts > pi-intercom transport > receives exact advice once, acknowledges it and rejects unrelated peers 4ms
✓ test/intercom.test.ts > pi-intercom transport > restores an unacknowledged steer on reconnect and stops replay after acknowledgment 2ms
✓ test/intercom.test.ts > pi-intercom transport > advances the incremental overview only after acknowledgment 1ms
✓ test/intercom.test.ts > pi-intercom transport > cancels a readiness wait on shutdown 1ms
✓ test/intercom.test.ts > does not acknowledge a synchronous handoff failure, and retries the instruction 1ms
✓ test/intercom.test.ts > detaches a completed binding and ignores its late advice without replay errors or false acceptance 1ms
✓ test/role-models.test.ts > remembers each role without automatic switching overwriting another role 32ms
✓ test/role-models.test.ts > fails on an unavailable remembered model without replacing the choice 5ms
✓ test/intercom-handshake.test.ts > re-handshakes unchanged peers in either direction without hello ping-pong or lost advice 9ms
✓ test/intercom-handshake.test.ts > replays pending advice and views across either role's own readiness transition 2ms
✓ test/intercom-handshake.test.ts > cancels pending waits immediately on detach or reconfiguration 2ms
✓ test/worker-view.test.ts > keeps human direction and source location while sending only new messages 3ms
✓ test/worker-view.test.ts > restarts after compaction and does not report historical tool calls as active 1ms
✓ test/worker-view.test.ts > bounds serialized Unicode and quoted logs while marking omissions 3ms
✓ test/approval.test.ts > hashes only the current goal, excluding the log, interview, and their historical goal text 8ms
✓ test/prompts.test.ts > planning prompt > requires fact finding or a focused question before a goal 2ms
✓ test/prompts.test.ts > planning prompt > restores the same rule after compaction 2ms
✓ test/prompts.test.ts > planning prompt > anchors work and sign-off to the user-visible result 0ms
✓ test/herdr.test.ts > supervisor pane command > forks the planning session with pi-goals owning its Intercom dependency 3ms
✓ test/herdr.test.ts > supervisor pane command > accepts Herdr's text version output and stale pane cleanup 51ms
✓ test/background.test.ts > reports tracked running work, rather than equating idle agent with finished jobs 52ms
✓ test/background.test.ts > distinguishes missing providers from an unavailable installed tracker 5ms
✓ test/fold.test.ts > foldPlan (current goals are above ## Log; durable memory is below it) > keeps the title, user voice and goals 2ms
✓ test/fold.test.ts > foldPlan (current goals are above ## Log; durable memory is below it) > drops the log, the learnings and the unlimited appendix 1ms
✓ test/fold.test.ts > foldPlan (current goals are above ## Log; durable memory is below it) > returns the whole plan when there is no ## Log yet (a fresh draft) 0ms
✓ test/fold.test.ts > openSubtasks (the widget shows the next action, so the plan IS the task list) > lists the active goal's open and in-progress subtasks, stopping at the next goal 1ms
✓ test/fold.test.ts > openSubtasks (the widget shows the next action, so the plan IS the task list) > does not leak subtasks from the goal below 1ms
✓ test/fold.test.ts > does not show historical Log subtasks under the last active goal 0ms
✓ test/append-log.test.ts > appendLog (the extension's only plan-file write) > creates ## Log at EOF when absent 2ms
✓ test/append-log.test.ts > appendLog (the extension's only plan-file write) > appends after the last existing log line, before any following header 0ms
stdout | test/intercom-broker.test.ts > exchanges readiness, views and exact advice over a real isolated pi-intercom broker
Intercom broker: readiness confirmed; exact worker view and supervisor advice received.
✓ test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > ticks the exact-matching goal line, case-insensitive, leaving subtasks alone 2ms
✓ test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > returns null on wording drift (fuzzy matching is the judge's job, not TypeScript's) 0ms
× test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > returns null when the subject matches more than one goal line 5ms
→ expected '# Plan\n\n## Goals\n\n1. [/] goal: Im…' to be null
✓ test/intercom-broker.test.ts > exchanges readiness, views and exact advice over a real isolated pi-intercom broker 254ms
✓ test/goals-flow.test.ts > /goals flow > reports actual idle state, invalidates stopped views on start, and stops completed plans 59ms
✓ test/goals-flow.test.ts > /goals flow > preserves drafts, records the interview, and keeps planning read-only 33ms
✓ test/goals-flow.test.ts > /goals flow > forks a visible supervisor on Ready and keeps the main session as worker 27ms
✓ test/goals-flow.test.ts > /goals flow > starts work only after the supervisor launcher resolves 38ms
✓ test/goals-flow.test.ts > /goals flow > delivers an Intercom instruction to the worker 41ms
✓ test/goals-flow.test.ts > /goals flow > closes the supervisor on clear but keeps the plan file 27ms
✓ test/goals-flow.test.ts > /goals flow > accepts only an approval for the exact clean commit and goal block 61ms
✓ test/goals-flow.test.ts > process role > keeps subagent children and visible supervisors out of the worker extension 0ms
✓ test/goals-flow.test.ts > restores working linkage even when its remembered model is unavailable, and supports explicit recovery 21ms
✓ test/goals-flow.test.ts > restores planning linkage even when its remembered model is unavailable, and supports explicit recovery 23ms
✓ test/goals-flow.test.ts > shows a missing resumed supervisor, pauses writes, and automatically unpauses when that peer returns 26ms
✓ test/goals-flow.test.ts > times out stale Ready retries in five seconds, without replacing the pane automatically 29ms
✓ test/goals-flow.test.ts > explicitly restarts only the tracked pane, keeps the plan, and invalidates old approval binding 24ms
✓ test/goals-flow.test.ts > does not persist startup results or launch work after session shutdown 23ms
✓ test/goals-flow.test.ts > keeps a failed Ready model not-ready and recovers the same real supervisor binding 31ms
✓ test/goals-flow.test.ts > points a present-but-paused peer recovery at the supervisor pane 21ms
✓ test/goals-flow.test.ts > clear during the initial Ready wait cancels immediately and cannot resurrect the plan 25ms
✓ test/goals-flow.test.ts > clear before the launcher resolves rejects late pane callbacks without restoring the binding 21ms
✓ test/supervisor-session.test.ts > visible supervisor session > restores monitoring and read-only tools without replaying persisted views 8ms
✓ test/supervisor-session.test.ts > visible supervisor session > renders all advice in real Pi tool rows, including collapsed and restored rows 21ms
✓ test/supervisor-session.test.ts > visible supervisor session > asks for judgment and useful recaps without inventing instructions 1ms
✓ test/supervisor-session.test.ts > visible supervisor session > writes readiness only after removing writing tools 2ms
✓ test/supervisor-session.test.ts > visible supervisor session > compacts a large planning fork before writing readiness 1ms
✓ test/supervisor-session.test.ts > visible supervisor session > does not become ready when initial compaction fails 2ms
✓ test/supervisor-session.test.ts > visible supervisor session > writes a durable worker instruction 1ms
✓ test/supervisor-session.test.ts > visible supervisor session > records approval only from a stopped view with evidence and no active work 96ms
✓ test/supervisor-session.test.ts > blocks the general intercom actuator even if enabled after startup 3ms
✓ test/supervisor-session.test.ts > keeps a supervisor unready after model restoration failure, then recovers explicitly without substituting a model 2ms
✓ test/supervisor-session.test.ts > warns once on unavailable usage but stays quiet for Pi's post-compaction null token sample 3ms
✓ test/rpc-review.test.ts > RPC review flow > opens Refine's editor before it starts the revision turn 1541ms
stdout | test/native-intercom.test.ts > runs a forked Pi supervisor and receives its exact instruction in another Pi session
Native Pi pair: fork retained planning context; SteerWorker delivered exactly: Read the real outputs before declaring completion.
✓ test/native-intercom.test.ts > runs a forked Pi supervisor and receives its exact instruction in another Pi session 2503ms
⎯⎯⎯⎯⎯⎯⎯ Failed Tests 1 ⎯⎯⎯⎯⎯⎯⎯
FAIL test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > returns null when the subject matches more than one goal line
AssertionError: expected '# Plan\n\n## Goals\n\n1. [/] goal: Im…' to be null
- Expected:
null
+ Received:
"# Plan
## Goals
1. [/] goal: Implement the cache layer
- tasks:
1. [x] wire client
2. [x] goal: Ship the docs
## Log
3. [ ] goal: Ship the docs
"
test/tick-goal.test.ts:30:42
28| it("returns null when the subject matches more than one goal line", (…
29| const dup = `${plan}3. [ ] goal: Ship the docs\n`;
30| expect(tickGoal(dup, "Ship the docs")).toBeNull();
| ^
31| });
32| });
⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯[1/1]⎯
Test Files 1 failed | 16 passed (17)
Tests 1 failed | 65 passed (66)
Start at 19:22:13
Duration 2.84s (transform 2.51s, setup 0ms, import 5.72s, tests 5.21s, environment 2ms)
-42
View File
@@ -1,42 +0,0 @@
# Post-review P1P5 fixes — Pi/OpenAI implementation worker
Baseline: `1668c94`. Independent review: [attributed, preserved source](20260908-independent-post-fix-review.md), reviewer run `bdb93a2e-52f4-4a6d-bac2-7c9eb48118b5`.
Read AGENTS.md and installed Pi extension docs for lifecycle teardown, commands, model selection and compaction before editing. No user pane/session was operated; tests use isolated mocks/brokers/native Pi processes. No nested delegation or push.
## Dispositions
- **P1:** Replaced change-gated hello replies with an explicit request/reply bit. Every request receives one reply even when the peer state is unchanged; a reply never elicits another hello. Each successful exchange retries only still-pending instructions/current view, including after either side's own readiness transition. Repeated wire frames are allowed and deduplicated at the receiving adapter; this is not a new durable-delivery claim. `test/intercom-handshake.test.ts` wires **two real GoalIntercom adapters**, not an auto-ready peer. It checks repeated worker and supervisor reconfiguration, concurrent reset (four hello frames), single-sided reset (two frames), exact advice handoff, own-ready pause/resume, pending advice/view replay, and reconnect deduplication. Both peers must load the updated transport; mixed-version reconnect is not claimed supported.
- **P2:** The worker configures not-ready during startup/recovery. Startup can await peer readiness without claiming implementation readiness. It announces ready only after worker model restoration and the phase transition to working. Model failures remain not-ready. The Ready/retry flow test uses the same two real adapters and proves unavailable worker model → not-ready → `/model` + reconnect → Ready → working on the **same** binding/pane, followed by successful advice after healthy reconnect. Planning reconnect alone does not authorize implementation.
- **P3:** A known peer with incomplete readiness is distinguished from an absent peer. Guidance points to the supervisor pane's compaction/model diagnostics and `/model` + `/goals reconnect`, rather than treating every pause as disconnection. Regression checks widget and prompt guidance.
- **P4:** `src/plan.ts` now owns the single goal-line and Log-fold definitions. Widget scanning, subtasks, goal ticking and approval use the same current-plan boundary. Tick still rejects duplicate active-region matches; historical Log copies remain byte-for-byte unchanged. The existing approval/sign-off flow now includes duplicate/historical goal lines in the Log, succeeds and ends the active plan instead of reopening historical goals.
- **P5:** Detach/reconfigure immediately reject old readiness waiters. A small Ready-attempt identity plus plan-version guard invalidates asynchronous startup results on clear/recovery/replacement; stale menu/editor responses are also ignored. Regressions clear while the five-minute initial wait is pending (no clock advance needed to settle), then advance five minutes and verify no resurrection; a second test clears before the launcher callback resolves and verifies no late binding/pane persistence or work launch. No automatic late-pane kill was added.
- **F8 observability:** One warning per runtime if the entire usage result is unavailable at a settled check. No warning for Pi's ordinary post-compaction `tokens: null` sample. No speculative token estimator, new compaction policy, or change to Pi auto-compaction. Persistent null usage still cannot trigger the custom 100k check.
## Verification and changed old assertions
[Full successful commands/output](20260908-handshake-validation.txt): **67 tests passed in 17 files**, followed by successful typecheck, lint, build and `git diff --check`. The exact main-session test command unsets `PI_SUBAGENT_CHILD` and `PI_GOALS_ROLE` and sets a **fresh explicit** `PI_GOALS_EVIDENCE_DIR` to `slop/reviews/handshake-native`.
Two intermediate failures are preserved, not counted as passes:
1. [Handshake-focused run](20260908-handshake-initial-validation.txt): 26 passed/1 failed. The old assertion demanded exactly one outbound wire retry after configure+markReady. These now generate separate request/reply exchanges, which can retry the same still-unacked id more than once before its ack. Updated assertion requires at least one retry, every retry's exact id/text, and no further retries after ack. Two-real-adapter tests independently require exactly one user handoff/view callback after duplicate wire delivery.
2. [First full boundary run](20260908-handshake-boundary-initial-validation.txt): 65 passed/1 failed. Its old duplicate-goal fixture appended the duplicate **below `## Log`**, precisely the P4 behavior being corrected. The duplicate-rejection test now inserts the duplicate above the fold and still requires null; an added test requires historical copies below the fold to be ignored and unchanged.
An intermediate typecheck passed; lint initially flagged import order and a nested assignment. Those were corrected; the full final lint passed with no fixes applied.
[Native log inspection](20260908-handshake-log-inspection.txt) reads the final worker/supervisor event files, verifies zero error records and empty stderr, and matches the outgoing instruction, worker incoming instruction and adapter ack id `22068654-6e7c-4328-890f-9382b25c8ea7`. The worker user message is exactly `[supervisor] Read the real outputs before declaring completion.` This deterministic native test proves context retention/routing/tool exposure, not autonomous judgment or durable enqueue guarantees.
## Evidence provenance caveat
At the first inspection, these two tracked files were **already dirty**:
- `slop/reviews/review-fixes-native/supervisor-events.jsonl`
- `slop/reviews/review-fixes-native/worker-events.jsonl`
The inherited `PI_GOALS_EVIDENCE_DIR` pointed there. The first full test run accidentally refreshed them again. Their pre-task uncommitted bytes were not captured, so it is not established that all differences from HEAD were produced by this worker. They are left **unstaged and uncommitted**, not restored over unknown prior edits. The refreshed copies were separately preserved under this worker's output directory, `scratch-refreshed-prior-evidence/`. Final evidence uses only the fresh `handshake-native/` directory and is not mixed with these prior paths.
## Still open / acceptance limits
**F3 async enqueue confirmation remains open.** Pi's void `sendUserMessage` wrapper can return before a later async enqueue rejection. An adapter ack is not durable enqueue, model receipt, or execution confirmation. No correlated-receipt protocol was added; the future forced-async-rejection UAT remains required. A synchronous handoff failure still remains unacked for retry.
Parent/reviewer owns independent post-change review and push. Rendered Herdr acceptance, the complete two-native-session ApproveGoal → CompleteGoal chain, fresh-shell role recovery without launcher environment, useful independent judgment and cost savings remain unproven. Planning/pause shell gates remain trusted-repo guardrails, not a security sandbox. If a pane split finishes after cancellation, it can remain untracked for human inspection; this change prevents stale state resurrection rather than operating a late pane automatically.
@@ -1,77 +0,0 @@
> @wassname2/pi-goals@0.2.2 test
> vitest run --run test/intercom-handshake.test.ts test/intercom.test.ts test/goals-flow.test.ts --reporter=verbose
RUN v4.1.9 /home/code/.pi/agent/git/github.com/wassname/pi-goals
✓ test/intercom-handshake.test.ts > re-handshakes unchanged peers in either direction without hello ping-pong or lost advice 7ms
✓ test/intercom-handshake.test.ts > replays pending advice and views across either role's own readiness transition 1ms
✓ test/intercom-handshake.test.ts > cancels pending waits immediately on detach or reconfiguration 1ms
✓ test/intercom.test.ts > pi-intercom transport > receives exact advice once, acknowledges it and rejects unrelated peers 4ms
× test/intercom.test.ts > pi-intercom transport > restores an unacknowledged steer on reconnect and stops replay after acknowledgment 7ms
→ expected [ { binding: 'binding', …(4) }, …(1) ] to match object [ { …(2) } ]
✓ test/intercom.test.ts > pi-intercom transport > advances the incremental overview only after acknowledgment 1ms
✓ test/intercom.test.ts > pi-intercom transport > cancels a readiness wait on shutdown 1ms
✓ test/intercom.test.ts > does not acknowledge a synchronous handoff failure, and retries the instruction 1ms
✓ test/intercom.test.ts > detaches a completed binding and ignores its late advice without replay errors or false acceptance 3ms
✓ test/goals-flow.test.ts > /goals flow > reports actual idle state, invalidates stopped views on start, and stops completed plans 34ms
✓ test/goals-flow.test.ts > /goals flow > preserves drafts, records the interview, and keeps planning read-only 18ms
✓ test/goals-flow.test.ts > /goals flow > forks a visible supervisor on Ready and keeps the main session as worker 24ms
✓ test/goals-flow.test.ts > /goals flow > starts work only after the supervisor launcher resolves 22ms
✓ test/goals-flow.test.ts > /goals flow > delivers an Intercom instruction to the worker 18ms
✓ test/goals-flow.test.ts > /goals flow > closes the supervisor on clear but keeps the plan file 23ms
✓ test/goals-flow.test.ts > /goals flow > accepts only an approval for the exact clean commit and goal block 47ms
✓ test/goals-flow.test.ts > process role > keeps subagent children and visible supervisors out of the worker extension 0ms
✓ test/goals-flow.test.ts > restores working linkage even when its remembered model is unavailable, and supports explicit recovery 18ms
✓ test/goals-flow.test.ts > restores planning linkage even when its remembered model is unavailable, and supports explicit recovery 16ms
✓ test/goals-flow.test.ts > shows a missing resumed supervisor, pauses writes, and automatically unpauses when that peer returns 17ms
✓ test/goals-flow.test.ts > times out stale Ready retries in five seconds, without replacing the pane automatically 26ms
✓ test/goals-flow.test.ts > explicitly restarts only the tracked pane, keeps the plan, and invalidates old approval binding 23ms
✓ test/goals-flow.test.ts > does not persist startup results or launch work after session shutdown 23ms
✓ test/goals-flow.test.ts > keeps a failed Ready model not-ready and recovers the same real supervisor binding 23ms
✓ test/goals-flow.test.ts > points a present-but-paused peer recovery at the supervisor pane 18ms
✓ test/goals-flow.test.ts > clear during the initial Ready wait cancels immediately and cannot resurrect the plan 21ms
✓ test/goals-flow.test.ts > clear before the launcher resolves rejects late pane callbacks without restoring the binding 35ms
⎯⎯⎯⎯⎯⎯⎯ Failed Tests 1 ⎯⎯⎯⎯⎯⎯⎯
FAIL test/intercom.test.ts > pi-intercom transport > restores an unacknowledged steer on reconnect and stops replay after acknowledgment
AssertionError: expected [ { binding: 'binding', …(4) }, …(1) ] to match object [ { …(2) } ]
- Expected
+ Received
[
{
+ "binding": "binding",
+ "id": "7f4566ea-f2ef-4a14-ad75-e138fc3a26a0",
+ "kind": "steer",
+ "role": "supervisor",
+ "text": "Read the full output.",
+ },
+ {
+ "binding": "binding",
"id": "7f4566ea-f2ef-4a14-ad75-e138fc3a26a0",
+ "kind": "steer",
+ "role": "supervisor",
"text": "Read the full output.",
},
]
test/intercom.test.ts:45:76
43| resumed.link.markReady();
44| await resumed.link.waitReady();
45| expect(resumed.fixture.sent.filter(message => message.kind === "stee…
| ^
46| resumed.fixture.receive({ binding: "binding", role: "worker", kind: …
47| resumed.fixture.connect(false);
⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯[1/1]⎯
Test Files 1 failed | 2 passed (3)
Tests 1 failed | 26 passed (27)
Start at 19:20:05
Duration 861ms (transform 365ms, setup 0ms, import 583ms, tests 437ms, environment 0ms)
@@ -1,8 +0,0 @@
slop/reviews/handshake-native/worker-events.jsonl: 22 events; 0 error records; stderr 0 bytes
worker: ack received cf656aef-1404-4d5c-9a11-4fbd4ed5b5dc
worker: ack received cf656aef-1404-4d5c-9a11-4fbd4ed5b5dc
worker: in steer 22068654-6e7c-4328-890f-9382b25c8ea7
worker: [{"type":"text","text":"[supervisor] Read the real outputs before declaring completion."}]
slop/reviews/handshake-native/supervisor-events.jsonl: 21 events; 0 error records; stderr 0 bytes
supervisor: out steer 22068654-6e7c-4328-890f-9382b25c8ea7
supervisor: ack received 22068654-6e7c-4328-890f-9382b25c8ea7
@@ -1,107 +0,0 @@
+ env -u PI_SUBAGENT_CHILD -u PI_GOALS_ROLE PI_GOALS_EVIDENCE_DIR=/home/code/.pi/agent/git/github.com/wassname/pi-goals/slop/reviews/handshake-native npm test -- --reporter=verbose
> @wassname2/pi-goals@0.2.2 test
> vitest run --reporter=verbose
RUN v4.1.9 /home/code/.pi/agent/git/github.com/wassname/pi-goals
✓ test/background.test.ts > reports tracked running work, rather than equating idle agent with finished jobs 5ms
✓ test/background.test.ts > distinguishes missing providers from an unavailable installed tracker 47ms
✓ test/package-agent.test.ts > package manifest > includes the extension without registering a packaged subagent 3ms
✓ test/herdr.test.ts > supervisor pane command > forks the planning session with pi-goals owning its Intercom dependency 3ms
✓ test/herdr.test.ts > supervisor pane command > accepts Herdr's text version output and stale pane cleanup 26ms
✓ test/prompts.test.ts > planning prompt > requires fact finding or a focused question before a goal 2ms
✓ test/prompts.test.ts > planning prompt > restores the same rule after compaction 0ms
✓ test/prompts.test.ts > planning prompt > anchors work and sign-off to the user-visible result 0ms
✓ test/worker-view.test.ts > keeps human direction and source location while sending only new messages 3ms
✓ test/worker-view.test.ts > restarts after compaction and does not report historical tool calls as active 1ms
✓ test/worker-view.test.ts > bounds serialized Unicode and quoted logs while marking omissions 2ms
stdout | test/role-models.test.ts > remembers each role without automatic switching overwriting another role
Role preferences restored: planning=planner, worker=small-worker, supervisor=astra; restore events did not overwrite the choice.
✓ test/role-models.test.ts > remembers each role without automatic switching overwriting another role 14ms
✓ test/role-models.test.ts > fails on an unavailable remembered model without replacing the choice 5ms
✓ test/approval.test.ts > hashes only the current goal, excluding the log, interview, and their historical goal text 5ms
✓ test/intercom-handshake.test.ts > re-handshakes unchanged peers in either direction without hello ping-pong or lost advice 9ms
✓ test/intercom-handshake.test.ts > replays pending advice and views across either role's own readiness transition 1ms
✓ test/intercom-handshake.test.ts > cancels pending waits immediately on detach or reconfiguration 2ms
✓ test/intercom.test.ts > pi-intercom transport > receives exact advice once, acknowledges it and rejects unrelated peers 7ms
✓ test/intercom.test.ts > pi-intercom transport > restores an unacknowledged steer on reconnect and stops replay after acknowledgment 4ms
✓ test/intercom.test.ts > pi-intercom transport > advances the incremental overview only after acknowledgment 1ms
✓ test/intercom.test.ts > pi-intercom transport > cancels a readiness wait on shutdown 1ms
✓ test/intercom.test.ts > does not acknowledge a synchronous handoff failure, and retries the instruction 2ms
✓ test/intercom.test.ts > detaches a completed binding and ignores its late advice without replay errors or false acceptance 1ms
✓ test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > ticks the exact-matching goal line, case-insensitive, leaving subtasks alone 2ms
✓ test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > returns null on wording drift (fuzzy matching is the judge's job, not TypeScript's) 0ms
✓ test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > returns null when the subject matches more than one goal line 0ms
✓ test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > ignores a historical duplicate below the Log and leaves it unchanged 0ms
✓ test/append-log.test.ts > appendLog (the extension's only plan-file write) > creates ## Log at EOF when absent 4ms
✓ test/append-log.test.ts > appendLog (the extension's only plan-file write) > appends after the last existing log line, before any following header 1ms
✓ test/fold.test.ts > foldPlan (current goals are above ## Log; durable memory is below it) > keeps the title, user voice and goals 2ms
✓ test/fold.test.ts > foldPlan (current goals are above ## Log; durable memory is below it) > drops the log, the learnings and the unlimited appendix 1ms
✓ test/fold.test.ts > foldPlan (current goals are above ## Log; durable memory is below it) > returns the whole plan when there is no ## Log yet (a fresh draft) 0ms
✓ test/fold.test.ts > openSubtasks (the widget shows the next action, so the plan IS the task list) > lists the active goal's open and in-progress subtasks, stopping at the next goal 1ms
✓ test/fold.test.ts > openSubtasks (the widget shows the next action, so the plan IS the task list) > does not leak subtasks from the goal below 1ms
✓ test/fold.test.ts > does not show historical Log subtasks under the last active goal 0ms
stdout | test/intercom-broker.test.ts > exchanges readiness, views and exact advice over a real isolated pi-intercom broker
Intercom broker: readiness confirmed; exact worker view and supervisor advice received.
✓ test/goals-flow.test.ts > /goals flow > reports actual idle state, invalidates stopped views on start, and stops completed plans 47ms
✓ test/goals-flow.test.ts > /goals flow > preserves drafts, records the interview, and keeps planning read-only 24ms
✓ test/intercom-broker.test.ts > exchanges readiness, views and exact advice over a real isolated pi-intercom broker 236ms
✓ test/goals-flow.test.ts > /goals flow > forks a visible supervisor on Ready and keeps the main session as worker 32ms
✓ test/goals-flow.test.ts > /goals flow > starts work only after the supervisor launcher resolves 29ms
✓ test/goals-flow.test.ts > /goals flow > delivers an Intercom instruction to the worker 26ms
✓ test/goals-flow.test.ts > /goals flow > closes the supervisor on clear but keeps the plan file 20ms
✓ test/goals-flow.test.ts > /goals flow > accepts only an approval for the exact clean commit and goal block 62ms
✓ test/goals-flow.test.ts > process role > keeps subagent children and visible supervisors out of the worker extension 0ms
✓ test/goals-flow.test.ts > restores working linkage even when its remembered model is unavailable, and supports explicit recovery 33ms
✓ test/goals-flow.test.ts > restores planning linkage even when its remembered model is unavailable, and supports explicit recovery 24ms
✓ test/goals-flow.test.ts > shows a missing resumed supervisor, pauses writes, and automatically unpauses when that peer returns 24ms
✓ test/goals-flow.test.ts > times out stale Ready retries in five seconds, without replacing the pane automatically 25ms
✓ test/goals-flow.test.ts > explicitly restarts only the tracked pane, keeps the plan, and invalidates old approval binding 42ms
✓ test/goals-flow.test.ts > does not persist startup results or launch work after session shutdown 36ms
✓ test/goals-flow.test.ts > keeps a failed Ready model not-ready and recovers the same real supervisor binding 31ms
✓ test/goals-flow.test.ts > points a present-but-paused peer recovery at the supervisor pane 17ms
✓ test/goals-flow.test.ts > clear during the initial Ready wait cancels immediately and cannot resurrect the plan 25ms
✓ test/goals-flow.test.ts > clear before the launcher resolves rejects late pane callbacks without restoring the binding 19ms
✓ test/supervisor-session.test.ts > visible supervisor session > restores monitoring and read-only tools without replaying persisted views 7ms
✓ test/supervisor-session.test.ts > visible supervisor session > renders all advice in real Pi tool rows, including collapsed and restored rows 22ms
✓ test/supervisor-session.test.ts > visible supervisor session > asks for judgment and useful recaps without inventing instructions 1ms
✓ test/supervisor-session.test.ts > visible supervisor session > writes readiness only after removing writing tools 2ms
✓ test/supervisor-session.test.ts > visible supervisor session > compacts a large planning fork before writing readiness 1ms
✓ test/supervisor-session.test.ts > visible supervisor session > does not become ready when initial compaction fails 2ms
✓ test/supervisor-session.test.ts > visible supervisor session > writes a durable worker instruction 1ms
✓ test/rpc-review.test.ts > RPC review flow > opens Refine's editor before it starts the revision turn 1350ms
✓ test/supervisor-session.test.ts > visible supervisor session > records approval only from a stopped view with evidence and no active work 87ms
✓ test/supervisor-session.test.ts > blocks the general intercom actuator even if enabled after startup 2ms
✓ test/supervisor-session.test.ts > keeps a supervisor unready after model restoration failure, then recovers explicitly without substituting a model 2ms
✓ test/supervisor-session.test.ts > warns once on unavailable usage but stays quiet for Pi's post-compaction null token sample 2ms
stdout | test/native-intercom.test.ts > runs a forked Pi supervisor and receives its exact instruction in another Pi session
Native Pi pair: fork retained planning context; SteerWorker delivered exactly: Read the real outputs before declaring completion.
✓ test/native-intercom.test.ts > runs a forked Pi supervisor and receives its exact instruction in another Pi session 2530ms
Test Files 17 passed (17)
Tests 67 passed (67)
Start at 19:24:07
Duration 2.84s (transform 2.36s, setup 0ms, import 6.39s, tests 4.95s, environment 3ms)
+ npm run typecheck
> @wassname2/pi-goals@0.2.2 typecheck
> tsc --noEmit
+ npm run lint
> @wassname2/pi-goals@0.2.2 lint
> biome check src/ test/
Checked 32 files in 91ms. No fixes applied.
+ npm run build
> @wassname2/pi-goals@0.2.2 build
> tsc
+ git diff --check
@@ -1,100 +0,0 @@
# Post-fix independent bug review — pi-goals supervision recovery
Scope: changes `2824396..1668c94` (fix commit `325b939` + evidence commit `1668c94`).
Inputs: AGENTS.md, `slop/reviews/20260908-review-fixes.md` (dispositions), `slop/reviews/20260908-independent-supervision-bug-review.md` (original F1F9), full current sources of `src/{index,intercom,supervisor-session,approval,role-models,herdr}.ts`, changed tests, native evidence logs.
Read-only: no repo edits, no live panes, no messaging. Repro artifacts lived in /tmp only.
Labels: **[TESTED]** = executed/compiled and observed. **[CODE]** = unambiguous from source. **[INFERENCE]** = depends on runtime behavior I could not observe here. Test passage is treated as evidence of the asserted path only, not as design proof.
Baseline check: `env -u PI_SUBAGENT_CHILD -u PI_GOALS_ROLE npx vitest run` → 57/57 pass in 16 files, matching the worker's validation claim. **[TESTED]**
---
## Fix verification F1F7
**F1 (unavailable remembered model aborts restore) — verified fixed. [CODE + repo tests]**
`session_start` now sets `modelError` first, configures the binding and timers independent of model selection, and only then attempts `restoreModel` in try/catch (`src/index.ts:557-580`). On failure: no `setModel`, no ready hello (`configure(..., false)` at :562, `markReady` gated on `!modelError` at :572-573), paused widget (`pauseReason`/`updateWidget` :149-153, 271-276), write/sign-off gating (:453-456, 592-597), human input and read-only diagnosis retained. `/model` saves over the failed role choice because `RoleModels.enter` sets `this.role` before throwing (`src/role-models.ts:29-30`), so `/goals reconnect` then picks up the user's replacement — a deliberate, workable recovery chain. No fallback model is substituted anywhere.
**F2 (resumed worker silently unsupervised) — verified fixed, with a residual in P3 below. [CODE + repo tests]**
`connected` now requires own-ready + binding + channel + peerReady (`src/intercom.ts:87`); `onConnectionChange` refreshes the widget immediately (:139, :145, :164); a resumed working worker hellos not-ready until its model restores, then `waitReady(5000)` and warns on failure (`src/index.ts:572-577`). Returning peers clear the pause automatically via the hello/`changed` path. Explicit `/goals restart` preserves plan/version and replaces only the tracked pane with a fresh approval binding (test asserts old checkpoint removed, plan unchanged, exactly one close).
**F3 (inactive-plan steer throws/replays) — lifecycle part fixed; delivery gap honestly open. [CODE + repo tests]**
`detach()` (`src/intercom.ts:72-81`) clears the binding on completion/clear/restart; late steers for a dead binding are dropped at the binding check (:151) without invoking `onSteer` or acking — covered by the new intercom tests. Ack ordering is still handoff-before-ack (:186-193), so a synchronous `sendUserMessage` throw leaves the steer unrecorded/unacked and it retries (test proves retry succeeds). The documented residual is real and correctly **not** claimed fixed: Pi 0.84.1's `sendUserMessage` is a void wrapper over an async enqueue, so an ack can precede an asynchronous enqueue failure, after which the instruction is gone from the supervisor's pending set and never reaches the model — silently. This is a genuine gap a future correlated-receipt protocol should close; the recorded UAT requirement (force an async enqueue rejection) is the right acceptance test. Acceptable as an explicitly-open item, not as a resolved one.
**F4 (stale pane → repeated 5-minute Ready waits) — verified fixed for the timeout itself. [CODE + repo tests]**
Existing-pane reconnect waits are 5s (`src/index.ts:186`, `:323`); first launch keeps the 300s compaction allowance (:213); failed `pane run` retains and reports the pane ID (:204-208); no automatic pane kill. **However, see P1: in one important sub-scenario the 5s retry fails deterministically even when the supervisor is healthy, so the fix's "retry" guidance does not actually recover there.**
**F5 (supervisor gets general `intercom` tool) — verified fixed. [CODE + native test]**
`intercom` is in `BLOCKED_TOOLS` (`src/supervisor-session.ts:13`), filtered from active tools at start and bootstrap (:108-110, :146), and blocked at tool-call time even if re-enabled (:170-173). The native pair test asserts the real supervisor model request's tool list excludes `intercom` and `bash`. Note the tool gate uses `terminate: true`, so a blocked call ends the whole supervisor turn — a deliberate-looking but behaviorally stronger choice than the planning gate's plain block.
**F6 (nested placeholder evidence) — verified fixed as far as claimed. [CODE + repo tests]**
Both the inline and child-bullet paths reject exactly `(empty until sign-off)` case-insensitively (`src/supervisor-session.ts:46,52`); the string matches the template in `src/prompts.ts:97`. Residual (documented as a presence floor): the child scan still accepts *any* deeper-indented nonblank bullet as evidence, and quoted variants like `"(empty until sign-off)"` pass. That is a semantic-judging limit, accurately disclaimed; supervisor judgment remains the real gate. Acceptable.
**F7 (last-goal hash includes Log/Interview) — verified fixed. [CODE + TESTED via unit tests]**
`goalBlock` now truncates the plan at `## Log` before scanning and ends the block at the next goal line or any `#`/`##` heading, with `trimEnd` (`src/approval.ts:43-58`). `approval.test.ts` covers duplicate goal text in the log, Interview section, next-goal boundary, and real block edits invalidating the hash; the flow test proves a manual log line between ApproveGoal and CompleteGoal no longer invalidates. Fail-closed on upgrade (old hashes need re-approval) is the right direction. One residual asymmetry (P4 below).
---
## New findings
### P1 — Reconnect/Ready-retry can wedge in a half-open state: peer hello is only re-sent on *perceived* state change (Medium) [TESTED]
`GoalIntercom.configure()` resets `peer`/`peerReady` (`src/intercom.ts:45-46`) and sends a hello, but the peer replies to a hello only when *its own* view changed (`src/intercom.ts:154-164`: `changed = !this.peer || this.peerReady !== message.ready; if (changed) this.hello()`). There is no periodic hello. If the peer's stored state already matches the incoming hello (same session id, same ready flag), it stays silent — so the side that reconfigured never learns the peer and `connected` stays false forever (until some unrelated broker `session_joined` at :148 happens to trigger a hello).
Reproduced in isolation (compiled real `src/intercom.ts` from HEAD, two links cross-wired as broker peers, script in /tmp, no repo changes):
```
after initial link: worker.connected = true supervisor.connected = true
after worker reconfigure: worker.connected = false supervisor.connected = true
waitReady REJECTED after 201 ms: Supervisor did not become ready through pi-intercom; inspect its pane.
supervisor steer() succeeded (reports sent)
worker delivered steer: null
```
Consequences, all reachable through new/changed code paths:
1. **`/goals reconnect` on a healthy link breaks it.** `src/index.ts:322-323` reconfigures the same binding; if nothing about readiness actually changed, every retry times out after 5s with "Goal recovery failed", and the only in-app escape is `/goals restart` — which closes the *healthy* pane and invalidates the approval binding (`beginReview` deletes checkpoints).
2. **The F1-on-Ready retry fails deterministically.** First Ready: `startSupervisor` completes the hello exchange (worker announced `ready=true` at `beginReview`/`configure`), then `restoreModel("worker")` throws → back to planning. After the user fixes the model, the next Ready takes the existing-pane path (`src/index.ts:184-186`): `configure` resets the worker's peer, hellos `ready=true`, the supervisor sees no change, stays silent, and `waitReady(5000)` times out — even though the supervisor is up and healthy. Every Ready/reconnect retry repeats this. This undercuts the F1/F4 recovery story on exactly the path those fixes target.
3. **Silent steer loss during the window.** While half-open, the supervisor's `connected` is true, so `SteerWorker` "succeeds", but the worker drops the message at `src/intercom.ts:166` (`event.fromSessionId !== this.peer`) with no notification; the steer sits in pending awaiting a changed hello that may never come. The SteerWorker result text ("Receipt and execution are not confirmed") softens but does not surface this.
Why the tests miss it: the fixture auto-replies to **every** hello with `ready: true` (`test/intercom-fixture.ts:21`), which is precisely the behavior the real peer logic does not have. The new peer-return and reconnect tests therefore cannot observe the change-gated reply.
Suggested direction (not implemented): reply to a hello whenever the sender may have lost state — e.g. have `configure` retain `peer`/`peerReady` when the binding is unchanged (re-handshake is only needed after a real transport/binding change), or include a monotonic hello generation and reply to any newer/unknown generation. An unconditional reply to every hello also works without ping-pong, because the *response* hello is still change-gated on the receiver's side.
### P2 — Failed Ready leaves the worker announcing `ready=true` while paused (Low) [CODE]
In the Ready flow, `beginReview``configure(approvalId, "worker", ctx)` defaults to `ready=true` (`src/intercom.ts:43`, `src/index.ts:171`). If `restoreModel("worker")` then throws (`src/index.ts:525` → catch at :537-544), the code rolls back `phase` to planning but never rolls back intercom readiness or detaches. The worker thereafter hellos `ready=true` on any broker event while `modelError` is set; the supervisor sees a ready, connected worker, `SteerWorker` sends successfully, and the worker's `onSteer` throws (`src/index.ts:113-116`) — unacked, error notification per replay. Self-consistent recovery exists (next Ready after `/model` works, modulo P1), so impact is confusing error noise and a misleading readiness signal, not loss. A `markNotReady`/detach in that catch would align the announced state with the pause.
### P3 — Worker pause message misattributes a *supervisor-side* pause (Low) [CODE]
`pauseReason()` (`src/index.ts:149-154`) collapses "peer absent" and "peer present but not ready" into one message: "Supervisor disconnected. Run /goals reconnect, or /goals restart…". When the supervisor pane is alive but paused on its own model restoration (`src/supervisor-session.ts:150-158` sets supervisor `modelError`, readiness stays false), the worker-side `/goals reconnect` will hello, get a `ready=false` reply, and time out after 5s — the advised action cannot work; the actual fix is `/model` + `/goals reconnect` in the supervisor pane. The supervisor pane does display its own error notification, and the design keeps both panes visible, so the user has the information — but the worker-side guidance points the wrong way. `peer` set + `peerReady` false is distinguishable from no peer; the message could be too.
### P4 — `goalBlock` and `tickGoal` now scan different regions (Low) [CODE]
Post-F7, `goalBlock` only sees the pre-`## Log` region (`src/approval.ts:44`), while `tickGoal` and `scanGoals` still scan the whole file (`src/index.ts:670-677`, :53-60). A goal-shaped line quoted inside the Log (e.g. a pasted checklist) yields: `goalBlock` finds a unique match → approval proceeds and hashes, but `CompleteGoal``tickGoal` finds two hits → returns null → sign-off blocked after a successful approval. Fail-closed, requires unusual plan content, and the same class of confusion pre-dates the fix (both sides failed before); noting it because the fix changed the boundary of only one of the two scanners.
### P5 — Ready catch can resurrect a cleared plan phase after a concurrent `/goals clear` (Low) [CODE/INFERENCE]
The Ready path awaits up to 300s inside `startSupervisor` (`src/index.ts:213`), and neither `detach()` nor `configure()` wakes `waitReady` waiters (only hellos/shutdown do; `detach`'s clearing of `binding` means its own not-ready hello is ignored by waiters, and the peer's reply is dropped by the now-empty binding check). If the user runs `/goals clear` during that wait, the plan state is cleared; when the wait later times out, the catch at `src/index.ts:537-544` unconditionally sets `phase: "planning"` and persists — yielding `phase: "planning"` with `planVersion: null`, a "drafting goals" widget over no plan, and "No active plan to disconnect" from `/goals clear`. Recoverable via a fresh `/goals <objective>`, and the interleaving requires issuing a command while the Ready select-loop is mid-wait, hence Low. I did not execute this interleaving; it follows from the unconditional catch and the waiter semantics. Guarding the catch on "state still belongs to this Ready attempt" (e.g. approvalId/planVersion unchanged) would close it.
---
## Assessment of documented residuals (not accepted on documentation alone)
- **F3 durable-delivery gap**: genuine and correctly scoped as open. Concretely, after an acked-but-async-failed enqueue, the supervisor waits indefinitely for a response to an instruction the worker model never saw, with no signal on either side; the recorded future UAT (inject an async enqueue rejection, assert no confirmed-delivery claim and recoverability) is the right bar. Fine to defer; not fine to call resolved — and it isn't.
- **F8 (unknown usage disables 100k compaction)**: the `?? 0` fallback (`src/supervisor-session.ts:187`) silently disables the custom compaction wherever `getContextUsage()` is unavailable, contradicting the AGENTS.md cost design with no user-visible signal. Mitigating factor I verified: the supervisor system prompt (with `planPath`) is re-appended every `before_agent_start` (:175), and approvals/checkpoints live on disk, so a fallback default-compaction does not lose the plan pointer or approval state — the consequence is cost/context-rot drift, not correctness. Still, a one-time "usage unknown; custom compaction inactive" notification would close the observability gap cheaply. Acceptable as a documented limitation; the silence is the weakest part.
- **F9 (planning/pause bash gate holes)**: accurately disclaimed as guardrail-not-sandbox. The paused-diagnostic gate (`src/index.ts:453-456`) intentionally inherits the same heuristic, including the `git diff --ext-diff` external-command hole that requires a pre-existing hostile `.git/config`. Given the threat model (trusted repo, trusted extensions), the README statement is sufficient; a hardened policy remains correctly out of scope.
- **Test-quality caveat**: beyond the fixture issue in P1, the native pair test drives only `SteerWorker`; the two-real-session `ApproveGoal → CompleteGoal` chain is still unexecuted end to end, so the F7 hash boundary and the view-freshness gate are verified only per-side (unit/flow tests) plus one real supervisor tool-list inspection. The disposition states this; I confirm it remains true at 1668c94.
## What is solid
- Shutdown/late-startup guards (`src/index.ts:180, 199-203, 210`) and the supervisor's `bootstrapping` `finally` fix are correct; the test proves no late persistence after shutdown.
- Queued pending steers when *own* readiness changes are handled correctly on both roles: republish is gated on `peerReady && this.ready` (`src/intercom.ts:158-162`), pause suppresses republication, and recovery replays exactly the unacked set from session entries. The only hole in this chain is P1's missing trigger.
- Approval binding safety (per-approvalId, head/tree/clean-worktree/goal-block-hash equality, restart invalidating old approvals) is preserved and extended by the restart flow.
- Human recovery availability while paused is real on both roles: input, read-only tools, `/model`, `/goals reconnect|restart|clear` all remain reachable; sign-off and writes fail closed.
## Summary
F1F7 are fixed as claimed, with tests and native evidence matching the dispositions. The significant new finding is **P1**: the change-gated hello reply combined with `configure()`'s peer reset makes `/goals reconnect` and Ready-retry wedge half-open precisely when readiness did not change — including the F1-on-Ready retry scenario the fixes were built for — and steers are silently dropped in that window while `steer()` reports success. P2P5 are low-severity consistency/guard gaps. Documented residuals F3/F8/F9 are honest; F3's delivery gap and F8's silent compaction-disable remain open items, not fixes.
Attribution: independent reviewer, run bdb93a2e-52f4-4a6d-bac2-7c9eb48118b5; preserved verbatim by Pi/OpenAI implementation worker.
@@ -1,151 +0,0 @@
# pi-goals supervision bug review — HEAD 2824396
> Attribution: independent delegated reviewer, run `5c8c2017-a92f-4a5f-baf6-f441f9b50495`, artifact `supervision-bug-review.md`. Findings below are preserved from that reviewer, not authored by the implementation worker. Implementation dispositions are in `20260908-review-fixes.md`.
Scope: AGENTS.md, src/{index,intercom,supervisor-session,background,role-models,approval,worker-view,herdr,prompts}.ts and tests.
Priorities: lifecycle/reload, delivery/reconnect, approval safety, autonomy failures.
Method: static review plus targeted checks against the installed `@earendil-works/pi-coding-agent` 0.84.1 and `pi-intercom` 0.13.0 sources, and one live reproduction (F1). Nothing in the repo was modified; repro scripts lived in /tmp.
Labels: **[TESTED]** = demonstrated by execution or verified against dependency source. **[CODE]** = read directly from pi-goals source; control flow unambiguous. **[INFERENCE]** = depends on behavior I could not observe.
---
## F1 — Working-phase session restore aborts halfway when the remembered role model is unavailable (Medium) [TESTED]
`src/index.ts:486-495` (`session_start`):
```ts
if (state.phase) await models.enter(...); // line 488 — can throw
planningContextPending = state.phase === "planning";
resyncReason = state.phase === "working" ? "New session." : null;
if (state.phase === "working") {
intercom.configure(state.approvalId!, "worker", ctx); // line 492 — skipped on throw
startWorkerTimers(ctx); // line 493 — skipped
}
updateWidget(ctx); // line 495 — skipped
```
`RoleModels.enter` (`src/role-models.ts:30-40`) throws `worker model is unavailable...` when the saved `.pi/pi-goals/models/worker.json` names a model that `ctx.modelRegistry.find` can no longer resolve (provider removed, auth expired). That is a realistic state: the feature exists precisely to remember models across sessions, and model availability changes over time.
Reproduction (executed): mock Pi host, persisted state `{phase: "working", approvalId: "appr-1", planVersion: 1}`, saved worker model `gone/expired`, `modelRegistry.find → undefined`. Result:
```
session_start handler threw: worker model is unavailable. Select an available model with /model, then retry. Saved choice was not replaced.
intercom.configure called during working-phase restore: false
```
Consequences after the throw:
- Intercom binding is never restored: no hello, `peerReady` stays false, every subsequent `publishWorkerView` silently records views with an empty binding and never publishes them.
- The hourly view timer never starts.
- Widget is not updated.
- On a planning-phase resume, `planningContextPending` is never set, so the planning snapshot is never re-injected.
- Pi catches per-handler errors (`ExtensionRunner.emit`, runner.js:587-601) and routes them to `emitError`, so the user sees at most an extension-error diagnostic. The error text says "then retry", but no code path retries the restore — `session_start` does not re-run when the user picks a new model.
This overlaps F2: the session resumes looking normal while supervision is dead.
## F2 — No supervisor liveness check on worker resume; dead supervisor pane is invisible (Medium) [CODE]
`src/index.ts:486-495`: on resume with `phase === "working"`, the worker calls `intercom.configure` (which sends one hello) and starts timers. There is no `waitReady`, no Herdr pane probe, and no timeout. If the supervisor pane died while the worker session was closed:
- `GoalIntercom.view()` (`src/intercom.ts:82-88`) records the view and skips publishing because `connected` is false — silently. No notify anywhere on this path.
- `updateWidget` still renders "· supervised" (`src/index.ts:249`).
- The worker system prompt tells the model to "Stop when a goal appears complete so the supervisor can inspect a settled worker view" — it will stop and wait for an approval that can never arrive. `CompleteGoal` then fails with "no matching supervisor approval checkpoint" with no hint that the supervisor is gone.
- The only reconnect wait (`waitReady`) lives in `startSupervisor`, which is unreachable from the working phase: the Ready menu only renders when `state.phase === "planning"` (`src/index.ts:417`). The only recovery is `/goals clear` (drops plan linkage) or `/goals <new objective>` (new plan version, old plan orphaned). There is no "restart supervisor" path that preserves the current plan.
[INFERENCE] Whether the broker notices the dead pane while the worker is offline is irrelevant here — the worker has no handler for "peer never came back after resume" in either case.
## F3 — `onSteer` rejection throws before ack: unacked steer replays forever, error notification each reconnect (Medium-low) [CODE]
`src/index.ts:113-116`:
```ts
intercom.onSteer = (instruction) => {
if (state.phase !== "working") throw new Error("Worker plan is not active; instruction rejected.");
pi.sendUserMessage(`[supervisor] ${instruction}`, { deliverAs: "steer" });
};
```
`src/intercom.ts:167-174` (worker steer branch):
```ts
this.onSteer(message.text!); // throws → everything below skipped
this.received.add(message.id);
this.record("in", message);
this.publish({ ... kind: "received" ... });
```
Because `onSteer` runs before dedupe/record/ack, a steer that arrives when the plan is not active (plan just completed — `publishWorkerView` sets `phase: null` at index.ts:213; or `/goals clear`; or a supervisor that ignores "stop issuing instructions") is:
1. never acked — the supervisor keeps it in `pending` and republishes it on every `changed` hello (`src/intercom.ts:143-149`), so each supervisor reconnect re-fires the throw;
2. never recorded — so the dedupe set can't suppress it;
3. surfaced only as `Goal Intercom error: ... instruction rejected.` notifications in the worker pane; the supervisor's `SteerWorker` result says only "Receipt and execution are not confirmed", so the supervisor model cannot distinguish "rejected" from "lost" and may re-send, producing one error notification per attempt.
Related at-least-once window: a crash between `pi.sendUserMessage` (persisted) and `record("in", ...)` causes the same `[supervisor] ...` instruction to be delivered twice after resume. Narrow, but the fix is the same: record/ack before invoking `onSteer`, and add a rejection result back to the supervisor instead of throwing.
## F4 — Stale `supervisorPaneId` makes every Ready retry block for 5 minutes (Medium-low) [CODE]
`src/index.ts:163-166`:
```ts
if (state.supervisorPaneId && state.approvalId) {
intercom.configure(state.approvalId, "worker", ctx);
await intercom.waitReady(); // default 300_000 ms, intercom.ts:73
return;
}
```
This reconnect path is taken after a partial `startSupervisor` failure — e.g. `herdr pane split` succeeded (pane id persisted via the `onOpened` callback at index.ts:174-176) but `herdr pane run` failed (`src/herdr.ts:76-84`), or `models.enter("worker")` threw after the supervisor started. The pane is dead or the supervisor process exited, but the retry never asks Herdr whether the pane exists; it blocks the `agent_settled` handler (and therefore the planning menu) until the 5-minute `waitReady` timeout. Every subsequent Ready repeats the 5-minute hang. `/goals clear` recovers (`closeSupervisorPane` tolerates `NOT_FOUND`/`PANE_GONE`, herdr.ts:60-66), but the timeout error message ("inspect its pane") does not say so.
Also note the same 5-minute blocking wait applies to the supervisor's first-time initial compaction (`supervisor-session.ts:133-160`); a slow compaction of a large fork produces the same opaque worker-side failure, though that path self-heals on retry.
## F5 — The "read-only" supervisor gets pi-intercom's full `intercom` tool (Low-medium, approval/authority surface) [TESTED against pi-intercom source]
The supervisor runs with `--no-extensions -e src/index.ts` (`src/herdr.ts:48-58`), so pi-intercom is never an installed extension in the supervisor session, so `GoalIntercom.loadIntercom` (`src/intercom.ts:189-200`) always dynamically imports it. `intercom(api)` executes pi-intercom's full default export, which registers:
- the `intercom` tool: "Send a message to another pi session running on this machine" (pi-intercom/index.ts:2088),
- `/intercom`, `/intercom-id`, `/alias` commands (pi-intercom/index.ts:2802-2812).
The supervisor's read-only enforcement filters only `WRITER_TOOLS` (`src/supervisor-session.ts:13`, applied at session_start line ~124 and in bootstrap), so `intercom` remains an active tool for the supervisor model. Effect: the supervisor — prompted as read-only with `SteerWorker`/`ApproveGoal` as its only actuators — can message arbitrary Pi sessions on the machine, including the user's other sessions, outside the auditable SteerWorker channel whose renders the tests assert are visible. Severity depends on how much you trust the supervisor model; the capability contradicts the stated design ("all supervisor thinking and messages should be visible", AGENTS.md).
Mitigation would be filtering `intercom` (and any other messaging tools) out of the supervisor's active set, or passing a `registerTool` denylist through the `loadIntercom` proxy (it currently only wraps `on`).
## F6 — `hasEvidenceEntry` accepts placeholder or unrelated nested bullets as evidence (Low) [CODE]
`src/supervisor-session.ts:41-60`. The inline placeholder `(empty until sign-off)` is rejected, but when the inline value is empty the child scan returns true for *any* deeper-indented bullet with nonblank text — including `- (empty until sign-off)` written as a child bullet, or any stray nested line. So this block passes the gate:
```
1. [ ] goal: x
- evidence:
- (empty until sign-off)
```
The supervisor model is instructed to actually read the evidence, so this is a heuristic floor rather than the real defense; still, the placeholder check should apply to child bullets too.
## F7 — Approval goal block for the last goal runs to EOF; tail edits spuriously invalidate approvals (Low) [CODE]
`goalBlock` (`src/approval.ts:36-53`) slices from the goal line to the next goal line *or EOF*. For the last goal, the block includes `## Log`, `## Interview`, and the Appendix. `hashGoalBlock` therefore changes if the worker appends a manual `## Log` line (which the prompts encourage — `stamp()` exists for that) between `ApproveGoal` and `CompleteGoal`, producing "no matching supervisor approval checkpoint" and forcing a fresh review. Fail-closed, so not a safety bug; it is an availability/UX trap in the normal approve → log → sign-off rhythm. Consider ending the block at the fold (`## Log`) like `foldPlan` does.
## F8 — Supervisor 100k compaction silently disabled when `getContextUsage` is unavailable (Low) [INFERENCE]
`src/supervisor-session.ts:141-143`: `if (compacting || (ctx.getContextUsage()?.tokens ?? 0) < COMPACT_AT_TOKENS) return;`. If `getContextUsage()` returns undefined (RPC/print modes or any runtime where it isn't wired), tokens coerce to 0 and the supervisor never self-compacts, contradicting the AGENTS.md cost design ("compacts every 100k"). Pi's own auto-compaction will eventually fire without the custom instructions that protect the plan pointer and approval state. I could not confirm whether `getContextUsage` is ever undefined in the Herdr-pane interactive mode; in the test mock it is explicitly set.
## F9 — Plan-mode bash gate: residual holes are narrow but worth noting (Low) [CODE/INFERENCE]
`isPlanningReadOnlyCommand` (`src/index.ts:566-574`) is otherwise tight (blocks pipes/redirects/backticks/`$`, splits on `&&`/`;`, whitelists verbs, special-cases `--output`, `find -delete/-exec...`, mutating `git branch`). Residual issues:
- The whitelist allows `git log/show/diff` with *arbitrary* flags. `git diff --ext-diff` / `git log --ext-diff` execute the command configured in `diff.external`/`GIT_EXTERNAL_DIFF`. Env-prefix assignments are blocked (the part must start with a whitelisted verb), so this requires a pre-existing malicious `.git/config` in the target repo. [INFERENCE] that any real repo would have this.
- Plan mode blocks only `edit`/`write` by name (`PLAN_MODE_BLOCKED_TOOLS`, index.ts:34). Any other extension's mutating tool (e.g. a `process`/background-task launcher, `apply_patch`-style tools — the supervisor's own `WRITER_TOOLS` list at supervisor-session.ts:13 acknowledges several) is not blocked in plan mode. In the worker session all user extensions are loaded, so this depends on the user's setup. [INFERENCE]
## Non-findings (checked, working as intended)
- **Shutdown latch**: `GoalIntercom.stopped = true` on `session_shutdown` looked dangerous for in-process `/resume`, but Pi tears down and re-creates the ExtensionRunner (and therefore all extension instances) on resume/new/fork/reload (agent-session-runtime.js:102-112, agent-session.js:2053-2073). [TESTED against pi source]
- **Handler ordering**: Pi runs handlers sequentially in registration order and awaits them (runner.js:579-604), so `GoalIntercom`'s constructor-registered `session_start` (channel load) completes before index.ts's `configure` → hello. Per-handler errors are swallowed into `emitError` (this is why F1 is silent). [TESTED against pi source]
- **ApproveGoal freshness gates**: the `view === newest.text` equality check is sound — `sendUserMessage` stores the text verbatim (agent-session.js:1106-1133), `latestView` is set before `onView` fires, and any newer queued view makes the comparison fail closed. Worker "stopped"/`backgroundQuiet` are extension-computed (`ctx.isIdle()`, `backgroundState`), not model-controlled, so the worker model cannot spoof a stopped/quiet view. `backgroundState` fails closed ("unknown" → not quiet) when an installed tracker doesn't answer, and distinguishes missing providers (background.ts, covered by test/background.test.ts).
- **Approval checkpoint binding**: head/tree/clean-worktree/goal-block-hash equality plus per-`approvalId` binding and `beginReview`'s deletion of prior approvals make approval replay across plans or commits infeasible; `.pi/plan`, approvals, and model prefs are correctly excluded from the dirtiness check relative to repo root (`approval.ts:20-34`).
- **Steer/view redelivery after restart**: pending steers and `received` dedupe survive restart via session-entry replay (`intercom.ts:54-68`) and are covered by test/intercom.test.ts; ack cursors are monotonic.
- **Two-peer guard**: the "Two peers claim this supervision binding" throw fires before any state mutation and repeats harmlessly; it can wedge only if the broker failed to emit `session_left` for the previous peer, which the broker does send on disconnect/reregister (broker.ts:327,540).
## Test-coverage gaps relevant to the above
- No test exercises F1 (resume with unavailable remembered model).
- No test exercises a resumed worker whose supervisor never answers (F2) — the intercom fixture auto-replies to hellos, so `connected` is always true in tests.
- The native end-to-end test (test/native-intercom.test.ts) drives `SteerWorker` only; the `ApproveGoal` → approval file → `CompleteGoal` chain has never run through two real Pi sessions, so F7-class friction and the `view === newest.text` gate are unverified end to end.
@@ -1,62 +0,0 @@
> @wassname2/pi-goals@0.2.2 test
> vitest run --reporter=verbose
RUN v4.1.9 /home/code/.pi/agent/git/github.com/wassname/pi-goals
✓ test/package-agent.test.ts > package manifest > includes the extension without registering a packaged subagent 6ms
✓ test/herdr.test.ts > supervisor pane command > forks the planning session with pi-goals owning its Intercom dependency 3ms
✓ test/herdr.test.ts > supervisor pane command > accepts Herdr's text version output and stale pane cleanup 40ms
✓ test/prompts.test.ts > planning prompt > requires fact finding or a focused question before a goal 2ms
✓ test/prompts.test.ts > planning prompt > restores the same rule after compaction 0ms
✓ test/prompts.test.ts > planning prompt > anchors work and sign-off to the user-visible result 0ms
✓ test/intercom.test.ts > pi-intercom transport > receives exact advice once, acknowledges it and rejects unrelated peers 14ms
✓ test/intercom.test.ts > pi-intercom transport > restores an unacknowledged steer on reconnect and stops replay after acknowledgment 7ms
✓ test/intercom.test.ts > pi-intercom transport > cancels a readiness wait on shutdown 4ms
✓ test/fold.test.ts > foldPlan (current goals are above ## Log; durable memory is below it) > keeps the title, user voice and goals 2ms
✓ test/fold.test.ts > foldPlan (current goals are above ## Log; durable memory is below it) > drops the log, the learnings and the unlimited appendix 1ms
✓ test/fold.test.ts > foldPlan (current goals are above ## Log; durable memory is below it) > returns the whole plan when there is no ## Log yet (a fresh draft) 0ms
✓ test/fold.test.ts > openSubtasks (the widget shows the next action, so the plan IS the task list) > lists the active goal's open and in-progress subtasks, stopping at the next goal 1ms
✓ test/fold.test.ts > openSubtasks (the widget shows the next action, so the plan IS the task list) > does not leak subtasks from the goal below 1ms
✓ test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > ticks the exact-matching goal line, case-insensitive, leaving subtasks alone 2ms
✓ test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > returns null on wording drift (fuzzy matching is the judge's job, not TypeScript's) 0ms
✓ test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > returns null when the subject matches more than one goal line 0ms
stdout | test/intercom-broker.test.ts > exchanges readiness, views and exact advice over a real isolated pi-intercom broker
Intercom broker: readiness confirmed; exact worker view and supervisor advice received.
✓ test/append-log.test.ts > appendLog (the extension's only plan-file write) > creates ## Log at EOF when absent 2ms
✓ test/append-log.test.ts > appendLog (the extension's only plan-file write) > appends after the last existing log line, before any following header 1ms
✓ test/intercom-broker.test.ts > exchanges readiness, views and exact advice over a real isolated pi-intercom broker 221ms
✓ test/goals-flow.test.ts > /goals flow > reports actual idle state, invalidates stopped views on start, and stops completed plans 38ms
✓ test/goals-flow.test.ts > /goals flow > preserves drafts, records the interview, and keeps planning read-only 21ms
✓ test/goals-flow.test.ts > /goals flow > forks a visible supervisor on Ready and keeps the main session as worker 24ms
✓ test/goals-flow.test.ts > /goals flow > starts work only after the supervisor launcher resolves 20ms
✓ test/goals-flow.test.ts > /goals flow > delivers an Intercom instruction to the worker 20ms
✓ test/goals-flow.test.ts > /goals flow > closes the supervisor on clear but keeps the plan file 24ms
✓ test/goals-flow.test.ts > /goals flow > accepts only an approval for the exact clean commit and goal block 49ms
✓ test/goals-flow.test.ts > process role > keeps subagent children and visible supervisors out of the worker extension 0ms
✓ test/supervisor-session.test.ts > visible supervisor session > restores monitoring and read-only tools without replaying persisted views 6ms
✓ test/supervisor-session.test.ts > visible supervisor session > renders all advice in real Pi tool rows, including collapsed and restored rows 25ms
✓ test/supervisor-session.test.ts > visible supervisor session > asks for judgment and useful recaps without inventing instructions 1ms
✓ test/supervisor-session.test.ts > visible supervisor session > writes readiness only after removing writing tools 2ms
✓ test/supervisor-session.test.ts > visible supervisor session > compacts a large planning fork before writing readiness 1ms
✓ test/supervisor-session.test.ts > visible supervisor session > does not become ready when initial compaction fails 1ms
✓ test/supervisor-session.test.ts > visible supervisor session > writes a durable worker instruction 1ms
✓ test/supervisor-session.test.ts > visible supervisor session > records approval only from a stopped view with evidence and no active work 58ms
✓ test/rpc-review.test.ts > RPC review flow > opens Refine's editor before it starts the revision turn 1384ms
Test Files 11 passed (11)
Tests 37 passed (37)
Start at 16:31:10
Duration 1.67s (transform 1.31s, setup 0ms, import 3.59s, tests 2.00s, environment 1ms)
> @wassname2/pi-goals@0.2.2 typecheck
> tsc --noEmit
> @wassname2/pi-goals@0.2.2 lint
> biome check src/ test/
Checked 21 files in 67ms. No fixes applied.
@@ -1,81 +0,0 @@
> @wassname2/pi-goals@0.2.2 test
> vitest run --reporter=verbose
RUN v4.1.9 /home/code/.pi/agent/git/github.com/wassname/pi-goals
✓ test/package-agent.test.ts > package manifest > includes the extension without registering a packaged subagent 2ms
✓ test/prompts.test.ts > planning prompt > requires fact finding or a focused question before a goal 2ms
✓ test/prompts.test.ts > planning prompt > restores the same rule after compaction 1ms
✓ test/prompts.test.ts > planning prompt > anchors work and sign-off to the user-visible result 0ms
✓ test/background.test.ts > reports tracked running work, rather than equating idle agent with finished jobs 3ms
✓ test/background.test.ts > distinguishes missing providers from an unavailable installed tracker 4ms
stdout | test/role-models.test.ts > remembers each role without automatic switching overwriting another role
Role preferences restored: planning=planner, worker=small-worker, supervisor=astra; restore events did not overwrite the choice.
✓ test/role-models.test.ts > remembers each role without automatic switching overwriting another role 7ms
✓ test/role-models.test.ts > fails on an unavailable remembered model without replacing the choice 4ms
✓ test/worker-view.test.ts > keeps human direction and source location while sending only new messages 5ms
✓ test/worker-view.test.ts > restarts after compaction and does not report historical tool calls as active 1ms
✓ test/worker-view.test.ts > bounds serialized Unicode and quoted logs while marking omissions 3ms
✓ test/herdr.test.ts > supervisor pane command > forks the planning session with pi-goals owning its Intercom dependency 3ms
✓ test/herdr.test.ts > supervisor pane command > accepts Herdr's text version output and stale pane cleanup 30ms
✓ test/intercom.test.ts > pi-intercom transport > receives exact advice once, acknowledges it and rejects unrelated peers 6ms
✓ test/intercom.test.ts > pi-intercom transport > restores an unacknowledged steer on reconnect and stops replay after acknowledgment 6ms
✓ test/intercom.test.ts > pi-intercom transport > advances the incremental overview only after acknowledgment 1ms
✓ test/intercom.test.ts > pi-intercom transport > cancels a readiness wait on shutdown 1ms
✓ test/fold.test.ts > foldPlan (current goals are above ## Log; durable memory is below it) > keeps the title, user voice and goals 2ms
✓ test/fold.test.ts > foldPlan (current goals are above ## Log; durable memory is below it) > drops the log, the learnings and the unlimited appendix 1ms
✓ test/fold.test.ts > foldPlan (current goals are above ## Log; durable memory is below it) > returns the whole plan when there is no ## Log yet (a fresh draft) 0ms
✓ test/fold.test.ts > openSubtasks (the widget shows the next action, so the plan IS the task list) > lists the active goal's open and in-progress subtasks, stopping at the next goal 1ms
✓ test/fold.test.ts > openSubtasks (the widget shows the next action, so the plan IS the task list) > does not leak subtasks from the goal below 1ms
✓ test/append-log.test.ts > appendLog (the extension's only plan-file write) > creates ## Log at EOF when absent 2ms
✓ test/append-log.test.ts > appendLog (the extension's only plan-file write) > appends after the last existing log line, before any following header 0ms
stdout | test/intercom-broker.test.ts > exchanges readiness, views and exact advice over a real isolated pi-intercom broker
Intercom broker: readiness confirmed; exact worker view and supervisor advice received.
✓ test/intercom-broker.test.ts > exchanges readiness, views and exact advice over a real isolated pi-intercom broker 206ms
✓ test/goals-flow.test.ts > /goals flow > reports actual idle state, invalidates stopped views on start, and stops completed plans 34ms
✓ test/goals-flow.test.ts > /goals flow > preserves drafts, records the interview, and keeps planning read-only 21ms
✓ test/goals-flow.test.ts > /goals flow > forks a visible supervisor on Ready and keeps the main session as worker 25ms
✓ test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > ticks the exact-matching goal line, case-insensitive, leaving subtasks alone 2ms
✓ test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > returns null on wording drift (fuzzy matching is the judge's job, not TypeScript's) 0ms
✓ test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > returns null when the subject matches more than one goal line 0ms
✓ test/goals-flow.test.ts > /goals flow > starts work only after the supervisor launcher resolves 23ms
✓ test/goals-flow.test.ts > /goals flow > delivers an Intercom instruction to the worker 23ms
✓ test/goals-flow.test.ts > /goals flow > closes the supervisor on clear but keeps the plan file 27ms
✓ test/goals-flow.test.ts > /goals flow > accepts only an approval for the exact clean commit and goal block 163ms
✓ test/goals-flow.test.ts > process role > keeps subagent children and visible supervisors out of the worker extension 0ms
✓ test/supervisor-session.test.ts > visible supervisor session > restores monitoring and read-only tools without replaying persisted views 8ms
✓ test/supervisor-session.test.ts > visible supervisor session > renders all advice in real Pi tool rows, including collapsed and restored rows 27ms
✓ test/supervisor-session.test.ts > visible supervisor session > asks for judgment and useful recaps without inventing instructions 1ms
✓ test/supervisor-session.test.ts > visible supervisor session > writes readiness only after removing writing tools 3ms
✓ test/supervisor-session.test.ts > visible supervisor session > compacts a large planning fork before writing readiness 2ms
✓ test/supervisor-session.test.ts > visible supervisor session > does not become ready when initial compaction fails 2ms
✓ test/supervisor-session.test.ts > visible supervisor session > writes a durable worker instruction 2ms
✓ test/supervisor-session.test.ts > visible supervisor session > records approval only from a stopped view with evidence and no active work 59ms
✓ test/rpc-review.test.ts > RPC review flow > opens Refine's editor before it starts the revision turn 1226ms
stdout | test/native-intercom.test.ts > runs a forked Pi supervisor and receives its exact instruction in another Pi session
Native Pi pair: fork retained planning context; SteerWorker delivered exactly: Read the real outputs before declaring completion.
✓ test/native-intercom.test.ts > runs a forked Pi supervisor and receives its exact instruction in another Pi session 2314ms
Test Files 15 passed (15)
Tests 46 passed (46)
Start at 16:58:17
Duration 2.73s (transform 2.47s, setup 0ms, import 5.82s, tests 4.28s, environment 2ms)
> @wassname2/pi-goals@0.2.2 typecheck
> tsc --noEmit
> @wassname2/pi-goals@0.2.2 lint
> biome check src/ test/
Checked 28 files in 21ms. No fixes applied.
> @wassname2/pi-goals@0.2.2 build
> tsc
@@ -1,17 +0,0 @@
> @wassname2/pi-goals@0.2.2 test
> vitest run --run test/native-intercom.test.ts --reporter=verbose
RUN v4.1.9 /home/code/.pi/agent/git/github.com/wassname/pi-goals
stdout | test/native-intercom.test.ts > runs a forked Pi supervisor and receives its exact instruction in another Pi session
Native Pi pair: fork retained planning context; SteerWorker delivered exactly: Read the real outputs before declaring completion.
✓ test/native-intercom.test.ts > runs a forked Pi supervisor and receives its exact instruction in another Pi session 2264ms
Test Files 1 passed (1)
Tests 1 passed (1)
Start at 16:52:40
Duration 2.43s (transform 26ms, setup 0ms, import 56ms, tests 2.27s, environment 0ms)
@@ -1,24 +0,0 @@
# Initial delegated-worker test failure — Pi/OpenAI
The first implementation check ran `npm run typecheck && npm test` inside the delegated worker's inherited environment (`PI_SUBAGENT_CHILD=1`). Typecheck passed. At that point the suite reported:
```
Test Files 2 failed | 13 passed (15)
Tests 8 failed | 38 passed (46)
```
Representative actual output from that run (18:39:14):
```
FAIL test/goals-flow.test.ts > /goals flow > preserves drafts, records the interview, and keeps planning read-only
TypeError: Cannot read properties of undefined (reading 'handler')
at flow.commands.get("goals").handler("first objective", flow.ctx)
FAIL test/rpc-review.test.ts > RPC review flow > opens Refine's editor before it starts the revision turn
Error: Test timed out in 15000ms.
```
Diagnosis: the production `isMainSession()` deliberately excludes subagent children. Consequently the mock host never registered `/goals`, and the real RPC test process inherited the child flag and did not register it either. This was not treated as a passing test and no product guard was removed to conceal it.
Exact corrected test command: `env -u PI_SUBAGENT_CHILD -u PI_GOALS_ROLE npm test`.
That rerun passed all 46 then-existing tests. Subsequent added regressions also passed. The final complete command and unabridged final output are saved in `20260908-review-fixes-validation.txt`; it uses the same two-variable isolation. All role-specific tests still explicitly configure their intended role. No live user session's environment or settings were changed.
@@ -1,4 +0,0 @@
worker: 21 events parsed; 0 errors; stderr empty
Worker user-message event contains exact instructed text.
supervisor: 21 events parsed; 0 errors; stderr empty
Supervisor outbound/ack ID matched: 780f7dac-e4e5-4351-b890-0684a42de681. This is adapter handling, not durable queue confirmation.
@@ -1,93 +0,0 @@
COMMAND: env -u PI_SUBAGENT_CHILD -u PI_GOALS_ROLE PI_GOALS_EVIDENCE_DIR="$PWD/slop/reviews/review-fixes-native" npm test -- --reporter=verbose && npm run typecheck && npm run lint && npm run build && git diff --check
> @wassname2/pi-goals@0.2.2 test
> vitest run --reporter=verbose
RUN v4.1.9 /home/code/.pi/agent/git/github.com/wassname/pi-goals
✓ test/package-agent.test.ts > package manifest > includes the extension without registering a packaged subagent 2ms
✓ test/approval.test.ts > hashes only the current goal, excluding the log, interview, and their historical goal text 3ms
✓ test/prompts.test.ts > planning prompt > requires fact finding or a focused question before a goal 3ms
✓ test/prompts.test.ts > planning prompt > restores the same rule after compaction 0ms
✓ test/prompts.test.ts > planning prompt > anchors work and sign-off to the user-visible result 1ms
stdout | test/role-models.test.ts > remembers each role without automatic switching overwriting another role
Role preferences restored: planning=planner, worker=small-worker, supervisor=astra; restore events did not overwrite the choice.
✓ test/background.test.ts > reports tracked running work, rather than equating idle agent with finished jobs 3ms
✓ test/background.test.ts > distinguishes missing providers from an unavailable installed tracker 6ms
✓ test/role-models.test.ts > remembers each role without automatic switching overwriting another role 7ms
✓ test/role-models.test.ts > fails on an unavailable remembered model without replacing the choice 4ms
✓ test/worker-view.test.ts > keeps human direction and source location while sending only new messages 3ms
✓ test/worker-view.test.ts > restarts after compaction and does not report historical tool calls as active 1ms
✓ test/worker-view.test.ts > bounds serialized Unicode and quoted logs while marking omissions 3ms
✓ test/herdr.test.ts > supervisor pane command > forks the planning session with pi-goals owning its Intercom dependency 3ms
✓ test/herdr.test.ts > supervisor pane command > accepts Herdr's text version output and stale pane cleanup 25ms
✓ test/intercom.test.ts > pi-intercom transport > receives exact advice once, acknowledges it and rejects unrelated peers 5ms
✓ test/intercom.test.ts > pi-intercom transport > restores an unacknowledged steer on reconnect and stops replay after acknowledgment 3ms
✓ test/intercom.test.ts > pi-intercom transport > advances the incremental overview only after acknowledgment 1ms
✓ test/intercom.test.ts > pi-intercom transport > cancels a readiness wait on shutdown 1ms
✓ test/intercom.test.ts > does not acknowledge a synchronous handoff failure, and retries the instruction 1ms
✓ test/intercom.test.ts > detaches a completed binding and ignores its late advice without replay errors or false acceptance 1ms
✓ test/append-log.test.ts > appendLog (the extension's only plan-file write) > creates ## Log at EOF when absent 2ms
✓ test/append-log.test.ts > appendLog (the extension's only plan-file write) > appends after the last existing log line, before any following header 0ms
✓ test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > ticks the exact-matching goal line, case-insensitive, leaving subtasks alone 2ms
✓ test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > returns null on wording drift (fuzzy matching is the judge's job, not TypeScript's) 0ms
✓ test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > returns null when the subject matches more than one goal line 0ms
✓ test/fold.test.ts > foldPlan (current goals are above ## Log; durable memory is below it) > keeps the title, user voice and goals 2ms
✓ test/fold.test.ts > foldPlan (current goals are above ## Log; durable memory is below it) > drops the log, the learnings and the unlimited appendix 1ms
✓ test/fold.test.ts > foldPlan (current goals are above ## Log; durable memory is below it) > returns the whole plan when there is no ## Log yet (a fresh draft) 0ms
✓ test/fold.test.ts > openSubtasks (the widget shows the next action, so the plan IS the task list) > lists the active goal's open and in-progress subtasks, stopping at the next goal 1ms
✓ test/fold.test.ts > openSubtasks (the widget shows the next action, so the plan IS the task list) > does not leak subtasks from the goal below 1ms
stdout | test/intercom-broker.test.ts > exchanges readiness, views and exact advice over a real isolated pi-intercom broker
Intercom broker: readiness confirmed; exact worker view and supervisor advice received.
✓ test/intercom-broker.test.ts > exchanges readiness, views and exact advice over a real isolated pi-intercom broker 226ms
✓ test/goals-flow.test.ts > /goals flow > reports actual idle state, invalidates stopped views on start, and stops completed plans 45ms
✓ test/goals-flow.test.ts > /goals flow > preserves drafts, records the interview, and keeps planning read-only 21ms
✓ test/goals-flow.test.ts > /goals flow > forks a visible supervisor on Ready and keeps the main session as worker 26ms
✓ test/goals-flow.test.ts > /goals flow > starts work only after the supervisor launcher resolves 19ms
✓ test/goals-flow.test.ts > /goals flow > delivers an Intercom instruction to the worker 22ms
✓ test/goals-flow.test.ts > /goals flow > closes the supervisor on clear but keeps the plan file 23ms
✓ test/goals-flow.test.ts > /goals flow > accepts only an approval for the exact clean commit and goal block 42ms
✓ test/goals-flow.test.ts > process role > keeps subagent children and visible supervisors out of the worker extension 0ms
✓ test/goals-flow.test.ts > restores working linkage even when its remembered model is unavailable, and supports explicit recovery 19ms
✓ test/goals-flow.test.ts > restores planning linkage even when its remembered model is unavailable, and supports explicit recovery 18ms
✓ test/goals-flow.test.ts > shows a missing resumed supervisor, pauses writes, and automatically unpauses when that peer returns 19ms
✓ test/goals-flow.test.ts > times out stale Ready retries in five seconds, without replacing the pane automatically 27ms
✓ test/goals-flow.test.ts > explicitly restarts only the tracked pane, keeps the plan, and invalidates old approval binding 22ms
✓ test/goals-flow.test.ts > does not persist startup results or launch work after session shutdown 19ms
✓ test/supervisor-session.test.ts > visible supervisor session > restores monitoring and read-only tools without replaying persisted views 8ms
✓ test/supervisor-session.test.ts > visible supervisor session > renders all advice in real Pi tool rows, including collapsed and restored rows 28ms
✓ test/supervisor-session.test.ts > visible supervisor session > asks for judgment and useful recaps without inventing instructions 2ms
✓ test/supervisor-session.test.ts > visible supervisor session > writes readiness only after removing writing tools 19ms
✓ test/supervisor-session.test.ts > visible supervisor session > compacts a large planning fork before writing readiness 2ms
✓ test/supervisor-session.test.ts > visible supervisor session > does not become ready when initial compaction fails 2ms
✓ test/supervisor-session.test.ts > visible supervisor session > writes a durable worker instruction 2ms
✓ test/supervisor-session.test.ts > visible supervisor session > records approval only from a stopped view with evidence and no active work 89ms
✓ test/supervisor-session.test.ts > blocks the general intercom actuator even if enabled after startup 2ms
✓ test/supervisor-session.test.ts > keeps a supervisor unready after model restoration failure, then recovers explicitly without substituting a model 2ms
✓ test/rpc-review.test.ts > RPC review flow > opens Refine's editor before it starts the revision turn 1303ms
stdout | test/native-intercom.test.ts > runs a forked Pi supervisor and receives its exact instruction in another Pi session
Native Pi pair: fork retained planning context; SteerWorker delivered exactly: Read the real outputs before declaring completion.
✓ test/native-intercom.test.ts > runs a forked Pi supervisor and receives its exact instruction in another Pi session 2338ms
Test Files 16 passed (16)
Tests 57 passed (57)
Start at 18:57:11
Duration 2.57s (transform 1.87s, setup 0ms, import 4.26s, tests 4.46s, environment 2ms)
> @wassname2/pi-goals@0.2.2 typecheck
> tsc --noEmit
> @wassname2/pi-goals@0.2.2 lint
> biome check src/ test/
Checked 29 files in 28ms. No fixes applied.
> @wassname2/pi-goals@0.2.2 build
> tsc
-38
View File
@@ -1,38 +0,0 @@
# Independent review fixes — Pi/OpenAI implementation worker
Baseline: `2824396a711ed56bd462742ab22620df44e5624f`.
Original independent review: [preserved review and attribution](20260908-independent-supervision-bug-review.md), run `5c8c2017-a92f-4a5f-baf6-f441f9b50495`.
The parent approved explicit `/goals reconnect` and `/goals restart`, with human input and read-only diagnosis available while paused. No existing user pane/session was inspected, operated, restarted, or closed. All Herdr recovery operations in this work used mocks. No additional reviewer or subagent was launched by this worker.
Read AGENTS.md and installed Pi extension documentation covering session replacement/shutdown, sequential events, model selection, input, command context, tool gates, compaction and context usage before editing extension lifecycle code. The native tests use repository-local Pi **0.84.1**; the parent host's 0.85.1 version is not the test executable's version.
## Finding dispositions
| Finding | Disposition and concrete proof |
| --- | --- |
| F1: unavailable remembered model aborts restore | Confirmed and fixed. Planning injection and worker binding/timers initialize independently of model selection. A failure leaves an explicit paused widget and gates implementation/sign-off, not a partially initialized normal worker. No fallback model is selected. The worker does not announce readiness until model restoration succeeds. `/model` followed by `/goals reconnect` retries the same plan. Added flow reproductions for both working/planning restoration and supervisor model recovery. Tests assert no `setModel` on unavailable lookup, no ready hello, preserved preferences/binding/version, retained human input, allowed diagnostic reads, blocked writes/sign-off and successful explicit recovery. |
| F2: resumed worker silently has no supervisor | Confirmed and fixed. Connection changes update the widget immediately; absence on restore warns after five seconds. Writes/sign-off are gated while disconnected; human prompts, diagnostic reads and recovery commands remain available. Returning peers clear the connection pause automatically. Explicit restart preserves the working plan and replaces only its tracked pane with a new approval binding. Tests exercise a never-answering peer, later hello, exact owned-pane close, unchanged plan/version, removed old checkpoint, and no automatic pane replacement. |
| F3: inactive-plan steer throws/replays | Confirmed; lifecycle cause addressed without premature acceptance. Completed, cancelled or cleared plans detach their binding and announce not-ready; stale advice is ignored without invoking delivery or acknowledging it. Tests cover completion/clear not accepting advice or restarting, transport detach, and a *synchronous handoff* failure remaining unrecorded/unacked until retry succeeds. **Delivery gap remains:** Pi 0.84.1 `dist/core/agent-session.js:18551862` implements ExtensionAPI.sendUserMessage as a void wrapper calling async `this.sendUserMessage(...).catch(emitError)`; `:11061133` awaits `prompt` internally. The adapter therefore cannot observe durable enqueue success. An async enqueue error may occur after the ack and suppress replay even though the model never received the instruction. A crash between handoff and recording can instead duplicate it. Pending transport messages retain at-least-once retry semantics, but end-to-end durable/at-least-once/exactly-once model delivery is NOT guaranteed. Recording/acking before even the synchronous handoff would worsen loss and was deliberately NOT implemented. Parent explicitly accepted documenting this deeper limitation rather than expanding the protocol in this commit. README and the code comment distinguish adapter handling from persistence/model receipt/execution. |
| F4: stale pane causes repeated five-minute Ready waits | Confirmed and fixed. Existing-pane Ready/reconnect waits are five seconds, with explicit reconnect/restart guidance. First-time launch retains the five-minute compaction allowance. Failed `pane run` retains the pane ID for inspection and reports it. No automatic probe-driven kill/replacement of a possibly healthy slow supervisor. Planning restart clears its failed tracked pane for the next Ready; working restart forks a replacement immediately. Test simulates split success/run failure and two Ready attempts, and proves one launch, zero automatic closes, and a five-second retry. Startup results arriving after shutdown are not persisted and do not launch worker work. |
| F5: general intercom tool available to supervisor | Confirmed and fixed. `intercom` is removed alongside writing tools before readiness and blocked at tool-call time even if later re-enabled. `SteerWorker` remains available. Both mocked gate tests and the real native pair test assert this; the latter inspects the actual supervisor model request's tool list. |
| F6: nested placeholder evidence accepted | Confirmed and fixed. The same exact `(empty until sign-off)` rejection applies to inline and child bullets. Tests exercise both through `ApproveGoal`, assert no approval file, then confirm actual nonblank evidence still passes. This is a presence floor, not a semantic evidence judge; unrelated nonblank prose still requires supervisor judgment. |
| F7: last goal hash includes Log/Interview | Confirmed and fixed. The canonical block ignores the Log and stops at the next goal or top-level section. Trailing section-separator whitespace is excluded. Unit tests cover log history containing duplicate goal text, interview, next goal, and actual goal edits still invalidating the hash. The flow test appends a manual Log entry between approval and CompleteGoal and still succeeds. Previously recorded hashes may require a fresh approval after upgrade (fail closed). |
| F8: unknown usage disables 100k compaction | Assessed; no speculative estimator added. Installed `agent-session.js:getContextUsage()` returns undefined without a usable model/window and explicitly returns `tokens: null` after compaction until a later assistant usage sample exists. Native RPC tests have valid usage; RPC mode itself is not evidence of permanent unavailability. Existing unknown handling avoids immediate repeat compaction. Persistent unavailable usage still prevents the custom 100k trigger; this remains a documented limitation, not claimed fixed. |
| F9: planning read-only guard residuals | Confirmed as a guardrail limitation, not fixed by broad tool/shell policy changes in this task. Planning still explicitly gates edit/write and selected bash commands, not every installed extension actuator. Git read commands can invoke configured external diff/textconv programs. Paused diagnostic bash uses this same heuristic, so trusted repository configuration and extensions are required; it is NOT a security sandbox. README now states this. A hardened shell policy or comprehensive planning tool allowlist needs separately scoped review; no claim of airtight isolation is made. |
## Validation and inspected evidence
- [Full final command/output](20260908-review-fixes-validation.txt): **57 tests passed in 16 files**, typecheck, lint, build and `git diff --check` passed.
- Exact test environment isolation: `env -u PI_SUBAGENT_CHILD -u PI_GOALS_ROLE PI_GOALS_EVIDENCE_DIR="$PWD/slop/reviews/review-fixes-native" npm test -- --reporter=verbose`. This runs main-session tests as a main session, while explicit role tests still select their role.
- [Initial child-environment failure](20260908-review-fixes-initial-validation.md): recorded the original failure (8 failed/38 passed), cause and exact corrected command. It was not omitted or counted as a pass.
- Inspected [worker native events](review-fixes-native/worker-events.jsonl) and [supervisor native events](review-fixes-native/supervisor-events.jsonl): the worker received `[supervisor] Read the real outputs before declaring completion.`; supervisor out and ack records share the same instruction ID in the saved run. Both stderr files are empty; neither event log contains an error/failed-response/error-notification record.
- Tests preserve human recovery/input while paused, peer-return unpause, and clear/complete not receiving stale advice or reopening supervision. Shutdown guards prevent late startup results from writing the disposed runtime.
## Remaining acceptance limits
**Priority residual: F3 durable delivery confirmation is still open.** Required UAT for a future correlated-receipt design: force an asynchronous Pi enqueue rejection after the adapter returns; the supervisor must not report confirmed model delivery and the instruction must remain recoverable. The current receipt does not make that promise.
These fixes still need the parent's independent post-change review. The native pair uses a deterministic local model and a transport-only worker fixture; it proves routing/context retention and supervisor tool exposure, not good judgment, cost savings, rendered Herdr behavior, or the full two-native-session ApproveGoal → CompleteGoal chain. Full fresh-shell supervisor role restoration without launcher environment remains unverified. An already-created pane can remain for inspection if shutdown interrupts startup; the fix avoids stale context use rather than silently operating such a pane. Background work is not killed by recovery, and unregistered detached work remains outside tracker coverage.
No changes were pushed by this implementation worker.
@@ -1,73 +0,0 @@
> @wassname2/pi-goals@0.2.2 test
> vitest run --reporter=verbose
RUN v4.1.9 /home/code/.pi/agent/git/github.com/wassname/pi-goals
✓ test/package-agent.test.ts > package manifest > includes the extension without registering a packaged subagent 3ms
stdout | test/role-models.test.ts > remembers each role without automatic switching overwriting another role
Role preferences restored: planning=planner, worker=small-worker, supervisor=astra; restore events did not overwrite the choice.
✓ test/background.test.ts > reports tracked running work, rather than equating idle agent with finished jobs 2ms
✓ test/background.test.ts > distinguishes missing providers from an unavailable installed tracker 6ms
✓ test/role-models.test.ts > remembers each role without automatic switching overwriting another role 7ms
✓ test/role-models.test.ts > fails on an unavailable remembered model without replacing the choice 6ms
✓ test/prompts.test.ts > planning prompt > requires fact finding or a focused question before a goal 2ms
✓ test/prompts.test.ts > planning prompt > restores the same rule after compaction 0ms
✓ test/prompts.test.ts > planning prompt > anchors work and sign-off to the user-visible result 0ms
✓ test/intercom.test.ts > pi-intercom transport > receives exact advice once, acknowledges it and rejects unrelated peers 5ms
✓ test/intercom.test.ts > pi-intercom transport > restores an unacknowledged steer on reconnect and stops replay after acknowledgment 3ms
✓ test/intercom.test.ts > pi-intercom transport > advances the incremental overview only after acknowledgment 1ms
✓ test/intercom.test.ts > pi-intercom transport > cancels a readiness wait on shutdown 1ms
✓ test/herdr.test.ts > supervisor pane command > forks the planning session with pi-goals owning its Intercom dependency 2ms
✓ test/herdr.test.ts > supervisor pane command > accepts Herdr's text version output and stale pane cleanup 30ms
✓ test/worker-view.test.ts > keeps human direction and source location while sending only new messages 2ms
✓ test/worker-view.test.ts > restarts after compaction and does not report historical tool calls as active 0ms
✓ test/worker-view.test.ts > bounds serialized Unicode and quoted logs while marking omissions 2ms
✓ test/fold.test.ts > foldPlan (current goals are above ## Log; durable memory is below it) > keeps the title, user voice and goals 2ms
✓ test/fold.test.ts > foldPlan (current goals are above ## Log; durable memory is below it) > drops the log, the learnings and the unlimited appendix 0ms
✓ test/fold.test.ts > foldPlan (current goals are above ## Log; durable memory is below it) > returns the whole plan when there is no ## Log yet (a fresh draft) 0ms
✓ test/fold.test.ts > openSubtasks (the widget shows the next action, so the plan IS the task list) > lists the active goal's open and in-progress subtasks, stopping at the next goal 1ms
✓ test/fold.test.ts > openSubtasks (the widget shows the next action, so the plan IS the task list) > does not leak subtasks from the goal below 1ms
stdout | test/intercom-broker.test.ts > exchanges readiness, views and exact advice over a real isolated pi-intercom broker
Intercom broker: readiness confirmed; exact worker view and supervisor advice received.
✓ test/append-log.test.ts > appendLog (the extension's only plan-file write) > creates ## Log at EOF when absent 1ms
✓ test/append-log.test.ts > appendLog (the extension's only plan-file write) > appends after the last existing log line, before any following header 0ms
✓ test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > ticks the exact-matching goal line, case-insensitive, leaving subtasks alone 2ms
✓ test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > returns null on wording drift (fuzzy matching is the judge's job, not TypeScript's) 0ms
✓ test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > returns null when the subject matches more than one goal line 0ms
✓ test/intercom-broker.test.ts > exchanges readiness, views and exact advice over a real isolated pi-intercom broker 222ms
✓ test/goals-flow.test.ts > /goals flow > reports actual idle state, invalidates stopped views on start, and stops completed plans 36ms
✓ test/goals-flow.test.ts > /goals flow > preserves drafts, records the interview, and keeps planning read-only 24ms
✓ test/goals-flow.test.ts > /goals flow > forks a visible supervisor on Ready and keeps the main session as worker 26ms
✓ test/goals-flow.test.ts > /goals flow > starts work only after the supervisor launcher resolves 21ms
✓ test/goals-flow.test.ts > /goals flow > delivers an Intercom instruction to the worker 21ms
✓ test/goals-flow.test.ts > /goals flow > closes the supervisor on clear but keeps the plan file 19ms
✓ test/goals-flow.test.ts > /goals flow > accepts only an approval for the exact clean commit and goal block 47ms
✓ test/goals-flow.test.ts > process role > keeps subagent children and visible supervisors out of the worker extension 0ms
✓ test/supervisor-session.test.ts > visible supervisor session > restores monitoring and read-only tools without replaying persisted views 7ms
✓ test/supervisor-session.test.ts > visible supervisor session > renders all advice in real Pi tool rows, including collapsed and restored rows 22ms
✓ test/supervisor-session.test.ts > visible supervisor session > asks for judgment and useful recaps without inventing instructions 1ms
✓ test/supervisor-session.test.ts > visible supervisor session > writes readiness only after removing writing tools 2ms
✓ test/supervisor-session.test.ts > visible supervisor session > compacts a large planning fork before writing readiness 2ms
✓ test/supervisor-session.test.ts > visible supervisor session > does not become ready when initial compaction fails 3ms
✓ test/supervisor-session.test.ts > visible supervisor session > writes a durable worker instruction 5ms
✓ test/supervisor-session.test.ts > visible supervisor session > records approval only from a stopped view with evidence and no active work 49ms
✓ test/rpc-review.test.ts > RPC review flow > opens Refine's editor before it starts the revision turn 1427ms
Test Files 14 passed (14)
Tests 45 passed (45)
Start at 16:49:24
Duration 1.79s (transform 1.51s, setup 0ms, import 4.33s, tests 2.03s, environment 1ms)
> @wassname2/pi-goals@0.2.2 typecheck
> tsc --noEmit
> @wassname2/pi-goals@0.2.2 lint
> biome check src/ test/
Checked 26 files in 62ms. No fixes applied.
@@ -1,27 +0,0 @@
INITIAL VIEW
The worker stopped.
review trigger: settled
source session: /isolated/worker.jsonl
worker model: test/worker
latest human direction:
Modal does not use our GPU.
tool calls with no result: none
tracked background work: processes: 0; subagents: 0; unregistered work is not tracked
new worker transcript (initial or reset view):
I am waiting for the local queue.
AFTER ACKNOWLEDGMENT
The worker stopped.
review trigger: settled
source session: /isolated/worker.jsonl
worker model: test/worker
latest human direction:
Modal does not use our GPU.
tool calls with no result: none
tracked background work: processes: 0; subagents: 0; unregistered work is not tracked
new worker transcript since the last acknowledged view:
The command launches a Modal remote GPU; local default stays paused.
@@ -1,68 +0,0 @@
> @wassname2/pi-goals@0.2.2 test
> vitest run --reporter=verbose
RUN v4.1.9 /home/code/.pi/agent/git/github.com/wassname/pi-goals
✓ test/worker-view.test.ts > keeps human direction and source location while sending only new messages 6ms
✓ test/worker-view.test.ts > restarts after compaction and does not report historical tool calls as active 0ms
✓ test/worker-view.test.ts > bounds serialized Unicode and quoted logs while marking omissions 2ms
✓ test/background.test.ts > reports tracked running work, rather than equating idle agent with finished jobs 2ms
✓ test/background.test.ts > distinguishes missing providers from an unavailable installed tracker 5ms
✓ test/package-agent.test.ts > package manifest > includes the extension without registering a packaged subagent 2ms
✓ test/intercom.test.ts > pi-intercom transport > receives exact advice once, acknowledges it and rejects unrelated peers 5ms
✓ test/intercom.test.ts > pi-intercom transport > restores an unacknowledged steer on reconnect and stops replay after acknowledgment 3ms
✓ test/intercom.test.ts > pi-intercom transport > advances the incremental overview only after acknowledgment 1ms
✓ test/intercom.test.ts > pi-intercom transport > cancels a readiness wait on shutdown 1ms
✓ test/herdr.test.ts > supervisor pane command > forks the planning session with pi-goals owning its Intercom dependency 2ms
✓ test/herdr.test.ts > supervisor pane command > accepts Herdr's text version output and stale pane cleanup 26ms
✓ test/prompts.test.ts > planning prompt > requires fact finding or a focused question before a goal 2ms
✓ test/prompts.test.ts > planning prompt > restores the same rule after compaction 1ms
✓ test/prompts.test.ts > planning prompt > anchors work and sign-off to the user-visible result 0ms
✓ test/append-log.test.ts > appendLog (the extension's only plan-file write) > creates ## Log at EOF when absent 1ms
✓ test/append-log.test.ts > appendLog (the extension's only plan-file write) > appends after the last existing log line, before any following header 0ms
✓ test/fold.test.ts > foldPlan (current goals are above ## Log; durable memory is below it) > keeps the title, user voice and goals 1ms
✓ test/fold.test.ts > foldPlan (current goals are above ## Log; durable memory is below it) > drops the log, the learnings and the unlimited appendix 1ms
✓ test/fold.test.ts > foldPlan (current goals are above ## Log; durable memory is below it) > returns the whole plan when there is no ## Log yet (a fresh draft) 0ms
✓ test/fold.test.ts > openSubtasks (the widget shows the next action, so the plan IS the task list) > lists the active goal's open and in-progress subtasks, stopping at the next goal 1ms
✓ test/fold.test.ts > openSubtasks (the widget shows the next action, so the plan IS the task list) > does not leak subtasks from the goal below 1ms
✓ test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > ticks the exact-matching goal line, case-insensitive, leaving subtasks alone 2ms
✓ test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > returns null on wording drift (fuzzy matching is the judge's job, not TypeScript's) 1ms
✓ test/tick-goal.test.ts > tickGoal (sign-off ticks the goal; agent only ticks on wording drift) > returns null when the subject matches more than one goal line 0ms
stdout | test/intercom-broker.test.ts > exchanges readiness, views and exact advice over a real isolated pi-intercom broker
Intercom broker: readiness confirmed; exact worker view and supervisor advice received.
✓ test/intercom-broker.test.ts > exchanges readiness, views and exact advice over a real isolated pi-intercom broker 226ms
✓ test/goals-flow.test.ts > /goals flow > reports actual idle state, invalidates stopped views on start, and stops completed plans 45ms
✓ test/goals-flow.test.ts > /goals flow > preserves drafts, records the interview, and keeps planning read-only 17ms
✓ test/goals-flow.test.ts > /goals flow > forks a visible supervisor on Ready and keeps the main session as worker 20ms
✓ test/goals-flow.test.ts > /goals flow > starts work only after the supervisor launcher resolves 18ms
✓ test/goals-flow.test.ts > /goals flow > delivers an Intercom instruction to the worker 22ms
✓ test/goals-flow.test.ts > /goals flow > closes the supervisor on clear but keeps the plan file 20ms
✓ test/goals-flow.test.ts > /goals flow > accepts only an approval for the exact clean commit and goal block 44ms
✓ test/goals-flow.test.ts > process role > keeps subagent children and visible supervisors out of the worker extension 0ms
✓ test/supervisor-session.test.ts > visible supervisor session > restores monitoring and read-only tools without replaying persisted views 5ms
✓ test/supervisor-session.test.ts > visible supervisor session > renders all advice in real Pi tool rows, including collapsed and restored rows 20ms
✓ test/supervisor-session.test.ts > visible supervisor session > asks for judgment and useful recaps without inventing instructions 1ms
✓ test/supervisor-session.test.ts > visible supervisor session > writes readiness only after removing writing tools 1ms
✓ test/supervisor-session.test.ts > visible supervisor session > compacts a large planning fork before writing readiness 1ms
✓ test/supervisor-session.test.ts > visible supervisor session > does not become ready when initial compaction fails 1ms
✓ test/supervisor-session.test.ts > visible supervisor session > writes a durable worker instruction 1ms
✓ test/supervisor-session.test.ts > visible supervisor session > records approval only from a stopped view with evidence and no active work 49ms
✓ test/rpc-review.test.ts > RPC review flow > opens Refine's editor before it starts the revision turn 1197ms
Test Files 13 passed (13)
Tests 43 passed (43)
Start at 16:41:18
Duration 1.43s (transform 927ms, setup 0ms, import 3.00s, tests 1.77s, environment 1ms)
> @wassname2/pi-goals@0.2.2 typecheck
> tsc --noEmit
> @wassname2/pi-goals@0.2.2 lint
> biome check src/ test/
Checked 24 files in 19ms. No fixes applied.
@@ -1,72 +0,0 @@
# Review against user intent
## Follow-up: code fixes, full goal still unproven
Implemented directly after the subagent runner failed and the user authorized direct work. The tests now exercise full advice in real Pi tool components (collapsed, expanded, restored, streaming arguments), emitted thinking/text display, resume without replay of persisted views, latest-view coalescing, actual idle/busy status, stale-view approval rejection, and stopping completed-plan timers. The supervisor prompt now asks for a brief evidence-based progress assessment and useful judgment instead of instruction-only reviews. Background job status is explicitly unmeasured; approval still requires the supervisor to inspect job evidence when relevant.
[Saved validation output](20260908_supervision-fixes-validation.txt):
> Tests 34 passed (34)
> resumed: deliveredViews=0, activeTools=read, readyReceipt=true
> interval view without any work: The worker stopped.
Typecheck and lint also succeeded in that log. The reproduction script now asserts the corrected behavior; the original reproduction output below is retained as historical evidence. Readiness is cleared on startup and normal shutdown, but it is not a heartbeat or proof of worker receipt. The review here is my own source/diff review, not the independent review that failed to launch. Existing user panes and the separate pi-supervise worktree were not modified.
Remaining acceptance: a real isolated two-pane run with the intended model pair, observed useful advice and worker response, plus measured token/cost totals. Prompt assertions do not establish judgment quality. No full-goal completion is claimed.
-- Pi/OpenAI
## Original review
Verdict at `06794bf`: not achieved.
Reviewed `experiment/goals-owned-supervision` at `4ebb4d1` against [AGENTS.md](../../AGENTS.md#user-intent-for-this-branch). This is a source review and isolated runtime reproduction by Pi/OpenAI, not an independent model review or a real two-pane acceptance test. No existing session or pane was operated.
The overnight `goals-supervisor-01a040d0` transcript used the older pi-supervise/intercom implementation. It is not runtime evidence for this mailbox branch. The uncommitted display patch in `/tmp/pi-supervise-visible-advice` is also separate from this branch and was not counted as completed work.
## Findings
1. **P1: the supervisor's actual advice is still hidden by the default tool-call display.** `src/supervisor-session.ts:157-169` registers `SteerWorker` without a call renderer and returns only a receipt. This fails the user's explicit visibility requirement. Normal emitted assistant text/thinking uses Pi's own display; the local setting already has `hideThinkingBlock: false`. That does not reveal advice inside unrendered tool arguments.
Observed in the isolated harness:
> steer: renderCall=undefined, result=Worker instruction 1 recorded.
2. **P1: supervisor resume loses monitoring and read-only tool selection.** `src/supervisor-session.ts:94-107` returns when it finds the persisted bootstrap marker, before starting the new process's polling timer or removing write tools. `ready.json` remains present, so the receipt does not identify this loss of supervision. The harness starts, shuts down, then registers a new extension instance using the saved entries and default tools:
> fresh: deliveredViews=1, activeTools=read, readyReceipt=true
> resumed: deliveredViews=0, activeTools=read,write,bash, readyReceipt=true
This reproduces a branch bug; it is not a diagnosis of the different overnight implementation.
3. **P1: periodic views can tell the supervisor an idle worker is running.** `src/index.ts:201-203` publishes an interval view without checking idle state. `src/worker-view.ts:45` derives worker status from the review trigger, not actual execution. This undermines decisions about whether continuation is needed.
> interval view without any work: The worker is still working.
4. **The intended judgment and recap behavior is not established.** The current supervisor prompt (`src/supervisor-session.ts:70-73`) emphasizes:
> Use SteerWorker to give one concrete instruction when work is incomplete.
Most of the remaining prompt concerns approval checks. It does not request the user's short assessment of progress, independent perspective, or explanation of a recommendation. This is a mismatch in emphasis, not proof that Astra cannot exercise judgment. Neither minimal thinking nor the requirement to use a steer tool establishes a cause of poor advice.
5. **Low-cost, useful supervision remains untested.** `src/worker-view.ts:41-46` repeats the last compaction summary and up to 12,000 characters from recent messages; it does not make incremental views or measure usefulness/cost. The RPC test (`test/rpc-review.test.ts:51-52`) tests Refine/editor ordering with a deterministic model, not a cheaper worker benefiting from an expensive supervisor. Passing it cannot establish the intended economic or behavioral outcome.
## What is present
- Herdr two-pane launch with an explicit planning-session fork: `src/herdr.ts:49-86`.
- Separate supervisor model selection via `/goals model`; the worker keeps its model. The cheaper-worker/more-expensive-supervisor arrangement is possible but not established by default or validated on a task.
- Initial context compaction above 20k and subsequent compaction at 100k: `src/supervisor-session.ts:8-10,113-155`. This broadly meets the request for compaction around 150k or similar; the exact threshold is not the main gap.
- Direct canonical plan path in the supervisor prompt and worker resynchronization after compaction.
- Settle, 50-turn, and hourly review triggers. Reliable continuation is incomplete because of the resume/status defects above.
## Acceptance still needed
First make the advice visible and correct resume/status behavior. Then run one bounded task in separate test panes with the intended model pair. Save the rendered advice, worker receipt, a useful progress assessment or correction, continuation after compaction/resume, and measured token/cost totals. Judge the content of the advice, not the number of messages or merely successful delivery. Do not use the user's working panes for this test.
The transport rewrite is an implementation choice, not the user's goal.
## Reproduction
The mailbox reproduction script is historical; retrieve it at commit `386305a`. The Intercom migration removes that implementation. Current transport checks are in `test/intercom.test.ts` and `test/intercom-broker.test.ts`.
[Saved output](20260908_supervisor-intent-reproduction.txt) records the exact observations quoted above. The harness uses only temporary mailbox files and mocked Pi lifecycle events; it neither launches Pi nor contacts another session. It asserts the currently observed failure, not desired behavior.
-- Pi/OpenAI
@@ -1,26 +0,0 @@
> @wassname2/pi-goals@0.2.2 test
> vitest run
RUN v4.1.9 /home/code/.pi/agent/git/github.com/wassname/pi-goals
Test Files 9 passed (9)
Tests 34 passed (34)
Start at 10:49:05
Duration 1.34s (transform 639ms, setup 0ms, import 2.76s, tests 1.68s, environment 1ms)
> @wassname2/pi-goals@0.2.2 typecheck
> tsc --noEmit
> @wassname2/pi-goals@0.2.2 lint
> biome check src/ test/
Checked 17 files in 20ms. No fixes applied.
fresh: deliveredViews=1, activeTools=read, readyReceipt=true
steer: renderCall=function, result=Worker instruction 1 recorded. Worker receipt and execution are not confirmed.
resumed: deliveredViews=0, activeTools=read, readyReceipt=true
interval view without any work: The worker stopped.
@@ -1,4 +0,0 @@
fresh: deliveredViews=1, activeTools=read, readyReceipt=true
steer: renderCall=undefined, result=Worker instruction 1 recorded.
resumed: deliveredViews=0, activeTools=read,write,bash, readyReceipt=true
interval view without any work: The worker is still working.
@@ -1,47 +0,0 @@
# Real Herdr functional check
Pi/OpenAI observed this interactive run. Code: HEAD `2b61440` plus uncommitted plan-watch/manual-claim, supervisor-prompt, planning-prompt and startup-compaction changes. These observations do not cover later changes.
## Task and result
Isolated repository: `/tmp/pi-goals-herdr-functional-task`. Worker pane `w8:p4V`; second supervisor pane `w8:p4Y`. Real model: openai-codex/gpt-5.6-terra. Parent selected Ready through the rendered menu. No research pane was operated during this check.
Task: create `hello-again.txt` containing exactly `Hello again.\n`, save byte verification, and commit only the two new files. Commit observed: `1732acccb798e6edd9626fbfde38e3aca941ce4a`.
Observed worker tool output:
> CompleteGoal
> Sign-off accepted. Goal ticked [x] in
> .pi/plan/01a0831d-38ca-76db-b91a-ef4dd0bfecdd-v2.md.
Observed final supervisor response:
> Complete. Supervisor approval and CompleteGoal sign-off are recorded.
Independent parent `od -An -tx1 hello-again.txt` output:
```text
48 65 6c 6c 6f 20 61 67 61 69 6e 2e 0a
```
This is the requested text and final newline. Verification artifact: `/tmp/pi-goals-herdr-functional-task/verify-hello-again.log`.
## Behavior observed
The worker manually ticked the goal before sign-off. The widget displayed `claimed complete; awaiting supervisor review` and supervision remained connected. The supervisor read the actual artifact, verification log and plan, then directed the worker to reopen the goal checkbox. The worker reopened it, preserving evidence. The supervisor recorded approval and instructed CompleteGoal. The worker called it successfully. Parent did not supply these corrective instructions or perform the artifact work in this second run.
## Earlier failures and interventions
The first task stopped for three routine confirmations because the planning prompt required three questions. Parent answered and removed that quota with subsequent user approval. Ready opened a supervisor, but the separate 20k startup compaction threshold caused `Nothing to compact (session too small)`. Parent removed that lower threshold and reloaded the test supervisor. The first run produced its artifact but manual ticking detached supervision before approval; it was NOT successful workflow acceptance.
The first run also showed approval attempts against older queued views. Error text now distinguishes a disconnected worker from a newer pending view and directs the supervisor to finish its response to receive the update rather than request another handoff. The second task reached Ready without routine confirmations and completed without parent repair after Ready.
## Source records
- Worker: `/home/code/.pi/agent/sessions/--tmp-pi-goals-herdr-functional-task--/2026-09-08T22-22-05-515Z_01a0831d-38ca-76db-b91a-ef4dd0bfecdd.jsonl`
- Successful supervisor: `/home/code/.pi/agent/sessions/--tmp-pi-goals-herdr-functional-task--/2026-09-08T22-57-20-349Z_01a0833d-7ddd-7523-92b3-0560f61dbc64.jsonl`
- Failed first supervisor: `/home/code/.pi/agent/sessions/--tmp-pi-goals-herdr-functional-task--/2026-09-08T22-26-54-633Z_01a08321-a229-70ad-9007-cba97aef7072.jsonl`
## Limits
This proves one real trivial workflow, including visible corrective supervision of a manual tick, artifact delivery and sign-off. It does not establish broad judgment quality or cost savings. Idle external-plan edits, active worker reload recovery, all-cancelled handling, and requested `/goals supervise` and `/goals noplan` still require acceptance. Those commands are not implemented yet. Test panes were left available for inspection. Two old dirty native-evidence files remain untouched and are unrelated to this evidence.
@@ -1,39 +0,0 @@
# Full-profile supervisor: focused implementation
## Approved scope
The user explicitly chose normal Pi extensions and tools, including bash/edit/write and custom actions, with the division of work enforced by role instructions rather than a tool denylist. This change does not grant the supervisor implementation authority: the repeated short opening directs inspection/diagnosis and delegates changes through SteerWorker. The long prompt explicitly states that this is not an enforced sandbox.
## Changes
- `src/herdr.ts`: remove only `--no-extensions`; retain explicit source extension, fork, role/binding environment, name and selected model. The inherited environment and normal Pi discovery remain intact.
- `src/supervisor-session.ts`: remove the supervisor BLOCKED_TOOLS constant, both active-tool filters, and tool_call denylist hook. No replacement hooks, per-tool reminders, approval changes or lifecycle repair.
- `src/prompts.ts`: centralize the concise instruction in the already-repeated opening, and clarify the trust boundary in long orientation.
- README/AGENTS: describe normal-profile discovery and instruction-only inspection; avoid claiming hard read-only enforcement or full lifecycle recovery.
- Tests assert bash/edit/write/intercom and custom tools survive startup, simulated reload and reconnect without resetting extension selections. The launcher retains normal discovery. The real native Pi RPC test now enables normal discovery in an isolated agent directory, auto-loads a custom inspection tool without `-e`, verifies it reaches the supervisor's model tool schema, and still observes exact SteerWorker delivery. Its worker remains deliberately isolated with `--no-extensions`.
## Sources inspected
Installed Pi documentation: `docs/usage.md` extension/resource discovery flags, `docs/extensions.md` active-tool APIs and loading, `docs/packages.md` profile scope/deduplication. Read applicable local `recommending-pi-extensions` skill for the full-permission trust boundary. No packages installed or fetched. Existing Intercom reuse/fallback code is unchanged; broker/native tests pass.
## Validation
`validation.txt` records final successful run:
```
env -u PI_GOALS_EVIDENCE_DIR -u PI_SUBAGENT_CHILD -u PI_GOALS_ROLE npm test
npm run typecheck
npm run lint
npm run build
git diff --check
```
108/108 tests in 19 files, typecheck, lint (37 files), build and diff check passed. No changes to `src/index.ts` or `src/approval.ts`; worker planning restrictions and approval checks remain intact. No supervisor BLOCKED_TOOLS, setActiveTools or tool_call enforcement remains.
## Limits and remaining acceptance
This verifies normal discovery using a deterministic local model and an isolated custom extension. It does not prove a real user's complete profile respects the role instruction. Arbitrary extensions retain their own hooks/side effects/tool policies; tools can still write if the model disregards its task. The parent still needs to run real full-profile Herdr acceptance and obtain an independent review. No panes were opened, reloaded or operated.
Issue #6 cancellation, Ready content drift, compaction delivery, fresh-shell role restoration and other lifecycle bugs are intentionally not fixed in this scoped task. Existing running supervisors retain their already-loaded profile until appropriately restarted/reloaded by their owner.
Pre-existing dirty `slop/reviews/review-fixes-native/supervisor-events.jsonl`, `worker-events.jsonl` and untracked `docs/human_journal.md` were neither modified nor staged by this task. No commits include them.
@@ -1,26 +0,0 @@
> @wassname2/pi-goals@0.2.2 test
> vitest run
RUN v4.1.9 /home/code/.pi/agent/git/github.com/wassname/pi-goals
Test Files 19 passed (19)
Tests 108 passed (108)
Start at 12:24:25
Duration 4.69s (transform 4.90s, setup 0ms, import 9.57s, tests 12.54s, environment 3ms)
> @wassname2/pi-goals@0.2.2 typecheck
> tsc --noEmit
> @wassname2/pi-goals@0.2.2 lint
> biome check src/ test/
Checked 37 files in 109ms. No fixes applied.
> @wassname2/pi-goals@0.2.2 build
> tsc
@@ -1,21 +0,0 @@
{"type":"extension_ui_request","id":"1b7b765d-82f4-4ac3-bd12-011f1f3227af","method":"notify","message":"supervisor model: offline/test","notifyType":"info"}
{"type":"entry_appended","entry":{"type":"custom","customType":"pi-goals-visible-supervisor-v2","data":{"version":2,"workerSessionId":"01a080c2-dc16-705a-b544-e383580d9ac7","planPath":"/tmp/goals-native-pair-vfPu3e/plan.md"},"id":"e0a271f9","parentId":"d768c1fd","timestamp":"2026-09-08T11:24:10.287Z"}}
{"type":"entry_appended","entry":{"type":"custom","customType":"pi-goals-intercom","data":{"direction":"in","message":{"binding":"native-pair-test","role":"worker","kind":"view","id":"cf656aef-1404-4d5c-9a11-4fbd4ed5b5dc","text":"The worker stopped.\n\nThe saved plan needs a check of the actual outputs.\n\nworker view id: cf656aef-1404-4d5c-9a11-4fbd4ed5b5dc","reason":"settled","backgroundQuiet":true}},"id":"848cb24d","parentId":"e0a271f9","timestamp":"2026-09-08T11:24:10.295Z"}}
{"type":"agent_start"}
{"type":"turn_start"}
{"type":"message_start","message":{"role":"user","content":[{"type":"text","text":"The worker stopped.\n\nThe saved plan needs a check of the actual outputs.\n\nworker view id: cf656aef-1404-4d5c-9a11-4fbd4ed5b5dc"}],"timestamp":1788866650296}}
{"type":"message_end","message":{"role":"user","content":[{"type":"text","text":"The worker stopped.\n\nThe saved plan needs a check of the actual outputs.\n\nworker view id: cf656aef-1404-4d5c-9a11-4fbd4ed5b5dc"}],"timestamp":1788866650296}}
{"type":"message_start","message":{"role":"assistant","content":[{"type":"toolCall","id":"test-steer","name":"SteerWorker","arguments":{"instruction":"Read the real outputs before declaring completion."},"partialArgs":"{\"instruction\":\"Read the real outputs before declaring completion.\"}","streamIndex":0}],"api":"openai-completions","provider":"offline","model":"test","usage":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"totalTokens":0,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"pending","timestamp":1788866650324}}
{"type":"message_update","assistantMessageEvent":{"type":"toolcall_start","contentIndex":0}}
{"type":"message_update","assistantMessageEvent":{"type":"toolcall_delta","contentIndex":0,"delta":"{\"instruction\":\"Read the real outputs before declaring completion.\"}"}}
{"type":"message_update","assistantMessageEvent":{"type":"toolcall_end","contentIndex":0,"toolCall":{"type":"toolCall","id":"test-steer","name":"SteerWorker","arguments":{"instruction":"Read the real outputs before declaring completion."}}}}
{"type":"message_end","message":{"role":"assistant","content":[{"type":"toolCall","id":"test-steer","name":"SteerWorker","arguments":{"instruction":"Read the real outputs before declaring completion."}}],"api":"openai-completions","provider":"offline","model":"test","usage":{"input":10,"output":10,"cacheRead":0,"cacheWrite":0,"reasoning":0,"totalTokens":20,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"toolUse","timestamp":1788866650324,"rawStopReason":"tool_calls"}}
{"type":"tool_execution_start","toolCallId":"test-steer","toolName":"SteerWorker","args":{"instruction":"Read the real outputs before declaring completion."}}
{"type":"entry_appended","entry":{"type":"custom","customType":"pi-goals-intercom","data":{"direction":"out","message":{"binding":"native-pair-test","role":"supervisor","kind":"steer","id":"22068654-6e7c-4328-890f-9382b25c8ea7","text":"Read the real outputs before declaring completion."}},"id":"0c0166ea","parentId":"ed2e1ca2","timestamp":"2026-09-08T11:24:10.345Z"}}
{"type":"tool_execution_end","toolCallId":"test-steer","toolName":"SteerWorker","result":{"content":[{"type":"text","text":"Worker instruction 22068654-6e7c-4328-890f-9382b25c8ea7 sent through pi-intercom. Receipt and execution are not confirmed by this result."}],"details":{},"isError":false},"isError":false}
{"type":"message_start","message":{"role":"toolResult","toolCallId":"test-steer","toolName":"SteerWorker","content":[{"type":"text","text":"Worker instruction 22068654-6e7c-4328-890f-9382b25c8ea7 sent through pi-intercom. Receipt and execution are not confirmed by this result."}],"details":{},"isError":false,"timestamp":1788866650346}}
{"type":"message_end","message":{"role":"toolResult","toolCallId":"test-steer","toolName":"SteerWorker","content":[{"type":"text","text":"Worker instruction 22068654-6e7c-4328-890f-9382b25c8ea7 sent through pi-intercom. Receipt and execution are not confirmed by this result."}],"details":{},"isError":false,"timestamp":1788866650346}}
{"type":"turn_end","message":{"role":"assistant","content":[{"type":"toolCall","id":"test-steer","name":"SteerWorker","arguments":{"instruction":"Read the real outputs before declaring completion."}}],"api":"openai-completions","provider":"offline","model":"test","usage":{"input":10,"output":10,"cacheRead":0,"cacheWrite":0,"reasoning":0,"totalTokens":20,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"toolUse","timestamp":1788866650324,"rawStopReason":"tool_calls"},"toolResults":[{"role":"toolResult","toolCallId":"test-steer","toolName":"SteerWorker","content":[{"type":"text","text":"Worker instruction 22068654-6e7c-4328-890f-9382b25c8ea7 sent through pi-intercom. Receipt and execution are not confirmed by this result."}],"details":{},"isError":false,"timestamp":1788866650346}]}
{"type":"turn_start"}
{"type":"entry_appended","entry":{"type":"custom","customType":"pi-goals-intercom","data":{"direction":"ack","message":{"binding":"native-pair-test","role":"worker","kind":"received","id":"22068654-6e7c-4328-890f-9382b25c8ea7"}},"id":"6b63b93d","parentId":"8ce5aa46","timestamp":"2026-09-08T11:24:10.348Z"}}
{"id":"supervisor-state","type":"response","command":"get_state","success":true,"data":{"model":{"id":"test","name":"Offline test model","reasoning":false,"input":["text"],"contextWindow":16000,"maxTokens":1000,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0},"api":"openai-completions","provider":"offline","baseUrl":"http://127.0.0.1:37773"},"thinkingLevel":"off","isStreaming":true,"isCompacting":false,"steeringMode":"one-at-a-time","followUpMode":"one-at-a-time","sessionFile":"/tmp/goals-native-pair-vfPu3e/agent/sessions/--tmp-goals-native-pair-vfPu3e--/2026-09-08T11-24-10-111Z_01a080c2-dfff-7290-9118-66b87ab29080.jsonl","sessionId":"01a080c2-dfff-7290-9118-66b87ab29080","autoCompactionEnabled":true,"messageCount":5,"pendingMessageCount":0}}
@@ -1,22 +0,0 @@
{"id":"planning","type":"response","command":"prompt","success":true}
{"type":"agent_start"}
{"type":"turn_start"}
{"type":"message_start","message":{"role":"user","content":[{"type":"text","text":"Retain this planning context for the supervisor fork."}],"timestamp":1788866649278}}
{"type":"message_end","message":{"role":"user","content":[{"type":"text","text":"Retain this planning context for the supervisor fork."}],"timestamp":1788866649278}}
{"type":"message_start","message":{"role":"assistant","content":[{"type":"text","text":"Test context retained. Actual outputs still need inspection."}],"api":"openai-completions","provider":"offline","model":"test","usage":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"totalTokens":0,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"pending","timestamp":1788866649355}}
{"type":"message_update","assistantMessageEvent":{"type":"text_start","contentIndex":0}}
{"type":"message_update","assistantMessageEvent":{"type":"text_delta","contentIndex":0,"delta":"Test context retained. Actual outputs still need inspection."}}
{"type":"message_update","assistantMessageEvent":{"type":"text_end","contentIndex":0,"content":"Test context retained. Actual outputs still need inspection."}}
{"type":"message_end","message":{"role":"assistant","content":[{"type":"text","text":"Test context retained. Actual outputs still need inspection."}],"api":"openai-completions","provider":"offline","model":"test","usage":{"input":10,"output":10,"cacheRead":0,"cacheWrite":0,"reasoning":0,"totalTokens":20,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"stop","timestamp":1788866649355,"rawStopReason":"stop"}}
{"type":"turn_end","message":{"role":"assistant","content":[{"type":"text","text":"Test context retained. Actual outputs still need inspection."}],"api":"openai-completions","provider":"offline","model":"test","usage":{"input":10,"output":10,"cacheRead":0,"cacheWrite":0,"reasoning":0,"totalTokens":20,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"stop","timestamp":1788866649355,"rawStopReason":"stop"},"toolResults":[]}
{"type":"agent_end","messages":[{"role":"user","content":[{"type":"text","text":"Retain this planning context for the supervisor fork."}],"timestamp":1788866649278},{"role":"assistant","content":[{"type":"text","text":"Test context retained. Actual outputs still need inspection."}],"api":"openai-completions","provider":"offline","model":"test","usage":{"input":10,"output":10,"cacheRead":0,"cacheWrite":0,"reasoning":0,"totalTokens":20,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"stop","timestamp":1788866649355,"rawStopReason":"stop"}],"willRetry":false}
{"type":"agent_settled"}
{"id":"worker-state","type":"response","command":"get_state","success":true,"data":{"model":{"id":"test","name":"Offline test model","reasoning":false,"input":["text"],"contextWindow":16000,"maxTokens":1000,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0},"api":"openai-completions","provider":"offline","baseUrl":"http://127.0.0.1:37773"},"thinkingLevel":"off","isStreaming":false,"isCompacting":false,"steeringMode":"one-at-a-time","followUpMode":"one-at-a-time","sessionFile":"/tmp/goals-native-pair-vfPu3e/agent/sessions/--tmp-goals-native-pair-vfPu3e--/2026-09-08T11-24-09-110Z_01a080c2-dc16-705a-b544-e383580d9ac7.jsonl","sessionId":"01a080c2-dc16-705a-b544-e383580d9ac7","autoCompactionEnabled":true,"messageCount":2,"pendingMessageCount":0}}
{"type":"entry_appended","entry":{"type":"custom","customType":"pi-goals-intercom","data":{"direction":"out","message":{"binding":"native-pair-test","role":"worker","kind":"view","id":"cf656aef-1404-4d5c-9a11-4fbd4ed5b5dc","text":"The worker stopped.\n\nThe saved plan needs a check of the actual outputs.\n\nworker view id: cf656aef-1404-4d5c-9a11-4fbd4ed5b5dc","reason":"settled","backgroundQuiet":true}},"id":"57ac2295","parentId":"21d6e68a","timestamp":"2026-09-08T11:24:10.294Z"}}
{"type":"entry_appended","entry":{"type":"custom","customType":"pi-goals-intercom","data":{"direction":"ack","message":{"binding":"native-pair-test","role":"supervisor","kind":"received","id":"cf656aef-1404-4d5c-9a11-4fbd4ed5b5dc"}},"id":"7ffd87dc","parentId":"57ac2295","timestamp":"2026-09-08T11:24:10.295Z"}}
{"type":"entry_appended","entry":{"type":"custom","customType":"pi-goals-intercom","data":{"direction":"ack","message":{"binding":"native-pair-test","role":"supervisor","kind":"received","id":"cf656aef-1404-4d5c-9a11-4fbd4ed5b5dc"}},"id":"b2ffeed1","parentId":"7ffd87dc","timestamp":"2026-09-08T11:24:10.335Z"}}
{"type":"entry_appended","entry":{"type":"custom","customType":"pi-goals-intercom","data":{"direction":"in","message":{"binding":"native-pair-test","role":"supervisor","kind":"steer","id":"22068654-6e7c-4328-890f-9382b25c8ea7","text":"Read the real outputs before declaring completion."}},"id":"34521c62","parentId":"b2ffeed1","timestamp":"2026-09-08T11:24:10.346Z"}}
{"type":"agent_start"}
{"type":"turn_start"}
{"type":"message_start","message":{"role":"user","content":[{"type":"text","text":"[supervisor] Read the real outputs before declaring completion."}],"timestamp":1788866650346}}
{"type":"message_end","message":{"role":"user","content":[{"type":"text","text":"[supervisor] Read the real outputs before declaring completion."}],"timestamp":1788866650346}}
@@ -1,33 +0,0 @@
RUN v4.1.9 /home/code/.pi/agent/git/github.com/wassname/pi-goals
test/goals-flow.test.ts (21 tests | 1 failed | 20 skipped) 71ms
× accepts only an approval for the exact clean commit and goal block 70ms
⎯⎯⎯⎯⎯⎯⎯ Failed Tests 1 ⎯⎯⎯⎯⎯⎯⎯
FAIL test/goals-flow.test.ts > /goals flow > accepts only an approval for the exact clean commit and goal block
AssertionError: expected false to be true // Object.is equality
- Expected
+ Received
- true
+ false
test/goals-flow.test.ts:318:38
316| const cancelled = flow.tools.get("CompleteGoal").execute("cancelled…
317| controller.abort(); // Cancel while the background-state lookup yie…
318| expect((await cancelled).isError).toBe(true);
| ^
319| expect(readFileSync(planPath, "utf8")).toBe(beforeCancel);
320| expect((await flow.tools.get("CompleteGoal").execute("already-cance…
⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯[1/1]⎯
Test Files 1 failed (1)
Tests 1 failed | 20 skipped (21)
Start at 12:28:54
Duration 734ms (transform 273ms, setup 0ms, import 544ms, tests 71ms, environment 0ms)
@@ -1,26 +0,0 @@
> @wassname2/pi-goals@0.2.2 test
> vitest run
RUN v4.1.9 /home/code/.pi/agent/git/github.com/wassname/pi-goals
Test Files 19 passed (19)
Tests 110 passed (110)
Start at 12:30:42
Duration 3.60s (transform 4.23s, setup 0ms, import 8.38s, tests 8.31s, environment 2ms)
> @wassname2/pi-goals@0.2.2 typecheck
> tsc --noEmit
> @wassname2/pi-goals@0.2.2 lint
> biome check src/ test/
Checked 37 files in 34ms. No fixes applied.
> @wassname2/pi-goals@0.2.2 build
> tsc
@@ -1,33 +0,0 @@
RUN v4.1.9 /home/code/.pi/agent/git/github.com/wassname/pi-goals
stdout | test/native-compaction-delivery.test.ts > real Pi preserves worker delivery through compaction success, failure and cancellation
real Pi worker/success: retained message presented once and saved, no extension errors
stdout | test/native-compaction-delivery.test.ts > real Pi preserves worker delivery through compaction success, failure and cancellation
real Pi worker/failure: retained message presented once and saved, no extension errors
stdout | test/native-intercom.test.ts > runs a forked Pi supervisor and receives its exact instruction in another Pi session
Native Pi pair: fork retained planning context; SteerWorker delivered exactly: Read the real outputs before declaring completion.
✓ test/native-intercom.test.ts > runs a forked Pi supervisor and receives its exact instruction in another Pi session 2071ms
stdout | test/native-compaction-delivery.test.ts > real Pi preserves worker delivery through compaction success, failure and cancellation
real Pi worker/cancel: retained message presented once and saved, no extension errors
✓ test/native-compaction-delivery.test.ts > real Pi preserves worker delivery through compaction success, failure and cancellation 2239ms
stdout | test/native-compaction-delivery.test.ts > real Pi preserves supervisor delivery through compaction success, failure and cancellation
real Pi supervisor/success: retained message presented once and saved, no extension errors
stdout | test/native-compaction-delivery.test.ts > real Pi preserves supervisor delivery through compaction success, failure and cancellation
real Pi supervisor/failure: retained message presented once and saved, no extension errors
stdout | test/native-compaction-delivery.test.ts > real Pi preserves supervisor delivery through compaction success, failure and cancellation
real Pi supervisor/cancel: retained message presented once and saved, no extension errors
✓ test/native-compaction-delivery.test.ts > real Pi preserves supervisor delivery through compaction success, failure and cancellation 2176ms
Test Files 2 passed (2)
Tests 3 passed (3)
Start at 12:59:23
Duration 4.60s (transform 52ms, setup 0ms, import 133ms, tests 6.49s, environment 0ms)
-44
View File
@@ -1,44 +0,0 @@
# Lifecycle recovery and role-aware commands
## Scope and decisions
Continue issue #6 and the independent lifecycle review after full-profile commit `1d52857`. Keep normal extensions/tools; do not alter Git/evidence approval policy. The supervisor approved delayed role selection at session_start, a durable inbound-message record, and requiring Pi 0.85.1 instead of maintaining a 0.84 compatibility retry layer. The user additionally authorized `work`, `supervise`, and `noplan` recovery commands.
`138bde5` already committed/pushed the first increment: CompleteGoal cancellation and Ready content stability. Remaining changes build on it, not replace it.
## Fixes
- CompleteGoal checks its signal before/after the asynchronous background lookup and before persistence; stale binding/version/phase or a disposed runtime also rejects. Cancelling one call leaves the plan active. `cancellation-before.txt` records a regression failure against the earlier implementation (it returned success after abort); the updated test verifies no tick/sign-off marker is written and a later valid call still works.
- Ready checks the displayed plan content before launch, after launch, after worker-model restoration and after the first view. A changed plan returns to planning using the existing pane; it does not start the changed implementation. Tests mutate content at launch and model restoration, then select Ready again without another pane.
- Real supervisor and worker sessions now select their role when session entries are available, before registering either role's handlers. A complete supervisor marker (worker, owner, plan path, approval binding) is written before model restoration/compaction. Persisted identity wins over launch environment. Legacy bootstrap markers migrate only with an existing pairing; incomplete records throw visibly without enabling worker mode. Stopped supervisor forks retain their identity. No tool denylist was reintroduced.
- Intercom saves each incoming non-started view/steer in a bounded inbox before calling Pi. It acknowledges only a matching user message_start. That is **session acceptance**, not model judgment or action execution. Unconfirmed payloads are restored from the active branch on reload; separate incremental views are retained rather than overwritten. A pending Pi queue is not re-enqueued while waiting for presentation. Completed/detached bindings and shutdown cancel delivery timers.
- Pi 0.85.1 has a public session_compact_failed event and fixes isIdle to include manual compaction; repo 0.84.1 did not. The minimum peer and exact dev version are now 0.85.1. Installation used `--ignore-scripts --no-audit --no-fund`; no global Pi change. Success/failure/cancel events resume retained context. Since session_compact precedes final controller cleanup, delivery waits for compaction-aware idle state; it never probes by sending a prompt during compaction. Waiting is bounded to 300 one-second idle checks with retained payload and a visible reconnect instruction on exhaustion, not a deadline that interrupts the model.
- Readiness/reconnect paths allow five minutes rather than five seconds. Reload while an inherited compaction is active waits for it rather than starting a second one. An existing last compaction or Pi's Already compacted/Nothing to compact result can proceed to bootstrap. Startup model/compaction failure is communicated through the existing hello so the worker sees the cause promptly. A later ready hello clears the failure.
- An established worker pairing republishes one fresh current view when disconnected→connected, including after supervisor-only reload where the old stopped view had already been accepted. This reuses the connection callback; Ready retains its own initial publication and session_start/reconnect no longer separately publish duplicates. Cleared/completed sessions do not restart monitoring.
- A started-worker view now reports that work is running instead of falsely claiming a newer review is queued for delivery.
## Command meanings
- `/goals work`: existing approved worker session reconnects its saved pairing/model; no new plan, pairing or model fallback. Missing/unapproved pairing is rejected.
- `/goals supervise`: existing saved supervisor reconnects its role/model/pairing. Running it in a worker session is rejected rather than converting the role.
- `/goals noplan`: leave planning restrictions and preserve the draft/history without Ready, implementation, supervisor launch or file deletion. In-flight Ready is invalidated. It does not claim the retained draft was approved.
- `/goals reconnect` remains generic recovery; `/goals restart` explicitly replaces only the tracked pane and invalidates the prior binding; `/goals clear` closes/disconnects while retaining the plan file.
## Runtime validation actually observed
`native-validation.txt` is fresh verbose output from installed Pi 0.85.1 with a local deterministic HTTP model; no credentials or model credits used.
1. Real Pi worker and supervisor delivery during manual compaction: success, local model failure and cancellation, six cases total. Each retained payload is presented exactly once and saved in the session; no extension_error events. The transport in this fixture is deterministic, while Pi owns the real compaction and prompt lifecycle. Success uses an extension-provided summary; failure exercises Pi's HTTP summarization failure. These are not rendered Herdr sessions or 60-second real-model runs.
2. Real native Pi/Intercom pair: full-profile discovery in an isolated agent directory, exact steering delivery, then supervisor termination and fresh-shell `--session` resume with role/binding launcher environment removed. The resumed model sees SteerWorker/ApproveGoal and the discovered profile tool, not CompleteGoal, and retains the supervisor opening. No second supervisor pairing is constructed.
Hook tests additionally cover a simulated 60-second inherited compaction without competing compaction, five-minute Ready/reconnect patience, immediate reported failure plus rejoin, retained distinct deltas through reload, delayed presentation without duplicate enqueue, role migration/incomplete identity, cancelled completion, Ready content drift, and command semantics. Existing paired tests cover symmetric reconnect/model restoration. The accepted-view reconnect regression checks one new view ID and unchanged-payload replay deduplication separately; cleared/completed pairings produce no new view. The tests model `/reload` with new extension instances or saved state; no real interactive `/reload` command was exercised in this task.
Final `validation.txt`: 123 tests in 22 files, typecheck, lint, build, and diff check pass. Native fixture initially could not compact a single retained turn; it now seeds two sufficiently sized turns. This corrected fixture setup is not counted as a product failure. No test processes from earlier runs remained when resuming after timeout; all processes started by these tests were shut down.
## Limits and remaining acceptance
The parent must still run full-profile Herdr acceptance: actual reloads in both orders, drafting/Ready/checkpoint interruption, stopped pair resume, real-model long compaction, and an unmet-outcome correction followed by both sign-offs. Automated session acceptance does not establish judgment quality or cheaper-worker success.
The inbox holds at most 64 messages; overflow is visible and unacknowledged. Arbitrary extensions that rewrite or consume injected user messages can defeat exact-text acceptance matching; crashes between message_start and message persistence can require review/replay. This is not an exactly-once execution guarantee or a general durable model queue. Role instructions remain the only prohibition on supervisor writes. Existing all-cancelled completion behavior and Git-tracked verification policy are unchanged.
No user or test Herdr panes, research sessions, human journal, or pre-existing dirty native evidence logs were operated/read/edited by this task. Changes to package-lock reflect the approved local Pi dependency upgrade. This report does not claim all issue #6 behavioral acceptance is complete.
@@ -1,26 +0,0 @@
> @wassname2/pi-goals@0.2.2 test
> vitest run
RUN v4.1.9 /home/code/.pi/agent/git/github.com/wassname/pi-goals
Test Files 22 passed (22)
Tests 123 passed (123)
Start at 13:08:28
Duration 4.90s (transform 5.07s, setup 0ms, import 11.10s, tests 11.14s, environment 4ms)
> @wassname2/pi-goals@0.2.2 typecheck
> tsc --noEmit
> @wassname2/pi-goals@0.2.2 lint
> biome check src/ test/
Checked 41 files in 77ms. No fixes applied.
> @wassname2/pi-goals@0.2.2 build
> tsc
@@ -1,21 +0,0 @@
{"type":"extension_ui_request","id":"bd32f722-e23e-418f-9c7d-ad1c95622d41","method":"notify","message":"supervisor model: offline/test","notifyType":"info"}
{"type":"entry_appended","entry":{"type":"custom","customType":"pi-goals-visible-supervisor-v2","data":{"version":2,"workerSessionId":"01a08038-30f7-77a0-943b-8a16928ce6f1","planPath":"/tmp/goals-native-pair-KSyOe8/plan.md"},"id":"6b40c31e","parentId":"a6375cb3","timestamp":"2026-09-08T08:52:42.516Z"}}
{"type":"entry_appended","entry":{"type":"custom","customType":"pi-goals-intercom","data":{"direction":"in","message":{"binding":"native-pair-test","role":"worker","kind":"view","id":"508e947c-aff9-427b-a8ff-6f8158fada1f","text":"The worker stopped.\n\nThe saved plan needs a check of the actual outputs.\n\nworker view id: 508e947c-aff9-427b-a8ff-6f8158fada1f","reason":"settled","backgroundQuiet":true}},"id":"666c7a1b","parentId":"6b40c31e","timestamp":"2026-09-08T08:52:42.525Z"}}
{"type":"agent_start"}
{"type":"turn_start"}
{"type":"message_start","message":{"role":"user","content":[{"type":"text","text":"The worker stopped.\n\nThe saved plan needs a check of the actual outputs.\n\nworker view id: 508e947c-aff9-427b-a8ff-6f8158fada1f"}],"timestamp":1788857562526}}
{"type":"message_end","message":{"role":"user","content":[{"type":"text","text":"The worker stopped.\n\nThe saved plan needs a check of the actual outputs.\n\nworker view id: 508e947c-aff9-427b-a8ff-6f8158fada1f"}],"timestamp":1788857562526}}
{"type":"message_start","message":{"role":"assistant","content":[{"type":"toolCall","id":"test-steer","name":"SteerWorker","arguments":{"instruction":"Read the real outputs before declaring completion."},"partialArgs":"{\"instruction\":\"Read the real outputs before declaring completion.\"}","streamIndex":0}],"api":"openai-completions","provider":"offline","model":"test","usage":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"totalTokens":0,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"pending","timestamp":1788857562553}}
{"type":"message_update","assistantMessageEvent":{"type":"toolcall_start","contentIndex":0}}
{"type":"message_update","assistantMessageEvent":{"type":"toolcall_delta","contentIndex":0,"delta":"{\"instruction\":\"Read the real outputs before declaring completion.\"}"}}
{"type":"message_update","assistantMessageEvent":{"type":"toolcall_end","contentIndex":0,"toolCall":{"type":"toolCall","id":"test-steer","name":"SteerWorker","arguments":{"instruction":"Read the real outputs before declaring completion."}}}}
{"type":"message_end","message":{"role":"assistant","content":[{"type":"toolCall","id":"test-steer","name":"SteerWorker","arguments":{"instruction":"Read the real outputs before declaring completion."}}],"api":"openai-completions","provider":"offline","model":"test","usage":{"input":10,"output":10,"cacheRead":0,"cacheWrite":0,"reasoning":0,"totalTokens":20,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"toolUse","timestamp":1788857562553,"rawStopReason":"tool_calls"}}
{"type":"tool_execution_start","toolCallId":"test-steer","toolName":"SteerWorker","args":{"instruction":"Read the real outputs before declaring completion."}}
{"type":"entry_appended","entry":{"type":"custom","customType":"pi-goals-intercom","data":{"direction":"out","message":{"binding":"native-pair-test","role":"supervisor","kind":"steer","id":"1508350f-7ffc-4b01-a976-da06813569f8","text":"Read the real outputs before declaring completion."}},"id":"066af95c","parentId":"1bcc9002","timestamp":"2026-09-08T08:52:42.575Z"}}
{"type":"tool_execution_end","toolCallId":"test-steer","toolName":"SteerWorker","result":{"content":[{"type":"text","text":"Worker instruction 1508350f-7ffc-4b01-a976-da06813569f8 sent through pi-intercom. Receipt and execution are not confirmed by this result."}],"details":{},"isError":false},"isError":false}
{"type":"message_start","message":{"role":"toolResult","toolCallId":"test-steer","toolName":"SteerWorker","content":[{"type":"text","text":"Worker instruction 1508350f-7ffc-4b01-a976-da06813569f8 sent through pi-intercom. Receipt and execution are not confirmed by this result."}],"details":{},"isError":false,"timestamp":1788857562575}}
{"type":"message_end","message":{"role":"toolResult","toolCallId":"test-steer","toolName":"SteerWorker","content":[{"type":"text","text":"Worker instruction 1508350f-7ffc-4b01-a976-da06813569f8 sent through pi-intercom. Receipt and execution are not confirmed by this result."}],"details":{},"isError":false,"timestamp":1788857562575}}
{"type":"turn_end","message":{"role":"assistant","content":[{"type":"toolCall","id":"test-steer","name":"SteerWorker","arguments":{"instruction":"Read the real outputs before declaring completion."}}],"api":"openai-completions","provider":"offline","model":"test","usage":{"input":10,"output":10,"cacheRead":0,"cacheWrite":0,"reasoning":0,"totalTokens":20,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"toolUse","timestamp":1788857562553,"rawStopReason":"tool_calls"},"toolResults":[{"role":"toolResult","toolCallId":"test-steer","toolName":"SteerWorker","content":[{"type":"text","text":"Worker instruction 1508350f-7ffc-4b01-a976-da06813569f8 sent through pi-intercom. Receipt and execution are not confirmed by this result."}],"details":{},"isError":false,"timestamp":1788857562575}]}
{"type":"turn_start"}
{"type":"entry_appended","entry":{"type":"custom","customType":"pi-goals-intercom","data":{"direction":"ack","message":{"binding":"native-pair-test","role":"worker","kind":"received","id":"1508350f-7ffc-4b01-a976-da06813569f8"}},"id":"46f0a926","parentId":"7f0c0a7d","timestamp":"2026-09-08T08:52:42.578Z"}}
{"id":"supervisor-state","type":"response","command":"get_state","success":true,"data":{"model":{"id":"test","name":"Offline test model","reasoning":false,"input":["text"],"contextWindow":16000,"maxTokens":1000,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0},"api":"openai-completions","provider":"offline","baseUrl":"http://127.0.0.1:38351"},"thinkingLevel":"off","isStreaming":true,"isCompacting":false,"steeringMode":"one-at-a-time","followUpMode":"one-at-a-time","sessionFile":"/tmp/goals-native-pair-KSyOe8/agent/sessions/--tmp-goals-native-pair-KSyOe8--/2026-09-08T08-52-42-353Z_01a08038-34f1-74a8-a4a6-0f10c436d961.jsonl","sessionId":"01a08038-34f1-74a8-a4a6-0f10c436d961","autoCompactionEnabled":true,"messageCount":5,"pendingMessageCount":0}}
@@ -1,21 +0,0 @@
{"id":"planning","type":"response","command":"prompt","success":true}
{"type":"agent_start"}
{"type":"turn_start"}
{"type":"message_start","message":{"role":"user","content":[{"type":"text","text":"Retain this planning context for the supervisor fork."}],"timestamp":1788857561517}}
{"type":"message_end","message":{"role":"user","content":[{"type":"text","text":"Retain this planning context for the supervisor fork."}],"timestamp":1788857561517}}
{"type":"message_start","message":{"role":"assistant","content":[{"type":"text","text":"Test context retained. Actual outputs still need inspection."}],"api":"openai-completions","provider":"offline","model":"test","usage":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"totalTokens":0,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"pending","timestamp":1788857561554}}
{"type":"message_update","assistantMessageEvent":{"type":"text_start","contentIndex":0}}
{"type":"message_update","assistantMessageEvent":{"type":"text_delta","contentIndex":0,"delta":"Test context retained. Actual outputs still need inspection."}}
{"type":"message_update","assistantMessageEvent":{"type":"text_end","contentIndex":0,"content":"Test context retained. Actual outputs still need inspection."}}
{"type":"message_end","message":{"role":"assistant","content":[{"type":"text","text":"Test context retained. Actual outputs still need inspection."}],"api":"openai-completions","provider":"offline","model":"test","usage":{"input":10,"output":10,"cacheRead":0,"cacheWrite":0,"reasoning":0,"totalTokens":20,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"stop","timestamp":1788857561554,"rawStopReason":"stop"}}
{"type":"turn_end","message":{"role":"assistant","content":[{"type":"text","text":"Test context retained. Actual outputs still need inspection."}],"api":"openai-completions","provider":"offline","model":"test","usage":{"input":10,"output":10,"cacheRead":0,"cacheWrite":0,"reasoning":0,"totalTokens":20,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"stop","timestamp":1788857561554,"rawStopReason":"stop"},"toolResults":[]}
{"type":"agent_end","messages":[{"role":"user","content":[{"type":"text","text":"Retain this planning context for the supervisor fork."}],"timestamp":1788857561517},{"role":"assistant","content":[{"type":"text","text":"Test context retained. Actual outputs still need inspection."}],"api":"openai-completions","provider":"offline","model":"test","usage":{"input":10,"output":10,"cacheRead":0,"cacheWrite":0,"reasoning":0,"totalTokens":20,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"stop","timestamp":1788857561554,"rawStopReason":"stop"}],"willRetry":false}
{"type":"agent_settled"}
{"id":"worker-state","type":"response","command":"get_state","success":true,"data":{"model":{"id":"test","name":"Offline test model","reasoning":false,"input":["text"],"contextWindow":16000,"maxTokens":1000,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0},"api":"openai-completions","provider":"offline","baseUrl":"http://127.0.0.1:38351"},"thinkingLevel":"off","isStreaming":false,"isCompacting":false,"steeringMode":"one-at-a-time","followUpMode":"one-at-a-time","sessionFile":"/tmp/goals-native-pair-KSyOe8/agent/sessions/--tmp-goals-native-pair-KSyOe8--/2026-09-08T08-52-41-336Z_01a08038-30f7-77a0-943b-8a16928ce6f1.jsonl","sessionId":"01a08038-30f7-77a0-943b-8a16928ce6f1","autoCompactionEnabled":true,"messageCount":2,"pendingMessageCount":0}}
{"type":"entry_appended","entry":{"type":"custom","customType":"pi-goals-intercom","data":{"direction":"out","message":{"binding":"native-pair-test","role":"worker","kind":"view","id":"508e947c-aff9-427b-a8ff-6f8158fada1f","text":"The worker stopped.\n\nThe saved plan needs a check of the actual outputs.\n\nworker view id: 508e947c-aff9-427b-a8ff-6f8158fada1f","reason":"settled","backgroundQuiet":true}},"id":"ac6b2134","parentId":"741cdd0c","timestamp":"2026-09-08T08:52:42.523Z"}}
{"type":"entry_appended","entry":{"type":"custom","customType":"pi-goals-intercom","data":{"direction":"ack","message":{"binding":"native-pair-test","role":"supervisor","kind":"received","id":"508e947c-aff9-427b-a8ff-6f8158fada1f"}},"id":"fd82ceb3","parentId":"ac6b2134","timestamp":"2026-09-08T08:52:42.525Z"}}
{"type":"entry_appended","entry":{"type":"custom","customType":"pi-goals-intercom","data":{"direction":"in","message":{"binding":"native-pair-test","role":"supervisor","kind":"steer","id":"1508350f-7ffc-4b01-a976-da06813569f8","text":"Read the real outputs before declaring completion."}},"id":"495adb1a","parentId":"fd82ceb3","timestamp":"2026-09-08T08:52:42.575Z"}}
{"type":"agent_start"}
{"type":"turn_start"}
{"type":"message_start","message":{"role":"user","content":[{"type":"text","text":"[supervisor] Read the real outputs before declaring completion."}],"timestamp":1788857562576}}
{"type":"message_end","message":{"role":"user","content":[{"type":"text","text":"[supervisor] Read the real outputs before declaring completion."}],"timestamp":1788857562576}}
@@ -1,21 +0,0 @@
{"type":"extension_ui_request","id":"ec31db54-0eee-4cc4-bbdc-550e3297292e","method":"notify","message":"supervisor model: offline/test","notifyType":"info"}
{"type":"entry_appended","entry":{"type":"custom","customType":"pi-goals-visible-supervisor-v2","data":{"version":2,"workerSessionId":"01a080aa-3018-770c-8926-822a3e1a2aa9","planPath":"/tmp/goals-native-pair-Mk0U2D/plan.md"},"id":"280d42da","parentId":"6c8e3540","timestamp":"2026-09-08T10:57:13.430Z"}}
{"type":"entry_appended","entry":{"type":"custom","customType":"pi-goals-intercom","data":{"direction":"in","message":{"binding":"native-pair-test","role":"worker","kind":"view","id":"b483d8c1-8c16-4f2b-8d2f-2de98f190337","text":"The worker stopped.\n\nThe saved plan needs a check of the actual outputs.\n\nworker view id: b483d8c1-8c16-4f2b-8d2f-2de98f190337","reason":"settled","backgroundQuiet":true}},"id":"97ea169c","parentId":"280d42da","timestamp":"2026-09-08T10:57:13.439Z"}}
{"type":"agent_start"}
{"type":"turn_start"}
{"type":"message_start","message":{"role":"user","content":[{"type":"text","text":"The worker stopped.\n\nThe saved plan needs a check of the actual outputs.\n\nworker view id: b483d8c1-8c16-4f2b-8d2f-2de98f190337"}],"timestamp":1788865033440}}
{"type":"message_end","message":{"role":"user","content":[{"type":"text","text":"The worker stopped.\n\nThe saved plan needs a check of the actual outputs.\n\nworker view id: b483d8c1-8c16-4f2b-8d2f-2de98f190337"}],"timestamp":1788865033440}}
{"type":"message_start","message":{"role":"assistant","content":[{"type":"toolCall","id":"test-steer","name":"SteerWorker","arguments":{"instruction":"Read the real outputs before declaring completion."},"partialArgs":"{\"instruction\":\"Read the real outputs before declaring completion.\"}","streamIndex":0}],"api":"openai-completions","provider":"offline","model":"test","usage":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"totalTokens":0,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"pending","timestamp":1788865033468}}
{"type":"message_update","assistantMessageEvent":{"type":"toolcall_start","contentIndex":0}}
{"type":"message_update","assistantMessageEvent":{"type":"toolcall_delta","contentIndex":0,"delta":"{\"instruction\":\"Read the real outputs before declaring completion.\"}"}}
{"type":"message_update","assistantMessageEvent":{"type":"toolcall_end","contentIndex":0,"toolCall":{"type":"toolCall","id":"test-steer","name":"SteerWorker","arguments":{"instruction":"Read the real outputs before declaring completion."}}}}
{"type":"message_end","message":{"role":"assistant","content":[{"type":"toolCall","id":"test-steer","name":"SteerWorker","arguments":{"instruction":"Read the real outputs before declaring completion."}}],"api":"openai-completions","provider":"offline","model":"test","usage":{"input":10,"output":10,"cacheRead":0,"cacheWrite":0,"reasoning":0,"totalTokens":20,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"toolUse","timestamp":1788865033468,"rawStopReason":"tool_calls"}}
{"type":"tool_execution_start","toolCallId":"test-steer","toolName":"SteerWorker","args":{"instruction":"Read the real outputs before declaring completion."}}
{"type":"entry_appended","entry":{"type":"custom","customType":"pi-goals-intercom","data":{"direction":"out","message":{"binding":"native-pair-test","role":"supervisor","kind":"steer","id":"780f7dac-e4e5-4351-b890-0684a42de681","text":"Read the real outputs before declaring completion."}},"id":"d35e2a1d","parentId":"d5c62400","timestamp":"2026-09-08T10:57:13.489Z"}}
{"type":"tool_execution_end","toolCallId":"test-steer","toolName":"SteerWorker","result":{"content":[{"type":"text","text":"Worker instruction 780f7dac-e4e5-4351-b890-0684a42de681 sent through pi-intercom. Receipt and execution are not confirmed by this result."}],"details":{},"isError":false},"isError":false}
{"type":"message_start","message":{"role":"toolResult","toolCallId":"test-steer","toolName":"SteerWorker","content":[{"type":"text","text":"Worker instruction 780f7dac-e4e5-4351-b890-0684a42de681 sent through pi-intercom. Receipt and execution are not confirmed by this result."}],"details":{},"isError":false,"timestamp":1788865033490}}
{"type":"message_end","message":{"role":"toolResult","toolCallId":"test-steer","toolName":"SteerWorker","content":[{"type":"text","text":"Worker instruction 780f7dac-e4e5-4351-b890-0684a42de681 sent through pi-intercom. Receipt and execution are not confirmed by this result."}],"details":{},"isError":false,"timestamp":1788865033490}}
{"type":"turn_end","message":{"role":"assistant","content":[{"type":"toolCall","id":"test-steer","name":"SteerWorker","arguments":{"instruction":"Read the real outputs before declaring completion."}}],"api":"openai-completions","provider":"offline","model":"test","usage":{"input":10,"output":10,"cacheRead":0,"cacheWrite":0,"reasoning":0,"totalTokens":20,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"toolUse","timestamp":1788865033468,"rawStopReason":"tool_calls"},"toolResults":[{"role":"toolResult","toolCallId":"test-steer","toolName":"SteerWorker","content":[{"type":"text","text":"Worker instruction 780f7dac-e4e5-4351-b890-0684a42de681 sent through pi-intercom. Receipt and execution are not confirmed by this result."}],"details":{},"isError":false,"timestamp":1788865033490}]}
{"type":"turn_start"}
{"type":"entry_appended","entry":{"type":"custom","customType":"pi-goals-intercom","data":{"direction":"ack","message":{"binding":"native-pair-test","role":"worker","kind":"received","id":"780f7dac-e4e5-4351-b890-0684a42de681"}},"id":"13443ef1","parentId":"573b245e","timestamp":"2026-09-08T10:57:13.492Z"}}
{"id":"supervisor-state","type":"response","command":"get_state","success":true,"data":{"model":{"id":"test","name":"Offline test model","reasoning":false,"input":["text"],"contextWindow":16000,"maxTokens":1000,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0},"api":"openai-completions","provider":"offline","baseUrl":"http://127.0.0.1:34037"},"thinkingLevel":"off","isStreaming":true,"isCompacting":false,"steeringMode":"one-at-a-time","followUpMode":"one-at-a-time","sessionFile":"/tmp/goals-native-pair-Mk0U2D/agent/sessions/--tmp-goals-native-pair-Mk0U2D--/2026-09-08T10-57-13-272Z_01a080aa-3438-70b0-8498-53cf3c7d68b3.jsonl","sessionId":"01a080aa-3438-70b0-8498-53cf3c7d68b3","autoCompactionEnabled":true,"messageCount":5,"pendingMessageCount":0}}
@@ -1,21 +0,0 @@
{"id":"planning","type":"response","command":"prompt","success":true}
{"type":"agent_start"}
{"type":"turn_start"}
{"type":"message_start","message":{"role":"user","content":[{"type":"text","text":"Retain this planning context for the supervisor fork."}],"timestamp":1788865032458}}
{"type":"message_end","message":{"role":"user","content":[{"type":"text","text":"Retain this planning context for the supervisor fork."}],"timestamp":1788865032458}}
{"type":"message_start","message":{"role":"assistant","content":[{"type":"text","text":"Test context retained. Actual outputs still need inspection."}],"api":"openai-completions","provider":"offline","model":"test","usage":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"totalTokens":0,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"pending","timestamp":1788865032494}}
{"type":"message_update","assistantMessageEvent":{"type":"text_start","contentIndex":0}}
{"type":"message_update","assistantMessageEvent":{"type":"text_delta","contentIndex":0,"delta":"Test context retained. Actual outputs still need inspection."}}
{"type":"message_update","assistantMessageEvent":{"type":"text_end","contentIndex":0,"content":"Test context retained. Actual outputs still need inspection."}}
{"type":"message_end","message":{"role":"assistant","content":[{"type":"text","text":"Test context retained. Actual outputs still need inspection."}],"api":"openai-completions","provider":"offline","model":"test","usage":{"input":10,"output":10,"cacheRead":0,"cacheWrite":0,"reasoning":0,"totalTokens":20,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"stop","timestamp":1788865032494,"rawStopReason":"stop"}}
{"type":"turn_end","message":{"role":"assistant","content":[{"type":"text","text":"Test context retained. Actual outputs still need inspection."}],"api":"openai-completions","provider":"offline","model":"test","usage":{"input":10,"output":10,"cacheRead":0,"cacheWrite":0,"reasoning":0,"totalTokens":20,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"stop","timestamp":1788865032494,"rawStopReason":"stop"},"toolResults":[]}
{"type":"agent_end","messages":[{"role":"user","content":[{"type":"text","text":"Retain this planning context for the supervisor fork."}],"timestamp":1788865032458},{"role":"assistant","content":[{"type":"text","text":"Test context retained. Actual outputs still need inspection."}],"api":"openai-completions","provider":"offline","model":"test","usage":{"input":10,"output":10,"cacheRead":0,"cacheWrite":0,"reasoning":0,"totalTokens":20,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"stop","timestamp":1788865032494,"rawStopReason":"stop"}],"willRetry":false}
{"type":"agent_settled"}
{"id":"worker-state","type":"response","command":"get_state","success":true,"data":{"model":{"id":"test","name":"Offline test model","reasoning":false,"input":["text"],"contextWindow":16000,"maxTokens":1000,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0},"api":"openai-completions","provider":"offline","baseUrl":"http://127.0.0.1:34037"},"thinkingLevel":"off","isStreaming":false,"isCompacting":false,"steeringMode":"one-at-a-time","followUpMode":"one-at-a-time","sessionFile":"/tmp/goals-native-pair-Mk0U2D/agent/sessions/--tmp-goals-native-pair-Mk0U2D--/2026-09-08T10-57-12-216Z_01a080aa-3018-770c-8926-822a3e1a2aa9.jsonl","sessionId":"01a080aa-3018-770c-8926-822a3e1a2aa9","autoCompactionEnabled":true,"messageCount":2,"pendingMessageCount":0}}
{"type":"entry_appended","entry":{"type":"custom","customType":"pi-goals-intercom","data":{"direction":"out","message":{"binding":"native-pair-test","role":"worker","kind":"view","id":"b483d8c1-8c16-4f2b-8d2f-2de98f190337","text":"The worker stopped.\n\nThe saved plan needs a check of the actual outputs.\n\nworker view id: b483d8c1-8c16-4f2b-8d2f-2de98f190337","reason":"settled","backgroundQuiet":true}},"id":"0615fd50","parentId":"0390c249","timestamp":"2026-09-08T10:57:13.437Z"}}
{"type":"entry_appended","entry":{"type":"custom","customType":"pi-goals-intercom","data":{"direction":"ack","message":{"binding":"native-pair-test","role":"supervisor","kind":"received","id":"b483d8c1-8c16-4f2b-8d2f-2de98f190337"}},"id":"4df9ba42","parentId":"0615fd50","timestamp":"2026-09-08T10:57:13.439Z"}}
{"type":"entry_appended","entry":{"type":"custom","customType":"pi-goals-intercom","data":{"direction":"in","message":{"binding":"native-pair-test","role":"supervisor","kind":"steer","id":"780f7dac-e4e5-4351-b890-0684a42de681","text":"Read the real outputs before declaring completion."}},"id":"814b241e","parentId":"4df9ba42","timestamp":"2026-09-08T10:57:13.490Z"}}
{"type":"agent_start"}
{"type":"turn_start"}
{"type":"message_start","message":{"role":"user","content":[{"type":"text","text":"[supervisor] Read the real outputs before declaring completion."}],"timestamp":1788865033490}}
{"type":"message_end","message":{"role":"user","content":[{"type":"text","text":"[supervisor] Read the real outputs before declaring completion."}],"timestamp":1788865033490}}
@@ -1,66 +0,0 @@
> @wassname2/pi-goals@0.2.2 test
> vitest run
RUN v4.1.9 /home/code/.pi/agent/git/github.com/wassname/pi-goals
Test Files 19 passed (19)
Tests 108 passed (108)
Start at 10:47:37
Duration 3.83s (transform 2.36s, setup 0ms, import 6.55s, tests 9.35s, environment 2ms)
> @wassname2/pi-goals@0.2.2 typecheck
> tsc --noEmit
> @wassname2/pi-goals@0.2.2 lint
> biome check src/ test/
src/worker-view.ts:2:1 assist/source/organizeImports FIXABLE ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
× Sort the imported names.
1 │ import { compile } from "@sting8k/pi-vcc/src/core/summarize";
> 2 │ import { supervisorCheckIn, type SupervisorReviewReason } from "./prompts.js";
│ ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
3 │
4 │ export interface SessionBlock {
i Safe fix: Organize imports and exports (Biome)
1 1 │ import { compile } from "@sting8k/pi-vcc/src/core/summarize";
2 │ - import·{·supervisorCheckIn,·type·SupervisorReviewReason·}·from·"./prompts.js";
2 │ + import·{·type·SupervisorReviewReason,·supervisorCheckIn·}·from·"./prompts.js";
3 3 │
4 4 │ export interface SessionBlock {
test/worker-view.test.ts:2:1 assist/source/organizeImports FIXABLE ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
× Sort the imported names.
1 │ import { expect, it } from "vitest";
> 2 │ import { supervisorPeriodicReview, supervisorPlanChangeReview, supervisorReadyReview, type SupervisorReviewReason, supervisorStartedReview, supervisorStoppedReview } from "../src/prompts.js";
│ ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
3 │ import { workerView } from "../src/worker-view.js";
4 │
i Safe fix: Organize imports and exports (Biome)
1 1 │ import { expect, it } from "vitest";
2 │ - import·{·supervisorPeriodicReview,·supervisorPlanChangeReview,·supervisorReadyReview,·type·SupervisorReviewReason,·supervisorStartedReview,·supervisorStoppedReview·}·from·"../src/prompts.js";
2 │ + import·{·type·SupervisorReviewReason,·supervisorPeriodicReview,·supervisorPlanChangeReview,·supervisorReadyReview,·supervisorStartedReview,·supervisorStoppedReview·}·from·"../src/prompts.js";
3 3 │ import { workerView } from "../src/worker-view.js";
4 4 │
Checked 36 files in 63ms. No fixes applied.
Found 2 errors.
check ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
× Some errors were emitted while running checks.
@@ -1,49 +0,0 @@
# Supervisor prompt flow review
Pi/OpenAI implementation, based on `a7385d4`. Scope: centralize supervisor instructions in `src/prompts.ts` and make check-in tasks and tool descriptions ask for judgment followed by useful action. No transport, lifecycle, approval-gate, plan-selection, or planning-policy changes.
## Narrative order and wiring
1. Existing planning and worker resync prompts, unchanged.
2. `supervisorOpening`, `supervisorPrompt`, `supervisorReviewContext`, `supervisorOrientation`, `supervisorCompaction`: role and plan context. The user-authored agency opening and constitution/pi-supervisor provenance are retained. Long role asks for applicable AGENTS.md/skills, remains generic, removes one duplicate autonomy paragraph, and makes SteerWorker—not a recap—the continuation action. The short review and startup/compaction cadence are unchanged.
3. `supervisorCheckIn`: ready, started, active periodic, stopped/settled, plan-edit tasks. `src/worker-view.ts` invokes it outside truncatable activity content. Status prefixes remain exactly `The worker is ready to begin.`, `The worker is still working.`, and `The worker stopped.`. Observed idleness still governs the prefix; an idle interval gets stopped guidance, while a nominal settled event that is not idle gets active-work guidance.
4. `supervisorPlanReview`: existing diff/claim data plus plan-change guidance, wired from `src/index.ts`. The guidance now precedes truncatable diff detail so long diffs do not evict it.
5. SteerWorker description, parameter description and delivery result.
6. ApproveGoal description, parameter descriptions and approval-success instruction. Acceptance is conditional on the supervisor judging the result achieved; mechanics are a separate paragraph. Gate errors stay at their checks, unchanged. The successful result tells the supervisor to use SteerWorker for CompleteGoal and continue remaining goals.
7. Existing worker CompleteGoal description corrected to address its caller: the worker runs verification and seeks supervisor review first; the tool consumes recorded approval. It no longer tells the worker to "direct the worker" or implies the read-only supervisor can create evidence. Approval gates are unchanged.
Runtime data labels and view serialization remain near their producers, rather than turning this into a string registry. The dynamic mechanical errors remain in supervisor-session.ts as allowed by the task.
## Exact event tasks
Ready:
> Check the agreed outcome and decide the next useful action. Use SteerWorker to send the worker a concrete starting instruction; do not repeat one already being acted on.
Started:
> The worker has begun a turn. Check whether its direction fits the agreed goal; let productive work continue and use SteerWorker only if a correction is needed.
Active periodic:
> Is the worker on track toward the user's intended outcome? Check for drift, mistaken assumptions, or wasted effort. Use SteerWorker to send a correction where useful; otherwise let productive work continue without interruption.
Stopped/settled:
> Inspect the results and judge whether the agreed goal is actually achieved. If unfinished, investigate why the worker stopped and use SteerWorker to send the next useful instruction and resume work. If a verified dependency prevents progress, establish what will resume it and how that will be observed. Do not treat stopping as completion. Consider ApproveGoal only after the results satisfy the goal.
Plan edit/manual tick:
> Assess plan changes against the user's intent and preferences. Manual checkbox edits are claims, not proof of completion. Inspect the actual result before accepting a claim; use SteerWorker to send corrections when the plan or work has drifted. Preserve authorized changes.
ApproveGoal decision paragraph:
> Use only after judging that the actual result satisfies the user's intended outcome and the goal's discriminator. This tool records your acceptance; its mechanical checks cannot establish success. If the goal is unmet or evidence is insufficient, do not approve: use SteerWorker to request the next useful work or check.
## Validation and limits
- Read AGENTS.md, annoy-less skill and installed Pi extension docs: before_agent_start persistent custom messages/chained system prompt, and sendUserMessage behavior (an idle worker starts a turn; an active worker receives queued steering).
- `validation.txt`: 108 tests pass in 19 files, including real installed Pi RPC and native fork/Intercom checks; typecheck, lint, build and diff check pass.
- `initial-validation.txt`: same tests/typecheck passed, lint found only two import-order issues. Fixed those and reran the full command successfully.
- Added 9 worker-view event/status combinations and 3 prompt-semantic tests. Updated flow tests assert manual ticks and external plan edits carry judgment/continuation instructions. Supervisor hook/tool tests verify centralized text is wired, including startup/compaction and approval success.
- Native pair fixture now produces its view through the actual workerView. The real Pi provider request is asserted to contain the stopped task and actual registered SteerWorker/ApproveGoal descriptions, and its emitted instruction reaches the worker exactly. The local model is deterministic: this establishes wiring, not judgment quality.
- Approval logic/transport/plan extraction are unchanged. `git diff --quiet HEAD -- src/approval.ts src/intercom.ts src/plan-view.ts src/plan.ts` passed before commit. Unicode envelope budget regression still passes with the added event tasks.
- No user or test Herdr panes operated. No push. Unrelated dirty native logs were not changed; docs/human_journal.md was never read or written. Tests unset inherited PI_GOALS_EVIDENCE_DIR, PI_SUBAGENT_CHILD and PI_GOALS_ROLE.
## Parent acceptance still required
In a new isolated Herdr task, require an exact result (for example a specific byte sequence). Let the worker stop with a real artifact that fails that goal. Read both panes and the artifact: the supervisor must identify the mismatch, send a corrective SteerWorker instruction rather than approve, observe the resumed worker, and only approve after the corrected result satisfies the discriminator. Also confirm productive active work is left alone and an authorized plan edit is not mechanically rejected. Do not count deterministic test output or delivery receipts as autonomous outcome success. Independent reviewer gate remains parent-owned.
@@ -1,26 +0,0 @@
> @wassname2/pi-goals@0.2.2 test
> vitest run
RUN v4.1.9 /home/code/.pi/agent/git/github.com/wassname/pi-goals
Test Files 19 passed (19)
Tests 108 passed (108)
Start at 10:48:47
Duration 3.88s (transform 4.98s, setup 0ms, import 9.43s, tests 8.78s, environment 2ms)
> @wassname2/pi-goals@0.2.2 typecheck
> tsc --noEmit
> @wassname2/pi-goals@0.2.2 lint
> biome check src/ test/
Checked 36 files in 37ms. No fixes applied.
> @wassname2/pi-goals@0.2.2 build
> tsc
-56
View File
@@ -1,56 +0,0 @@
// Read-only replay of recorded research branches. Run from the pi-goals root after npm run build.
import assert from "node:assert/strict";
import { execFileSync } from "node:child_process";
import { createHash } from "node:crypto";
import { readFileSync, writeFileSync } from "node:fs";
import { createRequire } from "node:module";
import { resolve } from "node:path";
import ts from "typescript";
const output = "slop/reviews/vcc-view";
const root = "/home/code/.pi/agent/sessions/--workspace-2026-mfv-manifold-steer--/";
const workerPath = `${root}2026-09-08T10-41-19-145Z_01a0809b-a528-7724-a514-59f3c61116a6.jsonl`;
const supervisorPath = `${root}2026-09-08T22-43-35-654Z_01a08330-e866-7004-9b7f-5efdceb2488e.jsonl`;
const load = path => readFileSync(path, "utf8").trim().split("\n").map(line => JSON.parse(line));
const entries = load(workerPath);
const byId = new Map(entries.map(entry => [entry.id, entry]));
const records = load(supervisorPath);
const oldSource = execFileSync("git", ["show", "8953dce:src/worker-view.ts"], { encoding: "utf8" });
const oldCode = ts.transpileModule(oldSource, { compilerOptions: { module: ts.ModuleKind.ES2022 } }).outputText;
const { workerView: oldView } = await import(`data:text/javascript;base64,${Buffer.from(oldCode).toString("base64")}`);
const piRequire = createRequire(import.meta.resolve("@earendil-works/pi-coding-agent"));
const { createJiti } = piRequire("jiti");
const jiti = createJiti(import.meta.url, { moduleCache: false, fsCache: false });
const { workerView: newView } = await jiti.import(resolve("src/worker-view.ts"));
const { workerView: builtView } = await jiti.import(resolve("dist/worker-view.js"));
const results = [];
for (const [name, through] of [["pilot-preparation", "3cb9b26f"], ["flow-implementation", "69943231"], ["settled-checkpoint", "e266d41e"]]) {
const record = records.find(entry => entry.customType === "pi-goals-intercom" && entry.data.message.kind === "view" && entry.data.message.through === through);
assert(record, `recorded view ${through}`);
const message = record.data.message;
const branch = [];
for (let entry = byId.get(through); entry; entry = byId.get(entry.parentId)) branch.unshift(entry);
assert(branch.length, "nonempty live branch");
const ack = branch.filter(entry => entry.customType === "pi-goals-intercom" && entry.data.direction === "ack" && entry.data.message.through).at(-1);
const context = {
sourceSession: workerPath,
model: message.text.match(/^worker model: (.*)$/m)[1],
latestDirection: message.text.match(/latest human direction:\n([\s\S]*?)\ntool calls with no result:/)[1],
background: message.text.match(/^tracked background work: (.*)$/m)[1],
since: ack?.data.message.through,
};
const args = [branch, message.reason, message.text.startsWith("The worker stopped."), context];
const before = oldView(...args);
const after = newView(...args);
assert.equal(builtView(...args), after, "built/source real compiler parity");
const envelope = { binding: message.binding, role: "worker", kind: "view", id: message.id, text: after, reason: message.reason, through, backgroundQuiet: message.backgroundQuiet };
assert(Buffer.byteLength(JSON.stringify(envelope)) < 16_000, "serialized transport bound");
// Normalize only the saved files' trailing blank lines; byte metrics use the exact rendered strings.
writeFileSync(`${output}/${name}-old.md`, before.trimEnd() + "\n");
writeFileSync(`${output}/${name}-vcc.md`, after.trimEnd() + "\n");
results.push({ name, timestamp: record.timestamp, through, since: context.since, branchEntries: branch.length, branchSha256: createHash("sha256").update(JSON.stringify(branch)).digest("hex"), oldBytes: Buffer.byteLength(before), vccBytes: Buffer.byteLength(after), oldSerializedTextBytes: Buffer.byteLength(JSON.stringify(before)), vccSerializedTextBytes: Buffer.byteLength(JSON.stringify(after)), envelopeBytes: Buffer.byteLength(JSON.stringify(envelope)) });
}
const manifest = { baseline: "8953dce", workerPath, supervisorPath, compiler: "@sting8k/pi-vcc@0.5.0", results };
writeFileSync(`${output}/comparison.json`, JSON.stringify(manifest, null, 2) + "\n");
console.log(JSON.stringify(manifest, null, 2));
console.log("PASS: three identical historical branch/ack windows, serialized bounds, source and built compiler execution agree.");
-46
View File
@@ -1,46 +0,0 @@
{
"baseline": "8953dce",
"workerPath": "/home/code/.pi/agent/sessions/--workspace-2026-mfv-manifold-steer--/2026-09-08T10-41-19-145Z_01a0809b-a528-7724-a514-59f3c61116a6.jsonl",
"supervisorPath": "/home/code/.pi/agent/sessions/--workspace-2026-mfv-manifold-steer--/2026-09-08T22-43-35-654Z_01a08330-e866-7004-9b7f-5efdceb2488e.jsonl",
"compiler": "@sting8k/pi-vcc@0.5.0",
"results": [
{
"name": "pilot-preparation",
"timestamp": "2026-09-08T22:59:31.347Z",
"through": "3cb9b26f",
"branchEntries": 597,
"branchSha256": "f0da668db6266780aa3ba803e5260d4009732c74ab3276f4db55910b8d74af5a",
"oldBytes": 4961,
"vccBytes": 5356,
"oldSerializedTextBytes": 5324,
"vccSerializedTextBytes": 5462,
"envelopeBytes": 5655
},
{
"name": "flow-implementation",
"timestamp": "2026-09-08T23:17:08.542Z",
"through": "69943231",
"since": "54648ab4",
"branchEntries": 715,
"branchSha256": "2293e2e7158c051c3571cd50befb14900cea39314640421a5735633775af427b",
"oldBytes": 4897,
"vccBytes": 2396,
"oldSerializedTextBytes": 5109,
"vccSerializedTextBytes": 2452,
"envelopeBytes": 2646
},
{
"name": "settled-checkpoint",
"timestamp": "2026-09-09T00:11:07.924Z",
"through": "e266d41e",
"since": "18c6af89",
"branchEntries": 981,
"branchSha256": "3460caf8d1a093309ad2639decbc181151f27871c42ffa62ca98803aae726ce7",
"oldBytes": 1676,
"vccBytes": 1840,
"oldSerializedTextBytes": 1721,
"vccSerializedTextBytes": 1882,
"envelopeBytes": 2078
}
]
}
@@ -1,67 +0,0 @@
The worker is still working.
review trigger: turns
source session: /home/code/.pi/agent/sessions/--workspace-2026-mfv-manifold-steer--/2026-09-08T10-41-19-145Z_01a0809b-a528-7724-a514-59f3c61116a6.jsonl
worker model: openai-codex/gpt-6-astra
latest human direction:
but also try the flow healing one as a next goal on the list
tool calls with no result: none
tracked background work: processes: 1 (e55-fine-job802-follower); subagents: 0; unregistered detached work is not tracked
new worker transcript since the last acknowledged view:
[truncated; inspect source session]
: answer_reached={} reason={} E={:.3f}", setting.name, task.name, r["scorable"], r["reason"], r["E"])
if setting.method == "base":
if r["scorable"]:
base_scorable.add(task.name)
if task.name in {"s_add", "l_moral_lie"}:
ref_ids = ids[:, :n_prompt + cfg.kl_tokens]
base_logp = model(ref_ids, use_cache=False).logits[:, n_prompt - 1:-1].float().log_softmax(-1)
references.append((ref_ids, n_prompt - 1, base_logp))
report = evaluate_with_vector(model, tok, vignettes=vignettes, max_think_tokens=cfg.think_tokens,
batch_size=2, log_demo=False, verbose=0)
kl = shared_prefix_kl(model, references)
if setting.method == "logit_diff":
dump(outdir / f"{setting.name}_adapter.json", stats)
dump(outdir / f"{setting.name}_behavior.json", report["per_row"])
if setting.method == "base":
base_report = report
delta = dclr_per_foundation(base_report, report)
care, auth = delta["Care"]["mean"], delta["Authority"]["mean"]
other = [delta[f]["mean"] for f in FOUNDATION_ORDER if f not in {"Care", "Authority"}]
off = sum(abs(x) for x in other) / len(other)
scorable = [r for r in generated if r["scorable"]]
subset = [r for r in generated if r["task"] in base_scorable]
direction = random_v if setting.random_direction else v0
along = setting.c * float(direction @ v0)
point = dict(name=setting.name, method=setting.method, internal_c=setting.c,
logit_alpha=setting.alpha if setting.method == "logit_diff" else 1.0,
frac_scorable=len(scorable) / len(tasks), n_base_scorable=len(subset),
frac_on_base_scorable=sum(r["scorable"] for r in subset) / len(subset) if subset else float("nan"),
mean_nonforced_E=sum(r["E"] for r in generated) / len(tasks),
care=care, auth=auth, dlog_on_target=-auth, dlog_off_target=off,
net_behavior_nats=care - auth, score=float("nan"),
pmass_coherence=report["mean_pmass_allowed"], base_pmass=base_report["mean_pmass_allowed"],
pmass_floor=0.99 * base_report["mean_pmass_allowed"],
passes_pmass=report["mean_pmass_allowed"] >= 0.99 * base_report["mean_pmass_allowed"],
steering_strength_v0=along, total_strength=setting.c,
off_axis_strength=setting.c * float((direction - (direction @ v0) * v0).norm()),
shared_prefix_kl_nats=kl, behavior_pairs=delta["Authority"]["n"],
behavior_pairs_total=delta["Authority"]["n_total"], elapsed_s=time.monotonic() - stage_start)
points.append(point)
pl.DataFrame([{k: v for k, v in r.items() if k not in {"completion", "prefix", "generated_ids"}} for r in records]).write_csv(outdir / "tasks.csv")
pl.DataFrame([{"name": r["name"], "prompt": r["task"], "task": r["task"],
"scenario": choice_metadata[r["task"]]["scenario"] if r["task"] in choice_metadata else None,
"rating_1_to_5": None, "coherent": None, "passes_demo_gate": None,
"premise_preserved": None, "post_answer_repetition": None, "evidence_quote": None,
"care_choice_verified": None, "failure_reason": "pending_manual"} for r in records]).write_csv(outdir / "demo_audit.tsv", separator="\t")
table = write_report(outdir, points, records, cfg)
logger.info("{}: {:.1f}s, ΔCare={:+.3f}, ΔAuth={:+.3f}, KL={:.4f}", setting.name, point["elapsed_s"], care, auth, kl)
assert {(r["name"], r["task"]) for r in records} == {(s.name, t.name) for s in settings for t in tasks}
assert len(records) == len(settings) * len(tasks), "duplicate or missing generation"
logger.info("SHOULD every treatment/prompt cell retained: {} records PASS", len(records))
logger.info("RESULT_DEMO: NO_RESULT (pending manual audit)\n{}\nreport={}\nelapsed_s={:.1f}", table, outdir / "report.md", time.monotonic() - start)
if __name__ == "__main__":
main(tyro.cli(Cfg))
@@ -1,39 +0,0 @@
The worker is still working.
review trigger: turns
source session: /home/code/.pi/agent/sessions/--workspace-2026-mfv-manifold-steer--/2026-09-08T10-41-19-145Z_01a0809b-a528-7724-a514-59f3c61116a6.jsonl
worker model: openai-codex/gpt-6-astra
latest human direction:
but also try the flow healing one as a next goal on the list
tool calls with no result: none
tracked background work: processes: 1 (e55-fine-job802-follower); subagents: 0; unregistered detached work is not tracked
new worker overview since the last acknowledged view (VCC algorithmic compression; local # refs index new messages; tool-result bodies omitted; inspect source for evidence):
[Files And Changes]
- Modified: experiments/e56_flow_repair/flow.py, experiments/e56_flow_repair/test_flow.py,
slop/reviews/e56_flow_matching_source.md, slop/reviews/e56_flow_discussion_brief.md,
experiments/e56_flow_repair/intervention.py, src/manifold_steer/autoencoder.py
- Read: slop/reviews/2026-09-09_glm-5.3-flash_e56_flow_scientist.md,
/workspace/2026/lite/steering-lite/src/steering_lite/variants/mean_diff.py,
slop/audits/steering_tradeoff/flow_synthetic.log, slop/reviews/2026-09-09_deepseek-v4-pro-0813_e56_flow_scientist.md,
/home/code/.pi/agent/skills/arxiv/SKILL.md, /workspace/2026/lite/steering-lite/src/steering_lite/config.py,
experiments/e55_logit_diff_amplification/logit_diff.py, /workspace/2026/lite/steering-lite/src/steering_lite/vector.py
, slop/reviews/2026-09-09_deepseek-v4-pro-0813_e56_flow_discussion.md,
slop/reviews/2026-09-09_glm-5.3-flash_e56_flow_discussion.md
[assistant]
* (15 earlier tool-call entries omitted)
* read "experiments/e55_logit_diff_amplification/logit_diff.py" (#30)
* read "/workspace/2026/lite/steering-lite/src/steering_lite/vector.py" (#30)
* write "experiments/e56_flow_repair/intervention.py" (#34)
* edit "experiments/e56_flow_repair/test_flow.py" (#36)
* read "slop/reviews/2026-09-09_deepseek-v4-pro-0813_e56_flow_discussion.md" (#38)
* read "slop/reviews/2026-09-09_glm-5.3-flash_e56_flow_discussion.md" (#40)
* edit "src/manifold_steer/autoencoder.py" (#42, #44, #46) x3
(thinking) Thinking: **Preparing evaluation configuration**
**Refactoring evaluation context** (#48)
(thinking) Thinking: **Preparing token geometry logging**
**Implementing token geometry logging** (#48)
* bash "sed -n '255,370p' experiments/e55_logit_diff_amplification/run.py" (#48)
-20
View File
@@ -1,20 +0,0 @@
# VCC functional acceptance
Pi/OpenAI observed the isolated interactive worker in Herdr pane `w8:p54`, task repo `/tmp/pi-goals-vcc-functional-task`, using source commit `039f4a4`. Parent submitted the trivial exact-byte goal and selected Ready. The pair then completed without parent task execution or steering.
Observed rendered output:
> [supervisor] Supervisor approval is recorded. Call CompleteGoal for Deliver the committed hello file with byte proof and completion approval now. Do not change any files or run further work.
> CompleteGoal
> Sign-off accepted. Goal ticked [x] in .pi/plan/01a083f1-296e-7594-8623-3e009c90a85d-v1.md.
Parent independently read artifact bytes with `od -An -tx1 hello.txt`:
```
48 65 6c 6c 6f 20 66 72 6f 6d 20 56 43 43 2e 0a
```
These encode `Hello from VCC.` plus one newline. Task commit: `a701105 Add verified VCC hello file`.
This establishes successful real planning/Ready/supervised completion with the VCC dependency loaded. It does not establish improved scientific judgment or cost savings. Replay comparisons are in `review.md`. The subsequent goal-repeat/reminder change was not loaded in this pair; its cadence, changed-checkbox and compaction behavior were checked separately in automated tests. Rejecting a valid artifact that fails a scientific goal remains a behavioral acceptance gap.
@@ -1,144 +0,0 @@
The worker is still working.
review trigger: turns
source session: /home/code/.pi/agent/sessions/--workspace-2026-mfv-manifold-steer--/2026-09-08T10-41-19-145Z_01a0809b-a528-7724-a514-59f3c61116a6.jsonl
worker model: openai-codex/gpt-6-astra
latest human direction:
but also try the flow healing one as a next goal on the list
tool calls with no result: none
tracked background work: processes: 0; subagents: 0; unregistered detached work is not tracked
compaction summary (worker account, not independent evidence):
[OpenAI native compaction checkpoint]
new worker transcript (initial or reset view):
[truncated; inspect source session]
"enqueued_at": "2026-09-08T13:38:57.301057325+08:00"
}
},
"priority": 0,
"label": "why: validate common L22-24 C2 on dog legs; resolve: correct clean controls and consistent transfer on plain questions",
"path": "/workspace/2026/suppressed-activations"
},
{
"id": 769,
"status": {
"Queued": {
"enqueued_at": "2026-09-08T13:38:57.518018760+08:00"
}
},
"priority": 0,
"label": "why: validate common L22-24 C2 on dog name; resolve: correct clean controls and consistent transfer on plain questions",
"path": "/workspace/2026/suppressed-activations"
},
{
"id": 770,
"status": {
"Queued": {
"enqueued_at": "2026-09-08T13:38:57.740040876+08:00"
}
},
"priority": 0,
"label": "why: validate common L22-24 C2 on dog property; resolve: correct clean controls and consistent transfer on plain questions",
"path": "/workspace/2026/suppressed-activations"
},
{
"id": 771,
"status": {
"Queued": {
"enqueued_at": "2026-09-08T13:38:57.987386109+08:00"
}
},
"priority": 0,
"label": "why: validate common L22-24 C2 on ant legs; resolve: correct clean controls and consistent transfer on plain questions",
"path": "/workspace/2026/suppressed-activations"
},
{
"id": 772,
"status": {
"Queued": {
"enqueued_at": "2026-09-08T13:38:58.231236887+08:00"
}
},
"priority": 0,
"label": "why: validate common L22-24 C2 on ant name; resolve: correct clean controls and consistent transfer on plain questions",
"path": "/workspace/2026/suppressed-activations"
},
{
"id": 773,
"status": {
"Queued": {
"enqueued_at": "2026-09-08T13:38:58.435527993+08:00"
}
},
"priority": 0,
"label": "why: validate common L22-24 C2 on ant property; resolve: correct clean controls and consistent transfer on plain questions",
"path": "/workspace/2026/suppressed-activations"
},
{
"id": 775,
"status": {
"Queued": {
"enqueued_at": "2026-09-08T13:41:03.538541658+08:00"
}
},
"priority": 0,
"label": "why: selected dog band may just cause generic changes; resolve: eight random spans matched per-token edit magnitude",
"path": "/workspace/2026/suppressed-activations"
},
{
"id": 776,
"status": {
"Queued": {
"enqueued_at": "2026-09-08T13:41:04.114346905+08:00"
}
},
"priority": 0,
"label": "why: selected ant band may just cause generic changes; resolve: eight random spans matched per-token edit magnitude",
"path": "/workspace/2026/suppressed-activations"
},
{
"id": 778,
"status": {
"Queued": {
"enqueued_at": "2026-09-08T15:16:24.724372591+08:00"
}
},
"priority": 0,
"label": "why: dog clean controls may fail from assistant-prefilled questions; resolve: user-role and generation-boundary repair must give correct clean answers before assessing fixed L22-24 C2 transfer",
"path": "/workspace/2026/suppressed-activations"
},
{
"id": 779,
"status": {
"Queued": {
"enqueued_at": "2026-09-08T15:16:24.923827832+08:00"
}
},
"priority": 0,
"label": "why: ant clean controls may fail from assistant-prefilled questions; resolve: user-role and generation-boundary repair must give correct clean answers before assessing fixed L22-24 C2 transfer",
"path": "/workspace/2026/suppressed-activations"
},
{
"id": 801,
"status": {
"Running": {
"enqueued_at": "2026-09-09T06:50:35.856041965+08:00",
"start": "2026-09-09T06:50:48.080797309+08:00"
}
},
"priority": 0,
"label": "why: larger paired MLP reader/writer needs a fitting check; resolve: batch-eight memory and complete local readouts before held-out training; args --steps 4 --eval-every 2",
"path": "/workspace/2026/LUCID3_wikit"
}
]
}
tool: edit
Successfully replaced 3 block(s) in experiments/e55_logit_diff_amplification/run_fine_s43/run_card.md.
tool: bash
(no output)
@@ -1,82 +0,0 @@
The worker is still working.
review trigger: turns
source session: /home/code/.pi/agent/sessions/--workspace-2026-mfv-manifold-steer--/2026-09-08T10-41-19-145Z_01a0809b-a528-7724-a514-59f3c61116a6.jsonl
worker model: openai-codex/gpt-6-astra
latest human direction:
but also try the flow healing one as a next goal on the list
tool calls with no result: none
tracked background work: processes: 0; subagents: 0; unregistered detached work is not tracked
compaction summary (worker account, not independent evidence):
[OpenAI native compaction checkpoint]
new worker overview (initial or reset view) (VCC algorithmic compression; local # refs index new messages; tool-result bodies omitted; inspect source for evidence):
[Session Goal]
- was your job killed?
- [Scope change]
- maybe read it your self ml-debug
[Files And Changes]
- Modified: slop/audits/e55/job798_parent_read.md, /workspace/2026/mfv/manifold-steer/.pi/plan/01a0809b-a528-7724-a514-5
9f3c61116a6-v1.md, experiments/e55_logit_diff_amplification/LAB.md, experiments/ACTIVE.md,
experiments/e55_logit_diff_amplification/choice_tasks.py, experiments/e55_logit_diff_amplification/run.py,
experiments/e55_logit_diff_amplification/choice_summary.py,
experiments/e55_logit_diff_amplification/test_choice_summary.py, justfile,
experiments/e55_logit_diff_amplification/run_fine_s43/run_card.md (+2 more)
- Read: experiments/e55_logit_diff_amplification/LAB.md, /home/code/.pi/agent/skills/ml-debug/SKILL.md,
experiments/e55_logit_diff_amplification/run_s43/run.log, experiments/e55_logit_diff_amplification/run_s43/run_card.md
, /home/code/.pi/agent/skills/plan-format/SKILL.md, experiments/e55_logit_diff_amplification/run.py,
/home/code/.pi/agent/skills/pueue/SKILL.md, /home/code/.pi/agent/skills/machine-map/SKILL.md,
/home/code/.pi/agent/skills/ponytailplus/SKILL.md, /workspace/2026/lite/steering-lite/src/steering_lite/eval/tinymfv.p
y (+11 more)
[Commits]
- dff95a9: Record E55 independent demo audit and parent caveats
[User Preferences]
- Style: Make it easy for a busy and forgetfull user to review. Use ASD-STE100 Simplified Technical English. Use active
voice, one idea per sentence, common words,
[truncated; inspect source session]
te the stale E55 LAB/ACTIVE claims ('Not run'/'queued798') from existing evidence.
Then implement and run the smallest finer-dose comparison resolving matched achieved behavior versus coherence, with a
reviewed run card and saved just smoke output before queueing on the existing default group. Specify behavior
measurement and uncertainty before collecting new results: forced 32-token CLR and answer-span E alone cannot establish
the tradeoff; retain full 512-token generations, premise/repetition audits and missing completions rather than selecting
survivors. Compare only overlapping measured effects and keep confirmation prompts separate. Diagnose unexpected results
with ml-debug. Goal2 is authorized next: inspect existing AE repair and prepare independent-reviewed corruption-to-clean
flow pseudocode during safe CPU work if goal1 is queued; no sign-off dependency forbids that preparation. Deliver the
single linked report with both plots, full demos, independent reviews and saved verification/job receipts. Continue
autonomously within scope; no approval claim until real evidence is ready.
[assistant]
* (40 earlier tool-call entries omitted)
* edit "experiments/e55_logit_diff_amplification/run.py" (#161, #163) x2
* process (#165)
* bash "cp /home/code/.pi/agent/sessions/--workspace-2026-mfv-manifold-steer--/subagent-artifacts/outputs/7a33c86b-5383-
4752-8ecb-d5912c2583bd/slop/reviews/tradeoff_measurement.md slop/reviews/tradeoff_prequeue.md; cp
/home/code/.pi/agent/sessio..." (#167)
The review found an important measurement issue: moralmaps deliberately prevents `</think>` and EOS during its probe.
Its `emitted_close=0` therefore was not evidence of natural nontermination.
The follow-up keeps that probe diagnostic only. It adds freely generated care-versus-authority choices, finer doses,
paired option orders, and explicit uncertainty for missing answers. Im fixing the reviews parser and analysis issues
before queueing.
Flow preparation also confirms a distinct test: the previous online AE used one learned map; flow repair would integrate
a time-conditioned recovery field. (#169)
* edit ".pi/plan/01a0809b-a528-7724-a514-59f3c61116a6-v1.md" (#169)
* bash "grep -E 'Ran |OK|PASS|elapsed_s=' slop/audits/steering_tradeoff/reviewed_smoke.log; cat
slop/audits/steering_tradeoff/saved_vector_check.log; git diff --check; pueue add --help | head -65; pueue status
--json | jq '[.tasks[] | select(.gr..." (#171)
* bash "pueue status --json | jq '{groups:.groups,tasks:[.tasks[] | select(.group=="default" and (.status.Done == null))
| {id,status,priority,label,path}]}'" (#173)
(thinking) Thinking: **Refining run-card wording** (#175)
* edit "experiments/e55_logit_diff_amplification/run_fine_s43/run_card.md" (#175)
(thinking) Thinking: **Checking saved-vector comment**
**Extracting old-run report blocks** (#177)
* bash "UV_NO_SYNC=1 uv run python -c 'from pathlib import Path;
p=Path("experiments/e55_logit_diff_amplification/LAB.md"); report=Path("experiments/e55_logit_diff_amplification/run_s
43/report.md").read_text(); blocks=report.split("\n## ")[1:]; ..." (#177)
-7
View File
@@ -1,7 +0,0 @@
# VCC worker-view change / UAT plan
Goal: improve supervisor judgment per context token by replacing raw transcript-tail extraction with the existing deterministic VCC compiler. Keep acknowledged-entry slicing, plan changes, tracked background work, and missing tool results. Preserve two recent thinking tails next to their actions. No transport or supervision lifecycle redesign.
Acceptance: pin and inspect the compiler dependency; test new-turn slicing, compaction/rewind resets, thinking/action ordering, tool arguments, extracted files/context, output omission notices and serialized byte bounds. Run full tests, typecheck, lint and build. Render old and new views from identical recorded maniworker windows, saving reproducible comparison and honest information-loss notes. The parent must perform real isolated Herdr acceptance after this handoff; no research pane interaction here.
Baseline: HEAD 8953dce, src/worker-view.ts 69 lines. Pre-existing dirty native worker/supervisor event logs and untracked docs/human_journal.md are outside scope and remain untouched/unstaged. No dependency lifecycle scripts will run.
-62
View File
@@ -1,62 +0,0 @@
# VCC worker overview: implementation and replay review
## Decision and scope
Use the deterministic compiler from `@sting8k/pi-vcc@0.5.0` inside the existing worker view. No model call, copied compiler, transport/lifecycle change, new monitoring framework, or change to approval rules. Keep acknowledged-entry boundaries, compaction reset, missing-result matching, plan diff/status claims and existing managed process/subagent tracking. Add context percentage from `ctx.getContextUsage().percent`; unknown remains omitted.
`src/worker-view.ts`: **69 -> 100 lines (+31)**. Compiler declaration: **10 lines**. Caller: **+1 line**. Not fewer lines than the previous raw-tail implementation, but much smaller than transplanting the 302-line pi-supervise view plus its lifecycle. VCC itself remains an external dependency, not free code complexity.
## Dependency provenance and security
- Inspected `../pi-supervise/src/view.ts`, package manifest/lock, installed compiler and normalization/brief/extractor path. Custom last-two-thinking support is in pi-supervise's adapter, not a patched installed VCC package.
- Downloaded exact registry tarball using `npm pack @sting8k/pi-vcc@0.5.0 --ignore-scripts --pack-destination /tmp/pi-goals-vcc-package --json`.
- `diff -qr /tmp/pi-goals-vcc-package/package ../pi-supervise/node_modules/@sting8k/pi-vcc` produced no differences. This includes all installed package files, not just version strings.
- Pinned exact `0.5.0` in dependencies and lockfile. Registry: `https://registry.npmjs.org/@sting8k/pi-vcc/-/pi-vcc-0.5.0.tgz`; SHA512 integrity: `KJbOVUFbyghn6h+RD9bDXFNWkKNqpxaCpPQWceOuxMPe9ySpbEfaYnqO9CZUiCP3AFmQ5Ghnsg2B8pdKgY+0Hg==`.
- Tarball SHA1: `090e5c7cacec00b1083bf423bc08aa2d3eb9cb3a`; size 16,206,703 bytes compressed, 16,712,402 unpacked. It ships more than just the compiler. Added one package; no new transitive packages beyond already installed peers.
- Read cybersec-situational-awareness skill before fetching/installing. Used `npm install --save-exact @sting8k/pi-vcc@0.5.0 --ignore-scripts --no-audit --no-fund`. No lifecycle scripts run. Mise is installed but has no configured/installed Node version; used current project Node v22.23.2/npm rather than install another toolchain. This was not a sandboxed install.
- Runtime imports only compiler source, not the VCC extension entrypoint. The compiler pipeline is algorithmic: no network, shell, or model call.
- Local upstream clone is newer (09c4a74, 0.6.0 work); deliberately did not switch versions. This reproduces the installed reference dependency.
### Source-only package type boundary
Direct tsc traversal exposed three upstream 0.5.0 errors: `brief.ts:61,77` passes Intl SegmentData with optional `isWordLike` to a required-boolean shape, and `normalize.ts:21` compares Pi Message role with `bashExecution`, outside that union. Supervisor approved a narrow declaration for the exact compile input/output, with tsconfig path mapping just as this repo handles pi-intercom. No runtime fallback or node_modules patch. Source and built JS imports execute the real compiler in replay; tests likewise execute the real package. This declaration must be reviewed if the pinned compiler version changes.
## Replay method and result
`node slop/reviews/vcc-view/compare.mjs` loads the actual maniworker branch terminating at each recorded manisuper view's `through` ID, follows parent links (not dead branches), and recovers its last acknowledged view boundary. Both renderers receive identical entries, context, trigger and idle state. Old renderer comes from HEAD 8953dce; new source and built renderer outputs must agree. Paths, timestamps, IDs and branch SHA256 hashes are in `comparison.json`. No sessions were messaged, reloaded or edited. The source sessions remain local prerequisites to reproduce the replay; saved rendered views are reviewable without them.
| Recorded window | Old UTF-8 bytes | VCC UTF-8 bytes | Observation |
|---|---:|---:|---|
| Pilot preparation, 22:59:31 | 4,961 | 5,356 | Slightly larger, much better task signal |
| Flow implementation, 23:17:08 | 4,897 | 2,396 | About half the bytes; restores action context |
| Settled checkpoint, 00:11:07 | 1,676 | 1,840 | Slightly larger; direct test output lost |
These are bytes, **not measured token counts or realized supervisor cost savings**. Each complete serialized transport envelope is below 16KB (largest 5,655 bytes). The raw transcript and VCC brief keep the same total 5.5KB serialized content allowance; VCC splits extracted headers (1.5KB) from newest brief (4KB) when headers exist, so one cannot evict the other.
### What improves
- Pilot old view is dominated by unrelated queue-job JSON. VCC retains the decision that moralmaps deliberately suppresses think closure/EOS, so `emitted_close=0` is not evidence of natural nontermination; the narrower choice pilot/uncertainty approach; edited files/commit; recent thinking about run-card wording and saved-vector checks; actual shell commands rather than `tool: bash`.
- Flow old view is almost entirely a raw Python source tail with no useful explanation of the current action. VCC gives changed file paths, reviewed source paths, edit/read/bash arguments and the two recent thinking tails about evaluation configuration and token geometry. Existing E55 follower tracking remains unchanged.
- Checkpoint retains the claim `Test passed. Committed as c41e0f2`, extracted commit title, changed files, verification-log path, and thinking about byte identity/rubric migration. The old view had no tool arguments or thinking.
### Honest limits / evidence lost
- The checkpoint's actual `Ran 1 test ... OK` tool result is absent in VCC. Supervisor must read the retained log path before treating the worker's pass claim as evidence. The view explicitly says tool-result bodies are omitted and provides the source session path.
- VCC file lists/commits are extracted activity, not independent proof that a write or commit succeeded. Some file classifications are heuristic (`write` is reported as Modified). Full source/artifact inspection still matters.
- VCC's initial Session Goal extraction includes weak historical phrases such as `was your job killed?`, not the actual agreed research discriminator. It is an overview, not a replacement for the plan or latest human direction. Existing plan review remains separate.
- Generic `process` calls appear by name only in VCC's installed compiler; their detailed command/state is not reconstructed here. Existing live background summary still names tracked processes/subagents. Unregistered detached work remains untracked, as before.
- Older brief/tool entries can still be cut. Long paths/commands can wrap or truncate. Local `#` references index fresh messages, not session entry IDs; the label now explains this. The compiler's unavailable `vcc_recall` instruction is removed.
- Two recent thinking tails are limited to 400 characters before the compiler's own shortening; hidden/redacted thinking cannot be recovered. Large views may still cut earlier retained thinking.
- First/reset views can repeat older instructions. No new deduplication or lifecycle machinery was introduced in this scoped change.
## Validation
Final output: `validation.txt`. `npm test`: **94/94**, 18 files including RPC. Typecheck, lint, build and diff check pass. Six focused worker-view tests added to the previous three: thinking/action order and immutability; extracted paths/blockers/arguments with omitted output notices and metadata; partial pending calls across acknowledgements; rewind/compaction reset and unknown context; oversized headers/brief preserving newest activity; omitted-result versus empty-update distinction and commit extraction. Existing flow fixture supplies the new standard context-usage API.
During implementation, full tests caught a partial `edit` call with no arguments: the adapter now supplies an empty argument object for that incomplete call while preserving missing-result status. Two added assertions initially assumed VCC classified `write` as Created and could extract a commit from a result without its call; corrected tests to the inspected compiler semantics, not patched dependency behavior. Upstream type errors are isolated as described above. All final checks pass.
## Remaining acceptance
The replay supports a **better overview**, especially when raw output crowds out decisions, but not a claim that this produces better outcomes or lower total token cost. Parent-owned isolated real Herdr acceptance and independent reviewer gate remain required. Suggested UAT: trivial artifact and saved verification log; inspect the supervisor's new overview and actual artifact read; exercise a manual plan tick/edit and full ApproveGoal -> CompleteGoal sequence. Do not use the user's research panes.
No Herdr panes, GPU jobs, supervisor sessions, user research files, old native evidence logs or human journal were modified by this task. No push performed.
@@ -1,44 +0,0 @@
The worker stopped.
review trigger: settled
source session: /home/code/.pi/agent/sessions/--workspace-2026-mfv-manifold-steer--/2026-09-08T10-41-19-145Z_01a0809b-a528-7724-a514-59f3c61116a6.jsonl
worker model: openai-codex/gpt-6-astra
latest human direction:
but also try the flow healing one as a next goal on the list
tool calls with no result: none
tracked background work: processes: 2 (e55-fine-job802-follower, e56-recovery-job805-follower); subagents: 0; unregistered detached work is not tracked
new worker transcript since the last acknowledged view:
tool: edit
Successfully replaced 1 block(s) in experiments/e55_logit_diff_amplification/audit_choices.py.
tool: edit
Successfully replaced 1 block(s) in experiments/e55_logit_diff_amplification/test_audit_choices.py.
tool: process
Started process audit-rubric-template-test (proc_43e4) with pid 3380015.
Moved the unchanged rubric to [audit_instructions.md](experiments/e55_logit_diff_amplification/audit_instructions.md). The file-roundtrip test is running; queued code is untouched.
tool: read
test_prepare_and_summary_file_paths (experiments.e55_logit_diff_amplification.test_audit_choices.AuditTests.test_prepare_and_summary_file_paths) ... ok
----------------------------------------------------------------------
Ran 1 test in 0.018s
OK
tool: bash
[main c41e0f2] Move generated audit rubric out of Python source
4 files changed, 19 insertions(+), 12 deletions(-)
create mode 100644 experiments/e55_logit_diff_amplification/audit_instructions.md
create mode 100644 slop/audits/steering_tradeoff/audit_rubric_template_test.log
Test passed. Committed as `c41e0f2`; rubric wording is unchanged.
@@ -1,33 +0,0 @@
The worker stopped.
review trigger: settled
source session: /home/code/.pi/agent/sessions/--workspace-2026-mfv-manifold-steer--/2026-09-08T10-41-19-145Z_01a0809b-a528-7724-a514-59f3c61116a6.jsonl
worker model: openai-codex/gpt-6-astra
latest human direction:
but also try the flow healing one as a next goal on the list
tool calls with no result: none
tracked background work: processes: 2 (e55-fine-job802-follower, e56-recovery-job805-follower); subagents: 0; unregistered detached work is not tracked
new worker overview since the last acknowledged view (VCC algorithmic compression; local # refs index new messages; tool-result bodies omitted; inspect source for evidence):
[Files And Changes]
- Modified: experiments/e55_logit_diff_amplification/audit_choices.py,
experiments/e55_logit_diff_amplification/test_audit_choices.py
- Read: slop/audits/steering_tradeoff/audit_rubric_template_test.log
[Commits]
- c41e0f2: Move generated audit rubric out of Python source
[assistant]
* edit "experiments/e55_logit_diff_amplification/audit_choices.py" (#0)
* edit "experiments/e55_logit_diff_amplification/test_audit_choices.py" (#2)
* process (#4)
(thinking) Thinking: **Checking baseline byte identity**
**Testing the rubric migration** (#6)
Moved the unchanged rubric to [audit_instructions.md](experiments/e55_logit_diff_amplification/audit_instructions.md).
The file-roundtrip test is running; queued code is untouched. (#6)
* read "slop/audits/steering_tradeoff/audit_rubric_template_test.log" (#7)
* bash "git add experiments/e55_logit_diff_amplification/audit_choices.py
experiments/e55_logit_diff_amplification/audit_instructions.md
experiments/e55_logit_diff_amplification/test_audit_choices.py && git add -f slop/audits/steering_tradeoff/a..." (#9)
Test passed. Committed as `c41e0f2`; rubric wording is unchanged. (#11)
-73
View File
@@ -1,73 +0,0 @@
> @wassname2/pi-goals@0.2.2 test
> vitest run
RUN v4.1.9 /home/code/.pi/agent/git/github.com/wassname/pi-goals
Test Files 18 passed (18)
Tests 94 passed (94)
Start at 10:10:30
Duration 3.11s (transform 3.98s, setup 0ms, import 8.30s, tests 7.14s, environment 2ms)
> @wassname2/pi-goals@0.2.2 typecheck
> tsc --noEmit
> @wassname2/pi-goals@0.2.2 lint
> biome check src/ test/
Checked 34 files in 45ms. No fixes applied.
> @wassname2/pi-goals@0.2.2 build
> tsc
{
"baseline": "8953dce",
"workerPath": "/home/code/.pi/agent/sessions/--workspace-2026-mfv-manifold-steer--/2026-09-08T10-41-19-145Z_01a0809b-a528-7724-a514-59f3c61116a6.jsonl",
"supervisorPath": "/home/code/.pi/agent/sessions/--workspace-2026-mfv-manifold-steer--/2026-09-08T22-43-35-654Z_01a08330-e866-7004-9b7f-5efdceb2488e.jsonl",
"compiler": "@sting8k/pi-vcc@0.5.0",
"results": [
{
"name": "pilot-preparation",
"timestamp": "2026-09-08T22:59:31.347Z",
"through": "3cb9b26f",
"branchEntries": 597,
"branchSha256": "f0da668db6266780aa3ba803e5260d4009732c74ab3276f4db55910b8d74af5a",
"oldBytes": 4961,
"vccBytes": 5356,
"oldSerializedTextBytes": 5324,
"vccSerializedTextBytes": 5462,
"envelopeBytes": 5655
},
{
"name": "flow-implementation",
"timestamp": "2026-09-08T23:17:08.542Z",
"through": "69943231",
"since": "54648ab4",
"branchEntries": 715,
"branchSha256": "2293e2e7158c051c3571cd50befb14900cea39314640421a5735633775af427b",
"oldBytes": 4897,
"vccBytes": 2396,
"oldSerializedTextBytes": 5109,
"vccSerializedTextBytes": 2452,
"envelopeBytes": 2646
},
{
"name": "settled-checkpoint",
"timestamp": "2026-09-09T00:11:07.924Z",
"through": "e266d41e",
"since": "18c6af89",
"branchEntries": 981,
"branchSha256": "3460caf8d1a093309ad2639decbc181151f27871c42ffa62ca98803aae726ce7",
"oldBytes": 1676,
"vccBytes": 1840,
"oldSerializedTextBytes": 1721,
"vccSerializedTextBytes": 1882,
"envelopeBytes": 2078
}
]
}
PASS: three identical historical branch/ack windows, serialized bounds, source and built compiler execution agree.
-176
View File
@@ -1,176 +0,0 @@
import { execFileSync } from "node:child_process";
import { createHash } from "node:crypto";
import { closeSync, existsSync, lstatSync, mkdirSync, openSync, readFileSync, readlinkSync, readSync, renameSync, rmSync, type Stats, statSync, writeFileSync } from "node:fs";
import { dirname, join, relative, resolve } from "node:path";
import { foldPlan, GOAL_LINE } from "./plan.js";
export interface WorktreeSnapshot {
status: string;
indexHash: string;
files: Array<{ path: string; kind: "file" | "symlink" | "missing"; mode?: number; contentHash?: string }>;
}
export interface ApprovalRecord {
version: 3;
verdict: "accept";
approvalId: string;
goal: string;
planPath: string;
goalBlockHash: string;
repoRoot: string;
head: string;
tree: string;
cleanWorktree: boolean;
force?: { reason: string; worktree: WorktreeSnapshot };
inspected: { plan: true; repository: true; evidence: true; verifyOutput: true };
verifyOutputPath: string;
supervisor: { sessionId: string; runId: string | null };
timestamp: string;
}
function command(repoRoot: string, args: string[]): string {
return execFileSync("git", args, { cwd: repoRoot, encoding: "utf8" }).trim();
}
// Capture bytes, not status flags: an edited file can change again while Git still reports M or ??.
function worktreeSnapshot(repoRoot: string, status: string, pathspec: string[]): WorktreeSnapshot {
const index = execFileSync("git", ["ls-files", "--stage", "-z", "--", ...pathspec], { cwd: repoRoot });
const paths = status.split("\0").filter(Boolean).map(entry => entry.slice(3)).sort();
const files = paths.map((path): WorktreeSnapshot["files"][number] => {
const fullPath = join(repoRoot, path);
let stat: Stats;
try { stat = lstatSync(fullPath); }
catch (error) {
if (["ENOENT", "ENOTDIR"].includes((error as NodeJS.ErrnoException).code ?? "")) return { path, kind: "missing" };
throw error;
}
const mode = stat.mode & 0o777;
const hash = createHash("sha256");
if (stat.isSymbolicLink()) return { path, kind: "symlink", mode, contentHash: hash.update(readlinkSync(fullPath, { encoding: "buffer" })).digest("hex") };
if (!stat.isFile()) throw new Error(`Cannot fingerprint dirty path ${path}: only regular files and symlinks are supported.`);
const fd = openSync(fullPath, "r");
try {
const buffer = Buffer.alloc(256 * 1024);
for (;;) {
const bytes = readSync(fd, buffer, 0, buffer.length, null);
if (!bytes) break;
hash.update(buffer.subarray(0, bytes));
}
} finally { closeSync(fd); }
return { path, kind: "file", mode, contentHash: hash.digest("hex") };
});
return { status, indexHash: createHash("sha256").update(index).digest("hex"), files };
}
export function repositoryState(cwd: string, captureWorktree = false): { repoRoot: string; head: string; tree: string; cleanWorktree: boolean; worktree?: WorktreeSnapshot } {
const repoRoot = command(cwd, ["rev-parse", "--show-toplevel"]);
const head = command(repoRoot, ["rev-parse", "HEAD"]);
const tree = command(repoRoot, ["rev-parse", "HEAD^{tree}"]);
const prefix = relative(repoRoot, resolve(cwd)).replaceAll("\\", "/");
const owned = prefix ? `${prefix}/.pi` : ".pi";
const pathspec = [".",
`:(exclude,glob)${owned}/plan/*.md`,
`:(exclude,glob)${owned}/pi-goals/approvals/*`,
`:(exclude,glob)${owned}/pi-goals/models/*`,
];
// NUL delimiters and no rename folding preserve whitespace/newlines and both sides of renames.
const raw = execFileSync("git", ["status", "--porcelain=v1", "-z", "--no-renames", ...(captureWorktree ? ["--ignore-submodules=none"] : []), "--untracked-files=all", "--", ...pathspec], { cwd: repoRoot });
const status = raw.toString("utf8");
if (captureWorktree && !raw.equals(Buffer.from(status))) throw new Error("Cannot fingerprint non-UTF-8 Git paths.");
return { repoRoot, head, tree, cleanWorktree: status === "", ...(captureWorktree ? { worktree: worktreeSnapshot(repoRoot, status, pathspec) } : {}) };
}
export function goalBlock(plan: string, goal: string): string | null {
const lines = foldPlan(plan).split("\n");
const wanted = goal.trim().toLowerCase();
const hits = lines.flatMap((line, index) => {
const match = GOAL_LINE.exec(line);
return match && (match[1] === " " || match[1] === "/") && match[2].trim().toLowerCase() === wanted ? [index] : [];
});
if (hits.length !== 1) return null;
const start = hits[0];
let end = lines.length;
for (let index = start + 1; index < lines.length; index++) {
if (GOAL_LINE.test(lines[index]) || /^#{1,2}\s/.test(lines[index])) {
end = index;
break;
}
}
return lines.slice(start, end).join("\n").trimEnd();
}
export function hashGoalBlock(block: string): string {
return createHash("sha256").update(block).digest("hex");
}
export function verifyOutputPath(repoRoot: string, path: string): string | null {
const resolved = resolve(repoRoot, path);
const relativePath = relative(repoRoot, resolved).replaceAll("\\", "/");
if (!relativePath || relativePath.startsWith("../") || relativePath === "..") return null;
try {
const output = statSync(resolved);
if (!output.isFile() || output.size === 0) return null;
command(repoRoot, ["ls-files", "--error-unmatch", "--", relativePath]);
return relativePath;
} catch {
return null;
}
}
export function approvalPath(cwd: string, sessionId: string, goal: string): string {
const goalId = createHash("sha256").update(goal.trim().toLowerCase()).digest("hex").slice(0, 16);
return join(cwd, ".pi", "pi-goals", "approvals", `${sessionId}-${goalId}.json`);
}
export function writeApproval(path: string, record: ApprovalRecord): void {
mkdirSync(dirname(path), { recursive: true });
const temporary = `${path}.${process.pid}.tmp`;
try {
writeFileSync(temporary, `${JSON.stringify(record, null, 2)}\n`);
renameSync(temporary, path);
} finally {
if (existsSync(temporary)) rmSync(temporary, { force: true });
}
}
export function readApproval(path: string): ApprovalRecord | null {
if (!existsSync(path)) return null;
try {
return JSON.parse(readFileSync(path, "utf8")) as ApprovalRecord;
} catch {
return null;
}
}
export function approvalMatches(record: ApprovalRecord | null, input: {
approvalId: string;
goal: string;
planPath: string;
goalBlockHash: string;
repoRoot: string;
head: string;
tree: string;
cleanWorktree: boolean;
worktree?: WorktreeSnapshot;
}): boolean {
return record?.version === 3
&& record.verdict === "accept"
&& record.approvalId === input.approvalId
&& record.goal === input.goal
&& resolve(record.planPath) === resolve(input.planPath)
&& record.goalBlockHash === input.goalBlockHash
&& resolve(record.repoRoot) === resolve(input.repoRoot)
&& record.head === input.head
&& record.tree === input.tree
&& (record.force
? Boolean(record.force.reason?.trim()) && Boolean(record.force.worktree) && Boolean(input.worktree)
&& record.cleanWorktree === input.cleanWorktree
&& JSON.stringify(record.force.worktree) === JSON.stringify(input.worktree)
: record.cleanWorktree === true && input.cleanWorktree)
&& record.inspected.plan === true
&& record.inspected.repository === true
&& record.inspected.evidence === true
&& record.inspected.verifyOutput === true
&& Boolean(record.verifyOutputPath);
}

Some files were not shown because too many files have changed in this diff Show More