Skip to content

feat(bin): enforce deterministic profiles for delegated Pi#877

Open
BazsaX254 wants to merge 7 commits into
kunchenguid:mainfrom
BazsaX254:fm/firstmate-pi-compaction-profile
Open

feat(bin): enforce deterministic profiles for delegated Pi#877
BazsaX254 wants to merge 7 commits into
kunchenguid:mainfrom
BazsaX254:fm/firstmate-pi-compaction-profile

Conversation

@BazsaX254

Copy link
Copy Markdown

Intent

Implement FirstMate-owned deterministic delegated Pi profile enforcement for Pi workers, scouts, helper routes, batches, supported secondmates, and recovery across tmux, Herdr, Zellij, Orca, and cmux, while leaving the primary Pi path xhigh. The opt-in operator-owned home profile must pin Pi 0.81.1, an exact model and effective context metadata, explicit medium thinking, and compaction at exactly 60 percent using reserveTokens = contextWindow - floor(0.60 * contextWindow), failing closed before launch on ambiguity, hostile environment/project/extension surfaces, raw launch wrappers, override/model cycling, or unsupported routes. Preserve only required FirstMate extensions, keep existing backend refusals, avoid KING-specific shared policy, and provide provider-free portable tests with overridable Pi/package/compiler discovery, exact local 272000 context and 108800 reserve proof, strict greater-than boundary behavior, resume stability, primary xhigh separation, and full backend coverage. Do not invoke a model or live Pi worker, mutate Herdr lifecycle, global Pi state, production configuration, or add an agent co-author.

What Changed

  • Add an opt-in delegated Pi profile that pins Pi 0.81.1, model/context metadata, medium thinking, and compaction strictly above 60%, failing closed on invalid profiles, hostile runtime surfaces, conflicting overrides, and raw launches.
  • Enforce the profile across workers, scouts, batches, recovery, and supported secondmates on every backend, requiring secondmate profile convergence while preserving the primary Pi xhigh path and existing backend refusals.
  • Add runtime guards, provider-free regression coverage, and documentation for compaction boundaries, resume stability, inheritance, and backend routing.

Risk Assessment

✅ Low: The change is well-bounded, closes the previously identified environment and secondmate fail-open paths, and introduces no remaining material source-verifiable risk.

Testing

Repository inspection, provider-free automated profile/dispatch tests, manual launch/refusal evidence, primary xhigh separation, secondmate inheritance, and all five backend families were exercised without invoking a model or live Pi worker; the intended behavior passed, with only unchanged environment-dependent checks blocked by missing tasks-axi, root permission semantics, and an unavailable TypeScript compiler.

Evidence: Delegated Pi user-experience transcript
USER-VISIBLE SPAWN RESULT
warn: no registry at /tmp/fm-spawn-dispatch-profile.hOzNZ8/evidence-delegated-pi/home/data/projects.md; defaulting project to no-mistakes off
spawned evidence-pi-z99 harness=pi kind=ship mode=no-mistakes yolo=off window=firstmate:fm-evidence-pi-z99 worktree=/tmp/fm-spawn-dispatch-profile.hOzNZ8/evidence-delegated-pi/wt

PERSISTED PROFILE METADATA
harness=pi
model=openai-codex/gpt-5.6-sol
effort=medium

CAPTURED COMMAND HANDED TO THE WORKER TERMINAL
NODE_OPTIONS= NODE_PATH= PI_PACKAGE_DIR= PI_CODING_AGENT_DIR='/tmp/fm-spawn-dispatch-profile.hOzNZ8/evidence-delegated-pi/home/pi-agent' FM_PI_DELEGATED_MODEL='openai-codex/gpt-5.6-sol' FM_PI_DELEGATED_CONTEXT_WINDOW='272000' FM_PI_DELEGATED_AGENT_DIR='/tmp/fm-spawn-dispatch-profile.hOzNZ8/evidence-delegated-pi/home/pi-agent' FM_PI_DELEGATED_RESERVE_TOKENS='108800' FM_PI_DELEGATED_KEEP_RECENT_TOKENS='20000' '/root/.hermes/node/lib/node_modules/@earendil-works/pi-coding-agent/dist/cli.js' --model 'openai-codex/gpt-5.6-sol' --thinking 'medium' --no-approve --no-extensions --models 'openai-codex/gpt-5.6-sol' -e '/root/.no-mistakes/worktrees/0898b415e35c/01KY5QVYG55970Z4HTME2WGJVG/bin/fm-pi-profile-guard.ts' -e '/tmp/fm-spawn-dispatch-profile.hOzNZ8/evidence-delegated-pi/home/state/evidence-pi-z99.pi-ext.ts' "$(cat '/tmp/fm-spawn-dispatch-profile.hOzNZ8/evidence-delegated-pi/home/data/evidence-pi-z99/brief.md')"

CONFLICTING OVERRIDE RESULT (exit 1)
error: delegated Pi profile refuses effort override 'xhigh' (required 'medium')
Evidence: Primary xhigh separation transcript
NO DELEGATED PROFILE: EXISTING PI PATH
warn: no registry at /tmp/fm-spawn-dispatch-profile.WilaLj/evidence-primary-separation/home/data/projects.md; defaulting project to no-mistakes off
spawned evidence-primary-z99 harness=pi kind=ship mode=no-mistakes yolo=off window=firstmate:fm-evidence-primary-z99 worktree=/tmp/fm-spawn-dispatch-profile.WilaLj/evidence-primary-separation/wt

PERSISTED PROFILE METADATA
harness=pi
model=openai-codex/gpt-5.6-sol
effort=xhigh

CAPTURED COMMAND
pi --model 'openai-codex/gpt-5.6-sol' --thinking 'xhigh' -e '/tmp/fm-spawn-dispatch-profile.WilaLj/evidence-primary-separation/home/state/evidence-primary-z99.pi-ext.ts' "$(cat '/tmp/fm-spawn-dispatch-profile.WilaLj/evidence-primary-separation/home/data/evidence-primary-z99/brief.md')"
Evidence: Compaction and profile proof
ok - effective Pi 0.81.1 metadata and controlled settings derive the 272000/108800 profile
ok - unknown models and effective context mismatches are refused before launch
ok - models without effective medium thinking support are refused before launch
ok - raw Pi launch wrappers are rejected without execution
ok - Pi uses strict greater-than: false at exactly 60 percent and true immediately above
ok - an explicit delegated medium change remains the restored session thinking state
ok - runtime compaction changes block turns and compaction
skip: tsc not found for delegated Pi profile guard typecheck
ok - hostile project and extension surfaces are neutralized while explicit FirstMate extensions remain supported
ok - ships, scouts, batches, recovery, and supported secondmates share one profile across all backends
skip: FM_PI_PRIMARY_LAUNCHER not set for optional primary Pi xhigh check
ok - delegated Pi profile requires medium
# all fm-pi-compaction-profile tests passed
Evidence: Spawn dispatch proof
ok - no --model/--effort records defaults and keeps the claude launch byte-identical
ok - active crew-dispatch profile requires an explicit harness for ship spawns
ok - active crew-dispatch profile requires an explicit harness for scout spawns
ok - active crew-dispatch profile allows an explicit resolved harness
ok - active crew-dispatch profile allows the legacy positional harness form
ok - active crew-dispatch profile allows the raw launch-command escape hatch
ok - claude receives --model and --effort profile flags
ok - codex receives --model and model_reasoning_effort profile flags
ok - codex omits unsupported max effort instead of passing a bad config value
ok - grok receives --model and --reasoning-effort profile flags
ok - grok omits unsupported max reasoning effort
ok - grok omits unsupported xhigh reasoning effort
ok - opencode receives --model and omits the unsupported effort axis
ok - pi receives --model and --thinking max profile flags
ok - top-level default array resolves through quota selection into the real spawn path
ok - configured delegated Pi profile overrides hostile ambience and pins the controlled command
ok - configured delegated Pi profile refuses model and effort substitution before launch
ok - active delegated Pi profile refuses env, env-command, shell-wrapper, and unknown raw launches
ok - malformed delegated Pi profile paths fail closed before launch
ok - batch dispatch forwards shared --harness, --model, and --effort to every pair
ok - active crew-dispatch profile does not block secondmate launches
ok - active delegated Pi profile must converge before secondmate launch or recovery
# all fm-spawn-dispatch-profile tests passed
- Outcome: ⚠️ 2 warnings across 1 run (7m31s)

Pipeline

Updates from git push no-mistakes

✅ **intent** - passed

✅ No issues found.

🔧 **Rebase** - 1 issue found → auto-fixed ✅
  • ⚠️ tests/fm-spawn-dispatch-profile.test.sh - merge conflict rebasing onto origin/main

🔧 Fix applied.
✅ Re-checked - no issues remain.

🔧 **Review** - 2 issues found → auto-fixed (2) ✅
  • 🚨 bin/fm-spawn.sh:791 - The required criterion says to fail closed on “hostile environment ... surfaces,” but this launch inherits PI_PACKAGE_DIR. Pi 0.81.1 uses that variable to derive its package metadata, application name, and agent-directory variable; a hostile package manifest can therefore make Pi ignore the pinned PI_CODING_AGENT_DIR, while the guard validates the intended directory instead of the one Pi actually uses. Clear package/runtime overrides during both validation and launch.
  • 🚨 bin/fm-spawn.sh:744 - The required criterion calls for enforcement across supported secondmates, but profile propagation failure only warns and launch continues. If pi-delegated-profile specifically fails or is skipped—such as when a secondmate could not fast-forward to the new ignore rule—the home can later launch Pi workers using a stale or absent profile. When the primary profile is active, require proof that this item converged before launching or recovering the secondmate.

🔧 Fix: Captain: Harden delegated Pi environment and inheritance
1 error still open:

  • 🚨 bin/fm-pi-profile.sh:97 - The required hostile-environment hardening remains incomplete: this clears PI_PACKAGE_DIR but still inherits NODE_OPTIONS while executing the pinned JavaScript CLI. A hostile preload can run before Pi 0.81.1, restore package redirection or alter validation/runtime state; the rendered launch at fm-spawn.sh:813 has the same gap. Run validation and launch with Node preload/runtime injection variables cleared or explicitly allowlisted.

🔧 Fix: Captain: Block Node injection in delegated Pi launches
✅ Re-checked - no issues remain.

⚠️ **Test** - 2 warnings
  • ⚠️ The environment lacks tasks-axi, preventing unrelated teardown assertions in unchanged backend tests from completing. The inheritance suite also contains a chmod-based assertion that cannot work when executed as root; a non-root retry was blocked because the workspace is beneath /root. Neither failure occurred in files changed by this commit.
  • ⚠️ Strict TypeScript compilation was skipped because no TypeScript compiler was installed or discoverable. The guard was still executed successfully using Node's type-stripping runtime against Pi 0.81.1.
  • git status --short --branch and git diff 51404137e8c4729670233cc31ff43eeae527b77c..66f0add70fcdf3b160fb56b470a9d7c09358d2c6
  • bash tests/fm-pi-compaction-profile.test.sh
  • bash tests/fm-spawn-dispatch-profile.test.sh
  • Manual fake-terminal delegated Pi spawn capturing CLI output, persisted metadata, exact launch command, and conflicting-override refusal
  • Manual no-profile Pi launch capturing persisted xhigh metadata and the exact --thinking 'xhigh' command
  • bin/fm-test-run.sh tests/fm-shared-captain-inheritance.test.sh tests/fm-secondmate-harness.test.sh tests/fm-spawn-batch.test.sh tests/fm-spawn-worktree-settle.test.sh tests/fm-backend.test.sh tests/fm-backend-herdr.test.sh --json /tmp/no-mistakes-evidence/01KY5QVYG55970Z4HTME2WGJVG/adjacent-tests.json
  • bin/fm-test-run.sh tests/fm-backend-zellij.test.sh tests/fm-backend-orca.test.sh tests/fm-backend-cmux.test.sh --json /tmp/no-mistakes-evidence/01KY5QVYG55970Z4HTME2WGJVG/remaining-backends.json
  • runuser -u nobody -- bash tests/fm-shared-captain-inheritance.test.sh (environment retry; workspace traversal denied)
  • Final git status --short and generated-directory inspection
✅ **Document** - passed

✅ No issues found.

⚠️ **Lint** - 1 warning
  • ⚠️ linter found issues (exit code 127)
✅ **Push** - passed

✅ No issues found.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant