docs: integrate installed resource loading

This commit is contained in:
2026-09-03 10:44:41 +08:00
parent d22d4b0f6e
commit bd377c9732
9 changed files with 143 additions and 301 deletions

View File

@@ -4,6 +4,25 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
## Integrated Through
- Packaged Device Package preparation source
`5a2f0eb6785b59d8b455ed5cb1d9773351ff895a` from task
`20260902-local-skill-install-fix-6b3e91a4` and installed-resource activation
source `17664c5fffcfe695653b4146503e645f54767c4b` from task
`20260903-load-installed-resources-8f3c1a72` are integrated by task
`20260903-integrate-installed-resources-4b7e2c91`. Packaged inspection now
imports package-management authority from the distributed physical Pi runtime
instead of the incomplete `app.asar` dependency graph. The parent Agent Server
keeps the generated Makelore bridge as its required first extension and loads
every further Main-selected, installed, and enabled Device Package extension
through Pi `0.84.2`'s explicit additional-extension input; all selected Skill
paths remain intact and ambient discovery remains disabled. Packaged prepare
passed for loose Skill, npm, and Git sources without committing a package, and
a real Agent Server regression registered commands from two external
extensions. Focused/full unit and pressure tests, typecheck, scoped lint,
production build, Windows packaging, and artifact/runtime verification passed
across the two source tasks. The currently installed 1.2.6 client was not
replaced; rebuilt exact-main installation and live prepare/confirm/activation
remain release acceptance work.
- Youth-facing AI Design client source
`0fd32a2d49045a8f9e7f2e19ba6477f48f93e30c` is integrated over Model Tools
frontier `7552cf59526449c29d663a769c0fb62d84a1a759` through merge
@@ -34,9 +53,10 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
local commit; lifecycle scripts stay disabled; new and idle parent workers refresh
automatically while active workers switch after settlement; child workers remain
empty. My Plugins now separates Official Plugins from Device Installed packages and
exposes no visible install picker. Packaged Skill/Pi-extension installation and real
selected-model search remain external acceptance gates; no paid Provider request,
production install, publish, push, or PR is claimed.
exposes no visible install picker. The later packaged prepare and multi-extension
activation corrections are recorded above; rebuilt exact-main installed-client
acceptance and real selected-model search remain external gates. No paid Provider
request, production install, publish, push, or PR is claimed.
- Windows titlebar Logo-overlap correction source
`99a210e244731d1cdc923e9dd4adf6e09e64c2a4` from task
`20260901-windows-titlebar-logo-overlap-5100e298` is integrated onto local
@@ -409,7 +429,7 @@ Makelore 在会话恢复、登录和刷新后由 Electron Main 请求 Works `/ap
AI 学习现在是已启用的运营精选项目目录,并继续受登录和 `module_access.learning` 控制。Renderer 通过 Main-owned Host API 获取分页项目卡片和 README 详情;Markdown 支持 GFM、禁用原始 HTML。服务端发布时只校验图片 URL 为无凭据、默认端口、无 fragment 且当前 DNS 结果全部为公网地址的 HTTPS URL,保留地址而不下载、识别格式、转码或镜像;客户端仅为 README 图片节点启用直连,因此 SVG 和 Electron 支持的其他格式可直接显示,单图失败不阻断详情。封面和历史发布媒体继续走受控路径。详情页的下载按钮打开系统保存对话框;Main 将 ZIP 流式写入临时文件,只允许最多五跳同 Works origin 重定向,不校验 `Content-Length`、`archiveBytes`、实际流字节数或客户端大小上限,校验 SHA-256 和 ZIP 签名后原子保存,Renderer 只接收 `saved` 或 `cancelled`。课程生成、进度、本地课程库、OpenMAIC player、Agent、ASR、课堂 runtime、Learning IPC 和 player artifact 打包已删除且没有兼容读取路径;历史课程数据保留但不再读取。服务端和客户端源码契约已完成,不代表生产部署或真实账号安装包联调已经完成。
AI 编程已经硬切到精确 pin 的 Pi `0.84.2`,不存在 OpenCode fallback 或双 runtime。project、Agent 与 Conversation 只在 `.makelore/project.json` 和 `.makelore/conversations.json` 使用本地 schema v2;当前客户端不从 `.niancode` 或 `.opencode` 读取、迁移或删除项目元数据。Electron Main 按需启动一个长驻父 Agent Server,每条 active/warm Conversation 在其中拥有独立 Runtime/Session/channel、credential store、extension context、generation/seq、Snapshot/Patch、model/thinking、队列、interaction 与错误状态,Composer 在 lazy prepare 期间仍可编辑。Renderer 只通过 `/api/coding/*` 和 Snapshot-first/`patch-batch` SSE 消费产品中立合同;gap/reconnect 只恢复目标 Conversation,accepted/uncertain mutation 不自动重放。未解析 Conversation 第一次选模先 validate 并持久化 resolved metadata,再 prepare;同账号模型切换使用 target `set_model`,跨账号只重建目标逻辑线程。top-level 逻辑 turn 并发为 4,warm idle logical-thread LRU 为 8;independent child 进程并发为 4 并使用 FIFO 进程预算 8;coding child 与 parent 共用项目 write lease。prompt/compact confirmation timeout 后仍保留 run/Agent-Server-or-child-process/background ownership,迟到 success/failure/exit/abort 单调且 exactly-once 收敛,页面隐藏不会停止 active/uncertain run。线程级替换只使目标 generation 失效;整个 Agent Server 退出会统一使所有旧 channel 失效,但 Main/Renderer 存活且下次恢复只重启一个 Server。Pi `0.84.2` 手动 compact 不发 `agent_settled`,由 correlated compact RPC 结果终结。父 Provider credential 只进入选中逻辑线程的内存 credential store,child 凭据只进入该短命进程;确定性的 Works user-context 缺失会失效 gateway credential、fail fast、不重放并投影固定 Provider-auth 错误,不归类为 Pi crash。真实 Provider 验证仍为用户明确接受的未验证风险,macOS x64/arm64 与 native non-WSL Linux 也未通过平台发布门禁。
AI 编程已经硬切到精确 pin 的 Pi `0.84.2`,不存在 OpenCode fallback 或双 runtime。project、Agent 与 Conversation 只在 `.makelore/project.json` 和 `.makelore/conversations.json` 使用本地 schema v2;当前客户端不从 `.niancode` 或 `.opencode` 读取、迁移或删除项目元数据。Electron Main 按需启动一个长驻父 Agent Server,每条 active/warm Conversation 在其中拥有独立 Runtime/Session/channel、credential store、extension context、generation/seq、Snapshot/Patch、model/thinking、队列、interaction 与错误状态,Composer 在 lazy prepare 期间仍可编辑。Renderer 只通过 `/api/coding/*` 和 Snapshot-first/`patch-batch` SSE 消费产品中立合同;gap/reconnect 只恢复目标 Conversation,accepted/uncertain mutation 不自动重放。未解析 Conversation 第一次选模先 validate 并持久化 resolved metadata,再 prepare;同账号模型切换使用 target `set_model`,跨账号只重建目标逻辑线程。Main-selected Device Package generation 把所有显式安装且当前启用的 Skill 路径和 extension 路径交给未来或空闲 parent;生成的 Makelore bridge 始终是必需的首个 extension,其余全部经 `additionalExtensionPaths` 加载,同时保持 ambient discovery 关闭。active parent 在 turn settled 后刷新,child 始终为空。top-level 逻辑 turn 并发为 4,warm idle logical-thread LRU 为 8;independent child 进程并发为 4 并使用 FIFO 进程预算 8;coding child 与 parent 共用项目 write lease。prompt/compact confirmation timeout 后仍保留 run/Agent-Server-or-child-process/background ownership,迟到 success/failure/exit/abort 单调且 exactly-once 收敛,页面隐藏不会停止 active/uncertain run。线程级替换只使目标 generation 失效;整个 Agent Server 退出会统一使所有旧 channel 失效,但 Main/Renderer 存活且下次恢复只重启一个 Server。Pi `0.84.2` 手动 compact 不发 `agent_settled`,由 correlated compact RPC 结果终结。父 Provider credential 只进入选中逻辑线程的内存 credential store,child 凭据只进入该短命进程;确定性的 Works user-context 缺失会失效 gateway credential、fail fast、不重放并投影固定 Provider-auth 错误,不归类为 Pi crash。真实 Provider 验证仍为用户明确接受的未验证风险,macOS x64/arm64 与 native non-WSL Linux 也未通过平台发布门禁。
Updater 仍由 Electron Main 选择目标 feed、记录原始诊断并保持失败语义。正式稳定源缺少对应平台 manifest 时,设置页只显示一条简洁中文提示并允许重试,不把缺包误报为已是最新版,也不向普通界面暴露堆栈、URL、路径或错误码;签名产物发布和真实升级安装仍属于外部 Release Gate。
@@ -417,6 +437,15 @@ Robot 绑定设备默认先显示“引导配网 / 已有激活码”路径选
## Recently Completed
- 2026-09-03: Integrated the paired Device Package prepare and activation fixes.
Packaged Main now resolves package inspection from the physical bundled Pi
runtime, and the parent Agent Server loads the required generated Makelore
bridge plus every explicit installed/enabled Pi extension while retaining all
selected Skills and keeping ambient discovery off. Source verification passed
packaged npm/Git/loose-Skill prepare, a real Agent Server with two external
extension commands, full unit/pressure, typecheck, lint, build, Windows
packaging, and artifact checks. The installed 1.2.6 client is unchanged, so
exact-main rebuild/install and live activation are still pending.
- 2026-08-31: Integrated the provider-neutral `makelore.game-resource` hosted Plugin
client with fetched `origin/main`. Generic schema-2 `platform_hosted` packages now
materialize frozen Skill/tool snapshots only for eligible parent Pi logical threads;

View File

@@ -1,147 +0,0 @@
# Task: Fix packaged local Skill installation
## Identity
- Task ID: 20260902-local-skill-install-fix-6b3e91a4
- Mode: Feature
- Branch: codex/20260902-local-skill-install-fix-6b3e91a4-local-skill-install-fix
- Worktree: D:\Datas\OthersProjects\makelore-local-skill-install-fix-6b3e91a4
- Base commit: 28e1690038d61b9333a2f6ca77f0187ea4273676
- Owner: codex-root
- Status: Ready for Integration
## Scope
- Fix packaged conversation-driven Device Package installation after the bundled
Pi CLI succeeds but the Main-owned package inspection path fails to load its
production dependency closure.
- Add a red/green packaged-runtime regression for the lazy package-manager
boundary.
- Preserve closed Device Package errors across the Pi extension bridge so
supported-source dependency failures and unsupported source syntax no longer
collapse to the same generic `Bridge request failed` response.
- Rebuild and verify the Windows `app.asar`/product artifact, then execute the
real packaged npm and Git prepare paths without committing a package.
## Intent And Constraints
- Keep the accepted Device Packages product model unchanged: installation is
initiated only through conversation tools; preview and a distinct later
confirmation precede commit; packages are local Main-owned immutable
generations; lifecycle scripts stay disabled; only future/idle parent workers
receive resources and child workers remain empty.
- Work only in the isolated feature worktree from exact client `main`
`28e1690038d61b9333a2f6ca77f0187ea4273676`. Preserve the three unowned task
records in the client root and do not reset, stash, clean, adopt, or modify
that worktree.
- Do not add a global Pi CLI requirement, visible installer, Account Library,
Marketplace Release/Admission, hosted Web Search, Provider, server, billing,
deploy, publish, push, or PR behavior.
- Avoid leaking local paths, stacks, credentials, or raw dependency diagnostics
to Pi/Renderer. Only closed Device Package codes and bounded public messages
may cross the bridge; internal errors may be logged in Main.
- The prior diagnosis is accepted evidence: installed bundled Pi npm/Git
resolution succeeds, while importing the packaged
`@earendil-works/pi-coding-agent` graph fails because
`partial-json@0.1.7` is absent from `app.asar`.
## Concurrent Task Gate
- `check_project_docs` passed for the client root.
- `task_context start` created the exact isolated worktree/branch/base recorded
above; `status --json` confirmed matching task, owner, mode, branch, worktree,
and base.
- The client root remains on `main` with exactly three pre-existing untracked
task records; none was copied as a change or adopted.
- The only semantically adjacent registered peer is the older native Web Search
client coordinator. Its task record owns hosted/model-tool composition, not
Device Package manager loading, bridge error projection, or packaging closure;
no semantic or file-ownership conflict is present.
- Gate result: Passed.
## Project Context Loaded
Read the project memory entry, active record, positioning/current state,
decision index, ADR-006, system/module/data-flow architecture, business rules,
success criteria, evidence/reflection/commitment/stale indexes, the completed
Model Tools and Device Packages integration record, the relevant peer record,
and the prior diagnosis record.
Relevant understanding:
- Electron Main owns package bytes, inspection, durable generations, Pi resource
materialization, and packaged dependency authority; Renderer/Pi receive only
closed projections.
- The current integrated frontier deliberately lazy-loads the ESM-only Pi package
manager for remote installs. Workspace tests passed, but packaged signed-in
installation remained an explicit acceptance gate and the installed artifact
now proves that its ESM dependency closure is incomplete.
- ADR-006 explicitly requires installed-package regressions to be exercised
against final `app.asar` and packaged runtime roots.
- Likely owned modules are `electron/coding-packages/**`, the Pi extension bridge,
artifact verification scripts/tests, and the root production dependency lock.
- Planning Gate result: Passed.
## Outcome
- Replaced the packaged Device Package inspection dependency on the incomplete
`app.asar` Pi graph with the already-distributed physical
`resources/pi-runtime/dist/index.js` authority used by the bundled Pi CLI.
- Preserved closed `local_package_*` failures through Main's worker bridge and
the generated Pi extension while keeping unknown failures generic.
- Added an artifact gate that rejects a Main-reachable bare
`@earendil-works/pi-coding-agent` dynamic import and proves that the packaged
physical runtime exposes `DefaultPackageManager` and
`SettingsManager.inMemory`.
- Bumped the generated MakeLore Pi extension generation so new workers cannot
reuse stale bridge code.
- Produced a final Windows x64 product at source commit
`5a2f0eb6785b59d8b455ed5cb1d9773351ff895a`. No package was committed to
the user's Device Package store and the installed MakeLore application was
not replaced.
## Verification
- Installed-artifact RED: importing the installed `app.asar` Pi graph failed
with `ERR_MODULE_NOT_FOUND` for `partial-json`; importing its physical
`resources/pi-runtime/dist/index.js` succeeded with both required exports.
- TDD RED: the new Device Package manager regression attempted the unavailable
app Pi graph; the real worker bridge reduced a closed failure to
`Bridge request failed`; the artifact gate accepted the stale bare import.
- Focused and adjacent unit tests: 8 files, 69 passed.
- Full unit suite: 222 files, 1815 passed, 2 skipped; pressure test 1 passed.
The first run saw two Windows `spawn EBUSY` failures while Electron was first
downloaded; that file then passed 3/3 alone and the complete rerun passed.
- `pnpm typecheck`: passed.
- Scoped ESLint for every changed TypeScript/JavaScript source and test: passed.
- `pnpm run build:vite`: passed; generated Main contains the physical runtime
loader and no bare dynamic import of `@earendil-works/pi-coding-agent`.
- Final source/runtime acceptance used the Windows product executable, physical
Pi CLI/runtime, and self-contained npm runtime from `release/win-unpacked`.
Prepare succeeded without commit for a loose `SKILL.md`,
`npm:pi-web-search`, and
`https://github.com/DietrichGebert/ponytail`; the latter projected six Skills
plus one Pi extension.
- `pnpm run package:stage:win-x64` and Electron Builder/NSIS: passed. The
installer is 208,323,462 bytes with SHA-256
`A5CA7422B3962ABF6B0391B73EC26C7600D962630289F0EFE3BAFDD03A3B97E1`.
- `pnpm run verify:artifact:win`: passed against source/verification head
`5a2f0eb6785b59d8b455ed5cb1d9773351ff895a`; Electron 43.4.0, Node 24.18.1,
Python, uv 0.10.0, npm 11.6.2 and native modules were verified from the
final product. The pinned Python/uv staging was reused from the existing root
after a fresh Python archive fetch stalled; the verifier proved the copied
runtimes rather than treating the network attempt as evidence.
- `pnpm run verify:artifact:pi`: passed. Its new Device Package evidence is
`authority=bundled-pi-runtime`, `appAsarRootImport=false`, and both package
manager exports are functions; Pi 0.84.2 closure and runtime probes passed.
- `git diff --check`: passed.
## Follow-ups
- Integrate the source commit onto client `main`, rebuild from that exact
frontier if a main-line installer is required, then install/restart MakeLore
before retrying the conversation-driven prepare/confirm flow.
## Promotion Candidates
- None recorded.

View File

@@ -0,0 +1,100 @@
# Task: Integrate installed resource loading fix to main
## Identity
- Task ID: 20260903-integrate-installed-resources-4b7e2c91
- Mode: Integration
- Branch: codex/20260903-integrate-installed-resources-4b7e2c91-integrate-installed-resources
- Worktree: D:\Datas\OthersProjects\makelore-integrate-installed-resources-4b7e2c91
- Base commit: 28e1690038d61b9333a2f6ca77f0187ea4273676
- Owner: codex
- Status: Ready for Main Promotion
## Scope
- Integrate the completed packaged Device Package prepare fix and the successor
installed-resource activation fix onto the current local `main` history.
- Promote the accepted behavior and evidence into current-state, architecture,
README, evidence, and release-acceptance memory.
- Verify the exact integrated source tree without installing a replacement
client, publishing artifacts, pushing, or modifying unrelated user work.
## Intent And Constraints
- Every resource explicitly installed and currently enabled by the user must be
included in the Main-selected parent resource generation. Manual disablement
remains authoritative.
- The generated Makelore extension remains the required first extension. All
further selected Device Package extensions load through Pi's explicit
additional-extension input while ambient project/user discovery stays off;
selected Skill paths remain unchanged and child workers stay empty.
- Treat the two source task records as read-only integration evidence. Do not
rewrite their history or broaden this merge into Marketplace, Provider,
Renderer, deployment, publication, or installed-application changes.
- The root `main` worktree is owned by an earlier diagnostic task and contains
three pre-existing untracked task records. Preserve them exactly; do not
stash, reset, clean, adopt, overwrite, or force-release that ownership
without explicit human confirmation.
## Integration Plan
1. Fast-forward the completed source history from current `main` into this
isolated integration branch and confirm both product commits are present.
2. Reconcile the accepted promotion with canonical product/architecture
memory and the release acceptance commitment.
3. Run focused tests, full unit/pressure verification, typecheck, scoped lint,
production build, diff checks, and the task documentation gates.
4. Advance local `main` only through a clean, ownership-safe operation.
## Outcome
- Fast-forwarded the completed source history through
`d22d4b0`, retaining product commits
`5a2f0eb6785b59d8b455ed5cb1d9773351ff895a` and
`17664c5fffcfe695653b4146503e645f54767c4b` on the integration history.
- Packaged Device Package inspection now resolves `DefaultPackageManager` and
in-memory settings from the distributed physical Pi runtime. The generated
Makelore bridge remains required, and the Agent Server loads every further
Main-selected installed/enabled extension through Pi's explicit additional
paths without ambient discovery; all selected Skill paths remain unchanged.
- Promoted the accepted behavior and verification boundary into `README.md`,
canonical current state, system overview, module map, evidence index, and the
Windows release commitment. The README's stale Hosted Web Search description
was reconciled with the already-integrated selected-model tool architecture.
- Excluded the two source task-owned records from the final integration tree as
required by the task-aware document boundary. Their files and commits remain
intact on the source branches; this integration record carries the promoted
default-branch result.
- No installed application, local Device Package store, user project, package,
deployment, publication, remote branch, or unrelated root-worktree file was
changed.
## Verification
- `corepack pnpm install --frozen-lockfile` — passed with pinned pnpm 10.33.4;
lockfile unchanged.
- Focused integrated regressions — 5 files / 31 tests passed, including packaged
package authority, generated extension bundle, real Agent Server multi-extension
registration, worker opener, and Device Package manager behavior.
- Full unit suite — 222 files / 1,815 passed / 2 conditional skips; serialized
coding-chat pressure test 1/1 passed.
- `corepack pnpm run typecheck` — passed.
- Scoped ESLint over all ten changed source/test files — passed.
- `corepack pnpm run build:vite` — Renderer, Main, Preload, and release utility
passed; only pre-existing mixed-import and chunk-size warnings were emitted.
- `git diff --check` — passed.
- The task-aware drift check initially identified the two imported source task
records as foreign ownership files. They were removed from the integration
result; the final drift result is recorded after this task record is committed.
## Follow-ups
- Build and install a client from the exact promoted `main`, then execute live
Conversation prepare→confirm→activation with npm/Git/loose Skill coverage and
a generation containing at least two enabled extensions. The currently
installed 1.2.6 client remains the old, known-failing artifact.
- No push was requested; remote publication remains separate.
## Promotion Candidates
- None. Accepted source-task promotions were applied during this integration.

View File

@@ -1,142 +0,0 @@
# Task: Load all enabled installed Pi resources
## Identity
- Task ID: 20260903-load-installed-resources-8f3c1a72
- Mode: Feature
- Branch: codex/20260903-load-installed-resources-8f3c1a72-load-installed-resources
- Worktree: D:\Datas\OthersProjects\makelore-load-installed-resources-8f3c1a72
- Base commit: 34e59bfaf2867e6a53a345de52c0ce850d6f426a
- Owner: codex
- Status: Ready for Integration
## Scope
- Make every enabled, conversation-installed Device Package Pi extension load in
the parent Agent Server alongside the required generated Makelore extension.
- Add a real Agent Server process regression that crosses the repeated
`--extension` seam and proves the external extension actually registers.
- Preserve existing Skill loading, manual disablement, parent-worker refresh,
and child-empty behavior. Do not broaden discovery to ambient project/global
Pi resources or change Plugin Marketplace authorization.
## Intent And Constraints
- The user decision is that installed resources load; the bounded
interpretation is every explicitly installed and currently enabled resource.
The existing disable toggle remains authoritative.
- Keep the first `--extension` path as the required Main-generated Makelore
bridge factory. Pass subsequent confirmed Device Package paths through Pi
`0.84.2`'s explicit additional-extension input while retaining discovery-off
settings.
- Make the smallest source/test change. Do not add compatibility layers,
feature flags, new validation frameworks, Renderer behavior, Provider calls,
package installation, or application restart.
## Concurrent Task Gate
- `check_project_docs.py` passed with the bundled Codex Python runtime.
- `task_context.py start` created this isolated feature worktree from clean,
human-verified adjacent fix head
`34e59bfaf2867e6a53a345de52c0ce850d6f426a`; `status --json` matched task ID,
branch, worktree, base, mode, and owner.
- Relevant peer records were read. The local-Skill installation task is the
predecessor and is included in this base. Runtime diagnosis, old package,
client-hang, Model Tools, and Marketplace tasks do not own this worktree.
- The package-1.2.6 record says In Progress while the registry says ready for
integration; it targets the old main artifact and does not overlap this
source change, so the discrepancy is noted but not blocking.
- Gate result: Passed.
## Project Context Loaded
- Read the memory entry and planning gate, active record, project positioning,
current state, decision index and ADR-006, system/module/data-flow
architecture, business rules, success criteria, evidence/reflection/
commitment/stale indexes, and relevant peer records.
- Main owns the Pi resource set. New and idle parent threads must receive every
enabled installed Device Package Skill/extension; active threads switch after
settlement and child threads stay empty.
- Live evidence proves the real Agent Server rejects built-in-plus-device
extension arguments before open. Canonical Device Package behavior is
therefore stale relative to the implementation, not semantically disputed.
- Likely files are `resources/pi-agent-server.mjs` and
`tests/unit/pi-agent-server-process-real.test.ts`.
- `project-positioning.md` remains a template; the repository guidance,
integrated state, ADR-006, and domain rules provide the applicable product
boundary.
- Planning Gate result: Passed.
## Implementation Plan
1. Add a real-process regression with one generated Makelore extension and one
external extension; verify it fails at the current exact-one guard.
2. Treat only the first extension as the Makelore bridge and load all remaining
explicit paths through Pi's additional extension list.
3. Run the focused real-process and opener/resource tests, typecheck, scoped
lint, production build, diff checks, and the project-document completion
gates.
## Outcome
- Product source and real-process regression are committed as
`17664c5fffcfe695653b4146503e645f54767c4b`.
- Removed the accidental exact-one Agent Server constraint. The first explicit
extension remains the required generated Makelore runtime factory, while
every subsequent explicit path is passed to Pi `0.84.2` as
`additionalExtensionPaths`.
- Retained `noExtensions: true`, so Pi loads the complete Main-selected
installed/enabled set without adding ambient project or user-global
discovery. Existing `additionalSkillPaths` behavior is unchanged, so all
enabled installed Skills continue to load through the same frozen parent
resource generation.
- Strengthened the real-process test to open two isolated Conversations with
the Makelore bridge plus two independent external extensions. Both external
commands must appear in `get_commands`, proving every supplied extension is
initialized rather than merely accepted by argument parsing.
- No Renderer, Marketplace policy, package index, child-worker, Provider,
application process, or installed-client state changed.
## Verification
- TDD red: the strengthened real Agent Server process test failed during
`thread_open` with `Thread requires exactly one Makelore extension`.
- TDD green and final focused matrix: `pi-agent-server-process-real`,
`pi-managed-worker-opener`, and `device-package-manager` — 3 files / 10
tests passed. The real process loaded both external extension commands.
- Final full unit suite: 222 files / 1,815 passed / 2 conditional skips;
serialized coding-chat pressure test 1/1 passed.
- `pnpm run typecheck` with pinned pnpm 10.33.4: passed.
- Scoped ESLint for the changed server and test: passed.
- `pnpm run build:vite`: Renderer, Main, Preload, and release utility passed;
only the existing dynamic-import and chunk-size warnings were emitted.
- `pnpm install --frozen-lockfile` used pnpm 10.33.4 and reused the local store
without changing the lockfile.
## Follow-ups
- Integrate this task together with its predecessor
`20260902-local-skill-install-fix-6b3e91a4`, then build and install a new
Windows client before re-enabling/retrying Ponytail in the live application.
- The currently installed 1.2.6 client is unchanged and still contains the
exact-one guard; disabling the Device Package remains the reversible recovery
until a replacement client is installed.
## Promotion Candidates
- Target canonical documents: `.project-docs/30-worklog/current-state.md` and
`.project-docs/50-evidence/evidence-index.md`.
- Proposal: record that the successor of the packaged local-Skill install fix
now loads the required generated Makelore extension plus every explicit
enabled Device Package extension, while keeping ambient discovery disabled.
- Evidence: exact red `thread_open` failure before the source change; real
Agent Server green with two external extension files and both registered
commands; focused, full-unit, pressure, typecheck, lint, and production-build
verification above.
- Future impact: Device Packages that contain Pi extensions no longer make the
parent Conversation unavailable; release acceptance should include
built-in-plus-multiple-device-extension activation, not prepare-only proof.
- Semantic conflicts: none. This implements the already accepted Device Package
behavior and the user's explicit all-installed/enabled loading decision.
- Human confirmation required: no for promotion of the implementation result;
yes before any separate install/restart action if not already authorized.