docs: finalize PI release proof evidence

This commit is contained in:
2026-08-24 17:27:03 +08:00
parent 0d26d17cfc
commit ead9d1dbaf

View File

@@ -8,7 +8,7 @@
- Worktree: D:\Datas\OthersProjects\makelore-pi-release-proof-3e725ac7 - Worktree: D:\Datas\OthersProjects\makelore-pi-release-proof-3e725ac7
- Base commit: 977445ba450f4ad32b6e6db2caf048517513ab39 - Base commit: 977445ba450f4ad32b6e6db2caf048517513ab39
- Owner: codex-root - Owner: codex-root
- Status: In Progress (second planner Spec review fixes required) - Status: Ready for Planner Re-review (PI-150 remains externally blocked by native non-WSL Linux evidence)
## Scope ## Scope
@@ -66,80 +66,93 @@
## Outcome ## Outcome
- Code candidate `df1151b5eb8588f126ccbee98cb7bf0b46285659` fixes every - Final code candidate `0d26d17cfc5d32c91d6e25d919be1fabd94a605b`
implementation defect from the planner's first Spec review. The packaged closes all three P1 implementation/proof defects from the planner's second
extension/subagent proof now executes Main and runtime code from final review. Final-product proof now runs Main from packaged `app.asar`, starts the
`app.asar`/`resources/pi-runtime`; cold and warm prompt samples are distinct packaged `resources/pi-runtime/dist/cli.js`, receives a real `subagent` tool
and include resources-ready, worker-spawn, RPC-ready, session-open, call from a controlled loopback provider, dispatches through the real
prompt-accepted, and agent-settled milestones; one packaged run holds four `PiSubagentScheduler`, and starts a real ephemeral Pi child with exactly the
parent workers plus four child workers while exercising the real UI and then `find`, `grep`, `ls`, and `read` tools.
proves process/permit/dispatch/lease cleanup; the verifier enumerates ASAR - Each cold and warm proof is one Main-owned correlated timeline containing
internals; and a Linux x64 RPM is generated and inspected. `worker.queue_wait`, `resources.ready`, `worker.spawn`, `rpc.ready`,
`session.open`, `prompt.accepted`, `agent.start`, `provider.first_event`, and
`agent.settled`. Direct admission emits an explicit zero-duration queue wait;
reopening the same session after a resource rebuild is correctly classified
as warm.
- The 4+4 pressure proof now holds four real persistent Pi parents and four
real ephemeral Pi children as eight distinct live OS processes while four
write leases are active, proves the product UI remains interactive, and then
proves all processes, provider requests, process-budget entries, child
permits, dispatches, parents, and write leases return to zero.
- Real concurrent parent startup exposed a supported Windows failure in the
shared managed provider catalog: simultaneous temporary-file renames could
fail with `EPERM`. Same-path catalog writes are now serialized, with focused
concurrency regression coverage. This is a product fix, not a proof-only
workaround.
- Windows x64 and WSL2 Linux x64 final products passed Pi `0.84.2` - Windows x64 and WSL2 Linux x64 final products passed Pi `0.84.2`
production-closure, packaged composition, lifecycle, controlled production-closure, packaged composition, lifecycle, controlled
provider-shaped, extension/subagent, 4+4 pressure/isolation, cleanup, and provider-shaped, real parent/child extension execution, 4+4
performance qualification. Windows NSIS and Linux AppImage/deb/RPM pressure/isolation, cleanup, and performance qualification. Windows NSIS and
distributables were produced. Linux AppImage/DEB/RPM distributables were produced.
- Full ASAR enumeration found zero product-owned OpenCode paths. Exact matches - Full ASAR enumeration found zero product-owned OpenCode paths. Exact matches
under the pinned upstream `@earendil-works/pi-ai/dist/providers/opencode*` under the pinned upstream `@earendil-works/pi-ai/dist/providers/opencode*`
closure remain classified separately because Pi imports them; they are not closure remain classified separately because Pi imports them; they are not
Makelore-owned runtime residue. Makelore-owned runtime residue.
- The second planner review accepted the ASAR enumeration and RPM fixes but - PI-150 remains blocked only by the missing independent native non-WSL Linux
found three remaining P1 proof defects: final subagent still used a fake desktop/compositor acceptance evidence. WSL2/WSLg is useful final-product
in-process child, managed milestone reports joined different probe samples evidence but is not relabelled as that native environment. PI-160 must not
and omitted `worker.queue_wait`, and the 4+4 PIDs were placeholder Node start while this blocker remains.
processes rather than real Pi workers. PI-150 remains blocked and PI-160 must - QG-004/QG-005 remain `Explicitly Waived / Accepted Risk`, with
not start until those defects and native non-WSL Linux evidence are resolved. `realTurnVerified=false`; concurrency, credential isolation, and protocol
QG-004/QG-005 remain `Explicitly Waived / Accepted Risk`, with compatibility against real Provider accounts are not claimed as Pass.
`realTurnVerified=false`.
## Verification ## Verification
- Exact pnpm `10.33.4` frozen install passed on Windows and WSL2 Ubuntu 24.04 - Exact pnpm `10.33.4` frozen install passed on Windows and WSL2 Ubuntu 24.04
x64; the candidate stayed clean at `df1151b` and the lockfile change is limited x64; both final-product runs were bound to clean commit `0d26d17`. The
to the direct `@electron/asar@3.4.1` verifier dependency. lockfile change remains limited to the direct `@electron/asar@3.4.1`
verifier dependency.
- Candidate-final Windows checks passed: `pnpm run typecheck`; `pnpm run - Candidate-final Windows checks passed: `pnpm run typecheck`; `pnpm run
lint:check` with 0 errors and five pre-existing warnings; `pnpm test` with 178 lint:check` with 0 errors and five pre-existing warnings; focused proof tests
files, 1505 passed and two skipped; `pnpm run test:e2e` with 24/24; `pnpm run with 6 files/25 passed/2 skipped; focused concurrency tests with 4 files/26
build:vite`; and the focused final-proof suite with 6 files/32 tests. passed; `pnpm test` with 178 files/1506 passed/2 skipped; `pnpm run test:e2e`
- Final Windows NSIS `release/Makelore-2.0.0-win-x64.exe` is 208,297,927 bytes with 24/24; and repeated `pnpm run build:vite` production builds.
- Final Windows NSIS `release/Makelore-2.0.0-win-x64.exe` is 208,369,701 bytes
with SHA-256 with SHA-256
`3DDCF48D28ABA914F427DC828428E4248A9751F8A449324F48060BA981E7B3D8`. `C68DF05932055CF950A3491CB34CACB8A2D39F8F3D987B32FE4950621D1CC9B6`.
The rebuilt `win-unpacked` artifact verifier enumerated 10,278 ASAR entries, Its unpacked `app.asar` SHA-256 is
found zero product-owned OpenCode path or development path residue, and passed `F03278F6CF08B2D72F1518EFAA8338A92A8DDA0261AEEFCE82D93ACB9333F4D8`.
packaged Electron/Node/runtime/resource qualification. Structured evidence is The post-installer-build final product proof passed from that ASAR with real
in ignored release reports `pi-artifact-win-followup.json`, Pi parent/child PIDs and complete cleanup. Windows structured reports are
`pi-product-proof-win-followup.json`, and `pi-smoke-win-followup.json`. `release/evidence/pi-smoke-win-real-workers.json`,
- The Windows packaged product proof loaded Main through final `app.asar`, ran `release/evidence/pi-performance-win-real-workers.json`, and
cold/warm managed workers and the materialized extension/subagent bridge, held `release/evidence/pi-product-proof-win-final-installer-build.json`.
4 parent + 4 child workers as 8 live OS processes while the UI remained - Windows formal five-sample performance passed every budget and recorded all
interactive, and then reported zero active/waiting process-budget entries, nine cold/warm milestones with five samples each. Cold p95 was queue `0 ms`,
child permits, dispatches, parents, PIDs, and write leases. resources `32 ms`, spawn `14 ms`, RPC `718 ms`, session `4 ms`, accepted `1
- Windows formal five-sample performance evidence ms`, agent start `1 ms`, first event `0 ms`, and settled `869 ms`; warm p95
`pi-performance-win-followup.json` passed every budget. Managed cold p95 was was `0/11/8/624/1/1/0/0/64 ms`. Five 4+4 pressure samples had UI p95 `188
resources `25 ms`, spawn `13 ms`, RPC `669 ms`, session `3 ms`, accepted `1 ms`; Renderer first-commit p95 was `33.466 ms`; exit p95 was `19 ms`.
ms`, settled `309 ms`; warm p95 was `8/13/674/8/0/270 ms`. Pressure UI p95 - WSL2 Linux x64 final product was rebuilt at exact clean commit `0d26d17`.
was `176 ms`; Renderer first-commit p95 was `33.6402 ms` (max `48.8593 ms`). AppImage/DEB/RPM SHA-256 values are respectively
- WSL2 Linux final product was rebuilt at the exact same clean commit. Final RPM `38c71302e26a0f7946ffcf72e23edd176b0abc1630da62ef25a808fddb6fdd5c`,
`release/Makelore-2.0.0-linux-x86_64.rpm` has SHA-256 `7c4b29d819aba21c66abb1f41d62cd5b8aed24e44823e9eb875981133672f22b`,
`c7d7eac673abed61d83af2fbd2cc33d81ffa3b2c1e449ad89ee8f118f7400c64`. and `cf6983f64a9d2c1f1080fabd9e1724914662e559843b9ceb4f11198a7312b917`.
RPM inspection reports Name `niancode`, Version `2.0.0`, Release `1`, Arch Final ASAR SHA-256 is
`x86_64`, and contains `/opt/Makelore/niancode`, `300dfeb32ded8c6fa764c6604f7d10c175dcbdc28e219169402f65a0dd50d7f7`.
`/opt/Makelore/resources/app.asar`, and - Linux formal smoke passed Pi `0.84.2` production closure, 10,282-entry ASAR
`/opt/Makelore/resources/pi-runtime/dist/cli.js`. enumeration, zero product-owned OpenCode paths, actual final Pi processes,
- Linux artifact verification enumerated 10,280 ASAR entries and found zero real packaged extension/subagent dispatch, 4+4 pressure, and zero cleanup.
product-owned OpenCode path. WSLg launched the final packaged product from Reports copied beside the Windows evidence are
`app.asar`; extension/subagent, live 4+4/8-PID pressure, UI interaction, and `release/evidence/pi-smoke-linux-wsl2-real-workers.json`,
zero-resource cleanup all passed. Evidence is in `release/evidence/pi-performance-linux-wsl2-real-workers.json`, and
`pi-artifact-linux-rpm-followup.json`, `release/evidence/pi-product-proof-linux-wsl2-real-workers.json`.
`pi-product-proof-linux-rpm-followup.json`, and - Linux formal five-sample performance passed every budget and recorded all
`pi-smoke-linux-rpm-followup.json` in the Linux checkout's ignored nine cold/warm milestones with five samples each. Cold p95 was queue `0 ms`,
`release/evidence` directory. resources `18 ms`, spawn `5 ms`, RPC `498 ms`, session `3 ms`, accepted `1
- Linux formal five-sample report `pi-performance-linux-rpm-followup.json` ms`, agent start `1 ms`, first event `0 ms`, and settled `602 ms`; warm p95
passed every budget. Managed cold p95 was resources `14 ms`, spawn `6 ms`, was `0/5/4/492/1/1/0/1/45 ms`. Five 4+4 pressure samples had UI p95 `142
RPC `456 ms`, session `2 ms`, accepted `1 ms`, settled `284 ms`; warm p95 was ms`; Renderer first-commit p95 was `28.217 ms`; exit p95 was `9 ms`.
`4/4/465/1/1/256 ms`. Pressure UI p95 was `99 ms`; Renderer first-commit p95
was `27.897758 ms` (max `42.186106 ms`); exit p95 was `7 ms`.
- Linux results are WSL2/WSLg final-product evidence, not an independent native - Linux results are WSL2/WSLg final-product evidence, not an independent native
non-WSL Linux desktop/compositor/distribution acceptance run. Controlled non-WSL Linux desktop/compositor/distribution acceptance run. Controlled
provider-shaped smoke issued six requests per protocol (distinct cold, warm, provider-shaped smoke issued six requests per protocol (distinct cold, warm,
@@ -148,14 +161,15 @@
## Follow-ups ## Follow-ups
- Planner re-review of `c7e7772..dc166a1` returned `Standards Pass / Spec Needs - Request planner re-review of `dc166a1..0d26d17`. The implementation evidence
Fix`. ASAR enumeration and RPM are closed; final packaged subagent dispatch, now directly closes final packaged subagent dispatch, the single Main-owned
a single Main-owned cold/warm timeline including zero-valued queue wait, and cold/warm timeline including zero-valued queue wait, and real
real persistent-parent/ephemeral-child 4+4 pressure remain P1. persistent-parent/ephemeral-child 4+4 pressure. The concurrent catalog-write
- Do not start PI-160 or integrate `df1151b` while PI-150 remains blocked by the fix and its regression test are also included.
accepted platform evidence boundary. If the planner accepts the five fixes, - Do not start PI-160 or integrate the candidate while PI-150 remains blocked
keep PI-150 as the active frontier until the missing platform decision or by the native non-WSL Linux platform evidence boundary. If the planner finds
evidence is resolved. no new implementation defect, keep PI-150 as the active frontier until that
external evidence is supplied or its gate is explicitly re-decided.
- Keep missing macOS x64/arm64 artifact/runtime/resource/performance evidence as - Keep missing macOS x64/arm64 artifact/runtime/resource/performance evidence as
`Deferred to PI-160 / Not Pass`; do not promote a final cross-platform release `Deferred to PI-160 / Not Pass`; do not promote a final cross-platform release
without independent macOS execution, but do not use it to block PI-150. without independent macOS execution, but do not use it to block PI-150.