Files
makelore/.project-docs/30-worklog/tasks/20260902-model-tools-client-integration-5d8b2f73.md

8.4 KiB

Task: Model Tools and Device Packages client integration

Identity

  • Task ID: 20260902-model-tools-client-integration-5d8b2f73
  • Mode: Integration
  • Branch: codex/20260902-model-tools-client-integration-5d8b2f73-model-tools-client-integration
  • Worktree: D:\Datas\OthersProjects\makelore-model-tools-integration-5d8b2f73
  • Base commit: 841273b433
  • Owner: codex-root
  • Status: Ready for Integration

Scope

  • Implement the MakeLore half of the accepted Model Tools and Device Packages specification from exact base 841273b43354b2237a52a7081a9fceb647ef4e3f.
  • Add the closed selected-model web_search tool, a Main-owned conversation-driven Device Package manager, immutable parent-worker resource materialization, and a split Official Plugins / Device Installed view in My Plugins.
  • Remove the old hosted Web Search client/package path only after the new model-tool composition is working; keep Game Resource and other official plugins unchanged.
  • Own the client integration record and final canonical-memory reconciliation.

Intent And Constraints

  • There is no visible install/source-picker entry. Installation is initiated by conversation tools, requires a preview and a distinct later user-confirmation turn, and accepted packages default to enabled for the next parent generation.
  • Device Packages are local to this OS user and never join Account Library, Admission, Release, Channel, or Marketplace Package Store state.
  • Executable Pi extensions run with desktop-user authority; the confirmation must state that plainly. P0 does not claim a sandbox or load packages into child agents.
  • Web Search uses the frozen selected model/provider/credential and never falls back to agent_browser, a separate model, hosted Web Search client, or Plugin Charges.
  • The two user-owned untracked files in D:\Datas\OthersProjects\makelore remain untouched; all product work occurs in this linked worktree.
  • No live paid Provider request, production install, publish, push, or PR is authorized by this implementation task.

Concurrent Task Gate

  • Task ID: 20260902-model-tools-client-integration-5d8b2f73
  • Mode: Integration
  • Branch: codex/20260902-model-tools-client-integration-5d8b2f73-model-tools-client-integration
  • Worktree: D:\Datas\OthersProjects\makelore-model-tools-integration-5d8b2f73
  • Base commit: 841273b43354b2237a52a7081a9fceb647ef4e3f
  • Ownership result: Claimed in an independently created linked worktree; the client integration lock belongs to this task.
  • Other local registry entries are historical isolated planning/ready tasks; none owns this worktree or the planned model-tool/device-package files. The two untracked root records were neither copied as changes nor claimed.
  • Gate result: Passed.

Project Context Loaded

Read:

  • .project-docs/05-agent-entry/{read-before-coding,concurrent-task-gate,planning-gate,memory-index}.md
  • project positioning/success criteria, current state, decision index, architecture, data flow, business rules/glossary, evidence/reflection indexes, commitments and stale-items registry
  • the accepted server-repository design and implementation Spec, proposal, and completed design task for the three-domain cutover
  • current Pi worker/resource loading, official Plugin resolver/Package Store, atomic JSON utilities, product composition, model capability parser, My Plugins, and their focused tests identified by the Spec

Relevant understanding:

  • Project goal: Electron Main owns credentials, local package bytes, effective resources, and worker generations; Renderer and Agent inputs receive only closed projections.
  • Current focus: make Web Search a selected-model core tool and let conversation install local Skills/Pi extensions that appear under Device Installed.
  • Active constraints: Pi 0.84.2, explicit --extension/--skill loading with discovery disabled, atomic durable index, no lifecycle scripts, parent-only P0, and safe refresh after the current turn.
  • Decisions affecting this task: no visible installer, automatic post-confirmation loading, Official/Device inventory split, no Web Search Marketplace card, and no dual hosted/model-tool runtime.
  • Evidence/commitments: current Pi runtime and Marketplace boundaries are already integrated; exact packaged and live Provider acceptance remains a later gate.
  • Likely modules: imported model/profile parsing, Pi provider/runtime composition, new electron/coding-packages/**, effective resources/worker lifecycle, Main-local management routes, My Plugins store/page, conversation protocol and artifact tests.
  • Unknowns/conflicts: provider-native Web Search must remain unavailable for any selected model lacking a proven closed capability; a third-party package manifest alone is not evidence that its tool supports Bailian/DeepSeek.
  • Planning Gate result: Passed.

Outcome

  • Added a closed parent-only makelore_web_search model tool. Its registry reads the frozen selected-model capability, keeps the same provider/credential/model, emits the verified provider-native forced-search request shape, and never falls back to agent_browser, a second model, the removed hosted client, or Plugin Charges.
  • Added a Main-owned Device Package deep module with conversation tools for inspect/preview, confirm/install, list, enable/disable, and uninstall. It accepts npm, Git, absolute local Plugin directories, and loose SKILL.md sources; lifecycle scripts are disabled and executable extensions require the explicit desktop-authority warning.
  • Device packages commit as immutable generations, default enabled, and automatically refresh new/idle parent workers. Active workers retain the frozen generation until settlement, and child workers receive no Device Package resources.
  • My Plugins now separates Official Plugins and Device Installed. It exposes no visible installer/source picker. Device state does not enter Account Library, Release, Channel, Admission, Marketplace Package Store, project enablement, or Agent assignment.
  • Removed the old Hosted Web Search package definition, Main client/adapter, conversation envelope cases, artifact authority, and associated tests while preserving Game Resource and generic Marketplace behavior.

Verification

  • TDD and focused model-tool/device-package/resource/route/Renderer tests passed; final focused Device Package slice: 4 files / 15 tests.
  • Full unit suite: 218 files, 1,786 passed, 2 skipped; pressure test 1 passed. One initial run saw two unchanged real-Pi spawn EBUSY failures; the isolated retry passed 3/3 and the full suite then passed.
  • pnpm typecheck passed. Full lint passed with 0 errors and 5 unchanged warnings in Home/Makelore.
  • Vite Renderer/Main/Preload/utility production build and Pi win32-x64 runtime staging passed; Renderer transformed 2,275 modules and the staged Pi closure contains 130 packages / 6 assets.
  • Windows Electron lifecycle suite passed 6/6 on clean retry. The first run's six tests passed but Electron returned a transient Windows access-violation exit code afterward.
  • git diff --check passed.
  • Exact committed-head Windows packaging passed from 0c54d874cf3d21f6694b9a246e3d11b68817234a. The first aggregate wrapper reached the external GitHub uv download and failed with ECONNRESET; the already verified local uv 0.10.0 binaries were then reused, after which staging, electron-builder, NSIS signing, verify:artifact:win, and verify:artifact:pi all passed.
  • The installer is 208,279,484 bytes with SHA-256 7F9AA7DC598256673D13C1FA103C1BEE173691F4A329B6F73BCBDA34CFF6C335. Artifact metadata records both gitCommit and verificationHead as the exact committed head. The packaged Plugin inventory is exactly Data Service + Game Resource; selected-model Web Search and Device Package authority are both proven reachable from app.asar, with no Hosted Web Search Provider authority.

Follow-ups

  • HOLD: packaged signed-in conversation acceptance for one loose Skill, one fixture Pi extension, and a live npm:pi-web-search install with network access.
  • HOLD: real selected-model Web Search through the deployed AI Gateway requires explicit paid-Provider authorization and a supported credential/model.
  • Independent fixed-range Standards and Spec reviews remain the next gate after the paired commits are integrated.

Promotion Candidates

  • Keep the model-tools/device-packages proposal pending until packaged install and live model-search acceptance satisfy its promotion criteria.