8.9 KiB
8.9 KiB
Task: Implement PI-050 worker pool and session registry
Identity
- Task ID: 20260822-pi-worker-pool-8a4e2c91
- Mode: Feature
- Branch: codex/20260822-pi-worker-pool-8a4e2c91-pi-worker-pool
- Worktree: D:\Datas\OthersProjects\makelore-pi-worker-pool-8a4e2c91
- Base commit:
161f3f471b - Owner: codex
- Status: Completed
Scope
- Implement PI-050 on top of PI-040 commit
161f3f471bfdb66fc8d9bb941d9e5e78abe13ea7. - Own
electron/coding-runtime/pi/runtime.ts, worker-pool/session-registry/permit-queue/idle-LRU orchestration, and focused tests. - Provide per-Conversation worker ownership, lazy prepare/session hydration, caps, fair queueing, stale rebuild, crash/recover/dispose/quit cleanup, and privacy-safe milestone correlation.
- Keep Host API, Renderer, event/session projection, extensions/subagents/write leases, and migration cutover in their later PI tickets.
Intent And Constraints
- Follow planner task
20260822-pi-runtime-spec-b6e2c9a4, ticketPI-050 — Worker pool and session registry. - A worker may own exactly one product Conversation/Pi session; running workers are never evicted.
- Top-level running cap is 4, warm idle cap is 4, total parent/child process soft-cap integration remains compatible with the later child-worker ticket.
- Prompt/steer/follow-up resolve on RPC acceptance, not
agent_settled; onlyagent_settledreleases the top-level permit. - Reuse PI-040 credential projection, managed-input args, refresh coordinator, and revision coordinator. Secrets stay in child environment/redaction only.
- Real external Provider validation remains Explicitly Waived / Accepted Risk with
realTurnVerified=false; provider-shaped packaged loopback remains required evidence. macOS validation remains deferred to PI-150. - The implementation must stay surgical: no Host API/Renderer wiring, no speculative feature flags or compatibility layer, and no incidental OpenCode/template refactor.
Outcome
- Planner audit of commit
9f55eecfound and the follow-up fixes close two reproducible acceptance gaps: stale rebuild now re-runs idle LRU, and concurrentrecover()reuses an existing rebuild flight rather than spawning an unowned second replacement. - Implemented the PI-050 runtime/pool/registry seam with one persistent Pi worker session per Conversation, generation-scoped resources, cap-4 fair top-level scheduling, idle LRU, and a shared default-eight process budget for later child workers.
- Wired the PI-040 managed resource, credential projection, revision, and single-auth-refresh contracts into worker open/reopen. Cross-account model changes rebuild only the target worker so the new Provider credential remains generation-isolated; active runs settle before that rebuild.
- Added targeted recover/dispose/fork/settings/queue/compact/abort orchestration, new-generation
get_state/get_entriesfetch plus snapshot replacement, privacy-safe milestone correlation, and bounded pool shutdown. PI-060 retains ownership of projecting the returned session tree into transcript nodes. - Prompt/steer/follow-up now distinguish RPC acceptance from authoritative
agent_settled; rejected queue/abort/compact mutations do not leave false accepted state. Worker crash, stale rebuild, cross-account reconfiguration, and explicit recover publish isolated generations without replaying an uncertain prompt. - Shutdown rejects new/queued work, waits for in-flight prepare/fork/rebuild openings, cancels generation-scoped command/interaction/child references, and stops all parent workers. Running workers are excluded from LRU eviction.
- Real external Provider validation remains Explicitly Waived / Accepted Risk and was not run;
realTurnVerified=false. macOS remains deferred to PI-150.
Verification
- Final focused suite: 7 files / 36 tests passed, covering prepare/binding single-flight, cap-4 FIFO permits, default-eight shared process budget, running-safe idle LRU including post-rebuild trimming, generation resource cleanup, stale revisions, rebuild/recover single-flight, in-flight shutdown, RPC acceptance/rejection, model/thinking target isolation, one-refresh auth recovery, recover/fork/dispose, managed credentials/resources, and a two-real-child-process abort-isolation integration.
corepack pnpm run typecheck: passed.corepack pnpm run lint:check: passed with 0 errors and 6 pre-existing warnings outside PI-050 files.corepack pnpm test: 193 files / 2171 tests passed after the planner-audit fixes.corepack pnpm run build:vite: passed for Renderer, Main, Preload, and release utility output; existing dynamic-import and chunk-size warnings remain unchanged.corepack pnpm run test:electron:windows: 1 file / 3 tests passed. No Host API or Renderer behavior is wired in PI-050, so there was no applicable user-visible Playwright spec to add or run.node scripts/probe-pi-provider-contracts.mjs --timeout-ms 30000: all four local provider-shaped contracts passed with distinct sessions, overlapping two-worker image turns, target-only abort, environment credential references, and clean stdin-close. The report explicitly retainedrealTurnVerified=falseandrealProviderDecision=explicitly-waived-accepted-risk.node scripts/probe-pi-packaged-runtime.mjs --samples 1 --timeout-ms 30000: Windows x64 production-shaped closure contained all 130 expected packages and 6 runtime assets; session/reopen/abort/settle/two-worker isolation and all four packaged Provider-shaped contracts passed. The aggregate result intentionally remainspartial-pass/incomplete: Linux aggregation is outside this Windows task, macOS is deferred, and real Provider evidence is waived rather than passed.- Existing Pi RPC process-tree test passed in the full suite, including forced Windows descendant cleanup; the PI-050 process integration additionally ended both parent workers and returned the shared process budget to zero.
git diff --check: passed before task documentation completion.
Follow-ups
PI-060owns durableget_entriesactive-branch projection, live-event reduction, settled reconciliation, and full recovery hydration. It should consume the generation replacement/fetch seam without moving Pi wire fields into Renderer contracts.PI-080should receive the samePiProcessBudgetinstance for child workers and register child cancellation through generation resources, preserving the global parent/child soft cap of 8.PI-100may expose only sanitized runtime/telemetry summaries through Host API; PI-050 worker/session/credential objects remain Main-private.- Real Provider authentication, protocol/account variation, rate limiting, true-provider concurrency, credential isolation, abort/session/model/image behavior remain explicitly accepted unverified risk with
realTurnVerified=false. macOS x64/arm64 remains deferred to PI-150.
Promotion Candidates
- Target: Pi runtime orchestration guidance and
PI-080child scheduler. Proposal: use one shared FIFOPiProcessBudget(default 8) across parent and child worker owners; every successful process open owns one idempotent lease until bounded stop, while pool-specific shutdown cancellation removes only that owner's waiters. Evidence: focused tests hold a third parent until a lease is released, cancel in-flight opens during shutdown, and verify two real child processes return the budget to zero. Future impact: PI-080 can enforce the locked global process soft cap without adding a second counter or coupling child scheduling to the parent pool internals. Semantic conflicts: none found. Human confirmation required: no. - Target: Pi credential isolation and model-switch architecture.
Proposal: same-account model changes may use Pi
set_model; cross-account changes must persist the target model then rebuild only that Conversation worker, deferring rebuild untilagent_settledwhen a run is active so each generation receives only its selected account credential environment. Evidence: runtime tests prove target-only generation replacement and sibling preservation; managed opener tests prove credentials remain in worker environment/redaction rather than argv/catalog/telemetry. Future impact: preserves PI-040 credential projection when Host API/Renderer model switching arrives, without broadening worker environments to every account secret. Semantic conflicts: none found. Human confirmation required: no. - Target:
PI-060generation/recovery architecture. Proposal: every worker replacement publishes a fresh generation Snapshot seam; explicit recover and auth reopen fetchget_state/get_entries, clear generation-scoped interactions, and never replay an uncertain prompt. Evidence: generation-gap regression, one-refresh/two-auth-failure, target recover, stale rebuild, and crash cleanup tests pass. Future impact: lets the projector own transcript reconstruction while the pool remains authoritative only for process/session lifecycle. Semantic conflicts: none found. Human confirmation required: no.