Files
makelore/.project-docs/30-worklog/tasks/20260825-pi-submit-rejected-hotfix-9f3c7a62.md
T

161 lines
9.0 KiB
Markdown

# Task: Fix Pi Works submit rejection and retry lock
## Identity
- Task ID: 20260825-pi-submit-rejected-hotfix-9f3c7a62
- Mode: Feature
- Branch: codex/20260825-pi-submit-rejected-hotfix-9f3c7a62-pi-submit-rejected-hotfix
- Worktree: D:\Datas\OthersProjects\makelore-pi-submit-rejected-hotfix-9f3c7a62
- Base commit: 4580568384f5391f2030bde57c63ff90891172b3
- Owner: codex-root
- Status: Ready
## Scope
- Fix the installed Windows Pi path where the Works Square OpenAI-completions
endpoint rejects Pi's leading `developer` message, by projecting the pinned
Pi `supportsDeveloperRole: false` compatibility only for the actual Works
gateway/proxy managed-model account modes.
- Make a definite prompt submission rejection restore the target Conversation's
draft and attachments as a retryable submission error that clears when the
user edits/retries, without poisoning persistent runtime preparation state.
- Add focused provider/Renderer isolation and no-replay regressions, then build
and verify a new Windows x64 NSIS through final packaged Main/UI proof.
## Intent And Constraints
- Keep the Pi hard cutover, Pi `0.84.2`, Main-owned Provider/secret boundary,
existing Host proxy body forwarding, and one runtime path. Do not add an
OpenCode fallback, compatibility dual track, generic body rewrite, Provider
watchdog, or Pi upgrade.
- Verify the actual Provider catalog before selecting account kinds. Preserve
built-in/direct/custom OpenAI-compatible auto-detection and do not alter
OpenAI Responses, Anthropic, Google, local Provider, image, tool, session, or
child behavior.
- A definite rejection is target-scoped submission feedback. Preserve genuine
runtime/session/preparation errors and their Recover semantics; preserve
uncertain request reconciliation and never automatically replay an accepted
or uncertain prompt.
- Error text must be stable, actionable Chinese and must not expose upstream
body, prompt, headers, credentials, session content, or complete paths.
- Do not modify the read-only diagnostic worktree, dirty/occupied `main`, the
previous cumulative worktree, or the user's installed application under
`D:\Tools\泥土\niancode\Makelore`. Do not use subagents.
- Real external Provider verification remains `Explicitly Waived / Accepted
Risk` with `realTurnVerified=false`; the controlled Works-shaped endpoint is
not a full Provider-matrix Pass.
## Project Context Loaded
- Concurrent Task Gate passed: task ID, feature mode, branch, absolute worktree,
base commit, task record, ownership, and reservation match the local registry.
- Base `4580568384f5391f2030bde57c63ff90891172b3` is both the cumulative delivery
HEAD and the diagnostic HEAD, so the implementation loses no prior Pi hotfix.
- Planning Gate passed after reading entry/memory/current-state, positioning,
decisions, architecture/data-flow, domain/success, evidence/reflection,
commitments/stale records, the Pi cutover and resilience contracts, cumulative
Pi tasks, and planning peer scopes.
- Shared integrated memory predates the Pi chain and retains older OpenCode
wording. Current source, the cumulative Pi task/spec, and the read-only
diagnostic record are authoritative for this hotfix. The entry document's
shorthand paths for memory/current-state are stale; the actual files are under
`05-agent-entry` and `30-worklog`.
- The diagnostic task is the only directly overlapping peer and explicitly owns
evidence/red tests, not product implementation. Other planning tasks are
isolated, older, unrelated, or have undefined scope; no unresolved semantic
conflict changes this repair.
- Source verification confirmed exactly two managed Works credential modes:
`works_square_ai_gateway` and `works_square_ai_gateway_proxy`; both use
OpenAI Completions. Direct/custom accounts retain Pi auto-detection.
- The locked Pi `0.84.2` models schema accepts `supportsDeveloperRole`, and its
OpenAI Completions adapter selects `system` when the explicit value is false.
- Gate result: Passed.
## Plan
1. Inspect the diagnostic red-test diff and actual Provider catalog, DTO,
managed-model projection, Renderer submission state, and packaged proof seam.
2. Recreate the two red regressions in this task and add direct/custom,
cross-Conversation, second-submit, and uncertain no-replay coverage.
3. Implement the smallest Works-only compat projection and target-scoped
definite-rejection cleanup; do not modify Host proxy bodies or runtime errors.
4. Run frozen install, focused tests, typecheck, lint, full unit, production
build, and Windows Electron E2E; fix only task-caused failures.
5. Commit a clean candidate, run formal Windows packaging and artifact closure
checks, then prove final-ASAR Works-shaped reject/system acceptance and real
UI reject/edit/retry/settle/cleanup with `realTurnVerified=false`.
6. Record exact commits, changed files, verification, installer size/hash,
packaged evidence, waivers, registry status, and clean state; complete the
Task Documentation Gate.
## Outcome
- Implemented the Works-only managed-model compat override after imported model
capability merging, so both gateway paths materialize
`supportsDeveloperRole: false` without changing direct/custom or other APIs.
- Definite and uncertain submission failures remain request/submission state;
they restore the target draft without writing the Conversation entry's
persistent preparation error. Existing runtime/session recovery state remains
reserved for preparation, hydration, worker, and session failures.
- Extended the final packaged proof with a Works-shaped endpoint role canary and
a real Renderer reject/edit/retry/settle flow. The endpoint rejects leading
`developer`, while an E2E-only one-shot Main service rejection exercises the
distinct definite-POST branch before the retry reaches the real Pi runtime.
The extension and proxy proof provider modes are protected by a focused
wiring regression.
- Implementation commits are `5f0ef761eaab8ac397ce83a5cfdb152579c4e86a`
(`fix(pi): recover from Works prompt rejection`) and
`e3debc9b3337ff20594997f445500e19c288dc64`
(`test(pi): separate submit rejection proof`). This task record is the final
documentation-only commit before producing the immutable installer candidate.
- Changed product/proof files: `electron/coding-runtime/pi/provider-config.ts`,
`electron/coding-runtime/pi/release-proof.ts`,
`scripts/run-pi-subagent-packaged-smoke.mjs`,
`src/stores/coding-conversations.ts`, and four focused unit suites plus the
release-proof wiring suite.
## Verification
- `corepack pnpm install --frozen-lockfile` — Pass; pnpm `10.33.4`, Pi `0.84.2`.
- Initial diagnostic red command — Expected fail: 2 files / 2 tests failed,
23 passed; missing compat and permanently disabled retry reproduced.
- Focused regressions — Pass: 4 files / 49 tests, including proof wiring.
- `corepack pnpm run typecheck` — Pass (rerun after proof wiring correction).
- `corepack pnpm run lint:check` — Pass with five pre-existing warnings and no
errors.
- `corepack pnpm test` — Pass: 180 files; 1523 passed, 2 skipped.
- `corepack pnpm run build:vite` — Pass; Renderer/Main/Preload/utility built,
with existing chunk/dynamic-import warnings.
- `corepack pnpm run test:electron:windows` — Pass: 2 files / 4 tests.
- The first packaged proof attempt correctly showed that a Provider HTTP 400
after Pi prompt preflight is an accepted-run failure, not a definite POST
rejection; it did not restore the draft and the proof failed. The proof was
corrected to keep role rejection and definite submission injection separate.
- After that correction, focused, typecheck, lint, full unit, `build:vite`, and
Windows Electron E2E were rerun and passed with the same counts/warnings.
- A formal clean-HEAD `package:win` qualification, Windows artifact/closure
verifier, Pi runtime/closure verifier, and packaged Main/UI proof all passed
before this documentation commit. The packaged proof established:
Works-shaped `developer` rejection and `system` acceptance; zero Provider
requests for the injected definite rejection; draft restoration and enabled
retry after edit; a settled retry through the actual packaged Pi runtime;
parent/child requests using only `system`; current Host-token use without
argv/models/log/diagnostic leakage; no permanent submitting/recovering or
runtime-unavailable banner; and zero residual Electron/Pi proof processes.
- Formal packaging and those three artifact/product verifiers are rerun after
this record is committed so the reported NSIS fingerprint is bound to the
final clean cumulative HEAD. The exact absolute path, size, SHA-256, and final
reports are intentionally recorded in the immutable handoff rather than by a
post-package source commit that would move HEAD.
- Real external Provider verification remains explicitly waived and accepted
risk (`realTurnVerified=false`). Controlled loopback/fault injection is not a
full Provider Pass; macOS and native non-WSL Linux status are unchanged.
## Follow-ups
- None recorded.
## Promotion Candidates
- None recorded.