Files
makelore/.project-docs/30-worklog/tasks/20260902-local-skill-install-fix-6b3e91a4.md
T

7.5 KiB

Task: Fix packaged local Skill installation

Identity

  • Task ID: 20260902-local-skill-install-fix-6b3e91a4
  • Mode: Feature
  • Branch: codex/20260902-local-skill-install-fix-6b3e91a4-local-skill-install-fix
  • Worktree: D:\Datas\OthersProjects\makelore-local-skill-install-fix-6b3e91a4
  • Base commit: 28e1690038
  • Owner: codex-root
  • Status: Ready for Integration

Scope

  • Fix packaged conversation-driven Device Package installation after the bundled Pi CLI succeeds but the Main-owned package inspection path fails to load its production dependency closure.
  • Add a red/green packaged-runtime regression for the lazy package-manager boundary.
  • Preserve closed Device Package errors across the Pi extension bridge so supported-source dependency failures and unsupported source syntax no longer collapse to the same generic Bridge request failed response.
  • Rebuild and verify the Windows app.asar/product artifact, then execute the real packaged npm and Git prepare paths without committing a package.

Intent And Constraints

  • Keep the accepted Device Packages product model unchanged: installation is initiated only through conversation tools; preview and a distinct later confirmation precede commit; packages are local Main-owned immutable generations; lifecycle scripts stay disabled; only future/idle parent workers receive resources and child workers remain empty.
  • Work only in the isolated feature worktree from exact client main 28e1690038d61b9333a2f6ca77f0187ea4273676. Preserve the three unowned task records in the client root and do not reset, stash, clean, adopt, or modify that worktree.
  • Do not add a global Pi CLI requirement, visible installer, Account Library, Marketplace Release/Admission, hosted Web Search, Provider, server, billing, deploy, publish, push, or PR behavior.
  • Avoid leaking local paths, stacks, credentials, or raw dependency diagnostics to Pi/Renderer. Only closed Device Package codes and bounded public messages may cross the bridge; internal errors may be logged in Main.
  • The prior diagnosis is accepted evidence: installed bundled Pi npm/Git resolution succeeds, while importing the packaged @earendil-works/pi-coding-agent graph fails because partial-json@0.1.7 is absent from app.asar.

Concurrent Task Gate

  • check_project_docs passed for the client root.
  • task_context start created the exact isolated worktree/branch/base recorded above; status --json confirmed matching task, owner, mode, branch, worktree, and base.
  • The client root remains on main with exactly three pre-existing untracked task records; none was copied as a change or adopted.
  • The only semantically adjacent registered peer is the older native Web Search client coordinator. Its task record owns hosted/model-tool composition, not Device Package manager loading, bridge error projection, or packaging closure; no semantic or file-ownership conflict is present.
  • Gate result: Passed.

Project Context Loaded

Read the project memory entry, active record, positioning/current state, decision index, ADR-006, system/module/data-flow architecture, business rules, success criteria, evidence/reflection/commitment/stale indexes, the completed Model Tools and Device Packages integration record, the relevant peer record, and the prior diagnosis record.

Relevant understanding:

  • Electron Main owns package bytes, inspection, durable generations, Pi resource materialization, and packaged dependency authority; Renderer/Pi receive only closed projections.
  • The current integrated frontier deliberately lazy-loads the ESM-only Pi package manager for remote installs. Workspace tests passed, but packaged signed-in installation remained an explicit acceptance gate and the installed artifact now proves that its ESM dependency closure is incomplete.
  • ADR-006 explicitly requires installed-package regressions to be exercised against final app.asar and packaged runtime roots.
  • Likely owned modules are electron/coding-packages/**, the Pi extension bridge, artifact verification scripts/tests, and the root production dependency lock.
  • Planning Gate result: Passed.

Outcome

  • Replaced the packaged Device Package inspection dependency on the incomplete app.asar Pi graph with the already-distributed physical resources/pi-runtime/dist/index.js authority used by the bundled Pi CLI.
  • Preserved closed local_package_* failures through Main's worker bridge and the generated Pi extension while keeping unknown failures generic.
  • Added an artifact gate that rejects a Main-reachable bare @earendil-works/pi-coding-agent dynamic import and proves that the packaged physical runtime exposes DefaultPackageManager and SettingsManager.inMemory.
  • Bumped the generated MakeLore Pi extension generation so new workers cannot reuse stale bridge code.
  • Produced a final Windows x64 product at source commit 5a2f0eb6785b59d8b455ed5cb1d9773351ff895a. No package was committed to the user's Device Package store and the installed MakeLore application was not replaced.

Verification

  • Installed-artifact RED: importing the installed app.asar Pi graph failed with ERR_MODULE_NOT_FOUND for partial-json; importing its physical resources/pi-runtime/dist/index.js succeeded with both required exports.
  • TDD RED: the new Device Package manager regression attempted the unavailable app Pi graph; the real worker bridge reduced a closed failure to Bridge request failed; the artifact gate accepted the stale bare import.
  • Focused and adjacent unit tests: 8 files, 69 passed.
  • Full unit suite: 222 files, 1815 passed, 2 skipped; pressure test 1 passed. The first run saw two Windows spawn EBUSY failures while Electron was first downloaded; that file then passed 3/3 alone and the complete rerun passed.
  • pnpm typecheck: passed.
  • Scoped ESLint for every changed TypeScript/JavaScript source and test: passed.
  • pnpm run build:vite: passed; generated Main contains the physical runtime loader and no bare dynamic import of @earendil-works/pi-coding-agent.
  • Final source/runtime acceptance used the Windows product executable, physical Pi CLI/runtime, and self-contained npm runtime from release/win-unpacked. Prepare succeeded without commit for a loose SKILL.md, npm:pi-web-search, and https://github.com/DietrichGebert/ponytail; the latter projected six Skills plus one Pi extension.
  • pnpm run package:stage:win-x64 and Electron Builder/NSIS: passed. The installer is 208,323,462 bytes with SHA-256 A5CA7422B3962ABF6B0391B73EC26C7600D962630289F0EFE3BAFDD03A3B97E1.
  • pnpm run verify:artifact:win: passed against source/verification head 5a2f0eb6785b59d8b455ed5cb1d9773351ff895a; Electron 43.4.0, Node 24.18.1, Python, uv 0.10.0, npm 11.6.2 and native modules were verified from the final product. The pinned Python/uv staging was reused from the existing root after a fresh Python archive fetch stalled; the verifier proved the copied runtimes rather than treating the network attempt as evidence.
  • pnpm run verify:artifact:pi: passed. Its new Device Package evidence is authority=bundled-pi-runtime, appAsarRootImport=false, and both package manager exports are functions; Pi 0.84.2 closure and runtime probes passed.
  • git diff --check: passed.

Follow-ups

  • Integrate the source commit onto client main, rebuild from that exact frontier if a main-line installer is required, then install/restart MakeLore before retrying the conversation-driven prepare/confirm flow.

Promotion Candidates

  • None recorded.