Files
makelore/.project-docs/30-worklog/tasks/20260824-pi-release-proof-3e725ac7.md
T

194 lines
11 KiB
Markdown

# Task: Implement PI-150 packaging, E2E, and performance proof
## Identity
- Task ID: 20260824-pi-release-proof-3e725ac7
- Mode: Feature
- Branch: codex/20260824-pi-release-proof-3e725ac7-pi-release-proof
- Worktree: D:\Datas\OthersProjects\makelore-pi-release-proof-3e725ac7
- Base commit: 977445ba450f4ad32b6e6db2caf048517513ab39
- Owner: codex-root
- Status: Ready for Planner Re-review (PI-150 remains externally blocked by native non-WSL Linux evidence)
## Scope
- Implement and verify `PI-150 — Packaging, E2E, and performance release proof`
from cumulative PI-140 delivery base `977445b`.
- Own final Pi production-closure staging, electron-builder wiring, artifact
verification, actual packaged Pi/provider-shaped smoke, Coding Electron E2E,
performance evidence, release note/runbook draft, and README current-state
updates.
- Produce Windows x64 and Linux x64 final-product artifact evidence available
from this host. Keep canonical `.project-docs` updates for PI-160 Integration
Gate; this feature record contains the task-scoped evidence and promotion
candidates.
## Intent And Constraints
- Preserve Main-owned runtime/provider/credential boundaries, the exact pinned
Pi package and pnpm versions, Makelore app identity, project-scoped state, and
the single light product system.
- Final artifact checks must prove Pi version/engine/entry/resources/production
closure/`get_state`, extension and skill presence, no OpenCode production
residue, and no development-machine absolute path.
- `smoke:pi:real` means the actual Pi process seam from the final artifact using
controlled loopback/provider-shaped endpoints. Real external Provider
Accounts and real-provider two-worker turns are explicitly waived accepted
risks, never Pass; every substitute report retains
`realTurnVerified=false`.
- The user explicitly skipped macOS validation. Do not manufacture or reuse
static/cross-platform evidence for macOS x64 or arm64. Per the planner's
second review this evidence is deferred to PI-160: it remains Not Pass and a
final cross-platform release blocker, but is not a PI-150 blocker.
- The canonical project memory at this base is stale and still describes
OpenCode. Treat the planner-owned PI Spec/ticket and current source as the
task authority; do not edit canonical memory in this feature worktree.
- The main worktree is occupied by an older integration task. Remain rooted in
this isolated worktree and do not inspect or modify peer uncommitted files.
## Plan
1. Audit the cumulative PI-140 tree against every PI-150 packaging, smoke,
E2E, performance, release-note, and README requirement; reuse only verified
existing seams and identify concrete missing behavior.
2. Implement focused missing harnesses/wiring/tests with behavior-level
regression coverage, then run typecheck and relevant unit tests.
3. Run the full pinned validation set and build the Windows x64 final product
artifact; run its verifier, actual packaged Pi/provider-shaped smoke, and
required performance scenarios with structured statistics.
4. Use WSL2 only if available to perform a frozen Linux x64 install, final
product build, verifier/smoke, and performance run; label any environment or
artifact limitation precisely.
5. Record reproducible commands/results, accepted Provider risk, skipped macOS
release blocker, release note/runbook, README delta, and PI-160 promotion
candidates; complete the Task Documentation Gate without overstating
release readiness.
## Outcome
- Final code candidate `0d26d17cfc5d32c91d6e25d919be1fabd94a605b`
closes all three P1 implementation/proof defects from the planner's second
review. Final-product proof now runs Main from packaged `app.asar`, starts the
packaged `resources/pi-runtime/dist/cli.js`, receives a real `subagent` tool
call from a controlled loopback provider, dispatches through the real
`PiSubagentScheduler`, and starts a real ephemeral Pi child with exactly the
`find`, `grep`, `ls`, and `read` tools.
- Each cold and warm proof is one Main-owned correlated timeline containing
`worker.queue_wait`, `resources.ready`, `worker.spawn`, `rpc.ready`,
`session.open`, `prompt.accepted`, `agent.start`, `provider.first_event`, and
`agent.settled`. Direct admission emits an explicit zero-duration queue wait;
reopening the same session after a resource rebuild is correctly classified
as warm.
- The 4+4 pressure proof now holds four real persistent Pi parents and four
real ephemeral Pi children as eight distinct live OS processes while four
write leases are active, proves the product UI remains interactive, and then
proves all processes, provider requests, process-budget entries, child
permits, dispatches, parents, and write leases return to zero.
- Real concurrent parent startup exposed a supported Windows failure in the
shared managed provider catalog: simultaneous temporary-file renames could
fail with `EPERM`. Same-path catalog writes are now serialized, with focused
concurrency regression coverage. This is a product fix, not a proof-only
workaround.
- Windows x64 and WSL2 Linux x64 final products passed Pi `0.84.2`
production-closure, packaged composition, lifecycle, controlled
provider-shaped, real parent/child extension execution, 4+4
pressure/isolation, cleanup, and performance qualification. Windows NSIS and
Linux AppImage/DEB/RPM distributables were produced.
- Full ASAR enumeration found zero product-owned OpenCode paths. Exact matches
under the pinned upstream `@earendil-works/pi-ai/dist/providers/opencode*`
closure remain classified separately because Pi imports them; they are not
Makelore-owned runtime residue.
- PI-150 remains blocked only by the missing independent native non-WSL Linux
desktop/compositor acceptance evidence. WSL2/WSLg is useful final-product
evidence but is not relabelled as that native environment. PI-160 must not
start while this blocker remains.
- QG-004/QG-005 remain `Explicitly Waived / Accepted Risk`, with
`realTurnVerified=false`; concurrency, credential isolation, and protocol
compatibility against real Provider accounts are not claimed as Pass.
## Verification
- Exact pnpm `10.33.4` frozen install passed on Windows and WSL2 Ubuntu 24.04
x64; both final-product runs were bound to clean commit `0d26d17`. The
lockfile change remains limited to the direct `@electron/asar@3.4.1`
verifier dependency.
- Candidate-final Windows checks passed: `pnpm run typecheck`; `pnpm run
lint:check` with 0 errors and five pre-existing warnings; focused proof tests
with 6 files/25 passed/2 skipped; focused concurrency tests with 4 files/26
passed; `pnpm test` with 178 files/1506 passed/2 skipped; `pnpm run test:e2e`
with 24/24; and repeated `pnpm run build:vite` production builds.
- Final Windows NSIS `release/Makelore-2.0.0-win-x64.exe` is 208,369,701 bytes
with SHA-256
`C68DF05932055CF950A3491CB34CACB8A2D39F8F3D987B32FE4950621D1CC9B6`.
Its unpacked `app.asar` SHA-256 is
`F03278F6CF08B2D72F1518EFAA8338A92A8DDA0261AEEFCE82D93ACB9333F4D8`.
The post-installer-build final product proof passed from that ASAR with real
Pi parent/child PIDs and complete cleanup. Windows structured reports are
`release/evidence/pi-smoke-win-real-workers.json`,
`release/evidence/pi-performance-win-real-workers.json`, and
`release/evidence/pi-product-proof-win-final-installer-build.json`.
- Windows formal five-sample performance passed every budget and recorded all
nine cold/warm milestones with five samples each. Cold p95 was queue `0 ms`,
resources `32 ms`, spawn `14 ms`, RPC `718 ms`, session `4 ms`, accepted `1
ms`, agent start `1 ms`, first event `0 ms`, and settled `869 ms`; warm p95
was `0/11/8/624/1/1/0/0/64 ms`. Five 4+4 pressure samples had UI p95 `188
ms`; Renderer first-commit p95 was `33.466 ms`; exit p95 was `19 ms`.
- WSL2 Linux x64 final product was rebuilt at exact clean commit `0d26d17`.
AppImage/DEB/RPM SHA-256 values are respectively
`38c71302e26a0f7946ffcf72e23edd176b0abc1630da62ef25a808fddb6fdd5c`,
`7c4b29d819aba21c66abb1f41d62cd5b8aed24e44823e9eb875981133672f22b`,
and `cf6983f64a9d2c1f1080fabd9e1724914662e559843b9ceb4f11198a7312b917`.
Final ASAR SHA-256 is
`300dfeb32ded8c6fa764c6604f7d10c175dcbdc28e219169402f65a0dd50d7f7`.
- Linux formal smoke passed Pi `0.84.2` production closure, 10,282-entry ASAR
enumeration, zero product-owned OpenCode paths, actual final Pi processes,
real packaged extension/subagent dispatch, 4+4 pressure, and zero cleanup.
Reports copied beside the Windows evidence are
`release/evidence/pi-smoke-linux-wsl2-real-workers.json`,
`release/evidence/pi-performance-linux-wsl2-real-workers.json`, and
`release/evidence/pi-product-proof-linux-wsl2-real-workers.json`.
- Linux formal five-sample performance passed every budget and recorded all
nine cold/warm milestones with five samples each. Cold p95 was queue `0 ms`,
resources `18 ms`, spawn `5 ms`, RPC `498 ms`, session `3 ms`, accepted `1
ms`, agent start `1 ms`, first event `0 ms`, and settled `602 ms`; warm p95
was `0/5/4/492/1/1/0/1/45 ms`. Five 4+4 pressure samples had UI p95 `142
ms`; Renderer first-commit p95 was `28.217 ms`; exit p95 was `9 ms`.
- Linux results are WSL2/WSLg final-product evidence, not an independent native
non-WSL Linux desktop/compositor/distribution acceptance run. Controlled
provider-shaped smoke issued six requests per protocol (distinct cold, warm,
and abort-isolation paths); real Provider verification remains false by the
explicit waiver.
## Follow-ups
- Request planner re-review of `dc166a1..0d26d17`. The implementation evidence
now directly closes final packaged subagent dispatch, the single Main-owned
cold/warm timeline including zero-valued queue wait, and real
persistent-parent/ephemeral-child 4+4 pressure. The concurrent catalog-write
fix and its regression test are also included.
- Do not start PI-160 or integrate the candidate while PI-150 remains blocked
by the native non-WSL Linux platform evidence boundary. If the planner finds
no new implementation defect, keep PI-150 as the active frontier until that
external evidence is supplied or its gate is explicitly re-decided.
- Keep missing macOS x64/arm64 artifact/runtime/resource/performance evidence as
`Deferred to PI-160 / Not Pass`; do not promote a final cross-platform release
without independent macOS execution, but do not use it to block PI-150.
- Keep the lack of an independent native non-WSL Linux
desktop/compositor/distribution run explicit. The WSL2/WSLg run qualifies the
generated Linux artifacts and final process seam but does not erase that
environment boundary.
- Real Provider Account and real-provider concurrency/credential/protocol
compatibility remain accepted risk unless the user explicitly revokes the
waiver and supplies provider access.
## Promotion Candidates
- After PI-150 is actually unblocked, PI-160 may promote the current Pi
runtime/Conversation state from README and
`docs/pi-runtime-release-runbook.md` into canonical project memory during
integration review.
- PI-160 must record QG-004/QG-005 as `Explicitly Waived / Accepted Risk`, with
`realTurnVerified=false`; this is not a Pass.
- PI-160 must preserve any unresolved macOS x64/arm64 or native Linux
missing-evidence blocker; this candidate does not authorize overriding it.