Skip to content

feat(extensions): add thin Pi /factory status, validate, and context commands - #14

Merged
0xnotdev merged 3 commits into
mainfrom
fm/factory-cp07
Oct 6, 2026
Merged

0xnotdev merged 3 commits into
mainfrom
fm/factory-cp07

Conversation

@0xnotdev

@0xnotdev 0xnotdev commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Intent

Complete Factory CP-07 end to end from merged CP-06 main c241673. Captain's exact current instruction: "do not stop until cp 7 and 8 are end to end complete fully and merged as per the technical specs". This task is ONLY CP-07; CP-08 follows accepted CP-07 landing. Worker never merges; Firstmate has concrete captain merge authority for both checkpoints, not standing autonomy or deployment/discard/login authority.

Authoritative scope: BUILD_PLAN.md CP-07, COMPLETION.md, PROJECT.md, ARCHITECTURE.md, docs/CONTRACTS.md, docs/INTEGRATIONS.md, docs/WORKFLOW.md and existing skills/factory/SKILL.md. The deliverable is a THIN Pi extension at extensions/factory.ts and package registration providing /factory status, /factory validate, /factory context as wrappers around proven Factory CLI. No /factory run, scheduler, worker launch, task state ownership, model router, new daemon/background process or duplicate shipping controls. Preserve CLI semantics/output/errors/exit statuses, argument-array subprocess boundaries, scope/freshness/budget/no-secret protections, spaces in paths and offline normal operation. Register discovery/reload correctly for CURRENT installed Pi, not assumed historical SDK. Write invalid/missing/extra/unsupported argument tests first, exact command parity positives and failure tests, and actual installed-Pi load/reload/smoke evidence (not mocked-only callbacks). Feature parity plus no new background process is CP07 gate.

Follow global CTX intent-document policy in YOUR isolated worktree: main has no .ctx workspace and Firstmate will not initialize main. Deliberately index only authoritative project-intent Markdown with offline verified BAAI/bge-small-en-v1.5. Use one document-qualified strict semantic CP07 context request when initialized; resolve conflicting/partial/omitted norms by reading originals, never claim semantic COMPLETE from partial. Follow normative source cross references. For Pi extension implementation read complete installed Pi docs extensions.md, packages.md and related linked API docs/examples before coding; current installed root is /home/ansh/.nvm/versions/node/v24.20.0/lib/node_modules/@earendil-works/pi-coding-agent, docs/examples resolved there. No copying generic docs into project memory. Do not change shared Pi installation or auth settings. Existing graph if any is a locator only; no unrequested graph-generation subsystem.

Use current source/tests and prior docs/probes CP00-CP06 as evidence, not unquestioned verdicts. CP06 final report data/factory-cp06-pr12-audit/report.md and landing receipt data/factory-cp06-complete/landing-receipt.md in /home/ansh/firstmate-factory establish preserved security protections/limitations. Do not weaken no-range successful-original-read condition, mount/FD/provenance/cleanup/read-only auth controls. CP06 null normalization is denied by final audit, not universal pre-execution raw-null rejection; STRICT_AGENT remains PARTIAL separately from passing STANDARD ten-pack. Product-wide Linux/Windows limits must remain honest. Do not rerun real credential probes or inherited process-memory attacks; security negatives only disposable literal DUMMY data/processes.

Checkpoint evidence must record executed commands/exits/output paths/tested exactGitSHA/date/reviewer, actual Pi version+reload command and observed statuses, CLI parity and foreground-only execution; failed/unrun is notpassed. Add docs/probes/CP-07.md and update task-appropriate documentation/package instructions without manufacturing past proof. BUILD_PLAN CP06 unchecked gate may be accurately reconciled against confirmed landed exact-head receipts; do not alter original normative acceptance contract or assert whole Factory/V1 complete. No broader docs migration. Commit first implementation, then Firstmate invokes no-mistakes; preserve all pipeline fix ancestry and validate finalhead. Final format/lint/typecheck/test, actual extension reload/smoke/parity and existing required regressions must pass, CIgreen fullPRURL/head/risk/evidence required.

Validation safety: never use or reconfigure shared/default no-mistakes daemon. Establish supported dedicated task-local NM_HOME/config/daemon under ignored .factory/state in YOUR copy with explicit environment before any run. Firstmate authorizes starting only that positively identified task-local daemon through supported commands. Keep task-local config/models stable; use existing native signed-in validator through supported model/provider surface if needed, not unproved shared/default login. CP06 receipt for setup mechanics data/factory-cp06-complete/brief.md may be read, but never copy credentials or couple to its daemon/home. No auth contents reads/export/copy/hash/refresh, new login, shared/global config writes or tool updates. Existing scoped publishing setup may use GH_CONFIG_DIR=/home/ansh/.config/gh and GIT_CONFIG_GLOBAL=/home/ansh/.gitconfig without exposing contents. Actual missing capacity/auth errors -> promptly report supported command/output/scope, never silent model/backend fallback. Current relaunched outer worker is Pi openai-codex/gpt-6.1-sol High in the same harness (accepted supersession after the prior usage-limit); catalog supported, provider quota stale/unknown despite captain reset report, not guaranteed capacity.

Routine accepted-intent fixes are already authorized in scope and must proceed via Firstmate decisions immediately, not extra captain waits. For any active ask-user gate supply exact run/head/step/finding IDs/full finding text, precise Fix consequence and exact supported respond command, then wait for Firstmate, not direct captain. You own every no-mistakes run/respond and synchronous return; no --yes, skip, blanket approval, manual edits while custody active, abort/reset/discard/duplicate code runs. Do not create separate manually stacked review; normal no-mistakes owns fresh review/test/doc/publish/CI. No app creation or CP08 implementation in this task; no deployment/remote creation beyond Factory's established origin.

Accepted Firstmate decisions: initialize ONLY independently owned standalone validator clone under this task's ignored .factory/state/v with own .git/common directory, NM_HOME=.factory/state/n, HOME=.factory/state/h. Do not alter the outer linked worktree's inherited no-mistakes remote (shared Git config). Standalone clone origin remains the established Factory origin. Only this positively identified dedicated daemon may be started/reloaded via supported commands; do not copy or control CP06 daemon/home/auth. Use supported native signed-in validation surface with explicit scoped GH_CONFIG_DIR=/home/ansh/.config/gh and GIT_CONFIG_GLOBAL=/home/ansh/.gitconfig; no credential copying/contents reads/export/hash/refresh/new login/global writes. Current dedicated validator is explicitly native Claude opus/high with existing CLAUDE_CONFIG_DIR=/home/ansh/.claude; no silent fallback. Keep configuration stable. Firstmate002 explicitly steered sole full no-mistakes validation from exact implementation bc1dd5d. You must preserve all pipeline fix ancestry and rerun final-head proofs; Firstmate alone merges after independent acceptance.

Implementation choices: wrapper uses the source entry extensions/factory.ts explicitly registered with the skill, host SDK peer plus pinned0.99.2 development SDK. Its Promise Pi slash handler cannot set a per-command OS exit code on persistent Pi: preserve separate exact stdout/stderr/exit_code/killed fields in factory-result.details and display CLI exit label, triggerTurn:false. Never exit persistent Pi or confuse RPC prompt acceptance/Pi exit with CLI status; CLI remains direct OS-status interface. Supported-command option parsing remains the CLI's existing semantics (including permissive global flags); only verb whitelist and argv quoting framing live in extension. No shell expansion. Current installed Pi root is explicit above; optional real CTX fixture proof initializes only two normative originals and offline verified model. No new product background process; the authorized preexisting tool's dedicated validation daemon is outside Factory runtime.

Development evidence (not final pipeline-head certification): outer copy9 ignored .factory/state/cp07-evidence/final-bc1dd5d0735d47ea3751cf428f7b6e6d5fa662e9-r2/receipt.json records exact implementationhead date/reviewer/commands/outputs: npm ci, format/lint/typecheck190/190 tests zero skips, actual installed Pi0.99.2 package/command/runtime replacement, exact CLI parity and real offline semantic CTX success/budget/stale negatives, actual installed CLI/TUI /reload, CP06 STANDARDten-pack/P07/DUMMY auth-security and all cleanup negatives all exit0. Earlier failed proof attempts are retained separately, not passed. CP06 tests/proofs require separately pinned0.85.1 SDK under each proof checkout's .factory/state/cp06-sdk, NOT the current0.99.2 development SDK; use docs/probes/CP-06.md supported installation and explicit CP06_PI_PACKAGE_ROOT/CP06_PI_BIN. CP06_OUTPUT must remain under .factory/state/cp06-correction/ to satisfy inherited safety guard. Do not rerun any real credential/model acceptance probe in this task.

What Changed

  • Adds extensions/factory.ts, a Pi extension registered alongside the Factory skill under pi in package.json. The host SDK is a peer dependency and the development SDK is pinned to 0.99.2. The extension registers only /factory, which accepts status, validate, or context <ID>. It splits the quoted input into arguments without any shell expansion, then runs the built CLI once in the foreground: the Pi host's Node is spawned with an argument array and shell: false.

    • Results are posted as a factory-result message with triggerTurn: false. The message shows unmodified stdout/stderr plus an exit: N label. Its details keep stdout, stderr, exit_code, signal, and killed as separate fields.
    • A CLI killed by a signal reports exit code 128 + the signal number, never 0.
    • An unsupported command, unterminated quote, or NUL returns FACTORY_ARGUMENT_ERROR (exit 2).
    • A Pi host that isn't a Node interpreter (Bun-compiled or single-executable builds) returns FACTORY_RUNTIME_UNAVAILABLE (exit 3) without starting any process.
    • The extension holds no task state, starts no background process, and has no /factory run.
  • Adds tests in test/cp07-extension.test.mjs and test/cp07-pi-smoke.test.mjs covering:

    • invalid or unsupported input, and CLI diagnostics passed through unchanged;
    • spaces, quotes, and shell metacharacters staying literal argument data;
    • multi-byte UTF-8 split across output chunks, signal handling, and rejection of non-Node hosts;
    • exact parity with the built CLI.

    Also adds two proof scripts and their npm entries: scripts/cp07-pi-smoke.mjs (proof:cp07:pi) for an installed-Pi load/parity smoke test, and scripts/cp07-pi-reload.py (proof:cp07:reload) for a real TUI /reload proof. Format, lint (including its shell: true ban), and typecheck now also cover extensions/. .gitignore now ignores Python bytecode.

  • Adds docs/probes/CP-07.md, covering the installed Pi version, the extension's boundaries, proof commands, and remaining limits. Updates README, docs/INTEGRATIONS.md, and skills/factory/SKILL.md with how to use the optional Pi package. In BUILD_PLAN.md, checks off the CP-07 steps and the CP-06 gate, with a note recording how the CP-06 gate was reconciled against its landed PR13 receipt.

🤖 Generated with Claude Code

Risk Assessment

✅ Low: The fixes check out against the code: the extension spawns the CLI directly (argv array, shell: false), decodes output once, reports signals instead of exit 0, refuses non-Node hosts, and the reload proof now checks exit labels with markers that can't come from an earlier redraw, so only a rare sync-spawn error path is left unwrapped.

Testing

After a fresh build at 77332a8, the targeted CP-07 extension and real-SDK smoke tests passed (23/23). That covers argument rejection and delegation, UTF-8 chunk boundaries, signal and nonzero exits, refusal of non-Node hosts, and no process started at registration. A standalone smoke against the installed Pi 0.99.2 showed exact CLI parity, runtime reload, and no model, network or background-child activity. A real installed-Pi TUI session showed the correct CLI exit labels before and after /reload, with a unique post-reload marker. Git now ignores generated bytecode and none is tracked. The CP-06 SDK-boundary tests passed 15/15 with the pinned 0.85.1 SDK. The only gap is the optional real-CTX semantic mode, which could not run here because the sandbox has no verified CTX model. All transient artifacts were removed.

Evidence: Installed Pi 0.99.2 TUI /reload proof summary (observed CLI exit codes)
{
  "command": [
    "/home/ansh/.nvm/versions/node/v24.20.0/bin/pi",
    "--offline",
    "--no-session",
    "--no-extensions",
    "--no-skills",
    "--no-context-files",
    "--no-approve",
    "--model",
    "openai/gpt-4.1",
    "-e",
    "/home/ansh/.treehouse/Factory-86709f/9/Factory/.factory/state/n/worktrees/568d237a06b1/01M48JTDMY09C8AKNQPPRZCMT2"
  ],
  "reload_command": "/reload",
  "statuses": [
    {
      "command": "/factory validate",
      "marker": "Factory validate: context-fixture",
      "cli_exit_code": 0
    },
    {
      "command": "/factory run",
      "marker": "FACTORY_ARGUMENT_ERROR",
      "cli_exit_code": 2
    },
    {
      "command": "/factory context",
      "marker": "VALIDATION_ERROR: context requires TASK-ID",
      "cli_exit_code": 2
    },
    {
      "command": "/reload",
      "marker": "Reloaded",
      "cli_exit_code": null
    },
    {
      "command": "/factory validate --json",
      "marker": "\"command\": \"validate\"",
      "cli_exit_code": 0
    },
    {
      "command": "/factory status",
      "marker": "Factory status: NOT COMPLETE",
      "cli_exit_code": 0
    },
    {
      "command": "/factory status POSTRELOAD_DUMMY_8cf07885",
      "marker": "VALIDATION_ERROR: Unknown argument: POSTRELOAD_DUMMY_8cf07885",
      "cli_exit_code": 2
    }
  ],
  "pi_exit": 0,
  "network": "--offline; no model input; sterile credential-free HOME",
  "foreground": "all CLI completions observed before next input; Pi exited normally"
}
Evidence: Readable TUI transcript (ANSI-stripped) showing /factory outputs, exit labels, Reloaded, and post-reload invocations
>7u
────────────────────────────────────────────────────────────────────────────────
────────────────────────────────────────────────────────────────────────────────
~/project (master)
0.0%/1.0M (auto)                                                         gpt-4.1
 ▀▀█  v0.99.2
 █▀ █ escape interrupt · ctrl+c/ctrl+d clear/exit · / commands · ! bash ·
 ctrl+o more
 Press ctrl+o to show full startup help and loaded resources.
 Pi can explain its own features and look up its docs. Ask it how to use or
 extend Pi.
[Skills]
  factory
[Extensions]
  factory.ts
────────────────────────────────────────────────────────────────────────────────
────────────────────────────────────────────────────────────────────────────────
~/project (master)
0.0%/1.0M (auto)                                                         gpt-4.1
 [factory-result]
 Factory validate: context-fixture
 tasks: 1; conditions: 1
 exit: 0
────────────────────────────────────────────────────────────────────────────────
────────────────────────────────────────────────────────────────────────────────
~/project (master)
0.0%/1.0M (auto)                                                         gpt-4.1
 [factory-result]
 FACTORY_ARGUMENT_ERROR: usage: /factory status | validate | context <ID>
 [Factory CLI options]
 exit: 2
────────────────────────────────────────────────────────────────────────────────
────────────────────────────────────────────────────────────────────────────────
~/project (master)
0.0%/1.0M (auto)                                                         gpt-4.1
 [factory-result]
 VALIDATION_ERROR: context requires TASK-ID
 exit: 2
────────────────────────────────────────────────────────────────────────────────
────────────────────────────────────────────────────────────────────────────────
~/project (master)
0.0%/1.0M (auto)                                                         gpt-4.1
 ▀▀█  v0.99.2
 █▀ █ escape interrupt · ctrl+c/ctrl+d clear/exit · / commands · ! bash ·
 ctrl+o more
 Press ctrl+o to show full startup help and loaded resources.
 Pi can explain its own features and look up its docs. Ask it how to use or
 extend Pi.
[Skills]
  factory
[Extensions]
  factory.ts
 [factory-result]
 Factory validate: context-fixture
 tasks: 1; conditions: 1
 exit: 0
 [factory-result]
 FACTORY_ARGUMENT_ERROR: usage: /factory status | validate | context <ID>
 [Factory CLI options]
 exit: 2
 [factory-result]
 VALIDATION_ERROR: context requires TASK-ID
 exit: 2
────────────────────────────────────────────────────────────────────────────────
 Reloading keybindings, extensions, skills, prompts, themes, and context
 files...
────────────────────────────────────────────────────────────────────────────────
~/project (master)
0.0%/1.0M (auto)                                                         gpt-4.1
 Reloaded keybindings, extensions, skills, prompts, themes, and context files
────────────────────────────────────────────────────────────────────────────────
────────────────────────────────────────────────────────────────────────────────
~/project (master)
0.0%/1.0M (auto)                                                         gpt-4.1
 [factory-result]
 {
   "schema_version": 1,
   "ok": true,
   "command": "validate",
   "root": "/tmp/factory CP07 reload DUMMY 1ynljyq2/project",
   "project_id": "context-fixture",
   "task_count": 1,
   "condition_count": 1,
   "task_order": [
     "CTX-001"
   ]
 }
 exit: 0
────────────────────────────────────────────────────────────────────────────────
────────────────────────────────────────────────────────────────────────────────
~/project (master)
0.0%/1.0M (auto)                                                         gpt-4.1
 [factory-result]
 Factory status: NOT COMPLETE
 backlog done: 0; product passed: 0; failed: 0; stale: 0; unverified: 1
 exit: 0
────────────────────────────────────────────────────────────────────────────────
────────────────────────────────────────────────────────────────────────────────
~/project (master)
0.0%/1.0M (auto)                                                         gpt-4.1
 [factory-result]
 VALIDATION_ERROR: Unknown argument: POSTRELOAD_DUMMY_8cf07885
 exit: 2
────────────────────────────────────────────────────────────────────────────────
────────────────────────────────────────────────────────────────────────────────
~/project (master)
0.0%/1.0M (auto)                                                         gpt-4.1
Evidence: Raw PTY bytes from the installed Pi TUI session
�[?2004h�[>7u�[?u�[c�[?25l�[?2031h�]10;?��]11;?��]4;0;?��]4;1;?��]4;2;?��]4;3;?��]4;4;?��]4;5;?��]4;6;?��]4;7;?��]4;8;?��]4;9;?��]4;10;?��]4;11;?��]4;12;?��]4;13;?��]4;14;?��]4;15;?��[c�[?2026h�[0m�]8;;�

�[39m�[2m────────────────────────────────────────────────────────────────────────────────�[22;39m�[0m�]8;;�

�[7m �[0m                                                                               �[0m�]8;;�

�[39m�[2m────────────────────────────────────────────────────────────────────────────────�[22;39m�[0m�]8;;�

�[39m�[2m~/project (master)�[22;39m�[0m�]8;;�

�[39m�[2m0.0%/1.0M (auto)�[22;39m�[39m�[2m                                                         gpt-4.1�[22;39m�[0m�]8;;��[?2026l�[3A�[1G�[?25l�]0;π - project��[?2026h�[1A
�[2K �[38;5;174m�[48;5;67m▀�[0m�[38;5;174m▀█�[0m  �[39m�[2mv0.99.2�[22;39m                                                                   �[0m�]8;;�

�[2K �[38;5;67m█▀�[0m �[38;5;179m█�[0m �[39m�[2mescape�[22;39m�[39m�[2m interrupt�[22;39m�[39m�[2m · �[22;39m�[39m�[2mctrl+c/ctrl+d�[22;39m�[39m�[2m clear/exit�[22;39m�[39m�[2m · �[22;39m�[39m�[2m/�[22;39m�[39m�[2m commands�[22;39m�[39m�[2m · �[22;39m�[39m�[2m!�[22;39m�[39m�[2m bash�[22;39m�[39m�[2m ·       �[0m�]8;;�

�[2K �[2m�[22;39m�[39m�[2mctrl+o�[22;39m�[39m�[2m more�[22;39m                                                                    �[0m�]8;;�

�[2K �[39m�[2mPress ctrl+o to show full startup help and loaded resources.�[22;39m                   �[0m�]8;;�

�[2K                                                                                �[0m�]8;;�

�[2K �[39m�[2mPi can explain its own features and look up its docs. Ask it how to use or     �[0m�]8;;�

�[2K �[2mextend Pi.�[22;39m                                                                     �[0m�]8;;�

�[2K�[0m�]8;;�

�[2K�[38;5;3m[Skills]�[39m                                                                        �[0m�]8;;�

�[2K�[39m�[2m  factory�[22;39m                                                                       �[0m�]8;;�

�[2K�[0m�]8;;�

�[2K�[38;5;3m[Extensions]�[39m                                                                    �[0m�]8;;�

�[2K�[39m�[2m  factory.ts�[22;39m                                                                    �[0m�]8;;�

�[2K�[0m�]8;;�

�[2K�[0m�]8;;�

�[2K�[39m�[2m────────────────────────────────────────────────────────────────────────────────�[22;39m�[0m�]8;;�

�[2K�[7m �[0m                                                                               �[0m�]8;;�

�[2K�[39m�[2m────────────────────────────────────────────────────────────────────────────────�[22;39m�[0m�]8;;�

�[2K�[39m�[2m~/project (master)�[22;39m�[0m�]8;;�

�[2K�[39m�[2m0.0%/1.0M (auto)�[22;39m�[39m�[2m                                                         gpt-4.1�[22;39m�[0m�]8;;��[?2026l�[3A�[1G�[?25l�[1G�[?25l�[1G�[?25l�[?2026h�[1A
�[2K�[49m                                                                                �[49m�[0m�]8;;�

�[2K�[49m �[38;5;5m�[1m[factory-result]�[22m�[39m                                                               �[49m�[0m�]8;;�

�[2K�[49m                                                                                �[49m�[0m�]8;;�

�[2K�[49m �[39m�[2mFactory validate: context-fixture�[22;39m                                              �[49m�[0m�]8;;�

�[2K�[49m �[39m�[2mtasks: 1; conditions: 1�[22;39m                                                        �[49m�[0m�]8;;�

�[2K�[49m �[39m�[2mexit: 0�[22;39m                                                                        �[49m�[0m�]8;;�

�[2K�[49m                                                                                �[49m�[0m�]8;;�

�[2K�[0m�]8;;�

�[2K�[39m�[2m────────────────────────────────────────────────────────────────────────────────�[22;39m�[0m�]8;;�

�[2K�[7m �[0m                                                                               �[0m�]8;;�

�[2K�[39m�[2m────────────────────────────────────────────────────────────────────────────────�[22;39m�[0m�]8;;�

�[2K�[39m�[2m~/project (master)�[22;39m�[0m�]8;;�

�[2K�[39m�[2m0.0%/1.0M (auto)�[22;39m�[39m�[2m                                                         gpt-4.1�[22;39m�[0m�]8;;��[?2026l�[3A�[1G�[?25l�[1G�[?25l�[?2026h�[1A
�[2K�[49m                                                                                �[49m�[0m�]8;;�

�[2K�[49m �[38;5;5m�[1m[factory-result]�[22m�[39m                                                               �[49m�[0m�]8;;�

�[2K�[49m                                                                                �[49m�[0m�]8;;�

�[2K�[49m �[39m�[2mFACTORY_ARGUMENT_ERROR: usage: /factory status | validate | context �[22;39m�[39m�[2m<ID>�[22;39m�[39m�[2m       �[49m�[0m�]8;;�

�[2K�[49m �[2m[Factory CLI options]�[22;39m                                                          �[49m�[0m�]8;;�

�[2K�[49m �[39m�[2mexit: 2�[22;39m                                                                        �[49m�[0m�]8;;�

�[2K�[49m                                                                                �[49m�[0m�]8;;�

�[2K�[0m�]8;;�

�[2K�[39m�[2m────────────────────────────────────────────────────────────────────────────────�[22;39m�[0m�]8;;�

�[2K�[7m �[0m                                                                               �[0m�]8;;�

�[2K�[39m�[2m────────────────────────────────────────────────────────────────────────────────�[22;39m�[0m�]8;;�

�[2K�[39m�[2m~/project (master)�[22;39m�[0m�]8;;�

�[2K�[39m�[2m0.0%/1.0M (auto)�[22;39m�[39m�[2m                                                         gpt-4.1�[22;39m�[0m�]8;;��[?2026l�[3A�[1G�[?25l�[1G�[?25l�[?2026h�[1A
�[2K�[49m                                                                                �[49m�[0m�]8;;�

�[2K�[49m �[38;5;5m�[1m[factory-result]�[22m�[39m                                                               �[49m�[0m�]8;;�

�[2K�[49m                                                                                �[49m�[0m�]8;;�

�[2K�[49m �[39m�[2mVALIDATION_ERROR: context requires TASK-ID�[22;39m                                     �[49m�[0m�]8;;�

�[2K�[49m �[39m�[2mexit: 2�[22;39m                                                                        �[49m�[0m�]8;;�

�[2K�[49m                                                                                �[49m�[0m�]8;;�

�[2K�[0m�]8;;�

�[2K�[39m�[2m────────────────────────────────────────────────────────────────────────────────�[22;39m�[0m�]8;;�

�[2K�[7m �[0m                                                                               �[0m�]8;;�

�[2K�[39m�[2m─────────────────────────────

... [4455 bytes truncated] ...

─────────────────────�[39m�[0m�]8;;�

�[0m�]8;;�

 �[39m�[2mReloading keybindings, extensions, skills, prompts, themes, and context        �[0m�]8;;�

 �[2mfiles...�[22;39m                                                                       �[0m�]8;;�

�[0m�]8;;�

�[38;5;4m────────────────────────────────────────────────────────────────────────────────�[39m�[0m�]8;;�

�[39m�[2m~/project (master)�[22;39m�[0m�]8;;�

�[39m�[2m0.0%/1.0M (auto)�[22;39m�[39m�[2m                                                         gpt-4.1�[22;39m�[0m�]8;;��[?2026l�[?25l�]10;?��]11;?��]4;0;?��]4;1;?��]4;2;?��]4;3;?��]4;4;?��]4;5;?��]4;6;?��]4;7;?��]4;8;?��]4;9;?��]4;10;?��]4;11;?��]4;12;?��]4;13;?��]4;14;?��]4;15;?��[c�[?2026h�[7A
�[2K �[39m�[2mReloaded keybindings, extensions, skills, prompts, themes, and context files�[22;39m   �[0m�]8;;�

�[2K�[0m�]8;;�

�[2K�[39m�[2m────────────────────────────────────────────────────────────────────────────────�[22;39m�[0m�]8;;�

�[2K�[7m �[0m                                                                               �[0m�]8;;�

�[2K�[39m�[2m────────────────────────────────────────────────────────────────────────────────�[22;39m�[0m�]8;;�

�[2K�[39m�[2m~/project (master)�[22;39m�[0m�]8;;�

�[2K�[39m�[2m0.0%/1.0M (auto)�[22;39m�[39m�[2m                                                         gpt-4.1�[22;39m�[0m�]8;;�

�[2K�[1A�[?2026l�[3A�[1G�[?25l�[1G�[?25l�[?2026h�[1A
�[2K�[49m                                                                                �[49m�[0m�]8;;�

�[2K�[49m �[38;5;5m�[1m[factory-result]�[22m�[39m                                                               �[49m�[0m�]8;;�

�[2K�[49m                                                                                �[49m�[0m�]8;;�

�[2K�[49m �[39m�[2m{�[22;39m                                                                              �[49m�[0m�]8;;�

�[2K�[49m �[39m�[2m  "schema_version": 1,�[22;39m                                                         �[49m�[0m�]8;;�

�[2K�[49m �[39m�[2m  "ok": true,�[22;39m                                                                  �[49m�[0m�]8;;�

�[2K�[49m �[39m�[2m  "command": "validate",�[22;39m                                                       �[49m�[0m�]8;;�

�[2K�[49m �[39m�[2m  "root": "/tmp/factory CP07 reload DUMMY 1ynljyq2/project",�[22;39m                   �[49m�[0m�]8;;�

�[2K�[49m �[39m�[2m  "project_id": "context-fixture",�[22;39m                                             �[49m�[0m�]8;;�

�[2K�[49m �[39m�[2m  "task_count": 1,�[22;39m                                                             �[49m�[0m�]8;;�

�[2K�[49m �[39m�[2m  "condition_count": 1,�[22;39m                                                        �[49m�[0m�]8;;�

�[2K�[49m �[39m�[2m  "task_order": [�[22;39m                                                              �[49m�[0m�]8;;�

�[2K�[49m �[39m�[2m    "CTX-001"�[22;39m                                                                  �[49m�[0m�]8;;�

�[2K�[49m �[39m�[2m  ]�[22;39m                                                                            �[49m�[0m�]8;;�

�[2K�[49m �[39m�[2m}�[22;39m                                                                              �[49m�[0m�]8;;�

�[2K�[49m �[39m�[2mexit: 0�[22;39m                                                                        �[49m�[0m�]8;;�

�[2K�[49m                                                                                �[49m�[0m�]8;;�

�[2K�[0m�]8;;�

�[2K�[39m�[2m────────────────────────────────────────────────────────────────────────────────�[22;39m�[0m�]8;;�

�[2K�[7m �[0m                                                                               �[0m�]8;;�

�[2K�[39m�[2m────────────────────────────────────────────────────────────────────────────────�[22;39m�[0m�]8;;�

�[2K�[39m�[2m~/project (master)�[22;39m�[0m�]8;;�

�[2K�[39m�[2m0.0%/1.0M (auto)�[22;39m�[39m�[2m                                                         gpt-4.1�[22;39m�[0m�]8;;��[?2026l�[3A�[1G�[?25l�[1G�[?25l�[?2026h�[1A
�[2K�[49m                                                                                �[49m�[0m�]8;;�

�[2K�[49m �[38;5;5m�[1m[factory-result]�[22m�[39m                                                               �[49m�[0m�]8;;�

�[2K�[49m                                                                                �[49m�[0m�]8;;�

�[2K�[49m �[39m�[2mFactory status: NOT COMPLETE�[22;39m                                                   �[49m�[0m�]8;;�

�[2K�[49m �[39m�[2mbacklog done: 0; product passed: 0; failed: 0; stale: 0; unverified: 1�[22;39m         �[49m�[0m�]8;;�

�[2K�[49m �[39m�[2mexit: 0�[22;39m                                                                        �[49m�[0m�]8;;�

�[2K�[49m                                                                                �[49m�[0m�]8;;�

�[2K�[0m�]8;;�

�[2K�[39m�[2m────────────────────────────────────────────────────────────────────────────────�[22;39m�[0m�]8;;�

�[2K�[7m �[0m                                                                               �[0m�]8;;�

�[2K�[39m�[2m────────────────────────────────────────────────────────────────────────────────�[22;39m�[0m�]8;;�

�[2K�[39m�[2m~/project (master)�[22;39m�[0m�]8;;�

�[2K�[39m�[2m0.0%/1.0M (auto)�[22;39m�[39m�[2m                                                         gpt-4.1�[22;39m�[0m�]8;;��[?2026l�[3A�[1G�[?25l�[1G�[?25l�[?2026h�[1A
�[2K�[49m                                                                                �[49m�[0m�]8;;�

�[2K�[49m �[38;5;5m�[1m[factory-result]�[22m�[39m                                                               �[49m�[0m�]8;;�

�[2K�[49m                                                                                �[49m�[0m�]8;;�

�[2K�[49m �[39m�[2mVALIDATION_ERROR: Unknown argument: POSTRELOAD_DUMMY_8cf07885�[22;39m                  �[49m�[0m�]8;;�

�[2K�[49m �[39m�[2mexit: 2�[22;39m                                                                        �[49m�[0m�]8;;�

�[2K�[49m                                                                                �[49m�[0m�]8;;�

�[2K�[0m�]8;;�

�[2K�[39m�[2m────────────────────────────────────────────────────────────────────────────────�[22;39m�[0m�]8;;�

�[2K�[7m �[0m                                                                               �[0m�]8;;�

�[2K�[39m�[2m────────────────────────────────────────────────────────────────────────────────�[22;39m�[0m�]8;;�

�[2K�[39m�[2m~/project (master)�[22;39m�[0m�]8;;�

�[2K�[39m�[2m0.0%/1.0M (auto)�[22;39m�[39m�[2m                                                         gpt-4.1�[22;39m�[0m�]8;;��[?2026l�[3A�[1G
Evidence: Installed Pi 0.99.2 smoke: CLI parity cases, reload, zero model/network/background children
{
  "pi_version": "0.99.2",
  "package_root": "/home/ansh/.nvm/versions/node/v24.20.0/lib/node_modules/@earendil-works/pi-coding-agent",
  "discovery": "settings packages local path",
  "reload": "await session.reload()",
  "reload_replaced_runtime": true,
  "model_requests": 0,
  "network_calls": 0,
  "background_children": 0,
  "real_ctx": false,
  "cases": [
    {
      "input": "/factory context",
      "exit_code": 2,
      "exact_stdout_stderr": true
    },
    {
      "input": "/factory validate extra",
      "exit_code": 2,
      "exact_stdout_stderr": true
    },
    {
      "input": "/factory status extra",
      "exit_code": 2,
      "exact_stdout_stderr": true
    },
    {
      "input": "/factory context X extra",
      "exit_code": 2,
      "exact_stdout_stderr": true
    },
    {
      "input": "/factory validate --root",
      "exit_code": 2,
      "exact_stdout_stderr": true
    },
    {
      "input": "/factory status --unsupported --json",
      "exit_code": 2,
      "exact_stdout_stderr": true
    },
    {
      "input": "/factory context X --token-budget 0 --json",
      "exit_code": 2,
      "exact_stdout_stderr": true
    },
    {
      "input": "/factory ",
      "exit_code": 2,
      "wrapper_rejection": true
    },
    {
      "input": "/factory run",
      "exit_code": 2,
      "wrapper_rejection": true
    },
    {
      "input": "/factory sync --apply",
      "exit_code": 2,
      "wrapper_rejection": true
    },
    {
      "input": "/factory validate --root 'unfinished",
      "exit_code": 2,
      "wrapper_rejection": true
    },
    {
      "input": "/factory validate",
      "exit_code": 0,
      "exact_stdout_stderr": true
    },
    {
      "input": "/factory validate --root \"/tmp/factory CP07 DUMMY nFpwyM/project\" --json",
      "exit_code": 0,
      "exact_stdout_stderr": true
    },
    {
      "input": "/factory status",
      "exit_code": 0,
      "exact_stdout_stderr": true
    },
    {
      "input": "/factory status --json",
      "exit_code": 0,
      "exact_stdout_stderr": true
    },
    {
      "input": "/factory status --home \"/tmp/factory CP07 DUMMY nFpwyM/absent home\" --json",
      "exit_code": 3,
      "exact_stdout_stderr": true
    },
    {
      "input": "/factory context CTX-001 --ctx-bin \"/tmp/factory CP07 DUMMY nFpwyM/absent ctx\" --json",
      "exit_code": 3,
      "exact_stdout_stderr": true
    },
    {
      "input": "/factory validate --json",
      "exit_code": 2,
      "exact_stdout_stderr": true
    },
    {
      "input": "/factory validate --json",
      "exit_code": 0,
      "exact_stdout_stderr": true
    },
    {
      "input": "/factory status",
      "exit_code": 0,
      "exact_stdout_stderr": true
    }
  ]
}
Evidence: CP-07 extension + SDK smoke node:test output
✔ reject wrapper syntax/unsupported command: "" (2.10291ms)
✔ reject wrapper syntax/unsupported command: "run" (0.23886ms)
✔ reject wrapper syntax/unsupported command: "sync --apply" (0.169787ms)
✔ reject wrapper syntax/unsupported command: "doctor" (0.122654ms)
✔ reject wrapper syntax/unsupported command: "inspect X" (0.109916ms)
✔ reject wrapper syntax/unsupported command: "validate --root 'unterminated" (0.182075ms)
✔ reject wrapper syntax/unsupported command: "validate --root \"unterminated" (0.144999ms)
✔ reject wrapper syntax/unsupported command: "validate\u0000" (0.101567ms)
✔ delegate CLI argument diagnostic unchanged: context (28.192038ms)
✔ delegate CLI argument diagnostic unchanged: context X extra (31.961549ms)
✔ delegate CLI argument diagnostic unchanged: validate extra (23.646994ms)
✔ delegate CLI argument diagnostic unchanged: status extra (25.509088ms)
✔ delegate CLI argument diagnostic unchanged: validate --root (27.917176ms)
✔ delegate CLI argument diagnostic unchanged: context X --token-budget 0 (28.4705ms)
✔ delegate CLI argument diagnostic unchanged: status --unsupported (28.046191ms)
✔ quoted/escaped spaces, empty values, Windows backslashes and shell metacharacters stay argv data (87.576186ms)
✔ sequential calls hold no task state and retain full output without truncation (66.960401ms)
✔ multi-byte UTF-8 split across pipe chunks is decoded exactly once (243.141644ms)
✔ a signal-terminated CLI is reported as a signal failure, not exit 0 (28.634185ms)
✔ a non-Node Pi host executable is never invoked as the Factory interpreter (1.360189ms)
✔ an unavailable working directory is a runtime failure, not success (2.953808ms)
✔ default registration runs the built CLI with the current Node and matches it exactly (223.308605ms)
✔ real Pi package discovery, command dispatch, CLI parity and runtime reload offline (5584.573332ms)
ℹ tests 23
ℹ suites 0
ℹ pass 23
ℹ fail 0
ℹ cancelled 0
ℹ skipped 0
ℹ todo 0
ℹ duration_ms 5664.826501
Evidence: Git ignores generated __pycache__ bytecode
## tracked pyc in HEAD:
(none)
## compile real bytecode via import
scripts/__pycache__/cp07-pi-reload.cpython-312.pyc
cp07-pi-reload.cpython-312.pyc
## git check-ignore -v
.gitignore:6:__pycache__/	scripts/__pycache__/cp07-pi-reload.cpython-312.pyc
check-ignore exit=0
## git status --porcelain --untracked-files=all
(end status)
Evidence: CP-06 SDK boundary regression with pinned 0.85.1
✔ Pi selection requires the explicit task-local package and executable paths (18.963765ms)
✔ exact artifact succeeds and same-version selected entry substitutions fail before SDK use (1417.965112ms)
✔ supervisor trusted provenance verifies the selected installation without executing Pi (1380.079605ms)
✔ pinned Pi dependency resolver handles substituted same-version import-only dependency (44.588661ms)
✔ pinned Pi dependency resolver handles newer hoisted import-only dependency (46.57733ms)
✔ real hardened probe executes retained read-only descriptors and inherited DUMMY denials (1114.153124ms)
✔ full semantic contracts reject forged nested evidence inside independently awaited cleanup (36.862114ms)
✔ worker provenance without an independently trusted expectation is rejected (1.12586ms)
✔ artifact replacement and reads are bound to the prepared inode (7.335467ms)
✔ ten-pack refuses a prepared contract replaced by another regular inode (72.263727ms)
✔ DUMMY fixture cleanup closes every descriptor and removes through its anchor despite failures (8.365877ms)
✔ supervisor CLI serializes fixture setup and independent fixture cleanup causes (135.490537ms)
✔ artifact writes, replacements, copies and reads reject redirected leaves and intermediate directories (9.619004ms)
✔ replay-cp06-ten-pack.mjs refuses a substituted raw artifact at its executable boundary (69.230275ms)
✔ replay-cp06-p07.mjs refuses a substituted raw artifact at its executable boundary (42.645787ms)
ℹ tests 15
ℹ suites 0
ℹ pass 15
ℹ fail 0
ℹ cancelled 0
ℹ skipped 0
ℹ todo 0
ℹ duration_ms 2978.786577
  • Evidence: Optional real-CTX smoke (blocked by sandbox CTX model absence) (local file: /home/ansh/.treehouse/Factory-86709f/9/Factory/.factory/state/n/evidence/01M48JTDMY09C8AKNQPPRZCMT2/cp07-installed-pi-smoke-real-ctx.log)
  • Outcome: ⚠️ 1 info across 1 run (3m0s)

Pipeline

Updates from git push no-mistakes

✅ **intent** - passed

✅ No issues found.

✅ **Rebase** - passed

✅ No issues found.

⚠️ **Review** - 1 info
  • ⚠️ extensions/factory.ts:70 - The wrapper depends on Pi's pi.exec, and that helper does not pass the CLI's exit status and output through faithfully. This contradicts the authoritative requirement to "Preserve CLI semantics/output/errors/exit statuses" and the CP-07.md claim that details holds "unmodified separate streams, numeric exit_code". In the installed Pi 0.99.2, dist/core/exec.js resolves with code: code ?? 0, and waitForChildProcess returns a null code when the child is ended by a signal. killed is only true when Pi itself killed the process, which never happens here because the wrapper passes no timeout or signal. So if the Factory CLI is killed externally (OOM, SIGKILL, SIGSEGV), /factory status shows exit: 0 with details.exit_code: 0, killed: false, which looks like success even though the direct CLI would report a signal. Separately, stdout += data.toString() decodes each pipe chunk on its own. When output is larger than about 64 KiB, for example a big status --json or a context pack with a large --byte-budget containing non-ASCII text such as the em-dashes used throughout these docs, a multi-byte character split across chunks becomes U+FFFD. JSON still parses, but stdout no longer matches the CLI byte for byte. The unit test covering 250 KB output uses a mocked ASCII exec, and the real smoke outputs are small, so neither case is tested. Fix: spawn node:child_process directly with an argv array and shell: false, collect Buffers and decode once, and report the signal (or a non-zero code) when code is null. Alternatively, at minimum treat a null code as failure. Update CP-07.md to match.
  • ⚠️ extensions/factory.ts:70 - process.execPath is assumed to be a Node binary. Installed Pi explicitly supports running as a Bun-compiled binary (dist/config.js isBunBinary), and the documented primary installer is curl -fsSL https://pi.dev/install.sh | sh in docs/quickstart.md. In that setup process.execPath is the Pi binary itself, so /factory status runs pi /…/dist/src/cli.js status. Per docs/cli.md, redirected stdout puts Pi in print mode and sends the positional arguments as a prompt. The result is a nested Pi agent run that uses the user's credentials, makes a model request, and may use tools. That conflicts with the CP-07 gate ("no new background process", "not model calls"), and the Factory CLI never runs. The proofs only cover npm-installed Pi on Node, so this path is untested. Fix: fail closed with FACTORY_ARGUMENT_ERROR (or a similar error) when process.versions.bun is set or process.execPath is not Node, or resolve an explicit Node executable, and record this limit in CP-07.md.
  • ℹ️ scripts/cp07-pi-reload.py:74 - The TUI /reload proof only checks that an output substring appears in the PTY bytes after each input. It never checks the exit: N label, so a post-reload /factory validate that printed the header but failed would still pass. The recorded statuses only repeat the expected substring rather than CLI exit codes, although CP-07.md and the intent ask for observed statuses. The second /factory validate also expects the same text as the first, so a full-screen redraw after /reload that repaints earlier transcript lines could satisfy it without the reloaded command running. Fix: match on the exit label as well (for example exit: 0 / exit: 2), and use a distinguishing post-reload marker or count new occurrences.

🔧 Fix: Spawn CLI directly, reject non-Node Pi hosts, tighten reload proof
1 warning still open:

  • ⚠️ scripts/__pycache__/cp07-pi-reload.cpython-312.pyc:1 - The review-fix commit 3d4dc49 added a generated CPython 3.12 bytecode file, scripts/__pycache__/cp07-pi-reload.cpython-312.pyc (8599 bytes, binary). It was produced when the reload proof was imported or run during the fix round, and .gitignore has no __pycache__/ or *.pyc rule (git check-ignore exits 1). The file goes stale whenever scripts/cp07-pi-reload.py changes, depends on the interpreter version, and is not a source, proof, or evidence artifact. Committing it also goes against the repo's rule that runtime artifacts stay out of tracked paths. Fix: git rm --cached scripts/__pycache__/cp07-pi-reload.cpython-312.pyc (delete the directory) and add __pycache__/ and *.pyc to .gitignore.

🔧 Fix: Untrack generated Python bytecode and ignore pycache artifacts
1 info still open:

  • ℹ️ extensions/factory.ts:97 - runCli only handles spawn failures that Node reports through the asynchronous error event (ENOENT, EACCES, EAGAIN, EMFILE, ENFILE). For any other libuv spawn error, child_process.spawn throws synchronously, and here the throw happens inside the new Promise executor. I confirmed this locally: spawning with cwd set to a file throws ENOTDIR synchronously, and an oversized argv gives E2BIG. The result is that the slash handler rejects with a raw exception and no factory-result message is sent. That contradicts the contract in CP-07.md and README, which says a wrapper-side start failure produces FACTORY_RUNTIME_UNAVAILABLE (exit 3) with details. This is not a false success, and the triggers are rare. Fix: wrap the spawn(...) call in try/catch and resolve failure(&#34;FACTORY_RUNTIME_UNAVAILABLE&#34;, error.message, 3). A DUMMY test with a file as the cwd would cover it.
⚠️ **Test** - 1 info
  • ℹ️ scripts/cp07-pi-smoke.mjs:134 - The optional CP07_REAL_CTX=1 smoke mode failed (exit 1) in this sandbox. The failure happens before the extension is ever compared: the direct Factory CLI itself returns CONTEXT_BLOCKED: CTX returned an unusable response (exit 3). This sandbox's HOME (.factory/state/h) has no verified offline BAAI/bge-small-en-v1.5 model. The previous review-fix round hit the same environment limit, and docs/probes/CP-07.md already records it as not passed. Context-pack parity with real semantic retrieval at this head therefore still depends on the outer final-head proof with a provisioned CTX model. The non-semantic context paths passed here (missing ID, extra arg, zero budget, absent ctx-bin).
  • npm run build (exit 0, HEAD 77332a8b2f912ddaca577c2df59568ae7afdc93b)
  • node --experimental-import-meta-resolve --test test/cp07-extension.test.mjs test/cp07-pi-smoke.test.mjs: 23/23 pass, 0 skipped. Covers unsupported, missing and extra arguments, quoting, NUL, spaces, Windows paths, metacharacters, large output, UTF-8 split across pipe chunks, SIGKILL reported as 137 with the signal name, refusal of a non-Node or Bun host, unavailable cwd, and parity with real SDK reload
  • CP07_PI_PACKAGE_ROOT=&lt;installed pi 0.99.2&gt; PI_OFFLINE=1 node scripts/cp07-pi-smoke.mjs (exit 0): 20 cases with exact stdout/stderr/exit parity, reload_replaced_runtime true, 0 model requests, 0 network calls, 0 background children
  • python3 -B scripts/cp07-pi-reload.py --pi-bin $(which pi) --output &lt;evidence&gt;/reload (exit 0): real installed Pi 0.99.2 TUI. Observed CLI exits 0, 2, 2, then /reload, then 0, 0, 2 with a unique POSTRELOAD_DUMMY marker; Pi exited 0
  • Rendered an ANSI-stripped TUI transcript. It shows the pre-reload transcript being redrawn and, separately, the new post-reload invocations
  • Bytecode policy: ran py_compile on scripts/cp07-pi-reload.py, then git check-ignore -v (matched .gitignore:6 __pycache__/), git status --porcelain --untracked-files=all (clean), and git ls-tree (no tracked .pyc)
  • Installed the pinned CP-06 SDK 0.85.1 under ignored .factory/state/cp06-sdk as documented in docs/probes/CP-06.md, then ran node --experimental-import-meta-resolve --test test/cp06-pi-dependency.test.mjs test/cp06-review-boundaries.test.mjs with CP06_PI_PACKAGE_ROOT/CP06_PI_BIN set: 15/15 pass, 0 skipped. This checks that the new 0.99.2 dev SDK does not disturb CP-06 SDK selection
  • CP07_REAL_CTX=1 ... node scripts/cp07-pi-smoke.mjs (exit 1: the direct CLI returned CONTEXT_BLOCKED because this sandbox has no verified CTX model)
  • Cleanup: removed the temporary cp06-sdk, npm cache, empty auth-security/cp06-correction dirs and scripts/__pycache__; worktree is clean
✅ **Document** - passed

✅ No issues found.

✅ **Lint** - passed

✅ No issues found.

✅ **Push** - passed

✅ No issues found.

@0xnotdev
0xnotdev merged commit 9ba7ded into main Oct 6, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant