Conversation
commit: |
Independent review — P1 startup-dialog deadlock, not acceptedHead P1: enabling user extensions exposes an unanswerable startup dialogThe removal of automatic extension opt-out ( export default function (pi) {
pi.on("session_start", async (_event, ctx) => {
if (ctx.hasUI) await ctx.ui.confirm("Startup verification", "Continue?");
});
}This is not terminal-only custom UI: confirm is part of the documented RPC request/response protocol, and Two initialization barriers prevent progress:
The normal live session consequently cannot finish acquisition with such an extension (the parent has a handshake timeout); command discovery cannot complete through the same startup barrier. Restoring extension loading makes this previously-disabled user-extension path reachable. Independent executable reproductionFresh pinned reviewer worktree, locked install, Turbo-built actual Bun Drove real JSONL stdin/stdout in two otherwise equivalent cases:
The diagnostic sent The normal extension/discovery/agent suite independently passed 4 files / 36 tests, no type errors. Its existing happy-path/handled-input/trust tests do not exercise startup dialogs. Required follow-up and scopeCoordinate startup input handling, parent readiness/UI routing and noninteractive command discovery so a startup extension cannot wait on a response that the host cannot deliver. Do not silently approve requests or weaken Project trust. Add deterministic startup-dialog and discovery regressions, then restart new-head CI, independent review and affected Web/Desktop acceptance. Review blocked; not merged. No source repair was attempted. This is actual bundled-child protocol verification, not paid-model or Web/Desktop UI acceptance. The author screenshots and previous happy-path proofs do not resolve this finding. Further acceptance stopped at this reproduced defect. |
Queue update after verified #423 merge — waiting at CIHead Required CI for this new head is queued/in progress at this observation, so no old-head review or acceptance is carried forward. The startup-dialog blocker remains unresolved: #427 (comment) No merge or deferred auto-merge. Continue only after the applicable blocker is resolved and the new version passes required CI → review → independent acceptance. |
|
Consolidated duplicate PR #428 into this PR. Production behavior was identical (only an explanatory comment differed). Preserved its additional |
Read startup UI responses while gating ordinary RPC commands on binding. Start parent UI routing before readiness and explicitly decline discovery dialogs. Cancel dialogs on EOF, drain admitted commands, and propagate graceful exit through the RPC entry point. Add real bundled-child startup and trust regressions. Serialize process-heavy verifier files to avoid full-suite startup starvation without changing security assertions or timeouts.
Startup-dialog fix — new head
|




Requirement
Restore loading of the user's local Pi extensions and configured plugin packages. A provider such as CLIProxyAPI can have endpoint/auth configuration in
models.jsonwhile its extension supplies the model list; the blanketnoExtensionspolicy introduced by #104 removed those models from Pie's picker.Expected behavior
defaultProjectTrust: always.--no-extensions,--extension, and Project trust overrides remain effective in the bundled child. No edits or migration of user settings, credentials, or model configuration.Changes and risks
dispositionalongside the existingstartedboolean. Ahandledinput returns an empty, non-started receipt without relaxing the queued-without-an-active-turn invariant.Extensions are trusted executable code with the user's OS permissions, just as in Pi; this is not a sandbox or an extension whitelist. Terminal-only custom extension UI remains unsupported. No new Pie-owned storage format or location is introduced.
Latest verification —
67aa9ee5Startup-dialog follow-up: child stdin/UI routing starts before binding finishes; parent UI routing starts before readiness; discovery explicitly declines dialogs. EOF cancels pending dialogs and gracefully drains admitted commands. Five real bundled-child startup/trust regressions added. Process-heavy verifier files run serially to avoid CI startup starvation without relaxing assertions or deadlines.
pnpm buildandpnpm checkpassed.Independent re-review/acceptance is still required. No merge or installation performed.
Original model-loading verification —
268a1f3eTested head:
268a1f3e59e48cf9ea6abf33306c3a532c61070a; baseline:01f864fe30b4376714547bd6bd6576b5540e3d03.pnpm check— passed (lint, formatting, workspace typechecks).pnpm exec vitest run --project server— 643 passed, 1 skipped, no type errors. The added integration tests run the real Bun-builtpie-pi-processwith an isolated agent directory and an in-process fixture provider; they do not substitute a fake Pi executable.pnpm exec turbo run build --filter=@getpie/server --force— passed for the tested head.E2E Fake, completes a Pi turn, exposes/local-ping, and handles it without hanging or browser errors. Screenshots and both recordings attached.Limits: Desktop proof uses a deterministic fixture provider, not a paid/remote model service. The user's real CLIProxyAPI endpoint/key was not exercised. Web browser drive and packaged
.appinstallation were not verified. This PR is not merged or installed locally.recording-001.webm
recording-001.webm