Skip to content

Qualify provider login, refresh and logout for Pi 1.0.4 #1458

Description

@piclaw-bot

Current target — Pi 1.0.4 and the shipping subprocess

Qualify provider authentication on exact released Pi1.0.4 using the current supported runtime/CLI credential path. Preserve provider/model approval, refresh/logout/rotation, private UI and isolation checks. A new credential broker, account-envelope migration or child-provider proxy is not a prerequisite for shipping Delegate.

Core Pi1.0.4 qualification is merged in #1574 at dc697b2; shipping Delegate0.2.18 thinking inheritance is merged in rcarmo/piclaw-addons#179 at69301a9. Source merge is not installation, restart, live-account acceptance or activation.

Current checklist

  • Fresh synthetic provider device, callback/browser, packaged CLI and cancelled-refresh qualification: PR1574.
  • Private Anthropic UI cases pass in Chromium/WebKit with fake tokens and no inference.
  • Review remaining provider/method coverage and record unsupported combinations.
  • Perform real-account/provider checks only when separately authorised.
  • Keep authentication success separate from provider approval and Delegate activation.

Superseded framework requirements below are historical, not current shipping dependencies. Unfinished security/auth/operational work is not marked delivered.

Previous issue scope and evidence — retained history

Current integration target — released Pi 1.0.3

Rui authorised the retarget on 5 October 2026 after the unified timeline/meters/audit integration. Exact upstream release: d78dc83d633229d12f8b79631384c4c2717c399f. The shipped MCP wrapper remains selected; Native replacement/parity and pi-durable are outside this integration.

Core source is merged through PR1558, 6ceaeaed1: eight exact archives and payload admission, fresh public SDK/provider/CLI/device/browser/private-UI evidence, frozen full 6,516 passed/eight existing skips/zero failed, and postmerge17tests/485assertions. No installation or restart. Azure's built-in provider is now azure; the Responses API identifier and Piclaw optional custom provider IDs are unchanged. Retired Azure selections fail closed with manual migration guidance; live auth/config files are not rewritten by source qualification. The released cancelled-refresh persistence fix is tested, but raw provider/auth settlement and account-generation contracts are still absent. Production Delegate remains inactive.

Earlier 1.0.2 and prior-version bodies and receipts are preserved below as history. Source merge authority does not permit deployment/restart, live account/server calls or provider spend. Those operations, canary/soak and operational rollback need separate approval.

Current checklist

  • Changed executable paths and exact1.0.3 package/CLI/browser/device/private-UI receipts are fresh (PR1558); synthetic cancellation preserves late rotated credentials.
  • Public-runtime credential ownership, private UI, explicit activation and approval constraints retain scoped tests. Retired Azure provider identity refuses automatic fallback.
  • Complete production parent/child credential-source agreement, raw settlement/account authority and supported composed-provider coverage; add-ons160 stays open.
  • Record required separately approved live login/refresh/revocation/canary and rotated-token recovery; authentication and inference approval remain separate.
Earlier target criteria and receipts — preserved historical record

Current integration target — Pi 1.0.2

Rui authorised retargeting to released Pi 1.0.2 on 5 October 2026, upstream commit cd32f7725fdbddbaecdff5b1e68491563394e0ca. This work integrates Pi with the standard MCP wrapper already shipped by Piclaw. Wrapper replacement, Native MCP parity and adapter removal are future work, not prerequisites for this integration. Keep one wrapper owner; reject unsupported Native selection without fallback. This scope decision does not weaken the shipped wrapper's credential, policy or cleanup requirements.

Preserve 0.99.1, 1.0.0 and 1.0.1 receipts as historical evidence. New 1.0.2 qualification is separate. Unreleased upstream OAuth cancellation changes after the 1.0.2 tag are excluded. Source updates, isolated tests, review and verified merges are authorised; installation, restart and real-account/provider tests still need separate approval. Pi-durable remains out of scope.

Integration checklist and completed slices

Previous target criteria and receipts — preserved historical record

Active target — Pi 1.0.1 (3 October 2026)

Rui authorised retargeting and implementation to exact Pi 1.0.1, upstream git head a7229ddc21810d6245105978033b7df645ecc2f7. This supersedes the earlier 1.0.0 execution target below. Preserve all 0.99.1 and 1.0.0 receipts as historical evidence; they are not 1.0.1 qualification.

Source migration, exact-package admission and isolated Bun-only synthetic qualification are authorised. Keep Adapter/Auto as the default, reject unsupported native combinations, retain failed-teardown/Apply security gates, and exclude pi-durable. Live accounts, deployment, production installation, restart and canary remain separately authorised. Do not waive unresolved native, provider or Delegate acceptance gates.

Earlier target and requirements (retained)

Checkpoint: 958ac185255840ee4f800becc5f7e3111ef9acda on feat/mcp-settings-host; stable 0.99.1 source baseline, not 1.0.0 admission.

Shared target and MCP policy

Selected target: Pi 1.0.0, gitHead a13d35a742c6ef8462812a28fbe1d8c8b7431c32. Rui explicitly authorised retargeting all remaining work on 1 October 2026: stabilise and commit current work → update relevant issues/dependencies → resume the 1.0.0 upgrade on that checkpoint. Source changes, isolated dependency installs and offline qualification are authorised; runtime admission remains an acceptance gate, not an assumed result. All new execution is Bun-only. Live accounts/MCP/provider calls, production installation, deployment/restart and experimental pi-durable activation still require separate approval. Preserve completed 0.99.1 receipts and closed issue states as historical evidence; do not relabel them as 1.0.0 results.

  • Preserve the approved consolidated instance MCP settings: adapter/native selector, adapter default, exactly one active owner, codemode Auto/On/Off default Auto.
  • Engine switching aborts active turns and reloads all extensions through supported public APIs, retaining chats/history; no service restart. Unsupported combinations reject with explicit reasons; no silent fallback or dropped settings.
  • Ten native public-API gap diagnostics persist in the 1.0.0 assessment. Target selection is not a capability/security waiver.
  • Old Harness/Pico3 exports are removed. Design the pi-durable 1.0.0 Harness successor and HC/PC crosswalk #1493 owns the pi-durable semantic/authority design and Qualify pi-durable 1.0.0 storage and Harness semantics on Bun without activation #1494 its isolated qualification. Do not add pi-durable to production merely to repair imports.

Provider login qualification for Earendil 1.0.0

Provider authentication is a separate release gate from MCP OAuth.

Summary

Qualify Piclaw's complete provider-login path against exact Earendil 1.0.0, including the packaged OpenAI /login fix for missing openai-chatgpt.js. Test the shipped artifact as well as SDK integration; a source import or model-catalogue check does not prove login works.

Parent: #1442

MCP-server OAuth belongs to #1450 and cannot satisfy this provider-auth gate.

Dependencies

Acceptance Criteria

  • Consume Qualify Pi 1.0.2 provider, MCP and Delegate integration deltas #1495 target-specific deltas, including Anthropic copy-code/headless login; do not require an obsolete callback flow. Re-run current-version executable receipts and retain old fixtures in their exact dependency environment.

  • Preserve all AUTH-01–08 security/ownership/activation requirements, approved child model/provider constraints and separate live-account approval.

  • AUTH-01 — Provider/method inventory: derive a versioned matrix from the exact runtime's provider-owned auth definitions, plus Piclaw custom/external providers. Cover OpenAI and OpenAI Codex as separate provider IDs; GitHub Copilot; Anthropic; other advertised OAuth providers (including Kimi, OpenRouter and Radius where present); API-key providers including OpenAI/Azure/Google; external AWS Bedrock/Google Vertex/Azure identity; and custom/local no-auth providers. Distinguish OAuth, API-key, external and no-auth paths. Reconcile dynamic methods with Piclaw's static fallback; removed/unsupported methods must not appear as working login options. Do not infer support from a model name or an API-key field.

  • AUTH-02 — Packaged login: exercise /login and provider selection through the built/published 1.0.0 artifact and Piclaw SDK path in an isolated profile. Specifically resolve and invoke the OpenAI ChatGPT OAuth module under mocked network conditions, proving openai-chatgpt.js is present and reachable. Test OpenAI Codex separately. No private imports or source-tree substitutions in the packaging receipt.

  • AUTH-03 — Complete interactions: test provider picker → applicable method → provider-owned prompts/events → completion → refreshed model list → explicit activation. Cover browser/redirect, device-code polling, remote/headless manual handoff where supported, secret/text/select/multiple prompts, progress/check, denial, invalid input, expiry, cancellation, timeout and retry. Unsupported non-UI modes must return an actionable error without hanging or starting an unapproved browser. Preserve provider-specific PKCE/state/redirect and device-code protections where applicable.

  • AUTH-04 — Auth lifecycle and ownership: test existing credentials after upgrade; refresh/rotation, expired/revoked credentials, failed refresh and reauthentication; concurrent sessions/refreshes; logout/remove and relogin; shutdown/replacement mid-flow. Provider-owned ModelRuntime APIs retain credential ownership. Failed/cancelled flows must neither report success nor replace working credentials. Logout removes the intended stored credential without implying revocation of externally managed environment/identity credentials; report the effective remaining auth source accurately.

  • AUTH-05 — Secrets and isolation: enforce the chosen authenticated-user/admin policy on login, callback submissions and logout. Reject cross-chat/user/provider/runtime and stale/replayed flow submissions; simultaneous flows must not leak prompts, codes, secrets or results. Secret card submissions must not persist in public transcript/card state, logs, traces, argv or models configuration. Preserve established secure credential backend/permissions, keychain/environment boundaries and scoped child access; no downgrade to an insecure store. Record callback/device-code exposure rules and redact sensitive URLs. Synthetic sentinel scans cover backups and failure paths too.

  • AUTH-06 — API keys, external and custom auth: cover save/update/remove, invalid/empty key, multi-field setup and effective precedence across stored, keychain/env and external sources using synthetic fixtures. Check Azure endpoint/deployment/identity distinctions and Bedrock/Vertex ambient-auth readiness without probing real cloud metadata. No invented browser login for external-only providers. Custom/local no-auth endpoints must not acquire an unnecessary credential requirement. Provider/environment fields and removed-provider diagnostics remain accurate.

  • AUTH-07 — Availability and Delegate: registry refresh reflects auth changes, while authenticating does not automatically select a model, approve a provider/model, raise a tier or change billing route. Preserve explicit activation in the initiating authorised session and Settings-approved/executable Delegate model gates. Parent SDK and child CLI resolve the same intended provider/credential source through their supported mechanism, with no unrelated credentials inherited or copied into child prompts/arguments. Logout/expiry yields a clear child failure, not fallback to another account/provider.

  • AUTH-08 — Recovery and release: document provider credential/profile format compatibility and safe upgrade/rollback behaviour using disposable synthetic profiles. Do not blindly restore superseded OAuth refresh tokens: reauthentication may be required after rotation. Protect snapshots and unrelated providers' credentials. Require passing offline artifact/SDK tests and web UI tests; record a separate user-approved live canary matrix for required account flows. A skipped required canary is a blocker or an explicit waiver, never a passing receipt. Authentication and billable inference are separate approvals.

Implementation Notes

Estimate: M · Risk: high · Source file: runtime/src/agent-control/handlers/login.ts

Source inspected on 29 September 2026 at Piclaw de82f7a0b31b460311a2192570b5ef66b2c936af; this is a later source snapshot than the initial epic's historical baseline. No deployment/version conclusion is inferred from the changed checkout.

  • runtime/src/agent-control/handlers/login.ts: card-driven provider flow delegates to ModelRuntime.login/logout/listCredentials; handles provider events and input, five-minute expiry, cancellation and post-login model selection. Flow keys currently use provider/auth type; isolation must be demonstrated, not assumed.
  • runtime/src/agent-control/provider-defs.ts: runtime getProviders() auth methods override static fallbacks; dynamic/removed provider and external-auth cases need fixtures. The static OpenAI fallback being API-key-only does not prove the exact runtime lacks OAuth.
  • runtime/src/utils/model-auth.ts and runtime/src/runtime/auth-maintenance.ts: runtime auth construction/maintenance and provider credential status.
  • Existing test seams: runtime/test/agent-control/agent-control-handlers.test.ts, provider-defs.test.ts, runtime/test/utils/model-auth.test.ts, runtime/test/agent-pool/ambient-auth-regressions.test.ts, runtime/test/runtime/provider-bootstrap.test.ts, runtime/test/secure/keychain-providers.test.ts.
  • Upstream 1.0.0 release, provider guide, OpenAI ChatGPT OAuth, OpenAI Codex OAuth and auth types.

This issue owns login acceptance and necessary auth-specific integration fixes; #1492 owns the new current-loop migration (#1445 is historical) and #160 owns Delegate packaging/policy. Avoid duplicate implementations. New unsupported provider methods require a clear disposition and user-approved scope decision.

Test Plan

  • Record every AUTH-01–08 row as not run, pass, fail or explicitly waived with evidence; distinguish static review, source tests, built-artifact tests, UI tests and live login.
  • Use temporary HOME/PI_AGENT_DIR, synthetic credentials, fake provider callbacks/HTTP and controlled clocks; deny unintended network calls and metadata access. Run focused tests via the repository's controlled launcher.
  • Browser/UI tests cover multi-step forms, cancellation, stale/replayed submissions, cross-session isolation, secret submission redaction and model activation. Non-UI tests cover supported manual handoff or bounded explicit rejection.
  • Test the actual distributable for the OpenAI openai-chatgpt.js regression and verify refresh/logout/persistence across a recreated runtime with synthetic state.
  • At qualification, request explicit approval before real OAuth/device login, credential refresh/revocation or account access. Never log the user out or rotate live credentials merely to test. Do not trigger a billable completion to validate login without separate permission.
  • Link exact package/commit/artifact, provider/auth-method matrix, test command/results and redacted evidence to Qualify Pi 1.0.4 core, shipped MCP wrapper and plain Delegate subprocess #1455 and Refactor extension system — pane contract, editor extraction, and tab support #160 before cutover.

Definition of Done

  • AUTH-01–08 criteria satisfied with exact-version receipts and reviewed provider/method coverage
  • Focused auth and UI tests, typechecks and packaged-artifact checks pass
  • Login/logout/headless/external-auth guidance and rollback notes updated
  • Security, account impact and credential migration risks assessed
  • Parent, qualification and Delegate dependency status reflects evidence

Historical 0.99.1 qualification is recorded in the linked receipts; it is not 1.0.0 execution evidence. No live account operations are authorised.

Pre-retarget issue body — historical record, not current target authority

Provider login qualification for Earendil 0.99.1

Provider authentication is a separate release gate from MCP OAuth. This is a planning amendment; no login, credential access, provider request, runtime test or deployment is authorised here.

Summary

Qualify Piclaw's complete provider-login path against exact Earendil 0.99.1, including the packaged OpenAI /login fix for missing openai-chatgpt.js. Test the shipped artifact as well as SDK integration; a source import or model-catalogue check does not prove login works.

Parent: #1442

MCP-server OAuth belongs to #1450 and cannot satisfy this provider-auth gate.

Dependencies

Acceptance Criteria

  • AUTH-01 — Provider/method inventory: derive a versioned matrix from the exact runtime's provider-owned auth definitions, plus Piclaw custom/external providers. Cover OpenAI and OpenAI Codex as separate provider IDs; GitHub Copilot; Anthropic; other advertised OAuth providers (including Kimi, OpenRouter and Radius where present); API-key providers including OpenAI/Azure/Google; external AWS Bedrock/Google Vertex/Azure identity; and custom/local no-auth providers. Distinguish OAuth, API-key, external and no-auth paths. Reconcile dynamic methods with Piclaw's static fallback; removed/unsupported methods must not appear as working login options. Do not infer support from a model name or an API-key field.
  • AUTH-02 — Packaged login: exercise /login and provider selection through the built/published 0.99.1 artifact and Piclaw SDK path in an isolated profile. Specifically resolve and invoke the OpenAI ChatGPT OAuth module under mocked network conditions, proving openai-chatgpt.js is present and reachable. Test OpenAI Codex separately. No private imports or source-tree substitutions in the packaging receipt.
  • AUTH-03 — Complete interactions: test provider picker → applicable method → provider-owned prompts/events → completion → refreshed model list → explicit activation. Cover browser/redirect, device-code polling, remote/headless manual handoff where supported, secret/text/select/multiple prompts, progress/check, denial, invalid input, expiry, cancellation, timeout and retry. Unsupported non-UI modes must return an actionable error without hanging or starting an unapproved browser. Preserve provider-specific PKCE/state/redirect and device-code protections where applicable.
  • AUTH-04 — Auth lifecycle and ownership: test existing credentials after upgrade; refresh/rotation, expired/revoked credentials, failed refresh and reauthentication; concurrent sessions/refreshes; logout/remove and relogin; shutdown/replacement mid-flow. Provider-owned ModelRuntime APIs retain credential ownership. Failed/cancelled flows must neither report success nor replace working credentials. Logout removes the intended stored credential without implying revocation of externally managed environment/identity credentials; report the effective remaining auth source accurately.
  • AUTH-05 — Secrets and isolation: enforce the chosen authenticated-user/admin policy on login, callback submissions and logout. Reject cross-chat/user/provider/runtime and stale/replayed flow submissions; simultaneous flows must not leak prompts, codes, secrets or results. Secret card submissions must not persist in public transcript/card state, logs, traces, argv or models configuration. Preserve established secure credential backend/permissions, keychain/environment boundaries and scoped child access; no downgrade to an insecure store. Record callback/device-code exposure rules and redact sensitive URLs. Synthetic sentinel scans cover backups and failure paths too.
  • AUTH-06 — API keys, external and custom auth: cover save/update/remove, invalid/empty key, multi-field setup and effective precedence across stored, keychain/env and external sources using synthetic fixtures. Check Azure endpoint/deployment/identity distinctions and Bedrock/Vertex ambient-auth readiness without probing real cloud metadata. No invented browser login for external-only providers. Custom/local no-auth endpoints must not acquire an unnecessary credential requirement. Provider/environment fields and removed-provider diagnostics remain accurate.
  • AUTH-07 — Availability and Delegate: registry refresh reflects auth changes, while authenticating does not automatically select a model, approve a provider/model, raise a tier or change billing route. Preserve explicit activation in the initiating authorised session and Settings-approved/executable Delegate model gates. Parent SDK and child CLI resolve the same intended provider/credential source through their supported mechanism, with no unrelated credentials inherited or copied into child prompts/arguments. Logout/expiry yields a clear child failure, not fallback to another account/provider.
  • AUTH-08 — Recovery and release: document provider credential/profile format compatibility and safe upgrade/rollback behaviour using disposable synthetic profiles. Do not blindly restore superseded OAuth refresh tokens: reauthentication may be required after rotation. Protect snapshots and unrelated providers' credentials. Require passing offline artifact/SDK tests and web UI tests; record a separate user-approved live canary matrix for required account flows. A skipped required canary is a blocker or an explicit waiver, never a passing receipt. Authentication and billable inference are separate approvals.

Implementation Notes

Estimate: M · Risk: high · Source file: runtime/src/agent-control/handlers/login.ts

Source inspected on 29 September 2026 at Piclaw de82f7a0b31b460311a2192570b5ef66b2c936af; this is a later source snapshot than the initial epic's historical baseline. No deployment/version conclusion is inferred from the changed checkout.

  • runtime/src/agent-control/handlers/login.ts: card-driven provider flow delegates to ModelRuntime.login/logout/listCredentials; handles provider events and input, five-minute expiry, cancellation and post-login model selection. Flow keys currently use provider/auth type; isolation must be demonstrated, not assumed.
  • runtime/src/agent-control/provider-defs.ts: runtime getProviders() auth methods override static fallbacks; dynamic/removed provider and external-auth cases need fixtures. The static OpenAI fallback being API-key-only does not prove the exact runtime lacks OAuth.
  • runtime/src/utils/model-auth.ts and runtime/src/runtime/auth-maintenance.ts: runtime auth construction/maintenance and provider credential status.
  • Existing test seams: runtime/test/agent-control/agent-control-handlers.test.ts, provider-defs.test.ts, runtime/test/utils/model-auth.test.ts, runtime/test/agent-pool/ambient-auth-regressions.test.ts, runtime/test/runtime/provider-bootstrap.test.ts, runtime/test/secure/keychain-providers.test.ts.
  • Upstream 0.99.1 release, provider guide, OpenAI ChatGPT OAuth, OpenAI Codex OAuth and auth types.

This issue owns login acceptance and necessary auth-specific integration fixes; #1445 owns general core migration and #160 owns Delegate packaging/policy. Avoid duplicate implementations. New unsupported provider methods require a clear disposition and user-approved scope decision.

Test Plan

  • Record every AUTH-01–08 row as not run, pass, fail or explicitly waived with evidence; distinguish static review, source tests, built-artifact tests, UI tests and live login.
  • Use temporary HOME/PI_AGENT_DIR, synthetic credentials, fake provider callbacks/HTTP and controlled clocks; deny unintended network calls and metadata access. Run focused tests via the repository's controlled launcher.
  • Browser/UI tests cover multi-step forms, cancellation, stale/replayed submissions, cross-session isolation, secret submission redaction and model activation. Non-UI tests cover supported manual handoff or bounded explicit rejection.
  • Test the actual distributable for the OpenAI openai-chatgpt.js regression and verify refresh/logout/persistence across a recreated runtime with synthetic state.
  • At qualification, request explicit approval before real OAuth/device login, credential refresh/revocation or account access. Never log the user out or rotate live credentials merely to test. Do not trigger a billable completion to validate login without separate permission.
  • Link exact package/commit/artifact, provider/auth-method matrix, test command/results and redacted evidence to Qualify Pi 1.0.4 core, shipped MCP wrapper and plain Delegate subprocess #1455 and Refactor extension system — pane contract, editor extraction, and tab support #160 before cutover.

Definition of Done

  • AUTH-01–08 criteria satisfied with exact-version receipts and reviewed provider/method coverage
  • Focused auth and UI tests, typechecks and packaged-artifact checks pass
  • Login/logout/headless/external-auth guidance and rollback notes updated
  • Security, account impact and credential migration risks assessed
  • Parent, qualification and Delegate dependency status reflects evidence

No tests or account operations have been run for this planning amendment.

Activity

  1. added
    area:webWeb UI, HTTP routes, service worker, and browser behavior
    on Sep 29, 2026
  2. added
    area:providersModel/provider login, auth, and provider-specific integrations
    area:securitySecurity, auth, and hardening
    type:auditAudit, review, or investigation
    blockedBlocked by another issue or external dependency
    on Sep 29, 2026
  3. piclaw-bot commented on Sep 30, 2026

    @piclaw-bot
    CollaboratorAuthor

    Source-only preflight against8bee16968 confirms AUTH gates needing implementation: runtimeAuthFlows keyed only provider/authType permits cross-session/stale-card lookup; deleteRuntimeAuthFlow deletes replacement by key without identity comparison; one-model successful login auto-activates via handleModel; raw provider errors enter logs/results and events require ownership-bound rendering. Independent bounded review agrees. Fix in dedicated#1458 worktree after#1453 evidence gate; no live credentials, login/logout/refresh or provider request performed.

  4. 59 remaining items

  5. piclaw-bot commented on Oct 2, 2026

    @piclaw-bot
    CollaboratorAuthor

    Pi1.0.0 official packaged-CLI auth delta is PR #1504. Ten guarded cases (8interactiveOpenAI/Codex +2provider-onlyconstraint) repeated3/261, full5914/8/0+25+9/historical468 and pack24746/types/reviews passed. Freshdisposableprofiles,netns,stablepreload,manualhandoff,/quit0 required. This does not qualify automaticcallback,CLIrefresh/logout,fullweb/private/tokenpolicy/Delegate/liveacceptance; old0991receipts preserved.

  6. piclaw-bot commented on Oct 2, 2026

    @piclaw-bot
    CollaboratorAuthor

    Exact1.0.0packagedCLI slice landed viaPR#1504 at276b212ec afterCI37001717260;postmerge3/261/10cases. Old0991receipts unchanged. OfficialOpenAI/CodexmanualPTYloginandprovider-onlyconstraint qualified, notautomaticcallback,CLIrefresh/logout,fullprivateweb/tokenpolicy/Delegate/liveacceptance. #1458 staysopen;no deploy/restart.

  7. piclaw-bot commented on Oct 2, 2026

    @piclaw-bot
    CollaboratorAuthor

    PR#1508 adds exact1.0.0builtinAnthropiccopy-code privatecard+recording/export browser evidence,10cases1342assertions bothengines; finalreceipt2/122 andfull5916/8/0+25+9/historical468/pack/types/reviews green. Existing syntheticmatrix unchanged. ActualUI cancel reachesblockedexchange afterprogressresponse; no productionworkaround. Familygateway/deployedshell/externaltraces/otherproviders remainunqualified bythisslice. #1458 remainsopen.

  8. piclaw-bot commented on Oct 2, 2026

    @piclaw-bot
    CollaboratorAuthor

    PR#1508 merged6254173f5: builtinAnthropiccopycode throughprivatecardcallback+fullrecording/exports qualified bothbrowsers10/1342postmerge,receipt2/122;exactCI37034098301green. URL/state/verifier/code/token/error sentinelsexcluded, explicitactivation andCancelbutton tested. Familyauthgateway/deployedshell/externaltracecollector/liveacceptance stillnotcertified;oldreceipts preserved. No install/restart.

  9. changed the title [-]Qualify provider login, refresh and logout for Pi 1.0.0[/-] [+]Qualify provider login, refresh and logout for Pi 1.0.1[/+] on Oct 3, 2026
  10. piclaw-bot commented on Oct 4, 2026

    @piclaw-bot
    CollaboratorAuthor

    Pi 1.0.1 implementation review — 4 October 2026

    Exact target: 1.0.1, upstream a7229ddc21810d6245105978033b7df645ecc2f7. Core #1537 merged at 98eb5ff4d after exact-head hosted CI and local full qualification: 6,095 passed / 8 skipped / 0 failed, 39,748 assertions, plus 25 feature and 9 web tests. Postmerge 55 tests / 1,380 assertions passed.

    Rui authorised the Smith install/restart. The restarted instance reports Piclaw 3.2.5 / Pi 1.0.1, canonical Bun, HTTP200, eight exact package payloads and import resolutions, unchanged configuration/database identity, recovered restart handoff and persisted chat. This local operational check does not complete provider-login or native-engine canary criteria.

    Delegate #166 merged at 12f35b5, published through the public tarball path, and 0.2.15 is installed. Global and workspace CLI both report1.0.1; manifest resolver and isolated synthetic catalogue checks passed with zero guarded network/child-process attempts. No model/provider approval or billing route changed.

    Original0.99.1/1.0.0 receipts are unchanged. The repository historical folder/replay hook was removed at Rui's explicit request; Git retains source history.

    Disposition

    Keep OPEN. Fresh1.0.1 provider inventory, packaged OpenAI/Codex CLI, browser/copy-code/device, credential lifecycle, Anthropic private UI and recording receipts passed; the migration keeps each historical receipt separate. AUTH-07 production Delegate credential/environment parity and AUTH-08 live-account/restore/canary disposition still require their own evidence or explicit scope decision. No live auth/inference was exercised.

    Exact-target evidence

    No missing acceptance row is marked passing.

  11. piclaw-bot commented on Oct 5, 2026

    @piclaw-bot
    CollaboratorAuthor

    The current Pi 1.0.1 acceptance matrix is merged in PR1548 (62a71d139).

    Remaining MCP/auth acceptance lists all15MCP and8AUTH requirements, current source/synthetic evidence and missing gates. Corrected fullgate6311pass/8skip/0fail plus25feature/9web; exactheadCI37248552703SUCCESS; postmerge8tests158assertions. Historical versioned receipts are unchanged.

    • The exact public1.0.1 probe still reports tenNativeAPIgaps; the separate close-failure regression still records an unclosed old transport despite reload success. Adapter/Auto retained, unsupportedNative admission denied.
    • Ledger1544, inactivehost1546 and sharedrequest1547 foundations are merged. Actualproductionprovider/authcleanup/accountauthority and Delegate/sharedactivation are unqualified; upstreamPi10461auto-close was contributorpolicy, not a fix.
    • Adapter server Settings controller/API/forms are a separate implementation lane; currentcorepin2400aec does not yet contain publicpreviewPR10.
    • Combined1455 and separatelyauthorisedcanary/rollout/soak/rollback1456 remain outstanding. Source gates do not extend the initial installedmigration receipt. Pi-durable stays excluded.

    This records evidence and blockers; no unmet acceptance criterion is waived and parent acceptance remains open. No new installation, restart, live account, credential lookup or provider expenditure was performed.

  12. changed the title [-]Qualify provider login, refresh and logout for Pi 1.0.1[/-] [+]Qualify provider login, refresh and logout for Pi 1.0.2[/+] on Oct 5, 2026
  13. piclaw-bot commented on Oct 5, 2026

    @piclaw-bot
    CollaboratorAuthor

    Released Pi1.0.2 retained-wrapper source reconciliation: #1552. Exact Settings CI37286187765, final full6456/8skip0fail, source-bound core100/405/wrapper316 and auth144 with explicit test-only correction are recorded. Historical criteria retained unchanged. This issue stays open for its production/live/rollout or wider resource gates. No installation/restart/live account/provider expenditure occurred.

  14. changed the title [-]Qualify provider login, refresh and logout for Pi 1.0.2[/-] [+]Qualify provider login, refresh and logout for Pi 1.0.3[/+] on Oct 5, 2026
  15. piclaw-bot commented on Oct 5, 2026

    @piclaw-bot
    CollaboratorAuthor

    Corrected synthetic VM900 canary completed

    PR1563 fixes the config-mode defect found by the first synthetic canary; PR1564 publishes the reviewed receipt and bounded acceptance scope.

    Corrected package SHA256 023d2541265cafa259bebe91ed41afbc3660816a7b98f5de0b719197a3516ddc, source 34e4bda1a6c35aebd22b9dd2a127854b2438d9cc, tree 66192a17691b6ddd36f47d4db175360b8187f43f. Frozen lock overlay installed on VM900 with Bun1.4.2; 785 package runtime/extension/manifest files verified against source and deployment. Source full6533/8existing skips/0fail42756 plus25feature/nineweb, exacthosted37346512175SUCCESS and config postmerge25/195. Receipt publication2ecb89364 merged78c49e26c, exacttreeparity, env/doc validation plus focused16/2388 and finalpostmerge5/69 pass; no unchanged full-suite repeat.

    Approved deterministic Classic service window ran17:13:30.017→17:43:30.036UTC: 1,800,019ms,59ordered prompt/reply cycles, samePID and exactly one terminal/plainreply each. Bothskin correlated visible prompt/reply/Settings checks, exact cancellation/SSE reconnect, actualrunningservice scheduler, packagedrealAgentPool leaf/source/recurrence, familyowner/CSRF/idempotency/500msrelease+revocation and actualruntimeMCPproxy syntheticloopback call passed within their stated scopes. Config modes stay0600 across observedstartup/restart/finalchecks. Watchdog32samples covers latterhalf only; Visualrestarts duringMCP qualification are not a second30minsoak. No outside-attempt markers; no universalpacket/rawauthsettlement claim.

    Allfivecanaryunits stopped; two freshprofiles quarantined withoutreplay; 48,755candidatefilehashes and65originalDB/sidecarhashes verified. OS/SSH/guestagentpreserved, approvedBunreplacementremains, Smithunchanged. Originalpackage8fc…failedafter21cycles becauseordinaryconfigwriterwidened0600→0644; failedrun/harnesscorrections/reviewtimeoutsretained and excluded. ConfigfixretainsstrictMCPcheck/privatewriteatomicrename.

    Evidence: canary document and receipt.

    Overall acceptance remains incomplete. Public rawauth/provider settlement/account-generation contracts and productionDelegate remain gated; required immutablecore/addon/policy/credential/soleowner/orphangates stayopen. Liveaccount/server/Memento checks, protectedAzurecredentialmigration, productionSmithdeployment/restart and token-aware rollback need separateapproval. Workspacegoaladdon typebox resolutionwarning is retained, not fixed by this slice. No parent issue closure or production activation follows from the synthetic pass.

  16. piclaw-bot commented on Oct 5, 2026

    @piclaw-bot
    CollaboratorAuthor

    Current Pi 1.0.3 source/synthetic checkpoint

    PR1565, merge ad2b298f10c10d81cb6d277620aa464da4c53dd4, fixes the fresh offline core add-on seed's missing host peers. Declared allowlisted peers link to the creating runtime instance; no duplicate Pi/package-manager/network startup install. Existing workspace/update/removal state is untouched, dangling targets fail closed, concurrent normal seed publishers are serialised. Absolute host links require a separate migration if the creating runtime moves; no native Windows execution or adversarial filesystem guarantee is asserted.

    Frozen 09a7597b1bb8073f78dcbfc7321486dbbf28286f, tree d1c2470b45d2a7656c098acbd4638699fcc89c9b: 6,537 pass / 8 existing skips / 0 fail / 42,781 assertions, plus25feature/nineweb; unchanged source binding. Sevenregressions/32assertions, guarded imports of seven actual pinned entry points with exact hostpeeridentity and0network/process attempts, publication22/2362 and postmerge7/32 pass. The import probe qualifies entry loading only, nottool/UI/paidDelegate execution. PR hosted37357905234/main37357910171 still in progress at18:48:52; no success inferred.

    PR1566, merge a446de1e0b72ed408bdcd6156f379faee3c4f8fa, records the current23-row MCP/auth checkpoint, hashes sevencurrentreceipts and retains older wrapper/auth/rollback executions as historical. Documentation-only parity, matrix/hash/link validation, env/diff and focused18/2394 plus postmerge10/96 pass; no unchanged full-suite rerun. Unsupported unbound postmerge counts were removed during independent review.

    Evidence: current acceptance matrix, checkpoint receipt, host-peer correction.

    Source/synthetic scopes are complete; overall production acceptance is not. Production Delegate still lacks public raw provider/auth settlement and account-generation authority contracts. Upstream10461 remains auto-closed by contributor policy with no delivered contract. Required immutable core/add-on/policy/credential/sole-owner/orphan checks and live account/server/Azure/Smith-rollout decisions remain open. No new installation/restart/live/account/paid request/production activation. No issue closing keywords or criterion waivers. User scope decision requested separately in card62795; generic goal continuation does not grant it. Original synthetic canary warning/failures are preserved, not retrospectively relabelled as new artifact passes.

  17. piclaw-bot commented on Oct 5, 2026

    @piclaw-bot
    CollaboratorAuthor

    Smith upgraded; current Delegate qualification merged

    Rui explicitly ordered core upgrade first, then Delegate. Smith upgrade verification passed19:34:42UTC: Pi1.0.1→1.0.3 across all8SDKpackages, canonicalBun1.4.2/newPID3025469/HTTP200, installedsourcea446de1e0/tree06d929eb verified, config/credentialbytesunchanged/config600, SQLiteDBidentity/quickcheck/chatmonotonicpreserved. Workingprivatebackup restored78,143file/symlinkentries, restoredSQLite healthy andold1.0.1SDKexecutionsmoke passed. Activewriter multi-fileJSONL snapshot is explicitly not a stopped-writer atomic snapshot. NoDelegateactivation/liveprovidertest follows automatically.

    Add-ons PR174 merged fbb7e02194336d3cf1280ee4b3d137d017a09a54. Current exactpublished1.0.3 CLI:76matchedselectedfiles/equalinventories, publicbin.pi offlineversion,1test94assertions; currentpublicprovider/privatepipeauth:564matchedselectedfiles/equalinventories,6casesrotation/scopedenvironment/logout/denied/disconnect/terminate,1test587assertions. Nonroot loopback-onlynamespace/capabilitieszero/noNewPrivs/minimalenv/no livecredentials ornetwork. Strictfixturetypesagainstexact103pass; compat281/15opt-in skips0fail1681 plus5typeprojects/catalog/standalone1/1 pass; postmerge3pass/2opt-skip0fail39. Tenhistorical1.0.0/1.0.1files preserved. This isqualificationtest/docs only; addonimplementation/version0.2.17unchanged andnotinstalled. Earliercatalogtimestampgate/incorrectintegrity/config/receiptcounterfailuresretained, notpasses.

    A fresh actualpublicPi1.0.3ModelRuntime syntheticheld-tail reproduction also passed in thecapzero/loopback-onlynamespace: cancelledauthdelivery rejects while rawresolverheld; terminal/result resolves whileprovider rawtailheld; bothrawtails laterreleased/drained. Zero network/emptycredentialstore. It confirms that publicresult()/auth delivery cannotimplementrawsettled/close acknowledgement. Upstream10461autoclosed status is notdelivery. No privateSDK/provider substitution/credentialcopy workaround isaccepted.

    InstalledSmithDelegate remains0.2.15, while publishedsource0.2.17hasCLI/authfailclosed fixes. Currentproductionchildlaunch inheritsparentenv; credential-freeparentproxy remainsunregistered and budget/MCP/account-generation/rawsettlement gatesopen. Newcurrent syntheticpipe doesnotclaimatomiclogoutdispatch/ambientcustomauth/realproviderbudgetparity. ProductionDelegate completion needs a qualified public raw-task/account-authority path or an explicitly narrowed reviewed execution plan and separate rollout/live validation authority. Keep #160 and core acceptance gatesopen; upgrade-order approval doesnotwaive those safetyrequirements.

  18. changed the title [-]Qualify provider login, refresh and logout for Pi 1.0.3[/-] [+]Qualify provider login, refresh and logout for Pi 1.0.4[/+] on Oct 6, 2026
  19. piclaw-bot commented on Oct 6, 2026

    @piclaw-bot
    CollaboratorAuthor

    v3.3.0 Modern Times is now published at e4c2b9a with Pi1.0.4. UX37509195565, main CI37509183176 and publish/integration37509955937 completed successfully after retained retries; release artifacts and GHCR architectures are verified. The release removes the old source-upgrade prerequisite, but does not satisfy the remaining acceptance in this issue: live account/provider coverage, outstanding supported-wrapper/security reconciliation or an explicitly approved installed canary/rollback must not be inferred from source/UX publication. Keeping this issue open; no Smith install/restart has occurred.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:providersModel/provider login, auth, and provider-specific integrationsarea:securitySecurity, auth, and hardeningarea:webWeb UI, HTTP routes, service worker, and browser behaviorblockedBlocked by another issue or external dependencyinitiative:earendil-0991Earendil 0.99.1 upgrade and upstream MCP replacementinitiative:earendil-100Pi 1.0.0 candidate assessment; no automatic target selectionpriority:highHigh prioritytype:auditAudit, review, or investigation

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions