You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Rui authorised retargeting to released Pi 1.0.2 on 5 October 2026, upstream commit cd32f7725fdbddbaecdff5b1e68491563394e0ca. This work integrates Pi with the standard MCP wrapper already shipped by Piclaw. Wrapper replacement, Native MCP parity and adapter removal are future work, not prerequisites for this integration. Keep one wrapper owner; reject unsupported Native selection without fallback. This scope decision does not weaken the shipped wrapper's credential, policy or cleanup requirements.
Preserve 0.99.1, 1.0.0 and 1.0.1 receipts as historical evidence. New 1.0.2 qualification is separate. Unreleased upstream OAuth cancellation changes after the 1.0.2 tag are excluded. Source updates, isolated tests, review and verified merges are authorised; installation, restart and real-account/provider tests still need separate approval. Pi-durable remains out of scope.
Integration checklist and completed slices
Retaining the shipped wrapper is the approved Pi 1.0.2 integration decision.
Adapter removal is excluded from current completion criteria.
Consider Native replacement only under a future explicit scope/approval and its own parity, security and rollback evidence.
Previous target criteria and receipts — preserved historical record
Active target — Pi 1.0.1 (3 October 2026)
Rui authorised retargeting and implementation to exact Pi 1.0.1, upstream git head a7229ddc21810d6245105978033b7df645ecc2f7. This supersedes the earlier 1.0.0 execution target below. Preserve all 0.99.1 and 1.0.0 receipts as historical evidence; they are not 1.0.1 qualification.
Source migration, exact-package admission and isolated Bun-only synthetic qualification are authorised. Keep Adapter/Auto as the default, reject unsupported native combinations, retain failed-teardown/Apply security gates, and exclude pi-durable. Live accounts, deployment, production installation, restart and canary remain separately authorised. Do not waive unresolved native, provider or Delegate acceptance gates.
Earlier target and requirements (retained)
Checkpoint: 958ac185255840ee4f800becc5f7e3111ef9acda on feat/mcp-settings-host; stable 0.99.1 source baseline, not 1.0.0 admission.
Shared target and MCP policy
Selected target: Pi 1.0.0, gitHead a13d35a742c6ef8462812a28fbe1d8c8b7431c32. Rui explicitly authorised retargeting all remaining work on 1 October 2026: stabilise and commit current work → update relevant issues/dependencies → resume the 1.0.0 upgrade on that checkpoint. Source changes, isolated dependency installs and offline qualification are authorised; runtime admission remains an acceptance gate, not an assumed result. All new execution is Bun-only. Live accounts/MCP/provider calls, production installation, deployment/restart and experimental pi-durable activation still require separate approval. Preserve completed 0.99.1 receipts and closed issue states as historical evidence; do not relabel them as 1.0.0 results.
Preserve the approved consolidated instance MCP settings: adapter/native selector, adapter default, exactly one active owner, codemode Auto/On/Off default Auto.
Engine switching aborts active turns and reloads all extensions through supported public APIs, retaining chats/history; no service restart. Unsupported combinations reject with explicit reasons; no silent fallback or dropped settings.
Ten native public-API gap diagnostics persist in the 1.0.0 assessment. Target selection is not a capability/security waiver.
Dormant conditional adapter-removal work. Begin only after a future explicit removal decision, native parity and matching Delegate qualification. This does not block the current selectable-engine release.
Also requires Delegate parity and an explicit future adapter-removal decision.
Acceptance Criteria
Treat removal as conditional future work, not a prerequisite for the approved selectable-engine release. Keep the adapter default and package available until parity and explicit removal approval exist.
Packaging must load only the selected implementation at runtime; retaining two available implementations must not create two active owners.
Only after explicit future adapter-removal approval, remove adapter dependency/lockfile entry, require/config/cache imports, factories, explicit extension paths and old timeout patch only after replacement coverage passes.
SDK and CLI inventory shows exactly one /mcp owner and one tool/connection registry; collision fails closed with no automatic fallback.
Migrate docs, seeded examples, skills/prompts/tests/automation from mcp proxy/direct prefixes to native discovery and the approved management/auth path.
Resume/fork of historical transcripts handles obsolete tool names without rewriting history, guessing targets or reconnecting a hidden server.
Keep previous matching core/Delegate artifacts and reference-only config for rollback, never simultaneously loaded.
Implementation Notes
Primary known seams: package.json, runtime/src/agent-pool/session.ts, secure/mcp-keychain.ts, mcp-status-hint-adapter.ts, mcp-timeout-patch.ts, bundled-adapter tests, docs/mcp.md and Delegate child loading. Use a bounded repository inventory to catch packaging and tests; do not claim absence from source search alone—inspect the built artifact.
Estimate: S · Risk: medium · Source file: package.json
MCP-15 artifact/lockfile/package scan, registration census and process count.
Updated bundled/native SDK/CLI/Delegate loading tests and migration-guidance checks.
Definition of Done
Acceptance criteria satisfied with exact-version evidence
Required tests/typechecks pass (documentation-only changes use structural/link review)
Docs and migration guidance updated
Operational impact and rollback assessed
Update history and parent/dependency status reflect evidence
Pre-retarget issue body — historical record, not current target authority
Summary
Build a single-owner candidate artifact after parity components and the Delegate replacement are complete.
Planning record only. This issue does not authorise package installation, live credentials/MCP/provider calls, production activation, deployment or restart. Target exactly Earendil 0.99.1 (gitHead d86654abb8862e201933517d6f1fce9f88dd117f), starting from 0.87.1 / Delegate 0.2.13. A later upstream fix needs an explicit target decision and its own receipt. Preserve completed 0.87.1 history.
Remove adapter dependency/lockfile entry, require/config/cache imports, factories, explicit extension paths and old timeout patch only after replacement coverage passes.
SDK and CLI inventory shows exactly one /mcp owner and one tool/connection registry; collision fails closed with no automatic fallback.
Migrate docs, seeded examples, skills/prompts/tests/automation from mcp proxy/direct prefixes to native discovery and the approved management/auth path.
Resume/fork of historical transcripts handles obsolete tool names without rewriting history, guessing targets or reconnecting a hidden server.
Keep previous matching core/Delegate artifacts and reference-only config for rollback, never simultaneously loaded.
Implementation Notes
Primary known seams: package.json, runtime/src/agent-pool/session.ts, secure/mcp-keychain.ts, mcp-status-hint-adapter.ts, mcp-timeout-patch.ts, bundled-adapter tests, docs/mcp.md and Delegate child loading. Use a bounded repository inventory to catch packaging and tests; do not claim absence from source search alone—inspect the built artifact.
Estimate: S · Risk: medium · Source file: package.json
Current integration target — Pi 1.0.2
Rui authorised retargeting to released Pi 1.0.2 on 5 October 2026, upstream commit
cd32f7725fdbddbaecdff5b1e68491563394e0ca. This work integrates Pi with the standard MCP wrapper already shipped by Piclaw. Wrapper replacement, Native MCP parity and adapter removal are future work, not prerequisites for this integration. Keep one wrapper owner; reject unsupported Native selection without fallback. This scope decision does not weaken the shipped wrapper's credential, policy or cleanup requirements.Preserve 0.99.1, 1.0.0 and 1.0.1 receipts as historical evidence. New 1.0.2 qualification is separate. Unreleased upstream OAuth cancellation changes after the 1.0.2 tag are excluded. Source updates, isolated tests, review and verified merges are authorised; installation, restart and real-account/provider tests still need separate approval. Pi-durable remains out of scope.
Integration checklist and completed slices
Previous target criteria and receipts — preserved historical record
Active target — Pi 1.0.1 (3 October 2026)
Rui authorised retargeting and implementation to exact Pi 1.0.1, upstream git head
a7229ddc21810d6245105978033b7df645ecc2f7. This supersedes the earlier 1.0.0 execution target below. Preserve all 0.99.1 and 1.0.0 receipts as historical evidence; they are not 1.0.1 qualification.Source migration, exact-package admission and isolated Bun-only synthetic qualification are authorised. Keep Adapter/Auto as the default, reject unsupported native combinations, retain failed-teardown/Apply security gates, and exclude pi-durable. Live accounts, deployment, production installation, restart and canary remain separately authorised. Do not waive unresolved native, provider or Delegate acceptance gates.
Earlier target and requirements (retained)
Checkpoint:
958ac185255840ee4f800becc5f7e3111ef9acdaonfeat/mcp-settings-host; stable 0.99.1 source baseline, not 1.0.0 admission.Shared target and MCP policy
Selected target: Pi 1.0.0, gitHead
a13d35a742c6ef8462812a28fbe1d8c8b7431c32. Rui explicitly authorised retargeting all remaining work on 1 October 2026: stabilise and commit current work → update relevant issues/dependencies → resume the 1.0.0 upgrade on that checkpoint. Source changes, isolated dependency installs and offline qualification are authorised; runtime admission remains an acceptance gate, not an assumed result. All new execution is Bun-only. Live accounts/MCP/provider calls, production installation, deployment/restart and experimental pi-durable activation still require separate approval. Preserve completed 0.99.1 receipts and closed issue states as historical evidence; do not relabel them as 1.0.0 results.Summary
Dormant conditional adapter-removal work. Begin only after a future explicit removal decision, native parity and matching Delegate qualification. This does not block the current selectable-engine release.
Parent: #1442
MCP contract: #1444
Dependencies
Acceptance Criteria
Treat removal as conditional future work, not a prerequisite for the approved selectable-engine release. Keep the adapter default and package available until parity and explicit removal approval exist.
Packaging must load only the selected implementation at runtime; retaining two available implementations must not create two active owners.
Only after explicit future adapter-removal approval, remove adapter dependency/lockfile entry, require/config/cache imports, factories, explicit extension paths and old timeout patch only after replacement coverage passes.
SDK and CLI inventory shows exactly one /mcp owner and one tool/connection registry; collision fails closed with no automatic fallback.
Migrate docs, seeded examples, skills/prompts/tests/automation from mcp proxy/direct prefixes to native discovery and the approved management/auth path.
Resume/fork of historical transcripts handles obsolete tool names without rewriting history, guessing targets or reconnecting a hidden server.
Keep previous matching core/Delegate artifacts and reference-only config for rollback, never simultaneously loaded.
Implementation Notes
Primary known seams: package.json, runtime/src/agent-pool/session.ts, secure/mcp-keychain.ts, mcp-status-hint-adapter.ts, mcp-timeout-patch.ts, bundled-adapter tests, docs/mcp.md and Delegate child loading. Use a bounded repository inventory to catch packaging and tests; do not claim absence from source search alone—inspect the built artifact.
Estimate: S · Risk: medium · Source file:
package.jsonSource anchors: Piclaw baseline, upstream release, MCP guide, public extension options.
Test Plan
Definition of Done
Pre-retarget issue body — historical record, not current target authority
Summary
Build a single-owner candidate artifact after parity components and the Delegate replacement are complete.
Planning record only. This issue does not authorise package installation, live credentials/MCP/provider calls, production activation, deployment or restart. Target exactly Earendil 0.99.1 (gitHead
d86654abb8862e201933517d6f1fce9f88dd117f), starting from 0.87.1 / Delegate 0.2.13. A later upstream fix needs an explicit target decision and its own receipt. Preserve completed 0.87.1 history.Parent: #1442
MCP contract: #1444
Dependencies
Acceptance Criteria
Implementation Notes
Primary known seams: package.json, runtime/src/agent-pool/session.ts, secure/mcp-keychain.ts, mcp-status-hint-adapter.ts, mcp-timeout-patch.ts, bundled-adapter tests, docs/mcp.md and Delegate child loading. Use a bounded repository inventory to catch packaging and tests; do not claim absence from source search alone—inspect the built artifact.
Estimate: S · Risk: medium · Source file:
package.jsonSource anchors: Piclaw baseline, upstream release, MCP guide, public extension options.
Test Plan
Definition of Done