Repository navigation
feat(claude-code-cli): add the pi:interactive native target - #213
Merged
Merged
Conversation
A native session runtime is needed for API-key vendors other than Claude and Codex, and the pi coding agent fits that role. pi ships no permission system of its own, so this target's whole job is the launch contract: an argv that disables every pi tool except the host-owned MCP server's, a server-owned agent directory the target writes itself, an authored system prompt, and loud wall-hits for every shape the contract cannot keep. The target realizes `--purpose analysis` only, requires `--native-mcp` and a `--pi-model <provider>/<model-id>`, rejects `--provider` fragments and scope entry, and degrades divergent step tiers to the single session model unless a host plan runs the steps. The MCP credential is referenced through its environment variable in `mcp.json`, never written. Existing targets' launch specs are unchanged; the renderer only gains an optional pi input. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…dash-leading model ids out of its argv Review of the pi target found two gaps between what the code enforced and what it claimed. `NativeHost::prepare` only knew the Claude and Codex vendors, so `--native-host` with `pi:interactive` was refused as a wall-hit while the docs and the capability profile said a host plan restores exact step tiers; the vendor table now has a `pi` arm, with the same no-scope-entry rule as Codex, and the v5 composed-session test covers pi. `PiModel::parse` accepted a provider or model id starting with `-`, which would have put an option-shaped value in a flag position of the closed argv; both now fail validation. Tests also cover a changed model being refused on repeat dispatch and the dashboard-only tool allowlist. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ost-plan targets `docs/site/docs/reference/direct-session.md` is generated from `docs/spec/direct-session.md`; the previous commit edited the generated page directly, so the docs-site workflow's generated-content check failed. The change now lives in the source the generator reads. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
GenBI wants a vendor-neutral native session runtime for API-key vendors (anything other than Claude Code and Codex). The pi coding agent (earendil-works/pi) fits that role, but it ships no permission system: it executes every tool call with the account's OS permissions. A Warble target for pi therefore has one job — author a launch contract that leaves the session nothing but the host-owned MCP server, and refuse every shape it cannot keep inside that contract.
What
A fifth native target,
pi:interactive, folded into thewarblebinary next tocodex:interactive.warble dispatch ir.json --target pi:interactive --purpose analysis --native-scope scope.json --native-mcp mcp.json --pi-model <provider>/<model-id> --out <cwd>emits:.warble/pi/SYSTEM.md— the authored system prompt (brief + analysis prompt fragment + scope/safety instructions + the shared persistence/presentation/dashboard instructions), handed to pi through--system-prompt, which replaces its default prompt;.warble/pi/agent/settings.jsonand.warble/pi/agent/mcp.json— the server-owned pi agent directory (PI_CODING_AGENT_DIR). Project trust is refused, telemetry is off, pi's own retries are off, and the MCP credential is referenced through${WARBLE_MCP_CONNECTION_CREDENTIAL}so the file never carries it (same posture as Codex'sbearer_token_env_var);RUN.md,.warble/interactive-launch.json(v4, or v5 with--native-host) and.warble/interactive-ownership.json.argvstarts an RPC session with every pi discovery mechanism switched off by name and an explicit--tools mcp__genbi_session__…allowlist.--no-toolsis deliberately not used: it also drops MCP tools. The spec's newpiobject carries the one-shot JSON-mode argv (prompt positional after--), the first prompt for the RPCpromptcommand, the agent directory, the required environment, and the minimum pi version (1.0.4, the first release whose--toolskeeps MCP tools when named).--native-hostplan runs the steps.analysis, a missing--native-mcp, a missing or malformed--pi-model,--providerfragments, scope entry, component composition without a host, and any component whose shape no host MCP tool serves.No existing target's output changes;
claude-code:*andcodex:interactivelaunch specs are byte-identical to before (the only shared-code change threads an optionalpiinput through the launch-spec renderer).Verification
cargo fmt --all --checkcargo clippy --workspace --all-targets --locked -- -D warningscargo build --workspace --lockedcargo test --workspace --lockedRUSTDOCFLAGS=-D warnings cargo doc --workspace --no-depscli/tests/pi_interactive_dispatch.rs(8 tests)cargo build --release -p warble-cli+just install-ts lint-ts test-ts build-tsjust install-codex-ts lint-codex-ts test-codex-ts build-codex-tsjust install-bird-eval lint-bird-eval test-bird-eval build-bird-evaljust publish-checkWhat I did not exercise:
--toolsallowlist semantics, env-var interpolation inmcp.json, RPC lifecycle). A comma-separated--toolslist with several exact names was not part of that measurement; only a single exact name and amcp__*glob were.--native-host(v5) path for pi is covered by the shared host validation and plan writing, not by a pi-specific live test.🤖 Generated with Claude Code