Skip to content

spec: 004 Pi coding agent support in Chainloop Trace - #3523

Open
waveywaves wants to merge 1 commit into
chainloop-dev:mainfrom
waveywaves:spec/pi-trace-provider
Open

waveywaves wants to merge 1 commit into
chainloop-dev:mainfrom
waveywaves:spec/pi-trace-provider

Conversation

@waveywaves

@waveywaves waveywaves commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

This PR adds Spec 004 only. It changes no implementation code. The implementation issue is #3520.

Summary

The spec designs native Chainloop Trace support for the Pi coding agent.

  • trace init --pi and trace run --pi install one marked, project-local Pi extension without overwriting an unrelated file.
  • Pi lifecycle and built-in write, edit, and bash events use the existing Trace hook pipeline without blocking Pi.
  • An optional normalized tool_call_id prevents concurrent Pi calls from overwriting each other's snapshots while preserving existing-provider behavior.
  • The provider copies and parses persisted Pi JSONL v3, rejects stale refreshes, persists /tree selection with a plain custom marker, and emits the existing AI coding-session evidence schema.
  • Pi receives the full model instruction once per session and the short Spec 003 capture reminder on every user turn.
  • Start banners and post-push links use Pi UI where available; headless links use stderr without corrupting stdout.
  • The design pins Pi 0.80.10 as the compatibility baseline and defines trust, timeout, output-bound, shutdown-reason, corruption, --no-session, and fork behavior.
  • Existing provider defaults, control-plane APIs, protobufs, and attestation schemas stay unchanged.

Decisions for reviewers

Please challenge these choices in particular:

  • D-001/D-002: generate a marked .pi/extensions/chainloop-trace.ts instead of requiring a Pi fork or separate package.
  • D-007: append a plain custom marker after session_tree, then parse from the last persisted entry.
  • D-011: do not make pre-push discover sessions whose Pi hooks never ran.
  • D-012: add optional tool_call_id only to normalized local hook/snapshot state.
  • D-013: bound each hook subprocess to five seconds and 64 KiB per output stream.
  • D-015: deliver post-push links through Pi UI or headless stderr.

Verification

  • Rebased on current main; the filename and title use the next available number, Spec 004.
  • Checked every requirement against the current Trace provider, hook, state, pre-push, and evidence paths.
  • Checked lifecycle, session-tree, custom-message, trust, mode, and tool-event claims against Pi 0.80.10 docs and installed types/runtime.
  • Reconciled Pi behavior with accepted Spec 003's per-turn capture reminder.
  • git diff --check

Refs #3520

AI assistance

pi helped research and write this spec. The commit carries an Assisted-by: pi trailer.

@chainloop-platform

chainloop-platform Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

AI Session Checks — ⚠️ no AI session found

Missing AI Coding Sessions

This organization requires every PR to be backed by a Chainloop Trace AI coding session, and none was found for this one.

Please make sure the AI coding session evidence has been sent by the Chainloop CLI, or add the skip-ai-session label to this PR to bypass this check.

Learn more about Chainloop Trace.


Security Checks — ✅ 5 passing

✅ secret-scan

Status Policy Messages
✅ Passed secrets-detection -

✅ sast-scan

Status Policy Messages
✅ Passed owasp-top10-2025 -
✅ Passed sast -
✅ Passed cwe-top25 -
✅ Passed cwe-top26-40-cusp -

✅ security-context — no advisories

Nothing this change touches has a recorded security-fix history.

View security context ↗ · Security context documentation ↗

⏭️ 3 scans not applied

Scan Reason
vulnerability-scan no manifest/lockfile changed
github-actions-scan no workflow files changed
iac-scan no IaC files changed

View attestation ↗


PR validation — ⚠️ 1 failing

Status Policy Material Messages
⚠️ Failed pr-min-approvals pr-info PR/MR #3523 has 0 approving reviews, 1 required.
✅ Passed pr-description-required pr-info -
✅ Passed pr-user-story-linked pr-info -

View attestation ↗


Powered by Chainloop and Chainloop Trace

@waveywaves
waveywaves force-pushed the spec/pi-trace-provider branch from 2725489 to 6f16d00 Compare October 5, 2026 12:53
@waveywaves waveywaves changed the title spec: Pi coding agent support in Chainloop Trace spec: 004 Pi coding agent support in Chainloop Trace Oct 5, 2026
Define the project-local Pi extension, lifecycle and tool hooks, JSONL v3 parsing, active-branch semantics, and evidence mapping for native Chainloop Trace support.

Refs: chainloop-dev#3520

Assisted-by: pi
Signed-off-by: Vibhav Bobade <vibhav.bobde@gmail.com>
@waveywaves
waveywaves force-pushed the spec/pi-trace-provider branch from 6f16d00 to 1e20465 Compare October 5, 2026 15:02
@waveywaves
waveywaves marked this pull request as ready for review October 6, 2026 05:56

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 1 file

Re-trigger cubic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant