Skip to content

chore(main): release 0.1.4 - #2

Merged
boadij merged 1 commit into
mainfrom
release-please--branches--main--components--pi-herdsman
Sep 7, 2026
Merged

boadij merged 1 commit into
mainfrom
release-please--branches--main--components--pi-herdsman

Conversation

@github-actions

@github-actions github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

🤖 I have created a release beep boop

0.1.4 (2026-09-07)

CI

  • add manual release workflow (a992304)

Other Changes

  • update package-lock.json version to 0.1.3 (80f450c)

This PR was generated with Release Please. See documentation.

@boadij
boadij merged commit ac8b944 into main Sep 7, 2026
@boadij
boadij deleted the release-please--branches--main--components--pi-herdsman branch September 7, 2026 12:45
boadij added a commit that referenced this pull request Oct 1, 2026
## Implementation report

- **Base:** `main` at `156b1c661a2e147d6bb2ef415abe44dd6b11af2f`
- **Head:** `ba06fdfe82f2dfce80aacec7d6cd09589db53f57` (`fix: align
project coordination handoff behavior`)
- **PR:** #201

### Project coordination

- Added automatic nonterminal Manager handoff when an assigned project
Lead herd run settles.
- The handoff reuses ordinary durable `ProjectMessage` transport and
persists independently of current Manager availability.
- The latest meaningful Lead assistant response from the herd run is
included when available:
  `Herd run settled.\n\n<summary>`
- Automatic handoff does **not** resolve the project assignment. Only
Manager `staff_complete` or `staff_discard` is terminal.
- Project publication and terminal resolution share the canonical
fail-fast project-assignment lock so a late handoff cannot recreate
messages after resolution.

### Supervisor awareness

- Added transient Lead supervisor-state context derived from current
Pi/Herdr authority rather than persisted presence.
- Assigned project Leads distinguish:
  - verified live Manager → `available`
  - verified absent Manager → `unavailable`
  - inconclusive Manager verification → `unknown`
- Ordinary Leads retain fail-closed behavior when no supervisor can be
verified.
- Supervisor-state messages are hidden, semantic, and appended only when
the observed state changes; Manager identity is not exposed to the
model.
- Tool definitions remain stable.

### Coordination guidance

- Updated `SKILL.md` and coordination docs so normal project progress
stays local and Herdsman performs the routine settled-run handoff
automatically.
- `supervisor_message` is reserved for coordination that changes what
the supervisor needs to decide, act on, review, or know about, including
blockers, warnings, scope changes, risks, and explicit evidence.
- Assigned project messages remain retained for the Manager role across
Manager absence or turnover.
- ADR 0012 now states that settled project herd runs may emit
nonterminal Manager handoffs and that these do not resolve the
assignment.

### Validation

- Focused suites passed:
  - controller-lifecycle: **93**
  - controller-api: **93**
  - commands: **75**
  - extension-contract: **41**
  - supervision: **54**
- `npm run check`: **779 passed, 1 skipped, 0 failed**
- `npm run build`: passed
- `npm run package:audit`: passed (**54 files**)
- `prettier . --write`: passed
- `git diff --check`: passed
- `npm run smoke -- manager-recovery`: passed on
`ba06fdfe82f2dfce80aacec7d6cd09589db53f57`
- Recorded environment: Node **26.8.1**, Pi **0.99.2**, Herdr
client/server **0.9.3**
- Smoke cleanup passed and the worktree remained clean.

### External review

- **External Review #2:** no findings at
`ba06fdfe82f2dfce80aacec7d6cd09589db53f57`.
- The four findings from External Review #1 were resolved:
- assigned Manager verification preserves `unknown` instead of inventing
`unavailable`
- Lead guidance no longer requires an available supervisor for project
messaging
- project publication and resolution use the canonical fail-fast
assignment lock
  - duplicate controller-api fixture field removed
- GitHub Actions Validate run **#575** passed on this head across
Ubuntu, macOS, Windows, package, container, scope, and aggregate CI.

### Reload behavior tracked separately

A later live test showed that the same automatic project handoff works
with fresh Pi Manager/Lead processes but can fail after `/reload` of
existing sessions until Pi is fully restarted.

That reload-specific behavior is tracked separately in **#205** and is
not part of this PR's normal fresh-session handoff implementation.

### Diff

- **11 files changed**
- **990 additions**
- **162 deletions**

---------

Co-authored-by: Jeffrey Boadi <25706638+boadij@users.noreply.github.com>
boadij added a commit that referenced this pull request Oct 4, 2026
## Summary
- Unify management selection menus around Pi's native SelectList,
SelectItem description metadata, Text contextual help, and
getSelectListTheme().
- Group low-frequency configuration under Settings; flatten Definitions
and align Running, layout, message-limit, and Chief interactions.
- Preserve runtime, configuration, definition, identity, and lifecycle
semantics. SettingsList was deliberately unnecessary: existing async
command workflows remain better expressed through the shared native
SelectList selector.

## Validation (current integrated PR head)
- `npm test -- extension/commands.test.ts`: 90 passed.
- `npm test -- extension/controller-api.test.ts`: 95 passed.
- `npm run build`: passed.
- `npm run check`: 835 passed, 1 skipped, 0 failed.
- `npm run smoke -- manager-recovery`: passed.
- `git diff --check`: passed.


## External Review #1 resolution / validation
- Applied Pi's native compact SelectList layout, clarified that explicit
Model/Thinking values apply to future Agent generations while unset
values inherit or restore as appropriate, changed the shared footer to
“Esc close,” and restored the schema Fields table formatting while
retaining the managed-Lead sentence correction.
- Focused checks: `npm test -- extension/commands.test.ts` 88/88; `npm
test -- extension/controller-api.test.ts` 95/95; `npm run build` passed;
`npm run check` 833 passed, 1 skipped, 0 failed; `git diff --check`
passed.
- Earlier package audit: `npm run package:audit` passed (59 files). Live
smoke not run.
- No Prettier rerun for this follow-up: a formatter attempt reflowed the
schema table and CHANGELOG; those incidental changes were restored
surgically. No permanent formatter configuration change was made.

## External Review #2 resolution / validation
- Limited the duplicate Running-label ambiguity guard to RPC, where
string selection cannot distinguish rows; TUI uses stable row values and
retains exact fresh identity revalidation before focus.
- Added managed-Lead-specific Model/Thinking help, one-row vertical
spacing around contextual help, and updated Getting Started to reflect
the Settings hierarchy.
- Validation: `extension/commands.test.ts` 89/89;
`extension/controller-api.test.ts` 95/95; `npm run build` passed; `npm
run check` 834 passed, 1 skipped, 0 failed; `git diff --check` passed.
- Prettier ran once with a temporary repository-root ignore excluding
only the schema table and CHANGELOG; no persistent config or broad
churn. Live smoke: NOT RUN because no compatible TTY/Herdr session was
available.

## External Review #3 resolution / validation
- Removed the shared 32-column cap: the maximum primary-column width now
derives from each label's `visibleWidth + 2`, with a minimum of 12; Pi
still clamps to the available terminal width. No menu-specific override
or new abstraction.
- Validation: `extension/commands.test.ts` 89/89;
`extension/controller-api.test.ts` 95/95; `npm run build` passed; `npm
run check` 834 passed, 1 skipped, 0 failed; `git diff --check` passed.
- Prettier ran once with temporary repository-root ignores; no
schema/CHANGELOG churn remains. Live smoke: NOT RUN.

## External Review #4 resolution and validation

- Shared contextual help is bounded and normalized to 160 display
characters.
- Manager/Chief supervision labels use a visible-width primary column
(`visibleWidth(label) + 2`, minimum 12). The model picker is unchanged.
- Validation: `extension/commands.test.ts` 89/89;
`extension/controller-api.test.ts` 95/95; build passed; `npm run check`
834 passed, 1 skipped, 0 failed; `git diff --check` passed. Prettier ran
once using a temporary ignore that preserved
`docs/reference/agent-definition-schema.md` and `CHANGELOG.md`. Live TUI
smoke: NOT RUN.

---------

Co-authored-by: Jeffrey Boadi <25706638+boadij@users.noreply.github.com>
boadij added a commit that referenced this pull request Oct 6, 2026
## Summary

- Make the exact current `ProjectAssignment` the durable authority edge
for managed Leads. Manager reports and staff actions include only live
exact assigned Leads; shared worktree scope alone grants no Manager
authority. This intentionally removes ambient Manager control over
unassigned Leads, which remain eligible for Chief supervision.
- Automatically return each completed direct turn from an assigned Lead
to the Manager role. When a herd run owns the work, its settlement
remains the single automatic handoff. Results are nonterminal and
routine progress is informational.
- Add confirmed `/takeover` to remove the current assignment and pending
project messages while preserving the Pi session and conversation,
branch, worktree, running process, and Lead-owned Agents. Manual
continuation of the exact assigned session remains managed until
explicit takeover.
- Serialize Manager `staff_stop` with the cross-process assignment lock
so takeover cannot revoke authority during stop. Revalidate Manager
lease and direct-report identity after `staff_inspect` evidence
collection.
- Derive and render `lead · managed` from current assignment state,
without changing the Agent ownership breadcrumb. Update current
documentation and add ADR 0017.
- Clarify that `supervisor_message` queues nonblocking material
coordination before the normal result boundary; it does not wait for a
Manager reply or block project work. It is not for routine status or
duplicate handoffs, and the example now describes a compatibility risk
rather than a blocked Agent.

## Validation

- Review #1 focused authority/takeover regressions: **3 passed**; `npm
test -- extension/controller-api.test.ts`: **100 passed**.
- Review #1 `npm run validate`: **848 passed, 1 skipped** (849 total);
build and package audit passed.
- Review #2 focused smoke-sequencing regression: **1 passed**; `npm test
-- extension/smoke-runner.test.ts`: **60 passed**.
- Review #2 `npm run validate`: **849 passed, 1 skipped** (850 total);
build and package audit passed.
- Final smoke-wait fix focused suite: `npm test --
extension/smoke-runner.test.ts` — **60 passed**; `npm run validate` —
**849 passed, 1 skipped**, build and package audit passed (62 files).
- Final formatting ran once with `prettier . --write`; two unrelated
formatter-only files were restored without rerunning Prettier. Then `npm
run check` passed (**849 passed, 1 skipped**, 850 total) and `git diff
--check` passed.
- Final documentation/guidance clarification: `npm run check` passed
(**855 passed, 1 skipped**, 856 total); `git diff --check` passed.
Prettier ran once; unrelated formatter-only changes were restored
without a second run.

### Manager-recovery smoke history

- The earlier pre-review feature-validation run passed once.
- The first manager-recovery run after the review #1 authority fixes
**failed (exit 1)** with repeated `Agent is already processing a prompt`
errors after the scenario reached recovery and `staff_stop`. Review #2
identified an obsolete sequencing assumption: it prompted Manager after
the Lead reply but before the automatically triggered project-message
turn was known to be settled.
- A separate diagnostic run before the sequencing correction **passed
(exit 0)** because the automatic Manager turn happened to finish before
the explicit prompt. That timing-dependent pass did not fix or
reclassify the earlier failure. Its log remains at
`.pi-herdsman/review1-smoke-diagnostic.log`.
- Review #2 changed the smoke to wait for the exact project-message
receipt matching branch, first Lead session, and context marker, then a
settled Manager assistant turn, before sending its explicit review
prompt. One invocation after this sequencing correction **passed (exit
0)** with cleanup passing. Its log remains at
`.pi-herdsman/review2-smoke.log`.
- A later run exposed missing model-wait classifications for the
`direct-handoff-settled` and `graceful-close` stages. The review #3 run
**failed (exit 1)** at `manager-recovery-graceful-close` with
`SMOKE_STALLED` after about 15 seconds; evidence showed the expected
READY handshakes had completed, but graceful close was not observed
before the control stall timeout. Cleanup passed. This outcome remains
recorded at `.pi-herdsman/review3-smoke.log` and was not reclassified.
- The final smoke fix adds both `direct-handoff-settled` and
`graceful-close` to the progress and stall-timeout model-wait lists. One
final `npm run smoke -- manager-recovery` invocation **passed (exit 0)**
through graceful close, resume/recovery, and retirement; cleanup passed.
Full output: `.pi-herdsman/final-smoke.log`; validation report:
`.pi-herdsman/final-smoke-validation.md`.

Closes #278
Closes #277

---------

Co-authored-by: Jeffrey Boadi <25706638+boadij@users.noreply.github.com>
boadij added a commit that referenced this pull request Oct 8, 2026
Closes #294

## Summary

- Add three standalone, independently configurable Lead definitions:
`flexible-lead`, `orchestrator-lead`, and `managed-lead`. Ordinary Leads
select Flexible or Orchestrate; assigned project Leads use
`managed-lead`. The definitions do not compose or inherit from one
another.
- Persist ordinary execution mode and its normal tool baseline
separately from role/authority state. Project native Pi active-tool
projection and structured prompt sections through the selected profile,
while preserving mandatory Lead coordination tools.
- Add the `/herdsman` Execution surface, `/lead` selector/direct
command, and a future-session `defaultLeadExecution` setting.
- Make successful `/takeover` release Manager assignment authority and
transition the preserved session to ordinary Orchestrate using
`orchestrator-lead`, after profile preflight.
- Preserve the ordinary tool baseline when a restricted Flexible profile
is selected, and restore branch-specific execution mode, baseline, tool
projection, and prompt guidance during `/tree` navigation.
- Reconcile cached Managed execution after successful assignment
retirement while preserving Managed state when assignment/topology
lookup fails. After takeover releases authority, recover safely from
local execution-state persistence failure and attempt fail-closed tool
projection without masking the original error.
- Keep temporary usage fixtures under `PI_AGENT_ROOT`; lifecycle socket
fixtures use platform-appropriate paths and close clients/server before
cleanup.

Manager authority remains established only by the existing exact
`ProjectAssignment` semantics, and Agent ownership semantics are
unchanged.

## External review follow-up

- **External Review #1:** Preserve the ordinary Pi tool baseline when
Flexible has a restrictive profile; restore branch-specific execution
state and projection during tree navigation; reconcile execution after
assignment retirement; and recover safely if takeover persistence fails
after authority release.
- **External Review #2:** Keep role reconciliation independent from
malformed branch execution state and fail ordinary execution closed;
reject ordinary mode changes when a Managed Lead's assignment scope is
unavailable; and make ordinary mode activation transactional, restoring
prior state/tools on failure or invalidating execution and failing
closed if rollback also fails.

## Validation

- Focused regression cases — **5 passed, 0 failed** (ordinary activation
rollback, failed rollback fail-closed behavior, malformed selected
branch, and Managed assignment-scope behavior in trusted/untrusted
variants).
- `npm test -- extension/commands.test.ts` — **109 passed, 0 failed**.
- `npm run smoke -- manager-recovery` — **PASS** on the single latest
run.
- `npm run validate` — **PASS**; 874 passed, 0 failed, 1 skipped; build
and package audit passed.
- Independent review — no findings.
- `prettier . --write` — completed; only the two changed files were
touched.
- `git diff --check` — **PASS**.
- Manual TUI acceptance — **NOT RUN**. The following flows remain
unverified manually: `/herdsman` Execution ordinary/managed flows,
`/lead` mode changes, Settings default, Definitions actions, and
takeover.

---------

Co-authored-by: Jeffrey Boadi <25706638+boadij@users.noreply.github.com>
boadij added a commit that referenced this pull request Oct 9, 2026
## Summary

Closes #320

Replace frequent unchanged-fleet observation with event-driven
invalidation and bounded authoritative reconciliation, reusing
Herdsman's existing Herdr subscription and single-flight snapshot paths.

- Subscribe to relevant Herdr lifecycle and presentation events.
Presentation-only invalidations refresh the visible status without
requesting Agent health scans.
- Coalesce presentation-only invalidations to a 2-second minimum
interval. Lifecycle and reconciliation notifications remain immediate;
an immediate event cancels any pending presentation timer, as does
abort.
- Reconcile after subscription acknowledgement, on `events_lost`, and
after reconnect. An unexpected close of an established subscription
notifies reconciliation exactly once per outage; the subsequent close
after `events_lost` does not duplicate that notification. Events remain
invalidations, never snapshot authority.
- Move ordinary Lead/delegating-Agent and leaf identity reconciliation
to 10 seconds. Chief/Manager full UI supervision observation also
reconciles every 10 seconds; the Manager widget redraws every 2 seconds
from its existing snapshot for elapsed-time presentation.
- Route local controller and project-assignment changes to active
supervision UI. Headless sessions do not start UI-only periodic
supervision observation.
- Keep explicit/model-context refreshes and action-time identity, role,
lease, ownership, and assignment verification fresh and authoritative.
No new cache, scheduler, or dependency is introduced.

## Measurement (deterministic fake-executor call counts)

These are test-harness counts of `api snapshot` calls, **not timing,
real-Herdr, or fleet-performance measurements**:

| Harness | Baseline | This branch |
|---|---:|---:|
| Leaf status, 10 captured 2-second callback ticks over virtual 20s | 10
calls | Inconclusive; no valid post-change count |
| Delegating status, 10 captured 2-second callback ticks over virtual
20s | 10 calls | 2 calls for 2 captured 10-second callback ticks over
virtual 20s |
| Chief supervision cadence (separate cadence test) | — | 2 calls for 2
captured 10-second callback ticks |
| Presentation burst through Herdr socket and managed-agent controller
wiring | — | 8 simulated presentation notifications resulted in exactly
1 fake-executor `herdr api snapshot` refresh; the coalescing timer was
advanced deterministically |

The baseline Leaf and Delegating results used the audited v0.22.0 code.
These probes establish scheduled/counted call behavior only; they do not
establish elapsed-time speedup, production resource use, real Herdr
behavior, or multi-Agent fleet scaling. The burst result is a simulated
fake-executor count, not real Herdr or fleet timing.

## Validation and review

- Review-fix focused tests: `extension/herdr.test.ts` — 71 tests passed;
the extension-contract presentation burst integration test passed.
- Earlier focused suites passed: `herdr.test.ts` (69),
`extension-contract.test.ts` (49), `controller-lifecycle.test.ts` (59),
`controller-api.test.ts` (100), `commands.test.ts` (111),
`presentation.test.ts` (85), and `agent-runtime.test.ts` (62).
- Final formatted full check: `npm run check` — 891 passed, 0 failed, 1
skipped. `git diff --check` passed.
- Packaging: `npm run build` and `npm run package:audit` passed (65
package files audited).
- Final review of the review-fix diff reported no findings.
- No live smoke scenarios were run.

- External Review #2 test cleanup: the event-watcher tests now advance
presentation timers deterministically and use `t.waitFor` for reconnect
assertions, removing repeated 2.1-second sleeps and the leftover
reconnect timeout. Focused validation (`npm test --
extension/herdr.test.ts extension/extension-contract.test.ts`) passed:
121 tests, 0 failed, 0 skipped.
- Final validation after the cleanup: `npm run check` — 891 passed, 0
failed, 1 skipped; `git diff --check` passed; `npm run build` passed;
`npm run package:audit` passed (65 package files audited).

## Limitations and review status

No real Herdr or scaled-fleet benchmark was run. Leaf's post-change
call-count probe was inconclusive, and the 10-second reconciliation
cadence bounds discovery of changes that do not produce a local
notification or relevant Herdr event. PR #326 remains open and is handed
back to the user for another external review; it has not been approved
or merged. AI-assisted implementation; please review the code and test
evidence as usual.


- External Review #3 CI fix: the lifecycle watcher test now ignores a
server-side `ECONNRESET` only when the test's abort signal is already
set; all other socket errors are thrown. The assertions that exactly two
connections occur and no callbacks are delivered remain intact.
- Validation for this fix: `npm test -- extension/herdr.test.ts` — 71
passed; `npm run validate` — 891 passed, 0 failed, 1 skipped, including
build and package audit (65 files); `git diff --check` passed.

---------

Co-authored-by: Jeffrey Boadi <25706638+boadij@users.noreply.github.com>
boadij added a commit that referenced this pull request Oct 10, 2026
## Summary

Issue #333: stopping an assigned Lead could leave its managed Agent tree
running when the Lead was in a different workspace. The Manager cleanup
discovery/revalidation used its own workspace, Lead delegation was not
synchronized with stop, and cleanup success was inferred from formatted
text.

- Discover and revalidate owned Agents across workspaces, constrained to
the exact target Lead workspace and full Agent generation identity.
- Revalidate cascade parents across workspaces and guard runtime-cache
invalidation by workspace so a foreign Agent with a duplicate label
cannot invalidate local tracking.
- Reuse the delegation lifecycle lock across Lead delegate/continue,
Manager stop, and confirmed Lead stop-all. Manager stop keeps the
assignment when descendant cleanup or Lead stop verification fails.
- Return structured cleanup completion and verify the final owned-Agent
inventory before stopping the Lead. No assignment, worktree, branch, or
saved session retirement is performed.
- Add cross-workspace duplicate-label, partial-cleanup, busy-lock,
gated-startup, and stop-race regressions.

## Validation

Validation on the preceding implementation head
`60b435a4df34ed419570bddab9c2f280c7c37637`:

- `npm run validate` — passed: 942 tests passed, 1 skipped; build
passed; package audit passed (68 files).
- `git diff --check` — passed.
- `npm test -- extension/controller-api.test.ts` — passed (114/114).
- `npm test -- extension/commands.test.ts` — passed (116/116) on the
preceding implementation head.
- `npm test -- extension/controller-lifecycle.test.ts` — passed (68/68).

A prior test failure was traced to the new regression test statically
importing `agent-controller.ts` before support test-module mocks were
registered. The corrected test defers that import until after mock
registration. For comparison, isolated baseline `b4ed98e` passed the
pre-correction controller-api suite (113/113). The final validation
above includes the correction.

Live smoke was not rerun; earlier `manager-recovery` smoke covered
ordinary stop/resume, not active recursive descendant cleanup. No
force-push was made.

Fixes #333


### External Review #2 follow-up

Final PR head: `6f231555398f5416bc557d2040e8a958778ffde7`.

- Locked empty stop-all revalidation now uses the authoritative Lead
Agent snapshot and refuses success when mailbox-state issues remain;
newly visible Agents still require reopening the confirmation flow.
- Added a regression proving unresolved mailbox state with zero visible
Agents produces no success summary and starts no cleanup. The
busy-delegation-lock regression remains in place.
- `npm test -- extension/commands.test.ts` — passed (117/117).
- `npm run validate` — passed (943 passed, 1 skipped; build and package
audit passed, 68 files).
- `npm run check` — passed (943 passed, 1 skipped).
- `git diff --check` — passed.

---------

Co-authored-by: Jeffrey Boadi <25706638+boadij@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant