gentle-pi v1.1.0
·
1160 commits
to main
since this release
gentle-pi v1.1.0
The largest release since 1.0: gentle-pi stops reimplementing review authority and delegates it to the vendored Gentle AI native engine over a negotiated, digest-verified contract.
Highlights
- Review Integration v1 (#158): Pi consumes the released
gentle-ai.review-integration/v1protocol. Gentle AI owns review identity, lifecycle, ledger, receipts, and recovery; Pi owns orchestration, model execution, UX, command interception, and the durable Git commit transaction with crash reconciliation. - Gentle AI v2.1.8 provider (#174, #181): pinned with all 12 archive and binary SHA-256 digests verified against the published checksums, failing closed on any mismatch. Includes the FINALIZE write-ahead journal, Windows durability contract, scoped authority discovery, and audited store reclaim from upstream v2.1.7–v2.1.8.
- Finalize reconciliation surfacing (#174): ambiguous FINALIZE outcomes resolve through
reconcile_finalizerouting with a fail-closed foreign-lineage identity guard and a bounded rerun cap counted only on finalize-driven retries — no more opaquenative-operation-faileddead ends. - Deny-by-default review actors (#177): every read-only review actor (4R lenses, refuter, validator, judgment-day judges) leads its tool map with an explicit deny-all rule, so omitted tools — including globally-enabled MCP namespaces — are denied by default.
- Windows support for Pi-owned persistence (#127, #131): absolute drive-letter Git common directories, portable fsync semantics, and no-replace lock guarantees preserved via NTFS hard-link semantics.
- Explicit workspace binding (#179):
gentle_reviewaccepts a validatedworkspaceRoot, START envelopes carryactor_bindingwith the frozen candidate view, and FINALIZE verifies the projection against the requested workspace — multi-worktree SDD flows now review the right tree.
Upgrade notes
npm install gentle-pi@1.1.0— the postinstall provisions the pinned Gentle AI 2.1.8 binary and verifies its digest.- Repositories with historical legacy-v1 review authorities: the native
releasegate may fail closed on pre-contract history (upstream gentle-ai#1439); candidate lineage validation and all commit/push/PR gates are unaffected.
Deferred
- Pristine review abandonment design (WS-D) and native-core slimming (WS-F) move to the v1.2.0 cycle.
- Adaptive review consumption (WS-E) tracks upstream gentle-ai#1380.