Repository navigation
Releases: jkelly/PiSharp
Release list
PiSharp 1.1.0.1
PiSharp 1.1.0.1
A C#-only patch on the Pi v1.1.0 baseline (commit
abe508e1b89912adde45528136c3221eb69acdd7). It ports Pi's tool_search and makes MCP
tools callable. Each change is tracked in
sync-1.1.0-applicability.json
(rows gap.tool-search and mcp.exposure-and-prompt).
Fixed
- MCP tool calls work. In 1.1.0 the CLI declared MCP tools to the model but refused
every call with "Final tool action was denied." Tools of the servers you configure in
mcp.jsoncan now be called, as in Pi: configuring a server trusts it, and there is no
separate approval step. Tools of servers that were skipped, and of an earlier session
generation after a reload, stay refused.
New
tool_search. Pi's BM25 search over deferred tools, ported with the same
tokenizer, ranking, result text and errors. Found tools are loaded for the model's next
call and recorded in the session.- Deferred MCP servers connect. Servers whose tools use
deferredexposure now
connect in normal sessions. Their tools stay hidden untiltool_searchloads them.
--toolsand--exclude-toolsgatetool_searchas in Pi; leaving it out keeps the
servers connected but prints Pi's warning that their tools can't be called.
Differences from Pi
tool_searchexists only when a configured server has deferred tools. Pi always
registers it, switched off.tool_searchdoesn't wait for servers that are still connecting, so a search early in
a one-shot prompt can find nothing.- Live sessions send a literal system prompt, so the
mcp_serverssection isn't sent
there yet. - Servers that need codemode still don't connect. Codemode is planned for 1.1.0.3.
Packages
All library packages and the PiSharp.Cli dotnet tool are published as 1.1.0.1:
dotnet tool update -g PiSharp.CliPiSharp 1.1.0
PiSharp 1.1.0
PiSharp 1.1.0 moves the porting baseline from Pi v0.99.1 to Pi v1.1.0 (commit
abe508e1b89912adde45528136c3221eb69acdd7), covering the upstream releases v0.99.2,
v1.0.0 to v1.0.4 and v1.1.0. As before, matching the upstream version names the
baseline; it is not a claim of complete behavioral parity. Each ported change is
tracked, with its test suite, in
sync-1.1.0-applicability.json;
the decisions are in decision 0002.
Breaking changes
- Azure provider id is now
azure. Pi 1.0.3 renamed the provider
azure-openai-responsestoazure. Updateauth.json,models.jsonand
settings.json(defaultProvider,enabledModels,modelThinkingLevels). The API
idazure-openai-responsesand theAZURE_OPENAI_*environment variables are
unchanged. Sessions recorded with the old provider id fall back to another model on
resume. - MCP tool and namespace names use
_instead of-.mcp__my-server__xis now
mcp__my_server__x. Colliding names get a stable hash suffix, and server names that
differ only by-/_are rejected. - Tool selection follows Pi 1.1.0. Restored tools that are not registered yet stay
pending and activate when they register. Unknown names in--tools,defaultTools
and explicit activation are ignored instead of failing, as upstream does.
--providerwithout--modelis an error. - Token estimates use 3.5 characters per token in the request estimators, which can
change output-limit calculations.
New
- Anthropic authentication:
/login(browser or copy-code) and/logoutover the
shared~/.pi/agent/auth.json; workload identity federation
(ANTHROPIC_FEDERATION_RULE_ID,ANTHROPIC_ORGANIZATION_ID,
ANTHROPIC_IDENTITY_TOKEN_FILE); credentials are re-resolved before every request,
and a stored token refresh is persisted even if the request is cancelled or the
refresh finishes late. - Azure provider: Azure OpenAI Responses and Azure Foundry Chat Completions
(azure/deepseek-v4-pro), configured withAZURE_OPENAI_API_KEY,
AZURE_OPENAI_BASE_URLorAZURE_OPENAI_RESOURCE_NAME, and
AZURE_OPENAI_DEPLOYMENT_NAME_MAP. - MCP: sessions load
~/.pi/agent/mcp.json; servers withoutdirecttools connect
in the background; anmcp_serverssystem-prompt section;.pi/mcp.jsonoverride
rules; OAuth hardening (RFC 9207 issuer checks, step-up scopes, credentials per server
name and URL, client ID metadata documents);pisharp mcp add|remove|list|login|logout
with a durablemcp-auth.json;--no-mcp. - Tool selection:
--toolsand--exclude-toolsaccept*patterns;+nameand
-namemodify the default selection;--toolskeeps MCP tools unless an entry starts
withmcp__. - User shell commands: RPC
bash/abort_bashand interactive!/!!, with ANSI
sequences split across chunks held back. - Events: optional
durationMson assistant messages, tool results and
tool_execution_end;agent_settledcarriesabortedin RPC, JSON mode and native
extensions. - Extension API:
registerToolRenderer, namespaceinstructions,
ToolLoadout.GetPromptGuidelines. - Providers: Anthropic inline tool definitions (
inline-tools-2026-09-15) and
non-strict fallback;samplingParamsByThinkingLevel; more retryable errors
(server_busy, capacity, Mistralfinish_reason: "error"); model catalog from
pi-ai 1.1.0, including Claude Haiku 5.5. - Claude Opus 5, Opus 5.5, Sonnet 5.5, Haiku 5.5 and Fable 5.1: these models
were rejected with "Unsupported native thinking metadata". They now work, with Pi's
per-turn thinking effort (output_configeffort markers replayed for each assistant
turn and the managed-effort beta headers). - Cost: prompt-length pricing tiers apply on every cost path (Anthropic, OpenAI
Responses and Completions, Google, Mistral), and the native Anthropic route now
reports catalog costs, including for fallback models. - OpenAI grammar tools: models with
supportsOpenAIGrammarToolsget grammar tools as
custom tools, and transcripts replay them with theirctc_item ids, as Pi 1.0.0 does. - Terminal: Home/End are editor-only and Ctrl+Home/Ctrl+End move to the transcript
top and bottom; OSC 7501 program status withPI_PROGRAM_STATUS=1.
Known gaps
- Codemode,
tool_search, classifiers and image generation were already missing at
v0.99.1. They are planned as 1.1.0.x releases on this baseline. Until then, MCP servers
whose tools need codemode ortool_searchdo not connect. - Pi's
quietStartup,outputPadandtuiModesettings have no PiSharp counterpart. - Upstream's durable runtime, remote execution environments, experimental client/server
modes and Nix packaging are out of scope.
Packages
All library packages and the PiSharp.Cli dotnet tool are published as 1.1.0:
dotnet tool update -g PiSharp.CliPiSharp 0.99.1
PiSharp 0.99.1
The public product and package version is 0.99.1, matching the upstream Pi
v0.99.1 porting baseline at commit
d86654abb8862e201933517d6f1fce9f88dd117f. The intended release tag is v0.99.1.
This note prepares release metadata; it does not record creation of a tag,
publication of a binary release, or publication of NuGet packages.
Qualification status
Fresh 0.99.1 artifacts have not yet been qualified. Earlier private package
versions, including 0.1.0-private.cb338cb1, retain their original byte identities
and receipts. They must not be renamed, repacked, or described as tested 0.99.1
artifacts. Version-specific source, restore locks, products, archives, package
dependencies and consumers require new exact evidence.
The existing bounded provider observations and remaining differences are recorded
in provider source projection.
The three approved provider differences
do not establish complete provider parity or close the complete native gate.
Matching the upstream version identifies the baseline; it makes no additional
compatibility claim.
Version identities
Directory.Build.props supplies VersionPrefix=0.99.1 when no explicit prefix is
provided. Explicitly admitted private builds can still supply their own version;
that does not change the public release baseline. Public packaging must pass
PiSharpReleaseVersion=0.99.1 together with the exact source commit and provenance
to the existing opt-in distribution and native SDK targets. Their explicit-input
and provenance checks remain unchanged.
Product/package versions and CLR assembly identities are separate. The normal
SDK-derived assembly version is 0.99.1.0. PiSharp.ExtensionHost deliberately
retains assembly version 1.0.0.0, required by the existing approved supervisor
system-import profile. Its product/file version can identify 0.99.1, but its
unchanged CLR identity is not permission to reuse old bytes: the existing exact
hash, metadata and approval checks still apply. Do not globally override
AssemblyVersion during release preparation.
The existing source locks contain earlier project-version ranges. They are
historical inputs, not evidence of a successful 0.99.1 locked restore. Generate
and review new locks in an isolated admitted copy using the existing offline
cache/feed closure, then perform the required locked restores. Preserve source
locks until their exact replacements and dependent integrity pins are reviewed.
Artifact scope
The existing reviewed routes cover a Windows native CLI payload and three
ordinary .NET library packages: PiSharp.Contracts,
PiSharp.Extensions.Abstractions and PiSharp.Extensions.Runtime. This note
adds no installer, platform, signing, dependency acquisition or public package
publication claim. Build and inspect fresh versioned products, then exercise
the actual produced packages through the separately reviewed consumer route.
Keep the complete producer and consumer budgets; never shorten operations to
fit a coordination window.