Conversation
`paired --host pi` runs both arms with Harbor's Pi agent as a fourth PluginHost. Harbor installs Pi from its former npm name, which ends before the versions the PowerContext Pi package supports, so the agent installs `@earendil-works/pi-coding-agent` 0.82.1, the version the package's lockfile and CI use, with Harbor's own steps. The ON arm runs `pi install` on the package, as `powercontext setup pi` does, and its POWERCONTEXT_PI_* environment carries the Server URL, Scope, plain-HTTP consent, and the harness Client's token. As on the other hosts, the OFF arm installs no package and mounts nothing. The ON container sees only the package's manifest, extension, sources, and Skill. The reasoning effort becomes `--thinking`. Harbor runs Pi with `--no-session`, so Pi saves no session. Pi's bash tool keeps the full output of a command over 2,000 lines or 50 KB as `pi-bash-*.log` in the temporary directory, and nothing clears it between the steps of a trial, so the agent removes those files before each session in both arms. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Which issue or RFC does this PR close?
Part of #1705, the last plugin host in the plan, after Codex (#1779), Claude Code (#1800), and OpenCode (#1835). It uses the OFF definition from #1816.
Rationale for this change
#1705 asks for PowerContext OFF/ON runs across agent hosts, including an overlapping configuration. Pi has an official PowerContext package, and Harbor ships a Pi agent, so it can run the same continuation workloads, grader, and evidence as the other hosts. This run uses GLM-5.3 through OpenRouter, the same model as the OpenCode run, so the two hosts can be compared on one model.
What changes are included in this PR?
paired --host piruns both arms withPowerContextPiAgent, a subclass of Harbor's Pi agent and a fourthPluginHost.@mariozechner/pi-coding-agent, which ends at 0.73.1. The PowerContext Pi package targets@earendil-works/pi-coding-agent, so the agent installs that package at 0.82.1, the version the Pi package's lockfile andmake pi-testuse, with Harbor 0.16's own install steps.POWERCONTEXT_*settings.pi installon the mounted package, aspowercontext setup pidoes. Pi records the path and loads the package in place, so the mount is read-only. The container sees only the package'spackage.json,extensions,src, andskills. The package reads its Server URL, Scope, plain-HTTP consent, and the harness Client's token (POWERCONTEXT_PI_AUTHORIZATION) from its environment.--no-session, so Pi saves no session. Pi's bash tool keeps the full output of a command over 2,000 lines or 50 KB aspi-bash-<id>.login the temporary directory and does not delete it, and Harbor does not clear that directory between the steps of a trial. Before each session in both arms, the agent removes those files, so a recall session cannot read its capture session's tool output.mediumby default, becomes Pi's--thinking. Harbor passes the key of the model's provider, such asOPENROUTER_API_KEY.Are there any user-facing changes?
paired --hostacceptspi.How was this change tested?
Pilot run
make harness-paired ARGS='--host pi --trials 2'on this PR's head commit, against a real Server, Harbor, Pi, and model:OceanBase/12, reward 1OceanBase/12, reward 1Report: OFF 0/2 and ON 2/2, with 2 scored pairs and a mean ON minus OFF of +1.00. There were no errors, timeouts, or integration failures.
Treatment evidence (ON):
OFF behavior: the Harbor job configs have no mounts and an empty agent environment. In the recall session both agents searched
/workspace, read the README, and wrotenullfor both values. Neither OFF trajectory mentions PowerContext, the Server, or Pi's saved tool output.Authentication: the Server ran with
POWERCONTEXT_SERVER_ACCESS_MODE=enforced. It answered/v1/scopeswith 401 without a token, and every ON capture and context request authenticated. Neither the full Server token nor the OpenRouter key appears in the evidence.Token usage (from Pi's own usage records, cached tokens included):
Each ON model call carries about 18k prompt tokens, against under 2k for OFF: the package registers its tools and guidance on every request. The ON recall used fewer calls because it answered directly.
Configuration:
openrouter/z-ai/glm-5.3with--thinking medium.codingextraction profile and enforced access. Generation usedopenrouter:deepseek/deepseek-v4-pro. Embeddings usedopenai/text-embedding-3-small(1536 dimensions) through OpenRouter's OpenAI-compatible endpoint, as in the OpenCode run; it answered in 0.3–0.6 s before the run. The agent reached the Server athttp://host-gateway:8000withPOWERCONTEXT_PI_ALLOW_INSECURE_HTTP=true.Time: each arm took 30–45 s.
Pi's saved tool output on a real Pi
In a throwaway
node:22-bookwormcontainer with@earendil-works/pi-coding-agent@0.82.1and the same model:[Showing lines 29017-30000 of 30000 (50.0KB limit). Full output: /tmp/pi-bash-565921934bc38449.log]. After Pi exited, that file was still there, 1.5 MB with every line.bashwithset -o pipefail), removed the file and exited 0. Run again with nothing to remove, it also exited 0.~/.pi/agent, Pi had written onlyauth.jsonandmodels-store.json, neither with session content.Checks
make checkandmake harness-checkpass.Authorization: Bearer <token>.bashagainst a seeded temporary directory, for both arms: the saved tool output is gone and other files stay. With nothing to remove, the session still starts.--no-session, which the statement that Pi saves no session depends on.POWERCONTEXT_PI_AUTHORIZATION.Limits
z-ai/glm-5.3is not in its model list for OpenRouter and uses it as a custom model ID. The run is unaffected.POWERCONTEXT_PI_ALLOW_INSECURE_HTTP=true, the package stays inactive against a plain-HTTP Server, and the run shows an integration failure rather than a scored result.config.jsonwith its own masking, which keeps the first four and last three characters ofPOWERCONTEXT_<HOST>_AUTHORIZATION(Bear****plus three characters of the token). This applies to every plugin host since fix(e2e): keep PowerContext out of the OFF arm #1816. The results directory is not committed./tests/test.shin the container during recall. It holds no answer, but its license header names OceanBase, which is also this task's answer.AI usage statement
This PR was developed with Claude Code (Claude Opus 5.5 and Claude Fable 5.1), which designed and wrote the change and tests, ran the checks, the container test, and the pilot above, and analyzed the evidence. The author chose the model, approved the OFF definition and the Server configuration, reviewed the change, and provided the pilot environment.
🤖 Generated with Claude Code