4 Commits
Author SHA1 Message Date
ZacharyZhang-NY d6e49bcc7d release: v0.1.6
Release / build (aarch64-apple-darwin) (push) Waiting to run
Release / build (x86_64-apple-darwin) (push) Waiting to run
Release / build (aarch64-unknown-linux-gnu) (push) Waiting to run
Release / build (x86_64-pc-windows-msvc) (push) Waiting to run
Release / publish GitHub Release (push) Blocked by required conditions
Release / build (x86_64-unknown-linux-gnu) (push) Failing after 8s
Since v0.1.5:
- fix(messages): Claude models no longer 400 with 'Invalid signature in
  thinking block' — thinking is replayed only for the active tool loop
  and only when genuinely signed (cross-backend/cross-model histories
  are stripped)
- fix(codex): ChatGPT Codex no longer 400s with 'System messages are
  not allowed' — system prompts ride the instructions field and
  encrypted reasoning is requested for stateless replay
- docs: AGENTS.md records both wire contracts
2026-07-22 23:36:22 -04:00
ZacharyZhang-NY d2358b037c fix(codex): adapt the Responses body to the ChatGPT/Codex backend contract
Root cause of 400 {"detail":"System messages are not allowed"} at
chatgpt.com/backend-api/codex/responses (both platforms): the codex
adaptation covered only IDENTITY HEADERS (originator/OpenAI-Beta/UA/
chatgpt-account-id) — the BODY still carried the system prompt as
role:system input items, which the codex backend rejects outright. Its
system channel is the top-level  field, and stateless
(store:false) reasoning replay requires
include:["reasoning.encrypted_content"] — both per the same reference
the headers were ported from (official Codex CLI + Pi's
api/openai-codex-responses.ts).

New adapt_body_for_codex_backend (kigi-sampling-types): hoists every
system input item into  (order preserved, appended to any
existing instructions; string and parts content shapes) and requests
encrypted reasoning. Idempotent. Applied at both Responses send paths,
openai_codex-GATED — the API-key  path stays byte-identical
(pinned by a control wire test).

Tests: adapter unit tests (hoist+include, no-system no-op, idempotence)
plus two mock-server wire tests (codex body has no system role,
instructions + include present; plain Responses body unchanged).

Verified: sampling-types + sampler + chat-state + shell 6076 tests
green, clippy clean.
2026-07-22 23:35:31 -04:00
ZacharyZhang-NY 6ba24db019 fix(messages): replay thinking blocks only for the active tool loop
Root cause of 'Invalid signature in thinking block' (400 at
messages.1.content.0, Claude models): build_messages_request replayed
EVERY stored Reasoning item as a thinking block with no origin check —
history synthesized by other backends (encrypted_content: None → the
mandatory signature field serialized as ""), Responses-API tco_* blobs
(signature bytes, no text), and blocks signed by a DIFFERENT model after
a mid-session /model switch. Anthropic validates every replayed
signature (model-bound), so such histories 400 deterministically. The
platform split was circumstantial: Windows sessions started on the
default model and switched to Claude; macOS sessions were Claude-native
from turn 1. Adversarially verified — no platform-divergent byte path
exists in capture, storage, or replay.

New prune_replayed_thinking pass (Pi/Claude Code replay policy): keep
exactly the final assistant message's thinking when its tool loop is
still open (request ends on the tool results — an open loop can never
span a model switch) and the block is genuinely signed; strip every
other thinking block (the API ignores valid prior-turn thinking and
rejects invalid). Assistant messages emptied by the strip (thinking-only
aborted turns) are removed — empty content arrays are rejected too.

Tests: three unit tests pin strip-outside-loop (unsigned, tco_*, stale
signed), keep-in-active-loop (verbatim text+signature at content.0), and
emptied-message removal; the legacy-upgrade integration test now proves
both wire fidelity in the active loop AND stripping once the loop
closes.

Verified: sampling-types + sampler + chat-state + shell 6072 tests
green, clippy clean.
2026-07-22 23:26:49 -04:00
ZacharyZhang-NY 10149f50dd install: stop persisting KIGI_GRAPH — the binary default is the product default
The README always shipped graph engineering enabled; the enablement was
delegated to installer env plumbing that diverged per platform:
install.sh exported KIGI_GRAPH=1 into shell rc (worked), install.ps1
wrote the User registry variable — which running Windows terminals (and
new tabs of an open Windows Terminal) never pick up, so /graph was
'missing on Windows' despite a successful install.

With resolve_graph() defaulting true in the binary (e53a66d), the env
writes are redundant complexity: drop them from both installers, keep
KIGI_GRAPH=0 as the documented opt-out (env still beats the default),
and correct the flag comment to tell this story instead of a
'gray release' one. Both scripts syntax-checked (sh -n / pwsh parser).

Installers are served from main (raw.githubusercontent), so this takes
effect for all new installs immediately — no retag needed; the running
v0.1.5 build already carries the binary-default fix.
2026-07-22 21:22:16 -04:00
10 changed files with 572 additions and 105 deletions
+17 -4
View File
@@ -220,7 +220,14 @@ edges stay deterministic Rust. The harness appends a terminal
system prefix — gated on `SamplerConfig.anthropic_oauth` (claude-pro-max system prefix — gated on `SamplerConfig.anthropic_oauth` (claude-pro-max
only), so API-key `anthropic`/`minimax` Messages requests stay only), so API-key `anthropic`/`minimax` Messages requests stay
byte-identical. Its `/v1/models` listing rides the same Bearer + byte-identical. Its `/v1/models` listing rides the same Bearer +
oauth-beta headers. oauth-beta headers. THINKING REPLAY (`prune_replayed_thinking`,
all Messages requests): Anthropic validates every replayed
`thinking` block (signature model-bound, non-empty required), so
only the final assistant message's signed thinking is replayed and
only while its tool loop is open (request ends on the tool
results); everything else — unsigned cross-backend history, `tco_*`
Responses blobs, stale-model blocks — is stripped, or the request
400s "Invalid `signature` in `thinking` block".
- `openai-codex` (ChatGPT Plus/Pro, `scope_key oauth/openai-codex`, port - `openai-codex` (ChatGPT Plus/Pro, `scope_key oauth/openai-codex`, port
1455 `/auth/callback`, FORM body, authorize+token host `auth.openai.com`, 1455 `/auth/callback`, FORM body, authorize+token host `auth.openai.com`,
client `app_EMoam…`, scope `openid profile email offline_access`, the 3 client `app_EMoam…`, scope `openid profile email offline_access`, the 3
@@ -237,9 +244,15 @@ edges stay deterministic Rust. The harness appends a terminal
`PlatformId::sends_codex_responses_headers()`): headers `PlatformId::sends_codex_responses_headers()`): headers
`chatgpt-account-id` (per-request from the JWT), `originator codex_cli_rs`, `chatgpt-account-id` (per-request from the JWT), `originator codex_cli_rs`,
`OpenAI-Beta responses=experimental`, a codex `User-Agent`; `store:false` `OpenAI-Beta responses=experimental`, a codex `User-Agent`; `store:false`
is the shared Responses default. API-key `openai` Responses requests carry is the shared Responses default. BODY adaptation
NONE of this (byte-identical). `reasoning.effort` carries the thinking (`adapt_body_for_codex_backend`, same gate): the backend 400s
level (incl. the codex-only `ultra`). NO websocket, NO base_instructions. `role:system` input ("System messages are not allowed") — system items
are hoisted into the top-level `instructions` field — and stateless
reasoning replay requires `include:["reasoning.encrypted_content"]`.
API-key `openai` Responses requests carry NONE of this
(byte-identical, pinned by a control wire test). `reasoning.effort`
carries the thinking level (incl. the codex-only `ultra`). NO
websocket, NO base_instructions.
CATALOG is HARDCODED (`PlatformId::hardcoded_catalog` → CATALOG is HARDCODED (`PlatformId::hardcoded_catalog` →
`openai_codex_wire_models`, mapped through the SAME `openai_codex_wire_models`, mapped through the SAME
`platform_wire_model_to_entry` output): exactly the 4 `visibility=list` && `platform_wire_model_to_entry` output): exactly the 4 `visibility=list` &&
Generated
+62 -62
View File
@@ -5442,7 +5442,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-acp-lib" name = "kigi-acp-lib"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"agent-client-protocol", "agent-client-protocol",
"async-trait", "async-trait",
@@ -5456,7 +5456,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-agent" name = "kigi-agent"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"chrono", "chrono",
"dirs 6.0.0", "dirs 6.0.0",
@@ -5486,7 +5486,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-agent-lifecycle" name = "kigi-agent-lifecycle"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"async-trait", "async-trait",
"tokio", "tokio",
@@ -5495,7 +5495,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-auth" name = "kigi-auth"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"async-trait", "async-trait",
"http 1.4.2", "http 1.4.2",
@@ -5508,7 +5508,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-bin" name = "kigi-bin"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"anyhow", "anyhow",
"clap", "clap",
@@ -5543,7 +5543,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-chat-state" name = "kigi-chat-state"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"indexmap", "indexmap",
"kigi-compaction", "kigi-compaction",
@@ -5560,7 +5560,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-codebase-graph" name = "kigi-codebase-graph"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"ahash", "ahash",
"clap", "clap",
@@ -5596,7 +5596,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-compaction" name = "kigi-compaction"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"anyhow", "anyhow",
"async-trait", "async-trait",
@@ -5609,7 +5609,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-config" name = "kigi-config"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"base64", "base64",
"blake3", "blake3",
@@ -5632,7 +5632,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-config-types" name = "kigi-config-types"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"agent-client-protocol", "agent-client-protocol",
"indexmap", "indexmap",
@@ -5646,7 +5646,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-crash-handler" name = "kigi-crash-handler"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"backtrace", "backtrace",
"libc", "libc",
@@ -5657,7 +5657,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-env" name = "kigi-env"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"tracing", "tracing",
"url", "url",
@@ -5665,7 +5665,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-fast-worktree" name = "kigi-fast-worktree"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"anyhow", "anyhow",
"bytes", "bytes",
@@ -5697,7 +5697,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-file-utils" name = "kigi-file-utils"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"anyhow", "anyhow",
"aws-config", "aws-config",
@@ -5721,7 +5721,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-fsnotify" name = "kigi-fsnotify"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"criterion", "criterion",
"dunce", "dunce",
@@ -5742,7 +5742,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-gix-status" name = "kigi-gix-status"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"gix", "gix",
"kigi-test-utils", "kigi-test-utils",
@@ -5752,7 +5752,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-hooks" name = "kigi-hooks"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"fastrand", "fastrand",
"kigi-config", "kigi-config",
@@ -5771,7 +5771,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-hooks-plugins-types" name = "kigi-hooks-plugins-types"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"serde", "serde",
"serde_json", "serde_json",
@@ -5779,7 +5779,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-http" name = "kigi-http"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"kigi-auth", "kigi-auth",
"kigi-log", "kigi-log",
@@ -5794,7 +5794,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-hunk-tracker" name = "kigi-hunk-tracker"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"chrono", "chrono",
"dunce", "dunce",
@@ -5815,14 +5815,14 @@ dependencies = [
[[package]] [[package]]
name = "kigi-interjection-core" name = "kigi-interjection-core"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"serde", "serde",
] ]
[[package]] [[package]]
name = "kigi-log" name = "kigi-log"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"anyhow", "anyhow",
"chrono", "chrono",
@@ -5840,7 +5840,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-markdown" name = "kigi-markdown"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"anstyle", "anstyle",
"anstyle-lossy", "anstyle-lossy",
@@ -5864,14 +5864,14 @@ dependencies = [
[[package]] [[package]]
name = "kigi-markdown-core" name = "kigi-markdown-core"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"pulldown-cmark", "pulldown-cmark",
] ]
[[package]] [[package]]
name = "kigi-mcp" name = "kigi-mcp"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"agent-client-protocol", "agent-client-protocol",
"async-trait", "async-trait",
@@ -5908,7 +5908,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-memory" name = "kigi-memory"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"anyhow", "anyhow",
"arc-swap", "arc-swap",
@@ -5942,7 +5942,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-mermaid" name = "kigi-mermaid"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"fontdb", "fontdb",
"image", "image",
@@ -5960,7 +5960,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-models" name = "kigi-models"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"kigi-env", "kigi-env",
"serde", "serde",
@@ -5970,7 +5970,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-pager-minimal" name = "kigi-pager-minimal"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"chrono", "chrono",
"crossterm", "crossterm",
@@ -5987,7 +5987,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-pager-pty-harness" name = "kigi-pager-pty-harness"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"alacritty_terminal", "alacritty_terminal",
"anyhow", "anyhow",
@@ -6012,7 +6012,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-pager-render" name = "kigi-pager-render"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"agent-client-protocol", "agent-client-protocol",
"anstyle", "anstyle",
@@ -6064,7 +6064,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-paths" name = "kigi-paths"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"camino", "camino",
"serde", "serde",
@@ -6074,7 +6074,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-prompt-queue" name = "kigi-prompt-queue"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"serde", "serde",
"serde_json", "serde_json",
@@ -6082,7 +6082,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-proto-build" name = "kigi-proto-build"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"anyhow", "anyhow",
"pbjson-build", "pbjson-build",
@@ -6093,7 +6093,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-ratatui-inline" name = "kigi-ratatui-inline"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"ansi-width", "ansi-width",
"anstyle-parse 0.2.7", "anstyle-parse 0.2.7",
@@ -6110,7 +6110,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-ratatui-textarea" name = "kigi-ratatui-textarea"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"arboard", "arboard",
"chrono", "chrono",
@@ -6131,7 +6131,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-sampler" name = "kigi-sampler"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"async-openai", "async-openai",
"async-stream", "async-stream",
@@ -6154,7 +6154,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-sampling-types" name = "kigi-sampling-types"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"assert_matches", "assert_matches",
"async-openai", "async-openai",
@@ -6171,7 +6171,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-sandbox" name = "kigi-sandbox"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"anyhow", "anyhow",
"chrono", "chrono",
@@ -6192,7 +6192,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-secrets" name = "kigi-secrets"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"regex", "regex",
"serde_json", "serde_json",
@@ -6230,7 +6230,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-shell" name = "kigi-shell"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"agent-client-protocol", "agent-client-protocol",
"anyhow", "anyhow",
@@ -6367,7 +6367,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-shell-base" name = "kigi-shell-base"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"anyhow", "anyhow",
"chrono", "chrono",
@@ -6392,7 +6392,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-sqlite-journal" name = "kigi-sqlite-journal"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"libc", "libc",
"rusqlite", "rusqlite",
@@ -6403,7 +6403,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-subagent-resolution" name = "kigi-subagent-resolution"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"kigi-sampling-types", "kigi-sampling-types",
"kigi-tool-types", "kigi-tool-types",
@@ -6418,7 +6418,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-system-power" name = "kigi-system-power"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"windows-sys 0.59.0", "windows-sys 0.59.0",
"zbus", "zbus",
@@ -6426,7 +6426,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-test-support" name = "kigi-test-support"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"agent-client-protocol", "agent-client-protocol",
"anyhow", "anyhow",
@@ -6448,7 +6448,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-test-utils" name = "kigi-test-utils"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"runfiles", "runfiles",
"tracing", "tracing",
@@ -6457,11 +6457,11 @@ dependencies = [
[[package]] [[package]]
name = "kigi-token-estimation" name = "kigi-token-estimation"
version = "0.1.5" version = "0.1.6"
[[package]] [[package]]
name = "kigi-tool-protocol" name = "kigi-tool-protocol"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"kigi-tool-types", "kigi-tool-types",
"serde", "serde",
@@ -6472,7 +6472,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-tool-runtime" name = "kigi-tool-runtime"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"anyhow", "anyhow",
"async-trait", "async-trait",
@@ -6490,7 +6490,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-tool-types" name = "kigi-tool-types"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"minijinja", "minijinja",
"schemars 1.2.1", "schemars 1.2.1",
@@ -6500,7 +6500,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-tools" name = "kigi-tools"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"anyhow", "anyhow",
"arc-swap", "arc-swap",
@@ -6577,7 +6577,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-tools-api" name = "kigi-tools-api"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"kigi-proto-build", "kigi-proto-build",
"kigi-tool-protocol", "kigi-tool-protocol",
@@ -6590,11 +6590,11 @@ dependencies = [
[[package]] [[package]]
name = "kigi-tracing-macros" name = "kigi-tracing-macros"
version = "0.1.5" version = "0.1.6"
[[package]] [[package]]
name = "kigi-tty-utils" name = "kigi-tty-utils"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"libc", "libc",
"nix 0.30.1", "nix 0.30.1",
@@ -6604,7 +6604,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-tui" name = "kigi-tui"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"agent-client-protocol", "agent-client-protocol",
"ansi-to-tui", "ansi-to-tui",
@@ -6691,7 +6691,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-update" name = "kigi-update"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"anyhow", "anyhow",
"dunce", "dunce",
@@ -6720,14 +6720,14 @@ dependencies = [
[[package]] [[package]]
name = "kigi-version" name = "kigi-version"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"semver", "semver",
] ]
[[package]] [[package]]
name = "kigi-workspace" name = "kigi-workspace"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"agent-client-protocol", "agent-client-protocol",
"anyhow", "anyhow",
@@ -6806,7 +6806,7 @@ dependencies = [
[[package]] [[package]]
name = "kigi-workspace-types" name = "kigi-workspace-types"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"base64", "base64",
"chrono", "chrono",
@@ -8840,7 +8840,7 @@ dependencies = [
[[package]] [[package]]
name = "ptyctl" name = "ptyctl"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"alacritty_terminal", "alacritty_terminal",
"anyhow", "anyhow",
@@ -8858,7 +8858,7 @@ dependencies = [
[[package]] [[package]]
name = "ptyctl-cli" name = "ptyctl-cli"
version = "0.1.5" version = "0.1.6"
dependencies = [ dependencies = [
"anyhow", "anyhow",
"axum", "axum",
+1 -1
View File
@@ -76,7 +76,7 @@ members = [
] ]
[workspace.package] [workspace.package]
version = "0.1.5" version = "0.1.6"
edition = "2024" edition = "2024"
license = "Apache-2.0" license = "Apache-2.0"
@@ -1183,6 +1183,9 @@ impl SamplingClient {
// old raw_output machinery. // old raw_output machinery.
kigi_sampling_types::patch_reasoning_text_types(&mut request_body); kigi_sampling_types::patch_reasoning_text_types(&mut request_body);
kigi_sampling_types::patch_reasoning_effort(&mut request_body, request.reasoning_effort); kigi_sampling_types::patch_reasoning_effort(&mut request_body, request.reasoning_effort);
if self.defaults.openai_codex {
kigi_sampling_types::adapt_body_for_codex_backend(&mut request_body);
}
let http_request = self.post(self.endpoint("responses")).json(&request_body); let http_request = self.post(self.endpoint("responses")).json(&request_body);
let response = http_request.send().await.map_err(|e| { let response = http_request.send().await.map_err(|e| {
@@ -1321,6 +1324,9 @@ impl SamplingClient {
} }
kigi_sampling_types::patch_reasoning_text_types(&mut request_body); kigi_sampling_types::patch_reasoning_text_types(&mut request_body);
kigi_sampling_types::patch_reasoning_effort(&mut request_body, request.reasoning_effort); kigi_sampling_types::patch_reasoning_effort(&mut request_body, request.reasoning_effort);
if self.defaults.openai_codex {
kigi_sampling_types::adapt_body_for_codex_backend(&mut request_body);
}
// Fresh per attempt so signals never leak across retries; `None` // Fresh per attempt so signals never leak across retries; `None`
// (check disabled) sends no header and does no peek work per event. // (check disabled) sends no header and does no peek work per event.
let doom_loop = self let doom_loop = self
@@ -3201,6 +3201,8 @@ pub fn build_messages_request(req: &ConversationRequest) -> crate::messages::Mes
flush_assistant(&mut pending_assistant, &mut messages); flush_assistant(&mut pending_assistant, &mut messages);
flush_tool_results(&mut pending_tool_results, &mut messages); flush_tool_results(&mut pending_tool_results, &mut messages);
prune_replayed_thinking(&mut messages);
// Attach cache_control: {type: "ephemeral"} to last system block // Attach cache_control: {type: "ephemeral"} to last system block
if let Some(last) = system_blocks.last_mut() { if let Some(last) = system_blocks.last_mut() {
last.cache_control = Some(CacheControl { last.cache_control = Some(CacheControl {
@@ -3290,6 +3292,74 @@ pub fn build_messages_request(req: &ConversationRequest) -> crate::messages::Mes
} }
} }
/// Strip replayed `thinking` blocks the Anthropic Messages API would
/// reject — keep exactly the one it requires.
///
/// Anthropic validates EVERY `thinking` block in the request: the
/// signature is bound to the emitting model and must be non-empty, so
/// history from another backend (`encrypted_content: None` replays as
/// `signature: ""`), a Responses-API `tco_*` blob (signature bytes with no
/// text), or a block signed by a DIFFERENT model after a mid-session
/// `/model` switch 400s the whole request with
/// "messages.N.content.0: Invalid `signature` in `thinking` block".
///
/// The API only NEEDS thinking for the ACTIVE tool-use continuation: the
/// final assistant message whose tool_use results follow must carry its
/// signed thinking back verbatim. Prior turns' thinking is ignored even
/// when valid (Pi/Claude Code replay exactly this way). So: keep the
/// final assistant message's thinking when the loop is open and the block
/// is genuinely signed (non-empty text AND signature — an open loop can
/// never span a model switch, so that signature is always the current
/// model's); strip every other thinking block. An assistant message left
/// EMPTY by the strip (a thinking-only aborted turn) is removed — the API
/// rejects empty content arrays.
fn prune_replayed_thinking(messages: &mut Vec<crate::messages::Message>) {
use crate::messages::{ContentBlock, MessageContent, MessageRole};
let last_assistant = messages
.iter()
.rposition(|m| matches!(m.role, MessageRole::Assistant));
let active_tool_loop = last_assistant.is_some_and(|i| {
let has_tool_use = matches!(
&messages[i].content,
MessageContent::Blocks(blocks)
if blocks.iter().any(|b| matches!(b, ContentBlock::ToolUse { .. }))
);
// The loop is OPEN only while the request ends on the tool results:
// a later plain user turn closes it (the results answered, the model
// replied — its thinking is history the API ignores or rejects).
let continuation = &messages[i + 1..];
let ends_on_results = !continuation.is_empty()
&& continuation.iter().all(|m| {
matches!(
&m.content,
MessageContent::Blocks(blocks)
if blocks.iter().any(|b| matches!(b, ContentBlock::ToolResult { .. }))
)
});
has_tool_use && ends_on_results
});
let mut index = 0;
messages.retain_mut(|m| {
let i = index;
index += 1;
if !matches!(m.role, MessageRole::Assistant) {
return true;
}
let MessageContent::Blocks(blocks) = &mut m.content else {
return true;
};
let keep_thinking = active_tool_loop && Some(i) == last_assistant;
blocks.retain(|b| match b {
ContentBlock::Thinking {
thinking,
signature,
} => keep_thinking && !thinking.is_empty() && !signature.is_empty(),
_ => true,
});
!blocks.is_empty()
});
}
/// Convert a MessagesResponse to a single Assistant `ConversationItem`. /// Convert a MessagesResponse to a single Assistant `ConversationItem`.
/// ///
/// Note: Anthropic `Thinking` blocks are dropped here because this `From` /// Note: Anthropic `Thinking` blocks are dropped here because this `From`
@@ -5332,6 +5402,160 @@ mod tests {
/// messages while setting top-level `thinking: null` — the Messages API /// messages while setting top-level `thinking: null` — the Messages API
/// rejects this with a 400. Verify that stripped reasoning produces a /// rejects this with a 400. Verify that stripped reasoning produces a
/// valid request with no thinking blocks in messages. /// valid request with no thinking blocks in messages.
/// Collect `(message_index, thinking, signature)` for every thinking
/// block in a built Messages request.
fn thinking_blocks(json: &serde_json::Value) -> Vec<(usize, String, String)> {
let mut out = Vec::new();
for (i, m) in json["messages"].as_array().unwrap().iter().enumerate() {
if let Some(content) = m.get("content").and_then(|c| c.as_array()) {
for b in content {
if b.get("type").and_then(|t| t.as_str()) == Some("thinking") {
out.push((
i,
b["thinking"].as_str().unwrap_or_default().to_string(),
b["signature"].as_str().unwrap_or_default().to_string(),
));
}
}
}
}
out
}
fn reasoning(text: &str, encrypted: Option<&str>) -> ConversationItem {
ConversationItem::Reasoning(rs::ReasoningItem {
id: String::new(),
summary: if text.is_empty() {
vec![]
} else {
vec![rs::SummaryPart::SummaryText(rs::SummaryTextContent {
text: text.to_string(),
})]
},
content: None,
encrypted_content: encrypted.map(str::to_owned),
status: None,
})
}
fn assistant_text(text: &str) -> ConversationItem {
ConversationItem::Assistant(AssistantItem {
content: text.into(),
tool_calls: vec![],
model_id: None,
model_fingerprint: None,
reasoning_effort: None,
})
}
/// Anthropic validates EVERY replayed `thinking` block: an unsigned one
/// (history synthesized by another backend replays as `signature: ""`),
/// a Responses `tco_*` blob (signature with no text), or a block signed
/// by a different model after a mid-session `/model` switch 400s the
/// whole request — "messages.N.content.0: Invalid `signature` in
/// `thinking` block". The API only NEEDS thinking for the active
/// tool-use continuation, so outside one the builder must replay NO
/// thinking blocks at all.
#[test]
fn messages_request_strips_thinking_outside_active_tool_loop() {
let req = ConversationRequest::from_items(vec![
ConversationItem::system("sys"),
ConversationItem::user("q1"),
// Cross-backend history: unsigned reasoning (the Windows repro —
// session started on another model, then switched to Claude).
reasoning("some thinking", None),
assistant_text("a1"),
ConversationItem::user("q2"),
// Responses-API blob: signature-shaped bytes, no text.
reasoning("", Some("tco_blob")),
assistant_text("a2"),
ConversationItem::user("q3"),
// Genuinely signed — but its tool loop (none) is closed, so the
// API ignores it when valid and 400s it after a model switch.
reasoning("signed thinking", Some("sig-real")),
assistant_text("a3"),
ConversationItem::user("q4"),
]);
let json = serde_json::to_value(build_messages_request(&req)).unwrap();
assert_eq!(
thinking_blocks(&json),
vec![],
"no thinking block may be replayed outside an active tool loop:\n{json:#}"
);
}
/// The active tool-use continuation is the one place Anthropic REQUIRES
/// the signed thinking block back: the final assistant message issued
/// tool_use and its results follow. Exactly that block is kept; a
/// prior turn's signed thinking is still stripped.
#[test]
fn messages_request_keeps_signed_thinking_for_active_tool_loop() {
let req = ConversationRequest::from_items(vec![
ConversationItem::user("q0"),
reasoning("old turn", Some("sig-old")),
assistant_text("a0"),
ConversationItem::user("q1"),
reasoning("current turn", Some("sig-current")),
ConversationItem::Assistant(AssistantItem {
content: "".into(),
tool_calls: vec![ToolCall {
id: std::sync::Arc::from("tc1"),
name: "read_file".to_string(),
arguments: std::sync::Arc::from("{}"),
}],
model_id: None,
model_fingerprint: None,
reasoning_effort: None,
}),
ConversationItem::tool_result("tc1", "file contents"),
]);
let json = serde_json::to_value(build_messages_request(&req)).unwrap();
let blocks = thinking_blocks(&json);
assert_eq!(
blocks.len(),
1,
"exactly the active loop's thinking survives:\n{json:#}"
);
let (msg_idx, thinking, signature) = &blocks[0];
assert_eq!(thinking, "current turn");
assert_eq!(signature, "sig-current");
// It sits at content.0 of the final assistant message.
let msg = &json["messages"].as_array().unwrap()[*msg_idx];
assert_eq!(msg["role"], "assistant");
assert_eq!(msg["content"][0]["type"], "thinking");
assert!(
msg["content"]
.as_array()
.unwrap()
.iter()
.any(|b| b["type"] == "tool_use"),
"the kept thinking belongs to the tool_use turn"
);
}
/// A thinking-only assistant turn (aborted before any text/tool output)
/// must not survive as an EMPTY assistant message after the strip —
/// Anthropic rejects empty content arrays.
#[test]
fn messages_request_drops_assistant_message_emptied_by_thinking_strip() {
let req = ConversationRequest::from_items(vec![
ConversationItem::user("q"),
reasoning("aborted turn thinking", Some("sig")),
assistant_text(""),
ConversationItem::user("follow-up"),
]);
let json = serde_json::to_value(build_messages_request(&req)).unwrap();
for m in json["messages"].as_array().unwrap() {
if let Some(content) = m.get("content").and_then(|c| c.as_array()) {
assert!(
!content.is_empty(),
"no message may ship an empty content array:\n{json:#}"
);
}
}
assert_eq!(thinking_blocks(&json), vec![]);
}
#[test] #[test]
fn test_btw_stripped_reasoning_produces_no_thinking_blocks() { fn test_btw_stripped_reasoning_produces_no_thinking_blocks() {
// Simulate a conversation where the model responded with thinking. // Simulate a conversation where the model responded with thinking.
@@ -1041,6 +1041,71 @@ pub fn patch_reasoning_effort(body: &mut Value, effort: Option<ReasoningEffort>)
} }
} }
/// Adapt a serialized Responses request body to the ChatGPT/Codex backend
/// contract (`chatgpt.com/backend-api/codex/responses`) — ported from the
/// same reference as the identity headers (official Codex CLI + Pi's
/// `api/openai-codex-responses.ts`):
///
/// 1. The backend rejects `role: system` input items outright
/// (400 `{"detail":"System messages are not allowed"}`); its system
/// channel is the top-level `instructions` field. Hoist every system
/// input message there (order preserved, blank-line joined, appended to
/// any existing instructions) and remove them from `input`.
/// 2. `store` is always `false` on this backend, so reasoning continuity
/// is stateless: `include: ["reasoning.encrypted_content"]` is required
/// for the response to carry replayable encrypted reasoning.
///
/// openai-codex-GATED at the call sites — API-key `openai` Responses
/// bodies stay byte-identical.
pub fn adapt_body_for_codex_backend(body: &mut Value) {
// 1. Hoist system messages into `instructions`.
let mut hoisted: Vec<String> = Vec::new();
if let Some(input) = body.get_mut("input").and_then(|v| v.as_array_mut()) {
input.retain(|item| {
let is_system = item.get("role").and_then(|r| r.as_str()) == Some("system");
if is_system {
match item.get("content") {
Some(Value::String(s)) => hoisted.push(s.clone()),
Some(Value::Array(parts)) => {
for p in parts {
if let Some(t) = p.get("text").and_then(|t| t.as_str()) {
hoisted.push(t.to_string());
}
}
}
_ => {}
}
}
!is_system
});
}
if !hoisted.is_empty() {
let mut instructions = body
.get("instructions")
.and_then(|v| v.as_str())
.map(str::to_owned)
.unwrap_or_default();
for part in hoisted {
if !instructions.is_empty() {
instructions.push_str("\n\n");
}
instructions.push_str(&part);
}
body["instructions"] = Value::String(instructions);
}
// 2. Request replayable encrypted reasoning.
let include = body
.as_object_mut()
.map(|obj| obj.entry("include").or_insert_with(|| Value::Array(vec![])));
if let Some(Value::Array(entries)) = include {
let key = Value::String("reasoning.encrypted_content".to_string());
if !entries.contains(&key) {
entries.push(key);
}
}
}
/// Neutralize a `reasoning.effort` echo the typed `rs` enum cannot parse /// Neutralize a `reasoning.effort` echo the typed `rs` enum cannot parse
/// (`max`): remove it so response deserialization succeeds. The turn's /// (`max`): remove it so response deserialization succeeds. The turn's
/// canonical effort lives in the session sampling config regardless; only /// canonical effort lives in the session sampling config regardless; only
@@ -1551,6 +1616,66 @@ mod tests {
use super::*; use super::*;
use serde_json::json; use serde_json::json;
/// The Codex backend rejects `role: system` input outright
/// (400 `{"detail":"System messages are not allowed"}`) — its system
/// channel is the top-level `instructions` field, and stateless
/// (`store: false`) reasoning replay needs
/// `include: ["reasoning.encrypted_content"]`. The adapter must hoist
/// every system item (string or parts content, order preserved),
/// append to existing instructions, and leave the rest of the input
/// untouched.
#[test]
fn codex_adapter_hoists_system_messages_and_requests_encrypted_reasoning() {
let mut body = json!({
"model": "gpt-5.2-codex",
"instructions": "base",
"input": [
{"type": "message", "role": "system", "content": "sys head"},
{"type": "message", "role": "user", "content": "hello"},
{"type": "message", "role": "system", "content": [
{"type": "input_text", "text": "memory reminder"}
]},
{"type": "message", "role": "assistant", "content": "hi"}
]
});
adapt_body_for_codex_backend(&mut body);
let input = body["input"].as_array().unwrap();
assert_eq!(input.len(), 2, "system items removed from input: {body:#}");
assert!(
input.iter().all(|i| i["role"] != "system"),
"no system role may remain: {body:#}"
);
assert_eq!(
body["instructions"], "base\n\nsys head\n\nmemory reminder",
"system content hoisted into instructions, order preserved"
);
assert_eq!(
body["include"],
json!(["reasoning.encrypted_content"]),
"stateless reasoning replay requires the include"
);
// Idempotent: a second pass changes nothing.
let before = body.clone();
adapt_body_for_codex_backend(&mut body);
assert_eq!(body, before);
}
/// No system items and no prior instructions: input untouched, no
/// empty-string instructions invented, include still requested.
#[test]
fn codex_adapter_without_system_messages_only_adds_include() {
let mut body = json!({
"model": "gpt-5.2-codex",
"input": [{"type": "message", "role": "user", "content": "q"}]
});
adapt_body_for_codex_backend(&mut body);
assert!(body.get("instructions").is_none(), "{body:#}");
assert_eq!(body["input"].as_array().unwrap().len(), 1);
assert_eq!(body["include"], json!(["reasoning.encrypted_content"]));
}
/// String content (the only shape non-Mistral providers send) stays the /// String content (the only shape non-Mistral providers send) stays the
/// answer verbatim with no thinking — byte-identical to the pre-change /// answer verbatim with no thinking — byte-identical to the pre-change
/// deserialization. /// deserialization.
@@ -1881,12 +1881,15 @@ impl Config {
.default(true) .default(true)
.resolve() .resolve()
} }
/// Graph mode (`/graph`) master switch. Default ON the gray release /// Graph mode (`/graph`) master switch. Default ON in the binary: the
/// (plan.md G0, `KIGI_GRAPH=1` only) is over; every install gets the /// README ships graph engineering enabled for every install, but the
/// same commands (its absence on non-dev machines read as a platform /// old `default(false)` delegated enablement to installer env plumbing
/// bug). `KIGI_GRAPH=0` remains the off-switch. Graph mode additionally /// (`install.sh` shell-rc export vs `install.ps1` registry write) — and
/// requires the goal harness (nodes execute as goals), enforced at /// Windows terminals don't pick up freshly-written registry env, so
/// availability time, not here. /// `/graph` went "missing on Windows". The product default lives HERE,
/// not in installers. `KIGI_GRAPH=0` is the off-switch. Graph mode
/// additionally requires the goal harness (nodes execute as goals),
/// enforced at availability time, not here.
pub(crate) fn resolve_graph(&self) -> Resolved<bool> { pub(crate) fn resolve_graph(&self) -> Resolved<bool> {
BoolFlag::env("KIGI_GRAPH").default(true).resolve() BoolFlag::env("KIGI_GRAPH").default(true).resolve()
} }
@@ -535,13 +535,20 @@ async fn responses_upgrade_roundtrips_reconstructed_reasoning_as_typed_input() {
/// Upgrade path, Anthropic Messages API: a legacy session whose assistant /// Upgrade path, Anthropic Messages API: a legacy session whose assistant
/// carries inline `reasoning: {text, encrypted, id}` (text = thinking, /// carries inline `reasoning: {text, encrypted, id}` (text = thinking,
/// encrypted = signature) must, on load, reconstruct a sibling Reasoning /// encrypted = signature) must, on load, reconstruct a sibling Reasoning
/// item that emits a Anthropic Messages `thinking` content block (with `thinking` /// item — and when that turn is the ACTIVE tool-use continuation, its
/// + `signature`) on the outgoing `/v1/messages` request. /// `thinking` block (text + signature) must reach the outgoing
/// `/v1/messages` request verbatim.
///
/// Outside an active tool loop the block must be STRIPPED: Anthropic
/// validates every replayed signature (model-bound), so replaying stale
/// thinking is exactly what 400'd with "Invalid `signature` in `thinking`
/// block" after cross-model histories (see `prune_replayed_thinking`).
#[tokio::test] #[tokio::test]
async fn messages_upgrade_emits_reconstructed_reasoning_as_thinking_block() { async fn messages_upgrade_replays_reconstructed_thinking_only_in_active_tool_loop() {
// 1. Seed a legacy Anthropic Messages-origin chat_history.jsonl. Anthropic Messages // 1. Seed a legacy Anthropic Messages-origin chat_history.jsonl whose
// thinking blocks never carried an id (stream/messages.rs sets // assistant turn issued a tool call (thinking blocks never carried an
// id=""), and the signature lives in `encrypted`. // id — stream/messages.rs sets id="" and the signature lives in
// `encrypted`). The pending tool_result makes this the active loop.
let dir = tempfile::tempdir().unwrap(); let dir = tempfile::tempdir().unwrap();
std::fs::write( std::fs::write(
dir.path().join("chat_history.jsonl"), dir.path().join("chat_history.jsonl"),
@@ -550,7 +557,9 @@ async fn messages_upgrade_emits_reconstructed_reasoning_as_thinking_block() {
"\n", "\n",
r#"{"type":"user","content":[{"type":"text","text":"q1"}]}"#, r#"{"type":"user","content":[{"type":"text","text":"q1"}]}"#,
"\n", "\n",
r#"{"type":"assistant","content":"a1","reasoning":{"text":"legacy anthropic thinking","encrypted":"SIGNATURE_abc","id":""},"model_id":"kigi-4.5"}"#, r#"{"type":"assistant","content":"a1","reasoning":{"text":"legacy anthropic thinking","encrypted":"SIGNATURE_abc","id":""},"model_id":"kigi-4.5","tool_calls":[{"id":"tc1","name":"read_file","arguments":"{}"}]}"#,
"\n",
r#"{"type":"tool_result","tool_call_id":"tc1","content":"file contents"}"#,
"\n", "\n",
), ),
) )
@@ -558,7 +567,7 @@ async fn messages_upgrade_emits_reconstructed_reasoning_as_thinking_block() {
// 2. Load + upgrade. // 2. Load + upgrade.
let adapter = JsonlStorageAdapter::with_root(dir.path().to_path_buf()); let adapter = JsonlStorageAdapter::with_root(dir.path().to_path_buf());
let mut items = adapter.load_chat_history_from_dir(dir.path()).unwrap(); let items = adapter.load_chat_history_from_dir(dir.path()).unwrap();
assert!( assert!(
items items
.iter() .iter()
@@ -566,20 +575,18 @@ async fn messages_upgrade_emits_reconstructed_reasoning_as_thinking_block() {
"legacy inline reasoning must be reconstructed as a sibling on load, got {items:?}" "legacy inline reasoning must be reconstructed as a sibling on load, got {items:?}"
); );
// 3. Continue and send over the Messages API, capturing the body. // 3. Send the tool-loop continuation over the Messages API.
items.push(ConversationItem::user("q2"));
let server = MockInferenceServer::start().await.unwrap(); let server = MockInferenceServer::start().await.unwrap();
server.set_response("ok"); server.set_response("ok");
let client = create_test_client(&server.url(), ApiBackend::Messages); let client = create_test_client(&server.url(), ApiBackend::Messages);
let _ = client let _ = client
.conversation_collect(ConversationRequest::from_items(items)) .conversation_collect(ConversationRequest::from_items(items.clone()))
.await .await
.unwrap(); .unwrap();
// 4. The reconstructed reasoning must emit a Anthropic Messages `thinking` // 4. The active loop's reconstructed reasoning must emit an Anthropic
// content block carrying the thinking text + signature. // `thinking` content block carrying the thinking text + signature.
let body = server.request_bodies().pop().unwrap(); let body = server.request_bodies().pop().unwrap();
let messages = body.get("messages").unwrap().as_array().unwrap(); let messages = body.get("messages").unwrap().as_array().unwrap();
let thinking_block = messages let thinking_block = messages
@@ -593,7 +600,7 @@ async fn messages_upgrade_emits_reconstructed_reasoning_as_thinking_block() {
}) })
.find(|b| b.get("type").and_then(Value::as_str) == Some("thinking")) .find(|b| b.get("type").and_then(Value::as_str) == Some("thinking"))
.unwrap_or_else(|| { .unwrap_or_else(|| {
panic!("reconstructed reasoning must emit an Anthropic thinking block; messages: {messages:#?}") panic!("active-loop reasoning must emit an Anthropic thinking block; messages: {messages:#?}")
}); });
assert_eq!( assert_eq!(
thinking_block.get("thinking").and_then(Value::as_str), thinking_block.get("thinking").and_then(Value::as_str),
@@ -605,6 +612,25 @@ async fn messages_upgrade_emits_reconstructed_reasoning_as_thinking_block() {
Some("SIGNATURE_abc"), Some("SIGNATURE_abc"),
"signature (encrypted) preserved — required to reuse the thought server-side" "signature (encrypted) preserved — required to reuse the thought server-side"
); );
// 5. A follow-up user turn CLOSES the loop: the same history plus a new
// user message must replay NO thinking block at all.
let mut closed = items;
closed.push(ConversationItem::user("q2"));
let _ = client
.conversation_collect(ConversationRequest::from_items(closed))
.await
.unwrap();
let body = server.request_bodies().pop().unwrap();
let any_thinking = body["messages"].as_array().unwrap().iter().any(|m| {
m.get("content")
.and_then(Value::as_array)
.is_some_and(|c| c.iter().any(|b| b["type"] == "thinking"))
});
assert!(
!any_thinking,
"stale thinking must be stripped outside the active tool loop; body: {body:#?}"
);
} }
// ============================================================================ // ============================================================================
@@ -1443,3 +1469,79 @@ async fn test_chat_completions_backend_hits_chat_endpoint_not_responses() {
"Should NOT have called /v1/responses" "Should NOT have called /v1/responses"
); );
} }
/// ChatGPT/Codex backend body contract (`openai_codex = true`): the
/// `/codex/responses` endpoint rejects `role: system` input outright
/// (400 {"detail":"System messages are not allowed"}) — system content
/// must ride the top-level `instructions` field, and stateless reasoning
/// replay needs `include: ["reasoning.encrypted_content"]`. Ported from
/// the official Codex CLI + Pi's api/openai-codex-responses.ts, like the
/// identity headers.
#[tokio::test]
async fn codex_responses_body_hoists_system_into_instructions() {
let server = MockInferenceServer::start().await.unwrap();
server.set_response("ok");
let mut config = common::test_sampler_config(&server.url(), ApiBackend::Responses, &[]);
config.openai_codex = true;
let client = Client::new(config).unwrap();
let _ = client
.conversation_collect(ConversationRequest::from_items(vec![
ConversationItem::system("You are Kigi."),
ConversationItem::user("test"),
]))
.await
.unwrap();
let body = server.request_bodies().pop().unwrap();
let input = body["input"].as_array().unwrap();
assert!(
input
.iter()
.all(|i| i.get("role").and_then(Value::as_str) != Some("system")),
"codex backend must never receive system-role input: {body:#?}"
);
assert_eq!(
body["instructions"].as_str(),
Some("You are Kigi."),
"system prompt must ride the instructions field: {body:#?}"
);
assert_eq!(
body["include"],
serde_json::json!(["reasoning.encrypted_content"]),
"stateless reasoning replay requires the include: {body:#?}"
);
}
/// Control: the API-key `openai` Responses path (`openai_codex = false`)
/// stays byte-compatible — system-role input preserved, no codex fields.
#[tokio::test]
async fn plain_responses_body_keeps_system_role_input() {
let server = MockInferenceServer::start().await.unwrap();
server.set_response("ok");
let client = create_test_client(&server.url(), ApiBackend::Responses);
let _ = client
.conversation_collect(ConversationRequest::from_items(vec![
ConversationItem::system("You are Kigi."),
ConversationItem::user("test"),
]))
.await
.unwrap();
let body = server.request_bodies().pop().unwrap();
assert!(
body["input"]
.as_array()
.unwrap()
.iter()
.any(|i| i.get("role").and_then(Value::as_str) == Some("system")),
"api-key openai keeps system-role input: {body:#?}"
);
assert!(
body.get("instructions")
.map(|v| v.is_null())
.unwrap_or(true),
"no instructions hoist outside codex: {body:#?}"
);
}
+7 -9
View File
@@ -149,15 +149,13 @@ try {
Write-Host "Run 'kigi' to get started." Write-Host "Run 'kigi' to get started."
} }
# Graph engineering ships enabled by default. Respect an explicit # Graph engineering is enabled by default IN THE BINARY (resolve_graph
# user choice: only set the variable when it is not already defined # defaults true) — no environment plumbing needed. The installer used
# (so a persisted opt-out of "0" survives reinstalls). # to persist KIGI_GRAPH=1 into the User registry env, but running
$Graph = [Environment]::GetEnvironmentVariable("KIGI_GRAPH", "User") # terminals (and new tabs of an open Windows Terminal) never pick up
if ($null -eq $Graph -or $Graph -eq "") { # freshly-written registry variables, which made /graph "missing on
[Environment]::SetEnvironmentVariable("KIGI_GRAPH", "1", "User") # Windows" while the shell-rc path worked on macOS/Linux. Opt out any
Write-Host "Enabled graph engineering (KIGI_GRAPH=1)." # time with: [Environment]::SetEnvironmentVariable('KIGI_GRAPH','0','User')
Write-Host "Disable: [Environment]::SetEnvironmentVariable('KIGI_GRAPH','0','User')"
}
} finally { } finally {
Remove-Item -Path $TmpDir -Recurse -Force -ErrorAction SilentlyContinue Remove-Item -Path $TmpDir -Recurse -Force -ErrorAction SilentlyContinue
} }
+4 -8
View File
@@ -209,7 +209,6 @@ case "${SHELL:-}" in
*/zsh) */zsh)
RC_FILE="${ZDOTDIR:-$HOME}/.zshrc" RC_FILE="${ZDOTDIR:-$HOME}/.zshrc"
PATH_LINE="export PATH=\"$BIN_DIR:\$PATH\"" PATH_LINE="export PATH=\"$BIN_DIR:\$PATH\""
GRAPH_LINE="export KIGI_GRAPH=1"
;; ;;
*/bash) */bash)
# macOS login shells read ~/.bash_profile; Linux reads ~/.bashrc. # macOS login shells read ~/.bash_profile; Linux reads ~/.bashrc.
@@ -219,7 +218,6 @@ case "${SHELL:-}" in
RC_FILE="$HOME/.bashrc" RC_FILE="$HOME/.bashrc"
fi fi
PATH_LINE="export PATH=\"$BIN_DIR:\$PATH\"" PATH_LINE="export PATH=\"$BIN_DIR:\$PATH\""
GRAPH_LINE="export KIGI_GRAPH=1"
;; ;;
*/fish) */fish)
# fish_add_path in config.fish is fish's own idempotent way # fish_add_path in config.fish is fish's own idempotent way
@@ -228,12 +226,10 @@ case "${SHELL:-}" in
mkdir -p "$FISH_CONF_DIR" mkdir -p "$FISH_CONF_DIR"
RC_FILE="$FISH_CONF_DIR/config.fish" RC_FILE="$FISH_CONF_DIR/config.fish"
PATH_LINE="fish_add_path $BIN_DIR" PATH_LINE="fish_add_path $BIN_DIR"
GRAPH_LINE="set -gx KIGI_GRAPH 1"
;; ;;
*) *)
RC_FILE="$HOME/.profile" RC_FILE="$HOME/.profile"
PATH_LINE="export PATH=\"$BIN_DIR:\$PATH\"" PATH_LINE="export PATH=\"$BIN_DIR:\$PATH\""
GRAPH_LINE="export KIGI_GRAPH=1"
;; ;;
esac esac
@@ -247,8 +243,8 @@ case ":$PATH:" in
;; ;;
esac esac
# Graph engineering ships enabled by default. The KIGI_GRAPH guard makes # Graph engineering is enabled by default IN THE BINARY (resolve_graph
# this idempotent AND respects an explicit user opt-out (an existing # defaults true) — the installer no longer writes KIGI_GRAPH=1 into shell
# `export KIGI_GRAPH=0` line is left untouched). Disable any time with: # rc files (per-shell env plumbing was fragile and diverged per platform).
# Disable any time with:
# echo 'export KIGI_GRAPH=0' >> <your shell rc> # echo 'export KIGI_GRAPH=0' >> <your shell rc>
persist_line "$RC_FILE" "$GRAPH_LINE" "KIGI_GRAPH" "graph engineering (KIGI_GRAPH=1)"