A deterministic DAG scheduler layered on the existing goal engine: /graph <objective> decomposes the objective via a graph-planner subagent, gates the result through Agentproof-style static validation (cycles, unknown deps, duplicate slugs, caps), appends a structural final-verification node, then executes each node as one ordinary goal — planner, worker loop, adversarial verifier, budget and pause machinery all reused verbatim. The in-turn loop advances nodes within the same turn (multi-loop closed loop); goal-side auto-pauses cascade to the graph at a single chokepoint; node goals are armed with the remaining graph budget so mid-node overruns trip graph-wide. Gated by KIGI_GRAPH=1 (default off) + the goal harness. State persists to <session_dir>/graph/state.json with a clear-tombstone; per-version immutable baselines and per-node artifact archives live under graph/<graph_id>/. Restore demotes Active->UserPaused and Running->Ready (verifier-gated re-run). Review hardening (adversarial multi-agent pass, 24 confirmed findings fixed): the goal-inactive loop break now consults the graph seam (mid-turn classifier-disabled completions can no longer strand an Active graph), the pause cascade fires even when no node goal is in flight (cancel during planning), node bookkeeping precedes the long setup await, /graph clear only resets the engine it owns, budget trips terminally fail the in-flight node, and the pause transitions in /goal pause + /graph pause no longer hide inside debug_assert! (a release-build no-op inherited from upstream). Tests: 4908 kigi-shell lib tests green, including a serial 4-node closed-loop e2e, restore/resume, cascade, mutual-exclusion, planning-retry, persistence round-trip + tombstone, and status rendering.
5.2 KiB
Kigi — agent/developer notes
Single source of truth for how this repository is organized and the constraints every change must respect. Update this file whenever the tech stack or product direction changes.
What this is
Kigi is an unofficial Kimi Code CLI community build: a hard fork of
xai-org/grok-build (Apache-2.0, Rust) re-targeted at the Kimi Code
subscription API and the Moonshot open platform. It coexists with the
official kimi CLI: binary kigi, config dir ~/.kigi
(KIGI_SHARE_DIR override), keyring service kigi, env prefix KIGI_*.
Never read or write ~/.kimi (except the explicit one-time read-only
import) or any KIMI_* env var.
Hard constraints
- Zero egress: outbound connections are limited to
auth.kimi.com,api.kimi.com,api.moonshot.cn,api.moonshot.ai, GitHub Releases domains, and user-configured MCP servers. No telemetry, no analytics, ever.crates/codegen/kigi-envis the single home of first-party endpoints. - Toolchain: Rust 1.97.0 (rust-toolchain.toml), edition 2024.
- Gates (all must stay green):
cargo check --workspace --all-targets,cargo clippy --workspace --all-targets(zero warnings),cargo fmt --all --check,cargo deny check advisories. - Observability is local:
kigi-log(unified session log,--debugfirehose, subsystem file logs, opt-in instrumentation) writes under~/.kigionly. Its zero-network property is a contract. - The root
Cargo.tomlis hand-maintained (upstream's generator is not in this repo). Members sorted; versions inherited fromworkspace.package.version(0.1.0).
Layout
crates/codegen/— the bulk of the application (62kigi-*crates). Key ones:kigi-bin(binarykigi),kigi-tui(full-screen TUI + headless-pmode +acp/mcpcommands),kigi-shell(agent runtime, leader-follower IPC, sessions),kigi-sampler(inference client; ChatCompletions/Responses/Messages backends),kigi-auth(credentials),kigi-config(config layering,~/.kigipaths),kigi-env(endpoints),kigi-tools(tool implementations incl. codex/opencode ports — see its THIRD_PARTY_NOTICES.md),kigi-workspace(FS/VCS/exec/permissions, checkpoint/worktree),kigi-log(local observability).crates/common/,crates/build/,prod/mc/— shared libs, proto build, proxy wire types (the latter to be redefined against Kimi in M1).third_party/— vendored Mermaid rendering stack (untouched policy).bin/protoc— dotslash launcher used by proto codegen.
Test seams
Cross-crate test hooks are behind the test-support cargo feature
(kigi-workspace, kigi-pager-render, kigi-config, kigi-tui), enabled via
dependents' [dev-dependencies]. Don't expose new test seams as plain
#[cfg(test)] items across crate boundaries.
Graph mode (/graph, post-0.1.x — plan.md in the parent dir)
A deterministic DAG scheduler layered over the goal engine: /graph <objective> decomposes the objective into nodes (graph planner subagent
→ Agentproof-style static gate in graph_plan.rs), then executes each
node as one ordinary goal — the agentic loop lives INSIDE the node; the
edges stay deterministic Rust. The harness appends a terminal
gn-final verification node depending on every planner node.
- Feature flag
KIGI_GRAPH=1(default off); availability additionally requires the goal harness (BuiltinGate::Graph). - Key modules (kigi-shell):
session/graph_tracker.rs(pure state machine; reusesGoalStatus/GoalPhase/GoalPauseReason),session/graph_plan.rs(planner-JSON contract + validation + fnv id canonicalization),session/graph_planner.rs(planner runner, reuses the goal planner spawn plumbing),session/acp_session_impl/graph.rs(orchestration seam). - Seam points:
handle_promptintercepts GraphSet/GraphResume; the in-turn loop'sEndTurnarm callsrun_graph_round_end()to advance nodes within the same turn; goal auto-pauses cascade to the graph inauto_pause_goal_if_active_inner; node goals are armed with the REMAINING graph budget soenforce_goal_token_budgetcascades trips. - Persistence:
PersistenceMsg::GraphModeState(Option<..>)→<session_dir>/graph/state.json(Nonetombstones after clear); immutable per-version baselinesgraph/graph.baseline.v{N}.json; per-node goal artifacts archived tograph/<node_id>/. Restore demotesActive→UserPausedandRunning→Ready(re-run is safe: the verifier gates completion). /goaland/graphare mutually exclusive while the graph owns the engine; e2e suite:acp_session_tests/graph/graph_e2e_tests.rs.
Milestones (PRD §8.3)
- M0 (done): rename, deletions (voice/telemetry/announcements/marketplace/ relay-gateway), toolchain, gates.
- M1: Kimi device-flow auth (F1), Moonshot API-key channel (F2), inference
via ChatCompletions (F3), dynamic model sync (F4). The auth stack in
kigi-shell/src/auth+kigi-authgets rewritten here; transitional grok.com references live only there and inkigi-sampler/proxy types. - M2: server-side search/fetch (F5), command parity with kimi-cli 1.49.0
(F6), one-time
~/.kimi/config.tomlimport (F7), F9 smoke list, perf CI. - M3: GitHub Releases distribution, install scripts, self-update (F8).