# Pi 1.0 qualification

## Current contract

Pi 1.0.0 is the supported floor. The five declared resources remain four curated Z.AI tools plus the status command. Connections are lazy and paid calls still require the existing user-intent and credential checks. Pi's native MCP feature is not a replacement for these curated tools or their bounded output and cancellation behavior.

Service credentials use the explicit Z.AI environment variables first, then the native model registry's provider authentication for `zai`, `zai-coding-cn`, or catalog aliases with Z.AI endpoints. Pi owns credential-command expansion and caching; the extension does not read `auth.json`, execute shell templates, or retain a session context. The missing-key startup warning checks credential availability without resolving a command. Model headers alone do not supply a bearer key for this separate service.

Native `outputSchema`/`structuredContent` contain only the existing bounded server/tool/text outcome, truncation flag and optional saved-file reference, not raw upstream MCP data. Shutdown aborts owned setup and requests, closes once, rejects queued calls and prevents late setup from publishing a client. Failures render as failures, never success, and are not automatically replayed.

## Vision dependency defaults — 2026-10-02

Merged dependency update #11 (`35040ae9894727ace0606f1e38aa02e7cd0705f8`) installs `@z_ai/mcp-server@0.1.5`. The owner selected its upstream defaults: `glm-5.3-flash` and 131,072 maximum output tokens, replacing `glm-4.6v` and 32,768. The extension imposes no model override or lower cap; explicit user vendor settings remain supported.

Actual vendor source/configuration and offline stdio initialization/tool listing were inspected. Full official Pi 1.0.0 and immutable fork877 compatibility checks pass on the current dependency tree, including intercepted real-child credential/logging and native private-output controls. No live availability, pricing or paid-call proof is claimed; the larger output ceiling can increase per-call cost. Evidence: `/tmp/pi100-extension-cleanup/services-evidence/current-reconciliation/current-union-pi-zai-mcp-14/` and `services-evidence/vendor/`.

## Safety maintenance qualification — 2026-10-02

The vision child now receives only the selected service credential, SDK-safe platform environment and explicit vendor options. Large saved outputs use unique private directories (0700) and exclusive files (0600).

At base `d01a0e70ed9a36d3b222ffe917433a883daafa66`, the new native controls failed for the intended reasons: shared-temp output directory 0755, unrelated credentials/Node hooks inherited by the real vendor child, and successful placeholder-key use. With the repair, full `check:compat` passed on official Pi 1.0.0 and the immutable maintained fork `8776b5e3511b1f00548abc6bd42a6da2bbc9ca02-eae8bb8666780a16-node24.21.0-darwin-arm64` (four native tests, zero skips). Both use physical Node 24.21.0 and coherent selected-host companions. Normal `ci` passed with zero production audit vulnerabilities.

The actual bundled vendor child analyzes a local fixture image with intercepted fetch and denied network; assertions observe its selected Bearer credential, absence of unrelated environment, configured model/token limit, actual selected log file and placeholder failure. Native loopback search verifies full saved bytes and Unix private modes under shared temp/umask 022. No live model/service request, paid call or Windows permission qualification was performed. Evidence: `/tmp/pi100-extension-cleanup/services-evidence/audits/mcp-safety/`.

## Original modernization evidence — 2026-10-01

- Base: `c7547ea244d5446525829c1878139af3bf494929`.
- Official Pi source: `a13d35a742c6ef8462812a28fbe1d8c8b7431c32` (v1.0.0). SDK SHA256 `5482298b995db935f7b96f5d6056fa1c36ac6fc80456be594ef65b83c62b0d30`; bundled CLI SHA256 `e79626f2dd6f94aa45d30f3fa63cd84319a6eefcd150b353cfaf274366926774`.
- Physical Node 24.21.0, eight Pi companion packages at 1.0.0, TypeBox 1.3.27. Checks use isolated HOME/agent profiles and explicit selected `PI_PACKAGE_DIR`; inherited live-fork overrides are discarded.
- `npm run ci`: typecheck, smoke, production dependency audit (zero vulnerabilities) and package dry-run passed. Existing compatible transitive dependency patches repair the initial production audit failures; production dependency ranges are unchanged.
- `npm run check:compat`: typecheck, smoke and the native SDK lifecycle fixture passed (one suite, zero skipped/failed). Native loopback MCP initialization, bounded structured outcomes, failure/no replay, reload/shutdown, auth resolution/cache and teardown-during-setup are exercised without paid calls.
- Source and extracted package: ordinary ESM import, actual bundled CLI registration, absolute official SDK registration/schema/reload/shutdown checks. Observers assert the selected SDK/CLI hashes and complete cohort, not only a version label.
- Installed bundled vision server: actual stdio initialize and tool listing expose all eight curated actions. The child has network denied and an opaque fixture credential; no vision tool is invoked.
- Fullscreen and regular actual CLI fixtures inspected at 48/100/160 columns, after resizing, collapsed and expanded. Unicode, bounded long output and a tool failure remain readable; the failure shows `failed` and the original failure text. Fixture HTTP/faux-model responses are owned and offline.

Local logs: `/tmp/zai-mcp-pi100-{ci,check,vision,esm,source-probe,packed-probe}.log`. Source/packed identity proofs: `/tmp/pi100-native-services/zai-mcp-{source,packed}-proof/identity.json`. UI captures: `/tmp/pi100-native-services/zai-mcp-{fullscreen,regular}-{48,100,160,expanded}.txt`, with host identity observations alongside them. Owned UI processes are stopped after inspection.

## Original modernization delivery boundaries — 2026-10-01

Recommended unused version: **0.2.0**, through the existing owned npm and GitHub release channels after parent review. No publication, tag or merge is part of this implementation. The older 0.87 cohort-only PR is not overwritten or cherry-picked.

The live fork, managed packages, settings and authentication are untouched. A future minimal 1.0 fork has no immutable qualified candidate yet; official checks do not certify that fork. No paid/provider request, live credential flow, user app mutation, live activation/reload/restart or manually triggered remote CI was attempted. Node 22.19 remains the existing manifest minimum, not a new runtime qualification claim; this evidence is on Node 24.21.0. The official pinned development cohort's audit advisory is not counted as a production dependency finding.
