Luigit
repositories / pi-ext

pi-ext

bugabingas pi extensions

owned by admin

extensions/strata/README.md

Raw
Rendered preview

Strata

Review local Git changes as LLM-organized cohorts and layers in a browser. Exact diff hunks stay code-owned; validation requires complete, non-duplicated coverage. Uses Pi's selected model and registered provider. Normal reviews need no forge account; optional GitHub context uses your existing gh authentication.

Load

Included through the root Pi package. For standalone loading: pi -e ./extensions/strata/index.ts. Requires Git and a browser.

Commands

  • /strata: tracked staged and unstaged changes against HEAD.
  • /strata --staged: staged changes only.
  • /strata --base REF: merge-base through HEAD.
  • /strata --pr [number|URL]: review a GitHub PR; without an identifier, resolve the current branch's PR.
  • /strata cancel: cancel model work and close the workspace.

Select layers, inspect original lines alongside explanations, mark hunks reviewed, and add line comments or notes. A compact two-line Pi widget above the editor keeps the review state, progress, and authenticated browser link visible without replacing the footer. Collapse either side panel to give code more space; Details, Ask, and Feedback share one drawer. Use j/k for diff lines, ]c / [c for hunks, and ]l / [l for layers. Space r toggles the focused hunk reviewed; Space R toggles the whole selected layer. The keyboard strip shows mode and focus; Space reveals contextual actions and ? opens the full shortcut guide. Text fields keep native typing; Escape returns to diff navigation. Send feedback to Pi starts a follow-up turn with snapshot-qualified feedback, not a commit or forge review. Refresh, feedback submission, and close ask for confirmation; refresh replaces the snapshot and its draft. Drafts and plans resume from the Pi session only when the snapshot matches. Pi buffers a brand-new session in memory until its first assistant response; before that, drafts do not survive process exit.

Optional GitHub context

Only --pr requires gh and makes forge requests. Strata reviews the checkout where the agent works, not a detached remote diff beside an unrelated branch. It asks before switching a clean checkout to the PR's pinned head, reuses a matching local branch, or creates a non-colliding PR branch. Dirty worktrees, unpublished/divergent local commits, protected-path changes, and unavailable confirmation prevent the switch. It never stashes, force-resets, or runs repository hooks. Repository-local external filters, included Git config, credential helpers, and URL rewrites are refused for PR operations rather than executed.

Details shows PR metadata and discussions with a GitHub icon, author, and source links. Current mapped discussions appear beside their diff anchors; outdated or unmapped discussions remain labeled in Details. Imported text stays read-only and separate from your findings, while planning and Ask receive it as untrusted context. A changed checkout or remote PR commit blocks feedback; reopen --pr if updating the checkout requires confirmation.

Feedback carries the PR identity, checkout, reviewed commits, and comment anchors to the agent. The agent can inspect and edit that branch normally; publishing to GitHub requires separate approval. Strata itself never publishes. The GitHub adapter returns forge-neutral metadata so another forge can be added without changing the review workflow.

Ask

Each layer has its own conversation; All changes has a separate review-wide thread. The displayed scope and focused hunk accompany every question, together with the full diff, review plan, and that thread's history. Ask can use bounded read, literal grep, and ls tools on the current filesystem. Investigation has no fixed call/round budget; it stops on an answer, cancellation, or provider failure while retaining per-tool resource limits. Relative paths resolve from the reviewed repository; absolute paths can inspect installed packages, node_modules, external documentation, and ordinary system paths. Live results are labeled CURRENT FILESYSTEM because they are evidence beside the immutable snapshot, not captured snapshot source. Tools reject protected paths, Git internals, resolved protected symlink targets, non-regular files, binary content, and unbounded traversal. Path and opened-file checks are not an OS sandbox against coordinated hostile filesystem races on platforms without descriptor-target inspection. Shift+Enter sends, Enter inserts a newline, and the composer stays below the scrolling transcript. Switching layers preserves unsent questions; completed conversations survive browser reload but clear on snapshot refresh or server closure.

Boundaries

Initial Git capture omits untracked, binary, and protected content; Ask may explicitly read untracked text through its protected filesystem tools. Git capture resource limits and invalid model structure fail visibly rather than silently truncating. Model input uses lossless file-grouped XML with unified-diff text, without a separate prompt byte cap. The provider enforces its context limit; provider errors remain visible. A clean repository opens an empty review without calling the model. Freshness is checked before and after Ask, and before feedback submission; changed snapshots must be refreshed. Source code and model text are rendered inertly, and the local server requires a per-review browser session token. Git external diff and text-conversion commands are disabled.

The review uses the model selected when the workspace opens. Generated explanations and flow diagrams are aids, not verified dependency analysis. No automatic approval, forge publishing, or code editing by Strata. Optional PR checkout changes branches only after the confirmation and safety checks above.

RPC clients receive the URL through Pi's extension notification protocol because component widgets are TUI-only. No-UI modes emit the URL and actionable failures as displayed strata-status custom messages without triggering an LLM turn. JSON mode exposes those messages through Pi's native message events. Pi's text print mode does not render standalone custom messages, so it cannot expose /strata command output. No other settings or user-facing Pi tools.

Settings

strata.openBrowser (boolean, default true) controls whether /strata launches a browser; false keeps the local URL in Pi's widget only. Set it in ~/.pi/agent/settings.json or .pi/settings.json, for example { "strata": { "openBrowser": false } }. STRATA_NO_OPEN overrides settings with inverted meaning: 1 or true disables opening, 0 or false enables it. Any other value, including empty, is invalid. There is no CLI flag. Precedence: STRATA_NO_OPEN, trusted project settings, user settings, default. Project settings apply only when Pi trusts the project. Settings values must be JSON booleans. An invalid value never falls back to a lower source; the review stays reachable through its URL, and Strata reports the error through its widget and notifications without launching a browser.

Verification

mise run //extensions/strata:test, mise run //extensions/strata:check, and mise run //extensions/strata:e2e. Browser tests cover Chromium and Firefox. For live-provider/TUI validation, run mise run //extensions/strata:live -- --model PROVIDER/MODEL, then /strata or /strata --base REF. This loads only Strata, disables coding tools, uses existing credentials, and shows the browser URL in the widget. The full behavior and verification contract is in SPEC.md.

Debug

Opt in through debug configuration. Safe events: session.start, session.shutdown, review.open.start, review.open.finish, review.open.error.

# Strata

Review local Git changes as LLM-organized cohorts and layers in a browser.
Exact diff hunks stay code-owned; validation requires complete, non-duplicated coverage.
Uses Pi's selected model and registered provider.
Normal reviews need no forge account; optional GitHub context uses your existing `gh` authentication.

## Load

Included through the root Pi package.
For standalone loading: `pi -e ./extensions/strata/index.ts`.
Requires Git and a browser.

## Commands

- `/strata`: tracked staged and unstaged changes against HEAD.
- `/strata --staged`: staged changes only.
- `/strata --base REF`: merge-base through HEAD.
- `/strata --pr [number|URL]`: review a GitHub PR; without an identifier, resolve the current branch's PR.
- `/strata cancel`: cancel model work and close the workspace.

Select layers, inspect original lines alongside explanations, mark hunks reviewed, and add line comments or notes.
A compact two-line Pi widget above the editor keeps the review state, progress, and authenticated browser link visible without replacing the footer.
Collapse either side panel to give code more space; Details, Ask, and Feedback share one drawer.
Use `j/k` for diff lines, `]c` / `[c` for hunks, and `]l` / `[l` for layers.
`Space r` toggles the focused hunk reviewed; `Space R` toggles the whole selected layer.
The keyboard strip shows mode and focus; Space reveals contextual actions and `?` opens the full shortcut guide.
Text fields keep native typing; Escape returns to diff navigation.
**Send feedback to Pi** starts a follow-up turn with snapshot-qualified feedback, not a commit or forge review.
Refresh, feedback submission, and close ask for confirmation; refresh replaces the snapshot and its draft.
Drafts and plans resume from the Pi session only when the snapshot matches.
Pi buffers a brand-new session in memory until its first assistant response; before that, drafts do not survive process exit.

## Optional GitHub context

Only `--pr` requires `gh` and makes forge requests.
Strata reviews the checkout where the agent works, not a detached remote diff beside an unrelated branch.
It asks before switching a clean checkout to the PR's pinned head, reuses a matching local branch, or creates a non-colliding PR branch.
Dirty worktrees, unpublished/divergent local commits, protected-path changes, and unavailable confirmation prevent the switch.
It never stashes, force-resets, or runs repository hooks.
Repository-local external filters, included Git config, credential helpers, and URL rewrites are refused for PR operations rather than executed.

Details shows PR metadata and discussions with a GitHub icon, author, and source links.
Current mapped discussions appear beside their diff anchors; outdated or unmapped discussions remain labeled in Details.
Imported text stays read-only and separate from your findings, while planning and Ask receive it as untrusted context.
A changed checkout or remote PR commit blocks feedback; reopen `--pr` if updating the checkout requires confirmation.

Feedback carries the PR identity, checkout, reviewed commits, and comment anchors to the agent.
The agent can inspect and edit that branch normally; publishing to GitHub requires separate approval.
Strata itself never publishes.
The GitHub adapter returns forge-neutral metadata so another forge can be added without changing the review workflow.

## Ask

Each layer has its own conversation; All changes has a separate review-wide thread.
The displayed scope and focused hunk accompany every question, together with the full diff, review plan, and that thread's history.
Ask can use bounded `read`, literal `grep`, and `ls` tools on the current filesystem.
Investigation has no fixed call/round budget; it stops on an answer, cancellation, or provider failure while retaining per-tool resource limits.
Relative paths resolve from the reviewed repository; absolute paths can inspect installed packages, `node_modules`, external documentation, and ordinary system paths.
Live results are labeled **CURRENT FILESYSTEM** because they are evidence beside the immutable snapshot, not captured snapshot source.
Tools reject protected paths, Git internals, resolved protected symlink targets, non-regular files, binary content, and unbounded traversal.
Path and opened-file checks are not an OS sandbox against coordinated hostile filesystem races on platforms without descriptor-target inspection.
Shift+Enter sends, Enter inserts a newline, and the composer stays below the scrolling transcript.
Switching layers preserves unsent questions; completed conversations survive browser reload but clear on snapshot refresh or server closure.

## Boundaries

Initial Git capture omits untracked, binary, and protected content; Ask may explicitly read untracked text through its protected filesystem tools.
Git capture resource limits and invalid model structure fail visibly rather than silently truncating.
Model input uses lossless file-grouped XML with unified-diff text, without a separate prompt byte cap.
The provider enforces its context limit; provider errors remain visible.
A clean repository opens an empty review without calling the model.
Freshness is checked before and after Ask, and before feedback submission; changed snapshots must be refreshed.
Source code and model text are rendered inertly, and the local server requires a per-review browser session token.
Git external diff and text-conversion commands are disabled.

The review uses the model selected when the workspace opens.
Generated explanations and flow diagrams are aids, not verified dependency analysis.
No automatic approval, forge publishing, or code editing by Strata.
Optional PR checkout changes branches only after the confirmation and safety checks above.

RPC clients receive the URL through Pi's extension notification protocol because component widgets are TUI-only.
No-UI modes emit the URL and actionable failures as displayed `strata-status` custom messages without triggering an LLM turn.
JSON mode exposes those messages through Pi's native message events.
Pi's text print mode does not render standalone custom messages, so it cannot expose `/strata` command output.
No other settings or user-facing Pi tools.

## Settings

`strata.openBrowser` (boolean, default `true`) controls whether `/strata` launches a browser; `false` keeps the local URL in Pi's widget only.
Set it in `~/.pi/agent/settings.json` or `.pi/settings.json`, for example `{ "strata": { "openBrowser": false } }`.
`STRATA_NO_OPEN` overrides settings with inverted meaning: `1` or `true` disables opening, `0` or `false` enables it.
Any other value, including empty, is invalid.
There is no CLI flag.
Precedence: `STRATA_NO_OPEN`, trusted project settings, user settings, default.
Project settings apply only when Pi trusts the project.
Settings values must be JSON booleans.
An invalid value never falls back to a lower source; the review stays reachable through its URL, and Strata reports the error through its widget and notifications without launching a browser.

## Verification

`mise run //extensions/strata:test`, `mise run //extensions/strata:check`, and `mise run //extensions/strata:e2e`.
Browser tests cover Chromium and Firefox.
For live-provider/TUI validation, run `mise run //extensions/strata:live -- --model PROVIDER/MODEL`, then `/strata` or `/strata --base REF`.
This loads only Strata, disables coding tools, uses existing credentials, and shows the browser URL in the widget.
The full behavior and verification contract is in [SPEC.md](SPEC.md).

## Debug

Opt in through [debug configuration](../DEBUG.md).
Safe events: `session.start`, `session.shutdown`, `review.open.start`, `review.open.finish`, `review.open.error`.