Skip to content

feat(trace): parse Pi coding sessions - #3547

Open
waveywaves wants to merge 1 commit into
chainloop-dev:mainfrom
waveywaves:feat/pi-trace-provider-parser
Open

waveywaves wants to merge 1 commit into
chainloop-dev:mainfrom
waveywaves:feat/pi-trace-provider-parser

Conversation

@waveywaves

@waveywaves waveywaves commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Implements the provider/parser slice of spec issue-3520:

  • copies the hook-reported Pi JSONL through a temporary file and atomically publishes it to Trace state;
  • prevents pre-push from parsing a stale Pi copy after a failed refresh without changing existing-provider fallback behavior;
  • validates Pi JSONL v3, follows the last persisted session-tree branch, and rejects duplicate IDs, cycles, selected orphans, invalid headers, and malformed interior lines;
  • retains valid native and unknown selected entries while excluding Chainloop tree markers;
  • maps deterministic model, token, cost, tool, conversation, timing, warning, and raw-session evidence; and
  • ignores invalid usage values without making the resulting evidence uncraftable.

This PR implements R-006, R-007, and the provider-copy portion of R-005. It intentionally does not register Pi or add extension/hooks/CLI flags; those are the next implementation slice.

Compatibility and safety

  • trace.ErrSessionDataNotFresh is opt-in. Existing providers keep their current behavior of attempting their previous copy after an ordinary refresh error.
  • Pi requires the transcript path reported by its future extension and does not guess from the working directory.
  • Copy and parse errors omit local transcript paths.
  • No control-plane API, protobuf, evidence-schema, provider registry, or CLI changes are included.

Verification

  • env -u CHAINLOOP_TOKEN -u CHAINLOOP_ORGANIZATION go test ./app/cli/...
  • go test -race ./app/cli/internal/trace/pi ./app/cli/pkg/action
  • parsed a live persisted Pi JSONL v3 session with the new provider
  • git diff --check

Refs #3520

AI assistance

pi assisted with implementation and review. The commit carries an Assisted-by: pi trailer.

Review in cubic

@chainloop-platform

chainloop-platform Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

PR validation — ⚠️ 1 failing

Status Policy Material Messages
⚠️ Failed pr-min-approvals pr-info PR/MR #3547 has 0 approving reviews, 1 required.
✅ Passed pr-description-required pr-info -
✅ Passed pr-user-story-linked pr-info -

View attestation ↗

AI Session Checks — ⚠️ no AI session found

Missing AI Coding Sessions

This organization requires every PR to be backed by a Chainloop Trace AI coding session, and none was found for this one.

Please make sure the AI coding session evidence has been sent by the Chainloop CLI, or add the skip-ai-session label to this PR to bypass this check.

Learn more about Chainloop Trace.

Security Checks — ✅ 6 passing

✅ secret-scan

Status Policy Messages
✅ Passed secrets-detection -

✅ sast-scan

Status Policy Messages
✅ Passed owasp-top10-2025 -
✅ Passed sast -
✅ Passed cwe-top25 -
✅ Passed cwe-top26-40-cusp -

✅ iac-scan

Status Policy Messages
✅ Passed iac-misconfiguration -
Scans not applied (2)
Scan Reason
vulnerability-scan no manifest/lockfile changed
github-actions-scan no workflow files changed

View attestation ↗

Security context

This change touches code with 2 recorded security-fix advisories. These are pointers to what past fixes established, not findings in this diff, and they never fail the check.

View in Chainloop ↗ · How this works ↗


Powered by Chainloop and Chainloop Trace

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 11 files

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread app/cli/internal/trace/pi/parse.go Outdated
@waveywaves
waveywaves force-pushed the feat/pi-trace-provider-parser branch 2 times, most recently from 7662966 to c389246 Compare October 7, 2026 18:59
Copy persisted Pi JSONL safely, follow the selected v3 session branch, and map deterministic usage, tools, conversation, and raw evidence.

Implements R-006 and R-007, plus the provider-copy portion of R-005 in Spec 005.

Refs: chainloop-dev#3520

Assisted-by: pi

Signed-off-by: Vibhav Bobade <vibhav.bobde@gmail.com>
@waveywaves
waveywaves force-pushed the feat/pi-trace-provider-parser branch from c389246 to 0c53304 Compare October 8, 2026 06:10
@matiasinsaurralde

Copy link
Copy Markdown
Contributor

Thanks for your contribution, we're looking into expanding testing and evaluations for this feature so we'll come back to your PR soon!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants