Pi 1.0 & Pi Durable: Unkillable Agent Harness Adds MCP Support & Crash Recovery

The article analyzes Pi 1.0 and Pi Durable, a minimalist agent harness framework that now supports MCP via Codemode, introduces virtual model routing, and provides six durability primitives including crash recovery, session forking, and background compression for long-running, multi-user agent applications.

TonyBai
TonyBai
TonyBai
Pi 1.0 & Pi Durable: Unkillable Agent Harness Adds MCP Support & Crash Recovery

Pi 1.0 Release: Seven Features That Stuck

Pi, the harness runtime behind OpenClaw, reached version 1.0 on October 1 (GitHub: ~11.1k stars, 1.4k forks). The team follows a restrained philosophy: only adopt a feature after it proves useful and its complexity cost is justified. The seven features that "stuck to the wall" are:

Codemode : Native MCP support plus support for non-LLM models like Jev and image models.

Virtual model extensions : Extensions can define virtual models that route to multiple real models behind the scenes.

Lazy tool loading : Tools no longer need to be stuffed into context all at once.

Anthropic cache warming : Optimized caching for Anthropic models.

Mid-conversation system messages : Modify prompts and tools while preserving conversation history awareness.

New TUI theme : Refreshed terminal interface.

Default full-screen mode : Improved terminal experience.

Major Reversal: MCP Now Core via Codemode

Pi previously declared "Pi does not support MCP" and criticized it in podcasts and articles. The 1.0 release reverses this stance, explained in a post titled "You Said No MCP!". Three reasons:

MCP evolved : Today's MCP differs from a year ago.

Changes for MCP benefit Pi overall : Supporting MCP required redesigning tool loading (distinguishing tools for models vs. Codemode), which also eased integration of models like Jev.

Shape the standard from inside : MCP's main pain point is poor composability; many servers return text for "dump all tools into context" harnesses. Pi argues MCP should resemble "OpenAPI with intelligent tool discovery" returning structured data.

What Is Codemode?

Harnesses typically execute tools in two places: an untrusted sandbox (bash) or the trusted agent loop environment. Codemode runs in the latter. It lets the agent orchestrate and compose tool calls via JavaScript running in a WASM sandbox. Because it runs on the harness side, its state lives in the session record, not the filesystem. JavaScript was chosen because small JS engines compile to WASM, providing reasonable isolation.

Official Demo: 331 Tool Calls, Zero Context Waste

Task: "Use Jev via Codemode to find the most frustrated commenters on the issue tracker." Pi wrote a script that:

Fetched all open issues from Linear via MCP.

Spawned 4 concurrent workers to read comments, sending each to Jev (a classification model on Cloudflare Workers AI) for sentiment analysis.

Aggregated and sorted results, returning only the final summary.

The process executed 331+ tool calls while none of the intermediate results occupied model context . Outcome: 167 open issues → 156 neutral, 11 mildly frustrated, 0 severely frustrated. Codemode's value: the model writes an orchestration script instead of round-tripping tool calls, saving context and boosting composition ability.

Virtual Models: Opus Plans, GPT Implements

Extensions can define virtual models. Demo: a virtual model router/auto that uses Claude Opus for planning , then Jev decides when to switch to GPT-6 Luna for implementation . After reload and new session, selecting router/auto triggers automatic switching. The /session command shows per-model cost and cache hits.

Why Pi Durable? Extending Beyond Single-User Terminal Agents

Pi's coding agent runs on a (remote) machine, in a terminal, driven by one person. If the process dies, the user sees what happened and continues. Pi 1.0 focuses on that. But Earendil wants to bring the tech to more people and form factors, requiring a harness that:

Runs anywhere.

Reachable via different interfaces.

Supports infinitely long conversations.

Survives catastrophic failures.

Allows multiple people to control the same agents simultaneously.

Instead of forcing Pi to become something it's not, they created Pi Durable — a framework for building any agent application (coding agent is just one). It shares low-level code (pi-ai) and two principles: minimal and malleable. New designs are explored in Pi Durable without disturbing Pi coding agent; validated ideas flow back.

Pi Durable's Six "Undying" Capabilities

1. Run Anywhere, Keep Running

"Anywhere" = any JavaScript runtime. Pi Durable ships Memory, SQLite, and JSONL storage adapters with consistency tests and benchmarks. SQLite and JSONL adapters use no Node APIs ; a small adapter lets them run on Bun or Cloudflare Durable Objects. Only the working set (active conversations, running tasks, pending commits) stays in memory; the rest remains on disk. Because active conversations are bounded by model context windows (compression summarizes old messages before overflow), even conversations with tens of thousands of messages fit comfortably in memory .

2. Crash and Continue

Every step is a task with a checkpoint saved before execution. On restart, a new process opens the same storage, finds unfinished tasks, and resumes from their checkpoints. Detailed rules:

Interrupted model requests : re-sent; partial response retained, marked "aborted".

Interrupted tool calls : if tool declares "replay safe" → re-run; else tell model "call was interrupted" and let model decide.

Queued messages: remain queued. requestId guarantees exactly-once submission : client retries after crash receive the original submission, no duplicate prompts.

Code illustration (simplified):

const job = {
  type: "input",
  content: "Fix the flaky login test",
  requestId: "job-42",
} as const;
await root.submit(job, context);
// process dies during tool call

// new process opens same storage
const harness = await Harness.open(
  await openNodeSqliteStorage("./agent.sqlite"),
  { models, registry, env },
  context,
);
harness.resume(); // continues interrupted run

Tool replay safety declaration:

const searchIssues = defineTool({
  name: "search_issues",
  replay: "safe", // read-only, safe to re-run after crash
  // ...
});

const deploy = defineTool({
  name: "deploy",
  // no replay declared: deployment interrupted → inform model, never auto-replay
  // ...
});

Read operations replay safely; side-effect operations like deploy never auto-replay — a pragmatic production consideration.

3. Multiple Concurrent Conversations with Zero-Copy Forking

A harness runs arbitrary concurrent conversations, each with identical guarantees. Conversations can fork at any point in history without copying ; child sees parent history up to fork point. Example: a Slack channel where an agent answers @mentions. A thread under a reply becomes a fork at that message. Both run concurrently, non-blocking. Thread can have separate permissions (e.g., search-only, no deploy).

4. Extensions, Hooks, Tasks: Everything Pluggable and Durable

An extension is a named collection of system prompt fragments, tools, hooks, and tasks. Each conversation stores only the names of selected extensions/tools. Notable designs:

System prompts rebuilt per request : changes recorded in conversation history at the exact point, so restarts/forks see what the model saw. For models supporting mid-stream prompt changes, only diffs sent → prompt cache stays valid .

Hooks intercept model requests, tool calls, compression. Example: pre-deploy human approval via Slack; answer stored in a "memo" (first write wins). Restart does not re-ask .

Tasks have checkpoints, cross-restart timers, and can await other tasks. Example: multi-card payment split — several cards charged concurrently; if one declines, others auto-abort and refund.

Ownership tree : tasks and conversations form a tree; aborting a task cascades bottom-up, each layer cleaning its own side effects.

Pi Durable has no built-in sub-agent, but a few lines create one: a tool spawns a child conversation with a smaller model and independent instructions; the child inherits crash resilience, independent billing, and appears nested in UI.

5. Compression Without Pausing, Handoffs Searchable

Long conversations often stall for context summarization. Pi Durable makes compression a background task ; conversation continues. When context nears limit, background compression starts; summary inserted at next turn boundary. Only if next request still exceeds limit does it wait for summary. If provider still rejects, harness compresses and retries once . Old messages never leave storage . reset() starts a fresh context with a handoff note plus a history-search tool, yielding an agent that "hands off to itself and retrieves old records when needed".

6. Durable Application State, Hot Reload, Multi-User Collaboration

Documents : typed JSON (todo lists, plans, tickets, sandbox state) stored alongside conversation, changed in same atomic commit → state never diverges from the conversation that produced it.

Hot reload : registry changes at runtime; install same name to replace extension. Running tool calls finish with old code; next call uses new code.

Multi-user : UI consumes only committed state, so any number of clients attach to any conversation. Late joiners get current view then incremental updates. Any client can steer a running conversation; message enqueues after current tool call.

15,000 Lines: Written for Agents to Read

Pi Durable targets ~15k lines (excl. tests) ≈ 150k GPT tokens / 250k Claude tokens worst-case. Storage backend alone is ~3k lines, often skippable. Onboarding: point your agent at packages/durable — let it read README, 30+ examples, two demos, then start building. The vacation planner demo is ~1.3k TypeScript lines, mostly TUI reused from coding agent.

Stability via Supply Chain Hardening & Honest Security Boundaries

Supply chain :

Direct dependencies pinned to exact versions. .npmrc sets min-release-age=2 to avoid same-day releases. package-lock.json is single source of truth; pre-commit hooks block accidental commits.

Published CLI bundles include npm-shrinkwrap.json locking transitive deps.

CI uses npm ci --ignore-scripts plus scheduled npm audit and signature verification.

Community governance : New contributors' issues/PRs auto-closed; maintainers manually review daily.

Security boundaries : Pi has no built-in permission system; runs with launching user/process privileges. For stronger isolation, use external layers — three documented modes:

Gondolin extension : Pi + auth on host; built-in tools and ! commands route to local Linux micro-VM.

Standard Docker : entire Pi process in local container.

OpenShell : entire Pi process in policy-controlled sandbox.

Honest, pragmatic trade-off: no false sense of security; delegate boundaries to specialized isolation layers.

Caveats: Experimental, TypeScript-Only, Details Pending, Minimalism Costs

Pi Durable is experimental : API may change; production use requires caution.

TypeScript only : team says TS is easiest to start; Rust/Assembly rewrite "well known to be easy" but not now.

Some details unpublished : Jev internals, full Codemode design, Slack/GitHub triage bots — promised "in coming weeks".

Minimalism has costs : no permission system, new contributors auto-rejected — evaluate fit for your team.

Two Takeaways for Agent Builders

"Durability" is becoming first-class agent infrastructure : checkpoints, idempotent commits, ownership trees, crash replay per declared safety — classic distributed systems/workflow engine concepts systematically brought into agent world.

"Make the framework readable by the agent itself" is a design principle worth adopting : line count, token count, skippable module boundaries treated as design metrics.

Try It

Install Pi 1.0: curl -fsSL https://pi.dev/install.sh | sh Install Pi Durable (experimental):

npm install @earendil-works/pi-durable @earendil-works/pi-ai @earendil-works/chord

Run demos from source:

npm install && npm build
node packages/coding-agent/src/experimental/durable/main.ts
node packages/coding-agent/src/experimental/vacation/main.ts

Both MIT licensed.

Summary

OpenClaw's buzz may rise and fall, but Pi's trajectory shows two clear patterns: (1) don't chase every weekly hype — throw a feature at the wall, see if it sticks ; (2) when single-user terminal agent isn't enough, spin a new package, keep restraint . Pi 1.0 answers "what does a dependable agent tool look like?"; Pi Durable answers "how to build an agent app that survives the real world?" Whether they become industry standards remains to be seen, but the "validate first, then adopt, stay small" methodology is already worth studying.

Original Source

Signed-in readers can open the original source through BestHub's protected redirect.

Sign in to view source
Republication Notice

This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactadmin@besthub.devand we will review it promptly.

TypeScriptMCPPiCrash RecoveryCheckpointingsupply chain securityAgent HarnessCodemodePi DurableVirtual Models
TonyBai
Written by

TonyBai

Tony Bai's tech world (tonybai.com). Not satisfied with just "knowing how", we strive for mastery. Focused on Go language internals, high-quality engineering practices, and cloud‑native architecture, exploring cutting‑edge intersections of Go and AI. Gophers who pursue technology are welcome—follow me and evolve with Go.

0 followers
Reader feedback

How this landed with the community

Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.