refactor(cli-registry): make CLI backends data instead of per-mode branching

Every run mode is now a `CliEntry` in `src/config/cli-registry/` — discovery
(search dirs, version + identity probes), the launch argv template, env
handling, the `capabilities` flags that replace per-CLI branching, and the
`overlays` that back the remote/docker pane commands. Code that used to ask
"which CLI is this?" reads the entry instead.

Behaviour is unchanged. `test/cli-registry-spawn-golden.test.ts` pins every
spawn command as a literal string, captured from the hand-written builders
before they were deleted, and `test/location-overlay-commands.test.ts` does the
same for all 20 remote and in-container pane commands.

Config can never contain shell text: an entry declares typed argv tokens,
literals are validated against a safe-word pattern at LOAD time (a bad literal
rejects the whole entry — a silently dropped `--no-approve` is not cosmetic),
and values resolve through patterns NAMED in code, so a user `clis.json` cannot
widen its own validation. `~/.codeman/clis.json` overrides any entry, read-only
in this release.

OMP is included as a registry entry rather than a tenth hand-written builder,
so `buildOmpCommand()`, the omp availability pre-flight, the omp arm of
`buildPathExport()` and the omp entries in the truecolor/NO_COLOR, alt-screen
and doctor ladders all drop out.

Guard rails:

- `test/cli-registry-no-id-branching.test.ts` fails the build if per-CLI-id
  branching reappears outside `stock.ts`, in any of its four shapes (`===`,
  `!==`, `switch`/`case`, `includes`) — an `===`-only version would miss the
  negated forms, which is how 36 of them survived an earlier pass. Every
  allowlisted branch carries its reason.
- `external`, `hooks` and `altScreen` stay three INDEPENDENT capabilities;
  deriving one from another shipped the `until=stop`-hangs-on-shell bug.
- `param` is two namespaces. `launch.params` keys, `configSetenv.fromParam` and
  `privilegedParams[].param` all name a LAUNCH param; the legacy `<Mode>Config`
  wire field is separate, bridged only by `legacyConfigAliases`. Getting
  `privilegedParams[].param` wrong is SILENT — it is the multi-user bypass
  clamp's only handle on a CLI's privilege switch, and a wrong name clamps
  nothing with no error and no failing test — so `schema.ts` rejects an entry
  naming a param it never declared.
- Registry data resolves AT CALL TIME (`sessionModeSchema()`,
  `allowedEnvPrefixes()`, `dependencyRegistry()`, the resolvers' `searchDirs`
  thunks). A module-level const freezes at first import, so a CLI enabled while
  the server ran moved the run menu but not that surface.
- Six fields are annotated DECLARED-FOR-LATER and read by nothing
  (`shortBadge`, `accent`, `capabilities.echo`/`wheelForward`/
  `keyboardAccessory`/`maxFrameBytes`): all frontend behaviour, transcribed
  rather than measured. A test pins the list so it cannot quietly grow.

Three user-visible changes, all deliberate and named:

- `probeDockerCliVersion()` derives the in-container binary from the registry
  rather than assuming it equals the mode name (`antigravity` runs `agy`).
- The remote CLI version probe now covers grok and deepseek, which the
  hardcoded map it replaces omitted while its own comment said the rule was
  "every mode except shell".
- `codeman doctor`'s CLI rows are generated from the entries, so Claude's
  install hint is the install command rather than a docs URL, five CLIs gain
  hints they never had, and the row order follows the catalog.

Also hardened along the way: `sessionModeSchema()` is bounded at 24 chars
(matching the `cliId` pattern) before its failure message quotes the value
back, and `deepMerge` skips `__proto__`/`constructor`/`prototype` when reading
the hand-editable `clis.json`.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WQkoi1cNegqVwZHgzx5SbJ
This commit is contained in:
Devvyn
2026-09-02 08:26:45 +08:00
co-authored by Claude Opus 5
parent 71ffbf18e4
commit 4830e662f9
45 changed files with 5772 additions and 1478 deletions
+48 -16
View File
@@ -1,5 +1,5 @@
import { describe, it, expect } from 'vitest';
import { DEPENDENCY_REGISTRY } from '../src/config/dependency-registry.js';
import { dependencyRegistry } from '../src/config/dependency-registry.js';
import {
detectEnvironment,
extractVersion,
@@ -11,41 +11,73 @@ import {
import type { ProbeHost } from '../src/utils/dependency-checker.js';
import type { ProbeEnvironment, ToolDependency } from '../src/config/dependency-registry.js';
import { PI_VERSION_REGEX } from '../src/utils/pi-cli-resolver.js';
import { GROK_VERSION_REGEX } from '../src/utils/grok-cli-resolver.js';
import { DEEPSEEK_VERSION_REGEX } from '../src/utils/deepseek-cli-resolver.js';
import { enabledClis } from '../src/config/cli-registry/registry.js';
describe('DEPENDENCY_REGISTRY', () => {
describe('dependencyRegistry()', () => {
it('has unique ids', () => {
const ids = DEPENDENCY_REGISTRY.map((t) => t.id);
const ids = dependencyRegistry().map((t) => t.id);
expect(new Set(ids).size).toBe(ids.length);
});
it('hard-requires only node and tmux; agent CLIs and office are optional', () => {
const required = DEPENDENCY_REGISTRY.filter((t) => t.required)
const required = dependencyRegistry()
.filter((t) => t.required)
.map((t) => t.id)
.sort();
expect(required).toEqual(['node', 'tmux']);
// all agent CLIs are optional (Codeman runs any of them)
const agentClis = ['claude', 'opencode', 'codex'];
expect(DEPENDENCY_REGISTRY.filter((t) => agentClis.includes(t.id)).every((t) => t.required === false)).toBe(true);
const office = DEPENDENCY_REGISTRY.filter((t) => t.category === 'office');
expect(
dependencyRegistry()
.filter((t) => agentClis.includes(t.id))
.every((t) => t.required === false)
).toBe(true);
const office = dependencyRegistry().filter((t) => t.category === 'office');
expect(office.every((t) => t.required === false)).toBe(true);
});
it('resolves pi through the SAME version rule the run mode uses', () => {
// `pi` is a short generic name, so pi-cli-resolver.ts refuses a binary that does not
// print semver. If the doctor did not apply the identical rule it would report
// "Pi CLI ✓" on a box where Run Pi stays hidden, which reads as a broken mode
// rather than a missing install. One regex, shared, is what keeps them agreeing.
const pi = DEPENDENCY_REGISTRY.find((t) => t.id === 'pi');
expect(pi).toBeDefined();
const spec = pi!.resolvers.find((r) => r.resolver.kind === 'path');
it.each([
['pi', PI_VERSION_REGEX],
['grok', GROK_VERSION_REGEX],
['dsh', DEEPSEEK_VERSION_REGEX],
])('resolves %s through the SAME version rule the run mode uses', (id, expected) => {
// These three have short, generic or squatted binary names, so their resolvers refuse a
// binary that does not print the right shape of version. If the doctor did not apply the
// identical rule it would report "Pi CLI ✓" on a box where Run Pi stays hidden, which
// reads as a broken mode rather than a missing install.
//
// Both sides now read one registry entry, so they cannot drift — but the assertion
// compares SOURCE rather than object identity, because the doctor compiles the entry's
// serialized pattern through compileVersionRegex()'s ReDoS guard rather than importing
// the resolver's own RegExp object.
const tool = dependencyRegistry().find((t) => t.id === id);
expect(tool).toBeDefined();
const spec = tool!.resolvers.find((r) => r.resolver.kind === 'path');
expect(spec).toBeDefined();
const resolver = spec!.resolver as { versionRegex?: RegExp; requireVersionMatch?: boolean };
expect(resolver.requireVersionMatch).toBe(true);
expect(resolver.versionRegex).toBe(PI_VERSION_REGEX);
expect(resolver.versionRegex?.source).toBe(expected.source);
});
it('keeps a doctor row for every CLI that has a binary to probe', () => {
// An earlier draft of the registry refactor silently dropped the grok and dsh rows, so
// `codeman doctor` stopped reporting two shipped CLIs entirely. Derive the expectation
// from the registry so this cannot pass by being updated to match a shrunken table.
const probeable = enabledClis().filter((c) => c.discovery.binaries.length > 0);
expect(probeable.length).toBeGreaterThanOrEqual(8);
for (const cli of probeable) {
const bin = cli.discovery.binaries[0];
const row = dependencyRegistry().find((t) =>
t.resolvers.some((r) => r.resolver.kind === 'path' && r.resolver.bins.includes(bin))
);
expect(row, `no codeman doctor row probes ${bin} (for CLI "${cli.id as string}")`).toBeDefined();
}
});
it('gives msoffice a windows-side resolver scoped to wsl + win32 only', () => {
const ms = DEPENDENCY_REGISTRY.find((t) => t.id === 'msoffice');
const ms = dependencyRegistry().find((t) => t.id === 'msoffice');
expect(ms).toBeDefined();
const spec = ms!.resolvers.find((r) => r.resolver.kind === 'windows-side');
expect(spec).toBeDefined();