feat(pi): add Pi (pi.dev) as a sixth CLI run mode (#206)

SessionMode gains 'pi', a first-class backend alongside Claude Code,
OpenCode, Codex, Gemini and Antigravity: its own PTY, tmux session, rose
tab identity, welcome button, run-mode entry, cron agentType, Docker and
remote-SSH command defaults, and clone-repo Brain option.

Pi is a different shape of CLI from the other four, and three decisions
follow from that:

- It has NO permission prompts and no sandbox, so there is no
  --dangerously-skip-permissions analog and none was invented. The
  privilege-shaped knob is the tri-state approveProjectTrust, which makes
  pi load and EXECUTE repo-local .pi/extensions TypeScript and install
  missing project packages. clampExternalCliBypassForOwner() therefore
  puts pi in the MATERIALIZE branch: a non-granted multi-user owner gets
  --no-approve even when no config was sent, because pi's own default is
  a prompt the session user could answer themselves. That helper had zero
  test coverage; it now has coverage for all four CLIs.
- Only the PI_ prefix joins the env allowlist. Pi's ~34 provider key vars
  share no prefix and ALLOWED_ENV_PREFIXES is one global list with no mode
  context, so admitting them would widen the allowlist for every mode at
  once. Auth goes through pi's /login or the server's own environment.
  --api-key is deliberately never wired: it would put a provider secret on
  the spawn command line.
- pi stays OUT of isAltScreenStripMode(). Its default TUI renders into the
  main screen with terminal-owned scrollback, and its 0.84.0 fullscreen
  mode is runtime-switchable via /settings; that flip was measured to put
  the pane into the alt screen, which the strip would have corrupted.

pi-cli-resolver.ts additionally sanity-probes `pi --version` and requires
semver-shaped output, because `pi` is a short generic name a stray binary
can shadow; GET /api/pi/status surfaces path and version so a
misresolution is diagnosable rather than presenting as a broken mode.

Docker installs pi in its own --ignore-scripts step so that flag cannot
affect the other four CLIs, and seeds its credentials per-file rather than
whole-dir (~/.pi/agent also holds sessions, extensions and package trees).

Verified end to end against pi 0.84.1 on an isolated instance: resolver
search-dir fallback, flag construction, piConfig persistence across a full
server restart, the trust prompt and its --no-approve suppression, the
rose Run button on the default daylight-blue skin (the nested skin block
eats per-mode gradients unless the rule lives inside it), and the buffer
local-echo policy, which pi tolerates where codex did not.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Codeman maintainer
2026-08-13 13:54:47 +02:00
parent f39beb3326
commit c5b59633d8
45 changed files with 2143 additions and 101 deletions
+191
View File
@@ -0,0 +1,191 @@
import { describe, expect, it } from 'vitest';
import { CreateSessionSchema, QuickStartSchema } from '../src/web/schemas.js';
import { buildSpawnCommand } from '../src/tmux-manager.js';
import { defaultDockerCommandForMode } from '../src/docker-hosts.js';
import { defaultRemoteCommandForMode } from '../src/remote-hosts.js';
import { isExternalCliMode, isAltScreenStripMode } from '../src/session.js';
describe('Pi mode schemas', () => {
it('accepts Pi session creation config', () => {
const parsed = CreateSessionSchema.parse({
workingDir: '/tmp',
mode: 'pi',
piConfig: {
model: 'sonnet:high',
provider: 'anthropic',
thinking: 'high',
},
});
expect(parsed.mode).toBe('pi');
expect(parsed.piConfig).toEqual({
model: 'sonnet:high',
provider: 'anthropic',
thinking: 'high',
});
});
it('accepts Pi quick-start config', () => {
const parsed = QuickStartSchema.parse({
caseName: 'pi-case',
mode: 'pi',
piConfig: { resumeSessionId: '0f9c2b14-aa10', continueSession: true },
});
expect(parsed.mode).toBe('pi');
expect(parsed.piConfig?.resumeSessionId).toBe('0f9c2b14-aa10');
});
it('accepts a provider-qualified model (`openai/gpt-4o`)', () => {
const parsed = CreateSessionSchema.parse({
workingDir: '/tmp',
mode: 'pi',
piConfig: { model: 'openai/gpt-4o' },
});
expect(parsed.piConfig?.model).toBe('openai/gpt-4o');
});
it('rejects unsafe Pi model strings', () => {
expect(() =>
CreateSessionSchema.parse({
workingDir: '/tmp',
mode: 'pi',
piConfig: { model: 'pi; rm -rf /' },
})
).toThrow();
});
it('rejects unsafe Pi provider strings', () => {
expect(() =>
CreateSessionSchema.parse({
workingDir: '/tmp',
mode: 'pi',
piConfig: { provider: 'anthropic`whoami`' },
})
).toThrow();
});
it('rejects unsafe Pi resumeSessionId values (ids only, never paths)', () => {
expect(() =>
CreateSessionSchema.parse({
workingDir: '/tmp',
mode: 'pi',
piConfig: { resumeSessionId: '../../etc/passwd' },
})
).toThrow();
});
it('rejects thinking levels outside pi’s enum', () => {
expect(() =>
CreateSessionSchema.parse({
workingDir: '/tmp',
mode: 'pi',
piConfig: { thinking: 'ultra' },
})
).toThrow();
});
it('allows PI_* env overrides but NOT bare provider keys', () => {
const parsed = CreateSessionSchema.parse({
workingDir: '/tmp',
mode: 'pi',
envOverrides: { PI_OFFLINE: '1' },
});
expect(parsed.envOverrides).toEqual({ PI_OFFLINE: '1' });
// Pi's ~34 provider key vars share no prefix, and ALLOWED_ENV_PREFIXES is a single
// GLOBAL list with no mode context — allowlisting them for pi would widen the
// allowlist for every mode at once. They stay out; auth goes through pi's /login.
expect(() =>
CreateSessionSchema.parse({
workingDir: '/tmp',
mode: 'pi',
envOverrides: { ANTHROPIC_API_KEY: 'sk-test' },
})
).toThrow();
});
});
describe('Pi spawn command', () => {
it('builds a bare pi command when no config is sent (pi has no permission prompts)', () => {
const cmd = buildSpawnCommand({ mode: 'pi', sessionId: 'abc12345' });
expect(cmd).toBe('pi');
});
it('maps model/provider/thinking to flags', () => {
const cmd = buildSpawnCommand({
mode: 'pi',
sessionId: 'abc12345',
piConfig: { model: 'sonnet:high', provider: 'anthropic', thinking: 'xhigh' },
});
expect(cmd).toBe('pi --model sonnet:high --provider anthropic --thinking xhigh');
});
it('emits --approve for true and --no-approve for false (tri-state project trust)', () => {
expect(buildSpawnCommand({ mode: 'pi', sessionId: 'a', piConfig: { approveProjectTrust: true } })).toBe(
'pi --approve'
);
expect(buildSpawnCommand({ mode: 'pi', sessionId: 'a', piConfig: { approveProjectTrust: false } })).toBe(
'pi --no-approve'
);
// Absent = pi's own defaultProjectTrust; Codeman must not decide it.
expect(buildSpawnCommand({ mode: 'pi', sessionId: 'a', piConfig: {} })).toBe('pi');
});
it('passes --session for resume and skips -c when both are present', () => {
expect(buildSpawnCommand({ mode: 'pi', sessionId: 'a', piConfig: { resumeSessionId: '0f9c2b14' } })).toBe(
'pi --session 0f9c2b14'
);
expect(buildSpawnCommand({ mode: 'pi', sessionId: 'a', piConfig: { continueSession: true } })).toBe('pi -c');
// The two conflict upstream: a valid explicit session id wins.
expect(
buildSpawnCommand({
mode: 'pi',
sessionId: 'a',
piConfig: { continueSession: true, resumeSessionId: '0f9c2b14' },
})
).toBe('pi --session 0f9c2b14');
});
it('drops unsafe values rather than escaping them (the result lands in `bash -c "..."`)', () => {
expect(buildSpawnCommand({ mode: 'pi', sessionId: 'a', piConfig: { model: 'a`b' } })).toBe('pi');
expect(buildSpawnCommand({ mode: 'pi', sessionId: 'a', piConfig: { provider: 'x;id' } })).toBe('pi');
expect(buildSpawnCommand({ mode: 'pi', sessionId: 'a', piConfig: { resumeSessionId: 'x; rm -rf /' } })).toBe('pi');
// An out-of-enum thinking level never reaches the command line either.
expect(
buildSpawnCommand({
mode: 'pi',
sessionId: 'a',
piConfig: { thinking: 'ultra' as unknown as 'high' },
})
).toBe('pi');
});
it('never emits --api-key (a provider secret must not reach the spawn line)', () => {
const cmd = buildSpawnCommand({
mode: 'pi',
sessionId: 'a',
piConfig: { model: 'sonnet', provider: 'anthropic', approveProjectTrust: true },
});
expect(cmd).not.toContain('--api-key');
});
});
describe('Pi mode gates', () => {
it('is an external CLI mode (readiness/ralph/respawn gating)', () => {
expect(isExternalCliMode('pi')).toBe(true);
});
it('is NOT an alt-screen strip mode (main-screen TUI + runtime-switchable fullscreen)', () => {
expect(isAltScreenStripMode('pi')).toBe(false);
});
it('has docker/remote default commands', () => {
expect(defaultDockerCommandForMode('pi')).toBe('exec pi');
// Routed through an interactive login shell so npm's global bin resolves —
// same fix as the other remote agent CLIs (see defaultRemoteCommandForMode).
expect(defaultRemoteCommandForMode('pi')).toBe('exec "${SHELL:-/bin/sh}" -i -l -c \'pi\'');
});
});