mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-03 14:09:42 +02:00
feat(pi): add Pi (pi.dev) as a sixth CLI run mode (#206)
SessionMode gains 'pi', a first-class backend alongside Claude Code, OpenCode, Codex, Gemini and Antigravity: its own PTY, tmux session, rose tab identity, welcome button, run-mode entry, cron agentType, Docker and remote-SSH command defaults, and clone-repo Brain option. Pi is a different shape of CLI from the other four, and three decisions follow from that: - It has NO permission prompts and no sandbox, so there is no --dangerously-skip-permissions analog and none was invented. The privilege-shaped knob is the tri-state approveProjectTrust, which makes pi load and EXECUTE repo-local .pi/extensions TypeScript and install missing project packages. clampExternalCliBypassForOwner() therefore puts pi in the MATERIALIZE branch: a non-granted multi-user owner gets --no-approve even when no config was sent, because pi's own default is a prompt the session user could answer themselves. That helper had zero test coverage; it now has coverage for all four CLIs. - Only the PI_ prefix joins the env allowlist. Pi's ~34 provider key vars share no prefix and ALLOWED_ENV_PREFIXES is one global list with no mode context, so admitting them would widen the allowlist for every mode at once. Auth goes through pi's /login or the server's own environment. --api-key is deliberately never wired: it would put a provider secret on the spawn command line. - pi stays OUT of isAltScreenStripMode(). Its default TUI renders into the main screen with terminal-owned scrollback, and its 0.84.0 fullscreen mode is runtime-switchable via /settings; that flip was measured to put the pane into the alt screen, which the strip would have corrupted. pi-cli-resolver.ts additionally sanity-probes `pi --version` and requires semver-shaped output, because `pi` is a short generic name a stray binary can shadow; GET /api/pi/status surfaces path and version so a misresolution is diagnosable rather than presenting as a broken mode. Docker installs pi in its own --ignore-scripts step so that flag cannot affect the other four CLIs, and seeds its credentials per-file rather than whole-dir (~/.pi/agent also holds sessions, extensions and package trees). Verified end to end against pi 0.84.1 on an isolated instance: resolver search-dir fallback, flag construction, piConfig persistence across a full server restart, the trust prompt and its --no-approve suppression, the rose Run button on the default daylight-blue skin (the nested skin block eats per-mode gradients unless the rule lives inside it), and the buffer local-echo policy, which pi tolerates where codex did not. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,132 @@
|
||||
/**
|
||||
* First coverage for `clampExternalCliBypassForOwner` (session-routes.ts), the
|
||||
* multi-user §6.3 gate that keeps a NON-GRANTED owner from launching an external
|
||||
* CLI with its safety switches off. It backs both `POST /api/sessions` and
|
||||
* `POST /api/quick-start` and, until pi was added, had no tests at all.
|
||||
*
|
||||
* The helper has two shapes and the difference is the whole point:
|
||||
* - only-if-sent (codex, antigravity): an ABSENT config already spawns safe, so
|
||||
* only a sent config needs its flag forced off.
|
||||
* - MATERIALIZE (gemini, pi): the absent-config default is itself unsafe for a
|
||||
* non-granted owner (gemini's builder defaults to `yolo`; pi's default is an
|
||||
* interactive trust prompt the session user could just answer "yes" to), so
|
||||
* the clamp has to CREATE a config.
|
||||
*/
|
||||
import { afterAll, beforeAll, describe, expect, it } from 'vitest';
|
||||
import { _clampExternalCliBypassForOwner } from '../../src/web/routes/session-routes.js';
|
||||
import { createUser, invalidateUsersCache } from '../../src/user-store.js';
|
||||
|
||||
const PASSWORD = 'clamp-test-password';
|
||||
|
||||
describe('clampExternalCliBypassForOwner — single-user mode', () => {
|
||||
it('passes every config through untouched (the gate is a no-op)', async () => {
|
||||
const out = await _clampExternalCliBypassForOwner(
|
||||
undefined,
|
||||
{ dangerouslyBypassApprovals: true },
|
||||
{ approvalMode: 'yolo' },
|
||||
{ dangerouslySkipPermissions: true },
|
||||
{ approveProjectTrust: true }
|
||||
);
|
||||
expect(out.codexConfig).toEqual({ dangerouslyBypassApprovals: true });
|
||||
expect(out.geminiConfig).toEqual({ approvalMode: 'yolo' });
|
||||
expect(out.antigravityConfig).toEqual({ dangerouslySkipPermissions: true });
|
||||
expect(out.piConfig).toEqual({ approveProjectTrust: true });
|
||||
});
|
||||
|
||||
it('leaves absent configs absent', async () => {
|
||||
const out = await _clampExternalCliBypassForOwner(undefined, undefined, undefined, undefined, undefined);
|
||||
expect(out.codexConfig).toBeUndefined();
|
||||
expect(out.geminiConfig).toBeUndefined();
|
||||
expect(out.antigravityConfig).toBeUndefined();
|
||||
expect(out.piConfig).toBeUndefined();
|
||||
});
|
||||
});
|
||||
|
||||
describe('clampExternalCliBypassForOwner — multi-user mode', () => {
|
||||
// The temp HOME from test/setup.ts is per-FILE, so users.json survives between
|
||||
// tests here — create the three accounts once.
|
||||
beforeAll(async () => {
|
||||
process.env.CODEMAN_MULTIUSER = '1';
|
||||
invalidateUsersCache();
|
||||
await createUser({ username: 'boss', role: 'admin', password: PASSWORD });
|
||||
await createUser({ username: 'peon', role: 'user', password: PASSWORD });
|
||||
await createUser({ username: 'trusted', role: 'user', password: PASSWORD, canBypassPermissions: true });
|
||||
});
|
||||
|
||||
afterAll(() => {
|
||||
delete process.env.CODEMAN_MULTIUSER;
|
||||
invalidateUsersCache();
|
||||
});
|
||||
|
||||
it('passes through for an admin owner', async () => {
|
||||
const out = await _clampExternalCliBypassForOwner(
|
||||
'boss',
|
||||
{ dangerouslyBypassApprovals: true },
|
||||
undefined,
|
||||
{ dangerouslySkipPermissions: true },
|
||||
{ approveProjectTrust: true }
|
||||
);
|
||||
expect(out.codexConfig).toEqual({ dangerouslyBypassApprovals: true });
|
||||
expect(out.geminiConfig).toBeUndefined();
|
||||
expect(out.antigravityConfig).toEqual({ dangerouslySkipPermissions: true });
|
||||
expect(out.piConfig).toEqual({ approveProjectTrust: true });
|
||||
});
|
||||
|
||||
it('passes through for a user holding the bypass grant', async () => {
|
||||
const out = await _clampExternalCliBypassForOwner('trusted', undefined, undefined, undefined, {
|
||||
approveProjectTrust: true,
|
||||
});
|
||||
expect(out.piConfig).toEqual({ approveProjectTrust: true });
|
||||
});
|
||||
|
||||
it('forces codex/antigravity bypass off for a non-granted owner (only-if-sent branch)', async () => {
|
||||
const out = await _clampExternalCliBypassForOwner(
|
||||
'peon',
|
||||
{ dangerouslyBypassApprovals: true, model: 'gpt-5' },
|
||||
undefined,
|
||||
{ dangerouslySkipPermissions: true, model: 'gemini-3-pro' },
|
||||
undefined
|
||||
);
|
||||
expect(out.codexConfig).toEqual({ dangerouslyBypassApprovals: false, model: 'gpt-5' });
|
||||
expect(out.antigravityConfig).toEqual({ dangerouslySkipPermissions: false, model: 'gemini-3-pro' });
|
||||
});
|
||||
|
||||
it('leaves codex/antigravity absent when nothing was sent (they already spawn safe)', async () => {
|
||||
const out = await _clampExternalCliBypassForOwner('peon', undefined, undefined, undefined, undefined);
|
||||
expect(out.codexConfig).toBeUndefined();
|
||||
expect(out.antigravityConfig).toBeUndefined();
|
||||
});
|
||||
|
||||
it('MATERIALIZES gemini to auto_edit even when no config was sent', async () => {
|
||||
const out = await _clampExternalCliBypassForOwner('peon', undefined, undefined, undefined, undefined);
|
||||
expect(out.geminiConfig).toEqual({ approvalMode: 'auto_edit' });
|
||||
});
|
||||
|
||||
it('MATERIALIZES pi to --no-approve even when no config was sent', async () => {
|
||||
// The load-bearing case: omitting --approve is NOT a clamp for pi, because
|
||||
// pi's own default is to ASK, and the session user can answer that prompt.
|
||||
const out = await _clampExternalCliBypassForOwner('peon', undefined, undefined, undefined, undefined);
|
||||
expect(out.piConfig).toEqual({ approveProjectTrust: false });
|
||||
});
|
||||
|
||||
it('forces a sent pi approveProjectTrust:true down to false, keeping other fields', async () => {
|
||||
const out = await _clampExternalCliBypassForOwner('peon', undefined, undefined, undefined, {
|
||||
approveProjectTrust: true,
|
||||
model: 'sonnet:high',
|
||||
provider: 'anthropic',
|
||||
});
|
||||
expect(out.piConfig).toEqual({
|
||||
approveProjectTrust: false,
|
||||
model: 'sonnet:high',
|
||||
provider: 'anthropic',
|
||||
});
|
||||
});
|
||||
|
||||
it('fails closed for an unknown/deleted owner', async () => {
|
||||
const out = await _clampExternalCliBypassForOwner('ghost', undefined, undefined, undefined, {
|
||||
approveProjectTrust: true,
|
||||
});
|
||||
expect(out.piConfig).toEqual({ approveProjectTrust: false });
|
||||
expect(out.geminiConfig).toEqual({ approvalMode: 'auto_edit' });
|
||||
});
|
||||
});
|
||||
@@ -86,6 +86,12 @@ vi.mock('../../src/utils/antigravity-cli-resolver.js', () => ({
|
||||
resolveAntigravityDir: vi.fn(() => null),
|
||||
}));
|
||||
|
||||
vi.mock('../../src/utils/pi-cli-resolver.js', () => ({
|
||||
isPiAvailable: vi.fn(() => false),
|
||||
resolvePiDir: vi.fn(() => null),
|
||||
getPiCliVersion: vi.fn(() => null),
|
||||
}));
|
||||
|
||||
import fs from 'node:fs/promises';
|
||||
import { existsSync, readdirSync } from 'node:fs';
|
||||
import { subagentWatcher } from '../../src/subagent-watcher.js';
|
||||
@@ -93,6 +99,7 @@ import { getLifecycleLog } from '../../src/session-lifecycle-log.js';
|
||||
import { isOpenCodeAvailable, resolveOpenCodeDir } from '../../src/utils/opencode-cli-resolver.js';
|
||||
import { isGeminiAvailable, resolveGeminiDir } from '../../src/utils/gemini-cli-resolver.js';
|
||||
import { isAntigravityAvailable, resolveAntigravityDir } from '../../src/utils/antigravity-cli-resolver.js';
|
||||
import { isPiAvailable, resolvePiDir, getPiCliVersion } from '../../src/utils/pi-cli-resolver.js';
|
||||
|
||||
const mockedReadFile = vi.mocked(fs.readFile);
|
||||
const mockedWriteFile = vi.mocked(fs.writeFile);
|
||||
@@ -106,6 +113,9 @@ const mockedIsGeminiAvailable = vi.mocked(isGeminiAvailable);
|
||||
const mockedResolveGeminiDir = vi.mocked(resolveGeminiDir);
|
||||
const mockedIsAntigravityAvailable = vi.mocked(isAntigravityAvailable);
|
||||
const mockedResolveAntigravityDir = vi.mocked(resolveAntigravityDir);
|
||||
const mockedIsPiAvailable = vi.mocked(isPiAvailable);
|
||||
const mockedResolvePiDir = vi.mocked(resolvePiDir);
|
||||
const mockedGetPiCliVersion = vi.mocked(getPiCliVersion);
|
||||
|
||||
describe('system-routes', () => {
|
||||
let harness: RouteTestHarness;
|
||||
@@ -839,6 +849,38 @@ describe('system-routes', () => {
|
||||
});
|
||||
});
|
||||
|
||||
// ========== GET /api/pi/status ==========
|
||||
|
||||
describe('GET /api/pi/status', () => {
|
||||
it('returns unavailable when pi is not installed', async () => {
|
||||
mockedIsPiAvailable.mockReturnValue(false);
|
||||
mockedResolvePiDir.mockReturnValue(null);
|
||||
mockedGetPiCliVersion.mockReturnValue(null);
|
||||
|
||||
const res = await harness.app.inject({ method: 'GET', url: '/api/pi/status' });
|
||||
expect(res.statusCode).toBe(200);
|
||||
const body = JSON.parse(res.body);
|
||||
expect(body.available).toBe(false);
|
||||
expect(body.path).toBeNull();
|
||||
expect(body.version).toBeNull();
|
||||
});
|
||||
|
||||
it('returns available with path AND version when pi is installed', async () => {
|
||||
// `version` is pi-specific: `pi` is a generic binary name, so the resolver
|
||||
// version-probes it and this endpoint is where a misresolution shows up.
|
||||
mockedIsPiAvailable.mockReturnValue(true);
|
||||
mockedResolvePiDir.mockReturnValue('/home/user/.local/bin');
|
||||
mockedGetPiCliVersion.mockReturnValue('0.84.1');
|
||||
|
||||
const res = await harness.app.inject({ method: 'GET', url: '/api/pi/status' });
|
||||
expect(res.statusCode).toBe(200);
|
||||
const body = JSON.parse(res.body);
|
||||
expect(body.available).toBe(true);
|
||||
expect(body.path).toBe('/home/user/.local/bin');
|
||||
expect(body.version).toBe('0.84.1');
|
||||
});
|
||||
});
|
||||
|
||||
// ========== GET /api/execution/model-config ==========
|
||||
|
||||
describe('GET /api/execution/model-config', () => {
|
||||
|
||||
Reference in New Issue
Block a user