mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-05 23:19:43 +02:00
fix(statusline): inject plan-usage telemetry via ephemeral CLI flag, never disk
Codeman's plan-usage chip wrote a statusLine.command into the case's
.claude/settings.local.json to receive Claude Code's rate_limits blob.
That file-based statusLine took precedence over the user's own
global/project statusline for ANY `claude` run in that directory,
including entirely outside Codeman, with no disclosure in the App
Settings UI (labeled only as a header-display toggle) and no way to
remove it once written (the removal code path was unreachable dead
code — nothing ever called it with false).
Replace the disk write with an EPHEMERAL `claude --settings
'{"statusLine":{...}}'` CLI flag, resolved fresh at spawn time
(resolveStatusLineCliCommand in hooks-config.ts) and merged with
effort/ultracode into one --settings object (buildClaudeSettingsFlag
in tmux-manager.ts, since Claude Code accepts only one --settings
flag). Never touches disk, so a plain `claude` run outside Codeman is
untouched. Self-healing: any legacy disk-written exporter from an
older build is stripped the first time a session starts in that
workspace again. Still respects a user's own hand-authored statusLine
(skips the flag entirely rather than overriding it).
Mid-fix bug found and fixed: the exporter's command legitimately
depends on $CODEMAN_SESSION_ID/$CODEMAN_API_URL/$CODEMAN_HOOK_SECRET_FILE
and an internal $INPUT, all meant to be expanded only when Claude Code
itself executes the statusline, using the pane's tmux-setenv'd
environment. Passing that text through --settings routed it through
execSync's own implicit /bin/sh -c first (tmux respawn-pane's
`bash -c "..."` wrapper) — POSIX double quotes don't suppress $
expansion, so those vars got expanded prematurely against the
server's own environment (unset there), producing malformed JSON that
printed as literal error text in the statusline. Fixed by writing the
exporter as a real, shared script file (ensureStatusLineExporterScript,
marker-versioned so stale copies self-heal) and passing only its bare
path via --settings — nothing for any intermediate shell to mangle.
Verified against a real Claude CLI on an isolated tmux socket, and via
direct execSync reproduction of the exact nested wrapping
createSession/respawnPane use.
A hard "never inject, even ephemerally" kill-switch was added and then
removed in the same pass: with the disk-leak fixed, disabling
injection only cost the plan-usage telemetry the feature exists to
provide, for no remaining benefit.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015GyMnFWnUzc41TDeHg9juW
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
a164c07f92
commit
d4aa3c8cca
+110
-1
@@ -31,7 +31,7 @@
|
||||
|
||||
import { randomBytes } from 'node:crypto';
|
||||
import { existsSync } from 'node:fs';
|
||||
import { readFile, writeFile, mkdir, lstat, readdir, realpath, rename, unlink, rmdir } from 'node:fs/promises';
|
||||
import { readFile, writeFile, mkdir, lstat, readdir, realpath, rename, unlink, rmdir, chmod } from 'node:fs/promises';
|
||||
import { homedir } from 'node:os';
|
||||
import { join, dirname } from 'node:path';
|
||||
import { fileURLToPath } from 'node:url';
|
||||
@@ -906,6 +906,115 @@ export async function applyStatusLineConfig(casePath: string, enabled: boolean):
|
||||
});
|
||||
}
|
||||
|
||||
/**
|
||||
* Version-agnostic marker embedded as a comment in the generated exporter
|
||||
* SCRIPT (see ensureStatusLineExporterScript) — bump the numeric suffix
|
||||
* whenever the script content changes so `ensureStatusLineExporterScript`'s
|
||||
* content comparison rewrites stale copies on next use.
|
||||
*/
|
||||
const STATUSLINE_EXPORTER_SCRIPT_MARKER = 'CODEMAN_STATUSLINE_EXPORTER_V1';
|
||||
|
||||
function statusLineExporterScriptContent(): string {
|
||||
// Byte-identical logic to generateStatusLineCommand(), just as a real file
|
||||
// instead of an inline string — see ensureStatusLineExporterScript for why
|
||||
// that distinction matters (it is NOT cosmetic).
|
||||
return (
|
||||
`#!/bin/sh\n` +
|
||||
`# ${STATUSLINE_EXPORTER_SCRIPT_MARKER} — auto-generated by Codeman; safe to delete, regenerated on demand.\n` +
|
||||
`INPUT=$(cat 2>/dev/null || echo '{}')\n` +
|
||||
`printf '{"sessionId":"%s","data":%s}' "$CODEMAN_SESSION_ID" "$INPUT" | ` +
|
||||
`curl -sk -X POST "$CODEMAN_API_URL${STATUSLINE_MARKER}" ` +
|
||||
`-H 'Content-Type: application/json' ` +
|
||||
`-H "X-Codeman-Hook-Secret: $(cat "$CODEMAN_HOOK_SECRET_FILE" 2>/dev/null)" ` +
|
||||
`--data @- 2>/dev/null || echo codeman\n`
|
||||
);
|
||||
}
|
||||
|
||||
/**
|
||||
* Write (or refresh) the SHARED, single exporter script every claude session
|
||||
* points its ephemeral --settings statusLine flag at, and return its absolute
|
||||
* path. Idempotent: only rewrites when the marker-versioned content differs.
|
||||
*
|
||||
* This is the fix for a real bug found live 2026-08-31: the exporter's
|
||||
* command string legitimately depends on `$CODEMAN_SESSION_ID`,
|
||||
* `$CODEMAN_API_URL`, `$CODEMAN_HOOK_SECRET_FILE`, and its own internal
|
||||
* `$INPUT` — all meant to be expanded ONLY when Claude Code itself finally
|
||||
* executes the statusLine command, using the PANE's tmux-setenv'd
|
||||
* environment. Passing that command as literal TEXT through
|
||||
* `--settings '...'` routes it through this server's OWN spawn-time shell
|
||||
* layers first (tmux respawn-pane's `bash -c "..."`, itself invoked via
|
||||
* execSync's implicit `/bin/sh -c`) — and POSIX double quotes do NOT
|
||||
* suppress `$` expansion, so those vars got expanded there and then, against
|
||||
* the SERVER process's environment (where they are unset), producing a
|
||||
* mangled curl call that posted malformed JSON and printed the server's raw
|
||||
* error response as the statusline text itself. A bare file PATH has no `$`,
|
||||
* quotes, or pipes for any of those intermediate shells to mangle — the
|
||||
* script's own content (containing the real `$VAR`s) is never touched by a
|
||||
* shell until Claude Code executes the file itself, at which point the
|
||||
* pane's real environment is in scope. This mirrors the existing #208 fix in
|
||||
* tmux-manager.ts (never embed a literal `$SHELL` meant for later
|
||||
* expansion — resolve it, or in this case reference a file, instead).
|
||||
*/
|
||||
export async function ensureStatusLineExporterScript(): Promise<string> {
|
||||
const scriptPath = dataPath('statusline-exporter.sh');
|
||||
const desired = statusLineExporterScriptContent();
|
||||
let current: string | null = null;
|
||||
try {
|
||||
current = await readFile(scriptPath, 'utf-8');
|
||||
} catch {
|
||||
// Doesn't exist yet.
|
||||
}
|
||||
if (current !== desired) {
|
||||
await writeFile(scriptPath, desired);
|
||||
await chmod(scriptPath, 0o755);
|
||||
}
|
||||
return scriptPath;
|
||||
}
|
||||
|
||||
/**
|
||||
* Resolve the statusLine command to pass as an EPHEMERAL `claude --settings`
|
||||
* CLI flag for this one process (see buildClaudeSettingsFlag in
|
||||
* tmux-manager.ts) — never written to disk. This supersedes the old
|
||||
* applyStatusLineConfig(path, true) disk-write: a file-based statusLine
|
||||
* leaked into any plain `claude` run in that directory outside Codeman
|
||||
* entirely (it took precedence over the user's own global/project
|
||||
* statusline with no disclosure and no way to remove it — found live
|
||||
* 2026-08-31).
|
||||
*
|
||||
* Also self-heals: if an OLDER Codeman build already wrote its marked
|
||||
* exporter into this workspace's settings.local.json, it is stripped here
|
||||
* (isOurs-guarded, same as applyStatusLineConfig's removal branch) so every
|
||||
* workspace migrates off the disk-based mechanism the first time a session
|
||||
* starts there again — no manual cleanup required.
|
||||
*
|
||||
* Returns undefined when telemetry wasn't requested, or when the workspace
|
||||
* already has its OWN hand-configured statusLine (never override a real one).
|
||||
*/
|
||||
export async function resolveStatusLineCliCommand(
|
||||
casePath: string,
|
||||
telemetryRequested: boolean
|
||||
): Promise<string | undefined> {
|
||||
const settingsPath = join(casePath, '.claude', 'settings.local.json');
|
||||
let userHasOwnStatusLine = false;
|
||||
if (existsSync(settingsPath)) {
|
||||
try {
|
||||
const existing = JSON.parse(await readFile(settingsPath, 'utf-8'));
|
||||
const current = existing.statusLine as { command?: unknown } | undefined;
|
||||
if (current && typeof current.command === 'string') {
|
||||
if (current.command.includes(STATUSLINE_MARKER)) {
|
||||
await applyStatusLineConfig(casePath, false); // strip legacy disk-written exporter
|
||||
} else {
|
||||
userHasOwnStatusLine = true;
|
||||
}
|
||||
}
|
||||
} catch {
|
||||
// Malformed — leave it alone, same guard applyStatusLineConfig itself uses.
|
||||
}
|
||||
}
|
||||
if (!telemetryRequested || userHasOwnStatusLine) return undefined;
|
||||
return ensureStatusLineExporterScript();
|
||||
}
|
||||
|
||||
// ─── Agent skill injection ───────────────────────────────────────────────────
|
||||
|
||||
/**
|
||||
|
||||
Reference in New Issue
Block a user