fix(pi): close four mode-list gaps in the pi run mode

Review follow-ups on #282. All four are the same failure shape: a list that
enumerates run modes, missed by the sweep that added 'pi'.

1. Cron ignored pi's project-trust clamp. The PR widened CronJobBaseSchema's
   agentType to accept 'pi' but not the matching clamp beside gemini's, so a
   non-granted multi-user owner's cron pi job spawned bare `pi` (pi's own
   defaultProjectTrust, an interactive prompt they can answer "yes" to, which
   loads and EXECUTES repo-local .pi/extensions TypeScript) while the same
   user's UI/API launch was forced to --no-approve. The clamp is now a pure
   exported helper, clampCronExternalCliConfigs(), so both it and gemini's
   previously untested materialization are pinned.

2. POST /api/sessions/:id/interactive auto-enabled the Ralph tracker for pi:
   its denylist covered opencode/codex/gemini/antigravity only. The tracker is
   never fed for an external CLI (_processExpensiveParsers returns early), so a
   pi session reported ralphEnabled and Ralph UI state no sibling backend shows.

3. REMOTE_CLI_BIN had no pi entry, so buildRemoteCliVersionProbeCommand()
   returned null and Session.cliVersion stayed blank for every remote-SSH pi
   session, even though the PR wired the remote launch command and the
   per-mode override schema field.

4. The desktop home rail's badge map had no pi entry, and its lookup falls back
   to '', which is what claude renders. A pi session read as Claude there while
   the tab strip and phone overview badged it correctly.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Codeman maintainer
2026-08-13 17:23:27 +02:00
parent c5b59633d8
commit f4dcfbe6ca
8 changed files with 105 additions and 12 deletions
+34 -1
View File
@@ -16,7 +16,7 @@ import { describe, it, expect, beforeEach, vi } from 'vitest';
import { existsSync, mkdtempSync, mkdirSync, writeFileSync, symlinkSync } from 'node:fs';
import { tmpdir } from 'node:os';
import { join } from 'node:path';
import { CronService, type CronDeps } from '../src/cron/cron-service.js';
import { CronService, clampCronExternalCliConfigs, type CronDeps } from '../src/cron/cron-service.js';
import { CronJobSchema } from '../src/web/schemas.js';
import { MAX_CRON_JOBS } from '../src/config/map-limits.js';
import type { CronJob, CronJobRun } from '../src/types/cron.js';
@@ -632,3 +632,36 @@ describe('CronService', () => {
});
});
});
/**
* The §6.3 clamp cron applies at FIRE time. Cron sends no per-CLI config, so a
* missing clamp here is not "the default applies" but "the CLI's own unsafe default
* applies", which is the whole reason gemini and pi are materialized rather than
* left absent like codex/antigravity.
*/
describe('clampCronExternalCliConfigs', () => {
it('leaves everything undefined for a granted owner (upstream defaults)', () => {
expect(clampCronExternalCliConfigs('gemini', true)).toEqual({ geminiConfig: undefined, piConfig: undefined });
expect(clampCronExternalCliConfigs('pi', true)).toEqual({ geminiConfig: undefined, piConfig: undefined });
});
it('materializes gemini auto_edit for a non-granted owner (its default is yolo)', () => {
expect(clampCronExternalCliConfigs('gemini', false)).toEqual({
geminiConfig: { approvalMode: 'auto_edit' },
piConfig: undefined,
});
});
it('materializes pi --no-approve for a non-granted owner (its default is an answerable prompt)', () => {
expect(clampCronExternalCliConfigs('pi', false)).toEqual({
geminiConfig: undefined,
piConfig: { approveProjectTrust: false },
});
});
it('clamps nothing for modes whose absent config already spawns safe', () => {
for (const mode of ['claude', 'shell', 'opencode', 'codex', 'antigravity'] as const) {
expect(clampCronExternalCliConfigs(mode, false)).toEqual({ geminiConfig: undefined, piConfig: undefined });
}
});
});
+20
View File
@@ -143,6 +143,26 @@ describe('home sessions column: model', () => {
});
expect(plain.buildHomeSessionRows()[0].modeBadge).toBe('');
});
it('badges every non-claude backend, so a new run mode cannot read as claude here', () => {
// The badge map is a per-mode lookup with a '' fallback, so a mode missing from it
// is indistinguishable from claude in this rail while the tab strip badges it fine.
for (const [mode, badge] of [
['shell', 'sh'],
['opencode', 'oc'],
['codex', 'cx'],
['gemini', 'gm'],
['antigravity', 'ag'],
['pi', 'pi'],
] as const) {
const app = loadHomeSessionsApp({
sessions: sessionMap([{ id: 'a', mode }]),
sessionOrder: ['a'],
cases: CASES,
});
expect(app.buildHomeSessionRows()[0].modeBadge).toBe(badge);
}
});
});
describe('home sessions column: gate', () => {
+10 -1
View File
@@ -2,7 +2,7 @@ import { describe, expect, it } from 'vitest';
import { CreateSessionSchema, QuickStartSchema } from '../src/web/schemas.js';
import { buildSpawnCommand } from '../src/tmux-manager.js';
import { defaultDockerCommandForMode } from '../src/docker-hosts.js';
import { defaultRemoteCommandForMode } from '../src/remote-hosts.js';
import { defaultRemoteCommandForMode, buildRemoteCliVersionProbeCommand } from '../src/remote-hosts.js';
import { isExternalCliMode, isAltScreenStripMode } from '../src/session.js';
describe('Pi mode schemas', () => {
@@ -188,4 +188,13 @@ describe('Pi mode gates', () => {
// same fix as the other remote agent CLIs (see defaultRemoteCommandForMode).
expect(defaultRemoteCommandForMode('pi')).toBe('exec "${SHELL:-/bin/sh}" -i -l -c \'pi\'');
});
it('probes the CLI version on a remote host (REMOTE_CLI_BIN carries pi)', () => {
// Without the REMOTE_CLI_BIN entry this returns null and Session.cliVersion stays
// blank for every remote pi session, which is invisible until someone asks why the
// version column is empty on that host only.
const cmd = buildRemoteCliVersionProbeCommand({ username: 'dev', host: 'box.example', port: 22 }, 'pi');
expect(cmd).not.toBeNull();
expect(cmd).toContain('pi --version');
});
});