Skip to content

fix: eliminate inline system prompts — all prompts via temp files (#568) - #569

Merged
namastex888 merged 2 commits into
devfrom
fix/leader-spawn
Mar 15, 2026
Merged

namastex888 merged 2 commits into
devfrom
fix/leader-spawn

Conversation

@namastex888

Copy link
Copy Markdown
Contributor

Summary

Kills inline --append-system-prompt / --system-prompt flags entirely. ALL system prompts now go through --append-system-prompt-file / --system-prompt-file using temp files at /tmp/genie-prompts/.

Fixes #568 — leader pane crashing because 2850-char multi-line prompt with bash code blocks was corrupted by shell escaping + tmux send-keys.

Root Cause

buildClaudeCommand() passed built-in agent prompts inline via escapeShellArg() which wraps in single quotes. Multi-line prompts with nested quotes, backticks, and $() patterns get double-escaped through tmux send-keys, corrupting the command and crashing Claude Code on startup.

Fix

One code path: when systemPrompt is set, write to /tmp/genie-prompts/<role>-<timestamp>.md and use --append-system-prompt-file. If there are additional prompt files (leader's wish context), merge into one file.

Test plan

  • bun run typecheck passes
  • 721 tests pass
  • No inline --append-system-prompt or --system-prompt in codebase
  • E2E: genie team create --wish → leader stays alive

…rompts

Inline --append-system-prompt and --system-prompt flags broke when passed
through tmux send-keys with multi-line prompts containing code blocks.
All system prompts are now written to temp files at /tmp/genie-prompts/
and passed via --append-system-prompt-file or --system-prompt-file.

When both systemPrompt and systemPromptFile are set, they are merged into
a single temp file. Extra --append-system-prompt-file args are also merged.

Closes #568
@coderabbitai

coderabbitai Bot commented Mar 15, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 8c73c384-db66-49fc-9cdb-2f47b6dc052c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/leader-spawn
📝 Coding Plan
  • Generate coding plan for human review comments

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request significantly enhances the robustness of system prompt handling by moving away from inline arguments to a temporary file-based approach. This change directly addresses and resolves a critical issue where complex, multi-line prompts with special characters were being corrupted by shell escaping mechanisms, leading to application crashes. By centralizing prompt content into temporary files, the system ensures reliable and consistent delivery of prompts, improving overall stability and agent performance, especially for those utilizing rich, code-block-heavy instructions.

Highlights

  • Elimination of Inline System Prompts: Direct inline system prompts (--append-system-prompt, --system-prompt) have been entirely removed to prevent shell escaping issues with complex prompt content.
  • Transition to Temporary Files for All System Prompts: All system prompts are now written to temporary files in /tmp/genie-prompts/ and passed using file-based flags (--append-system-prompt-file, --system-prompt-file).
  • Prompt Merging Logic: Introduced functionality to merge systemPrompt content with existing systemPromptFile content, and any extraArgs containing append-system-prompt-file, into a single temporary file before being passed.
  • Fix for Leader Pane Crashing: Resolved a critical bug where the leader pane would crash due to corrupted multi-line prompts containing special characters when passed via tmux send-keys.
Changelog
  • src/genie-commands/setup.ts
    • Updated CLI output messages to reflect the transition from inline prompt flags to file-based prompt flags.
  • src/lib/provider-adapters.test.ts
    • Modified a test description to accurately reflect that prompt file flags are not included when neither systemPromptFile nor systemPrompt is set.
    • Added new tests to verify that systemPrompt content is correctly written to a temporary file and passed using --append-system-prompt-file.
    • Included tests to confirm that systemPrompt with promptMode: 'system' uses --system-prompt-file.
    • Added tests to explicitly ensure that inline --system-prompt or --append-system-prompt flags are never emitted.
    • Verified fallback role naming for temporary prompt files when no specific role is provided.
    • Added a test to confirm the merging of systemPromptFile and systemPrompt content into a single temporary file.
  • src/lib/provider-adapters.ts
    • Updated the JSDoc for systemPrompt in the SpawnParams interface to indicate that it is now written to a temporary file.
    • Refactored the buildClaudeCommand function to prioritize systemPrompt handling: if systemPrompt is present, it creates a temporary file, merges content from systemPromptFile and extraArgs if applicable, and then uses the appropriate file-based flag (--system-prompt-file or --append-system-prompt-file).
    • Removed the direct handling of systemPrompt as an inline argument.
  • src/types/genie-config.ts
    • Updated the comment for the promptMode configuration option to reference the new file-based prompt flags (--system-prompt-file and --append-system-prompt-file).
Activity
  • Author confirmed bun run typecheck passes.
  • Author confirmed 721 tests pass.
  • Author confirmed no inline --append-system-prompt or --system-prompt flags remain in the codebase.
  • E2E test for genie team create --wish to ensure leader stays alive is pending.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request successfully addresses a critical shell escaping issue by switching from inline system prompts to temporary files. The implementation is a solid step forward. However, I've identified a few areas for improvement. There's a resource leak as temporary files are not cleaned up, a bug in parsing multiple prompt file arguments, and some minor deviations from best practices regarding code style and test hygiene. My review includes specific suggestions to address these points and enhance the robustness and maintainability of the code.

Comment on lines +235 to 266
if (params.systemPrompt) {
// Write built-in prompt to temp file — avoids shell escaping of complex content
const { mkdirSync, writeFileSync, readFileSync } = require('node:fs');
const { join } = require('node:path');
const dir = '/tmp/genie-prompts';
mkdirSync(dir, { recursive: true });
const ts = Date.now().toString(36);
const promptFile = join(dir, `${params.role || 'agent'}-${ts}.md`);

// If there is also a systemPromptFile (user agent), merge both
let content = params.systemPrompt;
if (params.systemPromptFile) {
content = readFileSync(params.systemPromptFile, 'utf-8') + '\n\n' + content;
}

// If extraArgs has --append-system-prompt-file, merge that too
if (params.extraArgs) {
const fileIdx = params.extraArgs.indexOf('--append-system-prompt-file');
if (fileIdx !== -1 && params.extraArgs[fileIdx + 1]) {
content = content + '\n\n' + readFileSync(params.extraArgs[fileIdx + 1], 'utf-8');
// Remove the extra arg since we merged it
params.extraArgs.splice(fileIdx, 2);
}
}

writeFileSync(promptFile, content);
const flag = params.promptMode === 'system' ? '--system-prompt-file' : '--append-system-prompt-file';
parts.push(flag, escapeShellArg(promptFile));
} else if (params.systemPromptFile) {
const flag = params.promptMode === 'system' ? '--system-prompt-file' : '--append-system-prompt-file';
parts.push(flag, escapeShellArg(params.systemPromptFile));
} else if (params.systemPrompt) {
const flag = params.promptMode === 'system' ? '--system-prompt' : '--append-system-prompt';
parts.push(flag, escapeShellArg(params.systemPrompt));
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

This new implementation for handling system prompts has a few issues I'd recommend addressing:

  1. Resource Leak: Temporary files are created but never deleted. This will lead to an accumulation of files in the temp directory, which is a resource leak. A cleanup mechanism is crucial. I'd suggest modifying the LaunchCommand interface to return the path of the temporary file, making the caller responsible for cleanup after the command finishes execution.

  2. Bug with extraArgs: The logic to merge --append-system-prompt-file from extraArgs only handles the first occurrence due to using indexOf. If multiple flags are passed, the subsequent ones will be missed. This should be a loop to handle all occurrences.

  3. Hardcoded Temp Directory: The path /tmp is hardcoded. It's better to use os.tmpdir() for portability across different operating systems. You'll need to import { tmpdir } from 'node:os';.

  4. Code Style: require() calls are made inside the function. It's a better practice to use top-level ES module import statements for fs, path, and os for consistency and clarity.

Here's a suggested implementation that addresses points 2, 3, and 4 (while I've used require to make the suggestion self-contained, I recommend moving them to top-level imports). The resource leak (point 1) will require changes to the LaunchCommand interface, which is outside the scope of this suggestion but should be addressed.

  if (params.systemPrompt) {
    // Write built-in prompt to temp file — avoids shell escaping of complex content
    const { mkdirSync, writeFileSync, readFileSync } = require('node:fs');
    const { join } = require('node:path');
    const { tmpdir } = require('node:os');
    const dir = join(tmpdir(), 'genie-prompts');
    mkdirSync(dir, { recursive: true });
    const ts = Date.now().toString(36);
    const promptFile = join(dir, `${params.role || 'agent'}-${ts}.md`);

    // If there is also a systemPromptFile (user agent), merge both
    let content = params.systemPrompt;
    if (params.systemPromptFile) {
      content = readFileSync(params.systemPromptFile, 'utf-8') + '\n\n' + content;
    }

    // If extraArgs has --append-system-prompt-file, merge that too
    if (params.extraArgs) {
      let fileIdx;
      while ((fileIdx = params.extraArgs.indexOf('--append-system-prompt-file')) !== -1) {
        if (fileIdx + 1 < params.extraArgs.length) {
          content = content + '\n\n' + readFileSync(params.extraArgs[fileIdx + 1], 'utf-8');
          // Remove the flag and filename
          params.extraArgs.splice(fileIdx, 2);
        } else {
          // Malformed, just remove the flag
          params.extraArgs.splice(fileIdx, 1);
        }
      }
    }

    writeFileSync(promptFile, content);
    const flag = params.promptMode === 'system' ? '--system-prompt-file' : '--append-system-prompt-file';
    parts.push(flag, escapeShellArg(promptFile));
  } else if (params.systemPromptFile) {
    const flag = params.promptMode === 'system' ? '--system-prompt-file' : '--append-system-prompt-file';
    parts.push(flag, escapeShellArg(params.systemPromptFile));
  }

Comment on lines +207 to +230
it('merges systemPromptFile and systemPrompt into one temp file', () => {
const fs = require('node:fs');
const testFile = '/tmp/genie-prompts/test-agents.md';
fs.mkdirSync('/tmp/genie-prompts', { recursive: true });
fs.writeFileSync(testFile, 'User agent instructions');

const result = buildClaudeCommand({
provider: 'claude',
team: 'work',
role: 'implementor',
systemPromptFile: testFile,
systemPrompt: 'Built-in prompt',
});
expect(result.command).toContain('--append-system-prompt-file');
// Should reference the NEW temp file, not the original
expect(result.command).toContain('/tmp/genie-prompts/implementor-');

// Verify merged content
const match = result.command.match(/\/tmp\/genie-prompts\/implementor-[^']+/);
expect(match).toBeTruthy();
const content = fs.readFileSync(match![0], 'utf-8');
expect(content).toContain('User agent instructions');
expect(content).toContain('Built-in prompt');
});

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

This test, and others in this file, create files and directories in /tmp/genie-prompts but do not clean them up. This creates side effects that can pollute the test environment and leave garbage on the file system.

Additionally, I noticed there's missing test coverage for the new logic that merges --append-system-prompt-file from extraArgs in buildClaudeCommand.

I recommend the following:

  1. Use test lifecycle hooks like afterEach or afterAll to clean up any files and directories created during the test run. You can use a unique temporary directory for each test run using fs.mkdtemp to make cleanup easier.
  2. Add new test cases to verify the extraArgs merging logic, especially a case with multiple --append-system-prompt-file flags to ensure it's handled correctly.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7e8d711325

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

const dir = '/tmp/genie-prompts';
mkdirSync(dir, { recursive: true });
const ts = Date.now().toString(36);
const promptFile = join(dir, `${params.role || 'agent'}-${ts}.md`);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Sanitize role before building temp prompt filename

Using params.role directly in join(dir, ${params.role || 'agent'}-${ts}.md) allows path traversal and absolute-path escapes when the role contains /, .., or starts with /. Agent names are only validated as non-empty elsewhere, so a role like ../../pwn causes prompt files to be written outside /tmp/genie-prompts (e.g. /pwn-<ts>.md), which is an unintended arbitrary file write and can also make worker startup fail on permission errors.

Useful? React with 👍 / 👎.

@namastex888
namastex888 merged commit fcf1afd into dev Mar 15, 2026
5 checks passed
@namastex888
namastex888 deleted the fix/leader-spawn branch March 29, 2026 22:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant