Preserve Pi provider credentials for workspace auto-naming - #9479
austinywang wants to merge 6 commits into
Conversation
📝 WalkthroughWalkthroughThe Pi stop hook now preserves allowlisted provider variables only when it uses a trusted bundled cmux executable. Tests cover auto-naming, credential isolation, executable selection, persisted state, and applied workspace titles. ChangesPi auto-naming environment flow
Estimated code review effort: 4 (Complex) | ~45 minutes Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 24 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (24 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…ce-auto-naming-does-not-run-fo # Conflicts: # tests/test_pi_extension_install.py
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@tests/test_pi_extension_install.py`:
- Around line 182-183: Add a concise comment immediately before the
TemporaryDirectory call explaining that dir="/tmp" keeps the AF_UNIX socket path
short because macOS has a roughly 104-byte path limit and its default TMPDIR may
be deeply nested. Preserve the existing socket_dir and socket_path logic.
- Line 21: Update the Iterator import in tests/test_pi_extension_install.py to
use the collections.abc alias instead of typing.Iterator, preserving all
existing Iterator usage.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 1a9970d1-a794-4154-a47c-9e72ec6904de
📒 Files selected for processing (3)
CLI/CMUXCLI+PiExtensionSourceDispatch.swiftCLI/CMUXCLI+PiExtensionSourcePart1.swifttests/test_pi_extension_install.py
…ce-auto-naming-does-not-run-fo
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@CLI/CMUXCLI`+PiExtensionSourcePart1.swift:
- Around line 595-603: Stop treating CMUX_BUNDLED_CLI_PATH as credential-trusted
in trustedBundledCmuxExecutable; derive trustedForCredentials only from an
authenticated bundled-CLI source. In CLI/CMUXCLI+PiExtensionSourceDispatch.swift
lines 426-433, gate forwarding CMUX_SOCKET_PASSWORD and provider credentials on
that stronger trust result. In tests/test_pi_extension_install.py lines
1462-1526, add coverage using an absolute PATH-shadow executable from
CMUX_BUNDLED_CLI_PATH and assert it receives no credentials.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: b5c99de6-8af1-45e4-acb6-6cc350573202
📒 Files selected for processing (4)
CLI/CMUXCLI+PiExtensionSourceDispatch.swiftCLI/CMUXCLI+PiExtensionSourcePart1.swifttests/test_pi_extension_dispatch.pytests/test_pi_extension_install.py
Bugbot is paused — on-demand spend limit reachedBugbot uses usage-based billing for this team and has hit its on-demand spend limit. A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue. |
Summary
When
--no-extensionsremoves a custom provider, Pi's built-in fallback can now authenticate without broadly exposing credentials.Fixes #8718
Testing
ba19285046:CMUX_CLI_BIN="$CLI_BIN" python3 tests/test_pi_extension_install.pyfailed withNo API key found for the selected model.;autoNameLastAttemptAtwas present andautoNameLastNamedAtwas absent.ec5656dbfd: the same regression passed, including fallback exit 0/title output, title application, and both timestamps.python3 tests/test_pi_extension_install.pyandpython3 tests/test_pi_extension_dispatch.pypass against the tagged CLI.ruff check tests/claude_teams_test_utils.py tests/test_pi_extension_install.py tests/test_pi_extension_dispatch.py./scripts/reload.sh --tag sym8718 --derived-data /private/tmp/cmux-sym8718-isolated/tmp/cmux-debug-sym8718.sock: a generated Pi 0.81.1-shaped extension ignored a conflicting absoluteCMUX_BUNDLED_CLI_PATH, invoked the installer-pinned CLI, ran the fallback with--no-extensionsat exit 0, populatedautoNameLastAttemptAt/autoNameLastNamedAt, and changed the live generic workspace title toPi Pinned Credential Handoff. The tagged app was then quit.