feat: harden runtime readiness and session workflow

This commit is contained in:
User
2026-07-14 10:27:25 +02:00
parent 6d7738d538
commit 6dbf93fff9
52 changed files with 1464 additions and 169 deletions
+5
View File
@@ -5,6 +5,11 @@
set -euo pipefail
export THT_CONFIG="${THT_CONFIG:-/app/harness/workspaces/local.yaml}"
# Pi 0.80 gates every project-local extension, prompt and skill behind its persistent
# trust store. The mounted profile may come from another host and therefore not contain
# the container path. Preserve its existing decisions and authorize only this harness.
node /app/docker/ensure-pi-trust.mjs "${THT_HARNESS_DIR:-/app/harness}"
cmd="${1:-server}"
case "$cmd" in
server)
+1 -1
View File
@@ -63,7 +63,7 @@ ENV PATH="/opt/venv/bin:/usr/local/bin:$PATH" \
PI_BIN=pi \
HOME=/home/thoth
COPY docker/core-entrypoint.sh /app/docker/core-entrypoint.sh
COPY docker/core-entrypoint.sh docker/ensure-pi-trust.mjs /app/docker/
RUN chmod +x /app/docker/core-entrypoint.sh
WORKDIR /app/backend
+30
View File
@@ -0,0 +1,30 @@
import { mkdirSync, readFileSync, renameSync, writeFileSync } from "node:fs";
import { homedir } from "node:os";
import { dirname, join, resolve } from "node:path";
export function ensurePiTrust(harnessDir, agentDir = join(homedir(), ".pi", "agent")) {
const trustPath = join(agentDir, "trust.json");
let trust = {};
try {
trust = JSON.parse(readFileSync(trustPath, "utf8"));
} catch (error) {
if (error?.code !== "ENOENT") throw error;
}
if (!trust || typeof trust !== "object" || Array.isArray(trust)) {
throw new Error(`Invalid Pi trust store: ${trustPath}`);
}
const canonicalHarness = resolve(harnessDir);
if (trust[canonicalHarness] === true) return false;
mkdirSync(dirname(trustPath), { recursive: true });
const next = { ...trust, [canonicalHarness]: true };
const temporaryPath = `${trustPath}.${process.pid}.tmp`;
writeFileSync(temporaryPath, `${JSON.stringify(next, null, 2)}\n`, { mode: 0o600 });
renameSync(temporaryPath, trustPath);
return true;
}
if (process.argv[1] && import.meta.url === new URL(`file://${process.argv[1]}`).href) {
ensurePiTrust(process.argv[2] ?? process.env.THT_HARNESS_DIR ?? "/app/harness");
}
+21
View File
@@ -0,0 +1,21 @@
import assert from "node:assert/strict";
import { mkdtempSync, readFileSync, writeFileSync } from "node:fs";
import { tmpdir } from "node:os";
import { join } from "node:path";
import test from "node:test";
import { ensurePiTrust } from "./ensure-pi-trust.mjs";
test("adds the canonical harness path and preserves existing trust entries", () => {
const root = mkdtempSync(join(tmpdir(), "thothii-pi-trust-"));
const agentDir = join(root, "agent");
ensurePiTrust("/first/harness", agentDir);
writeFileSync(
join(agentDir, "trust.json"),
`${JSON.stringify({ "/existing/project": true }, null, 2)}\n`,
);
assert.equal(ensurePiTrust("/app/harness/../harness", agentDir), true);
const trust = JSON.parse(readFileSync(join(agentDir, "trust.json"), "utf8"));
assert.deepEqual(trust, { "/existing/project": true, "/app/harness": true });
assert.equal(ensurePiTrust("/app/harness", agentDir), false);
});