feat: harden runtime readiness and session workflow
This commit is contained in:
@@ -5,6 +5,11 @@
|
||||
set -euo pipefail
|
||||
export THT_CONFIG="${THT_CONFIG:-/app/harness/workspaces/local.yaml}"
|
||||
|
||||
# Pi 0.80 gates every project-local extension, prompt and skill behind its persistent
|
||||
# trust store. The mounted profile may come from another host and therefore not contain
|
||||
# the container path. Preserve its existing decisions and authorize only this harness.
|
||||
node /app/docker/ensure-pi-trust.mjs "${THT_HARNESS_DIR:-/app/harness}"
|
||||
|
||||
cmd="${1:-server}"
|
||||
case "$cmd" in
|
||||
server)
|
||||
|
||||
@@ -63,7 +63,7 @@ ENV PATH="/opt/venv/bin:/usr/local/bin:$PATH" \
|
||||
PI_BIN=pi \
|
||||
HOME=/home/thoth
|
||||
|
||||
COPY docker/core-entrypoint.sh /app/docker/core-entrypoint.sh
|
||||
COPY docker/core-entrypoint.sh docker/ensure-pi-trust.mjs /app/docker/
|
||||
RUN chmod +x /app/docker/core-entrypoint.sh
|
||||
|
||||
WORKDIR /app/backend
|
||||
|
||||
@@ -0,0 +1,30 @@
|
||||
import { mkdirSync, readFileSync, renameSync, writeFileSync } from "node:fs";
|
||||
import { homedir } from "node:os";
|
||||
import { dirname, join, resolve } from "node:path";
|
||||
|
||||
export function ensurePiTrust(harnessDir, agentDir = join(homedir(), ".pi", "agent")) {
|
||||
const trustPath = join(agentDir, "trust.json");
|
||||
let trust = {};
|
||||
try {
|
||||
trust = JSON.parse(readFileSync(trustPath, "utf8"));
|
||||
} catch (error) {
|
||||
if (error?.code !== "ENOENT") throw error;
|
||||
}
|
||||
if (!trust || typeof trust !== "object" || Array.isArray(trust)) {
|
||||
throw new Error(`Invalid Pi trust store: ${trustPath}`);
|
||||
}
|
||||
|
||||
const canonicalHarness = resolve(harnessDir);
|
||||
if (trust[canonicalHarness] === true) return false;
|
||||
|
||||
mkdirSync(dirname(trustPath), { recursive: true });
|
||||
const next = { ...trust, [canonicalHarness]: true };
|
||||
const temporaryPath = `${trustPath}.${process.pid}.tmp`;
|
||||
writeFileSync(temporaryPath, `${JSON.stringify(next, null, 2)}\n`, { mode: 0o600 });
|
||||
renameSync(temporaryPath, trustPath);
|
||||
return true;
|
||||
}
|
||||
|
||||
if (process.argv[1] && import.meta.url === new URL(`file://${process.argv[1]}`).href) {
|
||||
ensurePiTrust(process.argv[2] ?? process.env.THT_HARNESS_DIR ?? "/app/harness");
|
||||
}
|
||||
@@ -0,0 +1,21 @@
|
||||
import assert from "node:assert/strict";
|
||||
import { mkdtempSync, readFileSync, writeFileSync } from "node:fs";
|
||||
import { tmpdir } from "node:os";
|
||||
import { join } from "node:path";
|
||||
import test from "node:test";
|
||||
import { ensurePiTrust } from "./ensure-pi-trust.mjs";
|
||||
|
||||
test("adds the canonical harness path and preserves existing trust entries", () => {
|
||||
const root = mkdtempSync(join(tmpdir(), "thothii-pi-trust-"));
|
||||
const agentDir = join(root, "agent");
|
||||
ensurePiTrust("/first/harness", agentDir);
|
||||
writeFileSync(
|
||||
join(agentDir, "trust.json"),
|
||||
`${JSON.stringify({ "/existing/project": true }, null, 2)}\n`,
|
||||
);
|
||||
|
||||
assert.equal(ensurePiTrust("/app/harness/../harness", agentDir), true);
|
||||
const trust = JSON.parse(readFileSync(join(agentDir, "trust.json"), "utf8"));
|
||||
assert.deepEqual(trust, { "/existing/project": true, "/app/harness": true });
|
||||
assert.equal(ensurePiTrust("/app/harness", agentDir), false);
|
||||
});
|
||||
Reference in New Issue
Block a user