mirror of
https://github.com/SikongJueluo/pi-extensions.git
synced 2026-10-05 11:52:55 +08:00
- replace the hardcoded timeout switch with an engine that iterates registered handlers - extract the timeout logic into handlers/timeout.ts and add handlers/env.ts that defers env as non-transparent - thread a partial-evidence bag so the engine exception log retains handler-derived values like innerCommand - add CONTEXT.md with the transparent vs non-transparent wrapper glossary - record ADR 0002: env always defers to the AI judge and is never unwrapped
29 lines
1.1 KiB
Markdown
29 lines
1.1 KiB
Markdown
# pi-extensions
|
|
|
|
Personal `pi` coding-agent extensions. This context covers the permission
|
|
extensions that inspect and re-evaluate Bash commands before they are allowed.
|
|
|
|
## Language
|
|
|
|
### Wrappers
|
|
|
|
**Wrapper**:
|
|
A Bash command of the form `<program> [modifier-args] <inner-command>`, where the
|
|
authorization question is "what does the inner command do?". Whether a wrapper
|
|
may be unwrapped depends on whether its modifier args are transparent.
|
|
_Avoid_: command type, prefix command
|
|
|
|
**Transparent wrapper**:
|
|
A wrapper whose modifier args do not change which program the inner command
|
|
resolves to or its trust boundary (e.g. `timeout`). Stripping the modifiers and
|
|
re-evaluating the inner command is sound: the verdict applies to the same
|
|
program that actually runs.
|
|
_Avoid_: safe wrapper
|
|
|
|
**Non-transparent wrapper**:
|
|
A wrapper whose modifier args change the inner command's resolution or effect
|
|
(e.g. `env`, whose `PATH=` or `-i` can make the inner name resolve to a
|
|
different binary). Stripping the modifiers and re-evaluating the inner command
|
|
is unsound: the verdict may apply to a different program than the one that runs.
|
|
_Avoid_: unsafe wrapper
|