feat: add Pi provider managed resources

This commit is contained in:
2026-08-22 21:48:00 +08:00
parent 81d8ad1b6b
commit 161f3f471b
31 changed files with 1581 additions and 40 deletions

View File

@@ -12,6 +12,7 @@ import {
PiWorkerProcess,
buildPiRpcArgs,
sanitizePiDiagnostic,
buildPiWorkerEnvironment,
} from '../../electron/coding-runtime/pi/worker-process';
const fakeChildPath = resolve('tests/fixtures/fake-pi-rpc-child.mjs');
@@ -254,6 +255,39 @@ describe('Pi worker process', () => {
expect(worker.stderrDiagnostic).toContain('[REDACTED]');
expect(Buffer.byteLength(worker.stderrDiagnostic)).toBeLessThanOrEqual(160);
expect(sanitizePiDiagnostic(`token=${secret}`, [secret])).toBe('token=[REDACTED]');
expect(sanitizePiDiagnostic('custom-header=q', ['q'])).toBe('custom-header=[REDACTED]');
});
it('inherits only the worker-safe environment allowlist', () => {
const env = buildPiWorkerEnvironment(
'D:\\managed-pi',
{ MAKELore_PI_SELECTED_API_KEY: 'selected-secret' },
{
PATH: 'D:\\tools',
OPENAI_API_KEY: 'unrelated-openai-secret',
ANTHROPIC_API_KEY: 'unrelated-anthropic-secret',
CUSTOM_APPLICATION_SECRET: 'unrelated-custom-secret',
},
);
expect(env).toMatchObject({
PATH: 'D:\\tools',
MAKELore_PI_SELECTED_API_KEY: 'selected-secret',
PI_CODING_AGENT_DIR: 'D:\\managed-pi',
PI_OFFLINE: '1',
PI_TELEMETRY: '0',
ELECTRON_RUN_AS_NODE: '1',
});
expect(env).not.toHaveProperty('OPENAI_API_KEY');
expect(env).not.toHaveProperty('ANTHROPIC_API_KEY');
expect(env).not.toHaveProperty('CUSTOM_APPLICATION_SECRET');
});
it('refuses to put a selected worker credential in argv', async () => {
const secret = 'argv-secret-value';
await expect(makeWorker({
additionalArgs: ['--api-key', secret],
sensitiveValues: [secret],
})).rejects.toThrow('arguments contain a sensitive value');
});
it('forces the complete child tree down after the graceful deadline', async () => {