sessionforge wire-paseo 명령 추가 — Paseo 플러그인 자동 설치 - #1
Conversation
- release.yml에 package-plugin 잡 추가: Paseo 플러그인(index.ts, main.client.tsx, src/server/*)을 독립 실행 가능한 디렉터리로 패키징해 릴리스에 함께 첨부 (scripts/package-plugin.mjs) - 실제로 확인해봄: paseo plugin install owner/repo 형태의 git 소스 설치는 이 저장소의 npm 워크스페이스 의존성(@aadaa88/sessionforge)을 해석하지 못해 빌드 자체가 실패함 — 그래서 npm 워크스페이스 심링크 대신 빌드된 aadaa88/sessionforge를 node_modules에 실제로 복사해 넣은 자기 완결형 패키지를 만듦 (실제로 paseo plugin install로 설치·구동까지 검증함) - 새 CLI 명령 sessionforge wire-paseo: paseo CLI 존재 확인 → 데몬의 pluginsEnabled 확인(비활성화면 절대 직접 켜지 않고 안내만 하고 중단) → 현재 CLI 버전과 일치하는 릴리스 자산 다운로드(releases/latest 아님) → 압축 해제 → paseo plugin install로 설치 → 실행 상태 검증 - sessionforge paseo-status: 설치/실행 상태 조회 - build-binary.mjs에서 esbuild define으로 버전을 바이너리에 주입(런타임에 package.json을 읽을 수 없으므로) — 실제 컴파일된 바이너리로 wire-paseo를 실행해 버전 문자열과 다운로드 URL이 올바른지 확인함 - README.md, README.ko.md, docs/MANUAL.md, docs/REFERENCE.md, CONTRIBUTING.md 문서 갱신, 테스트 12개 추가(전체 97개 통과)
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: bf7c2bb600
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| console.log("Plugins are enabled on this daemon."); | ||
|
|
||
| const version = flagString(args.flags, "version") ?? getVersion(); | ||
| const archivePath = join(tmpdir(), PLUGIN_ARCHIVE_NAME); |
There was a problem hiding this comment.
Create a private temporary archive
On a shared system, another local user can pre-create the predictable sessionforge-paseo-plugin.tar.gz path in the temp directory as a symlink to a victim-writable file. downloadPluginArchive opens this path with createWriteStream, which follows the symlink and truncates/writes the downloaded archive before extraction, so running wire-paseo can overwrite an arbitrary file owned by the caller. Use a uniquely created private temp directory or file (for example, via mkdtemp) and clean it up afterward.
Useful? React with 👍 / 👎.
요약
sessionforge wire-paseo: 버전 일치하는 릴리스 자산을 내려받아paseo plugin install로 자동 설치sessionforge paseo-status: 설치/실행 상태 조회release.yml에package-plugin잡 추가 — Paseo 플러그인을 자기 완결형 패키지(node_modules에 실제빌드 산출물 포함, 워크스페이스 심링크 아님)로 만들어 릴리스에 첨부
검증
paseo plugin install로 패키징된 번들을 설치해status: running확인wire-paseo실행 → 버전 주입과 다운로드 URL 정확성 확인