Skip to content

sessionforge wire-paseo 명령 추가 — Paseo 플러그인 자동 설치 - #1

Merged
4mGLn merged 1 commit into
mainfrom
feature/wire-paseo
Sep 2, 2026
Merged

4mGLn merged 1 commit into
mainfrom
feature/wire-paseo

Conversation

@4mGLn

@4mGLn 4mGLn commented Sep 2, 2026

Copy link
Copy Markdown
Owner

요약

  • sessionforge wire-paseo: 버전 일치하는 릴리스 자산을 내려받아 paseo plugin install로 자동 설치
  • sessionforge paseo-status: 설치/실행 상태 조회
  • release.yml에 package-plugin 잡 추가 — Paseo 플러그인을 자기 완결형 패키지(node_modules에 실제
    빌드 산출물 포함, 워크스페이스 심링크 아님)로 만들어 릴리스에 첨부

검증

  • 실제 paseo plugin install로 패키징된 번들을 설치해 status: running 확인
  • 실제 컴파일된 SEA 바이너리로 wire-paseo 실행 → 버전 주입과 다운로드 URL 정확성 확인
  • typecheck 통과, 테스트 97개 전부 통과 (신규 12개 포함)

- release.yml에 package-plugin 잡 추가: Paseo 플러그인(index.ts,
  main.client.tsx, src/server/*)을 독립 실행 가능한 디렉터리로 패키징해
  릴리스에 함께 첨부 (scripts/package-plugin.mjs)
- 실제로 확인해봄: paseo plugin install owner/repo 형태의 git 소스 설치는
  이 저장소의 npm 워크스페이스 의존성(@aadaa88/sessionforge)을 해석하지
  못해 빌드 자체가 실패함 — 그래서 npm 워크스페이스 심링크 대신 빌드된
  aadaa88/sessionforge를 node_modules에 실제로 복사해 넣은 자기 완결형
  패키지를 만듦 (실제로 paseo plugin install로 설치·구동까지 검증함)
- 새 CLI 명령 sessionforge wire-paseo: paseo CLI 존재 확인 → 데몬의
  pluginsEnabled 확인(비활성화면 절대 직접 켜지 않고 안내만 하고 중단) →
  현재 CLI 버전과 일치하는 릴리스 자산 다운로드(releases/latest 아님) →
  압축 해제 → paseo plugin install로 설치 → 실행 상태 검증
- sessionforge paseo-status: 설치/실행 상태 조회
- build-binary.mjs에서 esbuild define으로 버전을 바이너리에 주입(런타임에
  package.json을 읽을 수 없으므로) — 실제 컴파일된 바이너리로 wire-paseo를
  실행해 버전 문자열과 다운로드 URL이 올바른지 확인함
- README.md, README.ko.md, docs/MANUAL.md, docs/REFERENCE.md,
  CONTRIBUTING.md 문서 갱신, 테스트 12개 추가(전체 97개 통과)

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: bf7c2bb600

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

console.log("Plugins are enabled on this daemon.");

const version = flagString(args.flags, "version") ?? getVersion();
const archivePath = join(tmpdir(), PLUGIN_ARCHIVE_NAME);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Create a private temporary archive

On a shared system, another local user can pre-create the predictable sessionforge-paseo-plugin.tar.gz path in the temp directory as a symlink to a victim-writable file. downloadPluginArchive opens this path with createWriteStream, which follows the symlink and truncates/writes the downloaded archive before extraction, so running wire-paseo can overwrite an arbitrary file owned by the caller. Use a uniquely created private temp directory or file (for example, via mkdtemp) and clean it up afterward.

Useful? React with 👍 / 👎.

@4mGLn
4mGLn merged commit 01e7861 into main Sep 2, 2026
4 checks passed
@4mGLn
4mGLn deleted the feature/wire-paseo branch September 2, 2026 05:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant