Skip to content

feat(examples): add pi install support and update-safe config - #125

Open
ndimiduk wants to merge 1 commit into
earendil-works:mainfrom
ndimiduk:ndimiduk-pi-extension-install
Open

feat(examples): add pi install support and update-safe config#125
ndimiduk wants to merge 1 commit into
earendil-works:mainfrom
ndimiduk:ndimiduk-pi-extension-install

Conversation

@ndimiduk

Copy link
Copy Markdown

This change is intended to improve the everyday usability of gondolin.

Ship examples/pi-gondolin.ts as a pi extension via pi.extensions in package.json, enabling pi install npm:@earendil-works/gondolin.

HTTP hooks and secret injection are driven by update-safe config files (~/.pi/agent/extensions/gondolin.json and <cwd>/.pi/gondolin.json) instead of hardcoded values. With no config the VM runs with no outbound HTTP access.

Config hardening:

  • Validate secret entry shape and hosts element types at load time
  • Skip secrets whose env var is not set (warn instead of injecting "")
  • Warn when project config overrides a global secret
  • Omit allowedHosts when empty so createHttpHooks defaults to allow-all rather than deny-all, which would block secrets-only configs
  • Guard user_bash against post-shutdown VM creation (leaked QEMU)
  • Exclude examples from tsconfig.build.json to keep dist/ clean

Provide a brief description of the changes in this PR here.

Contribution Agreement

Please ensure this PR follows the guidelines in CONTRIBUTING.md.

By submitting this pull request, I confirm the following:

I understand that the entity Earendil Inc. (incorporated in the state of Delaware in 2025) needs some rights from me in order to utilize my contributions in this PR. As a contributor I retain all rights, title and interest in and to my contributions, and by keeping this boilerplate intact I confirm that Earendil Inc. can use, modify, copy, and redistribute my contributions, under Earendil Inc.'s choice of terms.

Ship `examples/pi-gondolin.ts` as a pi extension via `pi.extensions`
in package.json, enabling `pi install npm:@earendil-works/gondolin`.

HTTP hooks and secret injection are driven by update-safe config files
(`~/.pi/agent/extensions/gondolin.json` and `<cwd>/.pi/gondolin.json`)
instead of hardcoded values. With no config the VM runs with no
outbound HTTP access.

Config hardening:
- Validate secret entry shape and hosts element types at load time
- Skip secrets whose env var is not set (warn instead of injecting "")
- Warn when project config overrides a global secret
- Omit allowedHosts when empty so createHttpHooks defaults to allow-all
  rather than deny-all, which would block secrets-only configs
- Guard user_bash against post-shutdown VM creation (leaked QEMU)
- Exclude examples from tsconfig.build.json to keep dist/ clean

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant