Skip to content

fix(cli): verify caller ownership before stopping - #310

Open
EllAchE wants to merge 1 commit into
mainfrom
feat/nuke-gate-caller
Open

EllAchE wants to merge 1 commit into
mainfrom
feat/nuke-gate-caller

Conversation

@EllAchE

@EllAchE EllAchE commented Oct 11, 2026

Copy link
Copy Markdown
Contributor

Why

Ending a tracked agent through process termination skips Gate Inbox's intentional-stop record and kill observers. Tool shells that lost launch variables need caller verification before they can end a session safely.

Summary

  • Resolve unmarked private callers through pane process ancestry and complete adopted stops through the outside lifecycle worker.
  • Pin shutdown to the launch, pane and process start identity; reject foreign pane variables and changed processes.
  • Add stop --if-managed for an explicit unmanaged result. Refuse unresolved shared Codex daemon callers, including those with no thread ID, rather than trusting a stored conversation match.

Test plan

  • Build and vet affected packages.
  • Affected package suites run through the CI tmux-isolation harness; CLI compatibility snapshot updated and verified.
  • Private managed/adopted stop tests verify intentional ends, retained history, observer notification and surviving sentinels.
  • Private daemon fixtures cover missing/mismatched thread identity and spoofed pane variables without lifecycle writes.
  • Pinned pane shutdown rejects foreign and stale process identities.

@EllAchE EllAchE added the codex PR primarily authored by Codex label Oct 11, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 11, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-11T08:09:46.173313Z 0cc7076 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 0cc7076134

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +120 to +123
currentPin, err := runtime.paneProcess(target)
if err != nil || currentPin != processPin {
return Session{}, errors.New("stop request no longer matches this pane process")
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Pin the managed kill to the pane process

For a managed target, the process identity is checked here but is not included in the later atomic tmux condition: stopSession performs pane capture and database work before calling KillPane, which only verifies the session and window. If another actor runs respawn-pane after this check but before that kill, the replacement process is killed even though its PID/start identity differs from processPin. Pass the pinned PID into the managed kill and include #{pane_pid} in the same if-shell condition, as the adopted path already does for its PID.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

codex PR primarily authored by Codex

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant