Replies: 1 comment
Identity correction (2026-09-09)This thread is SSH locality, not git-checkpoint. Official Fact the opening post already owns, which later
Not this thread: #508 fork stash; #154 context rewind (must not touch the working tree); #502 host OS isolation; #472 worktree reclaim; gondolin guest Suggestion: keep asking only whether execution locality is an invariant (authoritative cwd / Trust / cancel / cleanup follow the place tools run) or a #169 Computer provider. Do not invent an SSH client. Do not merge a stash checkpoint into this Ideas. No new tracker. |
Uh oh!
There was an error while loading. Please reload this page.
一句话问题:工具执行位置(SSH 远程委派 read/write/edit/bash)该不该成为独立机制,还是只当作 #169 Computer / Security seam 的一种 provider? 它和 #502 的本机 OS sandbox 也不是同一件事。
这不是 commit 计划,也不是 Adopt。倾向 Discuss。本轮未安装、未运行。不提议新安装器。Pi 继续拥有 install / update / uninstall。不新增第二条
/openpi-setup。若以后出现模型可见的「切换远程」工具,必须写入CHILD_EXCLUDED_TOOL_NAMES或CHILD_SAFE_PACKAGE_TOOL_NAMES;未分类 = fail-closed。默认更像 parent-only。为什么目录里这个机制看起来有趣
冻结身份(last-seen 2026-09-08):
ssh.ts6ca4511(earendil-works/pimain)公开源码声明的机制(未在本轮执行验证):
--ssh user@host[:path]时,用 pluggable operations 把内建 read/write/edit/bash 和!转到远程;事实
a9b40f0。本轮未安装、未运行。推断
执行位置是正交原语:local cwd / worktree / OS sandbox / remote host。社区几乎没做成独立高下载产品,但官方 example 已经把 seam 暴露出来。OpenPI 若不管,in-process child 可能在用户自行
--ssh时把远程写成「本机」。建议
先回答所有权:只在 #169 登记一种 Computer provider,还是要一条「execution locality」不变量(权威 cwd、Trust、取消、cleanup 都跟位置走)。不要自研 SSH 客户端产品。配置若有,只走
/openpi-setup。未知
关联
docs/research/PI_COMMUNITY_PLUGIN_SURVEY_2026-09-08.mdAll reactions