Skip to content

feat: native cmux browser for Pi - #54

Draft
tmustier wants to merge 6 commits into
mainfrom
feat/issue-53-native-browser
Draft

tmustier wants to merge 6 commits into
mainfrom
feat/issue-53-native-browser

Conversation

@tmustier

@tmustier tmustier commented Jul 10, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • add typed Pi tools over cmux's supported native WKWebView browser CLI
  • provide background navigation, snapshots/ref interaction, screenshots, bounded diagnostics, and download readiness
  • enforce extension-owned surfaces, approved origins, fresh snapshot refs, synthetic mutation results, and private screenshot files
  • intentionally omit upload, automated value entry, eval/script injection, tabs, profile/state mutation, arbitrary selectors, and caller-selected host paths
  • document the public Codex/Pi/cmux route audit, shared-profile boundary, unsupported WKWebView/CDP operations, recovery, install, and rollback

Security remediation at 704f7d3

  • removed automated upload and every other exposed value-bearing browser capability
  • fixed argv validation to documented extension-generated shapes only
  • suppress raw stdout/stderr for sensitive and mutation commands; retain only allowlisted synthetic metadata
  • accept only the strict top-level UUID returned by the extension's own browser open
  • require origin approval and revalidation for inspect/interaction; reject unsafe URL schemes, credentials, and credential-like parameters
  • constrain actions to refs from the latest successful snapshot
  • generate screenshot paths under a private session directory and validate/read/delete them through an O_NOFOLLOW descriptor with owner/link/size/permission checks
  • close all owned surfaces during extension shutdown

Evidence at 704f7d3

  • npm run test:cmux-browser — 30/30 passing
  • npm run typecheck:cmux-browser — passing
  • git diff --check — passing
  • isolated Pi extension-load smoke — passing
  • path-filtered macOS CI added in .github/workflows/cmux-browser.yml

Draft gate: native E2E pending

The native cmux test remains implemented in scripts/test-cmux-browser-e2e.sh, using a local synthetic page and private temporary directory. It must pass from a fresh process launched directly inside a healthy cmux workspace before this PR is marked ready. The current session is not authorized/valid for live cmux socket testing, so the PR remains draft.

Closes #53

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Native Codex in-app browser parity inside cmux/Pi

1 participant