CB-161: match a pid's ancestry against a pane, not just direct shell/foreground pid #202

Closed
agent wants to merge 1 commits from worker/cb-161-pane-ancestry-293510-1 into main

1 Commits

Author SHA1 Message Date
Dai Ha 7954a4d399 CB-161: match a pid's ancestry against a pane, not just its shell/foreground pid
CI / contract (pull_request) Successful in 56s
CI / build (pull_request) Successful in 1m39s
paneOwnsPid only compared a pid directly against a pane's shell_pid and
foreground_processes pids, so a grandchild process a member spawns (a python3
or curl helper opening its own MCP connection) matched no pane. Connection
identity then fell through to loopback-trust and resolved that connection as
the primary -- a worker->primary privilege escalation.

terminalForPid now walks the caller's ancestry once (bounded at 32
generations, with a cycle guard) via an injectable ParentResolver seam, and
paneOwnsPid checks pane pids against that ancestor set instead of the raw
pid. Production wiring defaults to ProcessHandle; tests drive a fake
pid->parent map.
2026-08-31 14:04:05 +07:00