Skip to content

chore(whatsapp): bump local-whatsapp pin to 0.3.1 for the reply nudge - #827

Open
defangdevs wants to merge 1 commit into
masterfrom
chore/whatsapp-pin-0.3.1
Open

defangdevs wants to merge 1 commit into
masterfrom
chore/whatsapp-pin-0.3.1

Conversation

@defangdevs

Copy link
Copy Markdown
Owner

Problem

A WhatsApp sender only sees WhatsApp, so a Codex turn that runs long leaves their message unanswered for 15+ minutes with no sign of life. defangdevs/local-channels#79 (local-whatsapp 0.3.1) appends a short instruction to every delivered message asking the agent to acknowledge at once and post progress updates. The box only gets it once the pin moves.

Change

Nothing else changes: the pinned file set, install flow and integrity checks are untouched. The Claude peer (peer.mjs) comes from the plugin marketplace, not this pin.

Verification

  • nix run .#assemble, nix run .#update-golden
  • python3 tests/test-whatsapp-cli.py: 11 OK
  • nix checks: whatsapp-cli, module-generated-up-to-date, golden-snapshot, vendor-integrity, source-tree

🤖 Generated with Claude Code

https://claude.ai/code/session_01RZBL8MqNXVVnRmxR5DK5rU

A WhatsApp sender only sees WhatsApp, so a Codex turn that runs long
leaves their message unanswered for 15+ minutes with no sign of life.
local-channels#79 (local-whatsapp 0.3.1) appends a short instruction to
every delivered message asking the agent to acknowledge at once and post
progress updates; this box only gets it once the pin moves.

Bump REV in modules/src/whatsapp-cli.py to the #79 merge commit 7d0d307
and refresh the four per-file sha256 values (same file set as 0.3.0).
Regenerated modules/agent-box.nix and the golden agent-box-whatsapp payload.

Verification: nix run .#assemble, nix run .#update-golden; python3
tests/test-whatsapp-cli.py (11 OK); nix checks whatsapp-cli,
module-generated-up-to-date, golden-snapshot, vendor-integrity,
source-tree.

Co-Authored-By: Claude Code <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RZBL8MqNXVVnRmxR5DK5rU
@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (1)
AGENTS.md — auto-discovered

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 43db94a8-38ca-4801-8c9f-fa62ba90fdb5
📥 Commits

Reviewing files that changed from the base of the PR and between 5402470 and 4ca3e5d.

📒 Files selected for processing (3)
  • modules/agent-box.nix
  • modules/src/whatsapp-cli.py
  • tests/golden/vm/payloads/agent-box-whatsapp/bin/agent-box-whatsapp

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The WhatsApp runtime revision and SHA-256 hashes for four files were updated in the runtime configuration, download script, and golden test payload.

Changes

WhatsApp runtime pin

Layer / File(s) Summary
Update runtime revision and hashes
modules/agent-box.nix, modules/src/whatsapp-cli.py, tests/golden/vm/payloads/agent-box-whatsapp/bin/agent-box-whatsapp
The pinned runtime revision and expected hashes for bridge.mjs, state.mjs, package.json, and package-lock.json were updated in all three locations.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Feature

Suggested reviewers: lionello

Merge Risk: ⚪ Minimal · up to 4ca3e

The updated WhatsApp runtime pin appears ready to merge after normal checks; no actionable issue remains in the supplied evidence.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 4ca3e

The update preserves the existing download checks, pairing gate, and separation between runtime files and linked-device state. No introduced security weakness was established. However, the new upstream code and its instruction behavior were not independently inspected, so unchanged permissions and trust behavior cannot be fully confirmed.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The downloaded bridge executes within the invoking user's process authority and inherits its environment. The directly evidenced scope is the per-user runtime and linked-device state; any additional agent, tool, credential, or cross-service exposure depends on upstream behavior and deployment configuration not inspected here.

Security Findings and Attack Paths

  • inferred — No introduced attack path is established by the available evidence. Local integrity controls constrain downloaded bytes, but the new bridge's sender checks and treatment of message content versus appended instructions remain unverified. Hash agreement alone would not establish safe instruction semantics.

Trust Boundaries and Controls

  • observed — External source files cross into executable local runtime code only after a two-megabyte size bound and pinned SHA-256 validation during installation. npm ci disables lifecycle scripts. These controls remain in place, but provenance of the revised digests and the new dependency metadata were not independently established.

Resilience and Maintainability Implications

  • observed — The installer contains no cross-process lock around runtime replacement, and successful promotion removes recovery copies before bridge execution. Both properties predate the examined pin change. Caller-level serialization and compatibility of the promoted upstream runtime are not established, so these are existing assumptions rather than demonstrated PR regressions.

Hardening Proposals

  • proposed — Independently verify the four published files against the new digests and compare upstream revisions for sender authorization, credential handling, state compatibility, dependency changes, and separation of sender-controlled text from the reply instruction. This would resolve the dependency review gap without treating it as a verified vulnerability.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the WhatsApp pin update to version 0.3.1, which is the main change.
Description check ✅ Passed The description explains the reason for the pin update, the files and hashes changed, and the reported verification.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

sonarqubecloud Bot commented Oct 4, 2026

Copy link
Copy Markdown

@defangdevs

Copy link
Copy Markdown
Owner Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@lionello

lionello commented Oct 4, 2026

Copy link
Copy Markdown
Collaborator

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Backlog

Development

Successfully merging this pull request may close these issues.

2 participants