Skip to content
This repository was archived by the owner on Sep 23, 2026. It is now read-only.

feat(shell): deprecation-aware update flow with one-key migration to Kimi Code - #2630

Merged
sailist merged 1 commit into
MoonshotAI:mainfrom
jackfish212:feat/kimi-code-migration-notice
Sep 1, 2026
Merged

sailist merged 1 commit into
MoonshotAI:mainfrom
jackfish212:feat/kimi-code-migration-notice

Conversation

@jackfish212

@jackfish212 jackfish212 commented Aug 31, 2026 •

Copy link
Copy Markdown
Collaborator

Related Issue

Part of the kimi-cli → Kimi Code migration effort (no tracking issue on this repo).

Description

When the CDN publishes a deprecation/migration notice (https://cdn.kimi.com/kimi-code-tips/kimi_cli/migration.json), the CLI now treats the Python release as deprecated and drives migration to the new Kimi Code:

  • Startup gate (check_update_gate, now async): a pending newer Python release still takes precedence and shows the existing update gate; otherwise, when the notice is enabled and applies (min_cli_version, new Kimi Code not yet installed), a red "no longer maintained" panel blocks startup and offers one-key migration. The panel reappears on every launch — there is no skip.
  • Migration action: direct platform download (platforms map keyed by <arch>-<os> target, optional sha256, tar.gz extracted to ~/.kimi-code/bin/kimi + PATH shim) with automatic fallback to the official install script (install.sh / install.ps1, overridable from the notice).
  • Welcome panel: when no update gate fired, the cached notice is also surfaced inline below the welcome info.
  • Remote control: enabled kill switch, localized message (zh/en), and arbitrary links; a failed fetch keeps the previous cache.
  • Tests for the gate and notice behavior updated and extended (tests/ui/test_update_gate.py).

The companion CDN payload lives in the kimi-cli-cdn-sync repo. Changelog entry intentionally omitted for now.

Checklist

  • I have read the CONTRIBUTING document.
  • I have linked the related issue, if any.
  • I have added tests that prove my fix is effective or that my feature works.
  • I have run make gen-changelog to update the changelog.
  • I have run make gen-docs to update the user documentation.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 5 potential issues.

1 flag not posted on this PR by your GitHub settings — view it in Devin Review. (Configure)

Devin Review

Comment on lines +546 to +556
KIMI_CODE_BIN_DIR.mkdir(parents=True, exist_ok=True)
dest_path = KIMI_CODE_BIN_DIR / "kimi"
shutil.copy2(binary_path, dest_path)
os.chmod(
dest_path,
os.stat(dest_path).st_mode | stat.S_IXUSR | stat.S_IXGRP | stat.S_IXOTH,
)
except Exception:
logger.exception("Failed to install:")
console.print("[red]Failed to install.[/red]")
return False

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Failed installs suppress future migration

When copying or chmod fails after KIMI_CODE_BIN_DIR.mkdir, the partial directory remains. kimi_code_installed then suppresses future prompts despite no usable installation.

Prompt for agents
A failed direct installation can leave ~/.kimi-code behind because _download_and_install creates that directory before copying and chmodding the binary. migration_nudge.kimi_code_installed currently considers any ~/.kimi-code directory a completed installation, so subsequent startup gates and notices disappear. Make installation detection require a usable Kimi Code installation, or clean up only directories/artifacts created by the failed attempt without deleting pre-existing user data. Add a regression test covering copy or chmod failure followed by should_show_migration.
Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Comment on lines +558 to +562
if not _link_path_shim(KIMI_CODE_BIN_DIR / "kimi"):
console.print(
f"[yellow]Installed to {KIMI_CODE_BIN_DIR}/kimi but could not update PATH.[/yellow]"
)
return True

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Broken PATH setup reports success

When _link_path_shim fails, _download_and_install still returns success. The gate tells users to run kimi, which can resolve to the legacy CLI or nothing.

Prompt for agents
The direct migration reports success even when creating ~/.local/bin/kimi fails. The caller then exits successfully and instructs the user to run kimi, although PATH can still select the legacy executable or no executable. Treat PATH setup as an incomplete migration: either invoke the install-script fallback, verify that kimi resolves to the new binary before returning success, or present an actionable non-success result that does not claim the command is ready. Add coverage for shim failure with and without an existing legacy kimi command.
Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Comment on lines +476 to +489
if sys.platform == "win32":
cmd = [
"powershell",
"-NoProfile",
"-ExecutionPolicy",
"Bypass",
"-Command",
tips.install_ps1,
]
else:
cmd = ["bash", "-c", tips.install_sh]
console.print("[grey50]Running install script...[/grey50]")
try:
result = subprocess.run(cmd)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟥 Unsigned notices execute arbitrary commands

A modified CDN notice can replace install_sh or install_ps1. Accepting migration executes that command through the system shell without signature verification.

Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Comment on lines +519 to +522
if download.sha256 and not _sha256_matches(tar_path, download.sha256):
logger.error("Checksum mismatch for {url}", url=download.url)
console.print("[red]Downloaded file checksum mismatch.[/red]")
return False

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟥 Missing checksums allow unverified installs

A platform entry may omit sha256, causing _download_and_install to skip integrity verification. Accepted migrations can install a modified binary as kimi.

Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Comment on lines +527 to +528
with tarfile.open(tar_path, "r:gz") as tar:
tar.extractall(tmpdir)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟥 Migration archives escape extraction directory

tar.extractall accepts traversal links and paths from the downloaded archive. A crafted migration archive can overwrite files outside the temporary directory.

Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

@jackfish212
jackfish212 force-pushed the feat/kimi-code-migration-notice branch from 64eb2a3 to 02e7ff9 Compare August 31, 2026 13:52
@jackfish212
jackfish212 force-pushed the feat/kimi-code-migration-notice branch from 02e7ff9 to 0f519ee Compare August 31, 2026 14:04
@sailist
sailist added this pull request to the merge queue Sep 1, 2026
Merged via the queue into MoonshotAI:main with commit ffb4577 Sep 1, 2026
15 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants