CodeSnuffler Forgejo End-to-End historical review range codesnuffler-forgejo-live-20260714T181808540Z-118062c2-9a8 #65

Closed
jason-admin wants to merge 2 commits from change_forgejo_end_to_end into base_forgejo_end_to_end
Owner

Exercise the live Forgejo webhook review pipeline against a stable historical CodeSnuffler diff.

Run marker: codesnuffler-forgejo-live-20260714T181808540Z-118062c2-9a8.
Run started at: 2026-07-14T18:18:08.540Z.

Fixture range: f9d210eccd0075b6b39b606cea9b1376719aa062..d8a3fc420b055e04df1d203706b89b1f1261a9c1.
This stable two-commit AI Harness range is expected to produce actionable findings.

Exercise the live Forgejo webhook review pipeline against a stable historical CodeSnuffler diff. Run marker: codesnuffler-forgejo-live-20260714T181808540Z-118062c2-9a8. Run started at: 2026-07-14T18:18:08.540Z. Fixture range: f9d210eccd0075b6b39b606cea9b1376719aa062..d8a3fc420b055e04df1d203706b89b1f1261a9c1. This stable two-commit AI Harness range is expected to produce actionable findings.
This completes Step 12 of the AI harness plugin-instance plan by replacing the tool auth container session contract's persona field with explicit plugin instance identity. Controller request and response schemas, auth image refs, build payloads, dev-shell websocket forwarding, Docker labels, container env, and shared probe metadata now carry plugin_id, instance_id, and driver_id.

The controller now rejects mismatched plugin or driver identity, uses PLUGIN_INSTANCE_ID instead of TOOL_PERSONA_ID in auth containers, and labels containers/images with current plugin and driver keys. The app-side auth container client and session helpers send the new payload shape without accepting the old persona_id request field.

Validated with: pytest for the container image controller client, AI tool auth containers, and container image controller integration files; compileall for touched controller/app/contract/test modules; git diff --check; targeted cleanup search for removed tool-auth persona fields, env vars, labels, and probe keys in the edited boundary.
Update the AI harness runtime/status layer to project current plugin instance identity through auth runtime summaries, raw probe normalization, storage inventory, setup details, generic auth helpers, and system report rows. Runtime/status models now carry plugin_id, instance_id, and driver_id without a persona_id field, while later runner and review-policy persona cleanup remains explicitly scoped to follow-up plan steps.

Validated with: pytest for the AI tool instance suite, focused homepage runtime/status cases, the configured harness plugin catalog case, AI tool schema unit tests, compileall for the touched backend/test modules, git diff --check, and targeted persona cleanup searches.
Author
Owner

CodeSnuffler review banner

CodeSnuffler Review Findings

Recommendation Risk Open findings Files touched by findings
Request Changes Medium 1 1

Findings

1. Dev-shell auth commands ignore selected plugin instance

Severity Category Confidence Location Status
Medium Correctness 94% app/dev_shell.py:320 Open

Details for this finding were posted as an inline review comment on the changed line.

Open finding in CodeSnuffler

Fix via CodeSnuffler

![CodeSnuffler review banner](https://auth.codesnuffler.com/codesnuffler_review/assets/banner_mediumIssues) ## CodeSnuffler Review Findings | Recommendation | Risk | Open findings | Files touched by findings | | --- | --- | ---: | ---: | | Request Changes | Medium | 1 | 1 | ### Findings #### 1. Dev-shell auth commands ignore selected plugin instance | Severity | Category | Confidence | Location | Status | | --- | --- | ---: | --- | --- | | Medium | Correctness | 94% | `app/dev_shell.py:320` | Open | Details for this finding were posted as an [inline review comment](https://forgejo.codesnuffler.com/jason-admin/CodeSnuffler-FJ/pulls/65#issuecomment-248) on the changed line. [Open finding in CodeSnuffler](https://auth.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-65/findings/2) [Fix via CodeSnuffler](https://auth.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-65/findings/2/fix)
@ -316,3 +318,3 @@
async def dev_shell_websocket(websocket: WebSocket) -> None:
command_id = websocket.query_params.get("command", "bash")
persona_id = websocket.query_params.get("persona_id")
instance_id = websocket.query_params.get("instance_id")
Author
Owner

CodeSnuffler finding: Dev-shell auth commands ignore selected plugin instance

Severity: Medium Category: Correctness

dev_shell_websocket now reads only the instance_id query parameter, but frontend/src/dev-shell/components/DevShellTerminal.vue still sends persona_id from the AI tool setup flow. For any non-primary instance, _proxy_runner_auth_session receives None and defaults to primary, so login/auth shells operate on the wrong plugin-instance storage.

Commit: Open commit d8a3fc420b05

Open finding in CodeSnuffler

Fix via CodeSnuffler

Suggested fix: Update DevShellTerminal and its callers to use instanceId/instance_id instead of personaId/persona_id, matching the new backend contract.

**CodeSnuffler finding:** Dev-shell auth commands ignore selected plugin instance Severity: **Medium** Category: **Correctness** `dev_shell_websocket` now reads only the `instance_id` query parameter, but `frontend/src/dev-shell/components/DevShellTerminal.vue` still sends `persona_id` from the AI tool setup flow. For any non-primary instance, `_proxy_runner_auth_session` receives `None` and defaults to `primary`, so login/auth shells operate on the wrong plugin-instance storage. Commit: [Open commit `d8a3fc420b05`](https://forgejo.codesnuffler.com/jason-admin/CodeSnuffler-FJ/commit/d8a3fc420b055e04df1d203706b89b1f1261a9c1) [Open finding in CodeSnuffler](https://auth.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-65/findings/2) [Fix via CodeSnuffler](https://auth.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-65/findings/2/fix) **Suggested fix:** Update `DevShellTerminal` and its callers to use `instanceId`/`instance_id` instead of `personaId`/`persona_id`, matching the new backend contract.
jason-admin closed this pull request 2026-07-14 18:23:15 +00:00

Pull request closed

Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
jason-admin/CodeSnuffler-FJ!65
No description provided.