CodeSnuffler Forgejo End-to-End historical review range codesnuffler-forgejo-live-20260715T092125614Z-000e6077-e18 #67

Closed
jason-admin wants to merge 2 commits from change_forgejo_end_to_end into base_forgejo_end_to_end
Owner

Exercise the live Forgejo webhook review pipeline against a stable historical CodeSnuffler diff.

Run marker: codesnuffler-forgejo-live-20260715T092125614Z-000e6077-e18.
Run started at: 2026-07-15T09:21:25.614Z.

Fixture range: f9d210eccd0075b6b39b606cea9b1376719aa062..d8a3fc420b055e04df1d203706b89b1f1261a9c1.
This stable two-commit AI Harness range is expected to produce actionable findings.

Exercise the live Forgejo webhook review pipeline against a stable historical CodeSnuffler diff. Run marker: codesnuffler-forgejo-live-20260715T092125614Z-000e6077-e18. Run started at: 2026-07-15T09:21:25.614Z. Fixture range: f9d210eccd0075b6b39b606cea9b1376719aa062..d8a3fc420b055e04df1d203706b89b1f1261a9c1. This stable two-commit AI Harness range is expected to produce actionable findings.
This completes Step 12 of the AI harness plugin-instance plan by replacing the tool auth container session contract's persona field with explicit plugin instance identity. Controller request and response schemas, auth image refs, build payloads, dev-shell websocket forwarding, Docker labels, container env, and shared probe metadata now carry plugin_id, instance_id, and driver_id.

The controller now rejects mismatched plugin or driver identity, uses PLUGIN_INSTANCE_ID instead of TOOL_PERSONA_ID in auth containers, and labels containers/images with current plugin and driver keys. The app-side auth container client and session helpers send the new payload shape without accepting the old persona_id request field.

Validated with: pytest for the container image controller client, AI tool auth containers, and container image controller integration files; compileall for touched controller/app/contract/test modules; git diff --check; targeted cleanup search for removed tool-auth persona fields, env vars, labels, and probe keys in the edited boundary.
Update the AI harness runtime/status layer to project current plugin instance identity through auth runtime summaries, raw probe normalization, storage inventory, setup details, generic auth helpers, and system report rows. Runtime/status models now carry plugin_id, instance_id, and driver_id without a persona_id field, while later runner and review-policy persona cleanup remains explicitly scoped to follow-up plan steps.

Validated with: pytest for the AI tool instance suite, focused homepage runtime/status cases, the configured harness plugin catalog case, AI tool schema unit tests, compileall for the touched backend/test modules, git diff --check, and targeted persona cleanup searches.
Author
Owner

CodeSnuffler review banner

CodeSnuffler Review Findings

Recommendation Risk Open findings Files touched by findings
Request Changes Medium 1 1

Findings

1. Dev-shell auth ignores selected non-primary instance

Severity Category Confidence Location Status
Medium Correctness 94% app/dev_shell.py:320 Open

Details for this finding were posted as an inline review comment on the changed line.

Open finding in CodeSnuffler

Fix via CodeSnuffler

![CodeSnuffler review banner](https://auth.codesnuffler.com/codesnuffler_review/assets/banner_mediumIssues) ## CodeSnuffler Review Findings | Recommendation | Risk | Open findings | Files touched by findings | | --- | --- | ---: | ---: | | Request Changes | Medium | 1 | 1 | ### Findings #### 1. Dev-shell auth ignores selected non-primary instance | Severity | Category | Confidence | Location | Status | | --- | --- | ---: | --- | --- | | Medium | Correctness | 94% | `app/dev_shell.py:320` | Open | Details for this finding were posted as an [inline review comment](https://forgejo.codesnuffler.com/jason-admin/CodeSnuffler-FJ/pulls/67#issuecomment-257) on the changed line. [Open finding in CodeSnuffler](https://auth.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-67/findings/3) [Fix via CodeSnuffler](https://auth.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-67/findings/3/fix)
@ -316,3 +318,3 @@
async def dev_shell_websocket(websocket: WebSocket) -> None:
command_id = websocket.query_params.get("command", "bash")
persona_id = websocket.query_params.get("persona_id")
instance_id = websocket.query_params.get("instance_id")
Author
Owner

CodeSnuffler finding: Dev-shell auth ignores selected non-primary instance

Severity: Medium Category: Correctness

dev_shell_websocket now reads only the instance_id query parameter, but the current dev-shell terminal client still sends persona_id. For login commands launched from the UI with a non-primary instance, instance_id is None, so _proxy_runner_auth_session defaults to primary and creates/updates credentials in the wrong auth storage directory. Update the client to send instance_id for these auth websocket URLs and adjust the related tests; avoid reintroducing a persona_id fallback under the no-compatibility-shim policy.

Commit: Open commit d8a3fc420b05

Open finding in CodeSnuffler

Fix via CodeSnuffler

Suggested fix: Change the dev-shell frontend websocket URL builder from persona_id to instance_id, and update tests to cover a non-primary instance login command.

**CodeSnuffler finding:** Dev-shell auth ignores selected non-primary instance Severity: **Medium** Category: **Correctness** `dev_shell_websocket` now reads only the `instance_id` query parameter, but the current dev-shell terminal client still sends `persona_id`. For login commands launched from the UI with a non-primary instance, `instance_id` is `None`, so `_proxy_runner_auth_session` defaults to `primary` and creates/updates credentials in the wrong auth storage directory. Update the client to send `instance_id` for these auth websocket URLs and adjust the related tests; avoid reintroducing a `persona_id` fallback under the no-compatibility-shim policy. Commit: [Open commit `d8a3fc420b05`](https://forgejo.codesnuffler.com/jason-admin/CodeSnuffler-FJ/commit/d8a3fc420b055e04df1d203706b89b1f1261a9c1) [Open finding in CodeSnuffler](https://auth.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-67/findings/3) [Fix via CodeSnuffler](https://auth.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-67/findings/3/fix) **Suggested fix:** Change the dev-shell frontend websocket URL builder from `persona_id` to `instance_id`, and update tests to cover a non-primary instance login command.
jason-admin closed this pull request 2026-07-15 09:27:43 +00:00

Pull request closed

Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
jason-admin/CodeSnuffler-FJ!67
No description provided.