CodeSnuffler Forgejo End-to-End historical review range codesnuffler-forgejo-live-20260715T100138902Z-7e327c5c-91c #70

Closed
jason-admin wants to merge 2 commits from change_forgejo_end_to_end into base_forgejo_end_to_end
Owner

Exercise the live Forgejo webhook review pipeline against a stable historical CodeSnuffler diff.

Run marker: codesnuffler-forgejo-live-20260715T100138902Z-7e327c5c-91c.
Run started at: 2026-07-15T10:01:38.902Z.

Fixture range: f9d210eccd0075b6b39b606cea9b1376719aa062..d8a3fc420b055e04df1d203706b89b1f1261a9c1.
This stable two-commit AI Harness range is expected to produce actionable findings.

Exercise the live Forgejo webhook review pipeline against a stable historical CodeSnuffler diff. Run marker: codesnuffler-forgejo-live-20260715T100138902Z-7e327c5c-91c. Run started at: 2026-07-15T10:01:38.902Z. Fixture range: f9d210eccd0075b6b39b606cea9b1376719aa062..d8a3fc420b055e04df1d203706b89b1f1261a9c1. This stable two-commit AI Harness range is expected to produce actionable findings.
This completes Step 12 of the AI harness plugin-instance plan by replacing the tool auth container session contract's persona field with explicit plugin instance identity. Controller request and response schemas, auth image refs, build payloads, dev-shell websocket forwarding, Docker labels, container env, and shared probe metadata now carry plugin_id, instance_id, and driver_id.

The controller now rejects mismatched plugin or driver identity, uses PLUGIN_INSTANCE_ID instead of TOOL_PERSONA_ID in auth containers, and labels containers/images with current plugin and driver keys. The app-side auth container client and session helpers send the new payload shape without accepting the old persona_id request field.

Validated with: pytest for the container image controller client, AI tool auth containers, and container image controller integration files; compileall for touched controller/app/contract/test modules; git diff --check; targeted cleanup search for removed tool-auth persona fields, env vars, labels, and probe keys in the edited boundary.
Update the AI harness runtime/status layer to project current plugin instance identity through auth runtime summaries, raw probe normalization, storage inventory, setup details, generic auth helpers, and system report rows. Runtime/status models now carry plugin_id, instance_id, and driver_id without a persona_id field, while later runner and review-policy persona cleanup remains explicitly scoped to follow-up plan steps.

Validated with: pytest for the AI tool instance suite, focused homepage runtime/status cases, the configured harness plugin catalog case, AI tool schema unit tests, compileall for the touched backend/test modules, git diff --check, and targeted persona cleanup searches.
Author
Owner

CodeSnuffler review banner

CodeSnuffler Review Findings

Recommendation Risk Open findings Files touched by findings
Request Changes High 2 2

Findings

1. Probe containers now receive controller profile instead of probe profile

Severity Category Confidence Location Status
High Correctness 95% container_image_controller/api.py:977 Open

Details for this finding were posted as an inline review comment on the changed line.

Open finding in CodeSnuffler

Fix via CodeSnuffler

2. Dev shell auth ignores selected plugin instance

Severity Category Confidence Location Status
Medium Correctness 90% app/dev_shell.py:320 Open

Details for this finding were posted as an inline review comment on the changed line.

Open finding in CodeSnuffler

Fix via CodeSnuffler

![CodeSnuffler review banner](https://auth.codesnuffler.com/codesnuffler_review/assets/banner_majorIssues) ## CodeSnuffler Review Findings | Recommendation | Risk | Open findings | Files touched by findings | | --- | --- | ---: | ---: | | Request Changes | High | 2 | 2 | ### Findings #### 1. Probe containers now receive controller profile instead of probe profile | Severity | Category | Confidence | Location | Status | | --- | --- | ---: | --- | --- | | High | Correctness | 95% | `container_image_controller/api.py:977` | Open | Details for this finding were posted as an [inline review comment](https://forgejo.codesnuffler.com/jason-admin/CodeSnuffler-FJ/pulls/70#issuecomment-269) on the changed line. [Open finding in CodeSnuffler](https://auth.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-70/findings/2) [Fix via CodeSnuffler](https://auth.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-70/findings/2/fix) #### 2. Dev shell auth ignores selected plugin instance | Severity | Category | Confidence | Location | Status | | --- | --- | ---: | --- | --- | | Medium | Correctness | 90% | `app/dev_shell.py:320` | Open | Details for this finding were posted as an [inline review comment](https://forgejo.codesnuffler.com/jason-admin/CodeSnuffler-FJ/pulls/70#issuecomment-271) on the changed line. [Open finding in CodeSnuffler](https://auth.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-70/findings/3) [Fix via CodeSnuffler](https://auth.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-70/findings/3/fix)
@ -949,3 +975,3 @@
f"TOOL_AUTH_STORAGE_KEY={session.auth_storage_key}",
f"TOOL_AUTH_HOST_PATH={host_dir}",
f"TOOL_AUTH_PROFILE_JSON={json.dumps(profile.probe_config(), sort_keys=True, separators=(',', ':'))}",
f"TOOL_AUTH_PROFILE_JSON={json.dumps(profile.controller_payload(), sort_keys=True, separators=(',', ':'))}",
Author
Owner

CodeSnuffler finding: Probe containers now receive controller profile instead of probe profile

Severity: High Category: Correctness

TOOL_AUTH_PROFILE_JSON is now populated with profile.controller_payload(), but the embedded probe code still parses that environment value as the probe profile and expects keys such as tool_container_paths and tool_container_mount_paths. controller_payload() emits paths and mounts instead, so probe/login code paths that call auth_path() or harden_tool_mounts() can fail with a missing path error at runtime. Keep the launched tool environment on profile.probe_config() or update the embedded probe code to consume the controller payload shape consistently.

Commit: Open commit d8a3fc420b05

Open finding in CodeSnuffler

Fix via CodeSnuffler

Suggested fix: Use profile.probe_config() for TOOL_AUTH_PROFILE_JSON, or introduce a separate env var for controller metadata if _harden_tool_profile_tree needs the controller payload.

**CodeSnuffler finding:** Probe containers now receive controller profile instead of probe profile Severity: **High** Category: **Correctness** `TOOL_AUTH_PROFILE_JSON` is now populated with `profile.controller_payload()`, but the embedded probe code still parses that environment value as the probe profile and expects keys such as `tool_container_paths` and `tool_container_mount_paths`. `controller_payload()` emits `paths` and `mounts` instead, so probe/login code paths that call `auth_path()` or `harden_tool_mounts()` can fail with a missing path error at runtime. Keep the launched tool environment on `profile.probe_config()` or update the embedded probe code to consume the controller payload shape consistently. Commit: [Open commit `d8a3fc420b05`](https://forgejo.codesnuffler.com/jason-admin/CodeSnuffler-FJ/commit/d8a3fc420b055e04df1d203706b89b1f1261a9c1) [Open finding in CodeSnuffler](https://auth.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-70/findings/2) [Fix via CodeSnuffler](https://auth.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-70/findings/2/fix) **Suggested fix:** Use `profile.probe_config()` for `TOOL_AUTH_PROFILE_JSON`, or introduce a separate env var for controller metadata if `_harden_tool_profile_tree` needs the controller payload.
@ -316,3 +318,3 @@
async def dev_shell_websocket(websocket: WebSocket) -> None:
command_id = websocket.query_params.get("command", "bash")
persona_id = websocket.query_params.get("persona_id")
instance_id = websocket.query_params.get("instance_id")
Author
Owner

CodeSnuffler finding: Dev shell auth ignores selected plugin instance

Severity: Medium Category: Correctness

The websocket now reads instance_id, but the existing frontend terminal URL still sends the selected value as persona_id. For non-primary AI tool instances, runner auth commands opened from the dev shell will fall back to primary and mount/login the wrong auth storage. Because this PR removes the old contract, update the frontend caller to send instance_id in the same change.

Commit: Open commit d8a3fc420b05

Open finding in CodeSnuffler

Fix via CodeSnuffler

Suggested fix: Update frontend/src/dev-shell/components/DevShellTerminal.vue to set instance_id instead of persona_id when building the dev-shell websocket URL.

**CodeSnuffler finding:** Dev shell auth ignores selected plugin instance Severity: **Medium** Category: **Correctness** The websocket now reads `instance_id`, but the existing frontend terminal URL still sends the selected value as `persona_id`. For non-primary AI tool instances, runner auth commands opened from the dev shell will fall back to `primary` and mount/login the wrong auth storage. Because this PR removes the old contract, update the frontend caller to send `instance_id` in the same change. Commit: [Open commit `d8a3fc420b05`](https://forgejo.codesnuffler.com/jason-admin/CodeSnuffler-FJ/commit/d8a3fc420b055e04df1d203706b89b1f1261a9c1) [Open finding in CodeSnuffler](https://auth.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-70/findings/3) [Fix via CodeSnuffler](https://auth.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-70/findings/3/fix) **Suggested fix:** Update `frontend/src/dev-shell/components/DevShellTerminal.vue` to set `instance_id` instead of `persona_id` when building the dev-shell websocket URL.
jason-admin closed this pull request 2026-07-15 10:08:04 +00:00

Pull request closed

Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
jason-admin/CodeSnuffler-FJ!70
No description provided.