CodeSnuffler Forgejo End-to-End historical review range codesnuffler-forgejo-live-20260720T224743794Z-4cd3c742-3a3 #72

Closed
jason-admin wants to merge 2 commits from change_forgejo_end_to_end into base_forgejo_end_to_end
Owner

Exercise the live Forgejo webhook review pipeline against a stable historical CodeSnuffler diff.

Run marker: codesnuffler-forgejo-live-20260720T224743794Z-4cd3c742-3a3.
Run started at: 2026-07-20T22:47:43.794Z.

Fixture range: f9d210eccd0075b6b39b606cea9b1376719aa062..d8a3fc420b055e04df1d203706b89b1f1261a9c1.
This stable two-commit AI Harness range is expected to produce actionable findings.

Exercise the live Forgejo webhook review pipeline against a stable historical CodeSnuffler diff. Run marker: codesnuffler-forgejo-live-20260720T224743794Z-4cd3c742-3a3. Run started at: 2026-07-20T22:47:43.794Z. Fixture range: f9d210eccd0075b6b39b606cea9b1376719aa062..d8a3fc420b055e04df1d203706b89b1f1261a9c1. This stable two-commit AI Harness range is expected to produce actionable findings.
This completes Step 12 of the AI harness plugin-instance plan by replacing the tool auth container session contract's persona field with explicit plugin instance identity. Controller request and response schemas, auth image refs, build payloads, dev-shell websocket forwarding, Docker labels, container env, and shared probe metadata now carry plugin_id, instance_id, and driver_id.

The controller now rejects mismatched plugin or driver identity, uses PLUGIN_INSTANCE_ID instead of TOOL_PERSONA_ID in auth containers, and labels containers/images with current plugin and driver keys. The app-side auth container client and session helpers send the new payload shape without accepting the old persona_id request field.

Validated with: pytest for the container image controller client, AI tool auth containers, and container image controller integration files; compileall for touched controller/app/contract/test modules; git diff --check; targeted cleanup search for removed tool-auth persona fields, env vars, labels, and probe keys in the edited boundary.
Update the AI harness runtime/status layer to project current plugin instance identity through auth runtime summaries, raw probe normalization, storage inventory, setup details, generic auth helpers, and system report rows. Runtime/status models now carry plugin_id, instance_id, and driver_id without a persona_id field, while later runner and review-policy persona cleanup remains explicitly scoped to follow-up plan steps.

Validated with: pytest for the AI tool instance suite, focused homepage runtime/status cases, the configured harness plugin catalog case, AI tool schema unit tests, compileall for the touched backend/test modules, git diff --check, and targeted persona cleanup searches.
Author
Owner

CodeSnuffler review banner

CodeSnuffler Review Findings

Recommendation Risk Open findings Files touched by findings
Request Changes Medium 2 2

Findings

1. Dev shell auth sessions ignore selected non-primary instance

Severity Category Confidence Location Status
Medium Correctness 94% app/dev_shell.py:320 Open

Details for this finding were posted as an inline review comment on the changed line.

Open finding in CodeSnuffler

Fix via CodeSnuffler

2. Auth container env no longer matches documented contract

Severity Category Confidence Location Status
Medium Correctness 82% container_image_controller/api.py:971-973 Open

Details for this finding were posted as an inline review comment on the changed line.

Open finding in CodeSnuffler

Fix via CodeSnuffler

![CodeSnuffler review banner](https://frontend.codesnuffler.com/codesnuffler_review/assets/banner_mediumIssues) ## CodeSnuffler Review Findings | Recommendation | Risk | Open findings | Files touched by findings | | --- | --- | ---: | ---: | | Request Changes | Medium | 2 | 2 | ### Findings #### 1. Dev shell auth sessions ignore selected non-primary instance | Severity | Category | Confidence | Location | Status | | --- | --- | ---: | --- | --- | | Medium | Correctness | 94% | `app/dev_shell.py:320` | Open | Details for this finding were posted as an [inline review comment](https://forgejo.codesnuffler.com/jason-admin/CodeSnuffler-FJ/pulls/72#issuecomment-280) on the changed line. [Open finding in CodeSnuffler](https://frontend.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-72/findings/2) [Fix via CodeSnuffler](https://frontend.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-72/findings/2/fix) #### 2. Auth container env no longer matches documented contract | Severity | Category | Confidence | Location | Status | | --- | --- | ---: | --- | --- | | Medium | Correctness | 82% | `container_image_controller/api.py:971-973` | Open | Details for this finding were posted as an [inline review comment](https://forgejo.codesnuffler.com/jason-admin/CodeSnuffler-FJ/pulls/72#issuecomment-282) on the changed line. [Open finding in CodeSnuffler](https://frontend.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-72/findings/3) [Fix via CodeSnuffler](https://frontend.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-72/findings/3/fix)
@ -316,3 +318,3 @@
async def dev_shell_websocket(websocket: WebSocket) -> None:
command_id = websocket.query_params.get("command", "bash")
persona_id = websocket.query_params.get("persona_id")
instance_id = websocket.query_params.get("instance_id")
Author
Owner

CodeSnuffler finding: Dev shell auth sessions ignore selected non-primary instance

Severity: Medium Category: Correctness

The websocket route now only reads instance_id, but the existing frontend dev-shell terminal still sends persona_id. Any login terminal opened for a non-primary AI tool instance will arrive here with instance_id == None and _proxy_runner_auth_session will default to primary, writing auth into the wrong instance storage.

Commit: Open commit d8a3fc420b05

Open finding in CodeSnuffler

Fix via CodeSnuffler

Suggested fix: Update the dev-shell client/frontend to send instance_id and add coverage for a non-primary login command preserving that value end to end.

**CodeSnuffler finding:** Dev shell auth sessions ignore selected non-primary instance Severity: **Medium** Category: **Correctness** The websocket route now only reads `instance_id`, but the existing frontend dev-shell terminal still sends `persona_id`. Any login terminal opened for a non-primary AI tool instance will arrive here with `instance_id == None` and `_proxy_runner_auth_session` will default to `primary`, writing auth into the wrong instance storage. Commit: [Open commit `d8a3fc420b05`](https://forgejo.codesnuffler.com/jason-admin/CodeSnuffler-FJ/commit/d8a3fc420b055e04df1d203706b89b1f1261a9c1) [Open finding in CodeSnuffler](https://frontend.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-72/findings/2) [Fix via CodeSnuffler](https://frontend.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-72/findings/2/fix) **Suggested fix:** Update the dev-shell client/frontend to send `instance_id` and add coverage for a non-primary login command preserving that value end to end.
@ -945,3 +970,2 @@
env = [
f"TOOL_ID={profile.tool_id}",
f"TOOL_PERSONA_ID={session.persona_id}",
f"DRIVER_ID={profile.tool_id}",
Author
Owner

CodeSnuffler finding: Auth container env no longer matches documented contract

Severity: Medium Category: Correctness

The controller now emits DRIVER_ID and removed TOOL_ID, while the repository's runtime contract documents TOOL_ID, PLUGIN_ID, PLUGIN_INSTANCE_ID, and AI_TOOL_DRIVER_ID. Auth adapter commands or shell flows written against that contract will not receive the documented driver/tool variables.

Commit: Open commit d8a3fc420b05

Open finding in CodeSnuffler

Fix via CodeSnuffler

Suggested fix: Make the emitted env names match the current contract, or update the contract and all consumers/tests in the same change. Avoid leaving both old and new names unless compatibility is explicitly requested.

**CodeSnuffler finding:** Auth container env no longer matches documented contract Severity: **Medium** Category: **Correctness** The controller now emits `DRIVER_ID` and removed `TOOL_ID`, while the repository's runtime contract documents `TOOL_ID`, `PLUGIN_ID`, `PLUGIN_INSTANCE_ID`, and `AI_TOOL_DRIVER_ID`. Auth adapter commands or shell flows written against that contract will not receive the documented driver/tool variables. Commit: [Open commit `d8a3fc420b05`](https://forgejo.codesnuffler.com/jason-admin/CodeSnuffler-FJ/commit/d8a3fc420b055e04df1d203706b89b1f1261a9c1) [Open finding in CodeSnuffler](https://frontend.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-72/findings/3) [Fix via CodeSnuffler](https://frontend.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-72/findings/3/fix) **Suggested fix:** Make the emitted env names match the current contract, or update the contract and all consumers/tests in the same change. Avoid leaving both old and new names unless compatibility is explicitly requested.
jason-admin closed this pull request 2026-07-20 22:54:24 +00:00

Pull request closed

Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
jason-admin/CodeSnuffler-FJ!72
No description provided.