CodeSnuffler Forgejo End-to-End historical review range codesnuffler-forgejo-live-20260711T105227629Z-a93dd2a2-fd4 #58

Closed
jason-admin wants to merge 2 commits from change_forgejo_end_to_end into base_forgejo_end_to_end
Owner

Exercise the live Forgejo webhook review pipeline against a stable historical CodeSnuffler diff.

Run marker: codesnuffler-forgejo-live-20260711T105227629Z-a93dd2a2-fd4.
Run started at: 2026-07-11T10:52:27.629Z.

Fixture range: f9d210eccd0075b6b39b606cea9b1376719aa062..d8a3fc420b055e04df1d203706b89b1f1261a9c1.
This stable two-commit AI Harness range is expected to produce actionable findings.

Exercise the live Forgejo webhook review pipeline against a stable historical CodeSnuffler diff. Run marker: codesnuffler-forgejo-live-20260711T105227629Z-a93dd2a2-fd4. Run started at: 2026-07-11T10:52:27.629Z. Fixture range: f9d210eccd0075b6b39b606cea9b1376719aa062..d8a3fc420b055e04df1d203706b89b1f1261a9c1. This stable two-commit AI Harness range is expected to produce actionable findings.
This completes Step 12 of the AI harness plugin-instance plan by replacing the tool auth container session contract's persona field with explicit plugin instance identity. Controller request and response schemas, auth image refs, build payloads, dev-shell websocket forwarding, Docker labels, container env, and shared probe metadata now carry plugin_id, instance_id, and driver_id.

The controller now rejects mismatched plugin or driver identity, uses PLUGIN_INSTANCE_ID instead of TOOL_PERSONA_ID in auth containers, and labels containers/images with current plugin and driver keys. The app-side auth container client and session helpers send the new payload shape without accepting the old persona_id request field.

Validated with: pytest for the container image controller client, AI tool auth containers, and container image controller integration files; compileall for touched controller/app/contract/test modules; git diff --check; targeted cleanup search for removed tool-auth persona fields, env vars, labels, and probe keys in the edited boundary.
Update the AI harness runtime/status layer to project current plugin instance identity through auth runtime summaries, raw probe normalization, storage inventory, setup details, generic auth helpers, and system report rows. Runtime/status models now carry plugin_id, instance_id, and driver_id without a persona_id field, while later runner and review-policy persona cleanup remains explicitly scoped to follow-up plan steps.

Validated with: pytest for the AI tool instance suite, focused homepage runtime/status cases, the configured harness plugin catalog case, AI tool schema unit tests, compileall for the touched backend/test modules, git diff --check, and targeted persona cleanup searches.
Author
Owner

CodeSnuffler review banner

CodeSnuffler Review Findings

Recommendation Risk Open findings Files touched by findings
Request Changes Medium 2 2

Findings

1. Dev-shell auth ignores existing frontend persona query parameter

Severity Category Confidence Location Status
High Correctness 95% app/dev_shell.py:320-356 Open

Details for this finding were posted as an inline review comment on the changed line.

Open finding in CodeSnuffler

Fix via CodeSnuffler

2. Persona field remains in public AI review policy schema

Severity Category Confidence Location Status
Medium Maintainability 90% app/settings/ai_review_policy/schemas.py:72-77 Open

This PR removes persona_id from several AI tool contracts, but AiReviewPolicyAiToolInstanceChoiceResponse still exposes persona_id, and the generated frontend type still contains it. The repository instructions explicitly require removing old fields and generated frontend API types when standardizing a schema shape, so this leaves a stale public contract and frontend consumers on the removed naming.

Open finding in CodeSnuffler

Fix via CodeSnuffler

Suggested fix: Replace persona_id with the current identity fields needed by the UI, at minimum instance_id, regenerate frontend API types, and update AI review policy frontend consumers to use the new field names.

![CodeSnuffler review banner](https://ops.codesnuffler.com/codesnuffler_review/assets/banner_majorIssues) ## CodeSnuffler Review Findings | Recommendation | Risk | Open findings | Files touched by findings | | --- | --- | ---: | ---: | | Request Changes | Medium | 2 | 2 | ### Findings #### 1. Dev-shell auth ignores existing frontend persona query parameter | Severity | Category | Confidence | Location | Status | | --- | --- | ---: | --- | --- | | High | Correctness | 95% | `app/dev_shell.py:320-356` | Open | Details for this finding were posted as an [inline review comment](https://forgejo.codesnuffler.com/jason-admin/CodeSnuffler-FJ/pulls/58#issuecomment-220) on the changed line. [Open finding in CodeSnuffler](https://ops.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-58/findings/2) [Fix via CodeSnuffler](https://ops.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-58/findings/2/fix) #### 2. Persona field remains in public AI review policy schema | Severity | Category | Confidence | Location | Status | | --- | --- | ---: | --- | --- | | Medium | Maintainability | 90% | `app/settings/ai_review_policy/schemas.py:72-77` | Open | This PR removes `persona_id` from several AI tool contracts, but `AiReviewPolicyAiToolInstanceChoiceResponse` still exposes `persona_id`, and the generated frontend type still contains it. The repository instructions explicitly require removing old fields and generated frontend API types when standardizing a schema shape, so this leaves a stale public contract and frontend consumers on the removed naming. [Open finding in CodeSnuffler](https://ops.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-58/findings/3) [Fix via CodeSnuffler](https://ops.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-58/findings/3/fix) **Suggested fix:** Replace `persona_id` with the current identity fields needed by the UI, at minimum `instance_id`, regenerate frontend API types, and update AI review policy frontend consumers to use the new field names.
@ -316,3 +318,3 @@
async def dev_shell_websocket(websocket: WebSocket) -> None:
command_id = websocket.query_params.get("command", "bash")
persona_id = websocket.query_params.get("persona_id")
instance_id = websocket.query_params.get("instance_id")
Author
Owner

CodeSnuffler finding: Dev-shell auth ignores existing frontend persona query parameter

Severity: High Category: Correctness

The websocket now only reads instance_id, but the current dev-shell frontend still sends persona_id when opening a login shell. For non-primary plugin instances, login/auth sessions will silently use the default primary storage instead of the selected instance, so credentials can be written to or read from the wrong auth directory. Update the frontend query parameter and generated/consuming types together, or otherwise keep this boundary consistent with the new instance_id contract.

Commit: Open commit d8a3fc420b05

Open finding in CodeSnuffler

Fix via CodeSnuffler

Suggested fix: Change frontend/src/dev-shell/components/DevShellTerminal.vue to send instance_id and update any callers/props naming that still expose personaId for this websocket flow.

**CodeSnuffler finding:** Dev-shell auth ignores existing frontend persona query parameter Severity: **High** Category: **Correctness** The websocket now only reads `instance_id`, but the current dev-shell frontend still sends `persona_id` when opening a login shell. For non-primary plugin instances, login/auth sessions will silently use the default `primary` storage instead of the selected instance, so credentials can be written to or read from the wrong auth directory. Update the frontend query parameter and generated/consuming types together, or otherwise keep this boundary consistent with the new `instance_id` contract. Commit: [Open commit `d8a3fc420b05`](https://forgejo.codesnuffler.com/jason-admin/CodeSnuffler-FJ/commit/d8a3fc420b055e04df1d203706b89b1f1261a9c1) [Open finding in CodeSnuffler](https://ops.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-58/findings/2) [Fix via CodeSnuffler](https://ops.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-58/findings/2/fix) **Suggested fix:** Change `frontend/src/dev-shell/components/DevShellTerminal.vue` to send `instance_id` and update any callers/props naming that still expose `personaId` for this websocket flow.
jason-admin closed this pull request 2026-07-11 10:56:46 +00:00

Pull request closed

Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
jason-admin/CodeSnuffler-FJ!58
No description provided.