CodeSnuffler Forgejo End-to-End historical review range codesnuffler-forgejo-live-20260713T193414948Z-3a29b1bf-33d #61

Closed
jason-admin wants to merge 2 commits from change_forgejo_end_to_end into base_forgejo_end_to_end
Owner

Exercise the live Forgejo webhook review pipeline against a stable historical CodeSnuffler diff.

Run marker: codesnuffler-forgejo-live-20260713T193414948Z-3a29b1bf-33d.
Run started at: 2026-07-13T19:34:14.948Z.

Fixture range: f9d210eccd0075b6b39b606cea9b1376719aa062..d8a3fc420b055e04df1d203706b89b1f1261a9c1.
This stable two-commit AI Harness range is expected to produce actionable findings.

Exercise the live Forgejo webhook review pipeline against a stable historical CodeSnuffler diff. Run marker: codesnuffler-forgejo-live-20260713T193414948Z-3a29b1bf-33d. Run started at: 2026-07-13T19:34:14.948Z. Fixture range: f9d210eccd0075b6b39b606cea9b1376719aa062..d8a3fc420b055e04df1d203706b89b1f1261a9c1. This stable two-commit AI Harness range is expected to produce actionable findings.
This completes Step 12 of the AI harness plugin-instance plan by replacing the tool auth container session contract's persona field with explicit plugin instance identity. Controller request and response schemas, auth image refs, build payloads, dev-shell websocket forwarding, Docker labels, container env, and shared probe metadata now carry plugin_id, instance_id, and driver_id.

The controller now rejects mismatched plugin or driver identity, uses PLUGIN_INSTANCE_ID instead of TOOL_PERSONA_ID in auth containers, and labels containers/images with current plugin and driver keys. The app-side auth container client and session helpers send the new payload shape without accepting the old persona_id request field.

Validated with: pytest for the container image controller client, AI tool auth containers, and container image controller integration files; compileall for touched controller/app/contract/test modules; git diff --check; targeted cleanup search for removed tool-auth persona fields, env vars, labels, and probe keys in the edited boundary.
Update the AI harness runtime/status layer to project current plugin instance identity through auth runtime summaries, raw probe normalization, storage inventory, setup details, generic auth helpers, and system report rows. Runtime/status models now carry plugin_id, instance_id, and driver_id without a persona_id field, while later runner and review-policy persona cleanup remains explicitly scoped to follow-up plan steps.

Validated with: pytest for the AI tool instance suite, focused homepage runtime/status cases, the configured harness plugin catalog case, AI tool schema unit tests, compileall for the touched backend/test modules, git diff --check, and targeted persona cleanup searches.
Author
Owner

CodeSnuffler review banner

CodeSnuffler Review Findings

Recommendation Risk Open findings Files touched by findings
Request Changes Medium 2 2

Findings

1. Dev-shell auth ignores selected plugin instance

Severity Category Confidence Location Status
Medium Correctness 94% app/dev_shell.py:320 Open

Details for this finding were posted as an inline review comment on the changed line.

Open finding in CodeSnuffler

Fix via CodeSnuffler

2. Legacy persona alias remains in runtime model

Severity Category Confidence Location Status
Medium Maintainability 88% app/ai_tools/instances.py:226-227 Open

The PR standardizes auth identity to instance_id, but AiToolInstanceConfig.persona_id remains as a runtime alias and several call sites still use it. The repository instructions explicitly forbid retaining compatibility aliases/fallbacks when a field is standardized away; this keeps the old shape alive and makes future cleanup ambiguous.

Open finding in CodeSnuffler

Fix via CodeSnuffler

Suggested fix: Remove the persona_id property and update remaining config.persona_id/persona_id= runtime call sites to use instance_id; keep only rejection tests/docs for legacy payloads if needed.

![CodeSnuffler review banner](https://development.codesnuffler.com/codesnuffler_review/assets/banner_mediumIssues) ## CodeSnuffler Review Findings | Recommendation | Risk | Open findings | Files touched by findings | | --- | --- | ---: | ---: | | Request Changes | Medium | 2 | 2 | ### Findings #### 1. Dev-shell auth ignores selected plugin instance | Severity | Category | Confidence | Location | Status | | --- | --- | ---: | --- | --- | | Medium | Correctness | 94% | `app/dev_shell.py:320` | Open | Details for this finding were posted as an [inline review comment](https://forgejo.codesnuffler.com/jason-admin/CodeSnuffler-FJ/pulls/61#issuecomment-232) on the changed line. [Open finding in CodeSnuffler](https://development.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-61/findings/2) [Fix via CodeSnuffler](https://development.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-61/findings/2/fix) #### 2. Legacy persona alias remains in runtime model | Severity | Category | Confidence | Location | Status | | --- | --- | ---: | --- | --- | | Medium | Maintainability | 88% | `app/ai_tools/instances.py:226-227` | Open | The PR standardizes auth identity to `instance_id`, but `AiToolInstanceConfig.persona_id` remains as a runtime alias and several call sites still use it. The repository instructions explicitly forbid retaining compatibility aliases/fallbacks when a field is standardized away; this keeps the old shape alive and makes future cleanup ambiguous. [Open finding in CodeSnuffler](https://development.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-61/findings/3) [Fix via CodeSnuffler](https://development.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-61/findings/3/fix) **Suggested fix:** Remove the `persona_id` property and update remaining `config.persona_id`/`persona_id=` runtime call sites to use `instance_id`; keep only rejection tests/docs for legacy payloads if needed.
@ -316,3 +318,3 @@
async def dev_shell_websocket(websocket: WebSocket) -> None:
command_id = websocket.query_params.get("command", "bash")
persona_id = websocket.query_params.get("persona_id")
instance_id = websocket.query_params.get("instance_id")
Author
Owner

CodeSnuffler finding: Dev-shell auth ignores selected plugin instance

Severity: Medium Category: Correctness

dev_shell_websocket now reads instance_id, but frontend/src/dev-shell/components/DevShellTerminal.vue still sends the selected setup instance as persona_id. In the AI tool setup flow this means interactive login sessions for non-primary instances fall back to primary, so credentials are written/read from the wrong auth storage.

Commit: Open commit d8a3fc420b05

Open finding in CodeSnuffler

Fix via CodeSnuffler

Suggested fix: Update the frontend websocket query parameter to instance_id where DevShellTerminal builds the URL, and cover a non-primary setup/login case.

**CodeSnuffler finding:** Dev-shell auth ignores selected plugin instance Severity: **Medium** Category: **Correctness** `dev_shell_websocket` now reads `instance_id`, but `frontend/src/dev-shell/components/DevShellTerminal.vue` still sends the selected setup instance as `persona_id`. In the AI tool setup flow this means interactive login sessions for non-primary instances fall back to `primary`, so credentials are written/read from the wrong auth storage. Commit: [Open commit `d8a3fc420b05`](https://forgejo.codesnuffler.com/jason-admin/CodeSnuffler-FJ/commit/d8a3fc420b055e04df1d203706b89b1f1261a9c1) [Open finding in CodeSnuffler](https://development.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-61/findings/2) [Fix via CodeSnuffler](https://development.codesnuffler.com/codesnuffler_review/forgejo-jason-admin-CodeSnuffler-FJ-pr-61/findings/2/fix) **Suggested fix:** Update the frontend websocket query parameter to `instance_id` where `DevShellTerminal` builds the URL, and cover a non-primary setup/login case.
jason-admin closed this pull request 2026-07-13 19:39:05 +00:00

Pull request closed

Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
jason-admin/CodeSnuffler-FJ!61
No description provided.