Fix bundled Claude and Codex usage with isolated provider state - #2623
Conversation
|
/review |
|
✅ AI Code Review Complete requested by @integry Posted 1 review: |
🔍 AI Code Review — codex:gpt-6-astraOverall EvaluationThe PR addresses the provider-home failures with a small, shared preparation helper. It needs a localized packaging correction before merge. ✅ Private provider state — The helper copies only the two authentication files, sets directory/file permissions to 0700/0600, and preserves AGY’s configuration path. ✅ Consistent execution — Production and both verifier modes invoke the preparation helper before Agent Tank. ✅ Safe failure reporting — Preparation failures remove the runtime directory and emit a generic message without configuration contents. The supplied current-head status reports 20 passed checks and no failed or pending checks. This review used static analysis only, as requested. Merge blockersEvery finding below was introduced by this PR and must be resolved before merging. F1: 🔴 Include the helper in app packaging
SuggestionsThese are optional follow-ups and are not sent to S1: 🟢 Exercise cleanup after a successful copyThe failure test supplies an invalid first entry, so it verifies directory cleanup without first creating a credential copy. An additional case with a valid first provider and an invalid second provider would directly verify that already-copied credentials are removed. This is optional because the existing catch block statically covers that cleanup. ScoreThe runtime change is focused and implements the requested isolation well, but the missing production packaging update leaves the new hash contract inconsistent. The supplied checks are green; the packaging correction remains necessary. Score: 6/10 🤖 Review Details
🤖 Review by ProPR |
|
/ultrafix |
|
🔄 Ultrafix loop started (goal: 8/10, max cycles: 10) First action:
|
|
✅ Applied the requested follow-up changes in commit 84aa66d
Summary of ChangesAddressed F1 only: added the helper COPY to the production app’s runtime stage at the expected hash path. Strengthened the packaging regression to verify runtime-stage placement and destinations. All 14 bundle-content and supply-chain tests passed; 🤖 Implementation Details
Undo Changes • View Task Execution 💡 ProPR Slash Commands
🤖 Generated by ProPR |
…app’s runtime stage at the expected hash path. Strengthened the packaging regression to verify runtime-stage placement and destinations. Addressed F1 only: added the helper COPY to the production app’s runtime stage at the expected hash path. Strengthened the packaging regression to verify runtime-stage placement and destinations. All 14 bundle-content and supply-chain tests passed; `git diff --check` passed. No visual preview was needed. PR: #2623 Comment by: @integry (ID: 5889350886) Model: gpt-6-astra
|
✅ AI Code Review Complete requested by @propr-ultrafix Posted 1 review: |
🔍 AI Code Review — codex:gpt-6-astraOverall EvaluationReady to merge within scope. The change addresses the reported provider initialization failures with a small, shared runtime preparation helper. ✅ Private provider state — Claude and Codex receive only their authentication files in mode-0700 directories, with copies restricted to mode 0600. AGY retains its existing configuration path. ✅ Consistent image integration — Production and verifier bootstraps invoke the helper; both image-content hash lists and the production build context include it. ✅ Controlled failure behavior — Preparation errors remove the private runtime directory and produce a fixed error message without exposing configuration. This assessment uses static review of the supplied code; no commands were run. Authoritative current checks show 20 passed, no failures, and no pending checks. Merge blockersNo merge blockers. SuggestionsThese are optional follow-ups and are not sent to S2: 🟢 Exercise cleanup after a copyIn ScoreThe implementation satisfies the scoped objective, preserves read-only host mounts, and integrates the helper consistently across runtime and image packaging. Supplied validation and current checks support merge readiness, with no verified blocker. Score: 9/10 🤖 Review Details
🤖 Review by ProPR |
8b04403
into
2547/claude-opus-5-bundle-agent-tank-into-th-20260926-1849-t18
Bundled Agent Tank returned null Claude/Codex usage despite passing the mocked suites. Codex's app-server failed to initialize its SQLite state under the read-only credential mount; Claude's interactive path expected configuration absent from that mount.
Prepare private writable provider homes inside the disposable container, copying only Claude's
.credentials.jsonand Codex'sauth.json. Enable Agent Tank's existing direct Claude usage API. Keep original host mounts read-only, exclude host sessions/databases/plugins/MCP configuration, and leave AGY's working path unchanged. Credential copies have mode 0600 in private mode-0700 directories and are removed with the container. The preparation script is included in both image-content hash lists and used by production and the live verifier.This PR targets #2555's branch so it can be incorporated before that PR merges. Agent Tank remains pinned to 0.9.11; no Agent Tank source or release change is required.
Validation:
node, read-only host mounts, and an unchanged credential manifest.No staging deployment was performed. The API and matching agent image must be rolled out together because the updated runner invokes the new image helper.