fix(cloud-agent-next): apply resolved git author in control plane - #6795
Merged
Merged
Conversation
…d git author Control-plane (cloud-agent-web) sessions never applied the resolved GitHub author to the worktree, so commits always used the generic fallback identity (Kilo Code Cloud / agent@kilocode.ai) instead of the user or App bot. Carry the resolved gitAuthor through the session credential grant into the attach payload, apply it in the wrapper on first clone and on worktree reuse, and gate it behind a wrapper hello capability so older warm sandboxes keep working (the payload schema is strict).
Contributor
Code Review SummaryStatus: No Issues Found | Recommendation: Merge Executive SummaryThe incremental commit is a test-only update that realigns warm-reuse git expectations with the already-gated author write; both previously flagged findings are verified fixed at HEAD. Files Reviewed (4 files)
Previous Review Summaries (2 snapshots, latest commit 073ee13)Current summary above is authoritative. Previous snapshots are kept for context only. Previous review (commit 073ee13)Status: No Issues Found | Recommendation: Merge Executive SummaryThe incremental commit correctly restores the resolved git author on the legacy GitHub installation path and gates the warm-reuse author rewrite; no new issues found in the changed lines. Files Reviewed (6 files)
Previous review (commit 1de0bf1)Status: 2 Issues Found | Recommendation: Address before merge Overview
Issue Details (click to expand)WARNING
Files Reviewed (14 files)
Reviewed by deepseek-v4.1-flash · Input: 0 · Output: 0 · Cached: 0 Review guidance: REVIEW.md from base branch |
chrarnoldus
approved these changes
Sep 28, 2026
Resolve two review findings on the control-plane git author work: - Supply the installation App bot author from env in the legacy GitHub auth fallback, so the control plane attributes commits correctly when the git-token-service binding lacks getCloudAgentAuthForRepo. Share the helper with the legacy plane instead of duplicating it. - Only rewrite the workspace git author on warm reuse when a resolved author is present, so reuse without one stays a no-op and does not overwrite an identity set by setup commands.
The warm-reuse author write is now gated on a resolved author, so the managed-token refresh path no longer issues the two fallback git config calls. Restore the pre-existing runGit count and last-call assertions.
This was referenced Sep 27, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Control-plane (
cloud-agent-web) sessions never applied the resolved GitHub author to the worktree, so every agent commit used the generic fallback identity (Kilo Code Cloud/agent@kilocode.ai) instead of the user's connected identity or the App bot.authorto the attach payloadgitblock and agitAuthorwrapper capability.gitAuthorthrough the session credential grant (scm.author) for contained-capability, contained-direct, and non-contained GitHub resolution, and emit it in the prepared payload. Reject it for non-GitHub SCM.alreadyBootstrappedworktree-reuse path.authoron the advertised capability so an older warm wrapper (strict payload schema) keeps working; the worker strips it when unsupported, mirroring the existingworkingBranchesgate.Verification
pnpm run typecheck(tsgo + wrapper) — pass.pnpm run test— 253 files, 7709 passed / 3 skipped.bun test— 1734 passed.test/integration/sandbox-control.test.ts— 346 passed;sandbox-attach-recovery+sandbox-control-seam— 20 passed.src/wrapper/src.Visual Changes
N/A
Reviewer Notes
allowUserAuthorization(true forcloud-agent-web/slack) and falls back to the App bot otherwise. Vercel contained sessions keepallowUserAuthorization: false.commitCoAuthortrailer, so the App bot is not credited as co-author when the user identity is used.test/integration/sandbox-control.test.tsare excluded by the package lint glob; the changedsrc/wrapper/srcfiles are clean.