Skip to content

fix(cloud-agent-next): apply resolved git author in control plane - #6795

Merged
eshurakov merged 3 commits into
mainfrom
eshurakov/honest-lark
Sep 28, 2026
Merged

eshurakov merged 3 commits into
mainfrom
eshurakov/honest-lark

Conversation

@eshurakov

Copy link
Copy Markdown
Contributor

Summary

Control-plane (cloud-agent-web) sessions never applied the resolved GitHub author to the worktree, so every agent commit used the generic fallback identity (Kilo Code Cloud / agent@kilocode.ai) instead of the user's connected identity or the App bot.

  • Add an optional author to the attach payload git block and a gitAuthor wrapper capability.
  • Carry the resolved gitAuthor through the session credential grant (scm.author) for contained-capability, contained-direct, and non-contained GitHub resolution, and emit it in the prepared payload. Reject it for non-GitHub SCM.
  • Apply the author in the wrapper on first clone and on the alreadyBootstrapped worktree-reuse path.
  • Gate author on the advertised capability so an older warm wrapper (strict payload schema) keeps working; the worker strips it when unsupported, mirroring the existing workingBranches gate.

Verification

  • pnpm run typecheck (tsgo + wrapper) — pass.
  • pnpm run test — 253 files, 7709 passed / 3 skipped.
  • wrapper bun test — 1734 passed.
  • test/integration/sandbox-control.test.ts — 346 passed; sandbox-attach-recovery + sandbox-control-seam — 20 passed.
  • oxlint/oxfmt clean on changed src/wrapper/src.
  • No manual end-to-end run against a live sandbox was performed in this worktree.

Visual Changes

N/A

Reviewer Notes

  • Identity selection is unchanged; it depends on allowUserAuthorization (true for cloud-agent-web/slack) and falls back to the App bot otherwise. Vercel contained sessions keep allowUserAuthorization: false.
  • Deferred: the commitCoAuthor trailer, so the App bot is not credited as co-author when the user identity is used.
  • Unrelated pre-existing lint errors in test/integration/sandbox-control.test.ts are excluded by the package lint glob; the changed src/wrapper/src files are clean.

…d git author

Control-plane (cloud-agent-web) sessions never applied the resolved GitHub
author to the worktree, so commits always used the generic fallback identity
(Kilo Code Cloud / agent@kilocode.ai) instead of the user or App bot.

Carry the resolved gitAuthor through the session credential grant into the
attach payload, apply it in the wrapper on first clone and on worktree reuse,
and gate it behind a wrapper hello capability so older warm sandboxes keep
working (the payload schema is strict).
Comment thread services/cloud-agent-next/wrapper/src/control/apply-attach.ts
@kilo-code-bot

kilo-code-bot Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Executive Summary

The incremental commit is a test-only update that realigns warm-reuse git expectations with the already-gated author write; both previously flagged findings are verified fixed at HEAD.

Files Reviewed (4 files)
  • services/cloud-agent-next/test/unit/wrapper/worktree-credential-refresh.test.ts
  • services/cloud-agent-next/wrapper/src/control/apply-attach.ts (verification of prior finding)
  • services/cloud-agent-next/src/sandbox-control/session-credentials.ts (verification of prior finding)
  • services/cloud-agent-next/src/services/git-token-service-client.ts (verification of prior finding)
Previous Review Summaries (2 snapshots, latest commit 073ee13)

Current summary above is authoritative. Previous snapshots are kept for context only.

Previous review (commit 073ee13)

Status: No Issues Found | Recommendation: Merge

Executive Summary

The incremental commit correctly restores the resolved git author on the legacy GitHub installation path and gates the warm-reuse author rewrite; no new issues found in the changed lines.

Files Reviewed (6 files)
  • services/cloud-agent-next/src/sandbox-control/session-credentials.ts
  • services/cloud-agent-next/src/sandbox-control/session-credentials.test.ts
  • services/cloud-agent-next/src/services/git-token-service-client.ts
  • services/cloud-agent-next/src/session-service.ts
  • services/cloud-agent-next/wrapper/src/control/apply-attach.ts
  • services/cloud-agent-next/wrapper/src/control/apply-attach.test.ts

Previous review (commit 1de0bf1)

Status: 2 Issues Found | Recommendation: Address before merge

Overview

Severity Count
CRITICAL 0
WARNING 2
SUGGESTION 0
Issue Details (click to expand)

WARNING

File Line Issue
services/cloud-agent-next/src/sandbox-control/session-credentials.ts 851 Managed GitHub author is dropped when the token service falls back to legacy installation auth (no gitAuthor); the control plane lacks the installationGitAuthorFromEnv fallback the legacy plane uses. Also present at line 1060.
services/cloud-agent-next/wrapper/src/control/apply-attach.ts 622 The new already-bootstrapped block rewrites user.name/user.email to the generic fallback on every reuse when attach.git.author is undefined, unlike the guarded warm path in session-bootstrap.ts:647-652.
Files Reviewed (14 files)
  • services/cloud-agent-next/src/persistence/SandboxControl.ts
  • services/cloud-agent-next/src/sandbox-control/session-credentials.ts - 2 issues
  • services/cloud-agent-next/src/sandbox-control/session-credentials.test.ts
  • services/cloud-agent-next/src/sandbox-control/socket.ts
  • services/cloud-agent-next/src/sandbox-control/socket.test.ts
  • services/cloud-agent-next/src/sandbox-session/attach-payload.ts
  • services/cloud-agent-next/src/sandbox-session/attach-payload.test.ts
  • services/cloud-agent-next/src/shared/sandbox-control-protocol.ts
  • services/cloud-agent-next/test/integration/sandbox-control.test.ts
  • services/cloud-agent-next/test/unit/wrapper/worktree-credential-refresh.test.ts
  • services/cloud-agent-next/wrapper/src/control/apply-attach.ts - 1 issue
  • services/cloud-agent-next/wrapper/src/control/apply-attach.test.ts
  • services/cloud-agent-next/wrapper/src/control/sandbox-control-client.ts
  • services/cloud-agent-next/wrapper/src/control/sandbox-control-client.test.ts

Fix these issues in Kilo Cloud


Reviewed by deepseek-v4.1-flash · Input: 0 · Output: 0 · Cached: 0

Review guidance: REVIEW.md from base branch main

Resolve two review findings on the control-plane git author work:

- Supply the installation App bot author from env in the legacy GitHub
  auth fallback, so the control plane attributes commits correctly when
  the git-token-service binding lacks getCloudAgentAuthForRepo. Share the
  helper with the legacy plane instead of duplicating it.
- Only rewrite the workspace git author on warm reuse when a resolved
  author is present, so reuse without one stays a no-op and does not
  overwrite an identity set by setup commands.
The warm-reuse author write is now gated on a resolved author, so the
managed-token refresh path no longer issues the two fallback git config
calls. Restore the pre-existing runGit count and last-call assertions.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants