Repository navigation
feat(protocol): carry workspace developer identity - #22
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe API minor version advances to 1. ChangesAPI 1.1 workspace identity
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Feature Merge Risk: ⚪ Minimal · up to This change adds the documented API fields and generated accessors, with no demonstrated current in-repository compatibility failure. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change adds identity and provisioning information without changing current resource operations. Correct ownership handling depends on a later host/runtime integration that is not included here. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches✨ Simplify code
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@greptileai review |
|
|
@coderabbitai full review |
✅ Action performedFull review finished. |
|
Final-head review is complete for a8b968f: Greptile 5/5, full CodeRabbit review with no actionable findings or retained architectural concerns, all nine CI jobs successful, and a verified signature. CodeRabbit’s embedded Buf tool could not fetch the base schema because its runner proxy was unavailable. Independent local buf lint, buf format, and buf breaking against origin/main passed; CI also passed Buf lint/format and pinned binding regeneration. The generated bindings were included in the fresh local CodeRabbit review. Host forwarding and runtime ownership validation remain follow-up integration work, as described in the PR. |
Runtime Protocol v1 currently drops the developer identity and Dockerless provisioning mode from Devsy’s image-run intent. MicroSandbox uses both to resolve bind-mount ownership and reject unsafe ownership resolution before resource changes.
Add
RunImageRequest.remote_user(field 20) anddockerless(field 21), regenerate the Go bindings, and advance the Info API minor from 0 to 1. Keep the process user separate from the developer identity; an empty remote user falls back to the process user, then root. Document that Dockerless image contents may not yet contain the final developer identity.The README defines each field and the required host/runtime handoff. The SDK is not deployed yet, so this change follows current Devsy semantics without a legacy compatibility layer or old-schema fixtures.
This is a prerequisite for MicroSandbox server integration. Devsy host forwarding and the runtime’s ownership implementation follow after this SDK release; this PR does not switch providers or change resource replacement policy.
Validation: