Repository navigation
fix(driver): forward external workspace identity - #1411
Conversation
✅ Deploy Preview for devsydev canceled.
|
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (7)
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review. 📝 WalkthroughWalkthroughThe external runtime driver now forwards remote-user and dockerless values in runtime requests. Fixture labels and tests cover workspace identity configurations. The protocol documentation describes ownership precedence and related validation requirements. ChangesWorkspace identity propagation
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to No specific issue remains that needs resolution before merge; complete the normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to This change preserves the distinction between the account running a container and the account owning workspace files. No concrete security regression was established, but ownership enforcement and recovery depend on external runtime behavior that could not be verified here. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 4 files. (3 skipped: 3 unsupported.)
✨ Finishing Touches✨ Simplify code
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
✅ Deploy Preview for images-devsy-sh canceled.
|
|
This pull request does not currently match the merge queue conditions, so it cannot be queued from here. The box comes back if it matches again. |
External runtimes currently receive the container process user but lose the resolved developer identity and Dockerless provisioning mode. This forwards
RemoteUserandDockerlessunchanged inRunImage, allowing the runtime to distinguish process execution from workspace ownership before provisioning.Updates the Runtime SDK dependency to v1.4.0 (Runtime API 1.1), documents ownership intent in the provider protocol reference, and exercises named, numeric, and empty identities through a real runtime subprocess. The regenerated license report also corrects the existing shell-parser version to match go.mod.
Validation:
task cli:lint:ci, affected-fileprek, andtask cli:licenses:checkSummary by CodeRabbit