fix(review): respawn the reviewer pane when the harness changes#2800
Open
anuj7511 wants to merge 1 commit into
Open
fix(review): respawn the reviewer pane when the harness changes#2800anuj7511 wants to merge 1 commit into
anuj7511 wants to merge 1 commit into
Conversation
Gate pane reuse on the harness matching and destroy any stale pane before Spawn, so a reviewer-harness switch relaunches under the new harness's sandbox/permissions/env instead of reusing the old harness's live process.
Collaborator
|
Thanks for contributing to Agent Orchestrator. This PR is being picked up by the current external contributor on-call pair: If someone is already working on this, please continue as usual. For faster context or live questions, you can also join the AO Discord. Join the session here: Come by if you want to see what is being built, ask questions, or just hang around with the community. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
After switching a project's reviewer harness (e.g. claude-code → opencode), a
new review reused the still-live pane from the previous harness — so the review
ran under the old harness's sandbox/permissions/env while the DB recorded
the new harness.
Root cause
The reviewer handle is stable per worker (
review-<workerID>, independent ofharness), and
Triggerreused any live pane keyed only onAlive— it nevercompared the pane's harness to the freshly-resolved one. Reuse goes through
Notify, which only sends prompt text; sandbox/permissions/env are applied onlyat
Spawn. So a claude-code pane kept serving opencode-intended reviews.Impact
Security-relevant: if you switch to a stricter reviewer (e.g. opencode's
deny-all-bash profile), that stricter sandbox is silently not applied until the
old pane dies. Reviews run under the previous harness's looser profile.
Fix
Gate pane reuse on the resolved harness matching the harness the live pane was
launched under; a changed (or unrecorded) harness respawns instead. Because the
handle is stable and
tmux new-sessioncollides on a live name,Spawnnowdestroys any stale pane on that handle first (idempotent when absent), so the
switch actually replaces the process under the new harness's profile.