Skip to content

fix(review): respawn the reviewer pane when the harness changes#2800

Open
anuj7511 wants to merge 1 commit into
AgentWrapper:mainfrom
anuj7511:reviewer-harness-respawn
Open

fix(review): respawn the reviewer pane when the harness changes#2800
anuj7511 wants to merge 1 commit into
AgentWrapper:mainfrom
anuj7511:reviewer-harness-respawn

Conversation

@anuj7511

Copy link
Copy Markdown

Summary

After switching a project's reviewer harness (e.g. claude-code → opencode), a
new review reused the still-live pane from the previous harness — so the review
ran under the old harness's sandbox/permissions/env while the DB recorded
the new harness.

Root cause

The reviewer handle is stable per worker (review-<workerID>, independent of
harness), and Trigger reused any live pane keyed only on Alive — it never
compared the pane's harness to the freshly-resolved one. Reuse goes through
Notify, which only sends prompt text; sandbox/permissions/env are applied only
at Spawn. So a claude-code pane kept serving opencode-intended reviews.

Impact

Security-relevant: if you switch to a stricter reviewer (e.g. opencode's
deny-all-bash profile), that stricter sandbox is silently not applied until the
old pane dies. Reviews run under the previous harness's looser profile.

Fix

Gate pane reuse on the resolved harness matching the harness the live pane was
launched under; a changed (or unrecorded) harness respawns instead. Because the
handle is stable and tmux new-session collides on a live name, Spawn now
destroys any stale pane on that handle first (idempotent when absent), so the
switch actually replaces the process under the new harness's profile.

Gate pane reuse on the harness matching and destroy any stale pane before Spawn, so a reviewer-harness switch relaunches under the new harness's sandbox/permissions/env instead of reusing the old harness's live process.
@somewherelostt

Copy link
Copy Markdown
Collaborator

Thanks for contributing to Agent Orchestrator.

This PR is being picked up by the current external contributor on-call pair:

If someone is already working on this, please continue as usual.
The on-call pair is added for visibility, tracking, and support, not to take over the work.
If you need help with review, direction, reproduction, or next steps, please tag @neversettle17-101 and @somewherelostt here.

For faster context or live questions, you can also join the AO Discord.

Join the session here:
https://discord.gg/H6ZDcUXmq

Come by if you want to see what is being built, ask questions, or just hang around with the community.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants