Skip to content

feat(agent): install executor profiles restricted to project tools - #4477

Merged
kwakayama merged 29 commits into
mainfrom
feat/project-tools-executor-install
Sep 10, 2026
Merged

kwakayama merged 29 commits into
mainfrom
feat/project-tools-executor-install

Conversation

@kojiwakayama

@kojiwakayama kojiwakayama commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

The executor currently installs a full agent runtime. Add an explicit project-tools profile that installs only fixed project context, a bounded canonical tool allowlist, and call limits. It exposes discovery and project-tool operations, while excluding runtime preparation, agent streaming, and privileged host capability fields.

Reuse the one-shot installation gate and fixed-image owner/source binding. The selected profile and installer callback are captured before project code loads. Project discovery inherits the original installation deadline, and project resources remain owned until tool handlers finish after cancellation. The default runtime profile is preserved.

Validation: 40 focused installation/runtime/broker test steps passed; changed-file typecheck, lint, formatting, layout, anti-slop, and generated API-reference checks passed. Independent static review found no actionable issues. The existing fixed-port Node entrypoint fixture now tests both profiles in the same serialized suite, including actual project loading, allowed tool execution, and rejected full-runtime operations; native execution remains for CI.

Stacked on #4476. This component does not switch traffic or activate the allocator. Broker-local trusted runtime composition and staging verification remain required.

Part of https://github.com/veryfront/veryfront-issue-inbox/issues/367 and https://github.com/veryfront/veryfront-issue-inbox/issues/1037.

Summary by CodeRabbit

  • New Features

    • Added a project-tools installation profile alongside the default runtime profile.
    • Project-tools installations expose fixed-context project tool discovery and execution with configurable tool, call, and concurrency limits.
    • Added validation for project-tool configuration, bindings, permissions, and installation profiles.
  • Documentation

    • Updated executor runtime documentation to explain both installation profiles, their capabilities, and configuration requirements.
  • Tests

    • Added coverage for project-tool installation, validation, execution, cleanup, cancellation, and profile selection.

@coderabbitai

coderabbitai Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

Warning

Review limit reached

Next included review available in 51 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: 35004264-54d2-41e0-81ac-4afa61f7065a

📥 Commits

Reviewing files that changed from the base of the PR and between 0ad9423 and d816943.

📒 Files selected for processing (10)
  • docs/guides/agent-service-runtime.md
  • src/agent/hosted/executor-project-runtime.test.ts
  • src/agent/hosted/executor-project-runtime.ts
  • src/agent/hosted/executor-project-tools.ts
  • src/agent/hosted/executor-runtime-prepare.test.ts
  • src/agent/hosted/executor-runtime-prepare.ts
  • src/agent/project/agent-runtime.test.ts
  • src/agent/project/agent-runtime.ts
  • src/discovery/agent-scoped-capabilities.test.ts
  • src/discovery/agent-scoped-capabilities.ts

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: ef139169-1f00-4ca4-928e-a1308100dbbc

📥 Commits

Reviewing files that changed from the base of the PR and between 0025748 and 0ad9423.

📒 Files selected for processing (11)
  • docs/api-reference/veryfront/agent.md
  • docs/guides/agent-service-runtime.md
  • src/agent/hosted/executor-project-install.test.ts
  • src/agent/hosted/executor-project-runtime.test.ts
  • src/agent/hosted/executor-project-runtime.ts
  • src/agent/hosted/executor-runtime-entrypoint-options.test.ts
  • src/agent/hosted/executor-runtime-entrypoint.ts
  • src/agent/hosted/executor-runtime-install-schema.ts
  • src/agent/hosted/executor-runtime-install.ts
  • tests/fixtures/executor-runtime-process.ts
  • tests/integration/agent/executor-runtime-entrypoint.fixture.ts

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The executor runtime now supports runtime and project-tools profiles. The project-tools profile validates fixed project context, exposes discovery and tool operations, enforces limits, and retains resources during active tool streams. Entrypoint, integration tests, unit tests, and documentation cover both profiles.

Changes

Project-tools executor profile

Layer / File(s) Summary
Installation contract and operation modes
src/agent/hosted/executor-runtime-install-schema.ts, src/agent/hosted/executor-runtime-install.ts, src/agent/hosted/executor-project-install.test.ts
Adds the project-tools installation schema, limits, operation map, discriminated installation options, and profile-specific install handling. Tests validate accepted operations and rejected inputs.
Project-tool runtime construction
src/agent/hosted/executor-project-runtime.ts, src/agent/hosted/executor-project-runtime.test.ts
Adds project discovery validation, fixed context capture, allowed-tool enforcement, call and concurrency limits, stream retention, and cleanup behavior.
Entrypoint profile routing and validation
src/agent/hosted/executor-runtime-entrypoint.ts, src/agent/hosted/executor-runtime-entrypoint-options.test.ts, tests/fixtures/executor-runtime-process.ts, tests/integration/agent/executor-runtime-entrypoint.fixture.ts
Routes trusted startup modes to separate runtime paths. Invalid modes fail before bootstrap access. Integration coverage runs both profiles and verifies project tool listing and execution.
Profile behavior documentation
docs/api-reference/veryfront/agent.md, docs/guides/agent-service-runtime.md
Documents profile selection, installation fields, context binding, limits, available operations, and project-tools restrictions.

Estimated code review effort: 4 (Complex) | ~45 minutes

Merge Risk: ⚪ Minimal · up to 0ad94

The profile boundaries, validation, restricted operations, and cleanup behavior are covered without an identified merge-blocking issue.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 50.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 8 functions across 9 files. (2 skipped: 2… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the primary change: adding executor installation profiles with a project-tools restriction.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 50.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 8 functions across 9 files. (2 skipped: 2 unsupported.)

✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/project-tools-executor-install

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

📦 Client bundle boundary

Entrypoint Modules Source size Server leaks
src/index.client.ts 289 2307 KiB ✅ 0

A server module in a client graph aborts hydration in the browser. New leaks fail CI; known leaks are tracked in scripts/lint/client-bundle-baseline.json to burn down.

@gitar-bot

gitar-bot Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

Gitar is working

Gitar

@codecov

codecov Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 78.23129% with 64 lines in your changes missing coverage. Please review.

Files with missing lines Patch % Lines
src/agent/hosted/executor-runtime-entrypoint.ts 4.83% 56 Missing and 3 partials ⚠️
src/agent/hosted/executor-runtime-install.ts 91.11% 2 Missing and 2 partials ⚠️
src/agent/hosted/executor-project-runtime.ts 99.10% 0 Missing and 1 partial ⚠️

📢 Thoughts on this report? Let us know!

@kojiwakayama
kojiwakayama marked this pull request as ready for review September 10, 2026 13:31

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@github-actions

Copy link
Copy Markdown

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 👍

Reviewed commit: a2c1e0855c

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@github-actions

Copy link
Copy Markdown

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. What shall we delve into next?

Reviewed commit: 3ec1daf750

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

…ry' into feat/project-tools-executor-install

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@github-actions

Copy link
Copy Markdown

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3c7b55041e

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread src/agent/hosted/executor-project-runtime.ts Outdated
Comment thread src/agent/hosted/executor-runtime-entrypoint.ts

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 40743f993a

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread src/agent/hosted/executor-project-runtime.ts
@github-actions

Copy link
Copy Markdown

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits.
Repo admins can enable using credits for code reviews in their settings.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@github-actions

Copy link
Copy Markdown

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c2cdbd3a03

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread src/agent/hosted/executor-project-runtime.ts Outdated

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@github-actions

Copy link
Copy Markdown

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 141da2783a

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread src/agent/hosted/executor-project-runtime.ts Outdated
@kwakayama

Copy link
Copy Markdown
Contributor

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 141da2783a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/agent/hosted/executor-project-runtime.ts Outdated
@kwakayama

Copy link
Copy Markdown
Contributor

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 141da2783a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/agent/hosted/executor-project-runtime.ts Outdated
@kwakayama

Copy link
Copy Markdown
Contributor

@codex review. Please review exact head 141da27; if there are no actionable findings, report the clean verdict.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. More of your lovely PRs please.

Reviewed commit: 141da2783a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@github-actions

Copy link
Copy Markdown

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3a5a9814d4

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread src/agent/hosted/executor-runtime-prepare.ts Outdated

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@github-actions

Copy link
Copy Markdown

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Already looking forward to the next diff.

Reviewed commit: d816943fad

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

@sonarqubecloud

Copy link
Copy Markdown

@kwakayama
kwakayama added this pull request to the merge queue Sep 10, 2026
@kwakayama
kwakayama removed this pull request from the merge queue due to a manual request Sep 10, 2026
@kwakayama
kwakayama added this pull request to the merge queue Sep 10, 2026
Merged via the queue into main with commit 5618a35 Sep 10, 2026
60 checks passed
@kwakayama
kwakayama deleted the feat/project-tools-executor-install branch September 10, 2026 20:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants