Skip to content

long-running: wire the indexing, KB-population, security-scan and code-analysis operations to their existing implementations, or retire them — no parallel implementation #17023

Description

@mrveiss

Split out of #17017 on the coordinator's ruling. This issue must not become a parallel implementation. Consolidate, never fork.

Problem

The long-running operations API (api/long_running_operations.py) exposes work-starting routes whose operation functions (utils/operation_timeout_integration.py, _get_operation_function and its wrappers) do not do the work:

Route / type Operation function today Existing implementation elsewhere
POST /api/long-running/codebase/index from ..knowledge_base import KnowledgeBase (a relative import above the top-level utils package, so ImportError at run time), then kb.populate_from_codebase, which exists nowhere the codebase-analytics indexer: api/codebase_analytics/endpoints/indexing.py (POST /index, /index/cancel) and its queue
POST /api/long-running/knowledge-base/populate placeholder: sleeps, then reports done api/knowledge_population.py (populate_system_commands, populate_man_pages, populate_autobot_docs, refresh_system_knowledge, …) and its task machinery
POST /api/long-running/security/scan none: SECURITY_SCAN has no branch, so ValueError the CI security jobs. Whether a runtime scan is wanted at all is undecided
code analysis (type only, no route) placeholder: sleeps the codebase-analytics endpoints

#17017 makes the three routes answer 501 Not Implemented, naming this issue, and queue nothing, instead of failing with 500 or reporting fake success. /testing/comprehensive has a real implementation and keeps working.

Acceptance criteria

  • For each of the three routes and the code-analysis placeholder, the existing implementation is identified, then either the long-running route is wired to it, with the operations framework as a thin progress-tracking wrapper around the real work and no second copy of it, or the route and its placeholder are retired once supersession is proven and recorded here.
  • Security scan: record what exists today (CI security jobs, anything at runtime) and put the question "is a runtime security scan wanted at all?" to the owner (needs-decision). Wire or retire according to that answer.
  • No route answers 501 once this closes. Each one works or is gone, with a test.
  • Anything wired records its creator and follows long-running: the four start routes cannot create an operation — create_operation gets estimated_items/context it does not accept (TypeError → 500) #17017's creator-or-admin scoping.

Related

#17017, #17010, #17011

Activity

  1. added this to the v0.9.0 milestone on Sep 18, 2026
  2. added
    needs-decisionBlocked on an owner decision; options and a recommendation are on the issue
    on Sep 18, 2026
  3. mrveiss commented on Sep 28, 2026

    @mrveiss
    OwnerAuthor

    Classification (for work assignment — not a fix proposal)


    Generated by Claude Code

  4. modified the milestones: v0.9.0, v0.9-decisions on Sep 28, 2026
  5. mrveiss commented on Oct 3, 2026

    @mrveiss
    OwnerAuthor

    Three of the four have an unambiguous answer. The fourth — the security scan — cannot be answered as posed, because "security scan" names two different things here and each already has an implementation.

    The three that are decidable now

    Route Recommendation Why
    POST /api/long-running/codebase/index Wire to api/codebase_analytics/endpoints/indexing.py (verified present on main) A real indexer with its own queue exists; the current operation function imports ..knowledge_base from above the top-level utils package and calls kb.populate_from_codebase, which exists nowhere — so it is an ImportError wrapping a missing method, not a partial implementation worth salvaging
    POST /api/long-running/knowledge-base/populate Wire to api/knowledge_population.py (verified present) populate_system_commands, populate_man_pages, populate_autobot_docs, refresh_system_knowledge and their task machinery already exist; today's function sleeps and reports done
    code analysis (type only, no route) Retire OperationType.CODE_ANALYSIS has a branch at operation_timeout_integration.py:413 and a default at :600, but no route reaches it. A placeholder with no caller is not a feature with a missing implementation — it is dead weight, and retiring it is the honest reading of "consolidate, never fork"

    The security scan — the question is ambiguous, and that is the finding

    AC2 asks the owner "is a runtime security scan wanted at all?", on the premise that nothing exists at runtime. Something does — but possibly not the thing the route meant.

    agents/security_scanner_agent.py is 663 lines of real implementation: a StandardizedAgent with ActionHandler, supporting port_scan, service_detection, vulnerability_scan, ssl_scan. That is network and host scanning.

    The route's three siblings are all codebase-oriented — indexing, KB population, code analysis. A codebase security scan is SAST, and the implementation of that is the CI security jobs, which is what the issue table points at.

    So "is a runtime security scan wanted?" has two answers depending on which was meant:

    • Network/host scanning — already exists and is already reachable through the agent. The route would be a second front door onto it, which is the parallel implementation this issue opens by forbidding. Retire the route.
    • Codebase SAST at runtime — does not exist outside CI, and that is a genuine build-or-not decision. Note it would inherit security(ci): bandit and pip-audit parsers read a failed scan as zero findings, and pip-audit is gated at --fail-on any #16185's defect: parse_bandit currently reads a scan that errored as a clean result, so a runtime SAST surface built on it would report "no findings" for a file it could not parse.

    Recommended first step: settle which scan the route meant before answering wanted-or-not. If nobody can say, that is itself the answer — retire it, because a route whose subject cannot be identified has no consumer who would notice.

    One note on AC3

    "No route answers 501 once this closes. Each one works or is gone, with a test."

    Sound, and worth keeping — but it means #17017's 501s are a temporary state owned by this issue, so #17017 should not be closed on the 501s standing. Worth saying explicitly on #17017, which currently reads as delivered on exactly that.

    Verified against origin/main. Recommendation only; the call is the owner's.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    backendneeds-decisionBlocked on an owner decision; options and a recommendation are on the issuetech-debt

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions