Repository navigation
long-running: wire the indexing, KB-population, security-scan and code-analysis operations to their existing implementations, or retire them — no parallel implementation #17023
Description
Activity
- addedneeds-decisionBlocked on an owner decision; options and a recommendation are on the issueBlocked on an owner decision; options and a recommendation are on the issue
on Sep 18, 2026 Classification (for work assignment — not a fix proposal)
- Scope:
api(secondarykb) - Primary files/dirs:
autobot-backend/api/long_running_operations.py(verified on main; the_not_implementedroutes are at:136,:212and:218)autobot-backend/utils/operation_timeout_integration.py(verified on main)autobot-backend/api/codebase_analytics/endpoints/indexing.py(verified on main)autobot-backend/api/knowledge_population.py(verified on main)
- Same-file note:
api/long_running_operations.pyandutils/operation_timeout_integration.pyare shared with long-running: the four start routes cannot create an operation — create_operation gets estimated_items/context it does not accept (TypeError → 500) #17017 and ws: three unreachable WebSocket surfaces would accept unauthenticated if wired — finish or retire each (gateway adapter, /operations router, websocket_heartbeat) #17011, so under the same-file rule the three go to one session. - Umbrella: no. It is a child of security: /api/long-running has no authentication — anyone can start test runs, scans and KB population, or cancel any operation #17010 (closed).
- Blocked by: an owner ruling for the security-scan route. The acceptance criteria require asking the owner "is a runtime security scan wanted at all?", and the issue carries
needs-decision. Indexing, KB population and code analysis have nothing visible blocking them. - Read vs inferred: Read the issue body (0 comments) and the parent's state, and grepped main for the 501 stubs. It is inferred that the three routes still answer 501 on main.
- Undetermined: whether the owner has already answered the security-scan question anywhere outside this issue.
Generated by Claude Code
- Scope:
Three of the four have an unambiguous answer. The fourth — the security scan — cannot be answered as posed, because "security scan" names two different things here and each already has an implementation.
The three that are decidable now
Route Recommendation Why POST /api/long-running/codebase/indexWire to api/codebase_analytics/endpoints/indexing.py(verified present onmain)A real indexer with its own queue exists; the current operation function imports ..knowledge_basefrom above the top-levelutilspackage and callskb.populate_from_codebase, which exists nowhere — so it is an ImportError wrapping a missing method, not a partial implementation worth salvagingPOST /api/long-running/knowledge-base/populateWire to api/knowledge_population.py(verified present)populate_system_commands,populate_man_pages,populate_autobot_docs,refresh_system_knowledgeand their task machinery already exist; today's function sleeps and reports donecode analysis (type only, no route) Retire OperationType.CODE_ANALYSIShas a branch atoperation_timeout_integration.py:413and a default at:600, but no route reaches it. A placeholder with no caller is not a feature with a missing implementation — it is dead weight, and retiring it is the honest reading of "consolidate, never fork"The security scan — the question is ambiguous, and that is the finding
AC2 asks the owner "is a runtime security scan wanted at all?", on the premise that nothing exists at runtime. Something does — but possibly not the thing the route meant.
agents/security_scanner_agent.pyis 663 lines of real implementation: aStandardizedAgentwithActionHandler, supportingport_scan,service_detection,vulnerability_scan,ssl_scan. That is network and host scanning.The route's three siblings are all codebase-oriented — indexing, KB population, code analysis. A codebase security scan is SAST, and the implementation of that is the CI security jobs, which is what the issue table points at.
So "is a runtime security scan wanted?" has two answers depending on which was meant:
- Network/host scanning — already exists and is already reachable through the agent. The route would be a second front door onto it, which is the parallel implementation this issue opens by forbidding. Retire the route.
- Codebase SAST at runtime — does not exist outside CI, and that is a genuine build-or-not decision. Note it would inherit security(ci): bandit and pip-audit parsers read a failed scan as zero findings, and pip-audit is gated at --fail-on any #16185's defect:
parse_banditcurrently reads a scan that errored as a clean result, so a runtime SAST surface built on it would report "no findings" for a file it could not parse.
Recommended first step: settle which scan the route meant before answering wanted-or-not. If nobody can say, that is itself the answer — retire it, because a route whose subject cannot be identified has no consumer who would notice.
One note on AC3
"No route answers 501 once this closes. Each one works or is gone, with a test."
Sound, and worth keeping — but it means #17017's 501s are a temporary state owned by this issue, so #17017 should not be closed on the 501s standing. Worth saying explicitly on #17017, which currently reads as delivered on exactly that.
Verified against
origin/main. Recommendation only; the call is the owner's.
Split out of #17017 on the coordinator's ruling. This issue must not become a parallel implementation. Consolidate, never fork.
Problem
The long-running operations API (
api/long_running_operations.py) exposes work-starting routes whose operation functions (utils/operation_timeout_integration.py,_get_operation_functionand its wrappers) do not do the work:POST /api/long-running/codebase/indexfrom ..knowledge_base import KnowledgeBase(a relative import above the top-levelutilspackage, so ImportError at run time), thenkb.populate_from_codebase, which exists nowhereapi/codebase_analytics/endpoints/indexing.py(POST /index,/index/cancel) and its queuePOST /api/long-running/knowledge-base/populateapi/knowledge_population.py(populate_system_commands,populate_man_pages,populate_autobot_docs,refresh_system_knowledge, …) and its task machineryPOST /api/long-running/security/scanSECURITY_SCANhas no branch, so ValueError#17017 makes the three routes answer 501 Not Implemented, naming this issue, and queue nothing, instead of failing with 500 or reporting fake success.
/testing/comprehensivehas a real implementation and keeps working.Acceptance criteria
needs-decision). Wire or retire according to that answer.Related
#17017, #17010, #17011