Skip to content

refactor: remove the old Deep Scan result and merge tools - #1127

Closed
mldangelo-oai wants to merge 1 commit into
mdangelo/codex/pr939-stack-21-retire-enginefrom
mdangelo/codex/pr939-stack-22-retire-protocol
Closed

mldangelo-oai wants to merge 1 commit into
mdangelo/codex/pr939-stack-21-retire-enginefrom
mdangelo/codex/pr939-stack-22-retire-protocol

Conversation

@mldangelo-oai

@mldangelo-oai mldangelo-oai commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Superseded: The replacement PRs start at #1139; see the full stack index. This PR is retained as a reference, with its original description below.

Summary

The old Deep Scan processes used a separate server to save draft findings and read results in pages for merging. With those processes removed in part 21, remove their server, tools, schemas, and evaluation harness.

Changes

Remove get_codex_security_deep_reducer_inputs and record_codex_security_deep_reduction, the tools used to read and combine the old workers' findings. Also remove the worker server's record_codex_security_scan_draft registration. The main scan server keeps that draft tool and uses the existing database writer and its lock to save results.

Delete readers and context types specific to the old worker directories. Allow findings combined from multiple scans to reference reports in nested directories. Remove the plugin server's unused Codex SDK dependency and move its remaining test-only TOML dependency to development dependencies.

Testing

Ruff lint and formatting, the CI script build, SDK and plugin type checks, and the plugin source compatibility check and tests passed on this rebuilt commit.

Full SDK test results are reported on the final PR in the stack, #1095.

Risk and rollout

Callers of the retired server must use the main scan tools. Completed scan documents remain readable; the new result-saving code does not import partial results from the old workers or merge process. Tools for storing extra scan files remain available.

Part 22 of 23. Previous PR · Next PR · Stack index. Review against the base branch.

Public disclosure review

  • No customer, partner, prospect, or user identities, data, or identifying details are included.
  • No credentials, personal data, private source, scan findings, or nonpublic links or tickets are included.
  • I reviewed the branch name, title, description, commits, changes, comments, logs, screenshots, attachments, and links for public disclosure.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-30T18:20:11.710068Z e29cdc2 New commits
🔒 Security Review ✅ Completed 2026-09-30T18:21:16.415033Z e29cdc2 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@mldangelo-oai

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 🎉

Reviewed commit: 4eca17aa89

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The broad cleanup changes scan-draft persistence, checkpoint recovery, artifact writing, and packaging, warranting final human validation.

Review effort: Balanced
Findings: None

What changed in this PR

Removes the retired worker artifact server, reducer paging implementation, related schemas, evaluations, and dependencies while simplifying the remaining scan artifact pipeline.

Changes:

  • Deletes obsolete worker/reducer tools, templates, validation logic, and tests.
  • Simplifies artifact contexts and routes draft publication through the locked workbench writer.
  • Supports nested finding report paths and removes unused runtime dependencies.
File Description
plugins/​codex-security/​tests/​test_scan_contract_examples.py Removes reducer schema assertions.
plugins/​codex-security/​schemas/​tools/​worker-threat-model.schema.json Deletes worker threat-model schema.
plugins/​codex-security/​schemas/​tools/​scan-draft.schema.json Allows nested report paths.
plugins/​codex-security/​schemas/​tools/​review-items.schema.json Removes worker paging input.
plugins/​codex-security/​schemas/​tools/​deep-reducer.schema.json Deletes reducer schemas.
plugins/​codex-security/​plugin-files.json Updates shipped-file inventory.
plugins/​codex-security/​mcp-app/​tsconfig.json Excludes removed worker entrypoint.
plugins/​codex-security/​mcp-app/​tests/​test_deep_scan_templates.mjs Deletes old prompt tests.
plugins/​codex-security/​mcp-app/​tests/​test_deep_scan_artifact_validation.mjs Deletes worker artifact validation tests.
plugins/​codex-security/​mcp-app/​tests/​test_deep_reducer_paging_eval.mjs Deletes paging evaluation test.
plugins/​codex-security/​mcp-app/​tests/​test_artifact_worker_threat_model.mjs Deletes worker threat-model tests.
plugins/​codex-security/​mcp-app/​tests/​test_artifact_validation_phase.mjs Uses scan binding instead of layouts.
plugins/​codex-security/​mcp-app/​tests/​test_artifact_storage.mjs Shares production bundle options.
plugins/​codex-security/​mcp-app/​tests/​test_artifact_storage_regressions.mjs Updates bundling and contexts.
plugins/​codex-security/​mcp-app/​tests/​test_artifact_inventory.mjs Removes worker inventory cases.
plugins/​codex-security/​mcp-app/​tests/​test_artifact_foundation.mjs Tests simplified atomic replacement.
plugins/​codex-security/​mcp-app/​tests/​test_artifact_discovery.mjs Removes worker-context coverage.
plugins/​codex-security/​mcp-app/​tests/​test_artifact_deep_reducer.mjs Deletes reducer artifact tests.
plugins/​codex-security/​mcp-app/​tests/​test_artifact_deep_reducer_pages.mjs Deletes reducer pagination tests.
plugins/​codex-security/​mcp-app/​tests/​test_artifact_attack_path.mjs Uses scan binding instead of layouts.
plugins/​codex-security/​mcp-app/​tests/​support/​reducer-paging/​deep-reducer-paging.mjs Deletes paging harness.
plugins/​codex-security/​mcp-app/​tests/​support/​reducer-paging/​deep-reducer-paging-server.mjs Deletes evaluation server.
plugins/​codex-security/​mcp-app/​tests/​support/​reducer-paging/​deep-reducer-paging-fixture.mjs Deletes paging fixture.
plugins/​codex-security/​mcp-app/​tests/​support/​reducer-paging/​controlled-code-mode.mjs Deletes controlled runner.
plugins/​codex-security/​mcp-app/​templates/​deep-scan/​discovery.md Deletes old worker prompt.
plugins/​codex-security/​mcp-app/​templates/​deep-scan/​dedup.md Deletes old reducer prompt.
plugins/​codex-security/​mcp-app/​src/​server/​compact-artifact-tools.ts Removes worker/reducer tool registration.
plugins/​codex-security/​mcp-app/​src/​deep-scan/​templates.ts Deletes old prompt renderer.
plugins/​codex-security/​mcp-app/​src/​deep-scan/​artifacts.ts Deletes old artifact helpers.
plugins/​codex-security/​mcp-app/​src/​deep-scan/​artifact-validation.ts Deletes worker/reducer validation.
plugins/​codex-security/​mcp-app/​src/​deep-scan/​artifact-contracts.ts Removes relocated candidate contract.
plugins/​codex-security/​mcp-app/​src/​artifact-validation-phase.ts Uses shared candidate schema and scan binding.
plugins/​codex-security/​mcp-app/​src/​artifact-threat-model.ts Deletes worker threat-model writer.
plugins/​codex-security/​mcp-app/​src/​artifact-storage.ts Removes layout metadata.
plugins/​codex-security/​mcp-app/​src/​artifact-scan-draft.ts Simplifies locked draft publication and recovery.
plugins/​codex-security/​mcp-app/​src/​artifact-io.ts Removes worker contexts, append support, and locks.
plugins/​codex-security/​mcp-app/​src/​artifact-inventory.ts Removes worker schema and layout checks.
plugins/​codex-security/​mcp-app/​src/​artifact-discovery.ts Removes unused schema export.
plugins/​codex-security/​mcp-app/​src/​artifact-deep-reducer.ts Deletes reducer implementation.
plugins/​codex-security/​mcp-app/​src/​artifact-deep-reducer-pages.ts Deletes reducer pagination.
plugins/​codex-security/​mcp-app/​src/​artifact-context.ts Removes worker/reducer context construction.
plugins/​codex-security/​mcp-app/​src/​artifact-attack-path.ts Uses shared candidate schema and scan binding.
plugins/​codex-security/​mcp-app/​pnpm-lock.yaml Removes SDK packages and relocates TOML dependency.
plugins/​codex-security/​mcp-app/​package.json Removes unused runtime dependencies.
plugins/​codex-security/​mcp-app/​artifact-writer-main.ts Deletes worker MCP entrypoint.
evals/​README.md Removes reducer evaluation documentation.
evals/​deep-reducer/​run.mjs Deletes reducer evaluation runner.
evals/​deep-reducer/​README.md Deletes reducer evaluation guide.
evals/​deep-reducer/​.gitignore Removes obsolete report exclusion.
CONTRIBUTING.md Removes reducer CI reference.
Files not reviewed (1)
  • plugins/codex-security/mcp-app/pnpm-lock.yaml: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@mldangelo-oai mldangelo-oai changed the title refactor: remove worker artifact and reducer paging tools refactor: remove the old Deep Scan result and merge tools Sep 30, 2026

@alandelong-oai alandelong-oai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed 4eca17aa897c93228418b297c05fd6121f58f440 against mdangelo/codex/pr939-stack-21-retire-engine at 63c90a2461d5770963e56e17027b2e0b426aca82, scoped to this PR's diff and touched files.

Reviewed worker/reducer tool removal, remaining artifact I/O and registrations, schemas, package inventory, and changed tests/docs. No new actionable findings. The exact base/head diff passed git diff --check.

Review included simplification/deletion opportunities. Full repository and platform test suites were not run.

@mldangelo-oai
mldangelo-oai force-pushed the mdangelo/codex/pr939-stack-22-retire-protocol branch from 4eca17a to e30421d Compare September 30, 2026 16:55
@mldangelo-oai
mldangelo-oai force-pushed the mdangelo/codex/pr939-stack-21-retire-engine branch from 13d62a5 to 6c4d367 Compare September 30, 2026 17:19
@mldangelo-oai
mldangelo-oai force-pushed the mdangelo/codex/pr939-stack-22-retire-protocol branch from e30421d to 2348b94 Compare September 30, 2026 17:19
@mldangelo-oai
mldangelo-oai force-pushed the mdangelo/codex/pr939-stack-21-retire-engine branch from 6c4d367 to ac334c3 Compare September 30, 2026 18:17
@mldangelo-oai
mldangelo-oai force-pushed the mdangelo/codex/pr939-stack-22-retire-protocol branch from 2348b94 to e29cdc2 Compare September 30, 2026 18:18

@faizan-oai faizan-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the retired protocol/tool removals and remaining main-server draft path, together with nested report-path support and dependency changes. No issue found in this deletion layer. Integrated type checks and focused result/merge tests passed at the final stack tip.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants