Repository navigation
refactor(plugin): simplify workbench persistence - #1226
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
@codex review the current head SHA. |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The refactoring preserves existing behavior and transaction boundaries without introducing unresolved correctness issues.
Review effort: Balanced
Findings: None
What changed in this PR
Simplifies workbench persistence while preserving transaction, scan ownership, and recovery behavior.
Changes:
- Replaces manual commit/rollback blocks with SQLite connection contexts.
- Reuses shared scan identity, root resolution, and insertion helpers.
- Consolidates progress updates and removes redundant declarations.
| File | Description |
|---|---|
deep_scan_workbench.py |
Reuses shared scan startup helpers and transaction contexts. |
workbench_cli.py |
Registers remediation cancellation directly. |
workbench_constants.py |
Removes unused remediation constants. |
workbench_db.py |
Simplifies transaction handling across persistence operations. |
workbench_progress.py |
Writes progress fields in one transaction update. |
workbench_publication.py |
Simplifies publication transactions. |
workbench_remediation.py |
Simplifies cancellation transaction handling. |
workbench_scan_start.py |
Reuses diff identity construction. |
workbench_scan_usage.py |
Simplifies cost reconciliation transactions. |
workbench_validation.py |
Simplifies scope containment checks. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
Codex Review: Didn't find any major issues. 🚀 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
alandelong-oai
left a comment
There was a problem hiding this comment.
Reviewed the actual PR contribution at 1827f98ae57c3784acf036995c30e6f501f5416a against 1fb0e5fbf8684c926cac2a36d08389b212d28d5a with three independent full-diff review passes and root synthesis, including every changed test and fixture. No actionable introduced issue was identified.
Read the full contribution and complete scan insertion/start critical context. Shared identity/insertion helpers preserve the touched scan mode, target, directory and thread fields. No supported introduced cross-scan value change identified; concurrent and resumed-worker runtime behavior remains unexecuted.
Static source review only; tests and builds were not run locally. This approval does not establish whole-stack integration or deployment.
Summary
Workbench mutations repeat transaction cleanup, and Deep Scan startup duplicates the standard scan insertion path. Reuse the existing transaction and startup mechanisms while preserving scan ownership and recovery behavior.
Changes
Testing
Passed on commit
1827f98ae57c:python -m pytest plugins/codex-security/tests/test_workbench_*.py -q -n 4 --dist worksteal --max-worker-restart 0(25 files) — 884 passed, 2 skipped.python -m pytest plugins/codex-security/tests -q -n 4 --dist worksteal --max-worker-restart 0— 1,587 passed, 6 skipped, and 162 subtests passed.All five portable plugin checks passed:
Three independent Codex reviews and separate verification completed without findings.
Risk and rollout
Review focuses on commit timing, early returns, failure rollback and concurrent scan ownership. Progress updates preserve the supported command's committed result and diagnostics. Public command syntax, managed migrations and credential/path protections remain unchanged.
Public disclosure review