Skip to content

fix(cli): preserve patch work and validate publication state - #1251

Open
mldangelo-oai wants to merge 59 commits into
mainfrom
mdangelo/codex/patch-publication
Open

mldangelo-oai wants to merge 59 commits into
mainfrom
mdangelo/codex/patch-publication

Conversation

@mldangelo-oai

@mldangelo-oai mldangelo-oai commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Patch publication now preserves the original Git index when publication fails, includes the source deletion when a completed patch reports only a rename destination, and checks branch-name conflicts at every push destination before starting model work. Patch-risk artifacts include the actual changes inside nested checkouts, even when their Git metadata is replaced. Automatic publication refuses exact nonempty matches with pre-existing ignored regular files.

Changes

  • Restore the exact original index after a failed commit, including file-to-directory changes, staged entries and index flags. Detect a checkout hook that fails after Git has already switched branches, restore the original branch, and preserve the original diagnostic.
  • Use Git's rename and copy results to include rename-source deletions and reject publication of Git-detected transfers from tracked paths that were already dirty. Commit through a temporary native Git index so staged renames, already-selected source deletions, and source paths replaced by directories publish the reported selection. Explicitly selected replacement directories include their children; automatically inferred source deletions exclude unreported replacement contents. Stage committed nested updates through their gitlink without passing descendant paths to the parent repository. Seed the temporary index from selected native index entries so newly tracked ignored files remain visible to publication and risk assessment. Read each nested checkout’s own index when a parent alternate index is configured. Match native path spellings when recognizing deleted rename sources on Windows. Preserve hooks, signing, unrelated staged entries and index flags.
  • Check exact and ancestor/descendant branch conflicts locally and across configured push destinations before patching, retaining origin’s proxy and other transport settings without persistent config changes. Inspect Git’s already-expanded push destination through a child-only alias so URL rewriting occurs once, including destinations containing equals signs. Keep saved commits available for retries and verify resumed request identity. Parse SCP-style remotes with their native username and path semantics, preserving scoped IPv6 addresses and equivalent API address spellings. Decode URI fields only for URI forms and preserve native SSH configuration operands.
  • Retain nested snapshot tree objects in the outer Git store before model work. Build one coherent content diff from expanded native Git trees, preserving native gitlink revision diffs separately. Moving, flattening, replacing, or removing a nested checkout retains before/after content; recursive and subdirectory controls apply the resulting content patches with native Git. Resolve the recorded child commit after initialization, even if a subsequent child commit changed its checkout. Commit-only changes and same-commit initialization remain visible without inventing content changes.
  • Compare proposed file content against memory-only streaming digests of Git-enumerated, nonempty ignored regular files. Refuse exact matches before publication while preserving edits and existing same-path diagnostics. The ignored-file baseline retains only digests in memory; it does not store an ignored-content inventory. Preserve nested worktree validation, native Git configuration, hosting identity, completed work and diagnostics.
  • Integrate the captured main branch. Split hosting and nested-repository tests into separate modules with shared fixtures so CI can distribute them across runners. Use observed case durations for scheduling. Compare the five known textual Git-apply readbacks across native line endings while retaining exact index, artifact-hash and unchanged-file assertions. Use Git object-path separators in commit readbacks while retaining native Windows path inputs in the publication tests.

Testing

  • 662 SDK tests passed across ten affected modules, with 7 platform-specific skips; 22 sharding tests, types and full formatting pass. Four representative native Git-apply cases pass with both LF and CRLF checkout settings. Independent comparison confirms that all 76 test declarations and their case matrices are retained.
  • The 19 package tests, five portable source checks, SDK/plugin builds, bundle verification, native host proof, package-content checks and a fresh installed-package smoke passed with the final source.
  • That installed-package smoke verified public imports, NodeNext types, CLI/SDK lifecycle, credential locking, bundled plugin and MCP initialization, and nested worker launch. The package contract validates 541 entries; the 141-file plugin bundle contains 122 copies that match source exactly.
  • Real-Git before/after controls cover index restoration, failing checkout hooks, rename endpoints, tracked copies and type changes, ref namespace conflicts, multiple push destinations, and nested risk artifacts. Controls use synthetic repositories and local remotes. The hosting matrix passes 230 cases, including scoped IPv6, raw SCP versus encoded URI fields, equivalent IPv6 API addresses, and create/resume identity. Native Git transport and OpenSSH controls prove the before/after behavior without network calls.
  • Native Git controls also cover staged destination-only renames, source paths replaced by ordinary or ignored directories, explicitly selected replacement directories and absent source deletions, commit-result failures, checkpoint failures, exact index restoration after failing hooks, configured SSH commit signing, once-only push URL rewriting, newly tracked ignored files with explicit-file and directory selection, and initialization followed by a child commit. New risk artifacts are applied to the original synthetic baseline with native Git. Alternate parent-index controls preserve child ignored-file behavior, newly tracked child files, and parent and child index contents.
  • Native primitive artifacts come from a successful CI build with identical native inputs. Local native checks do not replace hosted Windows or macOS execution.
  • Both complete SDK test orders passed on the unchanged production source: 4,331 passed, 66 skipped and zero failed in each run. After the final test-only Git object-path correction, all 221 tests in the affected module passed; types and full formatting also passed. Native Git controls reproduce the rejected backslash object selector and verify the corrected selector reads the committed bytes.
  • Current hosted results are reported by the PR checks. The SDK, build and package results above are bound to the final source. Complete-suite and hosted results remain separately reported; no pending run is counted as a pass.

Risk and rollout

Content protection combines recorded paths, Git’s tracked-file rename/copy recognition, and exact nonempty matches against Git-enumerated ignored regular files. It does not detect arbitrary transformed or partial copies. Independently generated content identical to an ignored template or build output is also refused and must be reviewed and published manually. Empty files and external link targets are not fingerprinted. Streaming reads add cost proportional to ignored data: one measured 2.7 GB inventory took about 42 seconds; this is not a performance guarantee.

Existing remote branch conflicts stop before model work. A remote can change after preflight, and multiple push destinations can still be partially published if a later push fails. The verified commit remains available for retry.

Nested risk controls cover edits, moves, flattening, checkout replacement and removal, pointer-only changes, and initialization with or without a new child commit, including recursive and subdirectory targets. Invalid traversal preserves completed outer edits on disk. No new public flags, authentication defaults or diagnostic-redaction policy are introduced.

Public disclosure review

  • No customer, partner, prospect, or user identities, data, or identifying details are included.
  • No credentials, personal data, private source, scan findings, or nonpublic links or tickets are included.
  • I reviewed the branch name, title, description, commits, changes, comments, logs, screenshots, attachments, and links for public disclosure.

@github-actions github-actions Bot added the bug Something isn't working label Oct 5, 2026
@mldangelo-oai
mldangelo-oai marked this pull request as ready for review October 5, 2026 14:51
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-07T01:00:09.958582Z d3569fb New commits
🔒 Security Review ✅ Completed 2026-10-07T01:00:13.323339Z d3569fb New commits

Security findings

Blocking findings (5)

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4a092911c1

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread sdk/typescript/src/cli.ts Outdated
Comment thread sdk/typescript/src/cli.ts
Comment thread sdk/typescript/src/cli.ts Outdated
Comment thread sdk/typescript/src/cli.ts Outdated

@alandelong-oai alandelong-oai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the full contribution at 4a092911c1a4bc7470195beca82a760606dda892 with selected base e4eff6521926241c1ad1df1bb6395b71135e56d3, including changed tests and touched context, using three independent reviews followed by root synthesis.

No supported introduced finding.

Static source review; tests were inspected but not executed. CI, mergeability and integration are separate.

@alandelong-oai alandelong-oai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the complete contribution and changed tests with three independent review passes plus root synthesis. No supported introduced finding remains at this head. This is a static source review; tests were not executed, and CI and integration remain separate.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d7e9ee6ac4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread sdk/typescript/src/cli.ts Outdated
Comment thread sdk/typescript/src/cli.ts Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 33d3ee56fd

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread sdk/typescript/src/cli.ts Outdated
Comment thread sdk/typescript/src/cli.ts Outdated
Comment thread sdk/typescript/src/cli.ts

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 138fab2cff

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread sdk/typescript/src/cli.ts Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛡️ Codex Security Review · Automatically triggered

Here are some automated security review suggestions for this pull request.

Reviewed commit: 75e4002c54

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

Comment thread sdk/typescript/src/cli.ts Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 17b1dcf4f2

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread sdk/typescript/src/cli.ts Outdated
Comment thread sdk/typescript/src/cli.ts

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3aef41b039

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread sdk/typescript/src/cli.ts

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3aef41b039

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread sdk/typescript/src/cli.ts Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛡️ Codex Security Review · Automatically triggered

Here are some automated security review suggestions for this pull request.

Reviewed commit: 46f006f2d4

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

Comment thread sdk/typescript/src/cli.ts

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 46f006f2d4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread sdk/typescript/src/cli.ts
@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Something went wrong. Try again later by commenting “@codex review”.

Unknown error
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: dbfe41f8a5

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread sdk/typescript/src/cli.ts

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛡️ Codex Security Review · Automatically triggered

Here are some automated security review suggestions for this pull request.

Reviewed commit: dbfe41f8a5

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

Comment thread sdk/typescript/src/cli.ts

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d3569fbc0e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread sdk/typescript/src/cli.ts

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants