Skip to content

fix(scan): preserve draft identities and stopped-result replay - #1296

Open
mldangelo-oai wants to merge 88 commits into
mainfrom
mdangelo/codex/draft-identity-replay
Open

mldangelo-oai wants to merge 88 commits into
mainfrom
mdangelo/codex/draft-identity-replay

Conversation

@mldangelo-oai

@mldangelo-oai mldangelo-oai commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Preserve finding identities and independent observations across draft publication and stopped-result replay. Late Deep progress also preserves the accepted terminal result without restoring older findings or unfinished coverage.

Changes

  • Preserve existing draft identity, worker ownership, recovery chronology and scope behavior.
  • Exclude checkpoints strictly older than the retained Deep terminal during later progress reconciliation. Keep tied timestamps, Standard drafts and worker history behavior unchanged.
  • Retain saved scope and threat-model metadata when a terminal write stops after saving its raw checkpoint. Select existing metadata before excluding obsolete findings and coverage.
  • Exercise empty progress, outstanding current work, timestamp ties, Standard replay and interrupted terminal writes through the actual draft writer, including persisted output and unchanged historical checkpoint bytes.

Testing

  • At 79f43f5e, both draft test files passed: 326 tests, zero failures. The original terminal-history controls failed before the correction; the six interrupted-metadata regressions also failed before their correction and now pass.
  • Actual exported calls verified omitted, explicit, absent and latest saved metadata, explicit empty arrays, fresh Deep/Standard/worker behavior, two replays and unchanged historical checkpoint bytes.
  • Types, full formatting and all five portable source checks passed on the exact candidate.
  • Three fresh review passes and an independent verifier completed without findings.
  • GitHub node CI passed all 48 required jobs (2 skipped). The hosted Ubuntu MCP suite passed all 405 tests, including all 326 affected draft tests and the six interrupted-metadata regressions. All six workflows on this commit passed.
  • Current-head whole-SDK and native Windows execution have not run locally. Hosted SDK results are separate from the Ubuntu MCP recovery checks; no native Windows MCP recovery execution is claimed. Earlier published validation remains bound to its historical source.

Risk and rollout

No command, flag, schema or persisted identity format changes. The metadata correction moves existing lookups and adds no production lines overall. The correction applies only when a Deep parent retains an accepted terminal; equal-timestamp observations remain eligible under the existing ordering. Existing diagnostic text, credential protections and unsafe-path checks remain intact.

Public disclosure review

The accessible source, history, comments and ordinary CI artifacts were reviewed without identifying sensitive material. The existing CodeQL branch-alert content could not be opened through a public request, so the complete linked-content attestations remain unchecked. No new restricted link is included.

  • No customer, partner, prospect, or user identities, data, or identifying details are included.
  • No credentials, personal data, private source, scan findings, or nonpublic links or tickets are included.
  • I reviewed the branch name, title, description, commits, changes, comments, logs, screenshots, attachments, and links for public disclosure.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-07T01:06:13.161583Z 79f43f5 New commits
🔒 Security Review ✅ Completed 2026-10-07T01:08:20.761227Z 79f43f5 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actions github-actions Bot added the bug Something isn't working label Oct 5, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f5fdb8cd05

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread plugins/codex-security/scripts/workbench_saved_results.py

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 544e33e08a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread plugins/codex-security/mcp-app/src/artifact-scan-draft.ts
…9b00fe07dee041a54260f9d7a5ca33e54ede' into HEAD
…HEAD

# Conflicts:
#	plugins/codex-security/mcp-app/src/artifact-scan-draft.ts
#	plugins/codex-security/scripts/workbench_saved_results.py

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 781d33dffe

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

: -1;
if (retainedFinal) {
// Deep parent terminals replace history; worker terminals can still omit saved work.
if (terminalReplacesHistory) result = structuredClone(retainedFinal.input);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Stop replaying pre-terminal Deep checkpoints

When a Deep parent has already accepted a terminal draft and later receives an empty complete: false progress update, this branch correctly seeds result from the terminal, but sources still contains every pre-terminal checkpoint and the later source-reconciliation loop merges their findings and unresolved coverage back into the published result. Thus stale findings and deferred work that the authoritative terminal deliberately removed can reappear and mark coverage partial; restrict subsequent reconciliation to observations newer than the retained terminal when terminalReplacesHistory is set.

AGENTS.md reference: AGENTS.md:L43-L45

Useful? React with 👍 / 👎.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants