Repository navigation
fix(scan): preserve draft identities and stopped-result replay - #1296
mldangelo-oai wants to merge 88 commits into
Conversation
…/codex/draft-identity-replay
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f5fdb8cd05
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 544e33e08a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…9b00fe07dee041a54260f9d7a5ca33e54ede' into HEAD
…HEAD # Conflicts: # plugins/codex-security/mcp-app/src/artifact-scan-draft.ts # plugins/codex-security/scripts/workbench_saved_results.py
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 781d33dffe
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| : -1; | ||
| if (retainedFinal) { | ||
| // Deep parent terminals replace history; worker terminals can still omit saved work. | ||
| if (terminalReplacesHistory) result = structuredClone(retainedFinal.input); |
There was a problem hiding this comment.
Stop replaying pre-terminal Deep checkpoints
When a Deep parent has already accepted a terminal draft and later receives an empty complete: false progress update, this branch correctly seeds result from the terminal, but sources still contains every pre-terminal checkpoint and the later source-reconciliation loop merges their findings and unresolved coverage back into the published result. Thus stale findings and deferred work that the authoritative terminal deliberately removed can reappear and mark coverage partial; restrict subsequent reconciliation to observations newer than the retained terminal when terminalReplacesHistory is set.
AGENTS.md reference: AGENTS.md:L43-L45
Useful? React with 👍 / 👎.
Summary
Preserve finding identities and independent observations across draft publication and stopped-result replay. Late Deep progress also preserves the accepted terminal result without restoring older findings or unfinished coverage.
Changes
Testing
79f43f5e, both draft test files passed: 326 tests, zero failures. The original terminal-history controls failed before the correction; the six interrupted-metadata regressions also failed before their correction and now pass.Risk and rollout
No command, flag, schema or persisted identity format changes. The metadata correction moves existing lookups and adds no production lines overall. The correction applies only when a Deep parent retains an accepted terminal; equal-timestamp observations remain eligible under the existing ordering. Existing diagnostic text, credential protections and unsafe-path checks remain intact.
Public disclosure review
The accessible source, history, comments and ordinary CI artifacts were reviewed without identifying sensitive material. The existing CodeQL branch-alert content could not be opened through a public request, so the complete linked-content attestations remain unchecked. No new restricted link is included.