Skip to content

fix(patches): parse zero-padded patch hunk counts - #1297

Draft
mldangelo-oai wants to merge 119 commits into
mdangelo/codex/patch-publication-integrityfrom
mdangelo/codex/patch-snapshot-accounting
Draft

mldangelo-oai wants to merge 119 commits into
mdangelo/codex/patch-publication-integrityfrom
mdangelo/codex/patch-snapshot-accounting

Conversation

@mldangelo-oai

@mldangelo-oai mldangelo-oai commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Git accepts patch hunk counts with thousands of leading zeros. Python's integer digit limit caused the Workbench to omit their optional preview and change statistics. Remove leading zeros before converting the count so these valid patches remain visible.

Changes

Preserve each hunk count's numeric value and Python's existing significant-digit limit. Oversized nonzero counts still leave the saved scan and remediation readable when preview conversion fails. The current contribution against the published parent changes only the Python preview parser and its tests.

Testing

Seven focused parser and saved-scan checks passed, along with Ruff lint and format checks, the SDK CI build, portable plugin source compatibility, and all nine source-checker tests. The parser and its tests are unchanged by the parent CI corrections.

The fixtures use git apply --check to confirm that a count with 5,000 leading zeros is valid. The preview reports one addition and one deletion. Saved-scan fixtures attach padded and oversized nonzero patches through the remediation workflow and read them back: the padded patch retains its preview, while the oversized value leaves only the optional preview and statistics unavailable. Both saved scans remain readable.

Repeat the focused checks from the repository root:

python -m pytest plugins/codex-security/tests/test_workbench_db.py -k 'patch_statistics or padded_hunk_counts or large_hunk_counts'

The local results above are focused and portable-source checks; complete platform runs are tracked in the PR checks.

Risk and rollout

The count value, artifact digest checks, and existing preview failure behavior are preserved. No CLI or settings change is introduced. This builds on the existing patch-publication work and includes its test and CI corrections. The PR remains a draft.

Public disclosure review

The accessible branch name, title, body, commits, changed source, review material, and recorded test artifacts were reviewed. Some previously linked automated security-report content has unavailable or restricted visibility; maintainers should complete that linked-content review before merging. No restricted report link or identifier is added here.

  • No customer, partner, prospect, or user identities, data, or identifying details are included.
  • No credentials, personal data, private source, scan findings, or nonpublic links or tickets are included.
  • I reviewed the branch name, title, description, commits, changes, comments, logs, screenshots, attachments, and links for public disclosure.

mldangelo-oai and others added 30 commits October 5, 2026 14:15
…napshot-accounting

# Conflicts:
#	sdk/typescript/tests-ts/support/cli-patch-context.mts
Local comparison foundation for the patch snapshot follow-up.
…-integrity' into HEAD

# Conflicts:
#	sdk/typescript/tests-ts/support/cli-patch-context.mts
@mldangelo-oai

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-07T14:47:03.304468Z 8110998 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Delightful!

Reviewed commit: 8110998016

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mldangelo-oai mldangelo-oai changed the title fix(workbench): parse zero-padded patch hunk counts fix(patches): parse zero-padded patch hunk counts Oct 8, 2026
@mldangelo-oai mldangelo-oai added area:patches Patch generation, patch review, patch-risk assessment, and patch application. area:reports Human-readable reports, source excerpts, exports, and SARIF projections. bug Something isn't working and removed area:reports Human-readable reports, source excerpts, exports, and SARIF projections. area:patches Patch generation, patch review, patch-risk assessment, and patch application. labels Oct 8, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants