Repository navigation
fix(patches): parse zero-padded patch hunk counts - #1297
Draft
mldangelo-oai wants to merge 119 commits into
Draft
mldangelo-oai wants to merge 119 commits into
mldangelo-oai wants to merge 119 commits into
Conversation
…/codex/patch-snapshot-accounting
…/codex/patch-snapshot-accounting
…/codex/patch-snapshot-accounting
…/codex/patch-snapshot-accounting
…/codex/patch-snapshot-accounting
…/codex/patch-snapshot-accounting
…napshot-accounting # Conflicts: # sdk/typescript/tests-ts/support/cli-patch-context.mts
Local comparison foundation for the patch snapshot follow-up.
…/codex/patch-snapshot-accounting
…-integrity' into HEAD # Conflicts: # sdk/typescript/tests-ts/support/cli-patch-context.mts
…counting' into HEAD
…/codex/patch-snapshot-accounting
Collaborator
Author
|
@codex review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Codex Review: Didn't find any major issues. Delightful! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Git accepts patch hunk counts with thousands of leading zeros. Python's integer digit limit caused the Workbench to omit their optional preview and change statistics. Remove leading zeros before converting the count so these valid patches remain visible.
Changes
Preserve each hunk count's numeric value and Python's existing significant-digit limit. Oversized nonzero counts still leave the saved scan and remediation readable when preview conversion fails. The current contribution against the published parent changes only the Python preview parser and its tests.
Testing
Seven focused parser and saved-scan checks passed, along with Ruff lint and format checks, the SDK CI build, portable plugin source compatibility, and all nine source-checker tests. The parser and its tests are unchanged by the parent CI corrections.
The fixtures use
git apply --checkto confirm that a count with 5,000 leading zeros is valid. The preview reports one addition and one deletion. Saved-scan fixtures attach padded and oversized nonzero patches through the remediation workflow and read them back: the padded patch retains its preview, while the oversized value leaves only the optional preview and statistics unavailable. Both saved scans remain readable.Repeat the focused checks from the repository root:
python -m pytest plugins/codex-security/tests/test_workbench_db.py -k 'patch_statistics or padded_hunk_counts or large_hunk_counts'The local results above are focused and portable-source checks; complete platform runs are tracked in the PR checks.
Risk and rollout
The count value, artifact digest checks, and existing preview failure behavior are preserved. No CLI or settings change is introduced. This builds on the existing patch-publication work and includes its test and CI corrections. The PR remains a draft.
Public disclosure review
The accessible branch name, title, body, commits, changed source, review material, and recorded test artifacts were reviewed. Some previously linked automated security-report content has unavailable or restricted visibility; maintainers should complete that linked-content review before merging. No restricted report link or identifier is added here.