Repository navigation
fix(plugin): bind Standard completion to file review receipts - #829
Draft
soyeon-oai wants to merge 3 commits into
Draft
soyeon-oai wants to merge 3 commits into
soyeon-oai wants to merge 3 commits into
Conversation
3 tasks done
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Standard scans could finish with completed findings while their persisted review count remained zero. Bind review progress to the files selected at scan start, and require every file's review receipt before leaving discovery or sealing the result.
Changes
reviewedFilesand the workbench helper's repeatable--reviewed-fileargument. Validate their content, persist receipts transactionally, and derive coverage totals from those rows. Standard scans reject aggregate review counters.Testing
1/1/1coverage locally. Fresh npm installation remains locally blocked: registry requests returned HTTP 403, followed by npm'sExit handler never called!error.Risk and rollout
In-flight Standard scans created before this migration need to restart because they have no frozen per-file inventory. Existing completed scans remain readable. Receipts record declared review completion for frozen file content; they do not attest to the quality of model reasoning.
Native Desktop and live-model CLI scans of this OSS revision remain follow-up QA. This PR does not publish a release.
Public disclosure review
Change impact
The workbench freezes the file list, validates declared reviews against those bytes, and blocks real scan completion while receipts remain open.
flowchart LR subgraph column_0["Inputs"] direction TB node_0["Frozen file inventory"] node_1["MCP reviewedFiles"] end subgraph column_1["Persisted reviews"] direction TB node_2["Content-bound receipts"] end subgraph column_2["Completion rule"] direction TB node_3["All file reviews closed"] end subgraph column_3["Consumers"] direction TB node_4["Leave discovery"] node_5["Prepare or complete scan"] end node_0 -->|"binds paths and hashes"| node_2 node_1 -->|"records paths"| node_2 node_2 -->|"supplies closed rows"| node_3 node_3 -->|"permits transition"| node_4 node_3 -->|"permits finalization"| node_5 class node_0 changed class node_1 changed class node_2 changed class node_3 changed class node_4 affected class node_5 affected classDef changed fill:#d7f5e5,stroke:#237a4b,color:#111 classDef affected fill:#e6f0ff,stroke:#3569a8,color:#111 classDef context fill:#f2f3f5,stroke:#6e7781,color:#111Source evidence (6)
plugins/codex-security/scripts/workbench_scan_start.py:L217-L249— Startup freezes unique paths and SHA-256 digests, preserving direct file scopes and deriving the denominator from those rows.plugins/codex-security/mcp-app/server.ts:L1090-L1107— The progress tool forwards reviewedFiles to the workbench as repeated --reviewed-file arguments.plugins/codex-security/scripts/workbench_progress.py:L62-L116— The receipt writer checks persisted membership, canonical scope, containment, and content digest, then counts stored rows and closed timestamps.plugins/codex-security/scripts/workbench_progress.py:L25-L59— The shared gate requires a complete inventory with every receipt closed. Only an explicit persisted mock launch recipe skips real review completion.plugins/codex-security/scripts/workbench_progress.py:L400-L411— Forward transitions beyond discovery call the receipt gate before updating the scan phase.plugins/codex-security/scripts/workbench_db.py:L1467-L1477— The shared completion implementation checks receipts before finalization, including SDK preparation.