Skip to content

fix(plugin): keep resolved checkpoint deferrals closed - #771

Open
rohanpoudel2 wants to merge 2 commits into
openai:mainfrom
rohanpoudel2:fix/resolved-checkpoint-deferrals
Open

fix(plugin): keep resolved checkpoint deferrals closed#771
rohanpoudel2 wants to merge 2 commits into
openai:mainfrom
rohanpoudel2:fix/resolved-checkpoint-deferrals

Conversation

@rohanpoudel2

Copy link
Copy Markdown
Contributor

Summary

Fixes #741.

Interim scan checkpoints intentionally preserve deferred coverage so later writers cannot erase unfinished work by omission. That preservation also restored a linked deferral after the final draft had explicitly given every referenced surface a terminal disposition. The restored row downgraded otherwise complete coverage to partial and made the canonical result contradict the final draft.

Treat a deferral linked through surfaceIds as resolved only when every referenced surface has an unambiguous terminal outcome in the current draft. Historical checkpoint files remain unchanged.

Changes

  • Reconnect workbench-owned historical surface IDs to terminal semantic surfaces when the current draft omits derived IDs.
  • Drop an earlier linked deferral and its stale needs_follow_up surface only when all of the deferral's surface references resolve.
  • Preserve unlinked, missing, partially resolved, and duplicate-ambiguous surface work.
  • Cover successful terminal reconciliation, immutable checkpoint history, and the ambiguous duplicate-surface control through the real scan artifact writer.

Testing

  • pnpm --dir plugins/codex-security/mcp-app exec node --test tests/test_artifact_scan_draft.mjs — passed.
  • pnpm --dir sdk/typescript run test:mcp — 23 passed, 0 failed.
  • pnpm run types from sdk/typescript/ — passed; Node 25 emitted the repository's unsupported-engine warning.
  • pnpm run format from sdk/typescript/ — passed.
  • uv run --no-project --with ruff==0.16.1 python -m ruff check --config plugins/codex-security/pyproject.toml .github/scripts/check_plugin_source_compatibility.py .github/scripts/test_check_plugin_source_compatibility.py plugins/codex-security — passed.
  • uv run --no-project --with ruff==0.16.1 python -m ruff format --check --config plugins/codex-security/pyproject.toml .github/scripts/check_plugin_source_compatibility.py .github/scripts/test_check_plugin_source_compatibility.py plugins/codex-security — 137 files already formatted.
  • python .github/scripts/check_plugin_source_compatibility.py — passed.
  • git diff --check — passed.
  • pnpm run test --seed 12345 was attempted on unsupported Node 25 and was not used as passing validation. It reported seven failures in unchanged deduplication-review fixture cases, one unchanged workflow-fixture parse failure, and one ZIP-path stress test exceeded 30 seconds but passed in an isolated rerun. The broader run later stopped producing output and was interrupted. Focused reruns reproduced the first two unrelated failures; supported Node 22, 24, and 26 remain covered by hosted CI.

Risk and rollout

The reconciliation rule is limited to deferred rows with a nonempty surfaceIds list whose every reference resolves to one terminal surface. Missing references, follow-up outcomes, and duplicate semantic surfaces remain deferred, so the existing loss-prevention behavior stays in place. No public CLI, schema, stored-artifact format, dependency, or migration changes are required.

Public disclosure review

  • No customer, partner, prospect, or user identities, data, or identifying details are included.
  • No credentials, personal data, private source, scan findings, or nonpublic links or tickets are included.
  • I reviewed the branch name, title, description, commits, changes, comments, logs, screenshots, attachments, and links for public disclosure.
@github-actions github-actions Bot added the bug Something isn't working label Sep 1, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 1, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-09-01T03:26:29.465958Z bbbaca4 Manual request
🔒 Security Review Completed 2026-09-01T04:18:51.124324Z e896031 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: bbbaca48e8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread plugins/codex-security/mcp-app/src/artifact-scan-draft.ts
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

1 participant