Repository navigation
refactor(mcp): simplify internal Deep Scan state and finding caches - #1352
mldangelo-oai wants to merge 2 commits into
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
alandelong-oai
left a comment
There was a problem hiding this comment.
Reviewed the current diff; no actionable issues found.
kmbroai
left a comment
There was a problem hiding this comment.
Reviewed the full state/cache refactor, persisted schema, reducer snapshot binding, and preflight request lifecycle. Five focused test files passed locally, including store integration. Current CI inspected with no failures; broader rerun jobs remain pending. No actionable findings at this commit.
alandelong-oai
left a comment
There was a problem hiding this comment.
Reviewed the current diff; no actionable issues found.
Summary
Simplify the plugin's internal Deep Scan state without changing saved scan data. The coordinator adapter stops copying fields it never uses, and the result-merging worker keeps each finding in one cache slot instead of retaining both its object and serialized forms.
Changes
Testing
Recorded focused validation covers the coordinator, store, real workbench integration, permission preflight, and paged finding reads. Integration tests still inspect canonical artifact paths in the actual workbench response and read the resulting files, even though the private adapter no longer copies those fields. Coordinator restart tests check persisted workers and reported progress.
The paging fixture reconstructs large findings containing quotes, Unicode, and prior evidence, then replaces a source file and verifies that the already-bound pages and references stay unchanged. The preflight cancellation test hangs a child during configuration reading, aborts it, and verifies that the child stops.
To repeat after building the plugin bundle, run
node --experimental-strip-types --test tests/test_deep_scan_coordinator.ts tests/test_deep_scan_store.ts tests/test_deep_scan_store_integration.ts tests/test_deep_scan_permission_profile_preflight.ts tests/test_artifact_deep_reducer_pages.tsfromplugins/codex-security/mcp-app.After merging current main, all five focused MCP test entrypoints listed above passed, along with the executor, parent-sandbox, and stdio lifecycle test entrypoints. The portable plugin source checks, plugin bundle build, full type checks, and formatting checks also passed. The merge preserves the current runtime settings and diagnostic context; it removes the same redundant cleanup block already covered by this change.
Risk and rollout
No public CLI, persisted workbench schema, or worker settings change. The affected state adapter, reducer paging, and preflight lifecycle are covered by the focused tests. This can ship through the normal release process.
Public disclosure review