fix: preserve accepted evidence during Deep scan reduction - #442
fix: preserve accepted evidence during Deep scan reduction#442mldangelo-oai wants to merge 11 commits into
Conversation
|
@codex review |
|
Security review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5f90b68330
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 54aff1afa6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
Security review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a792d90968
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
Security review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4b1ed1f46b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d4a54c5401
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Security Review
Here are some automated security review suggestions for this pull request.
Reviewed commit: d4a54c5401
Only the user who started this review can view the report in Codex.
ℹ️ About Codex security reviews in GitHub
This is an experimental Codex feature. Security reviews are triggered when:
- You comment "@codex security review"
- A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review
Once complete, Codex will leave suggestions, or a comment if no findings are found.
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5ffd6d3f7f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 20b485b953
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Security Review
Here are some automated security review suggestions for this pull request.
Reviewed commit: 20b485b953
Only the user who started this review can view the report in Codex.
ℹ️ About Codex security reviews in GitHub
This is an experimental Codex feature. Security reviews are triggered when:
- You comment "@codex security review"
- A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review
Once complete, Codex will leave suggestions, or a comment if no findings are found.
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: be0a338634
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
@codex review |
|
Security review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: eb00fcec82
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d10222f09e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| result: { ...draft([first]), scope: { summary: "Invented review." } }, | ||
| sources: [{ ...draft([first]), scope: { summary: "Accepted review." } }], |
There was a problem hiding this comment.
Reject reducer-only scope metadata
When every accepted draft omits scope, a reducer can add an arbitrary scope such as runtimeStatus: "dynamically validated" or fabricated artifactsReviewed, because the validator derives the fields to check only from input sections and has no counterpart to the unsupported-threat-model guard. The added scope is then persisted as canonical evidence even though the reducer is prohibited from inspecting or validating the repository; reject a result scope when none was supplied, and reject result-only scope fields otherwise.
AGENTS.md reference: sdk/typescript/AGENTS.md:L20-L20
Useful? React with 👍 / 👎.
| result: draft([first, second], "complete", { | ||
| summary: "Administrator boundary.\n\nWorker boundary.\n\nInvented.", | ||
| assets: ["accounts", "workers"], | ||
| }), |
There was a problem hiding this comment.
Reject unsupported fields in differing threat models
When at least two accepted threat models differ, the reducer can add a field that every input omitted—for example, attackerCapabilities: ["unauthenticated remote attacker"]—because the array and string field sets are derived only from the inputs, while whole-object equality runs only when all accepted models are identical. The fabricated attacker assumptions are then persisted as canonical scan context; validate every result threat-model field against the accepted models in the differing-model branch as well.
AGENTS.md reference: sdk/typescript/AGENTS.md:L20-L20
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
💡 Codex Security Review
Here are some automated security review suggestions for this pull request.
Reviewed commit: d10222f09e
Only the user who started this review can view the report in Codex.
ℹ️ About Codex security reviews in GitHub
This is an experimental Codex feature. Security reviews are triggered when:
- You comment "@codex security review"
- A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review
Once complete, Codex will leave suggestions, or a comment if no findings are found.
| result: { ...draft([first]), scope: { limitations: [] } }, | ||
| sources: [ | ||
| { ...draft([first]), scope: { limitations: ["No runtime access."] } }, | ||
| ], |
There was a problem hiding this comment.
Security: Reject semantic metadata not supplied by workers
Required conditions: Deep mode is used and the reducer adds a scope field absent from every matching worker/previous result (or adds a new threat-model field while accepted models differ). The new validator builds its field set only from input entries, so those result-only keys are never checked. Against the target bundle I reproduced acceptance of fabricated runtimeStatus, validationMode, artifactsReviewed, and attackerCapabilities; parent finalization persists the scope and report projection presents it as canonical scan evidence. Reject every result metadata key not traceable to an accepted input. Unlike the earlier retained-scope report, this case has no accepted source for the added keys.
Useful? React with 👍 / 👎.
Summary
Preserve accepted worker findings, coverage, scope, and threat-model evidence during Deep scan reduction and recovery without introducing a separate runtime helper.
Changes
Testing
bun test --timeout 30000 --randomize --seed 12345 ./tests-ts: 1,132 passed, 11 skipped, and 0 failed.pnpm run types: passed.pnpm run format: passed.pnpm pack --pack-destination <temporary-directory>andnode scripts/check-package.mjs <packed-archive>: passed; validated 202 package entries, 106 bundled plugin files, the installed CLI and SDK, and a nested worker.--mode deep --workers 2 --subagents 0 --stop-after-no-new 2 --max-discovery-runs 2 --max-time-hours 1: completed with complete coverage, 19 reviewed surfaces, and no deferred work.Risk and rollout
The existing compressed runtime chunks change, but no packaged files or dependencies are added. Reducers now reject altered or incomplete accepted evidence, including saved reductions that do not match their original worker artifacts.
Public disclosure review