Repository navigation
Conversation
liuhedev
commented
Oct 10, 2026
liuhedev
left a comment
Author
There was a problem hiding this comment.
Review summary
本地审查结论:未发现阻塞性代码问题,可以进入合并准备。
已验证
- PR 新增回归测试:2 个文件、4 tests passed。
git diff --checkpassed。- PR 改动范围:6 files,190 additions / 11 deletions。
- 全量测试对比:PR 与
main基线均为 10 个失败测试文件、78 个失败测试;失败集合一致,未发现本 PR 新增的全量失败。 - PR 新增覆盖了:DSH YAML 依赖按 provider 隔离、跨日 Codex session 活动发现、host UI context 排除、
execwrapper 活动识别。
合并前阻塞
- PR 当前仍是 Draft,需要标记为 Ready for review。
- GitHub 当前没有可见的远端 CI 结果,需要 Ready 后触发并等待必需检查。
- 基线已有的 governance/reporting 失败不属于本 PR 引入,需按仓库现有 CI/维护流程单独处理或明确豁免。
没有提交代码修改,也没有发现需要 request changes 的问题。
liuhedev
marked this pull request as ready for review
October 10, 2026 10:38
liuhedev
added a commit
to liuhedev/better-harness
that referenced
this pull request
Oct 10, 2026
Resolve CR-001 in PR QoderAI#196 by classifying injected context before privacy sanitization. Image-only user requests retain their task boundary while privacy-safe summaries still omit image content, so later edits are not attributed to the preceding text request. Implements docs/specs/2026-10-10-image-request-task-boundary.md. The new regression failed before the fix and passed afterward. All 590 related tests across 33 files passed on Node 24.13.0/macOS, and an independent recheck closed CR-001 with no new must-fix findings. Co-authored-by: Codex (GPT 5.6 Sol) <codex@openai.com>
liuhedev
force-pushed
the
fix/plugin-runtime-session-evidence
branch
2 times, most recently
from
October 10, 2026 11:01
cc2ce96 to
2c67c4a
Compare
Defer optional DSH loading so Codex source-plugin collection can start independently. Recover resumed rollouts from in-window activity, keep host UI context out of task roots, retain exec wrapper activity without implying success, and preserve image-only user task boundaries after privacy sanitization. Validated 590 related tests across 33 files on Node 24.13.0/macOS. The image-boundary regression failed before the fix and passed afterward; an independent recheck found no new must-fix issues. Co-authored-by: Codex (GPT 6.1 Sol) <codex@openai.com>
liuhedev
force-pushed
the
fix/plugin-runtime-session-evidence
branch
from
October 10, 2026 11:02
2c67c4a to
4c7a2a9
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Codex source-plugin installs can fail before collecting evidence because the configured-assets registry eagerly loads DSH's YAML dependency. Bounded reviews also omit resumed sessions that started before
--since, and desktop page/browser context can become a shared task request across unrelated sessions.This change loads DSH only when selected and gives an actionable missing-YAML error, discovers Codex rollouts with activity inside the requested window, excludes host UI context from task requests, and includes Codex
execwrapper calls as observed activity. Wrapper activity does not imply nested-command success, validated changes, or release approval.The review fix separates context classification from privacy sanitization. A real image-only request retains its task boundary even when its privacy-safe summary is empty, so subsequent edits are not assigned to the preceding text request. Both Markdown and XML image representations are covered; image content remains omitted from summaries.
Validation on Node 24.13.0 / macOS:
complete, with all three lanes available. This is the original implementation's replay evidence; the review fix was verified with anonymous fixtures. No private session payloads or identifiers are included here.git diff --checkpassed; the documentation routing graph was regenerated without changes.Limits: native Windows/Linux CI and full repository checks have not run. Older matching rollouts require a read-only activity probe, stopping at the first eligible event. Existing dependency versions and YAML parsing are unchanged; this PR does not change deployment or release-waiver policy.