Skip to content

fix(codex): restore source-plugin startup and session evidence - #196

Open
liuhedev wants to merge 1 commit into
QoderAI:mainfrom
liuhedev:fix/plugin-runtime-session-evidence
Open

liuhedev wants to merge 1 commit into
QoderAI:mainfrom
liuhedev:fix/plugin-runtime-session-evidence

Conversation

@liuhedev

@liuhedev liuhedev commented Oct 10, 2026 •

Copy link
Copy Markdown

Codex source-plugin installs can fail before collecting evidence because the configured-assets registry eagerly loads DSH's YAML dependency. Bounded reviews also omit resumed sessions that started before --since, and desktop page/browser context can become a shared task request across unrelated sessions.

This change loads DSH only when selected and gives an actionable missing-YAML error, discovers Codex rollouts with activity inside the requested window, excludes host UI context from task requests, and includes Codex exec wrapper calls as observed activity. Wrapper activity does not imply nested-command success, validated changes, or release approval.

The review fix separates context classification from privacy sanitization. A real image-only request retains its task boundary even when its privacy-safe summary is empty, so subsequent edits are not assigned to the preceding text request. Both Markdown and XML image representations are covered; image content remains omitted from summaries.

Validation on Node 24.13.0 / macOS:

  • 590 tests passed across 33 files, with no skips: all session tests, agent-customize including DSH inventory and provider architecture, root CLI, source-plugin isolation, and doc-link integrity. Fresh JUnit output was verified against the actual test execution.
  • Anonymous regressions reproduced the original failures before their corresponding fixes. The image-only request regression also failed before the review fix and passed afterward, proving two episodes and correct edit attribution.
  • An affected local-session replay recovered one session / 681 in-window events and a candidate with 53 observed wrapper calls. The composed evidence bundle returned complete, with all three lanes available. This is the original implementation's replay evidence; the review fix was verified with anonymous fixtures. No private session payloads or identifiers are included here.
  • Independent review found CR-001; an independent L1 recheck of the fix and adjacent callers closed it with no new blocking or must-fix findings. The reviewer separately reran all four evidence-window tests successfully.
  • git diff --check passed; the documentation routing graph was regenerated without changes.

Limits: native Windows/Linux CI and full repository checks have not run. Older matching rollouts require a read-only activity probe, stopping at the first eligible event. Existing dependency versions and YAML parsing are unchanged; this PR does not change deployment or release-waiver policy.

@liuhedev liuhedev left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review summary

本地审查结论:未发现阻塞性代码问题,可以进入合并准备。

已验证

  • PR 新增回归测试:2 个文件、4 tests passed。
  • git diff --check passed。
  • PR 改动范围:6 files,190 additions / 11 deletions。
  • 全量测试对比:PR 与 main 基线均为 10 个失败测试文件、78 个失败测试;失败集合一致,未发现本 PR 新增的全量失败。
  • PR 新增覆盖了:DSH YAML 依赖按 provider 隔离、跨日 Codex session 活动发现、host UI context 排除、exec wrapper 活动识别。

合并前阻塞

  1. PR 当前仍是 Draft,需要标记为 Ready for review。
  2. GitHub 当前没有可见的远端 CI 结果,需要 Ready 后触发并等待必需检查。
  3. 基线已有的 governance/reporting 失败不属于本 PR 引入,需按仓库现有 CI/维护流程单独处理或明确豁免。

没有提交代码修改,也没有发现需要 request changes 的问题。

@liuhedev
liuhedev marked this pull request as ready for review October 10, 2026 10:38
liuhedev added a commit to liuhedev/better-harness that referenced this pull request Oct 10, 2026
Resolve CR-001 in PR QoderAI#196 by classifying injected context before privacy
sanitization. Image-only user requests retain their task boundary while
privacy-safe summaries still omit image content, so later edits are not
attributed to the preceding text request.

Implements docs/specs/2026-10-10-image-request-task-boundary.md. The new
regression failed before the fix and passed afterward. All 590 related tests
across 33 files passed on Node 24.13.0/macOS, and an independent recheck
closed CR-001 with no new must-fix findings.

Co-authored-by: Codex (GPT 5.6 Sol) <codex@openai.com>
@liuhedev
liuhedev force-pushed the fix/plugin-runtime-session-evidence branch 2 times, most recently from cc2ce96 to 2c67c4a Compare October 10, 2026 11:01
Defer optional DSH loading so Codex source-plugin collection can start independently. Recover resumed rollouts from in-window activity, keep host UI context out of task roots, retain exec wrapper activity without implying success, and preserve image-only user task boundaries after privacy sanitization.

Validated 590 related tests across 33 files on Node 24.13.0/macOS. The image-boundary regression failed before the fix and passed afterward; an independent recheck found no new must-fix issues.

Co-authored-by: Codex (GPT 6.1 Sol) <codex@openai.com>
@liuhedev
liuhedev force-pushed the fix/plugin-runtime-session-evidence branch from 2c67c4a to 4c7a2a9 Compare October 10, 2026 11:02

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant