Skip to content

refactor: simplify Deep Scan composition and recovery - #1093

Merged
mldangelo-oai merged 46 commits into
mdangelo/codex/simplify-deep-scanfrom
mdangelo/codex/pr939-simplification
Sep 30, 2026
Merged

mldangelo-oai merged 46 commits into
mdangelo/codex/simplify-deep-scanfrom
mdangelo/codex/pr939-simplification

Conversation

@mldangelo-oai

@mldangelo-oai mldangelo-oai commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Deep Scan repeats state reconstruction across composition, recovery, and publication. This follow-up to #939 simplifies those paths and implements the simplification audit, while retaining immutable completed evidence and the newer base's removal of retired recovery machinery.

Changes

  • Return source groups and select an existing canonical finding instead of rewriting findings. Preserve exact source evidence, stable identity, and host-owned coverage; skip model merge turns for clean batches.
  • Share operation accounting, prepared worker inputs, result context, draft publication, and comparison setup. Keep mutable worker state and settings isolated, including resumed discovery and reducer workers.
  • Keep one accepted draft plus explicitly pending checkpoints. Empty pending markers precede the single immutable history payload, so partial publication remains recoverable without duplicate payload writes. Acceptance removes only pending entries, preserving frozen recovery receipts and late evidence.
  • Preserve original report/evidence filenames in source-scan namespaces and keep long report references intact when reading saved findings. Reuse per-scan severity assessments, loaded composition state, indexed history queries, and existing severity totals; simplify seven transaction wrappers.
  • Preserve saved historical review counts in progress and CLI stop summaries using the existing stored counters.
  • Adopt the base's simpler sealed-result reader, native executable selection, shared bundle options, and timeout helper. Remove duplicate compatibility code, test harnesses, and publication benchmarks.
  • Move installed-launcher coverage into the existing package smoke test, deleting duplicate SDK compilation and installation setup. Use the existing Unix job deadline instead of a shorter nested test-step deadline.
  • Fix runtime package allowlists and generated declaration contracts, including the MCP SDK dependency required by public Codex SDK types.

Testing

  • Full Python suite at c1a3302c: 1,197 passed, 8 skipped; 109 subtests passed.
  • Full MCP suite at c1a3302c: 61 passed. MCP and SDK type/format checks passed.
  • All five required portable plugin checks passed, including 9 source-compatibility tests.
  • Actual npm tarball archive validation at c1a3302c passed: 604 entries. Fresh installed-package validation passed, including strict NodeNext TypeScript consumers, the real launcher flags and exit behavior, lifecycle and credential locking, MCP initialization, bundled tools, dashboard, and shared runtime.
  • Full SDK suite in two isolated shuffled orders passed at 7c611ae6: 3,484 passed, 46 skipped per order. The subsequent Python/MCP-only checkpoint fix passed focused cross-language publication tests; full Python/MCP and installed-package validation cover that final change.
  • Focused integration checks passed for grouping/projection/publication, recovery, accounting, and fresh/resumed worker settings.

Validation uses synthetic fixtures and local fake processes. No live model-quality or end-to-end Deep Scan performance measurement was run. Cross-platform results are reported by the checks on the published head.

Risk and rollout

This PR is stacked on #939. Grouping selects an existing narrative instead of synthesizing one. Historical semantic-draft aliases are retired; unsupported old drafts require a fresh scan and their original files remain evidence. Completed historical results remain readable, and verified sealed results finalize without model authentication. The newer base already retires unsealed legacy coordinator continuation and native package-layout guessing.

No new public CLI flags. Existing credential, unsafe-path, artifact-integrity, ownership, budget, cancellation, and per-scan settings protections remain. Keep this PR unmerged until its CI and review checks complete.

Public disclosure review

  • No customer, partner, prospect, or user identities, data, or identifying details are included.
  • No credentials, personal data, private source, scan findings, or nonpublic links or tickets are included.
  • I reviewed the branch name, title, description, commits, changes, comments, logs, screenshots, attachments, and links for public disclosure.

@mldangelo-oai
mldangelo-oai merged commit e338074 into mdangelo/codex/simplify-deep-scan Sep 30, 2026
72 of 86 checks passed
@mldangelo-oai
mldangelo-oai deleted the mdangelo/codex/pr939-simplification branch September 30, 2026 02:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants