Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
25 commits
Select commit Hold shift + click to select a range
cf00976
refactor(plugin): port candidate normalization to TypeScript
kmbroai Sep 8, 2026
61b1f0c
Merge branch 'review-cleanup-836' into review-cleanup-837
kmbroai Sep 10, 2026
280281d
refactor: simplify candidate parsing and input ordering
kmbroai Sep 10, 2026
f0c28f8
Merge main into candidate normalization migration
mldangelo-oai Sep 29, 2026
2f3b519
refactor(plugin): simplify candidate normalization checks
mldangelo-oai Sep 29, 2026
cf02f71
Merge updated Windows file operations into candidate normalization
mldangelo-oai Sep 29, 2026
c85f508
refactor(plugin): streamline candidate normalization flow
mldangelo-oai Sep 29, 2026
1891859
Merge simplified Windows file operations into candidate normalization
mldangelo-oai Sep 29, 2026
e3e2afc
fix(package): scan Brotli contents after decompression
mldangelo-oai Sep 29, 2026
0fd8e0a
refactor(plugin): share Unicode ordering and simplify migration fixtures
mldangelo-oai Sep 29, 2026
f25bfd5
Merge simplified Windows file operation fixtures
mldangelo-oai Sep 29, 2026
2c1fbb9
fix(plugin): ignore unused symlink loops in inventory probes
mldangelo-oai Sep 29, 2026
c51ef3d
refactor(plugin): replace Python compatibility emulation with native …
mldangelo-oai Sep 29, 2026
609ea05
Merge simplified native Windows file operations
mldangelo-oai Sep 29, 2026
f0d9311
test(plugin): run bundled normalizer with Node
mldangelo-oai Sep 29, 2026
d8a8a76
fix(plugin): normalize relative candidate paths before native lookup
mldangelo-oai Sep 29, 2026
909eb79
Merge native Windows scope-joining fix
mldangelo-oai Sep 29, 2026
f47cc35
fix(plugin): retain native errors for unresolved parent paths
mldangelo-oai Sep 29, 2026
4334e44
Merge native Windows path identity fixes
mldangelo-oai Sep 29, 2026
e201e45
Merge Windows proof comparison fix
mldangelo-oai Sep 29, 2026
eeaaa91
Merge native Windows fixture correction
mldangelo-oai Sep 29, 2026
f02379b
style(plugin): format candidate scope normalization
mldangelo-oai Sep 29, 2026
e26de2d
test(plugin): expect native Windows output paths
mldangelo-oai Sep 29, 2026
a377903
refactor(plugin): use native argument parsing and JSON ordering
mldangelo-oai Sep 29, 2026
aa716cb
merge: incorporate native Windows path simplification
mldangelo-oai Sep 29, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 8 additions & 2 deletions plugins/codex-security/mcp-app/helpers-main.ts
Original file line number Diff line number Diff line change
@@ -1,6 +1,8 @@
import { closeSync, readFileSync } from "node:fs";
import { resolveSecurityMdCommand } from "./src/helpers/resolve-security-md";
import { decodePosixBytes } from "./src/helpers/posix-path";
import { windowsBinding } from "./src/native";
import { normalizeCandidatesCommand } from "./src/helpers/normalize-candidates";

let commandLine = process.argv.slice(2);
if (process.platform === "win32") {
Expand All @@ -14,8 +16,10 @@ if (commandLine[0] === "--helper") {
if (process.platform === "win32") {
commandLine = commandLine.slice(1);
} else {
const encoded = readFileSync(3, "ascii");
closeSync(3);
const [homeSet, home, ...args] = decodePosixBytes(
Buffer.from(commandLine[1] ?? "", "hex"),
Buffer.from(encoded.trim(), "hex"),
)
.split("\0")
.slice(0, -1);
Expand All @@ -26,9 +30,11 @@ if (commandLine[0] === "--helper") {
const [command, ...args] = commandLine;
if (command === "resolve-security-md") {
process.exitCode = resolveSecurityMdCommand(args, posixHome);
} else if (command === "normalize-candidates") {
process.exitCode = normalizeCandidatesCommand(args, posixHome);
} else {
console.error(
"Usage: launch_codex_security_mcp[.cmd] --helper resolve-security-md [options]",
"Usage: launch_codex_security_mcp[.cmd] --helper <resolve-security-md | normalize-candidates> [options]",
);
process.exitCode = 2;
}
28 changes: 8 additions & 20 deletions plugins/codex-security/mcp-app/src/artifact-discovery.ts
Original file line number Diff line number Diff line change
Expand Up @@ -17,10 +17,6 @@ import {
type SchemaDocument,
} from "./artifact-schema-loader.js";
import { candidateSchemaV1 } from "./deep-scan/artifact-contracts.js";
import {
missingPythonHelperMessage,
resolvePythonCommand,
} from "./python_command.js";

const execFileAsync = promisify(execFile);
const discoveryComponents = ["artifacts", "02_discovery"] as const;
Expand Down Expand Up @@ -144,7 +140,7 @@ export async function recordCodexSecurityDiscoveryCandidates(
"candidate_ledger.jsonl",
];

// Verify the inventory is a context-bound regular file before passing it to Python.
// Verify the inventory is a context-bound regular file before normalization.
await readArtifactText(
context,
inventoryComponents,
Expand All @@ -167,23 +163,21 @@ export async function recordCodexSecurityDiscoveryCandidates(

try {
await fs.chmod(temporaryDirectory, 0o700);
const content =
candidates.length === 0
? ""
: `${candidates.map((candidate) => JSON.stringify(candidate)).join("\n")}\n`;
const content = candidates
.map((candidate) => `${JSON.stringify(candidate)}\n`)
.join("");
await fs.writeFile(temporaryInput, content, {
encoding: "utf8",
flag: "wx",
mode: 0o600,
});

const pythonCommand =
context.pythonCommand ?? (await resolvePythonCommand());
try {
await execFileAsync(
pythonCommand,
process.execPath,
[
join(pluginRoot, "scripts", "normalize_candidates.py"),
join(pluginRoot, "mcp", "helpers.mjs"),
"normalize-candidates",
"--input",
temporaryInput,
"--out",
Expand All @@ -201,7 +195,7 @@ export async function recordCodexSecurityDiscoveryCandidates(
},
);
} catch (error) {
throw discoveryNormalizationError(error, pythonCommand, [
throw discoveryNormalizationError(error, [
[temporaryInput, "candidate input"],
[temporaryDirectory, "private candidate input"],
[inventoryPath, "the assigned review inventory"],
Expand Down Expand Up @@ -245,14 +239,8 @@ export async function listCodexSecurityCandidates(

function discoveryNormalizationError(
error: unknown,
pythonCommand: string,
privateValues: Array<readonly [string, string]>,
): Error {
const pythonMessage = missingPythonHelperMessage(error, pythonCommand);
if (pythonMessage) {
return new Error(`${discoveryLabel}: ${pythonMessage}`, { cause: error });
}

const stderr =
error && typeof error === "object" && "stderr" in error
? error.stderr
Expand Down
Loading
Loading