Skip to content

refactor(plugin): add raw Unix directory entries - #840

Open
kmbroai wants to merge 4 commits into
dev/kyleb/python-free-deep-review-inputfrom
dev/kyleb/python-free-unix-directory-entries
Open

kmbroai wants to merge 4 commits into
dev/kyleb/python-free-deep-review-inputfrom
dev/kyleb/python-free-unix-directory-entries

Conversation

@kmbroai

@kmbroai kmbroai commented Sep 9, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Expose raw Unix directory entries through the existing native binding for ranking and the remaining workbench migration.

Changes

  • Expose raw directory-entry names with optional cached entry types, symlink flags, and per-entry filesystem errors.
  • Support names-only enumeration without child metadata queries.
  • Keep the native API and its proofs as a prerequisite for ranking and the remaining workbench traversal/copy migration.

Testing

  • Combined stack tip ba12023: both full SDK runs passed 2,656 tests with 50 skips and zero failures (seeds 12345 and 4201856736).
  • The six affected helper suites passed 213 tests with four Windows-only skips; all 23 MCP test processes passed.
  • CI compilation, plugin build, types, formatting, Ruff, portable source checks, and nine source-checker tests passed.
  • Rust formatting and cross-target Clippy for the Windows x64 native proof passed. Local execution was Linux; hosted CI supplies platform runtime coverage.

Risk and rollout

Stacked on deep-review input. The native export and typed declaration must ship together through the existing native build and packaging workflow. This adds no public CLI surface.

Public disclosure review

  • No customer, partner, prospect, or user identities, data, or identifying details are included.
  • No credentials, personal data, private source, scan findings, or nonpublic links or tickets are included.
  • I reviewed the branch name, title, description, commits, changes, comments, logs, screenshots, attachments, and links for public disclosure.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review ✅ Completed 2026-09-11T00:03:45.551692Z 0439480 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@kmbroai
kmbroai force-pushed the dev/kyleb/python-free-unix-directory-entries branch from 7ba5eba to 6353428 Compare September 9, 2026 01:38
@kmbroai
kmbroai added this pull request to stack #855 September 9, 2026 22:16
Comment thread plugins/codex-security/native/src/unix.rs
@mldangelo-oai

Copy link
Copy Markdown
Collaborator

Reviewed 63534280b1de796dfcde43ab04cdf88cbab18820 against its #839 base using GPT-6 Astra at ultra effort, including the PR deslop and critical review passes.

I found no demonstrated correctness or security regression. I left one nonblocking simplification comment: remove this new native directory API and use Node's names-only Buffer API in the subsequent ranking caller. The only production caller discards all type metadata. Removing the export, types, proof and package coupling cuts 212 net lines; the coordinated caller change cuts four more.

Verification beyond the complete-stack comparison with main:

  • Exact-head native build/proof, plugin build and bundled export assertion passed.
  • Raw-name, permission, symlink and forced-unknown-type checks passed on Node 22.13, 24 and 26.
  • Each implementation passed 100 shard/pool tests, with one Windows-only skip. Independent artifact/receipt comparisons covered 52 helper invocations.
  • An independent 100-test replay loaded the earlier native binary in 303 helper processes; that binary has no directory-enumeration export.
  • Portable source checks, formatting, Clippy and the focused policy suite passed.

Only first-invalid-name diagnostic precedence changes intentionally; valid artifact bytes and receipt hashes remain unchanged in the comparisons. Local OS execution was Linux. Exact-head CI provides separate platform/native evidence; the synthetic combined stack still needs platform CI after restacking. The shipped helper uses Node, so direct Bun directory-object differences do not justify this native addition.

kmbroai commented Sep 10, 2026 •

Copy link
Copy Markdown
Collaborator Author

Retained the native directory API for the implemented workbench traversal and directory-copy consumers in the remaining migration. They use raw names, type/symlink metadata, and per-entry errors, so the export and its proofs remain a shared prerequisite. The inline thread is resolved with that rationale, and the PR description now explains these consumers.

Updated head: 04394804f360fa5e1a424d96bd76892282bdae13. Hosted CI passes on this head, including Linux/macOS/Windows tests, native proofs, installed-package checks, plugin source contracts, types, and formatting. Codex Security Review also passes. The Windows shards passed on an unchanged-commit retry after PowerShell and Python startup-probe failures. The combined stack at 5bd1d1909ad99d2749fe8d3ec49a9a144ae2bac0 includes this head and has also passed platform CI.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants