Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
1ee4605 to
c60440c
Compare
|
Reviewed This preserves the existing callable pool API. Its immediate product value is limited: the current in-tree scan guidance excludes separate ranking-phase pools, and I found no production orchestrator or receipt parser beyond helper dispatch. That makes additional generic compatibility machinery difficult to justify. I found no introduced correctness or security regression and identified two nonblocking reductions totaling 58 lines:
Verification beyond the complete-stack comparison with main:
Keep original plan/output buffers for receipt hashing and the exact per-slot and shard-content validators. Coordinate the previously posted existence, native-directory and discovery simplifications through this caller. Local OS execution was Linux. Exact-head CI supplies separate Windows, PowerShell, macOS and native-runtime evidence. The proposed changes need that platform CI when applied, and the synthetic combined stack needs it after restacking. |
|
Applied the remaining reductions: aggregate assignment checks are removed, plan reads no longer precheck existence, and UTF-8 uses the shared strict decoder. Per-slot assignment validation, shard checks, BOM/UTF-16/32 support, and original-byte receipt hashing remain. The malformed-UTF-8 compatibility change is documented and tested. Updated head: |
Summary
Move ranking pool planning, validation, and result merging to the bundled TypeScript helper.
Changes
Testing
ba12023: both full SDK runs passed 2,656 tests with 50 skips and zero failures (seeds 12345 and 4201856736).Risk and rollout
Stacked on ranking shards.
make-rank-pool-plan,validate-rank-worker, andvalidate-rank-poolmove tolaunch_codex_security_mcp[.cmd] --helper, preserving arguments, defaults, and the existing worker bound. Malformed UTF-8 is rejected even in overwritten duplicate values; ASCII-escaped surrogates and valid UTF-8/16/32 plans retain their handling. Duplicate assignments report the existing round-robin error.Public disclosure review