Skip to content

fix(agent): restore project skill runtime hardening - #3266

Merged
kwakayama merged 1 commit into
codex/provider-catalog-recovery-20260802from
codex/project-skill-runtime-recovery-20260802
Aug 3, 2026
Merged

kwakayama merged 1 commit into
codex/provider-catalog-recovery-20260802from
codex/project-skill-runtime-recovery-20260802

Conversation

@kojiwakayama

Copy link
Copy Markdown
Contributor

Summary

  • restores the two effectively lost project-runtime hardening commits and the complete six-commit fix(agent): harden project skill runtime boundaries #3248 tail
  • makes project file discovery bounded and atomic, hardens skill metadata/policy/reference handling, and preserves hosted-runtime composition
  • removes the unsafe legacy parser/API path in favor of strict extension-owned YAML parsing
  • includes only narrow compatibility repairs required by the rebuilt parent stack

Recovery topology

This PR is intentionally stacked as:

#3247 -> #3264 -> #3265 -> this PR

The original #3248 could not be rebased safely because its ancestry contained feature-base merges that never reached main. This branch reconstructs the intended deltas on durable exact parents without carrying unrelated historical branch history.

Do not force-update a parent branch after a child PR has merged; rebase the remaining child instead.

Verification

  • focused changed suites: 355 passed across 100 test steps, 0 failed
  • deno task verify:quick
  • full typecheck
  • deno task lint:test-typecheck: 80 grandfathered files, 0 new
  • dependency, module, extension, and core third-party boundary checks
  • docs validation
  • git diff --check

@kojiwakayama
kojiwakayama requested a review from kwakayama as a code owner August 2, 2026 14:36
@kojiwakayama

Copy link
Copy Markdown
Contributor Author

@codex review

@kojiwakayama
kojiwakayama force-pushed the codex/provider-catalog-recovery-20260802 branch from 6fc5449 to 17ceacc Compare August 2, 2026 14:38
@kojiwakayama
kojiwakayama force-pushed the codex/project-skill-runtime-recovery-20260802 branch from bc523fe to 8b01324 Compare August 2, 2026 14:38
@kojiwakayama

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8b01324a89

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread src/agent/project/context.ts
@kojiwakayama
kojiwakayama force-pushed the codex/provider-catalog-recovery-20260802 branch from 17ceacc to 8512c39 Compare August 2, 2026 15:00
@kojiwakayama
kojiwakayama force-pushed the codex/project-skill-runtime-recovery-20260802 branch from 8b01324 to 488085c Compare August 2, 2026 15:00
@kojiwakayama

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 488085ccff

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread src/agent/hosted/project-steering-adapter.ts Outdated
@kojiwakayama
kojiwakayama force-pushed the codex/provider-catalog-recovery-20260802 branch from 8512c39 to be50521 Compare August 2, 2026 15:26
@kojiwakayama
kojiwakayama force-pushed the codex/project-skill-runtime-recovery-20260802 branch from 488085c to e0fdc6c Compare August 2, 2026 15:31
@kojiwakayama
kojiwakayama force-pushed the codex/provider-catalog-recovery-20260802 branch from bbd82d5 to ca4a345 Compare August 2, 2026 19:18
@kojiwakayama
kojiwakayama force-pushed the codex/project-skill-runtime-recovery-20260802 branch from 23994eb to 5ad7544 Compare August 2, 2026 19:27
@kojiwakayama

Copy link
Copy Markdown
Contributor Author

Rebased onto the current #3265 head and reconciled the recovered project-skill runtime without compatibility shims. The update preserves the strict hosted transport, extension-owned parsing, atomic discovery publication, confirmed project identity, bounded built-in file reads, and fail-closed skill policy enforcement.\n\nValidation at 5ad7544:\n- 401 affected tests + 101 nested steps passed\n- deno task verify:quick passed\n- git diff --check passed\n- merge-tree against the exact current base ca4a345 is clean\n- no unresolved review threads

@kojiwakayama

Copy link
Copy Markdown
Contributor Author

@codex review

@kojiwakayama
kojiwakayama force-pushed the codex/provider-catalog-recovery-20260802 branch from ca4a345 to 11a068a Compare August 2, 2026 19:32
@kojiwakayama
kojiwakayama force-pushed the codex/project-skill-runtime-recovery-20260802 branch from 5ad7544 to b424dea Compare August 2, 2026 19:32

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5ad75446a2

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/agent/runtime/project-files-client.ts Outdated
Comment thread src/agent/runtime/project-files-client.ts Outdated
Comment thread src/agent/runtime/skill-policy-enforcement.ts
Comment thread src/agent/runtime/project-files-client.ts
@kojiwakayama
kojiwakayama force-pushed the codex/provider-catalog-recovery-20260802 branch from 11a068a to 9344f1f Compare August 2, 2026 19:37
@kojiwakayama
kojiwakayama force-pushed the codex/project-skill-runtime-recovery-20260802 branch from b424dea to 6ad11ce Compare August 2, 2026 19:37
@kojiwakayama

kojiwakayama commented Aug 2, 2026 •

Copy link
Copy Markdown
Contributor Author

Restacked onto #3265 head 9344f1f2c; this PR is now 6ad11ceb2. The only tree delta from the prior head is the inherited skill-policy test correction, reconciled without weakening the recovered runtime contract.

Validation:

  • 403 affected tests / 207 nested steps: green
  • deno task verify:quick: green

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 6ad11ceb2e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/agent/runtime/project-files-client.ts Outdated
Comment thread src/agent/runtime/project-files-client.ts Outdated
@kojiwakayama
kojiwakayama force-pushed the codex/provider-catalog-recovery-20260802 branch from 9344f1f to 9f59070 Compare August 2, 2026 20:04
@kojiwakayama
kojiwakayama force-pushed the codex/project-skill-runtime-recovery-20260802 branch from 6ad11ce to 704c340 Compare August 2, 2026 20:04
@kojiwakayama
kojiwakayama force-pushed the codex/provider-catalog-recovery-20260802 branch from 9f59070 to 17d74ce Compare August 2, 2026 20:10
@kojiwakayama
kojiwakayama force-pushed the codex/project-skill-runtime-recovery-20260802 branch from 704c340 to 7d3756f Compare August 2, 2026 20:10
@kojiwakayama

Copy link
Copy Markdown
Contributor Author

Addressed all six review findings and resolved their threads. The public project-file transport is immutable and bounded, pagination rejects cycles, public filters and content limits are preserved, and reference-only Skill loads retain the active policy atomically. The complete changed-test surface and verify:quick pass on the final stacked head. @codex review

@kojiwakayama
kojiwakayama force-pushed the codex/provider-catalog-recovery-20260802 branch from 17d74ce to 75c1c74 Compare August 2, 2026 20:13
@kojiwakayama
kojiwakayama force-pushed the codex/project-skill-runtime-recovery-20260802 branch from 7d3756f to ed13a75 Compare August 2, 2026 20:13
@kojiwakayama
kojiwakayama force-pushed the codex/project-skill-runtime-recovery-20260802 branch from 002ab1d to f0f639b Compare August 2, 2026 20:44
@kojiwakayama

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f0f639b922

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/agent/runtime/project-skill-catalog.ts
Comment thread src/agent/runtime/project-skill-catalog.ts Outdated
Comment thread src/agent/runtime/builtin-skill-files.ts
@kojiwakayama
kojiwakayama force-pushed the codex/provider-catalog-recovery-20260802 branch from b4e646e to c3588f0 Compare August 2, 2026 20:55
@kojiwakayama
kojiwakayama force-pushed the codex/project-skill-runtime-recovery-20260802 branch from f0f639b to e0c21a5 Compare August 2, 2026 20:55
@kojiwakayama

Copy link
Copy Markdown
Contributor Author

@codex review

Restacked patch-identically onto final #3265 head c3588f0de8; exact #3266 head is e0c21a5702fc887af2cd29ec275ed78a88a49dc8. Range-diff marks all seventeen child patches equal. The final stack passes 91 focused tests / 48 nested steps and verify:quick.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e0c21a5702

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/agent/runtime/skill-prompt.ts Outdated
@kojiwakayama

Copy link
Copy Markdown
Contributor Author

@codex review

@kojiwakayama
kojiwakayama force-pushed the codex/provider-catalog-recovery-20260802 branch from c3588f0 to 30c2f9c Compare August 2, 2026 21:12
@kojiwakayama
kojiwakayama force-pushed the codex/project-skill-runtime-recovery-20260802 branch from 425e09b to 59beedf Compare August 2, 2026 21:13
@kojiwakayama

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Nice work!

Reviewed commit: 59beedff34

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@kojiwakayama
kojiwakayama force-pushed the codex/provider-catalog-recovery-20260802 branch from 30c2f9c to e6b7c6d Compare August 2, 2026 21:30
@kojiwakayama
kojiwakayama force-pushed the codex/project-skill-runtime-recovery-20260802 branch from 59beedf to 033b50f Compare August 2, 2026 21:32
@kojiwakayama

Copy link
Copy Markdown
Contributor Author

@codex review exact head 033b50f. Fresh merge-blocking review requested after restack onto #3265 head e6b7c6d. Commits 2-19 are range-diff identical; commit 1 preserves the parent private-validator fix while retaining the stronger bounded owned-identity implementation. Agent project/runtime suite passes 553 tests / 622 steps and verify:quick passes.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@kojiwakayama
kojiwakayama force-pushed the codex/provider-catalog-recovery-20260802 branch from e6b7c6d to 80b36d4 Compare August 2, 2026 21:40
@kojiwakayama
kojiwakayama force-pushed the codex/project-skill-runtime-recovery-20260802 branch from 033b50f to 3252f9e Compare August 2, 2026 21:40
@kojiwakayama

Copy link
Copy Markdown
Contributor Author

@codex review 3252f9e

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@kojiwakayama
kojiwakayama force-pushed the codex/provider-catalog-recovery-20260802 branch from 80b36d4 to c496b58 Compare August 2, 2026 21:44
@kojiwakayama
kojiwakayama force-pushed the codex/project-skill-runtime-recovery-20260802 branch from 3252f9e to 0814ac8 Compare August 2, 2026 21:44
@kojiwakayama

Copy link
Copy Markdown
Contributor Author

Final restack head: 0814ac8 on #3265 c496b58. All 19 child commits are range-diff identical. Exact top-of-stack verify:quick passes; the unchanged runtime delta passes 553 tests / 622 steps. Mergeability is clean and there are no unresolved review threads.

@kojiwakayama
kojiwakayama force-pushed the codex/provider-catalog-recovery-20260802 branch from b1e2372 to f1b5fd3 Compare August 3, 2026 05:08
@kojiwakayama
kojiwakayama force-pushed the codex/project-skill-runtime-recovery-20260802 branch from bc6fd82 to 1f4c357 Compare August 3, 2026 05:10
@kwakayama
kwakayama merged commit fb2e435 into codex/provider-catalog-recovery-20260802 Aug 3, 2026
1 check passed
@kwakayama
kwakayama deleted the codex/project-skill-runtime-recovery-20260802 branch August 3, 2026 05:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants