Repository navigation
fix(responses): scope the self-named namespace scrub to declared bare tools (carry of #3226) - #3234
Merged
Merged
Conversation
…ation set
buildTools accepts the Chat-shaped `{ type: "function", function: { name } }`
declaration and the undeclared-tool guard authorizes it, but the scrub's
raw-body collector only read `spec.name`. Such a function never entered the
raw-body set, the intersection dropped it, and a self-named echo for it
reached Codex again. Mirror addWireToolName and read the nested name.
Regression: Chat-shaped catalog + upstream `function_call { name: "wait",
namespace: "wait" }` is scrubbed; red without this change.
Contributor
|
✅ Deterministic PR hygiene checks passed. |
7 tasks done
lidge-jun
pushed a commit
that referenced
this pull request
Sep 2, 2026
lidge-jun
pushed a commit
that referenced
this pull request
Sep 2, 2026
lidge-jun
added a commit
that referenced
this pull request
Sep 2, 2026
…sion audit (#3218) * docs(devlog): open the bug/PR closeout stack roadmap * docs(devlog): fold the A-gate import-boundary finding into phase 5 * docs(devlog): record the #3163 and #3166 landings * docs(devlog): record why #2986 does not land in this train * docs(devlog): close out the bug/PR closeout stack * docs(devlog): record the final green CI verdict on dev * docs(devlog): open the bug-label drawdown roadmap with audit corrections * docs(devlog): record the Batch A landings and first rebase carry * docs(devlog): record the Batch B rebase carries * docs(devlog): record why the rebase service earned its keep * docs(devlog): record the Batch C rebases and the one real review finding * docs(devlog): record the #2999 scope boundary that survived execution * docs(devlog): record Batch D - every bug PR closed * docs(devlog): record what the PR half of the campaign cost * docs(devlog): replan the remaining issues to one per cycle * docs(devlog): carry the i3141 evidence into the replan * docs(devlog): diagnose i3141 - fix predates the reported version * docs(devlog): retire the second bundle * docs(devlog): record the i3141 re-triage action and outcome * docs(devlog): diagnose i3152 log table jitter * docs(devlog): i3152 - measurement disproved the layout diagnosis * docs(devlog): diagnose i3136 slashed-id price lookup * docs(devlog): diagnose i3150 citation marker passthrough * docs(devlog): diagnose i3155 capacity plan allowlist * docs(devlog): i1419 stays open pending crash frames * docs(devlog): record the i1419 re-triage ask * docs(devlog): diagnose i2999 publication overwrite race * docs(devlog): record the i2999 outcome and remaining scope * docs(devlog): diagnose i2813 as a client-side reserve gate * docs(devlog): diagnose i1527 residuals as trace-blocked * docs(devlog): correct i1527 envelope-cap wording (192 blobs, HTTP 400) * docs(devlog): plan p3193 loopback alpha-search reimplementation * docs(devlog): record p3193 landing (#3205 -> 53c09a2) * docs(devlog): plan the main->dev regression audit * docs(devlog): pin regaudit counts, add tests-only/security passes and the exact-head dispatch * docs(devlog): record regaudit reviewer verdicts * docs(devlog): record the exact-head dev CI verdict and Windows classification * docs(devlog): record the main control run proving the Windows failures predate the range * docs(devlog): record the pass-1 recount and the #3217 root cause * docs(devlog): plan i3217 (Spark functions-namespace flattening) * docs(devlog): record i3217 landing (#3224 -> d23eab4) * docs(devlog): regaudit2 recount and disposition table * docs(devlog): regaudit2 CI verdict on d23eab4 and the four PR arrivals * docs(devlog): plan p3226 (scoped namespace scrub) * docs(devlog): p3226 audit finding and carry plan * docs(devlog): record p3226 landing (#3234 -> b732b0d) * docs(devlog): plan p3227 (combo zero-output incomplete failover) * docs(devlog): record p3227 landing * docs(devlog): plan p3228 (encrypted V2 spawn native fallback) * docs(devlog): record p3228 landing * docs(devlog): plan p3229 (Codexless originator in task recovery) * docs(devlog): record p3229 landing and the #3239 regression repair * docs(devlog): r3239 regression repair record * docs(devlog): r3239 audit note * docs(devlog): record p3232 (merged by maintainer) * docs(devlog): p3232 verification result * docs(devlog): regaudit3 recount and landing table * docs(devlog): record the #3239/#3240 revert and correct the #3228 disposition * docs(devlog): rv3239 revert record * docs(devlog): rv3239 audit note * docs(devlog): regaudit3 second-dispatch verdict * docs(devlog): regaudit3 recount refreshed (#1419 closed by maintainer; count 4) * docs(devlog): regaudit3 final CI verdict and c-7 --------- Co-authored-by: jun <jun@lidge.dev>
This was referenced Sep 2, 2026
tarunravi
pushed a commit
to tarunravi/opencodex
that referenced
this pull request
Sep 14, 2026
… tools (carry of lidge-jun#3226) (lidge-jun#3234) * fix(responses): scope self-named namespace scrub * fix(responses): preserve colliding namespaced functions * fix(responses): honor scrub authorization identity * fix(responses): cover function scrub edge cases * fix(responses): read Chat-shaped function names in the scrub authorization set buildTools accepts the Chat-shaped `{ type: "function", function: { name } }` declaration and the undeclared-tool guard authorizes it, but the scrub's raw-body collector only read `spec.name`. Such a function never entered the raw-body set, the intersection dropped it, and a self-named echo for it reached Codex again. Mirror addWireToolName and read the nested name. Regression: Chat-shaped catalog + upstream `function_call { name: "wait", namespace: "wait" }` is scrubbed; red without this change. --------- Co-authored-by: Alex Jordan <60003097+alex-jordan547@users.noreply.github.com> Co-authored-by: jun <jun@lidge.dev>
tarunravi
pushed a commit
to tarunravi/opencodex
that referenced
this pull request
Sep 14, 2026
…sion audit (lidge-jun#3218) * docs(devlog): open the bug/PR closeout stack roadmap * docs(devlog): fold the A-gate import-boundary finding into phase 5 * docs(devlog): record the lidge-jun#3163 and lidge-jun#3166 landings * docs(devlog): record why lidge-jun#2986 does not land in this train * docs(devlog): close out the bug/PR closeout stack * docs(devlog): record the final green CI verdict on dev * docs(devlog): open the bug-label drawdown roadmap with audit corrections * docs(devlog): record the Batch A landings and first rebase carry * docs(devlog): record the Batch B rebase carries * docs(devlog): record why the rebase service earned its keep * docs(devlog): record the Batch C rebases and the one real review finding * docs(devlog): record the lidge-jun#2999 scope boundary that survived execution * docs(devlog): record Batch D - every bug PR closed * docs(devlog): record what the PR half of the campaign cost * docs(devlog): replan the remaining issues to one per cycle * docs(devlog): carry the i3141 evidence into the replan * docs(devlog): diagnose i3141 - fix predates the reported version * docs(devlog): retire the second bundle * docs(devlog): record the i3141 re-triage action and outcome * docs(devlog): diagnose i3152 log table jitter * docs(devlog): i3152 - measurement disproved the layout diagnosis * docs(devlog): diagnose i3136 slashed-id price lookup * docs(devlog): diagnose i3150 citation marker passthrough * docs(devlog): diagnose i3155 capacity plan allowlist * docs(devlog): i1419 stays open pending crash frames * docs(devlog): record the i1419 re-triage ask * docs(devlog): diagnose i2999 publication overwrite race * docs(devlog): record the i2999 outcome and remaining scope * docs(devlog): diagnose i2813 as a client-side reserve gate * docs(devlog): diagnose i1527 residuals as trace-blocked * docs(devlog): correct i1527 envelope-cap wording (192 blobs, HTTP 400) * docs(devlog): plan p3193 loopback alpha-search reimplementation * docs(devlog): record p3193 landing (lidge-jun#3205 -> 53c09a2) * docs(devlog): plan the main->dev regression audit * docs(devlog): pin regaudit counts, add tests-only/security passes and the exact-head dispatch * docs(devlog): record regaudit reviewer verdicts * docs(devlog): record the exact-head dev CI verdict and Windows classification * docs(devlog): record the main control run proving the Windows failures predate the range * docs(devlog): record the pass-1 recount and the lidge-jun#3217 root cause * docs(devlog): plan i3217 (Spark functions-namespace flattening) * docs(devlog): record i3217 landing (lidge-jun#3224 -> d23eab4) * docs(devlog): regaudit2 recount and disposition table * docs(devlog): regaudit2 CI verdict on d23eab4 and the four PR arrivals * docs(devlog): plan p3226 (scoped namespace scrub) * docs(devlog): p3226 audit finding and carry plan * docs(devlog): record p3226 landing (lidge-jun#3234 -> b732b0d) * docs(devlog): plan p3227 (combo zero-output incomplete failover) * docs(devlog): record p3227 landing * docs(devlog): plan p3228 (encrypted V2 spawn native fallback) * docs(devlog): record p3228 landing * docs(devlog): plan p3229 (Codexless originator in task recovery) * docs(devlog): record p3229 landing and the lidge-jun#3239 regression repair * docs(devlog): r3239 regression repair record * docs(devlog): r3239 audit note * docs(devlog): record p3232 (merged by maintainer) * docs(devlog): p3232 verification result * docs(devlog): regaudit3 recount and landing table * docs(devlog): record the lidge-jun#3239/lidge-jun#3240 revert and correct the lidge-jun#3228 disposition * docs(devlog): rv3239 revert record * docs(devlog): rv3239 audit note * docs(devlog): regaudit3 second-dispatch verdict * docs(devlog): regaudit3 recount refreshed (lidge-jun#1419 closed by maintainer; count 4) * docs(devlog): regaudit3 final CI verdict and c-7 --------- Co-authored-by: jun <jun@lidge.dev>
agentHits
pushed a commit
to agentHits/opencodex
that referenced
this pull request
Sep 17, 2026
… tools (carry of lidge-jun#3226) (lidge-jun#3234) * fix(responses): scope self-named namespace scrub * fix(responses): preserve colliding namespaced functions * fix(responses): honor scrub authorization identity * fix(responses): cover function scrub edge cases * fix(responses): read Chat-shaped function names in the scrub authorization set buildTools accepts the Chat-shaped `{ type: "function", function: { name } }` declaration and the undeclared-tool guard authorizes it, but the scrub's raw-body collector only read `spec.name`. Such a function never entered the raw-body set, the intersection dropped it, and a self-named echo for it reached Codex again. Mirror addWireToolName and read the nested name. Regression: Chat-shaped catalog + upstream `function_call { name: "wait", namespace: "wait" }` is scrubbed; red without this change. --------- Co-authored-by: Alex Jordan <60003097+alex-jordan547@users.noreply.github.com> Co-authored-by: jun <jun@lidge.dev>
agentHits
pushed a commit
to agentHits/opencodex
that referenced
this pull request
Sep 17, 2026
…sion audit (lidge-jun#3218) * docs(devlog): open the bug/PR closeout stack roadmap * docs(devlog): fold the A-gate import-boundary finding into phase 5 * docs(devlog): record the lidge-jun#3163 and lidge-jun#3166 landings * docs(devlog): record why lidge-jun#2986 does not land in this train * docs(devlog): close out the bug/PR closeout stack * docs(devlog): record the final green CI verdict on dev * docs(devlog): open the bug-label drawdown roadmap with audit corrections * docs(devlog): record the Batch A landings and first rebase carry * docs(devlog): record the Batch B rebase carries * docs(devlog): record why the rebase service earned its keep * docs(devlog): record the Batch C rebases and the one real review finding * docs(devlog): record the lidge-jun#2999 scope boundary that survived execution * docs(devlog): record Batch D - every bug PR closed * docs(devlog): record what the PR half of the campaign cost * docs(devlog): replan the remaining issues to one per cycle * docs(devlog): carry the i3141 evidence into the replan * docs(devlog): diagnose i3141 - fix predates the reported version * docs(devlog): retire the second bundle * docs(devlog): record the i3141 re-triage action and outcome * docs(devlog): diagnose i3152 log table jitter * docs(devlog): i3152 - measurement disproved the layout diagnosis * docs(devlog): diagnose i3136 slashed-id price lookup * docs(devlog): diagnose i3150 citation marker passthrough * docs(devlog): diagnose i3155 capacity plan allowlist * docs(devlog): i1419 stays open pending crash frames * docs(devlog): record the i1419 re-triage ask * docs(devlog): diagnose i2999 publication overwrite race * docs(devlog): record the i2999 outcome and remaining scope * docs(devlog): diagnose i2813 as a client-side reserve gate * docs(devlog): diagnose i1527 residuals as trace-blocked * docs(devlog): correct i1527 envelope-cap wording (192 blobs, HTTP 400) * docs(devlog): plan p3193 loopback alpha-search reimplementation * docs(devlog): record p3193 landing (lidge-jun#3205 -> 144ddf4) * docs(devlog): plan the main->dev regression audit * docs(devlog): pin regaudit counts, add tests-only/security passes and the exact-head dispatch * docs(devlog): record regaudit reviewer verdicts * docs(devlog): record the exact-head dev CI verdict and Windows classification * docs(devlog): record the main control run proving the Windows failures predate the range * docs(devlog): record the pass-1 recount and the lidge-jun#3217 root cause * docs(devlog): plan i3217 (Spark functions-namespace flattening) * docs(devlog): record i3217 landing (lidge-jun#3224 -> fe855b3) * docs(devlog): regaudit2 recount and disposition table * docs(devlog): regaudit2 CI verdict on fe855b3 and the four PR arrivals * docs(devlog): plan p3226 (scoped namespace scrub) * docs(devlog): p3226 audit finding and carry plan * docs(devlog): record p3226 landing (lidge-jun#3234 -> 827456e) * docs(devlog): plan p3227 (combo zero-output incomplete failover) * docs(devlog): record p3227 landing * docs(devlog): plan p3228 (encrypted V2 spawn native fallback) * docs(devlog): record p3228 landing * docs(devlog): plan p3229 (Codexless originator in task recovery) * docs(devlog): record p3229 landing and the lidge-jun#3239 regression repair * docs(devlog): r3239 regression repair record * docs(devlog): r3239 audit note * docs(devlog): record p3232 (merged by maintainer) * docs(devlog): p3232 verification result * docs(devlog): regaudit3 recount and landing table * docs(devlog): record the lidge-jun#3239/lidge-jun#3240 revert and correct the lidge-jun#3228 disposition * docs(devlog): rv3239 revert record * docs(devlog): rv3239 audit note * docs(devlog): regaudit3 second-dispatch verdict * docs(devlog): regaudit3 recount refreshed (lidge-jun#1419 closed by maintainer; count 4) * docs(devlog): regaudit3 final CI verdict and c-7 --------- Co-authored-by: jun <jun@lidge.dev>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Carry of #3226 by @alex-jordan547 (four commits cherry-picked with author credit) plus one maintainer commit.
#3226 scopes the #3217 self-named-namespace scrub (landed in #3224) to bare custom / bare function tools the current turn actually declared, so a genuine same-name namespaced tool (
namespace: "exec"holdingname: "exec", which codex-rs routes by structuredToolName) is no longer damaged. Authorization is built fromtools,additional_tools, andtool_search_output, threaded throughbuildToolBridgeMaps, honourstool_choice, and applies to both the SSE and bounded-JSON passthrough paths.Review found one hole:
collectBareToolSpecsread onlyspec.name, so a Chat-shaped{ type: "function", function: { name } }declaration — whichbuildToolsaccepts and the undeclared-tool guard authorizes — never entered the raw-body set; the intersection dropped it and a self-named echo for that function would loop Codex again. The maintainer commit mirrorsaddWireToolNameand reads the nested name, with a regression that is red without it.Supersedes #3226 (landed via maintainer).
Verification
bun test tests/responses-self-named-namespace-scrub.test.ts tests/responses-undeclared-tool-guard.test.ts tests/openai-responses-passthrough.test.ts— 202 pass / 0 fail. New case "a Chat-shaped function declaration still authorizes the bare function scrub" fails without the collector change.bun run typecheckclean;bun run privacy:scanpassed.Checklist
dev