feat(agents): Prepare hosted files and download turn artifacts - #1130
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
Security findingsAdvisory findings (3)
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Castiron custom code✅ No new custom-code files detected. 93 mixed files remain; 0 existing customizations changed. Compared 93 existing customizations unchanged
53 more in the full report. A changed generated baseline means this report cannot reliably identify which handwritten lines changed. Inspect the custom-code diffDownload the exact patch produced by this run (requires repository access): gh run download 36932146783 --repo openai/openai-java \
--name castiron-custom-code-36932146783-1 --dir /tmp/castiron-custom-code-36932146783-1
git apply --stat /tmp/castiron-custom-code-36932146783-1/custom-code.patch
cat /tmp/castiron-custom-code-36932146783-1/custom-code.patchOr reproduce it from an SDK checkout containing the vendored reporter: git fetch --no-tags origin e3b78a3089c618235eed12289b9b8f8113e5d3d0 d1195290a8c0a0df69e9172ca032266f64da440b
python3 scripts/castiron/custom_code_report.py report \
--base e3b78a3089c618235eed12289b9b8f8113e5d3d0 \
--head d1195290a8c0a0df69e9172ca032266f64da440b --fetch --require-head-hash --public \
--out /tmp/castiron-custom-code-d1195290a8c0
cat /tmp/castiron-custom-code-d1195290a8c0/custom-code.patchThis is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9d4caa8a37
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
🛡️ Codex Security Review · Automatically triggered
Here are some automated security review suggestions for this pull request.
Reviewed commit: 47d95dd266
ℹ️ About Codex security reviews in GitHub
This is an experimental Codex feature. Security reviews are triggered when:
- You comment "@codex security review"
- A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review
Once complete, Codex will leave suggestions, or a comment if no findings are found.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4f779d3690
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
bd1a953 to
5bd07cb
Compare
438d854 to
0649165
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5bd07cb767
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
0649165 to
a21cb33
Compare
5bd07cb to
880b54d
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 880b54d54e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
a21cb33 to
eb641f6
Compare
2bcf8f7 to
05f56d6
Compare
048963c to
fccc185
Compare
05f56d6 to
badc14b
Compare
badc14b to
721372c
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 721372cc93
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review pls |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 04ffa17d7c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
|
@codex review pls |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 88435565c6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f7497c9ec1
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: bea0dbc92b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 388c5b8613
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
🛡️ Codex Security Review · Automatically triggered
Here are some automated security review suggestions for this pull request.
Reviewed commit: 388c5b8613
ℹ️ About Codex security reviews in GitHub
This is an experimental Codex feature. Security reviews are triggered when:
- You comment "@codex security review"
- A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review
Once complete, Codex will leave suggestions, or a comment if no findings are found.
markstuart-oai
left a comment
There was a problem hiding this comment.
Reviewed at 741a41c5. Two changes remain before approval: keep directory selection from failing on excluded subtrees, and split the new 1,280-line test suite along the existing preparation/staging and artifact-download boundaries. Details are inline.
Validation: source/test review, including cancellation, stream ownership and path handling; 11 exact-head hosted checks passed, one skipped, and both Castiron statuses passed. No local tests or live API validation were run.
There was a problem hiding this comment.
🛡️ Codex Security Review · Automatically triggered
Here are some automated security review suggestions for this pull request.
Reviewed commit: d1195290a8
ℹ️ About Codex security reviews in GitHub
This is an experimental Codex feature. Security reviews are triggered when:
- You comment "@codex security review"
- A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review
Once complete, Codex will leave suggestions, or a comment if no findings are found.
markstuart-oai
left a comment
There was a problem hiding this comment.
Reviewed the follow-up at d1195290. The split into environment-file and artifact-download suites resolves the test-organization finding. One correctness issue remains: discovery errors can silently remove paths that explicitly match the requested selection; details are inline.
Validation: immutable source and test review, plus 11 successful exact-head hosted checks, one skipped queue check, and both successful Castiron statuses. No repository workloads or live API smoke tests were run locally.
| } | ||
|
|
||
| override fun visitFileFailed(path: Path, error: IOException): FileVisitResult { | ||
| if (path == root) throw error |
There was a problem hiding this comment.
[P2] Preserve failures for paths that match the requested selection
visitFileFailed also receives paths whose attributes could not be read, so returning CONTINUE for every descendant silently drops explicitly selected files. For example, on POSIX as an unprivileged user, let root/private/data.txt exist and make private readable but not searchable (mode 0400); include = listOf("private/data.txt") can enumerate the name but cannot stat it, reaches this callback, and returns a successful empty preparation. The new test only removes read permission from the file itself, whose attributes remain readable, so it exercises the later upload failure instead.
Please propagate failures for matching paths and for failed subtrees that could contain requested matches; only ignore discovery failures when the path is provably unrelated to the includes. A conservative fallback is fine; this does not require a full glob-pruning engine. Cover the matching-entry/required-subtree cases in both blocking and async helpers. Documenting blanket best-effort enumeration still leaves callers unable to tell that their requested input set is incomplete.
Summary
Prepare files for a hosted Agent and download the artifact from the turn that produced it, without assembling uploads, environment references, and paginated artifact searches by hand.
Before:
After:
The beta helpers also accept explicit directory include globs, stage an upload into an existing environment, and support async clients. Preparation checks selected local paths before uploading, leaves upload limits to the API, and returns upload IDs for explicit cleanup; partial failures retain known IDs. Downloads resolve the exact turn/path across pages and preserve request options. Use
.content(path)for the native response (including in-memory reads), or.download(path, destination)for an application-owned destination. Local upload paths assume application-owned files and stable source directories; uploaded contents may still be user-provided.This PR now targets
maindirectly. Reattachment/result recovery is deferred: a silent attachment cannot reliably distinguish pending work from an already-completed turn, so these helpers do not depend on SDK-side recovery heuristics.Stack