Skip to content

fix(source-read): recover GitHub PR diffs within the existing request budget - #6196

Draft
loopx-agent wants to merge 1 commit into
mainfrom
codex/public-source-github-diff-recovery-20261011
Draft

loopx-agent wants to merge 1 commit into
mainfrom
codex/public-source-github-diff-recovery-20261011

Conversation

@loopx-agent

@loopx-agent loopx-agent commented Oct 11, 2026 •

Copy link
Copy Markdown
Collaborator

Goal And Delivered Outcome

A query-free GitHub PR .diff can time out at every checked address even while its canonical public diff endpoint is reachable. The anonymous reader previously returned an error until the caller supplied that second URL. After transport failure it now derives the same PR's canonical URL and tries it through the existing checked HTTPS path, within the original deadline and six-hop limit.

Ordinary HTTPS reads and redirects retain their current path. TLS/certificate, HTTP-policy and mixed/private-DNS rejections do not activate recovery. requested_url and observed_url preserve source provenance.

Related to #6181; base: main. This is a reproduced transport defect, without a separate roadmap claim.

Author Declaration

  • Written by: model_agent (OpenAI GPT-6 / Codex).
  • Specification: no separate written specification; the bounded recovery request in this PR is the basis.
Criterion Disposition Symbol / path Evidence
Recover the exact anonymous public PR diff after transport failure implemented public_source_reader.fetch failing-before recovery fixture, passing after the change
Keep one deadline, checked DNS/address pinning, TLS identity, anonymous headers and existing hop limit implemented existing fetch loop deadline, mixed-DNS, policy, cleanup and six-hop negative cases
Do not rewrite queries, lookalike hosts or other source paths implemented exact hostname/path match nonmatching URL regression cases

Scope And Continuation

Python remains the existing specialized IO provider; no parallel capability, state store, configuration or frontend control is added. Native Chat already owns opt-in tool discovery, and this patch stays inside that provider. The future-facing pass found no useful separate helper: the recovery transition reuses the current redirect/request owner.

The reader slice is independently reversible. Formal installed-host adoption, original Lark-topic acceptance and response-time qualification remain with the existing delivery owner; this PR does not claim those outcomes. No runtime self-merge or installation is requested here.

Validation

  • Tested revision: 5a0be88.
  • Run state: running (whole-suite pytest; completed checks below).
  • Input classes: synthetic, public_fixture, authorized_private_read_only.
Check kind Result Public-safe evidence / limitation
regression_parity passed Before patch: recovery and canonical mixed-DNS fixtures fail; afterward all 15 new cases pass.
unit passed python -m pytest tests/test_public_source_reader.py tests/test_chat_agent.py tests/test_chat_codex_context.py -q: 287 passed. Includes TLS/HTTP rejection, source restriction, cleanup, deadline and hop boundaries.
static passed Required Ruff command, mypy (19 sources), CLI output-budget smoke, changed-scope loopx check and diff checks.
integration passed Goal-aware native premerge: 5 direct checks and 10 selected checks pass; quality policy disabled, no receipt manufactured.
real_entrypoint passed Actual native sol/low HTTP candidate requested only the original README and PR-diff URLs and returned full bodies and concrete facts. A further native candidate injected a primary timeout after checked DNS: one call to the original PR-diff URL automatically recovered through real canonical HTTPS, with 13,738 characters, no reader/orchestration truncation and matching digest. Trace confirms the recovery branch; no fallback URL was supplied. Model/transport/permissions remained sol/low, host HTTP, workspace-only; owned process closed. The injected outage is synthetic, not a natural-failure or installed Bot qualification. Existing opt-out and permission tests pass.
real_backend passed Anonymous worker independently read the original public PR diff, 13,738 characters, untruncated, matching digest. This run followed an ordinary redirect. A separate controlled primary-transport failure recovered through the real DNS-checked, pinned anonymous canonical endpoint in 0.963 seconds and returned the same full-body digest. The primary failure was injected; this does not prove a naturally occurring TCP stall in that run.
static failed Whole-tree loopx check reports two credential-pattern matches in unchanged synthetic rejection fixtures at tests/capabilities/test_issue_fix_explore_private_evidence.py:170,187; that file is byte-identical to the base. Changed-scope scan passes.
unit running Full python -m pytest -q; final aggregate will be added before declaring validation complete.

The earlier two-source native candidate turn took 56.388 seconds and repeated reads after output truncation. The additional single-source fault-injected native candidate took 19.862 seconds end to end (0.929 seconds in the reader); it completed one untruncated tool call without asking the user for a fallback URL. Neither run qualifies formal latency/SLA or installed Bot acceptance. Private observations remain local; no transcripts, raw tool results or credentials are attached. No frontend/Lark UI changed or packaged frontend acceptance is claimed.

Frontend / Visual Evidence

  • UI impact: none. Existing provider tool output and errors remain the entrypoint.

Type of Change / LoopX Area

  • Bug fix and focused regression tests; bundled capability/extension provider.
  • Shared-authority RFC fixture impact: N/A; no control-plane or authority contract changes.

Boundary Checklist

  • Public code and this description exclude private state, credentials, raw traces, local paths and private Goal/session identifiers.
  • Scope is limited to the reader and its regression tests.
  • Every commit includes a DCO sign-off.
  • UI impact is none; runtime changes are left for maintainer merge after exact-head review.

…ailure

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant