Sanitize MCP capture and board resource failures - #2443
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Independent review disposition for base Both reviews confirmed that all ten in-scope failed- One LOW documentation convenience finding is declined for this bounded slice: the security guide's older copy-paste filter does not name the two new test classes. The executable tests exist and were run directly, so this is not a runtime or security defect. The broader API project result remains reported as 2,786 passed, 4 skipped, 1 failed due the existing #2399 shared-interceptor contamination; its exact isolated test then passed 1/1. Exact-head hosted Linux and Windows API jobs remain required before merge. |
…e-board-error-safety
|
Current-base requalification is pushed at exact head The merge commit preserves the original slice and adds only #2440's two Smart CI files from main. The effective PR diff remains the same five MCP/test/security-doc files. A fresh interaction review found no CRITICAL/HIGH defect and no shared backend, sanitizer, MCP, test, or documentation path with the base delta. Reproof after the base merge:
The prior LOW copy-paste filter omission remains declined and non-blocking. The earlier broad API project result and #2399 disposition are unchanged because the base delta is scripts-only. Exact-head hosted CI and the automatic connector review are pending; the aging window restarted with this push. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a4a5448741
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…e-board-error-safety
|
Final bounded current-base refresh is pushed at exact head The added base delta is PR #2442's maintainer decision packet and is documentation-only. The effective PR diff remains exactly the same five MCP/test/security-guide files. A new fresh-context interaction review read the changed instructions and ADRs, found no authorization or acceptance change for this slice, and reported no CRITICAL/HIGH finding or human gate. Reproof after this refresh:
Exact-head hosted CI and the refreshed automatic connector review are pending, and the aging window restarted with this push. This is the final base refresh for this bounded cycle; another moving-base event before the verdict will park the PR with an exact restart contract. |
|
[Codex lane release v2] CLAUDE_SYNC_PACKET |
|
Coordinator merge disposition for exact head 8744a06: the base was refreshed to current main (delta since the reviewed base: PR #2444 docs, PR #2445 review-poll composable, PR #2427 CI edge, none touching the five MCP/test/security-guide files this PR changes), ci-required is green on this head, no open threads, and the two fresh-context passes plus the interaction reviews recorded above found no CRITICAL/HIGH. The earlier park was only because main moved. Merging with a merge commit. |
Summary
Resultmessages in MCP capture and board resources with the existing public failure sanitizerPart of #2351.
Verification
Taskdeck.Api.Tests: 2,786 passed, 4 skipped, 1 unrelated [Backend][Testing] Isolate intermittent batch command-shape samples on Windows #2399 isolation failure; the exact failed test then passed 1/1git diff --check: passedBoundaries
This slice covers failed
Resultmessages emitted byCaptureResourcesandBoardResources. PersistedCaptureItemDto.ErrorMessage, arbitrary thrown exceptions, invalid caller IDs, silent child-result behavior, MCP tools, provider health, and legacy persisted failure reasons remain separate contracts.