Skip to content

Bind executor plugin measurements to the trusted plugin version - #46528

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/d63430b37bf2de360c8d09af7f7453a5b5024d72
Sep 19, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/d63430b37bf2de360c8d09af7f7453a5b5024d72

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

Bind executor plugin measurements to the trusted plugin version

Why

Identical script contents across plugin versions do not establish that the same measurement declaration applies. Resolving measurements through generic command attribution could use a different version's declaration, while shared helper paths could make attribution ambiguous.

What changed

  • Match canonical executor paths against trusted plugin identities before comparing script contents. Require an exact version match for measurements while retaining attribution across versions with matching contents.
  • Keep measurement declarations bound to the selected trusted root, and allow distinct versions to coexist when extending trusted roots.
  • Add PluginMeasurementTarget to extract an untrusted plugin/version hint from canonical remote cache paths, respecting Windows and POSIX path conventions.
  • Skip executor lookups for unrelated scripts so attribution does not wait for executor provisioning.
  • Increase the login unit test timeout in Bazel to long.

Testing

Add regression coverage for multiple plugins and versions, canonical aliases, symlink escapes, path casing, and executor lookup avoidance. Add a remote execution integration test verifying that mismatched versions retain command attribution but receive no metrics sidecar, and matching versions use the trusted measurement declaration.

## Why

Identical script contents across plugin versions do not establish that the same measurement declaration applies. Resolving measurements through generic command attribution could use a different version's declaration, while shared helper paths could make attribution ambiguous.

## What changed

- Match canonical executor paths against trusted plugin identities before comparing script contents. Require an exact version match for measurements while retaining attribution across versions with matching contents.
- Keep measurement declarations bound to the selected trusted root, and allow distinct versions to coexist when extending trusted roots.
- Add `PluginMeasurementTarget` to extract an untrusted plugin/version hint from canonical remote cache paths, respecting Windows and POSIX path conventions.
- Skip executor lookups for unrelated scripts so attribution does not wait for executor provisioning.
- Increase the login unit test timeout in Bazel to `long`.

## Testing

Add regression coverage for multiple plugins and versions, canonical aliases, symlink escapes, path casing, and executor lookup avoidance. Add a remote execution integration test verifying that mismatched versions retain command attribution but receive no metrics sidecar, and matching versions use the trusted measurement declaration.

GitOrigin-RevId: d63430b37bf2de360c8d09af7f7453a5b5024d72
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/d63430b37bf2de360c8d09af7f7453a5b5024d72 branch from 1bd16da to 6cf2ff1 Compare September 19, 2026 00:14
@copyberry
copyberry Bot merged commit 6cf2ff1 into main Sep 19, 2026
1 check failed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/d63430b37bf2de360c8d09af7f7453a5b5024d72 branch September 19, 2026 00:14
@github-actions

Copy link
Copy Markdown
Contributor


Thank you for your submission, we really appreciate it. Like many open-source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution. You can sign the CLA by just posting a Pull Request Comment same as the below format.


I have read the CLA Document and I hereby sign the CLA


You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot.

@github-actions github-actions Bot locked and limited conversation to collaborators Sep 19, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant