Repository navigation
[codex] Gate remote plugin tools on feature flag - #27295
daniel-oai wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 11773bda24
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if !config.remote_plugin_enabled { | ||
| return HashMap::new(); |
There was a problem hiding this comment.
Preserve workspace remote plugin configs when sharing is enabled
With plugin_sharing on and remote_plugin off, app-server still lists Workspace installs. Returning empty configs here means installed workspace remote plugins never load skills/MCP/hooks, so the listed install is unusable. Gate only global configs or include the sharing flag. guidance
Useful? React with 👍 / 👎.
|
Closing per principal review. This encodes a product contract for remote plugin feature gating, and that is not a safe slam-dunk fix without explicit owner alignment on expected remote plugin behavior. |
Fixes #26275.
Summary
features.remote_pluginbefore plugin load, hook load, effective MCP construction, and startup remote cache/bundle refresh.remote_plugin = true, including app-server installed-plugin visibility.datascienceWidgets.Product contract
This PR chooses the contract that account-synced remote installed plugins are a feature-gated effective tool surface, not host-local config. A remote-installed plugin and its cached bundle may exist on disk, but without
remote_plugin = truethey do not contribute MCP servers, skills, hooks, or app-server installed-plugin surface.Explicit remote install/uninstall paths remain intended to work; those flows should operate under configs where remote plugin support is intentionally enabled. If a deployment wants synced remote plugin state to be globally forced while still allowing per-host opt-out, that remains a product/config-precedence decision outside this narrow fix.
Validation
just fmtjust test -p codex-core-pluginspassed: 204 testsjust test -p codex-core to_mcp_config_gates_cached_remote_plugin_mcp_by_remote_plugin_featurepassedjust test -p codex-app-server plugin_installed_omits_global_remote_installs_when_remote_plugin_disabled plugin_installed_prefers_remote_curated_conflicts_when_remote_plugin_enabledpassedjust fix -p codex-core-pluginspassed; it reported the existingclippy::large_enum_variantwarning incore-plugins/src/manifest.rsjust fix -p codex-corepassedjust fix -p codex-app-serverpassedI also attempted broad
just test -p codex-core. It did not complete green in this local managed sandbox, but the failures were unrelated local sandbox/harness categories rather than the new regression:Operation not permitted,sandbox-exec: sandbox_apply: Operation not permitted, and sandbox env expectation mismatches such asseatbeltvsnot-set./Users/daniels/.codex/proxy.could not locate binary "test_stdio_server".The broad run summary was: 2647 tests run, 2581 passed, 65 failed, 1 timed out, 16 skipped, with 2 flaky and 1 leaky result.