Skip to content

[codex] Gate remote plugin tools on feature flag - #27295

Closed
daniel-oai wants to merge 1 commit into
mainfrom
codex/fix-plugin-tool-scope-26275
Closed

daniel-oai wants to merge 1 commit into
mainfrom
codex/fix-plugin-tool-scope-26275

Conversation

@daniel-oai

Copy link
Copy Markdown
Contributor

Fixes #26275.

Summary

  • Gate account-synced remote installed plugin configs behind features.remote_plugin before plugin load, hook load, effective MCP construction, and startup remote cache/bundle refresh.
  • Keep intended remote-installed plugin behavior when remote_plugin = true, including app-server installed-plugin visibility.
  • Add regressions for cached Data Analytics-style remote plugin MCP config so cached bundles alone cannot silently expose datascienceWidgets.

Product contract

This PR chooses the contract that account-synced remote installed plugins are a feature-gated effective tool surface, not host-local config. A remote-installed plugin and its cached bundle may exist on disk, but without remote_plugin = true they do not contribute MCP servers, skills, hooks, or app-server installed-plugin surface.

Explicit remote install/uninstall paths remain intended to work; those flows should operate under configs where remote plugin support is intentionally enabled. If a deployment wants synced remote plugin state to be globally forced while still allowing per-host opt-out, that remains a product/config-precedence decision outside this narrow fix.

Validation

  • just fmt
  • just test -p codex-core-plugins passed: 204 tests
  • just test -p codex-core to_mcp_config_gates_cached_remote_plugin_mcp_by_remote_plugin_feature passed
  • just test -p codex-app-server plugin_installed_omits_global_remote_installs_when_remote_plugin_disabled plugin_installed_prefers_remote_curated_conflicts_when_remote_plugin_enabled passed
  • just fix -p codex-core-plugins passed; it reported the existing clippy::large_enum_variant warning in core-plugins/src/manifest.rs
  • just fix -p codex-core passed
  • just fix -p codex-app-server passed

I also attempted broad just test -p codex-core. It did not complete green in this local managed sandbox, but the failures were unrelated local sandbox/harness categories rather than the new regression:

  • Sandbox / Seatbelt / PATH-alias restrictions: Operation not permitted, sandbox-exec: sandbox_apply: Operation not permitted, and sandbox env expectation mismatches such as seatbelt vs not-set.
  • Managed network proxy setup in approval tests: failed to create /Users/daniels/.codex/proxy.
  • First-party test binary lookup in MCP stdio/code-mode/search/truncation tests: could not locate binary "test_stdio_server".
  • CLI/session/apply-patch/provider-auth harness failures and timeouts that depend on those local sandbox/binary assumptions.

The broad run summary was: 2647 tests run, 2581 passed, 65 failed, 1 timed out, 16 skipped, with 2 flaky and 1 leaky result.

@daniel-oai
daniel-oai marked this pull request as ready for review June 10, 2026 03:19
@daniel-oai
daniel-oai requested a review from a team as a code owner June 10, 2026 03:19

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 11773bda24

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +595 to +596
if !config.remote_plugin_enabled {
return HashMap::new();

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Preserve workspace remote plugin configs when sharing is enabled

With plugin_sharing on and remote_plugin off, app-server still lists Workspace installs. Returning empty configs here means installed workspace remote plugins never load skills/MCP/hooks, so the listed install is unusable. Gate only global configs or include the sharing flag. guidance

Useful? React with 👍 / 👎.

@daniel-oai

Copy link
Copy Markdown
Contributor Author

Closing per principal review. This encodes a product contract for remote plugin feature gating, and that is not a safe slam-dunk fix without explicit owner alignment on expected remote plugin behavior.

@daniel-oai daniel-oai closed this Jun 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Data Analytics plugin tools appear in remote Codex CLI without local install/config

1 participant