fix(security): stop delayed and additional tool callbacks after cancellation - #2430
fix(security): stop delayed and additional tool callbacks after cancellation#2430HAYDEN-OAI wants to merge 2 commits into
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Castiron custom code✅ No new custom-code files detected. 34 mixed files remain; 0 existing customizations changed. Compared 34 existing customizations unchanged
A changed generated baseline means this report cannot reliably identify which handwritten lines changed. Inspect the custom-code diffDownload the exact patch produced by this run (requires repository access): gh run download 32412082344 --repo openai/openai-node \
--name castiron-custom-code-32412082344-1 --dir /tmp/castiron-custom-code-32412082344-1
git apply --stat /tmp/castiron-custom-code-32412082344-1/custom-code.patch
cat /tmp/castiron-custom-code-32412082344-1/custom-code.patchOr reproduce it from an SDK checkout containing the vendored reporter: git fetch --no-tags origin a0d68cc53125c2cb82eab31271b8984b8d65d4b2 32d1c19a983598b67fe6e2449ea1e3b361306c63
python3 scripts/castiron/custom_code_report.py report \
--base a0d68cc53125c2cb82eab31271b8984b8d65d4b2 \
--head 32d1c19a983598b67fe6e2449ea1e3b361306c63 --fetch --require-head-hash --public \
--out /tmp/castiron-custom-code-32d1c19a9835
cat /tmp/castiron-custom-code-32d1c19a9835/custom-code.patchThis is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 20219f5f61
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
jbeckwith-oai
left a comment
There was a problem hiding this comment.
Independent two-pass security review validates the three existing cancellation findings, including a High post-abort callback bypass, and identifies one additional Medium result-preservation regression documented inline.
Summary
chat.completions.runTools()from starting a privileged parsed tool callback after cancellation occurs during asynchronous argument parsing.runner.abort().APIUserAbortError, wait for callbacks that were already running, and retain results/messages for callbacks that began before cancellation.Regression-first proof
Before the change, the new real-public-client suite produced 10 failing security cases and 6 passing compatibility controls: synthetic privileged transfer callbacks ran with the runner signal already aborted. The final 20-case suite covers non-streaming and streaming public clients, external abort signals and direct runner cancellation, delayed parsers, sequential callbacks, in-flight parallel callback completion, one-shot buffered-turn compatibility, context, parser feedback, and
afterCompletion.Verification
publintpassed with only the pre-existing vendor-export warning.