🤖 feat: choose what a settings backup carries - #3985
Conversation
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: cbfabe752e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
This comment has been minimized.
This comment has been minimized.
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7c2d5ad4be
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Security Review
Here are some automated security review suggestions for this pull request.
Reviewed commit: 7c2d5ad4be
ℹ️ About Codex security reviews in GitHub
This is an experimental Codex feature. Security reviews are triggered when:
- You comment "@codex security review"
- A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review
Once complete, Codex will leave suggestions, or a comment if no findings are found.
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 543d699c8f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 543d699c8f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
This comment has been minimized.
This comment has been minimized.
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 875b0c8c82
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
This comment has been minimized.
This comment has been minimized.
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b9f9f51be0
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Security Review
Here are some automated security review suggestions for this pull request.
Reviewed commit: b9f9f51be0
ℹ️ About Codex security reviews in GitHub
This is an experimental Codex feature. Security reviews are triggered when:
- You comment "@codex security review"
- A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review
Once complete, Codex will leave suggestions, or a comment if no findings are found.
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9fd948f88e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Security Review
Here are some automated security review suggestions for this pull request.
Reviewed commit: 9fd948f88e
ℹ️ About Codex security reviews in GitHub
This is an experimental Codex feature. Security reviews are triggered when:
- You comment "@codex security review"
- A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review
Once complete, Codex will leave suggestions, or a comment if no findings are found.
|
@codex review |
This comment has been minimized.
This comment has been minimized.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 38cdefbd50
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
This comment has been minimized.
This comment has been minimized.
|
@codex review |
This comment has been minimized.
This comment has been minimized.
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 39b3c721eb
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
This comment has been minimized.
This comment has been minimized.
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
|
@codex review New head 2312afa adds one CI-only commit: the Codex Comments gate now accepts a completed status board whose findings are all marked Resolved (this PR's board lists 43 resolved advisories from the earlier revision, which made the job fail with zero open findings). Product code is unchanged from 5bca829. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2312afad94
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 354ed9213e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ef0346acfe
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2f1f575a55
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Replace credential detection in the MCP export with a per-category content
selection saved in settingsBackup (includeInstructions, includeAgents,
includeSkills, includeGlobalMemory, includeMcp, includeMcpHeaders,
includeMcpCommands, includePreferences; includeProjects keeps its opt-in
default). One selection governs both directions: collection and export skip
unselected categories, and a restore only writes selected ones.
MCP header values and stdio commands are published as written when selected,
gated by the existing byte-bound secret-scan approval. When deselected they
become the existing redaction marker, so a restore keeps this machine's values;
the same projection is applied to a checked-out backup at restore time so the
restoring machine's selection wins. Literal headers from a backup now restore
verbatim; {secret: NAME} references keep the local-only endpoint-match rule.
The Backup settings screen replaces the static "Included" list with the
checkbox selection (MCP has two indented sub-options).
Review follow-ups: readBackupPayload skips unselected manifest entries so a deselected category is never parsed; the preview says when MCP is excluded; every content toggle has a Ctrl+Alt shortcut.
With a category deselected, the restore-side projection now marks the field even when the backup entry does not carry it, so the existing rehydration keeps this machine's value instead of dropping it with the entry. Exports are unchanged.
… markers parseManifest drops mcpRedactions unread when the selection leaves MCP alone, so a malformed or oversized list cannot fail a restore of the other categories. The restore-side projection no longer applies the publish caps to the markers it adds for absent deselected fields, so a large valid backup stays restorable when a category is deselected.
A backup written when header values were redacted one by one lists child paths; deselecting headers now replaces the object with one marker, and the stale child path made the restore reject the manifest. Keep only listed paths that still name a marker in the projected file.
parseManifest now filters entries by the content selection before the per-entry checks, so a malformed entry for a category the restore leaves alone cannot fail it. This replaces the read-loop skip.
2f1f575 to
c360ada
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c360ada2f3
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
The file-count limit ran before the selection filter, so a manifest with too many entries in a deselected category blocked a restore of the rest. The manifest bytes are already budget-charged and the tree walked whole before this point, so counting the retained entries weakens nothing.
A failed export half of the preview returns an empty redaction list, which the "Kept on this device" card read as full coverage.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3281f2ee4d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3281f2ee4d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
… refuse them Builds before this change restore a header as the same-named local value or nothing, so a backup carrying literal header values would restore on them as complete while dropping every header the user chose to carry. Such backups now declare schema version 2, which those builds reject as an invalid manifest; backups without literal headers keep version 1 and still restore on a downgraded build. The current reader accepts both.
|
Pausing the review loop on this PR for a human decision. Reason: the same area has produced a new finding in each of the last rounds. Five findings so far ask that damage in a deselected category never block a restore, at successive layers: manifest entries (fixed), MCP redaction metadata (fixed), the file-count limit (fixed), duplicate keys in the manifest document (open), and now repository tree validation before checkout (open). Each remaining fix adds mechanism at a layer this PR does not otherwise touch. Rather than keep extending the selection downward, the description now states the boundary the code implements: the selection filters payload entries; integrity checks on the manifest document and the repository tree still apply to the whole backup. Open threads awaiting that decision: the duplicate-key check and the tree validation. Everything else on the current head is fixed or deferred with a recorded follow-up. |
The selection filters payload entries. Document well-formedness and the repository tree validation before checkout stay whole-backup checks; the comment records why the filter cannot run first.
Summary
The settings backup now lets the user choose what it carries. Nine checkboxes in the Backup settings form select the categories (global instructions, agent definitions, skills, global memory, portable preferences, MCP server configuration, and under MCP the HTTP header values and stdio commands) alongside the existing project opt-in. The same selection governs export and restore: an unselected category is absent from the published backup and is never written by a restore. Deselected MCP headers or commands become the existing redaction marker, so a restore keeps this machine's values for them.
Background
Backups publish
mcp.jsonc, and MCP header values, stdio commands, and URLs commonly hold credentials. The earlier revision of this PR tried to solve that with credential-format detection and shell-grammar redaction ofNAME=valueassignments. That approach guesses at what is secret, fails closed on shapes it cannot parse, and makes the user rehydrate redacted values on every restore even when they wanted them published. Per review discussion, this PR replaces detection with an explicit choice: the user decides which categories a backup carries, and anything sensitive that is still selected goes through the existing byte-bound secret-scan approval.Supersedes the redaction approach previously on this PR (old head
e6352db362).Implementation
settingsBackup.tsadds optionalinclude*flags next toincludeProjects;resolveBackupContents()applies defaults once (all on, projects off as before, which was a deliberate privacy default in 🤖 feat: opt-in project bundle for settings backup #4043). Olderconfig.jsonfiles load unchanged.collectAllowlistedFilesandscanBackupFilesForSecretstake the resolved contents, so unselected categories are never read or scanned.redactMcpConfignow receives anMcpProjectionOptions(headers and commands on or off) instead of deciding by pattern; deselected fields become__MUX_BACKUP_REDACTED__and are listed inmcpRedactions.mcpConfigRequiresPublishApprovalflags selected stdio commands, credential-bearing URLs, and now literal header values too. A{secret: NAME}reference names a secret without carrying it, so it does not trigger approval. URL credentials are covered by the approval gate only; no detection.readBackupPayloadtakes the current machine's selection and skips unselected manifest entries before opening them, so a deselected category is never read or parsed and a malformed entry there cannot fail a restore of the rest. Checks that apply to the backup as a whole (manifest well-formedness, the repository tree validation before checkout) still cover every category: the selection filters payload entries, not the integrity of the document or repository that lists them. The selected payload is then projected throughselectBackupContentsbefore preview, approval, and restore, so a machine with headers unchecked keeps its own header values whether the backup carries them or omits the field entirely, and unselected local files are no longer reported as local-only.{secret: NAME}references keep the local-only plus endpoint-match rule, since redirecting a secret reference to a different URL would exfiltrate a value the repository never held.Ctrl+Altshortcut (listed under Keybinds, hint hidden on mobile widths). The preview's "Kept on this device" card says so when MCP is excluded from the backup entirely.Validation
Risks
mcp.jsoncafterreadBackupPayloadhas verified the manifest hashes, so the on-disk checkout is never modified; the manifest file list is filtered in step with the files, and the integration test pins the round trip.schemaVersion: 2. Builds before this PR restore a header as the same-named local value or nothing, so they would report a complete restore while dropping every carried header; they refuse version 2 as an invalid manifest instead. Backups without literal headers keep version 1 and restore on any build. The reader here accepts both versions.settingsBackupthrough a stripping schema and rewrites it on its next config write, so the newinclude*flags are lost and a later upgrade resolves them to the default (all on, projects off). The reset is visible in the checkboxes. Preserving unknown keys inSettingsBackupSchemawould protect later flags from this cycle for builds from that point on; tracked as a follow-up rather than added to this PR.Generated with
xum• Model:anthropic:claude-fable-5-1• Thinking:xhigh• Cost:$1186.44