Skip to content

fix(devin): apply Cognition blocklist rewrites to the system prompt - #6328

Merged
lidge-jun merged 1 commit into
devfrom
codex/carry-6281-devin-system-prompt-blocklist
Sep 30, 2026
Merged

lidge-jun merged 1 commit into
devfrom
codex/carry-6281-devin-system-prompt-blocklist

Conversation

@lidge-jun

Copy link
Copy Markdown
Owner

Summary

Carries #6281 by @lonefisher. The contributor gate returned the original to draft after a maintainer review commit, so the final state lands here with author credit.

Cognition's request blocklist refused every Codex turn because Codex injects the clause asking the user if they want to allow the action in \justification` parameter` into the system prompt. This adds a live-verified, meaning-preserving rewrite for that clause and applies the sanitizer to request field #2, the leading system prompt, in addition to tool descriptions. Conversation text, replayed thinking and tool-call arguments stay byte-exact.

The maintainer review commit strengthens the regression: the original test accepted a rewritten tool description as proof of system-prompt sanitization and still passed with the system rewrite disabled. It now asserts decoded field #2 independently, and that mutation fails.

Closes #6281

Co-authored-by: lonefisher 132996955+lonefisher@users.noreply.github.com

Verification

Checklist

  • Scope stays focused and avoids unrelated cleanup.
  • Docs or release notes were updated when needed.
  • Security-sensitive changes were reviewed for secrets, auth, and unsafe defaults.

Carries #6281 unchanged plus maintainer review fixes; the contributor gate re-drafted the original after the maintainer push.

Co-authored-by: lonefisher <132996955+lonefisher@users.noreply.github.com>
@lidge-jun
lidge-jun requested a review from Ingwannu as a code owner September 30, 2026 14:59
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-30T15:03:50.219701Z 5e21443 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actions

Copy link
Copy Markdown
Contributor

✅ Deterministic PR hygiene checks passed.

@github-actions github-actions Bot added the bug Something isn't working label Sep 30, 2026
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Repository: lidge-jun/opencodex/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 28d77893-60b0-4b4f-a82a-e4723699cff1

📥 Commits

Reviewing files that changed from the base of the PR and between b0d275d and 5e21443.

📒 Files selected for processing (3)
  • src/adapters/devin/cloud-direct/chat.ts
  • structure/providers-and-adapters.md
  • tests/providers/devin-adapter.test.ts
 _________________________________
< My GPU is bigger than your GPU. >
 ---------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@lidge-jun

Copy link
Copy Markdown
Owner Author

Maintainer integration into dev (MAINTAINERS.md, dev-only exception) by @lidge-jun. Carries #6281 with a Co-authored-by trailer; review and local integration evidence are in the description. Cross-platform CI for this head was cancelled per the maintainer's single-final-run instruction and runs once on the final dev tip. scripts/ci/assert-mergeable-review.sh --maintainer-integration OK at this head.

@lidge-jun
lidge-jun merged commit 662dfe1 into dev Sep 30, 2026
15 of 28 checks passed
@lidge-jun
lidge-jun deleted the codex/carry-6281-devin-system-prompt-blocklist branch September 30, 2026 15:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant