Repository navigation
fix: make the safety hooks and MCP servers work in Codex - #5
Merged
Merged
Conversation
The safety hooks never ran in Codex, for four separate reasons:
- Codex looks for plugin hooks in hooks/hooks.json, and the file sat at
the plugin root, so it was never loaded. It now lives in
plugins/cockroachdb/hooks/hooks.json.
- Codex replaces every character outside [A-Za-z0-9_] in MCP tool
names, so the Toolbox SQL tool is
mcp__cockroachdb_toolbox__cockroachdb_execute_sql. The hyphenated
matcher never matched it.
- Codex runs hook commands in the session's working directory, so
python3 ./scripts/... couldn't find the script, and Python's exit 2
would have blocked every matched call. Commands now reference
"${PLUGIN_ROOT}/scripts/...", which Codex substitutes, and end with
"; exit 0" so a missing or crashing script fails open.
- Codex rejects unknown top-level keys in hook output and then ignores
the whole output, so the scripts' Copilot CLI fields made a deny a
no-op. The scripts take a --codex flag that emits only the keys Codex
accepts; without it their output is unchanged.
check-sql-files.py also reads the edited paths out of apply_patch input,
which is how Codex edits files, so the lint now runs after Codex edits.
The localhost cockroachdb-toolbox-http server is gone: it failed unless
Toolbox was already serving HTTP on port 5000. The README no longer
says the cluster ID is required, documents turning off a backend
through config.toml, replaces the nonexistent codex plugin trust
command with /hooks, fixes the secure-cluster troubleshooting (Codex
never forwarded the SSL variables it described), and adds Toolbox
over HTTP and the first-party CockroachDB MCP Server as alternative
backends. The execute-sql description no longer promises DDL and DML,
since Toolbox runs read-only.
Related to cockroachdb/claude-plugin#27
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The safety hooks never ran in Codex. There were four separate causes, each fixed here:
hooks/hooks.json, and the file sat at the plugin root. It now lives inplugins/cockroachdb/hooks/hooks.json.[A-Za-z0-9_]in MCP tool names, so the Toolbox SQL tool ismcp__cockroachdb_toolbox__cockroachdb_execute_sql. The hyphenated matcher never matched it.python3 ./scripts/...couldn't find the script. Python's exit 2 would also have blocked every matched call once the first two causes were fixed. Commands now reference"${PLUGIN_ROOT}/scripts/...", which Codex substitutes, and end with; exit 0so a missing or crashing script fails open.--codexflag that emits only the keys Codex accepts. Without the flag, their output is unchanged, so the copilot plugin can keep sharing them.The lint hook now sees Codex file edits.
check-sql-files.pyreads the edited paths fromapply_patchinput, which is how Codex edits files.MCP and docs.
cockroachdb-toolbox-httpserver is gone; it failed unless Toolbox was already serving HTTP on port 5000.COCKROACHDB_CLUSTER_IDis required, and documents turning off a backend throughconfig.toml.codex plugin trustcommand is replaced with/hooks.Testing
python3 -m unittest -v tests/test_plugin_package.py: all pass. New cases check:.mcp.jsonandtools.yaml;${PLUGIN_ROOT}commands and; exit 0;--codexoutput uses only keys Codex accepts;apply_patchpath parsing;CODEX_HOMEand run against a local CockroachDB v25.4 cluster with Toolbox 1.12.0 (codex exec --dangerously-bypass-hook-trust):TRUNCATEthrough the Toolbox tool: "Tool call blocked by PreToolUse hook: TRUNCATE is blocked by CockroachDB plugin safety hook... Tool: mcp__cockroachdb_toolbox__cockroachdb_execute_sql"..sqlfile that usesSERIAL: Codex wrote it withapply_patch, and the lint reached the model ("CockroachDB lint: SERIAL/BIGSERIAL detected...").Not tested: the interactive
/hookstrust flow (the live runs used the bypass flag) and Windows.Related to cockroachdb/claude-plugin#27.