Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
49 commits
Select commit Hold shift + click to select a range
a1b85b2
Complete September infrastructure campaign
Calmingstorm Sep 23, 2026
eb94135
Pin campaign edge cases and retire Slack coverage baseline
Calmingstorm Sep 23, 2026
bf4764d
Address PR 367 review: retire plan runner and harden campaign paths
Calmingstorm Sep 23, 2026
9bb4f86
Exercise auth repair routes and remove unreachable token guard
Calmingstorm Sep 23, 2026
b33a66a
Cover unusable token repair stale-write and readback guards
Calmingstorm Sep 23, 2026
9653017
Pin malformed token row diagnostics and privacy
Calmingstorm Sep 23, 2026
21070a3
Add Codex account quota visibility and failover
Calmingstorm Sep 23, 2026
90d7c78
Address PR 367 round-two review and stop acknowledgement
Calmingstorm Sep 23, 2026
927a380
Keep webhook and quota service typing gates green
Calmingstorm Sep 23, 2026
35823f8
Regenerate API reference for webhook route shifts
Calmingstorm Sep 23, 2026
b0f2ed8
Cover round-two persistence and quota edge paths
Calmingstorm Sep 23, 2026
d1100c7
Cover missing unusable-token row response
Calmingstorm Sep 23, 2026
1e4f89d
Fix PR 367 usage and knowledge regressions
Calmingstorm Sep 24, 2026
3a57f5b
test: make webhook YAML IDs deterministic
Calmingstorm Sep 24, 2026
a32c5f4
fix: run UI repair check and clarify stop output
Calmingstorm Sep 24, 2026
4ae3c4d
fix: scope webhook saves and preserve YAML comments and credentials
Calmingstorm Sep 24, 2026
f20ea9f
Fix Codex pool exhaustion and refresh safety
Calmingstorm Sep 24, 2026
c532759
Keep Codex quota probe bound to live serving pool
Calmingstorm Sep 24, 2026
d707e66
Order Codex quota check test imports
Calmingstorm Sep 24, 2026
e48cd7d
Fix Codex quota UI status and API limit flag
Calmingstorm Sep 24, 2026
dd7e4c0
Derive Codex limit flag only from usage
Calmingstorm Sep 24, 2026
d164a10
fix: redact session identity and preserve computer audit reason throu…
Calmingstorm Sep 24, 2026
f88741f
test: link quota view model in LLM refresh harness
Calmingstorm Sep 24, 2026
fc7bf06
fix: expose quota failure state to account template
Calmingstorm Sep 24, 2026
d20d9dd
build: refresh WebUI assets for quota indicators
Calmingstorm Sep 24, 2026
5b33181
test: align DM stop outcome and regenerate API reference
Calmingstorm Sep 24, 2026
df1da30
test: distinguish unconfirmed DM stop from confirmed stop
Calmingstorm Sep 24, 2026
76eed9b
fix: preserve final webhook comments and validate create fields
Calmingstorm Sep 24, 2026
b5d9d33
Fix Codex quota snapshot and display gaps
Calmingstorm Sep 24, 2026
51f0e64
Fix Hyprland scope failure audit scanner
Calmingstorm Sep 24, 2026
20350ac
docs: synchronize API reference after webhook validation
Calmingstorm Sep 24, 2026
93fe4ca
build: refresh quota display assets
Calmingstorm Sep 24, 2026
24e4bb2
fix: resolve CI mypy findings
Calmingstorm Sep 24, 2026
484dad7
test: cover persistence and webhook validation branches
Calmingstorm Sep 24, 2026
6f65977
test: cover Codex quota failover edge cases
Calmingstorm Sep 24, 2026
e3c596a
test: cover invalid numeric config placeholder
Calmingstorm Sep 24, 2026
56208d2
test: reject missing webhook update target without writing
Calmingstorm Sep 24, 2026
fb32eaa
Fix round four campaign audit quota and webhook regressions
Calmingstorm Sep 24, 2026
3bb6511
Keep webhook typing and generated API reference in sync
Calmingstorm Sep 24, 2026
cded1e6
Preserve webhook comments with validated source-span edits
Calmingstorm Sep 24, 2026
1612004
Pin session-save failure delivery to stabilize coverage across runners
Calmingstorm Sep 24, 2026
6fd6630
Keep webhook id-less provenance across CRUD rebinding
Calmingstorm Sep 24, 2026
6b519fd
Refresh generated API reference after webhook fix
Calmingstorm Sep 24, 2026
e2c19a0
Mask outbound webhook Basic auth passwords in registration logs
Calmingstorm Sep 24, 2026
4e39d2b
Ignore unreported Codex quota windows in UI API and failover
Calmingstorm Sep 24, 2026
abcbb46
Fold permissions into scalable Host Access and resolve Discord identi…
Calmingstorm Sep 24, 2026
b0c9a26
Update quota-check and slash fixtures to use reported window durations
Calmingstorm Sep 24, 2026
f9a2820
feat(webui): edit host access and defaults in a modal
Calmingstorm Sep 24, 2026
d09f8be
test: use exact module-local clock for stream TTL boundary
Calmingstorm Sep 24, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
47 changes: 47 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,53 @@ Each GitHub release body is the matching section of this file.

## [Unreleased]

### Changed

- The Codex accounts table shows per-account quota windows and remaining usage;
an idle quota check refreshes accounts periodically, and limit-aware failover
prefers an account with remaining quota. When all accounts are limited, the
request still reaches Codex on the account whose limit resets first.
- Outbound webhooks may target private and homelab addresses, while cloud-metadata
destinations remain blocked. Redirects and DNS are validated at delivery, and
webhook signatures are never forwarded to another origin.
- MCP calls keep the first response for a request ID on all transports; later
responses are ignored with a payload-free warning. The handshake remains strict.
- The completion judge no longer imposes a 128-token output cap. Native Codex
requests are unchanged; compatible and Ollama reasoning judges can use their
normal output budget. Empty or ambiguous judge answers are logged as warnings.
- Knowledge ingestion splits unusually long words into bounded chunks. Existing
documents are unchanged until re-ingested.

### Fixed

- `/stop` removes its private deferred acknowledgement after Odin's public stop
message is delivered, avoiding a duplicate private notification.
- Outbound webhook edits made in the API or WebUI persist across restarts and
report their durable state. Configured per-target TLS verification and secret
scrubbing settings now apply at startup.
- Malformed permission overrides and API token records survive unrelated writes,
with operator-visible diagnostics; existing effective tiers and token access
are not changed by the migration.
- Trusted-proxy forwarding validates IP addresses, supports CIDR trust ranges,
and walks the forwarded chain from the nearest proxy to prevent rate-limit
bucket spoofing and inaccurate audit IPs.
- Concurrent knowledge ingests no longer bypass duplicate checks or add
spurious versions, and colliding chunk ID prefixes cannot overwrite chunks
belonging to another source, including on version restore.
- Usage coverage recovers from transient scan failures and detects oversized
unfinished trajectory rows instead of stalling later records silently.
- Computer-use audit and System Logs retain specific refusal reasons, including
`target_changed_observe_again`, instead of collapsing them to a generic
rejection; desktop input and receipts are unchanged.

### Removed

- Removed the unused standalone plan engine. The `python -m src.odin` plan
runner is gone; remove any scripts or automation that invoke it when upgrading.
- Removed the Slack integration, its configuration fields, API routes and WebUI
controls. Existing `slack:` configuration sections are ignored for upgrade
compatibility; generic Slack-token redaction remains active.

## [4.6.0] - 2026-09-23

### Added
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -111,7 +111,7 @@ The package also grants the `odin` service account passwordless sudo; restrict `

- Create, edit, enable, disable, import, export, and invoke Python skills at runtime.
- Configure skills with JSON schemas, dependencies, and operator-managed settings.
- Integrate external systems through webhooks, email, MCP servers, Slack, Grafana alerts, and custom skill code.
- Integrate external systems through webhooks, email, MCP servers, Grafana alerts, and custom skill code.

### Management interface

Expand Down
10 changes: 0 additions & 10 deletions config.yml
Original file line number Diff line number Diff line change
Expand Up @@ -322,16 +322,6 @@ web:

# --- Optional integrations (uncomment and configure to enable) ---

# # Slack webhook forwarding
# slack:
# enabled: false
# webhook_urls: {} # { "channel-name": "https://hooks.slack.com/..." }
# default_webhook_url: ''
# scrub_secrets: true
# rate_limit_seconds: 1
# forward_alerts: true
# forward_webhooks: false

# # Grafana alert auto-remediation
# grafana_alerts:
# auto_remediate: false
Expand Down
96 changes: 0 additions & 96 deletions coverage-baseline.json
Original file line number Diff line number Diff line change
Expand Up @@ -1193,12 +1193,6 @@
"percent": 100.0,
"statements": 12
},
"src/notifications/slack.py": {
"covered": 129,
"missing": 0,
"percent": 100.0,
"statements": 129
},
"src/observability/__init__.py": {
"covered": 3,
"missing": 0,
Expand Down Expand Up @@ -1235,96 +1229,6 @@
"percent": 87.5,
"statements": 16
},
"src/odin/__init__.py": {
"covered": 7,
"missing": 0,
"percent": 100.0,
"statements": 7
},
"src/odin/cli.py": {
"covered": 46,
"missing": 13,
"percent": 77.97,
"statements": 59
},
"src/odin/context.py": {
"covered": 122,
"missing": 7,
"percent": 94.57,
"statements": 129
},
"src/odin/executor.py": {
"covered": 42,
"missing": 1,
"percent": 97.67,
"statements": 43
},
"src/odin/plan_loader.py": {
"covered": 29,
"missing": 8,
"percent": 78.38,
"statements": 37
},
"src/odin/planner.py": {
"covered": 95,
"missing": 3,
"percent": 96.94,
"statements": 98
},
"src/odin/registry.py": {
"covered": 26,
"missing": 0,
"percent": 100.0,
"statements": 26
},
"src/odin/reporter.py": {
"covered": 25,
"missing": 0,
"percent": 100.0,
"statements": 25
},
"src/odin/tools/__init__.py": {
"covered": 0,
"missing": 0,
"percent": 100.0,
"statements": 0
},
"src/odin/tools/base.py": {
"covered": 8,
"missing": 1,
"percent": 88.89,
"statements": 9
},
"src/odin/tools/file_ops.py": {
"covered": 19,
"missing": 0,
"percent": 100.0,
"statements": 19
},
"src/odin/tools/http.py": {
"covered": 8,
"missing": 13,
"percent": 38.1,
"statements": 21
},
"src/odin/tools/process.py": {
"covered": 29,
"missing": 0,
"percent": 100.0,
"statements": 29
},
"src/odin/tools/shell.py": {
"covered": 19,
"missing": 1,
"percent": 95.0,
"statements": 20
},
"src/odin/types.py": {
"covered": 37,
"missing": 0,
"percent": 100.0,
"statements": 37
},
"src/odin_log/__init__.py": {
"covered": 2,
"missing": 0,
Expand Down
Loading
Loading