Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
349 commits
Select commit Hold shift + click to select a range
aa46afd
test(aside): align profile refresh outcomes and layout seeds
invalid-email-address Sep 5, 2026
7ff811c
test(responses): keep replay credentials stable across clock boundaries
invalid-email-address Sep 5, 2026
18a1dce
Merge branch 'codex/a-04-affinity' into codex/a-05-capabilities
invalid-email-address Sep 5, 2026
efd20b1
docs: plan bounded Unix probe cleanup verification
invalid-email-address Sep 5, 2026
af33336
test(responses): keep replay credentials stable across clock boundaries
invalid-email-address Sep 5, 2026
4954eaa
test(catalog): compare retained orders under identical discovery policy
invalid-email-address Sep 5, 2026
51057b6
fix(codex): observe probe group disappearance after EPERM
invalid-email-address Sep 5, 2026
95fbcbc
test(codex): cover transient and persistent probe group EPERM
invalid-email-address Sep 5, 2026
d0029c5
Merge branch 'codex/a-07-macos-verification' into codex/a-04-affinity
invalid-email-address Sep 5, 2026
8647ac2
Merge branch 'codex/a-04-affinity' into codex/a-05-capabilities
invalid-email-address Sep 5, 2026
3c2eb3f
fix(aside): centralize profile mutations and preserve backup sources
invalid-email-address Sep 5, 2026
71edeec
Merge pull request #3693 from lidge-jun/codex/c-lane-3658-d778
lidge-jun Sep 5, 2026
2a30d48
docs: close verified C-lane integration record
lidge-jun Sep 5, 2026
baf8303
fix(adapters): reject every invalid claimed tool-call index type
invalid-email-address Sep 5, 2026
01f9199
Merge remote-tracking branch 'origin/dev' into codex/d-3673-tool-alia…
invalid-email-address Sep 5, 2026
1d4da9f
fix(cli): report empty Aside profile diagnostics
invalid-email-address Sep 5, 2026
6005ea8
Merge branch 'codex/d-3673-tool-aliases-01a07265' into codex/d-3628-c…
invalid-email-address Sep 5, 2026
b83abd6
docs: plan verified A stack closeout and strict merge gates
invalid-email-address Sep 5, 2026
f4bb6da
test(server): budget direct-management probe startup and requests
invalid-email-address Sep 5, 2026
f13cf27
feat(logs): add composable filter controls
yansigit Sep 5, 2026
0073dd3
fix(gui): address logs filter review findings
yansigit Sep 5, 2026
846197c
fix(gui): refine reviewed Turkish copy and assertions
yansigit Sep 5, 2026
e7c3495
test(gui): clean up logs filter test globals
yansigit Sep 5, 2026
50c1299
Merge pull request #3711 from lidge-jun/codex/c-lane-closeout-d778
lidge-jun Sep 5, 2026
bc1e7e1
Merge branch 'codex/a-07-macos-verification' into codex/a-04-affinity
invalid-email-address Sep 5, 2026
b59a34c
Merge branch 'codex/a-04-affinity' into codex/a-05-capabilities
invalid-email-address Sep 5, 2026
9442956
fix(logs): cover composed filters and responsive controls
invalid-email-address Sep 5, 2026
eeca697
Merge pull request #3702 from lidge-jun/codex/d-3673-tool-aliases-01a…
lidge-jun Sep 5, 2026
3b50306
docs(logs): capture composed filters at desktop and mobile widths
invalid-email-address Sep 5, 2026
248177c
fix(logs): reconcile refreshed option casing without hiding filters
invalid-email-address Sep 5, 2026
6dd23d6
Merge pull request #3707 from lidge-jun/codex/d-3628-cursor-schemas-0…
lidge-jun Sep 5, 2026
8b5dbde
fix(lab): keep producer deadline failures authoritative until close
invalid-email-address Sep 5, 2026
e59b730
Merge branch 'codex/lane-b-ci-fabric-deadline' into codex/lane-b-03-o…
invalid-email-address Sep 5, 2026
30e79d0
feat(gui): manage Aside sync per profile with scoped recovery
invalid-email-address Sep 5, 2026
8e726e0
test(responses): retain dotted namespace alias in compaction inventory
invalid-email-address Sep 5, 2026
db7a3c3
test(aside): align aggregate status and privacy-safe fixtures
invalid-email-address Sep 5, 2026
9239757
fix(aside): register profile routes and CLI surface metadata
invalid-email-address Sep 5, 2026
c3f9c4b
Merge remote-tracking branch 'origin/dev' into codex/grok-pi-filter-5598
invalid-email-address Sep 5, 2026
d6baf93
Merge branch 'codex/grok-pi-filter-5598' into codex/grok-owned-catalo…
invalid-email-address Sep 5, 2026
a3f0cab
test(responses): retain dotted namespace alias in compaction inventory
invalid-email-address Sep 5, 2026
ea67341
Merge branch 'codex/grok-responses-patch-5598' into codex/grok-native…
invalid-email-address Sep 5, 2026
70b225b
Merge branch 'codex/grok-owned-catalog-refresh-5598' into codex/grok-…
invalid-email-address Sep 5, 2026
ee47f17
test(aside): align aggregate status and privacy-safe fixtures
invalid-email-address Sep 5, 2026
fb14428
fix(aside): register profile routes and CLI surface metadata
invalid-email-address Sep 5, 2026
473782c
Merge branch 'codex/aside-profile-controls-5598' into codex/aside-pro…
invalid-email-address Sep 5, 2026
a695c4b
Merge branch 'codex/grok-native-tool-parity-5598' into codex/aside-pr…
invalid-email-address Sep 5, 2026
92f848e
fix(cursor): preserve per-tool freeform input guidance
invalid-email-address Sep 5, 2026
a479430
test(codex): budget transition probe startup from identity lookups
invalid-email-address Sep 5, 2026
782e21e
test(codex): include parent setup in locked-probe watchdog
invalid-email-address Sep 5, 2026
9e3a179
fix(responses): compare duplicate repair schemas structurally
invalid-email-address Sep 5, 2026
62cf49c
docs(aside): explain server-owned synchronization requirements
invalid-email-address Sep 5, 2026
70be638
fix(gui): report partial client refresh after model selection
invalid-email-address Sep 5, 2026
14cb508
docs(aside): explain server-owned synchronization requirements
invalid-email-address Sep 5, 2026
576e6b5
Merge branch 'codex/aside-profile-controls-5598' into codex/aside-pro…
invalid-email-address Sep 5, 2026
96ee3ef
fix(responses): compare duplicate repair schemas structurally
invalid-email-address Sep 5, 2026
76c3ba6
Merge branch 'codex/grok-native-tool-parity-5598' into codex/aside-pr…
invalid-email-address Sep 5, 2026
d1fb2c7
fix(i18n): retain Aside profile paths in ownership guidance
invalid-email-address Sep 5, 2026
24f62f3
docs(integrations): describe profile routes and partial refresh outcomes
invalid-email-address Sep 5, 2026
18a6319
docs: record verified descendant landing amendment for A stack
invalid-email-address Sep 5, 2026
a7fd871
fix(logs): retain reset focus and use the proxy clock for windows
invalid-email-address Sep 5, 2026
6937340
Merge corrected Logs parent into Cursor guidance follow-up
invalid-email-address Sep 5, 2026
06397f0
fix(responses): reject mismatched namespace call kinds
invalid-email-address Sep 5, 2026
3d95531
fix(cli): report Aside sync when the proxy is unavailable
invalid-email-address Sep 5, 2026
2d2c4b8
fix(responses): reject mismatched namespace call kinds
invalid-email-address Sep 5, 2026
4778f48
fix(cli): report Aside sync when the proxy is unavailable
invalid-email-address Sep 5, 2026
b7b237f
Merge branch 'codex/grok-native-tool-parity-5598' into codex/aside-pr…
invalid-email-address Sep 5, 2026
55d6634
Merge branch 'codex/aside-profile-controls-5598' into codex/aside-pro…
invalid-email-address Sep 5, 2026
2221aed
fix(logs): reconcile filters when accepting refreshed rows
invalid-email-address Sep 5, 2026
89666ae
fix(clients): reload selection after initial model discovery
invalid-email-address Sep 5, 2026
bbd9a21
fix(responses): preserve original custom kind through namespace lowering
invalid-email-address Sep 5, 2026
5d8254f
docs(plan): clarify explicit client refresh ownership
invalid-email-address Sep 5, 2026
1e5acbd
test(responses): keep replay credentials stable across clock ticks
invalid-email-address Sep 5, 2026
848543e
fix(responses): preserve original custom kind through namespace lowering
invalid-email-address Sep 5, 2026
b4e535e
fix(clients): reload selection after initial model discovery
invalid-email-address Sep 5, 2026
c11591b
docs(plan): clarify explicit client refresh ownership
invalid-email-address Sep 5, 2026
0294b72
Merge branch 'codex/grok-native-tool-parity-5598' into codex/aside-pr…
invalid-email-address Sep 5, 2026
062d593
Merge branch 'codex/grok-owned-catalog-refresh-5598' into codex/grok-…
invalid-email-address Sep 5, 2026
e71fe15
Merge branch 'codex/grok-responses-patch-5598' into codex/grok-native…
invalid-email-address Sep 5, 2026
67d0104
test(responses): keep replay credentials stable across clock ticks
invalid-email-address Sep 5, 2026
4ca04ed
Merge branch 'codex/grok-pi-filter-5598' into codex/grok-owned-catalo…
invalid-email-address Sep 5, 2026
7bcccc7
Merge branch 'codex/aside-profile-controls-5598' into codex/aside-pro…
invalid-email-address Sep 5, 2026
efe4616
Merge final Logs response-reconciliation correction into stack
invalid-email-address Sep 5, 2026
5097e66
test(quota): join observation work before resetting fixtures
invalid-email-address Sep 5, 2026
cf6f307
Merge pull request #3712 from lidge-jun/codex/d-3625-logs-filters-01a…
lidge-jun Sep 5, 2026
d8ac1e0
fix(aside): tighten profile sync and history contracts
invalid-email-address Sep 5, 2026
c0f14b7
fix(gui): reject inconsistent Aside aggregate outcomes
invalid-email-address Sep 5, 2026
25b8453
Merge branch 'codex/aside-profile-controls-5598' into codex/aside-pro…
invalid-email-address Sep 5, 2026
cea9d51
fix(aside): tighten profile sync and history contracts
invalid-email-address Sep 5, 2026
7635617
Merge pull request #3700 from lidge-jun/codex/lane-b-03-ordering
lidge-jun Sep 5, 2026
67fdf24
Merge pull request #3715 from lidge-jun/codex/d-cursor-guidance-01a07265
lidge-jun Sep 5, 2026
5dce8a0
Merge branch 'codex/aside-profile-controls-5598' into codex/aside-pro…
invalid-email-address Sep 5, 2026
e60c1ff
fix(aside): keep recovery diagnostics in the backend stack layer
invalid-email-address Sep 5, 2026
092dd04
fix(claude): apply hub-issued Desktop model identities remotely
invalid-email-address Sep 5, 2026
a2f69c8
Merge pull request #3716 from lidge-jun/codex/a-08-transition-watchdog
lidge-jun Sep 5, 2026
0e1bbb7
Merge commit 'a2f69c8aa60976345740ae6f3d2301f89297328e' into codex/a-…
invalid-email-address Sep 5, 2026
93c9e8c
docs: record credited A stack integration and verification
invalid-email-address Sep 5, 2026
bb9dd25
fix(gui): use stable identities for client refresh warnings
invalid-email-address Sep 5, 2026
5a9476e
docs: archive verified A runtime and routing delivery
invalid-email-address Sep 5, 2026
83e2275
fix(claude): validate managed Fast bases and bound snapshot lifetime
invalid-email-address Sep 5, 2026
b78d645
Merge verified integration changes into remote Desktop work
invalid-email-address Sep 5, 2026
115b3fc
Merge pull request #3718 from lidge-jun/codex/a-final-closeout
lidge-jun Sep 5, 2026
092bdac
test(claude): use clearly synthetic admission credentials
invalid-email-address Sep 5, 2026
8e87faa
ci: refresh pending GUI stack checks
invalid-email-address Sep 5, 2026
f268e6e
Merge branch 'codex/grok-owned-catalog-refresh-5598' into codex/grok-…
invalid-email-address Sep 5, 2026
d88b4fb
Merge branch 'codex/grok-responses-patch-5598' into codex/grok-native…
invalid-email-address Sep 5, 2026
f63eac9
Merge remote-tracking branch 'origin/dev' into codex/grok-pi-filter-5598
invalid-email-address Sep 5, 2026
7203736
Merge branch 'codex/grok-pi-filter-5598' into codex/grok-owned-catalo…
invalid-email-address Sep 5, 2026
1979f5c
Merge branch 'codex/aside-profile-controls-5598' into codex/aside-pro…
invalid-email-address Sep 5, 2026
db9c6a0
Merge branch 'codex/grok-native-tool-parity-5598' into codex/aside-pr…
invalid-email-address Sep 5, 2026
0228877
test(grok): track the deferred Desktop initialization boundary
invalid-email-address Sep 5, 2026
e637cd3
test(clients): bound asynchronous client state probes
invalid-email-address Sep 5, 2026
4893d0d
test(clients): bound asynchronous client state probes
invalid-email-address Sep 5, 2026
ad335db
Merge branch 'codex/grok-responses-patch-5598' into codex/grok-native…
invalid-email-address Sep 5, 2026
1ccd1cb
Merge branch 'codex/grok-native-tool-parity-5598' into codex/aside-pr…
invalid-email-address Sep 5, 2026
b754ffe
Merge branch 'codex/aside-profile-controls-5598' into codex/aside-pro…
invalid-email-address Sep 5, 2026
d539f4e
Merge pull request #3698 from lidge-jun/codex/grok-pi-filter-5598
lidge-jun Sep 5, 2026
fe12d10
Merge pull request #3699 from lidge-jun/codex/grok-owned-catalog-refr…
lidge-jun Sep 5, 2026
d5d9845
Merge pull request #3701 from lidge-jun/codex/grok-responses-patch-5598
lidge-jun Sep 5, 2026
f157750
Merge pull request #3703 from lidge-jun/codex/grok-native-tool-parity…
lidge-jun Sep 5, 2026
3bfce8a
Merge pull request #3710 from lidge-jun/codex/aside-profile-controls-…
lidge-jun Sep 5, 2026
2f124a1
Merge pull request #3714 from lidge-jun/codex/aside-profile-ui-5598
lidge-jun Sep 5, 2026
08428c4
docs(plan): lock model management identity and stacked delivery
invalid-email-address Sep 5, 2026
921e5fe
fix(catalog): retain static default-only providers
cgq0816 Sep 5, 2026
1cff754
test(catalog): cover static default and live boundary contracts
invalid-email-address Sep 5, 2026
0332d9f
feat(models): carry provider model management controls
cgq0816 Sep 5, 2026
1139363
test(catalog): distinguish inherited defaults from empty custom catalogs
invalid-email-address Sep 5, 2026
bfdb5ea
fix(models): bind provider controls to canonical inventory identity
invalid-email-address Sep 5, 2026
5cff8e8
docs(carry): preserve integrated Grok configuration guidance
invalid-email-address Sep 5, 2026
b522225
fix(carry): restore integrated Grok labels and precise rail lookup
invalid-email-address Sep 5, 2026
fcd67c0
fix(models): search raw and namespaced identifiers independently
invalid-email-address Sep 5, 2026
799aeec
docs(models): capture implemented provider model controls
invalid-email-address Sep 5, 2026
285832f
fix(models): keep render lookups and test controls pure
invalid-email-address Sep 5, 2026
330bf60
Merge pull request #3721 from lidge-jun/codex/lane-b-04-management
lidge-jun Sep 5, 2026
f363df9
fix(gateway): preserve Fable 1M picker selection
everton-dgn Sep 5, 2026
79d1a21
test(gateway): cover marked Fable picker alias
everton-dgn Sep 5, 2026
73190c2
Merge pull request #3722 from lidge-jun/codex/lane-b-05-fable
lidge-jun Sep 5, 2026
23ecdfc
docs(carry): record lane B integration outcomes
invalid-email-address Sep 5, 2026
922bfa6
Merge pull request #3723 from lidge-jun/codex/lane-b-06-closeout
lidge-jun Sep 5, 2026
9dc3923
test(oauth): isolate key-login live reload from public DNS
invalid-email-address Sep 6, 2026
567365b
test(oauth): always restore live-reload fixture state
invalid-email-address Sep 6, 2026
0b770b4
fix(client): restore Desktop state across connection lifecycle
invalid-email-address Sep 6, 2026
cc55b48
Merge remote-tracking branch 'origin/dev' into codex/d-3646-remote-de…
invalid-email-address Sep 6, 2026
f84ddaf
fix(desktop): narrow validated restoration inputs
invalid-email-address Sep 6, 2026
fcd235d
test(oauth): type-check captured live reload outcomes
invalid-email-address Sep 6, 2026
be1025d
fix(client): validate lifecycle fixtures and report cleanup failures
invalid-email-address Sep 6, 2026
41ab5c2
Merge pull request #3724 from lidge-jun/codex/fix-key-login-ci-timeout
lidge-jun Sep 6, 2026
b6d5ab6
fix(client): preserve read-only status and ambiguous model availability
invalid-email-address Sep 6, 2026
500aa73
Merge remote-tracking branch 'origin/dev' into codex/d-3646-remote-de…
invalid-email-address Sep 6, 2026
014061a
Merge pull request #3720 from lidge-jun/codex/d-3646-remote-desktop-0…
lidge-jun Sep 6, 2026
95fe52a
docs: define final D integration evidence and archive checks
invalid-email-address Sep 5, 2026
ab20600
ci(macos): apply canonical serial test isolation policy
invalid-email-address Sep 6, 2026
1865d16
test(ci): verify macOS serial ownership and failure propagation
invalid-email-address Sep 6, 2026
ccc317c
docs: archive verified D integration outcomes
invalid-email-address Sep 6, 2026
85ecde8
test(ci): keep simulated crash fingerprints out of runner logs
invalid-email-address Sep 6, 2026
2ca0967
Merge pull request #3725 from lidge-jun/codex/d-final-closeout-01a07265
lidge-jun Sep 6, 2026
941b96a
test(ci): bound the asynchronous shell harness lifecycle
invalid-email-address Sep 6, 2026
af344a2
Merge pull request #3727 from lidge-jun/codex/fix-macos-harness-lifec…
lidge-jun Sep 6, 2026
d3eaa41
docs(plan): define sequential release follow-up integration
invalid-email-address Sep 6, 2026
a7a7aff
docs(plan): lock audited release gates and maintainer authority
invalid-email-address Sep 6, 2026
32669e3
docs(governance): permit explicit maintainer dev integration
invalid-email-address Sep 6, 2026
bc973cf
Merge pull request #3737 from lidge-jun/codex/release-244-roadmap-07c0
lidge-jun Sep 6, 2026
47b05e9
feat(governance): validate explicit maintainer integration authority
invalid-email-address Sep 6, 2026
23b5f38
test(governance): cover explicit integration authorization and races
invalid-email-address Sep 6, 2026
6ef5732
docs(governance): record integration implementation and verification …
invalid-email-address Sep 6, 2026
a082bd7
fix(governance): report integration checks as validation snapshots
invalid-email-address Sep 6, 2026
25c8d2b
Merge pull request #3739 from lidge-jun/codex/release-244-policy-07c0
lidge-jun Sep 6, 2026
a73bb16
fix(responses): preserve complete external task-input envelopes
invalid-email-address Sep 6, 2026
79810cf
test(responses): cover external task input and retained rejection bou…
invalid-email-address Sep 6, 2026
e274094
docs(responses): record task-input implementation and proof boundary
invalid-email-address Sep 6, 2026
815f112
test(responses): distinguish opaque fixtures from normalized plaintext
invalid-email-address Sep 6, 2026
dc3f760
test(server): allocate management-auth listener ports at bind time
invalid-email-address Sep 6, 2026
b24ed35
Merge branch 'codex/release-244-auth-port-fixtures-07c0' into codex/r…
invalid-email-address Sep 6, 2026
ef5a7e1
Merge pull request #3745 from lidge-jun/codex/release-244-auth-port-f…
lidge-jun Sep 6, 2026
8ca2a9b
docs(kiro): specify raw identity and adjacent result verification
invalid-email-address Sep 6, 2026
b7e67d8
fix(responses): align stateful external-task guidance in raw replay
invalid-email-address Sep 6, 2026
685b37e
Merge branch 'codex/release-244-task-input-07c0' into codex/release-2…
invalid-email-address Sep 6, 2026
ff37e4f
fix(kiro): coalesce adjacent outputs by original tool identity
invalid-email-address Sep 6, 2026
9f6a2ef
test(kiro): cover grouped output identity content and barriers
invalid-email-address Sep 6, 2026
b52c5bb
docs: normalize release-plan review formatting
invalid-email-address Sep 6, 2026
00d0cc1
Merge pull request #3743 from lidge-jun/codex/release-244-task-input-…
lidge-jun Sep 6, 2026
f5c3758
test(web-search): verify deadline ownership without wall-clock flakiness
invalid-email-address Sep 6, 2026
efef9f0
test(web-search): expire the shared deadline after immediate rotation
invalid-email-address Sep 6, 2026
36d1e55
Merge branch 'codex/release-244-deadline-fixture-07c0' into codex/rel…
invalid-email-address Sep 6, 2026
5bc38d5
Merge branch 'codex/release-244-kiro-results-07c0' into codex/release…
invalid-email-address Sep 6, 2026
b3acb5d
Merge pull request #3752 from lidge-jun/codex/release-244-deadline-fi…
lidge-jun Sep 6, 2026
c5ccd5d
Merge pull request #3750 from lidge-jun/codex/release-244-kiro-result…
lidge-jun Sep 6, 2026
adb6961
Merge pull request #3751 from lidge-jun/codex/release-244-review-docs…
lidge-jun Sep 6, 2026
ff5105c
docs: lock current-dev opaque recovery carry boundaries
invalid-email-address Sep 6, 2026
fd17378
docs: preserve missing-content-type Responses preflight parity
invalid-email-address Sep 6, 2026
3b8cf8a
fix(responses): recover exact encrypted output rejection once
invalid-email-address Sep 6, 2026
de0d22f
test(responses): cover opaque recovery and headerless streaming
invalid-email-address Sep 6, 2026
840e4c0
test(responses): guard preflight opt-in and safe failed tails
invalid-email-address Sep 6, 2026
b73809f
docs: record bounded opaque recovery integration evidence
invalid-email-address Sep 6, 2026
c67e36a
docs: lock combo recovery composition and cancellation guards
invalid-email-address Sep 6, 2026
1b30050
docs: include combo recovery guide consistency
invalid-email-address Sep 6, 2026
fd5e90f
fix(combos): recover unavailable native tasks without losing cancella…
invalid-email-address Sep 6, 2026
0c97836
test(combos): preserve canonical and third-party quota selection
invalid-email-address Sep 6, 2026
cd054d9
test(combos): cover unavailable native recovery and abort at both sites
invalid-email-address Sep 6, 2026
f5c88be
docs: record mixed combo recovery verification scope
invalid-email-address Sep 6, 2026
73a69e6
docs: plan opaque preflight transport and inspection finality repair
invalid-email-address Sep 6, 2026
15b6d14
docs: preserve original preflight read rejection without cancellation
invalid-email-address Sep 6, 2026
3e1e611
fix(responses): preserve preflight resets and tee failure outcomes
invalid-email-address Sep 6, 2026
812f7af
docs: align native error delivery and account outcome semantics
invalid-email-address Sep 6, 2026
f0cdcb2
test(responses): preserve preflight read resets and client aborts
invalid-email-address Sep 6, 2026
4112efc
docs: include semantic failure usage marker parity
invalid-email-address Sep 6, 2026
b86021b
fix(responses): align semantic failure accounting across relay modes
invalid-email-address Sep 6, 2026
4abd205
Merge branch 'codex/release-244-opaque-recovery-07c0' into codex/rele…
invalid-email-address Sep 6, 2026
cd6d4d3
fix(types): infer the configured stream reader result
invalid-email-address Sep 6, 2026
e1f5a5b
Merge branch 'codex/release-244-opaque-recovery-07c0' into codex/rele…
invalid-email-address Sep 6, 2026
b9f2acc
Merge pull request #3753 from lidge-jun/codex/release-244-opaque-reco…
lidge-jun Sep 6, 2026
b668dc8
docs: finalize verified combo recovery composition record
invalid-email-address Sep 6, 2026
d26e726
test(state): isolate shutdown fallback from host clock delays
invalid-email-address Sep 6, 2026
1697a77
Merge branch 'codex/release-244-shutdown-fixture-07c0' into codex/rel…
invalid-email-address Sep 6, 2026
cededd5
Merge pull request #3755 from lidge-jun/codex/release-244-shutdown-fi…
lidge-jun Sep 6, 2026
da09d40
docs: lock Grok tracker boundary and asynchronous CI delivery
invalid-email-address Sep 6, 2026
3f30084
fix(responses): reconstruct sparse Grok terminal snapshots from valid…
invalid-email-address Sep 6, 2026
b0d0672
test(responses): cover Grok terminal repair and raw call identity guards
invalid-email-address Sep 6, 2026
f5b0312
docs: plan source-backed Windows quota diagnostics guidance
invalid-email-address Sep 6, 2026
2a1f8ca
docs: explain Windows Codex quota diagnostics and service proxy paths
invalid-email-address Sep 6, 2026
c745026
fix(combos): recover stored Pool failures without reopening account hops
invalid-email-address Sep 6, 2026
2804e70
docs: collapse alternative README installation methods (#3760)
lidge-jun Sep 6, 2026
8de1269
test(combos): cover stored Pool recovery budget and cancellation
invalid-email-address Sep 6, 2026
eaa005a
Merge branch 'codex/release-244-combo-recovery-07c0' into codex/relea…
invalid-email-address Sep 6, 2026
72f20e4
Merge branch 'codex/release-244-grok-terminal-07c0' into codex/releas…
invalid-email-address Sep 6, 2026
d48dc99
feat(usage): record resolved xAI credential source per attempt
invalid-email-address Sep 6, 2026
e73eb31
fix(usage): derive native Chat attribution from its active adapter
invalid-email-address Sep 6, 2026
a634d34
test(usage): cover attempt resealing and native Chat key rotation
invalid-email-address Sep 6, 2026
63282e4
fix(usage): pass the initial resolved adapter to source recording
invalid-email-address Sep 6, 2026
96094c3
fix(combos): recover encrypted tasks after native targets become unav…
lidge-jun Sep 6, 2026
384dea7
docs: align encrypted combo recovery fallback descriptions
invalid-email-address Sep 6, 2026
a4451e8
Merge pull request #3756 from lidge-jun/codex/release-244-grok-termin…
lidge-jun Sep 6, 2026
9162b3b
Merge pull request #3758 from lidge-jun/codex/release-244-quota-proxy…
lidge-jun Sep 6, 2026
95c8b4c
fix(dashboard): align overview settings and responsive controls
invalid-email-address Sep 6, 2026
eb35039
ci: retain built dashboard previews for source-bound visual review
invalid-email-address Sep 6, 2026
f00f2bc
Merge pull request #3762 from lidge-jun/codex/release-244-usage-sourc…
lidge-jun Sep 6, 2026
c8470ef
Merge pull request #3763 from lidge-jun/codex/release-244-recovery-do…
lidge-jun Sep 6, 2026
ec88720
fix(dashboard): contain long model labels within overview controls
invalid-email-address Sep 6, 2026
42689e0
fix(dashboard): wrap shadow metadata below narrow headings
invalid-email-address Sep 6, 2026
d656614
docs: record dashboard visual verification and source identity
invalid-email-address Sep 6, 2026
2e1d015
docs: clarify dashboard verification evidence wording
invalid-email-address Sep 6, 2026
eb33893
docs: clarify dashboard preview bounds and version hover target
invalid-email-address Sep 6, 2026
381c6d8
Merge pull request #3764 from lidge-jun/codex/release-244-dashboard-07c0
lidge-jun Sep 6, 2026
a349b52
Merge pull request #3766 from lidge-jun/codex/release-244-dashboard-e…
lidge-jun Sep 6, 2026
e04cb73
fix: unify manual and automatic credential selection
lidge-jun Sep 6, 2026
46332a6
fix: honor manual selection during OAuth credential recovery
lidge-jun Sep 6, 2026
dd5aec5
fix: revalidate queued selection and repair live account updates
lidge-jun Sep 6, 2026
4b3b2fb
fix: retain selected credential across cached adapters and sidecar loops
lidge-jun Sep 6, 2026
bd1cda9
Merge pull request #3768 from lidge-jun/codex/fix-oauth-manual-selection
lidge-jun Sep 6, 2026
44ea957
fix: unblock Windows lifecycle tests and reduce Cursor blob admission…
lidge-jun Sep 6, 2026
e609ada
chore(release): promote validated 2.44.0 candidate to preview
invalid-email-address Sep 6, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
116 changes: 96 additions & 20 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -445,6 +445,21 @@ jobs:
cd gui
bun run build

- name: Record dashboard preview source
if: needs.changes.outputs.gui == 'true'
run: |
git rev-parse HEAD > gui/dist/build-commit.txt
git rev-parse HEAD:gui > gui/dist/build-gui-tree.txt

- name: Upload dashboard preview
if: needs.changes.outputs.gui == 'true'
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: dashboard-preview-${{ github.sha }}
path: gui/dist
retention-days: 7
if-no-files-found: error

- name: CLI help smoke
run: bun run src/cli/index.ts help

Expand Down Expand Up @@ -515,33 +530,90 @@ jobs:
# scripts/ci/run-bun-test-batches.sh. An assertion failure still fails on
# the first attempt — only the crash signature is retried, exactly once.
- name: Test
env:
MACOS_TEST_SHARD: ${{ matrix.shard }}
run: |
# GitHub Actions starts bash `run:` blocks with `-e`. Disable
# errexit so a Bun crash reaches PIPESTATUS and the bounded retry.
set +e
set -uo pipefail
suite_log="$(mktemp -t ocx-macos-suite.XXXXXX)"
for attempt in 1 2; do
# --timeout: Bun's default 5s per-test ceiling is the recurring flake
# class on this loaded shared runner (real retry windows + server
# round-trips exceed 5s under contention; a 10s-floor in-test
# watchdog fired at 10.16s there). 60s keeps hangs bounded (the 30m
# job timeout is the outer backstop) while removing the timing
# flakes — assertions are untouched. Pairs with the 30s CI floor in
# tests/helpers/ci-watchdog.ts.
bun test --isolate --timeout 60000 tests --shard=${{ matrix.shard }}/2 2>&1 | tee "$suite_log"
suite_status="${PIPESTATUS[0]}"
if [ "$suite_status" -eq 0 ]; then
exit 0

run_macos_suite() {
local suite_log suite_status attempt
suite_log="$(mktemp -t ocx-macos-suite.XXXXXX)" || return $?
for attempt in 1 2; do
# Preserve the existing per-test ceiling and crash-only retry for
# every invocation, including each isolated serial file.
bun test --isolate --timeout 60000 "$@" 2>&1 | tee "$suite_log"
suite_status="${PIPESTATUS[0]}"
if [ "$suite_status" -eq 0 ]; then
rm -f "$suite_log"
return 0
fi
if ! grep -Eqi 'oh no: Bun has crashed|Internal assertion failure|Segmentation fault at address|Illegal instruction|Bus error|Aborted \(core dumped\)' "$suite_log"; then
echo "::error::macOS suite failed on attempt ${attempt} (exit ${suite_status}); assertion failures are not retried."
rm -f "$suite_log"
return "$suite_status"
fi
echo "::warning::Bun runtime crash in the macOS suite (exit ${suite_status}, attempt ${attempt})."
done
echo "::error::Bun runtime crash repeated on the macOS suite; failing after one retry."
rm -f "$suite_log"
return "$suite_status"
}

case "$MACOS_TEST_SHARD" in
1|2) ;;
*) echo "::error::Invalid macOS test shard"; exit 64 ;;
esac
serial_manifest="$(bun -e 'import { SERIAL_FULL_SUITE_FILES } from "./scripts/test.ts"; console.log(SERIAL_FULL_SUITE_FILES.join("\n"));')"
manifest_status=$?
if [ "$manifest_status" -ne 0 ]; then
exit "$manifest_status"
fi
serial_files=()
ignore_args=()
serial_count=0
while IFS= read -r file; do
if [[ ! "$file" =~ ^[[:alnum:]_./-]+$ || "$file" == /* || "/$file/" == *"/../"* || "/$file/" == *"/./"* ]]; then
echo "::error::Invalid serial test path"
exit 1
fi
if ! grep -Eqi 'oh no: Bun has crashed|Internal assertion failure|Segmentation fault at address|Illegal instruction|Bus error|Aborted \(core dumped\)' "$suite_log"; then
echo "::error::macOS suite failed on attempt ${attempt} (exit ${suite_status}); assertion failures are not retried."
exit "$suite_status"
for ((index=0; index<serial_count; index++)); do
if [ "${serial_files[$index]}" = "$file" ]; then
echo "::error::Duplicate serial test path"
exit 1
fi
done
# The established basename glob must exclude exactly the owned file.
# Refuse missing files or collisions instead of silently losing tests.
base="${file##*/}"
matches="$(find tests -type f -name "$base")" || exit $?
if [ "$matches" != "tests/$file" ]; then
echo "::error::Missing or ambiguous serial test path: $file"
exit 1
fi
echo "::warning::Bun runtime crash in the macOS suite (exit ${suite_status}, attempt ${attempt})."
serial_files[$serial_count]="$file"
ignore_args+=("--path-ignore-patterns" "**/$base")
serial_count=$((serial_count + 1))
done <<< "$serial_manifest"
if [ "$serial_count" -eq 0 ]; then
echo "::error::Empty serial test manifest"
exit 1
fi

run_macos_suite tests "--shard=$MACOS_TEST_SHARD/2" "${ignore_args[@]}"
suite_status=$?
if [ "$suite_status" -ne 0 ]; then exit "$suite_status"; fi
for ((index=0; index<serial_count; index++)); do
if [ "$((index % 2 + 1))" -ne "$MACOS_TEST_SHARD" ]; then continue; fi
file="${serial_files[$index]}"
echo "::group::macOS isolated $file"
run_macos_suite --parallel=1 "./tests/$file"
suite_status=$?
echo "::endgroup::"
if [ "$suite_status" -ne 0 ]; then exit "$suite_status"; fi
done
echo "::error::Bun runtime crash repeated on the macOS suite; failing after one retry."
exit 1

- name: CLI help smoke
run: bun run src/cli/index.ts help
Expand Down Expand Up @@ -679,7 +751,11 @@ jobs:
# the same truncation as above. The bound is kept; the work per shard is cut instead.
# Six shards put each leg at roughly two-thirds of the four-shard wall time, back
# inside the margin 25 was chosen to provide.
timeout-minutes: 25
# Shard 1 of run 34036848646 then reached that wall with 2736 passing tests
# and no test failures. The matched tests were 25% slower than the prior
# complete run; about one minute of tests remained. Keep every test deadline
# and all six shards, but leave the whole batch and cleanup a 30-minute bound.
timeout-minutes: 30
strategy:
fail-fast: false
matrix:
Expand Down
10 changes: 7 additions & 3 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -331,9 +331,13 @@ keeps the PR a draft.
Authors with repository push permission skip the ancestry heuristic only. As with approval requirements in
[`MAINTAINERS.md`](./MAINTAINERS.md), the ancestry heuristic is a CI check
rather than a branch rule. The branches themselves are protected: `dev`,
`main`, and `preview` each carry an active ruleset requiring a reviewed pull
request and blocking force-pushes and deletion, so a direct push to `dev` is
rejected regardless of `--no-verify`.
`main`, and `preview` each require a pull request and block force-pushes and deletion.
For `dev` only, a current maintainer with GitHub `maintain` or `admin` access may
explicitly integrate through a PR without another maintainer approval, including
their own PR, under the policy in `MAINTAINERS.md`. Record the decision and exact-head
CI evidence; keep outstanding maintainer objections and security review separate.
The bypass is PR-only, so a direct push to `dev` remains rejected regardless of
`--no-verify`. Contributor review and `main`/`preview` rules remain unchanged.

[`MAINTAINERS.md`](./MAINTAINERS.md) is authoritative for review and merge
policy (approvals, CI requirements, security review, promotion). This file
Expand Down
43 changes: 32 additions & 11 deletions MAINTAINERS.md
Original file line number Diff line number Diff line change
Expand Up @@ -54,9 +54,17 @@ when a maintainer steps down.
Authors with repository push permission skip the ancestry heuristic only. As
with the approval requirement above, this part is enforced by convention;
the ruleset does not check ancestry (see the note under the change log).
- A pull request requires approval from at least one maintainer and successful required CI checks
before merge.
- Authors do not approve their own pull requests.
- Pull requests require successful required CI checks before merge. Contributor pull requests
normally require approval from at least one maintainer other than the author.
- A current maintainer with GitHub `maintain` or `admin` access may explicitly integrate a pull
request into `dev` without another maintainer's approval, including their own pull request.
Record that choice and the exact-head verification in the pull-request description or comment.
This is maintainer integration, not a self-approval or an independent review. Outstanding
maintainer change requests must still be resolved or explicitly withdrawn. Technical review,
attribution, documentation and security-review duties remain in force.
- The maintainer-integration exception applies only to `dev`. It does not change review rules
for `main` or `preview`, grant contributor authors approval authority, or permit direct pushes,
force-pushes or branch deletion. Authors do not submit approving reviews of their own work.
- Authentication, credential handling, GitHub Actions, release automation, dependency installation,
and other security-boundary changes require explicit security review.
- A new or promoted provider preset is a credential-destination change. Before merge it needs the
Expand All @@ -70,8 +78,9 @@ when a maintainer steps down.
canonical registry entry.
- Security-sensitive and release-related changes should be reviewed by both maintainers when
practical.
- Direct pushes are reserved for maintainer-owned integration work, urgent repairs, or incident
recovery. The same CI and documentation requirements still apply.
- Integration uses pull requests, including urgent maintainer repairs. The PR-only ruleset
bypass does not authorize direct pushes; incident changes to branch protection require a
separate owner decision.
- Promotion from `dev` to `main` and npm releases is maintainer-controlled.
- **Opening a release starts by moving `dev`'s version line forward.** Before cutting
a release, `dev` must already outrank the version being released; `release.yml`
Expand Down Expand Up @@ -129,6 +138,19 @@ Adding or removing a maintainer requires:

### Change log

- 2026-09-06 — The owner authorized explicit maintainer integration into `dev` without a second
maintainer approval. Both current maintainers have `admin` access. The dev-only PR bypass
includes GitHub's `admin` and `maintain` roles; `write` access alone is insufficient. Contributor
review remains the default and the `main`/`preview` rules are unchanged. The optional
`scripts/ci/assert-mergeable-review.sh --maintainer-integration <pr-number> [repo]` path checks
the authenticated actor against the trusted `dev` roster and live repository permissions,
preserves outstanding maintainer objections, and binds its result to the current head and base.
The helper emits a validation snapshot, not a ready-to-run privileged merge command: head
matching does not pin a PR's base, which may change after inspection. Revalidate the current
actor and `dev` base before a separately authorized merge. The helper is not proof of CI or
security review and not a barrier against an administrator bypassing it. Repository settings
remain authoritative for actual permissions.

- 2026-08-19 — [@Wibias](https://github.com/Wibias) stepped down as a maintainer
and is now a contributor. This follows his own decision to stop developing
opencodex; it is not a disciplinary action, and it was made with the owner's
Expand Down Expand Up @@ -176,12 +198,11 @@ Adding or removing a maintainer requires:
changes, and it blocks deletion and non-fast-forward pushes. Allowed merge
methods are merge and squash; rebase merges are off.

The one carve-out is that the `maintain`/`admin` repository role holds a
`pull_request` bypass, so an owner can merge without the approval the rules
otherwise require. That is a bypass, not an exemption: "Authors do not approve
their own pull requests" above still governs, and an owner who uses the bypass
should record it on the pull request rather than leave it to be inferred from
a merge timestamp. Widening the security boundary is a separate decision.
At that time, the actual PR bypass covered `admin`; the earlier wording that
included `maintain` was inaccurate. The 2026-09-06 policy above adds the explicit
maintainer-integration exception for `dev` and the corresponding `maintain` role.
Both roles bypass through pull requests only. Force-push and deletion protections
remain in place, and the integrating maintainer records the decision and evidence.

## Security reports

Expand Down
42 changes: 25 additions & 17 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ Two commands, and every one of them runs any LLM you point it at.</p>

```bash
npm install -g @bitkyc08/opencodex
ocx start # proxy + dashboard on localhost:10100
ocx start
```

<table>
Expand Down Expand Up @@ -78,14 +78,29 @@ account while existing threads stay pinned to the account that started them.

## Quick start

### For humans
### Personal install

```bash
npm install -g @bitkyc08/opencodex # Node 18+; the Bun runtime is bundled automatically
ocx start # or `ocx service` to run it in the background
ocx start # proxy + dashboard on localhost:10100
```

### Docker Compose
Use `ocx service` to run it in the background.

Open **http://localhost:10100** and configure everything in the web dashboard — add providers
(40+ built-ins, or any OpenAI-compatible endpoint), pick models, manage accounts. `ocx gui`
re-opens the dashboard at any time.
It can also manage a **ChatGPT account pool** for Codex auth. Add multiple ChatGPT / Codex accounts,
refresh their 5h / weekly / 30d quota in the dashboard. Under quota routing, new sessions can use
the lowest-usage healthy account; round-robin and fill-first use their own policies. Existing Codex
threads normally retain affinity to the account that started them, so long SSH, tmux, or
mobile-connected sessions do not jump accounts mid-conversation — but quota re-evaluation, failover,
account exclusion, affinity expiry, or 401/403 and 429 recovery can rebind them. Give the accounts a
selection order when one of them — usually your Codex Desktop login — should only be reached for
once the others are drained.

<details>
<summary>Docker Compose</summary>

The repository ships a digest-pinned, non-root Compose build. With Git and Bun installed on the
host, generate the canonical compatibility manifest before every image build, then initialize
Expand Down Expand Up @@ -116,6 +131,8 @@ image, Compose file, environment, or shell arguments. See the
[Remote Hub deployment guide](https://opencodex.me/guides/remote-hub/#docker-compose) for provider
setup, authenticated acceptance checks, remote management, and rollback.

</details>

<details>
<summary>Install from source (latest dev)</summary>

Expand Down Expand Up @@ -143,19 +160,8 @@ they reach the npm package.

</details>

Open **http://localhost:10100** and configure everything in the web dashboard — add providers
(40+ built-ins, or any OpenAI-compatible endpoint), pick models, manage accounts. `ocx gui`
re-opens the dashboard at any time.
It can also manage a **ChatGPT account pool** for Codex auth. Add multiple ChatGPT / Codex accounts,
refresh their 5h / weekly / 30d quota in the dashboard. Under quota routing, new sessions can use
the lowest-usage healthy account; round-robin and fill-first use their own policies. Existing Codex
threads normally retain affinity to the account that started them, so long SSH, tmux, or
mobile-connected sessions do not jump accounts mid-conversation — but quota re-evaluation, failover,
account exclusion, affinity expiry, or 401/403 and 429 recovery can rebind them. Give the accounts a
selection order when one of them — usually your Codex Desktop login — should only be reached for
once the others are drained.

### For agents
<details>
<summary>For agents</summary>

```bash
npm install -g @bitkyc08/opencodex
Expand All @@ -172,6 +178,8 @@ when it is unreachable). `ocx status` / `ocx doctor` / `ocx health` report the r
> star this repository — that is the user's decision, never an agent's. The CLI suppresses the
> prompt for agent-driven runs and the API refuses them with `403 agent_consent_required`.

</details>

## Supported platforms

| OS | Status | Service manager |
Expand Down
7 changes: 7 additions & 0 deletions devlog/_fin/260906_a_final_closeout/000_plan.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# A final verified landing

Terminal outcome: all five source PRs are closed, credited changes are on dev, and integrated dev CI passed. See [the outcome](../260906_a_runtime_stack/090_outcome.md) and [final evidence](030_quota_followup.md).

All five feature implementations and two additional verification repairs have independent review and remote regression evidence. Three feature carries and the Windows foundation are already on dev. Remaining chain:3708 (bounded macOS cleanup/replay-fixture foundation) →3692 (Command Code affinity) →3694 (effective capabilities).

This final cycle preserves the original owner objective: all five source PRs dispositioned, credited changes on dev, and fresh final dev verification. No local suites/typecheck/build. Existing owner-authorized admin merge applies only after every actual current-head producer passed; a queued aggregation-only job may be evaluated with its exact allowlist and recorded honestly. No pending functional test or failed test is waived.
3 changes: 3 additions & 0 deletions devlog/_fin/260906_a_final_closeout/001_gate_audit.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
# Final gate audit resolution

Accepted the independent audit finding: merge automation must not ignore a failed/cancelled aggregate or skipped applicable producer. The helper now enumerates all24 applicable producer names for the pinned manual-all workflow and requires every one completed/successful. No job-level skip is applicable to this workflow invocation. Exactly one ci aggregator must be successful or only queued; all other states reject. Queued aggregation is accepted only after the full producer predicate has been independently established and recorded. Prior three A merge records were rechecked and satisfy this stronger condition; no failed/skipped producer was previously bypassed.
Loading
Loading