Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
26 commits
Select commit Hold shift + click to select a range
acb064a
test(update): use native host pnpm shim fixtures
lidge-jun Sep 12, 2026
293c37d
fix(devin-cli): resolve credential paths for the selected platform
lidge-jun Sep 12, 2026
8fe9a1c
Merge pull request #4379 from lidge-jun/codex/260912-combo-pnpm-ci-re…
lidge-jun Sep 12, 2026
c311f9b
Merge pull request #4400 from lidge-jun/codex/260912-60plus-models-de…
lidge-jun Sep 12, 2026
a33b51e
feat(codex): relay experimental context history under a least-privile…
lidge-jun Sep 12, 2026
f2e9891
fix(codex): require proof of owner identity and revalidate admission …
lidge-jun Sep 12, 2026
5f5c08a
test(codex): model real credential rotation in relay ownership regres…
lidge-jun Sep 12, 2026
5a5e0bf
test(codex): cover cancellation during relay credential selection
lidge-jun Sep 12, 2026
cb5ddf7
fix(codex): let a loopback context caller name itself with its openco…
lidge-jun Sep 12, 2026
2f2d1dc
fix(codex): resolve the relay principal the same way when recording o…
lidge-jun Sep 12, 2026
47f3ed4
docs: fix a wrapped-line indent in the context relay paragraph
lidge-jun Sep 12, 2026
69b5485
fix(codex): gate context relay and ownership recording on the experim…
lidge-jun Sep 12, 2026
bfc91b4
fix(codex): keep the activation gate fail-closed and inert at dispatch
lidge-jun Sep 12, 2026
bb22526
test(context): activate isolated relay admission fixtures
lidge-jun Sep 12, 2026
b1be256
fix(history): repair resumed relay contracts and hosted regression fi…
lidge-jun Sep 12, 2026
157f7a7
test(chat): cover conversation identity at native outbound boundary
lidge-jun Sep 12, 2026
ad00a4d
docs: reconcile cache CI failures with shared integration repair
lidge-jun Sep 12, 2026
65da842
docs: bind Hermes final verification to reserved integration base
lidge-jun Sep 12, 2026
24e637f
docs: separate operational identifiers in cache handoff
lidge-jun Sep 12, 2026
db7062c
Merge pull request #4365 from lidge-jun/codex/260912-60plus-cache-hermes
lidge-jun Sep 12, 2026
94b609a
test(cli): stop judging a stale record on a port another test can take
lidge-jun Sep 12, 2026
2526715
Merge pull request #4360 from lidge-jun/codex/260912-60plus-relay
lidge-jun Sep 12, 2026
b266e57
chore(release): open dev at 2.53.0 before releasing 2.52.0
github-actions[bot] Sep 12, 2026
f0d4adb
Merge pull request #4405 from lidge-jun/codex/dev-version-2.53.0
lidge-jun Sep 12, 2026
7bfb2ad
Merge pull request #4403 from lidge-jun/codex/260912-status-port-flake
lidge-jun Sep 12, 2026
3608119
release: promote verified 2.52.0-preview.20260912 product tree to pre…
lidge-jun Sep 12, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions devlog/_plan/260912_cache_lane/040_hermes.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,3 +7,5 @@ MODIFY tests/responses/chat-completions-endpoint.test.ts or a registered adjacen
MODIFY canonical inbound contract docs to distinguish stable client conversation identity, request-scoped lane and prompt prefix. Durable scratch evidence names public comment URLs, actual test command coverage and limitations. Real Hermes same-conversation/fresh-session identifier and outbound capture from its running client are unavailable unless provided by existing public evidence; synthetic regression proves transport contract only. Do not claim actual client identity was observed, cache hits improved or #3433 solved.

C hosted final tip executes the contract; local suite NOT RUN. D records exactly what is proven and remaining controlled live-client comparison.

Execution refinement: NEW tests/responses/chat-conversation-affinity.test.ts and register it in both layout maps. Invoke actual Chat handler with synthetic caller JWT against canonical ChatGPT Responses config in isolated homes. Mock only outbound fetch, record Headers/body. Two header shapes (underscore session_id, hyphen session-id/thread-id), key present/absent, A/A/B growing messages; explicit request-id differs per turn. Absent identity controls prove shared key never becomes a session. This fixture establishes OCX preservation, not actual Hermes emission. No runtime patch unless evidence finds loss.
11 changes: 11 additions & 0 deletions devlog/_plan/260912_cache_lane/041_hermes_ci_refresh.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
# Hermes hosted-CI refresh after shared fixture repair

Resume preserves the same worktree and session. The host goal is blocked and persisted phase remains C; no goal/FSM reset, reactivation or completion is claimed. This file records the authorized remaining work, not a new completed cycle.

The original Hermes head `b254efc8385ce2a9dc34b9a5ac7d2a449605d75d` failed gates on the Combo active-reactivation fixture, while four Linux and two macOS product shards succeeded. Shared repair #4390 is now integrated as `20861aebf56c6f8ec2b0d8d04d1d0b54441650bb` and its exact hosted CI `34688482827` succeeds. Affinity/prefix old runs failed restore/Cline fixtures subsequently repaired by that same PR. Old failed runs remain failed.

Rebase the one owned Hermes test-only commit from `e4ee8c54` onto current `origin/dev` at `392e182a00` (record full SHA in handoff). Read-only merge-tree reports no conflict. Preserve the 99-line runtime-boundary test and both mappings; no Combo, Cline, restore or provider source edits. Compare old/new authored source deltas and obtain an inherited-model independent source audit. Append terminal evidence to `060_handoff.md`, preserving real Hermes acceptance as open. Push only existing Hermes branch with `--no-verify` and exact old-head lease; no new task/worktree or recreation of merged evidence PR #4377. Bind new final hosted CI to new Hermes SHA. Parent owns integration and chooses any source collision slot.

Local suites/focused/GUI/build/typecheck/install remain NOT RUN. The successful shared integration CI proves its own cumulative source tree, not the old failed PR heads. A new Hermes tip must be independently verified remotely before a passing delivery claim.

Parent integration-slot update: final pinned base is `c311f9bf7f5003af29fa8e7ebc2f2b5db20267f6`, including the subsequently integrated pnpm and Devin fixture corrections. Rebase the two owned commits from `392e182a` without runtime changes. Original 99-line test and mappings must remain byte-identical; source review is renewed for final head. Prior run `34693156321` at `524afd8d80` is superseded evidence only, never final-tip proof. Parent is holding the Hermes slot. Persisted phase C and blocked host goal stay unchanged.
10 changes: 10 additions & 0 deletions devlog/_plan/260912_cache_lane/060_handoff.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,3 +28,13 @@ Local tests of every size, build, typecheck and install were **NOT RUN** by expl
## Final evidence-cycle record

The final evidence B phase produces this tracked update as its documentation artifact. An earlier C transition was rejected by SOURCE-DELTA-01 because only scratch metadata and the PR body had changed; that rejected transition did not advance the FSM. The evidence branch now records the actual delivered source heads, parent integrations and unproven closure attribution. It changes no runtime code. Hosted terminal results must still be read before this cycle closes; an evidence document is not a product-test pass.

## Resumed terminal-CI reconciliation

The original final-tip results are now terminal: affinity run `34674962749` FAILED (native restore/injection fixtures); prefix run `34675829597` FAILED (the same restore family plus Cline registry/CLI/localization/icon/test-layout expectations); Hermes run `34674763850` FAILED (Combo active-reactivation GUI fixture). Their passing cache assertions do not make those runs green. Claim run `34673563105` remains SUCCESS and was not rerun.

Shared fixture repair #4390 is merged at `20861aebf56c6f8ec2b0d8d04d1d0b54441650bb`, containing the delivered affinity and repaired prefix heads by verified Git ancestry. Its [hosted CI 34688482827](https://github.com/lidge-jun/opencodex/actions/runs/34688482827) succeeded: 19 jobs successful, 2 skipped. This is new cumulative integration evidence, not a relabeling of the old failed results. Cache runtime sources were not rewritten to fix another lane's failure.

The remaining open Hermes PR #4365 is refreshed onto `392e182a004d61b38c7cf652642e63b9a11d9a65` without conflicts, preserving its test-only delta. Its new final head and hosted outcome are exported to that PR description and the scratch handoff after source audit and publication. Merged evidence PR #4377 is left intact. The host goal is blocked; persisted phase C is preserved and neither is claimed completed. Local product suites/build/typecheck/install remain NOT RUN.

Final Hermes slot: the coordinator pinned `c311f9bf7f5003af29fa8e7ebc2f2b5db20267f6` after the pnpm/Devin fixture corrections. The test-only PR is rebased onto that fixed base without conflicts or runtime edits. Its exact final-head source review and hosted run replace the earlier `524afd8d80` candidate evidence in the PR description. The previous failed runs remain historical failures, and actual Hermes client-field acceptance remains open.
27 changes: 27 additions & 0 deletions devlog/_plan/260912_combo_carry/040_pnpm_ci_repair.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
# Native-platform pnpm shim regression fixtures

The final all-lane run found two pnpm shim tests failing on Windows. Both request Linux shim
semantics against Windows filesystem metadata. The tested source and fixture blobs are identical
at the Combo base, failing tip and current dev; this is source evidence of pre-existing code, not
an executed baseline reproduction. Hosted run34674363301 job103503916566 contains the failure.

Scope: MODIFY tests/update/update-pnpm.test.ts only, plus this record. Production resolver,
POSIX executable-bit guard, declaration file and update/job.ts remain unchanged. Local suites,
build/typecheck/install remain NOT RUN; hosted CI observes the repair. No workflow changes.

NEW local fixture helper emits actual-host launchers: POSIX ocx/opencodex scripts with executable
permissions; Windows cmd and PowerShell files for both commands. MODIFY the active-target and
alias cases to use the helper and verifier's real host default. The stale-target case replaces
both forms of only opencodex on Windows, preserving rejection coverage for both command names.
The two previously failing cases continue to run on every platform.

NEW separate POSIX permission case: native valid target passes, removing one shim's execute bits
rejects that command, restoring permissions passes. This new filesystem-specific case runs on
POSIX only; NTFS cannot provide the claimed mode-bit contract. This is not a skip of either
failing test and does not weaken the production permission predicate.

Preserve the existing explicit Windows cmd/PowerShell case. Reject the earlier proposed stat
injection: host-native fixtures preserve coverage without changing production APIs. Use a new
owned dev repair PR, independent read-only review, --no-verify push and repaired cumulative tip
hosted CI. Original Combo all-lane FAIL remains recorded. Windows shard3's separate devin CLI
discovery failure is handed to the parent for its owner; this pnpm change does not claim to fix it.
25 changes: 25 additions & 0 deletions devlog/_plan/260912_history_containment/051_resume_status.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
# Resumed history verification

Continuation carry #4350 was merged by the coordinator; its final-head hosted run 34673958547
completed successfully. Containment carry #4342 was also merged, but run 34674692660 failed and
has not been represented as passing. Relay #4360 remains draft; latest inspected carry92592066
includes the independently supplied activation-fixture update. Run34682796830 failed.

This repair addresses hosted history-owned failures: canonical temporary-home identities on macOS,
explicit failed config artifacts, complete preimage preservation after failed cleanup, admission
principal result fields and relay error/credential validation ordering. Default-off dispatch is
revalidated after asynchronous waits. Listener cancellation coverage observes actual active-turn
accounting; a manually released fake lease is not release evidence.

Local product suites, builds, typecheck and installation: NOT RUN by explicit user direction.
Regression source and independent source review are not a runtime pass. Final repaired-head hosted
CI remains required. Unrelated GUI/client/translation failures are recorded for their owners and
are not changed in this lane. No new worktree, task, account setting or service mutation occurred.

The host goal is blocked and the persisted workflow remains A. Its state was not reset or edited;
authorized repairs continue under the explicit resume instruction. This status does not claim a
completed verification cycle.

The prior same-process Windows spill impossibility conclusion is withdrawn: the existing ACL
compliance check executes before the timeout-memo refusal. Actual long-lived process recovery,
native paginated-writer support and damaged-history recovery remain unverified and unresolved.
81 changes: 81 additions & 0 deletions docs-site/src/content/docs/guides/codex-integration.md
Original file line number Diff line number Diff line change
Expand Up @@ -123,6 +123,87 @@ The proxy listens on port `10100` by default and serves `POST /v1/responses`,
`POST /v1/responses/compact`, `POST /v1/images/generations`, `POST /v1/images/edits`,
`GET /v1/models`, `GET /healthz`, and the `/api/*` management surface.

### Experimental context management (Codex 0.153+)

For an eligible ChatGPT account, enable the experimental feature in Codex's own
`config.toml` (merge this into an existing `[features]` table):

```toml
[features]
context_management.experimental_mode = true
```

On the default built-in loopback integration, the next `ocx sync` or proxy start changes the
managed root `openai_base_url` to `http://127.0.0.1:10100/backend-api/codex`. Codex checks this
backend path before enabling its `new_context`, history, and notes tools. Start a new Codex
session after synchronization. The feature remains opt-in; user-owned base URLs and remote
custom-provider injection are not rewritten. No context-window or compaction-limit override
is needed or added.

The backend prefix aliases the existing data-plane routes, including Responses WebSocket
upgrades. The original `/v1` routes and the realtime sideband override remain available. The
proxy also relays the ten native `alpha/history/v2/*` and `alpha/notes/v2/*` POST endpoints
through the built-in `openai` provider with the `openai-responses` adapter and canonical
ChatGPT forward destination. Direct uses the current caller/main login; Pool selects a Codex
account. `openai-apikey` uses its configured API key, and custom or noncanonical Responses
providers are not candidates for this context relay and receive no Codex-account credentials
from it. These private endpoints are not implemented by other model providers or the OpenAI
API-key route.

Caller headers are restricted to the shared Codex forward allowlist: `authorization`,
`chatgpt-account-id`, and approved OpenAI beta, originator, session, and Codex protocol metadata.
The context relay additionally forwards `x-openai-encrypted-tool-arguments` and
`x-openai-tool-output-truncation-policy`; arbitrary caller headers such as cookies are not
forwarded. A proxy data-plane key presented as a bearer is replaced with the selected Codex
credential (the stored main login in Direct); missing credentials fail before forwarding.
Proxy admission credentials never go upstream. Encrypted arguments, response bodies, and
upstream error statuses are preserved.

A successful ChatGPT model response records the root session's actual serving account in a
bounded, process-local ownership registry. History and notes use that recorded owner, including
an explicitly selected account, even when the current active account changes. Stored-account token
refresh may continue for the same physical account; a replaced account identity is rejected.
Direct caller-owned sessions keep the caller credential and cannot be taken over by a proxy bearer.
This does not migrate server-side history between accounts.

Ownership is partitioned by the opencodex API key that admitted the request, so two keys never
reach each other's sessions even when both resolve to the same ChatGPT workspace. A workspace id
names an organization rather than a person, so the registry also binds the stable user carried by
the credential upstream accepted: an ordinary token refresh for that same user continues the
session, while a different user in the same workspace does not. When the accepted credential
proves no stable user, only that exact credential continues. That principal is the opencodex API key the request presents. A remote bind already requires one,
so ownership works there. On the default loopback bind opencodex admits requests without reading a
key, and the built-in loopback injection cannot carry the `x-opencodex-api-key` header, so Codex
presents no opencodex key and context history returns HTTP 403. **The relay is therefore available
on a remote bind with a configured key, or to a client that sends `x-opencodex-api-key` itself, and
not through the default built-in loopback integration.** Whether a loopback-bound proxy should be
able to name a caller at all is an open maintainer decision, so the current behaviour refuses
rather than guessing.

Unknown, expired, evicted, conflicting, or restart-lost ownership returns HTTP 409 before account
selection or upstream I/O. The relay does not guess from the current active account. Existing
sessions should save a checkpoint or other durable summary before enabling the feature or resetting
context. Enabling it does not backfill earlier history or notes, and a new ownership observation
does not prove that older backend content exists. After a restart, establish ownership with a
successful model request before using context tools; start a new session when ownership conflicts.

Existing model affinity, cooldown, and retry rules are unchanged. Context requests are not
automatically retried, including notes writes; ChatGPT forward requests do not use same-key 429
replay. History traffic does not consume or settle a model quota-recovery probe.

One 35-second deadline covers the whole relay operation, starting before the request body is read
and covering credential selection, so a stalled client cannot hold an admitted turn slot open.
A client disconnect returns 499 and an expired deadline returns 504; nothing is dispatched
upstream after either.

To disable the feature, remove the experimental key (or set it to `false`), run `ocx sync`,
and start a new Codex session. The managed root base returns to `/v1`.

While the key is absent or `false` the relay does not exist: the ten endpoints answer 404 for any
caller, including one that posts them directly, and a model turn records no history ownership.
opencodex decides this by reading Codex own config itself, so the switch does not depend on the
injected URL or on anything a client sends, and turning it off takes effect without a restart.

### Built-in image generation (`image_gen`)

Codex's built-in `image_gen` tool does not go through `/v1/responses` — the codex-rs extension
Expand Down
Loading
Loading