Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
76 commits
Select commit Hold shift + click to select a range
137d6a7
chore(release): open dev at 2.46.0 before releasing 2.45.0 (#3812)
github-actions[bot] Sep 6, 2026
e963aa6
docs: plan platform validation follow-up
invalid-email-address Sep 6, 2026
eabe7ce
docs: plan axis1 bounded bug fixes [skip ci]
invalid-email-address Sep 6, 2026
58fcb09
fix(claude): preserve reasoning and tool result envelopes
lidge-jun Sep 6, 2026
b2703f8
fix(grok): filter Codex control frames for strict Responses clients
lidge-jun Sep 6, 2026
0d42efa
docs(plan): define axis five display and CLI delivery
invalid-email-address Sep 6, 2026
ef54e82
docs: describe BigModel and Raycast integration contracts
invalid-email-address Sep 6, 2026
6a51f04
test(oauth): drain ACL flights before fixture teardown [skip ci]
invalid-email-address Sep 6, 2026
336c621
fix(grok): honor SSE event order and empty resets
lidge-jun Sep 6, 2026
9cde6e7
test(responses): cover established task delivery and compaction
lidge-jun Sep 6, 2026
cb8ac02
fix(diagnostics): distinguish inbound size measurement provenance [sk…
invalid-email-address Sep 6, 2026
c7f6ba7
feat(providers): carry static BigModel Responses preset from #3641
invalid-email-address Sep 6, 2026
130be8d
feat(catalog): carry native display labels with normalization contrac…
invalid-email-address Sep 6, 2026
1ee829d
feat(cli): carry provider list JSONL output [skip ci]
invalid-email-address Sep 6, 2026
e00d5c3
test(container): verify build startup and volume recreation [skip ci]
invalid-email-address Sep 6, 2026
92c95fa
feat(gui): carry discovered model name editor with recoverable saves
invalid-email-address Sep 6, 2026
f215f79
fix(anthropic): attribute quota headers and honor measured reset dead…
invalid-email-address Sep 6, 2026
12b174e
fix(claude): preserve signed and opaque replay block boundaries
lidge-jun Sep 6, 2026
8f8790e
docs(devlog): record axis three protocol delivery plan
lidge-jun Sep 6, 2026
9d775fa
fix(gui): preserve display name receipts across recovery failures
invalid-email-address Sep 6, 2026
d523990
fix(providers): repair static BigModel login and Responses effort
invalid-email-address Sep 6, 2026
9336a27
test(providers): distinguish BigModel upstream and bridge modalities
invalid-email-address Sep 6, 2026
e352ede
fix(gui): balance name editor helper text on narrow screens
invalid-email-address Sep 6, 2026
c721b94
fix(claude): report terminal closure buffer overflow once
lidge-jun Sep 6, 2026
513391e
test(container): isolate synthetic inference without internal network…
invalid-email-address Sep 6, 2026
76e667f
test(responses): account for ordinary tool catalog guidance
lidge-jun Sep 6, 2026
9b5b670
test(claude): correct replay and closure overflow oracles
lidge-jun Sep 6, 2026
619f7a7
test(container): declare the synthetic loopback destination [skip ci]
invalid-email-address Sep 6, 2026
4c1d9af
fix(gui): reconcile display name draft during snapshot render
invalid-email-address Sep 6, 2026
d6cf876
feat(integrations): carry Raycast client from #3733
invalid-email-address Sep 6, 2026
ea3d03a
fix(integrations): repair Raycast #3733 ownership and plan guidance
invalid-email-address Sep 6, 2026
387d787
fix(raycast): honor live export admission and defer ensure refresh (#…
invalid-email-address Sep 6, 2026
22f39ff
test(responses): exercise empty effort ladder through valid ingress
invalid-email-address Sep 6, 2026
95edd0a
fix(export): preserve live CLI destination despite saved listener dri…
invalid-email-address Sep 6, 2026
d175335
test(container): verify first-start migrations before persistence bas…
invalid-email-address Sep 6, 2026
ab2bbc6
Merge pull request #3828 from lidge-jun/codex/axis2-bigmodel-stack-11fe
lidge-jun Sep 6, 2026
b65b9d8
Merge pull request #3829 from lidge-jun/codex/axis2-raycast-stack-11fe
lidge-jun Sep 6, 2026
68d90aa
docs(claude): describe redacted reasoning replay
lidge-jun Sep 6, 2026
2269e07
Merge pull request #3830 from lidge-jun/codex/axis3-protocol-foundation
lidge-jun Sep 6, 2026
07f8d70
Merge pull request #3831 from lidge-jun/codex/axis3-grok-control-frames
lidge-jun Sep 6, 2026
4349cf3
Merge pull request #3832 from lidge-jun/codex/axis3-protocol-combined
lidge-jun Sep 6, 2026
e873008
docs(devlog): record verified protocol delivery and remainders
lidge-jun Sep 6, 2026
943e5a7
merge verified runtime landing into documentation closeout
lidge-jun Sep 6, 2026
e337374
Merge current dev into axis five native labels [skip ci]
invalid-email-address Sep 6, 2026
e862b86
Merge refreshed native label base into JSONL layer [skip ci]
invalid-email-address Sep 6, 2026
f51ec24
Merge refreshed axis five base for final integrated validation
invalid-email-address Sep 6, 2026
a5f9c34
Merge pull request #3834 from lidge-jun/codex/axis3-protocol-docs
lidge-jun Sep 6, 2026
91fba4b
ci: gate source-build Docker lifecycle verification [skip ci]
invalid-email-address Sep 6, 2026
15fa571
fix(container): retain routed catalog across managed recreation [skip…
invalid-email-address Sep 6, 2026
6f2ad1e
ci: select explicit-file typecheck mode for TypeScript 7 [skip ci]
invalid-email-address Sep 6, 2026
a3c2eb5
fix(anthropic): expire retained quota measurements at known resets [s…
invalid-email-address Sep 7, 2026
54fcc68
test(anthropic): keep probe fixtures inside live reset windows [skip ci]
invalid-email-address Sep 7, 2026
d3c70f9
fix(anthropic): normalize retained quota metadata and guard test tran…
invalid-email-address Sep 7, 2026
872f0e5
fix(cli): explain which side of a version mismatch is older [skip ci]
invalid-email-address Sep 6, 2026
2e8ef03
fix(responses): classify encrypted task recovery failures
invalid-email-address Sep 6, 2026
6388ec7
Merge pull request #3818 from lidge-jun/codex/platform-lane4-oauth
lidge-jun Sep 7, 2026
da18da4
Merge pull request #3819 from lidge-jun/codex/platform-lane4-body
lidge-jun Sep 7, 2026
5dee8cf
Merge pull request #3822 from lidge-jun/codex/platform-lane4-docker
lidge-jun Sep 7, 2026
7fdb0e9
Merge pull request #3823 from lidge-jun/codex/platform-lane4-final
lidge-jun Sep 7, 2026
1e16fe4
Merge axis five native display names (#3820)
lidge-jun Sep 7, 2026
be24986
Merge axis five provider JSONL output (#3821)
lidge-jun Sep 7, 2026
44c69fd
Merge axis five discovered model name editor (#3824)
lidge-jun Sep 7, 2026
2c8ec0b
docs(devlog): close axis five display and CLI delivery
invalid-email-address Sep 7, 2026
e894dcb
Close axis five delivery record (#3835)
lidge-jun Sep 7, 2026
0ccc6bd
docs: keep delivery attribution without contact addresses [skip ci]
invalid-email-address Sep 7, 2026
bf85e67
Merge PR #3836: repair delivery-note privacy scan [skip ci]
lidge-jun Sep 7, 2026
b29bbb4
fix(clients): preserve exact Aside file identities [skip ci]
invalid-email-address Sep 7, 2026
85fbdb5
Merge pull request #3825: verified axis1 bug fix [skip ci]
lidge-jun Sep 7, 2026
860baaf
Merge pull request #3826: verified axis1 bug fix [skip ci]
lidge-jun Sep 7, 2026
5a97db9
Merge pull request #3827: verified axis1 bug fix [skip ci]
lidge-jun Sep 7, 2026
5fdf9bb
Merge pull request #3842: verified axis1 bug fix [skip ci]
lidge-jun Sep 7, 2026
be112e4
docs: close axis1 bug-fix delivery record [skip ci]
invalid-email-address Sep 7, 2026
0d8b0cd
Merge PR #3847: close axis1 delivery record [skip ci]
lidge-jun Sep 7, 2026
3970601
chore(release): prepare 2.46.0 stable promotion
invalid-email-address Sep 7, 2026
bba6322
Merge pull request #3851 from lidge-jun/codex/release-246-main
lidge-jun Sep 7, 2026
d674aa9
fix(usage): bound persisted requested model selectors
luvs01 Sep 7, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
31 changes: 30 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,10 @@ on:
push:
branches: [main, preview, dev]
paths:
- "Dockerfile"
- "compose.yaml"
- ".dockerignore"
- "docker/**"
- "src/**"
- "bin/**"
- "tests/**"
Expand Down Expand Up @@ -180,6 +184,10 @@ jobs:
# start the workflow so the aggregate check exists, while these
# paths decide whether the expensive test jobs need to run.
ci:
- 'Dockerfile'
- 'compose.yaml'
- '.dockerignore'
- 'docker/**'
- 'src/**'
- 'bin/**'
- 'tests/**'
Expand Down Expand Up @@ -423,6 +431,7 @@ jobs:
run: |
bun x tsc --noEmit
bun x tsc --noEmit -p tests/tsconfig.doctor-service-memory-contract.json
bun x tsc --ignoreConfig --noEmit --strict --target ESNext --module ESNext --moduleResolution bundler --types bun-types --skipLibCheck scripts/ci/docker-smoke.ts

- name: GUI tests
run: cd gui && bun test --isolate tests
Expand Down Expand Up @@ -908,6 +917,26 @@ jobs:
bun run scripts/keyring-smoke.ts
'

# Exercise the source-build Compose contract, including real volume reuse.
# Host fixtures cannot prove image construction or container recreation.
docker-smoke:
name: docker smoke
needs: changes
if: github.event_name != 'pull_request' || needs.changes.outputs.ci == 'true'
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
with:
persist-credentials: false

- name: Setup project Bun
uses: ./.github/actions/setup-project-bun

- name: Build, start, and recreate the container
run: bun scripts/ci/docker-smoke.ts

npm-global-smoke:
name: npm-global ${{ matrix.os }}
needs: changes
Expand Down Expand Up @@ -986,7 +1015,7 @@ jobs:
# direct dependencies only, so a failing `select-windows-runner` would
# otherwise reach this gate as nothing at all while its dependents report
# `skipped` — which the gate is required to read as a deliberate skip.
needs: [changes, select-windows-runner, test, storage-policy, api-usage, gates, platform-macos, macos-control, platform-windows, keyring-smoke, npm-global-smoke]
needs: [changes, select-windows-runner, test, storage-policy, api-usage, gates, platform-macos, macos-control, platform-windows, keyring-smoke, docker-smoke, npm-global-smoke]
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
Expand Down
3 changes: 3 additions & 0 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,10 @@ RUN cd gui && bun run build
FROM ${BUN_IMAGE} AS runtime
WORKDIR /home/bun/app

# Docker supervises this foreground process; retain routed state on stop/recreate.
# This uses the existing service lifecycle mode and does not install a service manager.
ENV NODE_ENV=production \
OCX_SERVICE=1 \
OPENCODEX_HOME=/home/bun/.opencodex \
CODEX_HOME=/home/bun/.codex \
OCX_API_TOKEN_FILE=/home/bun/.opencodex/service-api-token
Expand Down
24 changes: 24 additions & 0 deletions devlog/_fin/260907_axis1_bugfixes/000_plan.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
# Axis 1: measured bug fixes and failure diagnostics

Completed: see [031_delivery_record.md](031_delivery_record.md) for merged commits, final CI, attribution and deferrals.

Archetype: satisfy existing contracts. Trigger: owner assigned axis 1 (#3809, #3464, #3661). Goal: deliver reviewable fixes through a manual PR chain and merge the verified scope. Non-goals: new account/retry policy, auth defaults, multipart recovery, releases, native stacks, sibling edits. Stop: merged feasible scope plus explicit unresolved dispositions. Escalation: defer a policy-dependent or unreproducible slice; reclaim a worker slice after two failed packets. Evidence: this unit plus ignored `.tmp/axis1/` and `.codexclaw` receipts. Resources: task-owned worktree/branches and GitHub repository access; Astra high leaves within host capacity; no caller-specified token or wall-clock budget.

Baseline: origin/dev 137d6a727; source PR #3809 at 4a1012359a522ddd6d7ff77203c9e5f3632d605c. Assigned 5cc8 checkout has pre-existing changes and remains untouched. Code lives in /tmp/ocx-axis1-20260907.

## Cycle map
1. wp0: docs-only scope, source audit and dependency roadmap; no runtime changes.
2. wp1: bounded quota, version-guidance and recovery-diagnostic changes; independent source/security review and structural checks. Runtime verification deferred explicitly to wp2.
3. wp2: publish ordinary PR chain, run final cumulative hosted CI, resolve findings, admin merge bottom-up and verify dev ancestry. Lower CI only if final CI fails.

## Delivery contract
The owner explicitly requests a manual delivery chain even where units are independent: quota -> CLI guidance -> recovery reasons, with each layer carrying its own tests and credit. This order is an integration order, not a fabricated runtime dependency. No native registration. Lower commits carry [skip ci] to defer duplicate workflow runs; final head does not. Skipped lower runs are never called passing. No local tests/typecheck/build suites and no hook-triggered suites; task pushes use --no-verify. Hosted ci.yml on the final head must cover all changed runtime/tests; lower-level runs are diagnostic only after final failure. Merge with --admin under the explicit owner exception; preserve original commits/trailers with merge commits, retarget each child to dev, and check integration trees against final evidence. Concurrent dev changes require fresh combined verification.

## Work boundaries
- Quota: src/providers/quota.ts, src/oauth/anthropic-routing.ts, src/oauth/health.ts, src/server/responses/core.ts, src/images/loop.ts, src/web-search/loop.ts, focused quota tests/layout, provider documentation.
- CLI: src/cli/version-skew.ts and relevant status/doctor consumers, tests/cli/cli-version-skew.test.ts, troubleshooting documentation. No service restart or repair behavior changes.
- Recovery: src/server/responses/agent-task-recovery.ts, agent-task-recovery-cache.ts, src/lib/bounded-body.ts and existing focused tests, Responses error projection if needed, recovery documentation. No expanded admission/retry.
- Main owns shared core.ts integration and test-layout files. Workers must not touch each other's paths or git index.

## Verification and acceptance
No local suite commands are executed. Source mapping, git diff --check and documentation structural checks are local evidence only. Hosted Cross-platform CI at final head provides runtime/typecheck/privacy and affected platform proof; inspect jobs for skipped coverage. Build completion is provisional until that run and independent audit succeed. Original PR author(s) must be named in commit Co-authored-by trailers, sourced from original commits/API; report authors may also be acknowledged accurately. Source-of-truth sync uses relevant existing structure and docs-site pages.
3 changes: 3 additions & 0 deletions devlog/_fin/260907_axis1_bugfixes/010_roadmap.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
# wp0: scope roadmap

Read current source, prior issue disposition and PR #3809 before choosing changes. Independent Astra high reviewers map each bounded issue. Confirm existing launcher behavior and bounded recovery reasons are already in dev; plan only residual fixes. Record exact file boundaries and acceptance scenarios in 020. Success: all three slices have verifiable requirements, main-owned shared files, original author anchors and explicit policy exclusions. Local evidence is documentation and source inspection; no runtime claim.
5 changes: 5 additions & 0 deletions devlog/_fin/260907_axis1_bugfixes/011_audit.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
# wp0 audit disposition

Independent Astra high reviewer Hooke: VERDICT: GO-WITH-FIXES (blockers=1). Shared-flight failure propagation was the blocker. Accepted: 000/020 now assign cache and bounded-body ownership and define shared typed outcomes, success-only cache, caller-local cancellation and capacity semantics. Source scouts independently identified and confirmed these requirements. Fixed stale CLI test path. Windows runtime proof requires final workflow_dispatch, now explicit in 030.

No runtime code changed. Documentation source/ownership inspection and git diff --check are the wp0 evidence. Runtime verification remains wp2.
5 changes: 5 additions & 0 deletions devlog/_fin/260907_axis1_bugfixes/012_roadmap_lock.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
# Roadmap lock

The second independent audit returned VERDICT: PASS with no remaining blockers. The three accepted slices are ready for scoped implementation. Original quota author: Éverton Toffanetto (everton-dgn), commit identity from 4f3779c04753 and 3ef0ade296c3. Issue reporters: garysassano (10464497) and Hu9956 (282876394). Reporter acknowledgement is separate from code authorship.

Preserve raw unequal version diagnostics. Detailed recovery outcomes must travel in the shared flight, not caller-local closures. Quota observations use immutable dispatch identity. Final verification is hosted workflow_dispatch for full Windows coverage; local suites remain prohibited.
20 changes: 20 additions & 0 deletions devlog/_fin/260907_axis1_bugfixes/020_bounded_fixes.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
# wp1: implement bounded bug fixes

## Quota
Carry only the source PR diff onto current dev, with original-author trailer. Header utilization fraction -> percentage; reset epoch -> timestamp. Creation: parser; serialization: account quota cache; deserialization: existing hydration; consumers: account ranking/health and management reading. Account-bound writer generation is captured with serving credentials, including retry/sidecar/continuation rebinds. Header observations merge model-specific windows and cannot indefinitely postpone probes. Existing 429 eligibility and retry count stay unchanged. Explicit reset evidence must not be truncated by an invented six-hour policy; any unresolved policy piece is deferred.
Scenarios: 200 and 429 on main/sidecar/continuation attribute only the serving account; generation invalidation discards writes; partial/malformed headers preserve known fields; no prior probe means model-window probe is still due; weekly rejected reset outlasts five-hour reset; absent evidence retains existing fallback. Verify with focused tests included in final hosted CI.

## Version guidance
Compare CLI and running proxy using existing semantic-version utilities if present. CLI newer points to service restart; proxy newer points to upgrading/PATH resolution of CLI; equal/unknown retain suppression; incomparable differing builds use neutral wording. status and doctor share advice. Preserve whether requests are allowed and do not perform repair. Test both directions, prereleases, placeholders, malformed versions and consumer projection.

## Recovery reasons
Keep existing public wrapper returning boolean and typed detailed result. Classify actual upstream HTTP refusal, transport error, timeout/caller cancellation, response-body/decode failures with a bounded vocabulary. Creation: request/collector; propagation: detailed recovery result; consumers: existing response reason projection/tests/docs. No raw upstream body/errors/tokens/ciphertext in output. Strict admission, one attempt, same credential and unchanged request mutation guarantees. Exercise each failure branch, cancellation races, malformed terminal output and successful recovery in final hosted CI.

Main owns src/server/responses/core.ts and layout metadata. Source/security review must check public boundaries and negative cases, not only implementation-mirroring tests. Source-only C evidence does not claim runtime correctness; wp2 is mandatory.

## Source-map clarification from independent #3464 research
Use src/lib/strict-semver.ts unchanged. Raw unequal versions remain skewed; equal precedence with different build metadata and invalid/whitespace/v-prefixed values get neutral wording, not normalization or a guessed direction. Placeholder suppression is unchanged. src/cli/doctor.ts must not call suppressed placeholders a confirmed match. Focused files: tests/cli/cli-version-skew.test.ts, tests/cli/cli-status-json.test.ts, tests/codex-integration/doctor.test.ts. Documentation: reference/cli/lifecycle.md and directly affected Korean/Russian pages. Existing launcher landed via #3616 (4e2246c32); no service runtime changes.

## Audit refinements
Quota: observe physical responses at the existing oauthDispatch boundary before any main/continuation replacement or return. Use immutable request binding to pair response with selected account; skip when final authorization headers do not prove that bearer or credentialGeneration has changed. An active-account switch alone does not invalidate another account's in-flight observation. Native Claude passthrough and single-account expansion remain outside #3809 carry. Preserve Retry-After precedence; only reject nonfinite/unrepresentable deadlines rather than invent an anomaly ceiling. Header-only rows are probe-due; hydrated Anthropic observations must be probe-due unless probe time is proven. Failed probes settle with the most recent committed observation for all joiners.
Recovery: worker owns agent-task-recovery-cache.ts and bounded-body.ts narrow decode discriminator alongside focused tests. Shared flight carries typed outcome, cache retains only success plaintext, cancelled waiters remain local. Recognized caller cancellation precedes owned timeout, which precedes decode/transport classification. Fatal UTF-8 discriminator must identify actual decoder exceptions without reclassifying fetch/body-reader TypeErrors. Rejected-response cancellation is nonblocking best effort. Keep current public wrappers and combo error projection. Update documented reason lists in structure/04_transports-and-sidecars.md and docs-site/reference/architecture.md.
7 changes: 7 additions & 0 deletions devlog/_fin/260907_axis1_bugfixes/021_source_review.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# wp1 source review

Three bounded patches implemented with regression coverage. Hooke independently passed the physical-response quota observer wiring; Tesla independently passed quota/recovery security and source review with zero blockers. Version comparator and status/doctor projections inspected by main. All source workers report no local suite/typecheck/build execution.

Quota source: #3809, Éverton Toffanetto; Co-authored-by included in f215f79b4. Version report: garysassano; Reported-by included in f91e3953a. Recovery report: Hu9956; Reported-by included in recovery commit.

Source-only checks: git diff --check and documentation fence/whitespace inspection. These do not prove runtime correctness. wp2 final cumulative hosted CI is still mandatory. Final CI dispatch includes Windows because ordinary PR workflow omits it. No release/deploy workflow will be dispatched.
7 changes: 7 additions & 0 deletions devlog/_fin/260907_axis1_bugfixes/030_delivery.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# wp2: hosted proof and manual-stack landing

Publish task-owned branches with --no-verify. Standard PR template, source links, truthful skipped-local/lower-CI disclosure and contributor trailers. Lower layers use [skip ci], final cumulative head runs existing Cross-platform CI; never modify shared workflow filters or fabricate checks. On final failure inspect failing jobs, fix owned defects, and only then use lower CI to localize ambiguity. Leave unrelated/unresolvable slices unmerged with evidence.

Before admin merge: source/security review findings resolved, final CI SHA/run pinned, current PR head and manual membership inspected. Record owner-authorized admin review/lower-CI exception. Merge bottom-up with original commits preserved; do not delete parent branches while children depend on them. Retarget child to dev after parent landing. Reconcile concurrent dev before claiming final integrated proof. Verify every merge SHA is ancestor of refreshed origin/dev. Close #3809 only after its accepted replacement scope lands; keep #3661 open for multipart/retry and #3464 open if broader original acceptance remains unresolved. No release/deploy.

Final full platform evidence uses workflow_dispatch ci.yml on the final cumulative branch, because ordinary PR CI excludes the Windows runtime job. Cancel only duplicate task-owned PR CI runs; skipped/cancelled runs are not passing evidence.
Loading
Loading