Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
445 commits
Select commit Hold shift + click to select a range
bb9dd25
fix(gui): use stable identities for client refresh warnings
invalid-email-address Sep 5, 2026
5a9476e
docs: archive verified A runtime and routing delivery
invalid-email-address Sep 5, 2026
83e2275
fix(claude): validate managed Fast bases and bound snapshot lifetime
invalid-email-address Sep 5, 2026
b78d645
Merge verified integration changes into remote Desktop work
invalid-email-address Sep 5, 2026
115b3fc
Merge pull request #3718 from lidge-jun/codex/a-final-closeout
lidge-jun Sep 5, 2026
092bdac
test(claude): use clearly synthetic admission credentials
invalid-email-address Sep 5, 2026
8e87faa
ci: refresh pending GUI stack checks
invalid-email-address Sep 5, 2026
f268e6e
Merge branch 'codex/grok-owned-catalog-refresh-5598' into codex/grok-…
invalid-email-address Sep 5, 2026
d88b4fb
Merge branch 'codex/grok-responses-patch-5598' into codex/grok-native…
invalid-email-address Sep 5, 2026
f63eac9
Merge remote-tracking branch 'origin/dev' into codex/grok-pi-filter-5598
invalid-email-address Sep 5, 2026
7203736
Merge branch 'codex/grok-pi-filter-5598' into codex/grok-owned-catalo…
invalid-email-address Sep 5, 2026
1979f5c
Merge branch 'codex/aside-profile-controls-5598' into codex/aside-pro…
invalid-email-address Sep 5, 2026
db9c6a0
Merge branch 'codex/grok-native-tool-parity-5598' into codex/aside-pr…
invalid-email-address Sep 5, 2026
0228877
test(grok): track the deferred Desktop initialization boundary
invalid-email-address Sep 5, 2026
e637cd3
test(clients): bound asynchronous client state probes
invalid-email-address Sep 5, 2026
4893d0d
test(clients): bound asynchronous client state probes
invalid-email-address Sep 5, 2026
ad335db
Merge branch 'codex/grok-responses-patch-5598' into codex/grok-native…
invalid-email-address Sep 5, 2026
1ccd1cb
Merge branch 'codex/grok-native-tool-parity-5598' into codex/aside-pr…
invalid-email-address Sep 5, 2026
b754ffe
Merge branch 'codex/aside-profile-controls-5598' into codex/aside-pro…
invalid-email-address Sep 5, 2026
d539f4e
Merge pull request #3698 from lidge-jun/codex/grok-pi-filter-5598
lidge-jun Sep 5, 2026
fe12d10
Merge pull request #3699 from lidge-jun/codex/grok-owned-catalog-refr…
lidge-jun Sep 5, 2026
d5d9845
Merge pull request #3701 from lidge-jun/codex/grok-responses-patch-5598
lidge-jun Sep 5, 2026
f157750
Merge pull request #3703 from lidge-jun/codex/grok-native-tool-parity…
lidge-jun Sep 5, 2026
3bfce8a
Merge pull request #3710 from lidge-jun/codex/aside-profile-controls-…
lidge-jun Sep 5, 2026
2f124a1
Merge pull request #3714 from lidge-jun/codex/aside-profile-ui-5598
lidge-jun Sep 5, 2026
08428c4
docs(plan): lock model management identity and stacked delivery
invalid-email-address Sep 5, 2026
921e5fe
fix(catalog): retain static default-only providers
cgq0816 Sep 5, 2026
1cff754
test(catalog): cover static default and live boundary contracts
invalid-email-address Sep 5, 2026
0332d9f
feat(models): carry provider model management controls
cgq0816 Sep 5, 2026
1139363
test(catalog): distinguish inherited defaults from empty custom catalogs
invalid-email-address Sep 5, 2026
bfdb5ea
fix(models): bind provider controls to canonical inventory identity
invalid-email-address Sep 5, 2026
5cff8e8
docs(carry): preserve integrated Grok configuration guidance
invalid-email-address Sep 5, 2026
b522225
fix(carry): restore integrated Grok labels and precise rail lookup
invalid-email-address Sep 5, 2026
fcd67c0
fix(models): search raw and namespaced identifiers independently
invalid-email-address Sep 5, 2026
799aeec
docs(models): capture implemented provider model controls
invalid-email-address Sep 5, 2026
285832f
fix(models): keep render lookups and test controls pure
invalid-email-address Sep 5, 2026
330bf60
Merge pull request #3721 from lidge-jun/codex/lane-b-04-management
lidge-jun Sep 5, 2026
f363df9
fix(gateway): preserve Fable 1M picker selection
everton-dgn Sep 5, 2026
79d1a21
test(gateway): cover marked Fable picker alias
everton-dgn Sep 5, 2026
73190c2
Merge pull request #3722 from lidge-jun/codex/lane-b-05-fable
lidge-jun Sep 5, 2026
23ecdfc
docs(carry): record lane B integration outcomes
invalid-email-address Sep 5, 2026
922bfa6
Merge pull request #3723 from lidge-jun/codex/lane-b-06-closeout
lidge-jun Sep 5, 2026
9dc3923
test(oauth): isolate key-login live reload from public DNS
invalid-email-address Sep 6, 2026
567365b
test(oauth): always restore live-reload fixture state
invalid-email-address Sep 6, 2026
0b770b4
fix(client): restore Desktop state across connection lifecycle
invalid-email-address Sep 6, 2026
cc55b48
Merge remote-tracking branch 'origin/dev' into codex/d-3646-remote-de…
invalid-email-address Sep 6, 2026
f84ddaf
fix(desktop): narrow validated restoration inputs
invalid-email-address Sep 6, 2026
fcd235d
test(oauth): type-check captured live reload outcomes
invalid-email-address Sep 6, 2026
be1025d
fix(client): validate lifecycle fixtures and report cleanup failures
invalid-email-address Sep 6, 2026
41ab5c2
Merge pull request #3724 from lidge-jun/codex/fix-key-login-ci-timeout
lidge-jun Sep 6, 2026
b6d5ab6
fix(client): preserve read-only status and ambiguous model availability
invalid-email-address Sep 6, 2026
500aa73
Merge remote-tracking branch 'origin/dev' into codex/d-3646-remote-de…
invalid-email-address Sep 6, 2026
014061a
Merge pull request #3720 from lidge-jun/codex/d-3646-remote-desktop-0…
lidge-jun Sep 6, 2026
95fe52a
docs: define final D integration evidence and archive checks
invalid-email-address Sep 5, 2026
ab20600
ci(macos): apply canonical serial test isolation policy
invalid-email-address Sep 6, 2026
1865d16
test(ci): verify macOS serial ownership and failure propagation
invalid-email-address Sep 6, 2026
ccc317c
docs: archive verified D integration outcomes
invalid-email-address Sep 6, 2026
85ecde8
test(ci): keep simulated crash fingerprints out of runner logs
invalid-email-address Sep 6, 2026
2ca0967
Merge pull request #3725 from lidge-jun/codex/d-final-closeout-01a07265
lidge-jun Sep 6, 2026
941b96a
test(ci): bound the asynchronous shell harness lifecycle
invalid-email-address Sep 6, 2026
af344a2
Merge pull request #3727 from lidge-jun/codex/fix-macos-harness-lifec…
lidge-jun Sep 6, 2026
d3eaa41
docs(plan): define sequential release follow-up integration
invalid-email-address Sep 6, 2026
a7a7aff
docs(plan): lock audited release gates and maintainer authority
invalid-email-address Sep 6, 2026
32669e3
docs(governance): permit explicit maintainer dev integration
invalid-email-address Sep 6, 2026
bc973cf
Merge pull request #3737 from lidge-jun/codex/release-244-roadmap-07c0
lidge-jun Sep 6, 2026
47b05e9
feat(governance): validate explicit maintainer integration authority
invalid-email-address Sep 6, 2026
23b5f38
test(governance): cover explicit integration authorization and races
invalid-email-address Sep 6, 2026
6ef5732
docs(governance): record integration implementation and verification …
invalid-email-address Sep 6, 2026
a082bd7
fix(governance): report integration checks as validation snapshots
invalid-email-address Sep 6, 2026
25c8d2b
Merge pull request #3739 from lidge-jun/codex/release-244-policy-07c0
lidge-jun Sep 6, 2026
a73bb16
fix(responses): preserve complete external task-input envelopes
invalid-email-address Sep 6, 2026
79810cf
test(responses): cover external task input and retained rejection bou…
invalid-email-address Sep 6, 2026
e274094
docs(responses): record task-input implementation and proof boundary
invalid-email-address Sep 6, 2026
815f112
test(responses): distinguish opaque fixtures from normalized plaintext
invalid-email-address Sep 6, 2026
dc3f760
test(server): allocate management-auth listener ports at bind time
invalid-email-address Sep 6, 2026
b24ed35
Merge branch 'codex/release-244-auth-port-fixtures-07c0' into codex/r…
invalid-email-address Sep 6, 2026
ef5a7e1
Merge pull request #3745 from lidge-jun/codex/release-244-auth-port-f…
lidge-jun Sep 6, 2026
8ca2a9b
docs(kiro): specify raw identity and adjacent result verification
invalid-email-address Sep 6, 2026
b7e67d8
fix(responses): align stateful external-task guidance in raw replay
invalid-email-address Sep 6, 2026
685b37e
Merge branch 'codex/release-244-task-input-07c0' into codex/release-2…
invalid-email-address Sep 6, 2026
ff37e4f
fix(kiro): coalesce adjacent outputs by original tool identity
invalid-email-address Sep 6, 2026
9f6a2ef
test(kiro): cover grouped output identity content and barriers
invalid-email-address Sep 6, 2026
b52c5bb
docs: normalize release-plan review formatting
invalid-email-address Sep 6, 2026
00d0cc1
Merge pull request #3743 from lidge-jun/codex/release-244-task-input-…
lidge-jun Sep 6, 2026
f5c3758
test(web-search): verify deadline ownership without wall-clock flakiness
invalid-email-address Sep 6, 2026
efef9f0
test(web-search): expire the shared deadline after immediate rotation
invalid-email-address Sep 6, 2026
36d1e55
Merge branch 'codex/release-244-deadline-fixture-07c0' into codex/rel…
invalid-email-address Sep 6, 2026
5bc38d5
Merge branch 'codex/release-244-kiro-results-07c0' into codex/release…
invalid-email-address Sep 6, 2026
b3acb5d
Merge pull request #3752 from lidge-jun/codex/release-244-deadline-fi…
lidge-jun Sep 6, 2026
c5ccd5d
Merge pull request #3750 from lidge-jun/codex/release-244-kiro-result…
lidge-jun Sep 6, 2026
adb6961
Merge pull request #3751 from lidge-jun/codex/release-244-review-docs…
lidge-jun Sep 6, 2026
ff5105c
docs: lock current-dev opaque recovery carry boundaries
invalid-email-address Sep 6, 2026
fd17378
docs: preserve missing-content-type Responses preflight parity
invalid-email-address Sep 6, 2026
3b8cf8a
fix(responses): recover exact encrypted output rejection once
invalid-email-address Sep 6, 2026
de0d22f
test(responses): cover opaque recovery and headerless streaming
invalid-email-address Sep 6, 2026
840e4c0
test(responses): guard preflight opt-in and safe failed tails
invalid-email-address Sep 6, 2026
b73809f
docs: record bounded opaque recovery integration evidence
invalid-email-address Sep 6, 2026
c67e36a
docs: lock combo recovery composition and cancellation guards
invalid-email-address Sep 6, 2026
1b30050
docs: include combo recovery guide consistency
invalid-email-address Sep 6, 2026
fd5e90f
fix(combos): recover unavailable native tasks without losing cancella…
invalid-email-address Sep 6, 2026
0c97836
test(combos): preserve canonical and third-party quota selection
invalid-email-address Sep 6, 2026
cd054d9
test(combos): cover unavailable native recovery and abort at both sites
invalid-email-address Sep 6, 2026
f5c88be
docs: record mixed combo recovery verification scope
invalid-email-address Sep 6, 2026
73a69e6
docs: plan opaque preflight transport and inspection finality repair
invalid-email-address Sep 6, 2026
15b6d14
docs: preserve original preflight read rejection without cancellation
invalid-email-address Sep 6, 2026
3e1e611
fix(responses): preserve preflight resets and tee failure outcomes
invalid-email-address Sep 6, 2026
812f7af
docs: align native error delivery and account outcome semantics
invalid-email-address Sep 6, 2026
f0cdcb2
test(responses): preserve preflight read resets and client aborts
invalid-email-address Sep 6, 2026
4112efc
docs: include semantic failure usage marker parity
invalid-email-address Sep 6, 2026
b86021b
fix(responses): align semantic failure accounting across relay modes
invalid-email-address Sep 6, 2026
4abd205
Merge branch 'codex/release-244-opaque-recovery-07c0' into codex/rele…
invalid-email-address Sep 6, 2026
cd6d4d3
fix(types): infer the configured stream reader result
invalid-email-address Sep 6, 2026
e1f5a5b
Merge branch 'codex/release-244-opaque-recovery-07c0' into codex/rele…
invalid-email-address Sep 6, 2026
b9f2acc
Merge pull request #3753 from lidge-jun/codex/release-244-opaque-reco…
lidge-jun Sep 6, 2026
b668dc8
docs: finalize verified combo recovery composition record
invalid-email-address Sep 6, 2026
d26e726
test(state): isolate shutdown fallback from host clock delays
invalid-email-address Sep 6, 2026
1697a77
Merge branch 'codex/release-244-shutdown-fixture-07c0' into codex/rel…
invalid-email-address Sep 6, 2026
cededd5
Merge pull request #3755 from lidge-jun/codex/release-244-shutdown-fi…
lidge-jun Sep 6, 2026
da09d40
docs: lock Grok tracker boundary and asynchronous CI delivery
invalid-email-address Sep 6, 2026
3f30084
fix(responses): reconstruct sparse Grok terminal snapshots from valid…
invalid-email-address Sep 6, 2026
b0d0672
test(responses): cover Grok terminal repair and raw call identity guards
invalid-email-address Sep 6, 2026
f5b0312
docs: plan source-backed Windows quota diagnostics guidance
invalid-email-address Sep 6, 2026
2a1f8ca
docs: explain Windows Codex quota diagnostics and service proxy paths
invalid-email-address Sep 6, 2026
c745026
fix(combos): recover stored Pool failures without reopening account hops
invalid-email-address Sep 6, 2026
2804e70
docs: collapse alternative README installation methods (#3760)
lidge-jun Sep 6, 2026
8de1269
test(combos): cover stored Pool recovery budget and cancellation
invalid-email-address Sep 6, 2026
eaa005a
Merge branch 'codex/release-244-combo-recovery-07c0' into codex/relea…
invalid-email-address Sep 6, 2026
72f20e4
Merge branch 'codex/release-244-grok-terminal-07c0' into codex/releas…
invalid-email-address Sep 6, 2026
d48dc99
feat(usage): record resolved xAI credential source per attempt
invalid-email-address Sep 6, 2026
e73eb31
fix(usage): derive native Chat attribution from its active adapter
invalid-email-address Sep 6, 2026
a634d34
test(usage): cover attempt resealing and native Chat key rotation
invalid-email-address Sep 6, 2026
63282e4
fix(usage): pass the initial resolved adapter to source recording
invalid-email-address Sep 6, 2026
96094c3
fix(combos): recover encrypted tasks after native targets become unav…
lidge-jun Sep 6, 2026
384dea7
docs: align encrypted combo recovery fallback descriptions
invalid-email-address Sep 6, 2026
a4451e8
Merge pull request #3756 from lidge-jun/codex/release-244-grok-termin…
lidge-jun Sep 6, 2026
9162b3b
Merge pull request #3758 from lidge-jun/codex/release-244-quota-proxy…
lidge-jun Sep 6, 2026
95c8b4c
fix(dashboard): align overview settings and responsive controls
invalid-email-address Sep 6, 2026
eb35039
ci: retain built dashboard previews for source-bound visual review
invalid-email-address Sep 6, 2026
f00f2bc
Merge pull request #3762 from lidge-jun/codex/release-244-usage-sourc…
lidge-jun Sep 6, 2026
c8470ef
Merge pull request #3763 from lidge-jun/codex/release-244-recovery-do…
lidge-jun Sep 6, 2026
ec88720
fix(dashboard): contain long model labels within overview controls
invalid-email-address Sep 6, 2026
42689e0
fix(dashboard): wrap shadow metadata below narrow headings
invalid-email-address Sep 6, 2026
d656614
docs: record dashboard visual verification and source identity
invalid-email-address Sep 6, 2026
2e1d015
docs: clarify dashboard verification evidence wording
invalid-email-address Sep 6, 2026
eb33893
docs: clarify dashboard preview bounds and version hover target
invalid-email-address Sep 6, 2026
381c6d8
Merge pull request #3764 from lidge-jun/codex/release-244-dashboard-07c0
lidge-jun Sep 6, 2026
a349b52
Merge pull request #3766 from lidge-jun/codex/release-244-dashboard-e…
lidge-jun Sep 6, 2026
e04cb73
fix: unify manual and automatic credential selection
lidge-jun Sep 6, 2026
46332a6
fix: honor manual selection during OAuth credential recovery
lidge-jun Sep 6, 2026
dd5aec5
fix: revalidate queued selection and repair live account updates
lidge-jun Sep 6, 2026
4b3b2fb
fix: retain selected credential across cached adapters and sidecar loops
lidge-jun Sep 6, 2026
bd1cda9
Merge pull request #3768 from lidge-jun/codex/fix-oauth-manual-selection
lidge-jun Sep 6, 2026
44ea957
fix: unblock Windows lifecycle tests and reduce Cursor blob admission…
lidge-jun Sep 6, 2026
7d8523e
chore(release): open dev at 2.45.0 before releasing 2.44.0 (#3783)
github-actions[bot] Sep 6, 2026
116c2ac
Merge commit '44ea9576e27c6be8be7f13a86e32bb349368c54d' into codex/re…
invalid-email-address Sep 6, 2026
07b48da
Merge pull request #3785 from lidge-jun/codex/release-244-main-07c0
lidge-jun Sep 6, 2026
3a991a3
fix(cli): report inert generic account thresholds truthfully
invalid-email-address Sep 6, 2026
c18afc9
fix(cli): keep unknown generic pool capabilities inactive
invalid-email-address Sep 6, 2026
5faaff7
fix(storage): publish cleanup manifests atomically [skip ci]
invalid-email-address Sep 6, 2026
e23eb63
fix(gui): render subscription credit quota bars consistently
invalid-email-address Sep 6, 2026
24c761a
docs(credits): restore missing stacked-PR contributor attribution (#3…
lidge-jun Sep 6, 2026
7b1ac51
fix(container): persist Codex home separately [skip ci]
invalid-email-address Sep 6, 2026
1ddbc4e
docs(skill): keep plaintext keys out of agent recipes [skip ci]
invalid-email-address Sep 6, 2026
17c657c
fix(diagnostics): distinguish spill ACL timeout origins [skip ci]
invalid-email-address Sep 6, 2026
20d84d3
fix(gui): keep subscription quota rows readable in narrow cards
invalid-email-address Sep 6, 2026
59a2f0d
fix(quota): align Antigravity probes with fixed outbound destinations
invalid-email-address Sep 6, 2026
cb84ad8
perf(logs): poll verified request-history deltas without losing updates
invalid-email-address Sep 6, 2026
ff5996d
fix(config): add exclusive initial configuration publication [skip ci]
invalid-email-address Sep 6, 2026
6eec126
feat(models): save picker order without replacing the featured roster
invalid-email-address Sep 6, 2026
dcfae46
fix(cli): preserve existing config during setup [skip ci]
invalid-email-address Sep 6, 2026
0390ce9
Merge current dev into track 3 validation head [skip ci]
invalid-email-address Sep 6, 2026
91111f9
fix(models): preserve usage attribution and own post-save status reads
invalid-email-address Sep 6, 2026
9b0f060
test(models): expect requested-identity-only usage ranking
invalid-email-address Sep 6, 2026
f437219
test(config): use a valid initial publication fixture [skip ci]
invalid-email-address Sep 6, 2026
eca7b63
Merge validated fixture correction from initializer layer [skip ci]
invalid-email-address Sep 6, 2026
2c44fb7
test(cli): drain stdout after prompt reads [skip ci]
invalid-email-address Sep 6, 2026
7aceb0a
test(state): pin the reviewed memory field allowlist [skip ci]
invalid-email-address Sep 6, 2026
4c30386
Merge Windows diagnostic contract correction [skip ci]
invalid-email-address Sep 6, 2026
93184f6
Merge corrected parent layers for final verification [skip ci]
invalid-email-address Sep 6, 2026
6ffa357
fix(lint): classify the picker cache suffix as technical text
invalid-email-address Sep 6, 2026
84f3d80
fix(models): preserve canonical deletion intent across failed saves […
invalid-email-address Sep 6, 2026
118819f
test(models): follow the lifecycle-owned stale-banner reader [skip ci]
invalid-email-address Sep 6, 2026
d1915c4
fix(types): retain config-key types in rollback capture [skip ci]
invalid-email-address Sep 6, 2026
a92835d
Merge pull request #3797 from lidge-jun/codex/t4-01-pool-status-81a8
lidge-jun Sep 6, 2026
b72b8ea
Merge pull request #3798 from lidge-jun/codex/t4-02-credit-bars-81a8
lidge-jun Sep 6, 2026
f7bc920
Merge pull request #3799 from lidge-jun/codex/t4-03-antigravity-81a8
lidge-jun Sep 6, 2026
57211f4
Merge pull request #3800 from lidge-jun/codex/t4-04-log-polling-81a8
lidge-jun Sep 6, 2026
8615f1a
Merge pull request #3801 from lidge-jun/codex/t4-05-picker-81a8
lidge-jun Sep 6, 2026
867dcb7
test(windows): reserve spawn time for profile readiness [skip ci]
invalid-email-address Sep 6, 2026
50f1649
Merge refreshed lower layer for final track 3 CI [skip ci]
invalid-email-address Sep 6, 2026
1ea6895
Merge refreshed lower layer for final track 3 CI [skip ci]
invalid-email-address Sep 6, 2026
067c497
Merge refreshed lower layer for final track 3 CI [skip ci]
invalid-email-address Sep 6, 2026
ae325ab
Merge refreshed lower layer for final track 3 CI [skip ci]
invalid-email-address Sep 6, 2026
618297d
Merge refreshed lower layer for final track 3 CI [skip ci]
invalid-email-address Sep 6, 2026
6401e23
Merge refreshed lower layer for final track 3 CI [skip ci]
invalid-email-address Sep 6, 2026
1eaf529
docs: record track 2 protocol repair roadmap
invalid-email-address Sep 6, 2026
3c142df
fix(chat): preserve JSON completion semantics in streamed delivery
invalid-email-address Sep 6, 2026
9bc4dce
fix(chat): finalize projected JSON once and count append bytes increm…
invalid-email-address Sep 6, 2026
723e59e
fix(chat): enforce per-call budgets in buffered projection [skip ci]
invalid-email-address Sep 6, 2026
2aac0b6
fix(catalog): bound proven native custom reasoning efforts [skip ci]
invalid-email-address Sep 6, 2026
73f1d2c
fix(chat): preserve refusal across completion projections
invalid-email-address Sep 6, 2026
4d982ab
feat(claude): gate translated Messages with a conservative compatibil…
invalid-email-address Sep 6, 2026
fd10390
test(chat): register refusal regression coverage
invalid-email-address Sep 6, 2026
3ff52b3
test(claude): register compatibility policy coverage
invalid-email-address Sep 6, 2026
660967b
fix(chat): constrain sparse refusal identities across output positions
invalid-email-address Sep 6, 2026
4255bfa
fix(test): place compatibility test in the explicit layout inventory …
invalid-email-address Sep 6, 2026
14ee44b
fix(chat): validate known refusal IDs in sparse moved snapshots [skip…
invalid-email-address Sep 6, 2026
d17d323
fix(responses): classify incomplete quota terminals [skip ci]
invalid-email-address Sep 6, 2026
17b1899
fix(compact): preserve progress and accepted request lifetime [skip ci]
invalid-email-address Sep 6, 2026
c8f438b
fix(responses): preserve precommit WebSocket refusals [skip ci]
invalid-email-address Sep 6, 2026
bf94d8d
fix(responses): expose bounded recovery refusal reasons [skip ci]
invalid-email-address Sep 6, 2026
7c6fc74
test(windows): budget quota restart process startup [skip ci]
invalid-email-address Sep 6, 2026
8f30fe0
Merge refreshed lower layer for final track 3 CI [skip ci]
invalid-email-address Sep 6, 2026
5e97d5e
Merge refreshed lower layer for final track 3 CI [skip ci]
invalid-email-address Sep 6, 2026
5fd9b31
Merge refreshed lower layer for final track 3 CI [skip ci]
invalid-email-address Sep 6, 2026
82b0252
Merge refreshed lower layer for final track 3 CI [skip ci]
invalid-email-address Sep 6, 2026
517e8df
Merge refreshed lower layer for final track 3 CI [skip ci]
invalid-email-address Sep 6, 2026
1cbb177
Merge refreshed lower layer for final track 3 CI [skip ci]
invalid-email-address Sep 6, 2026
0f8936b
test(windows): retain an owned module cache in composed fixtures [ski…
invalid-email-address Sep 6, 2026
fcf0744
Merge pull request #3791: preserve incomplete quota attribution [skip…
lidge-jun Sep 6, 2026
823ffeb
Merge pull request #3792: preserve compaction progress and deadlines …
lidge-jun Sep 6, 2026
110623e
Merge pull request #3793: preserve WebSocket refusal status [skip ci]
lidge-jun Sep 6, 2026
eff908e
Merge pull request #3794: expose bounded recovery reasons [skip ci]
lidge-jun Sep 6, 2026
d682e06
Merge current integration base into track 3 [skip ci]
invalid-email-address Sep 6, 2026
b6d3626
Merge current integration base into track 3 [skip ci]
invalid-email-address Sep 6, 2026
1f83fc6
Merge current integration base into track 3 [skip ci]
invalid-email-address Sep 6, 2026
cc7568a
Merge current integration base into track 3 [skip ci]
invalid-email-address Sep 6, 2026
d760f66
Merge current integration base into track 3 [skip ci]
invalid-email-address Sep 6, 2026
9ea8967
Merge current integration base into track 3 [skip ci]
invalid-email-address Sep 6, 2026
4ce1b8f
test: clean composed fixture on cache setup failure [skip ci]
invalid-email-address Sep 6, 2026
bd6b367
Merge current dev for track2 final integration [skip ci]
invalid-email-address Sep 6, 2026
c7a96b1
test: allocate Windows competing OFF preparation separately [skip ci]
invalid-email-address Sep 6, 2026
4397079
fix(storage): publish cleanup manifests atomically (#3786) [skip ci]
lidge-jun Sep 6, 2026
ad5285e
fix(container): persist Codex home separately (#3788) [skip ci]
lidge-jun Sep 6, 2026
26fa364
docs(skill): keep plaintext keys out of agent recipes (#3789) [skip ci]
lidge-jun Sep 6, 2026
c2b4dc0
fix(diagnostics): distinguish spill ACL timeout origins (#3790) [skip…
lidge-jun Sep 6, 2026
443310e
fix(config): add exclusive initial configuration publication (#3796) …
lidge-jun Sep 6, 2026
f89b815
fix(cli): preserve existing config during setup (#3802) [skip ci]
lidge-jun Sep 6, 2026
4a75971
test: own Windows shim advisory process deadline [skip ci]
invalid-email-address Sep 6, 2026
ac4a765
Merge pull request #3803: preserve Chat JSON streaming semantics [ski…
lidge-jun Sep 6, 2026
0a4e4bc
Merge pull request #3804: bound proven custom reasoning efforts [skip…
lidge-jun Sep 6, 2026
eccbdc4
Merge pull request #3805: preserve Chat refusal semantics [skip ci]
lidge-jun Sep 6, 2026
9dc8988
Merge current dev with verified track2 integration tree [skip ci]
invalid-email-address Sep 6, 2026
5759d9e
Merge pull request #3808: integrate Claude compatibility and Windows …
lidge-jun Sep 6, 2026
cf9f662
docs(credits): record four-track contributor attribution (#3811) [ski…
lidge-jun Sep 6, 2026
bcdf559
chore(release): promote validated 2.45.0 to main [skip ci]
invalid-email-address Sep 6, 2026
b0900e5
chore(release): promote 2.45.0 to main (#3813)
lidge-jun Sep 6, 2026
8ffd675
sync: resolve upstream v2.45.0 conflicts and preserve fork hotspots
cursoragent Sep 6, 2026
f91d071
sync(quota): restore upstream canonical Antigravity quota URL helpers
cursoragent Sep 6, 2026
674d582
sync(gui): restore fork GUI from dev pending upstream API re-fit
cursoragent Sep 6, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
908 changes: 484 additions & 424 deletions .github/workflows/ci.yml

Large diffs are not rendered by default.

10 changes: 7 additions & 3 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -363,9 +363,13 @@ keeps the PR a draft.
Authors with repository push permission skip the ancestry heuristic only. As with approval requirements in
[`MAINTAINERS.md`](./MAINTAINERS.md), the ancestry heuristic is a CI check
rather than a branch rule. The branches themselves are protected: `dev`,
`main`, and `preview` each carry an active ruleset requiring a reviewed pull
request and blocking force-pushes and deletion, so a direct push to `dev` is
rejected regardless of `--no-verify`.
`main`, and `preview` each require a pull request and block force-pushes and deletion.
For `dev` only, a current maintainer with GitHub `maintain` or `admin` access may
explicitly integrate through a PR without another maintainer approval, including
their own PR, under the policy in `MAINTAINERS.md`. Record the decision and exact-head
CI evidence; keep outstanding maintainer objections and security review separate.
The bypass is PR-only, so a direct push to `dev` remains rejected regardless of
`--no-verify`. Contributor review and `main`/`preview` rules remain unchanged.

[`MAINTAINERS.md`](./MAINTAINERS.md) is authoritative for review and merge
policy (approvals, CI requirements, security review, promotion). This file
Expand Down
149 changes: 147 additions & 2 deletions CREDITS.md

Large diffs are not rendered by default.

15 changes: 8 additions & 7 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ RUN cd gui && bun install --frozen-lockfile

COPY --chown=bun:bun src ./src
COPY --chown=bun:bun scripts/model-metadata.source.json ./scripts/model-metadata.source.json
COPY --chown=bun:bun docker/bootstrap-tls.ts docker/bootstrap-token.ts docker/config.json docker/healthcheck.ts docker/verify-compatibility.ts ./docker/
COPY --chown=bun:bun docker ./docker
COPY --chown=bun:bun gui ./gui
RUN cd gui && bun run build

Expand All @@ -27,9 +27,11 @@ WORKDIR /home/bun/app

ENV NODE_ENV=production \
OPENCODEX_HOME=/home/bun/.opencodex \
CODEX_HOME=/home/bun/.codex \
OCX_API_TOKEN_FILE=/home/bun/.opencodex/service-api-token

RUN install -d -m 0700 -o bun -g bun /home/bun/.opencodex
# These homes have incompatible auth.json formats; persist them without combining them.
RUN install -d -m 0700 -o bun -g bun /home/bun/.opencodex /home/bun/.codex
COPY --chown=bun:bun --chmod=0600 docker/config.json /home/bun/.opencodex/config.json

COPY --from=build --chown=bun:bun /home/bun/app/package.json ./package.json
Expand All @@ -44,13 +46,12 @@ COPY --from=build --chown=bun:bun /home/bun/app/docker ./docker
COPY --from=build --chown=bun:bun /home/bun/app/gui/dist ./gui/dist

USER bun
RUN ["bun", "docker/verify-compatibility.ts", "--runtime"]
RUN ["bun", "docker/verify-compatibility.ts"]
RUN ["bun", "-e", "import { readOpenCodexCompatibilityVersion } from './src/routing/compatibility/version.ts'; if (!/^[0-9a-f]{64}$/.test(readOpenCodexCompatibilityVersion() ?? '')) throw new Error('Missing or invalid generated compatibility manifest');"]
RUN ["/usr/bin/openssl", "version"]
VOLUME ["/home/bun/.opencodex"]
VOLUME ["/home/bun/.opencodex", "/home/bun/.codex"]
EXPOSE 10100

HEALTHCHECK --interval=30s --timeout=5s --start-period=20s --retries=3 \
CMD ["bun", "docker/healthcheck.ts"]
CMD ["bun", "-e", "const r=await fetch('http://127.0.0.1:10100/healthz');if(!r.ok)process.exit(1)"]

CMD ["sh", "-c", "bun run docker/bootstrap-tls.ts && exec bun run src/cli/index.ts start --port 10100"]
CMD ["bun", "run", "src/cli/index.ts", "start", "--port", "10100"]
100 changes: 63 additions & 37 deletions MAINTAINERS.md
Original file line number Diff line number Diff line change
@@ -1,26 +1,21 @@
# Maintainers

This document lists the people responsible for maintaining the `yansigit/opencodex` fork and
defines its review and merge policy.
This document lists the people responsible for maintaining opencodex and defines the project's
review and merge policy.

## Current maintainers

| GitHub account | Project role | Responsibilities |
| --- | --- | --- |
| [@yansigit](https://github.com/yansigit) | Fork owner | Fork direction, `dev` integration, releases, repository administration, security review, and final governance decisions |
| [@lidge-jun](https://github.com/lidge-jun) | Project owner | Project direction, releases, repository administration, and final governance decisions |
| [@Ingwannu](https://github.com/Ingwannu) | Maintainer | Issue and pull-request triage, `dev` integration, security review, and repository maintenance |

The table describes project responsibilities. Actual repository permissions remain controlled
through GitHub repository settings.

`dev` is the only integration line. The former `dev2-go` carry duty is retired;
see [The retired `dev2-go` line](#the-retired-dev2-go-line).

## Upstream contacts

[@lidge-jun](https://github.com/lidge-jun) and
[@Ingwannu](https://github.com/Ingwannu) maintain the upstream project. Their approval is not
required for changes made only in this fork.

## Former maintainers

| GitHub account | Project role | Period |
Expand Down Expand Up @@ -56,12 +51,20 @@ when a maintainer steps down.
start repository CI; a maintainer has to — so the gate never disproves it;
a new push still resets every box. A disproved claim unticks the matching
box and keeps the PR a draft.
Authors with repository push permission skip the contributor-readiness
checklist. Branch and quality failures still apply.
- Contributor pull requests require successful required CI checks and exact controller authorization;
generic maintainer approval is not a merge prerequisite.
- The fork owner may merge their own pull requests or push directly. An explicit owner request is
sufficient authorization; no upstream or second-maintainer approval is required.
Authors with repository push permission skip the ancestry heuristic only. As
with the approval requirement above, this part is enforced by convention;
the ruleset does not check ancestry (see the note under the change log).
- Pull requests require successful required CI checks before merge. Contributor pull requests
normally require approval from at least one maintainer other than the author.
- A current maintainer with GitHub `maintain` or `admin` access may explicitly integrate a pull
request into `dev` without another maintainer's approval, including their own pull request.
Record that choice and the exact-head verification in the pull-request description or comment.
This is maintainer integration, not a self-approval or an independent review. Outstanding
maintainer change requests must still be resolved or explicitly withdrawn. Technical review,
attribution, documentation and security-review duties remain in force.
- The maintainer-integration exception applies only to `dev`. It does not change review rules
for `main` or `preview`, grant contributor authors approval authority, or permit direct pushes,
force-pushes or branch deletion. Authors do not submit approving reviews of their own work.
- Authentication, credential handling, GitHub Actions, release automation, dependency installation,
and other security-boundary changes require explicit security review.
- A new or promoted provider preset is a credential-destination change. Before merge it needs the
Expand All @@ -73,19 +76,34 @@ when a maintainer steps down.
with the service is disclosed, not disqualifying, and it does not lower the evidence bar. When the
evidence is incomplete, prefer an inert `src/providers/free-directory.ts` reference row over a
canonical registry entry.
- Security-sensitive and release-related changes should receive additional review when practical;
upstream approval is not required for fork-only work.
- Required CI and documentation checks apply to owner merges and direct pushes.
- Required merge checks are `ci`, `hygiene`, `enforce-target`, and `mergeable`, bound to the trusted check App where supported. Autonomous sync requires exact published-head provenance and no handoff, protected path, ownership conflict, or agent resolution. Jules controller advances require recorded parents `[previous Jules head, current dev]`; active editing blocks them. Holds older than 24 hours are summarized and never removed automatically.
- Promotion from `dev` to `main` and npm releases is controlled by the fork owner.
- Post-release version advancement has one writer: `promote-dev.yml` verifies the
published tag and exact release SHA, then advances `dev` through the repository
App. `dev-version-bump.yml` remains a dormant fallback and must not become a
second live authority.
- Opening a preview for the next core ends the current patch line. After
- Security-sensitive and release-related changes should be reviewed by both maintainers when
practical.
- Integration uses pull requests, including urgent maintainer repairs. The PR-only ruleset
bypass does not authorize direct pushes; incident changes to branch protection require a
separate owner decision.
- Promotion from `dev` to `main` and npm releases is maintainer-controlled.
- **Opening a release starts by moving `dev`'s version line forward.** Before cutting
a release, `dev` must already outrank the version being released; `release.yml`
asserts this and refuses to publish otherwise. Dispatch
`.github/workflows/dev-version-bump.yml` with the intended version, merge the pull
request it opens, then promote and release. When `dev` already outranks the target
— a preview cut, or a stable hotfix below `dev`'s line — no move is needed and the
workflow reports `changed=false`.

Opening a preview for the next core ends the current patch line. After
`vX.Y.0-preview.*` is tagged, a fix ships as part of `X.Y.0`, not as
`X.(Y-1).(Z+1)`. The release helper refuses that lower stable patch instead
of publishing a version already outranked by the repository's release line.
`X.(Y-1).(Z+1)`. The release helper refuses such a bump rather than producing a
version the repository would reject. This is a deliberate policy restriction, not
a claim that lower stable patches were historically unused.

Done after the publish, as this repository did for ten releases (`32529c2b2`,
`e4a85d134`, `076ad3036`, `befcac3e1`, then #3045, #3076, #3127, #3265, #3354,
#3434), it leaves `dev` and every open pull request carrying a failure contributors
cannot fix from their own diff. The pull request itself does not go away — `Protect
dev` requires a reviewed merge. If the pre-move is missed and publication somehow
succeeds, dispatch `dev-version-bump.yml` from the default branch with the released
version and `mode=repair`, then merge the repair pull request. Design:
`devlog/_plan/260904_release_version_line/`.

## The retired `dev2-go` line

Expand Down Expand Up @@ -114,15 +132,24 @@ defects. Bun-native TypeScript on `dev` is the single runtime line again.

Adding or removing a maintainer requires:

1. agreement from the fork owner,
1. agreement from the project owner,
2. review by another current maintainer when available, and
3. updates to this file and [`.github/CODEOWNERS`](./.github/CODEOWNERS).

### Change log

- 2026-08-28 — [@yansigit](https://github.com/yansigit) recorded as owner and sole current
maintainer of this fork. Upstream maintainers remain credited as upstream contacts but are not
required approvers for fork-only work.
- 2026-09-06 — The owner authorized explicit maintainer integration into `dev` without a second
maintainer approval. Both current maintainers have `admin` access. The dev-only PR bypass
includes GitHub's `admin` and `maintain` roles; `write` access alone is insufficient. Contributor
review remains the default and the `main`/`preview` rules are unchanged. The optional
`scripts/ci/assert-mergeable-review.sh --maintainer-integration <pr-number> [repo]` path checks
the authenticated actor against the trusted `dev` roster and live repository permissions,
preserves outstanding maintainer objections, and binds its result to the current head and base.
The helper emits a validation snapshot, not a ready-to-run privileged merge command: head
matching does not pin a PR's base, which may change after inspection. Revalidate the current
actor and `dev` base before a separately authorized merge. The helper is not proof of CI or
security review and not a barrier against an administrator bypassing it. Repository settings
remain authoritative for actual permissions.

- 2026-08-19 — [@Wibias](https://github.com/Wibias) stepped down as a maintainer
and is now a contributor. This follows his own decision to stop developing
Expand Down Expand Up @@ -171,12 +198,11 @@ Adding or removing a maintainer requires:
changes, and it blocks deletion and non-fast-forward pushes. Allowed merge
methods are merge and squash; rebase merges are off.

The one carve-out is that the `maintain`/`admin` repository role holds a
`pull_request` bypass, so an owner can merge without the approval the rules
otherwise require. That is a bypass, not an exemption: "Authors do not approve
their own pull requests" above still governs, and an owner who uses the bypass
should record it on the pull request rather than leave it to be inferred from
a merge timestamp. Widening the security boundary is a separate decision.
At that time, the actual PR bypass covered `admin`; the earlier wording that
included `maintain` was inaccurate. The 2026-09-06 policy above adds the explicit
maintainer-integration exception for `dev` and the corresponding `maintain` role.
Both roles bypass through pull requests only. Force-push and deletion protections
remain in place, and the integrating maintainer records the decision and evidence.

## Security reports

Expand Down
Loading
Loading