diff --git a/CHANGELOG.md b/CHANGELOG.md index 0c6d0248..f14ea3f4 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,24 +6,38 @@ All notable changes to codexclaw are documented here. The format follows ## [Unreleased] +## [0.2.40] - 2026-09-29 + ### Added - Codex Desktop sometimes starts threads created by `create_thread` with on-request approvals even when the user's config is full access (openai/codex #33282). A SessionStart advisory now tells the model and the user when an agent-created thread starts that way. An opt-in PermissionRequest hook (`permissions.agentCreatedThreadAutoAllow: true` in `~/.codexclaw/config.json`, off by default) answers those threads' approval prompts, including one-time network requests, only when the user's top-level `config.toml` sets `approval_policy = "never"` and `sandbox_mode = "danger-full-access"`; it never changes the thread's sandbox, never denies, and ignores project-local config. Two new hooks (31 total) need trust approval after upgrade. - Dispatch guidance: for bounded worktree lanes a full-access coordinator can create a managed worktree and hand a subagent that path as its shell `workdir`, which keeps the coordinator's permission; workers may keep an optional `PROGRESS.md` checkpoint so a replacement can resume from files (#265, guidance only). - `CODEXCLAW_PABCD=off` (or `on`) and project `codexclaw.json` `{"pabcd": {"enabled": false}}` turn the PABCD hook policy off while keeping the worktree, memory-write, automation-ownership and apply_patch lint guards and recall active. A recognized environment value wins over the project file in both directions (#252). - When codexclaw creates a project's `.codexclaw` folder, it also writes `.codexclaw/.gitignore` so session state, ledgers and evidence stay out of git; user-authored `rules/*.md` stay committable unless an ancestor ignore rule hides the folder. Existing `.codexclaw` folders are never modified. Lazy creation of session state is deferred (#255, partial). +- Dispatch packets can declare each verifier's write effects (`verifierEffects`), and a pure `verifierPreflight(packet)` reports which verifiers need an isolated copy: under a shared-read packet only a verifier declared read-only runs in the shared tree. Nothing executes a command (#277). +- Interview assumptions carry their source, confidence, consequence if wrong and a status (`proposed`, `open`, `user_confirmed`, `user_rejected`); confirmed and rejected entries need an answer reference, and the plan keeps open assumptions apart from confirmed requirements and rejected ones (INTERVIEW-ASSUME-01, guidance only, #275). ### Changed -- Goalplans can record pending user decisions: `cxc loop ask --session --id --question [--recommendation ] [--work-phase ]...` links a question the agent already asked to the phases that wait on it, and `cxc loop decide --session --id --answer ` records the answer. Linked phases are not runnable while the decision is open; unrelated phases stay ready. When every remaining phase and unmet criterion waits on an open decision, the Stop hook lets an IDLE turn end instead of asking to start another phase; the goal stays active and cannot be completed early. Old plans load unchanged (#262). +- Goalplans can record pending user decisions: `cxc loop ask --session --id --question [--recommendation ] [--work-phase ]...` links a question the agent already asked to the phases that wait on it, and `cxc loop decide --session --id --answer ` records the answer. Linked phases are not runnable while the decision is open; unrelated phases stay ready. When every remaining phase and unmet criterion waits on an open decision, the Stop hook lets an IDLE turn end instead of asking to start another phase; the goal stays active and cannot be completed early. Old plans load unchanged (#262). `cxc loop ask` also takes a repeatable `--option `; when options are given the recommendation must be one of them, the answer stays free text, and `ready --json` and `show` list them. - The absolute Stop continuation cap (24) now counts per genuine user turn instead of per session, and the release prints one notice per turn (#254). ### Fixed +- A dispatch receipt satisfies its packet only when every required verifier command has a matching result with exit 0 and, when commands are required, no result names another command. Receipts can report `verifierResults[]`; a single legacy `verifierResult` for a multi-command packet reports incomplete (#276). - Ordinary words (for example "interview", "keep going until", "끝까지 진행해", quoted or fenced examples) no longer inject PABCD phase directives or arm the loop; hints need an explicit codexclaw request such as `cxc-pabcd` or `cxc-loop` (#250). - The SubagentStop evidence gate no longer blocks Codex's built-in `worker` outside an active PABCD build or check cycle; registered `executor` stays gated while PABCD is on (#251). - An active native goal without a bound goalplan no longer blocks Stop at IDLE (#253). +### Compatibility + +- `receiptSatisfiesPacket` is stricter (#276): a receipt whose one result names a different command than the packet's, even cosmetically (`npm run test` vs `npm test`), no longer satisfies; extra passing checks belong in `commandsRun`. `validateReceipt` now checks the verifier result shapes and `validatePacket` rejects blank or non-string verifier commands. +- Builds older than 0.2.40 drop a goalplan decision's `options` if they rewrite the plan; no schema-version bump signals the new key. +- The two hooks added in this release (31 total) need trust approval after upgrade. + +### Verification + +- 3737 tests, 0 failures (`npm test`); `gate.mjs`, inventory and `platform-smoke.mjs` pass. Hosted CI and the packed-install lifecycle passed on every merged pull request (#269-#272, #278-#280). ## [0.2.39] - 2026-09-24 diff --git a/cli/package.json b/cli/package.json index e10c2d4a..d0fec216 100644 --- a/cli/package.json +++ b/cli/package.json @@ -1,6 +1,6 @@ { "name": "@codexclaw/cli", - "version": "0.2.39", + "version": "0.2.40", "private": true, "type": "module", "description": "codexclaw CLI \u2014 status, subagent config, provider toggle, GUI launcher.", diff --git a/devlog/_plan/260930_issue_train/030_wp5_decision_options.md b/devlog/_plan/260930_issue_train/030_wp5_decision_options.md index 698ba7a1..99662820 100644 --- a/devlog/_plan/260930_issue_train/030_wp5_decision_options.md +++ b/devlog/_plan/260930_issue_train/030_wp5_decision_options.md @@ -180,3 +180,9 @@ Built at `355afde3` per the file map (1a-1d, 2a-2h, docs 5), plus seven tests (s C round 1 on `0c0ae34f`: fresh implementation reviewer `01a0ee5f-7c4f` PASS (four Low findings), initiative verifier `01a0ee5f-7d90` GO-WITH-FIXES (4, all procedural: finished gate, hosted CI, independent review verdict, goalplan records); the initiative verifier also reproduced the red/green counts in an isolated `git archive`-style export (35/6 red, 41/0 green). C gate on `0c0ae34f`: 3737 tests, 0 failures, inventory, gate, smoke, hook diff 0. Folded: assertions (no new tests, count stays 3737) for `show` with options and no recommendation, `ready --json` without options, the exact `unknown flag '--option` error, and the `--option=value` form; `async-questions.md:56` now says "recommended first by convention". Residual for the wp4 CHANGELOG: builds older than this one rebuild decisions field by field and drop `options` if they rewrite the plan (no schema-version bump signals the key). Criterion c-10 is linked to wp5 by its text (work-phase `criteriaIds` are empty in this goalplan); #262 entered through the objective's "worthwhile improvements among the open issues" outcome, not its enumerated Scope IN list. + +## wp5 D summary (2026-09-30) + +Conclusion: the #262 options half is merged into `dev` through PR #280 (head `7e4b90a3`, 14/14 checks, merge `99c9df6a`); #262 stays open for `withdrawn`. Evidence: red 6/41 on the `58a8a174` source (reproduced independently), 41/41 on the new source, C gate on the final head (3737 tests, 0 failures). Next: wp4 delivers per 040. + +What did not go well: the first test set left two rendering branches unobserved and asserted a parse error too loosely; the red check swapped tracked files in place in a shared tree, which worked but is riskier than an export. The downgrade residual (older builds drop `options` on rewrite) was found only at C. Evidence that the direction is wrong: users need `withdrawn` or answer-to-option linking more than option lists, which would show up as `decide` answers that repeat an option verbatim. diff --git a/devlog/_plan/260930_issue_train/040_wp4_delivery.md b/devlog/_plan/260930_issue_train/040_wp4_delivery.md index bc7696c1..a23b23ee 100644 --- a/devlog/_plan/260930_issue_train/040_wp4_delivery.md +++ b/devlog/_plan/260930_issue_train/040_wp4_delivery.md @@ -38,3 +38,31 @@ The installed plugin cache and remote hosts are not updated by this train (goal ## Acceptance All goalplan criteria met with captured evidence; `cxc loop validate` passes; v0.2.40 is the latest release and its assets verify. + +## wp4 P revalidation and executable amendment (2026-09-30) + +Continuity (LOOP-CONTINUITY-01), quoting the wp5 D summary in 030: "the #262 options half is merged ... Next: wp4 delivers per 040." State at entry: `origin/dev` = `99c9df6a` with PRs #278 (`069a7d0e`), #279 (`58a8a174`), #280 (`99c9df6a`) merged after 14/14 checks on their heads; `main` = `8e6aa800` (v0.2.39); no v0.2.40 tag or release exists. Branch `codex/release-0240` from `99c9df6a`. No architect consultation: this phase makes no design decisions (the 0927 train's wp5 precedent); the A reviewers cover the steps. + +Resource bounds (disclosed gap): the release is C4 and the initiative's loop-engineering rule asks for a token and wall-clock bound; the user authorized push, merge to `dev` and `main`, and release on 2026-09-30 without stating one, so none is invented. Stop conditions instead: any red check on an exact head, a release dry run that is not READY, or an asset mismatch halts delivery with the state reported. + +### Version edits (re-verified with the `rg` in step 2 at `99c9df6a`) + +`0.2.39` -> `0.2.40` in `package.json`, `cli/package.json`, `plugins/codexclaw/gui/package.json`, the nine `plugins/codexclaw/components/*/package.json`, and the 13 `"version": "0.2.39"` entries in `package-lock.json` (root and workspace entries). `plugins/codexclaw/.codex-plugin/plugin.json`: `"version": "0.2.40+codex."`. `inventory.json` component versions and README badges via `inventory.mjs --write --tests 3737`. `pabcd-state/test/hook.test.ts:181` contains `0.2.39` only inside a fixture cache path; it stays. + +### CHANGELOG diff + +`## [Unreleased]` becomes `## [0.2.40] - 2026-09-30`, a fresh empty `## [Unreleased]` goes above it, and these lines join the existing sections: + +- Added: "Dispatch packets can declare each verifier's write effects (`verifierEffects`), and a pure `verifierPreflight(packet)` reports which verifiers need an isolated copy: under a shared-read packet only a verifier declared read-only runs in the shared tree. Nothing executes a command (#277)." +- Added: "Interview assumptions carry their source, confidence, consequence if wrong and a status (`proposed`, `open`, `user_confirmed`, `user_rejected`); confirmed and rejected entries need an answer reference, and the plan keeps open assumptions apart from confirmed requirements and rejected ones (INTERVIEW-ASSUME-01, guidance only, #275)." +- Changed (extend the existing #262 bullet): "`cxc loop ask` also takes a repeatable `--option `; when options are given the recommendation must be one of them, the answer stays free text, and `ready --json` and `show` list them. Builds older than 0.2.40 drop `options` if they rewrite such a plan." +- Fixed: "A dispatch receipt satisfies its packet only when every required verifier command has a matching result with exit 0 and, when commands are required, no result names another command. Receipts can report `verifierResults[]`; a single legacy `verifierResult` for a multi-command packet reports incomplete. `validateReceipt` now checks the result shapes and `validatePacket` rejects blank or non-string verifier commands; a receipt whose one result names a different command, even cosmetically, no longer satisfies (#276)." + +### Issue comments (wording) + +- #276, #277, #275: "Fixed in #278/#279 (merged into `dev` as ) and released in v0.2.40." closed as completed. +- #262: "Options shipped in #280 (`ask --option`, recommendation must be one of them, answers stay free text). `withdrawn` still needs a decision on how a withdrawn question releases its linked phases, so this stays open." +- Not planned (#209, #213, #247, #258, #259, #263, #264, #265, #266, #267, #268): the reason line from 001 and "Closing as not planned in the 2026-09-30 issue train: codexclaw is keeping its hook surface small, and this needs ." plus the link to 001 on `dev`. +- Kept open (#255, #256, #257, #260, #273, #274): the reason line from 001 and the link. + +Order: issue comments and closes run after the release so "released in v0.2.40" is true. diff --git a/package-lock.json b/package-lock.json index 21701540..bd3e0112 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "codexclaw", - "version": "0.2.39", + "version": "0.2.40", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "codexclaw", - "version": "0.2.39", + "version": "0.2.40", "license": "MIT", "workspaces": [ "plugins/codexclaw/components/*", @@ -20,7 +20,7 @@ }, "cli": { "name": "@codexclaw/cli", - "version": "0.2.39", + "version": "0.2.40", "bin": { "codexclaw": "bin/codexclaw.mjs" } @@ -1953,43 +1953,43 @@ }, "plugins/codexclaw/components/bg-wake": { "name": "@codexclaw/bg-wake", - "version": "0.2.39" + "version": "0.2.40" }, "plugins/codexclaw/components/config-guard": { "name": "@codexclaw/config-guard", - "version": "0.2.39" + "version": "0.2.40" }, "plugins/codexclaw/components/cxc-ops": { "name": "@codexclaw/cxc-ops", - "version": "0.2.39" + "version": "0.2.40" }, "plugins/codexclaw/components/messenger-bridge": { "name": "@codexclaw/messenger-bridge", - "version": "0.2.39" + "version": "0.2.40" }, "plugins/codexclaw/components/pabcd-state": { "name": "@codexclaw/pabcd-state", - "version": "0.2.39" + "version": "0.2.40" }, "plugins/codexclaw/components/provider-bridge": { "name": "@codexclaw/provider-bridge", - "version": "0.2.39" + "version": "0.2.40" }, "plugins/codexclaw/components/recall": { "name": "@codexclaw/recall", - "version": "0.2.39" + "version": "0.2.40" }, "plugins/codexclaw/components/skill-search": { "name": "@codexclaw/skill-search", - "version": "0.2.39" + "version": "0.2.40" }, "plugins/codexclaw/components/subagent-config": { "name": "@codexclaw/subagent-config", - "version": "0.2.39" + "version": "0.2.40" }, "plugins/codexclaw/gui": { "name": "@codexclaw/gui", - "version": "0.2.39", + "version": "0.2.40", "dependencies": { "react": "^18.3.1", "react-dom": "^18.3.1" diff --git a/package.json b/package.json index 9cf31582..9f815263 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "codexclaw", - "version": "0.2.39", + "version": "0.2.40", "private": true, "description": "cli-jaw-style dev discipline + multi-model subagents for the OpenAI Codex runtime.", "type": "module", diff --git a/plugins/codexclaw/.codex-plugin/plugin.json b/plugins/codexclaw/.codex-plugin/plugin.json index d48e0fbe..ad49a502 100644 --- a/plugins/codexclaw/.codex-plugin/plugin.json +++ b/plugins/codexclaw/.codex-plugin/plugin.json @@ -1,6 +1,6 @@ { "name": "codexclaw", - "version": "0.2.39+codex.20260924082502", + "version": "0.2.40+codex.20260929183231", "description": "cli-jaw-style dev discipline (dev skills + PABCD) and multi-model subagents for the OpenAI Codex runtime, with optional opencodex provider routing.", "author": { "name": "lidge-jun", diff --git a/plugins/codexclaw/components/bg-wake/package.json b/plugins/codexclaw/components/bg-wake/package.json index 9ac8a293..7a34369a 100644 --- a/plugins/codexclaw/components/bg-wake/package.json +++ b/plugins/codexclaw/components/bg-wake/package.json @@ -1,6 +1,6 @@ { "name": "@codexclaw/bg-wake", - "version": "0.2.39", + "version": "0.2.40", "private": true, "type": "module", "description": "Background task registry + completion wake for Codex. Registers detached commands, then wakes the agent through the Stop hook when they finish.", diff --git a/plugins/codexclaw/components/config-guard/package.json b/plugins/codexclaw/components/config-guard/package.json index 2230cb6f..c2399f07 100644 --- a/plugins/codexclaw/components/config-guard/package.json +++ b/plugins/codexclaw/components/config-guard/package.json @@ -1,6 +1,6 @@ { "name": "@codexclaw/config-guard", - "version": "0.2.39", + "version": "0.2.40", "private": true, "type": "module", "description": "Controlled feature-flag activation: enables only codexclaw's declared [features] flags via the official `codex features` CLI, with a revert manifest and backup.", diff --git a/plugins/codexclaw/components/cxc-ops/package.json b/plugins/codexclaw/components/cxc-ops/package.json index 38e952d8..6a7a532c 100644 --- a/plugins/codexclaw/components/cxc-ops/package.json +++ b/plugins/codexclaw/components/cxc-ops/package.json @@ -1,6 +1,6 @@ { "name": "@codexclaw/cxc-ops", - "version": "0.2.39", + "version": "0.2.40", "private": true, "type": "module", "description": "codexclaw ops CLI \u2014 doctor (plugin health), reset (scoped state cleanup).", diff --git a/plugins/codexclaw/components/messenger-bridge/package.json b/plugins/codexclaw/components/messenger-bridge/package.json index 656e39d9..2b5ed058 100644 --- a/plugins/codexclaw/components/messenger-bridge/package.json +++ b/plugins/codexclaw/components/messenger-bridge/package.json @@ -1,6 +1,6 @@ { "name": "@codexclaw/messenger-bridge", - "version": "0.2.39", + "version": "0.2.40", "private": true, "type": "module", "description": "codexclaw messenger bridge \u2014 cxc serve HTTP server + SQLite state substrate (zero third-party deps).", diff --git a/plugins/codexclaw/components/pabcd-state/package.json b/plugins/codexclaw/components/pabcd-state/package.json index 898d370f..9804aa9a 100644 --- a/plugins/codexclaw/components/pabcd-state/package.json +++ b/plugins/codexclaw/components/pabcd-state/package.json @@ -1,6 +1,6 @@ { "name": "@codexclaw/pabcd-state", - "version": "0.2.39", + "version": "0.2.40", "private": true, "type": "module", "description": "IPABCD finite-state machine backed by per-session .codexclaw/sessions/.json + shared ledger.jsonl.", diff --git a/plugins/codexclaw/components/provider-bridge/package.json b/plugins/codexclaw/components/provider-bridge/package.json index e89a28fd..d679a650 100644 --- a/plugins/codexclaw/components/provider-bridge/package.json +++ b/plugins/codexclaw/components/provider-bridge/package.json @@ -1,6 +1,6 @@ { "name": "@codexclaw/provider-bridge", - "version": "0.2.39", + "version": "0.2.40", "private": true, "type": "module", "description": "Detect-only opencodex (ocx) status probe at session start; graceful native path when absent.", diff --git a/plugins/codexclaw/components/recall/package.json b/plugins/codexclaw/components/recall/package.json index 1978765b..25f536e8 100644 --- a/plugins/codexclaw/components/recall/package.json +++ b/plugins/codexclaw/components/recall/package.json @@ -1,6 +1,6 @@ { "name": "@codexclaw/recall", - "version": "0.2.39", + "version": "0.2.40", "private": true, "type": "module", "description": "Read-only chat/memory recall search over the Codex session root (~/.codex): date-pruned rollout scan + thread/memory sqlite enrichment.", diff --git a/plugins/codexclaw/components/skill-search/package.json b/plugins/codexclaw/components/skill-search/package.json index 65726187..c483b427 100644 --- a/plugins/codexclaw/components/skill-search/package.json +++ b/plugins/codexclaw/components/skill-search/package.json @@ -1,6 +1,6 @@ { "name": "@codexclaw/skill-search", - "version": "0.2.39", + "version": "0.2.40", "private": true, "type": "module", "description": "Remote dormant-skill search over cli-jaw-skills / Hermes / ClawHub / gh code search. Zero-dep, TTL-cached, adapter-preamble output. No local vendoring.", diff --git a/plugins/codexclaw/components/subagent-config/package.json b/plugins/codexclaw/components/subagent-config/package.json index f4b74372..292d2a28 100644 --- a/plugins/codexclaw/components/subagent-config/package.json +++ b/plugins/codexclaw/components/subagent-config/package.json @@ -1,6 +1,6 @@ { "name": "@codexclaw/subagent-config", - "version": "0.2.39", + "version": "0.2.40", "private": true, "type": "module", "description": "Stores subagent model/prompt config; serves it to the GUI and an MCP tool.", diff --git a/plugins/codexclaw/gui/package.json b/plugins/codexclaw/gui/package.json index c7a6d32d..ea7b36c8 100644 --- a/plugins/codexclaw/gui/package.json +++ b/plugins/codexclaw/gui/package.json @@ -1,6 +1,6 @@ { "name": "@codexclaw/gui", - "version": "0.2.39", + "version": "0.2.40", "private": true, "type": "module", "description": "codexclaw local dashboard (Vite + React) \u2014 subagent config, prompts, provider link bar.", diff --git a/plugins/codexclaw/inventory.json b/plugins/codexclaw/inventory.json index a468f6e2..d0615024 100644 --- a/plugins/codexclaw/inventory.json +++ b/plugins/codexclaw/inventory.json @@ -2,8 +2,8 @@ "schemaVersion": 1, "plugin": { "name": "codexclaw", - "manifestVersion": "0.2.39+codex.20260924082502", - "packageVersion": "0.2.39" + "manifestVersion": "0.2.40+codex.20260929183231", + "packageVersion": "0.2.40" }, "skills": [ { @@ -326,55 +326,55 @@ { "folder": "bg-wake", "packageName": "@codexclaw/bg-wake", - "version": "0.2.39", + "version": "0.2.40", "hasTests": true }, { "folder": "config-guard", "packageName": "@codexclaw/config-guard", - "version": "0.2.39", + "version": "0.2.40", "hasTests": true }, { "folder": "cxc-ops", "packageName": "@codexclaw/cxc-ops", - "version": "0.2.39", + "version": "0.2.40", "hasTests": true }, { "folder": "messenger-bridge", "packageName": "@codexclaw/messenger-bridge", - "version": "0.2.39", + "version": "0.2.40", "hasTests": true }, { "folder": "pabcd-state", "packageName": "@codexclaw/pabcd-state", - "version": "0.2.39", + "version": "0.2.40", "hasTests": true }, { "folder": "provider-bridge", "packageName": "@codexclaw/provider-bridge", - "version": "0.2.39", + "version": "0.2.40", "hasTests": true }, { "folder": "recall", "packageName": "@codexclaw/recall", - "version": "0.2.39", + "version": "0.2.40", "hasTests": true }, { "folder": "skill-search", "packageName": "@codexclaw/skill-search", - "version": "0.2.39", + "version": "0.2.40", "hasTests": true }, { "folder": "subagent-config", "packageName": "@codexclaw/subagent-config", - "version": "0.2.39", + "version": "0.2.40", "hasTests": true } ]