Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 15 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,24 +6,38 @@ All notable changes to codexclaw are documented here. The format follows

## [Unreleased]

## [0.2.40] - 2026-09-29

### Added

- Codex Desktop sometimes starts threads created by `create_thread` with on-request approvals even when the user's config is full access (openai/codex #33282). A SessionStart advisory now tells the model and the user when an agent-created thread starts that way. An opt-in PermissionRequest hook (`permissions.agentCreatedThreadAutoAllow: true` in `~/.codexclaw/config.json`, off by default) answers those threads' approval prompts, including one-time network requests, only when the user's top-level `config.toml` sets `approval_policy = "never"` and `sandbox_mode = "danger-full-access"`; it never changes the thread's sandbox, never denies, and ignores project-local config. Two new hooks (31 total) need trust approval after upgrade.
- Dispatch guidance: for bounded worktree lanes a full-access coordinator can create a managed worktree and hand a subagent that path as its shell `workdir`, which keeps the coordinator's permission; workers may keep an optional `PROGRESS.md` checkpoint so a replacement can resume from files (#265, guidance only).
- `CODEXCLAW_PABCD=off` (or `on`) and project `codexclaw.json` `{"pabcd": {"enabled": false}}` turn the PABCD hook policy off while keeping the worktree, memory-write, automation-ownership and apply_patch lint guards and recall active. A recognized environment value wins over the project file in both directions (#252).
- When codexclaw creates a project's `.codexclaw` folder, it also writes `.codexclaw/.gitignore` so session state, ledgers and evidence stay out of git; user-authored `rules/*.md` stay committable unless an ancestor ignore rule hides the folder. Existing `.codexclaw` folders are never modified. Lazy creation of session state is deferred (#255, partial).
- Dispatch packets can declare each verifier's write effects (`verifierEffects`), and a pure `verifierPreflight(packet)` reports which verifiers need an isolated copy: under a shared-read packet only a verifier declared read-only runs in the shared tree. Nothing executes a command (#277).
- Interview assumptions carry their source, confidence, consequence if wrong and a status (`proposed`, `open`, `user_confirmed`, `user_rejected`); confirmed and rejected entries need an answer reference, and the plan keeps open assumptions apart from confirmed requirements and rejected ones (INTERVIEW-ASSUME-01, guidance only, #275).

### Changed

- Goalplans can record pending user decisions: `cxc loop ask --session <id> --id <q> --question <text> [--recommendation <text>] [--work-phase <id>]...` links a question the agent already asked to the phases that wait on it, and `cxc loop decide --session <id> --id <q> --answer <text>` records the answer. Linked phases are not runnable while the decision is open; unrelated phases stay ready. When every remaining phase and unmet criterion waits on an open decision, the Stop hook lets an IDLE turn end instead of asking to start another phase; the goal stays active and cannot be completed early. Old plans load unchanged (#262).
- Goalplans can record pending user decisions: `cxc loop ask --session <id> --id <q> --question <text> [--recommendation <text>] [--work-phase <id>]...` links a question the agent already asked to the phases that wait on it, and `cxc loop decide --session <id> --id <q> --answer <text>` records the answer. Linked phases are not runnable while the decision is open; unrelated phases stay ready. When every remaining phase and unmet criterion waits on an open decision, the Stop hook lets an IDLE turn end instead of asking to start another phase; the goal stays active and cannot be completed early. Old plans load unchanged (#262). `cxc loop ask` also takes a repeatable `--option <text>`; when options are given the recommendation must be one of them, the answer stays free text, and `ready --json` and `show` list them.
- The absolute Stop continuation cap (24) now counts per genuine user turn instead of per session, and the release prints one notice per turn (#254).

### Fixed

- A dispatch receipt satisfies its packet only when every required verifier command has a matching result with exit 0 and, when commands are required, no result names another command. Receipts can report `verifierResults[]`; a single legacy `verifierResult` for a multi-command packet reports incomplete (#276).
- Ordinary words (for example "interview", "keep going until", "끝까지 진행해", quoted or fenced examples) no longer inject PABCD phase directives or arm the loop; hints need an explicit codexclaw request such as `cxc-pabcd` or `cxc-loop` (#250).
- The SubagentStop evidence gate no longer blocks Codex's built-in `worker` outside an active PABCD build or check cycle; registered `executor` stays gated while PABCD is on (#251).
- An active native goal without a bound goalplan no longer blocks Stop at IDLE (#253).

### Compatibility

- `receiptSatisfiesPacket` is stricter (#276): a receipt whose one result names a different command than the packet's, even cosmetically (`npm run test` vs `npm test`), no longer satisfies; extra passing checks belong in `commandsRun`. `validateReceipt` now checks the verifier result shapes and `validatePacket` rejects blank or non-string verifier commands.
- Builds older than 0.2.40 drop a goalplan decision's `options` if they rewrite the plan; no schema-version bump signals the new key.
- The two hooks added in this release (31 total) need trust approval after upgrade.

### Verification

- 3737 tests, 0 failures (`npm test`); `gate.mjs`, inventory and `platform-smoke.mjs` pass. Hosted CI and the packed-install lifecycle passed on every merged pull request (#269-#272, #278-#280).

## [0.2.39] - 2026-09-24

Expand Down
2 changes: 1 addition & 1 deletion cli/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@codexclaw/cli",
"version": "0.2.39",
"version": "0.2.40",
"private": true,
"type": "module",
"description": "codexclaw CLI \u2014 status, subagent config, provider toggle, GUI launcher.",
Expand Down
6 changes: 6 additions & 0 deletions devlog/_plan/260930_issue_train/030_wp5_decision_options.md
Original file line number Diff line number Diff line change
Expand Up @@ -180,3 +180,9 @@ Built at `355afde3` per the file map (1a-1d, 2a-2h, docs 5), plus seven tests (s
C round 1 on `0c0ae34f`: fresh implementation reviewer `01a0ee5f-7c4f` PASS (four Low findings), initiative verifier `01a0ee5f-7d90` GO-WITH-FIXES (4, all procedural: finished gate, hosted CI, independent review verdict, goalplan records); the initiative verifier also reproduced the red/green counts in an isolated `git archive`-style export (35/6 red, 41/0 green). C gate on `0c0ae34f`: 3737 tests, 0 failures, inventory, gate, smoke, hook diff 0. Folded: assertions (no new tests, count stays 3737) for `show` with options and no recommendation, `ready --json` without options, the exact `unknown flag '--option` error, and the `--option=value` form; `async-questions.md:56` now says "recommended first by convention".

Residual for the wp4 CHANGELOG: builds older than this one rebuild decisions field by field and drop `options` if they rewrite the plan (no schema-version bump signals the key). Criterion c-10 is linked to wp5 by its text (work-phase `criteriaIds` are empty in this goalplan); #262 entered through the objective's "worthwhile improvements among the open issues" outcome, not its enumerated Scope IN list.

## wp5 D summary (2026-09-30)

Conclusion: the #262 options half is merged into `dev` through PR #280 (head `7e4b90a3`, 14/14 checks, merge `99c9df6a`); #262 stays open for `withdrawn`. Evidence: red 6/41 on the `58a8a174` source (reproduced independently), 41/41 on the new source, C gate on the final head (3737 tests, 0 failures). Next: wp4 delivers per 040.

What did not go well: the first test set left two rendering branches unobserved and asserted a parse error too loosely; the red check swapped tracked files in place in a shared tree, which worked but is riskier than an export. The downgrade residual (older builds drop `options` on rewrite) was found only at C. Evidence that the direction is wrong: users need `withdrawn` or answer-to-option linking more than option lists, which would show up as `decide` answers that repeat an option verbatim.
28 changes: 28 additions & 0 deletions devlog/_plan/260930_issue_train/040_wp4_delivery.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,3 +38,31 @@ The installed plugin cache and remote hosts are not updated by this train (goal
## Acceptance

All goalplan criteria met with captured evidence; `cxc loop validate` passes; v0.2.40 is the latest release and its assets verify.

## wp4 P revalidation and executable amendment (2026-09-30)

Continuity (LOOP-CONTINUITY-01), quoting the wp5 D summary in 030: "the #262 options half is merged ... Next: wp4 delivers per 040." State at entry: `origin/dev` = `99c9df6a` with PRs #278 (`069a7d0e`), #279 (`58a8a174`), #280 (`99c9df6a`) merged after 14/14 checks on their heads; `main` = `8e6aa800` (v0.2.39); no v0.2.40 tag or release exists. Branch `codex/release-0240` from `99c9df6a`. No architect consultation: this phase makes no design decisions (the 0927 train's wp5 precedent); the A reviewers cover the steps.

Resource bounds (disclosed gap): the release is C4 and the initiative's loop-engineering rule asks for a token and wall-clock bound; the user authorized push, merge to `dev` and `main`, and release on 2026-09-30 without stating one, so none is invented. Stop conditions instead: any red check on an exact head, a release dry run that is not READY, or an asset mismatch halts delivery with the state reported.

### Version edits (re-verified with the `rg` in step 2 at `99c9df6a`)

`0.2.39` -> `0.2.40` in `package.json`, `cli/package.json`, `plugins/codexclaw/gui/package.json`, the nine `plugins/codexclaw/components/*/package.json`, and the 13 `"version": "0.2.39"` entries in `package-lock.json` (root and workspace entries). `plugins/codexclaw/.codex-plugin/plugin.json`: `"version": "0.2.40+codex.<UTC yyyymmddHHMMSS at commit>"`. `inventory.json` component versions and README badges via `inventory.mjs --write --tests 3737`. `pabcd-state/test/hook.test.ts:181` contains `0.2.39` only inside a fixture cache path; it stays.

### CHANGELOG diff

`## [Unreleased]` becomes `## [0.2.40] - 2026-09-30`, a fresh empty `## [Unreleased]` goes above it, and these lines join the existing sections:

- Added: "Dispatch packets can declare each verifier's write effects (`verifierEffects`), and a pure `verifierPreflight(packet)` reports which verifiers need an isolated copy: under a shared-read packet only a verifier declared read-only runs in the shared tree. Nothing executes a command (#277)."
- Added: "Interview assumptions carry their source, confidence, consequence if wrong and a status (`proposed`, `open`, `user_confirmed`, `user_rejected`); confirmed and rejected entries need an answer reference, and the plan keeps open assumptions apart from confirmed requirements and rejected ones (INTERVIEW-ASSUME-01, guidance only, #275)."
- Changed (extend the existing #262 bullet): "`cxc loop ask` also takes a repeatable `--option <text>`; when options are given the recommendation must be one of them, the answer stays free text, and `ready --json` and `show` list them. Builds older than 0.2.40 drop `options` if they rewrite such a plan."
- Fixed: "A dispatch receipt satisfies its packet only when every required verifier command has a matching result with exit 0 and, when commands are required, no result names another command. Receipts can report `verifierResults[]`; a single legacy `verifierResult` for a multi-command packet reports incomplete. `validateReceipt` now checks the result shapes and `validatePacket` rejects blank or non-string verifier commands; a receipt whose one result names a different command, even cosmetically, no longer satisfies (#276)."

### Issue comments (wording)

- #276, #277, #275: "Fixed in #278/#279 (merged into `dev` as <sha>) and released in v0.2.40." closed as completed.
- #262: "Options shipped in #280 (`ask --option`, recommendation must be one of them, answers stay free text). `withdrawn` still needs a decision on how a withdrawn question releases its linked phases, so this stays open."
- Not planned (#209, #213, #247, #258, #259, #263, #264, #265, #266, #267, #268): the reason line from 001 and "Closing as not planned in the 2026-09-30 issue train: codexclaw is keeping its hook surface small, and this needs <a new hook | a host signal the plugin cannot observe | nothing further on the plugin side>." plus the link to 001 on `dev`.
- Kept open (#255, #256, #257, #260, #273, #274): the reason line from 001 and the link.

Order: issue comments and closes run after the release so "released in v0.2.40" is true.
26 changes: 13 additions & 13 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "codexclaw",
"version": "0.2.39",
"version": "0.2.40",
"private": true,
"description": "cli-jaw-style dev discipline + multi-model subagents for the OpenAI Codex runtime.",
"type": "module",
Expand Down
2 changes: 1 addition & 1 deletion plugins/codexclaw/.codex-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "codexclaw",
"version": "0.2.39+codex.20260924082502",
"version": "0.2.40+codex.20260929183231",
"description": "cli-jaw-style dev discipline (dev skills + PABCD) and multi-model subagents for the OpenAI Codex runtime, with optional opencodex provider routing.",
"author": {
"name": "lidge-jun",
Expand Down
2 changes: 1 addition & 1 deletion plugins/codexclaw/components/bg-wake/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@codexclaw/bg-wake",
"version": "0.2.39",
"version": "0.2.40",
"private": true,
"type": "module",
"description": "Background task registry + completion wake for Codex. Registers detached commands, then wakes the agent through the Stop hook when they finish.",
Expand Down
2 changes: 1 addition & 1 deletion plugins/codexclaw/components/config-guard/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@codexclaw/config-guard",
"version": "0.2.39",
"version": "0.2.40",
"private": true,
"type": "module",
"description": "Controlled feature-flag activation: enables only codexclaw's declared [features] flags via the official `codex features` CLI, with a revert manifest and backup.",
Expand Down
2 changes: 1 addition & 1 deletion plugins/codexclaw/components/cxc-ops/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@codexclaw/cxc-ops",
"version": "0.2.39",
"version": "0.2.40",
"private": true,
"type": "module",
"description": "codexclaw ops CLI \u2014 doctor (plugin health), reset (scoped state cleanup).",
Expand Down
2 changes: 1 addition & 1 deletion plugins/codexclaw/components/messenger-bridge/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@codexclaw/messenger-bridge",
"version": "0.2.39",
"version": "0.2.40",
"private": true,
"type": "module",
"description": "codexclaw messenger bridge \u2014 cxc serve HTTP server + SQLite state substrate (zero third-party deps).",
Expand Down
2 changes: 1 addition & 1 deletion plugins/codexclaw/components/pabcd-state/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@codexclaw/pabcd-state",
"version": "0.2.39",
"version": "0.2.40",
"private": true,
"type": "module",
"description": "IPABCD finite-state machine backed by per-session .codexclaw/sessions/<sessionId>.json + shared ledger.jsonl.",
Expand Down
2 changes: 1 addition & 1 deletion plugins/codexclaw/components/provider-bridge/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@codexclaw/provider-bridge",
"version": "0.2.39",
"version": "0.2.40",
"private": true,
"type": "module",
"description": "Detect-only opencodex (ocx) status probe at session start; graceful native path when absent.",
Expand Down
2 changes: 1 addition & 1 deletion plugins/codexclaw/components/recall/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@codexclaw/recall",
"version": "0.2.39",
"version": "0.2.40",
"private": true,
"type": "module",
"description": "Read-only chat/memory recall search over the Codex session root (~/.codex): date-pruned rollout scan + thread/memory sqlite enrichment.",
Expand Down
2 changes: 1 addition & 1 deletion plugins/codexclaw/components/skill-search/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@codexclaw/skill-search",
"version": "0.2.39",
"version": "0.2.40",
"private": true,
"type": "module",
"description": "Remote dormant-skill search over cli-jaw-skills / Hermes / ClawHub / gh code search. Zero-dep, TTL-cached, adapter-preamble output. No local vendoring.",
Expand Down
2 changes: 1 addition & 1 deletion plugins/codexclaw/components/subagent-config/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@codexclaw/subagent-config",
"version": "0.2.39",
"version": "0.2.40",
"private": true,
"type": "module",
"description": "Stores subagent model/prompt config; serves it to the GUI and an MCP tool.",
Expand Down
2 changes: 1 addition & 1 deletion plugins/codexclaw/gui/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@codexclaw/gui",
"version": "0.2.39",
"version": "0.2.40",
"private": true,
"type": "module",
"description": "codexclaw local dashboard (Vite + React) \u2014 subagent config, prompts, provider link bar.",
Expand Down
22 changes: 11 additions & 11 deletions plugins/codexclaw/inventory.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,8 +2,8 @@
"schemaVersion": 1,
"plugin": {
"name": "codexclaw",
"manifestVersion": "0.2.39+codex.20260924082502",
"packageVersion": "0.2.39"
"manifestVersion": "0.2.40+codex.20260929183231",
"packageVersion": "0.2.40"
},
"skills": [
{
Expand Down Expand Up @@ -326,55 +326,55 @@
{
"folder": "bg-wake",
"packageName": "@codexclaw/bg-wake",
"version": "0.2.39",
"version": "0.2.40",
"hasTests": true
},
{
"folder": "config-guard",
"packageName": "@codexclaw/config-guard",
"version": "0.2.39",
"version": "0.2.40",
"hasTests": true
},
{
"folder": "cxc-ops",
"packageName": "@codexclaw/cxc-ops",
"version": "0.2.39",
"version": "0.2.40",
"hasTests": true
},
{
"folder": "messenger-bridge",
"packageName": "@codexclaw/messenger-bridge",
"version": "0.2.39",
"version": "0.2.40",
"hasTests": true
},
{
"folder": "pabcd-state",
"packageName": "@codexclaw/pabcd-state",
"version": "0.2.39",
"version": "0.2.40",
"hasTests": true
},
{
"folder": "provider-bridge",
"packageName": "@codexclaw/provider-bridge",
"version": "0.2.39",
"version": "0.2.40",
"hasTests": true
},
{
"folder": "recall",
"packageName": "@codexclaw/recall",
"version": "0.2.39",
"version": "0.2.40",
"hasTests": true
},
{
"folder": "skill-search",
"packageName": "@codexclaw/skill-search",
"version": "0.2.39",
"version": "0.2.40",
"hasTests": true
},
{
"folder": "subagent-config",
"packageName": "@codexclaw/subagent-config",
"version": "0.2.39",
"version": "0.2.40",
"hasTests": true
}
]
Expand Down
Loading