Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
200 commits
Select commit Hold shift + click to select a range
9e8529b
fix(security): require pairing for child link join
luvs01 Sep 27, 2026
232fc74
merge: retain paired-only join and align its route inventory
luvs01 Sep 28, 2026
4fbad2b
fix(security): add explicit bounded standalone GUI pairing for link join
luvs01 Sep 29, 2026
4aea69c
Merge latest dev into standalone link pairing fix
luvs01 Oct 1, 2026
1a20825
fix(link): explain dashboard join denial causes
luvs01 Oct 1, 2026
b4616be
chore(release): open dev at 2.77.0 before releasing 2.76.0 (#6462)
github-actions[bot] Oct 2, 2026
4b74668
fix(gui): remove blank tail from account-page scrolling (#6475)
lidge-jun Oct 3, 2026
11bbc17
docs(providers): update TokenLab documentation links (carry #6474)
lidge-jun Oct 3, 2026
f5572a0
fix(chatgpt): recognize snake-case quota usage windows (carry #6463)
lidge-jun Oct 3, 2026
763dda2
fix(cli): escape terminal controls in human output (carry #6459)
lidge-jun Oct 3, 2026
1097556
fix(providers): declare MiniMax M3 image input for combos (carry #6445)
lidge-jun Oct 3, 2026
6d4e404
fix(gui): queue optimistic model visibility saves (carry #6426)
lidge-jun Oct 3, 2026
b0b884b
fix(desktop): quote Windows login executable paths (carry #6479)
lidge-jun Oct 3, 2026
1ad42a7
fix(update): resolve Scoop Node npm from user home (carry #6119)
lidge-jun Oct 3, 2026
9f5194c
fix(service): keep backup names out of cmd logging (carry #6455)
lidge-jun Oct 3, 2026
9d3e6e2
feat(usage): aggregate end-to-end output throughput (carry #6471)
lidge-jun Oct 3, 2026
26755d9
fix(claude): clean legacy picker keys before prechecks (carry #6457)
lidge-jun Oct 3, 2026
00c69c3
fix(update): recognize bindable stopped endpoints (carry #6477)
lidge-jun Oct 3, 2026
b2d27e3
fix(clients): read role mirrors through nonblocking descriptors (carr…
lidge-jun Oct 3, 2026
8efd79c
fix(claude): register subagents after first-party setup (#6484)
lidge-jun Oct 3, 2026
4ef04ff
fix(codex): stabilize fnm shims and report connect readiness (carry #…
lidge-jun Oct 3, 2026
7625014
fix(grok): forward the Grok conversation as session_id so OpenAI pref…
lidge-jun Oct 3, 2026
c294e58
feat(desktop): remember zoom with sidebar controls (carry #6335)
lidge-jun Oct 3, 2026
a85a437
fix(web-search): retain forced-answer tool declarations (carry #6470)
lidge-jun Oct 3, 2026
ce0e767
fix(cursor): preserve structured final-output contracts (carry #6417)
lidge-jun Oct 3, 2026
60ed4c6
fix(responses): preserve opted-in launcher replay metadata (carry #6254)
lidge-jun Oct 3, 2026
7ccc592
feat(responses): forward explicitly selected safe client headers (car…
lidge-jun Oct 3, 2026
2abd734
fix(logs): measure decode rate over observed generation (carry #6416)
lidge-jun Oct 3, 2026
2753ef9
fix(sse): align event framing before tool validation (carry #6461)
lidge-jun Oct 3, 2026
ce87c68
fix(combos): enforce API-key scope on decision providers (carry #6450)
lidge-jun Oct 3, 2026
f548303
fix(claude): bound picker catalog row expansion (carry #6449)
lidge-jun Oct 3, 2026
1108236
fix(responses): bound hosted image display expansion (carry #6451)
lidge-jun Oct 3, 2026
dbed9c7
fix(zed): bound buffered translation and cancel delegated streams (ca…
lidge-jun Oct 3, 2026
0358e72
fix(chatgpt): validate bundle trust before restore (carry #6453)
lidge-jun Oct 3, 2026
f264187
fix(oauth): quarantine Antigravity verify-account refusals (carry #6192)
lidge-jun Oct 3, 2026
6ef255f
fix(codex): require consent for spendable-credit headroom (carry #6466)
lidge-jun Oct 3, 2026
3e65384
feat(compaction): scope overrides to source models (carry #6149)
lidge-jun Oct 3, 2026
de82861
feat(droid): preserve per-model reasoning defaults (carry #6151)
lidge-jun Oct 3, 2026
56ea6d7
fix(exports): preserve OpenCode and Kilo model controls (carry #6405)
lidge-jun Oct 3, 2026
5d7efbb
feat(gui): add Brazilian Portuguese dashboard locale (carry #6458)
lidge-jun Oct 3, 2026
684cbfb
merge lane a
lidge-jun Oct 3, 2026
74d64cc
merge lane b
lidge-jun Oct 3, 2026
f076383
merge lane c
lidge-jun Oct 3, 2026
d5d995e
merge lane d
lidge-jun Oct 3, 2026
2a3652c
docs(structure): keep catalog.md within its line budget after the tra…
lidge-jun Oct 3, 2026
da40c73
fix(gui): add the desktop zoom keys to the pt-BR catalog after the tr…
lidge-jun Oct 3, 2026
2e3acab
docs(providers): use self-hosted TokenLab docs (#6474)
hedging8563 Oct 3, 2026
995dee5
docs: lock recovered train integration roadmap
lidge-jun Oct 3, 2026
193c2dc
docs: record train recovery implementation entry
lidge-jun Oct 3, 2026
e79220a
merge: recover reviewed train baseline for final integration
lidge-jun Oct 3, 2026
43cb4e3
merge: reconcile current dev before train recovery handoffs
lidge-jun Oct 3, 2026
946f57c
test(chatgpt): make bundle ancestor fixtures portable
lidge-jun Oct 3, 2026
4b01aab
docs: record bounded Lane A recovery plan
lidge-jun Oct 3, 2026
153fbfd
fix(sse): reconcile delayed LF in terminal repair
lidge-jun Oct 3, 2026
7321021
fix(web-search): stop empty recovery at the iteration ceiling
lidge-jun Oct 3, 2026
ea2a570
fix(i18n): align Portuguese decode-window explanation
lidge-jun Oct 3, 2026
47af987
docs: record audited Lane E recovery plan
lidge-jun Oct 3, 2026
34a42b3
feat(subagents): add opt-in Claude Code model force
lidge-jun Oct 3, 2026
8f337fa
fix(gui): guide Remote Link host setup and recovery
lidge-jun Oct 3, 2026
9475feb
docs: preserve recovered contributor attribution
lidge-jun Oct 3, 2026
c7f06eb
test(update): remove Windows junction fixtures as directories
lidge-jun Oct 3, 2026
14bb403
fix(cli): bound connect readiness launcher inspection
lidge-jun Oct 3, 2026
ce778ca
docs: distinguish resolve and updater liveness probes
lidge-jun Oct 3, 2026
244fc40
merge: integrate reviewed response and search recovery fixes
lidge-jun Oct 3, 2026
81aac74
merge: integrate portable bundle trust regression fixture
lidge-jun Oct 3, 2026
40567c7
merge: integrate bounded readiness and Windows regression fixes
lidge-jun Oct 3, 2026
68cd2af
fix(subagents): preserve explicit launch selection and fresh exposure
lidge-jun Oct 3, 2026
6d3344d
test(remote-link): require new fingerprint confirmation after rescan
lidge-jun Oct 3, 2026
70e27e8
docs: record Lane D recovery verification
lidge-jun Oct 3, 2026
96e3148
merge: retain GUI integration verification evidence
lidge-jun Oct 3, 2026
f583224
fix(gui): translate Claude subagent force controls
lidge-jun Oct 3, 2026
4fa0e2e
docs: sequence ready train landing before remaining feature lane
lidge-jun Oct 3, 2026
ff1a7fa
fix(gui): keep Korean force label readable at narrow widths
lidge-jun Oct 3, 2026
9238f90
test(codex): assert credit-only snapshots without usage windows
lidge-jun Oct 3, 2026
7cb3d70
fix(gui): remove repeated lookups and preserve active response handling
lidge-jun Oct 3, 2026
643e9f1
merge: prepare reviewed subagent force and Remote Link follow-up
lidge-jun Oct 3, 2026
a41e545
fix(gui): guard stale subagent force loading explicitly
lidge-jun Oct 3, 2026
ee2e15f
fix(cli): escape human output while preserving structured exports (#6…
luvs01 Oct 3, 2026
115fa03
fix(service): keep backup names out of Windows cmd logging (#6455)
luvs01 Oct 3, 2026
9fb7923
fix(claude): preserve legacy cleanup before startup prechecks (#6457)
luvs01 Oct 3, 2026
f88a4e6
fix(cli): distinguish inactive and unverified shim readiness
lidge-jun Oct 3, 2026
d2aa9ab
merge: reconcile independently landed CLI and platform fixes
lidge-jun Oct 3, 2026
6fbd999
docs: record progressive source PR landings
lidge-jun Oct 3, 2026
512d0bf
fix(oauth): preserve verify refusal when quarantine persistence fails
lidge-jun Oct 3, 2026
a79ef3e
docs(oauth): scope persistence failure guarantee to adapter recovery
lidge-jun Oct 3, 2026
a3ad806
merge: carry reviewed parent fixes into feature follow-up
lidge-jun Oct 3, 2026
c15d141
test(codex): track convergence in extracted subagent routes
lidge-jun Oct 3, 2026
3ada270
Merge pull request #6487 from lidge-jun/codex/recover-train-261003
lidge-jun Oct 3, 2026
e9c0ccf
merge: retarget feature follow-up onto landed recovery train
lidge-jun Oct 3, 2026
cbf8cbe
test(web-search): count physical sends after search refusal
lidge-jun Oct 3, 2026
0deb8fd
fix(subagents): initialize force settings on first run without replac…
lidge-jun Oct 3, 2026
10b3782
fix(subagents): reject unverified force context markers
lidge-jun Oct 3, 2026
50c5ca6
test(update): make bind fallback fixture independent of socket reuse
lidge-jun Oct 3, 2026
4f345c7
fix: address Droid defaults and dashboard late-review findings
lidge-jun Oct 3, 2026
e02a3fc
fix(oauth): normalize preserved verification replay failures
lidge-jun Oct 3, 2026
adf18d8
fix(server): declare extracted subagent route ownership
lidge-jun Oct 3, 2026
dae85fd
fix(usage): reject nonpositive throughput observations
lidge-jun Oct 3, 2026
452f9a4
Merge pull request #6489 from lidge-jun/codex/recover-train-261003-fe…
lidge-jun Oct 3, 2026
c24c94e
merge: reconcile feature landing into review recovery
lidge-jun Oct 3, 2026
b254139
Merge pull request #6490 from lidge-jun/codex/train-review-followup
lidge-jun Oct 3, 2026
2b01f50
fix(update): canonicalize Scoop home before persist-bin checks
lidge-jun Oct 3, 2026
f9a0559
test(cli): drain startup child pipes and retain bounded diagnostics
lidge-jun Oct 3, 2026
0d99a23
test(nous): drain Windows ACL work before removing test homes
lidge-jun Oct 3, 2026
4b98328
Merge pull request #6494 from lidge-jun/codex/train-windows-final-fixes
lidge-jun Oct 3, 2026
7c59baf
Merge pull request #6495 from lidge-jun/codex/train-windows-test-life…
lidge-jun Oct 3, 2026
3bae88c
fix(antigravity): group discovered effort families across versions (#…
lidge-jun Oct 3, 2026
1913656
fix(cli): keep restart rechecks within their deadline
lidge-jun Oct 3, 2026
42b657d
docs(cli): plan command help UX stack
lidge-jun Oct 3, 2026
b82c5a9
feat(cli): resolve nested help without running commands
lidge-jun Oct 3, 2026
42ef78e
feat(cli): organize help around common tasks
lidge-jun Oct 3, 2026
13c0e82
test(cli): check restore guidance in full help
lidge-jun Oct 3, 2026
d642e2f
feat(cli): guide recovery from command typos
lidge-jun Oct 3, 2026
5ffef49
docs(cli): record published help UX stack and verification
lidge-jun Oct 3, 2026
6d21de0
Merge current dev into #6076
luvs01 Oct 3, 2026
6dce5e9
Add join denial copy to Portuguese locale
luvs01 Oct 3, 2026
62d017e
Merge branch 'codex/cli-ux-help-foundation' into codex/cli-ux-navigation
lidge-jun Oct 3, 2026
fba04f4
Merge branch 'codex/cli-ux-navigation' into codex/cli-ux-recovery
lidge-jun Oct 3, 2026
3084b85
Merge remote-tracking branch 'origin/dev' into codex/cli-ux-help-foun…
lidge-jun Oct 3, 2026
67c4049
Merge pull request #6506 from lidge-jun/codex/cli-restart-deadline
lidge-jun Oct 3, 2026
c893417
docs(cli): keep provider usage open to all subcommands
lidge-jun Oct 3, 2026
53d64d3
Merge branch 'codex/cli-ux-navigation' into codex/cli-ux-recovery
lidge-jun Oct 3, 2026
b82b390
Merge pull request #6498 from lidge-jun/codex/cli-ux-help-foundation
lidge-jun Oct 3, 2026
cb2d173
Merge pull request #6500 from lidge-jun/codex/cli-ux-navigation
lidge-jun Oct 3, 2026
9f89b72
Merge pull request #6503 from lidge-jun/codex/cli-ux-recovery
lidge-jun Oct 3, 2026
b124c4b
docs: plan independent Lane C stabilization carries
lidge-jun Oct 3, 2026
12d0ba4
docs: trim roadmap patch whitespace
lidge-jun Oct 3, 2026
1572ddd
docs: plan release Lane A transport and context recovery
lidge-jun Oct 3, 2026
0076dc5
fix(responses): encode large native Codex HTTP uploads as bytes
MaxyMilan Oct 3, 2026
775bd9b
merge: carry paired Child enrollment onto current dev
lidge-jun Oct 3, 2026
1d06d1a
docs: record public native-account stabilization sources
lidge-jun Oct 3, 2026
d74d453
test(responses): cover native upload threshold and cancellation
lidge-jun Oct 3, 2026
82507bd
docs: normalize upload roadmap patch whitespace
lidge-jun Oct 3, 2026
5d21f20
fix(antigravity): group Claude 5.5 usage and derive reference prices
lidge-jun Oct 3, 2026
1a18376
docs: record public Child pairing stabilization roadmap
lidge-jun Oct 3, 2026
4f0a2e4
fix(codex): treat a revoked main session as needing sign-in and keep …
vadymhimself Oct 3, 2026
f9e1e6b
test: keep layout registrations under the merged file-size limit
lidge-jun Oct 3, 2026
29a9e91
test: remove identical duplicate layout mappings
lidge-jun Oct 3, 2026
db094c4
docs: state native upload byte threshold
lidge-jun Oct 3, 2026
8de421f
fix(claude): preserve terminal native context errors in Messages
lidge-jun Oct 3, 2026
8322239
docs: record reviewed Lane A publication handoff
lidge-jun Oct 3, 2026
179a227
test: remove identical duplicate layout mappings
lidge-jun Oct 3, 2026
63b73b5
test: remove identical duplicate layout mappings
lidge-jun Oct 3, 2026
7a3a18c
test: remove identical duplicate layout mappings
lidge-jun Oct 3, 2026
58ad497
test(gui): verify standalone pairing over real CLI and HTTP
lidge-jun Oct 3, 2026
778fee6
fix(ollama-native): keep tool batches open across assistant commentary
adtumk Oct 3, 2026
77dc218
docs(ollama-native): describe replay batch construction
adtumk Oct 3, 2026
d30b4fa
docs(ollama-native): document deferred replay and test fixtures
adtumk Oct 3, 2026
5931e1b
docs(ollama-native): document fixture model discovery
adtumk Oct 3, 2026
9f661c7
test: preserve known plan in stale quota coverage expectations
lidge-jun Oct 3, 2026
917fa41
test(ollama-native): guard commentary replay validation and immutability
lidge-jun Oct 3, 2026
84630c5
fix(oauth): bind Claude imports to bearer-owned account identity
lidge-jun Oct 3, 2026
e77bfb4
Merge pull request #6513 from lidge-jun/codex/release-261003-a
lidge-jun Oct 3, 2026
d5145c2
Merge remote-tracking branch 'origin/dev' into codex/release-261003-a…
lidge-jun Oct 3, 2026
37fc1fd
fix(oauth): include the profile OAuth beta header
lidge-jun Oct 3, 2026
3aeacab
test(claude): clean up context fixture on setup failures
lidge-jun Oct 3, 2026
8e96348
docs: align Lane C publication gates and replay evidence
lidge-jun Oct 3, 2026
07f96a6
fix(oauth): resume retry-safe cleanup before account mismatch refusal
lidge-jun Oct 3, 2026
2a665a1
fix(codex): attribute reauth only to terminal probe evidence
lidge-jun Oct 3, 2026
60c449b
fix(oauth): retire obsolete intents after verified credential adoption
lidge-jun Oct 3, 2026
a141b83
Merge pull request #6519 from lidge-jun/codex/release-261003-c-ollama
lidge-jun Oct 3, 2026
3898f8f
merge: reconcile release lane D with current dev
lidge-jun Oct 3, 2026
5416d6a
Merge current dev into Lane E identity carry
lidge-jun Oct 3, 2026
36330ae
Merge pull request #6516 from lidge-jun/codex/release-261003-a-messages
lidge-jun Oct 3, 2026
aa40fb4
Merge pull request #6514 from lidge-jun/codex/release-261003-c
lidge-jun Oct 3, 2026
e601cef
Merge pull request #6515 from lidge-jun/codex/release-261003-b
lidge-jun Oct 3, 2026
23a9b67
fix(codex): preserve stored-main ownership and scoped refresh refusal
lidge-jun Oct 3, 2026
b4450b8
perf(oauth): avoid the redundant pre-adoption credential read
lidge-jun Oct 3, 2026
ef74307
merge: validate pairing carry after release auth integration
lidge-jun Oct 3, 2026
90ffac2
Merge latest release integration into Lane E identity carry
lidge-jun Oct 3, 2026
fdbc76c
test(oauth): keep identity registration beside OAuth cases
lidge-jun Oct 3, 2026
358b8ff
Merge pull request #6518 from lidge-jun/codex/release-261003-e-identity
lidge-jun Oct 3, 2026
a99de42
Merge pull request #6517 from lidge-jun/codex/release-261003-d
lidge-jun Oct 3, 2026
d332136
fix(codex): retain caller ownership across preview selection
lidge-jun Oct 3, 2026
80b13f8
fix(codex): cancel alternate main refresh with its caller
lidge-jun Oct 3, 2026
7e1973b
fix(combos): preserve plan-model refusal evidence through error proje…
lidge-jun Oct 3, 2026
e72d468
fix(combos): retain cross-envelope refusal ambiguity
lidge-jun Oct 3, 2026
06034e4
fix(codex): keep main refusal guidance and refresh diagnostics coherent
lidge-jun Oct 3, 2026
d5eccb7
test(codex): guard coherent status reads under main hard lock
lidge-jun Oct 3, 2026
dc7d20d
docs: record native account carry publication
lidge-jun Oct 3, 2026
a41f672
Merge pull request #6523 from lidge-jun/codex/release-261003-b-auth
lidge-jun Oct 3, 2026
9638c45
Merge remote-tracking branch 'origin/dev' into codex/release-261003-b…
lidge-jun Oct 3, 2026
af350a1
fix(combo): detect conflicting error fields before carrier selection
lidge-jun Oct 3, 2026
5d9016d
docs: pin combo verification to the final carry head
lidge-jun Oct 3, 2026
ab68539
Merge pull request #6527 from lidge-jun/codex/release-261003-b-combo
lidge-jun Oct 3, 2026
dd9a980
Merge pull request #6536 from lidge-jun/codex/release-261003-b-records
lidge-jun Oct 3, 2026
160961a
fix(combo): recognize bounded nested HTTP refusal carriers
lidge-jun Oct 3, 2026
c46febd
fix(spend): refuse unbooked dispatches under applicable ceilings
lidge-jun Oct 3, 2026
7796f5d
fix(combo): preserve hard stops across bounded error carriers
lidge-jun Oct 3, 2026
a83b3a1
docs: record scoped release stabilization and verification gates
lidge-jun Oct 3, 2026
efc20e7
Merge pull request #6538 from lidge-jun/codex/spend-capacity-guard
lidge-jun Oct 3, 2026
037dc72
merge: integrate verified existing-format capacity guard
lidge-jun Oct 3, 2026
fe73745
docs: record capacity guard landing and remaining acceptance gates
lidge-jun Oct 3, 2026
cf4061b
Merge remote-tracking branch 'origin/dev' into codex/release-261003-b…
lidge-jun Oct 3, 2026
fa040a0
fix(combo): keep diagnostic types out of hard-stop code evidence
lidge-jun Oct 3, 2026
3541261
Merge pull request #6541 from lidge-jun/codex/release-stabilization-p…
lidge-jun Oct 3, 2026
9f23b1f
Merge pull request #6540 from lidge-jun/codex/release-261003-b-nested…
lidge-jun Oct 3, 2026
9351746
test: isolate release fixtures and cooperatively release child leases
lidge-jun Oct 3, 2026
095fa0f
test: retain all drain failures and prove cleanup before disposal
lidge-jun Oct 3, 2026
0818ea1
Merge pull request #6543 from lidge-jun/codex/release-261004-c-fixtur…
lidge-jun Oct 3, 2026
ee89f59
Merge main into 2.77.0 promotion
lidge-jun Oct 4, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
3 changes: 2 additions & 1 deletion desktop/src-tauri/Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

6 changes: 5 additions & 1 deletion desktop/src-tauri/Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[package]
name = "opencodex-desktop"
version = "2.76.0"
version = "2.77.0"
description = "OpenCodex desktop shell"
authors = ["OpenCodex contributors"]
license = "MIT"
Expand Down Expand Up @@ -38,6 +38,10 @@ tokio = { version = "=1.45.1", features = ["sync", "time"] }
[target.'cfg(target_os = "linux")'.dependencies]
dbus = "=0.9.12"

# Already present in the lock graph; only Windows writes its quoted Run command.
[target.'cfg(target_os = "windows")'.dependencies]
winreg = "=0.55.0"

[profile.release]
codegen-units = 1
lto = "thin"
Expand Down
9 changes: 7 additions & 2 deletions desktop/src-tauri/src/first_run.rs
Original file line number Diff line number Diff line change
Expand Up @@ -6,8 +6,13 @@ use tauri_plugin_autostart::ManagerExt;
const MARKER: &str = "start-at-login-claimed";

/// Marker file recording that the login item names the launch-origin argument.
#[cfg(not(target_os = "windows"))]
const ORIGIN_MARKER: &str = "start-at-login-origin-flag";

// Windows must revisit registrations claimed by the earlier, unquoted writer.
#[cfg(target_os = "windows")]
const ORIGIN_MARKER: &str = "start-at-login-quoted-origin-flag";

/// What the one-time Start at Login decision did on this launch.
#[derive(Clone, Copy, Debug, PartialEq, Eq)]
pub enum StartAtLogin {
Expand Down Expand Up @@ -63,7 +68,7 @@ pub fn apply_start_at_login_default(app: &AppHandle) -> StartAtLogin {
if app.autolaunch().is_enabled().unwrap_or(false) {
return StartAtLogin::AlreadyDecided;
}
match app.autolaunch().enable() {
match crate::login_autostart::enable(app) {
Ok(()) => StartAtLogin::Enabled,
Err(_) => StartAtLogin::Unavailable,
}
Expand Down Expand Up @@ -99,7 +104,7 @@ pub fn adopt_launch_origin_argument(app: &AppHandle) {
// leave a login launch showing its window forever.
match app.autolaunch().is_enabled() {
Ok(true) => {
if app.autolaunch().enable().is_err() {
if crate::login_autostart::enable(app).is_err() {
return;
}
}
Expand Down
3 changes: 3 additions & 0 deletions desktop/src-tauri/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,9 @@ mod first_run;
mod formatting;
mod identity;
mod logging;
mod login_autostart;
#[cfg(any(target_os = "windows", test))]
mod windows_autostart_command;
// macOS only: it exists to replace one item in a menu no other platform installs. Compiling it
// elsewhere would leave its contents unreachable, which -D warnings rejects.
#[cfg(target_os = "macos")]
Expand Down
45 changes: 45 additions & 0 deletions desktop/src-tauri/src/login_autostart.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
use tauri::AppHandle;

/// All shell-owned enables use this entry point; the plugin still owns status and disable.
#[cfg(not(target_os = "windows"))]
pub fn enable(app: &AppHandle) -> Result<(), String> {
use tauri_plugin_autostart::ManagerExt;
app.autolaunch().enable().map_err(|error| error.to_string())
}

#[cfg(target_os = "windows")]
pub fn enable(app: &AppHandle) -> Result<(), String> {
use winreg::enums::{HKEY_CURRENT_USER, KEY_SET_VALUE, REG_BINARY};
use winreg::{RegKey, RegValue};

let executable = std::env::current_exe().map_err(|error| error.to_string())?;
let executable = executable
.to_str()
.ok_or("autostart executable path is not Unicode")?;
let command =
crate::windows_autostart_command::command(executable, crate::startup::AUTOSTART_FLAG)?;
let name = &app.package_info().name;
let hkcu = RegKey::predef(HKEY_CURRENT_USER);
hkcu.open_subkey_with_flags(
r"SOFTWARE\Microsoft\Windows\CurrentVersion\Run",
KEY_SET_VALUE,
)
.and_then(|key| key.set_value(name, &command))
.map_err(|error| error.to_string())?;

// Match the plugin's explicit-enable behavior when Task Manager has an override.
if let Ok(key) = hkcu.open_subkey_with_flags(
r"SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run",
KEY_SET_VALUE,
) {
key.set_raw_value(
name,
&RegValue {
vtype: REG_BINARY,
bytes: vec![2, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0],
},
)
.map_err(|error| error.to_string())?;
}
Ok(())
}
2 changes: 1 addition & 1 deletion desktop/src-tauri/src/tray.rs
Original file line number Diff line number Diff line change
Expand Up @@ -208,7 +208,7 @@ pub fn install(app: &AppHandle) -> tauri::Result<()> {
if enabled {
let _ = app.autolaunch().disable();
} else {
let _ = app.autolaunch().enable();
let _ = crate::login_autostart::enable(app);
}
}
"stop-proxy" => {
Expand Down
41 changes: 41 additions & 0 deletions desktop/src-tauri/src/windows_autostart_command.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
/// Build the Run value without letting spaces split the executable path.
pub fn command(executable: &str, argument: &str) -> Result<String, &'static str> {
if executable.is_empty() || executable.contains(['"', '\0']) {
return Err("invalid executable path for Windows autostart");
}
Ok(format!("\"{executable}\" {argument}"))
}

#[cfg(test)]
mod tests {
use super::command;

#[test]
fn quotes_program_files_path_and_keeps_launch_origin() {
assert_eq!(
command(
r"C:\Program Files\OpenCodex\opencodex-desktop.exe",
"--autostart"
)
.unwrap(),
r#""C:\Program Files\OpenCodex\opencodex-desktop.exe" --autostart"#
);
}

#[test]
fn quotes_paths_without_spaces_and_preserves_unicode() {
for path in [r"C:\OpenCodex\app.exe", r"C:\用户\OpenCodex\app.exe"] {
assert_eq!(
command(path, "--autostart").unwrap(),
format!("\"{path}\" --autostart")
);
}
}

#[test]
fn rejects_paths_that_cannot_be_represented_in_a_run_command() {
for path in ["", "bad\"path.exe", "bad\0path.exe"] {
assert!(command(path, "--autostart").is_err());
}
}
}
2 changes: 1 addition & 1 deletion desktop/src-tauri/tauri.conf.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"$schema": "https://schema.tauri.app/config/2",
"productName": "OpenCodex",
"version": "2.76.0",
"version": "2.77.0",
"identifier": "com.opencodex.desktop",
"build": {
"frontendDist": "../ui",
Expand Down
49 changes: 49 additions & 0 deletions devlog/_fin/261003_antigravity_effort_families/000_plan.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
# Antigravity discovered effort families

New Claude 5.5 Opus and Sonnet tiers currently appear as separate models because discovery only collapses families listed in the bundled catalog. This unit makes complete discovered low/medium/high families one model with selectable effort, including future versions, while preserving explicit suffix requests.

- Class: C3, one cohesive PABCD work-phase (wp1); satisfy-spec.
- Trigger/goal: group the new Antigravity models and retain grouping during automatic refresh; publish and merge one ordinary PR into dev.
- Non-goals: upstream API invention, authentication changes, release, deployment, running-service restart, unrelated UI changes.
- Scope: current managed worktree; existing GitHub identity for authorized PR publication/integration. No user token/cost/wall-clock cap was set.
- Verifiers: focused parser/wire/catalog/new-model-policy regressions, typecheck, structure/privacy/layout gates, docs build, exact-head hosted CI and merge receipt. Existing wire baseline: 61 pass, 0 fail (`bun test tests/adapters/google/google-antigravity-wire.test.ts`). Tests name source arguments directly; typecheck includes src through tsconfig; Bun executes the targeted test files.
- Stop: implementation and independent review complete, relevant checks green, PR merged into dev. DONE needs these proofs; unresolved external checks remain unmet, never passed by assumption.
- Evidence: this unit and local .codexclaw receipts. Escalate only new authority or genuine unresolved design blockers.

## Findings and decisions

`src/providers/antigravity-models.ts:127` and `:207` require a bundled picker ID before recognizing a full suffix family. `src/codex/catalog/provider-models.ts:756` then publishes an empty effort ladder for newly discovered models even when their wire map is exact. Existing base-URL scoped discovery mappings already route effort and are generation-fenced.

Reuse those owners. No new provider registry version list or GUI grouping implementation is needed. Saved suffix IDs remain wire-authoritative. Incomplete ladders stay directly routable; unknown single-wire/tiered semantics remain unknown. Existing explicit configuration overrides retain precedence.

## Consultation

Architect proposal/reflection pending from handle 01a10104-3fca-79a2-8f9c-a410eb64d57e (V1 logical read-only architect, inherited model). Main owns integration; independent reviewer will audit the final plan before implementation.

Architect D01/D02/D03/D05/D06 accepted. D04 amended: carry exact discovered family evidence with CatalogModel; normalize only discovery baseline and base disabled state through the existing reconciliation/persistence path. Keep provider selectedModels unchanged; a read-only shared visibility projection recognizes selected suffixes. Preserve raw default/combo references. No provider configuration migration or extra persistence surface. All-disabled suffixes transfer disabled status once; any enabled known suffix preserves an enabled base. A previously known base and explicit base disable win on later refreshes.

Reflection: D01/D02/D03/D05/D06 ALIGNED; D04 gap (retained suffix IDs reappearing as new arrivals) folded into final plan by normalizing both policy input and baseline. Same architect recheck requested; no implementation before resolution and independent A audit.

Final same-architect reflection: ALIGNED for D01-D06, no remaining material design gap. Baseline additionally passed typecheck and 29 listing/policy tests. Proceed to independent A audit.

A round 1: FAIL, one accepted blocker: final merge independently filters raw selectedModels. Added retained-sync and convergence consumers and final-merge regression. No other material design blocker. Same reviewer re-audit requested.

## Build and verification

Implemented the audited plan. A bounded worker owned the family helper/policy/tests; main integrated parser, catalog, both final-merge selection callers and management projection. Discovery tests first failed 8/8 on the original source and passed after the fix. Existing future-family expectations were updated to assert the requested grouping. OpenCodex's existing synthetic ultra orchestration level remains separate from upstream low/medium/high; no unsupported synthetic max is added to the discovered ladder by default.

Focused verification: 43 isolated test files, 830 pass / 0 fail, covering all Google adapter tests, family/policy/persistence, management and final merge, layout, file-size and optional-Lab import boundaries. The initial combined-process run had 803 pass / 2 fail: new test names disagreed with seed ownership (fixed by provider-prefixed names); an unchanged gemini-web-search mock replaced the listing test's OAuth token across files (each file passes in its own process). Full local suite is disproportionate for this bounded catalog change and shared workstation; repository resource exception uses these affected regressions, with full platform coverage left to exact-head hosted CI. Local logs stay in ignored scratch.

Typecheck passed. Docs build passed (561 pages and 77,923 internal links). Structure and privacy scans passed. Structure catalog was already at its 600-line budget, so the shared family contract lives in providers-and-adapters with a link from the existing catalog paragraph.

## Reviewed implementation outcome

Independent implementation reviewer checked commit `916bd9d600723375c3c5667f4fe7b085af962c4d`, found no concrete regression, and independently ran all 28 new family tests with zero failures. The parser, cache, compatibility, policy projection, both final merge filters, and public list callers are covered. No live upstream model request was made; tests exercise the supplied wire-ID contract with controlled CCA discovery fixtures.

Implementation is complete and published in PR #6501: https://github.com/lidge-jun/opencodex/pull/6501. The PR's live Verification section carries the final hosted-CI and authorized maintainer-integration receipt. Final goal completion additionally requires that exact-head gate and verified dev merge; neither publication nor this archived implementation record claims those external steps already passed.

## External-review corrections

The initial PR head passed hosted CI, but external review found a restart/outage defect that the in-memory tests missed. Accepted and corrected: a bounded exact-family snapshot now precedes synthetic catalog publication, restores routing after restart, and cannot revive after generation invalidation or an authoritative empty/partial replacement. Private no-follow atomic replacement and destination hashes keep URLs and credentials out of the snapshot. Write failure retains prior coherent discovery state. Overlapping family identities are preserved in public rows, policy and original-only selection projection.

The same architect confirmed the revised D05 design ALIGNED. Independent code/security re-review closed both findings and passed 35 then-current focused tests. Main subsequently added two boundary assertions and confirmed 839 tests across 44 affected files (per-file isolation plus the final focused additions), with typecheck and structure checks passing. Restart tests use separate processes and the actual Google adapter while discovery throws, including each tier, medium default, corruption, size bounds, destination/home separation, tombstones and write-failure publication. Process restart is verified; power-loss durability is not claimed. Final updated-head hosted CI and merge receipt remain in the PR's Verification section.
Loading
Loading