Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
197 commits
Select commit Hold shift + click to select a range
93d7102
docs(cli): plan GUI workflow parity stack
lidge-jun Oct 3, 2026
ff8eb3c
docs(cli): link roadmap review and verification receipts
lidge-jun Oct 3, 2026
aa72090
Merge remote-tracking branch 'origin/dev' into codex/cli-parity-found…
lidge-jun Oct 3, 2026
167881a
refactor(cli): separate capability data and task references
lidge-jun Oct 3, 2026
77ac2a9
Merge commit 'e601cefcebcc20b2e04a04821ab45df6538d98f9' into codex/cl…
lidge-jun Oct 3, 2026
59ae05f
feat(cli): expose existing management workflows in help and skill
lidge-jun Oct 3, 2026
8379bdd
Merge remote-tracking branch 'origin/dev' into codex/cli-parity-found…
lidge-jun Oct 3, 2026
6040865
feat(cli): add live provider lifecycle and editor workflows
lidge-jun Oct 3, 2026
7209223
test(cli): align provider parity fixtures with live receipts
lidge-jun Oct 3, 2026
728677b
feat(cli): add model ordering and routing editor workflows
lidge-jun Oct 3, 2026
105ce99
feat(cli): expose account policy and runtime settings workflows
lidge-jun Oct 3, 2026
543a670
docs: revalidate CLI integration and maintenance parity plan
lidge-jun Oct 3, 2026
4d1f59d
docs: require fixed-target redirect refusal for parity commands
lidge-jun Oct 3, 2026
c8d7a0e
test(cli): align legacy login assertions with verified outcomes
lidge-jun Oct 3, 2026
1a51e53
Merge branch 'codex/cli-parity-accounts-settings' into codex/cli-pari…
lidge-jun Oct 3, 2026
d7f7352
feat(cli): expose integration preview recovery and maintenance workflows
lidge-jun Oct 3, 2026
5da6891
docs: lock observation and explicit-key CLI workflow contracts
lidge-jun Oct 3, 2026
7acc2c0
feat(cli): complete observation and explicit-key API workflows
lidge-jun Oct 3, 2026
fda51f7
docs: plan residual read parity and final stack acceptance
lidge-jun Oct 3, 2026
20e3019
Merge commit '0818ea1812a028e1c14cd0b0511b44863407bc52' into codex/cl…
lidge-jun Oct 3, 2026
6579f1e
test: compact layout bookkeeping without changing expectations
lidge-jun Oct 3, 2026
746eddc
Merge branch 'codex/cli-parity-foundation' into codex/cli-parity-prov…
lidge-jun Oct 3, 2026
f1b3a36
Merge branch 'codex/cli-parity-providers' into codex/cli-parity-model…
lidge-jun Oct 3, 2026
85e6770
Merge branch 'codex/cli-parity-models-routing' into codex/cli-parity-…
lidge-jun Oct 3, 2026
28d38da
Merge branch 'codex/cli-parity-accounts-settings' into codex/cli-pari…
lidge-jun Oct 3, 2026
543c1c3
Merge branch 'codex/cli-parity-integrations-maintenance' into codex/c…
lidge-jun Oct 3, 2026
70de532
feat(cli): close filtered observation and per-key quota gaps
lidge-jun Oct 3, 2026
023cc8b
fix(cli): preserve actionable snapshot target recovery
lidge-jun Oct 3, 2026
8e0ced3
docs: bind task acceptance to source and executed evidence
lidge-jun Oct 3, 2026
db9997a
docs: preserve union spellings in rendered planning tables
lidge-jun Oct 3, 2026
ac6e1b3
fix(cli): validate explicit local provider auth overrides before save
lidge-jun Oct 3, 2026
8b55e44
fix(cli): expose nested help and preserve generated option tables
lidge-jun Oct 3, 2026
2b1f256
docs: record acceptance review repairs and remaining proof
lidge-jun Oct 3, 2026
37075e9
fix(cli): preserve failed provider connectivity exit status
lidge-jun Oct 3, 2026
3d7ebe7
fix(cli): expose nested help and preserve generated option tables
lidge-jun Oct 3, 2026
d14df99
docs: preserve union spellings in rendered planning tables
lidge-jun Oct 3, 2026
0d670ab
docs(cli): regenerate readable help tables and correct usage aliases
lidge-jun Oct 3, 2026
99a1729
Merge branch 'codex/cli-parity-foundation' into codex/cli-parity-prov…
lidge-jun Oct 3, 2026
d07abbd
fix(cli): validate explicit local provider auth overrides before save
lidge-jun Oct 3, 2026
991110d
fix(cli): preserve failed provider connectivity exit status
lidge-jun Oct 3, 2026
0b0f090
Merge branch 'codex/cli-parity-providers' into codex/cli-parity-model…
lidge-jun Oct 3, 2026
901c557
Merge branch 'codex/cli-parity-models-routing' into codex/cli-parity-…
lidge-jun Oct 3, 2026
deead72
Merge branch 'codex/cli-parity-accounts-settings' into codex/cli-pari…
lidge-jun Oct 3, 2026
49b0f34
Merge branch 'codex/cli-parity-integrations-maintenance' into codex/c…
lidge-jun Oct 3, 2026
776aca7
docs: complete independently reviewed CLI task acceptance
lidge-jun Oct 3, 2026
16f27e2
docs: archive accepted CLI parity unit for final publication checks
lidge-jun Oct 3, 2026
2ae75ee
test(cli): include companion usage in the route-filter roster
lidge-jun Oct 3, 2026
9ff8637
fix(cli): reject stale companion timeline windows
lidge-jun Oct 3, 2026
87e3156
chore(release): open dev at 2.78.0 before releasing 2.77.0 (#6549)
github-actions[bot] Oct 4, 2026
5965256
docs: record 2.77.0 candidate acceptance and publication (#6561)
lidge-jun Oct 4, 2026
f85925d
fix(server): promote scoped caller conversation headers (#6554)
lidge-jun Oct 4, 2026
be297a5
fix(devin): retain bounded conversation trajectories (#6557)
lidge-jun Oct 4, 2026
df3dd3f
fix(claude): preserve bounded large headers in picker relay (#6551)
lidge-jun Oct 4, 2026
7edad58
fix(devin): qualify child trajectories by supplied parent (#6565)
lidge-jun Oct 4, 2026
16d5dae
fix(responses): share reset replay grants across translated sends (#6…
lidge-jun Oct 4, 2026
eb66133
docs: plan focused Claude request preservation replacements
lidge-jun Oct 4, 2026
17632e3
fix(anthropic): preserve declared native OAuth tool references
lidge-jun Oct 4, 2026
0c01d51
fix(anthropic): retain narrowed typed block during copy-on-write
lidge-jun Oct 4, 2026
221b7dc
fix(anthropic): retain required beta for inline tool changes
lidge-jun Oct 4, 2026
124c85e
docs: clarify native OAuth scope and repair roadmap formatting
lidge-jun Oct 4, 2026
0455845
Merge pull request #6552 from lidge-jun/codex/next-release-261004-cla…
lidge-jun Oct 4, 2026
d13c144
fix(anthropic): retain native client preambles and feature betas
lidge-jun Oct 4, 2026
a0c3f3a
fix(anthropic): preserve native Messages through pooled dispatch
lidge-jun Oct 4, 2026
26dd8cf
Merge pull request #6559 from lidge-jun/codex/next-release-261004-cla…
lidge-jun Oct 4, 2026
33125e6
feat(anthropic): add native pool preference with explicit opt-out pre…
lidge-jun Oct 4, 2026
3ee6137
fix(codex): require saved config authority for routed catalog removal
lidge-jun Oct 4, 2026
d5f9c39
fix(codex): require combo authority for routed aliases
lidge-jun Oct 4, 2026
9289396
Merge pull request #6553 from lidge-jun/codex/next-release-261004-cat…
lidge-jun Oct 4, 2026
8094078
fix(codex): bind catalog writes to home ownership and intent
lidge-jun Oct 4, 2026
3d8bc39
test(codex): keep client guard scenarios reachable after owner admission
lidge-jun Oct 4, 2026
37d0a22
fix(codex): enforce ownership at journal writer entrypoints
lidge-jun Oct 4, 2026
f74a3db
Merge pull request #6558 from lidge-jun/codex/next-release-261004-cat…
lidge-jun Oct 4, 2026
950a5f7
feat(codex): audit catalog writes with bounded private records
lidge-jun Oct 4, 2026
e57243a
fix(codex): harden fresh Windows audit files before diagnostics
lidge-jun Oct 4, 2026
9cc0357
docs: state the deferred Windows audit stream coverage
lidge-jun Oct 4, 2026
8aff79e
Merge pull request #6560 from lidge-jun/codex/next-release-261004-cat…
lidge-jun Oct 4, 2026
68ca3bf
feat(codex): heal lost catalog rows only from the idle owner
lidge-jun Oct 4, 2026
98a9fc8
fix(codex): observe startup catalog promptly and fence path aliases
lidge-jun Oct 4, 2026
5bd1d55
test(cli): follow catalog observation readiness forwarding
lidge-jun Oct 4, 2026
89f5ef8
fix(codex): accept owner publications while heal writes are gated
lidge-jun Oct 4, 2026
33185c2
Merge pull request #6563 from lidge-jun/codex/next-release-261004-cat…
lidge-jun Oct 4, 2026
a6bc608
feat(gui): icon theme switch sharing a row with the zoom stepper (#6579)
lidge-jun Oct 4, 2026
584b92a
test(layout): compact test-layout fixture to restore ratchet headroom…
lidge-jun Oct 4, 2026
50482e2
Merge remote-tracking branch 'origin/dev' into codex/cli-parity-found…
lidge-jun Oct 4, 2026
3a0558e
Merge branch 'codex/cli-parity-foundation' into codex/cli-parity-prov…
lidge-jun Oct 4, 2026
922485b
fix(cli): surface catalog-owner safety refusals in provider add --sync
lidge-jun Oct 4, 2026
7bad34a
Merge branch 'codex/cli-parity-providers' into codex/cli-parity-model…
lidge-jun Oct 4, 2026
bfa4d0b
Merge branch 'codex/cli-parity-models-routing' into codex/cli-parity-…
lidge-jun Oct 4, 2026
a78321e
Merge branch 'codex/cli-parity-accounts-settings' into codex/cli-pari…
lidge-jun Oct 4, 2026
85aaeaf
Merge branch 'codex/cli-parity-integrations-maintenance' into codex/c…
lidge-jun Oct 4, 2026
dcd630e
fix(cli): accept the nativeMessages pool capability from refreshed dev
lidge-jun Oct 4, 2026
cb0cd76
Merge branch 'codex/cli-parity-accounts-settings' into codex/cli-pari…
lidge-jun Oct 4, 2026
9894ea7
Merge branch 'codex/cli-parity-integrations-maintenance' into codex/c…
lidge-jun Oct 4, 2026
9950cd8
fix(cli): keep the pool-save bookkeeping warning from refreshed dev
lidge-jun Oct 4, 2026
fad6f66
Merge branch 'codex/cli-parity-accounts-settings' into codex/cli-pari…
lidge-jun Oct 4, 2026
146994d
Merge branch 'codex/cli-parity-integrations-maintenance' into codex/c…
lidge-jun Oct 4, 2026
9096934
fix(ollama): preserve additional tool outputs during replay (#6576)
Ingwannu Oct 4, 2026
1b3ecb8
test: make provider proxy fixture DNS and child lifetime deterministi…
Hylouis233 Oct 4, 2026
a0ea6d3
test(clients): guard Kilo symlink regression on Windows (#6405)
imranshaiedi-byte Oct 4, 2026
6e5cf45
fix(chatgpt): say why a dropped chatgptDesktop block reads as off (#6…
lcxhh521 Oct 4, 2026
815b1f6
feat(service): name the holder when the runtime mutation lease is bus…
lcxhh521 Oct 4, 2026
6467207
Merge remote-tracking branch 'origin/dev' into codex/cli-parity-found…
lidge-jun Oct 4, 2026
598b5c8
Merge branch 'codex/cli-parity-foundation' into codex/cli-parity-prov…
lidge-jun Oct 4, 2026
dd646e4
Merge branch 'codex/cli-parity-providers' into codex/cli-parity-model…
lidge-jun Oct 4, 2026
4fc2914
Merge branch 'codex/cli-parity-models-routing' into codex/cli-parity-…
lidge-jun Oct 4, 2026
292535a
Merge branch 'codex/cli-parity-accounts-settings' into codex/cli-pari…
lidge-jun Oct 4, 2026
69e42d1
Merge branch 'codex/cli-parity-integrations-maintenance' into codex/c…
lidge-jun Oct 4, 2026
2dd3f82
fix(codex): honor consented credits after included quota exhaustion (…
Ingwannu Oct 4, 2026
dabaed4
fix(cli): default config flags-only calls to show (carry #6483) (#6585)
lidge-jun Oct 4, 2026
4bcd561
Merge remote-tracking branch 'origin/dev' into codex/cli-parity-found…
lidge-jun Oct 4, 2026
c08bbca
Merge branch 'codex/cli-parity-foundation' into codex/cli-parity-prov…
lidge-jun Oct 4, 2026
8a6dc57
Merge branch 'codex/cli-parity-providers' into codex/cli-parity-model…
lidge-jun Oct 4, 2026
95868c7
Merge branch 'codex/cli-parity-models-routing' into codex/cli-parity-…
lidge-jun Oct 4, 2026
ea4b1c6
Merge branch 'codex/cli-parity-accounts-settings' into codex/cli-pari…
lidge-jun Oct 4, 2026
7b1b7a4
Merge branch 'codex/cli-parity-integrations-maintenance' into codex/c…
lidge-jun Oct 4, 2026
989bb24
fix(oauth): release Anthropic refresh intent after a proven-unsent DN…
lidge-jun Oct 4, 2026
df61d03
fix(combos): report the spent primary, not the fallback's own refusal…
vadymhimself Oct 4, 2026
c560b81
Merge remote-tracking branch 'origin/dev' into codex/cli-parity-found…
lidge-jun Oct 4, 2026
e3ff9fd
chore(test-layout): compact this layer's own layout entries
lidge-jun Oct 4, 2026
3953f11
fix(codex): skip non-executable POSIX PATH entries in readiness check…
hulkbig Oct 4, 2026
1909deb
Merge branch 'codex/cli-parity-foundation' into codex/cli-parity-prov…
lidge-jun Oct 4, 2026
697cc9e
chore(test-layout): compact this layer's own layout entries
lidge-jun Oct 4, 2026
7114851
Merge branch 'codex/cli-parity-providers' into codex/cli-parity-model…
lidge-jun Oct 4, 2026
7d23f8a
chore(test-layout): compact this layer's own layout entries
lidge-jun Oct 4, 2026
8d2ccf9
Merge branch 'codex/cli-parity-models-routing' into codex/cli-parity-…
lidge-jun Oct 4, 2026
f812563
chore(test-layout): compact this layer's own layout entries
lidge-jun Oct 4, 2026
3e6035d
Merge branch 'codex/cli-parity-accounts-settings' into codex/cli-pari…
lidge-jun Oct 4, 2026
b6cd273
chore(test-layout): compact this layer's own layout entries
lidge-jun Oct 4, 2026
6f8943e
Merge branch 'codex/cli-parity-integrations-maintenance' into codex/c…
lidge-jun Oct 4, 2026
e950893
chore(test-layout): compact this layer's own layout entries
lidge-jun Oct 4, 2026
de0361e
fix(droid): preserve reasoning defaults after settings normalization …
shawn-kim-ai Oct 4, 2026
accd694
fix(server): wait for a complete Bun before restarting onto a replace…
LilMGenius Oct 4, 2026
270c33c
Merge remote-tracking branch 'origin/dev' into codex/cli-parity-found…
lidge-jun Oct 4, 2026
24ca58e
Merge branch 'codex/cli-parity-foundation' into codex/cli-parity-prov…
lidge-jun Oct 4, 2026
adf8574
Merge branch 'codex/cli-parity-providers' into codex/cli-parity-model…
lidge-jun Oct 4, 2026
04a639e
Merge branch 'codex/cli-parity-models-routing' into codex/cli-parity-…
lidge-jun Oct 4, 2026
b63ced6
Merge branch 'codex/cli-parity-accounts-settings' into codex/cli-pari…
lidge-jun Oct 4, 2026
b9b6b53
Merge branch 'codex/cli-parity-integrations-maintenance' into codex/c…
lidge-jun Oct 4, 2026
01a9923
feat(gui): group the sidebar into eight rows and tidy the Claude surf…
lidge-jun Oct 4, 2026
907c6f4
fix(codex): keep Unix autostart shims off package-manager paths (carr…
lidge-jun Oct 4, 2026
de7c7bb
Merge remote-tracking branch 'origin/dev' into codex/cli-parity-found…
lidge-jun Oct 4, 2026
c28c84e
Merge branch 'codex/cli-parity-foundation' into codex/cli-parity-prov…
lidge-jun Oct 4, 2026
604044d
Merge branch 'codex/cli-parity-providers' into codex/cli-parity-model…
lidge-jun Oct 4, 2026
a5d3554
Merge branch 'codex/cli-parity-models-routing' into codex/cli-parity-…
lidge-jun Oct 4, 2026
5e829cc
Merge branch 'codex/cli-parity-accounts-settings' into codex/cli-pari…
lidge-jun Oct 4, 2026
e468022
Merge branch 'codex/cli-parity-integrations-maintenance' into codex/c…
lidge-jun Oct 4, 2026
7cf1b76
fix(cli): guard standalone update restart with exact replacement veri…
lidge-jun Oct 4, 2026
c4b02a2
Merge remote-tracking branch 'origin/dev' into codex/cli-parity-found…
lidge-jun Oct 4, 2026
8ba53fe
Merge branch 'codex/cli-parity-foundation' into codex/cli-parity-prov…
lidge-jun Oct 4, 2026
2f1993c
Merge branch 'codex/cli-parity-providers' into codex/cli-parity-model…
lidge-jun Oct 4, 2026
4491ef7
Merge branch 'codex/cli-parity-models-routing' into codex/cli-parity-…
lidge-jun Oct 4, 2026
fcbdc06
Merge branch 'codex/cli-parity-accounts-settings' into codex/cli-pari…
lidge-jun Oct 4, 2026
31ded57
Merge branch 'codex/cli-parity-integrations-maintenance' into codex/c…
lidge-jun Oct 4, 2026
69ce37c
fix(integrations): write DSH routes to the Desktop profile patch it r…
lcxhh521 Oct 4, 2026
e65d30c
Merge remote-tracking branch 'origin/dev' into codex/cli-parity-found…
lidge-jun Oct 4, 2026
637f26a
Merge branch 'codex/cli-parity-foundation' into codex/cli-parity-prov…
lidge-jun Oct 4, 2026
e36d125
Merge branch 'codex/cli-parity-providers' into codex/cli-parity-model…
lidge-jun Oct 4, 2026
a8d2d65
Merge branch 'codex/cli-parity-models-routing' into codex/cli-parity-…
lidge-jun Oct 4, 2026
1b4df42
Merge branch 'codex/cli-parity-accounts-settings' into codex/cli-pari…
lidge-jun Oct 4, 2026
e4504e4
docs(structure): keep clients/integrations.md within its 600-line budget
lidge-jun Oct 4, 2026
f108061
fix(cli): accept the DSH profile-patch plan path from refreshed dev
lidge-jun Oct 4, 2026
1ae0faa
Merge branch 'codex/cli-parity-integrations-maintenance' into codex/c…
lidge-jun Oct 4, 2026
5c645e3
feat(cli): make existing management workflows discoverable (#6526)
lidge-jun Oct 4, 2026
275dc63
Merge dev after the #6526 squash (tree unchanged)
lidge-jun Oct 4, 2026
432bc4d
Merge cli-parity-providers after the dev sync (tree unchanged)
lidge-jun Oct 4, 2026
dcdaf13
Merge cli-parity-models-routing after the dev sync (tree unchanged)
lidge-jun Oct 4, 2026
b55fe09
Merge cli-parity-accounts-settings after the dev sync (tree unchanged)
lidge-jun Oct 4, 2026
5dc1ad1
Merge cli-parity-integrations-maintenance after the dev sync (tree un…
lidge-jun Oct 4, 2026
a8d8562
Merge pull request #6528 from lidge-jun/codex/cli-parity-providers
lidge-jun Oct 4, 2026
4cc48d9
Merge pull request #6535 from lidge-jun/codex/cli-parity-models-routing
lidge-jun Oct 4, 2026
79db47c
Merge pull request #6539 from lidge-jun/codex/cli-parity-accounts-set…
lidge-jun Oct 4, 2026
f14e3a3
Merge pull request #6542 from lidge-jun/codex/cli-parity-integrations…
lidge-jun Oct 4, 2026
dadc232
Merge pull request #6545 from lidge-jun/codex/cli-parity-observation-api
lidge-jun Oct 4, 2026
164786a
test(cli): make audio device refusal and login child import portable …
lidge-jun Oct 4, 2026
c22aba6
feat(gui): one-page Claude Code settings and Desktop model roles (#6596)
lidge-jun Oct 4, 2026
8ef6ad9
test(oauth): make the startup-proxy refresh test hold on Windows (#6600)
lidge-jun Oct 4, 2026
e53c807
test: make catalog audit and provider proxy fixture robust on Windows…
lidge-jun Oct 4, 2026
829a18b
docs(devlog): close the CLI update restart unit with its delivery out…
lidge-jun Oct 5, 2026
e023835
feat(integrations): show the missing-store remedy in the dashboard (#…
lcxhh521 Oct 5, 2026
8431189
fix(cli): explain Codex shim overlay migration and activation in stat…
lidge-jun Oct 5, 2026
29f8a38
fix(cli): show account health actions, paid-credit consent, and empty…
lidge-jun Oct 5, 2026
a055b67
fix(cli): correct help and CLI reference text and show declared flags…
lidge-jun Oct 5, 2026
f89e42a
fix(update): stop-first manual reinstall guidance; refresh shim, upda…
lidge-jun Oct 5, 2026
fe09557
fix(management): keep inference ports independent of management ingre…
Ingwannu Oct 5, 2026
e44cada
fix(responses): normalize native upstream session aliases (#6588)
Yuxin-Qiao Oct 5, 2026
33ec795
fix(gui): short sidebars, Claude sidecar rows, Save errors and legacy…
lidge-jun Oct 5, 2026
e9d5908
docs: sync Connect, Claude settings and DSH profile-patch guides with…
lidge-jun Oct 5, 2026
10d063b
fix(test): keep armed test processes out of the real Codex home (#6591)
lcxhh521 Oct 5, 2026
aa10846
fix(claude): serve the Desktop picker over HTTP/2 so SSE streams cann…
lidge-jun Oct 5, 2026
96f0a21
fix(cli): stop echoing values in claude desktop apply argument errors…
lidge-jun Oct 5, 2026
6af4ef4
fix(gui): keep Claude Desktop role selects inside the Models card (#6…
lidge-jun Oct 5, 2026
4a7d96e
fix(gui): integration dialog starts on Close; client status failure o…
lidge-jun Oct 5, 2026
b8d0302
fix(cli): name ocx start when integration preview finds no running pr…
lidge-jun Oct 5, 2026
62fa24d
fix(cli): reject arguments to uninstall and redact credential values …
lidge-jun Oct 5, 2026
f9e3678
fix(cli): honest exit codes and JSON receipts for config, alias, heal…
lidge-jun Oct 5, 2026
0511f45
fix(cli): name the real cause and next action in restart, update, and…
lidge-jun Oct 5, 2026
e847a24
Merge main into 2.78.0 promotion
lidge-jun Oct 5, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
21 changes: 11 additions & 10 deletions bin/ocx.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,7 @@ import {
} from "../src/update/npm-cache-preflight.mjs";
import { handoffWindowsTrayForUpdate, planWindowsTrayUpdate } from "../src/update/tray-update-plan.mjs";
import { bootRestoreProbe, launcherUsableAfterNpmUpdate, transactionalNpmUpdate } from "../src/update/transactional-install.mjs";
import { npmUpdateFailureGuidance } from "../src/update/update-failure-guidance.mjs";
import { manualUpdateFailureGuidance, npmUpdateFailureGuidance } from "../src/update/update-failure-guidance.mjs";
import {
CODEX_CLI_VERSION_MANAGER_ROOT_ENV_SLOTS,
isCodexCliUpdateInspectionArgv,
Expand Down Expand Up @@ -816,14 +816,11 @@ function runPackageManagerSelfUpdate(manager) {
// legacy in-place install (which deletes live first) is exactly the wrong rescue —
// it recreates the #1849 destruction path. Report and stop; the boot probe and the
// recovery marker cover the swap-window states.
const manual = manager === "pnpm"
? `pnpm add -g --allow-build=bun ${PKG}@${tag}`
: `npm install -g --allow-scripts=bun ${PKG}@${tag}`;
// An unexpected exception leaves the active package path unproven for either manager.
// Do not run service/tray/proxy recovery through a possibly half-swapped tree.
postUpdateLauncherUsable = false;
console.error(`opencodex: ${manager} update failed unexpectedly (${error?.message ?? error}). ` +
`The live install was not knowingly modified; run 'ocx update' again or reinstall with ${manual}.`);
`Run 'ocx update' again or follow the manual recovery steps below.`);
res = { status: 1 };
}
if (res.status !== 0) recoverStoppedRuntimeAfterFailure("update failed");
Expand Down Expand Up @@ -861,13 +858,17 @@ function runPackageManagerSelfUpdate(manager) {
// Phase-specific next step (#5624): whether the previous version is still in place decides
// between "retry" and "restore", and a bare reinstall must follow a stop (#5496).
const guidance = npmUpdateFailureGuidance({ ...npmFailure, pkgName: PKG, version: latest || undefined, tag });
console.error(`\nUpdate failed (npm ${npmFailure.phase}). ${guidance.lines.join(" ")}`);
console.error(`\nUpdate failed (npm ${npmFailure.phase}). ${guidance.lines.join("\n")}`);
process.exit(1);
}
const manual = manager === "pnpm"
? `pnpm add -g --allow-build=bun ${PKG}@${tag}`
: `npm install -g --allow-scripts=bun ${PKG}@${tag}`;
console.error(`\nUpdate failed (${manager} exit ${res.status ?? "?"}). Try manually: ${manual}`);
const guidance = manualUpdateFailureGuidance({
bin: manager,
args: manager === "pnpm"
? ["add", "-g", "--allow-build=bun", `${PKG}@${latest || tag}`]
: ["install", "-g", "--allow-scripts=bun", `${PKG}@${latest || tag}`],
owner,
});
console.error(`\nUpdate failed (${manager} exit ${res.status ?? "?"}). ${guidance.join("\n")}`);
process.exit(1);
}

Expand Down
2 changes: 1 addition & 1 deletion desktop/src-tauri/Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion desktop/src-tauri/Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[package]
name = "opencodex-desktop"
version = "2.77.0"
version = "2.78.0"
description = "OpenCodex desktop shell"
authors = ["OpenCodex contributors"]
license = "MIT"
Expand Down
2 changes: 1 addition & 1 deletion desktop/src-tauri/tauri.conf.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"$schema": "https://schema.tauri.app/config/2",
"productName": "OpenCodex",
"version": "2.77.0",
"version": "2.78.0",
"identifier": "com.opencodex.desktop",
"build": {
"frontendDist": "../ui",
Expand Down
60 changes: 60 additions & 0 deletions devlog/_fin/261003_cli_gui_parity/000_plan.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,60 @@
# Make dashboard workflows usable from the terminal

OpenCodex already implements many dashboard operations in its CLI, but discovery omits working commands and several workflows expose only some GUI fields. This unit completes the eligible task gaps, makes existing commands discoverable, and gives the shipped ocx skill verified task recipes. Operators keep the same management validation and consent boundaries, with explicit local/live target selection where those effects differ.

Reader: maintainers reviewing the six-layer manual PR stack; they need the scope, exact command contracts and proof for each layer.

## Loop contract

- Archetype: satisfy a fixed, source-audited task inventory, followed by residual accounting.
- Trigger: user requested near-GUI CLI parity, improved shipped skill, inherited-model subagents, repeated PABCD and a published stack.
- Goal: every eligible GUI task has a named command/sequence, useful help, safe output, documented target and behavioral evidence; genuine exclusions and duplicate views remain explicit.
- Non-goals: GUI redesign, provider routing redesign, new auth authority, raw API/config escape hatches, live-user operation, native GitHub stacks, merging, release or deployment.
- Verifier: numbered phase acceptance tests plus the baseline/QA strategy in 003_verification_strategy.md; a docs checker observes these exact plan files and task ownership before B.
- Stop: six open, reviewable PRs with successful current-head hosted CI; all task ledger rows closed as verified, alias or justified exclusion, with no unexplained UNKNOWN.
- Durable artifacts: this unit, 008_task_ledger.json and ignored command/QA receipts under this session.
- Outcomes: DONE requires implementation, synchronized skill/docs, independent reviews and CI. Real unsupported prerequisites/authority are reported under host blocked rules; workload or compaction is not completion.
- Escalation: main resolves source/architecture conflicts; ask the user only for genuinely new authority. Failed delegates follow the bounded retry/retirement owner; do not swap models silently.
- Resources: no user token/cost/time cap. Tool scope is repository editing, isolated local fixtures and GitHub PR/CI for this repository. No real accounts, credentials, running services, paid upstream calls or destructive user files are QA targets.

## Baseline and source owners

Baseline dev is 9f89b7265b754eb681215ad327fc9459af37b9e1. The initial inventories contain 176 task-entry rows, with two additional embedded dashboard setting groups subsequently found (memory models and compaction routing). Duplicate entry points are retained as aliases rather than silently dropped. Source-coverage labels in 004/005 are not passing runtime evidence. Executable 010..080 decisions supersede earlier source-join syntax proposals; the private audit record retains their history.

The tree remains Bun TypeScript: src/cli owns domain handlers and pure help/capability data; existing server management modules own validation/live mutation; tests/cli plus domain server tests own proof; skills/ocx and docs-site own operating guidance; structure owns current contracts. Existing structure/manifest.json maps src/cli to runtime/config/integration/Desktop/release docs. Only affected owners are updated.

## Dependency-ordered work phases and PR layers

| Phase | Executable document | Dependency | Output / PR layer |
| --- | --- | --- | --- |
| wp0 | This roadmap, inventories and UX contract | none | Docs-only audit; locks the remaining designs before source edits |
| wp1 | 010_discovery_foundation.md | wp0 | Pure metadata and generated-document capacity; layer 1 |
| wp2 | 020_existing_workflow_discovery.md | wp1 | Accurate existing task discovery and skill routing; finish layer 1 |
| wp3 | 030_provider_management.md | wp2 | Bounded input and exact provider live workflows; layer 2 |
| wp4 | 040_models_routing.md | wp3 | Models, picker order, combos and routing profile edits; layer 3 |
| wp5 | 050_accounts_runtime_settings.md | wp4 | Account policies, explicit auth options, agent/settings/v2 parity; layer 4 |
| wp6 | 060_integrations_maintenance.md | wp5 | Live Desktop profile, integration recovery, storage and Hub reads; layer 5 |
| wp7 | 070_observation_api_tools.md | wp6 | Timeline/log fidelity, scoped usage and chosen-key/audio tools; layer 6 |
| wp8 | 080_acceptance_publication.md | wp7 | Residual task proof, final skill/docs and all exact-head PR receipts; finish layer 6 |

The final source adjudication found bounded read gaps in log selection, model-row search and Tray-equivalent quota/filtered totals. [083_residual_read_workflows.md](083_residual_read_workflows.md) adds those repairs inside wp8's P amendment. [081](081_acceptance_revalidation.md) records the pinned-dev propagation and closure sequence; [082](082_acceptance_contract.md) defines the final evidence ledger. These additions preserve the fixed objective and all acceptance criteria.

Every work phase runs a full P→A→B→C→D cycle. wp0 is code-free. Later P revalidates its existing decade doc and quotes the previous D conclusion; changes to decisions return to the same architect before A. Branch names: codex/cli-parity-foundation → codex/cli-parity-providers → codex/cli-parity-models → codex/cli-parity-accounts → codex/cli-parity-integrations → codex/cli-parity-observation. The bottom targets dev; each child targets its open parent. No native stack registration or merge is authorized.

## Coverage and decisions

- 002_terminal_ux.md defines terminal behavior and progressive disclosure.
- 003_verification_strategy.md records real baseline checks and verification scope.
- 004_settings_coverage.md and 005_operations_coverage.md preserve field-level source joins.
- 007_architecture_decisions.md records proposal dispositions, additive field chain and target boundaries.
- 008_task_ledger.json assigns every row to a phase; historical labels are retained while current status/evidence advance.

Source comparison established that local provider/custom-model/v2/logout effects differ from live management receipts. --live is therefore explicit and never inferred from proxy availability or --json. Existing local behavior remains available. Browser-session identity actions stay outside automated parity; data-plane API testing is included with the same data-plane admission authority.

## Alternatives rejected

A generic API request command would expose routes without usable task contracts. Generic config writes would bypass existing live validation and completion receipts. A new command framework would duplicate the existing Capability/domain-handler architecture. Declaring routes that local commands never fetch would make coverage appear complete while remaining false. None is used.

## Phase records

wp0 roadmap was locked after independent audits passed. Inventory corrections already folded: existing v2 verbs are real local implementations, not absent agent verbs; model preset custom is disabled in the GUI; Lab local commands must not acquire fictitious HTTP coverage; memory-model and compaction-routing controls need explicit rows. Whole-plan architect reflection is ALIGNED at a095a4e514d6d8e5a37dbf05a66b2c9156ebaeeb28a8e0fb878bc76f931c27b1; the serializer and data-plane contract amendments were audited independently and passed. See 009_roadmap_lock.md.
29 changes: 29 additions & 0 deletions devlog/_fin/261003_cli_gui_parity/002_terminal_ux.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
# Terminal UX contract

This is a repeated-use management tool for people and automation. The design preserves the compact root help and contextual family navigation delivered by the CLI help stack; it extends task coverage without turning the terminal into an endpoint debugger.

Design variance: 2/10. Motion: 1/10 (no decorative animation). Density: D8 for the full reference, progressive disclosure for first use. Monospace, plain text and predictable line ordering carry meaning; color or symbols never determine correctness. Raster concepts do not help this utility surface and are intentionally omitted.

## Task language

- Extend existing nouns before adding new roots. Prefer list/show/status, set/update, enable/disable, apply/reset and their established domain equivalents.
- A family with no action offers a safe overview/help or an existing read-only default. It must never silently choose a write.
- Help is available without a live proxy and never runs a management action. Examples use registered grammar and placeholders, with a next read/verify command after a mutation.
- Short human output answers what changed, what remains unapplied and the next action. JSON preserves safe API DTO fidelity on stdout; diagnostics stay on stderr and failures keep documented exit codes.
- Empty lists distinguish no configuration, no matching rows and unavailable evidence. Do not render unavailable as zero or an empty successful inventory.
- Unknown/missing/duplicate arguments must fail before network writes. Boolean and numeric syntax reuse established parsers; structured inputs receive bounded, explicit JSON file/stdin forms only when the task's data shape needs them.
- IDs and names are encoded at path/query boundaries. No arbitrary method/URL command is counted as GUI parity.

## Writes and recovery

Existing management routes remain the source of validation, persistence, ownership and live application. A saved configuration is not proof that the client/runtime applied it; preserve refusal, partial application and restart-needed fields in output.

Destructive operations retain explicit confirmation or preview as appropriate to the existing command family and server contract. Read, preview, apply and verify are distinguishable operations. No hidden retry of non-idempotent writes. New commands do not expand account identity, browser consent or secret-returning authority.

No-running-proxy output names the recovery command. Invalid input names the argument and expected syntax without leaking its value when secret-bearing. Server errors preserve meaningful reason/hint fields and failure exit codes. Tests activate server refusal, not-found/conflict, malformed arguments and non-confirmed mutation paths.

## Discoverability and skills

The capability registry, help resolver, generated management reference and human recipes describe the same supported commands. Existing undeclared commands must be mapped before declaring a gap. Skill recipes start with readiness/version checks when operating a real proxy, then task-specific commands and verification. Human-only exclusions stay explicit and do not gain an API workaround.

Each inventory row records GUI task, existing API contract, existing CLI route, implementation/discovery gap, final command and verification, or a reasoned exclusion. Coverage is measured against user tasks, not endpoint count or lines added.
30 changes: 30 additions & 0 deletions devlog/_fin/261003_cli_gui_parity/003_verification_strategy.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
# Verification strategy and observed baseline

Baseline: `9f89b7265b754eb681215ad327fc9459af37b9e1`, the completed CLI-help stack on dev. This unit starts on `codex/cli-parity-foundation` in the existing managed worktree.

Before implementation, the following ran successfully:

| Command | Result | What it observes |
| --- | --- | --- |
| `bun run typecheck` | exit 0 | The repository TypeScript graph, including src/cli. |
| `bun run structure:check` | exit 0 | Structure manifest, declared source ownership, existing paths and invariant bindings; not prose correctness. |
| `bun run skill:surface:check` | exit 0 | Generated skill reference compared with src/cli/capabilities.ts. |
| `bun test tests/cli/cli-capabilities.test.ts tests/cli/cli-capabilities-arguments.test.ts tests/server/management-route-registry.test.ts tests/ci-workflows/skill-ocx.test.ts` | 62 pass, 0 fail, 1180 assertions | Capability parsing, leaf-module import boundary, management declaration reconciliation and shipped-skill command/consent boundaries. |

Raw evidence is in the ignored `.tmp/cli-parity/baseline-*.log` files. The source-map command is unavailable in the installed plugin (it requires a codexclaw development checkout); bounded file inventories and exact source anchors replace it.

## Per-unit proof

Each implementation phase owns focused regression files with exact expected HTTP method/path/body, safe structured output, error/exit mapping and no-request assertions for rejected inputs. Tests use isolated homes and injected RuntimeApiDeps or a disposable loopback fixture; they do not mutate the operator's running proxy, credentials, client applications or accounts.

Acceptance includes real CLI subprocess invocations with separated stdout/stderr, recorded exit codes and plain/pipe output. Help/version paths must remain offline and write-free. For mutations, run an equivalent isolated management-route contract scenario where appropriate; mocking a request records transport shape but does not by itself prove server acceptance. Input files/stdin, cancellation and confirmation paths receive explicit reachable scenarios. Each QA-owned temporary server/process has a teardown receipt.

Existing global gates remain intact. New test files enter both test-layout maps. Source changes update their owning structure docs; public behavior updates CLI docs and the operating skill. Generated output is regenerated from its actual registry owner and checked for drift. Prose/UX semantics receive independent human-style review, not a test that only looks for a phrase.

## Broad verification and publication

Focused tests and type/static/document gates run locally. Full-suite and platform coverage use the current-head hosted PR CI for every layer; the repository's full suite has tens of thousands of tests and concurrent worktrees make repeated local full/changed runs disproportionate. This is the resource-scoped verification plan, not permission to ignore failing focused tests. Record exact commands and the coverage left to CI in each PR.

The preceding CLI-help task recorded four local full-suite failures, all reproduced on its untouched baseline (three restart-lease failures and a pre-request directory snapshot EISDIR). Those records are history, not current-unit passing evidence. If this unit encounters a failure, inspect it and attribute or repair it with fresh source/command evidence. No skip, threshold relaxation, retry-as-fix or unrelated suite substitution is allowed.

Each PR must retain its own current-head CI run, event, attempt, expected executed jobs, checkouts actually tested and open-review dispositions. Canceled/skipped/missing jobs are not passing tests. The stack remains open for review at completion; merge/release is not part of this request.
Loading
Loading