Repository navigation
[WRONG BRANCH] release: 2.81.0 - #6771
Conversation
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
`ocx logs explain <id>` passed the pretty-printed route decision to printData as a single entry. printData escapes control characters per entry for terminal safety, so every line break was printed as a literal `\x0a` and the whole decision came out on one line. Pass one entry per line instead; values keep the same terminal-safety escaping, and --json output is unchanged.
…6711) * release: v2.33.0-preview.20260825 * release: v2.34.0-preview.20260827 * release: v2.36.0-preview.20260829 * fix(release): pass the bump job's permissions through the reusable-workflow call (#3262) Both v2.40.0 release dispatches (33615174183 preview, 33615177849 main) died at startup_failure: a workflow_call cannot grant its callee more than the calling job holds, and dev-version-bump.yml's job declares contents+pull- requests write. #3129 wired the call but never dispatched a release, so this is its first live run. The caller job now declares exactly the callee's two permissions; no other job in release.yml gains anything. Co-authored-by: jun <jun@lidge.dev> (cherry picked from commit 7ce0ba5) * release: set preview channel version 2.48.0-preview.20260908 * release: set main channel version 2.48.0 * chore(release): promote 2.55.0-preview.20260914 to preview Promotes the dev product snapshot 62f0222 to the preview train. The 2.55.0 line carries the #4546 cost-guard work: one send budget per logical request with a shared final-recovery reserve, zero-is-zero refusals with a typed error rather than a synthetic 502, compact and the Kiro inner retries admitted against that budget, a finite send ceiling per root workflow with an interactive reserve a fan-out cannot take, and a healthy detour promoted on transient-hold expiry instead of released cold. The previous preview tip 2.54.0-preview.20260914 is already tagged and published and is outranked by v2.54.0, so it could not be re-released; this is a new candidate rather than a re-cut. * chore(release): promote the verified 2.55.0 product tree to main Same product tree as preview 7bdd1b2 / 2.55.0-preview.20260914, which published successfully with its registry smoke green. Only package.json version differs. * ci(release): expose Linux bundler diagnostics for stable artifacts * fix(release): prepare stable platform bundles * fix(desktop): carry native sidecar packaging repair to main (#5532) * chore(ci): refresh main release verification (#5534) * fix(release): carry lipo argument fix to main (#5537) * fix(release): carry checksum and signature repair to main (#5546) * fix(release): carry Windows checksum record support to main (#5552) * fix(release): publish the GitHub release only after its verified assets attach (#5555) (#5558) GitHub freezes a release when it is published, so the attach step's upload came back HTTP 422 "Cannot upload assets to an immutable release". Every release from v2.55.0 to v2.60.0 therefore shipped with zero assets and the desktop updater had nothing to download. Create the release as a draft and flip it to published in attach-release, after the verified bundle is uploaded. Release notes still come from the validated notes file written at creation. * release: prepare 2.63.0 version metadata (#5612) * release: prepare 2.69.0 version metadata * fix(release): sign the packaged macOS keyring addons before notarization (#6271) * fix(release): sign the packaged macOS keyring addons before notarization Notarization rejected the 2.73.0 preview app: Resources/keyring/*.node, bundled since #6161, were unsigned or ad-hoc and had no secure timestamp, and Tauri does not sign files under Resources. Sign each darwin addon in place with the Developer ID identity, hardened runtime and timestamp after the certificate import and before tauri build, verify the result, and fail a real release that lacks signing material. * fix(release): match keyring signature fields without a pipe (cherry picked from commit 11782ee) * chore(release): 2.74.0 * fix: demote developer to user for OrcaSAQ-2 leading-system template The OrcaSAQ-2-Cyber-27B GGUF pins the same chat-template contract as Qwen3.8-27B — a non-leading `system` raises and `developer` is unsupported — so translated requests carrying a mid-conversation developer reminder failed upstream with a 500 template error. Widen the leading-system matcher to the OrcaSAQ family (org prefix optional, quant tag optional) so the reminder keeps its slot as `user`. --------- Co-authored-by: JUN <bitkyc08@gmail.com> Co-authored-by: jun <jun@junui-MacBookPro.local> Co-authored-by: jun <jun@lidge.dev> Co-authored-by: lidge-jun <243035832+lidge-jun@users.noreply.github.com> Co-authored-by: t <a@b.com> Co-authored-by: JUN <jun@lidgeai.com>
* fix(codex): renew main credit evidence before expiry * test(codex): cover main credit evidence recovery * fix(codex): distinguish stale credit evidence in refusal hints * test(codex): use existing auth error response mapper * test(codex): isolate main credit recovery generations * docs(codex): explain historical credit spendability check * fix(codex): renew opted-in main credits before expiry (#6692) Restrict renewal to valid previously spendable identity-bound credit evidence from three minutes of age. Prepare a token before WHAM and recheck eligibility. Preserve reauth during passive renewal and identity retries, retaining pacing. Remove the out-of-scope refusal-message and retry-hint changes from #6669. Co-authored-by: AiriDea <28827642+AiriDea@users.noreply.github.com> * fix(codex): preserve joiner auth behavior during passive renewal --------- Co-authored-by: OpenCodex Tier Replay <opencodex-tier-replay@local.invalid> Co-authored-by: JUN <jun@lidgeai.com> Co-authored-by: AiriDea <28827642+AiriDea@users.noreply.github.com>
* fix(antigravity): rotate web-search validation refusals * refactor(antigravity): share validation refusal predicate * test(antigravity): assert cancelled refusal stays healthy * fix: narrow Antigravity web-search rotation to structured refusals Match ordinary dispatch gates, keep durable account health unchanged, and charge Antigravity sidecar rotations once per physical send. Co-authored-by: 重音 <hi.baozheng@gmail.com> * fix: preserve Antigravity search refusals and refund unsent hops --------- Co-authored-by: JUN <jun@lidgeai.com>
* fix(claude): stop re-attaching the token footer as a user turn * docs: align translated Claude token footer guidance
* fix(kiro): surface a dead refresh token as needing re-auth * fix(oauth): project Kiro refresh attention in canonical health
…6724) * fix(lifecycle): propose shorter restart drain grace Separate the proposed two-second active/scoped-drain grace from the existing sixty-second cleanup watchdog and seventy-second replacement-readiness budget. Keep API and dashboard timing aligned, cover lifecycle timing and ownership with synthetic clocks, and document interrupted-execution uncertainty. Proposal for owner review of the shared lifecycle default; does not authorize automatic replay or guarantee a two-second recovery. Refs #6643 * feat(lifecycle): make shorter restart grace an explicit API option Signed-off-by: BigHulk <happyhls@gmail.com> * docs: describe explicit restart grace in localized API pages Signed-off-by: BigHulk <happyhls@gmail.com> * docs(api): clarify replacement readiness in French * fix(lifecycle): cut turns at a sub-200ms restart grace without shortening the flush window The restart drain always started 200ms after acceptance so the 202 response could flush, which meant an explicit drainGraceMs below 200 cancelled active turns late. Arm a separate early-cut timer at acceptance + grace for those values; cleanup, listener stop and process exit still wait for the 200ms flush window, and a pending veto cancels the timer. Default and >=200ms grace arm nothing new. Co-authored-by: Hulk <happyhls@gmail.com> --------- Signed-off-by: BigHulk <happyhls@gmail.com> Co-authored-by: Hulk <happyhls@gmail.com>
Map the upstream reasoning subset without changing inclusive output totals. Cover final cumulative SSE usage and buffered/streamed Chat and Responses projections. Co-authored-by: Ingwannu <186453546+Ingwannu@users.noreply.github.com> Co-authored-by: daehwanahn <31888220+daehwanahn@users.noreply.github.com>
… did not start (#6722) * fix(server): serve the desktop bundle's dashboard from an ocx the app did not start * test(server): cover every packaged dashboard layout, source fallback and absent resources
…ady revoked (#6707) * fix(codex): stop refreshing pool accounts whose refresh grant is already revoked A pool account whose refresh grant the token endpoint declared revoked or expired is persisted with a terminal validation verdict, but passive quota reads (dashboard polls, account listings, priming, recovery probes) still called getValidCodexToken on every pass. With no cached quota, or with the credits switch forcing a cache bypass, each pass POSTed the dead refresh token again and logged the same `[codex] pool refresh: reauth status=401` line. fetchPoolAccountQuota now answers those passive reads with the stored `refresh_failed` reauthentication result and re-marks the generation-scoped runtime flag, without a token request. An explicit dashboard refresh (validatePending), a post-reset readback, and source-linked credentials still probe. Any credential write or completed validation already drops the terminal marker, so a re-login recovers the account as before. * fix(codex): keep explicit admin refresh probing a dead pool grant `POST /api/codex-auth/accounts/refresh` sets validatePending only for a dashboard session, so `ocx account refresh` (a raw-admin POST) hit the new dead-grant hold and made no token request. Thread a separate explicitRefresh intent from that route through the account listing to fetchPoolAccountQuota so any explicit refresh command retries the grant once, without changing validatePending (inference consent stays GUI-only). Passive reads stay held: GET listings including `?refresh=1`, dashboard quota polls, priming, and recovery probes. Adds a raw-admin POST case next to the GUI-session case.
Add opt-in `ocx message sessions` and `ocx message send` for exact loaded local Codex sessions (relates to #6478). Submission sends one experimental `thread/queue/add` JSON-RPC over the same control-socket connection used for discovery and final revalidation, so message bodies never enter process arguments. The control socket and every ancestor directory must pass StrictModes-style ownership and permission checks. Receipts distinguish not_sent / queued / unknown (exit 1 / 0 / 3) and never replay an uncertain submission. Also keeps scripts/test-layout/layout.json under the 2,000-line ratchet (dev was at 2,000) and normalizes Windows glob paths in the activation-boundary test. Exact-head Cross-platform CI 37716039873 (attempt 2) passed at 7a39de1; independent security, correctness and final-head reviews approved. Co-authored-by: JUN <jun@lidgeai.com>
Qoder can now return Codex-owned tool calls as Responses function_call and custom_tool_call items through a request-scoped stdio MCP catalog. Codex keeps approval, sandboxing and execution; Qoder's built-in tools stay disabled. Maintainer hardening on top of the original bridge: Qoder-only history name projection (CodeBuddy unchanged), restricted store:false continuation for function and custom tool pairs that fails closed without valid provider-output provenance, init-handshake gating, translator-budget charging, one identity ledger for complete and partial tool calls, and independent bounds on distinct calls and open capture blocks. Closes #5270
…atchet (#6733) #6721 and #6724 each added one explicit registration and together took scripts/test-layout/layout.json to 2000 lines, over the 1999-line NEW_OVERSIZED ratchet, so file-size ratchet: repository fails on dev and on every PR's merge ref. Fold forty single-entry lines into four-per-line rows (the file's existing compact form). The parsed mapping is unchanged; the file drops to 1970 lines.
…ct (carry #6659) (#6725) Carry #6659 without its new upload cap or idle/absolute deadlines. Close refused and early-replied unfinished uploads after the reply finishes: HTTP/1.1 discards remaining input and ends the socket gracefully (immediate destroy truncated large early replies), HTTP/2 sends RST_STREAM NO_ERROR after a complete response and CANCEL otherwise. Completed uploads and bodyless requests keep existing behavior, including keep-alive on generated 502s. Compact the claude-picker layout registrations to stay under the layout ratchet. Co-authored-by: Epinephrine <luvs01@hanmail.net>
) * feat: allow arbitrary HTTPS JEV decision endpoints * fix(jev): keep exact HTTPS decision paths and refuse empty URL delimiters Review follow-up on #6384: - Reject URLs whose raw text carries an empty query, fragment, or userinfo delimiter; WHATWG URL drops those, so the parsed-field check missed them. - Send an arbitrary HTTPS decision path exactly as configured (a trailing slash is significant); /systemone keeps its trailing-slash normalization. Discovery reports the same URL. - Drop the runtime refusal of non-key authMode values. The decision request only ever carries the row's own apiKey, so the refusal protected nothing and made rows that the dashboard and save validation accept unusable at runtime. Cover oauth/local/forward rows sending only their own key. * fix(jev): refuse control characters before the decision URL userinfo check URL strips tab, CR and LF before parsing, so https:<TAB>//@host evaded the raw empty-userinfo check. Refuse any C0 control or DEL in the configured URL, and cover the validation and runtime send boundaries. * chore(jev): drop the lint suppression on the control-character check src/ is not linted for no-control-regex; src/protocols/dto.ts uses the same expression unsuppressed. --------- Co-authored-by: Vadim Rogachyov <vadim.rogachyov@megafon.ru>
…(carry #6672) (#6729) Stored API-key reveal now requires a dashboard session issued through pairing or a trusted Tailscale identity. Automatic loopback sessions and admin-token-only requests are refused, and the requirement is rechecked after the request body is read. The dashboard expires displayed values when the shared session is cleared or replaced, on browser or desktop-host hide, and on server switch. Successful create and rotate operations reconcile the key list through the sequenced resource refresh. The guides in all locales document the rules. Carries and supersedes #6672. Co-authored-by: luvs01 <27862058+luvs01@users.noreply.github.com>
) * fix(runtime): pin Bun 1.4.2 so Windows streams survive Bun.fetch * fix(ci): split Bun 1.4.2 runtime from 1.4.0 test runner * fix(test): resolve pinned Bun runner outside package script PATH * fix(test): cover remaining local Bun runner entrypoints * fix(test): forward pinned runner termination signals * fix(test): resync README manifest and keep layout.json under the ratchet
…back to the task model (#6727) * fix(catalog): keep Codex's auto-review model so reviews stop falling back to the task model The canonical native catalog dropped codex-auto-review as an unsupported bare Codex slug. Because model_catalog_json replaces Codex's entire catalog, the approval reviewer could no longer find its preferred model and fell back to the parent task model at Low effort. Share the exact control-plane id set with routing and preserve or separately backfill one hidden reviewer row whenever native OpenAI rows are included. Keep its upstream reasoning metadata and exclude it from native synthesis, account clones, picker ordering, public lists and override stamping. Preserve provider/per-model/root reviewer precedence and non-OpenAI fallback behavior. Cover all catalog writers, persisted duplicates, visibility, Low effort, HTTP model lists, shared routing and override selection. Register the new regression file in both layout inventories and document the contract. * fix(catalog): skip the reviewer row when the pin lacks it * fix(catalog): gate and version the hidden auto-review row Project the internal reviewer before multi-agent mode normalization so explicit v2 and native v1 exceptions apply in both catalog builders. Keep it outside account clones, featured/picker ordering and effort synthesis. Require an ordinary bare native OpenAI row in the final catalog before preserving or backfilling a reviewer. Hidden natives count; Reserve, account-only and native-less catalogs do not. Prune persisted orphan reviewers after effort clamps and preserve the missing-pin skip fallback. Add regression coverage for mode projection, suppressed/Reserve-only native sets, account-only catalogs and orphan cleanup. Keep the three CI-failing tests and their expectations unchanged. * test(layout): compact two registrations to restore layout.json headroom
…carry #3833) (#6728) Carries #3833 by @rrmlima onto current dev. Adds an opt-in Command Code client: `ocx commandcode` (alias `ocx cmd`), a Connect-page tab and `ocx export --client commandcode` write `provider.opencodex` into `~/.commandcode/providers.json` with `apiKey: false`, under whichever root the file already uses, with the existing snapshot, lock, drift, journal and restore guarantees. On top of #3833: on Windows the store follows the client's `HOME ?? USERPROFILE` for the OS-default home; undoing a plural-root disable reports `current`; dashboard sync and Models-page saves refresh an owned block like `ocx sync`; Connect guide, CLI reference and Fast-row docs list Command Code in every locale; GUI keep-English allowlists and the reused provider mark are registered; test-layout registrations are compacted under the ratchet. Supersedes #3833. Co-authored-by: Rafael Moreira Lima <rrmlima@gmail.com>
…#6744) * feat(anthropic): add Haiku 5.5 request contract * feat(pricing): add Haiku 5.5 prompt bands and refresh Sonnet cache rates * feat(catalog): seed Haiku 5.5 across Claude and harness providers * chore(cursor): keep the Sonnet 5.5 note beside its own capability row * docs(devlog): record the Haiku 5.5 plan, audit and live evidence
…tartup roots (#6748) * test(claude): drain config-dir ACL hardening before removing picker-startup roots * test(claude): attempt every picker-startup stop and root before rethrowing
…unt (#6753) * docs: record 2.81.0 train recovery and publication gates * docs-site: improve mobile homepage and keep GitHub stars visible
* fix(commandcode): bind restore requests to the selected client * fix(commandcode): refuse unscoped restore on legacy proxies * fix(cli): expose client-bound Command Code restore capability * test(cli): assign Command Code capability to integration chapter
…6756) * docs(commandcode): align home resolution and provider copy; clean test fixtures * docs(commandcode): clarify validated Windows home in all affected notes
…l with a green Pool 2 mark (#6743) Adds anthropic2 ("Anthropic · Pool 2"), a second builtin Anthropic OAuth provider that runs the same Anthropic implementation with its own account pool: separate credentials (browser OAuth only), pool settings, routing state, quota, usage labels and reset-grant journal. Helpers bind to an explicit or inherited pool and never fall back across pools; bare claude-* models stay on anthropic. Management API, CLI, catalog and dashboard accept the provider explicitly, and Pool 2 gets a green Claude mark. Verified by hosted CI on 9445c48 (Cross-platform CI 37812949507) plus independent correctness, security and CodeRabbit reviews.
…nting (#6763) * fix(spend): keep OAuth logs out of pool identity * fix(spend): preserve explicit historical pool continuity Aggregate verified salted aliases without moving original balances; fail closed on unresolved pool history before dispatch. Preserve compatibility metadata in v1 checkpoints and document the supported rollback boundary. Add synthetic cross-version, retention, durability, and rootless preflight coverage. * fix(spend): honor verified pool merges and prepaid dispatches Validate historical identity proposals atomically, retain exact reservation ownership through child preflight, and record rooted continuity refusals once. Add synthetic regressions for graph ordering, permit lifecycle and scope, exact-limit recovery/combo dispatch, and refusal event accounting. * fix(spend): attribute external reports to exact dispatch receipts * fix(spend): report prepaid reset-only combo sends * fix(spend): aggregate pool eviction once and sync locale guidance * fix(spend): isolate legacy pool history and explain refusals * wip(spend): checkpoint contract C carry of #6370 Recovery checkpoint of the in-progress contract C implementation so the lane can continue from a managed worktree. Not review-ready; T1-T9, docs and independent review remain. Co-authored-by: Epinephrine <luvs01@hanmail.net> * fix(spend): bind contract C accounting to physical executors Preserve v1 ledger interpretation, durable seed settlement, actual transport coverage and one-invocation CLI accounting. Co-authored-by: Epinephrine <luvs01@hanmail.net> * test(kiro): provide complete retry permit cleanup stub * fix(spend): isolate provider pools and completed tracker cleanup Address the seven review threads with read-time provider self-binding, strict mapping destinations, owner-scoped reporter cleanup, deferred persistence recovery, reverse indexes, live roster refresh and compact refusal parity. Co-authored-by: Epinephrine <luvs01@hanmail.net> * fix(spend): retain accounting through policy activation and cleanup errors Co-authored-by: Epinephrine <luvs01@hanmail.net> * fix(spend): freeze request policy at first admission Co-authored-by: Epinephrine <luvs01@hanmail.net> * fix(spend): retain reported sends through ownership errors Co-authored-by: Epinephrine <luvs01@hanmail.net> * fix(spend): retry repair journal on observe-only admission Flush pending ordinary repair records at each admission and preserve enforced durability refusal. Cover recovery through admission for settled and unknown usage with current and frozen readers. Co-authored-by: Epinephrine <luvs01@hanmail.net> --------- Co-authored-by: Epinephrine <luvs01@hanmail.net> Co-authored-by: luvs01 <27862058+luvs01@users.noreply.github.com>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
✅ Deterministic PR hygiene checks passed. |
|
Important Review skippedToo many files! This PR contains 586 files, which is 286 over the limit of 300. To get a review, reduce the PR to 300 files or fewer by splitting it into smaller PRs or changing its base branch. Usage-priced reviews support at most 300 files. ⚙️ Run configuration
⛔ Files ignored due to path filters (4)
📒 Files selected for processing (586)
You can disable this status message by setting the
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
⏳ DRAFT
What to do
Its title has been prefixed with |
| - name: Setup project Bun test runner | ||
| id: bun-test-runner | ||
| uses: ./.github/actions/setup-project-bun | ||
| with: | ||
| role: test-runner | ||
|
|
||
| - name: Require the test runner package.json declares |
| } | ||
|
|
||
| function tokenFingerprint(token: string): string | undefined { | ||
| return token.length > 0 ? createHash("sha256").update(token).digest("hex") : undefined; |
|
Maintainer release promotion evidence for
Release authorization: the repository owner asked on 2026-10-08 to finish the 2.81.0 train and complete the deployment. |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Summary
Promote the
devcandidate53b83698480d7e09756131c75e57931d666fcab9tomainas stable2.81.0. The candidate already carries 2.81.0 in all four version sources (package.json,desktop/src-tauri/Cargo.toml,Cargo.lock,tauri.conf.json), so the branch is the candidate plus anoursmerge oforigin/main;git diff 53b8369848 HEADis empty and the branch tree equals the candidate treebb97213376. Every dependency fix thatmaincarried (MCP SDK 1.31.0, proxy-addr, fast-uri, ip-address, source-map-js) is already on the candidate at the same or newer version.2.81.0 contents since v2.80.0 (32 first-parent landings):
anthropic2, an independent Anthropic account pool with its own Pool 2 mark (feat(anthropic): add anthropic2, an independent Anthropic account pool with a green Pool 2 mark #6743); v1 pool history preserved with bounded physical-send accounting, carrying fix(responses): record the canonical spend pool for request usage #6370 (fix(spend): preserve v1 pool history with bounded physical-send accounting #6763); Codex pool accounts with a revoked refresh grant stop refreshing (fix(codex): stop refreshing pool accounts whose refresh grant is already revoked #6707); opted-in main credits renew before expiry (fix(codex): renew opted-in main credits before expiry (#6692) #6669); Kiro dead refresh tokens surface as needing re-auth (fix(kiro): surface a dead refresh token as needing re-auth #6716).logs explainkeeps line breaks (fix(cli): keep line breaks in logs explain text output #6704).Verification
lane=all) on the exact candidate53b8369848: run 37823614163 (attempt 2 success, 31 success and 3 condition-skipped; attempt 1 failed onlywindows 8/9on a teardown EPERM inserver-management-auth.test.tswith the same signature as the scheduled main run 37668264606 on the published 2.80.0 code).mainSHA, then therelease.ymldry-run, gate publication.Checklist
maindeliberately: this is a maintainer release promotion (target-branch exception;enforce-targetallows onlydevand is expected to fail here, as on [WRONG BRANCH] release: 2.80.0 #6706).gui/changes (65 files againstmain) arrive only from already-revieweddevlandings, each with its own PR screenshot evidence (for example feat(anthropic): add anthropic2, an independent Anthropic account pool with a green Pool 2 mark #6743); the promotion adds no GUI change beyond the candidate tree, andgit diff 53b8369848 HEADis empty.Release authorization: the repository owner asked on 2026-10-08 to finish the 2.81.0 train and complete the deployment.