Repository navigation
[WRONG BRANCH] release: 2.82.0 - #6878
Conversation
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
…6772) * fix(claude): compare picker metadata file identity with BigInt stats A Windows file ID exceeds 2^53, so Number ino drops low bits and two files can compare equal. Read lstat and fstat with { bigint: true } as local-ca-files.ts already does. * test(claude): pin picker metadata identity beyond 2^53
…Code compacts (#6778) * docs(devlog): plan the Claude 1M-by-default unit Roadmap and diff-level phase docs for treating long-window models as 1M on Claude surfaces, the prompt-is-too-long recovery they rely on, and a 200k accounting opt-in. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(claude): word context overflow as "prompt is too long" so Claude Code compacts Claude Code recovers from an oversized prompt only when the API error says "prompt is too long" (or "input is too long for requested model"); it then compacts reactively. Routed providers word the refusal their own way, so the session ended on a fatal error instead. anthropicErrorBody now rewrites a context_length_exceeded message into that form, carrying token counts only when the upstream states both. The native Messages lane does the same for a configured provider's 400/413 refusal and its streamed or folded error frames, without changing the envelope shape; a 429 that mentions tokens stays a rate limit, and Anthropic pools skip the stream rewrite. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(claude): keep throughput limits and stall timing out of the overflow rewrite Review follow-up. The shared classifier files a "too many tokens per minute" 429 under context_length_exceeded; worded as an overflow it would make Claude Code compact instead of wait, so throughput wording keeps its text. The native stream rewrite buffers whole SSE frames. Placed before the log tap it made stall detection time complete frames instead of raw bytes, so a slow but alive frame could be cut. It now runs after the tap. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(claude): describe the prompt-is-too-long recovery in the Claude Code guide Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…effort ladder, omo tab) (#6785) * fix(codex): mirror LazyCodex role models into the [codex] section omo reads LazyCodex reads per-role overrides from `[codex].agents` in ~/.omo/omo.jsonc. The mirror wrote a bare `codex` key, which LazyCodex's strict config loader drops as unknown, so a role picked in the dashboard reverted to the old model on the next LazyCodex install. * docs(codex): name the [codex] section in the omo.jsonc mirror docs and messages * test(codex): seed the role route tests with the [codex] section The fixtures still wrote a bare "codex" block, which passed only because the writer creates the section it needs. They now start from the shape LazyCodex reads. * fix(codex): size routed roles on the reasoning ladder Codex shows for them Auto-assign took a candidate's efforts from its provider row only. A routed model whose row declares no levels (for example cpa/claude-*) got an empty ladder, so its proposal carried no effort even though Codex's catalog offers low..ultra for it. The mapper now falls back to the written catalog's ladder and default, the same source the Models page reads. * feat(gui): show the LazyCodex role models on the omo tab The section manages omo's Codex variant, so it sits with the other omo controls. It still renders only when LazyCodex is detected, so a Pi-based omo install sees the tab unchanged. * fix(gui): set the LazyCodex section apart from the Pi-based omo block On the omo tab the section's heading ran straight on from the Pi restore center and read as part of it. A rule and spacing now separate the two variants. * test(gui): pin the LazyCodex section to the omo tab and to a detected install * fix(codex): keep the shown default and an explicit empty ladder when sizing routed roles A routed row that declares its own ladder but no default now keeps the default the written Codex catalog shows, when that rung is on the ladder, instead of falling back to the middle rung. An explicit empty reasoningEfforts declares no effort control and no longer borrows the written ladder. Documents the fallback in the auto-assign contract. Co-authored-by: LilMGenius <smsmeee@naver.com> * docs(devlog): plan the LazyCodex role carry (#6760, #6761, #6762) * test(gui): wait on the LazyCodex roles answer instead of a fixed delay The omo-tab placement test checked the section 30 ms after mounting, so a slow runner could pass the absence checks before the roles request landed or fail the presence check before React rendered. Each step now waits for the state it asserts: the roles answer for the undetected case, the rendered row for the detected case, the panel for the Codex tab. Co-authored-by: LilMGenius <smsmeee@naver.com> * test(gui): check LazyCodex section placement from a seeded store The omo-tab placement test waited on timing and asserted absence with toBeNull(), which under happy-dom also accepts an HTMLElement, so its absence checks could not fail. It now seeds the role list's store, so the active tab's copy of the section renders in the first commit, and compares the list of panels that carry it: none for a Pi-based omo install, only the omo panel when LazyCodex is detected, none with the Codex tab active. Placing the section on the Codex tab, alone or alongside the omo tab, fails the test. Co-authored-by: LilMGenius <smsmeee@naver.com> --------- Co-authored-by: LilMGenius <smsmeee@naver.com>
* docs(devlog): plan the L5 auth and quota lane (#6739, #6745) * docs(devlog): fold L5 plan audit findings * docs(devlog): lock L5 roadmap * docs(devlog): revalidate L5 wp2 plan * fix(quota): read the Ollama Cloud quota from /api/balance Ollama replaced the /api/usage quota payload with request-count data. Read /api/balance first, retaining /api/usage for older deployments. Handle transport failures per endpoint and retain terminal verdicts from review. Carries #6739. Co-authored-by: xingqi-gif <67894334+xingqi-gif@users.noreply.github.com> * fix(quota): keep included-only Ollama credits out of routing vetoes Purchased credit is not part of creditsUsd, so an exhausted included allowance vetoes routing only when purchased balance is known to be zero. Co-authored-by: xingqi-gif <67894334+xingqi-gif@users.noreply.github.com> * docs(quota): state when Ollama included credits affect routing * docs(quota): match the purchased-credit routing rule --------- Co-authored-by: xingqi-gif <67894334+xingqi-gif@users.noreply.github.com>
…irs (carry #6769) (#6795) * docs(devlog): L3 compaction and Responses carry roadmap * fix(responses): keep external task input a user turn in raw-body repairs (#6764) * docs(responses): describe external task input in raw-body repairs (#6764) * fix(responses): map original image detail to high in raw-body task input (#6764) * fix(responses): recognize task input with a blank call_id in raw-body repair (#6764) * fix(responses): keep a nonempty call_id a tool result in raw-body repair; scope compaction docs (#6764) * fix(responses): apply the call_id rule in forward orphan repair too (#6764) --------- Co-authored-by: Robin Bially <7304732+robin-bially@users.noreply.github.com>
…s in portable summaries (carry #6746) (#6799) * fix(compaction): omit hosted search replay from portable summaries * fix(compaction): preserve hosted search metadata as text * fix(compaction): bound hosted search notes and keep them assistant reference text * fix(compaction): collect only the capped search note list entries --------- Co-authored-by: panyuanyuan <panyuanyuan@hetao101.com>
… minting route (carry #6741) (#6804) * fix(claude): carry a provider's own encrypted reasoning through the Claude route On the translated Claude Messages route a Responses provider's native encrypted_content was discarded on the way out, and nothing could carry it back: the body is store:false and Claude Code replays only the thinking block. The routed model lost its own reasoning every turn (#6736). Keep the native blob in the thinking block's ocxr1 envelope as `nat`, with the client-facing model and the provider's item id, and emit that block even when no summary arrived. Inbound restores it as encrypted_content and id only for a request naming the same model; any other model gets the visible text alone. Translated bodies that reason now request include: ["reasoning.encrypted_content"], as Codex does. Refs #6736 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(claude): bind native reasoning replay to serving route * test(claude): verify native reasoning provenance and document replay boundary * test(claude): cover absent reasoning and failover send order * fix(claude): reserve native projection copies against the translator budget * fix(claude): hold the decode reservation while re-encoding native projections --------- Co-authored-by: rhomat27 <8294456+rhomat27@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…moval (#6797) * docs(devlog): L7 CI/infra stability roadmap Docs-only roadmap for the L7 lane: Windows test-teardown ownership, test sandbox caching, catalog/runtime and CI work-phases, and maintainer reports. * fix(test): drain ACL work and close history before Windows fixture removal Retain removal ownership across normal asynchronous ACL work, command gaps, and deadline survivors. Synchronize policy fixtures at the initial policy load. Drain fixture producers and both homes' config flights, close request history, then drain ACL work before removal. Preserve failed roots and restore environment in finally. Extract management-auth fixtures, await WebSocket closure, and carry retry-aware cleanup for the remaining audited fixtures. Capture lexical and canonical removal identities before work starts and retain them through settlement, including deadline survivors and changed aliases. Co-authored-by: mashfromband <matsumoto.yukuhashi@gmail.com> Co-authored-by: 김상훈 <luvs01@hanmail.net> * test(layout): place the fixture teardown suite where its seed resolves The membership oracle in tests/test-layout-tooling.test.ts rejects an explicit layout entry that disagrees with its regex seed. The seed resolves fixture-teardown-helper.test.ts to ci-workflows, beside test-sandbox-cleanup.test.ts; move it there and update both layout tables and the docs that cite its path. * fix(test): drain the Anthropic instance fixture and budget Windows picker startup Make Anthropic instance fixture disposal asynchronous and await producer, config hardening, history, and ACL teardown before removing its isolated home. Preserve state clears, protected-tree validation, environment restoration, and idempotent disposal. Await every fixture disposer call in the affected tests. Give the two real picker startup/disable tests watchdogMs(10_000) budgets. Their measured Windows lifecycle-lock ACL and CA inspection costs reach 4.9 s and 8.0-8.4 s, exceeding or approaching the implicit five-second budget. Document the Anthropic fixture's use of the shared teardown helper. Validation: 275 focused tests passed across 12 files; typecheck, privacy scan, structure check, changed-file size audit, and diff whitespace check passed. The full suite was not run, as scoped. Native Windows validation remains for CI. --------- Co-authored-by: mashfromband <matsumoto.yukuhashi@gmail.com> Co-authored-by: 김상훈 <luvs01@hanmail.net>
…en (#6796) Carry the runtime portion of #6723: cancellable bounded Codex probes, same-selection snapshots, guarded persistence, shared flights and retry cooldown. Release owned translator accounting on request abort without changing prepared transport verdicts or awaiting producer cancellation. Own subprocess abort/deadline handling rather than execFile's built-in observer. Reject the caller promptly while the existing bounded-subprocess helper reaps actual exit, escalating SIGTERM to SIGKILL after the shared 2-second grace. Readiness-synchronized Bun children prove termination even when SIGTERM is ignored; Windows keeps forceful termination and still asserts exit. Keep Windows removal ownership, Rust diagnostics and workflow changes in their separate lanes. Refs #6671; this does not establish the Windows leak is resolved. Co-authored-by: mashfromband <matsumoto.yukuhashi@gmail.com>
#6787) * test(link): isolate the remote-prelude tests from a host-installed ocx * test(link): document the stub ocx helper in the remote-prelude tests Carries #6726 so it runs under repository CI. Co-authored-by: Sungyong Cho <dev@sungyongcho.com> --------- Co-authored-by: Sungyong Cho <dev@sungyongcho.com>
Carry #6779's Haiku wire pin and direct resolver regression. Cover the exact model through captureRouteStaticPolicy and the resolver's fifth argument for Responses, Chat and Anthropic inbound, attempted Chat/Responses overrides, repeat resolution, sibling models and custom provider identity. Update the source owner, Responses transport contract and English provider guide to match OpenCode Go's documented Messages endpoint. The seven translated guides contain no Go wire description and remain unchanged. Verification: adapter-resolve red 20 pass / 2 fail before the source fix; green 22 pass / 0 fail after. Layout 2 pass / 0 fail. Typecheck, privacy and structure pass. Full suite and docs build deferred to coordinator CI under this bounded lane's explicit validation scope. Co-authored-by: agents-dev <306679077+agents-dev@users.noreply.github.com>
#6794) * fix(catalog): refresh Azure metadata with captured discovery roots Carry #6754 with all eight provider documentation locales and regenerated OpenAI metadata. Refresh public Azure metadata during discovery with bounded Accept-only requests that reject redirects and retain stale offline fallback. Isolate snapshots, in-flight refreshes and retry cooldowns by resolved config directory. Capture that directory at discovery admission and carry it through refresh, upstream awaits, cached and retained hints, custom rows and combo members. Include the directory in the gather flight identity so distinct roots cannot join. Cache only upstream model evidence for Azure-enriched discovery results. Apply root-specific metadata and configured retention after every fresh, stale and failure-cooldown read so one upstream result serves A-to-B-to-A root switches without leaking another root's enriched capabilities or limits. Register the Azure regression suite in both layout tables. Cover snapshot, flight, cooldown, pending-discovery and warm-cache root switches, plus a native 302 fixture that proves redirected loopback metadata is never requested. Co-authored-by: x3M3x <amroeid1999@gmail.com> * test(catalog): place the Azure metadata suite where its layout seed resolves The ^azure- seed resolves azure-vendor-metadata.test.ts to providers, and the membership oracle rejects an explicit entry that disagrees with its seed. Move the suite to tests/providers/ and register it there in both layout tables. Co-authored-by: x3M3x <amroeid1999@gmail.com> --------- Co-authored-by: x3M3x <amroeid1999@gmail.com>
…#6789) Carry #6765's fallback hint with installation-only error handling. Show the known version's release link through textContent and a fixed GitHub URL, including preview versions, and clear it for navigation or check errors. Place desktop recovery guidance after the complete npm-cache section and stop proxies through their owner; Get-Process is only an identification aid. Verification: - bun test tests/clients/desktop-update-surface.test.ts: old source 9 pass, 2 fail (missing hint/link); fixed source 11 pass, 0 fail. - bun run typecheck: exit 0. - bun run privacy:scan: passed. - bun run structure:check: passed. - bun run --cwd docs-site build: exit 0; 569 pages, 79204 internal links. - git diff --check: passed; four uncapped changed files remain below 2000 lines. Full suite, hosted exact-head CI and native Tauri validation were not run. Co-authored-by: Yum-wu <1172989563@qq.com>
Carry of #6750 onto current dev with review fixes. A validated JEV choice now owns the first native Chat dispatch, including an explicit no-effort choice; provider pins, caps and wire normalization still apply downstream, and later targets do not ask the judge again. Review fixes on top of the contributor's change: - collapse adjacent identical segments in the Combo requested-effort label, so a provider pin that kept the JEV effort no longer logs high->low->low - assert the native lane actually ran in the initial-effort wire matrix Supersedes #6750 Co-authored-by: GeunwooJun <313474999+geunwoojun99@users.noreply.github.com>
…tions (#6791) Carry of #6698 onto current dev with a review fix. The System One / TypeSafe HTTP exchange moves from src/combos/jev.ts into src/combos/jev-service-exchange.ts behind exchangeJevDecision(options, prepare, parse); route state, choices and accounting stay route-owned. Caller cancellation now takes precedence at every gate, HTTP error-body cleanup no longer waits, and the extracted resolver uses the shared jevDecisionEndpointUrl / isSystemOneEndpoint authority from #6731. Review fix: drop a wall-clock assertion from the cancellation test. The one-second race and the abort-reason identity checks already prove prompt cancellation, and an elapsed-time bound flakes on loaded CI workers. Supersedes #6698 Co-authored-by: GeunwooJun <313474999+geunwoojun99@users.noreply.github.com>
…6751) (#6798) * fix(responses): retain child-owned prepaid send reservations Carry of #6751 onto current dev with a parity regression. With transientRetryOn5xx.attempts: 1, a Combo prepaid its target's first send and immediately spent the permit, so the child computed a zero send allowance and answered a local 429 without reaching the provider. The child now owns its exact prepaid booking until physical dispatch: HTTP receipts settle after final local admission, WS receipts after the frame is sent, adapter-owned transports through a live dispatch view, and hosted search/image/video producers keep the same owner. Unsent bookings are released; target-local totals still intersect the shared ceilings. #6763's reporter remains the accounting path whenever spend enforcement is active. Added here: a regression that a two-round hosted web-search turn makes the same model sends (two) for a direct request and a Combo target under attempts: 1, so the child-owned booking keeps parity with the direct path. Supersedes #6751 Co-authored-by: GeunwooJun <313474999+geunwoojun99@users.noreply.github.com> * fix(responses): admit WS receipts before send and own Combo 403 hops Review fixes for the #6751 carry. - Codex WebSocket: the physical-dispatch receipt now runs before the frame is sent. A refused receipt rejects before any frame leaves, without an SSE fallback. One receipt covers a WS attempt and its HTTP fallback, so a frame that never left is not charged twice. If WS send throws and the HTTP fallback then refuses before dispatch, the booking stays charged with no physical send; that conservative case is pinned by a test. - Antigravity 403 verification retry: a Combo child now hands the sibling hop to the sidecar owner, the same as the 429 path, so a retry stopped before dispatch releases its booking. Co-authored-by: GeunwooJun <313474999+geunwoojun99@users.noreply.github.com> * docs(responses): say the WebSocket receipt runs before the frame is sent Co-authored-by: GeunwooJun <313474999+geunwoojun99@users.noreply.github.com> --------- Co-authored-by: GeunwooJun <313474999+geunwoojun99@users.noreply.github.com>
…us, doctor and resolve (#6802) * docs(devlog): plan L1 desktop sidecar CLI authority roadmap * docs(devlog): fold L1 audit rounds into the roadmap * docs(devlog): lock the L1 contract index * docs(devlog): wp2 execution packets * docs(devlog): fold wp2 packet audit * feat(service): recognize live Desktop supervision without an ownership claim * fix(cli): report the Desktop supervisor and stop recommending a competing service * fix(gui): hide service actions while OpenCodex Desktop runs the proxy * docs: describe Desktop supervision for CLI status and startup safety * fix(cli): bind the supervision override to the live runtime and keep localized GUI guidance * fix(service): recheck ownership after the final supervision probe; keep custom gateway guidance first
…box (#6805) Own the default executable cache beneath the exclusive test root, preserve explicit overrides, and inherit the selected cache across nested homes. Cover cache permissions, independent lifetimes, legacy directories and links, and real Bun children. Warm the affected child graphs and bound synchronous children without extending their test deadlines. Keep the GUI typecheck gate in a dedicated serial lane and retain wp1's config drain in desktop fixtures. Co-authored-by: 김상훈 <luvs01@hanmail.net>
…e version skew (#6807) * docs(devlog): carry the L1 plan unit for the launcher PR * docs(devlog): wp3 execution packets * docs(devlog): fold wp3 packet audit * fix(launcher): fall back to a validated PATH Bun when the bundled runtime is missing * feat(cli): warn once when a lifecycle command runs against a different proxy version * docs: document the PATH Bun fallback and the lifecycle version notice * docs(devlog): close wp3 * docs(devlog): sync the L1 plan unit * test: pin the launcher's install guard and keep Windows dotenv paths verbatim * docs(devlog): point the PATH installer follow-up at its owner * fix(launcher): give the PATH Bun fallback a cold-start budget
…ice, update, start and stop (#6809) * fix(service): refuse service activation while OpenCodex Desktop runs the proxy * fix(update): leave a Desktop-supervised runtime and its package alone * fix(cli): explain Desktop supervision on start, stop and restart * docs: describe the Desktop supervision command guards * test: follow the guarded service calls in source-oracle tests
…d recovery to it (carry #6774) (#6811) * fix(codex): serialize config writes and bind recovery to locked journal Coordinate cooperating config writers through one explicit lock handle. Fence stale-lock takeover and initialization, and select journal replay and live-owner checks within the same config write section. Stub quota transport in two metadata-only test fixtures; retain every assertion and timeout while keeping synthetic credentials offline. Carries the Codex config writer work from c7ac1a0, with reproduced lock takeover and journal selection regressions fixed. Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(codex): harden the config write lock carry Key the lock by the canonical write destination and revalidate it immediately before every rename, including prompt durable writes and the Windows replace retries. Keep journal selection, recovery, removal and cleanup inside one held section, and leave an absent Codex home alone. Record host and process-start evidence with each lock and claim. Only a same-host owner proven dead is taken over; foreign-host, hostless and unverifiable records report a non-retryable unsafe state naming the lock. Validate namespace types and POSIX ownership; on Windows the claims directory is hardened through the existing ACL helper. Bound acquisition with a finite timeout on a monotonic clock, release the prompt store lock when config acquisition throws, and pin native feature children to the held canonical home. A native transition refuses when the locked file is not config.toml, and an alias retarget during the child restores the locked file from its preimage. Co-authored-by: 김상훈 <luvs01@hanmail.net> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(codex): recover pre-staging config on native validation failures Capture canonical bytes or absence before transition staging and protect all later validations, publications, child errors, and postconditions in one recovery scope. Restore only the witnessed canonical destination; retain the original private preimage when replacement makes recovery unsafe. Cover alias retargets before wrapper entry and initial spawn validation, canonical replacement before spawn, and failed standalone toggle rollback. Co-authored-by: 김상훈 <luvs01@hanmail.net> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * test(codex): preserve recovery journal after unreadable profile compensation The locked compensation hardening deliberately defers journal restoration until both config and profile are restored. The integration expectation still assumed independent journal restoration from origin/dev and the #6774 carry (51c1f18), so a real EACCES on the profile produced the additional journal entry and failed hosted CI despite preserving all current bytes. Retain production behavior: the wp3 contract requires the current journal to remain recovery authority when artifact compensation fails. Update the expected deferred journal diagnostic and cover matching, absent, and different journal preimages, asserting that the current journal survives in every case. Historical-function replay confirms that the older compensation deletes a current journal for an absent preimage after the profile restore has failed. Co-authored-by: 김상훈 <luvs01@hanmail.net> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(codex): pass rename validation through a hooks object The Lab activation walk follows free calls; an optional callback parameter invoked as a free call has no declaration to inspect. Carry it as hooks.validateBeforeRename like the atomic writer does. Co-authored-by: 김상훈 <luvs01@hanmail.net> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * Avoid per-acquisition Windows subprocesses in config write locks Cache lazy owner identity probes, including unavailable results, and probe other process starts only when liveness permits takeover. Rely on profile ACLs for claims directories and separate contender startup from acquisition deadlines. Co-authored-by: 김상훈 <luvs01@hanmail.net> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(codex): acquire Windows config locks without PowerShell identity probes Resolve reg.exe through the trusted Windows system directory and query MachineGuid with argv, strict parsing, a three-second timeout and a process-local cache. Read Linux machine-id files directly; retain macOS identity probes. Record this Windows process's start identity as unknown without spawning. Missing start evidence disables only the PID-reuse comparison: live or unknown PIDs remain busy, while matching-host owners proven dead twice remain recoverable past the grace window. Failed host discovery still publishes hostless records that later contenders must preserve as unsafe. Cover registry parsing, command failure, caching, trusted executable resolution, and unknown-start takeover. Align Windows journal and unsafe writer fixtures with the canonical production home; retain the contention deadline while separately bounding successful Windows initialization. Document the identity sources and conservative recovery contract. Co-authored-by: 김상훈 <luvs01@hanmail.net> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(tests): isolate Windows Codex home aliases Only set, inspect, and restore Codex_Home on platforms with case-sensitive environment names. On Windows that assignment overwrites CODEX_HOME and makes the held-home fixture operate on B instead of A. Keep the ORCA override removal assertion on every platform and retain the POSIX case-variant checks. Strip all inherited CODEX_HOME case variants before spawning the injector fixture. A duplicate Windows environment name can select the inherited home, where v2 is off, so reconciliation never calls the toggle. Preserve the injector result and effective home in diagnostics even when no child ran. The legacy eligibility mock bypasses coordinator namespace admission, and the canonical junction/lock checks succeed with the isolated environment; no production-path change is needed for this fixture defect. Verification with Bun 1.4.0 on macOS: - Simulated case-insensitive child environment: 0 pass / 1 fail before the environment cleanup, 1 pass / 0 fail after it; effective home and skipped toggle matched the Windows failure mechanism. Native Windows not rerun. - bun scripts/test.ts with codex-config-write-lock, codex-prompt-lock, codex-inject-write-lock, codex-v2-gate, both layout files, and file-size ratchet: 305 pass / 1 skip / 0 fail across seven files. - bun run typecheck: exit 0. Co-authored-by: 김상훈 <luvs01@hanmail.net> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(codex): canonicalize lock destinations with native realpath On Windows the JavaScript realpath can leave 8.3 short components unexpanded, so the same config could canonicalize to different strings depending on whether the file existed, and a held handle was refused as unsafe. Use realpathSync.native for every lock destination, home and alias comparison, as the Codex path module already does. Reproduced and verified with an 8.3 TEMP on a native Windows host. Co-authored-by: 김상훈 <luvs01@hanmail.net> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(codex): return contention for Windows lock sharing violations Retry claim, reservation, evidence and quarantine filesystem operations through the existing bounded Windows retry envelope. Exhaustion stays busy and cannot authorize takeover, including sharing contention followed by EEXIST. Revalidate the release token before each retry and preserve writer errors. Co-authored-by: 김상훈 <luvs01@hanmail.net> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(codex): recover abandoned claims and revalidate every retry Remember completed local reservations whose bounded cleanup fails and retry their removal before acquisition, preserving active reservations. Revalidate captured parent and entry identities and exact claim evidence before destructive attempts so replacements survive retry sleeps. Preserve normal ENOENT handling when a scanned peer releases its claim. Co-authored-by: 김상훈 <luvs01@hanmail.net> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(codex): fence stale lock takeover and cleanup retries Share claim evidence guards with reusable prompt/config locks. Revalidate observed bytes, inode and parent before every takeover or cleanup attempt, and bind exclusive creation and release retries to their captured namespace. Cover sharing-error replacement races deterministically on all three codes. Co-authored-by: 김상훈 <luvs01@hanmail.net> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(codex): keep malformed stale lock records as unsafe evidence The fenced stale-record reader parsed the observed body without the token and pid shape gate, so an expired dead-owner record missing its token could be quarantined. Apply the same gate as readRecord. Co-authored-by: 김상훈 <luvs01@hanmail.net> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(codex): carry Windows retry callbacks as step members The Lab activation walk follows free calls and cannot inspect callback parameters. Pass the operation and its observers in one step object, as rename validation already does. Co-authored-by: 김상훈 <luvs01@hanmail.net> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> --------- Co-authored-by: 김상훈 <luvs01@hanmail.net> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
…tion (#6819) With ultraFastTier enabled, a regenerated routed row was rebuilt from the native template with Fast-only tiers, and the merge dropped the persisted row, so an operator-supplied ultrafast declaration was lost on every sync or convergence. The shared observed-state merge now carries only the exact persisted routed row's Ultra Fast entries (first-win on duplicate slugs) after admission filters, using the opt-in passed explicitly from both writers. Disabling the setting removes Ultra Fast from ordinary routed rows. Closes #6817 Co-authored-by: JUN <lidge-jun@users.noreply.github.com>
* fix(codex): treat a missing Codex home as nothing to restore Skip native restore, removal and journal recovery before ownership checks and configuration locks when the home is proven absent. Preserve writer refusal and bootstrap behavior, return typed missing-parent lock failures, and cover isolated missing-home restore and stop regressions. * fix(codex): preserve missing homes when native toggles and prompt commits fail * fix(codex): keep a prepared Codex home instead of removing it by path A pathname-based removal cannot prove it still names the directory this request created, so a failed toggle or prompt commit could delete a concurrent replacement. Keep the empty home, which is what Codex itself creates; executable resolution still happens before any home is prepared. * fix(cli): keep the shutdown external-provider gate in place The missing-home check belongs inside the restore attempt; the external-provider gate stays on the teardown condition the dispatch source contract pins.
* feat(logs): unwrap pasted codex://threads links in conversation search Codex's copy-session-link clipboard carries a codex://threads/<id> deep link while clients send the bare thread id on the wire. Unwrap the wrapper inside the shared conversation matcher so the Logs conversation field, /api/logs?conversationId, and ocx logs filter --conversation all match the bare id (direct or via its persisted digest) without changing what is persisted. Co-Authored-By: Epinephrine <luvs01@hanmail.net> (cherry picked from commit 19a0f35) * fix(logs): drop query metadata and bound unwrap of codex://threads links Review feedback on #711: codex://threads/<id>?hostId=… pastes kept the query string in the candidate id so neither raw-id nor digest matching worked, and the lazy-wildcard regex had quadratic backtracking on malformed slash-flooded inputs run per log row. unwrapLogConversationQuery is now a bounded (512-char) linear scan: cut at ? or #, strip trailing slashes, and only return a single-segment id. Regression cases cover durable and percent-encoded remote-control hostId values across the dashboard matcher, GET /api/logs conversationId, and ocx logs filter --conversation. Co-Authored-By: Epinephrine <luvs01@hanmail.net> (cherry picked from commit 6d8225f) * fix(logs): keep literal codex://threads session ids searchable Devin Review on #711: a client that literally sends a codex://threads/… session id has it hashed whole for storage, but unwrapping the paste before hashing meant that digest could never match again — the unwrap must add a match path, not replace one. logConversationQueryCandidates now yields the unwrapped id AND the untouched paste; the server matcher tries each (direct + digest) and the GUI hashes every candidate so filterLogs gets both digests. Co-Authored-By: Epinephrine <luvs01@hanmail.net> (cherry picked from commit 0df8335) * fix(logs): batch conversation-query digests with Promise.all React Doctor flagged the sequential await-in-loop in hashLogConversationQuery; candidates are independent, so map them through crypto.subtle.digest concurrently and keep result order. Co-Authored-By: Devin AI <devin-ai-integration[bot]@users.noreply.github.com> (cherry picked from commit a600bf2) * docs(logs): record pasted thread-link search contract Record the conversation filter contract for the work from luvs01#711, including literal URI compatibility and input bounds. The four original commits remain separately cherry-picked with their author identities and source SHA trailers. Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> Co-authored-by: Epinephrine <27862058+luvs01@users.noreply.github.com> --------- Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> Co-authored-by: Devin AI <devin-ai-integration[bot]@users.noreply.github.com> Co-authored-by: Codex <codex@users.noreply.github.com> Co-authored-by: Epinephrine <27862058+luvs01@users.noreply.github.com>
…onc (carry #6801) (#6823) GET /api/codex-agent-roles returns each role's effort, PUT with an effort also writes "[codex]".agents.<role>.reasoning in omo.jsonc (none -> off; a level LazyCodex lacks removes a stale reasoning; a model-only save keeps it), and ocx agent roles set accepts --effort. An empty --effort is refused before any request, and the omo.jsonc contract in structure/clients/integrations.md describes the reasoning mirror. Carries #6801. Co-authored-by: LilMGenius <smsmeee@naver.com>
… (stale) (#6825) Sync refreshes only profiles whose preference is on, so an "off (stale)" Aside profile left `ocx integration client sync --client aside` printing a bare no-op. The empty result now names the status command and the preview-then-enable commands, and status (list and --profile) prints them with the real ID for each off profile beside a stale block. Nothing is re-enabled; no request is added; --json output is unchanged. A malformed asideProfileSync still falls back to all profiles off, and the config load now says so once without echoing the value. Includes the N5 sweep plan unit. Closes #6757
…to a full record fingerprint (#6808) * docs(devlog): L2 service/restart/config-journal carry roadmap * docs(devlog): lock L2 roadmap after independent audit * docs(devlog): wp2 P revalidation * docs(devlog): wp2 L1 overlap and integration seam * fix(cli): bind update restart admission to frozen service records Fingerprint every service-state candidate and POSIX definition, verify inactive supervision within the transaction deadline, and enforce the frozen handoff at parent and child checkpoints. Co-authored-by: agentHits <140916359+agentHits@users.noreply.github.com> * fix(cli): close admission deadline checks and document inactive-service restarts Recheck deadlines after the final home fingerprint and child admission evidence; cover present service definitions and align lifecycle guidance with the frozen service-record contract. Co-authored-by: agentHits <140916359+agentHits@users.noreply.github.com> * fix(cli): harden update restart admission probes and record reads Resolve manager probes from trusted absolute locations, bound descriptor reads to 1 MiB after checking file identity, and share explicit SSH user-bus discovery across parent and child admission. Co-authored-by: agentHits <140916359+agentHits@users.noreply.github.com> * docs(devlog): wp4 review disposition (no root deletion, single admission) * fix(service): treat empty systemd runtime directory as absent Co-authored-by: agentHits <140916359+agentHits@users.noreply.github.com> * test(cli): skip the chmod-only fingerprint edit on Windows Windows chmod only toggles the read-only bit, so 0o644 to 0o600 is not an observable edit there. Name each edit in the assertion so a platform-specific miss is identifiable. Co-authored-by: agentHits <140916359+agentHits@users.noreply.github.com> * test(cli): make fingerprint read drift observable by size NTFS updates last-write time lazily for an open handle; a different-length rewrite keeps the drift case deterministic on Windows. Name each edit in the assertion. Co-authored-by: agentHits <140916359+agentHits@users.noreply.github.com> * test(cli): preserve Desktop veto with inactive service admission Cover unchanged installed service records when Desktop supervision appears before stop, is present initially, or is absent, through the production transaction and standalone validator on macOS and Linux. Co-authored-by: agentHits <140916359+agentHits@users.noreply.github.com> * test(codex): await contender results before releasing prompt lock Use atomic result publication to signal completed acquisition, with a 30-second hang ceiling and a longer owner hold guard. Preserve the at-most-one live owner assertion and usable retry check. Co-authored-by: agentHits <140916359+agentHits@users.noreply.github.com> * fix(codex): treat a vanished claims directory as lock contention Under contention a peer's final directory removal can delete the claims directory between the identity check and the link into it. Linux reports ENOENT, which already meant busy; macOS link reports EINVAL, which escaped tryAcquire and crashed the contender. Treat EINVAL as busy when the claims directory is gone or replaced. The contenders test now reports a crashed child's exit and stderr instead of only timing out. Reproduced locally: 3 crashed rounds in 60 before, 0 in 80 after. Co-authored-by: agentHits <140916359+agentHits@users.noreply.github.com> --------- Co-authored-by: agentHits <140916359+agentHits@users.noreply.github.com>
* docs(devlog): plan the Desktop-owned ocx command on PATH * docs(devlog): wp1 execution plan * feat(desktop): install a Desktop-owned ocx command on PATH * fix(desktop): Windows lint and fixture path escaping in the terminal command * test(desktop): check other-platform record fixtures against the real Windows host * test(desktop): only a bundle-less tombstone is valid across platforms * test(desktop): real zsh and bash select the Desktop shim on a temporary HOME * docs(devlog): wp1 outcome * docs(devlog): plan the PR 1 review fixes * fix(desktop): harden the terminal command against crashes, ACLs and stale page state * test(desktop): build an exact unprotected root for the Windows ACL negative case * docs(structure): record the terminal command's crash, ACL and broadcast rules * fix(desktop): observe the current bundle on every enabled reconcile * docs(devlog): PR 1 review fix outcome * docs(devlog): wp4 landing plan * fix(desktop): set the Windows private DACL natively instead of running icacls * docs(structure): move the terminal command contract into its own document
…ion test) (#6847) * fix: carry remaining #6723 log admission split and fixture drain 39663ff's BigInt picker identity check is already on dev via #6772, so this keeps that implementation. The rest of the commit that still applies moves the log-cursor cases into a registered sibling under the current fixture drain, waits for ACL work before model-arrival fixture removal, and records the bigint file-id comparison in the Claude Desktop contract. The diagnostic-crate hunks stay with #6806. Co-authored-by: mashfromband <matsumoto.yukuhashi@gmail.com> * fix: keep the test-layout map under the file-size ratchet The new log-admission entry shares a line with the management-auth entry so scripts/test-layout/layout.json stays at 1999 lines. Co-authored-by: mashfromband <matsumoto.yukuhashi@gmail.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: mashfromband <matsumoto.yukuhashi@gmail.com>
* feat(claude): treat long windows as 1M on every Claude surface Claude Code accounts an unmarked gateway id at 200k, so GPT-6 natives opted into their 872k window showed as 200k in the Desktop Code-tab picker, the cc picker, Desktop 3P and generated subagents. Those surfaces only marked windows of 1M or more, because their runner may lack CLAUDE_CODE_AUTO_COMPACT_WINDOW. With overflow now answered as "prompt is too long", which Claude Code compacts on, they share one rule (src/claude/long-context.ts): a window of 1M, or one that can host the 829,800 default compact window, gets the [1m] selector, supports1m/prefer1m, a discovery 1M row and a marked subagent selector. The floor is fixed, so a custom compact window cannot re-admit a 372k route (#854). Anthropic rows of either pool still need a genuine 1M, and a discovery variant reports the real input ceiling. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(claude): key the genuine-1M exception on Claude models, not the pool name Review follow-up. The real-Anthropic exception checked only the provider name, so a configured gateway named anthropic2 serving other models lost the long-window rule, while generated and forced subagent markers ignored the exception entirely and could widen a capped Pool 2 Claude row listed by a connected launch's catalog windows. isAnthropicClaudeRoute now requires an Anthropic instance name and a claude-* model id; pickers, discovery, Desktop 3P, the launch window map and both subagent paths use it, and a bare claude-* selector counts as Anthropic. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(claude): leave the launch window map filter as it was The launch path pairs [1m] with CLAUDE_CODE_AUTO_COMPACT_WINDOW and is not one of the unpaired surfaces this layer widens, so its Anthropic filter goes back to the original provider === "anthropic" check. The Claude-model exception stays on the unpaired surfaces, where a capped Claude row keeps its previous 200k accounting. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(claude): document long-window 1M marking in the Claude Code guides English and the six translated guides now say that a window of 1M or at least the 829,800 default compaction threshold gets the [1m] row, that the floor is fixed, that Claude models on an Anthropic route need a genuine 1M, and that an overflow is recovered by Claude Code's own compaction. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(claude): separate the fixed picker floor from launch-slot marking Discovery and Desktop picker rows use the fixed 829,800-token floor. Launch env slots follow the configured compact threshold. Forced subagents mark a non-Anthropic selector at that floor and keep the genuine-1M rule for Anthropic Claude and bare claude-* ids. Co-authored-by: JUN <jun@lidgeai.com> * fix(test-layout): keep the long-context registration under the line cap scripts/test-layout/layout.json is one line under the 2000-line ratchet. The new eligibility entry shares a line with the surface-matrix registration, the same pairing this file already uses, so the map stays at 1999 lines. Co-authored-by: JUN <jun@lidgeai.com> * docs(claude): limit the genuine-1M exception to Claude models The picker contract requires a genuine 1M only for Claude models on either Anthropic pool. A non-Claude model on that route still follows the 829,800 floor. The Desktop structure note, the eligibility test header, and the Chinese and Turkish guides said otherwise. Co-authored-by: JUN <jun@lidgeai.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> Co-authored-by: Cursor Agent <cursoragent@cursor.com>
* docs(devlog): amend the context-accounting plan after layer 2 review
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* feat(claude): add a 200k context-accounting opt-in
claudeCode.contextAccounting decides what opencodex picks by default on
Claude surfaces. Absent (1m, the default) keeps long-window models at 1M.
"200k" opts out everywhere at once: resolveAutoContext returns a mode under
which nothing is marked [1m] automatically and no compact window is
injected, the Desktop pickers leave rows unmarked, Desktop 3P keeps
supports1m but drops prefer1m, and generated or forced subagents keep an
unmarked selector bare. A selector the user marks [1m] keeps it, and
discovery still lists genuine 1M rows as a choice.
Settable with `ocx claude config set --context-accounting <1m|200k>` and
PUT /api/claude-code ("1m" drops the key, other values are a 400); GET
reports it and a change re-applies the system env. Documented in the Claude
Code guides.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* docs(claude): state what the 200k opt-in keeps and what it leaves alone
Review follow-up: an explicit [1m] stays available but generated and forced
subagents still drop a marker the window cannot carry, and an exported
compact window no longer re-enables automatic marking while opencodex
leaves the export itself in place.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* docs(structure): record the 200k context-accounting opt-in
The Claude Desktop, subagent, config, and management-API contracts now
state that claudeCode.contextAccounting "200k" stops automatic 1M
marking while an explicit marker and genuine 1M discovery rows stay.
Co-authored-by: JUN <jun@lidgeai.com>
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
…6782) * feat(gui): add a Context accounting control to the Claude Code page The Claude Code settings page gets a 1M (default) / 200k select for claudeCode.contextAccounting. Under 200k the auto-context and auto-summarize rows are hidden (they have no effect there) and the manual env block stops exporting a compact window, matching what the runtime injects. A state cached by an older proxy, or read from one, normalizes to the 1m default. Strings are added to all eleven locales. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(gui): describe the 200k opt-in precisely and complete test fixtures Review follow-up: the description now says 200k only stops automatic 1M marking (an explicit 1M row and a context override still apply), and the two component fixtures that mount the settings card directly carry the new field. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * test(gui): treat the 200k token-count label as intentional in the French guard Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(gui): keep the Claude quickstart on one accounting snapshot Selecting 200k dropped the compact window while the pasted model ids still carried the server's automatic [1m] marks. The snippet now strips those marks, keeps an explicit [1m], and omits the compact window until the model env was built under the same policy. Co-authored-by: JUN <jun@lidgeai.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> Co-authored-by: Cursor Agent <cursoragent@cursor.com>
A cold bun.exe on Windows spent 13.2s loading src/cli/index.ts, past the 12s spawnSync literal, and returned ETIMEDOUT. Pay that graph in beforeAll and time the badge child against the shared internal deadline. Co-authored-by: Cursor Agent <cursoragent@cursor.com>
…er concurrency (#6860) Track transient Codex failures as a 60-second ratio so concurrent completions can steer new threads without dropping a bound thread or a manual pin. Cross-turn WebSocket reuse stays off unless it is explicitly enabled. Co-authored-by: Cursor Agent <cursoragent@cursor.com>
…6862) A loaded windows-latest runner starts pwsh.exe past the 15s internal deadline, so the caller-token restore sees a null status. The shell is the assertion, so the wait uses the shared spawn budget minus that deadline on win32, including the aged-lock ready file. Co-authored-by: Cursor Agent <cursoragent@cursor.com>
…get (#6863) A loaded windows-latest runner missed the 2s PATH Bun deadline and spent the product 5s probe on a freshly copied bun.exe. The direct probe uses the internal deadline on win32, that copy is warmed before the launcher runs, and the identity powershell wait uses the shared spawn budget so one slow query does not retry out the case. Co-authored-by: Cursor Agent <cursoragent@cursor.com>
…ase (#6861) * test(temp): quarantine a final Windows EPERM instead of failing the case The 15s remove budget is already the whole hosted-runner failure. On the last EPERM, print holder diagnostics and, when no child of the test is alive, rename the subtree into the contained run temp. The lane fails if that trash is still locked when the sandbox root is removed. Co-authored-by: JUN <jun@lidgeai.com> * test(temp): ignore the lock probe when deciding to quarantine The Windows child probe is itself a direct child of the test process, and its command line does not name the temp directory. Counting it refused every quarantine, so a final EPERM still failed the case. Co-authored-by: JUN <jun@lidgeai.com> * test(runtime): give the Windows PATH Bun probe the internal deadline Windows 2 on this branch returned null from findPathBun at 2.4s against the 2s deadline in bun-runtime.test.ts. On win32 that probe now uses INTERNAL_DEADLINE_MS, the same bound as the launcher PATH check. Co-authored-by: JUN <jun@lidgeai.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com>
…wrappers (#6852) The Windows shim and service-script generators write a Bun that lives under the user profile as a %LOCALAPPDATA%/%USERPROFILE% token (src/lib/win-paths.ts), but three preflight assertions expected the literal process.execPath. They passed on CI, whose Bun sits in the tool cache, and failed on any Windows machine with Bun in the default profile location. The assertions now expect the complete `set "OCX_BUN=..."` line rendered the way the generators render it.
…6851) * test(desktop): read only marked lines from the real-shell PATH probe The ignored real_shell_selects_desktop_shim_on_temp_home test required exactly two stdout lines from `bash -l -i`. On Ubuntu, /etc/bash.bashrc prints the sudo hint to stdout for any sudo-group user without ~/.hushlogin, so the release-QA evidence test failed before it checked anything. The shell script now prints sentinel-prefixed result lines and exits non-zero if the lookup or the CLI fails; the assertions read only those lines. * test(desktop): fail the real-shell probe on extra CLI output lines End the marked output line with :OCX-END so a CLI that prints the expected line followed by another line no longer passes; verified by temporarily adding a second echo to the fixture CLI (zsh: wrong CLI output).
…#6855) * docs(devlog): record the cross-OS probe of the desktop-owned CLI path Plan, per-host execution notes and outcomes for probing #6802, #6807, #6809, #6812, #6816 and #6818 on Ubuntu 24.04 and Windows 11. Follow-ups: #6851, #6852, #6853, #6854. * docs(devlog): tighten evidence citations and the F1 hypothesis * docs(devlog): qualify unretained evidence in the probe outcome * docs(devlog): record exact-head CI for the probe follow-ups * docs(devlog): close the cross-OS probe unit and fold review fixes * docs(devlog): align the P2 escape note and guard the probe cleanup paths
…ostic (#6806) Adds .github/workflows/catalog-async-contracts.yml and the Rust contract crate under scripts/diagnostics/windows-version-control/, carrying the CI part of #6723. Portable contracts run the real Bun catalog modules on Linux, macOS and Windows; push runs are limited to dev/main/preview, PR runs cancel superseded runs, and the toolchain is pinned to 1.99.0. Co-authored-by: mashfromband <matsumoto.yukuhashi@gmail.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Important Review skippedToo many files! This PR contains 630 files, which is 330 over the limit of 300. To get a review, reduce the PR to 300 files or fewer by splitting it into smaller PRs or changing its base branch. Usage-priced reviews support at most 300 files. ⚙️ Run configuration
⛔ Files ignored due to path filters (3)
📒 Files selected for processing (630)
You can disable this status message by setting the
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
⏳ DRAFT
What to do
Its title has been prefixed with |
| const salt = thoughtSignatureReplaySalt(); | ||
| if (!owner || !salt || salt.length < 16 || blob.length === 0) return undefined; | ||
| return createHmac("sha256", salt).update("native-reasoning\0") | ||
| .update(JSON.stringify([owner.destination, owner.credential, createHash("sha256").update(blob).digest("hex")])) |
|
Maintainer note on the hygiene result: The |
Summary
Promote the frozen dev candidate
55557dc64edd52d7ce28bdaf0f76e4d0aa9290fdtomainas stable 2.82.0. The promotion head87e93b766b4d222ac9da509f96efed0fc8b1cc20merges inmainancestry andhas exactly the candidate tree. package.json, desktop tauri.conf.json, Cargo.toml and the opencodex-desktop Cargo.lock
entry all carry 2.82.0. The dev pre-move has merged (#6875) and
devnow carries 2.83.0.This is a maintainer-controlled release promotion under MAINTAINERS.md. It targets
maindeliberately: enforce-targetaccepts
devand open stacked bases only, so its wrong_base failure is expected (same as #6771).Verification
87e93b766b4d222ac9da509f96efed0fc8b1cc20: https://github.com/lidge-jun/opencodex/actions/runs/38032868934 (9 Windows shards, 2 macOS shards, macOS control).55557dc64edd52d7ce28bdaf0f76e4d0aa9290fd(dev push): https://github.com/lidge-jun/opencodex/actions/runs/38032802318.release.ymlruns (dry-run, then live) withexpected-shaset to that SHA.devthrough reviewed PRs; screenshot from merged feat(gui): add a Context accounting control to the Claude Code page #6782:Checklist