Skip to content

[WRONG BRANCH] release: 2.82.0 - #6878

Merged
lidge-jun merged 60 commits into
mainfrom
codex/promote-main-2.82.0
Oct 10, 2026
Merged

lidge-jun merged 60 commits into
mainfrom
codex/promote-main-2.82.0

Conversation

@lidge-jun

Copy link
Copy Markdown
Owner

Summary

Promote the frozen dev candidate 55557dc64edd52d7ce28bdaf0f76e4d0aa9290fd to main as stable 2.82.0. The promotion head 87e93b766b4d222ac9da509f96efed0fc8b1cc20 merges in main ancestry and
has exactly the candidate tree. package.json, desktop tauri.conf.json, Cargo.toml and the opencodex-desktop Cargo.lock
entry all carry 2.82.0. The dev pre-move has merged (#6875) and dev now carries 2.83.0.

This is a maintainer-controlled release promotion under MAINTAINERS.md. It targets main deliberately: enforce-target
accepts dev and open stacked bases only, so its wrong_base failure is expected (same as #6771).

Verification

Context accounting control included in this promotion

Checklist

  • Scope stays focused and avoids unrelated cleanup.
  • Docs or release notes were updated when needed.
  • Security-sensitive changes were reviewed for secrets, auth, and unsafe defaults.

github-actions Bot and others added 30 commits October 9, 2026 04:19
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
…6772)

* fix(claude): compare picker metadata file identity with BigInt stats

A Windows file ID exceeds 2^53, so Number ino drops low bits and two files can compare equal. Read lstat and fstat with { bigint: true } as local-ca-files.ts already does.

* test(claude): pin picker metadata identity beyond 2^53
…Code compacts (#6778)

* docs(devlog): plan the Claude 1M-by-default unit

Roadmap and diff-level phase docs for treating long-window models as 1M on
Claude surfaces, the prompt-is-too-long recovery they rely on, and a 200k
accounting opt-in.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(claude): word context overflow as "prompt is too long" so Claude Code compacts

Claude Code recovers from an oversized prompt only when the API error says
"prompt is too long" (or "input is too long for requested model"); it then
compacts reactively. Routed providers word the refusal their own way, so
the session ended on a fatal error instead.

anthropicErrorBody now rewrites a context_length_exceeded message into that
form, carrying token counts only when the upstream states both. The native
Messages lane does the same for a configured provider's 400/413 refusal and
its streamed or folded error frames, without changing the envelope shape; a
429 that mentions tokens stays a rate limit, and Anthropic pools skip the
stream rewrite.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(claude): keep throughput limits and stall timing out of the overflow rewrite

Review follow-up. The shared classifier files a "too many tokens per minute"
429 under context_length_exceeded; worded as an overflow it would make
Claude Code compact instead of wait, so throughput wording keeps its text.

The native stream rewrite buffers whole SSE frames. Placed before the log
tap it made stall detection time complete frames instead of raw bytes, so
a slow but alive frame could be cut. It now runs after the tap.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(claude): describe the prompt-is-too-long recovery in the Claude Code guide

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…effort ladder, omo tab) (#6785)

* fix(codex): mirror LazyCodex role models into the [codex] section omo reads

LazyCodex reads per-role overrides from `[codex].agents` in ~/.omo/omo.jsonc. The mirror wrote a bare
`codex` key, which LazyCodex's strict config loader drops as unknown, so a role picked in the
dashboard reverted to the old model on the next LazyCodex install.

* docs(codex): name the [codex] section in the omo.jsonc mirror docs and messages

* test(codex): seed the role route tests with the [codex] section

The fixtures still wrote a bare "codex" block, which passed only because the writer creates the
section it needs. They now start from the shape LazyCodex reads.

* fix(codex): size routed roles on the reasoning ladder Codex shows for them

Auto-assign took a candidate's efforts from its provider row only. A routed model whose row declares
no levels (for example cpa/claude-*) got an empty ladder, so its proposal carried no effort even
though Codex's catalog offers low..ultra for it. The mapper now falls back to the written catalog's
ladder and default, the same source the Models page reads.

* feat(gui): show the LazyCodex role models on the omo tab

The section manages omo's Codex variant, so it sits with the other omo controls. It still renders
only when LazyCodex is detected, so a Pi-based omo install sees the tab unchanged.

* fix(gui): set the LazyCodex section apart from the Pi-based omo block

On the omo tab the section's heading ran straight on from the Pi restore center and read as part of
it. A rule and spacing now separate the two variants.

* test(gui): pin the LazyCodex section to the omo tab and to a detected install

* fix(codex): keep the shown default and an explicit empty ladder when sizing routed roles

A routed row that declares its own ladder but no default now keeps the default
the written Codex catalog shows, when that rung is on the ladder, instead of
falling back to the middle rung. An explicit empty reasoningEfforts declares no
effort control and no longer borrows the written ladder. Documents the fallback
in the auto-assign contract.

Co-authored-by: LilMGenius <smsmeee@naver.com>

* docs(devlog): plan the LazyCodex role carry (#6760, #6761, #6762)

* test(gui): wait on the LazyCodex roles answer instead of a fixed delay

The omo-tab placement test checked the section 30 ms after mounting, so a
slow runner could pass the absence checks before the roles request landed or
fail the presence check before React rendered. Each step now waits for the
state it asserts: the roles answer for the undetected case, the rendered row
for the detected case, the panel for the Codex tab.

Co-authored-by: LilMGenius <smsmeee@naver.com>

* test(gui): check LazyCodex section placement from a seeded store

The omo-tab placement test waited on timing and asserted absence with
toBeNull(), which under happy-dom also accepts an HTMLElement, so its absence
checks could not fail. It now seeds the role list's store, so the active tab's
copy of the section renders in the first commit, and compares the list of
panels that carry it: none for a Pi-based omo install, only the omo panel
when LazyCodex is detected, none with the Codex tab active. Placing the section
on the Codex tab, alone or alongside the omo tab, fails the test.

Co-authored-by: LilMGenius <smsmeee@naver.com>

---------

Co-authored-by: LilMGenius <smsmeee@naver.com>
* docs(devlog): plan the L5 auth and quota lane (#6739, #6745)

* docs(devlog): fold L5 plan audit findings

* docs(devlog): lock L5 roadmap

* docs(devlog): revalidate L5 wp2 plan

* fix(quota): read the Ollama Cloud quota from /api/balance

Ollama replaced the /api/usage quota payload with request-count data.
Read /api/balance first, retaining /api/usage for older deployments.
Handle transport failures per endpoint and retain terminal verdicts from review.

Carries #6739.

Co-authored-by: xingqi-gif <67894334+xingqi-gif@users.noreply.github.com>

* fix(quota): keep included-only Ollama credits out of routing vetoes

Purchased credit is not part of creditsUsd, so an exhausted included allowance vetoes routing only when purchased balance is known to be zero.

Co-authored-by: xingqi-gif <67894334+xingqi-gif@users.noreply.github.com>

* docs(quota): state when Ollama included credits affect routing

* docs(quota): match the purchased-credit routing rule

---------

Co-authored-by: xingqi-gif <67894334+xingqi-gif@users.noreply.github.com>
…irs (carry #6769) (#6795)

* docs(devlog): L3 compaction and Responses carry roadmap

* fix(responses): keep external task input a user turn in raw-body repairs (#6764)

* docs(responses): describe external task input in raw-body repairs (#6764)

* fix(responses): map original image detail to high in raw-body task input (#6764)

* fix(responses): recognize task input with a blank call_id in raw-body repair (#6764)

* fix(responses): keep a nonempty call_id a tool result in raw-body repair; scope compaction docs (#6764)

* fix(responses): apply the call_id rule in forward orphan repair too (#6764)

---------

Co-authored-by: Robin Bially <7304732+robin-bially@users.noreply.github.com>
…s in portable summaries (carry #6746) (#6799)

* fix(compaction): omit hosted search replay from portable summaries

* fix(compaction): preserve hosted search metadata as text

* fix(compaction): bound hosted search notes and keep them assistant reference text

* fix(compaction): collect only the capped search note list entries

---------

Co-authored-by: panyuanyuan <panyuanyuan@hetao101.com>
… minting route (carry #6741) (#6804)

* fix(claude): carry a provider's own encrypted reasoning through the Claude route

On the translated Claude Messages route a Responses provider's native
encrypted_content was discarded on the way out, and nothing could carry it
back: the body is store:false and Claude Code replays only the thinking
block. The routed model lost its own reasoning every turn (#6736).

Keep the native blob in the thinking block's ocxr1 envelope as `nat`, with
the client-facing model and the provider's item id, and emit that block even
when no summary arrived. Inbound restores it as encrypted_content and id
only for a request naming the same model; any other model gets the visible
text alone. Translated bodies that reason now request
include: ["reasoning.encrypted_content"], as Codex does.

Refs #6736

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(claude): bind native reasoning replay to serving route

* test(claude): verify native reasoning provenance and document replay boundary

* test(claude): cover absent reasoning and failover send order

* fix(claude): reserve native projection copies against the translator budget

* fix(claude): hold the decode reservation while re-encoding native projections

---------

Co-authored-by: rhomat27 <8294456+rhomat27@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Carry #6745 onto current OAuth refresh coordination.
Sanitize cancellation and transport failures, bound token bodies and deadlines,
and cover listener cleanup, generation fences and recovery regressions.

Carries #6745.

Co-authored-by: 김상훈 <luvs01@hanmail.net>
…moval (#6797)

* docs(devlog): L7 CI/infra stability roadmap

Docs-only roadmap for the L7 lane: Windows test-teardown ownership, test
sandbox caching, catalog/runtime and CI work-phases, and maintainer reports.

* fix(test): drain ACL work and close history before Windows fixture removal

Retain removal ownership across normal asynchronous ACL work, command gaps,
and deadline survivors. Synchronize policy fixtures at the initial policy load.

Drain fixture producers and both homes' config flights, close request history,
then drain ACL work before removal. Preserve failed roots and restore environment
in finally. Extract management-auth fixtures, await WebSocket closure, and carry
retry-aware cleanup for the remaining audited fixtures.

Capture lexical and canonical removal identities before work starts and retain
them through settlement, including deadline survivors and changed aliases.

Co-authored-by: mashfromband <matsumoto.yukuhashi@gmail.com>
Co-authored-by: 김상훈 <luvs01@hanmail.net>

* test(layout): place the fixture teardown suite where its seed resolves

The membership oracle in tests/test-layout-tooling.test.ts rejects an explicit layout entry that disagrees with its regex seed. The seed resolves fixture-teardown-helper.test.ts to ci-workflows, beside test-sandbox-cleanup.test.ts; move it there and update both layout tables and the docs that cite its path.

* fix(test): drain the Anthropic instance fixture and budget Windows picker startup

Make Anthropic instance fixture disposal asynchronous and await producer,
config hardening, history, and ACL teardown before removing its isolated home.
Preserve state clears, protected-tree validation, environment restoration, and
idempotent disposal. Await every fixture disposer call in the affected tests.

Give the two real picker startup/disable tests watchdogMs(10_000) budgets.
Their measured Windows lifecycle-lock ACL and CA inspection costs reach 4.9 s
and 8.0-8.4 s, exceeding or approaching the implicit five-second budget.
Document the Anthropic fixture's use of the shared teardown helper.

Validation: 275 focused tests passed across 12 files; typecheck, privacy scan,
structure check, changed-file size audit, and diff whitespace check passed.
The full suite was not run, as scoped. Native Windows validation remains for CI.

---------

Co-authored-by: mashfromband <matsumoto.yukuhashi@gmail.com>
Co-authored-by: 김상훈 <luvs01@hanmail.net>
…en (#6796)

Carry the runtime portion of #6723: cancellable bounded Codex probes,
same-selection snapshots, guarded persistence, shared flights and retry cooldown.
Release owned translator accounting on request abort without changing prepared
transport verdicts or awaiting producer cancellation.

Own subprocess abort/deadline handling rather than execFile's built-in observer.
Reject the caller promptly while the existing bounded-subprocess helper reaps
actual exit, escalating SIGTERM to SIGKILL after the shared 2-second grace.
Readiness-synchronized Bun children prove termination even when SIGTERM is
ignored; Windows keeps forceful termination and still asserts exit.

Keep Windows removal ownership, Rust diagnostics and workflow changes in their
separate lanes. Refs #6671; this does not establish the Windows leak is resolved.

Co-authored-by: mashfromband <matsumoto.yukuhashi@gmail.com>
#6787)

* test(link): isolate the remote-prelude tests from a host-installed ocx

* test(link): document the stub ocx helper in the remote-prelude tests

Carries #6726 so it runs under repository CI.

Co-authored-by: Sungyong Cho <dev@sungyongcho.com>

---------

Co-authored-by: Sungyong Cho <dev@sungyongcho.com>
Carry #6779's Haiku wire pin and direct resolver regression. Cover the exact
model through captureRouteStaticPolicy and the resolver's fifth argument for
Responses, Chat and Anthropic inbound, attempted Chat/Responses overrides,
repeat resolution, sibling models and custom provider identity.

Update the source owner, Responses transport contract and English provider
guide to match OpenCode Go's documented Messages endpoint. The seven translated
guides contain no Go wire description and remain unchanged.

Verification: adapter-resolve red 20 pass / 2 fail before the source fix;
green 22 pass / 0 fail after. Layout 2 pass / 0 fail. Typecheck, privacy and
structure pass. Full suite and docs build deferred to coordinator CI under
this bounded lane's explicit validation scope.

Co-authored-by: agents-dev <306679077+agents-dev@users.noreply.github.com>
#6794)

* fix(catalog): refresh Azure metadata with captured discovery roots

Carry #6754 with all eight provider documentation locales and regenerated
OpenAI metadata. Refresh public Azure metadata during discovery with bounded
Accept-only requests that reject redirects and retain stale offline fallback.

Isolate snapshots, in-flight refreshes and retry cooldowns by resolved config
directory. Capture that directory at discovery admission and carry it through
refresh, upstream awaits, cached and retained hints, custom rows and combo members.
Include the directory in the gather flight identity so distinct roots cannot join.

Cache only upstream model evidence for Azure-enriched discovery results. Apply
root-specific metadata and configured retention after every fresh, stale and
failure-cooldown read so one upstream result serves A-to-B-to-A root switches
without leaking another root's enriched capabilities or limits.

Register the Azure regression suite in both layout tables. Cover snapshot,
flight, cooldown, pending-discovery and warm-cache root switches, plus a native
302 fixture that proves redirected loopback metadata is never requested.

Co-authored-by: x3M3x <amroeid1999@gmail.com>

* test(catalog): place the Azure metadata suite where its layout seed resolves

The ^azure- seed resolves azure-vendor-metadata.test.ts to providers, and the
membership oracle rejects an explicit entry that disagrees with its seed. Move
the suite to tests/providers/ and register it there in both layout tables.

Co-authored-by: x3M3x <amroeid1999@gmail.com>

---------

Co-authored-by: x3M3x <amroeid1999@gmail.com>
…#6789)

Carry #6765's fallback hint with installation-only error handling. Show the
known version's release link through textContent and a fixed GitHub URL,
including preview versions, and clear it for navigation or check errors.
Place desktop recovery guidance after the complete npm-cache section and
stop proxies through their owner; Get-Process is only an identification aid.

Verification:
- bun test tests/clients/desktop-update-surface.test.ts: old source 9 pass,
  2 fail (missing hint/link); fixed source 11 pass, 0 fail.
- bun run typecheck: exit 0.
- bun run privacy:scan: passed.
- bun run structure:check: passed.
- bun run --cwd docs-site build: exit 0; 569 pages, 79204 internal links.
- git diff --check: passed; four uncapped changed files remain below 2000 lines.
Full suite, hosted exact-head CI and native Tauri validation were not run.

Co-authored-by: Yum-wu <1172989563@qq.com>
Carry of #6750 onto current dev with review fixes.

A validated JEV choice now owns the first native Chat dispatch, including an
explicit no-effort choice; provider pins, caps and wire normalization still
apply downstream, and later targets do not ask the judge again.

Review fixes on top of the contributor's change:
- collapse adjacent identical segments in the Combo requested-effort label,
  so a provider pin that kept the JEV effort no longer logs high->low->low
- assert the native lane actually ran in the initial-effort wire matrix

Supersedes #6750

Co-authored-by: GeunwooJun <313474999+geunwoojun99@users.noreply.github.com>
…tions (#6791)

Carry of #6698 onto current dev with a review fix.

The System One / TypeSafe HTTP exchange moves from src/combos/jev.ts into
src/combos/jev-service-exchange.ts behind exchangeJevDecision(options,
prepare, parse); route state, choices and accounting stay route-owned.
Caller cancellation now takes precedence at every gate, HTTP error-body
cleanup no longer waits, and the extracted resolver uses the shared
jevDecisionEndpointUrl / isSystemOneEndpoint authority from #6731.

Review fix: drop a wall-clock assertion from the cancellation test. The
one-second race and the abort-reason identity checks already prove prompt
cancellation, and an elapsed-time bound flakes on loaded CI workers.

Supersedes #6698

Co-authored-by: GeunwooJun <313474999+geunwoojun99@users.noreply.github.com>
…6751) (#6798)

* fix(responses): retain child-owned prepaid send reservations

Carry of #6751 onto current dev with a parity regression.

With transientRetryOn5xx.attempts: 1, a Combo prepaid its target's first
send and immediately spent the permit, so the child computed a zero send
allowance and answered a local 429 without reaching the provider. The child
now owns its exact prepaid booking until physical dispatch: HTTP receipts
settle after final local admission, WS receipts after the frame is sent,
adapter-owned transports through a live dispatch view, and hosted
search/image/video producers keep the same owner. Unsent bookings are
released; target-local totals still intersect the shared ceilings. #6763's
reporter remains the accounting path whenever spend enforcement is active.

Added here: a regression that a two-round hosted web-search turn makes the
same model sends (two) for a direct request and a Combo target under
attempts: 1, so the child-owned booking keeps parity with the direct path.

Supersedes #6751

Co-authored-by: GeunwooJun <313474999+geunwoojun99@users.noreply.github.com>

* fix(responses): admit WS receipts before send and own Combo 403 hops

Review fixes for the #6751 carry.

- Codex WebSocket: the physical-dispatch receipt now runs before the frame
  is sent. A refused receipt rejects before any frame leaves, without an
  SSE fallback. One receipt covers a WS attempt and its HTTP fallback, so a
  frame that never left is not charged twice. If WS send throws and the
  HTTP fallback then refuses before dispatch, the booking stays charged
  with no physical send; that conservative case is pinned by a test.
- Antigravity 403 verification retry: a Combo child now hands the sibling
  hop to the sidecar owner, the same as the 429 path, so a retry stopped
  before dispatch releases its booking.

Co-authored-by: GeunwooJun <313474999+geunwoojun99@users.noreply.github.com>

* docs(responses): say the WebSocket receipt runs before the frame is sent

Co-authored-by: GeunwooJun <313474999+geunwoojun99@users.noreply.github.com>

---------

Co-authored-by: GeunwooJun <313474999+geunwoojun99@users.noreply.github.com>
…us, doctor and resolve (#6802)

* docs(devlog): plan L1 desktop sidecar CLI authority roadmap

* docs(devlog): fold L1 audit rounds into the roadmap

* docs(devlog): lock the L1 contract index

* docs(devlog): wp2 execution packets

* docs(devlog): fold wp2 packet audit

* feat(service): recognize live Desktop supervision without an ownership claim

* fix(cli): report the Desktop supervisor and stop recommending a competing service

* fix(gui): hide service actions while OpenCodex Desktop runs the proxy

* docs: describe Desktop supervision for CLI status and startup safety

* fix(cli): bind the supervision override to the live runtime and keep localized GUI guidance

* fix(service): recheck ownership after the final supervision probe; keep custom gateway guidance first
…box (#6805)

Own the default executable cache beneath the exclusive test root, preserve
explicit overrides, and inherit the selected cache across nested homes.
Cover cache permissions, independent lifetimes, legacy directories and links,
and real Bun children. Warm the affected child graphs and bound synchronous
children without extending their test deadlines. Keep the GUI typecheck gate
in a dedicated serial lane and retain wp1's config drain in desktop fixtures.

Co-authored-by: 김상훈 <luvs01@hanmail.net>
…e version skew (#6807)

* docs(devlog): carry the L1 plan unit for the launcher PR

* docs(devlog): wp3 execution packets

* docs(devlog): fold wp3 packet audit

* fix(launcher): fall back to a validated PATH Bun when the bundled runtime is missing

* feat(cli): warn once when a lifecycle command runs against a different proxy version

* docs: document the PATH Bun fallback and the lifecycle version notice

* docs(devlog): close wp3

* docs(devlog): sync the L1 plan unit

* test: pin the launcher's install guard and keep Windows dotenv paths verbatim

* docs(devlog): point the PATH installer follow-up at its owner

* fix(launcher): give the PATH Bun fallback a cold-start budget
…ice, update, start and stop (#6809)

* fix(service): refuse service activation while OpenCodex Desktop runs the proxy

* fix(update): leave a Desktop-supervised runtime and its package alone

* fix(cli): explain Desktop supervision on start, stop and restart

* docs: describe the Desktop supervision command guards

* test: follow the guarded service calls in source-oracle tests
…d recovery to it (carry #6774) (#6811)

* fix(codex): serialize config writes and bind recovery to locked journal

Coordinate cooperating config writers through one explicit lock handle.
Fence stale-lock takeover and initialization, and select journal replay
and live-owner checks within the same config write section.

Stub quota transport in two metadata-only test fixtures; retain every
assertion and timeout while keeping synthetic credentials offline.

Carries the Codex config writer work from c7ac1a0,
with reproduced lock takeover and journal selection regressions fixed.

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(codex): harden the config write lock carry

Key the lock by the canonical write destination and revalidate it
immediately before every rename, including prompt durable writes and the
Windows replace retries. Keep journal selection, recovery, removal and
cleanup inside one held section, and leave an absent Codex home alone.

Record host and process-start evidence with each lock and claim. Only a
same-host owner proven dead is taken over; foreign-host, hostless and
unverifiable records report a non-retryable unsafe state naming the lock.
Validate namespace types and POSIX ownership; on Windows the claims
directory is hardened through the existing ACL helper.

Bound acquisition with a finite timeout on a monotonic clock, release the
prompt store lock when config acquisition throws, and pin native feature
children to the held canonical home. A native transition refuses when the
locked file is not config.toml, and an alias retarget during the child
restores the locked file from its preimage.

Co-authored-by: 김상훈 <luvs01@hanmail.net>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(codex): recover pre-staging config on native validation failures

Capture canonical bytes or absence before transition staging and protect all
later validations, publications, child errors, and postconditions in one
recovery scope. Restore only the witnessed canonical destination; retain the
original private preimage when replacement makes recovery unsafe.

Cover alias retargets before wrapper entry and initial spawn validation,
canonical replacement before spawn, and failed standalone toggle rollback.

Co-authored-by: 김상훈 <luvs01@hanmail.net>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* test(codex): preserve recovery journal after unreadable profile compensation

The locked compensation hardening deliberately defers journal restoration
until both config and profile are restored. The integration expectation still
assumed independent journal restoration from origin/dev and the #6774 carry
(51c1f18), so a real EACCES on the profile produced the additional journal
entry and failed hosted CI despite preserving all current bytes.

Retain production behavior: the wp3 contract requires the current journal to
remain recovery authority when artifact compensation fails. Update the
expected deferred journal diagnostic and cover matching, absent, and different
journal preimages, asserting that the current journal survives in every case.
Historical-function replay confirms that the older compensation deletes a
current journal for an absent preimage after the profile restore has failed.

Co-authored-by: 김상훈 <luvs01@hanmail.net>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(codex): pass rename validation through a hooks object

The Lab activation walk follows free calls; an optional callback parameter invoked as a free call has no declaration to inspect. Carry it as hooks.validateBeforeRename like the atomic writer does.

Co-authored-by: 김상훈 <luvs01@hanmail.net>

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* Avoid per-acquisition Windows subprocesses in config write locks

Cache lazy owner identity probes, including unavailable results, and probe other process starts only when liveness permits takeover. Rely on profile ACLs for claims directories and separate contender startup from acquisition deadlines.

Co-authored-by: 김상훈 <luvs01@hanmail.net>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(codex): acquire Windows config locks without PowerShell identity probes

Resolve reg.exe through the trusted Windows system directory and query
MachineGuid with argv, strict parsing, a three-second timeout and a
process-local cache. Read Linux machine-id files directly; retain macOS
identity probes.

Record this Windows process's start identity as unknown without spawning.
Missing start evidence disables only the PID-reuse comparison: live or
unknown PIDs remain busy, while matching-host owners proven dead twice
remain recoverable past the grace window. Failed host discovery still
publishes hostless records that later contenders must preserve as unsafe.

Cover registry parsing, command failure, caching, trusted executable
resolution, and unknown-start takeover. Align Windows journal and unsafe
writer fixtures with the canonical production home; retain the contention
deadline while separately bounding successful Windows initialization.
Document the identity sources and conservative recovery contract.

Co-authored-by: 김상훈 <luvs01@hanmail.net>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(tests): isolate Windows Codex home aliases

Only set, inspect, and restore Codex_Home on platforms with case-sensitive
environment names. On Windows that assignment overwrites CODEX_HOME and
makes the held-home fixture operate on B instead of A. Keep the ORCA override
removal assertion on every platform and retain the POSIX case-variant checks.

Strip all inherited CODEX_HOME case variants before spawning the injector
fixture. A duplicate Windows environment name can select the inherited home,
where v2 is off, so reconciliation never calls the toggle. Preserve the
injector result and effective home in diagnostics even when no child ran.
The legacy eligibility mock bypasses coordinator namespace admission, and
the canonical junction/lock checks succeed with the isolated environment;
no production-path change is needed for this fixture defect.

Verification with Bun 1.4.0 on macOS:
- Simulated case-insensitive child environment: 0 pass / 1 fail before the
  environment cleanup, 1 pass / 0 fail after it; effective home and skipped
  toggle matched the Windows failure mechanism. Native Windows not rerun.
- bun scripts/test.ts with codex-config-write-lock, codex-prompt-lock,
  codex-inject-write-lock, codex-v2-gate, both layout files, and file-size
  ratchet: 305 pass / 1 skip / 0 fail across seven files.
- bun run typecheck: exit 0.

Co-authored-by: 김상훈 <luvs01@hanmail.net>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(codex): canonicalize lock destinations with native realpath

On Windows the JavaScript realpath can leave 8.3 short components unexpanded, so the same config could canonicalize to different strings depending on whether the file existed, and a held handle was refused as unsafe. Use realpathSync.native for every lock destination, home and alias comparison, as the Codex path module already does. Reproduced and verified with an 8.3 TEMP on a native Windows host.

Co-authored-by: 김상훈 <luvs01@hanmail.net>

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(codex): return contention for Windows lock sharing violations

Retry claim, reservation, evidence and quarantine filesystem operations through
the existing bounded Windows retry envelope. Exhaustion stays busy and cannot
authorize takeover, including sharing contention followed by EEXIST.
Revalidate the release token before each retry and preserve writer errors.

Co-authored-by: 김상훈 <luvs01@hanmail.net>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(codex): recover abandoned claims and revalidate every retry

Remember completed local reservations whose bounded cleanup fails and
retry their removal before acquisition, preserving active reservations.
Revalidate captured parent and entry identities and exact claim evidence
before destructive attempts so replacements survive retry sleeps.
Preserve normal ENOENT handling when a scanned peer releases its claim.

Co-authored-by: 김상훈 <luvs01@hanmail.net>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(codex): fence stale lock takeover and cleanup retries

Share claim evidence guards with reusable prompt/config locks. Revalidate
observed bytes, inode and parent before every takeover or cleanup attempt,
and bind exclusive creation and release retries to their captured namespace.
Cover sharing-error replacement races deterministically on all three codes.

Co-authored-by: 김상훈 <luvs01@hanmail.net>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(codex): keep malformed stale lock records as unsafe evidence

The fenced stale-record reader parsed the observed body without the token and pid shape gate, so an expired dead-owner record missing its token could be quarantined. Apply the same gate as readRecord.

Co-authored-by: 김상훈 <luvs01@hanmail.net>

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(codex): carry Windows retry callbacks as step members

The Lab activation walk follows free calls and cannot inspect callback parameters. Pass the operation and its observers in one step object, as rename validation already does.

Co-authored-by: 김상훈 <luvs01@hanmail.net>

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

---------

Co-authored-by: 김상훈 <luvs01@hanmail.net>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
…tion (#6819)

With ultraFastTier enabled, a regenerated routed row was rebuilt from the native template with Fast-only tiers, and the merge dropped the persisted row, so an operator-supplied ultrafast declaration was lost on every sync or convergence. The shared observed-state merge now carries only the exact persisted routed row's Ultra Fast entries (first-win on duplicate slugs) after admission filters, using the opt-in passed explicitly from both writers. Disabling the setting removes Ultra Fast from ordinary routed rows.

Closes #6817

Co-authored-by: JUN <lidge-jun@users.noreply.github.com>
* fix(codex): treat a missing Codex home as nothing to restore

Skip native restore, removal and journal recovery before ownership checks and configuration locks when the home is proven absent. Preserve writer refusal and bootstrap behavior, return typed missing-parent lock failures, and cover isolated missing-home restore and stop regressions.

* fix(codex): preserve missing homes when native toggles and prompt commits fail

* fix(codex): keep a prepared Codex home instead of removing it by path

A pathname-based removal cannot prove it still names the directory this request created, so a failed toggle or prompt commit could delete a concurrent replacement. Keep the empty home, which is what Codex itself creates; executable resolution still happens before any home is prepared.

* fix(cli): keep the shutdown external-provider gate in place

The missing-home check belongs inside the restore attempt; the external-provider gate stays on the teardown condition the dispatch source contract pins.
* feat(logs): unwrap pasted codex://threads links in conversation search

Codex's copy-session-link clipboard carries a codex://threads/<id> deep link while clients send the bare thread id on the wire. Unwrap the wrapper inside the shared conversation matcher so the Logs conversation field, /api/logs?conversationId, and ocx logs filter --conversation all match the bare id (direct or via its persisted digest) without changing what is persisted.

Co-Authored-By: Epinephrine <luvs01@hanmail.net>
(cherry picked from commit 19a0f35)

* fix(logs): drop query metadata and bound unwrap of codex://threads links

Review feedback on #711: codex://threads/<id>?hostId=… pastes kept the
query string in the candidate id so neither raw-id nor digest matching
worked, and the lazy-wildcard regex had quadratic backtracking on
malformed slash-flooded inputs run per log row.

unwrapLogConversationQuery is now a bounded (512-char) linear scan: cut
at ? or #, strip trailing slashes, and only return a single-segment id.
Regression cases cover durable and percent-encoded remote-control hostId
values across the dashboard matcher, GET /api/logs conversationId, and
ocx logs filter --conversation.

Co-Authored-By: Epinephrine <luvs01@hanmail.net>
(cherry picked from commit 6d8225f)

* fix(logs): keep literal codex://threads session ids searchable

Devin Review on #711: a client that literally sends a codex://threads/…
session id has it hashed whole for storage, but unwrapping the paste
before hashing meant that digest could never match again — the unwrap
must add a match path, not replace one.

logConversationQueryCandidates now yields the unwrapped id AND the
untouched paste; the server matcher tries each (direct + digest) and the
GUI hashes every candidate so filterLogs gets both digests.

Co-Authored-By: Epinephrine <luvs01@hanmail.net>
(cherry picked from commit 0df8335)

* fix(logs): batch conversation-query digests with Promise.all

React Doctor flagged the sequential await-in-loop in
hashLogConversationQuery; candidates are independent, so map them
through crypto.subtle.digest concurrently and keep result order.

Co-Authored-By: Devin AI <devin-ai-integration[bot]@users.noreply.github.com>
(cherry picked from commit a600bf2)

* docs(logs): record pasted thread-link search contract

Record the conversation filter contract for the work from luvs01#711, including literal URI compatibility and input bounds. The four original commits remain separately cherry-picked with their author identities and source SHA trailers.

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Epinephrine <27862058+luvs01@users.noreply.github.com>

---------

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Devin AI <devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Codex <codex@users.noreply.github.com>
Co-authored-by: Epinephrine <27862058+luvs01@users.noreply.github.com>
…onc (carry #6801) (#6823)

GET /api/codex-agent-roles returns each role's effort, PUT with an effort also writes "[codex]".agents.<role>.reasoning in omo.jsonc (none -> off; a level LazyCodex lacks removes a stale reasoning; a model-only save keeps it), and ocx agent roles set accepts --effort. An empty --effort is refused before any request, and the omo.jsonc contract in structure/clients/integrations.md describes the reasoning mirror.

Carries #6801.

Co-authored-by: LilMGenius <smsmeee@naver.com>
… (stale) (#6825)

Sync refreshes only profiles whose preference is on, so an "off (stale)" Aside profile left `ocx integration client sync --client aside` printing a bare no-op. The empty result now names the status command and the preview-then-enable commands, and status (list and --profile) prints them with the real ID for each off profile beside a stale block. Nothing is re-enabled; no request is added; --json output is unchanged. A malformed asideProfileSync still falls back to all profiles off, and the config load now says so once without echoing the value. Includes the N5 sweep plan unit.

Closes #6757
…to a full record fingerprint (#6808)

* docs(devlog): L2 service/restart/config-journal carry roadmap

* docs(devlog): lock L2 roadmap after independent audit

* docs(devlog): wp2 P revalidation

* docs(devlog): wp2 L1 overlap and integration seam

* fix(cli): bind update restart admission to frozen service records

Fingerprint every service-state candidate and POSIX definition, verify inactive supervision within the transaction deadline, and enforce the frozen handoff at parent and child checkpoints.

Co-authored-by: agentHits <140916359+agentHits@users.noreply.github.com>

* fix(cli): close admission deadline checks and document inactive-service restarts

Recheck deadlines after the final home fingerprint and child admission evidence; cover present service definitions and align lifecycle guidance with the frozen service-record contract.

Co-authored-by: agentHits <140916359+agentHits@users.noreply.github.com>

* fix(cli): harden update restart admission probes and record reads

Resolve manager probes from trusted absolute locations, bound descriptor reads to 1 MiB after checking file identity, and share explicit SSH user-bus discovery across parent and child admission.

Co-authored-by: agentHits <140916359+agentHits@users.noreply.github.com>

* docs(devlog): wp4 review disposition (no root deletion, single admission)

* fix(service): treat empty systemd runtime directory as absent

Co-authored-by: agentHits <140916359+agentHits@users.noreply.github.com>

* test(cli): skip the chmod-only fingerprint edit on Windows

Windows chmod only toggles the read-only bit, so 0o644 to 0o600 is not an observable edit there. Name each edit in the assertion so a platform-specific miss is identifiable.

Co-authored-by: agentHits <140916359+agentHits@users.noreply.github.com>

* test(cli): make fingerprint read drift observable by size

NTFS updates last-write time lazily for an open handle; a different-length rewrite keeps the drift case deterministic on Windows. Name each edit in the assertion.

Co-authored-by: agentHits <140916359+agentHits@users.noreply.github.com>

* test(cli): preserve Desktop veto with inactive service admission

Cover unchanged installed service records when Desktop supervision appears before stop, is present initially, or is absent, through the production transaction and standalone validator on macOS and Linux.

Co-authored-by: agentHits <140916359+agentHits@users.noreply.github.com>

* test(codex): await contender results before releasing prompt lock

Use atomic result publication to signal completed acquisition, with a 30-second hang ceiling and a longer owner hold guard. Preserve the at-most-one live owner assertion and usable retry check.

Co-authored-by: agentHits <140916359+agentHits@users.noreply.github.com>

* fix(codex): treat a vanished claims directory as lock contention

Under contention a peer's final directory removal can delete the claims
directory between the identity check and the link into it. Linux reports
ENOENT, which already meant busy; macOS link reports EINVAL, which escaped
tryAcquire and crashed the contender. Treat EINVAL as busy when the claims
directory is gone or replaced. The contenders test now reports a crashed
child's exit and stderr instead of only timing out. Reproduced locally:
3 crashed rounds in 60 before, 0 in 80 after.

Co-authored-by: agentHits <140916359+agentHits@users.noreply.github.com>

---------

Co-authored-by: agentHits <140916359+agentHits@users.noreply.github.com>
* docs(devlog): plan the Desktop-owned ocx command on PATH

* docs(devlog): wp1 execution plan

* feat(desktop): install a Desktop-owned ocx command on PATH

* fix(desktop): Windows lint and fixture path escaping in the terminal command

* test(desktop): check other-platform record fixtures against the real Windows host

* test(desktop): only a bundle-less tombstone is valid across platforms

* test(desktop): real zsh and bash select the Desktop shim on a temporary HOME

* docs(devlog): wp1 outcome

* docs(devlog): plan the PR 1 review fixes

* fix(desktop): harden the terminal command against crashes, ACLs and stale page state

* test(desktop): build an exact unprotected root for the Windows ACL negative case

* docs(structure): record the terminal command's crash, ACL and broadcast rules

* fix(desktop): observe the current bundle on every enabled reconcile

* docs(devlog): PR 1 review fix outcome

* docs(devlog): wp4 landing plan

* fix(desktop): set the Windows private DACL natively instead of running icacls

* docs(structure): move the terminal command contract into its own document
lidge-jun and others added 14 commits October 10, 2026 06:06
…ion test) (#6847)

* fix: carry remaining #6723 log admission split and fixture drain

39663ff's BigInt picker identity check is already on dev via #6772, so this
keeps that implementation. The rest of the commit that still applies moves the
log-cursor cases into a registered sibling under the current fixture drain,
waits for ACL work before model-arrival fixture removal, and records the
bigint file-id comparison in the Claude Desktop contract. The diagnostic-crate
hunks stay with #6806.

Co-authored-by: mashfromband <matsumoto.yukuhashi@gmail.com>

* fix: keep the test-layout map under the file-size ratchet

The new log-admission entry shares a line with the management-auth entry so
scripts/test-layout/layout.json stays at 1999 lines.

Co-authored-by: mashfromband <matsumoto.yukuhashi@gmail.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: mashfromband <matsumoto.yukuhashi@gmail.com>
* feat(claude): treat long windows as 1M on every Claude surface

Claude Code accounts an unmarked gateway id at 200k, so GPT-6 natives
opted into their 872k window showed as 200k in the Desktop Code-tab
picker, the cc picker, Desktop 3P and generated subagents. Those
surfaces only marked windows of 1M or more, because their runner may
lack CLAUDE_CODE_AUTO_COMPACT_WINDOW.

With overflow now answered as "prompt is too long", which Claude Code
compacts on, they share one rule (src/claude/long-context.ts): a window
of 1M, or one that can host the 829,800 default compact window, gets the
[1m] selector, supports1m/prefer1m, a discovery 1M row and a marked
subagent selector. The floor is fixed, so a custom compact window cannot
re-admit a 372k route (#854). Anthropic rows of either pool still need a
genuine 1M, and a discovery variant reports the real input ceiling.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(claude): key the genuine-1M exception on Claude models, not the pool name

Review follow-up. The real-Anthropic exception checked only the provider
name, so a configured gateway named anthropic2 serving other models lost
the long-window rule, while generated and forced subagent markers ignored
the exception entirely and could widen a capped Pool 2 Claude row listed
by a connected launch's catalog windows.

isAnthropicClaudeRoute now requires an Anthropic instance name and a
claude-* model id; pickers, discovery, Desktop 3P, the launch window map
and both subagent paths use it, and a bare claude-* selector counts as
Anthropic.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(claude): leave the launch window map filter as it was

The launch path pairs [1m] with CLAUDE_CODE_AUTO_COMPACT_WINDOW and is not
one of the unpaired surfaces this layer widens, so its Anthropic filter
goes back to the original provider === "anthropic" check. The Claude-model
exception stays on the unpaired surfaces, where a capped Claude row keeps
its previous 200k accounting.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(claude): document long-window 1M marking in the Claude Code guides

English and the six translated guides now say that a window of 1M or at
least the 829,800 default compaction threshold gets the [1m] row, that the
floor is fixed, that Claude models on an Anthropic route need a genuine 1M,
and that an overflow is recovered by Claude Code's own compaction.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(claude): separate the fixed picker floor from launch-slot marking

Discovery and Desktop picker rows use the fixed 829,800-token floor.
Launch env slots follow the configured compact threshold. Forced
subagents mark a non-Anthropic selector at that floor and keep the
genuine-1M rule for Anthropic Claude and bare claude-* ids.

Co-authored-by: JUN <jun@lidgeai.com>

* fix(test-layout): keep the long-context registration under the line cap

scripts/test-layout/layout.json is one line under the 2000-line ratchet.
The new eligibility entry shares a line with the surface-matrix registration,
the same pairing this file already uses, so the map stays at 1999 lines.

Co-authored-by: JUN <jun@lidgeai.com>

* docs(claude): limit the genuine-1M exception to Claude models

The picker contract requires a genuine 1M only for Claude models on either
Anthropic pool. A non-Claude model on that route still follows the 829,800
floor. The Desktop structure note, the eligibility test header, and the
Chinese and Turkish guides said otherwise.

Co-authored-by: JUN <jun@lidgeai.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
* docs(devlog): amend the context-accounting plan after layer 2 review

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat(claude): add a 200k context-accounting opt-in

claudeCode.contextAccounting decides what opencodex picks by default on
Claude surfaces. Absent (1m, the default) keeps long-window models at 1M.
"200k" opts out everywhere at once: resolveAutoContext returns a mode under
which nothing is marked [1m] automatically and no compact window is
injected, the Desktop pickers leave rows unmarked, Desktop 3P keeps
supports1m but drops prefer1m, and generated or forced subagents keep an
unmarked selector bare. A selector the user marks [1m] keeps it, and
discovery still lists genuine 1M rows as a choice.

Settable with `ocx claude config set --context-accounting <1m|200k>` and
PUT /api/claude-code ("1m" drops the key, other values are a 400); GET
reports it and a change re-applies the system env. Documented in the Claude
Code guides.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(claude): state what the 200k opt-in keeps and what it leaves alone

Review follow-up: an explicit [1m] stays available but generated and forced
subagents still drop a marker the window cannot carry, and an exported
compact window no longer re-enables automatic marking while opencodex
leaves the export itself in place.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(structure): record the 200k context-accounting opt-in

The Claude Desktop, subagent, config, and management-API contracts now
state that claudeCode.contextAccounting "200k" stops automatic 1M
marking while an explicit marker and genuine 1M discovery rows stay.

Co-authored-by: JUN <jun@lidgeai.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
…6782)

* feat(gui): add a Context accounting control to the Claude Code page

The Claude Code settings page gets a 1M (default) / 200k select for
claudeCode.contextAccounting. Under 200k the auto-context and
auto-summarize rows are hidden (they have no effect there) and the
manual env block stops exporting a compact window, matching what the
runtime injects. A state cached by an older proxy, or read from one,
normalizes to the 1m default. Strings are added to all eleven locales.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(gui): describe the 200k opt-in precisely and complete test fixtures

Review follow-up: the description now says 200k only stops automatic 1M
marking (an explicit 1M row and a context override still apply), and the
two component fixtures that mount the settings card directly carry the
new field.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* test(gui): treat the 200k token-count label as intentional in the French guard

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(gui): keep the Claude quickstart on one accounting snapshot

Selecting 200k dropped the compact window while the pasted model ids
still carried the server's automatic [1m] marks. The snippet now strips
those marks, keeps an explicit [1m], and omits the compact window until
the model env was built under the same policy.

Co-authored-by: JUN <jun@lidgeai.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
A cold bun.exe on Windows spent 13.2s loading src/cli/index.ts, past the
12s spawnSync literal, and returned ETIMEDOUT. Pay that graph in beforeAll
and time the badge child against the shared internal deadline.

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
…er concurrency (#6860)

Track transient Codex failures as a 60-second ratio so concurrent completions
can steer new threads without dropping a bound thread or a manual pin.
Cross-turn WebSocket reuse stays off unless it is explicitly enabled.

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
…6862)

A loaded windows-latest runner starts pwsh.exe past the 15s internal
deadline, so the caller-token restore sees a null status. The shell is
the assertion, so the wait uses the shared spawn budget minus that
deadline on win32, including the aged-lock ready file.

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
…get (#6863)

A loaded windows-latest runner missed the 2s PATH Bun deadline and spent
the product 5s probe on a freshly copied bun.exe. The direct probe uses
the internal deadline on win32, that copy is warmed before the launcher
runs, and the identity powershell wait uses the shared spawn budget so
one slow query does not retry out the case.

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
…ase (#6861)

* test(temp): quarantine a final Windows EPERM instead of failing the case

The 15s remove budget is already the whole hosted-runner failure. On the last
EPERM, print holder diagnostics and, when no child of the test is alive,
rename the subtree into the contained run temp. The lane fails if that trash
is still locked when the sandbox root is removed.

Co-authored-by: JUN <jun@lidgeai.com>

* test(temp): ignore the lock probe when deciding to quarantine

The Windows child probe is itself a direct child of the test process, and
its command line does not name the temp directory. Counting it refused
every quarantine, so a final EPERM still failed the case.

Co-authored-by: JUN <jun@lidgeai.com>

* test(runtime): give the Windows PATH Bun probe the internal deadline

Windows 2 on this branch returned null from findPathBun at 2.4s against
the 2s deadline in bun-runtime.test.ts. On win32 that probe now uses
INTERNAL_DEADLINE_MS, the same bound as the launcher PATH check.

Co-authored-by: JUN <jun@lidgeai.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
…wrappers (#6852)

The Windows shim and service-script generators write a Bun that lives under the user profile as a %LOCALAPPDATA%/%USERPROFILE% token (src/lib/win-paths.ts), but three preflight assertions expected the literal process.execPath. They passed on CI, whose Bun sits in the tool cache, and failed on any Windows machine with Bun in the default profile location. The assertions now expect the complete `set "OCX_BUN=..."` line rendered the way the generators render it.
…6851)

* test(desktop): read only marked lines from the real-shell PATH probe

The ignored real_shell_selects_desktop_shim_on_temp_home test required exactly two stdout lines from `bash -l -i`. On Ubuntu, /etc/bash.bashrc prints the sudo hint to stdout for any sudo-group user without ~/.hushlogin, so the release-QA evidence test failed before it checked anything. The shell script now prints sentinel-prefixed result lines and exits non-zero if the lookup or the CLI fails; the assertions read only those lines.

* test(desktop): fail the real-shell probe on extra CLI output lines

End the marked output line with :OCX-END so a CLI that prints the expected line followed by another line no longer passes; verified by temporarily adding a second echo to the fixture CLI (zsh: wrong CLI output).
…#6855)

* docs(devlog): record the cross-OS probe of the desktop-owned CLI path

Plan, per-host execution notes and outcomes for probing #6802, #6807, #6809, #6812, #6816 and #6818 on Ubuntu 24.04 and Windows 11. Follow-ups: #6851, #6852, #6853, #6854.

* docs(devlog): tighten evidence citations and the F1 hypothesis

* docs(devlog): qualify unretained evidence in the probe outcome

* docs(devlog): record exact-head CI for the probe follow-ups

* docs(devlog): close the cross-OS probe unit and fold review fixes

* docs(devlog): align the P2 escape note and guard the probe cleanup paths
…ostic (#6806)

Adds .github/workflows/catalog-async-contracts.yml and the Rust contract crate under scripts/diagnostics/windows-version-control/, carrying the CI part of #6723. Portable contracts run the real Bun catalog modules on Linux, macOS and Windows; push runs are limited to dev/main/preview, PR runs cancel superseded runs, and the toolchain is pinned to 1.99.0.

Co-authored-by: mashfromband <matsumoto.yukuhashi@gmail.com>
@lidge-jun
lidge-jun requested a review from Ingwannu as a code owner October 10, 2026 08:31
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-10T08:59:22.262035Z 87e93b7 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Too many files!

This PR contains 630 files, which is 330 over the limit of 300.

To get a review, reduce the PR to 300 files or fewer by splitting it into smaller PRs or changing its base branch.

Usage-priced reviews support at most 300 files.

⚙️ Run configuration
  • Configuration used: Repository: lidge-jun/opencodex/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 7b8a73b2-bc07-41b0-9511-d047f6759706

📥 Commits

Reviewing files that changed from the base of the PR and between 19bd34a and 87e93b7.


⛔ Files ignored due to path filters (3)
  • desktop/src-tauri/Cargo.lock is excluded by !**/*.lock
  • scripts/diagnostics/windows-version-control/Cargo.lock is excluded by !**/*.lock
  • src/generated/model-metadata.ts is excluded by !**/generated/**

📒 Files selected for processing (630)
  • .github/workflows/catalog-async-contracts.yml
  • bin/ocx.mjs
  • desktop/src-tauri/Cargo.toml
  • desktop/src-tauri/src/cli_command.rs
  • desktop/src-tauri/src/cli_command_posix.rs
  • desktop/src-tauri/src/cli_command_record.rs
  • desktop/src-tauri/src/cli_command_windows.rs
  • desktop/src-tauri/src/lib.rs
  • desktop/src-tauri/src/startup.rs
  • desktop/src-tauri/src/tray.rs
  • desktop/src-tauri/src/window.rs
  • desktop/src-tauri/tauri.conf.json
  • desktop/ui/cli.html
  • desktop/ui/cli.js
  • desktop/ui/update.html
  • devlog/_fin/260808_metadata_pipeline_dejawcode/020_azure_context_refresh.md
  • devlog/_fin/261009_n3_test_infra/000_plan.md
  • devlog/_fin/261009_n3_test_infra/010_6775_client_home_isolation.md
  • devlog/_fin/261009_n3_test_infra/020_6777_combo_fixture.md
  • devlog/_fin/261009_n3_test_infra/030_6776_toggle_ownership_fixture.md
  • devlog/_fin/261010_cli_path_crossos_probe/000_plan.md
  • devlog/_fin/261010_cli_path_crossos_probe/001_host_baseline.md
  • devlog/_fin/261010_cli_path_crossos_probe/010_linux_probe.md
  • devlog/_fin/261010_cli_path_crossos_probe/011_wp2_execution.md
  • devlog/_fin/261010_cli_path_crossos_probe/019_wp2_outcome.md
  • devlog/_fin/261010_cli_path_crossos_probe/020_windows_probe.md
  • devlog/_fin/261010_cli_path_crossos_probe/021_wp3_execution.md
  • devlog/_fin/261010_cli_path_crossos_probe/029_wp3_outcome.md
  • devlog/_fin/261010_cli_path_crossos_probe/030_release_qa_matrix.md
  • devlog/_fin/261010_cli_path_crossos_probe/040_fixes_issues_closeout.md
  • devlog/_fin/261010_cli_path_crossos_probe/041_wp4_execution.md
  • devlog/_fin/261010_cli_path_crossos_probe/049_outcome.md
  • devlog/_plan/261009_L1-desktop-cli/000_plan.md
  • devlog/_plan/261009_L1-desktop-cli/001_evidence.md
  • devlog/_plan/261009_L1-desktop-cli/002_consultation.md
  • devlog/_plan/261009_L1-desktop-cli/003_contract_index.md
  • devlog/_plan/261009_L1-desktop-cli/010_supervision_evidence_projection.md
  • devlog/_plan/261009_L1-desktop-cli/011_wp2_execution_packets.md
  • devlog/_plan/261009_L1-desktop-cli/019_wp2_done.md
  • devlog/_plan/261009_L1-desktop-cli/020_command_guards.md
  • devlog/_plan/261009_L1-desktop-cli/021_wp5_execution_packets.md
  • devlog/_plan/261009_L1-desktop-cli/030_launcher_bun_fallback.md
  • devlog/_plan/261009_L1-desktop-cli/031_wp3_execution_packets.md
  • devlog/_plan/261009_L1-desktop-cli/039_wp3_done.md
  • devlog/_plan/261009_L1-desktop-cli/040_path_cli_decision_closeout.md
  • devlog/_plan/261009_L1-desktop-cli/041_wp4_cycle_plan.md
  • devlog/_plan/261009_L2-service-journal/010_overview.md
  • devlog/_plan/261009_L2-service-journal/020_6649_restart_admission.md
  • devlog/_plan/261009_L2-service-journal/030_6774_config_write_lock.md
  • devlog/_plan/261009_L2-service-journal/040_6695_runtime_write_preflight.md
  • devlog/_plan/261009_L5-auth-quota/000_roadmap.md
  • devlog/_plan/261009_L5-auth-quota/010_ollama_balance_quota.md
  • devlog/_plan/261009_L6-lazycodex/010_plan.md
  • devlog/_plan/261009_L7-ci-infra/000_plan.md
  • devlog/_plan/261009_L7-ci-infra/001_architect_reflection.md
  • devlog/_plan/261009_L7-ci-infra/010_wp1_windows_removal_ownership.md
  • devlog/_plan/261009_L7-ci-infra/020_wp2_transpiler_cache.md
  • devlog/_plan/261009_L7-ci-infra/030_wp3_link_test_isolation.md
  • devlog/_plan/261009_L7-ci-infra/040_wp4_catalog_async_budget.md
  • devlog/_plan/261009_L7-ci-infra/050_wp5_contracts_ci.md
  • devlog/_plan/261009_L7-ci-infra/060_wp6_provider_carries.md
  • devlog/_plan/261009_L7-ci-infra/070_wp7_desktop_and_reports.md
  • devlog/_plan/261009_claude_1m_default/000_plan.md
  • devlog/_plan/261009_claude_1m_default/010_prompt_too_long_envelope.md
  • devlog/_plan/261009_claude_1m_default/020_long_context_eligibility.md
  • devlog/_plan/261009_claude_1m_default/030_context_accounting_policy.md
  • devlog/_plan/261009_claude_1m_default/040_context_accounting_gui.md
  • devlog/_plan/261009_desktop_owned_path_cli/000_plan.md
  • devlog/_plan/261009_desktop_owned_path_cli/001_audit_evidence.md
  • devlog/_plan/261009_desktop_owned_path_cli/002_architecture.md
  • devlog/_plan/261009_desktop_owned_path_cli/003_reflection.md
  • devlog/_plan/261009_desktop_owned_path_cli/010_desktop_cli_command.md
  • devlog/_plan/261009_desktop_owned_path_cli/011_wp1_execution.md
  • devlog/_plan/261009_desktop_owned_path_cli/019_wp1_done.md
  • devlog/_plan/261009_desktop_owned_path_cli/020_launcher_handoff_and_diagnostics.md
  • devlog/_plan/261009_desktop_owned_path_cli/021_wp2_execution.md
  • devlog/_plan/261009_desktop_owned_path_cli/030_docs_review_merge.md
  • devlog/_plan/261009_desktop_owned_path_cli/031_wp3_review_fixes.md
  • devlog/_plan/261009_desktop_owned_path_cli/032_wp3_cycle1_outcome.md
  • devlog/_plan/261009_desktop_owned_path_cli/040_wp4_land.md
  • devlog/_plan/261009_desktop_owned_path_cli/049_outcome.md
  • devlog/_plan/261009_l3_compaction_responses/000_plan.md
  • devlog/_plan/261009_l3_compaction_responses/010_carry_6769_external_task_input.md
  • devlog/_plan/261009_l3_compaction_responses/020_carry_6746_hosted_search_compaction.md
  • devlog/_plan/261009_l3_compaction_responses/030_carry_6741_claude_native_reasoning.md
  • devlog/_plan/261009_n1_catalog_client/000_plan.md
  • devlog/_plan/261009_n1_catalog_client/010_carry_6801_role_effort.md
  • devlog/_plan/261009_n1_catalog_client/020_autorefresh_client_fanout.md
  • devlog/_plan/261009_n4_responses_quota/000_plan.md
  • devlog/_plan/261009_n4_responses_quota/010_spill_admission_headroom.md
  • devlog/_plan/261009_n4_responses_quota/020_main_quota_observation.md
  • devlog/_plan/261009_n5_small_sweep/000_plan.md
  • devlog/_plan/261009_n5_small_sweep/010_pr6734_thread_links.md
  • devlog/_plan/261009_n5_small_sweep/011_pr6734_review.md
  • devlog/_plan/261009_n5_small_sweep/020_pr6813_account_selection_carry.md
  • devlog/_plan/261009_n5_small_sweep/030_issue6757_aside_recovery.md
  • devlog/_plan/261009_n5_small_sweep/040_closeout.md
  • docs-site/src/content/docs/fr/guides/claude-code.md
  • docs-site/src/content/docs/fr/reference/configuration/providers.md
  • docs-site/src/content/docs/fr/troubleshooting/windows-memory.md
  • docs-site/src/content/docs/getting-started/installation.md
  • docs-site/src/content/docs/guides/claude-code.md
  • docs-site/src/content/docs/guides/codex-integration.md
  • docs-site/src/content/docs/guides/combos.md
  • docs-site/src/content/docs/guides/desktop-app.md
  • docs-site/src/content/docs/guides/integrations.md
  • docs-site/src/content/docs/guides/providers.md
  • docs-site/src/content/docs/guides/sub-agent-surface.md
  • docs-site/src/content/docs/guides/web-dashboard.md
  • docs-site/src/content/docs/ja/guides/claude-code.md
  • docs-site/src/content/docs/ja/reference/configuration/providers.md
  • docs-site/src/content/docs/ja/reference/management-api.md
  • docs-site/src/content/docs/ja/troubleshooting/windows-memory.md
  • docs-site/src/content/docs/ko/getting-started/installation.md
  • docs-site/src/content/docs/ko/guides/claude-code.md
  • docs-site/src/content/docs/ko/guides/desktop-app.md
  • docs-site/src/content/docs/ko/reference/configuration/providers.md
  • docs-site/src/content/docs/ko/reference/management-api.md
  • docs-site/src/content/docs/ko/troubleshooting/windows-memory.md
  • docs-site/src/content/docs/reference/adapters.md
  • docs-site/src/content/docs/reference/cli.md
  • docs-site/src/content/docs/reference/cli/agents.md
  • docs-site/src/content/docs/reference/cli/lifecycle.md
  • docs-site/src/content/docs/reference/cli/providers-accounts.md
  • docs-site/src/content/docs/reference/configuration/providers.md
  • docs-site/src/content/docs/reference/configuration/server.md
  • docs-site/src/content/docs/reference/management-api.md
  • docs-site/src/content/docs/reference/proxy-formats.md
  • docs-site/src/content/docs/ru/guides/claude-code.md
  • docs-site/src/content/docs/ru/reference/configuration/providers.md
  • docs-site/src/content/docs/ru/reference/management-api.md
  • docs-site/src/content/docs/ru/troubleshooting/windows-memory.md
  • docs-site/src/content/docs/tr/guides/claude-code.md
  • docs-site/src/content/docs/tr/reference/configuration/providers.md
  • docs-site/src/content/docs/tr/troubleshooting/windows-memory.md
  • docs-site/src/content/docs/troubleshooting/spend-ledger-synced-folder.md
  • docs-site/src/content/docs/troubleshooting/update-failed.md
  • docs-site/src/content/docs/troubleshooting/windows-memory.md
  • docs-site/src/content/docs/zh-cn/guides/claude-code.md
  • docs-site/src/content/docs/zh-cn/reference/configuration/providers.md
  • docs-site/src/content/docs/zh-cn/reference/management-api.md
  • docs-site/src/content/docs/zh-cn/troubleshooting/windows-memory.md
  • docs-site/src/content/docs/zh-tw/guides/claude-code.md
  • docs-site/src/content/docs/zh-tw/reference/configuration/providers.md
  • docs-site/src/content/docs/zh-tw/troubleshooting/windows-memory.md
  • gui/src/App.tsx
  • gui/src/components/sidebar-github-row.tsx
  • gui/src/i18n/de.ts
  • gui/src/i18n/en.ts
  • gui/src/i18n/fr.ts
  • gui/src/i18n/ja.ts
  • gui/src/i18n/ko.ts
  • gui/src/i18n/pt.ts
  • gui/src/i18n/ru.ts
  • gui/src/i18n/tr.ts
  • gui/src/i18n/vi.ts
  • gui/src/i18n/zh-TW.ts
  • gui/src/i18n/zh.ts
  • gui/src/lib/desktop-shell.ts
  • gui/src/log-conversation-id.ts
  • gui/src/pages/ClaudeCode.tsx
  • gui/src/pages/Integrations.tsx
  • gui/src/pages/Logs.tsx
  • gui/src/pages/claude-code-save.ts
  • gui/src/pages/claude-code-sections.tsx
  • gui/src/pages/claude-code-types.ts
  • gui/src/pages/claude-manual-env.ts
  • gui/src/pages/logs-filter.ts
  • gui/src/pages/startup-sections.tsx
  • gui/src/pages/startup-shared.ts
  • gui/src/startup-health-ui.ts
  • gui/src/styles/lazycodex-role-models.css
  • gui/tests/anthropic-instance-helper-controls.test.tsx
  • gui/tests/claude-code-save.test.ts
  • gui/tests/claude-code-sidecar-draft.test.tsx
  • gui/tests/desktop-shell.test.ts
  • gui/tests/fr-localization.test.ts
  • gui/tests/integrations-surfaces.test.tsx
  • gui/tests/locale-parity.test.ts
  • gui/tests/logs-filter-bar.test.ts
  • gui/tests/logs-filter.test.ts
  • package.json
  • scripts/diagnostics/windows-version-control/Cargo.toml
  • scripts/diagnostics/windows-version-control/README.md
  • scripts/diagnostics/windows-version-control/src/control.rs
  • scripts/diagnostics/windows-version-control/src/fixture.rs
  • scripts/diagnostics/windows-version-control/src/main.rs
  • scripts/diagnostics/windows-version-control/src/process.rs
  • scripts/diagnostics/windows-version-control/tests/async_contracts.rs
  • scripts/generate-model-metadata.ts
  • scripts/model-metadata.source.json
  • scripts/test-layout/layout.json
  • scripts/test-temp-lock.ts
  • scripts/test-temp.ts
  • scripts/test.ts
  • skills/ocx/references/01_surface_agents-routing.md
  • skills/ocx/references/01_surface_integrations.md
  • src/adapters/anthropic.ts
  • src/adapters/openai-responses/compaction-search-history.ts
  • src/adapters/openai-responses/passthrough.ts
  • src/adapters/openai-responses/tool-output-recovery.ts
  • src/claude/agents-inject.ts
  • src/claude/context-windows.ts
  • src/claude/desktop-3p.ts
  • src/claude/desktop-profile.ts
  • src/claude/gateway-cache.ts
  • src/claude/inbound.ts
  • src/claude/intercept/cli-catalog.ts
  • src/claude/intercept/picker-ca-persistence.ts
  • src/claude/intercept/picker-models.ts
  • src/claude/intercept/settings.ts
  • src/claude/long-context.ts
  • src/claude/model-info.ts
  • src/claude/outbound.ts
  • src/claude/subagent-model.ts
  • src/cli/agent.ts
  • src/cli/aside-profile-recovery.ts
  • src/cli/capabilities-base.ts
  • src/cli/capabilities-integrations.ts
  • src/cli/cli-path-diagnostics.ts
  • src/cli/desktop-runtime-guidance.ts
  • src/cli/dispatch.ts
  • src/cli/doctor.ts
  • src/cli/index.ts
  • src/cli/integration-aside-sync.ts
  • src/cli/integrations.ts
  • src/cli/resolve.ts
  • src/cli/root.ts
  • src/cli/status.ts
  • src/cli/update-restart-child.ts
  • src/cli/update-restart-home.ts
  • src/cli/update-restart-service-record.ts
  • src/cli/update-restart-supervision.ts
  • src/cli/update-restart.ts
  • src/cli/v2.ts
  • src/cli/version-skew-notice.ts
  • src/clients/lazycodex.ts
  • src/clients/omo-role-models.ts
  • src/codex/auth-api/account-selection.ts
  • src/codex/auth-api/routes.ts
  • src/codex/auth-context.ts
  • src/codex/autostart-health.ts
  • src/codex/catalog-auto-refresh-sources.ts
  • src/codex/catalog-auto-refresh.ts
  • src/codex/catalog.ts
  • src/codex/catalog/build-entries.ts
  • src/codex/catalog/bundled.ts
  • src/codex/catalog/combo-member.ts
  • src/codex/catalog/effort.ts
  • src/codex/catalog/gather-capture.ts
  • src/codex/catalog/model-hints.ts
  • src/codex/catalog/model-visibility.ts
  • src/codex/catalog/operator-tiers.ts
  • src/codex/catalog/provider-models.ts
  • src/codex/catalog/retained-sync.ts
  • src/codex/catalog/routed-gather.ts
  • src/codex/codex-home-owner.ts
  • src/codex/config-write-lock.ts
  • src/codex/convergence.ts
  • src/codex/features.ts
  • src/codex/inject-coordination.ts
  • src/codex/inject.ts
  • src/codex/inject/config-write-section.ts
  • src/codex/inject/multi-agent-v2.ts
  • src/codex/inject/remove.ts
  • src/codex/inject/restore.ts
  • src/codex/journal.ts
  • src/codex/main-account-cache.ts
  • src/codex/paths.ts
  • src/codex/prepared-home.ts
  • src/codex/prompt-journal.ts
  • src/codex/prompt-layers.ts
  • src/codex/prompt-lock-claim.ts
  • src/codex/prompt-lock-evidence.ts
  • src/codex/prompt-lock-io.ts
  • src/codex/prompt-lock-owner.ts
  • src/codex/prompt-lock.ts
  • src/codex/routing.ts
  • src/codex/routing/failure-window.ts
  • src/codex/routing/selection.ts
  • src/codex/runtime.ts
  • src/codex/shim.ts
  • src/combos/jev-service-exchange.ts
  • src/combos/jev.ts
  • src/config/atomic-write.ts
  • src/config/codex-ws-reuse-setting.ts
  • src/config/live-reconcile.ts
  • src/config/load-degrade.ts
  • src/config/rebase-provenance.ts
  • src/config/schema/config-schema.ts
  • src/grok/inject.ts
  • src/grok/sync.ts
  • src/images/loop.ts
  • src/integrations/aside-profiles.ts
  • src/integrations/catalog-refresh.ts
  • src/integrations/writer.ts
  • src/lib/bun-path-runtime.d.mts
  • src/lib/bun-path-runtime.mjs
  • src/lib/bun-runtime-preflight.ts
  • src/lib/desktop-cli-handoff.d.mts
  • src/lib/desktop-cli-handoff.mjs
  • src/lib/desktop-cli-record.d.mts
  • src/lib/desktop-cli-record.mjs
  • src/lib/request-execution-budget.ts
  • src/lib/synced-state-location.ts
  • src/lib/test-home-guard.ts
  • src/lib/translator-budget.ts
  • src/lib/windows-atomic-replace.ts
  • src/lib/windows-elevation.ts
  • src/lib/windows-secret-acl.ts
  • src/lib/winsw.ts
  • src/oauth/anthropic-account-refusal.ts
  • src/oauth/anthropic-routing.ts
  • src/oauth/anthropic-send-ownership.ts
  • src/oauth/chatgpt.ts
  • src/oauth/index.ts
  • src/oauth/store.ts
  • src/providers/azure-model-metadata.ts
  • src/providers/derive.ts
  • src/providers/quota.ts
  • src/providers/quota/vendor-probes-key.ts
  • src/responses/reasoning-envelope.ts
  • src/responses/reasoning-replay-cache.ts
  • src/responses/spill-store.ts
  • src/responses/state.ts
  • src/responses/state/metrics.ts
  • src/responses/state/spill-failure.ts
  • src/responses/state/spill-queue.ts
  • src/responses/task-input.ts
  • src/server/background-lifecycle.ts
  • src/server/chat-completions.ts
  • src/server/chat-native.ts
  • src/server/claude-messages.ts
  • src/server/inbound-body-admission.ts
  • src/server/index.ts
  • src/server/index/claude-intercept-lifecycle.ts
  • src/server/index/serve-options.ts
  • src/server/index/spend-ledger-lifecycle.ts
  • src/server/index/startup-warnings.ts
  • src/server/management/agent-settings-routes.ts
  • src/server/management/codex-agent-role-routes.ts
  • src/server/management/codex-prompt-routes.ts
  • src/server/management/codex-role-auto-assign.ts
  • src/server/management/config-routes.ts
  • src/server/management/context.ts
  • src/server/management/shared.ts
  • src/server/messages-native-oauth.ts
  • src/server/messages-native.ts
  • src/server/messages-response-headers.ts
  • src/server/request-log-conversation.ts
  • src/server/request-log.ts
  • src/server/responses/adapter-continuation.ts
  • src/server/responses/adapter-dispatch.ts
  • src/server/responses/codex-ws-exchange.ts
  • src/server/responses/codex-ws-pool.ts
  • src/server/responses/codex-ws-wire.ts
  • src/server/responses/combo-requested-effort.ts
  • src/server/responses/core-codex-account.ts
  • src/server/responses/core-combo-native.ts
  • src/server/responses/core-combo.ts
  • src/server/responses/core-lifetime.ts
  • src/server/responses/core-options.ts
  • src/server/responses/core-replay.ts
  • src/server/responses/core.ts
  • src/server/responses/fetch-helpers.ts
  • src/server/responses/passthrough-delivery.ts
  • src/server/responses/passthrough-dispatch.ts
  • src/server/responses/request-prepare.ts
  • src/server/responses/request-send-budget.ts
  • src/server/responses/response-effects.ts
  • src/server/responses/run-turn-execution.ts
  • src/server/responses/sidecar-execution.ts
  • src/server/responses/sidecar-send-budget.ts
  • src/server/responses/ws-upstream.ts
  • src/server/startup-health-cache.ts
  • src/server/workflow-refusal.ts
  • src/service/cli.ts
  • src/service/desktop-command-guard.ts
  • src/service/desktop-startup.ts
  • src/service/desktop-supervision.d.mts
  • src/service/desktop-supervision.mjs
  • src/service/managing-cli.ts
  • src/service/orchestration.ts
  • src/service/repair.ts
  • src/service/state.ts
  • src/service/systemd.ts
  • src/service/windows-ops.ts
  • src/storage/policy-job.ts
  • src/storage/policy-worker.ts
  • src/storage/policy.ts
  • src/types/config.ts
  • src/types/request.ts
  • src/types/wire.ts
  • src/update/index.ts
  • src/update/restart-ownership.ts
  • src/update/runtime-ownership.d.mts
  • src/update/runtime-ownership.mjs
  • src/web-search/loop.ts
  • structure/INDEX.md
  • structure/adapters/registry.md
  • structure/catalog.md
  • structure/cli-management.md
  • structure/clients/claude-desktop.md
  • structure/clients/integrations.md
  • structure/codex-home.md
  • structure/config.md
  • structure/dashboard-and-usage.md
  • structure/data-planes/images.md
  • structure/data-planes/inbound-compat.md
  • structure/data-planes/protocol-paths.md
  • structure/data-planes/search.md
  • structure/desktop-shell.md
  • structure/desktop-terminal-command.md
  • structure/gui-and-management-api.md
  • structure/manifest.json
  • structure/ops/cross-platform-ci.md
  • structure/ops/docs-and-release.md
  • structure/ops/plugins.md
  • structure/ops/service-and-sidecars.md
  • structure/ops/test-sandbox-cleanup.md
  • structure/providers-and-adapters.md
  • structure/providers/anthropic-account-pool.md
  • structure/providers/chat-compat.md
  • structure/providers/jev-decision.md
  • structure/providers/openai-accounts.md
  • structure/providers/openai-tiers.md
  • structure/providers/xai-grok.md
  • structure/runtime.md
  • structure/subagents.md
  • structure/transports/byte-accounting.md
  • structure/transports/inventory.md
  • structure/transports/responses-failover.md
  • structure/transports/responses-spend.md
  • structure/transports/responses-wire-shapes.md
  • structure/transports/responses.md
  • structure/transports/streaming-health.md
  • tests/adapters/anthropic/anthropic-instance-isolation.test.ts
  • tests/adapters/anthropic/anthropic-instance-pool-parity.test.ts
  • tests/adapters/anthropic/anthropic-instance-quota.test.ts
  • tests/adapters/anthropic/anthropic-instance-recovery.test.ts
  • tests/adapters/anthropic/anthropic-message-stop-termination.test.ts
  • tests/adapters/anthropic/anthropic-revoked-token-boundaries.test.ts
  • tests/adapters/anthropic/anthropic-revoked-token-continuation.test.ts
  • tests/adapters/anthropic/anthropic-revoked-token-sidecars.test.ts
  • tests/adapters/anthropic/anthropic-revoked-token.test.ts
  • tests/adapters/anthropic/anthropic2-fast-parity.test.ts
  • tests/adapters/physical-send.test.ts
  • tests/adapters/translator-budget-lifetime.test.ts
  • tests/ci-workflows/bun-runtime.test.ts
  • tests/ci-workflows/ci-gui-typecheck-gate.test.ts
  • tests/ci-workflows/cold-spawn-warmup.test.ts
  • tests/ci-workflows/fixture-teardown-helper.test.ts
  • tests/ci-workflows/release-version-sources.test.ts
  • tests/ci-workflows/test-runner.test.ts
  • tests/ci-workflows/test-temp-quarantine.test.ts
  • tests/claude-integration/anthropic2-native-routing.test.ts
  • tests/claude-integration/claude-cli-picker.test.ts
  • tests/claude-integration/claude-cli.test.ts
  • tests/claude-integration/claude-config-home-isolation.test.ts
  • tests/claude-integration/claude-context-accounting.test.ts
  • tests/claude-integration/claude-desktop-first-party.test.ts
  • tests/claude-integration/claude-gateway-cache.test.ts
  • tests/claude-integration/claude-intercept-on-demand.test.ts
  • tests/claude-integration/claude-long-context-eligibility.test.ts
  • tests/claude-integration/claude-management-api.test.ts
  • tests/claude-integration/claude-messages-endpoint.test.ts
  • tests/claude-integration/claude-native-reasoning-continuity.test.ts
  • tests/claude-integration/claude-native-reasoning-provenance.test.ts
  • tests/claude-integration/claude-outbound.test.ts
  • tests/claude-integration/claude-picker-ca-store.test.ts
  • tests/claude-integration/claude-picker-models.test.ts
  • tests/claude-integration/claude-picker-recovery.test.ts
  • tests/claude-integration/claude-picker-startup.test.ts
  • tests/claude-integration/claude-prompt-too-long.test.ts
  • tests/claude-integration/claude-subagent-model-force.test.ts
  • tests/claude-integration/messages-native-oauth.test.ts
  • tests/claude-integration/messages-native.test.ts
  • tests/claude-integration/messages-request-id-endpoint.test.ts
  • tests/claude-integration/messages-request-id-headers.test.ts
  • tests/claude-integration/messages-revoked-token.test.ts
  • tests/cli/cli-aside-sync.test.ts
  • tests/cli/cli-dispatch.test.ts
  • tests/cli/cli-headless-parity.test.ts
  • tests/cli/cli-help-recovery.test.ts
  • tests/cli/cli-log-view-filter.test.ts
  • tests/cli/cli-path-diagnostics.test.ts
  • tests/cli/cli-ready-subprocess.test.ts
  • tests/cli/cli-resolve.test.ts
  • tests/cli/cli-restart-health.test.ts
  • tests/cli/cli-status-json.test.ts
  • tests/cli/cli-status-startup-health.test.ts
  • tests/cli/cli-stop-json.test.ts
  • tests/cli/cli-update-badge.test.ts
  • tests/cli/cli-update-restart-admission.test.ts
  • tests/cli/cli-update-restart-child.test.ts
  • tests/cli/cli-update-restart-desktop-service.test.ts
  • tests/cli/cli-update-restart-home.test.ts
  • tests/cli/cli-update-restart-service-record.test.ts
  • tests/cli/cli-update-restart-supervision.test.ts
  • tests/cli/cli-update-restart.test.ts
  • tests/cli/cli-version-skew.test.ts
  • tests/cli/ocx-launcher-desktop-handoff.test.ts
  • tests/cli/ocx-launcher-runtime.test.ts
  • tests/cli/ocx-launcher-source.test.ts
  • tests/cli/system-restart-client.test.ts
  • tests/clients/aside-profiles-catalog-refresh.test.ts
  • tests/clients/desktop-3p.test.ts
  • tests/clients/desktop-cli-command-surface.test.ts
  • tests/clients/desktop-update-surface.test.ts
  • tests/clients/integrations-writer-guard.test.ts
  • tests/clients/link-ssh-argv.test.ts
  • tests/clients/omo-role-models.test.ts
  • tests/clients/sync-client-integrations-unattended.test.ts
  • tests/codex-integration/catalog-async-lifetime.test.ts
  • tests/codex-integration/catalog-auto-refresh-client-fanout.test.ts
  • tests/codex-integration/catalog-auto-refresh-scheduler.test.ts
  • tests/codex-integration/catalog-remote-pull.test.ts
  • tests/codex-integration/catalog-slug-uniqueness-boundary.test.ts
  • tests/codex-integration/codex-account-selection-atomicity.test.ts
  • tests/codex-integration/codex-auth-api.test.ts
  • tests/codex-integration/codex-cli-update-launcher-policy.test.ts
  • tests/codex-integration/codex-config-write-lock.test.ts
  • tests/codex-integration/codex-failure-window.test.ts
  • tests/codex-integration/codex-inject-integration.test.ts
  • tests/codex-integration/codex-journal.test.ts
  • tests/codex-integration/codex-missing-home.test.ts
  • tests/codex-integration/codex-prompt-layers-write.test.ts
  • tests/codex-integration/codex-prompt-lock-sharing.test.ts
  • tests/codex-integration/codex-prompt-lock.test.ts
  • tests/codex-integration/codex-prompt-route.test.ts
  • tests/codex-integration/codex-shim-path-readiness.test.ts
  • tests/codex-integration/codex-shim-runtime-preflight.test.ts
  • tests/codex-integration/codex-shim.test.ts
  • tests/codex-integration/doctor.test.ts
  • tests/codex-integration/native-codex-toggle.test.ts
  • tests/codex-integration/ultrafast-tier-honesty.test.ts
  • tests/config/config-load-degrade.test.ts
  • tests/fixtures/desktop-cli-record/appimage-kind.json
  • tests/fixtures/desktop-cli-record/disabled-tombstone.json
  • tests/fixtures/desktop-cli-record/disabled-with-pending.json
  • tests/fixtures/desktop-cli-record/dotdot-target.json
  • tests/fixtures/desktop-cli-record/first-pending.json
  • tests/fixtures/desktop-cli-record/notify-pending.json
  • tests/fixtures/desktop-cli-record/pending-enabled.json
  • tests/fixtures/desktop-cli-record/relative-target.json
  • tests/fixtures/desktop-cli-record/valid-darwin.json
  • tests/fixtures/desktop-cli-record/valid-linux.json
  • tests/fixtures/desktop-cli-record/valid-win32.json
  • tests/fixtures/test-layout-expected.json
  • tests/gui/claude-manual-env.test.ts
  • tests/gui/startup-health-ui.test.ts
  • tests/helpers/anthropic-instance-fixture.ts
  • tests/helpers/fixture-teardown.ts
  • tests/helpers/hosted-send-fixture.ts
  • tests/helpers/isolated-codex-home.ts
  • tests/helpers/management-auth-fixture.ts
  • tests/helpers/responses-core-source.ts
  • tests/lib/bun-runtime-preflight.test.ts
  • tests/lib/synced-state-location.test.ts
  • tests/oauth/chatgpt-token-boundaries.test.ts
  • tests/oauth/chatgpt-token-expiry.test.ts
  • tests/oauth/oauth-anthropic-instance-health.test.ts
  • tests/oauth/oauth-login-cli-live-update.test.ts
  • tests/oauth/oauth-refresh-generic-lock.test.ts
  • tests/providers/azure-vendor-metadata.test.ts
  • tests/providers/provider-api-keys.test.ts
  • tests/providers/provider-quota-ollama-cloud.test.ts
  • tests/providers/provider-quota.test.ts
  • tests/responses/anthropic2-responses-parity.test.ts
  • tests/responses/chat-native-combo.test.ts
  • tests/responses/codex-ws-pool-contention.test.ts
  • tests/responses/continuation-dedup.test.ts
  • tests/responses/external-task-input-repair.test.ts
  • tests/responses/jev-initial-effort-wire.test.ts
  • tests/responses/openai-responses-passthrough.test.ts
  • tests/responses/protocol-direct-encoders-messages.test.ts
  • tests/responses/responses-compaction-override.test.ts
  • tests/responses/responses-dispatch-receipt.test.ts
  • tests/responses/responses-first-send-reservation.test.ts
  • tests/responses/responses-first-send-spend-policy.test.ts
  • tests/responses/responses-hosted-send-hop.test.ts
  • tests/responses/responses-hosted-send-producer.test.ts
  • tests/responses/responses-hosted-send-reservation.test.ts
  • tests/responses/responses-hosted-send-round-parity.test.ts
  • tests/responses/responses-hosted-send-unsent-hop.test.ts
  • tests/responses/responses-hosted-send-ws.test.ts
  • tests/responses/responses-main-quota-observation.test.ts
  • tests/responses/responses-passthrough-transient-policy.test.ts
  • tests/responses/responses-spill-admission-headroom.test.ts
  • tests/responses/responses-spill-orphan-sweep.test.ts
  • tests/responses/responses-state.test.ts
  • tests/routing/combo-management-api.test.ts
  • tests/routing/jev-service-exchange.test.ts
  • tests/server/adapter-resolve.test.ts
  • tests/server/codex-agent-role-routes.test.ts
  • tests/server/codex-role-auto-assign-routes.test.ts
  • tests/server/combo-requested-effort.test.ts
  • tests/server/link-management-routes.test.ts
  • tests/server/local-account-switch-ingress.test.ts
  • tests/server/memory-watchdog.test.ts
  • tests/server/plaintext-v2-agent-messages-server.test.ts
  • tests/server/restart-replacement.test.ts
  • tests/server/server-antigravity-web-search-validation.test.ts
  • tests/server/server-management-auth.test.ts
  • tests/server/server-management-log-admission.test.ts
  • tests/server/server-new-model-policy-arrival.test.ts
  • tests/server/startup-health-packaged-probe.test.ts
  • tests/server/startup-prompt.test.ts
  • tests/server/system-restart.test.ts
  • tests/service/autostart-health.test.ts
  • tests/service/launchd-repair.test.ts
  • tests/service/service-desktop-runtime-preflight.test.ts
  • tests/service/service-desktop-startup-health.test.ts
  • tests/service/service-desktop-startup-linux.test.ts
  • tests/service/service-desktop-startup.test.ts
  • tests/service/service-ownership-handover.test.ts
  • tests/service/service-runtime-preflight.test.ts
  • tests/service/service.test.ts
  • tests/storage/api-storage-policy-put-race.test.ts
  • tests/update/update-desktop-owner.test.ts
  • tests/update/update-restart-lease.test.ts
  • tests/usage/request-log-conversation.test.ts
  • tests/usage/upstream-failure-diagnostics.test.ts
  • tests/vision/vision-anthropic-instance-sidecar.test.ts
  • tests/web-search/web-search-anthropic-instance.test.ts
  • tests/web-search/web-search-bridge-replay.test.ts
  • tests/windows/windows-atomic-replace.test.ts
  • tests/windows/windows-deploy-close-regressions.test.ts
  • tests/windows/windows-elevation.test.ts
  • tests/windows/windows-secret-acl-removal-flight.test.ts

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added the intake: hygiene-blocked Deterministic PR hygiene checks failed label Oct 10, 2026
@github-actions

Copy link
Copy Markdown
Contributor

⚠️ Deterministic hygiene checks failed.

  • missing_coauthor_credit — This pull request says it reimplements, supersedes, carries, or rebases another author's pull request, but no Co-authored-by trailer names that author. Prose in a commit body is not read by anything; the trailer is what GitHub counts. Add it to the description or a commit, or obtain attribution-approved. Paths: #67.

@github-actions github-actions Bot changed the title release: 2.82.0 [WRONG BRANCH] release: 2.82.0 Oct 10, 2026
@github-actions

github-actions Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

⏳ DRAFT

  • wrong target branch (main); retarget to dev.

What to do

  • Retarget this PR to dev — all contributions go to dev.

Its title has been prefixed with [WRONG BRANCH].
Automatic draft conversion failed (token cannot change draft status). Please convert this pull request to a draft manually. The required enforce-target check will keep failing until every issue above is resolved.

@github-actions
github-actions Bot marked this pull request as draft October 10, 2026 08:32
const salt = thoughtSignatureReplaySalt();
if (!owner || !salt || salt.length < 16 || blob.length === 0) return undefined;
return createHmac("sha256", salt).update("native-reasoning\0")
.update(JSON.stringify([owner.destination, owner.credential, createHash("sha256").update(blob).digest("hex")]))
@lidge-jun

Copy link
Copy Markdown
Owner Author

Maintainer note on the hygiene result: missing_coauthor_credit names #67, but no commit carries #67. The carry window in .github/scripts/pr-carry-attribution.cjs is capped at 80 characters, and in #6785's subject ("fix(codex): carry LazyCodex role-model fixes ([codex] mirror, routed effort ladder, omo tab) (#6785)") that cap cuts #6785 to #67. Applying attribution-approved for this promotion only; the truncation bug is tracked separately.

The [WRONG BRANCH] / enforce-target result is the expected promotion exception (same as #6771). CodeQL reports alerts across the whole promotion diff, as it did on #6771; their disposition stays a separate maintainer decision.

@lidge-jun lidge-jun added the attribution-approved Maintainer approved a carry whose original author is not named in a trailer label Oct 10, 2026
@github-actions github-actions Bot removed the intake: hygiene-blocked Deterministic PR hygiene checks failed label Oct 10, 2026
@lidge-jun
lidge-jun marked this pull request as ready for review October 10, 2026 08:57
@lidge-jun
lidge-jun merged commit 848ec37 into main Oct 10, 2026
149 of 156 checks passed
@lidge-jun
lidge-jun deleted the codex/promote-main-2.82.0 branch October 10, 2026 08:57
@lidge-jun lidge-jun mentioned this pull request Oct 10, 2026
3 tasks done
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

attribution-approved Maintainer approved a carry whose original author is not named in a trailer

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants