Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
217 commits
Select commit Hold shift + click to select a range
a0f5897
release: v2.17.1-preview.20260814
lidge-jun Aug 14, 2026
fef111e
Merge main into preview: v2.19.0 release (preview keeps its prereleas…
lidge-jun Aug 15, 2026
255c25d
release: v2.19.0-preview.20260815
lidge-jun Aug 15, 2026
fd84ae1
Merge dev into preview: v2.20.0 line
lidge-jun Aug 15, 2026
906286c
Merge pull request #1768 from lidge-jun/promote/260815-preview
lidge-jun Aug 15, 2026
8e154f7
Merge main into preview: v2.22.0 line
lidge-jun Aug 16, 2026
0bc04f0
release: v2.23.0-preview.20260816
lidge-jun Aug 16, 2026
86039da
Merge dev into preview: v2.23.0 release
lidge-jun Aug 17, 2026
d240148
Merge dev into preview: v2.24.0 release
lidge-jun Aug 17, 2026
f32a2f5
Merge dev into preview: v2.24.1 release
lidge-jun Aug 17, 2026
6a23ea9
Merge dev into preview: Windows suite green
lidge-jun Aug 17, 2026
e25ec09
Merge pull request #1907 from lidge-jun/promote-preview
lidge-jun Aug 17, 2026
76e87cd
Merge dev into preview: ignore leftover test temp files
lidge-jun Aug 17, 2026
844081d
Merge pull request #1911 from lidge-jun/promote-preview2
lidge-jun Aug 17, 2026
56f2ed9
Merge main into preview: v2.24.2 release
lidge-jun Aug 17, 2026
506bcab
Merge pull request #1918 from lidge-jun/sync-preview
lidge-jun Aug 17, 2026
a43150c
Merge pull request #1962 from lidge-jun/codex/promote-preview-w5
lidge-jun Aug 18, 2026
e6709a1
Merge pull request #1967 from lidge-jun/codex/promote-preview-w5b
lidge-jun Aug 18, 2026
379a355
Merge pull request #1970 from lidge-jun/codex/promote-preview-w5c
lidge-jun Aug 18, 2026
bed4ca8
Merge pull request #1975 from lidge-jun/codex/promote-preview-w5d
lidge-jun Aug 18, 2026
c0961d8
Merge pull request #1979 from lidge-jun/codex/promote-preview-w5e
lidge-jun Aug 18, 2026
82c0576
Merge pull request #1982 from lidge-jun/codex/promote-preview-w5f
lidge-jun Aug 18, 2026
6d2eae7
Merge pull request #1985 from lidge-jun/codex/promote-preview-w5g
lidge-jun Aug 18, 2026
952a832
Merge dev into preview: v2.25.0 release train
lidge-jun Aug 18, 2026
70d7ba5
Merge pull request #2000 from lidge-jun/codex/promote-preview-2250
lidge-jun Aug 18, 2026
46858ef
release: v2.25.0-preview.20260818
lidge-jun Aug 18, 2026
11f6f4c
Merge pull request #2002 from lidge-jun/release-2.25.0-preview.20260818
lidge-jun Aug 18, 2026
f4cc168
Merge pull request #2088 from lidge-jun/dev
lidge-jun Aug 19, 2026
60f273d
release: v2.26.0-preview.20260819
lidge-jun Aug 19, 2026
6d6a1b4
Merge pull request #2090 from lidge-jun/release-2.26.0-preview.20260819
lidge-jun Aug 19, 2026
17c8a3a
merge preview into dev for the 2.27.0 preview sync
lidge-jun Aug 20, 2026
a055461
Merge pull request #2161 from lidge-jun/codex/sync-preview-2.27.0
lidge-jun Aug 20, 2026
a3c33bb
Merge pull request #2187 from lidge-jun/codex/sync-preview-2.28.0
lidge-jun Aug 20, 2026
19fbc93
release: v2.28.0-preview.20260820
lidge-jun Aug 20, 2026
d2c700c
Merge pull request #2191 from lidge-jun/codex/release-2.28.0-preview
lidge-jun Aug 20, 2026
190a457
merge dev into preview for the 2.29.0 preview sync
lidge-jun Aug 21, 2026
b2609a5
Merge pull request #2285 from lidge-jun/codex/promote-preview-2.29.0
lidge-jun Aug 21, 2026
aef1bf0
merge dev into preview for the 2.29.0 preview release
lidge-jun Aug 21, 2026
639dc73
merge main into preview for the 2.29.0-preview release
lidge-jun Aug 21, 2026
298e0f6
release: v2.29.0-preview.20260821
lidge-jun Aug 21, 2026
4cfdc26
merge dev into preview for the 2.30.0-preview release
lidge-jun Aug 21, 2026
e9f8840
release: v2.30.0-preview.20260821
lidge-jun Aug 21, 2026
7a0fb25
devlog: bun 1.4 follow-up memory roadmap (000-040) — research ledger,…
lidge-jun Aug 21, 2026
db040e7
fix(kiro): accept permissive parallel tool hints
Ingwannu Aug 21, 2026
efaa73f
Merge remote-tracking branch 'origin/dev' into ingw/fix-kiro-parallel…
Ingwannu Aug 21, 2026
1d5d935
Merge remote-tracking branch 'origin/dev' into ingw/fix-kiro-parallel…
Ingwannu Aug 21, 2026
87737d4
fix(responses): scope reasoning replay by conversation, not just pare…
olddonkey Aug 21, 2026
08d0e66
fix(responses): remember a proven opaque-blob rejection per destination
olddonkey Aug 21, 2026
d1edf0d
fix(responses): keep replay scope as a raw conversation identity
olddonkey Aug 21, 2026
ac90e80
docs(responses): record the opaque-blob rejection memo
olddonkey Aug 21, 2026
befb4df
docs(responses): clarify replay memo route changes
Ingwannu Aug 21, 2026
fe427aa
fix(responses): repair apply_patch envelopes
goodwilliam0126 Aug 20, 2026
e56471c
fix(responses): honor tool choice during patch repair
goodwilliam0126 Aug 22, 2026
14b6e43
fix(responses): scope custom repair to authorized items
goodwilliam0126 Aug 22, 2026
647a7ab
fix(responses): preserve native custom wrappers
goodwilliam0126 Aug 22, 2026
19befba
fix: scope apply patch response repair
goodwilliam0126 Aug 22, 2026
1acf734
fix: preserve namespaced patch payloads
goodwilliam0126 Aug 22, 2026
c1d2915
merge dev into preview for the 2.31.0-preview.20260822 release
lidge-jun Aug 22, 2026
22541fa
release: v2.31.0-preview.20260822
lidge-jun Aug 22, 2026
93b977d
fix(bridge): preserve custom tool namespaces
goodwilliam0126 Aug 22, 2026
d587a4b
fix(catalog): exclude uncallable OpenCode Go and Zen models (closes #…
chilung-cgu Aug 22, 2026
e724c63
fix(google): preserve stream signature source order
luvs01 Aug 22, 2026
4fb942d
test(google): keep carry fixture non-terminal
luvs01 Aug 22, 2026
b4c0b94
fix(reasoning): support per-effort field omission sentinel (__omit__)…
chilung-cgu Aug 22, 2026
e5c8306
fix(catalog): retain opencode-go/grok-4.6 in exposed models (#2330)
chilung-cgu Aug 22, 2026
e418f91
fix(tools): index tool-choice candidates
luvs01 Aug 20, 2026
662fe6c
fix(reasoning): support per-effort field omission sentinel (__omit__)…
chilung-cgu Aug 22, 2026
b96af22
Merge pull request #2309 from lidge-jun/ingw/fix-kiro-parallel-hint-2308
lidge-jun Aug 22, 2026
f26c7b5
Merge pull request #2339 from luvs01/fix/google-stream-signature-order
lidge-jun Aug 22, 2026
25324f8
Merge pull request #2335 from luvs01/fix/tool-choice-candidate-index
lidge-jun Aug 22, 2026
f96d9ef
Merge pull request #2313 from olddonkey/fix/replay-scope-and-memo
lidge-jun Aug 22, 2026
d374bb8
devlog: backlog disposition program roadmap (work-phase 0, docs-only)
lidge-jun Aug 22, 2026
5921c20
Merge pull request #2369 from lidge-jun/codex/wp1-green-merges
lidge-jun Aug 22, 2026
a9cb766
fix(tools): repair integral floats in native u64 tool fields
lidge-jun Aug 22, 2026
ae05672
Merge pull request #2371 from lidge-jun/codex/wp3-u64-timeout
lidge-jun Aug 22, 2026
e2424f3
fix(catalog): keep opencode-free/deepseek-v4-flash-free exposed and p…
chilung-cgu Aug 22, 2026
99b8de7
Merge pull request #2361 from chilung-cgu/fix/issue-2356-reasoning-ef…
lidge-jun Aug 22, 2026
556192a
devlog: work-phase records for the backlog disposition program
lidge-jun Aug 22, 2026
7dfe57a
Merge pull request #2372 from lidge-jun/codex/wp9-records
lidge-jun Aug 22, 2026
0b7a771
devlog: record the late #2362 review and what retirement cost
lidge-jun Aug 22, 2026
af5dd16
Merge pull request #2374 from lidge-jun/codex/wp9-2362-amend
lidge-jun Aug 22, 2026
d179fa4
Merge pull request #2359 from chilung-cgu/fix/issue-2330-exclude-unca…
lidge-jun Aug 22, 2026
e8b480a
devlog: Bun 1.4 follow-up memory roadmap (#2301 rebuilt on dev)
lidge-jun Aug 22, 2026
1ab34dc
test(scripts): land the Bun 1.4 memory harnesses with their review bl…
lidge-jun Aug 22, 2026
8923114
Merge pull request #2376 from lidge-jun/codex/wp7-bun14-docs
lidge-jun Aug 22, 2026
97286ee
devlog: work-phase 7 record — Bun 1.4 stack retargeted, not abandoned
lidge-jun Aug 22, 2026
378d889
Merge pull request #2377 from lidge-jun/codex/wp7-record
lidge-jun Aug 22, 2026
b268d18
Merge pull request #2310 from goodwilliam0126/fix/apply-patch-envelop…
lidge-jun Aug 22, 2026
d70b2d6
devlog: work-phase 2 record — one merged, three held on reproduced de…
lidge-jun Aug 22, 2026
425e8bd
Merge pull request #2381 from lidge-jun/codex/wp2-record
lidge-jun Aug 22, 2026
a3bbcdb
feat(cli): add an opt-in Windows desktop-app restart for a stale mode…
lidge-jun Aug 22, 2026
84ee2e2
Merge pull request #2382 from lidge-jun/codex/wp4-windows-picker
lidge-jun Aug 22, 2026
6f5e103
devlog: work-phase 4 record — #2292, and the audit that arrived after…
lidge-jun Aug 22, 2026
e1d1975
Merge pull request #2384 from lidge-jun/codex/wp4-record
lidge-jun Aug 22, 2026
e868200
devlog: WP5 security audit — native main refresh needs a decision bef…
lidge-jun Aug 22, 2026
cd77ee6
Merge pull request #2385 from lidge-jun/codex/wp5-audit
lidge-jun Aug 22, 2026
93fd83e
devlog: WP6 — verify and record the #1049 deferral
lidge-jun Aug 22, 2026
5e50590
Merge pull request #2386 from lidge-jun/codex/wp6-record
lidge-jun Aug 22, 2026
9551bbd
fix(codex): avoid TOML marker regex backtracking
luvs01 Aug 22, 2026
8c74f36
devlog: WP8 execution and the program's closing reconciliation
lidge-jun Aug 22, 2026
d292b9b
Merge pull request #2388 from luvs01/fix/codex-linear-toml-string-pat…
Ingwannu Aug 22, 2026
7185ecc
Merge pull request #2391 from lidge-jun/codex/wp8-record
lidge-jun Aug 22, 2026
5657fac
fix(gui): stop the sidecar copy collapse and align both cards on one …
lidge-jun Aug 22, 2026
d52032e
fix(auth): map compact substitution failures to 401 (#2390)
luvs01 Aug 22, 2026
6036232
fix(native): start owned lifecycle after ownership reprobe (#2352)
luvs01 Aug 22, 2026
3611850
fix(usage): bound incremental append reads (#2395)
luvs01 Aug 22, 2026
383279c
fix(responses): bound upstream error body reads (#2398)
luvs01 Aug 22, 2026
138cbe1
fix(responses): enforce explicit empty tool catalogs (#2370)
luvs01 Aug 22, 2026
c8c4178
fix(update): recover npm 12 self-updates (#2383)
n3wr1ch Aug 22, 2026
03d5767
fix(tools): teach nested apply_patch delimiters in code mode (#2368)
ArcSolver Aug 22, 2026
c9d10ed
fix(zcode): tolerate derived model metadata drift (#2393)
Ingwannu Aug 22, 2026
e882296
fix(anthropic): align minimal adaptive budget with low
luvs01 Aug 22, 2026
46d4150
test(codex): follow #2398 on the oversized pool-retry 400 body (#2404)
lidge-jun Aug 22, 2026
4f41a8e
feat(usage): answer today's cost from the CLI in one command (#2396)
lidge-jun Aug 22, 2026
be30524
fix(management): reject non-object custom-model bodies
luvs01 Aug 22, 2026
e8147d5
fix(sidecars): keep caller aborts account-neutral
luvs01 Aug 22, 2026
c6a1367
test(sidecars): cover response-body caller aborts
luvs01 Aug 22, 2026
1ec8aac
fix(sidecars): defer success until body completion
luvs01 Aug 22, 2026
c323405
fix(vision): guard HTTP error body cancellation
luvs01 Aug 22, 2026
35f0b88
fix(usage): reject rows without provider labels
luvs01 Aug 22, 2026
f73f3d2
fix(images): retain canonical interception for alias choices
luvs01 Aug 22, 2026
4c6582c
fix(xai): stop stripping web_search fields xAI accepts
olddonkey Aug 22, 2026
12a291b
fix(codex): preserve routed history provenance
luvs01 Aug 23, 2026
19de0f5
fix(codex): address history restore review findings
luvs01 Aug 23, 2026
415aec6
test(xai): prove the capability backfill is causal on both destinations
olddonkey Aug 23, 2026
43b2e26
Merge pull request #2422 from olddonkey/fix/xai-web-search-overstrip
Ingwannu Aug 23, 2026
b45e408
Merge pull request #2417 from luvs01/fix/image-alias-canonical-interc…
Ingwannu Aug 23, 2026
2569d90
Merge pull request #2424 from luvs01/fix/history-provider-provenance
Ingwannu Aug 23, 2026
d8b620e
Merge pull request #2413 from luvs01/fix/usage-log-provider-guard
Ingwannu Aug 23, 2026
03c7239
Merge pull request #2408 from luvs01/fix/custom-model-json-body
Ingwannu Aug 23, 2026
cc3678f
Merge branch 'dev' into fix/anthropic-minimal-effort-budget
Ingwannu Aug 23, 2026
939b989
Merge branch 'dev' into fix/sidecar-caller-abort-health
Ingwannu Aug 23, 2026
81461aa
Merge pull request #2402 from luvs01/fix/anthropic-minimal-effort-budget
Ingwannu Aug 23, 2026
d8b6b83
Merge branch 'dev' into fix/sidecar-caller-abort-health
Ingwannu Aug 23, 2026
bf8bcfd
Merge pull request #2403 from luvs01/fix/sidecar-caller-abort-health
Ingwannu Aug 23, 2026
3023be0
devlog: owner backlog closeout — inventory and disposition roadmap (w…
lidge-jun Aug 23, 2026
c2b72fa
devlog: record the eleven reviewer verdict blocks verbatim (wp0) (#2445)
lidge-jun Aug 23, 2026
2a2f6e6
feat(compatibility): add fixture-backed OpenAI contract manifest (#2439)
Ingwannu Aug 23, 2026
8147425
refactor(codex): centralize history manifest contract (#2437)
Ingwannu Aug 23, 2026
4fb0fbe
refactor(responses): isolate fetch helper imports (#2435)
Ingwannu Aug 23, 2026
b6c7c0a
refactor(config): extract proxy process-state ownership (#2387)
Ingwannu Aug 23, 2026
aa37c8b
refactor(config): extract provider validation boundary (#2380)
Ingwannu Aug 23, 2026
ed719b5
devlog: wp1-wp5 disposition records for PRs #2439 #2437 #2435 #2433 #…
lidge-jun Aug 23, 2026
88b7cc0
fix(combos): fail over zero-output stream failures, recording each te…
lidge-jun Aug 23, 2026
81bf4b9
fix(tools): scope wait integer coercion (#2448)
lidge-jun Aug 23, 2026
9cebfc6
refactor: centralize Codex auth error responses (#2450)
lidge-jun Aug 23, 2026
dfb62f9
fix(tools): coerce wait.yield_time_ms as an integral float
jeongjin0 Aug 23, 2026
95a3f67
test(tools): keep wait.priority bytes when it is the only field
jeongjin0 Aug 23, 2026
6b0f61f
test: stabilize Windows WP13 acceptance (#2452)
lidge-jun Aug 23, 2026
c9a202e
feat(gui): surface combo target quota state (#2454)
lidge-jun Aug 23, 2026
35a8990
devlog: owner backlog closeout — wp6-wp11 records and closing reconci…
lidge-jun Aug 23, 2026
438b9cc
devlog: model/provider UX design unit — aliases, new-models-off, defa…
lidge-jun Aug 24, 2026
2e9af3f
fix(cli): resolve the effort ladder the way the runtime resolves it
ntdatt812 Aug 24, 2026
d5018f0
Merge pull request #2469 from ntdatt812/fix/cli-models-effort-resolver
lidge-jun Aug 24, 2026
c44e43f
Merge pull request #2453 from jeongjin0/fix/wait-yield-time-ms-unders…
lidge-jun Aug 24, 2026
91f8606
Merge pull request #2478 from lidge-jun/dev
lidge-jun Aug 24, 2026
8bc7aa8
Merge pull request #2479 from lidge-jun/dev
lidge-jun Aug 24, 2026
96e2f67
release: v2.32.0
lidge-jun Aug 24, 2026
09a28e2
release: v2.32.0-preview.20260824
lidge-jun Aug 24, 2026
411e5f8
devlog: v2.32.1 hotfix train roadmap unit (260824)
lidge-jun Aug 24, 2026
29cf993
devlog: record wp1 delivery via PR #2487 and the two CI flakes
lidge-jun Aug 24, 2026
73a11a8
Merge pull request #2487 from lidge-jun/codex/v2321-hotfix-train-roadmap
lidge-jun Aug 24, 2026
3e3a028
fix(anthropic): classify capitalized/dotted Claude ids as adaptive th…
L-Y-J Aug 24, 2026
a60d517
fix(catalog): match selectedModels the way the canonical resolver mat…
ntdatt812 Aug 24, 2026
84ade0f
fix(codex): keep oversized Responses turns off the WS transport (#2473)
olddonkey Aug 24, 2026
1d4a92a
fix(responses): honor tool_choice for namespace aliases (#2477)
luvs01 Aug 24, 2026
02c302a
fix(responses): stop rewriting an unchanged snapshot every two second…
ntdat812 Aug 24, 2026
43227ac
fix(responses): close two post-merge review findings (#2500)
lidge-jun Aug 25, 2026
faaa78d
fix(responses): reject malformed selectors at the authorization gate …
lidge-jun Aug 25, 2026
03c988c
devlog: close the v2.32.1 train — GO/NO-GO, and two deferrals (#2504)
lidge-jun Aug 25, 2026
bb89eaf
devlog: pin the report to the code SHA its gates describe (#2506)
lidge-jun Aug 25, 2026
d35592b
merge dev into main for the v2.32.1 release
lidge-jun Aug 25, 2026
f4cb9f8
merge dev into preview for the v2.32.1-preview.20260825 release
lidge-jun Aug 25, 2026
71c57ea
release: v2.32.1
lidge-jun Aug 25, 2026
3be3e55
fix(management): validate the sidecar pair against the submitted back…
lidge-jun Aug 25, 2026
b06cb1b
fix(cli): report Codex routing in ocx status and name an unused proxy…
lidge-jun Aug 25, 2026
47a31d7
fix(codex): report a destroyed shim instead of bailing silently (#2519)
lidge-jun Aug 25, 2026
fff8611
fix(xai): stop the undeclared-tool guard from killing hosted x_search…
olddonkey Aug 25, 2026
c09f040
fix(gui): guard quota reset date formatting (#2405)
luvs01 Aug 25, 2026
312b3e7
fix(gui): ignore stale Startup secondary responses (#2416)
luvs01 Aug 25, 2026
d402272
fix(responses): retry pre-output EOFs affecting Ox Alpha (#2486)
kremnyi Aug 25, 2026
0f30b39
fix(claude): do not let a non-registering row veto a bare context key…
ntdatt812 Aug 25, 2026
0906201
fix(kiro): prioritize tool search results within catalog budget (#2475)
mchlkim Aug 25, 2026
d659c54
feat(codex): add per-model ChatGPT compaction budgets (#1905)
luvs01 Aug 25, 2026
b2f95e1
fix(anthropic): apply provider default reasoning effort when caller o…
L-Y-J Aug 25, 2026
b694268
fix(anthropic): do not let the __omit__ sentinel become an effort val…
lidge-jun Aug 25, 2026
224f23d
fix: normalize legacy exec_command/shell_command tool calls to declar…
L-Y-J Aug 25, 2026
121c1fb
test(bridge): pin legacy shell-name normalization on the SSE path (#2…
lidge-jun Aug 25, 2026
64bc085
fix(catalog): do not carry a retained compact limit onto a corrected …
lidge-jun Aug 25, 2026
8c21b69
devlog: operator visibility train roadmap unit (260825) (#2520)
lidge-jun Aug 25, 2026
98ed186
fix(gui): inset the Claude account-pool warning and threshold field (…
Yoonkeee Aug 25, 2026
b12658e
devlog: OAuth login UX roadmap unit (260825)
lidge-jun Aug 25, 2026
2e03252
devlog: OAuth login UX delivery map (issues + PR stack)
lidge-jun Aug 25, 2026
eae9fb4
fix(gui): show the device code and authorization link on every login …
lidge-jun Aug 25, 2026
4edef75
devlog: record the as-landed WP2 design and its test split
lidge-jun Aug 25, 2026
da6cbfc
fix(gui): render the login hint during a first-time provider add
lidge-jun Aug 25, 2026
d7d708f
Merge pull request #2530 from lidge-jun/codex/oauth-login-ux
lidge-jun Aug 25, 2026
315f5bf
Merge pull request #2534 from lidge-jun/codex/oauth-first-add-hint
lidge-jun Aug 25, 2026
1c49c38
feat(oauth): let the operator decline a proxy-side browser open
lidge-jun Aug 25, 2026
c6c98e9
fix(gui): read the server browser-open default as a resource, not pos…
lidge-jun Aug 25, 2026
90c4aa2
fix(gui): stop the browser-open toggle from issuing its own settings …
lidge-jun Aug 25, 2026
86bc623
fix(oauth): read code and state from a redirect URL fragment
lidge-jun Aug 25, 2026
34ef539
test(update): stop the launcher-recovery wait from failing a slow CI …
lidge-jun Aug 25, 2026
e65d6d3
Merge pull request #2537 from lidge-jun/codex/oauth-open-browser-choice
lidge-jun Aug 25, 2026
858352a
Merge pull request #2540 from lidge-jun/codex/oauth-paste-fragment
lidge-jun Aug 25, 2026
693b6e4
devlog: close out the OAuth login UX merge train
lidge-jun Aug 25, 2026
aeea04c
fix(oauth): never pair a code and state from different URL components
lidge-jun Aug 25, 2026
5170fc8
Merge pull request #2543 from lidge-jun/codex/oauth-mixed-source-fix
lidge-jun Aug 25, 2026
9af029c
Merge pull request #2544 from lidge-jun/dev
lidge-jun Aug 25, 2026
89295c6
fix(release): run the preflight suite in the same groups CI does
lidge-jun Aug 25, 2026
c0c9544
Merge pull request #2546 from lidge-jun/codex/release-gate-isolation-…
lidge-jun Aug 25, 2026
5559f85
Merge pull request #2547 from lidge-jun/dev
lidge-jun Aug 25, 2026
121ecbc
test(usage): stop asserting the overlay version against a moving oracle
lidge-jun Aug 25, 2026
e1fb675
Merge pull request #2549 from lidge-jun/codex/api-usage-overlay-versi…
lidge-jun Aug 25, 2026
d560ac6
merge dev into main for the v2.33.0 release
lidge-jun Aug 25, 2026
08ada6f
Merge pull request #2553 from lidge-jun/codex/promote-main-2330
lidge-jun Aug 25, 2026
ec51e42
release: v2.33.0
lidge-jun Aug 25, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
169 changes: 99 additions & 70 deletions bin/ocx.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -227,11 +227,90 @@ function runNpmSelfUpdate() {
} catch { /* keep default */ }
}

const launcher = fileURLToPath(import.meta.url);

function startProxyDirectly() {
if (!existsSync(launcher)) {
console.error("opencodex: cannot restart the proxy because the launcher is missing; reinstall opencodex manually.");
return;
}
const env = { ...process.env };
delete env.OCX_SERVICE;
console.log(`Attempting to restart the proxy on port ${bakePort}.`);
const child = spawn(process.execPath, [launcher, "start", "--port", String(bakePort)], {
detached: true,
stdio: "ignore",
windowsHide: true,
env,
});
child.on("error", error => {
console.error(`opencodex: direct proxy restart failed: ${error.message}`);
});
child.unref();
}

function refreshBackgroundServiceOrStartDirect() {
const prevBake = process.env.OCX_BAKE_PORT;
process.env.OCX_BAKE_PORT = String(bakePort);
try {
let svc = spawnSync(process.execPath, serviceRefreshArgs(), { stdio: "inherit", windowsHide: true });
// `serviceWasInstalled` is inferred from service-state.json alone, which can be
// STALE — present while the registration is gone. Repair refuses that case by
// design, and its thrown Error is indistinguishable from any other failure at
// this layer (plain Error, inherited stdio, generic exit status). So ask for
// structured state instead of parsing the failure: install only when the
// diagnostic says the service is genuinely absent. Installing after ANY repair
// failure would resurrect the elevation prompt this change exists to avoid, and
// could re-register a service the user just uninstalled.
if (svc.status !== 0 && readServiceInstalledFromStatus(launcher) === false) {
console.log("No registered service found — installing it instead.");
svc = spawnSync(process.execPath, serviceInstallArgs(), { stdio: "inherit", windowsHide: true });
}
let needDirectStart = svc.status !== 0;
if (!needDirectStart) {
// Exit 0 can still leave stale/missing assets that never bring the proxy
// back — match the GUI/CLI fallthrough so /healthz is not left dead.
try {
const st = spawnSync(process.execPath, [launcher, "status", "--json"], {
encoding: "utf8",
timeout: 20_000,
windowsHide: true,
});
if (st.status === 0 && typeof st.stdout === "string" && st.stdout.trim()) {
const parsed = JSON.parse(st.stdout);
const proxyUp = parsed?.proxy?.running === true || parsed?.proxy?.health?.ok === true;
const viable = parsed?.startup?.serviceViable === true;
if (!proxyUp && !viable) needDirectStart = true;
} else {
// status failed or empty — fail closed to direct start (match CLI).
needDirectStart = true;
}
} catch {
needDirectStart = true;
}
}
if (needDirectStart) {
// A repair needs no elevation, but it can still fail — or exit 0 while leaving
// a non-viable manager. Fall back to a direct detached proxy start so the
// update never leaves the user without a running proxy.
console.warn(
svc.status === 0
? "opencodex: service refresh left a non-viable manager — starting the proxy directly instead."
: "opencodex: service refresh failed — starting the proxy directly instead.",
);
console.warn(" Run 'ocx service repair' to see why the background service could not restart.");
startProxyDirectly();
}
} finally {
if (prevBake === undefined) delete process.env.OCX_BAKE_PORT;
else process.env.OCX_BAKE_PORT = prevBake;
}
}

// Never replace package files under a live proxy — stop it first (full `ocx stop`
// semantics: graceful drain, service stop, native Codex restore). Gate on the service
// and the runtime-port record too: a service-managed or orphaned proxy can be live
// while ocx.pid is stale/missing.
const launcher = fileURLToPath(import.meta.url);
if (trayBeforeUpdate.stopBeforeReplacement) {
console.log("⏹ Handing off the Windows tray before updating...");
try {
Expand All @@ -249,6 +328,17 @@ function runNpmSelfUpdate() {
}
const hasRuntimeState =
existsSync(join(configDir(), "ocx.pid")) || existsSync(join(configDir(), "runtime-port.json"));

function recoverStoppedRuntimeAfterFailure() {
if (serviceWasInstalled) {
console.warn("opencodex: update failed after stopping the proxy — restoring the previous background service.");
refreshBackgroundServiceOrStartDirect();
} else if (hasRuntimeState) {
console.warn("opencodex: update failed after stopping the proxy — restarting the previous version directly.");
startProxyDirectly();
}
}

if (serviceWasInstalled || hasRuntimeState) {
console.log("⏹ Stopping the running proxy before updating...");
const stopRes = spawnSync(process.execPath, [launcher, "stop"], { stdio: "inherit", windowsHide: true });
Expand All @@ -261,9 +351,9 @@ function runNpmSelfUpdate() {
}
if (historyRestoreIncomplete()) {
console.warn(
"opencodex: WARNING — Codex resume history was NOT restored (history DB locked; Codex app/IDE open?).\n" +
" Routed threads stay hidden in the native Codex app until restored.\n" +
" After the update: close the Codex app, then run 'ocx stop' once to restore.",
"opencodex: WARNING — Codex resume-history metadata restore is incomplete (a backup manifest remains).\n" +
" The DB may be busy or the manifest/target may need review; untracked routed history is intentionally unchanged.\n" +
" After the update: close the Codex app, run 'ocx doctor', then run 'ocx stop' once to retry.",
);
}
}
Expand Down Expand Up @@ -309,7 +399,8 @@ function runNpmSelfUpdate() {
// it recreates the #1849 destruction path. Report and stop; the boot probe and the
// recovery marker cover the swap-window states.
console.error(`opencodex: transactional update failed unexpectedly (${error?.message ?? error}). ` +
"The live install was not knowingly modified; run 'ocx update' again or reinstall with npm install -g.");
`The live install was not knowingly modified; run 'ocx update' again or reinstall with ` +
`npm install -g --allow-scripts=bun ${PKG}@${tag}.`);
res = { status: 1 };
}
if (res.status === 0) {
Expand All @@ -329,77 +420,15 @@ function runNpmSelfUpdate() {
// launcher so the new files write the baked paths and the service restarts.
if (serviceWasInstalled) {
console.log("Refreshing the background service with the updated files...");
const prevBake = process.env.OCX_BAKE_PORT;
process.env.OCX_BAKE_PORT = String(bakePort);
try {
let svc = spawnSync(process.execPath, serviceRefreshArgs(), { stdio: "inherit", windowsHide: true });
// `serviceWasInstalled` is inferred from service-state.json alone, which can be
// STALE — present while the registration is gone. Repair refuses that case by
// design, and its thrown Error is indistinguishable from any other failure at
// this layer (plain Error, inherited stdio, generic exit status). So ask for
// structured state instead of parsing the failure: install only when the
// diagnostic says the service is genuinely absent. Installing after ANY repair
// failure would resurrect the elevation prompt this change exists to avoid, and
// could re-register a service the user just uninstalled.
if (svc.status !== 0 && readServiceInstalledFromStatus(launcher) === false) {
console.log("No registered service found — installing it instead.");
svc = spawnSync(process.execPath, serviceInstallArgs(), { stdio: "inherit", windowsHide: true });
}
let needDirectStart = svc.status !== 0;
if (!needDirectStart) {
// Exit 0 can still leave stale/missing assets that never bring the proxy
// back — match the GUI/CLI fallthrough so /healthz is not left dead.
try {
const st = spawnSync(process.execPath, [launcher, "status", "--json"], {
encoding: "utf8",
timeout: 20_000,
windowsHide: true,
});
if (st.status === 0 && typeof st.stdout === "string" && st.stdout.trim()) {
const parsed = JSON.parse(st.stdout);
const proxyUp = parsed?.proxy?.running === true || parsed?.proxy?.health?.ok === true;
const viable = parsed?.startup?.serviceViable === true;
if (!proxyUp && !viable) needDirectStart = true;
} else {
// status failed or empty — fail closed to direct start (match CLI).
needDirectStart = true;
}
} catch {
needDirectStart = true;
}
}
if (needDirectStart) {
// A repair needs no elevation, but it can still fail — or exit 0 while leaving
// a non-viable manager. Fall back to a direct detached proxy start so the
// update never leaves the user without a running proxy.
console.warn(
svc.status === 0
? "opencodex: service refresh left a non-viable manager — starting the proxy directly instead."
: "opencodex: service refresh failed — starting the proxy directly instead.",
);
console.warn(" Run 'ocx service repair' to see why the background service could not restart.");
const env = { ...process.env };
delete env.OCX_SERVICE;
const child = spawn(process.execPath, [launcher, "start", "--port", String(bakePort)], {
detached: true,
stdio: "ignore",
windowsHide: true,
env,
});
child.unref();
console.log(`Proxy starting on port ${bakePort}.`);
}
} finally {
if (prevBake === undefined) delete process.env.OCX_BAKE_PORT;
else process.env.OCX_BAKE_PORT = prevBake;
}
refreshBackgroundServiceOrStartDirect();
} else {
console.log("Restart the proxy: ocx start");
}
process.exit(0);
}
if (trayBeforeUpdate.restoreOnFailure) runTrayLifecycle(launcher, "start");
console.error(`\nUpdate failed (npm exit ${res.status ?? "?"}). Try manually: npm install -g ${PKG}@${tag}`);
recoverStoppedRuntimeAfterFailure();
console.error(`\nUpdate failed (npm exit ${res.status ?? "?"}). Try manually: npm install -g --allow-scripts=bun ${PKG}@${tag}`);
process.exit(1);
}

Expand Down
17 changes: 17 additions & 0 deletions devlog/_plan/260822_260822-bun14-followup-memory/000_plan.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
# 000_plan — unit map

- 000_research.md — claim ledger + gap analysis
- 010_memory_diagnostics.md — extraMemorySize observability (PR parent, base dev)
- 020_watchdog_gc_relief.md — measurement-FIRST GC evaluation (Phase A harness),
conditional idle-gated production hook (Phase B) per the 260731 gate
- 030_smol_workers.md — smol:true gated on per-worker large-fixture A/B
- 040_macmini_measurement.md — live measurement protocol (feeds 020 Phase A)

Stack shape: PR-A(010, base dev) → PR-B(020 Phase A harness + evaluation,
base PR-A head) → conditional PR for Phase B only on gate PASS;
PR-C(030, base dev, lands per-call-site with A/B evidence).
One decade doc = one work-phase = one PABCD cycle (LOOP-UNIT-CHAIN-01).
Audit round 1: FAIL (4 findings) → docs revised: 020 restructured
measurement-first honoring 260731_macos_rss_retention/040_allocator_residual
gate; 010 static-import sync seam; 030 pre-landing A/B gate; separate
lastReliefAt. See ledger.
70 changes: 70 additions & 0 deletions devlog/_plan/260822_260822-bun14-followup-memory/000_research.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,70 @@
# 000 — Bun 1.4 follow-up memory patches: research and claim ledger

Date: 2026-08-22
Unit: 260822_260822-bun14-followup-memory
Question: from today's viewpoint (bundled Bun 1.4.0, released 2026-08-19), which
ADDITIONAL memory patches are possible and worthwhile in opencodex?

## Method

Luna 5-lane discovery swarm (official releases / GitHub issues+PRs / JSC-runtime /
community / server-SSE-proxy), then Tier-2 proof by the main agent via `gh api`
against oven-sh/bun. App-side baseline re-audited against
devlog/_fin/260813_bun_canary_dogfood/050_memory_patch_roadmap.md and current src/.

## Claim ledger (Tier-2 proven unless noted)

| # | Claim | Proof | Status |
|---|---|---|---|
| C1 | No Bun 1.4.x patch release exists after v1.4.0 (2026-08-19). | `gh api repos/oven-sh/bun/releases` → latest tag `bun-v1.4.0`; bun-v1.4.1/2/3 404. | verified |
| C2 | Bun PR #36467 (TLS Bun.serve use-after-free on `server.stop(true)` sibling-socket close) merged 2026-07-31, sha 529adec09, and IS an ancestor of bun-v1.4.0 (`compare/bun-v1.4.0...sha` → status=behind). Already in our bundled runtime; no action. | gh api pulls/36467 + compare | verified |
| C3 | Bun PR #32662 (fetch: release buffered response body + error reader on streaming abort) merged 2026-07-22, sha 4b7241669, ancestor of v1.4.0. In bundled runtime. | gh api pulls/32662 + compare | verified |
| C4 | Bun PR #35093 (fetch: error body stream when fully-buffered response aborted) merged 2026-07-28, sha 789be97db, ancestor of v1.4.0. In bundled runtime. | gh api pulls/35093 + compare | verified |
| C5 | Bun issue #34917: `--max-old-space-size`, `BUN_JSC_gcMaxHeapSize`, `BUN_JSC_forceRAMSize` are NOT reliable heap caps on the 1.4 line; still OPEN (created 2026-07-21, closed:null). Container/OOM bounding must come from app-side watchdog + supervision, not JSC flags. | gh api issues/34917 | verified |
| C6 | `Bun.gc(true)` on 1.4 asks JSC to collect AND asks mimalloc to release fragmented non-JS pages (allocator shared with JSC since the 1.4 Rust/allocator work). | Bun docs (bun.com/reference/bun/gc) opened by L3; local probe `typeof Bun.gc === "function"` on 1.4.0. | verified (docs) |
| C7 | `bun:jsc` heapStats exposes `extraMemorySize`/`heapCapacity`; `Bun.unsafe.mimallocDump` exists on 1.4.0. | local probe on bundled 1.4.0: `{"heapSize":…,"heapCapacity":…,"extraMemorySize":…}`, mimallocDump:function | verified (executed) |
| C8 | `new Worker(url, {smol:true})` works on bundled 1.4.0 (selects JSC Small heap growth policy per Bun docs). | local probe: "smol worker OK" | verified (executed) |
| C9 | RSS retention after GC (issue #27514) and SSE-proxy reader-cancel segfault (#31159) were closed as DUPLICATES, not demonstrated fixed; #26321 (Windows file-stream RSS) duplicate-closed too. Continued A/B measurement remains necessary. | gh issue pages opened by L2/L5 | verified |
| C10 | Community: Bun 1.4 advertises up to ~35% memory reduction (allocator rewrite, thread-local page purging, lazy zeroing); no long-running independent RSS measurements yet. | Reddit announcements (L4), snippet-grade | lead |
| C11 | Medium post claims 1.4-era HTTP long-connection RSS still grew 280→340MB over 7 days; page returned 403. | unreachable | candidate — unverified |

## App-side baseline (what is already done — do not re-patch)

- 260813 roadmap patches #1–#4 ALL landed since: native-main hardened-identity LRU
(src/codex/native-main-claim.ts:25-33), installation-salt LRU
(src/lab/subject/installation-salt.ts:7-17), mode-hint capability LRU
(src/codex/features.ts:1097-1106), Lab ledger event-id process index REMOVED
(no `eventIdIndexByLedger` in src/lab/ledger/store.ts).
- `Bun.serve({ idleTimeout: 255 })` (src/server/index.ts:736) and per-request
`server.timeout(req, 0)` for streaming (src/server/responses/fetch-helpers.ts:113)
already implement the SSE-timeout guidance the swarm surfaced.
- eager-relay vs legacy-tee runtime gate: src/lib/bun-stream-caps.ts
(MIN_FIXED_BUN_VERSION="1.4.0").
- Memory watchdog: warn-only ring sampler (src/server/memory-watchdog.ts), exposed at
/api/system/memory with bun:jsc heapSize/heapCapacity/objectCount.
- 36-store bounded-memory audit closed (devlog/_fin/260813…/050): only remaining
investigation is model-cache generation tombstones — needs an authority-token
redesign, NOT an eviction patch; excluded from this unit.

## Gap analysis → patch set for THIS unit

What Bun 1.4 newly makes possible, that opencodex does not use yet:

1. **Diagnostics gap** — /api/system/memory and the watchdog ignore
`extraMemorySize` (JSC-visible native memory) and the watchdog samples carry no
JSC data at all. On 1.4, extraMemorySize is the counter that moved most
(external-memory reporting fixes #31422/#32653/#34142). → doc 010.
2. **Reclaim gap** — nothing in the tree ever calls `Bun.gc`. On 1.4 a full
`Bun.gc(true)` also purges mimalloc pages (C6) — the exact mitigation for the
"heap shrinks, RSS stays" pattern (#27514) that JSC flags cannot deliver (C5).
A config-gated, rate-limited watchdog relief hook is now worth having. → doc 020.
3. **Worker heap gap** — history/restore/policy workers are short-lived batch jobs;
`smol: true` (C8) bounds their JSC heap growth policy at a small perf cost,
reducing peak RSS during storage jobs. → doc 030.
4. **Proof gap** — every claim above is config/diagnostic-grade until measured.
macmini-cf (arm64, bun 1.3.14 installed → good A/B host) runs the live
measurement protocol. → doc 040.

Explicit non-goals: no Bun runtime patching/fork (upstream 1.4.0 already carries
C2–C4); no JSC env-var "caps" (C5 proves them unreliable); no smol for the main
proxy process (throughput cost, unmeasured); no model-cache tombstone work.
Loading