Skip to content

chore: rolling promotion dev -> main - #2624

Merged
automagik-genie merged 70 commits into
mainfrom
dev
Jul 24, 2026
Merged

automagik-genie merged 70 commits into
mainfrom
dev

Conversation

@namastex888

@namastex888 namastex888 commented Jul 22, 2026 •

Copy link
Copy Markdown
Contributor

Rolling Promotion PR

Auto-maintained rolling promotion PR from dev to main.

Process:

  • This PR is automatically created and kept open
  • Human reviews and merges when ready
  • Label ready-to-merge added when all checks pass

IMPORTANT: Merge with "Create a merge commit" — NEVER squash.
Squash merging breaks history sync between dev and main,
causing the next rolling PR to show all commits again.

Human approval required for merge to production.

Summary by CodeRabbit

  • New Features
    • Improved Codex health reporting with expanded role-agent state breakdown.
    • Enhanced Codex runtime integration convergence to adopt frozen historical role agents when consent is committed.
    • Codex installs/updates can add immutable “delivery repair” for missing and already-current cases.
  • Bug Fixes
    • Releasing an in-progress task now clears heartbeat info so re-claims can’t restore stale liveness.
    • Codex activation now fails with a clearer “delivery-incomplete” refusal when an authenticated delivery record isn’t available.
  • Documentation
    • Updated task-release behavior docs to reflect heartbeat cleanup.
  • Tests
    • Added regression and expanded Codex/MCP integration coverage.
  • Chores
    • Bumped plugin/package versions to 5.260722.13.

namastex888 and others added 3 commits July 22, 2026 16:09
…liveness

releaseTask cleared claimed_by/claimed_at but left heartbeat_at, so after a
release the card kept the prior owner's pulse. when a new worker checked it
out, the liveness badge computed from the old heartbeat and could show a
fresh checkout as running (▶) before it ever pulsed. clear heartbeat_at in
the same conditional UPDATE; add a regression test (release → heartbeatAt
null → survives re-claim).

found by codex PR review of #2619 (P2).
fix(board): clear heartbeat_at on release so the next owner has no stale liveness
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@coderabbitai

coderabbitai Bot commented Jul 22, 2026 •

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Codex delivery is now authenticated before activation, repairable when already current, and fail-closed for invalid project context. Historical role-agent adoption, marker lifecycle handling, CWD evidence, heartbeat cleanup, MCP route changes, and release metadata updates are also included.

Changes

Codex delivery and activation

Layer / File(s) Summary
Delivery observation and contracts
src/lib/codex-host-observation.ts, src/lib/codex-release-version.ts, src/lib/codex-activation.ts
Adds bounded host observation, authenticated delivery assessment, release-version utilities, and attestation fields on delivery records.
Activation delivery guard
src/lib/codex-activation.ts, src/lib/codex-activation-executor.ts, src/lib/codex-activation.test.ts
Refuses activation before journaling when delivery is absent or mismatched and returns typed recovery data.
Same-version delivery repair
src/genie-commands/codex-delivery-repair.ts, src/genie-commands/update.ts, tests/integration/codex-delivery-bootstrap.test.ts
Pins and verifies artifacts, re-observes installed state, and publishes one attested delivery record under a lease.

Codex integrations and MCP routing

Layer / File(s) Summary
Historical role-agent adoption
src/lib/runtime-integrations.ts, src/genie-commands/doctor.ts, src/fixtures/codex-role-agent-allowlist.json
Adds consent-gated historical adoption, ownership states, canonical delivery metadata, and doctor reporting.
MCP route and CWD integration
src/lib/codex-project-mcp.ts, scripts/fresh-install-smoke.ts, tests/support/codex-cwd-evidence.ts, tests/integration/codex-app-server-cwd.test.ts
Removes the Codex plugin MCP route, adds a marker-owned fallback, and validates effective CWD isolation.
Fail-closed project context
src/lib/v5/genie-db.ts, src/lib/v5/mcp-server.ts, src/lib/v5/mcp-tools.ts, src/term-commands/mcp.ts
Resolves project context before database access and returns typed errors for missing or unsupported contexts.

Lifecycle and release maintenance

Layer / File(s) Summary
Task and install-marker lifecycle
src/lib/v5/task-state.ts, src/lib/install-version-marker.ts, src/lib/install-version-marker.test.ts
Clears heartbeat_at on release and adds safe marker read, retirement, uninstall, and backup behavior.
Install and update finalization
src/genie-commands/install.ts, src/genie-commands/update.ts
Publishes deferred delivery facts and retires .install-version after successful convergence or repair.
Release metadata and fixtures
.claude-plugin/marketplace.json, package.json, plugins/genie/*, plugins/hermes-genie/plugin.yaml, scripts/*
Updates versions to 5.260722.13, removes the Codex plugin MCP route artifact, and aligns smoke-test fixtures.

Estimated code review effort: 5 (Critical) | ~120 minutes

Sequence Diagram(s)

sequenceDiagram
  participant UpdateCommand
  participant DeliveryRepair
  participant DeliveryStore
  participant Activation
  UpdateCommand->>DeliveryRepair: assess or repair current delivery
  DeliveryRepair->>DeliveryStore: read or publish attested record
  DeliveryStore-->>DeliveryRepair: repair outcome
  DeliveryRepair-->>UpdateCommand: repair directive
  UpdateCommand->>Activation: converge or hand off
  Activation-->>UpdateCommand: activation result
Loading
sequenceDiagram
  participant IntegrationInstaller
  participant PluginConvergence
  participant ConsentState
  participant RoleAgentInstaller
  IntegrationInstaller->>PluginConvergence: provide genieHome
  PluginConvergence->>ConsentState: read committed Codex consent
  ConsentState-->>PluginConvergence: adoption decision
  PluginConvergence->>RoleAgentInstaller: install with adoption option
  RoleAgentInstaller-->>PluginConvergence: reconcile role-agent ownership
Loading

Possibly related PRs

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 60.62% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly matches the rolling promotion from dev to main and is concise enough for the main change.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dev

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

namastex888 and others added 7 commits July 22, 2026 17:18
…wlist

Close the dogfood-discovered role-agent gap where an old install fanned the
seven Genie Codex role TOMLs into ~/.codex/agents with no managed inventory
and a stale reviewer, leaving them permanently un-refreshed and unmanaged.

- Add a frozen, versioned historical-profile allowlist (name + regular type +
  mode + content digest) covering every legitimately fanned role, grounded in
  the git history of plugins/genie/codex-agents (reviewer carries four).
- On missing inventory, adopt a legacy file ONLY after committed Codex consent
  AND an exact allowlist match: record its on-disk identity as managed so the
  existing backup-first transaction refreshes a stale profile and writes the
  inventory atomically. Adoption is opt-in; bytes never grant ownership.
- Wire convergeCodexPluginOnly to derive adoption from committed codex/all
  consent on both enabled and disabled (R3 fallback) paths, leaving injected
  installAgents seams untouched.
- Extend the ownership report + doctor output with managed / adoptable-historical
  / collision / stale / personal states plus the expected delivered total and
  reviewer digest; a parity gate binds the canonical digests to the bundle.
- Preserve unknown, modified, symlinked, and profile-lookalike collisions
  byte- and mode-identically; never overwrite, adopt, or delete them.

Fixtures cover the observed 0/7-inventory state, stale reviewer, obsolete/
duplicate surfaces, unrelated personal agents, interrupted migration recovery,
and repeated idempotent convergence.

Validation: bun test src/lib/runtime-integrations.test.ts
src/lib/agent-sync.test.ts — 403 pass, 0 fail.
Group B (host-observation-attestation) keystone for the dogfood
remediation wish.

- Add production CodexHostObservation: one immutable typed result of
  runtime/plugin-observable facts only (plugin facts, bounded sanitized
  advisory stderr, optional child self-report, cache-family witness,
  typed failure). Accepts advisory stderr only with exit 0 + exactly one
  schema-valid JSON stdout; rejects timeout/overflow/nonzero-exit/
  malformed-or-duplicate JSON/invalid-version/duplicate-registration/
  unsafe-cache. It never carries raw thread/start.cwd or control facts.
- Add the pure authenticated-delivery-record assessment
  (matching|absent|invalid|mismatch) plus the stable delivery-incomplete
  result (authority none, exit 1, deliveryComplete false).
- Enforce the assessment inside beginActivation immediately before the
  first journal write; a non-matching re-observed record refuses with
  zero mutation, so no stale permit bypasses the inner guard. Map the new
  begin result through the executor.
- Extract the pure release-version grammar + stripControl into a leaf
  module so host-observation can share them with no import cycle; re-
  export from codex-activation for existing importers.
- Add the black-box CodexCwdEvidence harness and a real codex app-server
  integration proof: MCP child effective process.cwd() equals a Codex-
  launched control by string + OS directory identity for root, nested,
  symlink-normalized, and linked-worktree layouts, with sequential and
  concurrent two-repo threads, per-case raw request + PID + effective CWD
  + tagged sentinel, and no PID crossing a differing effective CWD. Skips
  honestly when no runnable codex app-server is available.
feat(codex): Group C — managed role-agent convergence via frozen allowlist (dogfood-remediation)
the harness spawned codex async; a missing binary emitted an unhandled
'error' (ENOENT) at module load that escaped the caller's try/catch and
aborted the whole file (CI: 1 fail + 2 errors). add a synchronous
codex --version preflight that throws a caught error (=> honest skip) plus
a benign child 'error' listener so a late spawn failure rejects initialize
instead of throwing. codex-absent: 1 pass/7 skip/0 fail; codex-present: 8/0.
feat(codex): Group B — host-observation attestation + app-server CWD proof (dogfood-remediation)

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
src/lib/runtime-integrations.ts (1)

953-1017: 🚀 Performance & Scalability | 🔵 Trivial | ⚡ Quick win

Redundant physicalRoleFileIdentity recomputation per entry.

For each ownership entry, inspectCodexAgentOwnership calls physicalRoleFileIdentity(path) directly (for identity), then classifyCodexAgentFile (for ownership) calls it again internally, and classifyCodexAgentDisplayState calls it a third time (plus a fourth via its own internal classifyCodexAgentFile(path, recorded) call) — up to 4 stat+hash passes over the same file per report entry, on every doctor run. The same pattern repeats on the install path: resolveCodexRoleAgentRecord computes physicalRoleFileIdentity(targetPath) to check adoption eligibility, then collectCurrentCodexAgentPayloads immediately calls classifyCodexAgentFile(targetPath, recorded, sourceIdentity), which recomputes it again.

Thread the already-computed RoleFileIdentity through these functions instead of letting each one re-derive it independently.

♻️ Sketch of the fix direction
-function classifyCodexAgentFile(
-  path: string,
-  recorded: RecordedCodexAgent | undefined,
-  legacyUpgradeIdentity?: RegularRoleFileIdentity,
-): CodexAgentOwnership {
-  const actual = physicalRoleFileIdentity(path);
+function classifyCodexAgentFile(
+  actual: RoleFileIdentity,
+  recorded: RecordedCodexAgent | undefined,
+  legacyUpgradeIdentity?: RegularRoleFileIdentity,
+): CodexAgentOwnership {
   if (actual.kind === 'absent') return 'absent';
   ...

Then compute physicalRoleFileIdentity(path) once per entry/target at the call sites and pass the result into both the ownership classifier and classifyCodexAgentDisplayState/resolveCodexRoleAgentRecord.

Also applies to: 1834-1868

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/lib/runtime-integrations.ts` around lines 953 - 1017, Thread a single
computed RoleFileIdentity through the Codex ownership and install flows to
eliminate repeated stat/hash work. Update classifyCodexAgentFile and
classifyCodexAgentDisplayState to accept and reuse the caller-provided identity,
then have inspectCodexAgentOwnership compute it once per entry and pass it to
both classifiers. Apply the same reuse in resolveCodexRoleAgentRecord and
collectCurrentCodexAgentPayloads so each target’s physicalRoleFileIdentity is
computed only once.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/genie-commands/doctor.ts`:
- Around line 402-437: Update the suggestion condition in codexAgentCheck to
include counts.absent > 0 alongside adoptable, stale, and managed < total. Keep
the existing adopt/refresh message for any actionable missing or outdated role
agents, while preserving the collision-review message for collision-only cases.

In `@src/lib/runtime-integrations.ts`:
- Around line 3306-3317: Update resolveConvergenceRoleAdoption to safely handle
errors from the consent reader selected by deps.readConsentState or
readIntegrationConsentState. Preserve explicit deps.adoptHistoricalRoleAgents
overrides, but when options.genieHome is set and consent reading fails, catch
the error and return false so convergence continues with historical role
adoption disabled.

---

Outside diff comments:
In `@src/lib/runtime-integrations.ts`:
- Around line 953-1017: Thread a single computed RoleFileIdentity through the
Codex ownership and install flows to eliminate repeated stat/hash work. Update
classifyCodexAgentFile and classifyCodexAgentDisplayState to accept and reuse
the caller-provided identity, then have inspectCodexAgentOwnership compute it
once per entry and pass it to both classifiers. Apply the same reuse in
resolveCodexRoleAgentRecord and collectCurrentCodexAgentPayloads so each
target’s physicalRoleFileIdentity is computed only once.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 07815532-c922-411e-a471-a8e874a9d3b3

📥 Commits

Reviewing files that changed from the base of the PR and between 33d2fa8 and 8284d5f.

📒 Files selected for processing (5)
  • src/fixtures/codex-role-agent-allowlist.json
  • src/genie-commands/doctor.ts
  • src/genie-commands/uninstall.test.ts
  • src/lib/runtime-integrations.test.ts
  • src/lib/runtime-integrations.ts

Comment thread src/genie-commands/doctor.ts
Comment thread src/lib/runtime-integrations.ts

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@tests/support/codex-cwd-evidence.ts`:
- Around line 110-152: Update CodexCwdEvidence.launch to wrap post-creation
initialization, including request('initialize'), in cleanup-before-rethrow
handling. If initialization fails, close or terminate the spawned child and
remove harnessRoot before propagating the original error, using the constructed
harness cleanup path where available. Preserve successful launch behavior and
ensure late spawn failures receive the same cleanup.
- Around line 133-139: Update the child-process setup around spawn and stdin
writes to handle errors emitted by child.stdin, preventing dead or exited
app-server writes from becoming unhandled test-process errors. Attach an
appropriate stdin error handler and preserve request-level failure behavior,
while keeping the existing child error handling and initialize flow unchanged.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 9e9fc175-d080-4cb5-a37c-e2c927e0eedc

📥 Commits

Reviewing files that changed from the base of the PR and between 8284d5f and a298d8d.

📒 Files selected for processing (15)
  • .claude-plugin/marketplace.json
  • package.json
  • plugins/genie/.claude-plugin/plugin.json
  • plugins/genie/.codex-plugin/plugin.json
  • plugins/genie/package.json
  • plugins/hermes-genie/plugin.yaml
  • src/lib/codex-activation-executor.test.ts
  • src/lib/codex-activation-executor.ts
  • src/lib/codex-activation.test.ts
  • src/lib/codex-activation.ts
  • src/lib/codex-host-observation.test.ts
  • src/lib/codex-host-observation.ts
  • src/lib/codex-release-version.ts
  • tests/integration/codex-app-server-cwd.test.ts
  • tests/support/codex-cwd-evidence.ts

Comment thread tests/support/codex-cwd-evidence.ts Outdated
Comment thread tests/support/codex-cwd-evidence.ts Outdated
namastex888 and others added 8 commits July 22, 2026 18:53
… lifecycle

Group D (immutable-delivery-repair): let update/install repair a MISSING
authenticated delivery record for the installed target exactly once, without
activation and without redefining the target from a moving channel.

- src/genie-commands/codex-delivery-repair.ts: the injectable repair
  orchestrator — pin channel/version/platform/tag/name + manifest digest
  before download, download the exact asset, SHA-256 after, authenticate via
  the existing attestation/cosign anchors, prove the candidate against
  canonical installed bytes, recheck the channel under the lease (advance =>
  ordinary upgrade, mint no stale record), reobserve + publish once. No-network
  fast path for matching records; every failure leaves state unchanged with
  deliveryComplete:false.
- src/lib/install-version-marker.ts: the ONE .install-version lifecycle module
  (D-owned). Retire on convergence success, preserve on failure/unsafe,
  idempotent uninstall for either layout. Canonical VERSION stays authoritative.
- src/lib/codex-activation.ts: additively extend the delivery record + publish
  input to carry the immutable attestation tuple (platform/tag/name/manifest/
  artifact/binary/root); the store parser round-trips them.
- update.ts: repair before the already-current return; retire the marker after
  successful convergence.
- install.ts: deferred install publishes its matching record before the exit-2
  handoff (idempotent); retire the marker on convergence success.

All network/attestation/codex is stubbed in tests; the suite passes with codex
present AND stripped from PATH (0 fail, 0 errors).
…y context

Group A (project-route-context) of codex-plugin-dogfood-remediation.

- Add resolveProjectContext in v5/genie-db: four-value model (effectiveLaunchCwd,
  worktreeConfigRoot, absolute gitCommonDir, genieStorageRoot=dirname(gitCommonDir))
  with typed states project-context-unavailable / project-database-unavailable /
  unsupported-project-layout. Bare/submodule/external-git-dir are rejected before
  any DB lookup; nested repos stop at their own boundary; linked worktrees keep
  config under the linked root but read the DB under the common root's parent.
- Wire the resolver into the shared MCP server loop (opt-in) so genie mcp fails
  closed with a structured error instead of masquerading as a healthy empty board;
  ui-bridge is unaffected. Re-resolve only until the context settles ok.
- Add genieFacadeMcpEntry (<GENIE_HOME>/bin/genie, args [mcp], no cwd) and make
  genie init always reconcile one marker-owned Codex route independent of plugin
  and delivery state; remove the verified-current gate.
- Remove the Codex plugin MCP route: drop mcpServers + MCP capability from the
  Codex manifest and delete plugins/genie/.mcp.json; retain Claude's inline
  launcher and its regression coverage. Reconcile build + smoke gates.
- Tests: resolver fixtures for every layout, fail-closed absent-db, facade marker,
  plugin-route removal, and a two-repo migration integration test.
On umask-0002 hosts mkdirSync creates the harness TMPDIR parent
group-writable (775), which install.sh's validate_private_temp_root
correctly rejects — the suite then failed with exit 127 instead of
exercising the exit-2 contract. Pin the fixture dir to 0700 so the
test is umask-independent.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…flake

openReadonlyDb opened the read-only handle with a raw bun:sqlite call,
bypassing the shared sqlite-open primitive that sets busy_timeout first.
Under concurrent access a straggling WAL writer surfaced as an instant
-32603 "database is locked". Apply BUSY_TIMEOUT_MS to the readonly
connection (valid on readonly, no file mutation; absent-db still throws
before the pragma so the degrade-to-null contract holds). Quiesce the
Group-A test writers with wal_checkpoint(TRUNCATE) before readers open.
…e-umask

test(install): pin exit-2 fixture temp-parent mode to 0700
feat(codex): Group D — immutable delivery repair + .install-version lifecycle (dogfood-remediation)
Group A removed the Codex plugin MCP route (no manifest mcpServers, no MCP
capability, no plugin .mcp.json); the marker-owned project .codex/config.toml
is now the Codex MCP path and Claude keeps its inline launcher. proveCodexPluginHealth
still required snapshot.usable (Codex-MCP-route usability) and a read-only
wish_status that returned isError:false, so a fresh install --integrations codex
rejected the post-A plugin as unhealthy and smoke:codex failed.

Redefine plugin health: a healthy plugin provides skills + hooks + the retained
Claude mcp-launcher.cjs and does NOT register a Codex MCP route. Drop the
snapshot.usable gate (usable stays the project-route signal for isUsableCodexPlugin).
The bounded health session now accepts a fail-closed typed no-project-context
wish_status (project-context-unavailable / project-database-unavailable /
unsupported-project-layout) as read-only-healthy, since the throwaway probe cwd
is not a project — the launcher spawning and speaking MCP is the signal, an
absent board there is expected. Any other tool error is still rejected.

Update reject-matrix + health-session tests to the new contract; manifest/.mcp.json
absence assertions unchanged.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/genie-commands/__tests__/update.test.ts`:
- Around line 2829-2851: Update the test setup and the
attemptAlreadyCurrentDeliveryRepair flow so the per-test temporary GENIE_HOME
value is used when execution begins, rather than a module-level value captured
during import. Prefer passing the current genieHome through the helper and
relevant seams, or reload/reset the module after setting the environment; ensure
the empty isolated directory is what the repair scan observes.

In `@src/genie-commands/install.ts`:
- Around line 180-205: Update finalizeInstallDeliveryLifecycle so codexFailed
only suppresses publishDeferredInstallDeliveryFacts for the
auto-with-codex-failure path, while retireInstallVersionMarker(GENIE_HOME) still
runs independently. Revise the function’s doc comment to state this actual
invariant and describe marker retirement as unrelated orphan cleanup.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 64e02445-f504-4ce7-9ff0-93593ae82787

📥 Commits

Reviewing files that changed from the base of the PR and between a298d8d and dff0dd6.

📒 Files selected for processing (16)
  • .claude-plugin/marketplace.json
  • package.json
  • plugins/genie/.claude-plugin/plugin.json
  • plugins/genie/.codex-plugin/plugin.json
  • plugins/genie/package.json
  • plugins/hermes-genie/plugin.yaml
  • src/genie-commands/__tests__/update.test.ts
  • src/genie-commands/codex-delivery-repair.test.ts
  • src/genie-commands/codex-delivery-repair.ts
  • src/genie-commands/install.ts
  • src/genie-commands/update.ts
  • src/lib/codex-activation.ts
  • src/lib/install-version-marker.test.ts
  • src/lib/install-version-marker.ts
  • tests/integration/codex-delivery-bootstrap.test.ts
  • tests/integration/install-exit2-propagation.test.ts

Comment thread src/genie-commands/__tests__/update.test.ts
Comment thread src/genie-commands/install.ts Outdated
namastex888 and others added 2 commits July 22, 2026 19:42
feat(codex): Group A — project-route-context, empty-board masquerade closed (dogfood-remediation)

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

♻️ Duplicate comments (1)
src/lib/runtime-integrations.ts (1)

3325-3329: 🩺 Stability & Availability | 🟠 Major | ⚡ Quick win

Unresolved: consent-read errors still crash convergence.

Previously flagged: resolveConvergenceRoleAdoption calls readIntegrationConsentState/deps.readConsentState with no try/catch. Per readIntegrationConsentState (lines 139-208), anything besides an absent file (corrupt JSON, invalid schema, non-physical file) throws. Since installCodexIntegration now always passes genieHome: stateDir, a malformed .integration-consent.json will crash convergeCodexPluginOnly entirely instead of just disabling adoption.

🛡️ Proposed fix
 function resolveConvergenceRoleAdoption(options: ConvergeCodexPluginOnlyOptions, deps: CodexPluginOnlyDeps): boolean {
   if (deps.adoptHistoricalRoleAgents !== undefined) return deps.adoptHistoricalRoleAgents;
   if (options.genieHome === undefined) return false;
-  return codexRoleAdoptionAllowed((deps.readConsentState ?? readIntegrationConsentState)(options.genieHome));
+  try {
+    return codexRoleAdoptionAllowed((deps.readConsentState ?? readIntegrationConsentState)(options.genieHome));
+  } catch {
+    return false;
+  }
 }
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/lib/runtime-integrations.ts` around lines 3325 - 3329, Update
resolveConvergenceRoleAdoption to catch errors from the selected consent-state
reader, including deps.readConsentState or readIntegrationConsentState, and
return false when reading consent fails. Preserve the existing dependency
override and genieHome-undefined behavior so consent-read failures only disable
historical role adoption without crashing convergence.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/lib/codex-mcp-health-session.ts`:
- Around line 25-38: Replace the local NO_PROJECT_CONTEXT_ERROR_KINDS string set
in the health probe with a derived non-ok ProjectContextKind source imported
from genie-db.ts. Update the checks around the health probe flow to use that
shared source, preserving the existing expected wish_status handling while
ensuring future ProjectContextKind changes produce compile-time synchronization.

In `@tests/integration/codex-project-route-migration.test.ts`:
- Around line 77-84: Update the subprocess environment in driveBoard so it sets
GENIE_HOME to the test’s isolated temporary home, matching the genieHome value
used by runInit. Preserve the existing inherited environment and
NO_COLOR/GENIE_TEST_SKIP_PGSERVE settings while ensuring genie mcp cannot access
the host GENIE_HOME.

---

Duplicate comments:
In `@src/lib/runtime-integrations.ts`:
- Around line 3325-3329: Update resolveConvergenceRoleAdoption to catch errors
from the selected consent-state reader, including deps.readConsentState or
readIntegrationConsentState, and return false when reading consent fails.
Preserve the existing dependency override and genieHome-undefined behavior so
consent-read failures only disable historical role adoption without crashing
convergence.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: db71f2ad-50dd-4947-8658-05aba1f67601

📥 Commits

Reviewing files that changed from the base of the PR and between dff0dd6 and 17ad7bc.

📒 Files selected for processing (26)
  • .claude-plugin/marketplace.json
  • package.json
  • plugins/genie/.claude-plugin/plugin.json
  • plugins/genie/.codex-plugin/plugin.json
  • plugins/genie/.mcp.json
  • plugins/genie/package.json
  • plugins/hermes-genie/plugin.yaml
  • scripts/build-binary.sh
  • scripts/codex-plugin-only-smoke.ts
  • scripts/fresh-install-smoke.test.ts
  • scripts/fresh-install-smoke.ts
  • src/lib/codex-mcp-health-session.test.ts
  • src/lib/codex-mcp-health-session.ts
  • src/lib/codex-project-mcp.test.ts
  • src/lib/codex-project-mcp.ts
  • src/lib/runtime-integrations.test.ts
  • src/lib/runtime-integrations.ts
  • src/lib/v5/genie-db.ts
  • src/lib/v5/mcp-server.ts
  • src/lib/v5/mcp-tools.test.ts
  • src/lib/v5/mcp-tools.ts
  • src/term-commands/init.test.ts
  • src/term-commands/init.ts
  • src/term-commands/mcp.test.ts
  • src/term-commands/mcp.ts
  • tests/integration/codex-project-route-migration.test.ts
💤 Files with no reviewable changes (2)
  • plugins/genie/.mcp.json
  • scripts/build-binary.sh

Comment thread src/lib/codex-mcp-health-session.ts
Comment thread tests/integration/codex-project-route-migration.test.ts
…ation

Group E lifecycle-truth integration, doctor half:
- new codex-doctor-observation: ONE bounded 'codex plugin list --json' feeds
  the check-list probe, the integration summary (replay runner), and the
  sanitized advisory; Decision 11 applied once at the seam so the real
  sandbox PATH advisory can no longer contradict the fail-closed parser
- new codex-lifecycle-truth: shared Decision-9 delivery gate (snapshot record
  vs canonical target) + typed route-layer classifier (route-collision,
  route-shadowed, global-route-same-key, untrusted-config,
  project-trust-required)
- doctor: delivery-incomplete presentation when a green state lacks a
  matching authenticated record; typed routeLayers/advisory JSON riders;
  Codex project context check reuses the MCP server's resolveProjectContext
… a typed outcome

Group E lifecycle-truth integration, setup half:
- Decision 9: assess the authenticated delivery record BEFORE the first
  consent prompt or activation-owned mutation (the executor's beginActivation
  inner guard stays as defense in depth); missing/invalid/mismatched records
  exit delivery-incomplete with the one update/install recovery command and
  the machine-readable trailer
- Decision 12: every invocation ends in one typed SetupCodexOutcomeCode; the
  green saved banner and the wizard summary line flow from THIS run's outcome,
  never from historical codex.configured state
github-actions Bot and others added 6 commits July 23, 2026 15:30
Centralize authenticated delivery bindings, ordered lifecycle leases, and app-server test transport.

Preserve fail-closed delivery semantics and add focused regression coverage.

Wish: codex-plugin-dogfood-remediation
Keep the local delivery candidate aligned with auto-versioned repository metadata.

Wish: codex-plugin-dogfood-remediation
refactor(codex): trim delivery lifecycle duplication
chore(release): restore published dev manifest pointer
@socket-security

socket-security Bot commented Jul 23, 2026 •

Copy link
Copy Markdown

github-actions Bot and others added 9 commits July 23, 2026 17:37
…diation

fix(deps): remediate Socket dependency alerts
…d unmet)

- Status DONE; all nine success criteria checked against consolidated
  ledger evidence, with a note that per-group and QA criteria remain the
  historical execution record
- F01 CLOSED: PR #2562 CI passed 15 checks / 0 failures on its exact
  head bd8c612 under CI's pinned Bun 1.3.11 (repo declares >=1.3.10)
- F02 recorded **NOT MET**, not waived: #2562 carries one COMMENTED
  review and no APPROVED review, and the merging identity is the one the
  commits were authored under, so no independent approval exists
- F05/F44 closed by observation: the metrics-updater has committed
  nothing since 2026-07-14 and the maintainer's routine list is empty,
  but the owning account was never identified, so deletion is inferred
- standing conditions kept explicit: untrusted hook hashes, upstream-
  blocked startup probe, F16-F18/F31 still blocking stable release, no
  package rebuilt at the successor head, accepted lock/uninstall residuals

pm-ledger-verify run 3 recorded: 21 findings, 18 must-fix (wrong exact
SHA and a self-merge presented as independent approval) — all corrected
before this commit.
docs(wish): close pr-2545-ultra-release-gate (F01 closed, F02 recorde…
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants