chore: rolling promotion dev -> main - #2624
Conversation
…liveness releaseTask cleared claimed_by/claimed_at but left heartbeat_at, so after a release the card kept the prior owner's pulse. when a new worker checked it out, the liveness badge computed from the old heartbeat and could show a fresh checkout as running (▶) before it ever pulsed. clear heartbeat_at in the same conditional UPDATE; add a regression test (release → heartbeatAt null → survives re-claim). found by codex PR review of #2619 (P2).
fix(board): clear heartbeat_at on release so the next owner has no stale liveness
|
Caution The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased. |
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughCodex delivery is now authenticated before activation, repairable when already current, and fail-closed for invalid project context. Historical role-agent adoption, marker lifecycle handling, CWD evidence, heartbeat cleanup, MCP route changes, and release metadata updates are also included. ChangesCodex delivery and activation
Codex integrations and MCP routing
Lifecycle and release maintenance
Estimated code review effort: 5 (Critical) | ~120 minutes Sequence Diagram(s)sequenceDiagram
participant UpdateCommand
participant DeliveryRepair
participant DeliveryStore
participant Activation
UpdateCommand->>DeliveryRepair: assess or repair current delivery
DeliveryRepair->>DeliveryStore: read or publish attested record
DeliveryStore-->>DeliveryRepair: repair outcome
DeliveryRepair-->>UpdateCommand: repair directive
UpdateCommand->>Activation: converge or hand off
Activation-->>UpdateCommand: activation result
sequenceDiagram
participant IntegrationInstaller
participant PluginConvergence
participant ConsentState
participant RoleAgentInstaller
IntegrationInstaller->>PluginConvergence: provide genieHome
PluginConvergence->>ConsentState: read committed Codex consent
ConsentState-->>PluginConvergence: adoption decision
PluginConvergence->>RoleAgentInstaller: install with adoption option
RoleAgentInstaller-->>PluginConvergence: reconcile role-agent ownership
Possibly related PRs
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…wlist Close the dogfood-discovered role-agent gap where an old install fanned the seven Genie Codex role TOMLs into ~/.codex/agents with no managed inventory and a stale reviewer, leaving them permanently un-refreshed and unmanaged. - Add a frozen, versioned historical-profile allowlist (name + regular type + mode + content digest) covering every legitimately fanned role, grounded in the git history of plugins/genie/codex-agents (reviewer carries four). - On missing inventory, adopt a legacy file ONLY after committed Codex consent AND an exact allowlist match: record its on-disk identity as managed so the existing backup-first transaction refreshes a stale profile and writes the inventory atomically. Adoption is opt-in; bytes never grant ownership. - Wire convergeCodexPluginOnly to derive adoption from committed codex/all consent on both enabled and disabled (R3 fallback) paths, leaving injected installAgents seams untouched. - Extend the ownership report + doctor output with managed / adoptable-historical / collision / stale / personal states plus the expected delivered total and reviewer digest; a parity gate binds the canonical digests to the bundle. - Preserve unknown, modified, symlinked, and profile-lookalike collisions byte- and mode-identically; never overwrite, adopt, or delete them. Fixtures cover the observed 0/7-inventory state, stale reviewer, obsolete/ duplicate surfaces, unrelated personal agents, interrupted migration recovery, and repeated idempotent convergence. Validation: bun test src/lib/runtime-integrations.test.ts src/lib/agent-sync.test.ts — 403 pass, 0 fail.
Group B (host-observation-attestation) keystone for the dogfood remediation wish. - Add production CodexHostObservation: one immutable typed result of runtime/plugin-observable facts only (plugin facts, bounded sanitized advisory stderr, optional child self-report, cache-family witness, typed failure). Accepts advisory stderr only with exit 0 + exactly one schema-valid JSON stdout; rejects timeout/overflow/nonzero-exit/ malformed-or-duplicate JSON/invalid-version/duplicate-registration/ unsafe-cache. It never carries raw thread/start.cwd or control facts. - Add the pure authenticated-delivery-record assessment (matching|absent|invalid|mismatch) plus the stable delivery-incomplete result (authority none, exit 1, deliveryComplete false). - Enforce the assessment inside beginActivation immediately before the first journal write; a non-matching re-observed record refuses with zero mutation, so no stale permit bypasses the inner guard. Map the new begin result through the executor. - Extract the pure release-version grammar + stripControl into a leaf module so host-observation can share them with no import cycle; re- export from codex-activation for existing importers. - Add the black-box CodexCwdEvidence harness and a real codex app-server integration proof: MCP child effective process.cwd() equals a Codex- launched control by string + OS directory identity for root, nested, symlink-normalized, and linked-worktree layouts, with sequential and concurrent two-repo threads, per-case raw request + PID + effective CWD + tagged sentinel, and no PID crossing a differing effective CWD. Skips honestly when no runnable codex app-server is available.
feat(codex): Group C — managed role-agent convergence via frozen allowlist (dogfood-remediation)
the harness spawned codex async; a missing binary emitted an unhandled 'error' (ENOENT) at module load that escaped the caller's try/catch and aborted the whole file (CI: 1 fail + 2 errors). add a synchronous codex --version preflight that throws a caught error (=> honest skip) plus a benign child 'error' listener so a late spawn failure rejects initialize instead of throwing. codex-absent: 1 pass/7 skip/0 fail; codex-present: 8/0.
feat(codex): Group B — host-observation attestation + app-server CWD proof (dogfood-remediation)
There was a problem hiding this comment.
Actionable comments posted: 2
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
src/lib/runtime-integrations.ts (1)
953-1017: 🚀 Performance & Scalability | 🔵 Trivial | ⚡ Quick winRedundant
physicalRoleFileIdentityrecomputation per entry.For each ownership entry,
inspectCodexAgentOwnershipcallsphysicalRoleFileIdentity(path)directly (foridentity), thenclassifyCodexAgentFile(forownership) calls it again internally, andclassifyCodexAgentDisplayStatecalls it a third time (plus a fourth via its own internalclassifyCodexAgentFile(path, recorded)call) — up to 4 stat+hash passes over the same file per report entry, on everydoctorrun. The same pattern repeats on the install path:resolveCodexRoleAgentRecordcomputesphysicalRoleFileIdentity(targetPath)to check adoption eligibility, thencollectCurrentCodexAgentPayloadsimmediately callsclassifyCodexAgentFile(targetPath, recorded, sourceIdentity), which recomputes it again.Thread the already-computed
RoleFileIdentitythrough these functions instead of letting each one re-derive it independently.♻️ Sketch of the fix direction
-function classifyCodexAgentFile( - path: string, - recorded: RecordedCodexAgent | undefined, - legacyUpgradeIdentity?: RegularRoleFileIdentity, -): CodexAgentOwnership { - const actual = physicalRoleFileIdentity(path); +function classifyCodexAgentFile( + actual: RoleFileIdentity, + recorded: RecordedCodexAgent | undefined, + legacyUpgradeIdentity?: RegularRoleFileIdentity, +): CodexAgentOwnership { if (actual.kind === 'absent') return 'absent'; ...Then compute
physicalRoleFileIdentity(path)once per entry/target at the call sites and pass the result into both the ownership classifier andclassifyCodexAgentDisplayState/resolveCodexRoleAgentRecord.Also applies to: 1834-1868
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@src/lib/runtime-integrations.ts` around lines 953 - 1017, Thread a single computed RoleFileIdentity through the Codex ownership and install flows to eliminate repeated stat/hash work. Update classifyCodexAgentFile and classifyCodexAgentDisplayState to accept and reuse the caller-provided identity, then have inspectCodexAgentOwnership compute it once per entry and pass it to both classifiers. Apply the same reuse in resolveCodexRoleAgentRecord and collectCurrentCodexAgentPayloads so each target’s physicalRoleFileIdentity is computed only once.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/genie-commands/doctor.ts`:
- Around line 402-437: Update the suggestion condition in codexAgentCheck to
include counts.absent > 0 alongside adoptable, stale, and managed < total. Keep
the existing adopt/refresh message for any actionable missing or outdated role
agents, while preserving the collision-review message for collision-only cases.
In `@src/lib/runtime-integrations.ts`:
- Around line 3306-3317: Update resolveConvergenceRoleAdoption to safely handle
errors from the consent reader selected by deps.readConsentState or
readIntegrationConsentState. Preserve explicit deps.adoptHistoricalRoleAgents
overrides, but when options.genieHome is set and consent reading fails, catch
the error and return false so convergence continues with historical role
adoption disabled.
---
Outside diff comments:
In `@src/lib/runtime-integrations.ts`:
- Around line 953-1017: Thread a single computed RoleFileIdentity through the
Codex ownership and install flows to eliminate repeated stat/hash work. Update
classifyCodexAgentFile and classifyCodexAgentDisplayState to accept and reuse
the caller-provided identity, then have inspectCodexAgentOwnership compute it
once per entry and pass it to both classifiers. Apply the same reuse in
resolveCodexRoleAgentRecord and collectCurrentCodexAgentPayloads so each
target’s physicalRoleFileIdentity is computed only once.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 07815532-c922-411e-a471-a8e874a9d3b3
📒 Files selected for processing (5)
src/fixtures/codex-role-agent-allowlist.jsonsrc/genie-commands/doctor.tssrc/genie-commands/uninstall.test.tssrc/lib/runtime-integrations.test.tssrc/lib/runtime-integrations.ts
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@tests/support/codex-cwd-evidence.ts`:
- Around line 110-152: Update CodexCwdEvidence.launch to wrap post-creation
initialization, including request('initialize'), in cleanup-before-rethrow
handling. If initialization fails, close or terminate the spawned child and
remove harnessRoot before propagating the original error, using the constructed
harness cleanup path where available. Preserve successful launch behavior and
ensure late spawn failures receive the same cleanup.
- Around line 133-139: Update the child-process setup around spawn and stdin
writes to handle errors emitted by child.stdin, preventing dead or exited
app-server writes from becoming unhandled test-process errors. Attach an
appropriate stdin error handler and preserve request-level failure behavior,
while keeping the existing child error handling and initialize flow unchanged.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 9e9fc175-d080-4cb5-a37c-e2c927e0eedc
📒 Files selected for processing (15)
.claude-plugin/marketplace.jsonpackage.jsonplugins/genie/.claude-plugin/plugin.jsonplugins/genie/.codex-plugin/plugin.jsonplugins/genie/package.jsonplugins/hermes-genie/plugin.yamlsrc/lib/codex-activation-executor.test.tssrc/lib/codex-activation-executor.tssrc/lib/codex-activation.test.tssrc/lib/codex-activation.tssrc/lib/codex-host-observation.test.tssrc/lib/codex-host-observation.tssrc/lib/codex-release-version.tstests/integration/codex-app-server-cwd.test.tstests/support/codex-cwd-evidence.ts
… lifecycle Group D (immutable-delivery-repair): let update/install repair a MISSING authenticated delivery record for the installed target exactly once, without activation and without redefining the target from a moving channel. - src/genie-commands/codex-delivery-repair.ts: the injectable repair orchestrator — pin channel/version/platform/tag/name + manifest digest before download, download the exact asset, SHA-256 after, authenticate via the existing attestation/cosign anchors, prove the candidate against canonical installed bytes, recheck the channel under the lease (advance => ordinary upgrade, mint no stale record), reobserve + publish once. No-network fast path for matching records; every failure leaves state unchanged with deliveryComplete:false. - src/lib/install-version-marker.ts: the ONE .install-version lifecycle module (D-owned). Retire on convergence success, preserve on failure/unsafe, idempotent uninstall for either layout. Canonical VERSION stays authoritative. - src/lib/codex-activation.ts: additively extend the delivery record + publish input to carry the immutable attestation tuple (platform/tag/name/manifest/ artifact/binary/root); the store parser round-trips them. - update.ts: repair before the already-current return; retire the marker after successful convergence. - install.ts: deferred install publishes its matching record before the exit-2 handoff (idempotent); retire the marker on convergence success. All network/attestation/codex is stubbed in tests; the suite passes with codex present AND stripped from PATH (0 fail, 0 errors).
…y context Group A (project-route-context) of codex-plugin-dogfood-remediation. - Add resolveProjectContext in v5/genie-db: four-value model (effectiveLaunchCwd, worktreeConfigRoot, absolute gitCommonDir, genieStorageRoot=dirname(gitCommonDir)) with typed states project-context-unavailable / project-database-unavailable / unsupported-project-layout. Bare/submodule/external-git-dir are rejected before any DB lookup; nested repos stop at their own boundary; linked worktrees keep config under the linked root but read the DB under the common root's parent. - Wire the resolver into the shared MCP server loop (opt-in) so genie mcp fails closed with a structured error instead of masquerading as a healthy empty board; ui-bridge is unaffected. Re-resolve only until the context settles ok. - Add genieFacadeMcpEntry (<GENIE_HOME>/bin/genie, args [mcp], no cwd) and make genie init always reconcile one marker-owned Codex route independent of plugin and delivery state; remove the verified-current gate. - Remove the Codex plugin MCP route: drop mcpServers + MCP capability from the Codex manifest and delete plugins/genie/.mcp.json; retain Claude's inline launcher and its regression coverage. Reconcile build + smoke gates. - Tests: resolver fixtures for every layout, fail-closed absent-db, facade marker, plugin-route removal, and a two-repo migration integration test.
On umask-0002 hosts mkdirSync creates the harness TMPDIR parent group-writable (775), which install.sh's validate_private_temp_root correctly rejects — the suite then failed with exit 127 instead of exercising the exit-2 contract. Pin the fixture dir to 0700 so the test is umask-independent. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…flake openReadonlyDb opened the read-only handle with a raw bun:sqlite call, bypassing the shared sqlite-open primitive that sets busy_timeout first. Under concurrent access a straggling WAL writer surfaced as an instant -32603 "database is locked". Apply BUSY_TIMEOUT_MS to the readonly connection (valid on readonly, no file mutation; absent-db still throws before the pragma so the degrade-to-null contract holds). Quiesce the Group-A test writers with wal_checkpoint(TRUNCATE) before readers open.
…e-umask test(install): pin exit-2 fixture temp-parent mode to 0700
feat(codex): Group D — immutable delivery repair + .install-version lifecycle (dogfood-remediation)
Group A removed the Codex plugin MCP route (no manifest mcpServers, no MCP capability, no plugin .mcp.json); the marker-owned project .codex/config.toml is now the Codex MCP path and Claude keeps its inline launcher. proveCodexPluginHealth still required snapshot.usable (Codex-MCP-route usability) and a read-only wish_status that returned isError:false, so a fresh install --integrations codex rejected the post-A plugin as unhealthy and smoke:codex failed. Redefine plugin health: a healthy plugin provides skills + hooks + the retained Claude mcp-launcher.cjs and does NOT register a Codex MCP route. Drop the snapshot.usable gate (usable stays the project-route signal for isUsableCodexPlugin). The bounded health session now accepts a fail-closed typed no-project-context wish_status (project-context-unavailable / project-database-unavailable / unsupported-project-layout) as read-only-healthy, since the throwaway probe cwd is not a project — the launcher spawning and speaking MCP is the signal, an absent board there is expected. Any other tool error is still rejected. Update reject-matrix + health-session tests to the new contract; manifest/.mcp.json absence assertions unchanged.
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/genie-commands/__tests__/update.test.ts`:
- Around line 2829-2851: Update the test setup and the
attemptAlreadyCurrentDeliveryRepair flow so the per-test temporary GENIE_HOME
value is used when execution begins, rather than a module-level value captured
during import. Prefer passing the current genieHome through the helper and
relevant seams, or reload/reset the module after setting the environment; ensure
the empty isolated directory is what the repair scan observes.
In `@src/genie-commands/install.ts`:
- Around line 180-205: Update finalizeInstallDeliveryLifecycle so codexFailed
only suppresses publishDeferredInstallDeliveryFacts for the
auto-with-codex-failure path, while retireInstallVersionMarker(GENIE_HOME) still
runs independently. Revise the function’s doc comment to state this actual
invariant and describe marker retirement as unrelated orphan cleanup.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 64e02445-f504-4ce7-9ff0-93593ae82787
📒 Files selected for processing (16)
.claude-plugin/marketplace.jsonpackage.jsonplugins/genie/.claude-plugin/plugin.jsonplugins/genie/.codex-plugin/plugin.jsonplugins/genie/package.jsonplugins/hermes-genie/plugin.yamlsrc/genie-commands/__tests__/update.test.tssrc/genie-commands/codex-delivery-repair.test.tssrc/genie-commands/codex-delivery-repair.tssrc/genie-commands/install.tssrc/genie-commands/update.tssrc/lib/codex-activation.tssrc/lib/install-version-marker.test.tssrc/lib/install-version-marker.tstests/integration/codex-delivery-bootstrap.test.tstests/integration/install-exit2-propagation.test.ts
feat(codex): Group A — project-route-context, empty-board masquerade closed (dogfood-remediation)
There was a problem hiding this comment.
Actionable comments posted: 2
♻️ Duplicate comments (1)
src/lib/runtime-integrations.ts (1)
3325-3329: 🩺 Stability & Availability | 🟠 Major | ⚡ Quick winUnresolved: consent-read errors still crash convergence.
Previously flagged:
resolveConvergenceRoleAdoptioncallsreadIntegrationConsentState/deps.readConsentStatewith no try/catch. PerreadIntegrationConsentState(lines 139-208), anything besides an absent file (corrupt JSON, invalid schema, non-physical file) throws. SinceinstallCodexIntegrationnow always passesgenieHome: stateDir, a malformed.integration-consent.jsonwill crashconvergeCodexPluginOnlyentirely instead of just disabling adoption.🛡️ Proposed fix
function resolveConvergenceRoleAdoption(options: ConvergeCodexPluginOnlyOptions, deps: CodexPluginOnlyDeps): boolean { if (deps.adoptHistoricalRoleAgents !== undefined) return deps.adoptHistoricalRoleAgents; if (options.genieHome === undefined) return false; - return codexRoleAdoptionAllowed((deps.readConsentState ?? readIntegrationConsentState)(options.genieHome)); + try { + return codexRoleAdoptionAllowed((deps.readConsentState ?? readIntegrationConsentState)(options.genieHome)); + } catch { + return false; + } }🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@src/lib/runtime-integrations.ts` around lines 3325 - 3329, Update resolveConvergenceRoleAdoption to catch errors from the selected consent-state reader, including deps.readConsentState or readIntegrationConsentState, and return false when reading consent fails. Preserve the existing dependency override and genieHome-undefined behavior so consent-read failures only disable historical role adoption without crashing convergence.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/lib/codex-mcp-health-session.ts`:
- Around line 25-38: Replace the local NO_PROJECT_CONTEXT_ERROR_KINDS string set
in the health probe with a derived non-ok ProjectContextKind source imported
from genie-db.ts. Update the checks around the health probe flow to use that
shared source, preserving the existing expected wish_status handling while
ensuring future ProjectContextKind changes produce compile-time synchronization.
In `@tests/integration/codex-project-route-migration.test.ts`:
- Around line 77-84: Update the subprocess environment in driveBoard so it sets
GENIE_HOME to the test’s isolated temporary home, matching the genieHome value
used by runInit. Preserve the existing inherited environment and
NO_COLOR/GENIE_TEST_SKIP_PGSERVE settings while ensuring genie mcp cannot access
the host GENIE_HOME.
---
Duplicate comments:
In `@src/lib/runtime-integrations.ts`:
- Around line 3325-3329: Update resolveConvergenceRoleAdoption to catch errors
from the selected consent-state reader, including deps.readConsentState or
readIntegrationConsentState, and return false when reading consent fails.
Preserve the existing dependency override and genieHome-undefined behavior so
consent-read failures only disable historical role adoption without crashing
convergence.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: db71f2ad-50dd-4947-8658-05aba1f67601
📒 Files selected for processing (26)
.claude-plugin/marketplace.jsonpackage.jsonplugins/genie/.claude-plugin/plugin.jsonplugins/genie/.codex-plugin/plugin.jsonplugins/genie/.mcp.jsonplugins/genie/package.jsonplugins/hermes-genie/plugin.yamlscripts/build-binary.shscripts/codex-plugin-only-smoke.tsscripts/fresh-install-smoke.test.tsscripts/fresh-install-smoke.tssrc/lib/codex-mcp-health-session.test.tssrc/lib/codex-mcp-health-session.tssrc/lib/codex-project-mcp.test.tssrc/lib/codex-project-mcp.tssrc/lib/runtime-integrations.test.tssrc/lib/runtime-integrations.tssrc/lib/v5/genie-db.tssrc/lib/v5/mcp-server.tssrc/lib/v5/mcp-tools.test.tssrc/lib/v5/mcp-tools.tssrc/term-commands/init.test.tssrc/term-commands/init.tssrc/term-commands/mcp.test.tssrc/term-commands/mcp.tstests/integration/codex-project-route-migration.test.ts
💤 Files with no reviewable changes (2)
- plugins/genie/.mcp.json
- scripts/build-binary.sh
…ation Group E lifecycle-truth integration, doctor half: - new codex-doctor-observation: ONE bounded 'codex plugin list --json' feeds the check-list probe, the integration summary (replay runner), and the sanitized advisory; Decision 11 applied once at the seam so the real sandbox PATH advisory can no longer contradict the fail-closed parser - new codex-lifecycle-truth: shared Decision-9 delivery gate (snapshot record vs canonical target) + typed route-layer classifier (route-collision, route-shadowed, global-route-same-key, untrusted-config, project-trust-required) - doctor: delivery-incomplete presentation when a green state lacks a matching authenticated record; typed routeLayers/advisory JSON riders; Codex project context check reuses the MCP server's resolveProjectContext
… a typed outcome Group E lifecycle-truth integration, setup half: - Decision 9: assess the authenticated delivery record BEFORE the first consent prompt or activation-owned mutation (the executor's beginActivation inner guard stays as defense in depth); missing/invalid/mismatched records exit delivery-incomplete with the one update/install recovery command and the machine-readable trailer - Decision 12: every invocation ends in one typed SetupCodexOutcomeCode; the green saved banner and the wizard summary line flow from THIS run's outcome, never from historical codex.configured state
Centralize authenticated delivery bindings, ordered lifecycle leases, and app-server test transport. Preserve fail-closed delivery semantics and add focused regression coverage. Wish: codex-plugin-dogfood-remediation
Keep the local delivery candidate aligned with auto-versioned repository metadata. Wish: codex-plugin-dogfood-remediation
refactor(codex): trim delivery lifecycle duplication
chore(release): restore published dev manifest pointer
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
…diation fix(deps): remediate Socket dependency alerts
…d unmet) - Status DONE; all nine success criteria checked against consolidated ledger evidence, with a note that per-group and QA criteria remain the historical execution record - F01 CLOSED: PR #2562 CI passed 15 checks / 0 failures on its exact head bd8c612 under CI's pinned Bun 1.3.11 (repo declares >=1.3.10) - F02 recorded **NOT MET**, not waived: #2562 carries one COMMENTED review and no APPROVED review, and the merging identity is the one the commits were authored under, so no independent approval exists - F05/F44 closed by observation: the metrics-updater has committed nothing since 2026-07-14 and the maintainer's routine list is empty, but the owning account was never identified, so deletion is inferred - standing conditions kept explicit: untrusted hook hashes, upstream- blocked startup probe, F16-F18/F31 still blocking stable release, no package rebuilt at the successor head, accepted lock/uninstall residuals pm-ledger-verify run 3 recorded: 21 findings, 18 must-fix (wrong exact SHA and a self-merge presented as independent approval) — all corrected before this commit.
docs(wish): close pr-2545-ultra-release-gate (F01 closed, F02 recorde…
Empty commit to fire the dev release chain now that the upload-artifact pin fix is live on main. The publish-side jobs added by PR #2624 have never completed; this run is their shakeout.
Rolling Promotion PR
Auto-maintained rolling promotion PR from
devtomain.Process:
ready-to-mergeadded when all checks passSummary by CodeRabbit