Skip to content

feat(codex): Group C — managed role-agent convergence via frozen allowlist (dogfood-remediation) - #2626

Merged
namastex888 merged 1 commit into
devfrom
wish/dogfood-C
Jul 22, 2026
Merged

namastex888 merged 1 commit into
devfrom
wish/dogfood-C

Conversation

@namastex888

Copy link
Copy Markdown
Contributor

Wave 1 of codex-plugin-dogfood-remediation. Group C (independent of B).

What

  • Frozen versioned historical-profile allowlist (src/fixtures/codex-role-agent-allowlist.json): name + type + mode + content digest for every legitimately-fanned Genie Codex role; digests grounded in real git history; a parity gate binds them to the actual bundle bytes.
  • Consent-gated adoption: an inventory-free file is adopted only with committed codex/all consent and an exact allowlist-tuple match — backup-first, atomic inventory write, then stale-profile refresh. Bytes never grant ownership.
  • Convergence: plugin-namespaced agents authoritative while enabled; removes only inventory-owned/exact-historical duplicates; R3 preserved (disabled/absent plugin still restores fallback roles). .curated is never resurrected.
  • Preservation, proven byte+mode identical: modified, unknown, broken-symlink (never followed), and profile-lookalike collisions are reported and never overwritten/adopted/deleted.
  • Doctor/inventory now distinguish managed / adoptable-historical / collision / stale / personal and report the expected delivered total + reviewer digest.

Validation (reproduced by orchestrator)

bun test src/lib/runtime-integrations.test.ts src/lib/agent-sync.test.ts → 403 pass / 0 fail. typecheck/lint/dead-code/complexity-budget clean.

Adversarial execution review: SHIP (0 gaps), independently reproduced. Orchestrator re-ran the suite, confirmed no .curated writes, and read the byte-identical preservation + broken-symlink safety tests.

…wlist

Close the dogfood-discovered role-agent gap where an old install fanned the
seven Genie Codex role TOMLs into ~/.codex/agents with no managed inventory
and a stale reviewer, leaving them permanently un-refreshed and unmanaged.

- Add a frozen, versioned historical-profile allowlist (name + regular type +
  mode + content digest) covering every legitimately fanned role, grounded in
  the git history of plugins/genie/codex-agents (reviewer carries four).
- On missing inventory, adopt a legacy file ONLY after committed Codex consent
  AND an exact allowlist match: record its on-disk identity as managed so the
  existing backup-first transaction refreshes a stale profile and writes the
  inventory atomically. Adoption is opt-in; bytes never grant ownership.
- Wire convergeCodexPluginOnly to derive adoption from committed codex/all
  consent on both enabled and disabled (R3 fallback) paths, leaving injected
  installAgents seams untouched.
- Extend the ownership report + doctor output with managed / adoptable-historical
  / collision / stale / personal states plus the expected delivered total and
  reviewer digest; a parity gate binds the canonical digests to the bundle.
- Preserve unknown, modified, symlinked, and profile-lookalike collisions
  byte- and mode-identically; never overwrite, adopt, or delete them.

Fixtures cover the observed 0/7-inventory state, stale reviewer, obsolete/
duplicate surfaces, unrelated personal agents, interrupted migration recovery,
and repeated idempotent convergence.

Validation: bun test src/lib/runtime-integrations.test.ts
src/lib/agent-sync.test.ts — 403 pass, 0 fail.
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@coderabbitai

coderabbitai Bot commented Jul 22, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 601bf19c-7b42-4d69-ae82-8cfc1015e9cf

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch wish/dogfood-C

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

if (!roleFileIdentityEquals(acceptedIdentity, sourceIdentity)) {
plan.writes.set(name, { content: sourceContent, identity: sourceIdentity });
plan.expected.set(name, acceptedIdentity);
}

P2 Badge Authenticate no-rewrite adoptions before inventory

For an inventory-free profile that already equals the current source, acceptedIdentity equals sourceIdentity, so this branch creates no journal operation for that role and the transaction publishes only .genie-role-agents.json. If the role file is edited between resolveCodexRoleAgentRecord and inventory promotion (for example at the existing beforePromotion('inventory') hook), no preimage check runs and the new inventory claims the edited user file as Genie-owned; adoption needs a no-op/preimage assertion even when no rewrite is needed.

AGENTS.md reference: AGENTS.md:L29-L31

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +3314 to +3315
if (options.genieHome === undefined) return false;
return codexRoleAdoptionAllowed((deps.readConsentState ?? readIntegrationConsentState)(options.genieHome));

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Pass GENIE_HOME into update adoption

When genie update runs after committed codex/all consent, it reaches runManualUpdateConvergence → refreshUpdatePlugins → convergeCodexForUpdateDelivery, but that caller never supplies genieHome; with this new default, resolveConvergenceRoleAdoption returns false for the entire update path. The N≠T deferral path also calls installCodexAgents without convergence options, so exact historical role profiles remain skipped/adoptable after update even though this change advertises update delivery/refresh. Please wire the consent home/adoption flag through update instead of disabling adoption there.

Useful? React with 👍 / 👎.

Comment on lines +425 to +427
counts.adoptable > 0 || counts.stale > 0 || counts.managed < total
? 'Run `genie setup --codex` to adopt and refresh delivered role agents; personal and collision files are never overwritten.'
: 'Review collision role agents (modified/symlinked/lookalike); Genie will not overwrite them, then run `genie setup --codex`.';

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Point doctor at a converging command

This warning fires for stale/adoptable role agents, but the suggested genie setup --codex command does not run role-agent convergence: setup.ts explicitly says role-agent delivery is done by update/install and configureCodex only activates the plugin, reconciles project MCP, and persists consent. Users who follow this advice can return to the same warning until they run a path that invokes installCodexAgents, so the doctor should suggest such a command or setup should perform the convergence.

Useful? React with 👍 / 👎.

@namastex888
namastex888 merged commit 8284d5f into dev Jul 22, 2026
16 checks passed
lirazsiri pushed a commit to lirazsiri/genie that referenced this pull request Jul 28, 2026
…s, IN_PROGRESS

The H3 SessionStart line surfaced ledger drift: waves 1+2 shipped 2026-07-22
(PRs automagik-dev#2625/automagik-dev#2626/automagik-dev#2628/automagik-dev#2629, per-group SHIP reviews, validations reproduced)
but their evidence and criteria were never recorded; status still read
APPROVED with execution long underway.

- status APPROVED -> IN_PROGRESS
- 41 evidence-backed criteria ticked (5 -> 46/67): Groups A-D ACs + global
  criteria owned by merged groups; deliberately NOT ticked: the two live
  'codex mcp get genie --json' operator proofs, Group F/G criteria, and all
  post-merge QA rows
- appended the waves-1+2 evidence block, the seven live-QA fixes
  (automagik-dev#2631-automagik-dev#2634, automagik-dev#2636), Group E's actual merge commit (4be6917), and the
  open automagik-dev#2633-deferred follow-up (pre-A route-arm retirement)

Adversarially verified pre-commit by the pm-ledger-verify workflow: 0
must-fix; its 4 advisory findings (defect count, untracked follow-up,
unrecorded E merge) are incorporated above.
@automagik-genie
automagik-genie deleted the wish/dogfood-C branch September 25, 2026 04:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant