Skip to content

chore: sync fork main and harden hosted-room lifecycle - #19

Merged
joojalre merged 33 commits into
mainfrom
codex/sync-fork-main-20260831-2
Sep 1, 2026
Merged

joojalre merged 33 commits into
mainfrom
codex/sync-fork-main-20260831-2

Conversation

@joojalre

@joojalre joojalre commented Aug 31, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • reconcile the fork with the upstream commits carried by this branch
  • preserve the upstream PKCE, Telegram shutdown, relay, and Windows fixes
  • harden hosted-room publication, cancellation, recovery, approval, prompt-budget, terminal-receipt, and SQLite lifecycle invariants
  • replace timing-sensitive hosted-room and virtual-history assertions with lifecycle conditions

Current head

87dec320debe42f6288d89327ee5d84669d8a2cf

Verification

  • all required GitHub checks pass on CI run 33387123843
  • Python slices 1/12 through 12/12, e2e, Windows-only, macOS-only, Ruff, Windows footguns, JS/TS, Nix, OSV, and supply-chain checks passed
  • local final-head checks: hosted-room runtime 33/33, virtual-history cache 17/17, Knowledge Sync 36/36, Windows backend readiness 21/21
  • UI-TUI and Desktop typechecks passed; Desktop production build passed
  • uv lock --check, npm audit --omit=dev, and git diff --check passed
  • review threads: 0/15 unresolved after exact-head evidence was posted

Review gate

A Codex review was requested for the exact current head. Do not merge until that review completes, the head is re-read, required checks remain green, and explicit merge approval is bound to the final SHA.

Safety

  • normal fast-forward pushes only; no force-push
  • no changes to Hostinger, DNS, email, credentials, or production
  • rollback references and isolated worktrees remain available

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Aug 31, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-01T03:32:50.981415Z 20d0a6a Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@joojalre

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e5b8f61c98

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tui_gateway/methods_groups.py Outdated
Comment thread gateway/hosted_rooms.py
Comment thread tui_gateway/hosted_room_service.py Outdated
Comment thread gateway/run.py
Comment thread gateway/hosted_room_discussion.py Outdated
Comment thread tui_gateway/hosted_room_server_rpc.py Outdated
@github-actions

github-actions Bot commented Aug 31, 2026 •

Copy link
Copy Markdown

૮ >ﻌ< ა ci review

ran on 20d0a6a — fix(groups): preserve concurrent disband and legacy approval

⚠️ Warnings

OSV vulnerability scan · View job

3 known vulnerabilities found in pinned dependencies.

How to fix:

Review the findings in the Security tab. Update the affected dependencies if a patched version is available.


debug info

CI timings

CI timings · View report · View job

Wall time 11m35s vs 10m8s (+14.3%). 13 job(s) slower, 9 faster, 1 unchanged.

  • Python tests / Run tests (4/12): +112.0s
  • Python tests / Run tests (12/12): -86.0s
  • JS & TS checks / JS & TS checks: +85.0s
  • Python tests / Run tests (1/12): +45.0s
  • Python tests / Run tests (11/12): -38.0s

benbarclay and others added 5 commits August 31, 2026 09:12
… hops stop dropping it (NousResearch#99176)

The PKCE payload is a flat 'provider=...;state=...;verifier=...;next=...'
string. A raw ';' is a cookie-attribute terminator, so Python's
http.cookies emits the value in RFC 6265 quoted form with each ';'
escaped as the backslash-octal '\073'. Mainstream browsers echo that
form back verbatim and Python parsers decode it — the browser round
trip is fine. But '"' and '\' are outside the plain cookie-octet set,
and non-Python hops that re-serialize the Cookie header reject the
value and drop the cookie entirely: Go's net/http (Traefik middleware,
Authentik outposts, other gateways) refuses any cookie value
containing a backslash. The OIDC callback then 400s with "Missing
PKCE state cookie" even though the browser sent the cookie.

Field reproduction: support thread "Still unable to use Authentik for
signin with traefik" — devtools showed the browser sending the intact
quoted \073 cookie on /auth/callback while Hermes logged
missing_pkce_cookie behind a Traefik+Authentik chain.

Fix: URL-encode the whole payload in set_pkce_cookie (quote(payload,
safe='') — ';' becomes '%3B') so the wire value contains only
cookie-octets and no parser in the chain has anything to reject, and
decode through a single shared inverse, cookies.parse_pkce_payload(),
in BOTH readers: the OAuth /auth/callback and the native
password-login path (routes.login_submit), whose broker/provider
binding check would otherwise parse zero segments from the
newly-encoded value and silently disable itself.

Regression coverage: the wire-shape test pins the full cookie-octet
set (the '"'/'\' assertions are the ones a Go-parser hop fails
pre-fix), the round-trip tests drive the real /auth/login →
/auth/callback path, and the next= test pins the exact post-login
redirect byte shape. Native-flow broker assertions updated to decode
through parse_pkce_payload instead of substring-matching the raw wire
value.

Salvaged from NousResearch#84065 (rebased onto current main, which gained the
SameSite=None PKCE attrs and the RFC 8252 native password flow since
the PR branched): kept main's _pkce_attrs cookie shape, extended the
fix to the login_submit reader the original PR predated, and reframed
the rationale — browsers do NOT truncate at the first ';' (there is
no literal ';' on the wire in the quoted form); the failing hop is a
strict middlebox cookie parser.

Closes NousResearch#83832

Co-authored-by: Kailigithub <12250313+Kailigithub@users.noreply.github.com>
_drain_polling_connections still bounded its shutdown()/initialize() with
asyncio.wait_for (NousResearch#66377), while its sibling the general-pool drain moved
to _await_with_thread_deadline (NousResearch#98094). httpcore's pool close runs under
AsyncShieldCancellation, so a cancellation-resistant close keeps wait_for
pending forever even after its timeout fires — the tracked
_polling_error_task wedges and every escalation gate behind it stalls.

Use the same wall-clock deadline helper (cancel + abandon, no cancel-await)
on both polling-drain awaits, and add a regression test whose close
swallows cancellation — the shape the existing cancellable-hang test
cannot catch.
_looks_like_connect_timeout and _looks_like_pool_timeout carried two
copies of the same 15-line DFS skeleton (seen-set, stack, __cause__/
__context__ descent) differing only in the one-line match predicate —
follow-up to the NousResearch#98094 review.

Extract _iter_exception_graph() and collapse both classifiers onto it.
Behavior is byte-identical (subprocess parity vs origin/main on real PTB
error fixtures: 6/6 identical), and the two classifiers gain direct unit
tests for the first time, including the cycle/diamond chain shapes the
inline copies had no coverage for.
@joojalre joojalre changed the title chore: finish upstream sync after PR #18 chore: sync fork with upstream through 6681f9e Aug 31, 2026
@joojalre

Copy link
Copy Markdown
Owner Author

@codex review

1 similar comment
@joojalre

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ca18e49eae

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread gateway/hosted_room_policy_checkpoint.py Outdated
Comment thread tui_gateway/hosted_room_service.py Outdated
Comment thread gateway/hosted_room_discussion.py Outdated
Comment thread tui_gateway/hosted_room_driver.py Outdated
@joojalre

Copy link
Copy Markdown
Owner Author

@codex review

benbarclay and others added 2 commits August 31, 2026 11:51
…mary identity (NousResearch#99206)

The stream consumer called prefers_fresh_final_streaming(text,
metadata=...) only, and no metadata producer stamps a platform key — so
RelayAdapter's hook always fell back to the PRIMARY descriptor's
platform (the scalar-vs-per-chat capability seam, third occurrence).
Two failure directions on multiplexed relays with
platforms.relay.extra.slack.unfurl_links/media: true (NousResearch#97957):

- Slack primary fronting Telegram/Discord: every link-bearing streamed
  final on the non-Slack chats finalized as a fresh send with no delete
  op advertised -> the answer delivered TWICE (orphaned preview).
- Non-Slack primary fronting Slack: the hook returned False, leaving
  the force-on unfurl feature dark on exactly the chats it shipped for.

Pass chat_id=self.chat_id from the consumer; the relay hook already
accepted it and resolves via _platform_by_chat + the per-platform
negotiated descriptor. Graduated TypeError fallback keeps the
single-platform hook signatures (Telegram, base class) and legacy test
doubles working unchanged.

Both regression tests verified RED against the unfixed consumer, GREEN
with the fix; single-platform relays are unaffected (NousResearch#97957's own 30
tests unchanged-green).

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8d42059049

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tui_gateway/methods_groups.py Outdated
Comment thread tui_gateway/hosted_room_server_rpc.py
Comment thread tui_gateway/server.py
Comment thread tui_gateway/hosted_room_driver.py Outdated
Comment thread tui_gateway/hosted_room_server_rpc.py
@joojalre

Copy link
Copy Markdown
Owner Author

@codex review

1 similar comment
@joojalre

Copy link
Copy Markdown
Owner Author

@codex review

@joojalre

Copy link
Copy Markdown
Owner Author

@codex review

Please review the current head only: 87dec32. Re-check the 15 unresolved review threads against this SHA, including outdated threads; do not treat outdated status alone as resolution.

@joojalre joojalre changed the title chore: sync fork with upstream through 6681f9e chore: sync fork main and harden hosted-room lifecycle Aug 31, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 87dec320de

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tui_gateway/hosted_room_service.py
Comment thread gateway/hosted_room_discussion.py Outdated
Comment thread tui_gateway/hosted_room_driver.py Outdated
Comment thread tui_gateway/hosted_room_driver.py Outdated
Comment thread hermes_cli/web_server.py Outdated
Comment thread gateway/hosted_room_driver.py
@joojalre

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

"""UPDATE hosted_rooms
SET authority_gateway_id=?, authority_epoch=?,
next_seq=next_seq+1, revision=revision+1, updated_at=?
WHERE room_id=?""",

P2 Badge Account authority-loss events against storage limits

Whenever a locally authoritative room is demoted, the preceding insert adds an authority.lost event, but this update advances only next_seq and never adds the event's encoded size to event_bytes. After one or more promotion/demotion cycles, both per-room and gateway-wide byte accounting understate the durable log, allowing later appends to exceed the configured storage bounds; compute the event size, apply the control-event capacity check, and increment event_bytes in this transaction.

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread gateway/hosted_rooms.py Outdated
Comment thread tui_gateway/hosted_room_driver.py Outdated
Comment thread tui_gateway/hosted_room_service.py Outdated
@joojalre

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d1ef0ea7d0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tui_gateway/hosted_room_driver.py Outdated
Comment thread plugins/platforms/telegram/adapter.py
@joojalre

Copy link
Copy Markdown
Owner Author

@codex review

Please review exact head 27cbc9b, including the cross-process Stop ownership fix and Telegram cancellation-resistant shutdown quarantine. Do not rely on reviews of older commits.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 27cbc9bbbb

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tui_gateway/hosted_room_driver.py
@joojalre

Copy link
Copy Markdown
Owner Author

@codex review

Please review exact head 10618eb. All 18 prior review threads now have exact-head evidence and are resolved. Local official-runner evidence: 310/310 across the eight modified hosted-room test files and 35/35 Telegram focused tests; all required GitHub checks are green. Please focus on Stop ownership/reclaim, admission fences, terminal publication correlation/reserve, and process identity, and report only findings that still apply to this exact head.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 10618eb097

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tui_gateway/hosted_room_service.py Outdated
Comment thread tui_gateway/hosted_room_server_rpc.py
Comment thread gateway/hosted_room_replicas.py Outdated
Comment thread tui_gateway/hosted_room_service.py Outdated
@joojalre

joojalre commented Sep 1, 2026

Copy link
Copy Markdown
Owner Author

@codex review

Please review exact head 7c6a0c8 only. All required GitHub checks pass and all prior review threads are resolved with exact-head evidence. Focus on atomic Stop/admission fencing, durable discussion and terminal capacity liabilities, correlated terminal replay, direct and cross-process demotion barriers, concurrent interrupt claims, and regressions across process boundaries. Re-open or add only findings that still apply to this SHA; do not rely on reviews of older commits.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7c6a0c8e64

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread gateway/hosted_rooms.py
Comment thread tui_gateway/hosted_room_service.py
Comment thread gateway/hosted_rooms.py
Comment thread gateway/hosted_room_driver.py Outdated
@joojalre

joojalre commented Sep 1, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 6db80964f7

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread gateway/hosted_room_replicas.py Outdated
Comment thread tui_gateway/hosted_room_driver.py Outdated
Comment thread tui_gateway/methods_groups.py
@joojalre

joojalre commented Sep 1, 2026

Copy link
Copy Markdown
Owner Author

@codex review

Please review exact head b7f1acd. Focus on the three remaining hosted-room concerns: replica promotion reserve accounting, durable member identity for approval actions including legacy payloads, and the durable disband admission barrier. Local evidence: 379 focused/broad tests passed via scripts/run_tests.sh, ruff passed, and git diff --check passed.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b7f1acdef0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tui_gateway/methods_groups.py
Comment thread tui_gateway/hosted_room_driver.py
@joojalre

joojalre commented Sep 1, 2026

Copy link
Copy Markdown
Owner Author

@codex review

Please review exact head 20d0a6a. This follow-up addresses the two prior exact-head findings: concurrent disband idempotence after another process commits the tombstone, and atomic migration/retirement of already-published legacy approval rows while preserving compatible decisions. Local evidence: 141 focused tests passed; 389 hosted-room/group tests passed;
uff check ., targeted y check --python ..., and git diff --check passed.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Breezy!

Reviewed commit: 20d0a6a423

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@joojalre
joojalre merged commit e6c0603 into main Sep 1, 2026
43 checks passed
@joojalre
joojalre deleted the codex/sync-fork-main-20260831-2 branch September 1, 2026 06:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants