Skip to content

docs(devlog): close the dev hardening unit with a promotion-readiness statement - #2752

Merged
lidge-jun merged 1 commit into
devfrom
codex/dev-hardening-readiness
Aug 27, 2026
Merged

lidge-jun merged 1 commit into
devfrom
codex/dev-hardening-readiness

Conversation

@lidge-jun

@lidge-jun lidge-jun commented Aug 27, 2026 •

Copy link
Copy Markdown
Owner

Summary

Closes the 260827 dev hardening unit with a record of what is proven about dev at 2a72cc017, what is deliberately not on it, and what a promoter still has to do. Docs only — no runtime change.

It is a state record, not an approval to promote. MAINTAINERS.md and scripts/release.ts remain the release authority.

What the unit changed

Work phase PR Merged as What it closed
wp1 #2738 5dfee1a05 inventory and remediation roadmap
wp2 #2739 ca3b379e1 dev carried a version behind its own releases
wp2b #2743 a57b9620a the version guard could go inert without fetch-tags
wp3 #2745 not merged credential identity on OAuth 429 rotation
wp4 #2746 802f04adc locale pages that contradicted the code
wp5 #2749 5000321e6 doctor:gui failed on dev, so prepush was routinely bypassed
wp6 #2751 2a72cc017 two invariants AGENTS.md claimed were enforced, and were not

Two things the statement is explicit about

PR #2745 stays open. It touches credential identity on OAuth 429 rotation, which MAINTAINERS.md puts behind explicit security review, so the identity drift is still present on dev. The review lane refuted the exploit's reachability — the missing continue recovery acts as an accidental guard — which is why this is a review-queue item rather than a release blocker. Anyone promoting dev should know it is there.

The audit scope was bounded. It covered the core/Lab boundary, the startup activation window, repository hygiene, the version line, locale docs, and the local gates. It did not cover provider adapters, the GUI beyond its lint configuration, or the release workflow itself. A green suite is evidence about code that has tests, and the statement says so rather than implying more.

Verification

  • dev = 2a72cc0173af36d4b8172b70ba0a3384db9e6047, 283 commits ahead of main (ec51e42d7, v2.33.0); package.json reads 2.34.0
  • full bun run test on the Linux host at the exact dev head: rc=0
  • Cross-platform CI green on every merged head in the table above (Linux, Windows, macOS)
  • every figure in the document was resolved from a command rather than from memory

Checklist

  • Local CI green (docs-only change; full suite on the remote host at the dev head)
  • Branch is on the latest dev commit
  • All correct Codex and CodeRabbit findings fixed
  • Ready for review

Summary by CodeRabbit

  • Documentation
    • Added a promotion-readiness record summarizing the current development status.
    • Documented completed and outstanding work, validation results, release requirements, and audit scope.
    • Recorded a known OAuth rate-limit credential-identity issue that remains unresolved.

… statement

Records what is proven about dev at 2a72cc0, what is deliberately not on it,
and what a promoter still has to do. It is a state record, not an approval to
promote: MAINTAINERS.md and scripts/release.ts remain the release authority.

The head is 283 commits ahead of main (ec51e42, v2.33.0) and package.json reads
2.34.0, so the version line now sits ahead of the published channel instead of
behind it, which was the wp2 defect.

Two things the statement is explicit about rather than quiet on. PR #2745 (wp3)
is open and must stay open: it touches credential identity on OAuth 429 rotation,
which MAINTAINERS.md puts behind security review, so the identity drift is still
present on dev. The reviewer refuted the exploit's reachability, which is why it
is a review-queue item and not a release blocker. And the audit scope was the
core/Lab boundary, the activation window, hygiene, the version line, locale docs,
and the local gates -- not provider adapters, not the GUI beyond lint config, and
not the release workflow itself.
@lidge-jun
lidge-jun requested a review from Ingwannu as a code owner August 27, 2026 11:16
@github-actions

Copy link
Copy Markdown
Contributor

✅ Deterministic PR hygiene checks passed.

@github-actions github-actions Bot added the documentation Improvements or additions to documentation label Aug 27, 2026
@coderabbitai

coderabbitai Bot commented Aug 27, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: e15d5168-0a28-4baf-ab91-88c6d26363c3

📥 Commits

Reviewing files that changed from the base of the PR and between 2a72cc0 and a195ba6.

📒 Files selected for processing (1)
  • devlog/_plan/260827_dev_hardening/070_wp7_promotion_readiness.md

📝 Walkthrough

Walkthrough

The pull request adds a promotion-readiness record for the dev hardening unit. It documents the target state, completed and incomplete work, validation results, the open OAuth 429 identity defect, promotion requirements, and audit exclusions.

Changes

Promotion readiness

Layer / File(s) Summary
Promotion-readiness documentation
devlog/_plan/260827_dev_hardening/070_wp7_promotion_readiness.md
Adds the promotion-readiness record at lines 1–60. It records the target commit and version state, hardening phases, local and cross-platform validation, the unmerged OAuth 429 credential-identity issue, maintainer-controlled release requirements, and audit scope exclusions.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Suggested reviewers: ingwannu

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/dev-hardening-readiness

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@lidge-jun
lidge-jun merged commit c457c70 into dev Aug 27, 2026
16 of 17 checks passed
@lidge-jun
lidge-jun deleted the codex/dev-hardening-readiness branch August 27, 2026 11:17

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a195ba6882

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +43 to +46
The review lane that examined it refuted the exploit's reachability — the missing
`continue recovery` acts as an accidental guard — so this is a correctness defect rather
than a live vulnerability. That is the reason it is a normal review queue item and not a
release blocker.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Remove the unfixed security assessment from the devlog

Because PR #2745 remains open and the credential defect is still present, these lines publish a severity assessment and the accidental guard that currently prevents exploitation in a tracked public directory. Repository policy requires findings, bypass reasoning, and assessments for unfixed security defects to remain in scratch space; remove these details from the promotion record until the fix has shipped.

AGENTS.md reference: AGENTS.md:L103-L108

Useful? React with 👍 / 👎.

Comment on lines +3 to +5
This is the closing record for the 260827 dev hardening unit. It states what is proven
about the current `dev` head, what is deliberately not on it, and what a promoter still
has to do. It is not an approval to promote.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Keep the unit open until the launcher failure is resolved

Calling this the unit's closing record omits the already-tracked wp8 result: 060_wp8_launcher_flake.md records two macOS failures of tests/update-stop-first.test.ts and explicitly classifies the recovery slowness as a known open defect. Consequently this closeout can tell a promoter the branch is ready while an unresolved readiness failure remains in the same unit; retain an open status and include wp8's disposition, or resolve it and then move the completed unit to _fin.

AGENTS.md reference: AGENTS.md:L83-L86

Useful? React with 👍 / 👎.

tarunravi pushed a commit to tarunravi/opencodex that referenced this pull request Sep 14, 2026
…readiness

docs(devlog): close the dev hardening unit with a promotion-readiness statement
agentHits pushed a commit to agentHits/opencodex that referenced this pull request Sep 17, 2026
…readiness

docs(devlog): close the dev hardening unit with a promotion-readiness statement
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant