Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
92 changes: 92 additions & 0 deletions devlog/_plan/260902_admin_merge_3190/000_plan.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,92 @@
# 000 — admin-merge remaining ready PRs, starting with #3190

Frozen at `origin/dev` = `5557772b7` (after #3189), 2026-09-02T02:40Z.
Worktree: `codex/260902-admin-merge-3190` tracking `origin/dev`.
Session: `01a05b23-083f-7413-a4d8-159a2ff4e2a1`.

## Loop-spec

- Archetype: HOTL maintainer merge train. One work-phase per PABCD cycle.
- Trigger: user said merge remaining ready work with admin, `--no-verify` pushes, no local full suite.
- Goal: land #3190 on `dev`, close superseded #2734, then refresh the live non-draft inventory and land only authorized mechanical leftovers.
- Non-goals: new product features, remote host QA, PDF/guide work, merging drafts, merging conflicting PRs, merging security-boundary PRs without a named security review, local `bun run test`.
- Verifier: `gh pr checks` on the exact head SHA (full rollup, not `--required` empty), then `git fetch origin && git merge-base --is-ancestor <merge> FETCH_HEAD`. Privacy repair also needs `bun run privacy:scan` exit 0.
- Stop: DONE when the inventory refresh finds no remaining authorized MERGEABLE item; BLOCKED if privacy/CI cannot be repaired without a new product change; UNSAFE if an auth/credential/workflow/release/dependency PR would land without security review.
- Memory: this unit. Goalplan slug `admin-merge-remaining-ready-opencodex-prs-onto-o`.
- Escalation: stop for a missing owner choice between two overlapping feature PRs that are not a documented carry.
- Resource bounds: this worktree + `gh`; serialize pushes/merges; unlimited `xai/grok-4.6` read-only reviewers already authorized.

## Class

C4 for the merge itself (protected `dev`, admin bypass). The only production-adjacent write in this train is the privacy-scan text fix in wp1. #3190's unique commits already exist; wp2 rebases and lands them.

## Why #3190 is first

It is the only current non-draft, MERGEABLE, maintainer-authored feature PR that is not `CHANGES_REQUESTED` and not a stale carry. Head `5f8cd24dd` is two unique commits on merge-base `e40245e4c` (#3169). It is 19 commits behind `origin/dev`. Cross-platform CI `gates` already failed on Privacy scan because GitHub merges that head with current `dev`, and current `dev` contains two remote-macOS home citations in `devlog/_plan/260902_multiplatform_qa_and_gui/091_wp6_merge_outcome.md`.

The scan only flags the macOS home-path shape. POSIX home prefixes and the Windows npm prefix that uses the allowed username `user` are a different detector. Allowed usernames in `devlog/` are the maintainer account plus `u` / `user` / `me` / `test`. The two remote macOS usernames in 091 are none of those.

## Why the other non-drafts are not in this train

| PR | Disposition | Reason |
| --- | --- | --- |
| #3142 | DEFER | CONFLICTING, CHANGES_REQUESTED |
| #3061 | DEFER | MERGEABLE but CHANGES_REQUESTED; macos/ci red; prior train already parked it |
| #2986 | DEFER | carry of #2083, CHANGES_REQUESTED; do not merge both |
| #2877 | DEFER | docs closeout, CHANGES_REQUESTED |
| #2805 | DEFER | CONFLICTING |
| #2783 | DEFER | CONFLICTING, CHANGES_REQUESTED |
| #2527 | DEFER | CONFLICTING, CHANGES_REQUESTED |
| #2366 | DEFER | MERGEABLE but CHANGES_REQUESTED, contributor feature |
| #2083 | DEFER | APPROVED original of the #2986 carry; merging both is forbidden |
| #2734 | CLOSE after #3190 | draft, CONFLICTING, superseded by #3190 |

wp3 re-reads this table live. A new MERGEABLE non-conflicted item that appears after #3190 can be appended; shrinking the table to escape the loop is forbidden.

## Work-phase map (dependency-ordered)

```
wp0 this unit (docs-only) -> 000 + 010 + 020 + 030
├── wp1 anonymize leaked remote home paths -> 010
├── wp2 rebase + exact-head CI + admin-merge 3190, close 2734 -> 020
└── wp3 refresh leftover inventory -> 030
```

Stack decision (`DEV-STACK-01`): do **not** stack wp1 under #3190. wp1 is a one-file text fix that every later PR inherits once it is on `dev`. Landing it first, then rebasing #3190 onto that tip, is cheaper than a mid-stack cascade. wp2 and wp3 are sequential because each merge invalidates the next candidate's merge-base.

## Scope boundary

**IN**

- Text-only anonymization of the two remote macOS home citations in 091 (and 020 if the Windows path is also a forbidden home-path hit).
- Rebase of #3190 unique commits onto current `origin/dev` after wp1 lands.
- `--no-verify` push of the rebase branch, exact-head CI, authorized admin squash merge.
- Close #2734 with credit after #3190 is an ancestor of `origin/dev`.
- Live refresh of open non-draft PRs; admin-merge only items that are MERGEABLE, not conflicting, not CHANGES_REQUESTED without a documented carry, and not security-boundary.

**OUT**

- Local full suite.
- Direct push to `dev`/`main`/`preview`.
- Merging #2083 and #2986 together.
- Re-implementing review blockers on parked PRs.
- Any auth, credential, workflow, release, or dependency-install change.

## Verifier commands that actually exist

- `bun run privacy:scan` -> `scripts/privacy-scan.ts` (reads `git ls-files`, including 091). Live run on HEAD `befefeb20` **exit 1**. Hits 091 line 13, two remote macOS homes. This is the wp1 red proof. After wp1 the same command must be exit 0 and name no 091 line.
- `gh pr view 3190 --json number,headRefOid,mergeable` live at freeze: `{"head":"5f8cd24ddf01082f35079c695a810324c33f4b3e","mergeable":"MERGEABLE","n":3190,"state":"OPEN"}` exit 0. Reads GitHub PR 3190, not the local 091 file.
- `gh pr checks 3190` live: `gates` fail (Privacy scan, job 99959406196, run 33538646261). Reads the exact-head check rollup for `5f8cd24dd`.
- `git merge-base --is-ancestor e40245e4c origin/codex/adaptive-reasoning-effort-2731` is true (merge-base of 3190). After merge, the command becomes `git fetch origin && git merge-base --is-ancestor <merge> origin/dev` and must exit 0.

Deferred non-draft freeze (same `gh pr list --state open` pass): #3142 CONFLICTING+CHANGES_REQUESTED, #3061 MERGEABLE+CHANGES_REQUESTED with macos/ci red, #2986 carry of #2083 CHANGES_REQUESTED, #2877 CHANGES_REQUESTED, #2805/#2783/#2527 CONFLICTING, #2366 CHANGES_REQUESTED, #2083 APPROVED original of the carry, #2734 draft CONFLICTING.

No `bun run test`. Focused tests only if wp2's rebase conflict touches `src/` or `tests/` unexpectedly.

## Field chain (PLAN-FIELD-CHAIN-01)

No new runtime field. N/A: this train does not add config/API keys. #3190 already added `reasoningEffortMode` and `omitReasoningEffortWithToolsModels` on its own branch; wp2 lands that existing chain, it does not invent a second one.

## Bypass named (PLAN-BYPASS-NAMED-01)

Admin squash merge is the named bypass of required maintainer approval on owner-authored PRs. It does not bypass: exact-head CI evidence, `enforce-target`, privacy:scan, or security review for security-boundary diffs. Record the bypass rationale on each merge comment.
18 changes: 18 additions & 0 deletions devlog/_plan/260902_admin_merge_3190/002_audit_round1.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
# 002 — audit round 1 synthesis

Reviewer: subagent Arendt (`01a05e18-6441-7251-b417-2aacda38462e`), `$codexclaw:cxc-dev-code-reviewer` + `$codexclaw:cxc-search`.

`VERDICT: GO-WITH-FIXES (blockers=1)`

## Blocker 1 (High) — folded

PLAN-VERIFIER-REAL-01: 000 listed verifier commands without exit codes or reads-target proof. Folded into `000_plan.md` "Verifier commands that actually exist":

- `bun run privacy:scan` live exit 1 on `befefeb20`, hits 091 line 13, reads `git ls-files`.
- `gh pr view 3190` live exit 0, MERGEABLE, head `5f8cd24dd`.
- `gh pr checks 3190` live: gates Privacy scan fail, run 33538646261 job 99959406196.
- merge-base of 3190 is `e40245e4c`; post-merge command named.

No residual High/Critical blockers. Non-blocking: stacking decision and deferred-PR table were confirmed sound.

Main-agent judgment: near-pass. Residual: none after the fold.
Original file line number Diff line number Diff line change
@@ -0,0 +1,63 @@
# 010 — wp1: anonymize leaked remote home paths on origin/dev

Depends on: wp0 (this unit exists). Independent of #3190's unique commits.

## Defect

`scripts/privacy-scan.ts` matches `/Users/<username>/` and fails any username that is not the maintainer account or the allowlist `u` / `user` / `me` / `test`. After #3181, `devlog/_plan/260902_multiplatform_qa_and_gui/091_wp6_merge_outcome.md` quotes two remote macOS home prefixes as the example of what the scan caught. That citation re-introduces the same shape, so every later PR whose GitHub merge commit includes current `dev` fails `gates` / Privacy scan. This is why #3190's matrix is red even though #3190 itself does not contain that file.

CI evidence (Cross-platform CI run 33538646261, job 99959406196, head `5f8cd24dd`):

```
Privacy scan failed:
devlog/_plan/260902_multiplatform_qa_and_gui/091_wp6_merge_outcome.md:13 home-path: /Users/<remote-a>/
devlog/_plan/260902_multiplatform_qa_and_gui/091_wp6_merge_outcome.md:13 home-path: /Users/<remote-b>/
```

Do not paste the real usernames into this unit. The scanner would fail this file the same way.

A second candidate is line 29 of `020_wp3_wp5_deploy_qa.md`, the Windows npm prefix under `/c/Users/user/...`. Username `user` is allowed. Confirm with a live `bun run privacy:scan` rather than assuming; if it is clean, leave 020 untouched.

## Diff (MODIFY only)

File: `devlog/_plan/260902_multiplatform_qa_and_gui/091_wp6_merge_outcome.md`

Before (line 13-15, sense only — do not restore the forbidden shape):

```
두 번째가 제일 의미 있다. 문서에 <two remote macOS homes>,
<posix home>, <windows npm prefix>를 실측 그대로 적었는데, 그건 다른 사람의
홈 경로다. 스캔이 정당하게 잡았고 `~/`로 바꿨다.
```

After:

```
두 번째가 제일 의미 있다. 문서에 원격 macOS 홈 경로 두 개,
POSIX 홈, Windows npm 접두를 실측 그대로 적었는데, 그건 다른 사람의
홈 경로다. 스캔이 정당하게 잡았고 `~/`로 바꿨다.
```

No other files. Do not edit `scripts/privacy-scan.ts` to widen the allowlist. The detector is correct; the citation is the bug.

## Steps

1. `git fetch origin && git switch -C codex/260902-privacy-091 origin/dev` if the current branch already carries later work; otherwise stay on `codex/260902-admin-merge-3190` while it still equals `origin/dev` plus this unit's docs.
2. Apply the 091 edit. Confirm `git grep -n '/Users/' -- devlog/_plan/260902_multiplatform_qa_and_gui` no longer prints a forbidden username.
3. `bun run privacy:scan` — exit 0. If it still names 091, the replacement still matches the regex; rewrite again without the `/Users/<name>/` shape.
4. Commit: `docs(devlog): drop remote home-path citations the privacy scanner flags`.
5. Push `--no-verify`. Open a PR targeting `dev`. Fill the template. This PR does not mention `gui` in title or body, so no screenshot gate.
6. Exact-head CI. `gates` / Privacy scan must be SUCCESS on this head. Other jobs may still be in flight; do not merge on a red privacy scan.
7. Admin squash merge with rationale: docs-only, privacy-scan self-repair, no production surface.
8. Proof: `git fetch origin && git merge-base --is-ancestor <merge> origin/dev`.

## Accept

- `bun run privacy:scan` exit 0 on the repair head.
- 091 no longer contains a `/Users/<other>/` token.
- The merge commit is an ancestor of `origin/dev`.
- `scripts/privacy-scan.ts` is unchanged.

## Activation scenario (C-ACTIVATION-GROUNDING-01)

Trigger: run `bun run privacy:scan` on a tree that includes the edited 091. Observable: stdout `Privacy scan passed`, exit 0. Negative: restoring the old 091 line must fail again — do not restore it; the CI log of run 33538646261 is the red proof.
3 changes: 3 additions & 0 deletions devlog/_plan/260902_admin_merge_3190/011_wp1_stale_check.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
# 011 — wp1 stale check against current tree

Rebased this branch onto `origin/dev` = `c87071400` (#3194) before wp1 implementation. 091 is unchanged: line 13 still has the two remote macOS home-path tokens that `bun run privacy:scan` reports. 020's Windows npm prefix uses allowed username `user` and is not a scan hit. 010's replacement text is still valid; no line-number drift.
Original file line number Diff line number Diff line change
@@ -0,0 +1,62 @@
# 020 — wp2: rebase, exact-head CI, admin-merge #3190, close #2734

Depends on: wp1 landed on `origin/dev` so a GitHub merge of this head no longer inherits the 091 privacy failure.

## What #3190 is

PR #3190, author `lidge-jun`, branch `codex/adaptive-reasoning-effort-2731`, targets `dev`.
Two unique commits on merge-base `e40245e4c` (#3169):

- `e1fc1729b` feat(combo): adapt reasoning effort to target capabilities
- `5f8cd24dd` test(combo): cover adaptive effort mode and the tool-bearing opt-out

35 files. Completes #2731. Supersedes draft #2734. Opt-in `reasoningEffortMode: "adaptive"` (default remains `"strict"`) plus `omitReasoningEffortWithToolsModels` on openai-chat, plus the dashboard round-trip #2734 left open.

Not a security-boundary PR: no auth, credential, workflow, release, or dependency-install change. Admin merge still needs exact-head CI, not an empty `--required` list.

## Why rebase, not merge-as-is

Head is 19 commits behind `origin/dev` at freeze. GitHub merge with current `dev` is what made Privacy scan fail. After wp1, rebase onto the new `origin/dev` so:

1. the unique two commits sit on the privacy-clean tip;
2. later landings (#3172 combo default effort, #3175 failover e2e assertion, #3189 alias overlay, …) are in the base rather than conflicted at merge time.

Do not force-push the original contributor-looking branch if a rebase rewrite is cleaner as a new maintainer branch. Prefer:

```
git fetch origin
git switch -C codex/adaptive-reasoning-effort-2731-rebased origin/dev
git cherry-pick e1fc1729b 5f8cd24dd
```

If cherry-pick is clean, push `--no-verify` and either retarget #3190's head or open a carry PR that closes #3190. If #3190 still points at the old branch and `maintainerCanModify` is ourselves, pushing the same branch after rebase is allowed; use `--force-with-lease` only on that topic branch, never on `dev`.

Conflict policy: stop and inspect. Likely touch points are combo catalog / openai-chat / GUI combo serializer because #3172 already landed combo default-effort behavior. Do not silently drop #3190 tests.

## PR hygiene

Title/body mention combo GUI. `enforce-target` requires a screenshot of the UI change. #3190 already carries a placeholder image; after rebase confirm the body still has Summary / Verification / Checklist and a real screenshot, not a 1×1 dummy. If the dummy is still there, replace it with a captured Capabilities-section shot from a local GUI build (no full suite).

## Steps

1. Confirm wp1 merge is an ancestor of `origin/dev`.
2. Cherry-pick or rebase the two unique commits onto that tip.
3. If conflicts: resolve against current combo/openai-chat/GUI code; keep both the adaptive-mode behavior and the #3172 default-effort behavior.
4. Focused checks only: `bun x tsc --noEmit`; `cd gui && bun x tsc --noEmit` if GUI files changed; `bun test tests/codex-catalog.test.ts tests/openai-chat-hardening.test.ts tests/combo-management-api.test.ts tests/combo-workspace-data.test.ts tests/combos.test.ts tests/management-provider-validation.test.ts` if those files still exist after rebase; `bun run privacy:scan`.
5. Push `--no-verify`. Refresh #3190 (or open the carry). Fill the template.
6. Wait for exact-head Cross-platform CI on the new SHA. Record the run id. `gates` Privacy scan must be SUCCESS. Known macOS websocket flake: rerun that job, compare against #3128, do not rewrite unrelated code.
7. Admin squash merge: `gh pr merge <n> --squash --admin --delete-branch` with comment naming the bypass (owner-authored, CI green on exact head, no security-boundary).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Bind the admin merge to the verified head

If another push updates the PR after step 6 checks the head but before this command runs, --admin can merge that new, unverified revision because the merge is not bound to the SHA whose CI was inspected. The installed gh pr merge --help explicitly provides --match-head-commit SHA for ensuring that “the pull request head must match to allow merge”; pass the verified headRefOid through that option so a concurrent update aborts rather than bypassing exact-head CI. This repository also resets readiness whenever the head changes, so the merge step must preserve that invariant.

AGENTS.md reference: AGENTS.md:L296-L299

Useful? React with 👍 / 👎.

8. Proof: `git fetch origin && git merge-base --is-ancestor <merge> origin/dev`.
9. Close #2734 with a comment: superseded by the landed #3190 merge SHA. Close #2731 only if the landed PR says Closes and the issue is still open — `dev` is not the default branch, so GitHub will not auto-close; close manually if the PR claims it.

## Accept

- Unique #3190 behavior is on `origin/dev` (adaptive mode + tool-bearing omit + GUI round-trip).
- Exact-head CI rollup for the merged SHA is recorded, including `gates` SUCCESS.
- `git merge-base --is-ancestor <merge> origin/dev` is true.
- #2734 is closed with credit.
- This worktree is not left on a deleted remote branch (switch back to a live topic or `origin/dev` tracking branch after delete).

## Activation

Trigger: after merge, `git fetch origin && git merge-base --is-ancestor <merge> origin/dev`; exit 0. Negative: if the merge commit is missing, do not claim DONE.
Original file line number Diff line number Diff line change
@@ -0,0 +1,64 @@
# 030 — wp3: refresh leftover inventory and merge only authorized ready items

Depends on: wp2 (#3190 on `origin/dev`).

## Fresh read, not the freeze table

At wp0 freeze the only authorized merge candidate was #3190. wp3 exists because the user asked to finish remaining ready work, not to stop after one PR. Re-run the inventory; do not reuse the freeze table as if it were live.

```
git fetch origin --prune
gh pr list --state open --limit 80 --json number,title,author,isDraft,mergeable,reviewDecision,headRefName,url
```

Then for every non-draft row:

```
gh pr view <n> --json number,title,isDraft,mergeable,mergeStateStatus,reviewDecision,headRefOid,statusCheckRollup,files
```

## Authorization filter (all must hold)

1. `isDraft == false`
2. `mergeable == MERGEABLE` (not CONFLICTING, not UNKNOWN-as-conflict)
3. Not `CHANGES_REQUESTED` unless this train already carries the requested change
4. Not a security-boundary diff (auth, credential, OAuth, workflow, release, dependency install) unless a named security review is already on the exact head
5. Not both of a documented pair (#2083 original and #2986 carry)
6. Not a parked item whose prior train already recorded a substantive blocker (#3061 launcher budget)

If zero rows survive, wp3 is NOOP with the live table recorded in an outcome doc, and criterion c-4 is met by that recording.

If a new row survives, land it the same way as wp2: rebase onto current `origin/dev` if behind, `--no-verify` push, exact-head CI, admin squash merge, fetch + merge-base proof. One PR per inner loop; do not batch-merge.

## Known likely leftovers after #3190

| PR | Expected live disposition | Merge now? |
| --- | --- | --- |
| #3142 | still CONFLICTING | no |
| #3061 | still CHANGES_REQUESTED + red macos | no |
| #2986 / #2083 | overlapping image-gen carry | no (pair) |
| #2877 | CHANGES_REQUESTED docs | no |
| #2805 #2783 #2527 | CONFLICTING | no |
| #2366 | CHANGES_REQUESTED contributor feature | no |
| #2734 | should already be closed by wp2 | verify |

A docs-only MERGEABLE PR with no CHANGES_REQUESTED and green hygiene (the #3114 shape) may be landed. Do not invent that it exists; the live list decides.

## Steps

1. Produce a timestamped table of every open non-draft PR with mergeable/review/CI bucket.
2. Apply the filter. Write survivors (possibly empty) into `031_wp3_outcome.md` at C, not here.
3. For each survivor, rebase / exact-head CI / admin merge / proof, serialized.
4. Re-fetch after each merge before judging the next row.
5. Switch this worktree off any deleted head branch.

## Accept

- Live inventory captured after #3190 landed.
- Every survivor that passed the filter is on `origin/dev` with merge-base proof, or the survivor list is empty and recorded.
- No conflicting, draft, or CHANGES_REQUESTED-without-carry PR was merged.
- #2083 and #2986 were not both merged.

## Activation

Trigger: the timestamped `gh pr list` output in the outcome doc is newer than the #3190 merge time. Observable: each claimed merge SHA is an ancestor of `origin/dev`. Negative: claiming c-4 from the wp0 freeze table without a second `gh pr list`.
Loading
Loading