Skip to content

fix: resolve 27 findings from merged PR reviews - #106

Merged
mrkillbobbot merged 6 commits into
mainfrom
codex/merged-review-repairs-20260913
Sep 20, 2026
Merged

mrkillbobbot merged 6 commits into
mainfrom
codex/merged-review-repairs-20260913

Conversation

@mrkillbob

Copy link
Copy Markdown
Owner

Repairs the 27 unresolved findings left on merged PRs #99, #101, #97, #91, and #88.

  • Persist the actual source checkout, support nonstandard Git layouts, and require independent worktree ownership claims before resume or cleanup.
  • Append gzip trajectory members with a durable recovery journal instead of copying historical data; respect the initial file umask. Interrupted appends recover on the next write.
  • Respect boolean egress settings and profile-scoped password-manager identities; avoid executing candidate plugin code during validation. Static capability checks explicitly do not certify runtime behavior or plugin safety.
  • Fix bootstrap synchronization, scheduled retry budgets, path-specific Git credentials, trusted terminal prompting, test discovery/OS markers, and internal import ownership.
  • Propagate gateway migration failure into update receipts; inventory all service scopes, restore surviving profiles independently, evict deleted profile plugin state, scope clone discovery to its source, and honor active federation reservations.
  • Cancel failed sign-ins, stop voice capture immediately, bind Kanban frames to their actual connection/profile, and move Discord registry I/O off the event loop.

Validation: 352 tests passed across all 18 changed Python test files through scripts/run_tests.sh; targeted desktop Vitest coverage passes (46 tests across seven files), including five regressions verified red on the original base. Additional worktree/Projects integration coverage passed. Linux/Windows-only checks require their hosted lanes. Full desktop TypeScript checking is blocked by existing missing Three.js declarations in world-glb-scene.tsx in the shared dependency installation; no changed-file errors were reported.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 13, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-14T17:47:12.489955Z f184138 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actions

github-actions Bot commented Sep 13, 2026 •

Copy link
Copy Markdown

૮ >ﻌ< ა ci review

ran on 63540a6 — Merge branch 'main' into codex/merged-review-repairs-2026091

⚠️ Warnings

OSV vulnerability scan · View job

12 known vulnerabilities found in pinned dependencies.

How to fix:

Review the findings in the Security tab. Update the affected dependencies if a patched version is available.


ℹ️ Info

CI-sensitive file review · View job

PR touches sensitive files, but the ci-reviewed label has been added, approving them.

Sensitive files changed:


debug info

CI timings

CI timings · View report · View job

Wall time 11m13s vs 11m44s (-4.4%). 8 job(s) slower, 22 faster, 1 unchanged.

  • Python tests / Run tests slice 8/8: -165.0s
  • Python tests / Run tests slice 6/8: -123.0s
  • Python tests / Run tests slice 5/8: -110.0s
  • Python lints / ruff enforcement (blocking): -61.0s
  • Python tests / Run tests slice 2/8: -53.0s

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a2fbcdabdc

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread hermes_cli/plugin_validate.py
Comment thread hermes_cli/plugin_validate.py
Comment thread agent/trajectory.py
Comment thread gateway/run_profile_reconcile.py Outdated
Comment thread tui_gateway/git_probe.py
- plugin_validate.py: accept re-exported register() via ImportFrom;
  exclude test/tests/_test/_tests dirs from capability scanning
- run_profile_reconcile.py: move evict_profile_plugins() off the
  gateway event loop via asyncio.to_thread (importlib locks)
- git_probe.py: fold --separate-git-dir worktrees into one repo
  identity by recognizing the worktrees/ segment of --git-common-dir

Co-authored-by: mrkillbob <mrkillbob@users.noreply.github.com>
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@mrkillbob

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f184138d9a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

from hermes_cli.plugins_loader import _plugin_home_scope

key = home.expanduser().resolve()
with plugins._plugin_managers_lock:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Release the global manager lock before plugin teardown

When a deleted profile's on_unload callback blocks, this worker holds _plugin_managers_lock throughout manager.unload(). Gateway hook paths synchronously call get_plugin_manager(), which needs the same process-wide lock, so the event-loop thread can still block and message delivery for unrelated profiles can stall indefinitely. Fresh evidence in this revision is that teardown was moved off-loop while the newly added lifecycle helper keeps the global lock around the unbounded callback execution.

Useful? React with 👍 / 👎.

Comment on lines +550 to +553
for service in desired_services:
if service not in current_services:
_service_op(*service, "install", default_home)
_service_op(*service, "start", default_home)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Restore only gateway services that were previously running

When both user and system service files exist for the default profile but only one was active before migration, _installed_services() records both without their running state and this rollback loop starts both. An explicit rollback or failed automatic migration can therefore launch two gateways for the same profile, causing credential/port contention and leaving the fleet unlike its pre-migration state; the manifest needs to preserve service activity or rollback must select the previously active scope.

Useful? React with 👍 / 👎.

Comment thread hermes_cli/federation.py
# directory exists. Recover only a provably abandoned reservation and
# retry the atomic claim once; never remove a live owner's lock.
if profile_dir.is_dir() or not _federation_seed_reservation_is_stale(profile_dir):
if (profile_dir.is_dir() and not refresh) or not _federation_seed_reservation_is_stale(profile_dir):

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Reclaim stale federation reservations without unlink races

When two --refresh-existing seeders concurrently encounter the same stale reservation, both can pass this stale check; after the first process unlinks and recreates the lock, the second can unlink that newly live reservation before performing its own O_EXCL create. Both processes may then believe they own the refresh, and their config, identity, skill-sync, snapshot rollback, and final lock removal operations can interleave. Reclaiming a stale lock needs to verify that the inode or reservation payload being removed is still the one that was inspected.

Useful? React with 👍 / 👎.

- Fix import sort order in voice-live.test.ts (add blank line between vitest and local import)
- Fix import sort order in kanban/api.source.test.ts (nanostores before vitest)
- Auto-fix padding-line-between-statements warnings via eslint --fix
- Fix react-hooks/exhaustive-deps: add missing VAULT_QUERY_KEY/VAULT_SOURCES_QUERY_KEY deps
- Remove unnecessary state?.phase dep in build.tsx useMemo
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@mrkillbob mrkillbob added the ci-reviewed Maintainer reviewed CI-sensitive changes label Sep 14, 2026
An empty or unparseable .federation_seed.lock file has no PID and
therefore no live owner. Treat it as stale immediately instead of
waiting out the 300s age floor, so seed_federation with
refresh_existing=True can reclaim a half-written lock left by a
crashed process.

Fixes test_seed_refresh_repairs_incomplete_profile_and_clears_artifacts.
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@mrkillbobbot mrkillbobbot added area/automation Managed PR metadata based on title and changed paths area/ci Managed PR metadata based on title and changed paths area/gui Managed PR metadata based on title and changed paths area/runtime Managed PR metadata based on title and changed paths codex PR authored by Codex type/bug Managed PR metadata based on title and changed paths labels Sep 16, 2026
@mrkillbobbot
mrkillbobbot merged commit 25c9f7b into main Sep 20, 2026
48 checks passed
@mrkillbobbot
mrkillbobbot deleted the codex/merged-review-repairs-20260913 branch September 20, 2026 04:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/automation Managed PR metadata based on title and changed paths area/ci Managed PR metadata based on title and changed paths area/gui Managed PR metadata based on title and changed paths area/runtime Managed PR metadata based on title and changed paths ci-reviewed Maintainer reviewed CI-sensitive changes codex PR authored by Codex type/bug Managed PR metadata based on title and changed paths

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants