Skip to content

Codex 0.157.1 switched on the workstation (daemon-safe) + native quota probe and runner gate - #348

Merged
seathatflowsinourveins merged 13 commits into
mainfrom
claude/codex-0157-switch-quota-20260926
Sep 26, 2026
Merged

seathatflowsinourveins merged 13 commits into
mainfrom
claude/codex-0157-switch-quota-20260926

Conversation

@seathatflowsinourveins

Copy link
Copy Markdown
Owner

lane:shared: it changes manifests/stack.json and the Linux pins. Hold: merge only after 9a's release WINDOW DONE and the trading lane's acknowledgement. Auto-merge is off.

This PR records the workstation switch of Codex CLI from 0.155.1 to 0.157.1, and adds a native Codex quota probe for the shared-budget practice the user chose on 2026-09-26: spend the GPT-6 quota in priority order now, and tell the user when the limit is reached.

The switch (qualified and staged in #332; run on this host 2026-09-26 at about 14:35Z)

The receipt's data.switch was run in order:

  1. Preflight: no Codex process running.
  2. codex features disable daemon_auto_start with the staged binary, read back as false.
  3. Relink bin/codex; codex --version reports codex-cli 0.157.1.
  4. A gpt-6-astra max exec probe returned PROBE-OK with one turn.completed.
  5. No app-server daemon process, and no daemon package.

The coordinator and f5 held their Codex runs for the window.

  • Host receipt nativestack-5975wx-20260925--codex--install--20260926: recorded from a clean checkout at published main, with read-only commands only (version, feature flag, daemon checks). It is recorded unbound: the landscape winner pins stay at 0.155.1 until a verdict wave.
  • Pins and stack:
    • the Linux pin moves to 0.157.1, with the wrapper tarball sha256 and the npm integrity from the qualification receipt;
    • the macOS pin stays at 0.155.1, listed in MAC_PIN_LAGS_LINUX;
    • stack.json, upstream-snapshot.json and the lifecycle-audit row are updated to match.
  • New hosts: adoption/templates/codex.config.template.toml now sets daemon_auto_start = false, so a new host that installs 0.157.1 never starts the self-updating daemon on its first interactive launch.

Native quota probe and gate

  • scripts/codex_quota.py reads the account's snapshot through Codex's own app-server protocol (account/rateLimits/read), checked against codex-rs/app-server-protocol at rust-v0.155.1 and rust-v0.157.1.
    • It reads no session transcript and no credential file, and never prints the account id.
    • A single deadline bounds the whole exchange, and cleanup ends the server's process group.
    • The server runs with a read-only sandbox, so no writable roots are prepared.
    • --gate PERCENT exits 3 at the threshold, or when rateLimitReachedType is set or ordinary usage is not allowed. --json prints one object.
  • Optional gate in the shared GPT-6 runner (codex_job.py, staged.json codex.quota_stop_percent, off by default): at the threshold a job refuses before Codex starts, like the usage-limit marker, and writes <work-dir>/LIMIT with the reason so the coordinator can tell the user. A failed probe is recorded and never blocks a job.
  • docs/token-practice.md gets a dated "Shared Codex quota" section, with only the measured figures, each labelled with its source.

Review record

  • Claude Opus: 1 medium (quoted figures without a retained source), fixed in the repair round, plus 3 low.
  • GPT-6 cross-family review: not run. The reviewer measured the shared account at the top of its weekly window and deliberately did not spend the last of the quota. It is owed once the new Codex login is active; please treat this PR as single-family reviewed until then.
  • The codex host receipt carries a self review only; an independent review is still to come.

Tests: tests.test_codex_quota and tests.test_landscape_sweep_harness ran 92, OK (2 skipped). The workflow's CI-style run over 37 modules passed with registration simulated. validate.py and host_receipts.py validate pass after registration.

SOTA sources

🤖 Generated with Claude Code

@seathatflowsinourveins seathatflowsinourveins added the lane:shared Touches files owned by both lanes; needs both lanes' acknowledgement label Sep 26, 2026
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Trading-lane ack (lane:shared), 2026-09-26.

  • In manifests/stack.json, only the codex component changes: 0.155.1 becomes 0.157.1, with the codex-01571-qualification-20260926 evidence id and the rust-v0.157.1 release source.
  • No catalogs/us-equities or blueprints/us-equities path is touched.
  • This session's GPT-6 runs already use 0.157.1 through codex exec --json with the same argv. That is consistent with your qualification note that only an optional web_search results field changed.

Merge after 9a's WINDOW DONE, on green CI.

🤖 Generated with Claude Code

@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

GPT-6 cross-family review (owed) and repair

GPT-6-Astra (max, read-only) reviewed c0a949f on the new Codex account and returned NOT_READY, with 4 P2 findings and 1 P3. All five were real and are fixed in 1cf35d2:

Finding Fix Regression test (fails on c0a949f)
P2: the probe echoed server error text, which can carry account ids stage and code with a fixed message; no server text test_error_answers (synthetic acct_SENSITIVE*) and the harness's test_a_failed_probe_...
P2: a probe timeout recorded the full command (absolute paths) fixed message without the command line covered by construction; the fixed strings hold no path
P2: setup failure after Popen (EMFILE) left the server and its pipes stop, reap and close on setup failure test_a_setup_failure_after_the_server_starts_leaves_nothing_running
P3: {:g} turned a threshold of 95.00001 into 95 round-trip repr(float(...)) test_the_stop_percent_keeps_its_precision
P2: the docs quoted quota figures with no retained source figures removed; cite only a retained, sanitized --json read none (docs)

Suites: tests.test_codex_quota and tests.test_landscape_sweep_harness ran 94, OK (2 skipped). validate.py passes. The codex host receipt has an independent headless review (agree).

Still held: merge after 9a's release WINDOW DONE (the trading lane acked). Following the bounded-review rule, this repair round has not been re-reviewed.

🤖 Generated with Claude Code

Scout and others added 13 commits September 26, 2026 12:22
scripts/codex_quota.py reads the account's usage snapshot through
`codex app-server` (stdio JSON-RPC, account/rateLimits/read). Checked
against openai/codex codex-rs/app-server-protocol at rust-v0.155.1 and
rust-v0.157.1 (common.rs, v1.rs, v2/account.rs, rpc.rs identical for
these shapes): messages carry no "jsonrpc" field; initialize sends
clientInfo {name, title, version}; the initialized notification follows
the initialize answer; the read uses excludeResetCreditDetails (the
background-poll form); error answers are {id, error {code, message,
data?}}; the top-level rateLimits is the account's "codex" snapshot
(app-server account_processor.rs).

Hardening over the first draft:
- One deadline bounds the whole exchange (selectors on the pipe); the
  draft's blocking readline never timed out on a silent server.
- Cleanup: EOF, then TERM and KILL to the server's own process group,
  so children that ignore TERM are gone too.
- The server runs in an empty temporary directory without RUST_LOG, and
  a server request is answered with method-not-found.
- --gate PERCENT exits 3 when a window's used_percent reaches PERCENT,
  rateLimitReachedType is set or ordinaryUsageAllowed is false; 2 when
  no snapshot arrives or nothing can be judged. --json prints exactly
  one object; accountId and the upsell banner are never printed.

tests/test_codex_quota.py (12 tests, no network, no account): snapshot
parsing and the exact protocol sequence, interleaved notifications and
a server request, the gate outcomes, an error answer, a server that
never answers and ignores TERM with a TERM-ignoring child (timeout and
group cleanup), a server silent on the read, an early exit, codex
missing from PATH.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
staged.json codex.quota_stop_percent (written by build_args.py
--quota-stop-percent; absent, the gate is off) makes the runner, after a
job gets its slot and before codex starts, run codex_quota.py --json
--gate <percent>. Exit 3 is refused like a usage limit: the job ends
with exit 3 before codex starts, <work-dir>/LIMIT (created only when
absent, so an earlier reason or a real limit is kept) and the job's
stderr.txt name the reason, the used percent and the reset time, and
later starts print the marker's reason. Every probe is kept in
<job>/quota.json (an attempt file, so it moves to attempts/<n>/ with
the rest) and `result` summarizes it as `quota`. A failed probe (no
snapshot within codex.quota_timeout_s, default 30 s, an error answer, a
missing script) is recorded and never blocks the job.

build_args.py stages scripts/codex_quota.py beside the runner as
codex_quota.py and records its sha256 under harness.quota_probe; a
staged runner uses only that frozen copy, the checkout runner uses
scripts/codex_quota.py. The fake codex in the harness tests now answers
the app-server quota read; new tests cover the gate off by default, a
probe below the stop percent, the refusal and the rerun after a reset,
a limit flag below the percent, an existing marker's reason kept, a
failed and a missing probe that do not block, bad stop percents and the
staged gate. README: files table, a Quota gate coordination entry and
the tests note.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…t, template, recipes, quota practice

evidence/hosts/nativestack-5975wx-20260925/...--codex--install--20260926.json:
recorded with scripts/host_receipts.py record from a clean detached
worktree at origin/main ca8e37f (published; the catalog_revision),
stage install, component codex, version 0.157.1 with
--allow-unbound-version because the landscape winner pins stay 0.155.1
until a verdict wave (the qualification receipt's own limitation).
Four bounded read-only commands, all exit 0: codex --version
(codex-cli 0.157.1), codex features list filtered to daemon_auto_start
(stable false), the data.switch daemon process count (0) and package
check (absent). It supersedes nothing (no same-day codex install
receipt). The quota read is not in it: scripts/codex_quota.py is not on
origin/main at that revision. Its manifests/evidence.json files[] entry
is left to the coordinator (sha256 b3b8495e..., 5,260 bytes).

Pins and manifests, following the qualification receipt's after-switch
follow-ups and the #307/#332 pattern:
- adoption/pins-linux-x86_64.json: codex 0.157.1, the wrapper tarball
  URL and sha256 813e2a94..., dist.integrity, the platform package's
  sha256 and integrity and the daemon note in install_note.
- manifests/stack.json: codex 0.157.1, evidence id
  codex-01571-qualification-20260926 (stack evidence ids must be
  receipts[] entries; host receipts are files[] only), the release URL
  and a dated freshness note.
- blueprints/token-native-focus/saturation-audit.json: the codex row's
  version and public receipt.
- adoption/templates/codex.config.template.toml: daemon_auto_start =
  false under [features], so a new host bootstrapped at the 0.157.1 pin
  does not start the self-updating daemon on its first interactive
  launch (0.155.1 accepts the key; results/daemon.json).
- recipes/README.md: the rust-v0.157.1 codex-package digest
  (sha256:0e211868..., equal to the GitHub API digest) and the codex row.
The macOS pin stays 0.155.1 (its own qualification; no test needs it
moved).

docs/token-practice.md: the native quota probe with the measured
numbers and the shared-budget practice (one host slot pool, the verdict
wave first, tell the user at the limit).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… switch

python3 scripts/component_matrix.py --write, then
python3 scripts/new_host_grand_list.py --write: the new codex install
receipt raises the native-clients and agent-sdks codex pass count from
7 to 8 (latest 2026-09-26T14:34:12Z; platform_status unchanged,
host_verified), and the Linux bootstrap column reads 0.157.1 while the
winner pin and the macOS bootstrap stay 0.155.1. The generators'
manifests/evidence.json hash updates are left to the coordinator's
registration.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…n lag

catalogs/landscape/upstream-snapshot.json: the codex row's
selected_version follows manifests/stack.json to 0.157.1 (scripts/
landscape.py requires them equal) and its release_relationship becomes
selected_version_matches_latest_stable: the snapshot's own 05:12Z
checks already name rust-v0.157.1 (commit 36650394) as the latest
stable release and checked its commit. codex leaves the summary's
newer-stable review queue, and the recommendation counts four.

tests/test_adoption_bootstrap_macos.py: MAC_PIN_LAGS_LINUX records
codex 0.155.1 (Mac) against 0.157.1 (Linux) with the qualification
receipt, the mechanism #307 used for ai-memory and mcporter. The macOS
pin itself stays 0.155.1 until a Mac qualifies 0.157.x.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Review finding: the section cited used_percent 61 to 63, the weekly window,
reset time and plan, plus a 14:28Z single-bucket 0.77 s read, but no committed
receipt or artifact retains that output, and the linked host receipt states the
quota read is not part of it. Keep the coordinator-reported figures, label them
unretained observations until a sanitized --json read is recorded from a
published checkout that contains the script, drop the unretained 14:28Z read,
and say the host receipt does not cover the quota read.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The probe only reads account state, so the server should prepare no writable roots (a
workspace-write sandbox protects .git mount points inside roots such as /tmp). Live
check on codex 0.157.1: the read-only probe returned the snapshot and created nothing
under /tmp. Both fakes now require the -c sandbox_mode="read-only" override.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A separate headless Claude session reviewed the 0.157.1 install receipt against the
#332 qualification's data.switch and the live host (codex 0.157.1, daemon_auto_start
false, no daemon process or package, 0.155.1 kept for rollback) and recorded
independent_session agree.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…949f)

- codex_quota.py never echoes server error text (backend errors can carry account ids);
  it reports stage and code with a fixed message.
- codex_quota.py stops and reaps the app-server and closes its pipes when setup fails
  after Popen (an injected EMFILE left them behind).
- codex_job.py records a fixed probe-failure message, never the command line (absolute
  interpreter and work-directory paths), and passes the stop percent and timeout with
  round-trip precision (95.00001 no longer becomes 95).
- docs/token-practice.md quotes no quota figure without a retained, sanitized read.
Each finding has a test that fails on c0a949f's code; both suites: 94 tests OK.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
….26.2

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…pages

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@seathatflowsinourveins
seathatflowsinourveins enabled auto-merge (squash) September 26, 2026 16:26
@seathatflowsinourveins
seathatflowsinourveins force-pushed the claude/codex-0157-switch-quota-20260926 branch from 979f69f to 34dc62e Compare September 26, 2026 16:26
@seathatflowsinourveins
seathatflowsinourveins merged commit c2ffaef into main Sep 26, 2026
25 checks passed
@seathatflowsinourveins
seathatflowsinourveins deleted the claude/codex-0157-switch-quota-20260926 branch September 26, 2026 16:44
seathatflowsinourveins pushed a commit that referenced this pull request Sep 30, 2026
…in version

evidence/receipts/codex-01592-qualification-20260930.json (native_cli_e2e,
mirroring codex-01571-qualification-20260926): npm and GitHub artifact integrity
with failing controls, byte identity of the existing tools/codex-0.159.2 prefix
(49/49), credential-free bwrap checks of 0.159.2 against 0.157.1 (version, help,
mcp list/get shapes, features, prompt-input marker, offline bundled catalog),
source identity of the exec --json layer at the two tag commits,
prove_codex_lane.py --help and static checks, apply_codex_lane.py dry run, and a
read-only rollout/item-shape check with the repository's own parsers over the
host's 19 rollouts written by 0.159.2. No live model call; the host launcher
already resolved to 0.159.2 and this unit changed nothing on the host.

Records that mirror the manifest version, as the 0.157.1 switch (#348) moved
them: catalogs/landscape/upstream-snapshot.json codex entry (selected 0.159.2;
repo and releases/latest re-checked 2026-09-30, the rust-v0.159.2 commit through
git protocol after REST 403s), blueprints/token-native-focus/saturation-audit.json
codex row (version and the new receipt), tests/test_adoption_bootstrap_macos.py
MAC_PIN_LAGS_LINUX (Mac 0.155.1, Linux 0.159.2). The manifests/stack.json codex
row and the evidence registration follow in the branch's last commit
(docs/lanes.md hot-file protocol).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
seathatflowsinourveins pushed a commit that referenced this pull request Sep 30, 2026
…in version

evidence/receipts/codex-01592-qualification-20260930.json (native_cli_e2e,
mirroring codex-01571-qualification-20260926): npm and GitHub artifact integrity
with failing controls, byte identity of the existing tools/codex-0.159.2 prefix
(49/49), credential-free bwrap checks of 0.159.2 against 0.157.1 (version, help,
mcp list/get shapes, features, prompt-input marker, offline bundled catalog),
source identity of the exec --json layer at the two tag commits,
prove_codex_lane.py --help and static checks, apply_codex_lane.py dry run, and a
read-only rollout/item-shape check with the repository's own parsers over the
host's 19 rollouts written by 0.159.2. No live model call; the host launcher
already resolved to 0.159.2 and this unit changed nothing on the host.

Records that mirror the manifest version, as the 0.157.1 switch (#348) moved
them: catalogs/landscape/upstream-snapshot.json codex entry (selected 0.159.2;
repo and releases/latest re-checked 2026-09-30, the rust-v0.159.2 commit through
git protocol after REST 403s), blueprints/token-native-focus/saturation-audit.json
codex row (version and the new receipt), tests/test_adoption_bootstrap_macos.py
MAC_PIN_LAGS_LINUX (Mac 0.155.1, Linux 0.159.2). The manifests/stack.json codex
row and the evidence registration follow in the branch's last commit
(docs/lanes.md hot-file protocol).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
seathatflowsinourveins pushed a commit that referenced this pull request Sep 30, 2026
…in version

evidence/receipts/codex-01592-qualification-20260930.json (native_cli_e2e,
mirroring codex-01571-qualification-20260926): npm and GitHub artifact integrity
with failing controls, byte identity of the existing tools/codex-0.159.2 prefix
(49/49), credential-free bwrap checks of 0.159.2 against 0.157.1 (version, help,
mcp list/get shapes, features, prompt-input marker, offline bundled catalog),
source identity of the exec --json layer at the two tag commits,
prove_codex_lane.py --help and static checks, apply_codex_lane.py dry run, and a
read-only rollout/item-shape check with the repository's own parsers over the
host's 19 rollouts written by 0.159.2. No live model call; the host launcher
already resolved to 0.159.2 and this unit changed nothing on the host.

Records that mirror the manifest version, as the 0.157.1 switch (#348) moved
them: catalogs/landscape/upstream-snapshot.json codex entry (selected 0.159.2;
repo and releases/latest re-checked 2026-09-30, the rust-v0.159.2 commit through
git protocol after REST 403s), blueprints/token-native-focus/saturation-audit.json
codex row (version and the new receipt), tests/test_adoption_bootstrap_macos.py
MAC_PIN_LAGS_LINUX (Mac 0.155.1, Linux 0.159.2). The manifests/stack.json codex
row and the evidence registration follow in the branch's last commit
(docs/lanes.md hot-file protocol).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
seathatflowsinourveins added a commit that referenced this pull request Sep 30, 2026
…ult GPT-6.1 Sol/Ultra with Astra escalation (unit D4) (#542)

* Pin Codex CLI 0.159.2 in the Linux pins; guard pin/manifest version agreement

adoption/pins-linux-x86_64.json codex entry: 0.157.1 -> 0.159.2 (npm wrapper
cf1e5d7b..., 4,904 bytes; platform package 84a6b35f..., 162,475,310 bytes), both
matched npm dist.integrity, npm audit signatures verified signatures and
attestations, SLSA provenance names rust-release.yml at refs/tags/rust-v0.159.2
(ff6aec96). The note now records that from 0.159.x the npm platform package's
vendor tree is the complete native package (44 files byte-identical to the
GitHub codex-package asset listed in codex-package_SHA256SUMS).

tests/test_adoption_status.py: PinManifestAgreementTests checks that every Linux
pin names manifests/stack.json's version of the same component (a " @ <commit>"
suffix is ignored), with a mutation self-check. It fails at this commit
(codex: pin 0.159.2, manifests/stack.json 0.157.1) and passes once the manifest
row moves in the last commit of this branch.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Codex template default: GPT-6.1 Sol at ultra (user decision 2026-09-30); model-currency addendum

adoption/templates/codex.config.template.toml: model gpt-6-astra -> gpt-6.1-sol,
model_reasoning_effort stays ultra, with a comment naming the addendum; the
client-pin comment now cites the 0.159.2 qualification receipt. The judgment
lanes keep their gpt-6-astra bindings (stack-worker profile, landscape-sweep
lane, cx/gpt-6-astra OmniRoute profile), and tests/test_codex_worker_lane.py's
K2 assertion now reads the template's (model, effort) pair.

docs/decisions/2026-09-27-model-currency.md: dated addendum 2026-09-30 with the
GPT-6.1 Sol release (Codex changelog and models page, read 2026-09-30; the
announcement page answered 403), the client gate (rust-v0.159.1 bundled
catalog; offline codex debug models), the OmniRoute xhigh clamp for unregistered
ids read from the installed build's reasoningSuffix.ts and codex.ts, the user's
decision (6.1 Sol ultra default, Astra ultra for complex workflows), and the
preregistered #359-style comparison (A0, S1, S61-0, S61-1; the -0.02 micro-F1
bound) that overturns the lane tiers.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Fold the Codex coordinator lane's Sol-primary routing defaults (2026-09-30)

Folded from the Codex coordinator lane's 2026-09-30 work in the main checkout
(snapshot tracked.diff sha256 5de56d6d81453ed3), D4's assigned files only:

- adoption/templates/codex.config.template.toml: both hunks, reconciled with
  this branch's header into one: Sol/Ultra coordinator with its rust-v0.159.2
  citations and the routing record; [agents] default_subagent_model
  gpt-6.1-sol with default_subagent_reasoning_effort max (child_config.rs
  L62-73, L204-249).
- adoption/templates/codex.stack-worker.config.toml: worker profile Sol/Max,
  Astra substitution for judgment or escalation (applied unchanged).
- tests/test_render_config.py (all hunks), tools/adoption/prove_codex_lane.py
  (live-worker line), recipes/README.md (worker command and effort paragraph):
  applied unchanged with git apply --include.
- tests/test_codex_worker_lane.py: only the profile-model, worker_pins,
  worker_command and recipe assertions; the TOP_RULE_SHA256 and word-count
  hunks are F1's; the template-model hunk is already covered by this branch's
  (model, effort) assertion.
- docs/harness-defaults.md: only the "Sol-primary quality defaults" paragraph.
- docs/decisions/2026-09-30-sol-primary-quality-defaults.md: verbatim, plus a
  dated attribution line linking the model-currency addendum.
- docs/decisions/2026-09-27-model-currency.md: the addendum now names that
  record as the routing contract and follows its routes (workers and generic
  children Sol/Max; Astra kept by the lanes that name it).

The Gate A runbook and preregistration arms, which pass -m gpt-6-astra
explicitly, are untouched. Hash registrations follow in the last commit.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Codex 0.159.2 qualification receipt and the records that mirror the pin version

evidence/receipts/codex-01592-qualification-20260930.json (native_cli_e2e,
mirroring codex-01571-qualification-20260926): npm and GitHub artifact integrity
with failing controls, byte identity of the existing tools/codex-0.159.2 prefix
(49/49), credential-free bwrap checks of 0.159.2 against 0.157.1 (version, help,
mcp list/get shapes, features, prompt-input marker, offline bundled catalog),
source identity of the exec --json layer at the two tag commits,
prove_codex_lane.py --help and static checks, apply_codex_lane.py dry run, and a
read-only rollout/item-shape check with the repository's own parsers over the
host's 19 rollouts written by 0.159.2. No live model call; the host launcher
already resolved to 0.159.2 and this unit changed nothing on the host.

Records that mirror the manifest version, as the 0.157.1 switch (#348) moved
them: catalogs/landscape/upstream-snapshot.json codex entry (selected 0.159.2;
repo and releases/latest re-checked 2026-09-30, the rust-v0.159.2 commit through
git protocol after REST 403s), blueprints/token-native-focus/saturation-audit.json
codex row (version and the new receipt), tests/test_adoption_bootstrap_macos.py
MAC_PIN_LAGS_LINUX (Mac 0.155.1, Linux 0.159.2). The manifests/stack.json codex
row and the evidence registration follow in the branch's last commit
(docs/lanes.md hot-file protocol).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Codex worker lane: CODEX_VERSION 0.159.2 with the Linux pin; guard the two agree

tools/adoption/apply_codex_lane.py: CODEX_VERSION 0.157.1 -> 0.159.2, so the lane
applies on a host at the Linux pin (the dry run refused 0.159.2 with "[fail] codex
version: codex-cli 0.159.2 (pin 0.157.1)"). The exact-equality check is unchanged.
Its source citations were compared at the two tag commits (36650394, ff6aec96)
through raw.githubusercontent.com: config_manager_service.rs, agent-roles
loader.rs and discovery.rs are byte-identical; rmcp_client.rs keeps the 30 s
DEFAULT_STARTUP_TIMEOUT and its unwrap_or at L105 and L344 (L103 and L342 before).

tests/test_codex_worker_lane.py: the fake codex answers --version and doctor
--json as 0.159.2; the module, fake and ApplyFlowTests docstrings and the
integration skip message name 0.159.2; the DOCTOR shape note records that
doctor.rs differs at rust-v0.159.2 only in a handshake-error match arm. New
TemplateTests.test_the_lane_pins_the_linux_codex_pin checks CODEX_VERSION against
adoption/pins-linux-x86_64.json; it failed first ('0.157.1' != '0.159.2').

Opt-in CodexIntegrationTests against the 0.159.2 prefix's native binary
(sha256 1748767b...): 10/10 OK; with 0.157.1 on PATH all 10 skip.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Current-pin prose at Codex 0.159.2; macOS follow-up for the 6.1 Sol template default

recipes/README.md: the codex archive-hash row names rust-v0.159.2's
codex-package asset (9e2d29a7..., equal to its API digest and its
codex-package_SHA256SUMS line); the codex component row names 0.159.2 with its
release link and npm prefix, scopes the --search and daemon_auto_start
measurements to the versions that ran them, and points to the 0.159.2 receipt;
the stack-worker bullet describes the folded profile (gpt-6.1-sol at max, Astra by
-m on escalation); the rmcp_client.rs, mcp add --help, exec_events.rs and two
strict-config statements now also cite 0.159.2 where it was checked (source
compared at ff6aec96; the strict cases re-run through CodexIntegrationTests); the
PreToolUse/MCP sentence is scoped as not re-checked at 0.159.2.

adoption/bootstrap.md, adoption/platforms/linux-wsl2.md and macos-arm64.md: the
Linux codex pin history reads 0.155.1 -> 0.157.1 -> 0.159.2; the WSL2 terminal
measurement keeps its Codex 0.157.1 condition, now marked as before the move;
the macOS pin stays 0.155.1, and both pages name the follow-up: macOS needs its
own 0.159.x qualification before the template default applies there.

docs/decisions/2026-09-27-model-currency.md (addendum 2026-09-30): the worker_pins
line citation follows the file (298-304); the CODEX_VERSION move is recorded as
done here; a new follow-up paragraph records the macOS gap (bundled catalogs of
the Linux 0.155.1 and 0.157.1 builds lack gpt-6.1-sol, offline) and where a
per-platform model override would go (render_config.py render_one,
resolve_socraticode_version, pinned_version), not implemented.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Codex 0.159.2 receipt: the lane's constant move, its integration run and the macOS gap

evidence/receipts/codex-01592-qualification-20260930.json, amended in data and
text (id, kind and components unchanged):
- claim: the apply dry run failed its version precondition while CODEX_VERSION
  was 0.157.1 and passes after the move ('[ok] codex version: codex-cli 0.159.2
  (pin 0.159.2)', the 0.157.1 control now [fail]); the opt-in
  CodexIntegrationTests passed 10 of 10 on the prefix's native binary and skip on
  0.157.1; the static prove checks re-run byte-identical with this branch's file;
  the 0.155.1 build's bundled catalog also lacks gpt-6.1-sol.
- limitations: the constant move is no longer outside this unit; the npm-launcher
  and /tmp-bwrap runs of the integration tests and why they fail are recorded;
  the list of what moves now includes the lane and the current-pin prose; a new
  item names the macOS follow-up (its own 0.159.x qualification before the
  template default applies there) and the render_config.py override site.
- data: lane_checks gains prove_static_rerun, apply_dry_run_after_constant_move
  and integration_tests (the original dry-run line now names the base file);
  source_checks.lane_citations records the compared sources;
  checks_after_the_constant_move holds mcp add --help, the offline bundled
  catalogs of 0.155.1, 0.157.1 and 0.159.2, and the strict-config stderr.
- provenance: the base-sha entries of prove_codex_lane.py and apply_codex_lane.py
  now say so, and this branch's two files, the test module and the two new
  scratch scripts are listed with their sha256.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Model-currency addendum: 20128's 6.1 Sol effort after #534's restart

main moved during this rebase: #534 restarted OmniRoute 20128 at
2026-09-30T06:32:50Z onto build cf6748d04, carrying the open upstream PR #15167
that adds gpt-6.1-sol to reasoningSuffix.ts's alias sets. The addendum's gateway
item read the earlier build (before 04:52Z) and stated the xhigh clamp in the
present tense. It now keeps that source reading in the past tense and adds what
#534's record shows (1,154 of 1,495 gpt-6.1-sol rows sent at xhigh before the
restart; cx/gpt-6.1-sol with body max sent at max after it; 20129 unchanged);
the Decision sentence and the preregistered comparison's reason for native
Codex follow. Nothing on either port was observed again here. The routing
record's attribution line says gateway-effort evidence.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Codex 0.159.2 receipt: withhold the quoted host client configuration

data.host_resolution.config_toml_top_level_model quoted the two top-level model
keys of the host's active ~/.codex/config.toml. AGENTS.md keeps machine-specific
active client configuration out of evidence, so the value is withheld; the entry
still records that the file was read once, read-only, at 2026-09-30T05:37:50Z.
Claim and limitations are unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Codex 0.159.2 receipt: scope the dry-run refusal to what each run printed

The claim said each dry run after the constant move refused only on the three
preconditions an empty scratch home cannot meet; the 0.157.1 control printed a
fourth [fail] line, its codex version. The claim now scopes "only the three" to
the 0.159.2 run and says the control adds its version line.
data.amended_at_utc is the time of this last amendment.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Codex user template: CODEX_MODEL from the platform's Codex pin (review of #542)

The template set model and default_subagent_model to "gpt-6.1-sol" on every platform, while
adoption/pins-macos-arm64.json pins Codex 0.155.1, whose bundled catalog has no GPT-6.1 entry. Both keys now read
${CODEX_MODEL}, which tools/adoption/render_config.py fills from the selected platform's Codex pin as it fills
SOCRATICODE_VERSION: gpt-6.1-sol from Codex 0.159.1, gpt-6-astra before it. --set CODEX_MODEL=<model> names
another; --out and --check print a derived value with its pin and sources.

The threshold is 0.159.1, not 0.159.0: openai/codex codex-rs/models-manager/models.json has no "gpt-6.1-sol" slug
at rust-v0.159.0 (687a119f) and one at rust-v0.159.1 (8e68a98e, line 178), whose release notes read "Added GPT-6.1
Sol as the default model in the bundled catalog". At rust-v0.155.1 (be2951ea) models.json lists gpt-6-astra with
efforts low to ultra, and config/src/config_toml.rs L694-696 reads both [agents] default_subagent keys.

The stack-worker profile keeps its literal gpt-6.1-sol: apply_codex_lane.py installs it verbatim, worker_pins()
passes its model as -m, and the lane refuses any codex but CODEX_VERSION (the Linux pin). test_profile_template
now asserts that the literal equals the rule for lane.CODEX_VERSION.

Tests: CodexModelTests (both platforms, the 0.159.0/0.159.1 boundary, a host override, a platform without pins
failing closed, the --out/--check note) failed first against the unchanged renderer and template (9 run: 6
failures, 12 errors). The K2 check in test_omniroute_profile_template reads a Linux render, and the strict-config
integration fixture fills CODEX_MODEL from the rule.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Docs and receipt: CODEX_MODEL keeps gpt-6-astra on Codex pins before 0.159.1

- docs/decisions/2026-09-27-model-currency.md, addendum 2026-09-30: the template lines now read the placeholder
  (lines 7-8 and 30-31), the table row cites the Linux render, the "Still open" list names the rule, and the macOS
  follow-up records the placeholder, its upstream source and the offline prompt-input check instead of "It is not
  implemented here".
- evidence/receipts/codex-01592-qualification-20260930.json: limitations[12] states the placeholder, and the new
  data.checks_after_the_constant_move.template_model_per_platform records the per-platform renders and a
  no-network `codex debug prompt-input` check: the 0.155.1 build over the macOS render includes Ultra's
  multi_agent_role and multi_agent_mode developer messages, drops both when only the two model values are set to
  gpt-6.1-sol, and 0.159.2 includes both over either render. Linux builds only; no model call.
- adoption/platforms/macos-arm64.md and adoption/bootstrap.md: one clause each on the macOS render and the new
  derived placeholder.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Provenance wording for the folded Sol-defaults record: no inferred author (Codex runtime lane's request)

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* Sol-defaults record: Astra/Ultra coordinates a complex workflow, Astra/Max takes a single consequential judgment

The user's 2026-09-30 selection named "astra ultra when tasks needed suitable for complex workflow"; the catalog
semantics in this record (Ultra = proactive delegation with xhigh reasoning, Max = the highest reasoning effort)
split the escalation accordingly. Docs only.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* Re-register the changed hash-listed files in manifests/evidence.json (hot-file protocol)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Scout <scout@local>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lane:shared Touches files owned by both lanes; needs both lanes' acknowledgement

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant