Repository navigation
Codex 0.157.1 switched on the workstation (daemon-safe) + native quota probe and runner gate - #348
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Trading-lane ack (lane:shared), 2026-09-26.
Merge after 9a's WINDOW DONE, on green CI. 🤖 Generated with Claude Code |
GPT-6 cross-family review (owed) and repairGPT-6-Astra (max, read-only) reviewed c0a949f on the new Codex account and returned NOT_READY, with 4 P2 findings and 1 P3. All five were real and are fixed in 1cf35d2:
Suites: Still held: merge after 9a's release WINDOW DONE (the trading lane acked). Following the bounded-review rule, this repair round has not been re-reviewed. 🤖 Generated with Claude Code |
scripts/codex_quota.py reads the account's usage snapshot through
`codex app-server` (stdio JSON-RPC, account/rateLimits/read). Checked
against openai/codex codex-rs/app-server-protocol at rust-v0.155.1 and
rust-v0.157.1 (common.rs, v1.rs, v2/account.rs, rpc.rs identical for
these shapes): messages carry no "jsonrpc" field; initialize sends
clientInfo {name, title, version}; the initialized notification follows
the initialize answer; the read uses excludeResetCreditDetails (the
background-poll form); error answers are {id, error {code, message,
data?}}; the top-level rateLimits is the account's "codex" snapshot
(app-server account_processor.rs).
Hardening over the first draft:
- One deadline bounds the whole exchange (selectors on the pipe); the
draft's blocking readline never timed out on a silent server.
- Cleanup: EOF, then TERM and KILL to the server's own process group,
so children that ignore TERM are gone too.
- The server runs in an empty temporary directory without RUST_LOG, and
a server request is answered with method-not-found.
- --gate PERCENT exits 3 when a window's used_percent reaches PERCENT,
rateLimitReachedType is set or ordinaryUsageAllowed is false; 2 when
no snapshot arrives or nothing can be judged. --json prints exactly
one object; accountId and the upsell banner are never printed.
tests/test_codex_quota.py (12 tests, no network, no account): snapshot
parsing and the exact protocol sequence, interleaved notifications and
a server request, the gate outcomes, an error answer, a server that
never answers and ignores TERM with a TERM-ignoring child (timeout and
group cleanup), a server silent on the read, an early exit, codex
missing from PATH.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
staged.json codex.quota_stop_percent (written by build_args.py --quota-stop-percent; absent, the gate is off) makes the runner, after a job gets its slot and before codex starts, run codex_quota.py --json --gate <percent>. Exit 3 is refused like a usage limit: the job ends with exit 3 before codex starts, <work-dir>/LIMIT (created only when absent, so an earlier reason or a real limit is kept) and the job's stderr.txt name the reason, the used percent and the reset time, and later starts print the marker's reason. Every probe is kept in <job>/quota.json (an attempt file, so it moves to attempts/<n>/ with the rest) and `result` summarizes it as `quota`. A failed probe (no snapshot within codex.quota_timeout_s, default 30 s, an error answer, a missing script) is recorded and never blocks the job. build_args.py stages scripts/codex_quota.py beside the runner as codex_quota.py and records its sha256 under harness.quota_probe; a staged runner uses only that frozen copy, the checkout runner uses scripts/codex_quota.py. The fake codex in the harness tests now answers the app-server quota read; new tests cover the gate off by default, a probe below the stop percent, the refusal and the rerun after a reset, a limit flag below the percent, an existing marker's reason kept, a failed and a missing probe that do not block, bad stop percents and the staged gate. README: files table, a Quota gate coordination entry and the tests note. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…t, template, recipes, quota practice evidence/hosts/nativestack-5975wx-20260925/...--codex--install--20260926.json: recorded with scripts/host_receipts.py record from a clean detached worktree at origin/main ca8e37f (published; the catalog_revision), stage install, component codex, version 0.157.1 with --allow-unbound-version because the landscape winner pins stay 0.155.1 until a verdict wave (the qualification receipt's own limitation). Four bounded read-only commands, all exit 0: codex --version (codex-cli 0.157.1), codex features list filtered to daemon_auto_start (stable false), the data.switch daemon process count (0) and package check (absent). It supersedes nothing (no same-day codex install receipt). The quota read is not in it: scripts/codex_quota.py is not on origin/main at that revision. Its manifests/evidence.json files[] entry is left to the coordinator (sha256 b3b8495e..., 5,260 bytes). Pins and manifests, following the qualification receipt's after-switch follow-ups and the #307/#332 pattern: - adoption/pins-linux-x86_64.json: codex 0.157.1, the wrapper tarball URL and sha256 813e2a94..., dist.integrity, the platform package's sha256 and integrity and the daemon note in install_note. - manifests/stack.json: codex 0.157.1, evidence id codex-01571-qualification-20260926 (stack evidence ids must be receipts[] entries; host receipts are files[] only), the release URL and a dated freshness note. - blueprints/token-native-focus/saturation-audit.json: the codex row's version and public receipt. - adoption/templates/codex.config.template.toml: daemon_auto_start = false under [features], so a new host bootstrapped at the 0.157.1 pin does not start the self-updating daemon on its first interactive launch (0.155.1 accepts the key; results/daemon.json). - recipes/README.md: the rust-v0.157.1 codex-package digest (sha256:0e211868..., equal to the GitHub API digest) and the codex row. The macOS pin stays 0.155.1 (its own qualification; no test needs it moved). docs/token-practice.md: the native quota probe with the measured numbers and the shared-budget practice (one host slot pool, the verdict wave first, tell the user at the limit). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… switch python3 scripts/component_matrix.py --write, then python3 scripts/new_host_grand_list.py --write: the new codex install receipt raises the native-clients and agent-sdks codex pass count from 7 to 8 (latest 2026-09-26T14:34:12Z; platform_status unchanged, host_verified), and the Linux bootstrap column reads 0.157.1 while the winner pin and the macOS bootstrap stay 0.155.1. The generators' manifests/evidence.json hash updates are left to the coordinator's registration. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…n lag catalogs/landscape/upstream-snapshot.json: the codex row's selected_version follows manifests/stack.json to 0.157.1 (scripts/ landscape.py requires them equal) and its release_relationship becomes selected_version_matches_latest_stable: the snapshot's own 05:12Z checks already name rust-v0.157.1 (commit 36650394) as the latest stable release and checked its commit. codex leaves the summary's newer-stable review queue, and the recommendation counts four. tests/test_adoption_bootstrap_macos.py: MAC_PIN_LAGS_LINUX records codex 0.155.1 (Mac) against 0.157.1 (Linux) with the qualification receipt, the mechanism #307 used for ai-memory and mcporter. The macOS pin itself stays 0.155.1 until a Mac qualifies 0.157.x. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Review finding: the section cited used_percent 61 to 63, the weekly window, reset time and plan, plus a 14:28Z single-bucket 0.77 s read, but no committed receipt or artifact retains that output, and the linked host receipt states the quota read is not part of it. Keep the coordinator-reported figures, label them unretained observations until a sanitized --json read is recorded from a published checkout that contains the script, drop the unretained 14:28Z read, and say the host receipt does not cover the quota read. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The probe only reads account state, so the server should prepare no writable roots (a workspace-write sandbox protects .git mount points inside roots such as /tmp). Live check on codex 0.157.1: the read-only probe returned the snapshot and created nothing under /tmp. Both fakes now require the -c sandbox_mode="read-only" override. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A separate headless Claude session reviewed the 0.157.1 install receipt against the #332 qualification's data.switch and the live host (codex 0.157.1, daemon_auto_start false, no daemon process or package, 0.155.1 kept for rollback) and recorded independent_session agree. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…949f) - codex_quota.py never echoes server error text (backend errors can carry account ids); it reports stage and code with a fixed message. - codex_quota.py stops and reaps the app-server and closes its pipes when setup fails after Popen (an injected EMFILE left them behind). - codex_job.py records a fixed probe-failure message, never the command line (absolute interpreter and work-directory paths), and passes the stop percent and timeout with round-trip precision (95.00001 no longer becomes 95). - docs/token-practice.md quotes no quota figure without a retained, sanitized read. Each finding has a test that fails on c0a949f's code; both suites: 94 tests OK. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
….26.2 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…pages Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
979f69f to
34dc62e
Compare
…in version evidence/receipts/codex-01592-qualification-20260930.json (native_cli_e2e, mirroring codex-01571-qualification-20260926): npm and GitHub artifact integrity with failing controls, byte identity of the existing tools/codex-0.159.2 prefix (49/49), credential-free bwrap checks of 0.159.2 against 0.157.1 (version, help, mcp list/get shapes, features, prompt-input marker, offline bundled catalog), source identity of the exec --json layer at the two tag commits, prove_codex_lane.py --help and static checks, apply_codex_lane.py dry run, and a read-only rollout/item-shape check with the repository's own parsers over the host's 19 rollouts written by 0.159.2. No live model call; the host launcher already resolved to 0.159.2 and this unit changed nothing on the host. Records that mirror the manifest version, as the 0.157.1 switch (#348) moved them: catalogs/landscape/upstream-snapshot.json codex entry (selected 0.159.2; repo and releases/latest re-checked 2026-09-30, the rust-v0.159.2 commit through git protocol after REST 403s), blueprints/token-native-focus/saturation-audit.json codex row (version and the new receipt), tests/test_adoption_bootstrap_macos.py MAC_PIN_LAGS_LINUX (Mac 0.155.1, Linux 0.159.2). The manifests/stack.json codex row and the evidence registration follow in the branch's last commit (docs/lanes.md hot-file protocol). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…in version evidence/receipts/codex-01592-qualification-20260930.json (native_cli_e2e, mirroring codex-01571-qualification-20260926): npm and GitHub artifact integrity with failing controls, byte identity of the existing tools/codex-0.159.2 prefix (49/49), credential-free bwrap checks of 0.159.2 against 0.157.1 (version, help, mcp list/get shapes, features, prompt-input marker, offline bundled catalog), source identity of the exec --json layer at the two tag commits, prove_codex_lane.py --help and static checks, apply_codex_lane.py dry run, and a read-only rollout/item-shape check with the repository's own parsers over the host's 19 rollouts written by 0.159.2. No live model call; the host launcher already resolved to 0.159.2 and this unit changed nothing on the host. Records that mirror the manifest version, as the 0.157.1 switch (#348) moved them: catalogs/landscape/upstream-snapshot.json codex entry (selected 0.159.2; repo and releases/latest re-checked 2026-09-30, the rust-v0.159.2 commit through git protocol after REST 403s), blueprints/token-native-focus/saturation-audit.json codex row (version and the new receipt), tests/test_adoption_bootstrap_macos.py MAC_PIN_LAGS_LINUX (Mac 0.155.1, Linux 0.159.2). The manifests/stack.json codex row and the evidence registration follow in the branch's last commit (docs/lanes.md hot-file protocol). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…in version evidence/receipts/codex-01592-qualification-20260930.json (native_cli_e2e, mirroring codex-01571-qualification-20260926): npm and GitHub artifact integrity with failing controls, byte identity of the existing tools/codex-0.159.2 prefix (49/49), credential-free bwrap checks of 0.159.2 against 0.157.1 (version, help, mcp list/get shapes, features, prompt-input marker, offline bundled catalog), source identity of the exec --json layer at the two tag commits, prove_codex_lane.py --help and static checks, apply_codex_lane.py dry run, and a read-only rollout/item-shape check with the repository's own parsers over the host's 19 rollouts written by 0.159.2. No live model call; the host launcher already resolved to 0.159.2 and this unit changed nothing on the host. Records that mirror the manifest version, as the 0.157.1 switch (#348) moved them: catalogs/landscape/upstream-snapshot.json codex entry (selected 0.159.2; repo and releases/latest re-checked 2026-09-30, the rust-v0.159.2 commit through git protocol after REST 403s), blueprints/token-native-focus/saturation-audit.json codex row (version and the new receipt), tests/test_adoption_bootstrap_macos.py MAC_PIN_LAGS_LINUX (Mac 0.155.1, Linux 0.159.2). The manifests/stack.json codex row and the evidence registration follow in the branch's last commit (docs/lanes.md hot-file protocol). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ult GPT-6.1 Sol/Ultra with Astra escalation (unit D4) (#542) * Pin Codex CLI 0.159.2 in the Linux pins; guard pin/manifest version agreement adoption/pins-linux-x86_64.json codex entry: 0.157.1 -> 0.159.2 (npm wrapper cf1e5d7b..., 4,904 bytes; platform package 84a6b35f..., 162,475,310 bytes), both matched npm dist.integrity, npm audit signatures verified signatures and attestations, SLSA provenance names rust-release.yml at refs/tags/rust-v0.159.2 (ff6aec96). The note now records that from 0.159.x the npm platform package's vendor tree is the complete native package (44 files byte-identical to the GitHub codex-package asset listed in codex-package_SHA256SUMS). tests/test_adoption_status.py: PinManifestAgreementTests checks that every Linux pin names manifests/stack.json's version of the same component (a " @ <commit>" suffix is ignored), with a mutation self-check. It fails at this commit (codex: pin 0.159.2, manifests/stack.json 0.157.1) and passes once the manifest row moves in the last commit of this branch. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Codex template default: GPT-6.1 Sol at ultra (user decision 2026-09-30); model-currency addendum adoption/templates/codex.config.template.toml: model gpt-6-astra -> gpt-6.1-sol, model_reasoning_effort stays ultra, with a comment naming the addendum; the client-pin comment now cites the 0.159.2 qualification receipt. The judgment lanes keep their gpt-6-astra bindings (stack-worker profile, landscape-sweep lane, cx/gpt-6-astra OmniRoute profile), and tests/test_codex_worker_lane.py's K2 assertion now reads the template's (model, effort) pair. docs/decisions/2026-09-27-model-currency.md: dated addendum 2026-09-30 with the GPT-6.1 Sol release (Codex changelog and models page, read 2026-09-30; the announcement page answered 403), the client gate (rust-v0.159.1 bundled catalog; offline codex debug models), the OmniRoute xhigh clamp for unregistered ids read from the installed build's reasoningSuffix.ts and codex.ts, the user's decision (6.1 Sol ultra default, Astra ultra for complex workflows), and the preregistered #359-style comparison (A0, S1, S61-0, S61-1; the -0.02 micro-F1 bound) that overturns the lane tiers. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Fold the Codex coordinator lane's Sol-primary routing defaults (2026-09-30) Folded from the Codex coordinator lane's 2026-09-30 work in the main checkout (snapshot tracked.diff sha256 5de56d6d81453ed3), D4's assigned files only: - adoption/templates/codex.config.template.toml: both hunks, reconciled with this branch's header into one: Sol/Ultra coordinator with its rust-v0.159.2 citations and the routing record; [agents] default_subagent_model gpt-6.1-sol with default_subagent_reasoning_effort max (child_config.rs L62-73, L204-249). - adoption/templates/codex.stack-worker.config.toml: worker profile Sol/Max, Astra substitution for judgment or escalation (applied unchanged). - tests/test_render_config.py (all hunks), tools/adoption/prove_codex_lane.py (live-worker line), recipes/README.md (worker command and effort paragraph): applied unchanged with git apply --include. - tests/test_codex_worker_lane.py: only the profile-model, worker_pins, worker_command and recipe assertions; the TOP_RULE_SHA256 and word-count hunks are F1's; the template-model hunk is already covered by this branch's (model, effort) assertion. - docs/harness-defaults.md: only the "Sol-primary quality defaults" paragraph. - docs/decisions/2026-09-30-sol-primary-quality-defaults.md: verbatim, plus a dated attribution line linking the model-currency addendum. - docs/decisions/2026-09-27-model-currency.md: the addendum now names that record as the routing contract and follows its routes (workers and generic children Sol/Max; Astra kept by the lanes that name it). The Gate A runbook and preregistration arms, which pass -m gpt-6-astra explicitly, are untouched. Hash registrations follow in the last commit. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Codex 0.159.2 qualification receipt and the records that mirror the pin version evidence/receipts/codex-01592-qualification-20260930.json (native_cli_e2e, mirroring codex-01571-qualification-20260926): npm and GitHub artifact integrity with failing controls, byte identity of the existing tools/codex-0.159.2 prefix (49/49), credential-free bwrap checks of 0.159.2 against 0.157.1 (version, help, mcp list/get shapes, features, prompt-input marker, offline bundled catalog), source identity of the exec --json layer at the two tag commits, prove_codex_lane.py --help and static checks, apply_codex_lane.py dry run, and a read-only rollout/item-shape check with the repository's own parsers over the host's 19 rollouts written by 0.159.2. No live model call; the host launcher already resolved to 0.159.2 and this unit changed nothing on the host. Records that mirror the manifest version, as the 0.157.1 switch (#348) moved them: catalogs/landscape/upstream-snapshot.json codex entry (selected 0.159.2; repo and releases/latest re-checked 2026-09-30, the rust-v0.159.2 commit through git protocol after REST 403s), blueprints/token-native-focus/saturation-audit.json codex row (version and the new receipt), tests/test_adoption_bootstrap_macos.py MAC_PIN_LAGS_LINUX (Mac 0.155.1, Linux 0.159.2). The manifests/stack.json codex row and the evidence registration follow in the branch's last commit (docs/lanes.md hot-file protocol). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Codex worker lane: CODEX_VERSION 0.159.2 with the Linux pin; guard the two agree tools/adoption/apply_codex_lane.py: CODEX_VERSION 0.157.1 -> 0.159.2, so the lane applies on a host at the Linux pin (the dry run refused 0.159.2 with "[fail] codex version: codex-cli 0.159.2 (pin 0.157.1)"). The exact-equality check is unchanged. Its source citations were compared at the two tag commits (36650394, ff6aec96) through raw.githubusercontent.com: config_manager_service.rs, agent-roles loader.rs and discovery.rs are byte-identical; rmcp_client.rs keeps the 30 s DEFAULT_STARTUP_TIMEOUT and its unwrap_or at L105 and L344 (L103 and L342 before). tests/test_codex_worker_lane.py: the fake codex answers --version and doctor --json as 0.159.2; the module, fake and ApplyFlowTests docstrings and the integration skip message name 0.159.2; the DOCTOR shape note records that doctor.rs differs at rust-v0.159.2 only in a handshake-error match arm. New TemplateTests.test_the_lane_pins_the_linux_codex_pin checks CODEX_VERSION against adoption/pins-linux-x86_64.json; it failed first ('0.157.1' != '0.159.2'). Opt-in CodexIntegrationTests against the 0.159.2 prefix's native binary (sha256 1748767b...): 10/10 OK; with 0.157.1 on PATH all 10 skip. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Current-pin prose at Codex 0.159.2; macOS follow-up for the 6.1 Sol template default recipes/README.md: the codex archive-hash row names rust-v0.159.2's codex-package asset (9e2d29a7..., equal to its API digest and its codex-package_SHA256SUMS line); the codex component row names 0.159.2 with its release link and npm prefix, scopes the --search and daemon_auto_start measurements to the versions that ran them, and points to the 0.159.2 receipt; the stack-worker bullet describes the folded profile (gpt-6.1-sol at max, Astra by -m on escalation); the rmcp_client.rs, mcp add --help, exec_events.rs and two strict-config statements now also cite 0.159.2 where it was checked (source compared at ff6aec96; the strict cases re-run through CodexIntegrationTests); the PreToolUse/MCP sentence is scoped as not re-checked at 0.159.2. adoption/bootstrap.md, adoption/platforms/linux-wsl2.md and macos-arm64.md: the Linux codex pin history reads 0.155.1 -> 0.157.1 -> 0.159.2; the WSL2 terminal measurement keeps its Codex 0.157.1 condition, now marked as before the move; the macOS pin stays 0.155.1, and both pages name the follow-up: macOS needs its own 0.159.x qualification before the template default applies there. docs/decisions/2026-09-27-model-currency.md (addendum 2026-09-30): the worker_pins line citation follows the file (298-304); the CODEX_VERSION move is recorded as done here; a new follow-up paragraph records the macOS gap (bundled catalogs of the Linux 0.155.1 and 0.157.1 builds lack gpt-6.1-sol, offline) and where a per-platform model override would go (render_config.py render_one, resolve_socraticode_version, pinned_version), not implemented. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Codex 0.159.2 receipt: the lane's constant move, its integration run and the macOS gap evidence/receipts/codex-01592-qualification-20260930.json, amended in data and text (id, kind and components unchanged): - claim: the apply dry run failed its version precondition while CODEX_VERSION was 0.157.1 and passes after the move ('[ok] codex version: codex-cli 0.159.2 (pin 0.159.2)', the 0.157.1 control now [fail]); the opt-in CodexIntegrationTests passed 10 of 10 on the prefix's native binary and skip on 0.157.1; the static prove checks re-run byte-identical with this branch's file; the 0.155.1 build's bundled catalog also lacks gpt-6.1-sol. - limitations: the constant move is no longer outside this unit; the npm-launcher and /tmp-bwrap runs of the integration tests and why they fail are recorded; the list of what moves now includes the lane and the current-pin prose; a new item names the macOS follow-up (its own 0.159.x qualification before the template default applies there) and the render_config.py override site. - data: lane_checks gains prove_static_rerun, apply_dry_run_after_constant_move and integration_tests (the original dry-run line now names the base file); source_checks.lane_citations records the compared sources; checks_after_the_constant_move holds mcp add --help, the offline bundled catalogs of 0.155.1, 0.157.1 and 0.159.2, and the strict-config stderr. - provenance: the base-sha entries of prove_codex_lane.py and apply_codex_lane.py now say so, and this branch's two files, the test module and the two new scratch scripts are listed with their sha256. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Model-currency addendum: 20128's 6.1 Sol effort after #534's restart main moved during this rebase: #534 restarted OmniRoute 20128 at 2026-09-30T06:32:50Z onto build cf6748d04, carrying the open upstream PR #15167 that adds gpt-6.1-sol to reasoningSuffix.ts's alias sets. The addendum's gateway item read the earlier build (before 04:52Z) and stated the xhigh clamp in the present tense. It now keeps that source reading in the past tense and adds what #534's record shows (1,154 of 1,495 gpt-6.1-sol rows sent at xhigh before the restart; cx/gpt-6.1-sol with body max sent at max after it; 20129 unchanged); the Decision sentence and the preregistered comparison's reason for native Codex follow. Nothing on either port was observed again here. The routing record's attribution line says gateway-effort evidence. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Codex 0.159.2 receipt: withhold the quoted host client configuration data.host_resolution.config_toml_top_level_model quoted the two top-level model keys of the host's active ~/.codex/config.toml. AGENTS.md keeps machine-specific active client configuration out of evidence, so the value is withheld; the entry still records that the file was read once, read-only, at 2026-09-30T05:37:50Z. Claim and limitations are unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Codex 0.159.2 receipt: scope the dry-run refusal to what each run printed The claim said each dry run after the constant move refused only on the three preconditions an empty scratch home cannot meet; the 0.157.1 control printed a fourth [fail] line, its codex version. The claim now scopes "only the three" to the 0.159.2 run and says the control adds its version line. data.amended_at_utc is the time of this last amendment. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Codex user template: CODEX_MODEL from the platform's Codex pin (review of #542) The template set model and default_subagent_model to "gpt-6.1-sol" on every platform, while adoption/pins-macos-arm64.json pins Codex 0.155.1, whose bundled catalog has no GPT-6.1 entry. Both keys now read ${CODEX_MODEL}, which tools/adoption/render_config.py fills from the selected platform's Codex pin as it fills SOCRATICODE_VERSION: gpt-6.1-sol from Codex 0.159.1, gpt-6-astra before it. --set CODEX_MODEL=<model> names another; --out and --check print a derived value with its pin and sources. The threshold is 0.159.1, not 0.159.0: openai/codex codex-rs/models-manager/models.json has no "gpt-6.1-sol" slug at rust-v0.159.0 (687a119f) and one at rust-v0.159.1 (8e68a98e, line 178), whose release notes read "Added GPT-6.1 Sol as the default model in the bundled catalog". At rust-v0.155.1 (be2951ea) models.json lists gpt-6-astra with efforts low to ultra, and config/src/config_toml.rs L694-696 reads both [agents] default_subagent keys. The stack-worker profile keeps its literal gpt-6.1-sol: apply_codex_lane.py installs it verbatim, worker_pins() passes its model as -m, and the lane refuses any codex but CODEX_VERSION (the Linux pin). test_profile_template now asserts that the literal equals the rule for lane.CODEX_VERSION. Tests: CodexModelTests (both platforms, the 0.159.0/0.159.1 boundary, a host override, a platform without pins failing closed, the --out/--check note) failed first against the unchanged renderer and template (9 run: 6 failures, 12 errors). The K2 check in test_omniroute_profile_template reads a Linux render, and the strict-config integration fixture fills CODEX_MODEL from the rule. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Docs and receipt: CODEX_MODEL keeps gpt-6-astra on Codex pins before 0.159.1 - docs/decisions/2026-09-27-model-currency.md, addendum 2026-09-30: the template lines now read the placeholder (lines 7-8 and 30-31), the table row cites the Linux render, the "Still open" list names the rule, and the macOS follow-up records the placeholder, its upstream source and the offline prompt-input check instead of "It is not implemented here". - evidence/receipts/codex-01592-qualification-20260930.json: limitations[12] states the placeholder, and the new data.checks_after_the_constant_move.template_model_per_platform records the per-platform renders and a no-network `codex debug prompt-input` check: the 0.155.1 build over the macOS render includes Ultra's multi_agent_role and multi_agent_mode developer messages, drops both when only the two model values are set to gpt-6.1-sol, and 0.159.2 includes both over either render. Linux builds only; no model call. - adoption/platforms/macos-arm64.md and adoption/bootstrap.md: one clause each on the macOS render and the new derived placeholder. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Provenance wording for the folded Sol-defaults record: no inferred author (Codex runtime lane's request) Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * Sol-defaults record: Astra/Ultra coordinates a complex workflow, Astra/Max takes a single consequential judgment The user's 2026-09-30 selection named "astra ultra when tasks needed suitable for complex workflow"; the catalog semantics in this record (Ultra = proactive delegation with xhigh reasoning, Max = the highest reasoning effort) split the escalation accordingly. Docs only. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * Re-register the changed hash-listed files in manifests/evidence.json (hot-file protocol) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Scout <scout@local> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
lane:shared: it changes
manifests/stack.jsonand the Linux pins. Hold: merge only after 9a's release WINDOW DONE and the trading lane's acknowledgement. Auto-merge is off.This PR records the workstation switch of Codex CLI from 0.155.1 to 0.157.1, and adds a native Codex quota probe for the shared-budget practice the user chose on 2026-09-26: spend the GPT-6 quota in priority order now, and tell the user when the limit is reached.
The switch (qualified and staged in #332; run on this host 2026-09-26 at about 14:35Z)
The receipt's
data.switchwas run in order:codex features disable daemon_auto_startwith the staged binary, read back asfalse.bin/codex;codex --versionreportscodex-cli 0.157.1.gpt-6-astramax exec probe returnedPROBE-OKwith oneturn.completed.The coordinator and f5 held their Codex runs for the window.
nativestack-5975wx-20260925--codex--install--20260926: recorded from a clean checkout at published main, with read-only commands only (version, feature flag, daemon checks). It is recorded unbound: the landscape winner pins stay at 0.155.1 until a verdict wave.MAC_PIN_LAGS_LINUX;stack.json,upstream-snapshot.jsonand the lifecycle-audit row are updated to match.adoption/templates/codex.config.template.tomlnow setsdaemon_auto_start = false, so a new host that installs 0.157.1 never starts the self-updating daemon on its first interactive launch.Native quota probe and gate
scripts/codex_quota.pyreads the account's snapshot through Codex's own app-server protocol (account/rateLimits/read), checked againstcodex-rs/app-server-protocolat rust-v0.155.1 and rust-v0.157.1.--gate PERCENTexits 3 at the threshold, or whenrateLimitReachedTypeis set or ordinary usage is not allowed.--jsonprints one object.codex_job.py,staged.json codex.quota_stop_percent, off by default): at the threshold a job refuses before Codex starts, like the usage-limit marker, and writes<work-dir>/LIMITwith the reason so the coordinator can tell the user. A failed probe is recorded and never blocks a job.docs/token-practice.mdgets a dated "Shared Codex quota" section, with only the measured figures, each labelled with its source.Review record
Tests:
tests.test_codex_quotaandtests.test_landscape_sweep_harnessran 92, OK (2 skipped). The workflow's CI-style run over 37 modules passed with registration simulated.validate.pyandhost_receipts.py validatepass after registration.SOTA sources
codex-rs/app-server-protocol(account/rateLimits/read,GetAccountRateLimitsResponse), and thedaemon_auto_startfeature and updater, measured in the Workstation tool refresh: MCP Inspector 2.8.0 and Prometheus 3.15.0 switched, Codex 0.157.1 staged (daemon-safe switch plan) #332 qualification.evidence/receipts/codex-01571-qualification-20260926.json(Workstation tool refresh: MCP Inspector 2.8.0 and Prometheus 3.15.0 switched, Codex 0.157.1 staged (daemon-safe switch plan) #332):data.switchanddata.rollback.🤖 Generated with Claude Code