OmniRoute account pool: decision record, sanitized evidence, unit template and stack records for the release/v3.8.51 source build - #396
Merged
seathatflowsinourveins merged 13 commits intoSep 27, 2026
Conversation
Owner
Author
|
Other-lane acknowledgement for the I reviewed the shared hot-file changes at 1e7c37c:
No trading-owned paths change beyond that inventory entry. Acknowledged for merge once CI is green. 🤖 Generated with Claude Code |
Records the gateway the coordinator installed on the workstation on 2026-09-27 at the user's direction. The build: - OmniRoute release/v3.8.51 at a58000c7 plus upstream PR #14904 (the Proxy-safe deadline wrapper) and PR #13788 (/v1/alpha/search for Codex web.run); - built with upstream's own scripts, BUILD_SHA dd6e9607e. The installation: - a systemd --user service on loopback; - a keyless, passwordless posture, with its risk recorded; - Codex wired through an omniroute provider and profile at max effort. The record says plainly that the preregistered three-arm workers comparison stays the gate for any agent-sdks default change. Evidence classes stay separate: - live provider execution: probe run 2, the gateway's effort columns, and the search probe with its log; - unchanged upstream tests: 26 route and keepalive files, 184 of 186 pass, 2 skipped; - local integration: the settings read-back, the installed unit, the build identity, and cherry-pick patch-ids with the build tree; - a synthetic Proxy reproduction on three Node runtimes; - live upstream metadata: PR, issue, npm and CI state. Reported but not retained: the red-to-green keepalive run, the alpha-search test and the peer's 8-check probe. The full upstream test:unit summary is pending. Sources: - https://github.com/diegosouzapw/OmniRoute at a58000c7685f4091c7a6fd8ddf3ebce7d2ec67c3; - pulls 14904 and 13788, issue 14866; - the files cited per decision. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…51 source build Two sentences in the OmniRoute section held only for 3.8.50, and are now scoped to it: - the executor's xhigh clamp for unknown models (open-sse/executors/codex.ts L346-347 at 5458026c); - "native Codex passthrough skips router compression", a bypass that a58000c7 removed (open-sse/handlers/chatCore.ts L1429-1449 at a58000c7, whose comment names the codex/* exclusion as the remedy). A short section describes the workstation's source build of release/v3.8.51 at a58000c7 with #14904 and #13788. It links the decision record, the evidence, upstream's build scripts and the new unit template. It also covers effort, compression, the cx/ slug with no router alias, and the keyless loopback posture. The component pin stays 3.8.50, so the page's release links still match manifests/stack.json (tests/test_foundation_stack_pins.py). Sources: - https://github.com/diegosouzapw/OmniRoute at a58000c7 and 5458026c; - pulls 14904 and 13788. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ctural tests adoption/templates/systemd/omniroute.service mirrors the unit installed on the workstation (the evidence copy). Three placeholders stand in for host values, following this directory's @name@ convention: @OMNIROUTE_PREFIX@, @NODE_PREFIX@ and @CODEX_CLIENT_VERSION@. Secrets arrive only through EnvironmentFile=. The file holds plain NAME=value lines, the format upstream's own scripts/build/bootstrap-env.mjs writes to {DATA_DIR}/server.env. Every non-secret Environment= line carries its reason and upstream source. The template adds one line the installed unit lacks: Environment=OMNIROUTE_SERVER_HOST=127.0.0.1. `omniroute serve` binds 0.0.0.0 when that variable is unset (bin/cli/utils/serverHost.mjs L16-26 at a58000c7), and the keyless posture needs loopback. On the workstation the environment file already sets the same value. tests/test_omniroute_gateway_unit.py checks, offline: - the template, rendered with the workstation's values, reproduces the recorded installed unit; - the placeholder set is exact and documented; - secret-like names never appear in Environment=; - each Environment= line has its own reason; - serve runs in the foreground (no --daemon or --no-recovery) with Restart=on-failure. Discriminating controls plant a secret line, an unexplained line and two drifts, and each is caught. Manual check, rendered copy: systemd-analyze --user verify rc 0 (systemd 255). A copy with a missing ExecStart binary fails with rc 1. Sources: - https://github.com/diegosouzapw/OmniRoute at a58000c7: bin/cli/commands/serve.mjs, bin/cli/utils/serverHost.mjs, bin/cli/utils/pid.mjs, scripts/build/runtime-env.mjs, scripts/build/bootstrap-env.mjs, src/shared/utils/runtimeTimeouts.ts, src/shared/services/cliRuntime.ts; - systemd.exec(5), EnvironmentFile=. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…count pool catalogs/foundation/manifest.json, native-clients selection: records the user's 2026-09-27 decision. A loopback OmniRoute gateway is adopted for pooled GPT-6 access by gateway-routed Codex lanes such as the landscape sweep. Native Codex stays the max-quality default. The agent-sdks layer default stays pending the preregistered three-arm workers comparison (docs/grand-catalog-handbook.md:602), which remains its only acceptance gate. Model routing is still not a separate layer. Only layer prose changes; checked_at and the decisions file are untouched. adoption/credential-inventory.json, omniroute entry: - a keyless loopback gateway with an optional per-lane key; - callers pass the placeholder local-loopback, and the store stays absent; - a host or lane that turns REQUIRE_API_KEY=true creates scoped keys per lane; - tools/sota-convergence/landscape-sweep/codex_job.py (#387) and Codex's env_key are added as environment-only consumers; - the lane is now model-gateway, because the foundation's Codex lanes consume the key as well as the trading routing recipe. The variable set is unchanged, so the secret-path guard's name list still covers every inventory variable. The docs/secret-storage.md row matches the entry. The decision record gains one line: the template adds an explicit OMNIROUTE_SERVER_HOST=127.0.0.1. Sources: - the decision record; - https://github.com/diegosouzapw/OmniRoute at a58000c7: bin/cli/utils/serverHost.mjs L16-26, docs/guides/CODEX-CLI-CONFIGURATION.md ("Local unauthenticated OmniRoute"), src/shared/validation/schemas/keys.ts (key scoping fields). Checks: validate_foundation.py errors [] and 159 tests OK across test_foundation_catalog, test_secret_path_guard, test_host_requests, test_ecosystem_manifest and test_credential_status. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The coordinator's upstream `npm run test:unit` run finished at 08:17Z (Node 24.21.0, upstream's own runner flags). Its summary is added verbatim, together with an extraction by the record's author: - the runner's own totals: 43,522 tests, 43,460 pass, 31 fail, 31 skipped; - the 21 failing files and the 31 failing names; - a diff with the 30 names from the same files on bare a58000c7. Exactly one failure comes from the picks. #13788's /v1/alpha/search route adds a connection-query site that tests/unit/hard-session-lease-bypass-inventory.test.ts:348 does not classify. It is not patched locally. The other 30 are base reds of the release branch (#14866). #14904 adds none. The output holds one totals block. upstream's test:unit chains three stages with &&, so stage 1's failures stopped the chain: the dashboard stage and test:unit:serial did not run (package.json line 132 at dd6e9607e). The README and the decision record say so, and do not call this the full suite. Sources: - https://github.com/diegosouzapw/OmniRoute package.json "test:unit" and "test:unit:serial" at the build tree; - the tests named above. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ll unit run
One GPT-6 review round (codex exec, read-only) reported 5 medium and 2
low findings. All 7 are fixed here.
1. medium: gateway-search-log.jsonl was ignored by the repository's
*.jsonl rule, so it was never committed or registered. Fix: a narrow
.gitignore exception for this evidence directory, following the
existing per-directory exceptions, and the file is now tracked.
2. medium: proxy-repro.txt shared one POST body between its two arms.
Its Node 22 "already been used" result came from that shared body,
not from the Proxy. Fix: a corrected rerun, proxy-repro-independent.
txt, gives each arm its own Request. Proxied POST and GET fail with
the #state TypeError on Node 24.21.0 and 26.10.0, and construct on
Node 22.23.3. The first attempt is kept and its flaw noted. The
decision now says defect 1 affects the Node 24 and 26 lines, that
upstream's Docker base is node:26 (Dockerfile L2), and that a Node 22
gateway was not tried. #13788 needed a source build anyway.
3. medium: the claim that secrets arrive only through EnvironmentFile=
overstated what a unit can enforce, because a user service inherits
the user manager's environment (systemd.exec(5)). Fix: the
template, decision, foundation-stack and README now say the unit
holds no secret and adds its secrets only through EnvironmentFile=.
They also say how to keep credentials out of the manager. The test
is renamed to what it checks.
4. medium: the route and keepalive summary lacked its selection and
skips. Fix: upstream-tests-route-keepalive-detail.txt retains the
totals, the two upstream skips with their reason, 0 not-ok lines,
and #14904's two passing cases. The command line and the 26-file
list are labelled reported, not retained.
5. medium: the decision cited research rows and an X1 preregistration
that are not in the repository. Fix: every such claim now carries a
pinned upstream citation, checked against local copies. That covers:
- the divergences: codex.ts L1467-1484, L1362-1369, L366, L374-393;
Codex client.rs L859-878, L897-954; provider.rs L410-423;
- the risk: management.ts L261-266, routeGuard.ts L79, hooks
route.ts L79;
- the backups: backup.mjs L27-32;
- systemd's env-util.c L28-50 at v255.
The synthesis items are labelled as recommendations not retained
here, and X1 is described as a sketch that is not frozen and has not
run.
6. low: settings.ts forces requireLogin only while first-time setup is
incomplete. Fix: the decision now states the condition. The
verbatim make_passwordless.py record is annotated in the README
rather than edited.
7. low: the suite summary's 07:45-08:17Z range was inconsistent. Fix:
a dated correction from the process's elapsed time (14:43 at
07:45:47Z) and the output file's mtime (08:03:29Z) puts the run at
about 07:31-08:03Z, which matches the runner's 1944 s. The
coordinator's summary stays verbatim.
Also:
- the decision's scope line no longer lists an observation-inference
change that was not made;
- one nested list is re-indented;
- the EnvironmentFile= exposure paragraph cites bin/omniroute.mjs
L134-216 and serve.mjs L281-298, and states the departure from
docs/secret-storage.md step 9.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…citations A line-by-line re-check of every cited upstream line, after the GPT-6 review round, found one misquote and three claims without a citation for their mechanism. GPT-6 did not see this commit (one review round only). Each change below was read at its pin: the local a58000c7 checkout, and Codex rust-v0.157.1 and systemd v255 through the GitHub contents API. Decision record: - Sticky limit. The record said AUTO-COMBO.md recommends sticky 1 for "one-model rotation". Upstream says to set the combo override to 1 "for one-request rotation" (docs/routing/AUTO-COMBO.md L354-357). The codex provider strategy's limit is read before the global setting (src/sse/services/auth.ts L1999-2000). - export lines. systemd's parser keeps "export NAME" as the key (src/basic/env-file.c L75-95). The EnvironmentFile= loader then drops every assignment with an invalid name (src/core/execute.c L773-787; src/basic/env-util.c L542-554, L78-90, L28-50). The record cited only the name check before. - Stream timeouts. The readiness budget never exceeds its cap (open-sse/utils/streamReadinessPolicy.ts L198). The content-stall watchdog reuses that budget (open-sse/handlers/chatCore.ts L6395-6399). The active timeout is a hard cap that upstream bytes never reset (open-sse/config/constants.ts L31-33). - The template mirrors the installed unit's directives apart from Description=. The source-review line names every pin. Unit template and its test: - Each Environment= line now has a one-line reason, as the unit brief asks. The lsof shim's failure and removal text moves to the header. The header says Description= and comments also differ from the installed unit. - unexplained_environment() now requires exactly one reason line. A planted two-line reason is caught. The previous template fails the stricter check on 3 lines: PATH, OMNIROUTE_SERVER_HOST and STREAM_READINESS_TIMEOUT_MS. Directives are unchanged, so the template still renders to the recorded installed unit. Evidence README: the installed-unit row no longer says every Environment= line has a reason comment. OMNIROUTE_MEMORY_MB has none in the installed unit. Sources: - https://github.com/diegosouzapw/OmniRoute at a58000c7685f4091c7a6fd8ddf3ebce7d2ec67c3; - https://github.com/systemd/systemd at v255; - the repository's own tests/test_token_report_refresh_units.py style for planted-violation controls. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…stener and search-row observation The independent verifier found that probe-lane-run2.json and probe-search-profile-only.json were derived by hand in an undeclared step, and that this step dropped one of run 2's four gateway rows. Changes: - scripts/derive_probe_records.py.txt re-derives both files from the same private outputs. The run 2 record keeps all four rows, with conn_hash replaced by an account letter, plus the rollout turn_context line and effort_fields as printed. The script also writes probe-lane-client-events.json: Codex's side of the 06:32Z "high demand" probe and of run 1. The README declares the sanitization, as docs/acceptance-evidence-policy.md requires. - The README explains the four rows. Each request is listed twice, once as an in-memory entry and once as a persisted row. That matches OmniRoute's list route (src/app/api/usage/call-logs/route.ts L116-226 and src/lib/usage/callLogs.ts L457-508 at a58000c7). - build-delta.txt shows that bf0255649 and dd6e9607e differ in two files. The README now names the build behind every live observation. - gateway-readonly-observation.txt comes from scripts/observe_gateway.py.txt, a read-only run at 10:40Z. The unit's only listeners are 127.0.0.1:20128, :20131 and :20132, and call_logs holds one /v1/search row per SEARCH line. That corrects the earlier claim that /v1/alpha/search writes no call_logs rows (open-sse/handlers/search.ts L1625-1638). - Two more items are reported, not retained: route_repro's status lines and run 1's account relation. Run 1's follow-up has no call_logs row, and the README says so. Sources: - https://github.com/diegosouzapw/OmniRoute at a58000c7685f4091c7a6fd8ddf3ebce7d2ec67c3 for the files above, and dd6e9607e4884ec75c9bc0d96e60b01e9483d84e for the build delta; - https://github.com/openai/codex at rust-v0.157.1, codex-rs/codex-api/src/api_bridge.rs L157-158 and codex-rs/protocol/src/error.rs L160-161 (HTTP 500 is shown as "high demand"); - iproute2 ss(8), https://man7.org/linux/man-pages/man8/ss.8.html, and the cgroup v2 cgroup.procs file, https://docs.kernel.org/admin-guide/cgroup-v2.html, for the listener observation; - docs/acceptance-evidence-policy.md ("declare every public sanitization"). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…t template and its test Decision record: - It names the build behind each live observation. The lane probe and the effort rows ran on bf0255649. Their results carry to dd6e9607e by the two-file build delta, not by a rerun. - The loopback bind is now cited for all three listeners, and the 10:40Z observation backs it. LIVE_WS_HOST, EMBED_WS_PROXY_HOST and the two _PORT variables join the keep-out-of-the-manager guidance. - It gives the source for Codex's "high demand" message, and lists route_repro's status lines and run 1's account relation as reported, not retained. - "No API exposes these columns" now rests on mapSummaryRow, and L646-653 explain when the columns are filled. - The CODEX_CLIENT_VERSION citation now points at open-sse/config/codexClient.ts, and the facts the verifier found uncited now carry their lines. The "every factual claim" sentence is narrowed. - The claim that /v1/alpha/search writes no call_logs rows is corrected. docs/foundation-stack.md: the Node 26 failure is labelled as a synthetic-fixture result, and the effort observation names its build. Unit template: the manager guidance covers the WebSocket bind variables, and the CODEX_CLIENT_VERSION reason cites the right file. The directives are unchanged, so the template still mirrors the installed unit. tests/test_omniroute_gateway_unit.py: the EnvironmentFile= count, the Environment= name set, the credential-text regex, the placeholder set and the supervision settings are now helpers with planted controls. A recorded red run fails the main secret test on a second EnvironmentFile=, an undocumented Environment= name and an export line, and passes it on the clean template. Sources, OmniRoute at a58000c7685f4091c7a6fd8ddf3ebce7d2ec67c3 (https://github.com/diegosouzapw/OmniRoute): - src/server/ws/liveServer.ts L50-54, L713-714; - src/lib/services/embedWsProxy.ts L35-36, L240-242, L256-257; - .env.example L2302-2308; - open-sse/config/codexClient.ts L13, L29-34, L36-83; - src/shared/constants/codexClient.ts L6; - src/lib/usage/callLogs.ts L457-508, L646-653, L1021, L1040; - src/app/api/usage/call-logs/route.ts L116-226; - open-sse/handlers/search.ts L1625-1638; - bin/cli/locales/en.json L255-256; - bin/cli/commands/serve.mjs L64-65; - src/sse/services/auth.ts L1995-2001; - src/lib/db/settings.ts L159, L163; - open-sse/services/compression/types.ts L421-423; - src/lib/db/compression.ts L663-664; - open-sse/services/thinkingBudget.ts L8-9, L19, L65-67. Also https://github.com/openai/codex at rust-v0.157.1: codex-rs/codex-api/src/api_bridge.rs L157-158 and codex-rs/protocol/src/error.rs L160-161. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… APIs and the manager bind variables - The four-row listing pattern is stated as consistent with the list route's merge, not proven, because the ids are withheld. - The in-memory entries of the list route also carry no effort field (src/app/api/usage/call-logs/route.ts L141-174, L186-215 at a58000c7). - A LIVE_WS_HOST or EMBED_WS_PROXY_HOST in the user manager could move a listener off loopback; it does not always do so. Source: https://github.com/diegosouzapw/OmniRoute at a58000c7685f4091c7a6fd8ddf3ebce7d2ec67c3. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…helpers with planted controls The module docstring says every check of the template's text is a helper that a planted violation fails. Two main assertions were still direct: the TEMPLATE_ONLY presence and absence loop, and the render-away check. Now: - template_only_problems() replaces the loop. Its control drops the line from the template and adds it to the installed copy. - placeholder_problems() also reports placeholders left after rendering. The unknown-placeholder control now expects both findings. A recorded red run fails each main template test on a planted copy, and each passes on the clean template (units/gateway/round2/red-run.txt). Source: docs/acceptance-evidence-policy.md, "Discriminating controls". Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The build carries one upstream fix (#14904, the deadline wrapper) and one upstream feature (#13788, the /v1/alpha/search route for Codex's standalone web search). Reword "two upstream fixes" and "both fixes" in the decision title, the foundation-stack section, the foundation catalog status and the upstream test summary. Raised by the other lane's acknowledgement review of #396. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…he workstation posture; evidence registration manifests/stack.json, omniroute. The schema has no field for a source build with cherry-picks, and scripts/landscape.py requires version and source_pin to equal the dated landscape freshness snapshot. So the pin stays the published 3.8.50 (5458026c, still npm latest on 2026-09-27). freshness records the running build: - the base: release/v3.8.51 at a58000c7685f4091c7a6fd8ddf3ebce7d2ec67c3; - the picks: #14904 and #13788, with patch-ids equal to upstream's; - BUILD_SHA dd6e9607e; - a pointer to the decision record and the evidence directory. Other fields: - command_scope names the unit template and the adoption scope. It now says that the workstation gateway runs keyless and passwordless on loopback by the user's decision (decision 5), and that a multi-user or non-loopback host keeps the recipe's API key and dashboard login. Native Codex stays the max-quality default, and agent-sdks waits on the three-arm comparison. - upstream_sources gains the base commit and the two PRs. - role is unchanged. tests/test_stack_lifecycle.py L31-32 pins it to the row in blueprints/token-native-focus/saturation-audit.json, so the stale "authenticated" wording is a recorded residual. manifests/evidence.json, per the docs/lanes.md hot-file protocol: - taken from main at 5f3a7c2; - re-registers the changed tracked files: .gitignore, the credential inventory, the foundation catalog manifest, foundation-stack, secret-storage and stack.json; - registers the 35 evidence files, the decision record, the unit template and its test. That is 44 files, the full list of files this branch adds or changes; - component_matrix.py --write and new_host_grand_list.py --write were rerun, with no content change. validate.py passed with hashed_files 7288. Sources: - https://github.com/diegosouzapw/OmniRoute at commit a58000c7 and pulls 14904 and 13788; - docs/lanes.md "Hot-file protocol". Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
seathatflowsinourveins
force-pushed
the
claude/omniroute-account-pool-20260927
branch
from
September 27, 2026 12:12
1e7c37c to
7bd7b3e
Compare
seathatflowsinourveins
deleted the
claude/omniroute-account-pool-20260927
branch
September 27, 2026 12:30
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Scope
What this PR changes. It records the OmniRoute account pool that the coordinator installed on the workstation on
2026-09-27 at the user's direction. The build is OmniRoute
release/v3.8.51ata58000c7plus upstream PRs#14904 and #13788 (
BUILD_SHA dd6e9607e), running as a keyless loopbacksystemd --userservice with Codex wiredat max effort. The PR adds:
docs/foundation-stack.md, the foundation catalog, the credential inventory andmanifests/stack.json.No host is changed by this PR. The record's author made read-only observations only.
Base commit:
5f3a7c21, currentorigin/main. The coordinator created the branch at50b9579f; it had nocommits, so it was fast-forwarded before the first commit.
Lane:
lane:shared. The PR changesmanifests/stack.json, a shared hot file, and it needs the trading lane'sacknowledgement before merge (
docs/lanes.md).Owned paths touched:
docs/decisions/2026-09-27-omniroute-account-pool.md(new);evidence/artifacts/omniroute-gateway-20260927/(new, 35 files);adoption/templates/systemd/omniroute.service(new);tests/test_omniroute_gateway_unit.py(new);docs/foundation-stack.md;docs/secret-storage.md(one table row);catalogs/foundation/manifest.json(native-clients prose);adoption/credential-inventory.json(theomnirouteentry);.gitignore(one narrow*.jsonlexception for the new evidence directory);manifests/stack.jsonandmanifests/evidence.json, in the last commit (1e7c37c4).SOTA sources
release/v3.8.51ata58000c7685f4091c7a6fd8ddf3ebce7d2ec67c3, still its head at 07:58Z pergit ls-remote.b94e2dba, commits07a6317b2,b94e2dba4) and PR feat(search): implement /v1/alpha/search endpoint for Codex native web search (fixes #8674) diegosouzapw/OmniRoute#13788 (head6c799005, commits24bbadbad,6c7990058). Their patch-ids equal the applied commits'.bf0255649anddd6e9607ediffer in twofiles (
build-delta.txt).a58000c7:open-sse/utils/earlyStreamKeepalive.ts:341;open-sse/executors/codex.tsL354-355, L366, L374-393, L1362-1369, L1463, L1467-1484;open-sse/executors/codex/reasoningSuffix.tsL11-31;open-sse/handlers/chatCore.tsL1429-1449, L6395-6399;open-sse/handlers/search.tsL1606, L1625-1638 (the free provider'sSEARCHline and its/v1/searchcall-log row);
open-sse/utils/streamReadinessPolicy.tsL198;open-sse/config/constants.tsL31-33;open-sse/config/codexClient.tsL13, L29-34, L36-83 (CODEX_CLIENT_VERSIONand the caller-first fallback);open-sse/services/compression/types.tsL421-423;open-sse/services/thinkingBudget.tsL8-9, L19, L65-67;src/sse/services/auth.tsL1952-1957, L1995-2001;src/shared/utils/runtimeTimeouts.tsL21, L24-25;src/shared/constants/codexClient.tsL6 (the built-in default, 0.156.1);src/shared/services/cliRuntime.tsL1077-1078;src/lib/db/settings.tsL159, L163, L301-311;src/lib/db/compression.tsL663-664;src/lib/usage/callLogs.tsL457-508, L646-653, L1021, L1040;src/app/api/usage/call-logs/route.tsL116-226;src/server/ws/liveServer.tsL50-54, L713-714;src/lib/services/embedWsProxy.tsL35-36, L240-242, L256-257;src/server/authz/policies/management.tsL261-266;src/server/authz/routeGuard.tsL79;src/app/api/middleware/hooks/route.tsL79;scripts/build/runtime-env.mjsL19;scripts/build/bootstrap-env.mjsL1-19, L183-186;bin/omniroute.mjsL134-216;bin/cli/commands/serve.mjsL64-65, L252-261, L281-298;bin/cli/locales/en.jsonL255-256;bin/cli/commands/backup.mjsL27-32;bin/cli/utils/pid.mjsL73-99;bin/cli/utils/serverHost.mjsL16-26;.env.exampleL2302-2308;DockerfileL2 (node:26-trixie-slim);package.jsonenginesandtest:unit(line 132 at the build tree);docs/guides/CODEX-CLI-CONFIGURATION.md("Session affinity");docs/routing/AUTO-COMBO.mdL354-357.5458026c216f77a3da68ea49152dc33470cfe2cb):open-sse/executors/codex.tsL346-347,for the
xhighclamp.npm ci,npm run build:release,npm run build:cli-api,npm packandnpm run check:pack-artifact.rust-v0.157.1:codex-rs/model-provider-info/src/lib.rsL136-196;codex-rs/core/src/client.rsL859-878 and L897-954;codex-rs/model-provider/src/provider.rsL410-423;codex-rs/codex-api/src/api_bridge.rsL157-158 andcodex-rs/protocol/src/error.rsL160-161: an HTTP 500 isshown as "We’re currently experiencing high demand";
codex-rs/shell-command/src/shell_snapshot_exports.rs, the 0644 snapshot finding from Landscape-sweep GPT-6 lane through OmniRoute: lane-local Codex home with the token stack at max effort (stacked on #385) #387.EnvironmentFile=values overrideEnvironment=, and user services inherit the user manager'senvironment. Both were read in the host's systemd 255 man page.
exportlines are dropped, at v255: the parser keepsexport NAMEas the key(https://github.com/systemd/systemd/blob/v255/src/basic/env-file.c#L75-L95), and the
EnvironmentFile=loaderdiscards invalid names (https://github.com/systemd/systemd/blob/v255/src/core/execute.c#L773-L787;
src/basic/env-util.cL542-554, L78-90, L28-50).systemd-analyze --user verifywas run with systemd 255.4.ss(https://man7.org/linux/man-pages/man8/ss.8.html) for sockets and theirowning pids, and the cgroup v2
cgroup.procsfile (https://docs.kernel.org/admin-guide/cgroup-v2.html) under theunit's
ControlGroupfor the unit's processes.next/dist/server/route-modules/app-route/module.jsL626-629 (proxyNextRequest), read inthe build's
node_modules.docs/lanes.md"Hot-file protocol";docs/acceptance-evidence-policy.md(classes, discriminating controls, declared sanitization);docs/secret-storage.md;docs/decisions/2026-09-26-codex-worker-lane.mdandevidence/artifacts/codex-worker-lane-20260926/README.md;adoption/templates/systemd/*.serviceandtests/test_token_report_refresh_units.py;.jsonlexceptions already in.gitignore.Evidence-class table
bf0255649; it carries to the runningdd6e9607eby the two-file source difference, not by a rerunevidence/artifacts/omniroute-gateway-20260927/probe-lane-run2.json(all four listing rows and the rollout line, derived byscripts/derive_probe_records.py.txt),build-delta.txtmaxrequested andmaxsent upstream on both reasoning turns, onbf0255649. No failing control: no clamping 3.8.50 gateway was probed, and the 3.8.50 clamp rests on source (v3.8.50codex.tsL346-347)call_logs, read-only select)gateway-effort-rows.jsonweb.runreaches/v1/alpha/search(duckduckgo-free) ondd6e9607e, and each search leaves a/v1/searchrow incall_logs; results are sparseprobe-search-profile-only.json,gateway-search-log.jsonl,gateway-readonly-observation.txt127.0.0.1:20128,:20131and:20132gateway-readonly-observation.txtviascripts/observe_gateway.py.txtprobe-lane-client-events.jsonupstream-tests-route-keepalive.txt,upstream-tests-route-keepalive-detail.txttest:unitstage 1 on the build: 43,522 tests, 31 fail. 30 are base reds (#14866) and 1 comes from #13788's inventory gap. Stages 2 and 3 did not runupstream-test-unit-summary.txt,upstream-test-unit-failures.txt6f3f9a23…;bf0255649anddd6e9607ediffer in two filescherry-pick-fidelity.txt,build-delta.txtBUILD_SHAisdd6e9607e; the service is active with 0 restartsinstalled-build-identity.txtcodex/*, passthrough, MCP/A2A off, login offgateway-settings-readback.jsonRequestfails to rebuild on Node 24 and 26 and rebuilds on Node 22. The first fixture's Node 22 result was an artifact of a shared bodyproxy-repro-independent.txt(corrected),proxy-repro.txt(first attempt, kept)upstream-state.txtEnvironmentFile=, uses the documentedEnvironment=names and placeholders once each, runsservein the foreground under systemd, and gives eachEnvironment=line a one-line reasonEnvironmentFile=, an undocumented name, anexportline, a dropped template-only line, an unrendered placeholder,--daemon) and passes each on the clean templatepython3 -m unittest tests.test_omniroute_gateway_unit(16 tests)route_repro.py's HTTP 500 status lines, and run 1's account relationb9abcc5fLocal commands run
All on the final head
1e7c37c4:Cross-family review (GPT-6, one round)
codex-omniroute exec -s read-onlyreviewedgit diff origin/main...HEAD. It answered DEFECTS FOUND: 5 medium and2 low findings. All 7 are fixed in
e50912f6.gateway-search-log.jsonlwas ignored by*.jsonl. Fix: a narrow.gitignoreexception, and the file is now tracked and registered.Node 24 and 26 fail. The decision no longer claims a runtime switch cannot help.
EnvironmentFile=-only claim ignored the inherited user-manager environment. Fix: the claim is narrowed inthe template, decision and docs, and the test is renamed.
and file list are labelled reported, not retained.
and the synthesis is labelled.
requireLogincondition was misstated. Fix: the first-time-setup condition is stated. The verbatim scriptrecord is annotated, not edited.
362aa10eis a precision pass that GPT-6 did not see: a misquote of AUTO-COMBO.md, three uncited mechanism claims,and a one-line reason for each template
Environment=line, enforced by the test.Independent verification round (no second GPT-6 round)
An independent verifier reported 4 medium and 7 low defects. All 11 are fixed in
4fa4cd01,01862d18,8da636c3,f7a0851eand1e7c37c4:called the resulting pattern an unexplained duplicate. Fix:
scripts/derive_probe_records.py.txtre-derives bothfiles from the private outputs with a declared sanitization. All four rows are kept, and each request is listed
twice, which matches upstream's list route (
call-logs/route.tsL116-226). The README says which filesstage_evidence.pywrote.foundation-stack.mdpresented Node 26 as observed. Fix: Node 26 is labelled a synthetic-fixtureresult; the gateway ran only on Node 24.
probe-lane-run2.json.Codex's side of the 06:32Z probe is retained, with the Codex source that shows an HTTP 500 as "high demand".
route_repro's status lines and run 1's account relation are listed as reported, not retained.observation, citations for all three binds, and
LIVE_WS_HOST/EMBED_WS_PROXY_HOSTin the manager guidance.build-delta.txtas the reason the results carry todd6e9607e.CODEX_CLIENT_VERSIONcitation now points atopen-sse/config/codexClient.ts.mapSummaryRow, and L646-653 explain the nulls.roleandcommand_scope. Fix:command_scopestates the keyless workstation posture.rolestays, as a residual below.
the template-only and render-away checks, which were also direct assertions. A red run is recorded.
The record's author also found, from source, that
/v1/alpha/searchdoes writecall_logsrows, under the path/v1/search(open-sse/handlers/search.tsL1625-1638). The read-only observation shows one row perSEARCHline. The earlier "writes no rows" claim came from a probe that looked only for
alpha/searchin the path, and it iscorrected in the decision and the README.
Decision record
docs/decisions/2026-09-27-omniroute-account-pool.md. It gives the evidence with its classes kept separate, thealternatives (including the settings synthesis's "require key and login", which the user overrode) and the overturn
conditions:
The preregistered three-arm workers comparison (
docs/grand-catalog-handbook.md:602) stays the only gate for theagent-sdks layer default.
Host evidence
Not applicable: no file under
evidence/hosts/changes.Not done and residuals
manifests/stack.json's omnirouterolestill reads "Optional authenticated model gateway…", although theworkstation gateway is keyless.
tests/test_stack_lifecycle.pyL31-32 requires the role to equal the row inblueprints/token-native-focus/saturation-audit.json, so changing it means changing that audit too. That is leftfor a follow-up;
command_scopenow states the workstation posture.source (v3.8.50
codex.tsL346-347).bf0255649. They carry todd6e9607eby the two-file sourcedifference, and the lane probe was not rerun on
dd6e9607e.call_logsrow. Run 1's client usage exceeds its one row, and therecord does not explain the gap.
route_repro.py's HTTP 500 status lines and run 1's account relation are reported, not retained.derive_probe_records.pyneeds the coordinator's private probe outputs, so only the coordinator can rerun it.The listener and search-row observation postdates the probes; the same process served them (0 restarts since
07:19:46Z).
blueprints/us-equities/routing/README.md:26still says no Linux gateway is proposed. It belongs to the tradinglane and is not edited here; the trading lane's acknowledgement should cover a follow-up edit.
catalogs/foundation/surfaces.json'somnirouterow still describes the Windows gateway.and a failing-first control, which is a separate change.
[shell_environment_policy.filters]exclude for the key. This is moot with thelocal-loopbackplaceholder, but becomes live once a real per-lane key is used.server.envlives insideDATA_DIR. Upstream's native backups exclude it, but a raw copy of the directory carriesthe key with the tokens.
test:unitstages 2 and 3 did not run on this tree.Environment=OMNIROUTE_SERVER_HOST=127.0.0.1. The effectiveenvironment is the same on the workstation. The coordinator may add the line to the installed unit.
make_passwordless.py.txtandeffort_rows.py.txtdocstrings keep their misstatements, which theREADME annotates.
Checklist
local-loopback, in ascript record, and the test's planted
Bearer fixtureline. gitleaks passed at every commit through the pre-commithook.
🤖 Generated with Claude Code