Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion adoption/bootstrap.md
Original file line number Diff line number Diff line change
Expand Up @@ -262,7 +262,7 @@ GitHub-hosted macOS runner; see
file is absent the command exits 0 and adds nothing.
`codex.config.template.toml` changed after `v2026.09.26`: it turns the context-mode plugin's own MCP server off and registers context-mode at user scope with no `cwd`, running the pinned npm install's `start.mjs`, so each Codex session's server binds that session's own directory ([recipe](../recipes/README.md#retained-context-mode)), and its `headroom` entry adds `HF_HUB_OFFLINE` and `TRANSFORMERS_OFFLINE`; `project.codex.config.template.toml` changed after `v2026.09.26` in its comments only.
The recipe's project-scoped alternative changed after `v2026.09.26.2`: it adds `default_tools_approval_mode = "approve"` and a `CLAUDE_PROJECT_DIR` equal to its project directory, as upstream `start.mjs` sets, so a project entry keeps Codex tool approvals and the server-side project `Bash(...)` denies ([recipe](../recipes/README.md#retained-context-mode)).
`codex.config.template.toml` changed after `v2026.09.26.2` again: it sets `web_search = "live"`, `check_for_update_on_startup = false`, `[features] shell_snapshot = false` and `[agents] default_subagent_reasoning_effort = "max"`, and it no longer trusts four dated validation directories. The opt-in gateway profile `codex.omniroute.config.toml` (added after that tag) is not rendered here; `tools/adoption/apply_codex_lane.py --omniroute-profile` installs it ([recipe](../recipes/README.md#codex-through-omniroute)).
`codex.config.template.toml` changed after `v2026.09.26.2` again: it sets `web_search = "live"`, `check_for_update_on_startup = false`, `[features] shell_snapshot = false` and `[agents] default_subagent_reasoning_effort = "max"`, and it no longer trusts four dated validation directories. Its SocratiCode server now runs `${ECO_ROOT}/tools/socraticode-${SOCRATICODE_VERSION}/`, which `render_config.py` renders from the selected platform's pin like `${AI_MEMORY_BIN}` (1.15.0 on Linux and 1.14.0 on macOS since 2026-09-27); `--set SOCRATICODE_VERSION=<version>` names another install. The opt-in gateway profile `codex.omniroute.config.toml` (added after that tag) is not rendered here; `tools/adoption/apply_codex_lane.py --omniroute-profile` installs it ([recipe](../recipes/README.md#codex-through-omniroute)).
The rendered `codex.config.toml` keeps the source host's `trusted_hash`
entries for the ai-memory commands in `~/.codex/hooks.json`, recorded before
those commands moved to 2.4.x; Codex treats the changed commands as
Expand Down
20 changes: 10 additions & 10 deletions adoption/pins-linux-x86_64.json
Original file line number Diff line number Diff line change
Expand Up @@ -261,11 +261,11 @@
},
{
"id": "ccusage",
"version": "20.0.24",
"version": "20.0.26",
"kind": "npm",
"url": "https://registry.npmjs.org/ccusage/-/ccusage-20.0.24.tgz",
"sha256": "69787a0aa2269cd14f3d0f41d179b80744d5384e912ee11852897ecd0bf91183",
"install_note": "2026-09-25 fetch to complete the `token-efficiency` profile's Linux pin coverage. npm registry tarball for ccusage@20.0.24 downloaded fresh and independently sha256-hashed; npm dist.integrity sha512-sHq7axM0ucbFS4m5xFzS7NxYSmOP1+PSDup3nVb+pitI3eEuwEiGObhsXvu47DSvB2hHpEts/quA3/0EE5i1Zw== matches a fresh openssl sha512/base64 digest of the same download exactly. `npm install --global --prefix tools/ccusage-20.0.24 ccusage@20.0.24`, the npm form recipes/native-upgrades-20260921.md's isolated-prefix installation documents, and the exact version manifests/stack.json already pins. `ccusage --version` prints `ccusage 20.0.24` and exits; confirmed 2026-09-25 in an isolated `npm --prefix` scratch install, not the shared host copy.",
"url": "https://registry.npmjs.org/ccusage/-/ccusage-20.0.26.tgz",
"sha256": "b8d59c191f357d5e847c109f306cf522e60496fc9219be2ab72d201fd59eb1f2",
"install_note": "2026-09-27 move from 20.0.24 (evidence/receipts/ccusage-20026-qualification-20260927.json). npm registry tarball for ccusage@20.0.26 downloaded fresh and independently hashed; npm dist.integrity sha512-46TTmFKcuNyWbtqj8HZqWTmVQIsApvGO4xP+E2VL5NC/oMjdtHOv9svVTsHX1WQgetbNOV4GdvQGHLG22vXZgg== and dist.shasum a0d190787b26183dd78797283c59db3ec9ee7817 match fresh sha512 and sha1 digests of the same download. The tarball carries only the JavaScript launcher; `npm view ccusage@20.0.26 optionalDependencies` lists six `@ccusage/ccusage-*@20.0.26` native builds and npm resolves `@ccusage/ccusage-linux-x64` at install time, outside this hash. `npm install --global --prefix tools/ccusage-20.0.26 ccusage@20.0.26`, the npm form recipes/native-upgrades-20260921.md's isolated-prefix installation documents, and the exact version manifests/stack.json pins. `ccusage --version` prints `ccusage 20.0.26` on the host install the coordinator switched to on 2026-09-27; the 20.0.24 prefix is retained for rollback.",
"version_probe": {
"method": "exec",
"command": "ccusage",
Expand Down Expand Up @@ -309,17 +309,17 @@
},
{
"id": "socraticode",
"version": "1.14.0",
"version": "1.15.0",
"kind": "npm",
"ignore_scripts": true,
"url": "https://registry.npmjs.org/socraticode/-/socraticode-1.14.0.tgz",
"sha256": "3dbb106c876be4214048289cef31094eb0e48e97007fb90180270edc4eed7c46",
"url": "https://registry.npmjs.org/socraticode/-/socraticode-1.15.0.tgz",
"sha256": "f1ec039e58013863c6e736d1c17876386b9fec1daf9abf72960fcc51c3e364d1",
"checksum_source": "npm_registry_integrity_crosscheck",
"checksum_ref": "npm view socraticode@1.14.0 dist.integrity read 2026-09-25; the tarball was downloaded to a scratch directory and independently sha256- and sha512-hashed, both matching, and the sha256 also matches adoption/pins-macos-arm64.json's existing socraticode pin exactly",
"install_note": "2026-09-25 addition to complete the `token-efficiency` profile's Linux pin coverage: mirrors adoption/pins-macos-arm64.json's existing `socraticode` entry (same version, url, sha256 and `--ignore-scripts`). AGPL-3.0-only; upstream commercial alternative. `npm install --global --prefix tools/socraticode-1.14.0 --ignore-scripts socraticode@1.14.0`, exactly recipes/README.md's documented recipe, which this pin now also drives through the bootstrap script instead of only a manual install. `--ignore-scripts` (this pin's own `ignore_scripts: true` field, read by `install_npm`) skips native postinstall/build steps. Only a reviewed archive hash, not a claim of a working native codebase-index handshake on this host.",
"checksum_ref": "npm view socraticode@1.15.0 dist.integrity (sha512-vfz1G5NDepksPjZNnr/rVU5tTK91ghO/izGQQXMaZhP7Py+1hP1k+ptL/ZsYCMhB5NLj5K0XGmcNmygbE1rIWQ==) and dist.shasum read 2026-09-27; the tarball was downloaded to a scratch directory and independently sha256-, sha512- and sha1-hashed, all matching (evidence/receipts/socraticode-1150-qualification-20260927.json). adoption/pins-macos-arm64.json keeps 1.14.0 until a Mac qualifies 1.15.0",
"install_note": "Moved from 1.14.0 on 2026-09-27 (docs/decisions/2026-09-25-workstation-sota-refresh.md, the cutover update; evidence/receipts/socraticode-1150-qualification-20260927.json). AGPL-3.0-only; upstream commercial alternative. recipes/README.md's recipe is `npm install --global --prefix tools/socraticode-1.15.0 --ignore-scripts --before=2026-09-24T12:00:00Z socraticode@1.15.0`: `--before` reproduces the qualified dependency tree, because the package ships no shrinkwrap and later releases inside its dependency ranges (undici 6.29.0, @lumis-sh/wasm-eex 0.26.2) resolve without it. The bootstrap's `install_npm` installs this pin's verified tarball with `--ignore-scripts` (this pin's own `ignore_scripts: true` field) but passes no `--before`, so its dependency tree can differ from the qualified one. Only a reviewed archive hash, not a claim of a working native codebase-index handshake on a new host.",
"version_probe": {
"method": "npm-metadata",
"note": "No argument parsing at all: every invocation, --help and --version included, starts its MCP stdio server (dist/index.js never reads process.argv; observed 2026-09-25 with socraticode 1.14.0, matching the macOS pin's own note), so the package version is read from npm metadata instead. Never run `socraticode --version` or with no arguments on a real install -- it starts the server."
"note": "No argument parsing at all: every invocation, --help and --version included, starts its MCP stdio server (dist/index.js never reads process.argv; observed 2026-09-25 with socraticode 1.14.0, matching the macOS pin's own note, and 1.15.0's dist/index.js still reads none), so the package version is read from npm metadata instead. Never run `socraticode --version` or with no arguments on a real install -- it starts the server."
}
}
]
Expand Down
Loading
Loading