Skip to content

OmniRoute Mac gateway: LE-18 read-only checks and version 2 of the update check - #638

Closed
seathatflowsinourveins wants to merge 4 commits into
mainfrom
claude/omniroute-mac-le18-20261003
Closed

seathatflowsinourveins wants to merge 4 commits into
mainfrom
claude/omniroute-mac-le18-20261003

Conversation

@seathatflowsinourveins

@seathatflowsinourveins seathatflowsinourveins commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Scope

Results

  • Running build. The listener on port 20128 started at the switch of Rebuild the Mac's OmniRoute gateway with GPT-6.1 Sol and follow the installed Codex version #599 (2026-10-02T03:44:48Z) from this build.

    • The installed dist/BUILD_SHA is 6f246e84a.
    • The retained tarball hashes to the build manifest's d602dc42….
  • The process title omniroute (v16.3.5) names the bundled Next.js 16.3.5, not OmniRoute's version. Next's start-server sets next-server (v16.3.5), and OmniRoute's startup instrumentation renames it.

  • Effort read-back: not possible through the gateway's APIs.

    • One GPT-6.1 Sol call at body effort max answered 200.
    • The call-log APIs record each call's time, model, provider, account, token counts and reasoning source, but no effort field.
    • The database, which holds credentials, stays unopened, so the recorded limit stands.
  • Update check, version 2. It still installs nothing. It adds a notification for:

    • a carried upstream PR closed without a merge, once per closure;
    • a new official release, with a read-only scan of its npm package for the two capabilities this build carries. The scan checks structure: the GPT-6.1 Sol model object in the server bundle, and the /api/v1/alpha/search/route manifest entry with its route file. Its result is a notice, never a switch gate.
  • Review round. The automated review's eight findings are answered in 021695e2 and all eight threads are resolved:

    • the structural scan;
    • bounded decompressed reads;
    • repeat-suppressing state written only after delivery;
    • a failed package read stays pending, and a failed PR lookup keeps the PR's previous record;
    • the capability result is kept between runs;
    • the retained tests, and a completeness-critic record.

    The revised script was redeployed at 10:02Z (sha256 dd79843c…).

SOTA sources

Evidence-class table

Claim Evidence class Command / receipt
Running build is BUILD_SHA 6f246e84a from tarball d602dc42… local_integration le18-20261003.json → read_only_checks.fingerprint
Process title names Next.js 16.3.5 source_review the installed package's start-server and instrumentation chunk
The call-log APIs carry no effort field local_integration le18-20261003.json → read_only_checks.effort_read_back
Version 2's structural scan, delivery and retry state, read bounds local_integration, synthetic checks/update-check-v2/: 16-case suite (all passed), red check against the first deployment, controls (own package: both; v3.8.51: neither), dry run, first real run

Local commands run

$ /usr/bin/python3 <scratch copy>/omniroute-update-check.py --scan-file <this build's tarball>   -> sol_catalog true, alpha_search_route true
$ /usr/bin/python3 <scratch copy>/omniroute-update-check.py --capability v3.8.51                 -> both false
$ OMNIROUTE_UPDATE_CHECK_DRY=1 XDG_STATE_HOME=<scratch> /usr/bin/python3 <scratch copy>/omniroute-update-check.py   -> new release v3.8.51 reported, one logged notification, would-restart logged   exit 0
$ /usr/bin/python3 stub_test.py   -> stub tests passed
$ /usr/bin/python3 <prefix>/omniroute-update-check.py   (first real run of version 2, 05:38Z)   -> codex_follow unchanged; no new release; no notification   exit 0
$ python3 scripts/validate.py   -> {"components": 69, "hashed_files": 9411, "profiles": 4, "receipts": 187, "status": "passed"}   exit 0

Host evidence

Not applicable: no file under evidence/hosts/ changes.

Checklist

  • New/changed GitHub Actions are pinned to a full commit SHA with a
    version comment (no floating tags). (No workflow changes.)
  • New/changed workflows declare top-level permissions: contents: read
    (or a narrower, explicitly justified addition). (No workflow changes.)
  • No secrets are printed, logged or committed; no new required secret was
    added without a documented owner.
  • No new paid hosting, subscription or billing surface was introduced.
  • Peer-owned untracked files and worktrees were preserved (not deleted,
    moved or overwritten).

🤖 Generated with Claude Code

@seathatflowsinourveins seathatflowsinourveins added the lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers label Oct 3, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-03T05:50:43.543060Z aec1c5d PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: aec1c5d779

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread evidence/artifacts/omniroute-mac-rebuild-20261002/le18-20261003.json Outdated
Comment thread evidence/artifacts/omniroute-mac-rebuild-20261002/le18-20261003.json Outdated
@seathatflowsinourveins
seathatflowsinourveins force-pushed the claude/omniroute-mac-le18-20261003 branch from aec1c5d to 237c40e Compare October 3, 2026 08:32
seathatflowsinourveins added a commit that referenced this pull request Oct 3, 2026
…can, bounded reads, delivery-based state, retained tests, completeness critic)

The automated review of #638 found eight defects. The capability scan now checks structure (the Sol model object in
the server bundle; the alpha search route in the server's app-paths manifest with its route file) and is a notice,
never a switch gate. Reads are bounded per package, per file and in total. Repeat-suppressing state is written only
after a notification is delivered, a failed package read stays pending, a failed PR lookup keeps the PR's record,
and the capability result is kept. The 16-case suite, its red check against the first deployment, both capability
controls, the dry run and the first real run are retained; the receipt records a completeness critic.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
seathatflowsinourveins added a commit that referenced this pull request Oct 3, 2026
…can, bounded reads, delivery-based state, retained tests, completeness critic)

The automated review of #638 found eight defects. The capability scan now checks structure (the Sol model object in
the server bundle; the alpha search route in the server's app-paths manifest with its route file) and is a notice,
never a switch gate. Reads are bounded per package, per file and in total. Repeat-suppressing state is written only
after a notification is delivered, a failed package read stays pending, a failed PR lookup keeps the PR's record,
and the capability result is kept. The 16-case suite, its red check against the first deployment, both capability
controls, the dry run and the first real run are retained; the receipt records a completeness critic.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@seathatflowsinourveins
seathatflowsinourveins force-pushed the claude/omniroute-mac-le18-20261003 branch from de27a20 to 8a1a983 Compare October 3, 2026 11:04
seathatflowsinourveins and others added 4 commits October 3, 2026 10:51
…date check

Answers the first two items of issue 624's LE-18 (Mac OmniRoute service owner): the running build's fingerprint
(BUILD_SHA 6f246e84a, tarball sha256 d602dc42...), the process title (the bundled Next.js 16.3.5), the update-check
state, and the effort read-back, which the gateway's call-log APIs cannot give (no effort field; the database stays
unopened). Version 2 of the update check notifies when a carried PR closes unmerged or a new release appears, with a
read-only capability scan of the release package (Sol catalog entry, /v1/alpha/search). Deployed with version 1
kept as the rollback; positive and negative controls, a dry run and stubbed paths recorded.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…can, bounded reads, delivery-based state, retained tests, completeness critic)

The automated review of #638 found eight defects. The capability scan now checks structure (the Sol model object in
the server bundle; the alpha search route in the server's app-paths manifest with its route file) and is a notice,
never a switch gate. Reads are bounded per package, per file and in total. Repeat-suppressing state is written only
after a notification is delivered, a failed package read stays pending, a failed PR lookup keeps the PR's record,
and the capability result is kept. The 16-case suite, its red check against the first deployment, both capability
controls, the dry run and the first real run are retained; the receipt records a completeness critic.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@seathatflowsinourveins
seathatflowsinourveins force-pushed the claude/omniroute-mac-le18-20261003 branch from 8a1a983 to b020127 Compare October 3, 2026 14:51
@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Closed with a record by the PR triage of 2026-10-07 (the command center's ruling, item review-ns2604-coop-20261007T023012Z (the command center's PR-triage ruling of 2026-10-07; proposal by github-ci-finalize, triage-20261007.json)). Not merged; the branch claude/omniroute-mac-le18-20261003 stays on origin at b020127.

What it holds: docs/decisions/2026-10-02-omniroute-mac-rebuild.md (LE-18 and update-check v2 sections); evidence/artifacts/omniroute-mac-rebuild-20261002/le18-20261003.json; evidence/artifacts/omniroute-mac-rebuild-20261002/checks/ (8 new files, update-check v2 tests); scripts/ (1 new), README.md (modified)

Superseded by: not superseded; unprioritized under the 2026-10-07 PR triage (confidence: medium: LE-18's third item landed separately in e70afbb (#637; manifests/stack.json:1900 is 3.8.51); the user's 2026-10-05 decision treats the Mac as portable or remote-control only (docs/decisions/2026-10-05-macos-ci-advisory.md:10); nothing on main replaces the Mac update-check v2 or LE-18 items 1-2, and issue #624 is open)

Reopen trigger: The Mac returns to serving an OmniRoute gateway beyond portable or remote-control use, or LE-18 items 1-2 of issue #624 are raised again for the Mac service owner. Reopen with gh pr reopen 638.

@seathatflowsinourveins
seathatflowsinourveins deleted the claude/omniroute-mac-le18-20261003 branch October 8, 2026 17:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant