Skip to content

Codex dated holds (R6): a host-agnostic 0.159.3 hold on the Linux pin row, held status, TUI notice key - #687

Merged
seathatflowsinourveins merged 12 commits into
mainfrom
foundation/codex-dated-holds-20261004
Oct 4, 2026
Merged

seathatflowsinourveins merged 12 commits into
mainfrom
foundation/codex-dated-holds-20261004

Conversation

@seathatflowsinourveins

Copy link
Copy Markdown
Owner

Draft. The inventory recount waits for #674, which is re-pinning docs/decisions/2026-10-02-new-wsl-client-configuration.md. The coordinator (CC) re-ACKs before this PR leaves draft. Until then, tests.test_new_wsl_client_config fails on exactly the two record assertions listed below, and on nothing else.

Scope

  • What this PR changes, in one or two sentences: it implements R6, "per-host Codex pins", as a host-agnostic dated hold on the single Linux codex pin row.
    • holds[] holds 0.159.3 until 2026-11-04 (X18, the Codex 0.159.3 -> 0.160.0 with the Python SDK pair: pins, qualification receipt, tests and checkpoint #626 landing exception).
    • scripts/adoption_status.py --pinned-versions reports a host on that version as held, not drift, until that date. From that date on it reports drift and states the expiry.
    • tools/adoption/apply_codex_lane.py still refuses such a host, and its refusal now names the hold.
    • The PR also adds an expiry and schema test, the Codex TUI notice key "gpt-6.1-sol" = 4, and a decision record.
  • Base commit: 6af8e55bd (origin/main at push). The branch was cut at 33efbc3b6 and rebased onto 6af8e55bd by docs/lanes.md's hot-file protocol, because CI least privilege: permissions {} by default, cache-mode none on pull requests, workflow policy tripwire #681 changed manifests/evidence.json.
  • Lane: lane:foundation
  • Owned paths touched:
    • adoption/pins-linux-x86_64.json
    • adoption/templates/codex.config.template.toml
    • scripts/adoption_status.py
    • tools/adoption/apply_codex_lane.py
    • tests/test_adoption_status.py
    • tests/test_codex_worker_lane.py
    • tests/test_pin_holds.py (new)
    • docs/decisions/2026-10-04-codex-dated-holds.md (new)
    • hot files, in the last commit only: manifests/stack.json (a reference to the hold, since that row carries no install data) and manifests/evidence.json (main's copy, re-registered)

SOTA sources

Evidence-class table

Claim Evidence class Command / receipt
The hold's wrapper URL and SHA-256 equal the codex row before f77a35eb2 (introduced by 85543efe5, #580). The 4,904-byte registry tarball matches them (SHA-256 31d5e584…), and its SHA-512 and SHA-1 equal the registry's dist.integrity and dist.shasum. local_integration git show f77a35eb2^:adoption/pins-linux-x86_64.json; registry download; sha256sum, openssl dgst -sha512, sha1sum
The hold's platform_dependency (@openai/codex@0.159.3-linux-x64, 162,464,331 bytes) is first recorded here, since no earlier record exists. SHA-512 and SHA-1 equal the registry's. SHA-256 is 0719027c… and the archive's executable SHA-256 is 8bf204b3…. No held host's installed executable was compared. local_integration registry download and extraction
"gpt-6.1-sol" = 4 under [tui.model_availability_nux] stops Codex's availability notice for that slug. source_review the rust-v0.160.0 lines above
A host still on 0.159.3 now prints codex: 0.159.3 held until 2026-11-04 (X18: …), and codex leaves mismatched for held. The base revision's script on the same pins file lists codex as mismatched. local_integration python3 scripts/adoption_status.py --pinned-versions on one held host, 2026-10-04
Before until, a hold is held. On and after until, it is drift and the expiry is stated. Any other version, a failing probe or a malformed hold is drift. synthetic tests.test_adoption_status.DatedHoldTests (9 tests)
Every hold is complete and unexpired, at most 90 days away, at most one per row, and never the pin itself. synthetic (structural plus mutants) tests.test_pin_holds
The lane still refuses a held codex, and its refusal names the hold and its until date. synthetic tests.test_codex_worker_lane ApplyFlowTests (fake codex)
The new tests detect the behaviour, not just pass. Six in-process mutations each fail them: no hold matching, < for <=, held not excluded, no well-formedness filter, and the live hold on its until date (two checks). synthetic in-process mock.patch controls

Local commands run

$ TMPDIR=<scratch> nice -n 19 python3 -m unittest tests.test_pin_holds            -> exit 0 (6 tests OK)
$ TMPDIR=<scratch> nice -n 19 python3 -m unittest tests.test_adoption_status      -> exit 0 (137 OK)
$ TMPDIR=<scratch> nice -n 19 python3 -m unittest tests.test_codex_worker_lane    -> exit 0 (108 OK, 10 skipped: opt-in real-codex integration tests)
$ TMPDIR=<scratch> nice -n 19 python3 -m unittest tests.test_osv_lockfile_coverage -> exit 0 (57 OK)
$ TMPDIR=<scratch> nice -n 19 python3 -m unittest tests.test_render_config        -> exit 0 (36 OK)
$ TMPDIR=<scratch> nice -n 19 python3 -m unittest tests.test_new_wsl_client_config -> exit 1 (159 run, 2 expected failures, below)
$ python3 scripts/adoption_status.py                    -> exit 0 (default run execs no probe; unchanged)
$ python3 scripts/adoption_status.py --pinned-versions  -> exit 0
    pinned versions: 2 matched, mismatched: rtk, ai-memory, mcporter, held: codex, unchecked: context-mode
      codex: 0.159.3 held until 2026-11-04 (X18: hosts not yet switched stay on 0.159.3 until retired (#626 landing exception))
$ python3 scripts/validate.py                           -> exit 0 ("hashed_files": 9880, "status": "passed")
$ python3 scripts/evidence_manifest.py --check          -> exit 0
$ python3 scripts/validate_convergence.py --all-recorded -> exit 0
$ git diff --check origin/main...HEAD                   -> exit 0

The rtk, ai-memory and mcporter mismatches are that host's own drift, unchanged by this PR.

Expected failures in tests.test_new_wsl_client_config (both come from docs/decisions/2026-10-02-new-wsl-client-configuration.md, which this PR does not edit):

  • RecordTests.test_the_counts_that_the_record_states_are_the_ones_check_prints: Tuples differ: (385, 293, 200, 93, 80, 41, 39, 12) != (386, 293, 200, 93, 81, 41, 40, 12).
  • RecordTests.test_the_record_holds_the_tables_the_tool_prints: the record's not-wired table lacks the one new row | `codex/config/tui.model_availability_nux."gpt-6.1-sol"` | `not_wired` | … |, which follows the gpt-6-astra row.

The measured new counts are 386 pieces, 293 wired (200 practice, 93 through a slot), 81 not wired (41 through a slot that does not install, 40 by their own entry), 12 authorization. new_wsl_client_config.py --check itself passes, because the map's existing tui.model_availability_nux* entry covers the piece. The recount after #674 changes three places in that record: the "Today:" counts, Decision 14's "80 pieces are not wired" (to 81), and the new table row.

Full suite (python3 -m unittest, before the rebase and registration): 10,278 tests, 4 failures.

  • The two failures above are expected.
  • test_catalog_freshness_propose…test_general_publication_validator_passes_after_the_run failed only because the registry was not yet updated. After the last commit it exits 0.
  • test_windows_terminal_defaults…test_the_installed_client_knows_no_notification_type_without_a_decision scans the installed Claude Code binary on that host. That binary knows an auth_storage_failure type the test's own table lacks. The failure is pre-existing and unrelated: neither that table nor the overlay is touched here, and CI skips the test.

Decision record

docs/decisions/2026-10-04-codex-dated-holds.md. It covers the design and these alternatives:

  • per-host pin rows, which would put host names in the portable repository;
  • no repository record, which leaves status red with no recorded reason;
  • moving the pin back.

It cites the in-repo precedent (.github/osv-scanner.toml ignoreUntil plus reason, and .grype.yaml "Re-review by"). Its overturn condition is that the held hosts retire or switch, and the hold is then deleted, or that a second concurrent hold is needed, and per-host rows are revisited. The test fails on a second hold and names the record.

Host evidence

Not applicable: no file under evidence/hosts/ changes.

Checklist

  • New/changed GitHub Actions are pinned to a full commit SHA with a version comment (none changed).
  • New/changed workflows declare top-level permissions: contents: read (none changed).
  • No secrets are printed, logged or committed; no new required secret was added.
  • No new paid hosting, subscription or billing surface was introduced.
  • Peer-owned untracked files and worktrees were preserved.

🤖 Generated with Claude Code

Scout and others added 2 commits October 4, 2026 06:42
… until 2026-11-04

- adoption/pins-linux-x86_64.json: the codex row carries holds[] with one entry, 0.159.3 until
  2026-11-04 (X18, the #626 landing exception). Wrapper URL and SHA-256 are the row's values before
  f77a35e (from 85543ef, #580), re-verified against a registry download; the linux-x64
  platform_dependency (row shape) is first recorded here from the npm registry.
- scripts/adoption_status.py --pinned-versions: a probe naming a hold's version before its until date
  (UTC) is held (hold_* fields, summary "held", "held until <date> (<reason>)"), not drift; on and
  after until it is mismatched with the expiry stated. Malformed holds are skipped. The default run,
  the exit code and the existing keys are unchanged.
- tools/adoption/apply_codex_lane.py still refuses any codex but CODEX_VERSION; the refusal now names
  a matching hold and its until date.
- tests/test_pin_holds.py: every hold complete, until a real date after today (UTC) and at most
  90 days away, at most one hold per row (the OSV ignoreUntil precedent), with mutants.
- adoption/templates/codex.config.template.toml: "gpt-6.1-sol" = 4 under [tui.model_availability_nux],
  cited from openai/codex rust-v0.160.0 (MODEL_AVAILABILITY_NUX_MAX_SHOW_COUNT = 4).
- docs/decisions/2026-10-04-codex-dated-holds.md: design, alternatives, precedent, overturn.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…le protocol, last commit)

manifests/stack.json's codex row carries no install data, so its freshness refers to the pins row's
dated hold instead of copying it. manifests/evidence.json takes main's copy (6af8e55) and
re-registers this branch's changed files plus its new test and decision record, as #626 did;
component_matrix.py and new_host_grand_list.py --write reproduced their outputs unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@seathatflowsinourveins seathatflowsinourveins added the lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers label Oct 4, 2026
Scout and others added 10 commits October 4, 2026 11:45
…ds branch (hot-file protocol: main's registry; PR rows re-registered last)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…y (387 pieces, 80 not wired, 39 own entry)

The key under tui.model_availability_nux is one more not-wired piece (client state, not
configuration). Recounted on the tree merged with main 54eb892 (#674, #683, #686) by the GPT-6.1 Sol
worker; reviewed by the coordinator.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…egistry plus the owned rows)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…fore the final hot-file commit

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… (hot-file protocol: every hot-file edit in the last commit)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…s-family P1)

pin_holds() now keeps only holds that hold_schema_problems() accepts. The same validator is imported by
tests/test_pin_holds.py. It requires the wrapper url and sha256, and the platform package's shape, version,
url, digest and binary check when the pin has one. So a hold with malformed install metadata is ignored,
and the version is reported as drift instead of held. Failing-first: the three missing-field cases failed
before the fix; 16 malformed-metadata cases pass after it.

Built by the GPT-6.1 Sol worker; reviewed by the coordinator (Claude Opus).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… to the merge base before the final hot-file commit

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…its on the merge base (hot-file protocol: every hot-file edit in the last commit)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@seathatflowsinourveins
seathatflowsinourveins marked this pull request as ready for review October 4, 2026 16:33
@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Claude session native-agent-stack-5f: landing at head c2aa04fcdeb3fd832781154e613224e335aeae2e. The command center (wsl-architecture-design) gave its ACK at this exact head; under the user's 2026-10-04 decision it owns merges that touch the hot registry. The read-only cross-family review (GPT-6.1 Sol max, the packaged Codex SDK worker) returned FINDINGS at 84245a3e59ec; this head is reached from it through recorded carry edges (equal owned patch-ids, or a cross-family delta read returning ACCEPT at the edge's target), with its 1 P1 item(s) resolved in one repair round as recorded.

Observed main 8c32a84b246da66e43a6188c973741b09329e223. coordination/merge_tree_landing_check.py (sha256 a11649fcf2e5844c…) exit 0:

main 8c32a84b246da66e43a6188c973741b09329e223 head c2aa04fcdeb3fd832781154e613224e335aeae2e base 8c32a84b246da66e43a6188c973741b09329e223 merged-tree aa4a746ec4a35c65549ebbab912ebdaf6aabf6ed merge-tree-exit 0
ok   1: clean three-way merge
ok   2: merged-vs-main paths 11, outside PR-owned 0 []
ok   3: main drift 0 paths, overlap with PR-owned inputs (registry excluded) []
ok   4: registry foreign rows equal True, order preserved True, PR-owned rows 10, unowned top-level keys differing []
ok   5: merged files[] sorted by path with no duplicates: True (9885 rows)
LANDABLE
condition 5: merged files[] sorted and unique (tree aa4a746ec4a35c65549ebbab912ebdaf6aabf6ed)

Required checks at this head: 8 pass . Unresolved review threads: 0.

@seathatflowsinourveins
seathatflowsinourveins merged commit df50444 into main Oct 4, 2026
26 checks passed
@seathatflowsinourveins
seathatflowsinourveins deleted the foundation/codex-dated-holds-20261004 branch October 4, 2026 17:11
@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Claude session native-agent-stack-5f: post-merge observation. Landed as df50444a4d58168c35829f3c6b1a663af9500783 (parent 8c32a84b246da66e43a6188c973741b09329e223), tree aa4a746ec4a35c65549ebbab912ebdaf6aabf6ed. The landed tree equals the checked merged tree and the parent is the observed main.

seathatflowsinourveins pushed a commit that referenced this pull request Oct 4, 2026
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
seathatflowsinourveins pushed a commit that referenced this pull request Oct 4, 2026
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
seathatflowsinourveins pushed a commit that referenced this pull request Oct 4, 2026
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
seathatflowsinourveins pushed a commit that referenced this pull request Oct 4, 2026
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
seathatflowsinourveins added a commit that referenced this pull request Oct 5, 2026
…04 directive (#684)

* New WSL builder: wire the token layer by default on the owner's 2026-10-04 directive

NativeStack2604's client configuration now carries the token layer:
- rtk: RTK_TELEMETRY_DISABLED (Claude env, Codex shell set tables), the
  PreToolUse Bash hook `rtk hook claude`, the six rtk force-push deny rules,
  and the Codex instruction block's RTK section (rtk-ai/rtk v0.50.0
  hooks/rtk-awareness-full.md, verbatim).
- the SubagentStart token-lane carrier (hook and six blocks, byte-pinned).
- the Claude Code session-start currency notice.
- CLAUDE_CODE_EXPERIMENTAL_AGENT_TEAMS=1 (code.claude.com agent-teams).

The builder gains a `directive` field for slot entries: the dated record
of the owner's directive adds the entry's owner beside what the slot
installs, only while the slot installs anything; --check fails when the
record is not a file. rtk's MCP-server env copies follow their server.
docs/decisions/2026-10-04-new-wsl-token-layer-default.md quotes the
directive, supersedes the 2026-10-02 not-wired rulings for these pieces,
claims no saving, and names the F-token arm as what decides it. The
2026-10-02 record's counts sentence and tables are recounted
(386 pieces, 315 wired, 59 not wired, 12 authorization).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* 2026-10-02 client-configuration record: addendum pointing to the 2026-10-04 token-layer record

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Main-session token-lane carrier: SessionStart hook, block, template group and installer entries

The SubagentStart carrier reaches subagents only. This adds its main-session counterpart:

- adoption/hooks/claude/token-lanes-session-start.py, modeled line for line on
  token-lanes-subagent-start.py (stdlib, fail-open, unbuffered write, exit 0), returns its sibling
  token-lanes-block.main.md as SessionStart additionalContext; blind-* and the subagent carrier's
  silent roles get nothing.
- token-lanes-block.main.md (1,842 bytes, budget 2,600): choose the lane first, Read only to Edit or
  for small verbatim files, ctx_execute_file/ctx_execute with intent then ctx_search, qmd for
  catalog docs, ctx_batch_execute for large output, RTK scope, delegation, code and memory lanes if
  exposed, one lane per artifact, savings only from client counters. It adds the ToolSearch line that
  context-mode 1.0.169 gives only Agent-tool prompts (sessionstart.mjs L49, routing.mjs L892-907 at
  589d8214).
- claude.settings.template.json: one SessionStart group after the currency notice, matcher
  startup|resume|clear|compact|fork (every source code.claude.com/docs/en/hooks documents; fork is
  separate since v2.1.214 and re-runs SessionStart hooks), timeout 5.
- install_claude_profile.py HOOKS and SHA256SUMS list both files; tests cover the hook contract,
  the text, the registration and the installed command; handbook section and decision addendum.

Advisory only: context-mode's Read/Grep PreToolUse guidance stays advisory (routing.mjs L843-872)
and RTK's hook covers Bash only (README v0.50.0 L153, L368).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* New-WSL builder map: wire the main-session carrier pieces, recompute the record's counts and tables

The SessionStart carrier of unit U1 added three pieces that the map did not know, so
`new_wsl_client_config.py --check` exited 1 with three unmapped pieces. They join the token-lane carrier entry
(same wiring and owner directive as the SubagentStart carrier): the SessionStart hook, its main-session block and
its script. The counts and tables of the 2026-10-02 record are recomputed from `--check` on this tree (389 pieces,
318 wired, 58 not wired, 13 authorization), adoption/bootstrap.md names the SessionStart carrier in both carrier
paragraphs, and two builder-test expectations follow the one additional wired hook command (5 to 6 commands, and
token-lanes-session-start.py in the set of hook files the repository copies with its checksum).

Checks at this commit: new_wsl_client_config.py --check exit 0; unittest tests.test_new_wsl_client_config
tests.test_install_claude_profile tests.test_render_config tests.test_token_lanes_session_start
tests.test_token_lanes_subagent_start tests.test_adoption_docs_consistency tests.test_wsl_new_distro_recipe
tests.test_new_wsl_definitive_defaults: 540 tests OK (5 skipped). Local integration checks, not upstream tests.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* New-WSL wave 3: the owner's token-efficiency decision as amendment 4 of the manifest's rule

- docs/decisions/2026-10-04-token-full-stack-owner-default.md: the owner's order
  verbatim, its authority path, the rows it overturns by file:line, the
  alternatives and the comparison that would remove each component, and the
  measured limits of #627 kept as usage rules. Net provider savings stay
  unmeasured.
- consensus.json wave3: ten owner_decision rows in token-efficiency
  (command-output, output-compression, code-index, code-graph, repo-packing,
  structured-data, doc-conversion, api-docs, trace-viewer,
  token-lane-carriers), owner defaults on context-supply (context-mode
  1.0.169, its wave-2 interim dropped), ccusage 20.0.26 and
  session-analytics (agentsview 0.43.0, local archive only), and the
  code-search interim widened to semble 0.6.1 + SocratiCode 1.15.0. Pins are
  the ones manifests/stack.json and adoption/pins-linux-x86_64.json record
  at f77a35e.
- assemble_manifest.py folds every wave batch in numeric order and checks an
  owner batch (hashed relaying record that quotes the order and names every
  slot and repository; no acknowledgement owed; replaced fields kept under
  overturned).
- render_tables.py lists the owner decisions and what each replaced, and keeps
  the blind-round basis of an overturned row; definitive-manifest.json and the
  2026-10-01 record's tables are regenerated, with a dated pointer paragraph.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit 93fec17155724f720ac06da9a267115bc21db252)
(cherry picked from commit f9da212cce86e105522bddcd071d79cd3e22b1fd)

* New-WSL install plan, wave 3: the token-efficiency owner rows, every-wave gate, tests

- install.sh / accept.sh / install-plan.json / owners.json: one install and one
  acceptance function per new owner row (command-output, output-compression,
  code-index, code-graph, repo-packing, structured-data, doc-conversion,
  api-docs, trace-viewer, token-lane-carriers), ccusage and session-analytics
  installed as owner defaults, code-search adds SocratiCode 1.15.0 beside
  semble; the --list rows, the --only lists and the slot loops follow. Every
  tool goes under ${ECO_ROOT:-$HOME/.local/share/codex-ecosystem}, the root
  the client templates run; archives and npm tarballs through fetch_verified
  against the recorded sha256 (no gh sign-in). Pins are the ones
  manifests/stack.json and adoption/pins-linux-x86_64.json record at f77a35e.
- interim_acknowledged reads every wave batch (refusing a misspelt wave key);
  context-supply, now an owner default, no longer calls it; check_plan.py
  refuses a gate call on a row without an interim.
- tests/test_new_wsl_definitive_defaults.py: invariants extended to the owner
  batch (rows, owner defaults, overturned fields, counts, rule text, tables),
  31 negative controls for the assembler's owner-batch checks, gate cases for
  later batches.
- README, SOURCES and VALIDATION: the Wave 3 sections. Nothing was installed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit 25b002046be9939b8506ee9778c588b4181dd627)
(cherry picked from commit 7440aeacacec7f570135a400bd2845601f7d27b7)

* New-WSL profile and handbook, wave 3: the token-efficiency owner defaults

- adoption/new-wsl-profile.json: RTK picked with default_install true and the
  release-asset install (docs/token-efficiency-stack.json) instead of the
  UNRUN cargo build; Headroom picked with the [mcp] extra, not [all]; ccusage's
  install command and documented acceptance filled; SocratiCode's install
  command filled, and it stays a comparison arm of the split code-search slot
  (validate_default_installs refuses a default install for it); new rows for
  context-mode, jcodemunch-mcp, codebase-memory-mcp, Repomix, TOON,
  MarkItDown, Context Hub, otel-tui and agentsview. boundary.default_profile
  names the token rows; install_dispatch is unchanged. Validated by
  scripts/new_wsl_profile.py.
- scripts/build_new_wsl_handbook.py: reads every wave batch, the row kind
  owner_decision and owner defaults (overturned.fields), counts interims for
  any wave batch, renders a multi-repository interim without a broken link
  and lists what each owner decision replaced. Outputs regenerated; the
  handbook receipt's frozen hashes follow them.
- catalogs/foundation/new-wsl-architecture-20261001.json: a superseded-by
  pointer in the token-efficiency row's notes (the edition has no
  context-supply row and admits no new row field); the dated text stays.
- Tests: profile owner defaults and arms; handbook owner rows, owner
  amendments and six negative controls; counts 100/10.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit 85735c7163888c23c8a513e4cd26d738349589a7)
(cherry picked from commit 800ae92c8fb9f1a1337a0ad7929bf0a6e699c875)

* New-WSL builder map: wire the owner-default token tools through their wave-3 slots

Wave 3 (the previous three commits) makes the token-efficiency tools owner defaults of new slots, so the builder's map
moves their pieces to those slots and wires the two tools it had left out. Twenty-four pieces change: RTK's environment
variable, PreToolUse Bash hook and deny rules (9) go from slot context-supply to command-output; Headroom's MCP server and
its approval slot (8) go to output-compression, MCP only, never the proxy mode; codebase-memory (3) and Context Hub's two
telemetry switches (2) leave not_wired for code-graph and api-docs; jCodeMunch gets two new pieces (a Claude user-scope
server and a Codex [mcp_servers] table) on code-index, registered as the console script the plan installs into the
ecosystem bin directory, the same registration NativeStack runs, and never through `jcodemunch-mcp init`, which writes a
prompt policy and hooks and stays the user's decision. SocratiCode keeps its code-search wiring and points at the pinned
1.15.0 build the plan installs. The 23 pieces that stay unwired are the Codex hook-trust hashes, the Codex role carriers,
the rescue plugin and its marketplace, the cache-heal hook and four settings of other owners.

The generated instruction blocks keep the sentences that name tools which are now installed; 41 test expectations move by
exactly that consequence (162 tests before and after, none deleted, every negative control kept: Promptfoo replaces the
now-installed Headroom as the unwired tool in the name-injection fixtures, and the split-slot test still flips SocratiCode
off when the slot's owner is changed to semble). The record's counts, tables and dropped-units list are recomputed from
`--check` on this tree (391 pieces, 355 wired, 23 not wired, 13 authorization).

Checks at this commit: new_wsl_client_config.py --check exit 0; unittest tests.test_new_wsl_client_config
tests.test_install_claude_profile tests.test_render_config tests.test_token_lanes_session_start
tests.test_token_lanes_subagent_start tests.test_adoption_docs_consistency tests.test_wsl_new_distro_recipe
tests.test_new_wsl_definitive_defaults tests.test_new_wsl_handbook tests.test_new_wsl_profile: 638 tests OK (5 skipped);
check_plan.py OK; build_new_wsl_handbook.py --check OK. Local integration checks, not upstream tests. Map and test edits
were drafted by a GPT-6.1 Sol/max worker through the packaged OmniRoute SDK worker and reviewed edit by edit here.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* New-WSL client-configuration record: recount on main 8c32a84 after #674 (392 pieces, 356 wired, 23 not wired, 13 authorization)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* New-WSL default: hold the token-lane carriers out of the clean install

The two carrier hook entries and the nine files install_claude_profile.py copies are this repository's own adaptation,
not a feature of an upstream tool. The owner's directive of 2026-10-04 (a clean install: upstream installers with
upstream default configuration), relayed by the command center, holds them out of the new distribution's default: the
map entry goes from practice to not_wired, so the rendered settings run no carrier file and --apply copies none.
Counts: 392 pieces, 345 wired, 34 not wired, 13 authorization (was 356 / 23). Shared template and carrier files are
unchanged, so other hosts keep what they render. New decision record, one new test, five expectations moved.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* New-WSL token layer: persist RTK and Context Hub configuration, register jCodeMunch per project, restore the directive-branch test

The four findings of the independent read of #684 (0 P1, 3 P2, 1 P3), each from an upstream-documented field:

- F1 jCodeMunch is registered per project, never at user scope (docs/token-session-handbook.md, adoption/bootstrap.md
  "jCodeMunch, per project"): the user-scope Claude and Codex additions and their map entry are gone; the code-index
  row still installs the console script. Four project agents name its tools, which the record's gap table now lists.
- F2 RTK [hooks] exclude_commands (the recipe's five entries) is written by command-output() to
  ${XDG_CONFIG_HOME:-~/.config}/rtk/config.toml, an existing file kept; the acceptance is version-neutral ($e/bin/rtk
  hook check, no version string for the new lines).
- F3 Context Hub telemetry:false and feedback:false are written by api-docs() to ${CHUB_DIR:-~/.chub}/config.yaml, an
  existing file kept; the acceptance asks upstream's own isTelemetryEnabled()/isFeedbackEnabled() with CHUB_* unset.
- F4 the directive branch has a positive test again (a slot that installs a different owner keeps the entry's
  directive; without the directive the piece is not wired); three PlanConfigurationTests run the two writes and
  check_plan.py in scratch homes.

Counts: 390 pieces, 343 wired, 34 not wired, 13 authorization (with the carrier hold-out of the commit before).
Native demonstration on rtk 0.51.0 and Context Hub 0.1.4 (scratch config dirs): the four excluded commands rewrite
before the config (rc 0) and exit 1 "No rewrite for" after it, git status rewrites in both; Context Hub reports
telemetry=true feedback=true without config.yaml and false/false with it, acceptance exit 0.
The repair worker (Sol max) stopped at its deadline with the work unverified; the verification is the coordinator's.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* New-WSL client-configuration record: recount on main df50444 after #687

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Agentsview pin registry: classify the wave-3 profile and its generated handbook as dated records

The macOS gate of PR 684 failed two tests of tests/test_agentsview_qualification.py (the same two fail on Linux): the
new-WSL profile and its generated handbook (json and md) name agentsview 0.43.0 since the owner's decision of
2026-10-04 and neither registry list classified them. They are built from the definitive manifest and the install plan,
not from manifests/stack.json, so a stack re-pin does not edit them: dated_record entries with basis 2026-10-04, in
the registry's path order. 12 tests of the module pass. The registry file's hash is to be re-registered in
manifests/evidence.json by the series' registry commit.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* New-WSL builder: turn on the You-should-know mod and the ConfigChange audit hook on NativeStack2604

The owner's order of 2026-10-04 asks for every latest changelog feature fully enabled in the native workflow of the new
WSL too. Two switches that NativeStack's own user settings already carry reach NativeStack2604 through the builder's
2604-only additions file, each with a `practice` map entry that cites its source. Neither is a token-layer adaptation:
the mod is a built-in Claude Code feature and the audit hook is zero-token host practice, so the clean-default
hold-out (the token-lane carriers only) does not touch them.

- enabledPlugins["cc-plugin-you-should-know@builtin"] = true: the built-in mod added in Claude Code 2.1.287 that runs a
  side agent and shows notes above the prompt (https://code.claude.com/docs/en/plugins/mods/overview, read 2026-10-04).
  It is disabled by default, and its side agent costs tokens that are counted apart from the token-efficiency measurements.
- hooks.ConfigChange: the logging-only audit hook of https://code.claude.com/docs/en/hooks-guide ("Audit configuration
  changes"), with the literal command NativeStack runs (it appends the change's source and file to
  ~/claude-config-audit.log and ends with `|| true`, so it cannot block anything).

Three test expectations move by exactly that consequence: the enabled-plugin set gains the mod, the hook-command allowance
gains the audit command (and ConfigChange must hold exactly that one command), and the expected event list gains
ConfigChange. The record's counts and tables are recomputed from `--check`: 393 pieces, 345 wired, 35 not wired,
13 authorization (head 316abe3 plus these two pieces). The commit was first withdrawn with the carriers and is
reinstated on the command center's correction of 2026-10-04.

Checks at this commit: new_wsl_client_config.py --check exit 0; unittest tests.test_new_wsl_client_config
tests.test_install_claude_profile tests.test_render_config tests.test_token_lanes_session_start
tests.test_token_lanes_subagent_start tests.test_adoption_docs_consistency tests.test_wsl_new_distro_recipe
tests.test_new_wsl_definitive_defaults tests.test_new_wsl_handbook tests.test_new_wsl_profile: 642 tests OK (5 skipped).
Local integration checks, not upstream tests.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* New-WSL changelog parity: advisor opus, crossSessionInbound accept, Codex fast tier and analytics_plan_history; Context Hub acceptance uses the PATH node

The user's directive of 2026-10-04 ("we need all the sota features, latest changlogs, fully enalbed seamlessly within our
naitve workflow for new wsl also"), relayed by the command center, carried to NativeStack2604 after a parity diff of
NativeStack's live Claude settings and Codex config against the builder's render of the PR 684 head. Everything else
NativeStack has enabled was already rendered; docs/decisions/2026-10-04-new-wsl-changelog-parity.md lists the rest and why.

- advisorModel = "opus": the map's own override entry, the user's decision of 2026-10-04 and NativeStack's value.
- crossSessionInbound = "accept": a fifth authorization setting (AUTHORIZATION_PIECES, the map entry, the additions file),
  written only with --with-authorization-settings; overturns the wave-2 messaging ruling on the user's directive.
- Codex service_tier = "fast" (2604 additions, the map's Codex practice entry): the user's 2026-10-03 choice, NativeStack's
  value; the 0.160.0 schema calls fast the legacy spelling of priority.
- Codex features.analytics_plan_history = true in the shared template, so both hosts: experimental, one ChatGPT-backend
  request, no model call.
- accept.sh and install-plan.json run the Context Hub acceptance with the node on the prepared PATH (the delta read of
  PR 684, P2: no plan command links Node into ${ECO_ROOT}/bin); check_plan.py agrees with the script.

Counts: 396 pieces, 347 wired, 35 not wired, 14 authorization. Tests: the authorization pins now name five standalone
settings (STANDALONE), the render test pins the advisor and the two Codex values, two authorization tests handle a
single-piece entry and a seeded value. Local integration checks, not upstream tests. Registry excluded.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* New-WSL: register jCodeMunch once at user scope, for Claude Code and Codex, on the user's directive

The user, 2026-10-04, replying to the You-should-know note that new projects and worktrees start without jCodeMunch:
"we need to set up all the sota repos, mcp tools, harness rules, upstream cc native hooks and beyond, resolute them cleanly
for future session to make sure their seamless pick up and thier native workflow enhanced with the sota practice". The
command center read it as one registration for every project. This overturns, for NativeStack2604, the per-project rule of
2026-09-25 (docs/decisions/2026-09-23-claude-user-profile.md addendum, 2026-09-25-codex-mcp-scope.md decision 2, F6 of
2026-09-26-token-practice-f1-f9.md).

- Claude: user-scope `jcodemunch` (type stdio, the console script the code-index row installs) with the documented savings
  opt-out JCODEMUNCH_SHARE_SAVINGS=0 in its env block; Codex: [mcp_servers.jcodemunch] with the same env table.
  Source: jgravelle/jcodemunch-mcp 1.108.319 at 8f7b34ab, README.md L119-122 (`claude mcp add -s user jcodemunch
  jcodemunch-mcp`), CONFIGURATION.md L229-233 and SECURITY.md L311 (the opt-out). `jcodemunch-mcp init` is not run.
- Map: the code-index slot entry back (slot:code-index, owner jcodemunch); install plan note; profile line and the generated
  handbook with its receipt hashes; two lines of the session handbook; the tests restored to the user-scope shape.
- docs/decisions/2026-10-04-new-wsl-jcodemunch-user-scope.md keeps the measured cost visible: Harbor 2026-09-30, the
  jcodemunch arm (init + hooks) at 1.387 times the lean arm, 95% CI 1.230 to 1.553, Holm p = 0.0006, Sonnet 5.5 at medium;
  the bare registration of this commit was not measured. Overturn: the user's instruction to remove a tool or scope.
Counts: 399 pieces, 350 wired, 35 not wired, 14 authorization. Local integration checks, not upstream tests.
Registry excluded.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* New-WSL: complete the Codex jCodeMunch entry (approval mode, front-door verbs, start-up allowance, env)

The user-scope Codex entry of the previous commit carried only the command and the savings opt-out. Codex's tools of this server
carry no MCP annotations, so under approval_policy = "never" Codex refuses every unapproved call: the repository's own
per-project registration (adoption/templates/project.codex.config.template.toml) sets default_tools_approval_mode = "approve"
(codex-rs/codex-mcp/src/mcp/mod.rs L89-L98 at rust-v0.157.1), names the three verbs of the front door in enabled_tools
(jcodemunch-mcp 1.108.319, counter.py FRONT_DOOR), gives a 60 s start-up allowance and PATH and RTK_TELEMETRY_DISABLED. The user
entry is now that one, moved to user scope; CODE_INDEX_PATH stays unset (upstream's default is ~/.code-index).

- The approval mode is an authorization piece: a new map entry ahead of the code-index slot entry classes
  codex/*/mcp_servers.jcodemunch.default_tools_approval_mode `authorization:` with slot code-index and owner jcodemunch, so it is
  written only with --with-authorization-settings and only while the slot installs jcodemunch, like the other servers' modes.
- Tests: the approval constants gain jcodemunch (seven modes), the default render pins the entry without the approval mode, the
  option adds it. Counts: 404 pieces, 354 wired, 35 not wired, 15 authorization. The record and the user-scope record say so.
Local integration checks, not upstream tests. Registry excluded.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Refresh PR #684 token pins after PR #693

Align the new WSL RTK owner row, verified Linux asset, install/acceptance
scripts and profile with main's 0.51.0 pin. Retain the exact five-entry
hooks configuration required by bootstrap. Align the mcporter profile with
0.14.2 and verify that the claude-hud row already uses 0.10.0.

Regenerate the manifest, client instruction blocks and handbook; replace
receipt digests without reformatting it and recount the client record.
Repair citations into all 42 files changed by PR #693, preserving original
sources for the dated architecture pins. Record the failed attempt and its
corrections in the install-plan validation notes.

Validation: all 780 requested unittest cases pass, with five skips. Client
configuration, plan consistency, handbook and diff checks pass. All 30
convergence records pass native positional validation. The all-recorded
discovery check and publication validator await the coordinator's evidence
registry refresh; publication failures are registry drift only. Leave the
separate RTK grep exactness control untouched.

Sources:
https://github.com/rtk-ai/rtk/releases/tag/v0.51.0
https://github.com/rtk-ai/rtk/releases/download/v0.51.0/checksums.txt
https://github.com/openclaw/mcporter/releases/tag/v0.14.2
https://registry.npmjs.org/mcporter/0.14.2
https://github.com/jarrodwatts/claude-hud/releases/tag/v0.10.0

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Fix the refresh's stale locators and the profile pin table after the cross-family read

The Claude read of a3045d6 found three P2s and several P3s. adoption/new-wsl-profile.md rows now match profile.json
(RTK 0.51.0, mcporter 0.14.2). The 'never run rtk init --global --codex' locator is docs/token-session-handbook.md:397 in
the tree #684 lands (consensus, owner record; the definitive manifest and handbook regenerated). The client-configuration
record cites claude.settings.template.json L417 and bootstrap.md L366-385, the map note says RTK 0.51.0, the agentsview
locator is :1749-1751, the owner record points its RTK 0.50.0 line at the refresh section, and the install-plan README
says the plan follows #693's pins. The consensus pin of the owner record was re-issued.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Regenerate the new-WSL handbook on main d850a53 (after #694's PowerShell 7 recipe) with the receipt's output digests

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Re-freeze the new-WSL handbook receipt on main d850a53: generator, profile and inventory follow #684's profile (78 entries)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* registry: re-register the token-layer builder, carrier, wave-3 plan, profile, records, jCodeMunch registration, the rtk 0.51.0 refresh, its locator fixes and the handbook receipt on main d850a53 (registry last)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Hot-file protocol: reset manifests/evidence.json to the merge base before the final hot-file commit

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Reapply this branch's manifests/evidence.json edits on the merge base (hot-file protocol: every hot-file edit in the last commit)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Hot-file protocol: reset manifests/evidence.json adoption/hooks/claude/SHA256SUMS to the merge base before the final hot-file commit

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Reapply this branch's manifests/evidence.json adoption/hooks/claude/SHA256SUMS edits on the merge base (hot-file protocol: every hot-file edit in the last commit)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Hot-file protocol: reset manifests/evidence.json to the merge base before the final hot-file commit

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Reapply this branch's manifests/evidence.json edits on the merge base (hot-file protocol: every hot-file edit in the last commit)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Hot-file protocol: reset manifests/evidence.json adoption/hooks/claude/SHA256SUMS to the merge base before the final hot-file commit

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Upstream-surface dispositions: re-point two citations at the lines this branch moved (otel.metrics_exporter, tui.status_line)

Main's new test_every_cited_line_names_the_key reads the cited lines; this branch's template and
definitive-defaults table shift them.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Reapply this branch's manifests/evidence.json adoption/hooks/claude/SHA256SUMS edits on the merge base (hot-file protocol: every hot-file edit in the last commit)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Scout <scout@local>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant