Repository navigation
Codex dated holds (R6): a host-agnostic 0.159.3 hold on the Linux pin row, held status, TUI notice key - #687
Conversation
… until 2026-11-04 - adoption/pins-linux-x86_64.json: the codex row carries holds[] with one entry, 0.159.3 until 2026-11-04 (X18, the #626 landing exception). Wrapper URL and SHA-256 are the row's values before f77a35e (from 85543ef, #580), re-verified against a registry download; the linux-x64 platform_dependency (row shape) is first recorded here from the npm registry. - scripts/adoption_status.py --pinned-versions: a probe naming a hold's version before its until date (UTC) is held (hold_* fields, summary "held", "held until <date> (<reason>)"), not drift; on and after until it is mismatched with the expiry stated. Malformed holds are skipped. The default run, the exit code and the existing keys are unchanged. - tools/adoption/apply_codex_lane.py still refuses any codex but CODEX_VERSION; the refusal now names a matching hold and its until date. - tests/test_pin_holds.py: every hold complete, until a real date after today (UTC) and at most 90 days away, at most one hold per row (the OSV ignoreUntil precedent), with mutants. - adoption/templates/codex.config.template.toml: "gpt-6.1-sol" = 4 under [tui.model_availability_nux], cited from openai/codex rust-v0.160.0 (MODEL_AVAILABILITY_NUX_MAX_SHOW_COUNT = 4). - docs/decisions/2026-10-04-codex-dated-holds.md: design, alternatives, precedent, overturn. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…le protocol, last commit) manifests/stack.json's codex row carries no install data, so its freshness refers to the pins row's dated hold instead of copying it. manifests/evidence.json takes main's copy (6af8e55) and re-registers this branch's changed files plus its new test and decision record, as #626 did; component_matrix.py and new_host_grand_list.py --write reproduced their outputs unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ds branch (hot-file protocol: main's registry; PR rows re-registered last) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…y (387 pieces, 80 not wired, 39 own entry) The key under tui.model_availability_nux is one more not-wired piece (client state, not configuration). Recounted on the tree merged with main 54eb892 (#674, #683, #686) by the GPT-6.1 Sol worker; reviewed by the coordinator. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…egistry plus the owned rows) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…fore the final hot-file commit Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… (hot-file protocol: every hot-file edit in the last commit) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…s-family P1) pin_holds() now keeps only holds that hold_schema_problems() accepts. The same validator is imported by tests/test_pin_holds.py. It requires the wrapper url and sha256, and the platform package's shape, version, url, digest and binary check when the pin has one. So a hold with malformed install metadata is ignored, and the version is reported as drift instead of held. Failing-first: the three missing-field cases failed before the fix; 16 malformed-metadata cases pass after it. Built by the GPT-6.1 Sol worker; reviewed by the coordinator (Claude Opus). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… to the merge base before the final hot-file commit Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…its on the merge base (hot-file protocol: every hot-file edit in the last commit) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude session native-agent-stack-5f: landing at head Observed main Required checks at this head: 8 pass . Unresolved review threads: 0. |
|
Claude session native-agent-stack-5f: post-merge observation. Landed as |
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…04 directive (#684) * New WSL builder: wire the token layer by default on the owner's 2026-10-04 directive NativeStack2604's client configuration now carries the token layer: - rtk: RTK_TELEMETRY_DISABLED (Claude env, Codex shell set tables), the PreToolUse Bash hook `rtk hook claude`, the six rtk force-push deny rules, and the Codex instruction block's RTK section (rtk-ai/rtk v0.50.0 hooks/rtk-awareness-full.md, verbatim). - the SubagentStart token-lane carrier (hook and six blocks, byte-pinned). - the Claude Code session-start currency notice. - CLAUDE_CODE_EXPERIMENTAL_AGENT_TEAMS=1 (code.claude.com agent-teams). The builder gains a `directive` field for slot entries: the dated record of the owner's directive adds the entry's owner beside what the slot installs, only while the slot installs anything; --check fails when the record is not a file. rtk's MCP-server env copies follow their server. docs/decisions/2026-10-04-new-wsl-token-layer-default.md quotes the directive, supersedes the 2026-10-02 not-wired rulings for these pieces, claims no saving, and names the F-token arm as what decides it. The 2026-10-02 record's counts sentence and tables are recounted (386 pieces, 315 wired, 59 not wired, 12 authorization). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * 2026-10-02 client-configuration record: addendum pointing to the 2026-10-04 token-layer record Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Main-session token-lane carrier: SessionStart hook, block, template group and installer entries The SubagentStart carrier reaches subagents only. This adds its main-session counterpart: - adoption/hooks/claude/token-lanes-session-start.py, modeled line for line on token-lanes-subagent-start.py (stdlib, fail-open, unbuffered write, exit 0), returns its sibling token-lanes-block.main.md as SessionStart additionalContext; blind-* and the subagent carrier's silent roles get nothing. - token-lanes-block.main.md (1,842 bytes, budget 2,600): choose the lane first, Read only to Edit or for small verbatim files, ctx_execute_file/ctx_execute with intent then ctx_search, qmd for catalog docs, ctx_batch_execute for large output, RTK scope, delegation, code and memory lanes if exposed, one lane per artifact, savings only from client counters. It adds the ToolSearch line that context-mode 1.0.169 gives only Agent-tool prompts (sessionstart.mjs L49, routing.mjs L892-907 at 589d8214). - claude.settings.template.json: one SessionStart group after the currency notice, matcher startup|resume|clear|compact|fork (every source code.claude.com/docs/en/hooks documents; fork is separate since v2.1.214 and re-runs SessionStart hooks), timeout 5. - install_claude_profile.py HOOKS and SHA256SUMS list both files; tests cover the hook contract, the text, the registration and the installed command; handbook section and decision addendum. Advisory only: context-mode's Read/Grep PreToolUse guidance stays advisory (routing.mjs L843-872) and RTK's hook covers Bash only (README v0.50.0 L153, L368). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * New-WSL builder map: wire the main-session carrier pieces, recompute the record's counts and tables The SessionStart carrier of unit U1 added three pieces that the map did not know, so `new_wsl_client_config.py --check` exited 1 with three unmapped pieces. They join the token-lane carrier entry (same wiring and owner directive as the SubagentStart carrier): the SessionStart hook, its main-session block and its script. The counts and tables of the 2026-10-02 record are recomputed from `--check` on this tree (389 pieces, 318 wired, 58 not wired, 13 authorization), adoption/bootstrap.md names the SessionStart carrier in both carrier paragraphs, and two builder-test expectations follow the one additional wired hook command (5 to 6 commands, and token-lanes-session-start.py in the set of hook files the repository copies with its checksum). Checks at this commit: new_wsl_client_config.py --check exit 0; unittest tests.test_new_wsl_client_config tests.test_install_claude_profile tests.test_render_config tests.test_token_lanes_session_start tests.test_token_lanes_subagent_start tests.test_adoption_docs_consistency tests.test_wsl_new_distro_recipe tests.test_new_wsl_definitive_defaults: 540 tests OK (5 skipped). Local integration checks, not upstream tests. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * New-WSL wave 3: the owner's token-efficiency decision as amendment 4 of the manifest's rule - docs/decisions/2026-10-04-token-full-stack-owner-default.md: the owner's order verbatim, its authority path, the rows it overturns by file:line, the alternatives and the comparison that would remove each component, and the measured limits of #627 kept as usage rules. Net provider savings stay unmeasured. - consensus.json wave3: ten owner_decision rows in token-efficiency (command-output, output-compression, code-index, code-graph, repo-packing, structured-data, doc-conversion, api-docs, trace-viewer, token-lane-carriers), owner defaults on context-supply (context-mode 1.0.169, its wave-2 interim dropped), ccusage 20.0.26 and session-analytics (agentsview 0.43.0, local archive only), and the code-search interim widened to semble 0.6.1 + SocratiCode 1.15.0. Pins are the ones manifests/stack.json and adoption/pins-linux-x86_64.json record at f77a35e. - assemble_manifest.py folds every wave batch in numeric order and checks an owner batch (hashed relaying record that quotes the order and names every slot and repository; no acknowledgement owed; replaced fields kept under overturned). - render_tables.py lists the owner decisions and what each replaced, and keeps the blind-round basis of an overturned row; definitive-manifest.json and the 2026-10-01 record's tables are regenerated, with a dated pointer paragraph. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> (cherry picked from commit 93fec17155724f720ac06da9a267115bc21db252) (cherry picked from commit f9da212cce86e105522bddcd071d79cd3e22b1fd) * New-WSL install plan, wave 3: the token-efficiency owner rows, every-wave gate, tests - install.sh / accept.sh / install-plan.json / owners.json: one install and one acceptance function per new owner row (command-output, output-compression, code-index, code-graph, repo-packing, structured-data, doc-conversion, api-docs, trace-viewer, token-lane-carriers), ccusage and session-analytics installed as owner defaults, code-search adds SocratiCode 1.15.0 beside semble; the --list rows, the --only lists and the slot loops follow. Every tool goes under ${ECO_ROOT:-$HOME/.local/share/codex-ecosystem}, the root the client templates run; archives and npm tarballs through fetch_verified against the recorded sha256 (no gh sign-in). Pins are the ones manifests/stack.json and adoption/pins-linux-x86_64.json record at f77a35e. - interim_acknowledged reads every wave batch (refusing a misspelt wave key); context-supply, now an owner default, no longer calls it; check_plan.py refuses a gate call on a row without an interim. - tests/test_new_wsl_definitive_defaults.py: invariants extended to the owner batch (rows, owner defaults, overturned fields, counts, rule text, tables), 31 negative controls for the assembler's owner-batch checks, gate cases for later batches. - README, SOURCES and VALIDATION: the Wave 3 sections. Nothing was installed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> (cherry picked from commit 25b002046be9939b8506ee9778c588b4181dd627) (cherry picked from commit 7440aeacacec7f570135a400bd2845601f7d27b7) * New-WSL profile and handbook, wave 3: the token-efficiency owner defaults - adoption/new-wsl-profile.json: RTK picked with default_install true and the release-asset install (docs/token-efficiency-stack.json) instead of the UNRUN cargo build; Headroom picked with the [mcp] extra, not [all]; ccusage's install command and documented acceptance filled; SocratiCode's install command filled, and it stays a comparison arm of the split code-search slot (validate_default_installs refuses a default install for it); new rows for context-mode, jcodemunch-mcp, codebase-memory-mcp, Repomix, TOON, MarkItDown, Context Hub, otel-tui and agentsview. boundary.default_profile names the token rows; install_dispatch is unchanged. Validated by scripts/new_wsl_profile.py. - scripts/build_new_wsl_handbook.py: reads every wave batch, the row kind owner_decision and owner defaults (overturned.fields), counts interims for any wave batch, renders a multi-repository interim without a broken link and lists what each owner decision replaced. Outputs regenerated; the handbook receipt's frozen hashes follow them. - catalogs/foundation/new-wsl-architecture-20261001.json: a superseded-by pointer in the token-efficiency row's notes (the edition has no context-supply row and admits no new row field); the dated text stays. - Tests: profile owner defaults and arms; handbook owner rows, owner amendments and six negative controls; counts 100/10. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> (cherry picked from commit 85735c7163888c23c8a513e4cd26d738349589a7) (cherry picked from commit 800ae92c8fb9f1a1337a0ad7929bf0a6e699c875) * New-WSL builder map: wire the owner-default token tools through their wave-3 slots Wave 3 (the previous three commits) makes the token-efficiency tools owner defaults of new slots, so the builder's map moves their pieces to those slots and wires the two tools it had left out. Twenty-four pieces change: RTK's environment variable, PreToolUse Bash hook and deny rules (9) go from slot context-supply to command-output; Headroom's MCP server and its approval slot (8) go to output-compression, MCP only, never the proxy mode; codebase-memory (3) and Context Hub's two telemetry switches (2) leave not_wired for code-graph and api-docs; jCodeMunch gets two new pieces (a Claude user-scope server and a Codex [mcp_servers] table) on code-index, registered as the console script the plan installs into the ecosystem bin directory, the same registration NativeStack runs, and never through `jcodemunch-mcp init`, which writes a prompt policy and hooks and stays the user's decision. SocratiCode keeps its code-search wiring and points at the pinned 1.15.0 build the plan installs. The 23 pieces that stay unwired are the Codex hook-trust hashes, the Codex role carriers, the rescue plugin and its marketplace, the cache-heal hook and four settings of other owners. The generated instruction blocks keep the sentences that name tools which are now installed; 41 test expectations move by exactly that consequence (162 tests before and after, none deleted, every negative control kept: Promptfoo replaces the now-installed Headroom as the unwired tool in the name-injection fixtures, and the split-slot test still flips SocratiCode off when the slot's owner is changed to semble). The record's counts, tables and dropped-units list are recomputed from `--check` on this tree (391 pieces, 355 wired, 23 not wired, 13 authorization). Checks at this commit: new_wsl_client_config.py --check exit 0; unittest tests.test_new_wsl_client_config tests.test_install_claude_profile tests.test_render_config tests.test_token_lanes_session_start tests.test_token_lanes_subagent_start tests.test_adoption_docs_consistency tests.test_wsl_new_distro_recipe tests.test_new_wsl_definitive_defaults tests.test_new_wsl_handbook tests.test_new_wsl_profile: 638 tests OK (5 skipped); check_plan.py OK; build_new_wsl_handbook.py --check OK. Local integration checks, not upstream tests. Map and test edits were drafted by a GPT-6.1 Sol/max worker through the packaged OmniRoute SDK worker and reviewed edit by edit here. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * New-WSL client-configuration record: recount on main 8c32a84 after #674 (392 pieces, 356 wired, 23 not wired, 13 authorization) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * New-WSL default: hold the token-lane carriers out of the clean install The two carrier hook entries and the nine files install_claude_profile.py copies are this repository's own adaptation, not a feature of an upstream tool. The owner's directive of 2026-10-04 (a clean install: upstream installers with upstream default configuration), relayed by the command center, holds them out of the new distribution's default: the map entry goes from practice to not_wired, so the rendered settings run no carrier file and --apply copies none. Counts: 392 pieces, 345 wired, 34 not wired, 13 authorization (was 356 / 23). Shared template and carrier files are unchanged, so other hosts keep what they render. New decision record, one new test, five expectations moved. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * New-WSL token layer: persist RTK and Context Hub configuration, register jCodeMunch per project, restore the directive-branch test The four findings of the independent read of #684 (0 P1, 3 P2, 1 P3), each from an upstream-documented field: - F1 jCodeMunch is registered per project, never at user scope (docs/token-session-handbook.md, adoption/bootstrap.md "jCodeMunch, per project"): the user-scope Claude and Codex additions and their map entry are gone; the code-index row still installs the console script. Four project agents name its tools, which the record's gap table now lists. - F2 RTK [hooks] exclude_commands (the recipe's five entries) is written by command-output() to ${XDG_CONFIG_HOME:-~/.config}/rtk/config.toml, an existing file kept; the acceptance is version-neutral ($e/bin/rtk hook check, no version string for the new lines). - F3 Context Hub telemetry:false and feedback:false are written by api-docs() to ${CHUB_DIR:-~/.chub}/config.yaml, an existing file kept; the acceptance asks upstream's own isTelemetryEnabled()/isFeedbackEnabled() with CHUB_* unset. - F4 the directive branch has a positive test again (a slot that installs a different owner keeps the entry's directive; without the directive the piece is not wired); three PlanConfigurationTests run the two writes and check_plan.py in scratch homes. Counts: 390 pieces, 343 wired, 34 not wired, 13 authorization (with the carrier hold-out of the commit before). Native demonstration on rtk 0.51.0 and Context Hub 0.1.4 (scratch config dirs): the four excluded commands rewrite before the config (rc 0) and exit 1 "No rewrite for" after it, git status rewrites in both; Context Hub reports telemetry=true feedback=true without config.yaml and false/false with it, acceptance exit 0. The repair worker (Sol max) stopped at its deadline with the work unverified; the verification is the coordinator's. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * New-WSL client-configuration record: recount on main df50444 after #687 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Agentsview pin registry: classify the wave-3 profile and its generated handbook as dated records The macOS gate of PR 684 failed two tests of tests/test_agentsview_qualification.py (the same two fail on Linux): the new-WSL profile and its generated handbook (json and md) name agentsview 0.43.0 since the owner's decision of 2026-10-04 and neither registry list classified them. They are built from the definitive manifest and the install plan, not from manifests/stack.json, so a stack re-pin does not edit them: dated_record entries with basis 2026-10-04, in the registry's path order. 12 tests of the module pass. The registry file's hash is to be re-registered in manifests/evidence.json by the series' registry commit. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * New-WSL builder: turn on the You-should-know mod and the ConfigChange audit hook on NativeStack2604 The owner's order of 2026-10-04 asks for every latest changelog feature fully enabled in the native workflow of the new WSL too. Two switches that NativeStack's own user settings already carry reach NativeStack2604 through the builder's 2604-only additions file, each with a `practice` map entry that cites its source. Neither is a token-layer adaptation: the mod is a built-in Claude Code feature and the audit hook is zero-token host practice, so the clean-default hold-out (the token-lane carriers only) does not touch them. - enabledPlugins["cc-plugin-you-should-know@builtin"] = true: the built-in mod added in Claude Code 2.1.287 that runs a side agent and shows notes above the prompt (https://code.claude.com/docs/en/plugins/mods/overview, read 2026-10-04). It is disabled by default, and its side agent costs tokens that are counted apart from the token-efficiency measurements. - hooks.ConfigChange: the logging-only audit hook of https://code.claude.com/docs/en/hooks-guide ("Audit configuration changes"), with the literal command NativeStack runs (it appends the change's source and file to ~/claude-config-audit.log and ends with `|| true`, so it cannot block anything). Three test expectations move by exactly that consequence: the enabled-plugin set gains the mod, the hook-command allowance gains the audit command (and ConfigChange must hold exactly that one command), and the expected event list gains ConfigChange. The record's counts and tables are recomputed from `--check`: 393 pieces, 345 wired, 35 not wired, 13 authorization (head 316abe3 plus these two pieces). The commit was first withdrawn with the carriers and is reinstated on the command center's correction of 2026-10-04. Checks at this commit: new_wsl_client_config.py --check exit 0; unittest tests.test_new_wsl_client_config tests.test_install_claude_profile tests.test_render_config tests.test_token_lanes_session_start tests.test_token_lanes_subagent_start tests.test_adoption_docs_consistency tests.test_wsl_new_distro_recipe tests.test_new_wsl_definitive_defaults tests.test_new_wsl_handbook tests.test_new_wsl_profile: 642 tests OK (5 skipped). Local integration checks, not upstream tests. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * New-WSL changelog parity: advisor opus, crossSessionInbound accept, Codex fast tier and analytics_plan_history; Context Hub acceptance uses the PATH node The user's directive of 2026-10-04 ("we need all the sota features, latest changlogs, fully enalbed seamlessly within our naitve workflow for new wsl also"), relayed by the command center, carried to NativeStack2604 after a parity diff of NativeStack's live Claude settings and Codex config against the builder's render of the PR 684 head. Everything else NativeStack has enabled was already rendered; docs/decisions/2026-10-04-new-wsl-changelog-parity.md lists the rest and why. - advisorModel = "opus": the map's own override entry, the user's decision of 2026-10-04 and NativeStack's value. - crossSessionInbound = "accept": a fifth authorization setting (AUTHORIZATION_PIECES, the map entry, the additions file), written only with --with-authorization-settings; overturns the wave-2 messaging ruling on the user's directive. - Codex service_tier = "fast" (2604 additions, the map's Codex practice entry): the user's 2026-10-03 choice, NativeStack's value; the 0.160.0 schema calls fast the legacy spelling of priority. - Codex features.analytics_plan_history = true in the shared template, so both hosts: experimental, one ChatGPT-backend request, no model call. - accept.sh and install-plan.json run the Context Hub acceptance with the node on the prepared PATH (the delta read of PR 684, P2: no plan command links Node into ${ECO_ROOT}/bin); check_plan.py agrees with the script. Counts: 396 pieces, 347 wired, 35 not wired, 14 authorization. Tests: the authorization pins now name five standalone settings (STANDALONE), the render test pins the advisor and the two Codex values, two authorization tests handle a single-piece entry and a seeded value. Local integration checks, not upstream tests. Registry excluded. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * New-WSL: register jCodeMunch once at user scope, for Claude Code and Codex, on the user's directive The user, 2026-10-04, replying to the You-should-know note that new projects and worktrees start without jCodeMunch: "we need to set up all the sota repos, mcp tools, harness rules, upstream cc native hooks and beyond, resolute them cleanly for future session to make sure their seamless pick up and thier native workflow enhanced with the sota practice". The command center read it as one registration for every project. This overturns, for NativeStack2604, the per-project rule of 2026-09-25 (docs/decisions/2026-09-23-claude-user-profile.md addendum, 2026-09-25-codex-mcp-scope.md decision 2, F6 of 2026-09-26-token-practice-f1-f9.md). - Claude: user-scope `jcodemunch` (type stdio, the console script the code-index row installs) with the documented savings opt-out JCODEMUNCH_SHARE_SAVINGS=0 in its env block; Codex: [mcp_servers.jcodemunch] with the same env table. Source: jgravelle/jcodemunch-mcp 1.108.319 at 8f7b34ab, README.md L119-122 (`claude mcp add -s user jcodemunch jcodemunch-mcp`), CONFIGURATION.md L229-233 and SECURITY.md L311 (the opt-out). `jcodemunch-mcp init` is not run. - Map: the code-index slot entry back (slot:code-index, owner jcodemunch); install plan note; profile line and the generated handbook with its receipt hashes; two lines of the session handbook; the tests restored to the user-scope shape. - docs/decisions/2026-10-04-new-wsl-jcodemunch-user-scope.md keeps the measured cost visible: Harbor 2026-09-30, the jcodemunch arm (init + hooks) at 1.387 times the lean arm, 95% CI 1.230 to 1.553, Holm p = 0.0006, Sonnet 5.5 at medium; the bare registration of this commit was not measured. Overturn: the user's instruction to remove a tool or scope. Counts: 399 pieces, 350 wired, 35 not wired, 14 authorization. Local integration checks, not upstream tests. Registry excluded. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * New-WSL: complete the Codex jCodeMunch entry (approval mode, front-door verbs, start-up allowance, env) The user-scope Codex entry of the previous commit carried only the command and the savings opt-out. Codex's tools of this server carry no MCP annotations, so under approval_policy = "never" Codex refuses every unapproved call: the repository's own per-project registration (adoption/templates/project.codex.config.template.toml) sets default_tools_approval_mode = "approve" (codex-rs/codex-mcp/src/mcp/mod.rs L89-L98 at rust-v0.157.1), names the three verbs of the front door in enabled_tools (jcodemunch-mcp 1.108.319, counter.py FRONT_DOOR), gives a 60 s start-up allowance and PATH and RTK_TELEMETRY_DISABLED. The user entry is now that one, moved to user scope; CODE_INDEX_PATH stays unset (upstream's default is ~/.code-index). - The approval mode is an authorization piece: a new map entry ahead of the code-index slot entry classes codex/*/mcp_servers.jcodemunch.default_tools_approval_mode `authorization:` with slot code-index and owner jcodemunch, so it is written only with --with-authorization-settings and only while the slot installs jcodemunch, like the other servers' modes. - Tests: the approval constants gain jcodemunch (seven modes), the default render pins the entry without the approval mode, the option adds it. Counts: 404 pieces, 354 wired, 35 not wired, 15 authorization. The record and the user-scope record say so. Local integration checks, not upstream tests. Registry excluded. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Refresh PR #684 token pins after PR #693 Align the new WSL RTK owner row, verified Linux asset, install/acceptance scripts and profile with main's 0.51.0 pin. Retain the exact five-entry hooks configuration required by bootstrap. Align the mcporter profile with 0.14.2 and verify that the claude-hud row already uses 0.10.0. Regenerate the manifest, client instruction blocks and handbook; replace receipt digests without reformatting it and recount the client record. Repair citations into all 42 files changed by PR #693, preserving original sources for the dated architecture pins. Record the failed attempt and its corrections in the install-plan validation notes. Validation: all 780 requested unittest cases pass, with five skips. Client configuration, plan consistency, handbook and diff checks pass. All 30 convergence records pass native positional validation. The all-recorded discovery check and publication validator await the coordinator's evidence registry refresh; publication failures are registry drift only. Leave the separate RTK grep exactness control untouched. Sources: https://github.com/rtk-ai/rtk/releases/tag/v0.51.0 https://github.com/rtk-ai/rtk/releases/download/v0.51.0/checksums.txt https://github.com/openclaw/mcporter/releases/tag/v0.14.2 https://registry.npmjs.org/mcporter/0.14.2 https://github.com/jarrodwatts/claude-hud/releases/tag/v0.10.0 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Fix the refresh's stale locators and the profile pin table after the cross-family read The Claude read of a3045d6 found three P2s and several P3s. adoption/new-wsl-profile.md rows now match profile.json (RTK 0.51.0, mcporter 0.14.2). The 'never run rtk init --global --codex' locator is docs/token-session-handbook.md:397 in the tree #684 lands (consensus, owner record; the definitive manifest and handbook regenerated). The client-configuration record cites claude.settings.template.json L417 and bootstrap.md L366-385, the map note says RTK 0.51.0, the agentsview locator is :1749-1751, the owner record points its RTK 0.50.0 line at the refresh section, and the install-plan README says the plan follows #693's pins. The consensus pin of the owner record was re-issued. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Regenerate the new-WSL handbook on main d850a53 (after #694's PowerShell 7 recipe) with the receipt's output digests Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Re-freeze the new-WSL handbook receipt on main d850a53: generator, profile and inventory follow #684's profile (78 entries) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * registry: re-register the token-layer builder, carrier, wave-3 plan, profile, records, jCodeMunch registration, the rtk 0.51.0 refresh, its locator fixes and the handbook receipt on main d850a53 (registry last) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Hot-file protocol: reset manifests/evidence.json to the merge base before the final hot-file commit Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Reapply this branch's manifests/evidence.json edits on the merge base (hot-file protocol: every hot-file edit in the last commit) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Hot-file protocol: reset manifests/evidence.json adoption/hooks/claude/SHA256SUMS to the merge base before the final hot-file commit Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Reapply this branch's manifests/evidence.json adoption/hooks/claude/SHA256SUMS edits on the merge base (hot-file protocol: every hot-file edit in the last commit) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Hot-file protocol: reset manifests/evidence.json to the merge base before the final hot-file commit Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Reapply this branch's manifests/evidence.json edits on the merge base (hot-file protocol: every hot-file edit in the last commit) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Hot-file protocol: reset manifests/evidence.json adoption/hooks/claude/SHA256SUMS to the merge base before the final hot-file commit Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Upstream-surface dispositions: re-point two citations at the lines this branch moved (otel.metrics_exporter, tui.status_line) Main's new test_every_cited_line_names_the_key reads the cited lines; this branch's template and definitive-defaults table shift them. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Reapply this branch's manifests/evidence.json adoption/hooks/claude/SHA256SUMS edits on the merge base (hot-file protocol: every hot-file edit in the last commit) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Scout <scout@local> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Draft. The inventory recount waits for #674, which is re-pinning
docs/decisions/2026-10-02-new-wsl-client-configuration.md. The coordinator (CC) re-ACKs before this PR leaves draft. Until then,tests.test_new_wsl_client_configfails on exactly the two record assertions listed below, and on nothing else.Scope
codexpin row.holds[]holds 0.159.3 until 2026-11-04 (X18, the Codex 0.159.3 -> 0.160.0 with the Python SDK pair: pins, qualification receipt, tests and checkpoint #626 landing exception).scripts/adoption_status.py --pinned-versionsreports a host on that version as held, not drift, until that date. From that date on it reports drift and states the expiry.tools/adoption/apply_codex_lane.pystill refuses such a host, and its refusal now names the hold."gpt-6.1-sol" = 4, and a decision record.6af8e55bd(origin/main at push). The branch was cut at33efbc3b6and rebased onto6af8e55bdbydocs/lanes.md's hot-file protocol, because CI least privilege: permissions {} by default, cache-mode none on pull requests, workflow policy tripwire #681 changedmanifests/evidence.json.lane:foundationadoption/pins-linux-x86_64.jsonadoption/templates/codex.config.template.tomlscripts/adoption_status.pytools/adoption/apply_codex_lane.pytests/test_adoption_status.pytests/test_codex_worker_lane.pytests/test_pin_holds.py(new)docs/decisions/2026-10-04-codex-dated-holds.md(new)manifests/stack.json(a reference to the hold, since that row carries no install data) andmanifests/evidence.json(main's copy, re-registered)SOTA sources
ignoreUntil, the expiry precedent, at v2.6.0 (tag commite840a6e8adb14b7777c78e26cfbf6e2abc1d1fc6):ignoreUntilis an "Optional exception expiry date".ignoreUntil.After(time.Now()), so it stops on its date..github/osv-scanner.tomlwithtests/test_osv_lockfile_coverage.pyignore_entry_problems(until <= date.today()is expired), plus.grype.yaml"Re-review by".rust-v0.160.0, for the TUI notice key. The tag object is79b1b666f2e8551f8abbbca34957227f67f3f553, which peels toa956835d020762cb2b570053af06f643a11c0ecc(git ls-remote), read from a pinned sparse clone:ModelAvailabilityNuxConfig, a flattenedHashMap<String, u32>of show counts per model slug. The[tui]field is at L940-L942.MODEL_AVAILABILITY_NUX_MAX_SHOW_COUNT: u32 = 4. L250-L266 show the notice only while the count is below 4. L281-L305 write the count back one higher per showing.set_model_availability_nux_count.availability_nuxat that tag.dist.integritysha512-hg4nlqCw…DkQ==anddist.shasumb49833a8…. ItsoptionalDependenciesmaps@openai/codex-linux-x64tonpm:@openai/codex@0.159.3-linux-x64.dist.integritysha512-xlHydfOk…s5og==anddist.shasum62a9c71b….Evidence-class table
f77a35eb2(introduced by85543efe5, #580). The 4,904-byte registry tarball matches them (SHA-25631d5e584…), and its SHA-512 and SHA-1 equal the registry'sdist.integrityanddist.shasum.git show f77a35eb2^:adoption/pins-linux-x86_64.json; registry download;sha256sum,openssl dgst -sha512,sha1sumplatform_dependency(@openai/codex@0.159.3-linux-x64, 162,464,331 bytes) is first recorded here, since no earlier record exists. SHA-512 and SHA-1 equal the registry's. SHA-256 is0719027c…and the archive's executable SHA-256 is8bf204b3…. No held host's installed executable was compared."gpt-6.1-sol" = 4under[tui.model_availability_nux]stops Codex's availability notice for that slug.rust-v0.160.0lines abovecodex: 0.159.3 held until 2026-11-04 (X18: …), and codex leavesmismatchedforheld. The base revision's script on the same pins file lists codex as mismatched.python3 scripts/adoption_status.py --pinned-versionson one held host, 2026-10-04until, a hold is held. On and afteruntil, it is drift and the expiry is stated. Any other version, a failing probe or a malformed hold is drift.tests.test_adoption_status.DatedHoldTests(9 tests)tests.test_pin_holdstests.test_codex_worker_laneApplyFlowTests(fake codex)<for<=, held not excluded, no well-formedness filter, and the live hold on its until date (two checks).mock.patchcontrolsLocal commands run
The rtk, ai-memory and mcporter mismatches are that host's own drift, unchanged by this PR.
Expected failures in
tests.test_new_wsl_client_config(both come fromdocs/decisions/2026-10-02-new-wsl-client-configuration.md, which this PR does not edit):RecordTests.test_the_counts_that_the_record_states_are_the_ones_check_prints:Tuples differ: (385, 293, 200, 93, 80, 41, 39, 12) != (386, 293, 200, 93, 81, 41, 40, 12).RecordTests.test_the_record_holds_the_tables_the_tool_prints: the record's not-wired table lacks the one new row| `codex/config/tui.model_availability_nux."gpt-6.1-sol"` | `not_wired` | … |, which follows thegpt-6-astrarow.The measured new counts are 386 pieces, 293 wired (200 practice, 93 through a slot), 81 not wired (41 through a slot that does not install, 40 by their own entry), 12 authorization.
new_wsl_client_config.py --checkitself passes, because the map's existingtui.model_availability_nux*entry covers the piece. The recount after #674 changes three places in that record: the "Today:" counts, Decision 14's "80 pieces are not wired" (to 81), and the new table row.Full suite (
python3 -m unittest, before the rebase and registration): 10,278 tests, 4 failures.test_catalog_freshness_propose…test_general_publication_validator_passes_after_the_runfailed only because the registry was not yet updated. After the last commit it exits 0.test_windows_terminal_defaults…test_the_installed_client_knows_no_notification_type_without_a_decisionscans the installed Claude Code binary on that host. That binary knows anauth_storage_failuretype the test's own table lacks. The failure is pre-existing and unrelated: neither that table nor the overlay is touched here, and CI skips the test.Decision record
docs/decisions/2026-10-04-codex-dated-holds.md. It covers the design and these alternatives:It cites the in-repo precedent (
.github/osv-scanner.tomlignoreUntilplus reason, and.grype.yaml"Re-review by"). Its overturn condition is that the held hosts retire or switch, and the hold is then deleted, or that a second concurrent hold is needed, and per-host rows are revisited. The test fails on a second hold and names the record.Host evidence
Not applicable: no file under
evidence/hosts/changes.Checklist
permissions: contents: read(none changed).🤖 Generated with Claude Code