Skip to content

fix(windows): make manual stops durable and bound bridge delivery receipts - #5782

Draft
tcflying wants to merge 8 commits into
lidge-jun:devfrom
tcflying:feat/chatgpt-bridge-2.62
Draft

tcflying wants to merge 8 commits into
lidge-jun:devfrom
tcflying:feat/chatgpt-bridge-2.62

Conversation

@tcflying

@tcflying tcflying commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Read shape, so the diff is not a surprise: this branch carries two feature lines plus their review wave. Roughly 2.3k lines are the src/chatgpt-bridge/ module and its extension, roughly 5.6k are the Windows recovery subsystem (guardian scripts, tray, launcher) that this branch introduces relative to the merge base, and roughly 1.9k are the fixes that round of review produced on top of both. Seven commits, each scoped to one of those three.

  • ocx stop, ocx start, ocx ensure, the visible launcher and the tray now share one durable recovery-intent contract: a manual stop survives a proxy that died before it could be restarted, a guardian-spawned recovery child is never mistaken for an operator stop (OPENCODEX_GUARDIAN_RECOVERY), and a stop whose intent cannot be written refuses loudly instead of leaving the proxy serving while the file claims stopped.

  • The Windows recovery guardian stops paying for its own work: the opening Inspect is adopted instead of re-run ~5 s later, launcher corroboration now decays so a healthy generation cannot freeze a stale pid+boot pair, the recovery path no longer double-pays Inspect, and incident retention counts only directories the guardian generated, so a stray file can no longer evict a real incident and a reparse point is never walked into fs.rm(recursive).

  • ChatGPT bridge: idempotent replay receipts survive pruning (the row cap now binds only outside the replay window it exists to answer), host-target uniqueness moved into a partial unique index because SELECT-then-INSERT only held inside one process, an unclaimed delivery releases its TARGET_ACTIVE gate once it is older than the same 120 s stale window, and a retired DevSpace session id is dropped on 404 so the next call re-initializes instead of failing for the life of the client.

  • Privacy and honest-declaration fixes: promptPreview is gone from the browser turn context (a serialized slice of the conversation is request content, and a transport that logs the context would then log the body), and the chatgpt-web dashboard preset is off because the shipped build cannot construct a browser transport, so the tile no longer promises a turn that can only answer CHATGPT_WEB_TRANSPORT_UNAVAILABLE.

  • One unrelated deletion is folded in: the unused module-level beginRuntimeSyncOperation instrument and the three module globals it needed (41 lines). Say the word and it moves to its own pull request.

Verification

Ran, and green:

  • bun run typecheck (bun x tsc --noEmit) — no output.
  • bun run privacy:scan — Privacy scan passed.
  • Focused files, quiet and exclusive: tests/windows/windows-recovery-main.test.ts 18/0, tests/windows/windows-recovery-policy.test.ts 12/0, windows-recovery-ownership, windows-recovery-repair 14/0, windows-tray 26/1 (the one red reproduces on origin/dev too, EADDRINUSE), tests/chatgpt-bridge/chatgpt-bridge-core.test.ts 17/0, chatgpt-bridge-codex-host, chatgpt-bridge-dsh-host, tests/adapters/adapter-tool-conformance.test.ts 9/0 (246 expects), tests/server/server-runtime-diagnostics.test.ts.
  • Every new assertion was checked against mutation, not just against a green run: the parenthesised reparse guard in intent.ps1 fails in 2.3 s when the parentheses are removed (Windows PowerShell binds -or and -and left-to-right at equal precedence, so the unparenthesised form lets a small symlink fail open); the chat-side uniqueness guard, the healthPid corroboration term, the budget-file content compare, the charged counter in the gateway cancel proof and the runTurn-only skip list each go red alone under their own mutant, and every mutant was restored byte-exactly with a sha pair recorded.

Not run, deliberately:

  • bun run test. The full suite is undecidable on this Windows box and this is a claim I want a maintainer to read as a limitation, not as a pass: both the branch tree and a clean origin/dev worktree died on the runner's own 900 s ceiling with a rotating red set, and tests/windows never got scheduled. The Windows-facing gates above were therefore taken quiet, exclusive and with a same-window git show HEAD: control; a run of 4 reds in windows-recovery-intent during a period when the machine itself began reporting EACLIDENTITY (the effective account SID could not be resolved) was discarded rather than tuned around. CI on Linux, Windows and macOS is the gate for this pull request.

Merge state: the branch is now 0 behind / 8 ahead of dev — origin/dev is merged in (651ff2f89), all 23 conflicts resolved and each decision recorded in that merge commit message. The two load-bearing ones: upstream routed handleStop through an approval gate, so the durable-intent fence now wraps that gate (an approval refusal rolls the written stopped back through the same path as an ownership refusal); and src/tray/windows.ts received two independent additions at the same spot, so both survive — upstream's windowsTrayRequiredFilesPresent` (which fixes the dotted-icon stale-install bug) AND our per-home intent-helper requirement, composed rather than chosen.

Security-sensitive surfaces, flagged rather than left to be found

Recovery marker and intent files are a trust boundary the guardian reads before it dispatches a lifecycle action (reparse point, size ceiling, maintenance-window contract); readKey/capability handling in the bridge store touches credentials; the preset change alters what the dashboard declares it can do. The two known-unfixed items in this area are recorded instead of patched, so they are visible here: recovery-incidents/<ts>/receipt.json stores the model's own diagnosis text (bounded, keyword-scrubbed per line), and a repair origin pointed at a public third party would send up to 16 KiB of real source out of the machine, where scrubbing is a per-line keyword filter. Both hinge on whether remote self-repair ships publicly at all.

Checklist

  • Scope stays focused and avoids unrelated cleanup.
  • Docs or release notes were updated when needed.
  • Security-sensitive changes were reviewed for secrets, auth, and unsafe defaults.

Codex Developer added 7 commits September 23, 2026 04:02
The startup path turned a silent admission refusal into a bare /readyz
failed with zero evidence; the refusal message is the operator's only
path to the cause (9-day silent catalog-sync stall on this deployment).

(cherry picked from commit 4bc1c67)
The bridge was written against the single-file config and provider registry. On
dev those modules are split, so the wiring lands per-owner: schema and
diagnostics for chatgptBridge, the adapter and provider rows, and the GUI
provider-list authority pin. The preset-count guard is what makes the docs half
of that change mandatory rather than optional.

Drops the three live-probe fixtures from the original branch: they hardcoded a
private devspace issuer and a user-temp token path, which privacy:scan rejects.
The recovery guardian only helps if a hand stop is distinguishable from a crash.
Intent is now written by every actor that can stop the proxy, before it dispatches:
the tray click handler, `ocx stop` (skipped for a guardian recovery child), and the
receipt-less management API stop, which fails closed when an enabled marker cannot be
persisted. The intent helper ships as an owned tray asset with rollback and uninstall
coverage, and the detached recorder is finally started by the server it describes.

The npm package does not ship scripts/, so installing the helper is conditional while
the tray script keeps its runtime refusal for a marker with no helper beside it.
A guardian-driven recovery child must not be read as an operator's durable
manual stop, and a stop that cannot write its intent must refuse loudly
instead of leaving the proxy serving while the file claims `stopped`.

- recovery-intent: fence `maintenance` with the shared `at < until <= at+180000`
  contract on every reader and writer (CLI, tray, launcher, action script),
  restore the durable intent verbatim when a later refusal rolls the stop back,
  and drop a re-affirmation of an intent that already reads `running`.
- guardian: adopt the opening inspection instead of paying for a second ~5 s
  PowerShell spawn, decay launcher corroboration so a generation cannot freeze
  a stale pid+start pair in place, and re-inspect after a recover so the
  recovery path stops double-paying Inspect.
- incidents: count only directories this process generated against the
  retention budget, and never walk a reparse point into `fs.rm(recursive)`.
- gateway: hoist the per-request allowed-host set and local port out of the
  request path.
- intent.ps1/launcher: parenthesise the reparse test (Windows PowerShell binds
  `-or` and `-and` left-to-right at equal precedence, so an unparenthesised
  guard lets a small symlink fail open) and refuse a malformed marker before
  dispatching any lifecycle action.

Verification: focused Windows files re-run quiet and exclusive
(recovery-main 18/0, recovery-intent green on a quiet box, policy, ownership,
repair, tray), each new assertion mutation-proven to fail alone.
`bun x tsc --noEmit` and `bun run privacy:scan` green.
… context

Review fixes on the carried ChatGPT bridge, each with a mutation-proven test.

- store: an idempotent replay must survive pruning, so `pruneOperations` now
  refuses to drop receipts inside the `OPERATION_REPLAY_MS` window it exists to
  answer (the row cap still binds outside it), and the host-target uniqueness
  guard moved into a partial unique index because a SELECT-then-INSERT only
  held within one process. A chat conversation keeps its one binding row for
  life by schema; the guard mirrors that instead of filtering by lifecycle.
- dsh host: an unclaimed delivery no longer holds the TARGET_ACTIVE gate
  forever. It now releases once the claim is older than the same 120 s stale
  window the core store uses, while a claimed-but-unfinished turn still refuses.
- mcp client: a DevSpace restart retires the minted session id, so a 404 drops
  it and the next call re-initializes instead of failing for the life of the
  client; a shared SSE frame is matched by request id, not by which frame
  arrives first.
- contracts/provider: retire the codes and the `replace` action this module no
  longer emits, add `BINDING_EXISTS`, hoist `MAX_PROMPT_CHARS` into the shared
  contract, and drop `promptPreview` from the turn context — a serialized
  slice of the conversation is request content, and any transport that logs the
  context would then log the body.
- tests: pin the chat-side uniqueness guard (it had no discriminating
  assertion), and make the runTurn-only skip list derived-and-checked instead
  of a hand-maintained allowlist over seven registry-wide loops.

Verification: `chatgpt-bridge-core` 17/0, `chatgpt-bridge-codex-host` and
`chatgpt-bridge-dsh-host` green, `adapter-tool-conformance` 9/0 with both
mutation directions firing. `bun x tsc --noEmit` green.
…strument

`beginRuntimeSyncOperation` was a second entry into the same instrumentation the
start scope already owns, and it needed three module globals plus their
teardown assignments to reach them. Nothing outside the module called it, and a
second live diagnostics instance would have had those globals point at whichever
child started last.

Verification: `server-runtime-diagnostics` green; `bun x tsc --noEmit` green.
…ly 503

`src/adapters/registry.ts` does not construct the adapter with a browser
transport yet, so every turn through a preset-selected chatgpt-web model answers
CHATGPT_WEB_TRANSPORT_UNAVAILABLE. A published preset therefore promised a
capability the shipped build cannot perform; the registry entry and its note
stay, only the preset flag goes off until the transport is attached.

Also register `src/chatgpt-bridge/` in the structure source-area map, which the
manifest guard requires for a new production directory.
@coderabbitai

coderabbitai Bot commented Sep 24, 2026

Copy link
Copy Markdown
Contributor

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added the intake: hygiene-blocked Deterministic PR hygiene checks failed label Sep 24, 2026
@github-actions

Copy link
Copy Markdown
Contributor

⚠️ Deterministic hygiene checks failed.

  • empty_catch — An empty catch block was added. Handle, report, or deliberately propagate the error. Paths: scripts/ocx-recovery-guardian/windows-action.ps1, scripts/windows-visible-proxy.ps1, src/tray/windows-tray.ps1, tests/windows/windows-recovery-ownership.test.ts.
  • unsponsored_surface — This changes an authentication, workflow, release-automation, or dependency surface. MAINTAINERS.md requires security review for these; ask a maintainer to apply maintainer-sponsored once they have reviewed it. Paths: src/server/management-api.ts.

@github-actions github-actions Bot added the bug Something isn't working label Sep 24, 2026
@github-actions

github-actions Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

⏳ DRAFT

  • hygiene: empty_catch. hygiene: unsponsored_surface.

What to do

  • Fix empty_catch — An empty catch block was added. Handle, report, or deliberately propagate the error. Paths: scripts/ocx-recovery-guardian/windows-action.ps1, scripts/windows-visible-proxy.ps1, src/tray/windows-tray.ps1, tests/windows/windows-recovery-ownership.test.ts.
  • Fix unsponsored_surface — This changes an authentication, workflow, release-automation, or dependency surface. MAINTAINERS.md requires security review for these; ask a maintainer to apply maintainer-sponsored once they have reviewed it. Paths: src/server/management-api.ts.
  • Tick all four boxes in the PR description once you're done (currently 0/4).

Review readiness checklist

  • ⬜ Required local validation passed; commands, results, and any full-suite exception are documented.
  • ⬜ I pushed my PR to a recent dev commit (at most 10 behind; a maintainer may still ask for the exact tip before merge).
  • ⬜ I resolved all correct Codex and CodeRabbit findings.
  • ⬜ My PR is ready for review.

0/4 boxes ticked.

This pull request was already a draft. Its draft status will be preserved after every issue above is resolved.
@tcflying Tick the boxes once required local validation has passed with commands, results, and any full-suite exception documented, your branch is on the latest dev commit, and every correct Codex and CodeRabbit finding is resolved.

Hygiene

⚠️ Deterministic hygiene checks failed.

  • empty_catch — An empty catch block was added. Handle, report, or deliberately propagate the error. Paths: scripts/ocx-recovery-guardian/windows-action.ps1, scripts/windows-visible-proxy.ps1, src/tray/windows-tray.ps1, tests/windows/windows-recovery-ownership.test.ts.
  • unsponsored_surface — This changes an authentication, workflow, release-automation, or dependency surface. MAINTAINERS.md requires security review for these; ask a maintainer to apply maintainer-sponsored once they have reviewed it. Paths: src/server/management-api.ts.

Brings the branch onto the current dev head so the Windows recovery chain and the
carried ChatGPT bridge can be reviewed against what upstream now does in the same
restart/stop area. 23 conflicts; how each was decided:

- src/cli/index.ts: upstream routed `handleStop` through an approval gate. Kept the
  gate and kept the durable-intent fence around it, so an approval refusal rolls the
  `stopped` intent back through the same path as an ownership refusal instead of
  through a second copy of it.
- src/tray/windows.ts: two independent additions landed at one spot (our
  `trayHomeRequiresRecoveryIntentHelper`, upstream's `windowsTrayRequiredFilesPresent`
  which fixes the dotted-icon stale-install bug). Both kept, and the ownership check now
  composes them: upstream's required-file rule AND the helper only where the home needs it.
- src/tray/windows-tray.ps1: kept upstream's Update menu item and our write-intent-first
  ordering comment.
- tests/fixtures/test-layout-expected.json: upstream had already relocated most of our
  entries; kept only the four chatgpt-bridge keys it lacks, so no duplicate property.
- docs-site guides and quickstarts (8 locales) + structure/ops/docs-and-release.md:
  recount is derived by `docs-provider-preset-counts` — the merged registry is 99 total
  (81 key-based, 13 OAuth, four local, one default), so the +1 is applied to every locale
  rather than only to the English page.
- structure/providers-and-adapters.md: kept upstream's mimo-free and command-code rows and
  our `src/chatgpt-bridge/` row.
- tests/adapters/adapter-tool-conformance.test.ts: upstream added `claude-cli` to the
  tool-less set; unioned it. The derived-and-checked skip pin still holds against it.

Verification: `bun x tsc --noEmit` clean; `test-layout`, `test-layout-tooling`, the three
`docs-provider-*` guards and `adapter-tool-conformance` green together (146 pass / 1 fail,
and that one — `move end to end` — passes alone, so it is coexistence noise from running
four files in one process, not a merge defect).
@tcflying

Copy link
Copy Markdown
Contributor Author

Post-merge verification on 651ff2f89 (branch is 0 behind / 8 ahead of dev):

  • bun run typecheck clean, bun run privacy:scan passed.
  • Focused, quiet, exclusive: tests/chatgpt-bridge, tests/adapters/adapter-tool-conformance.test.ts, tests/windows/windows-recovery-main.test.ts, tests/windows/windows-recovery-policy.test.ts → 81 pass / 0 fail. Same for tests/test-layout.test.ts, tests/test-layout-tooling.test.ts and the three docs-provider-* guards (146 pass / 1 fail in that run; the one failure, move end to end, passes in isolation, so it is coexistence noise from four files in one process).
  • The preset recount after the merge is derived, not hand-written: the registry says 99 total / 81 key-based / 13 OAuth / four local / one default, and all eight locales plus structure/ops/docs-and-release.md now carry it — docs-provider-preset-counts is the thing that says so.

Why this pull request stays a draft: the review-readiness checklist asks for "local CI green", and I am not going to tick that without having run bun run test. On this Windows box the full suite is not adjudicable — both this tree and a clean origin/dev worktree die on the runner's own 900 s ceiling with a rotating red set (the same shape as the two prior reports of it in this repo). The Windows-facing gates here were therefore taken quiet, exclusive and with a same-window git show HEAD: control. CI on Linux, Windows and macOS is the gate for this change, so a maintainer needs to start it.

@lidge-jun

Copy link
Copy Markdown
Owner

리뷰 · 우선순위 64 / 80

이 PR은 초안입니다. 하는 일이 두 갈래입니다.

윈도우에서 사람이 프록시를 끈 것과, 프로그램이 혼자 죽은 것을 구분합니다. ocx stop, 시작, 트레이, 보이는 실행기가 같은 메모(recovery-intent.json)에 "사람이 껐다 / 켜 두는 중이다 / 잠깐 재시작 중이다"를 적습니다. 가디언은 그 메모를 보고, 사람이 끈 경우에는 다시 살리지 않습니다. 메모를 못 쓰면 끄기를 거부해서, 파일은 "꺼짐"인데 프록시는 살아 있는 상태가 되지 않습니다. 가디언이 복구하려고 띄운 자식은 OPENCODEX_GUARDIAN_RECOVERY라서 사람 정지로 오해하지 않습니다.

ChatGPT 웹 브리지는 대화 연결을 저장합니다. 같은 요청을 나중에 다시 물어봐도 "이미 처리했다"는 기록이 남고, 한 파일에 프로세스가 둘 붙어도 같은 대상을 두 번 연결하지 못하게 잠급니다. 브라우저로 대화를 보내는 기능은 아직 없습니다. 그래서 대시보드 타일은 꺼 두었습니다. 켜 두면 매 턴이 CHATGPT_WEB_TRANSPORT_UNAVAILABLE만 돌려줍니다.

작은 변경도 같이 있습니다. Codex 쓰기가 거부되면 이유를 로그에 남깁니다. 안 쓰이던 beginRuntimeSyncOperation 계측을 지웠고, 작성자는 그 삭제를 다른 PR로 빼도 된다고 적었습니다.

베이스는 dev입니다. chatgptBridge 설정은 src/types/config.ts와 src/config/schema/config-schema.ts 양쪽에 들어가 있습니다. 같은 일을 하는 열린 중복 PR은 없습니다. 본문 체크리스트는 0/4입니다. 타입 검사와 프라이버시 검사, 일부 테스트는 통과했다고 본문에 적혀 있습니다. 전체 bun run test는 이 윈도우 컴퓨터에서 시간 제한으로 끝나지 않았다고 작성자가 적었습니다. 그 명령은 이 리뷰에서 다시 돌리지 않았습니다.

scripts/ocx-recovery-guardian/repair.cjs:17 - 수리 주소 허용 목록에 https://api.mnnai.ru/v1가 있습니다. 그 주소로 소스 조각을 최대 16KB 보냅니다. 보내는 파일 목록(25행)에 src/codex/user-identity.ts가 들어 있습니다. 가리는 방식은 줄마다 특정 단어가 있으면 그 줄만 지우는 것입니다. 단어가 없는 문장은 그대로 나갑니다. 진단 문장도 recovery-incidents/<ts>/receipt.json에 남습니다.

scripts/ocx-recovery-guardian/windows-action.ps1:243 - catch { }가 비어 있습니다. scripts/windows-visible-proxy.ps1의 창 제목과 뮤텍스 해제에도 빈 catch가 있습니다. 저장소 검사가 empty_catch로 이 PR을 막고 있습니다.

src/server/management-api.ts - 관리 화면의 끄기가 정지 메모를 먼저 씁니다. 이 파일은 인증과 작업 흐름이라 unsponsored_surface입니다. 메인테이너가 보안을 본 뒤에 maintainer-sponsored를 붙여야 그 검사가 풀립니다.

src/lib/recovery-intent.ts - runningIntentWritten은 메모 파일이 깨져 있으면 조용히 "아직 running이 아니다"를 반환하고, 시작 경로는 그 파일을 running으로 덮습니다. 가디언 마커 파일이 깨지면 같은 모듈은 동작을 거부합니다. 메모만 조용히 바뀝니다.

메인테이너의 판단이 필요한 지점
원격 자동 수리를 공개 기능으로 둘지입니다. 둔다면 api.mnnai.ru로 소스와 진단 문장이 나갑니다. 안 둔다면 이 수리 경로를 빼는 쪽이 맞습니다.

윈도우 복구와 ChatGPT 브리지를 한 PR로 머지할지도 정해야 합니다. 둘 다 크고, 실패 원인이 섞입니다. 안 쓰는 계측 삭제는 작성자가 이미 분리를 제안했습니다.

관리 API 정지에 maintainer-sponsored를 줄지도 봐야 합니다. 메모를 못 쓰면 503으로 끄기를 거부하는 쪽은 안전합니다. 다만 끄기 전에 stopped를 먼저 쓰기 때문에, 그 직후 프로세스가 죽으면 가디언은 "사람이 껐다"고 읽을 수 있습니다.

너의 추천
초안인 채로 두세요. 빈 catch는 고치거나, 일부러 비운 곳에는 이유를 한 줄 남기세요. 원격 수리는 이번 PR에서 빼거나, 공개 전에 허용 목록에서 api.mnnai.ru를 빼세요. 브리지와 윈도우 복구는 나눠서 리뷰하는 편이 안전합니다. 설정 분할은 이미 dev 기준으로 양쪽에 들어가 있어서, 이 PR을 중복으로 닫을 이유는 없습니다.

이 댓글은 grok-bot이 작성했습니다

@devin-ai-integration devin-ai-integration Bot added the priority: P3 Low: new provider/client integration, large or experimental feature (>2000 LOC or >50 files), RFC/ro label Sep 25, 2026
@devin-ai-integration

Copy link
Copy Markdown
Contributor

Maintainer triage: priority: P3 — large feature branch (>9k LOC, 70 files): ChatGPT bridge + Windows recovery subsystem.

Criteria (P3): Low: new provider/client integration, large or experimental feature (>2000 LOC or >50 files), RFC/roadmap, or long-stale branch.

@lidge-jun

lidge-jun commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

Release train 4 triage (reviewed against dev 24b2f39 at head 651ff2f; T4-P-5782): Hold; split. Windows durable-stop guardian and ChatGPT bridge/replay receipts are independent new subsystems, neither on dev. The draft is conflicting and hygiene fails; no portable narrow bug slice was found. Separate feature lines, rebase, review intent-file/credential boundaries, and obtain exact-head Windows and other platform CI. The feature PR stays open for that work.

Update (2026-09-28): a re-review found one narrow, independent bug fix in this PR, commit cdf0330b (a service-home admission refusal was never logged). It landed on dev as #6100 (7b83dede) with Co-authored-by: tcflying. One change from your version: the admission message can contain private home and service-definition paths, so the log line is path-free and points to POST /api/sync, which already returns the reason. Thank you, @tcflying. The Windows durable-stop and ChatGPT bridge work stays open here under the hold above, and a rebase can drop that commit.

lidge-jun added a commit that referenced this pull request Sep 27, 2026
A service-home admission refusal in syncModelsToCodex returned without any
log line. Startup then marked /readyz failed with no evidence and `ocx sync`
only said the sync did not complete. Log one line naming the authority and
pointing to POST /api/sync for the specific reason. The admission message
can contain private home and service-definition paths, so it stays out of
the log.

Reimplements the diagnostic slice of #5782 without the raw message.

Co-authored-by: tcflying <77509083+tcflying@users.noreply.github.com>
lidge-jun added a commit that referenced this pull request Sep 27, 2026
A service-home admission refusal in syncModelsToCodex returned without any
log line. Startup then marked /readyz failed with no evidence and `ocx sync`
only said the sync did not complete. Log one line naming the authority and
pointing to POST /api/sync for the specific reason. The admission message
can contain private home and service-definition paths, so it stays out of
the log.

Reimplements the diagnostic slice of #5782 without the raw message.

Co-authored-by: tcflying <77509083+tcflying@users.noreply.github.com>
lidge-jun added a commit that referenced this pull request Sep 27, 2026
A service-home admission refusal in syncModelsToCodex returned without any
log line. Startup then marked /readyz failed with no evidence and `ocx sync`
only said the sync did not complete. Log one line naming the authority and
pointing to POST /api/sync for the specific reason. The admission message
can contain private home and service-definition paths, so it stays out of
the log.

Reimplements the diagnostic slice of #5782 without the raw message.

Co-authored-by: tcflying <77509083+tcflying@users.noreply.github.com>
lidge-jun added a commit that referenced this pull request Sep 27, 2026
A service-home admission refusal in syncModelsToCodex now leaves one path-free log line pointing to POST /api/sync, instead of silently failing /readyz and ocx sync. Reimplements the diagnostic slice of #5782 without logging private paths.

Co-authored-by: tcflying <77509083+tcflying@users.noreply.github.com>
lidge-jun added a commit that referenced this pull request Sep 27, 2026
* docs(devlog): plan release train 4 issue triage

* docs(devlog): record issue triage roadmap gate

* docs(devlog): record issue triage comments

* docs(devlog): record large PR release decisions

* docs(devlog): refine standalone carry verification

* docs(devlog): hand off issue triage lane

* docs(devlog): plan issue triage lane resume

* docs(devlog): require Windows CI dispatch for carry

* docs(devlog): record Sol re-verification, #6093 and #5782 slice

* docs(devlog): record issue triage lane outcome

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working intake: hygiene-blocked Deterministic PR hygiene checks failed priority: P3 Low: new provider/client integration, large or experimental feature (>2000 LOC or >50 files), RFC/ro

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants