Skip to content

[WRONG BRANCH] release: 2.71.0 - #6228

Merged
lidge-jun merged 26 commits into
mainfrom
codex/promote-main-2.71.0
Sep 29, 2026
Merged

lidge-jun merged 26 commits into
mainfrom
codex/promote-main-2.71.0

Conversation

@lidge-jun

Copy link
Copy Markdown
Owner

Summary

Promote dev at d161c0e83e to main as 2.71.0. Candidate dev at d161c0e83e is #6224, which landed #6206, #6201, #6209, #6094, #5905 and #6198, plus the eight commits merged since 2.70.0 (#6217 Claude sampling/tool-choice contract, #6193, #6194, #6195, #6218 and housekeeping). The tree equals the candidate; its version sources already read 2.71.0. The -s ours merge keeps main history linear with the promotion.

Plan: devlog/_plan/260929_release_2_71_0/041_wp4_execution.md.

GUI changes in this promotion (from #6094 and #5905):

Provider request pacing with the Max concurrent requests field

Cursor integration page: local-mode installer notice for regular Cursor

Verification

  • git diff --quiet d161c0e83e HEAD: tree equal.
  • bun scripts/release-version-sources.ts check 2.71.0: 4 sources carry it.
  • Candidate CI on the chore(release): integrate six reviewed PRs for 2.71.0 #6224 head dcfbb2f708: Cross-platform CI pull_request 36525839698 and workflow_dispatch lane=all 36526719414 (windows 1-9) success; Service lifecycle 36525839767 success. The release dispatch waits for push-event Cross-platform CI and Service lifecycle on this merge SHA.

Checklist

  • Scope stays focused and avoids unrelated cleanup.
  • Docs or release notes were updated when needed.
  • Security-sensitive changes were reviewed for secrets, auth, and unsafe defaults.

github-actions Bot and others added 26 commits September 29, 2026 04:54
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
* docs(devlog): plan 2.70.0 release

* docs(devlog): fold release plan audit

* docs(devlog): record Sonnet 5.5 rollout and 2.70.0 release outcome
…very Claude family (#6217)

* docs(devlog): plan Claude contract hardening and PR carries

* docs(devlog): fold hardening plan audit

* fix(anthropic): apply the live sampling and tool-choice contract to every Claude family

A live probe of api.anthropic.com on 2026-09-29 showed the Sonnet 5.5 rules
from #6210 were narrower than the upstream contract:

- Opus 4.7+, Sonnet 5+ and every Fable return 400 on any non-default
  temperature/top_p, with or without thinking. The adapter only dropped them
  when it sent thinking, so a no-reasoning request with temperature failed.
- Haiku 4.5, Sonnet 4.5/4.6 and Opus 4.5/4.6 take either field alone but 400
  when both are sent; top_p is now dropped when both are present.
- Fable 5.1 rejects forced tool_choice like Opus 5.5; it now degrades to auto.
- Opus 5.5 and Fable reject both thinking disabled and between_tools, so the
  web-search and vision sidecars send a low effort and no thinking field for
  them (verified to end_turn with text inside a 1,024-token budget).

Plan, audit and evidence: devlog/_plan/260929_dev_next_hardening_carry/.
* fix(link): reject forged ss owner tuples before trusting a PID

parseListenEntriesFromSs attributed a listener with /pid=(\d+)/ over
the whole row. ss prints comm unescaped between quotes, so a crafted
15-byte task name containing an embedded quote plus pid= text lands a
forged pid field ahead of the real tuple — a local process could make
reclaim/join logic blame (or kill) an innocent PID.

Replace the row-wide regex with a strict users:(...) tuple parser:
quoted name taken verbatim, then pid= plus only the field keys ss is
known to emit (fd, ino, sk, v6only) inside the tuple boundary. Any
grammar deviation — a second quoted segment, an unknown key, trailing
garbage — drops the row's attribution entirely rather than trusting a
partial parse. Shared sockets still report every owner tuple.

* fix(link): require fd= on each accepted ss owner tuple

---------

Co-authored-by: luvs01 <27862058+luvs01@users.noreply.github.com>
…6195)

* fix(codex): preserve drift-heal ownership veto before config writes

healCodexConfigDrift re-injected missing routing roots whenever the
journal said they had drifted, without checking service-home
ownership — the same admission unattended sync requires. A heal tick
inside a no-longer-owned home could write config keys over a client
that now belongs to someone else.

Gate the heal on admitCodexWrite: a service-home refusal returns
not-healed before the injector is even called, and beforeClientWrite
re-runs the admission so ownership lost mid-write still throws.
Other refusal authorities (config/generation/external-provider) do
not block — they are not this heal's verdict.

* fix(codex): veto drift heal on unowned homes at both write boundaries

---------

Co-authored-by: luvs01 <27862058+luvs01@users.noreply.github.com>
An untrusted transcript can hold tens of thousands of unmatched
<conversation> openings. The greedy /<conversation>[\s\S]*<\/conversation>/i
scan re-walks the tail for every opening position, giving quadratic
regex backtracking and event-loop blocking inside request handling.

Replace it with two fixed-tag scans: an anchored case-insensitive
/<conversation>/i exec, then a /<\/conversation>/gi search resumed
from after that opening. Both run in place over the transcript — no
lowercased copy, whose second body-sized string would roughly double
peak memory for requests that can reach hundreds of MiB.

Regression tests pin the behavior with deterministic probes instead
of a wall-clock bound: every transcript scan must be one of the two
fixed tag patterns (a greedy [\s\S]* pass fails that assertion even
though it only scans once), and no transcript-sized normalized copy
may be allocated.

Co-authored-by: luvs01 <27862058+luvs01@users.noreply.github.com>
…#6218)

Carries #6089: .usw-section .tbl-wrap becomes the containing block for the absolutely positioned sr-only cache-rate captions, so their overflow stays inside the table scrollport instead of extending the outer document.

Co-authored-by: Jian Gong <fflake33@icloud.com>
Lands #6206 at head 46bf1c9 on dev through the 2.71.0 integration branch.
…profile (#6201)

Lands #6201 at head 986f9a0 on dev through the 2.71.0 integration branch.

Co-authored-by: Epinephrine <luvs01@hanmail.net>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
…ost cannot starve /healthz (#6209)

Lands #6209 at head 8fb990d on dev through the 2.71.0 integration branch.

Closes #6208.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…tings (#6094)

Lands #6094 at head de9880f on dev through the 2.71.0 integration branch.
…regular Cursor (#5905)

Lands #5905 at head 2b3dacd on dev through the 2.71.0 integration branch.

Co-authored-by: codingbooo <9621077+codingbooo@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
#6198)

Lands #6198 at head 8dbb264 on dev through the 2.71.0 integration branch.

Co-authored-by: Epinephrine <luvs01@hanmail.net>
…uota design

Review follow-up for #6206: two citations named files without their directory, and the
admission contract did not say what happens on a 3xx response (CodeRabbit thread
PRRT_kwDOS-0Gi86mz4CC).
Review follow-up for #6209: the reference said a saturated host no longer delays the probe past
its ceilings, but the PR's own measurement shows p90 3.0s at full saturation. State what the boost
does and does not guarantee.
Review follow-up for #6198: the comment carried two literal question marks where a dash was
meant.
… budget

The case registers 32 profiles through the real transaction path; each registration performs
several fsync'd atomic writes (and ACL hardening on Windows), and those writes are what the
test asserts. It normally takes 0.45s on windows-latest, drifted to 2.7-6.9s on dev dispatch
runs, and hit 35.0s against its 30s budget in Cross-platform CI run 36499924172 (windows 8/9),
turning the dev tip red with no code change. BULK_DURABLE_IO_BUDGET_MS (180s on Windows, 90s
elsewhere) is the budget tests/helpers/test-budget.ts defines for this kind of work; no
assertion depends on it, so a regression still fails.
chore(release): integrate six reviewed PRs for 2.71.0
@lidge-jun
lidge-jun requested a review from Ingwannu as a code owner September 29, 2026 06:07
@github-actions

Copy link
Copy Markdown
Contributor

✅ Deterministic PR hygiene checks passed.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Repository: lidge-jun/opencodex/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 6b67f4ff-0d54-480d-ac79-d390b4b1b201

📥 Commits

Reviewing files that changed from the base of the PR and between 53834ff and e272476.

⛔ Files ignored due to path filters (1)
  • desktop/src-tauri/Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (100)
  • desktop/src-tauri/Cargo.toml
  • desktop/src-tauri/tauri.conf.json
  • devlog/_fin/260929_dev_next_hardening_carry/010_plan.md
  • devlog/_fin/260929_dev_next_hardening_carry/030_done_wp2.md
  • devlog/_fin/260929_dev_next_hardening_carry/090_outcome.md
  • devlog/_fin/260929_sonnet_5_5_catalog/010_plan.md
  • devlog/_fin/260929_sonnet_5_5_catalog/020_audit.md
  • devlog/_fin/260929_sonnet_5_5_catalog/030_done.md
  • devlog/_fin/260929_sonnet_5_5_catalog/040_plan_release.md
  • devlog/_fin/260929_sonnet_5_5_catalog/090_outcome_release.md
  • devlog/_plan/260928_macos_quota_gate/000_design.md
  • devlog/_plan/260929_release_2_71_0/000_plan.md
  • devlog/_plan/260929_release_2_71_0/001_consultation.md
  • devlog/_plan/260929_release_2_71_0/010_integration.md
  • devlog/_plan/260929_release_2_71_0/011_wp1_execution.md
  • devlog/_plan/260929_release_2_71_0/020_verification.md
  • devlog/_plan/260929_release_2_71_0/021_wp2_execution.md
  • devlog/_plan/260929_release_2_71_0/022_wp2_results.md
  • devlog/_plan/260929_release_2_71_0/030_land.md
  • devlog/_plan/260929_release_2_71_0/031_wp3_execution.md
  • devlog/_plan/260929_release_2_71_0/040_release.md
  • docs-site/src/content/docs/fr/guides/cursor-private-inference.md
  • docs-site/src/content/docs/guides/cursor-private-inference.md
  • docs-site/src/content/docs/ja/guides/cursor-private-inference.md
  • docs-site/src/content/docs/ko/guides/cursor-private-inference.md
  • docs-site/src/content/docs/reference/cli.md
  • docs-site/src/content/docs/ru/guides/cursor-private-inference.md
  • docs-site/src/content/docs/tr/guides/cursor-private-inference.md
  • docs-site/src/content/docs/zh-cn/guides/cursor-private-inference.md
  • docs-site/src/content/docs/zh-tw/guides/cursor-private-inference.md
  • gui/src/components/provider-workspace/ProviderSettings.tsx
  • gui/src/i18n/de.ts
  • gui/src/i18n/en.ts
  • gui/src/i18n/fr.ts
  • gui/src/i18n/ja.ts
  • gui/src/i18n/ko.ts
  • gui/src/i18n/ru.ts
  • gui/src/i18n/tr.ts
  • gui/src/i18n/vi.ts
  • gui/src/i18n/zh-TW.ts
  • gui/src/i18n/zh.ts
  • gui/src/pages/integrations/CursorIntegrationPage.tsx
  • gui/src/pages/integrations/cursor-api.ts
  • gui/src/provider-workspace/catalog.ts
  • gui/src/styles-usage-workspace.css
  • gui/src/styles/provider-workspace-settings.css
  • gui/tests/cursor-integration-page.test.tsx
  • gui/tests/provider-settings-request-pacing.test.tsx
  • gui/tests/usage-custom-range.test.tsx
  • gui/tests/usage-scroll-browser.ts
  • gui/tests/usage-scroll-containment.test.ts
  • package.json
  • scripts/test-layout/layout.json
  • skills/ocx/references/01_management_surface.md
  • src/adapters/anthropic-model-contract.ts
  • src/adapters/anthropic.ts
  • src/adapters/openai-chat/summary-budget.ts
  • src/claude/desktop-picker.ts
  • src/claude/intercept/local-ca.ts
  • src/claude/intercept/picker-ca.ts
  • src/cli/capabilities.ts
  • src/cli/claude-desktop.ts
  • src/cli/cross-home-owner.ts
  • src/cli/index.ts
  • src/codex/catalog-auto-refresh.ts
  • src/config/owner-registry.ts
  • src/config/process-state.ts
  • src/integrations/cursor-detect.ts
  • src/integrations/cursor-local-installer.ts
  • src/server/management/cursor-integration-routes.ts
  • src/server/management/route-registry.ts
  • src/server/port-reclaim.ts
  • src/server/proxy-liveness.ts
  • src/service/windows-process-priority.ts
  • src/vision/anthropic-describe.ts
  • src/web-search/anthropic-executor.ts
  • structure/clients/claude-desktop.md
  • structure/clients/integrations.md
  • structure/codex-home.md
  • structure/config.md
  • structure/dashboard-and-usage.md
  • structure/providers-and-adapters.md
  • structure/providers/chat-compat.md
  • structure/remote-link.md
  • structure/runtime.md
  • tests/adapters/anthropic/anthropic-reasoning.test.ts
  • tests/adapters/anthropic/anthropic-sonnet-5-5-contract.test.ts
  • tests/adapters/openai/openai-chat-glm-summary.test.ts
  • tests/claude-integration/claude-desktop-cli.test.ts
  • tests/claude-integration/claude-picker-ca.test.ts
  • tests/cli/cli-dispatch.test.ts
  • tests/cli/sibling-home-client-sync.test.ts
  • tests/codex-integration/catalog-auto-refresh-scheduler.test.ts
  • tests/codex-integration/native-profile-manager.test.ts
  • tests/fixtures/test-layout-expected.json
  • tests/providers/cursor/cursor-integration-status.test.ts
  • tests/providers/cursor/cursor-local-installer.test.ts
  • tests/server/port-reclaim.test.ts
  • tests/server/proxy-liveness-package-tree-fence.test.ts
  • tests/windows/windows-process-priority.test.ts
 ___________________________
< I refactor in bunny hops. >
 ---------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@lidge-jun
lidge-jun merged commit 8a005dd into main Sep 29, 2026
30 of 38 checks passed
@lidge-jun
lidge-jun deleted the codex/promote-main-2.71.0 branch September 29, 2026 06:08
@github-actions github-actions Bot changed the title release: 2.71.0 [WRONG BRANCH] release: 2.71.0 Sep 29, 2026
@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

⏳ DRAFT

  • wrong target branch (main); retarget to dev.

What to do

  • Retarget this PR to dev — all contributions go to dev.

Its title has been prefixed with [WRONG BRANCH].
Automatic draft conversion failed (token cannot change draft status). Please convert this pull request to a draft manually. The required enforce-target check will keep failing until every issue above is resolved.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T06:08:44.915989Z e272476 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants