[WRONG BRANCH] release: promote 2.73.0 to main - #6266
Conversation
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Use null instead of a synthetic opencodex comp_hash so native/routed switches do not imply incompatible history. Clear retained markers, preserve native metadata and token limits, and cover migration and aliases.
* docs(devlog): plan the 2.72.0 TokenLab release * docs(devlog): record TokenLab payment and final-copy findings * docs(devlog): record the #6240 regression gate and merge * docs(devlog): record the 2.72.0 promotions * docs(devlog): record the 2.72.0 release results * docs(devlog): close the TokenLab sponsor and 2.72.0 release units * docs(devlog): keep the dev pre-move out of the 2.72.0 contents * docs(devlog): name the final #6240 head in the gate step --------- Co-authored-by: t <a@b.com>
…thropic error event (#6235) * fix(claude): end a passthrough stream on an upstream reset with an Anthropic error event tapAnthropicSseForLog relays the streamed body of the native Anthropic passthrough and of the managed native Messages lane. When the upstream socket reset after the 200 had gone out, the read rejection was handed to controller.error(): the client saw a connection reset (Bun 1.4.0) or a bare chunked EOF (Bun 1.3.x) with no protocol terminal, Bun printed the error stack to the service log, and the request log recorded the truncated turn as 200 / closeReason "terminal", which classifies as completed. A read failure now ends the body the way a stall already did: a blank-line boundary, an Anthropic `event: error` frame (`api_error`), and a clean close. The row matches the Responses relay's onReadError: status 502, terminalStatus "failed", transportPhase "mid_stream", a synthetic terminal source, the attempt marked streamAborted, and the redacted reason in upstreamError. messages-native forwards terminalStatus to its final log. A translator budget overflow is a local cap, not an upstream failure, and keeps erroring the stream so the non-streaming fold still answers 413. * fix(claude): keep cancels and finished turns out of the passthrough reset path Review follow-up. A read failure that is not an upstream failure keeps a non-failure outcome: - the cancel signal is already aborted (Bun can reject the read before it dispatches the abort listener): 499 client_cancel, as relay.ts checks; - the managed lane's own abort (shutdown, turn release): the tap now gets the upstream controller's signal, so it is a cancel too; - message_stop or an upstream error event was already seen, including one still buffered without its blank-line delimiter: 200, no extra frame. The reset path also cancels the upstream reader like every other exit, the test fixture clears its pending socket timers on stop, and the tests assert this proxy's message prefix instead of Bun's error text. * docs(structure): state the passthrough read-failure exceptions without a count * fix(claude): close the non-streaming fold's reset row like the streaming one Review follow-up. The managed lane's non-streaming fold answered a mid-stream reset with fail(502), whose default meta closed the row as closeReason "non_stream" without a terminalStatus, while the streaming lane's row for the same reset is terminal + failed. The fold now finishes the row with the tap's meta when the tap reported a failed terminal. An upstream error event (no reset) keeps its existing row. The structure doc also states that the logged status differs by frame: a stall or the byte cap keeps 200 with body_stall/body_overflow (incomplete), a reset is 502 (failed). * docs(structure): name the local body limits apart from upstream read failures * fix(claude): restore a cut-off terminal's delimiter and keep the fold's tap verdict CodeRabbit follow-up (outside-diff findings on 21a21d8): - When the read fails after message_stop arrived without its blank line, the tap now appends "\n\n" before closing. An SSE parser does not dispatch an event that EOF cuts off, so the client would otherwise miss the terminal the tap had counted. - The managed lane's non-streaming fold closes its row with the tap's meta for a stall or the byte cap as well as a reset, so body_stall / body_overflow survive instead of becoming non_stream. A plain upstream error event keeps the non_stream row.
Use the pinned Qwen3.8-27B chat template contract to preserve chronological developer reminders as user turns on the translated Chat wire. Keep other models and native OpenAI behavior unchanged.
* fix(packaging): ship keyring native addon * fix(packaging): make keyring bundle proof load-only * fix(packaging): resolve keyring addon from wrapper scope * fix(keyring): prefer the standalone-owned addon * fix(packaging): verify compiled keyring roots * fix(ci): cover packaged keyring prerequisites * fix(ci): keep keyring probe under file-size ratchet * style(cli): keep private probes inside size gate * fix(packaging): resolve symlinked keyring wrapper Resolve the wrapper entrypoint before locating its optional native addon, so virtual-store package layouts stage the installed addon. Cover nested and symlinked layouts. --------- Co-authored-by: Ingwannu <ingwannu@users.noreply.github.com> Co-authored-by: JUN <jun@lidgeai.com>
The auxiliary quota fences added for pause also aborted on any selection change, so a report probe in flight during an active-account switch no longer seeded the probed account. Pause, reauth and a replaced token still stop the send; the reading stays attributed to the account that was probed.
#6234) (#6255) Carries #6234 by @vadymhimself: a 429 attributed to a pooled account that was itself cooled no longer cools the whole combo target, so healthy sibling accounts stay usable; unknown-account 429s still cool the target. Co-authored-by: Vadym O <bolein95@gmail.com>
# Conflicts: # scripts/test-layout/layout.json # src/oauth/anthropic-routing.ts # tests/fixtures/test-layout-expected.json
…carry #6238) (#6258) Carries #6238 by @lcBreathe (fixes #6237): the Windows standalone service wrapper is accepted by the ownership probe, and only a wrapper and registered task that match the standalone generator (quoted OCX_BUN assignment, generator markers and control flow, executable bound to the recorded install state, single wscript.exe Exec action with the exact launcher arguments) can claim ownership. Co-authored-by: lcBreathe <165003424+lcBreathe@users.noreply.github.com>
feat(oauth): support Anthropic account pause and resume
* feat(oauth): add per-account Anthropic usage thresholds * fix(oauth): preserve manual Anthropic threshold intent * test(cli): update Anthropic auto-switch rejection * fix(oauth): fence Anthropic threshold policy ownership * fix(oauth): return committed Anthropic threshold policy * fix(gui): reconcile Anthropic threshold state safely * fix(gui): satisfy threshold lifecycle lint --------- Co-authored-by: Ingwannu <ingwannu@users.noreply.github.com> Co-authored-by: JUN <jun@lidgeai.com>
* fix(responses): support canonical nonstream delivery * fix(responses): fold canonical SSE for compaction clients * fix(responses): align buffered SSE failure semantics * fix(responses): cancel deferred replay on client disconnect * fix(responses): redact upstream terminal diagnostics before delivery * docs(responses): keep terminal contract within structure budget * fix(responses): redact full failed terminals and synthetic stream errors Delay buffered serving-route publication until deferred replay survives the final abort check. * fix(responses): mask credential in synthetic refusal code * test(responses): include terminal redaction in core owner inventory * fix(responses): mask pooled credential in buffered bare errors * test(responses): abort synchronously in the deferred-replay disconnect case --------- Co-authored-by: Ingwannu <ingwannu@users.noreply.github.com> Co-authored-by: JUN <jun@lidgeai.com>
* fix(oauth): recover Anthropic reset cooldowns * docs(accounts): document Anthropic cooldown clear * docs(accounts): localize Anthropic cooldown clear * fix(oauth): fence Anthropic quota flights and cache ownership Retire old joinable usage flights during cooldown recovery, reject superseded failures before negative-cache publication, and retain live ownership for cached quota reads. * fix(quota): fence stale Anthropic token failures by cooldown flight --------- Co-authored-by: Ingwannu <ingwannu@users.noreply.github.com> Co-authored-by: JUN <jun@lidgeai.com>
#6261) * fix(keyring): compute packaged addon candidates with the target platform's path rules * test(keyring): cover target-platform path rules from a foreign host
…kenLab per-model wires (#6263) * docs(devlog): plan GPT-6.1 Sol rollout, default swap and TokenLab protocol routing * docs(devlog): record the GPT-6.1 Sol plan audit and JEV deferral * feat(models): add GPT-6.1 Sol across providers and make it the Sol default OpenAI released GPT-6.1 Sol on 2026-09-29 as the upgrade to GPT-6 Sol (Astra and Luna did not move). List it wherever GPT-6 Sol is served: the native Codex row (pinned verbatim from openai/codex models.json after #49318; low..ultra, default low, 272K/872K), the OpenAI API (1.05M / 922K / 128K, low..max), OpenRouter, GitHub Copilot (Responses), CodeBuddy/Kiro/Devin preemptive seeds, and the Bedrock/Cloudflare/Kilo/OpenCode Zen/Vercel metadata rows. Price it at $2 / $0.10 cached / $2.50 write / $10 with the long-context tier. Move every GPT-6 Sol default to GPT-6.1 Sol: the subagent roster default, the configured-native template, docker smoke and docs. Roster migration v3 swaps a bare gpt-6-sol in stored rosters once; GPT-6 Sol stays selectable. * feat(tokenlab): route each model over its declared wire TokenLab publishes per-model request formats (tokenlab.accepted_request_formats on GET /v1/models/{id}). Keep the released Chat preset as the provider-wide wire, and: - send gpt-6-astra, gpt-6.1-sol, gpt-6-sol, gpt-6-luna, grok-4.7, deepseek-v4.1-flash, deepseek-v4-pro, kimi-k3 and glm-5.3 over Responses for Responses inbound (Codex); Chat and Anthropic clients keep Chat, and an explicit modelAdapters entry still wins; - pin claude-* ids to Anthropic Messages (/v1/messages, x-api-key) through the endpoint-bound prefix pin Command Code uses, so a retargeted row is untouched; - leave gemini-3.8-flash and every other model on Chat. No delivery-policy header is sent; the API key policy stays authoritative. * docs(devlog): script the 2.73.0 release bundling RT6 * test(ci): docker smoke expects subagent roster version 3
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: Repository: lidge-jun/opencodex/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: ⛔ Files ignored due to path filters (2)
📒 Files selected for processing (258)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
✅ Deterministic PR hygiene checks passed. |
⏳ DRAFT
What to do
Its title has been prefixed with |
Summary
Promote the verified 2.73.0 tree to
mainas2.73.0. The tree isdevatcfa56e34df(#6263 squash).2.73.0 contents since v2.72.0: the RT6 train (#6230, #6236, #6248, #6235, #6249, #6161, #6247, #6255, #6258, #6204, #6207, #6200, #6203), #6261 (Windows keyring test portability), and #6263 (GPT-6.1 Sol across providers as the Sol default, TokenLab per-model wires).
Release authorization: the repository owner explicitly authorized this release on 2026-09-30 and asked to merge and release right after Cross-platform CI. The
devmaintainer-integration exception does not covermain; this promotion merges on that owner authorization, as 2.70.0–2.72.0 did.Verification
0a8096167cwith 28 PR checks green; itslane=allCross-platform CI (36642804429) runs on a tree identical tocfa56e34df.540af24384(RT6 + fix(keyring): target-platform path rules for packaged addon candidates #6261): run 36640672883 success.git diff --quiet cfa56e34df HEADholds: the promoted tree equals the dev commit.release.yml.Checklist