Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
30 commits
Select commit Hold shift + click to select a range
4bcbf53
feat(oauth): support Anthropic account pause and resume
Ingwannu Sep 28, 2026
aea8b56
fix(oauth): preserve Anthropic pause refusals after pacing
Ingwannu Sep 28, 2026
60d1d3c
fix(oauth): retain scoped cooldown refusals after pacing
Ingwannu Sep 28, 2026
33e2cab
fix(oauth): preserve mixed-state Anthropic admission errors
Ingwannu Sep 28, 2026
9320009
test(oauth): drain failed pacing setup
Ingwannu Sep 28, 2026
132770d
fix(oauth): align native Messages account admission
Ingwannu Sep 28, 2026
73289d4
chore(release): open dev at 2.73.0 before releasing 2.72.0 (#6243)
github-actions[bot] Sep 29, 2026
41cc5de
fix(oauth): recheck Anthropic pause before auxiliary sends
lidge-jun Sep 29, 2026
f966c9f
fix(cursor): redirect native tool denials through code-mode exec (#6230)
lilinxiong Sep 29, 2026
d3d076c
fix(catalog): leave routed compaction compatibility unknown (#6236)
colthreepv Sep 29, 2026
f53f0c6
docs(devlog): record the 2.72.0 TokenLab release (#6250)
lidge-jun Sep 29, 2026
cbf5faa
fix(bridge): preserve rate-limit retry advice for Codex (carry #6225)…
lidge-jun Sep 29, 2026
ea7bd16
fix(claude): end a passthrough stream on an upstream reset with an An…
sh940701 Sep 29, 2026
6da09f6
fix(chat): keep Qwen3.8 reminders valid after first turn (#6249)
lidge-jun Sep 29, 2026
e41b5fc
Merge remote-tracking branch 'origin/dev' into codex/rt6-l2e-6204
lidge-jun Sep 29, 2026
8aa3c86
docs(structure): split Anthropic account pool contract
lidge-jun Sep 29, 2026
3092b55
fix(packaging): ship keyring native addon with desktop sidecar (#6161)
Ingwannu Sep 29, 2026
0126cb4
fix(oauth): let quota probes survive an active-account switch
lidge-jun Sep 29, 2026
48470c3
fix(responses): strip internal summary:none marker on the wire (#6247)
lidge-jun Sep 29, 2026
99878c3
fix(combos): a spent pool account must not cool the whole target (car…
lidge-jun Sep 29, 2026
36a12fc
fix(quota): suppress switched Anthropic provider report
lidge-jun Sep 29, 2026
b8d0662
Merge remote-tracking branch 'origin/dev' into HEAD
lidge-jun Sep 29, 2026
be218ba
fix(service): accept standalone Windows wrappers in ownership probe (…
lidge-jun Sep 29, 2026
f2771cf
Merge pull request #6204 from lidge-jun/fix/6013-anthropic-pause
lidge-jun Sep 29, 2026
eafa6bc
feat(oauth): add per-account Anthropic usage thresholds (#6207)
Ingwannu Sep 29, 2026
dad107c
fix(responses): support canonical non-streaming delivery (#6200)
Ingwannu Sep 29, 2026
b78bfb8
fix(oauth): recover Anthropic reset cooldowns (#6203)
Ingwannu Sep 29, 2026
540af24
fix(keyring): target-platform path rules for packaged addon candidate…
lidge-jun Sep 29, 2026
cfa56e3
feat(models): GPT-6.1 Sol across providers as the Sol default, and To…
lidge-jun Sep 29, 2026
6be91b7
Merge main into 2.73.0 promotion
lidge-jun Sep 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 13 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -261,6 +261,10 @@ jobs:
- 'src/service/**'
- 'src/cli/index.ts'
- 'src/lib/bun-runtime.ts'
- 'src/lib/standalone.ts'
- 'src/lib/keyring-native.ts'
- 'scripts/build-standalone.ts'
- 'scripts/standalone-keyring.ts'
- 'package.json'
- 'bun.lock'
- '.github/workflows/ci.yml'
Expand All @@ -276,6 +280,7 @@ jobs:
- 'gui/**'
- 'src/**'
- 'scripts/build-standalone.ts'
- 'scripts/standalone-keyring.ts'
- 'scripts/standalone-targets.ts'
- 'package.json'
- 'bun.lock'
Expand Down Expand Up @@ -1400,10 +1405,11 @@ jobs:
run: |
set -euo pipefail
triple="$(rustc -vV | sed -n 's/^host: //p')"
mkdir -p desktop/src-tauri/binaries desktop/src-tauri/resources/gui/dist
mkdir -p desktop/src-tauri/binaries desktop/src-tauri/resources/gui/dist desktop/src-tauri/resources/keyring
: > "desktop/src-tauri/binaries/ocx-${triple}"
chmod +x "desktop/src-tauri/binaries/ocx-${triple}"
: > desktop/src-tauri/resources/gui/dist/.keep
: > desktop/src-tauri/resources/keyring/.keep

- name: Check Rust formatting
run: cargo fmt --manifest-path desktop/src-tauri/Cargo.toml --check
Expand Down Expand Up @@ -1461,6 +1467,12 @@ jobs:
cp -a "$DEB_BUNDLE/." "$BUNDLE_ROOT/deb/"
chmod -R a-w "$BUNDLE_ROOT"

- name: Verify packaged Linux sidecar keyring
if: needs.changes.outputs.desktop == 'true'
env:
BUNDLE_ROOT: ${{ runner.temp }}/opencodex-linux-bundles
run: bash desktop/scripts/verify-linux-sidecar.sh "$BUNDLE_ROOT/appimage"

- name: Run Linux packaged-shell E2E
if: needs.changes.outputs.desktop == 'true'
env:
Expand Down
33 changes: 29 additions & 4 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -126,18 +126,28 @@ jobs:
include:
- os: ubuntu-latest
target: bun-linux-x64
dependency_os: linux
dependency_cpu: x64
smoke: true
- os: macos-latest
target: bun-darwin-arm64
dependency_os: darwin
dependency_cpu: arm64
smoke: true
- os: macos-latest
target: bun-darwin-x64
dependency_os: darwin
dependency_cpu: x64
smoke: false
- os: windows-latest
target: bun-windows-x64
dependency_os: win32
dependency_cpu: x64
smoke: true
- os: ubuntu-latest
target: bun-linux-arm64
dependency_os: linux
dependency_cpu: arm64
smoke: false
runs-on: ${{ matrix.os }}
timeout-minutes: 25
Expand All @@ -153,7 +163,7 @@ jobs:
uses: ./.github/actions/setup-project-bun

- name: Install dependencies
run: bun install --frozen-lockfile
run: bun install --frozen-lockfile --os=${{ matrix.dependency_os }} --cpu=${{ matrix.dependency_cpu }}

- name: Build dashboard
run: bun run build:gui
Expand Down Expand Up @@ -200,9 +210,9 @@ jobs:
set -euo pipefail
cd "dist/standalone/$STANDALONE_TARGET"
if [[ "$RUNNER_OS" == "Windows" ]]; then
powershell -NoProfile -Command 'Compress-Archive -Path ocx.exe,gui -DestinationPath ("../../ocx-{0}-{1}.zip" -f $env:RELEASE_VERSION,$env:STANDALONE_TARGET) -Force'
powershell -NoProfile -Command 'Compress-Archive -Path ocx.exe,gui,keyring -DestinationPath ("../../ocx-{0}-{1}.zip" -f $env:RELEASE_VERSION,$env:STANDALONE_TARGET) -Force'
else
tar -czf "../../ocx-${RELEASE_VERSION}-${STANDALONE_TARGET}.tar.gz" ocx gui
tar -czf "../../ocx-${RELEASE_VERSION}-${STANDALONE_TARGET}.tar.gz" ocx gui keyring
fi
cd ../..
# The pre-publication verifier resolves every recorded checksum from
Expand Down Expand Up @@ -232,16 +242,22 @@ jobs:
include:
- os: macos-latest
target: universal-apple-darwin
dependency_os: darwin
dependency_cpu: "*"
bundles: app,dmg
sidecar-targets: macos
artifact-suffixes: macos.dmg,macos.app.tar.gz
- os: windows-latest
target: x86_64-pc-windows-msvc
dependency_os: win32
dependency_cpu: x64
bundles: msi
sidecar-targets: x86_64-pc-windows-msvc
artifact-suffixes: windows-x64.msi
- os: ubuntu-22.04
target: x86_64-unknown-linux-gnu
dependency_os: linux
dependency_cpu: x64
bundles: appimage,deb
sidecar-targets: x86_64-unknown-linux-gnu
artifact-suffixes: linux-x86_64.AppImage,linux-amd64.deb
Expand Down Expand Up @@ -275,7 +291,7 @@ jobs:
run: bun scripts/release-version-sources.ts check "$RELEASE_VERSION"

- name: Install project dependencies
run: bun install --frozen-lockfile
run: bun install --frozen-lockfile --os=${{ matrix.dependency_os }} --cpu=${{ matrix.dependency_cpu }}

- name: Build dashboard
run: bun run build:gui
Expand Down Expand Up @@ -430,6 +446,15 @@ jobs:
# diagnostics on the first attempt; Apple signing commands stay non-verbose.
run: bunx tauri ${{ runner.os == 'Linux' && '--verbose' || '' }} build --ci --target ${{ matrix.target }} --bundles ${{ matrix.bundles }} --config "${{ runner.os == 'Windows' && format('{0}/opencodex-msi.json', runner.temp) || '{}' }}"

- name: Verify the packaged universal macOS runtime
if: runner.os == 'macOS'
run: |
set -euo pipefail
app=desktop/src-tauri/target/universal-apple-darwin/release/bundle/macos/OpenCodex.app
test -f "$app/Contents/Resources/keyring/keyring.darwin-arm64.node"
test -f "$app/Contents/Resources/keyring/keyring.darwin-x64.node"
bash desktop/scripts/verify-macos-runtime.sh "$app"

# Tauri patches a bundle-type marker into the application binary for each Linux format.
# Keep each format in its own Cargo target so the deb cannot inherit the AppImage marker
# and linuxdeploy cannot mutate the binary later consumed by the deb build.
Expand Down
5 changes: 4 additions & 1 deletion desktop/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,10 @@ bunx tauri dev
```

The sidecar is generated from the repository's standalone binary build and is
not checked into git.
not checked into git. That build also stages the target-matching native keyring addon
under `keyring/`; Tauri copies it as a resource because Bun cannot load a `.node` addon
from the compiled executable's virtual filesystem. Universal macOS preparation requires
both Darwin optional packages (`bun install --frozen-lockfile --os=darwin --cpu=*`).

The macOS tray panel is a SwiftUI/AppKit static library built from
`app/Sources/NativeTray` by the Rust build script and linked into this process.
Expand Down
23 changes: 12 additions & 11 deletions desktop/scripts/prepare-sidecar.ts
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
import { copyFileSync, cpSync, existsSync, mkdirSync } from "node:fs";
import { copyFileSync, cpSync, mkdirSync } from "node:fs";
import { join, resolve } from "node:path";
import { adHocSignSidecar, shouldAdHocSignSidecar } from "./sidecar-signing";

Expand Down Expand Up @@ -38,20 +38,20 @@ if (!triple || !targetByTriple[triple]) {
const target = targetByTriple[triple];
const source = join(repoRoot, "dist", "standalone", target);
const executable = join(source, target.startsWith("bun-windows-") ? "ocx.exe" : "ocx");
if (!existsSync(executable)) {
const result = Bun.spawnSync([
process.execPath,
"run",
"build:standalone",
"--target",
target,
], { cwd: repoRoot, stdout: "inherit", stderr: "inherit" });
if (result.exitCode !== 0) process.exit(result.exitCode);
}
// Preparation must consume this checkout, never a stale executable/addon pair left in dist.
const result = Bun.spawnSync([
process.execPath,
"run",
"build:standalone",
"--target",
target,
], { cwd: repoRoot, stdout: "inherit", stderr: "inherit" });
if (result.exitCode !== 0) process.exit(result.exitCode);

const desktopRoot = resolve(import.meta.dir, "..");
const binaries = join(desktopRoot, "src-tauri", "binaries");
const resources = join(desktopRoot, "src-tauri", "resources", "gui", "dist");
const keyringResources = join(desktopRoot, "src-tauri", "resources", "keyring");
mkdirSync(binaries, { recursive: true });
mkdirSync(resources, { recursive: true });
const destination = join(binaries, `ocx-${triple}${target.startsWith("bun-windows-") ? ".exe" : ""}`);
Expand All @@ -60,5 +60,6 @@ if (shouldAdHocSignSidecar(process.platform, target)) {
const signed = adHocSignSidecar(destination);
if (signed !== 0) process.exit(signed);
}
cpSync(join(source, "keyring"), keyringResources, { recursive: true });
cpSync(join(repoRoot, "gui", "dist"), resources, { recursive: true });
console.log(`Prepared ${destination}`);
9 changes: 9 additions & 0 deletions desktop/scripts/verify-linux-sidecar.sh
Original file line number Diff line number Diff line change
Expand Up @@ -18,8 +18,17 @@ trap 'rm -rf "$scratch"' EXIT
cd "$scratch"
"${images[0]}" --appimage-extract > /dev/null
sidecar="$scratch/squashfs-root/usr/bin/ocx"
keyring="$scratch/squashfs-root/usr/lib/OpenCodex/keyring/keyring.linux-x64-gnu.node"
test ! -L "$sidecar"
test -f "$keyring"
cmp "$original" "$sidecar"
sha256sum "$original" "$sidecar"
mkdir "$scratch/home"
timeout 30s env OPENCODEX_HOME="$scratch/home" "$sidecar" --version
timeout 15s env HOME="$scratch/home" OPENCODEX_HOME="$scratch/home/opencodex" \
"$sidecar" __keyring-load-check > "$scratch/keyring.json"
python3 - "$scratch/keyring.json" <<'PY'
import json, pathlib, sys
value = json.loads(pathlib.Path(sys.argv[1]).read_text())
assert value == {"schema": "ocx-keyring-load/1", "available": True}, "Packaged keyring binding is unavailable"
PY
36 changes: 33 additions & 3 deletions desktop/scripts/verify-macos-runtime.sh
Original file line number Diff line number Diff line change
@@ -1,12 +1,16 @@
#!/usr/bin/env bash
set -euo pipefail

app="${1:?usage: verify-macos-runtime.sh /path/to/OpenCodex.app}"
app_input="${1:?usage: verify-macos-runtime.sh /path/to/OpenCodex.app}"
app="$(cd "$(dirname "$app_input")" && pwd)/$(basename "$app_input")"
[[ "$(uname -s)" == Darwin ]] || { echo 'macOS bundle verification requires macOS' >&2; exit 1; }
executable="$(/usr/libexec/PlistBuddy -c 'Print :CFBundleExecutable' "$app/Contents/Info.plist")"
[[ -n "$executable" && "$executable" != */* ]] || { echo 'Invalid app executable name' >&2; exit 1; }
scratch="$(mktemp -d "${TMPDIR:-/tmp}/opencodex-bundle-check.XXXXXX")"
trap 'rm -rf "$scratch"' EXIT
cleanup() {
rm -rf "$scratch"
}
trap cleanup EXIT

codesign --verify --strict --deep "$app"
verify_member() {
Expand Down Expand Up @@ -39,4 +43,30 @@ value = json.loads(pathlib.Path(sys.argv[1]).read_text())
assert value.get("schema") == "ocx-resolve/1", "Unexpected resolve schema"
assert value.get("liveness", {}).get("status") in ("live", "absent-proven"), "Unusable resolve result"
PY
printf '%s\n' 'PASS: macOS signatures, exact entitlements, hardened runtime, Liquid Glass and bundled CLI resolve'

# Reproduce the packaged-keyring boundary from an unrelated cwd. This is deliberately load-only:
# an ad-hoc CI identity can trigger a Keychain consent dialog, while issue #6139 is module resolution.
mkdir -p "$scratch/home" "$scratch/work"
python3 - "$app/Contents/MacOS/ocx" "$scratch/work" "$scratch/home" "$scratch/keyring.json" <<'PY'
import os, pathlib, subprocess, sys
ocx, work, home, output = sys.argv[1:]
env = os.environ.copy()
env.update(HOME=home, OPENCODEX_HOME=str(pathlib.Path(home) / ".opencodex"))
try:
with open(output, "wb") as stdout:
subprocess.run(
[ocx, "__keyring-load-check"], cwd=work, env=env, stdout=stdout,
stderr=subprocess.PIPE, check=True, timeout=15,
)
except subprocess.TimeoutExpired as error:
raise SystemExit("Packaged keyring load probe timed out") from error
except subprocess.CalledProcessError as error:
sys.stderr.buffer.write((error.stderr or b"")[-4096:])
raise SystemExit(f"Packaged keyring load probe exited {error.returncode}") from error
PY
python3 - "$scratch/keyring.json" <<'PY'
import json, pathlib, sys
value = json.loads(pathlib.Path(sys.argv[1]).read_text())
assert value == {"schema": "ocx-keyring-load/1", "available": True}, "Packaged keyring binding is unavailable"
PY
printf '%s\n' 'PASS: macOS signatures, entitlements, hardened runtime, Liquid Glass, bundled CLI resolve and packaged keyring'
2 changes: 1 addition & 1 deletion desktop/src-tauri/Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion desktop/src-tauri/Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[package]
name = "opencodex-desktop"
version = "2.72.0"
version = "2.73.0"
description = "OpenCodex desktop shell"
authors = ["OpenCodex contributors"]
license = "MIT"
Expand Down
5 changes: 3 additions & 2 deletions desktop/src-tauri/tauri.conf.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"$schema": "https://schema.tauri.app/config/2",
"productName": "OpenCodex",
"version": "2.72.0",
"version": "2.73.0",
"identifier": "com.opencodex.desktop",
"build": {
"frontendDist": "../ui",
Expand All @@ -22,7 +22,8 @@
"binaries/ocx"
],
"resources": {
"resources/gui/dist": "gui/dist"
"resources/gui/dist": "gui/dist",
"resources/keyring": "keyring"
},
"icon": [
"icons/icon.icns",
Expand Down
46 changes: 46 additions & 0 deletions devlog/_fin/260928_anthropic_cooldown_recovery/000_decision.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
# Anthropic cooldown recovery ownership

## Decision log

- Purpose: let an authoritative Anthropic usage refresh release a stale reset-derived
cooldown without weakening explicit upstream backoff or clearing another account's state.
- Existing constraints: routing health is process-local, usage probes are asynchronous, and
credentials or a newer 429 can replace the state observed when a probe starts.
- Alternatives considered: clear every cooldown after any successful usage response; clear
only through the operator endpoint; or bind recovery to the observed refusal and credential.
- Decision: a probe captures the exact account credential generation and cooldown generation
before dispatch. Settlement requires the same live credential, the same reset-derived
cooldown, a fresh timestamp, and utilization below 100% for every window that the 429 marked
rejected. Account-level single-flight keys also include an active recovery generation, so a
forced post-429 refresh cannot join work dispatched before the refusal. Any later cooldown
mutation revokes publication ownership as well as settlement ownership. Partial, failed,
exhausted, stale, Retry-After, and default-backoff evidence does not recover anything.
- Why this option: a successful quota HTTP response alone says neither which credential it
measured nor whether a newer refusal arrived while it was in flight. Generation fences make
those ownership claims explicit while preserving the existing manual escape hatch.
- Impact and trade-off: recovered accounts re-enter routing immediately; uncertain evidence
remains fail-closed until expiry or `clear-cooldown`. The extra bookkeeping is process-local
and bounded to one generation plus one health record per account. Superseded probes return an
unavailable result instead of publishing quota that no longer describes the routing state.

## Data flow

1. A 429 records its source, rejected quota windows, and a monotonic cooldown generation.
2. A fresh usage probe captures that generation plus the stored credential generation.
When recovery is pending, both the provider-usage flight and the outer account-quota flight
are generation-scoped, so the probe dispatches after the claim instead of joining older work
that might describe pre-refusal state.
3. The usage response is parsed and checked for complete headroom evidence.
4. Publication and settlement both require the observed cooldown generation to remain current.
Settlement deletes only the still-matching reset-derived record.

The CLI dispatches `openai` to `/api/codex-auth/accounts/clear-cooldown` and `anthropic` to
`/api/oauth/accounts/clear-cooldown`. Anthropic IDs and aliases are resolved through the OAuth
account list before the write; other providers remain rejected because they do not expose this
process-local cooldown owner.

## Focused verification

- `tests/providers/anthropic-cooldown-recovery.test.ts`
- `tests/cli/cli-account-pool-verbs.test.ts`
- `tests/adapters/anthropic/anthropic-ratelimit-headers.test.ts`
17 changes: 17 additions & 0 deletions devlog/_fin/260930_release_2_72_0/000_plan.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
# 2.72.0 — TokenLab release

Owner request (2026-09-30): merge the TokenLab sponsor PR, verify for regressions, release, check
TokenLab's payment in the WORKS inbox through Aside, and have Aside email Vincent.

Previous unit: `devlog/_fin/260929_tokenlab_sponsor/` merged #6221 (preset, `f6cddd7d69`) and opened
#6240 (sponsor placement + CLI pinning, head `21cddd35c9`, 32/32 PR checks green). Release shape is
2.71.0 (`devlog/_fin/260929_release_2_71_0/040_release.md`).

| Doc | Work phase | Outcome |
|-----|-----------|---------|
| [010](./010_merge_6240.md) | wp2 | #6240 merged on full-lane CI (incl. windows 1–9) at its exact head |
| [020](./020_release.md) | wp3 | npm latest 2.72.0, preview 2.72.0-preview.20260930, GitHub releases, gitHead |
| [030](./030_payment_and_email.md) | wp4 | Payment/DocuSign status from WORKS; Vincent emailed by Aside exec; outcome recorded |

Release content since v2.71.0: #6221 (TokenLab preset), #6240 (sponsor placement, CLI sponsor
pinning), devlog-only commits.
14 changes: 14 additions & 0 deletions devlog/_fin/260930_release_2_72_0/010_merge_6240.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
# 010 — Regression gate and merge #6240 (wp2)

1. Dispatch full-lane Cross-platform CI on the PR head:
`gh workflow run ci.yml -R lidge-jun/opencodex --ref codex/tokenlab-sponsor -f lane=all`
(the pull_request event skips windows 1–9 and macOS control; 2.71.0 used the same dispatch).
Required: every job success, windows 1/9–9/9 present, on the final head `2b9295fea6` (the run on `21cddd35c9` was cancelled when the final sponsor copy landed; see 030).
2. Local regression scope: the lanes' focused tests plus `test:changed`; the full local suite is
not runnable from a worktree under `~/.codex` (test home guard), so CI is the full-suite proof.
3. `scripts/ci/assert-mergeable-review.sh --maintainer-integration 6240 lidge-jun/opencodex`, a PR
comment recording owner authorization, exact head and run IDs: PR-event Cross-platform CI,
Service lifecycle (triggered by `desktop/**` and `package.json`), and the `lane=all` dispatch.
4. `gh pr merge 6240 --admin --squash --match-head-commit <head>`. C is that exact squash commit,
fixed before anything else lands on `dev`; assert `git show C:package.json` reads 2.72.0.
The `260929_tokenlab_sponsor` plan docs on the branch land inside the squash.
14 changes: 14 additions & 0 deletions devlog/_fin/260930_release_2_72_0/011_wp2_execution.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
# 011 wp2 execution: regression gate and merge

| Step | Evidence |
|---|---|
| Final copy | #6240 took TokenLab's final blurbs and referral link at `2b9295fea6` (030 findings); the `lane=all` run on `21cddd35c9` was cancelled |
| PR-event CI on `2b9295fea6` | Cross-platform CI 36591071773, Service lifecycle 36591071699, React Doctor 36591071756: success; 32 pass, 5 path-skipped |
| Full-lane gate | Cross-platform CI `lane=all` 36591083341: attempt 1 failed windows 7/9 (`cli-connect-readiness` installed-root probe, exit null at 18 s) and windows 8/9 (`main quota policy at native admission`, 32 s cases); neither loads a changed module (`init`, `provider-runtime` are lazy CLI imports). One rerun (attempt 2): both shards and `ci` success |
| Review | Codex P2 and CodeRabbit sponsor-first-run fixed; CodeRabbit wording suggestion declined (verbatim sponsor copy, adapter chip visible, Responses-first pending) |
| Policy | `assert-mergeable-review.sh --maintainer-integration 6240`: OK; decision comment 5894282491 |
| Merge | `gh pr merge 6240 --admin --squash --match-head-commit 2b9295fea6` → dev `1cd9d25517` = C; `package.json` 2.72.0, version-sources check 2.72.0 passes |
| Pre-move | #6243 (four version sources 2.72.0 → 2.73.0), `maintainer-sponsored` after review, merged → dev `73289d46ae` (2.73.0) |

Local regression scope: focused sponsor/registry/README/GUI suites and `test:changed`; a full local run
is not possible from a worktree under `~/.codex` (test home guard), so CI above is the full-suite proof.
Loading
Loading