Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
145 commits
Select commit Hold shift + click to select a range
a0f5897
release: v2.17.1-preview.20260814
lidge-jun Aug 14, 2026
fef111e
Merge main into preview: v2.19.0 release (preview keeps its prereleas…
lidge-jun Aug 15, 2026
255c25d
release: v2.19.0-preview.20260815
lidge-jun Aug 15, 2026
fd84ae1
Merge dev into preview: v2.20.0 line
lidge-jun Aug 15, 2026
906286c
Merge pull request #1768 from lidge-jun/promote/260815-preview
lidge-jun Aug 15, 2026
8e154f7
Merge main into preview: v2.22.0 line
lidge-jun Aug 16, 2026
0bc04f0
release: v2.23.0-preview.20260816
lidge-jun Aug 16, 2026
86039da
Merge dev into preview: v2.23.0 release
lidge-jun Aug 17, 2026
d240148
Merge dev into preview: v2.24.0 release
lidge-jun Aug 17, 2026
f32a2f5
Merge dev into preview: v2.24.1 release
lidge-jun Aug 17, 2026
6a23ea9
Merge dev into preview: Windows suite green
lidge-jun Aug 17, 2026
e25ec09
Merge pull request #1907 from lidge-jun/promote-preview
lidge-jun Aug 17, 2026
76e87cd
Merge dev into preview: ignore leftover test temp files
lidge-jun Aug 17, 2026
844081d
Merge pull request #1911 from lidge-jun/promote-preview2
lidge-jun Aug 17, 2026
56f2ed9
Merge main into preview: v2.24.2 release
lidge-jun Aug 17, 2026
506bcab
Merge pull request #1918 from lidge-jun/sync-preview
lidge-jun Aug 17, 2026
a43150c
Merge pull request #1962 from lidge-jun/codex/promote-preview-w5
lidge-jun Aug 18, 2026
7979903
Merge pull request #1963 from lidge-jun/codex/promote-main-w5
lidge-jun Aug 18, 2026
e6709a1
Merge pull request #1967 from lidge-jun/codex/promote-preview-w5b
lidge-jun Aug 18, 2026
1f4e047
Merge pull request #1968 from lidge-jun/codex/promote-main-w5b
lidge-jun Aug 18, 2026
379a355
Merge pull request #1970 from lidge-jun/codex/promote-preview-w5c
lidge-jun Aug 18, 2026
286cbd2
Merge pull request #1971 from lidge-jun/codex/promote-main-w5c
lidge-jun Aug 18, 2026
bed4ca8
Merge pull request #1975 from lidge-jun/codex/promote-preview-w5d
lidge-jun Aug 18, 2026
c49fed6
Merge pull request #1976 from lidge-jun/codex/promote-main-w5d
lidge-jun Aug 18, 2026
c0961d8
Merge pull request #1979 from lidge-jun/codex/promote-preview-w5e
lidge-jun Aug 18, 2026
879dbb0
Merge pull request #1980 from lidge-jun/codex/promote-main-w5e
lidge-jun Aug 18, 2026
82c0576
Merge pull request #1982 from lidge-jun/codex/promote-preview-w5f
lidge-jun Aug 18, 2026
0013b23
Merge pull request #1983 from lidge-jun/codex/promote-main-w5f
lidge-jun Aug 18, 2026
6d2eae7
Merge pull request #1985 from lidge-jun/codex/promote-preview-w5g
lidge-jun Aug 18, 2026
e2d4621
Merge pull request #1986 from lidge-jun/codex/promote-main-w5g
lidge-jun Aug 18, 2026
952a832
Merge dev into preview: v2.25.0 release train
lidge-jun Aug 18, 2026
70d7ba5
Merge pull request #2000 from lidge-jun/codex/promote-preview-2250
lidge-jun Aug 18, 2026
f60a045
Merge dev into main: v2.25.0 release
lidge-jun Aug 18, 2026
19986ca
Merge pull request #2001 from lidge-jun/codex/promote-main-2250
lidge-jun Aug 18, 2026
46858ef
release: v2.25.0-preview.20260818
lidge-jun Aug 18, 2026
110ef57
release: v2.25.0
lidge-jun Aug 18, 2026
11f6f4c
Merge pull request #2002 from lidge-jun/release-2.25.0-preview.20260818
lidge-jun Aug 18, 2026
e97fb26
Merge pull request #2003 from lidge-jun/release-2.25.0
lidge-jun Aug 18, 2026
f4cc168
Merge pull request #2088 from lidge-jun/dev
lidge-jun Aug 19, 2026
60f273d
release: v2.26.0-preview.20260819
lidge-jun Aug 19, 2026
6d6a1b4
Merge pull request #2090 from lidge-jun/release-2.26.0-preview.20260819
lidge-jun Aug 19, 2026
8be5f19
Merge pull request #2093 from lidge-jun/dev
lidge-jun Aug 19, 2026
604c29f
release: v2.26.0
lidge-jun Aug 19, 2026
b4336b7
Merge pull request #2096 from lidge-jun/release-2.26.0
lidge-jun Aug 19, 2026
43256f7
merge main into dev for the 2.27.0 promotion
lidge-jun Aug 19, 2026
8e01dd4
Merge pull request #2159 from lidge-jun/codex/promote-2.27.0
lidge-jun Aug 20, 2026
17c8a3a
merge preview into dev for the 2.27.0 preview sync
lidge-jun Aug 20, 2026
a055461
Merge pull request #2161 from lidge-jun/codex/sync-preview-2.27.0
lidge-jun Aug 20, 2026
5bdf560
Merge pull request #2186 from lidge-jun/codex/promote-2.28.0
lidge-jun Aug 20, 2026
a3c33bb
Merge pull request #2187 from lidge-jun/codex/sync-preview-2.28.0
lidge-jun Aug 20, 2026
ce4e05d
release: v2.28.0
lidge-jun Aug 20, 2026
5840591
Merge pull request #2189 from lidge-jun/codex/release-2.28.0
lidge-jun Aug 20, 2026
19fbc93
release: v2.28.0-preview.20260820
lidge-jun Aug 20, 2026
d2c700c
Merge pull request #2191 from lidge-jun/codex/release-2.28.0-preview
lidge-jun Aug 20, 2026
0498a05
merge dev into main for the 2.29.0 promotion
lidge-jun Aug 21, 2026
190a457
merge dev into preview for the 2.29.0 preview sync
lidge-jun Aug 21, 2026
76e9138
Merge pull request #2284 from lidge-jun/codex/promote-main-2.29.0
lidge-jun Aug 21, 2026
b2609a5
Merge pull request #2285 from lidge-jun/codex/promote-preview-2.29.0
lidge-jun Aug 21, 2026
849bfae
merge dev into main for the 2.29.0 release
lidge-jun Aug 21, 2026
aef1bf0
merge dev into preview for the 2.29.0 preview release
lidge-jun Aug 21, 2026
231e622
release: v2.29.0
lidge-jun Aug 21, 2026
639dc73
merge main into preview for the 2.29.0-preview release
lidge-jun Aug 21, 2026
298e0f6
release: v2.29.0-preview.20260821
lidge-jun Aug 21, 2026
4cfdc26
merge dev into preview for the 2.30.0-preview release
lidge-jun Aug 21, 2026
e9f8840
release: v2.30.0-preview.20260821
lidge-jun Aug 21, 2026
ceed6bf
merge dev into main for the 2.31.0 release
lidge-jun Aug 22, 2026
c1d2915
merge dev into preview for the 2.31.0-preview.20260822 release
lidge-jun Aug 22, 2026
22541fa
release: v2.31.0-preview.20260822
lidge-jun Aug 22, 2026
6ae83b1
release: v2.31.0
lidge-jun Aug 22, 2026
91f8606
Merge pull request #2478 from lidge-jun/dev
lidge-jun Aug 24, 2026
8bc7aa8
Merge pull request #2479 from lidge-jun/dev
lidge-jun Aug 24, 2026
96e2f67
release: v2.32.0
lidge-jun Aug 24, 2026
09a28e2
release: v2.32.0-preview.20260824
lidge-jun Aug 24, 2026
411e5f8
devlog: v2.32.1 hotfix train roadmap unit (260824)
lidge-jun Aug 24, 2026
29cf993
devlog: record wp1 delivery via PR #2487 and the two CI flakes
lidge-jun Aug 24, 2026
73a11a8
Merge pull request #2487 from lidge-jun/codex/v2321-hotfix-train-roadmap
lidge-jun Aug 24, 2026
3e3a028
fix(anthropic): classify capitalized/dotted Claude ids as adaptive th…
L-Y-J Aug 24, 2026
a60d517
fix(catalog): match selectedModels the way the canonical resolver mat…
ntdatt812 Aug 24, 2026
84ade0f
fix(codex): keep oversized Responses turns off the WS transport (#2473)
olddonkey Aug 24, 2026
1d4a92a
fix(responses): honor tool_choice for namespace aliases (#2477)
luvs01 Aug 24, 2026
02c302a
fix(responses): stop rewriting an unchanged snapshot every two second…
ntdat812 Aug 24, 2026
43227ac
fix(responses): close two post-merge review findings (#2500)
lidge-jun Aug 25, 2026
faaa78d
fix(responses): reject malformed selectors at the authorization gate …
lidge-jun Aug 25, 2026
03c988c
devlog: close the v2.32.1 train — GO/NO-GO, and two deferrals (#2504)
lidge-jun Aug 25, 2026
bb89eaf
devlog: pin the report to the code SHA its gates describe (#2506)
lidge-jun Aug 25, 2026
f4cb9f8
merge dev into preview for the v2.32.1-preview.20260825 release
lidge-jun Aug 25, 2026
3be3e55
fix(management): validate the sidecar pair against the submitted back…
lidge-jun Aug 25, 2026
b06cb1b
fix(cli): report Codex routing in ocx status and name an unused proxy…
lidge-jun Aug 25, 2026
47a31d7
fix(codex): report a destroyed shim instead of bailing silently (#2519)
lidge-jun Aug 25, 2026
fff8611
fix(xai): stop the undeclared-tool guard from killing hosted x_search…
olddonkey Aug 25, 2026
c09f040
fix(gui): guard quota reset date formatting (#2405)
luvs01 Aug 25, 2026
312b3e7
fix(gui): ignore stale Startup secondary responses (#2416)
luvs01 Aug 25, 2026
d402272
fix(responses): retry pre-output EOFs affecting Ox Alpha (#2486)
kremnyi Aug 25, 2026
0f30b39
fix(claude): do not let a non-registering row veto a bare context key…
ntdatt812 Aug 25, 2026
0906201
fix(kiro): prioritize tool search results within catalog budget (#2475)
mchlkim Aug 25, 2026
d659c54
feat(codex): add per-model ChatGPT compaction budgets (#1905)
luvs01 Aug 25, 2026
b2f95e1
fix(anthropic): apply provider default reasoning effort when caller o…
L-Y-J Aug 25, 2026
b694268
fix(anthropic): do not let the __omit__ sentinel become an effort val…
lidge-jun Aug 25, 2026
224f23d
fix: normalize legacy exec_command/shell_command tool calls to declar…
L-Y-J Aug 25, 2026
121c1fb
test(bridge): pin legacy shell-name normalization on the SSE path (#2…
lidge-jun Aug 25, 2026
64bc085
fix(catalog): do not carry a retained compact limit onto a corrected …
lidge-jun Aug 25, 2026
8c21b69
devlog: operator visibility train roadmap unit (260825) (#2520)
lidge-jun Aug 25, 2026
98ed186
fix(gui): inset the Claude account-pool warning and threshold field (…
Yoonkeee Aug 25, 2026
b12658e
devlog: OAuth login UX roadmap unit (260825)
lidge-jun Aug 25, 2026
2e03252
devlog: OAuth login UX delivery map (issues + PR stack)
lidge-jun Aug 25, 2026
eae9fb4
fix(gui): show the device code and authorization link on every login …
lidge-jun Aug 25, 2026
4edef75
devlog: record the as-landed WP2 design and its test split
lidge-jun Aug 25, 2026
da6cbfc
fix(gui): render the login hint during a first-time provider add
lidge-jun Aug 25, 2026
d7d708f
Merge pull request #2530 from lidge-jun/codex/oauth-login-ux
lidge-jun Aug 25, 2026
315f5bf
Merge pull request #2534 from lidge-jun/codex/oauth-first-add-hint
lidge-jun Aug 25, 2026
1c49c38
feat(oauth): let the operator decline a proxy-side browser open
lidge-jun Aug 25, 2026
c6c98e9
fix(gui): read the server browser-open default as a resource, not pos…
lidge-jun Aug 25, 2026
90c4aa2
fix(gui): stop the browser-open toggle from issuing its own settings …
lidge-jun Aug 25, 2026
86bc623
fix(oauth): read code and state from a redirect URL fragment
lidge-jun Aug 25, 2026
34ef539
test(update): stop the launcher-recovery wait from failing a slow CI …
lidge-jun Aug 25, 2026
e65d6d3
Merge pull request #2537 from lidge-jun/codex/oauth-open-browser-choice
lidge-jun Aug 25, 2026
858352a
Merge pull request #2540 from lidge-jun/codex/oauth-paste-fragment
lidge-jun Aug 25, 2026
693b6e4
devlog: close out the OAuth login UX merge train
lidge-jun Aug 25, 2026
aeea04c
fix(oauth): never pair a code and state from different URL components
lidge-jun Aug 25, 2026
5170fc8
Merge pull request #2543 from lidge-jun/codex/oauth-mixed-source-fix
lidge-jun Aug 25, 2026
9af029c
Merge pull request #2544 from lidge-jun/dev
lidge-jun Aug 25, 2026
89295c6
fix(release): run the preflight suite in the same groups CI does
lidge-jun Aug 25, 2026
c0c9544
Merge pull request #2546 from lidge-jun/codex/release-gate-isolation-…
lidge-jun Aug 25, 2026
5559f85
Merge pull request #2547 from lidge-jun/dev
lidge-jun Aug 25, 2026
121ecbc
test(usage): stop asserting the overlay version against a moving oracle
lidge-jun Aug 25, 2026
e1fb675
Merge pull request #2549 from lidge-jun/codex/api-usage-overlay-versi…
lidge-jun Aug 25, 2026
57f2d4d
fix: normalize Responses terminal failures
Aug 24, 2026
9a350cb
fix: delimit repaired SSE EOF tails
Aug 24, 2026
097663a
docs: record Responses terminal boundary invariants
AiriDea Aug 24, 2026
d8d3141
fix(responses): keep unframed repair terminals fail-closed
AiriDea Aug 24, 2026
7dd669e
fix(responses): preserve terminal delivery after overflow
AiriDea Aug 24, 2026
bf1b280
test(responses): pin terminal relay parity
AiriDea Aug 24, 2026
b77b4da
fix(lab): await producer child main
AiriDea Aug 24, 2026
9de0d56
test: use executable PowerShell fixture on Windows
AiriDea Aug 24, 2026
0849af3
test: isolate Windows service-home probes
AiriDea Aug 24, 2026
574b77a
test(codex): bound inject lock child processes
AiriDea Aug 24, 2026
7bb99b4
test: assert PowerShell fixture start-time output
AiriDea Aug 24, 2026
4575a37
test(codex): extend lock contention hold
AiriDea Aug 24, 2026
13fa29e
test: pass Windows service probe preload explicitly
AiriDea Aug 24, 2026
117ea95
fix: close review races and fixture lifecycles
AiriDea Aug 25, 2026
963af13
test: always reap lock contention holder
AiriDea Aug 25, 2026
2fb77a1
test(docs): close review follow-up gaps
AiriDea Aug 25, 2026
a6cfb31
fix(responses): preserve cyber policy semantics
AiriDea Aug 25, 2026
c8c640e
fix(responses): mark thrown policy failures non-retryable
AiriDea Aug 25, 2026
30295ad
test(responses): keep policy fixtures privacy-safe
AiriDea Aug 25, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,251 @@
# 000 — v2.32.1 hotfix train: baseline, scope, and work-phase map

Unit opened 2026-08-24. Session `01a0339b-4c6e-73e3-8890-23f65c5bbd46`.
Goalplan slug `prepare-opencodex-dev-as-the-verified-release-ca`.

## Baseline correction

The planning note this unit started from was written against a v2.31 baseline.
That baseline is void. Verified live on 2026-08-24:

| Ref | SHA | Meaning |
|-----|-----|---------|
| `origin/dev` | `c44e43f00` | Merge of #2453 (wait yield_time_ms underscore) |
| `origin/main` | `96e2f67c3` | `release: v2.32.0` |

```
git merge-base --is-ancestor origin/dev origin/main -> exit 0 (dev IS an ancestor of main)
git merge-base --is-ancestor origin/main origin/dev -> exit 1
git rev-list --count origin/dev..origin/main -> 27
git rev-list --count origin/main..origin/dev -> 0
git diff --name-status origin/dev origin/main -> M package.json
git show origin/main:package.json -> "version": "2.32.0"
```

Three facts follow, and they set the entire unit:

1. **The next release is v2.32.1, not v2.31.1.** v2.32.0 is already published from
`main` (`npm` `latest` = 2.32.0, GitHub release `v2.32.0` targets `96e2f67c3`).
A 2.31.x number would move backwards over a shipped release.
2. **`dev` and `main` have NOT diverged.** `dev` is an *ancestor* of `main`:
0 commits ahead, 27 behind. The 27 are main-side promotion and release commits
accumulated since 2.25.0. This was recorded incorrectly in the first draft of
this document — the original text read the one-way `--is-ancestor` result as
divergence. Corrected here after an independent audit re-ran both directions.
3. **The net tree delta is one line.** `main` carries `version: 2.32.0`; `dev`
still says `2.27.0` because release bumps are made on the promotion commit and
never flow back. Nothing else differs.

### What wp1 therefore is

Because `dev` is strictly behind `main`, `git merge origin/main` on `dev` is a
**fast-forward**, not a merge commit. That is the intended operation and it is
recorded as such: wp1 advances `dev` to `96e2f67c3` so the release lineage and
the version line are one. `git merge-tree` confirms the only content change:

```
git merge-tree $(git merge-base origin/dev origin/main) origin/dev origin/main
- "version": "2.27.0",
+ "version": "2.32.0",
```

`bun.lock`, `scripts/release.ts`, and `.github/workflows/release.yml` are
untouched. **Mandatory post-condition: `dev` package.json reads exactly
`2.32.0`.** Keeping `2.27.0` would regress the release ledger; bumping to
`2.32.1` belongs to the promotion commit, not to wp1.

## Why bugfix-only

The open queue is far larger than one train can absorb: 46 open PRs, 25 of them
draft, 21 `review-ready`, 11 `intake: hygiene-blocked`, plus 67 open issues.
Merging by availability rather than by risk is how a hotfix release grows a
regression radius it cannot verify. This train is capped at five runtime fixes
plus one repository-infrastructure fix, each of which closes a defect class that
is *currently user-visible on the shipped v2.32.0*.

## Included units

| # | PR | Defect class it closes |
|---|-----|------------------------|
| wp3 | #2483 | Model unusable — capitalized/dotted Claude vendor ids take the legacy `thinking.enabled` wire and get a 400 |
| wp4 | #2481 | Catalog inconsistency — slash-bearing models vanish from the picker while direct calls still work |
| wp5 | #2473 | Thread unrecoverable — a >16 MiB turn repeatedly dies on the WS transport with no SSE escape |
| wp6 | #2477 | Tool authorization boundary — namespace aliases restored outside the caller's `tool_choice` |
| wp7 | #2476 | Disk/CPU amplification — a ~24 MiB snapshot rewritten every two seconds unchanged |
| wp2 | #2427 | Verification cost — the full suite reads as hung, which pushes contributors toward unverified merges |

## Excluded, with reason

Excluded because they widen the regression radius, not because they lack value:

- **#1905** per-model compaction budgets — 27 files, `+813/-80`, touches config,
management, and catalog. First candidate for v2.33.0.
- **#2418** subagent scoped cooldown — 8 files, `+2044/-111`, changes routing,
credential admission, quota probing, and encrypted recovery together. Needs its
own security lane.
- **#2470** Google thought-signature — three unrelated concerns in one PR
(signature replay, output clamps, Windows fixtures). Must be split.
- **#2475** Kiro tool-search priority, **#2425** xAI hosted `x_search`,
**#2429** `test:changed` — not release blockers; #2429 is stacked on #2427.
- **#2462** and every OAuth / remote-dashboard / hosted-SaaS / billing PR —
product-direction and security-boundary changes, currently hygiene-blocked.
- All 11 `intake: hygiene-blocked` PRs, by policy.

## Work-phase map (dependency order)

The order is a dependency chain, not a difficulty ranking. Each phase consumes
the verified output of the one before it.

```
wp0 docs (this unit)
└─ wp1 dev fast-forward to main (v2.32.0) [every later head depends on it]
├─ wp3 #2483 anthropic ids ┐
├─ wp4 #2481 selectedModels │ runtime fixes, merged
├─ wp5 #2473 oversized WS ├─ sequentially, each verified
├─ wp6 #2477 namespace authz [sec review] │ on the SERIAL runner
├─ wp7 #2476 snapshot writes [conditional]┘
│ │
│ └──── all of wp3..wp7 must be merged-or-deferred ────┐
│ │
└─ wp9 #2472 mixed-sequence regression │
[independent of wp3..wp7; may run any time after wp1]│
│ │
└──────────────┬───────────────────────────┘
wp2 #2427 test runner [LAST, or deferred]
wp8 freeze + GO/NO-GO
[requires wp3..wp7, wp9, and wp2]
```

The join is explicit because the ordering rule is easy to lose in a tree
drawing: **wp2 does not start until every runtime phase has a terminal
outcome.** It is drawn as a sibling of nothing — it is downstream of all of
them.

### Why #2427 moved to the end (audit amendment)

The first draft put #2427 first, reasoning that landing the verification
instrument early means every later phase is verified by the same runner. The
A-phase auditor argued the opposite and it is the stronger argument: #2427
switches the suite from serial isolated execution to file-parallel isolated
execution (`scripts/test.ts` default becomes `bun test --isolate --parallel
./tests/`), and its own PR body reports **7 failures across 902 files** on its
exact head. Landing an unproven runner first makes every subsequent runtime
failure ambiguous: flakiness from parallel shared-state contention would be
indistinguishable from a regression introduced by the runtime PR under test.

A verification instrument must be changed against a known-good baseline, not
used to establish one. #2427 therefore runs LAST, immediately before freeze, and
only with a pre/post gate: the runtime phases are verified on the serial runner,
then #2427's head must produce a green exact-head `bun run test` plus required
cross-platform CI. If it does not, it is deferred and the train proceeds on the
existing runner. It is a convenience, never a blocker.

wp8 depends on **every** runtime phase, not only on the phase drawn above it.

## Out of scope for this unit (STRICT)

No `dev` -> `main` promotion, no tag, no npm publish, no release workflow
dispatch, no version bump beyond what the backmerge carries. This unit ends at a
frozen, verified `dev` SHA plus a GO/NO-GO report. Promotion is a human decision.

## Verification doctrine

Exact-head evidence only. A remembered green run is not evidence. Every phase
closes with fresh command output captured at the SHA being claimed, and every
merge is proven with its merge SHA plus
`git merge-base --is-ancestor <merge> origin/dev`.

## Known defects already shipped in v2.32.0 (audit amendment)

v2.32.0 is the v2.27.0-line tree plus a version bump, so every defect open
against 2.31.0 also ships in 2.32.0. The audit was right that a hotfix train
without this ledger is choosing its scope blind. Dispositions:

| Issue | Defect | Fixing PR | Disposition | NO-GO? |
|-------|--------|-----------|-------------|--------|
| #2407 | Kiro drops tools loaded by `tool_search` | #2475 (draft, red suite) | Decide at wp2/wp8 on exact-head evidence; include only if it goes green before freeze | No |
| #2458 | Gemini 3.7 Flash video input 502 — routed provider emits undeclared client tool `get_video_duration` | none | Defer: the candidate fix touches the undeclared-tool guard, the same authorization surface wp6 is hardening. Two changes to one guard in one hotfix is exactly the regression radius this train exists to avoid | No |
| #2459 | Windows bare npm reinstall can leave a live proxy on a mixed old/new module graph | none | Defer: install/service surface, not a runtime defect the proxy can fix mid-session; needs its own unit | No |

None forces NO-GO, but each is now a recorded decision rather than an omission.
If any acquires a verified fix before freeze it may be reconsidered — the
inclusion bar stays exact-head green plus review, not urgency.

## Two review-ready PRs the first draft did not mention (audit amendment)

- **#2474** (`fix(scripts): run ocx-run commands in the requested workdir`) —
a real defect: `scripts/ocx-run:128` never enters the requested workdir.
But root `package.json` excludes `scripts/` from the published artifact, so it
cannot affect the shipped runtime. **This train does not use `ocx-run` in any
verification step**, so it is deferred as repository-operations work rather
than included. If a later phase adopts `ocx-run` for verification, this
becomes a prerequisite and must be pulled in first.
- **#2432** (docs, `__omit__` reasoning-effort sentinel) — currently
`CHANGES_REQUESTED` with unfixed table formatting. Excluded pending its
requested changes; docs-only work does not need a hotfix train.

## Per-phase verifiers (audit amendment, PLAN-VERIFIER-REAL-01)

The auditor ran the baseline commands and proved they pass while observing none
of the planned fixes:

```
bun run typecheck -> exit 0, 0.60s
bun test tests/namespace-tool-compat.test.ts \
tests/selected-models.test.ts \
tests/anthropic-reasoning.test.ts -> 67 pass 0 fail, exit 0
```

Green there means nothing yet: on current `dev`,
`tests/selected-models.test.ts:15` has no slash-bearing selector,
`tests/anthropic-reasoning.test.ts:53` has no capitalized/dotted id, and
`tests/namespace-tool-compat.test.ts:239` hand-builds an alias map without ever
testing `tool_choice` authorization. That run is a **preflight**, not fix
evidence.

Each phase therefore names its own verifier, run at that phase's exact merge
head, plus the specific assertion that must newly exist:

| Phase | Verifier command | Assertion that must be present after merge |
|-------|------------------|--------------------------------------------|
| wp3 #2483 | `bun test tests/anthropic-reasoning.test.ts` | capitalized + dotted + dashed + date-pinned ids classify correctly, and the explicit-disable caller is covered |
| wp4 #2481 | `bun test tests/selected-models.test.ts tests/codex-catalog.test.ts tests/slug-codec.test.ts` | an encoded slug in `selectedModels` keeps a slash-bearing model visible at the route/sync level, not only in the helper |
| wp5 #2473 | `bun test tests/ws-upstream.test.ts tests/sse-failed-tail.test.ts` | oversized frame opens zero sockets; adjacent-byte boundary routes WS vs SSE |
| wp6 #2477 | `bun test tests/namespace-tool-compat.test.ts tests/responses-parser.test.ts` | a foreign tool-type selector authorizes no alias and restores no call |
| wp7 #2476 | `bun test tests/responses-state-write-amplification.test.ts tests/responses-state.test.ts` | unchanged flush does not rewrite; deleted snapshot is regenerated; eviction order unchanged |
| wp2 #2427 | `bun run test` (full, exact head) + cross-platform CI | exit 0 |
| wp8 | `bun run typecheck`, `bun run test`, `bun run privacy:scan` at the frozen SHA | all exit 0 |

## The #2472 canary, restated (audit amendment)

The original criterion — a 100-call zero-output canary — is not a feasible gate
as written, and the audit demonstrated why. The proxy currently listening on
:10100 is PID 922, started 2026-08-23: the **stale process from the bug report
itself**, not a frozen candidate. Worse, the defect needs Cursor
native-shell/host-shell interleaving with duplicate call ids; duplicates are
already dropped at `src/adapters/cursor/protobuf-events.ts:1055` while the two
execution paths stay separate at `src/adapters/cursor/live-transport.ts:1445`.
An ordinary local prompt cannot deterministically produce that sequence, so a
"100 calls, zero empty results" run would prove nothing while spending real
provider credits and restarting the user's live proxy.

Restated criterion: the mandatory gate is an **automated mixed-sequence
regression** driving the interleaved native/host shell path with duplicate call
ids, asserting a typed error or failover instead of a silent empty success.
A live canary stays **optional and separately authorized**: isolated port and
config, disposable workdir, the exact frozen SHA, a bounded call budget, and
teardown evidence. Restarting PID 922 is not part of this unit.

**That regression does not exist and no included PR writes it**, which the
second audit round correctly called out: a mandatory gate with no implementing
phase is a wish, not a gate. It therefore gets its own work-phase, **wp9**,
documented at `090_wp9_issue2472_mixed_sequence_regression.md`. wp9 is
independent of wp3–wp7 and may run any time after wp1, but it must have a
terminal outcome before freeze. If wp9 concludes the sequence cannot be driven
deterministically in-process, #2472 is recorded as an explicitly deferred known
defect and **stops being a GO criterion** — with that finding written down,
rather than left as an unmet checkbox.
Loading
Loading