Skip to content

Commit 85f3a8e

Browse files
committed
fix: stabilize cross-host skill route bootstrap
1 parent 7e58147 commit 85f3a8e

52 files changed

Lines changed: 1066 additions & 264 deletions

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎CHANGELOG.md‎

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,16 +1,17 @@
11
# 变更日志 (CHANGELOG)
22

33
> **说明**: 版本概览摘要;历史版本见对应详细变更文件。
4-
> **最新版本详细变更文档**: [`changelogs/releases/v1.17.7.md`](./changelogs/releases/v1.17.7.md)
5-
> **最后更新**: 2026-08-15
6-
> **当前版本**: v1.17.7 收敛 ContextRead/SkillRoute 首轮绑定、首次分页、Memory/CP、全局配置事务、Readiness、真实宿主证据与 Windows Node 18 测试资源边界;版本发布权威以对应 Git tag、npm registry 与 GitHub Release 为准。
4+
> **最新版本详细变更文档**: [`changelogs/releases/v1.17.8.md`](./changelogs/releases/v1.17.8.md)
5+
> **最后更新**: 2026-08-16
6+
> **当前版本**: v1.17.8 以稳定 Hook launcher 消除升级信任漂移,为未分发宿主事件的 SkillRoute 增加结构化 `profile_context_plan` 自举回退,保持多项目 pending/复合 content 权威一致,并以当前身份不变量验证动态 capability;版本发布权威以对应 Git tag、npm registry 与 GitHub Release 为准。
77
88
---
99

1010
## 版本概览
1111

1212
| 版本 | 日期 | 变更摘要 | 详细 |
1313
|------|------|---------|------|
14+
| [v1.17.8](./changelogs/releases/v1.17.8.md) | 2026-08-16 | 🔧 **宿主稳定入口与 SkillRoute 自举修复**:Hook 信任身份与不可变 runtime generation 解耦;Codex 未分发 UserPromptSubmit 时由结构化 MCP 回退建立同一 SkillRoute envelope;多项目 pending 保留 exact host/显式 Skill,ContextRead 拒绝用 sidecar 覆盖复合返回体失配;S15 兼容 Hook/MCP 两种证据形态并绑定真实入口,closure 复算当前 runtime/adapter/evidence | [查看](./changelogs/releases/v1.17.8.md) |
1415
| [v1.17.7](./changelogs/releases/v1.17.7.md) | 2026-08-15 | 🔧 **全局运行态一致性与首载闭环修复**:正文读取绑定持久计划并在源层有界;未解析目标、catalog sidecar、Memory 状态、配置 CAS/Readiness、命令/对象身份与 CLI/Desktop 证据分层完成跨消费者收敛;Windows Node 18 插桩递归与验证预算假失败已关闭 | [查看](./changelogs/releases/v1.17.7.md) |
1516
| [v1.17.6](./changelogs/releases/v1.17.6.md) | 2026-08-14 | 🔧 **SkillRoute 最终 Stop 完备性修复**:非显式未提交路由在最终回复前返回 exact catalog action,阻止自然语言 workspace Skill 被无工具回复静默跳过;统一路由与宿主能力边界保持不变 | [查看](./changelogs/releases/v1.17.6.md) |
1617
| [v1.17.5](./changelogs/releases/v1.17.5.md) | 2026-08-14 | 🔧 **发布包 npm scripts 闭包修复**:最终 tarball 仅公开 8 个安装态入口,从最终 manifest 验证脚本与运行依赖闭包,并以事务保证源码 manifest 原字节恢复 | [查看](./changelogs/releases/v1.17.5.md) |

‎RULES.md‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
1-
# DevCodex v1.17.7 — 使用入口
1+
# DevCodex v1.17.8 — 使用入口
22

3-
> AI workflow injector for Copilot / Claude Code / Codex / Gemini / Grok / Cursor Beta · publisher: Rocky · version: 1.17.7
3+
> AI workflow injector for Copilot / Claude Code / Codex / Gemini / Grok / Cursor Beta · publisher: Rocky · version: 1.17.8
44
55
## 正式主支持客户端
66

‎changelogs/releases/v1.17.8.md‎

Lines changed: 50 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,50 @@
1+
# v1.17.8
2+
3+
> 发布日期:2026-08-16
4+
> 类型:Patch / 宿主稳定入口与 SkillRoute 自举修复
5+
6+
## 摘要
7+
8+
本版本修复 v1.17.7 发布后真实宿主验证及随后最低版本回归发现的一组相邻问题:版本化 Hook 命令会在升级时改变宿主信任身份;已发现的 UserPromptSubmit Hook 在部分 Codex 入口未实际分发;多项目 pending 的显式 Skill/宿主身份没有跨 MCP 保留;复合 content 的旧解析优先级还能掩盖返回体失配。修复保持既有 runtime generation 与本地 MCP 边界,不新增第三方依赖、网络监听或常驻服务。
9+
10+
## 主要修复
11+
12+
- 新增用户级稳定 `host-hook-launcher.cjs`。六宿主 Hook 命令不再直接嵌入 `runtime-<version>-<digest>` 路径;launcher 读取 committed `GlobalHostConfigReceiptV1`,校验 host、runtime containment、generation/version/source digest 后再转发到当前不可变 adapter。
13+
- MCP server 继续绑定版本化 runtime,保持滚动升级时的进程世代隔离;稳定 launcher 只拥有 Hook 转发职责,不复制 adapter 业务逻辑。
14+
- `profile_context_plan` 在没有宿主 Hook 注入时创建或复用同 turn、同 context 的 `SkillRouteBootstrapV1`,通过结构化 content 与 `_meta.devcodexSkillRouteBootstrap` 返回;已有 Hook envelope 或 route decision 时保持幂等,不重复注入。
15+
- 未解析项目的 pending nextCall 现在精确携带 canonical hostVariant 与显式 `explicitSkillId`;PostToolUse 同步同一 envelope,并在 MCP 已交付相同 digest 时抑制重复 bootstrap。
16+
- ContextRead 从复合 content 中选择唯一受支持 schema 的主载荷;可观察 plan 的 epoch/root/identity 不匹配时不再由 observation sidecar 覆盖。新增 MCP 参数保持最小 schema,避免 `tools/list` 越过 Grok stdio 首载预算。
17+
- S15 Hook 识别改为解析 canonical Base64URL argv,并兼容稳定 launcher 与上一代 versioned adapter;错误 host、路径逃逸、坏 receipt/generation 继续失败关闭。
18+
- S15 上下文证据统一支持 Hook `postHistory` 与 MCP `ContextReadReceiptV2.observations`,显式记录 observation mode;宿主观察使用 evidence-bound hostVariant,不再从父级 Desktop ambient 环境重算 CLI 身份。
19+
- Codex CLI portable capability 目标更新至 0.147.0;Codex/Grok runtime/adapter/evidence 摘要已在 R-19 后重新冻结。closure 与安装态全局配置回归不再硬编码迁移阶段的零 PASS/UNVERIFIED 快照,而是复算当前身份并只允许真实回放 surface 晋级;Codex Desktop 保持独立 `UNVERIFIED`,不会继承 CLI PASS。
20+
21+
## 防回归验证
22+
23+
- 六宿主配置事务、canonical command、stable launcher、receipt/runtime containment、幂等、CAS、回滚、竞态与临时目录清理。
24+
- MCP plan/bootstrap 创建、Hook envelope 复用、decision 后不重复注入、坏上下文 fail closed。
25+
- 多项目显式 Skill 与 exact hostVariant 跨 pending/MCP/PostToolUse 保真;重复交付抑制、返回体 epoch/root 篡改拒绝、sidecar 不覆盖可观察坏主体、Profile `tools/list` 字节预算。
26+
- Hook history 与 structured receipt 双形态证据;CLI/Desktop ambient 隔离;portable evidence 原始字节摘要与 runtime/adapter freshness。
27+
- R-19 后 Codex CLI 0.147.0 与 Grok 1.0.0 源码 S15 已重新通过;SkillRoute closure 同时验证允许 PASS 的 surface 白名单、当前 runtime、入口专属 adapter、portable evidence 与 Desktop UNVERIFIED 边界。
28+
- 源码 R4 已通过 Windows Node 18 控制面、Node 24 fresh full 95/95、coverage、audit、Profile 62/62、package 74/74 与 npmjs/all dry-run;发布仍须通过 exact-tree 复验、远端 CI、registry parity、fresh install、六宿主更新与已安装态 S15。
29+
30+
## 兼容性与已知边界
31+
32+
- 这是向后兼容 patch;旧 versioned Hook 配置可被合并器识别并迁移到稳定 launcher。
33+
- Codex 首次看到新的稳定 Hook 命令时仍可能要求一次信任确认;后续 DevCodex runtime generation 升级不会再仅因版本路径变化触发信任漂移。
34+
- Codex Desktop 已打开任务不会热替换启动时 generation。CLI PASS 不能替代 Desktop app 当前任务证据;安装后需新建任务或重启宿主,Desktop 未取得当前任务实证前继续标为 `UNVERIFIED`。
35+
36+
## 升级
37+
38+
```bash
39+
npm install -g devcodex@1.17.8
40+
devcodex global-adapters apply
41+
```
42+
43+
## 发布拓扑
44+
45+
- npm 包名:`devcodex`
46+
- registry:`https://registry.npmjs.org/`
47+
- 发布分支:`main`
48+
- 目标 Tag:`v1.17.8`
49+
- 上一版本:`v1.17.7`
50+
- 关联修复:`.devcodex/devcodex/bugs/第二轮深审问题与全局运行态一致性修复/`

‎changelogs/unreleased.md‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,12 @@
11
# 未发布变更(Unreleased)
22

33
> **用途**: 记录尚未正式发版的实现级变更。
4-
> **当前**: v1.17.7 全局运行态一致性与首次加载闭环修复已冻结为发布候选;正式发布事实仍以 Git tag、npm registry 与 GitHub Release 为准。
4+
> **当前**: v1.17.8 宿主稳定入口与 SkillRoute 自举修复已通过源码 R4 并冻结为发布候选;正式发布事实仍以 Git tag、npm registry 与 GitHub Release 为准。
55
66
## 当前未发布实现候选
77

8-
- **v1.17.7 全局运行态一致性与首次加载闭环修复候选**:22 项确认问题按 12 个根因域在原 owner 内收敛。Profile/Memory 正文读取必须绑定持久 ContextRead plan,section/fallback 在源层有界;未解析目标由 pending envelope 的 PreToolUse/Stop owner 强制;catalog recipe/ledger/sidecar 可恢复且 fail closed;Memory 使用 append-only last-event-wins;CP artifact、临时对象、Copilot 调用、nested project/prompt、Node 命令与宿主 entrySurface 均增加规范身份。全局配置增加解析失败关闭、全量 CAS、rename-window 复核、activation/readiness 同源;CI 覆盖最低兼容、Windows 控制面、Node 24 LTS full/package/publish 与 Node 26 current。发布复审继续关闭 Windows Node 18 read-trace 自递归和 `global-host-config` 180 秒预算假失败,局部/节点/CI 三层限时均已建立;最终 source R4 与 GitHub CI 7/7 已通过,tag/publish/registry/本机更新仍待完成。完整说明见 `changelogs/releases/v1.17.7.md`。
8+
- **v1.17.8 宿主稳定入口与 SkillRoute 自举修复候选(PI-251~255 / PF-303~307)**:六宿主 Hook 改为稳定 launcher,由 committed receipt 安全转发到当前不可变 runtime,避免每次升级改变 Codex Hook 信任身份;`profile_context_plan` 在宿主没有分发 UserPromptSubmit 时返回并复用精确 SkillRoute bootstrap,并把多项目 pending 的 canonical hostVariant/显式 Skill 保真带入 MCP;ContextRead 对复合 content 选择唯一主 schema,拒绝用 sidecar 覆盖可观察的身份失配;S15 归一化 Hook history 与结构化 receipt,并以 evidence-bound hostVariant 阻止 Desktop ambient 污染 CLI;closure 与安装态全局配置回归以当前 runtime、入口专属 adapter 与 portable evidence 不变量替代阶段性零 PASS/UNVERIFIED 快照。Codex/Grok 源码 S15 已按 R-19 后 runtime 重新通过,Desktop 当前任务仍保持 UNVERIFIED。完整说明见 `changelogs/releases/v1.17.8.md`。
9+
- **v1.17.7 全局运行态一致性与首次加载闭环修复已归档**:22 项确认问题及 Windows Node 18 插桩递归、验证预算假失败均已关闭;GitHub CI、Publish、npm/GitHub tarball parity 与六宿主本机更新已经完成。完整说明见 `changelogs/releases/v1.17.7.md`。
910
- **v1.17.6 工作区 Skill 非显式 Stop 完备性修复已归档(VL-098 / PF-296 / GR-088)**:非显式 `PLAN_NOT_COMMITTED` 除既有 PreToolUse 外,在最终 Stop 也 fail closed,并复用 `NextActionEnvelopeV1` 返回精确首个 catalog 调用;普通聊天通过统一 catalog 后 `commit(null)` 完成 0/1 决策,Hook 不恢复关键词 auto-match 或新增 final-text classifier。重复 Stop 继续使用现有 3 次饱和与 notice fingerprint,PreCompact、ContextRead allowlist、retirement 与 must-reply 合同不变。完整说明见 `changelogs/releases/v1.17.6.md`;正式发布事实仍以 Git tag、npm registry 与 GitHub Release 为准。
1011
- **v1.17.5 发布包 npm scripts 闭包修复已归档(PF-294 / GR-086)**:`PublishedPackageScriptsContractV1` 让源码保留完整维护脚本,同时把最终 tarball manifest 投影为 8 个 lifecycle / validate / global-adapters 入口;prepack/postpack 通过摘要收据事务原字节恢复源码 manifest。发布门禁从最终 manifest 建立 direct/nested/require/path.join/spawn 闭包,并执行真实 `pack → 隔离 HOME 安装 → installed validate → installed self-pack`;缺入口、缺依赖、source-only 泄漏、lifecycle 单边、恢复冲突或状态残留均失败关闭。完整说明见 `changelogs/releases/v1.17.5.md`,正式发布事实仍以 Git tag、npm registry 与 GitHub Release 为准。
1112
- **v1.17.4 工作区临时产物与六宿主安全卸载已归档(PI-241 / PF-290 / PI-242 / PF-291)**:统一 `<workspace>/.tmp/devcodex/`、受管 manifest/TTL/lease/backup 与 `tmp status/prune`;新增默认预览的 `devcodex uninstall` / `global-adapters remove`,以跨宿主单事务、路径与所有权 fail-closed、并发安全回滚和用户内容保留完成清理。完整候选见 `changelogs/releases/v1.17.4.md`;正式发布事实仍以 Git tag、npm registry 与 GitHub Release 为准。

‎content/duplication-inventory.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"schemaVersion": "ControlContentDuplicationInventoryV1",
3-
"sourceBundleDigest": "36d62dd1ff0bb610cdfe4c57004d1154b43c22c16000441e41e53c08d69dd134",
3+
"sourceBundleDigest": "ad1f27f53487db85bb54c0fa46b1ebfd39f0458e7a48474c76433b2f8ea17c18",
44
"thresholds": {
55
"minParagraphChars": 100,
66
"sectionThreshold": 0.94,

‎content/instructions/00-safety.instructions.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
applyTo: "**"
33
description: 安全底线与输出语言规则,定义 S01~S07、违规处理与不可豁免边界
44
priority: P2
5-
version: 1.17.7
5+
version: 1.17.8
66
---
77
# 安全底线规范(S01~S07)
88

‎content/instructions/01-common.instructions.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
applyTo: "**"
33
description: 通用规范总则,覆盖优先级、意图路由、Profile/active-root、宿主适配与治理总线
44
priority: P5
5-
version: 1.17.7
5+
version: 1.17.8
66
---
77
# 通用规范
88

‎content/instructions/01a-profile-loading.instructions.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
applyTo: "**"
33
description: 意图驱动的 Profile 加载、active-root 路径、目标项目识别与项目现实扩展规范
44
priority: P5
5-
version: 1.17.7
5+
version: 1.17.8
66
---
77
# Profile 加载与项目现实扩展
88

‎content/instructions/01b-record-router.instructions.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
applyTo: "**"
33
description: 任务切换边界、RecordRouter 分流、Improvement Intake 与提交发布边界的通用规范
44
priority: P5
5-
version: 1.17.7
5+
version: 1.17.8
66
---
77
# 任务边界与 RecordRouter
88

‎content/instructions/01c-intent-expansion.instructions.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
applyTo: "**"
33
description: 意图识别、Intent Expansion Card、上下文重建与可见回复证据的通用规范
44
priority: P5
5-
version: 1.17.7
5+
version: 1.17.8
66
---
77
# 意图扩展与上下文重建
88

0 commit comments

Comments
 (0)