Skip to content

Commit 8d1c8e1

Browse files
committed
release: prepare DevCodex 1.20.0 continuity control plane
1 parent 38cace3 commit 8d1c8e1

117 files changed

Lines changed: 15511 additions & 901 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/workflows/publish.yml‎

Lines changed: 67 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -12,20 +12,30 @@ on:
1212
default: finalize-only
1313
type: choice
1414
options:
15+
- publish-qualified
1516
- finalize-only
1617
release_tag:
1718
description: Existing published tag (for example v1.19.3)
1819
required: true
1920
type: string
2021
publish_run_id:
2122
description: Workflow run containing PublishedArtifactReceiptV1
22-
required: true
23+
required: false
2324
type: string
2425
publish_run_attempt:
2526
description: Attempt number that produced the receipt
2627
required: true
2728
default: "1"
2829
type: string
30+
qualification_run_id:
31+
description: Tag workflow run containing the qualified exact artifact
32+
required: false
33+
type: string
34+
qualification_run_attempt:
35+
description: Attempt number that produced the qualified exact artifact
36+
required: false
37+
default: "1"
38+
type: string
2939

3040
concurrency:
3141
group: publish-${{ github.ref }}
@@ -81,6 +91,17 @@ jobs:
8191
node scripts/exact-release-artifact.js create --output-dir "${RELEASE_DIR}"
8292
node scripts/exact-release-artifact.js verify --output-dir "${RELEASE_DIR}"
8393
94+
- name: Install and exercise the exact qualified artifact in isolation
95+
shell: bash
96+
run: |
97+
set -euo pipefail
98+
RELEASE_DIR="${RUNNER_TEMP}/devcodex-release-artifact"
99+
RELEASE_ARTIFACT_PATH="$(node -e 'const fs=require("fs"); const value=JSON.parse(fs.readFileSync(`${process.env.RELEASE_DIR}/exact-release-artifact.receipt.json`,"utf8")); process.stdout.write(`${process.env.RELEASE_DIR}/${value.artifactFile}`)')"
100+
node scripts/test-global-install-smoke.js --tarball "${RELEASE_ARTIFACT_PATH}"
101+
node scripts/exact-release-artifact.js verify --output-dir "${RELEASE_DIR}"
102+
env:
103+
RELEASE_DIR: ${{ runner.temp }}/devcodex-release-artifact
104+
84105
- name: Preserve qualified artifact
85106
uses: actions/upload-artifact@v4
86107
with:
@@ -91,15 +112,18 @@ jobs:
91112

92113
publish:
93114
needs: qualify
94-
if: github.event_name != 'workflow_dispatch'
115+
if: always() && github.event_name == 'workflow_dispatch' && inputs.mode == 'publish-qualified'
95116
runs-on: ubuntu-latest
96117
permissions:
118+
actions: read
97119
contents: read
98120
id-token: write
99121

100122
steps:
101123
- name: Checkout
102124
uses: actions/checkout@v6
125+
with:
126+
ref: ${{ inputs.release_tag }}
103127

104128
- name: Setup Node.js
105129
uses: actions/setup-node@v6
@@ -108,11 +132,31 @@ jobs:
108132
registry-url: https://registry.npmjs.org
109133
package-manager-cache: false
110134

135+
- name: Verify publish-qualified input binding
136+
shell: bash
137+
env:
138+
RELEASE_TAG: ${{ inputs.release_tag }}
139+
QUALIFICATION_RUN_ID: ${{ inputs.qualification_run_id }}
140+
QUALIFICATION_RUN_ATTEMPT: ${{ inputs.qualification_run_attempt }}
141+
run: |
142+
set -euo pipefail
143+
PKG_VERSION="$(node -p "require('./package.json').version")"
144+
if [ "${RELEASE_TAG}" != "v${PKG_VERSION}" ]; then
145+
echo "Release tag ${RELEASE_TAG} does not match package version ${PKG_VERSION}"
146+
exit 1
147+
fi
148+
if ! [[ "${QUALIFICATION_RUN_ID}" =~ ^[0-9]+$ ]] || ! [[ "${QUALIFICATION_RUN_ATTEMPT}" =~ ^[0-9]+$ ]]; then
149+
echo "publish-qualified requires numeric qualification run identity"
150+
exit 1
151+
fi
152+
111153
- name: Download qualified artifact
112154
uses: actions/download-artifact@v5
113155
with:
114-
name: qualified-release-${{ github.ref_name }}-${{ github.run_id }}-${{ github.run_attempt }}
156+
name: qualified-release-${{ inputs.release_tag }}-${{ inputs.qualification_run_id }}-${{ inputs.qualification_run_attempt }}
115157
path: ${{ runner.temp }}/devcodex-release-artifact
158+
run-id: ${{ inputs.qualification_run_id }}
159+
github-token: ${{ github.token }}
116160

117161
- name: Verify exact artifact and detect an existing version
118162
id: prepare
@@ -154,14 +198,14 @@ jobs:
154198
- name: Upload irreversible publish receipt
155199
uses: actions/upload-artifact@v4
156200
with:
157-
name: published-release-${{ github.ref_name }}-${{ github.run_id }}-${{ github.run_attempt }}
201+
name: published-release-${{ inputs.release_tag }}-${{ github.run_id }}-${{ github.run_attempt }}
158202
path: ${{ runner.temp }}/devcodex-release-artifact
159203
if-no-files-found: error
160204
retention-days: 90
161205

162206
finalize:
163207
needs: [qualify, publish]
164-
if: always() && ((github.event_name != 'workflow_dispatch' && needs.publish.result == 'success') || github.event_name == 'workflow_dispatch')
208+
if: always() && github.event_name == 'workflow_dispatch' && ((inputs.mode == 'publish-qualified' && needs.publish.result == 'success') || inputs.mode == 'finalize-only')
165209
runs-on: ubuntu-latest
166210
permissions:
167211
actions: read
@@ -179,15 +223,28 @@ jobs:
179223
node-version: 24.17.0
180224
package-manager-cache: false
181225

226+
- name: Verify finalize recovery input binding
227+
if: inputs.mode == 'finalize-only'
228+
shell: bash
229+
env:
230+
PUBLISH_RUN_ID: ${{ inputs.publish_run_id }}
231+
PUBLISH_RUN_ATTEMPT: ${{ inputs.publish_run_attempt }}
232+
run: |
233+
set -euo pipefail
234+
if ! [[ "${PUBLISH_RUN_ID}" =~ ^[0-9]+$ ]] || ! [[ "${PUBLISH_RUN_ATTEMPT}" =~ ^[0-9]+$ ]]; then
235+
echo "finalize-only requires numeric publish run identity"
236+
exit 1
237+
fi
238+
182239
- name: Download current publish receipt
183-
if: github.event_name != 'workflow_dispatch'
240+
if: inputs.mode == 'publish-qualified'
184241
uses: actions/download-artifact@v5
185242
with:
186-
name: published-release-${{ github.ref_name }}-${{ github.run_id }}-${{ github.run_attempt }}
243+
name: published-release-${{ inputs.release_tag }}-${{ github.run_id }}-${{ github.run_attempt }}
187244
path: ${{ runner.temp }}/devcodex-release-artifact
188245

189246
- name: Download prior publish receipt for finalize-only recovery
190-
if: github.event_name == 'workflow_dispatch'
247+
if: inputs.mode == 'finalize-only'
191248
uses: actions/download-artifact@v5
192249
with:
193250
name: published-release-${{ inputs.release_tag }}-${{ inputs.publish_run_id }}-${{ inputs.publish_run_attempt }}
@@ -198,7 +255,7 @@ jobs:
198255
- name: Verify tag and published receipt binding
199256
shell: bash
200257
env:
201-
RELEASE_TAG: ${{ github.event_name == 'workflow_dispatch' && inputs.release_tag || github.ref_name }}
258+
RELEASE_TAG: ${{ inputs.release_tag }}
202259
run: |
203260
set -euo pipefail
204261
TAG_VERSION="${RELEASE_TAG#v}"
@@ -245,7 +302,7 @@ jobs:
245302
shell: bash
246303
env:
247304
GH_TOKEN: ${{ github.token }}
248-
RELEASE_TAG: ${{ github.event_name == 'workflow_dispatch' && inputs.release_tag || github.ref_name }}
305+
RELEASE_TAG: ${{ inputs.release_tag }}
249306
RELEASE_DIR: ${{ runner.temp }}/devcodex-release-artifact
250307
run: |
251308
set -euo pipefail

‎CHANGELOG.md‎

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,16 +1,17 @@
11
# 变更日志 (CHANGELOG)
22

33
> **说明**: 版本概览摘要;历史版本见对应详细变更文件。
4-
> **最新版本详细变更文档**: [`changelogs/releases/v1.19.5.md`](./changelogs/releases/v1.19.5.md)
5-
> **最后更新**: 2026-08-30
6-
> **当前版本**: v1.19.5 修复正式任务在 finalized admission、过期/释放 owner 与 fresh resume 组合下无法恢复的 P0 死锁,并补齐 Stop/reacquire、单赢家 CAS、候选容量与滚动升级边界。版本发布权威以对应 Git tag、npm registry 与 GitHub Release 为准。
4+
> **最新版本详细变更文档**: [`changelogs/releases/v1.20.0.md`](./changelogs/releases/v1.20.0.md)
5+
> **最后更新**: 2026-09-06
6+
> **当前版本**: v1.20.0 完成任务连续性、项目 Profile、安全恢复、多语言、可扩展 SkillRoute、宿主原生多 Agent 编排合同与验证收敛架构升级。版本发布权威以对应 Git tag、npm registry 与 GitHub Release 为准。
77
88
---
99

1010
## 版本概览
1111

1212
| 版本 | 日期 | 变更摘要 | 详细 |
1313
|------|------|---------|------|
14+
| [v1.20.0](./changelogs/releases/v1.20.0.md) | 2026-09-06 | 🚀 **任务连续性与工程控制面升级**:合法 CP 演进可跨会话续代;无 taskId 与异常恢复不再形成永久死锁;项目优先 Profile 与 workspace fallback、多语言连续性、分层 SkillRoute、多 Agent 隔离编排及修复批次收敛进入统一合同;发布采用同一精确制品的两阶段资格化、真实宿主验收与续发 | [查看](./changelogs/releases/v1.20.0.md) |
1415
| [v1.19.5](./changelogs/releases/v1.19.5.md) | 2026-08-30 | 🚑 **正式任务连续性恢复**:finalized + expired/released owner 可由 fresh resume 原子换代;任务永久、owner 短租约;accepted Stop 停放、同会话重取、跨会话单赢家接管;旧 owner/nonce、活跃 turn/operation、漂移与终态继续失败关闭 | [查看](./changelogs/releases/v1.19.5.md) |
1516
| [v1.19.4](./changelogs/releases/v1.19.4.md) | 2026-08-29 | 🚑 **自适应流程与跨会话 owner 恢复**:PC0~PC10 与流程/方案/验证四轴决策落地;显式 `init --profile` 接受现存空目录;CI 按影响范围执行;publish/finalize 可恢复;awaiting-owner admission 可在严格身份与真相回读边界内安全换代接管 | [查看](./changelogs/releases/v1.19.4.md) |
1617
| [v1.19.3](./changelogs/releases/v1.19.3.md) | 2026-08-28 | 🚑 **确认持久化与任务 owner P0 修复**:有界恢复 taskless instruction/work-item/route/plan/project 绑定;超限降级为无 authority identity-only;CP writer 的安全链接投影可被 owner 精确复核,并提供 30 秒内专项快测 | [查看](./changelogs/releases/v1.19.3.md) |

‎RULES.md‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
1-
# DevCodex v1.19.5 — 使用入口
1+
# DevCodex v1.20.0 — 使用入口
22

3-
> AI workflow injector for Copilot / Claude Code / Codex / Gemini / Grok / Cursor Beta · publisher: Rocky · version: 1.19.5
3+
> AI workflow injector for Copilot / Claude Code / Codex / Gemini / Grok / Cursor Beta · publisher: Rocky · version: 1.20.0
44
55
## 正式主支持客户端
66

‎SECURITY.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44

55
| Version | Supported |
66
|---------|:----------:|
7-
| 1.19.x(当前) | ✅ |
7+
| 1.20.x(当前) | ✅ |
88
| 1.17.x | ⚠️ 仅安全补丁 |
99
| 1.16.x | ⚠️ 仅安全补丁 |
1010
| 1.12.x | ⚠️ 仅安全补丁 |

‎changelogs/releases/v1.20.0.md‎

Lines changed: 41 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
1+
# DevCodex v1.20.0
2+
3+
> 发布日期:2026-09-06
4+
5+
v1.20.0 是一次面向长任务可靠性的控制面升级。它让正式任务的写入、恢复、项目上下文、语言、Skill 路由、并行编排和验证收敛使用同一组可恢复、可审计且以人类阅读为主的合同。
6+
7+
## 核心能力
8+
9+
- **跨会话任务连续性**:任务检查点使用 epoch/generation 与 CAS 围栏;正常 CP 推进和需求文档演进可生成安全后继代次,不再把首次准入摘要当作永久不可变化的唯一真相。
10+
- **异常恢复不形成永久死锁**:无 taskId、owner 过期、终端续办、compact、冷恢复和候选漂移均有有界恢复或明确降级路线;旧 owner、旧 nonce、迟到写入和身份冲突仍被隔离。
11+
- **项目优先的 Profile**:识别到真实项目但缺少 Profile 时保持项目绑定并提供原子初始化;只有工作区没有可识别项目时才回退到 `.devcodex/workspace`。缺失、草稿、已审查与局部无效状态分开呈现。
12+
- **语言连续性**:`LanguageContextV3` 综合当前消息、任务上下文、持久偏好与短确认语义;中文任务回复“确认”后不会无故切换英文。workspace/project 可配置固定语言或自动推断。
13+
- **可扩展 SkillRoute**:项目、workspace 与内置 Skill 分层解析;目录规模增长时先加载元数据短名单,再按需精确分页正文。用户自定义 Skill 不受固定五页或小数量上限约束,冲突、循环、超限和 TOCTOU 失败保持局部化。
14+
- **宿主原生多 Agent 编排合同**:根 Agent 负责计划、隔离、租约、取消、证据汇合和最终写入;源码子任务要求独立 worktree,共享 CP、记忆、报告、Profile、package 和发布面保持单写者;宿主不支持时安全退回串行。
15+
16+
## 关键修复
17+
18+
- 正式任务在 finalized 后因合法概况变化触发 `FINALIZED_TASK_RESUME_CANONICAL_DRIFT` 的阻断路径已改为受验证的 G(n+1) 续代。
19+
- 默认项目绑定不再误落到 DevCodex 自身项目;缺项目 Profile 不再导致任务准入或只读工作永久阻断。
20+
- 正式产物写入绑定 canonical 模板、槽位、摘要、必需章节与写后回读,同时允许在受控扩展点增加人类需要的内容。
21+
- 用户可见响应、报告和进度以人类结论为主;大体量机器证据保留在索引和证据层,不再倾倒到主阅读面。
22+
- 历史 audit-state 按 current、legacy、non-audit、unsupported 和 invalid 分型;历史字节保持不变,当前无效状态仍严格失败。
23+
- Profile 分节读取按同一 source digest 累计全部必需标题,单节命中不再错误标记完整。
24+
- 验证修复期新增 `RepairConvergenceStateV1`:先冻结完整问题集、批量修复,再统一 affected;独立失败一次收齐,相同绿色候选零执行复用,避免每修一个问题就重跑近全量。
25+
- 验证执行支持有界并发、候选证据缓存、关键路径 ETA 与项目 `.tmp` 临时数据治理;发布、安全、恢复、真实宿主与共享状态节点继续现场验证。
26+
27+
## 兼容性与边界
28+
29+
- 无新增第三方运行时依赖、数据库迁移、端口或常驻服务。
30+
- 旧 TaskRecovery、ContextRead、SkillRoute、LanguageContext 与 Profile 状态继续按已登记的兼容路径读取;新写入只使用当前 schema。
31+
- DevCodex 只校验任务、项目、范围、代次和证据等工作流有效性;文件、命令、删除及工具调用权限继续由实际宿主和用户配置决定。
32+
- 多 Agent 是能力相关的编排合同,不假设所有宿主都提供相同原生能力;缺失能力时保持串行与诚实的 `UNVERIFIED` 上限。
33+
34+
## 发布验证范围
35+
36+
- 源码静态检查、控制面定向回归、Profile/历史兼容、完整 V3 与安全审计。
37+
- tag 阶段只生成一个正式精确 tarball,并先完成独立 consumer/HOME/npm prefix/cache/workspace 安装验收。
38+
- 本机真实 Codex 宿主复用该同一 tarball 完成 G1→G2、异常恢复、负例与精确清理后,才触发 `publish-qualified` 续发。
39+
- exact-head GitHub CI、annotated tag、npm provenance、GitHub Release、registry 摘要与发布后全局安装回读。
40+
41+
升级后建议运行 `devcodex global-adapters apply` 刷新用户级宿主适配器,再在目标项目执行 `devcodex status` 与 `devcodex doctor --json` 对账安装版本、runtime generation 和 Profile 状态。

‎changelogs/unreleased.md‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,12 @@
11
# 未发布变更(Unreleased)
22

33
> **用途**: 记录尚未正式发版的实现级变更。
4-
> **当前**: v1.19.5 已进入补丁发布候选资格链;本轮正式任务连续性修复已归档到 `changelogs/releases/v1.19.5.md`,正式发布事实只在 tag、registry、GitHub Release 与本机 R7 证据实际形成后成立。
4+
> **当前**: v1.20.0 已进入发布资格链;本轮任务连续性与控制面升级已归档到 `changelogs/releases/v1.20.0.md`,正式发布事实只在 tag、registry、GitHub Release 与本机 R7 证据实际形成后成立。
55
66
## 当前未发布实现候选
77

8+
- **v1.20.0 发布候选 — 任务连续性与工程控制面升级**:汇总 Stage A/B 的任务写入代际、合法 CP 演进续代、taskless 恢复、项目优先 Profile、多语言连续性、分层 SkillRoute、宿主原生多 Agent 编排合同、验证执行提速与修复批次收敛。完整说明见 [`changelogs/releases/v1.20.0.md`](./releases/v1.20.0.md)。正式发布事实仍只由 tag、registry、GitHub Release 与发布后安装回读共同成立。
9+
- **两阶段精确制品发布防护**:tag 资格阶段只生成一个正式精确 tarball,对同一制品完成隔离 consumer/HOME/prefix/cache/workspace 安装并保存;本机复用该制品完成真实 Codex G1→G2 后,才通过 `publish-qualified` 续发 npm 与 GitHub Release,避免 tag 触发后未经真实宿主验收即发生不可逆发布。
810
- **A4-R22 CP 候选模板资格前置**:`memory_cp_confirm` 在写入 Auto 确认状态或 CP 会话记录前,先按分层 `ArtifactSlotRegistryV2` 校验 `artifactPath` 的任务类型、CP 阶段与权威路径匹配,再对同一稳定文件执行 canonical template binding、资格校验和读回;模板失格、阶段错位或文件漂移均以 typed error 零写入拒绝。确认回执以加法字段携带 slot、binding 与 qualification,输入契约、工具名和 CP 表格式保持不变。本项仅为本地源码候选,未生成 H0 或 tarball,未安装、未修改 Profile,未执行 Git 或发布。
911
- **A4-R13 同确认点人类文档演进恢复**:finalized 正式任务续办不再把 `00-需求概况.md` 的全文摘要或其中固定 phase/version 文案当作永久权限凭据;同一机器 CP 链内的正常叙述更新以确定性的进程内 `verified-resume-reconciliation` 接入既有 canonical lineage,CAS 成功后仍只持久化旧版本可读的 `resume-generation`。合法 CP successor 与 legacy bridge 同样只依赖 TaskIdentity、项目/root 和摘要绑定的机器 CP 证据;错误 identity/CP/root/session、stale candidate、live operation、owner/CAS 冲突继续零写失败。本项仅为本地源码候选,未生成或安装 tarball,未修改 Profile,未提交、推送或发布。
1012
- **A4-R11 规模安全恢复与历史模板处置**:稳定 taskId 先复用受控路径提示,提示不可用时只分页读取任务身份并命中即停,不再预读所有任务 sessions/CP;未唯一定位时以 provisional disposition 允许当前读取、分析、消歧或普通新准入继续,且已绑定项目不再循环索要 project。历史 CP3 的错误模板合格声明由任务私有、文件摘要与严格合格后继共同绑定的 sidecar 隔离,当前 head、canonical、未知制品、摘要漂移和不合格 replacement 仍严格失败关闭。本项仅为本地候选,未生成或安装 tarball,未提交、推送或发布。

‎content/duplication-inventory.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"schemaVersion": "ControlContentDuplicationInventoryV1",
3-
"sourceBundleDigest": "a91a7dd3f03550a61892976a9a386f6b35eb08a153530de2c03a6bab9a85dddd",
3+
"sourceBundleDigest": "b91548e9d16e8d12c2c753dcb50a688dac31c58c879ecb2474f8f20c8081566a",
44
"thresholds": {
55
"minParagraphChars": 100,
66
"sectionThreshold": 0.94,

‎content/instructions/00-safety.instructions.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
applyTo: "**"
33
description: 安全底线与输出语言规则,定义 S01~S07、违规处理与不可豁免边界
44
priority: P2
5-
version: 1.19.5
5+
version: 1.20.0
66
---
77
# 安全底线规范(S01~S07)
88

‎content/instructions/01-common.instructions.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
applyTo: "**"
33
description: 通用规范总则,覆盖优先级、意图路由、Profile/active-root、宿主适配与治理总线
44
priority: P5
5-
version: 1.19.5
5+
version: 1.20.0
66
---
77
# 通用规范
88

‎content/instructions/01a-profile-loading.instructions.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
applyTo: "**"
33
description: 意图驱动的 Profile 加载、active-root 路径、目标项目识别与项目现实扩展规范
44
priority: P5
5-
version: 1.19.5
5+
version: 1.20.0
66
---
77
# Profile 加载与项目现实扩展
88

0 commit comments

Comments
 (0)