Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
85 commits
Select commit Hold shift + click to select a range
56e56a8
docs: clarify account pool policy boundary
YUHAO-corn Aug 20, 2026
1ff6ba1
docs(devlog): record the v2.28.0 release and its CI evidence
lidge-jun Aug 20, 2026
82acf30
docs(devlog): record the preview publish and the two runner-bound CI …
lidge-jun Aug 20, 2026
f2ebd30
Merge pull request #2192 from lidge-jun/codex/devlog-release-2280
lidge-jun Aug 20, 2026
bbf29b3
fix(responses): bound terminal guard delta retention
Ingwannu Aug 20, 2026
d541ffb
fix(google): support unwrapped freeform tool arguments in antigravity…
agentHits Aug 20, 2026
be65694
fix(google): restore signature on matched alternate key and bound inp…
agentHits Aug 20, 2026
99412cc
fix(google): parse validated trimmed input directly and test parse bo…
agentHits Aug 20, 2026
4e89471
fix(google): check string length before utf8.encode in replay unwrap
agentHits Aug 20, 2026
d949a68
docs: clarify pool enforcement boundary
YUHAO-corn Aug 20, 2026
13cf68a
fix(responses): bound orphan call reordering work
luvs01 Aug 20, 2026
b591cac
fix(responses): scope repeated orphan outputs per batch
luvs01 Aug 20, 2026
574fb8e
Merge pull request #2185 from YUHAO-corn/docs/account-pool-policy-risk
Ingwannu Aug 20, 2026
3fc4159
Merge pull request #2208 from luvs01/agent/bound-orphan-call-reordering
Ingwannu Aug 20, 2026
8ba7caa
Merge pull request #2198 from agentHits/fix/antigravity-replay-occurr…
Ingwannu Aug 20, 2026
03735ec
Merge pull request #2195 from lidge-jun/ingw/terminal-guard-delta-ret…
Ingwannu Aug 20, 2026
d8b37cc
fix(codex): refresh journaled injection ownership
luvs01 Aug 20, 2026
33d9a3b
fix(codex): preserve edits across reinjection restore
luvs01 Aug 20, 2026
f590791
fix(cursor): route composer-2.5 tool continuations through userMessag…
Aug 20, 2026
4a5042f
test(cursor): cover composer-2.5 tool-continuation routing
Aug 20, 2026
b277e74
test(cursor): use composer-2.5-fast for native replay regression
Aug 20, 2026
b30e5ba
fix(cursor): narrow composer-2.5 continuation to action selection
Aug 20, 2026
c6fa256
feat(clients): add Prime Agent as an export and integration client
umyunsang Aug 20, 2026
5b46620
fix(help): correct the export client count and hold it in lockstep
umyunsang Aug 20, 2026
42adf49
docs(integrations): document the Prime Agent client and sync client l…
umyunsang Aug 20, 2026
6cf3d2e
docs(clients): make the Prime path statement override-aware
umyunsang Aug 20, 2026
dba6acc
docs(clients): finish the translated client tables
umyunsang Aug 20, 2026
10c9498
fix(web-search): sanitize relayed citation sources
luvs01 Aug 20, 2026
6c41388
docs(clients): drop the stale loopback enumeration from four locales
umyunsang Aug 20, 2026
9a345f4
fix(web-search): close citation review gaps
luvs01 Aug 20, 2026
deacd53
fix(cursor): catch EOF terminal budget overflow
luvs01 Aug 20, 2026
4dd570b
fix(google): validate candidate, content and part containers
snowyukitty Aug 20, 2026
207f733
fix(responses): bound retained tool-search item IDs
luvs01 Aug 20, 2026
0866f2f
fix(clients): honor PI_CODING_AGENT_DIR for the pi client
umyunsang Aug 21, 2026
9c24e22
Merge pull request #2212 from ZSN12/fix/composer-2.5-tool-continuation
Ingwannu Aug 21, 2026
92c6b32
Merge pull request #2234 from luvs01/agent/bound-tool-search-item-ids…
Ingwannu Aug 21, 2026
38278e7
Merge pull request #2232 from snowyukitty/fix/google-response-shape-v…
Ingwannu Aug 21, 2026
b4ae86d
Merge pull request #2205 from luvs01/agent/refresh-codex-journal-owne…
Ingwannu Aug 21, 2026
78f1942
Merge pull request #2223 from luvs01/agent/sanitize-web-search-citati…
Ingwannu Aug 21, 2026
546ac8f
fix(management): answer 400 when a client path override is refused
umyunsang Aug 21, 2026
de3e38c
Merge remote-tracking branch 'origin/dev' into fix/pi-agent-dir-env
umyunsang Aug 21, 2026
ac76fd9
Merge pull request #2219 from umyunsang/feat/prime-agent-client
Ingwannu Aug 21, 2026
826a1b7
Merge pull request #2224 from luvs01/agent/cursor-eof-terminal-budget…
Ingwannu Aug 21, 2026
33c1572
Merge remote-tracking branch 'origin/dev' into fix/pi-agent-dir-env
umyunsang Aug 21, 2026
1423b86
Merge remote-tracking branch 'origin/dev' into fix/pi-agent-dir-env
umyunsang Aug 21, 2026
9d770c8
fix(management): validate the client path before loading the catalog
umyunsang Aug 21, 2026
377f229
feat(sidecar): shared auth module with login-shaped flags and auth sl…
lidge-jun Aug 21, 2026
a141859
feat(sidecar): unified picker candidate set for both sidecars (#2188 …
lidge-jun Aug 21, 2026
bd79ab5
feat(web-search): backend registry and executor-runnable candidate se…
lidge-jun Aug 21, 2026
60f60b6
feat(management): web-search sidecar write gates and filtered gui lis…
lidge-jun Aug 21, 2026
1e7c45b
feat(cli): ocx agent sidecar --list shares the server candidate sets …
lidge-jun Aug 21, 2026
29ce3da
feat(web-search): inert backend union + routed web_search field fix (…
lidge-jun Aug 21, 2026
d367927
Merge pull request #2235 from umyunsang/fix/pi-agent-dir-env
Ingwannu Aug 21, 2026
ef867c9
feat(web-search): live xai executor with opt-in x_search (#2188 L7) (…
lidge-jun Aug 21, 2026
738eed7
feat(web-search): live gemini executor on the Antigravity CCA transpo…
lidge-jun Aug 21, 2026
84d5523
feat(web-search): exa executor and the non-LLM search lane (#2188 L9)…
lidge-jun Aug 21, 2026
63d387c
fix(xai): default Grok OAuth to chat (#2255)
lidge-jun Aug 21, 2026
f46a1c6
docs(devlog): doc 110 new-wave triage rows (#2248-#2254 expansion) (#…
lidge-jun Aug 21, 2026
9884857
chore(codex): add privacy-bounded affinity diagnostics (#2196)
Ingwannu Aug 21, 2026
1ca08e6
fix(claude): sync agent roster on proxy startup (#2202)
Ingwannu Aug 21, 2026
0a120da
fix(oauth): redact secrets in structured event values (#2226)
luvs01 Aug 21, 2026
c175de1
fix(gui): keep select dropdowns opaque over rows beneath (#2253)
lilinxiong Aug 21, 2026
f8c97a3
docs(devlog): record the three-issue round, including the blocked ver…
lidge-jun Aug 21, 2026
83b4dc4
docs(devlog): record the backlog merge log and override adjudication …
lidge-jun Aug 21, 2026
ff3f304
fix(responses): bind continuation to final route (#2214)
luvs01 Aug 21, 2026
afd24bc
fix(google): repair tool-result adjacency (#2207)
Ingwannu Aug 21, 2026
faeedd9
fix(codex): preserve commented catalog assignments (#2236)
luvs01 Aug 21, 2026
4121827
fix(responses): routed-destination sanitize + opaque-state recovery s…
lidge-jun Aug 21, 2026
6c928aa
fix(integrations): honor OFF for Claude Desktop drift and Grok ensure…
lidge-jun Aug 21, 2026
2b988b3
fix(responses): capability-gate external_web_access in the canonical-…
lidge-jun Aug 21, 2026
6f1229a
test(xai): declare the web-search field capability in the raw streami…
lidge-jun Aug 21, 2026
6aecc8f
feat(xai): GUI opt-in switch for the Grok Responses lane (doc 130) (#…
lidge-jun Aug 21, 2026
3ffffc8
docs(devlog): release prep artifact for the next dev release (2.28.0 …
lidge-jun Aug 21, 2026
3c6a452
fix: recover pooled ChatGPT ciphertext rejection (#2269)
lidge-jun Aug 21, 2026
ca376d9
fix(lab): name the ACL failure code in the publisher key error (#2265)
ntdatt812 Aug 21, 2026
08cc2ac
fix(openai-chat): recover complete tool calls at EOF (#2271)
lidge-jun Aug 21, 2026
1f2615e
fix(google): enforce response part field contract (#2246)
Ingwannu Aug 21, 2026
e86a6fb
fix(responses): defer the serving-identity commit + passthrough findi…
lidge-jun Aug 21, 2026
6badac3
fix(zcode): use openai-compatible provider protocol to restore prefix…
lidge-jun Aug 21, 2026
bab8781
fix(integrations): sync MCode model capabilities (#2220 rebased) (#2276)
lidge-jun Aug 21, 2026
c378435
fix(cursor): reuse conversation checkpoints for incremental continuat…
lidge-jun Aug 21, 2026
e3b2136
docs(devlog): append the bug-backlog train to the release prep artifa…
lidge-jun Aug 21, 2026
d5ea14a
fix(router): backfill the xAI web-search capability into routed provi…
lidge-jun Aug 21, 2026
7881319
Merge pull request #2283 from lidge-jun/codex/backfill-xai-web-search…
lidge-jun Aug 21, 2026
0498a05
merge dev into main for the 2.29.0 promotion
lidge-jun Aug 21, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
10 changes: 9 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -129,8 +129,16 @@ see the [installation docs](https://opencodex.me/getting-started/installation/).

- **Use any LLM with Codex, Claude Code, Claude Desktop, and Grok Build** — 40+ providers out of
the box, each keeping its own native UI.
- **Pool ChatGPT accounts safely** — thread affinity, quota-aware auto-switching, cooldown and
- **Pool ChatGPT accounts** — thread affinity, quota-aware auto-switching, cooldown and
fail-closed auth handling.

> **Provider-policy note:** Account pooling is for routing and operational resilience only; it does
> not guarantee protection from provider rate limits, enforcement, suspension, or other account
> actions. OpenCodex does not endorse using additional accounts to circumvent provider limits or
> sharing account credentials between people. You are responsible for complying with each
> provider's current terms. See the
> [Codex Auth account-pool guidance](https://opencodex.me/guides/web-dashboard/#codex-auth-and-account-pools)
> and [OpenAI's current Terms of Use](https://openai.com/policies/terms-of-use/).
- **Combos** — one virtual model id with failover or weighted round-robin across providers. See
the [combo guide](https://opencodex.me/guides/combos/).
- **Sub-agents on any model** — feature routed models in Codex's sub-agent picker, with v1/v2
Expand Down
15 changes: 15 additions & 0 deletions devlog/_plan/260814_bug_resolution_campaign/030_wave3_cursor.md
Original file line number Diff line number Diff line change
Expand Up @@ -48,6 +48,21 @@ Cursor tool/continuation/edit 경로의 correctness fix를
- teardown 문제 (정상 완료를 aborted/expectedClose:false로 기록)는
별도 작은 PR로 먼저 고친다

2026-08-18 로컬 조사/prototype 메모 (fix/cursor-checkpoint-continuation, 아직 upstream PR 아님):

- 병목의 1차 원인은 JSON 포맷 자체가 아니라, 매 턴 rootPromptMessages/conversationTurns로
과거 대화를 다시 만드는 full replay semantics다.
- ConversationStateStructure checkpoint를 다음 conversationState로 재사용하면 no-tool
follow-up에서 로컬 rootBytes가 history와 같이 커지지 않는다. grok-4.6 live 3턴에서
2·3턴이 continuationMode=checkpoint였고 ALPHA-7을 기억했다.
- 공식 cursor-agent 같은 계정 대조: 1턴 cacheReadTokens 0 / input 18937, 같은 세션 2턴
cacheReadTokens 18816 / 새 input 331 / 답 ALPHA-7. OpenCodex Cursor wire는 usedTokens만
주므로 이쪽 usage로 cache hit를 주장하면 안 된다.
- tool-result는 마지막 정상 완료 턴 checkpoint + suffix replay가 live에서 동작했다.
client-tool suspend 턴 자체는 온전한 checkpoint가 없어 commit하지 않는다.
- 아직 미해결: 큰 context / 429 / kimi-k3 premature completion 재현, stateful live MCP
bridge, 정상 완료 teardown을 aborted로 분류하는 별건.

### Step 5: #1623 분할 (behavior fix 안정화 후)

1. refactor/adapter-registry-authority
Expand Down
119 changes: 119 additions & 0 deletions devlog/_plan/260820_bug_pr_backlog_consolidation/090_merge_log.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,119 @@
# 090 — Merge log: the bug-PR backlog landing on dev

Unit: 260820_bug_pr_backlog_consolidation
Work-phases: wp21-wp25.
dev before: `31ee7a683`. dev after: `a584890f8`.

## The override that was not needed

All 19 PRs sat at CHANGES_REQUESTED from @Ingwannu with green CI, and the plan was to merge
with admin authority. Three independent read-only lanes read every blocking review first, and
the answer was the same in all three: **the objection was factually current, not stale.**

The recurring complaint was "this head is N commits behind dev". Measured, it was true
everywhere — 16 to 25 commits, and `dev` had itself advanced to `31ee7a683` while the reviews
were being written. A green check on a stale head validates an integration state that no longer
exists, which is a real merge-readiness defect rather than a formality to wave through.

So the resolution was to rebase all 19 branches onto current `dev`, not to override. Admin
authority can bypass a gate; it cannot make an untested integration state tested.

Two reviews named genuine code defects, and both were fixed rather than overridden:

- **#2166** — `addRequestLog` is exported and bypassed the sanitizer: the reviewer reproduced a
raw 111-character value in the `/api/logs` ring against a sanitized 37-character value on
disk. Fixed at the shared ingress so both surfaces read from one normalized entry, with the
direct-ingress regression the reviewer asked for.
- **#2162** — a prompt mutation writing into the outbound user turn needed its content-shape
boundaries pinned. Added: an already-framed turn stays single, image-only content keeps its
image block behind the preamble, assistant-only block content keeps its tail before the
synthesized `(continue)` turn.

One more objection dissolved on rebase: #2148 was carrying eight `devlog/_plan/` planning files
inherited from its branch point. The rebase removed them.

## What landed

19 PRs, merged bottom-up. Every merge commit verified present in `git log origin/dev`.

| PR | dev merge commit | Absorbed from |
|---|---|---|
| #2134 | `930840ca4` | maintainer fix |
| #2160 | `114e9e543` | #2067 @waw4303 |
| #2162 | `087c3c368` | #2082 @yzxcj797 |
| #2164 | `31750b094` | #2027 @yzxcj797 |
| #2165 | `41689b374` | #2155 @waw4303 |
| #2166 | `5fbe65570` | #2163 @Ingwannu |
| #2137 | `be12328bc` | issue #2132 |
| #2146 | `aa07bc308` | #2101 @Ingwannu |
| #2138 | `81492fd10` | #2102 @lilinxiong |
| #2140 | `3ad9c7bf4` | #2100 + #2077 @ntdatt812 |
| #2141 | `1cc35c560` | #2056 @Ingwannu |
| #2142 | `52a463dd6` | #2131 @bet4it |
| #2144 | `8c8a66816` | #2105 @lilinxiong |
| #2145 | `83d5ffa3c` | #2040 @Ingwannu |
| #2147 | `7fc50846b` | #2104 @olddonkey |
| #2148 | `86ed9ed83` | #2109 + #2110 @drakonkat |
| #2149 | `17e8e916b` | #2053 @Ingwannu |
| #2150 | `9a7801547` | #2127 @agentHits |
| #2151 | `a584890f8` | #2075 @olddonkey |

Verification that the rebased content is what actually landed, split by what is still
re-runnable:

- **Re-runnable today:** every merge SHA in the table above satisfies
`git merge-base --is-ancestor <sha> origin/dev` (verified 2026-08-21, 19/19 true) — the
recorded merge commits are exactly the commits on `dev`, so the landed content is the
table's content by construction.
- **Historical assertion, no longer re-runnable:** six of the merges recorded a pre-rebase
branch SHA in their description. At merge time each rebased branch was compared with
`git diff --name-only origin/dev <branch> -- <that PR's own src/ and tests/ paths>` and
returned 0 differing files. The source branches were deleted in the wp0 cleanup
(260820 unit, executed record), so those comparisons cannot be reproduced from this log;
they stand as recorded assertions, not evidence, and the re-runnable ancestor check above
is the durable audit trail.

## Security surfaces, named rather than merged silently

`MAINTAINERS.md` reserves auth, credential handling, OAuth, workflows, and release automation
for explicit human review. Seven of the merged PRs touch that surface, and the user's merge
authorization is the human decision of record for each:

- **#2137 / #2146** — bearer admission and stored-credential substitution; entitlement-gated
model discovery sends the selected account's access token.
- **#2144** — decides whether the shell hook exposing `ANTHROPIC_AUTH_TOKEN` is installed.
- **#2145** — lowers third-party `function_call` output and restores it as a client-executed
private `tool_search_call`.
- **#2147** — OAuth 401 refresh and access-token replay.
- **#2148** — operator-selected destinations for Anthropic/Antigravity OAuth bearers. The
transport gate still rejects public cleartext HTTP; only explicitly opted-in local/private
relays may use it.
- **#2149** — OAuth credential commit ownership under the store lock.

## Issue closure

Every issue named by a merged PR is closed: #2133, #2132, #2092, #2047, #1950, #2097, #1886,
#2125, #2074, #1924, plus the superseded contributor PRs. Verified by `gh api` state, not by
assuming GitHub auto-closed them — these PRs targeted `dev`, not `main`, so auto-close does not
fire.

## Release readiness — not a release

At `a584890f8`:

- `bun run test` — 13716 pass / 10 skip / 0 fail across 866 files.
- `bun x tsc --noEmit` — exit 0.
- `bun run privacy:scan` — passed.
- `package.json` version line: **2.27.0** (unchanged by this campaign).

Changed surfaces: provider registry and transport headers, quota dispatch, routing capability
resolution, the Anthropic/OpenAI-chat/Google adapters, Responses core and compact, OAuth store
and credential commit, request logging and usage persistence, subagent roster management.

Not done, and deliberately: no `scripts/release.ts`, no npm publish, no tag, no change to
`main` or `preview`. Release execution needs its own authorization.

## Still open

**#2054** (@keepitmello) stays open by explicit instruction, carrying the wire-probe request.
**#2167** (@ntdatt812) arrived after this campaign and is untriaged.
Original file line number Diff line number Diff line change
@@ -0,0 +1,105 @@
# 110 — Three open bug issues: #2152, #2157, #2156

Unit: 260820_bug_pr_backlog_consolidation
Verification host: `ssh lidge:~/ci-wp3/opencodex`.

Three issues, three different shapes of answer. Two shipped fixes; one is honestly blocked.

## #2152 — Windows CI, three groups (PR #2178)

Three read-only lanes read the three groups. The shape PR #2178 already had was right, and two
of the issue's own premises turned out to be wrong — the fix follows the evidence:

- **Group 1** is not "the case budget is too small". `A-reduced` failed at 79,978 ms against a
150 s ceiling, so the outer budget was never the constraint. The real abort came from
`Fixture.request`'s unscaled 10 s `AbortSignal` firing from inside. And `E` does not start
`ocx` at all — it starts two lock helpers, and its holder released after a fixed 3 s wait
that a Windows contender's spawn can outlast.
- **Group 2** is not "an unprivileged Windows user cannot create symlinks". The runner can, so
`canSymlink` was true and the cases ran — then failed on Unix mode semantics that a Windows
directory cannot satisfy. Production already returns `windows_skip` for exactly that reason,
which is what makes the platform guard a correct skip rather than a masked failure.
- **Group 3** needed the crash retry the macOS leg already had.

### The defect I found in the fix

Group 3's retry grepped for `panic(thread`. This repository already worked that out and wrote
it down: `devlog/_fin/260731_pr_issue_triage_round/050_windows_ci_flake_rca.md:172` says not to
key on it, because Bun emits **both** `panic(thread 2852)` and `panic(main thread)` for the
same failure, and names `Internal assertion failure` as the stable fingerprint. Probed:

```text
MATCH panic(thread 3960): Internal assertion failure
MISS panic(main thread): Internal assertion failure
MISS panic(main thread): PANIC: reached unreachable code
```

The retry would have failed the shard on roughly half the crashes it exists to absorb, while
looking correct.

Three copies of that signature list exist — macOS inline, the new Windows inline, and
`is_bun_runtime_crash` — and the workflow comment already said to keep them in sync with
nothing enforcing it. They had drifted. All three now match, and the contract test pins **the
sync itself**, not the literal text, so the same drift cannot recur. RED-proven: restoring the
bad signature fails it with `windows:Internal assertion failure:false`.

`hasShellCommandHead` was added because the existing exact-whole-line matcher rejected the
`| tee` the retry requires — that is why the Windows step assertion went red — while still
rejecting an echoed or commented-out copy.

**What no local run can prove:** whether 45 s suffices under real Windows contention, the actual
skip result on the runner, and `PIPESTATUS` under Git Bash. Those need a `workflow_dispatch`,
and a useful proof run must exercise the crash path — a green Windows run shows the suite runs,
not that the retry fires.

## #2157 — shadow-helper observability (PR #2179)

The dashboard half of the attribution field #2166 landed. Delivered.

## #2156 — muse-spark truncation: BLOCKED, deliberately

PR #2180 was opened claiming to fix this. An adversarial review found the attribution wrong, and
the source agrees:

- A stall abort emits `response.incomplete` / `upstream_stall_timeout` (`bridge.ts:1371-1396`),
after which the bridge has cancelled upstream, closed, and explicitly discards any late
adapter event (`bridge.ts:837-845`).
- The reporter's error is emitted only after `reader.read()` returns EOF with tool calls still
pending (`openai-chat.ts:1819-1827`), surfacing as `response.failed`.

Different path, different client frame. The heartbeat **cannot** produce the reported error.

What the heartbeat does fix is real and worth landing alone: tool-call deltas are buffered, the
bridge arms its watchdog on adapter activity rather than socket activity, so a large argument
payload was indistinguishable from a hung upstream. The `#2156` references were reworded to
"found while investigating", and the closing keyword removed.

**Second finding, partially addressed.** Making the adapter emit one heartbeat per delta
exposed retention in `guardTerminalEventStream`'s `seen`, which feeds both the continuation
analysis and the rebuilt request. Two event classes must be distinguished: #2180 stopped
retaining `heartbeat` events, but the terminal guard still retains every OTHER nonterminal
event (tool-call deltas included), so a large argument payload can still grow `seen` without
bound wherever `terminalContinuationGuard` is on. The empty-completion guard passes heartbeats
through unretained; matching it for the remaining nonterminal classes is follow-up work, not
something this record's PR landed.

**Why blocked rather than fixed.** The adapter is reporting truthfully: that stream really did
end. What cannot be determined from here is why it ended for ocx and not for Pi direct.
`hadUsage: false` is suggestive — ocx does send `stream_options.include_usage` — but a provider
may simply ignore that flag, so it is not decisive either way.

Asked the reporter for the one thing that settles it: redacted raw SSE captures from a
Pi-direct success and an ocx failure for an equivalent request, through socket close, and
whether either carried `finish_reason`, `[DONE]`, or a usage-only final chunk. If ocx's
upstream closes without a terminal frame while Pi's does not, the difference is in what we send
or how we read it and it is ours. If both close identically and Pi is merely more tolerant, the
right answer is the buffered-mode fallback the reporter suggested — and that choice should rest
on their capture, not on a guess.

## Verification

At the branch tips, on `ssh lidge`:

- #2178: `bun test` 13719 pass / 15 skip / 0 fail; `tests/ci-workflows.test.ts` 132 pass / 0 fail.
- #2180: `bun test` 13722 pass / 15 skip / 0 fail; focused trio 112 pass / 0 fail.
- `bun x tsc --noEmit` exit 0 and `bun run privacy:scan` passed on both.
Loading
Loading