Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
375 commits
Select commit Hold shift + click to select a range
1cca4c8
fix(routing): give minContextWindow spec a uniform max member
Wibias Aug 6, 2026
97c973e
test(ci): accept the Copilot permission in the issue-quality workflow…
Wibias Aug 6, 2026
a5b3782
Merge pull request #1113 from lidge-jun/codex/fix-ci-issue-quality-pe…
Wibias Aug 6, 2026
f67753e
Merge remote-tracking branch 'refs/remotes/upstream/dev' into pr-1108…
Wibias Aug 6, 2026
0978221
fix(codex): address CodeRabbit round on the rebased head
XertroV Aug 6, 2026
48d35e9
test: replace hardcoded old username with generic 'user' in test fixture
Wibias Aug 6, 2026
7af5bba
Merge pull request #1116 from lidge-jun/codex/remove-old-username
Wibias Aug 6, 2026
4bfc4cc
fix(routing): satisfy react-doctor on the routing editor
Wibias Aug 6, 2026
efdfd1c
Merge pull request #715 from clankercode/feat/priority-levels
Wibias Aug 6, 2026
dc5ca52
feat(providers): add SambaNova and Nebius presets
olddonkey Aug 2, 2026
cb58400
fix(providers): address SambaNova and Nebius review feedback
olddonkey Aug 2, 2026
4c9c64b
test(providers): pin the renamed-preset destination-fallback boundary
lidge-jun Aug 6, 2026
cf3d4b5
fix(routing): address full reviewer set on the profiles editor
Wibias Aug 6, 2026
bbd82e7
Merge pull request #870 from olddonkey/codex/572-sambanova-nebius-mod…
lidge-jun Aug 6, 2026
1461de5
feat(providers): add DigitalOcean and Scaleway presets
olddonkey Aug 2, 2026
cecb6f4
fix(providers): tighten DigitalOcean and Scaleway metadata
olddonkey Aug 2, 2026
bcec06d
fix(routing): migrate subagentModelFallback and modelMap keys on alia…
Wibias Aug 6, 2026
e50f580
Merge pull request #872 from olddonkey/codex/572-digitalocean-scalewa…
lidge-jun Aug 6, 2026
96ae39b
fix(providers): replay DeepSeek reasoning for opencode-zen (#994)
justjxke Aug 5, 2026
957990a
test(providers): pin opencode-zen noVisionModels for DeepSeek models
justjxke Aug 5, 2026
5f44310
feat(providers): add Nscale and Vultr presets
olddonkey Aug 3, 2026
fcd713b
fix(routing): reject modelMap key collisions on profile alias change
Wibias Aug 6, 2026
7d0c02d
Merge pull request #1068 from justjxke/fix/opencode-zen-reasoning-replay
Wibias Aug 6, 2026
75f384c
Merge pull request #1108 from lidge-jun/feat/routing-profiles-editor
Wibias Aug 6, 2026
8b39f1a
fix(ci): re-run PR gate on issue_comment and gate prepush lint on gui…
Wibias Aug 6, 2026
ac8505d
fix(ci): pin issue_comment trigger and fallback checkout ref in gate …
Wibias Aug 6, 2026
8ed03e7
Merge pull request #937 from olddonkey/codex/572-nscale-vultr-model-apis
lidge-jun Aug 6, 2026
732f296
fix(ci): restrict issue_comment re-run to maintainers on PRs and cons…
Wibias Aug 6, 2026
36c87af
fix(ci): anchor hygiene delimiters to complete lines and share the ga…
Wibias Aug 6, 2026
4d13067
fix(ci): checkout dev on issue_comment reruns and fail closed on unve…
Wibias Aug 6, 2026
a0740f7
fix(ci): queue (not cancel) shared gate-comment writes and prove inte…
Wibias Aug 6, 2026
8c4ad03
fix(test): merge duplicate comments fixture and consume hygiene in re…
Wibias Aug 6, 2026
22cd62c
fix(ci): require canonical maintainer for issue_comment gate reruns
Wibias Aug 6, 2026
3c24629
Merge pull request #1123 from lidge-jun/codex/ci-gui-waiver-trigger
Ingwannu Aug 6, 2026
8c231ea
Merge remote-tracking branch 'origin/dev' into codex/260806-wp13-toggles
lidge-jun Aug 6, 2026
bdd12a9
fix(claude): stop POST /apply from cancelling its own enable
lidge-jun Aug 6, 2026
d9d5554
fix(claude): keep the server snapshot coherent after a Desktop enable
lidge-jun Aug 6, 2026
38d3834
fix(gui,cli): surface the partial-success apply instead of a clean su…
lidge-jun Aug 6, 2026
43a1fdc
Merge pull request #1106 from lidge-jun/codex/260806-wp13-toggles
lidge-jun Aug 6, 2026
eb0923e
fix(test): give the contended restore its real production wait budget
lidge-jun Aug 6, 2026
e9d957b
Merge pull request #1129 from lidge-jun/codex/260806-restore-watchdog…
lidge-jun Aug 6, 2026
435ade0
feat(codex): add account picker visibility setting
chrisae9 Aug 6, 2026
5bf9cc0
docs(devlog): plan the 260806 stacked bug campaign with contributor a…
lidge-jun Aug 6, 2026
b2d1bb8
fix(streaming): bound translated SSE inspection
Ingwannu Aug 6, 2026
6e6a52b
docs(devlog): correct the campaign roadmap after the A-phase audit
lidge-jun Aug 6, 2026
94c5ccf
fix(codex): skip empty native-profile stage sweeps
Ingwannu Aug 6, 2026
6b9f734
fix native-main ACL timeout recovery
luvs01 Aug 6, 2026
313608b
fix(codex): bound oversized rollout inspection
Simon-Opopeee Aug 6, 2026
e248660
fix(codex): bound rollout inspection reads and validate latest metadata
Simon-Opopeee Aug 6, 2026
7f8053c
fix(codex): parse rollout JSONL incrementally from bounded chunks
Simon-Opopeee Aug 6, 2026
bbdeb19
fix(codex): bound rollout reads to the observed size and decode UTF-8…
Simon-Opopeee Aug 6, 2026
3a3323b
fix(codex): re-stat rollout pathname, scan lines once, and preserve BOM
Simon-Opopeee Aug 6, 2026
3755aee
docs(devlog): repair the last stale anchors after audit round 2
lidge-jun Aug 6, 2026
e8f43e8
docs(devlog): redact contributor emails from the campaign unit
lidge-jun Aug 6, 2026
d4b5f36
docs(devlog): replace test globs with the contributors' real file lists
lidge-jun Aug 6, 2026
2edd21a
docs(devlog): disambiguate the src/combos overlap in phase 140
lidge-jun Aug 6, 2026
ea6ff8f
feat(responses): carry text.format into parsed request options
DevMello Aug 4, 2026
18585c7
feat(openai-chat): map text.format onto response_format
DevMello Aug 4, 2026
6ca6665
fix(openai-chat): preserve schema-less JSON formats
lidge-jun Aug 6, 2026
cc4dca1
feat(chat): forward response_format to routed openai-chat models
DevMello Aug 4, 2026
4d1e9fc
fix(responses): strip all structured-output traces from routed compac…
DevMello Aug 6, 2026
346687f
docs: distinguish response_format from Responses text.format
DevMello Aug 6, 2026
5fc7741
fix(google): send thinkingLevel for any model with an effort ladder
DevMello Aug 4, 2026
f5eb505
docs: note google effort ladders assert thinkingLevel support
DevMello Aug 6, 2026
bd65d72
docs(google): define effort ladder capability paths
lidge-jun Aug 6, 2026
1879bd0
fix(anthropic): preserve response model identity
lidge-jun Aug 6, 2026
0b72795
fix(vision): sync captions into Responses passthrough
baileyh8 Aug 5, 2026
d3bea65
fix(vision): skip empty message image references
baileyh8 Aug 5, 2026
c7dddb2
fix(vision): fail closed when raw-body captions are missing
lidge-jun Aug 6, 2026
90fa982
fix(telemetry): persist ordinary request attempts
lidge-jun Aug 6, 2026
8369eb9
fix(providers): normalize GitHub Copilot Responses streams
Simon-Opopeee Aug 6, 2026
58500d2
fix(copilot): keep oversized response streams flowing
Simon-Opopeee Aug 6, 2026
b6d3250
fix(responses): relay Darwin rewrites eagerly
lidge-jun Aug 6, 2026
362f1b9
fix(cursor): expose structured edit tools that convert to valid apply…
Aug 5, 2026
5442d56
fix(cursor): never shadow an existing bare edit tool with the synthet…
Aug 5, 2026
50b9ad8
test(cursor): cover native-exec mcpArgs structured edit translation
Aug 5, 2026
d5d96a6
fix(cursor): address CodeRabbit + Codex review feedback on #1017
Aug 5, 2026
d42722a
fix(cursor): gate structured-edit conversion on provenance, not tool …
lidge-jun Aug 6, 2026
ca5665d
fix(cursor): derive structured edits from final catalog
lidge-jun Aug 6, 2026
80e3b9a
fix(responses): preserve replay across empty deltas
Aug 6, 2026
2456ace
docs(devlog): record the campaign disposition matrix
lidge-jun Aug 6, 2026
ee048ef
docs(devlog): record the final audit findings and the attribution repair
lidge-jun Aug 6, 2026
5b32a5e
test: pin usage-log fixture writes to the scratch home
Yuxin-Qiao Aug 6, 2026
64be205
fix(test): isolate usage-log fixtures from the real OpenCodex home
Yuxin-Qiao Aug 4, 2026
5bf9955
docs(codex-app-models): document Desktop remote allowlist limitation
Yuxin-Qiao Aug 4, 2026
6341bd4
docs(devlog): close out phases 140 and 150
lidge-jun Aug 6, 2026
b39eecf
Merge pull request #1096 from chrisae9/split/1019-01-picker-setting
Wibias Aug 6, 2026
153f8aa
fix(probe): walk the Windows service definition chain for ownership
Wibias Aug 6, 2026
ca015f7
fix(probe): treat only definitive "not found" as absent in Windows ta…
Wibias Aug 6, 2026
c4fb80b
fix(probe): address Codex review findings on the Windows chain walk
Wibias Aug 6, 2026
783e4f2
feat(providers): fill rate-limit gaps in the providers overview
Wibias Aug 6, 2026
f01c2ce
feat(providers): add live quota probes for clinepass, z.ai, and minimax
Wibias Aug 6, 2026
fa659ca
feat(providers): add live quota probes for five more API-key providers
Wibias Aug 6, 2026
118ba32
fix(providers): address Codex + CodeRabbit findings on quota probes a…
Wibias Aug 6, 2026
dd7c7ce
fix(providers): address latest Codex + CodeRabbit findings
Wibias Aug 6, 2026
09b3a26
ci: trigger Cross-platform CI for the provider rate-limits PR
Wibias Aug 6, 2026
554525c
fix(providers): address Codex findings on limits resolution and probes
Wibias Aug 6, 2026
86e382d
fix(gui): restore React Fast Refresh and split documented-limits logic
Wibias Aug 6, 2026
5ce9358
feat(providers): add live Command Code quota probe
Wibias Aug 7, 2026
dadda32
refactor(providers): remove documented-rate-limits display
Wibias Aug 7, 2026
a312f75
revert(providers): drop Command Code quota probe (cookie-only billing…
Wibias Aug 7, 2026
b401f39
Merge pull request #1157 from Wibias/feat/provider-rate-limits
Wibias Aug 7, 2026
ca9618a
fix(probe): address bot review findings on the Windows service probe
Wibias Aug 7, 2026
9aff092
Merge pull request #1133 from lidge-jun/codex/260806-stack01-bounded-sse
lidge-jun Aug 7, 2026
5ba0c18
Merge pull request #1134 from lidge-jun/codex/260806-stack02-native-p…
lidge-jun Aug 7, 2026
83a21cc
fix(probe): address CodeRabbit findings on winsw, raw schtasks, and c…
Wibias Aug 7, 2026
ebd58d2
Merge pull request #1135 from lidge-jun/codex/260806-stack03-acl-timeout
lidge-jun Aug 7, 2026
635349b
Merge pull request #1136 from lidge-jun/codex/260806-stack04-rollout-…
lidge-jun Aug 7, 2026
e35faa7
Merge pull request #1137 from lidge-jun/codex/260806-stack05-structur…
lidge-jun Aug 7, 2026
2a13ed8
Merge pull request #1138 from lidge-jun/codex/260806-stack07-anthropi…
lidge-jun Aug 7, 2026
cd1c230
Merge pull request #1139 from lidge-jun/codex/260806-stack06-vision-u…
lidge-jun Aug 7, 2026
18d1729
Merge pull request #1141 from lidge-jun/codex/260806-stack08-copilot-…
lidge-jun Aug 7, 2026
abf430e
Merge pull request #1142 from lidge-jun/codex/260806-stack09-darwin-e…
lidge-jun Aug 7, 2026
a260006
Merge pull request #1144 from lidge-jun/codex/260806-stack10-cursor-r…
lidge-jun Aug 7, 2026
20c5bd2
Merge pull request #1150 from lidge-jun/codex/260806-stack11-test-iso…
lidge-jun Aug 7, 2026
48bbac6
test(probe): cover WinSW exe-missing fail-closed case
Wibias Aug 7, 2026
2daf3dd
docs(devlog): record the merge and its post-merge audit
lidge-jun Aug 7, 2026
f20a479
Merge pull request #1147 from lidge-jun/codex/260806-stack00-campaign…
lidge-jun Aug 7, 2026
dd1e1a8
fix(probe): fail closed on broken scheduler chains and WinSW exe gaps
Wibias Aug 7, 2026
7e877c4
test(probe): skip dangling-plist symlink test when symlinks are unava…
Wibias Aug 7, 2026
cc97b6c
test(probe): wire the trusted System32 resolver seam for Linux CI
Wibias Aug 7, 2026
ee580a6
fix(combos): keep unknown effort models selectable
lidge-jun Aug 6, 2026
db7c6f0
fix(pi): keep loopback models visible
lidge-jun Aug 6, 2026
634390d
test(export): align the Pi CLI assertions with the loopback placeholder
lidge-jun Aug 6, 2026
033db63
docs(devlog): add the #1151 effort-picker before/after capture
lidge-jun Aug 7, 2026
06ee274
test(probe): cover Windows ownership hardening gaps
Wibias Aug 7, 2026
aa0e221
fix(probe): harden Windows ownership evidence
Wibias Aug 7, 2026
00f13ce
fix(probe): harden Windows ownership evidence
Wibias Aug 7, 2026
3fc24da
fix(probe): preserve Windows probe compatibility
Wibias Aug 7, 2026
f2e5a88
Merge pull request #1151 from lidge-jun/codex/260806-stack12-picker-p…
lidge-jun Aug 7, 2026
ce4d2b4
docs(devlog): plan the #572 provider-preset stack landing
lidge-jun Aug 6, 2026
6a864de
docs(devlog): record the #572 provider-preset stack outcome
lidge-jun Aug 6, 2026
1fc24f0
Merge pull request #1154 from Wibias/fix/windows-ownership-probe
Wibias Aug 7, 2026
36f58c6
test(issue-quality): reproduce #1162 false close
Wibias Aug 7, 2026
01ab60d
test(ci): run split issue-quality regressions
Wibias Aug 7, 2026
27abfcd
fix(issue-quality): accept equivalent structured bug evidence
Wibias Aug 7, 2026
2931008
test(issue-quality): preserve strict alias validation
Wibias Aug 7, 2026
27e681b
test(ci): watch issue-quality core changes
Wibias Aug 7, 2026
272416f
fix(issue-quality): normalize equivalent bug evidence safely
Wibias Aug 7, 2026
3a85bdc
test(issue-quality): cover CodeRabbit regressions
Wibias Aug 7, 2026
21d9f52
fix(issue-quality): address review findings in core
Wibias Aug 7, 2026
5da6a3c
test(issue-quality): make env regression actionable
Wibias Aug 7, 2026
6d04574
Merge pull request #1173 from lidge-jun/fix/issue-quality-equivalent-…
Wibias Aug 7, 2026
3b1d5c3
fix(storage): settle worker teardown on Linux
Wibias Aug 7, 2026
6957c72
test(claude): bound launcher probe subprocesses
Wibias Aug 7, 2026
a53163f
test(storage): cover Linux worker join settle
Wibias Aug 7, 2026
44dce33
Merge pull request #1179 from lidge-jun/fix/bun-isolate-worker-hangs
Wibias Aug 7, 2026
556dc88
fix(ci): revalidate readiness on CodeRabbit findings
Wibias Aug 7, 2026
160ef53
test(ci): cover CodeRabbit readiness revalidation
Wibias Aug 7, 2026
296ab8a
test(ci): bind readiness guard assertion
Wibias Aug 7, 2026
388eb62
test(ci): keep readiness regression out of existing shards
Wibias Aug 7, 2026
be5857f
test(ci): remove superseded readiness test path
Wibias Aug 7, 2026
b98e6e5
fix(ci): retain CodeRabbit outside-diff findings
Wibias Aug 7, 2026
d1cb1a0
test(ci): pin durable outside-diff findings
Wibias Aug 7, 2026
410e855
test(ci): pin deterministic CodeRabbit review ordering
Wibias Aug 7, 2026
43479a0
fix(ci): make CodeRabbit review ordering deterministic
Wibias Aug 7, 2026
5dae9e2
test(ci): pin default-branch trust for comment gate
Wibias Aug 7, 2026
aaca47f
fix(ci): source comment gate scripts from default branch
Wibias Aug 7, 2026
3322303
test(ci): update trusted checkout boundary assertion
Wibias Aug 7, 2026
9d43c05
test(ci): run CodeRabbit ordering regression in required suite
Wibias Aug 7, 2026
e73ed2b
feat(codex): initialize account picker selectors
chrisae9 Aug 6, 2026
440432b
docs(codex): document selector namespace helpers
chrisae9 Aug 7, 2026
b093eac
test(ci): align hardening allowlist with trusted comment checkout
Wibias Aug 7, 2026
8b4fa60
docs(devlog): plan the Models workspace tab consolidation
lidge-jun Aug 7, 2026
dcab0ae
docs(devlog): fold the round-1 audit findings into the roadmap
lidge-jun Aug 7, 2026
a7aa3d1
docs(devlog): split phase 2 and specify the mechanisms audit round 2 …
lidge-jun Aug 7, 2026
8a922a1
docs(devlog): close the roadmap cycle on a near-pass audit
lidge-jun Aug 7, 2026
b5b6f5d
feat(gui): register the nested Models tab hashes
lidge-jun Aug 7, 2026
086c222
test(gui): close the tab-hash regression gaps review found
lidge-jun Aug 7, 2026
7dcb8c2
feat(gui): build the Models tab workspace beside the legacy pages
lidge-jun Aug 7, 2026
39ad11a
fix(gui): keep the tab workspace alive through catalog load and tab s…
lidge-jun Aug 7, 2026
af93e29
fix(gui): stop a failed combos reload from discarding retained work
lidge-jun Aug 7, 2026
d1ecbed
test(gui): use fake timers for the poll gate and stop overclaiming a …
lidge-jun Aug 7, 2026
035cce3
feat(gui): retire the standalone Combos and Routing pages
lidge-jun Aug 7, 2026
9659048
docs(site): point the dashboard guides at the Models tabs
lidge-jun Aug 7, 2026
eeca089
style(gui): demote the Combos detail switch to pills
lidge-jun Aug 7, 2026
3e2d467
feat(gui): drop the duplicate Claude row and finish the panel lifecycles
lidge-jun Aug 7, 2026
6b00d5e
fix(gui): stop a late mutation from loading into a hidden Routing panel
lidge-jun Aug 7, 2026
7ccf190
fix(gui): keep a hidden tab panel from painting anyway
lidge-jun Aug 7, 2026
306c117
docs(devlog): close the Models workspace tabs unit
lidge-jun Aug 7, 2026
4e861a6
docs(devlog): add UI evidence for the Models workspace tabs
lidge-jun Aug 7, 2026
1e5fa3d
Merge pull request #1152 from chrisae9/split/1019-02-selector-initial…
Wibias Aug 7, 2026
0ef8120
refactor(gui): name the load-cancel path instead of suppressing the l…
lidge-jun Aug 7, 2026
eeae008
Merge pull request #1175 from lidge-jun/agent/revalidate-review-findings
Wibias Aug 7, 2026
adf3072
fix(ci): isolate storage policy tests from Linux shards
Wibias Aug 7, 2026
90f4d36
fix: apply CodeRabbit auto-fixes
coderabbitai[bot] Aug 7, 2026
6d8d9fc
Merge pull request #1204 from lidge-jun/agent/isolate-storage-policy-ci
Wibias Aug 7, 2026
3e60b1d
Merge pull request #1200 from lidge-jun/codex/260807-models-workspace…
lidge-jun Aug 7, 2026
7bcd992
fix(sse): accept unspaced `data:` fields across six parsers (#1170)
lidge-jun Aug 7, 2026
263c07f
fix(sse): treat a colonless field line as an empty value, and cover a…
lidge-jun Aug 7, 2026
8662a09
test(claude): activate the budgeted raw-frame parser with unspaced fi…
lidge-jun Aug 7, 2026
aa8851f
fix(codex): propagate routed DeepSeek and GLM effort
lidge-jun Aug 7, 2026
6429e9c
fix(acl): give one harden sequence a 30s envelope, not 5s (#1156)
lidge-jun Aug 7, 2026
2f242bb
fix(codex): reach custom-named providers, and keep summary defaults o…
lidge-jun Aug 7, 2026
392179e
docs(devlog): record the #1100 audit findings and the deferred BigMod…
lidge-jun Aug 7, 2026
07e7525
fix(providers): register BigModel's Coding Plan endpoint, which #1100…
lidge-jun Aug 7, 2026
22283ec
Merge pull request #1194 from lidge-jun/codex/260807-sse-unspaced-dat…
lidge-jun Aug 7, 2026
d6e7045
build(hooks): rebuild the packaged GUI after a merge brings gui/ changes
lidge-jun Aug 7, 2026
0b8e608
fix(deepseek): restore live upstream streaming on the Responses wire
lidge-jun Aug 7, 2026
2a9656d
fix(deepseek): repair content_part item_id on streamed reasoning item…
lidge-jun Aug 7, 2026
aca150b
test(codex): accept SQLite contention as a pre-approval race, matchin…
lidge-jun Aug 7, 2026
524b481
fix(update): preflight npm cache before shutdown
lidge-jun Aug 7, 2026
6678cfa
fix(update): stop the preflight from blocking legitimate updates (#55…
lidge-jun Aug 7, 2026
624f4a6
fix(update): make the budget fix actually reach the caller, and redac…
lidge-jun Aug 7, 2026
327e3ee
fix(update): drop wrap indentation before redacting, and accept a sym…
lidge-jun Aug 7, 2026
47e7cb7
fix(update): stop a redacted path from swallowing the log lines after…
lidge-jun Aug 7, 2026
4c70fc1
fix(update): redact wrapped profile paths line-aware, not by guessing…
lidge-jun Aug 7, 2026
0058231
fix(update): stop persisting free-form vendor output (round 7)
lidge-jun Aug 7, 2026
313dac3
fix(update): make the code allowlist an actual allowlist, and close s…
lidge-jun Aug 7, 2026
6e41fed
fix(update): allow-list what gets persisted instead of redacting what…
lidge-jun Aug 7, 2026
2429dc5
fix(update): field-scoped persistence with rendered commands and with…
lidge-jun Aug 7, 2026
bfcc66c
fix(update): never persist error message text, and delete the unwired…
lidge-jun Aug 7, 2026
b0e2a41
fix(update): stop copying Error.name, and validate the /healthz versi…
lidge-jun Aug 7, 2026
b65c470
docs(devlog): plan the #1102 loopback listener after five audit rounds
lidge-jun Aug 7, 2026
5c24ff7
fix(update): never echo a reported health version, matching or not (r…
lidge-jun Aug 7, 2026
7e3f5b9
feat(server): optional unauthenticated loopback listener for direct-s…
lidge-jun Aug 7, 2026
53f46dd
feat(models): add context window controls (#1073)
estelledc Aug 7, 2026
6cced96
fix(update): restore diagnostics by reading npm's named fields (round…
lidge-jun Aug 7, 2026
835a827
test(server): exercise the loopback listener over real sockets, and r…
lidge-jun Aug 7, 2026
d2d0e6a
fix(models): space context window fields (#1073)
estelledc Aug 7, 2026
c1d63e1
fix(update): validate field VALUES, not just field names (round 15)
lidge-jun Aug 7, 2026
09813ab
test(server): probe each loopback route with its real method, and rea…
lidge-jun Aug 7, 2026
19c13db
修复模型上下文设置:保留草稿并准确反馈保存结果
estelledc Aug 7, 2026
e3dae0e
fix(update): echo only our own package spec and known registry hosts …
lidge-jun Aug 7, 2026
3759c6c
fix(cursor): preserve the Grok wire model prefix on requests (#1159)
lidge-jun Aug 7, 2026
14fd4e7
feat(providers): add the MiMo token-plan preset on the Chat wire (#1158)
lidge-jun Aug 7, 2026
972ed0e
fix(windows): grant secret ACLs to effective token SID
luvs01 Aug 6, 2026
4854254
refactor(server): make composite listener shutdown testable, and pin …
lidge-jun Aug 7, 2026
1cfb2e7
fix(models): save every edited context window, and stop stale drafts …
lidge-jun Aug 7, 2026
821a845
fix(update): drop the package spec entirely from notarget (round 17)
lidge-jun Aug 7, 2026
aabee91
fix(quota): report unlimited A6API keys instead of hiding them (#1171)
lidge-jun Aug 7, 2026
355640d
docs(devlog): reuse the existing trusted System32 resolver in the #11…
lidge-jun Aug 7, 2026
fca2cd7
fix(windows): make the ACL identity boundary testable and machine-rea…
lidge-jun Aug 7, 2026
912cb99
test(server): prove the direct-spawn path with a real Codex app-server
lidge-jun Aug 7, 2026
b07a582
refactor(models): hoist the context-window parser to module scope
lidge-jun Aug 7, 2026
cb3dcdd
fix(responses): resolve part-event item_id by exact raw id, not outpu…
lidge-jun Aug 7, 2026
cb00907
Merge pull request #1197 from lidge-jun/codex/260807-routed-reasoning…
lidge-jun Aug 7, 2026
4f38015
fix(responses): key part-event id repair by (output_index, raw id) an…
lidge-jun Aug 7, 2026
1a0aa79
Merge pull request #1207 from lidge-jun/codex/260807-npm-cache-preflight
lidge-jun Aug 7, 2026
347de8c
Merge pull request #1208 from lidge-jun/codex/260807-adopt-cursor-quota
lidge-jun Aug 7, 2026
4ff8d69
Merge pull request #1211 from lidge-jun/codex/260807-mimo-token-plan
lidge-jun Aug 7, 2026
66ef899
Merge pull request #1216 from lidge-jun/codex/260807-windows-acl-toke…
lidge-jun Aug 7, 2026
4c3ffa6
Merge pull request #1220 from lidge-jun/codex/260807-loopback-listener
lidge-jun Aug 7, 2026
5609faf
Merge pull request #1223 from lidge-jun/codex/260807-context-window-c…
lidge-jun Aug 7, 2026
7459eda
fix(lifecycle): consolidate restart and service install cleanup
Wibias Aug 7, 2026
fc7a561
test(service): follow safe install wrapper in star prompt assertion
Wibias Aug 7, 2026
b1a659e
fix(tray): fail tracked actions before state success
Wibias Aug 7, 2026
d282966
chore: retrigger PR checks after tray hardening
Wibias Aug 7, 2026
70646fb
test(cli): bound models subprocesses
Wibias Aug 7, 2026
9326b85
Merge pull request #1206 from lidge-jun/agent/consolidate-restart-sup…
Wibias Aug 7, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
82 changes: 82 additions & 0 deletions .github/scripts/copilot-workflows.test.cjs
Original file line number Diff line number Diff line change
@@ -0,0 +1,82 @@
const test = require('node:test');
const assert = require('node:assert/strict');
const fs = require('node:fs');
const path = require('node:path');

const ROOT = path.resolve(__dirname, '..', '..');
const AI_ACTION = 'actions/ai-inference@2c43c91ae16266ca159d311430343c67a5ffa222';
const CLI_INSTALL = 'npm install --global @github/copilot@1.0.74';
const SETUP_NODE = 'actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e';

function readWorkflow(name) {
return fs.readFileSync(path.join(ROOT, '.github', 'workflows', name), 'utf8');
}

function count(text, fragment) {
return text.split(fragment).length - 1;
}

test('issue automation uses pinned Copilot inference without tool access', () => {
const quality = readWorkflow('enforce-issue-quality.yml');
const triage = readWorkflow('issue-triage.yml');
const combined = quality + '\n' + triage;

assert.equal(count(quality, AI_ACTION), 2);
assert.equal(count(triage, AI_ACTION), 1);
assert.equal(count(quality, SETUP_NODE), 2);
assert.equal(count(triage, SETUP_NODE), 1);
assert.equal(count(quality, CLI_INSTALL), 2);
assert.equal(count(triage, CLI_INSTALL), 1);
assert.equal(count(quality, 'copilot-requests: write'), 2);
assert.equal(count(triage, 'copilot-requests: write'), 1);
assert.equal(count(quality, 'GITHUB_TOKEN: ${{ github.token }}'), 2);
assert.equal(count(triage, 'GITHUB_TOKEN: ${{ github.token }}'), 1);
assert.equal(count(quality, 'model: ""'), 2);
assert.equal(count(triage, 'model: ""'), 1);

assert.doesNotMatch(combined, /\bmodels:\s*read\b/);
assert.doesNotMatch(combined, /max-tokens:/);
assert.doesNotMatch(combined, /copilot-allow-tools:/);
assert.doesNotMatch(combined, /--allow-tool/);
assert.doesNotMatch(combined, /GitHub Models/);
});

test('Copilot failures leave issue enforcement and triage retryable', () => {
const quality = readWorkflow('enforce-issue-quality.yml');
const triage = readWorkflow('issue-triage.yml');

assert.equal(count(quality, 'continue-on-error: true'), 6);
assert.equal(count(triage, 'continue-on-error: true'), 3);

assert.equal(
count(
quality,
"if: steps.prepare.outputs.should_translate == 'true' && steps.copilot.outcome == 'success'",
),
2,
);
assert.equal(
count(
quality,
"if: steps.prepare.outputs.should_translate == 'true' && steps.ai.outcome == 'success'",
),
2,
);
assert.equal(count(quality, "steps.ai.outcome == 'success' &&"), 2);
assert.equal(count(quality, "steps.parse.outcome == 'success' &&"), 2);
assert.match(quality, /leaving the issue unchanged and retryable/);
assert.match(quality, /leaving the comment unchanged and retryable/);

assert.equal(
count(quality, "if: steps.prepare.outputs.should_translate == 'true' && steps.node.outcome == 'success'"),
2,
);
assert.match(triage, /if: steps\.node\.outcome == 'success'/);
assert.match(triage, /if: steps\.copilot\.outcome == 'success'/);
assert.match(triage, /if: steps\.infer\.outcome == 'success'/);
assert.match(triage, /skipping duplicate suggestions for this issue/);

// The deterministic quality gate must still run when translation fails.
assert.match(quality, /needs: translate/);
assert.match(quality, /always\(\) &&\n\s+needs\.translate\.result != 'cancelled'/);
});
120 changes: 118 additions & 2 deletions .github/scripts/enforce-pr-target.test.cjs
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@ const fs = require("node:fs");
const path = require("node:path");
const { describe, it } = require("node:test");
const assert = require("node:assert/strict");
const { latestCodeRabbitReviewForHead } = require("./pr-quality-state.cjs");

describe("enforce-pr-target workflow", () => {
const workflowPath = path.join(__dirname, "../workflows/enforce-pr-target.yml");
Expand Down Expand Up @@ -48,20 +49,135 @@ describe("enforce-pr-target workflow", () => {
assert.match(workflow, /synchronize/);
});

it("checks out trusted base-branch scripts only (never PR head)", () => {
it("re-runs on issue_comment so a maintainer GUI waiver takes effect", () => {
// The GUI-screenshot gate is waived by a maintainer issue comment
// ("not touching gui"). `pull_request_target` types do not include issue
// comments, so without this trigger the waiver sits unread until a PR
// edit or push re-runs the gate.
assert.match(workflow, /^ issue_comment:/m);
assert.match(workflow, /- created/);
assert.match(workflow, /- edited/);
// The script resolves the PR number from the issue payload, which is what
// an issue_comment event delivers instead of a pull_request object.
assert.match(workflow, /context\.payload\.issue\?\.number/);
});

it("does not add review events that would break the trusted-base model", () => {
// `pull_request_review` / `pull_request_review_comment` load the workflow
// from the PR head branch (like `pull_request`), while this workflow's
// checkout pins the base SHA — head YAML + base scripts mismatch, so the
// gate crashes (`parseGateState is not a function`) and the head controls
// the workflow definition under a write token. The findings claim runs on
// every `pull_request_target` event instead (opened/edited/synchronize/
// ready_for_review).
assert.doesNotMatch(workflow, /^ pull_request_review:/m);
assert.doesNotMatch(workflow, /^ pull_request_review_comment:/m);
});

it("queries review threads and feeds them to the findings claim check", () => {
// Paginated read: `after: $cursor` + `pageInfo.hasNextPage`, so a busy PR
// with more than 100 threads cannot hide unresolved bot threads (fail-open
// gap in a fail-closed check).
assert.match(workflow, /reviewThreads\(first: 100, after: \$cursor\)/);
assert.match(workflow, /hasNextPage/);
assert.match(workflow, /unresolvedFindingsClaim/);
assert.match(workflow, /findingsClaim\.byBot/);
assert.match(workflow, /review_findings/);
});

it("fails closed when review threads cannot be read", () => {
assert.match(workflow, /findingsUnverifiable/);
assert.match(workflow, /findings claim could not be verified/);
});

it("writes exactly one consolidated comment via a single upsert helper", () => {
assert.match(workflow, /GATE_MARKER,/);
assert.match(workflow, /comment\.body\?\.includes\(GATE_MARKER\)/);
assert.match(workflow, /upsertGateComment/);
assert.match(workflow, /buildGateCommentBody/);
// No legacy two-comment write path remains.
assert.doesNotMatch(workflow, /upsertReadinessComment/);
assert.doesNotMatch(workflow, /buildReadinessCommentBody/);
// No intermediate checkpoint comment writes.
assert.doesNotMatch(workflow, /Draft conversion pending/);
assert.doesNotMatch(workflow, /Recording ownership state/);
});

it("manages the review-ready status label at the ready moment", () => {
assert.match(workflow, /REVIEW_READY_LABEL\s*=\s*"review-ready"/);
assert.match(workflow, /github\.rest\.issues\.addLabels/);
assert.match(workflow, /github\.rest\.issues\.removeLabel/);
assert.match(workflow, /reviewReadyDesired/);
});

it("keeps CodeRabbit auto-review unfiltered so maintainer PRs are not starved", () => {
// A positive `labels:` filter under `reviews.auto_review` in
// `.coderabbit.yaml` would restrict ALL automatic reviews to PRs carrying
// that label. Maintainer PRs never carry `review-ready` (no checklist), so
// such a filter would silently stop CodeRabbit from reviewing maintainer
// PRs. The label is a status marker only; assert the reviewer config
// directly, since the workflow never writes a labels block.
const coderabbit = fs.readFileSync(
path.join(__dirname, "../../.coderabbit.yaml"),
"utf8",
);
const autoReview = coderabbit.match(/auto_review:[\s\S]*?(?=\n\S|\n\s{2}\S)/);
assert.ok(autoReview, ".coderabbit.yaml must declare auto_review");
assert.doesNotMatch(autoReview[0], /labels:/);
});

it("migrates legacy two-comment PRs and deletes the old comments", () => {
assert.match(workflow, /migrateLegacyCommentsIfNeeded/);
assert.match(workflow, /migrateLegacyGateState/);
assert.match(workflow, /github\.rest\.issues\.deleteComment/);
assert.match(workflow, /legacyEnforcerComment/);
assert.match(workflow, /legacyReadinessComment/);
});

it("checks out scripts from the event-specific trusted boundary (never PR head)", () => {
// Scope the assertions to the checkout step itself, so a stray `ref:` on
// another step cannot satisfy the pin while the checkout stays mutable.
const checkoutStep = workflow
.split("- name: Checkout trusted PR-quality scripts")[1]
.split(/\n {6}- name:/)[0];
assert.match(checkoutStep, /actions\/checkout@[0-9a-f]{40}/);
assert.match(checkoutStep, /ref:\s*\$\{\{\s*github\.event\.pull_request\.base\.sha\s*\}\}/);
// `pull_request_target` pins the PR base SHA. Privileged `issue_comment`
// runs must source scripts from the repository default branch, matching
// the branch that supplied the workflow itself; unpromoted `dev` scripts
// must never execute under the write-capable token.
assert.match(
checkoutStep,
/ref:\s*\$\{\{\s*github\.event_name\s*==\s*'issue_comment'\s*&&\s*github\.event\.repository\.default_branch\s*\|\|\s*github\.event\.pull_request\.base\.sha\s*\}\}/,
);
assert.doesNotMatch(checkoutStep, /\|\|\s*'dev'/);
// The readiness ping reads MAINTAINERS.md from the same trusted checkout.
assert.match(checkoutStep, /sparse-checkout:\s*\|\s*\n\s*\.github\/scripts\n\s*MAINTAINERS\.md/);
assert.match(checkoutStep, /persist-credentials:\s*false/);
assert.doesNotMatch(workflow, /ref:\s*\$\{\{\s*github\.event\.pull_request\.head/);
});

it("orders same-head CodeRabbit reviews deterministically without timestamps", () => {
const head = "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa";
const latest = latestCodeRabbitReviewForHead({
reviews: [
{
id: 41,
commit_id: head,
user: { login: "coderabbitai[bot]" },
body: "older",
},
{
id: 42,
commit_id: head,
user: { login: "coderabbitai[bot]" },
body: "newer",
},
],
liveHeadSha: head,
});
assert.equal(latest?.id, 42);
});

it("loads pr-quality via require from the checked-out scripts", () => {
assert.match(workflow, /pr-quality\.cjs/);
assert.match(workflow, /collectPrQualityFailures/);
Expand Down
Loading
Loading