forked from lidge-jun/opencodex
-
Notifications
You must be signed in to change notification settings - Fork 0
fix(ci): scan markdown fences in linear time #462
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Draft
luvs01
wants to merge
76
commits into
Dev
Choose a base branch
from
codex/propose-fix-for-regex-denial-of-service-ou1mku
base: Dev
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Draft
Changes from all commits
Commits
Show all changes
76 commits
Select commit
Hold shift + click to select a range
137d6a7
chore(release): open dev at 2.46.0 before releasing 2.45.0 (#3812)
github-actions[bot] e963aa6
docs: plan platform validation follow-up
invalid-email-address eabe7ce
docs: plan axis1 bounded bug fixes [skip ci]
invalid-email-address 58fcb09
fix(claude): preserve reasoning and tool result envelopes
lidge-jun b2703f8
fix(grok): filter Codex control frames for strict Responses clients
lidge-jun 0d42efa
docs(plan): define axis five display and CLI delivery
invalid-email-address ef54e82
docs: describe BigModel and Raycast integration contracts
invalid-email-address 6a51f04
test(oauth): drain ACL flights before fixture teardown [skip ci]
invalid-email-address 336c621
fix(grok): honor SSE event order and empty resets
lidge-jun 9cde6e7
test(responses): cover established task delivery and compaction
lidge-jun cb8ac02
fix(diagnostics): distinguish inbound size measurement provenance [sk…
invalid-email-address c7f6ba7
feat(providers): carry static BigModel Responses preset from #3641
invalid-email-address 130be8d
feat(catalog): carry native display labels with normalization contrac…
invalid-email-address 1ee829d
feat(cli): carry provider list JSONL output [skip ci]
invalid-email-address e00d5c3
test(container): verify build startup and volume recreation [skip ci]
invalid-email-address 92c95fa
feat(gui): carry discovered model name editor with recoverable saves
invalid-email-address f215f79
fix(anthropic): attribute quota headers and honor measured reset dead…
invalid-email-address 12b174e
fix(claude): preserve signed and opaque replay block boundaries
lidge-jun 8f8790e
docs(devlog): record axis three protocol delivery plan
lidge-jun 9d775fa
fix(gui): preserve display name receipts across recovery failures
invalid-email-address d523990
fix(providers): repair static BigModel login and Responses effort
invalid-email-address 9336a27
test(providers): distinguish BigModel upstream and bridge modalities
invalid-email-address e352ede
fix(gui): balance name editor helper text on narrow screens
invalid-email-address c721b94
fix(claude): report terminal closure buffer overflow once
lidge-jun 513391e
test(container): isolate synthetic inference without internal network…
invalid-email-address 76e667f
test(responses): account for ordinary tool catalog guidance
lidge-jun 9b5b670
test(claude): correct replay and closure overflow oracles
lidge-jun 619f7a7
test(container): declare the synthetic loopback destination [skip ci]
invalid-email-address 4c1d9af
fix(gui): reconcile display name draft during snapshot render
invalid-email-address d6cf876
feat(integrations): carry Raycast client from #3733
invalid-email-address ea3d03a
fix(integrations): repair Raycast #3733 ownership and plan guidance
invalid-email-address 387d787
fix(raycast): honor live export admission and defer ensure refresh (#…
invalid-email-address 22f39ff
test(responses): exercise empty effort ladder through valid ingress
invalid-email-address 95edd0a
fix(export): preserve live CLI destination despite saved listener dri…
invalid-email-address d175335
test(container): verify first-start migrations before persistence bas…
invalid-email-address ab2bbc6
Merge pull request #3828 from lidge-jun/codex/axis2-bigmodel-stack-11fe
lidge-jun b65b9d8
Merge pull request #3829 from lidge-jun/codex/axis2-raycast-stack-11fe
lidge-jun 68d90aa
docs(claude): describe redacted reasoning replay
lidge-jun 2269e07
Merge pull request #3830 from lidge-jun/codex/axis3-protocol-foundation
lidge-jun 07f8d70
Merge pull request #3831 from lidge-jun/codex/axis3-grok-control-frames
lidge-jun 4349cf3
Merge pull request #3832 from lidge-jun/codex/axis3-protocol-combined
lidge-jun e873008
docs(devlog): record verified protocol delivery and remainders
lidge-jun 943e5a7
merge verified runtime landing into documentation closeout
lidge-jun e337374
Merge current dev into axis five native labels [skip ci]
invalid-email-address e862b86
Merge refreshed native label base into JSONL layer [skip ci]
invalid-email-address f51ec24
Merge refreshed axis five base for final integrated validation
invalid-email-address a5f9c34
Merge pull request #3834 from lidge-jun/codex/axis3-protocol-docs
lidge-jun 91fba4b
ci: gate source-build Docker lifecycle verification [skip ci]
invalid-email-address 15fa571
fix(container): retain routed catalog across managed recreation [skip…
invalid-email-address 6f2ad1e
ci: select explicit-file typecheck mode for TypeScript 7 [skip ci]
invalid-email-address a3c2eb5
fix(anthropic): expire retained quota measurements at known resets [s…
invalid-email-address 54fcc68
test(anthropic): keep probe fixtures inside live reset windows [skip ci]
invalid-email-address d3c70f9
fix(anthropic): normalize retained quota metadata and guard test tran…
invalid-email-address 872f0e5
fix(cli): explain which side of a version mismatch is older [skip ci]
invalid-email-address 2e8ef03
fix(responses): classify encrypted task recovery failures
invalid-email-address 6388ec7
Merge pull request #3818 from lidge-jun/codex/platform-lane4-oauth
lidge-jun da18da4
Merge pull request #3819 from lidge-jun/codex/platform-lane4-body
lidge-jun 5dee8cf
Merge pull request #3822 from lidge-jun/codex/platform-lane4-docker
lidge-jun 7fdb0e9
Merge pull request #3823 from lidge-jun/codex/platform-lane4-final
lidge-jun 1e16fe4
Merge axis five native display names (#3820)
lidge-jun be24986
Merge axis five provider JSONL output (#3821)
lidge-jun 44c69fd
Merge axis five discovered model name editor (#3824)
lidge-jun 2c8ec0b
docs(devlog): close axis five display and CLI delivery
invalid-email-address e894dcb
Close axis five delivery record (#3835)
lidge-jun 0ccc6bd
docs: keep delivery attribution without contact addresses [skip ci]
invalid-email-address bf85e67
Merge PR #3836: repair delivery-note privacy scan [skip ci]
lidge-jun b29bbb4
fix(clients): preserve exact Aside file identities [skip ci]
invalid-email-address 85fbdb5
Merge pull request #3825: verified axis1 bug fix [skip ci]
lidge-jun 860baaf
Merge pull request #3826: verified axis1 bug fix [skip ci]
lidge-jun 5a97db9
Merge pull request #3827: verified axis1 bug fix [skip ci]
lidge-jun 5fdf9bb
Merge pull request #3842: verified axis1 bug fix [skip ci]
lidge-jun be112e4
docs: close axis1 bug-fix delivery record [skip ci]
invalid-email-address 0d8b0cd
Merge PR #3847: close axis1 delivery record [skip ci]
lidge-jun 3970601
chore(release): prepare 2.46.0 stable promotion
invalid-email-address bba6322
Merge pull request #3851 from lidge-jun/codex/release-246-main
lidge-jun d32b8d6
fix(ci): scan markdown fences in linear time
luvs01 File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,24 @@ | ||
| # Axis 1: measured bug fixes and failure diagnostics | ||
|
|
||
| Completed: see [031_delivery_record.md](031_delivery_record.md) for merged commits, final CI, attribution and deferrals. | ||
|
|
||
| Archetype: satisfy existing contracts. Trigger: owner assigned axis 1 (#3809, #3464, #3661). Goal: deliver reviewable fixes through a manual PR chain and merge the verified scope. Non-goals: new account/retry policy, auth defaults, multipart recovery, releases, native stacks, sibling edits. Stop: merged feasible scope plus explicit unresolved dispositions. Escalation: defer a policy-dependent or unreproducible slice; reclaim a worker slice after two failed packets. Evidence: this unit plus ignored `.tmp/axis1/` and `.codexclaw` receipts. Resources: task-owned worktree/branches and GitHub repository access; Astra high leaves within host capacity; no caller-specified token or wall-clock budget. | ||
|
|
||
| Baseline: origin/dev 137d6a727; source PR #3809 at 4a1012359a522ddd6d7ff77203c9e5f3632d605c. Assigned 5cc8 checkout has pre-existing changes and remains untouched. Code lives in /tmp/ocx-axis1-20260907. | ||
|
|
||
| ## Cycle map | ||
| 1. wp0: docs-only scope, source audit and dependency roadmap; no runtime changes. | ||
| 2. wp1: bounded quota, version-guidance and recovery-diagnostic changes; independent source/security review and structural checks. Runtime verification deferred explicitly to wp2. | ||
| 3. wp2: publish ordinary PR chain, run final cumulative hosted CI, resolve findings, admin merge bottom-up and verify dev ancestry. Lower CI only if final CI fails. | ||
|
|
||
| ## Delivery contract | ||
| The owner explicitly requests a manual delivery chain even where units are independent: quota -> CLI guidance -> recovery reasons, with each layer carrying its own tests and credit. This order is an integration order, not a fabricated runtime dependency. No native registration. Lower commits carry [skip ci] to defer duplicate workflow runs; final head does not. Skipped lower runs are never called passing. No local tests/typecheck/build suites and no hook-triggered suites; task pushes use --no-verify. Hosted ci.yml on the final head must cover all changed runtime/tests; lower-level runs are diagnostic only after final failure. Merge with --admin under the explicit owner exception; preserve original commits/trailers with merge commits, retarget each child to dev, and check integration trees against final evidence. Concurrent dev changes require fresh combined verification. | ||
|
|
||
| ## Work boundaries | ||
| - Quota: src/providers/quota.ts, src/oauth/anthropic-routing.ts, src/oauth/health.ts, src/server/responses/core.ts, src/images/loop.ts, src/web-search/loop.ts, focused quota tests/layout, provider documentation. | ||
| - CLI: src/cli/version-skew.ts and relevant status/doctor consumers, tests/cli/cli-version-skew.test.ts, troubleshooting documentation. No service restart or repair behavior changes. | ||
| - Recovery: src/server/responses/agent-task-recovery.ts, agent-task-recovery-cache.ts, src/lib/bounded-body.ts and existing focused tests, Responses error projection if needed, recovery documentation. No expanded admission/retry. | ||
| - Main owns shared core.ts integration and test-layout files. Workers must not touch each other's paths or git index. | ||
|
|
||
| ## Verification and acceptance | ||
| No local suite commands are executed. Source mapping, git diff --check and documentation structural checks are local evidence only. Hosted Cross-platform CI at final head provides runtime/typecheck/privacy and affected platform proof; inspect jobs for skipped coverage. Build completion is provisional until that run and independent audit succeed. Original PR author(s) must be named in commit Co-authored-by trailers, sourced from original commits/API; report authors may also be acknowledged accurately. Source-of-truth sync uses relevant existing structure and docs-site pages. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,3 @@ | ||
| # wp0: scope roadmap | ||
|
|
||
| Read current source, prior issue disposition and PR #3809 before choosing changes. Independent Astra high reviewers map each bounded issue. Confirm existing launcher behavior and bounded recovery reasons are already in dev; plan only residual fixes. Record exact file boundaries and acceptance scenarios in 020. Success: all three slices have verifiable requirements, main-owned shared files, original author anchors and explicit policy exclusions. Local evidence is documentation and source inspection; no runtime claim. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,5 @@ | ||
| # wp0 audit disposition | ||
|
|
||
| Independent Astra high reviewer Hooke: VERDICT: GO-WITH-FIXES (blockers=1). Shared-flight failure propagation was the blocker. Accepted: 000/020 now assign cache and bounded-body ownership and define shared typed outcomes, success-only cache, caller-local cancellation and capacity semantics. Source scouts independently identified and confirmed these requirements. Fixed stale CLI test path. Windows runtime proof requires final workflow_dispatch, now explicit in 030. | ||
|
|
||
| No runtime code changed. Documentation source/ownership inspection and git diff --check are the wp0 evidence. Runtime verification remains wp2. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,5 @@ | ||
| # Roadmap lock | ||
|
|
||
| The second independent audit returned VERDICT: PASS with no remaining blockers. The three accepted slices are ready for scoped implementation. Original quota author: Éverton Toffanetto (everton-dgn), commit identity from 4f3779c04753 and 3ef0ade296c3. Issue reporters: garysassano (10464497) and Hu9956 (282876394). Reporter acknowledgement is separate from code authorship. | ||
|
|
||
| Preserve raw unequal version diagnostics. Detailed recovery outcomes must travel in the shared flight, not caller-local closures. Quota observations use immutable dispatch identity. Final verification is hosted workflow_dispatch for full Windows coverage; local suites remain prohibited. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,20 @@ | ||
| # wp1: implement bounded bug fixes | ||
|
|
||
| ## Quota | ||
| Carry only the source PR diff onto current dev, with original-author trailer. Header utilization fraction -> percentage; reset epoch -> timestamp. Creation: parser; serialization: account quota cache; deserialization: existing hydration; consumers: account ranking/health and management reading. Account-bound writer generation is captured with serving credentials, including retry/sidecar/continuation rebinds. Header observations merge model-specific windows and cannot indefinitely postpone probes. Existing 429 eligibility and retry count stay unchanged. Explicit reset evidence must not be truncated by an invented six-hour policy; any unresolved policy piece is deferred. | ||
| Scenarios: 200 and 429 on main/sidecar/continuation attribute only the serving account; generation invalidation discards writes; partial/malformed headers preserve known fields; no prior probe means model-window probe is still due; weekly rejected reset outlasts five-hour reset; absent evidence retains existing fallback. Verify with focused tests included in final hosted CI. | ||
|
|
||
| ## Version guidance | ||
| Compare CLI and running proxy using existing semantic-version utilities if present. CLI newer points to service restart; proxy newer points to upgrading/PATH resolution of CLI; equal/unknown retain suppression; incomparable differing builds use neutral wording. status and doctor share advice. Preserve whether requests are allowed and do not perform repair. Test both directions, prereleases, placeholders, malformed versions and consumer projection. | ||
|
|
||
| ## Recovery reasons | ||
| Keep existing public wrapper returning boolean and typed detailed result. Classify actual upstream HTTP refusal, transport error, timeout/caller cancellation, response-body/decode failures with a bounded vocabulary. Creation: request/collector; propagation: detailed recovery result; consumers: existing response reason projection/tests/docs. No raw upstream body/errors/tokens/ciphertext in output. Strict admission, one attempt, same credential and unchanged request mutation guarantees. Exercise each failure branch, cancellation races, malformed terminal output and successful recovery in final hosted CI. | ||
|
|
||
| Main owns src/server/responses/core.ts and layout metadata. Source/security review must check public boundaries and negative cases, not only implementation-mirroring tests. Source-only C evidence does not claim runtime correctness; wp2 is mandatory. | ||
|
|
||
| ## Source-map clarification from independent #3464 research | ||
| Use src/lib/strict-semver.ts unchanged. Raw unequal versions remain skewed; equal precedence with different build metadata and invalid/whitespace/v-prefixed values get neutral wording, not normalization or a guessed direction. Placeholder suppression is unchanged. src/cli/doctor.ts must not call suppressed placeholders a confirmed match. Focused files: tests/cli/cli-version-skew.test.ts, tests/cli/cli-status-json.test.ts, tests/codex-integration/doctor.test.ts. Documentation: reference/cli/lifecycle.md and directly affected Korean/Russian pages. Existing launcher landed via #3616 (4e2246c32); no service runtime changes. | ||
|
|
||
| ## Audit refinements | ||
| Quota: observe physical responses at the existing oauthDispatch boundary before any main/continuation replacement or return. Use immutable request binding to pair response with selected account; skip when final authorization headers do not prove that bearer or credentialGeneration has changed. An active-account switch alone does not invalidate another account's in-flight observation. Native Claude passthrough and single-account expansion remain outside #3809 carry. Preserve Retry-After precedence; only reject nonfinite/unrepresentable deadlines rather than invent an anomaly ceiling. Header-only rows are probe-due; hydrated Anthropic observations must be probe-due unless probe time is proven. Failed probes settle with the most recent committed observation for all joiners. | ||
| Recovery: worker owns agent-task-recovery-cache.ts and bounded-body.ts narrow decode discriminator alongside focused tests. Shared flight carries typed outcome, cache retains only success plaintext, cancelled waiters remain local. Recognized caller cancellation precedes owned timeout, which precedes decode/transport classification. Fatal UTF-8 discriminator must identify actual decoder exceptions without reclassifying fetch/body-reader TypeErrors. Rejected-response cancellation is nonblocking best effort. Keep current public wrappers and combo error projection. Update documented reason lists in structure/04_transports-and-sidecars.md and docs-site/reference/architecture.md. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,7 @@ | ||
| # wp1 source review | ||
|
|
||
| Three bounded patches implemented with regression coverage. Hooke independently passed the physical-response quota observer wiring; Tesla independently passed quota/recovery security and source review with zero blockers. Version comparator and status/doctor projections inspected by main. All source workers report no local suite/typecheck/build execution. | ||
|
|
||
| Quota source: #3809, Éverton Toffanetto; Co-authored-by included in f215f79b4. Version report: garysassano; Reported-by included in f91e3953a. Recovery report: Hu9956; Reported-by included in recovery commit. | ||
|
|
||
| Source-only checks: git diff --check and documentation fence/whitespace inspection. These do not prove runtime correctness. wp2 final cumulative hosted CI is still mandatory. Final CI dispatch includes Windows because ordinary PR workflow omits it. No release/deploy workflow will be dispatched. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,7 @@ | ||
| # wp2: hosted proof and manual-stack landing | ||
|
|
||
| Publish task-owned branches with --no-verify. Standard PR template, source links, truthful skipped-local/lower-CI disclosure and contributor trailers. Lower layers use [skip ci], final cumulative head runs existing Cross-platform CI; never modify shared workflow filters or fabricate checks. On final failure inspect failing jobs, fix owned defects, and only then use lower CI to localize ambiguity. Leave unrelated/unresolvable slices unmerged with evidence. | ||
|
|
||
| Before admin merge: source/security review findings resolved, final CI SHA/run pinned, current PR head and manual membership inspected. Record owner-authorized admin review/lower-CI exception. Merge bottom-up with original commits preserved; do not delete parent branches while children depend on them. Retarget child to dev after parent landing. Reconcile concurrent dev before claiming final integrated proof. Verify every merge SHA is ancestor of refreshed origin/dev. Close #3809 only after its accepted replacement scope lands; keep #3661 open for multipart/retry and #3464 open if broader original acceptance remains unresolved. No release/deploy. | ||
|
|
||
| Final full platform evidence uses workflow_dispatch ci.yml on the final cumulative branch, because ordinary PR CI excludes the Windows runtime job. Cancel only duplicate task-owned PR CI runs; skipped/cancelled runs are not passing evidence. |
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
When a PR body or commit message uses CRLF line endings, splitting only at
\nleaves\rat the end of each line, but this code trims only spaces and tabs; consequently, a closing fence such as```\rnever equalspendingFence. I checked.github/workflows/pr-hygiene.ymllines 156–174, which pass REST commit messages directly into this parser, so fenced carry language in a CRLF-formatted commit can be treated as a real declaration and spuriously block the PR for missing attribution. Normalize line endings or strip the terminal\rbefore comparing the delimiter.Useful? React with 👍 / 👎.