Skip to content

feat: portable Jev v0.3 with Command Code and Engraphis memory integrations - #1

Closed
Coding-Dev-Tools wants to merge 30 commits into
mainfrom
codex/jev-harness-integration
Closed

Coding-Dev-Tools wants to merge 30 commits into
mainfrom
codex/jev-harness-integration

Conversation

@Coding-Dev-Tools

@Coding-Dev-Tools Coding-Dev-Tools commented Sep 28, 2026 •

Copy link
Copy Markdown
Owner

Jev v0.3 gives Python, TypeScript, CLI and MCP users a portable advisory runtime with explicit setup, protected credentials and bounded requests. Command Code users can capture approved evidence before model ingestion, and memory systems can consume structured advice without handing Jev permission or memory authority.

  • Enforce pinned provider contracts, redacted wire identifiers, per-caller label restoration, one request deadline and conservative shared Python budget accounting. Missing or anomalous usage remains unknown and reserved. Fresh clients, CLI/MCP processes and hooks stay offline; an explicit library key can opt in before setup, while saved disabled settings always win.
  • Preserve unrelated settings through owned installation/restoration. Command Code ships an explicitly invoked skill, shared-project ownership checks, core capture and Windows-safe argv handling. Generated POSIX launchers retain their environment interpreter; unexpanded credential references count as absent keys.
  • Add bounded assess_memory_relation and assess_memory_relevance helpers plus a dependency-free Engraphis question bridge. Unknown judgments and confidence remain null. Host consent, scoped routing, deterministic verifiers and memory governance remain authoritative.
  • Read saved evidence through pinned roots and validated opened handles, preserving original bytes, hashes and complete source spans. Credential files and Windows stream aliases are denied globally; redirected roots cannot grant new access. Off/shadow/select policy and workload qualification govern omission; no automatic omission profile ships.
  • Offer optional pre-tool shell hooks for five harnesses. They request a native prompt or deny flagged commands and fail open on unavailable advice. Command Code covers shell and Windows PowerShell. Path-qualified executables, unknown flags and effectful options are assessed; hooks never approve commands.
  • Advertise compact MCP questions while retaining complete backend/native-map compatibility and meaningful-content validation. Keep a single Python version source, task-oriented migration/setup guides, shared memory examples and clean package verification receipts. CI covers Python 3.9–3.14 and Node 22/24 on Windows, macOS and Linux.

Validation on Windows / Python 3.12.10 with the official MCP SDK 2.2.0: 781 passed, 2 platform-related skips; TypeScript build and 87 tests passed; Ruff and Git whitespace checks passed. Clean wheel, source and npm installations run outside the checkout, including packaged memory/bridge/hook/capture/skill checks and legacy/current MCP handshakes, with zero provider requests. Four bounded internal reviewers returned; the parent integrated their actionable findings.

This PR includes the current checkout's changes, all 14 commits from review/merge-ready, and the applicable safeguards from the preserved older worktree. Its remaining edits are superseded by the current contracts and remain untouched in that worktree. The combined review record explains the reconciliation and evidence boundaries.

These local/package checks do not establish authenticated provider operation, named-client live usability, improved recall or token/time/billing savings. Live evaluation remains separate and budget-authorized. No merge or package publication is included. GitHub CI and review status must be read for this PR's latest head.

Current head: 837d909. Fresh cross-platform CI passed all 24 jobs on its first attempt: Python 3.9–3.14 and Node 22/24 on Windows, macOS and Linux, including clean distribution installation. The PR is mergeable and remains open. All 13 existing review conversations are resolved. Automatic Codex rereview was blocked by the account's code-review usage limit; its earlier-head completion is not a review of this commit. Four bounded internal reviewers checked the combined implementation, and their actionable findings were fixed and rechecked.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T04:42:17.315860Z f9ed66c New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 2c321a9fd5

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread jev_decision/evidence.py Outdated
Comment thread jev_decision/mcp.py Outdated
Comment thread ts/src/index.ts Outdated
@Coding-Dev-Tools Coding-Dev-Tools changed the title feat: v0.3.0 managed advisory Jev runtime, multi-harness integration, and budget ledger feat: complete v0.3 portable Jev integration and qualified evidence selection Sep 28, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a100ae788d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread jev_decision/mcp.py Outdated
Comment thread jev_decision/evaluation.py Outdated
Comment thread jev_decision/evidence.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d6c4530e09

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread jev_decision/cli.py Outdated
@Coding-Dev-Tools Coding-Dev-Tools changed the title feat: complete v0.3 portable Jev integration and qualified evidence selection feat: portable Jev v0.3, qualified evidence and Command Code recipes Sep 28, 2026
@Coding-Dev-Tools

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 6ece687877

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread jev_decision/setup.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 95048e52ec

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread jev_decision/client.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: adc337cc7b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread jev_decision/client.py
Comment thread jev_decision/mcp.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 09cbde8623

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread jev_decision/credentials.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 05dfb54743

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread jev_decision/client.py Outdated
Coding-Dev-Tools and others added 5 commits September 29, 2026 00:36
Path(sys.executable).resolve() turns a POSIX venv/pipx/uv interpreter
(bin/python -> base python symlink) into the base interpreter, which
cannot import jev_decision. Every generated MCP entry and skill command
on macOS/Linux therefore failed to start. Windows keeps its resolved
physical path for MSIX-virtualized runtimes.

Claude Code passes an unset ${NAME} through as literal text, so its
environment reference now uses the ${NAME:-} empty default like
Command Code.

The package check now launches the generated interpreter and imports
the package, so CI exercises the actual entry instead of sys.executable.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018LueFkPH1uD3FYT56QuZ5S
Claude Code (and possibly other clients) passes an unset ${NAME} env
reference through as literal text. The placeholder passed the printable-
ASCII key check, so every call failed authentication while leaving a
worst-case budget hold. Environment loading and presence status now treat
${NAME}, ${NAME:-}, ${env:NAME}, {env:NAME}, $NAME and %NAME% as unset;
storage and the TypeScript constructor reject them as credentials.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018LueFkPH1uD3FYT56QuZ5S
The credential/private-name filter ran over every component of the
absolute path, including the approved root's own ancestors. Any
workspace under a directory such as auth-service/, oauth_app/,
secrets-manager/ or token.bridge/ rejected every evidence read with
credential_or_private_file_denied. Names are now screened below the most
specific approved root that grants access (the root itself is explicit
operator consent). Paths outside textual roots and exact-path recovery
keep the previous whole-path screen. Denied names inside the root
(.env, .git, secrets/, *.pem, credentials.*) are still refused.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018LueFkPH1uD3FYT56QuZ5S
JevClient(api_key=...) and JevClient() with TYPESAFE_API_KEY/JEV_API_KEY
returned runtime_disabled until `jev setup` had run, so the README's
first Python example silently did nothing for a new user. Supplying a key
to a library client before any saved configuration now opts in with the
default daily budget and shared ledger. CLI and MCP pass their loaded
runtime explicitly and still stay offline until setup; a saved
configuration (including a disabled one) is always respected, and an
unexpanded placeholder never opts in.

CLI results for a fresh installation now include a hint pointing to
`jev setup` instead of a bare runtime_disabled.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018LueFkPH1uD3FYT56QuZ5S
Coding-Dev-Tools and others added 12 commits September 30, 2026 02:22
The version was repeated in pyproject, __init__, the HTTP User-Agent,
the MCP server version, the package check and CI artifact names.
jev_decision/_version.py is now the only Python source (setuptools reads
it dynamically); a test keeps the TypeScript package, lockfile and
User-Agent in step with it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018LueFkPH1uD3FYT56QuZ5S
MCP-only integration leaves the primary model to decide whether to call
jev_guard_command, which spends its tokens and depends on compliance.
The fast path for a System 1 check is the harness's own pre-tool hook.

`jev hook run HARNESS` reads one hook payload (Claude Code, Command Code,
Codex, Cursor, Gemini CLI) and can only add friction:
- ask-capable hooks (Claude Code, Cursor) get "ask", forcing the normal
  approval prompt for a flagged command;
- allow/deny-only hooks (Command Code, Codex, Gemini CLI) get "deny" with
  a reason, by default only in no-prompt sessions (bypass/yolo), so a
  person never loses the chance to approve; --when always blocks in every
  mode.
It never answers "allow". Simple read-only commands (ls, cat, git status,
... without shell syntax or private-file arguments) skip the request.
Every local failure (no setup, no key, budget, timeout, malformed input,
stale arguments) exits 0 with no decision, because exit 2 means block.
JEV_HOOK=off disables it; JEV_HOOK_THRESHOLD tunes it (default 0.8).
`jev hook config HARNESS` prints the exact settings fragment to merge.

The Python command guard now gives every Choice category and the Noul
explicit criteria (provider guidance; matches the TypeScript guard) and
reports category_probabilities.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018LueFkPH1uD3FYT56QuZ5S
Most MCP clients send every tool's input schema to the primary model on
each request. jev_decide advertised both the native map and legacy array
forms (6.5 KB), so the six tools cost about 10 KB (~2.5K tokens) of model
context per request. Discovery now advertises only the preferred array
form (2.7 KB; ~960 fewer tokens per request across the tool list), while
the server still validates calls against the complete schema, so native
ID-keyed maps and legacy prompt/options/scale inputs keep working.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018LueFkPH1uD3FYT56QuZ5S
Python 3.14 is the current stable release and Node 24 the active LTS, so
both join the matrices (TypeScript jobs no longer fail fast). The Windows
key dialog no longer names one specific harness.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018LueFkPH1uD3FYT56QuZ5S
A zero daily budget (the interactive setup default) disables provider
calls, and decide/guard/verify/doctor --live then reported a bare
runtime_disabled. Results now carry a corrective hint for both a fresh
installation and a zero budget.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018LueFkPH1uD3FYT56QuZ5S
The MCP server, JSON CLI and TypeScript client all accept a list of
plain {id, type, instructions, criteria} objects, but the Python library
only took typed dataclasses or a native ID-keyed map, so examples could
not be copied between interfaces. Python now accepts the same objects
(including the legacy prompt/options/scale spellings) with the same
validation.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018LueFkPH1uD3FYT56QuZ5S
The README opened with qualification caveats and several paragraphs of
policy before a user could install anything. It now leads with what Jev
is, a four-step quickstart (install, setup, connect a harness, optional
guard hook), a harness table, a copy-pasteable Python example, the MCP
tool list and the provider's usage guidance, and keeps the evidence and
qualification boundaries in their own sections.

docs/HOOKS.md documents the escalate-only shell guard for all five
harnesses; the Command Code guide gains a guard section and the 1.72.4
hook-runner evidence; integration, migration and specification docs
cover the interpreter, placeholder, library opt-in and name-screen
changes. Skills tell agents never to rephrase a command to evade the
guard.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018LueFkPH1uD3FYT56QuZ5S
Reading private data is itself a sensitive effect, so the read-only
shortcut no longer skips commands with absolute, drive-qualified or
parent-relative path arguments (cat /etc/shadow, head ../other/x).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018LueFkPH1uD3FYT56QuZ5S
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@Coding-Dev-Tools Coding-Dev-Tools changed the title feat: portable Jev v0.3, qualified evidence and Command Code recipes feat: portable Jev v0.3 with Command Code and Engraphis memory integrations Oct 1, 2026
@Coding-Dev-Tools

Copy link
Copy Markdown
Owner Author

Superseded by merged #2

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant