Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
41 commits
Select commit Hold shift + click to select a range
d2c691f
Fix ACP turn deadlines so extensions stay authoritative and timeouts …
ajhcs Sep 10, 2026
eed128c
Isolate ACP turn AbortSignals so concurrent sessions cannot steal can…
ajhcs Sep 10, 2026
b485eeb
Keep complete engineering assignments with external owners
ajhcs Sep 10, 2026
b126d0d
Add reusable provider ownership and bounded producer revisions.
ajhcs Sep 10, 2026
1183f82
Correct owned-revision API identity, preference resolution, and super…
ajhcs Sep 10, 2026
9f2591c
Preserve owned-revision constraints, proven producer evidence, and co…
ajhcs Sep 10, 2026
c56057e
Add 3.4.3 onboarding and community contribution package.
ajhcs Sep 10, 2026
3131f9a
Add bounded run-result evidence projection and offline comparison too…
ajhcs Sep 10, 2026
6923918
Bound owned-revision corrections to a fixed three-round chain.
ajhcs Sep 10, 2026
2b6bdc0
Correct first-outcome utility and public onboarding guidance.
ajhcs Sep 10, 2026
4e2bafd
Correct run-result evidence outcome, acceptance, and bounded reports.
ajhcs Sep 10, 2026
3d90384
Correct offline comparison accounting and case materialization.
ajhcs Sep 10, 2026
04a2dc2
Integrate bounded ownership, result evidence, and the 3.4.3 adoption …
ajhcs Sep 10, 2026
c50550e
Verify explicit correction conflicts and clarify contributor acceptance.
ajhcs Sep 10, 2026
e764bbd
Fail closed missing revision reservation and require explicit clean p…
ajhcs Sep 11, 2026
9fe2f33
Direct owned-revision work to the assigned correction workspace.
ajhcs Sep 11, 2026
5d27886
Prepare unreleased 3.4.3 candidate metadata and qualification documen…
ajhcs Sep 11, 2026
194afab
Correct 3.4.3 candidate onboarding paths and marketplace identity.
ajhcs Sep 11, 2026
00aa001
Correct 3.4.3 version-gate assertions and first-outcome empty-input w…
ajhcs Sep 11, 2026
bfd60df
Restore stable marketplace identity for the public 3.4.3 candidate.
ajhcs Sep 11, 2026
2b4fda9
Fix Grok onboarding docs to the official Build overview login path.
ajhcs Sep 11, 2026
ed625fe
Correct 3.4.3 release docs for Astra host-gate and marketplace-wrappe…
ajhcs Sep 11, 2026
0c7600c
Add offline host-usage importer for allowlisted trial sessions.
ajhcs Sep 11, 2026
346cf7f
Correct offline host-usage importer Astra findings.
ajhcs Sep 11, 2026
ca6f65e
Correct importer AgentPath, CLI settings, and acceptance accounting.
ajhcs Sep 11, 2026
5f3017e
Give CI full Git history for pinned qualification fixtures.
ajhcs Sep 11, 2026
5a578a8
Add frozen 3.4.3 qualification cases and a non-provider materializer.
ajhcs Sep 11, 2026
ed101be
Bind qualification cases to historical sources and require four arms.
ajhcs Sep 11, 2026
ba22768
Correct qualification cohort accounting before measured trials.
ajhcs Sep 11, 2026
c5c5652
Reconcile host-usage by_model totals to primary trial usage.
ajhcs Sep 11, 2026
3ab2cff
Preserve incomplete Astra model numbers and rotate scheduled approaches.
ajhcs Sep 11, 2026
28e792e
Point 3.4.3 release-note process links at the public docs/release.md …
ajhcs Sep 11, 2026
b6a994c
Accept proven shared root session_id for helper usage records.
ajhcs Sep 11, 2026
3572ef1
Accept normal CLI string session_meta.source for shared-session helpers.
ajhcs Sep 11, 2026
2fec429
Fix intermittent ACP close cleanup so hostile descendants cannot hang…
ajhcs Sep 11, 2026
99d73d2
Fix ACP turn settlement so close retains and kills the client tree.
ajhcs Sep 11, 2026
b19c746
Assert ACP client retention before any await after turn.result.
ajhcs Sep 11, 2026
2be13b6
docs: publish 3.4.3 with explicit qualification limits
ajhcs Sep 11, 2026
b7f97a2
test: align published installation checks with 3.4.3
ajhcs Sep 11, 2026
179e17f
test: reproduce close racing ACP client retention
ajhcs Sep 11, 2026
c0aada7
Fix ACP finalization so close cannot retain a live client.
ajhcs Sep 11, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .agents/plugins/marketplace.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@
"plugins": [
{
"name": "codex-co-engineer",
"version": "3.4.2",
"version": "3.4.3",
"description": "Give Codex a team of external co-engineers without giving up control. Delegating to Co-Engineer starts one bounded run. The honest shape is up to eight isolated external co-engineers, one bounded run, one coordinated wait, one verified decision.",
"keywords": [
"codex",
Expand Down
21 changes: 21 additions & 0 deletions .codex/release-gate.toml
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,27 @@ failure_class = "product_test_failed"
timeout_seconds = 300
quiet_seconds = 30

[[stages]]
name = "comparison-fixtures"
kind = "unit_tests"
command = ["node", "--no-warnings", "--test", "scripts/compare-coengineer-runs.test.mjs"]
failure_class = "product_test_failed"
timeout_seconds = 30

[[stages]]
name = "trial-usage-unit"
kind = "unit_tests"
command = ["node", "--no-warnings", "--test", "scripts/collect-coengineer-trial-usage.test.mjs"]
failure_class = "product_test_failed"
timeout_seconds = 30

[[stages]]
name = "qualification-prep-unit"
kind = "unit_tests"
command = ["node", "--no-warnings", "--test", "scripts/prepare-coengineer-qualification.test.mjs"]
failure_class = "product_test_failed"
timeout_seconds = 30

[[stages]]
name = "cursor-compatibility-unit"
kind = "unit_tests"
Expand Down
81 changes: 81 additions & 0 deletions .github/ISSUE_TEMPLATE/bug.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,81 @@
name: Bug report
description: Something did not work as expected.
title: "[Bug]: "
labels: ["bug"]
body:
- type: markdown
attributes:
value: |
Thanks for reporting a problem. A short description of what you tried and what happened is enough to start. You do not need a technical diagnosis.

Security issues belong on the private [Security](https://github.com/ajhcs/Codex-Co-Engineer/security/advisories/new) route, not in a public issue. See [SECURITY.md](https://github.com/ajhcs/Codex-Co-Engineer/blob/main/SECURITY.md).
- type: textarea
id: attempt
attributes:
label: What did you try?
description: What you asked for or which steps you followed.
placeholder: Asked Codex to use Grok Co-Engineer to review the latest change…
validations:
required: true
- type: textarea
id: actual
attributes:
label: What happened?
description: The outcome you saw, including any error text you are comfortable sharing.
placeholder: The run stayed preparing, or Codex reported a missing local boundary…
validations:
required: true
- type: input
id: version
attributes:
label: Co-Engineer version (optional)
description: Public package or release tag if you know it (for example 3.4.2).
placeholder: 3.4.2
validations:
required: false
- type: dropdown
id: host
attributes:
label: Host (optional)
options:
- Codex CLI
- Codex Desktop or another Codex host
- Unsure / other
default: 2
validations:
required: false
- type: dropdown
id: provider
attributes:
label: Provider involved (optional)
options:
- None / not sure
- Grok
- Cursor Local
- Cursor Cloud
- Muse (DSH)
- More than one
default: 0
validations:
required: false
- type: textarea
id: expected
attributes:
label: What did you expect instead? (optional)
validations:
required: false
- type: textarea
id: repro
attributes:
label: Reproduction notes (optional)
description: Smallest steps that reproduce the problem. Synthetic or redacted data only.
validations:
required: false
- type: textarea
id: evidence
attributes:
label: Redacted evidence (optional)
description: Paste only sanitized excerpts. Do not include credentials, private paths, full prompts, or private repository contents.
placeholder: Sanitized status excerpt or failure category…
validations:
required: false
8 changes: 8 additions & 0 deletions .github/ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
blank_issues_enabled: false
contact_links:
- name: Security vulnerability
url: https://github.com/ajhcs/Codex-Co-Engineer/security/advisories/new
about: Private vulnerability reports only. Do not open a public issue for undisclosed security problems. See SECURITY.md.
- name: Support overview
url: https://github.com/ajhcs/Codex-Co-Engineer/blob/main/SUPPORT.md
about: Where to ask questions, report problems, and what helps maintainers.
33 changes: 33 additions & 0 deletions .github/ISSUE_TEMPLATE/feature.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
name: Feature or improvement
description: Suggest an outcome or improvement without designing the implementation.
title: "[Feature]: "
labels: ["enhancement"]
body:
- type: markdown
attributes:
value: |
Describe the outcome you want. You do not need to design the implementation.

Questions and usage help belong in a [Question](https://github.com/ajhcs/Codex-Co-Engineer/issues/new?template=question.yml) issue. Security reports stay on the private [Security](https://github.com/ajhcs/Codex-Co-Engineer/security/advisories/new) route.
- type: textarea
id: outcome
attributes:
label: Desired outcome
description: What should become possible or easier?
placeholder: After a failed setup on a supported host, the error should name the missing requirement and the next check to run…
validations:
required: true
- type: textarea
id: current
attributes:
label: Current behavior or workaround (optional)
description: What happens today, or how you work around it.
validations:
required: false
- type: textarea
id: example
attributes:
label: Example (optional)
description: A short scenario, sample prompt, or before/after sketch. Avoid implementation prescriptions unless you are offering a concrete patch later.
validations:
required: false
25 changes: 25 additions & 0 deletions .github/ISSUE_TEMPLATE/question.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
name: Question or workflow
description: Ask for help or share a useful workflow. Discussions is not enabled on this repository.
title: "[Question]: "
labels: ["question"]
body:
- type: markdown
attributes:
value: |
GitHub Discussions is not enabled for this repository, so questions use Issues.

For bugs, use the Bug report form. For vulnerabilities, use the private [Security](https://github.com/ajhcs/Codex-Co-Engineer/security/advisories/new) route.
- type: textarea
id: question
attributes:
label: Your question or workflow
description: What you are trying to do, where you are stuck, or a small workflow others can try.
validations:
required: true
- type: textarea
id: context
attributes:
label: Useful context (optional)
description: Version, host, chosen provider, or a short redacted excerpt. No credentials or private paths.
validations:
required: false
24 changes: 24 additions & 0 deletions .github/pull_request_template.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
## Problem

What concrete problem or gap does this change address?

## Result

What behavior or documentation changes for the user or maintainer?

## Checks

List the focused commands you ran (fixture tests preferred; no paid-provider runs required for ordinary docs or fixture work).

```text
# example
node --no-warnings --test plugins/codex-co-engineer/test/r1-final-decision-card.test.mjs
```

## Limits

Known gaps, follow-ups, or intentionally out-of-scope items.

## Agent assistance (optional)

If an agent drafted or edited substantial parts of this change, say so briefly and note what you personally reviewed or verified. You own the complete diff and the claims in this pull request.
5 changes: 5 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,8 @@ jobs:
NPM_CONFIG_CACHE: /tmp/codex-acpx-release-npm-cache
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- uses: actions/setup-node@v4
with:
node-version: 24
Expand All @@ -24,6 +26,9 @@ jobs:
- run: umask 077 && node scripts/validate-release.mjs
- run: umask 077 && npm --prefix tools/acpx-vendor ci --ignore-scripts --no-audit --no-fund
- run: umask 077 && npm --prefix plugins/codex-co-engineer test
- run: umask 077 && node --no-warnings --test scripts/compare-coengineer-runs.test.mjs
- run: umask 077 && node --no-warnings --test scripts/collect-coengineer-trial-usage.test.mjs
- run: umask 077 && node --no-warnings --test scripts/prepare-coengineer-qualification.test.mjs
- run: umask 077 && npm --prefix plugins/cursor-cloud-control test
- run: umask 077 && npm --prefix tools/acpx-vendor run test:publish-provenance
- run: umask 077 && node scripts/inspector-preflight.mjs
Expand Down
56 changes: 56 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,62 @@

## [Unreleased]

## [3.4.3] - 2026-09-11

Published at the maintainer's direction with partial qualification. Independent
code review, real owned corrections, Astra acceptance, the automated release
gate, and GitHub CI passed. Measured benefit, clean-agent onboarding, refreshed
native-host acceptance, and Desktop wait/recovery evidence remain incomplete.
No savings claim is made. See [PR43](https://github.com/ajhcs/Codex-Co-Engineer/pull/43)
and the [release notes](docs/releases/v3.4.3.md) for retained failures and limits;
existing qualification requirements remain unchanged.

### Added

- Explicit provider preferences and bounded candidate revisions through the
existing Co-Engineer tool surface, preserving external ownership and prior
evidence instead of rebuilding correction assignments in the lead agent.

- Ordinary run results and on-demand usage evidence through the existing ledger
and decision-card helpers; unknown usage stays unknown and completion never
implies Codex acceptance.
- A one-provider first-outcome example, issue forms, PR template, support links,
contributor tasks, roadmap, and a documented real development correction loop.
- Reproducible frozen comparison cases and an offline analyzer covering native
helpers, corrections, failed attempts, exact source identities, and missing
acceptance coverage. Synthetic fixtures do not establish savings.
- OpenAI showcase preparation with the current local-MCP submission limitation.

### Changed

- Delegate complete engineering assignments, checks and corrections to external
owners; return compact evidence for Astra and other autonomous lead agents.
Preserve final review, host model defaults, and repository authorization.

- Cap owned correction chains at three rounds, reserve one admitted child per
producer across server processes, and retain lineage through restart.

### Fixed

- Settle ACP results after persistent-client finalization so immediate runtime
close can clean up agents and descendants; retain a deterministic ordering
regression and the independently reviewed correction history.

- Point public Grok install docs at the official Grok Build overview and
document `grok login` / `grok login --device-auth` subscription login for
first-outcome work (no API key).
- Restore the distinct local marketplace-wrapper path for older open projects
that share the public marketplace identity, keep the shipped marketplace
manifest stable, and require `plugin/list` persistence checks after restart.
- Align the 3.4.3 evaluation gate so Astra own-output is measured versus
published 3.4.2 (helpers do not satisfy) and paid work does not dispatch
beyond the $25 cap.
- Make supported deadline extensions govern the active ACP turn and preserve
timeout/cancellation truth after partial provider output.
- Preserve empty capability restrictions and complete Unicode review feedback;
reject unproven producers and competing feedback instead of silently dropping it.
- Direct terminal uncertainty to inspection and keep active work on bounded waits.

## [3.4.2] - 2026-09-08

### Fixed
Expand Down
28 changes: 24 additions & 4 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,17 @@
# Contributing

Thanks for helping improve Codex-Co-Engineer. The project is intentionally a
thin trusted supervisor for Grok, Cursor Local, Cursor Cloud, and DeepSeek
Harness (DSH). Keep provider capabilities intact and avoid rebuilding a
second sandbox, target-attestation layer, daemon, or policy engine.
Thanks for helping improve Codex-Co-Engineer. Documentation fixes, examples,
compatibility reports, reproductions, tests, and code are all welcome. You do
not need to start with a large provider change.

**Good first contributions** live in [docs/contributor-tasks.md](docs/contributor-tasks.md).
Report problems and ask questions through [SUPPORT.md](SUPPORT.md). The
[roadmap](docs/roadmap.md) separates the 3.4.3 adoption package from later work.

The project is intentionally a thin trusted supervisor for Grok, Cursor Local,
Cursor Cloud, and DeepSeek Harness (DSH). Keep provider capabilities intact and
avoid rebuilding a second sandbox, target-attestation layer, daemon, or policy
engine.

## Before opening a pull request

Expand All @@ -17,6 +25,14 @@ not a sandbox or capability restriction. `npm run setup:check` validates the
CLI/worktree dependencies, while the release/live acceptance validates this
host boundary.

Focused fixture check (no paid provider required):

```bash
node --no-warnings --test plugins/codex-co-engineer/test/r1-final-decision-card.test.mjs
```

Broader local verification before a larger change:

```bash
node --version
npm --prefix plugins/codex-co-engineer test
Expand Down Expand Up @@ -94,3 +110,7 @@ release inventory check, MCP Inspector preflight, ACPX provenance/reproducible
checks, and package-inventory review. Update `CHANGELOG.md` for
user-visible behavior. Codex reviews and merges the release PR only after
those checks and any explicit live acceptance are complete.

Agent-assisted drafts are welcome when the submitter owns the complete diff,
reviews it, and states briefly what was checked. Prefer the pull request
template's short disclosure over lengthy attestations.
Loading
Loading