Skip to content

feat(prompt-input): issue the input profile for recorded Codex 0.157.1 - #69

Merged
Juliusolsson05 merged 5 commits into
integration/batch-2026-09-27-cxh-vfrom
fix/prompt-input-profile-0157
Sep 27, 2026
Merged

Juliusolsson05 merged 5 commits into
integration/batch-2026-09-27-cxh-vfrom
fix/prompt-input-profile-0157

Conversation

@Juliusolsson05

@Juliusolsson05 Juliusolsson05 commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

Fixes #63. Refs agent-code#234 (Codex 0.157.1 acceptance), #65, #66, #68.

The problem

prepareCodex01491PromptInputProfile issued a profile only for exactly 0.149.1. At 0.157.1, the version Agent Code runs, it returned unsupported-cli. PromptInputEvidence then produced nothing, and fresh-rollout ownership depended on the proxy identity path alone.

Change

  • Profile. A table of exact recorded versions (0.149.1, 0.157.1), never a range. Unrecorded versions still get unsupported-cli. The export name keeps 01491 for API stability; the comment says why.
  • Evidence for 0.157.1, each item recorded the same way as the 0.149.1 evidence:
    • codex-01571-recorded.json: the full corpus (16 cases, plus the 2 popup-Enter cases on 0.157.1), inline, comparable row for row with 0.149.1.
    • codex-01571-fullscreen-recorded.json: the same corpus in fullscreen, 0.157's default and how Agent Code launches Codex.
    • codex-01571-config-read-recorded.json: the config/read projection. Its effectiveInputProjection is identical to 0.149.1's; the older fixture's extra layerShapeEvidence has no 0.157.1 counterpart.
    • codex-01571-config-source.json: the per-tag audit of the config precedence code. All nine claims re-verified at rust-v0.157.1 coordinates.
  • Tests. SubmittedPromptInput.recorded.test.ts now runs the same contract once per corpus. Only provenance is per-version.

What 0.157.1 changed, from the recordings

Provider semantics. Every issued-profile case agrees with 0.149.1. The only difference is outside the profile: a Vim-default composer now opens in Insert (vim-normal-default submits iabc), and the profile forces Vim off anyway.

Four real surfaces the 0.149.1 composer classifier misread, each now pinned by a recorded frame:

  1. The trust dialog's hint row (enter continue · esc quit|back) has the idle-footer shape, so the dialog read as a composer drafting "1. Trust and continue". It is now a bottom-row structural modal check, byte-identical to fix(trust): detect the Codex 0.156+ Folder access dialog and send its keystrokes #67's.
  2. The skill/mention popup now paints ABOVE the composer, with the hint enter insert · esc close (skill_popup.rs). The old footer string no longer exists. Read as an idle composer, Enter (which inserts a completion) would have produced evidence for a prompt Codex never sent. It is now completion-popup.
  3. Fullscreen paints a two-row footer: the status line, then ? for shortcuts or tab to queue message. Only those exact rows are accepted, and any other footer.rs variant stays unknown, which declines.
  4. Every popup paints above the composer (review a and b): slash command, file, unified mention and skill. The slash and file popups have no hint row. With one open, the pane read as a composer holding the draft, and Enter, which selects the popup item, yielded evidence for a prompt Codex never sent.
    • The fix is fail-closed on the draft: a leading / or an @/$ token (what opens these popups upstream) never yields evidence. The unified-mention hint is also recognised.
    • Two new recorded cases, slash-popup-enter-selects-command and file-popup-enter-inserts-mention, show Codex submitted nothing.
    • Upstream's slash_popup_footer_wide snapshot (/m over /memories, reviewer b's reproduction) is a unit test.

Recorder changes, all gated to 0.156+ and explained inline:

Verification

  • Fail-first. Against origin/main both 0.157.1 suites fail at profile issuance. With only the classifier reverted, 6 recorded tests fail.
  • Tests. Recorded suites 144 passing. 2 skips are the popup cases in the 0.149.1 suite, which has no such recordings. tsc --noEmit clean.
  • Mutation. Removing the draft rule fails the recorded slash-popup cases in both corpora and the upstream-snapshot test.
  • Privacy. Every committed projection was scanned for account, path and credential strings; none found. Workspace paths are <private-path>.

Not verified / residuals

Plan: docs/plans/2026-09-27-prompt-input-profile-0157.md.

🤖 Generated with Claude Code

Juliusolsson05 and others added 2 commits September 26, 2026 23:18
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The profile refused every CLI but 0.149.1, so at 0.157.1 (the version
Agent Code runs) prompt-input evidence was gone and fresh-rollout
ownership rested on the proxy path alone. It now covers a table of
exact recorded versions: 0.149.1 and 0.157.1, never a range.

Evidence for 0.157.1:
- the full 16-case corpus re-recorded inline and fullscreen;
- the config/read projection (identical to 0.149.1's);
- a per-tag audit of the config precedence code.
The recorded contract test runs once per corpus.

Real 0.157 surfaces the 0.149.1 composer classifier misread, all pinned
by the recordings:
- the trust hint row has the idle-footer shape;
- the skill popup now paints above the composer;
- fullscreen uses a two-row footer.

Recorder fixes for 0.157, all version-gated, explained inline: daemon,
model migration, skill frontmatter, 1+Enter trust, title side requests,
prompt-carrying request match, painted-row windows, real resize repaint,
popup hint wait.

Fixes #63

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Juliusolsson05 and others added 3 commits September 27, 2026 01:47
Review a and b of #69: Codex 0.157.1 paints every popup above the
composer, and the slash-command and file popups carry no hint row. With
one open, the pane read as a composer holding the draft, so Enter (which
selects the popup item) produced evidence for a prompt Codex never sent.
Reviewer b reproduced it with upstream's slash_popup_footer_wide
snapshot: /m over /memories gave false evidence of /m.

Codex opens these popups from the draft itself (a leading /, an @ or $
token), so such a draft now never yields prompt evidence. That is
fail-closed: a real prompt starting with / is a safe miss. The unified
mention hint row is also recognised.

Evidence:
- two new recorded 0.156+ cases (slash-popup Enter dispatches /status,
  file-popup Enter inserts README.md; neither submitted), with both
  0.157.1 corpora re-recorded;
- upstream's snapshot as a unit test;
- removing the rule fails both.
The fullscreen '? for shortcuts' row is now asserted too.

Refs #63

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The popup rule required a character after @ or $, but the popup opens on
the bare sigil, so a draft ending in '@' or '$' could still yield prompt
evidence. Any token starting with the sigil now declines. Unit cases
cover '@', 'look at @', '$', 'use $' and '/'; the old pattern fails the
four sigil cases.

Refs #63

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…iew c)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Juliusolsson05

Copy link
Copy Markdown
Owner Author

Disposition for review c (head a425c84)

  • F1 (HIGH), fixed in 5480cc0: draftMayOpenPopup now matches any boundary-preceded @/$, including a bare sigil. Tests cover @, look at @, $, use $ and /. A comment in the surface explains why the draft rule, not the hint rows, is the primary guard: a popup can be open with zero rendered rows.
  • F2 (LOW), fixed in a425c84: a new frame has a painted enter insert · esc close hint over a sigil-free draft. Deleting the hint-row layer now fails.
  • F3 (LOW), fixed in a425c84:
    • RECORDED_PROMPT_INPUT_VERSIONS is pinned to exactly {0.149.1, 0.157.1}, and each version's corpus must exist.
    • The recorded suite asserts profile.upstreamTag.
    • An unrecorded second footer row must classify unknown.
    • All three mutations (widening the table, corrupting a tag, widening FULLSCREEN_SHORTCUTS_HINT) are now killed.
  • F4: a pre-existing RolloutOwnership flake, tracked in bug(testing): RolloutOwnership.recorded 'modern-0149-large-bootstrap-first' exceeds 5 s under load #60. No change here.

@Juliusolsson05

Copy link
Copy Markdown
Owner Author

Disposition (W1). Three reviews (codex a, codex b, pi c), then a verification pass by the same three at the final head a425c84: all three are MERGE-READY.

Finding Source Disposition
0.157 popups painted above the composer were read as a submittable composer, so Enter gave false prompt evidence a critical, b critical Fixed (aac7510). No evidence from a draft a popup may own, plus 2 recorded popup-Enter cases and the upstream slash_popup_footer_wide snapshot.
A bare @/$ sigil (empty query) escaped the draft rule c F1 HIGH Fixed (5480cc0).
The hint-row layer, version table, upstreamTag and second fullscreen footer row were unpinned c F2/F3 LOW Fixed (a425c84). All four mutations are killed.
RolloutOwnership flake c F4 Pre-existing, #60.

merge-gate.sh --dry: GATE PASS (0 behind main, checks green, reviews OK). READY for the manager's batch.

@Juliusolsson05
Juliusolsson05 changed the base branch from main to integration/batch-2026-09-27-cxh-v September 27, 2026 23:40
@Juliusolsson05
Juliusolsson05 merged commit 135fa37 into integration/batch-2026-09-27-cxh-v Sep 27, 2026
6 checks passed
Juliusolsson05 added a commit that referenced this pull request Sep 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working provider:codex Affects Codex integration upstream-update Upstream CLI moved; needs a compatibility pass

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug(prompt-input): the prompt-input profile refuses every Codex after 0.149.1 (unsupported-cli at 0.157.1)

1 participant