Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 14 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,20 @@ cut and that this clone does not carry.

## [Unreleased]

## [0.0.73] - 2026-09-19

nddev-builder guidance is refreshed against each harness's current native
extension model. Software artifacts are refreshed from verified vendor bytes:
Claude Code 2.1.278, Codex 0.155.1, Grok Build 1.0.38, Cursor
2026.09.18-9a7762b and Antigravity CLI 1.2.7. OpenCode remains 1.18.31 and
Pi 0.85.1. Public reusable workflows pin ci-workflows 0.1.20
(26749820fad5bde1f1726636af5b04d329ed2fe5). Previous artifact pins remain
available for rollback.

Providers gain the optional patch_instruction_region operation, which replaces
the managed instruction region in place while preserving unmanaged native
state. Setup content, postures and ownership are unchanged.

## [0.0.72] - 2026-09-16

nddev-builder guidance is refreshed against each harness's current native
Expand Down
8 changes: 4 additions & 4 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

8 changes: 4 additions & 4 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ members = [
]

[workspace.package]
version = "0.0.72"
version = "0.0.73"
edition = "2024"
rust-version = "1.89"
license = "AGPL-3.0-or-later"
Expand All @@ -23,9 +23,9 @@ sha2 = "0.11"
# `setup-core::archive`); an inflate loop is not, because its bugs are
# memory-safety bugs and it is not improved by being hand-written here.
miniz_oxide = "0.9"
setup-core = { path = "crates/setup-core", version = "0.0.72" }
provider-v3 = { path = "crates/provider-v3", version = "0.0.72" }
harness-runtime = { path = "crates/harness-runtime", version = "0.0.72" }
setup-core = { path = "crates/setup-core", version = "0.0.73" }
provider-v3 = { path = "crates/provider-v3", version = "0.0.73" }
harness-runtime = { path = "crates/harness-runtime", version = "0.0.73" }

[workspace.lints.rust]
unsafe_code = "forbid"
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -179,7 +179,7 @@ release is a convenience, not the authorised copy.

```bash
docker run --rm -v "$HOME/.config:/config" \
ghcr.io/nddev-opennetwork/codex-setup-system:0.0.72 \
ghcr.io/nddev-opennetwork/codex-setup-system:0.0.73 \
status --target /config/<dir> --json
```

Expand Down
1 change: 1 addition & 0 deletions crates/codex-setup-system/src/main.rs
Original file line number Diff line number Diff line change
Expand Up @@ -305,6 +305,7 @@ pub const CODEX: Harness = Harness {
// one on a disk it was never shipped to.
embedded_setups: include!(concat!(env!("OUT_DIR"), "/embedded_setups.rs")),
software: Some(software::SOFTWARE),
instruction_region: Some("AGENTS.md"),
};

fn main() -> ExitCode {
Expand Down
78 changes: 39 additions & 39 deletions crates/codex-setup-system/src/software.rs
Original file line number Diff line number Diff line change
Expand Up @@ -20,116 +20,116 @@ use harness_runtime::{Artifact, Delivery, Previous, Shape, Software};
pub(crate) const ARTIFACTS: &[Artifact] = &[
Artifact {
platform: "linux/arm64",
url: "https://registry.npmjs.org/@openai/codex/-/codex-0.154.0-linux-arm64.tgz",
bytes: 122_610_794,
sha256: "sha256:a2315b5f64bfeaff79b71e0d35505ba8c22cc1e96cab9dc950b614c804105b24",
url: "https://registry.npmjs.org/@openai/codex/-/codex-0.155.1-linux-arm64.tgz",
bytes: 135_126_766,
sha256: "sha256:7da3e7bea6db4751d1b837f046c9cec08918ac7f05427dd0b5bcf64ea6c85964",
shape: Shape::GzipTar,
member: "package/vendor/aarch64-unknown-linux-musl/bin/codex",
},
Artifact {
platform: "linux/x86_64",
url: "https://registry.npmjs.org/@openai/codex/-/codex-0.154.0-linux-x64.tgz",
bytes: 129_654_638,
sha256: "sha256:e27c83a49e6031685ee7f956c12aad5f16484d3a80181dd3fea930fb96b3832b",
url: "https://registry.npmjs.org/@openai/codex/-/codex-0.155.1-linux-x64.tgz",
bytes: 142_140_011,
sha256: "sha256:f110cccdd50b0be8130b84f45b3144ea775c233f1c8bd8226da6ee719d63d206",
shape: Shape::GzipTar,
member: "package/vendor/x86_64-unknown-linux-musl/bin/codex",
},
Artifact {
platform: "macos/arm64",
url: "https://registry.npmjs.org/@openai/codex/-/codex-0.154.0-darwin-arm64.tgz",
bytes: 116_501_639,
sha256: "sha256:2a98662d79316a59993c7233e3e25a1aa1d42da4b45904585d33a5a7da1cade1",
url: "https://registry.npmjs.org/@openai/codex/-/codex-0.155.1-darwin-arm64.tgz",
bytes: 127_465_533,
sha256: "sha256:93cc218b25b71c8da3edb50a013fbd22acf8f39058fb64083fefff638a084976",
shape: Shape::GzipTar,
member: "package/vendor/aarch64-apple-darwin/bin/codex",
},
Artifact {
platform: "macos/x86_64",
url: "https://registry.npmjs.org/@openai/codex/-/codex-0.154.0-darwin-x64.tgz",
bytes: 124_308_807,
sha256: "sha256:92c493533c53c433c4d94252251daba4f379ccba06a9964d260abb47a535dce1",
url: "https://registry.npmjs.org/@openai/codex/-/codex-0.155.1-darwin-x64.tgz",
bytes: 135_811_357,
sha256: "sha256:819db6dbb57a56cc21383a30331fc4115696e02f4c47ba7f686a285a2173fadd",
shape: Shape::GzipTar,
member: "package/vendor/x86_64-apple-darwin/bin/codex",
},
Artifact {
platform: "windows/arm64",
url: "https://registry.npmjs.org/@openai/codex/-/codex-0.154.0-win32-arm64.tgz",
bytes: 132_888_437,
sha256: "sha256:a072b19e67fd65f2827c925a9d3c89b1a55da70b8e24cc21b81c800a77cb3d53",
url: "https://registry.npmjs.org/@openai/codex/-/codex-0.155.1-win32-arm64.tgz",
bytes: 135_509_012,
sha256: "sha256:72525256ac769a23381236a374c71679927c988dd10b7a19d342c98193216b7f",
shape: Shape::GzipTar,
member: "package/vendor/aarch64-pc-windows-msvc/bin/codex.exe",
},
Artifact {
platform: "windows/x86_64",
url: "https://registry.npmjs.org/@openai/codex/-/codex-0.154.0-win32-x64.tgz",
bytes: 142_162_836,
sha256: "sha256:27eedae55e37ed1da4078b36a6ef9e4ffe8546a60fd6df5ee6408fdd16aff8ea",
url: "https://registry.npmjs.org/@openai/codex/-/codex-0.155.1-win32-x64.tgz",
bytes: 145_165_338,
sha256: "sha256:727fd5bfaeed16fe8fdeb57d1c0faa688f48edda4a0541323a103a3138925350",
shape: Shape::GzipTar,
member: "package/vendor/x86_64-pc-windows-msvc/bin/codex.exe",
},
];

/// The artifacts 0.153.4 was published as, kept so
/// The artifacts 0.154.0 was published as, kept so
/// `software_update` has a version to move from and `rollback` a tree to
/// return to. Measured from bytes when it was the current pin.
pub(crate) const PREVIOUS_ARTIFACTS: &[Artifact] = &[
Artifact {
platform: "linux/arm64",
url: "https://registry.npmjs.org/@openai/codex/-/codex-0.153.4-linux-arm64.tgz",
bytes: 121_707_000,
sha256: "sha256:439c0dd0d6923f607b4e5cd1e3079c12f0b86f6e5007f07e377d6ad25e2d7bb9",
url: "https://registry.npmjs.org/@openai/codex/-/codex-0.154.0-linux-arm64.tgz",
bytes: 122_610_794,
sha256: "sha256:a2315b5f64bfeaff79b71e0d35505ba8c22cc1e96cab9dc950b614c804105b24",
shape: Shape::GzipTar,
member: "package/vendor/aarch64-unknown-linux-musl/bin/codex",
},
Artifact {
platform: "linux/x86_64",
url: "https://registry.npmjs.org/@openai/codex/-/codex-0.153.4-linux-x64.tgz",
bytes: 129_272_137,
sha256: "sha256:54818cb9fce3360cc6e44cfc5a96952cd5c1243efb43cbe488e11dda84663e08",
url: "https://registry.npmjs.org/@openai/codex/-/codex-0.154.0-linux-x64.tgz",
bytes: 129_654_638,
sha256: "sha256:e27c83a49e6031685ee7f956c12aad5f16484d3a80181dd3fea930fb96b3832b",
shape: Shape::GzipTar,
member: "package/vendor/x86_64-unknown-linux-musl/bin/codex",
},
Artifact {
platform: "macos/arm64",
url: "https://registry.npmjs.org/@openai/codex/-/codex-0.153.4-darwin-arm64.tgz",
bytes: 115_672_312,
sha256: "sha256:535d301b49131abfda3264f959fb0defa40bbc306976d98ddbc15c424636c55c",
url: "https://registry.npmjs.org/@openai/codex/-/codex-0.154.0-darwin-arm64.tgz",
bytes: 116_501_639,
sha256: "sha256:2a98662d79316a59993c7233e3e25a1aa1d42da4b45904585d33a5a7da1cade1",
shape: Shape::GzipTar,
member: "package/vendor/aarch64-apple-darwin/bin/codex",
},
Artifact {
platform: "macos/x86_64",
url: "https://registry.npmjs.org/@openai/codex/-/codex-0.153.4-darwin-x64.tgz",
bytes: 123_544_033,
sha256: "sha256:5e468958503c60e940b1b1af3fe2064c16fd141f1607111caf99f2c0a0e80725",
url: "https://registry.npmjs.org/@openai/codex/-/codex-0.154.0-darwin-x64.tgz",
bytes: 124_308_807,
sha256: "sha256:92c493533c53c433c4d94252251daba4f379ccba06a9964d260abb47a535dce1",
shape: Shape::GzipTar,
member: "package/vendor/x86_64-apple-darwin/bin/codex",
},
Artifact {
platform: "windows/arm64",
url: "https://registry.npmjs.org/@openai/codex/-/codex-0.153.4-win32-arm64.tgz",
bytes: 132_173_674,
sha256: "sha256:6d0bf07e04810f0ed4ad2984f6c9f0547bb9e0e1bb1f8fe9ecce0de3376bbfef",
url: "https://registry.npmjs.org/@openai/codex/-/codex-0.154.0-win32-arm64.tgz",
bytes: 132_888_437,
sha256: "sha256:a072b19e67fd65f2827c925a9d3c89b1a55da70b8e24cc21b81c800a77cb3d53",
shape: Shape::GzipTar,
member: "package/vendor/aarch64-pc-windows-msvc/bin/codex.exe",
},
Artifact {
platform: "windows/x86_64",
url: "https://registry.npmjs.org/@openai/codex/-/codex-0.153.4-win32-x64.tgz",
bytes: 141_495_386,
sha256: "sha256:05f473573f38b3f4dc9484e6807a511a1bb0e128dfa50816dafc5f79e553cdca",
url: "https://registry.npmjs.org/@openai/codex/-/codex-0.154.0-win32-x64.tgz",
bytes: 142_162_836,
sha256: "sha256:27eedae55e37ed1da4078b36a6ef9e4ffe8546a60fd6df5ee6408fdd16aff8ea",
shape: Shape::GzipTar,
member: "package/vendor/x86_64-pc-windows-msvc/bin/codex.exe",
},
];

/// Codex's program, and where its bytes come from.
pub(crate) const SOFTWARE: Software = Software {
version: "0.154.0",
version: "0.155.1",
command: "codex",
delivery: Delivery::Artifacts(ARTIFACTS),
unsupported: &[],
previous: Some(Previous {
version: "0.153.4",
version: "0.154.0",
artifacts: PREVIOUS_ARTIFACTS,
}),
};
Expand Down
52 changes: 51 additions & 1 deletion crates/harness-runtime/src/facts.rs
Original file line number Diff line number Diff line change
Expand Up @@ -234,7 +234,20 @@ pub struct Harness {
/// [`Delivery::Manager`], which is a different statement -- the product is
/// installable, but not by fetching bytes whose digest was fixed in advance
/// -- and the refusal says which.
/// How the product's own software is installed, when this build can do it.
///
/// `None` means the software lifecycle is not offered at all. So does a
/// [`Delivery::Manager`], which is a different statement -- the product is
/// installable, but not by fetching bytes whose digest was fixed in advance
/// -- and the refusal says which.
pub software: Option<Software>,
/// Target-relative path of the user-global instruction attachment.
///
/// `None` when the product has no catalogued global instruction surface
/// (Antigravity). Present, this build implements `patch_instruction_region`
/// against that path. The bytes travel on `--instruction-section`; they are
/// not a setup payload.
pub instruction_region: Option<&'static str>,
}

/// A second set of ownings, for a target that is not the product's own home.
Expand Down Expand Up @@ -751,21 +764,44 @@ impl Harness {
/// manager this provider does not run.
#[must_use]
pub fn operations(&self) -> &'static [Operation] {
match (self.can_launch(), self.software) {
match (
self.can_launch(),
self.software,
self.instruction_region.is_some(),
) {
(
true,
Some(Software {
delivery: Delivery::Artifacts(_),
..
}),
true,
) => Operation::ALL,
(
true,
Some(Software {
delivery: Delivery::Artifacts(_),
..
}),
false,
) => Operation::ALL_WITHOUT_INSTRUCTION,
(
false,
Some(Software {
delivery: Delivery::Artifacts(_),
..
}),
true,
) => Operation::CORE_AND_SOFTWARE_AND_INSTRUCTION,
(
false,
Some(Software {
delivery: Delivery::Artifacts(_),
..
}),
false,
) => Operation::CORE_AND_SOFTWARE,
(_, _, true) => Operation::CORE_AND_INSTRUCTION,
_ => Operation::CORE,
}
}
Expand Down Expand Up @@ -968,6 +1004,7 @@ mod tests {
max_files: 4096,
max_bytes: 1024,
kit_identity: r#"{"aggregate_digest":"sha256:aa","protocol_version":3}"#,
instruction_region: None,
};

#[test]
Expand Down Expand Up @@ -1009,6 +1046,7 @@ mod tests {
Operation::SoftwareInstall,
Operation::SoftwareUpdate,
Operation::SoftwareRemove,
Operation::PatchInstructionRegion,
] {
assert!(
!info.declares(optional),
Expand All @@ -1017,6 +1055,18 @@ mod tests {
}
}

#[test]
fn an_instruction_surface_without_software_still_declares_the_patch() {
let named = Harness {
instruction_region: Some("AGENTS.md"),
..SAMPLE
};
let info = named.provider_info().unwrap();
assert!(info.declares(Operation::PatchInstructionRegion));
assert!(!info.declares(Operation::SoftwareInstall));
assert!(!info.declares(Operation::Launch));
}

#[test]
fn the_build_digest_is_reproducible_and_binds_the_kit() {
let once = SAMPLE.build_digest().unwrap();
Expand Down
5 changes: 5 additions & 0 deletions crates/harness-runtime/src/human.rs
Original file line number Diff line number Diff line change
Expand Up @@ -1154,6 +1154,8 @@ fn mutate(
// The human surface removes whole and carries no bundle, so no path
// has a second sentence.
end_state: Vec::new(),
instruction_path: None,
instruction_text: None,
effects: effect_lines(harness, &effect, applied.setup_id.as_deref()),
})?;
let plan_digest = artifact.digest()?;
Expand Down Expand Up @@ -1251,6 +1253,9 @@ fn effect_lines(harness: &Harness, effect: &Effect<'_>, setup_id: Option<&str>)
));
lines
}
Effect::PatchInstruction { path, .. } => {
vec![capture, format!("patch instruction region at {path}")]
}
}
}

Expand Down
Loading
Loading