Release DevSquad0.11: durable local core and verified runtime repairs - #1
Conversation
Shell suite passes. Core has one expected stale migration-version assertion while migration 002 and supervisor tests are unfinished.
…blic regressions (2026-10-02 13:18)
…g scopes (2026-10-02 13:27)
…rt proofs (2026-10-02 13:41)
…get-fenced trial chain (2026-10-02 14:07)
… affected gate (2026-10-02 14:10)
…worker deadline enforcement (2026-10-02 14:22)
…nd checkpoint R5 repair acceptance (2026-10-02 14:31)
… 16 (2026-10-02 14:37)
… trials gates (2026-10-02 14:53)
…leanup; checkpoint independent finish-recovery finding (2026-10-02 15:19)
… expiry edge findings (2026-10-02 15:55)
…nd round trips (2026-10-02 16:24)
… acceptance boundary (2026-10-02 16:26)
…ship rejection; retain Council upgrade proof (2026-10-02 16:39)
…d R5 from historical G4 (2026-10-02 16:48)
…d Python3.12 cleanup anchor (2026-10-02 16:54)
…ll schemas and prepare public0.11 core release (2026-10-02 17:20)
…ristine candidate proof (2026-10-02 17:26)
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
…e and scoped CI blockers (2026-10-02 17:41)
… agyCLI proof (2026-10-02 17:53)
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b83dda7fbf
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| ( sleep "$timeout_secs"; kill "$cli_pid" 2>/dev/null ) & | ||
| local watchdog_pid=$! | ||
| local process_snapshot="${stdout_file}.processes" timed_out="false" | ||
| local polls_remaining=$(( timeout_secs * 20 )) state="" |
There was a problem hiding this comment.
Measure the portable timeout against elapsed time
When the portable branch is selected, multiplying timeout_secs into a poll count does not enforce the requested deadline because every iteration pays for a separate ps invocation in addition to the 50 ms sleep. In the inspected test_m1_legacy.sh run, a 3-second timeout completed after 5.67 seconds, and a slow or hung ps can extend it further; use a Bash-3.2-compatible elapsed deadline instead of a fixed number of polls.
AGENTS.md reference: AGENTS.md:L3-L5
Useful? React with 👍 / 👎.
| def process_start_identity(pid: int) -> str | None: | ||
| if sys.platform.startswith("linux"): | ||
| try: | ||
| fields = open(f"/proc/{pid}/stat", encoding="ascii").read().rsplit(") ", 1)[1].split() |
There was a problem hiding this comment.
Close the Linux process-stat stream
On Linux, every call to process_start_identity leaves the /proc/<pid>/stat stream to finalization rather than closing it deterministically. Running the required core suite with PYTHONWARNINGS=error::ResourceWarning produced repeated Exception ignored diagnostics from this line, flooding test and worker stderr and preventing a clean strict-warning gate; read the file with a context manager.
AGENTS.md reference: AGENTS.md:L3-L5
Useful? React with 👍 / 👎.
| venv_python = Path(path).parent / "venv/bin/python" | ||
| if not venv_python.is_file(): | ||
| raise SystemExit("existing release has no runtime Python") |
There was a problem hiding this comment.
Smoke-test an existing release before reusing it
On a normal reinstall where the content-addressed release directory already exists, this branch only verifies the core source hash and that venv/bin/python is a file. If the executable bit, .pth file, dist-info, or optional MCP environment has been damaged, and current already selects this release, activation and the fresh-build smoke checks are both skipped, so the installer reports unchanged success while squad remains unusable. Re-run the version/import and optional dependency checks before accepting an existing release.
Useful? React with 👍 / 👎.
| local new_json | ||
| new_json=$(jq -n \ | ||
| --arg ts "$ts" \ | ||
| --arg gs "$g_status" --arg g "$g_models" \ | ||
| --arg ks "$k_status" --arg k "$k_models" \ | ||
| --argjson old "$old_json" \ |
There was a problem hiding this comment.
Recover from malformed cached catalog JSON
If models.json is truncated or otherwise invalid, passing its raw contents to jq --argjson old exits before the atomic replacement is written. I reproduced this with a malformed cache: refresh returned 2 and left the same broken file in place, so every subsequent refresh repeats the failure even when discovery succeeds. Validate the old document first and fall back to {} when it cannot be parsed.
Useful? React with 👍 / 👎.
| stdin=subprocess.DEVNULL, | ||
| stdout=subprocess.PIPE, | ||
| stderr=subprocess.PIPE, | ||
| start_new_session=False, |
There was a problem hiding this comment.
Terminate the entire timed-out check process group
When a declared check spawns workers, as test runners commonly do, start_new_session=False leaves those descendants in the review worker's group while the timeout path terminates only the direct process. Descendants can retain the captured pipes and make BoundedDrain.finish() raise after five seconds, or continue mutating the check workspace while later checks and integrity snapshots run; create a separate owned session for each check and confirm bounded group cleanup before recording its result.
Useful? React with 👍 / 👎.
| if len(oid) != 40 or any(character not in "0123456789abcdef" for character in oid): | ||
| raise ContractError(f"Git ref did not resolve to a full commit OID: {ref}") |
There was a problem hiding this comment.
Accept commit IDs for the repository's object format
In a Git repository initialized with --object-format=sha256, rev-parse correctly returns a 64-character commit ID, but this hard-coded 40-character check rejects HEAD; I reproduced the failure with Git 2.43. This prevents every review or delivery workflow from starting in SHA-256 repositories, so validate IDs against git rev-parse --show-object-format and update the downstream OID validators consistently.
Useful? React with 👍 / 👎.
| if code == "AUTH_ERROR" or code == "RATE_LIMITED": | ||
| status = "failed" | ||
| elif timed_out or returncode in (124, 137, 143): | ||
| status, code = "timed_out", "TIMEOUT" |
There was a problem hiding this comment.
Prioritize an observed timeout over stderr pattern matching
Because authentication and rate-limit matches are handled before timed_out and return code 124, a process killed by the timeout can be misclassified from incidental stderr. For example, timed_out=True, return code 124, and authenticating request... currently produces failed/AUTH_ERROR because the broad auth pattern matches, directing users toward reauthentication instead of timeout recovery; classify the observed timeout before provider text.
Useful? React with 👍 / 👎.
…tchdog and preserve current gates (2026-10-02 18:06)
…st synchronization repair status (2026-10-02 18:23)
…l neighboring waiter failure (2026-10-02 18:33)
…hout changing runtime (2026-10-02 18:39)
…hase fixture finding (2026-10-02 18:47)
…ctual blocked ownership phase (2026-10-02 19:06)
DevSquad0.11.0 — public local-core release
User-authorized GitHub release in this existing repository. Standalone core0.1.0
and Claude plugin0.11.0; no registry or hosted service.
Durable review and Claude implementation → independent Codex review → trusted
checks → fenced disposition, with setup/doctor/status/result/cancel/resume.
Catalog/quota/outcome/trial/qualification integration, immutable installs and
schema17 old-client fencing. Bounded native probe ownership/EOF, guided finish
recovery, ordinary CLI compatibility, all-schema wheel packaging, portable
legacy real-deadline watchdog and isolated caller EXIT cleanup.
Verified gates
failures/errors/unraisable diagnostics. Core tree unchanged by later edits.
fingerprints and zero undeclared bytecode.
accepted/succeeded22;60 affected tests/36.416s, required integrity unchanged.
idempotent reinstall/no drift/pip check, four matching registrations.
run/version in18.654s. Earlier accepted Claude delivery/handoff and Grok
operation receipts retained for their recorded candidates/scopes.
45 affected Python tests/0.927s, clean independent50-assertion review.
Original timing limits and Bash3.2/optional-jq preserved; reference/diff pass.
Python3.14.7 stopped486/679.063s at a fixed-sleep recovery test assumption.
Both receipt/confirmed-dead synchronization corrections are test-only,
independently reviewed with controlled red/green; all33 service tests pass
on local3.12/3.14 and root33/29.820s, Bash259/reference/JSON/diff pass.
Runtime core tree unchanged. Root neighboring33/32.435s failed attempt is
also retained; no cancelled or failed job is represented as accepted.
but Python3.11.9 failed137/191.313s at another fixed-sleep repair test
assumption. That test killed the runner, not its coordinator, and needed
positive blocked-phase synchronization before typed retain-ownership.
The independently reviewed test-only fix preserves the one-writer and
exact-three-invocation assertions. Controlled old red/new green passed,
all52 delivery/service tests passed on3.12/3.14, root19 delivery/48.911s
and root33 service/29.820s passed, final Bash259/11 and reference/JSON/diff
passed. No product runtime changes; rejected cleanup diagnostic conflict
is retained as an unconfirmed follow-up, not a passing or unsafe finding.
8488ed4 passed all four jobs:
Bash3.2, Python3.11.9 (604/804.964s), Python3.14.7 (604/1110.004s),
optionalMCP (23/4.656s, one optional skip). Both full core jobs had
two optionalSDK skips and zero failures/errors/unraisable diagnostics.
Merged2026-10-03T02:27:18Z as
e7ec4ce; merged tree equals tested tree
bc76f192e3bcc7ce4528a040d7e58740278fbb32.
Explicit limits
Council mechanics are integrated/offline-tested, but native unavailable,
comparison inconclusive and automaticOFF. Jev OFF/single pilot spent.
Grok/agy MCP operations do not imply automatic worker roles. Claude desktop
Code-tab remains unverified/TCC; Antigravity means CLI, not IDE.
Existing CodexApp MCP connection needs DevSquad-only reconnect after upgrade.
Whole engineering-team plan is not declared complete. Earlier failed/rejected/
cancelled gates are retained in tracked evidence, not presented as passes.
Publication: merge this exact tested head, tag exact merged commit v0.11.0,
attach source/plugin archives, core wheel and verified SHA256SUMS.