Skip to content

Release DevSquad0.11: durable local core and verified runtime repairs - #1

Merged
joshidikshant merged 197 commits into
mainfrom
codex/engineering-team
Oct 3, 2026
Merged

joshidikshant merged 197 commits into
mainfrom
codex/engineering-team

Conversation

@joshidikshant

@joshidikshant joshidikshant commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

DevSquad0.11.0 — public local-core release

User-authorized GitHub release in this existing repository. Standalone core0.1.0
and Claude plugin0.11.0; no registry or hosted service.

Durable review and Claude implementation → independent Codex review → trusted
checks → fenced disposition, with setup/doctor/status/result/cancel/resume.
Catalog/quota/outcome/trial/qualification integration, immutable installs and
schema17 old-client fencing. Bounded native probe ownership/EOF, guided finish
recovery, ordinary CLI compatibility, all-schema wheel packaging, portable
legacy real-deadline watchdog and isolated caller EXIT cleanup.

Verified gates

  • Frozen core b83dda7:604 tests/793.462s, two optional SDK skips, zero
    failures/errors/unraisable diagnostics. Core tree unchanged by later edits.
  • Actual pristine trusted check:60 tests/33.182s, unchanged exact input/payload
    fingerprints and zero undeclared bytecode.
  • Verified native Codex0.159.2/gpt-6.1-sol/low read-only EOF review: clean,
    accepted/succeeded22;60 affected tests/36.416s, required integrity unchanged.
  • Updated actual immutable schema17 MCP installation:9 SDK tests/no skips,
    idempotent reinstall/no drift/pip check, four matching registrations.
  • Actual updated agy CLI1.2.14/Gemini3.8FlashLow MCP status: exact saved
    run/version in18.654s. Earlier accepted Claude delivery/handoff and Grok
    operation receipts retained for their recorded candidates/scopes.
  • Integrated final legacy repair3fdc6bd:259 Bash assertions/11 files,
    45 affected Python tests/0.927s, clean independent50-assertion review.
    Original timing limits and Bash3.2/optional-jq preserved; reference/diff pass.
  • Prior public CI5a passed Bash/MCP/Python3.11 (604/1013.419s), but
    Python3.14.7 stopped486/679.063s at a fixed-sleep recovery test assumption.
    Both receipt/confirmed-dead synchronization corrections are test-only,
    independently reviewed with controlled red/green; all33 service tests pass
    on local3.12/3.14 and root33/29.820s, Bash259/reference/JSON/diff pass.
    Runtime core tree unchanged. Root neighboring33/32.435s failed attempt is
    also retained; no cancelled or failed job is represented as accepted.
  • Prior corrected public CI f40 passed Bash/MCP/Python3.14.7 (604/697.362s),
    but Python3.11.9 failed137/191.313s at another fixed-sleep repair test
    assumption. That test killed the runner, not its coordinator, and needed
    positive blocked-phase synchronization before typed retain-ownership.
    The independently reviewed test-only fix preserves the one-writer and
    exact-three-invocation assertions. Controlled old red/new green passed,
    all52 delivery/service tests passed on3.12/3.14, root19 delivery/48.911s
    and root33 service/29.820s passed, final Bash259/11 and reference/JSON/diff
    passed. No product runtime changes; rejected cleanup diagnostic conflict
    is retained as an unconfirmed follow-up, not a passing or unsafe finding.
  • Final public CI37088621735 on exact head
    8488ed4 passed all four jobs:
    Bash3.2, Python3.11.9 (604/804.964s), Python3.14.7 (604/1110.004s),
    optionalMCP (23/4.656s, one optional skip). Both full core jobs had
    two optionalSDK skips and zero failures/errors/unraisable diagnostics.
    Merged2026-10-03T02:27:18Z as
    e7ec4ce; merged tree equals tested tree
    bc76f192e3bcc7ce4528a040d7e58740278fbb32.

Explicit limits

Council mechanics are integrated/offline-tested, but native unavailable,
comparison inconclusive and automaticOFF. Jev OFF/single pilot spent.
Grok/agy MCP operations do not imply automatic worker roles. Claude desktop
Code-tab remains unverified/TCC; Antigravity means CLI, not IDE.
Existing CodexApp MCP connection needs DevSquad-only reconnect after upgrade.
Whole engineering-team plan is not declared complete. Earlier failed/rejected/
cancelled gates are retained in tracked evidence, not presented as passes.

Publication: merge this exact tested head, tag exact merged commit v0.11.0,
attach source/plugin archives, core wheel and verified SHA256SUMS.

Dikshant added 30 commits September 6, 2026 02:59
Shell suite passes. Core has one expected stale migration-version assertion while migration 002 and supervisor tests are unfinished.
Dikshant added 19 commits October 2, 2026 13:18
…worker deadline enforcement (2026-10-02 14:22)
…nd checkpoint R5 repair acceptance (2026-10-02 14:31)
…leanup; checkpoint independent finish-recovery finding (2026-10-02 15:19)
…ship rejection; retain Council upgrade proof (2026-10-02 16:39)
…d R5 from historical G4 (2026-10-02 16:48)
…d Python3.12 cleanup anchor (2026-10-02 16:54)
…ll schemas and prepare public0.11 core release (2026-10-02 17:20)
…ristine candidate proof (2026-10-02 17:26)
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-03T00:56:05.748412Z b83dda7 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Dikshant added 2 commits October 2, 2026 17:41

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b83dda7fbf

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread plugin/lib/adapter.sh Outdated
( sleep "$timeout_secs"; kill "$cli_pid" 2>/dev/null ) &
local watchdog_pid=$!
local process_snapshot="${stdout_file}.processes" timed_out="false"
local polls_remaining=$(( timeout_secs * 20 )) state=""

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Measure the portable timeout against elapsed time

When the portable branch is selected, multiplying timeout_secs into a poll count does not enforce the requested deadline because every iteration pays for a separate ps invocation in addition to the 50 ms sleep. In the inspected test_m1_legacy.sh run, a 3-second timeout completed after 5.67 seconds, and a slow or hung ps can extend it further; use a Bash-3.2-compatible elapsed deadline instead of a fixed number of polls.

AGENTS.md reference: AGENTS.md:L3-L5

Useful? React with 👍 / 👎.

def process_start_identity(pid: int) -> str | None:
if sys.platform.startswith("linux"):
try:
fields = open(f"/proc/{pid}/stat", encoding="ascii").read().rsplit(") ", 1)[1].split()

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Close the Linux process-stat stream

On Linux, every call to process_start_identity leaves the /proc/<pid>/stat stream to finalization rather than closing it deterministically. Running the required core suite with PYTHONWARNINGS=error::ResourceWarning produced repeated Exception ignored diagnostics from this line, flooding test and worker stderr and preventing a clean strict-warning gate; read the file with a context manager.

AGENTS.md reference: AGENTS.md:L3-L5

Useful? React with 👍 / 👎.

Comment thread scripts/install-core.sh
Comment on lines +316 to +318
venv_python = Path(path).parent / "venv/bin/python"
if not venv_python.is_file():
raise SystemExit("existing release has no runtime Python")

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Smoke-test an existing release before reusing it

On a normal reinstall where the content-addressed release directory already exists, this branch only verifies the core source hash and that venv/bin/python is a file. If the executable bit, .pth file, dist-info, or optional MCP environment has been damaged, and current already selects this release, activation and the fresh-build smoke checks are both skipped, so the installer reports unchanged success while squad remains unusable. Re-run the version/import and optional dependency checks before accepting an existing release.

Useful? React with 👍 / 👎.

local new_json
new_json=$(jq -n \
--arg ts "$ts" \
--arg gs "$g_status" --arg g "$g_models" \
--arg ks "$k_status" --arg k "$k_models" \
--argjson old "$old_json" \

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Recover from malformed cached catalog JSON

If models.json is truncated or otherwise invalid, passing its raw contents to jq --argjson old exits before the atomic replacement is written. I reproduced this with a malformed cache: refresh returned 2 and left the same broken file in place, so every subsequent refresh repeats the failure even when discovery succeeds. Validate the old document first and fall back to {} when it cannot be parsed.

Useful? React with 👍 / 👎.

stdin=subprocess.DEVNULL,
stdout=subprocess.PIPE,
stderr=subprocess.PIPE,
start_new_session=False,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Terminate the entire timed-out check process group

When a declared check spawns workers, as test runners commonly do, start_new_session=False leaves those descendants in the review worker's group while the timeout path terminates only the direct process. Descendants can retain the captured pipes and make BoundedDrain.finish() raise after five seconds, or continue mutating the check workspace while later checks and integrity snapshots run; create a separate owned session for each check and confirm bounded group cleanup before recording its result.

Useful? React with 👍 / 👎.

Comment on lines +56 to +57
if len(oid) != 40 or any(character not in "0123456789abcdef" for character in oid):
raise ContractError(f"Git ref did not resolve to a full commit OID: {ref}")

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Accept commit IDs for the repository's object format

In a Git repository initialized with --object-format=sha256, rev-parse correctly returns a 64-character commit ID, but this hard-coded 40-character check rejects HEAD; I reproduced the failure with Git 2.43. This prevents every review or delivery workflow from starting in SHA-256 repositories, so validate IDs against git rev-parse --show-object-format and update the downstream OID validators consistently.

Useful? React with 👍 / 👎.

Comment on lines +240 to +243
if code == "AUTH_ERROR" or code == "RATE_LIMITED":
status = "failed"
elif timed_out or returncode in (124, 137, 143):
status, code = "timed_out", "TIMEOUT"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Prioritize an observed timeout over stderr pattern matching

Because authentication and rate-limit matches are handled before timed_out and return code 124, a process killed by the timeout can be misclassified from incidental stderr. For example, timed_out=True, return code 124, and authenticating request... currently produces failed/AUTH_ERROR because the broad auth pattern matches, directing users toward reauthentication instead of timeout recovery; classify the observed timeout before provider text.

Useful? React with 👍 / 👎.

Dikshant added 6 commits October 2, 2026 18:06
…tchdog and preserve current gates (2026-10-02 18:06)
…st synchronization repair status (2026-10-02 18:23)
…l neighboring waiter failure (2026-10-02 18:33)
…ctual blocked ownership phase (2026-10-02 19:06)
@joshidikshant
joshidikshant merged commit e7ec4ce into main Oct 3, 2026
6 of 8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant