mirror of
https://github.com/garrytan/gstack.git
synced 2026-08-23 14:32:33 +02:00
v1.67.2.0 feat: gpt-5.6-sol bounded-scope profile for Codex installs (#2633)
* feat: model taxonomy gains gpt-5.6-sol + per-host generation defaults
Adds 'gpt-5.6-sol' to the model taxonomy with exact-match-only resolution
(Terra/Luna/suffixed IDs deliberately fall back to generic gpt) and replaces
the hardcoded 'claude' generation default with a validated
HostConfig.defaultModel: codex renders the gpt profile when --model is
absent, every other host keeps claude. Codex ship golden regenerated
accordingly; ADDING_A_HOST documents the new field.
* feat: gpt-5.6-sol bounded-scope overlay + scope-aware resolvers
The Sol profile pins the explicit task as the lake: adjacent work is
report-only, investigation is bounded, runs terminate on one clean
verification pass, and the AskUserQuestion decision-brief format is never
trimmed. The overlay wrapper grants scope-interpretation precedence while
concrete workflow steps, gates, and skill-mandated re-verification loops
still win. Sol-specific Completeness Principle and first-run intro copy.
New SETUP_COMMAND resolver renders './setup --host <host>' for every
non-claude host so generated upgrade skills reinstall their own host.
* feat: setup reads the Codex model from config.toml
New resolve-codex-generation-model.ts reads the top-level model from
${CODEX_HOME:-~/.codex}/config.toml, validates against the model allowlist,
strips control characters from every config-derived string it surfaces,
guards against non-absolute config locations, and warns on Sol near-misses.
setup runs it on EVERY invocation (read-only TOML lookup) so a plain
./setup can never clobber a Sol user's rendered profile with the hardcoded
fallback; --model <id> overrides for one run and prints the persistence
hint. Kiro installs render the claude profile before copying (Kiro fronts
Claude-family models), rewrite the baked setup command to --host kiro, and
restore the resolved Codex profile after; the codex skills path honors
CODEX_HOME. Static pins cover the resolver wiring, fail-closed exit,
quoted argv, and the Kiro sandwich.
* feat: hermetic Codex runner hardening + Sol scope-termination E2E
The Codex E2E runner copies auth.json only (operator plugins, MCP servers,
rules, and skills no longer leak into hermetic evals), pins CODEX_HOME to
the temp dir, and supports per-run model, TOML overrides, and
--ignore-user-config. New periodic E2E installs the FULL generated
investigate skill on gpt-5.6-sol against a planted one-line bug with decoy
TODOs: the fix must land inside the boundary (untracked files counted via
git status --porcelain), decoys stay byte-identical, the regression oracle
survives unweakened, nothing gets committed, all within 30 tool calls.
The shared .agents tree is snapshotted and restored exactly in beforeAll;
fixture commits disable gpg signing. Wired into the periodic CI matrix,
paid-shard globs, eval scripts, touchfiles/E2E_TIERS
(codex-sol-scope-termination), and diff-based selection. Real-file
periodic-tier classification pins both codex E2Es out of the gate tier.
Free-tier test proves an explicit --model overrides the host default
through the real generation CLI.
* chore: bump version and changelog (v1.67.2.0)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* docs: post-ship documentation sync for v1.67.2.0
- README: Codex skills path is CODEX_HOME-aware; state that
--model overrides detection for one run only (persist via
the Codex config.toml model key)
- CONTRIBUTING: add the model-overlay axis to the per-host
config table (per-host defaultModel, override precedence)
- CLAUDE.md: eval results dir is ~/.gstack/projects/<slug>/evals/
(legacy fallback ~/.gstack-dev/evals/), matching eval-store.ts
and the eval:* CLI headers
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* docs: post-ship documentation sync (v1.67.2.0)
Sol exact-match and near-miss warning documented in README; CODEX_HOME-aware
uninstall and troubleshooting paths; hermetic auth.json-only detail and the
build-clobber gotcha in CLAUDE.md; eval-store location corrected in
ARCHITECTURE.md; defaultModel row in the ADDING_A_HOST field reference;
resolver test count corrected in the CHANGELOG entry.
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
c86e6472eb
commit
60e51342b5
@@ -771,6 +771,52 @@ Originally listed in the plan's "TODOs surfaced for later" section:
|
||||
|
||||
---
|
||||
|
||||
## Codex model profiles: follow-ups (filed v1.67.2.0 via /ship review army)
|
||||
|
||||
### P2: Single owner for the Codex render model (persist the resolved profile)
|
||||
|
||||
**What:** `./setup` resolves the Codex generation model from config.toml on every
|
||||
run, but every OTHER regeneration surface (`bun run build`, direct
|
||||
`gen:skill-docs --host codex`, the free suite's tree-mutating shard) renders the
|
||||
host default (gpt), silently reverting a Sol user's live symlinked render until
|
||||
the next setup. Persist the resolved model (gstack-config key or marker file the
|
||||
generator reads when `--model` is absent for codex) so all surfaces agree.
|
||||
**Why:** A Sol-using contributor cannot keep both a correct install and a green
|
||||
free suite in one tree; CLAUDE.md's "Deploying to the active skill" flow
|
||||
(bun run build) downgrades the profile. Cross-model consensus finding
|
||||
(Claude adversarial M4, Codex adversarial P2, red team C-70).
|
||||
**Priority:** P2. **Effort:** S (human ~half day / CC ~20min).
|
||||
|
||||
### P3: Codex periodic CI shards never execute (no codex CLI in Dockerfile.ci)
|
||||
|
||||
**What:** `evals-periodic.yml` carries `e2e-codex`, and now `e2e-codex-sol-scope`,
|
||||
but the CI image installs only claude-code, so both shards boot, skip everything,
|
||||
and report green weekly. Either bake `@openai/codex` + an auth strategy into the
|
||||
image, or prune both matrix entries and document codex evals as local-only.
|
||||
**Why:** A green all-skip shard reads as coverage that does not exist.
|
||||
**Priority:** P3. **Effort:** M (auth strategy is the hard part).
|
||||
|
||||
### P3: `--model` override persistence across upgrades
|
||||
|
||||
**What:** `./setup --host codex --model <id>` applies to that run only; the
|
||||
upgrade flow re-resolves from config.toml. Setup now prints the persistence
|
||||
hint (set `model` in config.toml). If users keep tripping on it, persist the
|
||||
override in `~/.gstack/config.yaml` and read it between `--explicit` and the
|
||||
TOML lookup.
|
||||
**Why:** Explicit user choices should survive upgrades or say loudly that they
|
||||
will not (the hint covers the second half today).
|
||||
**Priority:** P3. **Effort:** S.
|
||||
|
||||
### P4: `./setup --host slate` accepted but installs nothing
|
||||
|
||||
**What:** `slate` passes the host-arg validation case but sets no INSTALL_* flag,
|
||||
so the run configures nothing and exits successfully. Either wire a slate branch
|
||||
or reject the value with guidance like openclaw/hermes/gbrain get.
|
||||
**Why:** Silent success with zero effect is the worst failure shape.
|
||||
**Priority:** P4. **Effort:** S.
|
||||
|
||||
---
|
||||
|
||||
## browse server: terminal-agent teardown follow-ups (filed v1.41 via /plan-eng-review)
|
||||
|
||||
### ✅ DONE (v1.44.0.0): Identity-based terminal-agent kill (replace pkill regex with PID)
|
||||
|
||||
Reference in New Issue
Block a user