Conversation
The founder reported three problems with two ChatGPT accounts. The browser was signed into one account and Codewhale's own ChatGPT sign-in held another account that had run out of usage. Login gave no way to choose the account. Nothing showed which account Codewhale was using. The usage-limit error did not say which account hit the limit or how to switch. Choose: the ChatGPT parameter row now sends prompt=login (OIDC Core 1.0 section 3.1.2.1) on the authorize URL, and the login prints a private-window fallback. The only change is the row's authorize_extras; refresh never visits the authorize endpoint. Evidence for prompt=login, and its limits: - openai/codex @ f53f5a6 codex-rs/login/src/server.rs build_authorize_url sends id_token_add_organizations, codex_cli_simplified_flow and originator, and no prompt. openai/codex issue #17092 "No way to switch accounts without clearing browser session" is still open. So upstream Codex does not use prompt, and openai/codex uses prompt=login only in generic OAuth and gateway test fixtures (oauth/client_tests.rs, gateway_auth_tests.rs). - cnlimiter/codex-manager, a third-party multi-account tool, src/core/openai/oauth.py sends prompt=login to auth.openai.com /oauth/authorize with the same public client and parameters. - auth.openai.com/.well-known/openid-configuration does not list prompt_values_supported. - It was not tested against the live issuer. Unauthenticated curl probes of /oauth/authorize, with and without prompt, get a Cloudflare 403. If the issuer ignores prompt, the printed "open the URL in a private window" fallback still lets the user choose the account. xAI's device flow already lets the user choose the account on the issuer's page. Replace: activate_login used to merge a new grant into the previous entry for the same scope. When the new grant had no refresh token, id token or account id, account A's value stayed next to account B's access token. A login now writes a fresh entry. OAuthActivation reports the replaced account. Show: account_label_from_id_token decodes the ID token already stored with the credential. It reads email or the https://api.openai.com/profile email, plus the chatgpt_plan_type claim, entirely locally. It strips control characters and caps the length. The label is display-only, so the signature is not verified. Nothing new is stored because the label is derived from the existing id_token. Where it appears: - the end of login: "Signed in to ChatGPT as <email> (<plan>). Replaced the previous Codewhale ChatGPT sign-in (<old>)." - the TUI transcript after /provider login - the provider picker "Credential:" line - `codewhale auth status` (active source for openai-codex, "signed-in account" for xai) and `codewhale auth list` `codewhale auth list` also now reports the owned ChatGPT sign-in as owned-oauth. Before, it printed "missing" for that row. Switch: `auth chatgpt` and `auth xai-device` help now says "run again to switch accounts", and status prints a switch-account line. Usage limit: a 429 with {"error":{"type":"usage_limit_reached"}} (the openai/codex codex-api/src/api_bridge.rs mapping) is now typed QuotaExhausted, which is not retried. Before, it was a retryable RateLimited. On a ChatGPT or xAI OAuth route, plan-quota errors now include the signed-in account label and the exact switch command. The command is `codewhale auth chatgpt` or `codewhale auth xai-device`. The guidance is left out when a process token (OPENAI_CODEX_ACCESS_TOKEN) outranks the sign-in. Docs: docs/PROVIDERS.md, "Subscription sign-in accounts (ChatGPT, xAI)". Known limits: a consented Codex CLI or Grok CLI import shows no account label, because only Codewhale-owned files are read. The org title from id_token_add_organizations is not shown. Tests (targeted, local): - codewhale-tui: 11 new or touched tests, "test result: ok. 11 passed; 0 failed". Broader oauth:: / provider_picker:: / llm_client:: / credential_resolve / native_xai_oauth run: "test result: ok. 304 passed; 0 failed". - To show the fixes matter, I reverted each one (prompt=login, the usagelimitreached code, and the fresh-entry replacement). The 4 regression tests then failed ("0 passed; 4 failed"); relogin failed on refresh-a surviving into account B's credential. - codewhale-cli: "test result: ok. 26 passed; 0 failed" (owned / xai / codex / status / list filter, including the new owned_subscription_sign_ins_show_account_label_without_token_material). - cargo fmt --all -- --check clean. cargo clippy -p codewhale-tui -p codewhale-cli --all-targets --all-features --locked with the CI flags (-D warnings plus the CI allow list) printed no warnings or errors. Blocking-call and dead-code budgets pass. Refs #5778 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014ZwqatxgVFxHvovngywnks
… one Review follow-up for #6715. - Quota guidance comes from the credential the client actually sends. ChatGPT: the label is read from the same credential snapshot (owned entry or consented Codex CLI file), so a stale owned generation that fell through to consent no longer names the owned account. xAI: guidance only when the resolver's source is the xAI OAuth branch (`XAI_OAUTH_KEY_SOURCE`); an `auth_mode = "oauth"` route that fell back to an API key gets none, and the label is kept only when it belongs to credentials holding the same token. - Account labels use the runtime's usability test (fresh access token or a refresh token), shared with `credentials_valid`, so an expired entry with no refresh token names no account in the picker, `auth status` or `auth list`. - A login replaces the whole owned sign-in: other scopes are no longer carried into the new generation, so an older account under a differently spelled issuer cannot outrank the new login or keep its refresh token on disk. `replaced` names the entry that was in use; a re-login as the same account says so and how to pick another. - Guidance points to `/auth chatgpt` / `/auth xai-device` inside Codewhale and says to restart open sessions after a shell login. - `usage_not_included` (plan without Codex) is classified with `usage_limit_reached` instead of retried as a rate limit. - `prompt=login` moves to `account_choice_extras` with an opt-out, `CODEWHALE_CHATGPT_OAUTH_NO_PROMPT`. - The xAI device flow prints the same account-choice hint as ChatGPT. - Workspace-plan labels (team, business, enterprise, unknown) carry an 8-character account-id prefix so two workspaces on one email differ. - `auth status`: with an env token set, the switch line says to unset it first; login prints the same warning. xAI status reports why the account label could not be read, and no longer claims storage was unprobed on the line that now reads it. Tests (targeted, CARGO_TARGET_DIR isolated): - cargo test -p codewhale-tui --lib -- account_label usage_limit relogin stale_owned_entry authorize_url subscription_quota xai_oauth_mode chatgpt_usage_limit activation test result: ok. 46 passed; 0 failed - cargo test -p codewhale-tui --lib -- oauth codex xai provider_picker quota test result: ok. 406 passed; 0 failed - cargo test -p codewhale-cli --lib -- auth xai owned test result: ok. 44 passed; 0 failed - New regressions relogin_drops_other_scopes_and_names_the_account_it_replaced, stale_owned_entry_names_no_account and xai_oauth_mode_that_fell_back_to_an_api_key_gets_no_sign_in_guidance fail with the fixes reverted (0 passed; 3 failed) and pass with them (3 passed; 0 failed). - cargo fmt --all -- --check: clean. Not run: npm test / check:web (no web surface touched), full workspace suite. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014ZwqatxgVFxHvovngywnks
Chain-segment ("<!-- scoped instructions: ... -->") and
<project_rule source=...> labels carried absolute paths into the pinned
system prompt, so a checkout move or recase changed the prompt prefix
and could emit a spurious <context_update> history append.
Render both labels repo-relative (git-root-relative, forward slashes),
falling back to workspace-relative for rules outside any checkout and
to the absolute spelling only for paths outside the label root
(unreachable by construction). The label root is computed once and
threaded through context_chain_dirs, so the chain bounds and the
chain-segment labels derive from one and the same git walk.
Regression tests pin repo-relative chain and rule labels, the
workspace-relative fallback without a git root, the absolute escape
hatch for unplaceable paths, and byte-identity of the whole system
block for the same tree checked out at two different locations.
Adapted from the Pinvou fork (Pinvou/CodeWhale 7f04c90, PR #70);
builds on the file-name labels from the previous commit.
Signed-off-by: asto18089 <asto18089@126.com>
The launcher integration doc claimed rc.6 was the latest release; it now states once that rc.6 (August 2026) is the last verified version, and what the code does with other versions: older or no --patch is incompatible, a newer parseable version is stale-version, and a version that does not parse (for example 0.1.7-alpha.2, since only -rc.N suffixes parse) is offline and refused. The authoring guide and the importer's module doc now separate the static importer (never executes plugin code; TUI slash command and Runtime API only, no CLI subcommand) from the launcher integration and from the experimental extension host, and say which CI job exercises the pinned five-file fixture. Docs and one comment only; no cargo run. web/scripts/check-docs.mjs passes but does not cover these files. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
The launcher integration parsed only MAJOR.MINOR.PATCH[-rc.N], so a current DSH release such as 0.1.7-alpha.2 was reported as offline and refused. The hand-rolled parser is replaced by the semver crate the tui crate already uses; precedence comparison ignores build metadata. Such a version is now stale-version (launchable once connected, unverified), like rc.7 was. VERIFIED_DSH_VERSION, the --patch check and the offline mapping for text that is not a version are unchanged; no newer version is claimed verified. cargo test -p codewhale-tui --lib integrations::dsh: 42 passed; 0 failed (run by the implementing agent; rustfmt check clean on both files). Full gate not run. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Cargo.toml declared rust-version 1.88, but a locked dependency (serde-saphyr) requires 1.89 and CI's MSRV job builds 1.89. docs/INSTALL.md already recorded that a 1.88 install of v0.10.0 fails. The declaration, the English and Chinese install guides and the npm wrapper's build-from-source hints now say 1.89. cargo metadata --locked: ok. npm wrapper tests: 75 passed, 0 failed. No Rust build run for this change. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
…ign-in summary Review repair for #6715 (choose, show and switch ChatGPT and xAI accounts): - Account labels come from the read that proved the sign-in usable: `usable_sign_in` replaces `credentials_present` in the credential resolver and `CredentialSource::OAuth` carries the label, so the provider picker opens no credential file of its own (`owned_account_label` and `get_xai_access_token` are removed). - xAI quota guidance reads its account label from the credential the client sends (`active_route_api_key_with_xai_sign_in`), one read shared by the resolver, the guidance and the picker. - `OAuthActivation::summary` / `env_override_warning` render through `tr(locale, MessageId::Auth*)`; the six keys ship in all 15 locale packs. The TUI passes its UI locale; shell commands pass `Locale::En` beside their English-only surrounding text. - A new login replaces the whole generation (it holds only the new scope), so an older account's entry can no longer outrank it in `select_entry`. Focused test results for this and the commits that follow are recorded in the merge commit of origin/wave/0.10.1-next that follows them (this commit was first authored as an untested WIP). Refs #6715 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
`codewhale auth status xai` opens the owned generation to read the account label, so "storage unprobed" misdescribed it. `auth get xai` and the generation line now say the account label is read and only the token's availability is not verified. The owned-OAuth status test pins both lines. Focused test results are recorded in the merge commit that follows. Refs #6715 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Plan-limit guidance names the account whose credential the client sends: a consented Grok CLI import names the Grok file's account (the switch command replaces the consent), and a ChatGPT process token gets no guidance because a re-login would not change the sending account. The Codex consented-import, xAI owned sign-in and xAI API-key fallback cases were already pinned; the three provenance classes the review listed are now all covered. Focused test results are recorded in the merge commit that follows. Refs #6715 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
`OAuthActivation::summary` substitutes `{provider}` and `{account}` into the
six Auth* messages, so a pack that drops a placeholder or ships English
would silently lose the account name or stay untranslated. The test checks
all complete packs for placeholder parity and non-English text.
Focused test results are recorded in the merge commit that follows.
Refs #6715
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: CodeWhale Bot <bot@codewhale.net>
…run) An extension can register a slash command through the host's `commands` service (registration kind `command`); invoking it sends `command/run` to the host. A command returns text shown to the user, a prompt submitted as the user's next message, or both; it never calls the model or a tool itself, so anything that follows goes through the normal turn and its approvals. - A command cannot take a built-in's name or alias, or another plugin's command name (refused at registration with a reason). A markdown command wins a clash when the user registry loads. - Registrations are owned like tools: removed on disable, crash and generation change; handles are never reused, so a stale reference fails rather than running a newer command. - Result text is stripped of terminal escapes and bounded; an oversized prompt is refused, never truncated. The call is bounded by a 30 s deadline, then cancelled. - DSH-style command registrations work unchanged. - Protocol: generated TypeScript regenerated, corpus cases 37-45, the core-authority lint still passes. Known limits (recorded in the design's "As built" section): no keypress cancel before the deadline; TUI only (the Runtime API omits extension commands); no agent/session handle or attachments for the handler. Still behind `[features] extension_host` (experimental, off by default). cargo test -p codewhale-tui --lib -- extension_host:: commands::user_registry (real Node host, macOS): 85 passed; 0 failed. Host suite on Node 22.20: 79 passed, 1 skipped (Bun-only). Reported by the implementing agent and not re-run by the committer: host suite on Bun 1.4.0, 80 passed. CI-policy clippy not yet run on this commit; Linux and Windows unrun. Signed-off-by: CodeWhale Bot <bot@codewhale.net> Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…o 15
Test infrastructure only; no production code and no visibility change in
crates/tui/src/mcp*. The suite is the gate a host-backed MCP dispatch must
pass before the Rust pool can be removed (CURRENT_DECISIONS section 26).
New cases pin, for the Rust pool: stdio over a real child (exit mid-call is
"outcome unknown, not retried", next call reconnects), Streamable HTTP
session lifecycle and stale-session replay, an unsupported protocol version,
catalog pagination and the three catalog budget caps, approval hints,
needs-auth on 401, a bearer that is sent but never recorded, refusal of a
cross-origin redirect, and tool and server deny rules. Each has a negative
control, and three deviant dispatches (replays a failed call, refreshes its
own catalog, leaks the bearer) are caught.
The dispatch trait gains `approval_hint`, the factory takes
`DispatchSetup { config, disallowed_tools }`, and `boot` may fail while
`catalog`/`call` still answer.
Recorded as current behaviour: `notifications/tools/list_changed` is
ignored by the Rust pool (the catalog refreshes on reconnect only).
Not covered: real OAuth login, legacy SSE transport, concurrent calls, the
32 MiB aggregate cap, reviewed-launch hash refusal for stdio; stdio cases
are skipped off Unix. The fixtures README still says two transcripts.
cargo test -p codewhale-tui --lib -- conformance:: (macOS): 32 passed;
0 failed. Blocking-call and dead-code budgets pass (implementing agent's
run). CI-policy clippy not yet run on this commit.
Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Brings the branch up to date with main, which now carries #6737 (the file-name labels this PR was stacked on) as merge 1d42af9. One conflict, in the import block of crates/tui/src/project_context.rs: this branch's side imported project_instructions_source_label (already present on main's side, after the #6737 rustfmt-ordering fix) and added repo_relative_source_label. Resolved by keeping main's single `pub(crate) use ...project_instructions_source_label;` and this PR's `use ...repo_relative_source_label;`, dropping the duplicate re-export. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Merges 9626357 (the 0.10.1 wave) into the #6715 review repair. One textual conflict, crates/localization/locales/zh-Hant.json, resolved keeping both sides: this branch's six Auth* sign-in keys and the wave's TranscriptThought / TranscriptThoughtFor keys (all 15 packs now hold 2446 keys). The wave's own fix for the Rust 1.99 `fetch_update` deprecation removes the two build errors this branch hit on the stable 1.99 toolchain. No semantic break surfaced: the wave's oauth.rs-adjacent, credentials and endpoint-boundary changes compiled and passed against the account-label work. Evidence on the merged tree, via cargowhale, warnings as errors: - cargo fmt --all -- --check: clean - cargo clippy -p codewhale-tui -p codewhale-cli -p codewhale-localization --all-targets --all-features --locked -- -D warnings -A clippy::uninlined_format_args -A clippy::too_many_arguments -A clippy::unnecessary_map_or: exit 0 (after the type alias in the next commit; the merged tree alone tripped clippy::type_complexity) - cargo test -p codewhale-tui --lib -- oauth:: credential_resolve credentials:: provider_picker quota_guidance quota_errors sign_in_guidance relogin_ activation_ xai_ auth_: 408 passed, 0 failed - cargo test -p codewhale-cli --lib -- xai_ auth_ owned_oauth: 33 passed, 0 failed - cargo test -p codewhale-localization: 53 passed, 0 failed - Regression proof: with activation reverting to `previous_file.clone()` + `remove(scope)` and `summary()` forced to Locale::En, `cargo test -p codewhale-tui --lib -- relogin_` gives 0 passed, 3 failed (relogin_under_another_client_id_switches_runtime_credentials_and_label: left "access-a" right "access-b"; relogin_with_another_account_replaces_the_owned_entry: localized summary equals English; relogin_drops_other_scopes_and_names_the_account_it_replaced). Restored, the same filter passes. - python3 scripts/check-blocking-calls-budget.py: within budget (707 sites); check-dead-code-budget.py and check-provider-registry.py pass. Local tests only; no hosted CI, provider call or deploy was run. Refs #6715 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
…er read `active_route_api_key_with_xai_sign_in` tripped clippy::type_complexity under CI's -D warnings; `ResolvedApiKey` and `XaiSignInLabel` aliases name its parts. The provider picker comment records the known limit for the account label: it adds no credential read (the resolver's structural read, formerly `credentials_present`, already ran synchronously when a row is built before #6715), and the blocking-calls ratchet stays within budget. Verified by the clippy, test and ratchet runs listed in the merge commit that precedes this one (re-run after this change: clippy exit 0; tui 408, cli 33 and localization 53 passed, 0 failed). Refs #6715 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
…y, linked state and file-mode fixes - Task workers (#6728, #6573): an idle worker with nothing claimable naps 1 s instead of stat-ing the queue every 200 ms (about 10 stats a second with two workers, which 0.9.12 did not do). Pending work and in-process notifies are unchanged. A settled queue now notices another process's write within about 1 s rather than 200 ms. - Task store lock (#6573): the holder records its pid and acquisition time in the lock file, so "busy" names the holder and how long it has held the lock when that can be read. The repeated "Task claim unavailable" error is logged once per episode, then at debug. - Web search (#6746): when the Bing fallback is allowed, DuckDuckGo gets 60% of the budget and Bing the rest, so a hanging DuckDuckGo no longer starves the fallback. A custom search_base_url still has no public fallback and keeps the full budget. - PowerShell (#6745): CODEWHALE_POWERSHELL_EXECUTION_POLICY=inherit omits the process-scope -ExecutionPolicy Bypass. The default is unchanged. Documented in ENVIRONMENTS (en, zh_hans). Not run on Windows. - Linked .codewhale: the workflow journal creates nothing until a record is appended and appends through the confined helpers; the coordination lock rejects a linked state path before creating directories. - File modes: the runtime log is created 0600 without following symlinks and an existing log is tightened; .reconcile.lock and current.json.lock reuse the private lock-file opener. fleet.lock was already 0600; a test pins it. Verified on macOS, Rust 1.99, together with the UI fixes in the next commit: cargo fmt --all --check clean; CI-policy clippy on codewhale-tui and codewhale-localization clean; focused tui lib tests 518 passed, 0 failed, 3 ignored; blocking-call budget within budget (one ratchet entry tightened for journal.rs); dead-code budget at budget. Full suite and other platforms not run locally. Signed-off-by: CodeWhale Bot <bot@codewhale.net> Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…e revision; short paste toast - #6800: a locally cancelled or stall-recovered turn cancels its in-flight dispatch instead of leaving input blocked for up to the 60 s dispatch bound. The cancel goes through the existing dispatch-failure path, so the unsent prompt returns to the composer. - /edit: when the rollback is refused, the revised text is restored to the composer with edit mode re-armed instead of being dropped; opening /edit while a queued draft is being edited returns that draft to the queue first. - Oversized paste: the toast is a short sentence that fits, and the full message with the write error goes to the transcript once. New key in all 15 locales. - #6652: the thinking-fold set is no longer cloned every frame. Verified with the previous commit: focused tui lib tests 518 passed, 0 failed, 3 ignored; codewhale-localization 52 passed, 0 failed; fmt and CI-policy clippy clean. macOS only; the larger scroll-lag change and the main-loop idle backoff are not in this commit. Signed-off-by: CodeWhale Bot <bot@codewhale.net> Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
… segments Merges the head of #6739 (38e04c5, by asto18089) unmodified, so the original commit keeps its author. The contributor's fork refuses maintainer pushes (HTTP 403), so the merge with main that resolves the import-block conflict in crates/tui/src/project_context.rs is carried here instead of on their branch. No change to the contributor's code. cargo test -p codewhale-tui --lib project_context: 88 passed; 0 failed (run on the merge with main, before this merge with the wave; the wave's two extra commits do not touch project_context). rustfmt clean on the touched files; CI-policy clippy on codewhale-tui printed no warnings. Refs #6739 Signed-off-by: CodeWhale Bot <bot@codewhale.net> Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ins, plugin config and context - Licence notices: the embedded host bundle carries MIT-licensed packages (cordis, schemastery, cosmokit, dsh-util-values, dsh-tools excerpts). dist/LICENSES.txt is now generated at build time from the bundler's metafile and each package's own licence, embedded, and written beside the materialised bundle. THIRD_PARTY_NOTICES.md lists the packages. A test reads the package markers in the embedded bundle and requires a notice and a third-party entry for each. - Tool input is checked against the tool's registered JSON Schema before an approval card exists and again before the call is sent; an invalid input is a tool error the model can correct. A schema that cannot be compiled is refused at registration. jsonschema moves from a dev-dependency to a dependency of codewhale-tui (already in the lock file through codewhale-workflow-js; Cargo.lock unchanged). - A plugin with several native entries activates all of them under one owner; a failing entry fails the owner and the earlier entries are disposed. - Plugin context: tools and commands receive the calling workspace and a private per-plugin data directory. `[plugins."<name>".config]` in the user's config.toml reaches the plugin (16 KiB cap; project config cannot set it); a change starts a new generation; `/plugin show` lists the configured keys, never values. - `codewhale --enable/--disable <feature>` before a subcommand is passed through by the dispatcher instead of being rejected. - Docs and config comments: Linux sandbox wording, the 30 s handshake, the macOS sandbox write allowances. Known gaps: the trust review screen does not show config keys; a running session does not watch config.toml; no end-to-end launch of a rebuilt binary for the --enable fix. Verified by the committer on macOS, Rust 1.99, real Node 22.20 host: cargo fmt --all --check clean; CI-policy clippy on codewhale-tui and codewhale-cli clean; cargo test -p codewhale-tui --lib -- extension_host:: plugins:: commands::user_registry conformance:: integrations::dsh: 411 passed, 0 failed, 1 ignored; codewhale-cli lib: 475 passed, 0 failed; host suite on Node: 88 passed, 0 failed, 1 skipped. Reported by the implementing agent, not re-run: host suite on Bun 1.4.0, 89 passed. Linux, Windows and the Rust-side Bun tests unrun. Signed-off-by: CodeWhale Bot <bot@codewhale.net> Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…nput validation, plugin config, MCP parity suite Brings the TypeScript extension work onto the 0.10.1 release branch: extension slash commands (command/run), licence notices for the embedded host bundle, tool input validation against the registered schema, multi-entry plugins, plugin config and context, the recorded MCP parity suite (2 to 15 cases), the DeepSeek Harness version fix and docs, and the declared Rust floor of 1.89. The extension host stays behind [features] extension_host (experimental, off by default). No textual conflicts. Verified on the merged tree (macOS, Rust 1.99, real Node 22.20 host): cargo fmt --all --check clean; CI-policy clippy across the workspace, all targets, clean; blocking-call and dead-code budgets pass; root npm test green (wrappers, SDK 19, extension host 88 passed and 1 skipped, web 653). Focused codewhale-tui lib tests (extension_host, plugins, commands, conformance, DSH, task manager, web search, project context, dispatch and edit paths): one failure, commands::debug_diagnostics_baseline_tests:: context_routing_and_report_branches_match_baseline, which reads the developer's real home directory and fails on this machine before and after this merge; its isolation is in progress separately. Linux and Windows are left to hosted CI. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Adds entries for what landed after 9626357: the experimental TypeScript extension host (new in this release, off by default) with slash commands, input validation, multi-entry plugins, plugin config and context, the --enable/--disable passthrough and third-party notices; the Rust 1.89 floor; the deferred-tool first call; the Git 2.31 floor; idle task workers; the task-store lock holder; the web search fallback and its time budget; cancelled turns releasing input; /edit restoring the revision; the oversized-paste notice; repo-relative labels (#6739); linked .codewhale and owner-only log and lock files. The DeepSeek Harness version bullet moves from Unreleased into 0.10.1. Four existing bullets change wording: the PowerShell bullet gains the inherit opt-out, the stall-watchdog bullet loses the sentence that the dispatch wait still blocks input, the audit-log sentence is qualified as Unix-only, and the Bun bullet's opening is reworded. The 0.10.1 section's repeated headings (Security seven times, Fixed three) are merged into one each; a byte-level compare shows every other original bullet present verbatim and in its original order (187 bullets before, 207 after: 19 new, 1 moved). scripts/sync-changelog.sh --check, check-contributor-credit.py, check-versions.sh --range-audit-advisory and the release-body test pass. No Rust change. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Per-frame transcript work grew with history length: ensure_iter collected every cell into a Vec, ran two full backward scans, and moved all N cached cells out of and back into a fresh Vec; the collapsed path allocated three N-length vectors with three hash lookups per cell. What changed - transcript.rs ensure_iter: cells are reached by index, the cache is updated in place, and a new contiguous `seen_revisions` mirror gives the first changed cell with one slice compare. A frame whose revisions, width, options and folds are unchanged renders, moves and allocates nothing; a tail-only frame renders only the tail. The newest-user-turn / newest-Work- receipt scans reuse the previous pass for the unchanged prefix (newest_matching_cell), asserted against the full scan in test builds. No new trust is added: reuse is still decided by the per-cell revision the cache already trusted. - app.rs / widgets/mod.rs: the collapsed row mapping (filtered->original index, summary slots) is cached per tool-run projection generation and the user's hidden-cell set; only revisions are gathered fresh each frame. - dispatch.rs: a failed dispatch rolled `history_version` back to its old value, so a cache keyed on (version, len) could match a different cell that later landed at the same version. It now bumps instead (snapshot field removed; test asserts the version moves). - transcript.rs: a tool, hidden or other cell replaced in place by a streaming answer at an unchanged cell count took the tail-only flatten and left its neighbour's group rail and spacer stale (found by the new cold- render property test; same in the pre-change code). The shortcut now requires the cell's kind/groupable/empty shape to be unchanged. Writer audit (every mutation of the state the caches key on; non-test code) - history_version bumps: app.rs add_message, maybe_fold_history, mark_history_updated, mark_live_motion_updated_inner, bump_history_cell, push_history_cell, extend_history, clear_history, pop_history, truncate_history_to, bump_active_cell_revision, cell_at_virtual_index_mut (both arms), flush_active_cell; ui/dispatch.rs failed-dispatch rollback (was a rewind, now a bump). - history_revisions writers: all in app.rs (the push/insert/drain/truncate/ clear/pop sites above, resync_history_revisions, bump_history_cell, mark_live_motion_updated_inner, cell_at_virtual_index_mut) plus the dispatch.rs rollback truncate. Every in-place `history.get_mut` / `history[i] =` site (event_loop x2, frame.rs append_streaming_text, streaming_thinking, subagent_routing x4, ui/apply.rs, ui/dispatch.rs, app.rs workflow/interrupt paths) calls bump_history_cell after it. - active_cell_revision: app.rs bump_active_cell_revision/mark_live_motion/ cell_at_virtual_index_mut, tool_routing.rs x2, ui/apply.rs; it is itself part of the tool-run key and of every active entry's revision. - collapsed_cells / thinking_folds / expanded_tool_runs: compared by value against a snapshot each frame, so their writers need no bump. The transcript cache itself keys on per-cell revisions, not on history_version, so a missed version bump cannot leave it stale; only the tool-run projection and the collapsed row mapping lean on the version, as before. history_has_live_motion is left O(N) (~3 ns/cell per tick): has_live_motion is derived from cell state mutated in place at many sites, so a maintained counter could not be proven correct. Also still O(N): the tool-run projection rebuild on every history_version bump (each streamed chunk) and mark_live_motion_updated_inner's per-tick scan. Measured (release profile, thin LTO, TestBackend 140x40, 200 frames, `cargo test -p codewhale-tui --lib --release -- --ignored bench_full_frame_scroll_cost_by_history_length --nocapture`; machine shared with other builds, so +/-10%): plain history before after 400 cells 136.3 us/scroll 155.5 us (noise) 4000 cells 198.8 181.5 20000 cells 454.2 287.2 (-37%; 16.2 -> 6.8 ns/cell) height-change 164.6/228.4/492.7 -> 172.1/206.3/309.4 An earlier run of the same final hot path gave 142.6/160.3/270.6. Collapsed history (new variant, after only): 500 cells 148.8 us, 5000 cells 199.8, 25000 cells 462.5. Isolated collapsed-input prep, same binary: 58.4 us -> 12.7 us/frame at 5000 cells, 52.3 -> 9.8 at 4021. Tests (debug, focused; code first, tests after) - New: cached_transcript_matches_a_cold_render_after_every_mutation (8 seeds x 150 mutations: append, replace, stream, finish, active replace, fold, width, options, clear, truncate, hide, owner, retarget; settled frames render zero cells), warm_chat_frame_matches_a_cold_frame_after_every_ mutation (6 seeds x 120 App-level mutations through the real widget), an_unchanged_frame_renders_and_moves_nothing, a_tail_only_change_renders_ only_the_tail_in_place, a_tool_slot_taken_by_a_streaming_answer_refreshes_ its_neighbour; rollback test now asserts the version moves. - tui::transcript:: 46 passed 0 failed 2 ignored; tui::widgets:: 258/0/2; tui::ui::tests:: 863/0/1; `tui:: golden commands::debug_diagnostics` 4049 passed 0 failed 7 ignored. Not run: the full suite, hosted CI. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
`commands::debug_diagnostics_baseline_tests::context_routing_and_report_ branches_match_baseline` failed on any machine whose real home carries global instructions or installed skills: `/context report` counts both, so the frozen token totals moved (here ~/.codewhale/instructions.md is 126,359 bytes, past the 102,400-byte cap, and the user's skills load too). The fixture owned its workspace and skills directory but not the user's home. Fix: `SealedHome` (debug_diagnostics_test_support) takes lock_test_env and pins HOME, USERPROFILE and CODEWHALE_HOME to empty temp dirs for the test's life, the same seal the restore-route tests use (81d9ec8). Applied to the two baseline tests that read the report. Sibling found by the real-home vs empty-home comparison: `context_alias_and_bare_action_are_preserved` compares `/ctx report` with `/context report` byte for byte and failed 6 of 40 real-home runs (the skills block moved between the two calls: 8103 vs 8589 tokens); 0 failures in 60 real-home and 10 empty-home runs after sealing. Nothing else in the module differed. Comparison runs (family filter `commands::debug_diagnostics`, 87 tests; the real-home loop is read-only for this family, checked by file mtimes): - before, baseline release binary: real home 86 passed 1 failed (the target); empty temp HOME+CODEWHALE_HOME 87 passed 0 failed. - after: real home 60/60 runs 87 passed 0 failed; empty home 10/10 87 passed. - `commands::debug_diagnostics_baseline_tests` 14 passed 0 failed. Not run: the full suite, hosted CI, Windows (the seal sets USERPROFILE too). Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
…pproved Records saved before the field existed now load as not auto-approved, so a missing grant never widens authority. A test loads a record with the field removed and checks the thread and turn requests built from it. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Every update request and every redirect hop must be HTTPS and must name GitHub's release hosts, the CNB mirror, the host of the configured release mirror, or a host listed in CODEWHALE_UPDATE_ALLOWED_HOSTS. A release tag read from a page must look like a tag. The 512 MB response cap and the HTTPS-only redirect rule are now tested through the real HTTP client. docs/INSTALL.md says how to use a private mirror. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Connecting, stalling, total time and response size are limited for the status, text and JSON requests the release check makes. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
…the workspace Agent profiles and skills read from a workspace no longer follow a link out of it; a refused entry is named in a warning or load issue. User-owned directories (personal profiles, ~/.claude/agents, home skill roots) still follow links. Adds one shared link check for paths taken by name. The pinned writer also asks again when macOS fails a concurrent create with ENOENT. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
…ined The destination is created through the pinned no-follow writer: a linked directory or file name is refused, new files are owner-only, and a dangling link at the destination name is no longer written through. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
added 21 commits
October 2, 2026 00:59
…fest schema The real Rust installer rejected the new hook-policy fixture because its schema field was absent. Add the existing agent-plugins manifest schema. Verification: original host phase 111 passed, 1 fixture failure; repaired exact hook timeout/revoke/workspace regression 1 passed, 0 failed. No permission or installation guard was loosened. Combined Engine/CLI build and protocol drift test pass; remaining focused phases continue.
Avoid an English renderer-only header on the new instructions receipt; the complete runtime message already identifies its source and purpose. The user sees the same recorded text as the model. Exact-file diff check passed; focused transcript regression in the compiled integration is pending.
The real Engine fixture reached the write approval, but its assertion incorrectly expected the generic File tool description to include a path. Inspect the actual approval input and require the complete revised write instead. Original engine phase: 52 passed, 1 assertion failure; this repair awaits the next coherent source build. The independent real-host timeout/revoke/workspace test passed after its manifest fix. No runtime gate changed.
Source checkpoint: replace local segment identities, shed and projection passes, painting and pointer-width arithmetic with the pinned kit MetricsLine. Keep all caller-facing fact/theme/action signatures, map distinct full-color source identities to the live ChromeInk grammar, and preserve untouched cells plus host backgrounds and modifiers. Scoped rustfmt and diff whitespace checks passed. Cargo compilation and focused buffer tests are pending the parent-owned build slot; no Cargo run for this checkpoint.
…ocale Use shared typed ExtensionPromptUnavailable at the Engine capture failure branch. Translate English plus all 14 complete locale packs. Locale parity: 2448/2448 keys in every complete pack, PASS. Static MessageId enum / ALL_MESSAGE_IDS / English reference check: 2448 unique keys, exact sync. Scoped diff check passed. No Cargo or web gate run for this narrow localization slice; combined Rust validation belongs to the integration owner.
Cover all 17 ChromeInk variants against independently customized live theme slots, actionable hover and untouched host style; exercise CJK/combining text and ASCII projection across widths 0-40 with clipped targets; prove hidden-control sanitation uses the same geometry as painting. Document complete MetricsLine adoption while keeping the exact existing vendor pin. Validation: scoped rustfmt --check and git diff --check passed. The 14 focused infoline tests, frame metrics tests and one-owner contracts await the parent-owned Cargo slot; no Rust tests were run for this checkpoint.
Pin upstream PR #8 merge de0f247dbe30176c4afbd100ea285b0f982985a3. Copy the same 176 committed source/package files byte for byte, retain MIT attribution and local ADOPTION.md, and regenerate every SHA-256 provenance entry. Preview media and local session artifacts stay excluded. The kit gains opt-in region ground matching and the native three-row shell floor; MetricsLine API and package manifests are unchanged. Validation: all 176 source files matched the exact upstream Git objects and SHA-256 inventory; tracked vendor inventory is exactly 178 files including the two local metadata/adoption files. Diff whitespace check passed. Exact merge SHA hosted CI and Gallery previews both completed successfully (runs 36981614975 and 36981614926). Engine integration compilation/tests remain parent-owned; no Cargo run or package publication for this checkpoint.
The guarded catalog refresh held its test environment lock while awaiting an unenrolled blocking worker. Carry the existing scope ticket into both preparation and publication workers without changing production credential or endpoint policy. Evidence: the focused 147-case ChatGPT integration run stalled at the unregistered-catalog fixture; stopped the owned test binary and preserved its log. Source diff check passed. A rebuilt focused run and npm/web gates remain pending.
Checkpoint the already reviewed MetricsLine adapter before posture adoption. The adapter preserves host backgrounds/modifiers/untouched cells and delegates native painting. Scoped rustfmt and git diff --check pass. No Cargo run; parent owns the shared build slot.
…eceipts Reconcile English extension and author guides plus the Chinese extension contract with stable ctx.skills.registerRoot API. State bundle-relative paths, existing parser and nested-package behavior, Native admission, logical root/candidate/raw-byte/instruction-field caps, disposal and host/process restart invalidation for queued selections. Existing Claude/Pi/static DSH distinctions remain. Checks:37local documentation links valid,0missing; scoped diff check pass. No Rust build or web gate run for this docs-only slice.
ctx.skills.registerRoot proposes bounded bundle-relative roots through the existing owned registration lifecycle; disposal withdraws the exact handle. The host only proposes Native-reviewed roots to Rust and never reads Skill bodies itself. Add a Native-only integration fixture and real-host admission/rollback cases. Source validation: Node 22.20.0 focused source tests 6 passed, 0 failed; Bun 1.4.0 focused source tests 6 passed, 0 failed; strict TypeScript typecheck and diff whitespace check passed. Host dist and real-host tests await the coordinated parent build. Rust admission/catalog consumer slice is in progress and not yet compiled; no release or parity claim.
Rebuild the embedded bundle and test protocol modules from the frozen skill-root API. The Rust binary still builds without Node or npm. Evidence: deterministic host build, strict TypeScript check and scoped diff check passed. The full npm/web gate is running; authoritative Rust wire drift and native root admission tests remain pending.
Replace the caller posture item/projection/shed/clipping/paint/count-layout implementation with kit PostureBar. Preserve the complete TidelineFooter facade and Engine facts, localization, clocks, live custom theme and action dispatch. Every host ChromeInk is encoded as a distinct source Role, including pinned right notices whose optional ink the current kit drops during layout; no pinned source fork. Delete 298 net production lines in phase_strip.rs. Add three regressions for all 17 inks across every fact/right notice with retained host style and count keys, CJK/combining/ASCII/control-safe pointer geometry across widths, and context-cap live warning ink. Existing 27 posture tests remain intact (30 focused tests total). Scoped rustfmt --check and git diff --check pass. No Cargo run; parent owns combined Rust verification.
…supported Use secrets as the unsupported injection fixture because the host now deliberately provides the owned skills service. No authority service is introduced. Evidence: host suite 212 passed, 0 failed, 1 Bun-only skip; npm wrapper 79 and runtime SDK 19 passed. Root npm gate stops in the concurrent website slice: two web suites cannot resolve the not-yet-created ratatui catalogue module (625 web cases passed). check:web has not run.
Use W for the clock cell so the all-ink assertion cannot match the earlier Tab key. Test-only correction; git diff --check passes. No Cargo run.
…alog Admit owner-scoped Native-reviewed staged bundle roots through the existing registration manager and Skill parser. Reviewed inventory and content hashes precede parsing; root accumulation and admission concurrency are bounded, and final owner/host count and instruction-field quotas reject excess without truncation. Disposal, revoke, host exit and restart retire exact registration lifetimes. All shared discovery consumers inherit the same catalog: model prompt and load_skill, user menus/activation, Runtime API and subagents. Native root provenance reuses process boot, host/owner generations and exact handle beside the existing reviewed authority; queued/persisted dispatch refuses withdrawn or cross-process instructions. Legacy bare plugin authority receipts remain readable. Extension epoch cache refresh runs outside the UI loop and installs only into the captured caller scope. Validation boundary: exact-path Rust formatting and whitespace checks passed. Added 9 focused Rust skills tests and 2 UI lifecycle/cache tests, including reviewed parser parity with declarative roots. Coordinated parent Cargo build, authoritative protocol generation and focused Rust execution remain pending; no Rust test pass, hosted CI pass or release claim. TypeScript checkpoint 9bbd138 separately records Node/Bun source 6/0 and strict TS pass; parent reports rebuilt host suite 212/0/1 skip.
The typed approval-withdrawn variant and producers were implemented, but EVENT_KINDS still omitted it. Include the event in its canonical position so consumers see the complete public catalogue. Evidence: full protocol library83passed1failed exposed the missing catalogue entry; roundtrip coverage passed. Corrected catalogue rerun remains pending rebuild. Integrated Engine/approval53passed0failed and ChatGPT147passed0failed are independently green. npm/web gate still awaits the concurrently owned component explorer.
Reuse the existing fast current-owner/tier guard, then validate Native authority and parse reviewed roots within one permit-held blocking job. Cancellation and abandoned handlers retain that permit until every disk phase finishes; final admission still checks host readiness/generation and current owner. Add a production-helper test for token cancellation, handler abort, cancelled queued work and resumed admission. Repair three test assumptions exposed by the coordinated run: add canonical $schema to parser bundles; prove Native-only fixtures have zero declarative Skill inventory/snapshots; require explicit retry after shutdown preserves a failed activation, then assert a fresh live owner and reject old handles. Owner diagnostics accompany restart lookup failures. Evidence: parent pre-repair all-feature four-package build passed in4m12; first selected extension-host run117 passed,4 failed (schema x2, inventory assertion, unchanged failed-owner replay assumption), retained at /Volumes/VIXinSSD/CW/artifacts/gpt61-0101-takeover-20261002/mods-extension-host.log. This batch passed exact-path formatting/whitespace and independent source review. No Cargo or post-repair execution by this agent; parent owns the rebuilt focused verification. No pass is inferred from source review.
The coordinated all-feature rebuild failed on two test-only Debug format expressions for OwnerReport. Use the already-debuggable owner_state in the diagnostics; keep production types and assertions unchanged. Original two-error output retained at artifacts/gpt61-0101-takeover-20261002/mods-repair-first-compile-failure.log outside the product repository. Exact diff whitespace passed; rebuilt focused verification follows. Root npm gate remains pending the concurrent Ratatui website completion.
Add /ratatui and 195 component pages to the existing Codewhale website, with public API search, 17 collections, nine terminal profiles and four actual column-width renders. Include source fixtures, immutable source links, SVG download, install examples, build/release links, native motion playback, English/Chinese copy, menu/footer discovery and sitemap entries. Previews use the library's actual painted Rust buffers and frames; no second terminal renderer or Engine dispatch is introduced. Motion starts paused, supports speed/scrubbing and pauses when hidden or reduced motion is requested. Narrow screens begin at 40 columns with collapsible browsing. Validation: 659/659 web cases across 66 files; npm run check:web passes facts, release freshness, docs, tokens, lint, TypeScript and production Next build. All 7,020 buffers and 762 frames match native exports. Kit exporters pass 16 Python tests, cargo fmt and focused clippy. Browser QA covers API search, paper/ocean profiles, narrow layouts, source copying, deep links, motion play/pause/end scrubbing, Chinese and responsive overflow. Independent finish review found no blocking defects. The initial root npm gate found the new menu link missing from a nav test; the expectation was corrected. A concurrent build caused two unrelated installer test timeouts; the sequential web rerun passed all 659 cases. No production deployment or package publication is claimed by this commit. Refs SHA-6831
Add /ratatui and 195 component pages to the existing Codewhale website, with public API search, 17 collections, nine terminal profiles and four actual column-width renders. Include source fixtures, immutable source links, SVG download, install examples, build/release links, native motion playback, English/Chinese copy, menu/footer discovery and sitemap entries. Previews use the library's actual painted Rust buffers and frames; no second terminal renderer or Engine dispatch is introduced. Motion starts paused, supports speed/scrubbing and pauses when hidden or reduced motion is requested. Narrow screens begin at 40 columns with collapsible browsing. Validation: 659/659 web cases across 66 files; npm run check:web passes facts, release freshness, docs, tokens, lint, TypeScript and production Next build. All 7,020 buffers and 762 frames match native exports. Kit exporters pass 16 Python tests, cargo fmt and focused clippy. Browser QA covers API search, paper/ocean profiles, narrow layouts, source copying, deep links, motion play/pause/end scrubbing, Chinese and responsive overflow. Independent finish review found no blocking defects. The initial root npm gate found the new menu link missing from a nav test; the expectation was corrected. A concurrent build caused two unrelated installer test timeouts; the sequential web rerun passed all 659 cases. No production deployment or package publication is claimed by this commit. Refs SHA-6831
This was referenced Oct 2, 2026
added 6 commits
October 2, 2026 01:51
Move existing reviewed launch/env/fd binding, bounded stderr/redaction, process-tree cancellation and graceful/Drop teardown into BrokerSession. The production StdioTransport immediately delegates lifetime and retains cancellation-safe framing. Migrate every direct child consumer and replace both hand-built test transports with real contained spawn; no new host RPC or raw-write grant. Evidence: all-feature TUI library build passed (5m50);25 selected real lifecycle/framing/environment/revocation and transcript-golden tests passed,0 failed (3.61s). Root npm gate before concurrent website capture changes:969 passed,0 failed,1 Bun-only skip;check:web passed. Same-source detached hash/copy checks, independent review and whitespace passed. Workspace Clippy/final combined head/host-SDK migration remain pending. This is adopted C2 process ownership, not completed host MCP parity. No live auth/provider/deploy/publication.
Replace stale 0.10.0 website cells with six actual native PTY captures from installed Codewhale 0.10.1 (e940149). Home, unsent composer, Tasks and Fleet workbars, provider selection and help share one accessible view selector on the homepage, product page and guide. Native cell text, colors and geometry stay unchanged. Captures use a sealed HOME and offline onboarding, with no provider prompts or fixture history. Refresh every README language and the public screenshot facts to the same native home frame. Render that frame through the existing SVG exporter, preserving Braille dot bits, and present explanatory reasoning as prose. The Ratatui explorer continues to label reusable component example data. Validation: web tests 661 passed / 0 failed (66 files); npm run check:web passed facts, release, install/docs, tokens, lint, TypeScript and production build. Capture generation --check and git diff --check passed. Desktop and 390px mobile browser QA passed in English and Chinese, including view selection and keyboard-scrollable native regions; independent final review found no blocking fidelity, accessibility or functional issues. Six capture SHA256s, dimensions and installed binary before/after identity verified. No Cargo build, provider workflow, production deploy or release claimed.
Replace stale 0.10.0 website cells with six actual native PTY captures from installed Codewhale 0.10.1 (e940149). Home, unsent composer, Tasks and Fleet workbars, provider selection and help share one accessible view selector on the homepage, product page and guide. Native cell text, colors and geometry stay unchanged. Captures use a sealed HOME and offline onboarding, with no provider prompts or fixture history. Refresh every README language and the public screenshot facts to the same native home frame. Render that frame through the existing SVG exporter, preserving Braille dot bits, and present explanatory reasoning as prose. The Ratatui explorer continues to label reusable component example data. Validation: web tests 661 passed / 0 failed (66 files); npm run check:web passed facts, release, install/docs, tokens, lint, TypeScript and production build. Capture generation --check and git diff --check passed. Desktop and 390px mobile browser QA passed in English and Chinese, including view selection and keyboard-scrollable native regions; independent final review found no blocking fidelity, accessibility or functional issues. Six capture SHA256s, dimensions and installed binary before/after identity verified. No Cargo build, provider workflow, production deploy or release claimed. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Bind the existing auth policy once to the guarded HTTP session and migrate preflight GET, Streamable POST, SSE GET and SSE POST. Delete transport auth fields and duplicated header passes; raw OAuth send/execute keeps its separate request shape. Original DNS, redirect, proxy, deadline, provenance, refresh and no-replay guards remain byte-identical. Validation: combined all-feature TUI lib test build passed in 4m24; selected MCP HTTP/credential/egress/streaming/revocation/conformance cases 36 passed, 0 failed. Root npm test 971 passed, 0 failed, 1 Bun-only skip; npm run check:web passed. Source/candidate hashes and exact preserved guard blocks reviewed. Hosted CI and real OAuth/provider flows are separate pending proof.
Pin all 178 exact upstream inventory files to merged Ratatui PR10 at5b4c5e6. Replace the Engine ramp/column sampling math with the shared kernel, preserving live semantic tints, absolute rows, actual-ramp cache identity, presence and monotonic clocks. Remove the callerless attention wrapper caught by the first build. Semantic finishing still follows the existing host backend policy; guarded paint adoption remains separate. Validation: all-feature TUI lib test build passed in4m24 after the unused-wrapper repair; native Ocean and pet-clock cases31 passed,0 failed. Root npm test971 passed,0 failed,1 Bun-only skip and check:web passed. Workspace fmt and source whitespace check passed; all178 upstream seals verified. Ratatui PR10 exact-head CI/Gallery green and merged. No native screen, provider, install or release claim.
…on/0101-ts-ratatui-1002
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs #6458
Codewhale 0.10.1 integrates official ChatGPT-plan sign-in with the extensible harness foundation: reviewed TypeScript tools, commands, hooks, prompts, state and skills feed the existing Rust Engine. Rust retains execution, permission, credential, session and event authority. This branch also replaces migrated native terminal renderers with the pinned Codewhale Ratatui components and carries the current website/gallery work.
The original ChatGPT sign-in commitc58a853f7754beef91c4ffa208f93ee1a240994c remains in the branch history. It implements OpenAI’s official open-source flow, secure registration/refresh, account-specific models, ChatGPT-plan requests and no automatic paid fallback. Author evidence: artifacts/chatgpt-sign-in-20261001/EVIDENCE.md. Live ChatGPT sign-in has not been verified;
codewhale auth chatgptrequires a qualified build and user login.Qualified source is pushed through71ecf69170adb4e80e5dc4eeff872b88c95ad365. Implementation evidence and retained failures: artifacts/gpt61-0101-takeover-20261002/EVIDENCE.md. Local and differently-hashed published website commits have identical web trees and are both preserved; no force push or published-history rewrite.
Local verification of the qualified slices:
The PR remains draft. All accepted TypeScript phases remain in0.10.1: official SDK host backend and parity/default-flip gate, remaining process/network brokering, native DSH composition and per-agent presets, script/shell orchestration, remaining native terminal consumers, runtime cleanup and binary consolidation are still being implemented. Full Access extension-human-card and shared catalogue-budget corrections passed10/0 and19/0. Pending-card upstream passed every exact-head CI and Gallery job before merge; its Engine adoption passed26/0 including1350 heights/6750 buffer comparisons. The199-entry actual website catalogue passed the971-case npm/web gate. Workspace Clippy passed locally after five source repairs. These later commits await the next qualified push. Approval DecisionBand upstream also merged after all CI/Gallery jobs; its local Engine acceptance exposed an old right-edge paint spill and is being qualified. Final combined-head tests, hosted cross-platform CI, shared-process qualification, stamped install and native acceptance remain separate gates. MCP deletion follows the accepted later release rollout gate.
No tag, package/advisory publication, deployment, live inference or provider spend occurred. No release readiness claim.