Skip to content

Harden Cloud decisions and fix recent graph and release regressions - #238

Open
Coding-Dev-Tools wants to merge 14 commits into
mainfrom
codex/review-48h-20260928
Open

Coding-Dev-Tools wants to merge 14 commits into
mainfrom
codex/review-48h-20260928

Conversation

@Coding-Dev-Tools

@Coding-Dev-Tools Coding-Dev-Tools commented Sep 28, 2026 •

Copy link
Copy Markdown
Owner

Cloud decision requests could expose bearer credentials through redirects or ambient loopback proxies, accept malformed advisory responses, and exceed their timeout during slow network operations. This PR validates and pins destinations, rejects redirects and proxy routing for loopback requests, requires explicit non-fallback responses, and shares a single deadline across connection retries, TLS, sends, proxy CONNECT, headers, and body reads. System DNS resolution remains noninterruptible; its elapsed time is charged before the next network phase.

Additional fixes:

  • Paint the final paused graph snapshot even inside the animation throttle interval.
  • Preserve HTTP 413 for streamed oversized read-only requests when FastAPI would otherwise return HTTP 400.
  • Keep older release repairs from replacing a newer GitHub Latest release. Both release-writing jobs retain the shared publication queue.
  • Remove unsupported hosted availability and performance promises, with public metrics bound to immutable v88 evidence.
  • Update the Pi production dependency and test host to address their dependency advisories. CI now audits the full dependency tree, including development packages; the tested host is Pi 0.87.1.

Validation at a498e039d5f5ebdb0eac28a90bcd9d4d3a0e19bf:

  • All 29 GitHub checks pass: CI and CodeQL.
  • Python 3.12: 6,763 passed, 20 skipped. Coverage job: 85.65%, above the 60% gate. Browser suite: 171 passed across Chromium, Firefox, and WebKit.
  • Python 3.9-3.14, encryption, installed journeys, packaging, Docker, offline evaluation gates, lint, type checking, and repository contracts pass in CI.
  • Pi type checking, 21 unit tests including the actual Pi package loader, one local MCP integration test, package dry-run, and the full dependency audit pass; the audit reports zero vulnerabilities.
  • All v88 source bindings remain intact. Historical evidence artifacts are preserved.

Workspace routing and managed Pro/Team Jev access are stacked separately in #239 and #240. This PR does not perform a release, deployment, live-provider qualification, or merge.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T00:03:11.210425Z a498e03 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: aad1e345cd

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread engraphis/backends/jev_decision.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e2883d934b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread engraphis/backends/jev_decision.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a04f166d22

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread engraphis/backends/jev_decision.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 75e6274b28

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread engraphis/backends/jev_decision.py

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: be6195089a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread engraphis/backends/jev_decision.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 2b16d92e7c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread engraphis/backends/jev_decision.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3ccbb58889

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/release.yml

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9cb95f67d6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/release.yml

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1b3c297c05

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/release.yml
Coding-Dev-Tools pushed a commit that referenced this pull request Sep 30, 2026
…advice

Review of the #238 -> #243 stack found three accuracy gaps in behavior that
1.7.9 would ship for the first time:

- `claude-mythos-preview` (and any unversioned Fable/Mythos id) did not match
  the model-trait pattern, so it still received `temperature` and got an
  HTTP 400. Fable/Mythos ids now match with or without a numeric version.
- A remote `verify_completion` probability between the certainty bound (0.75)
  and the 0.85 completion bar was reported as a decisive `is_complete=false`.
  It is now `uncertain` with a null conclusion, matching the documented
  "uncertain completion stays null" contract.
- The local completion heuristic missed Mocha/Jest-style `N passing`, treated
  `errors: none` as a failure, and needed `not passing`/`0 passing` handling
  once `passing` counts as success.

Every new test fails on the previous head. Rebind the public offline fixtures
to immutable v125 evidence; aggregates are unchanged from v124.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014ksPGXPZQTikJYpaGHa6R6

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant