Skip to content

codex-plugin-cc v1.3.0

Choose a tag to compare

@CBEPX CBEPX released this 27 Sep 21:34
· 156 commits to main since this release
78576a5

Lifecycle correctness: turns that no longer hang, kills that only ever hit the process they were meant for, and a stop gate you can pin.

Highlights

  • Terminal error notifications end the turn as failed instead of hanging; retried errors keep it running; a subagent's error no longer fails the main turn (openai#698, openai#757, openai#775, openai#781).
  • Broker lifecycle: bounded connects with ETIMEDOUT fallback, wedged-broker replacement with a 2 s readiness retry, no signal to a stale or recycled pid, freshly spawned brokers that never become ready are killed as a process group (openai#753, openai#762, openai#768, openai#749, openai#773, openai#782).
  • Identity-checked kills and reaping on posix (openai#743): pidIdentity in job records, JSON pid sidecars (legacy integer still read) and broker.json; cancel keeps a job running and says so when the kill could not be confirmed; SessionEnd keeps records of workers it did not stop.
  • status <id> --wait exits 1 and prints a timeout line when the wait times out (openai#774).
  • Stop gate: setup --review-gate-model <model|inherit> --review-gate-effort <effort|inherit>, default of 3 gate-induced rounds (CODEX_REVIEW_GATE_MAX_ROUNDS=0 restores unbounded), signal name and /codex:setup --disable-review-gate hint in every infrastructure failure reason, hooks.json without a top-level description (openai#769, openai#548, openai#589, openai#483, openai#459).
  • Transfer honours CLAUDE_CONFIG_DIR (openai#721).
  • Model aliases resolve against the local Codex catalogue ($CODEX_HOME/models_cache.json, then codex debug models --bundled), astra alias, effort validated per model (openai#468, openai#703, openai#485).
  • Security: fallback state root is per-user (0700) and per-plugin, symlinked roots refused; broker.json validated before use (openai#521, openai#609).

Compatibility

  • status --wait now exits 1 on timeout (also with --json; the snapshot keeps waitTimedOut).
  • CODEX_REVIEW_GATE_MAX_ROUNDS unset now means 3 rounds (was unbounded).
  • Pid sidecars jobs/<id>.pid are JSON; v1.2.x integer sidecars and records without pidIdentity still work on posix.
  • Windows: kills from stored records (cancel worker, SessionEnd cleanup, stale-broker replacement, broker teardown) are refused until process identity lands in v1.4.0; leaks are bounded by the broker idle timeout and the turn interrupt is still sent.
  • Fallback state under os.tmpdir() (only when CLAUDE_PLUGIN_DATA is unset) is keyed by plugin install path and is not carried over across plugin updates.

Validation

  • Exact tag target: 78576a5d376524d347e79a46fea7543332f7da3b
  • Local gate: 313/313 tests, 0 leaked test processes, npm run build, npm run check-version, claude plugin validate . --strict
  • GitHub CI: https://github.com/CBEPX/codex-plugin-cc/actions/runs/36351327223
  • Review: Codex adversarial review (five passes, final verdict: ship), Claude whole-branch review (with fixes, all addressed)
  • Runtime dependency audit: npm audit --omit=dev reports 0 vulnerabilities

Artifact

78e98e2296c9ab2d2cded2798e86f518e5dea7c9252a48641a87d738921f9550 cbepx-codex-plugin-cc-1.3.0.tgz