Collector 0.7.43: no false red after a restart, pairing indexes built by a plain update, dispatch tagging, Codex usage filed as Codex
Collector 0.7.43 replaces 0.7.42: no false red after a restart, pairing indexes built by a plain update, dispatch tagging, and Codex usage filed as Codex.
- No false red after a restart (
.163.101). After the collector restarts, an idle Claude source reads amber while its session counts reconcile, then green. 0.7.42 could read red once during that window, about 10 minutes after the restart. A real capture gap still reads red: session files with token activity that never reach the ledger. - A plain update builds the Codex pairing indexes (
.163.100).plimsoll lifecycle updatenow runs the pairing-index step itself, after readiness and before its completion receipt. The step has one 180-second window and retries once if another process holds the ledger. If the ledger is busy, the update still completes and its receipt records the skip with a reason; a later update builds the indexes. The standalonelifecycle pairing-indexes --applystep is unchanged. - Dispatch tagging (
.165.3).plimsoll dispatch bind,closeandrestamptag a dispatched lane's session with its work item, project, attempt and role. Every usage row of that session in the window carries them, including the kept Codex response log row. The paired response span carries none. - Codex usage is filed as Codex (
.163.98).- Codex service names, including
Codex_Desktopandcodex-app-server, are now read as Codex. - A Codex service that sends with a Claude credential gets
401 source_mismatchand must use the Codex source and producer token. A named service the collector does not recognise is stored as unknown, never as Claude Code. - A response span keeps its conversation id when the span carries it, or when exactly one session-bearing event shares its trace in the same export.
- Codex service names, including
- A LaunchAgent that loads without starting is kickstarted once (
.163.91). Coverscapture-roots add,load-launch-agentandupdate. If one kickstart does not bring/statusup, the command fails with a receipt; it never loops. capture-roots discoverlists live-covered homes separately (.163.93). A home that already reports live (Codex's OTLP exporter, or Claude hooks or OTLP) is listed with the evidence by key name only.capture-roots addon such a home warns that the file path will sit beside the live path.
Updating and rolling back:
- Rollback to 0.7.42 is supported. 0.7.42 runs on a ledger and config that 0.7.43 has used: snapshot list and prune, status, the daemon with hook and OTLP intake, export and session sync all passed on a home 0.7.43 had updated (32 of 32 checks). 0.7.42 does not recognise the new pairing-index result in an update receipt, so it keeps both snapshots after such an update; nothing is lost.
- Nothing is received while the collector is stopped. Hook posts and OTLP exports during the stop are not recorded; token usage in session files is captured again after the restart. The first 0.7.43 update on a ledger without pairing indexes also builds them, within its bounded window.
- Check for
source_mismatchafter each update. A Codex producer that has been sending with a Claude credential is refused from 0.7.43 on. Grep the collector log after each host's update, and correct that producer's source header and token.
Runtime CLI SHA256: 19b0fd836967c14bad96c2bb1bb42cdcd2ce2de90f38871ab9284b5257690828.
Qualification: typecheck, the proof suite and system end-to-end qualification ran on the merged commit. The published package is the qualified artifact from that run.