Repository navigation
Releases: OxygenAILab/KeepMyConfig
Release list
KeepMyConfig v26.0-Alpha.7
KeepMyConfig v26.0-Alpha.7
Completes CC Switch recovery: ccswitch recover now merges the union of every valid source instead of picking one.
Changed
- All Codex provider configs are layered richest-first (the richest wins conflicts), plus a synthetic
CC Switch MCP registrydocument built frommcp_serversrows withenabled_codex = 1. --provider NAMErestricts provider configs to the named one and still adds the MCP registry.- Reports list the merged sources.
Why
Once ccswitch adopt stores user MCP servers in CC Switch's own table, provider config text alone cannot rebuild them. Recovery must read both sources.
Verified
- Regression test seeds a registry-only MCP (
cu_bridge) and proves recovery restores it together with provider-text entries (prima-mock-api, plugin, desktop). - 37 tests passing;
clippy -D warningsandfmt --checkclean; CI green on Windows and Linux for commit 9371447.
Build
- Commit: 9371447
- Target:
x86_64-pc-windows-msvc, Rust stable - Crate version:
0.1.0-alpha.7 - Asset:
keepmyconfig-x86_64-pc-windows-msvc.zip
Alpha notice: CLI flags and policy defaults may change before v26.0. CC Switch database writes remain opt-in (
--apply), dry-run by default, and always preceded by a backup.
KeepMyConfig v26.0-Alpha.6
KeepMyConfig v26.0-Alpha.6
Adds a third recovery source, asset-snapshot coverage, and a launcher that survives the installing session.
Added
ccswitch recover [--provider NAME] [--db FILE] [--apply]: scans the Codex provider configs stored in CC Switch, picks the one protecting the most user-owned paths (current provider wins ties), merges it withoverlay_wins, and takes apre-recoverbackup. Dry-run by default.- Asset-coverage tracking:
backuprecords the snapshot instate.json;statusprints it anddoctorwarns when no snapshot exists or the newest is older than 30 days.
Fixed
- The immediate Startup helper now survives the installer session. It is launched through the WMI service (
Invoke-CimMethod Win32_Process Create) with a hidden VBS window, so it is not a member of the caller's job object. The previouscmd /C starthelper was reaped when the installing session ended.
Verified
- 37 tests passing (18 core unit + 13 workflow + 3 CLI + 3 autostart);
clippy -D warningsandfmt --checkclean. - CI green on Windows and Linux for commit a84c3af.
- Machine verification: WMI-launched hidden loop alive across command sessions; first hardlink asset snapshot covers skills and plugins.
Build
- Commit: a84c3af
- Target:
x86_64-pc-windows-msvc, Rust stable - Crate version:
0.1.0-alpha.6 - Asset:
keepmyconfig-x86_64-pc-windows-msvc.zip
Alpha notice: CLI flags and policy defaults may change before v26.0. CC Switch database writes remain opt-in (
--apply), dry-run by default, and always preceded by a backup.
KeepMyConfig v26.0-Alpha.5
KeepMyConfig v26.0-Alpha.5
Makes self-healing protection actually installable on hosts that deny Task Scheduler creation for non-elevated sessions.
Fixed
autostart installno longer fails withAccess is deniedfromschtasks /Create /SC ONLOGON.--method autonow falls back to a Startup-folder loop script that runswatch --once --quietevery N minutes (5 by default), so protection survives logons and app updates without administrator rights.- The immediate watch helper starts fully detached (
Stdio::null,DETACHED_PROCESS | CREATE_NEW_PROCESS_GROUP), so the install command returns cleanly instead of hanging on inherited pipes.
Added
autostart install --method auto|task|startup.- Startup-script state in
autostart statusanddoctor.
Verified on the affected machine
- Fallback script installed at
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\KeepMyConfig.cmd. - Detached watch daemon running; store journal records
watch_start. watch --once --quietexits 0;doctorreports protection ok and autostart ok.ccswitch adopt --apply --forceapplied: 3/3 Codex providers merge the common config, 4 codex MCP entries enabled, database backup recorded.
Build
- Commit: 156e24e
- Target:
x86_64-pc-windows-msvc, Rust stable - Crate version:
0.1.0-alpha.5 - Asset:
keepmyconfig-x86_64-pc-windows-msvc.zip
Upgrade
Replace keepmyconfig.exe, then run:
keepmyconfig status
keepmyconfig autostart installAlpha notice: CLI flags and policy defaults may change before v26.0. CC Switch database writes remain opt-in (
--apply), dry-run by default, and always preceded by a backup.
KeepMyConfig v26.0-Alpha.4
KeepMyConfig v26.0-Alpha.4
Fixes the failure that followed the Codex 0.147 update and makes protection survive future updates and reboots.
Root causes found
- No persistence. The manually started
watchprocess did not survive the update/reboot; neither the Startup folder nor Task Scheduler had a KeepMyConfig entry, so the 03:09 rewrite ofconfig.tomlwent unnoticed. - Detection blind spot. The Codex updater preserved
model/model_provider, so the diff scored 3 against the balanced threshold of 4 (12 protected paths removed, one new app key added) and would have been treated as a user edit.
Added
autostart install|status|uninstall(Windows): registersKeepMyConfig-Watch(logon daemon) andKeepMyConfig-Check(periodic one-shot repair, 5-minute default) with the current-user Task Scheduler and starts both immediately.doctornow reports autostart state.- Codex-update-aware detection: a changed
BROWSER_USE_CODEX_APP_VERSIONplus protected removals forces a clobber; removing 3+ completemcp_servers/plugins/marketplaces/projectsentries adds clobber weight.
Verified
- Real incident replay with the actual damaged backup:
Clobberscore 6 with 7 complete entries removed and app version26.930.31428 -> 26.930.31730;watch --oncerestored all 12 paths and kept the new app build. - 33 tests passing (18 core unit + 11 workflow + 3 CLI + 1 autostart);
clippy -D warningsandfmt --checkclean. - CI green on Windows and Linux for commit 98782b6.
Build
- Commit: 98782b6
- Target:
x86_64-pc-windows-msvc, Rust stable - Crate version:
0.1.0-alpha.4 - Asset:
keepmyconfig-x86_64-pc-windows-msvc.zip
Upgrade
Replace keepmyconfig.exe, then run:
keepmyconfig status
keepmyconfig autostart installAlpha notice: CLI flags and policy defaults may change before v26.0. CC Switch database writes remain opt-in (
--apply), dry-run by default, and always preceded by a backup.
KeepMyConfig v26.0-Alpha.3
Windows x86_64 pre-release build of KeepMyConfig.
Fixed
-
notifyis no longer captured into the protected overlay. The Codex desktop app
rewrites it with a version-scoped runtime path (runtimes\cua_node\<hash>\...), so
any copy captured before an app update is stale. The explicitrepaircommand runs
withmanual = trueand merges without requiring a clobber fingerprint, which meant
statusreporting a benignEdit(score 1, threshold 4) still led to arepair
that silently rewrotenotifyback to a runtime directory that no longer exists —
breaking theturn-endedComputer Use hook.notifynow sits in the default
ignoredset alongsidemcp_servers.node_repl, which shares the same lifecycle. -
ccswitch adoptno longer publishesnotifyinto CC Switch'scommon_config_codex.
Publishing a version-scoped runtime path there would have injected a stale path into
every future provider switch.
Behaviour change
After a CC Switch clobber, notify is no longer restored from the overlay: it is left to
the Codex app that owns it. The failure mode changes from silently pointing at a deleted
runtime indefinitely to briefly missing and self-healed by the app. If you maintain
notify by hand, remove it from ignored in policy.toml to protect it again.
Evidence
Recorded reproduction against the previous build (isolated CODEX_HOME):
| step | value |
|---|---|
baseline notify |
runtime 2134bcb1950af07e |
live notify after app update |
runtime 81ea4d5168ddd0a3 |
repair |
overwritten notify |
| result | stale runtime 2134bcb1950af07e restored (directory no longer exists) |
After the fix the same scenario reports NoChange and repair performs no action.
Verification
cargo fmt --all -- --check -> pass
cargo clippy --workspace --all-targets -D warnings -> pass
cargo test --workspace -> 27 passed / 0 failed
Install
Download keepmyconfig-x86_64-pc-windows-msvc.zip, extract keepmyconfig.exe, and put it
on your PATH. auth.json is never merged or restored automatically.
This is a pre-release; the Windows artifact is the primary platform.
KeepMyConfig v26.0-Alpha.2
KeepMyConfig v26.0-Alpha.2
Supersedes v26.0-Alpha.1. The Windows binary is functionally identical for the primary platform; this release fixes cross-platform manifest path validation so the Linux CI leg (and any Unix use) is correct and green.
Fixed
- Manifest restore path validation is now platform-independent: POSIX absolute paths, Windows drive-letter prefixes, UNC paths, NUL bytes, empty segments,
.and..are rejected before any write, on every host OS.
Verified
- CI matrix green:
test (windows-latest)success andtest (ubuntu-latest)success on commit 23e5b04. cargo test --workspace: 26 tests passing (14 unit + 9 workflow + 3 CLI).cargo fmt --checkandclippy -D warningsclean.- Real-data clobber rehearsal remains valid: score 7 detection, 26 protected paths restored, provider
modelpreserved.
Build
- Commit: 23e5b04
- Target:
x86_64-pc-windows-msvc, Rust stable 1.95.0 - Asset:
keepmyconfig-x86_64-pc-windows-msvc.zip - Crate version:
0.1.0-alpha.2
Install
Unzip, put keepmyconfig.exe on PATH, then run keepmyconfig init and keepmyconfig watch.
Alpha notice: CLI flags, policy defaults, and the CC Switch database integration may change before v26.0. Database writes remain opt-in (
--apply) and are always preceded by a backup.
KeepMyConfig v26.0-Alpha.1
Superseded by v26.0-Alpha.2. v26.0-Alpha.1 passed Windows CI but failed the Linux matrix due to a path-validation bug that is fixed in Alpha.2.
KeepMyConfig v26.0-Alpha.1
First pre-release. Protects user-owned Codex configuration (settings, MCP servers, plugins/marketplaces, skills) from whole-file rewrites performed by CC Switch provider switches and MCP sync.
Highlights
- Baseline/overlay engine built on
toml_editwith a configurable policy (managed,ignored, merge mode). - Explainable clobber detection plus
watch/repairwith pre-repair backups, a store lock, and a JSONL journal. capture --from FILErecovery for configurations that were already lost.- Asset backup/restore for
skills/,plugins/,prompts/,rules/;auth.jsonis backup-only. - Opt-in CC Switch database integration (
ccswitch adopt): dry-run by default, consistent SQLite backup, one transaction.
Verified
- CC Switch v3.20.4 provider-switch and MCP-sync paths reviewed from source; mechanisms recorded in
.devdocs/DESIGN.md. - Real-data sandbox: 26 protected paths restored, provider
modelpreserved,status --checkreturns 0 afterwards. cargo test --workspace: 26 tests passing;clippy -D warningsclean;cargo fmt --checkclean.
Build
- Commit: 44758c4
- Target:
x86_64-pc-windows-msvc, Rust stable 1.95.0 - Asset:
keepmyconfig-x86_64-pc-windows-msvc.zip
Install
Unzip, put keepmyconfig.exe on PATH, then run keepmyconfig init and keepmyconfig watch.
Alpha notice: this is a pre-release; CLI flags, policy defaults, and the CC Switch database integration may change before v26.0. Database writes are opt-in (
--apply) and always preceded by a backup.