Releases: easyvibecoding/codex-run-budget
Release list
v0.19.9 — Subagent visualization paths
修正
- 修正 SubAgent 圖卡輸出到父 Task 目錄、導致 Desktop 拒絕讀取的問題。經驗證的繼承路徑會自動轉到子代理自己的 UUIDv7 日期目錄。
- 若沙盒拒絕新位置,只嘗試一次子代理工作目錄下的
work/codex-usage-cards,沿用同份用量快照。 - 保留父圖卡、身分檢查與預算執行行為,拒絕跨 Task 路徑、路徑穿越及符號連結。
驗證與使用
490 項測試、隔離安裝與打包 runtime 測試通過;已用本機 Desktop 原始讀檔程式驗證輸出路徑。此項不是 GUI 端到端繪製驗證。
相容的簽署 runtime 更新不改 hook 定義或信任紀錄。請開始新 Task 與子代理使用新版;既有 Task 固定的 runtime 和舊圖卡不會回補。
v0.19.8
Changes
- Check final-answer eligibility before the usage-card command. Exact final output skips both preview and reference.
- Keep ordinary JSON/code/schema file work eligible when the final answer permits a card.
- Append only each agent's own reference on a separate line; do not forward other agents' cards. Emit compact reference JSON without changing the path payload.
- Preserve hook definitions, bootstrap, Task pinning, report identity and budget enforcement.
Validation
- 480 unit tests, Ruff, repository/plugin validators, reproducible artifacts and release signature checks passed.
- GPT-5.6 Sol/Terra/Luna and GPT-6 Astra/Sol/Luna passed all 92 checks each using native Codex CLI 0.157.1 at high reasoning. Each model covered ordinary browser/terminal work with a child, exact JSON and reporting disabled after footer injection.
- The dated validation record preserves baseline and intermediate failures, native read-back criteria, the controlled child-task clarification and scope limits.
- These checks use the configured local v2 catalog and local browser fixtures; they do not establish every reasoning level, authenticated desktop CUA/X workflow or Desktop visualization painting.
Compatible signed runtime: 0d0698b9f61d007264fc69c31ece36bf39c9139bdcfd49afb50cb383acdd3eea.
Existing Tasks retain their pinned runtime; new Tasks select the updated runtime after the signed channel updates.
v0.19.7: Scope usage-card footer instructions
Changes
Automatic usage-card instructions now appear in a delimited footer block. They explicitly preserve the user's ongoing task and scope ownership, quiet skips, card inspection, skills, and retry instructions to that footer.
Parent and subagent cards retain their own preview commands. Budget enforcement, report lifecycle, hook definitions, and existing Task pins are unchanged.
Validation
- 480 tests passed.
- Ruff, repository and plugin validators, deterministic runtime rebuild, release signature verification, and sensitive-data checks passed.
- Independent source and archive review found no behavioral changes outside the footer wording and version.
- Native hook read-back found 12 enabled/trusted hooks.
The revised wording still consumes model context and cannot guarantee that every model avoids distraction. New Tasks use the updated signed runtime; existing Tasks retain their pinned version.
v0.19.6
Fixed
- Persist hashed child revocations after contradictory native parent metadata, including identities without cached requests.
- Reject delayed scans within the same SQLite transaction and recheck revocations before collecting a subtotal. Existing Tasks using an older runtime cannot restore a revoked child's usage in a newer report.
- Reject explicitly contradictory or unknown baseline roles while preserving supported legacy identity evidence.
- Skip Stop observation and descendant collection for unverified identities, keeping their totals unavailable and preserving the original child scope.
- Preserve bounded storage and partial/unavailable accounting without changing budget decisions or hook definitions.
- Close the readonly quota timing-index connection on normal and early-return paths.
This compatible signed update applies to new Tasks. Existing Tasks keep their pinned runtime. See docs/VALIDATION.md for the exact installed-runtime checks and remaining Desktop rendering limit.
v0.19.5: Verified child lineage and report scope
Fixes
- Reject conflicting child-parent metadata and revoke affected cached request usage.
- Bind child reports to their original root and role across preview, Stop and completion reconciliation; missing historical proof stays unavailable.
- Show child own usage, descendant subtotals, direct parent and a matching selector in cards and receipts, with all nine report languages aligned.
Verification
- 466 local tests, Ruff, repository/plugin validation and sensitive-data checks passed.
- CI passed on Python 3.10, 3.11, 3.12 and 3.13.
- An isolated real Codex parent/child run verified both previews, Stop and completion receipts, matching selectors and saved root/parent proof.
- All 12 hook definitions and native trust hashes are unchanged. Existing Tasks remain pinned; new Tasks use the updated compatible runtime. Desktop painting was not observed.
Commit: 8a33d5a
v0.19.4 — Child-agent reports linked to parent Tasks
Child-agent reports linked to the parent Task
- Child agents can create their own turn preview and Stop receipt. The parent report keeps a separate, deduplicated descendant subtotal; both sides show the same hashed
@selector, including nested agents. - Native catalog lineage and child-owned transcript boundaries exclude shared-session ambiguity and copied parent history. Missing evidence remains partial or unknown.
- Concurrent report starts share a bounded SQLite wait deadline below the native hook timeout. A deterministic eight-Task contention test retained all starts; a two-lock test verifies that schema and preflight waits share the same deadline.
- Budget enforcement and the existing 12 native hook definitions are unchanged. Compatible signed updates retain reviewed trust hashes; existing Tasks stay pinned to their prior runtime.
- An isolated real Codex CLI turn generated a child preview file and inline reference, with matching parent/child selectors. Its parent recorded 47,523 own tokens and 36,391 descendant tokens separately. This does not verify Desktop card painting.
Validation: 449 local tests, Ruff, repository/plugin validation, staged sensitive-data scan, signed-release verification, and isolated installed-hook read-back. Test cleanup now waits for detached report readers and checks real process termination. See docs/VALIDATION.md.
Signed runtime SHA-256: c33221e03a94278a9245ba86d592e876d8a9f6ce67760ee755618f48d84def61.
v0.19.2 — Experimental multi-project pairing
Experimental cross-project pairing
- Register multiple named pairs of exact local Codex project roots. Each pair has separate remote-main cursors, pending reviews, and one-to-one Task bindings; a project can belong to several pairs.
- The feature has a global switch and per-pair switches. Fresh named pairs start disabled; an existing configured pair retains its state as
default. - Stop checks are mechanical and have no timed model polling. A change can be reviewed in the bound counterpart Task, with short Stop summaries and an echo guard.
- Updated setup, recovery, and the shared Run Budget–Usage Reports review contract. A live Codex test covered a forward review, a bound relay, and a reverse review; multi-pair fan-out and disabled switches were verified with local tests.
- Scoped the pre-push sensitive-data audit to refs being pushed. CI continues to audit all reachable repository history.
Signed runtime SHA-256: 4909b41f1076803d448b1d4e0f62911331617076d6679bb2a5637685f8422a64.
v0.19.1 — Paired Task Stop reviews
Project-scoped paired Task reviews
- Replaced the ten-minute heartbeat and local periodic scanner with a trusted
Stophook for the two configured Git projects. No timed model polling remains. - A source change opens one native review Task in the other Codex project and binds the two Tasks one-to-one. Later Stop summaries use
send_message_to_threadto reach that same counterpart. - Added hashed Task bindings, exact SHA cursors, reserved sends, and an echo guard so relayed messages do not create a Task loop. Uncertain sends remain held for inspection.
- Kept manual remote scans for changes that occur outside a paired Task. Updated the shared review contract and setup guide.
The hook itself makes no network or model call. A paired Task can use one event-driven model continuation to create its counterpart or send a summary. Existing Tasks stay pinned to their signed runtime; new Tasks use the active 0.19.1 runtime.
v0.19.0 — Paired repository change reviews
Paired repository change reviews
- Added an opt-in local scanner that records exact remote
mainchanges for Codex Run Budget and Codex Usage Reports in a private, crash-safe review queue. - Added a shared cross-repository decision contract. Codex App automation can open a review Task in the other project; the scanner alone does not create Tasks or copy code.
- Kept the two plugins independent. Usage Reports remains report-only, while Run Budget retains budget governance.
- Updated the documentation index and setup/recovery guide, and included the new coordinator in the signed 0.19.0 runtime.
The scanner requires an awake Mac and the separate Codex App heartbeat for Task dispatch. See docs/PAIRED_REVIEW_AUTOMATION.md before enabling it.
v0.18.0 — Cache observations for Task reports
Cache observations in Task reports
- Added per-window cache-read share, cached-input request counts, and ordered same-Task model, reasoning-effort, and service-tier change counts to JSON, Markdown, and HTML reports.
- Preserved unknown states when settings are missing or request timestamps tie. Local observations do not diagnose server-side cache misses or estimate subscription savings.
- Kept the existing signed bootstrap and native hook definitions unchanged so compatible updates retain their established trust boundary.
The signed runtime is version 0.18.0. See CHANGELOG.md and docs/REPORTS.md for details.