Skip to content

Releases: lidge-jun/codexclaw

codexclaw v0.2.40

Choose a tag to compare

@github-actions github-actions released this 29 Sep 19:27
3c1459a

[0.2.40] - 2026-09-29

Added

  • Codex Desktop sometimes starts threads created by create_thread with on-request approvals even when the user's config is full access (openai/codex #33282). A SessionStart advisory now tells the model and the user when an agent-created thread starts that way. An opt-in PermissionRequest hook (permissions.agentCreatedThreadAutoAllow: true in ~/.codexclaw/config.json, off by default) answers those threads' approval prompts, including one-time network requests, only when the user's top-level config.toml sets approval_policy = "never" and sandbox_mode = "danger-full-access"; it never changes the thread's sandbox, never denies, and ignores project-local config. Two new hooks (31 total) need trust approval after upgrade.
  • Dispatch guidance: for bounded worktree lanes a full-access coordinator can create a managed worktree and hand a subagent that path as its shell workdir, which keeps the coordinator's permission; workers may keep an optional PROGRESS.md checkpoint so a replacement can resume from files (#265, guidance only).
  • CODEXCLAW_PABCD=off (or on) and project codexclaw.json {"pabcd": {"enabled": false}} turn the PABCD hook policy off while keeping the worktree, memory-write, automation-ownership and apply_patch lint guards and recall active. A recognized environment value wins over the project file in both directions (#252).
  • When codexclaw creates a project's .codexclaw folder, it also writes .codexclaw/.gitignore so session state, ledgers and evidence stay out of git; user-authored rules/*.md stay committable unless an ancestor ignore rule hides the folder. Existing .codexclaw folders are never modified. Lazy creation of session state is deferred (#255, partial).
  • Dispatch packets can declare each verifier's write effects (verifierEffects), and a pure verifierPreflight(packet) reports which verifiers need an isolated copy: under a shared-read packet only a verifier declared read-only runs in the shared tree. Nothing executes a command (#277).
  • Interview assumptions carry their source, confidence, consequence if wrong and a status (proposed, open, user_confirmed, user_rejected); confirmed and rejected entries need an answer reference, and the plan keeps open assumptions apart from confirmed requirements and rejected ones (INTERVIEW-ASSUME-01, guidance only, #275).

Changed

  • Goalplans can record pending user decisions: cxc loop ask --session <id> --id <q> --question <text> [--recommendation <text>] [--work-phase <id>]... links a question the agent already asked to the phases that wait on it, and cxc loop decide --session <id> --id <q> --answer <text> records the answer. Linked phases are not runnable while the decision is open; unrelated phases stay ready. When every remaining phase and unmet criterion waits on an open decision, the Stop hook lets an IDLE turn end instead of asking to start another phase; the goal stays active and cannot be completed early. Old plans load unchanged (#262). cxc loop ask also takes a repeatable --option <text>; when options are given the recommendation must be one of them, the answer stays free text, and ready --json and show list them.
  • The absolute Stop continuation cap (24) now counts per genuine user turn instead of per session, and the release prints one notice per turn (#254).

Fixed

  • A dispatch receipt satisfies its packet only when every required verifier command has a matching result with exit 0 and, when commands are required, no result names another command. Receipts can report verifierResults[]; a single legacy verifierResult for a multi-command packet reports incomplete (#276).
  • Ordinary words (for example "interview", "keep going until", "끝까지 진행해", quoted or fenced examples) no longer inject PABCD phase directives or arm the loop; hints need an explicit codexclaw request such as cxc-pabcd or cxc-loop (#250).
  • The SubagentStop evidence gate no longer blocks Codex's built-in worker outside an active PABCD build or check cycle; registered executor stays gated while PABCD is on (#251).
  • An active native goal without a bound goalplan no longer blocks Stop at IDLE (#253).

Compatibility

  • receiptSatisfiesPacket is stricter (#276): a receipt whose one result names a different command than the packet's, even cosmetically (npm run test vs npm test), no longer satisfies; extra passing checks belong in commandsRun. validateReceipt now checks the verifier result shapes and validatePacket rejects blank or non-string verifier commands.
  • Builds older than 0.2.40 drop a goalplan decision's options if they rewrite the plan; no schema-version bump signals the new key.
  • The two hooks added in this release (31 total) need trust approval after upgrade.

Verification

  • 3737 tests, 0 failures (npm test); gate.mjs, inventory and platform-smoke.mjs pass. Hosted CI and the packed-install lifecycle passed on every merged pull request (#269-#272, #278-#280).

What's Changed

  • Record 0.2.39 delivery evidence by @lidge-jun in #249
  • Hook runtime fixes: explicit PABCD triggers, worker gate, idle goals, per-turn Stop cap, PABCD switch, .codexclaw/.gitignore by @lidge-jun in #269
  • Agent-created thread permission advisory and opt-in PermissionRequest hook by @lidge-jun in #270
  • Goalplan pending decisions: cxc loop ask/decide and decision-aware readiness (#262) by @lidge-jun in #271
  • docs(plan): issue train 0927 delivery record by @lidge-jun in #272
  • Dispatch receipts require a matching verifier result per command; optional verifier effects preflight (#276, #277) by @lidge-jun in #278
  • Interview: separate inferred assumptions from confirmed requirements at handoff (#275) by @lidge-jun in #279
  • Goalplan decisions record offered options; recommendation must be one of them (#262 follow-up) by @lidge-jun in #280
  • Release codexclaw 0.2.40 (version bump and CHANGELOG) by @lidge-jun in #281
  • Release codexclaw 0.2.40 by @lidge-jun in #282

Full Changelog: v0.2.39...v0.2.40

codexclaw v0.2.39

Choose a tag to compare

@github-actions github-actions released this 24 Sep 09:23
8e6aa80

[0.2.39] - 2026-09-24

Added

  • SessionStart injects a subagent dispatch card. When the collab family is unresolved,
    it gives one Code Mode cell that finds the unique spawn_agent helper, identifies V1
    or V2 from companion tools and spawns (V2 with task_name and fork_turns: "none"),
    stopping before any call if the helper or family is ambiguous. CODEXCLAW_SPAWN_V1=1
    prints the exact tools.multi_agent_v1__* calls as an override. A dated alias map
    (deepseek, swe2, kimi, sol, luna) is marked verified or unverified against the local
    Codex catalog; full model ids pass through unchanged (#243).
  • subagents_get returns spawnArgs per role and staleModel (true, false or null
    with a staleReason) from a catalog read bounded to 5 s (#243).

Fixed

  • The subagent-config MCP stdio server handles requests in order and finishes queued
    replies before exiting at stdin EOF.

Compatibility

  • subagents_get may take up to 5 s longer while it probes the catalog. The response
    envelope is unchanged; it only gains fields.

Verification

  • 3,609 tests measured locally on macOS; the release run and hosted CI remeasure them.
  • The card's resolver cell, run verbatim in a V1 Code Mode session, spawned the
    DeepSeek alias in one cell. V2 is covered by a tool harness only.

What's Changed

  • SessionStart subagent dispatch card and spawn-ready role args (0.2.39) by @lidge-jun in #246
  • Release codexclaw 0.2.39 by @lidge-jun in #248

Full Changelog: v0.2.38...v0.2.39

codexclaw v0.2.38

Choose a tag to compare

@github-actions github-actions released this 24 Sep 07:41
92d26a6

[0.2.38] - 2026-09-24

This is the first published release that contains the 0.2.37 changes: the native
desktop acceptance guidance, the macOS system approvals reference and the desktop
criterion surface. 0.2.37 was prepared on main but never published; its section below
still describes those changes.

Fixed

  • The paged-report exporter accepts a complete staged PDF from a headless Chrome that
    writes the file but never exits. It waits until the stage keeps a %PDF- header, a
    %%EOF trailer and an unchanged size and mtime for 1.5 s, kills the owned process
    tree, and counts the pass only when that kill caused the exit and the stage did not
    change. A child that survives the post-kill grace fails the pass without keeping the
    exporter alive. The text summary now prints each FAIL, BLOCKED and NOT_RUN reason (#240).

Added

  • Paged-report QA warns (P2) when a non-Korean document keeps Hangul or a Korean-format
    date in @page content, and reports an SVG label crossed by a connector painted
    after it (P2), using a bounded DOM pass on the final HTML. A failure of that pass is a
    nonblocking note (#241).
  • QA validates artifact-identity.json for desktop artifact verdicts (bundle tree
    digest, executable, archive, signing, toolchain and goalplan criterionIds) and binds
    those files into a typed artifactManifest in the QA receipt. A schemaVersion 2+
    final gate requires an identity entry for each non-native desktop criterion (#239).
  • cxc loop add-criterion --surface desktop --presented native marks a criterion
    proven by inspecting a native surface. At Check it gets a soft, fail-open advisory
    that clears on an explicit native app observation or a viewed declared screenshot (#239).
  • skills/dev-devops/scripts/verify-lipo-command.mjs judges a candidate lipo command
    by running it against the artifact and a verified thin negative control (#239).

Changed

  • cxc loop and cxc goalplan validate flags per verb. Unknown, misspelled and
    misplaced flags (including --surface outside add-criterion), stray positionals,
    missing values and repeated singleton flags fail before anything is written. Every
    value flag also accepts --flag=value (#239).
  • The paged-report template sizes its contents label column from content, marks the
    running-header literals for translation, and draws chart grid lines before labels.
    DIAGRAM-LAYOUT-01 states that labels paint after the lines they sit on (#241).

Compatibility

  • Scripts that passed a flag a verb ignored, or a space-separated value starting with
    --, now fail; use the verb's own flags and --flag=value.
  • On schemaVersion 2+ plans with a recorded final gate, a QA receipt from 0.2.37 or
    older has no artifactManifest and fails the gate while a non-native desktop
    criterion exists. Default v1 plans are unaffected.
  • Builds older than 0.2.38 drop presented on read and erase it on their next write.

Decided

  • #191: codexclaw does not override the native memory quota guard from a detect-only
    routing signal. The decision and the upstream boundary are recorded in
    devlog/_plan/260924_issue_sweep_0238/003_issue_191_decision.md.

Verification

  • 3,599 tests measured locally on macOS; the release run and hosted CI remeasure them.
  • Independent plan audits and implementation reviews for every work phase; real
    Chrome and real macOS lipo smoke runs locally.

What's Changed

  • Record 0.2.36 delivery evidence and activation gap by @lidge-jun in #236
  • Add native desktop acceptance guidance and a desktop criterion surface by @lidge-jun in #237
  • Release codexclaw 0.2.37 by @lidge-jun in #238
  • Issue sweep: PDF export completion, paged report QA, desktop evidence (0.2.38) by @lidge-jun in #242
  • Keep the extended-length cwd test valid on Node 24.21 by @lidge-jun in #245
  • Release codexclaw 0.2.38 by @lidge-jun in #244

Full Changelog: v0.2.36...v0.2.38

codexclaw v0.2.36

Choose a tag to compare

@github-actions github-actions released this 22 Sep 14:07
e42ca5d

[0.2.36] - 2026-09-22

Added

  • Metadata-only hook invocation observations, separated from stored trust in doctor,
    with session/actor and payload freshness checks. Invocation does not imply handler success.
  • A scoped heartbeat ownership guard for native automation tool calls. Foreign,
    ambiguous and child mutations are denied; views remain available. Host-wide
    atomic ownership enforcement remains outside this plugin's coverage (#213).
  • Explicit pending lane packets retain provisional creation evidence and refuse
    guessed canonical addresses. Native clientThreadId resolution remains open (#209).

Fixed

  • Lane packet CLI option ordering, missing values and conflicting modes are rejected
    consistently. Legacy dispatch/bound packets remain supported.
  • Memory status identifies its jobs-DB observation scope and leaves effective extraction
    routing and startup guard decisions explicitly unknown (#191). No quota bypass is applied.
  • Integration tests isolate native Codex homes as well as Codexclaw state.

Verification

  • 3,522 tests measured locally, 3,519 passed, three platform/environment skips,
    zero failures. Independent design and implementation reviews completed.
  • Installed hook activation and host-boundary fixes remain separate from unit-test proof.

What's Changed

  • fix(delegation): allow logical architect consultation on v1 by @lidge-jun in #228
  • [agent] Complete shared visualizer contracts with proportional verification by @lidge-jun in #229
  • [agent] Prepare codexclaw 0.2.35 release by @lidge-jun in #230
  • Release codexclaw 0.2.35 by @lidge-jun in #231
  • Add hook invocation diagnostics and task ownership safeguards by @lidge-jun in #233
  • Release codexclaw 0.2.36 by @lidge-jun in #234

Full Changelog: v0.2.34...v0.2.36

codexclaw v0.2.34

Choose a tag to compare

@github-actions github-actions released this 20 Sep 11:50
1914fb6

[0.2.34] - 2026-09-20

Visual verification now costs what the artifact can actually lose.

Changed

  • cxc-dev-visualizer replaces the flat render obligation with VIZ-VERIFY-SCALE-01,
    four tiers keyed to how the artifact can fail. An inline visual or a host-rendered
    diagram ships after rereading its source, and so does a small static HTML/SVG page in
    ordinary flow with no runtime data, library or export. A computed result — marks drawn
    from data, connector geometry derived from rendered bounds, a runtime library or
    webfont, an input that changes the output — still earns the full pass, and so does
    anything that leaves the conversation as a file. DIAGRAM-RENDER-VERIFY-01 keeps its
    ID and procedure and now names the tiers that call for it.
  • Two invariants keep the relief honest: an unrun check is never written up as a passed
    one, and a reported or observed defect promotes the artifact to the rendered tier for
    every further fix.
  • DIAGRAM-A11Y-01 splits the same way. The composition decisions — names, heading
    order, text alternatives, non-color meaning, contrast, reduced motion — still apply to
    the smallest inline visual; only the separate inspection pass moves to the tiers that
    already render.

What's Changed

  • Release 0.2.34 - proportional visualizer verification by @lidge-jun in #227

Full Changelog: v0.2.33...v0.2.34

codexclaw v0.2.33

Choose a tag to compare

@github-actions github-actions released this 19 Sep 19:58
5e4743d

[0.2.33] - 2026-09-20

A dispatched lane may now run its own loop, and the packet that says so is checkable.

Added

  • cxc-loop gains references/lane-dispatch.md: the packet a coordinator hands a lane,
    the separate merge grant, and the measured host envelope. LANE-LOOP-AUTH-01 — a leaf
    never opens a goal, a dispatched task owns one and loops when its packet grants the
    objective, criteria and completion condition. LANE-PACKET-01 — the create_thread
    prompt is the entire channel, so a packet carries scope, base, branch, authority and
    reporting. LANE-MERGE-GRANT-01 — merge is a separate sentence and may only land the
    lane's own branch.
  • scripts/check-lane-packet.mjs decides those cases instead of asserting prose: a loop
    without criteria, a merge without its grant, a merge naming another lane's branch, a
    provisional id used as an address, push/PR authority, and write scopes that overlap
    across a packet set after . and .. are normalized. Packets have declared
    dispatch and bound modes, because a packet cannot carry an address that creation
    has not returned yet.
  • scripts/check-host-bounds.mjs plus test/fixtures/host-thread-bounds.json record the
    measured surface — wait_threads 1-8 targets and 0-120000 ms, read_thread 1-10 turns
    and 0-20000 chars, list_threads 1-50, get_handoff_status 0-60000 ms, worktree
    retention 15, the default six-subagent session cap — and re-derive each from app.asar
    and the codex-rs sources. An absent artifact reports NOT RUN and never PASS.
  • dispatch-surfaces.md gains DISPATCH-FANOUT-CAP-01: branches are the cheap axis — no
    host-wide task cap was found — while subagents fail outright past six per session.

Changed

  • cxc-loop scopes its leaf rule to leaves and states the lane case positively. The old
    wording read as universal and left a dispatched task with no permission to run its own
    cycle, which is why one session did all the looping.

Known limitations

  • The validator enforces packets; it does not police the skill text. Deleting the prose
    authorization fails no test, and closing that would mean enforcing the packet at the
    orchestration boundary.
  • Measured absences are recorded as absences: no cap was found on referenced tasks and no
    model-visible resolver was found for a queued lane's clientThreadId (#209).

What's Changed

Full Changelog: v0.2.32...v0.2.33

codexclaw v0.2.32

Choose a tag to compare

@github-actions github-actions released this 19 Sep 17:04
30774a1

[0.2.32] - 2026-09-20

Verification depth becomes a choice, and the visualizer says where it came from.

Changed

  • The report receipt is an assurance level the caller states, not a fixed tax on
    every document. scripts/quality-gate.mjs takes a profile: draft requires
    nothing, standard requires pdf-parse, text-integrity and pagination,
    and publication keeps all seven checks. Pass it as --profile or as
    "profile" in the receipt; the argument wins. An unnamed profile stays
    publication, and an unknown name fails rather than falling back to something
    cheaper. A lighter profile reduces what is required and never invents a pass —
    the result carries its profile and an omitted list naming every publication
    check that did not complete, and a FAIL or REVIEW finding still propagates from a
    check outside the profile (REPORT-ASSURANCE-01, 11 tests).

Documentation

  • dev-visualizer records its origin and its limits. The standalone
    aside-visualizer repository stays Aside's own; codexclaw keeps the ported skill
    rather than running that roadmap or holding a second copy of it. VIZ-SCOPE-01: the
    skill builds and verifies the artifact its calling task asked for and does not open
    repositories of its own, install itself, publish or export unasked, or start its own
    loop. The three READMEs carry the same boundary and stop advertising the retired
    dev-diagram-viewer name.

What's Changed

Full Changelog: v0.2.31...v0.2.32

codexclaw v0.2.31

Choose a tag to compare

@github-actions github-actions released this 19 Sep 11:48
658ef50

[0.2.31] - 2026-09-19

Closes the last two issues from the 2026-09-19 sweep.

Added

  • The publication contract foundation is back in the skill:
    reference/report-pipeline.md, reference/page-role-catalog.md,
    scripts/report-contract.mjs, scripts/quality-gate.mjs and
    assets/report-model.example.json, with 41 tests. Recovered as a purely additive
    change: the exporter imports none of it, so no runtime path moved. The exporter
    migration stays separate, with its selection table and acceptance matrix in
    devlog/_plan/260919_issue_sweep/062_wp7b_recovery_matrix.md.
  • A versioned research handoff on that model (REPORT-RESEARCH-01): route, source
    boundary, source and output languages kept separate, questions mapped to claim ids,
    and gaps. Validated only when supplied, so a legacy document stays valid and is never
    reported research-complete. Three rules earn their place — a source-only route may
    not carry a discovered source, a load-bearing claim may not rest only on
    snippet-derived sources because snippets are leads, and an unanswered question must
    appear in gaps rather than vanish. researchReceipt records route, contract and
    skill versions, and completed versus omitted checks; an omitted check never renders as
    a pass (#199).
  • REPORT-STORY-00: genre selects the report structure. A decision memo ends at the
    decision, a research synthesis at what is unresolved, a history at what is contested,
    a reference at the definitions — where a topic label is correct rather than a defect.
    Review criteria are about content rather than length, and a document with no numbers
    in it can pass all of them (#200).

Changed

  • The universal one-argument, claim-heading and closing-ask mandates are scoped to the
    genres that want them, across report-writing.md, SKILL.md,
    report-pipeline.md and its editorial-review receipt row. The canonical
    cxc-dev references/reader-documents.md was edited alongside the visualizer's
    portable copy so the two stay synchronized (#200).

Known limitations

  • #191 remains open. The host quota guard gates on authentication while extraction is
    routed by provider; closing it needs a host-supported control that does not exist.
  • The visualizer exporter migration is not done. It changes exit semantics and has its
    own acceptance matrix; see 062_wp7b_recovery_matrix.md.

What's Changed

  • [agent] feat(visualizer): recover the publication contract foundation (additive) by @lidge-jun in #220
  • [agent] feat(visualizer): versioned research handoff on the report model by @lidge-jun in #221
  • [agent] feat(visualizer): let genre select the report structure by @lidge-jun in #222
  • [agent] chore(release): prepare codexclaw 0.2.31 by @lidge-jun in #223
  • release: codexclaw 0.2.31 by @lidge-jun in #224

Full Changelog: v0.2.30...v0.2.31

codexclaw v0.2.30

Choose a tag to compare

@github-actions github-actions released this 19 Sep 10:46
585bc70

[0.2.30] - 2026-09-19

Ships the work that landed after the 0.2.29 promotion. No new code beyond what those
pull requests already merged.

Added

  • cxc memory requeue returns dead-lettered extraction jobs to the host's retry queue.
    Dry run unless --apply, restricted to rows still matching status='error' with no
    retries left, re-checked inside the write transaction so a job the host has picked up
    is never clobbered, and preserving last_error and both watermarks. Transient causes
    are the default selection; context-window failures need --include-context-window,
    because an input that did not fit will not fit on a retry either (#188).
  • A lane manifest and a cross-task merge handoff for parallel worktree lanes, with
    scripts/check-lane-manifest.mjs to validate one. Issue references must name their
    repository, and two active lanes may share an issue only when each names a different
    scope. The manifest is coordination evidence, not a lock (#184).
  • dev-visualizer/reference/reader-documents.md, a portable restatement of the reader
    contract that names its canonical owner, and
    dev-visualizer/reference/print-provenance.md, dated and scoped summaries replacing
    three unshipped ledger pointers (#182, #183).

Fixed

  • dev-visualizer resolved nine references outside its own directory, so the skill
    worked in this repository and broke the moment it was copied on its own. All nine now
    resolve in-root, enforced by a test that runs against an isolated single-skill copy
    (#183, #182).

Known limitations

  • #199, #200 remain open. See
    devlog/_plan/260919_issue_sweep/062_wp7b_recovery_matrix.md for the selection table
    and acceptance matrix the recovery needs.
  • #191 remains open. The host quota guard's authentication/routing mismatch is untouched.

What's Changed

  • [agent] feat(recall): cxc memory requeue for dead-lettered extraction jobs by @lidge-jun in #214
  • [agent] feat(dispatch): lane manifest and cross-task merge handoff by @lidge-jun in #215
  • [agent] docs(devlog): visualizer recovery selection table and acceptance matrix by @lidge-jun in #216
  • [agent] fix(visualizer): make the skill installable without its siblings by @lidge-jun in #217
  • [agent] chore(release): prepare codexclaw 0.2.30 by @lidge-jun in #218
  • release: codexclaw 0.2.30 by @lidge-jun in #219

Full Changelog: v0.2.29...v0.2.30

codexclaw v0.2.29

Choose a tag to compare

@github-actions github-actions released this 19 Sep 09:51
ecf308e

[0.2.29] - 2026-09-19

Added

  • cxc memory status reports the host memory extraction pipeline: per-kind job
    counts, jobs that exhausted their retries bucketed by cause, and the newest
    success. It names the store it read, because the host supports more than one
    memories schema and can dual-write, and reports unsupported on an unfamiliar
    schema rather than guessing. It deliberately publishes no eligible-backlog
    number: host eligibility depends on source, age, idle time, memory mode and
    current-thread exclusion, none of which are visible to a reader (#187).
  • SessionStart emits one bounded line when extraction is stale or jobs have
    exhausted their retries, and stays silent otherwise. An unreadable store also
    stays silent rather than implying the project has no memories (#185).
  • cxc-dev §3 gains DEV-CI-EVIDENCE-01: five ways hosted CI reports nothing
    while looking green, the identifying facts required before claiming it passed,
    and the route for reading a completed job's log while its workflow is still
    running. The escape-sequence flag is documented as version-conditional
    (#195, #197).
  • cxc-pabcd references/dispatch-surfaces.md gains DISPATCH-LANE-ID-01,
    DISPATCH-WAKE-01 and DISPATCH-POLL-BUDGET-01; references/delegation.md gains
    DISPATCH-CONSUME-ONCE-01 and DISPATCH-PROMOTE-01 (#189, #192, #193, #194, #198).

Changed

  • dev is protected from deletion by a repository ruleset. The cleanup script
    already listed dev among protected branches; the exposure was configuration,
    since delete_branch_on_merge was enabled with no rule covering the branch, so
    GitHub deleted it whenever a promotion merged. The release guide now states the
    pre-merge check, the post-merge recheck, and that merging does not start a
    release — release.yml triggers only on workflow_dispatch with version and
    expected_sha, or a v* tag (#175).
  • cxc-dev §8 widens from token budget to resource budget: parallel lanes and
    the task observing them share one external allowance, so polling competes with
    the work being polled (#194).

Fixed

  • The apply_patch comment lint applied its code patterns to every added line
    without knowing the target file, so ordinary English matched the cast pattern
    and prose was denied — including the bug report describing it. Added lines now
    carry their target, set by the native file directives and unified headers and
    reset at each boundary, and prose targets skip the code patterns. Source files
    stay linted wherever they live, and all three patterns were fixed rather than
    only the reported one (#196).
  • The hook-trust doctor check downgraded a stale recorded hash to a warning and
    reported that hooks still run. The host excludes both untrusted and modified
    hooks from execution unless trust is bypassed, so operators were told a guard
    was live when it was not. Both now fail, with separate counts and repairs
    preserved, and the evidence states that execution itself was not verified (#186).
  • buildCwdContext returned an empty string for a project with no history and for
    an index that could not be read, so a broken index presented as an empty
    project. The outcome is now distinguished; an empty project still injects
    nothing (#190).
  • export-paged-report.mjs handed a destination inside a missing directory to
    Chromium, whose failure named the browser for a filesystem problem. The output
    directory is prepared first, and a regular file occupying that path fails
    naming the directory. --qa-only creates nothing (#181).

Known limitations

  • #199, #200 remain open. They must extend the publication report model that
    exists on an unmerged branch, and recovering it is a runtime migration of
    roughly 1,150 lines that changes exporter exit semantics. Deferred deliberately
    rather than rushed; see devlog/_plan/260919_issue_sweep/061_wp7_recovery_decision.md.
  • #188 remains open. 35 of the 52 retry-exhausted memory jobs failed on context
    window, and a plain requeue repeats that failure unchanged.
  • #191 remains open. The authentication/routing mismatch in the host quota guard
    is real and untouched here; the bypass proposed in the issue does not work,
    because the guard rejects a reached limit before the threshold arithmetic.
  • #182, #183, #184 remain open.

Changed (phase control)

  • Formal P now requires an architect proposal, a main-owned executable plan and
    reflection by the same architect before independent audit. C0/C1 fast paths and
    explicit user limits keep their existing precedence; this adds guidance, not a
    runtime gate.

Fixed (dispatch and retirement)

  • Native V2 spawn hooks preserve canonical Fernet-shaped task messages without
    appending plaintext skill affordances or leaf guards. Structural validation
    rejects malformed lookalikes; omission notices identify the guards that could
    not be attached. Ciphertext recognition does not authenticate the message.

  • Subagent waiting guidance instructed coordinators to retire workers after
    about three empty waits, even when analysis could still be progressing.
    waiting.md now requires evidence of progress or stagnation, preserves
    unavailable observations, and uses non-interrupting checkpoints. Delegation
    and DISPATCH-RETIRE-01 clarify actual shutdown checks and managed recovery;
    cancellation or exhausted limits grant no retry or replacement. Progress
    assessment remains agent-followed (#178).

  • Managed dispatch now accepts explicit task_failed reports for confirmed
    stagnation or unusable final output. A recorded stopped child, task evidence
    and reconciliation are required before the existing bounded handoff can run.
    Provider errors keep their existing classification; cancellation and permission
    denials cannot be overridden by a task-failure label (#178).


What's Changed

  • [agent] docs(devlog): diff-level roadmap for the 260919 open-issue sweep by @lidge-jun in #201
  • [agent] docs(release): require dev deletion protection and an explicit release dispatch by @lidge-jun in #202
  • [agent] feat(pabcd): strengthen architect consultation and retain safe recovery by @thisisjun786 in #180
  • [agent] feat(recall): cxc memory status, and a startup notice when the pipeline has stalled by @lidge-jun in #204
  • [agent] fix(hooks): scan patch lines against their target file, and stop calling untrusted hooks harmless by @lidge-jun in #203
  • [agent] docs(dispatch): lane identity, wake preflight, polling budget and one-shot report consumption by @lidge-jun in #205
  • [agent] docs(dev): hosted CI evidence procedure and the completed-job log route by @lidge-jun in #206
  • [agent] fix(visualizer): prepare the export output directory before printing by @lidge-jun in #207
  • [agent] chore(release): prepare codexclaw 0.2.29 by @lidge-jun in #210
  • [agent] test(visualizer): make the export preflight test portable on Windows by @lidge-jun in #212
  • release: codexclaw 0.2.29 by @lidge-jun in #211

Full Changelog: v0.2.28...v0.2.29