Releases: rennavationstudios-bit/codex-gpu-thalen-helper
Release list
Codex GPU Thalen Helper v0.1.0-beta.22
Codex GPU Thalen Helper v0.1.0-beta.22
This unsigned prerelease corrects the cold-load timeout uncovered while live-testing beta.21 with Qwythos 9B through LM Studio. It retains beta.19 task-aware routing, beta.20's clean compact UI, and beta.21's truthful loading/reviewing/releasing status.
Cold local models get their full bounded load budget
- The loopback Ollama and LM Studio clients now disable .NET's separate 100-second
HttpClientdefault timeout. - Existing operation-specific cancellation remains authoritative: inventory requests are bounded to 10 seconds, LM Studio loading and local generation to five minutes, and Ollama pulls to two hours.
- A slow cold load is therefore not misreported as a user cancellation merely because it crosses 100 seconds.
- Caller cancellation, GPU pressure guards, the one-review lock, foreign-model preservation, and exact helper-owned unload verification are unchanged.
- Passive LM Studio inventory continues to run with redirected streams and
CreateNoWindow=true; the regression suite now asserts that no-console launch contract directly.
Verification and trust boundary
Deterministic mocked tests set an artificially tiny HttpClient timeout and prove that both provider clients still complete within their own explicit operation budget. No real model inference runs in the automated suite.
The installer remains unsigned and this build remains a prerelease. Verify the published SHA-256 checksum and GitHub artifact attestation before running it; Windows SmartScreen may warn about an unknown publisher.
Codex GPU Thalen Helper v0.1.0-beta.21
Codex GPU Thalen Helper v0.1.0-beta.21
This unsigned prerelease completes the live activity-status fix begun in beta.20. It preserves beta.19 task-aware routing and structured advisory results plus beta.20's transparent overflow glyph.
Review activity that is visible and truthful
- A separate display-only activity record now follows bounded reviews through Loading, Review active, Releasing, and short-lived Check status phases.
- The activity begins only after the shared GPU lease and safety checks accept an exact provider/model route. This makes long LM Studio loads visible before the provider returns the instance identity required by strict ownership tracking.
- Ollama and LM Studio use the same observational contract, and the Control Center restores the exact prior passive status after the lifecycle ends.
- Malformed, future, or expired activity records are ignored. Loading/reviewing records expire after ten minutes; releasing/attention records expire after two minutes.
Trust boundary
Review activity is not model ownership, provider health, or proof of GPU residency. It cannot authorize release, unload, routing, configuration, or any model-control action. The existing active-routed-model.txt tracker remains the only cleanup authority, and all existing foreign-model preservation and exact-unload rules remain unchanged.
The activity file contains only schema version, a random operation identifier, normalized provider, validated model key, allowlisted phase, and timestamps. It contains no prompt, response, repository content, path, digest, username, hostname, or machine identifier. Activity I/O is best-effort and cannot block or reroute a review.
UI and packaging
The compact Advanced control remains a transparent keyboard-accessible ellipsis glyph with no painted pill or rectangular mask. The installer remains unsigned and this build remains a prerelease. Verify the published SHA-256 checksum and GitHub artifact attestation before running it; Windows SmartScreen may warn about an unknown publisher.
The isolated release suite passes 401 tests without real model inference, including cancellation during provider generation and post-load verification, ambiguous-load, verified-cleanup, release-failure, unknown-phase, and control-authority boundaries. Temporary uninstall reports also use collision-safe non-identifying filenames so simultaneous test or removal paths cannot overwrite one another; protected-file merging and model preservation are unchanged.
Codex GPU Thalen Helper v0.1.0-beta.20
Codex GPU Thalen Helper v0.1.0-beta.20
This unsigned prerelease is a focused Control Center hotfix. It preserves beta.19 task-aware routing, structured advisory output, provider safety, protected-file merging, and automatic unload behavior.
Visible fixes
- The compact three-dot Advanced menu no longer uses a pill-shaped owner-drawn button. It is now a transparent keyboard-accessible ellipsis glyph, removing the rectangular background and square focus-mask artifacts entirely.
- The GPU status strip now follows the helper-owned active-model tracker while the Control Center is open. Reviews started by Codex show the tracked model and provider, such as Qwythos 9B review via LM Studio or Qwen3 8B review via Ollama.
- After the tracker clears, the strip restores the exact prior passive status, including manual-startup or safety warnings. A tracker proves helper ownership and release responsibility; it does not by itself claim provider-confirmed GPU residency.
- The observer runs every 500 milliseconds on the UI thread and reads one small helper-owned local tracker file. It does not query provider inventories, start a process, load a model, run inference, or widen any trust boundary.
Safety and compatibility
The activity display never treats an arbitrary provider model as helper-owned. It reports only the strict tracker already used by the review lifecycle and cleanup controls. Existing loopback enforcement, single-review locking, resource-pressure refusal, foreign-model preservation, verified unload, exact-file LM Studio registration, and no-automatic-download behavior remain unchanged.
The complete isolated Windows test suite passes 387/387 tests, including nested-gradient rendering coverage for the transparent menu glyph and active-to-idle status restoration.
The installer remains unsigned and this build remains a prerelease. Verify the published SHA-256 checksum and GitHub artifact attestation before running it; Windows SmartScreen may warn about an unknown publisher.
Codex GPU Thalen Helper v0.1.0-beta.19
Codex GPU Thalen Helper v0.1.0-beta.19
This unsigned prerelease makes the local reviewer contract task-aware and machine-readable while preserving its bounded, read-only advisory role. It does not broaden filesystem, shell, Git, deployment, network, model-download, protected-file, or provider-control authority.
Task-aware routing and review contracts
- Automatic planning now classifies supported review work deterministically: an explicit task kind wins, then bounded focus and assignment phrases, followed by the existing conservative input-size fallback.
- Task and effort capability floors combine with the audited model catalog. Deep repository analysis can retain the strongest suitable route, while GPU-intensive work continues to prefer the smallest safe eligible model.
- Log triage, test-failure analysis, diff review, repository analysis, edge-case generation, and general review each receive a focused rubric grounded only in text explicitly supplied by Codex.
- Review responses preserve the original raw
findingswhile adding boundedstructuredFindingswith ID, claim, supplied location, supplied evidence, confidence, impact, independent verification, and false-positive condition fields. structuredFindingsStatusdistinguishes valid parsing, partial parsing with rejected items, malformed output, and reviews that did not run. An empty array is never presented as independently confirmed correctness.- Automatic health now reports the eligible loopback provider pool and Task-aware pool instead of implying that one stored Ollama model is the route for every task. Passive
local_gpu_planremains authoritative for the actual provider and model selected for a request. - Automatic health degrades to a validated Ollama pool when optional LM Studio is closed or untrusted, without a duplicate LM inventory probe. Eligibility remains provider-qualified even if two providers expose the same model tag.
- Control Center readiness accepts the new bounded structured readiness contract while retaining compatibility with the legacy raw readiness token.
All local-model conclusions remain untrusted advisory material. ConfirmedObservations remains empty until the primary Codex agent independently verifies a claim against source code, tests, runtime evidence, or authoritative documentation.
Compatibility, startup, and release evidence
Codex GPU Thalen Helper is an independent community project for Windows x64. It is not made, endorsed, or supported by OpenAI, Ollama, or LM Studio. Windows 11 is preferred; Windows 10 22H2 receives an end-of-general-support warning.
Installation never downloads, registers, loads, or runs a model without a separate reviewed choice. Ollama model storage is selected only after local free-space checks and explicit confirmation. LM Studio remains user-controlled: the helper registers only exact catalog-audited existing files and never silently downloads, copies, moves, or substitutes them.
Optional Ollama startup is per-user after sign-in. The managed launcher uses the existing loopback endpoint and process inventory to avoid duplicate processes; if the user declines startup, Ollama reviews require manual startup after each sign-in. LM Studio and its loopback server are not started or reconfigured by the helper.
The beta.19 release audit builds the self-contained x64 binaries and installer, runs all 385 isolated automated tests, audits NuGet vulnerabilities, scans tracked release inputs for secrets and personal paths, compiles the installer, and generates the SPDX SBOM and friend bundle. The dedicated CI lifecycle job, or an explicit release-audit.ps1 -RunInstallerLifecycle run, exercises installer upgrades against temporary Codex homes and mocked provider boundaries. Routine tests download no model and run no GPU inference.
All prior loopback enforcement, no-automatic-download behavior, foreign-model preservation, single-review concurrency, pressure refusal, exact-file LM Studio registration, helper-owned unloading, backups, hash-bound protected-file repair, idempotent updates, and rollback remain in force.
Software cannot prove PSU capacity, PCIe power cabling, card clearance, cooling, firmware compatibility, or every GPU and driver combination. It also cannot simulate a real reboot or sign-in on every destination computer. Destination post-install checks therefore remain authoritative for startup, selected-model availability, storage path, provider loopback status, current pressure, and real hardware compatibility.
The installer remains unsigned and this build remains a prerelease. Verify the published SHA-256 checksum and GitHub artifact attestation before running it; Windows SmartScreen may warn about an unknown publisher.
Codex GPU Thalen Helper v0.1.0-beta.18
Codex GPU Thalen Helper v0.1.0-beta.18
This unsigned prerelease is a focused Control Center rendering correction. It does not broaden the reviewer's permissions, network boundary, model-download behavior, provider control, or protected-file ownership.
Literal labels in the rounded Control Center
- Owner-drawn rounded buttons now display literal ampersands instead of interpreting them as WinForms mnemonic prefixes.
- Models & storage therefore renders exactly as written in the installed application, screenshots, and contest demonstrations.
- The shared rounded-button painter uses
TextFormatFlags.NoPrefix, so the correction applies consistently rather than escaping one label as a special case. - A regression test binds the custom drawing flags to literal ampersand behavior while retaining
UseMnemonic = false.
All beta.17 Control Center improvements remain intact: one local-review switch, task-aware Ollama and LM Studio routes, responsive bounded toggles, compact GPU status, rounded controls, hover help, and the quiet advanced menu.
Compatibility, startup, and release evidence
Codex GPU Thalen Helper is an independent community project for Windows x64. It is not made, endorsed, or supported by OpenAI, Ollama, or LM Studio. Windows 11 is preferred; Windows 10 22H2 receives an end-of-general-support warning.
Installation never downloads, registers, loads, or runs a model without a separate reviewed choice. Ollama model storage is selected only after local free-space checks and explicit confirmation. LM Studio remains user-controlled: this release can register only the exact existing catalog-audited Qwythos GGUF and never downloads, copies, moves, or substitutes it.
Optional Ollama startup is per-user after sign-in. The managed launcher uses the existing loopback endpoint and process inventory to avoid duplicate processes; if the user declines startup, Ollama reviews require manual startup after each sign-in. LM Studio and its loopback server are not started or reconfigured by the helper.
The beta.18 release audit builds the self-contained x64 binaries and installer, runs all 358 isolated automated tests, audits NuGet vulnerabilities, scans tracked release inputs for secrets and personal paths, compiles the installer, and generates the SPDX SBOM and friend bundle. The dedicated CI lifecycle job (or an explicit release-audit.ps1 -RunInstallerLifecycle run) exercises installer upgrades against temporary Codex homes and mocked provider boundaries. Routine tests download no model and run no GPU inference.
All prior loopback enforcement, no-automatic-download behavior, foreign-model preservation, single-review concurrency, pressure refusal, exact-file LM Studio registration, helper-owned unloading, backups, hash-bound protected-file repair, idempotent updates, and rollback remain in force.
Software cannot prove PSU capacity, PCIe power cabling, card clearance, cooling, firmware compatibility, or every GPU/driver combination. It also cannot simulate a real reboot or sign-in on every destination computer. Destination post-install checks therefore remain authoritative for startup, selected-model availability, storage path, provider loopback status, current pressure, and real hardware compatibility.
The installer remains unsigned and this build remains a prerelease. Verify the published SHA-256 checksum and GitHub artifact attestation before running it; Windows SmartScreen may warn about an unknown publisher.
Codex GPU Thalen Helper v0.1.0-beta.17
Codex GPU Thalen Helper v0.1.0-beta.17
This unsigned prerelease is a focused desktop usability update. It does not broaden the reviewer's permissions, network boundary, model-download behavior, or protected-file ownership.
A cleaner, faster Control Center
- The installed app now matches the compact Thalen AI website panel: one Local reviews switch, clear normal/deep and quick/GPU-busy routes, Test reviewer, Models & storage, and a small GPU status strip.
- Qwythos through LM Studio remains the prominent automatic normal/deep route when its exact registered file is installed and validated. Qwen3 8B through Ollama remains the quick or GPU-busy route on the validated RTX 3090 setup.
- Less-common low-impact, pinned-routing, keep-warm, release, repair, diagnostics, reliability, disconnect, and uninstall controls remain available through the quiet advanced menu.
- Long status and hero copy stays inside the compact card with a clean ellipsis; hovering exposes the full text instead of letting the card widen, hide controls, or produce a horizontal scrollbar.
Responsive switches without visual artifacts
- Toggle switches are fully owner-drawn controls with rounded keyboard focus, checked-state accessibility, and parent-surface compositing. They no longer inherit rectangular native focus or corner artifacts.
- Passive health and Quick/Standard/Deep route checks run concurrently.
- A switch is locked only for its bounded state mutation; the longer passive refresh no longer disables every switch for roughly twenty seconds.
- Overlapping passive refreshes are generation-checked so an older result cannot overwrite a newer preference.
All prior loopback enforcement, no-automatic-download behavior, foreign-model preservation, single-review concurrency, pressure refusal, exact-file LM Studio registration, helper-owned unloading, backups, hash-bound protected-file repair, idempotent updates, and rollback remain in force.
Compatibility, startup, and release evidence
Codex GPU Thalen Helper is an independent community project for Windows x64. It is not made, endorsed, or supported by OpenAI, Ollama, or LM Studio. Windows 11 is preferred; Windows 10 22H2 receives an end-of-general-support warning.
Installation never downloads, registers, loads, or runs a model without a separate reviewed choice. Ollama model storage is selected only after local free-space checks and explicit confirmation. LM Studio remains user-controlled: this release can register only the exact existing catalog-audited Qwythos GGUF and never downloads, copies, moves, or substitutes it.
Optional Ollama startup is per-user after sign-in. The managed launcher uses the existing loopback endpoint and process inventory to avoid duplicate processes; if the user declines startup, Ollama reviews require manual startup after each sign-in. LM Studio and its loopback server are not started or reconfigured by the helper.
The beta.17 release audit builds the self-contained x64 binaries and installer, runs all 357 isolated automated tests, audits NuGet vulnerabilities, scans tracked release inputs for secrets and personal paths, compiles the installer, generates the SPDX SBOM and friend bundle, and exercises the installer lifecycle against temporary Codex homes and mocked provider boundaries. Routine tests download no model and run no GPU inference.
Software cannot prove PSU capacity, PCIe power cabling, card clearance, cooling, firmware compatibility, or every GPU/driver combination. It also cannot simulate a real reboot or sign-in on every destination computer. The destination post-install checks therefore remain authoritative for startup, selected-model availability, storage path, provider loopback status, current pressure, and real hardware compatibility.
The installer remains unsigned and this build remains a prerelease. Verify the published SHA-256 checksum and GitHub artifact attestation before running it; Windows SmartScreen may warn about an unknown publisher.
Codex GPU Thalen Helper v0.1.0-beta.16
Codex GPU Thalen Helper v0.1.0-beta.16
This unsigned prerelease is a usability and truthfulness release for the Windows Control Center. The reviewer, provider, ownership, and protected-file safety boundaries remain unchanged.
A simpler Control Center
- One clear Local reviews switch pauses or resumes optional local processing while keeping the Codex integration understandable.
- The home screen shows the actual passively planned normal route prominently, plus current provider eligibility and GPU state. Quick, normal, and deep routing are checked independently without loading a model.
- Test reviewer asks before one bounded inference, reports the actual provider and model that ran, requires the exact readiness token, and verifies that any proven helper-owned model was released before reporting success.
- Guided model and storage setup, low-impact mode, and a collapsed advanced section replace the previous wall of paired pause/resume and enable/disable buttons.
- The new Thalen icon is included in the application, setup executable, Windows shortcuts, and uninstall entry. Rounded controls are antialiased and DPI-aware.
Recovery and status correctness
- Models & storage remains available when an incomplete first run has no managed state, while existing external integrations stay protected.
- A transient status failure now exposes a passive Retry status action instead of leaving the window inert.
- Ready now means the helper state is enabled and the managed Codex MCP entry is actually enabled. Turning reviews on repairs a disabled managed entry before telling the user to restart Codex.
- Automatic presentation no longer shows a stale pinned fallback or a catalog download estimate when Qwythos or another installed validated route is the actual plan.
All beta.15 LM Studio input isolation, beta.14 protected ownership reconciliation, beta.13 exact-file Qwythos validation, loopback enforcement, foreign-model preservation, managed backups, hash-bound repair, idempotent updates, and rollback remain in force.
The installer remains unsigned. Verify the published SHA-256 checksum and GitHub artifact attestation before running it; Windows SmartScreen may warn about an unknown publisher.
Codex GPU Thalen Helper v0.1.0-beta.15
Codex GPU Thalen Helper v0.1.0-beta.15
This unsigned prerelease fixes the LM Studio inventory process boundary used by the actual Codex MCP server.
Fixed
- The fixed, read-only
lms ls --jsonandlms ps --jsonchild processes now receive a private redirected standard-input stream that is closed immediately after launch. - The LM Studio CLI can no longer inherit, wait on, or consume the reviewer's MCP JSON-RPC input pipe. This removes the timeout that could exclude an otherwise validated Qwythos model and make automatic standard/deep planning fall back to Ollama.
- Regression coverage launches a child that waits for input and proves the helper supplies EOF without exposing the parent protocol stream.
All beta.14 ownership reconciliation, protected-file backups and hash-bound repair, beta.13 exact-file Qwythos validation, dynamic hardware/resource routing, loopback enforcement, foreign-model preservation, and exact-instance unload behavior remain unchanged.
Verification expectation
After installation and explicit Qwythos registration, a fresh Codex MCP session should passively report the LM Studio model as eligible. Standard or deep planning may prefer Qwythos when current GPU headroom satisfies the configured reserve; quick or GPU-busy planning should continue choosing the smallest safe validated Ollama model. Planning runs no inference, and both providers must report zero loaded models after validation or review cleanup.
The installer remains unsigned. Verify the published SHA-256 checksum and GitHub artifact attestation before running it; Windows SmartScreen may warn about an unknown publisher.
Codex GPU Thalen Helper v0.1.0-beta.14
Codex GPU Thalen Helper v0.1.0-beta.14
This prerelease adds a reviewable recovery path for a protected-file ownership contradiction discovered during a real beta.11-to-beta.13 upgrade.
Fixed
- A prior helper installation can now be reconciled when product state still records managed ownership but an external rewrite removed both markers and left exactly one structurally valid unmarked
local_gpu_reviewerfamily. - Ordinary repair continues to refuse that contradiction. Recovery requires an explicit
--migrate-existingchoice, a private read-only dry-run diff, and all four source/planned SHA-256 values at apply time. - The migration preserves unrelated TOML, comments, unknown settings, MCP servers, and existing instructions; creates timestamped backups; writes atomically; and is idempotent.
- Missing, duplicate, displaced, interleaved, or malformed reviewer families remain blocked. The helper never repairs ownership by silently editing state or inserting markers.
All beta.13 hardware-aware model selection, storage/free-space checks, Ollama acquisition, exact-file LM Studio/Qwythos routing, loopback enforcement, foreign-model preservation, single-flight inference, pressure refusal, and exact-instance unload behavior are unchanged.
This installer is unsigned and remains a prerelease. Verify its SHA-256 checksum and GitHub artifact attestation before installation; Windows SmartScreen may display an unknown-publisher warning.
Codex GPU Thalen Helper v0.1.0-beta.13
Codex GPU Thalen Helper v0.1.0-beta.13
This unsigned prerelease restores a fail-closed LM Studio route and makes first-run model setup provider-aware.
What changed
- Existing LM Studio GGUF models can be registered only when the signed current-user
lms.exeinventory binds the catalog model key to the exact audited relative path, size, file identity, and full SHA-256 digest. - Registration and every LM Studio review repeat that proof inside the shared single-review lease. The helper refuses foreign loaded instances, generates through the verified loopback provider, unloads only the exact helper-created instance, and confirms it is absent afterward.
- Legacy registrations without the new proof remain preserved but cannot route until the user explicitly revalidates them.
- The first-run model page separates hardware-compatible Ollama acquisition from existing LM Studio/GGUF registration. It shows provider, approximate size, storage destination, available space, and safety reserve before any model action.
- The default path still installs the helper without downloading, loading, validating, moving, or deleting a model. Every acquisition or validation remains a separate named confirmation.
- A fresh LM Studio-only setup can complete health, planning, and review without configuring Ollama. Dual-provider installations still check Ollama and refuse foreign loaded models.
- LM Studio load ownership is recorded as soon as the provider returns an instance identity. Any later failure must prove both REST unload and signed-CLI absence before the ownership record is cleared.
- The signed LM Studio CLI namespace is pinned through signature verification and execution. Ollama storage selection rejects symbolic links, junctions, mount points, network targets, and removable drive types, rechecks live free space, and detects path replacement around configuration and acquisition.
Provider boundaries
Ollama may be installed from its current official signed Windows installer and may acquire one named catalog model only after explicit approval. LM Studio itself and GGUF files are never downloaded or installed by Thalen; beta.13 registers only an existing catalog-audited local GGUF selected by the user.
Both providers must be owned by the current Windows user and listen only on IPv4 loopback. The MCP server remains a bounded, read-only advisory tool with no filesystem, shell, Git, deployment, publishing, email, or external-system access.
Upgrade behavior
The installer preserves existing Codex configuration and instructions through timestamped backups, a private dry-run, managed markers, hash-bound surgical merging, idempotent repair, and rollback. It never replaces config.toml or AGENTS.override.md wholesale. An existing unmarked local_gpu_reviewer integration remains protected by default.
Verification and limitations
Routine automated tests use temporary Codex homes, temporary model fixtures, mocked loopback providers, and mocked LM Studio CLI inventory. They do not download a model or run GPU inference. Real provider validation remains an explicit post-install action on the destination computer.
LM Studio's REST load API returns an instance identity but does not currently let the helper assign its own unique instance name. Do not manually load the same registered model key during a helper review. Different-key, additional-instance, path, identity, and unload mismatches fail closed; the narrow simultaneous same-key race remains documented until the supported runtime offers an identifier contract suitable for this boundary.
This installer is not Authenticode-signed and may trigger Windows SmartScreen. Verify the published SHA-256 checksum and GitHub artifact attestation before running it.