Repository navigation
1.4.1 — Worker integrity and safer dependency updates
1.4.1 — Worker integrity and safer dependency updates
Worker transport and concurrent admission
- Preserve Korean, emoji and other multibyte UTF-8 text when RPC data arrives
across byte boundaries; reject incomplete frames on disconnect. - Serialize admission through durable reservation and controller registration.
Matching job-ID retries return the existing status without executing twice;
different chats continue to execute concurrently. - Keep live chat reservations even if the disk index changes. Roll back failed
admissions; if rollback fails, pause new admission until healthy recovery.
Event log and storage recovery
- Derive event sequences from the committed, newline-terminated JSONL prefix,
reconciling stale state and cursors without reusing sequence numbers. - Preserve incomplete trailing writes in private quarantine before trimming.
Reject duplicate/decreasing sequences and logs behind persisted cursors. - Surface
EVENT_COMMITTEDwith the committed sequence when appending succeeds
but saving job state fails. Callers must not blindly repeat that event body. - Distinguish missing files, corrupt JSON/container structures, and permission
or I/O errors. Rebuild missing/corrupt active indexes only after validating
job records, preserving originals and propagating quarantine failures. - Recover interrupted reservations at startup without re-executing orphaned work.
Dependency pull-request merge security
- Verify updater author IDs/types and repository identity; reject spoofed branch
names and external forks. Preserve supported owner-PAT and Actions identities. - Inspect files at immutable commits as data; execute only trusted workflow code.
Permit dependency-version changes or Dependabot action-reference changes,
while routing script, permission and unrelated changes to manual review. - Require successful CI for the exact head commit, recheck head/base SHAs before
merging, and use--match-head-commitwithout an administrator bypass.
Upgrade and verification notes
- Add regression coverage for UTF-8 splits, concurrent starts and retries,
interrupted append/state saves, partial records, I/O failures, quarantine
failures and malicious or changed dependency PRs. - Stop accepting new work and drain running jobs plus final delivery before
restarting the worker. Historical invalid logs require explicit recovery;
preserve originals rather than discarding or replaying ambiguous records. - Recovery assumes one worker per state directory. File writes are not fsynced,
so this release does not promise OS/power-loss durability. Arbitrary event
bodies have no deduplication key. See Worker integrity.
Dependencies
- Public Codex SDK/CLI:
0.159.3→0.160.0.
Changes: v1.4.0…v1.4.1 · PR #99