Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
97 commits
Select commit Hold shift + click to select a range
6044a9a
chore(release): open dev at 2.60.0 before releasing 2.59.0 (#5072)
github-actions[bot] Sep 18, 2026
3d5efc7
fix(ci): classify the merged regression tests explicitly in the layou…
lidge-jun Sep 18, 2026
735f915
fix(providers): stop the Antigravity rename migration re-announcing i…
lidge-jun Sep 19, 2026
4f3c223
diag(google): describe the Antigravity wire request without its conte…
lidge-jun Sep 19, 2026
7817cd5
test(ci): split phase timing for the four #4997 budget overruns (#5081)
lidge-jun Sep 19, 2026
d385a56
test(ci): move fixture and host-probe cost out of the #4997 measured …
lidge-jun Sep 19, 2026
d4ca4d9
fix(tests): judge cold-spawn warm-up registration structurally (#5080)
lidge-jun Sep 19, 2026
0429c0a
test(ci): give the Windows nested live-lock case its own lock owner (…
lidge-jun Sep 19, 2026
6e5607b
fix(codex): keep routed rows from inheriting experimental context (#5…
Mpayro Sep 19, 2026
8b41575
fix(cli): shell-quote hub invite arguments (#5065)
luvs01 Sep 19, 2026
c289926
fix(gui): keep file clients unknown on a failed-cold client read (#5088)
luvs01 Sep 19, 2026
318f25b
fix(process-control): avoid sending management token to DNS-recorded …
luvs01 Sep 19, 2026
5be4f9d
fix(cursor): preserve mixed-case effort aliases (#5084)
luvs01 Sep 19, 2026
7864869
fix(gui): validate Claude Desktop status payloads before trusting the…
luvs01 Sep 19, 2026
04761a1
fix(responses): emit the tool name the undeclared-tool guard authoriz…
lidge-jun Sep 19, 2026
4e45e17
fix(responses): repair legacy dotted call names on replay (#5095) (#5…
lidge-jun Sep 19, 2026
4e7d713
fix(transport): return null bodies for 204 and 205 on raw outbound tr…
lidge-jun Sep 19, 2026
fe2b755
fix(gui): do not offer retry for the Grok coupon reset POST (#5103)
luvs01 Sep 19, 2026
52c427a
feat(providers): patient same-target 429 fallback for OpenCode Go (#5…
agentHits Sep 19, 2026
1b54f29
docs(config): describe apiKeys as data-plane credentials only (#5134)
lidge-jun Sep 19, 2026
e668aa1
fix(cursor): state the T04 re-arming contract on an injectable clock …
lidge-jun Sep 19, 2026
9824aa5
fix(transport): settle SOCKS5 uploads on abort and early final respon…
lidge-jun Sep 19, 2026
af4f744
fix(transport): decode content-coded responses on the pinned direct r…
lidge-jun Sep 19, 2026
bb2fa5a
fix(responses): share one progressive freeform decoder with routed re…
lidge-jun Sep 19, 2026
acd43bf
fix(responses): refuse a continuation whose task scope does not match…
lidge-jun Sep 19, 2026
5ce51cb
docs(structure): bind the Lab isolation invariant (#5138)
lidge-jun Sep 19, 2026
f39ba5a
fix(test): raise the native passthrough reset from a requested pull (…
lidge-jun Sep 19, 2026
f117c20
docs(proxy): align SOCKS5 HTTP/SSE routing documentation (#5153)
lidge-jun Sep 19, 2026
6d42723
Add versioned structure contract authority (#5155)
lidge-jun Sep 19, 2026
26d3a86
feat(devin): admit every inference send through the shared budget (#5…
lidge-jun Sep 19, 2026
46195ac
fix(ci): defuse bot-authored mentions at punctuation and Markdown bou…
luvs01 Sep 19, 2026
f6b59da
fix(doctor): tolerate a malformed CODEX_HOME/agents path during the r…
luvs01 Sep 19, 2026
dfb76e7
fix(devin): bound remote image prompt references (#5139)
luvs01 Sep 19, 2026
118c66a
fix(responses): keep custom websocket upstreams on bounded HTTP SSE (…
luvs01 Sep 19, 2026
d1745ee
test(server): report what the sideband peer saw at the 50MiB frame ce…
lidge-jun Sep 19, 2026
962e8a3
fix(codex): preserve legacy history manifest targets for history jobs…
luvs01 Sep 19, 2026
ef7e59f
test(cursor): state the T04 heartbeat-only contract on the injectable…
lidge-jun Sep 19, 2026
766e0aa
fix(web-search): replay burst 429s on the forward sidecar search (#5158)
agentHits Sep 19, 2026
dfbcf2b
fix(cursor): persist and enforce tool-suspended checkpoint snapshots …
luvs01 Sep 19, 2026
45a5ca5
fix(gui): distinguish unmapped prompt layers from the unprintable bas…
luvs01 Sep 19, 2026
ff8c337
feat(meta-muse): expose max reasoning effort to routed clients (#5094)
shawn-kim-ai Sep 19, 2026
7fd629f
fix(grok): normalize integral Responses timestamps (#5071)
shawn-kim-ai Sep 19, 2026
19b42c5
fix(codex): bound destroyed-shim diagnostics to the stable probe (#5136)
luvs01 Sep 19, 2026
49c79f3
test(devin): assert which error the refused send raises and what the …
lidge-jun Sep 19, 2026
8a03072
Report endpoint-scoped Google tool-schema loss (#5162)
lidge-jun Sep 19, 2026
57b1df7
docs: record contract gap analysis and delivery evidence (#5175)
lidge-jun Sep 19, 2026
4067004
feat(spend): require one writer lease per state directory for the spe…
lidge-jun Sep 19, 2026
838af40
feat(registry): derive selector decode hints from a classified regist…
lidge-jun Sep 19, 2026
96a6de8
Reject lossy Google tool schemas on opt-in (#5167)
lidge-jun Sep 19, 2026
00ac9b6
docs: record thirteen verified contract issue outcomes (#5187)
lidge-jun Sep 19, 2026
efb55e7
Resolve static model policy once for catalog and routing (#5171)
lidge-jun Sep 19, 2026
4823bbb
fix(ci): preserve punctuation-bearing emails when defusing mentions (…
luvs01 Sep 19, 2026
5c943d9
fix(providers): match the OpenCode Go destination canonically (#5165)
agentHits Sep 19, 2026
5d0122a
fix(accounts): honor autoSwitchThreshold=0 as disabled (#5091)
luvs01 Sep 19, 2026
05c14df
fix(devin): fail closed for legacy custom ACP rows (#5149)
luvs01 Sep 19, 2026
2aa6012
fix(codex): refuse provider-table transitions that strand paginated o…
luvs01 Sep 19, 2026
187c959
fix(combo): fail over Astra tool routing mismatch (#5142)
87003697 Sep 19, 2026
0c45969
fix(catalog): skip byte-identical models-cache writes so a start cann…
neerajdad123-byte Sep 19, 2026
920d8d7
docs: record contract campaign review and verification progress (#5192)
lidge-jun Sep 19, 2026
dbaad90
test(providers): assemble the userinfo fixture instead of writing it …
lidge-jun Sep 19, 2026
c81d430
refactor(codex,tests): split two files back under their size caps (#5…
lidge-jun Sep 19, 2026
3fd293d
Deliver an upstream refusal as a terminal error instead of a retryabl…
lidge-jun Sep 19, 2026
09698b9
fix: stop one account failure from taking the whole proxy out of serv…
lidge-jun Sep 19, 2026
4853f90
fix(streaming): carry three transport hardening PRs and close the reo…
lidge-jun Sep 19, 2026
b52bf57
feat(responses): route Codex compaction to a configured model for the…
lidge-jun Sep 19, 2026
98b9b34
Provider discovery and model surface: outbound User-Agent, Volcengine…
lidge-jun Sep 19, 2026
fec3add
Export bounded request metrics through an opt-in scrape endpoint (#5183)
lidge-jun Sep 19, 2026
1883f2f
docs: record fourteen verified contract issue closures (#5218)
lidge-jun Sep 19, 2026
6d42a00
chore(deps): declare wreq-js as optional TLS runtime dependency (#5083)
yansigit Sep 19, 2026
18bfdc1
fix(opencode): scope catalog credential (#5194)
luvs01 Sep 19, 2026
d764bb4
fix(client): clear disconnected hub token on standalone recycle (#5144)
luvs01 Sep 19, 2026
96a06a7
fix(adapters): bound inline image decoding (#5208)
luvs01 Sep 19, 2026
6b742ec
fix(oauth): validate raw paste code#state suffix against expected sta…
luvs01 Sep 19, 2026
bd55ab7
fix(routing): reuse parsed body for policy fallback (#5207)
luvs01 Sep 19, 2026
936e352
refactor(oauth): move in-flight login state into its own module (#5220)
lidge-jun Sep 19, 2026
b9d430b
Migrate static policy consumers onto the resolved policy (#5174)
lidge-jun Sep 19, 2026
3f9b956
fix(providers): replay ambiguous resets on the OpenCode Go initial se…
agentHits Sep 19, 2026
a32b8cc
fix(codex): persist terminal pool reauth causes and surface stored ve…
luvs01 Sep 19, 2026
c193f06
fix(tray): read restart safety through the CLI instead of the admin-g…
ahmedfrawelo Sep 19, 2026
3f9fe3f
Cover HEAD preservation, interim answers and the SOCKS response timeo…
lidge-jun Sep 20, 2026
29cc7a5
fix(codex): recognize boolean native context opt-in (#5156)
luvs01 Sep 20, 2026
c9793b0
fix(vision): let an explicit custom row outrank the provider vision h…
RobinBially Sep 20, 2026
3ebdbd4
fix(registry): reclassify the Zen Go DeepSeek route as native vision …
RobinBially Sep 20, 2026
97aaf8c
fix(codex): hand off affinity in refresh flight (#5135)
luvs01 Sep 20, 2026
e64d699
Add server-owned integration mutation previews (#5185)
lidge-jun Sep 20, 2026
cd2ffb4
fix(usage): bound concurrent filtered scans (#5231)
luvs01 Sep 20, 2026
bf3196b
fix(cursor): gate synthetic ultra (1m) catalog rows on discovered Max…
luvs01 Sep 20, 2026
d035cd6
fix(proxy): preserve Windows per-scheme proxy scope (#5227)
luvs01 Sep 20, 2026
4e73323
fix(adapters): thread abort signal into image normalization call site…
luvs01 Sep 20, 2026
2a2c01a
fix(adapters): terminate Windows coding-agent trees (#5224)
luvs01 Sep 20, 2026
148b09b
fix(sidecars): rebind the sidecar retry request after OAuth rotation …
luvs01 Sep 20, 2026
9164338
fix(opencode-go): bound replayed tool promotion (#5235)
luvs01 Sep 20, 2026
ed44e04
Show server-owned plans in integration confirmations (#5197)
lidge-jun Sep 20, 2026
86691c7
fix(registry): add modelResponsesTerminalRepair for muse-spark on Ope…
Yum-wu Sep 20, 2026
12cb129
fix(responses): reject Fernet-shaped agent plaintext (#5239)
Ingwannu Sep 20, 2026
d3d6379
docs: archive contract implementation and record release handoff (#5242)
lidge-jun Sep 20, 2026
015c67c
test(responses): mint the surviving blob as a valid Fernet token (#5246)
lidge-jun Sep 20, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added .github/pr-assets/508-grok-coupon-unknown.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added .github/pr-assets/5197-apply-desktop.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added .github/pr-assets/5197-apply-narrow.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
180 changes: 180 additions & 0 deletions .github/pr-assets/5197-capture-receipt.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,180 @@
{
"status": "HISTORICAL/CORRECTED-GUI-TREE",
"proofType": "fixture-rendered GUI proof from a hosted PR merge-ref build associated with the source head and GUI-tree-equivalent to the reviewed GUI; not a live backend or a literal PR-head build",
"sourceArtifact": {
"name": "PR #5197 hosted merge-ref GUI build associated with source head 07bf0a4dbe",
"artifactId": 10595174777,
"artifactName": "dashboard-preview-6c9576edb372200efec9d6ad4fea7b1e0dc35fb4",
"workflowRun": 35481230775,
"workflowAttempt": 1,
"workflowConclusion": "success",
"entrypoint": "index.html",
"javascript": "assets/index-CKL6ayU1.js",
"stylesheet": "assets/index-BTuCbqQd.css",
"buildCommit": "6c9576edb372200efec9d6ad4fea7b1e0dc35fb4",
"prHead": "07bf0a4dbe369f204c2216f5e8c07c87f52d649c",
"guiTree": "06c1f0c620cbfca2a557813f7ec54b7c11cbb540"
},
"commands": {
"fixtureServer": "cd <extracted-artifact-root> && python3 fixture_server.py",
"asideReplTemplate": "/usr/bin/perl -e 'alarm shift; exec @ARGV' 120 aside repl \"<single-session inspect-act-verify script>\"",
"desktopWindow": "Aside window {1446,762} -> CSS viewport 1280x720",
"narrowWindow": "Aside window {646,842} -> CSS viewport 480x800",
"ko390Window": "Aside native page zoom 125 percent plus window {654,900} -> observed CSS viewport 390x686"
},
"reproduction": {
"baseUrl": "http://127.0.0.1:18799/",
"harnessScript": "fixture_server.py (scratch-only capture harness; not tracked)",
"driver": "Aside CLI repl opened the base URL in the real browser, selected fixture modes through POST /__fixture/mode, drove the dashboard controls, read back assertions, and captured each frame at the recorded CSS viewport and DPR."
},
"fixtureRoutes": [
"GET / and static assets",
"GET /healthz",
"GET /api/startup-health",
"GET /api/client-integrations",
"GET /api/client-integrations/opencode",
"GET /api/client-integrations/journal?client=opencode",
"POST /api/client-integrations/preview",
"PUT /api/client-integrations/opencode",
"POST /api/client-integrations/restore/preview",
"POST /api/client-integrations/restore",
"GET /api/client-integrations/aside/profiles",
"GET /api/client-integrations/aside/profiles/7",
"GET /api/client-integrations/aside/profiles/7/journal",
"POST /api/client-integrations/aside/profiles/7/preview",
"PUT /api/client-integrations/aside/profiles/7",
"POST /__fixture/mode",
"GET /__fixture/state"
],
"requestSequences": {
"apply": [
"POST /__fixture/mode {mode:apply}",
"GET /api/client-integrations/opencode",
"GET /api/client-integrations/journal?client=opencode",
"POST /api/client-integrations/preview {clientId:opencode,operation:apply}"
],
"foreignOverwrite": [
"POST /__fixture/mode {mode:overwrite}",
"GET /api/client-integrations/opencode -> conflict, reason foreign-edit",
"GET /api/client-integrations/journal?client=opencode",
"POST /api/client-integrations/preview {clientId:opencode,operation:overwrite}"
],
"restoreDrift": [
"POST /__fixture/mode {mode:restore}",
"GET /api/client-integrations/opencode",
"GET /api/client-integrations/journal?client=opencode -> op-restore-001",
"POST /api/client-integrations/restore/preview {opId:op-restore-001,confirmDrift:false}"
],
"stale409Reconfirmation": [
"POST /__fixture/mode {mode:stale}",
"GET state and journal",
"POST /api/client-integrations/preview -> initial p1:dddd... plan",
"PUT /api/client-integrations/opencode with initial binding -> 409 integration_preview_stale plus p1:eeee... fresh plan",
"GET state and journal reconciliation",
"capture before reconfirming"
],
"koRestoreDrift390": ["select Korean in dashboard", "run restoreDrift", "capture at observed innerWidth 390"],
"koStaleReconfirm390": ["keep Korean selected", "run stale409Reconfirmation", "capture before reconfirming at innerWidth 390"],
"koProfileDisableNoop390": [
"POST /__fixture/mode {mode:profile-noop}",
"GET /api/client-integrations/aside/profiles -> profile 7 enabled=true,state=absent",
"POST /api/client-integrations/aside/profiles/7/preview {operation:disable} -> willChange=false,changes=[],profileId=7",
"assert document no-op copy and sync-preference disclosure",
"assert primary Disable button enabled",
"assert consequence body contains neither Korean backup nor rollback text",
"capture",
"PUT /api/client-integrations/aside/profiles/7 {enabled:false,operation:disable,planFingerprint:p1:ffffffffffffffffffffffffffffffff}",
"GET /__fixture/state verifies recorded binding"
],
"keyboardFocus": [
"open apply dialog",
"press Tab twice to focus primary Apply",
"capture visible focus ring",
"assert dialog count 1 before Escape",
"press Escape and assert dialog count 0"
]
},
"captureBinding": {
"prHead": "07bf0a4dbe369f204c2216f5e8c07c87f52d649c",
"hostedBuildCommit": "6c9576edb372200efec9d6ad4fea7b1e0dc35fb4",
"sourceGuiTree": "06c1f0c620cbfca2a557813f7ec54b7c11cbb540",
"hostedBuildGuiTree": "06c1f0c620cbfca2a557813f7ec54b7c11cbb540",
"guiTreeEqual": true
},
"interactionObservations": {
"keyboardFocusVisible": true,
"dialogCountBeforeEscape": 1,
"dialogCountAfterEscape": 0
},
"profileNoopVerification": {
"previewDto": {
"version": 1,
"clientId": "aside",
"operation": "disable",
"state": "absent",
"foreignEdit": "none",
"changes": [],
"fingerprint": "p1:ffffffffffffffffffffffffffffffff",
"canApply": true,
"willChange": false,
"profileId": 7
},
"assertions": {
"documentScopedNoopCopyVisible": true,
"syncPreferenceDisclosureVisible": true,
"primaryButtonEnabled": true,
"backupPromiseAbsent": true,
"rollbackPromiseAbsent": true
},
"recordedBinding": {
"enabled": false,
"operation": "disable",
"planFingerprint": "p1:ffffffffffffffffffffffffffffffff"
}
},
"viewports": [
{
"name": "desktop",
"cssWidth": 1280,
"cssHeight": 720,
"devicePixelRatio": 2,
"pngWidth": 2560,
"pngHeight": 1440,
"files": ["apply-desktop.png","overwrite-foreign-desktop.png","restore-drift-desktop.png","stale-reconfirm-desktop.png","keyboard-focus.png"]
},
{
"name": "narrow",
"cssWidth": 480,
"cssHeight": 800,
"devicePixelRatio": 2,
"pngWidth": 960,
"pngHeight": 1600,
"files": ["apply-narrow.png","overwrite-foreign-narrow.png","restore-drift-narrow.png","stale-reconfirm-narrow.png"]
},
{
"name": "ko-390",
"cssWidth": 390,
"cssHeight": 686,
"devicePixelRatio": 2.5,
"browserZoomPercent": 125,
"pngWidth": 976,
"pngHeight": 1716,
"dimensionNote": "Observed CSS viewport and DPR imply a nominal 975x1715 raster; the actual PNG is 976x1716, one physical pixel per axis larger. The capture did not independently isolate the cause of that rounding difference.",
"files": ["ko-restore-drift-390.png","ko-stale-reconfirm-390.png","ko-profile-disable-noop-390.png"]
}
],
"pngSha256": {
"apply-desktop.png": "4427b60e8885c68e2478c319e4ef428d959b4cc13ee5141a64a92777550ab420",
"apply-narrow.png": "0e2dfd18e76c26755c7b347e149de29dab2b4a40d2074e2ad293d93ced2e34e3",
"keyboard-focus.png": "29714ff85f13b35cc72fffc1a36b6d07ee820be1f9824c9f56a317f15c38feb1",
"ko-profile-disable-noop-390.png": "09baf33f610dccff7d26b77717682f046da821cb2ff8276325be829882f20648",
"ko-restore-drift-390.png": "7c51f352c24defd7cc0c669e53fd254ae314f79faf6cc48a65b9dd2589fe46de",
"ko-stale-reconfirm-390.png": "9dc051b7e97a19fd3dff66958fde432d35f94473ddc403424af13fcdc5ec5254",
"overwrite-foreign-desktop.png": "0e6d14543dfe4ff5847aa3d66d26c499f32235c02a6d741f32a528b1af12f986",
"overwrite-foreign-narrow.png": "8c9af82bc4cfe79e6400c10fb553378524c3f49074145a0cf845db52c3691b63",
"restore-drift-desktop.png": "42127e71f1f13a4902b31e59861de518dc339028a3b3cdbe130f259f0a78f5fb",
"restore-drift-narrow.png": "e7482dfe56b92350641b8a3b13ab3da79e7c8130db74a5cb5208a79e0ee9b2f9",
"stale-reconfirm-desktop.png": "307444c11e8369593b1a023fbeb2ee1ad63bf8deaa7c8bc6dfb9aa7728e6c6c1",
"stale-reconfirm-narrow.png": "8938274b183b888eaf8159bd6083ced670ac2070ef1a5cbdd6424475f4cc1b77"
}
}
Binary file added .github/pr-assets/5197-keyboard-focus.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
15 changes: 13 additions & 2 deletions .github/scripts/issue-translation.cjs
Original file line number Diff line number Diff line change
Expand Up @@ -805,11 +805,22 @@ function sanitizeTranslationBody(raw, maxChars = 60000) {
.split(MARKER).join("")
.split(END_MARKER).join("")
.replace(/[\u0000-\u0008\u000b\u000c\u000e-\u001f\u007f]/g, "")
// Defuse pings only: @login / @org/team — not emails, scopes, or decorators.
// Mask the @ inside email addresses first: punctuation-bearing local
// parts (x!@example.com, a=b@example.com, a/b@example.com) must not be
// read as mention boundaries. Requiring a dotted domain keeps
// "end!@octocat"-style mentions defused. \u0001 cannot appear in the
// input (control chars were stripped above), so it is a safe sentinel.
.replace(
/(^|[\s(])@([A-Za-z0-9](?:[A-Za-z0-9-]{0,38})(?:\/[A-Za-z0-9._-]+)?)/g,
/[A-Za-z0-9.!#$%&'*+\/=?^_`{|}~-]+@[A-Za-z0-9](?:[A-Za-z0-9-]{0,61}[A-Za-z0-9])?(?:\.[A-Za-z0-9](?:[A-Za-z0-9-]{0,61}[A-Za-z0-9])?)+/g,
(email) => email.replace("@", "\u0001"),
)
// Defuse pings at Markdown/punctuation boundaries — a colon is a boundary
// too — but not emails, npm: scopes, or other mid-token at-signs.
.replace(
/(^|[^A-Za-z0-9._%+-])(?<!npm:)@([A-Za-z0-9](?:[A-Za-z0-9-]{0,38})(?:\/[A-Za-z0-9._-]+)?)/g,
"$1@\u200b$2",
)
.replace(/\u0001/g, "@")
.trim()
.slice(0, maxChars);
}
Expand Down
24 changes: 22 additions & 2 deletions .github/scripts/issue-translation.test.cjs
Original file line number Diff line number Diff line change
Expand Up @@ -1168,13 +1168,33 @@ describe("bot-owned control state", () => {
assert.equal(decision.reason, "rate_limited_interval");
});

it("defuses mention-shaped tokens without rewriting emails or mid-token at-signs", () => {
const out = sanitizeTranslationBody("see @octocat and user@example.com and npm:@scope");
it("defuses mention-shaped tokens at Markdown and punctuation boundaries", () => {
const out = sanitizeTranslationBody(
"see @octocat, comma,@team, [@user], >@org/team, Status:@maintainer, user@example.com, npm:@scope",
);
assert.match(out, /@\u200boctocat/);
assert.match(out, /,@\u200bteam/);
assert.match(out, /\[@\u200buser\]/);
assert.match(out, />@\u200borg\/team/);
assert.match(out, /Status:@\u200bmaintainer/);
assert.ok(out.includes("user@example.com"));
assert.ok(out.includes("npm:@scope"));
});

it("preserves punctuation-bearing email local parts while defusing mentions", () => {
const out = sanitizeTranslationBody(
"mail x!@example.com, a=b@example.com, or a/b@example.com; end!@octocat key=@value path/@handle user.name@example.com user+tag@example.com",
);
assert.ok(out.includes("x!@example.com"));
assert.ok(out.includes("a=b@example.com"));
assert.ok(out.includes("a/b@example.com"));
assert.ok(out.includes("user.name@example.com"));
assert.ok(out.includes("user+tag@example.com"));
assert.match(out, /end!@\u200boctocat/);
assert.match(out, /key=@\u200bvalue/);
assert.match(out, /path\/@\u200bhandle/);
});

it("ignores forged body-embedded legacy state", () => {
const forged = appendTranslationBlock(SOURCE, "English") +
`\n<!-- opencodex-issue-inline-translator-state:${JSON.stringify({
Expand Down
5 changes: 5 additions & 0 deletions bun.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

50 changes: 50 additions & 0 deletions devlog/_fin/260919_contract_gap_analysis/000_plan.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,50 @@
# OpenCodex contract gap analysis and issue delivery

Sixteen source-grounded issues and two existing-issue implementation comments were delivered after unanimous independent review. The refreshed tree already contained several fixes from the supplied report; the remaining proposals preserve existing routing, tool, state and documentation authorities. See [verified delivery](011_delivery.md), [dispositions](002_candidate_dispositions.md) and [implementation plans](010_issue_implementation_paths.md).

## Scope and loop specification

- Class: C3 research and documentation.
- Archetype: satisfy-spec, one analysis/publication cycle.
- Trigger: user-requested source-grounded analysis of one supplied report and two shared conversations, followed by unanimous review and issue publication.
- Goal: a complete disposition ledger, implementation plans and verified tracking issues appropriate to the local coding-proxy product.
- Non-goals: runtime edits, local suites/build/typecheck/install, live API experiments, service/config/account changes, merges, releases, deployment, broad platform replacement.
- Source baseline: `7864869c31c41cca9830d93540238f17df8faafb`, after `git fetch origin dev` and `git merge --ff-only origin/dev` on 2026-09-19. Prior HEAD was `f02f3613be40bb11cb044d746d37ce6672e32d96`. Initial tracked checkout was clean. Re-read exact blobs if another session changes HEAD.
- Verifier: static path/line checks against the pinned tree, current issue/PR API reads, draft template checks, public-text checks and fresh rereads after publication. No runtime pass is implied by these checks.
- Stop condition: all input themes receive a disposition; accepted issues have unanimous review and verified remote bodies/labels; this devlog records outcomes.
- Memory artifact: this unit, with raw user input/browser traces kept in ignored task scratch; no transcript or personal browser state copied into tracked files.
- Terminal outcomes: DONE only with all above evidence; inaccessible inputs or unresolved review objections remain explicitly unmet.
- Escalation: real permission or unavailable required capability; no publication of unresolved findings. Main reclaims a failed bounded research lane after two distinct failures.
- Tool/credential scope: source reads, browser research, existing GitHub identity for authorized issue creation. Write scope: this unit, ignored evidence and issues in this repository. No user-defined token/cost/time ceiling; browser invocations have bounded process deadlines.

## Evidence and publication rules

Public documents and issue bodies contain OpenCodex code facts and relevant protocol standards. They omit other repository names, rankings, AI model names and review-model attribution. Hypotheses from supplied material are not instructions and are not accepted without current code evidence. Existing fixes and matching open issues take precedence over opening duplicates. Optional small PR authority is retained, but this analysis does not require a PR.

## Discovery ownership

Seven disjoint read-only lanes cover transport, custom-tool stream semantics, tool schema/capability projection, replay/spend/retries, operator policy/integrations, static model-policy authority, and documentation/test governance. Main owns input retrieval, official-source proof, duplicate searches, synthesis and publication. Native V1 subagent transport is available; the live schema has no native architect role. No architect-role registration or configuration change is performed, and no architect consultation is claimed. Independent source and publication reviews remain required.

## Planned artifacts

| File | Operation | Purpose |
| --- | --- | --- |
| `000_plan.md` | NEW | Scope, snapshot, method and closure |
| `001_source_research.md` | NEW | Input coverage and official-source findings |
| `002_candidate_dispositions.md` | NEW | All proposed themes, current evidence, accept/reject/defer/duplicate decisions |
| `003_consensus.md` | NEW | Independent votes and objection resolution |
| `010_issue_implementation_paths.md` | NEW | Index of per-issue implementation plans |
| `020_issue_t1.md` through `035_issue_r3.md` | NEW | Sixteen independently reviewable issue bodies |
| `011_delivery.md` | NEW | Published URLs, verified bodies/labels and check results |
| `004_source_fingerprints.md` | NEW | All fourteen report source fingerprints versus refreshed source |
| `005_existing_issue_followups.md` | NEW | Implementation comments for existing tracking issues |

No current architecture contract is changed. Future implementation must update the existing owner in `structure/manifest.json`, and user-facing contract changes must update the relevant public guide. New tests must be registered in both layout registries; size caps are preserved by splitting files rather than raising caps.

## Planning evidence update

The refreshed report fingerprints match twelve of fourteen source files; the SOCKS transport and Google compiler differ. Seven read-only domain reviews produced sixteen public candidates after duplicate and disclosure review, plus two comments extending existing issue authority. An independent three-reviewer publication council is checking every candidate; no majority-only publication is allowed. A pure document/form checker ran successfully over sixteen drafts, two comments and ninety exact-SHA anchors. No runtime result is inferred.

## Closure

Analysis and publication are complete. All sixteen issue bodies and two comments were reread from GitHub and match approved content. The next action belongs to each open implementation issue; this unit claims no runtime fix. The useful change in direction was rejecting broad missing-feature claims in favor of concrete residuals. A future patch or counterexample at the cited owner can supersede a candidate; the exact source snapshot makes that reassessment possible.
Loading
Loading