Skip to content

skill: make Codex inbox monitor idle-token free - #73

Merged
sumitake merged 23 commits into
mainfrom
dev/codex/codex-monitor-idle
Jul 28, 2026
Merged

skill: make Codex inbox monitor idle-token free#73
sumitake merged 23 commits into
mainfrom
dev/codex/codex-monitor-idle

Conversation

@sumitake

@sumitake sumitake commented Jul 28, 2026

Copy link
Copy Markdown
Owner

Summary

  • Release the public policy/plugin package as agent-collab 4.5.3.
  • Make new Codex inbox-monitor starts idle-token free: retain the canonical
    leased local process at its existing 10-second interval, but create no new
    Codex goal or recurring model-level continuation for liveness.
  • Check monitor state only on real activation, event, status, stop, or failure
    turns. Legacy cleanup requires closed same-turn structured-transcript proof
    and completes a goal only after the host proves the exec survives
    independently.
  • Report degraded_no_event_wake when the local process is live but the host
    has not proven an event-driven model wake, or
    legacy_goal_detach_unavailable when safe legacy detachment is unproven.
  • Constrain every residual pre-4.5.3 goal continuation to no exec/state poll or
    lifecycle mutation, and return stop_incomplete_legacy_goal instead of
    claiming a full stop when the host cannot safely bind and end the old goal.
  • Preserve the existing Claude, Antigravity, shared armed, singleton
    inspection, and continuation-status contracts.
  • Build on merged public broker/client PR runtime: separate broker activity from persistence #70 and its released 4.5.2 source
    state.

Exact final artifact

Boundary declaration

  • No provider executor source, raw provider command, credential, private
    absolute path, retired package tree, downloader, or post-install hook is
    included.
  • No native-runtime artifact or verification metadata changes are included.
  • The change does not create a host-specific preset or provider-specific
    plugin.
  • No live monitor, installed plugin, release tag, or Codex session is
    mutated by this source change.

Generated and release surfaces

  • Skill specs and generated SKILL.md files are in parity.
  • Claude and Codex marketplaces/manifests are in parity.
  • A unique changelog.d/ fragment is present; generated CHANGELOG.md
    remains unchanged under the fragment-only convention.
  • Version metadata is bumped from 4.5.2 to 4.5.3.

Verification

  • Focused monitor regression suite — 13 passed
  • Full public test suite — 608 passed
  • Script test suite — 254 passed
  • python3 -B scripts/build_skills.py --check
  • python3 -B scripts/build_marketplace.py --check
  • python3 -B scripts/build-changelog.py --dry-run
  • python3 -B scripts/check_release_consistency.py
  • python3 -B scripts/secret_scan.py — 330 source files clean
  • python3 -B scripts/check-public-export-safety.py --active-tree
  • Fresh full-clone
    python3 -B scripts/check-public-export-safety.py --active-tree --history
  • git diff --check
  • Claude and Antigravity source sections are byte-identical to the 4.5.2
    base; SHA-256
    d4765bfc8ea2240f8886250ec7c81fef40f3c175e2b0d04af2b6a0811ea55aec
  • No runtime bundle, manifest, or runtime-client path appears in the diff.

Independent exact-artifact review

  • Round 1 — xAI/Grok 4.5 RECONSIDER: found that the initial Codex-only wake
    policy had leaked into shared lifecycle semantics and that tripwire coverage
    was incomplete. The valid findings were integrated with RED/GREEN commits.
  • Round 2 — request
    agent-collab-pr73-exact-grok-review-20260728-round2, xAI/Grok 4.5,
    read-only governance authority, typed status=ok, severity None.
  • That reviewer explicitly verified restored non-Codex contracts,
    Codex-only degradation on startup and busy-lease adoption, goal-free
    zero-idle behavior, the bounded legacy tripwire, conditional model/effort
    advice, and focused regression coverage.
  • Rebasing onto merged PR runtime: separate broker activity from persistence #70 preserved all 11 patches exactly under
    git range-diff, but changed the commit identity and binary diff digest.
    The stacked-head approval is therefore superseded.
  • Round 3 — request
    agent-collab-pr73-final-exact-grok-review-20260728-2, xAI/Grok 4.5,
    read-only governance authority, typed status=ok: found that the legacy
    fingerprint and goal/exec detach safety were underspecified, the shared
    already_armed description needed its Codex exception, and tests needed
    exact positive and negative legacy fixtures. All valid findings were
    integrated in signed RED/GREEN commits.
  • A subsequent current-head GitHub automated review correctly found that the
    old skill required semantic fields but did not prescribe one literal
    objective paragraph. The text-only fingerprint was replaced by a closed
    same-turn structured-transcript proof over the original skill read,
    get_goal, explicit-start state, create_goal, canonical exec launch,
    retained exec ID, and startup anchors; transcript prose is untrusted data.
  • Round 4 — request
    agent-collab-pr73-final-exact-grok-review-20260728-3, xAI/Grok 4.5,
    read-only governance authority, typed status=ok: found that safe legacy
    detach failure left later empty turns and explicit-stop handling
    underspecified, while public wording overclaimed the upgraded-session path.
    All valid findings were integrated with an every-turn no-poll/no-mutation
    decision table, bounded transcript reads, explicit legacy-goal stop results,
    honest release wording, and RED/GREEN regression coverage.
  • Round 5 — request
    agent-collab-pr73-final-exact-grok-review-20260728-4, xAI/Grok 4.5,
    read-only governance authority, typed status=ok: its claimed missing
    Seen-files path assertion was contradicted by the exact Codex startup
    bullet and rejected. Its valid stop-authority and stale-design findings were
    integrated: stop now targets only monitor-bound retained exec identifiers,
    never other session execs, and the design requires fail-closed handling on
    every legacy continuation.
  • Round 6 exact-head request
    agent-collab-pr73-final-exact-grok-review-20260728-5, xAI/Grok 4.5,
    read-only governance authority, reviewed head
    e690e6b59ba3aebe6376d222d44403ab7525e6eb and artifact
    1dbb8561b8f2ea530ade46805d32e027c2a8908f8336efa020168cdb426251b4;
    typed status=ok with valid raw JSONL severity None.
  • Subsequent current-head GitHub automated review found two valid legacy-proof
    gaps: the old skill used status during automatic activation, not only
    explicit start, and a structurally matching turn still needed the old
    objective's session, scope, routing-exclusion, and no-scheduling semantics.
    Both were integrated as trigger-matched state alternatives and necessary
    objective fields with fail-closed table cases and RED/GREEN coverage.
  • Round 7 exact-head request
    agent-collab-pr73-final-exact-grok-review-20260728-6, xAI/Grok 4.5,
    read-only governance authority, reviewed head
    4281a2528a26f4a1f8f8b64530fb419afa670ba5 and artifact
    b813e51693661b91934a4f86a76554bb46431214e09135a0106ea97d081eaff6;
    typed status=ok with valid raw JSONL severity None.
  • A delayed current-head GitHub review then found that historical startup and
    retained control did not prove the monitor was still running at detach time.
    The valid finding was integrated: safe detach now requires attached positive
    current liveness for the exact retained exec or lease-owning process;
    absent, stale, ambiguous, or terminal evidence leaves both lifecycles
    untouched without a poll.
  • Final exact-head review — Anthropic Claude Opus 4.8 at high effort,
    synchronous read-only direct CLI with tools disabled and no session
    persistence, outside the broker/coordinator path — reviewed head
    2753afb8c6bdd482e70b206c069aca00c222ec36 and the exact 109,860-byte
    artifact
    125521a1050e6365f166e1350b5d195af41ae39b7a7991326674cf51ee912fe2;
    typed verdict APPROVE with zero Critical and zero Important findings.
  • Two Minor plan-document findings were adjudicated as nonblocking: the
    historical implementation plan retains an earlier “first empty
    continuation” phrase and an illustrative RED-test snippet, while the
    normative skill, design, generated skill, and committed regression tests
    consistently require the stronger every-empty-continuation rule. Reviewed
    source bytes were left unchanged.

Review and post-condition

Tier 2: this is a compatible user-visible skill/policy change. Merge only after
the final independent-family exact-head review, required CI, and a
MERGE-ELIGIBLE local compliance result. Stop at source merge: do not tag,
release, install, restart Codex, or mutate the live monitor in this task.

Compliance trace

author: codex
standing_directives: read and followed public AGENTS.md, docs/public-governance.md, generated parity, fragment-only changelog, signed-commit, exact-head validation, and public-source boundary requirements
tier: 2
cross_check: PROCEED - Anthropic Claude Opus 4.8 high-effort read-only direct exact-artifact review APPROVE with zero Critical or Important findings for head 2753afb, 109860 bytes, SHA-256 125521a1050e6365f166e1350b5d195af41ae39b7a7991326674cf51ee912fe2; two Minor historical-plan documentation findings adjudicated nonblocking
post_condition: stop at source merge with no tag, release, installed-plugin refresh, Codex restart, or live-monitor mutation
mcp_coverage_gap: NONE
contributor_rights: OWNER-AUTHORED
operator_reserved: no

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4ceeee70ac

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread skill-specs/start-inbox-monitor.md Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 64359e860f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread skill-specs/start-inbox-monitor.md Outdated
@sumitake

Copy link
Copy Markdown
Owner Author

Distinct-family review trace for exact stacked head a3cd50b44a1c90eaa1099d9214bd6dd9b4c21ee9 (artifact 77,707 bytes, SHA-256 734ea37a501a46de1a244787f59f927138fd27847962155cc135866472e0bef9):

  • Round 1 — xAI/Grok 4.5 RECONSIDER: correctly found that Codex-only wake semantics had leaked into shared armed, singleton inspection, and continuation-status behavior, and that tripwire tests were incomplete. Those findings were integrated. The suggestion that Antigravity successful startup should map to shared armed was rejected because its existing live contract is intentionally degraded_no_heartbeat.
  • Round 2 — request agent-collab-pr73-exact-grok-review-20260728-round2, typed status=ok, read-only governance provenance, severity None. It explicitly verified the restored non-Codex contracts, Codex-only degradation on startup and busy-lease adoption, goal-free zero-idle behavior, bounded tripwire, conditional model/effort advice, and focused regression coverage.

If rebasing after PR #70 changes the final head, this verdict will be treated as stale and the exact-head review gate will run again before merge.

@sumitake
sumitake force-pushed the dev/codex/dispatcher-idle-grace-status branch 2 times, most recently from d075e61 to 1f2fb48 Compare July 28, 2026 09:26
Base automatically changed from dev/codex/dispatcher-idle-grace-status to main July 28, 2026 10:01
@sumitake
sumitake force-pushed the dev/codex/codex-monitor-idle branch from a3cd50b to 6cd6700 Compare July 28, 2026 10:05

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8e9279edf5

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread skill-specs/start-inbox-monitor.md Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c865cf1bf9

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread skill-specs/start-inbox-monitor.md Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b5d79f5f05

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread skill-specs/start-inbox-monitor.md Outdated
@sumitake

Copy link
Copy Markdown
Owner Author

Final independent exact-head governance evidence: request agent-collab-pr73-final-exact-grok-review-20260728-5 reviewed head e690e6b59ba3aebe6376d222d44403ab7525e6eb, exact diff 103,760 bytes, SHA-256 1dbb8561b8f2ea530ade46805d32e027c2a8908f8336efa020168cdb426251b4; typed status=ok, valid raw JSONL severity None. Local verification: 13 focused, 608 public, and 254 script tests passed; generated parity, release consistency, secret scan, active-tree safety, and fresh-clone history safety passed.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4281a2528a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread skill-specs/start-inbox-monitor.md Outdated
@sumitake

Copy link
Copy Markdown
Owner Author

Superseding final review evidence after integrating the two current-head GitHub findings: request agent-collab-pr73-final-exact-grok-review-20260728-6 reviewed head 4281a2528a26f4a1f8f8b64530fb419afa670ba5, exact diff 107,230 bytes, SHA-256 b813e51693661b91934a4f86a76554bb46431214e09135a0106ea97d081eaff6; typed status=ok, valid raw JSONL severity None. The proof now accepts trigger-matched automatic status and requires the old objective’s session/scope/routing-exclusion/no-scheduling semantics.

@sumitake

Copy link
Copy Markdown
Owner Author

Final independent exact-artifact review evidence

  • Reviewer: Anthropic Claude Opus 4.8, high effort
  • Route: synchronous read-only direct CLI; --safe-mode, tools disabled,
    plan permission mode, no session persistence; no broker/coordinator slot
  • Head: 2753afb8c6bdd482e70b206c069aca00c222ec36
  • Base: 1687f89736f0ed4a862fed8f10893a0fb9c58b4d
  • Artifact: 109,860 bytes
  • SHA-256:
    125521a1050e6365f166e1350b5d195af41ae39b7a7991326674cf51ee912fe2
  • Typed terminal: process return code 0, schema-bound
    verdict: APPROVE
  • Findings: 0 Critical, 0 Important, 2 Minor

The reviewer confirmed the 11 requested contracts: goal-free new Codex starts,
zero idle model turns for new starts while preserving the local 10-second
process, fail-closed per-turn handling of legacy empty continuations, bounded
structured transcript proof, attached positive current-liveness proof before
detach, scoped stop authority, honest legacy residual wording, and unchanged
Claude/Antigravity behavior.

Minor adjudication: both findings concern the non-normative historical
implementation plan—an earlier “first empty continuation” phrase and an
illustrative RED-test snippet. The normative skill spec, generated skill,
design, and committed tests consistently require the stronger “every empty
legacy continuation” rule. They are therefore recorded as nonblocking and the
reviewed bytes remain unchanged.

Strongest counterargument recorded by the reviewer: enforcement is primarily
through instruction-text contracts and substring regression tests rather than
an executable host-behavior harness, so actual host adherence remains a
runtime residual risk. The reviewer nevertheless found the normative contract
appropriately fail-closed and approved the artifact.

@sumitake
sumitake merged commit 35a5c47 into main Jul 28, 2026
18 checks passed
@sumitake
sumitake deleted the dev/codex/codex-monitor-idle branch July 28, 2026 11:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant