Skip to content

feat(release): add managed updates and Codex sharing checks for v4.0.1 - #47

Merged
muggle-stack merged 9 commits into
masterfrom
dev
Sep 22, 2026
Merged

muggle-stack merged 9 commits into
masterfrom
dev

Conversation

@muggle-stack

@muggle-stack muggle-stack commented Sep 22, 2026 •

Copy link
Copy Markdown
Owner

Installer-managed deployments currently require rerunning a role installer for every upgrade, and Codex daemon startup does not establish whether the daily CLI and Wrapper can share the same account endpoint. This adds cc-remote update and installation-time shared-connection checks, packaged as v4.0.1.

Changes

  • Discover stable releases, support check-only and pinned-version updates, validate role/platform/manifests and SHA-256, then reuse the immutable role installer and rollback transaction. Preserve service identity and configuration; guard concurrent updates, downgrades, self-restarting controllers, protocol changes and Claude service compatibility.
  • Prepare each Codex account's official daemon without restarting active native clients. Compare the service PATH CLI and Wrapper executable, verify the same account endpoint and versions, and initialize both transports without a model turn. Print a fresh activation-bound result; preserve explicit sharing opt-outs and report failures instead of silently using a private server.
  • Preserve existing macOS Wrapper environment settings. Register the management command in both role bundles and exercise it in release packaging smoke checks.
  • Serialize direct role installers and managed updates with the same per-installation lock. Validate inherited descriptors before protected operations, and retain the lock through activation and rollback even if the controller disconnects.
  • Acquire the installation lock and refresh the active release before reporting a normal update as already current. Keep check-only invocations read-only.
  • Resolve an explicitly selected role in both the shell launcher and installation discovery, so an unrelated damaged runtime or installation cannot block its update. Retain strict validation of the selected role and its standard directory.
  • Register the Relay management command before committing activation, so registration failures roll back the release and service configuration. Preserve the existing source-deployment path.
  • Register the Wrapper command after its interruptible readiness check and define the activation commit before printing completion output. Interrupted first installs leave no dangling registration, and output failures after commit preserve the installed release.
  • Set product and installer versions to 4.0.1 and add bilingual release notes. Wire protocol remains v72. Existing v4.0.0 tags and artifacts remain unchanged.

Upgrade behavior

v4.0.0 does not install the new command: users run the verified v4.0.1 installer once, then use cc-remote update for subsequent releases. Updates affect only the selected local role. Source, custom and Docker deployments retain their existing procedures; the independent Claude service is not restarted.

Codex checks establish transport readiness, not an already-open terminal's route or shell aliases. An existing private terminal finishes its task and is reopened normally. Codex App attachment remains separately opt-in. DSH, Electron and MCP computer use are outside this release.

Validation

  • Complete local gate with Node 24.21.0: pytest (4,926 passed, 4 platform skips), Ruff 0.15.13, Web build/reliability/lint, shell syntax, ShellCheck and git diff --check.
  • Built Web metadata matches backend product 4.0.1 and protocol v72; management CLI version/help checked.
  • Real Wrapper-entrypoint process tests cover direct-install/update exclusion, concurrent direct installs, inherited and forged descriptors, and lock lifetime. Native uv 0.11.16 preserves the inherited descriptor without releasing the parent's lock.
  • Concurrent no-op tests reproduce provisional activation, reject success while the installer holds its lock, and refresh state after a previous activation commits or rolls back.
  • Role selection tests cover broken unrelated metadata, current links and manifests for both roles, plus rejection of a mismatched role in the selected managed directory.
  • Real shell-launcher tests cover broken unrelated Python imports, missing selected runtimes, separate/equal/abbreviated role options, invalid roles, and last-option-wins behavior.
  • Fault injection through the actual Relay activation tail verifies that failed CLI registration restores the previous release, Caddy and systemd configuration; successful registration commits, and source deployments do not acquire managed-install metadata.
  • Actual Wrapper cleanup/finalization tests cover first installs and upgrades: TERM during readiness, successful registration, and output failure after activation commits. All service calls are stubbed; no live Wrapper is restarted.
  • First-install startup diagnostics for legacy and explicit multi-account profiles held the Codex probe pending while the actual installer migration verifier passed. Work registries are initialized by constructor-time profile migration/assignment before daemon prewarming; the later run() initialization is idempotent.
  • Native Codex 0.154.0 checks covered reuse of a running service and first startup with an isolated account. Ordinary codex resume, without endpoint overrides, connected to the isolated account's daemon; temporary processes were cleaned up. No model prompts were sent.
  • Six-platform artifact builds and packaged dependency/import checks run in the release workflow. Production services have not been deployed by this PR.

- Add stable release discovery, checked downloads and local role selection.
- Reuse immutable installers with update locking and compatibility guards.
- Register the management CLI and preserve macOS Wrapper environment settings.
- Document the upgrade path and cover failure and interruption handling.
- Validate the full local gate: 4855 pytest passes, 4 skips and Node 24 Web checks.
- Prepare account-scoped native daemons without restarting active clients.
- Verify CLI and Wrapper transports and report activation-bound readiness.
- Preserve disabled sharing and surface unavailable or mismatched connections.
- Align runtime, Web metadata and installer defaults with v4.0.1.
- Document managed updates, shared Codex checks and the v4.0.0 transition.
- Preserve protocol v72 and existing v4.0.0 release artifacts.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: dd96596cd5

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread cc_remote/update.py Outdated
- Share an exclusive installation lock across both role entrypoints.
- Verify inherited descriptors and retain locks through activation and rollback.
- Cover concurrent installers and updater handoff with process-level tests.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9bbf3cbeba

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread cc_remote/update.py Outdated
- Select the standard role directory before reading installation state.
- Keep unrelated damaged installations from blocking role-scoped updates.
- Reject mismatched role metadata and cover both roles with regression tests.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7acec89102

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread scripts/cc-remote
- Route Linux role-scoped updates to that role's installed Python entrypoint.
- Preserve option forms and ordering while refusing an unrelated fallback.
- Exercise the real launcher against broken and missing role runtimes.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: bc0753662d

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread deploy/install-relay.sh Outdated
- Include management command registration in the Relay activation transaction.
- Validate managed bundles before registering their command and metadata.
- Verify registration failure rolls back release, Caddy and service state.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ffe4804fe4

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread deploy/install-wrapper.sh Outdated
- Keep management registration after the interruptible Codex readiness check.
- Preserve committed activation when post-install output fails.
- Verify first-install and upgrade behavior with real TERM and output faults.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e3afd9d052

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread cc_remote/update.py Outdated
- Acquire the install lock before comparing the active and selected versions.
- Refresh the release under the lock and preserve read-only update checks.
- Cover concurrent activation and version changes before lock acquisition.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a56f11ead6

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread cc_remote/wrapper/machine.py
@muggle-stack
muggle-stack merged commit 0f72217 into master Sep 22, 2026
2 checks passed
@muggle-stack
muggle-stack deleted the dev branch September 23, 2026 07:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants