Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
145 commits
Select commit Hold shift + click to select a range
307d2c3
feat: add Codex Micro Linux support
Jul 24, 2026
d893898
fix: reject symlinked Micro package ancestors early
Jul 25, 2026
de01891
Fix Codex Micro path safety and setup docs
ilysenko Jul 25, 2026
62a2b04
Make Codex Micro drift checks fail closed
ilysenko Jul 25, 2026
0f61938
Tighten Codex Micro gate matching
ilysenko Jul 25, 2026
2e6a9ce
Deduplicate Codex Micro symlink coverage
ilysenko Jul 25, 2026
ef58e46
Merge pull request #1151 from niogyn/codex/codex-micro-stage2
ilysenko Jul 25, 2026
a61fb28
chore(nix): update tar to 7.5.22
danielcadev Jul 25, 2026
ef284ae
Merge pull request #1154 from danielcadev/agent/refresh-nix-tar-depen…
ilysenko Jul 25, 2026
a7cc604
fix(computer-use): recognize Arch ydotool CLI
KamilBeda Jul 25, 2026
4b0d5f6
fix(computer-use): probe required ydotool semantics
KamilBeda Jul 25, 2026
2b921dc
Preserve acceptance source provenance on early failures
ilysenko Jul 26, 2026
1a8d18b
Merge pull request #1157 from ilysenko/codex/issue-1155-preserve-acce…
ilysenko Jul 26, 2026
4842dc7
Preserve ydotool probing without XDG runtime
Yo-DDV Jul 26, 2026
3723bc5
Merge pull request #1156 from kortylokai-web/fix/arch-ydotool-cli-det…
ilysenko Jul 26, 2026
8c6a945
test(launcher): add resident window-reopen behavior harness (#1147)
TanguyDeTaxis Jul 26, 2026
bc7b92c
Fix Computer Use plugin details for 26.721 (#1159)
DmytroMitin Jul 26, 2026
49afa21
fix(lifecycle): prevent windowless warm-start survivors
kortylokai-web Jul 26, 2026
08f0b76
Merge pull request #1160 from kortylokai-web/codex/fix-windowless-war…
ilysenko Jul 27, 2026
71be795
Add per-connection SSH command wrappers (#1161)
yanis-falaki Jul 27, 2026
c6d7623
Harden SSH command-wrapper patching (#1162)
yanis-falaki Jul 27, 2026
1fae9a4
Stabilize Dock settings contract matching
PinguuSS Jul 28, 2026
a8d0abb
Test Dock settings contract ambiguity
PinguuSS Jul 28, 2026
1193364
Reject mixed Dock settings contracts
PinguuSS Jul 28, 2026
32c231f
Merge pull request #1164 from PinguuSS/build/stabilize-dock-settings-…
ilysenko Jul 28, 2026
14989e8
HEROX-1165: Fix current DMG optional feature patch drift
ilysenko Jul 28, 2026
84f79e9
Merge pull request #1167 from ilysenko/codex/issue-1165-feature-patch…
ilysenko Jul 28, 2026
0186de6
Fix Linux desktop settings navigation grouping
magicJie Jul 29, 2026
9571e45
Merge pull request #1169 from magicJie/codex/sync-linux-desktop-navig…
ilysenko Jul 29, 2026
df41b3e
Recover stale npm Codex CLI upgrades (#1166)
PinguuSS Jul 29, 2026
9148083
fix(nix): refresh upstream Nix pins for 26.721.81911 (#1172)
github-actions[bot] Jul 29, 2026
65bc0b7
fix(remote-mobile-control): retarget current gate bridge
MatsumotoMorami Jul 29, 2026
ecbe128
Fix latest-DMG Arch bootstrap failures (#1173)
moxw Jul 29, 2026
586c20e
Merge pull request #1174 from MatsumotoMorami/codex/fix-remote-gate-b…
ilysenko Jul 29, 2026
0049083
HEROX-1175: Complete Linux Sparkle shim contract
ilysenko Jul 29, 2026
dc479a4
Merge pull request #1177 from ilysenko/codex/issue-1175-sparkle-contract
ilysenko Jul 29, 2026
2e17d47
fix(updater): complete Linux Sparkle menu contract
MatsumotoMorami Jul 29, 2026
042adb7
Merge pull request #1179 from MatsumotoMorami/codex/fix-linux-sparkle…
ilysenko Jul 29, 2026
5b74648
fix(window): require managed context-menu suppression
MatsumotoMorami Jul 29, 2026
b77f345
Fix current Linux open target command lookup (#1176)
PinguuSS Jul 29, 2026
c9c3275
fix(window): scope context menu suppression to GNOME X11
MatsumotoMorami Jul 29, 2026
b48075d
fix Codex Micro hot-plug discovery (#1186)
RoeeJ Jul 30, 2026
201ab4c
Fix upstream DMG drift (#1188)
ilysenko Jul 30, 2026
efe4917
fix(nix): refresh upstream Nix pins for 26.727.40816 (#1189)
github-actions[bot] Jul 30, 2026
689fc5b
Fix optional upstream DMG drift (#1191)
ilysenko Jul 31, 2026
dec2ddb
Fix shallow repository watches for current DMG (#1192)
nakasyou Jul 31, 2026
0f3ffbf
Keep current feature composition idempotent on second pass (#1184)
PinguuSS Jul 31, 2026
5f2db13
test: cover current Dock icon main contract
PinguuSS Jul 31, 2026
373c2ae
fix: retarget Dock icon to current main bundle
PinguuSS Jul 31, 2026
a73ef0a
Merge main and refresh GNOME/X11 context-menu patch
ilysenko Jul 31, 2026
afb0aef
Clarify managed-window patch ownership
ilysenko Jul 31, 2026
5b30c77
Merge pull request #1180 from MatsumotoMorami/codex/fix-gnome-x11-tit…
ilysenko Jul 31, 2026
d3c7baa
Merge pull request #1193 from PinguuSS/build/retarget-dock-icon-26-727
ilysenko Jul 31, 2026
94bea84
fix(computer-use): harden input and compositor handling
avifenesh Jul 31, 2026
1a93139
chore(computer-use): sync standalone v0.4.4 metadata
avifenesh Jul 31, 2026
cc239f8
fix(computer-use): complete input safety and compositor mapping
avifenesh Jul 31, 2026
9825ca6
fix(nix): refresh upstream Nix pins for 26.727.51351 (#1195)
github-actions[bot] Aug 1, 2026
c566ca1
chore(computer-use): sync standalone v0.4.5 metadata
avifenesh Aug 1, 2026
89b0651
Fix Chrome plugin install cache collision
ilysenko Aug 1, 2026
7fb9c81
Update Chrome extension metadata handling
ilysenko Aug 1, 2026
6591344
Harden Chrome plugin cache before host registration
ilysenko Aug 1, 2026
2056f2a
Align Chrome native host with app-server registry
ilysenko Aug 1, 2026
cef67b8
fix: restore AppImage window after remount (#1196)
walid-baharwal Aug 1, 2026
bef6f1b
Harden Chrome plugin runtime registration
ilysenko Aug 1, 2026
fa15591
Preserve Chrome runtime registry cleanup
ilysenko Aug 1, 2026
4f4bb87
Make Chrome runtime bridge replacement atomic
ilysenko Aug 1, 2026
e6572ae
Stabilize Chrome runtime smoke assertion
ilysenko Aug 1, 2026
6941c58
fix: use launched desktop entry for approval notification icons
Naerelyth Aug 1, 2026
2918e2c
fix: validate notification desktop entry launch PID
Naerelyth Aug 1, 2026
bfc0f3e
Merge pull request #1197 from ilysenko/codex/fix-chrome-plugin-instal…
ilysenko Aug 1, 2026
e84ed80
Merge pull request #1200 from Naerelyth/fix-approval-notification-icon
ilysenko Aug 1, 2026
75398cf
fix: bound Linux quit cleanup lifetime
ilysenko Aug 1, 2026
3439e76
test: verify stalled quit cleanup still finalizes
ilysenko Aug 1, 2026
06a84a8
test: harden Linux quit patch verification
ilysenko Aug 1, 2026
e639b10
fix: verify both Linux quit cleanup branches
ilysenko Aug 1, 2026
c396605
fix: validate Linux quit cleanup structure
ilysenko Aug 1, 2026
db690bb
test: preserve damaged quit helper shape
ilysenko Aug 1, 2026
c458119
Merge pull request #1201 from ilysenko/codex/fix-quit-icon-survivor
ilysenko Aug 1, 2026
d59fd70
test(computer-use): keep cursor socket path bounded
ilysenko Aug 2, 2026
19ffd28
HEROX-1202: Fix remote mobile Desktop app-server patch
ilysenko Aug 2, 2026
81238ab
HEROX-1202: Verify complete Desktop patch state
ilysenko Aug 2, 2026
75fa8ca
fix(computer-use): retain input safety through cancellation
ilysenko Aug 2, 2026
8dfcd29
fix(computer-use): prevent ambiguous input replay
ilysenko Aug 2, 2026
7e54a0c
Merge pull request #1204 from ilysenko/codex/issue-1202-local-app-ser…
ilysenko Aug 2, 2026
ec38ca6
Merge pull request #1194 from avifenesh/fix/computer-use-input-safety
ilysenko Aug 2, 2026
e8b6bf6
fix(updater): use scope-safe module imports
boommasterxd Aug 3, 2026
62e1617
project-group-last-updated-sort: retarget Codex 26.727 sorter symbols
moxw Aug 3, 2026
2a142b2
shared-app-server-socket: refresh current-DMG SSH transport matcher
moxw Aug 3, 2026
187ecf9
Merge pull request #1210 from moxw/codex/fix-26-727-enabled-feature-d…
ilysenko Aug 3, 2026
ab31492
Merge pull request #1208 from boommasterxd/fix/updater-scope-safe-imp…
ilysenko Aug 3, 2026
a4bec72
Document Raspberry Pi 5 validation
prichardsondev Aug 3, 2026
e23e074
fix(updater): preserve feature picker settings (#1211)
PinguuSS Aug 3, 2026
0f088bd
Record unavailable Pi optional capabilities
prichardsondev Aug 3, 2026
ddf84a0
Merge pull request #1212 from prichardsondev/agent/raspberry-pi-5-val…
ilysenko Aug 3, 2026
c4e5b5a
Correct Raspberry Pi Computer Use results
prichardsondev Aug 3, 2026
943693f
Record persistent Pi test artifact
prichardsondev Aug 3, 2026
85e71d4
Clean up orphaned shared app-server authorities (#1209)
moxw Aug 3, 2026
9f4a5ed
Clarify manual Labwc window control
prichardsondev Aug 3, 2026
717a981
Merge pull request #1214 from prichardsondev/agent/document-pi-comput…
ilysenko Aug 3, 2026
8b8daf9
fix(updater): ignore documentation-only wrapper changes
boommasterxd Aug 3, 2026
7166d11
Merge pull request #1217 from boommasterxd/fix/wrapper-ignore-doc-onl…
ilysenko Aug 4, 2026
21472a2
fix(api-key-model-visibility): match refactored upstream model gate
agentixsoftware Aug 4, 2026
39b4c43
fix(nix): refresh upstream Nix pins for 26.730.61309 (#1221)
github-actions[bot] Aug 5, 2026
111ec9d
Fix optional upstream DMG drift (#1222)
ilysenko Aug 5, 2026
2253b46
fix(nix): refresh upstream Nix pins for 26.730.61639 (#1223)
github-actions[bot] Aug 5, 2026
3a7eb3b
Fix optional upstream DMG drift (#1224)
ilysenko Aug 5, 2026
ee3f570
sync(computer-use): port standalone v0.4.6 (#1220)
avifenesh Aug 5, 2026
f7e84de
Docs/add simplified chinese readme (#1228)
FuHao0119 Aug 5, 2026
1e4e114
fix(remote-control): keep outbound tab visible on Linux (#1226)
huaixv Aug 5, 2026
8acb015
fix(api-key-model-visibility): address review feedback
ilysenko Aug 5, 2026
e939421
Merge pull request #1218 from agentixsoftware/fix/api-key-model-visib…
ilysenko Aug 5, 2026
61b6755
Fix Chrome plugin env compatibility and cache refresh
jadabreu Aug 5, 2026
b78154d
fix: CVE-2026-13697 security vulnerability
anupamme Aug 5, 2026
f3d144f
fix: scope undici 7.29.0 override to @electron/get (CVE-2026-13697)
anupamme Aug 5, 2026
e78ddeb
Make Chrome cache promotion failure-safe
jadabreu Aug 5, 2026
6aa19ed
updater: defer background builds behind user toggle
moxw Aug 5, 2026
65ce021
project-group-last-updated-sort: retarget Codex 26.730 sorter symbols
moxw Aug 5, 2026
366574a
updater: bundle check cycle options
moxw Aug 5, 2026
20825ea
Merge pull request #1230 from jadabreu/codex/fix-chrome-plugin-env-cache
ilysenko Aug 5, 2026
db7e54d
test: cover current Dock icon main contract
PinguuSS Aug 5, 2026
969f96e
fix: retarget Dock icon to current desktop bundle
PinguuSS Aug 5, 2026
a999a08
test: harden current Dock contract drift coverage
PinguuSS Aug 5, 2026
3b39665
Merge pull request #1231 from anupamme/fix-repo-codex-desktop-linux-c…
ilysenko Aug 5, 2026
424bd4c
Merge pull request #1234 from moxw/codex/fix-26-730-project-sort
ilysenko Aug 5, 2026
0bf7f41
Merge pull request #1235 from PinguuSS/build/retarget-dock-watchdog-2…
ilysenko Aug 5, 2026
2d0d4bd
updater: make deferred builds opt-in and revalidate DMGs
moxw Aug 5, 2026
1cfca15
fix(shared-app-server-socket): support systemd user adoption
kortylokai-web Aug 5, 2026
3c0427e
Merge pull request #1236 from kortylokai-web/codex/fix-systemd-user-s…
ilysenko Aug 5, 2026
e1d339e
updater: preserve deferred candidates across stale launch checks
moxw Aug 6, 2026
9db2ba5
updater: resume deferred builds after stale launch checks
moxw Aug 6, 2026
f20d825
Merge pull request #1233 from moxw/codex/auto-build-update-toggle
ilysenko Aug 6, 2026
df725ad
fix(directory-watch): route current Parcel working tree (#1238)
gadicc Aug 6, 2026
be1acdb
Fix upstream DMG drift (#1242)
ilysenko Aug 7, 2026
06d4209
Fix optional upstream DMG drift (#1245)
ilysenko Aug 7, 2026
07dc1a3
Fix Linux tray startup and watchdog metadata (#1247)
ilysenko Aug 7, 2026
4d429d7
project-group-last-updated-sort: retarget patch to 26.803 bundle (#1248)
moxw Aug 7, 2026
1399932
fix: bump rustls-webpki 0.103.10 → 0.103.13 (GHSA-82j2-j2ch-gfr8) (#1…
anupamme Aug 7, 2026
9a4cc39
browser-runtime: preserve Linux hooks across runtime clone (#1250)
moxw Aug 7, 2026
f33377f
fix(chrome): support concurrent browser clients (#1240)
Eeeeye Aug 7, 2026
d48fa56
Fix Nix PipeWire microphone support (#1249)
0xdeafbeef Aug 7, 2026
2c95511
fix(browser-use): re-target the IAB socket listing filter
jurgenmahn Aug 7, 2026
b7b81f7
fix(computer-use): re-target the settings card injection
jurgenmahn Aug 7, 2026
ffceae0
Merge pull request #1251 from jurgenmahn/fix/26.803-drift-patches
ilysenko Aug 8, 2026
e61ab2f
Merge remote-tracking branch 'upstream/main' into fix/upstream-26.803…
robustonian Aug 8, 2026
7c652d2
fix: harden latest DMG rebuild startup
robustonian Aug 8, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
99 changes: 99 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,7 @@ jobs:
bash -n scripts/build-rpm.sh
bash -n scripts/build-pacman.sh
bash -n scripts/build-appimage.sh
bash -n scripts/ci/download-upstream-dmg.sh
bash -n scripts/ci/update-nix-hashes.sh
bash -n scripts/ci/validate-nix-pins.sh

Expand Down Expand Up @@ -143,6 +144,40 @@ jobs:
echo "- Verified generic feature resource, 0640 mode, and runtime dependency."
} >> "$GITHUB_STEP_SUMMARY"

- name: Create Codex Micro packaged app fixture
env:
CODEX_FIXTURE_LINUX_FEATURES_JSON: '["codex-micro"]'
run: |
set -euo pipefail
rm -rf codex-app dist
tests/fixtures/create-packaged-app-fixture.sh codex-app
printf '%s\n' '{"enabled":["codex-micro"]}' > /tmp/codex-micro-features.json

- name: Build Codex Micro Debian package
env:
CODEX_LINUX_FEATURES_CONFIG: /tmp/codex-micro-features.json
run: PACKAGE_VERSION="$CI_PACKAGE_VERSION" ./scripts/build-deb.sh

- name: Inspect Codex Micro Debian package
run: |
set -euo pipefail
deb_file="$(find dist -maxdepth 1 -name 'codex-desktop_*.deb' -print -quit)"
test -n "$deb_file"
dpkg-deb -c "$deb_file" | tee /tmp/deb-micro-contents.txt >/dev/null
dpkg-deb -f "$deb_file" Depends | tee /tmp/deb-micro-depends.txt >/dev/null
grep -q './usr/lib/udev/rules.d/70-codex-micro.rules' /tmp/deb-micro-contents.txt
grep -q 'libudev1' /tmp/deb-micro-depends.txt
grep -q 'libusb-1.0-0' /tmp/deb-micro-depends.txt
rule_mode="$(
awk '$NF == "./usr/lib/udev/rules.d/70-codex-micro.rules" { print $1 }' \
/tmp/deb-micro-contents.txt
)"
test "$rule_mode" = '-rw-r--r--'
{
echo "- Codex Micro build: \`$(basename "$deb_file")\`"
echo "- Verified udev rule, 0644 mode, and libudev/libusb dependencies."
} >> "$GITHUB_STEP_SUMMARY"

nix:
name: Nix Package Builds
runs-on: ubuntu-latest
Expand Down Expand Up @@ -257,6 +292,7 @@ jobs:
.#codex-desktop-computer-use-ui
.#codex-desktop-remote-mobile-control
.#codex-desktop-computer-use-ui-remote-mobile-control
.#checks.x86_64-linux.nix-pipewire-alsa-wrapper
.#checks.x86_64-linux.nix-gsettings-schema-wrapper
.#checks.x86_64-linux.watchdog-linux-features
)
Expand Down Expand Up @@ -363,6 +399,41 @@ jobs:
echo "- Verified generic feature resource, 0640 mode, and runtime dependency."
} >> "$GITHUB_STEP_SUMMARY"

- name: Create Codex Micro packaged app fixture
env:
CODEX_FIXTURE_LINUX_FEATURES_JSON: '["codex-micro"]'
run: |
set -euo pipefail
rm -rf codex-app dist
tests/fixtures/create-packaged-app-fixture.sh codex-app
printf '%s\n' '{"enabled":["codex-micro"]}' > /tmp/codex-micro-features.json

- name: Build Codex Micro RPM package
env:
CODEX_LINUX_FEATURES_CONFIG: /tmp/codex-micro-features.json
run: PACKAGE_VERSION="$CI_PACKAGE_VERSION" ./scripts/build-rpm.sh

- name: Inspect Codex Micro RPM package
run: |
set -euo pipefail
rpm_file="$(find dist -maxdepth 1 -name 'codex-desktop-*.rpm' -print -quit)"
test -n "$rpm_file"
rpm -qlp "$rpm_file" | tee /tmp/rpm-micro-contents.txt >/dev/null
rpm -qlvp "$rpm_file" | tee /tmp/rpm-micro-long-contents.txt >/dev/null
rpm -qp --requires "$rpm_file" | tee /tmp/rpm-micro-requires.txt >/dev/null
grep -q '/usr/lib/udev/rules.d/70-codex-micro.rules' /tmp/rpm-micro-contents.txt
grep -q '^libudev\.so\.1' /tmp/rpm-micro-requires.txt
grep -q '^libusb-1\.0\.so\.0' /tmp/rpm-micro-requires.txt
rule_mode="$(
awk '$NF == "/usr/lib/udev/rules.d/70-codex-micro.rules" { print $1 }' \
/tmp/rpm-micro-long-contents.txt
)"
test "$rule_mode" = '-rw-r--r--'
{
echo "- Codex Micro build: \`$(basename "$rpm_file")\`"
echo "- Verified udev rule, 0644 mode, and libudev/libusb dependencies."
} >> "$GITHUB_STEP_SUMMARY"

package-pacman:
name: Build Pacman Package
runs-on: ubuntu-latest
Expand Down Expand Up @@ -426,21 +497,49 @@ jobs:
fixture_mode="$(sed -n "1s/ .*//p" /tmp/pacman-feature-long-contents.txt)"
test "$fixture_mode" = "-rw-r-----"
printf "%s\n" "$(basename "$feature_pkg_file")" > /tmp/pacman-feature-package-name.txt

rm -rf codex-app dist
CODEX_FIXTURE_LINUX_FEATURES_JSON="[\"codex-micro\"]" \
tests/fixtures/create-packaged-app-fixture.sh codex-app
printf "%s\n" "{\"enabled\":[\"codex-micro\"]}" \
> /tmp/codex-micro-features.json

CODEX_LINUX_FEATURES_CONFIG=/tmp/codex-micro-features.json \
PACKAGE_VERSION="$CI_PACKAGE_VERSION" \
./scripts/build-pacman.sh

micro_pkg_file="$(find dist -maxdepth 1 -name "codex-desktop-*.pkg.tar.*" -print -quit)"
test -n "$micro_pkg_file"
pacman -Qlp "$micro_pkg_file" | tee /tmp/pacman-micro-contents.txt >/dev/null
tar -xOf "$micro_pkg_file" .PKGINFO | tee /tmp/pacman-micro-pkginfo.txt >/dev/null
tar -tvf "$micro_pkg_file" \
usr/lib/udev/rules.d/70-codex-micro.rules \
| tee /tmp/pacman-micro-long-contents.txt >/dev/null
grep -q "usr/lib/udev/rules.d/70-codex-micro.rules" /tmp/pacman-micro-contents.txt
grep -q "^depend = libusb$" /tmp/pacman-micro-pkginfo.txt
grep -q "^depend = systemd-libs$" /tmp/pacman-micro-pkginfo.txt
micro_rule_mode="$(sed -n "1s/ .*//p" /tmp/pacman-micro-long-contents.txt)"
test "$micro_rule_mode" = "-rw-r--r--"
printf "%s\n" "$(basename "$micro_pkg_file")" > /tmp/pacman-micro-package-name.txt
'"'"'
cp /tmp/pacman-package-name.txt /work/.pacman-package-name.txt
cp /tmp/pacman-feature-package-name.txt /work/.pacman-feature-package-name.txt
cp /tmp/pacman-micro-package-name.txt /work/.pacman-micro-package-name.txt
'

- name: Write pacman validation summary
run: |
set -euo pipefail
pkg_file="$(cat .pacman-package-name.txt)"
feature_pkg_file="$(cat .pacman-feature-package-name.txt)"
micro_pkg_file="$(cat .pacman-micro-package-name.txt)"
{
echo "## Pacman Package Validation"
echo ""
echo "- Built: \`$pkg_file\`"
echo "- Verified updater binary, user service, update-builder bundle, and packaged runtime helper."
echo "- Feature-enabled build: \`$feature_pkg_file\`"
echo "- Verified generic feature resource, 0640 mode, and runtime dependency."
echo "- Codex Micro build: \`$micro_pkg_file\`"
echo "- Verified udev rule, 0644 mode, and systemd-libs/libusb dependencies."
} >> "$GITHUB_STEP_SUMMARY"
16 changes: 13 additions & 3 deletions .github/workflows/upstream-build-app.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,12 +10,16 @@ on:
- scripts/patch-linux-window-ui.js
- scripts/patch-linux-window-ui.test.js
- scripts/patches/**
- scripts/ci/download-upstream-dmg.sh
- scripts/ci/validate-patch-report.js
- scripts/ci/upstream-dmg-*.js
- scripts/validate-upstream-dmg.js
- scripts/lib/candidate-install.sh
- scripts/lib/bundled-plugins.sh
- scripts/lib/browser-client-node-repl-runtime.test.js
- scripts/lib/build-info.js
- scripts/lib/build-info.sh
- scripts/lib/build-info.test.js
- scripts/lib/patch-browser-client-iab-socket-scope.js
- scripts/lib/patch-validation.js
- scripts/lib/upstream-dmg-acceptance.js
Expand All @@ -33,12 +37,16 @@ on:
- scripts/patch-linux-window-ui.js
- scripts/patch-linux-window-ui.test.js
- scripts/patches/**
- scripts/ci/download-upstream-dmg.sh
- scripts/ci/validate-patch-report.js
- scripts/ci/upstream-dmg-*.js
- scripts/validate-upstream-dmg.js
- scripts/lib/candidate-install.sh
- scripts/lib/bundled-plugins.sh
- scripts/lib/browser-client-node-repl-runtime.test.js
- scripts/lib/build-info.js
- scripts/lib/build-info.sh
- scripts/lib/build-info.test.js
- scripts/lib/patch-browser-client-iab-socket-scope.js
- scripts/lib/patch-validation.js
- scripts/lib/upstream-dmg-acceptance.js
Expand Down Expand Up @@ -124,11 +132,12 @@ jobs:
key: upstream-dmg-${{ env.DMG_CACHE_SCHEMA_VERSION }}-${{ steps.upstream-metadata.outputs.cache_segment }}

- name: Download upstream DMG
if: steps.dmg-cache.outputs.cache-hit != 'true'
run: |
set -euo pipefail
mkdir -p "$(dirname "$UPSTREAM_DMG_PATH")"
curl -fL --retry 3 -o "$UPSTREAM_DMG_PATH" "$UPSTREAM_DMG_URL"
scripts/ci/download-upstream-dmg.sh \
"$UPSTREAM_DMG_URL" \
"$UPSTREAM_DMG_PATH" \
--reuse-existing

- name: Record local DMG fingerprint
id: local-dmg
Expand Down Expand Up @@ -277,5 +286,6 @@ jobs:
repo: context.repo,
decision,
currentHttpIdentityKey: httpIdentity(currentMetadata)?.key ?? null,
scanAll: true,
});
core.info(`Upstream DMG issue reconciliation: ${JSON.stringify(result)}`);
13 changes: 8 additions & 5 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -110,11 +110,14 @@ Repository governance: [issue and pull request labels](docs/label-governance.md)
- Core patch descriptors are the source of truth for shipped Linux
compatibility patches. Read `scripts/patches/core/README.md` before adding
or moving descriptors.
- ASAR patches are fail-soft unless intentionally marked `required-upstream`.
Each patch should be idempotent and report warnings when current upstream
drift prevents a needle from matching.
- Patch reports are written for installs/rebuilds. Upstream-build CI fails only
for required upstream patches that are missing or skipped.
- ASAR patches are fail-soft unless intentionally marked `required-upstream`,
or unless a transactional mutation reports `failed-integrity` because it
cannot prove rollback restored the original bytes. Each patch should be
idempotent and report warnings when current upstream drift prevents a needle
from matching.
- Patch reports are written for installs/rebuilds. Upstream-build CI fails for
required upstream patches that are missing or skipped and for every
`failed-integrity` status.
- Do not recreate deleted compatibility barrels such as
`scripts/patches/main-process.js`, `webview-assets.js`, or `shared.js`.
- Feature patching uses only `entrypoints.patchDescriptors`. Removed feature
Expand Down
65 changes: 65 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,14 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/).
- Linux launcher accepts `--profile NAME` / `--profile=NAME` / `-p NAME` and
applies the named Codex CLI profile to runtime commands and the local
app-server without changing the Desktop sign-in used for remote control.
- A disabled-by-default `deferred-update-build` Linux feature adds a **Build
updates automatically** setting. Turning it off keeps notification and DMG
verification active while deferring local package builds until an explicit
**Check for updates**.
- The embedded Computer Use backend is synchronized to standalone v0.4.6 as
`0.4.6-linux-alpha1`, including generic X11/EWMH window control, X11
`xdotool` keyboard, text, and coordinate-click input, KDE portal scroll
polarity, and portal key chords, with generic X11 registered last.
- A shared upstream DMG acceptance profile now produces the same structured
decision for local installs, updater rebuilds, and scheduled CI. Scheduled
rejections create one fingerprinted drift issue and supersede issues for
Expand Down Expand Up @@ -42,6 +50,63 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/).

### Fixed

- Deferred upstream DMGs are revalidated before a build. A newer candidate
supersedes the pending download, and a deleted cached DMG is redownloaded in
the same explicit check. Fresh app-launch checks preserve the stable deferred
candidate without an upstream DMG request; stale checks use HEAD and reuse a valid
unchanged cached DMG, while offline checks leave it pending. The optional
state marker retains the existing `update_detected` status so updater 0.10.x
can read the state and resume its previous automatic-build behavior. State
written by prerelease builds using `update_available` is migrated back to
`update_detected` on read.
- Native X11 coordinate clicks now use one supervised xdotool XTEST command,
fall back to ydotool only when xdotool cannot launch, and preserve nested X11
session identity instead of importing a host Wayland display.
- Wrapper update checks no longer offer rebuilds when every change since the
installed commit is limited to repository documentation or metadata.
- The updater feature picker now changes only the enabled feature list, preserving
nested feature settings and other local configuration keys across rebuilds.
- The opt-in Dock icon tweak now targets the current upstream main-process
bundle, restoring Linux window, tray, and desktop icon synchronization.
- The opt-in shallow repository watcher now patches both current app bundles
and routes the Linux Parcel working-tree path through the same shallow host,
restoring bounded watches on the latest upstream DMG.
- The opt-in directory-only working-tree watcher now routes the current Linux
Parcel working-tree path through its existing bounded directory watcher,
restoring the feature on the latest upstream DMG, with byte-verified rollback
for its paired bundle writes.
- Computer Use now supports Plasma 5 and 6 KWin scripting, validates every
ydotool 1.0.3+ command shape it emits, and rejects semantically incompatible
CLIs even when a daemon socket exists. Hyprland dispatch validation handles
exit-zero errors, modifier chords use the v0.4.3 delay, and an xdotool command
that starts but fails is never replayed through ydotool.
- Open Target Discovery now resolves the selected Linux editor or terminal
through the current private open-target command path. Command-path drift is
reported before the feature changes the main bundle, so enabled-feature
acceptance cannot mistake a partially patched bundle for success.
- Repeated current-DMG patch passes now keep composed native and frameless
titlebars, external-open handling, Record & Replay, and Browser Use runtime
resolution byte-identical. Complete markers no longer depend on
function-local minified aliases, while partial markers remain fail-soft and
leave drifted assets untouched.
- Remote mobile control now patches the current 26.721 dual-gate enablement
bridge instead of reporting it as already applied. Startup auto-connects the
environment owned by this Desktop without overwriting saved choices for
other enrolled hosts.
- Updater-managed npm Codex CLI installs now serialize across daemon, launcher,
and status processes. If npm reports the exact stale Arborist retirement
directory failure, automatic paths preserve the working CLI and direct the
user to read-only diagnostics. The explicit `repair-cli` command revalidates
the condition under the shared lock, records crash-durable quarantines, and
retries npm once per explicit invocation without discarding failed recovery
state or concurrent updater state. A parent-independent bounded supervisor
retains the lock while mutating npm children run without inheriting it,
terminates their complete process group, and releases the lock only after
cleanup if the updater parent or supervisor exits abruptly or the npm leader
leaves a background descendant.
Late routine CLI checks revalidate both the repair journal and their original
CLI state before persisting a result. Missing-CLI preflight also re-resolves a
CLI installed while it waited for the lock before consulting npm.
- Concurrent updater entrypoints now serialize state reloads and cache cleanup
before persisting startup state. A second process can no longer prune an
active rebuild workspace, while forced checks wait for startup maintenance
Expand Down
14 changes: 7 additions & 7 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading
Loading