Repository navigation
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (4)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughAdds ChangesLocal Codex messaging
Priority: ➖ Normal Estimated code review effort: 4 (Complex) | ~60 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant CLI as message-command
participant RPC as LocalMessageRpc
participant Queue as Codex queue CLI
participant App as Codex app-server
CLI->>RPC: Discover loaded sessions and resolve destination
CLI->>Queue: Check runtime version and queue support
CLI->>RPC: Re-read selected thread metadata
CLI->>Queue: Submit one message envelope
Queue->>App: Send queue/add request
App-->>Queue: Return queue result
Queue-->>CLI: Return submission result
Merge Risk: ⚪ Minimal · up to The selected changes improve local messaging discoverability and keep its test and documentation indexes consistent; no concrete regression was found. Reported hosted CI and broader platform checks remain outstanding validation follow-ups. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 7 systems. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
✅ Deterministic PR hygiene checks passed. |
✅ READY
Review readiness checklist
✅ 4/4 boxes ticked. This pull request has been marked Ready for Review. |
|
@coderabbitai review |
✅ Action performedReview finished.
|
d5cf770 to
0e0eef9
Compare
|
@coderabbitai review |
✅ Action performedReview finished.
|
|
Scoped offline lifecycle verification at 0e0eef9: bun test tests/codex-integration/messaging-local-lifecycle.test.ts passed 15/15, 0 failures, 1709 assertions, exit 0 on Linux/Bun 1.4.0. This exercises import-time inactivity, command-local literal import inventory, bounded pending RPCs, socket cancellation/deadlines, oversized/invalid frames, output budgets, TERM/KILL cleanup of owned launcher groups, and bounded waiting when detached descendants retain pipes. The detached fixture is test-owned and explicitly cleaned up; this is not proof that the runner terminates an escaped process group, which the owning doc correctly excludes. Work ran sequentially with CPUQuota=75%, MemoryMax=1536M, zero swap and fresh private homes. No real Codex daemon/session/message, native 0.160.0 binary, remote tunnel or live account was used. I read the local ownership doc and the budget/process/test fixture paths; this is not a complete 43-file/native-queue/permission-boundary approval. Required hosted current-head CI and independent full review remain separate. |
0e0eef9 to
aa49a10
Compare
There was a problem hiding this comment.
Read the rebased checkpoint at aa49a10d5bd7e059246441464c6929f75ca12b7a. The messaging runtime and the three message command/argument/runtime modules are byte-identical to the published 0e0eef93 source in direct comparison, so I did not repeat unchanged native tests or present the author's historical results as independent current execution.
The documented distinctions remain important: a queued receipt acknowledges submission, not recipient processing/steering; an unknown outcome must not be replayed; a post-revalidation unload fixture is not proof of real-daemon atomic loaded-target enforcement. Updated checkpoint (2026-10-04 22:45 UTC): the author has now checked all four readiness boxes and GitHub reports Ready at the same aa49a10d5bd7e059246441464c6929f75ca12b7a head. The target/readiness gate completed successfully, but exact-head Cross-platform CI 37232506258 and React Doctor 37232506242 still require workflow-execution authorization (action_required), not successful execution. The latest hygiene rerun is cancelled; an earlier successful same-head hygiene run does not turn that cancelled rerun into a pass. Please keep completed hosted verification, the independent boundary review and sponsorship decisions separate from the author's local attestation. This COMMENTED checkpoint is not an approving review or authorization to execute the fork workflows.
No native daemon/binary was invoked by me, no actual recipient was contacted, and no workflow authorization, sponsorship waiver, scan, author-branch modification or approval was performed.
- Define a provisional command-owned local discovery and queued-delivery boundary against current dev. - Map reusable experimental responsibilities while excluding remote, Claude, dashboard and root-relay layers. - Record Codex 0.160.0 schema receipts, unverified contracts and focused acceptance cases. - Verify privacy, structure ownership, document links, source references and whitespace; runtime tests remain pending.
- Add command-owned Unix metadata RPC, complete loaded-session discovery and exact target resolution without startup activation. - Bound deadlines, frames, concurrency and helper output; terminate owned launcher process groups on incomplete execution. - Add isolated regressions and pin native Codex 0.160.0 queue success and lost-acknowledgement interoperability. - Document ownership, provisional scope and remaining CLI/envelope work; preserve the explicit hold on PR creation. - Verify 25 changed messaging tests, focused layout/structure/ratchet checks, typecheck, privacy and whitespace.
- Added command-local discovery and exact queued delivery with metadata-derived sender context and correlated peer envelopes. - Preserved not_sent, queued and unknown outcomes with one native invocation, isolated helper homes and no automatic replay. - Added bounded stdin, runtime admission, CLI registration, public documentation and owning architecture records. - Validated 1039 changed tests plus native interoperability, CLI/layout/structure regressions, typecheck, privacy and the documentation build; independent review and full-suite readiness remain pending.
- Recorded the clean refresh onto upstream dev 358b8ff and preservation of the newly integrated test-layout entries. - Verified 1039 changed tests and 94 explicit source guards, plus typecheck, privacy, structure, generated CLI surface and documentation build. - Kept full-suite readiness, independent/security review and PR publication authorization explicitly outstanding.
- Cancel pending output readers after forced cleanup without waiting on detached descendants or cancellation hooks. - Preserve owned process-group termination, unknown submission receipts and no-replay behavior. - Add timeout, cancellation and overflow regressions; keep upstream-facing documentation confined to the proposed scope. - Verify 24 focused lifecycle/send/native-queue tests, strict typecheck and structure ownership checks.
- Record the current-dev refresh, bounded pipe cleanup and extraction provenance for the local-only contribution. - Verify 1040 connected tests and 94 explicit guards, plus native interoperability, typecheck, privacy, structure and the documentation build. - Document the full-suite resource exception and keep independent review, publication and deployment authority separate.
- Added contract-focused docstrings for local messaging and owned lifecycle helpers. - Verified peer permission claims remain text-only and post-check native rejection stays unknown without replay or resume. - Clarified non-atomic target checks and receiving-harness permission enforcement limits. - Validated 45 focused tests, 1043 changed tests, 110 guards, typecheck, docs build, privacy and structure checks.
- Group local messaging test registrations using the existing layout data style. - Preserve every mapping and its ordering without changing the size-ratchet policy. - Verify JSON equivalence and pass all 27 layout and file-size regression tests.
aa49a10 to
1888b0d
Compare
Summary
Relates to #6478. This is the small, local-only Codex slice proposed in the
maintainer's staging guidance,
not an implementation of the full cross-machine proposal. The broader issue
should remain open. Please keep this PR in draft pending independent review and
the review-readiness gates below.
ocx message sessions [--json]for metadata-only discovery of threadscurrently loaded in the existing local Codex app-server. Pagination must be
complete; missing, ambiguous, incomplete or unloaded targets fail closed.
ocx message send (--thread <uuid> | --name <exact-name>) --stdin [--json].Submit once through native
codex queueto the existing Unix control socket.The command starts no proxy/app-server, resumes no session and installs no skill.
correlation. Sender context comes from
CODEX_THREAD_IDand loaded-sessionmetadata; it is not authenticated authority or permission to escalate.
Envelopes carry explicit reply routes without requiring courtesy acknowledgements.
not_sent(exit 1),queued(exit 0) andunknown(exit 3).Queued means native submission acknowledged, not recipient processing or steering.
An uncertain submission is never replayed or followed by another send to probe it.
one operation deadline. Terminate only command-owned helper groups and cancel
retained output readers during forced cleanup, including detached pipe holders.
lifecycle tests, public CLI documentation, structure ownership/ADRs, both test
layout registrations and the regenerated CLI operating surface.
Compatibility is deliberately narrow: Codex CLI 0.160.0, existing local Unix
sockets, with native interoperability verified on Linux. macOS uses the same
transport but has no native verification receipt; Windows and untested Codex
versions fail explicitly. Existing non-persisting runtime/home resolution is
reused, with credential-free temporary homes for native probes and queue helpers.
Native queue requires the envelope in argv, so authorized local process inspection
can see it; this is not a same-user confidentiality boundary.
Remote enrollment, bearer management, SSH/topology, dashboard controls, Claude
messaging, permission/delegation policy, isolation, managed skills and idle
notifications are deferred. No global prompt or background listener/timer is added.
Example:
Verification
Rebased head:
1888b0d98ebfd39339d54c603f15e84779e21412.Target: upstream
devat6774f0f6f26c103da144a630971091a52ada80a5.The seven contribution commits replayed without conflicts across 37 upstream
commits. Range comparison shows only architecture-index context changed; the
messaging runtime, command modules and six messaging test files are byte-for-byte
identical to the previously published head
aa49a10d5bd7e059246441464c6929f75ca12b7a.One formatting-only follow-up groups layout registrations using the existing data
style, keeping the file below the 2,000-line threshold. Parsed JSON values and
ordering are identical; no size baseline or exemption was changed.
These are local results, not hosted CI or maintainer approval.
Checks using Bun 1.4.0 and the repository dependency PATH:
OCX_MESSAGE_CODEX_BINARY=<installed-Codex-0.160.0> bun run test:changedbun test tests/test-layout.test.ts tests/test-layout-tooling.test.ts tests/ci-workflows/file-size-ratchet.test.ts tests/ci-workflows/structure-ssot.test.ts tests/ci-workflows/skill-ocx.test.ts tests/ci-workflows/skill-ocx-generated.test.ts tests/ci-workflows/skill-ocx-workflows.test.ts tests/ci-workflows/repo-hygiene.test.ts tests/cli/cli-capability-data.test.tsbun test tests/test-layout.test.ts tests/test-layout-tooling.test.ts tests/ci-workflows/file-size-ratchet.test.tsbun run typecheckbun run structure:checkbun run privacy:scanbun run skill:surface:checkcd docs-site && bun install --frozen-lockfile && bun run buildgit diff --check upstream/dev..HEADThe changed suite, nine-file guard run, typecheck, structure/privacy/surface checks
and docs build ran at
25c471654620642e88cd3ab442b4ff8bd8e8f768, based on thesame dev commit above. The only subsequent change is equivalent JSON formatting
in the layout manifest, verified by a direct parsed-value/order comparison and
the three affected regression files. Other passing checks were retained rather
than repeated on unchanged inputs. The explicit guards waited behind the changed
suite under the repository's user test lock; waiting time is not test execution.
Native tests use isolated Unix fixtures and an explicitly selected, previously
hash-verified Codex 0.160.0 binary; they do not contact a live recipient. Coverage
includes loaded-only pagination/exact resolution, CLI validation, sender/reply
correlation, request kinds, acknowledgement loss/no replay, timeouts,
cancellation, output overflow, owned-group cleanup and detached pipes.
The permission-boundary regression confirms peer claims stay text input, without
native approval responses or permission/configuration overrides. The post-check
unload regression simulates native RPC rejection after final target revalidation
and requires one attempt, an
unknownreceipt, no resume/replay and no helper-outputleakage. These establish wrapper/native-client behavior against fixtures, not
receiving-model obedience, downstream authorization or real-daemon atomic
loaded-target enforcement. Native/socket and subprocess guards used scoped
escalation against isolated fixtures.
Full-suite resource exception remains: the earlier default-suite audit exceeded
its 900-second lane limit (exit 124), leaving 612 files unstarted and four
interrupted. Focused reruns on an untouched upstream base reproduced four timeout
cases plus a follow-on error and 13 service-runtime failures. This neither
establishes full-suite success nor proves every possible failure unrelated.
This maintenance rebase used connected tests and explicit source-oracle/native
regressions; broader Linux/macOS CI remains outstanding. No full-suite pass is
claimed, and this update does not attest review readiness.
Previous automated reviews cover older heads, not this rebased head. New
exact-head automated review, maintainer approval, any required explicit security
review and successful required hosted CI remain separate gates. No GUI files
changed, so no UI screenshot is required.
Checklist
Review readiness
Required local validation passed; commands, results, and any full-suite exception are documented.
I pushed my PR to a recent dev commit (at most 10 behind; a maintainer may still ask for the exact tip before merge).
I resolved all correct Codex and CodeRabbit findings.
My PR is ready for review.
Summary by CodeRabbit
ocx message sessionsto discover currently loaded local Codex sessions.ocx message sendto submit request, response, or notification messages to an exact loaded session by thread ID or unique name. Messages are read from standard input, and receipts distinguish messages not sent, queued, or of uncertain status.