Skip to content

[WRONG BRANCH] release: 2.75.0-preview.20261001 - #6352

Merged
lidge-jun merged 22 commits into
previewfrom
codex/promote-preview-2.75.0
Oct 1, 2026
Merged

lidge-jun merged 22 commits into
previewfrom
codex/promote-preview-2.75.0

Conversation

@lidge-jun

Copy link
Copy Markdown
Owner

Summary

Promote the verified dev candidate 82a4955196 to preview as 2.75.0-preview.20261001. The tree is that candidate plus the four version sources moved to the preview version.

2.75.0 contents since v2.74.0: #6319 (bound Cursor installer manifests), #6308 (preserve Codex TOML values and routing marker ownership), #6315 and #6324 (Devin signature-type bounds, sparse family scoring), #6325 (bound XML redaction scans), #6326 (pool quota policy requires live credential evidence), #6328 (Cognition blocklist rewrites for the system prompt), #6329 (real 128K Claude output maxima), #6330 (passthrough failure reason without upstream message text), #6331 and #6333 (new-model policy before discovery/sync/export; drifted reads project instead of 503), #6332 (structure doc budget), #6341 and #6343 (Grok OAuth 426 fix: report Grok CLI 1.0.46), #6342 (TokenLab guide link), #6344 (Devin late reasoning signatures), #6345 (quota popover hover gap), #6346 (bare native ids in pickerOrder, #6338), #6347 (Anthropic pool fails over on proven account 403s, #6340), #6349 (source oracles follow #6347).

Release authorization: the repository owner explicitly asked on 2026-10-01 to bump Grok, verify regressions and release. The dev maintainer-integration exception does not cover this branch; this promotion merges on that owner authorization, as 2.70.0–2.74.0 did.

quota popover hover bridge

quota popover

Verification

Checklist

  • Scope stays focused and avoids unrelated cleanup.
  • Docs or release notes were updated when needed.
  • Security-sensitive changes were reviewed for secrets, auth, and unsafe defaults.

luvs01 and others added 22 commits September 30, 2026 23:48
Co-authored-by: luvs01 <27862058+luvs01@users.noreply.github.com>
Co-authored-by: luvs01 <27862058+luvs01@users.noreply.github.com>
* fix(devin): bound held signature type payloads

Carry source commit 3a257a6.
Count signatureType in the held UTF-16 payload budget and cap its
wire bytes before UTF-8 decoding. Preserve the signed retry path below
the budget, with exact byte-boundary and multibyte regression coverage.

* test(devin): verify oversized-type legacy signature replay

---------

Co-authored-by: luvs01 <27862058+luvs01@users.noreply.github.com>
* fix(redaction): bound XML identifying-attribute scans

Carry luvs01#691 at f42e713. Replace wall-clock regression with delimiter-work accounting and preserve malformed/escaped credential coverage.

* fix(redaction): recognize quoted XML tag delimiters

Scan tag terminators outside quoted values, cover credential masking after embedded delimiters, and count manual character work in linear-scaling regressions.
…6326)

Preserve display snapshots and legacy login observations while gating pool policy changes on the captured writer. Cover missing writers in compact and WebSocket paths.
…6328)

Carries #6281 unchanged plus maintainer review fixes; the contributor gate re-drafted the original after the maintainer push.

Co-authored-by: lonefisher <132996955+lonefisher@users.noreply.github.com>
…6329)

Carries #6316 unchanged plus maintainer review fixes; the contributor gate re-drafted the original after the maintainer push.

Co-authored-by: vadymhimself <11277453+vadymhimself@users.noreply.github.com>
…g row (#6330)

Carries #6295 with a maintainer privacy rework: the stored reason is limited to the HTTP status plus an allowlisted Anthropic error type, so upstream message text (which can echo account identifiers or request content) never reaches the request log or usage history. Client responses are unchanged.

Co-authored-by: sh940701 <visioner2168@gmail.com>
… publication (#6331)

Carries #6260 with a maintainer fix: a file-loaded config keeps its file provenance after discovery inventory drift, so stale discovery is refused under the mutation coordinator instead of disabling a model in memory that a later unrelated save would persist over the operator's choice.

Co-authored-by: colthreepv <2657230+colthreepv@users.noreply.github.com>
…licy (#6333)

File-backed inventory drift rejected ordinary model reads with catalog_busy. Identical synthetic inventory succeeds on the same cached roster, ruling out row replacement and cache revision churn in the reproduction.

Allow read callers to receive a detached new-arrival policy projection. Management renders disabled arrivals; other shared-fetch consumers receive only visible projected rows. Keep retained-sync and direct stale-writer refusal contracts, inventory/revision checks, and persisted merge baselines intact.

Verification: eight authorized files, 80 passed / 0 failed; after adding save-safety coverage, runtime-policy and ratchet files, 24 passed / 0 failed. Typecheck and structure checks pass. Full suite and docs build were excluded by the delegated command restrictions.
* fix(xai): report a current Grok CLI version on the OAuth path

xAI now answers Grok OAuth requests that report a client version below 1.0.13 with HTTP 426 ("Your Grok CLI version (0.2.93) is outdated"), so every SuperGrok OAuth request failed. Report 1.0.25, the current stable Grok CLI, in x-grok-client-version and the User-Agent.

Carries #6339.

Co-authored-by: unsafe9 <24631203+unsafe9@users.noreply.github.com>

* test(xai): pin Grok compatibility header regression

---------

Co-authored-by: unsafe9 <24631203+unsafe9@users.noreply.github.com>
…6344)

Carries #6299 with the buffering note translated into the ja, ko, ru and zh-cn Claude Code guides.

Co-authored-by: foxytanuki <45069709+foxytanuki@users.noreply.github.com>
…6345)

Carries #6278 with maintainer review fixes: the chip description points at the text-only quota table, and the hover bridge spans both the chip and popover widths so wide chips keep the popover open.

Co-authored-by: colthreepv <2657230+colthreepv@users.noreply.github.com>
PUT /api/subagent-models validated pickerOrder against visible routed slugs only, so the
documented complete-picker ordering (a bare native id such as gpt-5.6-sol) could not be saved
through the API. Visible, enabled native catalog rows are now accepted; disabled and unknown
native ids are still rejected.

Closes #6338
@lidge-jun
lidge-jun requested a review from Ingwannu as a code owner October 1, 2026 03:31
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-01T03:33:09.881836Z e63d1cd PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

✅ Deterministic PR hygiene checks passed.

@lidge-jun
lidge-jun merged commit dc1a1b0 into preview Oct 1, 2026
11 of 31 checks passed
@lidge-jun
lidge-jun deleted the codex/promote-preview-2.75.0 branch October 1, 2026 03:32
@github-actions github-actions Bot changed the title release: 2.75.0-preview.20261001 [WRONG BRANCH] release: 2.75.0-preview.20261001 Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

⏳ DRAFT

  • wrong target branch (preview); retarget to dev.

What to do

  • Retarget this PR to dev — all contributions go to dev.

Its title has been prefixed with [WRONG BRANCH].
Automatic draft conversion failed (token cannot change draft status). Please convert this pull request to a draft manually. The required enforce-target check will keep failing until every issue above is resolved.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Repository: lidge-jun/opencodex/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 3ff98094-d04a-49f6-9e42-3334a3a205b6

📥 Commits

Reviewing files that changed from the base of the PR and between cbfa828 and e63d1cd.

⛔ Files ignored due to path filters (1)
  • desktop/src-tauri/Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (113)
  • desktop/src-tauri/Cargo.toml
  • desktop/src-tauri/tauri.conf.json
  • docs-site/src/content/docs/fr/guides/claude-code.md
  • docs-site/src/content/docs/fr/reference/configuration/providers.md
  • docs-site/src/content/docs/guides/claude-code.md
  • docs-site/src/content/docs/guides/codex-integration.md
  • docs-site/src/content/docs/guides/model-routing.md
  • docs-site/src/content/docs/guides/providers.md
  • docs-site/src/content/docs/guides/web-dashboard.md
  • docs-site/src/content/docs/ja/guides/claude-code.md
  • docs-site/src/content/docs/ja/guides/model-routing.md
  • docs-site/src/content/docs/ja/reference/configuration/providers.md
  • docs-site/src/content/docs/ko/guides/claude-code.md
  • docs-site/src/content/docs/ko/guides/model-routing.md
  • docs-site/src/content/docs/ko/reference/configuration/providers.md
  • docs-site/src/content/docs/reference/configuration/providers.md
  • docs-site/src/content/docs/ru/guides/claude-code.md
  • docs-site/src/content/docs/ru/guides/model-routing.md
  • docs-site/src/content/docs/ru/reference/configuration/providers.md
  • docs-site/src/content/docs/tr/guides/claude-code.md
  • docs-site/src/content/docs/tr/reference/configuration/providers.md
  • docs-site/src/content/docs/troubleshooting/codex-cannot-sign-in.md
  • docs-site/src/content/docs/zh-cn/guides/claude-code.md
  • docs-site/src/content/docs/zh-cn/guides/model-routing.md
  • docs-site/src/content/docs/zh-cn/reference/configuration/providers.md
  • docs-site/src/content/docs/zh-tw/guides/claude-code.md
  • docs-site/src/content/docs/zh-tw/reference/configuration/providers.md
  • gui/README.md
  • gui/package.json
  • gui/src/components/quota-summary-bar/QuotaSummaryBar.tsx
  • gui/src/components/quota-summary-bar/quota-summary-bar.css
  • gui/tests/quota-summary-bar.test.tsx
  • gui/tests/quota-summary-hover-browser.ts
  • package.json
  • scripts/test-layout/layout.json
  • src/adapters/devin.ts
  • src/adapters/devin/cloud-direct/chat.ts
  • src/adapters/devin/live-models.ts
  • src/claude/devin-output-order.ts
  • src/codex/auth-api/pool-quota-probe.ts
  • src/codex/catalog/retained-sync.ts
  • src/codex/inject/config-toml.ts
  • src/codex/inject/provider-table.ts
  • src/codex/inject/remove.ts
  • src/codex/injected-marker.ts
  • src/codex/quota-auto-refresh.ts
  • src/codex/quota.ts
  • src/codex/toml-source-lines.ts
  • src/config.ts
  • src/config/live-reconcile.ts
  • src/config/rebase-provenance.ts
  • src/images/loop.ts
  • src/integrations/cursor-local-installer.ts
  • src/lib/redact.ts
  • src/oauth/anthropic-account-refusal.ts
  • src/oauth/anthropic-routing.ts
  • src/providers/new-model-policy-runtime.ts
  • src/providers/new-model-policy.ts
  • src/providers/registry/entries-core.ts
  • src/providers/registry/model-seeds.ts
  • src/providers/xai-transport.ts
  • src/server/claude-messages.ts
  • src/server/management/agent-settings-routes.ts
  • src/server/management/model-rows.ts
  • src/server/management/shared.ts
  • src/server/responses/adapter-continuation.ts
  • src/server/responses/adapter-delivery.ts
  • src/server/responses/adapter-dispatch.ts
  • src/server/responses/compact.ts
  • src/server/responses/core-codex-account.ts
  • src/server/responses/passthrough-delivery.ts
  • src/server/responses/request-transport.ts
  • src/server/responses/run-turn-execution.ts
  • src/server/responses/sidecar-execution.ts
  • src/web-search/loop.ts
  • structure/catalog.md
  • structure/clients/claude-desktop.md
  • structure/clients/integrations.md
  • structure/codex-home.md
  • structure/config.md
  • structure/dashboard-and-usage.md
  • structure/gui-and-management-api.md
  • structure/providers-and-adapters.md
  • structure/providers/anthropic-account-pool.md
  • structure/providers/openai-accounts.md
  • structure/runtime.md
  • structure/transports/byte-accounting.md
  • structure/transports/inventory.md
  • structure/transports/responses-failover.md
  • tests/adapters/anthropic/anthropic-output-maxima.test.ts
  • tests/adapters/anthropic/anthropic-quota-dispatch.test.ts
  • tests/claude-integration/claude-devin-output-order.test.ts
  • tests/claude-integration/claude-native-passthrough.test.ts
  • tests/codex-integration/codex-config-preservation.test.ts
  • tests/codex-integration/codex-provider-table-retention.test.ts
  • tests/codex-integration/codex-sync-new-model-policy.test.ts
  • tests/codex-integration/low-quota-protection.test.ts
  • tests/codex-integration/model-visibility-management-api.test.ts
  • tests/fixtures/test-layout-expected.json
  • tests/lib/redact.test.ts
  • tests/oauth/generic-oauth-failover.test.ts
  • tests/providers/cursor/cursor-local-installer.test.ts
  • tests/providers/devin-adapter.test.ts
  • tests/providers/devin-anthropic-signature-fallback.test.ts
  • tests/providers/devin-family-resolution.test.ts
  • tests/providers/devin-reasoning-continuation.test.ts
  • tests/providers/new-model-policy-runtime.test.ts
  • tests/providers/new-model-policy.test.ts
  • tests/providers/xai/xai-transport.test.ts
  • tests/routing/always-on-429-failover.test.ts
  • tests/routing/subagent-roster-retention.test.ts
  • tests/server/model-export-new-model-policy.test.ts
  • tests/server/server-new-model-policy-arrival.test.ts
 __________________________________
< Pulling the bugs out of the hat. >
 ----------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants