Repository navigation
[WRONG BRANCH] release: 2.75.0-preview.20261001 - #6352
Conversation
Co-authored-by: luvs01 <27862058+luvs01@users.noreply.github.com>
Co-authored-by: luvs01 <27862058+luvs01@users.noreply.github.com>
* fix(devin): bound held signature type payloads Carry source commit 3a257a6. Count signatureType in the held UTF-16 payload budget and cap its wire bytes before UTF-8 decoding. Preserve the signed retry path below the budget, with exact byte-boundary and multibyte regression coverage. * test(devin): verify oversized-type legacy signature replay --------- Co-authored-by: luvs01 <27862058+luvs01@users.noreply.github.com>
* fix(redaction): bound XML identifying-attribute scans Carry luvs01#691 at f42e713. Replace wall-clock regression with delimiter-work accounting and preserve malformed/escaped credential coverage. * fix(redaction): recognize quoted XML tag delimiters Scan tag terminators outside quoted values, cover credential masking after embedded delimiters, and count manual character work in linear-scaling regressions.
…6326) Preserve display snapshots and legacy login observations while gating pool policy changes on the captured writer. Cover missing writers in compact and WebSocket paths.
…g row (#6330) Carries #6295 with a maintainer privacy rework: the stored reason is limited to the HTTP status plus an allowlisted Anthropic error type, so upstream message text (which can echo account identifiers or request content) never reaches the request log or usage history. Client responses are unchanged. Co-authored-by: sh940701 <visioner2168@gmail.com>
… publication (#6331) Carries #6260 with a maintainer fix: a file-loaded config keeps its file provenance after discovery inventory drift, so stale discovery is refused under the mutation coordinator instead of disabling a model in memory that a later unrelated save would persist over the operator's choice. Co-authored-by: colthreepv <2657230+colthreepv@users.noreply.github.com>
…licy (#6333) File-backed inventory drift rejected ordinary model reads with catalog_busy. Identical synthetic inventory succeeds on the same cached roster, ruling out row replacement and cache revision churn in the reproduction. Allow read callers to receive a detached new-arrival policy projection. Management renders disabled arrivals; other shared-fetch consumers receive only visible projected rows. Keep retained-sync and direct stale-writer refusal contracts, inventory/revision checks, and persisted merge baselines intact. Verification: eight authorized files, 80 passed / 0 failed; after adding save-safety coverage, runtime-policy and ratchet files, 24 passed / 0 failed. Typecheck and structure checks pass. Full suite and docs build were excluded by the delegated command restrictions.
* fix(xai): report a current Grok CLI version on the OAuth path
xAI now answers Grok OAuth requests that report a client version below 1.0.13 with HTTP 426 ("Your Grok CLI version (0.2.93) is outdated"), so every SuperGrok OAuth request failed. Report 1.0.25, the current stable Grok CLI, in x-grok-client-version and the User-Agent.
Carries #6339.
Co-authored-by: unsafe9 <24631203+unsafe9@users.noreply.github.com>
* test(xai): pin Grok compatibility header regression
---------
Co-authored-by: unsafe9 <24631203+unsafe9@users.noreply.github.com>
PUT /api/subagent-models validated pickerOrder against visible routed slugs only, so the documented complete-picker ordering (a bare native id such as gpt-5.6-sol) could not be saved through the API. Visible, enabled native catalog rows are now accepted; disabled and unknown native ids are still rejected. Closes #6338
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
✅ Deterministic PR hygiene checks passed. |
⏳ DRAFT
What to do
Its title has been prefixed with |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: Repository: lidge-jun/opencodex/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (113)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary
Promote the verified
devcandidate82a4955196topreviewas2.75.0-preview.20261001. The tree is that candidate plus the four version sources moved to the preview version.2.75.0 contents since v2.74.0: #6319 (bound Cursor installer manifests), #6308 (preserve Codex TOML values and routing marker ownership), #6315 and #6324 (Devin signature-type bounds, sparse family scoring), #6325 (bound XML redaction scans), #6326 (pool quota policy requires live credential evidence), #6328 (Cognition blocklist rewrites for the system prompt), #6329 (real 128K Claude output maxima), #6330 (passthrough failure reason without upstream message text), #6331 and #6333 (new-model policy before discovery/sync/export; drifted reads project instead of 503), #6332 (structure doc budget), #6341 and #6343 (Grok OAuth 426 fix: report Grok CLI 1.0.46), #6342 (TokenLab guide link), #6344 (Devin late reasoning signatures), #6345 (quota popover hover gap), #6346 (bare native ids in pickerOrder, #6338), #6347 (Anthropic pool fails over on proven account 403s, #6340), #6349 (source oracles follow #6347).
Release authorization: the repository owner explicitly asked on 2026-10-01 to bump Grok, verify regressions and release. The
devmaintainer-integration exception does not cover this branch; this promotion merges on that owner authorization, as 2.70.0–2.74.0 did.Verification
devCross-platform CI (workflow_dispatch) on candidate82a4955196: run 36808122713 success on attempt 1 (39 success, 1 skipped). The earlier run 36806598410 failed only on stale source oracles after fix(anthropic): fail over on proven pre-output account 403 refusals #6347 and was fixed by test(anthropic): follow the renamed refusal rotators in source oracles #6349.devat 2.76.0 (version sources only).release.yml.bun scripts/release-version-sources.ts check 2.75.0-preview.20261001passes;git diff 82a4955196 HEADis exactly the four version sources. The branch descends fromorigin/previewthrough anoursmerge.Checklist