Codex
Public Made by Adomby adom
Codex in Adom Hydrogen: ecosystem setup, dock dashboard and live engineering demos.
Runtime upgrade continuity: issue 2
Verified 2026-09-10 for adom/codex #2.
Cause and change
The durable runtime's version gate rejected a newer extension when the older backend had connected clients or active work. The launcher exited and the extension could not create a usable conversation editor. The navigator warning was not the cause, as the issue reporter's correction explains.
The runtime now compares the native app-server's generated JSON schema bundles, including experimental APIs. Matching schemas allow the newer extension to proxy to the existing writer. Different/unknown schemas still fail closed. It does not assume compatibility from a shared major version and never downgrades a backend. Schema hashes are cached by executable identity (bounded to eight entries). New backends retain an attestation in server.json; legacy backends require their original, unchanged binary to remain available for attestation.
A failed exclusive-lock conversion restores the shared client lock before reuse.
Backend-idle probe errors cannot authorize termination. Deferred state appears in
adom-codex-runtime --runtime-status. Replacement still requires no other proxy
clients and an authoritatively idle backend, on a subsequent connection. This
change does not implement a proactive watcher swap or an interrupt-and-upgrade UI.
Real-binary regression test
The installed extension builds were used in an isolated CODEX_HOME:
- openai.chatgpt 26.901.22334: native codex-cli 0.153.0.
- openai.chatgpt 26.903.71938: native codex-cli 0.153.4.
- Their complete generated experimental schema bundles matched byte-for-byte.
- A local HTTP/SSE model fixture held a turn open; no real model call or billing.
- A newer client connected while old clients were attached, read the existing active turn, and preserved the old backend PID.
- With all old clients gone but that turn still active, the newer client again connected without replacing the backend.
- Three proxy replacements preserved the turn ID and delivered its completion.
- Exactly one fixture model request occurred; reconnect did not restart work.
- Once clients closed and work completed, the newer backend replaced the old one and reopened the saved conversation successfully.
- An unattested identity change still refused replacement during active work.
Reproduce with the installed native paths in ADOM_TEST_CODEX_OLD, ADOM_TEST_CODEX_NEW and ADOM_CODEX_NATIVE (the latter selects the normal CLI):
python3 -m unittest discover -s tests -v
node --test tests/test_webview.cjs tests/test_dashboard.cjs
All 17 Python tests and four Node test entries passed. Unit tests also cover shared-lock retention, failed idle probes, different/unknown protocols, replaced legacy binaries, retained attestations after VSIX removal, cache invalidation, and downgrade refusal.
Local deployment
Only the installed package's runtime/runtime.py was patched from the reviewed source. No editor reload, backend restart, settings changes, auth changes, or arav-rog calls occurred. This is a local runtime patch, not a registry publication.
Before and after: native backend PID 49708, extension 26.903.71938. A fresh proxy using the installed runtime initialized and listed three loaded threads. The editor tab API retained the existing titled conversation editors. No new live user turn was submitted and no UI reload was used to manufacture an upgrade. The actual version transition was exercised in the isolated regression fixture.
Source and installed runtime SHA256:
5c3a3cc957df5663bc08ebea0458c7b3e2a2f5afa5c5dcbd579da19c6af9b927.
# Runtime upgrade continuity: issue 2
Verified 2026-09-10 for [adom/codex #2](https://wiki.adom.inc/adom/codex/issues/2).
## Cause and change
The durable runtime's version gate rejected a newer extension when the older
backend had connected clients or active work. The launcher exited and the extension
could not create a usable conversation editor. The navigator warning was not the
cause, as the issue reporter's correction explains.
The runtime now compares the native app-server's generated JSON schema bundles,
including experimental APIs. Matching schemas allow the newer extension to proxy
to the existing writer. Different/unknown schemas still fail closed. It does not
assume compatibility from a shared major version and never downgrades a backend.
Schema hashes are cached by executable identity (bounded to eight entries). New
backends retain an attestation in server.json; legacy backends require their
original, unchanged binary to remain available for attestation.
A failed exclusive-lock conversion restores the shared client lock before reuse.
Backend-idle probe errors cannot authorize termination. Deferred state appears in
`adom-codex-runtime --runtime-status`. Replacement still requires no other proxy
clients and an authoritatively idle backend, on a subsequent connection. This
change does not implement a proactive watcher swap or an interrupt-and-upgrade UI.
## Real-binary regression test
The installed extension builds were used in an isolated CODEX_HOME:
- openai.chatgpt 26.901.22334: native codex-cli 0.153.0.
- openai.chatgpt 26.903.71938: native codex-cli 0.153.4.
- Their complete generated experimental schema bundles matched byte-for-byte.
- A local HTTP/SSE model fixture held a turn open; no real model call or billing.
- A newer client connected while old clients were attached, read the existing
active turn, and preserved the old backend PID.
- With all old clients gone but that turn still active, the newer client again
connected without replacing the backend.
- Three proxy replacements preserved the turn ID and delivered its completion.
- Exactly one fixture model request occurred; reconnect did not restart work.
- Once clients closed and work completed, the newer backend replaced the old one
and reopened the saved conversation successfully.
- An unattested identity change still refused replacement during active work.
Reproduce with the installed native paths in ADOM_TEST_CODEX_OLD,
ADOM_TEST_CODEX_NEW and ADOM_CODEX_NATIVE (the latter selects the normal CLI):
```sh
python3 -m unittest discover -s tests -v
node --test tests/test_webview.cjs tests/test_dashboard.cjs
```
All 17 Python tests and four Node test entries passed. Unit tests also cover
shared-lock retention, failed idle probes, different/unknown protocols, replaced
legacy binaries, retained attestations after VSIX removal, cache invalidation,
and downgrade refusal.
## Local deployment
Only the installed package's runtime/runtime.py was patched from the reviewed
source. No editor reload, backend restart, settings changes, auth changes, or
arav-rog calls occurred. This is a local runtime patch, not a registry publication.
Before and after: native backend PID 49708, extension 26.903.71938. A fresh proxy
using the installed runtime initialized and listed three loaded threads. The
editor tab API retained the existing titled conversation editors. No new live
user turn was submitted and no UI reload was used to manufacture an upgrade.
The actual version transition was exercised in the isolated regression fixture.
Source and installed runtime SHA256:
`5c3a3cc957df5663bc08ebea0458c7b3e2a2f5afa5c5dcbd579da19c6af9b927`.