Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 15 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,20 @@
# Changelog

## 0.9.0 — Unreleased
## 0.9.1 — Unreleased

- Accept first-party Claude Team subscriptions alongside Pro and Max while
preserving exact first-party authentication checks and account-data redaction.
- Restore macOS Keychain discovery with canonical POSIX `USER` and `LOGNAME`
values without inheriting ambient identity, credential, provider, proxy, or
routing overrides.
- Accept either reviewed Fable runtime primary (`claude-fable-5` or
`claude-opus-4-8`) plus only the exact reviewed Haiku helper, while keeping
the separate Opus route pinned to `claude-opus-5` with no helper.
- Require schema-validated Advisor decisions, normalize one unambiguous Claude
result object/event, and reject malformed, conflicting, or raw-prose review
output without exposing model-authored content in errors.

## 0.9.0 — 2026-07-25

- Add Claude Opus 5 as a sealed first-party subscription Planner or Advisor
through Claude Code 2.1.219 or newer, with exact effort validation and
Expand Down
10 changes: 6 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -200,10 +200,12 @@ Fable 5 is the bundled cross-provider exception retained for compatibility;
Opus 5 is the second sealed bundled exception added in version 0.9.0.

The bundled Claude bridge starts each authentication and model subprocess with
only a minimal platform environment. It preserves canonical `HOME` on POSIX or
`USERPROFILE` on Windows so the official CLI can find the user's first-party login,
but it does not inherit credential, config-redirection, provider/model/effort,
endpoint/gateway, proxy/CA/mTLS, or telemetry override families.
only a minimal platform environment. It preserves `HOME` plus canonical
operating-system `USER` and `LOGNAME` on POSIX, or `USERPROFILE` on Windows, so
the official CLI can find the user's first-party login. It does not trust ambient
POSIX identity values or inherit credential, config-redirection,
provider/model/effort, endpoint/gateway, proxy/CA/mTLS, or telemetry override
families.

Models already available through Codex can still become ordinary user-owned roles:

Expand Down
2 changes: 1 addition & 1 deletion plugins/codex-orchestration/.codex-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "codex-orchestration",
"version": "0.9.0",
"version": "0.9.1",
"description": "Give Codex and audited external models safe, provider-pinned roles.",
"author": {
"name": "CJ Zafir",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -355,7 +355,7 @@ python3 <skill-dir>/scripts/configure_native_routing.py \
--apply
```

Add `--advisor-model` and `--advisor-effort` for a same-provider Codex advisor. For Claude Fable 5, use `--advisor-fable`; add `--advisor-effort low|medium|high|xhigh|max` when the user chooses one. Omitting Fable effort defaults to `high`, while user-facing `ultra` is normalized to Claude Code's `max`. The configurator verifies that the installed Claude Code CLI advertises the selected effective effort. It also requires Claude Code to be logged in through a first-party Pro or Max account, chooses an available Python 3.11+ MCP launcher, and performs only an auth/capability check during setup. It never extracts a token, writes a credential, or makes a model call during setup or status. Omission persists `advisor: none`.
Add `--advisor-model` and `--advisor-effort` for a same-provider Codex advisor. For Claude Fable 5, use `--advisor-fable`; add `--advisor-effort low|medium|high|xhigh|max` when the user chooses one. Omitting Fable effort defaults to `high`, while user-facing `ultra` is normalized to Claude Code's `max`. The configurator verifies that the installed Claude Code CLI advertises the selected effective effort. It also requires Claude Code to be logged in through a first-party Pro, Max, or Team account, chooses an available Python 3.11+ MCP launcher, and performs only an auth/capability check during setup. It never extracts a token, writes a credential, or makes a model call during setup or status. Omission persists `advisor: none`.

For Claude Opus 5 Advisor, use `--advisor-opus` with an optional exact
`--advisor-effort low|medium|high|xhigh|max`. The default is `high`. Setup also
Expand Down Expand Up @@ -466,10 +466,10 @@ Report authentication as `first-party login ready`; do not expose or restate Cla
Prerequisites:

- the official `claude` CLI is installed;
- `claude auth status` reports a first-party Pro or Max login;
- `claude auth status --json` reports a first-party Pro, Max, or Team login;
- a Python 3.11+ launcher is available.

The plugin packages three disabled MCP launcher variants for macOS, Linux, and Windows. Setup enables exactly one compatible variant through the plugin's namespaced config when either bundled Claude model is selected. At planning or review time the MCP server gives authentication and model subprocesses only a minimal platform environment. It preserves canonical `HOME` on POSIX or `USERPROFILE` on Windows for first-party login discovery, but does not inherit credential, config-redirection, provider/model/effort, endpoint/gateway, proxy/CA/mTLS, or telemetry override families. It invokes `claude --print --model <sealed-model-id>` with `--safe-mode`, no tools, no session persistence, prompt suggestions disabled, and JSON output. Each saved seat pins its model and effort; the root cannot replace them through tool arguments.
The plugin packages three disabled MCP launcher variants for macOS, Linux, and Windows. Setup enables exactly one compatible variant through the plugin's namespaced config when either bundled Claude model is selected. At planning or review time the MCP server gives authentication and model subprocesses only a minimal platform environment. It preserves `HOME` plus canonical operating-system `USER` and `LOGNAME` on POSIX, or `USERPROFILE` on Windows, for first-party login discovery. It does not trust ambient POSIX identity values and does not inherit credential, config-redirection, provider/model/effort, endpoint/gateway, proxy/CA/mTLS, or telemetry override families. It invokes `claude --print --model <sealed-model-id>` with `--safe-mode`, no tools, no session persistence, prompt suggestions disabled, and JSON output. Advisor review additionally requires Claude Code's `--json-schema` capability. Each saved seat pins its model and effort; the root cannot replace them through tool arguments.

Fable effort is configurable per setup. The default is `high`; supported Claude Code values are `low`, `medium`, `high`, `xhigh`, and `max`. Accept `ultra` as an alias for `max`, save the effective Claude Code value, and disclose the alias mapping in setup output. Existing saved `max` routes remain valid.

Expand All @@ -478,10 +478,12 @@ exactly `low`, `medium`, `high`, `xhigh`, and `max`; no alias is accepted.
Setup requires only that the selected sealed effort appear in the installed
CLI's advertised set. Extra advertised values do not expand the sealed set.

The bridge exposes only bounded, read-only planning operations. `create_plan` accepts one self-contained packet and requires `PLAN_DRAFT`. `revise_plan` requires the task, canonical current plan, latest critique, and compact findings history, then requires `PLAN_REVISION` plus a findings ledger and revised plan. `review_plan` remains the Advisor operation and requires `PLAN_APPROVED` or `PLAN_REVISE`. Every call uses the same full saved-state validator as native status/repair/disable, then requires runtime `modelUsage` to contain the pinned primary plus only that model's explicit exact helper allowlist. Fable permits its independently observed `claude-haiku-4-5-20251001` helper. No Opus helper identity is independently established, so Opus currently permits only `claude-opus-5` and fails closed if any additional runtime model appears. Return every observed ID in `used_models`; an unknown additional or missing primary model makes the seat unavailable. Any auth, transport, state, format, or model-confirmation failure makes that seat unavailable; it never counts as approval. The bridge returns no account identifier or credential. Local mocked verification does not prove a positive live Opus invocation.
The bridge exposes only bounded, read-only planning operations. `create_plan` accepts one self-contained packet and requires `PLAN_DRAFT`. `revise_plan` requires the task, canonical current plan, latest critique, and compact findings history, then requires `PLAN_REVISION` plus a findings ledger and revised plan. `review_plan` remains the Advisor operation and requires a locally revalidated JSON Schema object containing exactly `PLAN_APPROVED` or `PLAN_REVISE` plus a non-empty body; raw prose never counts as a decision. Every call uses the same full saved-state validator as native status/repair/disable, then requires runtime `modelUsage` to contain a reviewed Fable primary identity (`claude-fable-5` or `claude-opus-4-8`) or the exact Opus primary, plus only that model's explicit exact helper allowlist. Fable permits its independently observed `claude-haiku-4-5-20251001` helper. No Opus helper identity is independently established, so Opus currently permits only `claude-opus-5` and fails closed if any additional runtime model appears. Return every observed ID in `used_models`; an unknown additional or missing primary model makes the seat unavailable. Any auth, transport, state, format, or model-confirmation failure makes that seat unavailable; it never counts as approval. The bridge returns no account identifier or credential. Local mocked verification does not prove a positive live Opus invocation.

The legacy Fable contract requires runtime `modelUsage` to contain the pinned `claude-fable-5`
primary; Opus applies the same primary-presence rule to `claude-opus-5`.
The configured Fable route remains `claude-fable-5`, while runtime `modelUsage`
may confirm either reviewed Fable primary identity. This does not make
`claude-opus-4-8` an Opus route alias. Opus still requires the exact
`claude-opus-5` primary.

Plugin and policy updates cannot replace the MCP process already loaded into the
current task. If a bundled Claude call fails after an update or repair, run fresh
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -228,22 +228,25 @@ On Windows, in-place update and removal stage the replacement beside the existin

Direct v2 `model` overrides retain the parent's provider. They are the simplest route for an OpenAI root and OpenAI Luna/Terra child.

Claude Fable 5 and Claude Opus 5 are explicit built-in exceptions for Planner or Advisor. The plugin does not pretend either is a Codex model or translate Anthropic into the Responses protocol. Instead, a disabled-by-default local MCP server invokes the official `claude` CLI with the user's first-party Pro or Max login. Setup enables one Python 3.11+ launcher variant, and disable restores every prior plugin override value. The historical `fable-advisor-*` IDs are compatibility names shared by both sealed models. Codex's TOML editor can retain an inert empty table header after its final key is deleted; the configurator does not risk a broad TOML rewrite for cosmetic cleanup.

The bridge starts both `claude auth status` and model calls with only a minimal
platform environment. It preserves canonical `HOME` on POSIX or `USERPROFILE` on
Windows so the official CLI can discover the first-party login, but it does not
inherit credential, config-redirection, provider/model/effort, endpoint/gateway,
proxy/CA/mTLS, or telemetry override families. It pins the saved primary and effort,
disables tools and session persistence, disables prompt suggestions, and requires
JSON runtime metadata to contain that primary. Claude Code currently reports the
internal helper `claude-haiku-4-5-20251001` during valid Fable calls; the bridge
permits only that exact helper ID. No Opus helper identity is independently
established, so the Opus runtime allowlist currently contains only `claude-opus-5`.
Any missing primary or unknown additional model fails closed. Helper rotation
therefore requires a reviewed plugin update rather than a wildcard. Setup and status
never make a model call, and mocked local tests do not constitute a positive live
Opus invocation.
Claude Fable 5 and Claude Opus 5 are explicit built-in exceptions for Planner or Advisor. The plugin does not pretend either is a Codex model or translate Anthropic into the Responses protocol. Instead, a disabled-by-default local MCP server invokes the official `claude` CLI with the user's first-party Pro, Max, or Team login. Setup enables one Python 3.11+ launcher variant, and disable restores every prior plugin override value. The historical `fable-advisor-*` IDs are compatibility names shared by both sealed models. Codex's TOML editor can retain an inert empty table header after its final key is deleted; the configurator does not risk a broad TOML rewrite for cosmetic cleanup.

The bridge starts both `claude auth status --json` and model calls with only a
minimal platform environment. It preserves `HOME` plus canonical
operating-system `USER` and `LOGNAME` on POSIX, or `USERPROFILE` on Windows, so
the official CLI can discover the first-party login. Ambient POSIX identity,
credential, config-redirection, provider/model/effort, endpoint/gateway,
proxy/CA/mTLS, and telemetry override families are not trusted. It pins the
saved route and effort, disables tools and session persistence, disables prompt
suggestions, and requires JSON runtime metadata to contain an allowed primary.
For the Fable route, the reviewed primary identities are `claude-fable-5` and
its resolved runtime identity `claude-opus-4-8`; only the exact internal helper
`claude-haiku-4-5-20251001` is additionally permitted. The separate Opus route
still requires `claude-opus-5`, with no helper. Advisor decisions use
`--json-schema` and are locally revalidated; raw prose is not approval. Any
missing primary or unknown additional model fails closed. Identity rotation
therefore requires a reviewed plugin update rather than a wildcard. Setup and
status never make a model call, and mocked local tests do not constitute a
positive live Opus invocation.

An MCP process is loaded for the lifetime of its Codex task. Updating the plugin or
repairing policy state cannot replace that already loaded process. If a current-task
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -456,7 +456,7 @@ def __init__(
"clientInfo": {
"name": "codex_orchestration_installer",
"title": "Codex Orchestration Installer",
"version": "0.9.0",
"version": "0.9.1",
},
"capabilities": {"experimentalApi": True},
},
Expand Down Expand Up @@ -1005,6 +1005,7 @@ def verify_claude_prerequisites(model: str, effort: str) -> dict[str, str]:
"--no-session-persistence",
"--prompt-suggestions",
"--output-format",
"--json-schema",
"--system-prompt",
)
advertised_options = set(
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -142,13 +142,23 @@ def invoke(
result.get("effort") == selected_effort,
"subscription runtime effort drifted",
)
used_models = result.get("used_models")
_require(
model in result.get("used_models", []),
type(used_models) is list
and bool(used_models)
and all(type(value) is str and bool(value.strip()) for value in used_models),
"subscription runtime metadata is invalid",
)
reviewed_primaries = (
fable_advisor_mcp.REVIEWED_PRIMARY_MODELS_BY_ROUTE[model]
)
_require(
bool(set(used_models).intersection(reviewed_primaries)),
"subscription runtime metadata omitted the primary model",
)
allowed_runtime = fable_advisor_mcp.ALLOWED_RUNTIME_MODELS_BY_PRIMARY[model]
_require(
set(result.get("used_models", [])).issubset(allowed_runtime),
set(used_models).issubset(allowed_runtime),
"subscription runtime metadata included an unsealed helper model",
)
return result
Loading
Loading