- [fix merged] PR #360 (
e3787857953998a1916c39b10942ac6c15978a25) passed exact-head CI run31558654733: Static, macOS repository regressions plus universal DMG, Windows PowerShell 7, and Windows PowerShell 5.1 plus Setup.exe. It was squash-merged with the authorized same-owner review bypass at2026-08-12T03:06:37Zasmain@69a5a2e4b68174b1c0c70a2fa62adf1aca1eff2a. - [release branch] This isolated worktree is
codex/release-v1.5.14from that exact merge commit. Only the six version sources, two version-bound macOS assertions, both platform changelogs, and this durable progress record are in scope. All six version sources equal1.5.14. - [local gate] Portable Node regressions pass 103/103; runtime asset sync, macOS/Windows payload checks, Node/Bash syntax, version consistency, and
git diff --checkpass.CODEX_DREAM_SKIN_SKIP_DOCTOR=1 bash macos/tests/run-tests.shpasses with only the documented full-Xcode XCTest and installed signed Codex Doctor branches skipped. - [next] Commit and push the version branch, open a Ready PR, require exact-head CI, merge it, then verify the sole Release workflow creates
v1.5.14from the exact main merge and publishes non-empty DMG, Setup.exe, andSHA256SUMS.txt. Only after public asset/checksum verification will #352 receive the customer reply; keep it open pending field confirmation.
- [root cause] The reporter's exact
One-click apply requires an existing verified Dream Skin session.failure is the cold-session guard introduced by PR #245 (c44b434, merged as71f30f0), not PR #357. The guard conflicts with the documented one-click start/restart path by rejecting before that path can run. Upstream Issue #235 remains a separate limitation: current Store Codex may still fail to expose a verified CDP endpoint after startup. - [local implementation] Isolated worktree
/private/tmp/dreamskin-issue352-baseline, branchcodex/fix-352-one-click-baseline, starts from exact public v1.5.13main@6ae42e645c15f6ac91f5fa54a9c37dbc57af646c. The Windows community apply path now classifies only a missing session as bootstrap-eligible, releases the operation lock while invoking the existing start-and-verify child, then reacquires the lock and revalidates the complete old-theme baseline and its fingerprint. All other baseline failures remain fail-closed. - [safety/order] User confirmation still precedes startup. Old-theme baseline establishment and visible verification precede temporary work-root creation, ZIP download, import, snapshot, or active-theme write. The transaction keeps its second baseline check to reject a concurrent pause/theme/session change. A baseline failure therefore performs zero candidate download/import/write, and no longer claims that nonexistent download files were cleaned up.
- [tests] Before the final orchestration assertion, focused PowerShell suites passed for community apply, both appearance
recovery paths, renderer readiness, verified-skin preservation, config
rollback, and the structured start-result contract. All 11 Windows scripts
parse; Windows Node tests pass 27/27, tools Node tests 2/2, and the focused
macOS ZIP validator passes. The final portable Node set passes 103/103,
runtime asset sync, dual payload checks, Node syntax, and
git diff --checkpass. The portable macOS set previously passed 73/74 in one parallel run with only a host subprocess exit 141, and that exact ZIP case passed alone. Full Windows wrapper and one ZIP guard remain native-Windows CI gates because macOS lacksGet-AuthenticodeSignatureand resolves/varthrough a symlink. This shell no longer haspwshinstalled, so the final test-only orchestration ordering assertion has not been executed locally and remains an explicit exact-head Windows CI gate. - [independent review] Final read-only review found no P0/P1. It confirmed lock release before child startup, bounded lock reacquisition, exact fingerprint revalidation, download-before-baseline prevention, accurate cleanup messaging, and PowerShell 5.1-compatible syntax. Residual evidence required before merge is exact-head Windows PowerShell 5.1/7 CI plus Setup.
- [current truth] Six implementation/test/documentation/progress files are modified and uncommitted. No push, PR, merge, version bump, tag, Release, or Issue reply exists for this fix yet. Next: rerun the corrected focused/static gates, review the final diff, commit/push, open a Ready PR, and require all four exact-head CI jobs before merge. Then prepare v1.5.14 through the sole Release workflow, verify tag/assets/checksums/public status, and reply to #352 without closing it until the reporter confirms the field fix.
- [current local implementation] All prior independent-audit findings are
addressed. Startup appearance uses a strict, 64 KiB durable
preparing -> committedjournal before marker/config writes. Recovery is three-way per managed key and marker, preserves a newer post-crash usersystem -> lightedit, rejects a journal whose declared changes do not match its snapshots without mutating config/marker/evidence, and normalizes CRLF snapshot line endings before serialization. One-click child completion gets lock timeout plus 300000 ms independent grace, never force-kills a live child, and keeps candidate files coherent for timeout/invalid/blocked/preserved-renderedstates. A rendered-but-unverified result-token child closes its exact new CDP session and restores appearance before returningrestored. - [focused verification 2026-08-12] Seven PowerShell 7.6.4 suites pass together:
config-startup-rollback,start-result-contract, CDP-failure recovery, post-launch recovery, renderer readiness, verified-skin preservation, andcommunity-theme-link. Executable coverage includes marker/config hard-stop windows, tampered journals, CRLF quoted keys and dollar-bearing values, post-crash user edits, 480000 ms parent wait, no force-kill/result cleanup while the child remains live, preserved-rendered file coherence, and the full outer child catch/writer/reader category path. - [complete local gate 2026-08-12] Portable Node passes 103/103 (macOS 74,
Windows 27, tools 2). All 23 PowerShell files parse and satisfy the PS5.1
non-ASCII UTF-8 BOM policy; all Node and Bash syntax checks, both platform
payload checks, runtime asset sync, and
git diff --checkpass. The fullCODEX_DREAM_SKIN_SKIP_DOCTOR=1 bash macos/tests/run-tests.shwrapper exits 0, including signed-runtime switch and runtime-state integration. Native SwiftPM/XCTest is skipped because this host lacks a matching full Xcode platform, and Doctor is explicitly skipped because no installed signed Codex app is available. Native Windows PowerShell 5.1/7 and Setup remain CI gates. - [independent final audit] Read-only review of the complete local diff found no
remaining P0/P1. The prior parent hard-kill and
preserved-renderedmixed-state blockers are closed by executable production-helper/result-path coverage. Non-blocking P2 residuals are documented: same-user coherent rewriting of the entire local journal is outside corruption detection; the explicitly invoked test/debug-only-ForegroundInjectormode has a narrow pre-injector committed window and no production caller; and a concurrent manual action choosing byte-identical theme content is indistinguishable from no superseding change. - [remote state] PR #351 is squash-merged as
main@9e6798700c0e35be0713135ebd9b3a6f01583499; exact-head run31522162828and post-merge run31523222468passed all four client CI jobs. Draft PR #357 targets thatmainfromcodex/fix-354-appearance-rollback@fa3e53822a4158d56dc1ae10efa8f288b2d73a88. Exact-head run31531028135passed Static, macOS/DMG, Windows PowerShell 7, and Windows PowerShell 5.1/Setup. - [pushed checkpoint] The 15 implementation, test, and Windows documentation
files are committed as
54933c3678034333a4e00c0a93c9d4da5d2ded6d; the first verification checkpoint is8ad35f2. Both were pushed tocodex/fix-354-appearance-rollbackfor Draft PR #357. Run31531028135remains historical evidence for older headfa3e538, not the new changes. - [scope] The PR fixes only caught Windows failed-start partial appearance,
rollback ownership/concurrency, and bounded one-click diagnostics. It does
not claim that official Store Codex
26.803.5235.0restored a supported CDP endpoint. User authorization covers scoped commit, push, PR merge, and issue handling, but not a version, tag, Release, deployment, or external config. - [remaining] Push this progress-only checkpoint and update the PR body. Require
all four CI jobs green on the resulting exact head before marking #357 Ready
and squash-merging with head protection. Verify post-merge
mainCI, then update only #235, #352, and #354. Native Windows 5.1/7 and Setup are CI-only evidence on this macOS host.
- [scope] Reviewed and merged 10 pending community/self PRs that had accumulated
unmerged on
mainsince late July (#68, #212, #283, #284, #285, #286, #288, #289, #106, #342) — each individually verified against currentmainbefore merge: git-mergeable both alone and stacked together, no version-fragile selector/DOM assumptions, and (for #283 specifically) the Safe CSS sandbox inruntime/safe-css-policy.jsonwas cross-checked to confirm no community theme can trip the stricter visibility check (opacity floored at 0.65, display/visibility/position not themable at all). - [diagnosed] Merging #68 exposed that
macos/scripts/image-metadata.mjsis generated fromruntime/image-metadata.mjsviatools/sync-runtime-assets.mjs; #68 edited the generated output directly instead of the source, so--checkfailed onmainandwindows/scripts/image-metadata.mjsnever picked up the newreadRawDimensionsexport at all. Fixed at the source and regenerated both platform outputs (#347). - [diagnosed]
Static checksCI was independently red onmain— 3 tests inmacos/tests/renderer-verification.test.mjsfailed againstmainHEAD directly, unrelated to any merge here. Root cause: the test's hand-rolled DOM mock had drifted from the real runtime contract in three ways (staleshell-mainselector literal predating the 26.727:is(...)update, missingscope.missingL1thatassessRendererVerificationrequires, hardcodedversion: "1.5.6"against the realSKIN_VERSIONof"1.5.11"). Fixed the fixtures and exportedSKIN_VERSIONso the test imports the real constant instead of re-hardcoding a value that drifts on every release (#349). - [implemented] Regrouped the menu bar's ~16 flat top-level items into
主题/链接/维护submenus, and replaced the always-present manual "检查更新…" item with a background check (24h timer + one-shot ~15s after launch) that posts a system notification the first time a new version is seen and shows a conditional "🆕 发现新版本" item only while one is available; manual check moved into 维护 as "立即检查更新" (#348). Could not runswift build/swift testlocally — this sandbox's Command Line Tools (Swift 5.10) don't match the macOS 15.2 SDK (needs 6.0.3) — so an independent review agent read the full diff for compile-breaking issues before push, and the PR was only merged after real CI'smacos-latestjob (swift test --package-path macos/menubar-app+ DMG build) came back green. The review agent's two substantive findings (install doc no longer matched the new background-polling behavior; a manual check during an in-flight background check could double-spawncheck-update-macos.sh) were fixed before merge with a dedicatedupdateCheckInFlightguard separate from the broaderoperationInFlightbusy state, so the 24h timer no longer disables the primary apply/open actions while it runs. - [verified] Before cutting the version:
node --test macos/tests/*.test.mjs windows/tests/*.test.mjs tools/*.test.mjs(93/93 pass), fullmacos/tests/run-tests.shincluding signed-runtime and Doctor checks, and bothinjector.mjs --check-payloadinvocations all pass onmainpost-merge. - [implemented] Version bump touches all six release version sources
(
macos/VERSION,windows/VERSION,macos/package.json,macos/scripts/common-macos.sh, both platforms'injector.mjsSKIN_VERSION) plus the two hardcoded1.5.11assertions inmacos/tests/run-tests.sh(the update-check JSON fixture and thecommon-macos.sh-sourced$SKIN_VERSIONcheck). A grep-only pass across the repo for the literal1.5.11first missed a third real dependency:windows/tests/injector-window-readiness.test.mjsimportsverifySession(notassessRendererVerificationdirectly), so its mock__CODEX_DREAM_SKIN_STATE__.versionis transitively checked against the realSKIN_VERSIONeven though the test file never names that identifier. The full portable test run after the version bump caught this immediately (4 failures) before it reached CI; fixed the same way as the macOSrenderer-verification.test.mjscase — exportSKIN_VERSIONfromwindows/scripts/injector.mjs(as a separateexport { }statement, same reason as macOS) and import it into the test instead of re-hardcoding.windows/tests/start-verified-skin-preserved.tests.ps1's literal"version":"1.5.11"is a fully mocked PowerShell fixture with no path toSKIN_VERSIONat all (grepped every.ps1script; it's JS-only), so that one is genuinely safe to leave unchanged. - [gap] Live click-through of the reorganized macOS menu bar and a real
"update available" notification have not been manually exercised on a
physical Mac — verification here is CI (
swift test) plus static review, not an interactive smoke test.
- [scope] Branch
codex/fix-macos-reapply-open-chatgptwas created from latestupstream/main(0a727a5). Fix the macOS menu behavior where the first "重新应用皮肤" click can restart ChatGPT even though the prompt says no restart, and review its interaction with the separate "打开 ChatGPT" action. - [diagnosed] The menu title is derived from lightweight
session=activestatus, whileapply-from-menubar-macos.shalways callsstart-dream-skin-macos.sh --restart-existing. If ChatGPT is running without a verified CDP endpoint,start-dream-skin-macos.shstops and relaunches it. - [implemented]
apply-from-menubar-macos.shkeeps the originalCHEAP_RUNNING/SESSIONprompt flow and now attemptshot_reapply_themeafter the existing confirmation but before falling back tostart-dream-skin-macos.sh --restart-existing. A successful hot reapply exits without restarting ChatGPT. - [corrected] The native menu keeps the original "打开 ChatGPT" operation title
and always shows that action. Its implementation preserves the original
"未找到 ChatGPT" and "无法打开 ChatGPT" error surfaces, but replaces the
successful native
NSWorkspace.openApplicationlaunch with the Dream Skin start path only when the installed engine is complete. If the engine is missing or incomplete, the action falls back to nativeNSWorkspaceopening and does not install the engine implicitly. - [covered] Added static regressions to lock menu apply hot-reload ordering,
the preserved session-driven prompt model, the unchanged "打开 ChatGPT" title,
the Dream Skin-backed open action, and the native fallback when the engine is
not installed. The macOS test Gatekeeper scan now ignores the same
.build-*SwiftPM artifacts already listed inmacos/menubar-app/.gitignore. - [verified 2026-08-06]
bash -n macos/scripts/apply-from-menubar-macos.sh macos/tests/run-tests.sh,git diff --check,swift build --package-path macos/menubar-app --product CodexDreamSkinMenuBar, andCODEX_DREAM_SKIN_SKIP_DOCTOR=1 bash macos/tests/run-tests.shall pass. The wrapper skipped Doctor as requested by the environment flag. - [gap] Live restore / re-apply / open ChatGPT smoke has not been rerun after narrowing the implementation back to the minimal AppDelegate + hot-reapply path.
- [gap] Direct
swift test --package-path macos/menubar-appfails on this host because the installed Swift toolchain cannot importXCTest; the repository macOS test wrapper detects the missing full matching Xcode platform and skips native XCTest accordingly.
- [base/merged] Settings renderer PR #334 passed exact-head CI run
30648201928at6d8d2c561cae1e6084bd1fd288264be7c0823907: Static, macOS with Universal DMG, Windows PowerShell 7, and Windows PowerShell 5.1 with Setup.exe compilation all succeeded. It was squash-merged tomainas6e71534cd9cd55f87d1f6c9ff1cf305c7ef43893. - [scope] Independent worktree
/private/tmp/dreamskin-release-v1511.KVcKVgis oncodex/release-v1.5.11from that exactorigin/main. The release changes only the six required platform version sources, four version-bound assertions, both platform changelogs, and this durable record. - [implemented locally] All six release version sources and four bound test
assertions now report
1.5.11. Both changelogs describe the shared Codex 26.727 Settings marker fix and its strictapp:origin boundary. - [verified locally] The six-source consistency check passes. Portable Node
regressions pass 82/82 (macOS 63 and Windows 19); both platform payload
checks report v1.5.11; runtime asset sync and
git diff --checkpass. The complete applicable macOS suite passes with only its documented full-Xcode, installed signed-runtime, and Doctor branches skipped. - [committed locally] Reviewed release commit
7d87e6e5ab14256ce6a44a2b7c327bfa6afef878contains exactly the 12-file v1.5.11 scope above. - [pushed/PR open] Release commit
7d87e6e5ab14256ce6a44a2b7c327bfa6afef878and progress commit733b0a3ae95779714a736de86bcf1daf40cc1501are pushed oncodex/release-v1.5.11; PR #335 targetsmainathttps://github.com/Fei-Away/Codex-Dream-Skin/pull/335. - [pending] Commit and push this PR checkpoint, require four exact-head CI
jobs, then merge.
Only the Release workflow from the resulting
maincommit may tag and build the public DMG, Setup.exe, andSHA256SUMS.txt.
- [scope] Client worktree
/private/tmp/dreamskin-settings-fix.4tH4ldis oncodex/fix-26-727-settings-renderer; PR #334 targetsmain. The pre-fix PR head is159c650c3b43877df4413a7b0a20562fe556a018. - [reproduced from CI] Run
30646840223passed Static checks and macOS repository regressions, but both Windows PowerShell 5.1 and PowerShell 7 jobs failed in their regression suite. On the Windows CRLF checkout, the bootstrap source-contract test's fixed 2,200-character slice ended atsetInterval(in, before the assertedsetInterval(install, 250)text. - [fixed locally/tests only] Both platform bootstrap tests now inspect the
complete string returned by the already imported
earlyPayloadFor("", "source-contract"). This removes line-ending-dependent truncation without changing or weakening the early-injection assertions and without changing runtime implementation. - [verified locally]
node macos/tests/injector-bootstrap.test.mjs,node windows/tests/injector-bootstrap.test.mjs, both platformrenderer-inject.test.mjstests,node tools/doctor-selectors.test.mjs, andgit diff --checkall pass. - [committed/pushed] Test-only fix commit
7d19780ec56446c3d1bd1ac61931588c5487f55fis pushed toorigin/codex/fix-26-727-settings-rendererfor PR #334. - [pending] Require a fresh exact-head CI pass for all four jobs before merge. No merge, release, deployment, Issue reply, or Issue closure has occurred in this follow-up.
- [base] Feature PR #324 was squash-merged to
mainata58e63c6909082706c02824622d0e902b3539065; its exact-head CI run30638018730passed all four jobs. - [scope] Branch
codex/release-v1.5.10changes the six required version sources, version-bound assertions, dual-platform changelogs, the exact-event Release binding and its regression, plus this durable release record. Public v1.5.9 is the predecessor; v1.5.10 does not yet exist. - [verified locally] All six release version sources are exactly
1.5.10. Portable macOS/Windows Node regressions pass 82/82, and the complete applicable macOS suite exits 0 with only its documented full-Xcode native XCTest and installed signed-Codex Doctor branches skipped. Runtime asset sync, all Node/Bash syntax, both payload checks, PowerShell 5.1 BOM and execution-policy scans, andgit diff --checkpass. - [committed locally] Version release commit
7abaea700130207ab2a57cf6ae4881f9673ff93dcontains only the reviewed v1.5.10 release scope above. - [pushed/PR open] Branch
codex/release-v1.5.10is onorigin; release PR #332 targetsmainathttps://github.com/Fei-Away/Codex-Dream-Skin/pull/332. - [fixed before merge] Independent release review found the guard checked out
moving
main, so a later push could retarget v1.5.10 before packaging. The guard now checks out${{ github.sha }}, derives the release candidate from that exactHEAD, and has a portable regression rejecting moving-main release binding. - [pending] Require all PR CI jobs on the final head, merge #332 to
main, then verify the sole Release workflow creates tag v1.5.10 and publishes non-empty DMG, Setup.exe, and SHA256SUMS.txt from the exact merge.
- [reproduced by review] Both platform importers move the existing canonical theme to a hidden replacement backup before publishing the new directory. An uncatchable process termination or system restart between those two atomic moves leaves the canonical saved theme missing; neither platform currently recovers the hidden backup on the next import/startup.
- [scope] Add a persisted, contained replacement journal before the first move. Under the existing import lock, recovery must restore the verified old fingerprint when the canonical destination is absent, keep a verified new destination when publication committed, and fail closed without deleting evidence on identity/path/fingerprint ambiguity.
- [ownership] Root owns only macOS publisher/test changes; the Windows agent
owns only
windows/scripts/theme-windows.ps1andwindows/tests/theme-zip-import.tests.ps1; the protocol-review agent is read-only. Root will run the combined gates before any push. - [fixed locally/macOS] Replacement candidates and journals are durably synced
before the first canonical move. Prepared recovery now restores the verified
old canonical theme before inspecting a suspect candidate, retains malformed
evidence, rejects conflicting
committedpluscommit.tmpmarkers, and preflights duplicate destination journals before any recovery mutation. - [verified locally/macOS]
node --test macos/tests/theme-import-publish.test.mjspasses (1/1, 12.8 s), including real child-processSIGKILLafter backup rename, candidate publication and commit-marker rename, plus corrupt-candidate, conflicting-marker and duplicate-transaction recovery cases.node --checkandgit diff --checkalso pass at this checkpoint. - [verified locally/macOS app] An x86_64 menu-bar app build and strict deep code-signature verification passed before the final wrapper correction. Packaging included the new executable wrapper and publisher, but that build is now superseded and must be repeated before push.
- [fixed locally/macOS wrapper] Packaging review caught the wrapper calling the
nonexistent
discover_codex_bundle; it now uses the establishedensure_node_runtimepath. A source regression guards that call, and the focused publish suite, wrapper Bash syntax, andgit diff --checkpass after the correction. Startup recovery failure cancels any pending one-click apply and reports a bounded repair instruction instead of silently continuing. - [verified locally/macOS final app] The corrected source builds as
/tmp/CodexDreamSkin-pr324-recovery-final.app(x86_64 Mach-O). Strict deep code-signature verification passes; the packaged recovery wrapper is executable, and its bytes plus the publisher bytes match the current worktree exactly. - [verified locally/macOS full gate]
CODEX_DREAM_SKIN_SKIP_DOCTOR=1 bash macos/tests/run-tests.shpasses on the integrated macOS files, including the publish hard-kill regression, ZIP/archive bounds, community apply rollback, installer rollback, signed-runtime switch, and runtime-state integration. Only the documented full-Xcode native XCTest and installed signed-Codex Doctor branches skipped on this host. - [fixed locally/Windows] Only a durable
committedjournal plus marker retains the new theme. Earlier phases restore the verified old fingerprint first; corrupt or missing candidate evidence is retained with the journal and fails closed. Duplicate destinations and unsafe/unknown journal fields are rejected before mutation, cleanup order is crash-safe, and legacy cleanup is outside rollback. A corrupt published candidate is moved back to its contained stage before the exact old canonical theme is restored. - [covered/Windows] The focused suite now includes a real child
FailFastafter the first rename plus deterministic restart states for published and committed phases, corrupt/missing candidates, duplicate targets, unsafe journals, and committed-marker conflicts. Native PowerShell execution is unavailable on this Mac and remains a fresh PR CI gate. - [verified locally/final] Portable macOS/Windows Node regressions pass 81/81.
The complete applicable macOS suite passes with only its documented full-
Xcode native XCTest and installed signed-Codex Doctor branches skipped.
Runtime asset sync, all Node and changed Bash syntax, Windows PowerShell BOM,
execution-policy safety, and
git diff --checkgates pass. - [committed locally] Recovery implementation and Windows validation document
are commit
dd19005e8a37ad7a80f1b957cf9759743b50d7e7on branchcodex/pr324-final-review-fixes, intended for remote PR head branchorigin/codex/fix-318-320-322(Draft PR #324). - [pending] Commit this durable progress record, push both commits to the Draft PR branch, and require fresh PowerShell 5.1/7 CI. Do not merge, release, comment on issues, or close issues.
- [reviewed] Remote Draft PR head
8b39dcdaff5985f3a2247c13176cd4329a5186ebcorrectly rejects an ordinarythread/L0renderer, but still acceptshome/L0when required L1 shell anchors are missing. That permits an unrecognized sidebar/main/header to be reported as a successful apply or rollback on both platforms. - [fixed] macOS and Windows now reserve L0 visible verification only
for the real cross-platform Settings exception. Home and ordinary task views
require
scope=L1with an emptymissingL1; focused dual-platform readiness tests and Node syntax checks pass. - [verified locally] Shared runtime sync passes, portable Node regressions pass
80/80, and the complete macOS repository suite passes with only the documented
full-Xcode and installed signed-app Doctor skips.
git diff --checkpasses. - [committed/pushed] Code fix
0884be7c34cbbd62974d1ce8669a139ffbe81be2and progress commit1a693364db0086afed30fa9a4e5991d1c61f9237are on remote Draft PR #324. The PR remains open, Draft, and unmerged. - [verified] GitHub Actions run
30632592756passed all four jobs at exact head1a693364: Static checks, macOS repository regressions with Universal DMG, Windows PowerShell 7, and Windows PowerShell 5.1 with Setup.exe compilation. - [verified locally] Root repeated the portable Node suite (80/80), complete
applicable macOS suite, runtime asset sync, and
git diff --checkat the exact remote head; all passed. Only documented full-Xcode and installed-app Doctor branches were skipped. - [correlated] New issue #330 reports the same Codex
26.727.40816app-shell selector migration already reproduced for #322/#326 and covered by this PR's shared macOS/Windows selector contract. It is not evidence of a separate unresolved root cause. - [pending] Real Windows Codex validation must be repeated from exact head
1a693364usingdocs/pr-324-windows-validation.md. Do not merge, release, tell issue users to retry a public version, or close issues before that result is reviewed.
- [reviewed] Draft PR #324 head
598dd07f6831faa238230752531bc75064baa581passed all four CI jobs and has real Windows Codex 26.727 renderer/import evidence, but that evidence exposed follow-up behavior and does not waive review of the resulting shared-runtime/import changes. - [reproduced] The head can clear the registered wallpaper whenever validated
Safe CSS sets
background-color; its client Safe CSS parser also diverges from the website/server glass-filter contract. A preceding search textbox can prevent the real prompt composer from receiving its public part marker. - [reproduced] macOS validates the extracted payload before a missing or non-string source ID is normalized, while Windows normalizes first. Windows saved-theme enumeration also permits dotted recovery directories to leak into the tray menu.
- [fixed] Root/background colors preserve the registered body wallpaper; surface image clearing is limited to registered core surfaces. The client accepts the same bounded composite glass filters as Studio/server, and a preceding search input no longer hides the real semantic composer.
- [fixed] Missing/non-string IDs pass a private pre-publish payload check only after temporary normalization, then receive the stable cross-platform ID and pass the mandatory final check before any old theme moves. Windows saved-theme enumeration filters every dotted transaction/recovery directory.
- [fixed] Generic parts can verify an ordinary route only with
scope=L1and an emptymissingL1; an L0 thread missing shell/sidebar/header can no longer make apply or rollback report false visible success. Explicit settings/home L0 anchors remain supported on both platforms. - [verified locally] Portable Node regressions pass 80/80; focused Safe CSS,
renderer, fallback-ID ZIP import, runtime sync, Node/shell syntax, and
git diff --checkpass. The complete macOS repository suite passes with only its documented full-Xcode and installed-app Doctor skips. - [committed/pushed] Fix commit
8b39dcdaff5985f3a2247c13176cd4329a5186ebis the remote code head ofcodex/fix-318-320-322; Draft PR #324 remains open and unmerged. - [verified] GitHub Actions run
30632144001passed all four jobs for8b39dcd: Static checks, macOS repository regressions with Universal DMG, Windows PowerShell 7, and Windows PowerShell 5.1 with Setup.exe compilation. - [pending] The updated real-Windows checklist must still be run from the exact PR source-installed engine. Do not merge, release, comment on issues, or close issues until that user acceptance result is reviewed.
- [verified] The official Store package is
OpenAI.Codex_26.727.4816.0; the installed DreamSkin engine was replaced from this exact worktree underRemoteSigned, and its CSS, renderer, selector, validator, and importer hashes match the repository copies. - [verified] A real
dreamskin://applytransaction downloaded and applied Lyn-in's completejuzizhoutoupackage through the native confirmation UI. The result confirmed size/SHA-256, ZIP, manifest, and Safe CSS validation. - [verified] Three current complete community themes from different creators
(
juzizhoutou,taishan-wuyue-duzun, andcecilylove002) render in the real Codex Home/task UI. Home reportsL1withmissingL1=[]; task navigation refreshes tothread/L1; sidebar, header, message region, composer, toolbar, background, and controls remain visible and interactive with no overflow. - [fixed] Real rendering exposed two final shared-runtime gaps. A root Safe CSS
background color now also clears the body's canonical image, and Codex
26.727's user/assistant conversation anchors now map to the public
messagepart while retaining the legacy selector. Real task inspection found 8/8 message anchors inside the thread and zero sidebar matches. - [verified] Final real screenshots are under
%TEMP%\dreamskin-pr324-final-live. Focused 34/34 Node regressions, selector doctor, renderer runtime, asset sync, PowerShell 5.1/7 parsing, installer static checks, andgit diff --checkpass. Full dual-PowerShell CI remains the post-push gate; no merge, Release, or Issue mutation is authorized.
- [verified] Draft PR #324 and the local branch are both at
98e308a; the macOS follow-up commits9098060/98e308aare present. The shared selector change keeps the legacy anchors and adds Codex 26.727 app-shell attributes, so its compatibility direction is appropriate for Windows as well. Real Windows 26.727 acceptance is still pending. - [verified] On real Windows Codex
26.721.11231.0, the updated selector contract still reaches Home atL1withmissingL1=[]. The new CSS parses in the Windows Chromium 150 renderer, and shared macOS/Windows selector, renderer, and CSS assets are byte-identical. - [reproduced] Full community-theme Safe CSS loads but loses the cascade for
sidebar, header, composer, home typography, and toolbar colors because the
canonical runtime uses
!importantwhile the untrusted Safe CSS contract correctly rejects author-supplied!important. Root font-family is one of the few declarations that currently wins. - [in progress] Keep the Safe CSS input contract unchanged, compile only the already-validated declarations to a controlled runtime priority, synchronize both platform assets, and add cascade regressions. Also tighten generic composer/Home verification false positives before reinstalling the exact worktree engine and repeating real Windows community-theme checks.
- [fixed] The shared parser now recompiles only validated part/property/value
rules into the
dreamskin-communitycascade layer with client-owned priority. Author CSS still rejects!important; original bytes remain the semantic/fingerprint input. A higher-priority accessibility layer preservesprefers-reduced-motionbehavior. - [fixed] Generic composer fallback now requires an explicit composer/prompt semantic owner and never marks a plain form or bare textbox. Home verification fails when runtime scope claims Home but the real Home identity/surface is absent; thread/settings routes retain their existing acceptance boundaries.
- [verified] Shared runtime sync, renderer fixture, Windows readiness 10/10, Safe CSS 9/9, and macOS/Windows payload tests 12/12 pass. macOS and Windows generated CSS, renderer, and validator assets remain synchronized.
- [in progress] Run the complete Node and Windows PowerShell 5.1/7 suites, including the preserved same-ID, reserved-ID, long-path, legacy-suffix, and rollback import cases. Then deploy the exact worktree engine and repeat real Windows Codex computed-style and community-theme interaction checks.
- [preserved] Existing uncommitted cross-platform importer changes remain in the four macOS/Windows import implementation/test files. They are not being reverted or overwritten. No merge, Release, Issue edit, or publish is in scope until explicit authorization.
- [fixed] A theme whose destination passed the final semantic fingerprint is
now treated as committed on both platforms even when obsolete backup cleanup
fails. The import returns
cleanupWarning/CleanupWarning; manual import and one-click apply show a bounded local warning without exposing the raw path or rolling back the new theme. - [fixed] Invalid or Windows-reserved source IDs use one cross-platform stable
identity mapping. The fixed
con.themevector isimport-931599c2985393be807cf0edon macOS and Windows, so a later package with the same source ID updates in place instead of creating another directory. - [verified] Windows PowerShell 5.1 completed the full focused ZIP-import suite, including same-ID replacement, exact duplicate, conservative legacy cleanup, unrelated suffix preservation, file collision, pre-commit rollback, committed cleanup warning and long-path cases. Focused macOS publisher, community-link, Safe CSS, dual payload, renderer-runtime, readiness and asset sync checks pass; the macOS immutable-backup cleanup case remains a macOS CI execution because this worktree is on Windows.
- [fixed] The trusted Safe CSS compiler now clears a core background image when
a validated part supplies
background-color, bridges bounded root typography and color tobody, passes composer-toolbar color to its registered buttons, and marks the realgame-sourcenode ashome-herowhen present. SPA DOM mutations refresh both public parts and verification scope.
- [verified] Official Codex/ChatGPT
26.727.40816is running with this Draft PR #324 engine (1.5.9, head61d65e3) and renderer injection succeeds. - [reproduced] The real home view remains partially white despite successful
injection. Screenshot:
/tmp/dreamskin-pr324-mac-26.727.png. - [root cause] The live renderer has zero matches for legacy
main.main-surfaceandheader.app-header-tint; it exposesmain[data-app-shell-main-surface="default"]plus new app-shell header data attributes. The generic identity/part fallback added by #324 cannot replace the canonical CSS selector contract, so it only themes part of the page. - [in progress] Add exact legacy-plus-current selectors in
tools/selectors.jsonand canonical runtime CSS, regenerate both macOS/Windows assets, add dual- platform assertions, rerun all applicable tests, then reinstall/reinject and capture real macOS visual evidence. Do not merge or release.
- [fixed] Shared selector contract now recognizes legacy anchors plus the
Codex 26.727 stable attributes and constrained CSS Module prefixes:
main[data-app-shell-main-surface]/_MainContentSurface_,header[data-app-shell-header-edge-scroll]/_Header_, and the newdata-app-shell-main-content-top-fade/_MainContentTopFade_overlay. - [generated]
tools/sync-runtime-assets.mjsregenerated macOS and Windows selectors, renderer payloads, and canonical CSS. The three shared payload files are byte-identical across platforms;--checkpasses. - [verified] Real official Codex
26.727.40816with DreamSkin1.5.9now reports renderer scopehome/L1withmissingL1=[];<main>and<header>receivedata-ds-part="main|header"; the native top fade computes todisplay:none; header remainsposition:fixed; z-index:30. Clean visual evidence:/tmp/dreamskin-pr324-mac-26.727-clean.png. - [verified]
node --test macos/tests/*.test.mjs windows/tests/*.test.mjspasses 74/74. Focused selector/renderer/CSS tests and runtime sync check pass. The macOS shell suite passes its applicable checks with signed-runtime, runtime-state, and Doctor branches explicitly skipped by environment flags; native Swift/XCTest remains unavailable on this host. - [verified] A final live CDP read at 2026-07-31 16:44 HKT still reports
home/L1,missingL1=[], themed outer main, fixed header at z-index 30, hidden native top-fade, and no operation overlay. The Windows handoff now calls out these exact acceptance checks for Codex 26.727+. - [committed] Selector/top-fade follow-up is committed as
9098060(fix: support Codex 26.727 shell surfaces) on branchcodex/fix-318-320-322. - [pushed]
9098060cd256ca4ed0aa268283d72a0481188aaais pushed to the remote head of Draft PR #324, and the PR body documents the root cause, Mac evidence, Windows checklist, and remaining real-Windows acceptance boundary. - [pending] Wait for fresh CI and real Windows Codex visual acceptance. Do not merge, release, comment on, or close #326/#322 yet.
Updated: 2026-07-31 14:29 HKT (Asia/Hong_Kong)
- [fixed] Both platform injectors now use the registered Codex structural marker
data-testid="app-shell-header-context-menu-surface"for genericapp://identity. They no longer read page title, body text, or URL; the strictapp:protocol and generic main/input requirements remain in place. - [added] macOS and Windows bootstrap fixtures now cover an unbranded generic
app:rejection, a branded structural-marker acceptance, and source guards against title/body/URL reads. - [added] macOS and Windows ZIP import suites explicitly cover an existing
canonical theme plus an exact
-2legacy duplicate. Re-import must returnImported, retain only canonical, and leave no transaction directories. - [added] Windows ZIP import suite statically verifies published semantic fingerprint validation and mismatch handling precede canonical backup deletion; no runtime failure-injection backdoor was introduced.
- [verified] Both bootstrap fixtures pass under Node 22 and Node 24; the macOS
legacy re-import suite, injector syntax, runtime sync, renderer fixture,
static privacy/PowerShell-policy scan, and
git diff --checkpass. - [verified] Full portable suite: 74/74 passed. The complete macOS suite passed with only the documented full-Xcode and installed-app Doctor branches skipped; the current host does not provide those prerequisites.
- [blocked] PowerShell 5.1/7 and real Windows renderer validation remain unavailable on this macOS host and must be run by CI/user Windows machine.
- [fixed] Import replacement rollback is fail-closed on both platforms. A post-publish failure first quarantines the new directory, restores legacy cleanup backups and the original canonical directory, and verifies every move. Backup and quarantine cleanup errors are surfaced instead of being silently ignored; the old theme is never discarded before the replacement fingerprint is verified.
- [added]
docs/pr-324-windows-validation.mdis the Windows AI handoff. It covers #318/#320/#322, all-theme (not only colors-only) renderer checks, legacy suffix safety, rollback expectations, exact commands, and theRemoteSigned/no-ExecutionPolicy Bypassrequirement. - [verified] Portable client regressions:
node --test macos/tests/*.test.mjs windows/tests/*.test.mjs— 74 passed;NODE=$(command -v node) CODEX_DREAM_SKIN_SKIP_DOCTOR=1 bash macos/tests/run-tests.shpassed with only the documented full-Xcode/Doctor skips; runtime asset sync, Node syntax, renderer runtime, andgit diff --checkalso pass. - [verified] Focused import, package-validator, injector, readiness, and generic-renderer fixture checks pass after the rollback hardening.
- [blocked] This macOS host has no
powershell.exeorpwsh; Windows PowerShell 5.1/7, Setup.exe compilation, and a real Windows Codex renderer still require the user's Windows host or PR CI. - [pending] Commit and push the final client branch, update draft PR #324, and wait for fresh CI on the new head. Do not merge, publish a Release, close an issue, or post a user-facing fix comment.
- [fixed] Both platform importers now consolidate a legacy suffix directory
only when its stored identity matches the suffix and its semantic fingerprint
exactly matches the incoming package. Display-name equality is no longer
treated as lineage evidence, so an independent
family-2with the same name is preserved and ambiguous replacement remains fail-closed. - [fixed] Legacy suffix detection mirrors the old 80-character ID truncation, including max-length IDs, and rejects numeric overflow rather than throwing.
- [fixed] macOS and Windows import notifications distinguish an in-place saved theme update from a first import; platform README/docs now describe the same behavior and the exact-fingerprint cleanup boundary.
- [pending] Rerun all portable/macOS suites, inspect staged diffs, commit and push only after local checks pass. Windows PowerShell 5.1 remains a required user/CI validation because this host has no PowerShell runtime.
- [reviewed] Client draft PR #324 remains at
ee3b64f; its four GitHub CI jobs pass. Root reran shared-asset sync, the focused macOS/Windows import, bootstrap and readiness tests, plusgit diff --check; all passed. - [blocked] The generic
app://gate is broader than the PR description:(main && input)passes with no Codex/ChatGPT identity marker. A minimal negative fixture independently executed the early payload on both platforms. - [blocked] Generic renderer parts do not complete #320/#322: canonical
dream-skin.cssstill has no[data-ds-part]fallback for the core main/sidebar/composer rules, generic part selection is over-broad, and a home[role=main]can keep the earliermainpart instead ofhome. - [blocked] The #318 import change repairs only a clean future library. An
already-created
theme-id-2exact duplicate returns early asduplicate, leaving both old directories. Replacement is also selected by destination directory existence rather than confirmed stored identity, and the Windows post-publish mismatch path deletes the old backup before final verification. - [blocked] Site PR #13 has a validated-package CAS regression and no backfill for the already-reset live count; see the site repository progress file.
- [fact] No PR code, commit, push, merge, Release, issue comment, or issue closure was performed during this review.
- [complete] Work is isolated in clean temporary worktrees:
client branch
codex/fix-318-320-322at/tmp/dreamskin-client-fix.O9D3Vwand site branchcodex/fix-318-download-inheritanceat/tmp/dreamskin-site-fix.pHtykF. Main worktrees were left untouched. - [complete] Client implements same-id theme ZIP imports as in-place version
replacement on both macOS and Windows instead of suffixing
-2, while exact duplicate content remainsduplicateand different-id same-name imports still reportnameCollision. - [complete] Client keeps dual-platform renderer behavior aligned: generic
main/sidebar/composer part fallbacks are generated from shared runtime source and synced byte-for-byte into macOS and Windows assets. - [complete] Client injector verification now accepts newer
app://Codex renderer shells with generic visible main/input structure and Codex/ChatGPT branding, while preserving exact payload/theme/revision checks and loopback CDP target rejection. - [complete] Site moderation service now inherits the maximum prior same-theme approved/downloaded version counter into a pending version before approval, so newly approved community versions do not reset visible downloads to zero.
- [verified] Site backend checks in
/tmp/dreamskin-site-fix.pHtykF/server:go test ./internal/moderation ./internal/upload ./internal/httpapi,go vet ./...,go build ./..., and repogit diff --checkall pass. - [verified] Client checks in
/tmp/dreamskin-client-fix.O9D3Vw:node tools/sync-runtime-assets.mjs --check,node macos/tests/theme-import-publish.test.mjs,node macos/tests/theme-package-validator.test.mjs,node macos/tests/injector-bootstrap.test.mjs,node windows/tests/injector-bootstrap.test.mjs,node macos/tests/window-readiness.test.mjs,node windows/tests/injector-window-readiness.test.mjs,NODE=$(command -v node) bash macos/tests/run-tests.sh, andgit diff --checkall pass. Native SwiftPM/XCTest was the existing local environment skip; no localpwshis installed for Windows PowerShell tests. - [pending] Commit, push, and open draft PRs. No merge, Release publication, issue closure, or user-facing "fixed/retry" comment has been made.
- [complete] Created
codex/release-v1.5.1from the exact synchronizedorigin/main@3593e8f. No remotev1.5.1tag or GitHub Release existed at preflight. - [complete] Updated the six release version sources to
1.5.1, the two macOS current-version assertions, and the dated macOS/Windows changelog headings. The Windows readiness fixture added by #249 also encoded the current injected version; its1.5.0value initially made the two positive readiness cases fail after the bump, so that corresponding assertion now reports1.5.1. Historical changelog entries and unrelated fixture data remain unchanged. - [verified] Six-source consistency, semantic/unpublished-tag preflight,
focused macOS update/common version assertions, Bash and Node syntax, both
injector payload checks, 21 macOS and 11 Windows portable Node regressions,
and
git diff --checkpass locally. The Windows suite was rerun after the fixture correction and passed all 11 tests. - [complete] Release commit
3289f64is pushed tocodex/release-v1.5.1; ready PR #250 targetsmainwith that exact head. - [verified] Initial CI run
30136427124passed Static checks; both Windows suites passed their regressions/static checks and macOS passed regressions plus its native build before the required durable-progress checkpoint. - [in progress] Push this progress-only docs commit to PR #250, then require a fresh Static checks, Windows PowerShell 5.1, PowerShell 7, and macOS run for the new exact head. The superseded CI head is not merge evidence.
- [pending] After merge, verify the automatic Release workflow creates a
v1.5.1tag at the exact merge commit and publishes non-empty DMG, Setup.exe, andSHA256SUMS.txtassets. No manual package, tag, or Release publication is permitted.
- [complete] Branch
codex/fix-macos-installer-preflight-v1.5.1movesdiscover_codex_appbefore the outer running-app guard, soCODEX_EXEand the exact app bundle are bound before any engine bytes can be deployed. - [complete] A real outer-installer regression covers the closed-app inner failure rollback and a compiled matching app process rejected before deploy; it verifies that the prior engine stays intact and no installing, previous or broken staging tree remains.
- [verified] Root reran Bash syntax, the focused installer preflight regression,
git diff --check, and the complete macOS CI-parameter suite with signed runtime and Doctor integrations explicitly skipped. All applicable checks passed; full-Xcode SwiftPM/XCTest remains an environment skip. - [complete] Fix commit
747c618was pushed in PR #247. GitHub Actions run30134848593passed Static checks, both Windows jobs and macOS repository regressions; the PR was squash-merged tomain@3aa89d7after bypassing only the impossible same-account self-review requirement. - [complete] The post-merge Release guard run
30135002941skipped duplicate publication successfully because the version remained 1.5.0. Post-merge CI run30135002980also passed all four jobs, including DMG and Setup builds. - [in progress] Public v1.5.0 remains unsuitable for website enablement. ChatGPT 26.721.41059 currently reaches CDP without a native window; an independent worktree is implementing correct post-CDP app activation and fail-closed visible-window verification before the separate v1.5.1 version PR.
- [in progress] A Windows parity audit found the same release-blocking class: the current verifier can accept hidden or minimized L0/L1 renderers without native-window evidence. A separate origin/main worktree owns Windows window binding, DOM visibility and non-minimized readiness tests. Both platform fixes must merge before the v1.5.1 version bump.
- [complete] macOS readiness commit
1d76a86plus test-isolation follow-upe7cc38cpassed all four PR CI jobs in run30135795473; PR #248 was squash-merged tomain@ea5f37f. - [complete] Windows readiness commit
fc454cbpassed all four PR CI jobs in run30135894880, including the new PowerShell 5.1 startup rollback fixture; PR #249 was squash-merged tomain@3593e8f. - [in progress] Prepare the separate v1.5.1 version-only branch from
main@3593e8f, update all six sources, both assertions and both changelogs, then require CI before merge and automatic Release publication.
- [complete] Public v1.5.0 Release/tag/DMG/Setup.exe/SHA256SUMS were independently
downloaded and verified. The DMG installs and registers
dreamskin, but a real engine upgrade exposed a release P1: the outer installer invokescodex_is_runningbeforediscover_codex_app, so its pre-copy running-app guard expands undefinedCODEX_EXEand fails open underset -u. - [complete] The failed real upgrade atomically restored the entire previous v1.4.0 engine tree; no mixed tree or installer staging residue remains and the original active theme bytes are unchanged.
- [blocked] Current ChatGPT
26.721.41059opens a loopback CDP target but has no native window after launch on this host. The v1.5.0 injector applies its exact payload to that target but correctly refuses visible verification, so the outer installer rolls back. Do not enable the website for v1.5.0. - [in progress] Prepare a focused v1.5.1 installer-preflight fix with functional regression coverage, then retest a public build and the current renderer before enabling the website.
- [complete] PR #245 passed all four CI jobs and was squash-merged to client
mainas71f30f0. The v1.4.0 Release guard completed successfully without publishing a duplicate because the feature PR did not change versions. - [complete] Separate branch
codex/release-v1.5.0changes only the six version sources, two version assertions and the macOS/Windows changelog headings. Version consistency, stale-reference scan, all 24 portable Node regressions, the CI-mode macOS suite andgit diff --checkpass locally. - [complete] Version-only commit
3c43752was pushed and Draft PR #246 targetsmain. - [complete] PR #246 passed all four CI jobs and was squash-merged to client
mainasaad9fc0. - [in progress] Automatic Release run
30131800275is building v1.5.0 from that exact main commit. No public v1.5.0 tag/assets, website enablement or deployment exists yet. - [complete] Initial PR #245 CI run
30130742965exposed three gaps. The macOS-only Swift fixture now reports a real Node test skip on non-Darwin hosts; the signed package-identity shell integration honors the repository's existing CI skip; and Windows runtime fingerprinting recursively canonicalizes object keys so active-image renaming cannot change content identity. - [verified] Root reproduced the Windows fingerprint mismatch with portable
PowerShell, then proved the saved/active hashes are identical after the fix.
CI-mode macOS regressions, 20 macOS and 4 Windows Node regressions, all
PowerShell parse/encoding checks and
git diff --checkpass locally. Repair commit3a2c809is pushed; fresh CI run30131282832is the active gate. - [complete] Feature commit
c44b434was pushed tocodex/one-click-theme-apply; Draft PR #245 targetsmain. All release version sources intentionally remain1.4.0. - [in progress] PR #245 must pass Static checks, Windows PowerShell 5.1, PowerShell 7 and macOS repository regressions before it is marked ready or merged.
- [complete] The independent final Windows read-only audit reports PASS with no
P0/P1 findings.
git diff --checkpasses. Native PowerShell 5.1, compiled Setup.exe protocol registration and a real Windows renderer transaction remain required PR CI/Windows-host gates rather than local macOS claims. - [complete] Root reran all 24 portable macOS/Windows Node regressions and the complete macOS repository suite on the final stable tree. Both passed; only the documented full-Xcode XCTest and installed-app Doctor branches skipped on this Command Line Tools host.
- [complete] Final static checks and an x86_64 native app build passed, including
strict codesign, exact
dreamskinURL-scheme registration and packaged helper inventory. - [fact] The public client remains v1.4.0 and the website one-click action remains correctly disabled until the automatic v1.5.0 Release is public and verified.
- [complete] Root independently reran the exact pre-switch community transaction
regression, private ZIP identity regression, focused bounded-HTTP/import/
staging Node tests, relevant Bash syntax, plist validation and
git diff --check; all passed on the combined macOS tree. - [complete] All 13 currently approved production ZIPs were exercised through
the current strict macOS importer with an isolated temporary HOME. Every one
failed closed on the missing required
theme.css, and the isolated saved-theme library remained empty. The real user theme library and active renderer were not changed by this rejection test. - [pending] Windows click-time baseline closure, combined cross-platform CI, final public Release install and website-button acceptance remain.
- [complete] Inside the inherited community operation lock, the macOS
transaction now snapshots the active theme and runs
injector --verifyagainst that exact snapshot and current CDP port before the first switch. The injector therefore checks both the rollback theme ID and computed payload revision against the renderer; a mismatch exits before any theme switch. - [complete] The transaction fixture now records exact renderer-verification calls. A state mismatch proves zero verification and zero switches; an injected renderer-verification failure proves one verification and zero switches. Success, verified rollback and failed rollback cases continue to pass under one inherited lock.
- [complete] Rollback retention now distinguishes a snapshot promoted to the
private
recovery/tree, a structurally validated snapshot retained in its original operation directory when promotion fails, and no confirmed snapshot. The App does not delete an in-place fallback, startup stale cleanup skips community operations containing such a snapshot, and UI/docs no longer promise that retaining a snapshot means recovery succeeded. - [verified]
macos/tests/community-apply-transaction.test.sh, focusedbash -n,git diff --check, and a standalone Swift recovery-promotion failure smoke pass. A direct x86_64 app build with the macOS 14.4 SDK passed at/tmp/CodexDreamSkin-one-click-macos-closure.app; strict ad-hoc signature, exact bundled transaction-script bytes, and thedreamskinURL scheme were rechecked. The build was not installed. - [remaining] The owner must rerun the combined macOS suite after all agents finish, rebuild the final integrated app, reinstall it, verify bundled engine identity, and repeat the installed renderer transaction. Full SwiftPM/XCTest remains a CI/full-Xcode gate on this Command Line Tools-only host.
- [complete] Community downloads now pass their approved byte count and SHA-256 into the strict ZIP importer. The importer opens the archive exclusively, checks both values on that same FileStream, rewinds it, and extracts from the still-open handle. Replacement, truncation and wrong-hash regressions were added.
- [complete] Imported and duplicate results now return a stable runtime-content fingerprint. One-click apply copies the saved theme into a private transaction snapshot, recomputes the exact fingerprint, and refuses to write active files unless it still matches.
- [complete] The Windows operation lock now covers the exact active snapshot and active-file write. The parent releases it before invoking start-dream-skin.ps1, because that script acquires the same lock and only exits after exact renderer verification. Failed writes and failed startup restore under lock, restart, and verify the previous renderer; a newer manual theme choice is detected and never overwritten.
- [complete] Native confirmation metadata rejects Unicode Format, bidi, line-separator and paragraph-separator characters. Mocked transaction tests cover success, wrong private identity, partial writes, verified rollback, rollback file/renderer failure, and concurrent supersession.
- [in progress] Independent PowerShell 5.1/transaction review is running. This macOS host has no powershell.exe or pwsh, so executable Windows tests, Setup.exe protocol registration, and the real renderer transaction remain Windows CI/host gates. git diff --check currently passes.
- Worktree:
/private/tmp/dreamskin-one-click.36Mjwl - Branch:
codex/one-click-theme-applybased on public v1.4.0/main277b520 - Goal: strict
dreamskin://apply?version=ver_...website-to-client apply for macOS and Windows. - User primary client worktree was not touched.
- Root independently re-imported the three compliant official fixtures through
the installed strict importer; each returned
duplicate, validated Safe CSS and the expected stable content fingerprint. - Root switched all three themes live again. Exact renderer verification passed
each theme ID/revision with visible shell/sidebar/composer/home, zero business
class pollution and no horizontal overflow. Fresh evidence is under
/private/tmp/dreamskin-installed-smoke.iVev9i/. - A deliberately wrong imported-content fingerprint exercised the parent
transaction failure path. It returned exit
20, reapplied the exact previous snapshot and visibly reverified it. Root then reapplied the exact original snapshot;preset-gothic-void-crusadeis active and verified now. - macOS metadata display validation now explicitly rejects bidi controls and line/paragraph separators that could visually spoof the native confirmation. Targeted tests and the final rebuild/reinstall remain after this edit.
- Implemented fixed-origin bounded HTTP with explicit redirect failure, header/chunked size bounds, cancellation, and exactly-once completion coverage.
- Community ZIP import rechecks approved byte count and SHA-256 on the private no-follow snapshot used for extraction.
- Import publishing returns a runtime content fingerprint; staging calculates the same fingerprint and switching requires an exact match.
- Community apply holds one cross-process transaction lock across exact active-theme snapshot, apply/render verification, and verified rollback. Fresh ownerless locks fail closed; only a dead owner or an ownerless lock at least 10 minutes old is reclaimable.
- The rollback snapshot contains the exact active
theme.json, referenced image, optionaltheme.css, and content identity even when the active theme is not inthemes/<id>. - Hot apply now runs exact injector verification; cold apply already runs
injector --verifyagainst the active theme before success. Failed community apply re-applies and verifies the exact snapshot; exit 20 means verified recovery, exit 21 means recovery was not verified. - Quit/menu termination is blocked while network, import, apply, recovery, engine install, or runtime operations are busy. Startup removes only stale private operation directories older than 24 hours and preserves community operation roots that still contain a structurally validated rollback snapshot.
- Native confirmation states that a cold apply may restart ChatGPT and that unsent input should be saved. Menu progress covers metadata, download, import, snapshot/apply, and recovery state.
-
Root independently reran
CODEX_DREAM_SKIN_SKIP_DOCTOR=1 macos/tests/run-tests.sh: PASS, with only the documented full-Xcode SwiftPM/XCTest and explicitly skipped Doctor branches omitted. -
Root built and installed
/tmp/CodexDreamSkin-one-click-root.app, verified its ad-hoc signature,dreamskinURL scheme, complete runtime inventory, and byte-identical deployed engine. The previous 1.3.3 app, engine and user state are recoverably backed up at/tmp/dreamskin-before-one-click.g6pClo. -
The real installed importer added three official four-file fixtures as
local-one-click-1/2/3; all reportedsafeCssStatus=validatedand a stable content fingerprint without changing the active theme during import. -
The installed switcher applied all three fixtures to the real ChatGPT/Codex renderer. Exact
injector --verifypassed each theme ID/revision, Safe CSS, visible shell/sidebar/composer/card geometry, matching text colors, zero business-class pollution and no document overflow. Screenshots are/tmp/dreamskin-local-one-click-1.png,/tmp/dreamskin-local-one-click-2.png, and/tmp/dreamskin-local-one-click-3.png. -
Root restored
preset-gothic-void-crusade; its active theme/image are byte-identical to the pre-test backup (SHA-2568316c6ad...andb76a7cbe...), exact renderer verify passes, and deep status reportssession=active,injectorAlive=true,cdpOk=true. -
LaunchServices delivered malformed and canonical production legacy
dreamskin://links to the installed app as native warning windows. The production exact-metadata route currently returns 404, so the legacy link failed closed and did not change the active theme. A successful end-to-end network apply still requires a deployed compatible package. -
CODEX_DREAM_SKIN_SKIP_DOCTOR=1 macos/tests/run-tests.sh: PASS. SwiftPM/XCTest skipped because this Command Line Tools host has no matching full Xcode platform; Doctor intentionally skipped. Signed-runtime switch and runtime-state integration passed. -
Direct Swift x86_64 typecheck with macOS 14.4 SDK: PASS.
-
Bounded HTTP redirect/oversize/chunked/cancel/exactly-once fixture: PASS.
-
Community import private-snapshot byte/SHA identity fixture: PASS.
-
Community transaction success/verified rollback/rollback-failure and inherited-lock fixture: PASS.
-
DREAMSKIN_SDK=/Library/Developer/CommandLineTools/SDKs/MacOSX14.4.sdk DREAMSKIN_ARCHS=x86_64 macos/scripts/build-menubar-app.sh --skip-tests --output /tmp/CodexDreamSkin-one-click-hardened.app: PASS. Built Mach-O x86_64; packaged runtime helpers anddreamskinURL scheme verified. -
git diff --check: PASS before final build.
- No commit, push, PR, merge, replacement Release, or deployment has occurred. A local development build is installed and fully backed up; public v1.4.0 still does not contain one-click apply.
- A complete fixed-origin network success smoke still requires a deployed
approved
applyCompatible: truepackage. Existing approved legacy production packages are intentionally preview/download-only. - Real Windows PowerShell 5.1 and Setup.exe protocol install require Windows CI/host verification.
- [complete] Read-only inspection of the real Windows Codex 26.727.4816 task
renderer found zero
[data-message-author-role]nodes. The current semantic boundaries are four[data-local-conversation-user-anchor]nodes and four[data-local-conversation-final-assistant]nodes; all eight are inside the thread surface and none is in the sidebar. - [complete] The shared selector contract now retains the legacy message role
attribute and adds those two current semantic attributes. Core styling uses
the existing public
data-ds-part="message"bridge, and generated macOS and Windows selector/renderer/CSS assets are synchronized. - [verified] Selector doctor, both renderer runtime suites, both payload
integrity suites, runtime asset sync, JavaScript syntax, focused
git diff --check, and a second real-DOM read-only cardinality check pass. No installed runtime, Codex process, active theme, PR, issue, commit, or push was changed by this focused task.