Repository navigation
chore(release): prepare v3.9.0 - #1190
Merged
Merged
Conversation
…d copy
The Codex plugin shipped skills-codex/, a generated second copy of skills/
with the frontmatter cut to name and description. The bodies were the source
bodies, all 28 catalog rows were parity_only, and `ao skills link` and
`npx skills` already hand Codex the source tree. .codex-plugin/plugin.json
now ships ./skills and the copy is gone, with the generator and everything
that only policed it.
Deleted: skills-codex/ (278 files), skills-codex-overrides/, scripts/lint/,
18 scripts (codex-sync, regen-codex-hashes, register-new-codex-skill,
append-codex-override-entry, mirror-codex-references,
refresh-codex-artifacts, audit-codex-parity.{py,sh},
check-codex-parity-drift, lint-codex-native, smoke-test-codex-skills,
export-claude-skills-to-codex and six validate-codex-* validators), their
tests, four gate-registry entries, and the doctor failure mode
fm-skills-stale-codex-sync.
Kept and reduced to what still has a subject:
- validate-codex-api-conformance.sh now checks skills/ against the facts the
Codex loader enforces (observed with skills/list on codex-cli 0.156.1) and
the explicit-only invocation policy. It stays in regen-all.sh --check.
- skill.runtime-formats, skill.runtime-parity, skill.manifests and
derived.changed-scope keep their skills/ halves.
- ao skills check, ao skills link and ao workflows link find the repo root by
skills/ plus registry.json and PRODUCT.md, not by the skills-codex/ sibling.
Carried over so nothing Codex relied on is lost:
- skills/interview/agents/openai.yaml. Codex reads the invocation policy from
that file, and the generator derived it from disable-model-invocation. It is
now source-owned and the conformance check fails without it.
- skills/_fixtures moved to tests/fixtures/skill-eval. Codex loads every
SKILL.md under the plugin skill tree; the fixtures loaded as a skill named
"Good Skill" and a load error.
prompt.md, .agentops-generated.json and .agentops-manifest.json had no Codex
consumer and are dropped without replacement. The CHANGELOG states what
plugin users lose.
Gate-Loosen-Reason: the generated Codex skill copy is deleted, so check-codex-parity-drift.sh and the four skill.codex-* registry entries that policed only that copy have no subject; every gate over skills/ is kept
Test-Removal-Reason: the removed Go tests covered Codex-copy parity, manifest-hash and plugin-cache sync code paths that are deleted with the copy
…review The contract required a fresh author-distinct validation on every change, a PASS with nothing unchecked, and a re-validation after each repair. A reviewer asked to find problems always finds one, so that combination could not converge and review cost exceeded the cost of the work. The contract and the skills that drive review now say: for an ordinary change the author's checks and CI are the gate. One fresh read is used when the caller asks, when a mistake cannot be cheaply undone after it lands, or when no deterministic check covers the changed behavior. A review is one round, does not re-run checks, reports as defects only what would mislead a user, break install or the CLI, or remove protection for the product, and a repair is confirmed by a check instead of another review. Changed: AGENTS.md, the rpi, validate, implement, orchestrate, craft-goal and navigate skills, the rpi references, two standards references, and the workflow and traversal docs. craft-goal and navigate no longer give every bead its own validation. The fixed-dispatch adapter page now says not to select it for ordinary work. Two wording pins move to the new rule, including one that fails if 'a repair does not start another review' disappears.
- Docs: PRODUCT.md, the docs index, how-it-works, architecture, philosophy, first-value path, migration, CI and scale pages now describe validation as checks and CI plus one fresh read where a mistake is costly. - Remove the fixed-dispatch RPI reference adapter, which modelled repeated review rounds: run_once.py, its tests, its reference page and rpi.feature, plus tests/e2e/rpi-phased-domain.sh, a no-op tombstone kept only so that feature file's scenario link resolved. The conformance script drops the adapter canary and keeps its Validate substrate probe. - That probe now intercepts Git, tracker and delivery calls made in-process; before, they reached the real binaries unnoticed (shown by mutation). - Skill Builder heal.sh --check exits 2 when ao cannot run instead of passing. - The Codex policy check rejects agents/openai.yaml shapes Codex silently drops: non-object interface, dependencies without a tools list, and a boolean spelled other than true or false. - The Skill Builder converter's Codex target no longer writes prompt.md.
Owner decision. Drop the README's experimental label on goals, and align the README's flow lines with the validation rule: checks for every change, Validate where a mistake is costly.
…it-matters # Conflicts: # CHANGELOG.md # docs/CHANGELOG.md # docs/contracts/codex-skill-api.md # scripts/validate-codex-api-conformance.sh # tests/scripts/codex-skill-conformance.bats
Bump the Claude plugin, marketplace, Codex plugin, binary and Claude image verify surfaces to 3.9.0. Cut the unreleased changelog into 3.9.0, folding in the items the earlier PRs did not record and correcting the remedy sentences. Add curated notes covering the Codex plugin change, the validation rule, the removed skills, workflows and installers, and the pre-release fixes; the upgrade steps carry --dest for unlink and name only the workflow files a user has. Point the README upgrade section at 3.9, correct the Skill Builder dependency row, add the retired-workflows migration row, link the update guide from the release body header, and require exactly one curated notes file for the checked-in version.
A 3.8 ao looks for the deleted skills-codex/ directory and refuses an updated checkout, so the relink steps failed without an ao upgrade first. Add that step to the notes and the update guide. Name only the retired workflow files a user has in the migration example, and drop a claim that 3.8 derived an interview policy file; 3.8 had no interview skill.
# Conflicts: # CHANGELOG.md # docs/CHANGELOG.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Prepares v3.9.0. No tag is pushed by this PR; tagging is a separate step after merge.
What changes
aobinary fallback and the Claude image verify script.[Unreleased]cut into a dated[3.9.0]section, folding in items the earlier PRs did not record (Interview, Navigate, Council modes, theao skillscommands, Skill Builder changes, the moved guards, the gate changes) and correcting the remedy sentences.docs/CHANGELOG.mdis byte-identical.docs/releases/2026-10-03-v3.9.0-notes.md, with upgrade steps, breaking changes, product areas and known issues. They cover the Codex plugin readingskills/, the validation rule, the removed skills, workflows and installers, and the pre-release fixes.aobefore relinking.Review
A release is a costly-mistake case, so it had one fresh read with one question: would any instruction or claim mislead someone upgrading from 3.8? It found one real defect and two small inaccuracies, all fixed in
c0fa6c825:aorefuses an updated checkout because it looks for the deletedskills-codex/, so checkout users must upgradeaobefore relinking. This is confirmed on a clean export of the branch, and the step is now in the notes and the update guide.No second round.
Checks
At the merged tip:
ao gate check --full66 of 66;TestVersion_*pass; the command/test pairing gate passes;scripts/validate-release-notes.sh v3.9.0 --since v3.8.0passes with all seven touched product areas covered; the doc release gate,regen-all.sh --checkand both image verifies (Claude, Codex: 28 skills) pass.Not checked
radonandpytest, which are not installed here; the tag-triggered workflow runs its own checks.