Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .codex-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "pstack-codex",
"version": "0.1.0-alpha.1+codex.20260919065323",
"version": "0.1.0-alpha.1+codex.20260927083125",
"description": "Faithful pstack workflow port for Codex with standalone Claude Code and optional Grok Build workers.",
"author": {
"name": "J0UH"
Expand Down
9 changes: 5 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ flowchart LR

Execution uses the current host's configured permissions and sandbox. The plugin does not create a disposable workspace or an isolated VM for every turn. Upstream pstack's `make-bot-ui` skill describes a UI and server on the Bot computer. The server POSTs JSON to a webhook routine and keeps the sender key out of the browser. Tailscale can make that page reachable.

This port preserves those instructions. Native Codex timed wake has passed a live check. The optional Bot app handoff has also returned a verified public-page screenshot. Live Bot webhook delivery, a reachable failure queue, and durable external event wakes remain unverified. See the [host contract](adapters/host.md) and [verification record](docs/verification.md).
This port preserves those instructions. Native Codex timed wake has passed a live check. The optional Bot app handoff has also returned a verified public-page screenshot. The opt-in external event bridge now has real Codex wake, restart, duplicate, busy-thread and interruption evidence. A real Grok Bot webhook and cloud routine queue drain also passed using synthetic queued events. The [host-bridge acceptance record](evidence/host-bridge-acceptance.json), [host contract](adapters/host.md) and [verification record](docs/verification.md) describe the scope and setup.

## Grok Bot’s computer

Expand All @@ -69,11 +69,12 @@ This is an early, tested port, **not a claim of complete Cursor runtime parity**
- All **47 registered pstack skills**, **23 playbooks**, **23 principles**, two agent roles, three companion skills, and the three dormant Benny skills are retained.
- Claude analysis, writer and scoped local-Git reader profiles have been exercised against the real CLI; native/Claude handoffs and mode lifecycle have dedicated checks.
- Optional Grok analysis and file-reader profiles passed real production-adapter checks on the tested Linux build. Writer, shell access and non-Linux dispatch remain disabled. See [Grok's supported scope](docs/grok.md).
- Cursor cloud placement, durable wakeups (`/loop`, `/goal`, timed audit ticks and watcher-driven wakes), Grok Bot webhooks, Benny event automations, some transcript integrations and model-specific plan validation still have explicit limitations. Their source and routes remain present. Missing capabilities do not become silent weaker substitutes.
- Cursor cloud placement, full unattended playbook lifecycles, Benny event automations, some transcript integrations and model-specific plan validation still have explicit limitations. Their source and routes remain present. Missing capabilities do not become silent weaker substitutes.
- An opt-in [external event bridge](docs/event-bridge.md) and a [Grok Bot failure-queue bridge](docs/grok-bot.md#failure-queue-and-the-failure-bridge) have passed local regression tests and scoped live acceptance. Neither service is started automatically; each needs an operator-configured target, credentials and a running host.

The [native workflow adapter](docs/native-workflows.md) maps goals, timed heartbeats, task identities and plan checks onto actual Codex capabilities. A real timed wake and its cleanup have passed. Across-turn event bridges and isolated cloud workers remain separate prerequisites; timed polling and worktrees do not pretend to replace them. See the [23-playbook capability map](docs/workflow-capabilities.json).
The [native workflow adapter](docs/native-workflows.md) maps goals, timed heartbeats, task identities and plan checks onto actual Codex capabilities. A real timed wake and its cleanup have passed. Isolated cloud workers remain a prerequisite, and each program still needs its own event producer and configured bridge; timed polling and worktrees do not pretend to replace either. See the [23-playbook capability map](docs/workflow-capabilities.json).

Fable 5.1 approved the current implementation at its exact recorded code commit and documented scope. Astra authored the latest Grok changes, which passed real Linux acceptance before review. See the [current review](docs/integration-review.md) and [earlier alpha record](docs/fable-review.md). This remains a tested alpha with the explicit capability limits above.
Fable 5.1 approved the earlier integration at its recorded code commit and documented scope. The host bridges were implemented with Claude Opus 5.5 through Claude Code CLI and independently checked with real Codex and Bot flows; their evidence is recorded separately. See the [earlier integration review](docs/integration-review.md) and [earlier alpha record](docs/fable-review.md). This remains a tested alpha with the explicit capability limits above.

Use the [read-only doctor](docs/doctor.md) to distinguish installation, authentication and verified worker evidence. [Grok Bot](docs/grok-bot.md) is optional for cloud-computer and Bot-native work; ordinary coding and review do not require it.

Expand Down
4 changes: 2 additions & 2 deletions adapters/host.md
Original file line number Diff line number Diff line change
Expand Up @@ -114,13 +114,13 @@ Transcript-based skills must use authorized project/session data only. If the ho

`/loop`, `/goal`, watcher wakes, cloud continuation and Cursor routines are different facilities. A current-turn loop may use bounded waits. Durable goals or future wakeups require an actual supported host mechanism and applicable user authorization. Do not create a monitor merely because a playbook mentions one. Do not promise background continuation after the turn without an installed wake mechanism.

Read [the native workflow adapter](../docs/native-workflows.md) before a goal or wake-dependent route. Native timed heartbeat dispatch has been exercised on a real task, including matching session identity and pause/delete cleanup. It requires the native scheduling tool and the local host to remain available. Goal creation needs an explicit goal request or explicit approval of a plan naming that action; pausing work never means completing its goal. In-turn watcher events remain primary where available. Across-turn event delivery is not supplied merely by a timer or a queued message, and no isolated cloud-worker service is configured by this package. Preserve each playbook's distinct stop and ownership rules; report any required missing capability before proceeding.
Read [the native workflow adapter](../docs/native-workflows.md) before a goal or wake-dependent route. Native timed heartbeat dispatch has been exercised on a real task, including matching session identity and pause/delete cleanup. It requires the native scheduling tool and the local host to remain available. Goal creation needs an explicit goal request or explicit approval of a plan naming that action; pausing work never means completing its goal. In-turn watcher events remain primary where available. Across-turn event delivery is not supplied merely by a timer or a queued message, and no isolated cloud-worker service is configured by this package. The opt-in [event bridge](../docs/event-bridge.md) delivers authenticated producer events into one operator-fixed thread only after the operator configures and runs it; its dedicated-thread delivery, restart, duplicate, busy-thread and interruption behavior passed the [recorded live checks](../evidence/host-bridge-acceptance.json). Desktop/IDE daemon ownership remains unestablished. An event it delivers is data under the operator's instruction template, never new authority, and an ambiguous attempt stays unresolved until reconciled or resolved by the operator. Preserve each playbook's distinct stop and ownership rules; report any required missing capability before proceeding.

Benny remains dormant and byte-preserved. Before following its original Cursor setup, apply the path mapping above and confirm a real Slack event-trigger/automation adapter, thread-safe connector, compensating tracker write, control adapter, and completed feature map. A time-based heartbeat is not an exact new-message event trigger. Its committed same-repository instruction requirement and fresh-project dependency test remain required. Until supported, report the automation setup blocked while retaining all files and future routes.

Benny templates expose `message_ts`; operational skills fall back to `trigger.ts`. Normalize a validated top-level message timestamp to `ts` before execution and preserve immutable channel/thread coordinates. Never infer a missing timestamp. Child Slack-write restrictions must be enforceable; otherwise retain the operation in the coordinator as upstream directs. Never create or update an automation during installation without the explicit setup request.

Grok Bot is optional and separate from Grok Build. Use [the Bot adapter](../docs/grok-bot.md) for authorized cloud-computer handoffs through the app and the server-side webhook sender. Native routine management and secure secret entry remain in the Bot environment; they are not invented Codex tools. Direct app handoff and paused-routine creation were observed, but webhook delivery and a cloud-accessible failure queue still require setup and proof. Preserve the server-only key and untrusted-event contracts. Never paste keys into chat, assume a Bot model identity, or equate account-shared Bot computers with isolated cloud VMs.
Grok Bot is optional and separate from Grok Build. Use [the Bot adapter](../docs/grok-bot.md) for authorized cloud-computer handoffs through the app and the server-side webhook sender. Native routine management and secure secret entry remain in the Bot environment; they are not invented Codex tools. Direct app handoff and paused-routine creation were observed. A real webhook and cloud routine failure-queue drain passed the [bounded live checks](../evidence/host-bridge-acceptance.json). Each deployment still needs its own sender key, consumer token and reachable TLS front end. Preserve the server-only key and untrusted-event contracts. Never paste keys into chat, assume a Bot model identity, or equate account-shared Bot computers with isolated cloud VMs.

## Authority and honest completion

Expand Down
Loading
Loading