Skip to content

Codex: address remaining exact rewind compatibility limits #539

Description

@rynfar

Follow-up to merged #533 and completed upstream cycle #526; related to #200. Eligible Codex turns already support exact rewind through immutable native forks, complete native JSONL proof and inactive-goal preservation. This issue tracks the remaining compatibility limits.

Remaining cases:

  • Active or uninspectable native goals cannot be safely admitted: an active goal can continue autonomously without a readable source admission/deferral proof.
  • The pinned native server rejects paginated forks. External history bases and unsupported file shapes cannot currently supply a complete standalone history proof.
  • Current bounded proof rejects histories over 16 MiB or 100,000 records, and lines over 1 MiB.
  • Imported/older history without captured Pylon turn bindings has no guessed root or historical checkpoint.

Investigate native atomic goal suspension/admission, complete fork/history APIs and a bounded streaming proof for larger or externally based histories. Do not merely raise limits or treat the public visible-turn list as complete context. Revisit when native goal/fork/history APIs expose the missing proof, or a concrete large-history case justifies a bounded proof implementation. Reconstruct old checkpoints only when exact Pylon boundaries can be verified.

Acceptance:

  • Preserve hidden context, unknown semantic fields and complete goal state; no autonomous continuation before the next authorized send.
  • Preserve immutable targets through compaction, idempotent application/compensation, source integrity, same-incarnation recovery, and ordinary Stop/resume.
  • Add focused tests for each newly supported boundary and retain rejection coverage for unprovable cases; keep resource and cancellation bounds.
  • Independently review the final diff and require green CI. Record supported native versions and any upstream blockers with concrete revisit triggers.

Existing evidence: #533 records independent native-source/adapter review, 360 focused tests, integration checks, and green final/merge CI. No live Codex account/model test was claimed. Any later smoke must use isolated state and the applicable authorization boundaries.

Model: GPT-6. Harness: Codex.

Activity

  1. rynfar commented on Sep 24, 2026

    @rynfar
    CollaboratorAuthor

    Current capability correction: the issue's sentence that the native server rejects paginated forks is stale as a general upstream blocker. Current Codex supports paginated reference-backed thread/fork (upstream capability discussion, citing upstream #35220), and this host reports codex-cli 0.156.1. Pylon already has a paginated fork-response branch in apps/server/src/provider/Layers/CodexAbsoluteHistory.ts (near line 548).

    The remaining Pylon proof gap is narrower and still material: readNativeRecords rejects session_meta.payload.history_base (near line 266) because the current bounded proof reads only the local JSONL, so it cannot verify a reference-backed external history base as a complete standalone context. The active/uninspectable goal guard, 16 MiB/100,000-record/1 MiB-line bounds, and missing historical Pylon turn bindings remain in force. This update does not claim #539 acceptance or authorize a relative-turn fallback; it identifies a concrete revisit path: safely resolve and prove reference-backed history across its full lineage under bounded reads, then test exact fork/compensation/recovery behavior on a supported native version.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions