Files
msd-core/bin
Tom Boucher a22333034b fix(#2310): guard Codex agent model_overrides so Anthropic aliases never leak into .toml (#2312)
* fix(#2310): guard Codex agent model_overrides so Anthropic aliases never leak into .toml

generateCodexAgentToml embedded a per-agent `model_overrides` value verbatim as the
Codex `.toml` `model`, leaking GSD/Claude tier aliases (opus/sonnet/haiku/fable) and
`claude-*` ids. Codex/ChatGPT rejects those (400 "The 'sonnet' model is not supported
when using Codex with a ChatGPT account"), and since spawn_agent has no inline model
param, the model is baked into the .toml at install time — so the orchestrator could
not recover and fell back to the non-equivalent generic-agent workaround.

Translate a GSD tier alias through the Codex tier map (sonnet -> gpt-5.6-terra); drop
with a deduped warning any Anthropic-flavored value with no Codex mapping (fable) or a
`claude-*` id, so emission falls through to the runtime-aware resolver or Codex's
default. A final safety gate blocks an Anthropic-flavored model from the runtime-
resolver path too (runtime/target mismatch). Mirrors the Claude-side override guard
(#2041). Real Codex/OpenAI model ids in model_overrides still pass through verbatim
(#2256 preserved); runtime:"codex" tier resolution unchanged (#2517).

Adds regression + fast-check property tests in tests/codex-config.test.cjs.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* chore(#2310): backfill changeset PR number to #2312

* fix(#2310): Codex passive-model posture — omit Anthropic-flavored model (all namespacings)

Adopt ADR-1239's passive/session-only posture for Codex model handling: a Codex
agent .toml `model` is embedded ONLY for an explicit real-Codex model_overrides
pin; any Anthropic-flavored value is omitted so the agent inherits the always-
available session model (never a 400).

- model_overrides tier alias (opus/sonnet/haiku/fable) or a Claude model id →
  omit (was: translate to gpt-*); an explicit real-Codex model id → embed
  verbatim (#2256 preserved).
- Detect ALL Anthropic namespacings, not just `claude-*`: single-source the
  canonical CLAUDE_AGENT_ALIASES from model-resolver.cts and treat any id whose
  value contains "claude" (case-insensitive) as Anthropic-flavored — catching
  `anthropic/claude-*` and `us.anthropic.claude-*` (the forms the catalog assigns
  to opencode/hermes/kilo), which reach a Codex .toml via the runtime-resolver
  path on a mixed-runtime + Codex install.
- The final safety gate applies to the runtime-resolver path too.

The full passive posture (removing #2517's runtime-resolver per-tier embedding +
a correctness health-check + a Codex TOML sync path) is tracked as the ADR-2310
epic #2313.

Regression + fast-check property tests in tests/codex-config.test.cjs.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-15 21:39:38 -04:00
..