From 63bfd149dd04ffbe448f43004a17e371a514eb38 Mon Sep 17 00:00:00 2001 From: JUN Date: Wed, 19 Aug 2026 12:39:23 +0900 Subject: [PATCH 1/2] docs(governance): move @Wibias to former maintainers (#2098) @Wibias stepped down from developing opencodex, and repository permission was reduced to read access. Move him out of the current-maintainers table into a new Former maintainers section, drop him from the CODEOWNERS default-reviewer line and the four high-impact runtime paths, and record the change with the 2026-07-27 addition entry it closes. Nothing he authored is unwound: commits, merged pull requests, release-note attributions, and the code comments citing his reviews stay as they are. --- .github/CODEOWNERS | 10 +++++----- MAINTAINERS.md | 37 ++++++++++++++++++++++++++++++++----- 2 files changed, 37 insertions(+), 10 deletions(-) diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS index 71f14c14a9..ae2c27bce7 100644 --- a/.github/CODEOWNERS +++ b/.github/CODEOWNERS @@ -1,11 +1,11 @@ # Default reviewers -* @lidge-jun @Ingwannu @Wibias +* @lidge-jun @Ingwannu # High-impact runtime behavior -/src/adapters/ @lidge-jun @Ingwannu @Wibias -/src/providers/ @lidge-jun @Ingwannu @Wibias -/src/codex/ @lidge-jun @Ingwannu @Wibias -/src/server/ @lidge-jun @Ingwannu @Wibias +/src/adapters/ @lidge-jun @Ingwannu +/src/providers/ @lidge-jun @Ingwannu +/src/codex/ @lidge-jun @Ingwannu +/src/server/ @lidge-jun @Ingwannu # Repository automation and release security /.github/ @lidge-jun @Ingwannu diff --git a/MAINTAINERS.md b/MAINTAINERS.md index 3214adfdf1..43377c093d 100644 --- a/MAINTAINERS.md +++ b/MAINTAINERS.md @@ -9,7 +9,6 @@ review and merge policy. | --- | --- | --- | | [@lidge-jun](https://github.com/lidge-jun) | Project owner | Project direction, releases, repository administration, and final governance decisions | | [@Ingwannu](https://github.com/Ingwannu) | Maintainer | Issue and pull-request triage, `dev` integration, security review, and repository maintenance | -| [@Wibias](https://github.com/Wibias) | Maintainer | Issue and pull-request triage, `dev` integration, and provider/CI maintenance | The table describes project responsibilities. Actual repository permissions remain controlled through GitHub repository settings. @@ -17,6 +16,16 @@ through GitHub repository settings. `dev` is the only integration line. The former `dev2-go` carry duty is retired; see [The retired `dev2-go` line](#the-retired-dev2-go-line). +## Former maintainers + +| GitHub account | Project role | Period | +| --- | --- | --- | +| [@Wibias](https://github.com/Wibias) | Maintainer | 2026-07-27 – 2026-08-19 | + +Former maintainers keep contributor standing and are welcome to open issues and pull requests like +anyone else. Authorship credit in git history, release notes, and code comments is not rewritten +when a maintainer steps down. + ## Review and merge policy - Pull requests target `dev`. It is the only integration line, and promotion to @@ -98,6 +107,24 @@ Adding or removing a maintainer requires: ### Change log +- 2026-08-19 — [@Wibias](https://github.com/Wibias) stepped down as a maintainer + and is now a contributor. This follows his own decision to stop developing + opencodex; it is not a disciplinary action, and it was made with the owner's + agreement (requirement 1). Requirement 2 does not apply to a maintainer's own + resignation, which needs no second maintainer to ratify it. Requirement 3 is + met by this file and `.github/CODEOWNERS`, where the default-reviewer line + and the four runtime paths that listed him (`/src/adapters/`, + `/src/providers/`, `/src/codex/`, `/src/server/`) drop back to the two + remaining maintainers. Repository permission was reduced to read access at + the same time, so the roster and the GitHub settings agree again. + + Nothing he authored is being unwound. His commits, the pull requests he + merged, the release-note attributions, and the code comments citing his + reviews stay exactly as they are, and the trust-lane gate derived from his + work in `.github/scripts/pr-sponsored-surface.cjs` keeps its attribution. + Returning to the maintainer table later would go through the same three + requirements that govern every addition. + - 2026-07-27 — [@Wibias](https://github.com/Wibias) added as a maintainer. Requirement 1 (agreement from the project owner) is met: the owner requested the addition. **Requirement 2 (review by another current maintainer) was @@ -105,10 +132,10 @@ Adding or removing a maintainer requires: carried the addition (`a2693c02`, `dc3a4ade`, `02bbd47a`) landed on `dev` as direct owner pushes with no associated pull request, so no second maintainer reviewed them. Requirement 3 is met by this file and `.github/CODEOWNERS`. - The addition is in effect regardless: @Wibias holds write access on the - repository and has been merging pull requests since 2026-07-26. This entry - records the gap rather than papering over it — a later maintainer change - should go through a reviewed pull request. + The addition took effect regardless: @Wibias held write access on the + repository and merged pull requests from 2026-07-26 until he stepped down on + 2026-08-19. This entry records the gap rather than papering over it — a later + maintainer change should go through a reviewed pull request. Scope covers issue and pull-request triage, `dev` integration, and provider/CI maintenance. (This entry originally also described carrying From 84c848266ae0eb6edb9540d9952c2822a6453062 Mon Sep 17 00:00:00 2001 From: luvs01 Date: Mon, 17 Aug 2026 13:53:41 +0900 Subject: [PATCH 2/2] fix(responses): scope namespaced tool declarations --- src/server/responses-undeclared-tool-guard.ts | 7 +++--- tests/responses-undeclared-tool-guard.test.ts | 22 +++++++++++++++---- 2 files changed, 21 insertions(+), 8 deletions(-) diff --git a/src/server/responses-undeclared-tool-guard.ts b/src/server/responses-undeclared-tool-guard.ts index 3a263f6fb0..590c714859 100644 --- a/src/server/responses-undeclared-tool-guard.ts +++ b/src/server/responses-undeclared-tool-guard.ts @@ -19,11 +19,10 @@ function isPlainObject(value: unknown): value is Record { function addWireToolName(names: Set, tool: unknown, namespace?: string): void { if (!isPlainObject(tool) || typeof tool.name !== "string" || tool.name.length === 0) return; - names.add(tool.name); // Codex routes MCP calls by an explicit `namespace` field, so the same tool is reachable - // as a bare inner name or as the flattened form; accept both rather than guess which - // coordinate system this provider echoes back. - if (namespace) names.add(namespacedToolName(namespace, tool.name)); + // as a bare inner name paired with that namespace or as the flattened form. Store only the + // flattened coordinate so a namespace member cannot authorize a colliding top-level tool. + names.add(namespace ? namespacedToolName(namespace, tool.name) : tool.name); } function addWireToolSpecs(names: Set, specs: unknown): void { diff --git a/tests/responses-undeclared-tool-guard.test.ts b/tests/responses-undeclared-tool-guard.test.ts index 3cf8a08e17..891cc7d0b3 100644 --- a/tests/responses-undeclared-tool-guard.test.ts +++ b/tests/responses-undeclared-tool-guard.test.ts @@ -78,10 +78,8 @@ describe("collectDeclaredWireToolNames", () => { ], }); - // Namespaced MCP tools are reachable under either coordinate system, so both are accepted. - expect([...names].sort()).toEqual( - ["apply_patch", "create_issue", "exec", "linear__create_issue"], - ); + // Namespace members must not authorize a colliding top-level tool with the same bare name. + expect([...names].sort()).toEqual(["apply_patch", "exec", "linear__create_issue"]); }); test("reads tools carried inside input as an additional_tools item", () => { @@ -193,6 +191,22 @@ describe("undeclared tool call guard", () => { expect(await relay(upstream, ["linear__create_issue"])).toBe(upstream); }); + test("rejects a bare call declared only inside a namespace", async () => { + const declared = collectDeclaredWireToolNames({ + tools: [ + { type: "namespace", name: "safe", tools: [{ type: "function", name: "exec" }] }, + ], + }); + const upstream = sse("response.output_item.added", { + output_index: 0, + item: { type: "function_call", id: "fc_1", call_id: "call_1", name: "exec", arguments: "{}" }, + }); + + const out = await relay(upstream, declared); + expect(out).toContain(`"code":"${UNDECLARED_TOOL_CALL_ERROR_CODE}"`); + expect(out).toContain('routed provider emitted undeclared client tool \\"exec\\"'); + }); + test("never blocks apply_patch when the request really declared it", async () => { // `apply_patch` is exempt from the routed custom-tool rewrite, so it reaches upstream as // `{type:"custom"}` and comes back as a `custom_tool_call`. A request that declares it must