fix(server): one-click provider updates no longer wedge brew-installed Codex on macOS - #8247

Closed
t3dotgg wants to merge 1 commit into
mainfrom
fix/homebrew-cask-quarantine
Closed

fix(server): one-click provider updates no longer wedge brew-installed Codex on macOS#8247
t3dotgg wants to merge 1 commit into
mainfrom
fix/homebrew-cask-quarantine

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 26, 2026

Copy link
Copy Markdown
Member

Codex broke on a machine right before the stable cut: the provider status check timed out and the model picker showed no models. The cause was not a recent merge. A fresh `brew` cask install of codex left the binary quarantined, and macOS blocked every exec behind a Gatekeeper approval prompt that a background server can never answer. The T3 probe then timed out forever.

Our one-click provider update runs the same command (`brew upgrade codex`), so any stable user with a brew-installed Codex who clicks Update reproduces this exact wedge. This PR passes `--no-quarantine` to `brew upgrade` for Homebrew-managed providers, so the updated binary is never quarantined. The flag is a no-op for formulae and only changes cask behavior. Verified the flag parses with `brew upgrade --dry-run --no-quarantine codex` (exit 0).

Changes by Claude Fable 5 via Claude Code.


Note

Low Risk
Narrow change to Homebrew upgrade flags for provider maintenance; slightly relaxes quarantine on cask upgrades but targets a known headless-server failure mode.

Overview
Fixes one-click Homebrew provider updates wedging provider health checks on macOS when the installed tool is a cask whose binary gets quarantined after brew upgrade.

Homebrew-managed provider maintenance now runs brew upgrade --no-quarantine <formula> instead of plain brew upgrade. The flag avoids Gatekeeper quarantine on cask binaries so the T3 server can execute the provider probe without a manual approval dialog; it is documented as a no-op for formulae. Expectations in providerMaintenance.test.ts for Homebrew-resolved binaries are updated to match the new command and args.

Reviewed by Cursor Bugbot for commit 3c736e4. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add --no-quarantine flag to Homebrew update args in makeHomebrewProviderMaintenanceCapabilities

One-click provider updates invoke brew upgrade with a new --no-quarantine argument inserted before the formula identifier. This prevents macOS Gatekeeper quarantine from wedging brew-installed Codex after an update. Tests in providerMaintenance.test.ts are updated to expect the new argument shape.

Macroscope summarized 3c736e4.

… macOS
Homebrew cask upgrades quarantine the new binary. macOS then blocks the
next exec behind a Gatekeeper approval prompt the T3 server cannot
answer, so the provider probe hangs until it times out and the model
picker shows no models. Pass --no-quarantine to brew upgrade so managed
updates never quarantine the binary. The flag is a no-op for formulae.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e3213020-f054-42cd-a027-b7ba8d79d2e0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XS 0-9 changed lines (additions + deletions). labels Aug 26, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.3 KiB−2 B (−0.0%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−2 B (−0.0%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.4 KiB0 B (0.0%)7.8 KiB
CodexLive turn WebSocket decoded55.6 KiB55.6 KiB0 B (0.0%)66.4 KiB
CodexLive turn messages10100 (0.0%)21
ClaudeTotal thread wire13.3 KiB13.3 KiB−19 B (−0.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−4 B (−0.1%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.4 KiB−15 B (−0.2%)7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB56.4 KiB−44 B (−0.1%)66.4 KiB
ClaudeLive turn messages1110−1 (−9.1%)21

Baseline: badae6a · PR result: 3c736e4 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 3c736e4. Configure here.

// the next exec behind a Gatekeeper approval prompt, which the T3 server
// cannot answer, so the provider probe hangs until a human approves the
// binary. --no-quarantine skips that and is a no-op for formulae.
updateArgs: ["upgrade", "--no-quarantine", definition.homebrewFormula],

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed brew flag breaks updates

High Severity

--no-quarantine was disabled in Homebrew 5.1.0 and fully removed in July 2026, so current brew upgrade rejects it with an invalid/unknown-option error. providerMaintenanceRunner treats any non-zero exit as a failed update, so one-click Homebrew updates for Codex (and other brew-routed providers) fail instead of fixing the Gatekeeper wedge.

Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit 3c736e4. Configure here.

@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The PR changes production Homebrew update commands and intentionally bypasses binary quarantine for affected providers. An unresolved concrete review finding reports that the added flag is rejected by newer Homebrew versions, potentially causing one-click updates to fail.

You can add or adjust custom eligibility rules. Learn more.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS0-9 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(server): one-click provider updates no longer wedge brew-installed Codex on macOS - #8247

Closed
t3dotgg wants to merge 1 commit into
mainfrom
fix/homebrew-cask-quarantine
Closed

fix(server): one-click provider updates no longer wedge brew-installed Codex on macOS#8247
t3dotgg wants to merge 1 commit into
mainfrom
fix/homebrew-cask-quarantine

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 26, 2026

Copy link
Copy Markdown
Member

Codex broke on a machine right before the stable cut: the provider status check timed out and the model picker showed no models. The cause was not a recent merge. A fresh `brew` cask install of codex left the binary quarantined, and macOS blocked every exec behind a Gatekeeper approval prompt that a background server can never answer. The T3 probe then timed out forever.

Our one-click provider update runs the same command (`brew upgrade codex`), so any stable user with a brew-installed Codex who clicks Update reproduces this exact wedge. This PR passes `--no-quarantine` to `brew upgrade` for Homebrew-managed providers, so the updated binary is never quarantined. The flag is a no-op for formulae and only changes cask behavior. Verified the flag parses with `brew upgrade --dry-run --no-quarantine codex` (exit 0).

Changes by Claude Fable 5 via Claude Code.


Note

Low Risk
Narrow change to Homebrew upgrade flags for provider maintenance; slightly relaxes quarantine on cask upgrades but targets a known headless-server failure mode.

Overview
Fixes one-click Homebrew provider updates wedging provider health checks on macOS when the installed tool is a cask whose binary gets quarantined after brew upgrade.

Homebrew-managed provider maintenance now runs brew upgrade --no-quarantine <formula> instead of plain brew upgrade. The flag avoids Gatekeeper quarantine on cask binaries so the T3 server can execute the provider probe without a manual approval dialog; it is documented as a no-op for formulae. Expectations in providerMaintenance.test.ts for Homebrew-resolved binaries are updated to match the new command and args.

Reviewed by Cursor Bugbot for commit 3c736e4. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add --no-quarantine flag to Homebrew update args in makeHomebrewProviderMaintenanceCapabilities

One-click provider updates invoke brew upgrade with a new --no-quarantine argument inserted before the formula identifier. This prevents macOS Gatekeeper quarantine from wedging brew-installed Codex after an update. Tests in providerMaintenance.test.ts are updated to expect the new argument shape.

Macroscope summarized 3c736e4.

… macOS
Homebrew cask upgrades quarantine the new binary. macOS then blocks the
next exec behind a Gatekeeper approval prompt the T3 server cannot
answer, so the provider probe hangs until it times out and the model
picker shows no models. Pass --no-quarantine to brew upgrade so managed
updates never quarantine the binary. The flag is a no-op for formulae.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e3213020-f054-42cd-a027-b7ba8d79d2e0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XS 0-9 changed lines (additions + deletions). labels Aug 26, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.3 KiB−2 B (−0.0%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−2 B (−0.0%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.4 KiB0 B (0.0%)7.8 KiB
CodexLive turn WebSocket decoded55.6 KiB55.6 KiB0 B (0.0%)66.4 KiB
CodexLive turn messages10100 (0.0%)21
ClaudeTotal thread wire13.3 KiB13.3 KiB−19 B (−0.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−4 B (−0.1%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.4 KiB−15 B (−0.2%)7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB56.4 KiB−44 B (−0.1%)66.4 KiB
ClaudeLive turn messages1110−1 (−9.1%)21

Baseline: badae6a · PR result: 3c736e4 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 3c736e4. Configure here.

// the next exec behind a Gatekeeper approval prompt, which the T3 server
// cannot answer, so the provider probe hangs until a human approves the
// binary. --no-quarantine skips that and is a no-op for formulae.
updateArgs: ["upgrade", "--no-quarantine", definition.homebrewFormula],

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed brew flag breaks updates

High Severity

--no-quarantine was disabled in Homebrew 5.1.0 and fully removed in July 2026, so current brew upgrade rejects it with an invalid/unknown-option error. providerMaintenanceRunner treats any non-zero exit as a failed update, so one-click Homebrew updates for Codex (and other brew-routed providers) fail instead of fixing the Gatekeeper wedge.

Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit 3c736e4. Configure here.

@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The PR changes production Homebrew update commands and intentionally bypasses binary quarantine for affected providers. An unresolved concrete review finding reports that the added flag is rejected by newer Homebrew versions, potentially causing one-click updates to fail.

You can add or adjust custom eligibility rules. Learn more.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS0-9 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(server): one-click provider updates no longer wedge brew-installed Codex on macOS - #8247

Closed
t3dotgg wants to merge 1 commit into
mainfrom
fix/homebrew-cask-quarantine
Closed

fix(server): one-click provider updates no longer wedge brew-installed Codex on macOS#8247
t3dotgg wants to merge 1 commit into
mainfrom
fix/homebrew-cask-quarantine

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 26, 2026

Copy link
Copy Markdown
Member

Codex broke on a machine right before the stable cut: the provider status check timed out and the model picker showed no models. The cause was not a recent merge. A fresh `brew` cask install of codex left the binary quarantined, and macOS blocked every exec behind a Gatekeeper approval prompt that a background server can never answer. The T3 probe then timed out forever.

Our one-click provider update runs the same command (`brew upgrade codex`), so any stable user with a brew-installed Codex who clicks Update reproduces this exact wedge. This PR passes `--no-quarantine` to `brew upgrade` for Homebrew-managed providers, so the updated binary is never quarantined. The flag is a no-op for formulae and only changes cask behavior. Verified the flag parses with `brew upgrade --dry-run --no-quarantine codex` (exit 0).

Changes by Claude Fable 5 via Claude Code.


Note

Low Risk
Narrow change to Homebrew upgrade flags for provider maintenance; slightly relaxes quarantine on cask upgrades but targets a known headless-server failure mode.

Overview
Fixes one-click Homebrew provider updates wedging provider health checks on macOS when the installed tool is a cask whose binary gets quarantined after brew upgrade.

Homebrew-managed provider maintenance now runs brew upgrade --no-quarantine <formula> instead of plain brew upgrade. The flag avoids Gatekeeper quarantine on cask binaries so the T3 server can execute the provider probe without a manual approval dialog; it is documented as a no-op for formulae. Expectations in providerMaintenance.test.ts for Homebrew-resolved binaries are updated to match the new command and args.

Reviewed by Cursor Bugbot for commit 3c736e4. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add --no-quarantine flag to Homebrew update args in makeHomebrewProviderMaintenanceCapabilities

One-click provider updates invoke brew upgrade with a new --no-quarantine argument inserted before the formula identifier. This prevents macOS Gatekeeper quarantine from wedging brew-installed Codex after an update. Tests in providerMaintenance.test.ts are updated to expect the new argument shape.

Macroscope summarized 3c736e4.

… macOS
Homebrew cask upgrades quarantine the new binary. macOS then blocks the
next exec behind a Gatekeeper approval prompt the T3 server cannot
answer, so the provider probe hangs until it times out and the model
picker shows no models. Pass --no-quarantine to brew upgrade so managed
updates never quarantine the binary. The flag is a no-op for formulae.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e3213020-f054-42cd-a027-b7ba8d79d2e0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XS 0-9 changed lines (additions + deletions). labels Aug 26, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.3 KiB−2 B (−0.0%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−2 B (−0.0%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.4 KiB0 B (0.0%)7.8 KiB
CodexLive turn WebSocket decoded55.6 KiB55.6 KiB0 B (0.0%)66.4 KiB
CodexLive turn messages10100 (0.0%)21
ClaudeTotal thread wire13.3 KiB13.3 KiB−19 B (−0.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−4 B (−0.1%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.4 KiB−15 B (−0.2%)7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB56.4 KiB−44 B (−0.1%)66.4 KiB
ClaudeLive turn messages1110−1 (−9.1%)21

Baseline: badae6a · PR result: 3c736e4 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 3c736e4. Configure here.

// the next exec behind a Gatekeeper approval prompt, which the T3 server
// cannot answer, so the provider probe hangs until a human approves the
// binary. --no-quarantine skips that and is a no-op for formulae.
updateArgs: ["upgrade", "--no-quarantine", definition.homebrewFormula],

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed brew flag breaks updates

High Severity

--no-quarantine was disabled in Homebrew 5.1.0 and fully removed in July 2026, so current brew upgrade rejects it with an invalid/unknown-option error. providerMaintenanceRunner treats any non-zero exit as a failed update, so one-click Homebrew updates for Codex (and other brew-routed providers) fail instead of fixing the Gatekeeper wedge.

Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit 3c736e4. Configure here.

@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The PR changes production Homebrew update commands and intentionally bypasses binary quarantine for affected providers. An unresolved concrete review finding reports that the added flag is rejected by newer Homebrew versions, potentially causing one-click updates to fail.

You can add or adjust custom eligibility rules. Learn more.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS0-9 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(server): one-click provider updates no longer wedge brew-installed Codex on macOS - #8247

Closed
t3dotgg wants to merge 1 commit into
mainfrom
fix/homebrew-cask-quarantine
Closed

fix(server): one-click provider updates no longer wedge brew-installed Codex on macOS#8247
t3dotgg wants to merge 1 commit into
mainfrom
fix/homebrew-cask-quarantine

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 26, 2026

Copy link
Copy Markdown
Member

Codex broke on a machine right before the stable cut: the provider status check timed out and the model picker showed no models. The cause was not a recent merge. A fresh `brew` cask install of codex left the binary quarantined, and macOS blocked every exec behind a Gatekeeper approval prompt that a background server can never answer. The T3 probe then timed out forever.

Our one-click provider update runs the same command (`brew upgrade codex`), so any stable user with a brew-installed Codex who clicks Update reproduces this exact wedge. This PR passes `--no-quarantine` to `brew upgrade` for Homebrew-managed providers, so the updated binary is never quarantined. The flag is a no-op for formulae and only changes cask behavior. Verified the flag parses with `brew upgrade --dry-run --no-quarantine codex` (exit 0).

Changes by Claude Fable 5 via Claude Code.


Note

Low Risk
Narrow change to Homebrew upgrade flags for provider maintenance; slightly relaxes quarantine on cask upgrades but targets a known headless-server failure mode.

Overview
Fixes one-click Homebrew provider updates wedging provider health checks on macOS when the installed tool is a cask whose binary gets quarantined after brew upgrade.

Homebrew-managed provider maintenance now runs brew upgrade --no-quarantine <formula> instead of plain brew upgrade. The flag avoids Gatekeeper quarantine on cask binaries so the T3 server can execute the provider probe without a manual approval dialog; it is documented as a no-op for formulae. Expectations in providerMaintenance.test.ts for Homebrew-resolved binaries are updated to match the new command and args.

Reviewed by Cursor Bugbot for commit 3c736e4. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add --no-quarantine flag to Homebrew update args in makeHomebrewProviderMaintenanceCapabilities

One-click provider updates invoke brew upgrade with a new --no-quarantine argument inserted before the formula identifier. This prevents macOS Gatekeeper quarantine from wedging brew-installed Codex after an update. Tests in providerMaintenance.test.ts are updated to expect the new argument shape.

Macroscope summarized 3c736e4.

… macOS
Homebrew cask upgrades quarantine the new binary. macOS then blocks the
next exec behind a Gatekeeper approval prompt the T3 server cannot
answer, so the provider probe hangs until it times out and the model
picker shows no models. Pass --no-quarantine to brew upgrade so managed
updates never quarantine the binary. The flag is a no-op for formulae.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e3213020-f054-42cd-a027-b7ba8d79d2e0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XS 0-9 changed lines (additions + deletions). labels Aug 26, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.3 KiB−2 B (−0.0%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−2 B (−0.0%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.4 KiB0 B (0.0%)7.8 KiB
CodexLive turn WebSocket decoded55.6 KiB55.6 KiB0 B (0.0%)66.4 KiB
CodexLive turn messages10100 (0.0%)21
ClaudeTotal thread wire13.3 KiB13.3 KiB−19 B (−0.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−4 B (−0.1%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.4 KiB−15 B (−0.2%)7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB56.4 KiB−44 B (−0.1%)66.4 KiB
ClaudeLive turn messages1110−1 (−9.1%)21

Baseline: badae6a · PR result: 3c736e4 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 3c736e4. Configure here.

// the next exec behind a Gatekeeper approval prompt, which the T3 server
// cannot answer, so the provider probe hangs until a human approves the
// binary. --no-quarantine skips that and is a no-op for formulae.
updateArgs: ["upgrade", "--no-quarantine", definition.homebrewFormula],

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed brew flag breaks updates

High Severity

--no-quarantine was disabled in Homebrew 5.1.0 and fully removed in July 2026, so current brew upgrade rejects it with an invalid/unknown-option error. providerMaintenanceRunner treats any non-zero exit as a failed update, so one-click Homebrew updates for Codex (and other brew-routed providers) fail instead of fixing the Gatekeeper wedge.

Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit 3c736e4. Configure here.

@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The PR changes production Homebrew update commands and intentionally bypasses binary quarantine for affected providers. An unresolved concrete review finding reports that the added flag is rejected by newer Homebrew versions, potentially causing one-click updates to fail.

You can add or adjust custom eligibility rules. Learn more.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS0-9 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(server): one-click provider updates no longer wedge brew-installed Codex on macOS - #8247

Closed
t3dotgg wants to merge 1 commit into
mainfrom
fix/homebrew-cask-quarantine
Closed

fix(server): one-click provider updates no longer wedge brew-installed Codex on macOS#8247
t3dotgg wants to merge 1 commit into
mainfrom
fix/homebrew-cask-quarantine

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 26, 2026

Copy link
Copy Markdown
Member

Codex broke on a machine right before the stable cut: the provider status check timed out and the model picker showed no models. The cause was not a recent merge. A fresh `brew` cask install of codex left the binary quarantined, and macOS blocked every exec behind a Gatekeeper approval prompt that a background server can never answer. The T3 probe then timed out forever.

Our one-click provider update runs the same command (`brew upgrade codex`), so any stable user with a brew-installed Codex who clicks Update reproduces this exact wedge. This PR passes `--no-quarantine` to `brew upgrade` for Homebrew-managed providers, so the updated binary is never quarantined. The flag is a no-op for formulae and only changes cask behavior. Verified the flag parses with `brew upgrade --dry-run --no-quarantine codex` (exit 0).

Changes by Claude Fable 5 via Claude Code.


Note

Low Risk
Narrow change to Homebrew upgrade flags for provider maintenance; slightly relaxes quarantine on cask upgrades but targets a known headless-server failure mode.

Overview
Fixes one-click Homebrew provider updates wedging provider health checks on macOS when the installed tool is a cask whose binary gets quarantined after brew upgrade.

Homebrew-managed provider maintenance now runs brew upgrade --no-quarantine <formula> instead of plain brew upgrade. The flag avoids Gatekeeper quarantine on cask binaries so the T3 server can execute the provider probe without a manual approval dialog; it is documented as a no-op for formulae. Expectations in providerMaintenance.test.ts for Homebrew-resolved binaries are updated to match the new command and args.

Reviewed by Cursor Bugbot for commit 3c736e4. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add --no-quarantine flag to Homebrew update args in makeHomebrewProviderMaintenanceCapabilities

One-click provider updates invoke brew upgrade with a new --no-quarantine argument inserted before the formula identifier. This prevents macOS Gatekeeper quarantine from wedging brew-installed Codex after an update. Tests in providerMaintenance.test.ts are updated to expect the new argument shape.

Macroscope summarized 3c736e4.

… macOS
Homebrew cask upgrades quarantine the new binary. macOS then blocks the
next exec behind a Gatekeeper approval prompt the T3 server cannot
answer, so the provider probe hangs until it times out and the model
picker shows no models. Pass --no-quarantine to brew upgrade so managed
updates never quarantine the binary. The flag is a no-op for formulae.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e3213020-f054-42cd-a027-b7ba8d79d2e0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XS 0-9 changed lines (additions + deletions). labels Aug 26, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.3 KiB−2 B (−0.0%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−2 B (−0.0%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.4 KiB0 B (0.0%)7.8 KiB
CodexLive turn WebSocket decoded55.6 KiB55.6 KiB0 B (0.0%)66.4 KiB
CodexLive turn messages10100 (0.0%)21
ClaudeTotal thread wire13.3 KiB13.3 KiB−19 B (−0.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−4 B (−0.1%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.4 KiB−15 B (−0.2%)7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB56.4 KiB−44 B (−0.1%)66.4 KiB
ClaudeLive turn messages1110−1 (−9.1%)21

Baseline: badae6a · PR result: 3c736e4 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 3c736e4. Configure here.

// the next exec behind a Gatekeeper approval prompt, which the T3 server
// cannot answer, so the provider probe hangs until a human approves the
// binary. --no-quarantine skips that and is a no-op for formulae.
updateArgs: ["upgrade", "--no-quarantine", definition.homebrewFormula],

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed brew flag breaks updates

High Severity

--no-quarantine was disabled in Homebrew 5.1.0 and fully removed in July 2026, so current brew upgrade rejects it with an invalid/unknown-option error. providerMaintenanceRunner treats any non-zero exit as a failed update, so one-click Homebrew updates for Codex (and other brew-routed providers) fail instead of fixing the Gatekeeper wedge.

Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit 3c736e4. Configure here.

@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The PR changes production Homebrew update commands and intentionally bypasses binary quarantine for affected providers. An unresolved concrete review finding reports that the added flag is rejected by newer Homebrew versions, potentially causing one-click updates to fail.

You can add or adjust custom eligibility rules. Learn more.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS0-9 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(server): one-click provider updates no longer wedge brew-installed Codex on macOS - #8247

Closed
t3dotgg wants to merge 1 commit into
mainfrom
fix/homebrew-cask-quarantine
Closed

fix(server): one-click provider updates no longer wedge brew-installed Codex on macOS#8247
t3dotgg wants to merge 1 commit into
mainfrom
fix/homebrew-cask-quarantine

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 26, 2026

Copy link
Copy Markdown
Member

Codex broke on a machine right before the stable cut: the provider status check timed out and the model picker showed no models. The cause was not a recent merge. A fresh `brew` cask install of codex left the binary quarantined, and macOS blocked every exec behind a Gatekeeper approval prompt that a background server can never answer. The T3 probe then timed out forever.

Our one-click provider update runs the same command (`brew upgrade codex`), so any stable user with a brew-installed Codex who clicks Update reproduces this exact wedge. This PR passes `--no-quarantine` to `brew upgrade` for Homebrew-managed providers, so the updated binary is never quarantined. The flag is a no-op for formulae and only changes cask behavior. Verified the flag parses with `brew upgrade --dry-run --no-quarantine codex` (exit 0).

Changes by Claude Fable 5 via Claude Code.


Note

Low Risk
Narrow change to Homebrew upgrade flags for provider maintenance; slightly relaxes quarantine on cask upgrades but targets a known headless-server failure mode.

Overview
Fixes one-click Homebrew provider updates wedging provider health checks on macOS when the installed tool is a cask whose binary gets quarantined after brew upgrade.

Homebrew-managed provider maintenance now runs brew upgrade --no-quarantine <formula> instead of plain brew upgrade. The flag avoids Gatekeeper quarantine on cask binaries so the T3 server can execute the provider probe without a manual approval dialog; it is documented as a no-op for formulae. Expectations in providerMaintenance.test.ts for Homebrew-resolved binaries are updated to match the new command and args.

Reviewed by Cursor Bugbot for commit 3c736e4. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add --no-quarantine flag to Homebrew update args in makeHomebrewProviderMaintenanceCapabilities

One-click provider updates invoke brew upgrade with a new --no-quarantine argument inserted before the formula identifier. This prevents macOS Gatekeeper quarantine from wedging brew-installed Codex after an update. Tests in providerMaintenance.test.ts are updated to expect the new argument shape.

Macroscope summarized 3c736e4.

… macOS
Homebrew cask upgrades quarantine the new binary. macOS then blocks the
next exec behind a Gatekeeper approval prompt the T3 server cannot
answer, so the provider probe hangs until it times out and the model
picker shows no models. Pass --no-quarantine to brew upgrade so managed
updates never quarantine the binary. The flag is a no-op for formulae.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e3213020-f054-42cd-a027-b7ba8d79d2e0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XS 0-9 changed lines (additions + deletions). labels Aug 26, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.3 KiB−2 B (−0.0%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−2 B (−0.0%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.4 KiB0 B (0.0%)7.8 KiB
CodexLive turn WebSocket decoded55.6 KiB55.6 KiB0 B (0.0%)66.4 KiB
CodexLive turn messages10100 (0.0%)21
ClaudeTotal thread wire13.3 KiB13.3 KiB−19 B (−0.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−4 B (−0.1%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.4 KiB−15 B (−0.2%)7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB56.4 KiB−44 B (−0.1%)66.4 KiB
ClaudeLive turn messages1110−1 (−9.1%)21

Baseline: badae6a · PR result: 3c736e4 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 3c736e4. Configure here.

// the next exec behind a Gatekeeper approval prompt, which the T3 server
// cannot answer, so the provider probe hangs until a human approves the
// binary. --no-quarantine skips that and is a no-op for formulae.
updateArgs: ["upgrade", "--no-quarantine", definition.homebrewFormula],

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed brew flag breaks updates

High Severity

--no-quarantine was disabled in Homebrew 5.1.0 and fully removed in July 2026, so current brew upgrade rejects it with an invalid/unknown-option error. providerMaintenanceRunner treats any non-zero exit as a failed update, so one-click Homebrew updates for Codex (and other brew-routed providers) fail instead of fixing the Gatekeeper wedge.

Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit 3c736e4. Configure here.

@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The PR changes production Homebrew update commands and intentionally bypasses binary quarantine for affected providers. An unresolved concrete review finding reports that the added flag is rejected by newer Homebrew versions, potentially causing one-click updates to fail.

You can add or adjust custom eligibility rules. Learn more.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS0-9 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(server): one-click provider updates no longer wedge brew-installed Codex on macOS - #8247

Closed
t3dotgg wants to merge 1 commit into
mainfrom
fix/homebrew-cask-quarantine
Closed

fix(server): one-click provider updates no longer wedge brew-installed Codex on macOS#8247
t3dotgg wants to merge 1 commit into
mainfrom
fix/homebrew-cask-quarantine

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 26, 2026

Copy link
Copy Markdown
Member

Codex broke on a machine right before the stable cut: the provider status check timed out and the model picker showed no models. The cause was not a recent merge. A fresh `brew` cask install of codex left the binary quarantined, and macOS blocked every exec behind a Gatekeeper approval prompt that a background server can never answer. The T3 probe then timed out forever.

Our one-click provider update runs the same command (`brew upgrade codex`), so any stable user with a brew-installed Codex who clicks Update reproduces this exact wedge. This PR passes `--no-quarantine` to `brew upgrade` for Homebrew-managed providers, so the updated binary is never quarantined. The flag is a no-op for formulae and only changes cask behavior. Verified the flag parses with `brew upgrade --dry-run --no-quarantine codex` (exit 0).

Changes by Claude Fable 5 via Claude Code.


Note

Low Risk
Narrow change to Homebrew upgrade flags for provider maintenance; slightly relaxes quarantine on cask upgrades but targets a known headless-server failure mode.

Overview
Fixes one-click Homebrew provider updates wedging provider health checks on macOS when the installed tool is a cask whose binary gets quarantined after brew upgrade.

Homebrew-managed provider maintenance now runs brew upgrade --no-quarantine <formula> instead of plain brew upgrade. The flag avoids Gatekeeper quarantine on cask binaries so the T3 server can execute the provider probe without a manual approval dialog; it is documented as a no-op for formulae. Expectations in providerMaintenance.test.ts for Homebrew-resolved binaries are updated to match the new command and args.

Reviewed by Cursor Bugbot for commit 3c736e4. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add --no-quarantine flag to Homebrew update args in makeHomebrewProviderMaintenanceCapabilities

One-click provider updates invoke brew upgrade with a new --no-quarantine argument inserted before the formula identifier. This prevents macOS Gatekeeper quarantine from wedging brew-installed Codex after an update. Tests in providerMaintenance.test.ts are updated to expect the new argument shape.

Macroscope summarized 3c736e4.

… macOS
Homebrew cask upgrades quarantine the new binary. macOS then blocks the
next exec behind a Gatekeeper approval prompt the T3 server cannot
answer, so the provider probe hangs until it times out and the model
picker shows no models. Pass --no-quarantine to brew upgrade so managed
updates never quarantine the binary. The flag is a no-op for formulae.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e3213020-f054-42cd-a027-b7ba8d79d2e0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XS 0-9 changed lines (additions + deletions). labels Aug 26, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.3 KiB−2 B (−0.0%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−2 B (−0.0%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.4 KiB0 B (0.0%)7.8 KiB
CodexLive turn WebSocket decoded55.6 KiB55.6 KiB0 B (0.0%)66.4 KiB
CodexLive turn messages10100 (0.0%)21
ClaudeTotal thread wire13.3 KiB13.3 KiB−19 B (−0.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−4 B (−0.1%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.4 KiB−15 B (−0.2%)7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB56.4 KiB−44 B (−0.1%)66.4 KiB
ClaudeLive turn messages1110−1 (−9.1%)21

Baseline: badae6a · PR result: 3c736e4 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 3c736e4. Configure here.

// the next exec behind a Gatekeeper approval prompt, which the T3 server
// cannot answer, so the provider probe hangs until a human approves the
// binary. --no-quarantine skips that and is a no-op for formulae.
updateArgs: ["upgrade", "--no-quarantine", definition.homebrewFormula],

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed brew flag breaks updates

High Severity

--no-quarantine was disabled in Homebrew 5.1.0 and fully removed in July 2026, so current brew upgrade rejects it with an invalid/unknown-option error. providerMaintenanceRunner treats any non-zero exit as a failed update, so one-click Homebrew updates for Codex (and other brew-routed providers) fail instead of fixing the Gatekeeper wedge.

Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit 3c736e4. Configure here.

@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The PR changes production Homebrew update commands and intentionally bypasses binary quarantine for affected providers. An unresolved concrete review finding reports that the added flag is rejected by newer Homebrew versions, potentially causing one-click updates to fail.

You can add or adjust custom eligibility rules. Learn more.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS0-9 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(server): one-click provider updates no longer wedge brew-installed Codex on macOS - #8247

Closed
t3dotgg wants to merge 1 commit into
mainfrom
fix/homebrew-cask-quarantine
Closed

fix(server): one-click provider updates no longer wedge brew-installed Codex on macOS#8247
t3dotgg wants to merge 1 commit into
mainfrom
fix/homebrew-cask-quarantine

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 26, 2026

Copy link
Copy Markdown
Member

Codex broke on a machine right before the stable cut: the provider status check timed out and the model picker showed no models. The cause was not a recent merge. A fresh `brew` cask install of codex left the binary quarantined, and macOS blocked every exec behind a Gatekeeper approval prompt that a background server can never answer. The T3 probe then timed out forever.

Our one-click provider update runs the same command (`brew upgrade codex`), so any stable user with a brew-installed Codex who clicks Update reproduces this exact wedge. This PR passes `--no-quarantine` to `brew upgrade` for Homebrew-managed providers, so the updated binary is never quarantined. The flag is a no-op for formulae and only changes cask behavior. Verified the flag parses with `brew upgrade --dry-run --no-quarantine codex` (exit 0).

Changes by Claude Fable 5 via Claude Code.


Note

Low Risk
Narrow change to Homebrew upgrade flags for provider maintenance; slightly relaxes quarantine on cask upgrades but targets a known headless-server failure mode.

Overview
Fixes one-click Homebrew provider updates wedging provider health checks on macOS when the installed tool is a cask whose binary gets quarantined after brew upgrade.

Homebrew-managed provider maintenance now runs brew upgrade --no-quarantine <formula> instead of plain brew upgrade. The flag avoids Gatekeeper quarantine on cask binaries so the T3 server can execute the provider probe without a manual approval dialog; it is documented as a no-op for formulae. Expectations in providerMaintenance.test.ts for Homebrew-resolved binaries are updated to match the new command and args.

Reviewed by Cursor Bugbot for commit 3c736e4. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add --no-quarantine flag to Homebrew update args in makeHomebrewProviderMaintenanceCapabilities

One-click provider updates invoke brew upgrade with a new --no-quarantine argument inserted before the formula identifier. This prevents macOS Gatekeeper quarantine from wedging brew-installed Codex after an update. Tests in providerMaintenance.test.ts are updated to expect the new argument shape.

Macroscope summarized 3c736e4.

… macOS
Homebrew cask upgrades quarantine the new binary. macOS then blocks the
next exec behind a Gatekeeper approval prompt the T3 server cannot
answer, so the provider probe hangs until it times out and the model
picker shows no models. Pass --no-quarantine to brew upgrade so managed
updates never quarantine the binary. The flag is a no-op for formulae.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e3213020-f054-42cd-a027-b7ba8d79d2e0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XS 0-9 changed lines (additions + deletions). labels Aug 26, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.3 KiB−2 B (−0.0%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−2 B (−0.0%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.4 KiB0 B (0.0%)7.8 KiB
CodexLive turn WebSocket decoded55.6 KiB55.6 KiB0 B (0.0%)66.4 KiB
CodexLive turn messages10100 (0.0%)21
ClaudeTotal thread wire13.3 KiB13.3 KiB−19 B (−0.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−4 B (−0.1%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.4 KiB−15 B (−0.2%)7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB56.4 KiB−44 B (−0.1%)66.4 KiB
ClaudeLive turn messages1110−1 (−9.1%)21

Baseline: badae6a · PR result: 3c736e4 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 3c736e4. Configure here.

// the next exec behind a Gatekeeper approval prompt, which the T3 server
// cannot answer, so the provider probe hangs until a human approves the
// binary. --no-quarantine skips that and is a no-op for formulae.
updateArgs: ["upgrade", "--no-quarantine", definition.homebrewFormula],

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed brew flag breaks updates

High Severity

--no-quarantine was disabled in Homebrew 5.1.0 and fully removed in July 2026, so current brew upgrade rejects it with an invalid/unknown-option error. providerMaintenanceRunner treats any non-zero exit as a failed update, so one-click Homebrew updates for Codex (and other brew-routed providers) fail instead of fixing the Gatekeeper wedge.

Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit 3c736e4. Configure here.

@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The PR changes production Homebrew update commands and intentionally bypasses binary quarantine for affected providers. An unresolved concrete review finding reports that the added flag is rejected by newer Homebrew versions, potentially causing one-click updates to fail.

You can add or adjust custom eligibility rules. Learn more.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS0-9 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg