Skip to content

feat(gga): pin GGA reviews to Codex gpt-6.1-sol in a way that survives gentle-ai sync - #21

Merged
Dreamcoder08 merged 2 commits into
mainfrom
feat/gga-pin-hardening
Sep 29, 2026
Merged

Dreamcoder08 merged 2 commits into
mainfrom
feat/gga-pin-hardening

Conversation

@Dreamcoder08

Copy link
Copy Markdown
Owner

GGA must always review with OpenAI gpt-6.1-sol at medium reasoning, in every project. gentle-ai sync (default scope includes GGA) and install call gga.Inject, which rewrites the whole ~/.config/gga/config unconditionally (verified in gentle-ai 3.7.0: internal/components/gga/config.go, internal/cli/sync.go:1158-1170), so a pin that lives only in that file is lost on the next sync.

Design

  • scripts/gga-codex-shim.sh (installed as ~/.config/gga/bin/codex): adds -m <model> -c model_reasoning_effort=<effort> to codex exec only when a gga process is an ancestor and no explicit -m is given. Interactive codex and every other call pass through untouched. Model and effort come from ~/.config/gga/pin.env, parsed without being sourced. It does not depend on the gga config or its env, so a config rewrite cannot disable it.
  • scripts/install-gga-pin.sh (idempotent, --dry-run, honours XDG_CONFIG_HOME): installs the shim, creates pin.env only if missing, maintains a marked block at the end of ~/.config/gga/config (PROVIDER/GGA_PROVIDER = codex, PATH), and writes ~/.config/environment.d/50-gga-pin.conf for desktop-launched tools.
  • dreamcoder repair/install re-apply it (only when gga is on PATH); fish, zsh and bash export GGA_PROVIDER and the PATH entry.
  • docs/configuration/gga.md documents what is pinned, how to change model/effort and the sync overwrite.

Also fixed while GGA reviewed these files (pre-existing): .bashrc set set -euo pipefail, sourced cargo twice unguarded and ran fnm unchecked; dreamcoder-lib.sh set strict mode although it is only sourced; .zshrc had a hardcoded repo path.

Tests: 16 new bats tests (installer idempotency, block replace not duplicate, gentle-ai-style rewrite restored, pin.env not overwritten, dry-run writes nothing, unsafe config dir refused; shim ancestry, no-ancestor passthrough, explicit -m wins, non-exec untouched, pin.env overrides). RED was confirmed by breaking each behaviour on purpose. bats 171 ok, pytest exit 0, shellcheck/bash -n/zsh -n/fish -n/markdown links clean.

Note: GGA's review of the second commit did not run: Codex answered usage_limit_exceeded and this repo's .gga is STRICT_MODE="false", so the hook let it through. The pin itself is confirmed working (the failed call's session log shows gpt-6.1-sol/medium).

gentle-ai sync rewrites ~/.config/gga/config wholesale, which dropped the
codex provider and model pin. The pin now lives in a codex shim that only
injects the model for `codex exec` calls made by a gga process, reading
~/.config/gga/pin.env, plus an idempotent installer that maintains a marked
block at the end of the gga config and an environment.d drop-in.
- dreamcoder_apply_hooks runs install-gga-pin.sh when gga is installed, so
  `dreamcoder repair` restores the config block that gentle-ai sync drops
- fish, zsh and bash export GGA_PROVIDER=codex and put the shim dir first on
  PATH when it exists
- .bashrc and dreamcoder-lib.sh no longer set strict mode in the sourcing
  shell; .bashrc guards fnm and drops a duplicate unguarded cargo source
- .zshrc resolves the repo through its stowed link instead of a fixed path
- docs/configuration/gga.md explains the pin, pin.env and the sync overwrite
@Dreamcoder08
Dreamcoder08 merged commit 2fba0f6 into main Sep 29, 2026
8 checks passed
@Dreamcoder08
Dreamcoder08 deleted the feat/gga-pin-hardening branch September 29, 2026 23:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant