Add native Windows tray setup#1327
Conversation
|
Codex review: needs real behavior proof before merge. Reviewed June 7, 2026, 6:21 AM ET / 10:21 UTC. Summary Reproducibility: not applicable. as a user bug; this is a new platform feature. The review blockers are source-reproducible from the PR files: the signing fallbacks are in the workflows, and first-run settings enable sample data. Review metrics: 2 noteworthy metrics.
Merge readiness Overall follows the weaker of proof and patch quality, so missing proof can cap an otherwise strong patch. Rank-up moves:
Proof guidance:
Mantis proof suggestion Risk before merge
Maintainer options:
Next step before merge
Security Review findings
Review detailsBest possible solution: Require CodexBar-owned signing configuration, disable or clearly mark sample data, collect redacted proof for installer plus real provider-probe behavior, and then have maintainers explicitly approve whether Windows artifacts belong in first-party releases. Do we have a high-confidence way to reproduce the issue? Not applicable as a user bug; this is a new platform feature. The review blockers are source-reproducible from the PR files: the signing fallbacks are in the workflows, and first-run settings enable sample data. Is this the best way to solve the issue? No; the current PR is not the best merge-ready solution until signing fails closed to CodexBar-owned config, sample data cannot look live, and maintainers explicitly accept the Windows release surface. Full review comments:
Overall correctness: patch is incorrect AGENTS.md: found and applied where relevant. Codex review notes: model gpt-5.5, reasoning high; reviewed against 1583d6cc1005. Label changesLabel changes:
Label justifications:
Evidence reviewedSecurity concerns:
What I checked:
Likely related people:
What the crustacean ranks mean
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics. How this review workflow works
|
|
Added Windows visual proof.
Proof bundle gist: https://gist.github.com/vincentkoc/4eb0d10435048a7590fd0928d40103d2 |
|
Thanks for the substantial prototype. Closing this draft in its current form: it establishes a new first-party platform, release pipeline, installer, and signing burden without an approved Windows ownership plan. The current branch also falls back to unrelated signing identities and enables sample quota data that can look live on fresh installs. A new proposal would need explicit platform ownership, CodexBar-owned signing, real provider and installer proof, and a current-main implementation. |
Summary
Windows/with a provider snapshot/command probe contractVerification
git diff --checkruby -e 'require "yaml"; YAML.load_file(".github/workflows/ci.yml"); YAML.load_file(".github/workflows/release-cli.yml"); puts "yaml ok"'3bee2abf20c316298ae68066731e2074bd81b335https://github.com/vincentkoc/CodexBar/actions/runs/27071976339success on3bee2abf20c316298ae68066731e2074bd81b335Windows tray (win-x64): test, publish, installer, artifact upload passedWindows tray (win-arm64): test, publish, installer, artifact upload passedlint-build-test,build-linux-cli (linux-x64), andbuild-linux-cli (linux-arm64)passedcodexbar-windows-win-x64,codexbar-windows-win-arm64CodexBar.Windows.exefrom thecodexbar-windows-win-x64CI artifact on Crabbox AWS Windows desktop leasecbx_37c447e51894Screenshots
Screenshots are cropped to omit cloud host metadata.
Proof bundle gist: https://gist.github.com/vincentkoc/4eb0d10435048a7590fd0928d40103d2