github jlcodes99/cockpit-tools v1.3.66
Cockpit Tools v1.3.66

4 hours ago

更新日志(中文)

[1.3.66] - 2026-10-07

新增

  • API 服务请求日志支持首响耗时和请求详情,展示账号尝试轨迹及失败阶段;可选在本地记录有限长度的客户端与上游请求快照,默认关闭,支持单独清除已存正文。记录开关在并发保存配置及重启后保持用户选择。

  • Codex Chat 兼容回复支持流式及非流式搜索 URL 引用,使用标准 Chat Completions 引用格式,文本位置兼容多段内容和 Unicode 字符。

  • 语音反代支持 Codex backend 通话与控制连接路由、听写转写及 OpenAI 兼容音频接口。OAuth 账号使用 ChatGPT 转写服务并支持 JSON/纯文本返回及对应的内容类型;API Key 供应商可转发转写、翻译、语音合成及上游支持的流式响应,保留音频与语言提示,并沿用既有账号范围。混合账号池为语音合成和翻译选择 API Key,保留 OAuth 绑定限制;旧音频请求的迟到失败及重试暂停不会使新凭据失效。

  • Codex 模型管理支持每模型默认推理档位,以及模型、价格、别名和路由配置的 JSON 导入导出;导入先预览冲突并说明字段缺失、格式无效或不受支持的问题,默认保留已有配置,不包含账号凭据或 API Key,导入价格后在后台更新历史费用估算。

  • API 服务账号池失败记录显示可复制的请求 ID 与失败时间,便于对照日志排查;不同 API Key、模型和请求类型的诊断分别保留,无关请求成功或迟到结果不会清除较新的失败。

  • 通用设置与 Codex 设置弹框支持在 OAuth 切号时可选保留已安装的 Codex Web GPT 桥接;仅保留经本地集成记录验证的桥接,默认关闭。

  • API 服务账号池异常显示相关账号及具体筛选原因,区分账号范围不匹配、凭据映射失败、绑定账号未加载及未进入当前请求候选池;客户端同步收到本地化的范围筛选错误说明。

  • 账号池异常新增“检查绑定/检查配置”和逐条“清除记录”;公开 Key 可直接定位到对应策略,生图、内部和实例请求进入账号页并提示对应检查方向。清除仅移除诊断记录,保留账号认证、额度及调度状态,后续失败时重新显示异常。

  • 生图转发支持单独设置主模型,与图片工具模型分别配置;留空沿用 gpt-5.5,所选 OAuth 账号需支持该主模型的 image_generation。

  • Codex 额度设置支持选择参与平台及分组定时刷新的 OAuth 套餐;默认仍全选,手动刷新、当前账号刷新、Token 保活及其他账号类型沿用原有行为。

  • 日志支持内容搜索及可选的正则表达式,可与日志级别组合筛选并复制匹配条目;筛选在可取消、带超时的后台任务中执行,日志读取在后台进行并限制等待时间,失败提示保留在日志弹框内。

  • 通用设置新增可选的 OLED 配色,深色模式使用纯黑背景,浅色模式使用白色背景;保留既有默认配色和其他主题。

  • Codex 会话用量新增按本地日期计算的“今天”范围及每日估算费用,沿用既有内置模型价格;包含未计价模型的日期明确显示无法估算,保留已保存范围及近七天默认值。

  • 额度悬浮窗新增极简额度样式和背景强度调节,与通用设置同步;文字保持清晰,默认保留原完整卡片及背景。

  • Codex 会话导入支持可选的项目路径映射,便于在电脑之间迁移聊天;更新执行目录及对应权限路径,保留消息原文,并在客户端支持时归入已有目标项目。不填写映射时保留原导入行为。

  • 启动页设置支持分别选择 Antigravity APP 和 Antigravity IDE。

安全性

  • 更新 TLS 与 QUIC 依赖,覆盖已公开的 OpenSSL 缓冲区安全、证书撤销解析和流重组内存耗尽问题。

修复

  • Codex API 网关在刷新或旧请求迟到完成时保留较新的凭据,刷新期间隔离被拒 Token,并保留仍有效的额度冷却。

  • Codex WebSocket 在激活阶段正确返回上游断链错误,客户端切换上下文窗口时重新建立响应链;Chat 兼容流区分完整结束与输出截断。

  • Codex 转发保留兼容供应商的推理状态和请求的搜索来源。

  • Codex 自动切号与额度预警按实际窗口时长匹配短周期及周额度阈值,支持周额度位于主窗口的仅周额度账号;忽略缺失窗口,未返回时长时沿用原字段映射。

  • API Key 转发补齐内置模型能力查询,避免 GPT-6.1 Sol 的 Responses Lite 请求丢失推理上下文而失败。

  • OAuth 账号缺少身份 Token 元数据时,写入客户端凭据仍可从访问 Token 补齐账号 ID;保留已有有效账号 ID,不影响独立访问 Token 登录。

  • API 服务在首个有效输出前识别明确的账号额度耗尽或停用错误,并在授权候选范围内尝试其他账号;已经产生有效输出的请求保持原有处理,避免重复执行。

  • WebSocket 客户端在等待上游首响时断开,会及时取消请求并释放账号并发槽位,避免静默上游继续占用资源。

  • 自动识别带自定义端口的 HTTPS 代理订阅链接,避免误判为普通代理信息而无法导入。

  • 自建代理组选择成员时保留展示不可用的订阅节点及原因,并提供单节点证书选项授权;明确授权后即可添加成员,弹框保持打开且保留已编辑内容。

  • Codex 同优先级可用账号在各 API Key 范围与模型内均匀轮询,账号临时退出或重新进入池时仍正确推进;不同 Key 和模型不再相互占用轮次,保留既有路由优先级。账号范围先于额度保留及备用选择生效,避免范围外账号阻止授权备用账号被选中,或造成误导性的范围错误提示。

  • Codex Token 在途刷新结束时保留较新的授权、账号编辑与额度数据;旧刷新响应与错误不再覆盖新凭据或误标新授权,已删除账号不会被刷新结果恢复。

  • 编辑供应商 API Key 时保留接入模式、模型设置及账号记录,并保持默认实例、多开实例、模型路由及 API 服务账号绑定有效;引用更新失败时保留原账号,支持重试。

  • 同一供应商下不同 API Key 分别保存模型目录、上下文设置与识图能力,保存一把 Key 不再覆盖其他 Key 的模型配置。

  • Codex 启动恢复设置在通用设置及 Codex 设置弹框中一致保存与回读,关闭后不再悄悄恢复为开启。

  • 混合模型路由恢复不再把 API 服务或供应商网关绑定当作 OAuth 账号,避免误报绑定账号不存在。

  • 供应商网关启动失败时保留原客户端配置,避免留下不可用的本地地址;停止网关时记录实例、端口及原因,便于排查连接失败,正常停止的网关不再计为异常。

  • Windows 默认 Codex 启动不再继承受管实例的配置目录与用户数据目录参数。

  • 账号暂时不可用时保留 API Key 声明的账号范围,包括部分账号缺失的情况;无法解析任何公开 Key 时保留上次网关配置和认证文件,避免写出不可用配置。

  • 账号卡片、启动预览和设置统一显示公开 API 服务状态;停用时确认端口释放,即使停止失败也尝试恢复客户端配置,失败在当前设置弹框内显示并可重试。

  • 复制 Codex 实例后使用副本自己的会话历史和本机项目映射,包含已提交的 SQLite WAL 数据、无目录项目及历史索引过期的旧副本;历史不完整时拒绝发布副本,复制在后台执行且不占住实例登记锁,取消后不登记实例。

  • macOS 关闭 Codex 时直接向选定实例请求退出,避免模拟按键权限报错及切换前台窗口,并保留该实例后台进程的清理。

  • CLI 刷新凭据兼容未返回 id_token 的响应,保留轮换后的 access_token 和 refresh_token;有旧身份信息时继续保留,桌面启动仍执行凭据预检。

  • 设置保存等待磁盘或配置锁时,已有配置仍可读取;保存失败保留上次成功设置,配置锁等待超时后可重试。

  • Codex OAuth 完成后保存授权前填写的密码、2FA 等账号信息;本地保存失败时保留弹框并支持重试,无需重复授权,也不清空已有信息。

  • Codex API 请求在 Rust 转发及 Chat 协议转换时保留客户端明确指定的并行工具设置;携带 Responses Lite 标记的请求继续遵守串行要求,Chat 请求未指定时保留 Lite 模型的默认串行行为。

  • 重启后保留已选择的 Antigravity 客户端和分组默认平台,避免安装探测或布局兼容处理改回 IDE。

  • Antigravity 自动切号沿用所选 APP / IDE 客户端,APP 使用与手动切号相同的系统凭据写入及启动流程。

  • macOS 会话同步、恢复等操作支持新版 ChatGPT / Codex 内置 CLI 路径,并保留旧版客户端兼容。

  • Codex 周配额及重置时间排序按实际配额窗口计算,支持仅有周额度的账号,并将缺失额度放在末尾。

  • Windows Claude 切号备份兼容源文件的 EFS 加密属性,避免因目标目录无法保留该属性而中断;文件内容及原文件保持不变。

  • Linux 托盘可见内容未变化时跳过菜单重建,减少 GNOME AppIndicator 重复更新;失败更新可重试。

  • Codex 启动预览在账号详情超过窗口可用高度时保留标题及启动按钮,正文在弹框内滚动;Token 到期展示区分请求授权与身份信息,不再仅因 id_token 到期显示授权危险状态,刷新说明明确 id_token 仅在上游返回时更新。

  • Codex 实例启动时保留与默认配置不同的独立 Skills、规则及 AGENTS.md 指令,避免被默认实例内容替换。

  • Claude Cookie 数据库存在待恢复 SQLite 日志时,通过临时副本读取,不修改原始配置;允许未登录时打开验证窗口。

  • 实例供应商网关和固定供应商路由遵守已配置的账号并发及等待限制,并发槽位保留至响应结束;按绑定账号与上游模型遵守供应商 Retry-After 暂停时间。

  • 将已明确撤销的 Codex access_token 标记为需要重新授权,停止在切号及配额请求中重复使用;获取新凭据后恢复。

  • 自动网关模型目录保留用户在「模型管理」中明确配置的模型,支持比内置清单更新的模型。

  • API 服务请求费用估算遵守用户明确编辑的长上下文价格,包括配置了 Priority 价格的模型上的 Standard、Flex 请求;未编辑及旧配置继续使用既有倍率。

  • 单账号刷新显示成功或具体失败原因,完成后恢复刷新按钮状态。

  • 补齐所有支持语言中的账号分组「全部」页签翻译。

  • 会话操作识别运行中的 Codex 默认桌面实例,不再要求受管实例目录参数。

Changelog (English)

[1.3.66] - 2026-10-07

Added

  • API Service request logs now include first-response timing and request details with account attempts and failure stages. Optional bounded client and upstream request snapshots are stored locally, disabled by default, and saved bodies can be cleared separately. Recording choices survive concurrent configuration saves and application restarts.

  • Codex Chat-compatible replies include web-search URL citations in streaming and non-streaming responses, using the standard Chat Completions citation format with text offsets that support multiple content parts and Unicode.

  • Voice proxying supports native Codex backend call and sideband routes, dictation transcription, and OpenAI-compatible audio endpoints. OAuth accounts use ChatGPT transcription with JSON/text output and matching content types; API-key providers forward transcription, translation, speech and supported streaming responses, preserving audio and language hints within the existing account scope. Mixed pools select API-key credentials for speech and translation without escaping OAuth bindings; late audio failures and retry pauses do not invalidate newer credentials.

  • Codex model management supports per-model reasoning defaults and JSON import/export of models, prices, aliases, and routing rules. Imports preview conflicts and explain missing, invalid or unsupported fields, preserving existing settings by default; account credentials and API keys are excluded, and imported prices update historical cost estimates in the background.

  • API Service account-pool failures show a copyable request ID and failure time for log lookup. Diagnostics remain separate for each API Key, model and request type, so unrelated successes or late results cannot hide a newer failure.

  • General Settings and the Codex settings dialog offer optional preservation of an already installed Codex Web GPT bridge during OAuth account switches. Only bridges verified against local integration records are kept; the option is off by default.

  • API Service account-pool diagnostics show the affected accounts and distinguish scope mismatches, unmapped credentials, bound accounts not loaded in the service, and bound accounts absent from the current request candidate pool. Clients also receive localized explanations of scope selection failures.

  • Account-pool diagnostics offer binding/configuration inspection and per-record clearing. Public API Keys open at their matching policy; image, internal and instance requests open the account page with guidance for the relevant settings. Clearing removes only the diagnostic record, preserving account authentication, quota and scheduler state; subsequent failures appear again.

  • Image forwarding offers an optional main model separate from the image tool model. Leaving it blank keeps gpt-5.5; the selected OAuth accounts must support image_generation on the chosen model.

  • Codex quota settings can select which OAuth plans receive scheduled platform and group refreshes. All plans remain selected by default; manual and current-account refreshes, token keep-alive, and other account types keep their existing behavior.

  • Logs support content search and optional regular expressions, combined with log levels and copying matched entries. Filtering runs in cancellable workers with a time limit; log reads run in the background with bounded waits, and errors stay visible in the log dialog.

  • General Settings offer an optional OLED palette with a pure-black background in dark mode and a white background in light mode; the existing default and other palettes remain available.

  • Codex session usage offers a local-calendar “Today” range and daily estimated costs using the existing built-in model prices. Days containing unpriced models are marked as unavailable; the saved range and seven-day default are preserved.

  • Floating quota windows offer a minimal quota view and adjustable background strength, shared with General Settings. Text stays clear; the existing full card and background remain the defaults.

  • Codex session imports offer optional project-path mappings for moving chats between computers. Mappings update execution directories and matching permission paths without changing message text, and assign chats to existing destination projects when supported by the client. Leaving mappings empty preserves the existing import behavior.

  • Startup page settings can select Antigravity APP and Antigravity IDE separately.

Security

  • Update TLS and QUIC dependencies to address published OpenSSL buffer-safety, certificate-revocation parsing and stream-reassembly memory exhaustion advisories.

Fixed

  • Codex API gateways preserve newer credentials when refreshes or older requests finish late, isolate rejected tokens during refresh, and retain active quota cooldowns.

  • Codex WebSocket requests report upstream disconnects during activation and start a new response chain when the client changes context windows. Chat-compatible streams distinguish complete EOF from truncated output.

  • Codex forwarding preserves compatible provider reasoning state and requested web-search sources.

  • Codex automatic account switching and quota alerts use actual window durations for short-cycle and weekly thresholds, including weekly-only accounts whose limit appears in the primary window. Missing windows are ignored; responses without a duration retain the existing field mapping.

  • API-key forwarding resolves all shipped model capabilities, preserving Responses Lite reasoning context for GPT-6.1 Sol.

  • OAuth credential projection falls back to the access-token account ID when identity metadata is missing, while preserving an explicit stored ID and personal-access-token authentication.

  • API Service recognizes explicit account-quota and deactivation errors before the first meaningful output and tries other authorized candidates. Requests that already produced meaningful output retain their existing handling to avoid repeated execution.

  • WebSocket clients disconnecting while waiting for the first upstream response now cancel the request and release account concurrency slots, preventing silent upstreams from retaining resources.

  • Automatically recognize HTTPS proxy subscription links with custom ports instead of rejecting them as ordinary proxy input.

  • Keep unavailable subscription nodes visible when choosing custom proxy-group members, with their reasons and explicit per-node certificate permission; approved nodes can then be added without closing the editor or losing the draft.

  • Rotate equally ranked, eligible Codex accounts evenly within each API Key scope and model, including when accounts temporarily leave or rejoin the pool. Different Keys and models no longer consume each other’s turns; existing routing priorities remain effective. Apply account scopes before quota reserves and backup selection so out-of-scope accounts do not block an authorized backup account or cause a misleading scope error.

  • Preserve newer authorization, account edits and quota data when an in-flight Codex token refresh completes. Stale refresh responses and errors no longer overwrite or invalidate newly authorized credentials, and deleted accounts remain deleted.

  • Editing a provider API key preserves its access mode, model settings and account records, and keeps default-instance, multi-instance, model-route and API-service account bindings valid. Failed reference updates retain the original account for retry.

  • Different API keys at the same provider keep separate model catalogs, context settings and image capabilities; saving one key no longer overwrites another key's model configuration.

  • Codex startup restoration settings save and reload consistently in General Settings and the Codex settings dialog; disabling restoration no longer silently returns to the enabled state.

  • Mixed-model recovery no longer treats API-service or provider-gateway bindings as OAuth accounts, avoiding spurious missing-account errors.

  • Failed provider gateway starts preserve the previous client configuration instead of leaving an unavailable local endpoint. Gateway stops record the instance, port and reason for connection troubleshooting; normally stopped gateways no longer count as failures.

  • Windows default Codex launches no longer inherit managed-instance profile directories or user-data arguments.

  • Keep declared API Key account scopes when an account is temporarily unavailable, including partially missing scopes. If no public Key can be resolved, preserve the last gateway configuration and authentication files instead of writing an unusable configuration.

  • Show consistent public API service status across account cards, launch previews and settings. Disabling confirms port release, attempts to restore client configuration even if stopping fails, and keeps failures visible and retryable in the active settings dialog.

  • Copied Codex instances use their own conversation history and local project mappings, including committed SQLite WAL data, folderless projects and legacy copies with outdated history indexes. Incomplete history is rejected before publishing the copy; copying runs in the background without blocking the instance registry, and cancelled attempts do not register an instance.

  • macOS Codex shutdown requests target the selected instance directly, avoiding keyboard-control permission errors and changes to the foreground window while preserving cleanup of its background processes.

  • CLI token refresh accepts responses that omit id_token, preserving rotated access_token and refresh_token credentials. Existing identity metadata is retained when available; desktop launch credential checks remain in place.

  • Keep existing settings readable while saves wait on disk or configuration locks; failed saves retain the last saved values and lock waits time out instead of waiting indefinitely.

  • Save account details entered before Codex OAuth completion, including passwords and 2FA secrets; local save failures keep the dialog open and can be retried without repeating authorization or clearing existing details.

  • Preserve explicit parallel-tool settings on Codex API requests in the Rust forwarding and Chat conversion paths; requests carrying the Responses Lite marker retain its serial-call requirement, and Chat requests without an explicit setting retain the Lite model's serial default.

  • Preserve the selected Antigravity client and group default across restarts instead of reverting to IDE during installation discovery or layout compatibility handling.

  • Antigravity automatic account switching follows the selected APP / IDE client; APP switching uses the same system-credential writes and launch flow as manual switching.

  • Session synchronization, restoration, and related operations on macOS recognize the updated CLI location bundled with ChatGPT / Codex while retaining compatibility with older clients.

  • Sort Codex weekly quotas and reset times by their actual quota windows, including accounts with weekly-only limits, and place missing quota data last.

  • Claude account-switch backups on Windows tolerate source-file EFS attributes when the destination cannot preserve them, keeping file content and the original file unchanged.

  • Skip Linux tray menu rebuilding when visible content is unchanged to reduce repeated GNOME AppIndicator updates; failed updates remain retryable.

  • Codex launch previews keep the title and launch actions visible when account details exceed the available window height, with scrolling inside the body. Token expiry previews distinguish request authorization from identity information instead of showing an authorization danger state solely for an expired id_token; refresh descriptions clarify that id_token updates only when returned upstream.

  • Preserve distinct Skills, rules and AGENTS.md instructions in Codex instances instead of replacing them with the default profile when starting the client.

  • Read Claude cookie databases with pending SQLite journals from a temporary snapshot without modifying the original profile; allow verification windows to open before login.

  • Apply configured per-account concurrency and wait limits to instance provider gateways and fixed provider routes, holding slots until responses finish. Honor upstream Retry-After pauses for the bound account and upstream model.

  • Mark explicitly revoked Codex access tokens as requiring authorization, stop reusing them for switching and quota requests, and clear that state when new credentials arrive.

  • Keep explicitly configured models from Model Management visible in the automatic gateway catalog, including models newer than the built-in list.

  • Honor explicitly edited long-context prices when estimating API Service request costs, including Standard and Flex requests on models with Priority prices. Unedited and legacy prices continue to follow the existing multipliers.

  • Show success or detailed failure feedback when refreshing a single account, and restore the refresh button after completion.

  • Localize the account-group All tab in every supported language.

  • Recognize running default Codex desktop instances during session operations without requiring managed-profile arguments.

Don't miss a new cockpit-tools release

NewReleases is sending notifications on new releases.