Outcome and scope
Add a read-only, exact per-machine Codex default-profile observation in Settings. The existing browser correctly uses generic High/Ultra labels because frozen device registry v1 carries only an alias. This increment fills that information gap without treating a daemon default as an existing session's model or as proof of provider capability.
Baseline: reviewed main 3da9744acad51faf898f4d35c78bbe5f5be5dd2e after PR141, retaining the delivered PR151 schema50 and PR157 release documentation. The task-owned branch is codex/profile-binding-observation-20260908.
Design and invariants
- Capture the default alias and its publishing binary's active exact canonical identity together. Never derive target identity from the browser's own alias mapping, a daemon-version string or an in-flight command.
- Publish a small separately encrypted versioned companion atomically with the existing registry. Bind it to the exact next registry revision, registry ciphertext digest and heartbeat. Keep every old registry-v1 key and byte contract unchanged.
- Add no SQLite migration, model, preset, Work route, provider capability or remote mutation authority. Keep Sol Ultra the implicit default. Preserve all historical Sol/Astra/retired-provider identities.
- Observe hosted support from an optional versioned field on the normal successful registry-publication response before sending a new optional argument. An old hosted server continues receiving the existing shape. Support/cache ownership and fresh publication must remain bound to the exact current device/user/key authority.
- Clear the companion on omission by an old publisher. Require daemon authority, same account key and bounded ciphertext. Reuse the existing row's quota/lifecycle ownership; no new table is introduced.
- Settings displays only the daemon's last reported default, with current/stale/unreadable/unsupported/inactive distinctions. Bind asynchronous cache entries to complete companion and registry identities. Keep selectors, grid creation, session cards and command builders unchanged.
Alternatives considered
A local-only command would avoid hosted coordination but would not resolve the remote Settings information gap. Changing strict registry v1 would break old clients. Reusing the independent memory-summary pipeline would permit lagging or retained identity to appear current. The bounded atomic companion supplies remote visibility while leaving all selection authority with its existing owner.
Acceptance and delivery
Add focused parser, crypto, bridge/publication, daemon-source, Convex quota/clear, app cache/freshness and Settings regressions. Cover legacy client/server combinations, Sol/Astra distinction, invalid alias/key, wrong authority/revision/ciphertext, stale/future time, revocation/key rotation, cancellation and old asynchronous completion. Prove unchanged command payloads and frozen registry-v1 fixtures. A current default must never relabel an established session.
Independent source/impact review and fresh exact-tree full repository plus compiled-browser gates remain required, followed by protected PR/main delivery. Hosted deployment, package publication and browser deployment have independent gates and evidence. Existing capacity/activation, intended-target, daemon startup and live qualification boundaries remain unchanged. This issue does not authorize bypassing any of them or replacing immutable v0.7.0 artifacts.
Outcome and scope
Add a read-only, exact per-machine Codex default-profile observation in Settings. The existing browser correctly uses generic High/Ultra labels because frozen device registry v1 carries only an alias. This increment fills that information gap without treating a daemon default as an existing session's model or as proof of provider capability.
Baseline: reviewed main
3da9744acad51faf898f4d35c78bbe5f5be5dd2eafter PR141, retaining the delivered PR151 schema50 and PR157 release documentation. The task-owned branch iscodex/profile-binding-observation-20260908.Design and invariants
Alternatives considered
A local-only command would avoid hosted coordination but would not resolve the remote Settings information gap. Changing strict registry v1 would break old clients. Reusing the independent memory-summary pipeline would permit lagging or retained identity to appear current. The bounded atomic companion supplies remote visibility while leaving all selection authority with its existing owner.
Acceptance and delivery
Add focused parser, crypto, bridge/publication, daemon-source, Convex quota/clear, app cache/freshness and Settings regressions. Cover legacy client/server combinations, Sol/Astra distinction, invalid alias/key, wrong authority/revision/ciphertext, stale/future time, revocation/key rotation, cancellation and old asynchronous completion. Prove unchanged command payloads and frozen registry-v1 fixtures. A current default must never relabel an established session.
Independent source/impact review and fresh exact-tree full repository plus compiled-browser gates remain required, followed by protected PR/main delivery. Hosted deployment, package publication and browser deployment have independent gates and evidence. Existing capacity/activation, intended-target, daemon startup and live qualification boundaries remain unchanged. This issue does not authorize bypassing any of them or replacing immutable v0.7.0 artifacts.