mirror of
https://github.com/stablyai/orca.git
synced 2026-10-01 16:02:03 +00:00
Some config.toml settings name a location inside CODEX_HOME itself. A bundled marketplace only loads when its source sits inside the *active* home, so mirroring the value verbatim leaves the runtime copy pointing at the standalone home and Codex silently drops the plugin — ten effective plugins where the standalone home has eleven. The existing rewrite could not fix this because it does the opposite job: it anchors *relative* values to the source home so user-owned assets stay reachable after the TOML moves, and it deliberately skips absolute and tilde-prefixed values. Adding these keys to that allowlist would have cemented the bug. They need their own class, named for the distinction so the next reader does not reach for the anchoring set. Only values that genuinely live under the source home are moved; a path pointing anywhere else is the user's own and is left exactly as written. Deliberately narrow: marketplace sources and an MCP server's CODEX_HOME are unambiguous. The node_repl NODE_REPL_TRUSTED_* values named in the report are trust boundaries, and silently re-pointing what a tool trusts is not a change to make without a decision. Reported in #18682.