Maintenance study · 2 October 2026 · migration/workspace context retains 29 September checks
Distribute and maintain a plugin
“I changed my plugin; what actually changed for adopters?” A source edit establishes changed source bytes—not the loaded copy, public package or live backend.
Use the offline recorder to keep those claims apart, then collect the evidence for your release channel. A package can keep its version while instructions change; a backend can change while package bytes stay identical.
The explicitly chosen source inventories differ; the root version is read separately.
Next evidence: Retain selected scope, changed paths and hashes. Complete-package validity needs separate checks.
These are not loaded or published bytes.
No plugin installation, refresh or invocation was observed in a host. A declared loaded version is not an observation.
Next evidence: Record actual client/version, catalog root/ref, applicable update/restart steps, fresh-session provenance and behavior.
A source edit does not establish an adopter update.
No upload, review, approval, Publish or directory-version check occurred.
Next evidence: Observe the selected ZIP/version, checks and review, separate Publish action, then the actual listing/version.
Upload and approval do not establish publication.
No deployment, authorized endpoint call or scan was observed. Service-change facts are declarations.
Next evidence: Obtain deployment and behavior evidence, live/held definitions, scan/tool availability and current-contract/auth regressions.
The package version does not freeze backend code.
Our original evidence model, informed by Packaging and cached installs, Public submission and updates, MCP review and maintenance and Supported-client user guide. Consequential sections checked 2 Oct 2026; no substantive policy change established.
Start with the same-version trap
LABEL STAYS
0.1.0 → 0.1.0
plugin.json is byte-identical.
CONTENT CHANGES
2,603 → 2,677 bytes
Changed only skills/meeting-evidence/SKILL.md; no added or removed paths.
CHANGED_BYTES_SAME_VERSION
The chosen skill bytes changed; adopter delivery is not established.
Skill SHA-256 abd57a1e767a… → 8d4d784770db…. Loaded host, published package and live backend: UNKNOWN / NOT RUN. Full inventories, hashes and fingerprints are in the actual offline record.
The worked context declares an intended public release, so its recommendation follows the documented complete versioned-bundle process after manual version choice. A local/repo declaration instead calls for source/cache and fresh loaded evidence. Neither declaration performs an action or establishes eligibility.
Record a change without login
Download the release-change recorder · 2 October 2026
Tooling with synthetic fixtures—not a runtime submission ZIP or a new Meeting Evidence release. 98,674 bytes; 51 regular-file members. SHA-256: 6adef503a09ecc8cfb472d58722658d2703eb803d15c259d84ded04c097c64ff.
Requires Python 3.8+ on POSIX with no-follow support; tested on Python 3.11.2/Linux. Extract into scratch, enter change-record/, then:
python3 record.py --before fixtures/snapshots/baseline \
--after fixtures/snapshots/instruction-same-version \
--context fixtures/contexts/public.json --out my-change-record
python3 selftest.py
my-change-record must be a new directory with an existing parent. One output directory receives readable record.md and machine record.json. Repeat with a new output name. Exit 0 means a record was written—not a plugin was validated. Exit 2 is a recorder CLI/input/I/O/platform error, not an OpenAI rule violation.
Actual command/expectation log · Final engineering JSON · Worked record JSON · Blank next-evidence worksheet · Blank recorder context
Scope, engineering evidence and reading safeguards
The recorder hashes every regular file in explicitly selected intended-runtime snapshot directories, including hidden files. It never selects runtime scope from a whole repo, installs, connects, deploys, packages ZIPs or contacts a portal.
Portable root plugin.json identity/version reading is narrow, not full schema validation. Missing/malformed/unsupported interpretation remains UNKNOWN; compatibility-only layouts are not universally invalid. Effective extensions/overlays, components, semantics, secrets/safety and permissions are not evaluated.
Fingerprints include sorted paths, bytes and SHA-256s—not modes, mtimes, empty directories, input location or context. They identify selected snapshot bytes, not installed/public bytes or remote identity.
No-symlink/no-special-file/no-parent-traversal rules, finite file/depth/size limits and exclusive non-overwriting output are our recorder safeguards, not OpenAI requirements. Freeze snapshots; this is not an adversarial filesystem sandbox.
48 subprocess commands + one deterministic-byte invariant = 49 passed recorder-engineering assertions; zero failures. That is 21 synthetic scenarios, one repeat and 26 exact negative input/output-boundary commands. Expected diagnostics—not merely nonzero exits—were checked. The final download’s 50 provenance payload hashes and both documented commands were independently reproduced. These are not plugin, model, safety, propagation or acceptance rates.
The previous 1 October checker kit and ten NOT RUN host contracts retain their saved results and dates. No source/version/old ZIP was edited.
Pick the change; identify the next evidence
This is our maintenance aid, not an official form. Only selected byte differences are OBSERVED OFFLINE. Channel, listing history, endpoints, review/deploy labels and service changes are READER DECLARATIONS. Every actual host/public/backend test remains NOT RUN, with observed fields UNKNOWN. Documentary requirements and our next-evidence recommendations are separate.
Bundled instructions changed
- What the record can say
- Skill file bytes differ; version is read independently.
- Our next-evidence recommendation
- For a public bundle, choose the release version and prepare the complete updated package through its checks/review/Publish path. For local/repo use, establish the refreshed loaded copy and regress the changed instructions.
- Do not infer
- Changed bytes do not prove improved behavior, host compatibility or adopter delivery.
Documentary boundary: Packaging and cached installs; Public submission and updates. Checked 2 Oct 2026; not an acceptance result.
Metadata, icon or resource changed
- What the record can say
- Manifest or asset paths differ; file groups are inventory aids only.
- Our next-evidence recommendation
- Check actual references/host compatibility, full package contents and the intended channel’s release evidence. Public bundled metadata/assets use a versioned ZIP update.
- Do not infer
- An asset hash is not valid-icon, component, capability or eligibility evidence.
Documentary boundary: Public submission and updates. Checked 2 Oct 2026; not an acceptance result.
Version-only edit—or payload change with the same version
- What the record can say
- A version-only label requires only plugin.json to have changed, known versions to differ, and parsed root objects to be equal after removing version; serialization may differ. Payload/version changes are recorded independently.
- Our next-evidence recommendation
- Explain the release label versus content provenance; select patch/minor/major yourself. Observe actual loaded/public versions separately.
- Do not infer
- Equal version strings need not mean equal bytes; a version bump does not prove rollout.
Documentary boundary: Portable manifest schema; Public submission and updates. Checked 2 Oct 2026; not an acceptance result.
Local/repo source edited; loaded copy unobserved
- What the record can say
- The selected source fingerprint changes. Loaded source/version remain UNKNOWN.
- Our next-evidence recommendation
- Identify the exact client and catalog/root/ref. Use the applicable documented source refresh, restart, install/new-session procedure; preserve reliable loaded provenance or explain UNKNOWN.
- Do not infer
- Configured catalog roots, refresh commands or a fresh session alone do not prove which bytes loaded.
Documentary boundary: Packaging and cached installs; Supported-client user guide. Checked 2 Oct 2026; not an acceptance result.
New public ZIP or pending review; listing unobserved
- What the record can say
- Any upload/review/approval status in context is a reader declaration. No portal operation ran.
- Our next-evidence recommendation
- Observe selected ZIP/version/checks, review/approval, the distinct Publish event and actual directory entry/version. Publish replacement is documented.
- Do not infer
- Old-package availability throughout every pending/rejected review and continuous adopter access are not established.
Documentary boundary: Public submission and updates. Checked 2 Oct 2026; not an acceptance result.
Live implementation changed; package stayed identical
- What the record can say
- Identical source inventories plus a declared backend change—not a detected deployment.
- Our next-evidence recommendation
- Obtain an authorized deployment record and actual result/current-contract regressions. Reviewed definitions and server implementation need separate records.
- Do not infer
- Held metadata does not shelter users from deployed code; unchanged package/version need not mean unchanged results.
Documentary boundary: MCP review and maintenance. Checked 2 Oct 2026; not an acceptance result.
Tool contract, additions/removals or permissions changed
- What the record can say
- Tool/auth/permission changes are declared facts, never conclusions from source hashes.
- Our next-evidence recommendation
- Observe live versus held definitions, completed scans, tool availability and current schema/auth/permission behavior under authorized conditions.
- Do not infer
- Do not infer joint approval, granted provider access, successful scans or safety.
Documentary boundary: Public submission and updates; MCP review and maintenance. Checked 2 Oct 2026; not an acceptance result.
Endpoint path or origin moved
- What the record can say
- URLs and movement category are declarations. Documentary requirements conflict.
- Our next-evidence recommendation
- Preserve production endpoint; obtain identity-specific portal/support clarification before movement and authorized migration evidence if permitted.
- Do not infer
- The recorder does not decide which conflicting update rule controls or promise rollback/continuity.
Documentary boundary: Public submission and updates; MCP review and maintenance. Checked 2 Oct 2026; not an acceptance result.
MCP proposed for an existing skills-only public listing
- What the record can say
- Existing component history and proposal are declarations; filenames cannot establish them.
- Our next-evidence recommendation
- Resolve a supported identity/release roadmap before promising a connected public upgrade. The inspected submission path does not support this addition.
- Do not infer
- Local authoring or a file named mcp.json is not public-upgrade eligibility.
Documentary boundary: Public submission and updates. Checked 2 Oct 2026; not an acceptance result.
Public package and live service are different releases
Documented: bundled skills/metadata/assets updates use a complete updated-version ZIP with retained components, version-specific checks, applicable review and chosen Publish. Publish replaces the package version; the inspected text does not guarantee old-package availability through every pending/rejected review. Our recommendation is to observe the actual listing/version and adopter access separately. Public submission and updates. Checked 2 Oct 2026.
Documented: hosted tool definitions have independent daily/manual scans and live/held statuses. Calls still reach live server implementation; retaining reviewed metadata does not retain a copy of backend code. Preserve the current contract and observe deployment, definitions and behavior independently. Server rollback advice is not a portal/adopter rollback guarantee. Public submission and updates; MCP review and maintenance. Checked 2 Oct 2026.
Make the next observation, not the next assumption
Documented inspection handles · 7 October 2026: for a configured-marketplace plugin in Codex CLI, inspect marketplace/source and installed/enabled state, then the relevant skill or current-session MCP branch. Commands are reader checks, not runs observed here. Installed version labels and selected/callable capability still do not prove loaded bytes, authorization or useful output; missing provenance remains UNKNOWN. This qualification does not revise the 2 October fetched user-guide limit or establish a universal cache path or repair. Developer commands · codex plugin / marketplace / /skills / /mcp.
- Host/session: record actual client/version/surface, catalog root/ref, exact refresh/restart/install steps and fresh-session provenance. The user guide fetched on 2 October 2026 lacked an explicit loaded-version inspection method; that does not establish that every host lacks one. If loaded provenance is unavailable, keep UNKNOWN. Supported-client user guide; Packaging and cached installs.
- Public package: retain actual selected ZIP/version/checks, observed review/approval, separate Publish evidence and directory version. Do not fill these from intentions or context declarations.
- Remote service: obtain authorized deployment/endpoint behavior, live versus held contract, scan completion, tool availability and auth/permission regressions.
Download the blank next-evidence worksheet
Our manual companion—not valid recorder context, a portal form or a replacement for the ten prior host cases. Fill actual evidence only after performing it. All three platform states in this study remain UNKNOWN / NOT RUN.
Three channels to compare
Channel scope · 6 October: a supported local artifact is not automatically eligible public input. Check the hook/registered-MCP-mapping ZIP exclusion before reuse. Reader-declared public channel and recorder success never validate eligibility; the recorder/endpoint study retains 2 October.
- Local / repository catalog
- A catalog points to the source package for development or team use. Preserve existing catalogs; version source changes, follow restart/new-session guidance and retest. It is not universal public publication.
- Authorized workspace import / sharing
- Admin/role controls, repository access and service connections remain separate. Sharing does not automatically install or grant provider access. Imported raw MCP configurations remain Desktop-only even for HTTPS.
- Universal public directory
- A complete reviewed release reaches the explicit Publish stage. Exact-name/direct-link availability is distinct from enhanced distribution, which is discretionary and not requestable.
Package your plugin, Workspace plugin management, MCP review and distribution. Checked 29 Sep 2026.
Custom GPT migration as an access-continuity task
- Confirm scope. Establish the affected Enterprise workspace, creator/admin role and intended users; do not infer an all-plan deadline.
- Inventory what translates. Track instructions/reference material separately from custom actions and model choice; rebuild the actions rather than assuming transfer.
- Retest the route. Verify behavior, sharing, installation and provider access for the actual intended users.
- Plan maintenance. Preserve the new source/version and unresolved access conditions before declaring continuity.
This is a planning checklist, not an executed migration or a new migration service. The saved source provides no calendar transition deadline.
Custom GPT migration guidance. Checked 29 Sep 2026.
Next: check the commercial constraints → · Retest each changed boundary