# ConnectOnion 1.9.2b7 (beta)

## Install this preview

Stable remains 1.9.1. Install this opt-in beta by exact pin:

```bash
python -m pip install --upgrade 'connectonion==1.9.2b7'
```

## A first run that does not trip over itself

These fixes come from a real `co rem init` of 1.9.2b3 installed from PyPI:
180 days of Gmail and Outlook, 312 pages, Codex with 16 workers. All 312
pages were written. Its run records and all 637 Codex turns were then read
back one by one.

- **Another `co` command no longer fails the run.** 14 investigations failed
  within the same two minutes with "The selected credential record changed".
  A `co` command in another terminal had refreshed the Microsoft sign-in, and
  Microsoft issues a new refresh token every time. Each process remembered only
  the rotations it made itself. Rotations are now recorded next to the env file
  as token digests (the tokens themselves are never stored), so every `co`
  process recognises them. A sign-in for a different account written over the
  record is still refused.
- **A new notebook runs on Codex.** With both coding agents signed in, a fresh
  install picked the other runner. It then announced about 460M input tokens
  on a plan the user had not chosen. Codex with gpt-6-luna is now the default.
  The other runner is used only when Codex is not installed or not signed in.
  A notebook keeps the runner saved in its `config.yaml`.
- **Turns stop looking for a file the package does not ship.** Each REM Skill
  named the document explaining its rules. Codex loads a Skill exactly as
  written, so 127 of 637 turns went looking for that document. The documents
  now name their Skill, and the Skills no longer name the documents.
- **A run record names its Codex threads.** Every turn of an investigation,
  including each round, the search follow-up and the editing turn, is listed
  under `threads`. A page now leads straight to the transcripts that wrote it.
  Before this, about two thirds of runs could not be matched to their traces
  by timestamps alone.

## Checking a run after it finishes

`scripts/rem_trial_audit.py NOTEBOOK` reads what a run left behind and exits 1
when it finds something severe:

- a page citing REM's own session as the user's words;
- a refused page missing from the refusal ledger;
- a background job macOS never started.

It also reports the following:

- where investigation turns read outside the material they were given;
- MCP, web and sub-agent calls;
- refused Outlook searches and missing files;
- page problems: citations with no source, gaps in source numbering, more than
  five Uncertainties, Also known as holding only addresses, and organisations
  titled by their domain.

Reading outside the material is measured, not treated as a failure.
Investigations keep full disk access by choice. `--strict-reads` makes it
severe.

On the 1.9.2b3 notebook, the script found what had been found by reading the
logs by hand:

- the owner page citing REM's own model check;
- 3 refusals missing from the ledger;
- 44 turns with a refused Outlook search.

## Verification and limits

- Every fix has a regression test that fails before the fix. The co rem unit
  suite passed.
- The real run that found these used 1.9.2b3. These fixes have not had their
  own real run yet.
- The run took 259 minutes on a machine that was busy with other work
  throughout, against 122 minutes on a quiet one the day before. Duration
  here is not a measure of this release.
- **Open, in issue 2349:**
  - The first page of your own takes about 15 minutes, not the 4 the help
    promises.
  - Some Open threads are months old with no sign they still matter.
  - Two project pages cite a source they do not list.
