M3 is based on the idea that shared immutable structure and indexed metadata can provide a basis for reusable computation. The programme starts with M3 String, regex, and precompute in M3JDK21, then collections and SWT/Eclipse integration.
This CodexPro fork is a supporting local tooling surface for repository inspection and repeatable development workflows. Its tool and access contracts remain separate from M3JDK21 runtime ownership.
Explore the idea: M3 technical design paper · Programme goals and roadmap. The paper explains the proposed architecture, cost tradeoffs, and evaluation plan. Readers are invited to examine the work and contribute representative workloads.
This section describes the direction of the hsoliwal fork. Upstream documentation follows below; upstream authorship, licenses, and project identity remain intact.
Give ChatGPT local coding tools for repos you explicitly allow.
CodexPro is a local MCP server. It connects your ChatGPT session to your machine and repos you allow.
ChatGPT can read, search, edit, review, verify, import attachments, and write handoff plans. It stays inside those roots.
It is not a hosted SaaS product, model proxy, quota bypass, account pool, or remote shell service.
Needs:
- Node.js 20+
- A ChatGPT account that can create custom MCP plugins
- An HTTPS URL to your machine for ChatGPT web (tunnel or Tailscale Funnel)
npm install -g codexpro
cd /path/to/your/repo
codexpro setupSettings -> Security and login→ turn Developer mode on (keep CSP enforcement on).Settings -> Plugins→ Plugins tab → + beside Search plugins.- Create a plugin named
CodexPro. - Connection: Server URL → paste the URL CodexPro copied.
- Authentication: No Authentication / None (change this if the form defaults to OAuth).
CodexPro auth is the token already in that URL. Do not share the URL.
Open Plugins and click + |
Complete the New Plugin form |
|---|---|
![]() |
![]() |
Daily use from the same repo:
codexpro startIf plugin creation fails, run codexpro connection-test and check whether ChatGPT requests reach the local server.
With workspace write mode (the normal agent setup):
- read, search, and inspect the repo with bounded code intelligence
- edit with
write,edit, or guardedapply_patch - import ChatGPT attachments with
import_file - run allowlisted checks with
bash - review diffs and likely impact with
show_changes - write plans under
.ai-bridge - export a context bundle for chats that cannot call tools
CodexPro does more than raw file search:
inspect_workspacemaps languages, project types, entrypoints, areas, symbols, and internal relationships.searchsupports targetedsymbol,references, andimpactintents as well as ordinary text and regex search.show_changesidentifies affected areas, likely dependents, related tests, risk signals, and relevant verification commands.- TypeScript/JavaScript, Python, Go, Rust, Swift, Java, C#, C, and C++ declarations are recognized. Other languages retain safe inventory and lexical search.
Analysis is local, bounded, and cached by a workspace fingerprint. It needs no model API key, language-server daemon, embedding service, or vector database. Coverage and inference strength are reported instead of presented as certainty.
CodexPro is optimized for a narrow loop: connect ChatGPT to explicitly allowed local repositories, make a reviewable change, verify it, and preserve a handoff record. The project prioritizes:
- explicit workspace boundaries and separate controls for reads, writes, commands, sessions, and handoffs
- useful code navigation without sending a repository to a separate indexing service
- cross-platform installation and release checks on supported Node.js versions
- compact, bounded tool results that remain usable in long ChatGPT sessions
See the roadmap for the next reliability, code-navigation, and workflow improvements.
One CodexPro process can allow more than one repo:
codexpro settings set --project ~/code/web --project ~/code/api
codexpro settings show
codexpro startAsk ChatGPT to open_workspace on an allowed project. open_current_workspace returns to the launch repo.
For two ChatGPT accounts or hard isolation, run two CodexPro processes on different ports and Server URLs.
codexpro setup
codexpro start
codexpro start --root /path/to/repo
codexpro doctor
codexpro connection-test
codexpro settings
codexpro inspect
codexpro reviewUseful modes:
codexpro start --no-bash
codexpro start --tool-mode minimal
codexpro start --tool-mode full
codexpro start --mode handoff
codexpro start --mode pro
codexpro start --headlessOpt-in tool cards:
CODEXPRO_TOOL_CARDS=1 codexpro startChatGPT web needs HTTPS:
codexpro start --tunnel cloudflare # quick demo URL (changes)
codexpro ngrok --hostname your.ngrok-free.dev
codexpro stable --hostname codexpro.example.com --tunnel-name codexpro
codexpro tailscale --hostname your-device.your-tailnet.ts.net
codexpro start --tunnel none # local onlyKeep a stable token for stable hostnames:
mkdir -p ~/.codexpro
openssl rand -hex 32 > ~/.codexpro/http-token
chmod 600 ~/.codexpro/http-tokenPrefer Authorization: Bearer <token> when the client supports headers. The ?codexpro_token= query form is a personal compatibility fallback.
- Public tunnels require a CodexPro HTTP token (min 24 bytes)
- Writes stay hidden unless write mode is
workspace - Safe bash is the default
- Blocked paths cover
.env, keys,.git, build caches, and similar - Attachment import only accepts ChatGPT Apps SDK file objects from approved HTTPS hosts
Read SECURITY.md before exposing a tunnel.
npm install -g codexpro@latest
codexpro --versionRestart codexpro start after updating. Saved profiles under ~/.codexpro stay in place.
CodexPro's TypeScript runtime requires Node.js 20 or newer. Building the optional Camel/KIE CPU-DAG sidecar also requires Java 17 and Maven.
npm install
npm run build
npm run build:camel
npm run smoke
npm run stress
npm run package:smoke
npm run release:checkThe fabric MCP tool exposes ten bounded actions:
invariantsreturns the recursive fleet contract.dag_contractreturns registered capabilities, policy root, and hard limits.dag_executeadmits a JSON plan through Drools, executes its fixed capability with a bounded Camel SEDA route, performs stable fan-in, and returns a SHA-256-bound receipt.chrome_contractreturns the fixed local-inference trust boundary.chrome_statusverifies the loopback Chrome2api service and required model.chrome_completeexecutes one bounded text-only request through ChromeML and returns request, response, and terminal receipt roots.chrome_summarizer_contractreturns the Chrome Summarizer-compatible option and lifecycle contract.chrome_summarizeexecutes a bounded local summary across every documented type, format, length, and preference mode.chrome_summarize_documentreads one workspace-confined UTF-8 document, creates exact byte-range chunks, maps them locally, performs a bounded summary-of-summaries reduction, and returns a candidate-only receipt.chrome_summarize_corpusresolves one safe top-level workspace glob, content-deduplicates at most 64 documents / 8 MB, summarizes each unique source once, and returns per-path alias receipts. Unchanged requests reuse a bounded process-local summary cache.
The planner is never the router. A model may propose only data; it cannot supply Camel endpoint URIs, shell commands, executables, or credentials. See the CPU-DAG contract and fleet invariants. The optional Chrome2api provider is loopback-only and never forwards authorization, cookies, browser state, local file paths, or media.
Publish only from the CodexPro root:
cd /path/to/codexpro
npm run release:publish
