Commit Graph

10689 Commits

Author SHA1 Message Date
Abhinav
16537b20a5 Use captured step settings for request metadata and tool hooks (#45248)
## Why

Model and reasoning effort updates during a turn can leave request metadata and tool hooks reporting the turn's initial settings. Metadata should describe the step that issued the request or tool call.

## What changed

- Share captured execution metadata across Responses, MCP, and extension tool calls, including model, reasoning effort, and automatic review and Node REPL flags.
- Build Responses tool inventory metadata from the issuing step's finalized tool router. Attach the finalized inventory separately for remote compaction.
- Use captured step settings for pre- and post-tool hooks, and captured review settings for permission-request hooks.

## Testing

Add and extend regression tests for model and effort changes during a turn, MCP metadata, pre-tool hook model attribution, captured review flags, and tool inventory matching the issuing request.

GitOrigin-RevId: 9dee46a8b4839de8b434cdad4ed441cc0bb6ff9b
2026-09-13 15:47:59 +00:00
chess
36f0dbe796 Register Windows desktop uninstall ownership before sandbox setup (#45224)
## Why

Desktop uninstall cleanup needs an installation owner even when the user has not signed in or configured the Windows sandbox. Recording ownership only during provisioning leaves those installations unregistered.

## What changed

- Add an authenticated installation registration request and attempt it during Windows desktop stdio initialization, with a five-second timeout before the initialization response.
- Persist ownership independently of provisioning, preserve existing desktop ownership, and prevent another user or home from replacing the registered owner.
- Validate write authority and retain directory handles and guards to protect the registered home against junction conversion through privileged cleanup.
- Preserve existing CLI homes during desktop uninstall while removing their `CodexSandboxUsers` ACL entries. Report ACL revocation errors and avoid propagating unchanged ACLs.
- Grant the owner `WRITE_DAC` on `.sandbox-bin` and allow elevated-helper fallback when older permissions need repair or the service cannot establish an uninstall watcher.

## Testing

Add tests for installation registration without sandbox settings and for preserving a child's null DACL when revoking an absent SID from its parent.

GitOrigin-RevId: fb48923e9d76758d1bf5b50c7305aa60f91629db
2026-09-13 13:06:40 +00:00
ningyi-oai
1715e55076 Bind direct tool-call metadata to invocation outputs (#45185)
## Why

Direct tool-call records need to stay associated with the invocation that produced each output, including when call IDs are reused. Completeness must describe the recorded call inventory, independently of tool success.

## What changed

- Attach direct-call records to outputs before they enter history, and set `tool_calls_complete` when the invocation's arguments are fully recorded.
- Bound pending recordings and retained metadata, release reservations on completion or cancellation, and invalidate pending records when capture is disabled.
- Apply request budgets to direct metadata and strip it from inference and compaction inputs when capture is disabled.
- Remove executed-call metadata from app-server raw response notifications and exclude its size from Guardian history retention budgets.
- Track call IDs that bypass dispatch so their reuse cannot incorrectly establish Code Mode completeness.

## Testing

Add regression coverage for direct-call attribution, malformed calls, metadata budgets, cancellation, configuration changes, compaction, notification filtering, and Guardian context isolation.

GitOrigin-RevId: 2ebd39c7f141d04788736491495109841656b4c0
2026-09-13 06:53:20 +00:00
zm-oai
e61f381900 Validate Windows sandbox token groups before copying SIDs (#45182)
## Why

Logon SID lookup previously walked token group entries and SID pointers without checking that they fit within the returned buffer.

## What changed

Add a shared `token_groups` helper with a caller-supplied size limit. Validate the group layout, SID bounds, revision, and length before copying SIDs into owned `TokenGroup` values, preserving group order, duplicates, and attributes. Use this helper for logon SID lookup.

## Testing

Add Windows tests for owned SID storage, preserved order and attributes, truncated layouts, malformed and out-of-buffer SIDs, query size limits, and current-token logon SID lookup.

GitOrigin-RevId: f51ff6aa5266b6c73fe07968015e462c888a95e4
2026-09-13 06:43:42 +00:00
Sean Huang
cfde11a24c Extract shared network configuration and environment policy helpers (#45180)
## What changed

- Introduce `PreparedNetworkConfig` to separate proxy preparation from applying managed network requirements, preserving preparation before permission fallback in local configuration loading.
- Add helpers to build portable environment policies, retain selected or managed policies even when the proxy is disabled, and validate policies against the final permission profile using the execution resolver.
- Strip listener addresses from environment network configuration and reject unsupported settings, malformed domain patterns, and invalid Unix socket paths.
- Expose supporting managed-feature and permission-profile configuration helpers.

## Testing

Add coverage for policy retention, listener removal, unsupported and malformed policies, and validation against permission profiles. Strengthen configuration tests to compare rebuilt proxy specifications and verify proxy configuration survives permission fallback.

GitOrigin-RevId: 444bf02d8543eaebdbd2ebc14b56d92ce6d2ad2f
2026-09-13 06:29:49 +00:00
zm-oai
a4c61afff2 Split Windows sandbox cleanup into preparation and completion phases (#45178)
## What changed

Expose `prepare_packaged_windows_sandbox_cleanup` to disable sandbox accounts and stop their processes before returning a `PreparedWindowsSandboxCleanup` guard that retains the setup lock. Its `finish` method removes resources and protections; dropping it only releases the lock, leaving accounts disabled and protections intact.

Keep `clean_up_packaged_windows_sandbox` as a wrapper around both phases, and extract the service's existing package cleanup logic into a dedicated module.

GitOrigin-RevId: a32663171bce027f771f738d71b0c46404edbedc
2026-09-13 06:15:35 +00:00
iceweasel-oai
c379459bba Wire the Windows MXC sandbox into command execution (#45176)
## What changed

- Add explicit MXC backend selection and carry its identity through exec-server process reporting and sandbox violation classification.
- Launch MXC through the Codex executable with the effective permission profile and command environment.
- Reject exec-server MXC requests when native MXC is unavailable or when they request a TTY, an `arg0` override, or managed networking. Reject private desktop isolation during MXC preparation.
- Allow an explicitly empty child environment and avoid exposing request payload values in launcher decode errors.

## Testing

Add coverage for sandbox selection and unsupported-request rejection, plus Windows RPC tests for stdin writes and temporary-directory permissions derived from the command environment. Native MXC tests skip when MXC is unavailable.

GitOrigin-RevId: 3626ff0f9ad7f9b812ce09b68c31ea9a5a9c72b1
2026-09-13 06:07:03 +00:00
zm-oai
dfaf451426 Extract Windows sandbox setup and installation storage into the library (#45169)
## What changed

- Move the setup helper implementation and its existing tests into `codex-windows-sandbox`, with the binary delegating to `setup_helper_main`.
- Expose installation record types and storage operations from the library, preserving the registry key, size limit, and serialization format. Reuse them in the service and remove its direct `serde` dependencies.
- Extract service provisioning from IPC handling into a dedicated module, preserving authentication and machine-policy checks before provisioning and retaining directory handles through helper execution.

GitOrigin-RevId: dd1ea015aff901d5dfe39b395de1971ee0f2d33f
2026-09-13 04:59:49 +00:00
zm-oai
a592c38c16 Use OpenSSL 3.6.4 for musl builds (#45149)
## Why

The latest `openssl-src` 300.x crate still bundles OpenSSL 3.6.3. Build the 3.6.4 security release directly while preserving the existing 3.x ABI.

## What changed

- Build static OpenSSL libraries with the musl compiler for `x86_64` and `aarch64`, verifying the source archive's SHA-256 checksum.
- Set target-specific OpenSSL overrides to bypass vendored builds without affecting host build dependencies.
- Add `perl` and `make` to the musl build prerequisites and reuse completed OpenSSL installations.

GitOrigin-RevId: 4276c7d6cf30c31c8554246cea2f406dfbf7568b
2026-09-13 01:19:53 +00:00
Felipe Coury
7efa9d96fb Remove Astra sparkle animation from the TUI composer (#45137)
## What changed

Remove the animated stars shown when selecting Astra, along with their input, terminal-focus, and model-selection hooks.

## Testing

Retain draft text and live voice control snapshots in a standalone composer snapshot test, and remove sparkle-specific tests and snapshots.

GitOrigin-RevId: cbe4396e8700cabfb1e0db9fbe8f997b94316c0f
2026-09-13 00:01:05 +00:00
Eric Traut
b966240bea Preview streaming prose before a newline arrives in the TUI (#45135)
## Why

Unterminated prose stayed hidden until a newline arrived or the stream completed, leaving long single-line responses invisible while they streamed.

## What changed

- Show live prose previews for agent messages and proposed plans, requesting redraws when the preview changes.
- Keep previews out of the scrollback queue and render the full source on newline or completion without duplicating text.
- Bound previews to the most recent 8 KiB at a Unicode character boundary, with an ellipsis for omitted text, and reflow them when the width changes.
- Preserve holdback for incomplete table and code structures, retaining the last safe prose preview when a pipe arrives.

## Testing

Add controller tests and TUI snapshots covering visibility before completion, resize reflow, finalization without duplication, long Unicode previews, table and code holdback, and inline visualization context.

GitOrigin-RevId: 26c83c218b986625820b20779a46d1b800a7e0ff
2026-09-12 23:54:20 +00:00
alishobeiri-oai
b979d4f1f0 Add a feature flag for asynchronous user messages (#45124)
## What changed

Add the disabled-by-default `send_message_to_user_async` feature flag so root agents can use the tool without model catalog support. Preserve catalog-based opt-in and keep the tool unavailable to subagents. Register the flag as under development and expose it in the configuration schema.

## Testing

Extend integration tests to cover feature and catalog opt-ins, deduplication when both are enabled, subagent exclusion, and the retired `send_async_message` flag. Check that either opt-in allows messages to be emitted without ending the turn.

GitOrigin-RevId: 3f53181ab074b0432c795550de73a9b1da7caf15
2026-09-12 22:28:41 +00:00
Eric Traut
70eb36203d Prevent multiline report notes from submitting early (#45116)
## Why

Unbracketed multiline pastes could submit the report form at the first newline, before the full note was entered.

## What changed

Use `PasteBurst` in the report note editor to insert newlines during rapid paste input and allow `Enter` to submit after the burst ends. Extend the burst window across newlines and tabs, and clear burst state after explicit pastes or other editing input.

## Testing

Add regression tests for multiline paste bursts with short first lines, blank lines, and tabs, verifying the complete submitted note with and without logs. Add a multiline rendering snapshot and a test that bracketed paste stays in the report form, leaves the chat composer empty, and allows immediate submission.

GitOrigin-RevId: a76e680a01767c619a4fcc150d1dcad537e67194
2026-09-12 21:35:33 +00:00
Adam Perry @ OpenAI
a7475e74aa Use blueberry in the realtime background-agent test fixture (#45112)
Update the mock user transcript, assistant response, and expected delegation
transcript in `websocket_v2_background_agent_returns_function_output` to use
`blueberry` instead of `strawberry`.

GitOrigin-RevId: a2c6209d2565529d63c7a45a65d1162ee1f60425
2026-09-12 21:14:07 +00:00
Felipe Coury
b4c864dd64 Cancel pending thread title generation after manual renames (#45108)
## Why

Saving a manual thread name leaves pending title generation running and its progress indicator visible until the request finishes.

## What changed

- Cancel pending title requests after a successful manual rename, including renames from the agents overview, and clear the progress indicator immediately.
- Interrupt canceled title-generation turns and unsubscribe their temporary threads. Ignore late start and completion events so canceled requests cannot affect newer requests.
- Cancel pending title requests when resetting connection state.
- Show only a spinner when generating a title without an existing name, removing the `renaming...` placeholder.

## Testing

Add regression tests for manual and overview renames that verify turn interruption, cleanup, and preservation of the saved name. Cover late events after cancellation and update footer and terminal-title snapshots for the spinner-only display.

GitOrigin-RevId: f9490ea7be9968ea6c35d80bfbac06fee57d0135
2026-09-12 20:22:47 +00:00
Won Park
b04a2c2645 Estimate history tokens from content instead of serialized envelopes (#45094)
## Why

Serialized response items include message IDs, metadata, and JSON escaping that inflate token estimates without adding model-visible content.

## What changed

- Estimate each response item from its content, retaining JSON syntax for structured tool payloads.
- Apply image estimates to all image inputs, including non-base64 URLs, and count audio and encrypted content through their modality-specific estimates.
- Exclude plaintext reasoning and bookkeeping-only items from replay accounting.

## Testing

Update unit expectations for text, images, audio, and encrypted content. Add a remote compaction regression test showing that equal-length text produces identical token usage estimates despite different message IDs, metadata, and JSON escaping, while preserving the submitted messages.

GitOrigin-RevId: 1c43d5abbcc1668b4ab413901a2b4b6511ca5892
2026-09-12 18:41:47 +00:00
Felipe Coury
8d3c6cc13d Preserve conversation context and separate next actions in recaps (#45090)
## Why

The 900-byte recap prompt limit leaves little room for completed progress, unresolved caveats, and recent corrections. Recaps need this context to distinguish completed work from pending requests.

## What changed

- Introduce a shared `RecapPrompt` with a 32 KiB ceiling for instructions and history, using an 8,192-token estimate. Instruct summaries to retain the broader goal, completed outcomes, and unresolved availability or validation caveats.
- Select up to eight answered exchanges plus a pending request, preserving adjacent steering and progress messages. Drop older whole exchanges before excerpting both ends of oversized messages, while retaining the newest answer and pending correction.
- Require a `summary` and nullable `next_action`, bounded to 700 and 200 characters respectively. Reject malformed or oversized responses and display an optional, separately styled `Next:` line.

## Testing

Add coverage for UTF-8 prompt bounds, exchange selection, pending corrections, excerpt boundaries, strict response parsing, and next-action rendering. Extend the recap generation integration test to verify bounded history and the structured response schema.

GitOrigin-RevId: 6c6a84bc602a168418c1952feb1d286ec0cb9e28
2026-09-12 18:16:17 +00:00
Felipe Coury
f16c2237a5 Delay automatic recaps and compact their TUI layout (#45089)
## What changed

- Increase the automatic recap delay from 3 to 30 minutes.
- Replace the recap heading and divider with an italic `↳ Recap:` layout, hanging indentation, and right padding. Preserve explicit line breaks and Unicode, splitting URLs only when they exceed the available text column.
- Use Tokio's clock for automatic recap eligibility and create the timer before spawning its task.
- Remove the `token_budget.use_history_notes_extension` override from temporary structured requests.

## Testing

Add coverage for the 30-minute deadline, recap styling, narrow terminals, Unicode, and URL wrapping. Update recap generation and reconnect tests to advance Tokio's clock instead of relying on host uptime.

GitOrigin-RevId: 79a9bca779020b59a409207163b02944b30c1a20
2026-09-12 18:14:31 +00:00
Charlie Marsh
ee6814bfa4 Consolidate Rust release artifact downloads (#45051)
Download target artifacts, supplemental release assets, and staged npm
packages in a single `actions/download-artifact` step in
`.github/workflows/rust-release.yml` using a combined artifact pattern.

GitOrigin-RevId: 64c63cc7a2e263418b2a4064c1fd46e1c514cc29
2026-09-12 14:36:38 +00:00
Charlie Marsh
53c542d944 Use gzip compression level 6 for Codex package archives (#45039)
GitOrigin-RevId: ffd0d1cedb56a10dd9e2e0410c60deafc4202f37
2026-09-12 13:13:20 +00:00
Charlie Marsh
727e48697d Run DotSlash publishing directly on Ubuntu runners (#45035)
## Why

Avoid rebuilding the upstream Docker image and downloading its apt dependencies for each release by using the Python and `gh` already available on Ubuntu runners.

## What changed

Add a shared composite action that checks out the pinned upstream publisher and uses pinned `uv` to install hash-verified Python dependencies from wheels in a virtual environment. Accept multiple configuration paths and publish each manifest for the requested tag.

Update the Rust and zsh release workflows to use the action, combining the Codex and argument-comment-lint manifests into one invocation.

GitOrigin-RevId: 2a7ffef9a076a1d426349bcea587b10599cb8175
2026-09-12 13:07:13 +00:00
pakrym-oai
c4017a87aa Make context snapshot text rendering consistent (#44976)
## What changed

- Use the same text rendering for model instructions in request settings and Responses Lite developer content.
- Make `rewrite_known_segments` emit plain tags for recognized guidance, including collaboration and multi-agent instructions. Check message roles and complete tag boundaries so lookalike user or tool content stays visible, and retain generated compaction summaries.
- Normalize working-directory, workspace-root, and temporary paths in permission guidance while preserving policy differences.
- Separate text clipping from normalization and retain eight lines at each end of long sections, with fingerprints for omitted content. Update affected snapshots.

## Testing

Add regression coverage for instruction rendering across transports, literal and rewritten guidance, malformed and lookalike tags, compaction summary preservation, and permission path normalization that keeps policy changes detectable.

GitOrigin-RevId: 33b052911323c73b0387d650478f9cc3370fd001
2026-09-12 05:04:11 +00:00
Eric Traut
aee8a55ab6 Show task tokens and usage estimates in the agent command center (#44970)
## What changed

- Display input/output token counts and estimated credits and USD cost in task details. Prefer live token totals, falling back to complete totals from usage breakdowns.
- Fetch estimates for the selected task on a one-minute cadence for supported Business and Enterprise plans. Cache results, preserve prior nonzero estimates when a response reports zero, and stop fetching when the capability is unavailable.
- Clear cached usage and discard pending results on account changes, reconnects, or missed server events. Prioritize activity and usage over the original prompt when space is limited.

## Testing

Add a rendering snapshot and tests covering caching, stale results, unavailable usage, token resets, and incomplete usage breakdowns.

GitOrigin-RevId: b72c96053557389fdc723a70fab0dab841a52e49
2026-09-12 04:29:48 +00:00
Eric Traut
7efb0262d6 Open tasks managed elsewhere as read-only history in the command center (#44969)
## Why

The command center previously refused to open tasks managed by another app server, preventing users from viewing their saved history.

## What changed

- Fall back to a frozen, read-only history snapshot when attaching fails because another server owns the task. Preserve drafts and skip buffered request replay and paused-goal prompts while viewing.
- Keep the snapshot when reopening the displayed task, and allow explicit retry to attach once the other server releases it.
- Allow pasting into the command center while a read-only conversation is displayed, while keeping the conversation composer protected.
- Box the TUI startup future to keep it out of the CLI caller's frame.

## Testing

Add coverage for read-only history, draft and selection preservation, retry before and after ownership release, and history-read failure without leaving the current conversation. Assert that opening a read-only task does not start a turn and that the TUI startup future remains below 64 KiB.

GitOrigin-RevId: f1bdb5b2d9182079de4e53346a56742a4a02a1c7
2026-09-12 04:28:14 +00:00
Eric Traut
53ff712a48 Add model grouping to the agent command center (#44957)
## What changed

- Cycle task grouping through project, status, and model with `Ctrl+S`, and show the active grouping in the footer.
- Group tasks by model with the most recently updated tasks first within each group. Use `Unknown` for missing or empty model names.
- Display the model in task details and refresh it when thread settings change.
- In model grouping, dispatch new tasks without inheriting the selected task's working directory, matching status grouping.

## Testing

Add coverage for model grouping, selection preservation, navigation, and new-task dispatch across grouping modes. Update snapshots for model details and grouping hints.

GitOrigin-RevId: 429cf61c1e7438ba3b2f989d3ed14e12545856f7
2026-09-12 02:24:02 +00:00
Benjamin Carlsson
944d6fd1ba Keep voice captions visible across speaker updates and history handoff (#44952)
## Why

Completed voice captions could disappear before their queued history insertion ran. Interleaved user and assistant updates could also hide the other speaker's caption and restart its animation.

## What changed

- Preserve separate live caption cells for both speakers, rendering the user above the assistant without restarting settled text.
- Render completed captions while history insertion is pending, then move them into history in one app event. Keep them visible when agent streaming delays insertion.
- Invalidate the transcript overlay when an interleaved caption is cleared.

## Testing

Add regression tests for caption visibility through deferred history insertion, settled animations with either speaker arriving first, and empty caption completion during active and stopping sessions. Update replay coverage to exercise the app's history handoff.

GitOrigin-RevId: 31de6fc74b6dc7ff148c554e3176bf3ee92dced9
2026-09-12 01:21:25 +00:00
pakrym-oai
89c8bcf37d Add context snapshots for async questions and plugin refresh (#44948)
## What changed

- Add a multi-turn scenario covering `request_user_input_async`, continued work while awaiting an answer, and delivery of the answer into the active turn.
- Add a scenario covering plugin configuration reload in an existing thread, including discovery and use of newly installed skills and MCP tools across turns.
- Render explicit tool output names and namespaces in context snapshots, with a regression test ensuring outputs do not inherit metadata from their calls.

GitOrigin-RevId: 64fca8cb51a3a697fa84bf444ce55b8408961ab5
2026-09-12 00:34:18 +00:00
rhan-oai
132c739171 Retire Friendly and Pragmatic personality selection (#44946)
## What changed

- Use literal model instruction templates and the standard fallback prompt, ignoring legacy personality variables. Retain catalog decoding compatibility and report `supports_personality` as `false` for generated model presets.
- Stop emitting `<personality_spec>` developer messages and assigning an implicit Pragmatic configuration default.
- Filter Friendly/Pragmatic overrides from TUI requests while preserving explicit `personality = "none"`. With `features.personality` enabled, this opt-out still strips the model's personality section.
- Refresh inherited model instructions for agent roles only when the personality opt-out changes, preserving custom instructions.

## Testing

Update coverage for literal legacy templates, deprecated overrides on turn start and resume, role instruction refresh, and forwarding the explicit opt-out through thread start, resume, and fork requests.

GitOrigin-RevId: 1391db4e565e010569f0885f80013d1f86b45825
2026-09-12 00:22:04 +00:00
Eric Traut
cebdb732ea Route TUI Windows sandbox setup through the app server (#44945)
## What changed

Use `windowsSandbox/setupStart` for elevated and unelevated setup, and handle completion notifications while retaining the pending approval preset and permission profile selection. Verify the effective sandbox mode before enabling Agent mode.

Keep input locked and setup pending when the start request times out or its response is lost. Block thread replacement during setup, ignore completion notifications for a different mode, and clear interrupted setup state with a restart message after reconnection. Preserve the fallback prompt when elevated setup fails and report unelevated setup failures.

Remove the TUI's direct sandbox setup helpers and sandbox-mode configuration writes.

## Testing

Add regression coverage for uncertain setup responses, matching completion modes, blocked thread replacement with retained input, and interrupted setup during reconnection.

GitOrigin-RevId: 5ec1101a1a69b3f96f01fc2ba6a03112705f4918
2026-09-12 00:20:30 +00:00
alexsong-oai
39d193d72d Enforce managed provider requirements on existing app-server threads (#44944)
## Why

Existing threads retain their model provider configuration, which can stop matching managed requirements after those requirements change.

## What changed

- Check retained providers against current managed `model_provider` and `model_providers` requirements before turn start/steer, review, compaction, manual queue start, and active goal updates. Reject requests when requirements cannot be loaded or no longer match; provider mismatches prompt users to restart Codex.
- Load managed requirements independently of user, project, system defaults, and thread configuration, and resolve Bedrock provider overrides before comparison.
- Keep interrupt, realtime stop, and goal pause/clear available. Realtime connections use separate routing and are outside these checks.
- Make detached reviews inherit their parent thread's configuration.

## Testing

Add unit and integration coverage for provider selection and definition changes, Bedrock overrides, requirement load failures, unchanged queue and goal state after rejection, and continued operation after local configuration changes. Extend detached review coverage to verify inheritance of the parent's provider route.

GitOrigin-RevId: 21abf08ad2bcc2ea4698209fa33a17485eed4740
2026-09-12 00:12:26 +00:00
Benjamin Carlsson
d43f1e7eb2 Clarify the Windows Visual C++ runtime notice for voice packages (#44942)
Identify the bundled runtime as `bin/vcruntime140.dll`, relative to the
notice in release packages. Add a dedicated section with links to Microsoft's
license terms, redistributable downloads and support, and Visual Studio 2026
redistribution information.

GitOrigin-RevId: 9ef14ebd9b2d5b2ff0b449d50717f40e7823c727
2026-09-12 00:06:16 +00:00
Eric Traut
c210f4c222 Respect execution hosts in Windows sandbox setup (#44939)
## Why

The Windows TUI cannot configure a remote executor's sandbox. Required elevated sandbox setup also needs to reflect the local app server's readiness rather than the TUI's local setup files.

## What changed

- Restrict setup prompts and actions to local connections with local executors, including local daemon connections. Let remote servers own Agent permission selection, and warn when local and remote executors are configured together.
- Query `WindowsSandboxReadiness` at startup when elevated sandboxing is required locally, and track successful setup across chat widget replacement and reconnects.
- Restore pending initial input to the composer when mixed executors prevent required setup or a local connection goes offline.

## Testing

Add regression coverage for local, remote, and mixed host selection, remote Agent permission selection, pending input restoration with mixed executors, and setup state preservation during daemon reconnects.

GitOrigin-RevId: bd45b308ac3ae4c2489b0bd2ac5d7e12a7fc35d6
2026-09-11 23:44:29 +00:00
priyanshusingh-de
2e572378f4 Add connector auth failure detection without an install URL (#44938)
## Why

`connector_auth_failure_from_tool_result` requires an install URL to return an auth failure, even when the tool result contains valid auth failure metadata.

## What changed

Export `is_connector_auth_failure_from_tool_result` from `codex-mcp` to detect auth failures independently of an install URL. Share metadata validation with the existing parser, requiring an error result, an explicit auth failure flag, and a nonempty connector ID that does not conflict with the metadata.

## Testing

Add unit tests for detection without an install URL, rejection of missing or mismatched connector identities and non-auth errors or successful results, and detection for all three supported auth reasons.

GitOrigin-RevId: 6e4e177f26d9a34c56874b0360bae63f6c89107e
2026-09-11 23:36:17 +00:00
rhan-oai
12e82f44f8 Remove personality selection from the TUI (#44935)
## What changed

Remove the `/personality` command, selection popup, tooltip, and associated settings update and persistence handlers. Stop sending a personality override with TUI user turns.

GitOrigin-RevId: 0549a1f9dcfd8118340fad4b60fd24d4eee7f93a
2026-09-11 23:28:38 +00:00
pakrym-oai
e8271aa8b4 Add scenario snapshots for remote compaction and Code Mode tools (#44934)
## What changed

Add two integration scenarios for `gpt-6-astra` that snapshot request history and settings:

- A multi-turn conversation with local and plugin skills, remote compaction, and a follow-up containing an image.
- A release check combining direct collaboration calls with Code Mode shell commands, MCP calls, image viewing, and patch application, including reading back the edited file.

GitOrigin-RevId: 9b8a48a817c3dba4b139d1b0d015e8084dcb219b
2026-09-11 23:14:52 +00:00
Eric Traut
f3c4d082d9 Remove Windows world-writable scans and warnings from the TUI (#44933)
## What changed

Remove TUI-triggered world-writable scans at startup and during permission changes, along with their warning dialogs, acknowledgement handling, and scan telemetry. Permission selection and shortcuts no longer check for these warnings, and terminal color probing no longer waits for a startup scan.

GitOrigin-RevId: a8d2fb5de7f891dcae5261286743fe3a125b82aa
2026-09-11 23:02:27 +00:00
pakrym-oai
202d61c629 Unify context snapshots and group requests into windows (#44932)
## What changed

- Use one renderer for captured requests, raw request bodies, and input items. Show only appended items when inputs extend the previous request and settings match; start a new snapshot window otherwise and explain the boundary.
- Add optional request settings and tool inventory deltas. Normalize volatile values with stable labels, preserve multiline content, and fingerprint omitted content so changes remain visible.
- Migrate existing context snapshots and expand compaction snapshots to include request history.

## Testing

Add focused tests for window boundaries, cache key changes, tool deltas, shared item rendering, stable normalization, and fingerprints. Assert that the follow-up request after pre-turn compaction includes the working directory override.

GitOrigin-RevId: 6445b014081208ea432b1f3e2ac835c5e4955cb0
2026-09-11 22:55:38 +00:00
viyatb-oai
4d205c7a4d Stop setting YARN_NO_PROXY in the managed proxy environment (#44931)
GitOrigin-RevId: f690a944b8c6d4d846b35a66b95953645028bb1b
2026-09-11 22:33:24 +00:00
rhan-oai
c18277043e Embed friendly instructions in bundled GPT-5.4 and GPT-5.5 (#44930)
## What changed

Replace the selectable personality templates in the bundled `gpt-5.4` and `gpt-5.5` definitions with fixed friendly instructions. Personality selection becomes unavailable for these models in the TUI, and submitted turns omit the personality override. Remove personality overrides from Python SDK examples and the walkthrough notebook.

## Testing

Update core and TUI tests to cover fixed friendly instructions, ignored pragmatic updates, unavailable personality selection, and omitted turn overrides. Preserve coverage for selectable personalities in legacy catalogs, and add coverage for resumed legacy sessions and explicit empty instruction overrides.

GitOrigin-RevId: 869a71445584272405fcbd1325efc31c224808c8
2026-09-11 22:29:54 +00:00
Benjamin Carlsson
16491f7f70 Preserve voice meter history through quiet samples (#44928)
## Why

A quiet sample cleared all earlier activity from that channel's voice meter, making recent speech disappear immediately.

## What changed

Let quiet samples scroll into the microphone and speaker meter history so earlier activity remains visible until it ages out.

## Testing

Update history assertions and the meter snapshot to cover quiet samples on each channel and the eventual return to silence after a full history window.

GitOrigin-RevId: 834157df28c9d2cfbe9fa17bbfaf32b81313a295
2026-09-11 22:17:40 +00:00
Benjamin Carlsson
1b5e27c7f0 Accept voice response audio before captions on quiet turns (#44925)
## Why

Starting a voice turn while the speaker is idle suppresses response audio until assistant captions arrive, preventing audio that arrives first from being accepted.

## What changed

Make speaker suppression conditional when user transcripts start a new turn. Keep idle output ready for audio while preserving interruption of active assistant output and older, uncaptioned speech that is queued or accepted.

## Testing

Add regression coverage for quiet turns with incremental or final-only user transcripts and for interruption of older pending speech across queue and caption states.

GitOrigin-RevId: 288d2071766a1d0c1b8c7a10c0ab434dc4d7cee1
2026-09-11 22:09:26 +00:00
Benjamin Carlsson
7ef70f95d5 Refresh the speaker format when restarting voice output (#44924)
## Why

Opening a Bluetooth microphone can change the speaker format, leaving the previously cached sample rate unsupported when the speaker stream restarts.

## What changed

Requery and validate the speaker configuration after stopping the old stream. Update playback and render resampling to the current sample rate, and revalidate callback timing. Discard stale echo references while preserving capture history and audio processing state.

## Testing

Extend the speaker reset test to cover 48, 24, and 44.1 kHz output rates, checking that render output matches a fresh converter while capture history and pending samples are preserved.

GitOrigin-RevId: 3a4fba577288a83a7509fc78be86171ac85a3c0a
2026-09-11 22:09:02 +00:00
Benjamin Carlsson
ce7fbb373b Bundle native voice runtimes in Windows releases (#44922)
## Why

Windows release packages need the voice helper and native audio libraries. Realtime TLS connections on fresh Windows installations also need platform certificate validation so Windows can retrieve missing trusted roots on demand.

## What changed

- Build and sign the voice helper and audio DLLs for Windows x64 and ARM64, bundle a pinned Microsoft CRT DLL, and verify signatures and runtime receipts before packaging.
- Add verified, pinned Cygwin and native build tools plus MSVC linker, compiler, and path handling fixes for the Windows Bazel builds.
- Include voice resources in primary release archives and WinGet packages. Preserve WinGet executable names, update manifest hashes, and recognize the package root through matching entrypoint metadata. Keep Python runtime wheels voice-free to preserve their existing Windows support floor.
- Use Windows platform TLS validation for realtime WebSockets when no custom CA bundle is configured, preserving custom CA behavior.

## Testing

Add coverage for build-input integrity and unsafe paths, signed Windows runtime assembly, WinGet file and hash preservation, package discovery, and TLS trust selection, untrusted certificate rejection, and hostname validation.

GitOrigin-RevId: 423da35872fa5549d69fd4ca97d922bb49599386
2026-09-11 21:59:24 +00:00
Benjamin Carlsson
3f59eb965a Enable TUI voice conversations by default (#44921)
## What changed

Promote `realtime_conversation` to stable and enable it by default, removing its experimental announcement. Update popup and tooltip tests to use explicit experimental voice fixtures now that the feature is stable.

GitOrigin-RevId: 4e947189f41de465d1f343e95100b26d6200db24
2026-09-11 21:59:01 +00:00
Owen Lin
3052bbcf8c Remove the deprecated thread/rollback API (#44915)
## What changed

Remove `thread/rollback`, its request and response types, generated bindings, and the core `Op::ThreadRollback` operation. Requests now follow the generic unknown-method rejection path. Document `thread/revert` as the alternative for paginated threads.

Keep historical `ThreadRolledBack` markers and legacy error deserialization so existing rollouts remain compatible with replay and migration.

## Testing

Adapt retained-context and Guardian history tests to append legacy rollback markers and resume threads, preserving coverage of surviving instructions, answers, and review history.

GitOrigin-RevId: b3da1becdf86b1869275aacb0ffc2817cee5af2e
2026-09-11 21:32:04 +00:00
Matthew Zeng
c62d191c4c Expose disabled plugin settings in the app-server API (#44905)
## What changed

- Accept `disabledPluginIds` in `thread/settings/update` and `turn/start`. A supplied list replaces the saved selection; omission or `null` preserves it, and `[]` clears it.
- Return the selection in thread start, resume, and fork responses and `thread/settings/updated` notifications. Update generated schemas and client types.
- Restore disabled plugin IDs from the history retained at the requested fork boundary, preserving explicit overrides.

The selection persists across resume but does not yet filter plugin capabilities.

## Testing

Add coverage for replacing, preserving, and clearing selections without inference; turn-start notifications; resume; and fork boundaries across legacy and paginated history, with loaded and restarted parents. Add a core regression test for history restoration and explicit clearing.

GitOrigin-RevId: 654a8c2a0527228d422c0dd4919228447e2663db
2026-09-11 20:27:37 +00:00
iceweasel-oai
42cd1ec497 Wire up the native Windows MXC helper entry point (#44903)
## What changed

- Dispatch `--__codex-windows-mxc` before normal CLI parsing, launch the decoded request, and propagate the child exit code.
- Build the native request from the helper's environment and working directory, discovered Windows platform directories, and volume roots, including UNC working-directory roots. Reject non-Unicode environment values and empty child environments.
- Allow Win32k calls and desktop handles needed for PowerShell startup while retaining clipboard, input-injection, and desktop/system-control restrictions.
- Keep policy, transport, and native launch internals private, and report an explicit error when the helper is invoked outside Windows.

## Testing

Add a wrapper regression test covering exact argument preservation, Windows quoting, separate policy and command working directories, and explicit environment forwarding.

GitOrigin-RevId: 674d0d61a3265bd517b77da9f9de2cd9fad62917
2026-09-11 20:10:02 +00:00
faizan-oai
e3a52b87b2 Expose available access programs in model discovery (#44893)
## What changed

Carry optional `available_access_programs` metadata through model information, presets, caches, and the TUI, and expose it as `availableAccessPrograms` in app-server `model/list` responses. Update the generated JSON schemas, TypeScript types, and Python models.

Preserve the distinction between missing metadata and an empty `cyber` list. Ignore unknown cyber program names when reading the catalog so new server programs do not prevent older clients from loading it. Discovery metadata does not grant access; inference still enforces authorization.

## Testing

Add coverage for absent, null, empty, and populated metadata, unknown program names, and app-server serialization. Extend cache tests and verify that online refreshes persist changed access metadata even when the catalog ETag stays unchanged.

GitOrigin-RevId: b3ef5805c1c61b8d64b9b896c9c0a79120143667
2026-09-11 19:13:04 +00:00
jif
4dcce4f0c4 Reject token-budget history notes for unsupported starting models (#44883)
## What changed

After resolving startup configuration and model defaults, reject `features.token_budget.use_history_notes_extension` when the starting model lacks `supports_experimental_context`. Return an error directing users to disable the option or select a compatible model.

## Testing

Add startup coverage for explicit configuration and model defaults, verifying rejection for unsupported models and successful activation for supported models and standalone token budgets. Update history-notes test fixtures to declare experimental context support.

GitOrigin-RevId: abf1a024efc5acf97cfc858fbb93821363769dc0
2026-09-11 17:55:03 +00:00
Ian MacLeod
33bdf976cc Fade Astra composer stars and stabilize cursor redraws (#44879)
## What changed

- Fade Astra stars over one second after 15 seconds from the first visible frame, or quickly on composer input, drafts, voice input, and popups. Disconnected key handling also dismisses the animation.
- Preserve placeholder and draft text, including spaces. Stop scheduling animation frames when unfocused or finished, while allowing the idle deadline to elapse without terminal focus.
- Hide the terminal cursor before repainting and cache its style to avoid redundant anchor repairs. Invalidate cursor state after screen transitions, external programs, resume, and caught-panic recovery.

## Testing

Add regression tests and snapshots for fade timing, input dismissal, focus changes, text preservation, and frame scheduling. Add cursor redraw tests and a PTY test for cursor visibility and shape restoration after a caught panic. Update the reconnect test to wait until both the draft and notification are visible.

GitOrigin-RevId: 0c9aaa13e6bde820f88e3757457063680d7921a3
2026-09-11 17:43:36 +00:00