Commit Graph

8886 Commits

Author SHA1 Message Date
felixxia-oai
1a7519fa07 Move host skill root resolution into the skills extension (#36943)
## What changed

- Move config-layer, user, system, plugin, extra, and repository skill-root
  resolution from `core-skills` into the host skills extension.
- Keep the core loader focused on loading explicit `SkillRoot` values.
- Relocate and expand tests for root precedence, deduplication, repository
  ancestry, plugin metadata, and concurrent probing.

GitOrigin-RevId: 3b95cf28101b8b4d64d54079d202154dad560aab
2026-08-04 18:41:55 +00:00
jif
d1fb77d692 Use current session settings for review threads (#36941)
## Why

Reviews may use a different model from their parent turn. They need current
thread settings without inheriting defaults resolved for the parent model.

## What changed

- Build review configuration from the parent turn context while preserving
  explicitly configured token-budget overrides.
- Use the review model's token-budget defaults and select a supported reasoning
  effort when switching models.
- Carry the session's resolved service tier and current environment,
  permissions, and approval settings into the review thread.

## Testing

Expanded review coverage for updated thread settings, model-specific
token-budget defaults, service tiers, and reasoning effort selection.

GitOrigin-RevId: cefa0f22cd9b9e28047d94e1d2d49ff83eded43e
2026-08-04 18:09:58 +00:00
Dylan Hurd
2b1357c27c Include policy approval reasons in Guardian reviews (#36939)
## Why

Guardian reviews received sandbox retry reasons, but not the execution-policy reason that triggered an initial approval request.

## What changed

- Propagate approval and retry reasons through the tool approval flow and include the applicable reason in the Guardian prompt.
- Prefer a sandbox retry reason when both are available.
- Truncate approval context to 512 tokens while preserving the start and end of the reason.

## Testing

Added prompt and integration coverage for policy reasons, retry precedence, and truncation.

GitOrigin-RevId: 5b0f4e1c40b792b031bc8f7b31685a61d12b8d92
2026-08-04 18:01:04 +00:00
Celia Chen
3ca9f375aa Enable cached web search for Amazon Bedrock (#36938)
## Why

Amazon Bedrock supports hosted text web search, but it rejects the
`search_content_types` field used for multimodal search and does not support
external live or indexed web access.

## What changed

- Advertise hosted web search for Amazon Bedrock while marking external web
  access as unsupported.
- Resolve unsupported live and indexed modes to cached search, or disable the
  tool when cached search is prohibited by managed requirements.
- Normalize built-in and configured Bedrock model catalogs to text-only web
  search, and retain the runtime provider in session configuration so turn
  setup can apply its capabilities.

## Testing

- Cover cached fallback, managed-mode restrictions, text-only tool payloads,
  provider capabilities, and catalog normalization.

GitOrigin-RevId: 310473849257401654388a4ebb42920e03aa3228
2026-08-04 17:55:28 +00:00
Eric Traut
1e59dc5bda Trust undecided local projects automatically (#36935)
## What changed

- Replace the TUI directory-trust prompt with automatic trust for local projects whose trust level is unset. Keep explicit trust settings and remote workspaces unchanged.
- Persist trust for the resolved Git or configured project root, then reload configuration so project-local settings take effect.
- Fall back to an in-memory trust override and an embedded app server when the config update cannot be persisted.

## Testing

- Cover persisted and in-memory trust, custom project-root markers, and the working directories selected by resume and fork flows.

GitOrigin-RevId: 8fd51eb4cd88267073324bfd7dc4106a56d7c745
2026-08-04 17:49:54 +00:00
jif
90314a9207 Read turn permissions from the current configuration (#36930)
## What changed

- Remove the cached permission profile from `TurnContext` and derive the
  effective profile, filesystem policy, network policy, and legacy sandbox
  policy from `config.permissions`.
- Update sandbox consumers and tests to use the current turn configuration.
- Verify that role-based agent spawning reapplies runtime permissions and that
  cold-resumed agents retain their disabled permission profile.

GitOrigin-RevId: d67c5d2bcbe6dc76f15b56defb485b155fd1f138
2026-08-04 17:13:13 +00:00
Jeremy Rose
7ada37a15e Reject implicitly discovered bare Git repositories (#36924)
## Why

A repository can contain a tracked directory that Git implicitly treats as a bare
repository. Its configuration may select helpers such as `core.fsmonitor`, causing
Codex Git operations in that directory to execute repository-controlled code.

## What changed

- Pass `-c safe.bareRepository=explicit` to Codex-managed Git commands so they
  reject implicitly discovered bare repositories.
- Continue to support repositories explicitly selected with `--git-dir` or
  `GIT_DIR`.

## Testing

Add a regression test that clones a repository containing a tracked embedded Git
repository and verifies that guarded Git inspection rejects it without running
its configured filesystem monitor.

GitOrigin-RevId: 344b5bc1e0ffa94f2a1b788488aa653222da10f3
2026-08-04 16:53:33 +00:00
felixxia-oai
02bc1dd796 Move the host skills service into the skills extension (#36921)
## What changed

- Move host skill discovery, snapshot caching, and configuration handling from
  `codex-core-skills` to `codex-skills-extension`.
- Rename `SkillsService` and `SkillsLoadInput` to `HostSkillsService` and
  `HostSkillsLoadInput` to distinguish the host implementation from other skill
  providers.
- Keep shared loading primitives and skill outcome modeling in
  `codex-core-skills`.

GitOrigin-RevId: d81a21791d2ef8c066e157e7e538b8cb7ee4c24b
2026-08-04 16:28:46 +00:00
Greg Brisebois
d75f94a94d Merge local plugins into plugin search results (#36919)
## What changed

- Discover plugins from configured and repository marketplaces using the request's `cwds`, and merge up to 100 ranked local matches into the first remote result page.
- Match local plugin names, display names, and keywords without case or punctuation sensitivity, while applying global, personal, and workspace scope semantics.
- Deduplicate local and remote copies, preserve local installation metadata on the remote result, and treat the remote global catalog as authoritative over the local curated marketplace.
- Keep local search available for API-key authentication and when `remote_plugin` is disabled, and consistently report `enabled: false` because search results describe discovery rather than effective activation.

## Testing

- Add coverage for merged pagination and ranking, API-key local search, scope and feature behavior, deduplication, installed state, and explicit disabled-state reporting.

GitOrigin-RevId: 63696a00d16166dfdd86e0cc456769c583ebe9a7
2026-08-04 16:16:30 +00:00
jif
7325f348a2 Test explicit plugin mentions with disabled apps (#36917)
## What changed

Expand the ChatGPT dual-surface plugin integration test to cover both enabled
and disabled app configurations. Verify that plugin app guidance and searchable
app tools follow `apps.calendar.enabled`, while plugin MCP guidance and tools
remain suppressed.

GitOrigin-RevId: 40c51fbc075e07a8b03b5c520f5c46e360f71ceb
2026-08-04 16:04:35 +00:00
jif
c8e255e7f8 Centralize app enabled-state evaluation (#36916)
## What changed

- Add `AppToolPolicyEvaluator::apply_app_enabled_state` and use it when
  presenting app lists, building plugin context, and deciding whether app
  instructions are available.
- Preserve each app's source state unless local or managed configuration
  explicitly overrides it.
- Keep connector discovery and post-install refresh checks based on raw
  accessibility rather than configured enablement.

## Testing

- Cover default enablement, per-app overrides, managed disablement, and
  preservation of unconfigured source state.

GitOrigin-RevId: f1a62d55e7cc48b37113848e3baa0d69d8d9c8a8
2026-08-04 15:49:49 +00:00
felixxia-oai
2999b8e831 Move skill policy resolution into codex-skills (#36913)
## What changed

- Move `resolve_disabled_skill_paths` into `codex-skills` and expose it from the crate.
- Re-export the resolver from `core-skills` to preserve existing callers.
- Split config-layer and policy-resolution coverage into focused unit tests, including ordered path and name overrides.

GitOrigin-RevId: 6528ff99285925132bf80eb33eafb1b62118e033
2026-08-04 15:37:42 +00:00
jif
6a828ca26f Read approval policy from the current turn configuration (#36912)
## Why

Thread settings can update the approval policy after a turn context is created.
Keeping a separate copy on `TurnContext` could leave tool approval checks using
the previous policy.

## What changed

- Remove the duplicated approval-policy field from `TurnContext`.
- Resolve the policy through the turn's current configuration everywhere it is
  needed, including tool execution, Guardian routing, MCP handling, and
  permission requests.

## Testing

- Update the shell escalation test to apply a thread-level policy override and
  verify that the next turn rejects an escalation using the updated policy.

GitOrigin-RevId: e5966ba08f179d53fd76871ad904762958c0f5ea
2026-08-04 15:32:31 +00:00
Martin Au-Yeung
ee46c5ba0e Negotiate MCP extensions per app-server session (#36910)
## Why

App-server clients need to advertise structured MCP extension settings, including supported MCP App UI MIME types, rather than only opting into OpenAI form elicitation with a boolean.

## What changed

- Add an `extensions` map to initialize capabilities and preserve `mcpServerOpenaiFormElicitation` as a legacy alias for `openai/form`.
- Capture the declared extension profile when a thread is started, resumed, or forked, propagate it to subagents, and advertise it to downstream MCP servers during initialization.
- Keep the profile stable for the lifetime of the loaded session instead of changing it on later turns or direct tool calls.

## Testing

- Cover extension conversion, downstream MCP initialization, session isolation, legacy form support, and subagent inheritance.

GitOrigin-RevId: fbcedbb74ce788e574b0f884a4c45c4cedb9de54
2026-08-04 15:23:43 +00:00
Alec Barber
bab7c2dcc1 Improve bearer token secret redaction (#36908)
## Why

Bearer credentials can contain characters outside the previous token pattern or
start with another recognized key prefix. This could leave part of the
credential visible after redaction.

## What changed

- Recognize bearer tokens containing URL-safe and base64-style characters,
  optional padding, and horizontal whitespace after the scheme.
- Redact bearer credentials before matching narrower OpenAI and AWS key forms so
  the whole credential is replaced.
- Preserve delimiters following the credential and avoid matching short tokens,
  joined scheme names, or tokens separated by vertical or non-ASCII whitespace.

## Testing

Added focused positive and negative cases for the supported token forms and
false-positive boundaries.

GitOrigin-RevId: 1e5b10685281dc91d232d619b938bacbadaa47f9
2026-08-04 15:14:57 +00:00
jif
d1f14e31a7 Preserve model providers when reloading v2 agents (#36906)
## Why

Reloading an unloaded v2 agent could inherit the model provider from the
agent that triggered the reload, even though the worker's model was restored
from its persisted thread state.

## What changed

- Restore both the model and model provider from the stored thread when
  reloading a v2 agent.
- Return an invalid-request error if the stored provider is no longer present
  in the configured provider map.

## Testing

Extend the v2 agent reload test to trigger the reload with a different sender
provider and verify that the worker retains its stored provider.

GitOrigin-RevId: 6401d9f0d1c116e9954e3bd193d016f04da5f223
2026-08-04 15:01:28 +00:00
jif
d98eb72e18 Limit RMCP logs persisted to SQLite (#36904)
## What changed

- Persist `rmcp` and `codex_rmcp_client` events only at `INFO` level or above.
- Cover nested targets from both namespaces in the SQLite log filter test.

GitOrigin-RevId: dfeeec302a9562f533a09a735b392d202c1f7801
2026-08-04 14:56:06 +00:00
felixxia-oai
49b0aebd6f Load skill interface metadata in the host loader (#36903)
## What changed

- Move skill interface validation and asset-path resolution into `codex-skills` so both skill loaders share the same behavior.
- Populate host-loaded skills with validated display metadata, prompts, brand colors, and local icons from `agents/openai.yaml`.
- Allow plugin skills to reference icons under the plugin's shared `assets` directory while rejecting absolute paths and paths that escape permitted asset roots.

## Testing

- Add resolver tests for valid, invalid, local, and plugin-shared interface assets.
- Add host loader coverage for interface fields and asset-path restrictions.

GitOrigin-RevId: 3f316191752eeebd15d11ac0bee82201574320ec
2026-08-04 14:51:08 +00:00
jif
f93109615f Propagate updated permissions to review threads (#36901)
## What changed

- Apply the session's current approval policy whenever per-turn configuration is built.
- Have review threads inherit the parent turn's full permission settings and approval reviewer.
- Add coverage for settings updated after session startup, including the approval policy, permission profile, and approval reviewer.

GitOrigin-RevId: bff050c6de157dd65d62f7b49651bef3f426ee3f
2026-08-04 14:29:24 +00:00
jif
18f03c1eb7 Register app tools independently of the connector list (#36900)
## What changed

- Gate Codex Apps MCP tool registration on whether apps are enabled instead of requiring each tool's connector to appear in the accessible connector list.
- Continue enforcing model-visibility and app-tool policy checks, including the requirement for connector metadata.
- Use the merged connector catalog for tool-suggestion discovery.

## Testing

- Cover app-tool registration from catalog metadata, including synthetic links, source ordering, and the apps-disabled case.

GitOrigin-RevId: eef4eb03da9738d3a165dd6cfda0d3c1844d51e7
2026-08-04 14:19:13 +00:00
Charlie Marsh
40e5de94e9 Avoid redundant filesystem metadata probes (#36898)
## What changed

- Reuse directory-entry file types in local memory listing while continuing to
  exclude symlinks, and reuse rollout metadata when reading modification times.
- Avoid following non-symlinks twice in direct filesystem metadata and directory
  listing operations while preserving target classification for valid symlinks.

## Testing

- Cover symlink handling in local memory listing and search.
- Extend Unix filesystem tests for followed file and directory symlinks and
  dangling metadata links.

GitOrigin-RevId: e4e24576e2e9db704f9da54727928e121f81dc86
2026-08-04 13:56:52 +00:00
jif
17df7545a3 Handle late MCP startup results after lag timeout (#36895)
## Why

MCP startup status delivery can lag. Treating a server that is still starting or
has not reported yet as cancelled produces a misleading interruption warning and
can hide its eventual terminal result.

## What changed

- Only report an interrupted startup when a server explicitly enters the
  cancelled state.
- Allow a complete set of terminal updates received after the lag timeout to be
  promoted and reported, including failures and cancellations.

## Testing

Added TUI tests covering unresolved servers at the lag timeout and late failure
and cancellation updates.

GitOrigin-RevId: 555f3d13ac87bda6e9b0bf72335a1c04851ac25a
2026-08-04 13:29:21 +00:00
Alec Barber
fcf636a41d Redact secrets from app-server command execution items (#36893)
## Why

Client-facing command execution items can include recognizable secrets in the
rendered command or parsed command actions.

## What changed

- Redact secrets in `commandExecution.command` and `commandActions` for live
  items, completed items, and replayed thread history.
- Keep command approval requests backed by the original executable command and
  parsed actions while using the redacted representation for display items.
- Document that execution item commands are redacted display values rather than
  executable commands.

## Testing

- Cover redaction for command conversion, parsed search actions, legacy replay,
  approval flows, completion notifications, and rejected commands.

GitOrigin-RevId: 2ad056f21882bf5166182ad1a4ff0bf6471d9c0e
2026-08-04 13:16:58 +00:00
jif
6d4d9442c7 Support leaf models in multi-agent v2 (#36892)
## What changed

- Allow multi-agent v2 parents to spawn any visible model that has not explicitly disabled multi-agent support.
- Expose collaboration tools to child agents only when their selected model supports multi-agent v2, keeping legacy models as leaf workers.
- Preserve a worker's selected model when reloading it into residency.
- Propagate multi-agent capability metadata to Amazon Bedrock model entries so delegation is gated consistently.

## Testing

- Cover model selection, leaf-worker tool visibility, Bedrock capability handling, and model preservation after reload.

GitOrigin-RevId: 1457adb1a09806d1f0621311d5a42a6815b9dd4e
2026-08-04 12:36:14 +00:00
felixxia-oai
1669c2403f Add host skill root loading (#36884)
## What changed

- Add a loader that discovers skills from canonical host roots and preserves their `SkillScope`.
- Skip hidden directories, follow directory symlinks for user, repo, and admin scopes, and ignore them for system skills.
- Load dependencies and policy from optional `agents/openai.yaml` metadata without rejecting a skill when that metadata is missing or invalid.
- Resolve plugin and symlink namespaces while retaining host paths and reporting per-skill errors outside system scope.

## Testing

Add coverage for frontmatter and metadata loading, invalid optional metadata, hidden directories, plugin namespaces, and scope-specific symlink discovery.

GitOrigin-RevId: ac436d93b5943b7eaae32143e43367921dd1c350
2026-08-04 11:19:27 +00:00
jif
fd1e4d7a6d Preserve complete MCP namespace descriptions (#36882)
## What changed

- Keep complete MCP namespace descriptions in tool-search source metadata.
- Raise the namespace tool-spec description limit from 1,000 bytes to 512 KiB,
  truncating at a UTF-8 character boundary only when the new limit is exceeded.

## Testing

- Cover descriptions beyond the former limit and multibyte truncation at 512 KiB.
- Update SSE and stdio MCP tests to verify that complete server instructions are
  preserved without hiding tools.

GitOrigin-RevId: 000bfcafb3df348065ae451685bfbf978a0e3248
2026-08-04 11:14:06 +00:00
felixxia-oai
77ce1d10aa Move direct executor skill discovery into the skills extension (#36880)
## What changed

- Add extension-owned discovery and namespace resolution for skills loaded directly through an `ExecutorFileSystem`.
- Preserve hidden and symlinked skills, nested plugin namespaces, optional `agents/openai.yaml` metadata, product restrictions, and deterministic ordering.
- Reuse the filesystem walk inventory and bound concurrent skill, metadata, and manifest reads.
- Route direct executor catalog loading through the new extension loader.

## Testing

- Cover namespace lookup, metadata probing, walk reuse, concurrent reads, and parity with the existing environment loader.

GitOrigin-RevId: 4e0b821eb84d03f0dc1c2dee7b2b9a072ee3fd44
2026-08-04 11:04:45 +00:00
felixxia-oai
4c25d6cc5c Move executor skill bundle loading into the skills extension (#36877)
## What changed

- Move parsing of pre-discovered executor skill bundles from `core-skills` to
  the skills extension.
- Expose shared `SKILL.md` frontmatter parsing from `codex-skills` so direct
  and pre-discovered loading use the same validation and repair behavior.

## Testing

- Add parity coverage for direct and pre-discovered executor skill catalogs,
  including plugin namespaces, metadata, product policy, and warnings.
- Add a snapshot for the resulting pre-discovered executor catalog.

GitOrigin-RevId: c5f888226fa5600bd8b90f5682400da39a5db5ff
2026-08-04 10:41:01 +00:00
zsol-openai
2a16af8234 Parallelize R2 asset publishing with DotSlash (#36871)
## Why

R2 publication waited for DotSlash to finish before uploading any release
assets, extending the release pipeline's critical path.

## What changed

- Start an `assets` stage after the GitHub release is created, in parallel with
  DotSlash publication. Upload available assets concurrently without publishing
  release metadata or channel aliases.
- Run a `finalize` stage after both jobs complete. Verify assets already present
  in R2, upload any assets DotSlash added, and then publish metadata, stable
  installer aliases, and release channels.
- Validate downloaded assets before upload and retain no-overwrite semantics
  across both stages.

GitOrigin-RevId: 1c3e8ca715be4064c2532a5c651f1bbe03ed96a4
2026-08-04 10:05:24 +00:00
jif
9873cba8ce Consolidate thread spawning behind a request object (#36862)
## What changed

- Add `ThreadSpawnRequest` to carry thread options, authentication, agent
  control, fork metadata, inherited state, and shell overrides.
- Route new, resumed, and forked threads through one `spawn_thread` path.
- Centralize default session-source and environment selection when the request
  is consumed.

GitOrigin-RevId: 8fd1a8531a212000c7430218c2200aa4a047cb9a
2026-08-04 08:51:35 +00:00
rka-oai
d4fb78bfc5 Support custom tools in namespaces (#36857)
## What changed

- Allow namespace tool specs to contain custom freeform tools alongside function tools.
- Include namespaced custom tools in deferred tool search and expose them to code mode with names such as `editor__apply_patch`.
- Route custom payloads to matching extension tools while preserving function-only payload validation.

## Testing

- Add serialization, tool search, code-mode definition, and end-to-end dispatch coverage for namespaced custom tools.

GitOrigin-RevId: be64d35f6ae54685c5a9fcf45a732320742ea7e5
2026-08-04 08:28:43 +00:00
rka-oai
12288240b4 Support deferred loading for freeform tools (#36856)
## What changed

- Add optional `defer_loading` support to freeform Responses API tool definitions.
- Omit the field when it is unset so existing eager tool definitions retain their wire shape.

## Testing

- Verify legacy freeform tool deserialization and eager and deferred serialization shapes.

GitOrigin-RevId: 50e8658a54ac5b6ae0c1dbfe65f7bb62efef561d
2026-08-04 08:24:42 +00:00
pradeepg-oai
5af85998c2 Keep API request metrics out of Statsig exports (#36840)
## What changed

- Treat `codex.api_request` and `codex.api_request.duration_ms` as runtime-only metrics for Statsig exporters, matching the existing tool-call metric behavior.
- Keep both metrics available through other OTLP exporters.

## Testing

- Extend the Statsig filtering test to cover both API request metrics.
- Verify the OTLP HTTP exporter still sends the API request count and duration.

GitOrigin-RevId: f0f800ade7979e4da72ae59641bf42aa8a3ebd5a
2026-08-04 05:24:58 +00:00
Eric Traut
db1a414569 Avoid requesting key-release events in Ghostty (#36834)
## Why

Ghostty can leak release events for shortcuts that the terminal consumes.

## What changed

- Detect Ghostty when `TERM` is `xterm-ghostty`, including when `TERM_PROGRAM` is unavailable.
- Omit `REPORT_EVENT_TYPES` from keyboard enhancement flags for Ghostty while retaining alternate-key and escape-code disambiguation reporting.

## Testing

- Cover Ghostty detection through `TERM` and its keyboard enhancement flags.

GitOrigin-RevId: d865a6cdd1373aad4b78099e821d1ebaeb6cfdff
2026-08-04 03:49:53 +00:00
Adam Perry @ OpenAI
8e3b5d3e87 Time out stalled code-mode host requests (#36830)
## Why

Code-mode `wait` and `terminate` requests can remain pending when the host
transport stalls.

## What changed

- Add a 60-second transport allowance to the runtime timeout for `wait`, and
  apply the same transport deadline to `terminate`.
- Return a model-visible timeout error and invalidate the connection when the
  deadline expires, so the next execution reconnects to the host.

## Testing

- Cover queued `wait` and `terminate` requests that exceed their deadlines.
- Verify that a timed-out `wait` reports the error and reconnects on the next
  code-mode execution.

GitOrigin-RevId: 5d772e5a6f3793aa8865a1160639b851fd4824fb
2026-08-04 03:23:48 +00:00
Dylan Hurd
b2dc8b3e4b Consolidate approval telemetry context (#36825)
## What changed

Add the tool name to `ApprovalCtx` and use the context's call ID and session
telemetry when recording approval decisions. This removes redundant `ToolCtx`
and telemetry parameters from `resolve_tool_approval`.

GitOrigin-RevId: 238a6f708f83993d64606bfaa74df344b0b46178
2026-08-04 02:29:43 +00:00
Dylan Hurd
64bb8094ba Fix typo in approval resolver name (#36822)
Rename `resolve_tool_apporval` to `resolve_tool_approval` and update its
call sites in the tool orchestrator.

GitOrigin-RevId: bc7d9ae675b45dd5b6b5b5643fd75e532f6314ca
2026-08-04 02:03:22 +00:00
Boyang Niu
7431f10d0d Identify agents by name in token budget context (#36815)
## What changed

- Replace the thread ID in `<context_window>` metadata with the session's canonical agent path.
- Default sessions without an agent path to `/root`.
- Verify that root sessions emit `/root` and subagent sessions emit their own path, such as `/root/worker`.

GitOrigin-RevId: bcf057842ed31f93d554b7de063b6c03403a2594
2026-08-04 00:51:53 +00:00
Channing Conger
60c722e075 Add a dual-WebSocket transport for code mode (#36812)
## Why

Large nested-tool callbacks can occupy a WebSocket and delay unrelated session
operations on the same code-mode connection.

## What changed

- Negotiate the optional `dual-websocket-v1` capability and pair a second,
  token-scoped WebSocket with the control connection.
- Route nested-tool callbacks and their results over the bulk socket while
  keeping session operations, notifications, and execution responses on the
  control socket. Reject messages sent on the wrong lane.
- Preserve the single-connection transport when the capability is unavailable,
  and bound pairing, queued callbacks, and deferred cross-socket messages.
- Defer callbacks that arrive before their execution-started response, and
  return delegate errors without disconnecting the connection.

## Testing

Add protocol, transport, driver, and WebSocket integration coverage for
capability negotiation, lane routing, pairing failures, out-of-order messages,
and progress during large concurrent tool results.

GitOrigin-RevId: fa4504653e7cbf3c4ec930ae57aa0a41345bad66
2026-08-03 23:48:28 +00:00
sayan-oai
b258c028fe Honor per-environment login shell policy (#36811)
## What changed

- Store the effective `allow_login_shell` setting on each turn environment, including inherited environments whose child thread has a different policy.
- Expose the `login` argument for shell tools when any selected environment permits login shells.
- Validate each command against the policy of its selected environment instead of the turn-wide configuration.

## Testing

- Cover tool schema generation for single and multiple environments.
- Cover login-shell rejection by both the command handler and the unified exec integration.

GitOrigin-RevId: 5a93149a5c86f4087f2b92d663ebc33feff8a57c
2026-08-03 23:33:05 +00:00
thomas
61dc1d97f6 Add MCP client conformance regression gates (#36810)
## What changed

- Add a harness that runs the Codex executable against a pinned official MCP
  client conformance suite across shipping, intermediate, and modern protocol
  versions, HTTP and stdio transports, and OAuth scenarios.
- Add a separate app-server regression matrix for transport, security, schema,
  pagination, SSE, multi-round request, and catalog-boundary behavior.
- Check both suites against committed baselines so previously passing or
  required checks cannot disappear or newly fail, while keeping known failures
  visible in complete reports.
- Run the fixture self-tests and both executable-level gates from the Python
  and TypeScript SDK test workflows.

## Testing

- Add unit tests for the fixture server, official-suite adapter, conformance
  runner, baseline comparison, and reviewer regression runner.

GitOrigin-RevId: de59f039294e34ed72873d9f6940b52e89172c0d
2026-08-03 23:20:41 +00:00
Charlie Marsh
41e2f67e56 Prefer the state database for exec resume --last (#36809)
## Why

Successful `codex exec resume --last` lookups should not need to audit every rollout file.

## What changed

- Query the state database first when it is available and treat the first usable matching entry as authoritative.
- Verify that an indexed rollout's session ID matches the indexed thread ID before resuming it.
- Fall back to scanning rollouts after a complete database miss, allowing the existing backfill path to repair missing entries.

## Testing

Added integration coverage for missing database entries, usable indexed candidates, and mismatched indexed rollout paths.

GitOrigin-RevId: 9959dacbc908e97f1073118142f276b470aa8e06
2026-08-03 23:10:34 +00:00
Charlie Marsh
9c8f9ce897 Prefer SQLite names for local session archive commands (#36808)
## What changed

- Resolve local `archive`, `delete`, and `unarchive` targets from SQLite before falling back to rollout scanning and repair.
- Verify each SQLite match points to a rollout in the expected active or archived collection with the same session ID, skipping stale entries safely.
- Preserve the existing server-side lookup behavior for remote workspaces and compatibility sorting for external app servers.

## Testing

Added coverage for archiving and unarchiving by SQLite-backed names, preferring renamed SQLite metadata over the legacy index, and skipping a stale duplicate during deletion.

GitOrigin-RevId: 5275b94e1132ca7cdbdd1adc3293d2ccc685ff6d
2026-08-03 23:05:35 +00:00
Sean Huang
cc03518c36 Extract audio preparation into a utility crate (#36807)
## What changed

- Add `codex-utils-audio` as a workspace crate for canonicalizing audio inputs
  and estimating their token usage.
- Update `codex-core` to consume the new crate while preserving the existing
  audio preparation tests.

GitOrigin-RevId: d719ecc08363ef52778aa37f3df0ca14f7778324
2026-08-03 22:46:26 +00:00
felixxia-oai
1bbfb5cfad Avoid reinjecting permissions after command approvals (#36800)
## What changed

- Track approved command prefixes separately from the stable permissions
  instructions in world-state snapshots.
- Emit only newly approved prefixes after an exec-policy amendment instead of
  appending the full permissions block again.
- Preserve prefix updates when full permissions instructions are disabled and
  remain compatible with legacy world-state snapshots.

## Testing

- Cover incremental prefix additions, removals, legacy snapshots, history
  rollback, and approval flows with permissions instructions enabled or disabled.

GitOrigin-RevId: e6f68c6a91be82750e70e28456f2b7c58607fbd8
2026-08-03 21:37:17 +00:00
Adam Perry @ OpenAI
51d4aa946c Normalize rusty_v8 checksum manifest line endings (#36797)
## What changed

- Write staged `rusty_v8` checksum manifests with LF line endings on every platform.
- Strip carriage returns when verifying manifests so existing Windows-built releases with CRLF line endings remain usable.

## Testing

- Assert that staged checksum manifests contain no carriage returns.

GitOrigin-RevId: 142855c147a08a60f5e5782c61e2fcd6b2e350d6
2026-08-03 20:41:24 +00:00
jacobzhou-oai
bd12b3a9ec Add Agent Plugins MCP config parsing (#36796)
## What changed

- Add `parse_agent_plugin_mcp_config` to translate Agent Plugins v1 `mcp.json` files into Codex MCP server configuration.
- Normalize `stdio` and streamable HTTP transports, including `PLUGIN_ROOT` and `PLUGIN_DATA` expansion, contained plugin paths, secure endpoint validation, and filtering of client-owned HTTP headers.
- Keep valid sibling servers when another server is invalid, while returning per-server parse errors.
- Preserve UTF-8 HTTP header values when forwarding streamable HTTP protocol headers.

## Testing

- Cover transport mapping, placeholder expansion, path containment, schema and field validation, per-server errors, platform-specific environment handling, and UTF-8 headers.

GitOrigin-RevId: ed4ab0fcf495afbb381ce48beb93989629444c56
2026-08-03 20:36:59 +00:00
Colin Young
3149fa4b99 Terminate timed-out Git process trees (#36793)
## Why

Timing out a Git metadata command must not leave helper processes running after
the command wrapper exits.

## What changed

- Run Git metadata commands in a dedicated process group on Unix and a Job
  Object on Windows so timeout cleanup terminates their full process trees.
- Start Windows commands suspended, assign them to the Job Object, and then
  resume them so immediate descendants cannot escape containment.
- Preserve descendants when a Git command completes normally, and retain the
  existing direct-spawn fallback if Windows Job Object setup fails.

## Testing

Added cross-platform regression tests for cleanup both while the command wrapper
is running and after it exits, plus Windows coverage for immediate-child Job
Object containment.

GitOrigin-RevId: 351851708e23ff06b89fe1894bd09a3558f67293
2026-08-03 20:00:49 +00:00
rhan-oai
e4e0c7070e Gate plugin usage instructions by model capability (#36792)
## What changed

- Add `include_plugin_usage_instructions` to model metadata, defaulting to false.
- Emit generic plugin guidance only when plugins are available and the selected model enables it.
- Enable the capability for interactive model presets while leaving `codex-auto-review` opted out.

GitOrigin-RevId: 67f5a97e978033f5f1d533956c0b9deeae610283
2026-08-03 19:51:43 +00:00
rhan-oai
df72fdb415 Consolidate model instructions in ModelMessages (#36787)
## What changed

- Remove `ModelInfo.base_instructions` as an in-memory instruction source and use `model_messages.instructions_template` consistently for bundled, remote, fallback, and overridden model metadata.
- Preserve compatibility by promoting legacy `base_instructions` values when reading model responses and caches, and by including rendered legacy instructions when serializing `ModelsResponse` for older clients.
- Treat templates without instruction variables as literal text and retain the other model-message fields when applying instruction overrides.

This completes the consolidation proposed in https://github.com/openai/codex/pull/31302.

## Testing

- Cover legacy response and cache migration, canonical-template precedence, fallback instructions, personality rendering, overrides, and model switching.

GitOrigin-RevId: 089d986ca5e30da67db2c77a1b6a046d2cff52dc
2026-08-03 19:30:40 +00:00