Commit Graph

4475 Commits

Author SHA1 Message Date
arun eswara
edcec13372 Expose image generation usage-limit failures (#38024)
## What changed

- Add structured `usageLimitExceeded` metadata to failed image-generation
  items, including the image limit ID and optional reset timestamp.
- Preserve the failure metadata in completion events, app-server thread
  history, thread reads and resumes, and migrated legacy rollouts.
- Export the new failure type in the generated JSON and TypeScript schemas.

## Testing

- Cover usage-limit responses through item completion, persistence, and thread
  resume.
- Verify legacy rollout migration retains image-generation failure metadata.

GitOrigin-RevId: 91c31a2a47456b6b916ee03002ff314b05946dd4
2026-08-11 15:40:52 +00:00
jif
279b93242c Remove config lockfile support (#38011)
## What changed

- Remove effective-config lockfile export, replay, and validation from session startup.
- Remove the `debug.config_lockfile` settings and generated schema entries.
- Remove feature-config materialization helpers that were only used to create lockfiles.

GitOrigin-RevId: a8c07c1c06325b3ec3dae9a97c36c2488d37df25
2026-08-11 13:52:48 +00:00
felixxia-oai
3d4d253f8f Stop re-exporting skill APIs from codex-core (#37984)
## What changed

- Import skill metadata and mention helpers directly from `codex-skills`.
- Import host skill loading types directly from `codex-skills-extension`.
- Make the remaining `codex-core` skills module private and remove its skill API re-exports, including the `HostSkillsService` re-export from `codex-core-api`.

GitOrigin-RevId: 26bf8fffd980df9c4d0c308d7e983ceab9a5df82
2026-08-11 10:43:11 +00:00
felixxia-oai
7d486ffa94 Honor per-directory bundled skill settings in skills/list (#37979)
## Why

`skills/list` can load multiple working directories in one request, but bundled
skill discovery did not account for different effective configurations across
those directories.

## What changed

- Resolve `skills.bundled.enabled` from each load input's effective config layer
  stack inside the host skills service.
- Include or exclude system-scoped skills for each working directory based on
  that resolved setting.
- Keep bundled skills enabled by default when the setting is absent or invalid.

## Testing

- Add a multi-directory `skills/list` test with bundled skills disabled in one
  project and enabled in another.
- Add config-layer tests for defaults, overrides, and malformed bundled-skill
  configuration.

GitOrigin-RevId: e4e97dc7d0a374ac71d0aa11e55a9e337f661717
2026-08-11 10:20:54 +00:00
jif
0ca439900e Cache tool catalogs for streamable HTTP MCP servers (#37970)
## Why

Subagents should be able to use known HTTP MCP tool definitions without opening a connection until a tool is actually called.

## What changed

- Add streamable HTTP configurations to the process-scoped MCP tool catalog cache when their authentication identity can be derived safely.
- Fingerprint transport settings, relevant environment variables, protocol mode, plugin status, and client capabilities so catalogs are reused only across equivalent connections.
- Keep OAuth and other dynamically resolved credential configurations out of the shared cache.

## Testing

- Add an integration test proving that a subagent receives cached HTTP tools without reinitializing the server, then starts its own connection when it calls one.

GitOrigin-RevId: bb2787e29e9b71993def31aafd1f0d8f1b728d26
2026-08-11 09:22:50 +00:00
rka-oai
41ece455b7 Validate images before returning view_image output (#37939)
## What changed

- Reject invalid or unsupported image data before producing tool output, so
  non-image file contents are not exposed through code mode.
- Preserve valid image bytes and metadata while leaving image preparation and
  resizing to the history insertion path.

## Testing

- Cover invalid images in both code mode and standard `view_image` calls.
- Verify that code mode preserves PNG bytes, dimensions, EXIF orientation, and
  metadata.

GitOrigin-RevId: 07343ed10b781d0ce0ffb5b24432658be4c046e3
2026-08-11 05:32:28 +00:00
Bryan Ashley
722784e936 Distinguish turn-start thread persistence (#37926)
## What changed

- Add `PersistContext` to the thread-store persistence contract so stores can
  identify persistence requested immediately before model sampling. A
  `TurnStart` request may be enqueued in the background when later flush and
  shutdown operations fence it and report any failure; all other persistence
  remains synchronous.
- Use the turn-start context only for the initial input of a regular turn, while
  admission acknowledgments, steered input, and other persistence paths keep
  the standard durability behavior.
- Flush pending metadata before turn-start persistence and ensure shutdown is
  still attempted if that metadata update fails.

## Testing

- Verify that developer instructions and user input are persisted before the
  model request completes for a default paginated-history thread.

GitOrigin-RevId: 162f0ec796a61aebe66ca0b909fbcccec3047b85
2026-08-11 03:35:45 +00:00
Abhinav
070a26a1f0 Apply refreshed cloud config bundles to later sessions (#37908)
## Why

Background refreshes previously warmed only the on-disk cache, so new sessions in the same process continued using the startup snapshot.

## What changed

- Make `CloudConfigBundleLoader` retrieve the latest shared bundle on each configuration load.
- Update the in-memory bundle after successful refreshes while preserving the last successful bundle when a refresh fails.
- Stop refresh work when its loader is replaced or its final clone is dropped.

## Testing

- Cover refreshed requirements and managed configuration in later sessions.
- Cover concurrent initial loads, refresh failures and recovery, bundle clearing, and refresh-task cancellation.

GitOrigin-RevId: ae3d79b575bad71a1eed370cee6dc66dc022ffa8
2026-08-11 01:05:48 +00:00
rka-oai
260261ed8f Defer view_image processing to history insertion (#37902)
## What changed

- Pass image bytes from `view_image` through unchanged for both direct and code-mode calls, leaving decoding and resizing to the shared history-insertion path.
- Represent invalid image data with the existing image-omission placeholder instead of returning a tool error.

## Testing

- Update the `view_image` integration test to cover placeholder output for invalid image data.

GitOrigin-RevId: 62863defd4815efb8a7725712fd583ad81db3fbb
2026-08-11 00:17:36 +00:00
Owen Lin
ab3b4d26d4 Make submission operations move-only (#37901)
## What changed

- Remove `Clone` from `Submission` and remove `Clone` and `PartialEq` from `Op`.
- Consume operations directly in the submission loop instead of cloning them.
- Limit thread-manager test capture to the operation variants under test and update assertions to compare their relevant fields.

GitOrigin-RevId: 781cc631391b8583d94dad5ca45f589856c0b21a
2026-08-10 23:41:52 +00:00
knittel-openai
9e301c8c9a Add configurable Responses API request metadata (#37895)
## What changed

- Add `responses_api_metadata` for product-owned key/value metadata included in
  every Responses API turn metadata payload, including parent and subagent
  requests.
- Limit the map to 16 entries, ASCII identifier keys of at most 64 bytes, and
  values of at most 128 bytes. Reject reserved Codex metadata keys and ignore
  this setting in project-local configuration.
- Give configured product metadata precedence over app-server client metadata
  while keeping it out of metadata sent to external MCP servers.

## Testing

- Cover reserved-key validation, metadata precedence, MCP isolation, and
  propagation to parent and subagent Responses API requests.

GitOrigin-RevId: a7be798294fde25145ab375a468321bb4e4a49f1
2026-08-10 22:58:53 +00:00
Vivian Fang
7a18a5c528 Validate images before returning view_image output (#37892)
## What changed

- Decode image data in the `view_image` handler and return a clear error for invalid or unsupported input.
- Re-encode code-mode images as PNG pixel data while preserving original image bytes for direct tool calls.
- Cover code-mode PNG output and rejection of invalid image data.

GitOrigin-RevId: 0a00e595ab749c19eab866a22f6577b6627e19f1
2026-08-10 22:43:47 +00:00
ftoddywala
9558d830f6 Read safety buffering from response metadata (#37882)
## What changed

- Parse safety-buffering payloads from typed `response.metadata` SSE events.
- Preserve the existing top-level `safety_buffering` field as the authoritative value when it is present, including when it is null or malformed.
- Continue applying the header-provided fallback model when the metadata payload omits `retry_model`.

## Testing

- Add parser coverage for metadata fallback, top-level precedence, and unrelated metadata events.
- Exercise metadata-based safety-buffering delivery through the core SSE integration test.

GitOrigin-RevId: 7dadfd54be28f2f33c2283de92fd49da0557d98a
2026-08-10 21:50:55 +00:00
Eric Traut
a9dee37f9c Add configurable goal token budget limits (#37878)
## What changed

- Add `goals.max_goal_token_budget` as a positive-integer configuration setting.
- Use the configured maximum as the default budget for new goals and when `tokenBudget` is reset to `null`.
- Reject goal creation and updates whose token budget exceeds the configured maximum, including requests through goal tools and `thread/goal/set`.
- Respect managed configuration precedence and per-thread configuration overrides.

## Testing

- Cover configuration parsing and managed overrides.
- Cover defaulting, resetting, and rejecting oversized budgets through the goal service, goal tools, and app-server API.

GitOrigin-RevId: f8d7e6418cdc237d454c8cf47bb32ba0d44a60cf
2026-08-10 21:00:00 +00:00
iceweasel-oai
a603d7ca5c Honor the configured Windows sandbox level for managed networking (#37875)
## Why

Managed networking implicitly selected the elevated Windows sandbox backend,
even when the sandbox was configured to use a restricted token.

## What changed

- Select the Windows sandbox backend solely from `WindowsSandboxLevel`.
- Reject managed networking with a restricted-token sandbox before spawning a
  process, since managed networking requires the elevated backend.
- Cover the rejection through sandbox preparation, unified exec, and Windows
  sandbox session tests.

GitOrigin-RevId: 308858652d7b629af623d22896dafde3a23d3758
2026-08-10 19:57:40 +00:00
Adam Perry @ OpenAI
63002bdb26 Extract persisted history types into a dedicated crate (#37871)
## What changed

- Add `codex-history` for model-history and persisted-rollout domain types, including `RolloutItem`, `RolloutLine`, `CompactedItem`, and initial/resumed history state.
- Re-export the persisted types from `codex-rollout` and update consumers to use the new crate boundary instead of `codex-protocol`.
- Preserve existing rollout serialization, including legacy numeric compacted-window IDs.

## Testing

- Add `codex-history` tests for rollout JSON round trips, compacted-history compatibility, persisted history modes, and multi-agent version selection.

GitOrigin-RevId: 944daa9297ddd231d3aebbdcb05fff4adf8b4e1b
2026-08-10 19:26:52 +00:00
viyatb-oai
a1c88e865d Reject duplicate resolved paths in apply_patch (#37867)
## What changed

- Reject patches containing multiple operations whose paths resolve to the same file, such as `duplicate.txt` and `./duplicate.txt`.
- Preserve support for patches that update multiple distinct files.

## Testing

- Add CLI integration coverage for distinct updates and duplicate resolved paths.

GitOrigin-RevId: 0fb7f69ae31acc5c677268ffd9e38ad8d8314276
2026-08-10 18:44:58 +00:00
jif
dd22460869 Add MCP OAuth credential contention regression tests (#37866)
## What changed

- Cover non-blocking credential probes when the file or secrets store is locked, including retaining only a matching prior credential snapshot and recovering after the lock is released.
- Extend the streamable HTTP OAuth round trip to verify that user turns continue during store contention, newly discovered servers recover after contention, and logged-out servers do not reuse authenticated connections.
- Cover reconciliation of authentication failures and effective `Authorization` headers.

GitOrigin-RevId: 8e377644001bd0be04dc9f79841080094d09d199
2026-08-10 18:40:02 +00:00
mchen-oai
4b0e2a0bff Support MCP form input in full-access user threads (#37864)
## Why

Standard MCP forms can require user-entered values even when tool permissions are
otherwise auto-approved in full-access sessions.

## What changed

- Recognize the `openai/standard-form-input` client extension and surface
  non-approval forms in full-access, user-initiated root threads.
- Keep approval forms, automation and subagent threads, headless sessions, and
  clients without the capability on their existing decline or review paths.
- Treat the capability as client-only so it is not advertised to MCP servers,
  and enable it after session startup so required servers cannot block startup
  waiting for form input.

## Testing

Add unit and app-server coverage for accepted form round trips, declined cases,
approval metadata safeguards, resumed threads, and extension filtering.

GitOrigin-RevId: 053bfe397a5c79eceef90a81d13e2aca6353af43
2026-08-10 18:20:12 +00:00
sayan-oai
ee7815dad2 Rename environment config for turn scope (#37862)
## What changed

- Rename `EnvironmentConfig` to `TurnEnvironmentConfig` to make its scope explicit.
- Rename the corresponding `SessionConfiguration` accessor and update all call sites.

GitOrigin-RevId: f47d745566199e699bd8e7c671c313eaf3bba79e
2026-08-10 18:03:46 +00:00
Dylan Hurd
d06dc73290 Route intercepted exec approvals through shared review (#37851)
## What changed

- Send Unix `execve` approvals intercepted by the zsh fork through the shared approval pipeline, including permission hooks, Guardian review, user prompts, and telemetry.
- Resolve the active turn and its auto-review setting when an intercepted command needs approval, so commands sent to persistent terminals use the current turn's reviewer.
- Give each intercepted command a distinct approval ID and propagate an aborted approval as a turn abort.

## Testing

- Cover Guardian review for intercepted `unified_exec` commands and persistent terminals across turns.
- Verify repeated identical intercepted commands receive separate user approvals.

GitOrigin-RevId: e6cccf160637e4246aff4714c22f08c90b65306d
2026-08-10 17:24:51 +00:00
jif
97729885d4 Expose the session ID to shell commands (#37848)
## What changed

- Set `CODEX_SESSION_ID` to the shared root-session ID for shell tool calls,
  unified exec processes, and user shell commands.
- Preserve `CODEX_SESSION_ID` when restoring a shell snapshot, alongside the
  existing runtime-owned environment variables.

GitOrigin-RevId: 5228867d25507105c7edf11607a8298958c3b917
2026-08-10 17:02:19 +00:00
jif
4996cf05af Preserve environments when reloading V2 agents (#37847)
## What changed

- Restore a V2 agent's inherited environment selections when reloading its
  thread after residency eviction.
- Keep the restored execution environment and its tools available when the
  agent receives a follow-up task.

## Testing

- Add an integration test that evicts and reloads a V2 agent, then verifies
  its environment selection and `exec_command` tool are preserved.

GitOrigin-RevId: a5d4ad0fa465c717b32b7ae6807486429187a41d
2026-08-10 16:57:09 +00:00
felixxia-oai
3b67b03a3f Run plugin and skill tests on Windows (#37836)
## Why

The plugin and skill test suites were excluded wholesale on Windows, even though
most cases do not depend on POSIX behavior.

## What changed

- Make generated TOML and JSON fixtures escape Windows paths correctly.
- Use Windows-safe path canonicalization and normalize advertised skill paths.
- Select test environments through the environment-aware builders.
- Run the suites on Windows while narrowly skipping cases that execute POSIX
  commands or require matching host and executor path conventions.

GitOrigin-RevId: aadf31013c2bf9bac728adc4dd96f572d4a3bf3f
2026-08-10 14:45:55 +00:00
jif
d109393270 Track running unified exec processes at turn completion (#37828)
## What changed

Add the `codex.turn.unified_exec.running_processes` counter and increment it
by the number of background terminal processes remaining when a turn finishes.

GitOrigin-RevId: 82a33b89533960d86cef95360fa122836c8aa84d
2026-08-10 13:39:23 +00:00
Charlie Marsh
1c042dd4d8 Keep multi-workspace skill listings consistent (#37812)
## Why

A single `skills/list` request should use one view of shared skill roots across
all requested workspaces while still applying each workspace's skill rules.

## What changed

- Add a request-scoped host skills view that reuses non-plugin root snapshots
  across `cwd` entries without persisting them across requests.
- Resolve user-scoped plugin skill roots once per request, then apply workspace
  skill configuration separately for each `cwd`.
- Make `forceReload` refresh plugin roots before building the request-scoped
  view so subsequent entries see the refreshed skills.

## Testing

Expanded `skills/list` and host skills service tests to cover multiple ordered
workspaces, per-workspace skill rules, request-local snapshots, cached results,
and forced plugin-root refreshes.

GitOrigin-RevId: eedd3a4c3e213b7f30df6cacd3adf23ba2967437
2026-08-10 11:27:22 +00:00
jif
09f47c8785 Simplify package-based skill reads (#37808)
## What changed

- Make `package` the only required argument to `skills.read`, resolving the
  owning orchestrator or executor catalog automatically.
- Default omitted `resource` values to the package's main `SKILL.md`.
- Render orchestrator skills as package locators and instruct the model to read
  them directly without first calling `skills.list`.
- Update skill extension and app-server coverage for direct main-resource
  reads, referenced resources, aliases, and the revised tool schema.

GitOrigin-RevId: 9faf57a8d0935566a15094931eaabaa8f0613e9e
2026-08-10 11:10:01 +00:00
Charlie Marsh
beeba1d2fc Share model-visible tool specs across prompts (#37807)
## Why

Building a prompt cloned every model-visible `ToolSpec`, even though the tool
set is immutable for the lifetime of its router.

## What changed

- Store model-visible tool specs as an `Arc<[ToolSpec]>` in `ToolRouter` and
  `Prompt` so prompt construction only clones the shared pointer.
- Keep separately built routers on distinct shared slices so refreshed tool
  sets remain independent.

## Testing

Extend router tests to verify allocation sharing within a router, allocation
separation across rebuilt routers, and the existing deferred-tool filtering.

GitOrigin-RevId: 1e04cd7c4d1b3fa0b494c5c51670232d38ba8ebb
2026-08-10 10:50:49 +00:00
Charlie Marsh
c9c6c0daa9 Add a feature flag to preserve apply_patch line endings (#37758)
## What changed

- Add the `apply_patch_preserve_line_endings` feature, disabled by default, to
  preserve CRLF, CR, and mixed line endings when `apply_patch` updates files.
- Apply the feature consistently to built-in patch handling and patches invoked
  through shell, user-shell, unified-exec, and app-server command execution.
- Keep the active feature configuration authoritative over inherited, shell
  snapshot, and client-provided environment values.

## Testing

- Cover line-ending behavior with the feature enabled and disabled for custom
  tool calls, shell heredocs, command execution, and the `apply_patch` CLI.

GitOrigin-RevId: 531a7c66761959c650270559f57941929f03e6c4
2026-08-10 01:44:30 +00:00
sayan-oai
420accf199 Use the step context for command approval prefix rules (#37641)
## What changed

Read `allow_prefix_rules` from the turn attached to the active step context
when selecting the exec policy and constructing unified exec approval requests.

GitOrigin-RevId: d2d26e88b9cefa28bb2df5b9f71aa7b30b7ea331
2026-08-09 00:29:14 +00:00
sayan-oai
dd43a9967f Use step environments for Guardian approval reviews (#37618)
## Why

Deferred environments can become ready after a turn starts. Guardian approval
reviews must use the environment selected for the current step so their working
directory and permission context are not taken from the stale turn snapshot.

## What changed

- Carry `StepContext` through tool execution and approval handling.
- Add a Guardian review context that pairs the parent turn with the current
  step's environment snapshot.
- Use that snapshot for Guardian prompts, reviewer sessions, and delegated
  reviewer threads while retaining turn-level fallbacks for callers without a
  step context.

## Testing

Added an integration test that makes a deferred remote environment ready before
an escalated command and verifies Guardian receives that environment's working
directory and denied-read policy instead of the initial local environment's.

GitOrigin-RevId: 779096bc7d0e0c7453a009c02141029714b9b407
2026-08-08 20:07:27 +00:00
cooper-oai
c4513cb982 Prevent launch context from reaching child processes (#37607)
## Why

Model-reachable child processes should not inherit Codex launch context.

## What changed

- Treat `OPENAI_FEDERATION_RULE_ID` and `OPENAI_IDENTITY_TOKEN_FILE` as non-inheritable environment variables, with case-insensitive matching.
- Remove them after shell environment policy overrides and before spawning commands across execution, MCP, hooks, Git helpers, and remote helper processes.

## Testing

- Cover inherited and explicitly configured variants, including mixed-case names.
- Verify the variables are absent from real child environments and app-server command and process execution.

GitOrigin-RevId: 2535527893985fef0995617f4c5b2462bea7c136
2026-08-08 16:58:26 +00:00
Abhinav
6f647caa9b Support asynchronous command hooks (#37533)
## Why

Hook configurations can mark command handlers as asynchronous, but Codex previously skipped those handlers outside `SessionEnd`.

## What changed

- Run asynchronous command hooks in the background with a per-session concurrency limit, while keeping `SessionEnd` hooks synchronous.
- Prevent asynchronous hooks from blocking, stopping, rewriting, or otherwise controlling the operation that launched them.
- Deliver warnings and additional context at safe turn boundaries: inject results into an active turn after sampling, or buffer them ahead of the next user prompt when the session is idle.
- Preserve in-flight hooks across configuration reloads, scope spilled output to the thread, and abort outstanding work during session shutdown.

## Testing

Add unit and integration coverage for background scheduling, concurrency, output parsing, active and idle result delivery, configuration reloads, and shutdown cleanup.

GitOrigin-RevId: 8094552e4afe7b47b09a61bb575bb20f4e491d8d
2026-08-08 04:24:12 +00:00
andrewgu-oai
e734a1a5c1 Ignore reusable command approvals for cyber models (#37516)
## What changed

- Filter saved `allow` prefix rules from the execution policy for cyber-specialized models and models listed in `auto_review.ignore_rules`, while preserving prompt, forbidden, network, and host-executable policy entries.
- Apply the filtered policy consistently to permission instructions, shell commands, unified exec, and the zsh-fork backend.
- Limit cyber-model command approvals to one-time decisions without proposing reusable policy amendments. General models continue to honor saved prefixes, including after switching models within a thread.

## Testing

- Add policy-level coverage for filtering allow-prefix rules while retaining restrictive and network rules.
- Add end-to-end coverage across shell and unified exec paths, zsh-fork execution, user and automatic review, and model switching.

GitOrigin-RevId: f3bd3872424291b12354ec415f33986ec369a368
2026-08-08 00:59:39 +00:00
Won Park
c2bcb9a26b Reuse parent compactions in Guardian review sessions (#37513)
## What changed

- Add the under-development `guardian_reuse_parent_compaction` feature.
- Restart Guardian review sessions after parent history rewrites and seed them with the latest encrypted compaction that has a response item ID.
- Keep the existing reviewer when a rewritten history has no reusable compaction, preserving authorization and restriction context held by that session.

## Testing

- Cover reuse-key invalidation and compaction eligibility.
- Verify review-session behavior across parent compaction and a subsequent summary-free history reset.

GitOrigin-RevId: 891805d3c3dca34ddda6e3bfc5097be4ff164267
2026-08-07 23:49:12 +00:00
viyatb-oai
208f05b233 Enforce automatic review for managed models (#37511)
## What changed

- Add the managed `auto_review.required_on_models` requirement, unioning model slugs across requirement layers and exposing the result through `configRequirements/read`.
- Force listed models to use `on-request` approvals with the `auto_review` reviewer. Downgrade Full Access to workspace-write when starting a protected session, and reject incompatible runtime overrides or use when automatic review is disabled.
- Preserve these protections across thread starts, resumes, forks, model changes, turn overrides, MCP approvals, and TUI session attachment.

## Testing

- Add coverage for layered model requirements and exact provider-alias matching.
- Add app-server tests for protected thread lifecycle operations, unsafe setting overrides, legacy thread upgrades, disabled automatic review, and requirements API output.

GitOrigin-RevId: c4b1d52c3b5b75e86880725412b8f0812e0dfcd9
2026-08-07 23:43:14 +00:00
sayan-oai
4ca25a2c4e Include sandbox mode in response metadata (#37507)
## What changed

- Add the effective permission profile as `sandbox_mode` in turn metadata for regular, prewarm, compaction, and detached memory requests.
- Reserve `sandbox_mode` so client-provided metadata cannot override the computed value.

## Testing

- Cover metadata headers and request bodies for read-only and danger-full-access modes.

GitOrigin-RevId: 13c690cc99bc2691023f281ca527af049bb1286f
2026-08-07 22:41:20 +00:00
felixxia-oai
45f8cafa4e Remove the codex-core-skills crate (#37505)
## What changed

- Move `SkillLoadOutcome` and its implicit-path indexing into
  `codex-skills-extension`.
- Import shared skill types directly from `codex-skills` and keep the skill
  prompt size limit with the extension renderer that uses it.
- Remove `codex-core-skills` from the Cargo workspace and dependent crates.

GitOrigin-RevId: 4e9e84909fa2f692bcc94af990bb4671affd776f
2026-08-07 21:36:33 +00:00
felixxia-oai
beac16cccd Move host skill prompt injection into the skills extension (#37503)
## What changed

- Add `HostSkillsSnapshot::load_skill_prompts` so the skills extension owns reading and rendering selected host skills.
- Keep explicit invocation telemetry, unreadable-skill warnings, plugin prompt ordering, and suppression of host prompts superseded by provider prompts.
- Remove the legacy prompt injection and fragment implementation from `codex-core-skills`.

## Testing

- Cover prompt truncation without an installed skills extension, skill/plugin ordering, selective provider supersession, unreadable skills, and contextual fragment detection.

GitOrigin-RevId: 9c8b84ad54b90d174abc287ab49cc5a231e9e1aa
2026-08-07 21:04:16 +00:00
rka-oai
8e4b10446e Remove the legacy code-mode tool metadata inventory (#37500)
## What changed

- Stop adding `code_mode_tool_names` to Responses Lite turn metadata.
- Keep `code_mode_tool_names` reserved so client metadata cannot reintroduce the removed, unbounded inventory.
- Use the opt-in `tool_namespaces_info` metadata, including each function's `code_mode_name`, when authoritative tool details are requested.

## Testing

- Update Responses Lite and code-mode tests to verify the opt-in namespace metadata and normalized code-mode names.

GitOrigin-RevId: cbfb9af984de71c7cc175d0cd47ae799a5275309
2026-08-07 20:26:08 +00:00
rka-oai
2b1811e562 Include tool namespace inventory in turn metadata (#37492)
## What changed

- Add opt-in `tool_namespaces_info` metadata for Responses Lite turns when
  `tool_registry.turn_metadata_includes_tool_info` is enabled.
- Describe each model-visible function's namespace, direct and deferred
  exposure, Code Mode name, and harness or MCP ownership.
- Reject visible namespaces shared by different owners when strict collision
  checking and tool inventory metadata are enabled.
- Keep tool inventories out of compatibility headers and metadata sent to MCP
  servers.

## Testing

- Cover opt-in behavior, MCP exposure details, namespace ownership collisions,
  reserved metadata handling, and Responses Lite request serialization.

GitOrigin-RevId: 6a6965d2ba98e29444fdfbb4ccec6aafcf0391e6
2026-08-07 19:32:15 +00:00
rphilizaire-openai
ba94150c2a Alias resource-backed skill locators under context pressure (#37489)
## Why

Long executor and orchestrator resource identifiers can consume enough of the
skills context budget to omit otherwise available skills.

## What changed

- Add source-aware root aliases for executor, orchestrator, and host skill
  catalogs, including catalogs with a single shared root.
- Select the best combination of aliased catalogs under the shared metadata
  budget while accounting for root tables and alias usage instructions.
- Explain how to expand shortened `skill://` locators and accept the resulting
  description-shortening warning in app-server coverage.

## Testing

- Add rendering and production-turn coverage for singleton, executor,
  orchestrator, host, and combined catalog aliases.

GitOrigin-RevId: c1bc1f3d371eae9526232674060235272cc28f16
2026-08-07 19:09:46 +00:00
jif
27e4a05cd3 Expose runtime activity in server diagnostics (#37486)
## What changed

- Add lifecycle-backed gauges for in-flight and queued app requests, pending server requests and mailbox messages, active turns, and live MCP connections.
- Register each gauge on first use and decrement it when the tracked work or resource is dropped.
- Document the new `server/diagnostics` gauge names and account for the diagnostics request itself in the response example and test.

GitOrigin-RevId: 4bb82a3918af0b502d149b5d761ad669b2083f39
2026-08-07 18:38:24 +00:00
jif
5a0d0929e2 Keep response streams alive through connection failures (#37485)
## What changed

- Classify HTTP connection failures separately from other network errors without exposing request URLs.
- For sampling requests, retry connection failures with exponential delays from 5 to 60 seconds and show a `Reconnecting... waiting for network` stream error.
- Preserve the normal stream retry budget while waiting for the provider to become reachable. Keep the existing bounded retry behavior for other retryable errors.

## Testing

- Verify connection errors are classified without leaking URL contents.
- Verify a turn recovers after its provider becomes reachable and still applies the configured retry limit to a subsequent incomplete stream.

GitOrigin-RevId: 646553290c865a1332abd30c4a64ed9266bbfc6f
2026-08-07 18:33:46 +00:00
pakrym-oai
509565820f Interrupt active code-mode cells with their turn (#37483)
## Why

Interrupting a turn should also stop code-mode work that the turn left running.

## What changed

- Add the disabled-by-default `code_mode_interrupt` feature.
- When an interrupted turn has the feature enabled, terminate all active code-mode cells and propagate cancellation through nested tool calls.
- Keep the reusable code-mode session alive so its stored state remains available to later turns.

## Testing

Add an integration test that interrupts a long-running nested tool, verifies that active and background cells are removed, and confirms that session state is preserved.

GitOrigin-RevId: 2b8634776a89b636318a39b9e9ad2eefc07cead8
2026-08-07 18:22:42 +00:00
iceweasel-oai
511262b984 Delegate remote process sandboxing to the executor (#37480)
## What changed

- Preserve executor-native working directories, workspace roots, and permission profiles when preparing remote `exec_command` requests instead of resolving them through the host platform.
- Send sandbox intent to the remote executor, including a restricted-token default for Windows executors and `-NoProfile` for elevated PowerShell commands.
- Reject intercepted cross-platform `apply_patch` commands when filesystem writes are restricted, while continuing to allow them for unsandboxed or full-disk-write profiles.

## Testing

Extended remote unified-exec coverage for foreign Windows workspaces, elevated PowerShell, sandbox metadata, and restricted and unrestricted intercepted patches.

GitOrigin-RevId: 9fd328879fa2c15594fd58e40b6b32e8ba0847e7
2026-08-07 18:05:17 +00:00
tongzhou wang
248d8c0e22 Include call IDs in MCP requests and clarify metadata config (#37477)
## What changed

- Add the tool call ID to `_meta.callId` for every MCP tool request.
- Rename `features.tool_registry.include_tool_metadata` to
  `features.tool_registry.turn_metadata_includes_tool_info` to clarify that the
  setting controls authoritative tool information in per-turn metadata.
- Update config parsing, schema generation, and session config locking for the
  renamed setting.

## Testing

- Cover `callId` metadata for custom, plugin, and Codex Apps MCP calls.
- Update strict-config, config-loading, feature-config, and config-lock tests for
  the renamed setting.

GitOrigin-RevId: ac0e58c489b03bd9b55a356f545de86c8ecaf865
2026-08-07 17:44:05 +00:00
felixxia-oai
b3278e96cb Move skill config rule resolution into codex-config (#37466)
## What changed

- Define skill config selectors, ordered rules, and layer-stack parsing in `codex-config`.
- Resolve disabled skill paths from generic skill name/path pairs, so configuration logic no longer depends on `SkillMetadata`.
- Update plugin and host skill consumers to use the `codex-config` API and consolidate the rule tests with the skill config tests.

GitOrigin-RevId: 3fe67869708df2652befe28d58cdeba933256f84
2026-08-07 16:20:38 +00:00
felixxia-oai
3b366654f1 Remove the unused remote skills client (#37461)
## What changed

- Remove the unused `core-skills` client for listing and exporting remote
  skills.
- Remove its `codex-core-skills` and `codex-core` exports and dependencies that
  are no longer needed.

GitOrigin-RevId: 747f760dc97da3d4dea10d619a2341f43410d0bf
2026-08-07 15:38:22 +00:00
felixxia-oai
33e365b19e Remove the legacy core skill loader (#37457)
## What changed

- Use `HostSkillRoot` throughout host root resolution and loading, including plugin roots.
- Remove the duplicate loader, root snapshot, and product-filtering implementation from `core-skills` now that loading is owned by the skills extension.
- Move and expand loader coverage for discovery, namespaces, filesystem routing, root merging, symlinks, and frontmatter parsing.

## Testing

- Added focused unit and integration tests under `ext/skills` and `skills` for the consolidated loader behavior.

GitOrigin-RevId: 214d06d59bf3033ee0f220ea5959ee4feff66782
2026-08-07 15:16:06 +00:00