## Why
Guardian request and section cost distributions need shared bucket boundaries across synchronous and asynchronous reviewers so their measurements align.
## What changed
- Add `histogram_with_boundaries` to session telemetry and extension metrics while preserving session attribution.
- Use shared request-token buckets up to 2,000,000 tokens and section-cost buckets up to 16,777,216 for both review paths.
## Testing
Extend telemetry tests to verify explicit bucket boundaries and sample counts, and Guardian integration coverage to check exported request and section metric bounds for both synchronous and asynchronous reviews.
GitOrigin-RevId: e34f6972b3418bac3b061939b62eeeccaec5a299
## Why
Session transitions need stack headroom to rebuild configuration and the chat widget. Tokio stores task outputs inline even when it boxes the task future, so returning a large `Config` adds stack pressure during task allocation.
## What changed
Box the configuration build result inside the runtime worker and unbox it after joining. Box the `App::run` future to keep the large event loop out of enclosing startup futures.
## Testing
Extend the production-stack TUI integration test to enter `/side`, verify the process remains running, and return to the saved conversation with Ctrl+C.
GitOrigin-RevId: 44975300bb837bf3645ff762cf7bcdc44a277f41
## Why
Diagnostic attachment reads assume the queued file path still exists and contains plain bytes. Compressed rollouts can therefore be omitted when only the logical `.jsonl` path is available, or attached as compressed data when a `.jsonl.zst` path is supplied.
## What changed
- Read rollout attachments through a bounded decoder that resolves plain or compressed representations without materializing a durable JSONL file.
- Use canonical `.jsonl` filenames for attachments and app-server report metadata, while preserving filename overrides.
- Apply size limits to decoded bytes and preserve JSONL prefix truncation.
## Testing
Add regression tests for compressed attachments, representation changes after queuing, plain-sibling preference, filename overrides, decoded size limits, truncation, nonregular files, and unrelated `.zst` attachments.
GitOrigin-RevId: b30f7dd08a741b0c99283460a1ce8933d2920ddf
## What changed
Add `ComposedContext::enforce_budget` to fit evidence within the input token allowance after reserving existing context. Preserve required content and message boundaries, reserve an omission notice, and return an error if required evidence cannot fit.
Carry retention policies through transcript rendering and composition. Protect user messages, protected messages, and the newest five tool entries. Remove oversized optional items first, then evict commentary, older tool evidence, and images in priority order. Add image admission support and record omitted content in truncation observations.
## Testing
Add tests for existing-context reservations, required-message preservation, image omission, framing costs, and protection of the newest five tool entries in both context profiles.
GitOrigin-RevId: 8a0f245bad82f562323b4533442385ddbcb6e541
## What changed
- Record per-section text bytes, estimated text tokens, image bytes, and image counts for synchronous reviews and asynchronous scoring without logging evidence payloads.
- Emit estimated request tokens through `codex.guardian.context.request_tokens`. Synchronous estimates include assembled history, instructions, tool definitions, and output format, and measure the full logical request before WebSocket delta generation. Asynchronous estimates cover the assembled input.
- Add shared context budgeting helpers, including conservative image token reservations independent of encoded payload size and model-aware input limit calculation.
## Testing
Add coverage for separate text and image accounting, image estimates independent of encoded size, and section estimates that bound delivered messages. Extend asynchronous scorer and app-server tests to verify cost metric emission.
GitOrigin-RevId: aed45ecd9c23706f88caa51f2a4f2c77872d3bdb
## Why
Cold rollout files can still have active writers. Compression must not replace their files while writes are pending, including background work that outlives the local thread store.
## What changed
- Share cross-process writer locks between the rollout compressor and local thread store. Skip busy threads and recheck file state under coordination before publishing compressed files.
- Retain writer ownership through recorder background I/O and compressed rollout materialization. Wait for writers to exit on shutdown or discard, and stop queued file work before deletion.
- Route rollout metadata patches through owned recorders, reject competing writers before updating SQLite, and serialize metadata appends with shutdown.
## Testing
Add regression coverage for compression with live and detached writers, parallel cold-file compression, publication locking, metadata ownership conflicts, updates to compressed rollouts, concurrent shutdown, and discarding deferred items.
GitOrigin-RevId: c52f4037eb2019e8095b554e29bf531af95aa4bd
## Why
Dormant MCP servers with usable cached tool catalogs prevented binding reuse, causing each model step to capture a new binding even when the catalog was unchanged.
## What changed
Track dormant catalog revisions alongside ready client revisions so bindings can be reused until the catalog changes or the server starts. Explicit server and plugin requirements still trigger binding capture and startup. Check cached catalog availability without cloning tool definitions.
## Testing
Extend the lazy-startup integration test to verify that two model steps share one binding while the server stays dormant, and that starting the server invalidates that binding.
GitOrigin-RevId: ef0469a85000f84a928946c24350e3bda1522fb5
Guard the `voice_args` array expansion to avoid unbound-variable errors
under `set -u` when packaging bundles without voice arguments. Preserve
quoted arguments for the `primary` bundle.
GitOrigin-RevId: 677a565d1678dc1e218cd9a98298aa6a26873643
## Why
Configured HTTP credential destinations need dummy credentials translated inside `CONNECT` and SOCKS5 tunnels, where credential interception previously detected only TLS.
## What changed
- Detect plaintext HTTP for configured credential destinations and proxy requests with URL-scoped credential substitution.
- Keep requests bound to the authorized tunnel destination, rejecting mismatched authorities and nested `CONNECT` requests.
- Support HTTP/2 clients and preserve HTTP upgrades, including `h2c`, and opaque traffic in full mode.
- Enforce limited-mode method restrictions on plaintext HTTP and reject upgrades and opaque traffic.
## Testing
Add end-to-end tests for both tunnel transports covering credential URL scope, request bodies, HTTP/2, destination mismatches, upgrades, lossless opaque forwarding, and limited-mode enforcement.
GitOrigin-RevId: 89262c996ea4ee156c628f9ed8e72b52504b2f6b
## Why
Applications need to deliver content from other agents, tools, or services with tool-level authority, without treating it as user input or granting authorization.
## What changed
- Export `ExternalMessage` for sync and async `run(...)` and `turn(...)`, accepting text or structured content with a tool name and optional namespace. Send it through `toolOutput` and require CLI 0.151.0 or newer.
- Support starting a turn or joining an active regular turn while preserving external content as function output in history. Keep external messages separate from user-input lists and `steer(...)`.
- Give turn handles independent subscriptions, replaying completed items and latest usage to joining handles. Release consumed transient events and clean up subscriptions on closure, failure, or cancellation.
- Document the authority boundary and add sync and async examples.
## Testing
Add coverage for wire representations, input validation, runtime compatibility, tool authority across resume, active-turn joins, and tool-output truncation. Add subscription tests for replay, concurrent consumers, early completion, cancellation, and cleanup.
GitOrigin-RevId: 6106327085fd9c4bd11b71e20b3d8e74738b8bb5
## Why
Python callers need control over response history loading and a way to override the service tier for one turn. These options also need runtime compatibility checks to prevent older CLIs from silently ignoring them.
## What changed
- Add `include_turns` to sync and async thread resume/fork methods. Omission preserves server defaults; `False` skips response history loading without changing model context.
- Add `turn_service_tier` and `source` to sync and async `run()` and `turn()`, and generate both methods together to keep their options aligned.
- Require CLI `0.151.0` or newer when sending the new options, with lazy schema checks for unversioned local builds.
- Pin the bundled runtime dependency to `0.153.4` and reject unsupported runtime versions during SDK packaging.
## Testing
Add coverage for option forwarding, history flag omission and inversion, runtime version checks, cached schema probing, and packaging compatibility. Extend app-server and installed SDK smoke tests to exercise the new options.
GitOrigin-RevId: 4bcc9cff687b0651e67852e7c080df7fadac6d76
## Why
GNU tar extraction and signing require writable copies of Bazel outputs.
## What changed
Recursively add owner write permission to the staged macOS voice runtime before creating the unsigned release archive.
GitOrigin-RevId: 1d415251b26303ac17cf886f35ae18277e9e6032
## What changed
Move TLS prefix detection into `brokered_tunnel` and carry explicit `BrokeredProtocols` requirements from the credential broker through HTTP `CONNECT` and SOCKS5 tunnel handling. Dispatch on `TunnelProtocol::Tls` or `TunnelProtocol::Opaque`, preserving the initial-read timeout, fragmented TLS header detection, and replay of all inspected bytes.
## Testing
Move the fragmented TLS regression test alongside the detector, retaining coverage for delayed header fragments and lossless prefix replay. Update broker and proxy assertions for the protocol-aware types.
GitOrigin-RevId: 6e5a92d8bdf6db5b59cff7f210c17b01d93ee23b
## Why
Credential brokerage must retain trusted destination hints even when shell environment policy hides them from child processes. Snapshot replay also needs to preserve credential aliases when tokens are short or captured dummy values change.
## What changed
- Add `features.network_proxy.credentials` and preserve provider settings when toggling the proxy. Prevent project configuration from overriding providers or their credential and destination environment variables.
- Use provider metadata throughout snapshot capture and replay, and pass hidden destination context to the broker without exposing it in the child environment.
- Rewrite aliases containing short credentials or previously captured dummies, respecting environment filters and explicit overrides.
- Preserve case-distinct `shell_environment_policy.set` keys so Windows credential ambiguity checks survive configuration merging and permission profile changes.
- Restore independent MITM settings when credential brokerage is disabled.
## Testing
Add regression coverage for custom providers, hidden destination hints, Bash and Zsh alias replay, configuration edits and merging, Windows ambiguity handling, and credential protection during approved execution.
GitOrigin-RevId: b2bd935d2d8555be56baf8feb1a8e5b3a0c666bc
Return `AudioPreparationError::InvalidDataUrl` with the reason
`audio payload is empty` when the decoded base64 payload is empty.
GitOrigin-RevId: e886dab5f49ebb1a363dbc1c292813b2b52698d4
## Why
Filtering destination variables out of a child environment can undo credential registrations. Rotating a provider token and destination must also leave older credential aliases bound to their original destinations.
## What changed
- Add `CredentialBrokerContext` to retain local destination hints for built-in and configured providers without adding them to child environments or serialized configuration. Explicit environment values, including empty values, override these fallbacks.
- Preserve registered destinations when hints are absent, reconcile fallback changes, and keep credential aliases scoped to their source identities and environments during rotation and inheritance.
- Expose provider context and source matching for trusted captured text, including configured provider context keys.
- Disable brokerage on Windows when provider environment overrides contain conflicting case-insensitive keys.
## Testing
Add regression coverage for filtered destinations, token rotation, inherited aliases, fallback updates and clearing, context redaction, trusted text matching, and non-Unicode environment values.
GitOrigin-RevId: 411790ea6339e1d8fa568049cf8160a67b134666
## What changed
Add a downstream workflow that builds the Python SDK and runtime from the stable CLI release commit, using the CLI version for both packages and the SDK's exact runtime dependency. Publish and verify the runtime on PyPI before publishing the SDK.
Require a successful CLI `release` job, an unchanged release tag, and complete runtime assets. Skip CLI prereleases and allow publication despite unrelated publisher failures. Support retries by CLI workflow run ID and accept existing PyPI uploads while verifying the complete release.
Document release setup, retry procedures, and independent SDK releases.
## Testing
Add resolver unit tests covering tag resolution, prerelease skipping, partial reruns, pagination, invalid runs, moved tags, missing assets, and equivalent automatic and manual release resolution.
GitOrigin-RevId: 4ec6b2e77c94c851507dbe7200ea420994fce36e
## What changed
- Discover configured provider credentials in child environment values even when canonical credential variables are absent. Match complete tokens while preserving regex word boundaries and avoiding ambiguous or overlapping provider matches.
- Replace and restore credentials by their original spans, preserving adjacent tokens and generated dummy aliases across destination rebinding. Reject dummy values that embed another provider's credentials.
- Extend text virtualization and provider source checks to configured credentials, including short credentials with distinctive prefixes, while preserving operational paths.
- Expose trusted provider metadata and active bindings through `CredentialBrokerEnvironment`, and remove marked configured credential variables when stripping the managed proxy environment.
## Testing
Add regression tests for alias discovery, regex boundaries and alternatives, overlapping and adjacent credentials, destination rebinding, dummy restoration, disallowed credential sources, and operational path preservation.
GitOrigin-RevId: dd85c595ce9550fbfdb07ef296a23e458ca165dd
## What changed
- Build the voice host and native runtime with Bazel's `-c opt` configuration.
- Resolve runtime paths before validating their contents in the release workflow.
- Make `runtime.json` owner-writable before sealing the post-signing release receipt.
- Use `scripts` in `PYTHONPATH` so archive creation can import `codex_package.archive`.
GitOrigin-RevId: 02f960573a4151f52cde486e17e1d45b73435306
## Why
The SDK release workflow published the runtime before building the SDK, so an SDK build failure could leave the runtime published on its own.
## What changed
- Extract a reusable SDK build workflow that packages checked-in generated code and runs alongside runtime preparation. Require both builds before publishing the runtime, and verify runtime availability before publishing the SDK.
- Add `stage-sdk --codex-version` to set an explicit runtime dependency independently of the SDK version, retaining the checked-in pin by default and rejecting missing or duplicate pins.
- Accept Codex release tags in the runtime version resolver and use its normalized Python version for standalone runtime PyPI verification.
## Testing
Add coverage for wheel and source distribution metadata, preservation of checked-in code, independent beta SDK versions, runtime tag normalization, and invalid versions or dependency pins.
GitOrigin-RevId: feb572fadcf5d148814b26b480b4bae5ef6a39c5
## What changed
Increase `GUARDIAN_MAX_ACTION_BYTES` from 8,000 to 200,000 bytes to allow larger actions to be reviewed. Keep unified exec stdin approvals capped at 8,000 bytes with a separate `MAX_STDIN_APPROVAL_BYTES` constant.
## Testing
Update aggregate payload rejection coverage for the new limit and exercise MCP elicitation reviews with tool descriptions exceeding the previous 8,000-byte limit.
GitOrigin-RevId: fd4b97980803a7a687449043931e6f1e57e260d3
## What changed
- Add `credential_providers` configuration for environment variables, credential patterns, static or environment-derived URL prefixes, and bearer, token, Basic, or custom header authentication.
- Generate matching dummy credentials and restrict replacement to authorized schemes, hosts, ports, and path prefixes. Scope credentials and destination history to each environment.
- Preserve real credentials for destinations that bypass the proxy with `allow_local_binding`, while providing snapshot redaction and alias matching.
- Validate provider definitions and preserve unchanged providers across configuration reloads.
## Testing
Add coverage for dummy generation, authentication translation, URL restrictions, environment isolation, configuration reloads, and credential restoration for local proxy bypass.
GitOrigin-RevId: 5d60ecc684cf4e9aa7637af33af12179aa0c672a
## Why
The SDK publish job needs to wait for runtime wheels to become available on PyPI, and release reruns need to tolerate SDK files that have already been uploaded.
## What changed
- Require runtime publication and verification before publishing the SDK, and enable `skip-existing` for SDK uploads.
- Share a PyPI verifier between runtime and SDK releases. Require the exact expected artifact set, including the SDK wheel and source distribution.
- Canonicalize versions with `packaging.version.Version` and retry registry errors, malformed responses, and incomplete artifact sets with a bounded retry loop.
## Testing
Add unit tests for transient failures and malformed responses, waiting for complete SDK artifacts, canonical version lookup, and retry exhaustion when runtime wheels are missing. Run them in repository checks.
GitOrigin-RevId: 9cb2ddced4ce6d509ebfd130511ab3f39239dd62
## Why
Python SDK CI needs to exercise the checkout's CLI while retaining coverage of the wheel installation and its default runtime.
## What changed
- Run the Python SDK test suite against the same Bazel-built CLI as the TypeScript SDK tests. Build and stage `codex-code-mode-host` alongside the CLI so it can be discovered.
- Make the Python test harness prefer `CODEX_EXEC_PATH`, then a local debug build, then the installed runtime. Exclude optional turn-cost probes from recorded model requests.
- Add a separate installation job that builds the Python SDK wheel and installs it in a fresh environment.
## Testing
The installation smoke test verifies that imports resolve to the installed SDK and that its default runtime completes a mocked turn with the expected user input and final response.
GitOrigin-RevId: 8e3126742a014e2cf042afe799bc657e1ea2a282
Move environment and marker helpers into `credential_broker/environment.rs`
and credential prioritization and selection into `credential_broker/registry.rs`.
Preserve existing behavior and public helper exports.
GitOrigin-RevId: 92bb94af3b00fc454bffea363a00a49f4a7cc44c
## What changed
Pass `StartThreadOptions` through rollout, loaded-history, and prepared forks instead of separate configuration and startup arguments. Replace `options.initial_history` with the fork snapshot while preserving the other supplied startup options, and update app-server and test callers.
Box the app-server's `thread_fork_inner` future to keep the large fork future out of the shared request dispatcher's stack frame.
GitOrigin-RevId: d54eb8b212dedabaf2c5d99d155637cefd7deb7a
## Why
Shell quoting can hide credentials from raw-text checks, and startup files can restore real credentials after the broker replaces them with dummy values.
## What changed
- Decode shell literals without evaluating them and reject snapshots containing credentials in executable source, including aliases, functions, and heredocs.
- Preserve credential policy overrides, explicit unsets, and aliases whose source variables were removed. Support credential aliases in Zsh tied arrays while rejecting credentials that span array elements.
- Guard snapshot replay against credential restoration through shell startup files and preserve unrelated `ENV` settings.
- Apply Windows environment-key casing rules to credential overrides, suppress unredacted sandbox diagnostics during snapshot capture, and clear inherited environment variables before launching escalated commands.
## Testing
Add regression coverage for shell quoting and escaped credentials, Zsh tied arrays, startup-file replay, readonly credentials, policy overrides, and sensitive capture timeout and cancellation handling.
GitOrigin-RevId: 58274c07c715423241d26ce6dd2c2b4230cf0f64
## Why
Shell startup can copy a credential into another variable and unset its original source. These aliases need credential brokering without losing source restrictions or mistaking ordinary shell content for credentials.
## What changed
- Discover supported GitHub and OpenAI credentials embedded in environment values, even without their canonical variables. Preserve source ownership so unbound enterprise tokens cannot acquire a default host binding.
- Redact unregistered supported credentials during text virtualization, distinguish adjacent credentials, and avoid matching unrelated provider prefixes and common hashed paths.
- Expose helpers for checking allowed credential sources and restoring known dummy credentials in trusted text for fail-open execution.
- Render allowed credential aliases as snapshot exports and replace known credential values in shell state, preserving exported functions and credential-shaped function names.
## Testing
Add regression coverage for copied aliases, enterprise host binding, source filtering, adjacent tokens, path false positives, and dummy restoration. Add a Bash snapshot test that preserves exported functions while replacing credentials in heredoc content.
GitOrigin-RevId: f1c3d531405a96ac6bfa3882a11b74643fa6f123
## Why
Keep Python protocol models aligned with the checked-in app-server schemas and preserve reviewed generated artifacts when staging SDK releases.
## What changed
- Generate SDK types from the schema directory configured in `pyproject.toml`, with a `--schema-dir` override, instead of invoking the pinned runtime binary.
- Refresh Python artifacts through `just write-app-server-schema` for standard repository exports. Skip SDK updates for scratch and experimental exports.
- Regenerate protocol models and notification dispatch, deriving the known payload union from the registry so `Notification.payload` covers every registered event.
- Explicitly allowlist convenience API parameters so new protocol fields do not silently expand method signatures. Preserve existing approval path wrappers.
- Stage SDK releases using checked-in generated files without regenerating them.
## Testing
Add coverage for schema selection, refresh gating and failure handling, release artifact preservation, notification payload typing, and approval path compatibility. Update the generation drift test to use repository schemas.
GitOrigin-RevId: fab350b07cf170258b91fbafa8da384aeb2e3bd7
## What changed
Support `model_providers.amazon-bedrock.aws.credential_export` with `command`, `args`, and `timeout_ms` to supply SigV4 signing credentials from a command's JSON output. Accept both flat credential-process output and nested STS `Credentials` objects.
Cache credentials in memory, refresh before expiration, and share exports across sessions with matching AWS configuration. On recoverable authentication failures, run the optional `aws.auth_refresh` command before exporting fresh credentials, coalescing concurrent recovery attempts.
Bound command execution time and output size, and keep credential values out of errors. Reject combining `aws.credential_export` with `aws.profile`. Bedrock setup and login reject changes while an exporter is configured, preserving configuration and saved credentials.
## Testing
Add coverage for output formats, expiration, credential precedence, caching, concurrent recovery, command failures, and secret redaction. Integration tests verify request signing with rotated credentials, bounded recovery attempts, and setup/login rejection across configuration layers.
GitOrigin-RevId: 4ef799f88ab5e3b2578f8f41a5e56e4f30e2cd81
## Why
The agents overview submitted background task prompts as plain text, without image attachments or their text elements.
## What changed
- Enable image pasting in the overview composer and include attachments and text elements in the first task prompt.
- Resolve local image paths and send image bytes when using a remote workspace.
- Reject image inputs for models declared text-only before starting a thread.
- Restore unsent text and attachments after failures, or show image reattachment paths when a newer draft prevents restoration.
## Testing
Add tests for attachment rendering and submission, remote image payloads, draft recovery without overwriting newer text, and text-only model rejection.
GitOrigin-RevId: 08e3db8bace51ec007f5741f1b2be94658cbaea4
## Why
Release tags bump `Cargo.toml` versions without updating the workspace lockfile, leaving stale versions for Bazel's Cargo dependency graph.
## What changed
Run `cargo update --workspace` in `codex-rs` before the macOS voice release job builds the voice host and native runtime with Bazel.
GitOrigin-RevId: ed923530ff5bc9982968cac4f1def4dde379f422
## What changed
Introduce `ExecutedToolCalls` to own optional shared recorder state and centralize feature checks, call recording, and accepted result source lookup. Update session, tool runtime, MCP, and Code Mode callers to use this interface.
Move prompt attachment, retry handling, and metadata budgeting into the `request_metadata` module, preserving existing recording and request behavior.
## Testing
Add coverage for all session and turn feature combinations, lazy result source lookup, and unchanged prompts when recording is disabled. Retain the existing metadata budget and cell completeness tests in the new module.
GitOrigin-RevId: bc19f34317232b6599c7ec71c15db4a80123ff6f
## Why
History events queued by the previous thread can repopulate the transcript after a thread switch, mixing old content into the new thread's replay.
## What changed
- Reset the transcript immediately and queue another reset before replaying the new thread, covering both snapshot switches and app-server thread replacement.
- Leave the alternate screen when resetting, and pause terminal event handling until queued resets finish.
- Process queued resets even when the transport is offline.
## Testing
Add regression tests for both switch paths, including queued history, an open transcript overlay, and a disconnect before replay events are handled. Snapshot the replacement transcript to verify it contains only the new thread's content.
GitOrigin-RevId: b68b07fb10ff35e908c2c184f80859dda637f977
## What changed
- Build, sign, and notarize `codex-voice-host` and its native runtime for Apple Silicon and Intel macOS release packages, granting the helper audio-input access.
- Include voice resources in primary package archives and DMGs, with a root-level `codex` symlink to `bin/codex` so the runtime can be located.
- Seal runtime receipts with post-signing hashes, require matching release versions and source builds, and bundle dependency notices, licenses, and source metadata.
- Keep voice resources out of Python wheels to preserve their older macOS compatibility; the native voice build targets macOS 14.
## Testing
Add packaging tests for alpha, beta, and stable versions, signed-byte preservation, license hashes, receipt validation, tamper detection, and exclusion of unlisted files. Extend release verification to check voice architectures, signatures, build identity, package hashes, and DMG contents.
GitOrigin-RevId: 9f9415a8b2532d655a9a8740bcdf64066ddb7472
Use `Box::pin` in
`cached_legacy_resume_revalidates_history_across_migration_settings` to
keep the large resume future off the Windows test thread's stack.
GitOrigin-RevId: 2539b7733e9f92e65a27bbea8f75170ce01b1884
## What changed
Replace straight apostrophes with curly apostrophes in usage-limit and high-demand error messages, and update usage-limit test expectations. Document that the context-window error's ASCII prefix is matched by the iOS input-limit classifier.
GitOrigin-RevId: 93484aaf805b9e6f8785fd1b43fe6ff9f1a13efa
## Why
New client requests and automatic continuations can start more work while the app-server is draining. Shutdown also needs to account for requests still preparing or submitting work before they appear as running turns.
## What changed
- Close a shared admission gate when shutdown begins, rejecting new turn work and thread lifecycle changes with the server-draining error.
- Apply the gate to automatic turn starts, including queued work and goal continuations, and recheck serialized turn requests before execution.
- Wait for admitted requests and running turns to finish, while preserving forced shutdown. Keep reads and `turn/interrupt` available during drain.
## Testing
Add coverage for admission permit tracking, discarded queued requests, forced shutdown, and WebSocket drain behavior, including request rejection, interruption, and suppression of automatic continuations.
GitOrigin-RevId: 1bc108aa00a427cfa41974fa9ec60754c2b968c2
Raise the Tokio worker thread stack size from 8 MiB to 12 MiB in
`selected_and_resumed_threads_use_server_capability_for_v1_and_v2_children`.
GitOrigin-RevId: 5f2462e50f0d67eeb1f5668d196431c7dc08d27f
## Why
Credential-brokered commands rebuild shell snapshots on every invocation. Snapshot capture failures can also include credential-bearing startup output, and descendants holding output pipes need cleanup even after the shell exits.
## What changed
- Cache successful protected snapshots per environment, keyed by working directory, shell, login mode, and sandbox configuration. Rebuild missing or stale snapshots while keeping concurrent captures independently cancellable.
- Invalidate snapshots when shell settings or credential broker configuration change, and retry capture once if broker configuration changes during startup.
- Restore credentials and associated provider context while respecting environment policy filters and explicit overrides.
- Keep full-buffer capture subject to timeout and cancellation through output draining, clean up descendants on capture expiration or drain failure, and omit startup output from snapshot errors.
## Testing
Add regression coverage for snapshot reuse, invalidation, recovery after storage failure, concurrent cancellation, credential-safe errors, and descendant cleanup. Verify that successful background startup and output beyond the shell output cap remain supported.
GitOrigin-RevId: 7c7c8455bf6e3b9ca173dbb4277783469f0b45e6
## What changed
Parse optional `generation_id` values from image API responses and carry the selected image's ID through the image generation tool into analytics events. Keep the ID out of serialized extension items, JSON schemas, and TypeScript types. Responses without an ID remain supported.
## Testing
Add coverage for distinct IDs in multi-image responses and responses without IDs. Extend analytics and app-server tests to verify that the selected image's ID reaches analytics, and item tests to verify that it is omitted from serialization and TypeScript types.
GitOrigin-RevId: 70a600856990140b76fdbda51a0d73b3414338b1
## Why
Thread startup, running-thread resume, and rollback could outlive their request handlers, allowing connection draining and request serialization to finish too early.
## What changed
- Await thread startup and listener completion for running-thread resume and rollback.
- Release the thread-list permit before waiting for resume completion so the listener can finish rollback responses.
- Release pending rollback waiters when clearing a listener, and discard queued requests when their connection closes.
## Testing
Add coverage for releasing queued requests and rollback waiters, and pipeline resume during rollback to check that both responses complete. Update diagnostics expectations to allow startup to remain in flight after its response is queued.
GitOrigin-RevId: 138156179afbc40de29965820db7fa9cd3669cc7
## What changed
- Replace the `ThreadArtifact` model and related exports with attachment terminology.
- Add `StateRuntime::add_thread_attachment` and `remove_thread_attachment` using SQLite transactions. Repeated additions for the same thread, attachment type, and identity key return the existing record without changing its payload or creation time.
- Enforce limits of 100 attachments per thread, 64 KiB per serialized payload, and 256 bytes each for nonblank attachment types and identity keys. Removal returns the deleted record or `NotFound` and frees capacity immediately. Both mutations reject unknown threads.
## Testing
Add tests for idempotency, thread isolation, removal outcomes, capacity reuse, invalid inputs, unknown threads, and concurrent additions creating exactly one record.
GitOrigin-RevId: a68fe5076832f071524f1b4fc87d08b96ac270b7
## What changed
Report the automatic-update setting and update interval from the daemon's `settings.json` in the background-server check, labeling each value as configured. Report unreadable, invalid, or oversized settings files without displaying their values, with a 16 KiB size limit.
## Testing
Add snapshot coverage for disabled automatic updates and a configured interval when the updater PID file is missing, plus invalid boolean and zero-interval settings.
GitOrigin-RevId: e8e77d1a10448f7d62fd84d8325f3e61738a689b
## Why
Refresh failures could leave expired MCP OAuth credentials reporting ordinary errors instead of signaling that authentication is required, preventing tool calls from offering a reconnect signal.
## What changed
- Classify provider failures and timeouts as `AuthorizationRequired` when the access token has expired. Keep proactive refresh failures as ordinary errors while the token remains valid.
- Reread stored credentials after a failed refresh and adopt a valid login completed during the request, enforcing the existing issuer binding for refresh tokens. Preserve stored credentials for later retries.
- Convert authentication-required tool-call errors into a reconnect message with `mcp/www_authenticate` metadata, without exposing provider or transport details.
## Testing
Add coverage for startup and runtime OAuth recovery, proactive refresh failures, concurrent login adoption, issuer mismatches, credential preservation, and successful retries. Verify failed local refreshes do not send tool calls and server-rejected calls are not replayed.
GitOrigin-RevId: 9cf64b0452685d2085df5dc0bcecee16ffe42e47
## Why
Hosts need to stop new turn-input work during shutdown without consuming pending input or preventing already-running delegated work from finishing.
## What changed
- Add an optional `TurnStartAdmission` extension gate, checked before reserving or starting a new turn. Hosts without a gate retain existing behavior.
- Return `NotSubmittedReason::ServerDraining` for refused starts and surface an app-server error instructing clients to reconnect and retry.
- Keep steering, parent-delegated subagent input, and memory-only mailbox wakeups available during drain, while gating automatic starts.
- Close realtime conversations with an ordered handoff, error, and close event sequence when a handoff is refused during drain.
## Testing
Add regression coverage for rejected input staying out of subsequent requests, persisted queue items remaining available for later starts, delegated agent and review work completing during drain, mailbox wakeups, and realtime handoff error ordering.
GitOrigin-RevId: 03dbdcd71eab200e597c0649e6eb39bd92dbc82f
## What changed
- Display owner thread titles, relative update times, and archived or unavailable status in the managed worktree browser. Offer resume only for resumable owners, including those with compressed thread history.
- Add a delete action with a confirmation dialog that defaults to Cancel and preserves thread history.
- Restrict removal to managed worktrees in the current repository. Refuse the current checkout, including path aliases, and checkouts containing local changes, untracked files, or ignored files.
## Testing
Add browser snapshots and tests for owner states, deletion confirmation, and compressed thread history. Add worktree removal coverage for unrelated checkouts, current-directory aliases, untracked and ignored files, and successful removal of a clean checkout.
GitOrigin-RevId: e5867f1540d5d5bc8130acc76875e51e3d8b3b6a
## Why
Filesystem policies for remote execution need to interpret paths, home directories, and temporary directories using the execution host's context.
## What changed
- Add context-based read-denial matching, read-access checks, glob resolution, and `PathUri` workspace-write constructors without consulting local paths or environment variables.
- Share managed read-denial validation through `DenyReadValidator` and use it in core configuration, preserving required-entry checks, concrete grant validation, and constraint diagnostics.
- Reject invalid or unresolvable denial paths when constructing a context-based matcher, and apply `/tmp` denials according to the execution host's path convention.
- Preserve workspace-root symbols and protected metadata entries when materializing URI-based writable roots.
## Testing
Add regression tests for POSIX, Windows, and UNC path matching; conflicting read and write grants; malformed or unresolvable denials; `/tmp` handling; and workspace metadata protection.
GitOrigin-RevId: aa2b174288d1172ab52ff485f58d306236d27652
## What changed
Add `terminal_name` and `multiplexer` attributes to `codex.tui.start` alongside `app_server_mode`. Use fixed terminal categories rather than versioned or user-provided identifiers, with `unknown` for unrecognized terminals. Report the multiplexer as `tmux`, `zellij`, or `none`.
## Testing
Extend the CLI worktree test to parse metric payloads and assert the exact startup attributes for an unrecognized terminal without a multiplexer. Keep coverage that no metrics are sent when analytics is disabled.
GitOrigin-RevId: 024c82653098b9bddd6c5e8d7133ff798b58dcd1
## What changed
- Match parent follow-up responses by tool call IDs in the grandchild context baseline test, and assert that the grandchild completes with `done`.
- Drive delayed terminal output with newline-delimited stdin instead of sleeps, keeping the process alive across three `write_stdin` calls and updating the expected stdin events.
GitOrigin-RevId: 433954e5ed5ecce920cf198d1bf1264e58178ba6