Commit Graph

9604 Commits

Author SHA1 Message Date
sayan-oai
5bcd7b0fbc Refresh bundled model definitions (#39770)
## What changed

- Add the hidden Daybreak Blue and Daybreak Red model definitions.
- Refresh model capabilities, instructions, plan availability, and service-tier metadata.
- Configure the auto-review model for Responses Lite and code-mode tools, and update Guardian request tests for the resulting `additional_tools` and developer-message layout.

## Testing

- Update Guardian request snapshots and assertions for initial and follow-up reviews.
- Verify MCP approval routing against the developer-message form of the Guardian prompt.

GitOrigin-RevId: 6680e9abebdcbc43224a81348591e26f8422f3ec
2026-08-20 18:17:28 +00:00
william-openai
39073ca3a7 Include suggestion IDs in plugin install metadata (#39765)
## What changed

- Add `suggestion_id` to plugin install elicitation metadata, using the same
  value as the elicitation request ID and plugin-install analytics event.
- Leave connector install metadata unchanged by omitting the field.

## Testing

- Cover plugin and connector metadata serialization.
- Verify that remote plugin install metadata and analytics carry matching
  suggestion IDs.

GitOrigin-RevId: 05dd1d210e2a82857094f09d27ecba79ee460b7e
2026-08-20 17:54:42 +00:00
victor-openai
097825f75a Add app-server MCP event streaming (#39761)
## What changed

- Add experimental `mcpServer/event/stream/start` and `mcpServer/event/stream/stop` requests for hosted apps, plus `mcpServer/event/stream/notification` forwarding.
- Scope subscriptions to the owning app-server connection and subscribed thread, enforce unique IDs and a per-connection limit, and clean them up when the thread is unsubscribed or the connection closes.
- Wait for the MCP active notification before completing startup, retry streams that close immediately, and terminate them when authentication or hosted runtime ownership changes.

## Testing

- Add an app-server integration test covering activation, event forwarding, duplicate subscription rejection, and explicit cancellation.

GitOrigin-RevId: 8a6fc1615adfc5af7e67def3b824fa5909ab3e7b
2026-08-20 17:49:35 +00:00
jif
8a40095ea3 Standardize shell execution on unified exec (#39757)
## What changed

- Remove the legacy `shell_command` handler and runtime, leaving `exec_command`
  and `write_stdin` as the shell execution tools.
- Treat legacy `shell_command` model metadata as `unified_exec`, and normalize
  legacy user opt-outs so they do not disable command execution. Managed feature
  requirements and `shell_tool` can still disable it.
- Preserve shell approvals, sandboxing, zsh-fork support, and output truncation
  through the unified execution path.

## Testing

- Cover legacy configuration and model-metadata compatibility.
- Exercise unified shell execution, approvals, truncation, and `apply_patch`
  serialization across the app-server and core test suites.

GitOrigin-RevId: 5c2fd6164fc3519cdae4944cb9db276b8467311c
2026-08-20 17:46:05 +00:00
jif
d0cc662b8c Cache shell snapshots in the exec server (#39756)
## What changed

- Add the `shellSnapshotV2` executor capability and an optional shell snapshot request to `ExecParams`.
- Capture and restore Unix shell state and profile exports from an in-memory, attachment-scoped cache for `bash`, `zsh`, and `sh`.
- Apply environment policies, runtime `PATH` entries, sandbox context, and live managed-proxy settings when preparing restored commands.
- Bound snapshot size, capture time, scope length, and cache capacity, and fall back to the original command when capture fails.

## Testing

- Cover local, remote, TTY, sandboxed, and supported-shell execution, plus environment filtering, proxy handling, in-memory reuse, and capture failure fallback.

GitOrigin-RevId: 624f747972c249c88c6f10f42cf0af97b75b5541
2026-08-20 17:39:06 +00:00
joeflorencio-openai
ce950dcf26 Add managed developer instructions to requirements (#39755)
## What changed

- Add `additional_developer_instructions` to managed requirements and expose it through `configRequirements/read` as `additionalDeveloperInstructions`, independently of ordinary developer instructions.
- Include the managed instructions in model context, emit explicit replacement or removal messages when requirements change, and preserve the current value across compaction, resume, and agent forks without duplication.
- Reject managed instructions whose rendered context exceeds 10,000 estimated tokens.

## Testing

- Cover requirements layering and API serialization, context updates and removal, size validation, repeated model requests, compaction and resume, rollout migration, and agent forks.

GitOrigin-RevId: bc0b70fb7988944c2f68176dff55f5ed61eb46c8
2026-08-20 17:36:22 +00:00
Sean Huang
85a1b0e33d Expose uncompiled permission profile selection (#39752)
## What changed

- Add `resolve_permission_profile_selection` to select the effective profile using configured defaults, managed requirements, and allowlists.
- Return the merged configured and managed profile catalog without compiling platform-specific paths, leaving path interpretation to the executor.

## Testing

- Verify that a managed default overrides a configured default while preserving Windows-style paths.
- Verify that an allowlisted but undefined profile is rejected.

GitOrigin-RevId: 0172193d48f0346522f931d3b806054895d199c0
2026-08-20 17:25:14 +00:00
cgst-oai
a26d50852a Require filesystem backends to implement directory walks (#39749)
## What changed

- Make `ExecutorFileSystem::walk` a required backend operation instead of
  providing a fallback built from directory reads and metadata requests.
- Implement bounded local walks on a blocking task with cancellation, symlink
  cycle detection, deterministic ordering, error collection, and response-size
  limits.
- Have remote filesystems use the server's walk operation directly.

## Testing

- Cover local and remote handling of invalid roots and limits, directory
  symlinks, non-UTF-8 names, cancellation, sandbox contexts, and response
  budgets.

GitOrigin-RevId: 7499bf05080c3f9965a5eb7ffd593de604d62c2a
2026-08-20 17:16:52 +00:00
sayan-oai
2e1f18e0db Refresh resumed thread capability roots from executors (#39746)
## Why

Resumed threads can carry a persisted capability-root location that no longer
matches the location reported by the attached executor.

## What changed

- Refresh matching thread-owned capability roots from the live environment while
  preserving persisted roots when the executor reports none.
- Use the same merge behavior for capability-root inspection and per-step MCP
  resolution, without changing owner-configured root precedence.

## Testing

Extend the remote-environment resume test to cover both an executor-provided
replacement root and the persisted-root fallback.

GitOrigin-RevId: 0c66195b2406f431a2e156e00d5225a8d22d18b2
2026-08-20 17:12:15 +00:00
Benjamin Carlsson
c3db180493 Skip postprocessing for short composer input (#39744)
## What changed

Return the initial wrapping ranges directly when the composer input produces a
single line and its byte length is less than the available width. This avoids
the additional grapheme and word-boundary pass for input that cannot wrap.

GitOrigin-RevId: 55d990a354fcc61e9a90d5796b4b39d16742cc50
2026-08-20 17:00:05 +00:00
rhan-oai
4f38432d87 Use model-specific auto-review outcome instructions (#39741)
## What changed

- Add `rejection_instructions` and `timeout_instructions` to catalog-provided auto-review messages.
- Use the acting model's instructions for denied and timed-out reviews across tool approvals, shell escalation, and MCP elicitation responses.
- Fall back to the existing instructions only when a catalog value is absent, while preserving explicit empty-string overrides.

## Testing

- Cover catalog overrides, legacy fallbacks, empty values, and separation between acting-model and reviewer-model messages.

GitOrigin-RevId: c5b2c2dbdaefd45d1d658651dd1abaeb6d8c93da
2026-08-20 16:52:16 +00:00
felixxia-oai
88da5520d4 Honor Guardian runtime settings from model defaults (#39738)
## What changed

- Add `max_tool_call_lag`, `reuse_parent_compaction`, and transcript
  `include_images` to the Guardian model configuration.
- Inherit these settings from model defaults while preserving explicit local
  overrides.
- Enable image capture for Node REPL review evidence when transcript images are
  included.

## Testing

- Cover inheritance and local override precedence for the new settings.
- Verify that enabling transcript images initializes review-evidence capture.

GitOrigin-RevId: 7c1965c2ec00a78a0436fa916b630be0004dbb51
2026-08-20 16:45:59 +00:00
rhan-oai
8c828b18d6 Remove private executor directory creation (#39736)
## What changed

- Create remote plugin metrics directories through the standard executor filesystem API.
- Remove the `private` directory-creation protocol option and its platform-specific handling.
- Update the executor temporary-directory documentation to describe child-visible sidecars without an owner-private guarantee.

GitOrigin-RevId: 9a8532403a3ad2bf998281735be0b668893918c9
2026-08-20 16:22:45 +00:00
Charlie Marsh
bf2aee99c5 Avoid rollout reads for configured TUI sessions (#39731)
## Why

A newly started thread may not have materialized its rollout before the TUI
receives `ThreadStarted`. Trying to infer session state from that path can wait
through rollout reader retries even when a lifecycle response already provided
the authoritative session.

## What changed

- Preserve session state already stored for a known thread instead of inferring
  it again from `ThreadStarted`.
- Continue updating agent-picker metadata from the notification.
- Restrict fallback session inference to newly observed `ThreadStarted`
  notifications that do not already have session state.

## Testing

Added a startup test that verifies a known thread routes `ThreadStarted`
immediately, retains its configured session, buffers the notification, and
updates agent metadata when the rollout does not exist yet.

GitOrigin-RevId: 7ed98fb46df17566c4a61ac677f60fc8d94f7321
2026-08-20 15:42:40 +00:00
jif
9bf673718a Box the WebSocket dial future (#39726)
## What changed

Box `dialer::connect` before awaiting it in `WebSocketConnector::connect`,
erasing the dialer's concrete future type at the connector boundary.

GitOrigin-RevId: 617a2e4fd5bd61a408281973452e7b71b104bff2
2026-08-20 14:55:08 +00:00
jif
9894a14c81 Track multi-agent v2 spawn calls in analytics (#39722)
## What changed

- Emit started and completed collaboration tool events for multi-agent v2
  `spawn_agent` calls, including failed invocations.
- Record execution duration and successful child-agent configuration metadata
  without including the spawn prompt.
- Deduplicate collaboration and subagent activity items by call ID when
  calculating per-turn subagent tool counts.

## Testing

- Extend the app-server multi-agent v2 integration test to cover successful
  and failed spawn telemetry, duration, prompt omission, and turn counts.

GitOrigin-RevId: c1c2fb9cc2a1a9b0f63ef68509ad36d11a92d1e5
2026-08-20 14:33:55 +00:00
rafael-oai
1674b0a130 Expose managed policy for browser settings imports (#39720)
## What changed

- Add `in_app_browser.allow_external_browser_settings_import` to managed requirements, preserving explicit Boolean values through layered composition while leaving an omitted value unset.
- Return the policy as `inAppBrowser.allowExternalBrowserSettingsImport` from `configRequirements/read` and include it in the generated protocol schemas.
- Keep the import policy independent from the in-app browser feature flag and agent Browser Use requirements.

## Testing

- Cover parsing, managed-layer precedence, invalid values, user and session override resistance, and app-server response serialization.

GitOrigin-RevId: efa2621d2b1cf503f1bee2505d9914cb4fb7221d
2026-08-20 14:13:56 +00:00
William Woodruff
6d020311f0 Stop persisting checkout credentials in V8 workflows (#39719)
## What changed

Set `persist-credentials: false` for the V8 canary repository checkout and
for the `rusty_v8` checkouts in both the canary and release workflows.

GitOrigin-RevId: b4ccca7c7edf4e038b7b84c83f83d1416f655f65
2026-08-20 14:08:18 +00:00
William Woodruff
2c74b56fcd Pass CI workflow inputs through environment variables (#39717)
## Why

Embedding reusable-workflow inputs directly in shell scripts can cause their
contents to be interpreted as shell syntax.

## What changed

- Export the Rust nextest target, profile, and test-thread inputs as environment
  variables before using them in Bash commands and paths.
- Pass the MSVC target and host architecture to PowerShell through environment
  variables.

GitOrigin-RevId: f96bbeeb7b556022e4bdea9db384a88f925050bf
2026-08-20 14:02:13 +00:00
Tamir Duberstein
4a942885c8 Reduce unified exec output buffer allocations (#39712)
## What changed

- Accept borrowed byte slices when appending output chunks, avoiding clones before
  forwarding those chunks to streaming consumers.
- Merge drained head-tail buffers by reusing their owned storage while preserving
  the retained prefix, latest suffix, and omitted-byte count.
- Make unified exec output handles capacity-generic so bounded-output tests can
  exercise repeated drains with small buffers.

## Testing

- Update head-tail buffer and process manager tests to cover chunk retention,
  omission accounting, and repeated output drains with the new APIs.

GitOrigin-RevId: caa9813d3c9d9921cff28888263a212def381640
2026-08-20 13:17:20 +00:00
Tamir Duberstein
59f7da58d6 Log TUI app event variants without their payloads (#39709)
## Why

The TUI session logger is meant to record only the variant for unhandled app
events. Parsing `Debug` output removed tuple payloads but retained fields from
struct variants.

## What changed

Derive `IntoStaticStr` for `AppEvent` and use that conversion when recording
fallback `app_event` entries, so the `variant` field consistently contains only
the enum variant name.

GitOrigin-RevId: 5b539f414269c6b001e69cf9496db5b49aceb759
2026-08-20 12:17:44 +00:00
felixxia-oai
3675fe014b Remove redundant code mode image helper test (#39707)
GitOrigin-RevId: 38bf61c1d71827d65a7824318911ac0e9f2756bb
2026-08-20 12:12:53 +00:00
jif
02de49f718 Harden Seatbelt writable root path binding (#39706)
## Why

Resolving attacker-mutable path components while preparing a Seatbelt profile can let a writable root be rebound to a different location before the sandbox is applied. File roots also need to remain confined to the file itself rather than granting access to descendants after replacement.

## What changed

- Preserve mutable components of writable-root paths until Seatbelt binds them, while still normalizing trusted top-level aliases such as `/tmp`.
- Use literal grants for existing file and device roots, and subpath grants for directories and missing roots.
- Exclude both logical and resolved forms of protected subpaths so symlinked metadata directories remain read-only.

## Testing

Add coverage for ancestor rebinding, file-root symlink and directory replacement, missing directory roots, top-level aliases, and symlinked metadata carveouts.

GitOrigin-RevId: 63c00e44dd30766e873b8acdad09d6657657fad9
2026-08-20 12:08:35 +00:00
felixxia-oai
37a9da9901 Move the global scope check into the code-mode runtime (#39703)
## What changed

Replace the core integration test for allowed `globalThis` properties with an
in-process code-mode runtime test. The test continues to fail when the runtime
exposes a global outside the allowlist without requiring the core network test
harness.

GitOrigin-RevId: f33846ae2bb35e6779b5bec0a3f0ba5729eb707d
2026-08-20 12:02:42 +00:00
felixxia-oai
585b97d394 Wait for turn completion events in multi-agent resume tests (#39702)
## What changed

Use the shared `wait_for_event` helper to wait for `TurnComplete` from initial
and reloaded worker threads before checking their requests. This replaces
manual polling of `AgentStatus` with two-second deadlines.

GitOrigin-RevId: 862884afae9969aacf0f53c5c24cf8b72f8d078a
2026-08-20 11:57:32 +00:00
jif
f277e313f1 Fail closed on unsafe config and sed parsing (#39700)
## Why

Unsupported untrusted approval policies must remain startup errors even when
app-server is allowed to fall back from other invalid configuration. Likewise,
compound command summaries must not discard a `sed` stage that can edit files
in place.

## What changed

- Propagate `UnsupportedUntrustedApprovalPolicyError` from both app-server
  configuration loads instead of replacing it with default configuration.
- Parse `sed` options through `--`, option arguments, combined short flags, and
  backup suffixes so `-i`/`--in-place` commands remain unknown actions.
- Keep non-mutating `sed` operands after `--` from being mistaken for flags.

## Testing

Added parser coverage for in-place `sed` variants in compound commands and for
dash-prefixed operands after `--`.

GitOrigin-RevId: 112ead912e10fcb6c7dd0ede4bf84e390af82da8
2026-08-20 11:52:46 +00:00
felixxia-oai
478dbe9df0 Make Guardian v2 parent compaction reuse configurable (#39691)
## What changed

- Add `features.guardianv2.reuse_parent_compaction`, defaulting to `true` to preserve existing behavior.
- When disabled, omit parent compaction items from Guardian v2 contributor requests.
- Cover configuration parsing and disabled-reuse request construction.

GitOrigin-RevId: 0cf7c0ac7a2567c9f73a3f9724df6f6a6170e995
2026-08-20 10:57:03 +00:00
Ben Romano
312b62ac95 Trace MCP runtime refresh coordination (#39667)
## What changed

Add named tracing spans for MCP dirty-state refreshes and time spent waiting
to acquire the refresh semaphore.

GitOrigin-RevId: 1dbb3572d2061581beb83b3de098d6ec91791104
2026-08-20 08:36:00 +00:00
pakrym-oai
2584e88cad Improve no-follow filesystem behavior across platforms (#39666)
## What changed

- Use `statx` for no-follow metadata on Linux so `created_at_ms` includes the birth time when the filesystem provides it, with a fallback for unavailable or blocked `statx` calls.
- Mark files and directories for deletion explicitly on Windows after opening them without traversing reparse points.
- Cover create, write, metadata, remove, and link-rejection behavior for local and remote filesystems, including sandboxed execution on Linux and Windows.

## Testing

- Add Linux coverage for preserving birth time in no-follow metadata.
- Add cross-platform coverage for sandboxed no-follow operations and removal of files and empty directories.

GitOrigin-RevId: 1bc531669839bf5d033aa4a215220ed1cc5f63d5
2026-08-20 08:32:11 +00:00
Dylan Hurd
fec2dccfcf Add macOS Seatbelt filesystem integration tests (#39665)
## What changed

Add macOS-only integration coverage that runs commands under the production
Seatbelt policy and verifies:

- deny globs protect matching files, directory ancestors, symlink aliases, and
  paths created after policy application;
- protected directories cannot be moved, replaced, or exchanged across
  writable roots; and
- standard read-only and workspace-write profiles continue to allow expected
  filesystem operations.

GitOrigin-RevId: 1f666835ee402bedd1d32e87f1082eaaf7b7bf6a
2026-08-20 08:28:35 +00:00
charlesgong-openai
97c82c0900 Restrict plugin migration to home scope (#39663)
## Why

Plugin imports persist user-global enabled state. Repository-controlled settings
must not be allowed to select executable plugin content for installation.

## What changed

- Detect plugin migrations only from home-scoped external agent settings.
- Reject plugin imports with a non-empty project `cwd` before loading Codex
  configuration, while continuing to treat an empty `cwd` as home scope.

## Testing

- Cover repository-scoped detection with remote, installed, and project-relative
  marketplaces.
- Verify that forged project-scoped imports fail without writing `config.toml`.

GitOrigin-RevId: 53cb46ae049cb49283187312d475d40cf42e35ab
2026-08-20 08:24:18 +00:00
ianw-oai
240bbfc14a Add max and ultra reasoning efforts to the SDKs (#39662)
## What changed

- Add `max` and `ultra` to the TypeScript `ModelReasoningEffort` type.
- Add matching Python `ReasoningEffort` members and preserve them when SDK artifacts are regenerated.
- Update the Python model-selection examples to rank the new effort levels.

## Testing

- Cover serialization of both new Python enum members while continuing to accept unknown future values.

GitOrigin-RevId: 1412b77bdbb2530f5d38921cdea971dd34458353
2026-08-20 08:20:08 +00:00
Benjamin Carlsson
631d5a8b02 Expand Vim change commands and add character replacement (#39661)
## What changed

- Add the configurable `vim_normal.replace_char` action, bound to `r` by default, to replace the grapheme under the cursor while remaining in normal mode.
- Support change-operator motions such as `cw`, `c$`, `cj`, and `ck`, plus the repeated `cc` command for changing the current line.
- Let `Esc` cancel a pending replacement before it reaches composer-level handling.
- Preserve existing custom Vim bindings and chord prefixes when introducing the new default.

## Testing

- Cover replacement, grapheme boundaries, remapping and unbinding, change motions, cancellation, keymap conflicts, and keymap picker snapshots.

GitOrigin-RevId: 98feb4eeb57142c37adb73abfe58d1f703b9270d
2026-08-20 08:13:56 +00:00
pakrym-oai
e3e5ad2847 Harden unsandboxed patch filesystem access (#39659)
## Why

An `apply_patch` path can be replaced with a symlink after verification, allowing an unsandboxed patch operation to reach a different file than the one that was approved.

## What changed

- Add `follow_symlinks` options to executor filesystem reads, writes, metadata lookups, directory creation, and removal, including the corresponding `followSymlinks` protocol fields.
- Implement no-follow filesystem operations on Unix and Windows that reject links in any path component and restrict file access to regular files.
- Run `apply_patch` with symlink traversal disabled when an otherwise-required sandbox is bypassed, while retaining the existing follow-symlink default for standalone callers.

## Testing

- Cover leaf and ancestor symlinks across patch add, update, delete, and move operations, including a path swap after verification.
- Exercise local and remote no-follow filesystem behavior, concurrent directory creation, special-file rejection, and Windows reparse points.

GitOrigin-RevId: 43fd479084891493ce13564fbd894b98f329c6dd
2026-08-20 08:10:08 +00:00
Ankush Gupta
4e1a772a7d Let Guardian V2 satisfy required model reviews (#39658)
## What changed

- Allow the Guardian V2 approval monitor to handle reviews for models that require automatic review.
- Preserve full Guardian review when Guardian V2 is disabled by configuration or managed requirements.
- Cover required-model routing for low- and high-risk actions, plus both Guardian V2 disable paths.

GitOrigin-RevId: d1201cc3dbd7c4a07de633388b14f17ada9feb39
2026-08-20 08:07:06 +00:00
Eric Traut
5e3a6fe4ee Warn when launching the deprecated MCP server (#39657)
## What changed

Print a warning to standard error when `codex mcp-server` is invoked, noting
that the command is deprecated and will be removed in a future release. The
server continues to launch after the warning.

GitOrigin-RevId: 0fefa2579a420a2fad85ef3afe373204f9836869
2026-08-20 08:02:39 +00:00
Eric Traut
4a432d180d Advertise the Desktop app in graphical Linux sessions (#39656)
## What changed

- Add Linux-specific install and launch guidance to the generic and paid tooltip pools when `DISPLAY` or `WAYLAND_DISPLAY` is set.
- Keep the Linux tooltip hidden in WSL and headless sessions, and preserve platform-specific macOS and Windows behavior.

## Testing

- Add coverage for native graphical Linux, WSL, headless Linux, macOS, and Windows tooltip selection.

GitOrigin-RevId: cbe9435db064d5718a591db363dcb7cc1429d5ee
2026-08-20 07:58:28 +00:00
pakrym-oai
1802a65571 Make core integration test permissions explicit (#39655)
## What changed

- Run local and remote compaction test turns with approvals disabled and an unrestricted permission profile.
- Keep the full test harness available where compaction turns need the configured model and working directory.
- Enable the Windows sandbox for managed-network unified exec process-event coverage.
- Update request snapshots to reflect the resulting `danger-full-access` sandbox metadata.

GitOrigin-RevId: 38eb46ca6ab28246d738e31eab900b2825072c7d
2026-08-20 07:52:35 +00:00
Adam Perry @ OpenAI
7ece061767 Enforce filesystem permissions when loading AGENTS.md (#39653)
## Why

Project instructions must respect the selected environment's filesystem read
permissions. Tightening those permissions for a later turn must not allow
previously cached instructions to reach the model.

## What changed

- Apply each environment's filesystem sandbox while discovering and reading
  `AGENTS.md` files.
- Fail thread or turn setup when sandboxing blocks a discovered instruction
  file, while allowing a restricted project with no instructions to start.
- Clear cached instructions before refresh and include the Windows sandbox
  level in the cache key.
- Ignore inaccessible ancestor marker probes so readable instructions in the
  selected working directory can still load.

## Testing

Added coverage for restricted projects, denied instruction files, cache
invalidation after permissions tighten, and unreadable ancestor markers.

GitOrigin-RevId: 6ea1a27b9c873a6260e4f87d42ae1317a6a4ae4b
2026-08-20 07:48:46 +00:00
zm-oai
ab82cddd04 Resolve bundled Windows helpers through bin junctions (#39649)
## Why

Installer `bin` directories can be junctions, so looking for bundled helpers
relative to the apparent executable path can miss the package's
`codex-resources` directory.

## What changed

Retry bundled executable lookup from the canonical executable path when lookup
from the original path fails.

## Testing

Add a Windows regression test that creates a `bin` junction and verifies that
the sandbox setup helper is resolved from the package resources directory.

GitOrigin-RevId: f2f20ce1ccfa95ae65171a03a986d10e2560e696
2026-08-20 07:42:18 +00:00
Dylan Hurd
8aaf839774 Exercise restricted-token sandboxing in cyber policy tests (#39646)
## What changed

Run both branches of the heuristically safe command policy test with the
Windows sandbox level set to `RestrictedToken`.

GitOrigin-RevId: ae5d754ec4a51d73a8e5f9d844f94a91f795fb72
2026-08-20 07:37:52 +00:00
Anton Panasenko
af0e82c562 Enforce managed residency for model providers (#39645)
## Why

Model provider configuration could override the residency header required by
`enforce_residency`, so provider-backed requests did not reliably honor the
managed setting.

## What changed

- Apply the managed residency header after building a provider, making it
  authoritative for model requests and model discovery.
- Warn when a provider configures the residency header through
  `http_headers` or `env_http_headers`, while preserving the original provider
  configuration and unrelated headers.
- Cover HTTP and WebSocket requests, model discovery, and case-insensitive
  header detection with targeted tests.

GitOrigin-RevId: 461ef8989d5bd06ffdea694aee4265e392e07590
2026-08-20 07:33:27 +00:00
evanz-oai
663da53823 Sanitize developer context in full-history agent forks (#39641)
## Why

Developer messages can contain both inherited agent policy and unrelated context. Full-history forks need to replace the parent policy without dropping the unrelated content that shares its message.

## What changed

- Filter fork-specific developer instructions by content item instead of excluding an entire developer message.
- Remove inherited multi-agent mode instructions before applying the child agent's current mode.
- Preserve unrelated content items and discard developer messages only when filtering leaves them empty.

## Testing

Extend agent-control and subagent notification tests to cover compound compacted messages, multi-agent mode instructions, and proactive-to-explicit mode transitions.

GitOrigin-RevId: 028834e237d8636c13b17a724574bc8eb09a55ba
2026-08-20 07:29:43 +00:00
Jeremy Rose
d944ce83a2 Prompt to unarchive sessions before resuming or forking (#39640)
## Why

Starting an archived session with `codex resume` or `codex fork` stopped with
guidance to run a separate `codex unarchive` command first.

## What changed

- Detect archived-session startup failures and offer to unarchive and retry the
  requested operation.
- Allow the user to cancel without modifying the archived session.
- Render the confirmation in the alternate screen when available and preserve
  inline terminal context when `--no-alt-screen` is set.
- Preserve `--no-alt-screen` whether it appears before or after the `resume` or
  `fork` subcommand.

## Testing

- Cover confirmation, cancellation, retry behavior, and unrelated startup
  failures for both resume and fork.
- Add prompt interaction and terminal rendering coverage, including narrow and
  inline viewports.

GitOrigin-RevId: 382cdbd15b5d12c091e554d6d3a2f9b3589654f4
2026-08-20 07:25:40 +00:00
Alvin
fdc23b93b8 Treat invalid_grant refresh failures as permanent (#39637)
## Why

OAuth token endpoints can report an unusable refresh token with the standard
`invalid_grant` error instead of a legacy expired, reused, or revoked subtype.

## What changed

- Classify `400 Bad Request` responses with an `invalid_grant` error code as
  permanent refresh failures, preserving the generic failure reason.
- Cache that failure so subsequent refresh attempts do not repeat the request.
- Keep other `400 Bad Request` errors transient and retryable.

## Testing

Added refresh tests covering terminal `invalid_grant` responses and retryable
`invalid_request` responses.

GitOrigin-RevId: 513d34b514a7e4118a70c76e9d0fe779c006d5d8
2026-08-20 07:21:24 +00:00
Dylan Hurd
7edd0a4c9d Show strict review warnings in the TUI (#39635)
## What changed

- Render `StrictReviewRequired` notifications as warning history cells that explain tool calls may take extra time.
- Preserve the active command and task-running state when the notification arrives.

## Testing

- Add a TUI snapshot test covering the warning and continued command output.

GitOrigin-RevId: bf01b612a22b537b247b6df6818080fc73b5414d
2026-08-20 07:17:31 +00:00
Sean Huang
7ea7b29369 Expose permission profile resolution in the core API (#39632)
## What changed

- Add `Config::resolve_permission_profile` to resolve named profiles from the
  effective configuration and managed requirements.
- Make active-profile network proxy lookup public and re-export
  `CodexThreadSettingsOverrides` from `codex-core-api`.
- Cover configured and managed profile inheritance, duplicate-name rejection,
  and preservation of managed network settings.

GitOrigin-RevId: ffb5f54a932ef1a4b624677b5f051ecdcd1134b8
2026-08-20 07:11:46 +00:00
Dylan Hurd
910ecccf30 Skip sandboxed shell commands in Guardian v2 by default (#39631)
## What changed

- Exclude sandboxed `exec_command` and `shell_command` calls from Guardian v2 classification by default while continuing to classify calls that request `require_escalated` permissions.
- Add `guardianv2.review_scope.sandboxed_exec_commands` to opt sandboxed shell commands back into classification.
- Keep other tools and namespaced shell tools in scope, and advance tool-call progress when a call is skipped.

## Testing

- Cover the default and configured review scopes, tool namespaces, permission modes, and skipped-call progress tracking.

GitOrigin-RevId: 32fb540c69959b9a82569f0f2fc76b5517496e6b
2026-08-20 07:08:31 +00:00
jif
942af8447b Retire the untrusted approval policy (#39630)
## What changed

- Remove `untrusted` from the CLI, configuration schema, and MCP tool interface. Explicit `approval_policy = "untrusted"` settings now fail with an actionable error.
- Remove the known-safe command allowlist. Projects marked untrusted now request approval for every command unless an explicit exec policy rule allows it.
- Keep command parsing conservative by treating in-place `sed` forms as mutating and ignoring unrecognized commands when recording memory usage.

## Testing

- Cover rejection of the retired configuration value and approval requests for commands in untrusted projects.

GitOrigin-RevId: d6bf425edddfffbb325eee6acf383434af5fd33b
2026-08-20 07:03:02 +00:00
Eric Traut
9ca99b5171 Preserve parent repository discovery through sandbox metadata mounts (#39629)
## Why

The Linux sandbox represents missing protected metadata paths such as `.git`
with empty read-only directories. Repository and project discovery treated any
`.git` directory as a checkout root, so this synthetic directory could hide a
real parent repository and its trust configuration.

## What changed

- Treat a `.git` directory as repository metadata only when it contains
  `HEAD`, while continuing to recognize file-based `.git` entries.
- Protect missing `.git` paths with the same read-only synthetic mounts as
  other workspace metadata without disrupting parent-repository discovery.
- Canonicalize and read-only bind the synthetic-mount registry into the
  sandbox, and make protected-path cleanup handle read-only directory trees.

## Testing

Added coverage for repository, project-root, trust, synthetic-mount, and
Landlock behavior, including nested incomplete `.git` directories and a
redirected `TMPDIR`.

GitOrigin-RevId: 0724c54d56531143bb28011e4ca414cd3b0212be
2026-08-20 06:57:00 +00:00