Commit Graph

4448 Commits

Author SHA1 Message Date
Celia Chen
3ca9f375aa Enable cached web search for Amazon Bedrock (#36938)
## Why

Amazon Bedrock supports hosted text web search, but it rejects the
`search_content_types` field used for multimodal search and does not support
external live or indexed web access.

## What changed

- Advertise hosted web search for Amazon Bedrock while marking external web
  access as unsupported.
- Resolve unsupported live and indexed modes to cached search, or disable the
  tool when cached search is prohibited by managed requirements.
- Normalize built-in and configured Bedrock model catalogs to text-only web
  search, and retain the runtime provider in session configuration so turn
  setup can apply its capabilities.

## Testing

- Cover cached fallback, managed-mode restrictions, text-only tool payloads,
  provider capabilities, and catalog normalization.

GitOrigin-RevId: 310473849257401654388a4ebb42920e03aa3228
2026-08-04 17:55:28 +00:00
Eric Traut
1e59dc5bda Trust undecided local projects automatically (#36935)
## What changed

- Replace the TUI directory-trust prompt with automatic trust for local projects whose trust level is unset. Keep explicit trust settings and remote workspaces unchanged.
- Persist trust for the resolved Git or configured project root, then reload configuration so project-local settings take effect.
- Fall back to an in-memory trust override and an embedded app server when the config update cannot be persisted.

## Testing

- Cover persisted and in-memory trust, custom project-root markers, and the working directories selected by resume and fork flows.

GitOrigin-RevId: 8fd51eb4cd88267073324bfd7dc4106a56d7c745
2026-08-04 17:49:54 +00:00
jif
90314a9207 Read turn permissions from the current configuration (#36930)
## What changed

- Remove the cached permission profile from `TurnContext` and derive the
  effective profile, filesystem policy, network policy, and legacy sandbox
  policy from `config.permissions`.
- Update sandbox consumers and tests to use the current turn configuration.
- Verify that role-based agent spawning reapplies runtime permissions and that
  cold-resumed agents retain their disabled permission profile.

GitOrigin-RevId: d67c5d2bcbe6dc76f15b56defb485b155fd1f138
2026-08-04 17:13:13 +00:00
felixxia-oai
02bc1dd796 Move the host skills service into the skills extension (#36921)
## What changed

- Move host skill discovery, snapshot caching, and configuration handling from
  `codex-core-skills` to `codex-skills-extension`.
- Rename `SkillsService` and `SkillsLoadInput` to `HostSkillsService` and
  `HostSkillsLoadInput` to distinguish the host implementation from other skill
  providers.
- Keep shared loading primitives and skill outcome modeling in
  `codex-core-skills`.

GitOrigin-RevId: d81a21791d2ef8c066e157e7e538b8cb7ee4c24b
2026-08-04 16:28:46 +00:00
jif
c8e255e7f8 Centralize app enabled-state evaluation (#36916)
## What changed

- Add `AppToolPolicyEvaluator::apply_app_enabled_state` and use it when
  presenting app lists, building plugin context, and deciding whether app
  instructions are available.
- Preserve each app's source state unless local or managed configuration
  explicitly overrides it.
- Keep connector discovery and post-install refresh checks based on raw
  accessibility rather than configured enablement.

## Testing

- Cover default enablement, per-app overrides, managed disablement, and
  preservation of unconfigured source state.

GitOrigin-RevId: f1a62d55e7cc48b37113848e3baa0d69d8d9c8a8
2026-08-04 15:49:49 +00:00
jif
6a828ca26f Read approval policy from the current turn configuration (#36912)
## Why

Thread settings can update the approval policy after a turn context is created.
Keeping a separate copy on `TurnContext` could leave tool approval checks using
the previous policy.

## What changed

- Remove the duplicated approval-policy field from `TurnContext`.
- Resolve the policy through the turn's current configuration everywhere it is
  needed, including tool execution, Guardian routing, MCP handling, and
  permission requests.

## Testing

- Update the shell escalation test to apply a thread-level policy override and
  verify that the next turn rejects an escalation using the updated policy.

GitOrigin-RevId: e5966ba08f179d53fd76871ad904762958c0f5ea
2026-08-04 15:32:31 +00:00
Martin Au-Yeung
ee46c5ba0e Negotiate MCP extensions per app-server session (#36910)
## Why

App-server clients need to advertise structured MCP extension settings, including supported MCP App UI MIME types, rather than only opting into OpenAI form elicitation with a boolean.

## What changed

- Add an `extensions` map to initialize capabilities and preserve `mcpServerOpenaiFormElicitation` as a legacy alias for `openai/form`.
- Capture the declared extension profile when a thread is started, resumed, or forked, propagate it to subagents, and advertise it to downstream MCP servers during initialization.
- Keep the profile stable for the lifetime of the loaded session instead of changing it on later turns or direct tool calls.

## Testing

- Cover extension conversion, downstream MCP initialization, session isolation, legacy form support, and subagent inheritance.

GitOrigin-RevId: fbcedbb74ce788e574b0f884a4c45c4cedb9de54
2026-08-04 15:23:43 +00:00
jif
d1f14e31a7 Preserve model providers when reloading v2 agents (#36906)
## Why

Reloading an unloaded v2 agent could inherit the model provider from the
agent that triggered the reload, even though the worker's model was restored
from its persisted thread state.

## What changed

- Restore both the model and model provider from the stored thread when
  reloading a v2 agent.
- Return an invalid-request error if the stored provider is no longer present
  in the configured provider map.

## Testing

Extend the v2 agent reload test to trigger the reload with a different sender
provider and verify that the worker retains its stored provider.

GitOrigin-RevId: 6401d9f0d1c116e9954e3bd193d016f04da5f223
2026-08-04 15:01:28 +00:00
jif
f93109615f Propagate updated permissions to review threads (#36901)
## What changed

- Apply the session's current approval policy whenever per-turn configuration is built.
- Have review threads inherit the parent turn's full permission settings and approval reviewer.
- Add coverage for settings updated after session startup, including the approval policy, permission profile, and approval reviewer.

GitOrigin-RevId: bff050c6de157dd65d62f7b49651bef3f426ee3f
2026-08-04 14:29:24 +00:00
jif
18f03c1eb7 Register app tools independently of the connector list (#36900)
## What changed

- Gate Codex Apps MCP tool registration on whether apps are enabled instead of requiring each tool's connector to appear in the accessible connector list.
- Continue enforcing model-visibility and app-tool policy checks, including the requirement for connector metadata.
- Use the merged connector catalog for tool-suggestion discovery.

## Testing

- Cover app-tool registration from catalog metadata, including synthetic links, source ordering, and the apps-disabled case.

GitOrigin-RevId: eef4eb03da9738d3a165dd6cfda0d3c1844d51e7
2026-08-04 14:19:13 +00:00
jif
6d4d9442c7 Support leaf models in multi-agent v2 (#36892)
## What changed

- Allow multi-agent v2 parents to spawn any visible model that has not explicitly disabled multi-agent support.
- Expose collaboration tools to child agents only when their selected model supports multi-agent v2, keeping legacy models as leaf workers.
- Preserve a worker's selected model when reloading it into residency.
- Propagate multi-agent capability metadata to Amazon Bedrock model entries so delegation is gated consistently.

## Testing

- Cover model selection, leaf-worker tool visibility, Bedrock capability handling, and model preservation after reload.

GitOrigin-RevId: 1457adb1a09806d1f0621311d5a42a6815b9dd4e
2026-08-04 12:36:14 +00:00
jif
fd1e4d7a6d Preserve complete MCP namespace descriptions (#36882)
## What changed

- Keep complete MCP namespace descriptions in tool-search source metadata.
- Raise the namespace tool-spec description limit from 1,000 bytes to 512 KiB,
  truncating at a UTF-8 character boundary only when the new limit is exceeded.

## Testing

- Cover descriptions beyond the former limit and multibyte truncation at 512 KiB.
- Update SSE and stdio MCP tests to verify that complete server instructions are
  preserved without hiding tools.

GitOrigin-RevId: 000bfcafb3df348065ae451685bfbf978a0e3248
2026-08-04 11:14:06 +00:00
jif
9873cba8ce Consolidate thread spawning behind a request object (#36862)
## What changed

- Add `ThreadSpawnRequest` to carry thread options, authentication, agent
  control, fork metadata, inherited state, and shell overrides.
- Route new, resumed, and forked threads through one `spawn_thread` path.
- Centralize default session-source and environment selection when the request
  is consumed.

GitOrigin-RevId: 8fd1a8531a212000c7430218c2200aa4a047cb9a
2026-08-04 08:51:35 +00:00
rka-oai
d4fb78bfc5 Support custom tools in namespaces (#36857)
## What changed

- Allow namespace tool specs to contain custom freeform tools alongside function tools.
- Include namespaced custom tools in deferred tool search and expose them to code mode with names such as `editor__apply_patch`.
- Route custom payloads to matching extension tools while preserving function-only payload validation.

## Testing

- Add serialization, tool search, code-mode definition, and end-to-end dispatch coverage for namespaced custom tools.

GitOrigin-RevId: be64d35f6ae54685c5a9fcf45a732320742ea7e5
2026-08-04 08:28:43 +00:00
rka-oai
12288240b4 Support deferred loading for freeform tools (#36856)
## What changed

- Add optional `defer_loading` support to freeform Responses API tool definitions.
- Omit the field when it is unset so existing eager tool definitions retain their wire shape.

## Testing

- Verify legacy freeform tool deserialization and eager and deferred serialization shapes.

GitOrigin-RevId: 50e8658a54ac5b6ae0c1dbfe65f7bb62efef561d
2026-08-04 08:24:42 +00:00
Dylan Hurd
b2dc8b3e4b Consolidate approval telemetry context (#36825)
## What changed

Add the tool name to `ApprovalCtx` and use the context's call ID and session
telemetry when recording approval decisions. This removes redundant `ToolCtx`
and telemetry parameters from `resolve_tool_approval`.

GitOrigin-RevId: 238a6f708f83993d64606bfaa74df344b0b46178
2026-08-04 02:29:43 +00:00
Dylan Hurd
64bb8094ba Fix typo in approval resolver name (#36822)
Rename `resolve_tool_apporval` to `resolve_tool_approval` and update its
call sites in the tool orchestrator.

GitOrigin-RevId: bc7d9ae675b45dd5b6b5b5643fd75e532f6314ca
2026-08-04 02:03:22 +00:00
Boyang Niu
7431f10d0d Identify agents by name in token budget context (#36815)
## What changed

- Replace the thread ID in `<context_window>` metadata with the session's canonical agent path.
- Default sessions without an agent path to `/root`.
- Verify that root sessions emit `/root` and subagent sessions emit their own path, such as `/root/worker`.

GitOrigin-RevId: bcf057842ed31f93d554b7de063b6c03403a2594
2026-08-04 00:51:53 +00:00
sayan-oai
b258c028fe Honor per-environment login shell policy (#36811)
## What changed

- Store the effective `allow_login_shell` setting on each turn environment, including inherited environments whose child thread has a different policy.
- Expose the `login` argument for shell tools when any selected environment permits login shells.
- Validate each command against the policy of its selected environment instead of the turn-wide configuration.

## Testing

- Cover tool schema generation for single and multiple environments.
- Cover login-shell rejection by both the command handler and the unified exec integration.

GitOrigin-RevId: 5a93149a5c86f4087f2b92d663ebc33feff8a57c
2026-08-03 23:33:05 +00:00
Sean Huang
cc03518c36 Extract audio preparation into a utility crate (#36807)
## What changed

- Add `codex-utils-audio` as a workspace crate for canonicalizing audio inputs
  and estimating their token usage.
- Update `codex-core` to consume the new crate while preserving the existing
  audio preparation tests.

GitOrigin-RevId: d719ecc08363ef52778aa37f3df0ca14f7778324
2026-08-03 22:46:26 +00:00
felixxia-oai
1bbfb5cfad Avoid reinjecting permissions after command approvals (#36800)
## What changed

- Track approved command prefixes separately from the stable permissions
  instructions in world-state snapshots.
- Emit only newly approved prefixes after an exec-policy amendment instead of
  appending the full permissions block again.
- Preserve prefix updates when full permissions instructions are disabled and
  remain compatible with legacy world-state snapshots.

## Testing

- Cover incremental prefix additions, removals, legacy snapshots, history
  rollback, and approval flows with permissions instructions enabled or disabled.

GitOrigin-RevId: e6f68c6a91be82750e70e28456f2b7c58607fbd8
2026-08-03 21:37:17 +00:00
rhan-oai
e4e0c7070e Gate plugin usage instructions by model capability (#36792)
## What changed

- Add `include_plugin_usage_instructions` to model metadata, defaulting to false.
- Emit generic plugin guidance only when plugins are available and the selected model enables it.
- Enable the capability for interactive model presets while leaving `codex-auto-review` opted out.

GitOrigin-RevId: 67f5a97e978033f5f1d533956c0b9deeae610283
2026-08-03 19:51:43 +00:00
rhan-oai
df72fdb415 Consolidate model instructions in ModelMessages (#36787)
## What changed

- Remove `ModelInfo.base_instructions` as an in-memory instruction source and use `model_messages.instructions_template` consistently for bundled, remote, fallback, and overridden model metadata.
- Preserve compatibility by promoting legacy `base_instructions` values when reading model responses and caches, and by including rendered legacy instructions when serializing `ModelsResponse` for older clients.
- Treat templates without instruction variables as literal text and retain the other model-message fields when applying instruction overrides.

This completes the consolidation proposed in https://github.com/openai/codex/pull/31302.

## Testing

- Cover legacy response and cache migration, canonical-template precedence, fallback instructions, personality rendering, overrides, and model switching.

GitOrigin-RevId: 089d986ca5e30da67db2c77a1b6a046d2cff52dc
2026-08-03 19:30:40 +00:00
tongzhou wang
51c9ed6d4f Add per-surface MCP tool exposure controls (#36781)
## Why

MCP tools can be exposed directly, discovered through tool search, or called
from Code Mode. Servers need to be able to opt out of any of these surfaces
without disabling their tools everywhere.

## What changed

- Add `omit_tools_from` to MCP server configuration, accepting any combination
  of `direct`, `deferred`, and `code_mode`.
- Apply the exclusions independently when building direct, deferred, and Code
  Mode tool surfaces while keeping omitted tools registered for permitted uses.
- Remove client-private `_meta` fields from MCP results returned to Code Mode.
- Include the new setting in the configuration schema and MCP config
  serialization.

## Testing

- Cover every exposure combination across Code Mode, Code-Mode-only sessions,
  tool search, direct-only namespaces, and prefixed and unprefixed MCP names.
- Verify direct and nested execution paths, parallel-call support, config
  round-tripping, and `_meta` filtering.

GitOrigin-RevId: 12dfcb78bb5c5ecf4d70f38a8b5022792463a27f
2026-08-03 18:51:46 +00:00
jif
78306a32af Clarify config layer iteration APIs (#36774)
## What changed

- Replace the ordering enum and `include_disabled` boolean with named
  `ConfigLayerStack` iterators for each precedence direction.
- Keep enabled-only iteration separate from `all_layers_*` iteration, which
  includes disabled layers.
- Update config consumers to use the iterator matching their precedence and
  disabled-layer requirements without allocating an intermediate `Vec`.

## Testing

- Add coverage that verifies ordering and disabled-layer filtering for all four
  iterators.

GitOrigin-RevId: d14df3db4a2eae80ba97cdec246bff405e6c5f3d
2026-08-03 17:29:42 +00:00
jif
ca2b47997e Avoid building code-mode definitions during registration (#36764)
## What changed

Derive code-mode tool names directly from registered tool names when checking
eligibility and collisions. Skip unsupported and empty tool specs explicitly,
without serializing schemas or augmenting descriptions that are not used during
executor registration.

GitOrigin-RevId: b439327aafd85ce3745d900301b7e48b56dbd6b4
2026-08-03 15:47:29 +00:00
jif
7750465934 Consolidate apply_patch runtime execution (#36745)
## What changed

- Route verified patches from both direct tool calls and intercepted shell commands through a shared execution helper.
- Simplify patch safety preparation to return either a runtime invocation or a rejection directly.
- Keep permission resolution, approval handling, event emission, runtime execution, and diff tracking in the common path.

GitOrigin-RevId: e16aae8e91d96b8108aefac7f3fbf2da2cbac016
2026-08-03 12:03:33 +00:00
jif
7dd2f689e9 Simplify contextual user fragment registration (#36742)
## What changed

Replace the type-erased `FragmentRegistration` trait and proxy objects with a
static list of `matches_text` function pointers. Remove the registration types
and their re-exports while preserving the existing contextual fragment matchers.

GitOrigin-RevId: 4e5a296b278984c6e783a67f48fa4bb37646946b
2026-08-03 11:39:51 +00:00
jif
79479cdf09 Store turn skill state in extension data (#36740)
## What changed

- Store each turn's host skills snapshot in `ExtensionData` and expose it through
  `TurnContext::skills_snapshot`.
- Lazily keep implicit skill invocation deduplication state in the same turn-scoped
  store.
- Carry the skills snapshot into review turns without a separate
  `TurnSkillsContext` field.

GitOrigin-RevId: d71579b5d230bd0b5f3c2ad062861f74d614d88c
2026-08-03 11:00:40 +00:00
jif
d6407d7359 Deduplicate MCP resource list handling (#36734)
## What changed

- Share argument normalization, server selection, cursor validation, and pagination setup between `list_mcp_resources` and `list_mcp_resource_templates`.
- Use a generic server-tagged wrapper to build single-server and deterministically sorted all-server payloads for both resources and templates.

## Testing

- Cover shared argument normalization and sorted resource-template payload serialization.

GitOrigin-RevId: 3505e4c1d2b95d8bbbb01f6f930fb914309eb898
2026-08-03 10:41:03 +00:00
jif
155f1ca9e5 Correlate code mode tool analytics with model responses (#36729)
## What changed

- Emit dynamic tool-call analytics for code mode `exec` and `wait` calls, including duration and terminal status.
- Associate code-mode cells and their nested tool calls with the originating and subsequent model response IDs.
- Buffer correlated tool events until the next response is known, while flushing pending events when turns, threads, or the analytics queue close.

## Testing

- Add reducer coverage for correlating `exec`, `wait`, and nested tool events across turns.
- Add an app-server test that verifies production analytics include the cell and response IDs for a code-mode `exec` call.

GitOrigin-RevId: 8b34ab59c1ad68ebbd57f9c8a05f19ab04df48a4
2026-08-03 10:19:04 +00:00
jif
dae2122214 Simplify turn metadata state ownership (#36727)
## What changed

- Store synchronization primitives directly in `TurnMetadataState` instead of
  wrapping each field in its own `Arc`.
- Require an `Arc<TurnMetadataState>` when spawning Git enrichment so the
  background task retains the complete state.
- Update Git enrichment tests to use the shared state container.

GitOrigin-RevId: 745ca6504c0a6533cb7726d045905472e51726df
2026-08-03 10:14:34 +00:00
jif
1b594980f3 Deduplicate MCP resource operation handling (#36716)
## What changed

- Add a shared runner for MCP resource operation lifecycle events, output serialization, truncation, timing, and error handling.
- Use it for listing resources, listing resource templates, and reading resources.

GitOrigin-RevId: 84cae2e01a096d5b8ed97ea1cb462f01fe2ed1f9
2026-08-03 09:50:51 +00:00
rka-oai
8b8fa7276f Use provider-reported rollout budget units (#36715)
## What changed

- Charge `codex_rollout_budget_units` against the shared rollout budget when the provider includes it in response usage.
- Fall back to weighted input and output token accounting when provider units are absent.
- Reject non-finite or negative provider units as a fatal response error.

## Testing

- Cover provider units in reminder thresholds and local and remote compaction budget exhaustion.
- Verify invalid units fail without retrying the response.

GitOrigin-RevId: b452403e365985854d16f298d1ba46383e9892c4
2026-08-03 09:46:38 +00:00
rka-oai
bb5054fe47 Capture rollout budget units from response usage (#36641)
## What changed

- Parse `codex_rollout_budget_units` from completed Responses API usage into
  `TokenUsage`.
- Keep the provider-only value out of serialized protocol, JSON schema, and
  TypeScript representations.

## Testing

- Cover the value in unit and end-to-end SSE response parsing tests.

GitOrigin-RevId: a53d4202beb9c8985d25894cb10e7c01f20b2a44
2026-08-03 00:30:57 +00:00
ningyi-oai
a1dd74b535 Retain attempted tool metadata across prompts (#36507)
## What changed

- Reattach recorded `executed_tool_calls` metadata when an output is included in a subsequent prompt.
- Bound retained metadata to 32 KiB, prioritizing recent calls and reporting omitted calls in truncation metadata.
- Drop retained entries after their corresponding outputs leave the prompt history.

## Testing

- Cover metadata replay, cleanup after compaction, bounded retained history, and propagation through later tool requests.

GitOrigin-RevId: 1c23a26123be3b7ad51c61f4ad522139b71bb773
2026-08-01 17:36:39 +00:00
jiayuhuang-openai
6751b54cae Add a realtime delegation acknowledgement control (#36413)
## What changed

- Add the optional `delegationAckFiller` field to `thread/realtime/start`.
- Forward explicit `true` or `false` values to V3 Frameless Bidi session payloads as `delegation.ack_filler`; leave the field absent when unspecified so the Realtime API default is preserved.
- Document that V1 and V2 ignore this setting.

## Testing

- Cover both boolean values in Frameless Bidi serialization and verify the WebRTC V3 session creation payload.

GitOrigin-RevId: 9fe8efd14e42738c3e86e3e9a8af81d0f4521244
2026-08-01 01:17:26 +00:00
Shijie Rao
e2c0837923 Make user input blocking behavior explicit (#36410)
## Why

Clients need to know whether a `request_user_input` request must wait for an
explicit response or may auto-resolve. Using `autoResolutionMs` as that signal
conflated the blocking decision with timeout policy.

## What changed

- Add required `isBlocking` fields to user input protocol and app-server
  request payloads. Plan-mode requests are blocking, while requests from other
  enabled modes are non-blocking.
- Drive the TUI's auto-resolution behavior from `isBlocking` and remove
  `autoResolutionMs` from the model-facing tool schema.
- Deprecate `autoResolutionMs` while retaining it for compatibility, and treat
  legacy payloads without `isBlocking` as blocking.

## Testing

- Cover mode-derived blocking behavior, legacy deserialization, app-server
  forwarding, delegated requests, and TUI auto-resolution.

GitOrigin-RevId: 29aade657ef743065ec264376ba567a9b353d7d7
2026-08-01 00:38:10 +00:00
guinness-oai
670f69416b Allow custom Codex instructions for realtime transitions (#36408)
## What changed

- Add optional `realtimeStartInstructions` and `realtimeEndInstructions` fields to `thread/realtime/start`.
- Apply the instructions when Codex enters and leaves realtime mode, while preserving the existing defaults when either field is omitted.
- Limit each field to 8,192 estimated tokens.

## Testing

- Cover custom entry and exit instructions across realtime state transitions.
- Cover token-limit validation for both fields.

GitOrigin-RevId: b9cfa1ff22e084d8a6b2ed56bd27d95ffdd6b6bd
2026-07-31 23:51:33 +00:00
Curtis 'Fjord' Hawthorne
1bef168976 Track image preparation details in turn analytics (#36388)
## What changed

- Record the effective detail setting and source and prepared dimensions for
  successfully decoded images.
- Associate message images with their role and tool-output images with their
  originating call ID.
- Include the collected image preparation metadata in the corresponding turn
  analytics event.

## Testing

- Cover image resize metadata, tool-output attribution, turn aggregation, event
  serialization, and app-server analytics output.

GitOrigin-RevId: dbfb5ba1ce7cb02dd93d9b579c5109817f16aef5
2026-07-31 20:34:41 +00:00
keith thornhill
bf7804c254 Add acknowledged user message submission to core (#36385)
## What changed

- Add `CodexThread::submit_user_input_and_wait_for_admission` and export the
  `UserMessageAdmission` result through `codex-core-api`.
- Resolve submissions only after they start a new turn or steer the active
  turn, returning the accepting turn ID in either case.
- Return errors for invalid operations, rejected thread settings, and session
  termination instead of leaving admission waiters unresolved.

## Testing

Add integration coverage for concurrent start-and-steer submissions, settings
rejection and recovery, non-user operations, and submission after shutdown.

GitOrigin-RevId: 21f1ede38d399baa9836d61a59b9f9af2dbf83b8
2026-07-31 20:17:25 +00:00
jif
775fb21d2a Keep effective tool exposure in the registry (#36367)
## Why

`ToolExecutor::exposure()` describes a tool's preferred exposure, while the host
may apply step-specific policy when building a tool plan.

## What changed

- Store each runtime together with its effective exposure in `ToolRegistry`.
- Apply MCP, namespace, and collaboration-tool exposure overrides directly to
  registry entries instead of wrapping runtimes.
- Use the registry-owned exposure when building model-visible specs, deferred
  tool search, code-mode executors, and parallel-call support.

## Testing

- Cover that a hidden MCP tool remains routable but is not eligible for parallel
  tool calls.

GitOrigin-RevId: 1bc2760add8d993f477954269fa13681bfcc2444
2026-07-31 17:24:33 +00:00
Ankush Gupta
287e1020ae Add strict automatic review for MCP elicitations (#36365)
## What changed

- Recognize the `codex_strict_auto_review` MCP elicitation marker and route
  marked approval requests through the configured automatic reviewer.
- Accept only canonical automatic-review approvals and fail closed without a
  user prompt when review is unavailable, denied, malformed, disallowed by
  policy, or requests persistence.
- Validate Codex Apps approval metadata against the active MCP invocation and
  build the review request from the trusted invocation details.

## Testing

- Add unit coverage for strict review decisions, malformed markers, reviewer
  failures, explicit policy denials, and lifecycle cleanup.
- Add app-server round-trip coverage for approvals, denials, configuration
  constraints, spoofed metadata, persistent requests, and subsequent turns.

GitOrigin-RevId: af73b45a9b63118f25f6429d95b3222c5dbb59fb
2026-07-31 17:18:08 +00:00
felixxia-oai
0d109f097c Move skill catalog rendering out of core (#36364)
## What changed

- Make the skills extension own the catalog prompt templates and rendering path.
- Remove the duplicate core fallback that injected available skills into initial context.
- Update core integration tests to install the skills extension explicitly when they expect model-visible skill context.

GitOrigin-RevId: bbe6b15c4e776a09c98b7f4166426fe4e58434ba
2026-07-31 17:12:10 +00:00
jif
385fe95ce1 Use MCP bindings as the step tool catalog (#36360)
## What changed

- Read the frozen MCP tool catalog directly from the step-scoped `McpBinding`
  when building tool routers, plugin injections, and connector state.
- Remove the redundant `Vec<ToolInfo>` from `StepContext` and stop returning a
  duplicate catalog from `built_tools`.

GitOrigin-RevId: d12d694e1224da3f6ccb1960868491f0d80c6e19
2026-07-31 16:35:14 +00:00
jif
d97cb0dcad Consolidate MCP config editing in codex-core (#36359)
## What changed

- Route skill dependency updates through the shared `codex-core` `ConfigEditsBuilder`.
- Remove the duplicate MCP config writer and its tests from `codex-config`, while retaining MCP config loading there.

GitOrigin-RevId: cdce84c8353514529126156750433e859b78be3b
2026-07-31 16:28:22 +00:00
jif
66ebeb7037 Use the step-scoped router for tool execution (#36357)
## Why

Tool calls can outlive the sampling request that advertised them, so execution
must retain the finalized tool plan for that specific step.

## What changed

- Resolve tool runtimes, parallelism, cancellation behavior, argument diff
  consumers, and dispatch from the `ToolRouter` stored in `StepContext`.
- Remove the separate router parameter from `ToolCallRuntime` and code-mode
  worker construction so callers cannot supply a different router.
- Add a test helper for installing a router into a test `StepContext`.

GitOrigin-RevId: 9e476ddd228ca5b1c03ed87863618ba77de6200c
2026-07-31 16:23:53 +00:00
jif
c4f2746c43 Keep MCP tool calls bound to their thread (#36355)
## Why

Threads can configure the same MCP server name with different runtimes. Tool calls
must use the runtime associated with the thread that issued the call.

## What changed

- Route MCP readiness checks and call preparation through the invoking session.
- Add regression coverage that alternates calls between two threads and verifies
  that each thread continues using its own MCP server process and configuration.

GitOrigin-RevId: 5735f7b29a579f545351385ab01a575e35ead01e
2026-07-31 16:12:46 +00:00
jif
35eab50501 Pass sessions directly to session tasks (#36354)
## What changed

- Replace `SessionTaskContext` with `Arc<Session>` in the session task run and abort interfaces.
- Read extension data from `TurnContext` during regular turns instead of storing and forwarding a duplicate reference through the running task.

GitOrigin-RevId: 04bc0d324e5ba781f35ac9c61e811888208b74ae
2026-07-31 16:05:52 +00:00
rhan-oai
2c005abb07 Use model catalog collaboration mode messages (#36351)
## What changed

- Add optional `default` and `plan` collaboration-mode messages to model catalog metadata.
- Prefer the active mode's catalog message, including an explicit empty value, while falling back to the existing developer instructions when the catalog variant is absent.
- Track the model in collaboration-mode world state so mode and model changes append the appropriate instructions, and clear prior instructions when no current message exists.
- Preserve catalog collaboration messages when instruction overrides remove other model instruction fields.

## Testing

- Cover catalog deserialization, variant selection, fallback and empty-message behavior, legacy snapshot migration, mode changes, and model changes.

GitOrigin-RevId: d4c6c0028423bc50b0e8175e55586f3e7bc1c3a8
2026-07-31 15:40:52 +00:00