## What changed
- Parse the optional `retirement_at` RFC 3339 value from model upgrade metadata, treating missing, null, or malformed values as unknown.
- Expose known retirement times from `model/list` as nullable Unix timestamps in `upgradeInfo.retirementAt` and preserve them when converting app-server models back into model presets.
- Update the generated protocol schemas and app-server documentation.
## Testing
- Cover absent, null, valid, and malformed catalog values.
- Verify `model/list` serialization and app-server model conversion for known, missing, and out-of-range timestamps.
GitOrigin-RevId: 969baf9f5b012997f460fb4611ba63c963ee658c
## What changed
- Add `oauth.callback_port` to MCP server configuration and preserve it when
serializing configuration edits.
- Accept `oauth.callbackPort` from plugin MCP declarations and skill dependency
metadata.
- Prefer the server-specific callback port over `mcp_oauth_callback_port` for
CLI login, app-server, plugin installation, executor, and skill dependency
OAuth flows.
## Testing
- Cover configuration parsing, serialization, and fallback behavior.
- Verify plugin, executor, and skill OAuth registrations use their configured
callback ports instead of the global port.
GitOrigin-RevId: 7f65e5e7869358307e49779f1b75e8672b607736
## What changed
When `Ctrl-C` is pressed with an empty composer while a task is running in a local daemon session, show a menu that lets the user:
- cancel the task and stay in Codex;
- exit Codex while leaving the task running; or
- stop the task and exit Codex.
Do not offer background execution for side-thread tasks or when follow-up messages are queued. Preserve existing `Ctrl-C` behavior for non-daemon sessions, drafts, paste bursts, MCP startup, and returning from an active side thread.
## Testing
Add TUI tests for each exit action, menu dismissal, side threads, queued follow-ups, composer input, MCP startup, and non-daemon sessions.
GitOrigin-RevId: 539c33d3a4ff288a015bddbe9465d2bbdbe018d0
## What changed
- Exclude current-time reminder developer messages when copying parent history into a full-history subagent.
- Keep the child's newly generated reminder, preventing inherited reminders from accumulating while preserving the rest of the forked context.
## Testing
- Extend the full-history V2 spawn test to verify that two reminders in the parent become one fresh reminder in the child request.
GitOrigin-RevId: fb61c72f7f0d61d1068f2c599a8b8caf1788b7e2
## Why
Client-authored developer instructions should remain available after a context
window is compacted when `retain_client_developer_messages` is enabled.
## What changed
- Preserve annotated client-authored developer messages during remote compaction
v2 and local token-budget context resets.
- Apply the existing retained-message token budget when carrying those messages
into the new context window.
## Testing
- Cover enabled and disabled retention for remote compaction v2, manual
token-budget compaction, and mid-turn automatic compaction.
GitOrigin-RevId: 4cb3782cb86ef46458413a17a3255d0016fd675f
## What changed
- Wrap injected current time reminders in `<current_time_reminder>` tags.
- Keep direct `clock.curr_time` tool output and log previews as plain text.
## Testing
- Update core and app-server coverage for tagged reminders and untagged tool output.
GitOrigin-RevId: ad27f1fa10cca7f83d1ac731e01255320bb60f47
## Why
Guardian V2 needs the requested action and its conversation context to assess
risk; a tool name and call ID alone do not describe what the tool will do.
## What changed
- Expose the original, pre-hook `ToolPayload` to tool lifecycle contributors.
- Build Guardian V2 classifier input from the bounded conversation transcript
and a structured planned-action object containing the tool name and arguments.
- Warn and skip classification if the planned action cannot be serialized.
## Testing
- Verify lifecycle contributors receive tool arguments.
- Verify Guardian V2 sends transcript history and planned-action JSON to the
classifier.
GitOrigin-RevId: 28266ef7c1d2267ba705fcfbd9be4ef48e64e104
## What changed
- Add the experimental `thread/revert` request, which replaces a loaded paginated thread's durable history with the prefix before `beforeTurnId` while preserving the thread ID.
- Interrupt any active turn, reload the replacement history without unloading the thread, preserve mutable thread settings, and emit `thread/reverted`.
- Return backward pagination cursors for the retained turns and items, reject stale rollout paths after a revert, and document that local file changes are unaffected.
## Testing
- Cover history replacement, pagination, stale paths, missing turns, subsequent turns, active-turn interruption, and preserved thread settings.
GitOrigin-RevId: 435a8163ad4f310cc47219b436f6bdde21f2b83a
## What changed
- Keep the configured `approvalPolicy` when a model in
`auto_review.required_on_models` selects the `auto_review` reviewer.
- Continue downgrading full-access sessions to workspace-write and rejecting
incompatible reviewer overrides.
## Testing
- Cover supported approval policies across thread start, settings updates,
turn-time model switches, resume, and fork flows.
GitOrigin-RevId: 2bd3e2dcd46f3cadeb2fad20222cf8917c267208
## Why
Local MCP requests can fail when the platform TLS backend cannot negotiate a
protocol version with an HTTPS endpoint.
## What changed
- Retry replayable local MCP requests once with rustls after a recognized TLS
protocol-version negotiation failure. Keep certificate, timeout, and unrelated
connection failures on the existing error path.
- Remember successful fallback per HTTPS origin and outbound route, while keeping
the platform TLS backend as the default for other destinations.
- Share the fallback-enabled client across local MCP resolution, CLI login, and
OAuth discovery while preserving remote environment HTTP clients.
## Testing
Added coverage for platform-specific error detection, request replay, cached
fallback reuse and isolation, non-replayable requests, redirects, and remote MCP
client selection.
GitOrigin-RevId: 39a2d96fdb2ea0e51df14f652ba2a953d24e69a1
## What changed
- Use the specialized Node REPL approval guidance only when the parent turn's
model sets `node_repl_auto_review_required`.
- Keep Node REPL JavaScript requests on the generic approval prompt otherwise.
- Cover both prompt paths in the Guardian tests.
GitOrigin-RevId: e3eb89a59cc74fe2b53bb1c3f29a30d450e173de
## Why
The model provider does not reliably identify which curated plugin catalog is
available. ChatGPT authentication can be used with a custom provider, while an
unauthenticated session should use the API-compatible catalog regardless of its
provider.
## What changed
- Select the ChatGPT curated catalog only for authentication modes that use the
Codex backend; use the API curated catalog for API-key and unauthenticated
sessions.
- Initialize standalone plugin managers with the current authentication mode
across CLI, app-server, MCP, and external-agent migration paths.
- Preserve authentication mode while detecting and importing migrated plugins.
## Testing
- Cover catalog and skill routing across ChatGPT, API-key, unauthenticated,
Bedrock, and custom-provider configurations.
- Verify authenticated plugin migration uses the ChatGPT curated marketplace.
GitOrigin-RevId: 660a339ee8891c33aad961078d3a979242a6a166
## Why
JavaScript executed through the Node REPL can invoke connected MCP, browser,
or computer-use tools, so reviewing only the outer tool call does not capture
its immediate effects.
## What changed
- Add dedicated Guardian review guidance for `node_repl` `js` requests that
evaluates nested calls, authorization boundaries, staged data, and concrete
side effects.
- Keep the existing generic approval prompt for other MCP tools and shell
requests.
## Testing
- Cover the dedicated Node REPL prompt, retry reasons, serialized request data,
and the generic fallback behavior.
GitOrigin-RevId: bf8d49d7e3dc3d36aa41b6b56ff8a0eb02da3e53
## Why
Workload identity credentials are owned by the app-server host and must not be replaced, removed, or exported through client account operations.
## What changed
- Reject account login and logout RPCs while workload identity is selected.
- Continue reporting the active authentication method from `getAuthStatus`, but omit the host-owned token even when `includeToken` is requested.
GitOrigin-RevId: 750c9d07ed2f4ba7007bbe75f188573e79749647
## What changed
- Treat workload identity environment markers as an explicit authentication selection, even when another process credential is present.
- Return initialization errors from `AuthManager` and propagate them through commands and services instead of continuing with an unusable authentication state.
- Make `codex login status` validate workload identity, keep the TUI on an embedded app server for local workload identity, and reject workload identity in `codex mcp-server`, where it is unsupported.
## Testing
- Cover workload identity precedence and partial configuration errors.
- Verify login status reports an unreadable identity assertion and app-server routing enforces the supported workload identity topology.
GitOrigin-RevId: efc6b6b4cd4d61652617de82aaa3d7ffc75d6618
## What changed
- Make `ThreadEnvironments` the source of truth for live environment selections and use it when building configuration snapshots, permission profiles, per-turn configuration, and MCP refresh inputs.
- Keep settings previews side-effect free while applying accepted environment updates consistently to subsequent turns.
- Move `EnvironmentConfig` into `codex-protocol` so environment ownership no longer depends on a core-only type.
## Testing
- Cover environment previews and snapshots, accepted and rejected steer updates, and active-turn environment stability.
GitOrigin-RevId: 7bcf8fb5df1215f720e4e9c419541a51a871aa5e
## Why
Transient executor disconnects could leave capability discovery and skill catalogs
stuck on a cached failure for the rest of a thread, even after the executor
reconnected.
## What changed
- Replay capability discovery after executor recovery and retry transient failures
on later requests while continuing to cache permanent failures.
- Avoid caching skill catalogs produced from failed discovery so a later step can
load the recovered catalog.
- Mark the MCP runtime dirty when recovered manifests change the projected MCP
servers, and allow discovery to be cancelled with the turn.
## Testing
- Cover same-request recovery after a disconnect and recovery on a later request.
- Cover retry classification through connection-attempt errors and skill catalog
caching after discovery recovers.
GitOrigin-RevId: a57f90844351e73ea831931f72a9ddc4e4f3335c
## What changed
Clarify that commits created through a GitHub app or plugin must include the
Codex co-author trailer in the tool's `message` argument. This covers commits
that create, update, or delete files.
GitOrigin-RevId: 58be9302da9f8d4f11aa100c32f779fac9cc05e9
## Why
When an MCP server rejects existing OAuth credentials, reporting that the server
is merely not logged in obscures that the user needs to authenticate again.
## What changed
Pass the MCP startup failure reason into error formatting and report that the
server requires OAuth reauthentication when appropriate. Preserve the existing
recovery hint for either `codex mcp login` or the client's OAuth sign-in flow.
## Testing
Cover the reauthentication message for both login flows and verify it in the
streamable HTTP OAuth round-trip test.
GitOrigin-RevId: 6f6d5fe7519b1a476f8b70d976223b2ea1ec938e
## Why
App tool file arguments could read and upload files without applying the active
filesystem sandbox policy.
## What changed
- Apply the effective filesystem policy, including session and turn grants, when
reading metadata and streaming files for upload.
- Reject uploads before contacting the files endpoint when the selected path is
denied.
- Report an error when the executor cannot provide sandboxed file streaming for
a restricted policy.
## Testing
Added integration coverage showing that restricted policies allow permitted
files and reject denied files before upload.
GitOrigin-RevId: 63b239c5066dcb9d18b5050089c659fb2a784909
## What changed
- Classify simple PowerShell `Get-Content` commands, including `gc` and `type` aliases, as file reads while preserving Windows paths.
- Reuse the shared classification for implicit skill invocation detection on Windows and render recognized commands as `Read <file>` in the TUI.
- Leave commands with unsupported flags, multiple operands, wildcards, or expressions unclassified.
## Testing
- Cover supported and rejected PowerShell forms, Windows executor skill detection, and the TUI read summary.
GitOrigin-RevId: 4e8f5470f2ae31c08d74091f9634c2926e516ccf
## What changed
- Add a configurable renderer that converts conversation messages, agent
messages, tool calls and outputs, and reasoning into a numbered plaintext
transcript.
- Keep only relevant readable content, including manual-approval developer
messages, while omitting media payloads, encrypted content, and unsupported
response items.
- Limit transcripts to the most recent 320 KiB without splitting UTF-8
characters.
## Testing
- Cover source selection, content filtering, tool-name correlation, and bounded
UTF-8 truncation with unit tests.
GitOrigin-RevId: e2c6535f4a895862ca744258399fb36fc92e42c6
## Why
Thread stores may filter a metadata patch to a no-op. Requiring every successful
update to return a `StoredThread` forces those implementations to materialize a
thread even when the caller does not need one.
## What changed
- Let `ThreadStore::update_thread_metadata` return `None` after a successful
update that did not materialize a thread.
- Preserve the materialized-thread contract of `LiveThread` and `ThreadManager`
metadata updates by reading the thread when the store returns `None`.
- Keep completion-only metadata updates from issuing that fallback read.
## Testing
Cover materialized in-memory updates and verify that fallback reads occur only
for callers that require the updated thread.
GitOrigin-RevId: 3059efc9d5b69e0b46e35fb5b5aa9638086654f2
## What changed
- Register a tool lifecycle contributor when Guardian V2 is installed.
- On tool start, asynchronously ask the existing Luna sampler for a low-effort
`action_risk` score constrained to the range from `0.0` to `1.0`.
- Bound the tool metadata supplied to the classifier and treat it as untrusted
input.
- Emit an extension warning if classification sampling fails.
## Testing
Add an integration test that verifies the contributor reuses the configured
Luna pool and sends the expected model, attribution metadata, reasoning effort,
strict output schema, and tool-call context.
GitOrigin-RevId: 6b69fcc0443086544086849c38bcdd90560a291f
## What changed
- Prewarm two Responses WebSocket connections and grow the pool on demand, up to eight connections, so overlapping samples can run concurrently.
- Lease each connection to a single sample and return healthy connections to the idle pool after completion.
- Replace closed or 55-minute-old connections and retry a sample once after a retryable or stream error.
- Keep the sampler available when the second prewarm connection cannot be opened.
## Testing
- Cover connection reuse, partial prewarm success, concurrent pool growth, and retrying an expired connection on another warm connection.
GitOrigin-RevId: 3ee7b05adc00a2135ba7cb35f6e4455199bf3784
## What changed
- Add a shared, read-only `ConversationHistorySnapshot` capability to the extension API.
- Include the snapshot in `ToolStartInput`, preserving conversation order while excluding contextual user messages.
- Avoid acquiring a history snapshot when no tool lifecycle contributors are registered.
## Testing
- Verify snapshots share existing response items, remain stable as history changes, and filter contextual user messages.
- Verify tool-start callbacks receive the history available for successive tool calls.
GitOrigin-RevId: 822cae33781dd876ea628f104be08d8a449a4900
## What changed
Rebuild the tracing callsite interest cache after installing the test-local
subscriber so the `event_enabled!` assertion uses that subscriber's filters.
GitOrigin-RevId: d221dca4d7e7cb2ddd492a46f7a9d5c977088593
## Why
Serde's generic buffering for flattened and internally tagged fields is incompatible with `serde_json`'s `arbitrary_precision` representation. As a result, persisted rollout items containing nested floating-point values can fail to decode.
## What changed
- Decode the rollout envelope at the JSON persistence boundary before deserializing the item payload.
- Use the shared decoder for both session resume and thread-history projection.
- Cover token-count floats, response-item metadata, field ordering, and ignored metadata in the decoder compatibility test.
GitOrigin-RevId: 59c7f6fbcf83162b5ed6980a69381fe45fc20a0a
## What changed
- Capture accepted, successful `node_repl` results from Code Mode and include them as bounded, untrusted evidence in Guardian review prompts.
- Enable the enhanced transcript through `guardian_enhanced_node_repl_transcripts` or when the selected model requires automatic Node REPL review.
- Keep this evidence out of the parent model history, exclude encrypted and failed results, and avoid resending admitted evidence when a Guardian session is reused.
- Clear retained evidence and invalidate review sessions when a thread is rolled back.
## Testing
- Add unit coverage for evidence ordering, escaping, truncation, and empty responses.
- Add an integration test covering feature-disabled, feature-enabled, and model-required behavior, including filtering and review-session reuse.
GitOrigin-RevId: edc3dca5d5b88d472a492f35531ec46889a89d72
## Why
Sandboxed descendants can outlive their immediate parent and must be collected by
PID 1 in the Bubblewrap namespace.
## What changed
- Launch `codex-linux-sandbox` with Bubblewrap's `--as-pid-1` option, and fall
back to the bundled Bubblewrap when the system version does not support it.
- Run the sandboxed command as a child, forward signals to it, reap other exited
descendants, and preserve the command's exit status.
- Verify proxy bridge parent identity when arming its parent-death signal.
## Testing
Added Linux sandbox coverage for the filtered namespace reaper, orphan
collection, and fallback from an incompatible system Bubblewrap.
GitOrigin-RevId: 379f08d6c2732ea0a4caeb61f93ae302e16d2458
## Why
Hooks supplied as managed requirements must not be silently skipped when their
handlers cannot be loaded.
## What changed
- Fail session and app-server thread startup when an enabled managed requirement
contains an invalid matcher, an empty command, or an unsupported handler type.
- Keep load failures for ordinary managed configuration hooks as warnings, and do
not enforce managed hook requirements while the hooks feature is disabled.
## Testing
Added hook-engine, core session, and app-server coverage for valid and invalid
managed hook requirements.
GitOrigin-RevId: 91a23b0c1d85e143aba6aabe874c5274e52fc6b2
## Why
Project-local configuration can launch host processes. Requested write access may be reduced to read-only by managed constraints or platform support, so the request alone must not cause the app server to trust a project and load its configuration.
## What changed
- Base automatic project trust on the effective permission profile after configuration is loaded.
- Trust managed profiles only when their effective filesystem policy allows writes to the working directory.
- Continue resolving trusted nested working directories to the repository root.
## Testing
- Verify that managed read-only permissions neither persist project trust nor load a project-local MCP server when workspace-write access was requested.
- Cover effective read-only fallback for workspace-write requests and nested repository working directories.
GitOrigin-RevId: e548fd9c4552c328f779cc0365fe86f37d4a9b71
## What changed
- Rework the bundled `skill-creator` guidance around concise, scoped instructions, progressive disclosure, optional resources, invocation policy, and risk-based forward-testing.
- Simplify generated skill and reference templates so new skills start with only the placeholders and resources they need.
- Reject unfinished `[TODO: ...]` placeholders in skill descriptions and instruction bodies while allowing examples inside fenced code blocks.
GitOrigin-RevId: b0871aaeeb768c12b1a467d48037eecc8db5d52b
## Why
Structured output can be complete before the Responses stream emits its terminal
events. Waiting for those events unnecessarily delays the sampler and can leave it
waiting after usable output has arrived.
## What changed
- Return a Luna sample as soon as accumulated text deltas parse as a complete JSON
object.
- Continue draining the remaining response events in the background so the
authenticated WebSocket stays reusable for subsequent samples.
- Enforce the output-size limit while accumulating deltas on the early-return path.
## Testing
- Cover returning complete JSON without terminal response events.
- Verify that early return still allows the authenticated WebSocket to be reused.
GitOrigin-RevId: 80c9963f1540f7862356aaad3503e3071a8fb92a
## Why
Awaiting a bounded consumer event queue can stall the in-process app-server
worker when notifications are not being drained, preventing it from delivering
a request response queued behind them.
## What changed
- Use an unbounded queue for caller-facing in-process events while keeping
command and embedded-runtime queues bounded.
- Preserve all events in order instead of dropping best-effort events and
emitting lag markers when the consumer queue fills.
- Document that callers can await requests without concurrently draining
notifications.
## Testing
Add a regression test that fills a capacity-one client with unread settings
notifications, verifies subsequent requests complete, and then confirms the
notifications remain readable in order.
GitOrigin-RevId: 6ca6cfb9349dfa04a613236836f813c1f799783e
## Why
Terminal autowrap for oversized URL tokens can drop the user-message gutter and background on continuation rows.
## What changed
- Explicitly wrap long URLs within the available message width.
- Preserve the complete OSC 8 hyperlink destination on every wrapped fragment.
- Keep the user-message gutter and background styling across continuation rows.
## Testing
Add history-cell and VT100 coverage for URL content, hyperlink targets, gutters, and backgrounds across wrapped rows.
GitOrigin-RevId: 59514eee4ab967bd937b55574b9f8d0d1c82df7c
## Why
Guardian review sessions must not gain access to paths that the parent turn is
not allowed to read.
## What changed
- Derive Guardian permissions by intersecting managed parent filesystem rules
with read-only access, preserving denied paths and restricting network access.
- Offer Guardian execution tools only when a managed sandbox can enforce those
rules.
- Include the selected environment IDs in the review-session reuse key so a
session is not reused across different environment sets.
## Testing
Update the Guardian reuse integration test to verify that a review cannot read
a parent-denied file or write a local file while consecutive reviews still
reuse the same session.
GitOrigin-RevId: 20f17a6c379f1eda651e8508459d642a51e4ce94
## What changed
- Add a `LunaSampler` that opens an authenticated Responses WebSocket and reuses it for structured, tool-free `gpt-5.6-luna` requests.
- Carry the host's provider, authentication, proxy, attribution, and service-tier configuration into the connection and requests.
- Require strict JSON schemas, preserve per-request reasoning effort and turn metadata, and reject missing or oversized output.
## Testing
- Add a WebSocket test covering authentication and attribution headers, connection reuse, structured request fields, per-turn metadata, reasoning effort, and returned output.
GitOrigin-RevId: aef85fd8ddcfcb7c76a9ede0d3191e3a0321656b
## What changed
- Add a `SecurityRiskScore` rollout item containing a category and numeric score.
- Persist the item in both thread history modes while excluding it from model context, user-visible thread history, search text, forks, and reconstructed conversation history.
- Re-export the score type from the extension API.
## Testing
- Cover serialization, persistence and loading, thread history projection, session reconstruction, append planning, and memory filtering.
GitOrigin-RevId: 1926fe366aeaa75052708a6da589f45a38eefb52
## What changed
- Send the scripted HTTP response before queuing body deltas in the
single-stream byte-budget test.
- Allow 30 seconds for barrier requests in both byte-budget tests while
retaining the default timeout for other operations.
GitOrigin-RevId: ac65580b479d93fcbcca787f15e04c084f0aa56b
## What changed
- Add dedicated coverage for explicitly starting a queued item that a prompt hook rejects.
- Verify the rejected item is consumed and no model request is sent.
- Keep the automatic queue dispatch test focused on consuming a rejected item while allowing later queued input to proceed.
GitOrigin-RevId: e01cefb9d8581b0d4be05d4595f279d61e628e83
## What changed
- Collect borrowed call IDs in a single pass instead of cloning IDs across
separate sets.
- Record orphan positions and compact the history only when orphan outputs are
present, while preserving the existing matching and error behavior.
GitOrigin-RevId: de399ba92ff451cb12fc69218d60d3ac29fccb3d
## Why
Streaming reads previously rejected requests that used a platform filesystem
sandbox.
## What changed
- Open streamed files in the sandbox helper and return the open file to the
exec-server by passing a file descriptor on Unix or duplicating a file handle
on Windows.
- Advertise support through the `sandboxedFileStreaming` environment capability.
- Preserve close-on-exec behavior for transferred descriptors, including the
required inherited-descriptor cleanup on macOS.
## Testing
- Cover bounded sandboxed streams, continued reads after path replacement, and
rejection of symlink escapes outside readable roots.
GitOrigin-RevId: 677b2444b74e834b78b87a8554bc119c1c6e08b2
## What changed
- Add the `codex-guardian-v2` crate with an extension install entry point that does not register contributors yet.
- Register the crate in the Cargo workspace and add its Bazel target.
GitOrigin-RevId: 7c0c9479c6722d65f0f0dad9b0fd4a756e4649b3
## What changed
- Use a never-resolving promise when verifying that a session continues to
enforce its yield limit after terminating a cell.
- Use `yield_control()` to create the yielded cell in the notification-draining
test instead of relying on timer scheduling.
GitOrigin-RevId: 01cdaa94e5b8b5c89c6fa98c4bbdb28a690678e0
## Why
Inline visualization viewer documents must remain outside locations that a
sandboxed session can modify before they are opened in a browser.
## What changed
- Materialize viewer documents in a dedicated cache under `CODEX_HOME`, keyed
by the source and artifact thread IDs, instead of alongside visualization
artifacts.
- Create visualization links only when the active filesystem policy cannot
write to the viewer cache. This also disables links for full-disk-write
sessions and applies the policy consistently when loading transcript history.
- Reject viewer cache paths containing symbolic links and track materialized
documents in memory so unchanged viewers are reused without trusting existing
file contents.
## Testing
- Verify that rendering an unchanged visualization reuses the existing viewer
file, while an updated fragment refreshes it.
GitOrigin-RevId: 12b7fbe522a68076e5d683a987b7801940d131c2
## What changed
- Add `RecoverTurnRequest` and `CodexThread::recover_turn_if_idle` to resume an interrupted regular turn with its existing turn ID and updated thread settings.
- Treat recovery separately from automatic idle work so it can resume in Plan mode without injecting an empty user message.
- Reject recovery while another turn is active without applying settings or queuing input.
## Testing
- Cover successful Plan-mode recovery, turn ID preservation, and the absence of an empty user message.
- Cover active-turn rejection and verify that it leaves settings and pending input unchanged.
GitOrigin-RevId: 2376fdc78b5d48b571633981960741ba269ab1ef
## What changed
- Represent blocked network requests as approval actions so permission hooks,
automatic review, and user review use the common approval flow.
- Route network requests using the active turn's review settings, including for
background terminals started by an earlier turn.
- Record the final applied network decision in tool telemetry without exposing
the destination or assigning an approval source.
- Persist deny amendments and keep the blocked request denied.
## Testing
Added coverage for strict automatic review, cross-turn background network
requests, deny amendment persistence, and destination-safe telemetry.
GitOrigin-RevId: a2a9d106962f407ed93f4d198f40ced15f090b8e
## What changed
- Add `ThreadStore::revert_thread` to retain history before a selected turn by creating a new immutable rollout and atomically switching the thread's stored rollout path.
- Preserve the logical thread ID and session metadata across repeated reverts.
- Track every rollout owned by a thread so archive, unarchive, and delete operations handle the complete lineage and restore moved files when metadata updates fail.
- Prevent deletion when forks still reference any rollout in the thread's lineage.
## Testing
- Cover repeated reverts, compressed source rollouts, lifecycle operations over reverted histories, reference-aware deletion, and cross-process unarchive locking.
GitOrigin-RevId: 1c05a6db3d0036ee91b562263d7ca200c6a0ea71
## What changed
- Delete the unused standalone `apply_patch` instruction template and its
`codex-prompts` export.
- Simplify prompt-caching coverage to assert that requests use the model's base
instructions.
GitOrigin-RevId: 8c0dc9426d9ac0184d587272622db608a75e8436