Commit Graph

9528 Commits

Author SHA1 Message Date
Charlie Marsh
a7edf37cb4 Remove the TUI test dependency on codex-cli (#38746)
## What changed

Remove the unused `codex-cli` dev-dependency and the no-op import that kept it
visible to `cargo-shear`. TUI tests continue to locate spawned binaries through
`codex-utils-cargo-bin`.

GitOrigin-RevId: ba5855590c6f0300845170f15f39d77c0611a60a
2026-08-15 11:01:30 +00:00
Charlie Marsh
3c7ae4a812 Scope TUI app directory state to the active context (#38743)
## Why

App directory data and in-flight requests can outlive the account, workspace, or thread that produced them, allowing stale apps to appear in the current TUI context.

## What changed

- Invalidate cached app data, dismiss the app picker, and start a fresh fetch when the account, workspace, or thread changes.
- Tag app directory fetches with their originating thread, workspace, and scope generation, and ignore queued requests or results that no longer match.
- Treat `AppListUpdated` notifications as revalidation signals instead of directly adopting their unscoped contents, with deduplication and a bounded error retry.

## Testing

Added coverage for stale request and result rejection, context invalidation, picker dismissal, and notification revalidation.

GitOrigin-RevId: f20930a0598a6abbdfb3c7826ec955346fe2da7a
2026-08-15 10:57:15 +00:00
Abhinav
85fc4def35 Add MCP tool handler support to the hooks engine (#38705)
## What changed

- Discover synchronous `mcp_tool` hook handlers and invoke their configured MCP server and tool through a supplied executor.
- Expand nested hook-event placeholders in MCP tool inputs while preserving JSON types, and process tool output through the existing hook output contract.
- Represent hook details as handler-specific metadata in `hooks/list`, including MCP server and tool fields, and show those details in the TUI hooks browser.
- Skip unsupported `SessionEnd` MCP hooks and runtimes without MCP invocation support with startup warnings.

## Testing

- Cover argument expansion, missing placeholders, MCP invocation and hook decisions, discovery warnings, `hooks/list` metadata, and TUI rendering.

GitOrigin-RevId: 295b845471fe92bd7ad7cd272fbcd2c3713912e0
2026-08-15 05:53:54 +00:00
kevinlin-openai
3685a61dad Normalize CRLF line endings in pasted text (#38704)
## Why

Replacing every carriage return with a line feed turns each CRLF pair into two
line breaks when text is pasted into the TUI composer.

## What changed

Normalize CRLF pairs before converting remaining bare carriage returns, so each
pasted line ending becomes a single line feed while existing line feeds remain
unchanged.

## Testing

Add a regression test covering mixed CRLF, bare CR, and LF line endings.

GitOrigin-RevId: 86c66d2a52fae52c9ae58c2f24a49eed685b60be
2026-08-15 05:43:44 +00:00
Abhinav
e5470f1bce Refresh hook runtimes after plugin changes (#38703)
## What changed

- Rebuild hook runtimes for loaded sessions when effective plugins change or a marketplace upgrade installs new plugin content.
- Refresh plugin-related caches and MCP runtimes alongside hooks after plugin mutations.
- Preserve each loaded session's current configuration while rebuilding its hooks.

## Testing

- Cover direct plugin upgrades, including subsequent turn and session-end hooks.
- Cover automatic marketplace upgrades for an already loaded session.

GitOrigin-RevId: fef64c68d652f300c7f3d88e81c5017459aa9a18
2026-08-15 05:28:53 +00:00
Dylan Hurd
53f3fa7496 Route permission requests through shared Guardian approvals (#38701)
## What changed

- Represent `request_permissions` calls as shared approval actions and convert them into Guardian permission requests through the common approval path.
- Preserve turn cancellation while an automatic permission review is pending.
- Cover Guardian allow and deny decisions, cancellation without a user-approval fallback, and clean follow-up turns.

GitOrigin-RevId: 95d0df0288e232f32b162756aa7d64a30df7efa5
2026-08-15 05:09:19 +00:00
Ben Romano
4861236f06 Propagate request trace context through exec-server relays (#38690)
## What changed

- Add optional W3C `traceparent` and `tracestate` fields to relay frames.
- Copy trace context from JSON-RPC requests onto relay data frames.
- For encrypted requests split across multiple Noise records, attach the context only to the first record while keeping the request payload encrypted.

## Testing

- Cover trace propagation for both Noise relay paths, including fragmented encrypted requests.

GitOrigin-RevId: a61bbbefef31e2e7e93a43f439c5f296700feb7b
2026-08-15 03:00:35 +00:00
sayan-oai
2ca575026c Support pending environment attachment configuration (#38684)
## Why

An environment connection can be available before its owner has supplied the
configuration for a particular thread attachment. Threads need to start without
blocking while ensuring turns do not use that attachment prematurely.

## What changed

- Accept `Pending` environment configuration and resolve each attachment only
  after both its shared executor connection and owner configuration are ready.
- Add a `Failed` configuration state and `environment_failed` callback so an
  owner can fail one thread's attachment without affecting other threads.
- Keep pending and failed attachments out of capability-root inspection and turn
  environments, and allow failed attachments to recover through a ready update.
- Apply owner configuration before waking a waiting turn so its permission
  profile, login-shell policy, capability roots, and tools are immediately
  consistent.

## Testing

Add an integration test covering non-blocking thread startup, independent ready
and failed callbacks, waiting-turn resumption, installed capability and tool
configuration, and recovery from failure.

GitOrigin-RevId: d587e2025d584c867d782d470b18bf5a1a27b76c
2026-08-15 01:39:04 +00:00
Francis Chalissery
eb147c0db3 Surface misalignment policy violations as typed errors (#38682)
## What changed

- Recognize `misalignment_policy_violation` errors from response streams and HTTP 400 or 403 responses.
- Preserve the upstream message, use a fallback for blank messages, and treat the error as non-retryable.
- Expose `misalignmentPolicyViolation` through the app-server protocol and generated schemas so turns fail with a typed terminal error.

## Testing

- Cover streamed and HTTP policy violations, fallback messages, retry behavior, and app-server turn completion.

GitOrigin-RevId: fd3485bf0be7bfe3d51c078bbc36a081692fd57f
2026-08-15 01:34:33 +00:00
Dylan Hurd
4e9a1a9073 Preserve HTTP fallback for delegated sessions (#38681)
## Why

Responses WebSocket fallback is session-scoped. A delegated session created
after its parent switched to HTTP could otherwise make another WebSocket
connection attempt.

## What changed

Disable WebSocket support for a delegated session when the parent session has
already fallen back to HTTP.

## Testing

Add a guardian review regression test that verifies only the parent's initial
WebSocket attempt occurs and the guardian request uses the HTTP response path.

GitOrigin-RevId: 1345f8fe739f55975aef432045348eae5a9278d6
2026-08-15 01:24:46 +00:00
sayan-oai
22bf16a37e Preserve environment configuration ownership (#38678)
## Why

Environment attachments can either inherit configuration from their thread or
provide their own. Later thread setting updates must refresh inherited
configuration without overwriting attachment-owned permissions and capability
roots.

## What changed

- Resolve each attachment's configuration when it is selected and retain
  whether it came from the thread or the attachment owner.
- Apply subsequent thread configuration updates only to thread-owned
  attachments, while preserving ownership across snapshots and child threads.
- Keep the resolved configuration with the environment selection so runtime
  consumers use a single canonical value.

## Testing

- Extend remote-environment coverage to verify that thread-owned permissions
  follow thread updates while owner-provided read-only permissions remain in
  effect.
- Cover configuration inheritance, attachment replacement, and owner-configured
  capability roots.

GitOrigin-RevId: fe70c4be5f151432b69bf4b141e316faa89036ae
2026-08-15 00:43:44 +00:00
Darius Karel
233739e76a Exclude shortcut-modified input from TUI paste bursts (#38675)
## What changed

- Treat plain, Shift-modified, and Windows AltGr character events as text-producing input for paste-burst detection.
- Exclude Super, Hyper, and Meta character events from paste bursts, flushing any pending text before handling them as shortcuts.

## Testing

- Add coverage for plain and Shift-modified spaces, shortcut-modified spaces, pending burst flushes, and platform-specific AltGr input.

GitOrigin-RevId: 3c43224966307fd014eb1586dce0c53ee56c75aa
2026-08-15 00:32:58 +00:00
sayan-oai
1873e947f8 Honor per-environment permission profiles (#38673)
## What changed

- Add a resolved `permission_profile` to each `EnvironmentConfig` and use the
  complete attachment config for execution and capability-root selection.
- Let `Ready` environment configurations override thread permissions while
  `FromThread` selections continue to inherit them.
- Restrict inherited Guardian environment profiles to read-only permissions.

## Testing

- Add coverage proving that a read-only environment blocks writes even when
  the thread permits workspace writes.
- Update environment inheritance, Guardian review, and capability-root tests
  for the resolved attachment configuration.

GitOrigin-RevId: 1a313b9e4892b1a579a0e880e322a782b4f6c0a7
2026-08-15 00:24:25 +00:00
viyatb-oai
15fde8c1f2 Forward executor network policy decisions for auditing (#38670)
## What changed

- Add a best-effort `network/policyDecision` notification for final domain and non-domain policy decisions made by executor-local proxies.
- Validate notifications against the active process on the controller and emit audit events with controller-trusted session and execution metadata.
- Reserve outbound RPC capacity so audit notifications cannot block control messages, and expose valid `chatgpt-account-id` header values for audit attribution.

## Testing

- Cover notification serialization, proxy decision capture, executor-to-controller delivery, trusted metadata handling, and reserved RPC capacity.

GitOrigin-RevId: a39f96a6b3d9401c03d54eaef5b9a6d3fe0da78b
2026-08-14 23:42:40 +00:00
aphonpra-oai
a186f5484d Resolve local JSON Schema refs in Code Mode types (#38664)
## Why

Code Mode rendered document-local `$ref` values as `unknown`, hiding referenced
input and structured-output shapes from generated TypeScript declarations.

## What changed

- Resolve fragment-only JSON Pointer references against the root schema,
  including escaped and percent-encoded pointer segments.
- Preserve `$ref` siblings as intersections and parenthesize unions used in
  `allOf` intersections.
- Bound recursive and repeated expansion, intermediate rendering work, and
  final output size, falling back to `unknown` when a limit is reached or a
  reference cannot be resolved safely.

## Testing

Add unit coverage for recursive, escaped, nested-resource, dangling, and
oversized references, plus integration coverage for generated Code Mode tool
descriptions and MCP structured output types.

GitOrigin-RevId: 95c6aa32e25325b5be9359dfac3b3328e5e7a499
2026-08-14 22:40:19 +00:00
kevinlin-openai
274727d37f Delete Thai combining marks one at a time in the composer (#38662)
## Why

Backspace should let users remove Thai vowel and tone marks without deleting the
entire grapheme cluster.

## What changed

- Treat Thai nonspacing marks as individual backward-deletion boundaries.
- Keep embedded text elements atomic and preserve the existing behavior for
  other grapheme clusters, including decomposed Latin text and joined emoji.

## Testing

Add coverage for successive deletion of Thai marks, cursor rendering after
deletion, unchanged non-Thai grapheme handling, and atomic Thai text elements.

GitOrigin-RevId: f4834183909d93f4b4dd92f5d93e89235dc2b621
2026-08-14 22:35:23 +00:00
johnl-oai
848cbad7f4 Enforce managed deny-read rules in the Windows sandbox (#38660)
## Why

Windows sandbox requests must preserve managed filesystem deny rules across every execution path and setup refresh. Unsupported policies should fail closed instead of allowing a command to run without the requested protection.

## What changed

- Resolve Windows filesystem overrides while constructing each sandbox execution request so both `shell_command` and `exec_command` enforce exact-path and glob deny-read entries.
- Carry resolved deny-read paths into Windows sandbox setup refreshes, including workspace-relative entries.
- Reject unelevated restricted-token requests that cannot enforce deny-read rules.
- Reject recursive globs rooted at a filesystem root unless `glob_scan_max_depth` bounds their expansion.

## Testing

Added coverage for deny-read enforcement through both command runtimes, setup refresh resolution, restricted-token failure, and bounded root-level glob scans.

GitOrigin-RevId: 33dfa4d1a45b14850cbf58f9173717e3e707d9bf
2026-08-14 22:28:33 +00:00
Charlie Marsh
5186e2ccc3 Skip terminal hyperlink layout when no links are present (#38657)
## What changed

Return early from `mark_buffer_hyperlinks` when none of the supplied lines
contain hyperlink metadata, avoiding unnecessary paragraph layout work.

GitOrigin-RevId: bdd6727f3dab7cef87646f97ac955e848cfcfee2
2026-08-14 21:54:14 +00:00
sayan-oai
c530bcd4cd Move permission profile snapshots into the protocol (#38651)
## What changed

- Define `PermissionProfileSnapshot` as a protocol model and re-export it from
  `core-api`.
- Store snapshots directly in core permission state while continuing to apply
  constraints to their concrete `PermissionProfile`.
- Preserve active profile identity and profile-declared workspace roots without
  the core-only resolved profile variants.

GitOrigin-RevId: cc5e03908e62054cde5de691faa47e471f2e1af5
2026-08-14 21:17:29 +00:00
Adam Perry @ OpenAI
ff6e7c77a3 Canonicalize default namespaces in gRPC subscription filters (#38650)
## What changed

- Normalize both tool invocations and subscription filters before matching them.
- Treat missing and empty namespaces as aliases for the `functions` namespace while preserving the namespace reported with each invocation.

## Testing

- Add a gRPC service test covering missing, empty, and explicit default namespaces on both sides of a filtered subscription.

GitOrigin-RevId: 409326f8ee6b3ab9a6ff5ceca0693558bc9c364d
2026-08-14 21:03:00 +00:00
Charlie Marsh
aa1b81e46f Reuse the TUI startup account response during bootstrap (#38649)
## Why

The TUI reads the account to determine login status, then bootstrap reads the
same account again during startup.

## What changed

- Preserve the login-status account response and pass it to app-server
  bootstrap, avoiding the second account request.
- Discard the prefetched response when onboarding or a resume-directory prompt
  allows authentication to change, when a picker replaces the app-server
  session, or when the model provider changes.

## Testing

- Verify bootstrap reuses a prefetched account without issuing another account
  request and retains its account metadata.
- Verify normal bootstrap still reads the account when none was prefetched.
- Verify matching resume directories skip the interactive prompt.

GitOrigin-RevId: 8da1b9104b9e7f048c4254399b126116798d641a
2026-08-14 20:59:34 +00:00
Michael Zeng
b8aa9e9a01 Add an override to skip project configuration (#38647)
## What changed

- Add `LoaderOverrides::ignore_project_config` to bypass project-root discovery and all project configuration layers.
- Keep other configuration sources, including session overrides and cloud configuration, active when the override is set.

## Testing

- Add a config loader test that verifies project configuration is not loaded or parsed while session and cloud values remain effective.

GitOrigin-RevId: b9aa44de526354fad6b900d6ae8d9b5fb8f700bb
2026-08-14 20:53:22 +00:00
Eric Burke
cce33123a1 Read Apple notarization issuer ID from Key Vault (#38646)
## What changed

- Load the Apple issuer ID from the notarization key's `apple-issuer-id`
  tag alongside its key ID and pinned version.
- Require the tag to contain a valid UUID before creating the notarization JWT.
- Remove the separate `APPLE_NOTARIZATION_ISSUER_ID` environment variable and
  release workflow secret wiring.

## Testing

- Cover valid, missing, empty, and malformed issuer ID tags in the macOS
  notarization tests.

GitOrigin-RevId: c42da96a36293cf39312d8238f958f6898247f19
2026-08-14 20:49:15 +00:00
Adam Perry @ OpenAI
fe556c4b6c Deliver gRPC code-mode notifications without truncation (#38645)
## What changed

- Forward notification text to the session delegate without applying the previous 1,024-byte limit or appending a truncation suffix.
- Update the gRPC host integration test to verify that oversized multibyte notification text is delivered unchanged.

GitOrigin-RevId: 9a9e24b359a07540f70ec4e98b28524db3f7a4a0
2026-08-14 20:42:35 +00:00
Charlie Marsh
efa97f9bc6 Show onboarding when Codex home lacks authentication state (#38644)
## Why

Routine state such as history, logs, sessions, or temporary files does not mean
that the default account can authenticate. Treating any non-pristine Codex home
as configured can show the composer before onboarding is complete.

## What changed

- Base the startup decision on authentication-relevant state instead of requiring
  an empty Codex home. Existing credentials, configuration, workload identity,
  managed configuration, or a running local daemon continue to keep the composer
  visible.
- Treat an unreadable or ambiguous home conservatively and keep the composer
  visible.
- Allow onboarding when the legacy `--search` flag is the only configuration
  override.

## Testing

Expanded startup preflight and draft tests to cover existing home state,
credential sources, workload identity markers, daemon state, ambiguous paths,
and search-only overrides.

GitOrigin-RevId: 76837e3fd6aa714f2a7f72d191088a3faae23515
2026-08-14 20:38:52 +00:00
Charlie Marsh
6d97d4c102 Delay the startup composer until first-login onboarding (#38643)
## Why

On a pristine default installation, the provisional composer can appear before
first-login onboarding takes over the terminal.

## What changed

- Detect pristine local installations conservatively, accounting for existing
  Codex state, custom homes, access tokens, system configuration, and managed
  configuration sources, including macOS managed preferences.
- Keep the composer hidden and ignore draft input until onboarding completes,
  while still allowing startup cancellation with `Ctrl-C` or `Ctrl-D`.
- Reveal the configured composer after onboarding for normal new-session
  launches; resume and fork pickers retain their existing startup flow.

## Testing

- Cover pristine and existing home layouts, environment credentials, system and
  managed configuration, inaccessible state, onboarding input suppression,
  cancellation, and the transition to the composer.

GitOrigin-RevId: c1a47ea3ba7c1ff1dd229895c0362b6dd9bfd713
2026-08-14 20:35:11 +00:00
Charlie Marsh
a0bed4be21 Keep the composer editable during TUI startup (#38642)
## Why

Configuration and app-server initialization can take time before the main TUI is ready, leaving users unable to begin drafting a prompt.

## What changed

- Show a provisional composer while startup work runs and carry its text, cursor position, paste state, and attachments into the initialized chat.
- Limit the provisional composer to safe editing and cancellation, and quarantine input around session pickers, approvals, and other actionable startup screens.
- Preserve configuration validation before terminal checks and recover terminal state cleanly from startup failures and caught panics.

## Testing

- Cover startup editing, multiline and large pastes, keymaps, cancellation, session-picker handoff, approval boundaries, and draft restoration.
- Verify non-interactive launches report configuration errors before terminal errors.

GitOrigin-RevId: fe04a85cfbbcff21ff87fa81fd17474827858575
2026-08-14 20:30:30 +00:00
Charlie Marsh
58d2daba45 Harden TUI startup input handling (#38641)
## Why

Terminal probes and other bootstrap work can leave keys or partial control
sequences buffered before an interactive startup screen is visible. Those
inputs must not accidentally select or confirm an action, while typeahead
intended for the composer should survive terminal initialization.

## What changed

- Replay user input consumed by Unix startup probes through Crossterm while
  filtering completed terminal color replies, and avoid consuming the Windows
  console input queue when detecting default colors.
- Drain decoded and unread input after rendering actionable startup screens,
  including onboarding trust, migration, update, provider, resume, and hooks
  prompts. Keep incomplete control sequences quarantined and fail closed when
  an input boundary cannot be resolved.
- Restore terminal modes if initialization exits early and bound terminal probe
  reads by time and byte limits.

## Testing

Add parser, boundary, onboarding, and PTY coverage for preserved typeahead,
split escape sequences, bracketed paste, delayed input, and fresh input after
an interactive screen becomes ready.

GitOrigin-RevId: 321198996cdd88fe9b43c4a762e750bff450482c
2026-08-14 20:23:49 +00:00
Charlie Marsh
7e65e4f330 Render the initial TUI session header before input (#38639)
## What changed

- Drain queued app events until the initial session header is installed before
  handling terminal input.
- Render the active session header without a leading separator so it starts at
  the top of the viewport.

## Testing

- Add a rendering snapshot that verifies the initial header begins on the first
  viewport row.

GitOrigin-RevId: 070417776b629c681b3f94e93ba619dfefe764b1
2026-08-14 20:19:42 +00:00
Adam Perry @ OpenAI
ccee70f813 Remove repository-local Codex skills (#38635)
## What changed

- Remove the `codex-bug` issue-triage skill.
- Remove the `codex-issue-digest` skill, including its collector, agent metadata, and tests.
- Remove the `pushing-ci-changes` skill.

GitOrigin-RevId: 90f69a32b09456271344d49ebe5aa3eed5a8c808
2026-08-14 20:02:03 +00:00
thomas
6bed213411 Add MCP protocol discovery metrics (#38634)
## What changed

- Record a counter and duration for MCP client protocol discovery.
- Tag observations with the configured `legacy` or `auto` mode and classify
  outcomes as `modern`, `legacy`, or `failure`.

GitOrigin-RevId: f348e0d900b437d5a9fef1c33cdb1314f2421785
2026-08-14 19:57:04 +00:00
Adam Perry @ OpenAI
6595071e65 Remove the gRPC code-mode open session limit (#38630)
## What changed

Allow the gRPC code-mode host to register more than
`MAX_IN_FLIGHT_REQUESTS` open sessions. Existing limits on in-flight
requests, control requests, and active cells remain unchanged.

GitOrigin-RevId: 126c5088868e7783f8592f3f9250f5c8573df51f
2026-08-14 19:26:36 +00:00
felixxia-oai
baab1705c6 Make Guardian v2 risk classification configurable (#38628)
## What changed

- Allow `features.guardianv2` to remain a boolean toggle or specify classifier instructions, the review threshold, reasoning effort, and action and instruction token limits.
- Add transcript controls for included sources, per-entry and total token budgets, and the number of recent non-user entries.
- Validate configured ranges and relationships, expose them in the generated config schema, and apply the resolved settings throughout Guardian v2 classification and approval review.

## Testing

- Cover boolean compatibility, configuration parsing and boundaries, config-manager rejection, and the resulting classifier request and approval decision.

GitOrigin-RevId: dc018b53b782e2d6b4d6a795cca4945130a71678
2026-08-14 19:11:41 +00:00
iceweasel-oai
d8d7ca73f8 Enable unified exec by default on Windows (#38625)
## What changed

- Enable the stable `unified_exec` feature by default on every platform.
- Update cross-platform integration test expectations so `exec_command` and
  `write_stdin` are exposed on Windows instead of `shell_command`.

GitOrigin-RevId: e5c864bacbde7eab109e7a0e399b8f7b843b384c
2026-08-14 19:07:15 +00:00
Benjamin Carlsson
1426592fcc Open notes when accepting the request input Other option (#38624)
## What changed

When the generated `None of the above` option is selected in a request user
input prompt, route Enter and configured accept actions to the notes editor
instead of submitting the response. Tab continues to open the same editor.

## Testing

Add a regression test confirming that both Tab and Enter reveal the notes editor
without submitting the response.

GitOrigin-RevId: 8a563d81a82a11ca0b26c2b1100053f13be8e8f4
2026-08-14 19:02:27 +00:00
jif
42b5f05cef Preserve MCP namespace descriptions in the tool catalog cache (#38623)
## What changed

Keep MCP namespace descriptions when publishing tool definitions to the
process-scoped catalog cache. Cached definitions now expose the server
instructions to the model before a lazily started MCP connection finishes
initializing.

## Testing

Update the cached MCP startup integration test to verify that cached namespace
descriptions retain the originating server instructions.

GitOrigin-RevId: d1b73381852fd43c6b54a7c22a599474c774dc20
2026-08-14 18:35:13 +00:00
Adam Perry @ OpenAI
478215c5c1 Preserve large gRPC code-mode tool errors (#38621)
## Why

Code-mode tool failure messages larger than 64 KiB were truncated before they
reached the host.

## What changed

- Remove the tool error size limit from the gRPC protocol and host validation.
- Forward failed tool completion messages without truncation.

## Testing

- Verify that a multibyte error larger than 64 KiB is preserved exactly.

GitOrigin-RevId: 264ae4ba4adea5c19b669e4f41ccfd41a0c30fb5
2026-08-14 18:30:45 +00:00
rhan-oai
395723b238 Source multi-agent instructions from the model catalog (#38619)
## What changed

- Add model-catalog messages for root and subagent roles, explicit delegation, and delegation hints.
- Resolve role instructions in config, catalog, then bundled-default order, while preserving empty values as an explicit way to suppress fallback text.
- Refresh catalog-provided role and mode instructions when the model changes, and give full-history forks the selected child model's subagent role without retaining the parent's role guidance.
- Keep existing config overrides and reasoning-effort behavior, including proactive delegation for ultra reasoning effort.

## Testing

- Cover message deserialization and preservation through model overrides.
- Cover precedence, empty overrides, model switches, resumed sessions, and full-history subagent forks.

GitOrigin-RevId: 4625cf7c6a5490176adddfaa0fb99100707daea9
2026-08-14 18:26:20 +00:00
felixxia-oai
14a6813fa8 Apply Guardian policies to v2 risk classification (#38618)
## What changed

- Include the resolved Guardian security policy in the v2 classifier's developer instructions.
- Prefer an explicit `guardian_policy_config`, then the reviewer model's catalog policy, and finally the bundled policy.
- Limit the combined classifier instructions and policy to 10,000 tokens.

## Testing

- Cover configured and catalog policies, policy truncation, and the bundled-policy fallback.

GitOrigin-RevId: 1b84d70081dd924e214636b4b470d57a63d7cb88
2026-08-14 18:21:22 +00:00
Celia Chen
086396f7f6 Prioritize global models in the Bedrock Runtime catalog (#38617)
## What changed

Group Amazon Bedrock Runtime models by routing variant so every Global model
appears before the US cross-region models, while preserving the base model order
within each group. Update catalog priorities and tests to match the new order.

GitOrigin-RevId: e5a55d61163404172a418cb794b25f3b27f83618
2026-08-14 18:01:06 +00:00
jif
fa595fbab8 Route escalated approval retries through Guardian (#38616)
## What changed

- Bypass extension approval contributors when an approval request includes a retry reason, ensuring the retry is reviewed by Guardian.
- Add coverage showing that Guardian can deny an escalated retry even when an extension contributor would approve it, and that the retry reason is included in the review request.

GitOrigin-RevId: c8f556623f26fea605898d4b8e89679cebd63e65
2026-08-14 17:56:38 +00:00
Adam Perry @ OpenAI
0fce933290 Remove the gRPC code-mode enabled tool limit (#38615)
## What changed

Stop rejecting code-mode execute requests solely because `enabled_tools`
contains more than 1,024 definitions. Continue validating each tool definition
while converting the request.

GitOrigin-RevId: da83b61c5f659e6aa221ed663821edcdfc29d3f1
2026-08-14 17:50:01 +00:00
jif
f535950eaa Skip stale Guardian risk score persistence (#38612)
## Why

Concurrent Guardian samples can finish out of order. A stale result rejected by
the thread's latest-score update could still be appended to the rollout.

## What changed

Return without persisting a risk score when `insert_if` rejects it as older than
the score already stored on the thread.

GitOrigin-RevId: 7b2c895742753a19dfe48fd7f8ecd912d3cd3af6
2026-08-14 17:41:34 +00:00
cooper-oai
fb5aa093e0 Support workload identity in remote exec-server auth (#38610)
## Why

Remote exec-server registry requests need to refresh managed credentials before sending a request. Static auth-header resolution cannot perform the asynchronous token exchange required by workload identity.

## What changed

- Add asynchronous auth-header resolution to `AuthProvider`, with the existing static-header behavior as the default.
- Resolve fresh managed credentials for each remote environment registry request while preserving the expected account and workspace identity.
- Load the cloud configuration bundle during remote exec-server startup when workload identity is selected.

## Testing

- Update the managed-auth and environment-registry auth tests to exercise asynchronous header resolution.

GitOrigin-RevId: 5d60f1127467aaacdb5d1a8f3d92278bc4bf2e29
2026-08-14 17:32:37 +00:00
jif
c0d59bf614 Fix the missing resume picker history mode import (#38608)
Import `ThreadHistoryMode` where the resume picker uses it for session
selection state and history mode tracking.

GitOrigin-RevId: ae8b30ad959c872d35eb2a38d514e67ecf1275f1
2026-08-14 17:18:26 +00:00
Adam Perry @ OpenAI
a3cb1c14fb Allow larger gRPC code mode tool descriptions (#38606)
## What changed

Stop rejecting gRPC execute requests when an enabled tool's description exceeds
16 KiB. Identifier, tool-count, and subscription-filter limits remain in place.

GitOrigin-RevId: c30dbf555e691b02bd6d6a835a0c40f671b0d172
2026-08-14 16:42:32 +00:00
Charlie Marsh
3b3a91ccf0 Fix resume transcript preview line selection (#38605)
## What changed

- Scan legacy and paginated transcript items newest-first and stop after collecting the six newest nonblank preview lines.
- Keep paging through bounded paginated history when newer items do not produce visible preview text, while preserving chronological display order and assistant markdown rewrites.
- Move transcript preview loading into a focused module and add coverage for reverse scanning, legacy/paginated parity, and paging past invisible items.

GitOrigin-RevId: 576afe37d034b32db363691bd4f401815fffaea7
2026-08-14 16:37:40 +00:00
Charlie Marsh
1bb6384c19 Avoid paginated resume requests for verified legacy rollouts (#38604)
## Why

Resuming a known legacy rollout with `excludeTurns` first requires the TUI to
retry after the app server rejects paginated history loading.

## What changed

- Carry the history mode reported by the session picker into the resume flow.
- For embedded app-server sessions, resume a legacy rollout with its turns when
  the rollout is still legacy and background migration cannot race the check.
- Keep requesting paginated history when the picker metadata may be stale,
  migration is enabled or active, or the app server is remote.

## Testing

Added coverage for picker server replacement, background migration, maintenance
lock contention, stale history metadata, and paginated resume requests.

GitOrigin-RevId: 2300d1ad93a817eeeeb8f8ed60b073400ddf7106
2026-08-14 16:33:28 +00:00
Dylan Hurd
588ee89324 Isolate Guardian reviewer sessions from parent extensions (#38602)
## What changed

- Start Guardian reviewer delegates with an empty extension registry while preserving extension inheritance for other delegates.
- Disable `GuardianV2` in the reviewer session configuration so reviews do not trigger nested Guardian processing.
- Cover both the reviewer isolation and continued delivery of parent-session tool lifecycle events.

GitOrigin-RevId: 858b3e23d1c06177e443fb0779fcf06cc5294fc2
2026-08-14 16:28:42 +00:00
Adam Perry @ OpenAI
da898490fc Make unbounded connection retries configurable (#38601)
## What changed

- Add the stable, default-enabled `unbounded_connection_retries` feature.
- Require the feature for unbounded sampling retries after connection failures.
  When disabled, connection failures use the existing bounded retry and
  transport fallback path.
- Expose the feature in the generated configuration schema.

GitOrigin-RevId: bd80d02ef065ba924f805c29b639752fc817ed64
2026-08-14 16:23:17 +00:00