Commit Graph

9937 Commits

Author SHA1 Message Date
Michael Bolin
b71c13ebf0 merge commit for archive created by Sapling 2026-03-20 12:03:01 -07:00
Michael Bolin
d90caa52a9 fix: fall back to vendored bubblewrap when system bwrap lacks --argv0 2026-03-20 12:02:45 -07:00
Michael Bolin
fabfdff909 Merge e1b1e33021 into sapling-pr-archive-bolinfest 2026-03-20 11:57:52 -07:00
Michael Bolin
e1b1e33021 fix: fall back to vendored bubblewrap when system bwrap lacks --argv0 2026-03-20 11:57:38 -07:00
Michael Bolin
553449b2df merge commit for archive created by Sapling 2026-03-20 10:58:15 -07:00
Michael Bolin
c59669d603 fix: flip use_legacy_landlock feature so it defaults to true again 2026-03-20 10:57:59 -07:00
pakrym-oai
4ddde54c19 Add remote test skill (#15324)
Teach codex to run remote tests.
2026-03-20 10:37:57 -07:00
jif-oai
b9fa08ec61 try to fix bazel (#15328)
Fix Bazel macOS CI failures caused by the llvm module's pinned macOS SDK
URL returning 403 Forbidden from Apple's CDN.

Bump llvm to 0.6.8, switch to the new osx.from_archive(...) /
osx.frameworks(...) API, and refresh MODULE.bazel.lock so Bazel uses the
updated SDK archive configuration.
2026-03-20 10:18:19 -07:00
Eric Traut
4f28b64abc Add temporary app-server originator fallback for codex-tui (#15218)
## Summary
- make app-server treat `clientInfo.name == "codex-tui"` as a legacy
compatibility case
- fall back to `DEFAULT_ORIGINATOR` instead of sending `codex-tui` as
the originator header
- add a TODO noting this is a temporary workaround that should be
removed later

## Testing
- Not run (not requested)
2026-03-20 10:51:21 -06:00
pakrym-oai
ba85a58039 Add remote env CI matrix and integration test (#14869)
`CODEX_TEST_REMOTE_ENV` will make `test_codex` start the executor
"remotely" (inside a docker container) turning any integration test into
remote test.
2026-03-20 08:02:50 -07:00
xl-openai
e5f4d1fef5 feat: prefer git for curated plugin sync (#15275)
start with git clone, fallback to http.
2026-03-20 00:06:24 -07:00
Michael Bolin
a224097924 merge commit for archive created by Sapling 2026-03-19 23:45:09 -07:00
Michael Bolin
65dfa94c29 core: add stdin-backed sandboxed fs writes 2026-03-19 23:44:57 -07:00
Michael Bolin
16588ffc6d core: route view_image through a sandbox-backed fs helper 2026-03-19 23:44:57 -07:00
Michael Bolin
29633f0578 core: add a sandbox-backed fs helper 2026-03-19 23:44:56 -07:00
Michael Bolin
f71639542e merge commit for archive created by Sapling 2026-03-19 23:38:47 -07:00
Michael Bolin
7aca0d8e9e core: route view_image through a sandbox-backed fs helper 2026-03-19 23:34:23 -07:00
Michael Bolin
20d1ddfecd merge commit for archive created by Sapling 2026-03-19 23:05:48 -07:00
Michael Bolin
7ed4bf734a core: add stdin-backed sandboxed fs writes 2026-03-19 23:05:25 -07:00
Michael Bolin
512f7ed02e core: route view_image through a sandbox-backed fs helper 2026-03-19 23:05:24 -07:00
Michael Bolin
b6af17385d core: add a sandbox-backed fs helper 2026-03-19 23:05:01 -07:00
Won Park
461ba012fc Feat/restore image generation history (#15223)
Restore image generation items in resumed thread history
2026-03-19 22:57:16 -07:00
Michael Bolin
dab86facb8 merge commit for archive created by Sapling 2026-03-19 22:57:00 -07:00
Michael Bolin
e800c8bafb core: add stdin-backed sandboxed fs writes 2026-03-19 22:56:50 -07:00
Michael Bolin
09fd6cd7c1 core: route view_image through a sandbox-backed fs helper 2026-03-19 22:56:50 -07:00
Michael Bolin
76ecd98408 core: add a sandbox-backed fs helper 2026-03-19 22:56:50 -07:00
Michael Bolin
bb43550a15 merge commit for archive created by Sapling 2026-03-19 22:50:00 -07:00
Michael Bolin
a50f24d6d1 core: add stdin-backed sandboxed fs writes 2026-03-19 22:49:49 -07:00
Michael Bolin
97c5db35cc core: route view_image through a sandbox-backed fs helper 2026-03-19 22:49:49 -07:00
Michael Bolin
4bf454e71b core: add a sandbox-backed fs helper 2026-03-19 22:49:48 -07:00
Charley Cunningham
b3a4da84da Add guardian follow-up reminder (#15262)
## Summary
- add a short guardian follow-up developer reminder before reused
reviews
- cache prior-review state on the guardian session instead of rescanning
full history on each request
- update guardian follow-up coverage and snapshot expectations

---------

Co-authored-by: Codex <noreply@openai.com>
2026-03-19 22:35:52 -07:00
Michael Bolin
d38301db08 merge commit for archive created by Sapling 2026-03-19 22:33:31 -07:00
Michael Bolin
9c3dd13d2b core: add stdin-backed sandboxed fs writes 2026-03-19 22:32:40 -07:00
Michael Bolin
c56d2f1f48 core: route view_image through a sandbox-backed fs helper 2026-03-19 22:32:40 -07:00
Michael Bolin
013b9a46f6 core: add a sandbox-backed fs helper 2026-03-19 22:32:40 -07:00
Michael Bolin
d662c2815c merge commit for archive created by Sapling 2026-03-19 22:12:34 -07:00
Michael Bolin
c3f1765779 core: add a sandbox-backed fs helper 2026-03-19 22:12:19 -07:00
xl-openai
b1570d6c23 feat: Add One-Time Startup Remote Plugin Sync (#15264)
For early users who have already enabled apps, we should enable plugins
as part of the initial setup.
2026-03-20 05:01:39 +00:00
Andrei Eternal
cc192763e1 Disable hooks on windows for now (#15252)
We'll verify a bit later that all of this works correctly and re-enable
2026-03-19 21:31:56 -07:00
canvrno-oai
f7201e5a9f Initial plugins TUI menu - list and read only. tui + tui_app_server (#15215)
### Preliminary /plugins TUI menu
- Adds a preliminary /plugins menu flow in both tui and tui_app_server.
- Fetches plugin list data asynchronously and shows loading/error/cached
states.
  - Limits this first pass to the curated ChatGPT marketplace.
  - Shows available plugins with installed/status metadata.
- Supports in-menu search over plugin display name, plugin id, plugin
name, and marketplace label.
- Opens a plugin detail view on selection, including summaries for
Skills, Apps, and MCP Servers, with back navigation.

### Testing
  - Launch codex-cli with plugins enabled (`--enable plugins`).
  - Run /plugins and verify:
      - loading state appears first
      - plugin list is shown
      - search filters results
- selecting a plugin opens detail view, with a list of
skills/connectors/MCP servers for the plugin
      - back action returns to the list.
- Verify disabled behavior by running /plugins without plugins enabled
(shows “Plugins are disabled” message).
- Launch with `--enable tui_app_server` (and plugins enabled) and repeat
the same /plugins flow; behavior should match.
2026-03-19 21:28:33 -07:00
Michael Bolin
f3acc02dfd merge commit for archive created by Sapling 2026-03-19 20:34:15 -07:00
Michael Bolin
6fc6a7889a core: add stdin-backed sandboxed fs writes 2026-03-19 20:33:44 -07:00
Michael Bolin
269fe16050 core: route view_image through a sandbox-backed fs helper 2026-03-19 20:33:44 -07:00
Michael Bolin
98ea221446 core: add a sandbox-backed fs helper 2026-03-19 20:33:44 -07:00
Michael Bolin
943f9eb766 merge commit for archive created by Sapling 2026-03-19 20:27:07 -07:00
Michael Bolin
8d99dc0404 core: add stdin-backed sandboxed fs writes 2026-03-19 20:26:58 -07:00
Michael Bolin
d63213b7d0 core: route view_image through a sandbox-backed fs helper 2026-03-19 20:23:55 -07:00
Michael Bolin
45b4632cad core: add a sandbox-backed fs helper 2026-03-19 20:23:18 -07:00
Michael Bolin
fa2a2f0be9 Use released DotSlash package for argument-comment lint (#15199)
## Why
The argument-comment lint now has a packaged DotSlash artifact from
[#15198](https://github.com/openai/codex/pull/15198), so the normal repo
lint path should use that released payload instead of rebuilding the
lint from source every time.

That keeps `just clippy` and CI aligned with the shipped artifact while
preserving a separate source-build path for people actively hacking on
the lint crate.

The current alpha package also exposed two integration wrinkles that the
repo-side prebuilt wrapper needs to smooth over:
- the bundled Dylint library filename includes the host triple, for
example `@nightly-2025-09-18-aarch64-apple-darwin`, and Dylint derives
`RUSTUP_TOOLCHAIN` from that filename
- on Windows, Dylint's driver path also expects `RUSTUP_HOME` to be
present in the environment

Without those adjustments, the prebuilt CI jobs fail during `cargo
metadata` or driver setup. This change makes the checked-in prebuilt
wrapper normalize the packaged library name to the plain
`nightly-2025-09-18` channel before invoking `cargo-dylint`, and it
teaches both the wrapper and the packaged runner source to infer
`RUSTUP_HOME` from `rustup show home` when the environment does not
already provide it.

After the prebuilt Windows lint job started running successfully, it
also surfaced a handful of existing anonymous literal callsites in
`windows-sandbox-rs`. This PR now annotates those callsites so the new
cross-platform lint job is green on the current tree.

## What Changed
- checked in the current
`tools/argument-comment-lint/argument-comment-lint` DotSlash manifest
- kept `tools/argument-comment-lint/run.sh` as the source-build wrapper
for lint development
- added `tools/argument-comment-lint/run-prebuilt-linter.sh` as the
normal enforcement path, using the checked-in DotSlash package and
bundled `cargo-dylint`
- updated `just clippy` and `just argument-comment-lint` to use the
prebuilt wrapper
- split `.github/workflows/rust-ci.yml` so source-package checks live in
a dedicated `argument_comment_lint_package` job, while the released lint
runs in an `argument_comment_lint_prebuilt` matrix on Linux, macOS, and
Windows
- kept the pinned `nightly-2025-09-18` toolchain install in the prebuilt
CI matrix, since the prebuilt package still relies on rustup-provided
toolchain components
- updated `tools/argument-comment-lint/run-prebuilt-linter.sh` to
normalize host-qualified nightly library filenames, keep the `rustup`
shim directory ahead of direct toolchain `cargo` binaries, and export
`RUSTUP_HOME` when needed for Windows Dylint driver setup
- updated `tools/argument-comment-lint/src/bin/argument-comment-lint.rs`
so future published DotSlash artifacts apply the same nightly-filename
normalization and `RUSTUP_HOME` inference internally
- fixed the remaining Windows lint violations in
`codex-rs/windows-sandbox-rs` by adding the required `/*param*/`
comments at the reported callsites
- documented the checked-in DotSlash file, wrapper split, archive
layout, nightly prerequisite, and Windows `RUSTUP_HOME` requirement in
`tools/argument-comment-lint/README.md`
2026-03-20 03:19:22 +00:00
Michael Bolin
c5c2209a76 merge commit for archive created by Sapling 2026-03-19 20:17:43 -07:00