Commit Graph

10943 Commits

Author SHA1 Message Date
Eddie Chen
12b0164a48 Classify tool analytics events by call origin (#45535)
## What changed

Add `tool_event_type` to tool analytics events, using exact call ID evidence to distinguish `model_tool_call` from `inner_tool_call`. Serialize `null` when evidence is missing or conflicting at emission time; later evidence does not revise emitted events.

Classify sampled code-mode `exec` and `wait` calls as model calls and dispatched child calls as inner calls, without inferring origin from cell associations or parent lineage.

## Testing

Add coverage for exact and ambiguous origin evidence and late sampling evidence. Extend serialization, code-mode, collaborator, and subagent tests to check the classification.

GitOrigin-RevId: a41085b4665b28b20026aa2bcb10ff7fa8af8778
2026-09-14 22:52:40 +00:00
viyatb-oai
99914f4950 Honor explicit Unix socket grants in the Linux managed sandbox (#45534)
## Why

Linux proxy-routed sandboxing denied standalone Unix sockets even when the effective network policy enabled `dangerously_allow_all_unix_sockets`.

## What changed

- Carry Unix socket permissions in `ManagedNetworkSandboxContext` and pass the prepared context through Linux sandbox launches with `--managed-network`.
- Allow `AF_UNIX` socket creation in proxy-routed mode when `dangerously_allow_all_unix_sockets` is enabled, while preserving network namespace isolation and restrictions on other socket families.
- Keep standalone Unix sockets denied by default and for path-only grants. Default missing fields in older serialized contexts to restrictive values.

## Testing

Add coverage for policy preparation and transport, legacy deserialization, and malformed policy rejection. Add a Linux integration test covering default denial, path-only denial, and explicit allow-all access, while checking that direct TCP access and `AF_NETLINK`/`AF_VSOCK` sockets remain blocked.

GitOrigin-RevId: 2695b945ad3e59fcb3faf7662d852a26650af16c
2026-09-14 22:40:20 +00:00
zm-oai
d39cfa8a2d Harden and share Windows sandbox identity helpers (#45533)
## What changed

- Share process package-family queries, token user SID extraction, and account-name lookup through `codex_windows_sandbox`, and use them in the provisioning service.
- Bound token query sizes and validate SID pointers, revisions, and lengths before copying SIDs into owned storage.
- Use a drop guard to balance firewall COM initialization, and track the package lifecycle directory guard separately so cleanup releases it while keeping ancestor and home handles pinned.

## Testing

Add tests that verify copied SIDs outlive their query buffers and reject truncated token data, malformed SIDs, and invalid SID pointers.

GitOrigin-RevId: 2b893e4524d3e00cb114df05215beef7b9eebbe9
2026-09-14 22:40:01 +00:00
acrognale-oai
a4354e2d27 Expose selected workspace routing in app-server account reads (#45529)
## What changed

- Add experimental `account/read.workspaceRouting` metadata containing the selected ChatGPT workspace ID, resolved HTTPS backend origin, and routing override (`us`, `us_cr`, or `NO_CONSTRAINT`).
- Discover and cache routing through `accounts/check` for saved logins, new logins, and workspace switches. Return `null` for signed-out accounts, API-only accounts, and saved credentials without a selected workspace.
- Validate discovered origins against required `chatgpt_base_url` origins. Return errors for failed or malformed discovery and retry on later reads.
- Wait for requirements and routing before publishing account updates, including to newly initialized connections. Clear routing on logout, discard stale discovery results, and guard queued notifications against account changes.

## Testing

Add unit and integration coverage for origin resolution and validation, discovery failures and retries, startup discovery, workspace switching, logout, configuration changes during discovery, and authentication changes while notifications wait for queue capacity.

GitOrigin-RevId: 2c5367bb01dd7543b08d374f44444323e40f1981
2026-09-14 22:31:32 +00:00
Charlie Marsh
b44af92ca0 Compress larger Windows release artifacts first (#45528)
Sort top-level artifact files by descending size before dispatching them to
`xargs -P2`, so both compression workers stay busy.

GitOrigin-RevId: a459af0a0c50ead1aaf2a7c19563d8100cd63f0e
2026-09-14 22:30:27 +00:00
Charlie Marsh
b0d95427c2 Stage Python runtime wheels directly from package directories (#45526)
## Why

The Windows release workflow builds an extra package archive only to extract it again when staging the Python runtime wheel. Reuse the package directory to avoid this round trip.

## What changed

- Allow `stage-runtime` to accept a Codex package directory as well as a `.tar.gz` archive, with the same package layout validation.
- Reject overlapping source and staging directories, symlinks, and non-regular directory entries before staging.
- Stage Windows runtime wheels from the existing package directory and retain the check that voice resources are absent.

## Testing

Add coverage for matching directory and archive output, including file permissions, source preservation, invalid layouts, non-regular entries, overlapping directories, and CLI handling of both source formats.

GitOrigin-RevId: bf6d1e05888367d482d8d51a4a8061f92a9cae8b
2026-09-14 22:16:27 +00:00
iceweasel-oai
60e35765c3 Enable MXC TTY launches and managed networking in the exec server (#45524)
## What changed

- Report `windows_mxc` from native MXC availability on Windows.
- Allow MXC TTY launches and managed networking, using dedicated proxy listeners without requiring a shared-ingress restricting SID.
- Reject MXC custom `argv0` and private-desktop launches, and continue failing closed when native MXC is unavailable.

## Testing

Extend the Windows remote sandbox process-write test to cover MXC with both pipes and ConPTY. Retain coverage for rejecting MXC requests when native support is unavailable.

GitOrigin-RevId: 80c5f319b9066d06b26f0a7eb7119a109e6ebef7
2026-09-14 21:45:09 +00:00
jif
e84a594636 Move Guardian reviewer startup into the pool (#45521)
## What changed

Replace `ReviewerSessionFactory` with a startup callback installed through
`ReviewerPool::new`. Review requests supply shared setup data and reuse context,
while the pool uses its callback to create both reusable and forked reviewers.

Update Guardian session setup, prewarming, and existing test fixtures to use the
new pool API.

GitOrigin-RevId: fa171503afcee8bdbdf6822573bea8ded50ce117
2026-09-14 21:34:33 +00:00
zm-oai
78dfc1349e Add dependencies to the Windows sandbox service (#45520)
Add `base64` and `serde_json` as workspace dependencies of
`codex-windows-sandbox-service` and update `Cargo.lock`. Temporarily exclude
both dependencies from `cargo-shear` checks until they are used.

GitOrigin-RevId: f77a0ba13cfa9ba2315dcf00a80163afff32d0b4
2026-09-14 21:34:09 +00:00
Eric Traut
91d54f1667 Restore collaboration mode when resuming threads (#45519)
## Why

Resuming a thread initialized its collaboration mode to Default, losing the saved Plan mode and its developer instructions. Reconnecting clients also lacked a server-reported mode to reconcile changes made by another client.

## What changed

- Restore the saved collaboration mode from the latest matching `ThreadSettingsApplied` event, falling back to the last legacy `TurnContext`. Apply the effective model and reasoning effort while retaining the saved mode and developer instructions.
- Include `collaborationMode` in `thread/resume` responses and update the generated schemas and bindings.
- Use the restored mode in the TUI, including the first prompt after resume. Prefer the server's mode when restoring disconnected input, while preserving the local selection for older servers that omit it.

## Testing

Add regression coverage for persisted and legacy collaboration modes, model and reasoning-effort overrides, the resumed Plan mode display and first prompt, and reconnect behavior with and without a server-reported mode.

GitOrigin-RevId: ed064516e7fae1c1668152ab448f510cbcacfe06
2026-09-14 21:33:45 +00:00
jif
7c73903be2 Route Guardian reviewers through ThreadManager for inline parents (#45518)
## Why

Inline delegates have no entry in the thread registry, so reviewer creation cannot depend on looking up the parent or waiting for its thread-ready notification.

## What changed

- Capture parent identity, authentication, shared agent control, originator, and inherited instructions in `StartThreadOptions` so `ThreadManager` can start a child without a registered parent.
- Route Guardian reviewer creation through this path, remove the standalone fallback and readiness gate, and require a Guardian extension host.
- Install explicit reviewer hosts in unit tests and the Guardian reviewer extension in the integration test harness, using `ExtensionRegistry::to_builder()` to preserve existing contributors.

## Testing

Extend the thread-manager regression test to remove the parent from the registry before starting a child, then verify inherited lineage, originator, session identity, and authentication, and exclusion from the public thread list.

GitOrigin-RevId: 468ded6fdce7520cb39d55c1a884dcfa5aaea2d9
2026-09-14 21:23:06 +00:00
zm-oai
280c7e1e56 Use a dedicated mock server in the provider enforcement test (#45517)
The provider requirement change test asserts that no traffic reaches the
replacement provider. Start a dedicated server with
`MockServer::builder().start()` and include unexpected request methods and
URL paths in assertion failures.

GitOrigin-RevId: 4020c43c0ec0472fe54d4003bff120349ddd5597
2026-09-14 21:21:21 +00:00
Won Park
520e13a4bc Allow configuring the Guardian prompt template (#45516)
## What changed

Add `auto_review.experimental_policy_template` to override the Guardian prompt template in `config.toml`. Trim the configured value and ignore it when empty. Prefer the override over the model catalog template, retaining the bundled template as the final fallback.

The template's `{{ tenant_policy_config }}` placeholder is replaced with the resolved Guardian policy.

## Testing

Extend tests to cover template deserialization, trimming, precedence over the catalog template, and rendered policy text in Guardian inference requests.

GitOrigin-RevId: 85b4a8fc193a42735354894203ccbd1f738a3b58
2026-09-14 21:06:36 +00:00
zm-oai
fd5bf3b059 Filter plugin-install test analytics by event type (#45515)
## Why

The analytics test helper returned the first analytics request, which could contain unrelated events. Plugin-install assertions need to select the expected event even when it arrives in a later request or shares a batch with other events.

## What changed

Update `wait_for_plugin_analytics_payload` to accept an event type, scan requests until matching events appear, and return the payload with only those events. Update callers to request `codex_plugin_installed` or `codex_plugin_install_failed` as appropriate.

## Testing

Add a regression test that sends an unrelated analytics request followed by a mixed batch and verifies that the helper returns only the expected plugin-install failure event.

GitOrigin-RevId: 41290c63ea1c2a3da1efa78b81222b8da76bcbff
2026-09-14 21:03:49 +00:00
faizan-oai
ef8b356c22 Allow setting daybreakEnabled when starting a thread (#45513)
## What changed

Add experimental `thread/start.daybreakEnabled` so clients can set the initial preference for persistent threads. Omitted or null values leave it unset; explicit values are rejected for ephemeral threads.

Return the choice in the start response, `thread/started`, and reads before persistence. Stage it with the initial thread metadata and save it when the thread is persisted. Later changes still use `thread/metadata/update`. The preference does not select `turn/start.cyberAccessProgram` or grant access.

## Testing

Add coverage for true, false, and unset values in responses, notifications, reads, and reads after persistence and restart, plus rejection for ephemeral threads. Update existing metadata and access-program tests to exercise threads with an initial preference.

GitOrigin-RevId: 3bff3dc55a18436067bc2a3f156f5abf52d7321b
2026-09-14 20:57:48 +00:00
Owen Lin
ea3c4848d8 Share MCP tool specs until search results are selected (#45509)
## Why

Building MCP search entries eagerly cloned tool specs and normalized schemas even for tools that were never selected.

## What changed

Store search specs in `Arc<ToolSpec>` and let MCP search entries share the handler's spec. Materialize and normalize loadable specs only for selected results, preserving existing result formatting and dynamic-tool cache equality behavior.

## Testing

Add coverage for function, freeform, and namespace specs that verifies shared specs produce equivalent results, retain the source while needed, and release it when the search entry is dropped.

GitOrigin-RevId: 4260f2e2527834d8a856b1528654c6951aab8a7d
2026-09-14 20:20:29 +00:00
Bryan Ashley
b9bfc0aff8 Allow background persistence for steered user input (#45506)
## Why

Persisting user input received during an active turn currently blocks the next model request. Stores that support background persistence can overlap this checkpoint with inference.

## What changed

- Add `PersistContext::SteeredUserInput` and `allows_background_persistence()` so stores may enqueue these checkpoints, with durability and error reporting enforced by later flush or shutdown operations.
- Use the new context for accepted steered user input and apply the same metadata handling as turn-start persistence.
- Keep tool outputs synchronous, including in mixed input batches, and allow stores to retain synchronous persistence for all contexts.

## Testing

Add gated-store integration tests covering background user-input persistence, synchronous stores, and synchronous tool-output checkpoints. Verify that the next request includes the steered input and waits for persistence when required.

GitOrigin-RevId: c60b7b6c9b483245fd3169306bcf0de248ccdf35
2026-09-14 19:39:31 +00:00
Adam Perry @ OpenAI
4d5d37c5f8 Add lifecycle tracing for unified exec (#45505)
## What changed

- Add spans for one-shot and resumable `exec_command`, `write_stdin`, session creation, and output collection, recording outcomes and output collection stop reasons.
- Correlate calls with conversations, turns, and processes; link stdin interactions to the original exec call and process start requests to executor process IDs. Omit empty turn and call IDs and those longer than 256 bytes.
- Propagate the current tracing span into the spawned one-shot execution task and distinguish timeouts, cancellations, and failures.

GitOrigin-RevId: 722728dc3f5b624e7a4da69fc867c3c672465af0
2026-09-14 19:39:08 +00:00
iceweasel-oai
6ce16aadce Allow ConPTY output to close after the last console client exits (#45504)
## Why

Retaining the pseudoconsole's creation pipe handles prevents output readers from seeing EOF while the session remains alive.

## What changed

Drop the creation handles after a successful process spawn and call `ReleasePseudoConsole` when available on Windows 11 24H2 or newer. This lets output close after the last attached client exits while preserving I/O for surviving console descendants. Older Windows versions retain the `ClosePseudoConsole` cleanup path on drop.

## Testing

Add Windows lifecycle tests for output closure after normal exit and termination while retaining the session, plus continued input and output for a surviving console child. These tests skip when `ReleasePseudoConsole` is unavailable.

GitOrigin-RevId: fb1094fb2a570e6fec0cc80d6356f5d7eb1edcbf
2026-09-14 19:38:45 +00:00
acrognale-oai
973ec2942c Add revocable network policy primitives to the HTTP client (#45503)
## What changed

- Add `NetworkPolicyController` and `NetworkPolicy` APIs for publishing destination policies, checking access, and observing policy changes. Restricted policies permit only `https` and `wss` URLs with exact allowed hosts.
- Add revocable `NetworkPermit` values with cancellation support. Reject stale policy publications, revoke permits when access is removed, and prevent account-bound policy handles from regaining access after invalidation.
- Provide a permit API for SDK transports without destination enforcement that denies access under restricted policies.
- Let `HttpClientFactory` carry a network policy, defaulting to unmanaged access, and include policy identity in factory equality.

## Testing

Add tests for secure host matching, invalidation, stale publication, recovery after policy load failure, account isolation, and SDK permit revocation. Make accepted sockets blocking in redirect test servers to handle macOS socket inheritance, and add a missing read timeout.

GitOrigin-RevId: c79231527bc5e6954cda6581c0b9f43c90335755
2026-09-14 19:30:37 +00:00
jif
08d3748cf0 Add managed thread lifetimes with cancellation-safe startup (#45502)
## Why

Callers need to tie isolated threads to an explicit lifetime and wait for cleanup even when startup is cancelled or its result is never received.

## What changed

- Add `ThreadManager::start_thread_until` to run an isolated thread until a caller-provided future completes or the thread exits, with a `TaskTracker` covering cleanup and deregistration.
- Retain persistence and session resources across interrupted startup so cleanup can release partially initialized resources or shut down a running session using normal history rules.
- Reject resumed history and startup without explicit session isolation.

## Testing

Add integration tests for cancellation during stalled required MCP initialization, dropping an unconsumed startup result, and owner cancellation that preserves history and parent usability. Also verify that failed duplicate startup leaves the existing thread's writer intact.

GitOrigin-RevId: 47251c1b0c43821ab8f950816c6d341d39cdc823
2026-09-14 19:30:11 +00:00
Eric Traut
ad8a5e3a1b Render inline TeX math as Unicode in the TUI (#45501)
## What changed

Convert supported expressions inside `$...$` and `\(...\)` to readable Unicode in regular and streaming Markdown. For example, `$\alpha^2 + \beta_{10}$` renders as `α² + β₁₀`. Support a bounded TeX subset including symbols, superscripts, subscripts, square roots, and parenthesized fractions, with verbatim fallback for unsupported expressions.

Exclude code, links, HTML, and display equations from conversion, and avoid interpreting common currency and shell syntax as math. Preserve file citation paths and keep streaming cache boundaries outside display equations.

## Testing

Add snapshots for inline rendering and narrow wrapping, plus regression tests for unsupported input, parser limits, Markdown contexts, file citations, and streaming display boundaries across chunks and widths.

GitOrigin-RevId: 828bf7b48345b05bc6c2fb5cb2798412c3b71dbe
2026-09-14 19:29:19 +00:00
Eric Traut
d38b5260a1 Send local TUI images as portable attachments to remote app servers (#45499)
## Why

Remote app servers cannot read image paths on the TUI host. Image attachments need to carry their contents when submitting to a remote workspace.

## What changed

- Prepare local images as data URLs off the event loop for new turns and steers, preserving source pixels for model-specific resizing and enforcing a 32 MiB image transport budget.
- Show preparation progress, preserve queued message order, and recover drafts on preparation failures, cancellation, disconnects, or thread switches. Ignore stale preparation completions.
- Avoid duplicate user messages from server receipts and duplicate image labels in history.

## Testing

Add regression tests for portable image contents, receipt deduplication, draft restoration, responsive input during preparation, and cancellation across thread and connection changes.

GitOrigin-RevId: 6404615eae0b06c141af96b4229501c61f7fcfee
2026-09-14 19:21:08 +00:00
vkg-oai
afaad7cdc0 Trace global user instruction loading (#45496)
## What changed

Add an `instructions.load` tracing span with `provider = "global"` around loading user instructions from the Codex home directory. Skip recording function arguments and add the `tracing` dependency to `codex-home`.

GitOrigin-RevId: 1b11e4b18f7a0dbee742a092aba580a184dc5fbf
2026-09-14 19:12:59 +00:00
acrognale-oai
a20092a7a2 Expose effective login methods in config requirements (#45495)
## Why

Configuration requirements did not report which login methods the running app server permits after applying managed policy, forced login settings, and workspace restrictions.

## What changed

- Add `allowedLoginMethods` to `configRequirements/read`, using the running authentication manager's effective policy rather than newly read authentication settings.
- Return requirements when login methods are restricted even without managed requirements, while preserving `requirements: null` for the unrestricted default.
- Update protocol schemas and generated TypeScript and Python types. An empty list permits no login method; older servers may omit the field.

## Testing

Add coverage for managed and forced login restrictions, workspace intersections, policy reporting after requirements files change, invalid login methods, and API-only Amazon Bedrock without ChatGPT requests. Extend tests for conflicting authentication requirements and cloud policy precedence.

GitOrigin-RevId: 56c0767a74143e793aac2ac165d0cbe98a09469b
2026-09-14 19:11:29 +00:00
felixxia-oai
d3812ddbb3 Make the Guardian deadline cancellation helper crate-private (#45493)
## What changed

Restrict `run_before_review_deadline_with_cancel` and its re-export to `codex-guardian-reviewer`. Move its timeout, abort, and successful-completion tests from core into the reviewer's deadline module, and remove the standalone `run_before_review_deadline` tests from core.

GitOrigin-RevId: dd9f1ed571a40a4bd66b08c88f3ee2be071f4870
2026-09-14 18:57:52 +00:00
felixxia-oai
43da136850 Split Guardian V2 async scoring into focused modules (#45492)
## What changed

Extract tool observation and evidence capture into `observation.rs`, background classification into `classification.rs`, and score tracking and failure handling into `score.rs`. Keep lifecycle hooks in `extension.rs` and pass captured evidence through a `Classification` struct, preserving the existing snapshot and background task boundaries.

## Testing

Move the fail-closed score-ordering test into `score_tests.rs` and extend it to verify that a failed sample replaces an equally dated score while preserving newer scores.

GitOrigin-RevId: b25b9e828cce78fb2be522d7209346b63403d824
2026-09-14 18:57:06 +00:00
felixxia-oai
f2d9bccbde Remove Guardian subagent-spawner plumbing (#45491)
## What changed

- Remove `AgentSpawner` and `AgentSpawnFuture` from the extension API, along with the Guardian wrapper, thread lifecycle context, and app-server injection plumbing.
- Define `InternalSessionSpawnFuture` directly as a boxed future instead of aliasing `AgentSpawnFuture`.
- Raise the workspace `rustls` minimum version to `0.23.45`.

GitOrigin-RevId: b7319dee41bfb869479afeb7555a6f050c4d00a5
2026-09-14 18:56:43 +00:00
zm-oai
e5a2094817 Update rustls and AWS-LC dependencies in Cargo and Bazel lockfiles (#45489)
## What changed

- Update `rustls` from 0.23.36 to 0.23.45 and `rustls-webpki` from 0.103.13 to 0.103.15.
- Update `aws-lc-rs` from 1.16.2 to 1.18.1 and `aws-lc-sys` from 0.39.0 to 0.45.0, including its new `pkg-config` dependency.
- Refresh the corresponding dependency metadata in `MODULE.bazel.lock`.

GitOrigin-RevId: 7b37b3cea5485c0b5bd11d229b2949aec399afd9
2026-09-14 18:47:17 +00:00
jif
21b1ef18c6 Retain thread persistence acquisition through session cancellation (#45487)
## Why

Session initialization can be cancelled after a persistence writer is installed but before acquisition returns. Cleanup must wait for acquisition to finish so it can discard the writer.

## What changed

Extend `LiveThreadInitGuard` to own in-flight acquisition and finish it before discarding persistence, including when the guard is dropped. Use the guard for thread creation, resume, and inherited model context initialization.

## Testing

Add a regression test that cancels acquisition after writer installation, verifies cleanup waits for handoff, and confirms the writer is removed afterward.

GitOrigin-RevId: 09041fa5cd675d082a86a4cc8a719c572afe11a8
2026-09-14 18:40:02 +00:00
Eric Traut
5fb3b7e401 Fix fuzzy match scoring within Unicode lowercase expansions (#45475)
## Why

Matches starting inside a lowercase expansion such as `İ` → `i̇` could receive an incorrect prefix bonus or gap penalty, causing strings that lowercase identically to rank differently.

## What changed

Track the first matched position in the lowercased text directly when calculating scores. Preserve original character indices for highlighting.

## Testing

Add a skill popup regression test and snapshot covering ranking and highlighting for matches beginning at the combining dot in expanded and already-lowercase names.

GitOrigin-RevId: 78a8b79f1defca9f76fde5df945b0b1ff4af25da
2026-09-14 17:36:11 +00:00
iceweasel-oai
99b3ab2131 Allow dedicated listeners for managed network proxies (#45463)
## Why

Sandboxes that enforce endpoint access directly need dedicated loopback proxy ports instead of shared SID-attributed ingress.

## What changed

Expose `ManagedProxyRouting` through `NetworkProxyBuilder::managed_proxy_routing`. Selecting `DedicatedListeners` reserves per-proxy loopback listeners on Windows as well as other platforms. Keep `SharedIngress` as the default and include the routing mode in proxy equality.

## Testing

Add regression coverage for distinct loopback endpoints, sandbox port metadata, and HTTP and SOCKS allow/deny policy enforcement. On Windows, verify that dedicated routing requires no restricting SID and omits the shared-ingress proxy-port environment variable.

GitOrigin-RevId: e198891bef1d089f9492d2982505a2d6bb002a74
2026-09-14 16:51:56 +00:00
jif
3fa9039bd7 Label rollout compression failures by stage and I/O error kind (#45461)
## Why

Rollout compression failure counters report only that an operation failed,
without identifying the failing stage or I/O error kind.

## What changed

- Add `stage` and `error_kind` labels to failure counters for compression runs,
  individual files, materialization for append, and stale temporary file cleanup.
- Record failures at their source, including lock acquisition and task joins,
  and avoid counting file compression failures twice.
- Use static stage labels and a fixed set of error categories, keeping error
  messages, paths, and rollout contents out of metric tags.

GitOrigin-RevId: ac2bfc7ae4cec4e9f60de9557b03345a3986aa53
2026-09-14 16:37:47 +00:00
Nick Steele
374c4b2d82 Resolve enterprise-managed MCP registrations in the catalog (#45459)
## What changed

- Retain the trusted enterprise identity provider in runtime configuration and bind winning MCP registrations during catalog finalization. Require `features.use_xaa` and a configured identity provider for activation, while preserving existing server restrictions.
- Apply plugin `ema_auth` client, issuer, resource, and scope settings to installed and selected plugins. Disable registrations with mismatched endpoints or empty resources without rewriting plugin endpoints.
- Preserve enterprise auth policy across catalog rebuilds and rebind registrations when materialized server settings change. Keep registration rejection separate from persistent server-name vetoes so it does not disable replacement hosted apps.

## Testing

Add coverage for activation gates, configuration ownership, plugin endpoint validation, catalog rebuilds, and skipping interactive OAuth during installation of enterprise-managed plugins. Stabilize the sandbox network proxy test by reading request headers before closing the loopback connection.

GitOrigin-RevId: 3374f507d120835b285767cedbbb511fc7b0fba2
2026-09-14 16:30:00 +00:00
Felipe Coury
b876f88981 Fix clipboard routing for tmux and SSH sessions (#45457)
## Why

A persistent tmux session can gain remote clients after Codex starts, so successful native copying must not skip terminal forwarding. Terminal sends also lack delivery acknowledgement and cannot replace native copying reliably.

## What changed

- Attempt native copying first, then independently forward through tmux or OSC 52 in tmux and SSH sessions. Preserve existing native clipboard leases when a later copy returns no new lease.
- Target the most recently active client in the current pane's tmux session, checking that client's clipboard capability before sending. Retain OSC 52 fallback when tmux forwarding fails.
- Reject empty selections without touching clipboards and apply the 100,000-byte terminal payload limit to tmux copies.
- Resolve tmux and PowerShell through trusted system locations, adding Nix system profiles and the WSL PowerShell directory to helper discovery.

## Testing

Add regression coverage for native-before-terminal ordering, fallback routing, clipboard lease retention, empty and oversized payloads, tmux client selection, capability checks, and combined backend errors.

GitOrigin-RevId: df4b66fa4368a3cf19b4d07fde6c76ea96a8fef5
2026-09-14 16:15:34 +00:00
zm-oai
1a02867bd1 Refactor Windows sandbox setup and service helpers (#45455)
## What changed

- Extract helper copying, token-user SID queries, provisioning pipe ownership, and service runtime lifecycle into dedicated modules.
- Simplify command-runner resolution and extract setup configuration loading, payload execution, provisioning request exchange, and response handling into helpers.
- Parameterize installation-record registry access and return the saved installation record from authenticated user registration.

## Testing

Add tests for explicit setup `cwd` selection and effective workspace roots, plus valid and invalid token-user SID queries. Move existing helper-copy and freshness tests alongside the extracted copy implementation.

GitOrigin-RevId: ffb39adae7611baa95e85c89f9a31ef7a779e217
2026-09-14 16:05:40 +00:00
Eric Traut
7a48b95c6c Preserve tabs in non-bracketed paste bursts (#45454)
## Why

When terminals deliver pasted text as individual key events, tabs can trigger completion, submission, or queuing instead of preserving indentation in the draft.

## What changed

Capture unmodified `Tab` events during paste bursts before shortcut dispatch, including after short Unicode prefixes. Refresh the burst idle timeout when appending tabs or newlines, and flush expired bursts before handling manual `Tab` shortcuts.

## Testing

Add regression tests for multiline tab preservation, ASCII and Unicode prefixes, idle timeout refresh, completion suppression, and normal submission and queue shortcuts. Add a snapshot for pasted indentation.

GitOrigin-RevId: ba404cfe66c23f37da5a0db7cccfdd3d4c4af331
2026-09-14 16:05:17 +00:00
jwang-openai
4d8eca1ff3 Attribute command and plugin analytics to the invoking model (#45445)
## Why

Command execution and plugin measurement events lack model and reasoning-effort labels. Attribution needs to reflect the step that invoked the command, even when model settings change before a background process finishes.

## What changed

- Add `model_slug` and `reasoning_effort` to command execution and plugin measurement analytics.
- Capture model context from resolved step settings and carry it through execution, approval, Guardian review, and plugin metrics collection.
- Preserve the first command-start model context when subsequent start notifications arrive.
- Keep the carried context out of serialized protocol items and generated schemas.

## Testing

Extend analytics tests to cover model switches before invocation and during background execution, default reasoning effort, Guardian-denied commands, and repeated start notifications retaining the original model context.

GitOrigin-RevId: af90e1c0d39bab625f2e89786085b61a9b96c0ce
2026-09-14 15:30:22 +00:00
jif
b6a5d5bb14 Preserve Guardian parent response IDs across sampling requests (#45441)
## Why

Running code-mode cells can request Guardian review while the next response is in flight. Clearing the response ID before that response emits `response.created` leaves those reviews without a `parent_response_id`.

## What changed

Keep the latest response ID received in the turn until a later `response.created` replaces it, including across sampling retries.

## Testing

Add regression coverage for reviews before and after a response handoff and for a fresh turn that must not inherit the previous turn's ID. Update retry coverage to expect the last known parent when the retry supplies no response ID.

GitOrigin-RevId: af0a08de09edad59e1a7ade7904a42d616b05679
2026-09-14 15:13:13 +00:00
Charlie Marsh
f8bed26f7b Share Apps tool catalogs without retaining unused snapshots (#45440)
## Why

Idle Apps clients and cached MCP bindings can retain replaced tool definitions. Shared catalog updates can also invalidate prepared calls even when the current definitions match the captured catalog, including after tools are restored while a call awaits approval.

## What changed

- Share immutable tool arrays across equivalent live discovery contexts and reuse storage for equal results. Let unused providers and cached bindings expire.
- Include requested capabilities and initialization results in the sharing scope, and detach servers that disable catalog caching from live sharing.
- Capture catalog snapshots for prepared calls. Accept equivalent shared catalogs regardless of tool-list order, while rejecting changed definitions and calls captured before an explicit refresh on that client.

## Testing

Add regression coverage for shared storage and scope isolation, release of replaced tools and unused bindings, equivalent catalog restoration, explicit refresh invalidation, and an Apps call completing after catalog restoration while awaiting approval.

GitOrigin-RevId: a0516186e4286d0ff13405fafbab6fcf3f1f3773
2026-09-14 15:06:28 +00:00
Charlie Marsh
f3803587c9 Share tool output schemas and defer MCP envelope construction (#45439)
## Why

MCP tool parsing eagerly cloned structured output schemas and built full call-result envelopes. Cloning tool definitions also copied their output-schema JSON, even before a consumer needed it.

## What changed

- Introduce `ToolOutputSchema` with immutable `Arc` storage so tool definitions share output schemas when cloned.
- Retain MCP structured output schemas and materialize the call-result envelope only when JSON is requested.
- Update code-mode consumers and schema mutation sites to materialize JSON explicitly, reusing uniquely owned storage when possible.
- Move structured content into the MCP envelope without an extra clone, preserving property order.

## Testing

Add tests for JSON preservation, mutation isolation, equality between lazy and materialized schemas, reuse of uniquely owned storage, and equivalent code-mode definitions.

GitOrigin-RevId: e98ba4c2f0efedc99f7cbc7bba206cc63a3bd8f4
2026-09-14 15:05:16 +00:00
Charlie Marsh
e9633d7a02 Avoid cloning MCP server status snapshot data (#45428)
Remove entries from the owned snapshot maps when building MCP server status
responses, moving server metadata, tools, resources, and auth statuses into
the response instead of cloning them. Preserve pagination and missing-entry
defaults.

GitOrigin-RevId: 012301f55ddb9c52c7934a638bdd0310f11077fa
2026-09-14 13:56:18 +00:00
felixxia-oai
2f8603f075 Extract Guardian sampler execution into a dedicated module (#45420)
## What changed

Move request execution from `LunaSampler` into `SamplingExecution` in
`sampler/execution.rs`, keeping request preparation and active-request tracking
in the sampler. Preserve the existing retry, authentication recovery,
cancellation, streaming, connection reuse, and token accounting behavior.

GitOrigin-RevId: 5e50116459fe9cc196c30c58e42773fc32be3d02
2026-09-14 12:55:41 +00:00
felixxia-oai
9d036249da Extract Guardian conversation bookkeeping into the reviewer crate (#45418)
## What changed

Add `ConversationState` and `ConversationCheckpoint` to `codex-guardian-reviewer` and use them in core review sessions to track transcript cursors, completed review counts, and committed snapshots. Keep history and admitted evidence host-owned.

Preserve the separation between live review progress and committed checkpoints so forks inherit the history, cursor, and review count from the last committed snapshot.

## Testing

Add a unit test verifying that forks retain committed history and progress after an uncommitted review, then advance when the next snapshot is committed.

GitOrigin-RevId: 9f92410b11beec6b8f413c4c922fabba65852399
2026-09-14 12:52:37 +00:00
felixxia-oai
b3e0c49dfb Extract guardian transcript selection into guardian-context (#45417)
## What changed

Move full/delta transcript selection into the shared `TranscriptMode::select` API and use it when building guardian prompts. Export `TranscriptCursor`, `TranscriptMode`, and `TranscriptSelection` from `codex-guardian-context`.

Preserve full-transcript fallback when the history version changes or the saved cursor exceeds the collected entry count. Select entries before profile retention, preserving their numbering and returning a proposed cursor that counts all collected entries. Hosts remain responsible for committing and invalidating cursors.

## Testing

Add a regression test verifying that sliding-window retention preserves the collected-entry cursor and that an appended entry is selected and numbered correctly in the next delta.

GitOrigin-RevId: a2192c08e23c18302b0105ba47aeb2780eb4a015
2026-09-14 12:52:16 +00:00
jif
99cda7a9a5 Invalidate Guardian review sessions after parent history resets (#45413)
## Why

A summary-free parent context reset could reuse a Guardian review session and carry forward rationale from before the reset.

## What changed

Track destructive history replacements with `reset_version` and include it in the Guardian session reuse key. Ordinary input and compaction preserve this version.

## Testing

Update the review-session reuse test to require a new Guardian thread after a summary-free reset, with no prior review context or previous rationale.

GitOrigin-RevId: bd05c149774839f68b75294751f7619ba7ce0bfe
2026-09-14 12:11:26 +00:00
jif
d761097734 Add session and originating window IDs to MCP request metadata (#45409)
## What changed

Include `sessionId` and the originating `windowId` alongside `threadId` and optional `itemId` in MCP request metadata. Retain the originating item and window for code-mode cells across waits and compaction, including the window when no matching history item is found.

## Testing

Extend metadata assertions for direct and nested MCP calls. Add a regression test verifying that a code-mode cell retains its original item and window IDs when it resumes after compaction.

GitOrigin-RevId: 5e3cf761f2bed4c16565334c94654496367325fd
2026-09-14 11:03:22 +00:00
jif
d77ebc7223 Cancel code mode timer tasks when cleared or the cell finishes (#45399)
## Why

Each `setTimeout` spawned a sleeping thread that remained alive until its delay elapsed, even after `clearTimeout` or cell completion.

## What changed

Replace per-timer threads with Tokio sleep tasks held by `AbortOnDropHandle`, so removing a timeout or dropping the isolate cancels its task. Enter the caller's Tokio runtime on the code mode runtime thread to support scheduling these timers.

## Testing

Add a regression test using virtual time to verify that cleared timers release their tasks, an awaited timer completes, and cell completion cancels remaining timers without emitting their output.

GitOrigin-RevId: 59c7e57ed226cb32633e2d4c25b778cfab2af423
2026-09-14 09:29:51 +00:00
riley-oai
5b1d656018 Publish opt-in provisioned macOS packages with Rust releases (#45345)
## What changed

- When `CODEX_PROVISIONED_MACOS_CANDIDATE` is `true`, require the provisioned macOS job to succeed and upload its verified packages as release assets. Allow releases to proceed when the job is disabled and skipped.
- Include provisioned archives in `codex-package_SHA256SUMS` and remove per-architecture `SHA256SUMS` files before upload.
- Publish a `codex-provisioned` DotSlash manifest for macOS ARM64 and x86_64 packages, pointing to `bin/codex`.

GitOrigin-RevId: 7e36df484a3b7da6b66180fa31418a6958d1fe77
2026-09-14 04:37:04 +00:00
Sean Huang
3abbf9fe2c Extract Windows sandbox configuration preparation into a helper (#45312)
## What changed

Expose `prepare_windows_sandbox_config` and `PreparedWindowsSandboxConfig`
and use them during config loading. Preserve requirement enforcement and the
separation between the configured mode and the effective sandbox level.

## Testing

Add a unit test covering explicit mode precedence over feature fallback and
ensuring a feature-only fallback leaves the configured mode unset.

GitOrigin-RevId: 98e7f9fbc473b6a841257eca80d9a51950986055
2026-09-14 00:39:43 +00:00