mirror of
https://github.com/openai/codex.git
synced 2026-09-05 15:18:41 +00:00
## Why
Multi-agent v2 currently routes agent instructions through normal tool
arguments and inter-agent context. That means the parent model can emit
plaintext task text, Codex can persist it in history/rollouts, and the
recipient can receive it as ordinary assistant-message JSON.
This changes the v2 path so agent instructions stay encrypted between
model calls: Responses encrypts the `message` argument returned by the
model, Codex forwards only that ciphertext, and Responses decrypts it
internally for the recipient model.
## What changed
- Mark the v2 `message` parameter as encrypted for `spawn_agent`,
`send_message`, and `followup_task`.
- Treat multi-agent v2 tool `message` values as ciphertext
unconditionally.
- Store v2 inter-agent task text in
`InterAgentCommunication.encrypted_content` with empty plaintext
`content`.
- Convert encrypted inter-agent communications into the Responses
`agent_message` input item before sending the child request.
- Preserve `agent_message` items across history, rollout, compaction,
telemetry, and app-server schema paths.
- Leave multi-agent v1 unchanged.
## Message shape
The model still calls the v2 tools with a `message` argument, but that
value is now ciphertext:
```json
{
"name": "spawn_agent",
"arguments": {
"task_name": "worker",
"message": "<ciphertext>"
}
}
```
Codex stores the task as encrypted inter-agent communication:
```json
{
"author": "/root",
"recipient": "/root/worker",
"content": "",
"encrypted_content": "<ciphertext>",
"trigger_turn": true
}
```
When Codex builds the recipient request, it forwards the ciphertext
using the new Responses input item:
```json
{
"type": "agent_message",
"author": "/root",
"recipient": "/root/worker",
"content": [
{
"type": "encrypted_content",
"encrypted_content": "<ciphertext>"
}
]
}
```
Responses decrypts that item internally for the recipient model.
## Context impact
- Parent context no longer carries plaintext v2 agent task instructions
from these tool arguments.
- Codex rollout/history stores ciphertext for v2 agent instructions.
- Recipient requests receive an `agent_message` item instead of
assistant commentary JSON for encrypted task delivery.
- Plaintext completion/status notifications are still plaintext because
they are Codex-generated status messages, not encrypted model tool
arguments.
## Validation
- `just test -p codex-tools`
- `just test -p codex-protocol`
- `just test -p codex-rollout`
- `just test -p codex-rollout-trace`
- `just test -p codex-otel`
- `just write-app-server-schema`
100 lines
2.9 KiB
Rust
100 lines
2.9 KiB
Rust
pub use codex_api::ResponseEvent;
|
|
use codex_config::types::Personality;
|
|
use codex_protocol::error::Result;
|
|
use codex_protocol::models::BaseInstructions;
|
|
use codex_protocol::models::ResponseItem;
|
|
use codex_protocol::protocol::InterAgentCommunication;
|
|
use codex_tools::ToolSpec;
|
|
use futures::Stream;
|
|
use serde_json::Value;
|
|
use std::pin::Pin;
|
|
use std::task::Context;
|
|
use std::task::Poll;
|
|
use tokio::sync::mpsc;
|
|
use tokio_util::sync::CancellationToken;
|
|
|
|
/// API request payload for a single model turn
|
|
#[derive(Debug, Clone)]
|
|
pub struct Prompt {
|
|
/// Conversation context input items.
|
|
pub input: Vec<ResponseItem>,
|
|
|
|
/// Tools available to the model, including additional tools sourced from
|
|
/// external MCP servers.
|
|
pub(crate) tools: Vec<ToolSpec>,
|
|
|
|
/// Whether parallel tool calls are permitted for this prompt.
|
|
pub(crate) parallel_tool_calls: bool,
|
|
|
|
pub base_instructions: BaseInstructions,
|
|
|
|
/// Optionally specify the personality of the model.
|
|
pub personality: Option<Personality>,
|
|
|
|
/// Optional the output schema for the model's response.
|
|
pub output_schema: Option<Value>,
|
|
|
|
/// Whether the Responses API should strictly validate `output_schema`.
|
|
pub output_schema_strict: bool,
|
|
}
|
|
|
|
impl Default for Prompt {
|
|
fn default() -> Self {
|
|
Self {
|
|
input: Vec::new(),
|
|
tools: Vec::new(),
|
|
parallel_tool_calls: false,
|
|
base_instructions: BaseInstructions::default(),
|
|
personality: None,
|
|
output_schema: None,
|
|
output_schema_strict: true,
|
|
}
|
|
}
|
|
}
|
|
|
|
impl Prompt {
|
|
pub(crate) fn get_formatted_input(&self) -> Vec<ResponseItem> {
|
|
self.input
|
|
.iter()
|
|
.cloned()
|
|
.map(|item| {
|
|
let ResponseItem::Message { role, content, .. } = &item else {
|
|
return item;
|
|
};
|
|
if role != "assistant" {
|
|
return item;
|
|
}
|
|
InterAgentCommunication::from_message_content(content)
|
|
.filter(|communication| communication.encrypted_content.is_some())
|
|
.map(|communication| communication.to_model_input_item())
|
|
.unwrap_or(item)
|
|
})
|
|
.collect()
|
|
}
|
|
}
|
|
|
|
pub struct ResponseStream {
|
|
pub(crate) rx_event: mpsc::Receiver<Result<ResponseEvent>>,
|
|
/// Signals the mapper task that the consumer stopped polling before the
|
|
/// provider stream reached its own terminal event.
|
|
pub(crate) consumer_dropped: CancellationToken,
|
|
}
|
|
|
|
impl Stream for ResponseStream {
|
|
type Item = Result<ResponseEvent>;
|
|
|
|
fn poll_next(mut self: Pin<&mut Self>, cx: &mut Context<'_>) -> Poll<Option<Self::Item>> {
|
|
self.rx_event.poll_recv(cx)
|
|
}
|
|
}
|
|
|
|
impl Drop for ResponseStream {
|
|
fn drop(&mut self) {
|
|
self.consumer_dropped.cancel();
|
|
}
|
|
}
|
|
|
|
#[cfg(test)]
|
|
#[path = "client_common_tests.rs"]
|
|
mod tests;
|