mirror of
https://github.com/openai/codex.git
synced 2026-09-20 12:47:38 +00:00
## Why MCP elicitation reviewers are reused across runtime refreshes, while an active turn can retain the approval settings it started with. Reviewing against that turn could therefore apply stale authority after session settings changed. ## What changed - Read the latest published MCP runtime configuration when reviewing an elicitation, including the approval policy, permission profile, configuration layers, and reviewer selection. - Apply `never` and granular MCP-elicitation policy decisions before routing an eligible request to Guardian. - Keep MCP runtime startup registered for refresh invalidation through session creation. ## Testing Added coverage that refreshes a running session and verifies the same reviewer uses the latest authority for Guardian routing, denial, and empty-form auto-approval. GitOrigin-RevId: 826a157aa70fc8e3a9e3a14ecb0261bf7b63f63a