Commit Graph
11511 Commits
Author SHA1 Message Date
Ian MacLeod 55a7c57075 Release 0.159.0-alpha.12 rust-v0.159.0-alpha.12 2026-09-27 19:09:46 -07:00
Felipe Coury 1cc7e23612 Show a short, neutral TUI interruption notice (#48830)
## What changed

Render interrupted turns with secondary text styling and shorter wording,
removing the suggestion to tell the model what to do differently.

## Testing

Update interruption snapshots and assert that the notice uses secondary text
styling.

GitOrigin-RevId: 7cb042ed9e6781d107a93d5677fa193f082c764d
2026-09-28 01:10:27 +00:00
zm-oai e6f4af1d92 Wait briefly for the Windows sandbox provisioning service to start (#48829)
## Why

Allow the provisioning service time to start without holding up desktop readiness checks for the full provisioning timeout.

## What changed

- Poll service status while startup is pending, waiting up to five seconds within the caller's deadline. Treat absent, deletion-pending, or other non-running service states as unavailable.
- Preserve the original provisioning deadline for pipe availability and request processing, and reject requests whose deadline expires during server authentication.
- Recheck service status when the pipe disappears while waiting for an available instance.

GitOrigin-RevId: ea89175cb41749b9768ac5915083bbfd8ad32713
2026-09-28 00:59:19 +00:00
Benjamin Carlsson 81d5405882 Allow archiving threads before their first turn (#48828)
## Why

Fresh threads have no rollout until their first turn, so archiving them previously failed with a missing-rollout error.

## What changed

Persist loaded, non-ephemeral threads before looking them up for archival. This lets a newly started thread be archived without creating a user turn.

## Testing

Update the archive regression test to cover threads with no turns in both legacy and paginated history modes. Verify the archive notification, empty turn history, `NotLoaded` status, and archived rollout path.

GitOrigin-RevId: 507351c6238ad96f5e3ffbd2ed7f432058e3d52c
2026-09-28 00:58:56 +00:00
Benjamin Carlsson 6af89155d0 Show a hand pointer over transcript links in Ghostty and Kitty (#48827)
## What changed

- Show a hand pointer over actionable transcript links while Codex captures mouse input in Ghostty and Kitty, excluding sessions inside terminal multiplexers.
- Share link hit testing between hover and click activation, and refresh hover after rendering so scrolling and live output cannot leave a stale hand pointer.
- Suppress link hover during mouse presses and drags, overlays, and popups, and clear remembered mouse coordinates on focus loss, resize, and resume.
- Restore the terminal's pointer policy when releasing mouse capture, releasing Kitty's override and using a text pointer in Ghostty. Deduplicate pointer updates and preserve cleanup after write failures.

## Testing

Add tests for wrapped links containing wide characters, hover/click target agreement, scrolling, pointer transitions and restoration, write-failure retries, and hover invalidation.

GitOrigin-RevId: 1cf52e039a229e12260fa334879784c9bc1c8c87
2026-09-28 00:53:05 +00:00
Benjamin Carlsson 84cc4b3fb5 Keep voice RTP timestamps aligned to 20 ms packets (#48824)
## Why

Capture jitter and mute transitions can shift RTP timestamps off the 20 ms source grid, causing receivers that assemble fixed-duration frames to reject subsequent audio.

## What changed

Advance elapsed gaps in whole 20 ms packets and keep the track clock on that grid. Bias empty gap durations by 1 ns to avoid losing an RTP tick to floating-point truncation.

## Testing

Update jitter and mute tests to assert exact clock advancement, including a 580 ms gap, and verify that resumed RTP timestamps stay aligned to 960-sample packets.

GitOrigin-RevId: 1511c739b77ee5871f72723fd34cb67aa9a48c95
2026-09-28 00:43:04 +00:00
Matthew Zeng 456212ca21 Use explicit histogram buckets for tool and skill context metrics (#48819)
## What changed

- Give tool fragment sizes and namespace counts logarithmic boundaries through 32,768.
- Give enabled and kept skill counts integer boundaries from 0 through 512, removed description characters logarithmic boundaries through 131,072, and skill truncation flags boundaries at 0 and 1.
- Record these metrics with explicit boundaries, separating zero values and retaining overflow buckets above each range.

## Testing

Extend tool and skill metric tests to assert explicit boundaries. Add an export test covering zero, one, the upper boundary, and overflow, including bucket counts, ordering, and sample totals.

GitOrigin-RevId: 9fbf3acbe352d7c74f3ad11f0b690148c083a6ef
2026-09-28 00:05:54 +00:00
Eric Traut 659b35f131 Preserve punctuation and semicolons in Mermaid labels (#48814)
## Why

Splitting every statement at semicolons and rejecting label punctuation prevents rendering labels such as `A["Go []; &"]`, sequence messages containing `data[0] = {x: 1}`, and class members containing semicolons.

## What changed

- Split statements using diagram-specific rules, preserving semicolons inside flowchart labels, quoted tokens, and class member lines. Sequence quotes remain literal text.
- Respect quoted flowchart label delimiters and allow printable label punctuation, including literal ampersands and comparison operators.
- Reject unsupported entity escapes before statement splitting can truncate them, while retaining rejection of HTML markup and malformed labels.
- Document the supported syntax and require newlines between class members.

## Testing

Add parser assertions and update rendering snapshots for punctuation, quoted delimiters, and semicolons. Extend rejection coverage for entity escapes across diagram families, malformed quotes, and invalid class bodies.

GitOrigin-RevId: da94007a66c7c58444e6f0d6a1b409c8c7251941
2026-09-27 23:41:04 +00:00
vkg-oai 3f4668da20 Add history-aware prewarming for idle threads (#48812)
## What changed

- Add `CodexThread::prewarm_with_history()` to prepare a WebSocket response with existing conversation history and executed-tool metadata using `generate: false`. The next turn can reuse the prepared response when its prompt extends that history and request settings match.
- Keep startup prewarming and `prewarm()` on the existing empty-input path, and skip preparation when the cached WebSocket is ready.
- Label prewarm telemetry by input mode and WebSocket continuation metrics with `after_prewarm`.
- Rename `persistent_mode_enabled` to `persistent_execution_enabled` without changing its behavior.

## Testing

Extend WebSocket coverage to check history preservation during reconnect prewarming, reuse of the prepared response on the next turn, and omission of `previous_response_id` for a non-prefix prompt.

GitOrigin-RevId: c7731541b11b2e6668027a47f37f696213268c66
2026-09-27 23:21:25 +00:00
Felipe Coury 99f7758a57 Show short turn durations in TUI completion footers (#48807)
## Why

Completion footers hid known durations unless they exceeded 60 seconds, leaving short turns without elapsed-time information.

## What changed

Show all known durations for live and restored turns, rendering sub-second durations as `Worked for <1s`. Separate completion metadata with `•` instead of `·`.

## Testing

Update live completion, history replay, and separator tests to cover short durations, missing timestamps, and the revised footer format. Refresh affected TUI snapshots.

GitOrigin-RevId: 666e765db5426c5f9cc00d73f71cab649ad34947
2026-09-27 23:02:36 +00:00
Felipe Coury d9487a2930 Allow transcript wheel scrolling while a modal is open (#48805)
## Why

The “Implement this plan?” prompt blocked transcript scrolling, preventing users from reviewing earlier steps in a long plan while deciding how to proceed.

## What changed

Allow mouse-wheel scrolling over the visible transcript while a modal is active. Keep keyboard input with the modal and preserve restrictions on transcript selection, scrolling outside the transcript, and scrolling with completion popups open.

## Testing

Add input tests and a snapshot covering plan-prompt scrolling, keyboard navigation, dismissal and submission, pointer boundaries, and completion-popup behavior.

GitOrigin-RevId: ac5227c877ce34324a0d3830d5383495241ddbc3
2026-09-27 22:55:27 +00:00
Eric Traut abc8f0c9a1 Use the terminal palette for ordered Markdown list markers (#48800)
## What changed

Render ordered list markers in the TUI with the terminal's `LightBlue` color instead of `accent_color()`.

## Testing

Add a snapshot covering ordered list markers alongside links and inline code. Update rendering expectations and nested-list streaming tests to assert `LightBlue`, including the incremental rendering snapshot.

GitOrigin-RevId: dea0081737a5bbe8652c761582fb82b20964431a
2026-09-27 22:14:21 +00:00
Eric Traut 4c8cf3964d Fix SGR mouse reporting for Windows terminal capture (#48799)
## Why

Some Windows terminals send legacy mouse reports as key records. Requesting SGR reports lets ConPTY translate them into mouse records.

## What changed

Write and flush the SGR encoding request separately from `EnablePointerCapture`, so it also reaches terminals when capture uses the Windows console API. Explicitly reset SGR encoding during Windows mouse cleanup, even if restoring the console mode fails.

## Testing

Add regression tests for cleanup after SGR setup fails and an isolated Windows console test that checks mouse input activation, SGR encoding, and restoration of the original console mode and default encoding.

GitOrigin-RevId: c1a48d641cda4e770dbbe9fdf805a27e036d35c3
2026-09-27 22:13:56 +00:00
Won Park d7748e1185 Add opt-in structured errors for Guardian circuit-breaker interruptions (#48796)
## Why

Guardian denial-limit interruptions lack a structured error identifying the cause. Make this opt-in because older clients may not recognize the new error in shared history.

## What changed

- Add `auto_review.circuit_break_action = "strict"` to attach `TooManyDenials` to the interrupted turn. The default leaves the error unset.
- Expose `turn.error.codexErrorInfo = "tooManyDenials"` in app-server notifications and saved history, and update protocol schemas and generated types.
- Preserve the warning, denial limit, and interrupted status without emitting a separate error notification.

## Testing

Add an integration test covering omitted, `default`, and `strict` settings, checking warnings, live turn errors, the absence of separate error notifications, and persisted turn errors after restart.

GitOrigin-RevId: cb5d379e64728d4d7b9daf834c13756e4a70db31
2026-09-27 22:05:19 +00:00
victor-openai ea64727556 Add single-server MCP status discovery with thread connection reuse (#48783)
## Why

Inspecting one MCP server should not require full-inventory discovery or a separate connection when a thread already has one.

## What changed

- Add optional `serverName` to `mcpServerStatus/list` and update generated schemas and bindings.
- With `threadId`, apply any pending runtime refresh and reuse the thread's current connection and tool catalog, waiting only for the selected server during discovery.
- Without `threadId`, create a discovery connection for only the selected server. Unknown names return an empty page; omitting `serverName` preserves full-inventory discovery.

## Testing

Add a regression test covering both status detail modes, checking that tool metadata is preserved and that status reads do not repeat `initialize` or `tools/list` requests.

GitOrigin-RevId: 1b361b67a993ab45cae493e88c146f50cfaf753a
2026-09-27 21:07:54 +00:00
felixxia-oai 21eb35513d Preserve independent Guardian history across parent compaction (#48779)
## Why

Guardian reviews need to retain original evidence across parent compaction when checkpoint reuse is disabled, including after resume and rollback.

## What changed

- Make disabling `guardian_reuse_parent_compaction` select a bounded, independent review transcript while preserving thread-owned authorization.
- Keep synchronous reviews and asynchronous scoring independent of parent checkpoints, and allow reviewer sessions to continue using transcript deltas across parent compaction.
- Persist transcript entries with rollback provenance while remaining compatible with older checkpoint readers and metadata-free checkpoints.
- Exclude compaction output from the transcript and synthetic summaries from rollback turn boundaries. Use acceptance ordering to remove rolled-back evidence even when persistence order differs.

## Testing

Add regression coverage for reviewer continuity, evidence retention across compaction and resume, rollback after local and remote compaction, and checkpoint serialization compatibility.

GitOrigin-RevId: fea0852cc5537372854f4a34bacb6bfda6d13e88
2026-09-27 20:15:23 +00:00
Eric Traut 89bf86d0bd Remove the current badge from TUI task rows (#48776)
Let task titles use the space previously reserved for the `current` badge
in the agents overview. Update the overview assertion and rendering
snapshots to match.

GitOrigin-RevId: 6a007d4f8b1a3a77459895725e2db8ef4a4d584d
2026-09-27 19:48:44 +00:00
Eric Traut 596f8c5c3c Match pinned transcript headers to the original prompt style (#48775)
## What changed

Add the `› ` prefix to pinned prompt headers, using bold red for spoken prompts and bold dim styling for other prompts. Reserve one column when truncating the header.

## Testing

Add a rendering test comparing pinned headers with the original prompt rows for both regular and spoken prompts. Update snapshots for the prefix and display-width truncation.

GitOrigin-RevId: 89c2d9267374ef8f6504058c12c078025f302fef
2026-09-27 19:47:40 +00:00
Eric Traut fdbce2080c Fix Unix socket connections through long symlink paths (#48772)
## Why

An advertised control socket path can exceed the Unix socket path limit even when its symlink target is short enough to connect to.

## What changed

On Unix, resolve the socket path and retry the connection when the initial attempt returns `InvalidInput`.

## Testing

Add a regression test that creates control sockets under two long home paths, checks that their symlink targets are distinct, and verifies that clients can connect through both advertised paths.

GitOrigin-RevId: 2541f0a9b02d85035fa89fe26bbcd36d5cd0cc1e
2026-09-27 19:14:24 +00:00
victor-openai 32f5784851 Preserve MCP app resource URIs without defaulting display mode (#48764)
## Why

Defaulting missing or unsupported display preferences to `inline` prevents clients from applying resource display defaults.

## What changed

Populate `mcpAppUi` only when a tool descriptor has a resource URI and an explicit `inline` or `fullscreen` preference. Preserve `mcpAppResourceUri` independently in tool-call events, including when `mcpAppUi` is unset, and document the behavior.

## Testing

Update integration coverage for explicit display modes, missing and unsupported preferences, and legacy resource URIs, checking tool-call events and resumed history.

GitOrigin-RevId: 4876cced068d8e464adeb265abd053d8abe667ce
2026-09-27 18:20:25 +00:00
Felipe Coury e75b6b1e0c Show hidden output line counts in compact terminal activity (#48761)
## What changed

Replace generic output disclosure labels with counts such as `+ 5 lines (ctrl+t to expand)` for compact command activity, both live and in history. Count retained output lines hidden or clipped by the preview, excluding output discarded by storage limits.

Use the configured `open_transcript` shortcut and omit the hint when it does not fit or the action is unbound. Invalidate cached layouts when keybindings change. Keep generic `Show details` labels for other hidden details and keep disclosure controls outside copyable and searchable text.

## Testing

Add regression tests for live/history consistency, remapped and disabled shortcuts, and exclusion of hints from source text. Add snapshot coverage for fully visible output, hidden and clipped lines, command-only details, and storage-truncated output.

GitOrigin-RevId: c468be9b88b69dc3ca1abdb6b7be023244d32a57
2026-09-27 18:09:34 +00:00
Felipe Coury 71b38795d8 Match TUI status shimmer timing to desktop headers (#48757)
## What changed

Replace the continuous two-second shimmer with a 600 ms initial delay and a one-second sweep every four seconds, matching the desktop app's thinking and reasoning header timings.

## Testing

Update snapshots for short, long, and Unicode labels in both themes to cover the initial delay, sweep, gap, and next sweep. Sample smoothness across two sweeps at 32 ms intervals and adjust the brightness-change bound for the faster sweep.

GitOrigin-RevId: d7a6a81db99bf0e8a73eee0c67eb7e44d4d76f42
2026-09-27 17:59:57 +00:00
Felipe Coury 819cdb726d Render /status without borders and wrap long values (#48754)
## Why

The status card truncates values in narrow terminals, hiding parts of paths, session IDs, and other details.

## What changed

- Remove the status border and wrap values with continuation lines aligned beneath the value column, falling back to less indentation at very narrow widths.
- Preserve full directory paths and session IDs in displayed and copied status output.
- Allow history updates with no previous rows to append new details while preserving existing history rows.

## Testing

Add regression coverage for long Unicode paths and session IDs across terminal widths, copied text, usage links, and appending late thread-usage details. Update status snapshots for the borderless layout and wrapped values.

GitOrigin-RevId: e059fed5b45e15b76250b684f1760797442eabce
2026-09-27 17:31:45 +00:00
jif 18344a972d Centralize executable fixture creation to avoid Linux ETXTBSY races (#48727)
## Why

Concurrent tests can inherit writable descriptors for executable fixtures, causing `ETXTBSY` when those fixtures launch on Linux.

## What changed

Expose shared `write_executable` and `copy_executable` helpers from `codex_utils_cargo_bin` and adopt them in CLI, exec-server, and MCP tests. On Linux, writes and copies complete in separate processes so sibling test spawns cannot inherit the writable descriptors. Script fixtures receive mode `0o755`, and copied executables retain their source permissions.

Remove the executable-busy retry loop from the program resolver test now that its script uses the shared helper.

GitOrigin-RevId: 61624158190bb1e75c27d9eb9c87a2defc147fb7
2026-09-27 15:25:13 +00:00
Ankush Gupta 88235f881d Retain confirmed Code Mode messages for Guardian reviews (#48725)
## Why

Guardian needs the assistant's delivered question to interpret a user's reply. Messages sent through nested Code Mode tools must remain available as review context, and approvals based on earlier context must become stale when a new delivery is confirmed. Assistant messages do not themselves grant authorization.

## What changed

- Capture successful hosted User Messaging sends after input rewriting and before result callbacks or post-tool hooks.
- Retain bounded delivery text in acceptance order, persist it through cancellation and shutdown, and preserve it across compaction and resume with an older-client-compatible rollout encoding.
- Track assistant review context separately from user authorization, invalidating pending and cached approvals for both local and worker reviews when that context changes.
- Associate retained deliveries with the correct instruction or communication boundary during rollback.

## Testing

Add coverage for nested messaging review context, fast replies and communication ordering, shutdown persistence, stale local and worker approvals, rollout compatibility, and rollback retention.

GitOrigin-RevId: 1bc1ec9e8947560b99f4b39a42ddb9f2099f519b
2026-09-27 15:03:38 +00:00
jif 274d41a398 Prevent Linux ETXTBSY races in MCP stdio tests (#48724)
## Why

Concurrent test spawns can inherit a writable descriptor for the MCP server
wrapper, causing `ETXTBSY` when launching it on Linux.

## What changed

Write the wrapper through a separate `/bin/sh` process on Linux so its writable
descriptor stays out of the test process. Check the writer's exit status and
include stderr on failure. Retain direct file writes on other Unix platforms.

GitOrigin-RevId: f99952ec000ba7317243e87fd664dc0e31bb7b24
2026-09-27 14:55:33 +00:00
chess 41f9084b30 Remove WebSocket headers and tool payloads from info logs (#48686)
Stop logging response headers on successful WebSocket connections and payload
previews for tool calls. Keep the connection URL, tool name, and thread ID in
their respective log entries.

GitOrigin-RevId: 1d410b6aef8f12153da9bfc60c515b8e797a9de0
2026-09-27 11:30:52 +00:00
Eric Traut 67a709665a Fix the session-start helper call in the command center test (#48646)
Replace the stale `start_fresh_session_with_summary_hint` call with
`start_fresh_session` in the test for restoring blank drafts and built-in
permissions.

GitOrigin-RevId: a1f1f75dc173a732af712511cf8f6a16f2e3c0fa
2026-09-27 07:53:13 +00:00
riley-oai d8ec479c34 Set the provisioned macOS CLI bundle name to ChatGPT (#48643)
Set `CFBundleName` to `ChatGPT` and add `CFBundleDisplayName` with the same
value in the generated `Info.plist`.

GitOrigin-RevId: e40a0b10895227148d6fdc199b1c4166b5c59372
2026-09-27 07:41:50 +00:00
Eric Traut 8f195c93d7 Preserve blank TUI sessions when switching tasks (#48628)
## Why

Untouched threads have no rollout for `thread/resume` yet. Switching away from a blank startup or fresh session needs to preserve its live subscription, draft, and settings so it can be reopened.

## What changed

- Retain blank startup and fresh sessions for non-ephemeral connections to an external app server, and save their input state before navigating away.
- Restore the current thread name and apply background settings updates after restoring drafts, so saved model choices do not overwrite newer server settings.

## Testing

Extend the task-switching regression test to cover blank startup and fresh sessions, preserved drafts and model choices, updated thread names, and restoration without `thread/resume` or `thread/unsubscribe`. Verify that background model, permission, and approval-policy updates are used for the first submitted turn.

GitOrigin-RevId: 958b0cb48a5a873d8d8f5858ac334fecbfad60c7
2026-09-27 05:53:43 +00:00
Eric Traut 449d42ced9 Stop showing previous-session summaries when switching TUI sessions (#48626)
## What changed

Remove the previous session's token usage and resume hint from the history
shown when starting a fresh session or resuming another thread. Remove the
unused summary helpers and their tests, and rename the fresh-session helper
to `start_fresh_session`.

GitOrigin-RevId: d808bdf355831d1c7b937b6a101ffbb33a805234
2026-09-27 05:52:35 +00:00
Eric Traut 98072cf5f6 Preserve empty Markdown list markers in the TUI (#48623)
## Why

Empty list items can lose their markers, and a bare marker received during streaming can still acquire content in a later chunk.

## What changed

- Render pending markers when an empty item ends or a nested list starts on a new line, including inside blockquotes.
- Keep trailing bare list markers mutable during streaming so later content and terminal resizing preserve the item correctly.

## Testing

Add snapshot coverage for empty ordered, nested, and blockquoted list items, plus regression tests for streamed continuations, finalization, and resizing with a held marker.

GitOrigin-RevId: d9116bddc49670ad66d71dbddc66b2ab347cb6b7
2026-09-27 05:43:41 +00:00
Eric Traut 334b6e7321 Remove follow-up prompt suggestions from the TUI (#48621)
## What changed

Remove automatic next-message generation after successful turns, suggestion rendering in the composer, and the associated Tab acceptance and Escape dismissal handling. Remove the `tui.prompt_suggestions` configuration option and its schema entry, along with suggestion-specific tests and snapshots.

GitOrigin-RevId: 63bf6f2ca85da6ece502c86e2a805d000bf34210
2026-09-27 05:29:53 +00:00
alishobeiri-oai 814de47b69 Centralize persistent mode enablement checks (#48611)
## What changed

Add `Features::persistent_mode_enabled` and use it for persistent instructions and current-time reminder defaults. Enablement still requires `ReasoningEffort::Persistent`.

Change `PersistentModeState::new` to accept an explicit enablement boolean, separating instruction rendering from reasoning-effort selection.

## Testing

Update persistent-context tests to use boolean enablement while preserving coverage for instruction replacement, removal, deduplication, and retained history without a snapshot.

GitOrigin-RevId: f412b90d783438d1526956a56c11b9e66385ee0e
2026-09-27 04:00:21 +00:00
Martin Au-Yeung 9db8162d65 Remove the bundled plugin-creator skill (#48604)
## What changed

- Delete the `plugin-creator` skill, its assets, reference docs, helper scripts, and associated Python tests.
- Update the app-server skills context budget warning test to expect six omitted skills instead of seven.

GitOrigin-RevId: 005b1ab7f2f7c2933e6c297d01541746cc489f68
2026-09-27 03:26:57 +00:00
richardopenai 985cf47a4e Allow provisioned executors more time to come online (#48575)
## Why

A provisioned executor can still be resuming after readiness is reported. Initial connection attempts can exhaust the ordinary registry retry limits before the executor comes online.

## What changed

Retry `environment_offline` registry responses during initial Noise rendezvous connections for provisioned environments until a fixed five-minute deadline, starting after provisioning succeeds. Keep the existing retry limits for other registry errors and stop on permanent failures.

## Testing

Add tests covering the five-minute deadline, ordinary limits for other errors and stalled requests, and termination on a later permanent error. Verify that readiness and info requests remain pending through an extended offline period and succeed using the same environment handle once the executor comes online.

GitOrigin-RevId: e22211499d9ec2f3590e75224eb39e2e4bf3538d
2026-09-27 00:01:17 +00:00
Alex Daley 0f9a731ade Preserve deferred tool namespace names before descriptions (#48574)
## Why

Long descriptions could exhaust the 4 KiB tool summary budget and hide later namespace names, limiting their visibility for tool discovery.

## What changed

- Reserve space for all namespace names before sharing the remaining budget across descriptions, including added and removed groups.
- Truncate descriptions at UTF-8 boundaries with `...`, including at the existing 250-character cap. Omit whole namespaces only when names alone exceed the budget, reserving omission notices only in that case.
- Render namespace names and descriptions without XML escaping.

## Testing

Add unit and snapshot coverage for description allocation, Unicode boundaries, namespace omissions, and empty-state notices. Add a scenario verifying that a crowded catalog retains every namespace name, allows discovery of a late namespace with its full description, and keeps the summary unchanged on follow-up.

GitOrigin-RevId: 9743cda5aa14190db22c788c9e91e1785a32682b
2026-09-26 23:46:10 +00:00
open-matt b8d5e3f12e Allow exec-server to proxy permitted private IPs upstream (#48568)
## Why

Private IP destinations always bypassed inherited upstream proxies, preventing their use for private networks reachable through an upstream VPN proxy.

## What changed

- Add `codex exec-server --proxy-private-ips-via-upstream`, also configurable with `CODEX_EXEC_SERVER_PROXY_PRIVATE_IPS_VIA_UPSTREAM=true`. The setting defaults to disabled.
- Allow permitted RFC 1918, carrier-grade NAT, and IPv6 unique-local destinations to use an applicable upstream proxy. Loopback and link-local destinations retain direct routing, and destination access policy still applies.
- Keep connections direct when no valid upstream proxy applies or `allow_upstream_proxy=false`. Errors after selecting an upstream proxy do not trigger a direct retry.
- Rename `ExecServerRuntimePaths` to `ExecServerRuntimeOptions` and carry the routing setting from executor startup into the managed network proxy.

## Testing

Add routing coverage for private address ranges, special-use addresses, and public targets with the option enabled and disabled. Verify that HTTP and CONNECT requests still enforce destination allowlists and denylists, and update the CLI help snapshot.

GitOrigin-RevId: b7c9cc7da0e0f545694a6521b74c9b36b7b92769
2026-09-26 23:17:41 +00:00
Winston Howes 228ae3da8d Allow macOS TLS trust evaluation in network-enabled Seatbelt profiles (#48565)
## Why

System libcurl needs access to `com.apple.TrustEvaluationAgent` for TLS, but Seatbelt network profiles did not allow lookup of this service.

## What changed

Allow `mach-lookup` for this service when unrestricted networking is enabled or a restricted profile permits proxy ports or local binding. Keep access denied for network-disabled, Unix-socket-only, and managed profiles without usable endpoints.

## Testing

Add macOS regression tests that apply Seatbelt policies and check trust-service access and loopback connections without external network dependencies. Cover managed-network overrides and verify that unrelated service lookups and connections to unapproved ports remain denied.

GitOrigin-RevId: 8b190d6181fe1321186837557caa379275abfaee
2026-09-26 23:08:50 +00:00
Felipe Coury e8fdbf1f7c Use a consistent borderless session header in the TUI (#48562)
## What changed

- Use the compact title, version, and directory layout for all session headers, including resume, fork, and clear-screen flows. Remove the boxed model row and retain the optional greeting and YOLO permissions indicator.
- Share title styling with the status card and honor the active render mode and wrapping policy when inserting a fresh header after clearing the screen.

## Testing

Update header and startup snapshots for the borderless layout, narrow widths, and halfwidth directory characters. Add assertions that clearing history preserves the raw header in raw output mode.

GitOrigin-RevId: 0b91c1ce6646f9d9d1954b1442936abe93bdcd3c
2026-09-26 22:50:16 +00:00
Felipe Coury 6a39914e37 Keep working tips stable during transcript interaction (#48560)
## Why

Hiding an already-visible working tip during mouse selection shifts the transcript layout and disrupts selection.

## What changed

Keep displayed working tips visible while interacting with the transcript or scrolling away from the latest output. Initial tip display and completion tips still require an idle viewport following the latest output.

Check usage notices directly when suppressing tips so a tip cannot appear merely because interaction temporarily hides the composer warning.

## Testing

Add a mouse-selection regression test and snapshot covering deferred initial display, stable transcript rows through mouse down, drag, and release, correct selected text, and continued tip suppression when a usage warning is hidden during interaction.

GitOrigin-RevId: 3cee527f3a7daaccecbeedbdf083c61075dfa32f
2026-09-26 22:40:08 +00:00
Eric Traut 7b7d934408 Fix TUI math rendering for zero and big wedge expressions (#48551)
## Why

Inline `$0$` was left unrendered, and expressions containing `\bigwedge`, `\bigl`, or `\bigr` fell back to raw LaTeX.

## What changed

- Allow `$0$` through the inline math detection heuristic.
- Render `\bigwedge` as `⋀`, with limits stacked above and below in display math.
- Handle `\bigl` and `\bigr` like `\left` and `\right`.

## Testing

Add a regression snapshot covering inline zero, inline big wedge, and a multiline display expression with stacked limits and delimiters.

GitOrigin-RevId: 89f596ea5f38070274505cfa7ea757595d7ae137
2026-09-26 22:05:32 +00:00
Felipe Coury 75a714843b Preserve Markdown tables and whitespace when copying TUI responses (#48549)
## Why

Copied table selections became code blocks containing the rendered grid, losing table structure. Stripping trailing whitespace from completed responses also removed Markdown hard breaks and spaces in code.

## What changed

- Reconstruct Markdown tables from selected cells across grid and record layouts, preserving alignment, inline formatting, and list or blockquote nesting.
- Copy a single selected cell as inline content and leave unselected cells empty without adding their text. Escape literal pipes in table code spans and link destinations.
- Preserve trailing whitespace on lines unchanged by assistant directive removal.
- Keep blank rows in copied text without painting newline selection highlights on empty rows.

## Testing

Add regression coverage for wrapped and rewrapped tables, partial selections, empty cells, literal pipes, and separate table and code blocks. Update snapshots for nested tables and selection highlights, and verify completed-response copying preserves hard breaks and code whitespace.

GitOrigin-RevId: 661e4c8331f2737bedff286548f9343bac44e0cb
2026-09-26 21:58:39 +00:00
Felipe Coury 16c21e3f36 Preserve table cell source metadata through TUI rendering (#48548)
## What changed

- Retain table identity, column alignments, cell coordinates, source byte ranges, and inline formatting in copy metadata.
- Carry cell fragments through grid padding, wrapping, key/value layouts, and pipe output, including escaped pipes and empty cells.
- Preserve logical source metadata when remapping wrapped lines, even without hyperlinks.

## Testing

Add coverage for cell fragments across narrow and wide layouts, blank table continuations, and Markdown selection copy structure and visible transformations.

GitOrigin-RevId: 8422f224cffe2e74813394f0623b9167bdd4ac59
2026-09-26 21:58:17 +00:00
Felipe Coury d6f25a54ba Fade blossom replays back to the idle state (#48547)
## Why

Clicking the welcome blossom replays its animation, but completion abruptly switches from full color to the dim idle frame.

## What changed

Fade the blossom back to idle opacity over 400 ms after the replay finishes spinning. Keep scheduling redraws until the fade completes, then clear the replay state.

## Testing

Extend the replay test with color snapshots at the start, midpoint, and end of the fade, and assertions that redraws stop and the original idle frame is restored.

GitOrigin-RevId: ec3fafb6766533d9c221913e8a3be03b8a8036f7
2026-09-26 21:57:55 +00:00
Eric Traut 7ed14a27db Make onboarding login links easier to copy (#48544)
## Why

When browser sign-in does not open automatically, users need to copy the login URL. Onboarding should also allow terminal selection of login URLs and device codes in fullscreen mode.

## What changed

- Add a `c` shortcut to copy the browser sign-in URL, with status messages for pending, successful, unconfirmed, busy, and failed clipboard requests.
- Apply asynchronous clipboard results only to the matching login attempt.
- Disable mouse capture during onboarding so the terminal can select text, and restore the previous input policy afterward.

## Testing

Update the narrow-screen login snapshot to show the copy shortcut and extend mouse-policy coverage to verify onboarding leaves mouse capture disabled.

GitOrigin-RevId: 01676b737efb192d900da306cd2c6b32f791ceb9
2026-09-26 21:44:28 +00:00
zm-oai 06f97622f8 Add context to Windows sandbox runtime registration errors (#48531)
Identify the failing setup step when starting, completing, or verifying managed runtime package registration, granting metadata permissions, or persisting the completed registration. Preserve the underlying errors with `anyhow::Context`.

GitOrigin-RevId: 85f712faf2519e95704d7e8cea15d2deeed0d51e
2026-09-26 20:26:34 +00:00
Felipe Coury 7f6c0f9387 Refresh the TUI welcome screen for new sessions (#48513)
## What changed

- Show a compact session header with a randomly selected greeting, preserving the greeting and blossom state from startup into the live session.
- Center a settled blossom in unused fullscreen space and replay its animation on click. Hide it while typing or when space is insufficient, and respect `tui.animations` and `tui.effects.welcome`.
- Hide startup tips in the fullscreen transcript while retaining them in terminal scrollback, and prevent hidden entries from shifting the first visible header.
- Keep the composer visible and responsive during daemon startup, routing startup diagnostics through tracing while direct lifecycle commands retain stderr output.

## Testing

Add regression tests and update snapshots for blossom placement and click replay, welcome opt-outs, greeting stability, startup transitions, tip visibility, and transcript spacing.

GitOrigin-RevId: ec7b082fbe25ced1180cad3348f5c76e48c0e92b
2026-09-26 18:59:50 +00:00
pakrym-oai 12de0e395d Preserve WebSocket continuations when steering a turn (#48508)
## Why

Steering an active WebSocket response previously dropped the connection and
resent the full history. Draining the response preserves the connection and
allows the follow-up request to continue with `previous_response_id`.

## What changed

- Drain WebSocket responses when steering. For models using
  `use_responses_lite`, first send `response.interrupt` with
  `mode: "discard_partial_items"` once the response ID is available.
- Treat `response.incomplete` with reason `interrupted` as completion with
  `end_turn: false`, preserving token usage and allowing the turn to continue.
  Other incomplete reasons remain errors.

## Testing

Update the steering integration test to cover completed and discarded reasoning
items, asserting connection reuse, incremental follow-up input, and token usage
from the interrupted response.

GitOrigin-RevId: bc714b713e797cf1a67e3b26ffbf7664cb92eb33
2026-09-26 18:36:55 +00:00
Eric Traut 0fbf0bedc2 Fix ChatGPT browser sign-in for local app servers (#48502)
## Why

Local daemons use a remote request handle even though their login callback is local, so the TUI skipped opening the browser. Login completion could also arrive while the browser was opening, before the TUI had recorded the active login.

## What changed

- Use `AppServerTarget` to open the login URL for embedded servers and local daemons, while continuing to skip automatic browser opening for remote workspaces.
- Set the pending login state and schedule a frame before opening the browser so completion notifications can match the active login.

## Testing

Add regression tests for browser opening across embedded, local daemon, and remote targets, and for login completion during browser opening.

GitOrigin-RevId: 3feceb877e6131bfd0671c3556314c6c7fd4a677
2026-09-26 18:15:43 +00:00