## What changed
- Add `CodexThread::prewarm_with_history()` to prepare a WebSocket response with existing conversation history and executed-tool metadata using `generate: false`. The next turn can reuse the prepared response when its prompt extends that history and request settings match.
- Keep startup prewarming and `prewarm()` on the existing empty-input path, and skip preparation when the cached WebSocket is ready.
- Label prewarm telemetry by input mode and WebSocket continuation metrics with `after_prewarm`.
- Rename `persistent_mode_enabled` to `persistent_execution_enabled` without changing its behavior.
## Testing
Extend WebSocket coverage to check history preservation during reconnect prewarming, reuse of the prepared response on the next turn, and omission of `previous_response_id` for a non-prefix prompt.
GitOrigin-RevId: c7731541b11b2e6668027a47f37f696213268c66
## Why
Completion footers hid known durations unless they exceeded 60 seconds, leaving short turns without elapsed-time information.
## What changed
Show all known durations for live and restored turns, rendering sub-second durations as `Worked for <1s`. Separate completion metadata with `•` instead of `·`.
## Testing
Update live completion, history replay, and separator tests to cover short durations, missing timestamps, and the revised footer format. Refresh affected TUI snapshots.
GitOrigin-RevId: 666e765db5426c5f9cc00d73f71cab649ad34947
## Why
The “Implement this plan?” prompt blocked transcript scrolling, preventing users from reviewing earlier steps in a long plan while deciding how to proceed.
## What changed
Allow mouse-wheel scrolling over the visible transcript while a modal is active. Keep keyboard input with the modal and preserve restrictions on transcript selection, scrolling outside the transcript, and scrolling with completion popups open.
## Testing
Add input tests and a snapshot covering plan-prompt scrolling, keyboard navigation, dismissal and submission, pointer boundaries, and completion-popup behavior.
GitOrigin-RevId: ac5227c877ce34324a0d3830d5383495241ddbc3
## What changed
Render ordered list markers in the TUI with the terminal's `LightBlue` color instead of `accent_color()`.
## Testing
Add a snapshot covering ordered list markers alongside links and inline code. Update rendering expectations and nested-list streaming tests to assert `LightBlue`, including the incremental rendering snapshot.
GitOrigin-RevId: dea0081737a5bbe8652c761582fb82b20964431a
## Why
Some Windows terminals send legacy mouse reports as key records. Requesting SGR reports lets ConPTY translate them into mouse records.
## What changed
Write and flush the SGR encoding request separately from `EnablePointerCapture`, so it also reaches terminals when capture uses the Windows console API. Explicitly reset SGR encoding during Windows mouse cleanup, even if restoring the console mode fails.
## Testing
Add regression tests for cleanup after SGR setup fails and an isolated Windows console test that checks mouse input activation, SGR encoding, and restoration of the original console mode and default encoding.
GitOrigin-RevId: c1a48d641cda4e770dbbe9fdf805a27e036d35c3
## Why
Guardian denial-limit interruptions lack a structured error identifying the cause. Make this opt-in because older clients may not recognize the new error in shared history.
## What changed
- Add `auto_review.circuit_break_action = "strict"` to attach `TooManyDenials` to the interrupted turn. The default leaves the error unset.
- Expose `turn.error.codexErrorInfo = "tooManyDenials"` in app-server notifications and saved history, and update protocol schemas and generated types.
- Preserve the warning, denial limit, and interrupted status without emitting a separate error notification.
## Testing
Add an integration test covering omitted, `default`, and `strict` settings, checking warnings, live turn errors, the absence of separate error notifications, and persisted turn errors after restart.
GitOrigin-RevId: cb5d379e64728d4d7b9daf834c13756e4a70db31
## Why
Inspecting one MCP server should not require full-inventory discovery or a separate connection when a thread already has one.
## What changed
- Add optional `serverName` to `mcpServerStatus/list` and update generated schemas and bindings.
- With `threadId`, apply any pending runtime refresh and reuse the thread's current connection and tool catalog, waiting only for the selected server during discovery.
- Without `threadId`, create a discovery connection for only the selected server. Unknown names return an empty page; omitting `serverName` preserves full-inventory discovery.
## Testing
Add a regression test covering both status detail modes, checking that tool metadata is preserved and that status reads do not repeat `initialize` or `tools/list` requests.
GitOrigin-RevId: 1b361b67a993ab45cae493e88c146f50cfaf753a
## Why
Guardian reviews need to retain original evidence across parent compaction when checkpoint reuse is disabled, including after resume and rollback.
## What changed
- Make disabling `guardian_reuse_parent_compaction` select a bounded, independent review transcript while preserving thread-owned authorization.
- Keep synchronous reviews and asynchronous scoring independent of parent checkpoints, and allow reviewer sessions to continue using transcript deltas across parent compaction.
- Persist transcript entries with rollback provenance while remaining compatible with older checkpoint readers and metadata-free checkpoints.
- Exclude compaction output from the transcript and synthetic summaries from rollback turn boundaries. Use acceptance ordering to remove rolled-back evidence even when persistence order differs.
## Testing
Add regression coverage for reviewer continuity, evidence retention across compaction and resume, rollback after local and remote compaction, and checkpoint serialization compatibility.
GitOrigin-RevId: fea0852cc5537372854f4a34bacb6bfda6d13e88
Let task titles use the space previously reserved for the `current` badge
in the agents overview. Update the overview assertion and rendering
snapshots to match.
GitOrigin-RevId: 6a007d4f8b1a3a77459895725e2db8ef4a4d584d
## What changed
Add the `› ` prefix to pinned prompt headers, using bold red for spoken prompts and bold dim styling for other prompts. Reserve one column when truncating the header.
## Testing
Add a rendering test comparing pinned headers with the original prompt rows for both regular and spoken prompts. Update snapshots for the prefix and display-width truncation.
GitOrigin-RevId: 89c2d9267374ef8f6504058c12c078025f302fef
## Why
An advertised control socket path can exceed the Unix socket path limit even when its symlink target is short enough to connect to.
## What changed
On Unix, resolve the socket path and retry the connection when the initial attempt returns `InvalidInput`.
## Testing
Add a regression test that creates control sockets under two long home paths, checks that their symlink targets are distinct, and verifies that clients can connect through both advertised paths.
GitOrigin-RevId: 2541f0a9b02d85035fa89fe26bbcd36d5cd0cc1e
## Why
Defaulting missing or unsupported display preferences to `inline` prevents clients from applying resource display defaults.
## What changed
Populate `mcpAppUi` only when a tool descriptor has a resource URI and an explicit `inline` or `fullscreen` preference. Preserve `mcpAppResourceUri` independently in tool-call events, including when `mcpAppUi` is unset, and document the behavior.
## Testing
Update integration coverage for explicit display modes, missing and unsupported preferences, and legacy resource URIs, checking tool-call events and resumed history.
GitOrigin-RevId: 4876cced068d8e464adeb265abd053d8abe667ce
## What changed
Replace generic output disclosure labels with counts such as `+ 5 lines (ctrl+t to expand)` for compact command activity, both live and in history. Count retained output lines hidden or clipped by the preview, excluding output discarded by storage limits.
Use the configured `open_transcript` shortcut and omit the hint when it does not fit or the action is unbound. Invalidate cached layouts when keybindings change. Keep generic `Show details` labels for other hidden details and keep disclosure controls outside copyable and searchable text.
## Testing
Add regression tests for live/history consistency, remapped and disabled shortcuts, and exclusion of hints from source text. Add snapshot coverage for fully visible output, hidden and clipped lines, command-only details, and storage-truncated output.
GitOrigin-RevId: c468be9b88b69dc3ca1abdb6b7be023244d32a57
## What changed
Replace the continuous two-second shimmer with a 600 ms initial delay and a one-second sweep every four seconds, matching the desktop app's thinking and reasoning header timings.
## Testing
Update snapshots for short, long, and Unicode labels in both themes to cover the initial delay, sweep, gap, and next sweep. Sample smoothness across two sweeps at 32 ms intervals and adjust the brightness-change bound for the faster sweep.
GitOrigin-RevId: d7a6a81db99bf0e8a73eee0c67eb7e44d4d76f42
## Why
The status card truncates values in narrow terminals, hiding parts of paths, session IDs, and other details.
## What changed
- Remove the status border and wrap values with continuation lines aligned beneath the value column, falling back to less indentation at very narrow widths.
- Preserve full directory paths and session IDs in displayed and copied status output.
- Allow history updates with no previous rows to append new details while preserving existing history rows.
## Testing
Add regression coverage for long Unicode paths and session IDs across terminal widths, copied text, usage links, and appending late thread-usage details. Update status snapshots for the borderless layout and wrapped values.
GitOrigin-RevId: e059fed5b45e15b76250b684f1760797442eabce
## Why
Concurrent tests can inherit writable descriptors for executable fixtures, causing `ETXTBSY` when those fixtures launch on Linux.
## What changed
Expose shared `write_executable` and `copy_executable` helpers from `codex_utils_cargo_bin` and adopt them in CLI, exec-server, and MCP tests. On Linux, writes and copies complete in separate processes so sibling test spawns cannot inherit the writable descriptors. Script fixtures receive mode `0o755`, and copied executables retain their source permissions.
Remove the executable-busy retry loop from the program resolver test now that its script uses the shared helper.
GitOrigin-RevId: 61624158190bb1e75c27d9eb9c87a2defc147fb7
## Why
Guardian needs the assistant's delivered question to interpret a user's reply. Messages sent through nested Code Mode tools must remain available as review context, and approvals based on earlier context must become stale when a new delivery is confirmed. Assistant messages do not themselves grant authorization.
## What changed
- Capture successful hosted User Messaging sends after input rewriting and before result callbacks or post-tool hooks.
- Retain bounded delivery text in acceptance order, persist it through cancellation and shutdown, and preserve it across compaction and resume with an older-client-compatible rollout encoding.
- Track assistant review context separately from user authorization, invalidating pending and cached approvals for both local and worker reviews when that context changes.
- Associate retained deliveries with the correct instruction or communication boundary during rollback.
## Testing
Add coverage for nested messaging review context, fast replies and communication ordering, shutdown persistence, stale local and worker approvals, rollout compatibility, and rollback retention.
GitOrigin-RevId: 1bc1ec9e8947560b99f4b39a42ddb9f2099f519b
## Why
Concurrent test spawns can inherit a writable descriptor for the MCP server
wrapper, causing `ETXTBSY` when launching it on Linux.
## What changed
Write the wrapper through a separate `/bin/sh` process on Linux so its writable
descriptor stays out of the test process. Check the writer's exit status and
include stderr on failure. Retain direct file writes on other Unix platforms.
GitOrigin-RevId: f99952ec000ba7317243e87fd664dc0e31bb7b24
Stop logging response headers on successful WebSocket connections and payload
previews for tool calls. Keep the connection URL, tool name, and thread ID in
their respective log entries.
GitOrigin-RevId: 1d410b6aef8f12153da9bfc60c515b8e797a9de0
Replace the stale `start_fresh_session_with_summary_hint` call with
`start_fresh_session` in the test for restoring blank drafts and built-in
permissions.
GitOrigin-RevId: a1f1f75dc173a732af712511cf8f6a16f2e3c0fa
Set `CFBundleName` to `ChatGPT` and add `CFBundleDisplayName` with the same
value in the generated `Info.plist`.
GitOrigin-RevId: e40a0b10895227148d6fdc199b1c4166b5c59372
## Why
Untouched threads have no rollout for `thread/resume` yet. Switching away from a blank startup or fresh session needs to preserve its live subscription, draft, and settings so it can be reopened.
## What changed
- Retain blank startup and fresh sessions for non-ephemeral connections to an external app server, and save their input state before navigating away.
- Restore the current thread name and apply background settings updates after restoring drafts, so saved model choices do not overwrite newer server settings.
## Testing
Extend the task-switching regression test to cover blank startup and fresh sessions, preserved drafts and model choices, updated thread names, and restoration without `thread/resume` or `thread/unsubscribe`. Verify that background model, permission, and approval-policy updates are used for the first submitted turn.
GitOrigin-RevId: 958b0cb48a5a873d8d8f5858ac334fecbfad60c7
## What changed
Remove the previous session's token usage and resume hint from the history
shown when starting a fresh session or resuming another thread. Remove the
unused summary helpers and their tests, and rename the fresh-session helper
to `start_fresh_session`.
GitOrigin-RevId: d808bdf355831d1c7b937b6a101ffbb33a805234
## Why
Empty list items can lose their markers, and a bare marker received during streaming can still acquire content in a later chunk.
## What changed
- Render pending markers when an empty item ends or a nested list starts on a new line, including inside blockquotes.
- Keep trailing bare list markers mutable during streaming so later content and terminal resizing preserve the item correctly.
## Testing
Add snapshot coverage for empty ordered, nested, and blockquoted list items, plus regression tests for streamed continuations, finalization, and resizing with a held marker.
GitOrigin-RevId: d9116bddc49670ad66d71dbddc66b2ab347cb6b7
## What changed
Remove automatic next-message generation after successful turns, suggestion rendering in the composer, and the associated Tab acceptance and Escape dismissal handling. Remove the `tui.prompt_suggestions` configuration option and its schema entry, along with suggestion-specific tests and snapshots.
GitOrigin-RevId: 63bf6f2ca85da6ece502c86e2a805d000bf34210
## What changed
Add `Features::persistent_mode_enabled` and use it for persistent instructions and current-time reminder defaults. Enablement still requires `ReasoningEffort::Persistent`.
Change `PersistentModeState::new` to accept an explicit enablement boolean, separating instruction rendering from reasoning-effort selection.
## Testing
Update persistent-context tests to use boolean enablement while preserving coverage for instruction replacement, removal, deduplication, and retained history without a snapshot.
GitOrigin-RevId: f412b90d783438d1526956a56c11b9e66385ee0e
## What changed
- Delete the `plugin-creator` skill, its assets, reference docs, helper scripts, and associated Python tests.
- Update the app-server skills context budget warning test to expect six omitted skills instead of seven.
GitOrigin-RevId: 005b1ab7f2f7c2933e6c297d01541746cc489f68
## Why
A provisioned executor can still be resuming after readiness is reported. Initial connection attempts can exhaust the ordinary registry retry limits before the executor comes online.
## What changed
Retry `environment_offline` registry responses during initial Noise rendezvous connections for provisioned environments until a fixed five-minute deadline, starting after provisioning succeeds. Keep the existing retry limits for other registry errors and stop on permanent failures.
## Testing
Add tests covering the five-minute deadline, ordinary limits for other errors and stalled requests, and termination on a later permanent error. Verify that readiness and info requests remain pending through an extended offline period and succeed using the same environment handle once the executor comes online.
GitOrigin-RevId: e22211499d9ec2f3590e75224eb39e2e4bf3538d
## Why
Long descriptions could exhaust the 4 KiB tool summary budget and hide later namespace names, limiting their visibility for tool discovery.
## What changed
- Reserve space for all namespace names before sharing the remaining budget across descriptions, including added and removed groups.
- Truncate descriptions at UTF-8 boundaries with `...`, including at the existing 250-character cap. Omit whole namespaces only when names alone exceed the budget, reserving omission notices only in that case.
- Render namespace names and descriptions without XML escaping.
## Testing
Add unit and snapshot coverage for description allocation, Unicode boundaries, namespace omissions, and empty-state notices. Add a scenario verifying that a crowded catalog retains every namespace name, allows discovery of a late namespace with its full description, and keeps the summary unchanged on follow-up.
GitOrigin-RevId: 9743cda5aa14190db22c788c9e91e1785a32682b
## Why
Private IP destinations always bypassed inherited upstream proxies, preventing their use for private networks reachable through an upstream VPN proxy.
## What changed
- Add `codex exec-server --proxy-private-ips-via-upstream`, also configurable with `CODEX_EXEC_SERVER_PROXY_PRIVATE_IPS_VIA_UPSTREAM=true`. The setting defaults to disabled.
- Allow permitted RFC 1918, carrier-grade NAT, and IPv6 unique-local destinations to use an applicable upstream proxy. Loopback and link-local destinations retain direct routing, and destination access policy still applies.
- Keep connections direct when no valid upstream proxy applies or `allow_upstream_proxy=false`. Errors after selecting an upstream proxy do not trigger a direct retry.
- Rename `ExecServerRuntimePaths` to `ExecServerRuntimeOptions` and carry the routing setting from executor startup into the managed network proxy.
## Testing
Add routing coverage for private address ranges, special-use addresses, and public targets with the option enabled and disabled. Verify that HTTP and CONNECT requests still enforce destination allowlists and denylists, and update the CLI help snapshot.
GitOrigin-RevId: b7c9cc7da0e0f545694a6521b74c9b36b7b92769
## Why
System libcurl needs access to `com.apple.TrustEvaluationAgent` for TLS, but Seatbelt network profiles did not allow lookup of this service.
## What changed
Allow `mach-lookup` for this service when unrestricted networking is enabled or a restricted profile permits proxy ports or local binding. Keep access denied for network-disabled, Unix-socket-only, and managed profiles without usable endpoints.
## Testing
Add macOS regression tests that apply Seatbelt policies and check trust-service access and loopback connections without external network dependencies. Cover managed-network overrides and verify that unrelated service lookups and connections to unapproved ports remain denied.
GitOrigin-RevId: 8b190d6181fe1321186837557caa379275abfaee
## What changed
- Use the compact title, version, and directory layout for all session headers, including resume, fork, and clear-screen flows. Remove the boxed model row and retain the optional greeting and YOLO permissions indicator.
- Share title styling with the status card and honor the active render mode and wrapping policy when inserting a fresh header after clearing the screen.
## Testing
Update header and startup snapshots for the borderless layout, narrow widths, and halfwidth directory characters. Add assertions that clearing history preserves the raw header in raw output mode.
GitOrigin-RevId: 0b91c1ce6646f9d9d1954b1442936abe93bdcd3c
## Why
Hiding an already-visible working tip during mouse selection shifts the transcript layout and disrupts selection.
## What changed
Keep displayed working tips visible while interacting with the transcript or scrolling away from the latest output. Initial tip display and completion tips still require an idle viewport following the latest output.
Check usage notices directly when suppressing tips so a tip cannot appear merely because interaction temporarily hides the composer warning.
## Testing
Add a mouse-selection regression test and snapshot covering deferred initial display, stable transcript rows through mouse down, drag, and release, correct selected text, and continued tip suppression when a usage warning is hidden during interaction.
GitOrigin-RevId: 3cee527f3a7daaccecbeedbdf083c61075dfa32f
## Why
Inline `$0$` was left unrendered, and expressions containing `\bigwedge`, `\bigl`, or `\bigr` fell back to raw LaTeX.
## What changed
- Allow `$0$` through the inline math detection heuristic.
- Render `\bigwedge` as `⋀`, with limits stacked above and below in display math.
- Handle `\bigl` and `\bigr` like `\left` and `\right`.
## Testing
Add a regression snapshot covering inline zero, inline big wedge, and a multiline display expression with stacked limits and delimiters.
GitOrigin-RevId: 89f596ea5f38070274505cfa7ea757595d7ae137
## Why
Copied table selections became code blocks containing the rendered grid, losing table structure. Stripping trailing whitespace from completed responses also removed Markdown hard breaks and spaces in code.
## What changed
- Reconstruct Markdown tables from selected cells across grid and record layouts, preserving alignment, inline formatting, and list or blockquote nesting.
- Copy a single selected cell as inline content and leave unselected cells empty without adding their text. Escape literal pipes in table code spans and link destinations.
- Preserve trailing whitespace on lines unchanged by assistant directive removal.
- Keep blank rows in copied text without painting newline selection highlights on empty rows.
## Testing
Add regression coverage for wrapped and rewrapped tables, partial selections, empty cells, literal pipes, and separate table and code blocks. Update snapshots for nested tables and selection highlights, and verify completed-response copying preserves hard breaks and code whitespace.
GitOrigin-RevId: 661e4c8331f2737bedff286548f9343bac44e0cb
## Why
Clicking the welcome blossom replays its animation, but completion abruptly switches from full color to the dim idle frame.
## What changed
Fade the blossom back to idle opacity over 400 ms after the replay finishes spinning. Keep scheduling redraws until the fade completes, then clear the replay state.
## Testing
Extend the replay test with color snapshots at the start, midpoint, and end of the fade, and assertions that redraws stop and the original idle frame is restored.
GitOrigin-RevId: ec3fafb6766533d9c221913e8a3be03b8a8036f7
## Why
When browser sign-in does not open automatically, users need to copy the login URL. Onboarding should also allow terminal selection of login URLs and device codes in fullscreen mode.
## What changed
- Add a `c` shortcut to copy the browser sign-in URL, with status messages for pending, successful, unconfirmed, busy, and failed clipboard requests.
- Apply asynchronous clipboard results only to the matching login attempt.
- Disable mouse capture during onboarding so the terminal can select text, and restore the previous input policy afterward.
## Testing
Update the narrow-screen login snapshot to show the copy shortcut and extend mouse-policy coverage to verify onboarding leaves mouse capture disabled.
GitOrigin-RevId: 01676b737efb192d900da306cd2c6b32f791ceb9
Identify the failing setup step when starting, completing, or verifying managed runtime package registration, granting metadata permissions, or persisting the completed registration. Preserve the underlying errors with `anyhow::Context`.
GitOrigin-RevId: 85f712faf2519e95704d7e8cea15d2deeed0d51e
## What changed
- Show a compact session header with a randomly selected greeting, preserving the greeting and blossom state from startup into the live session.
- Center a settled blossom in unused fullscreen space and replay its animation on click. Hide it while typing or when space is insufficient, and respect `tui.animations` and `tui.effects.welcome`.
- Hide startup tips in the fullscreen transcript while retaining them in terminal scrollback, and prevent hidden entries from shifting the first visible header.
- Keep the composer visible and responsive during daemon startup, routing startup diagnostics through tracing while direct lifecycle commands retain stderr output.
## Testing
Add regression tests and update snapshots for blossom placement and click replay, welcome opt-outs, greeting stability, startup transitions, tip visibility, and transcript spacing.
GitOrigin-RevId: ec7b082fbe25ced1180cad3348f5c76e48c0e92b
## Why
Steering an active WebSocket response previously dropped the connection and
resent the full history. Draining the response preserves the connection and
allows the follow-up request to continue with `previous_response_id`.
## What changed
- Drain WebSocket responses when steering. For models using
`use_responses_lite`, first send `response.interrupt` with
`mode: "discard_partial_items"` once the response ID is available.
- Treat `response.incomplete` with reason `interrupted` as completion with
`end_turn: false`, preserving token usage and allowing the turn to continue.
Other incomplete reasons remain errors.
## Testing
Update the steering integration test to cover completed and discarded reasoning
items, asserting connection reuse, incremental follow-up input, and token usage
from the interrupted response.
GitOrigin-RevId: bc714b713e797cf1a67e3b26ffbf7664cb92eb33
## Why
Local daemons use a remote request handle even though their login callback is local, so the TUI skipped opening the browser. Login completion could also arrive while the browser was opening, before the TUI had recorded the active login.
## What changed
- Use `AppServerTarget` to open the login URL for embedded servers and local daemons, while continuing to skip automatic browser opening for remote workspaces.
- Set the pending login state and schedule a frame before opening the browser so completion notifications can match the active login.
## Testing
Add regression tests for browser opening across embedded, local daemon, and remote targets, and for login completion during browser opening.
GitOrigin-RevId: 3feceb877e6131bfd0671c3556314c6c7fd4a677
## Why
Windows launchers such as `cargo run` can prevent background processes from outliving them, causing automatic daemon startup to fail and blocking the CLI from opening.
## What changed
- Classify detached launch restrictions by retrying an access-denied launch probe without the job breakaway flag. Keep both probes suspended and terminate and reap successful probes.
- Use the embedded server with a visible warning when automatic startup encounters this restriction. Preserve errors for other launch failures, including inaccessible executables and elevated startup.
- Keep explicit daemon lifecycle operations failing on the restriction, with guidance to build and run `codex.exe` directly.
## Testing
Add Windows coverage for restriction classification and executable access failures, plus a CLI integration test and warning snapshot for embedded fallback under a restrictive job. The integration test also checks that elevated startup still fails and no daemon PID file is created.
GitOrigin-RevId: fc7c46e0f5f07ca0aba12b535a0e372021bdf46a
## What changed
- Reject unsupported flowchart shapes and Markdown strings so the terminal renderer preserves the source with an unsupported-feature notice instead of misrendering it. Keep ordinary quoted labels containing shape-like punctuation valid.
- Preserve class relationship targets beginning with `o`, such as `A --orange`, instead of consuming the first letter as an aggregation marker.
- Accumulate state aliases and descriptions in source order: use the first as the title and subsequent entries as body rows, preserving state identity and limiting body rows to 16.
## Testing
Add parser regressions for these cases and description limits, update class and state snapshots, and extend TUI snapshots to verify source preservation for unsupported flowchart syntax.
GitOrigin-RevId: c44d954312c77229a3752a0d9ada14e34a43a376
## Why
Piped child processes launched from a detached Windows process should not allocate a console window.
## What changed
Set `CREATE_NO_WINDOW` by default for `codex-rs/utils/pty` child commands. Preserve it alongside `CREATE_SUSPENDED` when preparing a child for Job Object containment, since Tokio's `creation_flags` replaces existing flags.
## Testing
Add a Windows regression test that runs from a detached process and verifies that children have no console window and retain working piped stdin and stdout, both with and without Job Object containment.
GitOrigin-RevId: 990386032d74fa783a66bb20faff769539ea41c1
## What changed
Make `tui.copy_on_select = "auto"` copy on mouse release unless a direct terminal is known to forward its native copy shortcut: Ghostty with a parsed version at least `1.2.0`, Kitty on macOS, Windows Terminal, or VS Code on Windows.
Unknown terminals and Ghostty with older, missing, or unrecognized versions now default to copying. Keep copying enabled under tmux/Zellij and preserve explicit `always` and `never` overrides. Update the configuration documentation and schema to describe these defaults.
## Testing
Expand the existing configuration test matrix to cover more terminals, Ghostty versions (including `1.2.0-dev`), platform-specific defaults, and multiplexer behavior alongside configuration and launch overrides.
GitOrigin-RevId: 410abfa580156454b0f88e0bf4ed977fb8c81b1e
## Why
Changes in executor availability can alter cloud skill catalog rendering under a shared budget and repeat an unchanged executor catalog when it reconnects.
## What changed
- Cap cloud skills at three quarters of the metadata budget initially, leaving the remaining budget and unused cloud allowance for filesystem skills. Reduce the cloud cap only when doing so allows all skill entries to fit; description truncation alone does not trigger rebalancing.
- Persist the allocation across disconnects, compaction, and thread resume. Recompute it when the cloud inventory or total budget changes.
- Emit a short availability update when an unchanged selected-environment catalog returns and its full text remains in history. Reinject the full catalog when that text is missing.
## Testing
Add coverage for allocation stability, catalog and budget changes, omission handling, and full catalog reinjection after compaction and resume. Extend the selected capability stack test to verify reconnection avoids repeating the catalog.
GitOrigin-RevId: 839fe98024e00c4082a46e6a40675e15fd2c16c6
## What changed
- Show a random tip beneath the working status after 30 seconds, using the existing tooltip catalog and current key bindings.
- Show completion tips only after successful turns with a final answer, starting with the third turn and spacing displayed tips by at least three turn starts. Limit completion tips to two per app session, and skip them when a working tip was already shown for that turn.
- Respect `tui.show_tooltips`, hide tips during composer or transcript interactions, and omit tips when space is insufficient. Count exposure only when a tip is rendered.
- Anchor completion tips after queued history updates, keep them outside transcript selection and search, and dismiss them on history replay or transcript clearing.
## Testing
Add lifecycle tests for timing, completion cadence, duplicate notifications, failed and interrupted turns, and hidden tips. Add rendering snapshots and assertions for completion ordering, resizing, limited terminal space, and exclusion from transcript selection and search.
GitOrigin-RevId: 9e956f5b0377e3be71f9574639c3c6ef11ad1168
## What changed
Print `To reconnect, run:` followed by the indented resume command on its own line in disconnect exit summaries. Update CLI expectations and TUI snapshots for the new layout, and adjust the remote reconnect test to parse the command from its new line.
GitOrigin-RevId: 46f05084482063cf4f196b3b49471f331bc91384