## Why
Concurrent tests can inherit writable descriptors for executable fixtures, causing `ETXTBSY` when those fixtures launch on Linux.
## What changed
Expose shared `write_executable` and `copy_executable` helpers from `codex_utils_cargo_bin` and adopt them in CLI, exec-server, and MCP tests. On Linux, writes and copies complete in separate processes so sibling test spawns cannot inherit the writable descriptors. Script fixtures receive mode `0o755`, and copied executables retain their source permissions.
Remove the executable-busy retry loop from the program resolver test now that its script uses the shared helper.
GitOrigin-RevId: 61624158190bb1e75c27d9eb9c87a2defc147fb7
## Why
Private IP destinations always bypassed inherited upstream proxies, preventing their use for private networks reachable through an upstream VPN proxy.
## What changed
- Add `codex exec-server --proxy-private-ips-via-upstream`, also configurable with `CODEX_EXEC_SERVER_PROXY_PRIVATE_IPS_VIA_UPSTREAM=true`. The setting defaults to disabled.
- Allow permitted RFC 1918, carrier-grade NAT, and IPv6 unique-local destinations to use an applicable upstream proxy. Loopback and link-local destinations retain direct routing, and destination access policy still applies.
- Keep connections direct when no valid upstream proxy applies or `allow_upstream_proxy=false`. Errors after selecting an upstream proxy do not trigger a direct retry.
- Rename `ExecServerRuntimePaths` to `ExecServerRuntimeOptions` and carry the routing setting from executor startup into the managed network proxy.
## Testing
Add routing coverage for private address ranges, special-use addresses, and public targets with the option enabled and disabled. Verify that HTTP and CONNECT requests still enforce destination allowlists and denylists, and update the CLI help snapshot.
GitOrigin-RevId: b7c9cc7da0e0f545694a6521b74c9b36b7b92769
## Why
Windows launchers such as `cargo run` can prevent background processes from outliving them, causing automatic daemon startup to fail and blocking the CLI from opening.
## What changed
- Classify detached launch restrictions by retrying an access-denied launch probe without the job breakaway flag. Keep both probes suspended and terminate and reap successful probes.
- Use the embedded server with a visible warning when automatic startup encounters this restriction. Preserve errors for other launch failures, including inaccessible executables and elevated startup.
- Keep explicit daemon lifecycle operations failing on the restriction, with guidance to build and run `codex.exe` directly.
## Testing
Add Windows coverage for restriction classification and executable access failures, plus a CLI integration test and warning snapshot for embedded fallback under a restrictive job. The integration test also checks that elevated startup still fails and no daemon PID file is created.
GitOrigin-RevId: fc7c46e0f5f07ca0aba12b535a0e372021bdf46a
## What changed
Print `To reconnect, run:` followed by the indented resume command on its own line in disconnect exit summaries. Update CLI expectations and TUI snapshots for the new layout, and adjust the remote reconnect test to parse the command from its new line.
GitOrigin-RevId: 46f05084482063cf4f196b3b49471f331bc91384
## Why
Sibling tests can spawn children while an executable fixture is open for
writing, allowing inherited writable descriptors to cause `ETXTBSY` when
launching the fixture.
## What changed
Add a shared `copy_executable` helper for the daemon, doctor path safety, and
exec-server tests. On Linux, run `/bin/cp` in a separate process and wait for
it to exit before launching the fixture, then restore the source permissions
to account for restrictive umasks. Keep `std::fs::copy` on other platforms.
GitOrigin-RevId: 88f36826bbc6ab4e16e28ff02d5e7d6bd8dbf793
## Why
When a container denies fresh `/proc` mounts, the existing sandbox fallback retains the caller's `/proc` while creating a new PID namespace. Process IDs inside the sandbox can then differ from those exposed by `/proc`, breaking process lookups.
## What changed
- Add `codex exec-server --linux-sandbox-pid-namespace=inherit` to reuse the caller's PID namespace and `/proc` for both process and filesystem helpers. Repository config and command environment variables cannot enable it.
- Keep `isolate` as the default, preserving the existing mount fallback and compatibility with older helpers. Inheritance requires an updated helper and omits `--unshare-pid` and `--as-pid-1`.
- Preserve other sandbox restrictions. With `:minimal`, bind the inherited `/proc` read-only with its container masks and apply explicit filesystem denials afterward.
Inheritance is intended for dedicated environments: it allows sandboxed commands to signal other same-UID processes, including the executor.
## Testing
Add unit and integration coverage for namespace flags, denied proc mounts, consistent process IDs, retained sandbox restrictions, and startup-only selection across process and filesystem helpers.
GitOrigin-RevId: dd13f2b9286d7edcf366b3a42a455f4d78daaf27
## What changed
- Recognize `flex_unavailable` in HTTP 429 responses and streamed `error` and `response.failed` events. End normal turns without retries and report `Flex capacity unavailable.`
- Expose `flexUnavailable` through the core and app-server protocols and generated schemas and SDK types.
- Keep Flex capacity failures eligible for Guardian review and sampler retries, with a distinct telemetry classification.
- Map unexpected HTTP responses to `HttpConnectionFailed`, preserving their status codes.
## Testing
Add regression coverage for terminal Flex failures over HTTP, SSE, and WebSocket, HTTP 504 status preservation after a stream retry, and protocol serialization. Update Guardian retry and sampler recovery tests to cover Flex failures.
GitOrigin-RevId: f2e03a6d2d36a6d9748c35952e40397f8670d121
## Why
Fixed schema budgets can strip parameter descriptions from large MCP tools or render their Code Mode input types as `unknown`. Allow larger budgets to preserve that guidance.
## What changed
- Add `mcp_servers.<name>.tool_input_schema_max_bytes` to configure the UTF-8 byte threshold for best-effort input schema compaction, retaining the 5,000-byte default.
- Add `features.code_mode.tool_input_schema_max_bytes` for rendered input types. Use the largest of the 16,000-byte default, the Code Mode setting, and the ordinary MCP server's explicit setting.
- Apply rendering budgets to prompt declarations and the runtime tool catalog, and avoid reusing cached declarations after the Code Mode budget changes.
## Testing
Add coverage for UTF-8 compaction thresholds, budget precedence, configuration round trips, and preservation of parameter guidance in both the Code Mode prompt and `ALL_TOOLS`.
GitOrigin-RevId: 0ef2823a614d4794e636f518b09c0b03a5239b45
## Why
Required MCP servers can block startup while establishing a live connection even when a usable tool catalog is already cached.
## What changed
- Add per-server `startup_readiness = "catalog"` to expose cached tools while the connection starts, retaining `"connection"` as the default.
- Allow an eligible cached catalog to satisfy required-server startup validation and model binding capture. Explicit server or plugin requirements still wait for a live connection, and tool execution still requires the current connection.
- Check tool filters and model visibility when accepting cached catalogs, and preserve cached catalog revisions for binding reuse.
- Serialize the new setting, expose it in the configuration schema, and trace startup readiness at validation and model binding gates.
GitOrigin-RevId: a1cbdf1757ebb5824cffe2cc56408be49711c422
## Why
MCP OAuth configuration supported a pre-registered client ID but could not supply a client secret for token exchange or refresh.
## What changed
- Add `oauth.client_secret` and `codex mcp add --oauth-client-secret`, requiring a nonempty secret and client ID. Persist the secret in server configuration and accept `clientSecret` in plugin configuration.
- Pass configured credentials through CLI, app-server, and plugin login flows and token refresh. Require a new login when a configured confidential client's ID differs from stored credentials.
- Redact secrets in debug output and keep them out of authorization URLs and persisted OAuth token records.
- Invalidate cached OAuth connections when the configured client ID or secret changes.
## Testing
Add coverage for configuration validation and round trips, CLI argument redaction and subsequent login, app-server login, connection invalidation, and refresh with `client_secret_basic` and `client_secret_post` in both refresh modes. Verify secret exclusion from token records and reject mismatched client IDs before contacting the provider.
GitOrigin-RevId: 85bb0e410e9e68e6cd68eb6359badfc7eac78147
## Why
Cold Rosetta translation and cache invalidation from hard-linked executables can interfere with timed CLI tests. Sampling the clock twice also makes local retry telemetry report a delay shorter than the selected backoff.
## What changed
- Warm CLI fixtures with `--version` on macOS x86_64 before timed checks, and use copies or Unix symlinks to avoid invalidating the shared executable's Rosetta cache.
- Use one clock sample to calculate the response retry deadline and recorded delay.
- Include the retry telemetry event in delay-range assertion failures for the headerless rate-limit stream test.
GitOrigin-RevId: fc573bfff912e999cf74b94a1c6e7ae1be07974b
## Why
Passing extra descriptors to a PTY previously selected behavior intended for inherited escalation sockets: no EOF on stdin close, different signal exit statuses, and no default `SHELL`. Launch attachments need ordinary PTY behavior and must survive execution even when marked `FD_CLOEXEC`.
## What changed
- Add `ChildFds::Attached` alongside `ChildFds::Inherited` to distinguish launch attachments from legacy inherited descriptors.
- Preserve ordinary EOF, default `SHELL`, and signal exit status behavior for PTY attachments.
- Allow explicitly supplied close-on-exec descriptors through pipe and PTY launches without changing the parent's descriptor flags, using child-side flag updates and macOS spawn inheritance actions.
- Update existing callers to use `ChildFds::Inherited`.
## Testing
Add Unix coverage for attachment accessibility, unchanged parent descriptor flags, default `SHELL`, and signal exit statuses. Extend the PTY stdin-draining test to cover attachments and EOF delivery.
GitOrigin-RevId: 864aedc6c5717d8b43c9d71057c9f54409834509
## Why
App-server clients need a way to connect to executors that require bearer authentication through `environment/add` and `environments.toml`.
## What changed
- Add optional `authBearerToken` to `environment/add` and `auth_bearer_token` to URL entries in `environments.toml`.
- Send the token as an `Authorization: Bearer` header on initial connections and reconnects, without automatic refresh. Require `wss://` or a loopback destination when a token is supplied.
- Redact tokens in debug output, mark connection headers sensitive, and omit source text from TOML parse errors.
- Preserve unauthenticated behavior when tokens are omitted, including requests with a null `authBearerToken`.
## Testing
Add integration coverage for authenticated and unauthenticated executors through both RPC and TOML configuration, including missing, null, incorrect, and malformed RPC tokens. Extend tests for reconnect authorization headers, token redaction, URL-only token configuration, and timeout preservation.
GitOrigin-RevId: 2a5d48a1846df1720e4a9b295968348378c287c6
## Why
HTTP retries used local backoff even when the server supplied `Retry-After`. Relative retry delays also failed to account for time spent propagating errors or reporting retries.
## What changed
- Parse `Retry-After` delay seconds and HTTP dates into a monotonic deadline captured when response headers arrive.
- Honor that deadline for HTTP retries, falling back to local backoff when valid advice is absent.
- Preserve deadlines through API and Bedrock error mapping, stream retries, and exhausted retry state. Expired advice remains a zero delay instead of triggering local backoff.
## Testing
Add coverage for header parsing, deadline countdown and expiry, error mapping after exhausted HTTP retries, and delayed stream retry notifications. Update Responses and remote compaction tests to verify that HTTP retries honor `Retry-After`.
GitOrigin-RevId: a2eff02946e5524f29e06f7ba1431e3d339261a4
## What changed
Expose the shared `--ws-auth` options on `codex exec-server` for direct WebSocket listeners. Support capability tokens configured by token file or SHA-256 digest, and signed JWT bearer tokens. Validate `Authorization: Bearer TOKEN` before each WebSocket upgrade, rejecting missing or invalid credentials with HTTP 401 when authentication is enabled.
Reject listener authentication with stdio, `--remote`, or `forward`. Document the options and connection-time authentication behavior.
## Testing
Add CLI integration tests for all three credential configurations, unauthorized upgrade rejection, authenticated RPC initialization and reconnects, invalid configuration, and incompatible transports.
GitOrigin-RevId: 941fbd3d43e732c910d29b6f8137077b7c332835
## What changed
Move WebSocket authentication arguments, settings, credential loading, and upgrade authorization into a shared crate using `http` types. Update the app server, transport, and CLI to consume it directly, and remove the `AppServer` prefix from the shared types.
Hide token digests and JWT verification secrets from authentication policy `Debug` output.
## Testing
Move the existing argument validation, capability-token authorization, and signed bearer-token verification tests into the new crate.
GitOrigin-RevId: 1dd20043a3f8efbca55af7eda338b62a62e8fd68
## Why
AWS credential discovery, analytics, and telemetry used clients that did not share the application's network policy. These requests need to honor destination restrictions and permission revocation.
## What changed
- Route AWS credential and region HTTP requests through the shared HTTP client, and check the signing destination before loading credentials. Skip discovery for static access keys with an explicit region.
- Apply account-scoped policy to Bedrock authentication. Require unrestricted policy for credential exporters and reauthentication commands, and cancel active work when permission is revoked. Document that AWS profile `credential_process` network traffic remains outside the application's HTTP policy.
- Send analytics through the authenticated account's HTTP client factory.
- Guard OTLP log, trace, and metric exports with revocable permits, disable them under destination restrictions, and make managed HTTP exports cancellable. Suppress global Statsig settings while managed policy is active.
## Testing
Add coverage for metadata credential request cancellation, allowed and denied SigV4 destinations, AWS credential precedence and endpoint configuration, and blocked credential exporter recovery. Update telemetry tests for account transitions and managed-policy Statsig suppression.
GitOrigin-RevId: d8a2018bfbbe971ec430699b0d3f86a7a9e1e072
## Why
Destination restrictions and policy revocation must remain effective during redirects, response body reads, and established WebSocket traffic. Policy denials must also survive error handling so callers do not retry them or report a revoked operation as successful.
## What changed
- Route managed HTTP clients through a shared `RequestBuilder` and policy-aware execution, checking each redirect destination before route resolution and retaining a network permit while consuming response bodies.
- Guard WebSocket connection setup, reads, and writes with revocable permits, including independent wakeups for split readers and writers.
- Preserve `TransportError::Policy` through HTTP, SSE, and realtime error handling, and treat policy denials as non-retryable.
- Keep the supplied network policy in plugin startup HTTP requests and propagate response body failures from backend and plugin requests.
## Testing
Add regression coverage for rejection before connecting, revocation during redirect routing and streamed body reads, split WebSocket revocation, realtime writer error propagation, and revoked plugin upload responses.
GitOrigin-RevId: fba36700444c98a8364c09b4dc5452c4d78a90fb
## What changed
Add the default-off `features.prefer_mxc` flag to select MXC for local Windows execution when native support is available and effective network settings do not explicitly forbid local binding. Otherwise, retain the configured backend and legacy setup behavior.
Resolve the preference during config loading and use the effective local backend for execution, network proxy setup, sandbox diagnostics, and `windowsSandbox/readiness`. Preserve the configured backend for remote executors and `config/read`. Explicit `windows.sandbox = "mxc"` remains strict, and command failures do not trigger backend fallback.
## Testing
Add coverage for preference resolution, startup readiness without rewriting configuration, local and remote backend selection across environment updates and child threads, and workspace-write permission context in an agent turn.
GitOrigin-RevId: b51178f0371d38ebb58e41af54a068fca67fa316
## What changed
Highlight recognized paths and URLs in check descriptions and details in red for failed checks and cyan otherwise. Extend path recognition on Windows to drive-absolute, UNC, Win32, and NT DOS paths.
## Testing
Add Windows and non-Windows color snapshots covering successful, warning, and failed checks, punctuation, and backtick-quoted paths with spaces. Assert that descriptions and details remain unchanged when color is disabled.
GitOrigin-RevId: e8f9982505aa155fd312b12f91a71271effeb35e
## Why
`invalid_prompt` responses were classified as generic invalid requests, losing the server's specific error classification.
## What changed
Add `InvalidPrompt` variants to the API and core error types and serialize the core protocol classification as `invalid_prompt`. Recognize the code in HTTP 400 responses, wrapped WebSocket errors, and SSE `response.failed` events while preserving server messages and keeping the error non-retryable. Map it to `other` in the app-server v2 protocol.
## Testing
Extend coverage for typed error mapping, missing and blank messages, protocol conversion, and guardian retry handling. Exercise HTTP and SSE failures in core integration tests, asserting the error message, serialized classification, and a single request without retry.
GitOrigin-RevId: 5d9a299a013b06158a4dc27a4054f3dbc5fd0f4d
## What changed
- Add `gpt-6-sol` and `gpt-6-luna` catalog entries and refresh model descriptions.
- Offer migrations from `gpt-5.5`, `gpt-5.6-sol`, and `gpt-5.6-terra` to `gpt-6-sol`, and from `gpt-5.6-luna` to `gpt-6-luna`.
- Retarget retired `gpt-5.4` and `gpt-5.4-mini` selections to GPT-6 Sol and Luna, respectively.
- Recommend `gpt-6-luna` in the rate-limit switch prompt.
## Testing
Extend migration tests to cover the new targets, their default reasoning effort, and prompting again after a previously acknowledged migration to an older target. Update model-picker and rate-limit prompt snapshots.
GitOrigin-RevId: d3a093d18ce44a903383504ab8f5cbbc911d602d
## Why
The generic state integrity failure message does not identify which database needs attention.
## What changed
- Include the paths of all databases that fail integrity checks in a structured issue, shown in text summaries and JSON output, with the existing recovery guidance.
- Redact sensitive details using `: ` as the field-label separator so Windows drive letters are not mistaken for labels and unlabeled sensitive paths are fully redacted.
## Testing
Add coverage for single and multiple failed databases, summary and detailed text output, JSON output, preservation of damaged database contents, and sensitive path redaction on Unix and Windows.
GitOrigin-RevId: ac5fec9473d22b6b137a9fc8a751aba8605d940f
## Why
Automatic daemon launches could silently fall back to embedded mode when shared feature settings differed from the session's requirements. Changing those settings affects other clients, and restarting the server may interrupt active or queued work.
## What changed
- Offer interactive choices to run without the daemon, restart with the required settings, or cancel. Default to cancel and require explicit confirmation for restart.
- Allow restart only for managed daemons with a feature mismatch, then recheck compatibility once. Noninteractive required-daemon failures return an error with `--no-daemon` guidance; optional attachment retains its fallback behavior.
- Preserve saved feature overrides on startup and require confirmation before applying requested shared-feature disables, including on fresh starts.
- Merge confirmed settings under the lifecycle lock, persist changes after the old process stops, and avoid restarting when the saved overrides already match.
## Testing
Add recovery-menu snapshots and confirmation tests, compatibility tests for required and optional attachment, daemon ownership and settings-preservation tests, and CLI terminal tests for cancellation, embedded fallback, confirmed restart, and disabling shared features.
GitOrigin-RevId: d50a6cf7e476b9647237431e8fc0fc6041ed17db
## What changed
Promote `daemon_auto_start` to stable and enable it by default for eligible interactive launches. Remove its entry from `/experimental`.
## Testing
Update daemon startup, `--no-daemon`, and startup failure tests to exercise the default without explicitly enabling the feature. Disable daemon startup in unrelated TUI and path-safety test fixtures.
GitOrigin-RevId: 107d71108b96d09431148d7d61f10c6381929e05
## What changed
Move `codex exec-server` argument definitions, transport validation, configuration loading, authentication, and shutdown orchestration from `codex-rs/cli/src/main.rs` into `codex-rs/cli/src/exec_server_command.rs`.
Expose startup through `ExecServerCommand::run`, merge the root `--strict-config` flag into the command before dispatch, and update existing argument tests to use the new entry point.
GitOrigin-RevId: 4bcc59db2bd6e1d153a366142bd0b93ad03c6951
## Why
Remote plugin requests always sent `OAI-Product-Sku: codex`, ignoring the existing `apps_mcp_product_sku` setting.
## What changed
Pass `apps_mcp_product_sku` through plugin configuration and use it for authenticated remote plugin requests, including discovery, search, installation, and sharing. Keep `codex` as the default and include the SKU when comparing remote service configurations.
## Testing
Extend app-server plugin listing and core agent-turn tests to check default and configured SKU headers. Update the CLI worktree test to wait for the user prompt's model request, skipping background title generation requests.
GitOrigin-RevId: 508c9ef9aa3e41b87c92383c3088eb1eb9227fd8
## What changed
- Replace the built-in orchestrator skill provider with a host-supplied cloud provider, using `cloud` authority and `c` root aliases in skill tools and prompts.
- Add `cloud.skills.enabled`, defaulting to true but requiring a supplied provider. Keep `orchestrator.skills` accepted as a legacy no-op setting, and remove the app server's automatic orchestrator provider registration.
- Discover cloud skills once per turn during cancellable startup. Serve catalog snapshots to prompts and tools without triggering discovery or retries.
- Scope cached catalogs and resources to authentication state. Preserve them on refresh failures within the same scope, invalidate them when that scope changes, and reject late discovery or read results from replaced cache generations.
- Reuse executor discovery catalogs only when successful discovery inputs and bundled-skill settings match.
## Testing
Add coverage for per-turn refresh, skill removal, same-account failures and reconnects, authentication changes, and stale in-flight results. Update configuration and tool tests for cloud authority, provider gating, and resource reads without an executor.
GitOrigin-RevId: c57e38ec7dcc880c0d4c8a2995adfd3e28301079
macOS temporary directories can use symlinked paths. Use `project_trust_key`
in `doctor_reports_only_safe_config_error_metadata` so the fixture trusts the
canonical workspace when testing project configuration errors.
GitOrigin-RevId: 61b15e4cfc2eaa8d258b51a482decc0b9bd684e9
## Why
Configuration load errors can echo configuration values, including credentials, into diagnostic reports.
## What changed
Replace raw error messages in `config.load` failures with typed metadata. Report the file, line, and column when a `ConfigLoadError` is available, including when wrapped in an I/O error. Otherwise, report only the I/O error kind or a generic configuration load failure.
## Testing
Add regression tests and snapshots for malformed user and project configuration, an unknown model provider, and invalid header configuration. Verify that both tested JSON reporting modes omit the test credentials while retaining the expected failure details.
GitOrigin-RevId: bec53313888dbfc8c0869f3cb410b1c3e5496630
## What changed
Rename the `/status` connection row from `Remote` to `Server`. For local daemon connections, display `Local background server` instead of the socket address and version. Keep the address and version for remote connections, including explicitly configured Unix sockets.
## Testing
Add a local background server snapshot and coverage distinguishing local daemon connections from remote Unix sockets. Update daemon startup and worktree tests to expect the new label.
GitOrigin-RevId: 9460415fe1ec16d90f575917c1a4ce1bf19faaaf
## What changed
Use `tui.fullscreen_transcript` to opt into the fullscreen transcript, including scrolling, selection, and search. It defaults to `false`; `--no-alt-screen` and `tui.alternate_screen = "never"` still take precedence.
The new preference controls both the first frame and application startup. Boolean CLI overrides for it are allowed during daemon startup. The old `features.transcript_v2` flag is deprecated and ignored, with a notice directing users to the new setting; it does not migrate into or override the preference.
## Testing
Add coverage for default terminal scrollback, fullscreen persistence through startup, alternate-screen restrictions, daemon override validation, and independence from the deprecated flag. Update existing history and activity tests to use the new preference.
GitOrigin-RevId: 4117bf1ee548fa8d101a594f9506673d87c74c15
## What changed
- Render transcript history and live output above the composer when `features.transcript_v2` is enabled and alternate-screen rendering is available. Handle scrolling, selection, copying, links, and older-history pagination in the main view.
- Add a clickable return-to-latest control with new-activity hints and temporary clipboard status. Let plain Enter return to latest when the composer is empty.
- Reflow retained transcript content during drawing and preserve the launch-selected screen mode across configuration reloads and session transitions, including `--no-alt-screen` restrictions.
- Enter the alternate screen with its first synchronized frame, and box CLI startup futures to reduce stack usage during session transitions.
## Testing
Add regression coverage for transcript layout, input routing, follow controls, clipboard status, and screen-mode persistence. Add a PTY test for the first alternate-screen frame and clean exit, and extend session-transition coverage through the CLI dispatcher.
GitOrigin-RevId: 1daf077826c7744b0f57399d10d159923dc87a97
## What changed
- Remove the private-desktop opt-out from elevated and unelevated Windows sandbox launches.
- Remove `windows.sandbox_private_desktop` and its managed requirement and API fields. Warn users to remove the obsolete setting.
- Require a private desktop name when launching through the Windows sandbox wrapper and command runner.
## Testing
Add coverage for the obsolete-setting migration warning and update wrapper tests to verify a live private desktop is passed and a missing desktop name is rejected.
GitOrigin-RevId: c7135f8d211aac8d812180691c2c1e433d77cde4
## Why
Configured filesystem paths can be slow or inaccessible. Doctor needs to identify those paths and their configuration sources without letting a blocked filesystem call delay runtime shutdown.
## What changed
- Add `sandbox.filesystem_paths` to report literal filesystem grants, access modes, resolution outcomes, and configuration sources when available. Exclude deny rules and denied paths without expanding globs or special paths.
- Resolve paths in disposable helper processes, with wait budgets of two seconds per path and eight seconds total, checking at most 32 paths. Warn on slow or unsuccessful probes and incomplete checks; missing paths alone do not trigger warnings. Probes do not test read/write access.
- List paths without probing on Windows or when filesystem read restrictions apply.
- Increase the app-server doctor report timeout from 25 to 35 seconds to accommodate the probes.
## Testing
Add unit and integration coverage for path deduplication and deny filtering, configuration provenance, blocked-helper timeouts, helper execution without loading configuration, and report snapshots for resolved, missing, Windows, and read-restricted paths.
GitOrigin-RevId: b0732265fc2c83ea67acc24b442e39139d705f1b
## Why
Feature overrides previously forced embedded mode even when they could work with the shared daemon. A running daemon can also have different feature settings from the current invocation, including when the invocation uses defaults.
## What changed
- Allow selected Boolean feature overrides and `suppress_unstable_features_warning` in daemon mode. Keep explicit overrides that disable shared services in embedded mode.
- Pass shared-service feature overrides to newly launched daemons and persist them for restarts and updates without changing a running daemon's settings.
- Check daemon feature settings with `experimentalFeature/list` before attaching. Warn and fall back to embedded mode on mismatches, failed checks, or an incompatible code-mode host fallback policy. Skip this check for the agents overview.
- Resolve worktree configuration before daemon selection and allow worktree sessions to auto-start the daemon.
- Forward `suppress_unstable_features_warning` in thread configuration overrides.
## Testing
Add coverage for override eligibility and precedence, launch-feature persistence and reuse, and TUI fallback warnings for feature and host-policy mismatches. Extend worktree integration coverage to exercise daemon auto-start and warning suppression.
GitOrigin-RevId: 68c316f74843b1dfd8fa39bdb48bd1f649fee57f
## Why
Freshly copied executables can briefly remain busy on Linux CI workers, causing packaged daemon tests to fail at launch.
## What changed
Retry the command launch in `packaged_daemon_launch` up to twice on `std::io::ErrorKind::ExecutableFileBusy`, waiting 10 ms between attempts. Other launch errors still propagate immediately.
GitOrigin-RevId: afb6213173a7ae4bcfe2e1e6fab6ced65ab5bf77
## Why
MXC's native host-loopback access is bidirectional, so it cannot enforce `allow_local_binding = false`. Treating an omitted setting as `false` prevents managed networking from working with the default configuration.
## What changed
- Preserve an omitted `allow_local_binding` until the executor's sandbox policy is known. Default to `true` for Windows MXC and `false` elsewhere, including remote execution.
- Reject an effective `false` for MXC managed networking after applying policy restrictions, without enabling disabled networking.
- Use the executor's resolved value for remote network approval decisions while preserving explicit controller restrictions.
- Document that local binding permits local servers and direct host-loopback connections and skips additional private-network destination checks; proxy domain rules still apply.
## Testing
Add coverage for per-executor defaults, explicit values, MXC rejection of `false`, and remote network review cleanup with the resolved policy.
GitOrigin-RevId: 0fa7c1eaec68bebada2b8f7af45688315eea70a9
## Why
Model pickers and session details show raw model IDs even when the catalog provides a display name.
## What changed
- Use catalog display names in model and reasoning pickers, session headers, status displays, and terminal titles, retaining fallback labels for models absent from the catalog.
- Keep model IDs for selection and persistence, and preserve picker highlights by ID when display names change or are shared by multiple models.
- Remove the legacy-model instruction from the full model picker.
## Testing
Add regression tests and snapshots for custom display names, startup and resumed session headers, fallback labels, terminal titles, and picker refreshes. Verify that selecting a display name still persists the original model ID.
GitOrigin-RevId: 101fe82b20f7a8a90ceeff7999bd07ad42ca46db
## Why
`--worktree` and command-line worktree feature overrides previously excluded sessions from using the local daemon, even though worktree allocation is client-owned and thread requests already forward the feature.
## What changed
- Allow `--worktree` and boolean `features.worktrees` overrides to remain eligible for daemon connections, while preserving exclusions for other configuration overrides and `--no-daemon`.
- Skip daemon auto-start for `--worktree` launches.
## Testing
Add daemon eligibility tests for worktree options and overrides. Run the existing worktree startup and fork test scenarios against both embedded and daemon backends, checking ownership before the first turn and confirming daemon connections through `/status`.
GitOrigin-RevId: b3f4782e83d8e20974fb4a831442cae013d58e56
## Why
Workspace paths from the client configuration belong to the client host. Sending them to a remote app server can override the server's workspace roots.
## What changed
- Omit client-configured `runtimeWorkspaceRoots` from remote start, resume, and fork requests so the server resolves defaults or restores saved roots.
- Preserve server-provided roots when forking an active session or side conversation, including after reloading client configuration.
- Reject `--add-dir` and `sandbox_workspace_write.writable_roots` command-line overrides with `--remote` before connecting, directing users to configure additional roots on the server.
## Testing
Add regression coverage for remote workspace roots across start, turn, resume, and fork operations; active-session forks after configuration reloads; and embedded requests retaining explicit roots. CLI tests cover rejected root overrides and continued acceptance of network-access overrides.
GitOrigin-RevId: b87ea6037d197db68e25a1a8610d693f6aa13caf
## Why
Streaming `bio_policy` failures were classified as generic invalid requests, losing their policy-specific classification.
## What changed
- Add `BioPolicy` errors across the API and core protocol, recognizing streaming failures and HTTP 400 responses, including wrapped WebSocket errors.
- Preserve server messages and use a biological-risk fallback when the message is missing or blank.
- Treat bio policy errors as non-retryable in core and guardian handling, and classify them in diagnostics and telemetry.
- Map `BioPolicy` to `other` in the app-server v2 protocol.
## Testing
Add coverage for error classification, message preservation and fallbacks, HTTP and wrapped WebSocket responses, guardian retry decisions, and app-server conversion. Extend the core integration test to verify that bio policy failures emit a typed error and complete the turn after a single request.
GitOrigin-RevId: 78c2647e8fc8f80297cb8a23fff06ab141099632
## What changed
- Accept `windows.sandbox = "mxc"` and preserve the selected backend through environment configuration, command execution, patch writes, and sandbox metadata.
- Treat MXC as enabled in the TUI and report Windows sandbox readiness as `ready`, avoiding legacy setup prompts.
- Keep `allowed_sandbox_implementations` scoped to the legacy elevated and unelevated backends without restricting MXC.
- Default `windows.sandbox_private_desktop` to `false` for MXC while retaining `true` for legacy sandboxes.
## Testing
Add coverage for MXC configuration precedence, legacy requirement handling, sandbox selection, and TUI state. Add a Wine integration test that verifies command and patch routing fails when native MXC is unavailable and reports `windows_mxc` in turn metadata.
GitOrigin-RevId: e2162447d0750f60753864c92a20e02a7f297bca
## Why
TUI startup metrics report the selected app-server mode before a connection succeeds, which can misrepresent embedded fallback or failed startup. Daemon startup and update actions also need distinct outcome observations.
## What changed
- Record `codex.tui.start` once after the first connection attempt, using the actual mode or `unconfirmed`, and include daemon selection and auto-start tags.
- Add `codex.daemon.start` for TUI auto-start and `codex.daemon.update` for foreground CLI updates and TUI update handoffs, using existing analytics consent and identity handling.
- Report TUI handoffs as `handoff_requested` and suppress duplicate child reporting. Remove the suppression flag when spawning long-lived daemon processes.
- Tag daemon settings by enabled state and explicit presence, without exporting setting values or contents; report invalid or unreadable settings as `unknown`.
## Testing
Add coverage for analytics defaults and explicit consent overrides, unconfirmed CLI updates, settings presence, and exactly-once launch observations. Extend the worktree TUI test to check startup tags and a single update handoff observation.
GitOrigin-RevId: 176d2ee594f930033fa1ece55d4c1c9603dbbc16
## What changed
- Add `features.daemon_auto_start`, disabled by default and available through `/experimental`, to start the shared local server for eligible new, resumed, and forked sessions. Changes take effect on the next launch, and disabling the feature persists an explicit `false`.
- Require successful daemon startup and connection when auto-start applies. On failure, show guidance to rerun the same command with `--no-daemon` instead of silently falling back to an embedded server.
- Preserve embedded mode for excluded launches, including Bedrock sign-in, and carry exclusion warnings through resume and fork pickers. Honor `--no-daemon` without an exclusion warning.
- Update `/import` guidance to recommend restarting with `codex --no-daemon`.
## Testing
Add CLI and TUI coverage for automatic daemon attachment, startup and connection failures, `--no-daemon`, picker warning persistence, and Bedrock onboarding with and without a running daemon. Add snapshots and configuration-write assertions for the experimental toggle.
GitOrigin-RevId: 2e8eb163bc7ddd268a86c7546c05a85356c1e9ee
## Why
Older Desktop clients can still provide bundled Sites to an independently updated SSH app-server. A cached remote Sites install must take precedence, even when disabled, while a missing remote bundle must preserve the bundled fallback.
## What changed
- Remove persisted bundled-plugin exclusions, Sites migration checks, and the migration wait when loading local plugin configuration.
- Suppress `sites@openai-bundled` during plugin loading when the remote global catalog is active and a cached remote Sites install is available.
- Remove exclusion-based catalog filtering and read/install guards, and simplify `install_plugin` to accept `ConfigLayerStack`.
## Testing
Expand the agent-turn Sites test to cover enabled remote precedence, disabled remote suppression of bundled Sites, and fallback when the remote bundle is missing.
GitOrigin-RevId: e2758596e5493ccee051cdfbf6b4afbe4f98948c
## What changed
- Run with `--no-daemon` without starting or probing the shared server, even when it is already running. Preserve the flag through `resume` and `fork`, and honor it for session archive commands.
- Reject combinations with `--remote`, `codex agents`, and `codex queue`, which require a server connection. Point users to `codex --no-daemon` when the agents overview cannot start its shared server.
- Centralize daemon eligibility checks and exclude launches using `--profile` or `CODEX_EXEC_SERVER_URL` from implicit daemon reuse.
## Testing
Add coverage for flag propagation, incompatible command combinations, and daemon eligibility. Add a PTY test verifying that `--no-daemon` starts the TUI without creating daemon state or connecting to an existing control socket.
GitOrigin-RevId: acc6a7cb339df6433bb8273c796194cdceda37c1
## What changed
Add `codex tcp-tunnel` and the `codex-tcp-tunnel` crate to forward loopback TCP connections to an explicit target through a TLS-verified HTTP/3 CONNECT proxy.
- Require the proxy origin to match an approved HTTPS origin in a supplied policy file.
- Read bearer tokens and optional bounded, non-forwarding `x-` headers from stdin. Support token updates for new connections, `LISTENING` and `AUTH_UPDATED` notifications, and shutdown when the control pipe closes in token-update mode.
- Preserve the listener across proxy reconnects without replaying TCP streams, and let accepted streams continue while a proxy drains.
## Testing
Add tests for hidden CLI parsing, proxy and target validation, credential renewal, control-pipe closure, and invalid input without secret disclosure. A local HTTP/3 proxy test covers token replacement, transport recovery without stream replay, and graceful draining.
GitOrigin-RevId: c6af3025301c61e9fe90940cf5a6df0039465e69
## Why
Executor profile roots can use path conventions that are not native to the current host. Converting them to host paths during configuration or turn reconstruction can reject or drop those roots, while case-insensitive comparison can hide Windows path spelling changes.
## What changed
- Store profile roots as URI-backed `ProfileWorkspaceRoot` values throughout permission snapshots and thread settings, preserving spelling in equality and deduplication.
- Keep effective workspace roots as `PathUri` values for permission materialization and status summaries. Convert Windows sandbox root hints to native paths only at native Windows sandbox boundaries, rejecting incompatible roots.
- Omit the legacy rollout `workspace_roots` field when profile roots cannot be represented as host paths, retaining the compiled permission profile.
## Testing
Add regression coverage for Windows and UNC root spelling changes, settings restoration and turn recording with foreign roots, executor-root status display, and backend-specific Windows root conversion.
GitOrigin-RevId: 903c068fd74959bdd10e7cb1141aa42b953a59a4
## Why
Local daemon version warnings direct users to a shell command. Provide an update flow from the TUI with an explicit choice of package source and confirmation before exiting.
## What changed
- Add `/daemon` with options to install the latest public stable release or use the current CLI package. Point local server version notices to the menu.
- Default confirmation to Cancel and explain restart, interruption, and relaunch behavior. After confirmation, exit the TUI and run the update through the launching CLI executable, propagating failures.
- Keep maintenance available when disconnected or using the embedded server. Disable updates for remote connections or a missing CLI executable, and disable copying the CLI build when no local package is available.
## Testing
Add menu snapshots and interaction tests covering both update sources, cancellation, and unavailable actions. Add a Unix CLI handoff test verifying the selected executable, command arguments, and failure propagation.
GitOrigin-RevId: 06b485feb5650673ec7dd00adda01fedb8909393