635 Commits
Author SHA1 Message Date
jif 18344a972d Centralize executable fixture creation to avoid Linux ETXTBSY races (#48727)
## Why

Concurrent tests can inherit writable descriptors for executable fixtures, causing `ETXTBSY` when those fixtures launch on Linux.

## What changed

Expose shared `write_executable` and `copy_executable` helpers from `codex_utils_cargo_bin` and adopt them in CLI, exec-server, and MCP tests. On Linux, writes and copies complete in separate processes so sibling test spawns cannot inherit the writable descriptors. Script fixtures receive mode `0o755`, and copied executables retain their source permissions.

Remove the executable-busy retry loop from the program resolver test now that its script uses the shared helper.

GitOrigin-RevId: 61624158190bb1e75c27d9eb9c87a2defc147fb7
2026-09-27 15:25:13 +00:00
open-matt b8d5e3f12e Allow exec-server to proxy permitted private IPs upstream (#48568)
## Why

Private IP destinations always bypassed inherited upstream proxies, preventing their use for private networks reachable through an upstream VPN proxy.

## What changed

- Add `codex exec-server --proxy-private-ips-via-upstream`, also configurable with `CODEX_EXEC_SERVER_PROXY_PRIVATE_IPS_VIA_UPSTREAM=true`. The setting defaults to disabled.
- Allow permitted RFC 1918, carrier-grade NAT, and IPv6 unique-local destinations to use an applicable upstream proxy. Loopback and link-local destinations retain direct routing, and destination access policy still applies.
- Keep connections direct when no valid upstream proxy applies or `allow_upstream_proxy=false`. Errors after selecting an upstream proxy do not trigger a direct retry.
- Rename `ExecServerRuntimePaths` to `ExecServerRuntimeOptions` and carry the routing setting from executor startup into the managed network proxy.

## Testing

Add routing coverage for private address ranges, special-use addresses, and public targets with the option enabled and disabled. Verify that HTTP and CONNECT requests still enforce destination allowlists and denylists, and update the CLI help snapshot.

GitOrigin-RevId: b7c9cc7da0e0f545694a6521b74c9b36b7b92769
2026-09-26 23:17:41 +00:00
Felipe Coury a6bd19261c Fall back to embedded mode under restrictive Windows launchers (#48491)
## Why

Windows launchers such as `cargo run` can prevent background processes from outliving them, causing automatic daemon startup to fail and blocking the CLI from opening.

## What changed

- Classify detached launch restrictions by retrying an access-denied launch probe without the job breakaway flag. Keep both probes suspended and terminate and reap successful probes.
- Use the embedded server with a visible warning when automatic startup encounters this restriction. Preserve errors for other launch failures, including inaccessible executables and elevated startup.
- Keep explicit daemon lifecycle operations failing on the restriction, with guidance to build and run `codex.exe` directly.

## Testing

Add Windows coverage for restriction classification and executable access failures, plus a CLI integration test and warning snapshot for embedded fallback under a restrictive job. The integration test also checks that elevated startup still fails and no daemon PID file is created.

GitOrigin-RevId: fc7c46e0f5f07ca0aba12b535a0e372021bdf46a
2026-09-26 17:31:48 +00:00
Eric Traut 09a3d2108f Display reconnect commands on a separate line (#48350)
## What changed

Print `To reconnect, run:` followed by the indented resume command on its own line in disconnect exit summaries. Update CLI expectations and TUI snapshots for the new layout, and adjust the remote reconnect test to parse the command from its new line.

GitOrigin-RevId: 46f05084482063cf4f196b3b49471f331bc91384
2026-09-26 04:09:02 +00:00
jif 58670eeac4 Isolate executable fixture copies in CLI tests on Linux (#48213)
## Why

Sibling tests can spawn children while an executable fixture is open for
writing, allowing inherited writable descriptors to cause `ETXTBSY` when
launching the fixture.

## What changed

Add a shared `copy_executable` helper for the daemon, doctor path safety, and
exec-server tests. On Linux, run `/bin/cp` in a separate process and wait for
it to exit before launching the fixture, then restore the source permissions
to account for restrictive umasks. Keep `std::fs::copy` on other platforms.

GitOrigin-RevId: 88f36826bbc6ab4e16e28ff02d5e7d6bd8dbf793
2026-09-25 20:54:31 +00:00
open-matt aa380897f6 Add startup-only PID namespace inheritance to exec-server (#47989)
## Why

When a container denies fresh `/proc` mounts, the existing sandbox fallback retains the caller's `/proc` while creating a new PID namespace. Process IDs inside the sandbox can then differ from those exposed by `/proc`, breaking process lookups.

## What changed

- Add `codex exec-server --linux-sandbox-pid-namespace=inherit` to reuse the caller's PID namespace and `/proc` for both process and filesystem helpers. Repository config and command environment variables cannot enable it.
- Keep `isolate` as the default, preserving the existing mount fallback and compatibility with older helpers. Inheritance requires an updated helper and omits `--unshare-pid` and `--as-pid-1`.
- Preserve other sandbox restrictions. With `:minimal`, bind the inherited `/proc` read-only with its container masks and apply explicit filesystem denials afterward.

Inheritance is intended for dedicated environments: it allows sandboxed commands to signal other same-UID processes, including the executor.

## Testing

Add unit and integration coverage for namespace flags, denied proc mounts, consistent process IDs, retained sandbox restrictions, and startup-only selection across process and filesystem helpers.

GitOrigin-RevId: dd13f2b9286d7edcf366b3a42a455f4d78daaf27
2026-09-25 03:12:10 +00:00
Steve Coffey dafb133c5b Surface Flex capacity failures as a distinct terminal error (#47967)
## What changed

- Recognize `flex_unavailable` in HTTP 429 responses and streamed `error` and `response.failed` events. End normal turns without retries and report `Flex capacity unavailable.`
- Expose `flexUnavailable` through the core and app-server protocols and generated schemas and SDK types.
- Keep Flex capacity failures eligible for Guardian review and sampler retries, with a distinct telemetry classification.
- Map unexpected HTTP responses to `HttpConnectionFailed`, preserving their status codes.

## Testing

Add regression coverage for terminal Flex failures over HTTP, SSE, and WebSocket, HTTP 504 status preservation after a stream retry, and protocol serialization. Update Guardian retry and sampler recovery tests to cover Flex failures.

GitOrigin-RevId: f2e03a6d2d36a6d9748c35952e40397f8670d121
2026-09-24 23:33:38 +00:00
Vivian Fang 339e981ba7 Make MCP and Code Mode input schema budgets configurable (#47936)
## Why

Fixed schema budgets can strip parameter descriptions from large MCP tools or render their Code Mode input types as `unknown`. Allow larger budgets to preserve that guidance.

## What changed

- Add `mcp_servers.<name>.tool_input_schema_max_bytes` to configure the UTF-8 byte threshold for best-effort input schema compaction, retaining the 5,000-byte default.
- Add `features.code_mode.tool_input_schema_max_bytes` for rendered input types. Use the largest of the 16,000-byte default, the Code Mode setting, and the ordinary MCP server's explicit setting.
- Apply rendering budgets to prompt declarations and the runtime tool catalog, and avoid reusing cached declarations after the Code Mode budget changes.

## Testing

Add coverage for UTF-8 compaction thresholds, budget precedence, configuration round trips, and preservation of parameter guidance in both the Code Mode prompt and `ALL_TOOLS`.

GitOrigin-RevId: 0ef2823a614d4794e636f518b09c0b03a5239b45
2026-09-24 20:39:37 +00:00
Henry Levy b62fcd3c4b Allow cached catalogs to satisfy MCP startup readiness (#47935)
## Why

Required MCP servers can block startup while establishing a live connection even when a usable tool catalog is already cached.

## What changed

- Add per-server `startup_readiness = "catalog"` to expose cached tools while the connection starts, retaining `"connection"` as the default.
- Allow an eligible cached catalog to satisfy required-server startup validation and model binding capture. Explicit server or plugin requirements still wait for a live connection, and tool execution still requires the current connection.
- Check tool filters and model visibility when accepting cached catalogs, and preserve cached catalog revisions for binding reuse.
- Serialize the new setting, expose it in the configuration schema, and trace startup readiness at validation and model binding gates.

GitOrigin-RevId: a1cbdf1757ebb5824cffe2cc56408be49711c422
2026-09-24 20:38:50 +00:00
willwang-openai 83b56bc5ad Support client secrets for pre-registered MCP OAuth clients (#47891)
## Why

MCP OAuth configuration supported a pre-registered client ID but could not supply a client secret for token exchange or refresh.

## What changed

- Add `oauth.client_secret` and `codex mcp add --oauth-client-secret`, requiring a nonempty secret and client ID. Persist the secret in server configuration and accept `clientSecret` in plugin configuration.
- Pass configured credentials through CLI, app-server, and plugin login flows and token refresh. Require a new login when a configured confidential client's ID differs from stored credentials.
- Redact secrets in debug output and keep them out of authorization URLs and persisted OAuth token records.
- Invalidate cached OAuth connections when the configured client ID or secret changes.

## Testing

Add coverage for configuration validation and round trips, CLI argument redaction and subsequent login, app-server login, connection invalidation, and refresh with `client_secret_basic` and `client_secret_post` in both refresh modes. Verify secret exclusion from token records and reject mismatched client IDs before contacting the provider.

GitOrigin-RevId: 85bb0e410e9e68e6cd68eb6359badfc7eac78147
2026-09-24 17:26:18 +00:00
jif 282cd7b019 Stabilize Rosetta test timing and retry delay telemetry (#47832)
## Why

Cold Rosetta translation and cache invalidation from hard-linked executables can interfere with timed CLI tests. Sampling the clock twice also makes local retry telemetry report a delay shorter than the selected backoff.

## What changed

- Warm CLI fixtures with `--version` on macOS x86_64 before timed checks, and use copies or Unix symlinks to avoid invalidating the shared executable's Rosetta cache.
- Use one clock sample to calculate the response retry deadline and recorded delay.
- Include the retry telemetry event in delay-range assertion failures for the headerless rate-limit stream test.

GitOrigin-RevId: fc573bfff912e999cf74b94a1c6e7ae1be07974b
2026-09-24 13:09:49 +00:00
jif 51d4562070 Support close-on-exec attachments without changing PTY semantics (#47797)
## Why

Passing extra descriptors to a PTY previously selected behavior intended for inherited escalation sockets: no EOF on stdin close, different signal exit statuses, and no default `SHELL`. Launch attachments need ordinary PTY behavior and must survive execution even when marked `FD_CLOEXEC`.

## What changed

- Add `ChildFds::Attached` alongside `ChildFds::Inherited` to distinguish launch attachments from legacy inherited descriptors.
- Preserve ordinary EOF, default `SHELL`, and signal exit status behavior for PTY attachments.
- Allow explicitly supplied close-on-exec descriptors through pipe and PTY launches without changing the parent's descriptor flags, using child-side flag updates and macOS spawn inheritance actions.
- Update existing callers to use `ChildFds::Inherited`.

## Testing

Add Unix coverage for attachment accessibility, unchanged parent descriptor flags, default `SHELL`, and signal exit statuses. Extend the PTY stdin-draining test to cover attachments and EOF delivery.

GitOrigin-RevId: 864aedc6c5717d8b43c9d71057c9f54409834509
2026-09-24 09:25:19 +00:00
Ruslan Nigmatullin ad26b2520a Support bearer tokens for app-server executor connections (#47648)
## Why

App-server clients need a way to connect to executors that require bearer authentication through `environment/add` and `environments.toml`.

## What changed

- Add optional `authBearerToken` to `environment/add` and `auth_bearer_token` to URL entries in `environments.toml`.
- Send the token as an `Authorization: Bearer` header on initial connections and reconnects, without automatic refresh. Require `wss://` or a loopback destination when a token is supplied.
- Redact tokens in debug output, mark connection headers sensitive, and omit source text from TOML parse errors.
- Preserve unauthenticated behavior when tokens are omitted, including requests with a null `authBearerToken`.

## Testing

Add integration coverage for authenticated and unauthenticated executors through both RPC and TOML configuration, including missing, null, incorrect, and malformed RPC tokens. Extend tests for reconnect authorization headers, token redaction, URL-only token configuration, and timeout preservation.

GitOrigin-RevId: 2a5d48a1846df1720e4a9b295968348378c287c6
2026-09-23 20:05:37 +00:00
Adam Perry @ OpenAI 9d8de19674 Honor Retry-After and preserve server retry deadlines (#47641)
## Why

HTTP retries used local backoff even when the server supplied `Retry-After`. Relative retry delays also failed to account for time spent propagating errors or reporting retries.

## What changed

- Parse `Retry-After` delay seconds and HTTP dates into a monotonic deadline captured when response headers arrive.
- Honor that deadline for HTTP retries, falling back to local backoff when valid advice is absent.
- Preserve deadlines through API and Bedrock error mapping, stream retries, and exhausted retry state. Expired advice remains a zero delay instead of triggering local backoff.

## Testing

Add coverage for header parsing, deadline countdown and expiry, error mapping after exhausted HTTP retries, and delayed stream retry notifications. Update Responses and remote compaction tests to verify that HTTP retries honor `Retry-After`.

GitOrigin-RevId: a2eff02946e5524f29e06f7ba1431e3d339261a4
2026-09-23 19:53:11 +00:00
Ruslan Nigmatullin 2210190435 Add opt-in WebSocket authentication to exec-server (#47601)
## What changed

Expose the shared `--ws-auth` options on `codex exec-server` for direct WebSocket listeners. Support capability tokens configured by token file or SHA-256 digest, and signed JWT bearer tokens. Validate `Authorization: Bearer TOKEN` before each WebSocket upgrade, rejecting missing or invalid credentials with HTTP 401 when authentication is enabled.

Reject listener authentication with stdio, `--remote`, or `forward`. Document the options and connection-time authentication behavior.

## Testing

Add CLI integration tests for all three credential configurations, unauthorized upgrade rejection, authenticated RPC initialization and reconnects, invalid configuration, and incompatible transports.

GitOrigin-RevId: 941fbd3d43e732c910d29b6f8137077b7c332835
2026-09-23 17:56:46 +00:00
Ruslan Nigmatullin c44deff7b1 Extract WebSocket authentication into codex-websocket-auth (#47447)
## What changed

Move WebSocket authentication arguments, settings, credential loading, and upgrade authorization into a shared crate using `http` types. Update the app server, transport, and CLI to consume it directly, and remove the `AppServer` prefix from the shared types.

Hide token digests and JWT verification secrets from authentication policy `Debug` output.

## Testing

Move the existing argument validation, capability-token authorization, and signed bearer-token verification tests into the new crate.

GitOrigin-RevId: 1dd20043a3f8efbca55af7eda338b62a62e8fd68
2026-09-23 04:25:28 +00:00
acrognale-oai 8f8ace78cb Enforce application network policy for AWS auth and telemetry (#47408)
## Why

AWS credential discovery, analytics, and telemetry used clients that did not share the application's network policy. These requests need to honor destination restrictions and permission revocation.

## What changed

- Route AWS credential and region HTTP requests through the shared HTTP client, and check the signing destination before loading credentials. Skip discovery for static access keys with an explicit region.
- Apply account-scoped policy to Bedrock authentication. Require unrestricted policy for credential exporters and reauthentication commands, and cancel active work when permission is revoked. Document that AWS profile `credential_process` network traffic remains outside the application's HTTP policy.
- Send analytics through the authenticated account's HTTP client factory.
- Guard OTLP log, trace, and metric exports with revocable permits, disable them under destination restrictions, and make managed HTTP exports cancellable. Suppress global Statsig settings while managed policy is active.

## Testing

Add coverage for metadata credential request cancellation, allowed and denied SigV4 destinations, AWS credential precedence and endpoint configuration, and blocked credential exporter recovery. Update telemetry tests for account transitions and managed-policy Statsig suppression.

GitOrigin-RevId: d8a2018bfbbe971ec430699b0d3f86a7a9e1e072
2026-09-23 00:47:34 +00:00
acrognale-oai 888e02db34 Enforce network policy throughout HTTP and WebSocket requests (#47389)
## Why

Destination restrictions and policy revocation must remain effective during redirects, response body reads, and established WebSocket traffic. Policy denials must also survive error handling so callers do not retry them or report a revoked operation as successful.

## What changed

- Route managed HTTP clients through a shared `RequestBuilder` and policy-aware execution, checking each redirect destination before route resolution and retaining a network permit while consuming response bodies.
- Guard WebSocket connection setup, reads, and writes with revocable permits, including independent wakeups for split readers and writers.
- Preserve `TransportError::Policy` through HTTP, SSE, and realtime error handling, and treat policy denials as non-retryable.
- Keep the supplied network policy in plugin startup HTTP requests and propagate response body failures from backend and plugin requests.

## Testing

Add regression coverage for rejection before connecting, revocation during redirect routing and streamed body reads, split WebSocket revocation, realtime writer error propagation, and revoked plugin upload responses.

GitOrigin-RevId: fba36700444c98a8364c09b4dc5452c4d78a90fb
2026-09-22 23:37:39 +00:00
iceweasel-oai 418199f6ad Add an opt-in preference for the local MXC sandbox (#47375)
## What changed

Add the default-off `features.prefer_mxc` flag to select MXC for local Windows execution when native support is available and effective network settings do not explicitly forbid local binding. Otherwise, retain the configured backend and legacy setup behavior.

Resolve the preference during config loading and use the effective local backend for execution, network proxy setup, sandbox diagnostics, and `windowsSandbox/readiness`. Preserve the configured backend for remote executors and `config/read`. Explicit `windows.sandbox = "mxc"` remains strict, and command failures do not trigger backend fallback.

## Testing

Add coverage for preference resolution, startup readiness without rewriting configuration, local and remote backend selection across environment updates and child threads, and workspace-write permission context in an agent turn.

GitOrigin-RevId: b51178f0371d38ebb58e41af54a068fca67fa316
2026-09-22 21:57:52 +00:00
Dmitriy Kovalenko 722dae7afd Color paths and URLs in codex doctor by check status (#47358)
## What changed

Highlight recognized paths and URLs in check descriptions and details in red for failed checks and cyan otherwise. Extend path recognition on Windows to drive-absolute, UNC, Win32, and NT DOS paths.

## Testing

Add Windows and non-Windows color snapshots covering successful, warning, and failed checks, punctuation, and backtick-quoted paths with spaces. Assert that descriptions and details remain unchanged when color is disabled.

GitOrigin-RevId: e8f9982505aa155fd312b12f91a71271effeb35e
2026-09-22 20:20:06 +00:00
Rennie 559264d92e Preserve invalid_prompt as a distinct error classification (#47353)
## Why

`invalid_prompt` responses were classified as generic invalid requests, losing the server's specific error classification.

## What changed

Add `InvalidPrompt` variants to the API and core error types and serialize the core protocol classification as `invalid_prompt`. Recognize the code in HTTP 400 responses, wrapped WebSocket errors, and SSE `response.failed` events while preserving server messages and keeping the error non-retryable. Map it to `other` in the app-server v2 protocol.

## Testing

Extend coverage for typed error mapping, missing and blank messages, protocol conversion, and guardian retry handling. Exercise HTTP and SSE failures in core integration tests, asserting the error message, serialized classification, and a single request without retry.

GitOrigin-RevId: 5d9a299a013b06158a4dc27a4054f3dbc5fd0f4d
2026-09-22 20:07:50 +00:00
andrewgu-oai 49e95cc73f Add GPT-6 Sol and Luna to the model catalog (#47332)
## What changed

- Add `gpt-6-sol` and `gpt-6-luna` catalog entries and refresh model descriptions.
- Offer migrations from `gpt-5.5`, `gpt-5.6-sol`, and `gpt-5.6-terra` to `gpt-6-sol`, and from `gpt-5.6-luna` to `gpt-6-luna`.
- Retarget retired `gpt-5.4` and `gpt-5.4-mini` selections to GPT-6 Sol and Luna, respectively.
- Recommend `gpt-6-luna` in the rate-limit switch prompt.

## Testing

Extend migration tests to cover the new targets, their default reasoning effort, and prompting again after a previously acknowledged migration to an older target. Update model-picker and rate-limit prompt snapshots.

GitOrigin-RevId: d3a093d18ce44a903383504ab8f5cbbc911d602d
2026-09-22 18:17:39 +00:00
dkovalenko-oai 3b7a8520ef Identify failed SQLite databases in codex doctor output (#47330)
## Why

The generic state integrity failure message does not identify which database needs attention.

## What changed

- Include the paths of all databases that fail integrity checks in a structured issue, shown in text summaries and JSON output, with the existing recovery guidance.
- Redact sensitive details using `: ` as the field-label separator so Windows drive letters are not mistaken for labels and unlabeled sensitive paths are fully redacted.

## Testing

Add coverage for single and multiple failed databases, summary and detailed text output, JSON output, preservation of damaged database contents, and sensitive path redaction on Unix and Windows.

GitOrigin-RevId: ac5fec9473d22b6b137a9fc8a751aba8605d940f
2026-09-22 17:59:02 +00:00
Eric Traut d6093d3228 Offer explicit recovery for incompatible background servers (#47318)
## Why

Automatic daemon launches could silently fall back to embedded mode when shared feature settings differed from the session's requirements. Changing those settings affects other clients, and restarting the server may interrupt active or queued work.

## What changed

- Offer interactive choices to run without the daemon, restart with the required settings, or cancel. Default to cancel and require explicit confirmation for restart.
- Allow restart only for managed daemons with a feature mismatch, then recheck compatibility once. Noninteractive required-daemon failures return an error with `--no-daemon` guidance; optional attachment retains its fallback behavior.
- Preserve saved feature overrides on startup and require confirmation before applying requested shared-feature disables, including on fresh starts.
- Merge confirmed settings under the lifecycle lock, persist changes after the old process stops, and avoid restarting when the saved overrides already match.

## Testing

Add recovery-menu snapshots and confirmation tests, compatibility tests for required and optional attachment, daemon ownership and settings-preservation tests, and CLI terminal tests for cancellation, embedded fallback, confirmed restart, and disabling shared features.

GitOrigin-RevId: d50a6cf7e476b9647237431e8fc0fc6041ed17db
2026-09-22 16:07:38 +00:00
Eric Traut 75ec81c862 Enable automatic daemon startup by default (#47179)
## What changed

Promote `daemon_auto_start` to stable and enable it by default for eligible interactive launches. Remove its entry from `/experimental`.

## Testing

Update daemon startup, `--no-daemon`, and startup failure tests to exercise the default without explicitly enabling the feature. Disable daemon startup in unrelated TUI and path-safety test fixtures.

GitOrigin-RevId: 107d71108b96d09431148d7d61f10c6381929e05
2026-09-22 03:20:27 +00:00
Adam Perry @ OpenAI 517f51a6f7 Extract exec-server CLI startup into a dedicated module (#47143)
## What changed

Move `codex exec-server` argument definitions, transport validation, configuration loading, authentication, and shutdown orchestration from `codex-rs/cli/src/main.rs` into `codex-rs/cli/src/exec_server_command.rs`.

Expose startup through `ExecServerCommand::run`, merge the root `--strict-config` flag into the command before dispatch, and update existing argument tests to use the new entry point.

GitOrigin-RevId: 4bcc59db2bd6e1d153a366142bd0b93ad03c6951
2026-09-22 01:01:44 +00:00
Jesse Du 3fd5160cd6 Honor the configured product SKU in remote plugin requests (#47116)
## Why

Remote plugin requests always sent `OAI-Product-Sku: codex`, ignoring the existing `apps_mcp_product_sku` setting.

## What changed

Pass `apps_mcp_product_sku` through plugin configuration and use it for authenticated remote plugin requests, including discovery, search, installation, and sharing. Keep `codex` as the default and include the SKU when comparing remote service configurations.

## Testing

Extend app-server plugin listing and core agent-turn tests to check default and configured SKU headers. Update the CLI worktree test to wait for the user prompt's model request, skipping background title generation requests.

GitOrigin-RevId: 508c9ef9aa3e41b87c92383c3088eb1eb9227fd8
2026-09-21 22:30:43 +00:00
Anthony Tafoya f3037cafd3 Refresh host-supplied cloud skills at turn startup (#47074)
## What changed

- Replace the built-in orchestrator skill provider with a host-supplied cloud provider, using `cloud` authority and `c` root aliases in skill tools and prompts.
- Add `cloud.skills.enabled`, defaulting to true but requiring a supplied provider. Keep `orchestrator.skills` accepted as a legacy no-op setting, and remove the app server's automatic orchestrator provider registration.
- Discover cloud skills once per turn during cancellable startup. Serve catalog snapshots to prompts and tools without triggering discovery or retries.
- Scope cached catalogs and resources to authentication state. Preserve them on refresh failures within the same scope, invalidate them when that scope changes, and reject late discovery or read results from replaced cache generations.
- Reuse executor discovery catalogs only when successful discovery inputs and bundled-skill settings match.

## Testing

Add coverage for per-turn refresh, skill removal, same-account failures and reconnects, authentication changes, and stale in-flight results. Update configuration and tool tests for cloud authority, provider gating, and resource reads without an executor.

GitOrigin-RevId: c57e38ec7dcc880c0d4c8a2995adfd3e28301079
2026-09-21 17:28:14 +00:00
jif ffbd30aeb7 Canonicalize the workspace trust key in the doctor config test (#46981)
macOS temporary directories can use symlinked paths. Use `project_trust_key`
in `doctor_reports_only_safe_config_error_metadata` so the fixture trusts the
canonical workspace when testing project configuration errors.

GitOrigin-RevId: 61b15e4cfc2eaa8d258b51a482decc0b9bd684e9
2026-09-21 09:14:48 +00:00
jif 0ad18769ad Avoid exposing config values in codex doctor errors (#46962)
## Why

Configuration load errors can echo configuration values, including credentials, into diagnostic reports.

## What changed

Replace raw error messages in `config.load` failures with typed metadata. Report the file, line, and column when a `ConfigLoadError` is available, including when wrapped in an I/O error. Otherwise, report only the I/O error kind or a generic configuration load failure.

## Testing

Add regression tests and snapshots for malformed user and project configuration, an unknown model provider, and invalid header configuration. Verify that both tested JSON reporting modes omit the test credentials while retaining the expected failure details.

GitOrigin-RevId: bec53313888dbfc8c0869f3cb410b1c3e5496630
2026-09-21 08:14:18 +00:00
Eric Traut 88ef37c649 Identify local background servers in /status (#46905)
## What changed

Rename the `/status` connection row from `Remote` to `Server`. For local daemon connections, display `Local background server` instead of the socket address and version. Keep the address and version for remote connections, including explicitly configured Unix sockets.

## Testing

Add a local background server snapshot and coverage distinguishing local daemon connections from remote Unix sockets. Update daemon startup and worktree tests to expect the new label.

GitOrigin-RevId: 9460415fe1ec16d90f575917c1a4ce1bf19faaaf
2026-09-20 23:23:13 +00:00
Eric Traut a2de8fedcc Move fullscreen transcript control to TUI configuration (#46849)
## What changed

Use `tui.fullscreen_transcript` to opt into the fullscreen transcript, including scrolling, selection, and search. It defaults to `false`; `--no-alt-screen` and `tui.alternate_screen = "never"` still take precedence.

The new preference controls both the first frame and application startup. Boolean CLI overrides for it are allowed during daemon startup. The old `features.transcript_v2` flag is deprecated and ignored, with a notice directing users to the new setting; it does not migrate into or override the preference.

## Testing

Add coverage for default terminal scrollback, fullscreen persistence through startup, alternate-screen restrictions, daemon override validation, and independence from the deprecated flag. Update existing history and activity tests to use the new preference.

GitOrigin-RevId: 4117bf1ee548fa8d101a594f9506673d87c74c15
2026-09-20 16:59:00 +00:00
Eric Traut f1feda2299 Integrate the interactive transcript into the alternate-screen TUI (#46733)
## What changed

- Render transcript history and live output above the composer when `features.transcript_v2` is enabled and alternate-screen rendering is available. Handle scrolling, selection, copying, links, and older-history pagination in the main view.
- Add a clickable return-to-latest control with new-activity hints and temporary clipboard status. Let plain Enter return to latest when the composer is empty.
- Reflow retained transcript content during drawing and preserve the launch-selected screen mode across configuration reloads and session transitions, including `--no-alt-screen` restrictions.
- Enter the alternate screen with its first synchronized frame, and box CLI startup futures to reduce stack usage during session transitions.

## Testing

Add regression coverage for transcript layout, input routing, follow controls, clipboard status, and screen-mode persistence. Add a PTY test for the first alternate-screen frame and clean exit, and extend session-transition coverage through the CLI dispatcher.

GitOrigin-RevId: 1daf077826c7744b0f57399d10d159923dc87a97
2026-09-20 00:06:00 +00:00
iceweasel-oai a633ebc124 Always use private desktops for legacy Windows sandboxes (#46554)
## What changed

- Remove the private-desktop opt-out from elevated and unelevated Windows sandbox launches.
- Remove `windows.sandbox_private_desktop` and its managed requirement and API fields. Warn users to remove the obsolete setting.
- Require a private desktop name when launching through the Windows sandbox wrapper and command runner.

## Testing

Add coverage for the obsolete-setting migration warning and update wrapper tests to verify a live private desktop is passed and a missing desktop name is rejected.

GitOrigin-RevId: c7135f8d211aac8d812180691c2c1e433d77cde4
2026-09-19 01:21:32 +00:00
Eric Traut b33199b1fb Add bounded filesystem path diagnostics to codex doctor (#46543)
## Why

Configured filesystem paths can be slow or inaccessible. Doctor needs to identify those paths and their configuration sources without letting a blocked filesystem call delay runtime shutdown.

## What changed

- Add `sandbox.filesystem_paths` to report literal filesystem grants, access modes, resolution outcomes, and configuration sources when available. Exclude deny rules and denied paths without expanding globs or special paths.
- Resolve paths in disposable helper processes, with wait budgets of two seconds per path and eight seconds total, checking at most 32 paths. Warn on slow or unsuccessful probes and incomplete checks; missing paths alone do not trigger warnings. Probes do not test read/write access.
- List paths without probing on Windows or when filesystem read restrictions apply.
- Increase the app-server doctor report timeout from 25 to 35 seconds to accommodate the probes.

## Testing

Add unit and integration coverage for path deduplication and deny filtering, configuration provenance, blocked-helper timeouts, helper execution without loading configuration, and report snapshots for resolved, missing, Windows, and read-restricted paths.

GitOrigin-RevId: b0732265fc2c83ea67acc24b442e39139d705f1b
2026-09-19 00:54:45 +00:00
Eric Traut 1537497e52 Allow compatible feature overrides when starting the shared daemon (#46529)
## Why

Feature overrides previously forced embedded mode even when they could work with the shared daemon. A running daemon can also have different feature settings from the current invocation, including when the invocation uses defaults.

## What changed

- Allow selected Boolean feature overrides and `suppress_unstable_features_warning` in daemon mode. Keep explicit overrides that disable shared services in embedded mode.
- Pass shared-service feature overrides to newly launched daemons and persist them for restarts and updates without changing a running daemon's settings.
- Check daemon feature settings with `experimentalFeature/list` before attaching. Warn and fall back to embedded mode on mismatches, failed checks, or an incompatible code-mode host fallback policy. Skip this check for the agents overview.
- Resolve worktree configuration before daemon selection and allow worktree sessions to auto-start the daemon.
- Forward `suppress_unstable_features_warning` in thread configuration overrides.

## Testing

Add coverage for override eligibility and precedence, launch-feature persistence and reuse, and TUI fallback warnings for feature and host-policy mismatches. Extend worktree integration coverage to exercise daemon auto-start and warning suppression.

GitOrigin-RevId: 68c316f74843b1dfd8fa39bdb48bd1f649fee57f
2026-09-19 00:14:40 +00:00
felixxia-oai 5701a576cc Retry busy executable launches in packaged daemon tests (#46524)
## Why

Freshly copied executables can briefly remain busy on Linux CI workers, causing packaged daemon tests to fail at launch.

## What changed

Retry the command launch in `packaged_daemon_launch` up to twice on `std::io::ErrorKind::ExecutableFileBusy`, waiting 10 ms between attempts. Other launch errors still propagate immediately.

GitOrigin-RevId: afb6213173a7ae4bcfe2e1e6fab6ced65ab5bf77
2026-09-19 00:08:18 +00:00
iceweasel-oai 74af2496c9 Default local binding to true for MXC managed networking (#46523)
## Why

MXC's native host-loopback access is bidirectional, so it cannot enforce `allow_local_binding = false`. Treating an omitted setting as `false` prevents managed networking from working with the default configuration.

## What changed

- Preserve an omitted `allow_local_binding` until the executor's sandbox policy is known. Default to `true` for Windows MXC and `false` elsewhere, including remote execution.
- Reject an effective `false` for MXC managed networking after applying policy restrictions, without enabling disabled networking.
- Use the executor's resolved value for remote network approval decisions while preserving explicit controller restrictions.
- Document that local binding permits local servers and direct host-loopback connections and skips additional private-network destination checks; proxy domain rules still apply.

## Testing

Add coverage for per-executor defaults, explicit values, MXC rejection of `false`, and remote network review cleanup with the resolved policy.

GitOrigin-RevId: 0fa7c1eaec68bebada2b8f7af45688315eea70a9
2026-09-19 00:00:01 +00:00
Eric Traut 547c9a1aad Use catalog model display names throughout the TUI (#46503)
## Why

Model pickers and session details show raw model IDs even when the catalog provides a display name.

## What changed

- Use catalog display names in model and reasoning pickers, session headers, status displays, and terminal titles, retaining fallback labels for models absent from the catalog.
- Keep model IDs for selection and persistence, and preserve picker highlights by ID when display names change or are shared by multiple models.
- Remove the legacy-model instruction from the full model picker.

## Testing

Add regression tests and snapshots for custom display names, startup and resumed session headers, fallback labels, terminal titles, and picker refreshes. Verify that selecting a display name still persists the original model ID.

GitOrigin-RevId: 101fe82b20f7a8a90ceeff7999bd07ad42ca46db
2026-09-18 23:15:39 +00:00
Eric Traut e497393552 Allow worktree sessions to use an existing local daemon (#46498)
## Why

`--worktree` and command-line worktree feature overrides previously excluded sessions from using the local daemon, even though worktree allocation is client-owned and thread requests already forward the feature.

## What changed

- Allow `--worktree` and boolean `features.worktrees` overrides to remain eligible for daemon connections, while preserving exclusions for other configuration overrides and `--no-daemon`.
- Skip daemon auto-start for `--worktree` launches.

## Testing

Add daemon eligibility tests for worktree options and overrides. Run the existing worktree startup and fork test scenarios against both embedded and daemon backends, checking ownership before the first turn and confirming daemon connections through `/status`.

GitOrigin-RevId: b3f4782e83d8e20974fb4a831442cae013d58e56
2026-09-18 23:05:31 +00:00
Eric Traut 6d29cc6bac Keep remote workspace roots under server control (#46494)
## Why

Workspace paths from the client configuration belong to the client host. Sending them to a remote app server can override the server's workspace roots.

## What changed

- Omit client-configured `runtimeWorkspaceRoots` from remote start, resume, and fork requests so the server resolves defaults or restores saved roots.
- Preserve server-provided roots when forking an active session or side conversation, including after reloading client configuration.
- Reject `--add-dir` and `sandbox_workspace_write.writable_roots` command-line overrides with `--remote` before connecting, directing users to configure additional roots on the server.

## Testing

Add regression coverage for remote workspace roots across start, turn, resume, and fork operations; active-session forks after configuration reloads; and embedded requests retaining explicit roots. CLI tests cover rejected root overrides and continued acceptance of network-access overrides.

GitOrigin-RevId: b87ea6037d197db68e25a1a8610d693f6aa13caf
2026-09-18 22:53:00 +00:00
Rennie fa8cf44985 Preserve bio policy errors as a distinct non-retryable error (#46306)
## Why

Streaming `bio_policy` failures were classified as generic invalid requests, losing their policy-specific classification.

## What changed

- Add `BioPolicy` errors across the API and core protocol, recognizing streaming failures and HTTP 400 responses, including wrapped WebSocket errors.
- Preserve server messages and use a biological-risk fallback when the message is missing or blank.
- Treat bio policy errors as non-retryable in core and guardian handling, and classify them in diagnostics and telemetry.
- Map `BioPolicy` to `other` in the app-server v2 protocol.

## Testing

Add coverage for error classification, message preservation and fallbacks, HTTP and wrapped WebSocket responses, guardian retry decisions, and app-server conversion. Extend the core integration test to verify that bio policy failures emit a typed error and complete the turn after a single request.

GitOrigin-RevId: 78c2647e8fc8f80297cb8a23fff06ab141099632
2026-09-17 21:25:55 +00:00
iceweasel-oai 8b78600dc8 Enable MXC selection through Windows sandbox configuration (#46271)
## What changed

- Accept `windows.sandbox = "mxc"` and preserve the selected backend through environment configuration, command execution, patch writes, and sandbox metadata.
- Treat MXC as enabled in the TUI and report Windows sandbox readiness as `ready`, avoiding legacy setup prompts.
- Keep `allowed_sandbox_implementations` scoped to the legacy elevated and unelevated backends without restricting MXC.
- Default `windows.sandbox_private_desktop` to `false` for MXC while retaining `true` for legacy sandboxes.

## Testing

Add coverage for MXC configuration precedence, legacy requirement handling, sandbox selection, and TUI state. Add a Wine integration test that verifies command and patch routing fails when native MXC is unavailable and reports `windows_mxc` in turn metadata.

GitOrigin-RevId: e2162447d0750f60753864c92a20e02a7f297bca
2026-09-17 18:20:28 +00:00
Eric Traut b0659c5386 Record daemon startup and update telemetry with consent handling (#46126)
## Why

TUI startup metrics report the selected app-server mode before a connection succeeds, which can misrepresent embedded fallback or failed startup. Daemon startup and update actions also need distinct outcome observations.

## What changed

- Record `codex.tui.start` once after the first connection attempt, using the actual mode or `unconfirmed`, and include daemon selection and auto-start tags.
- Add `codex.daemon.start` for TUI auto-start and `codex.daemon.update` for foreground CLI updates and TUI update handoffs, using existing analytics consent and identity handling.
- Report TUI handoffs as `handoff_requested` and suppress duplicate child reporting. Remove the suppression flag when spawning long-lived daemon processes.
- Tag daemon settings by enabled state and explicit presence, without exporting setting values or contents; report invalid or unreadable settings as `unknown`.

## Testing

Add coverage for analytics defaults and explicit consent overrides, unconfirmed CLI updates, settings presence, and exactly-once launch observations. Extend the worktree TUI test to check startup tags and a single update handoff observation.

GitOrigin-RevId: 176d2ee594f930033fa1ece55d4c1c9603dbbc16
2026-09-17 05:26:45 +00:00
Eric Traut 70e8fe1be3 Add opt-in automatic background server startup (#46117)
## What changed

- Add `features.daemon_auto_start`, disabled by default and available through `/experimental`, to start the shared local server for eligible new, resumed, and forked sessions. Changes take effect on the next launch, and disabling the feature persists an explicit `false`.
- Require successful daemon startup and connection when auto-start applies. On failure, show guidance to rerun the same command with `--no-daemon` instead of silently falling back to an embedded server.
- Preserve embedded mode for excluded launches, including Bedrock sign-in, and carry exclusion warnings through resume and fork pickers. Honor `--no-daemon` without an exclusion warning.
- Update `/import` guidance to recommend restarting with `codex --no-daemon`.

## Testing

Add CLI and TUI coverage for automatic daemon attachment, startup and connection failures, `--no-daemon`, picker warning persistence, and Bedrock onboarding with and without a running daemon. Add snapshots and configuration-write assertions for the experimental toggle.

GitOrigin-RevId: 2e8eb163bc7ddd268a86c7546c05a85356c1e9ee
2026-09-17 04:53:51 +00:00
Jiwon Kim 108e6a6dbe Replace Sites migration state with a runtime compatibility guard (#46108)
## Why

Older Desktop clients can still provide bundled Sites to an independently updated SSH app-server. A cached remote Sites install must take precedence, even when disabled, while a missing remote bundle must preserve the bundled fallback.

## What changed

- Remove persisted bundled-plugin exclusions, Sites migration checks, and the migration wait when loading local plugin configuration.
- Suppress `sites@openai-bundled` during plugin loading when the remote global catalog is active and a cached remote Sites install is available.
- Remove exclusion-based catalog filtering and read/install guards, and simplify `install_plugin` to accept `ConfigLayerStack`.

## Testing

Expand the agent-turn Sites test to cover enabled remote precedence, disabled remote suppression of bundled Sites, and fallback when the remote bundle is missing.

GitOrigin-RevId: e2758596e5493ccee051cdfbf6b4afbe4f98948c
2026-09-17 04:23:45 +00:00
Eric Traut 787823cf95 Add --no-daemon to bypass the shared background server (#46088)
## What changed

- Run with `--no-daemon` without starting or probing the shared server, even when it is already running. Preserve the flag through `resume` and `fork`, and honor it for session archive commands.
- Reject combinations with `--remote`, `codex agents`, and `codex queue`, which require a server connection. Point users to `codex --no-daemon` when the agents overview cannot start its shared server.
- Centralize daemon eligibility checks and exclude launches using `--profile` or `CODEX_EXEC_SERVER_URL` from implicit daemon reuse.

## Testing

Add coverage for flag propagation, incompatible command combinations, and daemon eligibility. Add a PTY test verifying that `--no-daemon` starts the TUI without creating daemon state or connecting to an existing control socket.

GitOrigin-RevId: acc6a7cb339df6433bb8273c796194cdceda37c1
2026-09-17 02:46:49 +00:00
richardopenai 2aff7208fe Add a hidden HTTP/3 TCP tunnel command (#45900)
## What changed

Add `codex tcp-tunnel` and the `codex-tcp-tunnel` crate to forward loopback TCP connections to an explicit target through a TLS-verified HTTP/3 CONNECT proxy.

- Require the proxy origin to match an approved HTTPS origin in a supplied policy file.
- Read bearer tokens and optional bounded, non-forwarding `x-` headers from stdin. Support token updates for new connections, `LISTENING` and `AUTH_UPDATED` notifications, and shutdown when the control pipe closes in token-update mode.
- Preserve the listener across proxy reconnects without replaying TCP streams, and let accepted streams continue while a proxy drains.

## Testing

Add tests for hidden CLI parsing, proxy and target validation, credential renewal, control-pipe closure, and invalid input without secret disclosure. A local HTTP/3 proxy test covers token replacement, transport recovery without stream replay, and graceful draining.

GitOrigin-RevId: c6af3025301c61e9fe90940cf5a6df0039465e69
2026-09-16 09:03:41 +00:00
Sean Huang 83dc7d11e8 Preserve executor path URIs in permission profile workspace roots (#45863)
## Why

Executor profile roots can use path conventions that are not native to the current host. Converting them to host paths during configuration or turn reconstruction can reject or drop those roots, while case-insensitive comparison can hide Windows path spelling changes.

## What changed

- Store profile roots as URI-backed `ProfileWorkspaceRoot` values throughout permission snapshots and thread settings, preserving spelling in equality and deduplication.
- Keep effective workspace roots as `PathUri` values for permission materialization and status summaries. Convert Windows sandbox root hints to native paths only at native Windows sandbox boundaries, rejecting incompatible roots.
- Omit the legacy rollout `workspace_roots` field when profile roots cannot be represented as host paths, retaining the compiled permission profile.

## Testing

Add regression coverage for Windows and UNC root spelling changes, settings restoration and turn recording with foreign roots, executor-root status display, and backend-specific Windows root conversion.

GitOrigin-RevId: 903c068fd74959bdd10e7cb1141aa42b953a59a4
2026-09-16 04:23:46 +00:00
Eric Traut 04581f9604 Add /daemon menu for local background server updates (#45854)
## Why

Local daemon version warnings direct users to a shell command. Provide an update flow from the TUI with an explicit choice of package source and confirmation before exiting.

## What changed

- Add `/daemon` with options to install the latest public stable release or use the current CLI package. Point local server version notices to the menu.
- Default confirmation to Cancel and explain restart, interruption, and relaunch behavior. After confirmation, exit the TUI and run the update through the launching CLI executable, propagating failures.
- Keep maintenance available when disconnected or using the embedded server. Disable updates for remote connections or a missing CLI executable, and disable copying the CLI build when no local package is available.

## Testing

Add menu snapshots and interaction tests covering both update sources, cancellation, and unavailable actions. Add a Unix CLI handoff test verifying the selected executable, command arguments, and failure propagation.

GitOrigin-RevId: 06b485feb5650673ec7dd00adda01fedb8909393
2026-09-16 03:43:59 +00:00